Commit graph

903,547 commits

Author SHA1 Message Date
Greg Kroah-Hartman
be024bb2cd Revert "media: ttpci: fix two memleaks in budget_av_attach"
This reverts commit af37aed049 which is
commit d0b07f712bf61e1a3cf23c87c663791c42e50837 upstream.

It breaks the Android kernel abi and can be brought back in the future
in an abi-safe way if it is really needed.

Bug: 161946584
Change-Id: Iabd4008cdfded1c0447ac5a1d3dd83a2f0efbb09
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-04-17 16:48:45 +00:00
Greg Kroah-Hartman
d873f54a70 Revert "net: ip_tunnel: make sure to pull inner header in ip_tunnel_rcv()"
This reverts commit ec6bb01e02 which is
commit b0ec2abf98267f14d032102551581c833b0659d3 upstream.

It breaks the Android kernel abi and can be brought back in the future
in an abi-safe way if it is really needed.

Bug: 161946584
Change-Id: I8848ef10b837f2943ad2e56b56fd64d759558a81
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-04-17 16:48:43 +00:00
Greg Kroah-Hartman
960240ce53 Merge 5.4.273 into android11-5.4-lts
Changes in 5.4.273
	io_uring/unix: drop usage of io_uring socket
	io_uring: drop any code related to SCM_RIGHTS
	selftests: tls: use exact comparison in recv_partial
	ASoC: rt5645: Make LattePanda board DMI match more precise
	x86/xen: Add some null pointer checking to smp.c
	MIPS: Clear Cause.BD in instruction_pointer_set
	HID: multitouch: Add required quirk for Synaptics 0xcddc device
	RDMA/mlx5: Relax DEVX access upon modify commands
	net/iucv: fix the allocation size of iucv_path_table array
	parisc/ftrace: add missing CONFIG_DYNAMIC_FTRACE check
	block: sed-opal: handle empty atoms when parsing response
	dm-verity, dm-crypt: align "struct bvec_iter" correctly
	btrfs: fix data race at btrfs_use_block_rsv() when accessing block reserve
	scsi: mpt3sas: Prevent sending diag_reset when the controller is ready
	Bluetooth: rfcomm: Fix null-ptr-deref in rfcomm_check_security
	firewire: core: use long bus reset on gap count error
	ASoC: Intel: bytcr_rt5640: Add an extra entry for the Chuwi Vi8 tablet
	Input: gpio_keys_polled - suppress deferred probe error for gpio
	ASoC: wm8962: Enable oscillator if selecting WM8962_FLL_OSC
	ASoC: wm8962: Enable both SPKOUTR_ENA and SPKOUTL_ENA in mono mode
	ASoC: wm8962: Fix up incorrect error message in wm8962_set_fll
	do_sys_name_to_handle(): use kzalloc() to fix kernel-infoleak
	nbd: null check for nla_nest_start
	fs/select: rework stack allocation hack for clang
	aoe: fix the potential use-after-free problem in aoecmd_cfg_pkts
	timekeeping: Fix cross-timestamp interpolation on counter wrap
	timekeeping: Fix cross-timestamp interpolation corner case decision
	timekeeping: Fix cross-timestamp interpolation for non-x86
	wifi: ath10k: fix NULL pointer dereference in ath10k_wmi_tlv_op_pull_mgmt_tx_compl_ev()
	b43: dma: Fix use true/false for bool type variable
	wifi: b43: Stop/wake correct queue in DMA Tx path when QoS is disabled
	wifi: b43: Stop/wake correct queue in PIO Tx path when QoS is disabled
	b43: main: Fix use true/false for bool type
	wifi: b43: Stop correct queue in DMA worker when QoS is disabled
	wifi: b43: Disable QoS for bcm4331
	wifi: wilc1000: fix declarations ordering
	wifi: wilc1000: fix RCU usage in connect path
	wifi: mwifiex: debugfs: Drop unnecessary error check for debugfs_create_dir()
	sock_diag: annotate data-races around sock_diag_handlers[family]
	af_unix: Annotate data-race of gc_in_progress in wait_for_unix_gc().
	net: blackhole_dev: fix build warning for ethh set but not used
	wifi: libertas: fix some memleaks in lbs_allocate_cmd_buffer()
	arm64: dts: mediatek: mt7622: add missing "device_type" to memory nodes
	bpf: Add typecast to bpf helpers to help BTF generation
	bpf: Factor out bpf_spin_lock into helpers.
	bpf: Mark bpf_spin_{lock,unlock}() helpers with notrace correctly
	arm64: dts: qcom: db820c: Move non-soc entries out of /soc
	arm64: dts: qcom: msm8996: Use node references in db820c
	arm64: dts: qcom: msm8996: Move regulator consumers to db820c
	arm64: dts: qcom: msm8996: Pad addresses
	ACPI: processor_idle: Fix memory leak in acpi_processor_power_exit()
	bus: tegra-aconnect: Update dependency to ARCH_TEGRA
	iommu/amd: Mark interrupt as managed
	wifi: brcmsmac: avoid function pointer casts
	net: ena: cosmetic: fix line break issues
	net: ena: Remove ena_select_queue
	ARM: dts: arm: realview: Fix development chip ROM compatible value
	ARM: dts: imx6dl-yapp4: Move phy reset into switch node
	ARM: dts: imx6dl-yapp4: Fix typo in the QCA switch register address
	ARM: dts: imx6dl-yapp4: Move the internal switch PHYs under the switch node
	ACPI: scan: Fix device check notification handling
	x86, relocs: Ignore relocations in .notes section
	SUNRPC: fix some memleaks in gssx_dec_option_array
	mmc: wmt-sdmmc: remove an incorrect release_mem_region() call in the .remove function
	igb: move PEROUT and EXTTS isr logic to separate functions
	igb: Fix missing time sync events
	Bluetooth: Remove superfluous call to hci_conn_check_pending()
	Bluetooth: hci_core: Fix possible buffer overflow
	sr9800: Add check for usbnet_get_endpoints
	bpf: Fix hashtab overflow check on 32-bit arches
	bpf: Fix stackmap overflow check on 32-bit arches
	ipv6: fib6_rules: flush route cache when rule is changed
	net: ip_tunnel: make sure to pull inner header in ip_tunnel_rcv()
	net: hns3: fix port duplex configure error in IMP reset
	tcp: fix incorrect parameter validation in the do_tcp_getsockopt() function
	l2tp: fix incorrect parameter validation in the pppol2tp_getsockopt() function
	udp: fix incorrect parameter validation in the udp_lib_getsockopt() function
	net: kcm: fix incorrect parameter validation in the kcm_getsockopt) function
	net/x25: fix incorrect parameter validation in the x25_getsockopt() function
	nfp: flower: handle acti_netdevs allocation failure
	dm raid: fix false positive for requeue needed during reshape
	dm: call the resume method on internal suspend
	drm/tegra: dsi: Add missing check for of_find_device_by_node
