Commit graph

906,677 commits

Author SHA1 Message Date
Kalesh Singh
87d2008253 ANDROID: 16K: Remove ELF padding entry from map_file ranges
Symbolization techniques use address ranges as reported in /proc/*/maps
to infer the corresponding /proc/*/map_files/ entry.

Per Daniel, this is done because the path in /proc/*/maps is problematic
for at least two reasons:

    1. The file could have been deleted from the file system (this is
       indicated with the  (deleted) suffix), meaning that you can't
       actually open it through the "regular" file system. However,
       while the mapping is alive, the kernel keeps the inode accessible
       via the corresponding /proc/*/map_files entry, allowing for
       access after all.

    2. It makes dealing with changed root and file system namespaces
       much more painful. The /proc/*/maps path is relative, and so now
       you need to concatenate paths etc. Accessing file through
       /proc/*/map_files just works (assuming necessary permissions), as
       the kernel redirects the request to the proper inode,
       irrespective of how it is exposed through the non-proc
       filesystem.

Android extends ELF padding regions to be contiguously mapped in memory
to mitigate increase in unreclaimable VMA slab memory usage.

Commit 8c2a805a857914324b077708b45c31c2f20d02da [1] emulates the padding
region of such extended mappings to be outputted as PROT_NONE
[page size compat] entries from /proc/*/[s]maps. This breaks the use
case of /proc/*/maps_files/, as the ranges in /proc/*/map_files/ are
the true ranges of the actual underlying VMA layout; while those in
/proc/*/[s]maps are the emulated (shortened) ranges.

Remove the padding (extended) ranges from /proc/*/maps_files entries.

====== Example Output ======

=== maps ===

❯ adb shell cat /proc/1/maps | grep -A1 libdl_android.so | sed '$d'

7f76663df000-7f76663e0000 r--p 00000000 fe:09 1911                       /system/lib64/bootstrap/libdl_android.so
7f76663e0000-7f76663e3000 ---p 00000000 00:00 0                          [page size compat]
7f76663e3000-7f76663e4000 r-xp 00004000 fe:09 1911                       /system/lib64/bootstrap/libdl_android.so
7f76663e4000-7f76663e7000 ---p 00000000 00:00 0                          [page size compat]
7f76663e7000-7f76663e8000 r--p 00008000 fe:09 1911                       /system/lib64/bootstrap/libdl_android.s

=== map_files - Before patch ===

❯ adb shell ls /proc/1/map_files | grep -A2 7f76663df000

7f76663df000-7f76663e3000
7f76663e3000-7f76663e7000
7f76663e7000-7f76663e8000

=== map_files - After patch ===

❯ adb shell ls /proc/1/map_files | grep -A2 7f76663df000

7f76663df000-7f76663e0000
7f76663e3000-7f76663e4000
7f76663e7000-7f76663e8000

[1] https://android.googlesource.com/kernel/common/+/8c2a805a857914324b077708b45c31c2f20d02da

Bug: 418042003
Change-Id: I0f6d703715a0e709fa1d4bd52241b5fd913dd55e
Reported-by: Daniel Müller <deso@posteo.net>
Signed-off-by: Kalesh Singh <kaleshsingh@google.com>
2025-05-19 13:28:38 -07:00
Greg Kroah-Hartman
1aec9e76fe Merge tag 'android11-5.4.292_r00' into android11-5.4
This merges the android11-5.4.292_r00 tag into the android11-5.4 branch,
catching it up with the latest LTS releases.

It contains the following commits:

*   9b78f083cb Merge 5.4.292 into android11-5.4-lts
|\
| * 1b01d9c341 Linux 5.4.292
| * 2809029821 jfs: add index corruption check to DT_GETPAGE()
| * 3d6fd5b9c6 jfs: fix slab-out-of-bounds read in ea_get()
| * 42561fe62c tracing: Fix use-after-free in print_graph_function_flags during tracer switching
| * 922a70031c mmc: sdhci-pxav3: set NEED_RSP_BUSY capability
| * a7d0f84a31 ACPI: resource: Skip IRQ override on ASUS Vivobook 14 X1404VAP
| * 618d5612ec x86/mm: Fix flush_tlb_range() when used for zapping normal PMDs
| * c0189c02b5 x86/tsc: Always save/restore TSC sched_clock() on suspend/resume
| * 2414095a8c ntb_perf: Delete duplicate dmaengine_unmap_put() call in perf_copy_chunk()
| * a1ef4447b8 can: flexcan: only change CAN state when link up in system PM
| * 661cf5d102 arcnet: Add NULL check in com20020pci_probe()
| * 5309432c67 net: dsa: mv88e6xxx: propperly shutdown PPU re-enable timer on destroy
| * 87c53a1c65 ipv6: fix omitted netlink attributes when using RTEXT_FILTER_SKIP_STATS
| * 42df95e5ea vsock: avoid timeout during connect() if the socket is closing
| * 7abc8318ce net_sched: skbprio: Remove overly strict queue assertions
| * 1ad9166cab netlabel: Fix NULL pointer exception caused by CALIPSO on IPv4 sockets
| * b9f2980327 ntb: intel: Fix using link status DB's
| * f56951f211 ntb_hw_switchtec: Fix shift-out-of-bounds in switchtec_ntb_mw_set_trans
| * 829bd61399 spufs: fix a leak in spufs_create_context()
| * b1eef06d10 spufs: fix a leak on spufs_new_file() failure
| * 5214156633 hwmon: (nct6775-core) Fix out of bounds access for NCT679{8,9}
| * 12d344d74c can: statistics: use atomic access in hot path
| * d6ae75c3ba locking/semaphore: Use wake_q to wake up processes outside lock critical section
| * 0ab44f03c5 sched/deadline: Use online cpus for validating runtime
| * 04039a3806 affs: don't write overlarge OFS data block size fields
| * 739499e146 affs: generate OFS sequence numbers starting at 1
| * f5302f6786 wifi: iwlwifi: fw: allocate chained SG tables for dump
| * 99bd64445f sched/smt: Always inline sched_smt_active()
| * da3b90f71b octeontx2-af: Fix mbox INTR handler when num VFs > 64
| * 4a760b682e ring-buffer: Fix bytes_dropped calculation issue
| * 536f7f3595 objtool, media: dib8000: Prevent divide-by-zero in dib8000_set_dds()
| * 6601c04a87 fs/procfs: fix the comment above proc_pid_wchan()
| * 38dffe995b perf python: Check if there is space to copy all the event
| * 213ee3d738 perf python: Decrement the refcount of just created event on failure
| * 58edf5e6a3 perf python: Fixup description of sample.id event member
| * ef34840bda ocfs2: validate l_tree_depth to avoid out-of-bounds access
| * 8a3ebead12 kexec: initialize ELF lowest address to ULONG_MAX
| * 466806997a perf units: Fix insufficient array space
| * d1696caf8b iio: accel: mma8452: Ensure error return on failure to matching oversampling ratio
| * 61c6dc3b55 coresight: catu: Fix number of pages while using 64k pages
| * 99c737ec34 isofs: fix KMSAN uninit-value bug in do_isofs_readdir()
| * 85a17b9ab3 x86/dumpstack: Fix inaccurate unwinding from exception stacks due to misplaced assignment
| * 2bf98cc76b mfd: sm501: Switch to BIT() to mitigate integer overflows
| * 3b97d77049 RDMA/mlx5: Fix mlx5_poll_one() cur_qp update flow
| * a4be0b575a power: supply: max77693: Fix wrong conversion of charge input threshold value
| * b26152f504 x86/entry: Fix ORC unwinder for PUSH_REGS with save_ret=1
| * 62ae4a1b29 clk: amlogic: g12a: fix mmc A peripheral clock
| * 450a1d9eac clk: amlogic: gxbb: drop non existing 32k clock parent
| * d15e95d7b8 clk: amlogic: g12b: fix cluster A parent data
| * 0c23a6f147 IB/mad: Check available slots before posting receive WRs
| * 64f805c30c clk: rockchip: rk3328: fix wrong clk_ref_usb3otg parent
| * f53c2937ab pinctrl: renesas: rza2: Fix missing of_node_put() call
| * 37e63b0af9 lib: 842: Improve error handling in sw842_compress()
| * 794d6b4b4e bpf: Use preempt_count() directly in bpf_send_signal_common()
| * 671760004d clk: amlogic: gxbb: drop incorrect flag on 32k clock
| * 90ab169fb9 fbdev: sm501fb: Add some geometry checks.
| * 38b9a21a75 mdacon: rework dependency list
| * ab846209f4 fbdev: au1100fb: Move a variable assignment behind a null pointer check
| * ed8bf338d7 PCI: pciehp: Don't enable HPIE when resuming in poll mode
| * 70a83ba1df PCI: Remove stray put_device() in pci_register_host_bridge()
| * c6f9613a22 PCI/portdrv: Only disable pciehp interrupts early when needed
| * 0a0f9aecf6 PCI/ASPM: Fix link state exit during switch upstream function removal
| * 6038b90cdf drm/mediatek: mtk_hdmi: Fix typo for aud_sampe_size member
| * b66baefc08 ALSA: hda/realtek: Always honor no_shutup_pins
| * fc50ed312c perf/ring_buffer: Allow the EPOLLRDNORM flag for poll
| * c6d87a552c lockdep: Don't disable interrupts on RT in disable_irq_nosync_lockdep.*()
| * 41b5a58878 PM: sleep: Fix handling devices with direct_complete set on errors
| * d0d21c8e44 thermal: int340x: Add NULL check for adev
| * cc4b161029 EDAC/ie31200: Fix the error path order of ie31200_init()
| * 563493f22c EDAC/ie31200: Fix the DIMM size mask for several SoCs
| * eb96456b70 EDAC/ie31200: Fix the size of EDAC_MC_LAYER_CHIP_SELECT layer
| * 095a5cba17 selinux: Chain up tool resolving errors in install_policy.sh
| * e6748cbbbd x86/platform: Only allow CONFIG_EISA for 32-bit
| * 3b2e1ce751 x86/fpu: Avoid copying dynamic FP state from init_task in arch_dup_task_struct()
| * 73cee9b56a cpufreq: governor: Fix negative 'idle_time' handling in dbs_update()
| * c918f836a4 x86/mm/pat: cpa-test: fix length for CPA_ARRAY test
| * 0d510e175b serial: 8250_dma: terminate correct DMA in tx_dma_flush()
| * 914c5e5bfc memstick: rtsx_usb_ms: Fix slab-use-after-free in rtsx_usb_ms_drv_remove
| * e206041b55 net: usb: usbnet: restore usb%d name exception for local mac addresses
| * 52ea3f5803 net: usb: qmi_wwan: add Telit Cinterion FE990B composition
| * c960ab007a net: usb: qmi_wwan: add Telit Cinterion FN990B composition
| * 16eed55a08 tty: serial: 8250: Add some more device IDs
| * b7e4d3d707 counter: stm32-lptimer-cnt: fix error handling when enabling
| * 6488b96a79 netfilter: socket: Lookup orig tuple for IPv6 SNAT
| * 0387a57cc9 ARM: Remove address checking for MMUless devices
| * 1c078dadb4 ARM: 9351/1: fault: Add "cut here" line for prefetch aborts
| * 11bb05969b ARM: 9350/1: fault: Implement copy_from_kernel_nofault_allowed()
| * ab92f51c7f atm: Fix NULL pointer dereference
| * b93e9fd3ee HID: hid-plantronics: Add mic mute mapping and generalize quirks
| * ece47d9213 ALSA: usb-audio: Add quirk for Plantronics headsets to fix control names
| * 0effb378eb drm/radeon: fix uninitialized size issue in radeon_vce_cs_parse()
| * 9bd50100ee batman-adv: Ignore own maximum aggregation size during RX
| * 8310e6a1c9 ARM: shmobile: smp: Enforce shmobile_smp_* alignment
| * 450cd5f5fe mmc: atmel-mci: Add missing clk_disable_unprepare()
| * a354b8bbdf drm/v3d: Don't run jobs that have errors flagged in its fence
| * d3e4439a79 i2c: omap: fix IRQ storms
| * 9dcf9db183 net/neighbor: add missing policy for NDTPA_QUEUE_LENBYTES
| * 50e288097c net: atm: fix use after free in lec_send()
| * f400408c5e ipv6: Set errno after ip_fib_metrics_init() in ip6_route_info_create().
| * 16267a5036 ipv6: Fix memleak of nhc_pcpu_rth_output in fib_check_nh_v6_gw().
| * b3d607e36f Bluetooth: Fix error code in chan_alloc_skb_cb()
| * 2cf5228644 RDMA/hns: Fix wrong value of max_sge_rd
| * 7cfd80fa58 RDMA/bnxt_re: Avoid clearing VLAN_ID mask in modify qp path
| * 4f0f83799a xfrm_output: Force software GSO only in tunnel mode
| * d541325120 firmware: imx-scu: fix OF node leak in .probe()
| * c9e2b3b231 i2c: sis630: Fix an error handling path in sis630_probe()
| * 20521ee78c i2c: ali15x3: Fix an error handling path in ali15x3_probe()
| * 75148adf8c i2c: ali1535: Fix an error handling path in ali1535_probe()
| * f26d827172 ASoC: codecs: wm0010: Fix error handling path in wm0010_spi_probe()
| * 5d45755de5 drm/gma500: Add NULL check for pci_gfx_root in mid_get_vbt_data()
| * 880295b68a qlcnic: fix memory leak issues in qlcnic_sriov_common.c
| * cca3ab74f9 drm/amd/display: Assign normalized_pix_clk when color depth = 14
| * 31ed3586f4 drm/atomic: Filter out redundant DPMS calls
| * d509c47310 x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes
| * 2175d3c126 USB: serial: option: match on interface class for Telit FN990B
| * f26a86f829 USB: serial: option: fix Telit Cinterion FE990A name
| * 57f6ae8b88 USB: serial: option: add Telit Cinterion FE990B compositions
| * abb9f684f8 USB: serial: ftdi_sio: add support for Altera USB Blaster 3
| * 8d8e2c9961 block: fix 'kmem_cache of name 'bio-108' already exists'
| * f6e43f6aea drm/nouveau: Do not override forced connector status
| * f8e635b762 x86/irq: Define trace events conditionally
| * 34468b2e39 fuse: don't truncate cached, mutated symlink
| * e7fa90c0cb nvme: only allow entering LIVE from CONNECTING state
| * 36256b2447 sctp: Fix undefined behavior in left shift operation
| * 72f676364d nvmet-rdma: recheck queue state is LIVE in state lock in recv done
| * 3dbbc37db8 ASoC: rsnd: don't indicate warning on rsnd_kctrl_accept_runtime()
| * 8b3c9b69fa s390/cio: Fix CHPID "configure" attribute caching
| * 9af297aea8 HID: ignore non-functional sensor in HP 5MP Camera
| * bfa6d90db3 HID: intel-ish-hid: fix the length of MNG_SYNC_FW_CLOCK in doorbell
| * cc4d9d3a1e ACPI: resource: IRQ override for Eluktronics MECH-17
| * afa27b7c17 scsi: qla1280: Fix kernel oops when debug level > 2
| * a858cd58de iscsi_ibft: Fix UBSAN shift-out-of-bounds warning in ibft_attr_show_nic()
| * 6752747a11 powercap: call put_device() on an error path in powercap_register_control_type()
| * 66beda69bb hrtimers: Mark is_migration_base() with __always_inline
| * 27b2f3dc04 nvme-fc: go straight to connecting state when initializing
| * bb728b5521 net/mlx5e: Prevent bridge link show failure for non-eswitch-allowed devices
| * aaeefb9868 netfilter: nft_exthdr: fix offset with ipv4_find_option()
| * e05d9938b1 net_sched: Prevent creation of classes with TC_H_ROOT
| * ab45c0ee54 ipvs: prevent integer overflow in do_ip_vs_get_ctl()
| * f522229c55 netfilter: nf_conncount: Fully initialize struct nf_conncount_tuple in insert_tree()
| * ca61dc0c2f Drivers: hv: vmbus: Don't release fb_mmio resource in vmbus_free_mmio()
| * 1485aaf8d7 drivers/hv: Replace binary semaphore with mutex
| * 6a3c34e875 netpoll: hold rcu read lock in __netpoll_send_skb()
| * 413691c54e netpoll: netpoll_send_skb() returns transmit status
| * e3235e0486 netpoll: move netpoll_send_skb() out of line
| * ddf5458095 netpoll: remove dev argument from netpoll_send_skb_on_dev()
| * 0945ed0e62 netpoll: Fix use correct return type for ndo_start_xmit()
| * 9cc1b39f5a pinctrl: bcm281xx: Fix incorrect regmap max_registers value
| * cf387cdebf sctp: sysctl: auth_enable: avoid using current->nsproxy
| * 5599b212d2 sctp: sysctl: cookie_hmac_alg: avoid using current->nsproxy
| * 19573dcddb Revert "sctp: sysctl: auth_enable: avoid using current->nsproxy"
| * 2ced96df87 Revert "sctp: sysctl: cookie_hmac_alg: avoid using current->nsproxy"
| * 769f2099d9 sched/isolation: Prevent boot crash when the boot CPU is nohz_full
| * 9f89d4ad21 clockevents/drivers/i8253: Fix stop sequence for timer 0
| * 549de58dba vlan: fix memory leak in vlan_newlink()
* | 51aa3bfef8 Revert "tasklet: Introduce new initialization API"
* | fa82985d52 Revert "net: usb: rtl8150: use new tasklet API"
* | 2461d9a37e Revert "net: usb: rtl8150: enable basic endpoint checking"
* | eb00272aa5 Revert "usb: xhci: Add timeout argument in address_device USB HCD callback"
* | 4364e0f8cf Revert "usb: xhci: Fix NULL pointer dereference on certain command aborts"
* | d6a7c6fab0 Merge 5.4.291 into android11-5.4-lts
|\|
| * 52bcf31d8e Linux 5.4.291
| * 7f24cff72a eeprom: digsy_mtc: Make GPIO lookup table match the device
| * cec8c0ac17 slimbus: messaging: Free transaction ID in delayed interrupt scenario
| * 5619084876 intel_th: pci: Add Panther Lake-P/U support
| * 3940fe7d0c intel_th: pci: Add Panther Lake-H support
| * 8740a9ddc4 intel_th: pci: Add Arrow Lake support
| * 32c114a582 Squashfs: check the inode number is not the invalid value of zero
| * e722515dab xhci: pci: Fix indentation in the PCI device ID definitions
| * 19b3918840 usb: gadget: Check bmAttributes only if configuration is valid
| * 9af1d5c4d5 usb: gadget: Fix setting self-powered state on suspend
| * 7367e87b6e usb: gadget: Set self-powered based on MaxPower and bmAttributes
| * 094b49dec3 usb: typec: tcpci_rt1711h: Unmask alert interrupts to fix functionality
| * b654e4c757 usb: typec: ucsi: increase timeout for PPM reset operations
| * dcd592ab9d usb: atm: cxacru: fix a flaw in existing endpoint checks
| * 4cd847a7b6 usb: renesas_usbhs: Flush the notify_hotplug_work
| * a5c8be5903 usb: quirks: Add DELAY_INIT and NO_LPM for Prolific Mass Storage Card Reader
| * 97f8c81570 usb: renesas_usbhs: Use devm_usb_get_phy()
| * d1968edada usb: renesas_usbhs: Call clk_put()
| * 0971d857c2 Revert "drivers/card_reader/rtsx_usb: Restore interrupt based detection"
| * efbddfb96c gpio: rcar: Fix missing of_node_put() call
| * a3895a367f net: ipv6: fix missing dst ref drop in ila lwtunnel
| * c2fb9104b3 net: ipv6: fix dst ref loop in ila lwtunnel
| * 4ca4dce141 net-timestamp: support TCP GSO case for a few missing flags
| * 7f1564b2b2 vlan: enforce underlying device type
| * d685096c81 ppp: Fix KMSAN uninit-value warning with bpf
| * 797bb9439c be2net: fix sleeping while atomic bugs in be_ndo_bridge_getlink
| * f5a7fa426a drm/sched: Fix preprocessor guard
| * 7a115f431b hwmon: fix a NULL vs IS_ERR_OR_NULL() check in xgene_hwmon_probe()
| * cd1c44327b llc: do not use skb_get() before dev_queue_xmit()
| * b205ac53a6 hwmon: (ad7314) Validate leading zero bits and return error
| * 90b2aee418 hwmon: (ntc_thermistor) Fix the ncpXXxh103 sensor table
| * d51369e720 hwmon: (pmbus) Initialise page count in pmbus_identify()
| * 990fff6980 caif_virtio: fix wrong pointer check in cfv_probe()
| * 9f28205ddb net: gso: fix ownership in __udp_gso_segment
| * 0c1fb475ef HID: intel-ish-hid: Fix use-after-free issue in ishtp_hid_remove()
| * 8ecee2b056 HID: google: fix unused variable warning under !CONFIG_ACPI
| * 38f0d398b6 wifi: iwlwifi: limit printed string from FW file
| * b7f3090f19 mm/page_alloc: fix uninitialized variable
| * d4ec862ce8 rapidio: fix an API misues when rio_add_net() fails
| * 6d22953c4a rapidio: add check for rio_add_net() in rio_scan_alloc_net()
| * 5ea856d937 wifi: nl80211: reject cooked mode if it is set along with other flags
| * 62b1a9bbfe wifi: cfg80211: regulatory: improve invalid hints checking
| * 62c602f3c7 x86/cpu: Properly parse CPUID leaf 0x2 TLB descriptor 0x63
| * c67b103a8d x86/cpu: Validate CPUID leaf 0x2 EDX output
| * 0d1275424f x86/cacheinfo: Validate CPUID leaf 0x2 EDX output
| * 9616539e62 platform/x86: thinkpad_acpi: Add battery quirk for ThinkPad X131e
| * 1f75482717 drm/radeon: Fix rs400_gpu_init for ATI mobility radeon Xpress 200M
| * 19abf50b6c ALSA: hda/realtek: update ALC222 depop optimize
| * 07bc341d61 ALSA: hda: intel: Add Dell ALC3271 to power_save denylist
| * 6db423b009 HID: appleir: Fix potential NULL dereference at raw event handle
| * 38807477c1 Revert "of: reserved-memory: Fix using wrong number of cells to get property 'alignment'"
| * f1f5e41577 drm/amdgpu: disable BAR resize on Dell G5 SE
| * d6566c66c2 drm/amdgpu: Check extended configuration space register when system uses large bar
| * fa996df875 drm/amdgpu: skip BAR resizing if the bios already did it
| * 8acbf4a88c acct: perform last write from workqueue
| * 8d30d9dde5 kernel/acct.c: use dedicated helper to access rlimit values
| * 1b18a0118c kernel/acct.c: use #elif instead of #end and #elif
| * 6e9e0f224f drop_monitor: fix incorrect initialization order
| * 78285b5326 pfifo_tail_enqueue: Drop new packet when sch->limit == 0
| * 321794b75a sched/core: Prevent rescheduling when interrupts are disabled
| * 4af1aff347 phy: exynos5-usbdrd: fix MPLL_MULTIPLIER and SSC_REFCLKSEL masks in refclk
| * 074f4e6284 phy: tegra: xusb: reset VBUS & ID OVERRIDE
| * 5f2dbabbce usbnet: gl620a: fix endpoint checking in genelink_bind()
| * 813822972e perf/core: Fix low freq setting via IOC_PERIOD
| * 5b3d32f607 ftrace: Avoid potential division by zero in function_stat_show()
| * 58446f9868 x86/CPU: Fix warm boot hang regression on AMD SC1100 SoC systems
| * 7ff67d1967 net: mvpp2: cls: Fixed Non IP flow, with vlan tag flow defination.
| * 747010edd6 ipvs: Always clear ipvs_property flag in skb_scrub_packet()
| * aa91462f1f ASoC: es8328: fix route from DAC to output
| * a15efcf84f net: cadence: macb: Synchronize stats calculations
| * c75c6e6e4f net: loopback: Avoid sending IP packets without an Ethernet header
| * a049c2d86c sunrpc: suppress warnings for unused procfs functions
| * 1c33462917 batman-adv: Drop unmanaged ELP metric worker
| * 77bff7bb11 batman-adv: Ignore neighbor throughput metrics in error case
| * fe7343b8a3 acct: block access to kernel internal filesystems
| * 521ad61fc4 ALSA: hda/conexant: Add quirk for HP ProBook 450 G4 mute LED
| * d64c6ca420 nfp: bpf: Add check for nfp_app_ctrl_msg_alloc()
| * 3eb4911364 tee: optee: Fix supplicant wait loop
| * 3c6e8129a4 power: supply: da9150-fg: fix potential overflow
| * 607b0b1c83 flow_dissector: Fix port range key handling in BPF conversion
| * c67e23568e flow_dissector: Fix handling of mixed port and port-range keys
| * 895d04846e net: extract port range fields from fl_flow_key
| * d37e36db58 geneve: Suppress list corruption splat in geneve_destroy_tunnels().
