mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-06 03:45:24 -04:00
985,442 commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
2906b38ea7 |
Revert "disp: msm:: reset the param value to the default value"
This reverts commit
|
||
|
|
b3dd3932b4 |
Revert "fixup! (CR): disp: msm:: reset the param value to the default value"
This reverts commit
|
||
|
|
cbded7bc5c |
disp: msm: dsi: invert CABC status code
0: off, 1: ui, 2: movie Change-Id: Ie8ef4b9fac60fb16e087be3c9f1b97a19a816951 |
||
|
|
5f7c152f42 |
disp: msm: sde: expose panel features to sysfs by wrapping moto utils
Change-Id: Ibb70f479fb8fcfd582d41e47f759327679b40f46 |
||
|
|
aae02053fd |
Merge tag 'MMI-V1TC35H.88-16' of https://github.com/MotorolaMobilityLLC/kernel-msm-5.4-techpack-display into lineage-22.2
Bangkk push for Android 15 * tag 'MMI-V1TC35H.88-16' of https://github.com/MotorolaMobilityLLC/kernel-msm-5.4-techpack-display: disp: msm: dsi: add null pointer check in dsi_display_dev_remove msm/dsi_display: resend new roi to panel, fix pu dup issue disp: msm: sde: clear cached rectangles when PU ROI is set Change-Id: I2eed4c78f491b527ed088576e799dfb4488e5e97 |
||
|
|
284572d645 |
Merge tag 'MMI-V1TC35H.88-16' of https://github.com/MotorolaMobilityLLC/kernel-devicetree into lineage-22.2
Bangkk push for Android 15 * tag 'MMI-V1TC35H.88-16' of https://github.com/MotorolaMobilityLLC/kernel-devicetree: [Fogo5G NA] DCP fallback to 10W Change-Id: I4251180025c5905372e2dbccfdf9c8db76e060a5 |
||
|
|
273969fc48 |
Merge branch 'staging/kernel-msm/MMI-V1TC35H.88-16' into lineage-22.2
* staging/kernel-msm/MMI-V1TC35H.88-16: bangkk:en62680 PD TEST.PD.PROT.PORT3.02 bangkk:en62680 PD TEST.PD.VDM.SNK.02&05 bangkk: en62680 PD test Change-Id: I2e7de2f0c8bc3fb007c6b0359d7dd44b540a355e |
||
|
|
6a5f80b78d |
bangkk:en62680 PD TEST.PD.PROT.PORT3.02
Changes, Fixe the PD test case TEST.PD.PROT.PORT3.02. Change-Id: I881b1890f6ad618467c1775e7d93efa93d482ed3 Signed-off-by: Lei Chen <chenlei18@lenovo.com> Reviewed-on: https://gerrit.mot.com/3137769 SLTApproved: Slta Waiver SME-Granted: SME Approvals Granted Tested-by: Jira Key Reviewed-by: Zonghua Liu <a17671@motorola.com> Reviewed-by: Xiangpo Zhao <zhaoxp3@motorola.com> Submit-Approved: Jira Key |
||
|
|
3feb6cd70d |
bangkk:en62680 PD TEST.PD.VDM.SNK.02&05
PROPAGATED_from (CR) Fix EU common charger failed case TEST.PD.VDM.SNK.02 Exit Mode without Entering TEST.PD.VDM.SNK.05 DR Swap in Modal Operation Change-Id: If642f90442175af9d5ae4b19bb588c45bb2bca88 Signed-off-by: Lei Chen <chenlei18@lenovo.com> Reviewed-on: https://gerrit.mot.com/3141838 SME-Granted: SME Approvals Granted SLTApproved: Slta Waiver Tested-by: Jira Key Reviewed-by: Zonghua Liu <a17671@motorola.com> Reviewed-by: Xiangpo Zhao <zhaoxp3@motorola.com> Submit-Approved: Jira Key Reviewed-on: https://gerrit.mot.com/3239425 Reviewed-by: Bruno Oliveira <brunosoe@motorola.com> Reviewed-by: Deise Alves <deisema@motorola.com> Submit-Approved: Deise Alves <deisema@motorola.com> |
||
|
|
1c37a3a2d1 |
bangkk: en62680 PD test
PROPAGATED_from (CR) main changes: add several protocol related interface to pass cases such as TEST.PD.PROT.ALL.01 Corrupted GoodCRC TEST.PD.PROT.ALL.04 Reset Signals and MessageID TEST.PD.PROT.ALL3.08 Get Revision Response TEST.PD.PROT.PORT3.01 Get_Battery_Status Response TEST.PD.PROT.PORT3.02 Invalid Battery Status Reference TEST.PD.PROT.PORT3.03 Get_Battery_Cap Response TEST.PD.PROT.PORT3.04 Invalid Battery Capabilities Reference TEST.PD.PROT.SRC.03 SenderResponseTimer Deadline TEST.PD.PROT.SNK.12 PR_Swap - PSSourceOffTimer Timeout TEST.PD.PROT.SNK.13 PR_Swap - Request SenderResponseTimer Timeout TEST.PD.VDM.SRC.01 Discovery Process and Enter Mode TEST.PD.VDM.SRC.02 Invalid Fields - Discover Identity TEST.PD.VDM.SNK.06 Structured VDM Revision Number Test TEST.PD.PS.SRC.01 Multiple Request Load Test TEST.PD.PS.SNK.03 Multiple Request Load Test Post PR Swap Change-Id: I0d5df498d1b9d42080eaac9c9b8297c31a120938 Signed-off-by: Lei Chen <chenlei18@lenovo.com> Reviewed-on: https://gerrit.mot.com/3126980 SME-Granted: SME Approvals Granted SLTApproved: Slta Waiver Tested-by: Jira Key Reviewed-by: Zonghua Liu <a17671@motorola.com> Reviewed-by: Wei Xu <xuwei9@lenovo.com> Reviewed-by: Xiangpo Zhao <zhaoxp3@motorola.com> Submit-Approved: Jira Key Reviewed-on: https://gerrit.mot.com/3239424 Reviewed-by: Bruno Oliveira <brunosoe@motorola.com> Reviewed-by: Deise Alves <deisema@motorola.com> Submit-Approved: Deise Alves <deisema@motorola.com> |
||
|
|
1de2e5d505 |
input: touchscreen: nova_0flash_mmi: Start firmware update immediately
Allows touch to immediately be available in recovery. Change-Id: I426dc7a42bc6c2692d8a0aa039648178c1d35c51 Signed-off-by: AnierinB <anierin@evolution-x.org> |
||
|
|
85ce702b47 |
disp: msm: dsi: Avoid dynamic mode switch during first commit
Dynamic mode switch (DMS) is not supported for video mode panels before cont-splash handoff handled for first frame. so avoid dynamic mode-switch during cont-splash handoff for any DRM mode change. WA is given by QC for GSI issue, as of observation there are no side effects QC SR:05515278 QC CR:NA QC Change ID:Icd5881af99afb3e398d3bba3746b7a35bcda4491 Change-Id: I97f5712ce5bb8448f1c600ccf306d0dac7fa6eae Signed-off-by: maheshmk <maheshmk@motorola.com> Reviewed-on: https://gerrit.mot.com/2113033 SME-Granted: SME Approvals Granted SLTApproved: Slta Waiver Tested-by: Jira Key Reviewed-by: Ashwin Kumar Pathmudi <jfxr63@motorola.com> Reviewed-by: Shuo Yan <shuoyan@motorola.com> Reviewed-by: Guobin Zhang <zhanggb@motorola.com> Submit-Approved: Jira Key |
||
|
|
ee69f5d73d |
Merge remote-tracking branch 'sm8350/lineage-20' into lineage-22.2
* sm8350/lineage-20: ANDROID: bpf: do not fail to load if log is full ANDROID: fix kernelci compressed kernel linking ANDROID: GKI: Update symbol list for Zebra UPSTREAM: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() Linux 5.4.295 scsi: qedf: Use designated initializer for struct qed_fcoe_cb_ops arm64/ptrace: Fix stack-out-of-bounds read in regs_get_kernel_stack_nth() perf: Fix sample vs do_exit() s390/pci: Fix __pcilg_mio_inuser() inline assembly rtc: test: Fix invalid format specifier. jbd2: fix data-race and null-ptr-deref in jbd2_journal_dirty_metadata() mm/huge_memory: fix dereferencing invalid pmd migration entry rtc: Make rtc_time64_to_tm() support dates before 1970 rtc: Improve performance of rtc_time64_to_tm(). Add tests. xprtrdma: fix pointer derefs in error cases of rpcrdma_ep_create posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() ARM: dts: am335x-bone-common: Increase MDIO reset deassert delay to 50ms ARM: dts: am335x-bone-common: Increase MDIO reset deassert time ARM: dts: am335x-bone-common: Add GPIO PHY reset on revision C3 board net: atm: fix /proc/net/atm/lec handling ... Change-Id: Ibdde607f7a4ae5a74994603f513e7f94a9eb04ad |
||
|
|
2b9e22c70c |
Merge tag 'ASB-2025-08-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
https://source.android.com/docs/security/bulletin/2025-08-01 * tag 'ASB-2025-08-05_11-5.4' of https://android.googlesource.com/kernel/common: ANDROID: bpf: do not fail to load if log is full ANDROID: fix kernelci compressed kernel linking ANDROID: GKI: Update symbol list for Zebra UPSTREAM: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() Linux 5.4.295 scsi: qedf: Use designated initializer for struct qed_fcoe_cb_ops arm64/ptrace: Fix stack-out-of-bounds read in regs_get_kernel_stack_nth() perf: Fix sample vs do_exit() s390/pci: Fix __pcilg_mio_inuser() inline assembly rtc: test: Fix invalid format specifier. jbd2: fix data-race and null-ptr-deref in jbd2_journal_dirty_metadata() mm/huge_memory: fix dereferencing invalid pmd migration entry rtc: Make rtc_time64_to_tm() support dates before 1970 rtc: Improve performance of rtc_time64_to_tm(). Add tests. xprtrdma: fix pointer derefs in error cases of rpcrdma_ep_create posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() ARM: dts: am335x-bone-common: Increase MDIO reset deassert delay to 50ms ARM: dts: am335x-bone-common: Increase MDIO reset deassert time ARM: dts: am335x-bone-common: Add GPIO PHY reset on revision C3 board net: atm: fix /proc/net/atm/lec handling net: atm: add lec_mutex calipso: Fix null-ptr-deref in calipso_req_{set,del}attr(). tipc: fix null-ptr-deref when acquiring remote ip of ethernet bearer tcp: fix tcp_packet_delayed() for tcp_is_non_sack_preventing_reopen() behavior atm: atmtcp: Free invalid length skb in atmtcp_c_send(). mpls: Use rcu_dereference_rtnl() in mpls_route_input_rcu(). wifi: carl9170: do not ping device which has failed to load firmware aoe: clean device rq_list in aoedev_downdev() hwmon: (occ) fix unaligned accesses drm/nouveau/bl: increase buffer size to avoid truncate warning erofs: remove unused trace event erofs_destroy_inode ALSA: hda/realtek: enable headset mic on Latitude 5420 Rugged ALSA: hda/intel: Add Thinkpad E15 to PM deny list Input: sparcspkr - avoid unannotated fall-through HID: usbhid: Eliminate recurrent out-of-bounds bug in usbhid_parse() atm: Revert atm_account_tx() if copy_from_iter_full() fails. selinux: fix selinux_xfrm_alloc_user() to set correct ctx_len scsi: s390: zfcp: Ensure synchronous unit_add scsi: storvsc: Increase the timeouts to storvsc_timeout jffs2: check jffs2_prealloc_raw_node_refs() result in few other places jffs2: check that raw node were preallocated before writing summary drivers/rapidio/rio_cm.c: prevent possible heap overwrite Revert "x86/bugs: Make spectre user default depend on MITIGATION_SPECTRE_V2" on v6.6 and older powerpc/eeh: Fix missing PE bridge reconfiguration during VFIO EEH recovery platform/x86: dell_rbu: Stop overwriting data buffer platform: Add Surface platform directory Revert "bus: ti-sysc: Probe for l4_wkup and l4_cfg interconnect devices first" tee: Prevent size calculation wraparound on 32-bit kernels ARM: OMAP2+: Fix l4ls clk domain handling in STANDBY bus: fsl-mc: increase MC_CMD_COMPLETION_TIMEOUT_MS value watchdog: da9052_wdt: respect TWDMIN i40e: fix MMIO write access to an invalid page in i40e_clear_hw sock: Correct error checking condition for (assign|release)_proto_idx() scsi: lpfc: Use memcpy() for BIOS version vxlan: Do not treat dst cache initialization errors as fatal clk: rockchip: rk3036: mark ddrphy as critical wifi: mac80211: do not offer a mesh path if forwarding is disabled net: mlx4: add SOF_TIMESTAMPING_TX_SOFTWARE flag when getting ts info pinctrl: armada-37xx: propagate error from armada_37xx_gpio_get() pinctrl: armada-37xx: propagate error from armada_37xx_pmx_gpio_set_direction() pinctrl: armada-37xx: propagate error from armada_37xx_gpio_get_direction() pinctrl: armada-37xx: propagate error from armada_37xx_pmx_set_by_name() ipv4/route: Use this_cpu_inc() for stats on PREEMPT_RT tcp: fix initial tp->rcvq_space.space value for passive TS enabled flows tcp: always seek for minimal rtt in tcp_rcv_rtt_update() net: dlink: add synchronization for stats update sctp: Do not wake readers in __sctp_write_space() emulex/benet: correct command version selection in be_cmd_get_stats() i2c: designware: Invoke runtime suspend on quick slave re-registration net: macb: Check return value of dma_set_mask_and_coherent() cpufreq: Force sync policy boost with global boost on sysfs update nios2: force update_mmu_cache on spurious tlb-permission--related pagefaults media: platform: exynos4-is: Add hardware sync wait to fimc_is_hw_change_mode() media: