Commit graph

891,364 commits

Author SHA1 Message Date
Miklos Szeredi
3dbc1d366e UPSTREAM: ovl: simplify file splice
commit 82a763e61e2b601309d696d4fa514c77d64ee1be upstream.

generic_file_splice_read() and iter_file_splice_write() will call back into
f_op->iter_read() and f_op->iter_write() respectively.  These already do
the real file lookup and cred override.  So the code in ovl_splice_read()
and ovl_splice_write() is redundant.

In addition the ovl_file_accessed() call in ovl_splice_write() is
incorrect, though probably harmless.

Fix by calling generic_file_splice_read() and iter_file_splice_write()
directly.

Bug: 203035944
Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
[reported to resolve issues with 1a980b8cbf00 ("ovl: add splice file read write helper")]
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Change-Id: I1b3c7610b27faad8eefa91dead167ceaeb4ff0d8
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2021-10-20 10:35:34 +02:00
Greg Kroah-Hartman
5b84549191 Merge tag 'android11-5.4.147_r00' android11-5.4
This is the merge of the upstream LTS release of 5.4.147 into the
android11-5.4 branch.

It contains the following commits:

5e10f36746 Merge 5.4.147 into android11-5.4-lts
48a24510c3 Linux 5.4.147
1f8ee02449 Revert "time: Handle negative seconds correctly in timespec64_to_ns()"
dc15f641c6 Revert "posix-cpu-timers: Force next expiration recalc after itimer reset"
541e757944 Revert "block: nbd: add sanity check for first_minor"
5f3ecbf4d5 Revert "Bluetooth: Move shutdown callback before flushing tx and rx queue"
d756462d85 Merge 5.4.146 into android11-5.4-lts
245f15a48c Linux 5.4.146
b40facee46 clk: kirkwood: Fix a clocking boot regression
8810c51077 backlight: pwm_bl: Improve bootloader/kernel device handover
5de2ee621b fbmem: don't allow too huge resolutions
4a95b04afa IMA: remove the dependency on CRYPTO_MD5
c69935f0b0 IMA: remove -Wmissing-prototypes warning
85b0726d5b fuse: flush extending writes
8a98ced6e1 fuse: truncate pagecache on atomic_o_trunc
06dad664d4 KVM: nVMX: Unconditionally clear nested.pi_pending on nested VM-Enter
1735cec1e8 KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted
20fff3ef33 KVM: s390: index kvm->arch.idle_mask by vcpu_idx
0323ab5b25 x86/resctrl: Fix a maybe-uninitialized build warning treated as error
51f4575ca1 perf/x86/amd/ibs: Extend PERF_PMU_CAP_NO_EXCLUDE to IBS Op
03c3e977ee tty: Fix data race between tiocsti() and flush_to_ldisc()
7a25a0a94c time: Handle negative seconds correctly in timespec64_to_ns()
ae968e270f bpf: Fix pointer arithmetic mask tightening under state pruning
a0a4778fea bpf: verifier: Allocate idmap scratch in verifier env
f5893af270 bpf: Fix leakage due to insufficient speculative store bypass mitigation
e80c3533c3 bpf: Introduce BPF nospec instruction for mitigating Spectre v4
1c9424a765 ipv4: fix endianness issue in inet_rtm_getroute_build_skb()
b3fe6d1921 octeontx2-af: Fix loop in free and unmap counter
8216d7157b net: qualcomm: fix QCA7000 checksum handling
4648917e49 net: sched: Fix qdisc_rate_table refcount leak when get tcf_block failed
e46e23c289 ipv4: make exception cache less predictible
f73cbdd1b8 ipv6: make exception cache less predictible
aa167dcde4 brcmfmac: pcie: fix oops on failure to resume and reprobe
5debec63a2 bcma: Fix memory leak for internally-handled cores
574e563649 ath6kl: wmi: fix an error code in ath6kl_wmi_sync_point()
d946e685d6 ASoC: wcd9335: Disable irq on slave ports in the remove function
f3ec07f832 ASoC: wcd9335: Fix a memory leak in the error handling path of the probe function
a6088f4ed3 ASoC: wcd9335: Fix a double irq free in the remove function
7bfa680f3b tty: serial: fsl_lpuart: fix the wrong mapbase value
0f1375fa69 usb: bdc: Fix an error handling path in 'bdc_probe()' when no suitable DMA config is available
06203abb72 usb: ehci-orion: Handle errors of clk_prepare_enable() in probe
a0a9ecca2d i2c: mt65xx: fix IRQ check
b444064a0e CIFS: Fix a potencially linear read overflow
e37eeaf950 bpf: Fix possible out of bound write in narrow load handling
fb8e695e9c mmc: moxart: Fix issue with uninitialized dma_slave_config
48b1f117e8 mmc: dw_mmc: Fix issue with uninitialized dma_slave_config
57314d8414 ASoC: Intel: Skylake: Fix module resource and format selection
92397571c2 ASoC: Intel: Skylake: Leave data as is when invoking TLV IPCs
b58cf18e38 rsi: fix an error code in rsi_probe()
d82fe3dd0b rsi: fix error code in rsi_load_9116_firmware()
4be8deab6f i2c: s3c2410: fix IRQ check
da3e5f3204 i2c: iop3xx: fix deferred probing
2da3272ae0 Bluetooth: add timeout sanity check to hci_inquiry
70d71611eb mm/swap: consider max pages in iomap_swapfile_add_extent
8f5e26053c usb: gadget: mv_u3d: request_irq() after initializing UDC
eb3c6a2501 nfsd4: Fix forced-expiry locking
81e69d3fdd lockd: Fix invalid lockowner cast after vfs_test_lock
e1c02e2e6a mac80211: Fix insufficient headroom issue for AMSDU
606668e24a usb: phy: tahvo: add IRQ check
ecf18ac8ff usb: host: ohci-tmio: add IRQ check
abbcd61d09 Bluetooth: Move shutdown callback before flushing tx and rx queue
93ec1fd04f usb: gadget: udc: renesas_usb3: Fix soc_device_match() abuse
30d9607bcd usb: phy: twl6030: add IRQ checks
e1473ac285 usb: phy: fsl-usb: add IRQ check
9535f55d0c usb: gadget: udc: at91: add IRQ check
05e5b16b79 drm/msm/dsi: Fix some reference counted resource leaks
5ccb04c6e1 Bluetooth: fix repeated calls to sco_sock_kill
c2451d5439 counter: 104-quad-8: Return error when invalid mode during ceiling_write
a1194b805c arm64: dts: exynos: correct GIC CPU interfaces address range on Exynos7
1b6fcd1037 drm/msm/dpu: make dpu_hw_ctl_clear_all_blendstages clear necessary LMs
156eaacba3 PM: EM: Increase energy calculation precision
5537dc810b Bluetooth: increase BTNAMSIZ to 21 chars to fix potential buffer overflow
c0faa638f0 debugfs: Return error during {full/open}_proxy_open() on rmmod
f44714b4eb soc: qcom: smsm: Fix missed interrupts if state changes while masked
e7997fe3e9 PCI: PM: Enable PME if it can be signaled from D3cold
9e570f3d47 PCI: PM: Avoid forcing PCI_D0 for wakeup reasons inconsistently
f865b316cc media: venus: venc: Fix potential null pointer dereference on pointer fmt
d2ea2f0725 media: em28xx-input: fix refcount bug in em28xx_usb_disconnect
ebf570042b leds: trigger: audio: Add an activate callback to ensure the initial brightness is set
0a01dc7766 leds: lt3593: Put fwnode in any case during ->probe()
e39c73563a i2c: highlander: add IRQ check
fba783ddd9 net: cipso: fix warnings in netlbl_cipsov4_add_std
9fdac650c4 cgroup/cpuset: Fix a partition bug with hotplug
ffde058199 net/mlx5e: Prohibit inner indir TIRs in IPoIB
87f817c560 ARM: dts: meson8b: ec100: Fix the pwm regulator supply properties
e55d7cbe1f ARM: dts: meson8b: mxq: Fix the pwm regulator supply properties
4b0bbc412b ARM: dts: meson8b: odroidc1: Fix the pwm regulator supply properties
f7058060c0 ARM: dts: meson8: Use a higher default GPU clock frequency
37ed461b52 tcp: seq_file: Avoid skipping sk during tcp_seek_last_pos
9521362753 drm/amdgpu/acp: Make PM domain really work
252fad3d02 netns: protect netns ID lookups with RCU
bd1cd32caa 6lowpan: iphc: Fix an off-by-one check of array index
c4895cf45f Bluetooth: sco: prevent information leak in sco_conn_defer_accept()
a96eb96ce4 media: coda: fix frame_mem_ctrl for YUV420 and YVU420 formats
7163014d7d media: go7007: remove redundant initialization
8101492879 media: dvb-usb: Fix error handling in dvb_usb_i2c_init
fa8aaa7690 media: dvb-usb: fix uninit-value in vp702x_read_mac_addr
88933f9c93 media: dvb-usb: fix uninit-value in dvb_usb_adapter_dvb_init
f81c89614e soc: qcom: rpmhpd: Use corner in power_off
5b3987f583 arm64: dts: renesas: r8a77995: draak: Remove bogus adv7511w properties
6c106c7320 ARM: dts: aspeed-g6: Fix HVI3C function-group in pinctrl dtsi
004778bf39 bpf: Fix potential memleak and UAF in the verifier.
fa4802c54e bpf: Fix a typo of reuseport map in bpf.h.
9a193caf9d media: cxd2880-spi: Fix an error handling path
34106f5260 soc: rockchip: ROCKCHIP_GRF should not default to y, unconditionally
b928930530 media: TDA1997x: enable EDID support
43282ca83a drm/panfrost: Fix missing clk_disable_unprepare() on error in panfrost_clk_init()
fc9cf22290 EDAC/i10nm: Fix NVDIMM detection
32d8a3684b spi: spi-zynq-qspi: use wait_for_completion_timeout to make zynq_qspi_exec_mem_op not interruptible
4206dbc985 spi: sprd: Fix the wrong WDG_LOAD_VAL
1f70517eac regulator: vctrl: Avoid lockdep warning in enable/disable ops
d255d6a645 regulator: vctrl: Use locked regulator_get_voltage in probe path
013177ccc4 certs: Trigger creation of RSA module signing key if it's not an RSA key
cc74533a47 crypto: qat - use proper type for vf_mask
b3fa499d72 block: nbd: add sanity check for first_minor
c60a31db39 clocksource/drivers/sh_cmt: Fix wrong setting if don't request IRQ for clock source channel
6b10d3d3a9 lib/mpi: use kcalloc in mpi_resize
57c8e2ea47 genirq/timings: Fix error return code in irq_timings_test_irqs()
2d00b22c8b spi: spi-pic32: Fix issue with uninitialized dma_slave_config
b29593d069 spi: spi-fsl-dspi: Fix issue with uninitialized dma_slave_config
449884aeb3 sched: Fix UCLAMP_FLAG_IDLE setting
67da2d9c9e m68k: emu: Fix invalid free in nfeth_cleanup()
c68ba4a708 s390/debug: fix debug area life cycle
7a67a00ea8 s390/kasan: fix large PMD pages address alignment check
98296eb3de udf_get_extendedattr() had no boundary checks.
ae4240d1f4 fcntl: fix potential deadlock for &fasync_struct.fa_lock
a6273c8c2a crypto: qat - do not export adf_iov_putmsg()
7dfa7bb69e crypto: qat - fix naming for init/shutdown VF to PF notifications
843b4e713a crypto: qat - fix reuse of completion variable
4a98826455 crypto: qat - handle both source of interrupt in VF ISR
c2b3f81125 crypto: qat - do not ignore errors from enable_vf2pf_comms()
1c189ccef0 libata: fix ata_host_start()
e55b627d6e s390/cio: add dev_busid sysfs entry for each subchannel
0423517520 power: supply: max17042_battery: fix typo in MAx17042_TOFF
eb45ae88bf nvmet: pass back cntlid on successful completion
6cb5d6ae68 nvme-rdma: don't update queue count when failing to set io queues
3073ec7f06 nvme-tcp: don't update queue count when failing to set io queues
93cf19b4d9 bcache: add proper error unwinding in bcache_device_init
e55f20798f isofs: joliet: Fix iocharset=utf8 mount option
0f5cd92e5e udf: Fix iocharset=utf8 mount option
86987cf0fb udf: Check LVID earlier
cc608af36e hrtimer: Ensure timerfd notification for HIGHRES=n
a845787830 hrtimer: Avoid double reprogramming in __hrtimer_start_range_ns()
c322a963d5 posix-cpu-timers: Force next expiration recalc after itimer reset
28996dbb8a rcu/tree: Handle VM stoppage in stall detection
b7c560ae51 sched/deadline: Fix missing clock update in migrate_task_rq_dl()
40db13e3ef crypto: omap-sham - clear dma flags only after omap_sham_update_dma_stop()
ebf0f71ae3 power: supply: axp288_fuel_gauge: Report register-address on readb / writeb errors
bba2b82d1b sched/deadline: Fix reset_on_fork reporting of DL tasks
53a6ef40c6 crypto: mxs-dcp - Check for DMA mapping errors
344a38789a regmap: fix the offset of register error log
a5e42516a6 locking/mutex: Fix HANDOFF condition
f019fa5605 Merge branch 'android11-5.4' into 'android11-5.4-lts'
80833b7bc2 ANDROID: GKI: db845c: Update symbols list and ABI for lts v5.4.144
9ccfa71ab0 Merge 5.4.145 into android11-5.4-lts
a0f68fb55e Linux 5.4.145
d83f0b39e7 PCI: Call Max Payload Size-related fixup quirks early
0c8277e334 x86/reboot: Limit Dell Optiplex 990 quirk to early BIOS versions
d31a4c35b9 xhci: fix unsafe memory usage in xhci tracing
e00d39ca92 usb: mtu3: fix the wrong HS mult value
c3ffd35014 usb: mtu3: use @mult for HS isoc or intr
00b6325590 usb: host: xhci-rcar: Don't reload firmware after the completion
7a74ae301c ALSA: usb-audio: Add registration quirk for JBL Quantum 800
c1ea74f642 Revert "btrfs: compression: don't try to compress if we don't have enough pages"
f05c74e104 x86/events/amd/iommu: Fix invalid Perf result due to IOMMU PMC power-gating
b1ca1665e6 Revert "r8169: avoid link-up interrupt issue on RTL8106e if user enables ASPM"
cf1222b877 mm/page_alloc: speed up the iteration of max_order
17d409c83e net: ll_temac: Remove left-over debug message
ccadb91437 powerpc/boot: Delete unneeded .globl _zimage_start
295501c77c ipv4/icmp: l3mdev: Perform icmp error route lookup on source device routing table (v2)
6dec8e17b8 USB: serial: mos7720: improve OOM-handling in read_mos_reg()
d84708451d igmp: Add ip_mc_list lock in ip_check_mc_rcu
cd8ad6ed9a media: stkwebcam: fix memory leak in stk_camera_probe
9febc9153f ARC: wireup clone3 syscall
417b11d325 ALSA: pcm: fix divide error in snd_pcm_lib_ioctl
cf28619cd9 ALSA: hda/realtek: Workaround for conflicting SSID on ASUS ROG Strix G17
a8146f1490 ARM: 8918/2: only build return_address() if needed
ebad44b643 cryptoloop: add a deprecation warning
d12526ddf5 perf/x86/amd/power: Assign pmu.module
be1f76fcee perf/x86/amd/ibs: Work around erratum #1197
861118d64e perf/x86/intel/pt: Fix mask of num_address_ranges
40d23de514 qede: Fix memset corruption
468623f696 net: macb: Add a NULL check on desc_ptp
50f73f31ae qed: Fix the VF msix vectors flow
92abb09f7a reset: reset-zynqmp: Fixed the argument data type
b820c4c651 gpu: ipu-v3: Fix i.MX IPU-v3 offset calculations for (semi)planar U/V formats
48051387fa xtensa: fix kconfig unmet dependency warning for HAVE_FUTEX_CMPXCHG
56c77c1b52 kthread: Fix PF_KTHREAD vs to_kthread() race
af3cf928b9 ubifs: report correct st_size for encrypted symlinks
aa4e216156 f2fs: report correct st_size for encrypted symlinks
52d8e5b0ab ext4: report correct st_size for encrypted symlinks
228a4203d8 fscrypt: add fscrypt_symlink_getattr() for computing st_size
9b3849ba66 ext4: fix race writing to an inline_data file while its xattrs are changing
8ac6727e49 Revert "once: Fix panic when module unload"
2e0ca55ea4 Merge 5.4.144 into android11-5.4-lts
c6bf0ed9d1 Linux 5.4.144
0634c0f919 audit: move put_tree() to avoid trim_trees refcount underflow and UAF
cab0003311 net: don't unconditionally copy_from_user a struct ifreq for socket ioctls
6752b3b062 Revert "parisc: Add assembly implementations for memset, strlen, strcpy, strncpy and strcat"
67871ada3a Revert "floppy: reintroduce O_NDELAY fix"
d7f7eca72e btrfs: fix NULL pointer dereference when deleting device by invalid id
e644da7ace arm64: dts: qcom: msm8994-angler: Fix gpio-reserved-ranges 85-88
4f76285f6d KVM: x86/mmu: Treat NX as used (not reserved) for all !TDP shadow MMUs
620681d720 net: dsa: mt7530: fix VLAN traffic leaks again
38adbf21f3 bpf: Fix cast to pointer from integer of different size warning
812ee47ad7 bpf: Track contents of read-only maps as scalars
f441801520 vt_kdsetmode: extend console locking
8a19e00450 btrfs: fix race between marking inode needs to be logged and log syncing
f3a1ac258e net/rds: dma_map_sg is entitled to merge entries
ad6a2bc758 drm/nouveau/disp: power down unused DP links during init
689179c462 drm: Copy drm_wait_vblank to user before returning
18ceb99f84 qed: Fix null-pointer dereference in qed_rdma_create_qp()
f1a0db49ab qed: qed ll2 race condition fixes
73ba9e4ece vringh: Use wiov->used to check for read/write desc order
ee52acae6f virtio_pci: Support surprise removal of virtio pci device
be9b79e841 virtio: Improve vq->broken access to avoid any compiler optimization
0d4ba693db opp: remove WARN when no valid OPPs remain
baf56a1d81 perf/x86/intel/uncore: Fix integer overflow on 23 bit left shift of a u32
0ad96094ab usb: gadget: u_audio: fix race condition on endpoint stop
c5c2b4ca50 drm/i915: Fix syncmap memory leak
2f3cefa6ab net: hns3: fix get wrong pfc_en when query PFC configuration
6f0c0b35e2 net: hns3: fix duplicate node in VLAN list
951805c23d net: hns3: clear hardware resource when loading driver
08162f6564 rtnetlink: Return correct error on changing device netns
f58e42d192 net: marvell: fix MVNETA_TX_IN_PRGRS bit number
45454400a6 xgene-v2: Fix a resource leak in the error handling path of 'xge_probe()'
53b480e68c ip_gre: add validation for csum_start
bb8ca7e2e6 RDMA/efa: Free IRQ vectors on error flow
e29565b451 e1000e: Fix the max snoop/no-snoop latency for 10M
8a21e84334 IB/hfi1: Fix possible null-pointer dereference in _extend_sdma_tx_descs()
944a50f56f RDMA/bnxt_re: Add missing spin lock initialization
28b1895410 scsi: core: Fix hang of freezing queue between blocking and running device
628c582854 usb: dwc3: gadget: Stop EP0 transfers during pullup disable
d9da281c8f usb: dwc3: gadget: Fix dwc3_calc_trbs_left()
21880abf19 USB: serial: option: add new VID/PID to support Fibocom FG150
2e098e91ee Revert "USB: serial: ch341: fix character loss at high transfer rates"
16b281a70a can: usb: esd_usb2: esd_usb2_rx_event(): fix the interchange of the CAN RX and TX error counters
765437d1f0 mm, oom: make the calculation of oom badness more accurate
1cccf5c030 mmc: sdhci-msm: Update the software timeout value for sdhc
aec1e470d9 ovl: fix uninitialized pointer read in ovl_lookup_real_one()
57bd5b59f1 once: Fix panic when module unload
5892f910f4 netfilter: conntrack: collect all entries in one cycle
7c95c89b69 ARC: Fix CONFIG_STACKDEPOT
a6b049aeef net: qrtr: fix another OOB Read in qrtr_endpoint_post
feaf47115a Merge branch 'android11-5.4' into 'android11-5.4-lts'
4a23ba6f12 Merge branch 'android11-5.4' into 'android11-5.4-lts'
406300927b Revert "virtio: Protect vqs list access"
