Commit graph

896,279 commits

Author SHA1 Message Date
Geert Uytterhoeven
28066cfbc9 BACKPORT: ARM: 9035/1: uncompress: Add be32tocpu macro
DTB stores all values as 32-bit big-endian integers.
Add a macro to convert such values to native CPU endianness, to reduce
duplication.

Signed-off-by: Geert Uytterhoeven <geert+renesas@glider.be>
Reviewed-by: Ard Biesheuvel <ardb@kernel.org>
Reviewed-by: Nicolas Pitre <nico@fluxnic.net>
Signed-off-by: Russell King <rmk+kernel@armlinux.org.uk>

(cherry picked from commit 0557ac83fd1a0a7cd6909665bad50006507115a0)
(resolved conflict due to different patch context, caused by missing
 "ARM: 9010/1: uncompress: Print the location of appended DTB")
Bug: 178411248
Change-Id: I0807f36352dbfd5f5808959e358a7469dc9753bb
Signed-off-by: Eric Biggers <ebiggers@google.com>
2022-11-09 18:51:40 +00:00
Sai Prakash Ranjan
cc190ff2f8 UPSTREAM: drm/meson: Fix overflow implicit truncation warnings
[ Upstream commit 98692f52c588225034cbff458622c2c06dfcb544 ]

Fix -Woverflow warnings for drm/meson driver which is a result
of moving arm64 custom MMIO accessor macros to asm-generic function
implementations giving a bonus type-checking now and uncovering these
overflow warnings.

drivers/gpu/drm/meson/meson_viu.c: In function ‘meson_viu_init’:
drivers/gpu/drm/meson/meson_registers.h:1826:48: error: large integer implicitly truncated to unsigned type [-Werror=overflow]
 #define  VIU_OSD_BLEND_REORDER(dest, src)      ((src) << (dest * 4))
                                                ^
drivers/gpu/drm/meson/meson_viu.c:472:18: note: in expansion of macro ‘VIU_OSD_BLEND_REORDER’
   writel_relaxed(VIU_OSD_BLEND_REORDER(0, 1) |
                  ^~~~~~~~~~~~~~~~~~~~~

Reported-by: kernel test robot <lkp@intel.com>
Signed-off-by: Sai Prakash Ranjan <quic_saipraka@quicinc.com>
Reviewed-by: Arnd Bergmann <arnd@arndb.de>
Cc: Arnd Bergmann <arnd@arndb.de>
Cc: Neil Armstrong <narmstrong@baylibre.com>
Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Fixes: 147ae1cbaa ("drm: meson: viu: use proper macros instead of magic constants")
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: Id3502967ec9df74ea9420a34549bc0ac3c49dfa8
Signed-off-by: Lee Jones <joneslee@google.com>
2022-11-09 13:14:07 +00:00
Sai Prakash Ranjan
0d0c1b2686 UPSTREAM: irqchip/tegra: Fix overflow implicit truncation warnings
[ Upstream commit 443685992bda9bb4f8b17fc02c9f6c60e62b1461 ]

Fix -Woverflow warnings for tegra irqchip driver which is a result
of moving arm64 custom MMIO accessor macros to asm-generic function
implementations giving a bonus type-checking now and uncovering these
overflow warnings.

drivers/irqchip/irq-tegra.c: In function ‘tegra_ictlr_suspend’:
drivers/irqchip/irq-tegra.c:151:18: warning: large integer implicitly truncated to unsigned type [-Woverflow]
   writel_relaxed(~0ul, ictlr + ICTLR_COP_IER_CLR);
                  ^

Suggested-by: Marc Zyngier <maz@kernel.org>
Signed-off-by: Sai Prakash Ranjan <quic_saipraka@quicinc.com>
Reviewed-by: Arnd Bergmann <arnd@arndb.de>
Cc: Marc Zyngier <maz@kernel.org>
Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Fixes: de3ce08049 ("irqchip: tegra: Add DT-based support for legacy interrupt controller")
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: Iaee226d0220c9774635cd51953d577ab7e2ebe77
2022-11-09 13:14:01 +00:00
Hyunwoo Kim
026441f593 UPSTREAM: video: fbdev: pxa3xx-gcu: Fix integer overflow in pxa3xx_gcu_write
[ Upstream commit a09d2d00af53b43c6f11e6ab3cb58443c2cac8a7 ]

In pxa3xx_gcu_write, a count parameter of type size_t is passed to words of
type int.  Then, copy_from_user() may cause a heap overflow because it is used
as the third argument of copy_from_user().

Bug: 245928838
Signed-off-by: Hyunwoo Kim <imv4bel@gmail.com>
Signed-off-by: Helge Deller <deller@gmx.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I9e21917a52e2cb78cc640a77a6eba21838aa8655
2022-11-08 20:24:48 +00:00
Aneesh Kumar K.V
482efd771f UPSTREAM: mm/mremap: hold the rmap lock in write mode when moving page table entries.
commit 97113eb39fa7972722ff490b947d8af023e1f6a2 upstream.

To avoid a race between rmap walk and mremap, mremap does
take_rmap_locks().  The lock was taken to ensure that rmap walk don't miss
a page table entry due to PTE moves via move_pagetables().  The kernel
does further optimization of this lock such that if we are going to find
the newly added vma after the old vma, the rmap lock is not taken.  This
is because rmap walk would find the vmas in the same order and if we don't
find the page table attached to older vma we would find it with the new
vma which we would iterate later.

As explained in commit eb66ae0308 ("mremap: properly flush TLB before
releasing the page") mremap is special in that it doesn't take ownership
of the page.  The optimized version for PUD/PMD aligned mremap also
doesn't hold the ptl lock.  This can result in stale TLB entries as show
below.

This patch updates the rmap locking requirement in mremap to handle the race condition
explained below with optimized mremap::

Optmized PMD move

    CPU 1                           CPU 2                                   CPU 3

    mremap(old_addr, new_addr)      page_shrinker/try_to_unmap_one

    mmap_write_lock_killable()

                                    addr = old_addr
                                    lock(pte_ptl)
    lock(pmd_ptl)
    pmd = *old_pmd
    pmd_clear(old_pmd)
    flush_tlb_range(old_addr)

    *new_pmd = pmd
                                                                            *new_addr = 10; and fills
                                                                            TLB with new addr
                                                                            and old pfn

    unlock(pmd_ptl)
                                    ptep_clear_flush()
                                    old pfn is free.
                                                                            Stale TLB entry

Optimized PUD move also suffers from a similar race.  Both the above race
condition can be fixed if we force mremap path to take rmap lock.

Bug: 248354871
Link: https://lkml.kernel.org/r/20210616045239.370802-7-aneesh.kumar@linux.ibm.com
Fixes: 2c91bd4a4e ("mm: speed up mremap by 20x on large regions")
Fixes: c49dd3401802 ("mm: speedup mremap on 1GB or larger regions")
Link: https://lore.kernel.org/linux-mm/CAHk-=wgXVR04eBNtxQfevontWnP6FDm+oj5vauQXP3S-huwbPw@mail.gmail.com
Signed-off-by: Aneesh Kumar K.V <aneesh.kumar@linux.ibm.com>
Acked-by: Hugh Dickins <hughd@google.com>
Acked-by: Kirill A. Shutemov <kirill.shutemov@linux.intel.com>
Cc: Christophe Leroy <christophe.leroy@csgroup.eu>
Cc: Joel Fernandes <joel@joelfernandes.org>
Cc: Kalesh Singh <kaleshsingh@google.com>
Cc: Kirill A. Shutemov <kirill@shutemov.name>
Cc: Michael Ellerman <mpe@ellerman.id.au>
Cc: Nicholas Piggin <npiggin@gmail.com>
Cc: Stephen Rothwell <sfr@canb.auug.org.au>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
[patch rewritten for backport since the code was refactored since]
Signed-off-by: Jann Horn <jannh@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I046ea082f78b4c35c364dca305953a3f9ed28f1d
2022-11-07 11:17:25 +00:00
Carlos Llamas
c262d21607 FROMLIST: binder: fix UAF of alloc->vma in race with munmap()
In commit 720c241924 ("ANDROID: binder: change down_write to
down_read") binder assumed the mmap read lock is sufficient to protect
alloc->vma inside binder_update_page_range(). This used to be accurate
until commit dd2283f260 ("mm: mmap: zap pages with read mmap_sem in
munmap"), which now downgrades the mmap_lock after detaching the vma
from the rbtree in munmap(). Then it proceeds to teardown and free the
vma with only the read lock held.

This means that accesses to alloc->vma in binder_update_page_range() now
will race with vm_area_free() in munmap() and can cause a UAF as shown
in the following KASAN trace:

  ==================================================================
  BUG: KASAN: use-after-free in vm_insert_page+0x7c/0x1f0
  Read of size 8 at addr ffff16204ad00600 by task server/558

  CPU: 3 PID: 558 Comm: server Not tainted 5.10.150-00001-gdc8dcf942daa #1
  Hardware name: linux,dummy-virt (DT)
  Call trace:
   dump_backtrace+0x0/0x2a0
   show_stack+0x18/0x2c
   dump_stack+0xf8/0x164
   print_address_description.constprop.0+0x9c/0x538
   kasan_report+0x120/0x200
   __asan_load8+0xa0/0xc4
   vm_insert_page+0x7c/0x1f0
   binder_update_page_range+0x278/0x50c
   binder_alloc_new_buf+0x3f0/0xba0
   binder_transaction+0x64c/0x3040
   binder_thread_write+0x924/0x2020
   binder_ioctl+0x1610/0x2e5c
   __arm64_sys_ioctl+0xd4/0x120
   el0_svc_common.constprop.0+0xac/0x270
   do_el0_svc+0x38/0xa0
   el0_svc+0x1c/0x2c
   el0_sync_handler+0xe8/0x114
   el0_sync+0x180/0x1c0

  Allocated by task 559:
   kasan_save_stack+0x38/0x6c
   __kasan_kmalloc.constprop.0+0xe4/0xf0
   kasan_slab_alloc+0x18/0x2c
   kmem_cache_alloc+0x1b0/0x2d0
   vm_area_alloc+0x28/0x94
   mmap_region+0x378/0x920
   do_mmap+0x3f0/0x600
   vm_mmap_pgoff+0x150/0x17c
   ksys_mmap_pgoff+0x284/0x2dc
   __arm64_sys_mmap+0x84/0xa4
   el0_svc_common.constprop.0+0xac/0x270
   do_el0_svc+0x38/0xa0
   el0_svc+0x1c/0x2c
   el0_sync_handler+0xe8/0x114
   el0_sync+0x180/0x1c0

  Freed by task 560:
   kasan_save_stack+0x38/0x6c
   kasan_set_track+0x28/0x40
   kasan_set_free_info+0x24/0x4c
   __kasan_slab_free+0x100/0x164
   kasan_slab_free+0x14/0x20
   kmem_cache_free+0xc4/0x34c
   vm_area_free+0x1c/0x2c
   remove_vma+0x7c/0x94
   __do_munmap+0x358/0x710
   __vm_munmap+0xbc/0x130
   __arm64_sys_munmap+0x4c/0x64
   el0_svc_common.constprop.0+0xac/0x270
   do_el0_svc+0x38/0xa0
   el0_svc+0x1c/0x2c
   el0_sync_handler+0xe8/0x114
   el0_sync+0x180/0x1c0

  [...]
  ==================================================================

To prevent the race above, revert back to taking the mmap write lock
inside binder_update_page_range(). One might expect an increase of mmap
lock contention. However, binder already serializes these calls via top
level alloc->mutex. Also, there was no performance impact shown when
running the binder benchmark tests.

Note this patch is specific to stable branches 5.4 and 5.10. Since in
newer kernel releases binder no longer caches a pointer to the vma.
Instead, it has been refactored to use vma_lookup() which avoids the
issue described here. This switch was introduced in commit a43cfc87caaf
("android: binder: stop saving a pointer to the VMA").

Bug: 254837884
Link: https://lore.kernel.org/all/20221104175534.307317-1-cmllamas@google.com/
Fixes: dd2283f260 ("mm: mmap: zap pages with read mmap_sem in munmap")
Reported-by: Jann Horn <jannh@google.com>
Cc: <stable@vger.kernel.org> # 5.4.x
Cc: Minchan Kim <minchan@kernel.org>
Cc: Yang Shi <yang.shi@linux.alibaba.com>
Cc: Liam Howlett <liam.howlett@oracle.com>
Signed-off-by: Carlos Llamas <cmllamas@google.com>
Change-Id: I87e95bf5c15069f7cb1a0b30186a5f0ed9b1b096
2022-11-04 22:28:57 +00:00
Jann Horn
6d1487a4aa UPSTREAM: mm: Fix TLB flush for not-first PFNMAP mappings in unmap_region()
This is a stable-specific patch.
I botched the stable-specific rewrite of
commit b67fbebd4cf98 ("mmu_gather: Force tlb-flush VM_PFNMAP vmas"):
As Hugh pointed out, unmap_region() actually operates on a list of VMAs,
and the variable "vma" merely points to the first VMA in that list.
So if we want to check whether any of the VMAs we're operating on is
PFNMAP or MIXEDMAP, we have to iterate through the list and check each VMA.

Bug: 245812080
Signed-off-by: Jann Horn <jannh@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit 3998dc50ebdc127ae79b10992856fb76debc2005)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: Ib8ddb51815e53f42daec5d98a196866a078a7550
2022-11-03 08:06:02 +00:00
Jann Horn
4a5337dfb3 UPSTREAM: mm: Force TLB flush for PFNMAP mappings before unlink_file_vma()
commit b67fbebd4cf980aecbcc750e1462128bffe8ae15 upstream.

Some drivers rely on having all VMAs through which a PFN might be
accessible listed in the rmap for correctness.
However, on X86, it was possible for a VMA with stale TLB entries
to not be listed in the rmap.

This was fixed in mainline with
commit b67fbebd4cf9 ("mmu_gather: Force tlb-flush VM_PFNMAP vmas"),
but that commit relies on preceding refactoring in
commit 18ba064e42df3 ("mmu_gather: Let there be one tlb_{start,end}_vma()
implementation") and commit 1e9fdf21a4339 ("mmu_gather: Remove per arch
tlb_{start,end}_vma()").

This patch provides equivalent protection without needing that
refactoring, by forcing a TLB flush between removing PTEs in
unmap_vmas() and the call to unlink_file_vma() in free_pgtables().

Bug: 245812080
[This is a stable-specific rewrite of the upstream commit!]
Signed-off-by: Jann Horn <jannh@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: Ic29df5cfb76676aa87a14619dd19aba301580507
Signed-off-by: Lee Jones <joneslee@google.com>
2022-11-03 01:37:25 +00:00
Herbert Xu
e8453c3dec UPSTREAM: af_key: Do not call xfrm_probe_algs in parallel
[ Upstream commit ba953a9d89a00c078b85f4b190bc1dde66fe16b5 ]

When namespace support was added to xfrm/afkey, it caused the
previously single-threaded call to xfrm_probe_algs to become
multi-threaded.  This is buggy and needs to be fixed with a mutex.

Bug: 245674737
Reported-by: Abhishek Shah <abhishek.shah@columbia.edu>
Fixes: 283bc9f35b ("xfrm: Namespacify xfrm state/policy locks")
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Change-Id: I71fb89a999447862a6c4b1ff754378bb0452ad3a
Signed-off-by: Lee Jones <joneslee@google.com>
2022-11-02 15:04:14 +00:00
Johannes Berg
40a8e0ed5c UPSTREAM: wifi: cfg80211: fix u8 overflow in cfg80211_update_notlisted_nontrans()
commit aebe9f4639b13a1f4e9a6b42cdd2e38c617b442d upstream.

In the copy code of the elements, we do the following calculation
to reach the end of the MBSSID element:

	/* copy the IEs after MBSSID */
	cpy_len = mbssid[1] + 2;

This looks fine, however, cpy_len is a u8, the same as mbssid[1],
so the addition of two can overflow. In this case the subsequent
memcpy() will overflow the allocated buffer, since it copies 256
bytes too much due to the way the allocation and memcpy() sizes
are calculated.

Fix this by using size_t for the cpy_len variable.

This fixes CVE-2022-41674.

Bug: 253641805
Reported-by: Soenke Huster <shuster@seemoo.tu-darmstadt.de>
Tested-by: Soenke Huster <shuster@seemoo.tu-darmstadt.de>
Fixes: 0b8fb8235b ("cfg80211: Parsing of Multiple BSSID information in scanning")
Reviewed-by: Kees Cook <keescook@chromium.org>
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I25a9aebdc6507fd3d7c2aaa7348276afd5da7499
2022-10-25 10:27:37 +00:00
Johannes Berg
f7fbd478a0 UPSTREAM: wifi: cfg80211/mac80211: reject bad MBSSID elements
commit 8f033d2becc24aa6bfd2a5c104407963560caabc upstream.

Per spec, the maximum value for the MaxBSSID ('n') indicator is 8,
and the minimum is 1 since a multiple BSSID set with just one BSSID
doesn't make sense (the # of BSSIDs is limited by 2^n).

Limit this in the parsing in both cfg80211 and mac80211, rejecting
any elements with an invalid value.

This fixes potentially bad shifts in the processing of these inside
the cfg80211_gen_new_bssid() function later.

I found this during the investigation of CVE-2022-41674 fixed by the
previous patch.

Bug: 253641805
Fixes: 0b8fb8235b ("cfg80211: Parsing of Multiple BSSID information in scanning")
Fixes: 78ac51f815 ("mac80211: support multi-bssid")
Reviewed-by: Kees Cook <keescook@chromium.org>
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I26d9765f49e2a0759f70c93b0533cc48bbfddda2
2022-10-25 10:26:21 +00:00
Johannes Berg
569d099d40 UPSTREAM: wifi: cfg80211: ensure length byte is present before access
commit 567e14e39e8f8c6997a1378bc3be615afca86063 upstream.

When iterating the elements here, ensure the length byte is
present before checking it to see if the entire element will
fit into the buffer.

Longer term, we should rewrite this code using the type-safe
element iteration macros that check all of this.

Bug: 254180332
Fixes: 0b8fb8235b ("cfg80211: Parsing of Multiple BSSID information in scanning")
Reported-by: Soenke Huster <shuster@seemoo.tu-darmstadt.de>
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I2ff6215eabd24d0fbb57a9467cdd548523ffbd9b
2022-10-25 10:26:21 +00:00
Johannes Berg
916a29b486 UPSTREAM: wifi: cfg80211: fix BSS refcounting bugs
commit 0b7808818cb9df6680f98996b8e9a439fa7bcc2f upstream.

There are multiple refcounting bugs related to multi-BSSID:
 - In bss_ref_get(), if the BSS has a hidden_beacon_bss, then
   the bss pointer is overwritten before checking for the
   transmitted BSS, which is clearly wrong. Fix this by using
   the bss_from_pub() macro.

