Commit graph

905,622 commits

Author SHA1 Message Date
Takashi Iwai
01c19aa890 UPSTREAM: ALSA: usb-audio: Fix out of bounds reads when finding clock sources
commit a3dd4d63eeb452cfb064a13862fb376ab108f6a6 upstream.

The current USB-audio driver code doesn't check bLength of each
descriptor at traversing for clock descriptors.  That is, when a
device provides a bogus descriptor with a shorter bLength, the driver
might hit out-of-bounds reads.

For addressing it, this patch adds sanity checks to the validator
functions for the clock descriptor traversal.  When the descriptor
length is shorter than expected, it's skipped in the loop.

For the clock source and clock multiplier descriptors, we can just
check bLength against the sizeof() of each descriptor type.
OTOH, the clock selector descriptor of UAC2 and UAC3 has an array
of bNrInPins elements and two more fields at its tail, hence those
have to be checked in addition to the sizeof() check.

Bug: 382239029
Reported-by: Benoît Sevens <bsevens@google.com>
Cc: <stable@vger.kernel.org>
Link: https://lore.kernel.org/20241121140613.3651-1-bsevens@google.com
Link: https://patch.msgid.link/20241125144629.20757-1-tiwai@suse.de
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Benoît Sevens <bsevens@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit 45a92cbc88e4013bfed7fd2ccab3ade45f8e896b)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I13e916ffd46fce6fd08f7b9f96cea82bb4bc475d
2024-12-17 12:19:30 +00:00
Benoît Sevens
5d0f724962 UPSTREAM: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices
commit b909df18ce2a998afef81d58bbd1a05dc0788c40 upstream.

A bogus device can provide a bNumConfigurations value that exceeds the
initial value used in usb_get_configuration for allocating dev->config.

This can lead to out-of-bounds accesses later, e.g. in
usb_destroy_configuration.

Bug: 382243530
Signed-off-by: Benoît Sevens <bsevens@google.com>
Fixes: 1da177e4c3 ("Linux-2.6.12-rc2")
Cc: stable@kernel.org
Link: https://patch.msgid.link/20241120124144.3814457-1-bsevens@google.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit 9887d859cd60727432a01564e8f91302d361b72b)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I2df0d59750943fa34747bd4bae2e549320f2a0ce
2024-12-16 14:42:37 +00:00
Todd Kjos
d24bf3c271 Revert "UPSTREAM: unicode: Don't special case ignorable code points"
This reverts commit 62bbb08add179b68e2ce0ede59f3c4b37d6c92a8.

Reason for revert: b/382800956

Bug: 382800956
Change-Id: Ic7a0cdbb060c12c1628a5859d795e78cd6b9341d
Signed-off-by: Todd Kjos <tkjos@google.com>
(cherry picked from commit c376628415656f16d398aad95c218a06805038bd)
Signed-off-by: Lee Jones <joneslee@google.com>
2024-12-11 19:10:28 +00:00
Todd Kjos
dd94f8e4bc Reapply "UPSTREAM: unicode: Don't special case ignorable code points"
This reverts commit e1ba90026d98e53f5736131f3363424e83315f00.

Reapplying only to re-revert with the correct Change-Id

Bug: 382800956
Signed-off-by: Todd Kjos <tkjos@google.com>
Change-Id: Icdd08040f04ed7e85d31b7f8551ee2ef1d0b95b0
2024-12-11 19:10:27 +00:00
Todd Kjos
a820058846 Revert "UPSTREAM: unicode: Don't special case ignorable code points"
This reverts commit 425419e5b2.

Reason for revert: b/382800956

Change-Id: Ia691b87280a67f974a949fb402e71431a88a61d1
Signed-off-by: Todd Kjos <tkjos@google.com>
2024-12-11 01:17:35 +00:00
Greg Kroah-Hartman
8ee3ff6010 Merge tag 'android11-5.4.286_r00' into android11-5.4
This catches the android11-5.4 branch up to the 5.4.286 LTS release.
Changes merged here are:

* 3871647ee4 Revert "spi: Fix deadlock when adding SPI controllers on SPI buses"
* a1434939a5 Revert "spi: fix use-after-free of the add_lock mutex"
*   da1a77953e Merge 5.4.286 into android11-5.4-lts
|\
| * cd5b619ac4 Linux 5.4.286
| * 3213fdcab9 mm: avoid leaving partial pfn mappings around in error case
| * cfb280cc3b 9p: fix slab cache name creation for real
| * b97a50adb3 mm: add remap_pfn_range_notrack
| * 00106a045d mm/memory.c: make remap_pfn_range() reject unaligned addr
| * e681c83006 mm: fix ambiguous comments for better code readability
| * 31ccf3b44e mm: clarify a confusing comment for remap_pfn_range()
| * 882e4c6a3b md/raid10: improve code of mrdev in raid10_sync_request
| * 8bb1d617a3 net: usb: qmi_wwan: add Fibocom FG132 0x0112 composition
| * 17ecb40c5c fs: Fix uninitialized value issue in from_kuid and from_kgid
| * 45eadf46ff powerpc/powernv: Free name on error in opal_event_init()
| * 1fe7d27e6a sound: Make CONFIG_SND depend on INDIRECT_IOMEM instead of UML
| * c868a06a3f bpf: use kvzmalloc to allocate BPF verifier environment
| * a8a1c7fe27 HID: multitouch: Add quirk for HONOR MagicBook Art 14 touchpad
| * 9c28c5edc8 9p: Avoid creating multiple slab caches with the same name
| * fae6fcef17 ALSA: usb-audio: Add endianness annotations
| * fd8ae34669 vsock/virtio: Initialization of the dangling pointer occurring in vsk->trans
| * 4fe1d42f2a hv_sock: Initializing vsk->trans to NULL to prevent a dangling pointer
| * eea46baf14 ftrace: Fix possible use-after-free issue in ftrace_location()
| * 52300eb17e NFSD: Fix NFSv4's PUTPUBFH operation
| * 56fa2e5dec ALSA: usb-audio: Add quirks for Dell WD19 dock
| * a19f12b52a ALSA: usb-audio: Support jack detection on Dell dock
| * 168a9b8303 ocfs2: remove entry once instead of null-ptr-dereference in ocfs2_xa_remove()
| * 8cdb2d0796 irqchip/gic-v3: Force propagation of the active state with a read-back
| * 2f29a9fbae USB: serial: option: add Quectel RG650V
| * 02fcc5cda6 USB: serial: option: add Fibocom FG132 0x0112 composition
| * 853fffe789 USB: serial: qcserial: add support for Sierra Wireless EM86xx
| * 39709ce93f USB: serial: io_edgeport: fix use after free in debug printk
| * 4aa77d5ea9 usb: musb: sunxi: Fix accessing an released usb phy
| * a1be63b9e7 fs/proc: fix compile warning about variable 'vmcore_mmap_ops'
| * 684022f81f media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format
| * b2b7c43cd3 net: bridge: xmit: make sure we have at least eth header len bytes
| * 54c2c96eaf spi: fix use-after-free of the add_lock mutex
| * aa3f3d7bef spi: Fix deadlock when adding SPI controllers on SPI buses
| * fb77ce7138 mtd: rawnand: protect access to rawnand devices while in suspend
| * 93c5b8decc btrfs: reinitialize delayed ref list after deleting it from the list
| * bbfcd261cc nfs: Fix KMSAN warning in decode_getfattr_attrs()
| * 95da52fb73 dm-unstriped: cast an operand to sector_t to prevent potential uint32_t overflow
| * 2222b0929d dm cache: fix potential out-of-bounds access on the first resume
| * 8c3400a7fb dm cache: optimize dirty bit checking with find_next_bit when resizing
| * 8501e38dc9 dm cache: fix out-of-bounds access to the dirty bitset when resizing
| * a45d78569b dm cache: correct the number of origin blocks to match the target length
| * 8d7a28eca7 drm/amdgpu: prevent NULL pointer dereference if ATIF is not supported
| * 7ccd781794 drm/amdgpu: add missing size check in amdgpu_debugfs_gprwave_read()
| * f1d086c9b9 pwm: imx-tpm: Use correct MODULO value for EPWM mode
| * 0bfc6e38ee media: v4l2-tpg: prevent the risk of a division by zero
| * cad97ca8cf media: cx24116: prevent overflows on SNR calculus
| * e5117f6e7a media: s5p-jpeg: prevent buffer overflows
| * 2df76b10cb ALSA: firewire-lib: fix return value on fail in amdtp_tscm_init()
| * 31e562e5ed media: adv7604: prevent underflow condition when reporting colorspace
| * 5b389fe18c media: dvb_frontend: don't play tricks with underflow values
| * 3b88675e18 media: dvbdev: prevent the risk of out of memory access
| * 39023c18e8 media: stb0899_algo: initialize cfr before using it
| * 7ae4e56de7 net: hns3: fix kernel crash when uninstalling driver
| * 83b3b73afc can: c_can: fix {rx,tx}_errors statistics
| * 9b5d42aeaf sctp: properly validate chunk size in sctp_sf_ootb()
| * 4d846b3671 net: enetc: set MAC address to the VF net_device
| * 98394cf697 enetc: simplify the return expression of enetc_vf_set_mac_addr()
| * 4efb69a0e2 security/keys: fix slab-out-of-bounds in key_task_permission
| * 3f9e88f267 HID: core: zero-initialize the report buffer
| * 1e635487b0 ARM: dts: rockchip: Fix the realtek audio codec on rk3036-kylin
| * 18f4ca39c6 ARM: dts: rockchip: Fix the spi controller on rk3036
| * a10fa5624b ARM: dts: rockchip: drop grf reference from rk3036 hdmi
| * 43b8d98629 ARM: dts: rockchip: fix rk3036 acodec node
| * 27873e995d arm64: dts: rockchip: Remove #cooling-cells from fan on Theobroma lion
| * b57072b869 arm64: dts: rockchip: Fix bluetooth properties on Rock960 boards
| * 8d258ec8c3 arm64: dts: rockchip: Remove hdmi's 2nd interrupt on rk3328
| * 282a6ed21b arm64: dts: rockchip: Fix rt5651 compatible value on rk3399-sapphire-excavator
* | bc1dcc543b Revert "genetlink: hold RCU in genlmsg_mcast()"
* | 9d6ed89ef0 Revert "arm64: probes: Fix uprobes for big-endian kernels"
* | 73ec729f1b Revert "arm64/uprobes: change the uprobe_opcode_t typedef to fix the sparse warning"
* | 39666daae5 Revert "inet: inet_defrag: prevent sk release while still in use"
* | 94424b0fce Merge 5.4.285 into android11-5.4-lts
|\|
| * 6b8cbbd597 Linux 5.4.285
| * 8ebee7565e mm: krealloc: Fix MTE false alarm in __do_krealloc
| * c6ab967946 mac80211: always have ieee80211_sta_restart()
| * dc794e878e vt: prevent kernel-infoleak in con_font_get()
| * 7e948e456d Revert "drm/mipi-dsi: Set the fwnode for mipi_dsi_device"
| * 7cc30ada84 mm: shmem: fix data-race in shmem_getattr()
| * 64afad73e4 nilfs2: fix kernel bug due to missing clearing of checked flag
| * 95fbed8ae8 ocfs2: pass u64 to ocfs2_truncate_inline maybe overflow
| * 23669f189f riscv: Remove unused GENERATING_ASM_OFFSETS
| * a1686db1e5 nilfs2: fix potential deadlock with newly created symlinks
| * fcd6b59f7a staging: iio: frequency: ad9832: fix division by zero in ad9832_calc_freqreg()
| * 9d89941e51 wifi: iwlegacy: Clear stale interrupts before resuming device
| * 6fc9af3df6 wifi: ath10k: Fix memory leak in management tx
| * 78b698fbf3 wifi: mac80211: do not pass a stopped vif to the driver in .get_txpower
| * d4dba9a076 Revert "driver core: Fix uevent_show() vs driver detach race"
| * b115ecd0c6 xhci: Fix Link TRB DMA in command ring stopped completion event
| * ceb2f3fe8e usb: phy: Fix API devm_usb_put_phy() can not release the phy
| * aaa1b28378 usbip: tools: Fix detach_port() invalid port error path
| * d54dad3af7 misc: sgi-gru: Don't disable preemption in GRU driver
| * 57aabb8c97 net: amd: mvme147: Fix probe banner message
| * 14b6ca78c9 firmware: arm_sdei: Fix the input parameter of cpuhp_remove_state()
| * 3c2206700e drivers/misc: ti-st: Remove unneeded variable in st_tty_open
| * ac7df3fc80 netfilter: nft_payload: sanitize offset and length before calling skb_checksum()
| * 477b35d94a net: skip offload for NETIF_F_IPV6_CSUM if ipv6 header contains extension
| * 5715da5410 net: support ip generic csum processing in skb_csum_hwoffload_help
| * 91afbc0eb3 bpf: Fix out-of-bounds write in trie_get_next_key()
| * dbe778b08b net/sched: stop qdisc_tree_reduce_backlog on TC_H_ROOT
| * 2bb69ce76e gtp: allow -1 to be specified as file description from userspace
| * 5f6907bf5c gtp: simplify error handling code in 'gtp_encap_enable()'
| * c593895bf0 dt-bindings: gpu: Convert Samsung Image Rotator to dt-schema
| * b2ed38ff2a ASoC: cs42l51: Fix some error handling paths in cs42l51_probe()
| * 9c98ee7ea4 wifi: iwlwifi: mvm: Fix response handling in iwl_mvm_send_recovery_cmd()
| * 8b30a66a94 wifi: iwlwifi: mvm: disconnect station vifs if recovery failed
| * 130b34a204 mac80211: Add support to trigger sta disconnect on hardware restart
| * 0a2112edf6 mac80211: do drv_reconfig_complete() before restarting all
| * e67cb5a1cd wifi: mac80211: skip non-uploaded keys in ieee80211_iter_keys
| * 4f3e9217fb cgroup: Fix potential overflow issue when checking max_depth
| * 401ad99a5a xfrm: validate new SA's prefixlen using SA family when sel.family is unset
| * 9085d7eaac arm64/uprobes: change the uprobe_opcode_t typedef to fix the sparse warning
| * 5121ac6723 selinux: improve error checking in sel_write_load()
| * 31a38a908c hv_netvsc: Fix VF namespace also in synthetic NIC NETDEV_REGISTER event
| * ae95e0235c ALSA: hda/realtek: Add subwoofer quirk for Acer Predator G9-593
| * 412a30b1b2 nilfs2: fix kernel bug due to missing clearing of buffer delay flag
| * 507f393403 ACPI: button: Add DMI quirk for Samsung Galaxy Book2 to fix initial lid detection issue
| * 0fdb503758 ACPI: resource: Add LG 16T90SP to irq1_level_low_skip_override[]
| * 43b4fa6e0e drm/amd: Guard against bad data for ATIF ACPI method
| * 4cab98a173 ALSA: hda/realtek: Update default depop procedure
| * d575414361 ALSA: firewire-lib: Avoid division by zero in apply_constraint_to_size()
| * a8219446b9 posix-clock: posix-clock: Fix unbalanced locking in pc_clock_settime()
| * 6e2bbba8bb r8169: avoid unsolicited interrupts
| * 2f868ce601 net: sched: fix use-after-free in taprio_change()
| * 9fc566dfed net: usb: usbnet: fix name regression
| * 6b7ce8ee01 be2net: fix potential memory leak in be_xmit()
| * 8d5b20fbc5 net/sun3_82586: fix potential memory leak in sun3_82586_send_packet()
| * 5e3231b352 tracing: Consider the NULL character when validating the event length
| * 8bbfbf681e jfs: Fix sanity check in dbMount
| * 417bd613bd udf: fix uninit-value use in udf_get_fileshortad
| * 02c86c5d5e drm/vboxvideo: Replace fake VLA at end of vbva_mouse_pointer_shape with real VLA
| * c491ce22f9 KVM: s390: gaccess: Check if guest address is in memslot
| * f334578c68 KVM: s390: gaccess: Cleanup access to guest pages
| * 8a2e882914 KVM: s390: gaccess: Refactor access address range check
| * f1f3615bc3 KVM: s390: gaccess: Refactor gpa and length calculation
| * e6ab336213 arm64: probes: Fix uprobes for big-endian kernels
| * 5aa6cd3130 arm64:uprobe fix the uprobe SWBP_INSN in big-endian
| * 2c439470b2 Bluetooth: bnep: fix wild-memory-access in proto_unregister
| * 2c15c4133d usb: typec: altmode should keep reference to parent
| * 6f0516ef12 smb: client: fix OOBs when building SMB2_IOCTL request
| * 0d2bd44bfe genetlink: hold RCU in genlmsg_mcast()
| * 31701ef0c4 net: systemport: fix potential memory leak in bcm_sysport_xmit()
| * 389bdb093f net: ethernet: aeroflex: fix potential memory leak in greth_start_xmit_gbit()
| * 37441f39ee macsec: don't increment counters for an unrelated SA
| * ec674722c4 drm/msm/dsi: fix 32-bit signed integer extension in pclk_rate calculation
| * 825ffa86c3 RDMA/bnxt_re: Return more meaningful error
| * 772d5834e4 ipv4: give an IPv4 dev to blackhole_netdev
| * d7c4fd4902 RDMA/cxgb4: Fix RDMA_CM_EVENT_UNREACHABLE error for iWARP
| * fc2f42e4fe ARM: dts: bcm2837-rpi-cm3-io3: Fix HDMI hpd-gpio pin
| * 17648b72cb RDMA/bnxt_re: Fix incorrect AVID type in WQE structure
| * 7526339f91 mac80211: Fix NULL ptr deref for injected rate info
| * 9ff2d260b2 erofs: fix lz4 inplace decompression
| * b4b3dc9e7e nilfs2: propagate directory read errors from nilfs_find_entry()
| * 4aa8948673 x86/apic: Always explicitly disarm TSC-deadline timer
| * fd7133ec79 x86/resctrl: Annotate get_mem_config() functions as __init
| * b0641e53e6 parport: Proper fix for array out-of-bounds access
| * 5ead5b445f USB: serial: option: add Telit FN920C04 MBIM compositions
| * bd704359a8 USB: serial: option: add support for Quectel EG916Q-GL
| * 1f8cab3365 xhci: Fix incorrect stream context type macro
| * d42c3fa120 Bluetooth: btusb: Fix regression with fake CSR controllers 0a12:0001
| * 4b9cf50a78 Bluetooth: Remove debugfs directory on module init failure
| * f193dddd2f iio: adc: ti-ads124s08: add missing select IIO_(TRIGGERED_)BUFFER in Kconfig
| * f36e441f30 iio: proximity: mb1232: add missing select IIO_(TRIGGERED_)BUFFER in Kconfig
| * 81c795125a iio: light: opt3001: add missing full-scale range value
| * 96c1a70c13 iio: hid-sensors: Fix an error handling path in _hid_sensor_set_report_latency()
| * 65cbc40d8c iio: adc: ti-ads8688: add missing select IIO_(TRIGGERED_)BUFFER in Kconfig
| * 06f899ff18 iio: dac: stm32-dac-core: add missing select REGMAP_MMIO in Kconfig
| * 28d6fb095a iio: dac: ltc1660: add missing select REGMAP_SPI in Kconfig
| * ab4274f9ab drm/vmwgfx: Handle surface check failure correctly
| * d04b72c9ef blk-rq-qos: fix crash on rq_qos_wait vs. rq_qos_wake_function race
| * 9051f851a4 x86/cpufeatures: Define X86_FEATURE_AMD_IBPB_RET
| * 45d5596d44 KVM: s390: Change virtual to physical address access in diag 0x258 handler
| * f2f7d15487 s390/sclp_vt220: Convert newlines to CRLF instead of LFCR
| * 4c141136a2 KVM: Fix a data race on last_boosted_vcpu in kvm_vcpu_on_spin()
| * 2408f491ff wifi: mac80211: fix potential key use-after-free
| * ba7f982cdb mm/swapfile: skip HugeTLB pages for unuse_vma
| * 085e68e97f fat: fix uninitialized variable
| * 10edcff094 PCI: Add function 0 DMA alias quirk for Glenfly Arise chip
| * f198659ecb tracing/kprobes: Fix symbol counting logic by looking at modules as well
| * d3679f63a1 tracing/kprobes: Return EADDRNOTAVAIL when func matches several symbols
| * 87677556d5 arm64: probes: Fix simulate_ldr*_literal()
| * ae743deca7 arm64: probes: Remove broken LDR (literal) uprobe support
| * e0c966bd3e posix-clock: Fix missing timespec64 check in pc_clock_settime()
| * fd9bb7e996 nouveau/dmem: Fix vulnerability in migrate_to_ram upon copy error
| * 8e0766fcf3 net: Fix an unsafe loop on the list
| * 7f435eba84 hid: intel-ish-hid: Fix uninitialized variable 'rv' in ish_fw_xfer_direct_dma
| * 5319b50c49 usb: storage: ignore bogus device raised by JieLi BR21 USB sound chip
| * 72887e9fd6 usb: xhci: Fix problem with xhci resume from suspend
| * edb9ef4d88 usb: dwc3: core: Stop processing of pending events if controller is halted
| * 3ac86888fc Revert "usb: yurex: Replace snprintf() with the safer scnprintf() variant"
| * afaec54239 HID: plantronics: Workaround for an unexcepted opposite volume key
| * 9957fbf34f CDC-NCM: avoid overflow in sanity checking
| * 333fbaf686 resource: fix region_intersects() vs add_memory_driver_managed()
| * a20d4f0d9e lockdep: fix deadlock issue between lockdep and rcu
| * abdc85d630 locking/lockdep: Avoid potential access of invalid memory in lock_class
| * 991e129724 locking/lockdep: Rework lockdep_lock
| * 60519a39ae locking/lockdep: Fix bad recursion pattern
| * ba6501ea06 slip: make slhc_remember() more robust against malicious packets
| * 8dfe93901b ppp: fix ppp_async_encode() illegal access
| * 38a35450f3 sctp: ensure sk_state is set to CLOSED if hashing fails in sctp_listen_start
| * ed494a6050 net: annotate lockless accesses to sk->sk_max_ack_backlog
| * e9b8a2629e net: annotate lockless accesses to sk->sk_ack_backlog
| * e2882b4677 net: ibm: emac: mal: fix wrong goto
| * 2acbb9539b net/sched: accept TCA_STAB only for root qdisc
| * c92cbd283d igb: Do not bring the device up after non-fatal error
| * 4fdc7ce5f3 gpio: aspeed: Use devm_clk api to manage clock source
| * eda428e573 gpio: aspeed: Add the flush write to ensure the write complete.
| * 869c6ee62a Bluetooth: RFCOMM: FIX possible deadlock in rfcomm_sk_state_change
| * 75dfcb7580 netfilter: br_netfilter: fix panic with metadata_dst skb
| * b56fc6407e tcp: fix tcp_enter_recovery() to zero retrans_stamp when it's safe
| * ff81628202 tcp: fix to allow timestamp undo if no retransmits were sent
| * dcd96d7352 SUNRPC: Fix integer overflow in decode_rc_list()
| * 761bcde586 ice: fix VLAN replay after reset
| * c91fb72a2c RDMA/rxe: Fix seg fault in rxe_comp_queue_pkt
| * 57c4f4db0a fbdev: sisfb: Fix strbuf array overflow
| * 7ad47b64c6 driver core: bus: Return -EIO instead of 0 when show/store invalid bus attribute
| * 33529e2703 tools/iio: Add memory allocation failure check for trigger_name
| * 59ac565c62 virtio_pmem: Check device status before requesting flush
| * 0547f710d8 usb: dwc2: Adjust the timing of USB Driver Interrupt Registration in the Crashkernel Scenario
| * 2a806805d3 usb: chipidea: udc: enable suspend interrupt after usb reset
| * 6900b41263 media: videobuf2-core: clear memory related fields in __vb2_plane_dmabuf_put()
| * 5126d8f556 ntb: ntb_hw_switchtec: Fix use after free vulnerability in switchtec_ntb_remove due to race condition
| * 018a356880 PCI: Mark Creative Labs EMU20k2 INTx masking as broken
| * a3a4d6a441 i2c: i801: Use a different adapter-name for IDF adapters
| * 7ca8f74f39 PCI: Add ACS quirk for Qualcomm SA8775P
| * 96225fd15c clk: bcm: bcm53573: fix OF node leak in init
| * 978d712486 ktest.pl: Avoid false positives with grub2 skip regex
| * 4a7b939113 s390/cpum_sf: Remove WARN_ON_ONCE statements
| * aa03f841cd ext4: nested locking for xattr inode
| * e040f33b30 s390/mm: Add cond_resched() to cmm_alloc/free_pages()
| * 0671121942 s390/facility: Disable compile time optimization for decompressor code
| * d2e35f220c bpf: Check percpu map value size first
| * a9beea8c85 Input: synaptics-rmi4 - fix UAF of IRQ domain on driver removal
| * 3088336ff7 virtio_console: fix misc probe bugs
| * 578d66b048 tracing: Have saved_cmdlines arrays all in one allocation
| * 07effb3c96 drm/crtc: fix uninitialized variable use even harder
| * 49da44d24c tracing: Remove precision vsnprintf() check from print event
| * 7eb94e52eb net: ethernet: cortina: Drop TSO support
| * 18b5f47e7d unicode: Don't special case ignorable code points
| * 6de83ed473 ext4: fix inode tree inconsistency caused by ENOMEM
| * c47843a831 ACPI: battery: Fix possible crash when unregistering a battery hook
| * b5b7d4a012 ACPI: battery: Simplify battery hook locking
| * 64648ae8c9 r8169: add tally counter fields added with RTL8125
| * c2d43f2221 r8169: Fix spelling mistake: "tx_underun" -> "tx_underrun"
| * 9dcff844c1 clk: qcom: clk-rpmh: Fix overflow in BCM vote
| * 997526f85b clk: qcom: rpmh: Simplify clk_rpmh_bcm_send_cmd()
| * 86c3f6130b nfsd: fix delegation_blocked() to block correctly for at least 30 seconds
| * 8843824b67 nfsd: use ktime_get_seconds() for timestamps
| * fe5e9182d3 uprobes: fix kernel info leak via "[uprobes]" vma
| * 7fc8b76903 arm64: errata: Expand speculative SSBS workaround once more
| * 3b35b4461f arm64: cputype: Add Neoverse-N3 definitions
| * d493f26ef8 arm64: Add Cortex-715 CPU part definition
| * 889b912954 i2c: qcom-geni: Use IRQF_NO_AUTOEN flag in request_irq()
| * 66b9e6e2d4 i2c: qcom-geni: Grow a dev pointer to simplify code
| * d5bcb2f9ae i2c: qcom-geni: Let firmware specify irq trigger flags
| * dd6a664bd8 gpio: davinci: fix lazy disable
| * a71349b692 btrfs: wait for fixup workers before stopping cleaner kthread during umount
| * 1282f001cb btrfs: fix a NULL pointer dereference when failed to start a new trasacntion
| * af40b4297a ACPI: resource: Add Asus ExpertBook B2502CVA to irq1_level_low_skip_override[]
| * fc2c013638 ACPI: resource: Add Asus Vivobook X1704VAP to irq1_level_low_skip_override[]
| * 5d9dcd5b21 Input: adp5589-keys - fix adp5589_gpio_get_value()
| * fe6cdc1eea rtc: at91sam9: fix OF node leak in probe() error path
| * 3ba06256d2 tomoyo: fallback to realpath if symlink's pathname does not exist
