Commit graph

894,809 commits

Author SHA1 Message Date
Oleksiy Avramchenko
0cb7b914b7 ANDROID: GKI: update Sony KMI symbol list
Add a symbol required by sec_touchscreen.ko.

Leaf changes summary: 1 artifact changed
Changed leaf types summary: 0 leaf type changed
Removed/Changed/Added functions summary: 0 Removed, 0 Changed, 1 Added function
Removed/Changed/Added variables summary: 0 Removed, 0 Changed, 0 Added variable

1 Added function:

  [A] 'function void input_set_timestamp(input_dev*, ktime_t)'

Bug: 239073629
Change-Id: I7fa07f161326c529d3d581accceef97685ed473a
Signed-off-by: Oleksiy Avramchenko <oleksiy.avramchenko@sony.com>
2022-07-15 13:14:50 +02:00
Linus Torvalds
8828cbe3c7 UPSTREAM: mm: fix misplaced unlock_page in do_wp_page()
Commit 09854ba94c6a ("mm: do_wp_page() simplification") reorganized all
the code around the page re-use vs copy, but in the process also moved
the final unlock_page() around to after the wp_page_reuse() call.

That normally doesn't matter - but it means that the unlock_page() is
now done after releasing the page table lock.  Again, not a big deal,
you'd think.

But it turns out that it's very wrong indeed, because once we've
released the page table lock, we've basically lost our only reference to
the page - the page tables - and it could now be free'd at any time.  We
do hold the mmap_sem, so no actual unmap() can happen, but madvise can
come in and a MADV_DONTNEED will zap the page range - and free the page.

So now the page may be free'd just as we're unlocking it, which in turn
will usually trigger a "Bad page state" error in the freeing path.  To
make matters more confusing, by the time the debug code prints out the
page state, the unlock has typically completed and everything looks fine
again.

This all doesn't happen in any normal situations, but it does trigger
with the dirtyc0w_child LTP test.  And it seems to trigger much more
easily (but not expclusively) on s390 than elsewhere, probably because
s390 doesn't do the "batch pages up for freeing after the TLB flush"
that gives the unlock_page() more time to complete and makes the race
harder to hit.

Fixes: 09854ba94c6a ("mm: do_wp_page() simplification")
Link: https://lore.kernel.org/lkml/a46e9bbef2ed4e17778f5615e818526ef848d791.camel@redhat.com/
Link: https://lore.kernel.org/linux-mm/c41149a8-211e-390b-af1d-d5eee690fecb@linux.alibaba.com/
Reported-by: Qian Cai <cai@redhat.com>
Reported-by: Alex Shi <alex.shi@linux.alibaba.com>
Bisected-and-analyzed-by: Gerald Schaefer <gerald.schaefer@linux.ibm.com>
Tested-by: Gerald Schaefer <gerald.schaefer@linux.ibm.com>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
(cherry picked from commit be068f29034fb00530a053d18b8cf140c32b12b3)

Bug: 176847924
Signed-off-by: Kalesh Singh <kaleshsingh@google.com>
Change-Id: I85ea395b6b722fbfc63036041d11615dacf96a7b
2022-07-06 18:37:37 -07:00
Linus Torvalds
e791f407b1 BACKPORT: mm: do_wp_page() simplification
How about we just make sure we're the only possible valid user fo the
page before we bother to reuse it?

Simplify, simplify, simplify.

And get rid of the nasty serialization on the page lock at the same time.

[peterx: add subject prefix]

Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Peter Xu <peterx@redhat.com>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
(cherry picked from commit 09854ba94c6aad7886996bfbee2530b3d8a7f4f4)

[Kalesh Singh: Resolve conflict in mm/memory.c]
Bug: 176847924
Signed-off-by: Kalesh Singh <kaleshsingh@google.com>
Change-Id: I0b855b305332564670b8cbea9660405fed89a044
2022-07-06 18:37:16 -07:00
Peter Xu
fb8e4568af UPSTREAM: mm/ksm: Remove reuse_ksm_page()
Remove the function as the last reference has gone away with the do_wp_page()
changes.

Signed-off-by: Peter Xu <peterx@redhat.com>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
(cherry picked from commit 1a0cf26323c80e2f1c58fc04f15686de61bfab0c)

Bug: 176847924
Signed-off-by: Kalesh Singh <kaleshsingh@google.com>
Change-Id: I70e5938a046d0fc449288ae46c83cb7c39d7de48
2022-07-06 18:36:53 -07:00
Takashi Iwai
2ddac3780b BACKPORT: ALSA: pcm: Fix races among concurrent prealloc proc writes
commit 69534c48ba8ce552ce383b3dfdb271ffe51820c3 upstream.

We have no protection against concurrent PCM buffer preallocation
changes via proc files, and it may potentially lead to UAF or some
weird problem.  This patch applies the PCM open_mutex to the proc
write operation for avoiding the racy proc writes and the PCM stream
open (and further operations).

Bug: 232293337
Cc: <stable@vger.kernel.org>
Reviewed-by: Jaroslav Kysela <perex@perex.cz>
Link: https://lore.kernel.org/r/20220322170720.3529-5-tiwai@suse.de
Signed-off-by: Takashi Iwai <tiwai@suse.de>
[OP: backport to 5.4: adjusted context]
Signed-off-by: Ovidiu Panait <ovidiu.panait@windriver.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Lee Jones <lee.jones@linaro.org>
Change-Id: I52d0347c440b87c700b28e082eee9ab9d3ec4910
2022-06-30 16:11:23 +00:00
Takashi Iwai
6ef42e5789 BACKPORT: ALSA: pcm: Fix races among concurrent prepare and hw_params/hw_free calls
commit 3c3201f8c7bb77eb53b08a3ca8d9a4ddc500b4c0 upstream.

Like the previous fixes to hw_params and hw_free ioctl races, we need
to paper over the concurrent prepare ioctl calls against hw_params and
hw_free, too.

This patch implements the locking with the existing
runtime->buffer_mutex for prepare ioctls.  Unlike the previous case
for snd_pcm_hw_hw_params() and snd_pcm_hw_free(), snd_pcm_prepare() is
performed to the linked streams, hence the lock can't be applied
simply on the top.  For tracking the lock in each linked substream, we
modify snd_pcm_action_group() slightly and apply the buffer_mutex for
the case stream_lock=false (formerly there was no lock applied)
there.

Bug: 232293337
Cc: <stable@vger.kernel.org>
Reviewed-by: Jaroslav Kysela <perex@perex.cz>
Link: https://lore.kernel.org/r/20220322170720.3529-4-tiwai@suse.de
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Lee Jones <lee.jones@linaro.org>
Change-Id: Idcb26b8b178b9617e44443f2ca093074b76068b0
2022-06-30 16:11:23 +00:00
Takashi Iwai
32745ed213 BACKPORT: ALSA: pcm: Fix races among concurrent read/write and buffer changes
commit dca947d4d26dbf925a64a6cfb2ddbc035e831a3d upstream.

In the current PCM design, the read/write syscalls (as well as the
equivalent ioctls) are allowed before the PCM stream is running, that
is, at PCM PREPARED state.  Meanwhile, we also allow to re-issue
hw_params and hw_free ioctl calls at the PREPARED state that may
change or free the buffers, too.  The problem is that there is no
protection against those mix-ups.

This patch applies the previously introduced runtime->buffer_mutex to
the read/write operations so that the concurrent hw_params or hw_free
call can no longer interfere during the operation.  The mutex is
unlocked before scheduling, so we don't take it too long.

Bug: 232293337
Cc: <stable@vger.kernel.org>
Reviewed-by: Jaroslav Kysela <perex@perex.cz>
Link: https://lore.kernel.org/r/20220322170720.3529-3-tiwai@suse.de
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Ovidiu Panait <ovidiu.panait@windriver.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Lee Jones <lee.jones@linaro.org>
Change-Id: I4ec9ab14347e88de6b51025b845d13514ac289e9
2022-06-30 16:11:23 +00:00
Greg Kroah-Hartman
bf4e161bf9 ANDROID: Fix up abi issue with struct snd_pcm_runtime
A portion of the fix for CVE-2022-1048, commit 0f6947f5f520 ("ALSA: pcm:
Fix races among concurrent hw_params and hw_free calls"), caused an ABI
break by adding a new field to struct snd_pcm_runtime.  Because we have
to keep this new addition, it is safe to move it to the end of the
structure because this is only ever created by the sound core, and
referenced as a pointer everywhere else.

This does require a .xml update also to handle the increased structure
size:

Leaf changes summary: 1 artifact changed
Changed leaf types summary: 1 leaf type changed
Removed/Changed/Added functions summary: 0 Removed, 0 Changed, 0 Added function
Removed/Changed/Added variables summary: 0 Removed, 0 Changed, 0 Added variable

'struct snd_pcm_runtime at pcm.h:342:1' changed:
  type size changed from 6080 to 6336 (in bits)
  1 data member insertion:
    'mutex buffer_mutex', at offset 6080 (in bits) at pcm.h:428:1
  92 impacted interfaces

Bug: 161946584
Fixes: 0f6947f5f520 ("ALSA: pcm: Fix races among concurrent hw_params and hw_free calls")
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
[Lee: Update XML files for this branch]
Signed-off-by: Lee Jones <lee.jones@linaro.org>
Change-Id: I20340387fbe85fb82676517a93bb0184c8c1eb65
2022-06-30 16:11:23 +00:00
Takashi Iwai
3026e8262a BACKPORT: ALSA: pcm: Fix races among concurrent hw_params and hw_free calls
commit 92ee3c60ec9fe64404dc035e7c41277d74aa26cb upstream.

Currently we have neither proper check nor protection against the
concurrent calls of PCM hw_params and hw_free ioctls, which may result
in a UAF.  Since the existing PCM stream lock can't be used for
protecting the whole ioctl operations, we need a new mutex to protect
those racy calls.

This patch introduced a new mutex, runtime->buffer_mutex, and applies
it to both hw_params and hw_free ioctl code paths.  Along with it, the
both functions are slightly modified (the mmap_count check is moved
into the state-check block) for code simplicity.

Bug: 5d95acffca4c
Reported-by: Hu Jiahui <kirin.say@gmail.com>
Cc: <stable@vger.kernel.org>
Reviewed-by: Jaroslav Kysela <perex@perex.cz>
Link: https://lore.kernel.org/r/20220322170720.3529-2-tiwai@suse.de
Signed-off-by: Takashi Iwai <tiwai@suse.de>
[OP: backport to 5.4: adjusted context]
Signed-off-by: Ovidiu Panait <ovidiu.panait@windriver.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Lee Jones <lee.jones@linaro.org>
Change-Id: I33b5ed3d1f38904e215692a236fe39e8b3ee1f15
2022-06-30 16:11:23 +00:00
Duoming Zhou
46eb6b6125 BACKPORT: nfc: nfcmrvl: main: reorder destructive operations in nfcmrvl_nci_unregister_dev to avoid bugs
commit d270453a0d9ec10bb8a802a142fb1b3601a83098 upstream.

There are destructive operations such as nfcmrvl_fw_dnld_abort and
gpio_free in nfcmrvl_nci_unregister_dev. The resources such as firmware,
gpio and so on could be destructed while the upper layer functions such as
nfcmrvl_fw_dnld_start and nfcmrvl_nci_recv_frame is executing, which leads
to double-free, use-after-free and null-ptr-deref bugs.

There are three situations that could lead to double-free bugs.

The first situation is shown below:

   (Thread 1)                 |      (Thread 2)
nfcmrvl_fw_dnld_start         |
 ...                          |  nfcmrvl_nci_unregister_dev
 release_firmware()           |   nfcmrvl_fw_dnld_abort
  kfree(fw) //(1)             |    fw_dnld_over
                              |     release_firmware
  ...                         |      kfree(fw) //(2)
                              |     ...

The second situation is shown below:

   (Thread 1)                 |      (Thread 2)
nfcmrvl_fw_dnld_start         |
 ...                          |
 mod_timer                    |
 (wait a time)                |
 fw_dnld_timeout              |  nfcmrvl_nci_unregister_dev
   fw_dnld_over               |   nfcmrvl_fw_dnld_abort
    release_firmware          |    fw_dnld_over
     kfree(fw) //(1)          |     release_firmware
     ...                      |      kfree(fw) //(2)

The third situation is shown below:

       (Thread 1)               |       (Thread 2)
nfcmrvl_nci_recv_frame          |
 if(..->fw_download_in_progress)|
  nfcmrvl_fw_dnld_recv_frame    |
   queue_work                   |
                                |
fw_dnld_rx_work                 | nfcmrvl_nci_unregister_dev
 fw_dnld_over                   |  nfcmrvl_fw_dnld_abort
  release_firmware              |   fw_dnld_over
   kfree(fw) //(1)              |    release_firmware
                                |     kfree(fw) //(2)

The firmware struct is deallocated in position (1) and deallocated
in position (2) again.

The crash trace triggered by POC is like below:

BUG: KASAN: double-free or invalid-free in fw_dnld_over
Call Trace:
  kfree
  fw_dnld_over
  nfcmrvl_nci_unregister_dev
  nci_uart_tty_close
  tty_ldisc_kill
  tty_ldisc_hangup
  __tty_hangup.part.0
  tty_release
  ...

What's more, there are also use-after-free and null-ptr-deref bugs
in nfcmrvl_fw_dnld_start. If we deallocate firmware struct, gpio or
set null to the members of priv->fw_dnld in nfcmrvl_nci_unregister_dev,
then, we dereference firmware, gpio or the members of priv->fw_dnld in
nfcmrvl_fw_dnld_start, the UAF or NPD bugs will happen.

This patch reorders destructive operations after nci_unregister_device
in order to synchronize between cleanup routine and firmware download
routine.

The nci_unregister_device is well synchronized. If the device is
detaching, the firmware download routine will goto error. If firmware
download routine is executing, nci_unregister_device will wait until
firmware download routine is finished.

Bug: 234690530
Fixes: 3194c68701 ("NFC: nfcmrvl: add firmware download support")
Signed-off-by: Duoming Zhou <duoming@zju.edu.cn>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Lee Jones <lee.jones@linaro.org>
Change-Id: I8cc1f6450c7fecf5f5994033931da1d23a522282
2022-06-30 11:46:05 +01:00
Greg Kroah-Hartman
375c2e2cdb Merge tag 'android11-5.4.191_r01' into android11-5.4
This is the merge of the upstream LTS release of 5.4.191 into the
android11-5.4 branch.

It contains the following commits:

d81463675427 Merge tag 'android11-5.4.191_r01' into android11-5.4
84c84ac7a3 Revert "oom_kill.c: futex: delay the OOM reaper to allow time for proper futex cleanup"
36dda9143f Merge 5.4.191 into android11-5.4-lts
4426e6017f Linux 5.4.191
3c946909a3 Revert "net: micrel: fix KS8851_MLL Kconfig"
c028b81d06 block/compat_ioctl: fix range check in BLKGETSIZE
27da8d16e4 staging: ion: Prevent incorrect reference counting behavour
cb158b152e spi: atmel-quadspi: Fix the buswidth adjustment between spi-mem and controller
1b6ad24210 jbd2: fix a potential race while discarding reserved buffers after an abort
0b1ba14ab2 ext4: force overhead calculation if the s_overhead_cluster makes no sense
425301ef60 ext4: fix overhead calculation to account for the reserved gdt blocks
ea9c206111 ext4, doc: fix incorrect h_reserved size
259dc49dea ext4: limit length to bitmap_maxbytes - blocksize in punch_hole
faadbf7ac4 ext4: fix use-after-free in ext4_search_dir
0309665eb2 ext4: fix symlink file size not match to file content
ddfe3babc5 arm_pmu: Validate single/group leader events
852b02d1f8 ARC: entry: fix syscall_trace_exit argument
016ba7cbed e1000e: Fix possible overflow in LTR decoding
1217cf141b ASoC: soc-dapm: fix two incorrect uses of list iterator
aa70705560 openvswitch: fix OOB access in reserve_sfa_size()
d24e0d9d69 xtensa: fix a7 clobbering in coprocessor context load/store
4c26a96d0c xtensa: patch_text: Fixup last cpu should be master
8d6937c1e0 powerpc/perf: Fix power9 event alternatives
0dafb826ed drm/vc4: Use pm_runtime_resume_and_get to fix pm_runtime_get_sync() usage
013231f75f KVM: PPC: Fix TCE handling for VFIO
9cf05812cb drm/panel/raspberrypi-touchscreen: Initialise the bridge in prepare
4f08e85ca0 drm/panel/raspberrypi-touchscreen: Avoid NULL deref if not initialised
23f0ba5585 dma: at_xdmac: fix a missing check on list iterator
a22f3c9926 ata: pata_marvell: Check the 'bmdma_addr' beforing reading
0441d3e95b oom_kill.c: futex: delay the OOM reaper to allow time for proper futex cleanup
530d32ac52 EDAC/synopsys: Read the error count from the correct register
91367af460 stat: fix inconsistency between struct stat and struct compat_stat
837e319ebe scsi: qedi: Fix failed disconnect handling
4b813ce289 net: macb: Restart tx only if queue pointer is lagging
a1419bee4d drm/msm/mdp5: check the return of kzalloc()
80b188da30 dpaa_eth: Fix missing of_node_put in dpaa_get_ts_info()
46f9fa0a66 brcmfmac: sdio: Fix undefined behavior due to shift overflowing the constant
12a753edd9 mt76: Fix undefined behavior due to shift overflowing the constant
7c48a6e62d cifs: Check the IOCB_DIRECT flag, not O_DIRECT
435142fbdc vxlan: fix error return code in vxlan_fdb_append
99c2d9a52f ALSA: usb-audio: Fix undefined behavior due to shift overflowing the constant
3e28d157e5 platform/x86: samsung-laptop: Fix an unsigned comparison which can never be negative
54be94d336 reset: tegra-bpmp: Restore Handle errors in BPMP response
0cb2c00dd1 ARM: vexpress/spc: Avoid negative array index when !SMP
3a5ad1b8db selftests: mlxsw: vxlan_flooding: Prevent flooding of unwanted packets
d37295129e netlink: reset network and mac headers in netlink_dump()
4c4f2a019f l3mdev: l3mdev_master_upper_ifindex_by_index_rcu should be using netdev_master_upper_dev_get_rcu
8c5ca6492a net/sched: cls_u32: fix possible leak in u32_init_knode()
f883def546 net/packet: fix packet_sock xmit return value checking
e1bc684c81 net/smc: Fix sock leak when release after smc_shutdown()
f10e5c9f22 rxrpc: Restore removed timer deletion
9a9c481593 igc: Fix BUG: scheduling while atomic
f9d5d17d23 igc: Fix infinite loop in release_swfw_sync
6d6271dbbb dmaengine: mediatek:Fix PM usage reference leak of mtk_uart_apdma_alloc_chan_resources
65c36555bd dmaengine: imx-sdma: Fix error checking in sdma_event_remap
ccf554d148 ASoC: msm8916-wcd-digital: Check failure for devm_snd_soc_register_component
6a20bf46c6 ASoC: atmel: Remove system clock tree configuration for at91sam9g20ek
6a54979c78 ALSA: usb-audio: Clear MIDI port active flag after draining
9c99aacfb4 tcp: Fix potential use-after-free due to double kfree()
5a4f3eba21 net/sched: cls_u32: fix netns refcount changes in u32_change()
b01b700e0c tcp: fix race condition when creating child sockets from syncookies
ebb3b84596 gfs2: assign rgrp glock before compute_bitstructs
660784e719 can: usb_8dev: usb_8dev_start_xmit(): fix double dev_kfree_skb() in error path
2da11442a1 tracing: Dump stacktrace trigger to the corresponding instance
bad7ed5575 mm: page_alloc: fix building error on -Werror=array-compare
ac94e87675 etherdevice: Adjust ether_addr* prototypes to silence -Wstringop-overead
af912bfbcd Merge branch 'android11-5.4' into 'android11-5.4-lts'
4bd8a3c04c Merge 5.4.190 into android11-5.4-lts
dc213ac856 Linux 5.4.190
a83a18c4c9 ax25: Fix UAF bugs in ax25 timers
40cb8b3b19 ax25: Fix NULL pointer dereferences in ax25 timers
d2be5b563e ax25: fix NPD bug in ax25_disconnect
eaa7eb23fa ax25: fix UAF bug in ax25_send_control()
9e1e088a57 ax25: Fix refcount leaks caused by ax25_cb_del()
7528d0f221 ax25: fix UAF bugs of net_device caused by rebinding operation
1db0b2c55c ax25: fix reference count leaks of ax25_dev
418993bbaa ax25: add refcount in ax25_dev to avoid UAF bugs
4459946e86 dma-direct: avoid redundant memory sync for swiotlb
7efb8e49f6 i2c: pasemi: Wait for write xfers to finish
659855c62c smp: Fix offline cpu check in flush_smp_call_function_queue()
7f84c93722 dm integrity: fix memory corruption when tag_size is less than digest size
89931d4762 ARM: davinci: da850-evm: Avoid NULL pointer dereference
28956e530b tick/nohz: Use WARN_ON_ONCE() to prevent console saturation
f4fb50ee25 genirq/affinity: Consider that CPUs on nodes can be unbalanced
f616ecec0f drm/amd/display: don't ignore alpha property on pre-multiplied mode
ab2f5afb7a ipv6: fix panic when forwarding a pkt with no in6 dev
377a80ca65 ALSA: pcm: Test for "silence" field in struct "pcm_format_data"
5f77b1c0e6 ALSA: hda/realtek: Add quirk for Clevo PD50PNT
358e7b451a btrfs: mark resumed async balance as writing
d5b0b11c06 btrfs: remove unused variable in btrfs_{start,write}_dirty_block_groups()
0aad67337f ath9k: Fix usage of driver-private space in tx_info
7fb98e4f5b ath9k: Properly clear TX status area before reporting to mac80211
7a9e1327cc gcc-plugins: latent_entropy: use /dev/urandom
534d0aebe1 mm: kmemleak: take a full lowmem check in kmemleak_*_phys()
b56d305274 mm, page_alloc: fix build_zonerefs_node()
e07a70ca83 perf/imx_ddr: Fix undefined behavior due to shift overflowing the constant
d05cd68ed8 drivers: net: slip: fix NPD bug in sl_tx_timeout()
6d41134f30 scsi: megaraid_sas: Target with invalid LUN ID is deleted during scan
3ecd43dcda scsi: mvsas: Add PCI ID of RocketRaid 2640
deab81144d powerpc: Fix virt_addr_valid() for 64-bit Book3E & 32-bit
dd9b4b435a drm/amd/display: Fix allocate_mst_payload assert on resume
404998a137 net: usb: aqc111: Fix out-of-bounds accesses in RX fixup
4a24416796 tlb: hugetlb: Add more sizes to tlb_remove_huge_tlb_entry
29c2910c50 arm64: alternatives: mark patch_alternative() as `noinstr`
8c4db601ac regulator: wm8994: Add an off-on delay for WM8994 variant
066180758f gpu: ipu-v3: Fix dev_dbg frequency output
b4ef44c7c2 ata: libata-core: Disable READ LOG DMA EXT for Samsung 840 EVOs
4cd3c9e070 net: micrel: fix KS8851_MLL Kconfig
6117facb44 scsi: ibmvscsis: Increase INITIAL_SRP_LIMIT to 1024
fb7a511542 scsi: target: tcmu: Fix possible page UAF
70b97c1546 Drivers: hv: vmbus: Prevent load re-ordering when reading ring buffer
c7a268b338 drm/amdkfd: Check for potential null return of kmalloc_array()
2f3e1f3863 drm/amdkfd: Fix Incorrect VMIDs passed to HWS
46ca8233f1 drm/amd/display: Update VTEM Infopacket definition
74090c44c1 drm/amd/display: fix audio format not updated after edid updated
0b3c2222d7 drm/amd: Add USBC connector ID
22d658c6c5 cifs: potential buffer overflow in handling symlinks
5c63ad2b0a nfc: nci: add flush_workqueue to prevent uaf
1407cc68aa testing/selftests/mqueue: Fix mq_perf_tests to free the allocated cpu set
37e54d151e sctp: Initialize daddr on peeled off socket
a05f5e26cb net/smc: Fix NULL pointer dereference in smc_pnet_find_ib()
1ac7c6d75e drm/msm/dsi: Use connector directly in msm_dsi_manager_connector_init()
02ee10d2a4 cfg80211: hold bss_lock while updating nontrans_list
99a435c378 net/sched: taprio: Check if socket flags are valid
7e59fdf954 net: ethernet: stmmac: fix altr_tse_pcs function when using a fixed-link
94541468c1 net/sched: fix initialization order when updating chain 0 head
4f83ba16a1 mlxsw: i2c: Fix initialization error flow
8cefae8c40 gpiolib: acpi: use correct format characters
2fd90b86df veth: Ensure eth header is in skb's linear part
5f2e543918 net/sched: flower: fix parsing of ethertype following VLAN header
9250186785 memory: atmel-ebi: Fix missing of_node_put in atmel_ebi_probe
347d6f40b8 ANDROID: GKI: fix crc issue with commit 3f91687e6e ("block: don't merge across cgroup boundaries if blkcg is enabled")
ebb848e772 Revert "PCI: Reduce warnings on possible RW1C corruption"
023cd1cf3f Merge 5.4.189 into android11-5.4-lts
e7f5213d75 Linux 5.4.189
b15feb09a3 ACPI: processor idle: Check for architectural support for LPI
60b6aae072 cpuidle: PSCI: Move the `has_lpi` check to the beginning of the function
598a22a077 selftests: cgroup: Test open-time cgroup namespace usage for migration checks
a3f6c5949f selftests: cgroup: Test open-time credential usage for migration checks
48848242d3 selftests: cgroup: Make cg_create() use 0755 for permission instead of 0644
8a887060af cgroup: Use open-time cgroup namespace for process migration perm checks
9bd1ced646 cgroup: Allocate cgroup_file_ctx for kernfs_open_file->priv
691a0fd625 cgroup: Use open-time credentials for process migraton perm checks
1a623d361f io_uring: fix fs->users overflow
33fcb359a6 drm/amdkfd: Fix -Wstrict-prototypes from amdgpu_amdkfd_gfx_10_0_get_functions()
1549bc8cc1 drm/amdkfd: add missing void argument to function kgd2kfd_init
fdfb9ae261 mm/sparsemem: fix 'mem_section' will never be NULL gcc 12 warning
a0c0867f06 arm64: module: remove (NOLOAD) from linker script
2bd5b0d56d mm: don't skip swap entry even if zap_details specified
dfa87d9a5d mmc: mmci: stm32: correctly check all elements of sg list
c645de49e9 mmc: mmci_sdmmc: Replace sg_dma_xxx macros
0d99cce85e dmaengine: Revert "dmaengine: shdma: Fix runtime PM imbalance on error"
9e6980c68c tools build: Use $(shell ) instead of `` to get embedded libperl's ccopts
f0752ee5ef tools build: Filter out options and warnings not supported by clang
3c07cc242b irqchip/gic-v3: Fix GICR_CTLR.RWP polling
e44d6af17b perf: qcom_l2_pmu: fix an incorrect NULL check on list iterator
55e1465ba7 ata: sata_dwc_460ex: Fix crash due to OOB write
b0c4b3fc01 arm64: patch_text: Fixup last cpu should be master
44277c50fd btrfs: fix qgroup reserve overflow the qgroup limit
17f3e31c86 x86/speculation: Restore speculation related MSRs during S3 resume
0b8043e0fc x86/pm: Save the MSR validity status at context setup
25f506273b mm/mempolicy: fix mpol_new leak in shared_policy_replace
c19d8de4e6 mmmremap.c: avoid pointless invalidate_range_start/end on mremap(old_size=0)
73953dfa9d lz4: fix LZ4_decompress_safe_partial read out of bound
3b35143888 mmc: renesas_sdhi: don't overwrite TAP settings when HS400 tuning is complete
0869cb9f62 Revert "mmc: sdhci-xenon: fix annoying 1.8V regulator warning"
c79c1846bd perf session: Remap buf if there is no space for event
9b6894db7c perf tools: Fix perf's libperf_print callback
4ecef6f28a SUNRPC: Handle low memory situations in call_status()
9a0da98a36 SUNRPC: Handle ENOMEM in call_transmit_status()
b6a4055036 drbd: Fix five use after free bugs in get_initial_state
a581b08921 bpf: Support dual-stack sockets in bpf_tcp_check_syncookie
eb175e0606 spi: bcm-qspi: fix MSPI only access with bcm_qspi_exec_mem_op()
034a92c6a8 qede: confirm skb is allocated before using
7ee84d29f2 rxrpc: fix a race in rxrpc_exit_net()
fee500c335 net: openvswitch: don't send internal clone attribute to the userspace.
c154cf184b ipv6: Fix stats accounting in ip6_pkt_drop
fbe5f4c0dd dpaa2-ptp: Fix refcount leak in dpaa2_ptp_probe
8a50937227 IB/rdmavt: add lock to call to rvt_error_qp to prevent a race condition
1ef586a864 bnxt_en: reserve space inside receive page for skb_shared_info
c539a6a589 drm/imx: Fix memory leak in imx_pd_connector_get_modes
cc9c2f51cd net: stmmac: Fix unset max_speed difference between DT and non-DT platforms
f5064531c2 net: ipv4: fix route with nexthop object delete warning
2b7d14c105 net/tls: fix slab-out-of-bounds bug in decrypt_internal
34a47f7ddb scsi: zorro7xx: Fix a resource leak in zorro7xx_remove_one()
2133c422a1 Drivers: hv: vmbus: Fix potential crash on module unload
c5e12c3a47 drm/amdgpu: fix off by one in amdgpu_gfx_kiq_acquire()
0091429095 KVM: arm64: Check arm64_get_bp_hardening_data() didn't return NULL
18e0097daf mm: fix race between MADV_FREE reclaim and blkdev direct IO read
abb1f310e7 parisc: Fix patch code locking and flushing
bab8e3b4f6 parisc: Fix CPU affinity for Lasi, WAX and Dino chips
1b8a6d1bda SUNRPC: Fix socket waits for write buffer space
e19c3149a8 jfs: prevent NULL deref in diFree
3504b0a177 virtio_console: eliminate anonymous module_init & module_exit
60ade478c9 serial: samsung_tty: do not unlock port->lock for uart_write_wakeup()
14e6bab373 NFS: swap-out must always use STABLE writes.
66cf5de084 NFS: swap IO handling is slightly different for O_DIRECT IO
fa47286c01 SUNRPC/call_alloc: async tasks mustn't block waiting for memory
e427cd0ad5 clk: Enforce that disjoints limits are invalid
8a7462b521 xen: delay xen_hvm_init_time_ops() if kdump is boot on vcpu>=32
3f8f3a1c10 NFSv4: Protect the state recovery thread against direct reclaim
96cdf2fdbe w1: w1_therm: fixes w1_seq for ds28ea00 sensors
823f0364d4 clk: si5341: fix reported clk_rate when output divider is 2
f4e16d12bc minix: fix bug when opening a file with O_DIRECT
a95bbfea8f init/main.c: return 1 from handled __setup() functions
b4be80aa4b netlabel: fix out-of-bounds memory accesses
3803d896dd Bluetooth: Fix use after free in hci_send_acl
8beb760f63 xtensa: fix DTC warning unit_address_format
d41bdccb3c usb: dwc3: omap: fix "unbalanced disables for smps10_out1" on omap5evm
5cf2ce8967 scsi: libfc: Fix use after free in fc_exch_abts_resp()
0aeaadc52b MIPS: fix fortify panic when copying asm exception handlers
c871b83748 bnxt_en: Eliminate unintended link toggle during FW reset
1166f5c139 tuntap: add sanity checks about msg_controllen in sendmsg
c68dd44fb8 macvtap: advertise link netns via netlink
060a485df4 mips: ralink: fix a refcount leak in ill_acc_of_setup()
1dd7569b8c net/smc: correct settings of RMB window update limit
2fda284a3a scsi: aha152x: Fix aha152x_setup() __setup handler return value
a0ef536256 scsi: pm8001: Fix pm8001_mpi_task_abort_resp()
a45af7e340 drm/amdkfd: make CRAT table missing message informational only
0320bac580 dm ioctl: prevent potential spectre v1 gadget
73dd98ac19 ipv4: Invalidate neighbour for broadcast address upon address addition
f5e4f728d5 power: supply: axp288-charger: Set Vhold to 4.4V
6e2dff272c PCI: pciehp: Add Qualcomm quirk for Command Completed erratum
4225947957 usb: ehci: add pci device support for Aspeed platforms
ea057ac8c9 iommu/arm-smmu-v3: fix event handling soft lockup
4e85f5ab58 PCI: aardvark: Fix support for MSI interrupts
c0e9d868a1 drm/amdgpu: Fix recursive locking warning
cee00fd800 powerpc: Set crashkernel offset to mid of RMA region
fbb7b03320 ipv6: make mc_forwarding atomic
9f24efe239 power: supply: axp20x_battery: properly report current when discharging
3575fa75da scsi: bfa: Replace snprintf() with sysfs_emit()
9cd46ee374 scsi: mvsas: Replace snprintf() with sysfs_emit()
ca5da71a58 bpf: Make dst_port field in struct bpf_sock 16-bit wide
90dbc4c664 powerpc: dts: t104xrdb: fix phy type for FMAN 4/5
9388d87609 ptp: replace snprintf with sysfs_emit
4009f104b0 drm/amd/amdgpu/amdgpu_cs: fix refcount leak of a dma_fence obj
c4e2f57727 ath5k: fix OOB in ath5k_eeprom_read_pcal_info_5111
61ffe21833 drm: Add orientation quirk for GPD Win Max
01f700bae4 KVM: x86/svm: Clear reserved bits written to PerfEvtSeln MSRs
a5476f8d35 ARM: 9187/1: JIVE: fix return value of __setup handler
63efb90030 riscv module: remove (NOLOAD)
68a7bb6948 rtc: wm8350: Handle error for wm8350_register_irq
d95e0367fd ubifs: Rectify space amount budget for mkdir/tmpfile operations
9e24d03dd4 KVM: x86: Forbid VMM to set SYNIC/STIMER MSRs when SynIC wasn't activated
1553126ecc KVM: x86/mmu: do compare-and-exchange of gPTE via the user address
eb05ef70b6 openvswitch: Fixed nd target mask field in the flow dump.
ce8043771f um: Fix uml_mconsole stop/go
337eb95570 ARM: dts: spear13xx: Update SPI dma properties
4e48a66623 ARM: dts: spear1340: Update serial node properties
7f19400e59 ASoC: topology: Allow TLV control to be either read or write
32a76a5574 ubi: fastmap: Return error code if memory allocation fails in add_aeb()
0c1a26c3d3 dt-bindings: spi: mxic: The interrupt property is not mandatory
97ba943e99 dt-bindings: mtd: nand-controller: Fix a comment in the examples
a42ab650d3 dt-bindings: mtd: nand-controller: Fix the reg property description
7d418a0a56 bpf: Fix comment for helper bpf_current_task_under_cgroup()
a075e95614 mm/usercopy: return 1 from hardened_usercopy __setup() handler
abc0b4ea02 mm/memcontrol: return 1 from cgroup.memory __setup() handler
2e16f48838 mm/mmap: return 1 from stack_guard_gap __setup() handler
d650ed0617 ASoC: soc-compress: Change the check for codec_dai
7f19245c36 powerpc/kasan: Fix early region not updated correctly
cb249f8c00 ACPI: CPPC: Avoid out of bounds access when parsing _CPC data
7d4a3c930d ARM: iop32x: offset IRQ numbers by 1
d727fd32cb ubi: Fix race condition between ctrl_cdev_ioctl and ubi_cdev_ioctl
4f9a59cf84 ASoC: mediatek: mt6358: add missing EXPORT_SYMBOLs
230987c2bb pinctrl: nuvoton: npcm7xx: Use %zu printk format for ARRAY_SIZE()
18455cc74e pinctrl: nuvoton: npcm7xx: Rename DS() macro to DSTR()
9611d8ef68 pinctrl: pinconf-generic: Print arguments for bias-pull-*
b0c0f40570 net: hns3: fix software vlan talbe of vlan 0 inconsistent with hardware
2a548fbf09 gfs2: Make sure FITRIM minlen is rounded up to fs block size
8d67f67361 rtc: check if __rtc_read_time was successful
9a8835902e XArray: Update the LRU list in xas_split()
cbd110b8dd can: mcba_usb: properly check endpoint type
2dfe9422d5 can: mcba_usb: mcba_usb_start_xmit(): fix double dev_kfree_skb in error path
3e2852eda1 XArray: Fix xas_create_range() when multi-order entry present
a840286f13 ubifs: rename_whiteout: correct old_dir size computing
b80ccbec0e ubifs: Fix read out-of-bounds in ubifs_wbuf_write_nolock()
1afe219e4a ubifs: setflags: Make dirtied_ino_d 8 bytes aligned
786013ecba ubifs: Add missing iput if do_tmpfile() failed in rename whiteout
37bdf1ad59 ubifs: Fix deadlock in concurrent rename whiteout and inode writeback
14276d38c8 ubifs: rename_whiteout: Fix double free for whiteout_ui->data
01df5f7627 ASoC: SOF: Intel: Fix NULL ptr dereference when ENOMEM
4c277c846a KVM: x86: fix sending PV IPI
a1c03f11cc KVM: Prevent module exit until all VMs are freed
8f608ee87e scsi: qla2xxx: Use correct feature type field during RFF_ID processing
af744ef8f1 scsi: qla2xxx: Reduce false trigger to login
7f9ce17a1d scsi: qla2xxx: Fix N2N inconsistent PLOGI
2d087c7e55 scsi: qla2xxx: Fix missed DMA unmap for NVMe ls requests
4a0a3c66a5 scsi: qla2xxx: Fix hang due to session stuck
9d1651c8a4 scsi: qla2xxx: Fix incorrect reporting of task management failure
2eb1274176 scsi: qla2xxx: Fix disk failure to rediscover
8077a7162b scsi: qla2xxx: Suppress a kernel complaint in qla_create_qpair()
c478b2cde9 scsi: qla2xxx: Check for firmware dump already collected
96391480ab scsi: qla2xxx: Add devids and conditionals for 28xx
08d04784cc scsi: qla2xxx: Fix device reconnect in loop topology
167debaeaa scsi: qla2xxx: Fix warning for missing error code
e67e9620a0 scsi: qla2xxx: Fix wrong FDMI data for 64G adapter
8e561cbb78 scsi: qla2xxx: Fix stuck session in gpdb
f196d94cc7 powerpc: Fix build errors with newer binutils
71ca99a509 powerpc/lib/sstep: Fix build errors with newer binutils
d42b045e92 powerpc/lib/sstep: Fix 'sthcx' instruction
0af21531f5 ALSA: hda/realtek: Add alc256-samsung-headphone fixup
95d65bca6e mmc: host: Return an error when ->enable_sdio_irq() ops is missing
813553e4a9 media: hdpvr: initialize dev->worker at hdpvr_register_videodev
236311be09 media: Revert "media: em28xx: add missing em28xx_close_extension"
3b36c05f68 video: fbdev: sm712fb: Fix crash in smtcfb_write()
11186875ba ARM: mmp: Fix failure to remove sram device
dc958cd4c8 ARM: tegra: tamonten: Fix I2C3 pad setting
691b0c0cb6 media: cx88-mpeg: clear interrupt status register before streaming video
b239e9d52d ASoC: soc-core: skip zero num_dai component in searching dai name
7d0afbc41b video: fbdev: udlfb: replace snprintf in show functions with sysfs_emit
efe9631a76 video: fbdev: omapfb: panel-tpo-td043mtea1: Use sysfs_emit() instead of snprintf()
ee7ce43367 video: fbdev: omapfb: panel-dsi-cm: Use sysfs_emit() instead of snprintf()
046d9fd86b ASoC: madera: Add dependencies on MFD
46ac0e768d ARM: dts: bcm2837: Add the missing L1/L2 cache information
bf27f5dfcf ARM: dts: qcom: fix gic_irq_domain_translate warnings for msm8960
3856562e94 video: fbdev: omapfb: acx565akm: replace snprintf with sysfs_emit
53a2088a39 video: fbdev: cirrusfb: check pixclock to avoid divide by zero
b19c7df304 video: fbdev: w100fb: Reset global state
055cdd2e7b video: fbdev: nvidiafb: Use strscpy() to prevent buffer overflow
fe41ad8be0 ntfs: add sanity check on allocation size
5a016c053f ext4: don't BUG if someone dirty pages without asking ext4 first
07150842fa spi: tegra20: Use of_device_get_match_data()
0cccf9d4fb PM: core: keep irq flags in device_pm_check_callbacks()
f24e2362d6 ACPI/APEI: Limit printable size of BERT table data
