Commit graph

903,996 commits

Author SHA1 Message Date
Greg Kroah-Hartman
5c67c52b0d Merge branch 'android11-5.4' into branch 'android11-5.4-lts'
This catches the android11-5.4-lts branch up with recent changes made in
the android11-5.4 branch.  Changes included in here are:

* 564901bd7f ANDROID: 16K: Only check basename of linker context
* 73b793dd7d UPSTREAM: af_unix: Do not use atomic ops for unix_sk(sk)->inflight.
* ff29a6cf6e ANDROID: ABI fixup for abi break in struct dst_ops
* 8b6880fcb8 BACKPORT: net: fix __dst_negative_advice() race

Change-Id: I7fa20e52026e7bf98e973e632d9cedead8fb0aaf
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-06-18 07:28:30 +00:00
Kalesh Singh
564901bd7f ANDROID: 16K: Only check basename of linker context
Depending on the platform binary being executed, the linker
(interpreter) requested can be one of:

    1) /system/bin/bootstrap/linker64
    2) /system/bin/linker64
    3) /apex/com.android.runtime/bin/linker64

Relax the check to the basename (linker64), instead of the path.

Bug: 330767927
Bug: 335584973
Change-Id: I4a1f95b7cecd126f85ad8cefd9ff10d272947f9e
Signed-off-by: Kalesh Singh <kaleshsingh@google.com>
2024-06-12 03:28:10 +00:00
Kuniyuki Iwashima
73b793dd7d UPSTREAM: af_unix: Do not use atomic ops for unix_sk(sk)->inflight.
[ Upstream commit 97af84a6bba2ab2b9c704c08e67de3b5ea551bb2 ]

When touching unix_sk(sk)->inflight, we are always under
spin_lock(&unix_gc_lock).

Let's convert unix_sk(sk)->inflight to the normal unsigned long.

Bug: 336226035
Signed-off-by: Kuniyuki Iwashima <kuniyu@amazon.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://lore.kernel.org/r/20240123170856.41348-3-kuniyu@amazon.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Stable-dep-of: 47d8ac011fe1 ("af_unix: Fix garbage collector racing against connect()")
Signed-off-by: Sasha Levin <sashal@kernel.org>
(cherry picked from commit 301fdbaa0bba4653570f07789909939f977a7620)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I0d965d5f2a863d798c06de9f21d0467f256b538e
2024-06-11 11:08:14 +01:00
Greg Kroah-Hartman
ff29a6cf6e ANDROID: ABI fixup for abi break in struct dst_ops
In commit 92f1655aa2b2 ("net: fix __dst_negative_advice() race") the
struct dst_ops callback negative_advice is callback changes function
parameters.  But as this pointer is part of a structure that is tracked
in the ABI checker, the tool triggers when this is changed.

However, the callback pointer is internal to the networking stack, so
changing the function type is safe, so needing to preserve this is not
required.  To do so, switch the function pointer type back to the old
one so that the checking tools pass, AND then do a hard cast of the
function pointer to the new type when assigning and calling the
function.

Bug: 343727534
Fixes: 92f1655aa2b2 ("net: fix __dst_negative_advice() race")
Change-Id: I48d4ab4bbd29f8edc8fbd7923828b7f78a23e12e
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-06-01 11:28:49 +00:00
Eric Dumazet
8b6880fcb8 BACKPORT: net: fix __dst_negative_advice() race
__dst_negative_advice() does not enforce proper RCU rules when
sk->dst_cache must be cleared, leading to possible UAF.

RCU rules are that we must first clear sk->sk_dst_cache,
then call dst_release(old_dst).

Note that sk_dst_reset(sk) is implementing this protocol correctly,
while __dst_negative_advice() uses the wrong order.

Given that ip6_negative_advice() has special logic
against RTF_CACHE, this means each of the three ->negative_advice()
existing methods must perform the sk_dst_reset() themselves.

Note the check against NULL dst is centralized in
__dst_negative_advice(), there is no need to duplicate
it in various callbacks.

Many thanks to Clement Lecigne for tracking this issue.

This old bug became visible after the blamed commit, using UDP sockets.

Bug: 343727534
Fixes: a87cb3e48e ("net: Facility to report route quality of connected sockets")
Reported-by: Clement Lecigne <clecigne@google.com>
Diagnosed-by: Clement Lecigne <clecigne@google.com>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Tom Herbert <tom@herbertland.com>
Reviewed-by: David Ahern <dsahern@kernel.org>
Link: https://lore.kernel.org/r/20240528114353.1794151-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 92f1655aa2b2294d0b49925f3b875a634bd3b59e)
[Lee: Trivial/unrelated conflict - no change to the patch]
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I293734dca1b81fcb712e1de294f51e96a405f7e4
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-06-01 11:27:58 +00:00
Greg Kroah-Hartman
4b533a5511 This is the 5.4.277 stable release
-----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCAAdFiEEZH8oZUiU471FcZm+ONu9yGCSaT4FAmZR8vIACgkQONu9yGCS
 aT4p4BAAh4+a0Jkrf2h0QKSQq+OP4yATIzoGWzNDXrrJC5t9g7clDgGxZCj0vz31
 klLc8Jbw0vgjPmzI1w/jfdgw/0o4CMc7K1kvYHa8V0sNxeH6aE0VfETMAhgEDHoX
 vX6pMoYkLsc5Yd5uKnaL2MXfV0agEuvupJq/C4yY2JOHrPsRnFPpqgqDNIlAZ6a7
 7k7QY/CYK7lqVnbFWxdH2wlJKRupAMmx0rdeCIMAN6GTl/ON+pWbPG2PKta25j4F
 25M4S25OINX9rPg5b27OMSzwoqgCBDDNjVTUp4w7Kqbpt11D/xylv+DKZxRvwS4y
 UdMGFoo+sO/8IzROal40rCLaAIXnh1lYpjx/QMw3yNCjWXFgjD2yAzAZroLbWUXg
 v6px5lOE5U5b0OfjuuK9fTO8WzUESegLyNyE8aEz0ZFeOkXLWGmcLwOMyerl1bdA
 cLkfTC9rhTj9Q8O7+aBq9jJF5i3POWtV3weJEqJl4+RPSH61J4Ch1hROz+C59pqn
 mkbcjf4nggVBeK9tSca9LNu54AUIx12q4bmaTb/tauhL673favONReIR1JH+a30P
 luTuOiYnAGiG9M0/Qoq8BrZ8uF/BqdhLZjM584A3O1e/qAtirhEHvjonozANok7C
 XmXqq0Gm8u3Q31UnNoFoW8tLzkv5Za6Nto9tc+btc7vhjXYyPKs=
 =ao+L
 -----END PGP SIGNATURE-----

Merge 5.4.277 into android11-5.4-lts

Changes in 5.4.277
	pinctrl: core: handle radix_tree_insert() errors in pinctrl_register_one_pin()
	ext4: fix bug_on in __es_tree_search
	Revert "selftests: mm: fix map_hugetlb failure on 64K page size systems"
	Revert "net: bcmgenet: use RGMII loopback for MAC reset"
	net: bcmgenet: keep MAC in reset until PHY is up
	net: bcmgenet: synchronize EXT_RGMII_OOB_CTRL access
	net: bcmgenet: synchronize use of bcmgenet_set_rx_mode()
	net: bcmgenet: synchronize UMAC_CMD access
	smb: client: fix potential OOBs in smb2_parse_contexts()
	firmware: arm_scmi: Harden accesses to the reset domains
	arm64: dts: qcom: Fix 'interrupt-map' parent address cells
	btrfs: add missing mutex_unlock in btrfs_relocate_sys_chunks()
	drm/amdgpu: Fix possible NULL dereference in amdgpu_ras_query_error_status_helper()
	usb: typec: ucsi: displayport: Fix potential deadlock
	serial: kgdboc: Fix NMI-safety problems from keyboard reset code
	docs: kernel_include.py: Cope with docutils 0.21
	Linux 5.4.277

Change-Id: I7c64905bd76358d7f6f86f33522fb03811684946
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-06-01 07:58:08 +00:00
Greg Kroah-Hartman
18ae7bded0 Merge branch 'android11-5.4' into branch 'android11-5.4-lts'
This is a backmerge of the recent commits from android11-5.4 into
android11-5.4-lts.  Included in here are the following commits.

* 85547bc085 Merge tag 'android11-5.4.274_r00' into branch 'android11-5.4'
* 519c36cd38 UPSTREAM: selftests: timers: Fix valid-adjtimex signed left-shift undefined behavior
* f952d4f3c8 ANDROID: 16K: Fix show maps CFI failure
* ecba20dd59 ANDROID: 16K: Handle pad VMA splits and merges
* 7231bbf0e4 ANDROID: 16K: madvise_vma_pad_pages: Remove filemap_fault check
* 95ac7272d7 ANDROID: 16K: Only madvise padding from dynamic linker context
* 1375f8328b ANDROID: 16K: Separate padding from ELF LOAD segment mappings
* 6ad75e7a9d ANDROID: 16K: Exclude ELF padding for fault around range
* 0f0e4aae7a ANDROID: 16K: Use MADV_DONTNEED to save VMA padding pages.
* 05f9de39f7 ANDROID: 16K: Introduce ELF padding representation for VMAs
* c54460e994 ANDROID: 16K: Introduce /sys/kernel/mm/pgsize_miration/enabled
* a563a5f035 ANDROID: GKI: add snd_compr_stop_error to Xiaomi_abi
* 70c1800271 UPSTREAM: netfilter: nf_tables: release mutex after nft_gc_seq_end from abort path
* a0aeb4678b UPSTREAM: netfilter: nf_tables: release batch on table validation from abort path
* ba915b85e5 UPSTREAM: netfilter: nf_tables: mark set as dead when unbinding anonymous set with timeout
* 66f4b04cb0 FROMLIST: binder: check offset alignment in binder_get_object()

Change-Id: Ic5b110b8083880521869f10cf92481fc57c3bde9
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-06-01 07:57:51 +00:00
Greg Kroah-Hartman
85547bc085 Merge tag 'android11-5.4.274_r00' into branch 'android11-5.4'
This is the merge of the upstream 5.4.274 relelease into the
android11-5.4 branch.  Included in here are the following commits:

* 181edea14a Revert "timers: Rename del_timer_sync() to timer_delete_sync()"
*   46cf330263 Merge 5.4.274 into android11-5.4-lts
|\
| * 0dbd436fb9 Linux 5.4.274
| * fba9c24c19 firmware: meson_sm: fix to avoid potential NULL pointer dereference
| * 35a5acfa7a ip_gre: do not report erspan version on GRE interface
| * 61206032d6 erspan: Check IFLA_GRE_ERSPAN_VER is set.
| * 7f12ecf453 VMCI: Fix possible memcpy() run-time warning in vmci_datagram_invoke_guest_handler()
| * d006b709db Bluetooth: btintel: Fixe build regression
| * 0bf9fd89ba x86/alternative: Don't call text_poke() in lazy TLB mode
| * 67944e6db6 drm/i915/gt: Reset queue_priority_hint on parking
| * 09e6bb5321 x86/mm/pat: fix VM_PAT handling in COW mappings
| * 6e5da7d65b virtio: reenable config if freezing device failed
| * e7bda8f58b drm/vkms: call drm_atomic_helper_shutdown before drm_dev_put()
| * 7a529c9023 tty: n_gsm: require CAP_NET_ADMIN to attach N_GSM0710 ldisc
| * 9a3b90904d netfilter: nf_tables: discard table flag update with pending basechain deletion
| * 61ac728434 netfilter: nf_tables: release mutex after nft_gc_seq_end from abort path
| * 0a14e16239 netfilter: nf_tables: release batch on table validation from abort path
| * 41bad13c0e netfilter: nf_tables: reject new basechain after table flag update
| * 72d091b751 fbmon: prevent division by zero in fb_videomode_from_videomode()
| * 77f34b9af3 fbdev: viafb: fix typo in hw_bitblt_1 and hw_bitblt_2
| * 0eab73ffb6 usb: sl811-hcd: only defined function checkdone if QUIRK2 is defined
| * 261a831427 usb: typec: tcpci: add generic tcpci fallback compatible
| * fcc68c952c tools: iio: replace seekdir() in iio_generic_buffer
| * 97832659b1 ktest: force $buildonly = 1 for 'make_warnings_file' test type
| * 71de605098 Input: allocate keycode for Display refresh rate toggle
| * edd073c78d block: prevent division by zero in blk_rq_stat_sum()
| * 73daab5b8c Revert "ACPI: PM: Block ASUS B1400CEAE from suspend to idle by default"
| * 4256e1460e SUNRPC: increase size of rpc_wait_queue.qlen from unsigned short to unsigned int
| * 08a07d5a20 drm/amd/display: Fix nanosec stat overflow
| * 4a35b778d0 media: sta2x11: fix irq handler cast
| * 2c1f840469 isofs: handle CDs with bad root inode but good Joliet root directory
| * e2cd32435b scsi: lpfc: Fix possible memory leak in lpfc_rcv_padisc()
| * 1b4fe801b5 sysv: don't call sb_bread() with pointers_lock held
| * e04cae532a Input: synaptics-rmi4 - fail probing if memory allocation for "phys" fails
| * 68a69bb2ec Bluetooth: btintel: Fix null ptr deref in btintel_read_version
| * 024529c27c btrfs: send: handle path ref underflow in header iterate_inode_ref()
| * a9252c8cfa btrfs: export: handle invalid inode or root reference in btrfs_get_parent()
| * 576164bd01 btrfs: handle chunk tree lookup error in btrfs_relocate_sys_chunks()
| * 41aff62bf1 tools/power x86_energy_perf_policy: Fix file leak in get_pkg_num()
| * 97ad3fc426 ionic: set adminq irq affinity
| * 67611c11d7 arm64: dts: rockchip: fix rk3399 hdmi ports node
| * 223145f838 arm64: dts: rockchip: fix rk3328 hdmi ports node
| * 60d417f3e4 panic: Flush kernel log buffer at the end
| * f15eca9513 VMCI: Fix memcpy() run-time warning in dg_dispatch_as_host()
| * dec0f1b008 wifi: ath9k: fix LNA selection in ath_ant_try_scan()
| * 485b5d1d6a s390/entry: align system call table on 8 bytes
| * 976b1b2680 x86/mce: Make sure to grab mce_sysfs_mutex in set_bank()
| * 039458c058 ALSA: hda/realtek: Update Panasonic CF-SZ6 quirk to support headset with microphone
| * fc4387dce4 ata: sata_mv: Fix PCI device ID table declaration compilation warning
| * 0e9207b054 scsi: mylex: Fix sysfs buffer lengths
| * d887674f09 ata: sata_sx4: fix pdc20621_get_from_dimm() on 64-bit
| * 517884404e ASoC: ops: Fix wraparound for mask in snd_soc_get_volsw
| * 9c11271714 net: ravb: Always process TX descriptor ring
| * e54a0c79cd erspan: make sure erspan_base_hdr is present in skb->head
| * 959fe471f1 erspan: Add type I version 0 support.
| * 19d7e7c1ee init: open /initrd.image with O_LARGEFILE
| * 32e34d96b3 initramfs: switch initramfs unpacking to struct file based APIs
| * 13b2d81505 fs: add a vfs_fchmod helper
| * 8eba8d1145 fs: add a vfs_fchown helper
| * 9550632ba9 staging: vc04_services: fix information leak in create_component()
| * bbd974d444 staging: vc04_services: changen strncpy() to strscpy_pad()
| * d07aab3ca7 staging: mmal-vchiq: Fix client_component for 64 bit kernel
| * 50bc5a96f8 staging: mmal-vchiq: Allocate and free components as required
| * 9dcf0fcb80 i40e: fix vf may be used uninitialized in this function warning
| * 9c52581961 ipv6: Fix infinite recursion in fib6_dump_done().
| * 73fac254ec selftests: reuseaddr_conflict: add missing new line at the end of the output
| * 2882bb3b91 net: stmmac: fix rx queue priority assignment
| * f356eb2fb5 net/sched: act_skbmod: prevent kernel-infoleak
| * f7990498b0 bpf, sockmap: Prevent lock inversion deadlock in map delete elem
| * a347bc8e62 netfilter: nf_tables: Fix potential data-race in __nft_flowtable_type_get()
| * f4e14695fe netfilter: nf_tables: flush pending destroy work before exit_net release
| * ab81b3d2f3 mm, vmscan: prevent infinite loop for costly GFP_NOIO | __GFP_RETRY_MAYFAIL allocations
| * 144c56d5dd Revert "x86/mm/ident_map: Use gbpages only where full GB page should be mapped."
| * 07afdfd8a6 vfio/platform: Create persistent IRQ handlers
| * b18fa894d6 vfio/pci: Create persistent INTx handler
| * 3777fa4c8f vfio: Introduce interface to flush virqfd inject workqueue
| * 1e71b6449d vfio/pci: Lock external INTx masking ops
| * 26389925d6 vfio/pci: Disable auto-enable of exclusive INTx IRQ
| * bcd46782e2 net/rds: fix possible cp null dereference
| * 49ce99ae43 netfilter: nf_tables: disallow timeout for anonymous sets
| * f5450973eb Bluetooth: Fix TOCTOU in HCI debugfs implementation
| * 5c8b927293 Bluetooth: hci_event: set the conn encrypted before conn establishes
| * 9d161e8af4 x86/cpufeatures: Add new word for scattered features
| * ff7a4adbd7 r8169: fix issue caused by buggy BIOS on certain boards with RTL8168d
| * e78f604693 dm integrity: fix out-of-range warning
| * 44e62f5d35 tcp: properly terminate timers for kernel sockets
| * a4bb81d890 ixgbe: avoid sleeping allocation in ixgbe_ipsec_vf_add_sa()
| * 03fe259649 nfc: nci: Fix uninit-value in nci_dev_up and nci_ntf_packet
| * 12d6a5681a USB: core: Fix deadlock in usb_deauthorize_interface()
| * ea9a4fce2e scsi: lpfc: Correct size for wqe for memset()
| * fa24c1a49d x86/cpu: Enable STIBP on AMD if Automatic IBRS is enabled
| * d7a68eee87 scsi: qla2xxx: Fix command flush on cable pull
| * 68d951880d usb: udc: remove warning when queue disabled ep
| * a79ac9f3da usb: dwc2: gadget: LPM flow fix
| * 693bbbccd9 usb: dwc2: host: Fix ISOC flow in DDMA mode
| * eb97df08c3 usb: dwc2: host: Fix hibernation flow
| * 4cf44c9fa0 usb: dwc2: host: Fix remote wakeup from hibernation
| * 0053f15d50 scsi: core: Fix unremoved procfs host directory regression
| * 4206ad65a0 ALSA: sh: aica: reorder cleanup operations to avoid UAF bugs
| * 3afdcc4e1a usb: cdc-wdm: close race between read and workqueue
| * b9a7339ae4 mmc: core: Avoid negative index with array access
| * fd20d84bae mmc: core: Initialize mmc_blk_ioc_data
| * c7a9b1b777 exec: Fix NOMMU linux_binprm::exec in transfer_args_to_stack()
| * be1dd9254f wifi: mac80211: check/clear fast rx for non-4addr sta VLAN changes
| * 747d4ee747 mm/migrate: set swap entry values of THP tail pages properly.
| * 7f75e937ec mm/memory-failure: fix an incorrect use of tail pages
| * 815be99d93 vt: fix memory overlapping when deleting chars in the buffer
| * d6077e0d38 bounds: support non-power-of-two CONFIG_NR_CPUS
| * 282e4deafe powerpc: xor_vmx: Add '-mhard-float' to CFLAGS
| * 34b5d2ff9e efivarfs: Request at most 512 bytes for variable names
| * 37a65df6a9 perf/core: Fix reentry problem in perf_output_read_group()
| * 861021710b loop: loop_set_status_from_info() check before assignment
| * b40877b856 loop: Check for overflow while configuring loop
| * f4476da8ea loop: Factor out configuring loop from status
| * 7423a124fa loop: Refactor loop_set_status() size calculation
| * 3c9e7e8cb6 loop: Factor out setting loop device size
| * e08b2e4176 loop: Remove sector_t truncation checks
| * ea3bec644a loop: Call loop_config_discard() only after new config is applied
| * 2ea7077748 Revert "loop: Check for overflow while configuring loop"
| * 735e525d8c btrfs: allocate btrfs_ioctl_defrag_range_args on stack
| * 501561d808 printk: Update @console_may_schedule in console_trylock_spinning()
| * 9470f5b250 xen/events: close evtchn after mapping cleanup
| * 03b19c7fa1 x86/speculation: Support intra-function call validation
| * f8f25fde0c objtool: Add support for intra-function calls
| * eafb29361a objtool: is_fentry_call() crashes if call has no destination
| * 396dbbc189 fs/aio: Check IOCB_AIO_RW before the struct aio_kiocb conversion
| * ff7342090c vt: fix unicode buffer corruption when deleting characters
| * 741dee500f tty: serial: fsl_lpuart: avoid idle preamble pending if CTS is enabled
| * d79cd5c29a usb: port: Don't try to peer unused USB ports based on location
| * a766761d20 usb: gadget: ncm: Fix handling of zero block length packets
| * eb7b01ca77 USB: usb-storage: Prevent divide-by-0 error in isd200_ata_command
| * 9e93b41109 ALSA: hda/realtek - Fix headset Mic no show at resume back for Lenovo ALC897 platform
| * 57ae281a67 xfrm: Avoid clang fortify warning in copy_to_user_tmpl()
| * 0920c618d2 netfilter: nf_tables: reject constant set with timeout
| * e9a0d3f376 netfilter: nf_tables: disallow anonymous set with timeout flag
| * edcf1a3f18 netfilter: nf_tables: mark set as dead when unbinding anonymous set with timeout
| * 1ba8fdef88 comedi: comedi_test: Prevent timers rescheduling during deletion
| * e7d4cff57c dm snapshot: fix lockup in dm_exception_table_exit
| * 35ff8175d9 ahci: asm1064: asm1166: don't limit reported ports
| * 86e248c2d6 ahci: asm1064: correct count of reported ports
| * 89c4357725 x86/CPU/AMD: Update the Zenbleed microcode revisions
| * 32eaee72e9 nilfs2: prevent kernel bug at submit_bh_wbc()
| * 6503d76d91 nilfs2: use a more common logging style
| * 9cbe1ad5f4 nilfs2: fix failure to detect DAT corruption in btree and direct mappings
| * f2cee08a69 memtest: use {READ,WRITE}_ONCE in memory scanning
| * 673fb93c92 drm/vc4: hdmi: do not return negative values from .get_modes()
| * 7ecbec89e4 drm/imx/ipuv3: do not return negative values from .get_modes()
| * 348aa3d47e drm/exynos: do not return negative values from .get_modes()
| * 9daddee03d s390/zcrypt: fix reference counting on zcrypt card objects
| * ff50716b7d soc: fsl: qbman: Use raw spinlock for cgr_lock
| * f248ecc186 soc: fsl: qbman: Add CGR update function
| * 6e9629518c soc: fsl: qbman: Add helper for sanity checking cgr ops
| * 62c3ecd283 soc: fsl: qbman: Always disable interrupts when taking cgr_lock
| * 3f91ba9653 ring-buffer: Fix full_waiters_pending in poll
| * f7578a3b7c ring-buffer: Fix resetting of shortest_full
| * b0beb669a8 vfio/platform: Disable virqfds on cleanup
| * b046ab1642 kbuild: Move -Wenum-{compare-conditional,enum-conversion} into W=1
| * 31722ed2c3 speakup: Fix 8bit characters from direct synth
| * b2b93a38d6 slimbus: core: Remove usage of the deprecated ida_simple_xx() API
| * aec74a14d1 nvmem: meson-efuse: fix function pointer type mismatch
| * 525ae72d9f firmware: meson_sm: Rework driver as a proper platform driver
| * ee4e9c1976 ext4: fix corruption during on-line resize
| * 1a560f1969 hwmon: (amc6821) add of_match table
| * d7bc1877c1 mmc: core: Fix switch on gp3 partition
| * 24019e5ac6 dm-raid: fix lockdep waring in "pers->hot_add_disk"
| * 0b949dc225 Revert "Revert "md/raid5: Wait for MD_SB_CHANGE_PENDING in raid5d""
| * 47d8aafcfe PCI/PM: Drain runtime-idle callbacks before driver removal
| * ec6f7c0807 PCI: Drop pci_device_remove() test of pci_dev->driver
| * 287a9a9b6e btrfs: fix off-by-one chunk length calculation at contains_pending_extent()
| * ab95a42020 fuse: don't unhash root
| * c180d65df8 mmc: tmio: avoid concurrent runs of mmc_request_done()
| * 2e94147e20 PM: sleep: wakeirq: fix wake irq warning in system suspend
| * bd140aef69 USB: serial: cp210x: add pid/vid for TDK NC0110013M and MM0110113M
| * b11cd74c31 USB: serial: option: add MeiG Smart SLM320 product
| * f5167c50af USB: serial: cp210x: add ID for MGP Instruments PDS100
| * 4fda3ad19d USB: serial: add device ID for VeriFone adapter
| * 3f01bf964e USB: serial: ftdi_sio: add support for GMC Z216C Adapter IR-USB
| * 4fc30a31e1 powerpc/fsl: Fix mfpmr build errors with newer binutils
| * 86bf75d915 clk: qcom: mmcc-msm8974: fix terminating of frequency table arrays
| * b2dfb216f3 clk: qcom: mmcc-apq8084: fix terminating of frequency table arrays
| * 83fe1bbd9e clk: qcom: gcc-ipq8074: fix terminating of frequency table arrays
| * ddcd5ea7b2 PM: suspend: Set mem_sleep_current during kernel command line setup
| * 42dcb0a374 parisc: Strip upper 32 bit of sum in csum_ipv6_magic for 64-bit builds
| * 10e031fbe5 parisc: Fix csum_ipv6_magic on 64-bit systems
| * 4dc4793c9d parisc: Fix csum_ipv6_magic on 32-bit systems
| * 89cb6c7169 parisc: Fix ip_fast_csum
| * 331b43d79a parisc: Do not hardcode registers in checksum functions
| * 64a1ccfa9a mtd: rawnand: meson: fix scrambling mode value in command macro
| * a1d549aec8 ubi: correct the calculation of fastmap size
| * 4e09d5210b ubi: Check for too small LEB size in VTBL code
| * 778c6ad402 ubifs: Set page uptodate in the correct place
| * f52d7663a1 fat: fix uninitialized field in nostale filehandles
| * b224a3b8d3 ext4: correct best extent lstart adjustment logic
| * e8b25c7bae selftests/mqueue: Set timeout to 180 seconds
| * 8e81cd58ae crypto: qat - resolve race condition during AER recovery
| * 5a9f7e9123 crypto: qat - fix double free during reset
| * fca0c42c34 sparc: vDSO: fix return value of __setup handler
| * 75159bcec2 sparc64: NMI watchdog: fix return value of __setup handler
| * 82e25cc1c2 KVM: Always flush async #PF workqueue when vCPU is being destroyed
| * ce6e52cade media: xc4000: Fix atomicity violation in xc4000_get_frequency
| * 7d271b798a serial: max310x: fix NULL pointer dereference in I2C instantiation
| * d453dd485e arm: dts: marvell: Fix maxium->maxim typo in brownstone dts
| * 36f6b76341 ARM: dts: mmp2-brownstone: Don't redeclare phandle references
| * 60f9cecf6a smack: Handle SMACK64TRANSMUTE in smack_inode_setsecurity()
| * cec55e30e3 smack: Set SMACK64TRANSMUTE only for dirs in smack_inode_setxattr()
| * 9a353d80ba clk: qcom: gcc-sdm845: Add soft dependency on rpmhpd
| * a7923ecece media: staging: ipu3-imgu: Set fields before media_entity_pads_init()
| * 8e3f03f4ef wifi: brcmfmac: Fix use-after-free bug in brcmf_cfg80211_detach
| * df4209170b timers: Rename del_timer_sync() to timer_delete_sync()
| * ef5f71db1e timers: Use del_timer_sync() even on UP
| * 9ec9c420db timers: Update kernel-doc for various functions
| * c513b79129 x86/bugs: Use sysfs_emit()
| * 922bc61d8c x86/cpu: Support AMD Automatic IBRS
| * d9caea5f1b Documentation/hw-vuln: Update spectre doc
| * 8b05647042 amdkfd: use calloc instead of kzalloc to avoid integer overflow
* | ff7463a1e9 Reapply "media: ttpci: fix two memleaks in budget_av_attach"
* | 7cc7098648 Revert "media: rename VFL_TYPE_GRABBER to _VIDEO"
* | b8c488bb24 Revert "media: media/pci: rename VFL_TYPE_GRABBER to _VIDEO"
* | be024bb2cd Revert "media: ttpci: fix two memleaks in budget_av_attach"
* | d873f54a70 Revert "net: ip_tunnel: make sure to pull inner header in ip_tunnel_rcv()"
* | 960240ce53 Merge 5.4.273 into android11-5.4-lts
|\|
| * 24489321d0 Linux 5.4.273
| * b37f030486 regmap: Add missing map->bus check
| * 55f8ea6731 spi: spi-mt65xx: Fix NULL pointer access in interrupt handler
| * 59426454b8 bpf: report RCU QS in cpumap kthread
| * 3ffe591b27 rcu: add a helper to report consolidated flavor QS
| * 2531f907d3 netfilter: nf_tables: do not compare internal table flags on updates
| * 71002d9eb1 ARM: dts: sun8i-h2-plus-bananapi-m2-zero: add regulator nodes vcc-dram and vcc1v2
| * 94cb17e5cf octeontx2-af: Use separate handlers for interrupts
| * 4f37d3a7e0 net/bnx2x: Prevent access to a freed page in page_pool
| * 69f9f55891 hsr: Handle failures in module init
| * f781fb5177 rds: introduce acquire/release ordering in acquire/release_in_xmit()
| * 84c510411e packet: annotate data-races around ignore_outgoing
| * 889ed056ea hsr: Fix uninit-value access in hsr_get_node()
| * 48cef94b69 s390/vtime: fix average steal time calculation
| * 305c31b970 octeontx2-af: Use matching wake_up API variant in CGX command interface
| * b63362b317 usb: gadget: net2272: Use irqflags in the call to net2272_probe_fin
| * 254b27c4ae staging: greybus: fix get_channel_from_mode() failure path
| * f6bf49e76f serial: 8250_exar: Don't remove GPIO device on suspend
| * 8dd52ab78f rtc: mt6397: select IRQ_DOMAIN instead of depending on it
| * ca6279d1a1 kconfig: fix infinite loop when expanding a macro at the end of file
| * a8cc354a81 tty: serial: samsung: fix tx_empty() to return TIOCSER_TEMT
| * f1c9a0c338 serial: max310x: fix syntax error in IRQ error message
| * bd2f4df259 tty: vt: fix 20 vs 0x20 typo in EScsiignore
| * 854ebf45a4 afs: Revert "afs: Hide silly-rename files from userspace"
| * afcbba70bf NFS: Fix an off by one in root_nfs_cat()
| * bcc3ec2bdb watchdog: stm32_iwdg: initialize default timeout
| * e95eeb7f7d net: sunrpc: Fix an off by one in rpc_sockaddr2uaddr()
| * 3b8415daaa scsi: bfa: Fix function pointer type mismatch for hcb_qe->cbfn
| * 2b38dbd7fa RDMA/device: Fix a race between mad_client and cm_client init
| * 39b1af7bc9 scsi: csiostor: Avoid function pointer casts
| * 6d5dc96b15 ALSA: usb-audio: Stop parsing channels bits when all channels are found.
| * d7ae7d1265 clk: Fix clk_core_get NULL dereference
| * a1129b0922 sparc32: Fix section mismatch in leon_pci_grpci
| * c8c038beb4 backlight: lp8788: Fully initialize backlight_properties during probe
| * 8c351a9ef5 backlight: lm3639: Fully initialize backlight_properties during probe
| * 12a0153f78 backlight: da9052: Fully initialize backlight_properties during probe
| * 1c8d8c6b4e backlight: lm3630a: Don't set bl->props.brightness in get_brightness
| * 40a89f1bc4 backlight: lm3630a: Initialize backlight_properties on init
| * bb9981f915 powerpc/embedded6xx: Fix no previous prototype for avr_uart_send() etc.
| * a6e96cc265 drm/msm/dpu: add division of drm_display_mode's hskew parameter
| * 41eec45c71 powerpc/hv-gpci: Fix the H_GET_PERF_COUNTER_INFO hcall return value checks
| * dfde84cc6c drm/mediatek: Fix a null pointer crash in mtk_drm_crtc_finish_page_flip
| * af37aed049 media: ttpci: fix two memleaks in budget_av_attach
| * 353f980a5d media: media/pci: rename VFL_TYPE_GRABBER to _VIDEO
| * fa83fca55c media: rename VFL_TYPE_GRABBER to _VIDEO
| * 25f5765521 media: v4l2-core: correctly validate video and metadata ioctls
| * 291cda0b80 media: go7007: fix a memleak in go7007_load_encoder
| * fa8b472952 media: dvb-frontends: avoid stack overflow warnings with clang
| * d29ed08964 media: pvrusb2: fix uaf in pvr2_context_set_notify
| * 86c10c56f2 drm/amdgpu: Fix missing break in ATOM_ARG_IMM Case of atom_get_src_int()
| * 23d57b99ca ASoC: meson: axg-tdm-interface: fix mclk setup without mclk-fs
| * 8df143c608 mtd: rawnand: lpc32xx_mlc: fix irq handler prototype
| * d9d4d1363b mtd: maps: physmap-core: fix flash size larger than 32-bit
| * a8c73f0439 crypto: arm/sha - fix function cast warnings
| * 4b6569e142 mfd: altera-sysmgr: Call of_node_put() only when of_parse_phandle() takes a ref
| * ac1170674d mfd: syscon: Call of_node_put() only when of_parse_phandle() takes a ref
| * 3472fa83d9 drm/tegra: put drm_gem_object ref on error in tegra_fb_create
| * f27aaaecf7 clk: hisilicon: hi3519: Release the correct number of gates in hi3519_clk_unregister()
| * 44163c73b0 PCI: Mark 3ware-9650SE Root Port Extended Tags as broken
| * 9b074f2ed1 drm/mediatek: dsi: Fix DSI RGB666 formats and definitions
| * 2e1120e480 clk: qcom: dispcc-sdm845: Adjust internal GDSC wait times
| * d2f3c762ba media: pvrusb2: fix pvr2_stream_callback casts
| * e9d391cc70 media: pvrusb2: remove redundant NULL check
| * 013fb50518 media: go7007: add check of return value of go7007_read_addr()
| * 8c2e4efe12 media: imx: csc/scaler: fix v4l2_ctrl_handler memory leak
| * cf95808632 perf stat: Avoid metric-only segv
| * 9e411c40bd ALSA: seq: fix function cast warnings
| * a0ae3335b3 drm/radeon/ni: Fix wrong firmware size logging in ni_init_microcode()
| * 9df9108a91 perf thread_map: Free strlist on normal path in thread_map__new_by_tid_str()
| * 79ab819393 PCI: switchtec: Fix an error handling path in switchtec_pci_probe()
| * 00b07b4962 quota: Fix rcu annotations of inode dquot pointers
| * 49669f8e7e quota: Fix potential NULL pointer dereference
| * ff29b5f9f0 quota: simplify drop_dquot_ref()
| * 68435ffc1c clk: qcom: reset: Ensure write completion on reset de/assertion
| * 026d3984a1 clk: qcom: reset: Commonize the de/assert functions
| * 48846ddc71 clk: qcom: reset: support resetting multiple bits
| * 7f82802d47 clk: qcom: reset: Allow specifying custom reset delay
| * f20c3270f3 media: edia: dvbdev: fix a use-after-free
| * 0175f2d34c media: v4l2-mem2mem: fix a memleak in v4l2_m2m_register_entity
| * 8269ab1641 media: v4l2-tpg: fix some memleaks in tpg_alloc
| * 2e6892b2be media: em28xx: annotate unchecked call to media_device_register()
| * 639155da9b perf evsel: Fix duplicate initialization of data->id in evsel__parse_sample()
| * e019d87e02 drm/amd/display: Fix potential NULL pointer dereferences in 'dcn10_set_output_transfer_func()'
| * 1d4d674173 perf record: Fix possible incorrect free in record__switch_output()
| * adc8a91676 PCI/DPC: Print all TLP Prefixes, not just the first
| * daf21394f9 media: tc358743: register v4l2 async device only after successful setup
| * ba34d8a5aa dmaengine: tegra210-adma: Update dependency to ARCH_TEGRA
| * cc31a90eb7 drm/rockchip: lvds: do not overwrite error code
| * f1dfd026cd drm: Don't treat 0 as -1 in drm_fixp2int_ceil
| * b061b28b66 drm/rockchip: inno_hdmi: Fix video timing
| * 91dc47cd72 drm/tegra: output: Fix missing i2c_put_adapter() in the error handling paths of tegra_output_probe()
| * 030d46f859 drm/tegra: dsi: Fix missing pm_runtime_disable() in the error handling path of tegra_dsi_probe()
| * b4cb57ec2c drm/tegra: dsi: Fix some error handling paths in tegra_dsi_probe()
| * e04e773fb8 drm/tegra: dsi: Make use of the helper function dev_err_probe()
| * 85f28e98c5 gpu: host1x: mipi: Update tegra_mipi_request() to be node based
| * f05631a852 drm/tegra: dsi: Add missing check for of_find_device_by_node
| * da7ece2197 dm: call the resume method on internal suspend
| * 6070692ea3 dm raid: fix false positive for requeue needed during reshape
| * 3b1e8a617e nfp: flower: handle acti_netdevs allocation failure
| * e06f0d3f66 net/x25: fix incorrect parameter validation in the x25_getsockopt() function
| * 26843eefcf net: kcm: fix incorrect parameter validation in the kcm_getsockopt) function
| * b9979cae62 udp: fix incorrect parameter validation in the udp_lib_getsockopt() function
| * 1bd08e5314 l2tp: fix incorrect parameter validation in the pppol2tp_getsockopt() function
| * 2e7f3cabc6 tcp: fix incorrect parameter validation in the do_tcp_getsockopt() function
| * fb6639c748 net: hns3: fix port duplex configure error in IMP reset
| * ec6bb01e02 net: ip_tunnel: make sure to pull inner header in ip_tunnel_rcv()
| * a9f5faf28e ipv6: fib6_rules: flush route cache when rule is changed
| * 21e5fa4688 bpf: Fix stackmap overflow check on 32-bit arches
| * 92c81fbb3e bpf: Fix hashtab overflow check on 32-bit arches
| * 8a8b6a2468 sr9800: Add check for usbnet_get_endpoints
| * 54a03e4ac1 Bluetooth: hci_core: Fix possible buffer overflow
| * f6177a1723 Bluetooth: Remove superfluous call to hci_conn_check_pending()
| * 03df15b579 igb: Fix missing time sync events
| * 141897c5b0 igb: move PEROUT and EXTTS isr logic to separate functions
| * 8081d80a92 mmc: wmt-sdmmc: remove an incorrect release_mem_region() call in the .remove function
| * bfa9d86d39 SUNRPC: fix some memleaks in gssx_dec_option_array
| * 52018aa146 x86, relocs: Ignore relocations in .notes section
| * 450ac90ed4 ACPI: scan: Fix device check notification handling
| * 33b498a123 ARM: dts: imx6dl-yapp4: Move the internal switch PHYs under the switch node
| * 0655698da8 ARM: dts: imx6dl-yapp4: Fix typo in the QCA switch register address
| * 8deafa61fb ARM: dts: imx6dl-yapp4: Move phy reset into switch node
| * 174e3c8ee7 ARM: dts: arm: realview: Fix development chip ROM compatible value
| * de8abc894b net: ena: Remove ena_select_queue
| * f434eacad6 net: ena: cosmetic: fix line break issues
| * a4fc14a662 wifi: brcmsmac: avoid function pointer casts
| * 6234e09e69 iommu/amd: Mark interrupt as managed
| * 073b5bbb13 bus: tegra-aconnect: Update dependency to ARCH_TEGRA
| * ea96bf3f80 ACPI: processor_idle: Fix memory leak in acpi_processor_power_exit()
| * 2eb2a5d6f5 arm64: dts: qcom: msm8996: Pad addresses
| * a8f3650656 arm64: dts: qcom: msm8996: Move regulator consumers to db820c
| * 1f685fa06c arm64: dts: qcom: msm8996: Use node references in db820c
| * adcf4eeb34 arm64: dts: qcom: db820c: Move non-soc entries out of /soc
| * 6bbbd2fd08 bpf: Mark bpf_spin_{lock,unlock}() helpers with notrace correctly
| * 6f51d61a43 bpf: Factor out bpf_spin_lock into helpers.
| * cf0d888ea7 bpf: Add typecast to bpf helpers to help BTF generation
| * e1f7fef6e2 arm64: dts: mediatek: mt7622: add missing "device_type" to memory nodes
| * bea9573c79 wifi: libertas: fix some memleaks in lbs_allocate_cmd_buffer()
| * 6fd9061497 net: blackhole_dev: fix build warning for ethh set but not used
| * ef036a0598 af_unix: Annotate data-race of gc_in_progress in wait_for_unix_gc().
| * 4bdfc38a98 sock_diag: annotate data-races around sock_diag_handlers[family]
| * 76ac9c141e wifi: mwifiex: debugfs: Drop unnecessary error check for debugfs_create_dir()
| * e556006de4 wifi: wilc1000: fix RCU usage in connect path
| * 1bda3ff1fd wifi: wilc1000: fix declarations ordering
| * 8c6210d175 wifi: b43: Disable QoS for bcm4331
| * 12062b149f wifi: b43: Stop correct queue in DMA worker when QoS is disabled
| * c668f0f825 b43: main: Fix use true/false for bool type
| * 47ec637b11 wifi: b43: Stop/wake correct queue in PIO Tx path when QoS is disabled
| * 31aaf17200 wifi: b43: Stop/wake correct queue in DMA Tx path when QoS is disabled
| * 801be44049 b43: dma: Fix use true/false for bool type variable
| * 88a9dffaec wifi: ath10k: fix NULL pointer dereference in ath10k_wmi_tlv_op_pull_mgmt_tx_compl_ev()
| * be26970980 timekeeping: Fix cross-timestamp interpolation for non-x86
| * fee4e84c4e timekeeping: Fix cross-timestamp interpolation corner case decision
| * 7cec7d8388 timekeeping: Fix cross-timestamp interpolation on counter wrap
| * 1a54aa506b aoe: fix the potential use-after-free problem in aoecmd_cfg_pkts
| * 72dacc72b2 fs/select: rework stack allocation hack for clang
| * 44214d744b nbd: null check for nla_nest_start
| * 772a7def98 do_sys_name_to_handle(): use kzalloc() to fix kernel-infoleak
| * 3f6186cc65 ASoC: wm8962: Fix up incorrect error message in wm8962_set_fll
| * 9f27f4d5d1 ASoC: wm8962: Enable both SPKOUTR_ENA and SPKOUTL_ENA in mono mode
| * f1d3be9eb9 ASoC: wm8962: Enable oscillator if selecting WM8962_FLL_OSC
| * 5f3c13930b Input: gpio_keys_polled - suppress deferred probe error for gpio
| * fa14a15373 ASoC: Intel: bytcr_rt5640: Add an extra entry for the Chuwi Vi8 tablet
| * da17f556ad firewire: core: use long bus reset on gap count error
| * 5f369efd9d Bluetooth: rfcomm: Fix null-ptr-deref in rfcomm_check_security
| * 6e9c113992 scsi: mpt3sas: Prevent sending diag_reset when the controller is ready
| * 2daa2a8e89 btrfs: fix data race at btrfs_use_block_rsv() when accessing block reserve
| * 890a1b31fa dm-verity, dm-crypt: align "struct bvec_iter" correctly
| * 5d8afc25c7 block: sed-opal: handle empty atoms when parsing response
| * 745718d00f parisc/ftrace: add missing CONFIG_DYNAMIC_FTRACE check
| * b43b1a7062 net/iucv: fix the allocation size of iucv_path_table array
| * c411a3c828 RDMA/mlx5: Relax DEVX access upon modify commands
| * 69dd0a99da HID: multitouch: Add required quirk for Synaptics 0xcddc device
| * 7d7fa0bea3 MIPS: Clear Cause.BD in instruction_pointer_set
| * 025a8a96c7 x86/xen: Add some null pointer checking to smp.c
| * 4c00abb52a ASoC: rt5645: Make LattePanda board DMI match more precise
| * ef5de5d505 selftests: tls: use exact comparison in recv_partial
| * cfb24022bb io_uring: drop any code related to SCM_RIGHTS
| * 2692b8a016 io_uring/unix: drop usage of io_uring socket
* | f509fa9b09 Revert "regmap: allow to define reg_update_bits for no bus configuration"
* | 012b5eceed Revert "regmap: Add bulk read/write callbacks into regmap_config"
* | 0efa1aa851 Revert "serial: max310x: fix IO data corruption in batched operations"
* | 43bbe91c9f Revert "geneve: make sure to pull inner header in geneve_rx()"
* | ee2f1c68f1 Merge 5.4.272 into android11-5.4-lts
|\|
| * 8407582630 Linux 5.4.272
| * 345ced4052 arm64: dts: qcom: sdm845: fix USB DP/DM HS PHY interrupts
| * 1b3d8cbd1c arm64: dts: qcom: add PDC interrupt controller for SDM845
| * 59b3583da1 serial: max310x: fix IO data corruption in batched operations
| * f5c252aaa1 serial: max310x: implement I2C support
| * 112094efd6 serial: max310x: make accessing revision id interface-agnostic
| * b96b017919 regmap: Add bulk read/write callbacks into regmap_config
| * 758c6799da regmap: allow to define reg_update_bits for no bus configuration