| * 844738f40e iio: magnetometer: ak8975: Fix reading for ak099xx sensors
| * 63bbe26471 media: venus: fix use after free bug in venus_remove due to race condition
| * 2f33c6b5ff media: uapi/linux/cec.h: cec_msg_set_reply_to: zero flags
| * fd0ef59c99 media: sun4i_csi: Implement link validate for sun4i_csi subdev
| * dc57b2cd80 clk: rockchip: fix error for unknown clocks
| * a786265aec aoe: fix the potential use-after-free problem in more places
| * a3915200c8 riscv: define ILLEGAL_POINTER_VALUE for 64bit
| * e68c832335 ocfs2: fix possible null-ptr-deref in ocfs2_set_buffer_uptodate
| * 703b2c7e07 ocfs2: fix null-ptr-deref when journal load failed.
| * 9753bcb17b ocfs2: remove unreasonable unlock in ocfs2_read_blocks
| * 89043e7ed6 ocfs2: cancel dqi_sync_work before freeing oinfo
| * 74364cb578 ocfs2: reserve space for inline xattr before attaching reflink tree
| * cb9561ef13 ocfs2: fix uninit-value in ocfs2_get_block()
| * efbe8e49a6 ocfs2: fix the la space leak when unmounting an ocfs2 volume
| * c383263ee8 mm: krealloc: consider spare memory for __GFP_ZERO
| * d5dc65370a jbd2: stop waiting for space when jbd2_cleanup_journal_tail() returns error
| * c17a4f52fa drm: omapdrm: Add missing check for alloc_ordered_workqueue
| * 6cda681004 of/irq: Support #msi-cells=<0> in of_msi_get_domain
| * c20a17c2d2 parisc: Fix stack start for ADDR_NO_RANDOMIZE personality
| * 8eed55de0d parisc: Fix 64-bit userspace syscall path
| * 897e2f5192 ext4: fix incorrect tid assumption in ext4_wait_for_tail_page_commit()
| * f9fd47c9d9 ext4: fix double brelse() the buffer of the extents path
| * 975ca06f3f ext4: aovid use-after-free in ext4_ext_insert_extent()
| * 2bcfc2dc6d ext4: fix incorrect tid assumption in __jbd2_log_wait_for_space()
| * 0ddc7a7933 ext4: propagate errors from ext4_find_extent() in ext4_insert_range()
| * cdfd6ef391 ext4: no need to continue when the number of entries is 1
| * f49f4fd18d ALSA: core: add isascii() check to card ID generator
| * 24b4c5be6a drm: Consistently use struct drm_mode_rect for FB_DAMAGE_CLIPS
| * 107937ba80 parisc: Fix itlb miss handler for 64-bit programs
| * d346599940 perf/core: Fix small negative period being ignored
| * fec2ccd74b spi: bcm63xx: Fix module autoloading
| * 006c109da9 firmware: tegra: bpmp: Drop unused mbox_client_to_bpmp()
| * 33efc8da77 i2c: xiic: Wait for TX empty to avoid missed TX NAKs
| * d6f1250a4d i2c: stm32f7: Do not prepare/unprepare clock during runtime suspend/resume
| * f53c17123b selftests: vDSO: fix vDSO symbols lookup for powerpc64
| * 48441fd34f selftests: breakpoints: use remaining time to check if suspend succeed
| * d5d9b789c3 spi: s3c64xx: fix timeout counters in flush_fifo
| * 3c46d6060d ext4: fix i_data_sem unlock order in ext4_ind_migrate()
| * 556452e986 ext4: ext4_search_dir should return a proper error
| * 7bd0f5cb6d of/irq: Refer to actual buffer size in of_irq_parse_one()
| * e17a5b8192 drm/radeon/r100: Handle unknown family in r100_cp_init_microcode()
| * 7e19f1d284 scsi: aacraid: Rearrange order of struct aac_srb_unit
| * 93a4273e5f drm/printer: Allow NULL data in devcoredump printer
| * 8f0abb39c1 drm/amd/display: Initialize get_bytes_per_element's default to 1
| * f5f6d90087 drm/amd/display: Fix index out of bounds in degamma hardware format translation
| * 471c53350a drm/amd/display: Check stream before comparing them
| * dac398ed27 jfs: Fix uninit-value access of new_ea in ea_buffer
| * 35b91f15f4 jfs: check if leafidx greater than num leaves per dmap tree
| * 3126ccde51 jfs: Fix uaf in dbFreeBits
| * 22b166d7e5 jfs: UBSAN: shift-out-of-bounds in dbFindBits
| * 2fe34fe07f ata: sata_sil: Rename sil_blacklist to sil_quirks
| * d35ad25f98 power: reset: brcmstb: Do not go into infinite loop if reset fails
| * 6d0a07f68b fbdev: pxafb: Fix possible use after free in pxafb_task()
| * da13b253ad x86/syscall: Avoid memcpy() for ia32 syscall_get_arguments()
| * 8e5dd7d867 ALSA: hdsp: Break infinite MIDI input flush loop
| * ce2953e448 ALSA: asihpi: Fix potential OOB array access
| * 53e9c1ab16 signal: Replace BUG_ON()s
| * 267960ded6 nfp: Use IRQF_NO_AUTOEN flag in request_irq()
| * f9310a6704 wifi: mwifiex: Fix memcpy() field-spanning write warning in mwifiex_cmd_802_11_scan_ext()
| * 299b917594 proc: add config & param to block forcing mem writes
| * f3b2acb1b6 ACPICA: iasl: handle empty connection_node
| * fb66354a6a tcp: avoid reusing FIN_WAIT2 when trying to find port in connect() process
| * b9d3b0459b ipv4: Mask upper DSCP bits and ECN bits in NETLINK_FIB_LOOKUP family
| * 0b54f8e73b ipv4: Check !in_dev earlier for ioctl(SIOCSIFADDR).
| * 89704e7aaa net: mvpp2: Increase size of queue_name buffer
| * c79768ffba tipc: guard against string buffer overrun
| * 402b4c6b75 ACPICA: check null return of ACPI_ALLOCATE_ZEROED() in acpi_db_convert_to_package()
| * bcb4a23f03 ACPI: EC: Do not release locks during operation region accesses
| * 1bf77d32e4 wifi: rtw88: select WANT_DEV_COREDUMP
| * f81b864fe5 net: sched: consistently use rcu_replace_pointer() in taprio_change()
| * f2c2c674cb ACPICA: Fix memory leak if acpi_ps_get_next_field() fails
| * b340de28c2 ACPICA: Fix memory leak if acpi_ps_get_next_namepath() fails
| * 62c0d526c9 net: hisilicon: hns_mdio: fix OF node leak in probe()
| * 8b8511d5bc net: hisilicon: hns_dsaf_mac: fix OF node leak in hns_mac_get_info()
| * beb04d5509 net: hisilicon: hip04: fix OF node leak in probe()
| * bd51b0e678 ice: Adjust over allocation of memory in ice_sched_add_root_node() and ice_sched_add_node()
| * d1f2fbc6a7 wifi: ath9k_htc: Use __skb_set_length() for resetting urb before resubmit
| * d96512bfee wifi: ath9k: fix possible integer overflow in ath9k_get_et_stats()
| * 4ce87674c3 f2fs: Require FMODE_WRITE for atomic write ioctls
| * 9213d0b6a1 ALSA: hda/conexant: Fix conflicting quirk for System76 Pangolin
| * ec7b2b0a3b ALSA: hda/generic: Unconditionally prefer preferred_dacs pairs
| * f30b5295e8 ALSA: hda/realtek: Fix the push button function for the ALC257
| * 0e4e2e6055 sctp: set sk_state back to CLOSED if autobind fails in sctp_listen_start
| * 5ac448133e ipv4: ip_gre: Fix drops of small packets in ipgre_xmit
| * 473426a1d5 net: add more sanity checks to qdisc_pkt_len_init()
| * 1598d70ad9 net: avoid potential underflow in qdisc_pkt_len_init() with UFO
| * 60c068444c net: ethernet: lantiq_etop: fix memory disclosure
| * efd9ff49d9 Bluetooth: btmrvl: Use IRQF_NO_AUTOEN flag in request_irq()
| * 8f390b9eed Bluetooth: btmrvl_sdio: Refactor irq wakeup
| * c0add6ed2c netfilter: nf_tables: prevent nf_skb_duplicated corruption
| * 83b0b227a9 net: ieee802154: mcr20a: Use IRQF_NO_AUTOEN flag in request_irq()
| * 4b16abbc2b netfilter: uapi: NFTA_FLOWTABLE_HOOK is NLA_NESTED
| * 409105f06e net/mlx5: Added cond_resched() to crdump collection
| * e61e5731a5 ieee802154: Fix build error
| * 9715751935 drivers: net: Fix Kconfig indentation, continued
| * a720ee9ce1 Minor fixes to the CAIF Transport drivers Kconfig file
| * 126b567a2e ceph: remove the incorrect Fw reference check when dirtying pages
| * b0de20de29 mailbox: bcm2835: Fix timeout during suspend mode
| * 07975f7bc5 mailbox: rockchip: fix a typo in module autoloading
| * 37480a590d usb: yurex: Fix inconsistent locking bug in yurex_read()
| * 031533b621 i2c: isch: Add missed 'else'
| * 64af4be29b i2c: aspeed: Update the stop sw state when the bus recovery occurs
| * 6ed7f633da mm: only enforce minimum stack gap size if it's sensible
| * 8b8de9986f pps: add an error check in parport_attach
| * 76abcdcabc pps: remove usage of the deprecated ida_simple_xx() API
| * e66c626682 USB: misc: yurex: fix race between read and write
| * 79038d945b usb: yurex: Replace snprintf() with the safer scnprintf() variant
| * c37bca2ce7 soc: versatile: realview: fix soc_dev leak during device remove
| * 0f167c1456 soc: versatile: realview: fix memory leak during device remove
| * 893e831406 PCI: xilinx-nwl: Fix off-by-one in INTx IRQ handler
| * 12350c6062 PCI: xilinx-nwl: Use irq_data_get_irq_chip_data()
| * a33145f494 ASoC: meson: axg-card: fix 'use-after-free'
| * 69f27ade48 ASoC: meson: axg: extract sound card utils
| * ba1cd08eb0 nfs: fix memory leak in error path of nfs4_do_reclaim
| * deaf93e3c9 fs: Fix file_set_fowner LSM hook inconsistencies
| * 489faddb1a vfs: fix race between evice_inodes() and find_inode()&iput()
| * 63b1db26b5 hwrng: mtk - Use devm_pm_runtime_enable
| * 8c0b118bcc f2fs: avoid potential int overflow in sanity_check_area_boundary()
| * a71b1bec2b f2fs: prevent possible int overflow in dir_block_index()
| * 60be28d8f9 debugobjects: Fix conditions in fill_pool()
| * 8587887c7c wifi: rtw88: 8822c: Fix reported RX band width
| * 8855fe99bf ACPI: resource: Add another DMI match for the TongFang GMxXGxx
| * 2364b6af90 ACPI: sysfs: validate return type of _STR method
| * 959974bf5d drbd: Add NULL check for net_conf to prevent dereference in state validation
| * 9679a6e148 drbd: Fix atomicity violation in drbd_uuid_set_bm()
| * 182e6a64db tty: rp2: Fix reset with non forgiving PCIe host bridges
| * 9b1ca33ebd firmware_loader: Block path traversal
| * 560ae2252f USB: class: CDC-ACM: fix race between get_serial and set_serial
| * 34f0773c94 USB: misc: cypress_cy7c63: check for short transfer
| * 18ae85ccae USB: appledisplay: close race between probe and completion handler
| * 2f4c0f5bb1 drm/amd/display: Round calculated vtotal
| * 00ff88849b soc: versatile: integrator: fix OF node leak in probe() error path
| * 4524056264 Remove *.orig pattern from .gitignore
| * b716e9c360 crypto: aead,cipher - zeroize key buffer after use
| * feea6020aa netfilter: ctnetlink: compile ctnetlink_label_size with CONFIG_NF_CONNTRACK_EVENTS
| * 16a73a0856 net: qrtr: Update packets cloning when broadcasting
| * 16e0387d87 tcp: check skb is non-NULL in tcp_rto_delta_us()
| * b5a84b6c77 net: seeq: Fix use after free vulnerability in ether3 Driver Due to Race Condition
| * 7bcbc4cda7 netfilter: nf_reject_ipv6: fix nf_reject_ip6_tcphdr_put()
| * b8efd48ed5 coresight: tmc: sg: Do not leak sg_table
| * f7f24d67f0 iio: adc: ad7606: fix standby gpio state to match the documentation
| * d44f8a17f4 iio: adc: ad7606: fix oversampling gpio array
| * 6ec0f44471 f2fs: reduce expensive checkpoint trigger frequency
| * 18a2f126fa f2fs: remove unneeded check condition in __f2fs_setxattr()
| * 363eb38b9a f2fs: fix to update i_ctime in __f2fs_setxattr()
| * 97a5007f2e f2fs: fix typo
| * f1850e6cca f2fs: enhance to update i_mode and acl atomically in f2fs_setattr()
| * 6d07040ae5 nfsd: return -EINVAL when namelen is 0
| * c6b16e700c nfsd: call cache_put if xdr_reserve_space returns NULL
| * 4b2fbba4e4 ntb: intel: Fix the NULL vs IS_ERR() bug for debugfs_create_dir()
| * 4e1fe68d69 RDMA/cxgb4: Added NULL check for lookup_atid
| * b1a0c9e35a riscv: Fix fp alignment bug in perf_callchain_user()
| * 5db879525c RDMA/hns: Optimize hem allocation performance
| * 9a1fe8d689 watchdog: imx_sc_wdt: Don't disable WDT in suspend
| * 6b669f3888 pinctrl: mvebu: Fix devinit_dove_pinctrl_probe function
| * 4679497af6 clk: ti: dra7-atl: Fix leak of of_nodes
| * 888d0b49f2 pinctrl: single: fix missing error code in pcs_probe()
| * 29b3bbd912 RDMA/iwcm: Fix WARNING:at_kernel/workqueue.c:#check_flush_dependency
| * fd9d50ee75 PCI: xilinx-nwl: Fix register misspelling
| * 9c9afc3e75 PCI: keystone: Fix if-statement expression in ks_pcie_quirk()
| * 883f794c6e drivers: media: dvb-frontends/rtl2830: fix an out-of-bounds write error
| * 49b33c38d2 drivers: media: dvb-frontends/rtl2832: fix an out-of-bounds write error
| * 08e13a9ee8 clk: rockchip: Set parent rate for DCLK_VOP clock on RK3228
| * 1993819aff perf time-utils: Fix 32-bit nsec parsing
| * fc8d057930 perf sched timehist: Fixed timestamp error when unable to confirm event sched_in time
| * 5c4a88f2aa perf sched timehist: Fix missing free of session in perf_sched__timehist()
| * adfbc2440a bpf: Fix bpf_strtol and bpf_strtoul helpers for 32bit
| * ed76d381da nilfs2: fix potential oob read in nilfs_btree_check_delete()
| * 98d0c6f11f nilfs2: determine empty node blocks as corrupted
| * 1d94dbdfbb nilfs2: fix potential null-ptr-deref in nilfs_btree_insert()
| * 8adf0eb4e3 ext4: avoid OOB when system.data xattr changes underneath the filesystem
| * 52c5fdad08 ext4: return error on ext4_find_inline_entry
| * dd0bc5b7bd ext4: avoid negative min_clusters in find_group_orlov()
| * e8c1082c72 smackfs: Use rcu_assign_pointer() to ensure safe assignment in smk_set_cipso
| * 22e130fe60 ext4: clear EXT4_GROUP_INFO_WAS_TRIMMED_BIT even mount with discard
| * cbb86a2339 jbd2: introduce/export functions jbd2_journal_submit|finish_inode_data_buffers()
| * a611f9ffcf kthread: fix task state in kthread worker if being frozen
| * 0f0de5d353 kthread: add kthread_work tracepoints
| * 6c371167fd xz: cleanup CRC32 edits from 2018
| * 8cd5699831 selftests/bpf: Fix error compiling test_lru_map.c
| * 44d9436ea9 selftests/bpf: Fix compiling tcp_rtt.c with musl-libc
| * a620219bdd selftests/bpf: Fix compiling flow_dissector.c with musl-libc
| * dc5f75f3c3 selftests/bpf: Fix compile error from rlim_t in sk_storage_map.c
| * 87e8134c18 tpm: Clean up TPM space after command failure
| * 5df29a445f xen/swiotlb: add alignment check for dma buffers
| * c87b0349f1 xen: use correct end address of kernel for conflict checking
| * 4dac65dadc drivers:drm:exynos_drm_gsc:Fix wrong assignment in gsc_bind()
| * 5c9a3510c8 drm/msm: fix %s null argument error
| * 5434fdccab ipmi: docs: don't advertise deprecated sysfs entries
| * 9bcf5687fe drm/msm/a5xx: fix races in preemption evaluation stage
| * 637823ff5e drm/msm/a5xx: properly clear preemption records on resume
| * 1299487518 drm/msm/a5xx: disable preemption in submits by default
| * df8e4cf27b drm/msm: Fix incorrect file name output in adreno_request_fw()
| * 5ad6284c8d jfs: fix out-of-bounds in dbNextAG() and diAlloc()
| * 41a3ed4182 drm/radeon/evergreen_cs: fix int overflow errors in cs track offsets
| * 2ee92b995e drm/rockchip: dw_hdmi: Fix reading EDID when using a forced mode
| * 20878dec6d drm/rockchip: vop: Allow 4096px width scaling
| * 746e3b6f25 drm/radeon: properly handle vbios fake edid sizing
| * 4477639573 drm/radeon: Replace one-element array with flexible-array member
| * 4209b70fea drm/amdgpu: properly handle vbios fake edid sizing
| * 24f4bdf1c8 drm/amdgpu: Replace one-element array with flexible-array member
| * ba2310096e drm/stm: Fix an error handling path in stm_drm_platform_probe()
| * c3c9c5daea mtd: powernv: Add check devm_kasprintf() returned value
| * bb8e820cf6 fbdev: hpfb: Fix an error handling path in hpfb_dio_probe()
| * 65af6f4a72 power: supply: max17042_battery: Fix SOC threshold calc w/ no current sense
| * 575ea801cc power: supply: axp20x_battery: Remove design from min and max voltage
| * 206734f557 power: supply: axp20x_battery: allow disabling battery charging
| * 1d8d2a0312 hwmon: (ntc_thermistor) fix module autoloading
| * 31bd8df755 mtd: slram: insert break after errors in parsing the map
| * ce56acc0e2 hwmon: (max16065) Fix overflows seen when writing limits
| * 06ca666a2e clocksource/drivers/qcom: Add missing iounmap() on errors in msm_dt_timer_init()
| * e8384befe2 reset: berlin: fix OF node leak in probe() error path
| * 1f578d2118 ARM: versatile: fix OF node leak in CPUs prepare
| * d3a63fa27f ARM: dts: imx7d-zii-rmu2: fix Ethernet PHY pinctrl property
| * 2d98263d5c spi: ppc4xx: Avoid returning 0 when failed to parse and map IRQ
| * dab6520643 spi: ppc4xx: handle irq_of_parse_and_map() errors
| * 3a5f45a4ad block, bfq: don't break merge chain in bfq_split_bfqq()
| * 140c8e2caa block, bfq: choose the last bfqq from merge chain in bfq_setup_cooperator()
| * bc2140534b block, bfq: fix possible UAF for bfqq->bic with merge chain
| * c3026230d2 net: tipc: avoid possible garbage value
| * 309eb08b48 Bluetooth: btusb: Fix not handling ZPL/short-transfer
| * a833da8eec can: bcm: Clear bo->bcm_proc_read after remove_proc_entry().
| * bc05f68556 sock_map: Add a cond_resched() in sock_hash_free()
| * 5a24cedc24 wifi: wilc1000: fix potential RCU dereference issue in wilc_parse_join_bss_param
| * 04f75f5bae wifi: mac80211: use two-phase skb reclamation in ieee80211_do_stop()
| * 73d2e264bd mac80211: parse radiotap header when selecting Tx queue
| * 7ce40a1121 wifi: cfg80211: fix two more possible UBSAN-detected off-by-one errors
| * 7d38d0cea3 wifi: cfg80211: fix UBSAN noise in cfg80211_wext_siwscan()
| * 05f6631614 netfilter: nf_tables: reject expiration higher than timeout
| * bd6b2e3a01 netfilter: nf_tables: reject element expiration with no timeout
| * 1f444ee91b netfilter: nf_tables: elements with timeout below CONFIG_HZ never expire
| * 30e197f8bb can: j1939: use correct function name in comment
| * ac076cb0db mount: handle OOM on mnt_warn_timestamp_expiry
| * c6c1e1356d fs/namespace: fnic: Switch to use %ptTd
| * 7e2e113f94 mount: warn only once about timestamp range expiration
| * 92738aab2f fs: explicitly unregister per-superblock BDIs
| * 8f88812306 wifi: ath9k: Remove error checks when creating debugfs entries
| * dab22cf5b4 wifi: ath9k: fix parameter check in ath9k_init_debug()
| * c2fbff12c6 ACPI: PMIC: Remove unneeded check in tps68470_pmic_opregion_probe()
| * fa65231888 USB: usbtmc: prevent kernel-usb-infoleak
| * a6eb2a486c USB: serial: pl2303: add device id for Macrosilicon MS3020
| * 1f5e352b90 bpf: Fix DEVMAP_HASH overflow check on 32-bit arches
| * 1b6de5e657 inet: inet_defrag: prevent sk release while still in use
| * 9ae2d8e75b gpio: prevent potential speculation leaks in gpio_device_get_desc()
| * e8f9c4af7a ocfs2: strict bound check before memcmp in ocfs2_xattr_find_entry()
| * 60c0d36189 ocfs2: add bounds checking to ocfs2_xattr_find_entry()
| * 71fbc5018d x86/hyperv: Set X86_FEATURE_TSC_KNOWN_FREQ when Hyper-V provides frequency
| * a38644c146 spi: bcm63xx: Enable module autoloading
| * 1ccc2b0f6c drm: komeda: Fix an issue related to normalized zpos
| * 79d978f254 ASoC: tda7419: fix module autoloading
| * 16c1e5d522 wifi: iwlwifi: mvm: don't wait for tx queues if firmware is dead
| * 5fa62c3fff wifi: iwlwifi: mvm: fix iwl_mvm_max_scan_ie_fw_cmd_room()
| * 9023ef9cba net: ftgmac100: Ensure tx descriptor updates are visible
| * 33d60cd46e microblaze: don't treat zero reserved memory regions as error
| * f03b3fe7d7 pinctrl: at91: make it work with current gpiolib
| * f7fe730011 ALSA: hda/realtek - FIxed ALC285 headphone no sound
| * 950b8ce6b8 ALSA: hda/realtek - Fixed ALC256 headphone no sound
| * 06064053e7 ASoC: allow module autoloading for table db1200_pids
| * 503e1d7cc8 selftests: breakpoints: Fix a typo of function name
| * 2fdc7540a9 soundwire: stream: Revert "soundwire: stream: fix programming slave ports for non-continous port maps"
| * aa05db44db spi: nxp-fspi: fix the KASAN report out-of-bounds bug
| * dc43a096cf net: dpaa: Pad packets to ETH_ZLEN
| * cfb4552c0c net: ftgmac100: Enable TX interrupt to avoid TX timeout
| * 453e69e145 net/mlx5e: Add missing link modes to ptys2ethtool_map
| * 164df4ec5a ice: fix accounting for filters shared by multiple VSIs
| * d5901c4975 arm64: dts: rockchip: override BIOS_DISABLE signal via GPIO hog on RK3399 Puma
| * af8151c833 scripts: kconfig: merge_config: config files: add a trailing newline
| * bd21d96484 net: phy: vitesse: repair vsc73xx autonegotiation
| * ef2c4556a3 net: ethernet: use ip_hdrlen() instead of bit shift
| * 11f5645c61 usbnet: ipheth: fix carrier detection in modes 1 and 4
* b1c3b1041a Merge branch 'android11-5.4' into android11-5.4-lts