| * 7f86fb07db gtp: Suppress list corruption splat in gtp_net_exit_batch_rtnl().
| * d5e86e27de geneve: Fix use-after-free in geneve_find_dev().
| * 97de585205 powerpc/code-patching: Fix KASAN hit by not flagging text patching area as VM_ALLOC
| * 206c9a8f57 ALSA: hda/realtek: Fixup ALC225 depop procedure
| * 85d63c559b ALSA: hda/realtek - Add type for ALC287
| * 2ecb663224 powerpc/64s: Rewrite __real_pte() and __rpte_to_hidx() as static inline
| * fc4f8ac3b9 powerpc/64s/mm: Move __real_pte stubs into hash-4k.h
| * 727dee0857 USB: gadget: f_midi: f_midi_complete to call queue_work
| * 89019ab7a6 usb/gadget: f_midi: Replace tasklet with work
| * ec42b4a0eb usb/gadget: f_midi: convert tasklets to use new tasklet_setup() API
| * 19aad69c2b usb: dwc3: Fix timeout issue during controller enter/exit from halt state
| * 935e842f98 usb: dwc3: Increase DWC3 controller halt timeout
| * 72f2c0b7c1 memcg: fix soft lockup in the OOM process
| * de3f6e7a84 mm: update mark_victim tracepoints fields
| * 3758d1ed60 crypto: testmgr - some more fixes to RSA test vectors
| * 5ecee5d5ee crypto: testmgr - populate RSA CRT parameters in RSA test vectors
| * 3a2f1eb708 crypto: testmgr - fix version number of RSA tests
| * 1bd5831c65 crypto: testmgr - Fix wrong test case of RSA
| * 321cc1d830 crypto: testmgr - fix wrong key length for pkcs1pad
| * 87bc3cb23c driver core: bus: Fix double free in driver API bus_register()
| * 0196802993 scsi: storvsc: Set correct data length for sending SCSI command without payload
| * eab83178ee vlan: move dev_put into vlan_dev_uninit
| * b195d229de vlan: introduce vlan_dev_free_egress_priority
| * 480afcbeb7 ima: Fix use-after-free on a dentry's dname.name
| * 785c78ed0d pps: Fix a use-after-free
| * 41d3c605bf btrfs: avoid monopolizing a core when activating a swap file
| * ed0c0c7de0 Revert "btrfs: avoid monopolizing a core when activating a swap file"
| * 67f70e61b8 x86/i8253: Disable PIT timer 0 when not in use
| * 81b605bbcd parport_pc: add support for ASIX AX99100
| * 14ffcc4571 serial: 8250_pci: add support for ASIX AX99100
| * 753ad96cdd can: ems_pci: move ASIX AX99100 ids to pci_ids.h
| * e1fc4a90a9 nilfs2: protect access to buffers with no active references
| * 7d0544bacc nilfs2: do not force clear folio if buffer is referenced
| * 1ca6d471f8 nilfs2: do not output warnings when clearing dirty buffers
| * 24d59c41e2 alpha: replace hardcoded stack offsets with autogenerated ones
| * 10a1f3fece ndisc: extend RCU protection in ndisc_send_skb()
| * e85a25d1a9 openvswitch: use RCU protection in ovs_vport_cmd_fill_info()
| * 10f555e3f5 arp: use RCU protection in arp_xmit()
| * e1aed6be38 neighbour: use RCU protection in __neigh_notify()
| * c5d53d3ad4 neighbour: delete redundant judgment statements
| * 96fc896d0e ndisc: use RCU protection in ndisc_alloc_skb()
| * 78ad057472 ipv6: use RCU protection in ip6_default_advmss()
| * 8cc8e1285a ipv4: use RCU protection in inet_select_addr()
| * 155298112a ipv4: use RCU protection in rt_is_expired()
| * 7f86ac1f40 net: add dev_net_rcu() helper
| * fde36de3b4 net: treat possible_net_t net pointer as an RCU one and add read_pnet_rcu()
| * ef539316c5 regmap-irq: Add missing kfree()
| * a3e77da9f8 partitions: mac: fix handling of bogus partition table
| * 9cb4edb23c gpio: stmpe: Check return value of stmpe_reg_read in stmpe_gpio_irq_sync_unlock
| * 7ec1e5e9f2 alpha: align stack for page fault and user unaligned trap handlers
| * bbec5998d7 serial: 8250: Fix fifo underflow on flush
| * ab4f7b1d95 alpha: make stack 16-byte aligned (most cases)
| * 1abecca55d can: j1939: j1939_sk_send_loop(): fix unable to send messages with data length zero
| * 85069553d1 can: c_can: fix unbalanced runtime PM disable in error path
| * 039cc7d94d USB: serial: option: drop MeiG Smart defines
| * 6621ddcdda USB: serial: option: fix Telit Cinterion FN990A name
| * b95bd1248b USB: serial: option: add Telit Cinterion FN990B compositions
| * 2b03876842 USB: serial: option: add MeiG Smart SLM828
| * 7cfb70e97f usb: cdc-acm: Fix handling of oversized fragments
| * a4e1ae5c05 usb: cdc-acm: Check control transfer buffer size before access
| * 42b3050171 USB: cdc-acm: Fill in Renesas R-Car D3 USB Download mode quirk
| * 49f077106f USB: hub: Ignore non-compliant devices with too many configs or interfaces
| * 3a983390d1 usb: gadget: f_midi: fix MIDI Streaming descriptor lengths
| * a0a18484ce USB: Add USB_QUIRK_NO_LPM quirk for sony xperia xz1 smartphone
| * a120aad69e USB: quirks: add USB_QUIRK_NO_LPM quirk for Teclast dist
| * 2b8a7cfefd USB: pci-quirks: Fix HCCPARAMS register error for LS7A EHCI
| * 1c231617ac usb: dwc2: gadget: remove of_node reference upon udc_stop
| * 3d921d29d4 usb: gadget: udc: renesas_usb3: Fix compiler warning
| * 27a15815af usb: roles: set switch registered flag early on
| * 167422a070 batman-adv: fix panic during interface removal
| * c4edbd5429 ASoC: Intel: bytcr_rt5640: Add DMI quirk for Vexia Edu Atla 10 tablet 5V
| * 18b7f84110 orangefs: fix a oob in orangefs_debug_write
| * c0c082fef5 Grab mm lock before grabbing pt lock
| * d85ab22daa vfio/pci: Enable iowrite64 and ioread64 for vfio pci
| * dde407d931 media: cxd2841er: fix 64-bit division on gcc-9
| * e9d30ea730 x86/xen: allow larger contiguous memory regions in PV guests
| * 386c8657fe xen: remove a confusing comment on auto-translated guest I/O
| * 69c84cf3b1 gpio: bcm-kona: Add missing newline to dev_err format string
| * f40d5f0169 gpio: bcm-kona: Make sure GPIO bits are unlocked when requesting IRQ
| * 9b4d03e5c0 gpio: bcm-kona: Fix GPIO lock/unlock for banks above bank 0
| * 4371ac7b49 arm64: cacheinfo: Avoid out-of-bounds write to cacheinfo array
| * 7c30483d0f team: better TEAM_OPTION_TYPE_STRING validation
| * 6ccaa5797f vrf: use RCU protection in l3mdev_l3_out()
| * a4b3863fe7 ndisc: ndisc_send_redirect() must use dev_get_by_index_rcu()
| * a04d96ef67 HID: multitouch: Add NULL check in mt_input_configured
| * 3cb901b8a9 ocfs2: check dir i_size in ocfs2_find_entry
| * 16e8693eb2 MIPS: ftrace: Declare ftrace_get_parent_ra_addr() as static
| * fdc1e72487 ptp: Ensure info->enable callback is always set
| * 70dc66d0cb net/ncsi: wait for the last response to Deselect Package before configuring channel
| * b04fd7cdd8 misc: fastrpc: Fix registered buffer page address
| * 2535f15d31 mtd: onenand: Fix uninitialized retlen in do_otp_read()
| * bd249109d2 NFC: nci: Add bounds checking in nci_hci_create_pipe()
| * 7649937987 nilfs2: fix possible int overflows in nilfs_fiemap()
| * cd3e22b206 ocfs2: handle a symlink read error correctly
| * 970ef46c6d ocfs2: fix incorrect CPU endianness conversion causing mount failure
| * 9377cdc118 vfio/platform: check the bounds of read/write syscalls
| * 406c63ceea nvmem: core: improve range check for nvmem_cell_write()
| * 8c735ef894 crypto: qce - unregister previously registered algos in error path
| * f933d3b26a crypto: qce - fix goto jump in error path
| * d7b11ef0c3 media: uvcvideo: Remove redundant NULL assignment
| * 4823ab3781 media: uvcvideo: Fix event flags in uvc_ctrl_send_events
| * 85b3a78845 media: ov5640: fix get_light_freq on auto
| * 5d50d51d50 soc: qcom: smem_state: fix missing of_node_put in error path
| * 6e3e74dd04 kbuild: Move -Wenum-enum-conversion to W=2
| * 1130e26e3e powerpc/pseries/eeh: Fix get PE state translation
| * 0367db43eb serial: sh-sci: Do not probe the serial port if its slot in sci_ports[] is in use
| * 8119f3afb6 serial: sh-sci: Drop __initdata macro for port_cfg
| * 7445fa0531 soc: qcom: socinfo: Avoid out of bounds read of serial number
| * cc4e1d76a1 usb: gadget: f_tcm: Don't prepare BOT write request twice
| * 54e7215ed1 usb: gadget: f_tcm: ep_autoconfig with fullspeed endpoint
| * 6e10b792fb usb: gadget: f_tcm: Decrement command ref count on cleanup
| * 5e051636b4 usb: gadget: f_tcm: Translate error to sense
| * 2326e19190 wifi: brcmfmac: fix NULL pointer dereference in brcmf_txfinalize()
| * b64e9092ab HID: hid-sensor-hub: don't use stale platform-data on remove
| * 4aac5315dc of: reserved-memory: Fix using wrong number of cells to get property 'alignment'
| * 8c4178d2d0 of: Fix of_find_node_opts_by_path() handling of alias+path+options
| * b3f14fccde of: Correct child specifier used as input of the 2nd nexus node
| * 7cd71d7574 perf bench: Fix undefined behavior in cmpworker()
| * 523003eb6c clk: qcom: clk-rpmh: prevent integer overflow in recalc_rate
| * 5d549136fa clk: qcom: clk-alpha-pll: fix alpha mode configuration
| * a9a7672fc1 Bluetooth: L2CAP: handle NULL sock pointer in l2cap_sock_alloc
| * 737c74bc17 drm/komeda: Add check for komeda_get_layer_fourcc_list()
| * a5ddf2626d KVM: s390: vsie: fix some corner-cases when grabbing vsie pages
| * 5cce2ed69b KVM: Explicitly verify target vCPU is online in kvm_get_vcpu()
| * db9088f402 arm64: dts: rockchip: increase gmac rx_delay on rk3399-puma
| * 0b6be54d73 binfmt_flat: Fix integer overflow bug on 32 bit systems
| * 15e94cfebc m68k: vga: Fix I/O defines
| * c763d34193 s390/futex: Fix FUTEX_OP_ANDN implementation
| * 2f50af0ca0 leds: lp8860: Write full EEPROM, not only half of it
| * 619708ef44 cpufreq: s3c64xx: Fix compilation warning
| * a2bfaf4ce2 tun: revert fix group permission check
| * e395fec75a netem: Update sch->q.qlen before qdisc_tree_reduce_backlog()
| * b8bf5c3fb7 net: rose: lock the socket in rose_bind()
| * 4fae092c3c udp: gso: do not drop small packets when PMTU reduces
| * 558d3acef0 tg3: Disable tg3 PCIe AER on system reboot
| * fe8b241e5e gpu: drm_dp_cec: fix broken CEC adapter properties check
| * 309b493990 firmware: iscsi_ibft: fix ISCSI_IBFT Kconfig entry
| * 3a1aeef304 nvme: handle connectivity loss in nvme_set_queue_count
| * fd8bfaeba4 usb: xhci: Fix NULL pointer dereference on certain command aborts
| * 7032df572e usb: xhci: Add timeout argument in address_device USB HCD callback
| * 431be4f782 net: usb: rtl8150: enable basic endpoint checking
| * 88892dabac net: usb: rtl8150: use new tasklet API
| * 21dc5a1de2 tasklet: Introduce new initialization API
| * 579fac0e5c kbuild: userprogs: use correct lld when linking through clang
| * 44fe1efb49 sched: sch_cake: add bounds checks to host bulk flow fairness counts
| * 2a29413ace media: uvcvideo: Remove dangling pointers
| * 1df994d852 media: uvcvideo: Only save async fh if success
| * b38c6c260c nilfs2: handle errors that nilfs_prepare_chunk() may return
| * 620e036978 nilfs2: eliminate staggered calls to kunmap in nilfs_rename
| * 49d80141af nilfs2: move page release outside of nilfs_delete_entry and nilfs_set_link
| * dff1553c27 spi-mxs: Fix chipselect glitch
| * 7220b2446e x86/mm: Don't disable PCID when INVLPG has been fixed by microcode
| * 96c2ddba89 APEI: GHES: Have GHES honor the panic= setting
| * 8bec50f4c3 HID: Wacom: Add PCI Wacom device support
| * 7283aa9700 mfd: lpc_ich: Add another Gemini Lake ISA bridge PCI device-id
| * c67efabddc tomoyo: don't emit warning in tomoyo_write_control()
| * 0a457223cb wifi: brcmsmac: add gain range check to wlc_phy_iqcal_gainparams_nphy()
| * ea7e57d54b mmc: core: Respect quirk_max_rate for non-UHS SDIO card
| * 369c063e35 tun: fix group permission check
| * 54c14022fa printk: Fix signed integer overflow when defining LOG_BUF_LEN_MAX
| * 9bc723d82e x86/amd_nb: Restrict init function to AMD-based systems
| * 7c4d23b6c5 sched: Don't try to catch up excess steal time.
| * 49c8a023ed btrfs: convert BUG_ON in btrfs_reloc_cow_block() to proper error handling
| * cee55b1219 btrfs: fix use-after-free when attempting to join an aborted transaction
| * ab476f0a45 btrfs: output the reason for open_ctree() failure
| * 7cb72dc08e usb: gadget: f_tcm: Don't free command immediately
| * d6e5ba2516 media: uvcvideo: Fix double free in error path
| * 3a002e4029 HID: core: Fix assumption that Resolution Multipliers must be in Logical Collections
| * 3b269db6fe usb: typec: tcpm: set SRC_SEND_CAPABILITIES timeout to PD_T_SENDER_RESPONSE
| * 0692c81957 drivers/card_reader/rtsx_usb: Restore interrupt based detection
| * 270c48e652 ktest.pl: Check kernelrelease return in get_version
| * d763fa3b65 NFSD: Reset cb_seq_status after NFS4ERR_DELAY
| * 2ac1d4705b hexagon: Fix unbalanced spinlock in die()
| * bfac520978 hexagon: fix using plain integer as NULL pointer warning in cmpxchg
| * 884385cb4f genksyms: fix memory leak when the same symbol is read from *.symref file
| * a149fe312e genksyms: fix memory leak when the same symbol is added from source
| * a78fbf9765 net: sh_eth: Fix missing rtnl lock in suspend/resume path
| * 64cd120639 vsock: Allow retrying on connect() failure
| * 093c20a38c perf trace: Fix runtime error of index out of bounds
| * db79e982c5 net: davicom: fix UAF in dm9000_drv_remove
| * 52f5aff33c net: rose: fix timer races against user threads
| * a51dedd586 PM: hibernate: Add error handling for syscore_suspend()
| * 71a0fcb68c ipmr: do not call mr_mfc_uses_dev() for unres entries
| * 6ffa190852 net: fec: implement TSO descriptor cleanup
| * 428aff8f7c ubifs: skip dumping tnc tree when zroot is null
| * 21cd59fcb9 rtc: pcf85063: fix potential OOB write in PCF85063 NVMEM read
| * 5057f4d0cf dmaengine: ti: edma: fix OF node reference leaks in edma_driver
| * 9fdcd0038b module: Extend the preempt disabled section in dereference_symbol_descriptor().
| * ab3e71ae07 ocfs2: mark dquot as inactive if failed to start trans while releasing dquot
| * b4beb4a96e scsi: ufs: bsg: Delete bsg_dev when setting up bsg fails
| * 9274ff6854 scsi: mpt3sas: Set ioc->manu_pg11.EEDPTagMode directly to 1
| * 01ace0742c staging: media: imx: fix OF node leak in imx_media_add_of_subdevs()
| * 7c22a9c3ee media: uvcvideo: Propagate buf->error to userspace
| * 12a73f441b media: camif-core: Add check for clk_enable()
| * 35654e1cb2 media: mipi-csis: Add check for clk_enable()
| * a0a943700f PCI: endpoint: Destroy the EPC device in devm_pci_epc_destroy()
| * 406429d873 media: lmedm04: Handle errors for lme2510_int_read
| * a6a31b4cfd media: lmedm04: Use GFP_KERNEL for URB allocation/submission.
| * 82e6f01637 media: rc: iguanair: handle timeouts
| * 9b9a7e6641 fbdev: omapfb: Fix an OF node leak in dss_of_port_get_parent_device()
| * e87fee8392 ARM: dts: mediatek: mt7623: fix IR nodename
| * f3606e14e1 arm64: dts: mediatek: mt8173-evb: Fix MT6397 PMIC sub-node names
| * 9cd56af0c6 arm64: dts: mediatek: mt8173-evb: Drop regulator-compatible property
| * 2b759f78b8 rdma/cxgb4: Prevent potential integer overflow on 32bit
| * c4e639acdf RDMA/mlx4: Avoid false error about access to uninitialized gids array
| * feba1308bc bpf: Send signals asynchronously if !preemptible
| * 66ad33b350 perf report: Fix misleading help message about --demangle
| * 819d7f3832 perf top: Don't complain about lack of vmlinux when not resolving some kernel samples
| * 8899c5146d padata: fix sysfs store callback check
| * 4bd8444adb ktest.pl: Remove unused declarations in run_bisect_test function
| * 3d13beb404 perf header: Fix one memory leakage in process_bpf_prog_info()
| * 7789f9f790 perf header: Fix one memory leakage in process_bpf_btf()
| * 3b22b8a1d2 ASoC: sun4i-spdif: Add clock multiplier settings
| * 0b920758f5 tools/testing/selftests/bpf/test_tc_tunnel.sh: Fix wait for server bind
| * cd796e2691 net: sched: Disallow replacing of child qdisc from one parent to another
| * cb53e470d3 net/mlxfw: Drop hard coded max FW flash image size
| * d0e0f9c821 net: let net.core.dev_weight always be non-zero
| * a24287200b clk: analogbits: Fix incorrect calculation of vco rate delta
| * 39f5d44f0a selftests: harness: fix printing of mismatch values in __EXPECT()
| * 822a5a0521 selftests/harness: Display signed values correctly
| * a84063de83 wifi: wlcore: fix unbalanced pm_runtime calls
| * d0c5fd206e regulator: of: Implement the unwind path of of_regulator_match()
| * 0a7794b9ca team: prevent adding a device which is already a team device lower
| * 6f4354ca0c cpupower: fix TSC MHz calculation
| * 167483d91a wifi: rtlwifi: pci: wait for firmware loading before releasing memory
| * 85b67b4c4a wifi: rtlwifi: fix memory leaks and invalid access at probe error path
| * f801e754ef wifi: rtlwifi: remove unused check_buddy_priv
| * 4f6d6cbf3f wifi: rtlwifi: remove unused dualmac control leftovers
| * bbac1dd053 wifi: rtlwifi: remove unused timer and related code
| * 0f02775e11 rtlwifi: replace usage of found with dedicated list iterator variable
| * 088e47ef06 dt-bindings: mmc: controller: clarify the address-cells description
| * 88f04590cd wifi: rtlwifi: usb: fix workqueue leak when probe fails
| * 1faa2647a0 wifi: rtlwifi: rtl8192se: rise completion of firmware loading as last step
| * f5dad52e01 rtlwifi: rtl8192se Rename RT_TRACE to rtl_dbg
| * ee74aec777 wifi: rtlwifi: do not complete firmware loading needlessly
| * 1a8a17c5ce ipmi: ipmb: Add check devm_kasprintf() returned value
| * a713ba7167 drm/amdgpu: Fix potential NULL pointer dereference in atomctrl_get_smc_sclk_range_table
| * b4a95da4c7 drm/etnaviv: Fix page property being used for non writecombine buffers
| * 092bb58ec7 partitions: ldm: remove the initial kernel-doc notation
| * e70a578487 nbd: don't allow reconnect after disconnect
| * f84e024057 afs: Fix directory format encoding struct
| * ed6c8c1fe6 overflow: Allow mixed type arguments
| * 0f6dd56712 overflow: Correct check_shl_overflow() comment
| * dbf89a4db3 overflow: Add __must_check attribute to check_*() helpers
| * 08c32d6729 udf: Fix use of check_add_overflow() with mixed type arguments
| * a4c54df0ad perf cs-etm: Add missing variable in cs_etm__process_queues()
* 6e905d8b5a Merge branch 'android11-5.4' into android11-5.4-lts