931aff6274 Revert "Revert "block, bfq: honor already-setup queue merges""
7a7b11d694 lib/raid6/test/Makefile: Use $(pound) instead of \# for Make 4.3
c7f6ae51b1 ACPICA: Avoid walking the ACPI Namespace if it is not there
5117c9ff4c bfq: fix use-after-free in bfq_dispatch_request
e464aafd35 irqchip/nvic: Release nvic_base upon failure
c159eb634e irqchip/qcom-pdc: Fix broken locking
c345724f2b Fix incorrect type in assignment of ipv6 port for audit
927649f3f3 loop: use sysfs_emit() in the sysfs xxx show()
799f22279e selinux: use correct type for context length
c4f5a678ad block, bfq: don't move oom_bfqq
f409e9d178 pinctrl: npcm: Fix broken references to chip->parent_device
f36dd10d1b gcc-plugins/stackleak: Exactly match strings instead of prefixes
ddcdda888e LSM: general protection fault in legacy_parse_param
1f316b42a8 lib/test: use after free in register_test_dev_kmod()
7a2ba24cee net: dsa: bcm_sf2_cfp: fix an incorrect NULL check on list iterator
910a98e5c1 NFSv4/pNFS: Fix another issue with a list iterator pointing to the head
9acf05b4e7 net/x25: Fix null-ptr-deref caused by x25_disconnect
d15a70fcda qlcnic: dcb: default to returning -EOPNOTSUPP
8ba93ab509 selftests: test_vxlan_under_vrf: Fix broken test case
ae713d7d99 net: phy: broadcom: Fix brcm_fet_config_init()
ab2c789d1c xen: fix is_xen_pmu()
d85841e4b2 clk: Initialize orphan req_rate
025c75ba38 clk: qcom: gcc-msm8994: Fix gpll4 width
f6f1c9a51e NFSv4.1: don't retry BIND_CONN_TO_SESSION on session error
806ef544cf netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options
cec71a718c jfs: fix divide error in dbNextAG
b3ac1e0196 driver core: dd: fix return value of __setup handler
1bb231de81 firmware: google: Properly state IOMEM dependency
e9f2a8c642 kgdbts: fix return value of __setup handler
16fe77f86a kgdboc: fix return value of __setup handler
7c617cb38c tty: hvc: fix return value of __setup handler
0615a444c5 pinctrl/rockchip: Add missing of_node_put() in rockchip_pinctrl_probe
bc1e29a351 pinctrl: nomadik: Add missing of_node_put() in nmk_pinctrl_probe
27681f9e02 pinctrl: mediatek: paris: Fix pingroup pin config state readback
e9eacc8952 pinctrl: mediatek: paris: Fix "argument" argument type for mtk_pinconf_get()
b348618c17 pinctrl: mediatek: Fix missing of_node_put() in mtk_pctrl_init
6e0d696188 staging: mt7621-dts: fix LEDs and pinctrl on GB-PC1 devicetree
efc605469e NFS: remove unneeded check in decode_devicenotify_args()
110c038779 clk: tegra: tegra124-emc: Fix missing put_device() call in emc_ensure_emc_driver
2b5e68095c clk: clps711x: Terminate clk_div_table with sentinel element
166c0185f3 clk: loongson1: Terminate clk_div_table with sentinel element
1d04467bbb clk: actions: Terminate clk_div_table with sentinel element
50b48ba439 remoteproc: qcom_wcnss: Add missing of_node_put() in wcnss_alloc_memory_region
b5625e7a16 remoteproc: qcom: Fix missing of_node_put in adsp_alloc_memory_region
16ad029942 clk: qcom: clk-rcg2: Update the frac table for pixel clock
52592f9afb clk: qcom: clk-rcg2: Update logic to calculate D value for RCG
b576488fa3 clk: imx7d: Remove audio_mclk_root_clk
79467b9563 dma-debug: fix return value of __setup handlers
fe334765e4 NFS: Return valid errors from nfs2/3_decode_dirent()
546604de8a iio: adc: Add check for devm_request_threaded_irq
1da082f728 serial: 8250: Fix race condition in RTS-after-send handling
617d9c0b98 serial: 8250_mid: Balance reference count for PCI DMA device
61d3fdef61 phy: dphy: Correct lpx parameter and its derivatives(ta_{get,go,sure})
84ee0c81dd clk: qcom: ipq8074: Use floor ops for SDCC1 clock
dd719fca42 pinctrl: renesas: r8a77470: Reduce size for narrow VIN1 channel
b82465c1ff staging:iio:adc:ad7280a: Fix handing of device address bit reversing.
3ba0143128 misc: alcor_pci: Fix an error handling path
af1fdbbb7b pwm: lpc18xx-sct: Initialize driver data and hardware before pwmchip_add()
996291d068 mxser: fix xmit_buf leak in activate when LSR == 0xff
58200dedbd mfd: asic3: Add missing iounmap() on error asic3_mfd_probe
043b197013 tipc: fix the timer expires after interval 100ms
6e2e80b2e9 openvswitch: always update flow key after nat
7a970dbb7d tcp: ensure PMTU updates are processed during fastopen
b4725ad1e4 selftests/bpf/test_lirc_mode2.sh: Exit with proper code
1c7b252a60 i2c: mux: demux-pinctrl: do not deactivate a master that is not active
41249fff50 af_netlink: Fix shift out of bounds in group mask calculation
874eca9396 Bluetooth: btmtksdio: Fix kernel oops in btmtksdio_interrupt
2fe415601b USB: storage: ums-realtek: fix error code in rts51x_read_mem()
94c6ac22ab bpf, sockmap: Fix double uncharge the mem of sk_msg
244ce90c8d bpf, sockmap: Fix more uncharged while msg has more_data
6d03722c34 bpf, sockmap: Fix memleak in tcp_bpf_sendmsg while sk msg is full
0174a89663 RDMA/mlx5: Fix memory leak in error flow for subscribe event routine
9b08d211db mtd: rawnand: atmel: fix refcount issue in atmel_nand_controller_init
443121c994 MIPS: RB532: fix return value of __setup handler
9a9a62846c vxcan: enable local echo for sent CAN frames
6f259b1a4a powerpc: 8xx: fix a return value error in mpc8xx_pic_init
d87803ba6b selftests/bpf: Make test_lwt_ip_encap more stable and faster
ac6edd6fcb mfd: mc13xxx: Add check for mc13xxx_irq_request
d2577dc2b3 powerpc/sysdev: fix incorrect use to determine if list is empty
7192df97a0 mips: DEC: honor CONFIG_MIPS_FP_SUPPORT=n
10705a4305 PCI: Reduce warnings on possible RW1C corruption
90bec38f6a power: supply: wm8350-power: Add missing free in free_charger_irq
a16d8f4191 power: supply: wm8350-power: Handle error for wm8350_register_irq
c703292315 i2c: xiic: Make bus names unique
6f41e4a69b hv_balloon: rate-limit "Unhandled message" warning
c00a91aca2 KVM: x86/emulator: Defer not-present segment check in __load_segment_descriptor()
5f43ec383e KVM: x86: Fix emulation in writing cr8
e91ba23f55 powerpc/Makefile: Don't pass -mcpu=powerpc64 when building 32-bit
3c660fa0f9 libbpf: Skip forward declaration when counting duplicated type names
b62e615a61 bpf, arm64: Feed byte-offset into bpf line info
8f3192a241 bpf, arm64: Call build_prologue() first in first JIT pass
54bc98a0ab drm/bridge: cdns-dsi: Make sure to to create proper aliases for dt
30c5cf4bf2 scsi: hisi_sas: Change permission of parameter prot_mask
e2cd206815 power: supply: bq24190_charger: Fix bq24190_vbus_is_enabled() wrong false return
a725070701 drm/tegra: Fix reference leak in tegra_dsi_ganged_probe
cc16d0bc1c ext2: correct max file size computing
b689622cc4 TOMOYO: fix __setup handlers return values
aa7981012a drm/amd/display: Remove vupdate_int_entry definition
765674e3b3 scsi: pm8001: Fix abort all task initialization
442685f952 scsi: pm8001: Fix payload initialization in pm80xx_set_thermal_config()
e7336d4775 scsi: pm8001: Fix command initialization in pm8001_chip_ssp_tm_req()
898c73387e scsi: pm8001: Fix command initialization in pm80XX_send_read_log()
5e3359ed09 dm crypt: fix get_key_size compiler warning if !CONFIG_KEYS
37e847b674 iwlwifi: mvm: Fix an error code in iwl_mvm_up()
4ad7d29ee4 iwlwifi: Fix -EIO error code that is never returned
770d42fff1 dax: make sure inodes are flushed before destroy cache
c10980c522 IB/cma: Allow XRC INI QPs to set their local ACK timeout
2eaa9d86e0 drm/amd/display: Add affected crtcs to atomic state for dsc mst unplug
8ae97a595b iommu/ipmmu-vmsa: Check for error num after setting mask
a29ce9592c HID: i2c-hid: fix GET/SET_REPORT for unnumbered reports
41ed613642 power: supply: ab8500: Fix memory leak in ab8500_fg_sysfs_init
af5ad6e837 PCI: aardvark: Fix reading PCI_EXP_RTSTA_PME bit on emulated bridge
93b47d22d6 net: dsa: mv88e6xxx: Enable port policy support on 6097
b03c06171b mt76: mt7615: check sta_rates pointer in mt7615_sta_rate_tbl_update
eb5932160e mt76: mt7603: check sta_rates pointer in mt7603_sta_rate_tbl_update
d2ee8da9f7 powerpc/perf: Don't use perf_hw_context for trace IMC PMU
135eb4e2be ray_cs: Check ioremap return value
3be1bb175f power: reset: gemini-poweroff: Fix IRQ check in gemini_poweroff_probe
9a0e270c40 i40e: don't reserve excessive XDP_PACKET_HEADROOM on XSK Rx to skb
5607badbb1 KVM: PPC: Fix vmx/vsx mixup in mmio emulation
4d244b7311 ath9k_htc: fix uninit value bugs
57f4ad5e28 drm/amd/display: Fix a NULL pointer dereference in amdgpu_dm_connector_add_common_modes()
1feb6ff89d drm/edid: Don't clear formats if using deep color
0d0ee651e7 mtd: rawnand: gpmi: fix controller timings setting
750d2dc19f mtd: onenand: Check for error irq
d58d281d6a Bluetooth: hci_serdev: call init_rwsem() before p->open()
5d50f851dd udmabuf: validate ubuf->pagecount
2cf7d537d3 ath10k: fix memory overwrite of the WoWLAN wakeup packet pattern
820e469a2f drm/bridge: Add missing pm_runtime_disable() in __dw_mipi_dsi_probe
e7a0c8546f drm/bridge: Fix free wrong object in sii8620_init_rcp_input_dev
f419751373 ASoC: msm8916-wcd-analog: Fix error handling in pm8916_wcd_analog_spmi_probe
1f31073b77 mmc: davinci_mmc: Handle error for clk_enable
93476f9f82 ASoC: msm8916-wcd-digital: Fix missing clk_disable_unprepare() in msm8916_wcd_digital_probe
9e1fdf18fe ASoC: imx-es8328: Fix error return code in imx_es8328_probe()
67e12f1cb2 ASoC: mxs: Fix error handling in mxs_sgtl5000_probe
ed41d104be ASoC: dmaengine: do not use a NULL prepare_slave_config() callback
29e91a49b6 ivtv: fix incorrect device_caps for ivtvfb
0342da6350 video: fbdev: omapfb: Add missing of_node_put() in dvic_probe_of
58e42ee4a0 ASoC: fsi: Add check for clk_enable
ea9adaa598 ASoC: wm8350: Handle error for wm8350_register_irq
0325193cf4 ASoC: atmel: Add missing of_node_put() in at91sam9g20ek_audio_probe
3cc050df73 media: stk1160: If start stream fails, return buffers with VB2_BUF_STATE_QUEUED
97398470c9 arm64: dts: rockchip: Fix SDIO regulator supply properties on rk3399-firefly
7025f40690 ALSA: firewire-lib: fix uninitialized flag for AV/C deferred transaction
fd5dda439e memory: emif: check the pointer temp in get_device_details()
0ead05f721 memory: emif: Add check for setup_interrupts
68a69ad8df ASoC: soc-compress: prevent the potentially use of null pointer
af6e1d11f7 ASoC: atmel_ssc_dai: Handle errors for clk_enable
fd0c4082fd ASoC: mxs-saif: Handle errors for clk_enable
5847873140 printk: fix return value of printk.devkmsg __setup handler
38bc92ae39 arm64: dts: broadcom: Fix sata nodename
9873232fde arm64: dts: ns2: Fix spi-cpol and spi-cpha property
c6475df1e7 ALSA: spi: Add check for clk_enable()
e0cfb41d46 ASoC: ti: davinci-i2s: Add check for clk_enable()
3905742f93 ASoC: rt5663: check the return value of devm_kzalloc() in rt5663_parse_dp()
a975000e7a uaccess: fix nios2 and microblaze get_user_8()
14cd5a8e61 media: usb: go7007: s2250-board: fix leak in probe()
92f84aa82d media: em28xx: initialize refcount before kref_get
c6f0999461 media: video/hdmi: handle short reads of hdmi info frame.
a9d0bb2988 ARM: dts: imx: Add missing LVDS decoder on M53Menlo
cac1473d83 soc: ti: wkup_m3_ipc: Fix IRQ check in wkup_m3_ipc_probe
fb7f2eabfe arm64: dts: qcom: sm8150: Correct TCS configuration for apps rsc
583fcb66ab soc: qcom: aoss: remove spurious IRQF_ONESHOT flags
755dbc3d73 soc: qcom: rpmpd: Check for null return of devm_kcalloc
12081a1520 ARM: dts: qcom: ipq4019: fix sleep clock
547d36fa41 video: fbdev: fbcvt.c: fix printing in fb_cvt_print_name()
125d10f0be video: fbdev: atmel_lcdfb: fix an error code in atmel_lcdfb_probe()
da8b269cc0 video: fbdev: smscufx: Fix null-ptr-deref in ufx_usb_probe()
4d847e455d media: aspeed: Correct value for h-total-pixels
bd342c7bef media: hantro: Fix overfill bottom register field name
db1b3b99d6 media: coda: Fix missing put_device() call in coda_get_vdoa_data
b0f6b41490 media: bttv: fix WARNING regression on tunerless devices
0478ccdc8e f2fs: fix to avoid potential deadlock
005f9cdab7 f2fs: fix missing free nid in f2fs_handle_failed_inode
a2e534c6a0 perf/x86/intel/pt: Fix address filter config for 32-bit kernel
015d31165d perf/core: Fix address filter parser for multiple filters
841f5b235d sched/debug: Remove mpol_get/put and task_lock/unlock from sched_show_numa
715a343172 clocksource: acpi_pm: fix return value of __setup handler
4c0173521d hwmon: (pmbus) Add Vin unit off handling
acba286182 crypto: ccp - ccp_dmaengine_unregister release dma channels
39a521faf4 ACPI: APEI: fix return value of __setup handlers
8dc887ae33 clocksource/drivers/timer-of: Check return value of of_iomap in timer_of_base_init()
b305975a66 crypto: vmx - add missing dependencies
b7f3e230ca hwrng: atmel - disable trng on failure path
63266a1488 PM: suspend: fix return value of __setup handler
6c4c026c3d PM: hibernate: fix __setup handler error handling
84fe3ca6e7 block: don't delete queue kobject before its children
b68d1742f4 hwmon: (sch56xx-common) Replace WDOG_ACTIVE with WDOG_HW_RUNNING
bf78aca8e4 hwmon: (pmbus) Add mutex to regulator ops
00d67f54b8 spi: pxa2xx-pci: Balance reference count for PCI DMA device
40e6d5d1de crypto: ccree - don't attempt 0 len DMA mappings
c3a5acf91c audit: log AUDIT_TIME_* records only from rules
152ebc0ee9 selftests/x86: Add validity check and allow field splitting
f8a3de8d7c spi: tegra114: Add missing IRQ check in tegra_spi_probe
e5e748a6ff crypto: mxs-dcp - Fix scatterlist processing
30d3f45bcf crypto: authenc - Fix sleep in atomic context in decrypt_tail
9b19022137 regulator: qcom_smd: fix for_each_child.cocci warnings
accf175d0c PCI: pciehp: Clear cmd_busy bit in polling mode
a92f720554 brcmfmac: pcie: Fix crashes due to early IRQs
51fffd722e brcmfmac: pcie: Replace brcmf_pcie_copy_mem_todev with memcpy_toio
d0ab87f8dc brcmfmac: pcie: Release firmwares in the brcmf_pcie_setup error path
2c894b12b2 brcmfmac: firmware: Allocate space for default boardrev in nvram
34a57be0f9 xtensa: fix xtensa_wsr always writing 0
54c9fb17be xtensa: fix stop_machine_cpuslocked call in patch_text
4df9d88a9c media: davinci: vpif: fix unbalanced runtime PM get
28859c3a77 DEC: Limit PMAX memory probing to R3k systems
baa4aa800d crypto: rsa-pkcs1pad - fix buffer overread in pkcs1pad_verify_complete()
058b2e59db crypto: rsa-pkcs1pad - restore signature length check
7973dc9118 crypto: rsa-pkcs1pad - correctly get hash from source scatterlist
002288800e lib/raid6/test: fix multiple definition linking error
e73efa5ad5 thermal: int340x: Increase bitmap size
5d553ed5c5 carl9170: fix missing bit-wise or operator for tx_params
55f078dc66 ARM: dts: exynos: add missing HDMI supplies on SMDK5420
0e0d9bd6be ARM: dts: exynos: add missing HDMI supplies on SMDK5250
a77dd759bd ARM: dts: exynos: fix UART3 pins configuration in Exynos5250
2fafe8b57c ARM: dts: at91: sama5d2: Fix PMERRLOC resource size
51186190c4 video: fbdev: atari: Atari 2 bpp (STe) palette bugfix
478154be3a video: fbdev: sm712fb: Fix crash in smtcfb_read()
67643b89fb drm/edid: check basic audio support on CEA extension block
3f91687e6e block: don't merge across cgroup boundaries if blkcg is enabled
8d3a7b2064 mailbox: tegra-hsp: Flush whole channel
28c8fd84be drivers: hamradio: 6pack: fix UAF bug caused by mod_timer()
5217ae080e ACPI: properties: Consistently return -ENOENT if there are no more references
f3ec0c9db5 udp: call udp_encap_enable for v6 sockets when enabling encap
11dc8286f9 powerpc/kvm: Fix kvm_use_magic_page
ded6277630 drbd: fix potential silent data corruption
35b72d8e2c mm/kmemleak: reset tag when compare object pointer
d102fcacfc mm,hwpoison: unmap poisoned page before invalidation
099553a1a8 ALSA: hda/realtek: Fix audio regression on Mi Notebook Pro 2020
a86bde8930 ALSA: cs4236: fix an incorrect NULL check on list iterator
8489774120 Revert "Input: clear BTN_RIGHT/MIDDLE on buttonpads"
097479aeb2 riscv: Fix fill_callchain return value
c82cbbefc6 qed: validate and restrict untrusted VFs vlan promisc mode
5081cbfb62 qed: display VF trust config
930a3ed5d8 scsi: libsas: Fix sas_ata_qc_issue() handling of NCQ NON DATA commands
ae2a271ed5 mempolicy: mbind_range() set_policy() after vma_merge()
d1313f5e8f mm: invalidate hwpoison page cache page in fault path
2efe956a74 mm/pages_alloc.c: don't create ZONE_MOVABLE beyond the end of a node
455f4a2349 jffs2: fix memory leak in jffs2_scan_medium
0978e9af45 jffs2: fix memory leak in jffs2_do_mount_fs
30bf7244ac jffs2: fix use-after-free in jffs2_clear_xattr_subsystem
e27caad38b can: ems_usb: ems_usb_start_xmit(): fix double dev_kfree_skb() in error path
00a856fa69 spi: mxic: Fix the transmit path
e05221d201 pinctrl: samsung: drop pin banks references on error paths
0996eaaddf f2fs: fix to do sanity check on .cp_pack_total_block_count
f1d5946d47 f2fs: quota: fix loop condition at f2fs_quota_sync()
947ca26390 f2fs: fix to unlock page correctly in error path of is_alive()
ce1aa09cc1 NFSD: prevent integer overflow on 32 bit systems
85259340fc NFSD: prevent underflow in nfssvc_decode_writeargs()
1cfeeeee8c SUNRPC: avoid race between mod_timer() and del_timer_sync()
1a1e73e9ad HID: intel-ish-hid: Use dma_alloc_coherent for firmware update
beb7d96906 Documentation: update stable tree link
20de1038e2 Documentation: add link to stable release candidate tree
d312c0035e KEYS: fix length validation in keyctl_pkey_params_get_2()
2458ecd21f ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE
8a609c88fe clk: uniphier: Fix fixed-rate initialization
9d97610e74 greybus: svc: fix an error handling bug in gb_svc_hello()
468757502e iio: inkern: make a best effort on offset calculation
be2b89a909 iio: inkern: apply consumer scale when no channel scale is available
5be8a07b95 iio: inkern: apply consumer scale on IIO_VAL_INT cases
c459b27945 iio: afe: rescale: use s64 for temporary scale calculations
576a1ce64c coresight: Fix TRCCONFIGR.QE sysfs interface
d8f98a23b4 xhci: fix uninitialized string returned by xhci_decode_ctrl_ctx()
b310e82e77 xhci: make xhci_handshake timeout for xhci_reset() adjustable
a771cc784a xhci: fix runtime PM imbalance in USB2 resume
b5a7ab0e1a USB: usb-storage: Fix use of bitfields for hardware data in ene_ub6250.c
212765c94f virtio-blk: Use blk_validate_block_size() to validate block size
40f282870d block: Add a helper to validate the block size
a27ed2f369 tpm: fix reference counting for struct tpm_chip
631bb18e83 iommu/iova: Improve 32-bit free space estimate
2e2dee5e22 net: dsa: microchip: add spi_device_id tables
ef388db2fe af_key: add __GFP_ZERO flag for compose_sadb_supported in function pfkey_register
0cdb512da0 spi: Fix erroneous sgs value with min_t()
ab951c9c23 net:mcf8390: Use platform_get_irq() to get the interrupt
e62e6c2d7a spi: Fix invalid sgs value
96f9c386fe ethernet: sun: Free the coherent when failing in probing
aa3c3746e7 virtio_console: break out of buf poll on remove
291efbad3d xfrm: fix tunnel model fragmentation behavior
a83df90a3b HID: logitech-dj: add new lightspeed receiver id
5c727ba42c netdevice: add the case if dev is NULL
7e9c9e3f62 USB: serial: simple: add Nokia phone driver
80e5bf89a8 USB: serial: pl2303: add IBM device IDs
6bfc5377a2 swiotlb: fix info leak with DMA_FROM_DEVICE
5789342ce9 Merge 5.4.188 into android11-5.4-lts
2845ff3fd3 Linux 5.4.188
993c23880b llc: only change llc->dev when bind() succeeds
bb4878b39d nds32: fix access_ok() checks in get/put_user
5b1d2561a0 tpm: use try_get_ops() in tpm-space.c
3bbd0000d0 mac80211: fix potential double free on mesh join
cda27a2c6d rcu: Don't deboost before reporting expedited quiescent state
edcc12ae32 crypto: qat - disable registration of algorithms
b0222e222d ACPI: video: Force backlight native for Clevo NL5xRU and NL5xNU
d7f29f397b ACPI: battery: Add device HID and quirk for Microsoft Surface Go 3
2374007850 ACPI / x86: Work around broken XSDT on Advantech DAC-BJ01 board
06f0ff82c7 netfilter: nf_tables: initialize registers in nft_do_chain()
5061bf0f79 ALSA: hda/realtek: Add quirk for ASUS GA402
f7a7cd530a ALSA: hda/realtek - Fix headset mic problem for a HP machine with alc671
0c4190b41a ALSA: oss: Fix PCM OSS buffer allocation overflow
ab49515f7d ASoC: sti: Fix deadlock via snd_pcm_stop_xrun() call
d5c7e1987c drivers: net: xgene: Fix regression in CRC stripping
7870321eaf ALSA: pci: fix reading of swapped values from pcmreg in AC97 codec
1f4eefc585 ALSA: cmipci: Restore aux vol on suspend/resume
d86bf7e073 ALSA: usb-audio: Add mute TLV for playback volumes on RODE NT-USB
0f27a350f8 ALSA: pcm: Add stream lock during PCM reset ioctl operations
572f9a0d3f llc: fix netdevice reference leaks in llc_ui_bind()
2e798814e0 thermal: int340x: fix memory leak in int3400_notify()
5ff048f4ab staging: fbtft: fb_st7789v: reset display before initialization
637d12f9dc tpm: Fix error handling in async work
fee4dfbda6 esp: Fix possible buffer overflow in ESP transformation
2774edd43a net: ipv6: fix skb_over_panic in __ip6_append_data
0aef718463 nfc: st21nfca: Fix potential buffer overflows in EVT_TRANSACTION
628adfa218 nfsd: Containerise filecache laundrette
c32f104138 nfsd: cleanup nfsd_file_lru_dispose()
400a374bce Merge 5.4.187 into android11-5.4-lts
055c4cf7e6 Linux 5.4.187
1771bc0d04 Revert "selftests/bpf: Add test for bpf_timer overwriting crash"
0dd366cfdf perf symbols: Fix symbol size calculation condition
e732b0412f Input: aiptek - properly check endpoint type
700a071585 usb: usbtmc: Fix bug in pipe direction for control transfers
2282a6eb6d usb: gadget: Fix use-after-free bug by not setting udc->dev.driver
2182937626 usb: gadget: rndis: prevent integer overflow in rndis_set_response()
58ee8e2cb3 arm64: fix clang warning about TRAMP_VALIAS
d7b9296375 net: dsa: Add missing of_node_put() in dsa_port_parse_of
f96aa063ff net: handle ARPHRD_PIMREG in dev_is_mac_header_xmit()
3fd96bc64c drm/panel: simple: Fix Innolux G070Y2-L01 BPP settings
b01e2df5fb hv_netvsc: Add check for kvmalloc_array
97ccef56e5 atm: eni: Add check for dma_map_single
268dcf1f7b net/packet: fix slab-out-of-bounds access in packet_recvmsg()
9369748366 net: phy: marvell: Fix invalid comparison in the resume and suspend functions
d0f3c2d1d8 efi: fix return value of __setup handlers
e61655430d ocfs2: fix crash when initialize filecheck kobj fails