tc358743: ignore video while HPD is low drm/amdkfd: Set SDMA_RLCx_IB_CNTL/SWITCH_INSIDE_IB jfs: Fix null-ptr-deref in jfs_ioc_trim drm/amdgpu/gfx9: fix CSIB handling drm/amdgpu/gfx8: fix CSIB handling jfs: fix array-index-out-of-bounds read in add_missing_indices drm/amdgpu/gfx7: fix CSIB handling drm/amdgpu/gfx10: fix CSIB handling drm/msm/a6xx: Increase HFI response timeout drm/amd/display: Add NULL pointer checks in dm_force_atomic_commit() media: uapi: v4l: Fix V4L2_TYPE_IS_OUTPUT condition drm/msm/hdmi: add runtime PM calls to DDC transfer function drm/bridge: analogix_dp: Add irq flag IRQF_NO_AUTOEN instead of calling disable_irq() sunrpc: update nextcheck time when adding new cache entries drm/amdgpu/gfx6: fix CSIB handling ACPI: battery: negate current when discharging PM: runtime: fix denying of auto suspend in pm_suspend_timer_fn() power: supply: bq27xxx: Retrieve again when busy ACPICA: fix acpi parse and parseext cache leaks ACPICA: Avoid sequence overread in call to strncmp() ACPICA: fix acpi operand cache leak in dswstate.c iio: adc: ad7606_spi: fix reg write value mask PCI: Fix lock symmetry in pci_slot_unlock() PCI: Add ACS quirk for Loongson PCIe uio_hv_generic: Use correct size for interrupt and monitor pages regulator: max14577: Add error check for max14577_read_reg() mips: Add -std= flag specified in KBUILD_CFLAGS to vdso CFLAGS staging: iio: ad5933: Correct settling cycles encoding per datasheet net: ch9200: fix uninitialised access during mii_nway_restart ftrace: Fix UAF when lookup kallsym after ftrace disabled dm-mirror: fix a tiny race condition mtd: nand: sunxi: Add randomizer configuration before randomizer enable mtd: rawnand: sunxi: Add randomizer configuration in sunxi_nfc_hw_ecc_write_chunk mm: fix ratelimit_pages update error in dirty_ratio_handler() ipc: fix to protect IPCS lookups using RCU parisc: fix building with gcc-15 vgacon: Add check for vc_origin address range in vgacon_scroll() fbdev: Fix fb_set_var to prevent null-ptr-deref in fb_videomode_to_var EDAC/altera: Use correct write width with the INTTEST register NFC: nci: uart: Set tty->disc_data only in success path f2fs: prevent kernel warning due to negative i_nlink from corrupted image Input: ims-pcu - check record size in ims_pcu_flash_firmware() ext4: fix calculation of credits for extent tree modification ext4: inline: fix len overflow in ext4_prepare_inline_data bus: fsl-mc: do not add a device-link for the UAPI used DPMCP device ata: pata_via: Force PIO for ATAPI devices on VT6415/VT6330 ARM: 9447/1: arm/memremap: fix arch_memremap_can_ram_remap() media: v4l2-dev: fix error handling in __video_register_device() media: gspca: Add error handling for stv06xx_read_sensor() wifi: rtlwifi: disable ASPM for RTL8723BE with subsystem ID 11ad:1723 nfsd: nfsd4_spo_must_allow() must check this is a v4 compound request wifi: p54: prevent buffer-overflow in p54_rx_eeprom_readback() gfs2: move msleep to sleepable context configfs: Do not override creating attribute file failure in populate_attrs() net: usb: aqc111: debug info before sanitation calipso: unlock rcu before returning -EAFNOSUPPORT xen/arm: call uaccess_ttbr0_enable for dm_op hypercall usb: Flush altsetting 0 endpoints before reinitializating them after reset. fs/filesystems: Fix potential unsigned integer underflow in fs_name() net/mdiobus: Fix potential out-of-bounds read/write access drm/amd/display: Do not add '-mhard-float' to dcn2{1,0}_resource.o for clang drm/amd/display: Do not add '-mhard-float' to dml_ccflags for clang MIPS: Move '-Wa,-msoft-float' check from as-option to cc-option x86/boot/compressed: prefer cc-option for CFLAGS additions net: mdio: C22 is now optional, EOPNOTSUPP if not provided net_sched: tbf: fix a race in tbf_change() net_sched: red: fix a race in __red_change() net_sched: prio: fix a race in prio_tune() net/mlx5: Fix return value when searching for existing flow group net/mlx5: Wait for inactive autogroups i40e: retry VFLR handling if there is ongoing VF reset i40e: return false from i40e_reset_vf if reset is in progress net_sched: sch_sfq: fix a potential crash on gso_skb handling scsi: iscsi: Fix incorrect error path labels for flashnode operations NFSD: Fix NFSv3 SETATTR/CREATE's handling of large file sizes NFSD: Fix ia_size underflow Input: synaptics-rmi - fix crash with unsupported versions of F34 Input: synaptics-rmi4 - convert to use sysfs_emit() APIs pmdomain: core: Fix error checking in genpd_dev_pm_attach_by_id() do_change_type(): refuse to operate on unmounted/not ours mounts PM: sleep: Fix power.is_suspended cleanup for direct-complete devices ice: create new Tx scheduler nodes for new queues only Bluetooth: L2CAP: Fix not responding with L2CAP_CR_LE_ENCRYPTION net/mlx4_en: Prevent potential integer overflow calculating Hz vt: remove VT_RESIZE and VT_RESIZEX from vt_compat_ioctl() serial: Fix potential null-ptr-deref in mlb_usio_probe() usb: renesas_usbhs: Reorder clock handling and power management in probe rtc: Fix offset calculation for .start_secs < 0 rtc: sh: assign correct interrupts with DT perf record: Fix incorrect --user-regs comments perf tests switch-tracking: Fix timestamp comparison mfd: stmpe-spi: Correct the name used in MODULE_DEVICE_TABLE mfd: exynos-lpass: Avoid calling exynos_lpass_disable() twice in exynos_lpass_remove() rpmsg: qcom_smd: Fix uninitialized return variable in __qcom_smd_send() perf scripts python: exported-sql-viewer.py: Fix pattern matching with Python 3 perf ui browser hists: Set actions->thread before calling do_zoom_thread() fbdev: core: fbcvt: avoid division by 0 in fb_cvt_hperiod() soc: aspeed: Add NULL check in aspeed_lpc_enable_snoop() soc: aspeed: lpc: Fix impossible judgment condition arm64: dts: rockchip: disable unrouted USB controllers and PHY on RK3399 Puma with Haikou ARM: dts: qcom: apq8064 merge hw splinlock into corresponding syscon device bus: fsl-mc: fix double-free on mc_dev nilfs2: do not propagate ENOENT error from nilfs_btree_propagate() nilfs2: add pointer check for nilfs_direct_propagate() Squashfs: check return result of sb_min_blocksize ARM: dts: at91: at91sam9263: fix NAND chip selects ARM: dts: at91: usb_a9263: fix GPIO for Dataflash chip select f2fs: fix to correct check conditions in f2fs_cross_rename f2fs: use d_inode(dentry) cleanup dentry->d_inode calipso: Don't call calipso functions for AF_INET sk. net: lan743x: rename lan743x_reset_phy to lan743x_hw_reset_phy net: usb: aqc111: fix error handling of usbnet read calls netfilter: nf_tables: nft_fib_ipv6: fix VRF ipv4/ipv6 result discrepancy wifi: ath9k_htc: Abort software beacon handling if disabled bpf: Fix WARN() in get_bpf_raw_tp_regs pinctrl: at91: Fix possible out-of-boundary access ktls, sockmap: Fix missing uncharge operation netfilter: bridge: Move specific fragmented packet to slow_path instead of dropping it f2fs: clean up w/ fscrypt_is_bounce_page() RDMA/hns: Include hnae3.h in hns_roce_hw_v2.h wifi: rtw88: do not ignore hardware read error during DPK net: ncsi: Fix GCPS 64-bit member variables f2fs: fix to do sanity check on sbi->total_valid_block_count drm/tegra: rgb: Fix the unbound reference count drm/vkms: Adjust vkms_state->active_planes allocation type drm: rcar-du: Fix memory leak in rcar_du_vsps_init() selftests/seccomp: fix syscall_restart test for arm compat firmware: psci: Fix refcount leak in psci_dt_init m68k: mac: Fix macintosh_config for Mac II drm/vmwgfx: Add seqno waiter for sync_files spi: sh-msiof: Fix maximum DMA transfer size ACPI: OSI: Stop advertising support for "3.0 _SCP Extensions" x86/mtrr: Check if fixed-range MTRRs exist in mtrr_save_fixed_ranges() PM: wakeup: Delete space in the end of string shown by pm_show_wakelocks() EDAC/skx_common: Fix general protection fault crypto: marvell/cesa - Avoid empty transfer descriptor crypto: marvell/cesa - Handle zero-length skcipher requests x86/cpu: Sanitize CPUID(0x80000000) output perf/core: Fix broken throttling when max_samples_per_tick=1 gfs2: gfs2_create_inode error handling fix netfilter: nft_socket: fix sk refcount leaks thunderbolt: Do not double dequeue a configuration request usb: usbtmc: Fix timeout value in get_stb usb: storage: Ignore UAS driver for SanDisk 3.2 Gen2 storage device usb: quirks: Add NO_LPM quirk for SanDisk Extreme 55AE pinctrl: armada-37xx: set GPIO output value before setting direction pinctrl: armada-37xx: use correct OUTPUT_VAL register for GPIOs > 31 tracing: Fix compilation warning on arm32 BACKPORT: binder: Create safe versions of binder log files UPSTREAM: binder: Refactor binder_node print synchronization Revert "coredump: hand a pidfd to the usermode coredump helper" Linux 5.4.294 xen/swiotlb: relax alignment requirements platform/x86: thinkpad_acpi: Ignore battery threshold change event notification platform/x86: fujitsu-laptop: Support Lifebook S2110 hotkeys spi: spi-sun4i: fix early activation um: let 'make clean' properly clean underlying SUBARCH as well platform/x86: thinkpad_acpi: Support also NEC Lavie X1475JAS nfs: don't share pNFS DS connections between net namespaces HID: quirks: Add ADATA XPG alpha wireless mouse support coredump: hand a pidfd to the usermode coredump helper fork: use pidfd_prepare() pid: add pidfd_prepare() pidfd: check pid has attached task in fdinfo coredump: fix error handling for replace_fd() net_sched: hfsc: Address reentrant enqueue adding class to eltree twice smb: client: Reset all search buffer pointers when releasing buffer smb: client: Fix use-after-free in cifs_fill_dirent drm/i915/gvt: fix unterminated-string-initialization warning netfilter: nf_tables: do not defer rule destruction via call_rcu netfilter: nf_tables: wait for rcu grace period on net_device removal netfilter: nf_tables: pass nft_chain to destroy function, not nft_ctx kbuild: Disable -Wdefault-const-init-unsafe spi: spi-fsl-dspi: restrict register range for regmap access mm/page_alloc.c: avoid infinite retries caused by cpuset race memcg: always call cond_resched() after fn() drm/edid: fixed the bug that hdr metadata was not reset llc: fix data loss when reading from a socket in llc_ui_recvmsg() ALSA: pcm: Fix race of buffer access at PCM OSS layer can: bcm: add missing rcu read protection for procfs content can: bcm: add locking for bcm_op runtime updates crypto: algif_hash - fix double free in hash_accept sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue() net: dwmac-sun8i: Use parsed internal PHY address instead of 1 bridge: netfilter: Fix forwarding of fragmented packets xfrm: Sanitize marks before insert __legitimize_mnt(): check for MNT_SYNC_UMOUNT should be under mount_lock xenbus: Allow PVH dom0 a non-local xenstore btrfs: correct the order of prelim_ref arguments in btrfs__prelim_ref nvmet-tcp: don't restore null sk_state_change ASoC: Intel: bytcr_rt5640: Add DMI quirk for Acer Aspire SW3-013 pinctrl: meson: define the pull up/down resistor value as 60 kOhm drm: Add valid clones check drm/atomic: clarify the rules around drm_atomic_state->allow_modeset regulator: ad5398: Add device tree support wifi: rtw88: Don't use static local variable in rtw8822b_set_tx_power_index_by_rate bpftool: Fix readlink usage in get_fd_type HID: usbkbd: Fix the bit shift number for LED_KANA scsi: st: Restore some drive settings after reset scsi: lpfc: Handle duplicate D_IDs in ndlp search-by D_ID routine rcu: fix header guard for rcu_all_qs() rcu: handle