	gpu: host1x: mipi: Update tegra_mipi_request() to be node based
	drm/tegra: dsi: Make use of the helper function dev_err_probe()
	drm/tegra: dsi: Fix some error handling paths in tegra_dsi_probe()
	drm/tegra: dsi: Fix missing pm_runtime_disable() in the error handling path of tegra_dsi_probe()
	drm/tegra: output: Fix missing i2c_put_adapter() in the error handling paths of tegra_output_probe()
	drm/rockchip: inno_hdmi: Fix video timing
	drm: Don't treat 0 as -1 in drm_fixp2int_ceil
	drm/rockchip: lvds: do not overwrite error code
	dmaengine: tegra210-adma: Update dependency to ARCH_TEGRA
	media: tc358743: register v4l2 async device only after successful setup
	PCI/DPC: Print all TLP Prefixes, not just the first
	perf record: Fix possible incorrect free in record__switch_output()
	drm/amd/display: Fix potential NULL pointer dereferences in 'dcn10_set_output_transfer_func()'
	perf evsel: Fix duplicate initialization of data->id in evsel__parse_sample()
	media: em28xx: annotate unchecked call to media_device_register()
	media: v4l2-tpg: fix some memleaks in tpg_alloc
	media: v4l2-mem2mem: fix a memleak in v4l2_m2m_register_entity
	media: edia: dvbdev: fix a use-after-free
	clk: qcom: reset: Allow specifying custom reset delay
	clk: qcom: reset: support resetting multiple bits
	clk: qcom: reset: Commonize the de/assert functions
	clk: qcom: reset: Ensure write completion on reset de/assertion
	quota: simplify drop_dquot_ref()
	quota: Fix potential NULL pointer dereference
	quota: Fix rcu annotations of inode dquot pointers
	PCI: switchtec: Fix an error handling path in switchtec_pci_probe()
	perf thread_map: Free strlist on normal path in thread_map__new_by_tid_str()
	drm/radeon/ni: Fix wrong firmware size logging in ni_init_microcode()
	ALSA: seq: fix function cast warnings
	perf stat: Avoid metric-only segv
	media: imx: csc/scaler: fix v4l2_ctrl_handler memory leak
	media: go7007: add check of return value of go7007_read_addr()
	media: pvrusb2: remove redundant NULL check
	media: pvrusb2: fix pvr2_stream_callback casts
	clk: qcom: dispcc-sdm845: Adjust internal GDSC wait times
	drm/mediatek: dsi: Fix DSI RGB666 formats and definitions
	PCI: Mark 3ware-9650SE Root Port Extended Tags as broken
	clk: hisilicon: hi3519: Release the correct number of gates in hi3519_clk_unregister()
	drm/tegra: put drm_gem_object ref on error in tegra_fb_create
	mfd: syscon: Call of_node_put() only when of_parse_phandle() takes a ref
	mfd: altera-sysmgr: Call of_node_put() only when of_parse_phandle() takes a ref
	crypto: arm/sha - fix function cast warnings
	mtd: maps: physmap-core: fix flash size larger than 32-bit
	mtd: rawnand: lpc32xx_mlc: fix irq handler prototype
	ASoC: meson: axg-tdm-interface: fix mclk setup without mclk-fs
	drm/amdgpu: Fix missing break in ATOM_ARG_IMM Case of atom_get_src_int()
	media: pvrusb2: fix uaf in pvr2_context_set_notify
	media: dvb-frontends: avoid stack overflow warnings with clang
	media: go7007: fix a memleak in go7007_load_encoder
	media: v4l2-core: correctly validate video and metadata ioctls
	media: rename VFL_TYPE_GRABBER to _VIDEO
	media: media/pci: rename VFL_TYPE_GRABBER to _VIDEO
	media: ttpci: fix two memleaks in budget_av_attach
	drm/mediatek: Fix a null pointer crash in mtk_drm_crtc_finish_page_flip
	powerpc/hv-gpci: Fix the H_GET_PERF_COUNTER_INFO hcall return value checks
	drm/msm/dpu: add division of drm_display_mode's hskew parameter
	powerpc/embedded6xx: Fix no previous prototype for avr_uart_send() etc.
	backlight: lm3630a: Initialize backlight_properties on init
	backlight: lm3630a: Don't set bl->props.brightness in get_brightness
	backlight: da9052: Fully initialize backlight_properties during probe
	backlight: lm3639: Fully initialize backlight_properties during probe
	backlight: lp8788: Fully initialize backlight_properties during probe
	sparc32: Fix section mismatch in leon_pci_grpci
	clk: Fix clk_core_get NULL dereference
	ALSA: usb-audio: Stop parsing channels bits when all channels are found.
	scsi: csiostor: Avoid function pointer casts
	RDMA/device: Fix a race between mad_client and cm_client init
	scsi: bfa: Fix function pointer type mismatch for hcb_qe->cbfn
	net: sunrpc: Fix an off by one in rpc_sockaddr2uaddr()
	watchdog: stm32_iwdg: initialize default timeout
	NFS: Fix an off by one in root_nfs_cat()
	afs: Revert "afs: Hide silly-rename files from userspace"
	tty: vt: fix 20 vs 0x20 typo in EScsiignore
	serial: max310x: fix syntax error in IRQ error message
	tty: serial: samsung: fix tx_empty() to return TIOCSER_TEMT
	kconfig: fix infinite loop when expanding a macro at the end of file
	rtc: mt6397: select IRQ_DOMAIN instead of depending on it
	serial: 8250_exar: Don't remove GPIO device on suspend
	staging: greybus: fix get_channel_from_mode() failure path
	usb: gadget: net2272: Use irqflags in the call to net2272_probe_fin
	octeontx2-af: Use matching wake_up API variant in CGX command interface
	s390/vtime: fix average steal time calculation
	hsr: Fix uninit-value access in hsr_get_node()
	packet: annotate data-races around ignore_outgoing
	rds: introduce acquire/release ordering in acquire/release_in_xmit()
	hsr: Handle failures in module init
	net/bnx2x: Prevent access to a freed page in page_pool
	octeontx2-af: Use separate handlers for interrupts
	ARM: dts: sun8i-h2-plus-bananapi-m2-zero: add regulator nodes vcc-dram and vcc1v2
	netfilter: nf_tables: do not compare internal table flags on updates
	rcu: add a helper to report consolidated flavor QS
	bpf: report RCU QS in cpumap kthread
	spi: spi-mt65xx: Fix NULL pointer access in interrupt handler
	regmap: Add missing map->bus check
	Linux 5.4.273

Change-Id: I7b54c53c62f7ae93eddbd8d677f0d5de9547073e
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-04-16 15:17:08 +00:00
Greg Kroah-Hartman
f509fa9b09 Revert "regmap: allow to define reg_update_bits for no bus configuration"
This reverts commit 758c6799da which is
commit 02d6fdecb9c38de19065f6bed8d5214556fd061d upstream.