184f7bd08c crypto: qcom-rng - ensure buffer for generate is completely filled
8aca45f6ed Merge branch 'android11-5.4' into 'android11-5.4-lts'
f54aeabbaa Merge 5.4.186 into android11-5.4-lts
8e24ff11b5 Linux 5.4.186
fcbdaa6a3c fixup for "arm64 entry: Add macro for reading symbol address from the trampoline"
b8bc0718ba kselftest/vm: fix tests build with old libc
2643ca24f5 sfc: extend the locking on mcdi->seqno
46fd0a0740 tcp: make tcp_read_sock() more robust
16a2e50fe9 nl80211: Update bss channel on channel switch for P2P_CLIENT
941e8bcd2b drm/vrr: Set VRR capable prop only if it is attached to connector
6becb05724 iwlwifi: don't advertise TWT support
51969ebe7f atm: firestream: check the return value of ioremap() in fs_init()
23352749f0 can: rcar_canfd: rcar_canfd_channel_probe(): register the CAN device when fully ready
4006447f55 ARM: 9178/1: fix unmet dependency on BITREVERSE for HAVE_ARCH_BITREVERSE
c2420bc333 MIPS: smp: fill in sibling and core maps earlier
d1df59e312 mac80211: refuse aggregations sessions before authorized
fb35b0cfba ARM: dts: rockchip: fix a typo on rk3288 crypto-controller
4857a9b291 ARM: dts: rockchip: reorder rk322x hmdi clocks
ba14ba2d4c arm64: dts: agilex: use the compatible "intel,socfpga-agilex-hsotg"
aca8fdddee arm64: dts: rockchip: reorder rk3399 hdmi clocks
e49ebea3f5 arm64: dts: rockchip: fix rk3399-puma eMMC HS400 signal integrity
bd33f9b864 xfrm: Fix xfrm migrate issues when address family changes
3c21ece775 xfrm: Check if_id in xfrm_migrate
970a21404e arm64: Use the clearbhb instruction in mitigations
fb65675f66 KVM: arm64: Allow SMCCC_ARCH_WORKAROUND_3 to be discovered and migrated
9013fd4bc9 arm64: Mitigate spectre style branch history side channels
26129ea295 KVM: arm64: Add templates for BHB mitigation sequences
1b735c8dc1 arm64: proton-pack: Report Spectre-BHB vulnerabilities as part of Spectre-v2
c45d885c5a arm64: Add percpu vectors for EL1
1bb1944970 arm64: entry: Add macro for reading symbol addresses from the trampoline
3abf6e8a7a arm64: entry: Add vectors that have the bhb mitigation sequences
2933ca8c81 arm64: entry: Add non-kpti __bp_harden_el1_vectors for mitigations
9232867e4f arm64: entry: Allow the trampoline text to occupy multiple pages
ad8800443b arm64: entry: Make the kpti trampoline's kpti sequence optional
4b91f35c87 arm64: entry: Move trampoline macros out of ifdef'd section
0bfdd73348 arm64: entry: Don't assume tramp_vectors is the start of the vectors
fb117a27c6 arm64: entry: Allow tramp_alias to access symbols after the 4K boundary
788fbb5fe2 arm64: entry: Move the trampoline data page before the text page
33397322d4 arm64: entry: Free up another register on kpti's tramp_exit path
3f95cc642c arm64: entry: Make the trampoline cleanup optional
8aa1257128 arm64: entry.S: Add ventry overflow sanity checks
503fdc244a arm64: Add Cortex-X2 CPU part definition
7103651c98 arm64: add ID_AA64ISAR2_EL1 sys register
f5f94aa500 arm64: Add Neoverse-N2, Cortex-A710 CPU part definition
ed5bf8a507 arm64: Add part number for Arm Cortex-A77
0b84cfaefe sctp: fix the processing for INIT chunk
57e401a53c Revert "xfrm: state and policy should fail if XFRMA_IF_ID 0"
80b62a22cd Merge 5.4.185 into android11-5.4-lts
70f77a2cb5 Linux 5.4.185
afb684cb97 KVM: SVM: Don't flush cache if hardware enforces cache coherency across encryption domains
690909c6d9 x86/mm/pat: Don't flush cache if hardware enforces cache coherency across encryption domnains
6b13a18860 x86/cpu: Add hardware-enforced cache coherency as a CPUID feature
9dd71ec106 x86/cpufeatures: Mark two free bits in word 3
a4eef9e769 ext4: add check to prevent attempting to resize an fs with sparse_super2
269db254c3 ARM: fix Thumb2 regression with Spectre BHB
635959a821 virtio: acknowledge all features before access
ffeb42e05d virtio: unexport virtio_finalize_features
19d57cfbf8 arm64: dts: marvell: armada-37xx: Remap IO space to bus address 0x0
978e4f2648 riscv: Fix auipc+jalr relocation range checks
d6948de3b6 mmc: meson: Fix usage of meson_mmc_post_req()
ba0d7beec2 net: macb: Fix lost RX packet wakeup race in NAPI receive
403e3afe24 staging: gdm724x: fix use after free in gdm_lte_rx()
a9174077fe fuse: fix pipe buffer lifetime for direct_io
d72c79b60d ARM: Spectre-BHB: provide empty stub for non-config
ad66df9064 selftests/memfd: clean up mapping in mfd_fail_write
849c78024e selftest/vm: fix map_fixed_noreplace test failure
500158df87 tracing: Ensure trace buffer is at least 4096 bytes large
090e73fb9c ipv6: prevent a possible race condition with lifetimes
1d4bdaaa8d Revert "xen-netback: Check for hotplug-status existence before watching"
60e4e3198c Revert "xen-netback: remove 'hotplug-status' once it has served its purpose"
8879b5313e net-sysfs: add check for netdevice being present to speed_show
dcf55b071d selftests/bpf: Add test for bpf_timer overwriting crash
e0eca9285c net: bcmgenet: Don't claim WOL when its not available
bbf59d7ae5 sctp: fix kernel-infoleak for SCTP sockets
e934371971 net: phy: DP83822: clear MISR2 register to disable interrupts
f7b3b52034 gianfar: ethtool: Fix refcount leak in gfar_get_ts_info
54fd6b2eb1 gpio: ts4900: Do not set DAT and OE together
82b298e014 selftests: pmtu.sh: Kill tcpdump processes launched by subshell.
cd2a5c0da0 NFC: port100: fix use-after-free in port100_send_complete
1a4017926e net/mlx5: Fix a race on command flush flow
6102e2e5c6 net/mlx5: Fix size field in bufferx_reg struct
0a64aea5fe ax25: Fix NULL pointer dereference in ax25_kill_by_device
45bfd0a937 net: ethernet: lpc_eth: Handle error for clk_enable
e84d37af40 net: ethernet: ti: cpts: Handle error for clk_enable
8ee065a7a9 ethernet: Fix error handling in xemaclite_of_probe
4c0b769d95 ARM: dts: aspeed: Fix AST2600 quad spi group
7db2bc0861 drm/sun4i: mixer: Fix P010 and P210 format numbers
7f8f564141 qed: return status of qed_iov_get_link
f59e786090 net: qlogic: check the return value of dma_alloc_coherent() in qed_vf_hw_prepare()
45d470e4f8 virtio-blk: Don't use MAX_DISCARD_SEGMENTS if max_discard_seg is zero
278b2c7d9f arm64: dts: armada-3720-turris-mox: Add missing ethernet0 alias
f62922b601 clk: qcom: gdsc: Add support to update GDSC transition delay
9ed911a069 Merge 5.4.184 into android11-5.4-lts
8f2333be80 Merge 5.4.183 into android11-5.4-lts
55d2e3e494 ANDROID: fix up rndis ABI breakage
1346e17653 Linux 5.4.184
f7fc9c3487 Revert "ACPI: PM: s2idle: Cancel wakeup before dispatching EC GPE"
0e35f3ab69 xen/netfront: react properly to failing gnttab_end_foreign_access_ref()
782e5ebcc8 xen/gnttab: fix gnttab_end_foreign_access() without page specified
051c4cc7bd xen/pvcalls: use alloc/free_pages_exact()
be63ea883e xen/9p: use alloc/free_pages_exact()
8efaf0c862 xen: remove gnttab_query_foreign_access()
d193785a4b xen/gntalloc: don't use gnttab_query_foreign_access()
089a8e491d xen/scsifront: don't use gnttab_query_foreign_access() for mapped status
b507879c1e xen/netfront: don't use gnttab_query_foreign_access() for mapped status
a83400456f xen/blkfront: don't use gnttab_query_foreign_access() for mapped status
44d86dccd2 xen/grant-table: add gnttab_try_end_foreign_access()
95ff823832 xen/xenbus: don't let xenbus_grant_ring() remove grants in error case
56f1b3c5c8 ARM: fix build warning in proc-v7-bugs.c
40da947ba0 ARM: Do not use NOCROSSREFS directive with ld.lld
583662bfd8 ARM: fix co-processor register typo
21a466c32f ARM: fix build error when BPF_SYSCALL is disabled
d1cfdd5077 ARM: include unprivileged BPF status in Spectre V2 reporting
920f7970cf ARM: Spectre-BHB workaround
dcf33beb49 ARM: use LOADADDR() to get load address of sections
31814db6e4 ARM: early traps initialisation
fdfc0baf82 ARM: report Spectre v2 status through sysfs
26171b016b arm/arm64: smccc/psci: add arm_smccc_1_1_get_conduit()
baaaba74e0 arm/arm64: Provide a wrapper for SMCCC 1.1 calls
6c1599fd1b x86/speculation: Warn about eIBRS + LFENCE + Unprivileged eBPF + SMT
7c77025694 x86/speculation: Warn about Spectre v2 LFENCE mitigation
865da3868b x86/speculation: Update link to AMD speculation whitepaper
b1bacf22a8 x86/speculation: Use generic retpoline by default on AMD
1e47ab3df9 x86/speculation: Include unprivileged eBPF status in Spectre v2 mitigation reporting
327a4da9b0 Documentation/hw-vuln: Update spectre doc
96b3d45aea x86/speculation: Add eIBRS + Retpoline options
41b50510e5 x86/speculation: Rename RETPOLINE_AMD to RETPOLINE_LFENCE
b70bc2e355 x86,bugs: Unconditionally allow spectre_v2=retpoline,amd
22aed24089 x86/speculation: Merge one test in spectre_v2_user_select_mitigation()
e7d1268f56 Linux 5.4.183
5817c13cd6 hamradio: fix macro redefine warning
3c7d63cfa1 net: dcb: disable softirqs in dcbnl_flush_dev()
5f53a6a8ae Revert "xfrm: xfrm_state_mtu should return at least 1280 for ipv6"
f73eb7342b btrfs: add missing run of delayed items after unlink during log replay
f8d4a8eebb btrfs: qgroup: fix deadlock between rescan worker and remove qgroup
39403d72b4 btrfs: fix lost prealloc extents beyond eof after full fsync
4dd5d3310c tracing: Fix return value of __setup handlers
c0f7253376 tracing/histogram: Fix sorting on old "cpu" value
35fa6f2a31 HID: add mapping for KEY_ALL_APPLICATIONS
ecefb8cc0f HID: add mapping for KEY_DICTATE
52b984b17d Input: elan_i2c - fix regulator enable count imbalance after suspend/resume
16eb602ead Input: elan_i2c - move regulator_[en|dis]able() out of elan_[en|dis]able_power()
3f123c305e nl80211: Handle nla_memdup failures in handle_nan_filter
ec89b27646 net: chelsio: cxgb3: check the return value of pci_find_capability()
6650fa5f3b soc: fsl: qe: Check of ioremap return value
e89c53fcd2 memfd: fix F_SEAL_WRITE after shmem huge page allocated
58b07100c2 ibmvnic: free reset-work-item when flushing
2e7abe2efc igc: igc_write_phy_reg_gpy: drop premature return
5c215ea574 ARM: 9182/1: mmu: fix returns from early_param() and __setup() functions
89b881f339 ARM: Fix kgdb breakpoint for Thumb2
87765309bf igc: igc_read_phy_reg_gpy: drop premature return
44ff6c29b2 arm64: dts: rockchip: Switch RK3399-Gru DP to SPDIF output
d59120a489 can: gs_usb: change active_channels's type from atomic_t to u8
bc65372492 ASoC: cs4265: Fix the duplicated control name
cff3987e09 firmware: arm_scmi: Remove space in MODULE_ALIAS name
461a26ebf0 efivars: Respect "block" flag in efivar_entry_set_safe()
b4f4659843 ixgbe: xsk: change !netif_carrier_ok() handling in ixgbe_xmit_zc()
e50c589678 net: arcnet: com20020: Fix null-ptr-deref in com20020pci_probe()
044e209c72 net: sxgbe: fix return value of __setup handler
a54dedf620 iavf: Fix missing check for running netdev
150b8a05d0 net: stmmac: fix return value of __setup handler
e9fa400903 mac80211: fix forwarded mesh frames AC & queue selection
f17b27f3d4 ia64: ensure proper NUMA distance and possible map initialization
80998dbde1 sched/topology: Fix sched_domain_topology_level alloc in sched_init_numa()
407ec382ba sched/topology: Make sched_init_numa() use a set for the deduplicating sort
b40c912624 xen/netfront: destroy queues before real_num_tx_queues is zeroed
fa84d44df4 block: Fix fsync always failed if once failed
849339fd72 net/smc: fix unexpected SMC_CLC_DECL_ERR_REGRMB error cause by server
8e306a76b9 net/smc: fix unexpected SMC_CLC_DECL_ERR_REGRMB error generated by client
1f5abd671d net: dcb: flush lingering app table entries for unregistered devices
ed05368024 batman-adv: Don't expect inter-netns unique iflink indices
8639532271 batman-adv: Request iflink once in batadv_get_real_netdevice
a1ccea6183 batman-adv: Request iflink once in batadv-on-batadv check
43c25da41e netfilter: nf_queue: fix possible use-after-free
3c934f1087 netfilter: nf_queue: don't assume sk is full socket
d2c96b1930 xfrm: enforce validity of offload input flags
019b4b9d59 xfrm: fix the if_id check in changelink
49c24579ce netfilter: fix use-after-free in __nf_register_net_hook()
ac858e4462 xfrm: fix MTU regression
f3537f1b2b ASoC: ops: Shift tested values in snd_soc_put_volsw() by +min
75a471401b ALSA: intel_hdmi: Fix reference to PCM buffer address
e28372b295 ata: pata_hpt37x: fix PCI clock detection
58b419d16e usb: gadget: clear related members when goto fail
ba6fdd55b1 usb: gadget: don't release an existing dev->buf
0babb778ff net: usb: cdc_mbim: avoid altsetting toggling for Telit FN990
a7ef01d25a i2c: qup: allow COMPILE_TEST
da9bf89344 i2c: cadence: allow COMPILE_TEST
bb07c8bb77 dmaengine: shdma: Fix runtime PM imbalance on error
e208668ef7 cifs: fix double free race when mount fails in cifs_get_root()
2ed93e3e3f Input: clear BTN_RIGHT/MIDDLE on buttonpads
7b6d98f869 ASoC: rt5682: do not block workqueue if card is unbound
e2106e429f ASoC: rt5668: do not block workqueue if card is unbound
7b7c65abeb i2c: bcm2835: Avoid clock stretching timeouts
964f155c38 mac80211_hwsim: initialize ieee80211_tx_info at hw_scan_work
1a7d2fccd8 mac80211_hwsim: report NOACK frames in tx_status
31855d74fd Merge 5.4.182 into android11-5.4-lts
866ae42cf4 Linux 5.4.182
fb2bbb7d30 fget: clarify and improve __fget_files() implementation
d6a29ce52a memblock: use kfree() to release kmalloced memblock regions
5d9453bf41 Revert "drm/nouveau/pmu/gm200-: avoid touching PMU outside of DEVINIT/PREOS/ACR"
1fb051bbbc gpio: tegra186: Fix chip_data type confusion
2782b05d02 tty: n_gsm: fix NULL pointer access due to DLCI release
c03a495814 tty: n_gsm: fix proper link termination after failed open
912144e8a3 tty: n_gsm: fix encoding of control signal octet bit DV
1879db4f25 xhci: Prevent futile URB re-submissions due to incorrect return value.
80922d7b52 xhci: re-initialize the HC during resume if HCE was set
0139a10090 usb: dwc3: gadget: Let the interrupt handler disable bottom halves.
6e74aebbf7 usb: dwc3: pci: Fix Bay Trail phy GPIO mappings
ba3e83e5a0 USB: serial: option: add Telit LE910R1 compositions
92ac25b79d USB: serial: option: add support for DW5829e
40256addf5 tracefs: Set the group ownership in apply_options() not parse_options()
6b23eda989 USB: gadget: validate endpoint index for xilinx udc
9ab652d41d usb: gadget: rndis: add spinlock for rndis response list
39848d7e4e Revert "USB: serial: ch341: add new Product ID for CH341A"
7c453de366 ata: pata_hpt37x: disable primary channel on HPT371
a28f8dbd47 iio: Fix error handling for PM
8fff0310e6 iio: adc: ad7124: fix mask used for setting AIN_BUFP & AIN_BUFM bits
ce1076b33e iio: adc: men_z188_adc: Fix a resource leak in an error handling path
cb90ab3f09 tracing: Have traceon and traceoff trigger honor the instance
901206f71e RDMA/ib_srp: Fix a deadlock
b7e2b91fcb configfs: fix a race in configfs_{,un}register_subsystem()
df14d2bed8 spi: spi-zynq-qspi: Fix a NULL pointer dereference in zynq_qspi_exec_mem_op()
a62f4266d5 net/mlx5: Fix wrong limitation of metadata match on ecpf
45618e9157 net/mlx5: Fix possible deadlock on rule deletion
53026346a9 netfilter: nf_tables: fix memory leak during stateful obj update
5ad5886f85 nfp: flower: Fix a potential leak in nfp_tunnel_add_shared_mac()
dfe537b0c9 net: Force inlining of checksum functions in net/checksum.h
eee01c88c9 net: ll_temac: check the return value of devm_kmalloc()
fc92a14fa0 net/mlx5e: Fix wrong return value on ioctl EEPROM query failure
3cbf1f98d8 drm/edid: Always set RGB444
d0251c38df openvswitch: Fix setting ipv6 fields causing hw csum failure
2b3cdd70ea gso: do not skip outer ip header in case of ipip and net_failover
0240bb276f tipc: Fix end of loop tests for list_for_each_entry()
2ed1326376 net: __pskb_pull_tail() & pskb_carve_frag_list() drop_monitor friends
97a6c07d6f bpf: Do not try bpf_msg_push_data with len 0
dffce58f6f perf data: Fix double free in perf_session__delete()
3174b09fe1 ping: remove pr_err from ping_lookup
767099f0ec lan743x: fix deadlock in lan743x_phy_link_status_change()
5d76e0b69d optee: use driver internal tee_context for some rpc
0e526f533f tee: export teedev_open() and teedev_close_context()
64e0b5894c x86/fpu: Correct pkru/xstate inconsistency
49c011a44e netfilter: nf_tables_offload: incorrect flow offload action array size
49a4536a46 USB: zaurus: support another broken Zaurus
b95d71abeb sr9700: sanity check for packet length
d0dac454b9 drm/amdgpu: disable MMHUB PG for Picasso
eb88a38831 parisc/unaligned: Fix ldw() and stw() unalignment handlers
b783ef3eb6 parisc/unaligned: Fix fldd and fstd unaligned handlers on 32-bit kernel
0b608b3392 vhost/vsock: don't check owner in vhost_vsock_stop() while releasing
dd0de35102 clk: jz4725b: fix mmc0 clock gating
d1f1de5dff cgroup/cpuset: Fix a race between cpuset_attach() and cpu hotplug
2867afd647 Revert "netfilter: conntrack: don't refresh sctp entries in closed state"
56f5213db8 Merge 5.4.181 into android11-5.4-lts
b6e8856b8a Linux 5.4.181
3e73b02af6 kconfig: fix failing to generate auto.conf
90c0d3cc67 net: macb: Align the dma and coherent dma masks
f1c3f41245 net: usb: qmi_wwan: Add support for Dell DW5829e
6b364ca481 tracing: Fix tp_printk option related with tp_printk_stop_on_boot
8bf73d5ea9 drm/rockchip: dw_hdmi: Do not leave clock enabled in error case
5a21d50723 ata: libata-core: Disable TRIM on M88V29
41da91158e kconfig: let 'shell' return enough output for deep path names
913932a306 arm64: dts: meson-g12: drop BL32 region from SEI510/SEI610
d2fd1c7804 arm64: dts: meson-g12: add ATF BL32 reserved-memory region
daa8680809 arm64: dts: meson-gx: add ATF BL32 reserved-memory region
ba4b40356a netfilter: conntrack: don't refresh sctp entries in closed state
d4de2bbcbc irqchip/sifive-plic: Add missing thead,c900-plic match string
2d7a327a12 ARM: OMAP2+: adjust the location of put_device() call in omapdss_init_of
fff21185f5 ARM: OMAP2+: hwmod: Add of_node_put() before break
3deabc3f60 KVM: x86/pmu: Use AMD64_RAW_EVENT_MASK for PERF_TYPE_RAW
fe595759c2 Drivers: hv: vmbus: Fix memory leak in vmbus_add_channel_kobj
ba71b1b30d i2c: brcmstb: fix support for DSL and CM variants
6f08452c56 copy_process(): Move fd_install() out of sighand->siglock critical section
e52dfd2a49 dmaengine: sh: rcar-dmac: Check for error num after setting mask
c83049cb88 net: sched: limit TC_ACT_REPEAT loops
87c575d2a2 lib/iov_iter: initialize "flags" in new pipe_buffer
091dac5c63 EDAC: Fix calculation of returned address and next offset in edac_align_ptr()
f0c2c023c2 scsi: lpfc: Fix pt2pt NVMe PRLI reject LOGO loop
56f9abba98 mtd: rawnand: brcmnand: Fixed incorrect sub-page ECC status
bdc70b603d mtd: rawnand: qcom: Fix clock sequencing in qcom_nandc_probe()
3758a57076 NFS: Do not report writeback errors in nfs_getattr()
357d42d593 NFS: LOOKUP_DIRECTORY is also ok with symlinks
20f4ee3c33 block/wbt: fix negative inflight counter when remove scsi device
4cd3281a91 mtd: rawnand: gpmi: don't leak PM reference in error path
c6fee7c854 powerpc/lib/sstep: fix 'ptesync' build error
edfac6b77b ASoC: ops: Fix stereo change notifications in snd_soc_put_volsw_range()
d6d8d1db80 ASoC: ops: Fix stereo change notifications in snd_soc_put_volsw()
99c2b13ce9 ALSA: hda: Fix missing codec probe on Shenker Dock 15
2b2b531ceb ALSA: hda: Fix regression on forced probe mask option
aca7e5b6a5 libsubcmd: Fix use-after-free for realloc(..., 0)
7af6164cee bonding: fix data-races around agg_select_timer
aeb993412e drop_monitor: fix data-race in dropmon_net_event / trace_napi_poll_hit
db3ffc5d33 bonding: force carrier update when releasing slave
fb8c98f92a ping: fix the dif and sdif check in ping_lookup
8198c4d4c2 net: ieee802154: ca8210: Fix lifs/sifs periods
a06440508a net: dsa: lan9303: fix reset on probe
73f8575216 netfilter: nft_synproxy: unregister hooks on init error path
5e8c5b217c iwlwifi: pcie: gen2: fix locking when "HW not ready"
e1d0e738b0 iwlwifi: pcie: fix locking when "HW not ready"
902528183f mmc: block: fix read single on recovery logic
5f326fe2ae vsock: remove vsock from connected table when connect is interrupted by a signal
f48a38703c dmaengine: at_xdmac: Start transfer for cyclic channels in issue_pending
41ce06a3ec taskstats: Cleanup the use of task->exit_code
8583d2ea90 ext4: prevent partial update of the extent blocks
d57fcf0d91 ext4: check for inconsistent extents between index and leaf block
6a332d095c ext4: check for out-of-order index extents in ext4_valid_extent_entries()
13f6ebef03 drm/radeon: Fix backlight control on iMac 12,1
494de920d9 iwlwifi: fix use-after-free
6194b46897 arm64: module/ftrace: intialize PLT at load time
adcc4b795f arm64: module: rework special section handling
dfe928f16c module/ftrace: handle patchable-function-entry
30af4dcfa8 ftrace: add ftrace_init_nop()
42c8cccf83 Revert "module, async: async_synchronize_full() on module init iff async is used"
5c7726bd57 drm/amdgpu: fix logic inversion in check
d411b2a5da nvme-rdma: fix possible use-after-free in transport error_recovery work
61a26ffd5a nvme-tcp: fix possible use-after-free in transport error_recovery work
70356b756a nvme: fix a possible use-after-free in controller reset during load
89d2bd1325 quota: make dquot_quota_sync return errors from ->sync_fs
f124d9eff9 vfs: make freeze_super abort when sync_filesystem returns error
cfc8b37ef0 ax25: improve the incomplete fix to avoid UAF and NPD bugs
dd2fcac324 selftests/zram: Adapt the situation that /dev/zram0 is being used
c3a9afa824 selftests/zram01.sh: Fix compression ratio calculation
8d1c50c868 selftests/zram: Skip max_comp_streams interface on newer kernel
455ef08d6e net: ieee802154: at86rf230: Stop leaking skb's
3bd8bebb16 selftests: rtc: Increase test timeout so that all tests run
bc6ac6c0f6 platform/x86: ISST: Fix possible circular locking dependency detected
bd6492930a btrfs: send: in case of IO error log it
3ff48a67ed parisc: Fix sglist access in ccio-dma.c
efccc9b0c7 parisc: Fix data TLB miss in sba_unmap_sg
3434d8837f parisc: Drop __init from map_pages declaration
bd282ee53e serial: parisc: GSC: fix build when IOSAPIC is not set
9d2aad133b Revert "svm: Add warning message for AVIC IPI invalid target"
1902725520 HID:Add support for UGTABLET WP5540
866a85813b Makefile.extrawarn: Move -Wunaligned-access to W=1

Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: Ic789d7f387b2848b0c0a9a72d4867720841a5e2b
2022-05-24 14:46:57 +02:00
Sachin Gupta
e7792e2790 BACKPORT: scsi: ufs: Resume ufs host before accessing ufs device
As a part of sysfs reading of descriptors/attributes/flags,
query commands should only be executed when hba's
power runtime status is active.
To guarantee this, add pm_runtime_get/put_sync()
to those paths where query commands are sent.

Bug: 232878917
Link: https://lore.kernel.org/r/f712a4f7bdb0ae32e0d83634731e7aaa1b3a6cdd.1585009663.git.asutoshd@codeaurora.org
Change-Id: I56b89be3ac850794b874a7b46295a8d12ef4ea02
(cherry picked from commit 0c2039dc1591bb9a3b887753b37946f09f4bf208)
[sachgupt: Resolved minor conflict in drivers/scsi/ufs/ufs-sysfs.c]
Signed-off-by: Nitin Rawat <quic_nitirawa@quicinc.com>
Signed-off-by: Sachin Gupta <quic_sachgupt@quicinc.com>
2022-05-17 20:45:20 +00:00
Hangyu Hua
12bf063cb9 BACKPORT: can: ems_usb: ems_usb_start_xmit(): fix double dev_kfree_skb() in error path
commit c70222752228a62135cee3409dccefd494a24646 upstream.

