Re: [PATCH v18 3/3] Input: new da7280 haptic driver

2020-07-30 Thread Uwe Kleine-König
Hello, On Wed, Jul 29, 2020 at 11:34:04PM -0700, Dmitry Torokhov wrote: > On Thu, Jul 30, 2020 at 08:16:31AM +0200, Uwe Kleine-König wrote: > > I suggested that some time ago with limited success, see > > https://lore.kernel.org/lkml/20200129115516.zsvxu56e6h7gh...@pathway.suse.cz/ > > . > > > >

[char-misc-next V2] mei: hdcp: fix mei_hdcp_verify_mprime() input paramter

2020-07-30 Thread Tomas Winkler
wired_cmd_repeater_auth_stream_req_in has a variable length array at the end. we use struct_size() overflow macro to determine the size for the allocation and sending size. Fixes: c56967d674e3 (mei: hdcp: Replace one-element array with flexible-array member) Fixes: c56967d674e3 (mei: hdcp: Replac

Re: [PATCH 08/23] fs: don't change the address limit for ->write_iter in __kernel_write

2020-07-30 Thread Christoph Hellwig
On Wed, Jul 29, 2020 at 09:50:36PM +0100, Al Viro wrote: > On Tue, Jul 07, 2020 at 07:47:46PM +0200, Christoph Hellwig wrote: > > If we write to a file that implements ->write_iter there is no need > > to change the address limit if we send a kvec down. Implement that > > case, and prefer it over

Re: [PATCH 22/23] fs: default to generic_file_splice_read for files having ->read_iter

2020-07-30 Thread Christoph Hellwig
On Thu, Jul 30, 2020 at 01:05:44AM +0100, Al Viro wrote: > On Tue, Jul 07, 2020 at 07:48:00PM +0200, Christoph Hellwig wrote: > > If a file implements the ->read_iter method, the iter based splice read > > works and is always preferred over the ->read based one. Use it by > > default in do_splice_

[PATCH v1] scsi: smartpqi: use generic power management

2020-07-30 Thread Vaibhav Gupta
Drivers using legacy power management .suspen()/.resume() callbacks have to manage PCI states and device's PM states themselves. They also need to take care of standard configuration registers. Switch to generic power management framework using a single "struct dev_pm_ops" variable to take the unn

Re: [PATCH v9 0/4] driver core: add probe error check helper

2020-07-30 Thread Greg Kroah-Hartman
On Tue, Jul 28, 2020 at 05:05:03PM +0200, Andrzej Hajda wrote: > Hi Greg, > > Apparently the patchset has no more comments. > > Could you take the patches to your tree? At least 1st and 2nd. All now queued up, thanks! greg k-h

Re: [PATCH 15/23] seq_file: switch over direct seq_read method calls to seq_read_iter

2020-07-30 Thread Thomas Gleixner
Al Viro writes: > On Fri, Jul 17, 2020 at 11:09:13PM +0200, Thomas Gleixner wrote: >> >> Needs some thought and maybe some cocci help from Julia, but that's way >> better than this brute force sed thing which results in malformed crap >> like this: >> >> static const struct file_operations debug

Re: bpfilter logging write errors in dmesg

2020-07-30 Thread Christian Brauner
On Mon, Jul 27, 2020 at 04:50:13PM +0200, Christoph Hellwig wrote: > Strange. Can you add this additional debugging patch: Sorry Christoph, didn't mean to leave you waiting. I got pulled into other stuff. Christian > > diff --git a/fs/read_write.c b/fs/read_write.c > index 4fb797822567a6..d0a

KASAN: slab-out-of-bounds Read in ath9k_hif_usb_rx_cb (2)

2020-07-30 Thread syzbot
Hello, syzbot found the following issue on: HEAD commit:ab4dc051 usb: mtu3: simplify mtu3_req_complete() git tree: https://git.kernel.org/pub/scm/linux/kernel/git/gregkh/usb.git usb-testing console output: https://syzkaller.appspot.com/x/log.txt?x=11c0666c90 kernel config: https:/

Re: [PATCH V3 3/3] pci: imx: Select RESET_IMX7 by default

2020-07-30 Thread Philipp Zabel
Hi Anson, On Thu, 2020-07-30 at 02:11 +, Anson Huang wrote: > Hi, Philipp/Rob > > > Subject: Re: [PATCH V3 3/3] pci: imx: Select RESET_IMX7 by default > > > > On Wed, 2020-07-29 at 09:26 -0600, Rob Herring wrote: > > > On Mon, Jul 20, 2020 at 8:26 AM Anson Huang > > wrote: > > > > i.MX7 res

Re: [patch V5 05/15] entry: Provide infrastructure for work before transitioning to guest mode

2020-07-30 Thread Thomas Gleixner
Qian Cai writes: > On Wed, Jul 22, 2020 at 11:59:59PM +0200, Thomas Gleixner wrote: > SR-IOV will start trigger a warning below in this commit, > > [ 765.434611] WARNING: CPU: 13 PID: 3377 at include/linux/entry-kvm.h:75 > kvm_arch_vcpu_ioctl_run+0xb52/0x1320 [kvm] Yes, I'm a moron. Fixed it lo

Re: [PATCH V8 1/6] clk: imx6sl: Use BIT(x) to avoid shifting signed 32-bit value by 31 bits

2020-07-30 Thread Arnd Bergmann
On Thu, Jul 30, 2020 at 2:03 AM Anson Huang wrote: > > Use readl_relaxed() instead of __raw_readl(), and use BIT(x) > instead of (1 << X) to fix below build warning reported by kernel > test robot: > > drivers/clk/imx/clk-imx6sl.c:149:49: warning: Shifting signed 32-bit > value by 31 bits is undef

Re: [RFC PATCH] arm64: defconfig: Disable fine-grained task level IRQ time accounting

2020-07-30 Thread Kurt Kanzenbach
Hi Vladimir, On Wed Jul 29 2020, Vladimir Oltean wrote: > For more context, here is my original report of the issue: > https://lkml.org/lkml/2020/6/4/1062 > > Just like you, I could not reproduce the RCU stalls and system hang on a > 5.6-rt kernel, just on mainline and derivatives, using the plain