Change-Id: I83d45c04bbee6185721829195b1bf0ddbd437f16
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2025-04-26 01:33:15 -07:00
Cong Wang
eb15b7766c UPSTREAM: net_sched: Prevent creation of classes with TC_H_ROOT
[ Upstream commit 0c3057a5a04d07120b3d0ec9c79568fceb9c921e ]

The function qdisc_tree_reduce_backlog() uses TC_H_ROOT as a termination
condition when traversing up the qdisc tree to update parent backlog
counters. However, if a class is created with classid TC_H_ROOT, the
traversal terminates prematurely at this class instead of reaching the
actual root qdisc, causing parent statistics to be incorrectly maintained.
In case of DRR, this could lead to a crash as reported by Mingi Cho.

Prevent the creation of any Qdisc class with classid TC_H_ROOT
(0xFFFFFFFF) across all qdisc types, as suggested by Jamal.

Bug: 403920173
Reported-by: Mingi Cho <mincho@theori.io>
Signed-off-by: Cong Wang <xiyou.wangcong@gmail.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Fixes: 066a3b5b23 ("[NET_SCHED] sch_api: fix qdisc_tree_decrease_qlen() loop")
Link: https://patch.msgid.link/20250306232355.93864-2-xiyou.wangcong@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
(cherry picked from commit 78533c4a29ac3aeddce4b481770beaaa4f3bfb67)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: Ieac912ddc0bc44e999fe0d29ddf3a3842abdfa14
2025-04-22 12:46:48 +01:00
Greg Kroah-Hartman
9b78f083cb This is the 5.4.292 stable release
-----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCAAdFiEEZH8oZUiU471FcZm+ONu9yGCSaT4FAmf3uc8ACgkQONu9yGCS
 aT7cOA/+IMZpVcP8BeutEqLl9O0SXf4QS9LT8u/eQKy3b26p8otQXOkElhGmchBv
 cvb7+ZuJQGUcjfhW0CsHGx/vKfDz3qbbLaXH/F0sRvZxkYApX35pkSDOtcE3jAHn
 klQejHzoFlom8d951VUpQukwGXPoVfPExdXMWNg4RCrn1pcDnb3JjmEyhDRu5Sna
 fA1JeQ54UReNPUnXOHyixy+xoOLGBdikqVzV8SIqKNuzBloXIbSA831BGocFffrW
 xng8XIemuCEuK552/Ex8AJfUiY/q6XGH2OYy46g4oEG85xoyseGlQJqsnziOxDGX
 VYbdYGmtTZB7Tv2fwjpKsyluexoQEXmxVbu8CuGn/X0B1d48tRl40ROBMoAnOOhZ
 j7gjZG9TK9G7+fQSEpS8bLwknRndQWlbxSRMVEGAqIDcxF09+Hkkycu82siCtKz2
 JYQnKsv7We/m7EI+3uAh50zZrLU6NL+wVnkGlQy17RTQYYshZpSs6GYvB4OjJ5vx
 OXovZA2IKDnWA336viL265etHsUf2agNIyWiMr/5Tp4RgirN2WSQubZjNhp/FdjR
 e3MxVPrUxBD/QyGs2KuZo/rA/SuYDtMxdoogrYQO1cbpvBCcsyYvnczhAUcjVgKq
 C+iGTOAs+EEHWYol/CWuOJAkG/0O7Uj2U+cDdQQgeKD9SCSzohA=
 =wRcs
 -----END PGP SIGNATURE-----

Merge 5.4.292 into android11-5.4-lts

Changes in 5.4.292
	vlan: fix memory leak in vlan_newlink()
	clockevents/drivers/i8253: Fix stop sequence for timer 0
	sched/isolation: Prevent boot crash when the boot CPU is nohz_full
	Revert "sctp: sysctl: cookie_hmac_alg: avoid using current->nsproxy"
	Revert "sctp: sysctl: auth_enable: avoid using current->nsproxy"
	sctp: sysctl: cookie_hmac_alg: avoid using current->nsproxy
	sctp: sysctl: auth_enable: avoid using current->nsproxy
	pinctrl: bcm281xx: Fix incorrect regmap max_registers value
	netpoll: Fix use correct return type for ndo_start_xmit()
	netpoll: remove dev argument from netpoll_send_skb_on_dev()
	netpoll: move netpoll_send_skb() out of line
	netpoll: netpoll_send_skb() returns transmit status
	netpoll: hold rcu read lock in __netpoll_send_skb()
	drivers/hv: Replace binary semaphore with mutex
	Drivers: hv: vmbus: Don't release fb_mmio resource in vmbus_free_mmio()
	netfilter: nf_conncount: Fully initialize struct nf_conncount_tuple in insert_tree()
	ipvs: prevent integer overflow in do_ip_vs_get_ctl()
	net_sched: Prevent creation of classes with TC_H_ROOT
	netfilter: nft_exthdr: fix offset with ipv4_find_option()
	net/mlx5e: Prevent bridge link show failure for non-eswitch-allowed devices
	nvme-fc: go straight to connecting state when initializing
	hrtimers: Mark is_migration_base() with __always_inline
	powercap: call put_device() on an error path in powercap_register_control_type()
	iscsi_ibft: Fix UBSAN shift-out-of-bounds warning in ibft_attr_show_nic()
	scsi: qla1280: Fix kernel oops when debug level > 2
	ACPI: resource: IRQ override for Eluktronics MECH-17
	HID: intel-ish-hid: fix the length of MNG_SYNC_FW_CLOCK in doorbell
	HID: ignore non-functional sensor in HP 5MP Camera
	s390/cio: Fix CHPID "configure" attribute caching
	ASoC: rsnd: don't indicate warning on rsnd_kctrl_accept_runtime()
	nvmet-rdma: recheck queue state is LIVE in state lock in recv done
	sctp: Fix undefined behavior in left shift operation
	nvme: only allow entering LIVE from CONNECTING state
	fuse: don't truncate cached, mutated symlink
	x86/irq: Define trace events conditionally
	drm/nouveau: Do not override forced connector status
	block: fix 'kmem_cache of name 'bio-108' already exists'
	USB: serial: ftdi_sio: add support for Altera USB Blaster 3
	USB: serial: option: add Telit Cinterion FE990B compositions
	USB: serial: option: fix Telit Cinterion FE990A name
	USB: serial: option: match on interface class for Telit FN990B
	x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes
	drm/atomic: Filter out redundant DPMS calls
	drm/amd/display: Assign normalized_pix_clk when color depth = 14
	qlcnic: fix memory leak issues in qlcnic_sriov_common.c
	drm/gma500: Add NULL check for pci_gfx_root in mid_get_vbt_data()
	ASoC: codecs: wm0010: Fix error handling path in wm0010_spi_probe()
	i2c: ali1535: Fix an error handling path in ali1535_probe()
	i2c: ali15x3: Fix an error handling path in ali15x3_probe()
	i2c: sis630: Fix an error handling path in sis630_probe()
	firmware: imx-scu: fix OF node leak in .probe()
	xfrm_output: Force software GSO only in tunnel mode
	RDMA/bnxt_re: Avoid clearing VLAN_ID mask in modify qp path
	RDMA/hns: Fix wrong value of max_sge_rd
	Bluetooth: Fix error code in chan_alloc_skb_cb()
	ipv6: Fix memleak of nhc_pcpu_rth_output in fib_check_nh_v6_gw().
	ipv6: Set errno after ip_fib_metrics_init() in ip6_route_info_create().
	net: atm: fix use after free in lec_send()
	net/neighbor: add missing policy for NDTPA_QUEUE_LENBYTES
	i2c: omap: fix IRQ storms
	drm/v3d: Don't run jobs that have errors flagged in its fence
	mmc: atmel-mci: Add missing clk_disable_unprepare()
	ARM: shmobile: smp: Enforce shmobile_smp_* alignment
	batman-adv: Ignore own maximum aggregation size during RX
	drm/radeon: fix uninitialized size issue in radeon_vce_cs_parse()
	ALSA: usb-audio: Add quirk for Plantronics headsets to fix control names
	HID: hid-plantronics: Add mic mute mapping and generalize quirks
	atm: Fix NULL pointer dereference
	ARM: 9350/1: fault: Implement copy_from_kernel_nofault_allowed()
	ARM: 9351/1: fault: Add "cut here" line for prefetch aborts
	ARM: Remove address checking for MMUless devices
	netfilter: socket: Lookup orig tuple for IPv6 SNAT
	counter: stm32-lptimer-cnt: fix error handling when enabling
	tty: serial: 8250: Add some more device IDs
	net: usb: qmi_wwan: add Telit Cinterion FN990B composition
	net: usb: qmi_wwan: add Telit Cinterion FE990B composition
	net: usb: usbnet: restore usb%d name exception for local mac addresses
	memstick: rtsx_usb_ms: Fix slab-use-after-free in rtsx_usb_ms_drv_remove
	serial: 8250_dma: terminate correct DMA in tx_dma_flush()
	x86/mm/pat: cpa-test: fix length for CPA_ARRAY test
	cpufreq: governor: Fix negative 'idle_time' handling in dbs_update()
	x86/fpu: Avoid copying dynamic FP state from init_task in arch_dup_task_struct()
	x86/platform: Only allow CONFIG_EISA for 32-bit
	selinux: Chain up tool resolving errors in install_policy.sh
	EDAC/ie31200: Fix the size of EDAC_MC_LAYER_CHIP_SELECT layer
	EDAC/ie31200: Fix the DIMM size mask for several SoCs
	EDAC/ie31200: Fix the error path order of ie31200_init()
	thermal: int340x: Add NULL check for adev
	PM: sleep: Fix handling devices with direct_complete set on errors
	lockdep: Don't disable interrupts on RT in disable_irq_nosync_lockdep.*()
	perf/ring_buffer: Allow the EPOLLRDNORM flag for poll
	ALSA: hda/realtek: Always honor no_shutup_pins
	drm/mediatek: mtk_hdmi: Fix typo for aud_sampe_size member
	PCI/ASPM: Fix link state exit during switch upstream function removal
	PCI/portdrv: Only disable pciehp interrupts early when needed
	PCI: Remove stray put_device() in pci_register_host_bridge()
	PCI: pciehp: Don't enable HPIE when resuming in poll mode
	fbdev: au1100fb: Move a variable assignment behind a null pointer check
	mdacon: rework dependency list
	fbdev: sm501fb: Add some geometry checks.
	clk: amlogic: gxbb: drop incorrect flag on 32k clock
	bpf: Use preempt_count() directly in bpf_send_signal_common()
	lib: 842: Improve error handling in sw842_compress()
	pinctrl: renesas: rza2: Fix missing of_node_put() call
	clk: rockchip: rk3328: fix wrong clk_ref_usb3otg parent
	IB/mad: Check available slots before posting receive WRs
	clk: amlogic: g12b: fix cluster A parent data
	clk: amlogic: gxbb: drop non existing 32k clock parent
	clk: amlogic: g12a: fix mmc A peripheral clock
	x86/entry: Fix ORC unwinder for PUSH_REGS with save_ret=1
	power: supply: max77693: Fix wrong conversion of charge input threshold value
	RDMA/mlx5: Fix mlx5_poll_one() cur_qp update flow
	mfd: sm501: Switch to BIT() to mitigate integer overflows
	x86/dumpstack: Fix inaccurate unwinding from exception stacks due to misplaced assignment
	isofs: fix KMSAN uninit-value bug in do_isofs_readdir()
	coresight: catu: Fix number of pages while using 64k pages
	iio: accel: mma8452: Ensure error return on failure to matching oversampling ratio
	perf units: Fix insufficient array space
	kexec: initialize ELF lowest address to ULONG_MAX
	ocfs2: validate l_tree_depth to avoid out-of-bounds access
	perf python: Fixup description of sample.id event member
	perf python: Decrement the refcount of just created event on failure
	perf python: Check if there is space to copy all the event
	fs/procfs: fix the comment above proc_pid_wchan()
	objtool, media: dib8000: Prevent divide-by-zero in dib8000_set_dds()
	ring-buffer: Fix bytes_dropped calculation issue
	octeontx2-af: Fix mbox INTR handler when num VFs > 64
	sched/smt: Always inline sched_smt_active()
	wifi: iwlwifi: fw: allocate chained SG tables for dump
	affs: generate OFS sequence numbers starting at 1
	affs: don't write overlarge OFS data block size fields
	sched/deadline: Use online cpus for validating runtime
	locking/semaphore: Use wake_q to wake up processes outside lock critical section
	can: statistics: use atomic access in hot path
	hwmon: (nct6775-core) Fix out of bounds access for NCT679{8,9}
	spufs: fix a leak on spufs_new_file() failure
	spufs: fix a leak in spufs_create_context()
	ntb_hw_switchtec: Fix shift-out-of-bounds in switchtec_ntb_mw_set_trans
	ntb: intel: Fix using link status DB's
	netlabel: Fix NULL pointer exception caused by CALIPSO on IPv4 sockets
	net_sched: skbprio: Remove overly strict queue assertions
	vsock: avoid timeout during connect() if the socket is closing
	ipv6: fix omitted netlink attributes when using RTEXT_FILTER_SKIP_STATS
	net: dsa: mv88e6xxx: propperly shutdown PPU re-enable timer on destroy
	arcnet: Add NULL check in com20020pci_probe()
	can: flexcan: only change CAN state when link up in system PM
	ntb_perf: Delete duplicate dmaengine_unmap_put() call in perf_copy_chunk()
	x86/tsc: Always save/restore TSC sched_clock() on suspend/resume
	x86/mm: Fix flush_tlb_range() when used for zapping normal PMDs
	ACPI: resource: Skip IRQ override on ASUS Vivobook 14 X1404VAP
	mmc: sdhci-pxav3: set NEED_RSP_BUSY capability
	tracing: Fix use-after-free in print_graph_function_flags during tracer switching
	jfs: fix slab-out-of-bounds read in ea_get()
	jfs: add index corruption check to DT_GETPAGE()
	Linux 5.4.292

Change-Id: I9386a675acdf4384f0d612b6fc80c59bd6bb739f
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2025-04-11 08:16:05 +00:00
Greg Kroah-Hartman
1b01d9c341 Linux 5.4.292
Link: https://lore.kernel.org/r/20250408104815.295196624@linuxfoundation.org
Tested-by: Florian Fainelli <florian.fainelli@broadcom.com>
Tested-by: Jon Hunter <jonathanh@nvidia.com>
Tested-by: Linux Kernel Functional Testing <lkft@linaro.org>
Tested-by: Alok Tiwari <alok.a.tiwari@oracle.com>
Tested-by: Shuah Khan <skhan@linuxfoundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-04-10 14:29:43 +02:00
Roman Smirnov
2809029821 jfs: add index corruption check to DT_GETPAGE()
commit a8dfb2168906944ea61acfc87846b816eeab882d upstream.