There is no need to call dev_kfree_skb() when usb_submit_urb() fails
beacause can_put_echo_skb() deletes the original skb and
can_free_echo_skb() deletes the cloned skb.

Bug: 228694391
Link: https://lore.kernel.org/all/20220228083639.38183-1-hbh25y@gmail.com
Fixes: 702171adee ("ems_usb: Added support for EMS CPC-USB/ARM7 CAN/USB interface")
Cc: stable@vger.kernel.org
Cc: Sebastian Haas <haas@ems-wuensche.com>
Signed-off-by: Hangyu Hua <hbh25y@gmail.com>
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Lee Jones <lee.jones@linaro.org>
Change-Id: Ia678a0b249eae6e80823461f18eb315ec5385eab
2022-05-17 16:04:38 +00:00
Aran Dalton
1ae6fd7e6f ANDROID: ABI: Added symbols for allwinner
Leaf changes summary: 1 artifact changed
Changed leaf types summary: 0 leaf type changed
Removed/Changed/Added functions summary: 0 Removed, 0 Changed, 1 Added function
Removed/Changed/Added variables summary: 0 Removed, 0 Changed, 0 Added variable

1 Added function:

  [A] 'function void devm_extcon_dev_free(device*, extcon_dev*)'

Bug: 231769124
Change-Id: I962814563554a960d45adb18def5987aaff25c65
Signed-off-by: Aran Dalton <arda@allwinnertech.com>
2022-05-17 09:46:27 +08:00
Hangyu Hua
7d33bb909e BACKPORT: can: usb_8dev: usb_8dev_start_xmit(): fix double dev_kfree_skb() in error path
commit 3d3925ff6433f98992685a9679613a2cc97f3ce2 upstream.

There is no need to call dev_kfree_skb() when usb_submit_urb() fails
because can_put_echo_skb() deletes original skb and
can_free_echo_skb() deletes the cloned skb.

Bug: 228694483
Fixes: 0024d8ad16 ("can: usb_8dev: Add support for USB2CAN interface from 8 devices")
Link: https://lore.kernel.org/all/20220311080614.45229-1-hbh25y@gmail.com
Cc: stable@vger.kernel.org
Signed-off-by: Hangyu Hua <hbh25y@gmail.com>
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Lee Jones <lee.jones@linaro.org>
Change-Id: I3c9191dd936d82e7c692fad33919b766e69ed7b5
2022-05-16 12:16:54 +01:00
Steffen Klassert
09c810c77d BACKPORT: esp: Fix possible buffer overflow in ESP transformation
commit ebe48d368e97d007bfeb76fcb065d6cfc4c96645 upstream.

The maximum message size that can be send is bigger than
the  maximum site that skb_page_frag_refill can allocate.
So it is possible to write beyond the allocated buffer.

Fix this by doing a fallback to COW in that case.

v2:

Avoid get get_order() costs as suggested by Linus Torvalds.

Bug: 227452856
Fixes: cac2661c53 ("esp4: Avoid skb_cow_data whenever possible")
Fixes: 03e2a30f6a ("esp6: Avoid skb_cow_data whenever possible")
Reported-by: valis <sec@valis.email>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Tadeusz Struk <tadeusz.struk@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Change-Id: I2c7f97914138271e7788adfcebbd0b2b8b43cdcb
Signed-off-by: Lee Jones <lee.jones@linaro.org>
2022-05-13 09:52:20 +01:00
Srinivasarao Pathipati
f896faff41 ANDROID: ABI: Update allowed list for QCOM
Update the android/abi_gki_aarch64_qcom with API kill_anon_super.

Bug: 230828747
Change-Id: I5abe6a5a27f343997ef8a83beb3b0adee796a23c
Signed-off-by: Srinivasarao Pathipati <quic_spathi@quicinc.com>
2022-05-11 15:39:17 +05:30
Lee Jones
0840b18507 ANDROID: dm-bow: Protect Ranges fetched and erased from the RB tree
Bug: 195565510
Signed-off-by: Lee Jones <lee.jones@linaro.org>
Change-Id: Ic8134eb902aa7d929e3121b2f69b1d258f570652
(cherry picked from commit 98c15b2bad1a277da43c65c642f8c3c3ee07bacc)
2022-05-10 11:42:43 +00:00
Lee Jones
7f04e0c309 BACKPORT: staging: ion: Prevent incorrect reference counting behavour
Supply additional check in order to prevent unexpected results.

Bug: 205573273
Fixes: b892bf75b2 ("ion: Switch ion to use dma-buf")
Suggested-by: Dan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: Lee Jones <lee.jones@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
[Lee: Patch now applies to ion_buffer.c instead of ion.c]
Change-Id: Ia6afdd9ca502caa9cad6619d438fc6c8e8457679
(cherry picked from commit 27da8d16e4)
2022-05-10 10:33:28 +00:00
Lina Wang
9adbfa635e FROMGIT: net: fix wrong network header length
When clatd starts with ebpf offloaing, and NETIF_F_GRO_FRAGLIST is enable,
several skbs are gathered in skb_shinfo(skb)->frag_list. The first skb's
ipv6 header will be changed to ipv4 after bpf_skb_proto_6_to_4,
network_header\transport_header\mac_header have been updated as ipv4 acts,
but other skbs in frag_list didnot update anything, just ipv6 packets.

udp_queue_rcv_skb will call skb_segment_list to traverse other skbs in
frag_list and make sure right udp payload is delivered to user space.
Unfortunately, other skbs in frag_list who are still ipv6 packets are
updated like the first skb and will have wrong transport header length.

e.g.before bpf_skb_proto_6_to_4,the first skb and other skbs in frag_list
has the same network_header(24)& transport_header(64), after
bpf_skb_proto_6_to_4, ipv6 protocol has been changed to ipv4, the first
skb's network_header is 44,transport_header is 64, other skbs in frag_list
didnot change.After skb_segment_list, the other skbs in frag_list has
different network_header(24) and transport_header(44), so there will be 20
bytes different from original,that is difference between ipv6 header and
ipv4 header. Just change transport_header to be the same with original.

Actually, there are two solutions to fix it, one is traversing all skbs
and changing every skb header in bpf_skb_proto_6_to_4, the other is
modifying frag_list skb's header in skb_segment_list. Considering
efficiency, adopt the second one--- when the first skb and other skbs in
frag_list has different network_header length, restore them to make sure
right udp payload is delivered to user space.

Signed-off-by: Lina Wang <lina.wang@mediatek.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
(cherry picked from commit cf3ab8d4a797960b4be20565abb3bcd227b18a68 https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net.git master)
Bug: 218157620
Test: TreeHugger
Signed-off-by: Maciej Żenczykowski <maze@google.com>
Change-Id: I36f2f329ec1a56bb0742141a7fa482cafa183ad3
2022-05-09 16:01:57 +00:00
Lecopzer Chen
2586f0405b ANDROID: fix KCFLAGS override by __ANDROID_COMMON_KERNEL__
Our test build is broken by KCFLAGS overrided in build.config.comm.

Since Linux Makefile supports 'export KCFLAGS=XXX' to customize the
KCFLAGS, and we should keep this functionality.

Bug: 230818006
Fixes: d2ed4cfcd5 ("ANDROID: Add flag to indicate compiling against ACK")
Signed-off-by: Lecopzer Chen <lecopzer.chen@mediatek.com>
Change-Id: I9425d79697bc1fe816ce82d523f91631dee6b8f4
2022-04-29 17:53:05 +00:00
Elliot Berman
d2ed4cfcd5 ANDROID: Add flag to indicate compiling against ACK
Add a flag: __ANDROID_COMMON_KERNEL__ which out-of-tree vendor drivers
can use to check if they are compiling against an Android Common Kernel.
These out-of-tree vendor drivers can use this flag +
LINUX_KERNEL_VERSION to determine if a feature has been backported.

Bug: 229953929
Change-Id: I832344d63f3639479784753edfb7ac405068312f
Signed-off-by: Elliot Berman <quic_eberman@quicinc.com>
2022-04-28 20:48:57 +00:00
Eric Dumazet
850a2f987c BACKPORT: net/packet: fix slab-out-of-bounds access in packet_recvmsg()
[ Upstream commit c700525fcc06b05adfea78039de02628af79e07a ]

syzbot found that when an AF_PACKET socket is using PACKET_COPY_THRESH
and mmap operations, tpacket_rcv() is queueing skbs with
garbage in skb->cb[], triggering a too big copy [1]

Presumably, users of af_packet using mmap() already gets correct
metadata from the mapped buffer, we can simply make sure
to clear 12 bytes that might be copied to user space later.

BUG: KASAN: stack-out-of-bounds in memcpy include/linux/fortify-string.h:225 [inline]
BUG: KASAN: stack-out-of-bounds in packet_recvmsg+0x56c/0x1150 net/packet/af_packet.c:3489
Write of size 165 at addr ffffc9000385fb78 by task syz-executor233/3631

CPU: 0 PID: 3631 Comm: syz-executor233 Not tainted 5.17.0-rc7-syzkaller-02396-g0b3660695e80 #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Call Trace:
 <TASK>
 __dump_stack lib/dump_stack.c:88 [inline]
 dump_stack_lvl+0xcd/0x134 lib/dump_stack.c:106
 print_address_description.constprop.0.cold+0xf/0x336 mm/kasan/report.c:255
 __kasan_report mm/kasan/report.c:442 [inline]
 kasan_report.cold+0x83/0xdf mm/kasan/report.c:459
 check_region_inline mm/kasan/generic.c:183 [inline]
 kasan_check_range+0x13d/0x180 mm/kasan/generic.c:189
 memcpy+0x39/0x60 mm/kasan/shadow.c:66
 memcpy include/linux/fortify-string.h:225 [inline]
 packet_recvmsg+0x56c/0x1150 net/packet/af_packet.c:3489
 sock_recvmsg_nosec net/socket.c:948 [inline]
 sock_recvmsg net/socket.c:966 [inline]
 sock_recvmsg net/socket.c:962 [inline]
 ____sys_recvmsg+0x2c4/0x600 net/socket.c:2632
 ___sys_recvmsg+0x127/0x200 net/socket.c:2674
 __sys_recvmsg+0xe2/0x1a0 net/socket.c:2704
 do_syscall_x64 arch/x86/entry/common.c:50 [inline]
 do_syscall_64+0x35/0xb0 arch/x86/entry/common.c:80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7fdfd5954c29
Code: 28 00 00 00 75 05 48 83 c4 28 c3 e8 41 15 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 c0 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007ffcf8e71e48 EFLAGS: 00000246 ORIG_RAX: 000000000000002f
RAX: ffffffffffffffda RBX: 0000000000000003 RCX: 00007fdfd5954c29
RDX: 0000000000000000 RSI: 0000000020000500 RDI: 0000000000000005
RBP: 0000000000000000 R08: 000000000000000d R09: 000000000000000d
R10: 0000000000000000 R11: 0000000000000246 R12: 00007ffcf8e71e60
R13: 00000000000f4240 R14: 000000000000c1ff R15: 00007ffcf8e71e54
 </TASK>

addr ffffc9000385fb78 is located in stack of task syz-executor233/3631 at offset 32 in frame:
 ____sys_recvmsg+0x0/0x600 include/linux/uio.h:246

this frame has 1 object:
 [32, 160) 'addr'

Memory state around the buggy address:
 ffffc9000385fa80: 00 04 f3 f3 f3 f3 f3 00 00 00 00 00 00 00 00 00
 ffffc9000385fb00: 00 00 00 00 00 00 00 00 00 00 00 f1 f1 f1 f1 00
>ffffc9000385fb80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 f3
                                                                ^
 ffffc9000385fc00: f3 f3 f3 00 00 00 00 00 00 00 00 00 00 00 00 f1
 ffffc9000385fc80: f1 f1 f1 00 f2 f2 f2 00 f2 f2 f2 00 00 00 00 00
==================================================================

Bug: 224546354
Fixes: 0fb375fb9b ("[AF_PACKET]: Allow for > 8 byte hardware addresses.")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reported-by: syzbot <syzkaller@googlegroups.com>
Link: https://lore.kernel.org/r/20220312232958.3535620-1-eric.dumazet@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Lee Jones <lee.jones@linaro.org>
Change-Id: I37e4a05a8d81b2645bc65db002e644b40d1a984d
2022-04-28 12:16:30 +00:00
Xie Yongji
45e2b6a26f BACKPORT: block: Add a helper to validate the block size
commit 570b1cac477643cbf01a45fa5d018430a1fddbce upstream.

There are some duplicated codes to validate the block
size in block drivers. This limitation actually comes
from block layer, so this patch tries to add a new block
layer helper for that.

Bug: 226679849
Signed-off-by: Xie Yongji <xieyongji@bytedance.com>
Link: https://lore.kernel.org/r/20211026144015.188-2-xieyongji@bytedance.com
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Lee Jones <lee.jones@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Change-Id: I869a720a18f85fac878459f719cae6a7183a8745
2022-04-28 12:11:10 +00:00
Xie Yongji
353ca06c86 BACKPORT: virtio-blk: Use blk_validate_block_size() to validate block size
The block layer can't support a block size larger than
page size yet. And a block size that's too small or
not a power of two won't work either. If a misconfigured
device presents an invalid block size in configuration space,
it will result in the kernel crash something like below:

[  506.154324] BUG: kernel NULL pointer dereference, address: 0000000000000008
[  506.160416] RIP: 0010:create_empty_buffers+0x24/0x100
[  506.174302] Call Trace:
[  506.174651]  create_page_buffers+0x4d/0x60
[  506.175207]  block_read_full_page+0x50/0x380
[  506.175798]  ? __mod_lruvec_page_state+0x60/0xa0
[  506.176412]  ? __add_to_page_cache_locked+0x1b2/0x390
[  506.177085]  ? blkdev_direct_IO+0x4a0/0x4a0
[  506.177644]  ? scan_shadow_nodes+0x30/0x30
[  506.178206]  ? lru_cache_add+0x42/0x60
[  506.178716]  do_read_cache_page+0x695/0x740
[  506.179278]  ? read_part_sector+0xe0/0xe0
[  506.179821]  read_part_sector+0x36/0xe0
[  506.180337]  adfspart_check_ICS+0x32/0x320
[  506.180890]  ? snprintf+0x45/0x70
[  506.181350]  ? read_part_sector+0xe0/0xe0
[  506.181906]  bdev_disk_changed+0x229/0x5c0
[  506.182483]  blkdev_get_whole+0x6d/0x90
[  506.183013]  blkdev_get_by_dev+0x122/0x2d0
[  506.183562]  device_add_disk+0x39e/0x3c0
[  506.184472]  virtblk_probe+0x3f8/0x79b [virtio_blk]
[  506.185461]  virtio_dev_probe+0x15e/0x1d0 [virtio]

So let's use a block layer helper to validate the block size.

Signed-off-by: Xie Yongji <xieyongji@bytedance.com>
Acked-by: Michael S. Tsirkin <mst@redhat.com>
Link: https://lore.kernel.org/r/20211026144015.188-5-xieyongji@bytedance.com
Signed-off-by: Jens Axboe <axboe@kernel.dk>
(cherry picked from commit 57a13a5b8157d9a8606490aaa1b805bafe6c37e1)
[keirf@: Implement missing error path]
Bug: 226679849
Signed-off-by: Keir Fraser <keirf@google.com>
Change-Id: I78cde1101baf8da2f68d0b9f942a0f1ec89fb30e
(cherry picked from commit 588affc843da96cda1747b4caa8fcd9bd8796d3c)
2022-04-28 11:35:38 +00:00
Greg Kroah-Hartman
84c84ac7a3 Revert "oom_kill.c: futex: delay the OOM reaper to allow time for proper futex cleanup"
This reverts commit 0441d3e95b.  It breaks
the abi and is not needed for Android devices.