| * 9a7bbea266 serial: max310x: Unprepare and disable clock in error path
| * 664a6a904a getrusage: use sig->stats_lock rather than lock_task_sighand()
| * 2b34f60383 getrusage: use __for_each_thread()
| * c50a059431 getrusage: move thread_group_cputime_adjusted() outside of lock_task_sighand()
| * ef8a8b36a1 getrusage: add the "signal_struct *sig" local variable
| * f184f21978 y2038: rusage: use __kernel_old_timeval
| * c7441c77c9 hv_netvsc: Register VF in netvsc_probe if NET_DEVICE_REGISTER missed
| * f2ab3eaa64 hv_netvsc: use netif_is_bond_master() instead of open code
| * 9b5ef7a528 hv_netvsc: Make netvsc/VF binding check both MAC and serial number
| * 5402ec577f Input: i8042 - fix strange behavior of touchpad on Clevo NS70PU
| * bf6bb3612e serial: max310x: prevent infinite while() loop in port startup
| * 7e30e5c143 serial: max310x: use a separate regmap for each port
| * 3fb7c9bcd0 serial: max310x: use regmap methods for SPI batch operations
| * 2c9c830d74 serial: max310x: Make use of device properties
| * b765176ae1 serial: max310x: fail probe if clock crystal is unstable
| * 816700131e serial: max310x: Try to get crystal clock rate from property
| * c76dcad53b serial: max310x: Use devm_clk_get_optional() to get the input clock
| * b569d91e51 um: allow not setting extra rpaths in the linux binary
| * 47c68edecc selftests: mm: fix map_hugetlb failure on 64K page size systems
| * f9055fa2b2 netrom: Fix data-races around sysctl_net_busy_read
| * 07bbccd1ad netrom: Fix a data-race around sysctl_netrom_link_fails_count
| * c4309e5f8e netrom: Fix a data-race around sysctl_netrom_routing_control
| * cbba77abb4 netrom: Fix a data-race around sysctl_netrom_transport_no_activity_timeout
| * 89aa78a343 netrom: Fix a data-race around sysctl_netrom_transport_requested_window_size
| * 1f60795dca netrom: Fix a data-race around sysctl_netrom_transport_busy_delay
| * 80578681ea netrom: Fix a data-race around sysctl_netrom_transport_acknowledge_delay
| * f716a68234 netrom: Fix a data-race around sysctl_netrom_transport_maximum_tries
| * eadec8da44 netrom: Fix a data-race around sysctl_netrom_transport_timeout
| * eda02a0bed netrom: Fix data-races around sysctl_netrom_network_ttl_initialiser
| * 1e84b108f2 netrom: Fix a data-race around sysctl_netrom_obsolescence_count_initialiser
| * 7f61523255 netrom: Fix a data-race around sysctl_netrom_default_path_quality
| * 4bafcc43ba netfilter: nf_conntrack_h323: Add protection for bmp length out of range
| * 6ec3032022 netfilter: nft_ct: fix l3num expectations with inet pseudo family
| * 997efea2bf net/rds: fix WARNING in rds_conn_connect_if_down
| * 664f9c6472 net/ipv6: avoid possible UAF in ip6_route_mpath_notify()
| * d9fefc5113 net: ice: Fix potential NULL pointer dereference in ice_bridge_setlink()
| * 59d2a40769 geneve: make sure to pull inner header in geneve_rx()
| * a248b1f58a ixgbe: {dis, en}able irqs in ixgbe_txrx_ring_{dis, en}able
| * 7f08778469 net: lan78xx: fix runtime PM count underflow on link stop
| * 81934a2ab5 lan78xx: Fix race conditions in suspend/resume handling
| * 57b9c48cd5 lan78xx: Fix partial packet errors on suspend/resume
| * e68b46e9aa lan78xx: Add missing return code checks
| * b1cc23ffe1 lan78xx: Fix white space and style issues
* | 79ed7de671 Merge branch 'android11-5.4' into branch 'android11-5.4-lts'
* | 26385fa150 UPSTREAM: arm64: dts: qcom: sdm845: fix USB DP/DM HS PHY interrupts
* | e1dfe2d3de UPSTREAM: arm64: dts: qcom: add PDC interrupt controller for SDM845
* | 40df6b551d Merge 5.4.271 into android11-5.4-lts
|\|
| * 3fec063b05 Linux 5.4.271
| * 9162730a83 gpio: 74x164: Enable output pins after registers are reset
| * 1dde8ef4b7 fs,hugetlb: fix NULL pointer dereference in hugetlbs_fill_super
| * 037d5a949b cachefiles: fix memory leak in cachefiles_add_cache()
| * ace0fdf796 x86/cpu/intel: Detect TME keyid bits before setting MTRR mask registers
| * 9d660e5adf mmc: core: Fix eMMC initialization with 1-bit bus connection
| * 3cc5fb824c dmaengine: fsl-qdma: init irq after reg initialization
| * 518d78b4fa dmaengine: fsl-qdma: fix SoC may hang on 16 byte unaligned read
| * c6652e20d7 btrfs: dev-replace: properly validate device names
| * 0cfbb26ee5 wifi: nl80211: reject iftype change with mesh ID change
| * ec92aa2cab gtp: fix use-after-free and null-ptr-deref in gtp_newlink()
| * 5c78be006e afs: Fix endless loop in directory parsing
| * 26dda65b09 ALSA: Drop leftover snd-rtctimer stuff from Makefile
| * 7394abc892 power: supply: bq27xxx-i2c: Do not free non existing IRQ
| * 950d4d74d3 efi/capsule-loader: fix incorrect allocation size
| * b9fbc44159 rtnetlink: fix error logic of IFLA_BRIDGE_FLAGS writing back
| * 260410c589 netfilter: nf_tables: allow NFPROTO_INET in nft_(match/target)_validate()
| * 20f6f150e1 Bluetooth: Enforce validation on max value of connection interval
| * 79820a7e1e Bluetooth: hci_event: Fix handling of HCI_EV_IO_CAPA_REQUEST
| * 98fb98fd37 Bluetooth: Avoid potential use-after-free in hci_error_reset
| * 6e0000a432 net: usb: dm9601: fix wrong return value in dm9601_mdio_read
| * 69624e28d6 lan78xx: enable auto speed configuration for LAN7850 if no EEPROM is detected
| * 9d4ffb5b9d ipv6: fix potential "struct net" leak in inet6_rtm_getaddr()
| * f5f11f7e28 tun: Fix xdp_rxq_info's queue_index when detaching
| * f81e94d2dc net: ip_tunnel: prevent perpetual headroom growth
| * 9ae51361da netlink: Fix kernel-infoleak-after-free in __skb_datagram_iter
* | 7dde2bcd3f ANDROID: GKI: update .xml file due to USB changes in 5.4.270
* | 1ac7c39f24 Merge 5.4.270 into android11-5.4-lts
|\|
| * e133c1ee6d Linux 5.4.270
| * 7a54338219 scripts/bpf: Fix xdp_md forward declaration typo
| * b4eea7a05e fs/aio: Restrict kiocb_set_cancel_fn() to I/O submitted via libaio
| * c28fc1aa6f drm/syncobj: call drm_syncobj_fence_add_wait when WAIT_AVAILABLE flag is set
| * 29db9725f2 drm/syncobj: make lockdep complain on WAIT_FOR_SUBMIT v3
| * ae4360cbd3 netfilter: nf_tables: set dormant flag on hook register failure
| * f310143961 tls: stop recv() if initial process_rx_list gave us non-DATA
| * a26742ada7 tls: rx: drop pointless else after goto
| * c1287c1d6b tls: rx: jump to a more appropriate label
| * 06de230254 s390: use the correct count for __iowrite64_copy()
| * 7eee00feb6 packet: move from strlcpy with unused retval to strscpy
| * 82831e3ff7 ipv6: sr: fix possible use-after-free and null-ptr-deref
| * 5c27d85a69 afs: Increase buffer size in afs_update_volume_status()
| * 799a4afaa5 ipv6: properly combine dev_base_seq and ipv6.dev_addr_genid
| * 5888f34249 ipv4: properly combine dev_base_seq and ipv4.dev_addr_genid
| * a50cb1d6f3 nouveau: fix function cast warnings
| * fe031dfcea scsi: jazz_esp: Only build if SCSI core is builtin
| * dd90af71fa bpf, scripts: Correct GPL license name
| * 1f18b5bb45 scripts/bpf: teach bpf_helpers_doc.py to dump BPF helper definitions
| * 48ebca0a11 RDMA/srpt: fix function pointer cast warnings
| * 3107633774 RDMA/srpt: Make debug output more detailed
| * 6e461952df RDMA/bnxt_re: Return error for SRQ resize
| * cecfb90cf7 IB/hfi1: Fix a memleak in init_credit_return
| * bbcf72333b usb: roles: don't get/set_role() when usb_role_switch is unregistered
| * a31cf46d10 usb: gadget: ncm: Avoid dropping datagrams of properly parsed NTBs
| * aad6132ae6 usb: cdns3: fix memory double free when handle zero packet
| * cfa9abb557 usb: cdns3: fixed memory use after free at cdns3_gadget_ep_disable()
| * 999a8bb70d ARM: ep93xx: Add terminator to gpiod_lookup_table
| * c1d3a84a67 l2tp: pass correct message length to ip6_append_data
| * caf4a67c01 PCI/MSI: Prevent MSI hardware interrupt number truncation
| * f8cbd17919 gtp: fix use-after-free and null-ptr-deref in gtp_genl_dump_pdp()
| * 0dccbb9353 dm-crypt: don't modify the data when using authenticated encryption
| * 5833024a98 IB/hfi1: Fix sdma.h tx->num_descs off-by-one error
| * 6ede985c6b PCI: tegra: Fix OF node reference leak
| * e04a2afd08 PCI: tegra: Fix reporting GPIO error value
| * e3fc080911 arm64: dts: qcom: msm8916: Fix typo in pronto remoteproc node
| * efd63c23a4 drm/amdgpu: Fix type of second parameter in trans_msg() callback
| * f691ab24cf iomap: Set all uptodate bits for an Uptodate page
| * 45227ae32f dm-integrity: don't modify bio's immutable bio_vec in integrity_metadata()
| * 3770c38cd6 x86/alternatives: Disable KASAN in apply_alternatives()
| * f45dc10a3c drm/amdgpu: Check for valid number of registers to read
| * 90aa9135a4 Revert "drm/sun4i: dsi: Change the start delay calculation"
| * 7000efb6d8 ALSA: hda/realtek - Enable micmute LED on and HP system
| * 82c53047fe selftests/bpf: Avoid running unprivileged tests with alignment requirements
| * 81e03f638d net: bridge: clear bridge's private skb space on xmit
| * 82174d6bd7 spi: mt7621: Fix an error message in mt7621_spi_probe()
| * 954a7a0011 pinctrl: rockchip: Fix refcount leak in rockchip_pinctrl_parse_groups
| * 759756e2cf pinctrl: pinctrl-rockchip: Fix a bunch of kerneldoc misdemeanours
| * 99dc568545 tcp: add annotations around sk->sk_shutdown accesses
| * 41ca938616 tcp: return EPOLLOUT from tcp_poll only when notsent_bytes is half the limit
| * 5a9dc14df2 tcp: factor out __tcp_close() helper
| * d428676420 pmdomain: renesas: r8a77980-sysc: CR7 must be always on
| * 3bc35da667 s390/qeth: Fix potential loss of L3-IP@ in case of network issues
| * b7bfaea8f5 virtio-blk: Ensure no requests in virtqueues before deleting vqs.
| * d124ab01fc firewire: core: send bus reset promptly on gap count error
| * b5854f923d scsi: lpfc: Use unsigned type for num_sge
| * 60635f8a05 hwmon: (coretemp) Enlarge per package core count limit
| * 6d338fb1a1 nvmet-fc: abort command when there is no binding
| * ac524b7b3f netfilter: conntrack: check SCTP_CID_SHUTDOWN_ACK for vtag setting in sctp_new
| * 6f5015ce25 ASoC: sunxi: sun4i-spdif: Add support for Allwinner H616
| * c3a25d4fdd nvmet-tcp: fix nvme tcp ida memory leak
| * 5068cb91ed regulator: pwm-regulator: Add validity checks in continuous .get_voltage
| * 6b92b1bc16 ext4: avoid allocating blocks from corrupted group in ext4_mb_find_by_goal()
| * 260fc96283 ext4: avoid allocating blocks from corrupted group in ext4_mb_try_best_found()
| * bccb418eba ahci: add 43-bit DMA address quirk for ASMedia ASM1061 controllers
| * e896bf4878 ahci: asm1166: correct count of reported ports
| * 6db07619d1 fbdev: sis: Error out if pixclock equals zero
| * 84dce0f6a4 fbdev: savage: Error out if pixclock equals zero
| * 85720b69ae wifi: mac80211: fix race condition on enabling fast-xmit
| * d3032de2c8 wifi: cfg80211: fix missing interfaces when dumping
| * bb3813a6a7 dmaengine: fsl-qdma: increase size of 'irq_name'
| * a7229c75c3 dmaengine: shdma: increase size of 'dev_id'
| * 11f3fe5001 scsi: target: core: Add TMF to tmr_list handling
| * d2fc4134aa sched/rt: Disallow writing invalid values to sched_rt_period_us
| * b69677bfd7 sched/rt: Fix sysctl_sched_rr_timeslice intial value
| * 429aaf144b userfaultfd: fix mmap_changing checking in mfill_atomic_hugetlb
| * b0911b8d37 nilfs2: replace WARN_ONs for invalid DAT metadata block requests
| * febd743200 memcg: add refcnt for pcpu stock to avoid UAF problem in drain_all_stock()
| * d7b5bdb52d sched/rt: sysctl_sched_rr_timeslice show default timeslice after reset
| * 010dc505ea net/sched: Retire dsmark qdisc
| * 40e8abb86d net/sched: Retire ATM qdisc
| * 493685f3dd net/sched: Retire CBQ qdisc
| * 9d17e73504 KVM: arm64: vgic-its: Test for valid IRQ in MOVALL handler
| * 68799371c9 KVM: arm64: vgic-its: Test for valid IRQ in its_sync_lpi_pending_table()
* | 3298a76a41 Revert "bpf: Add map and need_defer parameters to .map_fd_put_ptr()"
* | 241e0d860f Revert "hrtimer: Report offline hrtimer enqueue"
* | ce97b1b6bc Revert "drm/mipi-dsi: Fix detach call without attach"
* | 806fb883ea Merge 5.4.269 into android11-5.4-lts
|/
* 6e1f54a498 Linux 5.4.269
* e9aa8e5a72 of: gpio unittest kfree() wrong object
* 6ac8965955 of: unittest: fix EXPECT text for gpio hog errors
* 7dd275ce3b net: bcmgenet: Fix EEE implementation
* 10c586da9f Revert "Revert "mtd: rawnand: gpmi: Fix setting busy timeout setting""
* 25b42be4e0 netfilter: nf_tables: fix pointer math issue in nft_byteorder_eval()
* 3dd76bebcd lsm: new security_file_ioctl_compat() hook
* efdf644062 drm/msm/dsi: Enable runtime PM
* fef59ee6c0 PM: runtime: Have devm_pm_runtime_enable() handle pm_runtime_dont_use_autosuspend()
* 835ed5effb PM: runtime: add devm_pm_runtime_enable helper
* d31c8721e8 nilfs2: fix potential bug in end_buffer_async_write
* 2441a64070 sched/membarrier: reduce the ability to hammer on sys_membarrier
* cd1022eaf8 net: prevent mss overflow in skb_segment()
* 6587af96ef netfilter: ipset: Missing gc cancellations fixed
* c7f2733e50 netfilter: ipset: fix performance regression in swap operation
* d04acadb64 KVM: arm64: vgic-its: Avoid potential UAF in LPI translation cache
* 4705a9fc50 mips: Fix max_mapnr being uninitialized on early stages
* 5e0854b60a arch, mm: remove stale mentions of DISCONIGMEM
* c324e2716d bus: moxtet: Add spi device table
* 7f71d9817c Revert "md/raid5: Wait for MD_SB_CHANGE_PENDING in raid5d"
* 60e092289c tracing: Inform kmemleak of saved_cmdlines allocation
* fbe86124b7 pmdomain: core: Move the unused cleanup to a _sync initcall
* 08de58abed can: j1939: Fix UAF in j1939_sk_match_filter during setsockopt(SO_J1939_FILTER)
* a257ffde37 irqchip/irq-brcmstb-l2: Add write memory barrier before exit
* 91a7c00235 nfp: flower: prevent re-adding mac index for bonded port
* b22c9a37c7 nfp: use correct macro for LengthSelect in BAR config
* 862ee4422c nilfs2: fix hang in nilfs_lookup_dirty_data_buffers()
* a6efe6dbaa nilfs2: fix data corruption in dsync block recovery for small block sizes
* 6ce7d5e6d2 ALSA: hda/conexant: Add quirk for SWS JS201D
* 6b8bdc509e mmc: slot-gpio: Allow non-sleeping GPIO ro
* 4f2fde5051 x86/mm/ident_map: Use gbpages only where full GB page should be mapped.
* 4c7b1d08ad x86/Kconfig: Transmeta Crusoe is CPU family 5, not 6
* ed14ab2611 serial: max310x: improve crystal stable clock detection
* 5814a9045c serial: max310x: set default value when reading clock ready bit
* ef60665ea9 ring-buffer: Clean ring_buffer_poll_wait() error return
* 7200170e88 iio: magnetometer: rm3100: add boundary check for the value read from RM3100_REG_TMRC
* 720d0112b3 staging: iio: ad5933: fix type mismatch regression
* 77e7a316cd tracing: Fix wasted memory in saved_cmdlines logic
* afbcad9ae7 ext4: fix double-free of blocks due to wrong extents moved_len
* 15238f4b21 misc: fastrpc: Mark all sessions as invalid in cb_remove
* 42beab162d binder: signal epoll threads of self-work
* 93a52449fe ALSA: hda/realtek: Enable headset mic on Vaio VJFE-ADL
* 9086b27eac xen-netback: properly sync TX responses
* 71349abe3a nfc: nci: free rx_data_reassembly skb on NCI device cleanup
* 4ae191effb kbuild: Fix changing ELF file type for output of gen_btf for big endian
* 750a4e5999 firewire: core: correct documentation of fw_csr_string() kernel API
* 2209fc6e3d scsi: Revert "scsi: fcoe: Fix potential deadlock on &fip->ctlr_lock"
* d074d5ff5a i2c: i801: Fix block process call transactions
* 4de1489d80 i2c: i801: Remove i801_set_block_buffer_mode
* df112ccb9b usb: f_mass_storage: forbid async queue when shutdown happen
* addaa8627f USB: hub: check for alternate port before enabling A_ALT_HNP_SUPPORT
* dbaca8fa9e HID: wacom: Do not register input devices until after hid_hw_start
* e13bed5cfe HID: wacom: generic: Avoid reporting a serial of '0' to userspace
* 1f12e4b328 mm/writeback: fix possible divide-by-zero in wb_dirty_limits(), again
* 8ffd5590f4 tracing/trigger: Fix to return error if failed to alloc snapshot
* a67f1f83f3 i40e: Fix waiting for queues of all VSIs to be disabled
* 9a3a82affa MIPS: Add 'memory' clobber to csum_ipv6_magic() inline assembler
* 422d5243b9 ASoC: rt5645: Fix deadlock in rt5645_jack_detect_work()
* 91b48c6339 spi: ppc4xx: Drop write-only variable
* 61da1f41d0 of: unittest: Fix compile in the non-dynamic case
* f6997a2416 of: unittest: add overlay gpio test to catch gpio hog problem
* 89485251f6 btrfs: send: return EOPNOTSUPP on unknown flags
* 863837df8a btrfs: forbid deleting live subvol qgroup
* d25031ba2a btrfs: forbid creating subvol qgroups
* 10e9cb3931 netfilter: nft_set_rbtree: skip end interval element from gc
* 7fde2acc6d net: stmmac: xgmac: fix a typo of register name in DPP safety handling
* b9ff931f00 net: stmmac: xgmac: use #define for string constants
* 88c7e1e7a6 vhost: use kzalloc() instead of kmalloc() followed by memset()
* 09e77c7d67 Input: atkbd - skip ATKBD_CMD_SETLEDS when skipping ATKBD_CMD_GETID
* a012efe0df hrtimer: Report offline hrtimer enqueue
* 4a589de93c USB: serial: cp210x: add ID for IMST iM871A-USB
* cd0ab7f2a8 USB: serial: option: add Fibocom FM101-GL variant
* 896695af51 USB: serial: qcserial: add new usb-id for Dell Wireless DW5826e
* 11ca9624cc net/af_iucv: clean up a try_then_request_module()
* 1c7488156e netfilter: nft_ct: reject direction for ct id
* 8e2a84c6da netfilter: nft_compat: restrict match/target protocol to u16
* f139a4c6d2 netfilter: nft_compat: reject unused compat flag
* 56fae81633 ppp_async: limit MRU to 64K
* 6f70f0b412 tipc: Check the bearer type before calling tipc_udp_nl_bearer_add()
* ef1f56f2cd rxrpc: Fix response to PING RESPONSE ACKs to a dead call
* 5993f121fb inet: read sk->sk_family once in inet_recv_error()
* 7c96975c24 hwmon: (coretemp) Fix bogus core_id to attr name mapping
* 1eb74c00c9 hwmon: (coretemp) Fix out-of-bounds memory access
* 51d76b7230 hwmon: (aspeed-pwm-tacho) mutex for tach reading
* df0965935a atm: idt77252: fix a memleak in open_card_ubr0
* a0ac20fd53 selftests: net: avoid just another constant wait
* e9837c83be net: stmmac: xgmac: fix handling of DPP safety error for DMA channels
* 8398d8d735 phy: ti: phy-omap-usb2: Fix NULL pointer dereference for SRP
* 0cb90f27a3 dmaengine: fix is_slave_direction() return false when DMA_DEV_TO_DEV
* 6ff4827315 phy: renesas: rcar-gen3-usb2: Fix returning wrong error code
* 1c75fe450b dmaengine: fsl-qdma: Fix a memory leak related to the queue command DMA
* c263609416 dmaengine: fsl-qdma: Fix a memory leak related to the status queue DMA
* 817bedcd7f bonding: remove print in bond_verify_device_path
* e95120698b HID: apple: Add 2021 magic keyboard FN key mapping
* 5991ab8940 HID: apple: Swap the Fn and Left Control keys on Apple keyboards
* 6d4771ab2d HID: apple: Add support for the 2021 Magic Keyboard
* 67f56ef9e1 net: sysfs: Fix /sys/class/net/<iface> path
* b169ffde73 af_unix: fix lockdep positive in sk_diag_dump_icons()
* b3dace37f1 net: ipv4: fix a memleak in ip_setup_cork
* f549f340c9 netfilter: nft_ct: sanitize layer 3 and 4 protocol number in custom expectations
* 06608603fa netfilter: nf_log: replace BUG_ON by WARN_ON_ONCE when putting logger
* 64babb17e8 llc: call sock_orphan() at release time
* 2a09d1784c ipv6: Ensure natural alignment of const ipv6 loopback and router addresses
* 7f1a24914b ixgbe: Fix an error handling path in ixgbe_read_iosf_sb_reg_x550()
* a10e95d6cf ixgbe: Refactor overtemp event handling
* 2d533ddca2 ixgbe: Refactor returning internal error codes
* 980c806f67 ixgbe: Remove non-inclusive language
* 7c03b74865 net: remove unneeded break
* b81f679ac5 scsi: isci: Fix an error code problem in isci_io_request_build()
* 12f58dce48 wifi: cfg80211: fix RCU dereference in __cfg80211_bss_update
* ad2bd6cd17 perf: Fix the nr_addr_filters fix
* 34da3b9fa5 drm/amdgpu: Release 'adev->pm.fw' before return in 'amdgpu_device_need_post()'
* 6ab4fd508f ceph: fix deadlock or deadcode of misusing dget()
* ecd7744a14 blk-mq: fix IO hang from sbitmap wakeup race
* 977105472f virtio_net: Fix "‘%d’ directive writing between 1 and 11 bytes into a region of size 10" warnings
* 884b746209 libsubcmd: Fix memory leak in uniq()
* 3e06e9b906 PCI/AER: Decode Requester ID when no error info found
* 133bf750d7 fs/kernfs/dir: obey S_ISGID
* 17c252f192 usb: hub: Replace hardcoded quirk value with BIT() macro
* d8c2935499 PCI: switchtec: Fix stdev_release() crash after surprise hot remove
* a32a24da0e PCI: Only override AMD USB controller if required
* e2048eb3cb mfd: ti_am335x_tscadc: Fix TI SoC dependencies
* 838cbe01db i3c: master: cdns: Update maximum prescaler value for i2c clock
* a6946682dd um: net: Fix return type of uml_net_start_xmit()
* c8115f2bd8 um: Don't use vfprintf() for os_info()
* 735a29ce08 um: Fix naming clash between UML and scheduler
* ddd1f258f0 leds: trigger: panic: Don't register panic notifier if creating the trigger failed
* 9052b3e0e7 drm/amdgpu: Drop 'fence' check in 'to_amdgpu_amdkfd_fence()'
* 548f9a37d7 drm/amdgpu: Let KFD sync with VM fences
* 15d674571a clk: mmp: pxa168: Fix memory leak in pxa168_clk_init()
* 105444e207 clk: hi3620: Fix memory leak in hi3620_mmc_clk_init()
* 8a96f1caf1 drm/msm/dpu: Ratelimit framedone timeout msgs
* 4d181fe966 media: ddbridge: fix an error code problem in ddb_probe
* 615e3adc20 IB/ipoib: Fix mcast list locking
* fb703d31fd drm/exynos: Call drm_atomic_helper_shutdown() at shutdown/unbind time
* c1b2e5e837 ALSA: hda: Intel: add HDA_ARL PCI ID support
* c91bda92fb PCI: add INTEL_HDA_ARL to pci_ids.h
* fbbee078cf media: rockchip: rga: fix swizzling for RGB formats
* acb1bffe5f media: stk1160: Fixed high volume of stk1160_dbg messages
* 67997250d3 drm/mipi-dsi: Fix detach call without attach
* d778e10dde drm/framebuffer: Fix use of uninitialized variable
* da980f8db0 drm/drm_file: fix use of uninitialized variable
* 00a5feb060 RDMA/IPoIB: Fix error code return in ipoib_mcast_join
* b0f907a4ef fast_dput(): handle underflows gracefully
* 12ba5b9cf8 ASoC: doc: Fix undefined SND_SOC_DAPM_NOPM argument
* 9fceaf8182 f2fs: fix to check return value of f2fs_reserve_new_block()
* 52240224e7 wifi: cfg80211: free beacon_ies when overridden from hidden BSS
* 18c2989c30 wifi: rtlwifi: rtl8723{be,ae}: using calculate_bit_shift()
* 8ec36f2d0c wifi: rtl8xxxu: Add additional USB IDs for RTL8192EU devices
* f3b7a31bf1 arm64: dts: qcom: msm8998: Fix 'out-ports' is a required property
* c3f22192a2 arm64: dts: qcom: msm8996: Fix 'in-ports' is a required property
* 351b37b88e md: Whenassemble the array, consult the superblock of the freshest device
* 6f2cd02ff5 block: prevent an integer overflow in bvec_try_merge_hw_page
* fb9c25ea0a ARM: dts: imx23/28: Fix the DMA controller node name
* c48e75a7ee ARM: dts: imx23-sansa: Use preferred i2c-gpios properties
* 83b1cceca9 ARM: dts: imx27-apf27dev: Fix LED name
* 06c3f5920f ARM: dts: imx25/27: Pass timing0
* 826e8fa48e ARM: dts: imx1: Fix sram node
* 05f309a3fa ARM: dts: imx27: Fix sram node
* 1e35a4cf5a ARM: dts: imx: Use flash@0,0 pattern
* 30cfab1c8c ARM: dts: imx25/27-eukrea: Fix RTC node name
* ca14da9a1e ARM: dts: rockchip: fix rk3036 hdmi ports node
* e9ac3e3398 scsi: libfc: Fix up timeout error in fc_fcp_rec_error()
* f5a875051e scsi: libfc: Don't schedule abort twice
* eb6f68ec92 bpf: Add map and need_defer parameters to .map_fd_put_ptr()
* f11f0fd1ad wifi: ath9k: Fix potential array-index-out-of-bounds read in ath9k_htc_txstatus()
* 53dd674b32 ARM: dts: imx7s: Fix nand-controller #size-cells
* a86ce3671d ARM: dts: imx7s: Fix lcdif compatible
* 183edc0ad2 ARM: dts: imx7d: Fix coresight funnel ports
* 6c50e561ce bonding: return -ENOMEM instead of BUG in alb_upper_dev_walk
* 4d981d9224 PCI: Add no PM reset quirk for NVIDIA Spectrum devices
* 0e8c8aa8e3 scsi: lpfc: Fix possible file string name overflow when updating firmware
* cbd0b6268a selftests/bpf: Fix pyperf180 compilation failure with clang18
* 982bdaa0fc selftests/bpf: satisfy compiler by having explicit return in btf test
* e1f113b57d wifi: rt2x00: restart beacon queue when hardware reset
* b183fe8702 ext4: avoid online resizing failures due to oversized flex bg
* 92c3c5cfed ext4: remove unnecessary check from alloc_flex_gd()
* 7cb19e1336 ext4: unify the type of flexbg_size to unsigned int
* 360c28a2fd ext4: fix inconsistent between segment fstrim and full fstrim
* ec10755496 ecryptfs: Reject casefold directory inodes
* 7a96d85bf1 SUNRPC: Fix a suspicious RCU usage warning
* 5e63c9ae80 KVM: s390: fix setting of fpc register
* 6d0822f2cc s390/ptrace: handle setting of fpc register correctly
* de6a91aed1 jfs: fix array-index-out-of-bounds in diNewExt
* 592d29eb6b rxrpc_find_service_conn_rcu: fix the usage of read_seqbegin_or_lock()
* f4a0b57632 afs: fix the usage of read_seqbegin_or_lock() in afs_find_server*()
* 3f4cba4cf8 crypto: stm32/crc32 - fix parsing list of devices
* e9f6ac5089 pstore/ram: Fix crash when setting number of cpus to an odd number
* 93df0a2a0b jfs: fix uaf in jfs_evict_inode
* 3f8217c323 jfs: fix array-index-out-of-bounds in dbAdjTree
* 1b9d682858 jfs: fix slab-out-of-bounds Read in dtSearch
* fd3486a893 UBSAN: array-index-out-of-bounds in dtSplitRoot
* 98f9537fe6 FS:JFS:UBSAN:array-index-out-of-bounds in dbAdjTree
* d2049af7dd ACPI: extlog: fix NULL pointer dereference check
* 0d2adafba9 PNP: ACPI: fix fortify warning
* b0b96859ab ACPI: video: Add quirk for the Colorful X15 AT 23 Laptop
* 20277842d9 audit: Send netlink ACK before setting connection in auditd_set
* 27756ae366 regulator: core: Only increment use_count when enable_count changes
* aed181fbc2 perf/core: Fix narrow startup race when creating the perf nr_addr_filters sysfs file
* 980d5fe989 x86/mce: Mark fatal MCE's page as poison to avoid panic in the kdump kernel
* 0580f4403a powerpc/lib: Validate size for vector operations
* 7cd81d2358 powerpc: pmd_move_must_withdraw() is only needed for CONFIG_TRANSPARENT_HUGEPAGE
* 9bf6c6f097 powerpc/mm: Fix build failures due to arch_reserved_kernel_pages()
* 171468044b powerpc: Fix build error due to is_valid_bugaddr()
* f6781add1c powerpc/mm: Fix null-pointer dereference in pgtable_cache_add
* 3cdbfac106 x86/entry/ia32: Ensure s32 is sign extended to s64
* aa8bd0d9b2 tick/sched: Preserve number of idle sleeps across CPU hotplug events
* 200d17b226 mips: Call lose_fpu(0) before initializing fcr31 in mips_set_personality_nan
* b2b0d40775 spi: bcm-qspi: fix SFDP BFPT read by usig mspi read
* 344e8f3392 gpio: eic-sprd: Clear interrupt after set the interrupt type
* f81d67832c drm/exynos: gsc: minor fix for loop iteration in gsc_runtime_resume
* 83d86b4a77 drm/exynos: fix accidental on-stack copy of exynos_drm_plane
* 3e835d6e65 drm/bridge: nxp-ptn3460: simplify some error checking
* 021e214947 drm/bridge: nxp-ptn3460: fix i2c_master_send() error checking
* 9dd334a824 drm: Don't unref the same fb many times by mistake due to deadlock handling
* 5624d628a1 gpiolib: acpi: Ignore touchpad wakeup on GPD G1619-04
* 4e66422f1b netfilter: nf_tables: reject QUEUE/DROP verdict parameters
* bd517df3bd rbd: don't move requests to the running list on errors
* 69a0876252 btrfs: defrag: reject unknown flags of btrfs_ioctl_defrag_range_args
* d0bf04c965 btrfs: don't warn if discard range is not aligned to sector
* 927d1a3d32 btrfs: tree-checker: fix inline ref size in error messages
* 5c9e576bfd btrfs: ref-verify: free ref cache before clearing mount opt
* d3d6162eb1 net: fec: fix the unhandled context fault from smmu
* 3422bfda92 fjes: fix memleaks in fjes_hw_setup
* 07bcc3cd3d netfilter: nf_tables: validate NFPROTO_* family
* b55e492f06 netfilter: nf_tables: restrict anonymous set and map names to 16 bytes
* 2501afe6c4 net/mlx5e: fix a double-free in arfs_create_groups
* bca555e8a2 net/mlx5: Use kfree(ft->g) in arfs_create_groups()
* 0917d771f6 net/mlx5: DR, Use the right GVMI number for drop action
* 4f4dc7098b netlink: fix potential sleeping issue in mqueue_flush_file
* da70948068 tcp: Add memory barrier to tcp_push()
* 01d15b68f0 afs: Hide silly-rename files from userspace
* dad9b28f67 tracing: Ensure visibility when inserting an element into tracing_map
* a37ae111db net/rds: Fix UBSAN: array-index-out-of-bounds in rds_cmsg_recv
* b8e8838f82 llc: Drop support for ETH_P_TR_802_2.
* b643d0defc llc: make llc_ui_sendmsg() more robust against bonding changes
* 06f30fdbc4 vlan: skip nested type that is not IFLA_VLAN_QOS_MAPPING
* 1fea9969b8 net/smc: fix illegal rmb_desc access in SMC-D connection dump
* 5c6183f3c7 x86/CPU/AMD: Fix disabling XSAVES on AMD family 0x17 due to erratum
* 7e180b702a powerpc: Use always instead of always-y in for crtsavres.o
* 457ef4fe54 fs: move S_ISGID stripping into the vfs_*() helpers
* 0cb0093fd6 fs: add mode_strip_sgid() helper
* 635a0039e8 mtd: spinand: macronix: Fix MX35LFxGE4AD page size
* 3f4e660144 block: Remove special-casing of compound pages
* 0785e29899 rename(): fix the locking of subdirectories
* f0824ca283 ubifs: ubifs_symlink: Fix memleak of inode->i_link in error path
* a1e80a33bf nouveau/vmm: don't set addr on the fail path to avoid warning
* f49f9e8027 mmc: core: Use mrq.sbc in close-ended ffu
* e15b1553d0 arm64: dts: qcom: sdm845: fix USB wakeup interrupt types
* 830c99794b parisc/firmware: Fix F-extend for PDC addresses
* dd50fe18c2 rpmsg: virtio: Free driver_override when rpmsg_remove()
* 5030d4c798 hwrng: core - Fix page fault dead lock on mmap-ed hwrng
* 5bc17b4fc2 PM: hibernate: Enforce ordering during image compression/decompression
* cf6889bb8b crypto: api - Disallow identical driver names
* a7edaf40fc ext4: allow for the last group to be marked as trimmed
* e2ecfd5565 serial: sc16is7xx: add check for unsupported SPI modes during probe
* 120b65f80b spi: introduce SPI_MODE_X_MASK macro
* 2b708e6b28 serial: sc16is7xx: set safe default SPI clock frequency
* e53321b341 units: add the HZ macros
* 34d74cf3c7 units: change from 'L' to 'UL'
* 7478445a45 units: Add Watt units
* b617974548 include/linux/units.h: add helpers for kelvin to/from Celsius conversion
* 2ed05a8cc9 PCI: mediatek: Clear interrupt status before dispatching handler