Change-Id: Ifb715a26a2184f0dd505fb6c6e969132bf7133a7
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-11-28 17:18:11 +00:00
Pedro Tammela
ac5c9c9bf3 UPSTREAM: net/sched: stop qdisc_tree_reduce_backlog on TC_H_ROOT
[ Upstream commit 2e95c4384438adeaa772caa560244b1a2efef816 ]

In qdisc_tree_reduce_backlog, Qdiscs with major handle ffff: are assumed
to be either root or ingress. This assumption is bogus since it's valid
to create egress qdiscs with major handle ffff:
Budimir Markovic found that for qdiscs like DRR that maintain an active
class list, it will cause a UAF with a dangling class pointer.

In 066a3b5b23, the concern was to avoid iterating over the ingress
qdisc since its parent is itself. The proper fix is to stop when parent
TC_H_ROOT is reached because the only way to retrieve ingress is when a
hierarchy which does not contain a ffff: major handle call into
qdisc_lookup with TC_H_MAJ(TC_H_ROOT).

In the scenario where major ffff: is an egress qdisc in any of the tree
levels, the updates will also propagate to TC_H_ROOT, which then the
iteration must stop.

Fixes: 066a3b5b23 ("[NET_SCHED] sch_api: fix qdisc_tree_decrease_qlen() loop")
Reported-by: Budimir Markovic <markovicbudimir@gmail.com>
Suggested-by: Jamal Hadi Salim <jhs@mojatatu.com>
Tested-by: Victor Nogueira <victor@mojatatu.com>
Signed-off-by: Pedro Tammela <pctammela@mojatatu.com>
Signed-off-by: Jamal Hadi Salim <jhs@mojatatu.com>

 net/sched/sch_api.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
Reviewed-by: Simon Horman <horms@kernel.org>

Bug: 377197048
Link: https://patch.msgid.link/20241024165547.418570-1-jhs@mojatatu.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
(cherry picked from commit 597cf9748c3477bf61bc35f0634129f56764ad24)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I4ef8bee1095f7c51e4d458b25cd331018188b3d6
2024-11-25 16:28:00 +00:00
Aleksei Vetrov
e3a8df3001 ANDROID: add file for recording allowed ABI breaks
The tooling is configured to block any changes that has a chance to
break ABI, including the possibly safe:

* replacement of ANDROID_KABI_RESERVE with ANDROID_KABI_USE
* changes to internal structures that are not accessible to modules
* addition of enumerators

These changes are difficult for the tooling to identify as definitively
non-breaking, therefore, a human reviewer must check the change and
approve it as non-breaking.

This change adds a file to record the approval with the change that was
marked as breaking. This allows the tooling to:

* unblock presubmits for the change
* don't block presubmits when it is cherry-picked to another branch
* filter compatibility reports between a release branch and a tip of the
  development branch it was forked from

The file is prefilled with all breaks that happened from the KMI freeze.

Bug: 365521273
Change-Id: I63fbed5c364cb8c7bd149bf40d084d3d87533bf7
Signed-off-by: Aleksei Vetrov <vvvvvv@google.com>
2024-11-22 11:19:15 +00:00
Greg Kroah-Hartman
3871647ee4 Revert "spi: Fix deadlock when adding SPI controllers on SPI buses"
This reverts commit aa3f3d7bef which is
commit 6098475d4cb48d821bdf453c61118c56e26294f0 upstream.

It breaks the Android kernel abi and can be brought back in the future
in an abi-safe way if it is really needed.

Bug: 161946584
Change-Id: I2bd07f43254864be68c6426dc3215dcd60aa0516
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-11-21 22:00:36 +00:00
Greg Kroah-Hartman
a1434939a5 Revert "spi: fix use-after-free of the add_lock mutex"
This reverts commit 54c2c96eaf which is
commit 6c53b45c71b4920b5e62f0ea8079a1da382b9434 upstream.

It breaks the Android kernel abi and can be brought back in the future
in an abi-safe way if it is really needed.

Bug: 161946584
Change-Id: Icce07d26ecdbeb799b479babd47730046b402902
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-11-21 22:00:15 +00:00
Todd Kjos
0215dc2885 ANDROID: declare sp_in_global outside of CONFIG_FRAME_POINTER
Fix for riscv allmodconfig builds. Need sp_in_global to be declared
outside of #ifdef CONFIG_FRAME_POINTER to cover all cases

Fixes: f06e9ec979 ("BACKPORT: RISC-V: Stop relying on GCC's register allocator's hueristics")
Signed-off-by: Todd Kjos <tkjos@google.com>
Change-Id: Ifeb8901498895bb2079d9541e856b417619a6b78
2024-11-21 18:22:10 +00:00
Palmer Dabbelt
f06e9ec979 BACKPORT: RISC-V: Stop relying on GCC's register allocator's hueristics
GCC allows users to hint to the register allocation that a variable should be
placed in a register by using a syntax along the lines of

    function(...) {
        register long in_REG __asm__("REG");
    }

We've abused this a bit throughout the RISC-V port to access fixed registers
directly as C variables.  In practice it's never going to blow up because GCC
isn't going to allocate these registers, but it's not a well defined syntax so
we really shouldn't be relying upon this.  Luckily there is a very similar but
well defined syntax that allows us to still access these registers directly as
C variables, which is to simply declare the register variables globally.  For
fixed variables this doesn't change the ABI.