Re: [PATCH] ASoC: fsl-asoc-card: Remove fsl_asoc_card_set_bias_level function

2020-07-30 Thread Shengjiu Wang
On Mon, Jul 27, 2020 at 8:58 AM Nicolin Chen wrote: > > On Sun, Jul 26, 2020 at 07:20:17PM +0800, Shengjiu Wang wrote: > > With this case: > > aplay -Dhw:x 16khz.wav 24khz.wav > > There is sound distortion for 24khz.wav. The reason is that setting > > PLL of WM8962 with set_bias_level function, th

[PATCH v4] usb: typec: tcpm: Migrate workqueue to RT priority for processing events

2020-07-30 Thread Badhri Jagan Sridharan
"tReceiverResponse 15 ms Section 6.6.2 The receiver of a Message requiring a response Shall respond within tReceiverResponse in order to ensure that the sender’s SenderResponseTimer does not expire." When the cpu complex is busy running other lower priority work items, TCPM's work queue sometimes

[PATCH net] net: ll_temac: Use devm_platform_ioremap_resource_byname()

2020-07-30 Thread Wang Hai
platform_get_resource() may fail and return NULL, so we had better check its return value to avoid a NULL pointer dereference a bit later in the code. Fix it to use devm_platform_ioremap_resource_byname() instead of calling platform_get_resource_byname() and devm_ioremap(). Fixes: 8425c41d1ef7 ("n

Re: [PATCH V7 1/6] clk: imx6sl: Use BIT(x) to avoid shifting signed 32-bit value by 31 bits

2020-07-30 Thread Arnd Bergmann
On Thu, Jul 30, 2020 at 3:14 AM Anson Huang wrote: > > Subject: Re: [PATCH V7 1/6] clk: imx6sl: Use BIT(x) to avoid shifting signed > > 32-bit value by 31 bits > > or you could read Documentation/process/submit-checklist.rst, > > where rule #1 says: > > > > 1) If you use a facility then #include

Re: [PATCH v3] usb: typec: tcpm: Migrate workqueue to RT priority for processing events

2020-07-30 Thread Badhri Jagan Sridharan
Hi Greg, Yes Guenter's suspicion is right. Mine was conflicting with Han's following patch: commit 5f2b8d87bca528616e04344d1fc4032dc5ec0f3d Author: Hans de Goede Date: Fri Jul 24 19:46:57 2020 +0200 usb: typec: tcpm: Move mod_delayed_work(&port->vdm_state_machine) call into tcpm_queue_vdm(

Re: [PATCH 01/17] dt-bindings: clocks: imx8mp: Rename audiomix ids clocks to audio_blk_ctrl

2020-07-30 Thread Abel Vesa
On 20-07-29 12:47:26, Stephen Boyd wrote: > Quoting Abel Vesa (2020-07-29 05:07:47) > > In the reference manual the actual name is Audio BLK_CTRL. > > Lets make it more obvious here by renaming from audiomix to audio_blk_ctrl. > > And this is safe because there aren't any users of the defines? Ye

Re: [PATCH 10/17] Documentation: bindings: clk: Add bindings for i.MX BLK_CTRL

2020-07-30 Thread Abel Vesa
On 20-07-29 12:49:41, Stephen Boyd wrote: > Quoting Abel Vesa (2020-07-29 05:07:56) > > diff --git a/Documentation/devicetree/bindings/clock/fsl,imx-blk-ctrl.yaml > > b/Documentation/devicetree/bindings/clock/fsl,imx-blk-ctrl.yaml > > new file mode 100644 > > index ..036d3d3 > > --- /dev/n

Re: [PATCH] Revert "Bluetooth: btusb: Disable runtime suspend on Realtek devices"

2020-07-30 Thread Marcel Holtmann
Hi Kai-Heng, >> On Jul 30, 2020, at 07:17, Abhishek Pandit-Subedi >> wrote: >> >> This reverts commit 7ecacafc240638148567742cca41aa7144b4fe1e. >> >> Testing this change on a board with RTL8822CE, I found that enabling >> autosuspend has no effect on the stability of the system. The board >> c

Re: [PATCH v2 stable-5.4.y] Revert "dpaa_eth: fix usage as DSA master, try 3"

2020-07-30 Thread Greg KH
On Wed, Jun 24, 2020 at 03:45:17PM +0300, Vladimir Oltean wrote: > From: Vladimir Oltean > > This reverts commit 40a904b1c2e57b22dd002dfce73688871cb0bac8. > > The patch is not wrong, but the Fixes: tag is. It should have been: > > Fixes: 060ad66f9795 ("dpaa_eth: change DMA device") > > w

[PATCH net] net: gemini: Fix missing clk_disable_unprepare() in error path of gemini_ethernet_port_probe()

2020-07-30 Thread Wang Hai
Fix the missing clk_disable_unprepare() before return from gemini_ethernet_port_probe() in the error handling case. Fixes: 4d5ae32f5e1e ("net: ethernet: Add a driver for Gemini gigabit ethernet") Reported-by: Hulk Robot Signed-off-by: Wang Hai --- drivers/net/ethernet/cortina/gemini.c | 5 -

Re: [PATCH v2] checkpatch: Fix the usage of capture group ( ... )

2020-07-30 Thread Joe Perches
On Thu, 2020-07-30 at 07:58 +0200, Lukas Bulwahn wrote: > Hi Joe, > > did you see this quick fix to checkpatch.pl? Can you comment on the > commit and can we get a quick ack on that fix, please? Yes, in a bit. > General question on patches for ./scripts/checkpatch.pl: > How do they travel to Li

[PATCH] ACPI / APEI: do memory failure on the physical address reported by ARM processor error section

2020-07-30 Thread Xiaofei Tan
After the following commit applied, user-mode SEA is preferentially processed by APEI. Do memory failure to recover. But there are some problems: 1) The function apei_claim_sea() has processed an CPER, does not mean that memory failure handling has done. Because the firmware-first RAS error is rep