It breaks the Android kernel abi and can be brought back in the future
in an abi-safe way if it is really needed.

Bug: 161946584
Change-Id: I4a8c202a4ad8b3640b02d417a12c4a8d2d2d62e1
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-04-16 10:04:00 +00:00
Greg Kroah-Hartman
012b5eceed Revert "regmap: Add bulk read/write callbacks into regmap_config"
This reverts commit b96b017919 which is
commit d77e745613680c54708470402e2b623dcd769681 upstream.

It breaks the Android kernel abi and can be brought back in the future
in an abi-safe way if it is really needed.

Bug: 161946584
Change-Id: Icf14fb2d16a8460df4ef8a74e221d4526faa1f90
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-04-16 10:04:00 +00:00
Greg Kroah-Hartman
0efa1aa851 Revert "serial: max310x: fix IO data corruption in batched operations"
This reverts commit 59b3583da1 which is
commit 3f42b142ea1171967e40e10e4b0241c0d6d28d41 upstream.

It breaks the Android kernel abi and can be brought back in the future
in an abi-safe way if it is really needed.

Bug: 161946584
Change-Id: I176b89e22005da00d9208b6e5ff2898e6b5ac9ee
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-04-16 10:04:00 +00:00
Greg Kroah-Hartman
43bbe91c9f Revert "geneve: make sure to pull inner header in geneve_rx()"
This reverts commit 59d2a40769 which is
commit 1ca1ba465e55b9460e4e75dec9fff31e708fec74 upstream.

It breaks the Android kernel abi and can be brought back in the future
in an abi-safe way if it is really needed.

Bug: 161946584
Change-Id: I2b2aff69a954b1ed5f1218aa043be79b1cac0bb0
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-04-16 08:16:22 +00:00
Greg Kroah-Hartman
ee2f1c68f1 Merge 5.4.272 into android11-5.4-lts
Changes in 5.4.272
	lan78xx: Fix white space and style issues
	lan78xx: Add missing return code checks
	lan78xx: Fix partial packet errors on suspend/resume
	lan78xx: Fix race conditions in suspend/resume handling
	net: lan78xx: fix runtime PM count underflow on link stop
	ixgbe: {dis, en}able irqs in ixgbe_txrx_ring_{dis, en}able
	geneve: make sure to pull inner header in geneve_rx()
	net: ice: Fix potential NULL pointer dereference in ice_bridge_setlink()
	net/ipv6: avoid possible UAF in ip6_route_mpath_notify()
	net/rds: fix WARNING in rds_conn_connect_if_down
	netfilter: nft_ct: fix l3num expectations with inet pseudo family
	netfilter: nf_conntrack_h323: Add protection for bmp length out of range
	netrom: Fix a data-race around sysctl_netrom_default_path_quality
	netrom: Fix a data-race around sysctl_netrom_obsolescence_count_initialiser
	netrom: Fix data-races around sysctl_netrom_network_ttl_initialiser
	netrom: Fix a data-race around sysctl_netrom_transport_timeout
	netrom: Fix a data-race around sysctl_netrom_transport_maximum_tries
	netrom: Fix a data-race around sysctl_netrom_transport_acknowledge_delay
	netrom: Fix a data-race around sysctl_netrom_transport_busy_delay
	netrom: Fix a data-race around sysctl_netrom_transport_requested_window_size
	netrom: Fix a data-race around sysctl_netrom_transport_no_activity_timeout
	netrom: Fix a data-race around sysctl_netrom_routing_control
	netrom: Fix a data-race around sysctl_netrom_link_fails_count
	netrom: Fix data-races around sysctl_net_busy_read
	selftests: mm: fix map_hugetlb failure on 64K page size systems
	um: allow not setting extra rpaths in the linux binary
	serial: max310x: Use devm_clk_get_optional() to get the input clock
	serial: max310x: Try to get crystal clock rate from property
	serial: max310x: fail probe if clock crystal is unstable
	serial: max310x: Make use of device properties
	serial: max310x: use regmap methods for SPI batch operations
	serial: max310x: use a separate regmap for each port
	serial: max310x: prevent infinite while() loop in port startup
	Input: i8042 - fix strange behavior of touchpad on Clevo NS70PU
	hv_netvsc: Make netvsc/VF binding check both MAC and serial number
	hv_netvsc: use netif_is_bond_master() instead of open code
	hv_netvsc: Register VF in netvsc_probe if NET_DEVICE_REGISTER missed
	y2038: rusage: use __kernel_old_timeval
	getrusage: add the "signal_struct *sig" local variable
	getrusage: move thread_group_cputime_adjusted() outside of lock_task_sighand()
	getrusage: use __for_each_thread()
	getrusage: use sig->stats_lock rather than lock_task_sighand()
	serial: max310x: Unprepare and disable clock in error path
	regmap: allow to define reg_update_bits for no bus configuration
	regmap: Add bulk read/write callbacks into regmap_config
	serial: max310x: make accessing revision id interface-agnostic
	serial: max310x: implement I2C support
	serial: max310x: fix IO data corruption in batched operations
	arm64: dts: qcom: add PDC interrupt controller for SDM845
	arm64: dts: qcom: sdm845: fix USB DP/DM HS PHY interrupts
	Linux 5.4.272

Change-Id: Ia3f453dd3f080776d3fdd46b1ea58c6554a70fd6
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-04-05 12:37:33 +00:00
Greg Kroah-Hartman
79ed7de671 Merge branch 'android11-5.4' into branch 'android11-5.4-lts'
This brings it up to date with recent changes.  Included in here are the
following commits:

* 7570ec5696 Merge tag 'android11-5.4.268_r00' into android11-5.4
* b558f0cc4d BACKPORT: f2fs: expose # of overprivision segments
* ffb0cc5261 ANDROID: GKI: Update symbol list for Zebra
* d24801ee88 ANDROID: GKI: Update symbol list for Zebra
* 26423f6f2f UPSTREAM: usb: raw-gadget: properly handle interrupted requests
* 1306a39bd6 UPSTREAM: net: prevent skb corruption on frag list segmentation
* 502693befb UPSTREAM: netfilter: nft_set_rbtree: skip end interval element from gc

ABI updated with the following changes based on what happened in the
non-LTS branch:

'struct usb_role_switch at class.c:19:1' changed:
  type size hasn't changed
  1 data member insertion:
    'bool registered', at offset 7648 (in bits) at class.c:23:1
  15 impacted interfaces

Change-Id: I39c39d09a51f1995e938ad12a77bc292d78f310d
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-03-28 14:08:53 +00:00
Greg Kroah-Hartman
7570ec5696 Merge tag 'android11-5.4.268_r00' into android11-5.4
This merges up to the 5.4.268 LTS release into the android11-5.4 branch.
included in here are the following commits:

* 8eb6062606 ANDROID: GKI: db845c: Update symbols list and ABI
*   5400c339e0 Merge "Merge branch 'android11-5.4' into branch 'android11-5.4-lts'" into android11-5.4-lts
|\
| * 16a567b6c7 Merge branch 'android11-5.4' into branch 'android11-5.4-lts'
* | c980fbd6a6 UPSTREAM: drm/msm/dsi: Enable runtime PM
* | 7c607fec96 UPSTREAM: PM: runtime: Have devm_pm_runtime_enable() handle pm_runtime_dont_use_autosuspend()
* | f9f96d9da7 UPSTREAM: PM: runtime: add devm_pm_runtime_enable helper
|/
* b70f9975af FROMGIT: clk: qcom: gcc-sdm845: Add soft dependency on rpmhpd
*   74299cb130 Merge 5.4.268 into android11-5.4-lts
|\
| * f0602893f4 Linux 5.4.268
| * 5ff9836ab0 arm64: dts: armada-3720-turris-mox: set irq type for RTC
| * 300a55a3a6 perf top: Skip side-band event setup if HAVE_LIBBPF_SUPPORT is not set
| * ea5587946a i2c: s3c24xx: fix transferring more than one message in polling mode
| * 90734f1cde i2c: s3c24xx: fix read transfers in polling mode
| * 05b6d0234a mlxsw: spectrum_acl_erp: Fix error flow of pool allocation failure
| * d5661f46c1 kdb: Fix a potential buffer overflow in kdb_local()
| * cf6260a34d kdb: Censor attempts to set PROMPT without ENABLE_MEM_READ
| * 36b6db699c ipvs: avoid stat macros calls from preemptible context
| * 4c8a827d68 netfilter: nf_tables: skip dead set elements in netlink dump
| * db9fda526c net: dsa: vsc73xx: Add null pointer check to vsc73xx_gpio_probe
| * 8efe3e8a6c net: ravb: Fix dma_addr_t truncation in error case
| * f7a153e3ac net: phy: micrel: populate .soft_reset for KSZ9131
| * 02467ab8b4 net: qualcomm: rmnet: fix global oob in rmnet_policy
| * 5b58cfcd4c s390/pci: fix max size calculation in zpci_memcpy_toio()
| * 14a7e3a0d0 PCI: keystone: Fix race condition when initializing PHYs
| * 40d171ef23 nvmet-tcp: Fix the H2C expected PDU len calculation
| * 258dccd67b serial: imx: Correct clock error message in function probe()
| * 1d8e62b556 apparmor: avoid crash when parsed profile name is empty
| * 4cd5db4fc4 perf env: Avoid recursively taking env->bpf_progs.lock
| * f19a1cb1f9 perf bpf: Decouple creating the evlist from adding the SB event
| * 739b800279 perf top: Move sb_evlist to 'struct perf_top'
| * 2d59b6ed99 perf record: Move sb_evlist to 'struct record'
| * 14a9769a76 perf env: Add perf_env__numa_node()
| * 9638beb4e1 nvmet-tcp: fix a crash in nvmet_req_complete()
| * ee5e7632e9 nvmet-tcp: Fix a kernel panic when host sends an invalid H2C PDU length
| * 887ab0a444 perf genelf: Set ELF program header addresses properly
| * ed903eeb4e software node: Let args be NULL in software_node_get_reference_args
| * dbb71ba531 acpi: property: Let args be NULL in __acpi_node_get_property_reference
| * b502fb43f7 serial: 8250: omap: Don't skip resource freeing if pm_runtime_resume_and_get() failed
| * d8003fdcc6 MIPS: Alchemy: Fix an out-of-bound access in db1550_dev_setup()
| * 93a7b8d433 MIPS: Alchemy: Fix an out-of-bound access in db1200_dev_setup()
| * fa873e9030 mips: Fix incorrect max_low_pfn adjustment
| * b419fe1180 HID: wacom: Correct behavior when processing some confidence == false touches
| * f7a92bec8e x86/kvm: Do not try to disable kvmclock if it was not enabled
| * 1d6d95aaa6 wifi: mwifiex: configure BSSID consistently when starting AP
| * 249b78dbb1 wifi: rtlwifi: Convert LNKCTL change to PCIe cap RMW accessors
| * c22b4f159b wifi: rtlwifi: Remove bogus and dangerous ASPM disable/enable code
| * b33a303588 rootfs: Fix support for rootfstype= when root= is given
| * 02bd78673b fbdev: flush deferred work in fb_deferred_io_fsync()
| * 7cfc97d1ec ALSA: oxygen: Fix right channel of capture volume mixer
| * 85f6a6590d usb: mon: Fix atomicity violation in mon_bin_vma_fault
| * 14e60d584a usb: typec: class: fix typec_altmode_put_partner to put plugs
| * 94f2aa8145 Revert "usb: typec: class: fix typec_altmode_put_partner to put plugs"
| * a05ebd5779 usb: chipidea: wait controller resume finished for wakeup irq
| * d9c8275c59 Revert "usb: dwc3: don't reset device side if dwc3 was configured as host-only"
| * 548a00780d Revert "usb: dwc3: Soft reset phy on probe for host"
| * c145217af8 usb: dwc: ep0: Update request status in dwc3_ep0_stall_restart
| * 5d5d982701 usb: phy: mxs: remove CONFIG_USB_OTG condition for mxs_phy_is_otg_host()
| * 29032c8e3e tick-sched: Fix idle and iowait sleeptime accounting vs CPU hotplug
| * 5c3d4930c7 binder: fix unused alloc->free_async_space
| * 252a2a5569 binder: fix race between mmput() and do_exit()