LLVM disallows this ambiguous syntax, so this isn't just strictly a formatting
change.

Signed-off-by: Palmer Dabbelt <palmerdabbelt@google.com>
(cherry picked from commit 52e7c52d2ded5908e6a4f8a7248e5fa6e0d6809a)
[tkjos: minor conflict resolution in arch/riscv/kernel/process.c]
Change-Id: Ie4f7852fc12c6e6c368948f17e8649b8a0447030
2024-11-21 00:44:34 +00:00
Brian Gerst
fd0bf47f62 UPSTREAM: x86/percpu: Clean up percpu_add_op()
The core percpu macros already have a switch on the data size, so the switch
in the x86 code is redundant and produces more dead code.

Also use appropriate types for the width of the instructions.  This avoids
errors when compiling with Clang.

Signed-off-by: Brian Gerst <brgerst@gmail.com>
Signed-off-by: Nick Desaulniers <ndesaulniers@google.com>
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
Tested-by: Nick Desaulniers <ndesaulniers@google.com>
Tested-by: Sedat Dilek <sedat.dilek@gmail.com>
Reviewed-by: Nick Desaulniers <ndesaulniers@google.com>
Acked-by: Linus Torvalds <torvalds@linux-foundation.org>
Acked-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Acked-by: Dennis Zhou <dennis@kernel.org>
Link: https://lkml.kernel.org/r/20200720204925.3654302-5-ndesaulniers@google.com
(cherry picked from commit 33e5614a435ff8047d768e6501454ae1cc7f131f)
Change-Id: Ibef6652f6f391fbd3bf494f029ec95b7a93a9f00
2024-11-20 22:56:12 +00:00
Brian Gerst
cdc0c697ab UPSTREAM: x86/percpu: Clean up percpu_from_op()
The core percpu macros already have a switch on the data size, so the switch
in the x86 code is redundant and produces more dead code.

Also use appropriate types for the width of the instructions.  This avoids
errors when compiling with Clang.

Signed-off-by: Brian Gerst <brgerst@gmail.com>
Signed-off-by: Nick Desaulniers <ndesaulniers@google.com>
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
Tested-by: Nick Desaulniers <ndesaulniers@google.com>
Tested-by: Sedat Dilek <sedat.dilek@gmail.com>
Reviewed-by: Nick Desaulniers <ndesaulniers@google.com>
Acked-by: Linus Torvalds <torvalds@linux-foundation.org>
Acked-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Acked-by: Dennis Zhou <dennis@kernel.org>
Link: https://lkml.kernel.org/r/20200720204925.3654302-4-ndesaulniers@google.com
(cherry picked from commit bb631e3002840706362a7d76e3ebb3604cce91a7)
Change-Id: Icd6ee9478ee2cb73f7013fc7407cd983ab2ca27c
2024-11-20 22:56:12 +00:00
Brian Gerst
c35e6d0025 UPSTREAM: x86/percpu: Clean up percpu_to_op()
The core percpu macros already have a switch on the data size, so the switch
in the x86 code is redundant and produces more dead code.

Also use appropriate types for the width of the instructions.  This avoids
errors when compiling with Clang.

Signed-off-by: Brian Gerst <brgerst@gmail.com>
Signed-off-by: Nick Desaulniers <ndesaulniers@google.com>
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
Tested-by: Nick Desaulniers <ndesaulniers@google.com>
Tested-by: Sedat Dilek <sedat.dilek@gmail.com>
Reviewed-by: Nick Desaulniers <ndesaulniers@google.com>
Acked-by: Linus Torvalds <torvalds@linux-foundation.org>
Acked-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Acked-by: Dennis Zhou <dennis@kernel.org>
Link: https://lkml.kernel.org/r/20200720204925.3654302-3-ndesaulniers@google.com
(cherry picked from commit c175acc14719e69ecec4dafbb642a7f38c76c064)
Change-Id: Ie1e84ec5704adcc3f97ce8bca184ed0cb20c5c0e
2024-11-20 22:56:12 +00:00
Brian Gerst
3cd2aa357f UPSTREAM: x86/percpu: Introduce size abstraction macros
In preparation for cleaning up the percpu operations, define macros for
abstraction based on the width of the operation.

Signed-off-by: Brian Gerst <brgerst@gmail.com>
Signed-off-by: Nick Desaulniers <ndesaulniers@google.com>
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
Tested-by: Nick Desaulniers <ndesaulniers@google.com>
Tested-by: Sedat Dilek <sedat.dilek@gmail.com>
Reviewed-by: Nick Desaulniers <ndesaulniers@google.com>
Acked-by: Linus Torvalds <torvalds@linux-foundation.org>
Acked-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Acked-by: Dennis Zhou <dennis@kernel.org>
Link: https://lkml.kernel.org/r/20200720204925.3654302-2-ndesaulniers@google.com
(cherry picked from 6865dc3ae93b9acb336ca48bd7b2db3446d89370)
Change-Id: I2dae7026b177761a14a0ad224e7ffba28fe5e5e2
2024-11-20 22:56:12 +00:00
Carlos Llamas
fd66950d54 BACKPORT: FROMGIT: binder: add delivered_freeze to debugfs output
Add the pending proc->delivered_freeze work to the debugfs output. This
information was omitted in the original implementation of the freeze
notification and can be valuable for debugging issues.

Fixes: d579b04a52a1 ("binder: frozen notification")
Cc: stable@vger.kernel.org
Signed-off-by: Carlos Llamas <cmllamas@google.com>
Acked-by: Todd Kjos <tkjos@google.com>
Reviewed-by: Alice Ryhl <aliceryhl@google.com>
Link: https://lore.kernel.org/r/20240926233632.821189-9-cmllamas@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

Bug: 366003708
(cherry picked from commit cb2aeb2ec25884133110ffe5a67ff3cf7dee5ceb
 git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc.git
 char-misc-next)
Change-Id: Ifc9a22b52e38c35af661732486fa1f154adb34de
[cmllamas: fix KMI break with proc_wrapper()]
Signed-off-by: Carlos Llamas <cmllamas@google.com>
2024-11-20 18:24:19 +00:00
Carlos Llamas
d7f2e2600f BACKPORT: FROMGIT: binder: fix memleak of proc->delivered_freeze
If a freeze notification is cleared with BC_CLEAR_FREEZE_NOTIFICATION
before calling binder_freeze_notification_done(), then it is detached
from its reference (e.g. ref->freeze) but the work remains queued in
proc->delivered_freeze. This leads to a memory leak when the process
exits as any pending entries in proc->delivered_freeze are not freed:

  unreferenced object 0xffff38e8cfa36180 (size 64):
    comm "binder-util", pid 655, jiffies 4294936641
    hex dump (first 32 bytes):
      b8 e9 9e c8 e8 38 ff ff b8 e9 9e c8 e8 38 ff ff  .....8.......8..
      0b 00 00 00 00 00 00 00 3c 1f 4b 00 00 00 00 00  ........<.K.....
    backtrace (crc 95983b32):
      [<000000000d0582cf>] kmemleak_alloc+0x34/0x40
      [<000000009c99a513>] __kmalloc_cache_noprof+0x208/0x280
      [<00000000313b1704>] binder_thread_write+0xdec/0x439c
      [<000000000cbd33bb>] binder_ioctl+0x1b68/0x22cc
      [<000000002bbedeeb>] __arm64_sys_ioctl+0x124/0x190
      [<00000000b439adee>] invoke_syscall+0x6c/0x254
      [<00000000173558fc>] el0_svc_common.constprop.0+0xac/0x230
      [<0000000084f72311>] do_el0_svc+0x40/0x58
      [<000000008b872457>] el0_svc+0x38/0x78
      [<00000000ee778653>] el0t_64_sync_handler+0x120/0x12c
      [<00000000a8ec61bf>] el0t_64_sync+0x190/0x194

This patch fixes the leak by ensuring that any pending entries in
proc->delivered_freeze are freed during binder_deferred_release().

Fixes: d579b04a52a1 ("binder: frozen notification")
Cc: stable@vger.kernel.org
Signed-off-by: Carlos Llamas <cmllamas@google.com>
Reviewed-by: Alice Ryhl <aliceryhl@google.com>
Acked-by: Todd Kjos <tkjos@google.com>
Link: https://lore.kernel.org/r/20240926233632.821189-8-cmllamas@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

Bug: 366003708
(cherry picked from commit 1db76ec2b4b206ff943e292a0b55e68ff3443598
 git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc.git
 char-misc-next)
Change-Id: Iafdec3421c521b4b591b94455deba7ee5102c8ca
[cmllamas: drop BINDER_STAT_FREEZE and use proc_wrapper()]
Signed-off-by: Carlos Llamas <cmllamas@google.com>
2024-11-20 18:24:19 +00:00
Carlos Llamas
00553a4558 FROMGIT: binder: allow freeze notification for dead nodes
Alice points out that binder_request_freeze_notification() should not
return EINVAL when the relevant node is dead [1]. The node can die at
any point even if the user input is valid. Instead, allow the request
to be allocated but skip the initial notification for dead nodes. This
avoids propagating unnecessary errors back to userspace.

Fixes: d579b04a52a1 ("binder: frozen notification")
Cc: stable@vger.kernel.org
Suggested-by: Alice Ryhl <aliceryhl@google.com>
Link: https://lore.kernel.org/all/CAH5fLghapZJ4PbbkC8V5A6Zay-_sgTzwVpwqk6RWWUNKKyJC_Q@mail.gmail.com/ [1]
Signed-off-by: Carlos Llamas <cmllamas@google.com>
Acked-by: Todd Kjos <tkjos@google.com>
Link: https://lore.kernel.org/r/20240926233632.821189-7-cmllamas@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

Bug: 366003708
(cherry picked from commit ca63c66935b978441055e3d87d30225267f99329
 git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc.git
 char-misc-next)
Change-Id: I03af1eedfeb194f5a775388cbb4e7487e4a5dfc0
Signed-off-by: Carlos Llamas <cmllamas@google.com>
2024-11-20 18:24:19 +00:00
Carlos Llamas
44e90a1218 FROMGIT: binder: fix BINDER_WORK_CLEAR_FREEZE_NOTIFICATION debug logs
proc 699
context binder-test
  thread 699: l 00 need_return 0 tr 0
  ref 25: desc 1 node 20 s 1 w 0 d 00000000c03e09a3
  unknown work: type 11

proc 640
context binder-test
  thread 640: l 00 need_return 0 tr 0
  ref 8: desc 1 node 3 s 1 w 0 d 000000002bb493e1
  has cleared freeze notification

Fixes: d579b04a52a1 ("binder: frozen notification")
Cc: stable@vger.kernel.org
Suggested-by: Alice Ryhl <aliceryhl@google.com>
Signed-off-by: Carlos Llamas <cmllamas@google.com>
Reviewed-by: Alice Ryhl <aliceryhl@google.com>
Acked-by: Todd Kjos <tkjos@google.com>
Link: https://lore.kernel.org/r/20240926233632.821189-6-cmllamas@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

Bug: 366003708
(cherry picked from commit 595ea72efff9fa65bc52b6406e0822f90841f266
 git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc.git
 char-misc-next)
Change-Id: Ic6311aaea2040aaf4534cdaa4cbfa378afe31869
Signed-off-by: Carlos Llamas <cmllamas@google.com>
2024-11-20 18:24:19 +00:00
Carlos Llamas
4942a6719a FROMGIT: binder: fix BINDER_WORK_FROZEN_BINDER debug logs
The BINDER_WORK_FROZEN_BINDER type is not handled in the binder_logs
entries and it shows up as "unknown work" when logged:

  proc 649
  context binder-test
    thread 649: l 00 need_return 0 tr 0
    ref 13: desc 1 node 8 s 1 w 0 d 0000000053c4c0c3
    unknown work: type 10

This patch add the freeze work type and is now logged as such:

  proc 637
  context binder-test
    thread 637: l 00 need_return 0 tr 0
    ref 8: desc 1 node 3 s 1 w 0 d 00000000dc39e9c6
    has frozen binder

Fixes: d579b04a52a1 ("binder: frozen notification")
Cc: stable@vger.kernel.org
Acked-by: Todd Kjos <tkjos@google.com>
Signed-off-by: Carlos Llamas <cmllamas@google.com>
Reviewed-by: Alice Ryhl <aliceryhl@google.com>
Link: https://lore.kernel.org/r/20240926233632.821189-5-cmllamas@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

Bug: 366003708
(cherry picked from commit 830d7db744b42c693bf1db7e94db86d7efd91f0e
 git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc.git
 char-misc-next)
Change-Id: I06f888aa5218db19eeda79e315385506af09d9d5
Signed-off-by: Carlos Llamas <cmllamas@google.com>
2024-11-20 18:24:18 +00:00
Carlos Llamas
dd5ff84365 BACKPORT: FROMGIT: binder: fix freeze UAF in binder_release_work()
When a binder reference is cleaned up, any freeze work queued in the
associated process should also be removed. Otherwise, the reference is
freed while its ref->freeze.work is still queued in proc->work leading
to a use-after-free issue as shown by the following KASAN report:

  ==================================================================
  BUG: KASAN: slab-use-after-free in binder_release_work+0x398/0x3d0
  Read of size 8 at addr ffff31600ee91488 by task kworker/5:1/211

  CPU: 5 UID: 0 PID: 211 Comm: kworker/5:1 Not tainted 6.11.0-rc7-00382-gfc6c92196396 #22
  Hardware name: linux,dummy-virt (DT)
  Workqueue: events binder_deferred_func
  Call trace:
   binder_release_work+0x398/0x3d0
   binder_deferred_func+0xb60/0x109c
   process_one_work+0x51c/0xbd4
   worker_thread+0x608/0xee8

  Allocated by task 703:
   __kmalloc_cache_noprof+0x130/0x280
   binder_thread_write+0xdb4/0x42a0
   binder_ioctl+0x18f0/0x25ac
   __arm64_sys_ioctl+0x124/0x190
   invoke_syscall+0x6c/0x254

  Freed by task 211:
   kfree+0xc4/0x230
   binder_deferred_func+0xae8/0x109c
   process_one_work+0x51c/0xbd4
   worker_thread+0x608/0xee8
  ==================================================================

This commit fixes the issue by ensuring any queued freeze work is removed
when cleaning up a binder reference.