Change-Id: I1ddbcc9d61402546e16694894da56199a22ec74d
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-06-01 07:06:09 +00:00
Greg Kroah-Hartman
4a548b29cd Linux 5.4.277
Link: https://lore.kernel.org/r/20240523130325.743454852@linuxfoundation.org
Tested-by: Florian Fainelli <florian.fainelli@broadcom.com>
Tested-by: Mark Brown <broonie@kernel.org>
Tested-by: Harshit Mogalapalli <harshit.m.mogalapalli@oracle.com>
Tested-by: Linux Kernel Functional Testing <lkft@linaro.org>
Tested-by: Jon Hunter <jonathanh@nvidia.com>
Tested-by: Shuah Khan <skhan@linuxfoundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-05-25 16:17:18 +02:00
Akira Yokosawa
2b21f3095b docs: kernel_include.py: Cope with docutils 0.21
commit d43ddd5c91802a46354fa4c4381416ef760676e2 upstream.

Running "make htmldocs" on a newly installed Sphinx 7.3.7 ends up in
a build error:

    Sphinx parallel build error:
    AttributeError: module 'docutils.nodes' has no attribute 'reprunicode'

docutils 0.21 has removed nodes.reprunicode, quote from release note [1]:

  * Removed objects:

    docutils.nodes.reprunicode, docutils.nodes.ensure_str()
        Python 2 compatibility hacks

Sphinx 7.3.0 supports docutils 0.21 [2]:

kernel_include.py, whose origin is misc.py of docutils, uses reprunicode.