874997f95f Merge 5.4.143 into android11-5.4-lts
2d724dbd16 Revert "net: igmp: fix data-race in igmp_ifc_timer_expire()"
50637be299 Revert "net: igmp: increase size of mr_ifc_count"
f5f155f4d6 Revert "PCI/MSI: Protect msi_desc::masked for multi-MSI"
5395faca89 Merge 5.4.142 into android11-5.4-lts
48266f7c1b Merge branch 'android11-5.4' into 'android11-5.4-lts'
fd80923202 Linux 5.4.143
4bf1941581 netfilter: nft_exthdr: fix endianness of tcp option cast
e4fd994f02 fs: warn about impending deprecation of mandatory locks
41c7f46c89 mm: memcontrol: fix occasional OOMs due to proportional memory.low reclaim
1a3aa81444 mm, memcg: avoid stale protection values when cgroup is above protection
9c1c449dcc ASoC: intel: atom: Fix breakage for PCM buffer address setup
846ba58a7c PCI: Increase D3 delay for AMD Renoir/Cezanne XHCI
548b75f490 btrfs: prevent rename2 from exchanging a subvol with a directory from different parents
0fc6a9c202 ipack: tpci200: fix memory leak in the tpci200_register
280d66b317 ipack: tpci200: fix many double free issues in tpci200_pci_probe
cb7aa51031 slimbus: ngd: reset dma setup during runtime pm
abce32d0f7 slimbus: messaging: check for valid transaction id
0786d315f5 slimbus: messaging: start transaction ids from 1 instead of zero
20c2f141b1 tracing / histogram: Fix NULL pointer dereference on strcmp() on NULL event name
8fbfebe188 ALSA: hda - fix the 'Capture Switch' value change notifications
85e60614d1 mmc: dw_mmc: Fix hang on data CRC error
4f6c9caf7b ovl: add splice file read write helper
85813f1f9e iavf: Fix ping is lost after untrusted VF had tried to change MAC
a498115dcd i40e: Fix ATR queue selection
1b8a8fba78 ovs: clear skb->tstamp in forwarding path
84dbbf5482 net: mdio-mux: Handle -EPROBE_DEFER correctly
453486e79e net: mdio-mux: Don't ignore memory allocation errors
6b70c67849 net: qlcnic: add missed unlock in qlcnic_83xx_flash_read32
da92ce3645 virtio-net: use NETIF_F_GRO_HW instead of NETIF_F_LRO
9aeadce8e3 virtio-net: support XDP when not more queues
3ed7cf8386 vrf: Reset skb conntrack connection on VRF rcv
447b160289 bnxt_en: Add missing DMA memory barriers
c9566df334 ptp_pch: Restore dependency on PCI
a73b9aa142 net: 6pack: fix slab-out-of-bounds in decode_data
2bc7571343 bnxt: disable napi before canceling DIM
a9fb0f1559 bnxt: don't lock the tx queue from napi poll
1fe038030c bpf: Clear zext_dst of dead insns
73a45f75a0 vhost: Fix the calculation in vhost_overflow()
b9a59636c4 virtio: Protect vqs list access
b264e37b35 dccp: add do-while-0 stubs for dccp_pr_debug macros
9112ebc299 cpufreq: armada-37xx: forbid cpufreq for 1.2 GHz variant
cb9a9d5fe6 iommu: Check if group is NULL before remove device
911a8141ef Bluetooth: hidp: use correct wait queue when removing ctrl_wait
5b14c1f16e drm/amd/display: Fix Dynamic bpp issue with 8K30 with Navi 1X
f92dc3a89d net: usb: lan78xx: don't modify phy_device state concurrently
be70436799 ARM: dts: nomadik: Fix up interrupt controller node names
69aa1a1a56 scsi: core: Fix capacity set to zero after offlinining device
935de7ec7a scsi: core: Avoid printing an error if target_alloc() returns -ENXIO
7a721a1e18 scsi: scsi_dh_rdac: Avoid crash during rdac_bus_attach()
9900e06ae6 scsi: megaraid_mm: Fix end of loop tests for list_for_each_entry()
e37cf26bd5 dmaengine: of-dma: router_xlate to return -EPROBE_DEFER if controller is not yet available
12d1322d93 ARM: dts: am43x-epos-evm: Reduce i2c0 bus speed for tps65218
11145efd29 dmaengine: usb-dmac: Fix PM reference leak in usb_dmac_probe()
9c97a05392 dmaengine: xilinx_dma: Fix read-after-free bug when terminating transfers
fc566b5a21 USB: core: Avoid WARNings for 0-length descriptor requests
1bd505c814 media: drivers/media/usb: fix memory leak in zr364xx_probe
705660a6d9 media: zr364xx: fix memory leaks in probe()
79dff2a3f4 media: zr364xx: propagate errors from zr364xx_start_readpipe()
7305d6d407 mtd: cfi_cmdset_0002: fix crash when erasing/writing AMD cards
23f77ad13f ath9k: Postpone key cache entry deletion for TXQ frames reference it
c6feaf806d ath: Modify ath_key_delete() to not need full key entry
b7d593705e ath: Export ath_hw_keysetmac()
add283e251 ath9k: Clear key cache explicitly on disabling hardware
0c049ce432 ath: Use safer key clearing with key cache entries
172b91bbbb x86/fpu: Make init_fpstate correct with optimized XSAVE
81d152c8da ext4: fix EXT4_MAX_LOGICAL_BLOCK macro
62d24bac60 Merge branch 'android11-5.4' into 'android11-5.4-lts'
c15b830f7c Linux 5.4.142
a17f2f2c89 KVM: nSVM: always intercept VMLOAD/VMSAVE when nested (CVE-2021-3656)
7c1c96ffb6 KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653)
456fd88922 iommu/vt-d: Fix agaw for a supported 48 bit guest address width
5b5f855a79 vmlinux.lds.h: Handle clang's module.{c,d}tor sections
e9b2b2b29c ceph: take snap_empty_lock atomically with snaprealm refcount change
95ff775df6 ceph: clean up locking annotation for ceph_get_snap_realm and __lookup_snap_realm
1d8c232afb ceph: add some lockdep assertions around snaprealm handling
a6ff0f3f9f KVM: VMX: Use current VMCS to query WAITPKG support for MSR emulation
ec25d05e18 PCI/MSI: Protect msi_desc::masked for multi-MSI
48d2439c6f PCI/MSI: Use msi_mask_irq() in pci_msi_shutdown()
386ead1d35 PCI/MSI: Correct misleading comments
76d81dec16 PCI/MSI: Do not set invalid bits in MSI mask
6b4bcbf133 PCI/MSI: Enforce MSI[X] entry updates to be visible
4495a41fbc PCI/MSI: Enforce that MSI-X table entry is masked for update
1866c8f6d4 PCI/MSI: Mask all unused MSI-X entries
3b4220c2bf PCI/MSI: Enable and mask MSI-X early
0c8dea3fd5 genirq/timings: Prevent potential array overflow in __irq_timings_store()
4dfe809271 genirq/msi: Ensure deactivation on teardown
e3e54a9300 x86/resctrl: Fix default monitoring groups reporting
a6b594ad74 x86/ioapic: Force affinity setup before startup
db5e266694 x86/msi: Force affinity setup before startup
eda32c2188 genirq: Provide IRQCHIP_AFFINITY_PRE_STARTUP
06b3477436 x86/tools: Fix objdump version check again
74451dd8bf powerpc/kprobes: Fix kprobe Oops happens in booke
b74145d858 nbd: Aovid double completion of a request
ad9550114d vsock/virtio: avoid potential deadlock when vsock device remove
b9cd73cce5 xen/events: Fix race in set_evtchn_to_irq
4d3c5c319b net: igmp: increase size of mr_ifc_count
721ff564cc tcp_bbr: fix u32 wrap bug in round logic if bbr_init() called after 2B packets
2ce8a68a31 net: linkwatch: fix failure to restore device state across suspend/resume
33597972a2 net: bridge: fix memleak in br_add_if()
f6eee53beb net: dsa: sja1105: fix broken backpressure in .port_fdb_dump
1e6a570d37 net: dsa: lantiq: fix broken backpressure in .port_fdb_dump
564f6bbd0e net: dsa: lan9303: fix broken backpressure in .port_fdb_dump
a9243455e8 net: igmp: fix data-race in igmp_ifc_timer_expire()
ed957c77b3 net: Fix memory leak in ieee802154_raw_deliver
13a381b8bc net: dsa: microchip: Fix ksz_read64()
991117eeee drm/meson: fix colour distortion from HDR set during vendor u-boot
e114f15de8 net/mlx5: Fix return value from tracer initialization
f99aa76bb8 psample: Add a fwd declaration for skbuff
9dc8e396c1 iavf: Set RSS LUT and key in reset handle path
23436edae3 net: sched: act_mirred: Reset ct info when mirror/redirect skb
9636fbfe7b ppp: Fix generating ifname when empty IFLA_IFNAME is specified
1c31ee907f net: phy: micrel: Fix link detection on ksz87xx switch"
dfeb64f6e2 platform/x86: pcengines-apuv2: Add missing terminating entries to gpio-lookup tables
699db2bb96 platform/x86: pcengines-apuv2: revert wiring up simswitch GPIO as LED
af7f1539cf net: dsa: mt7530: add the missing RxUnicast MIB counter
d353a61860 ASoC: cs42l42: Fix LRCLK frame start edge
b036452082 netfilter: nf_conntrack_bridge: Fix memory leak when error
cd36a36ea4 ASoC: cs42l42: Remove duplicate control for WNF filter frequency
eb789cc917 ASoC: cs42l42: Fix inversion of ADC Notch Switch control
6a33813363 ASoC: cs42l42: Don't allow SND_SOC_DAIFMT_LEFT_J
55e86f07b8 ASoC: cs42l42: Correct definition of ADC Volume control
22d2e3c6a1 ieee802154: hwsim: fix GPF in hwsim_new_edge_nl
5bac8c2a30 ieee802154: hwsim: fix GPF in hwsim_set_edge_lqi
ddcf807fbb libnvdimm/region: Fix label activation vs errors
bc97fde4c6 ACPI: NFIT: Fix support for virtual SPA ranges
a753e3f334 ceph: reduce contention in ceph_check_delayed_caps()
aa04486c41 i2c: dev: zero out array used for i2c reads from userspace
c18b28e5ad ASoC: intel: atom: Fix reference to PCM buffer address
aab3fa5446 ASoC: xilinx: Fix reference to PCM buffer address
60e2854acf iio: adc: Fix incorrect exit of for-loop
bcac522592 iio: humidity: hdc100x: Add margin to the conversion time
da7cb80905 iio: adc: ti-ads7950: Ensure CS is deasserted after reading channels
7116e6b9d8 Merge 5.4.141 into android11-5.4-lts
b704883aa8 Linux 5.4.141
983d6a6b7e btrfs: don't flush from btrfs_delayed_inode_reserve_metadata
ea13f678a3 btrfs: export and rename qgroup_reserve_meta
41a9b8f36d btrfs: qgroup: don't commit transaction when we already hold the handle
38b8485b72 net: xilinx_emaclite: Do not print real IOMEM pointer
654c19a7e8 btrfs: fix lockdep splat when enabling and disabling qgroups
c55442cdfd btrfs: qgroup: remove ASYNC_COMMIT mechanism in favor of reserve retry-after-EDQUOT
fdaf6a322f btrfs: transaction: Cleanup unused TRANS_STATE_BLOCKED
36af2de520 btrfs: qgroup: try to flush qgroup space when we get -EDQUOT
5c79287c2b btrfs: qgroup: allow to unreserve range without releasing other ranges
b7a722fd75 btrfs: make btrfs_qgroup_reserve_data take btrfs_inode
dfadea4061 btrfs: make qgroup_free_reserved_data take btrfs_inode
812f39ed5b ovl: prevent private clone if bind mount is not allowed
eeb4742501 ppp: Fix generating ppp unit id when ifname is not specified
3460f3959d ALSA: hda: Add quirk for ASUS Flow x13
81d1a3f976 USB:ehci:fix Kunpeng920 ehci hardware problem
d28adaabbb KVM: X86: MMU: Use the correct inherited permissions to get shadow page
5f4ab7e25f usb: dwc3: gadget: Avoid runtime resume if disabling pullup
1782c4af6b usb: dwc3: gadget: Disable gadget IRQ during pullup disable
54b7022f28 usb: dwc3: gadget: Clear DEP flags after stop transfers in ep disable
e36245a68e usb: dwc3: gadget: Prevent EP queuing while stopping transfers
823f692508 usb: dwc3: gadget: Restart DWC3 gadget when enabling pullup
25a0625fa9 usb: dwc3: gadget: Allow runtime suspend if UDC unbinded
5f081a928d usb: dwc3: Stop active transfers before halting the controller
396f29ea0c tracing: Reject string operand in the histogram expression
28276c280f media: v4l2-mem2mem: always consider OUTPUT queue during poll
236aca7092 tee: Correct inappropriate usage of TEE_SHM_DMA_BUF flag
5b774238e8 KVM: SVM: Fix off-by-one indexing when nullifying last used SEV VMCB
c33130b10f Merge 5.4.140 into android11-5.4-lts
ac1d54ea63 Merge branch 'android11-5.4' into 'android11-5.4-lts'
a998faa9c4 Linux 5.4.140
3c197fdd07 arm64: fix compat syscall return truncation
72fcaf6952 net/qla3xxx: fix schedule while atomic in ql_wait_for_drvr_lock and ql_adapter_reset
742e85fa9e alpha: Send stop IPI to send to online CPUs
26946d2139 virt_wifi: fix error on connect
17d7c9c940 reiserfs: check directory items on read from disk
bcad6ece2a reiserfs: add check for root_inode in reiserfs_fill_super
e30a88f1f5 libata: fix ata_pio_sector for CONFIG_HIGHMEM
a2671d96a3 bpf, selftests: Adjust few selftest result_unpriv outcomes
4892b4f324 perf/x86/amd: Don't touch the AMD64_EVENTSEL_HOSTONLY bit inside the guest
d6cf5342fa soc: ixp4xx/qmgr: fix invalid __iomem access
a5bf7ef13e spi: meson-spicc: fix memory leak in meson_spicc_remove
27991c78d6 soc: ixp4xx: fix printing resources
07fd256d53 arm64: vdso: Avoid ISB after reading from cntvct_el0
90e498ef3f KVM: x86/mmu: Fix per-cpu counter corruption on 32-bit builds
2e1a80b934 KVM: Do not leak memory for duplicate debugfs directories
43486cd739 KVM: x86: accept userspace interrupt only if no event is injected
1b7b9713a5 md/raid10: properly indicate failure when ending a failed write request
790cb68d35 pcmcia: i82092: fix a null pointer dereference bug
42ac2c6348 timers: Move clearing of base::timer_running under base:: Lock
8211bb20da serial: 8250_pci: Avoid irq sharing for MSI(-X) interrupts.
f73dcb5d63 serial: 8250_pci: Enumerate Elkhart Lake UARTs via dedicated driver
607460d386 MIPS: Malta: Do not byte-swap accesses to the CBUS UART
3eb686d01c serial: 8250: Mask out floating 16/32-bit bus bits
3b73a69962 serial: 8250_mtk: fix uart corruption issue when rx power off
afdef443a8 serial: tegra: Only print FIFO error message when an error occurs
097a183f9c ext4: fix potential htree corruption when growing large_dir directories
ac23a17381 pipe: increase minimum default pipe size to 2 pages
f3cae04bd4 media: rtl28xxu: fix zero-length control request
e2f6d5b038 staging: rtl8712: get rid of flush_scheduled_work
8f241df0e6 staging: rtl8723bs: Fix a resource leak in sd_int_dpc
bbdd4a5162 tpm_ftpm_tee: Free and unregister TEE shared memory during kexec
3c712f14d8 optee: Fix memory leak when failing to register shm pages
0572199b78 tee: add tee_shm_alloc_kernel_buf()
b247bf412c optee: Clear stale cache entries during initialization
7da261e6bb tracing / histogram: Give calculation hist_fields a size
ba22053f5d scripts/tracing: fix the bug that can't parse raw_trace_func
8d1191f924 clk: fix leak on devm_clk_bulk_get_all() unwind
ed5c9a49e6 usb: otg-fsm: Fix hrtimer list corruption
449a705fba usb: gadget: f_hid: idle uses the highest byte for duration
02f336cee5 usb: gadget: f_hid: fixed NULL pointer dereference
f780a9580c usb: gadget: f_hid: added GET_IDLE and SET_IDLE handlers
134e27da54 usb: cdns3: Fixed incorrect gadget state
df1c6eec4e ALSA: usb-audio: Add registration quirk for JBL Quantum 600
639b45456e ALSA: hda/realtek: add mic quirk for Acer SF314-42
d09639528b firmware_loader: fix use-after-free in firmware_fallback_sysfs
1deb6b9030 firmware_loader: use -ETIMEDOUT instead of -EAGAIN in fw_load_sysfs_fallback
0ee687e672 USB: serial: ftdi_sio: add device ID for Auto-M3 OP-COM v2
01b2c35b05 USB: serial: ch341: fix character loss at high transfer rates
9ed43cfaa7 USB: serial: option: add Telit FD980 composition 0x1056
518e81874c USB: usbtmc: Fix RCU stall warning
ff29fe26ab Bluetooth: defer cleanup of resources in hci_unregister_dev()
580c10a40c blk-iolatency: error out if blk_get_queue() failed in iolatency_set_limit()
ed169b054b net: vxge: fix use-after-free in vxge_device_unregister
c5549876a9 net: fec: fix use-after-free in fec_drv_remove
3fed6dee16 net: pegasus: fix uninit-value in get_interrupt_interval
75cef4fc07 bnx2x: fix an error code in bnx2x_nic_load()
437ee90d7b mips: Fix non-POSIX regexp
b1fa6747b9 net: ipv6: fix returned variable type in ip6_skb_dst_mtu
3e63b566d9 nfp: update ethtool reporting of pauseframe control
d333503de1 sctp: move the active_key update after sh_keys is added
de30346dd3 gpio: tqmx86: really make IRQ optional
9d440b5c1d net: natsemi: Fix missing pci_disable_device() in probe and remove
6934040698 net: phy: micrel: Fix detection of ksz87xx switch
2b8ab7aec0 net: dsa: sja1105: invalidate dynamic FDB entries learned concurrently with statically added ones
71b0a935db net: dsa: sja1105: overwrite dynamic FDB entries with static ones in .port_fdb_add
88b7781609 net, gro: Set inner transport header offset in tcp/udp GRO hook
ba3abe3f82 dmaengine: imx-dma: configure the generic DMA type to make it work
ee2f81330a media: videobuf2-core: dequeue if start_streaming fails
3377f2f8c6 scsi: sr: Return correct event when media event code is 3
f588d4b7be spi: imx: mx51-ecspi: Fix low-speed CONFIGREG delay calculation
b58e3d59a5 spi: imx: mx51-ecspi: Reinstate low-speed CONFIGREG delay
2c1065d40a omap5-board-common: remove not physically existing vdds_1v8_main fixed-regulator
299e3968c0 ARM: dts: am437x-l4: fix typo in can@0 node
9cbe7e21dd clk: stm32f4: fix post divisor setup for I2S/SAI PLLs
3f9eed4462 ALSA: usb-audio: fix incorrect clock source setting
16db40fc4a arm64: dts: armada-3720-turris-mox: remove mrvl,i2c-fast-mode
7c08460773 ARM: dts: imx: Swap M53Menlo pinctrl_power_button/pinctrl_power_out pins
1b1f1aa225 ARM: imx: fix missing 3rd argument in macro imx_mmdc_perf_init
aecff98c3e ARM: dts: colibri-imx6ull: limit SDIO clock to 25MHz
c39907335b ARM: dts: imx6qdl-sr-som: Increase the PHY reset duration to 10ms
61b71c5f51 ARM: imx: add missing clk_disable_unprepare()
d88d6bba3b ARM: imx: add missing iounmap()
6c629cd023 arm64: dts: ls1028a: fix node name for the sysclk
4a830a37d3 ALSA: seq: Fix racy deletion of subscriber
0658a45335 Revert "ACPICA: Fix memory leak caused by _CID repair function"
ea224455dd Merge 5.4.139 into android11-5.4-lts
8ab681fd3f ANDROID: GKI: fix up android/abi_gki_aarch64.xml merge
1d03502d2e Merge branch 'android11-5.4' into 'android11-5.4-lts'
e350cd02e2 Linux 5.4.139
03ff8a4f9d spi: mediatek: Fix fifo transfer
a0f66ddf05 bpf, selftests: Adjust few selftest outcomes wrt unreachable code
d3796e8f6b bpf, selftests: Add a verifier test for assigning 32bit reg states to 64bit ones
8dec99abcd bpf: Test_verifier, add alu32 bounds tracking tests
fd568de580 bpf: Fix leakage under speculation on mispredicted branches
d2f790327f bpf: Do not mark insn as seen under speculative path verification
283d742988 bpf: Inherit expanded/patched seen count from old aux data
a0a9546aae Revert "watchdog: iTCO_wdt: Account for rebooting on second timeout"