Fixes: d579b04a52a1 ("binder: frozen notification")
Cc: stable@vger.kernel.org
Acked-by: Todd Kjos <tkjos@android.com>
Reviewed-by: Alice Ryhl <aliceryhl@google.com>
Signed-off-by: Carlos Llamas <cmllamas@google.com>
Link: https://lore.kernel.org/r/20240926233632.821189-4-cmllamas@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

Bug: 366003708
(cherry picked from commit 7e20434cbca814cb91a0a261ca0106815ef48e5f
 git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc.git
 char-misc-next)
Change-Id: Icc40e7dd6157981f4adbea7243e55be118552321
[cmllamas: drop BINDER_STAT_FREEZE as it's not supported here]
Signed-off-by: Carlos Llamas <cmllamas@google.com>
2024-11-20 18:24:18 +00:00
Carlos Llamas
6953269824 FROMGIT: binder: fix OOB in binder_add_freeze_work()
In binder_add_freeze_work() we iterate over the proc->nodes with the
proc->inner_lock held. However, this lock is temporarily dropped to
acquire the node->lock first (lock nesting order). This can race with
binder_deferred_release() which removes the nodes from the proc->nodes
rbtree and adds them into binder_dead_nodes list. This leads to a broken
iteration in binder_add_freeze_work() as rb_next() will use data from
binder_dead_nodes, triggering an out-of-bounds access:

  ==================================================================
  BUG: KASAN: global-out-of-bounds in rb_next+0xfc/0x124
  Read of size 8 at addr ffffcb84285f7170 by task freeze/660

  CPU: 8 UID: 0 PID: 660 Comm: freeze Not tainted 6.11.0-07343-ga727812a8d45 #18
  Hardware name: linux,dummy-virt (DT)
  Call trace:
   rb_next+0xfc/0x124
   binder_add_freeze_work+0x344/0x534
   binder_ioctl+0x1e70/0x25ac
   __arm64_sys_ioctl+0x124/0x190

  The buggy address belongs to the variable:
   binder_dead_nodes+0x10/0x40
  [...]
  ==================================================================

This is possible because proc->nodes (rbtree) and binder_dead_nodes
(list) share entries in binder_node through a union:

	struct binder_node {
	[...]
		union {
			struct rb_node rb_node;
			struct hlist_node dead_node;
		};

Fix the race by checking that the proc is still alive. If not, simply
break out of the iteration.

Fixes: d579b04a52a1 ("binder: frozen notification")
Cc: stable@vger.kernel.org
Reviewed-by: Alice Ryhl <aliceryhl@google.com>
Acked-by: Todd Kjos <tkjos@google.com>
Signed-off-by: Carlos Llamas <cmllamas@google.com>
Link: https://lore.kernel.org/r/20240926233632.821189-3-cmllamas@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

Bug: 366003708
(cherry picked from commit 011e69a1b23011c0db3af4b8293fdd4522cc97b0
 git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc.git
 char-misc-next)
Change-Id: I5ec9d49277a23b864862665b52213460750c535e
Signed-off-by: Carlos Llamas <cmllamas@google.com>
2024-11-20 18:24:18 +00:00
Carlos Llamas
b6005f2f2c FROMGIT: binder: fix node UAF in binder_add_freeze_work()
In binder_add_freeze_work() we iterate over the proc->nodes with the
proc->inner_lock held. However, this lock is temporarily dropped in
order to acquire the node->lock first (lock nesting order). This can
race with binder_node_release() and trigger a use-after-free:

  ==================================================================
  BUG: KASAN: slab-use-after-free in _raw_spin_lock+0xe4/0x19c
  Write of size 4 at addr ffff53c04c29dd04 by task freeze/640

  CPU: 5 UID: 0 PID: 640 Comm: freeze Not tainted 6.11.0-07343-ga727812a8d45 #17
  Hardware name: linux,dummy-virt (DT)
  Call trace:
   _raw_spin_lock+0xe4/0x19c
   binder_add_freeze_work+0x148/0x478
   binder_ioctl+0x1e70/0x25ac
   __arm64_sys_ioctl+0x124/0x190

  Allocated by task 637:
   __kmalloc_cache_noprof+0x12c/0x27c
   binder_new_node+0x50/0x700
   binder_transaction+0x35ac/0x6f74
   binder_thread_write+0xfb8/0x42a0
   binder_ioctl+0x18f0/0x25ac
   __arm64_sys_ioctl+0x124/0x190

  Freed by task 637:
   kfree+0xf0/0x330
   binder_thread_read+0x1e88/0x3a68
   binder_ioctl+0x16d8/0x25ac
   __arm64_sys_ioctl+0x124/0x190
  ==================================================================

Fix the race by taking a temporary reference on the node before
releasing the proc->inner lock. This ensures the node remains alive
while in use.

Fixes: d579b04a52a1 ("binder: frozen notification")
Cc: stable@vger.kernel.org
Reviewed-by: Alice Ryhl <aliceryhl@google.com>
Acked-by: Todd Kjos <tkjos@google.com>
Signed-off-by: Carlos Llamas <cmllamas@google.com>
Link: https://lore.kernel.org/r/20240926233632.821189-2-cmllamas@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

Bug: 366003708
(cherry picked from commit dc8aea47b928cc153b591b3558829ce42f685074
 git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc.git
 char-misc-next)
Change-Id: I47b053532dd4cd3424d35d6f254ca4d00c426411
Signed-off-by: Carlos Llamas <cmllamas@google.com>
2024-11-20 18:24:18 +00:00
Greg Kroah-Hartman
da1a77953e This is the 5.4.286 stable release
-----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCAAdFiEEZH8oZUiU471FcZm+ONu9yGCSaT4FAmc59qQACgkQONu9yGCS
 aT5mhRAAhpdEEcKgaikNdpvwRFb39OTRbuuumMAkBK1kG+YEC+zbOWJqTIrapJAu
 d70l6JVdGjK9JNn7bGH8laY+kdV9VLZWVyI1vrCG6eRSWe2G3ReAUoyHT50f+OG5
 mvLisZOT+8H+Tt1wumTcqpsj+Adg0QzIzk9VKcBV1nXZ6a2lzF5Optkq00nRYf2y
 +G2Yal731UstM141Ym7L3NTg8s6QpHeWMcAzy1RQprzufdHro2k1AVvKnCHIHLFi
 lDvOLrXMuVvOZvqZjKpB8TuirTwxtrJoH3RmqClVqqyruCJ0Cggl5kFN2AP9XqqI
 5/mgxZv2Y76YPZC+Y2dB52aPXldJrCb8o0TfPuRYc86RKi/+f30j634gdkulEkJQ
 uGTjDkKbgjns0MwaYtb7l2yzb6zwEHLB/O8wHIA4hwTzlDAFvhcvmdw6dmAR6ti/
 HaqOuSEUkH6CseZvDV8g3STXA6F3k8/AjZGEWO0rSwKJC0sYXm+y4E6WeJJVbs/4
 qJXPdJepHDKHc0BJYoGrRm/O0BzLlqoW7bnuHji//7UYVW7xwCuT9oogV18iBxul
 opmNeBk67WHyWwp104F1miC85vDwl8WgpMG48BFUy4p6wugs0ko9bvawuX+ZRQ4T
 EXHdV8GtFVdE3uNrEkjPGllvLGocX7MLRdb2O7I63h2hQ5kfQGM=
 =0azH
 -----END PGP SIGNATURE-----

Merge 5.4.286 into android11-5.4-lts

Changes in 5.4.286
	arm64: dts: rockchip: Fix rt5651 compatible value on rk3399-sapphire-excavator
	arm64: dts: rockchip: Remove hdmi's 2nd interrupt on rk3328
	arm64: dts: rockchip: Fix bluetooth properties on Rock960 boards
	arm64: dts: rockchip: Remove #cooling-cells from fan on Theobroma lion
	ARM: dts: rockchip: fix rk3036 acodec node
	ARM: dts: rockchip: drop grf reference from rk3036 hdmi
	ARM: dts: rockchip: Fix the spi controller on rk3036
	ARM: dts: rockchip: Fix the realtek audio codec on rk3036-kylin
	HID: core: zero-initialize the report buffer
	security/keys: fix slab-out-of-bounds in key_task_permission
	enetc: simplify the return expression of enetc_vf_set_mac_addr()
	net: enetc: set MAC address to the VF net_device
	sctp: properly validate chunk size in sctp_sf_ootb()
	can: c_can: fix {rx,tx}_errors statistics
	net: hns3: fix kernel crash when uninstalling driver
	media: stb0899_algo: initialize cfr before using it
	media: dvbdev: prevent the risk of out of memory access
	media: dvb_frontend: don't play tricks with underflow values
	media: adv7604: prevent underflow condition when reporting colorspace
	ALSA: firewire-lib: fix return value on fail in amdtp_tscm_init()
	media: s5p-jpeg: prevent buffer overflows
	media: cx24116: prevent overflows on SNR calculus
	media: v4l2-tpg: prevent the risk of a division by zero
	pwm: imx-tpm: Use correct MODULO value for EPWM mode
	drm/amdgpu: add missing size check in amdgpu_debugfs_gprwave_read()
	drm/amdgpu: prevent NULL pointer dereference if ATIF is not supported
	dm cache: correct the number of origin blocks to match the target length
	dm cache: fix out-of-bounds access to the dirty bitset when resizing
	dm cache: optimize dirty bit checking with find_next_bit when resizing
	dm cache: fix potential out-of-bounds access on the first resume
	dm-unstriped: cast an operand to sector_t to prevent potential uint32_t overflow
	nfs: Fix KMSAN warning in decode_getfattr_attrs()
	btrfs: reinitialize delayed ref list after deleting it from the list
	mtd: rawnand: protect access to rawnand devices while in suspend
	spi: Fix deadlock when adding SPI controllers on SPI buses
	spi: fix use-after-free of the add_lock mutex
	net: bridge: xmit: make sure we have at least eth header len bytes
	media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format
	fs/proc: fix compile warning about variable 'vmcore_mmap_ops'
	usb: musb: sunxi: Fix accessing an released usb phy
	USB: serial: io_edgeport: fix use after free in debug printk
	USB: serial: qcserial: add support for Sierra Wireless EM86xx
	USB: serial: option: add Fibocom FG132 0x0112 composition
	USB: serial: option: add Quectel RG650V
	irqchip/gic-v3: Force propagation of the active state with a read-back
	ocfs2: remove entry once instead of null-ptr-dereference in ocfs2_xa_remove()
	ALSA: usb-audio: Support jack detection on Dell dock
	ALSA: usb-audio: Add quirks for Dell WD19 dock
	NFSD: Fix NFSv4's PUTPUBFH operation
	ftrace: Fix possible use-after-free issue in ftrace_location()
	hv_sock: Initializing vsk->trans to NULL to prevent a dangling pointer
	vsock/virtio: Initialization of the dangling pointer occurring in vsk->trans
	ALSA: usb-audio: Add endianness annotations
	9p: Avoid creating multiple slab caches with the same name
	HID: multitouch: Add quirk for HONOR MagicBook Art 14 touchpad
	bpf: use kvzmalloc to allocate BPF verifier environment
	sound: Make CONFIG_SND depend on INDIRECT_IOMEM instead of UML
	powerpc/powernv: Free name on error in opal_event_init()
	fs: Fix uninitialized value issue in from_kuid and from_kgid
	net: usb: qmi_wwan: add Fibocom FG132 0x0112 composition
	md/raid10: improve code of mrdev in raid10_sync_request
	mm: clarify a confusing comment for remap_pfn_range()
	mm: fix ambiguous comments for better code readability
	mm/memory.c: make remap_pfn_range() reject unaligned addr
	mm: add remap_pfn_range_notrack
	9p: fix slab cache name creation for real
	mm: avoid leaving partial pfn mappings around in error case
	Linux 5.4.286

Change-Id: I924a69c454558bcb9f11b3748a31c15349b3a705
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-11-17 20:07:37 +00:00
Greg Kroah-Hartman
cd5b619ac4 Linux 5.4.286
Link: https://lore.kernel.org/r/20241115063722.834793938@linuxfoundation.org
Tested-by: Harshit Mogalapalli <harshit.m.mogalapalli@oracle.com>
Link: https://lore.kernel.org/r/20241115120451.517948500@linuxfoundation.org
Tested-by: Jon Hunter <jonathanh@nvidia.com>
Tested-by: Florian Fainelli <florian.fainelli@broadcom.com>
Tested-by: Linux Kernel Functional Testing <lkft@linaro.org>
Tested-by: Shuah Khan <skhan@linuxfoundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-11-17 14:58:53 +01:00
Linus Torvalds
3213fdcab9 mm: avoid leaving partial pfn mappings around in error case
commit 79a61cc3fc0466ad2b7b89618a6157785f0293b3 upstream.

As Jann points out, PFN mappings are special, because unlike normal
memory mappings, there is no lifetime information associated with the
mapping - it is just a raw mapping of PFNs with no reference counting of
a 'struct page'.

That's all very much intentional, but it does mean that it's easy to
mess up the cleanup in case of errors.  Yes, a failed mmap() will always
eventually clean up any partial mappings, but without any explicit
lifetime in the page table mapping itself, it's very easy to do the
error handling in the wrong order.

In particular, it's easy to mistakenly free the physical backing store
before the page tables are actually cleaned up and (temporarily) have
stale dangling PTE entries.

To make this situation less error-prone, just make sure that any partial
pfn mapping is torn down early, before any other error handling.

Reported-and-tested-by: Jann Horn <jannh@google.com>
Cc: Andrew Morton <akpm@linux-foundation.org>
Cc: Jason Gunthorpe <jgg@ziepe.ca>
Cc: Simona Vetter <simona.vetter@ffwll.ch>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Harshvardhan Jha <harshvardhan.j.jha@oracle.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-11-17 14:58:53 +01:00
Linus Torvalds
cfb280cc3b 9p: fix slab cache name creation for real
commit a360f311f57a36e96d88fa8086b749159714dcd2 upstream.

This was attempted by using the dev_name in the slab cache name, but as
Omar Sandoval pointed out, that can be an arbitrary string, eg something
like "/dev/root".  Which in turn trips verify_dirent_name(), which fails
if a filename contains a slash.

So just make it use a sequence counter, and make it an atomic_t to avoid
any possible races or locking issues.