quiescent states for PREEMPT_RCU=n, PREEMPT_COUNT=y vxlan: Annotate FDB data races hwmon: (xgene-hwmon) use appropriate type for the latency value ip: fib_rules: Fetch net from fib_rule in fib[46]_rule_configure(). net/mlx5e: reduce rep rxq depth to 256 for ECPF net/mlx5e: set the tx_queue_len for pfifo_fast net/mlx5: Extend Ethtool loopback selftest to support non-linear SKB phy: core: don't require set_mode() callback for phy_get_mode() to work net/mlx4_core: Avoid impossible mlx4_db_alloc() order value smack: recognize ipv4 CIPSO w/o categories pinctrl: devicetree: do not goto err when probing hogs in pinctrl_dt_to_map ASoC: ops: Enforce platform maximum on initial value net/mlx5: Apply rate-limiting to high temperature warning net/mlx5: Modify LSB bitmask in temperature event to include only the first bit ACPI: HED: Always initialize before evged PCI: Fix old_size lower bound in calculate_iosize() too EDAC/ie31200: work around false positive build warning net: pktgen: fix access outside of user given buffer in pktgen_thread_write() wifi: rtw88: Fix rtw_init_ht_cap() for RTL8814AU scsi: mpt3sas: Send a diag reset if target reset fails MIPS: pm-cps: Use per-CPU variables as per-CPU, not per-core MIPS: Use arch specific syscall name match function cpuidle: menu: Avoid discarding useful information x86/nmi: Add an emergency handler in nmi_desc & use it in nmi_shootdown_cpus() bonding: report duplicate MAC address in all situations net: xgene-v2: remove incorrect ACPI_PTR annotation drm/amdkfd: KFD release_work possible circular locking net/mlx5: Avoid report two health errors on same syndrome fpga: altera-cvp: Increase credit timeout drm/mediatek: mtk_dpi: Add checks for reg_h_fre_con existence hwmon: (gpio-fan) Add missing mutex locks x86/bugs: Make spectre user default depend on MITIGATION_SPECTRE_V2 net: pktgen: fix mpls maximum labels list parsing pinctrl: bcm281xx: Use "unsigned int" instead of bare "unsigned" media: cx231xx: set device_caps for 417 orangefs: Do not truncate file size dm cache: prevent BUG_ON by blocking retries on failed device resumes media: c8sectpfe: Call of_node_put(i2c_bus) only once in c8sectpfe_probe() ARM: tegra: Switch DSI-B clock parent to PLLD on Tegra114 ieee802154: ca8210: Use proper setters and getters for bitwise types rtc: ds1307: stop disabling alarms on probe powerpc/prom_init: Fixup missing #size-cells on PowerBook6,7 mmc: sdhci: Disable SD card clock before changing parameters netfilter: conntrack: Bound nf_conntrack sysctl writes posix-timers: Add cond_resched() to posix_timer_add() search loop xen: Add support for XenServer 6.1 platform device dm: restrict dm device size to 2^63-512 bytes kbuild: fix argument parsing in scripts/config scsi: st: ERASE does not change tape location scsi: st: Tighten the page format heuristics with MODE SELECT ext4: reorder capability check last um: Update min_low_pfn to match changes in uml_reserved um: Store full CSGSFS and SS register from mcontext btrfs: send: return -ENAMETOOLONG when attempting a path that is too long btrfs: avoid linker error in btrfs_find_create_tree_block() i2c: pxa: fix call balance of i2c->clk handling routines mmc: host: Wait for Vdd to settle on card power off libnvdimm/labels: Fix divide error in nd_label_data_init() pNFS/flexfiles: Report ENETDOWN as a connection error tools/build: Don't pass test log files to linker dql: Fix dql->limit value when reset. SUNRPC: rpc_clnt_set_transport() must not change the autobind setting NFSv4: Treat ENETUNREACH errors as fatal for state recovery fbdev: core: tileblit: Implement missing margin clearing for tileblit fbdev: fsl-diu-fb: add missing device_remove_file() mailbox: use error ret code of of_parse_phandle_with_args() kconfig: merge_config: use an empty file as initfile cgroup: Fix compilation issue due to cgroup_mutex not being exported dma-mapping: avoid potential unused data compilation warning scsi: target: iscsi: Fix timeout on deleted connection openvswitch: Fix unsafe attribute parsing in output_userspace() Input: synaptics - enable InterTouch on TUXEDO InfinityBook Pro 14 v5 Input: synaptics - enable SMBus for HP Elitebook 850 G1 clocksource/i8253: Use raw_spinlock_irqsave() in clockevent_i8253_disable() phy: renesas: rcar-gen3-usb2: Set timing registers only once phy: Fix error handling in tegra_xusb_port_init ALSA: es1968: Add error handling for snd_pcm_hw_constraint_pow2() ACPI: PPTT: Fix processor subtable walk dmaengine: Revert "dmaengine: dmatest: Fix dmatest waiting less when interrupted" NFSv4/pnfs: Reset the layout state after a layoutreturn NFSv4/pnfs: pnfs_set_layout_stateid() should update the layout cred qlcnic: fix memory leak in qlcnic_sriov_channel_cfg_cmd() ALSA: sh: SND_AICA should depend on SH_DMA_API net: dsa: sja1105: discard incoming frames in BR_STATE_LISTENING spi: loopback-test: Do not split 1024-byte hexdumps nfs: handle failure of nfs_get_lock_context in unlock path RDMA/rxe: Fix slab-use-after-free Read in rxe_queue_cleanup bug iio: chemical: sps30: use aligned_s64 for timestamp iio: adc: ad7768-1: Fix insufficient alignment of timestamp. staging: axis-fifo: Correct handling of tx_fifo_depth for size validation staging: axis-fifo: avoid parsing ignored device tree properties staging: axis-fifo: Remove hardware resets for user errors staging: axis-fifo: replace spinlock with mutex platform/x86: asus-wmi: Fix wlan_ctrl_by_user detection do_umount(): add missing barrier before refcount checks in sync case nvme: unblock ctrl state transition for firmware update MIPS: Fix MAX_REG_OFFSET iio: adc: dln2: Use aligned_s64 for timestamp types: Complement the aligned types with signed 64-bit one usb: usbtmc: Fix erroneous generic_read ioctl return usb: usbtmc: Fix erroneous wait_srq ioctl return usb: usbtmc: Fix erroneous get_stb ioctl error returns USB: usbtmc: use interruptible sleep in usbtmc_read usb: typec: ucsi: displayport: Fix NULL pointer access usb: typec: tcpm: delay SNK_TRY_WAIT_DEBOUNCE to SRC_TRYWAIT transition ocfs2: stop quota recovery before disabling quotas ocfs2: implement handshaking with ocfs2 recovery thread ocfs2: switch osb->disable_recovery to enum module: ensure that kobject_put() is safe for module type kobjects xenbus: Use kref to track req lifetime usb: uhci-platform: Make the clock really optional iio: imu: st_lsm6dsx: fix possible lockup in st_lsm6dsx_read_tagged_fifo iio: imu: st_lsm6dsx: fix possible lockup in st_lsm6dsx_read_fifo iio: adis16201: Correct inclinometer channel resolution iio: adc: ad7606: fix serial register access staging: iio: adc: ad7816: Correct conditional logic for store mode Input: synaptics - enable InterTouch on Dell Precision M3800 Input: synaptics - enable InterTouch on Dynabook Portege X30L-G Input: synaptics - enable InterTouch on Dynabook Portege X30-D net: dsa: b53: fix learning on VLAN unaware bridges netfilter: ipset: fix region locking in hash types sch_htb: make htb_deactivate() idempotent scsi: target: Fix WRITE_SAME No Data Buffer crash dm: fix copying after src array boundaries iommu/amd: Fix potential buffer overflow in parse_ivrs_acpihid arm64: dts: rockchip: fix iface clock-name on px30 iommus usb: chipidea: ci_hdrc_imx: implement usb_phy_init() error handling usb: chipidea: ci_hdrc_imx: use dev_err_probe() usb: chipidea: imx: refine the error handling for hsic usb: chipidea: imx: change hsic power regulator as optional irqchip/gic-v2m: Prevent use after free of gicv2m_get_fwnode() irqchip/gic-v2m: Mark a few functions __init irqchip/gic-v2m: Add const to of_device_id sch_htb: make htb_qlen_notify() idempotent of: module: add buffer overflow check in of_modalias() PCI: imx6: Skip controller_id generation logic for i.MX7D net: fec: ERR007885 Workaround for conventional TX net: lan743x: Fix memleak issue when GSO enabled lan743x: fix endianness when accessing descriptors lan743x: remove redundant initialization of variable current_head_index nvme-tcp: fix premature queue removal and I/O failover net: dlink: Correct endianness handling of led_mode net_sched: qfq: Fix double list add in class with netem as child qdisc net_sched: hfsc: Fix a UAF vulnerability in class with netem as child qdisc net_sched: drr: Fix double list add in class with netem as child qdisc net/mlx5: E-Switch, Initialize MAC Address for Default GID tracing: Fix oob write in trace_seq_to_buffer() dm: always update the array size in realloc_argv on success dm-integrity: fix a warning on invalid table line wifi: brcm80211: fmac: Add error handling for brcmf_usb_dl_writeimage() amd-xgbe: Fix to ensure dependent features are toggled with RX checksum offload parisc: Fix double SIGFPE crash i2c: imx-lpi2c: Fix clock count when probe defers EDAC/altera: Set DDR and SDMMC interrupt mask before registration EDAC/altera: Test the correct error reg offset Conflicts: Makefile drivers/platform/Kconfig drivers/platform/Makefile include/linux/pid.h Change-Id: Iab0fd96a23cfe218e945cbf71eef0e87dce204db |
||
|
|
6c9dd323b9 |
arm64: configs: denver: Disable CAMERA_CCI_MASTER_CHANGE
Change-Id: I9014c3a95ecffe8fc31d6d1d4a4d1c5090d43517 |
||
|
|
67cfbd9fb2 |
techpack: camera: Add guarding for header struct changes
* We don't build the Camera HAL from source so userspace does not need access to cam_sensor.h, move it and implement guarding for breaking changes for devices with older Camera Blobs. Change-Id: I5a45b83e01ad85752e99035805ee2a6d1f8dfa93 Signed-off-by: electimon <electimon@gmail.com> |
||
|
|
e7e3836bc3 |
drivers: power: Guard SMB5_QG_SOH function
* Fixes battery detection for denver Change-Id: I16087f472b8f06002486141dec23e4a2ef3f9688 |
||
|
|
6be9fdc19a |
arm64: configs: denver: Build moto kernel modules
Change-Id: Ia5c0b280ba99999f8713f3192ccead1157183421 |
||
|
|
24599b086c |
treewide: Setup inline build for denver modules
Change-Id: Ia804acc4af1e5424aabaf062d8ac897dc214b04d |
||
|
|
5bf63f8060 |
drivers: misc: pen: Send key events on removed/inserted
So that we can wire it up with KeyHandler. Change-Id: I8ec75d2bddb4864eed2806a84794c59e1ead3b20 Signed-off-by: AnierinB <anierin@evolution-x.org> |
||
|
|
e0e2ad134a |
arm64: configs: milanf: Build moto kernel modules
Change-Id: I63f601c9fba15bbcc415f40c5c49e197d034e4a1 Signed-off-by: AnierinB <anierin@evolution-x.org> |
||
|
|
839c9fd502 |
treewide: Setup inline build for milanf modules
Change-Id: Ie9eab43384d353290b6b8d967af2e87a64a537da Signed-off-by: AnierinB <anierin@evolution-x.org> |
||
|
|
eabd61eded |
[Fogo5G NA] DCP fallback to 10W
Ported from (CR) to fogo According to the conclusion of the D-team, DCP fallback to 10W Change-Id: I21fecd38d23e80dd419f72d7fb7483f5493f544c Reviewed-on: https://gerrit.mot.com/3246149 SME-Granted: SME Approvals Granted SLTApproved: Slta Waiver Tested-by: Jira Key Reviewed-by: Bruno Dias <brunorcd@motorola.com> Reviewed-by: Andrea dos Santos <andreads@motorola.com> Submit-Approved: Jira Key Submit-Approved: Andrea dos Santos <andreads@motorola.com> |
||
|
|
387dbb9a99 |
ANDROID: bpf: do not fail to load if log is full
Upstream commit 973c7a0d8a38 ("bpf: fix precision backtracking
instruction iteration") slightly changes the logic in the verifier which
results in the verifier log growing. This results in the log being too
small when loading the filterPowerSupplyEvents BPF program in Android,
and therefore causing the program loading to fail. Because this
program is labeled 'critical', a load failure forces a boot loop.