| * 4404c2b832 xen-netback: don't produce zero-size SKB frags
| * ee4e9c5fff Revert "ASoC: atmel: Remove system clock tree configuration for at91sam9g20ek"
| * 01fe1b7bb0 Input: atkbd - use ab83 as id when skipping the getid command
| * a53e15e592 binder: fix use-after-free in shinker's callback
| * fc1119a3c6 binder: fix async space check for 0-sized buffers
| * 1b7c039260 of: unittest: Fix of_count_phandle_with_args() expected value message
| * a0a061151a of: Fix double free in of_parse_phandle_with_args_map
| * a9de8a4f52 mmc: sdhci_omap: Fix TI SoC dependencies
| * b8bbe33544 clk: si5341: fix an error code problem in si5341_output_clk_set_rate
| * 4810cce029 watchdog: bcm2835_wdt: Fix WDIOC_SETTIMEOUT handling
| * 11a64041d9 watchdog/hpwdt: Only claim UNKNOWN NMI if from iLO
| * 0d5685c13d watchdog: set cdev owner before adding
| * 777aa44f63 drivers: clk: zynqmp: calculate closest mux rate
| * 5a572eb32f gpu/drm/radeon: fix two memleaks in radeon_vm_init
| * 8b55b06e73 drivers/amd/pm: fix a use-after-free in kv_parse_power_table
| * 06d95c99d5 drm/amd/pm: fix a double-free in si_dpm_init
| * 8ee1fb4c51 drm/amdgpu/debugfs: fix error code when smc register accessors are NULL
| * 68ec0a0211 media: dvbdev: drop refcount on error path in dvb_device_open()
| * 06a9263ac9 media: cx231xx: fix a memleak in cx231xx_init_isoc
| * 6a421928f7 drm/bridge: tc358767: Fix return value on error case
| * d46fe2e93e drm/radeon/trinity_dpm: fix a memleak in trinity_parse_power_table
| * c0769f091f drm/radeon/dpm: fix a memleak in sumo_parse_power_table
| * 5d12c5d75f drm/radeon: check the alloc_workqueue return value in radeon_crtc_init()
| * 09d59f73f4 drm/drv: propagate errors from drm_modeset_register_all()
| * 31b169a8be drm/msm/dsi: Use pm_runtime_resume_and_get to prevent refcnt leaks
| * 9170aa07cb drm/msm/mdp4: flush vblank event on disable
| * 136f919816 ASoC: cs35l34: Fix GPIO name and drop legacy include
| * 86af5d7acf ASoC: cs35l33: Fix GPIO name and drop legacy include
| * 94aa82723a drm/radeon: check return value of radeon_ring_lock()
| * bf48d89123 drm/radeon/r100: Fix integer overflow issues in r100_cs_track_check()
| * 8e5bcb781f drm/radeon/r600_cs: Fix possible int overflows in r600_cs_check_reg()
| * 5624a3c1b1 f2fs: fix to avoid dirent corruption
| * b083ec00f3 drm/bridge: Fix typo in post_disable() description
| * 47aa8fcd5e media: pvrusb2: fix use after free on context disconnection
| * f6a35c21cd RDMA/usnic: Silence uninitialized symbol smatch warnings
| * 9bb9775217 ARM: davinci: always select CONFIG_CPU_ARM926T
| * 3f15ba3dc1 ip6_tunnel: fix NEXTHDR_FRAGMENT handling in ip6_tnl_parse_tlv_enc_lim()
| * dcc9cd5ddb Bluetooth: btmtkuart: fix recv_buf() return value
| * efcfcd5f2b Bluetooth: Fix bogus check for re-auth no supported with non-ssp
| * 598c902649 netfilter: nf_tables: mark newset as dead on transaction abort
| * 8dbaaf71ff wifi: rtlwifi: rtl8192se: using calculate_bit_shift()
| * 8fa54f7532 wifi: rtlwifi: rtl8192ee: using calculate_bit_shift()
| * 4838d16666 wifi: rtlwifi: rtl8192de: using calculate_bit_shift()
| * e15fcb1945 rtlwifi: rtl8192de: make arrays static const, makes object smaller
| * ae1df4cc0a wifi: rtlwifi: rtl8192ce: using calculate_bit_shift()
| * a3a25b5d01 wifi: rtlwifi: rtl8192cu: using calculate_bit_shift()
| * 6f84a338ed wifi: rtlwifi: rtl8192c: using calculate_bit_shift()
| * ee0a81cf7e wifi: rtlwifi: rtl8188ee: phy: using calculate_bit_shift()
| * 7cbcf5fe01 wifi: rtlwifi: add calculate_bit_shift()
| * 4985e507e0 dma-mapping: clear dev->dma_mem to NULL after freeing it
| * 48614d528b virtio/vsock: fix logic which reduces credit update messages
| * 332cd73a92 selftests/net: fix grep checking for fib_nexthop_multiprefix
| * 12b91f3636 scsi: hisi_sas: Replace with standard error code return value
| * 14470da02d arm64: dts: qcom: sdm845-db845c: correct LED panic indicator
| * c23c4984ce scsi: fnic: Return error if vmalloc() failed
| * 16d21bfcb3 wifi: rtlwifi: rtl8821ae: phy: fix an undefined bitwise shift behavior
| * 4a20fa7322 rtlwifi: Use ffs in <foo>_phy_calculate_bit_shift
| * 0226926ba3 firmware: ti_sci: Fix an off-by-one in ti_sci_debugfs_create()
| * ef75f3c56b net/ncsi: Fix netlink major/minor version numbers
| * 7276fac0a6 ncsi: internal.h: Fix a spello
| * f6154d4983 ARM: dts: qcom: apq8064: correct XOADC register address
| * bd1bf5e805 wifi: libertas: stop selecting wext
| * dc843ed97d bpf, lpm: Fix check prefixlen before walking trie
| * 93c71706a1 wifi: rtw88: fix RX filter in FIF_ALLMULTI flag
| * aebe7e47c2 NFSv4.1/pnfs: Ensure we handle the error NFS4ERR_RETURNCONFLICT
| * db55dbbba5 blocklayoutdriver: Fix reference leak of pnfs_device_node
| * e0e3f4a187 crypto: scomp - fix req->dst buffer overflow
| * 77d2b18336 crypto: sahara - do not resize req->src when doing hash operations
| * 53ba86f765 crypto: sahara - fix processing hash requests with req->nbytes < sg->length
| * ba1ef4276e crypto: sahara - improve error handling in sahara_sha_process()
| * 0274697075 crypto: sahara - fix wait_for_completion_timeout() error handling
| * b588ed190b crypto: sahara - fix ahash reqsize
| * aea92cca43 crypto: virtio - Wait for tasklet to complete on device remove
| * efc8ef87ab gfs2: Fix kernel NULL pointer dereference in gfs2_rgrp_dump
| * d1fe1aede6 pstore: ram_core: fix possible overflow in persistent_ram_init_ecc()
| * 6e907574ef crypto: sahara - fix error handling in sahara_hw_descriptor_create()