Upstream docutils removed the offending line from the corresponding file
(docutils/docutils/parsers/rst/directives/misc.py) in January 2022.
Quoting the changelog [3]:

    Deprecate `nodes.reprunicode` and `nodes.ensure_str()`.

    Drop uses of the deprecated constructs (not required with Python 3).

Do the same for kernel_include.py.

Tested against:
  - Sphinx 2.4.5 (docutils 0.17.1)
  - Sphinx 3.4.3 (docutils 0.17.1)
  - Sphinx 5.3.0 (docutils 0.18.1)
  - Sphinx 6.2.1 (docutils 0.19)
  - Sphinx 7.2.6 (docutils 0.20.1)
  - Sphinx 7.3.7 (docutils 0.21.2)

Link: http://www.docutils.org/RELEASE-NOTES.html#release-0-21-2024-04-09 [1]
Link: https://www.sphinx-doc.org/en/master/changes.html#release-7-3-0-released-apr-16-2024 [2]
Link: c8471ce47a [3]
Signed-off-by: Akira Yokosawa <akiyks@gmail.com>
Cc: stable@vger.kernel.org
Signed-off-by: Jonathan Corbet <corbet@lwn.net>
Link: https://lore.kernel.org/r/faf5fa45-2a9d-4573-9d2e-3930bdc1ed65@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-05-25 16:17:18 +02:00
Daniel Thompson
ecef5df796 serial: kgdboc: Fix NMI-safety problems from keyboard reset code
commit b2aba15ad6f908d1a620fd97f6af5620c3639742 upstream.

Currently, when kdb is compiled with keyboard support, then we will use
schedule_work() to provoke reset of the keyboard status.  Unfortunately
schedule_work() gets called from the kgdboc post-debug-exception
handler.  That risks deadlock since schedule_work() is not NMI-safe and,
even on platforms where the NMI is not directly used for debugging, the
debug trap can have NMI-like behaviour depending on where breakpoints
are placed.

Fix this by using the irq work system, which is NMI-safe, to defer the
call to schedule_work() to a point when it is safe to call.

Reported-by: Liuye <liu.yeC@h3c.com>
Closes: https://lore.kernel.org/all/20240228025602.3087748-1-liu.yeC@h3c.com/
Cc: stable@vger.kernel.org
Reviewed-by: Douglas Anderson <dianders@chromium.org>
Acked-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Link: https://lore.kernel.org/r/20240424-kgdboc_fix_schedule_work-v2-1-50f5a490aec5@linaro.org
Signed-off-by: Daniel Thompson <daniel.thompson@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-05-25 16:17:18 +02:00
Heikki Krogerus
6b40d4c262 usb: typec: ucsi: displayport: Fix potential deadlock
commit b791a67f68121d69108640d4a3e591d210ffe850 upstream.

The function ucsi_displayport_work() does not access the
connector, so it also must not acquire the connector lock.

This fixes a potential deadlock scenario:

ucsi_displayport_work() -> lock(&con->lock)
typec_altmode_vdm()
dp_altmode_vdm()
dp_altmode_work()
typec_altmode_enter()
ucsi_displayport_enter() -> lock(&con->lock)

Reported-by: Mathias Nyman <mathias.nyman@linux.intel.com>
Fixes: af8622f6a5 ("usb: typec: ucsi: Support for DisplayPort alt mode")
Cc: stable@vger.kernel.org
Signed-off-by: Heikki Krogerus <heikki.krogerus@linux.intel.com>
Link: https://lore.kernel.org/r/20240507134316.161999-1-heikki.krogerus@linux.intel.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-05-25 16:17:18 +02:00
Srinivasan Shanmugam
467139546f drm/amdgpu: Fix possible NULL dereference in amdgpu_ras_query_error_status_helper()
commit b8d55a90fd55b767c25687747e2b24abd1ef8680 upstream.

Return invalid error code -EINVAL for invalid block id.

Fixes the below:

drivers/gpu/drm/amd/amdgpu/amdgpu_ras.c:1183 amdgpu_ras_query_error_status_helper() error: we previously assumed 'info' could be null (see line 1176)

Suggested-by: Hawking Zhang <Hawking.Zhang@amd.com>
Cc: Tao Zhou <tao.zhou1@amd.com>
Cc: Hawking Zhang <Hawking.Zhang@amd.com>
Cc: Christian König <christian.koenig@amd.com>
Cc: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Srinivasan Shanmugam <srinivasan.shanmugam@amd.com>
Reviewed-by: Hawking Zhang <Hawking.Zhang@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
[Ajay: applied AMDGPU_RAS_BLOCK_COUNT condition to amdgpu_ras_error_query()
       as amdgpu_ras_query_error_status_helper() not present in v5.10, v5.4
       amdgpu_ras_query_error_status_helper() was introduced in 8cc0f5669eb6]
Signed-off-by: Ajay Kaher <ajay.kaher@broadcom.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-05-25 16:17:18 +02:00
Dominique Martinet
791d236a68 btrfs: add missing mutex_unlock in btrfs_relocate_sys_chunks()
commit 9af503d91298c3f2945e73703f0e00995be08c30 upstream.

The previous patch that replaced BUG_ON by error handling forgot to
unlock the mutex in the error path.

Link: https://lore.kernel.org/all/Zh%2fHpAGFqa7YAFuM@duo.ucw.cz
Reported-by: Pavel Machek <pavel@denx.de>
Fixes: 7411055db5ce ("btrfs: handle chunk tree lookup error in btrfs_relocate_sys_chunks()")
CC: stable@vger.kernel.org
Reviewed-by: Pavel Machek <pavel@denx.de>
Signed-off-by: Dominique Martinet <dominique.martinet@atmark-techno.com>
Reviewed-by: David Sterba <dsterba@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Dominique Martinet <dominique.martinet@atmark-techno.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-05-25 16:17:18 +02:00
Rob Herring
ea4105d991 arm64: dts: qcom: Fix 'interrupt-map' parent address cells
commit 0ac10b291bee84b00bf9fb2afda444e77e7f88f4 upstream.

The 'interrupt-map' in several QCom SoCs is malformed. The '#address-cells'
size of the parent interrupt controller (the GIC) is not accounted for.

Cc: Andy Gross <agross@kernel.org>
Cc: Bjorn Andersson <bjorn.andersson@linaro.org>
Cc: linux-arm-msm@vger.kernel.org
Signed-off-by: Rob Herring <robh@kernel.org>
Signed-off-by: Bjorn Andersson <bjorn.andersson@linaro.org>
Link: https://lore.kernel.org/r/20210928192210.1842377-1-robh@kernel.org
Signed-off-by: Alex Elder <elder@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-05-25 16:17:18 +02:00
Cristian Marussi
7184491fc5 firmware: arm_scmi: Harden accesses to the reset domains
commit e9076ffbcaed5da6c182b144ef9f6e24554af268 upstream.

Accessing reset domains descriptors by the index upon the SCMI drivers
requests through the SCMI reset operations interface can potentially
lead to out-of-bound violations if the SCMI driver misbehave.

Add an internal consistency check before any such domains descriptors
accesses.

Link: https://lore.kernel.org/r/20220817172731.1185305-5-cristian.marussi@arm.com
Signed-off-by: Cristian Marussi <cristian.marussi@arm.com>
Signed-off-by: Sudeep Holla <sudeep.holla@arm.com>
Signed-off-by: Dominique Martinet <dominique.martinet@atmark-techno.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-05-25 16:17:17 +02:00
Paulo Alcantara
6726429c18 smb: client: fix potential OOBs in smb2_parse_contexts()
commit af1689a9b7701d9907dfc84d2a4b57c4bc907144 upstream.

Validate offsets and lengths before dereferencing create contexts in
smb2_parse_contexts().

This fixes following oops when accessing invalid create contexts from
server:

  BUG: unable to handle page fault for address: ffff8881178d8cc3
  #PF: supervisor read access in kernel mode
  #PF: error_code(0x0000) - not-present page
  PGD 4a01067 P4D 4a01067 PUD 0
  Oops: 0000 [#1] PREEMPT SMP NOPTI
  CPU: 3 PID: 1736 Comm: mount.cifs Not tainted 6.7.0-rc4 #1
  Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS
  rel-1.16.2-3-gd478f380-rebuilt.opensuse.org 04/01/2014
  RIP: 0010:smb2_parse_contexts+0xa0/0x3a0 [cifs]
  Code: f8 10 75 13 48 b8 93 ad 25 50 9c b4 11 e7 49 39 06 0f 84 d2 00
  00 00 8b 45 00 85 c0 74 61 41 29 c5 48 01 c5 41 83 fd 0f 76 55 <0f> b7
  7d 04 0f b7 45 06 4c 8d 74 3d 00 66 83 f8 04 75 bc ba 04 00
  RSP: 0018:ffffc900007939e0 EFLAGS: 00010216
  RAX: ffffc90000793c78 RBX: ffff8880180cc000 RCX: ffffc90000793c90
  RDX: ffffc90000793cc0 RSI: ffff8880178d8cc0 RDI: ffff8880180cc000
  RBP: ffff8881178d8cbf R08: ffffc90000793c22 R09: 0000000000000000
  R10: ffff8880180cc000 R11: 0000000000000024 R12: 0000000000000000
  R13: 0000000000000020 R14: 0000000000000000 R15: ffffc90000793c22
  FS: 00007f873753cbc0(0000) GS:ffff88806bc00000(0000)
  knlGS:0000000000000000
  CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
  CR2: ffff8881178d8cc3 CR3: 00000000181ca000 CR4: 0000000000750ef0
  PKRU: 55555554
  Call Trace:
   <TASK>
   ? __die+0x23/0x70
   ? page_fault_oops+0x181/0x480
   ? search_module_extables+0x19/0x60
   ? srso_alias_return_thunk+0x5/0xfbef5
   ? exc_page_fault+0x1b6/0x1c0
   ? asm_exc_page_fault+0x26/0x30
   ? smb2_parse_contexts+0xa0/0x3a0 [cifs]
   SMB2_open+0x38d/0x5f0 [cifs]
   ? smb2_is_path_accessible+0x138/0x260 [cifs]
   smb2_is_path_accessible+0x138/0x260 [cifs]
   cifs_is_path_remote+0x8d/0x230 [cifs]
   cifs_mount+0x7e/0x350 [cifs]
   cifs_smb3_do_mount+0x128/0x780 [cifs]
   smb3_get_tree+0xd9/0x290 [cifs]
   vfs_get_tree+0x2c/0x100
   ? capable+0x37/0x70
   path_mount+0x2d7/0xb80
   ? srso_alias_return_thunk+0x5/0xfbef5
   ? _raw_spin_unlock_irqrestore+0x44/0x60
   __x64_sys_mount+0x11a/0x150
   do_syscall_64+0x47/0xf0
   entry_SYSCALL_64_after_hwframe+0x6f/0x77
  RIP: 0033:0x7f8737657b1e

Reported-by: Robert Morris <rtm@csail.mit.edu>
Cc: stable@vger.kernel.org
Signed-off-by: Paulo Alcantara (SUSE) <pc@manguebit.com>
Signed-off-by: Steve French <stfrench@microsoft.com>
[Guru: Removed changes to cached_dir.c and checking return value
of smb2_parse_contexts in smb2ops.c]
Signed-off-by: Guruswamy Basavaiah <guruswamy.basavaiah@broadcom.com>
[v5.4: Fixed merge-conflicts in smb2_parse_contexts for
missing parameter POSIX response]
Signed-off-by: Shaoying Xu <shaoyi@amazon.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-05-25 16:17:17 +02:00
Doug Berger
db389e74d3 net: bcmgenet: synchronize UMAC_CMD access
commit 0d5e2a82232605b337972fb2c7d0cbc46898aca1 upstream.

The UMAC_CMD register is written from different execution
contexts and has insufficient synchronization protections to
prevent possible corruption. Of particular concern are the
acceses from the phy_device delayed work context used by the
adjust_link call and the BH context that may be used by the
ndo_set_rx_mode call.

A spinlock is added to the driver to protect contended register
accesses (i.e. reg_lock) and it is used to synchronize accesses
to UMAC_CMD.

Fixes: 1c1008c793 ("net: bcmgenet: add main driver file")
Cc: stable@vger.kernel.org
Signed-off-by: Doug Berger <opendmb@gmail.com>
Acked-by: Florian Fainelli <florian.fainelli@broadcom.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-05-25 16:17:17 +02:00
Doug Berger
ae59f1f444 net: bcmgenet: synchronize use of bcmgenet_set_rx_mode()
commit 2dbe5f19368caae63b1f59f5bc2af78c7d522b3a upstream.

The ndo_set_rx_mode function is synchronized with the
netif_addr_lock spinlock and BHs disabled. Since this
function is also invoked directly from the driver the
same synchronization should be applied.

Fixes: 72f96347628e ("net: bcmgenet: set Rx mode before starting netif")
Cc: stable@vger.kernel.org
Signed-off-by: Doug Berger <opendmb@gmail.com>
Acked-by: Florian Fainelli <florian.fainelli@broadcom.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-05-25 16:17:17 +02:00
Doug Berger
40fc58f86b net: bcmgenet: synchronize EXT_RGMII_OOB_CTRL access
commit d85cf67a339685beae1d0aee27b7f61da95455be upstream.

The EXT_RGMII_OOB_CTRL register can be written from different
contexts. It is predominantly written from the adjust_link
handler which is synchronized by the phydev->lock, but can
also be written from a different context when configuring the
mii in bcmgenet_mii_config().

The chances of contention are quite low, but it is conceivable
that adjust_link could occur during resume when WoL is enabled
so use the phydev->lock synchronizer in bcmgenet_mii_config()
to be sure.

Fixes: afe3f907d2 ("net: bcmgenet: power on MII block for all MII modes")
Cc: stable@vger.kernel.org
Signed-off-by: Doug Berger <opendmb@gmail.com>
Acked-by: Florian Fainelli <florian.fainelli@broadcom.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-05-25 16:17:17 +02:00
Doug Berger
4f470a80ce net: bcmgenet: keep MAC in reset until PHY is up
commit 88f6c8bf1aaed5039923fb4c701cab4d42176275 upstream.

As noted in commit 28c2d1a7a0 ("net: bcmgenet: enable loopback
during UniMAC sw_reset") the UniMAC must be clocked at least 5
cycles while the sw_reset is asserted to ensure a clean reset.

That commit enabled local loopback to provide an Rx clock from the
GENET sourced Tx clk. However, when connected in MII mode the Tx
clk is sourced by the PHY so if an EPHY is not supplying clocks
(e.g. when the link is down) the UniMAC does not receive the
necessary clocks.

This commit extends the sw_reset window until the PHY reports that
the link is up thereby ensuring that the clocks are being provided
to the MAC to produce a clean reset.

One consequence is that if the system attempts to enter a Wake on
LAN suspend state when the PHY link has not been active the MAC
may not have had a chance to initialize cleanly. In this case, we
remove the sw_reset and enable the WoL reception path as normal
with the hope that the PHY will provide the necessary clocks to
drive the WoL blocks if the link becomes active after the system
has entered suspend.

Fixes: 1c1008c793 ("net: bcmgenet: add main driver file")
Signed-off-by: Doug Berger <opendmb@gmail.com>
Acked-by: Florian Fainelli <f.fainelli@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-05-25 16:17:17 +02:00
Doug Berger
bf3ace5c10 Revert "net: bcmgenet: use RGMII loopback for MAC reset"
commit 612eb1c3b9e504de24136c947ed7c07bc342f3aa upstream.

This reverts commit 3a55402c93.

This is not a good solution when connecting to an external switch
that may not support the isolation of the TXC signal resulting in
output driver contention on the pin.

A different solution is necessary.

Signed-off-by: Doug Berger <opendmb@gmail.com>
Acked-by: Florian Fainelli <f.fainelli@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
[Adjusted to accommodate lack of commit 4f8d81b77e66]
Signed-off-by: Doug Berger <opendmb@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-05-25 16:17:17 +02:00
Harshit Mogalapalli
44f0418482 Revert "selftests: mm: fix map_hugetlb failure on 64K page size systems"
This reverts commit 47c68edecc which is
commit 91b80cc5b39f00399e8e2d17527cad2c7fa535e2 upstream.

map_hugetlb.c:18:10: fatal error: vm_util.h: No such file or directory
   18 | #include "vm_util.h"
      |          ^~~~~~~~~~~
compilation terminated.

vm_util.h is not present in 5.4.y, as commit:642bc52aed9c ("selftests:
vm: bring common functions to a new file") is not present in stable
kernels <=6.1.y

Signed-off-by: Harshit Mogalapalli <harshit.m.mogalapalli@oracle.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-05-25 16:17:17 +02:00
Baokun Li
d0083459e2 ext4: fix bug_on in __es_tree_search
commit d36f6ed761b53933b0b4126486c10d3da7751e7f upstream.

Hulk Robot reported a BUG_ON:
==================================================================
kernel BUG at fs/ext4/extents_status.c:199!
[...]
RIP: 0010:ext4_es_end fs/ext4/extents_status.c:199 [inline]
RIP: 0010:__es_tree_search+0x1e0/0x260 fs/ext4/extents_status.c:217
[...]
Call Trace:
 ext4_es_cache_extent+0x109/0x340 fs/ext4/extents_status.c:766
 ext4_cache_extents+0x239/0x2e0 fs/ext4/extents.c:561
 ext4_find_extent+0x6b7/0xa20 fs/ext4/extents.c:964
 ext4_ext_map_blocks+0x16b/0x4b70 fs/ext4/extents.c:4384
 ext4_map_blocks+0xe26/0x19f0 fs/ext4/inode.c:567
 ext4_getblk+0x320/0x4c0 fs/ext4/inode.c:980
 ext4_bread+0x2d/0x170 fs/ext4/inode.c:1031
 ext4_quota_read+0x248/0x320 fs/ext4/super.c:6257
 v2_read_header+0x78/0x110 fs/quota/quota_v2.c:63
 v2_check_quota_file+0x76/0x230 fs/quota/quota_v2.c:82
 vfs_load_quota_inode+0x5d1/0x1530 fs/quota/dquot.c:2368
 dquot_enable+0x28a/0x330 fs/quota/dquot.c:2490
 ext4_quota_enable fs/ext4/super.c:6137 [inline]
 ext4_enable_quotas+0x5d7/0x960 fs/ext4/super.c:6163
 ext4_fill_super+0xa7c9/0xdc00 fs/ext4/super.c:4754
 mount_bdev+0x2e9/0x3b0 fs/super.c:1158
 mount_fs+0x4b/0x1e4 fs/super.c:1261
[...]
==================================================================

Above issue may happen as follows:
-------------------------------------
ext4_fill_super
 ext4_enable_quotas
  ext4_quota_enable
   ext4_iget
    __ext4_iget
     ext4_ext_check_inode
      ext4_ext_check
       __ext4_ext_check
        ext4_valid_extent_entries
         Check for overlapping extents does't take effect
   dquot_enable
    vfs_load_quota_inode
     v2_check_quota_file
      v2_read_header
       ext4_quota_read
        ext4_bread
         ext4_getblk
          ext4_map_blocks
           ext4_ext_map_blocks
            ext4_find_extent
             ext4_cache_extents
              ext4_es_cache_extent
               ext4_es_cache_extent
                __es_tree_search
                 ext4_es_end
                  BUG_ON(es->es_lblk + es->es_len < es->es_lblk)

The error ext4 extents is as follows:
0af3 0300 0400 0000 00000000    extent_header
00000000 0100 0000 12000000     extent1
00000000 0100 0000 18000000     extent2
02000000 0400 0000 14000000     extent3

In the ext4_valid_extent_entries function,
if prev is 0, no error is returned even if lblock<=prev.
This was intended to skip the check on the first extent, but
in the error image above, prev=0+1-1=0 when checking the second extent,
so even though lblock<=prev, the function does not return an error.
As a result, bug_ON occurs in __es_tree_search and the system panics.

To solve this problem, we only need to check that:
1. The lblock of the first extent is not less than 0.
2. The lblock of the next extent  is not less than
   the next block of the previous extent.
The same applies to extent_idx.