This BPF program exists on the vendor partition, and therefore we must
maintain the GRF/ treble boundary and modify the kernel logic.
The kernel's bpf log logic is refactored in the 6.4 kernel and
acknowledges the shortcomings of the existing approach which causes the
program load to fail. Instead of backporting the significant changes,
this change simply ignores the fact that the log is full.
For more information see commit 121664093803 ("bpf: Switch BPF verifier
log to be a rotating log by default")
Bug: 432207940
Bug: 433641053
Test: verify pixel 6 boots on a 5.10 kernel including commit 973c7a0d8a38
Change-Id: I35c3d2074dd9b39e44bfdbaf66fa56ec917df0a6
Signed-off-by: Neill Kapron <nkapron@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
|
||
|
|
21224f4b67 |
Merge tag 'android11-5.4.295_r00' into android11-5.4
This merges the android11-5.4.295_r00 tag into the android11-5.4 branch, catching it up with the latest LTS releases. It contains the following commits: * |
||
|
|
5287b166b7 |
ANDROID: fix kernelci compressed kernel linking
Kernel versions 5.4 and below have several bogus relocations defined in arch/x86/boot/compressed/head_32.S that cause build errors like the following when linked with the llvm toolchain: ld.lld: error: relocation R_386_32 cannot be used against symbol '_bss'; recompile with -fPIC These errors only show up when linking with LLD because BFD allows relocations in read-only sections by default. Add "-z notext" to KBUILD_LDFLAGS to replicate that behavior with ld.lld and unblock kernelci builds for 5.4 branches. Bug: 430124841 Change-Id: I393174e264fbc0181abb5ecfd518055a7cb14162 Signed-off-by: Tiffany Yang <ynaffit@google.com> |
||
|
|
c88830fe05 |
Merge remote-tracking branch 'sm8350/lineage-20' into lineage-22.2
* sm8350/lineage-20: sched/headers: Move 'struct sched_param' out of uapi, to work around glibc/musl breakage ANDROID: binder: fix minimum node priority comparison ANDROID: 16K: Remove ELF padding entry from map_file ranges Linux 5.4.293 MIPS: cm: Fix warning if MIPS_CM is disabled crypto: atmel-sha204a - Set hwrng quality to lowest possible comedi: jr3_pci: Fix synchronous deletion of timer md/raid1: Add check for missing source disk in process_checks() scsi: pm80xx: Set phy_attached to zero when device is gone x86/bugs: Don't fill RSB on VMEXIT with eIBRS+retpoline ACPI PPTT: Fix coding mistakes in a couple of sizeof() calls selftests: ublk: fix test_stripe_04 udmabuf: fix a buf size overflow issue during udmabuf creation KVM: s390: Don't use %pK through tracepoints sched/isolation: Make CONFIG_CPU_ISOLATION depend on CONFIG_SMP ntb: reduce stack usage in idt_scan_mws qibfs: fix _another_ leak usb: gadget: aspeed: Add NULL pointer check in ast_vhub_init_dev() dmaengine: dmatest: Fix dmatest waiting less when interrupted usb: host: max3421-hcd: Add missing spi_device_id table ... Change-Id: Ic9ed345187af7171604f364f2abc621d180b26a9 |
||
|
|
d72ce6ed64 |
ANDROID: GKI: Update symbol list for Zebra
3 function symbol(s) added 'void drm_client_dev_hotplug(struct drm_device*)' 'int drm_edid_to_sad(struct edid*, struct cea_sad**)' 'int drm_edid_to_speaker_allocation(struct edid*, u8**)' Bug: 427631467 Change-Id: I0e0dbe03e7d3deaa5bf0b7f42d4cdc3b48577973 Signed-off-by: Akshay M Joshi <aakshayjoshi892@gmail.com> |
||
|
|
9be1f8739c |
sched/headers: Move 'struct sched_param' out of uapi, to work around glibc/musl breakage
Both glibc and musl define 'struct sched_param' in sched.h, while kernel
has it in uapi/linux/sched/types.h, making it cumbersome to use
sched_getattr(2) or sched_setattr(2) from userspace.
For example, something like this:
#include <sched.h>
#include <linux/sched/types.h>
struct sched_attr sa;
will result in "error: redefinition of ‘struct sched_param’" (note the
code doesn't need sched_param at all -- it needs struct sched_attr
plus some stuff from sched.h).
The situation is, glibc is not going to provide a wrapper for
sched_{get,set}attr, thus the need to include linux/sched_types.h
directly, which leads to the above problem.
Thus, the userspace is left with a few sub-par choices when it wants to
use e.g. sched_setattr(2), such as maintaining a copy of struct
sched_attr definition, or using some other ugly tricks.
OTOH, 'struct sched_param' is well known, defined in POSIX, and it won't
be ever changed (as that would break backward compatibility).
So, while 'struct sched_param' is indeed part of the kernel uapi,
exposing it the way it's done now creates an issue, and hiding it
(like this patch does) fixes that issue, hopefully without creating
another one: common userspace software rely on libc headers, and as
for "special" software (like libc), it looks like glibc and musl
do not rely on kernel headers for 'struct sched_param' definition
(but let's Cc their mailing lists in case it's otherwise).
The alternative to this patch would be to move struct sched_attr to,
say, linux/sched.h, or linux/sched/attr.h (the new file).
Oh, and here is the previous attempt to fix the issue:
https://lore.kernel.org/all/20200528135552.GA87103@google.com/
While I support Linus arguments, the issue is still here
and needs to be fixed.
[ mingo: Linus is right, this shouldn't be needed - but on the other
hand I agree that this header is not really helpful to
user-space as-is. So let's pretend that
<uapi/linux/sched/types.h> is only about sched_attr, and
call this commit a workaround for user-space breakage
that it in reality is ... Also, remove the Fixes tag. ]
Change-Id: I3943f8f4a11a9007ccc392de3ece9e62841e8fcb
Signed-off-by: Kir Kolyshkin <kolyshkin@gmail.com>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Link: https://lore.kernel.org/r/20230808030357.1213829-1-kolyshkin@gmail.com
|
||
|
|
a4761d1472 |
UPSTREAM: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
commit f90fff1e152dedf52b932240ebbd670d83330eca upstream. If an exiting non-autoreaping task has already passed exit_notify() and calls handle_posix_cpu_timers() from IRQ, it can be reaped by its parent or debugger right after unlock_task_sighand(). If a concurrent posix_cpu_timer_del() runs at that moment, it won't be able to detect timer->it.cpu.firing != 0: cpu_timer_task_rcu() and/or lock_task_sighand() will fail. Add the tsk->exit_state check into run_posix_cpu_timers() to fix this. This fix is not needed if CONFIG_POSIX_CPU_TIMERS_TASK_WORK=y, because exit_task_work() is called before exit_notify(). But the check still makes sense, task_work_add(&tsk->posix_cputimers_work.work) will fail anyway in this case. Bug: 425282960 Cc: stable@vger.kernel.org Reported-by: Benoît Sevens <bsevens@google.com> Fixes: |
||
|
|
978aeb58ff |
This is the 5.4.295 stable release
-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEEZH8oZUiU471FcZm+ONu9yGCSaT4FAmhebGEACgkQONu9yGCS
aT67mBAAqkBCrkNSqHHQpsl/YybmfDgGonfHeLkNOYp4G44Axp/oytb1bAEhg65A
oqfTSF67Hr3xjBVEvFMHMnuFO1+xHxkKIy3LUr9o9gjS+6+rEn7U5cYkaHYPNef5
hN/tPUwf90d2ivpAsTueUu4PegJUJTaux0VqW6PsECKJ/fRF2sdAW7NpGps4zwaw
+gnxZ7fhWnMLDeSH4d6HAFsVB10AH4sC/WzVMGlXpiS7V8vzM7QjAj3S7NWkOjaX
fUWmKLecRT6388V+PBH6tr7vwsbFAv83gKVENgFMPKnsfPLTKd3d81TJvWqbU5Dn
Y+KxG1NWmIUkhlMeqDld51JJCP2JpLxSchqHvJ2TiFJs3gRdkYeQxiDfXHzRsZ+v
8beqQufcmQFxOyUkWQLGlMR9ACva1IA7hQ4HdTqygDqcQjKcvIYGcy+29PpTBVjj
+BNs6F8ttK6jQ19IqwhP2AeIObq/DQCtn0xRaOkfAwyODhi2nD7F191ZtmrRwAq7
ax+hXzNIWkLhvsuG+YLuNXczYbOGKZ56mg8XI+3DQ0KNRUieznsgeXXsjkGbzivn
uDPWkRtqO48RnZHzlLUzT0Zv7pNCWXscnHEa1LfQ7Effj3G0C74TJWLDRcfSgf0i
+cdXwJhnHc1ztExtmuNvfk7SHEFRNhjB8Zmdd8weK6SUzH0knPE=
=jzgM
-----END PGP SIGNATURE-----
Merge 5.4.295 into android11-5.4-lts
Changes in 5.4.295
tracing: Fix compilation warning on arm32
pinctrl: armada-37xx: use correct OUTPUT_VAL register for GPIOs > 31
pinctrl: armada-37xx: set GPIO output value before setting direction
usb: quirks: Add NO_LPM quirk for SanDisk Extreme 55AE
usb: storage: Ignore UAS driver for SanDisk 3.2 Gen2 storage device
usb: usbtmc: Fix timeout value in get_stb
thunderbolt: Do not double dequeue a configuration request
netfilter: nft_socket: fix sk refcount leaks
gfs2: gfs2_create_inode error handling fix
perf/core: Fix broken throttling when max_samples_per_tick=1
x86/cpu: Sanitize CPUID(0x80000000) output
crypto: marvell/cesa - Handle zero-length skcipher requests
crypto: marvell/cesa - Avoid empty transfer descriptor
EDAC/skx_common: Fix general protection fault
PM: wakeup: Delete space in the end of string shown by pm_show_wakelocks()
x86/mtrr: Check if fixed-range MTRRs exist in mtrr_save_fixed_ranges()
ACPI: OSI: Stop advertising support for "3.0 _SCP Extensions"
spi: sh-msiof: Fix maximum DMA transfer size
drm/vmwgfx: Add seqno waiter for sync_files
m68k: mac: Fix macintosh_config for Mac II
firmware: psci: Fix refcount leak in psci_dt_init
selftests/seccomp: fix syscall_restart test for arm compat
drm: rcar-du: Fix memory leak in rcar_du_vsps_init()
drm/vkms: Adjust vkms_state->active_planes allocation type
drm/tegra: rgb: Fix the unbound reference count
f2fs: fix to do sanity check on sbi->total_valid_block_count
net: ncsi: Fix GCPS 64-bit member variables
wifi: rtw88: do not ignore hardware read error during DPK
RDMA/hns: Include hnae3.h in hns_roce_hw_v2.h
f2fs: clean up w/ fscrypt_is_bounce_page()
netfilter: bridge: Move specific fragmented packet to slow_path instead of dropping it
ktls, sockmap: Fix missing uncharge operation
pinctrl: at91: Fix possible out-of-boundary access
bpf: Fix WARN() in get_bpf_raw_tp_regs
wifi: ath9k_htc: Abort software beacon handling if disabled
netfilter: nf_tables: nft_fib_ipv6: fix VRF ipv4/ipv6 result discrepancy
net: usb: aqc111: fix error handling of usbnet read calls
net: lan743x: rename lan743x_reset_phy to lan743x_hw_reset_phy
calipso: Don't call calipso functions for AF_INET sk.