76f5314d78 firmware: arm_scmi: Add delayed response status check
1b38f70bbc firmware: arm_scmi: Ensure drivers provide a probe function
44f522298c Revert "Bluetooth: Shutdown controller after workqueues are flushed or cancelled"
38f54217b4 ACPI: fix NULL pointer dereference
0ea2f55bab nvme: fix nvme_setup_command metadata trace event
b508b652d4 net: Fix zero-copy head len calculation.
bf692e7ef6 qed: fix possible unpaired spin_{un}lock_bh in _qed_mcp_cmd_and_union()
6bc48348ec r8152: Fix potential PM refcount imbalance
a57c75ff07 ASoC: tlv320aic31xx: fix reversed bclk/wclk master bits
e2cccb839a spi: stm32h7: fix full duplex irq handler handling
b72f2d9e91 regulator: rt5033: Fix n_voltages settings for BUCK and LDO
86f2a3e9aa btrfs: fix lost inode on log replay after mix of fsync, rename and inode eviction
b7f0fa2192 btrfs: fix race causing unnecessary inode logging during link and rename
cb006da62a btrfs: do not commit logs and transactions during link and rename operations
174c27d0f9 btrfs: delete duplicated words + other fixes in comments
ae7ff75631 Merge 5.4.138 into android11-5.4-lts
7b90d57b09 Linux 5.4.138
7eef18c047 can: j1939: j1939_session_deactivate(): clarify lifetime of session object
18b536de3b i40e: Add additional info to PHY type error
d21eb93110 Revert "perf map: Fix dso->nsinfo refcounting"
16447b2f5c powerpc/pseries: Fix regression while building external modules
265883d1d8 PCI: mvebu: Setup BAR0 in order to fix MSI
21734a31c9 can: hi311x: fix a signedness bug in hi3110_cmd()
f4fa45b0f9 sis900: Fix missing pci_disable_device() in probe and remove
dff00ce448 tulip: windbond-840: Fix missing pci_disable_device() in probe and remove
e0310bbeaa sctp: fix return value check in __sctp_rcv_asconf_lookup
408614108a net/mlx5e: Fix nullptr in mlx5e_hairpin_get_mdev()
ac49832306 net/mlx5: Fix flow table chaining
527feae56f net: llc: fix skb_over_panic
ede4c93860 mlx4: Fix missing error code in mlx4_load_one()
acb97d4b2d net: Set true network header for ECN decapsulation
851946a681 tipc: fix sleeping in tipc accept routine
194b71d28b i40e: Fix log TC creation failure when max num of queues is exceeded
834af62212 i40e: Fix queue-to-TC mapping on Tx
74aea4b715 i40e: Fix firmware LLDP agent related warning
b2ab34e862 i40e: Fix logic of disabling queues
519582e44e netfilter: nft_nat: allow to specify layer 4 protocol NAT only
3a7a4cee7b netfilter: conntrack: adjust stop timestamp to real expiry value
1c04378340 cfg80211: Fix possible memory leak in function cfg80211_bss_update
6cf2abea10 nfc: nfcsim: fix use after free during module unload
6b313d0ffa NIU: fix incorrect error return, missed in previous revert
c4663c1627 HID: wacom: Re-enable touch by default for Cintiq 24HDT / 27QHDT
e9e2ce00ae can: esd_usb2: fix memory leak
43726620b2 can: ems_usb: fix memory leak
8198673892 can: usb_8dev: fix memory leak
a051dbd17b can: mcba_usb_start(): add missing urb->transfer_dma initialization
793581441b can: raw: raw_setsockopt(): fix raw_rcv panic for sock UAF
c621638d0e can: j1939: j1939_xtp_rx_dat_one(): fix rxtimer value between consecutive TP.DT to 750ms
a24d87b429 ocfs2: issue zeroout to EOF blocks
eaaa4284e2 ocfs2: fix zero out valid data
9bd1092148 KVM: add missing compat KVM_CLEAR_DIRTY_LOG
7a94dfe5e2 x86/kvm: fix vcpu-id indexed array sizes
2dc291582c Revert "ACPI: resources: Add checks for ACPI IRQ override"
a8eec69797 btrfs: mark compressed range uptodate only if all bio succeed
57429c1ec7 btrfs: fix rw device counting in __btrfs_free_extra_devids
61f2cbc792 x86/asm: Ensure asm/proto.h can be included stand-alone
99372c38a9 net_sched: check error pointer in tcf_dump_walker()
758a7acf8b Merge 5.4.137 into android11-5.4-lts
911bc13b3a Merge branch 'android11-5.4' into 'android11-5.4-lts'
5b1de8e15f Linux 5.4.137
ebb1b38be0 ipv6: ip6_finish_output2: set sk into newly allocated nskb
6c04123962 ARM: dts: versatile: Fix up interrupt controller node names
befa900533 iomap: remove the length variable in iomap_seek_hole
83fb41b2f6 iomap: remove the length variable in iomap_seek_data
302e1acd4c cifs: fix the out of range assignment to bit fields in parse_server_interfaces
02a470e3c6 firmware: arm_scmi: Fix range check for the maximum number of pending messages
289dd58431 firmware: arm_scmi: Fix possible scmi_linux_errmap buffer overflow
e3acb292f0 hfs: add lock nesting notation to hfs_find_init
af1178296d hfs: fix high memory mapping in hfs_bnode_read
89136a47e2 hfs: add missing clean-up in hfs_fill_super
ded37d0344 ipv6: allocate enough headroom in ip6_finish_output2()
f65b7f377c sctp: move 198 addresses from unusable to private scope
c8d32973ee net: annotate data race around sk_ll_usec
c23b9a5610 net/802/garp: fix memleak in garp_request_join()
88c4cae3ed net/802/mrp: fix memleak in mrp_request_join()
eef99860c6 cgroup1: fix leaked context root causing sporadic NULL deref in LTP
7f0365b4da workqueue: fix UAF in pwq_unbound_release_workfn()
85abe0d47f af_unix: fix garbage collect vs MSG_PEEK
af45f3527a KVM: x86: determine if an exception has an error code only when injecting it.
828cab3c8c tools: Allow proper CC/CXX/... override with LLVM=1 in Makefile.include
525c5513b6 selftest: fix build error in tools/testing/selftests/vm/userfaultfd.c
fab7e04ebb ANDROID: Update android/abi_gki_aarch64.xml
c1b1b25ee2 ANDROID: Update android/abi_gki_aarch64_goldfish
ccc19b14a1 Merge 5.4.136 into android11-5.4-lts
253dccefb5 Linux 5.4.136
587f86b7a2 xhci: add xhci_get_virt_ep() helper
f9d0c35556 perf inject: Close inject.output on exit
a9c103fa91 PCI: Mark AMD Navi14 GPU ATS as broken
11561d2f7b btrfs: compression: don't try to compress if we don't have enough pages
4980301e1c iio: accel: bma180: Fix BMA25x bandwidth register values
d04f2582c4 iio: accel: bma180: Use explicit member assignment
4e0afa8895 net: bcmgenet: ensure EXT_ENERGY_DET_MASK is clear
2a4865d154 net: dsa: mv88e6xxx: use correct .stats_set_histogram() on Topaz
7d8c06b8d2 drm: Return -ENOTTY for non-drm ioctls
b5d7bebd96 nds32: fix up stack guard gap
ba378b7960 rbd: always kick acquire on "acquired" and "released" notifications
13066d6628 rbd: don't hold lock_rwsem while running_list is being drained
b12ead825f hugetlbfs: fix mount mode command line processing
60dbbd76f1 userfaultfd: do not untag user pointers
540eee8cbb selftest: use mmap instead of posix_memalign to allocate memory
e706ac3fc8 ixgbe: Fix packet corruption due to missing DMA sync
e617fa62f6 media: ngene: Fix out-of-bounds bug in ngene_command_config_free_buf()
77713fb336 btrfs: check for missing device in btrfs_trim_fs
f899f24d34 tracing: Fix bug in rb_per_cpu_empty() that might cause deadloop.
59a9f75fb2 tracing/histogram: Rename "cpu" to "common_cpu"
379d8da335 firmware/efi: Tell memblock about EFI iomem reservations
281a94362b usb: dwc2: gadget: Fix sending zero length packet in DDMA mode.
167079fbfa USB: serial: cp210x: add ID for CEL EM3588 USB ZigBee stick
811c4cdf29 USB: serial: cp210x: fix comments for GE CS1000
f54ee7e16d USB: serial: option: add support for u-blox LARA-R6 family
e28d28eb9b usb: renesas_usbhs: Fix superfluous irqs happen after usb_pkt_pop()
863d071dbc usb: max-3421: Prevent corruption of freed memory
e4077a90e6 USB: usb-storage: Add LaCie Rugged USB3-FW to IGNORE_UAS
da6f6769ee usb: hub: Fix link power management max exit latency (MEL) calculations
fea6b53e63 usb: hub: Disable USB 3 device initiated lpm if exit latency is too high
962ce043ef KVM: PPC: Book3S HV Nested: Sanitise H_ENTER_NESTED TM state
2b9ffddd70 KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow
c968f563cc xhci: Fix lost USB 2 remote wake
a660ecde5c ALSA: hdmi: Expose all pins on MSI MS-7C94 board
f73696354d ALSA: sb: Fix potential ABBA deadlock in CSP driver
7aa2dfbc6b ALSA: usb-audio: Add registration quirk for JBL Quantum headsets
46d62c3fe2 ALSA: usb-audio: Add missing proc text entry for BESPOKEN type
f1754f96ab s390/boot: fix use of expolines in the DMA code
8eb521d192 s390/ftrace: fix ftrace_update_ftrace_func implementation
268132b070 Revert "MIPS: add PMD table accounting into MIPS'pmd_alloc_one"
f323809e31 proc: Avoid mixing integer types in mem_rw()
b71a75209f drm/panel: raspberrypi-touchscreen: Prevent double-free
2e6ab87f8e net: sched: cls_api: Fix the the wrong parameter
b60461696a sctp: update active_key for asoc when old key is being replaced
9fa89c2cae nvme: set the PRACT bit when using Write Zeroes with T10 PI
c50141b3d7 r8169: Avoid duplicate sysfs entry creation error
f726817d6b afs: Fix tracepoint string placement with built-in AFS
b22c9e433b Revert "USB: quirks: ignore remote wake-up on Fibocom L850-GL LTE modem"
69a49e7b5b nvme-pci: don't WARN_ON in nvme_reset_work if ctrl.state is not RESETTING
8302513614 ipv6: fix another slab-out-of-bounds in fib6_nh_flush_exceptions
a88414fb11 net/sched: act_skbmod: Skip non-Ethernet packets
c278b954cc net: hns3: fix rx VLAN offload state inconsistent issue
006ed6f4d0 net/tcp_fastopen: fix data races around tfo_active_disable_stamp
3942ba2356 net: hisilicon: rename CACHE_LINE_MASK to avoid redefinition
f11f12decd bnxt_en: Check abort error state in bnxt_half_open_nic()
16ce6cb786 bnxt_en: Add missing check for BNXT_STATE_ABORT_ERR in bnxt_fw_rset_task()
c993e7aadc bnxt_en: Refresh RoCE capabilities in bnxt_ulp_probe()
6ee8e6be30 bnxt_en: Improve bnxt_ulp_stop()/bnxt_ulp_start() call sequence.
35637acc98 spi: cadence: Correct initialisation of runtime PM again
2f2150bf41 scsi: target: Fix protect handling in WRITE SAME(32)
a6cb717f85 scsi: iscsi: Fix iface sysfs attr detection
25df44e90f netrom: Decrease sock refcount when sock timers expire
8d7924ce85 net: sched: fix memory leak in tcindex_partial_destroy_work
f38527f189 KVM: PPC: Fix kvm_arch_vcpu_ioctl vcpu_load leak
b85dadd434 KVM: PPC: Book3S: Fix CONFIG_TRANSACTIONAL_MEM=n crash
b3224bd318 net: decnet: Fix sleeping inside in af_decnet
bd2b3b13aa efi/tpm: Differentiate missing and invalid final event log table.
9413c0abb5 net: fix uninit-value in caif_seqpkt_sendmsg
6d56299ff9 bpftool: Check malloc return value in mount_bpffs_for_pin
edec100986 bpf, sockmap, tcp: sk_prot needs inuse_idx set for proc stats
58259e8b6e s390/bpf: Perform r1 range checking before accessing jit->seen_reg[r1]
cc876a5618 liquidio: Fix unintentional sign extension issue on left shift of u16
42fe8f433b ASoC: rt5631: Fix regcache sync errors on resume
d99aaf0736 spi: mediatek: fix fifo rx mode
08cdda8d89 regulator: hi6421: Fix getting wrong drvdata
b25be6bf64 regulator: hi6421: Use correct variable type for regmap api val argument
a1ade24ccc spi: stm32: fixes pm_runtime calls in probe/remove
40e203ce74 spi: stm32: Use dma_request_chan() instead dma_request_slave_channel()
24b78097a8 spi: imx: add a check for speed_hz before calculating the clock
52cff6123a perf data: Close all files in close_dir()
0f63857d10 perf probe-file: Delete namelist in del_events() on the error path
8b92ea243b perf lzma: Close lzma stream on exit
51351c6d5a perf script: Fix memory 'threads' and 'cpus' leaks on exit
d2bfc3eda9 perf dso: Fix memory leak in dso__new_map()
05804a7d22 perf test event_update: Fix memory leak of evlist
d257f3abdc perf test session_topology: Delete session->evlist
89d1762a4a perf env: Fix sibling_dies memory leak
fd335143be perf probe: Fix dso->nsinfo refcounting
6513dee46f perf map: Fix dso->nsinfo refcounting
ff9fc81fa8 nvme-pci: do not call nvme_dev_remove_admin from nvme_remove
d029df83c6 cxgb4: fix IRQ free race during driver unload
ae9b644344 pwm: sprd: Ensure configuring period and duty_cycle isn't wrongly skipped
a37ca2a076 selftests: icmp_redirect: IPv6 PMTU info should be cleared after redirect
05364a2794 selftests: icmp_redirect: remove from checking for IPv6 route get
7f4848229e ipv6: fix 'disable_policy' for fwd packets
c67fb96f54 gve: Fix an error handling path in 'gve_probe()'
e33da4eeaa igb: Fix position of assignment to *ring
7dd8977736 igb: Check if num of q_vectors is smaller than max before array access
d3d7cceee8 iavf: Fix an error handling path in 'iavf_probe()'
7a13a8a8a5 e1000e: Fix an error handling path in 'e1000_probe()'
9fc381db75 fm10k: Fix an error handling path in 'fm10k_probe()'
5d6a04927b igb: Fix an error handling path in 'igb_probe()'
cddd53237d igc: Fix an error handling path in 'igc_probe()'
47f69d8828 igc: Prefer to use the pci_release_mem_regions method
83b2d55a51 ixgbe: Fix an error handling path in 'ixgbe_probe()'
ba4fbb68fc igc: change default return of igc_read_phy_reg()
88e0720133 igb: Fix use-after-free error during reset
a9508e0edf igc: Fix use-after-free error during reset
f40a4f7a60 Merge 5.4.135 into android11-5.4-lts
0a0beb1f91 Linux 5.4.135
d2f7b384a7 udp: annotate data races around unix_sk(sk)->gso_size
c72374978b perf test bpf: Free obj_buf
17bc942c0b bpftool: Properly close va_list 'ap' by va_end() on error
84ed834094 ipv6: tcp: drop silly ICMPv6 packet too big messages
315033cab3 tcp: annotate data races around tp->mtu_info
41f45e91c9 dma-buf/sync_file: Don't leak fences on merge failure
04b0671683 net: fddi: fix UAF in fza_probe
8aa13a8696 net: validate lwtstate->data before returning from skb_tunnel_info()
8cff7b28ab net: send SYNACK packet with accepted fwmark
b7e5563f2a net: ti: fix UAF in tlan_remove_one
2b70ca9284 net: qcom/emac: fix UAF in emac_remove
463c0addb4 net: moxa: fix UAF in moxart_mac_probe
7ac4a6a74e net: ip_tunnel: fix mtu calculation for ETHER tunnel devices
d5dc50ca1f net: bcmgenet: Ensure all TX/RX queues DMAs are disabled
7ecd40801e net: bridge: sync fdb to new unicast-filtering ports
813d45499f net/sched: act_ct: fix err check for nf_conntrack_confirm
2497307356 netfilter: ctnetlink: suspicious RCU usage in ctnetlink_dump_helpinfo
c6f4a71153 net: ipv6: fix return value of ip6_skb_dst_mtu
9872273b67 net: dsa: mv88e6xxx: enable .rmu_disable() on Topaz
6148ddff2d net: dsa: mv88e6xxx: enable .port_set_policy() on Topaz
d73c180e6a dm writecache: return the exact table values that were set
8a85afc662 mm: slab: fix kmem_cache_create failed when sysfs node not destroyed
f53729b828 usb: cdns3: Enable TDL_CHK only for OUT ep
52b01a8086 f2fs: Show casefolding support only when supported
91d8460167 arm64: dts: marvell: armada-37xx: move firmware node to generic dtsi file
f696cc7f1b firmware: turris-mox-rwtm: add marvell,armada-3700-rwtm-firmware compatible string
e2b28026b8 arm64: dts: armada-3720-turris-mox: add firmware node
f7d1fa65e7 cifs: prevent NULL deref in cifs_compose_mount_options()
06d8a7eb58 s390: introduce proper type handling call_on_stack() macro
2a47e0719a sched/fair: Fix CFS bandwidth hrtimer expiry type
5b7d065868 scsi: qedf: Add check to synchronize abort and flush
0fe70c15f9 scsi: libfc: Fix array index out of bound exception
d7b647d055 scsi: libsas: Add LUN number check in .slave_alloc callback
863c4bc883 scsi: aic7xxx: Fix unintentional sign extension issue on left shift of u8
712e9ed613 rtc: max77686: Do not enforce (incorrect) interrupt trigger type
199d8ea4c7 kbuild: mkcompile_h: consider timestamp if KBUILD_BUILD_TIMESTAMP is set
484193b635 thermal/core: Correct function name thermal_zone_device_unregister()
556cf02830 arm64: dts: imx8mq: assign PCIe clocks
9d3eb68a53 arm64: dts: ls208xa: remove bus-num from dspi node
e054b361ca firmware: tegra: bpmp: Fix Tegra234-only builds
94d0095770 soc/tegra: fuse: Fix Tegra234-only builds
270a2e9faf ARM: dts: stm32: move stmmac axi config in ethernet node on stm32mp15
4bc66215bc ARM: dts: stm32: fix i2c node name on stm32f746 to prevent warnings
856c753237 ARM: dts: rockchip: fix supply properties in io-domains nodes
c5bb9cc2ce arm64: dts: juno: Update SCPI nodes as per the YAML schema
f572a91393 ARM: dts: stm32: fix timer nodes on STM32 MCU to prevent warnings
95e795474c ARM: dts: stm32: fix RCC node name on stm32f429 MCU
a898aa9f88 ARM: dts: stm32: fix gpio-keys node on STM32 MCU boards
5c17edaaea ARM: dts: am437x-gp-evm: fix ti,no-reset-on-init flag for gpios
3446233096 ARM: dts: am57xx-cl-som-am57x: fix ti,no-reset-on-init flag for gpios
e79e29a4e1 kbuild: sink stdout from cmd for silent build
f817d46775 rtc: mxc_v2: add missing MODULE_DEVICE_TABLE
0a22b51782 ARM: imx: pm-imx5: Fix references to imx5_cpu_suspend_info
e20e85639e ARM: dts: imx6: phyFLEX: Fix UART hardware flow control
a5b19d33ae ARM: dts: Hurricane 2: Fix NAND nodes names
f83535a47f ARM: dts: BCM63xx: Fix NAND nodes names
cb05b84ad7 ARM: NSP: dts: fix NAND nodes names
14e3bad3b5 ARM: Cygnus: dts: fix NAND nodes names
587a757afe ARM: brcmstb: dts: fix NAND nodes names
a9c32c7aee reset: ti-syscon: fix to_ti_syscon_reset_data macro
b400afa427 arm64: dts: rockchip: Fix power-controller node names for rk3328
dfb4e8ed07 arm64: dts: rockchip: Fix power-controller node names for px30
789070f178 ARM: dts: rockchip: Fix power-controller node names for rk3288
6aaffe6ce8 ARM: dts: rockchip: Fix power-controller node names for rk3188
439115ee56 ARM: dts: rockchip: Fix power-controller node names for rk3066a
3b4c347283 ARM: dts: rockchip: Fix IOMMU nodes properties on rk322x
c9d29d62da ARM: dts: rockchip: Fix the timer clocks order
d105e15de6 arm64: dts: rockchip: fix pinctrl sleep nodename for rk3399.dtsi
cfe3d29e5c ARM: dts: rockchip: fix pinctrl sleep nodename for rk3036-kylin and rk3288
79573c6441 ARM: dts: gemini: add device_type on pci
7037876393 ARM: dts: gemini: rename mdio to the right name
2a9f50cc6e Merge branch 'android11-5.4' into 'android11-5.4-lts'

Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: I1dfe5c5858c0c1f38ccb32e253ff7ff7f509eced
2021-10-20 10:32:16 +02:00
Mincheol Jeong
0dedfe3f54
ANDROID: ABI: update allowed list for galaxy
Leaf changes summary: 1 artifact changed
Changed leaf types summary: 0 leaf type changed
Removed/Changed/Added functions summary: 0 Removed, 0 Changed, 1 Added function
Removed/Changed/Added variables summary: 0 Removed, 0 Changed, 0 Added variable

1 Added function:

  [A] 'function int regulatory_set_wiphy_regd_sync_rtnl(wiphy*, ieee80211_regdomain*)'

Bug: 203121344
Signed-off-by: Mincheol Jeong <mc0115.jeong@samsung.corp-partner.google.com>
Change-Id: I5f5c4d14eebbfb5393bce35484ece9c863850ff1
2021-10-19 08:53:45 +09:00
Srinivasarao P
008930a84e ANDROID: ABI: Update allowed list for QCOM
Leaf changes summary: 1 artifact changed
Changed leaf types summary: 0 leaf type changed
Removed/Changed/Added functions summary: 0 Removed, 0 Changed, 1 Added function
Removed/Changed/Added variables summary: 0 Removed, 0 Changed, 0 Added variable

1 Added function:

  [A] 'function void __sdhci_set_timeout(sdhci_host*, mmc_command*)'

Bug: 203221370
Change-Id: I8ccdd4ceb851675f65a9428f62f563c8905631d0
Signed-off-by: Srinivasarao P <quic_spathi@quicinc.com>
2021-10-17 10:06:56 +05:30
Isaac Chen
05cd3c592d ANDROID: distribute Module.symvers
Module.symvers contains the exported symbols with additional metadata,
which can be used to build kernel modules that use/need them.