 - In cfg80211_bss_update() we copy the transmitted_bss pointer
   from tmp into new, but then if we release new, we'll unref
   it erroneously. We already set the pointer and ref it, but
   need to NULL it since it was copied from the tmp data.

 - In cfg80211_inform_single_bss_data(), if adding to the non-
   transmitted list fails, we unlink the BSS and yet still we
   return it, but this results in returning an entry without
   a reference. We shouldn't return it anyway if it was broken
   enough to not get added there.

This fixes CVE-2022-42720.

Bug: 253642015
Reported-by: Sönke Huster <shuster@seemoo.tu-darmstadt.de>
Tested-by: Sönke Huster <shuster@seemoo.tu-darmstadt.de>
Fixes: a3584f56de ("cfg80211: Properly track transmitting and non-transmitting BSS")
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I0389708d1ada86ab2fa0a7ada203b71f789c506b
2022-10-25 10:26:21 +00:00
Johannes Berg
a30ebebb22 UPSTREAM: wifi: cfg80211: avoid nontransmitted BSS list corruption
commit bcca852027e5878aec911a347407ecc88d6fff7f upstream.

If a non-transmitted BSS shares enough information (both
SSID and BSSID!) with another non-transmitted BSS of a
different AP, then we can find and update it, and then
try to add it to the non-transmitted BSS list. We do a
search for it on the transmitted BSS, but if it's not
there (but belongs to another transmitted BSS), the list
gets corrupted.

Since this is an erroneous situation, simply fail the
list insertion in this case and free the non-transmitted
BSS.

This fixes CVE-2022-42721.

Bug: 253642088
Reported-by: Sönke Huster <shuster@seemoo.tu-darmstadt.de>
Tested-by: Sönke Huster <shuster@seemoo.tu-darmstadt.de>
Fixes: 0b8fb8235b ("cfg80211: Parsing of Multiple BSSID information in scanning")
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: If733c3364cdca1ae7f33b2c07d8f872ad2ec5939
2022-10-25 10:22:13 +00:00
Johannes Berg
99f0812889 UPSTREAM: wifi: mac80211_hwsim: avoid mac80211 warning on bad rate
commit 1833b6f46d7e2830251a063935ab464256defe22 upstream.

If the tool on the other side (e.g. wmediumd) gets confused
about the rate, we hit a warning in mac80211. Silence that
by effectively duplicating the check here and dropping the
frame silently (in mac80211 it's dropped with the warning).

Bug: 254180332
Reported-by: Sönke Huster <shuster@seemoo.tu-darmstadt.de>
Tested-by: Sönke Huster <shuster@seemoo.tu-darmstadt.de>
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I427e5f4d1824d7678d59cd6ed6e490d62e695ecf
2022-10-25 10:22:13 +00:00
Johannes Berg
df86d024f6 UPSTREAM: wifi: cfg80211: update hidden BSSes to avoid WARN_ON
commit c90b93b5b782891ebfda49d4e5da36632fefd5d1 upstream.

When updating beacon elements in a non-transmitted BSS,
also update the hidden sub-entries to the same beacon
elements, so that a future update through other paths
won't trigger a WARN_ON().

The warning is triggered because the beacon elements in
the hidden BSSes that are children of the BSS should
always be the same as in the parent.

Bug: 254180332
Reported-by: Sönke Huster <shuster@seemoo.tu-darmstadt.de>
Tested-by: Sönke Huster <shuster@seemoo.tu-darmstadt.de>
Fixes: 0b8fb8235b ("cfg80211: Parsing of Multiple BSSID information in scanning")
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: Id6db4b0a1a7b7fa1ae300b69aa6176b5a429dff0
2022-10-25 10:10:56 +00:00
Johannes Berg
fa35741b59 UPSTREAM: mac80211: mlme: find auth challenge directly
Commit 49a765d6785e99157ff5091cc37485732496864e upstream.

There's no need to parse all elements etc. just to find the
authentication challenge - use cfg80211_find_elem() instead.
This also allows us to remove WLAN_EID_CHALLENGE handling
from the element parsing entirely.

Bug: 254180332
Link: https://lore.kernel.org/r/20210920154009.45f9b3a15722.Ice3159ffad03a007d6154cbf1fb3a8c48489e86f@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I0be0e5b6c94cd71fc920a1bea44f0e4ac00b79bf
2022-10-25 10:06:47 +00:00
Johannes Berg
7633d41a83 UPSTREAM: wifi: mac80211: don't parse mbssid in assoc response
This is simply not valid and simplifies the next commit.
I'll make a separate patch for this in the current main
tree as well.

Bug: 254180332
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
[Lee: Commit not upstream - plucked straight from Stable)
(cherry picked from commit 9478c5f9c0)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I83b35213bb47506e4c687e2c8be0c53dc497fd98
2022-10-25 10:06:47 +00:00
Johannes Berg
9f3b5ab822 UPSTREAM: wifi: mac80211: fix MBSSID parsing use-after-free
Commit ff05d4b45dd89b922578dac497dcabf57cf771c6 upstream.
This is a different version of the commit, changed to store
the non-transmitted profile in the elems, and freeing it in
the few places where it's relevant, since that is only the
case when the last argument for parsing (the non-tx BSSID)
is non-NULL.

When we parse a multi-BSSID element, we might point some
element pointers into the allocated nontransmitted_profile.
However, we free this before returning, causing UAF when the
relevant pointers in the parsed elements are accessed.

Fix this by not allocating the scratch buffer separately but
as part of the returned structure instead, that way, there
are no lifetime issues with it.

The scratch buffer introduction as part of the returned data
here is taken from MLO feature work done by Ilan.

This fixes CVE-2022-42719.

Bug: 253642087
Fixes: 5023b14cf4 ("mac80211: support profile split between elements")
Co-developed-by: Ilan Peer <ilan.peer@intel.com>
Signed-off-by: Ilan Peer <ilan.peer@intel.com>
Reviewed-by: Kees Cook <keescook@chromium.org>
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I4c6f396d82a1a5754b1d6948c367009d889d40f9
2022-10-25 08:23:25 +00:00
Nathan Chancellor
09cd270b42 ANDROID: Drop explicit 'CONFIG_INIT_STACK_ALL_ZERO=y' from gki_defconfig
After a backport of commit dcb7c0b9461c ("hardening: Clarify Kconfig
text for auto-var-init"), this becomes redundant, as
CONFIG_INIT_STACK_ALL_ZERO is enabled by default when the compiler
supports it, which results in savedefconfig dropping it.

Change-Id: Ia199fb999f98b936323cb60ecbbdc1ae365932c5
Signed-off-by: Nathan Chancellor <nathan@kernel.org>
2022-10-24 19:35:42 +00:00
Kees Cook
0d4d3b41a5 UPSTREAM: hardening: Remove Clang's enable flag for -ftrivial-auto-var-init=zero
Now that Clang's -enable-trivial-auto-var-init-zero-knowing-it-will-be-removed-from-clang
option is no longer required, remove it from the command line. Clang 16
and later will warn when it is used, which will cause Kconfig to think
it can't use -ftrivial-auto-var-init=zero at all. Check for whether it
is required and only use it when so.

Cc: Nathan Chancellor <nathan@kernel.org>
Cc: Masahiro Yamada <masahiroy@kernel.org>
Cc: Nick Desaulniers <ndesaulniers@google.com>
Cc: linux-kbuild@vger.kernel.org
Cc: llvm@lists.linux.dev
Cc: stable@vger.kernel.org
Fixes: f02003c860d9 ("hardening: Avoid harmless Clang option under CONFIG_INIT_STACK_ALL_ZERO")
Signed-off-by: Kees Cook <keescook@chromium.org>
(cherry picked from commit 607e57c6c62c00965ae276902c166834ce73014a)
Change-Id: I30ecd0e5226852b7d5ee12c44c346ac79051a671
Signed-off-by: Nathan Chancellor <nathan@kernel.org>
2022-10-24 19:35:42 +00:00
Kees Cook
9267f98065 UPSTREAM: hardening: Avoid harmless Clang option under CONFIG_INIT_STACK_ALL_ZERO
Currently under Clang, CC_HAS_AUTO_VAR_INIT_ZERO requires an extra
-enable flag compared to CC_HAS_AUTO_VAR_INIT_PATTERN. GCC 12[1] will
not, and will happily ignore the Clang-specific flag. However, its
presence on the command-line is both cumbersome and confusing. Due to
GCC's tolerant behavior, though, we can continue to use a single Kconfig
cc-option test for the feature on both compilers, but then drop the
Clang-specific option in the Makefile.

In other words, this patch does not change anything other than making the
compiler command line shorter once GCC supports -ftrivial-auto-var-init=zero.

[1] https://gcc.gnu.org/git/?p=gcc.git;a=commitdiff;h=a25e0b5e6ac8a77a71c229e0a7b744603365b0e9

Cc: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Cc: Masahiro Yamada <masahiroy@kernel.org>
Cc: llvm@lists.linux.dev
Fixes: dcb7c0b9461c ("hardening: Clarify Kconfig text for auto-var-init")
Suggested-by: Will Deacon <will@kernel.org>
Link: https://lore.kernel.org/lkml/20210914102837.6172-1-will@kernel.org/
Reviewed-by: Nick Desaulniers <ndesaulniers@google.com>
Reviewed-by: Nathan Chancellor <nathan@kernel.org>
Acked-by: Will Deacon <will@kernel.org>
Signed-off-by: Kees Cook <keescook@chromium.org>
(cherry picked from commit f02003c860d921171be4a27e2893766eb3bc6871)
Change-Id: I572f9d1763dbc7b53f2ad0dc87ba074313f556eb
Signed-off-by: Nathan Chancellor <nathan@kernel.org>
2022-10-24 19:35:42 +00:00
Kees Cook
f086581010 UPSTREAM: hardening: Clarify Kconfig text for auto-var-init
Clarify the details around the automatic variable initialization modes
available. Specifically this details the values used for pattern init
and expands on the rationale for zero init safety. Additionally makes
zero init the default when available.

Cc: glider@google.com
Cc: Nathan Chancellor <nathan@kernel.org>
Cc: Nick Desaulniers <ndesaulniers@google.com>
Cc: linux-security-module@vger.kernel.org
Cc: clang-built-linux@googlegroups.com
Signed-off-by: Kees Cook <keescook@chromium.org>
Acked-by: Gustavo A. R. Silva <gustavoars@kernel.org>
(cherry picked from commit dcb7c0b9461c2a30f6616262736daac6f01ecb09)
Change-Id: Id2a3b2b2953677e29e6deb931350b04091474b08
Signed-off-by: Nathan Chancellor <nathan@kernel.org>
2022-10-24 19:35:42 +00:00
Nobutaka Matsuo
07228609d8 ANDROID: GKI: Update FCNT KMI symbol list
No new symbols added that are not already in the .xml file.

Bug: 255213935
Change-Id: I826c588a136b3ec06d9f29f1145913705963b0fb
Signed-off-by: Nobutaka Matsuo <matsuo.nobu@fcnt.com>
2022-10-24 15:54:15 +00:00
Todd Kjos
b8dedbc2ab ANDROID: Fix kenelci build-break for !CONFIG_PERF_EVENTS
Kernelci builds were broken if !CONFIG_PERF_EVENTS since 467eb53acd ("ANDROID: cpu/hotplug:
avoid breaking Android ABI by fusing cpuhp steps") causes
perf_event_init_cpu(cpu) to be reduced to "NULL(cpu)":

kernel/cpu.c:1868:21: error: called object type 'void *' is not a function or function pointer

Fixes: 467eb53acd ("ANDROID: cpu/hotplug: avoid breaking Android ABI by fusing cpuhp steps")
Signed-off-by: Todd Kjos <tkjos@google.com>
Change-Id: Ifc7351f74470c87018770395af4b4f6096f0d73f
2022-10-13 19:47:26 +00:00
Lee Jones
c1957fce68 BACKPORT: HID: steam: Prevent NULL pointer dereference in steam_{recv,send}_report
commit cd11d1a6114bd4bc6450ae59f6e110ec47362126 upstream.

It is possible for a malicious device to forgo submitting a Feature
Report.  The HID Steam driver presently makes no prevision for this
and de-references the 'struct hid_report' pointer obtained from the
HID devices without first checking its validity.  Let's change that.

Bug: 223455965
Cc: Jiri Kosina <jikos@kernel.org>
Cc: Benjamin Tissoires <benjamin.tissoires@redhat.com>
Cc: linux-input@vger.kernel.org
Fixes: c164d6abf3 ("HID: add driver for Valve Steam Controller")
Signed-off-by: Lee Jones <lee.jones@linaro.org>
Signed-off-by: Jiri Kosina <jkosina@suse.cz>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: Ica12507b87309a7c46b4cab6fcfe4499cd96f45d
2022-10-11 11:26:44 +01:00
Srinivasarao Pathipati
7e0fbb9e25 ANDROID: ABI: Update allowed list for QCOM
Update the android/abi_gki_aarch64_qcom with API refcount_warn_saturate.

Bug: 244699106
Change-Id: Iee45f9e7ab3cc24b678fac28b5981c0e44745769
Signed-off-by: Srinivasarao Pathipati <quic_spathi@quicinc.com>
2022-10-04 15:52:56 +00:00
Johannes Berg
da8a8d7722 UPSTREAM: wifi: mac80211_hwsim: use 32-bit skb cookie
commit cc5250cdb43d444061412df7fae72d2b4acbdf97 upstream.

We won't really have enough skbs to need a 64-bit cookie,
and on 32-bit platforms storing the 64-bit cookie into the
void *rate_driver_data doesn't work anyway. Switch back to
using just a 32-bit cookie and uintptr_t for the type to
avoid compiler warnings about all this.

Fixes: 4ee186fa7e40 ("wifi: mac80211_hwsim: fix race condition in pending packet")
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Cc: Jeongik Cha <jeongik@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit 6dece5ad6e1e7d8c2bacfae606dc6f18a18c51e0)
Signed-off-by: Carlos Llamas <cmllamas@google.com>
Bug: 236994625
Change-Id: I81b075297ec2248f706aebc914cd5e2783665bbc
2022-09-30 15:15:44 -04:00
Johannes Berg
85f8095194 UPSTREAM: wifi: mac80211_hwsim: add back erroneously removed cast
commit 58b6259d820d63c2adf1c7541b54cce5a2ae6073 upstream.

The robots report that we're now casting to a differently
sized integer, which is correct, and the previous patch
had erroneously removed it.

Reported-by: kernel test robot <lkp@intel.com>
Fixes: 4ee186fa7e40 ("wifi: mac80211_hwsim: fix race condition in pending packet")
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Cc: Jeongik Cha <jeongik@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit d400222f49599423862010f0c7f6fee142be72d7)
Signed-off-by: Carlos Llamas <cmllamas@google.com>
Bug: 236994625
Change-Id: I4b5cfa77c47d4d03b46600f0b543e27340c228c0
2022-09-30 15:01:26 -04:00
Jeongik Cha
8b32ee8a9e UPSTREAM: wifi: mac80211_hwsim: fix race condition in pending packet
commit 4ee186fa7e40ae06ebbfbad77e249e3746e14114 upstream.

A pending packet uses a cookie as an unique key, but it can be duplicated
because it didn't use atomic operators.

And also, a pending packet can be null in hwsim_tx_info_frame_received_nl
due to race condition with mac80211_hwsim_stop.

For this,
 * Use an atomic type and operator for a cookie
 * Add a lock around the loop for pending packets

Signed-off-by: Jeongik Cha <jeongik@google.com>
Link: https://lore.kernel.org/r/20220704084354.3556326-1-jeongik@google.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit eb8fc4277b628ac81db806c130a500dd48a9e524)
Signed-off-by: Carlos Llamas <cmllamas@google.com>
Bug: 236994625
Change-Id: Ic6613c8869a51b5de303e40406f023af689b9d64
2022-09-30 14:47:17 -04:00
Greg Kroah-Hartman
7e6cbbe7e5 Merge tag 'android11-5.4.210_r00' into android11-5.4
This is the merge of the upstream LTS release of 5.4.210 into the
android11-5.4 branch.

It contains the following commits:

ab6cb81d83 Merge 5.4.210 into android11-5.4-lts
de0cd3ea70 Linux 5.4.210
b58882c69f x86/speculation: Add LFENCE to RSB fill sequence
f2f41ef035 x86/speculation: Add RSB VM Exit protections
3a0ef79c6a macintosh/adb: fix oob read in do_adb_query() function
54e1abbe85 media: v4l2-mem2mem: Apply DST_QUEUE_OFF_BASE on MMAP buffers across ioctls
17c2356e46 selftests: KVM: Handle compiler optimizations in ucall
170465715a KVM: Don't null dereference ops->destroy
6098562ed9 selftests/bpf: Fix "dubious pointer arithmetic" test
6a9b3f0f3b selftests/bpf: Fix test_align verifier log patterns
9d6f67365d bpf: Test_verifier, #70 error message updates for 32-bit right shift
751f05bc6f selftests/bpf: Extend verifier and bpf_sock tests for dst_port loads
7c1134c7da bpf: Verifer, adjust_scalar_min_max_vals to always call update_reg_bounds()
a8ba72bbed ACPI: APEI: Better fix to avoid spamming the console with old error logs
fa829bd4af ACPI: video: Shortening quirk list by identifying Clevo by board_name only
8ed6e5c5e2 ACPI: video: Force backlight native for some TongFang devices
828f4c3168 thermal: Fix NULL pointer dereferences in of_thermal_ functions
cc62c7de3d ANDROID: GKI: db845c: Update symbols list and ABI
60bba945eb Merge 5.4.209 into android11-5.4-lts
8d8935e76f Linux 5.4.209
0b0088e475 scsi: core: Fix race between handling STS_RESOURCE and completion
85fe8623f0 mt7601u: add USB device ID for some versions of XiaoDu WiFi Dongle.
d5a596c148 ARM: crypto: comment out gcc warning that breaks clang builds
8d6dab81ee sctp: leave the err path free in sctp_stream_init to sctp_stream_free
a49282eca8 sfc: disable softirqs for ptp TX
7799f742f2 perf symbol: Correct address for bss symbols
388b3f14ff virtio-net: fix the race between refill work and close
52be29e8b6 netfilter: nf_queue: do not allow packet truncation below transport header offset
8e0ed463db sctp: fix sleep in atomic context bug in timer handlers
bc135e464d i40e: Fix interface init with MSI interrupts (no MSI-X)
46462e26e6 tcp: Fix a data-race around sysctl_tcp_comp_sack_nr.
d42f68a9ce tcp: Fix a data-race around sysctl_tcp_comp_sack_delay_ns.
c2b57a4d3f Documentation: fix sctp_wmem in ip-sysctl.rst
2d30375343 tcp: Fix a data-race around sysctl_tcp_invalid_ratelimit.
5d235c2fc2 tcp: Fix a data-race around sysctl_tcp_autocorking.
e02c7ee5a4 tcp: Fix a data-race around sysctl_tcp_min_rtt_wlen.
558a294960 tcp: Fix a data-race around sysctl_tcp_min_tso_segs.
fb200869ea net: sungem_phy: Add of_node_put() for reference returned by of_get_parent()
e20dd1b0e0 igmp: Fix data-races around sysctl_igmp_qrv.
73e5a0b591 ipv6/addrconf: fix a null-ptr-deref bug for ip6_ptr
421e5dd1f1 net: ping6: Fix memleak in ipv6_renew_options().
3d492b008b tcp: Fix a data-race around sysctl_tcp_challenge_ack_limit.
dfdc635d55 tcp: Fix a data-race around sysctl_tcp_limit_output_bytes.
d62e255ecc scsi: ufs: host: Hold reference returned by of_parse_phandle()
b1343528c7 ice: do not setup vlan for loopback VSI
15d0198601 ice: check (DD | EOF) bits on Rx descriptor rather than (EOP | RS)
cd23a2ad7b tcp: Fix a data-race around sysctl_tcp_nometrics_save.
f9a03fd8ed tcp: Fix a data-race around sysctl_tcp_frto.
3be498bcf6 tcp: Fix a data-race around sysctl_tcp_adv_win_scale.
f4b83df011 tcp: Fix a data-race around sysctl_tcp_app_win.
f240d0cad2 tcp: Fix data-races around sysctl_tcp_dsack.
b9f937d3d5 s390/archrandom: prevent CPACF trng invocations in interrupt context
911904c577 ntfs: fix use-after-free in ntfs_ucsncmp()
098e07ef00 Bluetooth: L2CAP: Fix use-after-free caused by l2cap_chan_put
5b72a540b0 ANDROID: restore some removed refcount functions
380aec8a64 ANDROID: add tty_schedule_flip() back to the kernel
b1e3be07f2 Merge 5.4.208 into android11-5.4-lts
77ba2b9b46 Linux 5.4.208
ca5762c589 x86: drop bogus "cc" clobber from __try_cmpxchg_user_asm()
f88d8c1882 net: usb: ax88179_178a needs FLAG_SEND_ZLP
f7785092cb tty: use new tty_insert_flip_string_and_push_buffer() in pty_write()
815d936e92 tty: extract tty_flip_buffer_commit() from tty_flip_buffer_push()
2ea77b0b6d tty: drop tty_schedule_flip()
f20912215c tty: the rest, stop using tty_schedule_flip()
aa60c0cce8 tty: drivers/tty/, stop using tty_schedule_flip()
126137a53d Bluetooth: Fix bt_skb_sendmmsg not allocating partial chunks
836b47e643 Bluetooth: SCO: Fix sco_send_frame returning skb->len
aa2d34cab3 Bluetooth: Fix passing NULL to PTR_ERR
10bacb8917 Bluetooth: RFCOMM: Replace use of memcpy_from_msg with bt_skb_sendmmsg
bf46574d46 Bluetooth: SCO: Replace use of memcpy_from_msg with bt_skb_sendmsg
f00b06003b Bluetooth: Add bt_skb_sendmmsg helper
55bf99849b Bluetooth: Add bt_skb_sendmsg helper
015af30d37 ALSA: memalloc: Align buffer allocations in page size
352affc31e bitfield.h: Fix "type of reg too small for mask" test
0a0fbbd6cb x86/mce: Deduplicate exception handling
b524137fa1 mmap locking API: initial implementation as rwsem wrappers
592a1c6066 x86/uaccess: Implement macros for CMPXCHG on user addresses
1d778b54a5 x86: get rid of small constant size cases in raw_copy_{to,from}_user()
d0d583484d locking/refcount: Consolidate implementations of refcount_t
dab787c73f locking/refcount: Consolidate REFCOUNT_{MAX,SATURATED} definitions
0d3182fbe6 locking/refcount: Move saturation warnings out of line
809554147d locking/refcount: Improve performance of generic REFCOUNT_FULL code
9c9269977f locking/refcount: Move the bulk of the REFCOUNT_FULL implementation into the <linux/refcount.h> header
04bff7d7b8 locking/refcount: Remove unused refcount_*_checked() variants
513b19a43b locking/refcount: Ensure integer operands are treated as signed
68b4ee68e8 locking/refcount: Define constants for saturation and max refcount values
3f71d0e292 ima: remove the IMA_TEMPLATE Kconfig option
bc7581e36d dlm: fix pending remove if msg allocation fails
4f1d21c77b bpf: Make sure mac_header was set before using it
a1f8765f68 mm/mempolicy: fix uninit-value in mpol_rebind_policy()
76668d2a2f spi: bcm2835: bcm2835_spi_handle_err(): fix NULL pointer deref for non DMA transfers
50a1d3d097 tcp: Fix data-races around sysctl_tcp_max_reordering.
c64b99819d tcp: Fix a data-race around sysctl_tcp_rfc1337.
6cc566df68 tcp: Fix a data-race around sysctl_tcp_stdurg.
7f68bed16c tcp: Fix a data-race around sysctl_tcp_retrans_collapse.
369d99c2b8 tcp: Fix data-races around sysctl_tcp_slow_start_after_idle.
492f3713b2 tcp: Fix a data-race around sysctl_tcp_thin_linear_timeouts.
92c35113c6 tcp: Fix data-races around sysctl_tcp_recovery.
83767fe800 tcp: Fix a data-race around sysctl_tcp_early_retrans.
795aee11fd tcp: Fix data-races around sysctl knobs related to SYN option.
f39b03bd72 udp: Fix a data-race around sysctl_udp_l3mdev_accept.
6727f39e99 ipv4: Fix a data-race around sysctl_fib_multipath_use_neigh.
a8569f76df be2net: Fix buffer overflow in be_get_module_eeprom
91d6aa19dd gpio: pca953x: only use single read/write for No AI mode
031af9e617 ixgbe: Add locking to prevent panic when setting sriov_numvfs to zero
55a2a28b32 i40e: Fix erroneous adapter reinitialization during recovery process
d88d59faf4 iavf: Fix handling of dummy receive descriptors
25d53d858a tcp: Fix data-races around sysctl_tcp_fastopen.
78420d8e46 tcp: Fix data-races around sysctl_max_syn_backlog.
dc58e68d1e tcp: Fix a data-race around sysctl_tcp_tw_reuse.
e9362a9938 tcp: Fix a data-race around sysctl_tcp_notsent_lowat.
b0d9f04c87 tcp: Fix data-races around some timeout sysctl knobs.
ea309c467d tcp: Fix data-races around sysctl_tcp_reordering.
b222de2560 tcp: Fix data-races around sysctl_tcp_syncookies.
ff55c025e6 igmp: Fix a data-race around sysctl_igmp_max_memberships.
1656ecaddf igmp: Fix data-races around sysctl_igmp_llm_reports.
2aad2c5745 net/tls: Fix race in TLS device down flow
573768dede net: stmmac: fix dma queue left shift overflow issue
911b81fca2 i2c: cadence: Change large transfer count reset logic to be unconditional
73a1158875 tcp: Fix a data-race around sysctl_tcp_probe_interval.
b04817c94f tcp: Fix a data-race around sysctl_tcp_probe_threshold.
033963b220 tcp: Fix a data-race around sysctl_tcp_mtu_probe_floor.
fdb96b69f5 tcp: Fix data-races around sysctl_tcp_min_snd_mss.
30b73edc1d tcp: Fix data-races around sysctl_tcp_base_mss.
f966773e13 tcp: Fix data-races around sysctl_tcp_mtu_probing.
a7386602a2 tcp/dccp: Fix a data-race around sysctl_tcp_fwmark_accept.
25a635a67c ip: Fix a data-race around sysctl_fwmark_reflect.
281de37199 ip: Fix data-races around sysctl_ip_nonlocal_bind.
7828309df0 ip: Fix data-races around sysctl_ip_fwd_use_pmtu.
5af6d92263 ip: Fix data-races around sysctl_ip_no_pmtu_disc.
16cb6717f4 igc: Reinstate IGC_REMOVED logic and implement it properly
98c3c8fd0d perf/core: Fix data race between perf_event_set_output() and perf_mmap_close()
6194c02149 pinctrl: ralink: Check for null return of devm_kcalloc
78bdf732cf power/reset: arm-versatile: Fix refcount leak in versatile_reboot_probe
f4248bdb7d xfrm: xfrm_policy: fix a possible double xfrm_pols_put() in xfrm_bundle_lookup()
c68f6e2e4f serial: mvebu-uart: correctly report configured baudrate value
2230428fb8 PCI: hv: Fix interrupt mapping for multi-MSI
7121d7120f PCI: hv: Reuse existing IRTE allocation in compose_msi_msg()
584c9d4180 PCI: hv: Fix hv_arch_irq_unmask() for multi-MSI
8e94cc8830 PCI: hv: Fix multi-MSI to allow more than one MSI vector
3048666143 xen/gntdev: Ignore failure to unmap INVALID_GRANT_HANDLE
ed3fea5506 lockdown: Fix kexec lockdown bypass with ima policy
c3856fe718 mlxsw: spectrum_router: Fix IPv4 nexthop gateway indication
c3dc751184 riscv: add as-options for modules with assembly compontents
e5a6b05d0c pinctrl: stm32: fix optional IRQ support to gpios
06f012f2c0 Merge branch 'android11-5.4' into branch 'android11-5.4-lts'
d3891851c5 Revert "cgroup: Use separate src/dst nodes when preloading css_sets for migration"
836d95bfdc Merge 5.4.207 into android11-5.4-lts
002c3bbb47 Linux 5.4.207
08d90846e4 can: m_can: m_can_tx_handler(): fix use after free of skb
579c8a2e63 serial: pl011: UPSTAT_AUTORTS requires .throttle/unthrottle
0c8649a497 serial: stm32: Clear prev values before setting RTS delays
f4c7f5028b serial: 8250: fix return error code in serial8250_request_std_resource()
07379bd79d tty: serial: samsung_tty: set dma burst_size to 1
edcb261221 usb: dwc3: gadget: Fix event pending check
40034fe6b8 usb: typec: add missing uevent when partner support PD
42373b717a USB: serial: ftdi_sio: add Belimo device ids
cbc98dcc38 signal handling: don't use BUG_ON() for debugging
172cd32ada ARM: dts: stm32: use the correct clock source for CEC on stm32mp151
c7d4b3ec63 soc: ixp4xx/npe: Fix unused match warning
a3c7c1a726 x86: Clear .brk area at early boot
549f70b299 irqchip: or1k-pic: Undefine mask_ack for level triggered hardware
b0f41db500 ASoC: madera: Fix event generation for rate controls
79067a6632 ASoC: madera: Fix event generation for OUT1 demux
0e7e515a67 ASoC: cs47l15: Fix event generation for low power mux control
20b921f22a ASoC: wm5110: Fix DRE control
f298d2e4c6 ASoC: ops: Fix off by one in range control validation
ede990cfc4 net: sfp: fix memory leak in sfp_probe()
555cee1bc4 nvme: fix regression when disconnect a recovering ctrl
08082a642a NFC: nxp-nci: don't print header length mismatch on i2c error
4919d82f70 net: tipc: fix possible refcount leak in tipc_sk_create()
70d8aee1de platform/x86: hp-wmi: Ignore Sanitization Mode event
8dda30f81c cpufreq: pmac32-cpufreq: Fix refcount leak bug
b749af1b8f netfilter: br_netfilter: do not skip all hooks with 0 priority
0c9203e75d virtio_mmio: Restore guest page size on resume
569f1ee032 virtio_mmio: Add missing PM calls to freeze/restore
70433d9ea6 mm: sysctl: fix missing numa_stat when !CONFIG_HUGETLB_PAGE
da346adcf5 sfc: fix kernel panic when creating VF
ba60ca0ed1 seg6: bpf: fix skb checksum in bpf_push_seg6_encap()
de7849d9de seg6: fix skb checksum in SRv6 End.B6 and End.B6.Encaps behaviors
487f0f77f1 seg6: fix skb checksum evaluation in SRH encapsulation/insertion
bcad880865 sfc: fix use after free when disabling sriov
b8d77f2396 net: ftgmac100: Hold reference returned by of_get_child_by_name()
9b61d3f6df ipv4: Fix data-races around sysctl_ip_dynaddr.
cc9540ba5b raw: Fix a data-race around sysctl_raw_l3mdev_accept.
df691b9910 icmp: Fix a data-race around sysctl_icmp_ratemask.
8bc1f68714 icmp: Fix a data-race around sysctl_icmp_ratelimit.
3093a6fe31 drm/i915/gt: Serialize TLB invalidates with GT resets
40d58aad2f ARM: dts: sunxi: Fix SPI NOR campatible on Orange Pi Zero
bf676c9408 ARM: dts: at91: sama5d2: Fix typo in i2s1 node
7c1acd98fb ipv4: Fix a data-race around sysctl_fib_sync_mem.
0cba7ca667 icmp: Fix data-races around sysctl.
0e41a0f73c cipso: Fix data-races around sysctl.
861f1852af net: Fix data-races around sysctl_mem.
8d2daf565f inetpeer: Fix data-races around sysctl.
2968830c9b net: stmmac: dwc-qos: Disable split header for Tegra194
1273fd5153 ASoC: sgtl5000: Fix noise on shutdown/remove
388f3df7c3 ima: Fix a potential integer overflow in ima_appraise_measurement
72f231b9a8 drm/i915: fix a possible refcount leak in intel_dp_add_mst_connector()
0f02e7c02b ARM: 9210/1: Mark the FDT_FIXED sections as shareable
41ea241fb3 ARM: 9209/1: Spectre-BHB: avoid pr_info() every time a CPU comes out of idle
851730a198 ARM: dts: imx6qdl-ts7970: Fix ngpio typo and count
18881d7e51 ext4: fix race condition between ext4_write and ext4_convert_inline_data
423f269500 sched/rt: Disable RT_RUNTIME_SHARE by default
31e99fa969 Revert "evm: Fix memleak in init_desc"
d85d19f3b6 nilfs2: fix incorrect masking of permission flags for symlinks
393594aad5 drm/panfrost: Fix shrinker list corruption by madvise IOCTL
ad44e05f3e cgroup: Use separate src/dst nodes when preloading css_sets for migration
444be5a02b wifi: mac80211: fix queue selection for mesh/OCB interfaces
dba5484769 ARM: 9214/1: alignment: advance IT state after emulating Thumb instruction
b4d99aa5ae ARM: 9213/1: Print message about disabled Spectre workarounds only once
2c1cc40fb2 ip: fix dflt addr selection for connected nexthop
fb5a7f1548 net: sock: tracing: Fix sock_exceed_buf_limit not to dereference stale pointer
ecc6dec12c tracing/histograms: Fix memory leak problem
7425479d20 xen/netback: avoid entering xenvif_rx_next_skb() with an empty rx queue
9026b280eb ALSA: hda/realtek - Enable the headset-mic on a Xiaomi's laptop
bbb82d4d9b ALSA: hda/realtek - Fix headset mic problem for a HP machine with alc221
7e2fbf2d9b ALSA: hda/realtek - Fix headset mic problem for a HP machine with alc671
33d33a66e3 ALSA: hda/conexant: Apply quirk for another HP ProDesk 600 G3 model
5e7cc47ab9 ALSA: hda - Add fixup for Dell Latitidue E5430
f0aba2ea80 Merge 5.4.206 into android11-5.4-lts
6584107915 Linux 5.4.206
15a3adfe75 Revert "mtd: rawnand: gpmi: Fix setting busy timeout setting"
a5112e9833 Merge 5.4.205 into android11-5.4-lts
0ec831fa97 Linux 5.4.205
1be11d7f3c dmaengine: ti: Add missing put_device in ti_dra7_xbar_route_allocate
b31ab13256 dmaengine: ti: Fix refcount leak in ti_dra7_xbar_route_allocate
f19026ede2 dmaengine: at_xdma: handle errors of at_xdmac_alloc_desc() correctly
164e88024f dmaengine: pl330: Fix lockdep warning about non-static key
5af3f2a697 ida: don't use BUG_ON() for debugging
d88022b41e dt-bindings: dma: allwinner,sun50i-a64-dma: Fix min/max typo
aaf875578f misc: rtsx_usb: set return value in rsp_buf alloc err path
29612c43a2 misc: rtsx_usb: use separate command and response buffers
0e517d0d7f misc: rtsx_usb: fix use of dma mapped buffer for usb bulk transfer
858c2d0708 dmaengine: imx-sdma: Allow imx8m for imx7 FW revs
6758690689 i2c: cadence: Unregister the clk notifier in error path
acb72388ae selftests: forwarding: fix error message in learning_test
7adf3d45c4 selftests: forwarding: fix learning_test when h1 supports IFF_UNICAST_FLT
681738560b selftests: forwarding: fix flood_unicast_test when h2 supports IFF_UNICAST_FLT
0711d15ccb ibmvnic: Properly dispose of all skbs during a failover.
aa698affa6 ARM: at91: pm: use proper compatibles for sam9x60's rtc and rtt
6b4747d5af ARM: at91: pm: use proper compatible for sama5d2's rtc
1235402750 pinctrl: sunxi: sunxi_pconf_set: use correct offset
12a6905369 pinctrl: sunxi: a83t: Fix NAND function name for some pins
3cf8ece911 ARM: meson: Fix refcount leak in meson_smp_prepare_cpus
c465bbcd3c xfs: remove incorrect ASSERT in xfs_rename
845dac0276 can: kvaser_usb: kvaser_usb_leaf: fix bittiming limits
9afdff9dd8 can: kvaser_usb: kvaser_usb_leaf: fix CAN clock frequency regression
93f228fcbe can: kvaser_usb: replace run-time checks with struct kvaser_usb_driver_info
0adb049bac powerpc/powernv: delay rng platform device creation until later in boot
782b65ee7b video: of_display_timing.h: include errno.h
af93e82197 fbcon: Prevent that screen size is smaller than font size
4f34f380f9 fbcon: Disallow setting font bigger than screen size
997d86cd3e fbmem: Check virtual screen sizes in fb_set_var()
407c1b491f fbdev: fbmem: Fix logo center image dx issue
14ff118431 iommu/vt-d: Fix PCI bus rescan device hot add
800bb66ab2 net: rose: fix UAF bug caused by rose_t0timer_expiry
04894ab34f usbnet: fix memory leak in error case
6f655b5e13 can: gs_usb: gs_usb_open/close(): fix memory leak
eb7bbd7728 can: grcan: grcan_probe(): remove extra of_node_get()
5b48f5711f can: bcm: use call_rcu() instead of costly synchronize_rcu()
e7e3e90d67 mm/slub: add missing TID updates on slab deactivation
3defefd22a esp: limit skb_page_frag_refill use to a single page
63b83aede5 Merge 5.4.204 into android11-5.4-lts
49286fbdad Linux 5.4.204
0ac2845937 clocksource/drivers/ixp4xx: remove EXPORT_SYMBOL_GPL from ixp4xx_timer_setup()
d40057538b net: usb: qmi_wwan: add Telit 0x1070 composition
ea89a522b4 net: usb: qmi_wwan: add Telit 0x1060 composition
5c03cad51b xen/arm: Fix race in RB-tree based P2M accounting
60ac50daad xen/blkfront: force data bouncing when backend is untrusted
ede57be88a xen/netfront: force data bouncing when backend is untrusted
04945b5beb xen/netfront: fix leaking data in shared pages
42112e8f94 xen/blkfront: fix leaking data in shared pages
b7c996abe5 selftests/rseq: Change type of rseq_offset to ptrdiff_t
dc28252880 selftests/rseq: x86-32: use %gs segment selector for accessing rseq thread area
f89d15c986 selftests/rseq: x86-64: use %fs segment selector for accessing rseq thread area
618da2318e selftests/rseq: Fix: work-around asm goto compiler bugs