f2fs: use d_inode(dentry) cleanup dentry->d_inode
f2fs: fix to correct check conditions in f2fs_cross_rename
ARM: dts: at91: usb_a9263: fix GPIO for Dataflash chip select
ARM: dts: at91: at91sam9263: fix NAND chip selects
Squashfs: check return result of sb_min_blocksize
nilfs2: add pointer check for nilfs_direct_propagate()
nilfs2: do not propagate ENOENT error from nilfs_btree_propagate()
bus: fsl-mc: fix double-free on mc_dev
ARM: dts: qcom: apq8064 merge hw splinlock into corresponding syscon device
arm64: dts: rockchip: disable unrouted USB controllers and PHY on RK3399 Puma with Haikou
soc: aspeed: lpc: Fix impossible judgment condition
soc: aspeed: Add NULL check in aspeed_lpc_enable_snoop()
fbdev: core: fbcvt: avoid division by 0 in fb_cvt_hperiod()
perf ui browser hists: Set actions->thread before calling do_zoom_thread()
perf scripts python: exported-sql-viewer.py: Fix pattern matching with Python 3
rpmsg: qcom_smd: Fix uninitialized return variable in __qcom_smd_send()
mfd: exynos-lpass: Avoid calling exynos_lpass_disable() twice in exynos_lpass_remove()
mfd: stmpe-spi: Correct the name used in MODULE_DEVICE_TABLE
perf tests switch-tracking: Fix timestamp comparison
perf record: Fix incorrect --user-regs comments
rtc: sh: assign correct interrupts with DT
rtc: Fix offset calculation for .start_secs < 0
usb: renesas_usbhs: Reorder clock handling and power management in probe
serial: Fix potential null-ptr-deref in mlb_usio_probe()
vt: remove VT_RESIZE and VT_RESIZEX from vt_compat_ioctl()
net/mlx4_en: Prevent potential integer overflow calculating Hz
Bluetooth: L2CAP: Fix not responding with L2CAP_CR_LE_ENCRYPTION
ice: create new Tx scheduler nodes for new queues only
PM: sleep: Fix power.is_suspended cleanup for direct-complete devices
do_change_type(): refuse to operate on unmounted/not ours mounts
pmdomain: core: Fix error checking in genpd_dev_pm_attach_by_id()
Input: synaptics-rmi4 - convert to use sysfs_emit() APIs
Input: synaptics-rmi - fix crash with unsupported versions of F34
NFSD: Fix ia_size underflow
NFSD: Fix NFSv3 SETATTR/CREATE's handling of large file sizes
scsi: iscsi: Fix incorrect error path labels for flashnode operations
net_sched: sch_sfq: fix a potential crash on gso_skb handling
i40e: return false from i40e_reset_vf if reset is in progress
i40e: retry VFLR handling if there is ongoing VF reset
net/mlx5: Wait for inactive autogroups
net/mlx5: Fix return value when searching for existing flow group
net_sched: prio: fix a race in prio_tune()
net_sched: red: fix a race in __red_change()
net_sched: tbf: fix a race in tbf_change()
net: mdio: C22 is now optional, EOPNOTSUPP if not provided
x86/boot/compressed: prefer cc-option for CFLAGS additions
MIPS: Move '-Wa,-msoft-float' check from as-option to cc-option
drm/amd/display: Do not add '-mhard-float' to dml_ccflags for clang
drm/amd/display: Do not add '-mhard-float' to dcn2{1,0}_resource.o for clang
net/mdiobus: Fix potential out-of-bounds read/write access
fs/filesystems: Fix potential unsigned integer underflow in fs_name()
usb: Flush altsetting 0 endpoints before reinitializating them after reset.
xen/arm: call uaccess_ttbr0_enable for dm_op hypercall
calipso: unlock rcu before returning -EAFNOSUPPORT
net: usb: aqc111: debug info before sanitation
configfs: Do not override creating attribute file failure in populate_attrs()
gfs2: move msleep to sleepable context
wifi: p54: prevent buffer-overflow in p54_rx_eeprom_readback()
nfsd: nfsd4_spo_must_allow() must check this is a v4 compound request
wifi: rtlwifi: disable ASPM for RTL8723BE with subsystem ID 11ad:1723
media: gspca: Add error handling for stv06xx_read_sensor()
media: v4l2-dev: fix error handling in __video_register_device()
ARM: 9447/1: arm/memremap: fix arch_memremap_can_ram_remap()
ata: pata_via: Force PIO for ATAPI devices on VT6415/VT6330
bus: fsl-mc: do not add a device-link for the UAPI used DPMCP device
ext4: inline: fix len overflow in ext4_prepare_inline_data
ext4: fix calculation of credits for extent tree modification
Input: ims-pcu - check record size in ims_pcu_flash_firmware()
f2fs: prevent kernel warning due to negative i_nlink from corrupted image
NFC: nci: uart: Set tty->disc_data only in success path
EDAC/altera: Use correct write width with the INTTEST register
fbdev: Fix fb_set_var to prevent null-ptr-deref in fb_videomode_to_var
vgacon: Add check for vc_origin address range in vgacon_scroll()
parisc: fix building with gcc-15
ipc: fix to protect IPCS lookups using RCU
mm: fix ratelimit_pages update error in dirty_ratio_handler()
mtd: rawnand: sunxi: Add randomizer configuration in sunxi_nfc_hw_ecc_write_chunk
mtd: nand: sunxi: Add randomizer configuration before randomizer enable
dm-mirror: fix a tiny race condition
ftrace: Fix UAF when lookup kallsym after ftrace disabled
net: ch9200: fix uninitialised access during mii_nway_restart
staging: iio: ad5933: Correct settling cycles encoding per datasheet
mips: Add -std= flag specified in KBUILD_CFLAGS to vdso CFLAGS
regulator: max14577: Add error check for max14577_read_reg()
uio_hv_generic: Use correct size for interrupt and monitor pages
PCI: Add ACS quirk for Loongson PCIe
PCI: Fix lock symmetry in pci_slot_unlock()
iio: adc: ad7606_spi: fix reg write value mask
ACPICA: fix acpi operand cache leak in dswstate.c
ACPICA: Avoid sequence overread in call to strncmp()
ACPICA: fix acpi parse and parseext cache leaks
power: supply: bq27xxx: Retrieve again when busy
PM: runtime: fix denying of auto suspend in pm_suspend_timer_fn()
ACPI: battery: negate current when discharging
drm/amdgpu/gfx6: fix CSIB handling
sunrpc: update nextcheck time when adding new cache entries
drm/bridge: analogix_dp: Add irq flag IRQF_NO_AUTOEN instead of calling disable_irq()
drm/msm/hdmi: add runtime PM calls to DDC transfer function
media: uapi: v4l: Fix V4L2_TYPE_IS_OUTPUT condition
drm/amd/display: Add NULL pointer checks in dm_force_atomic_commit()
drm/msm/a6xx: Increase HFI response timeout
drm/amdgpu/gfx10: fix CSIB handling
drm/amdgpu/gfx7: fix CSIB handling
jfs: fix array-index-out-of-bounds read in add_missing_indices
drm/amdgpu/gfx8: fix CSIB handling
drm/amdgpu/gfx9: fix CSIB handling
jfs: Fix null-ptr-deref in jfs_ioc_trim
drm/amdkfd: Set SDMA_RLCx_IB_CNTL/SWITCH_INSIDE_IB
media: tc358743: ignore video while HPD is low
media: platform: exynos4-is: Add hardware sync wait to fimc_is_hw_change_mode()
nios2: force update_mmu_cache on spurious tlb-permission--related pagefaults
cpufreq: Force sync policy boost with global boost on sysfs update
net: macb: Check return value of dma_set_mask_and_coherent()
i2c: designware: Invoke runtime suspend on quick slave re-registration
emulex/benet: correct command version selection in be_cmd_get_stats()
sctp: Do not wake readers in __sctp_write_space()
net: dlink: add synchronization for stats update
tcp: always seek for minimal rtt in tcp_rcv_rtt_update()
tcp: fix initial tp->rcvq_space.space value for passive TS enabled flows
ipv4/route: Use this_cpu_inc() for stats on PREEMPT_RT
pinctrl: armada-37xx: propagate error from armada_37xx_pmx_set_by_name()
pinctrl: armada-37xx: propagate error from armada_37xx_gpio_get_direction()
pinctrl: armada-37xx: propagate error from armada_37xx_pmx_gpio_set_direction()
pinctrl: armada-37xx: propagate error from armada_37xx_gpio_get()
net: mlx4: add SOF_TIMESTAMPING_TX_SOFTWARE flag when getting ts info
wifi: mac80211: do not offer a mesh path if forwarding is disabled
clk: rockchip: rk3036: mark ddrphy as critical
vxlan: Do not treat dst cache initialization errors as fatal
scsi: lpfc: Use memcpy() for BIOS version
sock: Correct error checking condition for (assign|release)_proto_idx()
i40e: fix MMIO write access to an invalid page in i40e_clear_hw
watchdog: da9052_wdt: respect TWDMIN
bus: fsl-mc: increase MC_CMD_COMPLETION_TIMEOUT_MS value
ARM: OMAP2+: Fix l4ls clk domain handling in STANDBY
tee: Prevent size calculation wraparound on 32-bit kernels
Revert "bus: ti-sysc: Probe for l4_wkup and l4_cfg interconnect devices first"
platform: Add Surface platform directory
platform/x86: dell_rbu: Stop overwriting data buffer
powerpc/eeh: Fix missing PE bridge reconfiguration during VFIO EEH recovery
Revert "x86/bugs: Make spectre user default depend on MITIGATION_SPECTRE_V2" on v6.6 and older
drivers/rapidio/rio_cm.c: prevent possible heap overwrite
jffs2: check that raw node were preallocated before writing summary
jffs2: check jffs2_prealloc_raw_node_refs() result in few other places
scsi: storvsc: Increase the timeouts to storvsc_timeout
scsi: s390: zfcp: Ensure synchronous unit_add
selinux: fix selinux_xfrm_alloc_user() to set correct ctx_len
atm: Revert atm_account_tx() if copy_from_iter_full() fails.
HID: usbhid: Eliminate recurrent out-of-bounds bug in usbhid_parse()
Input: sparcspkr - avoid unannotated fall-through
ALSA: hda/intel: Add Thinkpad E15 to PM deny list
ALSA: hda/realtek: enable headset mic on Latitude 5420 Rugged
erofs: remove unused trace event erofs_destroy_inode
drm/nouveau/bl: increase buffer size to avoid truncate warning
hwmon: (occ) fix unaligned accesses
aoe: clean device rq_list in aoedev_downdev()
wifi: carl9170: do not ping device which has failed to load firmware
mpls: Use rcu_dereference_rtnl() in mpls_route_input_rcu().
atm: atmtcp: Free invalid length skb in atmtcp_c_send().
tcp: fix tcp_packet_delayed() for tcp_is_non_sack_preventing_reopen() behavior
tipc: fix null-ptr-deref when acquiring remote ip of ethernet bearer
calipso: Fix null-ptr-deref in calipso_req_{set,del}attr().
net: atm: add lec_mutex
net: atm: fix /proc/net/atm/lec handling
ARM: dts: am335x-bone-common: Add GPIO PHY reset on revision C3 board
ARM: dts: am335x-bone-common: Increase MDIO reset deassert time
ARM: dts: am335x-bone-common: Increase MDIO reset deassert delay to 50ms
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
xprtrdma: fix pointer derefs in error cases of rpcrdma_ep_create
rtc: Improve performance of rtc_time64_to_tm(). Add tests.
rtc: Make rtc_time64_to_tm() support dates before 1970
mm/huge_memory: fix dereferencing invalid pmd migration entry
jbd2: fix data-race and null-ptr-deref in jbd2_journal_dirty_metadata()
rtc: test: Fix invalid format specifier.