Re: [PATCH] s390/test_unwind: fix possible memleak in test_unwind()

2020-07-30 Thread Ilya Leoshkevich
On Thu, 2020-07-30 at 14:36 +0800, Wang Hai wrote: > test_unwind() misses to call kfree(bt) in an error path. > Add the missed function call to fix it. > > Fixes: 0610154650f1 ("s390/test_unwind: print verbose unwinding > results") > Reported-by: Hulk Robot > Signed-off-by: Wang Hai > --- > arc

[PATCH v2] drivers/net/wan/lapbether: Use needed_headroom instead of hard_header_len

2020-07-30 Thread Xie He
In net/packet/af_packet.c, the function packet_snd first reserves a headroom of length (dev->hard_header_len + dev->needed_headroom). Then if the socket is a SOCK_DGRAM socket, it calls dev_hard_header, which calls dev->header_ops->create, to create the link layer header. If the socket is a SOCK_RA

Re: [PATCH] vgacon: fix out of bounds write to the scrollback buffer

2020-07-30 Thread Jiri Slaby
On 30. 07. 20, 8:46, Jiri Slaby wrote: > Hi, OTOH, you should have CCed all the (public) lists. > > On 30. 07. 20, 4:50, 张云海 wrote: >> Zhang Xiao points out that the check should use > instead of >=, >> otherwise the last line will be skip. >> I agree with that, so I modify the patch. >> Could you

[PATCH net] wl1251: fix always return 0 error

2020-07-30 Thread Wang Hai
wl1251_event_ps_report() should not always return 0 because wl1251_ps_set_mode() may fail. Change it to return 'ret'. Fixes: f7ad1eed4d4b ("wl1251: retry power save entry") Reported-by: Hulk Robot Signed-off-by: Wang Hai --- drivers/net/wireless/ti/wl1251/event.c | 2 +- 1 file changed, 1 inser

Re: [PATCH 0/2] locking/qspinlock: Break qspinlock_types.h header loop

2020-07-30 Thread Andy Shevchenko
On Thu, Jul 30, 2020 at 4:00 AM Herbert Xu wrote: > > On Wed, Jul 29, 2020 at 06:04:57PM +0300, Andy Shevchenko wrote: > > On Wed, Jul 29, 2020 at 4:35 PM Waiman Long wrote: > > > On 7/29/20 8:28 AM, Herbert Xu wrote: > > > > ... > > > > > This patch series looks good to me. I just wonder if we s

Re: [PATCH 0/2] locking/qspinlock: Break qspinlock_types.h header loop

2020-07-30 Thread Herbert Xu
On Thu, Jul 30, 2020 at 10:47:16AM +0300, Andy Shevchenko wrote: > > We may ask Synopsys folks to look at this as well. > Vineet, any ideas if we may unify ATOMIC64_INIT() across the architectures? I don't think there is any technical difficulty. The custom atomic64_t simply adds an alignment req

linux-next: build failure after merge of the vhost tree

2020-07-30 Thread Stephen Rothwell
Hi all, After merging the vhost tree, today's linux-next build (x86_64 allmodconfig) failed like this: drivers/virtio/virtio_vdpa.c: In function 'virtio_vdpa_get': drivers/virtio/virtio_vdpa.c:60:32: warning: unused variable 'ops' [-Wunused-variable] 60 | const struct vdpa_config_ops *ops =

Re: [PATCH 0/2] locking/qspinlock: Break qspinlock_types.h header loop

2020-07-30 Thread Andy Shevchenko
On Thu, Jul 30, 2020 at 10:51 AM Herbert Xu wrote: > On Thu, Jul 30, 2020 at 10:47:16AM +0300, Andy Shevchenko wrote: > > > > We may ask Synopsys folks to look at this as well. > > Vineet, any ideas if we may unify ATOMIC64_INIT() across the architectures? > > I don't think there is any technical

Re: [PATCH 1/1] x86/tsr: Fix tsc frequency enumeration failure on lightning mountain SoC

2020-07-30 Thread Andy Shevchenko
On Thu, Jul 30, 2020 at 9:16 AM Dilip Kota wrote: > > Frequency descriptor of Lightning Mountain SoC doesn't have all the > frequency entries so resulting in the below failure causing kernel hang. > > [0.00] Error MSR_FSB_FREQ index 15 is unknown > [0.00] tsc: Fast TSC calibration

Re: [PATCH v2] scsi: ufs: Fix possible infinite loop in ufshcd_hold

2020-07-30 Thread Stanley Chu
Hi Can, On Wed, 2020-07-29 at 18:53 +0800, Can Guo wrote: > Hi Stanley, > > On 2020-07-29 18:26, Stanley Chu wrote: > > Hi Can, > > > > On Wed, 2020-07-29 at 16:43 +0800, Can Guo wrote: > >> Hi Stanley, > >> > >> On 2020-07-29 10:40, Stanley Chu wrote: > >> > In ufshcd_suspend(), after clk-gati

[RFC PATCH 3/3] opp: Power on (virtual) power domains managed by the OPP core

2020-07-30 Thread Stephan Gerhold
dev_pm_opp_attach_genpd() allows attaching an arbitrary number of power domains to an OPP table. In that case, the genpd core will create a virtual device for each of the power domains. At the moment, the OPP core only calls dev_pm_genpd_set_performance_state() on these virtual devices. It does no

[RFC PATCH 1/3] opp: Reduce code duplication in _set_required_opps()

2020-07-30 Thread Stephan Gerhold
Move call to dev_pm_genpd_set_performance_state() to a separate function so we can avoid duplicating the code for the single and multiple genpd case. Signed-off-by: Stephan Gerhold --- drivers/opp/core.c | 40 +--- 1 file changed, 21 insertions(+), 19 deletion

RE: [PATCH 2/2] ASoC: Intel: Add period size constraint on strago board

2020-07-30 Thread Lu, Brent
> > Is this patch required if you've already constrained the period sizes for the > platform driver in patch1? Yes or alsa will select 320 as default period size for it. Regards, Brent