Reported-and-tested-by: Omar Sandoval <osandov@fb.com>
Link: https://lore.kernel.org/all/ZxafcO8KWMlXaeWE@telecaster.dhcp.thefacebook.com/
Fixes: 79efebae4afc ("9p: Avoid creating multiple slab caches with the same name")
Acked-by: Vlastimil Babka <vbabka@suse.cz>
Cc: Dominique Martinet <asmadeus@codewreck.org>
Cc: Thorsten Leemhuis <regressions@leemhuis.info>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-11-17 14:58:53 +01:00
Christoph Hellwig
b97a50adb3 mm: add remap_pfn_range_notrack
commit 74ffa5a3e68504dd289135b1cf0422c19ffb3f2e upstream.

Patch series "add remap_pfn_range_notrack instead of reinventing it in i915", v2.

i915 has some reason to want to avoid the track_pfn_remap overhead in
remap_pfn_range.  Add a function to the core VM to do just that rather
than reinventing the functionality poorly in the driver.

Note that the remap_io_sg path does get exercises when using Xorg on my
Thinkpad X1, so this should be considered lightly tested, I've not managed
to hit the remap_io_mapping path at all.

This patch (of 4):

Add a version of remap_pfn_range that does not call track_pfn_range.  This
will be used to fix horrible abuses of VM internals in the i915 driver.

Link: https://lkml.kernel.org/r/20210326055505.1424432-1-hch@lst.de
Link: https://lkml.kernel.org/r/20210326055505.1424432-2-hch@lst.de
Signed-off-by: Christoph Hellwig <hch@lst.de>
Acked-by: Daniel Vetter <daniel.vetter@ffwll.ch>
Cc: Jani Nikula <jani.nikula@linux.intel.com>
Cc: Joonas Lahtinen <joonas.lahtinen@linux.intel.com>
Cc: Rodrigo Vivi <rodrigo.vivi@intel.com>
Cc: Chris Wilson <chris@chris-wilson.co.uk>
Cc: Peter Zijlstra <peterz@infradead.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
(cherry picked from commit 69d4e1ce9087c8767f2fe9b9426fa2755c8e9072)
Signed-off-by: Harshvardhan Jha <harshvardhan.j.jha@oracle.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-11-17 14:58:53 +01:00
Alex Zhang
00106a045d mm/memory.c: make remap_pfn_range() reject unaligned addr
commit 0c4123e3fb82d6014d0a70b52eb38153f658541c upstream.

This function implicitly assumes that the addr passed in is page aligned.
A non page aligned addr could ultimately cause a kernel bug in
remap_pte_range as the exit condition in the logic loop may never be
satisfied.  This patch documents the need for the requirement, as well as
explicitly adds a check for it.

Signed-off-by: Alex Zhang <zhangalex@google.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Reviewed-by: Andrew Morton <akpm@linux-foundation.org>
Link: http://lkml.kernel.org/r/20200617233512.177519-1-zhangalex@google.com
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Harshvardhan Jha <harshvardhan.j.jha@oracle.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-11-17 14:58:53 +01:00
chenqiwu
e681c83006 mm: fix ambiguous comments for better code readability
commit 552657b7b3343851916fde7e4fd6bfb6516d2bcb upstream.

The parameter of remap_pfn_range() @pfn passed from the caller is actually
a page-frame number converted by corresponding physical address of kernel
memory, the original comment is ambiguous that may mislead the users.

Meanwhile, there is an ambiguous typo "VMM" in the comment of
vm_area_struct.  So fixing them will make the code more readable.

Signed-off-by: chenqiwu <chenqiwu@xiaomi.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Reviewed-by: Andrew Morton <akpm@linux-foundation.org>
Link: http://lkml.kernel.org/r/1583026921-15279-1-git-send-email-qiwuchen55@gmail.com
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Harshvardhan Jha <harshvardhan.j.jha@oracle.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-11-17 14:58:53 +01:00
WANG Wenhu
31ccf3b44e mm: clarify a confusing comment for remap_pfn_range()
commit 86a76331d94c4cfa72fe1831dbe4b492f66fdb81 upstream.

It really made me scratch my head.  Replace the comment with an accurate
and consistent description.

The parameter pfn actually refers to the page frame number which is
right-shifted by PAGE_SHIFT from the physical address.

Signed-off-by: WANG Wenhu <wenhu.wang@vivo.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Reviewed-by: Andrew Morton <akpm@linux-foundation.org>
Link: http://lkml.kernel.org/r/20200310073955.43415-1-wenhu.wang@vivo.com
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Harshvardhan Jha <harshvardhan.j.jha@oracle.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-11-17 14:58:53 +01:00
Li Nan
882e4c6a3b md/raid10: improve code of mrdev in raid10_sync_request
commit 59f8f0b54c8ffb4521f6bbd1cb6f4dfa5022e75e upstream.

'need_recover' and 'mrdev' are equivalent in raid10_sync_request(), and
inc mrdev->nr_pending is unreasonable if don't need recovery. Replace
'need_recover' with 'mrdev', and only inc nr_pending when needed.

Signed-off-by: Li Nan <linan122@huawei.com>
Reviewed-by: Yu Kuai <yukuai3@huawei.com>
Signed-off-by: Song Liu <song@kernel.org>
Link: https://lore.kernel.org/r/20230527072218.2365857-3-linan666@huaweicloud.com
Cc: Hagar Gamal Halim <hagarhem@amazon.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-11-17 14:58:53 +01:00
Reinhard Speyerer
8bb1d617a3 net: usb: qmi_wwan: add Fibocom FG132 0x0112 composition
[ Upstream commit 64761c980cbf71fb7a532a8c7299907ea972a88c ]

Add Fibocom FG132 0x0112 composition:

T:  Bus=03 Lev=02 Prnt=06 Port=01 Cnt=02 Dev#= 10 Spd=12   MxCh= 0
D:  Ver= 2.01 Cls=00(>ifc ) Sub=00 Prot=00 MxPS=64 #Cfgs=  1
P:  Vendor=2cb7 ProdID=0112 Rev= 5.15
S:  Manufacturer=Fibocom Wireless Inc.
S:  Product=Fibocom Module
S:  SerialNumber=xxxxxxxx
C:* #Ifs= 4 Cfg#= 1 Atr=a0 MxPwr=500mA
I:* If#= 0 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=ff Prot=50 Driver=qmi_wwan
E:  Ad=82(I) Atr=03(Int.) MxPS=   8 Ivl=32ms
E:  Ad=81(I) Atr=02(Bulk) MxPS=  64 Ivl=0ms
E:  Ad=01(O) Atr=02(Bulk) MxPS=  64 Ivl=0ms
I:* If#= 1 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=ff Prot=30 Driver=option
E:  Ad=02(O) Atr=02(Bulk) MxPS=  64 Ivl=0ms
E:  Ad=83(I) Atr=02(Bulk) MxPS=  64 Ivl=0ms
I:* If#= 2 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=ff Prot=40 Driver=option
E:  Ad=85(I) Atr=03(Int.) MxPS=  10 Ivl=32ms
E:  Ad=84(I) Atr=02(Bulk) MxPS=  64 Ivl=0ms
E:  Ad=03(O) Atr=02(Bulk) MxPS=  64 Ivl=0ms
I:* If#= 3 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=00 Prot=00 Driver=option
E:  Ad=86(I) Atr=02(Bulk) MxPS=  64 Ivl=0ms
E:  Ad=04(O) Atr=02(Bulk) MxPS=  64 Ivl=0ms

Signed-off-by: Reinhard Speyerer <rspmn@arcor.de>

Link: https://patch.msgid.link/ZxLKp5YZDy-OM0-e@arcor.de
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-11-17 14:58:53 +01:00
Alessandro Zanni
17ecb40c5c fs: Fix uninitialized value issue in from_kuid and from_kgid
[ Upstream commit 15f34347481648a567db67fb473c23befb796af5 ]

ocfs2_setattr() uses attr->ia_mode, attr->ia_uid and attr->ia_gid in
a trace point even though ATTR_MODE, ATTR_UID and ATTR_GID aren't set.

Initialize all fields of newattrs to avoid uninitialized variables, by
checking if ATTR_MODE, ATTR_UID, ATTR_GID are initialized, otherwise 0.

Reported-by: syzbot+6c55f725d1bdc8c52058@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=6c55f725d1bdc8c52058
Signed-off-by: Alessandro Zanni <alessandro.zanni87@gmail.com>
Link: https://lore.kernel.org/r/20241017120553.55331-1-alessandro.zanni87@gmail.com
Reviewed-by: Jan Kara <jack@suse.cz>
Signed-off-by: Christian Brauner <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-11-17 14:58:53 +01:00
Michael Ellerman
45eadf46ff powerpc/powernv: Free name on error in opal_event_init()
[ Upstream commit cf8989d20d64ad702a6210c11a0347ebf3852aa7 ]

In opal_event_init() if request_irq() fails name is not freed, leading
to a memory leak. The code only runs at boot time, there's no way for a
user to trigger it, so there's no security impact.

Fix the leak by freeing name in the error path.

Reported-by: 2639161967 <2639161967@qq.com>
Closes: https://lore.kernel.org/linuxppc-dev/87wmjp3wig.fsf@mail.lhotse
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
Link: https://patch.msgid.link/20240920093520.67997-1-mpe@ellerman.id.au
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-11-17 14:58:53 +01:00
Julian Vetter
1fe7d27e6a sound: Make CONFIG_SND depend on INDIRECT_IOMEM instead of UML
[ Upstream commit ad6639f143a0b42d7fb110ad14f5949f7c218890 ]

When building for the UM arch and neither INDIRECT_IOMEM=y, nor
HAS_IOMEM=y is selected, it will fall back to the implementations from
asm-generic/io.h for IO memcpy. But these fall-back functions just do a
memcpy. So, instead of depending on UML, add dependency on 'HAS_IOMEM ||
INDIRECT_IOMEM'.

Reviewed-by: Yann Sionneau <ysionneau@kalrayinc.com>
Signed-off-by: Julian Vetter <jvetter@kalrayinc.com>
Link: https://patch.msgid.link/20241010124601.700528-1-jvetter@kalrayinc.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-11-17 14:58:53 +01:00
Rik van Riel
c868a06a3f bpf: use kvzmalloc to allocate BPF verifier environment
[ Upstream commit 434247637c66e1be2bc71a9987d4c3f0d8672387 ]

The kzmalloc call in bpf_check can fail when memory is very fragmented,
which in turn can lead to an OOM kill.

Use kvzmalloc to fall back to vmalloc when memory is too fragmented to
allocate an order 3 sized bpf verifier environment.

Admittedly this is not a very common case, and only happens on systems
where memory has already been squeezed close to the limit, but this does
not seem like much of a hot path, and it's a simple enough fix.

Signed-off-by: Rik van Riel <riel@surriel.com>
Reviewed-by: Shakeel Butt <shakeel.butt@linux.dev>
Link: https://lore.kernel.org/r/20241008170735.16766766@imladris.surriel.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-11-17 14:58:53 +01:00
WangYuli
a8a1c7fe27 HID: multitouch: Add quirk for HONOR MagicBook Art 14 touchpad
[ Upstream commit 7a5ab8071114344f62a8b1e64ed3452a77257d76 ]

The behavior of HONOR MagicBook Art 14 touchpad is not consistent
after reboots, as sometimes it reports itself as a touchpad, and
sometimes as a mouse.

Similarly to GLO-GXXX it is possible to call MT_QUIRK_FORCE_GET_FEATURE as a
workaround to force set feature in mt_set_input_mode() for such special touchpad
device.

[jkosina@suse.com: reword changelog a little bit]
Link: https://gitlab.freedesktop.org/libinput/libinput/-/issues/1040
Signed-off-by: Wentao Guan <guanwentao@uniontech.com>
Signed-off-by: WangYuli <wangyuli@uniontech.com>
Reviewed-by: Benjamin Tissoires <bentiss@kernel.org>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-11-17 14:58:53 +01:00
Pedro Falcato
9c28c5edc8 9p: Avoid creating multiple slab caches with the same name
[ Upstream commit 79efebae4afc2221fa814c3cae001bede66ab259 ]

In the spirit of [1], avoid creating multiple slab caches with the same
name. Instead, add the dev_name into the mix.

[1]: https://lore.kernel.org/all/20240807090746.2146479-1-pedro.falcato@gmail.com/

Signed-off-by: Pedro Falcato <pedro.falcato@gmail.com>
Reported-by: syzbot+3c5d43e97993e1fa612b@syzkaller.appspotmail.com
Message-ID: <20240807094725.2193423-1-pedro.falcato@gmail.com>
Signed-off-by: Dominique Martinet <asmadeus@codewreck.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-11-17 14:58:53 +01:00
Jan Schär
fae6fcef17 ALSA: usb-audio: Add endianness annotations
commit 61c606a43b6c74556e35acc645c7a1b6a67c2af9 upstream.

Fixes: 4b8ea38fabab ("ALSA: usb-audio: Support jack detection on Dell dock")
Reported-by: kernel test robot <lkp@intel.com>
Link: https://lore.kernel.org/r/202207051932.qUilU0am-lkp@intel.com
Signed-off-by: Jan Schär <jan@jschaer.ch>
Link: https://lore.kernel.org/r/20220705135746.13713-1-jan@jschaer.ch
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-11-17 14:58:52 +01:00
Hyunwoo Kim
fd8ae34669 vsock/virtio: Initialization of the dangling pointer occurring in vsk->trans
commit 6ca575374dd9a507cdd16dfa0e78c2e9e20bd05f upstream.

During loopback communication, a dangling pointer can be created in
vsk->trans, potentially leading to a Use-After-Free condition.  This
issue is resolved by initializing vsk->trans to NULL.

Cc: stable <stable@kernel.org>
Fixes: 06a8fc7836 ("VSOCK: Introduce virtio_vsock_common.ko")
Signed-off-by: Hyunwoo Kim <v4bel@theori.io>
Signed-off-by: Wongi Lee <qwerty@theori.io>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Message-Id: <2024102245-strive-crib-c8d3@gregkh>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-11-17 14:58:52 +01:00
Hyunwoo Kim
4fe1d42f2a hv_sock: Initializing vsk->trans to NULL to prevent a dangling pointer
commit e629295bd60abf4da1db85b82819ca6a4f6c1e79 upstream.

When hvs is released, there is a possibility that vsk->trans may not
be initialized to NULL, which could lead to a dangling pointer.
This issue is resolved by initializing vsk->trans to NULL.