58082d4e81 selftests/rseq: Remove arm/mips asm goto compiler work-around
1c9f13880f selftests/rseq: Fix warnings about #if checks of undefined tokens
6f87493c3a selftests/rseq: Fix ppc32 offsets by using long rather than off_t
4e9c8fd7f7 selftests/rseq: Fix ppc32 missing instruction selection "u" and "x" for load/store
d0ca70238f selftests/rseq: Fix ppc32: wrong rseq_cs 32-bit field pointer on big endian
20e2f01085 selftests/rseq: Uplift rseq selftests for compatibility with glibc-2.35
71c04fdf59 selftests/rseq: Introduce thread pointer getters
f491e073b9 selftests/rseq: Introduce rseq_get_abi() helper
158d91ffe0 selftests/rseq: Remove volatile from __rseq_abi
7037c511f6 selftests/rseq: Remove useless assignment to cpu variable
9aa134cb66 selftests/rseq: introduce own copy of rseq uapi header
8417f44759 selftests/rseq: remove ARRAY_SIZE define from individual tests
b131190070 rseq/selftests,x86_64: Add rseq_offset_deref_addv()
7b6bffcfb9 ipv6/sit: fix ipip6_tunnel_get_prl return value
05387c4ff5 sit: use min
e99a986161 net: dsa: bcm_sf2: force pause link settings
ac9cd4f66a hwmon: (ibmaem) don't call platform_device_del() if platform_device_add() fails
ee25841221 xen/gntdev: Avoid blocking in unmap_grant_pages()
5eac00ef2a net: tun: avoid disabling NAPI twice
8f968872ec NFC: nxp-nci: Don't issue a zero length i2c_master_read()
37287fd28f nfc: nfcmrvl: Fix irq_of_parse_and_map() return value
893825289b net: bonding: fix use-after-free after 802.3ad slave unbind
6fdef80e7e net: bonding: fix possible NULL deref in rlb code
bb1dc7cc57 net/sched: act_api: Notify user space if any actions were flushed before error
3b2ddeb89f netfilter: nft_dynset: restore set element counter when failing to update
5b3a1c6bca s390: remove unneeded 'select BUILD_BIN2C'
bdecd912e9 PM / devfreq: exynos-ppmu: Fix refcount leak in of_get_devfreq_events
e1284ec4a6 caif_virtio: fix race between virtio_device_ready() and ndo_open()
9204bc3e87 net: ipv6: unexport __init-annotated seg6_hmac_net_init()
7a79f71f69 usbnet: fix memory allocation in helpers
5af106f8e0 linux/dim: Fix divide by 0 in RDMA DIM
85d7d672e8 RDMA/qedr: Fix reporting QP timeout attribute
ea0519bc57 net: tun: stop NAPI when detaching queues
a8cf919022 net: tun: unlink NAPI from device on destruction
22e7546101 selftests/net: pass ipv6_args to udpgso_bench's IPv6 TCP test
1d877327da virtio-net: fix race between ndo_open() and virtio_device_ready()
7f89bb5d71 net: usb: ax88179_178a: Fix packet receiving
bb91556d2a net: rose: fix UAF bugs caused by timer handler
76a477d398 SUNRPC: Fix READ_PLUS crasher
13816057ea s390/archrandom: simplify back to earlier design and initialize earlier
f157bd9cf3 dm raid: fix KASAN warning in raid5_add_disks
90de153575 dm raid: fix accesses beyond end of raid member array
b6125c5dc3 powerpc/bpf: Fix use of user_pt_regs in uapi
1ef2e87736 powerpc/prom_init: Fix kernel config grep
d5e32f08e7 nvdimm: Fix badblocks clear off-by-one error
53fb996f27 ipv6: take care of disable_policy when restoring routes
15a9d795eb Merge 5.4.203 into android11-5.4-lts
871cbc208b Linux 5.4.203
572cc34503 crypto: arm/ghash-ce - define fpu before fpu registers are referenced
3bf992f9d9 crypto: arm - use Kconfig based compiler checks for crypto opcodes
1b43c30cd5 ARM: 9029/1: Make iwmmxt.S support Clang's integrated assembler
9e00e5d195 ARM: OMAP2+: drop unnecessary adrl
3657432a75 ARM: 8929/1: use APSR_nzcv instead of r15 as mrc operand
02c200fdba ARM: 8933/1: replace Sun/Solaris style flag on section directive
54e6ecd5b7 crypto: arm/sha512-neon - avoid ADRL pseudo instruction
5e6f800332 crypto: arm/sha256-neon - avoid ADRL pseudo instruction
e120403c0e ARM: 8971/1: replace the sole use of a symbol with its definition
0a43679016 ARM: 8990/1: use VFP assembler mnemonics in register load/store macros
472671eec9 ARM: 8989/1: use .fpu assembler directives instead of assembler arguments
2bfb0d43a4 net: mscc: ocelot: allow unregistered IP multicast flooding
223d551a66 kexec_file: drop weak attribute from arch_kexec_apply_relocations[_add]
ab3ed204a1 powerpc/ftrace: Remove ftrace init tramp once kernel init is complete
77e2ad0918 drm: remove drm_fb_helper_modinit
476819f502 Merge branch 'android11-5.4' into branch 'android11-5.4-lts'
8e932637c7 Merge 5.4.202 into android11-5.4-lts
9ef3ad40a8 Linux 5.4.202
ceda71d49f powerpc/pseries: wire up rng during setup_arch()
ece9838902 kbuild: link vmlinux only once for CONFIG_TRIM_UNUSED_KSYMS (2nd attempt)
2a81e81314 random: update comment from copy_to_user() -> copy_to_iter()
80f0038d75 modpost: fix section mismatch check for exported init/exit sections
d1359e4129 ARM: cns3xxx: Fix refcount leak in cns3xxx_init
29ca9c4efa ARM: Fix refcount leak in axxia_boot_secondary
734a4d1514 soc: bcm: brcmstb: pm: pm-arm: Fix refcount leak in brcmstb_pm_probe
f9b77a5293 ARM: exynos: Fix refcount leak in exynos_map_pmu
615907ccc4 ARM: dts: imx6qdl: correct PU regulator ramp delay
93e6137d2a powerpc/powernv: wire up rng during setup_arch
97808c7817 powerpc/rtas: Allow ibm,platform-dump RTAS call with null buffer address
b623297932 powerpc: Enable execve syscall exit tracepoint
e0701f150b parisc: Enable ARCH_HAS_STRICT_MODULE_RWX
e5234a9d64 xtensa: Fix refcount leak bug in time.c
a52972ee70 xtensa: xtfpga: Fix refcount leak bug in setup
f0fc7cdf5f iio: adc: axp288: Override TS pin bias current for some models
11c7ea38be iio: adc: stm32: fix maximum clock rate for stm32mp15x
5e39397d60 iio: trigger: sysfs: fix use-after-free on remove
6d2e68d021 iio: gyro: mpu3050: Fix the error handling in mpu3050_power_up()
1ad6d66854 iio: accel: mma8452: ignore the return value of reset operation
a391bced84 iio:accel:mxc4005: rearrange iio trigger get and register
23c158caa0 iio:accel:bma180: rearrange iio trigger get and register
8ea16a64aa iio:chemical:ccs811: rearrange iio trigger get and register
2333db14d8 usb: chipidea: udc: check request status before setting device address
47e41b4dab xhci: turn off port power in shutdown
d62d1c606d iio: adc: vf610: fix conversion mode sysfs node name
741b6c8363 s390/cpumf: Handle events cycles and instructions identical
4837d1c812 gpio: winbond: Fix error code in winbond_gpio_get()
bb18ad00c0 Revert "net/tls: fix tls_sk_proto_close executed repeatedly"
8c7a32b7c1 virtio_net: fix xdp_rxq_info bug after suspend/resume
28a78414f2 igb: Make DMA faster when CPU is active on the PCIe link
a5ed066bc2 regmap-irq: Fix a bug in regmap_irq_enable() for type_in_mask chips
844168a5da ice: ethtool: advertise 1000M speeds properly
e3a232e576 afs: Fix dynamic root getattr
cacab1e620 MIPS: Remove repetitive increase irq_err_count
788c954f19 x86/xen: Remove undefined behavior in setup_features()
c7bdaad9cb udmabuf: add back sanity check
05c6c36c79 net/tls: fix tls_sk_proto_close executed repeatedly
02da602bc2 erspan: do not assume transport header is always set
d1592d3e36 drm/msm/mdp4: Fix refcount leak in mdp4_modeset_init_intf
f1f9c2a5a3 net/sched: sch_netem: Fix arithmetic in netem_dump() for 32-bit platforms
47d31b97bf bonding: ARP monitor spams NETDEV_NOTIFY_PEERS notifiers
104a59b745 phy: aquantia: Fix AN when higher speeds than 1G are not advertised
8ffe2e50e9 bpf: Fix request_sock leak in sk lookup helpers
f074ab2539 USB: serial: option: add Quectel RM500K module support
ea7b23eade USB: serial: option: add Quectel EM05-G modem
613c849d73 USB: serial: option: add Telit LE910Cx 0x1250 composition
ae183969bd random: quiet urandom warning ratelimit suppression message
06a24ddba9 dm mirror log: clear log bits up to BITS_PER_LONG boundary
1f350f3cf0 dm era: commit metadata in postsuspend after worker stops
0e75acbe1b ata: libata: add qc->flags in ata_qc_complete_template tracepoint
71c76f56b9 mtd: rawnand: gpmi: Fix setting busy timeout setting
c8d37e6ca1 mmc: sdhci-pci-o2micro: Fix card detect by dealing with debouncing
af28f602df net: openvswitch: fix parsing of nw_proto for IPv6 fragments
6fda65dabd ALSA: hda/realtek: Add quirk for Clevo PD70PNT
5fbad99e76 ALSA: hda/realtek - ALC897 headset MIC no sound
cf81f367cf ALSA: hda/conexant: Fix missing beep setup
eca9b5e36e ALSA: hda/via: Fix missing beep setup
1df5178fde random: schedule mix_interrupt_randomness() less often
c87e851b23 vt: drop old FONT ioctls
d7a5d91fa5 Merge 5.4.201 into android11-5.4-lts
23db944f75 Linux 5.4.201
3994d2ee55 Revert "hwmon: Make chip parameter for with_info API mandatory"
7b9c3bfbad arm64: mm: Don't invalidate FROM_DEVICE buffers at start of DMA transfer
2e1591c27b tcp: drop the hash_32() part from the index calculation
c26e1addf1 tcp: increase source port perturb table to 2^16
77d29f3b18 tcp: dynamically allocate the perturb table used by source ports
7c0a777b7d tcp: add small random increments to the source port
53c5de3092 tcp: use different parts of the port_offset for index and offset
95921a3bab tcp: add some entropy in __inet_hash_connect()
bdcbf2602f usb: gadget: u_ether: fix regression in setting fixed MAC address
2577d67a9a dm: remove special-casing of bio-based immutable singleton target on NVMe
4143503b48 s390/mm: use non-quiescing sske for KVM switch to keyed guest
1dd92ce7e8 UPSTREAM: ext4: verify dir block before splitting it
1765fa5267 UPSTREAM: ext4: fix use-after-free in ext4_rename_dir_prepare
24ee3133e7 BACKPORT: ext4: Only advertise encrypted_casefold when encryption and unicode are enabled
4adf828284 BACKPORT: ext4: fix no-key deletion for encrypt+casefold
7f4133a55e BACKPORT: ext4: optimize match for casefolded encrypted dirs
ce3b26019c BACKPORT: ext4: handle casefolding with encryption
8515bb68ee Revert "ANDROID: ext4: Handle casefolding with encryption"
91b58da1b3 Revert "ANDROID: ext4: Optimize match for casefolded encrypted dirs"
467eb53acd ANDROID: cpu/hotplug: avoid breaking Android ABI by fusing cpuhp steps
c566c065e8 ANDROID: change function signatures for some random functions.
b2351c2368 Merge 5.4.200 into android11-5.4-lts
4c5060a549 Merge 5.4.199 into android11-5.4-lts
bba1b765b9 Revert "mailbox: forward the hrtimer if not queued and under a lock"
829ffaa71c Revert "drm: fix EDID struct for old ARM OABI format"
864659cb5f Revert "ALSA: jack: Access input_dev under mutex"
f0c280af0e Linux 5.4.200
ab8dff4b71 powerpc/mm: Switch obsolete dssall to .long
1a48a41f14 riscv: Less inefficient gcc tishift helpers (and export their symbols)
2464a1c0de RISC-V: fix barrier() use in <vdso/processor.h>
490a02cd82 arm64: kprobes: Use BRK instead of single-step when executing instructions out-of-line
ef6f9ce0a7 net: openvswitch: fix leak of nested actions
6bb3c77c74 net: openvswitch: fix misuse of the cached connection on tuple changes
b47319b4aa net/sched: act_police: more accurate MTU policing
13fbdea118 virtio-pci: Remove wrong address verification in vp_del_vqs()
80e4d8a274 ALSA: hda/realtek: fix right sounds and mute/micmute LEDs for HP machine
119e0268cc ALSA: hda/realtek: fix mute/micmute LEDs for HP 440 G8
fba5428917 ext4: add reserved GDT blocks check
4ca0d2f1e0 ext4: make variable "count" signed
a6b31616e5 ext4: fix bug_on ext4_mb_use_inode_pa
ae46031287 dm mirror log: round up region bitmap size to BITS_PER_LONG
64d2df6480 serial: 8250: Store to lsr_save_flags after lsr read
b75bddfcc1 usb: gadget: lpc32xx_udc: Fix refcount leak in lpc32xx_udc_probe
6506aff2dc usb: dwc2: Fix memory leak in dwc2_hcd_init
940653b51c USB: serial: io_ti: add Agilent E5805A support
31363b2b86 USB: serial: option: add support for Cinterion MV31 with new baseline
d0c3730f27 comedi: vmk80xx: fix expression for tx buffer size
bf833c4848 i2c: designware: Use standard optional ref clock implementation
8d884c08ee irqchip/gic-v3: Fix refcount leak in gic_populate_ppi_partitions
58e67c81e2 irqchip/gic-v3: Fix error handling in gic_populate_ppi_partitions
56526c3883 irqchip/gic/realview: Fix refcount leak in realview_gic_of_init
4695bafabf faddr2line: Fix overlapping text section failures, the sequel
1b34d6a938 certs/blacklist_hashes.c: fix const confusion in certs blacklist
fb775ee3cf arm64: ftrace: fix branch range checks
0e21311ba4 net: bgmac: Fix an erroneous kfree() in bgmac_remove()
c19cdd72b3 mlxsw: spectrum_cnt: Reorder counter pools
c03304dc42 misc: atmel-ssc: Fix IRQ check in ssc_probe
f7183c76d5 tty: goldfish: Fix free_irq() on remove
ff6e03fe84 i40e: Fix call trace in setup_tx_descriptors
4b94408e16 i40e: Fix calculating the number of queue pairs
43f65970ee i40e: Fix adding ADQ filter to TC0
cff3a7ce6e clocksource: hyper-v: unexport __init-annotated hv_init_clocksource()
11c870c0b5 pNFS: Don't keep retrying if the server replied NFS4ERR_LAYOUTUNAVAILABLE
e32fe87afc random: credit cpu and bootloader seeds by default
9e4cab02b7 net: ethernet: mtk_eth_soc: fix misuse of mem alloc interface netdev[napi]_alloc_frag
2f42389d27 ipv6: Fix signed integer overflow in l2tp_ip6_sendmsg
6b4d8b44e7 nfc: nfcmrvl: Fix memory leak in nfcmrvl_play_deferred
786428a1de virtio-mmio: fix missing put_device() when vm_cmdline_parent registration failed
aacb264d54 ALSA: hda/realtek - Add HW8326 support
ff882404df scsi: pmcraid: Fix missing resource cleanup in error case
c481192236 scsi: ipr: Fix missing/incorrect resource cleanup in error case
fe0855944a scsi: lpfc: Allow reduced polling rate for nvme_admin_async_event cmd completion
1f1be79189 scsi: lpfc: Fix port stuck in bypassed state after LIP in PT2PT topology
001de3d8ce scsi: vmw_pvscsi: Expand vcpuHint to 16 bits
9e3a0d3fc7 ASoC: wm_adsp: Fix event generation for wm_adsp_fw_put()
bc046649c5 ASoC: es8328: Fix event generation for deemphasis control
a81f5a7f7a ASoC: wm8962: Fix suspend while playing music
253334f84c ata: libata-core: fix NULL pointer deref in ata_host_alloc_pinfo()
052cd621ac ASoC: cs42l56: Correct typo in minimum level for SX volume controls
6d180913b3 ASoC: cs42l52: Correct TLV for Bypass Volume
385a031c56 ASoC: cs53l30: Correct number of volume levels on SX controls
675b6a49cf ASoC: cs35l36: Update digital volume TLV
b00f63dba5 ASoC: cs42l52: Fix TLV scales for mixer controls
cd8c1e6c01 dma-debug: make things less spammy under memory pressure
a45e19fd6e ASoC: nau8822: Add operation for internal PLL off and on
348831a9e8 powerpc/kasan: Silence KASAN warnings in __get_wchan()
5624055c8f random: account for arch randomness in bits
c0bf6bfce7 random: mark bootloader randomness code as __init
f96250197b random: avoid checking crng_ready() twice in random_init()
072cd87d12 crypto: drbg - make reseeding from get_random_bytes() synchronous
e9eb0c4741 crypto: drbg - always try to free Jitter RNG instance
f284afc3a9 crypto: drbg - move dynamic ->reseed_threshold adjustments to __drbg_seed()
babba4bf53 crypto: drbg - track whether DRBG was seeded with !rng_is_initialized()
1b93b302e9 crypto: drbg - prepare for more fine-grained tracking of seeding state
98e574a734 crypto: drbg - always seeded with SP800-90B compliant noise source
61f87ea3f9 Revert "random: use static branch for crng_ready()"
3faf33a856 random: check for signals after page of pool writes
2177cef53e random: wire up fops->splice_{read,write}_iter()
35db2a0731 random: convert to using fops->write_iter()
43e62db84a random: convert to using fops->read_iter()
c23188facd random: unify batched entropy implementations
1aeedbe02b random: move randomize_page() into mm where it belongs
ceaf1feefe random: move initialization functions out of hot pages
d3bf98d61f random: make consistent use of buf and len
70fce7f105 random: use proper return types on get_random_{int,long}_wait()
d05948dc23 random: remove extern from functions in header
d8b4296417 random: use static branch for crng_ready()
087a14b9cf random: credit architectural init the exact amount
ac48f7bee1 random: handle latent entropy and command line from random_init()
736a22645d random: use proper jiffies comparison macro
3266fba206 random: remove ratelimiting for in-kernel unseeded randomness
c5373bd6e4 random: move initialization out of reseeding hot path
0747ad152f random: avoid initializing twice in credit race
0baeec0eff random: use symbolic constants for crng_init states
55d64df3ad siphash: use one source of truth for siphash permutations
e4e8a9f8a6 random: help compiler out with fast_mix() by using simpler arguments
bf3b51eb0f random: do not use input pool from hard IRQs
6d4203a2cd random: order timer entropy functions below interrupt functions
58da574f10 random: do not pretend to handle premature next security model
e739d5bd14 random: use first 128 bits of input as fast init
c44f8b3863 random: do not use batches when !crng_ready()
e247ea8d97 random: insist on random_get_entropy() existing in order to simplify
9bfbcb37e5 xtensa: use fallback for random_get_entropy() instead of zero
fa15650b51 sparc: use fallback for random_get_entropy() instead of zero
9dfc14590c um: use fallback for random_get_entropy() instead of zero
0cc41e2c73 x86/tsc: Use fallback for random_get_entropy() instead of zero
f2a6e87270 nios2: use fallback for random_get_entropy() instead of zero
db1d13fe4c arm: use fallback for random_get_entropy() instead of zero
6fa912f987 mips: use fallback for random_get_entropy() instead of just c0 random
36f38f838c m68k: use fallback for random_get_entropy() instead of zero
a7d04ca9da timekeeping: Add raw clock fallback for random_get_entropy()
eb2f9d72f3 powerpc: define get_cycles macro for arch-override
10455a367c alpha: define get_cycles macro for arch-override
5f0b77ca19 parisc: define get_cycles macro for arch-override
80459abc9f s390: define get_cycles macro for arch-override
7338564449 ia64: define get_cycles macro for arch-override
5fac866639 init: call time_init() before rand_initialize()
b88ae87b10 random: fix sysctl documentation nits
4654257483 random: document crng_fast_key_erasure() destination possibility
ec07b34945 random: make random_get_entropy() return an unsigned long
fe156368f9 random: allow partial reads if later user copies fail
70788723da random: check for signals every PAGE_SIZE chunk of /dev/[u]random
2ce859d91f random: check for signal_pending() outside of need_resched() check
0e8030c9e0 random: do not allow user to keep crng key around on stack
95aed891f7 random: do not split fast init input in add_hwgenerator_randomness()
1d53d5a097 random: mix build-time latent entropy into pool at init
0aba75c617 random: re-add removed comment about get_random_{u32,u64} reseeding
81ea8a609b random: treat bootloader trust toggle the same way as cpu trust toggle
a08d52a608 random: skip fast_init if hwrng provides large chunk of entropy