Bug: 202914651
Signed-off-by: Isaac Chen <ycchen@google.com>
Change-Id: Ife00f368723f08bfdbe56cb1737ee328e2749d00
2021-10-14 13:14:46 +08:00
Mark Tomlinson
6eea8a6d1d UPSTREAM: usb: max-3421: Prevent corruption of freed memory
commit b5fdf5c6e6bee35837e160c00ac89327bdad031b upstream.

The MAX-3421 USB driver remembers the state of the USB toggles for a
device/endpoint. To save SPI writes, this was only done when a new
device/endpoint was being used. Unfortunately, if the old device was
removed, this would cause writes to freed memory.

To fix this, a simpler scheme is used. The toggles are read from
hardware when a URB is completed, and the toggles are always written to
hardware when any URB transaction is started. This will cause a few more
SPI transactions, but no causes kernel panics.

Fixes: 2d53139f31 ("Add support for using a MAX3421E chip as a host driver.")
Cc: stable <stable@vger.kernel.org>
Signed-off-by: Mark Tomlinson <mark.tomlinson@alliedtelesis.co.nz>
Link: https://lore.kernel.org/r/20210625031456.8632-1-mark.tomlinson@alliedtelesis.co.nz
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Bug: 202859772
Change-Id: Ic4ffd248449a240947b4e2f036360c5783a387e8
2021-10-12 12:22:25 -07:00
Venkata Rao Kakani
f625f1b305 ANDROID: ABI: Update allowed list for QCOM
Update the android/abi_gki_aarch64_qcom with core API's
required by mailbox driver.

Bug: 202098265
Change-Id: Id68553d58a8e826d2bb4e129db3dbd81e19050bc
Signed-off-by: Venkata Rao Kakani <quic_vkakani@quicinc.com>
2021-10-05 11:42:08 +00:00
Adrian Hunter
d7aa701af5 UPSTREAM: driver core: Prevent warning when removing a device link from unregistered consumer
sysfs_remove_link() causes a warning if the parent directory does not
exist. That can happen if the device link consumer has not been registered.
So do not attempt sysfs_remove_link() in that case.

Fixes: 287905e68dd29 ("driver core: Expose device link details in sysfs")
Signed-off-by: Adrian Hunter <adrian.hunter@intel.com>
Cc: stable@vger.kernel.org # 5.9+
Reviewed-by: Rafael J. Wysocki <rafael@kernel.org>
Link: https://lore.kernel.org/r/20210716114408.17320-2-adrian.hunter@intel.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit e64daad660a0c9ace3acdc57099fffe5ed83f977)
Bug: 187129171
Signed-off-by: Connor O'Brien <connoro@google.com>
Change-Id: Idfa829a1a16960fd4ffd1c2733ae9f11f9123d09
2021-10-01 11:32:56 -07:00
Paolo Abeni
2e30052a73 UPSTREAM: udp: properly flush normal packet at GRO time
If an UDP packet enters the GRO engine but is not eligible
for aggregation and is not targeting an UDP tunnel,
udp_gro_receive() will not set the flush bit, and packet
could delayed till the next napi flush.

Fix the issue ensuring non GROed packets traverse
skb_gro_flush_final().

Reported-and-tested-by: Matthias Treydte <mt@waldheinz.de>
Fixes: 18f25dc39990 ("udp: skip L4 aggregation for UDP tunnel packets")
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
(cherry picked from commit b43c8909be52f2baca8884f967b418a88424494a)
Bug: 187129171
Signed-off-by: Connor O'Brien <connoro@google.com>
Change-Id: Ic240b52b00c04621d0f523c1540e6d4b587ad1cd
2021-10-01 11:32:56 -07:00
Dmitry Safonov
833c1e231c UPSTREAM: net/xfrm/compat: Copy xfrm_spdattr_type_t atributes
The attribute-translator has to take in mind maxtype, that is
xfrm_link::nla_max. When it is set, attributes are not of xfrm_attr_type_t.
Currently, they can be only XFRMA_SPD_MAX (message XFRM_MSG_NEWSPDINFO),
their UABI is the same for 64/32-bit, so just copy them.

Thanks to YueHaibing for reporting this:
In xfrm_user_rcv_msg_compat() if maxtype is not zero and less than
XFRMA_MAX, nlmsg_parse_deprecated() do not initialize attrs array fully.
xfrm_xlate32() will access uninit 'attrs[i]' while iterating all attrs
array.

KASAN: probably user-memory-access in range [0x0000000041b58ab0-0x0000000041b58ab7]
CPU: 0 PID: 15799 Comm: syz-executor.2 Tainted: G        W         5.14.0-rc1-syzkaller #0
RIP: 0010:nla_type include/net/netlink.h:1130 [inline]
RIP: 0010:xfrm_xlate32_attr net/xfrm/xfrm_compat.c:410 [inline]
RIP: 0010:xfrm_xlate32 net/xfrm/xfrm_compat.c:532 [inline]
RIP: 0010:xfrm_user_rcv_msg_compat+0x5e5/0x1070 net/xfrm/xfrm_compat.c:577
[...]
Call Trace:
 xfrm_user_rcv_msg+0x556/0x8b0 net/xfrm/xfrm_user.c:2774
 netlink_rcv_skb+0x153/0x420 net/netlink/af_netlink.c:2504
 xfrm_netlink_rcv+0x6b/0x90 net/xfrm/xfrm_user.c:2824
 netlink_unicast_kernel net/netlink/af_netlink.c:1314 [inline]
 netlink_unicast+0x533/0x7d0 net/netlink/af_netlink.c:1340
 netlink_sendmsg+0x86d/0xdb0 net/netlink/af_netlink.c:1929
 sock_sendmsg_nosec net/socket.c:702 [inline]

Fixes: 5106f4a8acff ("xfrm/compat: Add 32=>64-bit messages translator")
Cc: <stable@kernel.org>
Reported-by: YueHaibing <yuehaibing@huawei.com>
Signed-off-by: Dmitry Safonov <dima@arista.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
(cherry picked from commit 4e9505064f58d1252805952f8547a5b7dbc5c111)
Bug: 187129171
Signed-off-by: Connor O'Brien <connoro@google.com>
Change-Id: I7a1bb8cd01a518c372f4b17b2363a0c3ce7cd9b4
2021-10-01 11:32:56 -07:00
Daniel Rosenberg
a95d35ae26 UPSTREAM: f2fs: Advertise encrypted casefolding in sysfs
Older kernels don't support encryption with casefolding. This adds
the sysfs entry encrypted_casefold to show support for those combined
features. Support for this feature was originally added by
commit 7ad08a58bf67 ("f2fs: Handle casefolding with Encryption")

Fixes: 7ad08a58bf67 ("f2fs: Handle casefolding with Encryption")
Cc: stable@vger.kernel.org # v5.11+
Signed-off-by: Daniel Rosenberg <drosen@google.com>
Reviewed-by: Eric Biggers <ebiggers@google.com>
Reviewed-by: Chao Yu <yuchao0@huawei.com>
Signed-off-by: Jaegeuk Kim <jaegeuk@kernel.org>
(cherry picked from commit 4c039d5452691fe80260e4c3dd7b629a095bd0a7)
Bug: 187129171
Signed-off-by: Connor O'Brien <connoro@google.com>
Change-Id: Icc037e5f1b2d14e704c823e73d896cdc0944d100
2021-10-01 11:32:56 -07:00
Kristian Klausen
8557d5a891 UPSTREAM: loop: Fix missing discard support when using LOOP_CONFIGURE
Without calling loop_config_discard() the discard flag and parameters
aren't set/updated for the loop device and worst-case they could
indicate discard support when it isn't the case (ex: if the
LOOP_SET_STATUS ioctl was used with a different file prior to
LOOP_CONFIGURE).

Cc: <stable@vger.kernel.org> # 5.8.x-
Fixes: 3448914e8cc5 ("loop: Add LOOP_CONFIGURE ioctl")
Signed-off-by: Kristian Klausen <kristian@klausen.dk>
Link: https://lore.kernel.org/r/20210618115157.31452-1-kristian@klausen.dk
Signed-off-by: Jens Axboe <axboe@kernel.dk>
(cherry picked from commit 2b9ac22b12a266eb4fec246a07b504dd4983b16b)
Bug: 187129171
Signed-off-by: Connor O'Brien <connoro@google.com>
Change-Id: I5dca23cbb70d4951101589efb5384444e443817f
2021-10-01 11:32:56 -07:00
Chunyan Zhang
d0cca8a1ea UPSTREAM: thermal/drivers/sprd: Add missing MODULE_DEVICE_TABLE
MODULE_DEVICE_TABLE is used to extract the device information out of the
driver and builds a table when being compiled. If using this macro,
kernel can find the driver if available when the device is plugged in,
and then loads that driver and initializes the device.

Fixes: 554fdbaf19b18 ("thermal: sprd: Add Spreadtrum thermal driver support")
Signed-off-by: Chunyan Zhang <chunyan.zhang@unisoc.com>
Signed-off-by: Daniel Lezcano <daniel.lezcano@linaro.org>
Link: https://lore.kernel.org/r/20210512093752.243168-1-zhang.lyra@gmail.com
(cherry picked from commit 4d57fd9aeaa013a245bf1fade81e2c30a5efd491)
Bug: 187129171
Signed-off-by: Connor O'Brien <connoro@google.com>
Change-Id: I4fe064ac629b39494c2d1d99bc9dbf42bdcf6ca6
2021-10-01 11:32:55 -07:00
Christophe JAILLET
ba83fe23f6 UPSTREAM: nvmem: sprd: Fix an error message
'ret' is known to be 0 here.
The expected error status is stored in 'status', so use it instead.

Also change %d in %u, because status is an u32, not a int.

Fixes: 096030e7f449 ("nvmem: sprd: Add Spreadtrum SoCs eFuse support")
Acked-by: Chunyan Zhang <zhang.lyra@gmail.com>
Signed-off-by: Christophe JAILLET <christophe.jaillet@wanadoo.fr>
Link: https://lore.kernel.org/r/5bc44aace2fe7e1c91d8b35c8fe31e7134ceab2c.1620406852.git.christophe.jaillet@wanadoo.fr
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit 20be064ec864086bca7a4eb62c772a397b44afb7)
Bug: 187129171
Signed-off-by: Connor O'Brien <connoro@google.com>
Change-Id: Ia63e64c36f925ecd550fa043f33c36f7ca1fbd27
2021-10-01 11:32:55 -07:00
Christophe JAILLET
98e9d16b6b UPSTREAM: usb: musb: Fix an error message
'ret' is known to be 0 here.
Initialize 'ret' with the expected error code before using it.

Fixes: 0990366bab3c ("usb: musb: Add support for MediaTek musb controller")
Signed-off-by: Christophe JAILLET <christophe.jaillet@wanadoo.fr>
Link: https://lore.kernel.org/r/69f514dc7134e3c917cad208e73cc650cb9e2bd6.1620159879.git.christophe.jaillet@wanadoo.fr
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit d9ff1096a840dddea3d5cfa2149ff7da9f499fb2)
Bug: 187129171
Signed-off-by: Connor O'Brien <connoro@google.com>
Change-Id: I3298b32087ae9e9d40ebc225bae54120b1339a92
2021-10-01 11:32:55 -07:00
Can Guo
ace71bcb51 UPSTREAM: scsi: ufs: core: Cancel rpm_dev_flush_recheck_work during system suspend
During ufs system suspend, leaving rpm_dev_flush_recheck_work running or
pending is risky because concurrency may happen between system
suspend/resume and runtime resume routine. Fix this by cancelling
rpm_dev_flush_recheck_work synchronously during system suspend.

Link: https://lore.kernel.org/r/1619408921-30426-3-git-send-email-cang@codeaurora.org
Fixes: 51dd905bd2f6 ("scsi: ufs: Fix WriteBooster flush during runtime suspend")
Reviewed-by: Daejun Park <daejun7.park@samsung.com>
Signed-off-by: Can Guo <cang@codeaurora.org>
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
(cherry picked from commit 637822e63b79ee8a729f7ba2645a26cf5a524ee4)
Bug: 187129171
Signed-off-by: Connor O'Brien <connoro@google.com>
Change-Id: Ib808d3d52921fa36142e39a05710d85fec9be053
2021-10-01 11:32:55 -07:00
Can Guo
dc5ccc2d9c UPSTREAM: scsi: ufs: core: Do not put UFS power into LPM if link is broken
During resume, if link is broken due to AH8 failure, make sure
ufshcd_resume() does not put UFS power back into LPM.

Link: https://lore.kernel.org/r/1619408921-30426-2-git-send-email-cang@codeaurora.org
Fixes: 4db7a2360597 ("scsi: ufs: Fix concurrency of error handler and other error recovery paths")
Reviewed-by: Daejun Park <daejun7.park@samsung.com>
Signed-off-by: Can Guo <cang@codeaurora.org>
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
(cherry picked from commit 23043dd87b153d02eaf676e752d32429be5e5126)
Bug: 187129171
Signed-off-by: Connor O'Brien <connoro@google.com>
Change-Id: I4a278b53ca70a5a55a410b1552e7e05751df847c
2021-10-01 11:32:55 -07:00
Paul Moore
5576e5e477 UPSTREAM: selinux: add proper NULL termination to the secclass_map permissions
This patch adds the missing NULL termination to the "bpf" and
"perf_event" object class permission lists.

This missing NULL termination should really only affect the tools
under scripts/selinux, with the most important being genheaders.c,
although in practice this has not been an issue on any of my dev/test
systems.  If the problem were to manifest itself it would likely
result in bogus permissions added to the end of the object class;
thankfully with no access control checks using these bogus
permissions and no policies defining these permissions the impact
would likely be limited to some noise about undefined permissions
during policy load.