Cc: stable@kernel.org
Fixes: 5946d08937 ("ext4: check for overlapping extents in ext4_valid_extent_entries()")
Reported-by: Hulk Robot <hulkci@huawei.com>
Signed-off-by: Baokun Li <libaokun1@huawei.com>
Reviewed-by: Jan Kara <jack@suse.cz>
Link: https://lore.kernel.org/r/20220518120816.1541863-1-libaokun1@huawei.com
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Reported-by: syzbot+2a58d88f0fb315c85363@syzkaller.appspotmail.com
[gpiccoli: Manual backport due to unrelated missing patches.]
Signed-off-by: Guilherme G. Piccoli <gpiccoli@igalia.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-05-25 16:17:16 +02:00
Sergey Shtylyov
c9e7f98f55 pinctrl: core: handle radix_tree_insert() errors in pinctrl_register_one_pin()
commit ecfe9a015d3e1e46504d5b3de7eef1f2d186194a upstream.

pinctrl_register_one_pin() doesn't check the result of radix_tree_insert()
despite they both may return a negative error code.  Linus Walleij said he
has copied the radix tree code from kernel/irq/ where the functions calling
radix_tree_insert() are *void* themselves; I think it makes more sense to
propagate the errors from radix_tree_insert() upstream if we can do that...

Found by Linux Verification Center (linuxtesting.org) with the Svace static
analysis tool.

Signed-off-by: Sergey Shtylyov <s.shtylyov@omp.ru>
Link: https://lore.kernel.org/r/20230719202253.13469-3-s.shtylyov@omp.ru
Signed-off-by: Linus Walleij <linus.walleij@linaro.org>
Cc: "Hemdan, Hagar Gamal Halim" <hagarhem@amazon.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-05-25 16:17:16 +02:00
John Stultz
519c36cd38 UPSTREAM: selftests: timers: Fix valid-adjtimex signed left-shift undefined behavior
[ Upstream commit 076361362122a6d8a4c45f172ced5576b2d4a50d ]

The struct adjtimex freq field takes a signed value who's units are in
shifted (<<16) parts-per-million.

Unfortunately for negative adjustments, the straightforward use of:

  freq = ppm << 16 trips undefined behavior warnings with clang:

valid-adjtimex.c:66:6: warning: shifting a negative signed value is undefined [-Wshift-negative-value]
        -499<<16,
        ~~~~^
valid-adjtimex.c:67:6: warning: shifting a negative signed value is undefined [-Wshift-negative-value]
        -450<<16,
        ~~~~^
..

Fix it by using a multiply by (1 << 16) instead of shifting negative values
in the valid-adjtimex test case. Align the values for better readability.

Bug: 339526723
Reported-by: Lee Jones <joneslee@google.com>
Reported-by: Muhammad Usama Anjum <usama.anjum@collabora.com>
Change-Id: Ied611c13a802acf9c7a2427f0a61eb358b571a3d
Signed-off-by: John Stultz <jstultz@google.com>
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
Reviewed-by: Muhammad Usama Anjum <usama.anjum@collabora.com>
Link: https://lore.kernel.org/r/20240409202222.2830476-1-jstultz@google.com
Link: https://lore.kernel.org/lkml/0c6d4f0d-2064-4444-986b-1d1ed782135f@collabora.com/
Signed-off-by: Sasha Levin <sashal@kernel.org>
(cherry picked from commit 1f3484dec916a3c4f43c4c44bad398bc24373110)
Signed-off-by: Edward Liaw <edliaw@google.com>
2024-05-24 00:17:42 +00:00
Greg Kroah-Hartman
7b99a72942 This is the 5.4.276 stable release
-----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCAAdFiEEZH8oZUiU471FcZm+ONu9yGCSaT4FAmZHJzwACgkQONu9yGCS
 aT5QAhAAmCKbzueOQ+Cte7BL99skul8mog/ujYqENdBymGSQPdOEUb6HYHSOERC+
 0cESIs1Om1ZngPLpjfirdmBV7KvMIc+paTXTQltxAukTfk+vvJgIZPbFRBR31thS
 dquS4vkU7wGSchLIPkl+LKLJzoNka/CrA+ffxzHVHxCF0PoFYmnR0KSUWudCljzW
 fji5T/NBpjvdtpxUl+4SmalYTIT1wHXmGEDZb7TxnpJUgdWV/6VGntH5LCNx4zAA
 ks3aYroOT8WyXgEmyu/ilHnbe6Eyo7bRdebgB/K8seeoBGsU2Bcplr/otDnAcWMT
 SgUcDj3BQj9tclxMhpcoQlCmYAYwVTe9uzu4TIzdyHfx1JRDovD7VMG98V22Kc1r
 xfJyNMKc7rxrvhILmWdAIOuw14hUx8r6aT5vGrPqeOjmMih13CWS3Gpr8ZQQHJLp
 9t00jALadQfAqlS5jNHAoC3OCUATtK11cAOXPROVepA2/t70eMllYEqkNJxbq39F
 eD6Igr6HVa24DuIgdeZFLNyex9NtYyQHzLSYtt6e+aEd8axOhB3VqxqunWAYw817
 FR6+/0GCPPXdI0L9bSI1HfWywNEJRlMMQQNOaM5l5SOZmO0ZaQ2duKpXvVB73IDt
 VkcPC/GLVyrtJddo6xuYBVccZ1FGR50v/5jeUYnvzRN4njNx+Xg=
 =kLCD
 -----END PGP SIGNATURE-----

Merge 5.4.276 into android11-5.4-lts

Changes in 5.4.276
	dmaengine: pl330: issue_pending waits until WFP state
	dmaengine: Revert "dmaengine: pl330: issue_pending waits until WFP state"
	wifi: nl80211: don't free NULL coalescing rule
	pinctrl: core: delete incorrect free in pinctrl_enable()
	pinctrl: mediatek: Check gpio pin number and use binary search in mtk_hw_pin_field_lookup()
	pinctrl: mediatek: Supporting driving setting without mapping current to register value
	pinctrl: mediatek: Refine mtk_pinconf_get() and mtk_pinconf_set()
	pinctrl: mediatek: Refine mtk_pinconf_get()
	pinctrl: mediatek: Backward compatible to previous Mediatek's bias-pull usage
	pinctrl: mediatek: remove shadow variable declaration
	pinctrl: mediatek: paris: Fix PIN_CONFIG_BIAS_* readback
	pinctrl: mediatek: paris: Rework mtk_pinconf_{get,set} switch/case logic
	pinctrl: mediatek: paris: Rework support for PIN_CONFIG_{INPUT,OUTPUT}_ENABLE
	sunrpc: add a struct rpc_stats arg to rpc_create_args
	nfs: expose /proc/net/sunrpc/nfs in net namespaces
	nfs: make the rpc_stat per net namespace
	nfs: Handle error of rpc_proc_register() in nfs_net_init().
	power: rt9455: hide unused rt9455_boost_voltage_values
	pinctrl: devicetree: fix refcount leak in pinctrl_dt_to_map()
	s390/mm: Fix storage key clearing for guest huge pages
	s390/mm: Fix clearing storage keys for huge pages
	bna: ensure the copied buf is NUL terminated
	nsh: Restore skb->{protocol,data,mac_header} for outer header in nsh_gso_segment().
	net l2tp: drop flow hash on forward
	net: qede: use return from qede_parse_flow_attr() for flow_spec
	net: dsa: mv88e6xxx: Add number of MACs in the ATU
	net: dsa: mv88e6xxx: Fix number of databases for 88E6141 / 88E6341
	net: bridge: fix multicast-to-unicast with fraglist GSO
	tipc: fix a possible memleak in tipc_buf_append
	clk: sunxi-ng: h6: Reparent CPUX during PLL CPUX rate change
	scsi: lpfc: Update lpfc_ramp_down_queue_handler() logic
	gfs2: Fix invalid metadata access in punch_hole
	wifi: mac80211: fix ieee80211_bss_*_flags kernel-doc
	wifi: cfg80211: fix rdev_dump_mpp() arguments order
	net: mark racy access on sk->sk_rcvbuf
	scsi: bnx2fc: Remove spin_lock_bh while releasing resources after upload
	ALSA: line6: Zero-initialize message buffers
	net: bcmgenet: Reset RBUF on first open
	ata: sata_gemini: Check clk_enable() result
	firewire: ohci: mask bus reset interrupts between ISR and bottom half
	tools/power turbostat: Fix added raw MSR output
	tools/power turbostat: Fix Bzy_MHz documentation typo
	btrfs: make btrfs_clear_delalloc_extent() free delalloc reserve
	btrfs: always clear PERTRANS metadata during commit
	scsi: target: Fix SELinux error when systemd-modules loads the target module
	gpu: host1x: Do not setup DMA for virtual devices
	MIPS: scall: Save thread_info.syscall unconditionally on entry
	selftests: timers: Fix valid-adjtimex signed left-shift undefined behavior
	fs/9p: only translate RWX permissions for plain 9P2000
	fs/9p: translate O_TRUNC into OTRUNC
	9p: explicitly deny setlease attempts
	gpio: wcove: Use -ENOTSUPP consistently
	gpio: crystalcove: Use -ENOTSUPP consistently
	clk: Don't hold prepare_lock when calling kref_put()
	fs/9p: drop inodes immediately on non-.L too
	net:usb:qmi_wwan: support Rolling modules
	pinctrl: mediatek: Fix fallback call path
	xfrm: Preserve vlan tags for transport mode software GRO
	tcp: defer shutdown(SEND_SHUTDOWN) for TCP_SYN_RECV sockets
	tcp: Use refcount_inc_not_zero() in tcp_twsk_unique().
	Bluetooth: Fix use-after-free bugs caused by sco_sock_timeout
	Bluetooth: l2cap: fix null-ptr-deref in l2cap_chan_timeout
	rtnetlink: Correct nested IFLA_VF_VLAN_LIST attribute validation
	phonet: fix rtm_phonet_notify() skb allocation
	net: bridge: fix corrupted ethernet header on multicast-to-unicast
	ipv6: fib6_rules: avoid possible NULL dereference in fib6_rule_action()
	net: qede: sanitize 'rc' in qede_add_tc_flower_fltr()
	net: qede: use return from qede_parse_flow_attr() for flower
	firewire: nosy: ensure user_length is taken into account when fetching packet contents
	usb: gadget: composite: fix OS descriptors w_value logic
	usb: gadget: f_fs: Fix a race condition when processing setup packets.
	tipc: fix UAF in error path
	dyndbg: fix old BUG_ON in >control parser
	drm/vmwgfx: Fix invalid reads in fence signaled events
	net: fix out-of-bounds access in ops_init
	regulator: core: fix debugfs creation regression
	pinctrl: mediatek: Fix fallback behavior for bias_set_combo
	pinctrl: mediatek: Fix some off by one bugs
	pinctrl: mediatek: remove set but not used variable 'e'
	pinctrl: mediatek: paris: Fix PIN_CONFIG_INPUT_SCHMITT_ENABLE readback
	Linux 5.4.276

Change-Id: Ied32380a46975c946419ee289430c9226038578a
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-05-17 15:29:56 +00:00
Greg Kroah-Hartman
24d2be3797 Linux 5.4.276
Link: https://lore.kernel.org/r/20240514100951.686412426@linuxfoundation.org
Tested-by: Harshit Mogalapalli <harshit.m.mogalapalli@oracle.com>
Tested-by: Florian Fainelli <florian.fainelli@broadcom.com>
Tested-by: Shuah Khan <skhan@linuxfoundation.org>
Tested-by: Linux Kernel Functional Testing <lkft@linaro.org>
Tested-by: Jon Hunter <jonathanh@nvidia.com>
Tested-by: kernelci.org bot <bot@kernelci.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-05-17 11:43:56 +02:00
Chen-Yu Tsai
ef9ea1c4a7 pinctrl: mediatek: paris: Fix PIN_CONFIG_INPUT_SCHMITT_ENABLE readback
commit 08f66a8edd08f6f7cfa769c81634b29a2b123908 upstream.

In the generic pin config library, readback of some options are handled
differently compared to the setting of those options: the argument value
is used to convey enable/disable of an option in the set path, but
success or -EINVAL is used to convey if an option is enabled or disabled
in the debugfs readback path.

PIN_CONFIG_INPUT_SCHMITT_ENABLE is one such option. Fix the readback of
the option in the mediatek-paris library, so that the debugfs dump is
not showing "input schmitt enabled" for pins that don't have it enabled.

Fixes: 1bea6afbc842 ("pinctrl: mediatek: Refine mtk_pinconf_get()")
Signed-off-by: Chen-Yu Tsai <wenst@chromium.org>
Reviewed-by: AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
Message-ID: <20240327091336.3434141-2-wenst@chromium.org>
Signed-off-by: Linus Walleij <linus.walleij@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-05-17 11:43:56 +02:00
YueHaibing
20c17102aa pinctrl: mediatek: remove set but not used variable 'e'
commit 86ecb7d6853c77711c14cb6600179196f179ee2d upstream.

drivers/pinctrl/mediatek/pinctrl-mtk-common-v2.c: In function mtk_hw_pin_field_lookup:
drivers/pinctrl/mediatek/pinctrl-mtk-common-v2.c:70:39: warning:
 variable e set but not used [-Wunused-but-set-variable]

Since commit 3de7deefce69 ("pinctrl: mediatek: Check gpio pin
number and use binary search in mtk_hw_pin_field_lookup()"),
it is not used any more, so remove it, also remove redundant
assignment to variable c, it will be assigned a new value later
before used.

Reported-by: Hulk Robot <hulkci@huawei.com>
Signed-off-by: YueHaibing <yuehaibing@huawei.com>
Reviewed-by: Matthias Brugger <matthias.bgg@gmail.com>
Link: https://lore.kernel.org/r/20200218023625.14324-1-yuehaibing@huawei.com
Signed-off-by: Linus Walleij <linus.walleij@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-05-17 11:43:56 +02:00
Dan Carpenter
fa812e30c9 pinctrl: mediatek: Fix some off by one bugs
commit 3385ab72d995fc0b876818a36203bf2429445686 upstream.

These comparisons should be >= instead of > to prevent accessing one
element beyond the end of the hw->soc->pins[] array.

Fixes: 3de7deefce69 ("pinctrl: mediatek: Check gpio pin number and use binary search in mtk_hw_pin_field_lookup()")
Fixes: 184d8e13f9b1 ("pinctrl: mediatek: Add support for pin configuration dump via debugfs.")
Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
Link: https://lore.kernel.org/r/20200218055247.74s2xa7veqx2do34@kili.mountain
Reviewed-by: Matthias Brugger <matthias.bgg@gmail.com>
Signed-off-by: Linus Walleij <linus.walleij@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-05-17 11:43:55 +02:00
Hsin-Yi Wang
1c86f75da0 pinctrl: mediatek: Fix fallback behavior for bias_set_combo
commit 798a315fc359aa6dbe48e09d802aa59b7e158ffc upstream.

Some pin doesn't support PUPD register, if it fails and fallbacks with
bias_set_combo case, it will call mtk_pinconf_bias_set_pupd_r1_r0() to
modify the PUPD pin again.

Since the general bias set are either PU/PD or PULLSEL/PULLEN, try
bias_set or bias_set_rev1 for the other fallback case. If the pin
doesn't support neither PU/PD nor PULLSEL/PULLEN, it will return
-ENOTSUPP.

Fixes: 81bd1579b43e ("pinctrl: mediatek: Fix fallback call path")
Signed-off-by: Hsin-Yi Wang <hsinyi@chromium.org>
Reviewed-by: Chen-Yu Tsai <wenst@chromium.org>
Reviewed-by: Zhiyong Tao <zhiyong.tao@mediatek.com>
Link: https://lore.kernel.org/r/20210701080955.2660294-1-hsinyi@chromium.org
Signed-off-by: Linus Walleij <linus.walleij@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-05-17 11:43:55 +02:00
Johan Hovold
3bbbcafb0d regulator: core: fix debugfs creation regression
commit 2a4b49bb58123bad6ec0e07b02845f74c23d5e04 upstream.

regulator_get() may sometimes be called more than once for the same
consumer device, something which before commit dbe954d8f163 ("regulator:
core: Avoid debugfs: Directory ...  already present! error") resulted in
errors being logged.

A couple of recent commits broke the handling of such cases so that
attributes are now erroneously created in the debugfs root directory the
second time a regulator is requested and the log is filled with errors
like:

	debugfs: File 'uA_load' in directory '/' already present!
	debugfs: File 'min_uV' in directory '/' already present!
	debugfs: File 'max_uV' in directory '/' already present!
	debugfs: File 'constraint_flags' in directory '/' already present!

on any further calls.

Fixes: 2715bb11cfff ("regulator: core: Fix more error checking for debugfs_create_dir()")
Fixes: 08880713ceec ("regulator: core: Streamline debugfs operations")
Cc: stable@vger.kernel.org
Cc: Geert Uytterhoeven <geert+renesas@glider.be>
Signed-off-by: Johan Hovold <johan+linaro@kernel.org>
Link: https://lore.kernel.org/r/20240509133304.8883-1-johan+linaro@kernel.org
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-05-17 11:43:55 +02:00
Thadeu Lima de Souza Cascardo
7b0e64583e net: fix out-of-bounds access in ops_init
commit a26ff37e624d12e28077e5b24d2b264f62764ad6 upstream.

net_alloc_generic is called by net_alloc, which is called without any
locking. It reads max_gen_ptrs, which is changed under pernet_ops_rwsem. It
is read twice, first to allocate an array, then to set s.len, which is
later used to limit the bounds of the array access.

It is possible that the array is allocated and another thread is
registering a new pernet ops, increments max_gen_ptrs, which is then used
to set s.len with a larger than allocated length for the variable array.

Fix it by reading max_gen_ptrs only once in net_alloc_generic. If
max_gen_ptrs is later incremented, it will be caught in net_assign_generic.

Signed-off-by: Thadeu Lima de Souza Cascardo <cascardo@igalia.com>
Fixes: 073862ba5d ("netns: fix net_alloc_generic()")
Reviewed-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Kuniyuki Iwashima <kuniyu@amazon.com>
Cc: stable@vger.kernel.org
Link: https://lore.kernel.org/r/20240502132006.3430840-1-cascardo@igalia.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-05-17 11:43:55 +02:00
Zack Rusin
cef0962f2d drm/vmwgfx: Fix invalid reads in fence signaled events
commit a37ef7613c00f2d72c8fc08bd83fb6cc76926c8c upstream.

Correctly set the length of the drm_event to the size of the structure
that's actually used.

The length of the drm_event was set to the parent structure instead of
to the drm_vmw_event_fence which is supposed to be read. drm_read
uses the length parameter to copy the event to the user space thus
resuling in oob reads.

Signed-off-by: Zack Rusin <zack.rusin@broadcom.com>
Fixes: 8b7de6aa84 ("vmwgfx: Rework fence event action")
Reported-by: zdi-disclosures@trendmicro.com # ZDI-CAN-23566
Cc: David Airlie <airlied@gmail.com>
CC: Daniel Vetter <daniel@ffwll.ch>
Cc: Zack Rusin <zack.rusin@broadcom.com>
Cc: Broadcom internal kernel review list <bcm-kernel-feedback-list@broadcom.com>
Cc: dri-devel@lists.freedesktop.org
Cc: linux-kernel@vger.kernel.org
Cc: <stable@vger.kernel.org> # v3.4+
Reviewed-by: Maaz Mombasawala <maaz.mombasawala@broadcom.com>
Reviewed-by: Martin Krastev <martin.krastev@broadcom.com>
Link: https://patchwork.freedesktop.org/patch/msgid/20240425192748.1761522-1-zack.rusin@broadcom.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-05-17 11:43:55 +02:00
Jim Cromie
343081c21e dyndbg: fix old BUG_ON in >control parser
commit 00e7d3bea2ce7dac7bee1cf501fb071fd0ea8f6c upstream.

Fix a BUG_ON from 2009.  Even if it looks "unreachable" (I didn't
really look), lets make sure by removing it, doing pr_err and return
-EINVAL instead.

Cc: stable <stable@kernel.org>
Signed-off-by: Jim Cromie <jim.cromie@gmail.com>
Link: https://lore.kernel.org/r/20240429193145.66543-2-jim.cromie@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-05-17 11:43:55 +02:00
Paolo Abeni
93bc2d6d16 tipc: fix UAF in error path
commit 080cbb890286cd794f1ee788bbc5463e2deb7c2b upstream.