Bug: 161946584
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: I0d9f161b4250bb6ec960e2a5ee2f425f6f8dbf4e
2022-04-27 15:56:55 +02:00
Greg Kroah-Hartman
36dda9143f This is the 5.4.191 stable release
-----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCAAdFiEEZH8oZUiU471FcZm+ONu9yGCSaT4FAmJpLh8ACgkQONu9yGCS
 aT4c2RAAipfvQHTVXY0hA9eXQUE9JVZQoKsh/m/SF5Q46oADN8y/JDwMEhbyrE5R
 tyOxSyXWTZ6gIgjevqG0FnRfH2E1E++0rH0l3snCDCPSq11LoK+rV7K1tWIm6nJQ
 AMgc/ooWgI9Ah4PfVei2hEvHy+Ejho8YNs+aw9wA3z95kySUE2PmNpwIkSluN3wr
 dH5jqi4J7xzc+DSU/hI24PFPdW4TQjYbw0D6a4HJAm4cbv7lHDRwN/Y1OTMfmKT4
 A3pG6ITTCAC9oQeLAu786fJgK+RFdMHj9VPgRZdZK18SiQ5jSJlGPetqklCcrL/7
 kR3hMl1tHR6NldNyaCTsqiAJXngbz5oIZh+zt8a1QMm7TtcAd1Zktp8Kt/ommWqs
 jv3IsZmcZ2VNhfcRy+yj8b20Yc+IrwG5An+5U4I7Rt236GmWB3GcZkV9QTSd9k+Y
 hFN/LU3p8T2T7v9kddsnofm8cnTmc6C6aTpfSQYjrbT3sJ5Glok1saYX8uYffLN+
 7Q+UfgLfTELr7JLZqdLtcasyZIkQvGR6HQsoxyrB5lbMy77t5eedjheu+ai5Rl6j
 3yM3o0xKYV6O5lrFK0PS4IcagCpwPsZX6ZwB4fnGa1Zpd2s1axAINrPyHTKYsIX5
 H4B0daJltyuUB7XQqLVwJQFgAEKtEMaSVno+B8EVwPkcBz4AYd0=
 =FAKD
 -----END PGP SIGNATURE-----

Merge 5.4.191 into android11-5.4-lts

Changes in 5.4.191
	etherdevice: Adjust ether_addr* prototypes to silence -Wstringop-overead
	mm: page_alloc: fix building error on -Werror=array-compare
	tracing: Dump stacktrace trigger to the corresponding instance
	can: usb_8dev: usb_8dev_start_xmit(): fix double dev_kfree_skb() in error path
	gfs2: assign rgrp glock before compute_bitstructs
	tcp: fix race condition when creating child sockets from syncookies
	net/sched: cls_u32: fix netns refcount changes in u32_change()
	tcp: Fix potential use-after-free due to double kfree()
	ALSA: usb-audio: Clear MIDI port active flag after draining
	ASoC: atmel: Remove system clock tree configuration for at91sam9g20ek
	ASoC: msm8916-wcd-digital: Check failure for devm_snd_soc_register_component
	dmaengine: imx-sdma: Fix error checking in sdma_event_remap
	dmaengine: mediatek:Fix PM usage reference leak of mtk_uart_apdma_alloc_chan_resources
	igc: Fix infinite loop in release_swfw_sync
	igc: Fix BUG: scheduling while atomic
	rxrpc: Restore removed timer deletion
	net/smc: Fix sock leak when release after smc_shutdown()
	net/packet: fix packet_sock xmit return value checking
	net/sched: cls_u32: fix possible leak in u32_init_knode()
	l3mdev: l3mdev_master_upper_ifindex_by_index_rcu should be using netdev_master_upper_dev_get_rcu
	netlink: reset network and mac headers in netlink_dump()
	selftests: mlxsw: vxlan_flooding: Prevent flooding of unwanted packets
	ARM: vexpress/spc: Avoid negative array index when !SMP
	reset: tegra-bpmp: Restore Handle errors in BPMP response
	platform/x86: samsung-laptop: Fix an unsigned comparison which can never be negative
	ALSA: usb-audio: Fix undefined behavior due to shift overflowing the constant
	vxlan: fix error return code in vxlan_fdb_append
	cifs: Check the IOCB_DIRECT flag, not O_DIRECT
	mt76: Fix undefined behavior due to shift overflowing the constant
	brcmfmac: sdio: Fix undefined behavior due to shift overflowing the constant
	dpaa_eth: Fix missing of_node_put in dpaa_get_ts_info()
	drm/msm/mdp5: check the return of kzalloc()
	net: macb: Restart tx only if queue pointer is lagging
	scsi: qedi: Fix failed disconnect handling
	stat: fix inconsistency between struct stat and struct compat_stat
	EDAC/synopsys: Read the error count from the correct register
	oom_kill.c: futex: delay the OOM reaper to allow time for proper futex cleanup
	ata: pata_marvell: Check the 'bmdma_addr' beforing reading
	dma: at_xdmac: fix a missing check on list iterator
	drm/panel/raspberrypi-touchscreen: Avoid NULL deref if not initialised
	drm/panel/raspberrypi-touchscreen: Initialise the bridge in prepare
	KVM: PPC: Fix TCE handling for VFIO
	drm/vc4: Use pm_runtime_resume_and_get to fix pm_runtime_get_sync() usage
	powerpc/perf: Fix power9 event alternatives
	xtensa: patch_text: Fixup last cpu should be master
	xtensa: fix a7 clobbering in coprocessor context load/store
	openvswitch: fix OOB access in reserve_sfa_size()
	ASoC: soc-dapm: fix two incorrect uses of list iterator
	e1000e: Fix possible overflow in LTR decoding
	ARC: entry: fix syscall_trace_exit argument
	arm_pmu: Validate single/group leader events
	ext4: fix symlink file size not match to file content
	ext4: fix use-after-free in ext4_search_dir
	ext4: limit length to bitmap_maxbytes - blocksize in punch_hole
	ext4, doc: fix incorrect h_reserved size
	ext4: fix overhead calculation to account for the reserved gdt blocks
	ext4: force overhead calculation if the s_overhead_cluster makes no sense
	jbd2: fix a potential race while discarding reserved buffers after an abort
	spi: atmel-quadspi: Fix the buswidth adjustment between spi-mem and controller
	staging: ion: Prevent incorrect reference counting behavour
	block/compat_ioctl: fix range check in BLKGETSIZE
	Revert "net: micrel: fix KS8851_MLL Kconfig"
	Linux 5.4.191

Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: Id8dee2348cd339ea32e592787839af337292ad17
2022-04-27 14:24:26 +02:00
Greg Kroah-Hartman
4426e6017f Linux 5.4.191
Link: https://lore.kernel.org/r/20220426081737.209637816@linuxfoundation.org
Tested-by: Jon Hunter <jonathanh@nvidia.com>
Tested-by: Florian Fainelli <f.fainelli@gmail.com>
Tested-by: Guenter Roeck <linux@roeck-us.net>
Tested-by: Shuah Khan <skhan@linuxfoundation.org>
Tested-by: Linux Kernel Functional Testing <lkft@linaro.org>
Tested-by: Sudip Mukherjee <sudip.mukherjee@codethink.co.uk>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-04-27 13:50:51 +02:00
Marek Vasut
3c946909a3 Revert "net: micrel: fix KS8851_MLL Kconfig"
This reverts commit 4cd3c9e070 which is
commit c3efcedd272aa6dd5929e20cf902a52ddaa1197a upstream.

The upstream commit c3efcedd272a ("net: micrel: fix KS8851_MLL Kconfig")
depends on e5f31552674e ("ethernet: fix PTP_1588_CLOCK dependencies")
which is not part of Linux 5.4.y . Revert the aforementioned commit to
prevent breakage in 5.4.y .

Signed-off-by: Marek Vasut <marex@denx.de>
Cc: David S. Miller <davem@davemloft.net>
Cc: Jakub Kicinski <kuba@kernel.org>
Cc: Paolo Abeni <pabeni@redhat.com>
Cc: Randy Dunlap <rdunlap@infradead.org>
Cc: Sasha Levin <sashal@kernel.org>
Cc: <stable@vger.kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-04-27 13:50:51 +02:00
Khazhismel Kumykov
c028b81d06 block/compat_ioctl: fix range check in BLKGETSIZE
commit ccf16413e520164eb718cf8b22a30438da80ff23 upstream.

kernel ulong and compat_ulong_t may not be same width. Use type directly
to eliminate mismatches.

This would result in truncation rather than EFBIG for 32bit mode for
large disks.

Reviewed-by: Bart Van Assche <bvanassche@acm.org>
Signed-off-by: Khazhismel Kumykov <khazhy@google.com>
Reviewed-by: Chaitanya Kulkarni <kch@nvidia.com>
Link: https://lore.kernel.org/r/20220414224056.2875681-1-khazhy@google.com
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-04-27 13:50:50 +02:00
Lee Jones
27da8d16e4 staging: ion: Prevent incorrect reference counting behavour
Supply additional check in order to prevent unexpected results.

Fixes: b892bf75b2 ("ion: Switch ion to use dma-buf")
Suggested-by: Dan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: Lee Jones <lee.jones@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-04-27 13:50:50 +02:00
Tudor Ambarus
cb158b152e spi: atmel-quadspi: Fix the buswidth adjustment between spi-mem and controller
commit 8c235cc25087495c4288d94f547e9d3061004991 upstream.

Use the spi_mem_default_supports_op() core helper in order to take into
account the buswidth specified by the user in device tree.

Cc: <stable@vger.kernel.org>
Fixes: 0e6aae08e9 ("spi: Add QuadSPI driver for Atmel SAMA5D2")
Signed-off-by: Tudor Ambarus <tudor.ambarus@microchip.com>
Link: https://lore.kernel.org/r/20220406133604.455356-1-tudor.ambarus@microchip.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-04-27 13:50:50 +02:00
Ye Bin
1b6ad24210 jbd2: fix a potential race while discarding reserved buffers after an abort
commit 23e3d7f7061f8682c751c46512718f47580ad8f0 upstream.

we got issue as follows:
[   72.796117] EXT4-fs error (device sda): ext4_journal_check_start:83: comm fallocate: Detected aborted journal
[   72.826847] EXT4-fs (sda): Remounting filesystem read-only
fallocate: fallocate failed: Read-only file system
[   74.791830] jbd2_journal_commit_transaction: jh=0xffff9cfefe725d90 bh=0x0000000000000000 end delay
[   74.793597] ------------[ cut here ]------------
[   74.794203] kernel BUG at fs/jbd2/transaction.c:2063!
[   74.794886] invalid opcode: 0000 [#1] PREEMPT SMP PTI
[   74.795533] CPU: 4 PID: 2260 Comm: jbd2/sda-8 Not tainted 5.17.0-rc8-next-20220315-dirty #150
[   74.798327] RIP: 0010:__jbd2_journal_unfile_buffer+0x3e/0x60
[   74.801971] RSP: 0018:ffffa828c24a3cb8 EFLAGS: 00010202
[   74.802694] RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000000
[   74.803601] RDX: 0000000000000001 RSI: ffff9cfefe725d90 RDI: ffff9cfefe725d90
[   74.804554] RBP: ffff9cfefe725d90 R08: 0000000000000000 R09: ffffa828c24a3b20
[   74.805471] R10: 0000000000000001 R11: 0000000000000001 R12: ffff9cfefe725d90
[   74.806385] R13: ffff9cfefe725d98 R14: 0000000000000000 R15: ffff9cfe833a4d00
[   74.807301] FS:  0000000000000000(0000) GS:ffff9d01afb00000(0000) knlGS:0000000000000000
[   74.808338] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[   74.809084] CR2: 00007f2b81bf4000 CR3: 0000000100056000 CR4: 00000000000006e0
[   74.810047] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
[   74.810981] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
[   74.811897] Call Trace:
[   74.812241]  <TASK>
[   74.812566]  __jbd2_journal_refile_buffer+0x12f/0x180
[   74.813246]  jbd2_journal_refile_buffer+0x4c/0xa0
[   74.813869]  jbd2_journal_commit_transaction.cold+0xa1/0x148
[   74.817550]  kjournald2+0xf8/0x3e0
[   74.819056]  kthread+0x153/0x1c0
[   74.819963]  ret_from_fork+0x22/0x30

Above issue may happen as follows:
        write                   truncate                   kjournald2
generic_perform_write
 ext4_write_begin
  ext4_walk_page_buffers
   do_journal_get_write_access ->add BJ_Reserved list
 ext4_journalled_write_end
  ext4_walk_page_buffers
   write_end_fn
    ext4_handle_dirty_metadata
                ***************JBD2 ABORT**************
     jbd2_journal_dirty_metadata
 -> return -EROFS, jh in reserved_list
                                                   jbd2_journal_commit_transaction
                                                    while (commit_transaction->t_reserved_list)
                                                      jh = commit_transaction->t_reserved_list;
                        truncate_pagecache_range
                         do_invalidatepage
			  ext4_journalled_invalidatepage
			   jbd2_journal_invalidatepage
			    journal_unmap_buffer
			     __dispose_buffer
			      __jbd2_journal_unfile_buffer
			       jbd2_journal_put_journal_head ->put last ref_count
			        __journal_remove_journal_head
				 bh->b_private = NULL;
				 jh->b_bh = NULL;
				                      jbd2_journal_refile_buffer(journal, jh);
							bh = jh2bh(jh);
							->bh is NULL, later will trigger null-ptr-deref
				 journal_free_journal_head(jh);

After commit 96f1e09745, we no longer hold the j_state_lock while
iterating over the list of reserved handles in
jbd2_journal_commit_transaction().  This potentially allows the
journal_head to be freed by journal_unmap_buffer while the commit
codepath is also trying to free the BJ_Reserved buffers.  Keeping
j_state_lock held while trying extends hold time of the lock
minimally, and solves this issue.

Fixes: 96f1e0974575("jbd2: avoid long hold times of j_state_lock while committing a transaction")
Signed-off-by: Ye Bin <yebin10@huawei.com>
Reviewed-by: Jan Kara <jack@suse.cz>
Link: https://lore.kernel.org/r/20220317142137.1821590-1-yebin10@huawei.com
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-04-27 13:50:50 +02:00
Theodore Ts'o
0b1ba14ab2 ext4: force overhead calculation if the s_overhead_cluster makes no sense
commit 85d825dbf4899a69407338bae462a59aa9a37326 upstream.

If the file system does not use bigalloc, calculating the overhead is
cheap, so force the recalculation of the overhead so we don't have to
trust the precalculated overhead in the superblock.

Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Cc: stable@kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-04-27 13:50:50 +02:00
Theodore Ts'o
425301ef60 ext4: fix overhead calculation to account for the reserved gdt blocks
commit 10b01ee92df52c8d7200afead4d5e5f55a5c58b1 upstream.

The kernel calculation was underestimating the overhead by not taking
into account the reserved gdt blocks.  With this change, the overhead
calculated by the kernel matches the overhead calculation in mke2fs.

Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Cc: stable@kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-04-27 13:50:50 +02:00
wangjianjian (C)
ea9c206111 ext4, doc: fix incorrect h_reserved size
commit 7102ffe4c166ca0f5e35137e9f9de83768c2d27d upstream.

According to document and code, ext4_xattr_header's size is 32 bytes, so
h_reserved size should be 3.

Signed-off-by: Wang Jianjian <wangjianjian3@huawei.com>
Link: https://lore.kernel.org/r/92fcc3a6-7d77-8c09-4126-377fcb4c46a5@huawei.com
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Cc: stable@kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-04-27 13:50:50 +02:00
Tadeusz Struk
259dc49dea ext4: limit length to bitmap_maxbytes - blocksize in punch_hole
commit 2da376228a2427501feb9d15815a45dbdbdd753e upstream.

Syzbot found an issue [1] in ext4_fallocate().
The C reproducer [2] calls fallocate(), passing size 0xffeffeff000ul,
and offset 0x1000000ul, which, when added together exceed the
bitmap_maxbytes for the inode. This triggers a BUG in
ext4_ind_remove_space(). According to the comments in this function
the 'end' parameter needs to be one block after the last block to be
removed. In the case when the BUG is triggered it points to the last
block. Modify the ext4_punch_hole() function and add constraint that
caps the length to satisfy the one before laster block requirement.

LINK: [1] https://syzkaller.appspot.com/bug?id=b80bd9cf348aac724a4f4dff251800106d721331
LINK: [2] https://syzkaller.appspot.com/text?tag=ReproC&x=14ba0238700000

Fixes: a4bb6b64e3 ("ext4: enable "punch hole" functionality")
Reported-by: syzbot+7a806094edd5d07ba029@syzkaller.appspotmail.com
Signed-off-by: Tadeusz Struk <tadeusz.struk@linaro.org>
Link: https://lore.kernel.org/r/20220331200515.153214-1-tadeusz.struk@linaro.org
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Cc: stable@kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-04-27 13:50:50 +02:00
Ye Bin
faadbf7ac4 ext4: fix use-after-free in ext4_search_dir
commit c186f0887fe7061a35cebef024550ec33ef8fbd8 upstream.

We got issue as follows:
EXT4-fs (loop0): mounted filesystem without journal. Opts: ,errors=continue
==================================================================
BUG: KASAN: use-after-free in ext4_search_dir fs/ext4/namei.c:1394 [inline]
BUG: KASAN: use-after-free in search_dirblock fs/ext4/namei.c:1199 [inline]
BUG: KASAN: use-after-free in __ext4_find_entry+0xdca/0x1210 fs/ext4/namei.c:1553
Read of size 1 at addr ffff8881317c3005 by task syz-executor117/2331

CPU: 1 PID: 2331 Comm: syz-executor117 Not tainted 5.10.0+ #1
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.14.0-0-g155821a1990b-prebuilt.qemu.org 04/01/2014
Call Trace:
 __dump_stack lib/dump_stack.c:83 [inline]
 dump_stack+0x144/0x187 lib/dump_stack.c:124
 print_address_description+0x7d/0x630 mm/kasan/report.c:387
 __kasan_report+0x132/0x190 mm/kasan/report.c:547
 kasan_report+0x47/0x60 mm/kasan/report.c:564
 ext4_search_dir fs/ext4/namei.c:1394 [inline]
 search_dirblock fs/ext4/namei.c:1199 [inline]
 __ext4_find_entry+0xdca/0x1210 fs/ext4/namei.c:1553
 ext4_lookup_entry fs/ext4/namei.c:1622 [inline]
 ext4_lookup+0xb8/0x3a0 fs/ext4/namei.c:1690
 __lookup_hash+0xc5/0x190 fs/namei.c:1451
 do_rmdir+0x19e/0x310 fs/namei.c:3760
 do_syscall_64+0x33/0x40 arch/x86/entry/common.c:46
 entry_SYSCALL_64_after_hwframe+0x44/0xa9
RIP: 0033:0x445e59
Code: 4d c7 fb ff c3 66 2e 0f 1f 84 00 00 00 00 00 66 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 0f 83 1b c7 fb ff c3 66 2e 0f 1f 84 00 00 00 00
RSP: 002b:00007fff2277fac8 EFLAGS: 00000246 ORIG_RAX: 0000000000000054
RAX: ffffffffffffffda RBX: 0000000000400280 RCX: 0000000000445e59
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 00000000200000c0
RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000002
R10: 00007fff2277f990 R11: 0000000000000246 R12: 0000000000000000
R13: 431bde82d7b634db R14: 0000000000000000 R15: 0000000000000000

The buggy address belongs to the page:
page:0000000048cd3304 refcount:0 mapcount:0 mapping:0000000000000000 index:0x1 pfn:0x1317c3
flags: 0x200000000000000()
raw: 0200000000000000 ffffea0004526588 ffffea0004528088 0000000000000000
raw: 0000000000000001 0000000000000000 00000000ffffffff 0000000000000000
page dumped because: kasan: bad access detected

Memory state around the buggy address:
 ffff8881317c2f00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
 ffff8881317c2f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
>ffff8881317c3000: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
                   ^
 ffff8881317c3080: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
 ffff8881317c3100: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
==================================================================

ext4_search_dir:
  ...
  de = (struct ext4_dir_entry_2 *)search_buf;
  dlimit = search_buf + buf_size;
  while ((char *) de < dlimit) {
  ...
    if ((char *) de + de->name_len <= dlimit &&
	 ext4_match(dir, fname, de)) {
	    ...
    }
  ...
    de_len = ext4_rec_len_from_disk(de->rec_len, dir->i_sb->s_blocksize);
    if (de_len <= 0)
      return -1;
    offset += de_len;
    de = (struct ext4_dir_entry_2 *) ((char *) de + de_len);
  }

Assume:
de=0xffff8881317c2fff
dlimit=0x0xffff8881317c3000

If read 'de->name_len' which address is 0xffff8881317c3005, obviously is
out of range, then will trigger use-after-free.
To solve this issue, 'dlimit' must reserve 8 bytes, as we will read
'de->name_len' to judge if '(char *) de + de->name_len' out of range.