8320bc665c random: check for signal and try earlier when generating entropy
3a53b818bb random: reseed more often immediately after booting
905759e0fc random: make consistent usage of crng_ready()
ad4c6bd98c random: use SipHash as interrupt entropy accumulator
631503001c random: replace custom notifier chain with standard one
1ae73fb2a6 random: don't let 644 read-only sysctls be written to
ed40975710 random: give sysctl_random_min_urandom_seed a more sensible value
75d95c1b5d random: do crng pre-init loading in worker rather than irq
219c84fe93 random: unify cycles_t and jiffies usage and types
673637c4c9 random: cleanup UUID handling
4d5151cc28 random: only wake up writers after zap if threshold was passed
ac0081dec7 random: round-robin registers as ulong, not u32
62cd795e46 random: clear fast pool, crng, and batches in cpuhp bring up
a7f8f385bb random: pull add_hwgenerator_randomness() declaration into random.h
ff607fc760 random: check for crng_init == 0 in add_device_randomness()
20788eb4ce random: unify early init crng load accounting
49567f9477 random: do not take pool spinlock at boot
4a61bf7f9b random: defer fast pool mixing to worker
944d1bd0e5 random: rewrite header introductory comment
c0e35949c7 random: group sysctl functions
d946084180 random: group userspace read/write functions
565a66043b random: group entropy collection functions
f2d587c493 random: group entropy extraction functions
a8786d5476 random: group crng functions
c12dfec1aa random: group initialization wait functions
22e3db57ab random: remove whitespace and reorder includes
cee64be605 random: remove useless header comment
904e6123c4 random: introduce drain_entropy() helper to declutter crng_reseed()
47c56790d5 random: deobfuscate irq u32/u64 contributions
e280b79c31 random: add proper SPDX header
776927dfd4 random: remove unused tracepoints
d68883956d random: remove ifdef'd out interrupt bench
4a14a5a696 random: tie batched entropy generation to base_crng generation
d8a6684950 random: fix locking for crng_init in crng_reseed()
b1d5611381 random: zero buffer after reading entropy from userspace
21da00f8cb random: remove outdated INT_MAX >> 6 check in urandom_read()
b530684129 random: make more consistent use of integer types
3eed6af93e random: use hash function for crng_slow_load()
cee3c70569 random: use simpler fast key erasure flow on per-cpu keys
ea9941fd6e random: absorb fast pool into input pool after fast load
a3562bf4e8 random: do not xor RDRAND when writing into /dev/random
574c883950 random: ensure early RDSEED goes through mixer on init
d3d3c1c214 random: inline leaves of rand_initialize()
817315517a random: get rid of secondary crngs
c15fc80b7d random: use RDSEED instead of RDRAND in entropy extraction
72db8151c8 random: fix locking in crng_fast_load()
7229c6d90a random: remove batched entropy locking
6c89115792 random: remove use_input_pool parameter from crng_reseed()
4ef908fb81 random: make credit_entropy_bits() always safe
42a9a7e807 random: always wake up entropy writers after extraction
373ef51f3e random: use linear min-entropy accumulation crediting
a1a2bae5ef random: simplify entropy debiting
4e5814bd2e random: use computational hash for entropy extraction
99a0f8e22d random: only call crng_finalize_init() for primary_crng
88609b892f random: access primary_pool directly rather than through pointer
0b9f9b94f1 random: continually use hwgenerator randomness
811e333c4e random: simplify arithmetic function flow in account()
56de23dcf9 random: selectively clang-format where it makes sense
86eac12b1c random: access input_pool_data directly rather than through pointer
4f5400ca7f random: cleanup fractional entropy shift constants
1b6f1d32a8 random: prepend remaining pool constants with POOL_
0fe4a64fd9 random: de-duplicate INPUT_POOL constants
e35576c4cb random: remove unused OUTPUT_POOL constants
74cb3093f2 random: rather than entropy_store abstraction, use global
14652d8642 random: remove unused extract_entropy() reserved argument
12f17e3f3a random: remove incomplete last_data logic
adcbbb44cc random: cleanup integer types
4ac4c7f057 random: cleanup poolinfo abstraction
5c3818e3bd random: fix typo in comments
0a7e658102 random: don't reset crng_init_cnt on urandom_read()
8d7c55563e random: avoid superfluous call to RDRAND in CRNG extraction
8b4695640b random: early initialization of ChaCha constants
cfc6906500 random: initialize ChaCha20 constants with correct endianness
922d082e33 random: use IS_ENABLED(CONFIG_NUMA) instead of ifdefs
565b3af168 random: harmonize "crng init done" messages
346c4a697c random: mix bootloader randomness into pool
afce74c0c0 random: do not re-init if crng_reseed completes before primary init
d76758c712 random: do not sign extend bytes for rotation when mixing
c2f0a89cd1 random: use BLAKE2s instead of SHA1 in extraction
6e6ae70c1e random: remove unused irq_flags argument from add_interrupt_randomness()
2580b0b3fd random: document add_hwgenerator_randomness() with other input functions
3cc36a4aa1 crypto: blake2s - adjust include guard naming
09342a544c crypto: blake2s - include <linux/bug.h> instead of <asm/bug.h>
f850f3643d MAINTAINERS: co-maintain random.c
967e3a136f random: remove dead code left over from blocking pool
610f0b439a random: avoid arch_get_random_seed_long() when collecting IRQ randomness
ad3fce6691 random: add arch_get_random_*long_early()
41b0d3e86c powerpc: Use bool in archrandom.h
89533373e1 linux/random.h: Mark CONFIG_ARCH_RANDOM functions __must_check
0222f9f1d1 linux/random.h: Use false with bool
15f93060b7 linux/random.h: Remove arch_has_random, arch_has_random_seed
a95ed04e21 s390: Remove arch_has_random, arch_has_random_seed
aab52172d9 powerpc: Remove arch_has_random, arch_has_random_seed
35e28a05f6 x86: Remove arch_has_random, arch_has_random_seed
98f749e297 random: avoid warnings for !CONFIG_NUMA builds
c13b9c3627 random: split primary/secondary crng init paths
c070b07aaf random: remove some dead code of poolinfo
898498bb44 random: fix typo in add_timer_randomness()
2c53d6d6a7 random: Add and use pr_fmt()
f3375cfe31 random: convert to ENTROPY_BITS for better code readability
9f757cad20 random: remove unnecessary unlikely()
4431c366fe random: remove kernel.random.read_wakeup_threshold
ec134003cc random: delete code to pull data into pools
a9564e14c6 random: remove the blocking pool
940cbc47b3 random: make /dev/random be almost like /dev/urandom
c4edc1055c random: ignore GRND_RANDOM in getentropy(2)
7f9f864af0 random: add GRND_INSECURE to return best-effort non-cryptographic bytes
479d39707f random: Add a urandom_read_nowait() for random APIs that don't warn
69441ba56f random: Don't wake crng_init_wait when crng_init == 1
69ef3109d4 random: don't forget compat_ioctl on urandom
927fc225af compat_ioctl: remove /dev/random commands
996fba14fa lib/crypto: sha1: re-roll loops to reduce code size
c4f4837440 lib/crypto: blake2s: move hmac construction into wireguard
97126d2f65 crypto: blake2s - generic C library implementation and selftest
76101f1b7f nfc: st21nfca: fix incorrect sizing calculations in EVT_TRANSACTION
e804587ecd bpf: Fix incorrect memory charge cost calculation in stack_map_alloc()
f91da317e6 9p: missing chunk of "fs/9p: Don't update file type when updating file attributes"
cf729493b6 Revert "ext4: fix use-after-free in ext4_rename_dir_prepare"
10f5759c4e Revert "ext4: verify dir block before splitting it"
a778a36923 Merge 5.4.198 into android11-5.4-lts
a31bd36611 Linux 5.4.199
4cc40b1022 x86/speculation/mmio: Print SMT warning
d49c22094e KVM: x86/speculation: Disable Fill buffer clear within guests
d961592635 x86/speculation/mmio: Reuse SRBDS mitigation for SBDS
bc64f38b5a x86/speculation/srbds: Update SRBDS mitigation selection
020ce7495c x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data
8d25482fc9 x86/speculation/mmio: Enable CPU Fill buffer clearing on idle
7f898baa20 x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations
0800f1b45b x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data
ae649e0cbf x86/speculation: Add a common function for MD_CLEAR mitigation update
814ccb6730 x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug
91f8147c83 Documentation: Add documentation for Processor MMIO Stale Data
1e9f4e8a7a x86/cpu: Add another Alder Lake CPU to the Intel family
45e744de25 x86/cpu: Add Lakefield, Alder Lake and Rocket Lake models to the to Intel CPU family
79568d5515 x86/cpu: Add Jasper Lake to Intel family
9e2efaa5dd cpu/speculation: Add prototype for cpu_show_srbds()
9d6e67bf50 Linux 5.4.198
602b338e3c tcp: fix tcp_mtup_probe_success vs wrong snd_cwnd
b35e08edb2 mtd: cfi_cmdset_0002: Use chip_ready() for write on S29GL064N
0c12d76255 md/raid0: Ignore RAID0 layout if the second zone has only one device
0c4bc0a2f8 powerpc/32: Fix overread/overwrite of thread_struct via ptrace
3c953d47eb Input: bcm5974 - set missing URB_NO_TRANSFER_DMA_MAP urb flag
6ec537c500 ixgbe: fix unexpected VLAN Rx in promisc mode on VF
24030768a7 ixgbe: fix bcast packets Rx on VF after promisc removal
3eca2c42da nfc: st21nfca: fix memory leaks in EVT_TRANSACTION handling
31f9c39b4a nfc: st21nfca: fix incorrect validating logic in EVT_TRANSACTION
4f4ab50046 mmc: block: Fix CQE recovery reset success
0245434e38 ata: libata-transport: fix {dma|pio|xfer}_mode sysfs files
b651f70ed3 cifs: return errors during session setup during reconnects
850965edc8 ALSA: hda/conexant - Fix loopback issue with CX20632
6c04a2ae03 scripts/gdb: change kernel config dumping method
1a36f77dc2 vringh: Fix loop descriptors check in the indirect cases
a3f9b0afd8 nodemask: Fix return values to be unsigned
9b306339a5 cifs: version operations for smb20 unneeded when legacy support disabled
5cb13cdc18 s390/gmap: voluntarily schedule during key setting
69893d6d7f nbd: fix io hung while disconnecting device
8a7da4ced2 nbd: fix race between nbd_alloc_config() and module removal
1be608e1ee nbd: call genl_unregister_family() first in nbd_cleanup()
045045b522 x86/cpu: Elide KCSAN for cpu_has() and friends
460083de66 modpost: fix undefined behavior of is_arm_mapping_symbol()
28fd384c78 drm/radeon: fix a possible null pointer dereference
9223144fdd ceph: allow ceph.dir.rctime xattr to be updatable
7df12bee54 Revert "net: af_key: add check for pfkey_broadcast in function pfkey_process"
0331d261c3 scsi: myrb: Fix up null pointer access on myrb_cleanup()
cf6b931687 md: protect md_unregister_thread from reentrancy
99e4c67a55 watchdog: wdat_wdt: Stop watchdog when rebooting the system
6fd031799e kernfs: Separate kernfs_pr_cont_buf and rename_lock.
19f4b51b83 serial: msm_serial: disable interrupts in __msm_console_write()
52a0d88c32 staging: rtl8712: fix uninit-value in r871xu_drv_init()
58762f1c63 staging: rtl8712: fix uninit-value in usb_read8() and friends
1bcfb95de1 clocksource/drivers/sp804: Avoid error on multiple instances
d472c78cc8 extcon: Modify extcon device to be created after driver data is set
fa0b2dd682 misc: rtsx: set NULL intfdata when probe fails
d232ca0bbc usb: dwc2: gadget: don't reset gadget's driver->bus
3a7170a3de USB: hcd-pci: Fully suspend across freeze/thaw cycle
2dcec0bc14 drivers: usb: host: Fix deadlock in oxu_bus_suspend()
09a5958a24 drivers: tty: serial: Fix deadlock in sa1100_set_termios()
c91a74b1f0 USB: host: isp116x: check return value after calling platform_get_resource()
64b05fa212 drivers: staging: rtl8192e: Fix deadlock in rtllib_beacons_stop()
1fbe033c52 drivers: staging: rtl8192u: Fix deadlock in ieee80211_beacons_stop()
8c014373f1 tty: Fix a possible resource leak in icom_probe
f6e07eb7eb tty: synclink_gt: Fix null-pointer-dereference in slgt_clean()
1b04c934e1 lkdtm/usercopy: Expand size of "out of frame" object
ca2498cce8 iio: st_sensors: Add a local lock for protecting odr
ab75e02366 iio: dummy: iio_simple_dummy: check the return value of kstrdup()
36acb4d9ce drm: imx: fix compiler warning with gcc-12
8174acbef8 net: altera: Fix refcount leak in altera_tse_mdio_create
3d08bc3a5d ip_gre: test csum_start instead of transport header
957d298526 net/mlx5: fs, fail conflicting actions
8a6740fdc5 net/mlx5: Rearm the FW tracer after each tracer event
317260b3eb net: ipv6: unexport __init-annotated seg6_hmac_init()
ef6d2354de net: xfrm: unexport __init-annotated xfrm4_protocol_init()
6a90a44d53 net: mdio: unexport __init-annotated mdio_bus_init()
978dcc55cf SUNRPC: Fix the calculation of xdr->end in xdr_get_next_encode_buffer()
180473e8e4 net/mlx4_en: Fix wrong return value on ioctl EEPROM query failure
7c8df6fad4 net: dsa: lantiq_gswip: Fix refcount leak in gswip_gphy_fw_list
e412b3d178 bpf, arm64: Clear prog->jited_len along prog->jited
556720013c af_unix: Fix a data-race in unix_dgram_peer_wake_me().
b49c884146 xen: unexport __init-annotated xen_xlate_map_ballooned_pages()
5b8d63489c netfilter: nf_tables: memleak flow rule from commit path
d5a1e7f33c ata: pata_octeon_cf: Fix refcount leak in octeon_cf_probe
e0212033ff netfilter: nat: really support inet nat without l3 address
da99331fa6 xprtrdma: treat all calls not a bcall when bc_serv is NULL
48dea4d3a1 video: fbdev: pxa3xx-gcu: release the resources correctly in pxa3xx_gcu_probe/remove()
a2b3be930e NFSv4: Don't hold the layoutget locks across multiple RPC calls
83960276ff dmaengine: zynqmp_dma: In struct zynqmp_dma_chan fix desc_size data type
4917e43bca m68knommu: fix undefined reference to `_init_sp'
f6bdafbb9b m68knommu: set ZERO_PAGE() to the allocated zeroed page
27fdb45723 i2c: cadence: Increase timeout per message if necessary
0a7a1fc7e7 f2fs: remove WARN_ON in f2fs_is_valid_blkaddr
23b2163b88 tracing: Avoid adding tracer option before update_tracer_options
48c6ee7d6c tracing: Fix sleeping function called from invalid context on RT kernel
cc0aed22d3 mips: cpc: Fix refcount leak in mips_cpc_default_phys_base
ff66ae4359 perf c2c: Fix sorting in percent_rmt_hitm_cmp()
8b91d0dfc8 tipc: check attribute length for bearer name
c2eba68d18 afs: Fix infinite loop found by xfstest generic/676
d05c2fdf8e tcp: tcp_rtx_synack() can be called from process context
1bd2f7f38b net: sched: add barrier to fix packet stuck problem for lockless qdisc
77b954ce2d net/mlx5e: Update netdev features after changing XDP state
a4c52440ac net/mlx5: Don't use already freed action pointer
00803d3051 nfp: only report pause frame configuration for physical device
8302620aeb ubi: ubi_create_volume: Fix use-after-free when volume creation failed
d3a4fff1e7 jffs2: fix memory leak in jffs2_do_fill_super
acf92b5257 modpost: fix removing numeric suffixes
a101793994 net: dsa: mv88e6xxx: Fix refcount leak in mv88e6xxx_mdios_register
2bd1faedb7 net: ethernet: mtk_eth_soc: out of bounds read in mtk_hwlro_get_fdir_entry()
be73e3bf68 net: sched: fixed barrier to prevent skbuff sticking in qdisc backlog
51ed32c1cf s390/crypto: fix scatterwalk_unmap() callers in AES-GCM
80f6712f24 clocksource/drivers/oxnas-rps: Fix irq_of_parse_and_map() return value
e5d479d73f ASoC: fsl_sai: Fix FSL_SAI_xDR/xFR definition
5b110d9404 watchdog: ts4800_wdt: Fix refcount leak in ts4800_wdt_probe
593b595332 driver core: fix deadlock in __device_attach
5d709f58c7 driver: base: fix UAF when driver_attach failed
3157118c17 bus: ti-sysc: Fix warnings for unbind for serial
a724634b2a firmware: dmi-sysfs: Fix memory leak in dmi_sysfs_register_handle
c3a16e7c86 serial: stm32-usart: Correct CSIZE, bits, and parity
29d963635e serial: st-asc: Sanitize CSIZE and correct PARENB for CS7
5c01c19f64 serial: sifive: Sanitize CSIZE and c_iflag
841cab744c serial: sh-sci: Don't allow CS5-6
942aa88467 serial: txx9: Don't allow CS5-6
eb8de4bac3 serial: rda-uart: Don't allow CS5-6
0de3d2344e serial: digicolor-usart: Don't allow CS5-6
035bc3b734 serial: 8250_fintek: Check SER_RS485_RTS_* only with RS485
1b3ae6d850 serial: meson: acquire port->lock in startup()
d77f28c1bc rtc: mt6397: check return value after calling platform_get_resource()
d041e88574 clocksource/drivers/riscv: Events are stopped during CPU suspend
69a30b2ed6 soc: rockchip: Fix refcount leak in rockchip_grf_init
0f91755514 coresight: cpu-debug: Replace mutex with mutex_trylock on panic notifier
47e4c42faa serial: sifive: Report actual baud base rather than fixed 115200
f2a16af2ee phy: qcom-qmp: fix pipe-clock imbalance on power-on failure
b6b0f8904b rpmsg: qcom_smd: Fix returning 0 if irq_of_parse_and_map() fails
088f449d9d iio: adc: sc27xx: Fine tune the scale calibration values
e5d48301d1 iio: adc: sc27xx: fix read big scale voltage not right
0f57d13930 iio: adc: stmpe-adc: Fix wait_for_completion_timeout return value check
bec18bb00f firmware: stratix10-svc: fix a missing check on list iterator
8ad7b3d9f8 usb: dwc3: pci: Fix pm_runtime_get_sync() error checking
1026ee392b rpmsg: qcom_smd: Fix irq_of_parse_and_map() return value
89d1b9dfcc pwm: lp3943: Fix duty calculation in case period was clamped
8e9f3f508a staging: fieldbus: Fix the error handling path in anybuss_host_common_probe()
67c2aa77b4 usb: musb: Fix missing of_node_put() in omap2430_probe
b78499772f USB: storage: karma: fix rio_karma_init return
72ab0f6f2b usb: usbip: add missing device lock on tweak configuration cmd
2f0ae93ec3 usb: usbip: fix a refcount leak in stub_probe()
077f58e469 tty: serial: fsl_lpuart: fix potential bug when using both of_alias_get_id and ida_simple_get
7320308b18 tty: serial: owl: Fix missing clk_disable_unprepare() in owl_uart_probe
9ae3d073f7 tty: goldfish: Use tty_port_destroy() to destroy port
d88fdea147 iio: adc: ad7124: Remove shift from scan_type
1aa30dc883 staging: greybus: codecs: fix type confusion of list iterator variable
6c8c536e00 pcmcia: db1xxx_ss: restrict to MIPS_DB1XXX boards
4faa6308e1 md: bcache: check the return value of kzalloc() in detached_dev_do_request()
5f62b21b7c block: fix bio_clone_blkg_association() to associate with proper blkcg_gq
ccddf8cd41 bfq: Make sure bfqg for which we are queueing requests is online
8afc13b958 bfq: Get rid of __bio_blkcg() usage
be1b78f949 bfq: Remove pointless bfq_init_rq() calls
f885f55033 bfq: Drop pointless unlock-lock pair
97be7d13fb bfq: Avoid merging queues with different parents
5407341053 MIPS: IP27: Remove incorrect `cpu_has_fpu' override
427c3c7ebd RDMA/rxe: Generate a completion for unsupported/invalid opcode
4946cfd1c8 Kconfig: add config option for asm goto w/ outputs
7ac21b24af phy: qcom-qmp: fix reset-controller leak on probe errors