Sam Page (sam4k) working with Trend Micro Zero Day Initiative reported
a UAF in the tipc_buf_append() error path:

BUG: KASAN: slab-use-after-free in kfree_skb_list_reason+0x47e/0x4c0
linux/net/core/skbuff.c:1183
Read of size 8 at addr ffff88804d2a7c80 by task poc/8034

CPU: 1 PID: 8034 Comm: poc Not tainted 6.8.2 #1
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS
1.16.0-debian-1.16.0-5 04/01/2014
Call Trace:
 <IRQ>
 __dump_stack linux/lib/dump_stack.c:88
 dump_stack_lvl+0xd9/0x1b0 linux/lib/dump_stack.c:106
 print_address_description linux/mm/kasan/report.c:377
 print_report+0xc4/0x620 linux/mm/kasan/report.c:488
 kasan_report+0xda/0x110 linux/mm/kasan/report.c:601
 kfree_skb_list_reason+0x47e/0x4c0 linux/net/core/skbuff.c:1183
 skb_release_data+0x5af/0x880 linux/net/core/skbuff.c:1026
 skb_release_all linux/net/core/skbuff.c:1094
 __kfree_skb linux/net/core/skbuff.c:1108
 kfree_skb_reason+0x12d/0x210 linux/net/core/skbuff.c:1144
 kfree_skb linux/./include/linux/skbuff.h:1244
 tipc_buf_append+0x425/0xb50 linux/net/tipc/msg.c:186
 tipc_link_input+0x224/0x7c0 linux/net/tipc/link.c:1324
 tipc_link_rcv+0x76e/0x2d70 linux/net/tipc/link.c:1824
 tipc_rcv+0x45f/0x10f0 linux/net/tipc/node.c:2159
 tipc_udp_recv+0x73b/0x8f0 linux/net/tipc/udp_media.c:390
 udp_queue_rcv_one_skb+0xad2/0x1850 linux/net/ipv4/udp.c:2108
 udp_queue_rcv_skb+0x131/0xb00 linux/net/ipv4/udp.c:2186
 udp_unicast_rcv_skb+0x165/0x3b0 linux/net/ipv4/udp.c:2346
 __udp4_lib_rcv+0x2594/0x3400 linux/net/ipv4/udp.c:2422
 ip_protocol_deliver_rcu+0x30c/0x4e0 linux/net/ipv4/ip_input.c:205
 ip_local_deliver_finish+0x2e4/0x520 linux/net/ipv4/ip_input.c:233
 NF_HOOK linux/./include/linux/netfilter.h:314
 NF_HOOK linux/./include/linux/netfilter.h:308
 ip_local_deliver+0x18e/0x1f0 linux/net/ipv4/ip_input.c:254
 dst_input linux/./include/net/dst.h:461
 ip_rcv_finish linux/net/ipv4/ip_input.c:449
 NF_HOOK linux/./include/linux/netfilter.h:314
 NF_HOOK linux/./include/linux/netfilter.h:308
 ip_rcv+0x2c5/0x5d0 linux/net/ipv4/ip_input.c:569
 __netif_receive_skb_one_core+0x199/0x1e0 linux/net/core/dev.c:5534
 __netif_receive_skb+0x1f/0x1c0 linux/net/core/dev.c:5648
 process_backlog+0x101/0x6b0 linux/net/core/dev.c:5976
 __napi_poll.constprop.0+0xba/0x550 linux/net/core/dev.c:6576
 napi_poll linux/net/core/dev.c:6645
 net_rx_action+0x95a/0xe90 linux/net/core/dev.c:6781
 __do_softirq+0x21f/0x8e7 linux/kernel/softirq.c:553
 do_softirq linux/kernel/softirq.c:454
 do_softirq+0xb2/0xf0 linux/kernel/softirq.c:441
 </IRQ>
 <TASK>
 __local_bh_enable_ip+0x100/0x120 linux/kernel/softirq.c:381
 local_bh_enable linux/./include/linux/bottom_half.h:33
 rcu_read_unlock_bh linux/./include/linux/rcupdate.h:851
 __dev_queue_xmit+0x871/0x3ee0 linux/net/core/dev.c:4378
 dev_queue_xmit linux/./include/linux/netdevice.h:3169
 neigh_hh_output linux/./include/net/neighbour.h:526
 neigh_output linux/./include/net/neighbour.h:540
 ip_finish_output2+0x169f/0x2550 linux/net/ipv4/ip_output.c:235
 __ip_finish_output linux/net/ipv4/ip_output.c:313
 __ip_finish_output+0x49e/0x950 linux/net/ipv4/ip_output.c:295
 ip_finish_output+0x31/0x310 linux/net/ipv4/ip_output.c:323
 NF_HOOK_COND linux/./include/linux/netfilter.h:303
 ip_output+0x13b/0x2a0 linux/net/ipv4/ip_output.c:433
 dst_output linux/./include/net/dst.h:451
 ip_local_out linux/net/ipv4/ip_output.c:129
 ip_send_skb+0x3e5/0x560 linux/net/ipv4/ip_output.c:1492
 udp_send_skb+0x73f/0x1530 linux/net/ipv4/udp.c:963
 udp_sendmsg+0x1a36/0x2b40 linux/net/ipv4/udp.c:1250
 inet_sendmsg+0x105/0x140 linux/net/ipv4/af_inet.c:850
 sock_sendmsg_nosec linux/net/socket.c:730
 __sock_sendmsg linux/net/socket.c:745
 __sys_sendto+0x42c/0x4e0 linux/net/socket.c:2191
 __do_sys_sendto linux/net/socket.c:2203
 __se_sys_sendto linux/net/socket.c:2199
 __x64_sys_sendto+0xe0/0x1c0 linux/net/socket.c:2199
 do_syscall_x64 linux/arch/x86/entry/common.c:52
 do_syscall_64+0xd8/0x270 linux/arch/x86/entry/common.c:83
 entry_SYSCALL_64_after_hwframe+0x6f/0x77 linux/arch/x86/entry/entry_64.S:120
RIP: 0033:0x7f3434974f29
Code: 00 c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48
89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d
01 f0 ff ff 73 01 c3 48 8b 0d 37 8f 0d 00 f7 d8 64 89 01 48
RSP: 002b:00007fff9154f2b8 EFLAGS: 00000212 ORIG_RAX: 000000000000002c
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f3434974f29
RDX: 00000000000032c8 RSI: 00007fff9154f300 RDI: 0000000000000003
RBP: 00007fff915532e0 R08: 00007fff91553360 R09: 0000000000000010
R10: 0000000000000000 R11: 0000000000000212 R12: 000055ed86d261d0
R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000
 </TASK>

In the critical scenario, either the relevant skb is freed or its
ownership is transferred into a frag_lists. In both cases, the cleanup
code must not free it again: we need to clear the skb reference earlier.

Fixes: 1149557d64 ("tipc: eliminate unnecessary linearization of incoming buffers")
Cc: stable@vger.kernel.org
Reported-by: zdi-disclosures@trendmicro.com # ZDI-CAN-23852
Acked-by: Xin Long <lucien.xin@gmail.com>
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Link: https://lore.kernel.org/r/752f1ccf762223d109845365d07f55414058e5a3.1714484273.git.pabeni@redhat.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-05-17 11:43:55 +02:00
Chris Wulff
77e49fb4bf usb: gadget: f_fs: Fix a race condition when processing setup packets.
commit 0aea736ddb877b93f6d2dd8cf439840d6b4970a9 upstream.

If the USB driver passes a pointer into the TRB buffer for creq, this
buffer can be overwritten with the status response as soon as the event
is queued. This can make the final check return USB_GADGET_DELAYED_STATUS
when it shouldn't. Instead use the stored wLength.

Fixes: 4d644abf25 ("usb: gadget: f_fs: Only return delayed status when len is 0")
Cc: stable <stable@kernel.org>
Signed-off-by: Chris Wulff <chris.wulff@biamp.com>
Link: https://lore.kernel.org/r/CO1PR17MB5419BD664264A558B2395E28E1112@CO1PR17MB5419.namprd17.prod.outlook.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-05-17 11:43:55 +02:00
Peter Korsgaard
567fed8d82 usb: gadget: composite: fix OS descriptors w_value logic
commit ec6ce7075ef879b91a8710829016005dc8170f17 upstream.

The OS descriptors logic had the high/low byte of w_value inverted, causing
the extended properties to not be accessible for interface != 0.

>From the Microsoft documentation:
https://learn.microsoft.com/en-us/windows-hardware/drivers/usbcon/microsoft-os-1-0-descriptors-specification

OS_Desc_CompatID.doc (w_index = 0x4):

- wValue:

  High Byte = InterfaceNumber.  InterfaceNumber is set to the number of the
  interface or function that is associated with the descriptor, typically
  0x00.  Because a device can have only one extended compat ID descriptor,
  it should ignore InterfaceNumber, regardless of the value, and simply
  return the descriptor.

  Low Byte = 0.  PageNumber is used to retrieve descriptors that are larger
  than 64 KB.  The header section is 16 bytes, so PageNumber is set to 0 for
  this request.

We currently do not support >64KB compat ID descriptors, so verify that the
low byte is 0.

OS_Desc_Ext_Prop.doc (w_index = 0x5):

- wValue:

  High byte = InterfaceNumber.  The high byte of wValue is set to the number
  of the interface or function that is associated with the descriptor.

  Low byte = PageNumber.  The low byte of wValue is used to retrieve
  descriptors that are larger than 64 KB.  The header section is 10 bytes, so
  PageNumber is set to 0 for this request.

We also don't support >64KB extended properties, so verify that the low byte
is 0 and use the high byte for the interface number.

Fixes: 37a3a53342 ("usb: gadget: OS Feature Descriptors support")
Cc: stable <stable@kernel.org>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Link: https://lore.kernel.org/r/20240404100635.3215340-1-peter@korsgaard.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-05-17 11:43:55 +02:00
Thanassis Avgerinos
7b8c7bd229 firewire: nosy: ensure user_length is taken into account when fetching packet contents
commit 38762a0763c10c24a4915feee722d7aa6e73eb98 upstream.

Ensure that packet_buffer_get respects the user_length provided. If
the length of the head packet exceeds the user_length, packet_buffer_get
will now return 0 to signify to the user that no data were read
and a larger buffer size is required. Helps prevent user space overflows.

Signed-off-by: Thanassis Avgerinos <thanassis.avgerinos@gmail.com>
Signed-off-by: Takashi Sakamoto <o-takashi@sakamocchi.jp>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-05-17 11:43:54 +02:00
Asbjørn Sloth Tønnesen
e44d406388 net: qede: use return from qede_parse_flow_attr() for flower
[ Upstream commit fcee2065a178f78be6fd516302830378b17dba3d ]

In qede_add_tc_flower_fltr(), when calling
qede_parse_flow_attr() then the return code
was only used for a non-zero check, and then
-EINVAL was returned.

qede_parse_flow_attr() can currently fail with:
* -EINVAL
* -EOPNOTSUPP
* -EPROTONOSUPPORT

This patch changes the code to use the actual
return code, not just return -EINVAL.

The blaimed commit introduced these functions.

Only compile tested.

Fixes: 2ce9c93eac ("qede: Ingress tc flower offload (drop action) support.")
Signed-off-by: Asbjørn Sloth Tønnesen <ast@fiberby.net>
Reviewed-by: Simon Horman <horms@kernel.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-05-17 11:43:54 +02:00
Asbjørn Sloth Tønnesen
e4bb83fb87 net: qede: sanitize 'rc' in qede_add_tc_flower_fltr()
[ Upstream commit e25714466abd9d96901b15efddf82c60a38abd86 ]

Explicitly set 'rc' (return code), before jumping to the
unlock and return path.

By not having any code depend on that 'rc' remains at
it's initial value of -EINVAL, then we can re-use 'rc' for
the return code of function calls in subsequent patches.

Only compile tested.

Signed-off-by: Asbjørn Sloth Tønnesen <ast@fiberby.net>
Reviewed-by: Simon Horman <horms@kernel.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Stable-dep-of: fcee2065a178 ("net: qede: use return from qede_parse_flow_attr() for flower")
[ resolved conflict in v5.4, no extack for qede_parse_actions() yet ]
Signed-off-by: Asbjørn Sloth Tønnesen <ast@fiberby.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-05-17 11:43:54 +02:00
Eric Dumazet
ddec23f206 ipv6: fib6_rules: avoid possible NULL dereference in fib6_rule_action()
[ Upstream commit d101291b2681e5ab938554e3e323f7a7ee33e3aa ]

syzbot is able to trigger the following crash [1],
caused by unsafe ip6_dst_idev() use.

Indeed ip6_dst_idev() can return NULL, and must always be checked.

[1]

Oops: general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] PREEMPT SMP KASAN PTI
KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]
CPU: 0 PID: 31648 Comm: syz-executor.0 Not tainted 6.9.0-rc4-next-20240417-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/27/2024
 RIP: 0010:__fib6_rule_action net/ipv6/fib6_rules.c:237 [inline]
 RIP: 0010:fib6_rule_action+0x241/0x7b0 net/ipv6/fib6_rules.c:267
Code: 02 00 00 49 8d 9f d8 00 00 00 48 89 d8 48 c1 e8 03 42 80 3c 20 00 74 08 48 89 df e8 f9 32 bf f7 48 8b 1b 48 89 d8 48 c1 e8 03 <42> 80 3c 20 00 74 08 48 89 df e8 e0 32 bf f7 4c 8b 03 48 89 ef 4c
RSP: 0018:ffffc9000fc1f2f0 EFLAGS: 00010246
RAX: 0000000000000000 RBX: 0000000000000000 RCX: 1a772f98c8186700
RDX: 0000000000000003 RSI: ffffffff8bcac4e0 RDI: ffffffff8c1f9760
RBP: ffff8880673fb980 R08: ffffffff8fac15ef R09: 1ffffffff1f582bd
R10: dffffc0000000000 R11: fffffbfff1f582be R12: dffffc0000000000
R13: 0000000000000080 R14: ffff888076509000 R15: ffff88807a029a00
FS:  00007f55e82ca6c0(0000) GS:ffff8880b9400000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000001b31d23000 CR3: 0000000022b66000 CR4: 00000000003506f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
 <TASK>
  fib_rules_lookup+0x62c/0xdb0 net/core/fib_rules.c:317
  fib6_rule_lookup+0x1fd/0x790 net/ipv6/fib6_rules.c:108
  ip6_route_output_flags_noref net/ipv6/route.c:2637 [inline]
  ip6_route_output_flags+0x38e/0x610 net/ipv6/route.c:2649
  ip6_route_output include/net/ip6_route.h:93 [inline]
  ip6_dst_lookup_tail+0x189/0x11a0 net/ipv6/ip6_output.c:1120
  ip6_dst_lookup_flow+0xb9/0x180 net/ipv6/ip6_output.c:1250
  sctp_v6_get_dst+0x792/0x1e20 net/sctp/ipv6.c:326
  sctp_transport_route+0x12c/0x2e0 net/sctp/transport.c:455
  sctp_assoc_add_peer+0x614/0x15c0 net/sctp/associola.c:662
  sctp_connect_new_asoc+0x31d/0x6c0 net/sctp/socket.c:1099
  __sctp_connect+0x66d/0xe30 net/sctp/socket.c:1197
  sctp_connect net/sctp/socket.c:4819 [inline]
  sctp_inet_connect+0x149/0x1f0 net/sctp/socket.c:4834
  __sys_connect_file net/socket.c:2048 [inline]
  __sys_connect+0x2df/0x310 net/socket.c:2065
  __do_sys_connect net/socket.c:2075 [inline]
  __se_sys_connect net/socket.c:2072 [inline]
  __x64_sys_connect+0x7a/0x90 net/socket.c:2072
  do_syscall_x64 arch/x86/entry/common.c:52 [inline]
  do_syscall_64+0xf5/0x240 arch/x86/entry/common.c:83
 entry_SYSCALL_64_after_hwframe+0x77/0x7f

Fixes: 5e5f3f0f80 ("[IPV6] ADDRCONF: Convert ipv6_get_saddr() to ipv6_dev_get_saddr().")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Reviewed-by: David Ahern <dsahern@kernel.org>
Link: https://lore.kernel.org/r/20240507163145.835254-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-05-17 11:43:54 +02:00
Felix Fietkau
2c110b4520 net: bridge: fix corrupted ethernet header on multicast-to-unicast
[ Upstream commit 86b29d830ad69eecff25b22dc96c14c6573718e6 ]

The change from skb_copy to pskb_copy unfortunately changed the data
copying to omit the ethernet header, since it was pulled before reaching
this point. Fix this by calling __skb_push/pull around pskb_copy.

Fixes: 59c878cbcdd8 ("net: bridge: fix multicast-to-unicast with fraglist GSO")
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Acked-by: Nikolay Aleksandrov <razor@blackwall.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-05-17 11:43:54 +02:00
Eric Dumazet
dc6beac059 phonet: fix rtm_phonet_notify() skb allocation
[ Upstream commit d8cac8568618dcb8a51af3db1103e8d4cc4aeea7 ]

fill_route() stores three components in the skb:

- struct rtmsg
- RTA_DST (u8)
- RTA_OIF (u32)

Therefore, rtm_phonet_notify() should use

NLMSG_ALIGN(sizeof(struct rtmsg)) +
nla_total_size(1) +
nla_total_size(4)

Fixes: f062f41d06 ("Phonet: routing table Netlink interface")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Acked-by: Rémi Denis-Courmont <courmisch@gmail.com>
Link: https://lore.kernel.org/r/20240502161700.1804476-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-05-17 11:43:54 +02:00
Roded Zats
5e7ef2d886 rtnetlink: Correct nested IFLA_VF_VLAN_LIST attribute validation
[ Upstream commit 1aec77b2bb2ed1db0f5efc61c4c1ca3813307489 ]

Each attribute inside a nested IFLA_VF_VLAN_LIST is assumed to be a
struct ifla_vf_vlan_info so the size of such attribute needs to be at least
of sizeof(struct ifla_vf_vlan_info) which is 14 bytes.
The current size validation in do_setvfinfo is against NLA_HDRLEN (4 bytes)
which is less than sizeof(struct ifla_vf_vlan_info) so this validation
is not enough and a too small attribute might be cast to a
struct ifla_vf_vlan_info, this might result in an out of bands
read access when accessing the saved (casted) entry in ivvl.