Signed-off-by: Ye Bin <yebin10@huawei.com>
Reviewed-by: Jan Kara <jack@suse.cz>
Link: https://lore.kernel.org/r/20220324064816.1209985-1-yebin10@huawei.com
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Cc: stable@kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-04-27 13:50:50 +02:00
Ye Bin
0309665eb2 ext4: fix symlink file size not match to file content
commit a2b0b205d125f27cddfb4f7280e39affdaf46686 upstream.

We got issue as follows:
[home]# fsck.ext4  -fn  ram0yb
e2fsck 1.45.6 (20-Mar-2020)
Pass 1: Checking inodes, blocks, and sizes
Pass 2: Checking directory structure
Symlink /p3/d14/d1a/l3d (inode #3494) is invalid.
Clear? no
Entry 'l3d' in /p3/d14/d1a (3383) has an incorrect filetype (was 7, should be 0).
Fix? no

As the symlink file size does not match the file content. If the writeback
of the symlink data block failed, ext4_finish_bio() handles the end of IO.
However this function fails to mark the buffer with BH_write_io_error and
so when unmount does journal checkpoint it cannot detect the writeback
error and will cleanup the journal. Thus we've lost the correct data in the
journal area. To solve this issue, mark the buffer as BH_write_io_error in
ext4_finish_bio().

Cc: stable@kernel.org
Signed-off-by: Ye Bin <yebin10@huawei.com>
Reviewed-by: Jan Kara <jack@suse.cz>
Link: https://lore.kernel.org/r/20220321144438.201685-1-yebin10@huawei.com
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-04-27 13:50:50 +02:00
Rob Herring
ddfe3babc5 arm_pmu: Validate single/group leader events
commit e5c23779f93d45e39a52758ca593bd7e62e9b4be upstream.

In the case where there is only a cycle counter available (i.e.
PMCR_EL0.N is 0) and an event other than CPU cycles is opened, the open
should fail as the event can never possibly be scheduled. However, the
event validation when an event is opened is skipped when the group
leader is opened. Fix this by always validating the group leader events.

Reported-by: Al Grant <al.grant@arm.com>
Cc: Will Deacon <will@kernel.org>
Cc: Mark Rutland <mark.rutland@arm.com>
Signed-off-by: Rob Herring <robh@kernel.org>
Acked-by: Mark Rutland <mark.rutland@arm.com>
Link: https://lore.kernel.org/r/20220408203330.4014015-1-robh@kernel.org
Cc: <stable@vger.kernel.org>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-04-27 13:50:50 +02:00
Sergey Matyukevich
852b02d1f8 ARC: entry: fix syscall_trace_exit argument
commit b1c6ecfdd06907554518ec384ce8e99889d15193 upstream.

Function syscall_trace_exit expects pointer to pt_regs. However
r0 is also used to keep syscall return value. Restore pointer
to pt_regs before calling syscall_trace_exit.

Cc: <stable@vger.kernel.org>
Signed-off-by: Sergey Matyukevich <sergey.matyukevich@synopsys.com>
Signed-off-by: Vineet Gupta <vgupta@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-04-27 13:50:49 +02:00
Sasha Neftin
016ba7cbed e1000e: Fix possible overflow in LTR decoding
commit 04ebaa1cfddae5f240cc7404f009133bb0389a47 upstream.

When we decode the latency and the max_latency, u16 value may not fit
the required size and could lead to the wrong LTR representation.

Scaling is represented as:
scale 0 - 1         (2^(5*0)) = 2^0
scale 1 - 32        (2^(5 *1))= 2^5
scale 2 - 1024      (2^(5 *2)) =2^10
scale 3 - 32768     (2^(5 *3)) =2^15
scale 4 - 1048576   (2^(5 *4)) = 2^20
scale 5 - 33554432  (2^(5 *4)) = 2^25
scale 4 and scale 5 required 20 and 25 bits respectively.
scale 6 reserved.

Replace the u16 type with the u32 type and allow corrected LTR
representation.

Cc: stable@vger.kernel.org
Fixes: 44a13a5d99c7 ("e1000e: Fix the max snoop/no-snoop latency for 10M")
Reported-by: James Hutchinson <jahutchinson99@googlemail.com>
Link: https://bugzilla.kernel.org/show_bug.cgi?id=215689
Suggested-by: Dima Ruinskiy <dima.ruinskiy@intel.com>
Signed-off-by: Sasha Neftin <sasha.neftin@intel.com>
Tested-by: Naama Meir <naamax.meir@linux.intel.com>
Tested-by: James Hutchinson <jahutchinson99@googlemail.com>
Signed-off-by: Tony Nguyen <anthony.l.nguyen@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-04-27 13:50:49 +02:00
Xiaomeng Tong
1217cf141b ASoC: soc-dapm: fix two incorrect uses of list iterator
commit f730a46b931d894816af34a0ff8e4ad51565b39f upstream.

These two bug are here:
	list_for_each_entry_safe_continue(w, n, list,
					power_list);
	list_for_each_entry_safe_continue(w, n, list,
					power_list);

After the list_for_each_entry_safe_continue() exits, the list iterator
will always be a bogus pointer which point to an invalid struct objdect
containing HEAD member. The funciton poniter 'w->event' will be a
invalid value which can lead to a control-flow hijack if the 'w' can be
controlled.

The original intention was to continue the outer list_for_each_entry_safe()
loop with the same entry if w->event is NULL, but misunderstanding the
meaning of list_for_each_entry_safe_continue().

So just add a 'continue;' to fix the bug.

Cc: stable@vger.kernel.org
Fixes: 163cac061c ("ASoC: Factor out DAPM sequence execution")
Signed-off-by: Xiaomeng Tong <xiam0nd.tong@gmail.com>
Link: https://lore.kernel.org/r/20220329012134.9375-1-xiam0nd.tong@gmail.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-04-27 13:50:49 +02:00
Paolo Valerio
aa70705560 openvswitch: fix OOB access in reserve_sfa_size()
commit cefa91b2332d7009bc0be5d951d6cbbf349f90f8 upstream.

Given a sufficiently large number of actions, while copying and
reserving memory for a new action of a new flow, if next_offset is
greater than MAX_ACTIONS_BUFSIZE, the function reserve_sfa_size() does
not return -EMSGSIZE as expected, but it allocates MAX_ACTIONS_BUFSIZE
bytes increasing actions_len by req_size. This can then lead to an OOB
write access, especially when further actions need to be copied.

Fix it by rearranging the flow action size check.

KASAN splat below:

==================================================================
BUG: KASAN: slab-out-of-bounds in reserve_sfa_size+0x1ba/0x380 [openvswitch]
Write of size 65360 at addr ffff888147e4001c by task handler15/836

CPU: 1 PID: 836 Comm: handler15 Not tainted 5.18.0-rc1+ #27
...
Call Trace:
 <TASK>
 dump_stack_lvl+0x45/0x5a
 print_report.cold+0x5e/0x5db
 ? __lock_text_start+0x8/0x8
 ? reserve_sfa_size+0x1ba/0x380 [openvswitch]
 kasan_report+0xb5/0x130
 ? reserve_sfa_size+0x1ba/0x380 [openvswitch]
 kasan_check_range+0xf5/0x1d0
 memcpy+0x39/0x60
 reserve_sfa_size+0x1ba/0x380 [openvswitch]
 __add_action+0x24/0x120 [openvswitch]
 ovs_nla_add_action+0xe/0x20 [openvswitch]
 ovs_ct_copy_action+0x29d/0x1130 [openvswitch]
 ? __kernel_text_address+0xe/0x30
 ? unwind_get_return_address+0x56/0xa0
 ? create_prof_cpu_mask+0x20/0x20
 ? ovs_ct_verify+0xf0/0xf0 [openvswitch]
 ? prep_compound_page+0x198/0x2a0
 ? __kasan_check_byte+0x10/0x40
 ? kasan_unpoison+0x40/0x70
 ? ksize+0x44/0x60
 ? reserve_sfa_size+0x75/0x380 [openvswitch]
 __ovs_nla_copy_actions+0xc26/0x2070 [openvswitch]
 ? __zone_watermark_ok+0x420/0x420
 ? validate_set.constprop.0+0xc90/0xc90 [openvswitch]
 ? __alloc_pages+0x1a9/0x3e0
 ? __alloc_pages_slowpath.constprop.0+0x1da0/0x1da0
 ? unwind_next_frame+0x991/0x1e40
 ? __mod_node_page_state+0x99/0x120
 ? __mod_lruvec_page_state+0x2e3/0x470
 ? __kasan_kmalloc_large+0x90/0xe0
 ovs_nla_copy_actions+0x1b4/0x2c0 [openvswitch]
 ovs_flow_cmd_new+0x3cd/0xb10 [openvswitch]
 ...

Cc: stable@vger.kernel.org
Fixes: f28cd2af22 ("openvswitch: fix flow actions reallocation")
Signed-off-by: Paolo Valerio <pvalerio@redhat.com>
Acked-by: Eelco Chaudron <echaudro@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-04-27 13:50:49 +02:00
Max Filippov
d24e0d9d69 xtensa: fix a7 clobbering in coprocessor context load/store
commit 839769c35477d4acc2369e45000ca7b0b6af39a7 upstream.

Fast coprocessor exception handler saves a3..a6, but coprocessor context
load/store code uses a4..a7 as temporaries, potentially clobbering a7.
'Potentially' because coprocessor state load/store macros may not use
all four temporary registers (and neither FPU nor HiFi macros do).
Use a3..a6 as intended.

Cc: stable@vger.kernel.org
Fixes: c658eac628 ("[XTENSA] Add support for configurable registers and coprocessors")
Signed-off-by: Max Filippov <jcmvbkbc@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-04-27 13:50:49 +02:00
Guo Ren
4c26a96d0c xtensa: patch_text: Fixup last cpu should be master
commit ee69d4be8fd064cd08270b4808d2dfece3614ee0 upstream.

These patch_text implementations are using stop_machine_cpuslocked
infrastructure with atomic cpu_count. The original idea: When the
master CPU patch_text, the others should wait for it. But current
implementation is using the first CPU as master, which couldn't
guarantee the remaining CPUs are waiting. This patch changes the
last CPU as the master to solve the potential risk.

Fixes: 64711f9a47 ("xtensa: implement jump_label support")
Signed-off-by: Guo Ren <guoren@linux.alibaba.com>
Signed-off-by: Guo Ren <guoren@kernel.org>
Reviewed-by: Max Filippov <jcmvbkbc@gmail.com>
Reviewed-by: Masami Hiramatsu <mhiramat@kernel.org>
Cc: <stable@vger.kernel.org>
Message-Id: <20220407073323.743224-4-guoren@kernel.org>
Signed-off-by: Max Filippov <jcmvbkbc@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-04-27 13:50:49 +02:00
Athira Rajeev
8d6937c1e0 powerpc/perf: Fix power9 event alternatives
[ Upstream commit 0dcad700bb2776e3886fe0a645a4bf13b1e747cd ]

When scheduling a group of events, there are constraint checks done to
make sure all events can go in a group. Example, one of the criteria is
that events in a group cannot use the same PMC. But platform specific
PMU supports alternative event for some of the event codes. During
perf_event_open(), if any event group doesn't match constraint check
criteria, further lookup is done to find alternative event.

By current design, the array of alternatives events in PMU code is
expected to be sorted by column 0. This is because in
find_alternative() the return criteria is based on event code
comparison. ie. "event < ev_alt[i][0])". This optimisation is there
since find_alternative() can be called multiple times. In power9 PMU
code, the alternative event array is not sorted properly and hence there
is breakage in finding alternative events.

To work with existing logic, fix the alternative event array to be
sorted by column 0 for power9-pmu.c

Results:

With alternative events, multiplexing can be avoided. That is, for
example, in power9 PM_LD_MISS_L1 (0x3e054) has alternative event,
PM_LD_MISS_L1_ALT (0x400f0). This is an identical event which can be
programmed in a different PMC.

Before:

 # perf stat -e r3e054,r300fc

 Performance counter stats for 'system wide':

           1057860      r3e054              (50.21%)
               379      r300fc              (49.79%)

       0.944329741 seconds time elapsed

Since both the events are using PMC3 in this case, they are
multiplexed here.

After:

 # perf stat -e r3e054,r300fc

 Performance counter stats for 'system wide':

           1006948      r3e054
               182      r300fc

Fixes: 91e0bd1e62 ("powerpc/perf: Add PM_LD_MISS_L1 and PM_BR_2PATH to power9 event list")
Signed-off-by: Athira Rajeev <atrajeev@linux.vnet.ibm.com>
Reviewed-by: Madhavan Srinivasan <maddy@linux.vnet.ibm.com>
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
Link: https://lore.kernel.org/r/20220419114828.89843-1-atrajeev@linux.vnet.ibm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
2022-04-27 13:50:49 +02:00
Miaoqian Lin
0dafb826ed drm/vc4: Use pm_runtime_resume_and_get to fix pm_runtime_get_sync() usage
[ Upstream commit 3d0b93d92a2790337aa9d18cb332d02356a24126 ]

If the device is already in a runtime PM enabled state
pm_runtime_get_sync() will return 1.

Also, we need to call pm_runtime_put_noidle() when pm_runtime_get_sync()
fails, so use pm_runtime_resume_and_get() instead. this function
will handle this.

Fixes: 4078f57571 ("drm/vc4: Add DSI driver")
Signed-off-by: Miaoqian Lin <linmq006@gmail.com>
Signed-off-by: Maxime Ripard <maxime@cerno.tech>
Link: https://patchwork.freedesktop.org/patch/msgid/20220420135008.2757-1-linmq006@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
2022-04-27 13:50:49 +02:00
Alexey Kardashevskiy
013231f75f KVM: PPC: Fix TCE handling for VFIO
[ Upstream commit 26a62b750a4e6364b0393562f66759b1494c3a01 ]

The LoPAPR spec defines a guest visible IOMMU with a variable page size.
Currently QEMU advertises 4K, 64K, 2M, 16MB pages, a Linux VM picks
the biggest (16MB). In the case of a passed though PCI device, there is
a hardware IOMMU which does not support all pages sizes from the above -
P8 cannot do 2MB and P9 cannot do 16MB. So for each emulated
16M IOMMU page we may create several smaller mappings ("TCEs") in
the hardware IOMMU.

The code wrongly uses the emulated TCE index instead of hardware TCE
index in error handling. The problem is easier to see on POWER8 with
multi-level TCE tables (when only the first level is preallocated)
as hash mode uses real mode TCE hypercalls handlers.
The kernel starts using indirect tables when VMs get bigger than 128GB
(depends on the max page order).
The very first real mode hcall is going to fail with H_TOO_HARD as
in the real mode we cannot allocate memory for TCEs (we can in the virtual
mode) but on the way out the code attempts to clear hardware TCEs using
emulated TCE indexes which corrupts random kernel memory because
it_offset==1<<59 is subtracted from those indexes and the resulting index
is out of the TCE table bounds.

This fixes kvmppc_clear_tce() to use the correct TCE indexes.

While at it, this fixes TCE cache invalidation which uses emulated TCE
indexes instead of the hardware ones. This went unnoticed as 64bit DMA
is used these days and VMs map all RAM in one go and only then do DMA
and this is when the TCE cache gets populated.

Potentially this could slow down mapping, however normally 16MB
emulated pages are backed by 64K hardware pages so it is one write to
the "TCE Kill" per 256 updates which is not that bad considering the size
of the cache (1024 TCEs or so).

Fixes: ca1fc489cf ("KVM: PPC: Book3S: Allow backing bigger guest IOMMU pages with smaller physical pages")

Signed-off-by: Alexey Kardashevskiy <aik@ozlabs.ru>
Tested-by: David Gibson <david@gibson.dropbear.id.au>
Reviewed-by: Frederic Barrat <fbarrat@linux.ibm.com>
Reviewed-by: David Gibson <david@gibson.dropbear.id.au>
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
Link: https://lore.kernel.org/r/20220420050840.328223-1-aik@ozlabs.ru
Signed-off-by: Sasha Levin <sashal@kernel.org>
2022-04-27 13:50:49 +02:00
Dave Stevenson
9cf05812cb drm/panel/raspberrypi-touchscreen: Initialise the bridge in prepare
[ Upstream commit 5f18c0782b99e26121efa93d20b76c19e17aa1dd ]

The panel has a prepare call which is before video starts, and an
enable call which is after.
The Toshiba bridge should be configured before video, so move
the relevant power and initialisation calls to prepare.

Fixes: 2f733d6194 ("drm/panel: Add support for the Raspberry Pi 7" Touchscreen.")
Signed-off-by: Dave Stevenson <dave.stevenson@raspberrypi.com>
Signed-off-by: Stefan Wahren <stefan.wahren@i2se.com>
Signed-off-by: Maxime Ripard <maxime@cerno.tech>
Link: https://patchwork.freedesktop.org/patch/msgid/20220415162513.42190-3-stefan.wahren@i2se.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
2022-04-27 13:50:49 +02:00