Cc: stable@vger.kernel.org
Fixes: ec27c3568a ("selinux: bpf: Add selinux check for eBPF syscall operations")
Fixes: da97e18458fb ("perf_event: Add support for LSM and SELinux checks")
Signed-off-by: Paul Moore <paul@paul-moore.com>

(cherry picked from commit e4c82eafb609c2badc56f4e11bc50fcf44b8e9eb)
Bug: 187129171
Signed-off-by: Connor O'Brien <connoro@google.com>
Change-Id: I82a810f0b436bdbca08110e2dcf56d87b2b281df
2021-10-01 11:32:55 -07:00
Ilya Lipnitskiy
f87a97cd71 UPSTREAM: of: property: fw_devlink: do not link ".*,nr-gpios"
[<vendor>,]nr-gpios property is used by some GPIO drivers[0] to indicate
the number of GPIOs present on a system, not define a GPIO. nr-gpios is
not configured by #gpio-cells and can't be parsed along with other
"*-gpios" properties.

nr-gpios without the "<vendor>," prefix is not allowed by the DT
spec[1], so only add exception for the ",nr-gpios" suffix and let the
error message continue being printed for non-compliant implementations.

[0] nr-gpios is referenced in Documentation/devicetree/bindings/gpio:
 - gpio-adnp.txt
 - gpio-xgene-sb.txt
 - gpio-xlp.txt
 - snps,dw-apb-gpio.yaml

[1] Link: cb53a16a1e/schemas/gpio/gpio-consumer.yaml (L20)

Fixes errors such as:
  OF: /palmbus@300000/gpio@600: could not find phandle

Fixes: 7f00be96f125 ("of: property: Add device link support for interrupt-parent, dmas and -gpio(s)")
Signed-off-by: Ilya Lipnitskiy <ilya.lipnitskiy@gmail.com>
Cc: Saravana Kannan <saravanak@google.com>
Cc: stable@vger.kernel.org # v5.5+
Link: https://lore.kernel.org/r/20210405222540.18145-1-ilya.lipnitskiy@gmail.com
Signed-off-by: Rob Herring <robh@kernel.org>
(cherry picked from commit d473d32c2fbac2d1d7082c61899cfebd34eb267a)
Bug: 187129171
Signed-off-by: Connor O'Brien <connoro@google.com>
Change-Id: I309004fd4c592ca2697b637d232f9839ba4153eb
2021-10-01 11:32:55 -07:00
Paolo Abeni
751aaf9f30 UPSTREAM: udp: never accept GSO_FRAGLIST packets
Currently the UDP protocol delivers GSO_FRAGLIST packets to
the sockets without the expected segmentation.

This change addresses the issue introducing and maintaining
a couple of new fields to explicitly accept SKB_GSO_UDP_L4
or GSO_FRAGLIST packets. Additionally updates  udp_unexpected_gso()
accordingly.

UDP sockets enabling UDP_GRO stil keep accept_udp_fraglist
zeroed.

v1 -> v2:
 - use 2 bits instead of a whole GSO bitmask (Willem)

Fixes: 9fd1ff5d2ac7 ("udp: Support UDP fraglist GRO/GSO.")
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Reviewed-by: Willem de Bruijn <willemb@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
(cherry picked from commit 78352f73dc5047f3f744764cc45912498c52f3c9)
Bug: 187129171
Signed-off-by: Connor O'Brien <connoro@google.com>
Change-Id: I79d90f403c10f83f21e3f99554b6fdbfc2cc60b0
2021-10-01 11:32:55 -07:00
Paolo Abeni
01228292a6 UPSTREAM: udp: skip L4 aggregation for UDP tunnel packets
If NETIF_F_GRO_FRAGLIST or NETIF_F_GRO_UDP_FWD are enabled, and there
are UDP tunnels available in the system, udp_gro_receive() could end-up
doing L4 aggregation (either SKB_GSO_UDP_L4 or SKB_GSO_FRAGLIST) at
the outer UDP tunnel level for packets effectively carrying and UDP
tunnel header.

That could cause inner protocol corruption. If e.g. the relevant
packets carry a vxlan header, different vxlan ids will be ignored/
aggregated to the same GSO packet. Inner headers will be ignored, too,
so that e.g. TCP over vxlan push packets will be held in the GRO
engine till the next flush, etc.

Just skip the SKB_GSO_UDP_L4 and SKB_GSO_FRAGLIST code path if the
current packet could land in a UDP tunnel, and let udp_gro_receive()
do GRO via udp_sk(sk)->gro_receive.

The check implemented in this patch is broader than what is strictly
needed, as the existing UDP tunnel could be e.g. configured on top of
a different device: we could end-up skipping GRO at-all for some packets.

Anyhow, that is a very thin corner case and covering it will add quite
a bit of complexity.

v1 -> v2:
 - hopefully clarify the commit message

Fixes: 9fd1ff5d2ac7 ("udp: Support UDP fraglist GRO/GSO.")
Fixes: 36707061d6ba ("udp: allow forwarding of plain (non-fraglisted) UDP GRO packets")
Reviewed-by: Willem de Bruijn <willemb@google.com>
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
(cherry picked from commit 18f25dc399901426dff61e676ba603ff52c666f7)
Bug: 187129171
Signed-off-by: Connor O'Brien <connoro@google.com>
Change-Id: If48b1d56009edac9710a100889696d75965eb764
2021-10-01 11:32:54 -07:00
Dmitry Safonov
13ab504be3 UPSTREAM: xfrm/compat: Cleanup WARN()s that can be user-triggered
Replace WARN_ONCE() that can be triggered from userspace with
pr_warn_once(). Those still give user a hint what's the issue.

I've left WARN()s that are not possible to trigger with current
code-base and that would mean that the code has issues:
- relying on current compat_msg_min[type] <= xfrm_msg_min[type]
- expected 4-byte padding size difference between
  compat_msg_min[type] and xfrm_msg_min[type]
- compat_policy[type].len <= xfrma_policy[type].len
(for every type)

Reported-by: syzbot+834ffd1afc7212eb8147@syzkaller.appspotmail.com
Fixes: 5f3eea6b7e8f ("xfrm/compat: Attach xfrm dumps to 64=>32 bit translator")
Cc: "David S. Miller" <davem@davemloft.net>
Cc: Eric Dumazet <eric.dumazet@gmail.com>
Cc: Herbert Xu <herbert@gondor.apana.org.au>
Cc: Jakub Kicinski <kuba@kernel.org>
Cc: Steffen Klassert <steffen.klassert@secunet.com>
Cc: netdev@vger.kernel.org
Cc: stable@vger.kernel.org
Signed-off-by: Dmitry Safonov <dima@arista.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
(cherry picked from commit ef19e111337f6c3dca7019a8bad5fbc6fb18d635)
Bug: 187129171
Signed-off-by: Connor O'Brien <connoro@google.com>
Change-Id: I9576dc6fd1be792674b2e4e844769b8b7659c151
2021-10-01 11:32:54 -07:00
Yangtao Li
236d41699d UPSTREAM: pinctrl: sunxi: fix irq bank map for the Allwinner A100 pin controller
A100's pin starts with PB, so it should start with 1.

Fixes: 473436e7647d6 ("pinctrl: sunxi: add support for the Allwinner A100 pin controller")
Signed-off-by: Yangtao Li <frank@allwinnertech.com>
Link: https://lore.kernel.org/r/9db51667bf9065be55beafd56e5c319e3bbe8310.1604988979.git.frank@allwinnertech.com
Signed-off-by: Linus Walleij <linus.walleij@linaro.org>
(cherry picked from commit 6de7ed693c631d4689acfe90c434147598d75543)
Bug: 187129171
Signed-off-by: Connor O'Brien <connoro@google.com>
Change-Id: I0bb4a3f8e522e4a1ee77aed4566cb66adde612e0
2021-10-01 11:32:54 -07:00
Martijn Coenen
4f031c8941 UPSTREAM: loop: Set correct device size when using LOOP_CONFIGURE
The device size calculation was done before processing the loop
configuration, which meant that the we set the size on the underlying
block device incorrectly in case lo_offset/lo_sizelimit were set in the
configuration. Delay computing the size until we've setup the device
parameters correctly.

Fixes: 3448914e8cc5("loop: Add LOOP_CONFIGURE ioctl")
Reported-by: Lennart Poettering <mzxreary@0pointer.de>
Tested-by: Yang Xu <xuyang2018.jy@cn.fujitsu.com>
Signed-off-by: Martijn Coenen <maco@android.com>
Signed-off-by: Jens Axboe <axboe@kernel.dk>
(cherry picked from commit 79e5dc59e2974a48764269fa9ff544ae8ffe3338)
Bug: 187129171
Signed-off-by: Connor O'Brien <connoro@google.com>
Change-Id: I823aba7e482eaf347992d507c875c10469a27c16
2021-10-01 11:32:54 -07:00
Lennart Poettering
38866fe5a7 UPSTREAM: loop: unset GENHD_FL_NO_PART_SCAN on LOOP_CONFIGURE
When LOOP_CONFIGURE is used with LO_FLAGS_PARTSCAN we need to propagate
this into the GENHD_FL_NO_PART_SCAN. LOOP_SETSTATUS does this,
LOOP_CONFIGURE doesn't so far. Effect is that setting up a loopback
device with partition scanning doesn't actually work when LOOP_CONFIGURE
is issued, though it works fine with LOOP_SETSTATUS.

Let's correct that and propagate the flag in LOOP_CONFIGURE too.

Fixes: 3448914e8cc5("loop: Add LOOP_CONFIGURE ioctl")

Signed-off-by: Lennart Poettering <lennart@poettering.net>
Acked-by: Martijn Coenen <maco@android.com>
Signed-off-by: Jens Axboe <axboe@kernel.dk>
(cherry picked from commit fe6a8fc5ed2f0081f17375ae2005718522c392c6)
Bug: 187129171
Signed-off-by: Connor O'Brien <connoro@google.com>
Change-Id: I0f541040a6bff3d682108bea213b57f89a531272
2021-10-01 11:32:54 -07:00
John Stultz
c060961254 ANDROID: ion_system_heap: Add __GFP_NOWARN to mid-order allocations
When testing ION, we often see warnings in dmesg where a
mid-order allocation failed. The logic will always fall back to
lower-order allocations (there is no strict need to return
contiguous pages) so these warnings are distracting noise.

To solve this, this patch adds the __GFP_NOWARN flag to all
mid-order allocations.

Signed-off-by: John Stultz <john.stultz@linaro.org>
Bug: 177702259
Change-Id: Id4c6f2435afd9e386afba280a7f05f2bab551484
2021-09-30 23:48:21 +00:00
Kaiyi Li
77e911a101 ANDROID: drivers: gpu: drm: increase the MAX_DRM_OPEN_COUNT
goldfish-opengl Vulkan driver with virtio-gpu will open one drm fd for
every allocated host visible VkDeviceMemory. 128 across the entire
system is too small for certain application.

Bug: 199949358
Change-Id: Id71cc3201461c5a83fcd1886d45914c286bca241
Signed-off-by: Kaiyi Li <kaiyili@google.com>
2021-09-30 13:00:06 -07:00
Miklos Szeredi
0923d5c13b UPSTREAM: af_unix: fix garbage collect vs MSG_PEEK
commit cbcf01128d0a92e131bd09f1688fe032480b65ca upstream.

unix_gc() assumes that candidate sockets can never gain an external
reference (i.e.  be installed into an fd) while the unix_gc_lock is
held.  Except for MSG_PEEK this is guaranteed by modifying inflight
count under the unix_gc_lock.

MSG_PEEK does not touch any variable protected by unix_gc_lock (file
count is not), yet it needs to be serialized with garbage collection.
Do this by locking/unlocking unix_gc_lock:

 1) increment file count

 2) lock/unlock barrier to make sure incremented file count is visible
    to garbage collection

 3) install file into fd

This is a lock barrier (unlike smp_mb()) that ensures that garbage
collection is run completely before or completely after the barrier.

Cc: <stable@vger.kernel.org>
Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Bug: 196926917
Signed-off-by: Todd Kjos <tkjos@google.com>
Change-Id: Iaae09d2603c9a680b596d0501479296491ee3d64
2021-09-17 15:10:24 -07:00
Venkata Rao Kakani
2385b6cc59 ANDROID: ABI: Update allowed list for QCOM
Update the android/abi_gki_aarch64_qcom with core API's
required by i2c driver.

Bug: 200125301
Signed-off-by: Venkata Rao Kakani <quic_vkakani@quicinc.com>
Change-Id: Iaec7dcb07e77d2a3c0bc878052fc835419eef53a
2021-09-16 14:53:24 +00:00
Greg Kroah-Hartman
5e10f36746 This is the 5.4.147 stable release
-----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCAAdFiEEZH8oZUiU471FcZm+ONu9yGCSaT4FAmFDItIACgkQONu9yGCS
 aT7qHw/+MC8nqbYT/fMu3ZsTsNB8JZelGhrpXVAFc4E80oZDVEF3aNh8koTk13o/
 sI+9LZD6vPJ7kxPBT45PPxDfwM7VlVlQTVWQ8lUjY+8a2Ml7xZSiz9I3bMX0MsvU
 ylXeAJ4BntXI4679ccSjWGwwcQa+PrHsPrpZqKLBI4+pjxps3eMGwK0yE5jcRd4Z
 WlhgYbE8QhmB4iWSA5CBr7IY5pVIlKpvovlvIi1TlU1C9LXU6O8OBPkhmbuFF4fG
 HY2ge6d+xZItcn9RFi+uH51PwPBpN9U2I+QakQ4iyMNgF1uqHzfWh30ZeINxHzw2
 2Nn/nCmNeUwoOt6YSQGxlZUieqqvq5y4VeXo2nThqBdds8GPJ4AhvvxmM/NnP0EV
 lfI6RSxJcYULfl0XQB5sj3fJ2Fo7G7Mx+kg0q0018iTuOx9kNdQF/WXdLqHvBUIi
 VIaRFR2wKeWXCV7tmb5o8928clv0FWJRi19Gcq8597zWxGC8mlSOg48jVVMkE9rU
 IaYhIiIRL/Dkf34Hal2+mZbvbD5IjtViw9uYOzME7NuF4VVHD6RavsMOM8AuUc+t
 OtSRo6mID1rH+RrvFZhZRzcT3Fg5NVbmEhiVG7tH26ZEJE2Gs/CjexQgTHf25+VL
 /H8Mnjjw7gAmvqAJyG9s3eocnhuuWeYj5YWg3vAxVNoUqUT2uO4=
 =RNKE
 -----END PGP SIGNATURE-----

Merge 5.4.147 into android11-5.4-lts

Changes in 5.4.147
	Revert "Bluetooth: Move shutdown callback before flushing tx and rx queue"
	Revert "block: nbd: add sanity check for first_minor"
	Revert "posix-cpu-timers: Force next expiration recalc after itimer reset"
	Revert "time: Handle negative seconds correctly in timespec64_to_ns()"
	Linux 5.4.147

Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: Ibc93011757992faa8b1dfe421787d9216901c508
2021-09-16 15:57:48 +02:00
Greg Kroah-Hartman
48a24510c3 Linux 5.4.147
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2021-09-16 12:56:14 +02:00
Greg Kroah-Hartman
1f8ee02449 Revert "time: Handle negative seconds correctly in timespec64_to_ns()"
This reverts commit 7a25a0a94c which is
commit 39ff83f2f6cc5cc1458dfcea9697f96338210beb upstream.

Arnd reports that this needs more review before being merged into all of
the trees.

Link: https://lore.kernel.org/r/CAK8P3a0z5jE=Z3Ps5bFTCFT7CHZR1JQ8VhdntDJAfsUxSPCcEw@mail.gmail.com
Reported-by: Arnd Bergmann <arnd@kernel.org>
Cc: Lukas Hannen <lukas.hannen@opensource.tttech-industrial.com>
Cc: Thomas Gleixner <tglx@linutronix.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2021-09-16 12:56:13 +02:00
Greg Kroah-Hartman
dc15f641c6 Revert "posix-cpu-timers: Force next expiration recalc after itimer reset"
This reverts commit c322a963d5 which is
commit 406dd42bd1ba0c01babf9cde169bb319e52f6147 upstream.