If the file system is corrupted, the header.stblindex variable
may become greater than 127. Because of this, an array access out
of bounds may occur:

------------[ cut here ]------------
UBSAN: array-index-out-of-bounds in fs/jfs/jfs_dtree.c:3096:10
index 237 is out of range for type 'struct dtslot[128]'
CPU: 0 UID: 0 PID: 5822 Comm: syz-executor740 Not tainted 6.13.0-rc4-syzkaller-00110-g4099a71718b0 #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024
Call Trace:
 <TASK>
 __dump_stack lib/dump_stack.c:94 [inline]
 dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120
 ubsan_epilogue lib/ubsan.c:231 [inline]
 __ubsan_handle_out_of_bounds+0x121/0x150 lib/ubsan.c:429
 dtReadFirst+0x622/0xc50 fs/jfs/jfs_dtree.c:3096
 dtReadNext fs/jfs/jfs_dtree.c:3147 [inline]
 jfs_readdir+0x9aa/0x3c50 fs/jfs/jfs_dtree.c:2862
 wrap_directory_iterator+0x91/0xd0 fs/readdir.c:65
 iterate_dir+0x571/0x800 fs/readdir.c:108
 __do_sys_getdents64 fs/readdir.c:403 [inline]
 __se_sys_getdents64+0x1e2/0x4b0 fs/readdir.c:389
 do_syscall_x64 arch/x86/entry/common.c:52 [inline]
 do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
 </TASK>
---[ end trace ]---

Add a stblindex check for corruption.

Reported-by: syzbot <syzbot+9120834fc227768625ba@syzkaller.appspotmail.com>
Closes: https://syzkaller.appspot.com/bug?extid=9120834fc227768625ba
Fixes: 1da177e4c3 ("Linux-2.6.12-rc2")
Cc: stable@vger.kernel.org
Signed-off-by: Roman Smirnov <r.smirnov@omp.ru>
Signed-off-by: Dave Kleikamp <dave.kleikamp@oracle.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-04-10 14:29:43 +02:00
Qasim Ijaz
3d6fd5b9c6 jfs: fix slab-out-of-bounds read in ea_get()
commit fdf480da5837c23b146c4743c18de97202fcab37 upstream.

During the "size_check" label in ea_get(), the code checks if the extended
attribute list (xattr) size matches ea_size. If not, it logs
"ea_get: invalid extended attribute" and calls print_hex_dump().

Here, EALIST_SIZE(ea_buf->xattr) returns 4110417968, which exceeds
INT_MAX (2,147,483,647). Then ea_size is clamped:

	int size = clamp_t(int, ea_size, 0, EALIST_SIZE(ea_buf->xattr));

Although clamp_t aims to bound ea_size between 0 and 4110417968, the upper
limit is treated as an int, causing an overflow above 2^31 - 1. This leads
"size" to wrap around and become negative (-184549328).

The "size" is then passed to print_hex_dump() (called "len" in
print_hex_dump()), it is passed as type size_t (an unsigned
type), this is then stored inside a variable called
"int remaining", which is then assigned to "int linelen" which
is then passed to hex_dump_to_buffer(). In print_hex_dump()
the for loop, iterates through 0 to len-1, where len is
18446744073525002176, calling hex_dump_to_buffer()
on each iteration:

	for (i = 0; i < len; i += rowsize) {
		linelen = min(remaining, rowsize);
		remaining -= rowsize;

		hex_dump_to_buffer(ptr + i, linelen, rowsize, groupsize,
				   linebuf, sizeof(linebuf), ascii);

		...
	}

The expected stopping condition (i < len) is effectively broken
since len is corrupted and very large. This eventually leads to
the "ptr+i" being passed to hex_dump_to_buffer() to get closer
to the end of the actual bounds of "ptr", eventually an out of
bounds access is done in hex_dump_to_buffer() in the following
for loop:

	for (j = 0; j < len; j++) {
			if (linebuflen < lx + 2)
				goto overflow2;
			ch = ptr[j];
		...
	}

To fix this we should validate "EALIST_SIZE(ea_buf->xattr)"
before it is utilised.

Reported-by: syzbot <syzbot+4e6e7e4279d046613bc5@syzkaller.appspotmail.com>
Tested-by: syzbot <syzbot+4e6e7e4279d046613bc5@syzkaller.appspotmail.com>
Closes: https://syzkaller.appspot.com/bug?extid=4e6e7e4279d046613bc5
Fixes: d9f9d96136cb ("jfs: xattr: check invalid xattr size more strictly")
Cc: stable@vger.kernel.org
Signed-off-by: Qasim Ijaz <qasdev00@gmail.com>
Signed-off-by: Dave Kleikamp <dave.kleikamp@oracle.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-04-10 14:29:43 +02:00
Tengda Wu
42561fe62c tracing: Fix use-after-free in print_graph_function_flags during tracer switching
commit 7f81f27b1093e4895e87b74143c59c055c3b1906 upstream.

Kairui reported a UAF issue in print_graph_function_flags() during
ftrace stress testing [1]. This issue can be reproduced if puting a
'mdelay(10)' after 'mutex_unlock(&trace_types_lock)' in s_start(),
and executing the following script:

  $ echo function_graph > current_tracer
  $ cat trace > /dev/null &
  $ sleep 5  # Ensure the 'cat' reaches the 'mdelay(10)' point
  $ echo timerlat > current_tracer

The root cause lies in the two calls to print_graph_function_flags
within print_trace_line during each s_show():

  * One through 'iter->trace->print_line()';
  * Another through 'event->funcs->trace()', which is hidden in
    print_trace_fmt() before print_trace_line returns.

Tracer switching only updates the former, while the latter continues
to use the print_line function of the old tracer, which in the script
above is print_graph_function_flags.

Moreover, when switching from the 'function_graph' tracer to the
'timerlat' tracer, s_start only calls graph_trace_close of the
'function_graph' tracer to free 'iter->private', but does not set
it to NULL. This provides an opportunity for 'event->funcs->trace()'
to use an invalid 'iter->private'.

To fix this issue, set 'iter->private' to NULL immediately after
freeing it in graph_trace_close(), ensuring that an invalid pointer
is not passed to other tracers. Additionally, clean up the unnecessary
'iter->private = NULL' during each 'cat trace' when using wakeup and
irqsoff tracers.

 [1] https://lore.kernel.org/all/20231112150030.84609-1-ryncsn@gmail.com/

Cc: stable@vger.kernel.org
Cc: Masami Hiramatsu <mhiramat@kernel.org>
Cc: Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
Cc: Zheng Yejian <zhengyejian1@huawei.com>
Link: https://lore.kernel.org/20250320122137.23635-1-wutengda@huaweicloud.com
Fixes: eecb91b9f98d ("tracing: Fix memleak due to race between current_tracer and trace")
Closes: https://lore.kernel.org/all/CAMgjq7BW79KDSCyp+tZHjShSzHsScSiJxn5ffskp-QzVM06fxw@mail.gmail.com/
Reported-by: Kairui Song <kasong@tencent.com>
Signed-off-by: Tengda Wu <wutengda@huaweicloud.com>
Signed-off-by: Steven Rostedt (Google) <rostedt@goodmis.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-04-10 14:29:43 +02:00
Karel Balej
922a70031c mmc: sdhci-pxav3: set NEED_RSP_BUSY capability
commit a41fcca4b342811b473bbaa4b44f1d34d87fcce6 upstream.

Set the MMC_CAP_NEED_RSP_BUSY capability for the sdhci-pxav3 host to
prevent conversion of R1B responses to R1. Without this, the eMMC card
in the samsung,coreprimevelte smartphone using the Marvell PXA1908 SoC
with this mmc host doesn't probe with the ETIMEDOUT error originating in
__mmc_poll_for_busy.

Note that the other issues reported for this phone and host, namely
floods of "Tuning failed, falling back to fixed sampling clock" dmesg
messages for the eMMC and unstable SDIO are not mitigated by this
change.

Link: https://lore.kernel.org/r/20200310153340.5593-1-ulf.hansson@linaro.org/
Link: https://lore.kernel.org/r/D7204PWIGQGI.1FRFQPPIEE2P9@matfyz.cz/
Link: https://lore.kernel.org/r/20250115-pxa1908-lkml-v14-0-847d24f3665a@skole.hr/
Cc: stable@vger.kernel.org
Signed-off-by: Karel Balej <balejk@matfyz.cz>
Acked-by: Adrian Hunter <adrian.hunter@intel.com>
Tested-by: Duje Mihanović <duje.mihanovic@skole.hr>
Link: https://lore.kernel.org/r/20250310140707.23459-1-balejk@matfyz.cz
Signed-off-by: Ulf Hansson <ulf.hansson@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-04-10 14:29:43 +02:00
Paul Menzel
a7d0f84a31 ACPI: resource: Skip IRQ override on ASUS Vivobook 14 X1404VAP
commit 2da31ea2a085cd189857f2db0f7b78d0162db87a upstream.

Like the ASUS Vivobook X1504VAP and Vivobook X1704VAP, the ASUS Vivobook 14
X1404VAP has its keyboard IRQ (1) described as ActiveLow in the DSDT, which
the kernel overrides to EdgeHigh breaking the keyboard.

    $ sudo dmidecode
    […]
    System Information
            Manufacturer: ASUSTeK COMPUTER INC.
            Product Name: ASUS Vivobook 14 X1404VAP_X1404VA
    […]
    $ grep -A 30 PS2K dsdt.dsl | grep IRQ -A 1
                 IRQ (Level, ActiveLow, Exclusive, )
                     {1}

Add the X1404VAP to the irq1_level_low_skip_override[] quirk table to fix
this.

Closes: https://bugzilla.kernel.org/show_bug.cgi?id=219224
Cc: All applicable <stable@vger.kernel.org>
Signed-off-by: Paul Menzel <pmenzel@molgen.mpg.de>
Reviewed-by: Hans de Goede <hdegoede@redhat.com>
Tested-by: Anton Shyndin <mrcold.il@gmail.com>
Link: https://patch.msgid.link/20250318160903.77107-1-pmenzel@molgen.mpg.de
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-04-10 14:29:43 +02:00
Jann Horn
618d5612ec x86/mm: Fix flush_tlb_range() when used for zapping normal PMDs
commit 3ef938c3503563bfc2ac15083557f880d29c2e64 upstream.

On the following path, flush_tlb_range() can be used for zapping normal
PMD entries (PMD entries that point to page tables) together with the PTE
entries in the pointed-to page table:

    collapse_pte_mapped_thp
      pmdp_collapse_flush
        flush_tlb_range

The arm64 version of flush_tlb_range() has a comment describing that it can
be used for page table removal, and does not use any last-level
invalidation optimizations. Fix the X86 version by making it behave the
same way.

Currently, X86 only uses this information for the following two purposes,
which I think means the issue doesn't have much impact:

 - In native_flush_tlb_multi() for checking if lazy TLB CPUs need to be
   IPI'd to avoid issues with speculative page table walks.
 - In Hyper-V TLB paravirtualization, again for lazy TLB stuff.

The patch "x86/mm: only invalidate final translations with INVLPGB" which
is currently under review (see
<https://lore.kernel.org/all/20241230175550.4046587-13-riel@surriel.com/>)
would probably be making the impact of this a lot worse.

Fixes: 016c4d92cd ("x86/mm/tlb: Add freed_tables argument to flush_tlb_mm_range")
Signed-off-by: Jann Horn <jannh@google.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Cc: stable@vger.kernel.org
Link: https://lkml.kernel.org/r/20250103-x86-collapse-flush-fix-v1-1-3c521856cfa6@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-04-10 14:29:43 +02:00
Guilherme G. Piccoli
c0189c02b5 x86/tsc: Always save/restore TSC sched_clock() on suspend/resume
commit d90c9de9de2f1712df56de6e4f7d6982d358cabe upstream.

TSC could be reset in deep ACPI sleep states, even with invariant TSC.

That's the reason we have sched_clock() save/restore functions, to deal
with this situation. But what happens is that such functions are guarded
with a check for the stability of sched_clock - if not considered stable,
the save/restore routines aren't executed.

On top of that, we have a clear comment in native_sched_clock() saying
that *even* with TSC unstable, we continue using TSC for sched_clock due
to its speed.

In other words, if we have a situation of TSC getting detected as unstable,
it marks the sched_clock as unstable as well, so subsequent S3 sleep cycles
could bring bogus sched_clock values due to the lack of the save/restore
mechanism, causing warnings like this:

  [22.954918] ------------[ cut here ]------------
  [22.954923] Delta way too big! 18446743750843854390 ts=18446744072977390405 before=322133536015 after=322133536015 write stamp=18446744072977390405
  [22.954923] If you just came from a suspend/resume,
  [22.954923] please switch to the trace global clock:
  [22.954923]   echo global > /sys/kernel/tracing/trace_clock
  [22.954923] or add trace_clock=global to the kernel command line
  [22.954937] WARNING: CPU: 2 PID: 5728 at kernel/trace/ring_buffer.c:2890 rb_add_timestamp+0x193/0x1c0

Notice that the above was reproduced even with "trace_clock=global".

The fix for that is to _always_ save/restore the sched_clock on suspend
cycle _if TSC is used_ as sched_clock - only if we fallback to jiffies
the sched_clock_stable() check becomes relevant to save/restore the
sched_clock.

Debugged-by: Thadeu Lima de Souza Cascardo <cascardo@igalia.com>
Signed-off-by: Guilherme G. Piccoli <gpiccoli@igalia.com>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Cc: stable@vger.kernel.org
Cc: Thomas Gleixner <tglx@linutronix.de>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Link: https://lore.kernel.org/r/20250215210314.351480-1-gpiccoli@igalia.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-04-10 14:29:43 +02:00
Markus Elfring
2414095a8c ntb_perf: Delete duplicate dmaengine_unmap_put() call in perf_copy_chunk()
commit 4279e72cab31dd3eb8c89591eb9d2affa90ab6aa upstream.

The function call “dmaengine_unmap_put(unmap)” was used in an if branch.
The same call was immediately triggered by a subsequent goto statement.
Thus avoid such a call repetition.

This issue was detected by using the Coccinelle software.

Fixes: 5648e56d03 ("NTB: ntb_perf: Add full multi-port NTB API support")
Cc: stable@vger.kernel.org
Signed-off-by: Markus Elfring <elfring@users.sourceforge.net>
Signed-off-by: Jon Mason <jdmason@kudzu.us>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-04-10 14:29:43 +02:00
Haibo Chen
a1ef4447b8 can: flexcan: only change CAN state when link up in system PM
[ Upstream commit fd99d6ed20234b83d65b9c5417794343577cf3e5 ]

After a suspend/resume cycle on a down interface, it will come up as
ERROR-ACTIVE.

$ ip -details -s -s a s dev flexcan0
3: flexcan0: <NOARP,ECHO> mtu 16 qdisc pfifo_fast state DOWN group default qlen 10
    link/can  promiscuity 0 allmulti 0 minmtu 0 maxmtu 0
    can state STOPPED (berr-counter tx 0 rx 0) restart-ms 1000

$ sudo systemctl suspend

$ ip -details -s -s a s dev flexcan0
3: flexcan0: <NOARP,ECHO> mtu 16 qdisc pfifo_fast state DOWN group default qlen 10
    link/can  promiscuity 0 allmulti 0 minmtu 0 maxmtu 0
    can state ERROR-ACTIVE (berr-counter tx 0 rx 0) restart-ms 1000

And only set CAN state to CAN_STATE_ERROR_ACTIVE when resume process
has no issue, otherwise keep in CAN_STATE_SLEEPING as suspend did.