Re: [PATCH v2] drivers/net/wan/lapbether: Use needed_headroom instead of hard_header_len

2020-07-30 Thread Xie He
Hi Martin, I'm currently working on a plan to make all X.25 drivers (lapbether.c, x25_asy.c, hdlc_x25.c) to set dev->hard_header_len / dev->needed_headroom correctly. So that upper layers no longer need to guess how much headroom a X.25 device needs with a constant value (as they currently do). A

Re: [PATCH] selinux: add tracepoint on denials

2020-07-30 Thread peter enderborg
On 7/28/20 6:02 PM, Thiébaud Weksteen wrote: > On Tue, Jul 28, 2020 at 5:12 PM Paul Moore wrote: >> Perhaps it would be helpful if you provided an example of how one >> would be expected to use this new tracepoint? That would help put >> things in the proper perspective. > The best example is the

[PATCH 5.7 12/20] tcp: allow at most one TLP probe per flight

2020-07-30 Thread Greg Kroah-Hartman
From: Yuchung Cheng [ Upstream commit 76be93fc0702322179bb0ea87295d820ee46ad14 ] Previously TLP may send multiple probes of new data in one flight. This happens when the sender is cwnd limited. After the initial TLP containing new data is sent, the sender receives another ACK that acks partial i

[PATCH 5.7 11/20] rxrpc: Fix sendmsg() returning EPIPE due to recvmsg() returning ENODATA

2020-07-30 Thread Greg Kroah-Hartman
From: David Howells [ Upstream commit 639f181f0ee20d3249dbc55f740f0167267180f0 ] rxrpc_sendmsg() returns EPIPE if there's an outstanding error, such as if rxrpc_recvmsg() indicating ENODATA if there's nothing for it to read. Change rxrpc_recvmsg() to return EAGAIN instead if there's nothing to

[PATCH 5.7 14/20] sctp: shrink stream outq only when new outcnt < old outcnt

2020-07-30 Thread Greg Kroah-Hartman
From: Xin Long [ Upstream commit 8f13399db22f909a35735bf8ae2f932e0c8f0e30 ] It's not necessary to go list_for_each for outq->out_chunk_list when new outcnt >= old outcnt, as no chunk with higher sid than new (outcnt - 1) exists in the outqueue. While at it, also move the list_for_each code in a

[PATCH 5.7 10/20] rtnetlink: Fix memory(net_device) leak when ->newlink fails

2020-07-30 Thread Greg Kroah-Hartman
From: Weilong Chen [ Upstream commit cebb69754f37d68e1355a5e726fdac317bcda302 ] When vlan_newlink call register_vlan_dev fails, it might return error with dev->reg_state = NETREG_UNREGISTERED. The rtnl_newlink should free the memory. But currently rtnl_newlink only free the memory which state is

[PATCH 5.7 13/20] AX.25: Prevent integer overflows in connect and sendmsg

2020-07-30 Thread Greg Kroah-Hartman
From: Dan Carpenter [ Upstream commit 17ad73e941b71f3bec7523ea4e9cbc3752461c2d ] We recently added some bounds checking in ax25_connect() and ax25_sendmsg() and we so we removed the AX25_MAX_DIGIS checks because they were no longer required. Unfortunately, I believe they are required to prevent

[PATCH 5.7 15/20] sctp: shrink stream outq when fails to do addstream reconf

2020-07-30 Thread Greg Kroah-Hartman
From: Xin Long [ Upstream commit 3ecdda3e9ad837cf9cb41b6faa11b1af3a5abc0c ] When adding a stream with stream reconf, the new stream firstly is in CLOSED state but new out chunks can still be enqueued. Then once gets the confirmation from the peer, the state will change to OPEN. However, if the

[PATCH 5.7 03/20] dev: Defer free of skbs in flush_backlog

2020-07-30 Thread Greg Kroah-Hartman
From: Subash Abhinov Kasiviswanathan [ Upstream commit 7df5cb75cfb8acf96c7f2342530eb41e0c11f4c3 ] IRQs are disabled when freeing skbs in input queue. Use the IRQ safe variant to free skbs here. Fixes: 145dd5f9c88f ("net: flush the softnet backlog in process context") Signed-off-by: Subash Abhin

[PATCH 5.7 07/20] net-sysfs: add a newline when printing tx_timeout by sysfs

2020-07-30 Thread Greg Kroah-Hartman
From: Xiongfeng Wang [ Upstream commit 9bb5fbea59f36a589ef886292549ca4052fe676c ] When I cat 'tx_timeout' by sysfs, it displays as follows. It's better to add a newline for easy reading. root@syzkaller:~# cat /sys/devices/virtual/net/lo/queues/tx-0/tx_timeout 0root@syzkaller:~# Signed-off-by:

[PATCH 5.4 13/19] sctp: shrink stream outq only when new outcnt < old outcnt

2020-07-30 Thread Greg Kroah-Hartman
From: Xin Long [ Upstream commit 8f13399db22f909a35735bf8ae2f932e0c8f0e30 ] It's not necessary to go list_for_each for outq->out_chunk_list when new outcnt >= old outcnt, as no chunk with higher sid than new (outcnt - 1) exists in the outqueue. While at it, also move the list_for_each code in a

[PATCH 5.4 10/19] rxrpc: Fix sendmsg() returning EPIPE due to recvmsg() returning ENODATA

2020-07-30 Thread Greg Kroah-Hartman
From: David Howells [ Upstream commit 639f181f0ee20d3249dbc55f740f0167267180f0 ] rxrpc_sendmsg() returns EPIPE if there's an outstanding error, such as if rxrpc_recvmsg() indicating ENODATA if there's nothing for it to read. Change rxrpc_recvmsg() to return EAGAIN instead if there's nothing to

[PATCH 5.4 12/19] AX.25: Prevent integer overflows in connect and sendmsg

2020-07-30 Thread Greg Kroah-Hartman
From: Dan Carpenter [ Upstream commit 17ad73e941b71f3bec7523ea4e9cbc3752461c2d ] We recently added some bounds checking in ax25_connect() and ax25_sendmsg() and we so we removed the AX25_MAX_DIGIS checks because they were no longer required. Unfortunately, I believe they are required to prevent