Fixes: 79aab093a0 ("net: Update API for VF vlan protocol 802.1ad support")
Signed-off-by: Roded Zats <rzats@paloaltonetworks.com>
Reviewed-by: Donald Hunter <donald.hunter@gmail.com>
Link: https://lore.kernel.org/r/20240502155751.75705-1-rzats@paloaltonetworks.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-05-17 11:43:54 +02:00
Duoming Zhou
6466ee65e5 Bluetooth: l2cap: fix null-ptr-deref in l2cap_chan_timeout
[ Upstream commit adf0398cee86643b8eacde95f17d073d022f782c ]

There is a race condition between l2cap_chan_timeout() and
l2cap_chan_del(). When we use l2cap_chan_del() to delete the
channel, the chan->conn will be set to null. But the conn could
be dereferenced again in the mutex_lock() of l2cap_chan_timeout().
As a result the null pointer dereference bug will happen. The
KASAN report triggered by POC is shown below:

[  472.074580] ==================================================================
[  472.075284] BUG: KASAN: null-ptr-deref in mutex_lock+0x68/0xc0
[  472.075308] Write of size 8 at addr 0000000000000158 by task kworker/0:0/7
[  472.075308]
[  472.075308] CPU: 0 PID: 7 Comm: kworker/0:0 Not tainted 6.9.0-rc5-00356-g78c0094a146b #36
[  472.075308] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.14.0-0-g155821a1990b-prebuilt.qemu4
[  472.075308] Workqueue: events l2cap_chan_timeout
[  472.075308] Call Trace:
[  472.075308]  <TASK>
[  472.075308]  dump_stack_lvl+0x137/0x1a0
[  472.075308]  print_report+0x101/0x250
[  472.075308]  ? __virt_addr_valid+0x77/0x160
[  472.075308]  ? mutex_lock+0x68/0xc0
[  472.075308]  kasan_report+0x139/0x170
[  472.075308]  ? mutex_lock+0x68/0xc0
[  472.075308]  kasan_check_range+0x2c3/0x2e0
[  472.075308]  mutex_lock+0x68/0xc0
[  472.075308]  l2cap_chan_timeout+0x181/0x300
[  472.075308]  process_one_work+0x5d2/0xe00
[  472.075308]  worker_thread+0xe1d/0x1660
[  472.075308]  ? pr_cont_work+0x5e0/0x5e0
[  472.075308]  kthread+0x2b7/0x350
[  472.075308]  ? pr_cont_work+0x5e0/0x5e0
[  472.075308]  ? kthread_blkcg+0xd0/0xd0
[  472.075308]  ret_from_fork+0x4d/0x80
[  472.075308]  ? kthread_blkcg+0xd0/0xd0
[  472.075308]  ret_from_fork_asm+0x11/0x20
[  472.075308]  </TASK>
[  472.075308] ==================================================================
[  472.094860] Disabling lock debugging due to kernel taint
[  472.096136] BUG: kernel NULL pointer dereference, address: 0000000000000158
[  472.096136] #PF: supervisor write access in kernel mode
[  472.096136] #PF: error_code(0x0002) - not-present page
[  472.096136] PGD 0 P4D 0
[  472.096136] Oops: 0002 [#1] PREEMPT SMP KASAN NOPTI
[  472.096136] CPU: 0 PID: 7 Comm: kworker/0:0 Tainted: G    B              6.9.0-rc5-00356-g78c0094a146b #36
[  472.096136] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.14.0-0-g155821a1990b-prebuilt.qemu4
[  472.096136] Workqueue: events l2cap_chan_timeout
[  472.096136] RIP: 0010:mutex_lock+0x88/0xc0
[  472.096136] Code: be 08 00 00 00 e8 f8 23 1f fd 4c 89 f7 be 08 00 00 00 e8 eb 23 1f fd 42 80 3c 23 00 74 08 48 88
[  472.096136] RSP: 0018:ffff88800744fc78 EFLAGS: 00000246
[  472.096136] RAX: 0000000000000000 RBX: 1ffff11000e89f8f RCX: ffffffff8457c865
[  472.096136] RDX: 0000000000000001 RSI: 0000000000000008 RDI: ffff88800744fc78
[  472.096136] RBP: 0000000000000158 R08: ffff88800744fc7f R09: 1ffff11000e89f8f
[  472.096136] R10: dffffc0000000000 R11: ffffed1000e89f90 R12: dffffc0000000000
[  472.096136] R13: 0000000000000158 R14: ffff88800744fc78 R15: ffff888007405a00
[  472.096136] FS:  0000000000000000(0000) GS:ffff88806d200000(0000) knlGS:0000000000000000
[  472.096136] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[  472.096136] CR2: 0000000000000158 CR3: 000000000da32000 CR4: 00000000000006f0
[  472.096136] Call Trace:
[  472.096136]  <TASK>
[  472.096136]  ? __die_body+0x8d/0xe0
[  472.096136]  ? page_fault_oops+0x6b8/0x9a0
[  472.096136]  ? kernelmode_fixup_or_oops+0x20c/0x2a0
[  472.096136]  ? do_user_addr_fault+0x1027/0x1340
[  472.096136]  ? _printk+0x7a/0xa0
[  472.096136]  ? mutex_lock+0x68/0xc0
[  472.096136]  ? add_taint+0x42/0xd0
[  472.096136]  ? exc_page_fault+0x6a/0x1b0
[  472.096136]  ? asm_exc_page_fault+0x26/0x30
[  472.096136]  ? mutex_lock+0x75/0xc0
[  472.096136]  ? mutex_lock+0x88/0xc0
[  472.096136]  ? mutex_lock+0x75/0xc0
[  472.096136]  l2cap_chan_timeout+0x181/0x300
[  472.096136]  process_one_work+0x5d2/0xe00
[  472.096136]  worker_thread+0xe1d/0x1660
[  472.096136]  ? pr_cont_work+0x5e0/0x5e0
[  472.096136]  kthread+0x2b7/0x350
[  472.096136]  ? pr_cont_work+0x5e0/0x5e0
[  472.096136]  ? kthread_blkcg+0xd0/0xd0
[  472.096136]  ret_from_fork+0x4d/0x80
[  472.096136]  ? kthread_blkcg+0xd0/0xd0
[  472.096136]  ret_from_fork_asm+0x11/0x20
[  472.096136]  </TASK>
[  472.096136] Modules linked in:
[  472.096136] CR2: 0000000000000158
[  472.096136] ---[ end trace 0000000000000000 ]---
[  472.096136] RIP: 0010:mutex_lock+0x88/0xc0
[  472.096136] Code: be 08 00 00 00 e8 f8 23 1f fd 4c 89 f7 be 08 00 00 00 e8 eb 23 1f fd 42 80 3c 23 00 74 08 48 88
[  472.096136] RSP: 0018:ffff88800744fc78 EFLAGS: 00000246
[  472.096136] RAX: 0000000000000000 RBX: 1ffff11000e89f8f RCX: ffffffff8457c865
[  472.096136] RDX: 0000000000000001 RSI: 0000000000000008 RDI: ffff88800744fc78
[  472.096136] RBP: 0000000000000158 R08: ffff88800744fc7f R09: 1ffff11000e89f8f
[  472.132932] R10: dffffc0000000000 R11: ffffed1000e89f90 R12: dffffc0000000000
[  472.132932] R13: 0000000000000158 R14: ffff88800744fc78 R15: ffff888007405a00
[  472.132932] FS:  0000000000000000(0000) GS:ffff88806d200000(0000) knlGS:0000000000000000
[  472.132932] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[  472.132932] CR2: 0000000000000158 CR3: 000000000da32000 CR4: 00000000000006f0
[  472.132932] Kernel panic - not syncing: Fatal exception
[  472.132932] Kernel Offset: disabled
[  472.132932] ---[ end Kernel panic - not syncing: Fatal exception ]---

Add a check to judge whether the conn is null in l2cap_chan_timeout()
in order to mitigate the bug.

Fixes: 3df91ea20e ("Bluetooth: Revert to mutexes from RCU list")
Signed-off-by: Duoming Zhou <duoming@zju.edu.cn>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-05-17 11:43:54 +02:00
Duoming Zhou
3212afd00e Bluetooth: Fix use-after-free bugs caused by sco_sock_timeout
[ Upstream commit 483bc08181827fc475643272ffb69c533007e546 ]

When the sco connection is established and then, the sco socket
is releasing, timeout_work will be scheduled to judge whether
the sco disconnection is timeout. The sock will be deallocated
later, but it is dereferenced again in sco_sock_timeout. As a
result, the use-after-free bugs will happen. The root cause is
shown below:

    Cleanup Thread               |      Worker Thread
sco_sock_release                 |
  sco_sock_close                 |
    __sco_sock_close             |
      sco_sock_set_timer         |
        schedule_delayed_work    |
  sco_sock_kill                  |    (wait a time)
    sock_put(sk) //FREE          |  sco_sock_timeout
                                 |    sock_hold(sk) //USE

The KASAN report triggered by POC is shown below:

[   95.890016] ==================================================================
[   95.890496] BUG: KASAN: slab-use-after-free in sco_sock_timeout+0x5e/0x1c0
[   95.890755] Write of size 4 at addr ffff88800c388080 by task kworker/0:0/7
...
[   95.890755] Workqueue: events sco_sock_timeout
[   95.890755] Call Trace:
[   95.890755]  <TASK>
[   95.890755]  dump_stack_lvl+0x45/0x110
[   95.890755]  print_address_description+0x78/0x390
[   95.890755]  print_report+0x11b/0x250
[   95.890755]  ? __virt_addr_valid+0xbe/0xf0
[   95.890755]  ? sco_sock_timeout+0x5e/0x1c0
[   95.890755]  kasan_report+0x139/0x170
[   95.890755]  ? update_load_avg+0xe5/0x9f0
[   95.890755]  ? sco_sock_timeout+0x5e/0x1c0
[   95.890755]  kasan_check_range+0x2c3/0x2e0
[   95.890755]  sco_sock_timeout+0x5e/0x1c0
[   95.890755]  process_one_work+0x561/0xc50
[   95.890755]  worker_thread+0xab2/0x13c0
[   95.890755]  ? pr_cont_work+0x490/0x490
[   95.890755]  kthread+0x279/0x300
[   95.890755]  ? pr_cont_work+0x490/0x490
[   95.890755]  ? kthread_blkcg+0xa0/0xa0
[   95.890755]  ret_from_fork+0x34/0x60
[   95.890755]  ? kthread_blkcg+0xa0/0xa0
[   95.890755]  ret_from_fork_asm+0x11/0x20
[   95.890755]  </TASK>
[   95.890755]
[   95.890755] Allocated by task 506:
[   95.890755]  kasan_save_track+0x3f/0x70
[   95.890755]  __kasan_kmalloc+0x86/0x90
[   95.890755]  __kmalloc+0x17f/0x360
[   95.890755]  sk_prot_alloc+0xe1/0x1a0
[   95.890755]  sk_alloc+0x31/0x4e0
[   95.890755]  bt_sock_alloc+0x2b/0x2a0
[   95.890755]  sco_sock_create+0xad/0x320
[   95.890755]  bt_sock_create+0x145/0x320
[   95.890755]  __sock_create+0x2e1/0x650
[   95.890755]  __sys_socket+0xd0/0x280
[   95.890755]  __x64_sys_socket+0x75/0x80
[   95.890755]  do_syscall_64+0xc4/0x1b0
[   95.890755]  entry_SYSCALL_64_after_hwframe+0x67/0x6f
[   95.890755]
[   95.890755] Freed by task 506:
[   95.890755]  kasan_save_track+0x3f/0x70
[   95.890755]  kasan_save_free_info+0x40/0x50
[   95.890755]  poison_slab_object+0x118/0x180
[   95.890755]  __kasan_slab_free+0x12/0x30
[   95.890755]  kfree+0xb2/0x240
[   95.890755]  __sk_destruct+0x317/0x410
[   95.890755]  sco_sock_release+0x232/0x280
[   95.890755]  sock_close+0xb2/0x210
[   95.890755]  __fput+0x37f/0x770
[   95.890755]  task_work_run+0x1ae/0x210
[   95.890755]  get_signal+0xe17/0xf70
[   95.890755]  arch_do_signal_or_restart+0x3f/0x520
[   95.890755]  syscall_exit_to_user_mode+0x55/0x120
[   95.890755]  do_syscall_64+0xd1/0x1b0
[   95.890755]  entry_SYSCALL_64_after_hwframe+0x67/0x6f
[   95.890755]
[   95.890755] The buggy address belongs to the object at ffff88800c388000
[   95.890755]  which belongs to the cache kmalloc-1k of size 1024
[   95.890755] The buggy address is located 128 bytes inside of
[   95.890755]  freed 1024-byte region [ffff88800c388000, ffff88800c388400)
[   95.890755]
[   95.890755] The buggy address belongs to the physical page:
[   95.890755] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0xffff88800c38a800 pfn:0xc388
[   95.890755] head: order:3 entire_mapcount:0 nr_pages_mapped:0 pincount:0
[   95.890755] anon flags: 0x100000000000840(slab|head|node=0|zone=1)
[   95.890755] page_type: 0xffffffff()
[   95.890755] raw: 0100000000000840 ffff888006842dc0 0000000000000000 0000000000000001
[   95.890755] raw: ffff88800c38a800 000000000010000a 00000001ffffffff 0000000000000000
[   95.890755] head: 0100000000000840 ffff888006842dc0 0000000000000000 0000000000000001
[   95.890755] head: ffff88800c38a800 000000000010000a 00000001ffffffff 0000000000000000
[   95.890755] head: 0100000000000003 ffffea000030e201 ffffea000030e248 00000000ffffffff
[   95.890755] head: 0000000800000000 0000000000000000 00000000ffffffff 0000000000000000
[   95.890755] page dumped because: kasan: bad access detected
[   95.890755]
[   95.890755] Memory state around the buggy address:
[   95.890755]  ffff88800c387f80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[   95.890755]  ffff88800c388000: fa fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
[   95.890755] >ffff88800c388080: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
[   95.890755]                    ^
[   95.890755]  ffff88800c388100: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
[   95.890755]  ffff88800c388180: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
[   95.890755] ==================================================================

Fix this problem by adding a check protected by sco_conn_lock to judget
whether the conn->hcon is null. Because the conn->hcon will be set to null,
when the sock is releasing.

Fixes: ba316be1b6a0 ("Bluetooth: schedule SCO timeouts with delayed_work")
Signed-off-by: Duoming Zhou <duoming@zju.edu.cn>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-05-17 11:43:53 +02:00
Kuniyuki Iwashima
1796ca9c6f tcp: Use refcount_inc_not_zero() in tcp_twsk_unique().
[ Upstream commit f2db7230f73a80dbb179deab78f88a7947f0ab7e ]

Anderson Nascimento reported a use-after-free splat in tcp_twsk_unique()
with nice analysis.

Since commit ec94c2696f ("tcp/dccp: avoid one atomic operation for
timewait hashdance"), inet_twsk_hashdance() sets TIME-WAIT socket's
sk_refcnt after putting it into ehash and releasing the bucket lock.

Thus, there is a small race window where other threads could try to
reuse the port during connect() and call sock_hold() in tcp_twsk_unique()
for the TIME-WAIT socket with zero refcnt.

If that happens, the refcnt taken by tcp_twsk_unique() is overwritten
and sock_put() will cause underflow, triggering a real use-after-free
somewhere else.

To avoid the use-after-free, we need to use refcount_inc_not_zero() in
tcp_twsk_unique() and give up on reusing the port if it returns false.

[0]:
refcount_t: addition on 0; use-after-free.
WARNING: CPU: 0 PID: 1039313 at lib/refcount.c:25 refcount_warn_saturate+0xe5/0x110
CPU: 0 PID: 1039313 Comm: trigger Not tainted 6.8.6-200.fc39.x86_64 #1
Hardware name: VMware, Inc. VMware20,1/440BX Desktop Reference Platform, BIOS VMW201.00V.21805430.B64.2305221830 05/22/2023
RIP: 0010:refcount_warn_saturate+0xe5/0x110
Code: 42 8e ff 0f 0b c3 cc cc cc cc 80 3d aa 13 ea 01 00 0f 85 5e ff ff ff 48 c7 c7 f8 8e b7 82 c6 05 96 13 ea 01 01 e8 7b 42 8e ff <0f> 0b c3 cc cc cc cc 48 c7 c7 50 8f b7 82 c6 05 7a 13 ea 01 01 e8
RSP: 0018:ffffc90006b43b60 EFLAGS: 00010282
RAX: 0000000000000000 RBX: ffff888009bb3ef0 RCX: 0000000000000027
RDX: ffff88807be218c8 RSI: 0000000000000001 RDI: ffff88807be218c0
RBP: 0000000000069d70 R08: 0000000000000000 R09: ffffc90006b439f0
R10: ffffc90006b439e8 R11: 0000000000000003 R12: ffff8880029ede84
R13: 0000000000004e20 R14: ffffffff84356dc0 R15: ffff888009bb3ef0
FS:  00007f62c10926c0(0000) GS:ffff88807be00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000020ccb000 CR3: 000000004628c005 CR4: 0000000000f70ef0
PKRU: 55555554
Call Trace:
 <TASK>
 ? refcount_warn_saturate+0xe5/0x110
 ? __warn+0x81/0x130
 ? refcount_warn_saturate+0xe5/0x110
 ? report_bug+0x171/0x1a0
 ? refcount_warn_saturate+0xe5/0x110
 ? handle_bug+0x3c/0x80
 ? exc_invalid_op+0x17/0x70
 ? asm_exc_invalid_op+0x1a/0x20
 ? refcount_warn_saturate+0xe5/0x110
 tcp_twsk_unique+0x186/0x190
 __inet_check_established+0x176/0x2d0
 __inet_hash_connect+0x74/0x7d0
 ? __pfx___inet_check_established+0x10/0x10
 tcp_v4_connect+0x278/0x530
 __inet_stream_connect+0x10f/0x3d0
 inet_stream_connect+0x3a/0x60
 __sys_connect+0xa8/0xd0
 __x64_sys_connect+0x18/0x20
 do_syscall_64+0x83/0x170
 entry_SYSCALL_64_after_hwframe+0x78/0x80
RIP: 0033:0x7f62c11a885d
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d a3 45 0c 00 f7 d8 64 89 01 48
RSP: 002b:00007f62c1091e58 EFLAGS: 00000296 ORIG_RAX: 000000000000002a
RAX: ffffffffffffffda RBX: 0000000020ccb004 RCX: 00007f62c11a885d
RDX: 0000000000000010 RSI: 0000000020ccb000 RDI: 0000000000000003
RBP: 00007f62c1091e90 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000296 R12: 00007f62c10926c0
R13: ffffffffffffff88 R14: 0000000000000000 R15: 00007ffe237885b0
 </TASK>

Fixes: ec94c2696f ("tcp/dccp: avoid one atomic operation for timewait hashdance")
Reported-by: Anderson Nascimento <anderson@allelesecurity.com>
Closes: https://lore.kernel.org/netdev/37a477a6-d39e-486b-9577-3463f655a6b7@allelesecurity.com/
Suggested-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: Kuniyuki Iwashima <kuniyu@amazon.com>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Link: https://lore.kernel.org/r/20240501213145.62261-1-kuniyu@amazon.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-05-17 11:43:53 +02:00
Eric Dumazet
ed5e279b69 tcp: defer shutdown(SEND_SHUTDOWN) for TCP_SYN_RECV sockets
[ Upstream commit 94062790aedb505bdda209b10bea47b294d6394f ]

TCP_SYN_RECV state is really special, it is only used by
cross-syn connections, mostly used by fuzzers.

In the following crash [1], syzbot managed to trigger a divide
by zero in tcp_rcv_space_adjust()

A socket makes the following state transitions,
without ever calling tcp_init_transfer(),
meaning tcp_init_buffer_space() is also not called.

         TCP_CLOSE
connect()
         TCP_SYN_SENT
         TCP_SYN_RECV
shutdown() -> tcp_shutdown(sk, SEND_SHUTDOWN)
         TCP_FIN_WAIT1

To fix this issue, change tcp_shutdown() to not
perform a TCP_SYN_RECV -> TCP_FIN_WAIT1 transition,
which makes no sense anyway.

When tcp_rcv_state_process() later changes socket state
from TCP_SYN_RECV to TCP_ESTABLISH, then look at
sk->sk_shutdown to finally enter TCP_FIN_WAIT1 state,
and send a FIN packet from a sane socket state.

This means tcp_send_fin() can now be called from BH
context, and must use GFP_ATOMIC allocations.

[1]
divide error: 0000 [#1] PREEMPT SMP KASAN NOPTI
CPU: 1 PID: 5084 Comm: syz-executor358 Not tainted 6.9.0-rc6-syzkaller-00022-g98369dccd2f8 #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/27/2024
 RIP: 0010:tcp_rcv_space_adjust+0x2df/0x890 net/ipv4/tcp_input.c:767
Code: e3 04 4c 01 eb 48 8b 44 24 38 0f b6 04 10 84 c0 49 89 d5 0f 85 a5 03 00 00 41 8b 8e c8 09 00 00 89 e8 29 c8 48 0f af c3 31 d2 <48> f7 f1 48 8d 1c 43 49 8d 96 76 08 00 00 48 89 d0 48 c1 e8 03 48
RSP: 0018:ffffc900031ef3f0 EFLAGS: 00010246
RAX: 0c677a10441f8f42 RBX: 000000004fb95e7e RCX: 0000000000000000
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000
RBP: 0000000027d4b11f R08: ffffffff89e535a4 R09: 1ffffffff25e6ab7
R10: dffffc0000000000 R11: ffffffff8135e920 R12: ffff88802a9f8d30
R13: dffffc0000000000 R14: ffff88802a9f8d00 R15: 1ffff1100553f2da
FS:  00005555775c0380(0000) GS:ffff8880b9500000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f1155bf2304 CR3: 000000002b9f2000 CR4: 0000000000350ef0
Call Trace:
 <TASK>
  tcp_recvmsg_locked+0x106d/0x25a0 net/ipv4/tcp.c:2513
  tcp_recvmsg+0x25d/0x920 net/ipv4/tcp.c:2578
  inet6_recvmsg+0x16a/0x730 net/ipv6/af_inet6.c:680
  sock_recvmsg_nosec net/socket.c:1046 [inline]
  sock_recvmsg+0x109/0x280 net/socket.c:1068
  ____sys_recvmsg+0x1db/0x470 net/socket.c:2803
  ___sys_recvmsg net/socket.c:2845 [inline]
  do_recvmmsg+0x474/0xae0 net/socket.c:2939
  __sys_recvmmsg net/socket.c:3018 [inline]
  __do_sys_recvmmsg net/socket.c:3041 [inline]
  __se_sys_recvmmsg net/socket.c:3034 [inline]
  __x64_sys_recvmmsg+0x199/0x250 net/socket.c:3034
  do_syscall_x64 arch/x86/entry/common.c:52 [inline]
  do_syscall_64+0xf5/0x240 arch/x86/entry/common.c:83
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7faeb6363db9
Code: 28 00 00 00 75 05 48 83 c4 28 c3 e8 c1 17 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007ffcc1997168 EFLAGS: 00000246 ORIG_RAX: 000000000000012b
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007faeb6363db9
RDX: 0000000000000001 RSI: 0000000020000bc0 RDI: 0000000000000005
RBP: 0000000000000000 R08: 0000000000000000 R09: 000000000000001c
R10: 0000000000000122 R11: 0000000000000246 R12: 0000000000000000
R13: 0000000000000000 R14: 0000000000000001 R15: 0000000000000001

Fixes: 1da177e4c3 ("Linux-2.6.12-rc2")
Reported-by: syzbot <syzkaller@googlegroups.com>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Acked-by: Neal Cardwell <ncardwell@google.com>
Link: https://lore.kernel.org/r/20240501125448.896529-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-05-17 11:43:53 +02:00