Fixes: 4de349e786 ("can: flexcan: fix resume function")
Cc: stable@vger.kernel.org
Signed-off-by: Haibo Chen <haibo.chen@nxp.com>
Link: https://patch.msgid.link/20250314110145.899179-1-haibo.chen@nxp.com
Reported-by: Marc Kleine-Budde <mkl@pengutronix.de>
Closes: https://lore.kernel.org/all/20250314-married-polar-elephant-b15594-mkl@pengutronix.de
[mkl: add newlines]
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-04-10 14:29:43 +02:00
Henry Martin
661cf5d102 arcnet: Add NULL check in com20020pci_probe()
[ Upstream commit fda8c491db2a90ff3e6fbbae58e495b4ddddeca3 ]

devm_kasprintf() returns NULL when memory allocation fails. Currently,
com20020pci_probe() does not check for this case, which results in a
NULL pointer dereference.

Add NULL check after devm_kasprintf() to prevent this issue and ensure
no resources are left allocated.

Fixes: 6b17a597fc2f ("arcnet: restoring support for multiple Sohard Arcnet cards")
Signed-off-by: Henry Martin <bsdhenrymartin@gmail.com>
Link: https://patch.msgid.link/20250402135036.44697-1-bsdhenrymartin@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-04-10 14:29:43 +02:00
David Oberhollenzer
5309432c67 net: dsa: mv88e6xxx: propperly shutdown PPU re-enable timer on destroy
[ Upstream commit a58d882841a0750da3c482cd3d82432b1c7edb77 ]

The mv88e6xxx has an internal PPU that polls PHY state. If we want to
access the internal PHYs, we need to disable the PPU first. Because
that is a slow operation, a 10ms timer is used to re-enable it,
canceled with every access, so bulk operations effectively only
disable it once and re-enable it some 10ms after the last access.

If a PHY is accessed and then the mv88e6xxx module is removed before
the 10ms are up, the PPU re-enable ends up accessing a dangling pointer.

This especially affects probing during bootup. The MDIO bus and PHY
registration may succeed, but registration with the DSA framework
may fail later on (e.g. because the CPU port depends on another,
very slow device that isn't done probing yet, returning -EPROBE_DEFER).
In this case, probe() fails, but the MDIO subsystem may already have
accessed the MIDO bus or PHYs, arming the timer.

This is fixed as follows:
 - If probe fails after mv88e6xxx_phy_init(), make sure we also call
   mv88e6xxx_phy_destroy() before returning
 - In mv88e6xxx_remove(), make sure we do the teardown in the correct
   order, calling mv88e6xxx_phy_destroy() after unregistering the
   switch device.
 - In mv88e6xxx_phy_destroy(), destroy both the timer and the work item
   that the timer might schedule, synchronously waiting in case one of
   the callbacks already fired and destroying the timer first, before
   waiting for the work item.
 - Access to the PPU is guarded by a mutex, the worker acquires it
   with a mutex_trylock(), not proceeding with the expensive shutdown
   if that fails. We grab the mutex in mv88e6xxx_phy_destroy() to make
   sure the slow PPU shutdown is already done or won't even enter, when
   we wait for the work item.

Fixes: 2e5f032095 ("dsa: add support for the Marvell 88E6131 switch chip")
Signed-off-by: David Oberhollenzer <david.oberhollenzer@sigma-star.at>
Reviewed-by: Vladimir Oltean <olteanv@gmail.com>
Link: https://patch.msgid.link/20250401135705.92760-1-david.oberhollenzer@sigma-star.at
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-04-10 14:29:43 +02:00
Fernando Fernandez Mancera
87c53a1c65 ipv6: fix omitted netlink attributes when using RTEXT_FILTER_SKIP_STATS
[ Upstream commit 7ac6ea4a3e0898db76aecccd68fb2c403eb7d24e ]

Using RTEXT_FILTER_SKIP_STATS is incorrectly skipping non-stats IPv6
netlink attributes on link dump. This causes issues on userspace tools,
e.g iproute2 is not rendering address generation mode as it should due
to missing netlink attribute.

Move the filling of IFLA_INET6_STATS and IFLA_INET6_ICMP6STATS to a
helper function guarded by a flag check to avoid hitting the same
situation in the future.

Fixes: d5566fd72e ("rtnetlink: RTEXT_FILTER_SKIP_STATS support to avoid dumping inet/inet6 stats")
Signed-off-by: Fernando Fernandez Mancera <ffmancera@riseup.net>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20250402121751.3108-1-ffmancera@riseup.net
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-04-10 14:29:43 +02:00
Stefano Garzarella
42df95e5ea vsock: avoid timeout during connect() if the socket is closing
[ Upstream commit fccd2b711d9628c7ce0111d5e4938652101ee30a ]

When a peer attempts to establish a connection, vsock_connect() contains
a loop that waits for the state to be TCP_ESTABLISHED. However, the
other peer can be fast enough to accept the connection and close it
immediately, thus moving the state to TCP_CLOSING.

When this happens, the peer in the vsock_connect() is properly woken up,
but since the state is not TCP_ESTABLISHED, it goes back to sleep
until the timeout expires, returning -ETIMEDOUT.

If the socket state is TCP_CLOSING, waiting for the timeout is pointless.
vsock_connect() can return immediately without errors or delay since the
connection actually happened. The socket will be in a closing state,
but this is not an issue, and subsequent calls will fail as expected.

We discovered this issue while developing a test that accepts and
immediately closes connections to stress the transport switch between
two connect() calls, where the first one was interrupted by a signal
(see Closes link).

Reported-by: Luigi Leonardi <leonardi@redhat.com>
Closes: https://lore.kernel.org/virtualization/bq6hxrolno2vmtqwcvb5bljfpb7mvwb3kohrvaed6auz5vxrfv@ijmd2f3grobn/
Fixes: d021c34405 ("VSOCK: Introduce VM Sockets")
Signed-off-by: Stefano Garzarella <sgarzare@redhat.com>
Acked-by: Paolo Abeni <pabeni@redhat.com>
Tested-by: Luigi Leonardi <leonardi@redhat.com>
Reviewed-by: Luigi Leonardi <leonardi@redhat.com>
Link: https://patch.msgid.link/20250328141528.420719-1-sgarzare@redhat.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-04-10 14:29:43 +02:00
Cong Wang
7abc8318ce net_sched: skbprio: Remove overly strict queue assertions
[ Upstream commit ce8fe975fd99b49c29c42e50f2441ba53112b2e8 ]

In the current implementation, skbprio enqueue/dequeue contains an assertion
that fails under certain conditions when SKBPRIO is used as a child qdisc under
TBF with specific parameters. The failure occurs because TBF sometimes peeks at
packets in the child qdisc without actually dequeuing them when tokens are
unavailable.

This peek operation creates a discrepancy between the parent and child qdisc
queue length counters. When TBF later receives a high-priority packet,
SKBPRIO's queue length may show a different value than what's reflected in its
internal priority queue tracking, triggering the assertion.

The fix removes this overly strict assertions in SKBPRIO, they are not
necessary at all.

Reported-by: syzbot+a3422a19b05ea96bee18@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=a3422a19b05ea96bee18
Fixes: aea5f654e6 ("net/sched: add skbprio scheduler")
Cc: Nishanth Devarajan <ndev2021@gmail.com>
Signed-off-by: Cong Wang <xiyou.wangcong@gmail.com>
Acked-by: Paolo Abeni <pabeni@redhat.com>
Link: https://patch.msgid.link/20250329222536.696204-2-xiyou.wangcong@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-04-10 14:29:43 +02:00
Debin Zhu
1ad9166cab netlabel: Fix NULL pointer exception caused by CALIPSO on IPv4 sockets
[ Upstream commit 078aabd567de3d63d37d7673f714e309d369e6e2 ]

When calling netlbl_conn_setattr(), addr->sa_family is used
to determine the function behavior. If sk is an IPv4 socket,
but the connect function is called with an IPv6 address,
the function calipso_sock_setattr() is triggered.
Inside this function, the following code is executed:

sk_fullsock(__sk) ? inet_sk(__sk)->pinet6 : NULL;

Since sk is an IPv4 socket, pinet6 is NULL, leading to a
null pointer dereference.

This patch fixes the issue by checking if inet6_sk(sk)
returns a NULL pointer before accessing pinet6.

Signed-off-by: Debin Zhu <mowenroot@163.com>
Signed-off-by: Bitao Ouyang <1985755126@qq.com>
Acked-by: Paul Moore <paul@paul-moore.com>
Fixes: ceba1832b1 ("calipso: Set the calipso socket label to match the secattr.")
Link: https://patch.msgid.link/20250401124018.4763-1-mowenroot@163.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-04-10 14:29:43 +02:00
Nikita Shubin
b9f2980327 ntb: intel: Fix using link status DB's
[ Upstream commit 8144e9c8f30fb23bb736a5d24d5c9d46965563c4 ]

Make sure we are not using DB's which were remapped for link status.

Fixes: f6e51c354b ("ntb: intel: split out the gen3 code")
Signed-off-by: Nikita Shubin <n.shubin@yadro.com>
Reviewed-by: Dave Jiang <dave.jiang@intel.com>
Signed-off-by: Jon Mason <jdmason@kudzu.us>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-04-10 14:29:42 +02:00
Yajun Deng
f56951f211 ntb_hw_switchtec: Fix shift-out-of-bounds in switchtec_ntb_mw_set_trans
[ Upstream commit de203da734fae00e75be50220ba5391e7beecdf9 ]

There is a kernel API ntb_mw_clear_trans() would pass 0 to both addr and
size. This would make xlate_pos negative.

[   23.734156] switchtec switchtec0: MW 0: part 0 addr 0x0000000000000000 size 0x0000000000000000
[   23.734158] ================================================================================
[   23.734172] UBSAN: shift-out-of-bounds in drivers/ntb/hw/mscc/ntb_hw_switchtec.c:293:7
[   23.734418] shift exponent -1 is negative

Ensuring xlate_pos is a positive or zero before BIT.

Fixes: 1e2fd202f8 ("ntb_hw_switchtec: Check for alignment of the buffer in mw_set_trans()")
Signed-off-by: Yajun Deng <yajun.deng@linux.dev>
Reviewed-by: Logan Gunthorpe <logang@deltatee.com>
Signed-off-by: Jon Mason <jdmason@kudzu.us>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-04-10 14:29:42 +02:00
Al Viro
829bd61399 spufs: fix a leak in spufs_create_context()
[ Upstream commit 0f5cce3fc55b08ee4da3372baccf4bcd36a98396 ]

Leak fixes back in 2008 missed one case - if we are trying to set affinity
and spufs_mkdir() fails, we need to drop the reference to neighbor.

Fixes: 58119068cb "[POWERPC] spufs: Fix memory leak on SPU affinity"
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-04-10 14:29:42 +02:00
Al Viro
b1eef06d10 spufs: fix a leak on spufs_new_file() failure
[ Upstream commit d1ca8698ca1332625d83ea0d753747be66f9906d ]

It's called from spufs_fill_dir(), and caller of that will do
spufs_rmdir() in case of failure.  That does remove everything
we'd managed to create, but... the problem dentry is still
negative.  IOW, it needs to be explicitly dropped.

Fixes: 3f51dd91c8 "[PATCH] spufs: fix spufs_fill_dir error path"
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-04-10 14:29:42 +02:00
Tasos Sahanidis
5214156633 hwmon: (nct6775-core) Fix out of bounds access for NCT679{8,9}
[ Upstream commit 815f80ad20b63830949a77c816e35395d5d55144 ]

pwm_num is set to 7 for these chips, but NCT6776_REG_PWM_MODE and
NCT6776_PWM_MODE_MASK only contain 6 values.

Fix this by adding another 0 to the end of each array.

Signed-off-by: Tasos Sahanidis <tasos@tasossah.com>
Link: https://lore.kernel.org/r/20250312030832.106475-1-tasos@tasossah.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-04-10 14:29:42 +02:00
Oliver Hartkopp
12d344d74c can: statistics: use atomic access in hot path
[ Upstream commit 80b5f90158d1364cbd80ad82852a757fc0692bf2 ]

In can_send() and can_receive() CAN messages and CAN filter matches are
counted to be visible in the CAN procfs files.

KCSAN detected a data race within can_send() when two CAN frames have
been generated by a timer event writing to the same CAN netdevice at the
same time. Use atomic operations to access the statistics in the hot path
to fix the KCSAN complaint.

Reported-by: syzbot+78ce4489b812515d5e4d@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/all/67cd717d.050a0220.e1a89.0006.GAE@google.com
Signed-off-by: Oliver Hartkopp <socketcan@hartkopp.net>
Reviewed-by: Vincent Mailhol <mailhol.vincent@wanadoo.fr>
Link: https://patch.msgid.link/20250310143353.3242-1-socketcan@hartkopp.net
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-04-10 14:29:42 +02:00
Waiman Long
d6ae75c3ba locking/semaphore: Use wake_q to wake up processes outside lock critical section
[ Upstream commit 85b2b9c16d053364e2004883140538e73b333cdb ]

A circular lock dependency splat has been seen involving down_trylock():

  ======================================================
  WARNING: possible circular locking dependency detected
  6.12.0-41.el10.s390x+debug
  ------------------------------------------------------
  dd/32479 is trying to acquire lock:
  0015a20accd0d4f8 ((console_sem).lock){-.-.}-{2:2}, at: down_trylock+0x26/0x90

  but task is already holding lock:
  000000017e461698 (&zone->lock){-.-.}-{2:2}, at: rmqueue_bulk+0xac/0x8f0

  the existing dependency chain (in reverse order) is:
  -> #4 (&zone->lock){-.-.}-{2:2}:
  -> #3 (hrtimer_bases.lock){-.-.}-{2:2}:
  -> #2 (&rq->__lock){-.-.}-{2:2}:
  -> #1 (&p->pi_lock){-.-.}-{2:2}:
  -> #0 ((console_sem).lock){-.-.}-{2:2}:

The console_sem -> pi_lock dependency is due to calling try_to_wake_up()
while holding the console_sem raw_spinlock. This dependency can be broken
by using wake_q to do the wakeup instead of calling try_to_wake_up()
under the console_sem lock. This will also make the semaphore's
raw_spinlock become a terminal lock without taking any further locks
underneath it.

The hrtimer_bases.lock is a raw_spinlock while zone->lock is a
spinlock. The hrtimer_bases.lock -> zone->lock dependency happens via
the debug_objects_fill_pool() helper function in the debugobjects code.