[PATCH 5.4 04/19] drivers/net/wan/x25_asy: Fix to make it work

2020-07-30 Thread Greg Kroah-Hartman
From: Xie He [ Upstream commit 8fdcabeac39824fe67480fd9508d80161c541854 ] This driver is not working because of problems of its receiving code. This patch fixes it to make it work. When the driver receives an LAPB frame, it should first pass the frame to the LAPB module to process. After proces

[PATCH 5.4 05/19] ip6_gre: fix null-ptr-deref in ip6gre_init_net()

2020-07-30 Thread Greg Kroah-Hartman
From: Wei Yongjun [ Upstream commit 46ef5b89ec0ecf290d74c4aee844f063933c4da4 ] KASAN report null-ptr-deref error when register_netdev() failed: KASAN: null-ptr-deref in range [0x03c0-0x03c7] CPU: 2 PID: 422 Comm: ip Not tainted 5.8.0-rc4+ #12 Call Trace: ip6gre_init_net

[PATCH 5.7 04/20] drivers/net/wan/x25_asy: Fix to make it work

2020-07-30 Thread Greg Kroah-Hartman
From: Xie He [ Upstream commit 8fdcabeac39824fe67480fd9508d80161c541854 ] This driver is not working because of problems of its receiving code. This patch fixes it to make it work. When the driver receives an LAPB frame, it should first pass the frame to the LAPB module to process. After proces

[PATCH 5.4 02/19] AX.25: Prevent out-of-bounds read in ax25_sendmsg()

2020-07-30 Thread Greg Kroah-Hartman
From: Peilin Ye [ Upstream commit 8885bb0621f01a6c82be60a91e5fc0f6e2f71186 ] Checks on `addr_len` and `usax->sax25_ndigis` are insufficient. ax25_sendmsg() can go out of bounds when `usax->sax25_ndigis` equals to 7 or 8. Fix it. It is safe to remove `usax->sax25_ndigis > AX25_MAX_DIGIS`, since

[PATCH] thermal: mediatek: Fix missing selection

2020-07-30 Thread Henry Yen
Mediatek thermal driver is compatible with multiple platforms. Some of the platforms (e.g., MT2701) requires to enable MEDIATEK_MT6577_AUXADC option. If lacks the config, the driver will not be able to read correct temperature. To fix it, select missing MEDIATEK_MT6577_AUXADC config. Signed-off-b

Re: [PATCH] MAINTAINERS: Include drivers subdirs for ARM PMU PROFILING AND DEBUGGING entry

2020-07-30 Thread John Garry
On 17/06/2020 12:17, John Garry wrote: Ensure that the ARM PMU PROFILING AND DEBUGGING maintainers are included for the HiSilicon PMU driver. Just a reminder in case this minor patch was missed... Signed-off-by: John Garry diff --git a/MAINTAINERS b/MAINTAINERS index 68f21d46614c..24f377f1

[PATCH 5.4 17/19] regmap: debugfs: check count when read regmap file

2020-07-30 Thread Greg Kroah-Hartman
From: Peng Fan commit 74edd08a4fbf51d65fd8f4c7d8289cd0f392bd91 upstream. When executing the following command, we met kernel dump. dmesg -c > /dev/null; cd /sys; for i in `ls /sys/kernel/debug/regmap/* -d`; do echo "Checking regmap in $i"; cat $i/registers; done && grep -ri "0x02

[PATCH 5.4 03/19] dev: Defer free of skbs in flush_backlog

2020-07-30 Thread Greg Kroah-Hartman
From: Subash Abhinov Kasiviswanathan [ Upstream commit 7df5cb75cfb8acf96c7f2342530eb41e0c11f4c3 ] IRQs are disabled when freeing skbs in input queue. Use the IRQ safe variant to free skbs here. Fixes: 145dd5f9c88f ("net: flush the softnet backlog in process context") Signed-off-by: Subash Abhin

[PATCH 5.4 15/19] udp: Copy has_conns in reuseport_grow().

2020-07-30 Thread Greg Kroah-Hartman
From: Kuniyuki Iwashima [ Upstream commit f2b2c55e512879a05456eaf5de4d1ed2f7757509 ] If an unconnected socket in a UDP reuseport group connect()s, has_conns is set to 1. Then, when a packet is received, udp[46]_lib_lookup2() scans all sockets in udp_hslot looking for the connected socket with th

[PATCH 4.19 01/17] AX.25: Fix out-of-bounds read in ax25_connect()

2020-07-30 Thread Greg Kroah-Hartman
From: Peilin Ye [ Upstream commit 2f2a7ffad5c6cbf3d438e813cfdc88230e185ba6 ] Checks on `addr_len` and `fsa->fsa_ax25.sax25_ndigis` are insufficient. ax25_connect() can go out of bounds when `fsa->fsa_ax25.sax25_ndigis` equals to 7 or 8. Fix it. This issue has been reported as a KMSAN uninit-val

[PATCH 5.4 16/19] udp: Improve load balancing for SO_REUSEPORT.

2020-07-30 Thread Greg Kroah-Hartman
From: Kuniyuki Iwashima [ Upstream commit efc6b6f6c3113e8b203b9debfb72d81e0f3dcace ] Currently, SO_REUSEPORT does not work well if connected sockets are in a UDP reuseport group. Then reuseport_has_conns() returns true and the result of reuseport_select_sock() is discarded. Also, unconnected so

[PATCH 5.4 07/19] net: udp: Fix wrong clean up for IS_UDPLITE macro

2020-07-30 Thread Greg Kroah-Hartman
From: Miaohe Lin [ Upstream commit b0a422772fec29811e293c7c0e6f991c0fd9241d ] We can't use IS_UDPLITE to replace udp_sk->pcflag when UDPLITE_RECV_CC is checked. Fixes: b2bf1e2659b1 ("[UDP]: Clean up for IS_UDPLITE macro") Signed-off-by: Miaohe Lin Signed-off-by: David S. Miller Signed-off-by:

[PATCH 5.4 18/19] PM: wakeup: Show statistics for deleted wakeup sources again

2020-07-30 Thread Greg Kroah-Hartman
From: zhuguangqing commit e976eb4b91e906f20ec25b20c152d53c472fc3fd upstream. After commit 00ee22c28915 (PM / wakeup: Use seq_open() to show wakeup stats), print_wakeup_source_stats(m, &deleted_ws) is not called from wakeup_sources_stats_seq_show() any more. Because deleted_ws is one of the wake

[PATCH 5.4 19/19] Revert "dpaa_eth: fix usage as DSA master, try 3"

2020-07-30 Thread Greg Kroah-Hartman
From: Vladimir Oltean This reverts commit 40a904b1c2e57b22dd002dfce73688871cb0bac8. The patch is not wrong, but the Fixes: tag is. It should have been: Fixes: 060ad66f9795 ("dpaa_eth: change DMA device") which means that it's fixing a commit which was introduced in: git tag --contai

[PATCH 4.19 03/17] dev: Defer free of skbs in flush_backlog

2020-07-30 Thread Greg Kroah-Hartman
From: Subash Abhinov Kasiviswanathan [ Upstream commit 7df5cb75cfb8acf96c7f2342530eb41e0c11f4c3 ] IRQs are disabled when freeing skbs in input queue. Use the IRQ safe variant to free skbs here. Fixes: 145dd5f9c88f ("net: flush the softnet backlog in process context") Signed-off-by: Subash Abhin

Re: [PATCH] scsi: sd: add runtime pm to open / release

2020-07-30 Thread Martin Kepplinger
On 29.06.20 18:15, Alan Stern wrote: > On Mon, Jun 29, 2020 at 11:42:59AM +0200, Martin Kepplinger wrote: >> >> >> On 26.06.20 17:44, Alan Stern wrote: >>> Martin's best approach would be to add some debugging code to find out why >>> blk_queue_enter() isn't calling bkl_pm_request_resume(), or why

[PATCH 5.4 09/19] rtnetlink: Fix memory(net_device) leak when ->newlink fails

2020-07-30 Thread Greg Kroah-Hartman
From: Weilong Chen [ Upstream commit cebb69754f37d68e1355a5e726fdac317bcda302 ] When vlan_newlink call register_vlan_dev fails, it might return error with dev->reg_state = NETREG_UNREGISTERED. The rtnl_newlink should free the memory. But currently rtnl_newlink only free the memory which state is

[PATCH 4.19 02/17] AX.25: Prevent out-of-bounds read in ax25_sendmsg()

2020-07-30 Thread Greg Kroah-Hartman
From: Peilin Ye [ Upstream commit 8885bb0621f01a6c82be60a91e5fc0f6e2f71186 ] Checks on `addr_len` and `usax->sax25_ndigis` are insufficient. ax25_sendmsg() can go out of bounds when `usax->sax25_ndigis` equals to 7 or 8. Fix it. It is safe to remove `usax->sax25_ndigis > AX25_MAX_DIGIS`, since

[PATCH 5.4 06/19] net-sysfs: add a newline when printing tx_timeout by sysfs

2020-07-30 Thread Greg Kroah-Hartman
From: Xiongfeng Wang [ Upstream commit 9bb5fbea59f36a589ef886292549ca4052fe676c ] When I cat 'tx_timeout' by sysfs, it displays as follows. It's better to add a newline for easy reading. root@syzkaller:~# cat /sys/devices/virtual/net/lo/queues/tx-0/tx_timeout 0root@syzkaller:~# Signed-off-by:

[PATCH 5.4 00/19] 5.4.55-rc1 review

2020-07-30 Thread Greg Kroah-Hartman
This is the start of the stable review cycle for the 5.4.55 release. There are 19 patches in this series, all will be posted as a response to this one. If anyone has any issues with these being applied, please let me know. Responses should be made by Sat, 01 Aug 2020 07:44:05 +. Anything rece

[PATCH 4.19 08/17] qrtr: orphan socket in qrtr_release()

2020-07-30 Thread Greg Kroah-Hartman
From: Cong Wang [ Upstream commit af9f691f0f5bdd1ade65a7b84927639882d7c3e5 ] We have to detach sock from socket in qrtr_release(), otherwise skb->sk may still reference to this socket when the skb is released in tun->queue, particularly sk->sk_wq still points to &sock->wq, which leads to a UAF.

[PATCH 4.19 09/17] rxrpc: Fix sendmsg() returning EPIPE due to recvmsg() returning ENODATA

2020-07-30 Thread Greg Kroah-Hartman
From: David Howells [ Upstream commit 639f181f0ee20d3249dbc55f740f0167267180f0 ] rxrpc_sendmsg() returns EPIPE if there's an outstanding error, such as if rxrpc_recvmsg() indicating ENODATA if there's nothing for it to read. Change rxrpc_recvmsg() to return EAGAIN instead if there's nothing to

[PATCH 4.19 16/17] rtnetlink: Fix memory(net_device) leak when ->newlink fails

2020-07-30 Thread Greg Kroah-Hartman
From: Weilong Chen [ Upstream commit cebb69754f37d68e1355a5e726fdac317bcda302 ] When vlan_newlink call register_vlan_dev fails, it might return error with dev->reg_state = NETREG_UNREGISTERED. The rtnl_newlink should free the memory. But currently rtnl_newlink only free the memory which state is

[PATCH 4.19 10/17] tcp: allow at most one TLP probe per flight

2020-07-30 Thread Greg Kroah-Hartman
From: Yuchung Cheng [ Upstream commit 76be93fc0702322179bb0ea87295d820ee46ad14 ] Previously TLP may send multiple probes of new data in one flight. This happens when the sender is cwnd limited. After the initial TLP containing new data is sent, the sender receives another ACK that acks partial i

[PATCH 4.19 15/17] udp: Improve load balancing for SO_REUSEPORT.