s390/pci: Fix __pcilg_mio_inuser() inline assembly
perf: Fix sample vs do_exit()
arm64/ptrace: Fix stack-out-of-bounds read in regs_get_kernel_stack_nth()
scsi: qedf: Use designated initializer for struct qed_fcoe_cb_ops
Linux 5.4.295
Change-Id: I44ee88afdff6b4865efac55635f7529a2d9715e8
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
|
||
|
|
691948d565 |
Merge tag 'ASB-2025-06-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
https://source.android.com/docs/security/bulletin/2025-06-01 * tag 'ASB-2025-06-05_11-5.4' of https://android.googlesource.com/kernel/common: ANDROID: binder: fix minimum node priority comparison ANDROID: 16K: Remove ELF padding entry from map_file ranges Linux 5.4.293 MIPS: cm: Fix warning if MIPS_CM is disabled crypto: atmel-sha204a - Set hwrng quality to lowest possible comedi: jr3_pci: Fix synchronous deletion of timer md/raid1: Add check for missing source disk in process_checks() scsi: pm80xx: Set phy_attached to zero when device is gone x86/bugs: Don't fill RSB on VMEXIT with eIBRS+retpoline ACPI PPTT: Fix coding mistakes in a couple of sizeof() calls selftests: ublk: fix test_stripe_04 udmabuf: fix a buf size overflow issue during udmabuf creation KVM: s390: Don't use %pK through tracepoints sched/isolation: Make CONFIG_CPU_ISOLATION depend on CONFIG_SMP ntb: reduce stack usage in idt_scan_mws qibfs: fix _another_ leak usb: gadget: aspeed: Add NULL pointer check in ast_vhub_init_dev() dmaengine: dmatest: Fix dmatest waiting less when interrupted usb: host: max3421-hcd: Add missing spi_device_id table parisc: PDT: Fix missing prototype warning clk: check for disabled clock-provider in of_clk_get_hw_from_clkspec() crypto: null - Use spin lock instead of mutex MIPS: cm: Detect CM quirks from device tree USB: VLI disk crashes if LPM is used usb: quirks: Add delay init quirk for SanDisk 3.2Gen1 Flash Drive usb: quirks: add DELAY_INIT quirk for Silicon Motion Flash Drive usb: dwc3: gadget: check that event count does not exceed event buffer length USB: OHCI: Add quirk for LS7A OHCI controller (rev 0x02) usb: cdns3: Fix deadlock when using NCM gadget USB: serial: simple: add OWON HDS200 series oscilloscope support USB: serial: option: add Sierra Wireless EM9291 USB: serial: ftdi_sio: add support for Abacus Electrics Optical Probe serial: sifive: lock port in startup()/shutdown() callbacks USB: storage: quirk for ADATA Portable HDD CH94 mcb: fix a double free bug in chameleon_parse_gdd() virtio_console: fix missing byte order handling for cols and rows net_sched: hfsc: Fix a potential UAF in hfsc_dequeue() too net_sched: hfsc: Fix a UAF vulnerability in class handling tipc: fix NULL pointer dereference in tipc_mon_reinit_self() net: phy: leds: fix memory leak cpufreq: scpi: Fix null-ptr-deref in scpi_cpufreq_get_rate() drm/amd/pm: Prevent division by zero misc: pci_endpoint_test: Fix displaying 'irq_type' after 'request_irq' error misc: pci_endpoint_test: Use INTX instead of LEGACY PCI: Rename PCI_IRQ_LEGACY to PCI_IRQ_INTX iio: adc: ad7768-1: Fix conversion result sign iio: adc: ad7768-1: Move setting of val a bit later to avoid unnecessary return value check net: dsa: mv88e6xxx: fix VTU methods for 6320 family media: vim2m: print device name after registering device ext4: fix OOB read when checking dotdot dir ext4: optimize __ext4_check_dir_entry() ext4: don't over-report free space or inodes in statvfs ext4: code cleanup for ext4_statfs_project() ext4: simplify checking quota limits in ext4_statfs() platform/x86: ISST: Correct command storage data length MIPS: ds1287: Match ds1287_set_base_clock() function types MIPS: cevt-ds1287: Add missing ds1287.h include MIPS: dec: Declare which_prom() as static virtio-net: Add validation for used length RDMA/srpt: Support specifying the srpt_service_guid parameter openvswitch: fix lockup on tx to unregistering netdev with carrier net: openvswitch: fix race on port output mmc: cqhci: Fix checking of CQHCI_HALT state nvmet-fc: Remove unused functions usb: dwc3: support continuous runtime PM with dual role misc: pci_endpoint_test: Fix 'irq_type' to convey the correct type misc: pci_endpoint_test: Avoid issue of interrupts remaining after request_irq error tcp/dccp: Don't use timer_pending() in reqsk_queue_unlink(). powerpc/prom_init: Use -ffreestanding to avoid a reference to bcmp kbuild: Add '-fno-builtin-wcslen' cpufreq: Reference count policy in cpufreq_update_limits() drm/sti: remove duplicate object names drm/nouveau: prime: fix ttm_bo_delayed_delete oops drm/repaper: fix integer overflows in repeat functions module: sign with sha512 instead of sha1 by default perf/x86/intel/uncore: Fix the scale of IIO free running counters on SNR perf/x86/intel: Allow to update user space GPRs from PEBS records virtiofs: add filesystem context source name check riscv: Avoid fortify warning in syscall_get_arguments() isofs: Prevent the use of too small fid i2c: cros-ec-tunnel: defer probe if parent EC is not present hfs/hfsplus: fix slab-out-of-bounds in hfs_bnode_read_key btrfs: correctly escape subvol in btrfs_show_options() nfs: add missing selections of CONFIG_CRC32 nfs: move nfs_fhandle_hash to common include file NFSD: Constify @fh argument of knfsd_fh_hash() asus-laptop: Fix an uninitialized variable writeback: fix false warning in inode_to_wb() net: b53: enable BPDU reception for management port net: openvswitch: fix nested key length validation in the set() action Revert "wifi: mac80211: Update skb's control block key in ieee80211_tx_dequeue()" Bluetooth: btrtl: Prevent potential NULL dereference Bluetooth: hci_event: Fix sending MGMT_EV_DEVICE_FOUND for invalid address RDMA/usnic: Fix passing zero to PTR_ERR in usnic_ib_pci_probe() scsi: iscsi: Fix missing scsi_host_put() in error path wifi: wl1251: fix memory leak in wl1251_tx_work wifi: mac80211: Purge vif txq in ieee80211_do_stop() wifi: mac80211: Update skb's control block key in ieee80211_tx_dequeue() wifi: at76c50x: fix use after free access in at76_disconnect HSI: ssi_protocol: Fix use after free vulnerability in ssi_protocol Driver Due to Race Condition pwm: mediatek: always use bus clock for PWM on MT7622 Bluetooth: hci_uart: Fix another race during initialization x86/e820: Fix handling of subpage regions when calculating nosave ranges in e820__register_nosave_regions() PCI: Fix reference leak in pci_alloc_child_bus() of/irq: Fix device node refcount leakages in of_irq_init() of/irq: Fix device node refcount leakage in API irq_of_parse_and_map() of/irq: Fix device node refcount leakages in of_irq_count() ntb: use 64-bit arithmetic for the MSI doorbell mask gpio: zynq: Fix wakeup source leaks on device unbind ftrace: Add cond_resched() to ftrace_graph_set_hash() dm-integrity: set ti->error on memory allocation failure crypto: ccp - Fix check for the primary ASP device thermal/drivers/rockchip: Add missing rk3328 mapping entry sctp: detect and prevent references to a freed transport in sendmsg mm: add missing release barrier on PGDAT_RECLAIM_LOCKED unlock sparc/mm: disable preemption in lazy mmu mode arm64: dts: mediatek: mt8173: Fix disp-pwm compatible string mtd: rawnand: Add status chack in r852_ready() mtd: inftlcore: Add error check for inftl_read_oob() lib: scatterlist: fix sg_split_phys to preserve original scatterlist offsets locking/lockdep: Decrease nr_unused_locks if lock unused in zap_class() jbd2: remove wrong sb->s_sequence check i3c: Add NULL pointer check in i3c_master_queue_ibi() ext4: fix off-by-one error in do_split wifi: mac80211: fix integer overflow in hwmp_route_info_get() net: dsa: mv88e6xxx: workaround RGMII transmit delay erratum for 6320 family media: venus: hfi_parser: add check to avoid out of bound access media: i2c: ov7251: Introduce 1 ms delay between regulators and en GPIO media: i2c: ov7251: Set enable GPIO low in probe media: v4l2-dv-timings: prevent possible overflow in v4l2_detect_gtf() media: streamzap: prevent processing IR data on URB failure mtd: rawnand: brcmnand: fix PM resume warning arm64: cputype: Add MIDR_CORTEX_A76AE xenfs/xensyms: respect hypervisor's "next" indication media: siano: Fix error handling in smsdvb_module_init() media: venus: hfi: add check to handle incorrect queue size media: venus: hfi: add a check to handle OOB in sfr region media: i2c: adv748x: Fix test pattern selection mask ext4: don't treat fhandle lookup of ea_inode as FS corruption ext4: reject casefold inode flag without casefold feature bpf: support SKF_NET_OFF and SKF_LL_OFF on skb frags bpf: Add endian modifiers to fix endian warnings pwm: fsl-ftm: Handle clk_get_rate() returning 0 pwm: mediatek: Prevent divide-by-zero in pwm_mediatek_config() pwm: mediatek: Always use bus clock fbdev: omapfb: Add 'plane' value check drm/mediatek: mtk_dpi: Explicitly manage TVD clock in power on/off drm/amdkfd: Fix pqm_destroy_queue race with GPU reset drm/amdkfd: clamp queue size to minimum drm: panel-orientation-quirks: Add new quirk for GPD Win 2 drm: panel-orientation-quirks: Add support for AYANEO 2S drm: allow encoder mode_set even when connectors change for crtc Bluetooth: hci_uart: fix race during initialization tracing: fix return value in __ftrace_event_enable_disable for TRACE_REG_UNREGISTER net: vlan: don't propagate flags on open wifi: mt76: mt76x2u: add TP-Link TL-WDN6200 ID to device table scsi: st: Fix array overflow in st_setup() ext4: ignore xattrs past end ext4: protect ext4_release_dquot against freezing ahci: add PCI ID for Marvell 88SE9215 SATA Controller ata: libata-eh: Do not use ATAPI DMA for a device limited to PIO mode jfs: add sanity check for agwidth in dbMount jfs: Prevent copying of nlink with value 0 from disk inode fs/jfs: Prevent integer overflow in AG size calculation fs/jfs: cast inactags to s64 to prevent potential overflow page_pool: avoid infinite loop to schedule delayed worker ALSA: usb-audio: Fix CME quirk for UF series keyboards ALSA: hda: intel: Fix Optimus when GPU has no sound HID: pidff: Fix null pointer dereference in pidff_find_fields HID: pidff: Do not send effect envelope if it's empty HID: pidff: Convert infinite length from Linux API to PID standard xen/mcelog: Add __nonstring annotations for unterminated strings perf: arm_pmu: Don't disable counter in armpmu_add() x86/cpu: Don't clear X86_FEATURE_LAHF_LM flag in init_amd_k8() on AMD when running in a virtual machine pm: cpupower: bench: Prevent NULL dereference on malloc failure net: ppp: Add bound checking for skb data on ppp_sync_txmung ata: sata_sx4: Add error handling in pdc20621_i2c_read() ata: sata_sx4: Drop pointless VPRINTK() calls and convert the remaining ones tipc: fix memory leak in tipc_link_xmit ata: pata_pxa: Fix potential NULL pointer dereference in pxa_ata_probe() Conflicts: arch/arm64/include/asm/cputype.h drivers/usb/core/quirks.c drivers/usb/dwc3/gadget.c Change-Id: Ie734fa9555f5cdd3575d8b29f71ab946102b5f84 |
||
|
|
39ed7800f9 |
Linux 5.4.295
Link: https://lore.kernel.org/r/20250623130611.896514667@linuxfoundation.org Tested-by: Florian Fainelli <florian.fainelli@broadcom.com> Tested-by: Alok Tiwari <alok.a.tiwari@oracle.com> Link: https://lore.kernel.org/r/20250625085227.279764371@linuxfoundation.org Tested-by: Jon Hunter <jonathanh@nvidia.com> Tested-by: Florian Fainelli <florian.fainelli@broadcom.com> Tested-by: Linux Kernel Functional Testing <lkft@linaro.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
||
|
|
5d84869995 |
scsi: qedf: Use designated initializer for struct qed_fcoe_cb_ops
commit d8720235d5b5cad86c1f07f65117ef2a96f8bec7 upstream.