d19fa8f252 blk-iolatency: Fix inflight count imbalances and IO hangs on offline
8a068913d1 dt-bindings: gpio: altera: correct interrupt-cells
3b8c37780d docs/conf.py: Cope with removal of language=None in Sphinx 5.0.0
da9634374d ARM: pxa: maybe fix gpio lookup tables
1668ad1036 phy: qcom-qmp: fix struct clk leak on probe errors
2040b60765 arm64: dts: qcom: ipq8074: fix the sleep clock frequency
8dd2e5f9c1 gma500: fix an incorrect NULL check on list iterator
a62591e361 tilcdc: tilcdc_external: fix an incorrect NULL check on list iterator
77ec584d3d serial: pch: don't overwrite xmit->buf[0] by x_char
f6cb1470ba carl9170: tx: fix an incorrect use of list iterator
2ea49d6310 ASoC: rt5514: Fix event generation for "DSP Voice Wake Up" control
b8ce58ab80 rtl818x: Prevent using not initialized queues
6f4a489d84 hugetlb: fix huge_pmd_unshare address update
73bdb2359d nodemask.h: fix compilation error with GCC12
6e071eaf50 iommu/msm: Fix an incorrect NULL check on list iterator
9caad70819 um: Fix out-of-bounds read in LDT setup
6cbe83680f um: chan_user: Fix winch_tramp() return value
3466e42652 mac80211: upgrade passive scan to active scan on DFS channels after beacon rx
cf465ecfe3 irqchip: irq-xtensa-mx: fix initial IRQ affinity
36bab24bb8 irqchip/armada-370-xp: Do not touch Performance Counter Overflow on A375, A38x, A39x
8858284dd7 RDMA/hfi1: Fix potential integer multiplication overflow errors
6462323626 Kconfig: Add option for asm goto w/ tied outputs to workaround clang-13 bug
532aa3f7a5 media: coda: Add more H264 levels for CODA960
adcea1c8ee media: coda: Fix reported H264 profile
f2c2ad538e mtd: cfi_cmdset_0002: Move and rename chip_check/chip_ready/chip_good_for_write
16e993ac7c md: fix an incorrect NULL check in md_reload_sb
d0bdc809f7 md: fix an incorrect NULL check in does_sb_need_changing
3623f833e1 drm/bridge: analogix_dp: Grab runtime PM reference for DP-AUX
8fa6eb03e3 drm/nouveau/clk: Fix an incorrect NULL check on list iterator
19323b3671 drm/etnaviv: check for reaped mapping in etnaviv_iommu_unmap_gem
c12984cdb0 drm/amdgpu/cs: make commands with 0 chunks illegal behaviour.
8e105178c2 scsi: ufs: qcom: Add a readl() to make sure ref_clk gets enabled
494685db00 scsi: dc395x: Fix a missing check on list iterator
82bf8e7271 ocfs2: dlmfs: fix error handling of user_dlm_destroy_lock
17ea634849 dlm: fix missing lkb refcount handling
49cd9eb7b9 dlm: fix plock invalid read
f160e7b4b0 mm, compaction: fast_find_migrateblock() should return pfn in the target zone
665602c837 PCI: qcom: Fix unbalanced PHY init on probe errors
c3919b10c4 PCI: qcom: Fix runtime PM imbalance on probe errors
c99306cf59 PCI/PM: Fix bridge_d3_blacklist[] Elo i2 overwrite of Gigabyte X299
c27f744cee tracing: Fix potential double free in create_var_ref()
742736dc9c ACPI: property: Release subnode properties with data nodes
e157c8f87e ext4: avoid cycles in directory h-tree
17034d45ec ext4: verify dir block before splitting it
73fd5b1928 ext4: fix bug_on in ext4_writepages
0ab308d72a ext4: fix warning in ext4_handle_inode_extension
eaecf7ebfd ext4: fix use-after-free in ext4_rename_dir_prepare
f36736fbd4 netfilter: nf_tables: disallow non-stateful expression in sets earlier
28a8060a0b bfq: Track whether bfq_group is still online
da9f3025d5 bfq: Update cgroup information before merging bio
31326bf551 bfq: Split shared queues on move between cgroups
b1cda6dd2c efi: Do not import certificates from UEFI Secure Boot for T2 Macs
440d345d02 fs-writeback: writeback_sb_inodes:Recalculate 'wrote' according skipped pages
e0dddab01f iwlwifi: mvm: fix assert 1F04 upon reconfig
265bec4779 wifi: mac80211: fix use-after-free in chanctx code
9259227605 f2fs: fix fallocate to use file_modified to update permissions consistently
1f926457c3 f2fs: don't need inode lock for system hidden quota
12ffc0044a f2fs: fix deadloop in foreground GC
54c116615c f2fs: fix to clear dirty inode in f2fs_evict_inode()
7361c9f2bd f2fs: fix to do sanity check on block address in f2fs_do_zero_range()
f8b3c3fcf3 f2fs: fix to avoid f2fs_bug_on() in dec_valid_node_count()
7f51f27345 perf jevents: Fix event syntax error caused by ExtSel
9eb684dc41 perf c2c: Use stdio interface if slang is not supported
e23eb2f43f iommu/amd: Increase timeout waiting for GA log enablement
db7ea8b261 dmaengine: stm32-mdma: remove GISR1 register
8db59df7f5 video: fbdev: clcdfb: Fix refcount leak in clcdfb_of_vram_setup
dcc00106c3 NFSv4/pNFS: Do not fail I/O when we fail to allocate the pNFS layout
3d216510f8 NFS: Don't report errors from nfs_pageio_complete() more than once
55f0fc32b2 NFS: Do not report flush errors in nfs_write_end()
59137943af NFS: Do not report EINTR/ERESTARTSYS as mapping errors
4826af9a07 i2c: at91: Initialize dma_buf in at91_twi_xfer()
d77a0f2842 i2c: at91: use dma safe buffers
e4db5f4b68 iommu/mediatek: Add list_del in mtk_iommu_remove
5e47a7add3 f2fs: fix dereference of stale list iterator after loop body
c8735252f9 Input: stmfts - do not leave device disabled in stmfts_input_open
addb192000 RDMA/hfi1: Prevent use of lock before it is initialized
6d8b9f574b mailbox: forward the hrtimer if not queued and under a lock
49c1e32e7b mfd: davinci_voicecodec: Fix possible null-ptr-deref davinci_vc_probe()
bcb6c4c5eb powerpc/fsl_rio: Fix refcount leak in fsl_rio_setup
2631fe5b53 macintosh: via-pmu and via-cuda need RTC_LIB
bc21634ce4 powerpc/perf: Fix the threshold compare group constraint for power9
cf0b52858f powerpc/64: Only WARN if __pa()/__va() called with bad addresses
bbc2b0ce60 Input: sparcspkr - fix refcount leak in bbc_beep_probe
6d7b2cf5c7 crypto: cryptd - Protect per-CPU resource by disabling BH.
3219ac364a tty: fix deadlock caused by calling printk() under tty_port->lock
ded067f24b PCI: imx6: Fix PERST# start-up sequence
0b35a685d9 ipc/mqueue: use get_tree_nodev() in mqueue_get_tree()
203537caad proc: fix dentry/inode overinstantiating under /proc/${pid}/net
6cdb6582b5 powerpc/4xx/cpm: Fix return value of __setup() handler
337eef19aa powerpc/idle: Fix return value of __setup() handler
1d83f30421 powerpc/8xx: export 'cpm_setbrg' for modules
662b70a45b dax: fix cache flush on PMD-mapped pages
386e69e068 drivers/base/node.c: fix compaction sysfs file leak
d1f908bd01 pinctrl: mvebu: Fix irq_of_parse_and_map() return value
9282496aac nvdimm: Allow overwrite in the presence of disabled dimms
b0e4bafac8 firmware: arm_scmi: Fix list protocols enumeration in the base protocol
ffd3bed66b scsi: fcoe: Fix Wstringop-overflow warnings in fcoe_wwn_from_mac()
829ea47487 mfd: ipaq-micro: Fix error check return value of platform_get_irq()
8c4eeab726 powerpc/fadump: fix PT_LOAD segment for boot memory area
bbf58e9742 arm: mediatek: select arch timer for mt7629
e7a0d0c280 crypto: marvell/cesa - ECB does not IV
de65c32ace misc: ocxl: fix possible double free in ocxl_file_register_afu
7f287d0c70 ARM: dts: bcm2835-rpi-b: Fix GPIO line names
3a37022d48 ARM: dts: bcm2837-rpi-3-b-plus: Fix GPIO line name of power LED
fd1c098b3b ARM: dts: bcm2837-rpi-cm3-io3: Fix GPIO line names for SMPS I2C
e0bf7f0844 ARM: dts: bcm2835-rpi-zero-w: Fix GPIO line name for Wifi/BT
e4594ca90b can: xilinx_can: mark bit timing constants as const
6077a1e637 KVM: nVMX: Leave most VM-Exit info fields unmodified on failed VM-Entry
9cccb3f6ed PCI: rockchip: Fix find_first_zero_bit() limit
f063429ac3 PCI: cadence: Fix find_first_zero_bit() limit
5543752a48 soc: qcom: smsm: Fix missing of_node_put() in smsm_parse_ipc
6695755216 soc: qcom: smp2p: Fix missing of_node_put() in smp2p_parse_ipc
56b8d748ec ARM: dts: suniv: F1C100: fix watchdog compatible
754ef324b7 arm64: dts: rockchip: Move drive-impedance-ohm to emmc phy on rk3399
60546c0b4b net/smc: postpone sk_refcnt increment in connect()
91121ee574 rxrpc: Fix decision on when to generate an IDLE ACK
d7b16ee15f rxrpc: Don't let ack.previousPacket regress
2fd958ae29 rxrpc: Fix overlapping ACK accounting
5aa14dafd2 rxrpc: Don't try to resend the request if we're receiving the reply
91b34bf040 rxrpc: Fix listen() setting the bar too high for the prealloc rings
0bfaff00d1 NFC: hci: fix sleep in atomic context bugs in nfc_hci_hcp_message_tx
9934025c4d ASoC: wm2000: fix missing clk_disable_unprepare() on error in wm2000_anc_transition()
b3461ccaa5 thermal/drivers/broadcom: Fix potential NULL dereference in sr_thermal_probe
449374565f drm: msm: fix possible memory leak in mdp5_crtc_cursor_set()
6832e36f15 drm/msm/a6xx: Fix refcount leak in a6xx_gpu_init
48d331a03b ext4: reject the 'commit' option on ext2 filesystems
3dc0323755 media: ov7670: remove ov7670_power_off from ov7670_remove
dc794fa2b3 sctp: read sk->sk_bound_dev_if once in sctp_rcv()
d43a87d660 m68k: math-emu: Fix dependencies of math emulation support
6f55fac0af Bluetooth: fix dangling sco_conn and use-after-free in sco_sock_timeout
c3c8c7e409 media: vsp1: Fix offset calculation for plane cropping
1310fc3538 media: pvrusb2: fix array-index-out-of-bounds in pvr2_i2c_core_init
83345b5365 media: exynos4-is: Change clk_disable to clk_disable_unprepare
b87d3a043b media: st-delta: Fix PM disable depth imbalance in delta_probe
12480f7578 media: aspeed: Fix an error handling path in aspeed_video_probe()
d2b1dc3a04 scripts/faddr2line: Fix overlapping text section failures
0be5d9da57 regulator: pfuze100: Fix refcount leak in pfuze_parse_regulators_dt
18b907ff0a ASoC: mxs-saif: Fix refcount leak in mxs_saif_probe
96fc3da618 ASoC: fsl: Fix refcount leak in imx_sgtl5000_probe
ddb1a77f94 perf/amd/ibs: Use interrupt regs ip for stack unwinding
f2e2e934d2 Revert "cpufreq: Fix possible race in cpufreq online error path"
1253811c71 iomap: iomap_write_failed fix
6b8291e574 media: uvcvideo: Fix missing check to determine if element is found in list
ab888b1a9a drm/msm: return an error pointer in msm_gem_prime_get_sg_table()
22d8424913 drm/msm/mdp5: Return error code in mdp5_mixer_release when deadlock is detected
b2aa2c4efe drm/msm/mdp5: Return error code in mdp5_pipe_release when deadlock is detected
cd4cfd99ec regulator: core: Fix enable_count imbalance with EXCLUSIVE_GET
db5a21f2dd x86/mm: Cleanup the control_va_addr_alignment() __setup handler
d2476a1fc5 irqchip/aspeed-i2c-ic: Fix irq_of_parse_and_map() return value
b97eb924a2 irqchip/exiu: Fix acknowledgment of edge triggered interrupts
9777de28cf x86: Fix return value of __setup handlers
ee3901d7c7 virtio_blk: fix the discard_granularity and discard_alignment queue limits
a9b4599665 drm/rockchip: vop: fix possible null-ptr-deref in vop_bind()
35d9a84e3b drm/msm/hdmi: fix error check return value of irq_of_parse_and_map()
2b3ed7547b drm/msm/hdmi: check return value after calling platform_get_resource_byname()
11709592b3 drm/msm/dsi: fix error checks and return values for DSI xmit functions
ef10d0c68e drm/msm/disp/dpu1: set vbif hw config to NULL to avoid use after memory free during pm runtime resume
db681127e9 perf tools: Add missing headers needed by util/data.h
31de06ef06 ASoC: rk3328: fix disabling mclk on pclk probe failure
ed8d5cf1dc x86/speculation: Add missing prototype for unpriv_ebpf_notify()
1d0c4bc628 x86/pm: Fix false positive kmemleak report in msr_build_context()
b889619eba scsi: ufs: core: Exclude UECxx from SFR dump list
e120d31d04 of: overlay: do not break notify on NOTIFY_{OK|STOP}
b0be017bc5 fsnotify: fix wrong lockdep annotations
60d159e0d0 inotify: show inotify mask flags in proc fdinfo
2326d398cc ath9k_htc: fix potential out of bounds access with invalid rxstatus->rs_keyix
cd1f386120 cpufreq: Fix possible race in cpufreq online error path
e7f0fd6f25 spi: img-spfi: Fix pm_runtime_get_sync() error checking
735b57a960 sched/fair: Fix cfs_rq_clock_pelt() for throttled cfs_rq
55fddbb1e2 drm/bridge: Fix error handling in analogix_dp_probe
f1d4f19a79 HID: elan: Fix potential double free in elan_input_configured
75a89bc1ba HID: hid-led: fix maximum brightness for Dream Cheeky
3caa2d7943 drbd: fix duplicate array initializer
65065f96d5 efi: Add missing prototype for efi_capsule_setup_info
fbf9c4c714 NFC: NULL out the dev->rfkill to prevent UAF
2c59535b6b spi: spi-ti-qspi: Fix return value handling of wait_for_completion_timeout
fa0d7ba25a drm: mali-dp: potential dereference of null pointer
797f8ee35f drm/komeda: Fix an undefined behavior bug in komeda_plane_add()
1a994f1f18 nl80211: show SSID for P2P_GO interfaces
93c0f9d78d bpf: Fix excessive memory allocation in stack_map_alloc()
c398c2149b drm/vc4: txp: Force alpha to be 0xff if it's disabled
8a60b54e41 drm/vc4: txp: Don't set TXP_VSTART_AT_EOF
a0c890c0ae drm/mediatek: Fix mtk_cec_mask()
ea8b2ecc92 x86/delay: Fix the wrong asm constraint in delay_loop()
c71494f5f2 ASoC: mediatek: Fix missing of_node_put in mt2701_wm8960_machine_probe
23f340ed90 ASoC: mediatek: Fix error handling in mt8173_max98090_dev_probe
e92b927fff drm/bridge: adv7511: clean up CEC adapter when probe fails
224e1eef03 drm/edid: fix invalid EDID extension block filtering
6577348668 ath9k: fix ar9003_get_eepmisc
ebede9aadf drm: fix EDID struct for old ARM OABI format
e60ad83f64 RDMA/hfi1: Prevent panic when SDMA is disabled
cb4f2dc513 powerpc/iommu: Add missing of_node_put in iommu_init_early_dart
6557555a86 macintosh/via-pmu: Fix build failure when CONFIG_INPUT is disabled
793b82d1c4 powerpc/powernv: fix missing of_node_put in uv_init()
537a317e5f powerpc/xics: fix refcount leak in icp_opal_init()
a910e96131 tracing: incorrect isolate_mote_t cast in mm_vmscan_lru_isolate
c9a81f9ed6 PCI: Avoid pci_dev_lock() AB/BA deadlock with sriov_numvfs_store()
e109058165 ARM: hisi: Add missing of_node_put after of_find_compatible_node
2f46a955b6 ARM: dts: exynos: add atmel,24c128 fallback to Samsung EEPROM
fcd1999ba9 ARM: versatile: Add missing of_node_put in dcscb_init
fd48cf8f97 fat: add ratelimit to fat*_ent_bread()
60ce637c19 powerpc/fadump: Fix fadump to work with a different endian capture kernel
41c7096286 ARM: OMAP1: clock: Fix UART rate reporting algorithm
e54fd01178 fs: jfs: fix possible NULL pointer dereference in dbFree()
a0180e324a PM / devfreq: rk3399_dmc: Disable edev on remove()
1995a60be7 ARM: dts: ox820: align interrupt controller node name with dtschema
58e55f4f5a IB/rdmavt: add missing locks in rvt_ruc_loopback
56fd9dcfe1 selftests/bpf: fix btf_dump/btf_dump due to recent clang change
063d945795 eth: tg3: silence the GCC 12 array-bounds warning
88d730463e rxrpc: Return an error to sendmsg if call failed
1ec0bc72f5 hwmon: Make chip parameter for with_info API mandatory
a7a41dd473 ASoC: max98357a: remove dependency on GPIOLIB
3cf43978ff media: exynos4-is: Fix compile warning
1e5fbfc2a6 net: phy: micrel: Allow probing without .driver_data
9d1764b926 nbd: Fix hung on disconnect request if socket is closed before
abe7554da6 ASoC: rt5645: Fix errorenous cleanup order
f767296626 nvme-pci: fix a NULL pointer dereference in nvme_alloc_admin_tags
69edf28d2c openrisc: start CPU timer early in boot
67fb494388 media: cec-adap.c: fix is_configuring state
4172a34ef9 media: coda: limit frame interval enumeration to supported encoder frame sizes
8f2a5721cd rtlwifi: Use pr_warn instead of WARN_ONCE
2d966c94ad ipmi: Fix pr_fmt to avoid compilation issues
2064a1eab2 ipmi:ssif: Check for NULL msg when handling events and messages
17cfc94558 ACPI: PM: Block ASUS B1400CEAE from suspend to idle by default
5a71f14a9b dma-debug: change allocation mode from GFP_NOWAIT to GFP_ATIOMIC
6583d0d6ad spi: stm32-qspi: Fix wait_cmd timeout in APM mode
1651a95517 s390/preempt: disable __preempt_count_add() optimization for PROFILE_ALL_BRANCHES
890b16b470 ASoC: tscs454: Add endianness flag in snd_soc_component_driver
00771de7cc HID: bigben: fix slab-out-of-bounds Write in bigben_probe
0d7074792b drm/amdgpu/ucode: Remove firmware load type check in amdgpu_ucode_free_bo
2317f3bfda mlxsw: spectrum_dcb: Do not warn about priority changes
121f56a9a8 ASoC: dapm: Don't fold register value changes into notifications
430af81135 net/mlx5: fs, delete the FTE when there are no rules attached to it
f857855a8a ipv6: Don't send rs packets to the interface of ARPHRD_TUNNEL
b507f067e9 drm: msm: fix error check return value of irq_of_parse_and_map()
efd183d988 arm64: compat: Do not treat syscall number as ESR_ELx for a bad syscall
a610cfe56c drm/amd/pm: fix the compile warning
1e29d829ad drm/plane: Move range check for format_count earlier
e1599ced6b scsi: megaraid: Fix error check return value of register_chrdev()
7923f95997 mmc: jz4740: Apply DMA engine limits to maximum segment size
0959aa00f9 md/bitmap: don't set sb values if can't pass sanity check
222292930c media: cx25821: Fix the warning when removing the module
fa636e9ee4 media: pci: cx23885: Fix the error handling in cx23885_initdev()
0ac84ab507 media: venus: hfi: avoid null dereference in deinit
de16cdf0b7 ath9k: fix QCA9561 PA bias level
af832028af drm/amd/pm: fix double free in si_parse_power_table()
7bd0ac1e23 tools/power turbostat: fix ICX DRAM power numbers
6266ab1f31 spi: spi-rspi: Remove setting {src,dst}_{addr,addr_width} based on DMA direction
f68bed124c ALSA: jack: Access input_dev under mutex
aea748501d drm/komeda: return early if drm_universal_plane_init() fails.
8ded0af90e ACPICA: Avoid cache flush inside virtual machines
c7b41fd76c fbcon: Consistently protect deferred_takeover with console_lock()
4460066eb2 ipv6: fix locking issues with loops over idev->addr_list
8fb1b9beb0 ipw2x00: Fix potential NULL dereference in libipw_xmit()
303380919d b43: Fix assigning negative value to unsigned variable
60d515fd87 b43legacy: Fix assigning negative value to unsigned variable
92225d3c22 mwifiex: add mutex lock for call in mwifiex_dfs_chan_sw_work_queue
f85cb059fa drm/virtio: fix NULL pointer dereference in virtio_gpu_conn_get_modes
670f5e40d7 btrfs: repair super block num_devices automatically
622ced791e btrfs: add "0x" prefix for unsupported optional features
0ca5112047 ptrace: Reimplement PTRACE_KILL by always sending SIGKILL
f5faa24137 ptrace/xtensa: Replace PT_SINGLESTEP with TIF_SINGLESTEP
e10356eae1 ptrace/um: Replace PT_DTRACE with TIF_SINGLESTEP
00c93ce266 perf/x86/intel: Fix event constraints for ICL
1b767500d1 usb: core: hcd: Add support for deferring roothub registration
1147908763 USB: new quirk for Dell Gen 2 devices
7c5a52dd4d USB: serial: option: add Quectel BG95 modem
6b3ecb2d92 ALSA: hda/realtek - Fix microphone noise on ASUS TUF B550M-PLUS
1c6cfb9e8a binfmt_flat: do not stop relocating GOT entries prematurely on riscv