It is reported to cause regressions.  A proposed fix has been posted,
but it is not in a released kernel yet.  So just revert this from the
stable release so that the bug is fixed.  If it's really needed we can
add it back in in a future release.

Link: https://lore.kernel.org/r/87ilz1pwaq.fsf@wylie.me.uk
Reported-by: "Alan J. Wylie" <alan@wylie.me.uk>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Frederic Weisbecker <frederic@kernel.org>
Cc: Thomas Gleixner <tglx@linutronix.de>
Cc: Peter Zijlstra (Intel) <peterz@infradead.org>
Cc: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2021-09-16 12:56:13 +02:00
Greg Kroah-Hartman
541e757944 Revert "block: nbd: add sanity check for first_minor"
This reverts commit b3fa499d72 which is
commit b1a811633f7321cf1ae2bb76a66805b7720e44c9 upstream.

The backport of this is reported to be causing some problems, so revert
this for now until they are worked out.

Link: https://lore.kernel.org/r/CACPK8XfUWoOHr-0RwRoYoskia4fbAbZ7DYf5wWBnv6qUnGq18w@mail.gmail.com
Reported-by: Joel Stanley <joel@jms.id.au>
Cc: Christoph Hellwig <hch@lst.de>
Cc: Pavel Skripkin <paskripkin@gmail.com>
Cc: Jens Axboe <axboe@kernel.dk>
Cc: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2021-09-16 12:56:13 +02:00
Sasha Levin
5f3ecbf4d5 Revert "Bluetooth: Move shutdown callback before flushing tx and rx queue"
This reverts commit abbcd61d09.

Botched backport, dropping to reword for next release.

Reported-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2021-09-16 12:56:13 +02:00
Todd Kjos
a151ec4843 FROMGIT: binder: make sure fd closes complete
During BC_FREE_BUFFER processing, the BINDER_TYPE_FDA object
cleanup may close 1 or more fds. The close operations are
completed using the task work mechanism -- which means the thread
needs to return to userspace or the file object may never be
dereferenced -- which can lead to hung processes.

Force the binder thread back to userspace if an fd is closed during
BC_FREE_BUFFER handling.

Fixes: 80cd795630 ("binder: fix use-after-free due to ksys_close() during fdget()")
Cc: stable <stable@vger.kernel.org>
Reviewed-by: Martijn Coenen <maco@android.com>
Acked-by: Christian Brauner <christian.brauner@ubuntu.com>
Signed-off-by: Todd Kjos <tkjos@google.com>
Link: https://lore.kernel.org/r/20210830195146.587206-1-tkjos@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Bug: 111997867
(cherry picked from commit 5fdb55c1ac9585eb23bb2541d5819224429e103d
 git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc.git
Change-Id: Idffa9b54edfc289d95b24f7ae2aa11ae494c7158
2021-09-15 09:29:22 -07:00
Greg Kroah-Hartman
d756462d85 This is the 5.4.146 stable release
-----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCAAdFiEEZH8oZUiU471FcZm+ONu9yGCSaT4FAmFBpSMACgkQONu9yGCS
 aT6PRw//T4GhyaqI0+hhYnYv2++RBzAtKsOAPE7JUZ8X5zNNe3NZKD/+c0q9loy3
 vs1GpkjppSzZcL2WGZidwpgOTO0fqEYiJKusI+E60UGbu8GmmoUl0EbV3A3PP1K7
 n+T1jzMID1j4NwmZQsAA1o3/9pkWrKLb/1+g0mHVCL6WQjA4/YROi5f6xhVeCq/u
 aZFLxrgJ8YRkT9znEHCBcipEGRLid5kQp1uxSA5KaQh0JJl01eoJ3M52swYiExC/
 8g+QXPHFWOs9a1vVyxUG5o4WCShnjKwY1fNkEJ5j54LMmmg52llHfMHajV2a1Kdt
 qihSgY5/pPY9FgEDQ3Sy6xiTO2Lvq17lvHtEbGIn5V7SjQ4ISEN15Pqv3l+PqAFc
 gHeukc28mBfw6/kbolKZ/wksIKyDzxCHd4QNEYZMKjSPbjpzg7zjsvCX53lHkKNb
 23I0iJTu9yVDcPzYYCh/8ndFtxEIBGXS8c9kL5YN8p2k1AMqXcr1qUbYzM9CJqwm
 MSaZ2C1rR58Uhd4CUvOK4N2K7lw+2PH6I0UcSGlp9jv+xHVlmERiM7uaZGBn7oLm
 +n+5BRAU/qDK+Vm1poIZogrsI4BwMp9ZH4terELR28i0gPwYo+tCzddWqq98BuGT
 52ylkG56l0gbC9Bvpf3Ou3K5/qbmhN9HYElt16HNFO6x/ufE2XI=
 =1neh
 -----END PGP SIGNATURE-----

Merge 5.4.146 into android11-5.4-lts

Changes in 5.4.146
	locking/mutex: Fix HANDOFF condition
	regmap: fix the offset of register error log
	crypto: mxs-dcp - Check for DMA mapping errors
	sched/deadline: Fix reset_on_fork reporting of DL tasks
	power: supply: axp288_fuel_gauge: Report register-address on readb / writeb errors
	crypto: omap-sham - clear dma flags only after omap_sham_update_dma_stop()
	sched/deadline: Fix missing clock update in migrate_task_rq_dl()
	rcu/tree: Handle VM stoppage in stall detection
	posix-cpu-timers: Force next expiration recalc after itimer reset
	hrtimer: Avoid double reprogramming in __hrtimer_start_range_ns()
	hrtimer: Ensure timerfd notification for HIGHRES=n
	udf: Check LVID earlier
	udf: Fix iocharset=utf8 mount option
	isofs: joliet: Fix iocharset=utf8 mount option
	bcache: add proper error unwinding in bcache_device_init
	nvme-tcp: don't update queue count when failing to set io queues
	nvme-rdma: don't update queue count when failing to set io queues
	nvmet: pass back cntlid on successful completion
	power: supply: max17042_battery: fix typo in MAx17042_TOFF
	s390/cio: add dev_busid sysfs entry for each subchannel
	libata: fix ata_host_start()
	crypto: qat - do not ignore errors from enable_vf2pf_comms()
	crypto: qat - handle both source of interrupt in VF ISR
	crypto: qat - fix reuse of completion variable
	crypto: qat - fix naming for init/shutdown VF to PF notifications
	crypto: qat - do not export adf_iov_putmsg()
	fcntl: fix potential deadlock for &fasync_struct.fa_lock
	udf_get_extendedattr() had no boundary checks.
	s390/kasan: fix large PMD pages address alignment check
	s390/debug: fix debug area life cycle
	m68k: emu: Fix invalid free in nfeth_cleanup()
	sched: Fix UCLAMP_FLAG_IDLE setting
	spi: spi-fsl-dspi: Fix issue with uninitialized dma_slave_config
	spi: spi-pic32: Fix issue with uninitialized dma_slave_config
	genirq/timings: Fix error return code in irq_timings_test_irqs()
	lib/mpi: use kcalloc in mpi_resize
	clocksource/drivers/sh_cmt: Fix wrong setting if don't request IRQ for clock source channel
	block: nbd: add sanity check for first_minor
	crypto: qat - use proper type for vf_mask
	certs: Trigger creation of RSA module signing key if it's not an RSA key
	regulator: vctrl: Use locked regulator_get_voltage in probe path
	regulator: vctrl: Avoid lockdep warning in enable/disable ops
	spi: sprd: Fix the wrong WDG_LOAD_VAL
	spi: spi-zynq-qspi: use wait_for_completion_timeout to make zynq_qspi_exec_mem_op not interruptible
	EDAC/i10nm: Fix NVDIMM detection
	drm/panfrost: Fix missing clk_disable_unprepare() on error in panfrost_clk_init()
	media: TDA1997x: enable EDID support
	soc: rockchip: ROCKCHIP_GRF should not default to y, unconditionally
	media: cxd2880-spi: Fix an error handling path
	bpf: Fix a typo of reuseport map in bpf.h.
	bpf: Fix potential memleak and UAF in the verifier.
	ARM: dts: aspeed-g6: Fix HVI3C function-group in pinctrl dtsi
	arm64: dts: renesas: r8a77995: draak: Remove bogus adv7511w properties
	soc: qcom: rpmhpd: Use corner in power_off
	media: dvb-usb: fix uninit-value in dvb_usb_adapter_dvb_init
	media: dvb-usb: fix uninit-value in vp702x_read_mac_addr
	media: dvb-usb: Fix error handling in dvb_usb_i2c_init
	media: go7007: remove redundant initialization
	media: coda: fix frame_mem_ctrl for YUV420 and YVU420 formats
	Bluetooth: sco: prevent information leak in sco_conn_defer_accept()
	6lowpan: iphc: Fix an off-by-one check of array index
	netns: protect netns ID lookups with RCU
	drm/amdgpu/acp: Make PM domain really work
	tcp: seq_file: Avoid skipping sk during tcp_seek_last_pos
	ARM: dts: meson8: Use a higher default GPU clock frequency
	ARM: dts: meson8b: odroidc1: Fix the pwm regulator supply properties
	ARM: dts: meson8b: mxq: Fix the pwm regulator supply properties
	ARM: dts: meson8b: ec100: Fix the pwm regulator supply properties
	net/mlx5e: Prohibit inner indir TIRs in IPoIB
	cgroup/cpuset: Fix a partition bug with hotplug
	net: cipso: fix warnings in netlbl_cipsov4_add_std
	i2c: highlander: add IRQ check
	leds: lt3593: Put fwnode in any case during ->probe()
	leds: trigger: audio: Add an activate callback to ensure the initial brightness is set
	media: em28xx-input: fix refcount bug in em28xx_usb_disconnect
	media: venus: venc: Fix potential null pointer dereference on pointer fmt
	PCI: PM: Avoid forcing PCI_D0 for wakeup reasons inconsistently
	PCI: PM: Enable PME if it can be signaled from D3cold
	soc: qcom: smsm: Fix missed interrupts if state changes while masked
	debugfs: Return error during {full/open}_proxy_open() on rmmod
	Bluetooth: increase BTNAMSIZ to 21 chars to fix potential buffer overflow
	PM: EM: Increase energy calculation precision
	drm/msm/dpu: make dpu_hw_ctl_clear_all_blendstages clear necessary LMs
	arm64: dts: exynos: correct GIC CPU interfaces address range on Exynos7
	counter: 104-quad-8: Return error when invalid mode during ceiling_write
	Bluetooth: fix repeated calls to sco_sock_kill
	drm/msm/dsi: Fix some reference counted resource leaks
	usb: gadget: udc: at91: add IRQ check
	usb: phy: fsl-usb: add IRQ check
	usb: phy: twl6030: add IRQ checks
	usb: gadget: udc: renesas_usb3: Fix soc_device_match() abuse
	Bluetooth: Move shutdown callback before flushing tx and rx queue
	usb: host: ohci-tmio: add IRQ check
	usb: phy: tahvo: add IRQ check
	mac80211: Fix insufficient headroom issue for AMSDU
	lockd: Fix invalid lockowner cast after vfs_test_lock
	nfsd4: Fix forced-expiry locking
	usb: gadget: mv_u3d: request_irq() after initializing UDC
	mm/swap: consider max pages in iomap_swapfile_add_extent
	Bluetooth: add timeout sanity check to hci_inquiry
	i2c: iop3xx: fix deferred probing
	i2c: s3c2410: fix IRQ check
	rsi: fix error code in rsi_load_9116_firmware()
	rsi: fix an error code in rsi_probe()
	ASoC: Intel: Skylake: Leave data as is when invoking TLV IPCs
	ASoC: Intel: Skylake: Fix module resource and format selection
	mmc: dw_mmc: Fix issue with uninitialized dma_slave_config
	mmc: moxart: Fix issue with uninitialized dma_slave_config
	bpf: Fix possible out of bound write in narrow load handling
	CIFS: Fix a potencially linear read overflow
	i2c: mt65xx: fix IRQ check
	usb: ehci-orion: Handle errors of clk_prepare_enable() in probe
	usb: bdc: Fix an error handling path in 'bdc_probe()' when no suitable DMA config is available
	tty: serial: fsl_lpuart: fix the wrong mapbase value
	ASoC: wcd9335: Fix a double irq free in the remove function
	ASoC: wcd9335: Fix a memory leak in the error handling path of the probe function
	ASoC: wcd9335: Disable irq on slave ports in the remove function
	ath6kl: wmi: fix an error code in ath6kl_wmi_sync_point()
	bcma: Fix memory leak for internally-handled cores
	brcmfmac: pcie: fix oops on failure to resume and reprobe
	ipv6: make exception cache less predictible
	ipv4: make exception cache less predictible
	net: sched: Fix qdisc_rate_table refcount leak when get tcf_block failed
	net: qualcomm: fix QCA7000 checksum handling
	octeontx2-af: Fix loop in free and unmap counter
	ipv4: fix endianness issue in inet_rtm_getroute_build_skb()
	bpf: Introduce BPF nospec instruction for mitigating Spectre v4
	bpf: Fix leakage due to insufficient speculative store bypass mitigation
	bpf: verifier: Allocate idmap scratch in verifier env
	bpf: Fix pointer arithmetic mask tightening under state pruning
	time: Handle negative seconds correctly in timespec64_to_ns()
	tty: Fix data race between tiocsti() and flush_to_ldisc()
	perf/x86/amd/ibs: Extend PERF_PMU_CAP_NO_EXCLUDE to IBS Op
	x86/resctrl: Fix a maybe-uninitialized build warning treated as error
	KVM: s390: index kvm->arch.idle_mask by vcpu_idx
	KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted
	KVM: nVMX: Unconditionally clear nested.pi_pending on nested VM-Enter
	fuse: truncate pagecache on atomic_o_trunc
	fuse: flush extending writes
	IMA: remove -Wmissing-prototypes warning
	IMA: remove the dependency on CRYPTO_MD5
	fbmem: don't allow too huge resolutions
	backlight: pwm_bl: Improve bootloader/kernel device handover
	clk: kirkwood: Fix a clocking boot regression
	Linux 5.4.146

Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: I5524baa0c07d9d9b80c0736488e3ea0e4fb8e335
2021-09-15 14:01:16 +02:00
Greg Kroah-Hartman
245f15a48c Linux 5.4.146
Link: https://lore.kernel.org/r/20210913131047.974309396@linuxfoundation.org
Tested-by: Florian Fainelli <f.fainelli@gmail.com>
Tested-by: Shuah Khan <skhan@linuxfoundation.org>
Tested-by: Jon Hunter <jonathanh@nvidia.com>
Tested-by: Linux Kernel Functional Testing <lkft@linaro.org>
Tested-by: Guenter Roeck <linux@roeck-us.net>
Tested-by: Sudip Mukherjee <sudip.mukherjee@codethink.co.uk>
Tested-by: Hulk Robot <hulkrobot@huawei.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2021-09-15 09:47:41 +02:00
Linus Walleij
b40facee46 clk: kirkwood: Fix a clocking boot regression
commit aaedb9e00e5400220a8871180d23a83e67f29f63 upstream.