Signed-off-by: Hyunwoo Kim <v4bel@theori.io>
Reviewed-by: Stefano Garzarella <sgarzare@redhat.com>
Acked-by: Michael S. Tsirkin <mst@redhat.com>
Link: https://patch.msgid.link/Zys4hCj61V+mQfX2@v4bel-B760M-AORUS-ELITE-AX
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-11-17 14:58:52 +01:00
Zheng Yejian
eea46baf14 ftrace: Fix possible use-after-free issue in ftrace_location()
commit e60b613df8b6253def41215402f72986fee3fc8d upstream.

KASAN reports a bug:

  BUG: KASAN: use-after-free in ftrace_location+0x90/0x120
  Read of size 8 at addr ffff888141d40010 by task insmod/424
  CPU: 8 PID: 424 Comm: insmod Tainted: G        W          6.9.0-rc2+
  [...]
  Call Trace:
   <TASK>
   dump_stack_lvl+0x68/0xa0
   print_report+0xcf/0x610
   kasan_report+0xb5/0xe0
   ftrace_location+0x90/0x120
   register_kprobe+0x14b/0xa40
   kprobe_init+0x2d/0xff0 [kprobe_example]
   do_one_initcall+0x8f/0x2d0
   do_init_module+0x13a/0x3c0
   load_module+0x3082/0x33d0
   init_module_from_file+0xd2/0x130
   __x64_sys_finit_module+0x306/0x440
   do_syscall_64+0x68/0x140
   entry_SYSCALL_64_after_hwframe+0x71/0x79

The root cause is that, in lookup_rec(), ftrace record of some address
is being searched in ftrace pages of some module, but those ftrace pages
at the same time is being freed in ftrace_release_mod() as the
corresponding module is being deleted:

           CPU1                       |      CPU2
  register_kprobes() {                | delete_module() {
    check_kprobe_address_safe() {     |
      arch_check_ftrace_location() {  |
        ftrace_location() {           |
          lookup_rec() // USE!        |   ftrace_release_mod() // Free!

To fix this issue:
  1. Hold rcu lock as accessing ftrace pages in ftrace_location_range();
  2. Use ftrace_location_range() instead of lookup_rec() in
     ftrace_location();
  3. Call synchronize_rcu() before freeing any ftrace pages both in
     ftrace_process_locs()/ftrace_release_mod()/ftrace_free_mem().

Link: https://lore.kernel.org/linux-trace-kernel/20240509192859.1273558-1-zhengyejian1@huawei.com

Cc: stable@vger.kernel.org
Cc: <mhiramat@kernel.org>
Cc: <mark.rutland@arm.com>
Cc: <mathieu.desnoyers@efficios.com>
Fixes: ae6aa16fdc ("kprobes: introduce ftrace based optimization")
Suggested-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Zheng Yejian <zhengyejian1@huawei.com>
Signed-off-by: Steven Rostedt (Google) <rostedt@goodmis.org>
[Hagar: Modified to apply on v5.4.y]
Signed-off-by: Hagar Hemdan <hagarhem@amazon.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-11-17 14:58:52 +01:00
Chuck Lever
52300eb17e NFSD: Fix NFSv4's PUTPUBFH operation
commit 202f39039a11402dcbcd5fece8d9fa6be83f49ae upstream.

According to RFC 8881, all minor versions of NFSv4 support PUTPUBFH.

Replace the XDR decoder for PUTPUBFH with a "noop" since we no
longer want the minorversion check, and PUTPUBFH has no arguments to
decode. (Ideally nfsd4_decode_noop should really be called
nfsd4_decode_void).

PUTPUBFH should now behave just like PUTROOTFH.

Reported-by: Cedric Blancher <cedric.blancher@gmail.com>
Fixes: e1a90ebd8b ("NFSD: Combine decode operations for v4 and v4.1")
Cc: Dan Shelton <dan.f.shelton@gmail.com>
Cc: Roland Mainz <roland.mainz@nrubsig.org>
Cc: stable@vger.kernel.org
[ cel: adjusted to apply to origin/linux-5.4.y ]
Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-11-17 14:58:52 +01:00
Jan Schär
56fa2e5dec ALSA: usb-audio: Add quirks for Dell WD19 dock
[ Upstream commit 4413665dd6c528b31284119e3571c25f371e1c36 ]

The WD19 family of docks has the same audio chipset as the WD15. This
change enables jack detection on the WD19.

We don't need the dell_dock_mixer_init quirk for the WD19. It is only
needed because of the dell_alc4020_map quirk for the WD15 in
mixer_maps.c, which disables the volume controls. Even for the WD15,
this quirk was apparently only needed when the dock firmware was not
updated.

Signed-off-by: Jan Schär <jan@jschaer.ch>
Cc: <stable@vger.kernel.org>
Link: https://patch.msgid.link/20241029221249.15661-1-jan@jschaer.ch
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-11-17 14:58:52 +01:00
Jan Schär
a19f12b52a ALSA: usb-audio: Support jack detection on Dell dock
[ Upstream commit 4b8ea38fabab45ad911a32a336416062553dfe9c ]

The Dell WD15 dock has a headset and a line out port. Add support for
detecting if a jack is inserted into one of these ports.
For the headset jack, additionally determine if a mic is present.

The WD15 contains an ALC4020 USB audio controller and ALC3263 audio codec
from Realtek. It is a UAC 1 device, and UAC 1 does not support jack
detection. Instead, jack detection works by sending HD Audio commands over
vendor-type USB messages.

I found out how it works by looking at USB captures on Windows.
The audio codec is very similar to the one supported by
sound/soc/codecs/rt298.c / rt298.h, some constant names and the mic
detection are adapted from there. The realtek_add_jack function is adapted
from build_connector_control in sound/usb/mixer.c.

I tested this on a WD15 dock with the latest firmware.

Signed-off-by: Jan Schär <jan@jschaer.ch>
Link: https://lore.kernel.org/r/20220627171855.42338-1-jan@jschaer.ch
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Stable-dep-of: 4413665dd6c5 ("ALSA: usb-audio: Add quirks for Dell WD19 dock")
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-11-17 14:58:52 +01:00
Andrew Kanner
168a9b8303 ocfs2: remove entry once instead of null-ptr-dereference in ocfs2_xa_remove()
commit 0b63c0e01fba40e3992bc627272ec7b618ccaef7 upstream.

Syzkaller is able to provoke null-ptr-dereference in ocfs2_xa_remove():

[   57.319872] (a.out,1161,7):ocfs2_xa_remove:2028 ERROR: status = -12
[   57.320420] (a.out,1161,7):ocfs2_xa_cleanup_value_truncate:1999 ERROR: Partial truncate while removing xattr overlay.upper.  Leaking 1 clusters and removing the entry
[   57.321727] BUG: kernel NULL pointer dereference, address: 0000000000000004
[...]
[   57.325727] RIP: 0010:ocfs2_xa_block_wipe_namevalue+0x2a/0xc0
[...]
[   57.331328] Call Trace:
[   57.331477]  <TASK>
[...]
[   57.333511]  ? do_user_addr_fault+0x3e5/0x740
[   57.333778]  ? exc_page_fault+0x70/0x170
[   57.334016]  ? asm_exc_page_fault+0x2b/0x30
[   57.334263]  ? __pfx_ocfs2_xa_block_wipe_namevalue+0x10/0x10
[   57.334596]  ? ocfs2_xa_block_wipe_namevalue+0x2a/0xc0
[   57.334913]  ocfs2_xa_remove_entry+0x23/0xc0
[   57.335164]  ocfs2_xa_set+0x704/0xcf0
[   57.335381]  ? _raw_spin_unlock+0x1a/0x40
[   57.335620]  ? ocfs2_inode_cache_unlock+0x16/0x20
[   57.335915]  ? trace_preempt_on+0x1e/0x70
[   57.336153]  ? start_this_handle+0x16c/0x500
[   57.336410]  ? preempt_count_sub+0x50/0x80
[   57.336656]  ? _raw_read_unlock+0x20/0x40
[   57.336906]  ? start_this_handle+0x16c/0x500
[   57.337162]  ocfs2_xattr_block_set+0xa6/0x1e0
[   57.337424]  __ocfs2_xattr_set_handle+0x1fd/0x5d0
[   57.337706]  ? ocfs2_start_trans+0x13d/0x290
[   57.337971]  ocfs2_xattr_set+0xb13/0xfb0
[   57.338207]  ? dput+0x46/0x1c0
[   57.338393]  ocfs2_xattr_trusted_set+0x28/0x30
[   57.338665]  ? ocfs2_xattr_trusted_set+0x28/0x30
[   57.338948]  __vfs_removexattr+0x92/0xc0
[   57.339182]  __vfs_removexattr_locked+0xd5/0x190
[   57.339456]  ? preempt_count_sub+0x50/0x80
[   57.339705]  vfs_removexattr+0x5f/0x100
[...]

Reproducer uses faultinject facility to fail ocfs2_xa_remove() ->
ocfs2_xa_value_truncate() with -ENOMEM.

In this case the comment mentions that we can return 0 if
ocfs2_xa_cleanup_value_truncate() is going to wipe the entry
anyway. But the following 'rc' check is wrong and execution flow do
'ocfs2_xa_remove_entry(loc);' twice:
* 1st: in ocfs2_xa_cleanup_value_truncate();
* 2nd: returning back to ocfs2_xa_remove() instead of going to 'out'.

Fix this by skipping the 2nd removal of the same entry and making
syzkaller repro happy.

Link: https://lkml.kernel.org/r/20241103193845.2940988-1-andrew.kanner@gmail.com
Fixes: 399ff3a748 ("ocfs2: Handle errors while setting external xattr values.")
Signed-off-by: Andrew Kanner <andrew.kanner@gmail.com>
Reported-by: syzbot+386ce9e60fa1b18aac5b@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/all/671e13ab.050a0220.2b8c0f.01d0.GAE@google.com/T/
Tested-by: syzbot+386ce9e60fa1b18aac5b@syzkaller.appspotmail.com
Reviewed-by: Joseph Qi <joseph.qi@linux.alibaba.com>
Cc: Mark Fasheh <mark@fasheh.com>
Cc: Joel Becker <jlbec@evilplan.org>
Cc: Junxiao Bi <junxiao.bi@oracle.com>
Cc: Changwei Ge <gechangwei@live.cn>
Cc: Jun Piao <piaojun@huawei.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-11-17 14:58:52 +01:00
Marc Zyngier
8cdb2d0796 irqchip/gic-v3: Force propagation of the active state with a read-back
commit 464cb98f1c07298c4c10e714ae0c36338d18d316 upstream.

Christoffer reports that on some implementations, writing to
GICR_ISACTIVER0 (and similar GICD registers) can race badly with a guest
issuing a deactivation of that interrupt via the system register interface.

There are multiple reasons to this:

 - this uses an early write-acknoledgement memory type (nGnRE), meaning
   that the write may only have made it as far as some interconnect
   by the time the store is considered "done"

 - the GIC itself is allowed to buffer the write until it decides to
   take it into account (as long as it is in finite time)

The effects are that the activation may not have taken effect by the time
the kernel enters the guest, forcing an immediate exit, or that a guest
deactivation occurs before the interrupt is active, doing nothing.

In order to guarantee that the write to the ISACTIVER register has taken
effect, read back from it, forcing the interconnect to propagate the write,
and the GIC to process the write before returning the read.

Reported-by: Christoffer Dall <christoffer.dall@arm.com>
Signed-off-by: Marc Zyngier <maz@kernel.org>
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
Acked-by: Christoffer Dall <christoffer.dall@arm.com>
Cc: stable@vger.kernel.org
Link: https://lore.kernel.org/all/20241106084418.3794612-1-maz@kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-11-17 14:58:52 +01:00
Benoît Monin
2f29a9fbae USB: serial: option: add Quectel RG650V
commit 3b05949ba39f305b585452d0e177470607842165 upstream.

Add support for Quectel RG650V which is based on Qualcomm SDX65 chip.
The composition is DIAG / NMEA / AT / AT / QMI.

T:  Bus=02 Lev=01 Prnt=01 Port=03 Cnt=01 Dev#=  4 Spd=5000 MxCh= 0
D:  Ver= 3.20 Cls=00(>ifc ) Sub=00 Prot=00 MxPS= 9 #Cfgs=  1
P:  Vendor=2c7c ProdID=0122 Rev=05.15
S:  Manufacturer=Quectel
S:  Product=RG650V-EU
S:  SerialNumber=xxxxxxx
C:  #Ifs= 5 Cfg#= 1 Atr=a0 MxPwr=896mA
I:  If#= 0 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=ff Prot=30 Driver=option
E:  Ad=01(O) Atr=02(Bulk) MxPS=1024 Ivl=0ms
E:  Ad=81(I) Atr=02(Bulk) MxPS=1024 Ivl=0ms
I:  If#= 1 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=00 Prot=00 Driver=option
E:  Ad=02(O) Atr=02(Bulk) MxPS=1024 Ivl=0ms
E:  Ad=82(I) Atr=02(Bulk) MxPS=1024 Ivl=0ms
I:  If#= 2 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=00 Prot=00 Driver=option
E:  Ad=03(O) Atr=02(Bulk) MxPS=1024 Ivl=0ms
E:  Ad=83(I) Atr=02(Bulk) MxPS=1024 Ivl=0ms
E:  Ad=84(I) Atr=03(Int.) MxPS=  10 Ivl=9ms
I:  If#= 3 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=00 Prot=00 Driver=option
E:  Ad=04(O) Atr=02(Bulk) MxPS=1024 Ivl=0ms
E:  Ad=85(I) Atr=02(Bulk) MxPS=1024 Ivl=0ms
E:  Ad=86(I) Atr=03(Int.) MxPS=  10 Ivl=9ms
I:  If#= 4 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=ff Prot=ff Driver=qmi_wwan
E:  Ad=05(O) Atr=02(Bulk) MxPS=1024 Ivl=0ms
E:  Ad=87(I) Atr=02(Bulk) MxPS=1024 Ivl=0ms
E:  Ad=88(I) Atr=03(Int.) MxPS=   8 Ivl=9ms

Signed-off-by: Benoît Monin <benoit.monin@gmx.fr>
Cc: stable@vger.kernel.org
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-11-17 14:58:52 +01:00