ABI .xml file was updated to add a new function that is now tracked:

1 Added function:

  [A] 'function void refcount_warn_saturate(refcount_struct*, refcount_saturation_type)'

Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: I93ce4a950729a57206f775a11adeec35b7b30fca
2022-09-27 13:18:23 +02:00
Tadeusz Struk
297aa83408 ANDROID: incfs: Add check for ATTR_KILL_SUID and ATTR_MODE in incfs_setattr
Add an explicite check for ATTR_KILL_SUID and ATTR_MODE in incfs_setattr.
Both of these attributes can not be set at the same time, otherwise
notify_change() function will check it and invoke BUG(), crashing
the system.

Bug: 243394930

Signed-off-by: Tadeusz Struk <tadeusz.struk@linaro.org>
Change-Id: I91080d68efbd62f1441e20a5c02feef3d1b06e4e
2022-09-19 15:14:36 -07:00
Greg Kroah-Hartman
ab6cb81d83 This is the 5.4.210 stable release
-----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCAAdFiEEZH8oZUiU471FcZm+ONu9yGCSaT4FAmL04LcACgkQONu9yGCS
 aT4CmxAAmBazgXFTCRsdk5u5V7mhFwB7JJbixykPaSdkLw4sB8RFG2FEtOEp3eMl
 NbXywQnEnoCv8/3MucEuypubPfT3DqRYTkUH8xTd14dmHPaqJ3PSY6dgayFrl987
 jiRL3Sep1FpIpPZ2JZKcLH/suRsg1g61nE9F6WoVy97z4J0xB6o40Ft3ZE0KfIbI
 Mw3hAGhLDhXCBVTyCVneSDIZVviBFeCkqJ7WZTFFAYml9r2gc2enJXWGUDkP7Hhz
 G/TfnfnqChTScWTt5MfYonZ1NutIrmKz2O6VA1SvpMgQtJX7y/Vc10Wpb3T0oZ5j
 iIsvnS1Hv40/lnnqFDkprWWQVGScbt/1DYXnFUUGkZ94dC3qvVG/K8XJr+XRwHLD
 xOeCYmEVaxHK9C00fNG/37xESbgolcsr/sSwO9qizBvWij+FYSsufUsDo5UgJ6Jb
 elxlXwdtTllkcPuDMX8YpoX3PdHwP+wu4FwDd2R7nmSJa3j19VpWn+GB3yjc+9Wo
 nkcNM4MqDCLk1Wx5xiQSoPkzwv9du6JlSeifyetXg1/VDIcSrdLzyuUJMvAlfYUH
 XULnFZhVdaewKT2xxqXfQ5+/6sTv7QzP527GJotW/kCMQ+DQtACvv6V1+CJ+NSzE
 nHUiqXVhvjZPg6PRPZTVLcoz4IFSG4RRPTbG2oVlPAnHCBu6/1g=
 =xh6Q
 -----END PGP SIGNATURE-----

Merge 5.4.210 into android11-5.4-lts

Changes in 5.4.210
	thermal: Fix NULL pointer dereferences in of_thermal_ functions
	ACPI: video: Force backlight native for some TongFang devices
	ACPI: video: Shortening quirk list by identifying Clevo by board_name only
	ACPI: APEI: Better fix to avoid spamming the console with old error logs
	bpf: Verifer, adjust_scalar_min_max_vals to always call update_reg_bounds()
	selftests/bpf: Extend verifier and bpf_sock tests for dst_port loads
	bpf: Test_verifier, #70 error message updates for 32-bit right shift
	selftests/bpf: Fix test_align verifier log patterns
	selftests/bpf: Fix "dubious pointer arithmetic" test
	KVM: Don't null dereference ops->destroy
	selftests: KVM: Handle compiler optimizations in ucall
	media: v4l2-mem2mem: Apply DST_QUEUE_OFF_BASE on MMAP buffers across ioctls
	macintosh/adb: fix oob read in do_adb_query() function
	x86/speculation: Add RSB VM Exit protections
	x86/speculation: Add LFENCE to RSB fill sequence
	Linux 5.4.210

Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: I64982119920496f2849c00005fbc654179daa21f
2022-08-11 14:59:05 +02:00
Greg Kroah-Hartman
de0cd3ea70 Linux 5.4.210
Link: https://lore.kernel.org/r/20220809175510.312431319@linuxfoundation.org
Tested-by: Florian Fainelli <f.fainelli@gmail.com>
Tested-by: Linux Kernel Functional Testing <lkft@linaro.org>
Tested-by: Sudip Mukherjee <sudip.mukherjee@codethink.co.uk>
Tested-by: Guenter Roeck <linux@roeck-us.net>
Tested-by: Jon Hunter <jonathanh@nvidia.com>
Tested-by: Shuah Khan <skhan@linuxfoundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-08-11 12:57:53 +02:00
Pawan Gupta
b58882c69f x86/speculation: Add LFENCE to RSB fill sequence
commit ba6e31af2be96c4d0536f2152ed6f7b6c11bca47 upstream.

RSB fill sequence does not have any protection for miss-prediction of
conditional branch at the end of the sequence. CPU can speculatively
execute code immediately after the sequence, while RSB filling hasn't
completed yet.

  #define __FILL_RETURN_BUFFER(reg, nr, sp)	\
  	mov	$(nr/2), reg;			\
  771:						\
  	call	772f;				\
  773:	/* speculation trap */			\
  	pause;					\
  	lfence;					\
  	jmp	773b;				\
  772:						\
  	call	774f;				\
  775:	/* speculation trap */			\
  	pause;					\
  	lfence;					\
  	jmp	775b;				\
  774:						\
  	dec	reg;				\
  	jnz	771b;  <----- CPU can miss-predict here.				\
  	add	$(BITS_PER_LONG/8) * nr, sp;

Before RSB is filled, RETs that come in program order after this macro
can be executed speculatively, making them vulnerable to RSB-based
attacks.

Mitigate it by adding an LFENCE after the conditional branch to prevent
speculation while RSB is being filled.

Suggested-by: Andrew Cooper <andrew.cooper3@citrix.com>
Signed-off-by: Pawan Gupta <pawan.kumar.gupta@linux.intel.com>
Signed-off-by: Borislav Petkov <bp@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-08-11 12:57:53 +02:00
Daniel Sneddon
f2f41ef035 x86/speculation: Add RSB VM Exit protections
commit 2b1299322016731d56807aa49254a5ea3080b6b3 upstream.

tl;dr: The Enhanced IBRS mitigation for Spectre v2 does not work as
documented for RET instructions after VM exits. Mitigate it with a new
one-entry RSB stuffing mechanism and a new LFENCE.

== Background ==

Indirect Branch Restricted Speculation (IBRS) was designed to help
mitigate Branch Target Injection and Speculative Store Bypass, i.e.
Spectre, attacks. IBRS prevents software run in less privileged modes
from affecting branch prediction in more privileged modes. IBRS requires
the MSR to be written on every privilege level change.

To overcome some of the performance issues of IBRS, Enhanced IBRS was
introduced.  eIBRS is an "always on" IBRS, in other words, just turn
it on once instead of writing the MSR on every privilege level change.
When eIBRS is enabled, more privileged modes should be protected from
less privileged modes, including protecting VMMs from guests.

== Problem ==

Here's a simplification of how guests are run on Linux' KVM:

void run_kvm_guest(void)
{
	// Prepare to run guest
	VMRESUME();
	// Clean up after guest runs
}

The execution flow for that would look something like this to the
processor:

1. Host-side: call run_kvm_guest()
2. Host-side: VMRESUME
3. Guest runs, does "CALL guest_function"
4. VM exit, host runs again
5. Host might make some "cleanup" function calls
6. Host-side: RET from run_kvm_guest()

Now, when back on the host, there are a couple of possible scenarios of
post-guest activity the host needs to do before executing host code:

* on pre-eIBRS hardware (legacy IBRS, or nothing at all), the RSB is not
touched and Linux has to do a 32-entry stuffing.

* on eIBRS hardware, VM exit with IBRS enabled, or restoring the host
IBRS=1 shortly after VM exit, has a documented side effect of flushing
the RSB except in this PBRSB situation where the software needs to stuff
the last RSB entry "by hand".

IOW, with eIBRS supported, host RET instructions should no longer be
influenced by guest behavior after the host retires a single CALL
instruction.

However, if the RET instructions are "unbalanced" with CALLs after a VM
exit as is the RET in #6, it might speculatively use the address for the
instruction after the CALL in #3 as an RSB prediction. This is a problem
since the (untrusted) guest controls this address.

Balanced CALL/RET instruction pairs such as in step #5 are not affected.

== Solution ==

The PBRSB issue affects a wide variety of Intel processors which
support eIBRS. But not all of them need mitigation. Today,
X86_FEATURE_RETPOLINE triggers an RSB filling sequence that mitigates
PBRSB. Systems setting RETPOLINE need no further mitigation - i.e.,
eIBRS systems which enable retpoline explicitly.

However, such systems (X86_FEATURE_IBRS_ENHANCED) do not set RETPOLINE
and most of them need a new mitigation.

Therefore, introduce a new feature flag X86_FEATURE_RSB_VMEXIT_LITE
which triggers a lighter-weight PBRSB mitigation versus RSB Filling at
vmexit.

The lighter-weight mitigation performs a CALL instruction which is
immediately followed by a speculative execution barrier (INT3). This
steers speculative execution to the barrier -- just like a retpoline
-- which ensures that speculation can never reach an unbalanced RET.
Then, ensure this CALL is retired before continuing execution with an
LFENCE.

In other words, the window of exposure is opened at VM exit where RET
behavior is troublesome. While the window is open, force RSB predictions
sampling for RET targets to a dead end at the INT3. Close the window
with the LFENCE.

There is a subset of eIBRS systems which are not vulnerable to PBRSB.
Add these systems to the cpu_vuln_whitelist[] as NO_EIBRS_PBRSB.
Future systems that aren't vulnerable will set ARCH_CAP_PBRSB_NO.

  [ bp: Massage, incorporate review comments from Andy Cooper. ]
  [ Pawan: Update commit message to replace RSB_VMEXIT with RETPOLINE ]

Signed-off-by: Daniel Sneddon <daniel.sneddon@linux.intel.com>
Co-developed-by: Pawan Gupta <pawan.kumar.gupta@linux.intel.com>
Signed-off-by: Pawan Gupta <pawan.kumar.gupta@linux.intel.com>
Signed-off-by: Borislav Petkov <bp@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-08-11 12:57:53 +02:00
Ning Qiang
3a0ef79c6a macintosh/adb: fix oob read in do_adb_query() function
commit fd97e4ad6d3b0c9fce3bca8ea8e6969d9ce7423b upstream.