2020-07-30 Thread Greg Kroah-Hartman
From: Kuniyuki Iwashima [ Upstream commit efc6b6f6c3113e8b203b9debfb72d81e0f3dcace ] Currently, SO_REUSEPORT does not work well if connected sockets are in a UDP reuseport group. Then reuseport_has_conns() returns true and the result of reuseport_select_sock() is discarded. Also, unconnected so

[PATCH 4.19 11/17] AX.25: Prevent integer overflows in connect and sendmsg

2020-07-30 Thread Greg Kroah-Hartman
From: Dan Carpenter [ Upstream commit 17ad73e941b71f3bec7523ea4e9cbc3752461c2d ] We recently added some bounds checking in ax25_connect() and ax25_sendmsg() and we so we removed the AX25_MAX_DIGIS checks because they were no longer required. Unfortunately, I believe they are required to prevent

[PATCH 4.14 01/14] AX.25: Fix out-of-bounds read in ax25_connect()

2020-07-30 Thread Greg Kroah-Hartman
From: Peilin Ye [ Upstream commit 2f2a7ffad5c6cbf3d438e813cfdc88230e185ba6 ] Checks on `addr_len` and `fsa->fsa_ax25.sax25_ndigis` are insufficient. ax25_connect() can go out of bounds when `fsa->fsa_ax25.sax25_ndigis` equals to 7 or 8. Fix it. This issue has been reported as a KMSAN uninit-val

[PATCH 4.19 12/17] sctp: shrink stream outq only when new outcnt < old outcnt

2020-07-30 Thread Greg Kroah-Hartman
From: Xin Long [ Upstream commit 8f13399db22f909a35735bf8ae2f932e0c8f0e30 ] It's not necessary to go list_for_each for outq->out_chunk_list when new outcnt >= old outcnt, as no chunk with higher sid than new (outcnt - 1) exists in the outqueue. While at it, also move the list_for_each code in a

[PATCH 4.19 17/17] regmap: debugfs: check count when read regmap file

2020-07-30 Thread Greg Kroah-Hartman
From: Peng Fan commit 74edd08a4fbf51d65fd8f4c7d8289cd0f392bd91 upstream. When executing the following command, we met kernel dump. dmesg -c > /dev/null; cd /sys; for i in `ls /sys/kernel/debug/regmap/* -d`; do echo "Checking regmap in $i"; cat $i/registers; done && grep -ri "0x02

[PATCH 4.9 09/61] SUNRPC reverting d03727b248d0 ("NFSv4 fix CLOSE not waiting for direct IO compeletion")

2020-07-30 Thread Greg Kroah-Hartman
From: Olga Kornievskaia commit 65caafd0d2145d1dd02072c4ced540624daeab40 upstream. Reverting commit d03727b248d0 "NFSv4 fix CLOSE not waiting for direct IO compeletion". This patch made it so that fput() by calling inode_dio_done() in nfs_file_release() would wait uninterruptably for any outstand

[PATCH 4.9 08/61] drm/nouveau/i2c/g94-: increase NV_PMGR_DP_AUXCTL_TRANSACTREQ timeout

2020-07-30 Thread Greg Kroah-Hartman
From: Ben Skeggs [ Upstream commit 0156e76d388310a490aeb0f2fbb5b284ded3aecc ] Tegra TRM says worst-case reply time is 1216us, and this should fix some spurious timeouts that have been popping up. Signed-off-by: Ben Skeggs Signed-off-by: Sasha Levin --- drivers/gpu/drm/nouveau/nvkm/subdev/i2c

[PATCH 4.9 02/61] mac80211: allow rx of mesh eapol frames with default rx key

2020-07-30 Thread Greg Kroah-Hartman
From: Markus Theil [ Upstream commit 0b467b63870d9c05c81456aa9bfee894ab2db3b6 ] Without this patch, eapol frames cannot be received in mesh mode, when 802.1X should be used. Initially only a MGTK is defined, which is found and set as rx->key, when there are no other keys set. ieee80211_drop_unen

[PATCH 4.9 06/61] drivers/net/wan/lapbether: Fixed the value of hard_header_len

2020-07-30 Thread Greg Kroah-Hartman
From: Xie He [ Upstream commit 9dc829a135fb5927f1519de11286e2bbb79f5b66 ] When this driver transmits data, first this driver will remove a pseudo header of 1 byte, then the lapb module will prepend the LAPB header of 2 or 3 bytes, then this driver will prepend a length field of 2 bytes,

[PATCH 4.9 01/61] pinctrl: amd: fix npins for uart0 in kerncz_groups

2020-07-30 Thread Greg Kroah-Hartman
From: Jacky Hu [ Upstream commit 69339d083dfb7786b0e0b3fc19eaddcf11fabdfb ] uart0_pins is defined as: static const unsigned uart0_pins[] = {135, 136, 137, 138, 139}; which npins is wronly specified as 9 later { .name = "uart0", .pins = uart0_pins,

[PATCH 4.9 24/61] regmap: dev_get_regmap_match(): fix string comparison

2020-07-30 Thread Greg Kroah-Hartman
From: Marc Kleine-Budde [ Upstream commit e84861fec32dee8a2e62bbaa52cded6b05a2a456 ] This function is used by dev_get_regmap() to retrieve a regmap for the specified device. If the device has more than one regmap, the name parameter can be used to specify one. The code here uses a pointer compa

[PATCH 4.14 09/14] ip6_gre: fix null-ptr-deref in ip6gre_init_net()

2020-07-30 Thread Greg Kroah-Hartman
From: Wei Yongjun [ Upstream commit 46ef5b89ec0ecf290d74c4aee844f063933c4da4 ] KASAN report null-ptr-deref error when register_netdev() failed: KASAN: null-ptr-deref in range [0x03c0-0x03c7] CPU: 2 PID: 422 Comm: ip Not tainted 5.8.0-rc4+ #12 Call Trace: ip6gre_init_net

[PATCH 4.14 11/14] tcp: allow at most one TLP probe per flight

2020-07-30 Thread Greg Kroah-Hartman
From: Yuchung Cheng [ Upstream commit 76be93fc0702322179bb0ea87295d820ee46ad14 ] Previously TLP may send multiple probes of new data in one flight. This happens when the sender is cwnd limited. After the initial TLP containing new data is sent, the sender receives another ACK that acks partial i