  -> #4 (&zone->lock){-.-.}-{2:2}:
         __lock_acquire+0xe86/0x1cc0
         lock_acquire.part.0+0x258/0x630
         lock_acquire+0xb8/0xe0
         _raw_spin_lock_irqsave+0xb4/0x120
         rmqueue_bulk+0xac/0x8f0
         __rmqueue_pcplist+0x580/0x830
         rmqueue_pcplist+0xfc/0x470
         rmqueue.isra.0+0xdec/0x11b0
         get_page_from_freelist+0x2ee/0xeb0
         __alloc_pages_noprof+0x2c2/0x520
         alloc_pages_mpol_noprof+0x1fc/0x4d0
         alloc_pages_noprof+0x8c/0xe0
         allocate_slab+0x320/0x460
         ___slab_alloc+0xa58/0x12b0
         __slab_alloc.isra.0+0x42/0x60
         kmem_cache_alloc_noprof+0x304/0x350
         fill_pool+0xf6/0x450
         debug_object_activate+0xfe/0x360
         enqueue_hrtimer+0x34/0x190
         __run_hrtimer+0x3c8/0x4c0
         __hrtimer_run_queues+0x1b2/0x260
         hrtimer_interrupt+0x316/0x760
         do_IRQ+0x9a/0xe0
         do_irq_async+0xf6/0x160

Normally a raw_spinlock to spinlock dependency is not legitimate
and will be warned if CONFIG_PROVE_RAW_LOCK_NESTING is enabled,
but debug_objects_fill_pool() is an exception as it explicitly
allows this dependency for non-PREEMPT_RT kernel without causing
PROVE_RAW_LOCK_NESTING lockdep splat. As a result, this dependency is
legitimate and not a bug.

Anyway, semaphore is the only locking primitive left that is still
using try_to_wake_up() to do wakeup inside critical section, all the
other locking primitives had been migrated to use wake_q to do wakeup
outside of the critical section. It is also possible that there are
other circular locking dependencies involving printk/console_sem or
other existing/new semaphores lurking somewhere which may show up in
the future. Let just do the migration now to wake_q to avoid headache
like this.

Reported-by: yzbot+ed801a886dfdbfe7136d@syzkaller.appspotmail.com
Signed-off-by: Waiman Long <longman@redhat.com>
Signed-off-by: Boqun Feng <boqun.feng@gmail.com>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Link: https://lore.kernel.org/r/20250307232717.1759087-3-boqun.feng@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-04-10 14:29:42 +02:00
Shrikanth Hegde
0ab44f03c5 sched/deadline: Use online cpus for validating runtime
[ Upstream commit 14672f059d83f591afb2ee1fff56858efe055e5a ]

The ftrace selftest reported a failure because writing -1 to
sched_rt_runtime_us returns -EBUSY. This happens when the possible
CPUs are different from active CPUs.

Active CPUs are part of one root domain, while remaining CPUs are part
of def_root_domain. Since active cpumask is being used, this results in
cpus=0 when a non active CPUs is used in the loop.

Fix it by looping over the online CPUs instead for validating the
bandwidth calculations.

Signed-off-by: Shrikanth Hegde <sshegde@linux.ibm.com>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Reviewed-by: Juri Lelli <juri.lelli@redhat.com>
Link: https://lore.kernel.org/r/20250306052954.452005-2-sshegde@linux.ibm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-04-10 14:29:42 +02:00
Simon Tatham
04039a3806 affs: don't write overlarge OFS data block size fields
[ Upstream commit 011ea742a25a77bac3d995f457886a67d178c6f0 ]

If a data sector on an OFS floppy contains a value > 0x1e8 (the
largest amount of data that fits in the sector after its header), then
an Amiga reading the file can return corrupt data, by taking the
overlarge size at its word and reading past the end of the buffer it
read the disk sector into!

The cause: when affs_write_end_ofs() writes data to an OFS filesystem,
the new size field for a data block was computed by adding the amount
of data currently being written (into the block) to the existing value
of the size field. This is correct if you're extending the file at the
end, but if you seek backwards in the file and overwrite _existing_
data, it can lead to the size field being larger than the maximum
legal value.

This commit changes the calculation so that it sets the size field to
the max of its previous size and the position within the block that we
just wrote up to.

Signed-off-by: Simon Tatham <anakin@pobox.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-04-10 14:29:42 +02:00
Simon Tatham
739499e146 affs: generate OFS sequence numbers starting at 1
[ Upstream commit e4cf8ec4de4e13f156c1d61977d282d90c221085 ]

If I write a file to an OFS floppy image, and try to read it back on
an emulated Amiga running Workbench 1.3, the Amiga reports a disk
error trying to read the file. (That is, it's unable to read it _at
all_, even to copy it to the NIL: device. It isn't a matter of getting
the wrong data and being unable to parse the file format.)

This is because the 'sequence number' field in the OFS data block
header is supposed to be based at 1, but affs writes it based at 0.
All three locations changed by this patch were setting the sequence
number to a variable 'bidx' which was previously obtained by dividing
a file position by bsize, so bidx will naturally use 0 for the first
block. Therefore all three should add 1 to that value before writing
it into the sequence number field.

With this change, the Amiga successfully reads the file.

For data block reference: https://wiki.osdev.org/FFS_(Amiga)

Signed-off-by: Simon Tatham <anakin@pobox.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-04-10 14:29:42 +02:00
Johannes Berg
f5302f6786 wifi: iwlwifi: fw: allocate chained SG tables for dump
[ Upstream commit 7774e3920029398ad49dc848b23840593f14d515 ]

The firmware dumps can be pretty big, and since we use single
pages for each SG table entry, even the table itself may end
up being an order-5 allocation. Build chained tables so that
we need not allocate a higher-order table here.

This could be improved and cleaned up, e.g. by using the SG
pool code or simply kvmalloc(), but all of that would require
also updating the devcoredump first since that frees it all,
so we need to be more careful. SG pool might also run against
the CONFIG_ARCH_NO_SG_CHAIN limitation, which is irrelevant
here.

Also use _devcd_free_sgtable() for the error paths now, much
simpler especially since it's in two places now.

Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Miri Korenblit <miriam.rachel.korenblit@intel.com>
Link: https://patch.msgid.link/20250209143303.697c7a465ac9.Iea982df46b5c075bfb77ade36f187d99a70c63db@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-04-10 14:29:42 +02:00
Josh Poimboeuf
99bd64445f sched/smt: Always inline sched_smt_active()
[ Upstream commit 09f37f2d7b21ff35b8b533f9ab8cfad2fe8f72f6 ]

sched_smt_active() can be called from noinstr code, so it should always
be inlined.  The CONFIG_SCHED_SMT version already has __always_inline.
Do the same for its !CONFIG_SCHED_SMT counterpart.

Fixes the following warning:

  vmlinux.o: error: objtool: intel_idle_ibrs+0x13: call to sched_smt_active() leaves .noinstr.text section

Fixes: 321a874a7e ("sched/smt: Expose sched_smt_present static key")
Reported-by: kernel test robot <lkp@intel.com>
Signed-off-by: Josh Poimboeuf <jpoimboe@kernel.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Link: https://lore.kernel.org/r/1d03907b0a247cf7fb5c1d518de378864f603060.1743481539.git.jpoimboe@kernel.org
Closes: https://lore.kernel.org/r/202503311434.lyw2Tveh-lkp@intel.com/
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-04-10 14:29:42 +02:00
Geetha sowjanya
da3b90f71b octeontx2-af: Fix mbox INTR handler when num VFs > 64
[ Upstream commit 0fdba88a211508984eb5df62008c29688692b134 ]

When number of RVU VFs > 64, the vfs value passed to "rvu_queue_work"
function is incorrect. Due to which mbox workqueue entries for
VFs 0 to 63 never gets added to workqueue.

Fixes: 9bdc47a6e3 ("octeontx2-af: Mbox communication support btw AF and it's VFs")
Signed-off-by: Geetha sowjanya <gakula@marvell.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20250327091441.1284-1-gakula@marvell.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-04-10 14:29:42 +02:00
Feng Yang
4a760b682e ring-buffer: Fix bytes_dropped calculation issue
[ Upstream commit c73f0b69648501978e8b3e8fa7eef7f4197d0481 ]

The calculation of bytes-dropped and bytes_dropped_nested is reversed.
Although it does not affect the final calculation of total_dropped,
it should still be modified.

Link: https://lore.kernel.org/20250223070106.6781-1-yangfeng59949@163.com
Fixes: 6c43e554a2 ("ring-buffer: Add ring buffer startup selftest")
Signed-off-by: Feng Yang <yangfeng@kylinos.cn>
Signed-off-by: Steven Rostedt (Google) <rostedt@goodmis.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-04-10 14:29:42 +02:00
Josh Poimboeuf
536f7f3595 objtool, media: dib8000: Prevent divide-by-zero in dib8000_set_dds()
[ Upstream commit e63d465f59011dede0a0f1d21718b59a64c3ff5c ]

If dib8000_set_dds()'s call to dib8000_read32() returns zero, the result
is a divide-by-zero.  Prevent that from happening.

Fixes the following warning with an UBSAN kernel:

  drivers/media/dvb-frontends/dib8000.o: warning: objtool: dib8000_tune() falls through to next function dib8096p_cfg_DibRx()

Fixes: 173a64cb3f ("[media] dib8000: enhancement")
Reported-by: kernel test robot <lkp@intel.com>
Signed-off-by: Josh Poimboeuf <jpoimboe@kernel.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Cc: Mauro Carvalho Chehab <mchehab@kernel.org>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Link: https://lore.kernel.org/r/bd1d504d930ae3f073b1e071bcf62cae7708773c.1742852847.git.jpoimboe@kernel.org
Closes: https://lore.kernel.org/r/202503210602.fvH5DO1i-lkp@intel.com/
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-04-10 14:29:42 +02:00
Bart Van Assche
6601c04a87 fs/procfs: fix the comment above proc_pid_wchan()
[ Upstream commit 6287fbad1cd91f0c25cdc3a580499060828a8f30 ]

proc_pid_wchan() used to report kernel addresses to user space but that is
no longer the case today.  Bring the comment above proc_pid_wchan() in
sync with the implementation.

Link: https://lkml.kernel.org/r/20250319210222.1518771-1-bvanassche@acm.org
Fixes: b2f73922d1 ("fs/proc, core/debug: Don't expose absolute kernel addresses via wchan")
Signed-off-by: Bart Van Assche <bvanassche@acm.org>
Cc: Kees Cook <kees@kernel.org>
Cc: Eric W. Biederman <ebiederm@xmission.com>
Cc: Alexey Dobriyan <adobriyan@gmail.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-04-10 14:29:42 +02:00
Arnaldo Carvalho de Melo
38dffe995b perf python: Check if there is space to copy all the event
[ Upstream commit 89aaeaf84231157288035b366cb6300c1c6cac64 ]

The pyrf_event__new() method copies the event obtained from the perf
ring buffer to a structure that will then be turned into a python object
for further consumption, so it copies perf_event.header.size bytes to
its 'event' member:

  $ pahole -C pyrf_event /tmp/build/perf-tools-next/python/perf.cpython-312-x86_64-linux-gnu.so
  struct pyrf_event {
  	PyObject                   ob_base;              /*     0    16 */
  	struct evsel *             evsel;                /*    16     8 */
  	struct perf_sample         sample;               /*    24   312 */

  	/* XXX last struct has 7 bytes of padding, 2 holes */

  	/* --- cacheline 5 boundary (320 bytes) was 16 bytes ago --- */
  	union perf_event           event;                /*   336  4168 */

  	/* size: 4504, cachelines: 71, members: 4 */
  	/* member types with holes: 1, total: 2 */
  	/* paddings: 1, sum paddings: 7 */
  	/* last cacheline: 24 bytes */
  };

  $

It was doing so without checking if the event just obtained has more
than that space, fix it.

This isn't a proper, final solution, as we need to support larger
events, but for the time being we at least bounds check and document it.

Fixes: 877108e42b ("perf tools: Initial python binding")
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Reviewed-by: Ian Rogers <irogers@google.com>
Link: https://lore.kernel.org/r/20250312203141.285263-7-acme@kernel.org
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-04-10 14:29:42 +02:00
Arnaldo Carvalho de Melo
213ee3d738 perf python: Decrement the refcount of just created event on failure
[ Upstream commit 3de5a2bf5b4847f7a59a184568f969f8fe05d57f ]

To avoid a leak if we have the python object but then something happens
and we need to return the operation, decrement the offset of the newly
created object.

Fixes: 377f698db1 ("perf python: Add struct evsel into struct pyrf_event")
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Reviewed-by: Ian Rogers <irogers@google.com>
Link: https://lore.kernel.org/r/20250312203141.285263-5-acme@kernel.org
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-04-10 14:29:41 +02:00
Arnaldo Carvalho de Melo
58edf5e6a3 perf python: Fixup description of sample.id event member
[ Upstream commit 1376c195e8ad327bb9f2d32e0acc5ac39e7cb30a ]

Some old cut'n'paste error, its "ip", so the description should be
"event ip", not "event type".

Fixes: 877108e42b ("perf tools: Initial python binding")
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Reviewed-by: Ian Rogers <irogers@google.com>
Link: https://lore.kernel.org/r/20250312203141.285263-2-acme@kernel.org
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-04-10 14:29:41 +02:00
Vasiliy Kovalev
ef34840bda ocfs2: validate l_tree_depth to avoid out-of-bounds access
[ Upstream commit a406aff8c05115119127c962cbbbbd202e1973ef ]

The l_tree_depth field is 16-bit (__le16), but the actual maximum depth is
limited to OCFS2_MAX_PATH_DEPTH.

Add a check to prevent out-of-bounds access if l_tree_depth has an invalid
value, which may occur when reading from a corrupted mounted disk [1].

Link: https://lkml.kernel.org/r/20250214084908.736528-1-kovalev@altlinux.org
Fixes: ccd979bdbc ("[PATCH] OCFS2: The Second Oracle Cluster Filesystem")
Signed-off-by: Vasiliy Kovalev <kovalev@altlinux.org>
Reported-by: syzbot+66c146268dc88f4341fd@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=66c146268dc88f4341fd [1]
Reviewed-by: Joseph Qi <joseph.qi@linux.alibaba.com>
Cc: Joel Becker <jlbec@evilplan.org>
Cc: Junxiao Bi <junxiao.bi@oracle.com>
Cc: Changwei Ge <gechangwei@live.cn>
Cc: Jun Piao <piaojun@huawei.com>
Cc: Kurt Hackel <kurt.hackel@oracle.com>
Cc: Mark Fasheh <mark@fasheh.com>
Cc: Vasiliy Kovalev <kovalev@altlinux.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-04-10 14:29:41 +02:00
Sourabh Jain
8a3ebead12 kexec: initialize ELF lowest address to ULONG_MAX
[ Upstream commit 9986fb5164c8b21f6439cfd45ba36d8cc80c9710 ]

Patch series "powerpc/crash: use generic crashkernel reservation", v3.

Commit 0ab97169aa05 ("crash_core: add generic function to do reservation")
added a generic function to reserve crashkernel memory.  So let's use the
same function on powerpc and remove the architecture-specific code that
essentially does the same thing.

The generic crashkernel reservation also provides a way to split the
crashkernel reservation into high and low memory reservations, which can
be enabled for powerpc in the future.

Additionally move powerpc to use generic APIs to locate memory hole for
kexec segments while loading kdump kernel.

This patch (of 7):

kexec_elf_load() loads an ELF executable and sets the address of the
lowest PT_LOAD section to the address held by the lowest_load_addr
function argument.

To determine the lowest PT_LOAD address, a local variable lowest_addr
(type unsigned long) is initialized to UINT_MAX.  After loading each
PT_LOAD, its address is compared to lowest_addr.  If a loaded PT_LOAD
address is lower, lowest_addr is updated.  However, setting lowest_addr to
UINT_MAX won't work when the kernel image is loaded above 4G, as the
returned lowest PT_LOAD address would be invalid.  This is resolved by
initializing lowest_addr to ULONG_MAX instead.