Recent fixes to the randstruct GCC plugin allowed it to notice
that this structure is entirely function pointers and is therefore
subject to randomization, but doing so requires that it always use
designated initializers. Explicitly specify the "common" member as being
initialized. Silences:
drivers/scsi/qedf/qedf_main.c:702:9: error: positional initialization of field in 'struct' declared with 'designated_init' attribute [-Werror=designated-init]
702 | {
| ^
Fixes: 035f7f87b729 ("randstruct: Enable Clang support")
Link: https://lore.kernel.org/r/20250502224156.work.617-kees@kernel.org
Signed-off-by: Kees Cook <kees@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
|
||
|
|
64773b3ea0 |
arm64/ptrace: Fix stack-out-of-bounds read in regs_get_kernel_stack_nth()
[ Upstream commit 39dfc971e42d886e7df01371cd1bef505076d84c ]
KASAN reports a stack-out-of-bounds read in regs_get_kernel_stack_nth().
Call Trace:
[ 97.283505] BUG: KASAN: stack-out-of-bounds in regs_get_kernel_stack_nth+0xa8/0xc8
[ 97.284677] Read of size 8 at addr ffff800089277c10 by task 1.sh/2550
[ 97.285732]
[ 97.286067] CPU: 7 PID: 2550 Comm: 1.sh Not tainted 6.6.0+ #11
[ 97.287032] Hardware name: linux,dummy-virt (DT)
[ 97.287815] Call trace:
[ 97.288279] dump_backtrace+0xa0/0x128
[ 97.288946] show_stack+0x20/0x38
[ 97.289551] dump_stack_lvl+0x78/0xc8
[ 97.290203] print_address_description.constprop.0+0x84/0x3c8
[ 97.291159] print_report+0xb0/0x280
[ 97.291792] kasan_report+0x84/0xd0
[ 97.292421] __asan_load8+0x9c/0xc0
[ 97.293042] regs_get_kernel_stack_nth+0xa8/0xc8
[ 97.293835] process_fetch_insn+0x770/0xa30
[ 97.294562] kprobe_trace_func+0x254/0x3b0
[ 97.295271] kprobe_dispatcher+0x98/0xe0
[ 97.295955] kprobe_breakpoint_handler+0x1b0/0x210
[ 97.296774] call_break_hook+0xc4/0x100
[ 97.297451] brk_handler+0x24/0x78
[ 97.298073] do_debug_exception+0xac/0x178
[ 97.298785] el1_dbg+0x70/0x90
[ 97.299344] el1h_64_sync_handler+0xcc/0xe8
[ 97.300066] el1h_64_sync+0x78/0x80
[ 97.300699] kernel_clone+0x0/0x500
[ 97.301331] __arm64_sys_clone+0x70/0x90
[ 97.302084] invoke_syscall+0x68/0x198
[ 97.302746] el0_svc_common.constprop.0+0x11c/0x150
[ 97.303569] do_el0_svc+0x38/0x50
[ 97.304164] el0_svc+0x44/0x1d8
[ 97.304749] el0t_64_sync_handler+0x100/0x130
[ 97.305500] el0t_64_sync+0x188/0x190
[ 97.306151]
[ 97.306475] The buggy address belongs to stack of task 1.sh/2550
[ 97.307461] and is located at offset 0 in frame:
[ 97.308257] __se_sys_clone+0x0/0x138
[ 97.308910]
[ 97.309241] This frame has 1 object:
[ 97.309873] [48, 184) 'args'
[ 97.309876]
[ 97.310749] The buggy address belongs to the virtual mapping at
[ 97.310749] [ffff800089270000, ffff800089279000) created by:
[ 97.310749] dup_task_struct+0xc0/0x2e8
[ 97.313347]
[ 97.313674] The buggy address belongs to the physical page:
[ 97.314604] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x14f69a
[ 97.315885] flags: 0x15ffffe00000000(node=1|zone=2|lastcpupid=0xfffff)
[ 97.316957] raw: 015ffffe00000000 0000000000000000 dead000000000122 0000000000000000
[ 97.318207] raw: 0000000000000000 0000000000000000 00000001ffffffff 0000000000000000
[ 97.319445] page dumped because: kasan: bad access detected
[ 97.320371]
[ 97.320694] Memory state around the buggy address:
[ 97.321511] ffff800089277b00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[ 97.322681] ffff800089277b80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[ 97.323846] >ffff800089277c00: 00 00 f1 f1 f1 f1 f1 f1 00 00 00 00 00 00 00 00
[ 97.325023] ^
[ 97.325683] ffff800089277c80: 00 00 00 00 00 00 00 00 00 f3 f3 f3 f3 f3 f3 f3
[ 97.326856] ffff800089277d00: f3 f3 00 00 00 00 00 00 00 00 00 00 00 00 00 00
This issue seems to be related to the behavior of some gcc compilers and
was also fixed on the s390 architecture before:
commit d93a855c31b7 ("s390/ptrace: Avoid KASAN false positives in regs_get_kernel_stack_nth()")
As described in that commit, regs_get_kernel_stack_nth() has confirmed that
`addr` is on the stack, so reading the value at `*addr` should be allowed.
Use READ_ONCE_NOCHECK() helper to silence the KASAN check for this case.
Fixes:
|
||
|
|
7b8f3c7217 |
perf: Fix sample vs do_exit()
[ Upstream commit 4f6fc782128355931527cefe3eb45338abd8ab39 ]
Baisheng Gao reported an ARM64 crash, which Mark decoded as being a
synchronous external abort -- most likely due to trying to access
MMIO in bad ways.
The crash further shows perf trying to do a user stack sample while in
exit_mmap()'s tlb_finish_mmu() -- i.e. while tearing down the address
space it is trying to access.
It turns out that we stop perf after we tear down the userspace mm; a
receipie for disaster, since perf likes to access userspace for
various reasons.
Flip this order by moving up where we stop perf in do_exit().
Additionally, harden PERF_SAMPLE_CALLCHAIN and PERF_SAMPLE_STACK_USER
to abort when the current task does not have an mm (exit_mm() makes
sure to set current->mm = NULL; before commencing with the actual
teardown). Such that CPU wide events don't trip on this same problem.
Fixes:
|
||
|
|
cc2f923e92 |
s390/pci: Fix __pcilg_mio_inuser() inline assembly
commit c4abe6234246c75cdc43326415d9cff88b7cf06c upstream.
Use "a" constraint for the shift operand of the __pcilg_mio_inuser() inline
assembly. The used "d" constraint allows the compiler to use any general
purpose register for the shift operand, including register zero.
If register zero is used this my result in incorrect code generation:
8f6: a7 0a ff f8 ahi %r0,-8
8fa: eb 32 00 00 00 0c srlg %r3,%r2,0 <----
If register zero is selected to contain the shift value, the srlg
instruction ignores the contents of the register and always shifts zero
bits. Therefore use the "a" constraint which does not permit to select
register zero.
Fixes: f058599e22d5 ("s390/pci: Fix s390_mmio_read/write with MIO")
Cc: stable@vger.kernel.org
Reported-by: Niklas Schnelle <schnelle@linux.ibm.com>
Reviewed-by: Niklas Schnelle <schnelle@linux.ibm.com>
Signed-off-by: Heiko Carstens <hca@linux.ibm.com>
Signed-off-by: Niklas Schnelle <schnelle@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
|
||
|
|
b9dc8b84b9 |
rtc: test: Fix invalid format specifier.
commit 8a904a3caa88118744062e872ae90f37748a8fd8 upstream.
'days' is a s64 (from div_s64), and so should use a %lld specifier.
This was found by extending KUnit's assertion macros to use gcc's
__printf attribute.
Fixes: 1d1bb12a8b18 ("rtc: Improve performance of rtc_time64_to_tm(). Add tests.")
Signed-off-by: David Gow <davidgow@google.com>
Tested-by: Guenter Roeck <linux@roeck-us.net>
Reviewed-by: Justin Stitt <justinstitt@google.com>
Acked-by: Alexandre Belloni <alexandre.belloni@bootlin.com>
Signed-off-by: Shuah Khan <skhan@linuxfoundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
|
||
|
|
5c1a34ff5b |
jbd2: fix data-race and null-ptr-deref in jbd2_journal_dirty_metadata()
commit af98b0157adf6504fade79b3e6cb260c4ff68e37 upstream.
Since handle->h_transaction may be a NULL pointer, so we should change it
to call is_handle_aborted(handle) first before dereferencing it.
And the following data-race was reported in my fuzzer:
==================================================================
BUG: KCSAN: data-race in jbd2_journal_dirty_metadata / jbd2_journal_dirty_metadata
write to 0xffff888011024104 of 4 bytes by task 10881 on cpu 1:
jbd2_journal_dirty_metadata+0x2a5/0x770 fs/jbd2/transaction.c:1556
__ext4_handle_dirty_metadata+0xe7/0x4b0 fs/ext4/ext4_jbd2.c:358
ext4_do_update_inode fs/ext4/inode.c:5220 [inline]
ext4_mark_iloc_dirty+0x32c/0xd50 fs/ext4/inode.c:5869
__ext4_mark_inode_dirty+0xe1/0x450 fs/ext4/inode.c:6074
ext4_dirty_inode+0x98/0xc0 fs/ext4/inode.c:6103
....
read to 0xffff888011024104 of 4 bytes by task 10880 on cpu 0:
jbd2_journal_dirty_metadata+0xf2/0x770 fs/jbd2/transaction.c:1512
__ext4_handle_dirty_metadata+0xe7/0x4b0 fs/ext4/ext4_jbd2.c:358
ext4_do_update_inode fs/ext4/inode.c:5220 [inline]
ext4_mark_iloc_dirty+0x32c/0xd50 fs/ext4/inode.c:5869
__ext4_mark_inode_dirty+0xe1/0x450 fs/ext4/inode.c:6074
ext4_dirty_inode+0x98/0xc0 fs/ext4/inode.c:6103
....
value changed: 0x00000000 -> 0x00000001
==================================================================
This issue is caused by missing data-race annotation for jh->b_modified.
Therefore, the missing annotation needs to be added.
Reported-by: syzbot+de24c3fe3c4091051710@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=de24c3fe3c4091051710
Fixes:
|
||
|
|
753f142f7f |
mm/huge_memory: fix dereferencing invalid pmd migration entry
commit be6e843fc51a584672dfd9c4a6a24c8cb81d5fb7 upstream.
When migrating a THP, concurrent access to the PMD migration entry during
a deferred split scan can lead to an invalid address access, as
illustrated below. To prevent this invalid access, it is necessary to
check the PMD migration entry and return early. In this context, there is
no need to use pmd_to_swp_entry and pfn_swap_entry_to_page to verify the
equality of the target folio. Since the PMD migration entry is locked, it
cannot be served as the target.
Mailing list discussion and explanation from Hugh Dickins: "An anon_vma
lookup points to a location which may contain the folio of interest, but
might instead contain another folio: and weeding out those other folios is
precisely what the "folio != pmd_folio((*pmd)" check (and the "risk of
replacing the wrong folio" comment a few lines above it) is for."
BUG: unable to handle page fault for address: ffffea60001db008
CPU: 0 UID: 0 PID: 2199114 Comm: tee Not tainted 6.14.0+ #4 NONE
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
RIP: 0010:split_huge_pmd_locked+0x3b5/0x2b60
Call Trace:
<TASK>
try_to_migrate_one+0x28c/0x3730
rmap_walk_anon+0x4f6/0x770
unmap_folio+0x196/0x1f0
split_huge_page_to_list_to_order+0x9f6/0x1560
deferred_split_scan+0xac5/0x12a0
shrinker_debugfs_scan_write+0x376/0x470
full_proxy_write+0x15c/0x220
vfs_write+0x2fc/0xcb0
ksys_write+0x146/0x250
do_syscall_64+0x6a/0x120
entry_SYSCALL_64_after_hwframe+0x76/0x7e
The bug is found by syzkaller on an internal kernel, then confirmed on
upstream.