Since a few kernel releases the Pogoplug 4 has crashed like this
during boot:

Unable to handle kernel NULL pointer dereference at virtual address 00000002
(...)
[<c04116ec>] (strlen) from [<c00ead80>] (kstrdup+0x1c/0x4c)
[<c00ead80>] (kstrdup) from [<c04591d8>] (__clk_register+0x44/0x37c)
[<c04591d8>] (__clk_register) from [<c04595ec>] (clk_hw_register+0x20/0x44)
[<c04595ec>] (clk_hw_register) from [<c045bfa8>] (__clk_hw_register_mux+0x198/0x1e4)
[<c045bfa8>] (__clk_hw_register_mux) from [<c045c050>] (clk_register_mux_table+0x5c/0x6c)
[<c045c050>] (clk_register_mux_table) from [<c0acf3e0>] (kirkwood_clk_muxing_setup.constprop.0+0x13c/0x1ac)
[<c0acf3e0>] (kirkwood_clk_muxing_setup.constprop.0) from [<c0aceae0>] (of_clk_init+0x12c/0x214)
[<c0aceae0>] (of_clk_init) from [<c0ab576c>] (time_init+0x20/0x2c)
[<c0ab576c>] (time_init) from [<c0ab3d18>] (start_kernel+0x3dc/0x56c)
[<c0ab3d18>] (start_kernel) from [<00000000>] (0x0)
Code: e3130020 1afffffb e12fff1e c08a1078 (e5d03000)

This is because the "powersave" mux clock 0 was provided in an unterminated
array, which is required by the loop in the driver:

        /* Count, allocate, and register clock muxes */
        for (n = 0; desc[n].name;)
                n++;

Here n will go out of bounds and then call clk_register_mux() on random
memory contents after the mux clock.

Fix this by terminating the array with a blank entry.

Fixes: 105299381d ("cpufreq: kirkwood: use the powersave multiplexer")
Cc: stable@vger.kernel.org
Cc: Andrew Lunn <andrew@lunn.ch>
Cc: Chris Packham <chris.packham@alliedtelesis.co.nz>
Cc: Gregory CLEMENT <gregory.clement@bootlin.com>
Cc: Sebastian Hesselbarth <sebastian.hesselbarth@gmail.com>
Signed-off-by: Linus Walleij <linus.walleij@linaro.org>
Link: https://lore.kernel.org/r/20210814235514.403426-1-linus.walleij@linaro.org
Reviewed-by: Andrew Lunn <andrew@lunn.ch>
Signed-off-by: Stephen Boyd <sboyd@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2021-09-15 09:47:41 +02:00
Daniel Thompson
8810c51077 backlight: pwm_bl: Improve bootloader/kernel device handover
commit 79fad92f2e596f5a8dd085788a24f540263ef887 upstream.

Currently there are (at least) two problems in the way pwm_bl starts
managing the enable_gpio pin. Both occur when the backlight is initially
off and the driver finds the pin not already in output mode and, as a
result, unconditionally switches it to output-mode and asserts the signal.

Problem 1: This could cause the backlight to flicker since, at this stage
in driver initialisation, we have no idea what the PWM and regulator are
doing (an unconfigured PWM could easily "rest" at 100% duty cycle).

Problem 2: This will cause us not to correctly honour the
post_pwm_on_delay (which also risks flickers).

Fix this by moving the code to configure the GPIO output mode until after
we have examines the handover state. That allows us to initialize
enable_gpio to off if the backlight is currently off and on if the
backlight is on.

Cc: stable@vger.kernel.org
Reported-by: Marek Vasut <marex@denx.de>
Signed-off-by: Daniel Thompson <daniel.thompson@linaro.org>
Acked-by: Marek Vasut <marex@denx.de>
Tested-by: Marek Vasut <marex@denx.de>
Signed-off-by: Lee Jones <lee.jones@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2021-09-15 09:47:41 +02:00
Tetsuo Handa
5de2ee621b fbmem: don't allow too huge resolutions
commit 8c28051cdcbe9dfcec6bd0a4709d67a09df6edae upstream.

syzbot is reporting page fault at vga16fb_fillrect() [1], for
vga16fb_check_var() is failing to detect multiplication overflow.

  if (vxres * vyres > maxmem) {
    vyres = maxmem / vxres;
    if (vyres < yres)
      return -ENOMEM;
  }

Since no module would accept too huge resolutions where multiplication
overflow happens, let's reject in the common path.

Link: https://syzkaller.appspot.com/bug?extid=04168c8063cfdde1db5e [1]
Reported-by: syzbot <syzbot+04168c8063cfdde1db5e@syzkaller.appspotmail.com>
Debugged-by: Randy Dunlap <rdunlap@infradead.org>
Signed-off-by: Tetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp>
Reviewed-by: Geert Uytterhoeven <geert+renesas@glider.be>
Cc: stable@vger.kernel.org
Signed-off-by: Daniel Vetter <daniel.vetter@ffwll.ch>
Link: https://patchwork.freedesktop.org/patch/msgid/185175d6-227a-7b55-433d-b070929b262c@i-love.sakura.ne.jp
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2021-09-15 09:47:41 +02:00
THOBY Simon
4a95b04afa IMA: remove the dependency on CRYPTO_MD5
commit 8510505d55e194d3f6c9644c9f9d12c4f6b0395a upstream.

MD5 is a weak digest algorithm that shouldn't be used for cryptographic
operation. It hinders the efficiency of a patch set that aims to limit
the digests allowed for the extended file attribute namely security.ima.
MD5 is no longer a requirement for IMA, nor should it be used there.

The sole place where we still use the MD5 algorithm inside IMA is setting
the ima_hash algorithm to MD5, if the user supplies 'ima_hash=md5'
parameter on the command line.  With commit ab60368ab6 ("ima: Fallback
to the builtin hash algorithm"), setting "ima_hash=md5" fails gracefully
when CRYPTO_MD5 is not set:
	ima: Can not allocate md5 (reason: -2)
	ima: Allocating md5 failed, going to use default hash algorithm sha256

Remove the CRYPTO_MD5 dependency for IMA.

Signed-off-by: THOBY Simon <Simon.THOBY@viveris.fr>
Reviewed-by: Lakshmi Ramasubramanian <nramas@linux.microsoft.com>
[zohar@linux.ibm.com: include commit number in patch description for
stable.]
Cc: stable@vger.kernel.org # 4.17
Signed-off-by: Mimi Zohar <zohar@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2021-09-15 09:47:41 +02:00
Austin Kim
c69935f0b0 IMA: remove -Wmissing-prototypes warning
commit a32ad90426a9c8eb3915eed26e08ce133bd9e0da upstream.

With W=1 build, the compiler throws warning message as below:

   security/integrity/ima/ima_mok.c:24:12: warning:
   no previous prototype for ‘ima_mok_init’ [-Wmissing-prototypes]
       __init int ima_mok_init(void)

Silence the warning by adding static keyword to ima_mok_init().

Signed-off-by: Austin Kim <austin.kim@lge.com>
Fixes: 41c89b64d7 ("IMA: create machine owner and blacklist keyrings")
Cc: stable@vger.kernel.org
Signed-off-by: Mimi Zohar <zohar@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2021-09-15 09:47:41 +02:00
Miklos Szeredi
85b0726d5b fuse: flush extending writes
commit 59bda8ecee2ffc6a602b7bf2b9e43ca669cdbdcd upstream.

Callers of fuse_writeback_range() assume that the file is ready for
modification by the server in the supplied byte range after the call
returns.

If there's a write that extends the file beyond the end of the supplied
range, then the file needs to be extended to at least the end of the range,
but currently that's not done.

There are at least two cases where this can cause problems:

 - copy_file_range() will return short count if the file is not extended
   up to end of the source range.

 - FALLOC_FL_ZERO_RANGE | FALLOC_FL_KEEP_SIZE will not extend the file,
   hence the region may not be fully allocated.

Fix by flushing writes from the start of the range up to the end of the
file.  This could be optimized if the writes are non-extending, etc, but
it's probably not worth the trouble.

Fixes: a2bc923629 ("fuse: fix copy_file_range() in the writeback case")
Fixes: 6b1bdb56b17c ("fuse: allow fallocate(FALLOC_FL_ZERO_RANGE)")
Cc: <stable@vger.kernel.org>  # v5.2
Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2021-09-15 09:47:41 +02:00
Miklos Szeredi
8a98ced6e1 fuse: truncate pagecache on atomic_o_trunc
commit 76224355db7570cbe6b6f75c8929a1558828dd55 upstream.

fuse_finish_open() will be called with FUSE_NOWRITE in case of atomic
O_TRUNC.  This can deadlock with fuse_wait_on_page_writeback() in
fuse_launder_page() triggered by invalidate_inode_pages2().

Fix by replacing invalidate_inode_pages2() in fuse_finish_open() with a
truncate_pagecache() call.  This makes sense regardless of FOPEN_KEEP_CACHE
or fc->writeback cache, so do it unconditionally.

Reported-by: Xie Yongji <xieyongji@bytedance.com>
Reported-and-tested-by: syzbot+bea44a5189836d956894@syzkaller.appspotmail.com
Fixes: e4648309b8 ("fuse: truncate pending writes on O_TRUNC")
Cc: <stable@vger.kernel.org>
Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2021-09-15 09:47:41 +02:00
Sean Christopherson
06dad664d4 KVM: nVMX: Unconditionally clear nested.pi_pending on nested VM-Enter
commit f7782bb8d818d8f47c26b22079db10599922787a upstream.

Clear nested.pi_pending on nested VM-Enter even if L2 will run without
posted interrupts enabled.  If nested.pi_pending is left set from a
previous L2, vmx_complete_nested_posted_interrupt() will pick up the
stale flag and exit to userspace with an "internal emulation error" due
the new L2 not having a valid nested.pi_desc.

Arguably, vmx_complete_nested_posted_interrupt() should first check for
posted interrupts being enabled, but it's also completely reasonable that
KVM wouldn't screw up a fundamental flag.  Not to mention that the mere
existence of nested.pi_pending is a long-standing bug as KVM shouldn't
move the posted interrupt out of the IRR until it's actually processed,
e.g. KVM effectively drops an interrupt when it performs a nested VM-Exit
with a "pending" posted interrupt.  Fixing the mess is a future problem.

Prior to vmx_complete_nested_posted_interrupt() interpreting a null PI
descriptor as an error, this was a benign bug as the null PI descriptor
effectively served as a check on PI not being enabled.  Even then, the
new flow did not become problematic until KVM started checking the result
of kvm_check_nested_events().

Fixes: 705699a139 ("KVM: nVMX: Enable nested posted interrupt processing")
Fixes: 966eefb89657 ("KVM: nVMX: Disable vmcs02 posted interrupts if vmcs12 PID isn't mappable")
Fixes: 47d3530f86c0 ("KVM: x86: Exit to userspace when kvm_check_nested_events fails")
Cc: stable@vger.kernel.org
Cc: Jim Mattson <jmattson@google.com>
Signed-off-by: Sean Christopherson <seanjc@google.com>
Message-Id: <20210810144526.2662272-1-seanjc@google.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2021-09-15 09:47:41 +02:00
Zelin Deng
1735cec1e8 KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted
commit d9130a2dfdd4b21736c91b818f87dbc0ccd1e757 upstream.

When MSR_IA32_TSC_ADJUST is written by guest due to TSC ADJUST feature
especially there's a big tsc warp (like a new vCPU is hot-added into VM
which has been up for a long time), tsc_offset is added by a large value
then go back to guest. This causes system time jump as tsc_timestamp is
not adjusted in the meantime and pvclock monotonic character.
To fix this, just notify kvm to update vCPU's guest time before back to
guest.

Cc: stable@vger.kernel.org
Signed-off-by: Zelin Deng <zelin.deng@linux.alibaba.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Message-Id: <1619576521-81399-2-git-send-email-zelin.deng@linux.alibaba.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2021-09-15 09:47:40 +02:00
Halil Pasic
20fff3ef33 KVM: s390: index kvm->arch.idle_mask by vcpu_idx
commit a3e03bc1368c1bc16e19b001fc96dc7430573cc8 upstream.

While in practice vcpu->vcpu_idx ==  vcpu->vcp_id is often true, it may
not always be, and we must not rely on this. Reason is that KVM decides
the vcpu_idx, userspace decides the vcpu_id, thus the two might not
match.

Currently kvm->arch.idle_mask is indexed by vcpu_id, which implies
that code like
for_each_set_bit(vcpu_id, kvm->arch.idle_mask, online_vcpus) {
                vcpu = kvm_get_vcpu(kvm, vcpu_id);
		do_stuff(vcpu);
}
is not legit. Reason is that kvm_get_vcpu expects an vcpu_idx, not an
vcpu_id.  The trouble is, we do actually use kvm->arch.idle_mask like
this. To fix this problem we have two options. Either use
kvm_get_vcpu_by_id(vcpu_id), which would loop to find the right vcpu_id,
or switch to indexing via vcpu_idx. The latter is preferable for obvious
reasons.

Let us make switch from indexing kvm->arch.idle_mask by vcpu_id to
indexing it by vcpu_idx.  To keep gisa_int.kicked_mask indexed by the
same index as idle_mask lets make the same change for it as well.

Fixes: 1ee0bc559d ("KVM: s390: get rid of local_int array")
Signed-off-by: Halil Pasic <pasic@linux.ibm.com>
Reviewed-by: Christian Bornträger <borntraeger@de.ibm.com>
Reviewed-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Cc: <stable@vger.kernel.org> # 3.15+
Link: https://lore.kernel.org/r/20210827125429.1912577-1-pasic@linux.ibm.com
Signed-off-by: Christian Borntraeger <borntraeger@de.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2021-09-15 09:47:40 +02:00
Babu Moger
0323ab5b25 x86/resctrl: Fix a maybe-uninitialized build warning treated as error
commit 527f721478bce3f49b513a733bacd19d6f34b08c upstream.

The recent commit

  064855a69003 ("x86/resctrl: Fix default monitoring groups reporting")

caused a RHEL build failure with an uninitialized variable warning
treated as an error because it removed the default case snippet.

The RHEL Makefile uses '-Werror=maybe-uninitialized' to force possibly
uninitialized variable warnings to be treated as errors. This is also
reported by smatch via the 0day robot.

The error from the RHEL build is:

  arch/x86/kernel/cpu/resctrl/monitor.c: In function ‘__mon_event_count’:
  arch/x86/kernel/cpu/resctrl/monitor.c:261:12: error: ‘m’ may be used
  uninitialized in this function [-Werror=maybe-uninitialized]
    m->chunks += chunks;
              ^~

The upstream Makefile does not build using '-Werror=maybe-uninitialized'.
So, the problem is not seen there. Fix the problem by putting back the
default case snippet.

 [ bp: note that there's nothing wrong with the code and other compilers
   do not trigger this warning - this is being done just so the RHEL compiler
   is happy. ]

Fixes: 064855a69003 ("x86/resctrl: Fix default monitoring groups reporting")
Reported-by: Terry Bowman <Terry.Bowman@amd.com>
Reported-by: kernel test robot <lkp@intel.com>
Signed-off-by: Babu Moger <babu.moger@amd.com>
Signed-off-by: Borislav Petkov <bp@suse.de>
Reviewed-by: Reinette Chatre <reinette.chatre@intel.com>
Cc: stable@vger.kernel.org
Link: https://lkml.kernel.org/r/162949631908.23903.17090272726012848523.stgit@bmoger-ubuntu
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2021-09-15 09:47:40 +02:00
Kim Phillips
51f4575ca1 perf/x86/amd/ibs: Extend PERF_PMU_CAP_NO_EXCLUDE to IBS Op
commit f11dd0d80555cdc8eaf5cfc9e19c9e198217f9f1 upstream.

Commit:

   2ff4025069 ("perf/core, arch/x86: Use PERF_PMU_CAP_NO_EXCLUDE for exclusion incapable PMUs")

neglected to do so.

Fixes: 2ff4025069 ("perf/core, arch/x86: Use PERF_PMU_CAP_NO_EXCLUDE for exclusion incapable PMUs")
Signed-off-by: Kim Phillips <kim.phillips@amd.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Cc: stable@vger.kernel.org
Link: https://lore.kernel.org/r/20210817221048.88063-2-kim.phillips@amd.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2021-09-15 09:47:39 +02:00