This issue was discovered while implementing crashkernel high/low
reservation on the PowerPC architecture.

Link: https://lkml.kernel.org/r/20250131113830.925179-1-sourabhjain@linux.ibm.com
Link: https://lkml.kernel.org/r/20250131113830.925179-2-sourabhjain@linux.ibm.com
Fixes: a0458284f0 ("powerpc: Add support code for kexec_file_load()")
Signed-off-by: Sourabh Jain <sourabhjain@linux.ibm.com>
Acked-by: Hari Bathini <hbathini@linux.ibm.com>
Acked-by: Baoquan He <bhe@redhat.com>
Cc: Madhavan Srinivasan <maddy@linux.ibm.com>
Cc: Mahesh Salgaonkar <mahesh@linux.ibm.com>
Cc: Michael Ellerman <mpe@ellerman.id.au>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-04-10 14:29:41 +02:00
Arnaldo Carvalho de Melo
466806997a perf units: Fix insufficient array space
[ Upstream commit cf67629f7f637fb988228abdb3aae46d0c1748fe ]

No need to specify the array size, let the compiler figure that out.

This addresses this compiler warning that was noticed while build
testing on fedora rawhide:

  31    15.81 fedora:rawhide                : FAIL gcc version 15.0.1 20250225 (Red Hat 15.0.1-0) (GCC)
    util/units.c: In function 'unit_number__scnprintf':
    util/units.c:67:24: error: initializer-string for array of 'char' is too long [-Werror=unterminated-string-initialization]
       67 |         char unit[4] = "BKMG";
          |                        ^~~~~~
    cc1: all warnings being treated as errors

Fixes: 9808143ba2 ("perf tools: Add unit_number__scnprintf function")
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Link: https://lore.kernel.org/r/20250310194534.265487-3-acme@kernel.org
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-04-10 14:29:41 +02:00
Jonathan Cameron
d1696caf8b iio: accel: mma8452: Ensure error return on failure to matching oversampling ratio
[ Upstream commit df330c808182a8beab5d0f84a6cbc9cff76c61fc ]

If a match was not found, then the write_raw() callback would return
the odr index, not an error. Return -EINVAL if this occurs.
To avoid similar issues in future, introduce j, a new indexing variable
rather than using ret for this purpose.

Fixes: 79de2ee469 ("iio: accel: mma8452: claim direct mode during write raw")
Reviewed-by: David Lechner <dlechner@baylibre.com>
Link: https://patch.msgid.link/20250217140135.896574-2-jic23@kernel.org
Signed-off-by: Jonathan Cameron <Jonathan.Cameron@huawei.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-04-10 14:29:41 +02:00
Ilkka Koskinen
61c6dc3b55 coresight: catu: Fix number of pages while using 64k pages
[ Upstream commit 0e14e062f5ff98aa15264dfa87c5f5e924028561 ]

Trying to record a trace on kernel with 64k pages resulted in -ENOMEM.
This happens due to a bug in calculating the number of table pages, which
returns zero. Fix the issue by rounding up.

$ perf record --kcore -e cs_etm/@tmc_etr55,cycacc,branch_broadcast/k --per-thread taskset --cpu-list 1 dd if=/dev/zero of=/dev/null
failed to mmap with 12 (Cannot allocate memory)

Fixes: 8ed536b1e2 ("coresight: catu: Add support for scatter gather tables")
Signed-off-by: Ilkka Koskinen <ilkka@os.amperecomputing.com>
Signed-off-by: Suzuki K Poulose <suzuki.poulose@arm.com>
Link: https://lore.kernel.org/r/20250109215348.5483-1-ilkka@os.amperecomputing.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-04-10 14:29:41 +02:00
Qasim Ijaz
99c737ec34 isofs: fix KMSAN uninit-value bug in do_isofs_readdir()
[ Upstream commit 81a82e8f33880793029cd6f8a766fb13b737e6a7 ]

In do_isofs_readdir() when assigning the variable
"struct iso_directory_record *de" the b_data field of the buffer_head
is accessed and an offset is added to it, the size of b_data is 2048
and the offset size is 2047, meaning
"de = (struct iso_directory_record *) (bh->b_data + offset);"
yields the final byte of the 2048 sized b_data block.

The first byte of the directory record (de_len) is then read and
found to be 31, meaning the directory record size is 31 bytes long.
The directory record is defined by the structure:

	struct iso_directory_record {
		__u8 length;                     // 1 byte
		__u8 ext_attr_length;            // 1 byte
		__u8 extent[8];                  // 8 bytes
		__u8 size[8];                    // 8 bytes
		__u8 date[7];                    // 7 bytes
		__u8 flags;                      // 1 byte
		__u8 file_unit_size;             // 1 byte
		__u8 interleave;                 // 1 byte
		__u8 volume_sequence_number[4];  // 4 bytes
		__u8 name_len;                   // 1 byte
		char name[];                     // variable size
	} __attribute__((packed));

The fixed portion of this structure occupies 33 bytes. Therefore, a
valid directory record must be at least 33 bytes long
(even without considering the variable-length name field).
Since de_len is only 31, it is insufficient to contain
the complete fixed header.

The code later hits the following sanity check that
compares de_len against the sum of de->name_len and
sizeof(struct iso_directory_record):

	if (de_len < de->name_len[0] + sizeof(struct iso_directory_record)) {
		...
	}

Since the fixed portion of the structure is
33 bytes (up to and including name_len member),
a valid record should have de_len of at least 33 bytes;
here, however, de_len is too short, and the field de->name_len
(located at offset 32) is accessed even though it lies beyond
the available 31 bytes.

This access on the corrupted isofs data triggers a KASAN uninitialized
memory warning. The fix would be to first verify that de_len is at least
sizeof(struct iso_directory_record) before accessing any
fields like de->name_len.

Reported-by: syzbot <syzbot+812641c6c3d7586a1613@syzkaller.appspotmail.com>
Tested-by: syzbot <syzbot+812641c6c3d7586a1613@syzkaller.appspotmail.com>
Closes: https://syzkaller.appspot.com/bug?extid=812641c6c3d7586a1613
Fixes: 2deb1acc65 ("isofs: fix access to unallocated memory when reading corrupted filesystem")
Signed-off-by: Qasim Ijaz <qasdev00@gmail.com>
Signed-off-by: Jan Kara <jack@suse.cz>
Link: https://patch.msgid.link/20250211195900.42406-1-qasdev00@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-04-10 14:29:41 +02:00
Jann Horn
85a17b9ab3 x86/dumpstack: Fix inaccurate unwinding from exception stacks due to misplaced assignment
[ Upstream commit 2c118f50d7fd4d9aefc4533a26f83338b2906b7a ]

Commit:

  2e4be0d011f2 ("x86/show_trace_log_lvl: Ensure stack pointer is aligned, again")

was intended to ensure alignment of the stack pointer; but it also moved
the initialization of the "stack" variable down into the loop header.

This was likely intended as a no-op cleanup, since the commit
message does not mention it; however, this caused a behavioral change
because the value of "regs" is different between the two places.

Originally, get_stack_pointer() used the regs provided by the caller; after
that commit, get_stack_pointer() instead uses the regs at the top of the
stack frame the unwinder is looking at. Often, there are no such regs at
all, and "regs" is NULL, causing get_stack_pointer() to fall back to the
task's current stack pointer, which is not what we want here, but probably
happens to mostly work. Other times, the original regs will point to
another regs frame - in that case, the linear guess unwind logic in
show_trace_log_lvl() will start unwinding too far up the stack, causing the
first frame found by the proper unwinder to never be visited, resulting in
a stack trace consisting purely of guess lines.

Fix it by moving the "stack = " assignment back where it belongs.

Fixes: 2e4be0d011f2 ("x86/show_trace_log_lvl: Ensure stack pointer is aligned, again")
Signed-off-by: Jann Horn <jannh@google.com>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Link: https://lore.kernel.org/r/20250325-2025-03-unwind-fixes-v1-2-acd774364768@google.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-04-10 14:29:41 +02:00
Nikita Zhandarovich
2bf98cc76b mfd: sm501: Switch to BIT() to mitigate integer overflows
[ Upstream commit 2d8cb9ffe18c2f1e5bd07a19cbce85b26c1d0cf0 ]

If offset end up being high enough, right hand expression in functions
like sm501_gpio_set() shifted left for that number of bits, may
not fit in int type.

Just in case, fix that by using BIT() both as an option safe from
overflow issues and to make this step look similar to other gpio
drivers.

Found by Linux Verification Center (linuxtesting.org) with static
analysis tool SVACE.

Fixes: f61be273d3 ("sm501: add gpiolib support")
Signed-off-by: Nikita Zhandarovich <n.zhandarovich@fintech.ru>
Link: https://lore.kernel.org/r/20250115171206.20308-1-n.zhandarovich@fintech.ru
Signed-off-by: Lee Jones <lee@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-04-10 14:29:41 +02:00
Patrisious Haddad
3b97d77049 RDMA/mlx5: Fix mlx5_poll_one() cur_qp update flow
[ Upstream commit 5ed3b0cb3f827072e93b4c5b6e2b8106fd7cccbd ]

When cur_qp isn't NULL, in order to avoid fetching the QP from
the radix tree again we check if the next cqe QP is identical to
the one we already have.

The bug however is that we are checking if the QP is identical by
checking the QP number inside the CQE against the QP number inside the
mlx5_ib_qp, but that's wrong since the QP number from the CQE is from
FW so it should be matched against mlx5_core_qp which is our FW QP
number.

Otherwise we could use the wrong QP when handling a CQE which could
cause the kernel trace below.

This issue is mainly noticeable over QPs 0 & 1, since for now they are
the only QPs in our driver whereas the QP number inside mlx5_ib_qp
doesn't match the QP number inside mlx5_core_qp.

BUG: kernel NULL pointer dereference, address: 0000000000000012
 #PF: supervisor read access in kernel mode
 #PF: error_code(0x0000) - not-present page
 PGD 0 P4D 0
 Oops: Oops: 0000 [#1] SMP
 CPU: 0 UID: 0 PID: 7927 Comm: kworker/u62:1 Not tainted 6.14.0-rc3+ #189
 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014
 Workqueue: ib-comp-unb-wq ib_cq_poll_work [ib_core]
 RIP: 0010:mlx5_ib_poll_cq+0x4c7/0xd90 [mlx5_ib]
 Code: 03 00 00 8d 58 ff 21 cb 66 39 d3 74 39 48 c7 c7 3c 89 6e a0 0f b7 db e8 b7 d2 b3 e0 49 8b 86 60 03 00 00 48 c7 c7 4a 89 6e a0 <0f> b7 5c 98 02 e8 9f d2 b3 e0 41 0f b7 86 78 03 00 00 83 e8 01 21
 RSP: 0018:ffff88810511bd60 EFLAGS: 00010046
 RAX: 0000000000000010 RBX: 0000000000000000 RCX: 0000000000000000
 RDX: 0000000000000000 RSI: ffff88885fa1b3c0 RDI: ffffffffa06e894a
 RBP: 00000000000000b0 R08: 0000000000000000 R09: ffff88810511bc10
 R10: 0000000000000001 R11: 0000000000000001 R12: ffff88810d593000
 R13: ffff88810e579108 R14: ffff888105146000 R15: 00000000000000b0
 FS:  0000000000000000(0000) GS:ffff88885fa00000(0000) knlGS:0000000000000000
 CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
 CR2: 0000000000000012 CR3: 00000001077e6001 CR4: 0000000000370eb0
 Call Trace:
  <TASK>
  ? __die+0x20/0x60
  ? page_fault_oops+0x150/0x3e0
  ? exc_page_fault+0x74/0x130
  ? asm_exc_page_fault+0x22/0x30
  ? mlx5_ib_poll_cq+0x4c7/0xd90 [mlx5_ib]
  __ib_process_cq+0x5a/0x150 [ib_core]
  ib_cq_poll_work+0x31/0x90 [ib_core]
  process_one_work+0x169/0x320
  worker_thread+0x288/0x3a0
  ? work_busy+0xb0/0xb0
  kthread+0xd7/0x1f0
  ? kthreads_online_cpu+0x130/0x130
  ? kthreads_online_cpu+0x130/0x130
  ret_from_fork+0x2d/0x50
  ? kthreads_online_cpu+0x130/0x130
  ret_from_fork_asm+0x11/0x20
  </TASK>

Fixes: e126ba97db ("mlx5: Add driver for Mellanox Connect-IB adapters")
Signed-off-by: Patrisious Haddad <phaddad@nvidia.com>
Reviewed-by: Edward Srouji <edwards@nvidia.com>
Link: https://patch.msgid.link/4ada09d41f1e36db62c44a9b25c209ea5f054316.1741875692.git.leon@kernel.org
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-04-10 14:29:41 +02:00
Artur Weber
a4be0b575a power: supply: max77693: Fix wrong conversion of charge input threshold value
[ Upstream commit 30cc7b0d0e9341d419eb7da15fb5c22406dbe499 ]

The charge input threshold voltage register on the MAX77693 PMIC accepts
four values: 0x0 for 4.3v, 0x1 for 4.7v, 0x2 for 4.8v and 0x3 for 4.9v.
Due to an oversight, the driver calculated the values for 4.7v and above
starting from 0x0, rather than from 0x1 ([(4700000 - 4700000) / 100000]
gives 0).

Add 1 to the calculation to ensure that 4.7v is converted to a register
value of 0x1 and that the other two voltages are converted correctly as
well.

Fixes: 87c2d90678 ("power: max77693: Add charger driver for Maxim 77693")
Signed-off-by: Artur Weber <aweber.kernel@gmail.com>
Reviewed-by: Krzysztof Kozlowski <krzysztof.kozlowski@linaro.org>
Link: https://lore.kernel.org/r/20250316-max77693-charger-input-threshold-fix-v1-1-2b037d0ac722@gmail.com
Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-04-10 14:29:41 +02:00
Jann Horn
b26152f504 x86/entry: Fix ORC unwinder for PUSH_REGS with save_ret=1
[ Upstream commit 57e2428f8df8263275344566e02c277648a4b7f1 ]

PUSH_REGS with save_ret=1 is used by interrupt entry helper functions that
initially start with a UNWIND_HINT_FUNC ORC state.

However, save_ret=1 means that we clobber the helper function's return
address (and then later restore the return address further down on the
stack); after that point, the only thing on the stack we can unwind through
is the IRET frame, so use UNWIND_HINT_IRET_REGS until we have a full
pt_regs frame.

( An alternate approach would be to move the pt_regs->di overwrite down
  such that it is the final step of pt_regs setup; but I don't want to
  rearrange entry code just to make unwinding a tiny bit more elegant. )

Fixes: 9e809d15d6 ("x86/entry: Reduce the code footprint of the 'idtentry' macro")
Signed-off-by: Jann Horn <jannh@google.com>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Cc: Andy Lutomirski <luto@kernel.org>
Cc: Brian Gerst <brgerst@gmail.com>
Cc: Juergen Gross <jgross@suse.com>
Cc: H. Peter Anvin <hpa@zytor.com>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Kees Cook <keescook@chromium.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Josh Poimboeuf <jpoimboe@redhat.com>
Link: https://lore.kernel.org/r/20250325-2025-03-unwind-fixes-v1-1-acd774364768@google.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-04-10 14:29:41 +02:00