In do_adb_query() function of drivers/macintosh/adb.c, req->data is copied
form userland. The parameter "req->data[2]" is missing check, the array
size of adb_handler[] is 16, so adb_handler[req->data[2]].original_address and
adb_handler[req->data[2]].handler_id will lead to oob read.

Cc: stable <stable@kernel.org>
Signed-off-by: Ning Qiang <sohu0106@126.com>
Reviewed-by: Kees Cook <keescook@chromium.org>
Reviewed-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Acked-by: Benjamin Herrenschmidt <benh@kernel.crashing.org>
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
Link: https://lore.kernel.org/r/20220713153734.2248-1-sohu0106@126.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-08-11 12:57:53 +02:00
Chen-Yu Tsai
54e1abbe85 media: v4l2-mem2mem: Apply DST_QUEUE_OFF_BASE on MMAP buffers across ioctls
commit 8310ca94075e784bbb06593cd6c068ee6b6e4ca6 upstream.

DST_QUEUE_OFF_BASE is applied to offset/mem_offset on MMAP capture buffers
only for the VIDIOC_QUERYBUF ioctl, while the userspace fields (including
offset/mem_offset) are filled in for VIDIOC_{QUERY,PREPARE,Q,DQ}BUF
ioctls. This leads to differences in the values presented to userspace.
If userspace attempts to mmap the capture buffer directly using values
from DQBUF, it will fail.

Move the code that applies the magic offset into a helper, and call
that helper from all four ioctl entry points.

[hverkuil: drop unnecessary '= 0' in v4l2_m2m_querybuf() for ret]

Fixes: 7f98639def ("V4L/DVB: add memory-to-memory device helper framework for videobuf")
Fixes: 908a0d7c58 ("[media] v4l: mem2mem: port to videobuf2")
Signed-off-by: Chen-Yu Tsai <wenst@chromium.org>
Signed-off-by: Hans Verkuil <hverkuil-cisco@xs4all.nl>
Signed-off-by: Mauro Carvalho Chehab <mchehab@kernel.org>
[OP: backport to 5.4: adjusted return logic in v4l2_m2m_qbuf() to match the
logic in the original commit: call v4l2_m2m_adjust_mem_offset() only if !ret
and before the v4l2_m2m_try_schedule() call]
Signed-off-by: Ovidiu Panait <ovidiu.panait@windriver.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-08-11 12:57:52 +02:00
Raghavendra Rao Ananta
17c2356e46 selftests: KVM: Handle compiler optimizations in ucall
[ Upstream commit 9e2f6498efbbc880d7caa7935839e682b64fe5a6 ]

The selftests, when built with newer versions of clang, is found
to have over optimized guests' ucall() function, and eliminating
the stores for uc.cmd (perhaps due to no immediate readers). This
resulted in the userspace side always reading a value of '0', and
causing multiple test failures.

As a result, prevent the compiler from optimizing the stores in
ucall() with WRITE_ONCE().

Suggested-by: Ricardo Koller <ricarkol@google.com>
Suggested-by: Reiji Watanabe <reijiw@google.com>
Signed-off-by: Raghavendra Rao Ananta <rananta@google.com>
Message-Id: <20220615185706.1099208-1-rananta@google.com>
Reviewed-by: Andrew Jones <drjones@redhat.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2022-08-11 12:57:52 +02:00
Alexey Kardashevskiy
170465715a KVM: Don't null dereference ops->destroy
[ Upstream commit e8bc2427018826e02add7b0ed0fc625a60390ae5 ]

A KVM device cleanup happens in either of two callbacks:
1) destroy() which is called when the VM is being destroyed;
2) release() which is called when a device fd is closed.

Most KVM devices use 1) but Book3s's interrupt controller KVM devices
(XICS, XIVE, XIVE-native) use 2) as they need to close and reopen during
the machine execution. The error handling in kvm_ioctl_create_device()
assumes destroy() is always defined which leads to NULL dereference as
discovered by Syzkaller.

This adds a checks for destroy!=NULL and adds a missing release().

This is not changing kvm_destroy_devices() as devices with defined
release() should have been removed from the KVM devices list by then.

Suggested-by: Paolo Bonzini <pbonzini@redhat.com>
Signed-off-by: Alexey Kardashevskiy <aik@ozlabs.ru>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2022-08-11 12:57:52 +02:00
Jean-Philippe Brucker
6098562ed9 selftests/bpf: Fix "dubious pointer arithmetic" test
commit 3615bdf6d9b19db12b1589861609b4f1c6a8d303 upstream.

The verifier trace changed following a bugfix. After checking the 64-bit
sign, only the upper bit mask is known, not bit 31. Update the test
accordingly.

Signed-off-by: Jean-Philippe Brucker <jean-philippe@linaro.org>
Acked-by: John Fastabend <john.fastabend@gmail.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Ovidiu Panait <ovidiu.panait@windriver.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-08-11 12:57:52 +02:00
Stanislav Fomichev
6a9b3f0f3b selftests/bpf: Fix test_align verifier log patterns
commit 5366d2269139ba8eb6a906d73a0819947e3e4e0a upstream.

Commit 294f2fc6da27 ("bpf: Verifer, adjust_scalar_min_max_vals to always
call update_reg_bounds()") changed the way verifier logs some of its state,
adjust the test_align accordingly. Where possible, I tried to not copy-paste
the entire log line and resorted to dropping the last closing brace instead.

Fixes: 294f2fc6da27 ("bpf: Verifer, adjust_scalar_min_max_vals to always call update_reg_bounds()")
Signed-off-by: Stanislav Fomichev <sdf@google.com>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Link: https://lore.kernel.org/bpf/20200515194904.229296-1-sdf@google.com
Signed-off-by: Ovidiu Panait <ovidiu.panait@windriver.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-08-11 12:57:52 +02:00
John Fastabend
9d6f67365d bpf: Test_verifier, #70 error message updates for 32-bit right shift
commit aa131ed44ae1d76637f0dbec33cfcf9115af9bc3 upstream.

After changes to add update_reg_bounds after ALU ops and adding ALU32
bounds tracking the error message is changed in the 32-bit right shift
tests.

Test "#70/u bounds check after 32-bit right shift with 64-bit input FAIL"
now fails with,

Unexpected error message!
	EXP: R0 invalid mem access
	RES: func#0 @0

7: (b7) r1 = 2
8: R0_w=map_value(id=0,off=0,ks=8,vs=8,imm=0) R1_w=invP2 R10=fp0 fp-8_w=mmmmmmmm
8: (67) r1 <<= 31
9: R0_w=map_value(id=0,off=0,ks=8,vs=8,imm=0) R1_w=invP4294967296 R10=fp0 fp-8_w=mmmmmmmm
9: (74) w1 >>= 31
10: R0_w=map_value(id=0,off=0,ks=8,vs=8,imm=0) R1_w=invP0 R10=fp0 fp-8_w=mmmmmmmm
10: (14) w1 -= 2
11: R0_w=map_value(id=0,off=0,ks=8,vs=8,imm=0) R1_w=invP4294967294 R10=fp0 fp-8_w=mmmmmmmm
11: (0f) r0 += r1
math between map_value pointer and 4294967294 is not allowed

And test "#70/p bounds check after 32-bit right shift with 64-bit input
FAIL" now fails with,

Unexpected error message!
	EXP: R0 invalid mem access
	RES: func#0 @0

7: (b7) r1 = 2
8: R0_w=map_value(id=0,off=0,ks=8,vs=8,imm=0) R1_w=inv2 R10=fp0 fp-8_w=mmmmmmmm
8: (67) r1 <<= 31
9: R0_w=map_value(id=0,off=0,ks=8,vs=8,imm=0) R1_w=inv4294967296 R10=fp0 fp-8_w=mmmmmmmm
9: (74) w1 >>= 31
10: R0_w=map_value(id=0,off=0,ks=8,vs=8,imm=0) R1_w=inv0 R10=fp0 fp-8_w=mmmmmmmm
10: (14) w1 -= 2
11: R0_w=map_value(id=0,off=0,ks=8,vs=8,imm=0) R1_w=inv4294967294 R10=fp0 fp-8_w=mmmmmmmm
11: (0f) r0 += r1
last_idx 11 first_idx 0
regs=2 stack=0 before 10: (14) w1 -= 2
regs=2 stack=0 before 9: (74) w1 >>= 31
regs=2 stack=0 before 8: (67) r1 <<= 31
regs=2 stack=0 before 7: (b7) r1 = 2
math between map_value pointer and 4294967294 is not allowed

Before this series we did not trip the "math between map_value pointer..."
error because check_reg_sane_offset is never called in
adjust_ptr_min_max_vals(). Instead we have a register state that looks
like this at line 11*,

11: R0_w=map_value(id=0,off=0,ks=8,vs=8,
                   smin_value=0,smax_value=0,
                   umin_value=0,umax_value=0,
                   var_off=(0x0; 0x0))
    R1_w=invP(id=0,
              smin_value=0,smax_value=4294967295,
              umin_value=0,umax_value=4294967295,
              var_off=(0xfffffffe; 0x0))
    R10=fp(id=0,off=0,
           smin_value=0,smax_value=0,
           umin_value=0,umax_value=0,
           var_off=(0x0; 0x0)) fp-8_w=mmmmmmmm
11: (0f) r0 += r1

In R1 'smin_val != smax_val' yet we have a tnum_const as seen
by 'var_off(0xfffffffe; 0x0))' with a 0x0 mask. So we hit this check
in adjust_ptr_min_max_vals()

 if ((known && (smin_val != smax_val || umin_val != umax_val)) ||
      smin_val > smax_val || umin_val > umax_val) {
       /* Taint dst register if offset had invalid bounds derived from
        * e.g. dead branches.
        */
       __mark_reg_unknown(env, dst_reg);
       return 0;
 }

So we don't throw an error here and instead only throw an error
later in the verification when the memory access is made.

The root cause in verifier without alu32 bounds tracking is having
'umin_value = 0' and 'umax_value = U64_MAX' from BPF_SUB which we set
when 'umin_value < umax_val' here,

 if (dst_reg->umin_value < umax_val) {
    /* Overflow possible, we know nothing */
    dst_reg->umin_value = 0;
    dst_reg->umax_value = U64_MAX;
 } else { ...}

Later in adjust_calar_min_max_vals we previously did a
coerce_reg_to_size() which will clamp the U64_MAX to U32_MAX by
truncating to 32bits. But either way without a call to update_reg_bounds
the less precise bounds tracking will fall out of the alu op
verification.

After latest changes we now exit adjust_scalar_min_max_vals with the
more precise umin value, due to zero extension propogating bounds from
alu32 bounds into alu64 bounds and then calling update_reg_bounds.
This then causes the verifier to trigger an earlier error and we get
the error in the output above.

This patch updates tests to reflect new error message.

* I have a local patch to print entire verifier state regardless if we
 believe it is a constant so we can get a full picture of the state.
 Usually if tnum_is_const() then bounds are also smin=smax, etc. but
 this is not always true and is a bit subtle. Being able to see these
 states helps understand dataflow imo. Let me know if we want something
 similar upstream.

Signed-off-by: John Fastabend <john.fastabend@gmail.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://lore.kernel.org/bpf/158507161475.15666.3061518385241144063.stgit@john-Precision-5820-Tower
Signed-off-by: Ovidiu Panait <ovidiu.panait@windriver.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-08-11 12:57:51 +02:00
Jakub Sitnicki
751f05bc6f selftests/bpf: Extend verifier and bpf_sock tests for dst_port loads
commit 8f50f16ff39dd4e2d43d1548ca66925652f8aff7 upstream.

Add coverage to the verifier tests and tests for reading bpf_sock fields to
ensure that 32-bit, 16-bit, and 8-bit loads from dst_port field are allowed
only at intended offsets and produce expected values.

While 16-bit and 8-bit access to dst_port field is straight-forward, 32-bit
wide loads need be allowed and produce a zero-padded 16-bit value for
backward compatibility.

Signed-off-by: Jakub Sitnicki <jakub@cloudflare.com>
Link: https://lore.kernel.org/r/20220130115518.213259-3-jakub@cloudflare.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
[OP: backport to 5.4: cherry-pick verifier changes only]
Signed-off-by: Ovidiu Panait <ovidiu.panait@windriver.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-08-11 12:57:51 +02:00
John Fastabend
7c1134c7da bpf: Verifer, adjust_scalar_min_max_vals to always call update_reg_bounds()
commit 294f2fc6da27620a506e6c050241655459ccd6bd upstream.

Currently, for all op verification we call __red_deduce_bounds() and
__red_bound_offset() but we only call __update_reg_bounds() in bitwise
ops. However, we could benefit from calling __update_reg_bounds() in
BPF_ADD, BPF_SUB, and BPF_MUL cases as well.

For example, a register with state 'R1_w=invP0' when we subtract from
it,

 w1 -= 2

Before coerce we will now have an smin_value=S64_MIN, smax_value=U64_MAX
and unsigned bounds umin_value=0, umax_value=U64_MAX. These will then
be clamped to S32_MIN, U32_MAX values by coerce in the case of alu32 op
as done in above example. However tnum will be a constant because the
ALU op is done on a constant.

Without update_reg_bounds() we have a scenario where tnum is a const
but our unsigned bounds do not reflect this. By calling update_reg_bounds
after coerce to 32bit we further refine the umin_value to U64_MAX in the
alu64 case or U32_MAX in the alu32 case above.

Signed-off-by: John Fastabend <john.fastabend@gmail.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://lore.kernel.org/bpf/158507151689.15666.566796274289413203.stgit@john-Precision-5820-Tower
Signed-off-by: Ovidiu Panait <ovidiu.panait@windriver.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-08-11 12:57:51 +02:00
Tony Luck
a8ba72bbed ACPI: APEI: Better fix to avoid spamming the console with old error logs
commit c3481b6b75b4797657838f44028fd28226ab48e0 upstream.

The fix in commit 3f8dec116210 ("ACPI/APEI: Limit printable size of BERT
table data") does not work as intended on systems where the BIOS has a
fixed size block of memory for the BERT table, relying on s/w to quit
when it finds a record with estatus->block_status == 0. On these systems
all errors are suppressed because the check:

	if (region_len < ACPI_BERT_PRINT_MAX_LEN)

always fails.

New scheme skips individual CPER records that are too large, and also
limits the total number of records that will be printed to 5.

Fixes: 3f8dec116210 ("ACPI/APEI: Limit printable size of BERT table data")
Cc: All applicable <stable@vger.kernel.org>
Signed-off-by: Tony Luck <tony.luck@intel.com>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-08-11 12:57:51 +02:00
Werner Sembach
fa829bd4af ACPI: video: Shortening quirk list by identifying Clevo by board_name only
commit f0341e67b3782603737f7788e71bd3530012a4f4 upstream.

Taking a recent change in the i8042 quirklist to this one: Clevo
board_names are somewhat unique, and if not: The generic Board_-/Sys_Vendor
string "Notebook" doesn't help much anyway. So identifying the devices just
by the board_name helps keeping the list significantly shorter and might
even hit more devices requiring the fix.

Signed-off-by: Werner Sembach <wse@tuxedocomputers.com>
Fixes: c844d22fe0c0 ("ACPI: video: Force backlight native for Clevo NL5xRU and NL5xNU")
Cc: All applicable <stable@vger.kernel.org>
Reviewed-by: Hans de Goede <hdegoede@redhat.com>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-08-11 12:57:50 +02:00
Werner Sembach
8ed6e5c5e2 ACPI: video: Force backlight native for some TongFang devices
commit c752089f7cf5b5800c6ace4cdd1a8351ee78a598 upstream.

The TongFang PF5PU1G, PF4NU1F, PF5NU1G, and PF5LUXG/TUXEDO BA15 Gen10,
Pulse 14/15 Gen1, and Pulse 15 Gen2 have the same problem as the Clevo
NL5xRU and NL5xNU/TUXEDO Aura 15 Gen1 and Gen2:
They have a working native and video interface. However the default
detection mechanism first registers the video interface before
unregistering it again and switching to the native interface during boot.
This results in a dangling SBIOS request for backlight change for some
reason, causing the backlight to switch to ~2% once per boot on the first
power cord connect or disconnect event. Setting the native interface
explicitly circumvents this buggy behaviour by avoiding the unregistering
process.

Signed-off-by: Werner Sembach <wse@tuxedocomputers.com>
Cc: All applicable <stable@vger.kernel.org>
Reviewed-by: Hans de Goede <hdegoede@redhat.com>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-08-11 12:57:50 +02:00
Subbaraman Narayanamurthy
828f4c3168 thermal: Fix NULL pointer dereferences in of_thermal_ functions
commit 96cfe05051fd8543cdedd6807ec59a0e6c409195 upstream.

of_parse_thermal_zones() parses the thermal-zones node and registers a
thermal_zone device for each subnode. However, if a thermal zone is
consuming a thermal sensor and that thermal sensor device hasn't probed
yet, an attempt to set trip_point_*_temp for that thermal zone device
can cause a NULL pointer dereference. Fix it.

 console:/sys/class/thermal/thermal_zone87 # echo 120000 > trip_point_0_temp
 ...
 Unable to handle kernel NULL pointer dereference at virtual address 0000000000000020
 ...
 Call trace:
  of_thermal_set_trip_temp+0x40/0xc4
  trip_point_temp_store+0xc0/0x1dc
  dev_attr_store+0x38/0x88
  sysfs_kf_write+0x64/0xc0
  kernfs_fop_write_iter+0x108/0x1d0
  vfs_write+0x2f4/0x368
  ksys_write+0x7c/0xec
  __arm64_sys_write+0x20/0x30
  el0_svc_common.llvm.7279915941325364641+0xbc/0x1bc
  do_el0_svc+0x28/0xa0
  el0_svc+0x14/0x24
  el0_sync_handler+0x88/0xec
  el0_sync+0x1c0/0x200

While at it, fix the possible NULL pointer dereference in other
functions as well: of_thermal_get_temp(), of_thermal_set_emul_temp(),
of_thermal_get_trend().

Suggested-by: David Collins <quic_collinsd@quicinc.com>
Signed-off-by: Subbaraman Narayanamurthy <quic_subbaram@quicinc.com>
Acked-by: Daniel Lezcano <daniel.lezcano@linaro.org>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Mark-PK Tsai <mark-pk.tsai@mediatek.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-08-11 12:57:50 +02:00
Jaegeuk Kim
26eb689452 BACKPORT: f2fs: do not set compression bit if kernel doesn't support
If kernel doesn't have CONFIG_F2FS_FS_COMPRESSION, a file having FS_COMPR_FL via
ioctl(FS_IOC_SETFLAGS) is unaccessible due to f2fs_is_compress_backend_ready().
Let's avoid it.

Bug: 240921972
Signed-off-by: Jaegeuk Kim <jaegeuk@kernel.org>
(cherry picked from commit d5a44717f6e0f0943808671e36b1909619707016)
Change-Id: Ieb0f8945175ea5ccb0060690e882f054360fb8f0
2022-08-10 13:06:44 -07:00