[PATCH 4.14 00/14] 4.14.191-rc1 review

2020-07-30 Thread Greg Kroah-Hartman
This is the start of the stable review cycle for the 4.14.191 release. There are 14 patches in this series, all will be posted as a response to this one. If anyone has any issues with these being applied, please let me know. Responses should be made by Sat, 01 Aug 2020 07:44:05 +. Anything re

[PATCH 4.14 08/14] AX.25: Prevent integer overflows in connect and sendmsg

2020-07-30 Thread Greg Kroah-Hartman
From: Dan Carpenter [ Upstream commit 17ad73e941b71f3bec7523ea4e9cbc3752461c2d ] We recently added some bounds checking in ax25_connect() and ax25_sendmsg() and we so we removed the AX25_MAX_DIGIS checks because they were no longer required. Unfortunately, I believe they are required to prevent

[PATCH 4.14 10/14] rtnetlink: Fix memory(net_device) leak when ->newlink fails

2020-07-30 Thread Greg Kroah-Hartman
From: Weilong Chen [ Upstream commit cebb69754f37d68e1355a5e726fdac317bcda302 ] When vlan_newlink call register_vlan_dev fails, it might return error with dev->reg_state = NETREG_UNREGISTERED. The rtnl_newlink should free the memory. But currently rtnl_newlink only free the memory which state is

[PATCH 4.14 06/14] net: udp: Fix wrong clean up for IS_UDPLITE macro

2020-07-30 Thread Greg Kroah-Hartman
From: Miaohe Lin [ Upstream commit b0a422772fec29811e293c7c0e6f991c0fd9241d ] We can't use IS_UDPLITE to replace udp_sk->pcflag when UDPLITE_RECV_CC is checked. Fixes: b2bf1e2659b1 ("[UDP]: Clean up for IS_UDPLITE macro") Signed-off-by: Miaohe Lin Signed-off-by: David S. Miller Signed-off-by:

[PATCH 4.9 07/61] net: sky2: initialize return of gm_phy_read

2020-07-30 Thread Greg Kroah-Hartman
From: Tom Rix [ Upstream commit 28b18e4eb515af7c6661c3995c6e3c34412c2874 ] clang static analysis flags this garbage return drivers/net/ethernet/marvell/sky2.c:208:2: warning: Undefined or garbage value returned to caller [core.uninitialized.UndefReturn] return v; ^~~~ stat

[PATCH 4.9 03/61] scsi: scsi_transport_spi: Fix function pointer check

2020-07-30 Thread Greg Kroah-Hartman
From: Tom Rix [ Upstream commit 5aee52c44d9170591df65fafa1cd408acc1225ce ] clang static analysis flags several null function pointer problems. drivers/scsi/scsi_transport_spi.c:374:1: warning: Called function pointer is null (null dereference) [core.CallAndMessage] spi_transport_max_attr(offse

[PATCH 4.14 13/14] regmap: debugfs: check count when read regmap file

2020-07-30 Thread Greg Kroah-Hartman
From: Peng Fan commit 74edd08a4fbf51d65fd8f4c7d8289cd0f392bd91 upstream. When executing the following command, we met kernel dump. dmesg -c > /dev/null; cd /sys; for i in `ls /sys/kernel/debug/regmap/* -d`; do echo "Checking regmap in $i"; cat $i/registers; done && grep -ri "0x02

[PATCH 4.9 29/61] usb: xhci-mtk: fix the failure of bandwidth allocation

2020-07-30 Thread Greg Kroah-Hartman
From: Chunfeng Yun commit 5ce1a24dd98c00a57a8fa13660648abf7e08e3ef upstream. The wMaxPacketSize field of endpoint descriptor may be zero as default value in alternate interface, and they are not actually selected when start stream, so skip them when try to allocate bandwidth. Cc: stable Fixes:

[PATCH 4.9 45/61] ath9k: Fix regression with Atheros 9271

2020-07-30 Thread Greg Kroah-Hartman
From: Mark O'Donovan commit 92f53e2fda8bb9a559ad61d57bfb397ce67ed0ab upstream. This fix allows ath9k_htc modules to connect to WLAN once again. Fixes: 2bbcaaee1fcb ("ath9k: Fix general protection fault in ath9k_hif_usb_rx_cb") Link: https://bugzilla.kernel.org/show_bug.cgi?id=208251 Signed-off

[PATCH 4.9 33/61] staging: comedi: addi_apci_1032: check INSN_CONFIG_DIGITAL_TRIG shift

2020-07-30 Thread Greg Kroah-Hartman
From: Ian Abbott commit 0bd0db42a030b75c20028c7ba6e327b9cb554116 upstream. The `INSN_CONFIG` comedi instruction with sub-instruction code `INSN_CONFIG_DIGITAL_TRIG` includes a base channel in `data[3]`. This is used as a right shift amount for other bitmask values without being checked. Shift a

[PATCH 4.9 16/61] hippi: Fix a size used in a pci_free_consistent() in an error handling path

2020-07-30 Thread Greg Kroah-Hartman
From: Christophe JAILLET [ Upstream commit 3195c4706b00106aa82c73acd28340fa8fc2bfc1 ] The size used when calling 'pci_alloc_consistent()' and 'pci_free_consistent()' should match. Fix it and have it consistent with the corresponding call in 'rr_close()'. Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2"

[PATCH 4.9 30/61] usb: xhci: Fix ASM2142/ASM3142 DMA addressing

2020-07-30 Thread Greg Kroah-Hartman
From: Forest Crossman commit dbb0897e805f2ab1b8bc358f6c3d878a376b8897 upstream. The ASM2142/ASM3142 (same PCI IDs) does not support full 64-bit DMA addresses, which can cause silent memory corruption or IOMMU errors on platforms that use the upper bits. Add the XHCI_NO_64BIT_SUPPORT quirk to fix

  1   2   3   4   5   6   7   8   9   10   >