| * e82d07d5c7 crypto: sahara - fix processing requests with cryptlen < sg->length
| * da43c26203 crypto: sahara - fix ahash selftest failure
| * beb815a000 crypto: sahara - remove FLAGS_NEW_KEY logic
| * 4c10928e31 crypto: af_alg - Disallow multiple in-flight AIO requests
| * ca3484d5ca crypto: ccp - fix memleak in ccp_init_dm_workarea
| * 9fffae6cc4 virtio_crypto: Introduce VIRTIO_CRYPTO_NOSPC
| * 01081d76cc crypto: virtio - don't use 'default m'
| * 830a4f073f crypto: virtio - Handle dataq logic with tasklet
| * 86a7c9ba83 selinux: Fix error priority for bind with AF_UNSPEC on PF_INET6 socket
| * 1bf4fe14e9 mtd: Fix gluebi NULL pointer dereference caused by ftl notifier
| * 6b84cb9e38 spi: sh-msiof: Enforce fixed DTDL for R-Car H3
| * 36e19f8463 calipso: fix memory leak in netlbl_calipso_add_pass()
| * 0396c1e211 netlabel: remove unused parameter in netlbl_netlink_auditinfo()
| * 7b99eafea0 net: netlabel: Fix kerneldoc warnings
| * 6c38e791bd ACPI: LPIT: Avoid u32 multiplication overflow
| * 1e3a2b9b40 ACPI: video: check for error while searching for backlight device parent
| * f5ea2cf3bb mtd: rawnand: Increment IFC_TIMEOUT_MSECS for nand controller response
| * 1e80aa25d1 powerpc/imc-pmu: Add a null pointer check in update_events_in_group()
| * 9da4a56dd3 powerpc/powernv: Add a null pointer check in opal_powercap_init()
| * e93d7cf4c1 powerpc/powernv: Add a null pointer check in opal_event_init()
| * f84c1446da powerpc/powernv: Add a null pointer check to scom_debug_init_one()
| * b0200560b6 selftests/powerpc: Fix error handling in FPU/VMX preemption tests
| * 9b5f03500b powerpc/pseries/memhp: Fix access beyond end of drmem array
| * 69c0b92f78 powerpc/pseries/memhotplug: Quieten some DLPAR operations
| * 5401b689ad powerpc/44x: select I2C for CURRITUCK
| * 245da9eebb powerpc: add crtsavres.o to always-y instead of extra-y
| * 5da3b6e719 EDAC/thunderx: Fix possible out-of-bounds string access
| * 555a2f09a6 x86/lib: Fix overflow when counting digits
| * 6ee48d7102 coresight: etm4x: Fix width of CCITMIN field
| * b00d5f7152 parport: parport_serial: Add Brainboxes device IDs and geometry
| * 760a5ab4d8 parport: parport_serial: Add Brainboxes BAR details
| * e93da893d5 uio: Fix use-after-free in uio_open
| * da488e1aad binder: fix comment on binder_alloc_new_buf() return value
| * a92b2797ca binder: fix trivial typo of binder_free_buf_locked()
| * 9774dabad7 binder: use EPOLLERR from eventpoll.h
| * 5e1eb0dfc9 ACPI: resource: Add another DMI match for the TongFang GMxXGxx
| * c5b0517500 drm/crtc: fix uninitialized variable use
| * cfc6afe930 ARM: sun9i: smp: fix return code check of of_property_match_string
| * ef7152f870 ida: Fix crash in ida_free when the bitmap is empty
| * c97996451f Input: xpad - add Razer Wolverine V2 support
| * 510a7bc368 ARC: fix spare error
| * 0fe6431622 s390/scm: fix virtual vs physical address confusion
| * 8fb5795bcf Input: i8042 - add nomux quirk for Acer P459-G2-M
| * 2c70bf9978 Input: atkbd - skip ATKBD_CMD_GETID in translated mode
| * 3d9a9c0881 reset: hisilicon: hi6220: fix Wvoid-pointer-to-enum-cast warning
| * 4f7512e779 ring-buffer: Do not record in NMI if the arch does not support cmpxchg in NMI
| * e405c22ee5 tracing: Add size check when printing trace_marker output
| * f787481af4 tracing: Have large events show up as '[LINE TOO BIG]' instead of nothing
| * d4408ffeb8 neighbour: Don't let neigh_forced_gc() disable preemption for long
| * 9cc9683aec drm/crtc: Fix uninit-value bug in drm_mode_setcrtc
| * 2f601e8696 jbd2: correct the printing of write_flags in jbd2_write_superblock()
| * 1c187cb210 clk: rockchip: rk3128: Fix HCLK_OTG gate register
| * 3f50a73fd9 drm/exynos: fix a wrong error checking
| * 8bc21ac17d drm/exynos: fix a potential error pointer dereference
| * 6eb9759328 nvme: introduce helper function to get ctrl state
| * 971c0b10c9 ASoC: da7219: Support low DC impedance headset
| * ec76b9e057 net/tg3: fix race condition in tg3_reset_task()
| * ef9fefca3f nouveau/tu102: flush all pdbs on vmm flush
| * b67005b284 ASoC: rt5650: add mutex to avoid the jack detection failure
| * 4fece6617b ASoC: cs43130: Fix incorrect frame delay configuration
| * 1bf33a67a9 ASoC: cs43130: Fix the position of const qualifier
| * 61c1e46fb8 ASoC: Intel: Skylake: mem leak in skl register function
| * 81610106fd ASoC: nau8822: Fix incorrect type in assignment and cast to restricted __be16
| * ad5a06e163 ASoC: Intel: Skylake: Fix mem leak in few functions
| * 57a95d06da ALSA: hda - Fix speaker and headset mic pin config for CHUWI CoreBook XPro
| * ebc3c8e090 pinctrl: lochnagar: Don't build on MIPS
| * 12cf91e23b f2fs: explicitly null-terminate the xattr list
* | 5826ec2af1 Revert "ipv6: make ip6_rt_gc_expire an atomic_t"
* | fa82780056 Revert "ipv6: remove max_size check inline with ipv4"
* |   bc9b1af36e Merge "Merge 5.4.267 into android11-5.4-lts" into android11-5.4-lts
|\ \
| * | ac7d08f396 Merge 5.4.267 into android11-5.4-lts
| |\|
| | * 9153fc9664 Linux 5.4.267
| | * 69ef165176 ASoC: meson: codec-glue: fix pcm format cast warning
| | * 584756c3d7 ipv6: remove max_size check inline with ipv4
| | * 66b3025202 ipv6: make ip6_rt_gc_expire an atomic_t
| | * ae424c848d net/dst: use a smaller percpu_counter batch for dst entries accounting
| | * 7b3a9c2bf3 PCI: Disable ATS for specific Intel IPU E2000 devices
| | * c6141c49bc PCI: Extract ATS disabling to a helper function
| | * 8711fa0c06 netfilter: nf_tables: Reject tables of unsupported family
| | * c67bf30baf net: tls, update curr on splice as well