Link: https://lkml.kernel.org/r/20250421113536.3682201-1-gavinguo@igalia.com
Link: https://lore.kernel.org/all/20250414072737.1698513-1-gavinguo@igalia.com/
Link: https://lore.kernel.org/all/20250418085802.2973519-1-gavinguo@igalia.com/
Fixes:
|
||
|
|
afef20f488 |
rtc: Make rtc_time64_to_tm() support dates before 1970
commit 7df4cfef8b351fec3156160bedfc7d6d29de4cce upstream. Conversion of dates before 1970 is still relevant today because these dates are reused on some hardwares to store dates bigger than the maximal date that is representable in the device's native format. This prominently and very soon affects the hardware covered by the rtc-mt6397 driver that can only natively store dates in the interval 1900-01-01 up to 2027-12-31. So to store the date 2028-01-01 00:00:00 to such a device, rtc_time64_to_tm() must do the right thing for time=-2208988800. Signed-off-by: Alexandre Mergnat <amergnat@baylibre.com> Reviewed-by: Uwe Kleine-König <u.kleine-koenig@baylibre.com> Link: https://lore.kernel.org/r/20250428-enable-rtc-v4-1-2b2f7e3f9349@baylibre.com Signed-off-by: Alexandre Belloni <alexandre.belloni@bootlin.com> Signed-off-by: Uwe Kleine-König <u.kleine-koenig@baylibre.com> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
||
|
|
31d87dda79 |
rtc: Improve performance of rtc_time64_to_tm(). Add tests.
commit 1d1bb12a8b1805ddeef9793ebeb920179fb0fa38 upstream. The current implementation of rtc_time64_to_tm() contains unnecessary loops, branches and look-up tables. The new one uses an arithmetic-based algorithm appeared in [1] and is approximately 4.3 times faster (YMMV). The drawback is that the new code isn't intuitive and contains many 'magic numbers' (not unusual for this type of algorithm). However, [1] justifies all those numbers and, given this function's history, the code is unlikely to need much maintenance, if any at all. Add a KUnit test case that checks every day in a 160,000 years interval starting on 1970-01-01 against the expected result. Add a new config RTC_LIB_KUNIT_TEST symbol to give the option to run this test suite. [1] Neri, Schneider, "Euclidean Affine Functions and Applications to Calendar Algorithms". https://arxiv.org/abs/2102.06959 Signed-off-by: Cassio Neri <cassio.neri@gmail.com> Reported-by: kernel test robot <lkp@intel.com> Signed-off-by: Alexandre Belloni <alexandre.belloni@bootlin.com> Link: https://lore.kernel.org/r/20210624201343.85441-1-cassio.neri@gmail.com Signed-off-by: Uwe Kleine-König <u.kleine-koenig@baylibre.com> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
||
|
|
59892d18dd |
xprtrdma: fix pointer derefs in error cases of rpcrdma_ep_create
commit a9c10b5b3b67b3750a10c8b089b2e05f5e176e33 upstream. If there are failures then we must not leave the non-NULL pointers with the error value, otherwise `rpcrdma_ep_destroy` gets confused and tries free them, resulting in an Oops. Signed-off-by: Dan Aloni <dan.aloni@vastdata.com> Acked-by: Chuck Lever <chuck.lever@oracle.com> Signed-off-by: Anna Schumaker <Anna.Schumaker@Netapp.com> [ Larry: backport to 5.4.y. Minor conflict resolved due to missing commit 93aa8e0a9de80 xprtrdma: Merge struct rpcrdma_ia into struct rpcrdma_ep ] Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> Signed-off-by: Larry Bassel <larry.bassel@oracle.com> |
||
|
|
78a4b8e379 |
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
commit f90fff1e152dedf52b932240ebbd670d83330eca upstream.
If an exiting non-autoreaping task has already passed exit_notify() and
calls handle_posix_cpu_timers() from IRQ, it can be reaped by its parent
or debugger right after unlock_task_sighand().
If a concurrent posix_cpu_timer_del() runs at that moment, it won't be
able to detect timer->it.cpu.firing != 0: cpu_timer_task_rcu() and/or
lock_task_sighand() will fail.
Add the tsk->exit_state check into run_posix_cpu_timers() to fix this.
This fix is not needed if CONFIG_POSIX_CPU_TIMERS_TASK_WORK=y, because
exit_task_work() is called before exit_notify(). But the check still
makes sense, task_work_add(&tsk->posix_cputimers_work.work) will fail
anyway in this case.
Cc: stable@vger.kernel.org
Reported-by: Benoît Sevens <bsevens@google.com>
Fixes:
|
||
|
|
0fee1b2b48 |
ARM: dts: am335x-bone-common: Increase MDIO reset deassert delay to 50ms
commit 929d8490f8790164f5f63671c1c58d6c50411cb2 upstream.
Commit b9bf5612610aa7e3 ("ARM: dts: am335x-bone-common: Increase MDIO
reset deassert time") already increased the MDIO reset deassert delay
from 6.5 to 13 ms, but this may still cause Ethernet PHY probe failures:
SMSC LAN8710/LAN8720 4a101000.mdio:00: probe with driver SMSC LAN8710/LAN8720 failed with error -5
On BeagleBone Black Rev. C3, ETH_RESETn is controlled by an open-drain
AND gate. It is pulled high by a 10K resistor, and has a 4.7µF
capacitor to ground, giving an RC time constant of 47ms. As it takes
0.7RC to charge the capacitor above the threshold voltage of a CMOS
input (VDD/2), the delay should be at least 33ms. Considering the
typical tolerance of 20% on capacitors, 40ms would be safer. Add an
additional safety margin and settle for 50ms.
Signed-off-by: Geert Uytterhoeven <geert+renesas@glider.be>
Reviewed-by: Roger Quadros <rogerq@kernel.org>
Link: https://lore.kernel.org/r/9002a58daa1b2983f39815b748ee9d2f8dcc4829.1730366936.git.geert+renesas@glider.be
Signed-off-by: Kevin Hilman <khilman@baylibre.com>
Signed-off-by: Nobuhiro Iwamatsu (CIP) <nobuhiro1.iwamatsu@toshiba.co.jp>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
|
||
|
|
b9ffe75f36 |
ARM: dts: am335x-bone-common: Increase MDIO reset deassert time
commit b9bf5612610aa7e38d58fee16f489814db251c01 upstream.
Prior to commit df16c1c51d81 ("net: phy: mdio_device: Reset device only
when necessary") MDIO reset deasserts were performed twice during boot.
Now that the second deassert is no longer performed, device probe
failures happen due to the change in timing with the following error
message:
SMSC LAN8710/LAN8720: probe of 4a101000.mdio:00 failed with error -5
Restore the original effective timing, which resolves the probe
failures.
Signed-off-by: Colin Foster <colin.foster@in-advantage.com>
Link: https://lore.kernel.org/r/20240531183817.2698445-1-colin.foster@in-advantage.com
Signed-off-by: Kevin Hilman <khilman@baylibre.com>
Signed-off-by: Nobuhiro Iwamatsu (CIP) <nobuhiro1.iwamatsu@toshiba.co.jp>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
|
||
|
|
6a4c1721a7 |
ARM: dts: am335x-bone-common: Add GPIO PHY reset on revision C3 board
commit 623cef652768860bd5f205fb7b741be278585fba upstream. This patch adds ethernet PHY reset GPIO config for Beaglebone Black series boards with revision C3. This fixes a random phy startup failure bug discussed at [1]. The GPIO pin used for reset is not used on older revisions, so it is ok to apply to all board revisions. The reset timing was discussed and tested at [2]. [1] https://forum.digikey.com/t/ethernet-device-is-not-detecting-on-ubuntu-20-04-lts-on-bbg/19948 [2] https://forum.beagleboard.org/t/recognizing-a-beaglebone-black-rev-c3-board/31249/ Signed-off-by: Robert Nelson <robertcnelson@gmail.com> Signed-off-by: Shengyu Qu <wiagn233@outlook.com> Message-ID: <TY3P286MB26113797A3B2EC7E0348BBB2980FA@TY3P286MB2611.JPNP286.PROD.OUTLOOK.COM> Signed-off-by: Tony Lindgren <tony@atomide.com> Signed-off-by: Nobuhiro Iwamatsu (CIP) <nobuhiro1.iwamatsu@toshiba.co.jp> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
||
|
|
fcfccf56f4 |
net: atm: fix /proc/net/atm/lec handling
[ Upstream commit d03b79f459c7935cff830d98373474f440bd03ae ]
/proc/net/atm/lec must ensure safety against dev_lec[] changes.
It appears it had dev_put() calls without prior dev_hold(),
leading to imbalance and UAF.
Fixes:
|
||
|
|
e91274cc7e |
net: atm: add lec_mutex
[ Upstream commit d13a3824bfd2b4774b671a75cf766a16637a0e67 ]
syzbot found its way in net/atm/lec.c, and found an error path
in lecd_attach() could leave a dangling pointer in dev_lec[].
Add a mutex to protect dev_lecp[] uses from lecd_attach(),
lec_vcc_attach() and lec_mcast_attach().
Following patch will use this mutex for /proc/net/atm/lec.
BUG: KASAN: slab-use-after-free in lecd_attach net/atm/lec.c:751 [inline]
BUG: KASAN: slab-use-after-free in lane_ioctl+0x2224/0x23e0 net/atm/lec.c:1008
Read of size 8 at addr ffff88807c7b8e68 by task syz.1.17/6142
CPU: 1 UID: 0 PID: 6142 Comm: syz.1.17 Not tainted 6.16.0-rc1-syzkaller-00239-g08215f5486ec #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:94 [inline]
dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:120
print_address_description mm/kasan/report.c:408 [inline]
print_report+0xcd/0x680 mm/kasan/report.c:521
kasan_report+0xe0/0x110 mm/kasan/report.c:634
lecd_attach net/atm/lec.c:751 [inline]
lane_ioctl+0x2224/0x23e0 net/atm/lec.c:1008
do_vcc_ioctl+0x12c/0x930 net/atm/ioctl.c:159
sock_do_ioctl+0x118/0x280 net/socket.c:1190
sock_ioctl+0x227/0x6b0 net/socket.c:1311
vfs_ioctl fs/ioctl.c:51 [inline]
__do_sys_ioctl fs/ioctl.c:907 [inline]
__se_sys_ioctl fs/ioctl.c:893 [inline]
__x64_sys_ioctl+0x18e/0x210 fs/ioctl.c:893
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0xcd/0x4c0 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
</TASK>
Allocated by task 6132:
kasan_save_stack+0x33/0x60 mm/kasan/common.c:47
kasan_save_track+0x14/0x30 mm/kasan/common.c:68
poison_kmalloc_redzone mm/kasan/common.c:377 [inline]
__kasan_kmalloc+0xaa/0xb0 mm/kasan/common.c:394
kasan_kmalloc include/linux/kasan.h:260 [inline]
__do_kmalloc_node mm/slub.c:4328 [inline]
__kvmalloc_node_noprof+0x27b/0x620 mm/slub.c:5015
alloc_netdev_mqs+0xd2/0x1570 net/core/dev.c:11711
lecd_attach net/atm/lec.c:737 [inline]
lane_ioctl+0x17db/0x23e0 net/atm/lec.c:1008
do_vcc_ioctl+0x12c/0x930 net/atm/ioctl.c:159
sock_do_ioctl+0x118/0x280 net/socket.c:1190
sock_ioctl+0x227/0x6b0 net/socket.c:1311
vfs_ioctl fs/ioctl.c:51 [inline]
__do_sys_ioctl fs/ioctl.c:907 [inline]
__se_sys_ioctl fs/ioctl.c:893 [inline]
__x64_sys_ioctl+0x18e/0x210 fs/ioctl.c:893
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0xcd/0x4c0 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Freed by task 6132:
kasan_save_stack+0x33/0x60 mm/kasan/common.c:47
kasan_save_track+0x14/0x30 mm/kasan/common.c:68
kasan_save_free_info+0x3b/0x60 mm/kasan/generic.c:576
poison_slab_object mm/kasan/common.c:247 [inline]
__kasan_slab_free+0x51/0x70 mm/kasan/common.c:264
kasan_slab_free include/linux/kasan.h:233 [inline]
slab_free_hook mm/slub.c:2381 [inline]
slab_free mm/slub.c:4643 [inline]
kfree+0x2b4/0x4d0 mm/slub.c:4842
free_netdev+0x6c5/0x910 net/core/dev.c:11892
lecd_attach net/atm/lec.c:744 [inline]
lane_ioctl+0x1ce8/0x23e0 net/atm/lec.c:1008
do_vcc_ioctl+0x12c/0x930 net/atm/ioctl.c:159
sock_do_ioctl+0x118/0x280 net/socket.c:1190
sock_ioctl+0x227/0x6b0 net/socket.c:1311
vfs_ioctl fs/ioctl.c:51 [inline]
__do_sys_ioctl fs/ioctl.c:907 [inline]
__se_sys_ioctl fs/ioctl.c:893 [inline]
__x64_sys_ioctl+0x18e/0x210 fs/ioctl.c:893
Fixes:
|
||
|
|
956f149941 |
calipso: Fix null-ptr-deref in calipso_req_{set,del}attr().
[ Upstream commit 10876da918fa1aec0227fb4c67647513447f53a9 ] syzkaller reported a null-ptr-deref in sock_omalloc() while allocating a CALIPSO option. [0] The NULL is of struct sock, which was fetched by sk_to_full_sk() in calipso_req_setattr(). Since commit |