| | * c2d9b43855 ath10k: Get rid of "per_ce_irq" hw param
| | * d15f869cb3 ath10k: Keep track of which interrupts fired, don't poll them
| | * 696b992edc ath10k: Add interrupt summary based CE processing
| | * 366df9ecbc ath10k: Wait until copy complete is actually done before completing
| | * c4541e3980 mmc: sdhci-sprd: Fix eMMC init failure after hw reset
| | * a9c9ffcd21 mmc: core: Cancel delayed work before releasing host
| | * bfc3720ca8 mmc: rpmb: fixes pause retune on all RPMB partitions.
| | * 77359c4973 mm: fix unmap_mapping_range high bits shift bug
| | * 5af5e946c4 i2c: core: Fix atomic xfer check for non-preempt config
| | * d8ec24d79d firewire: ohci: suppress unexpected system reboot in AMD Ryzen machines and ASM108x/VT630x PCIe cards
| | * 85015a96bc mm/memory-failure: check the mapcount of the precise page
| | * 3d8fab93ca net: Implement missing SO_TIMESTAMPING_NEW cmsg support
| | * f7084217d9 bnxt_en: Remove mis-applied code from bnxt_cfg_ntp_filters()
| | * acfeb9039b asix: Add check for usbnet_get_endpoints
| | * 6c00721ad7 net/qla3xxx: fix potential memleak in ql_alloc_buffer_queues
| | * a4ea54c528 net/qla3xxx: switch from 'pci_' to 'dma_' API
| | * 863ca421b4 i40e: Restore VF MSI-X state during PCI reset
| | * 01c2d73ae2 ASoC: meson: g12a-tohdmitx: Fix event generation for S/PDIF mux
| | * bdc00b8c3a ASoC: meson: g12a-tohdmitx: Validate written enum values
| | * fe2d1dda1d ASoC: meson: g12a: extract codec-to-codec utils
| | * 93d80aadc0 i40e: fix use-after-free in i40e_aqc_add_filters()
| | * b40828a2ab net: Save and restore msg_namelen in sock_sendmsg
| | * 68c8fdb9f9 net: bcmgenet: Fix FCS generation for fragmented skbuffs
| | * 4c0fa624a6 ARM: sun9i: smp: Fix array-index-out-of-bounds read in sunxi_mc_smp_init
| | * c1556217ff net-timestamp: extend SOF_TIMESTAMPING_OPT_ID to HW timestamps
| | * 2cdb650848 can: raw: add support for SO_MARK
| | * 96a6d1bb28 can: raw: add support for SO_TXTIME/SCM_TXTIME
| | * b1719cbb73 net: sched: em_text: fix possible memory leak in em_text_destroy()
| | * ef4fd7518c i40e: Fix filter input checks to prevent config with invalid values
| | * 65c6ef02ff nfc: llcp_core: Hold a ref to llcp_local->dev when holding a ref to llcp_local
* | | 6ba3eed4fa ANDROID: db845c: Enable device tree overlay support
|/ /
* / 0d5ac7fe30 Merge 5.4.266 into android11-5.4-lts
|/
* 4410df7011 Linux 5.4.266
* 7d0f1fd80a block: Don't invalidate pagecache for invalid falloc modes
* a0678f5047 ring-buffer: Fix wake ups when buffer_percent is set to 100
* 508e2fdd97 smb: client: fix OOB in smbCalcSize()
* 644b956c94 usb: fotg210-hcd: delete an incorrect bounds test
* a56a19e44b x86/alternatives: Sync core before enabling interrupts
* 4111986fb9 net: rfkill: gpio: set GPIO direction
* 5c375a83d1 net: 9p: avoid freeing uninit memory in p9pdu_vreadf
* 4e7f3899fb Bluetooth: hci_event: Fix not checking if HCI_OP_INQUIRY has been sent
* a83debb523 USB: serial: option: add Quectel RM500Q R13 firmware support
* c82ba4cb44 USB: serial: option: add Foxconn T99W265 with new baseline
* 1f87ba56c4 USB: serial: option: add Quectel EG912Y module support
* a59cb26bc1 USB: serial: ftdi_sio: update Actisense PIDs constant names
* a70b1933fa wifi: cfg80211: fix certs build to not depend on file order
* e8fb002051 wifi: cfg80211: Add my certificate
* 8717fd6d0c iio: adc: ti_am335x_adc: Fix return value check of tiadc_request_dma()
* 45af72f149 iio: common: ms_sensors: ms_sensors_i2c: fix humidity conversion time table
* 4257c16c14 scsi: bnx2fc: Fix skb double free in bnx2fc_rcv()
* e1b31edfe7 Input: ipaq-micro-keys - add error handling for devm_kmemdup
* a85d6aa2b5 iio: imu: inv_mpu6050: fix an error code problem in inv_mpu6050_read_raw
* 388c90c577 interconnect: Treat xlate() returning NULL node as an error
* 04c2223344 btrfs: do not allow non subvolume root targets for snapshot
* 3230a69e66 smb: client: fix NULL deref in asn1_ber_decoder()
* 0ccb39511a ALSA: hda/hdmi: add force-connect quirk for NUC5CPYB
* 6bcf819198 ALSA: hda/hdmi: Add quirk to force pin connectivity on NUC10
* 34e6c4c6a9 pinctrl: at91-pio4: use dedicated lock class for IRQ
* 624659563e i2c: aspeed: Handle the coalesced stop conditions with the start conditions.
* 47ae524229 afs: Fix overwriting of result of DNS query
* c04b7b28c9 net: check dev->gso_max_size in gso_features_check()
* 761ee09e9f net: warn if gso_type isn't set for a GSO SKB
* eec7ef60d2 afs: Fix dynamic root lookup DNS check
* 82d64cbe48 afs: Fix the dynamic root's d_delete to always delete unused dentries
* 2b4600fb69 net: check vlan filter feature in vlan_vids_add_by_dev() and vlan_vids_del_by_dev()
* b10265532d net/rose: fix races in rose_kill_by_device()
* ed4cb8a42c ethernet: atheros: fix a memleak in atl1e_setup_ring_resources
* 3f82a6a6d7 net: sched: ife: fix potential use-after-free
* f48e3337ab net/mlx5e: Correct snprintf truncation handling for fw_version buffer used by representors
* d07ef3a870 net/mlx5: Fix fw tracer first block check
* a46bb28fdb net/mlx5: improve some comments
* 333fd10955 Revert "net/mlx5e: fix double free of encap_header"
* 7bd305f5f2 wifi: mac80211: mesh_plink: fix matches_local logic
* 76366b399a s390/vx: fix save/restore of fpu kernel context
* f40d484e16 reset: Fix crash when freeing non-existent optional resets
* 14d915ca5a ARM: OMAP2+: Fix null pointer dereference and memory leak in omap_soc_device_init
* 62ef5887dd ksmbd: fix wrong name of SMB2_CREATE_ALLOCATION_SIZE
* 35e12efde0 ALSA: hda/realtek: Enable headset on Lenovo M90 Gen5

Updates the .xml file to add the new needed symbol:

Leaf changes summary: 1 artifact changed
Changed leaf types summary: 0 leaf type changed
Removed/Changed/Added functions summary: 0 Removed, 0 Changed, 1 Added function
Removed/Changed/Added variables summary: 0 Removed, 0 Changed, 0 Added variable

1 Added function:

  [A] 'function int devm_pm_runtime_enable(device*)'

Change-Id: I1e68409087f3f833dbfcdbfc56546d982d22d10c
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-03-27 18:12:26 +00:00
Sasha Levin
24489321d0 Linux 5.4.273
Tested-by: Florian Fainelli <florian.fainelli@broadcom.com>
Tested-by: Linux Kernel Functional Testing <lkft@linaro.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:23:12 -04:00
Marek Vasut
b37f030486 regmap: Add missing map->bus check
[ Upstream commit 5c422f0b970d287efa864b8390a02face404db5d ]

The map->bus can be NULL here, add the missing NULL pointer check.

Fixes: d77e745613680 ("regmap: Add bulk read/write callbacks into regmap_config")
Reported-by: kernel test robot <lkp@intel.com>
Reported-by: Dan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: Marek Vasut <marex@denx.de>
Cc: Dan Carpenter <dan.carpenter@oracle.com>
Cc: Mark Brown <broonie@kernel.org>
To: linux-kernel@vger.kernel.org
Link: https://lore.kernel.org/r/20220509003035.225272-1-marex@denx.de
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:25 -04:00
Fei Shao
55f8ea6731 spi: spi-mt65xx: Fix NULL pointer access in interrupt handler
[ Upstream commit a20ad45008a7c82f1184dc6dee280096009ece55 ]

The TX buffer in spi_transfer can be a NULL pointer, so the interrupt
handler may end up writing to the invalid memory and cause crashes.

Add a check to trans->tx_buf before using it.

Fixes: 1ce24864bf ("spi: mediatek: Only do dma for 4-byte aligned buffers")
Signed-off-by: Fei Shao <fshao@chromium.org>
Reviewed-by: AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
Link: https://msgid.link/r/20240321070942.1587146-2-fshao@chromium.org
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:25 -04:00
Yan Zhai
59426454b8 bpf: report RCU QS in cpumap kthread
[ Upstream commit 00bf63122459e87193ee7f1bc6161c83a525569f ]

When there are heavy load, cpumap kernel threads can be busy polling
packets from redirect queues and block out RCU tasks from reaching
quiescent states. It is insufficient to just call cond_resched() in such
context. Periodically raise a consolidated RCU QS before cond_resched
fixes the problem.

Fixes: 6710e11269 ("bpf: introduce new bpf cpu map type BPF_MAP_TYPE_CPUMAP")
Reviewed-by: Jesper Dangaard Brouer <hawk@kernel.org>
Signed-off-by: Yan Zhai <yan@cloudflare.com>
Acked-by: Paul E. McKenney <paulmck@kernel.org>
Acked-by: Jesper Dangaard Brouer <hawk@kernel.org>
Link: https://lore.kernel.org/r/c17b9f1517e19d813da3ede5ed33ee18496bb5d8.1710877680.git.yan@cloudflare.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:25 -04:00
Yan Zhai
3ffe591b27 rcu: add a helper to report consolidated flavor QS
[ Upstream commit 1a77557d48cff187a169c2aec01c0dd78a5e7e50 ]

When under heavy load, network processing can run CPU-bound for many
tens of seconds. Even in preemptible kernels (non-RT kernel), this can
block RCU Tasks grace periods, which can cause trace-event removal to
take more than a minute, which is unacceptably long.

This commit therefore creates a new helper function that passes through
both RCU and RCU-Tasks quiescent states every 100 milliseconds. This
hard-coded value suffices for current workloads.

Suggested-by: Paul E. McKenney <paulmck@kernel.org>
Reviewed-by: Jesper Dangaard Brouer <hawk@kernel.org>
Signed-off-by: Yan Zhai <yan@cloudflare.com>
Reviewed-by: Paul E. McKenney <paulmck@kernel.org>
Acked-by: Jesper Dangaard Brouer <hawk@kernel.org>
Link: https://lore.kernel.org/r/90431d46ee112d2b0af04dbfe936faaca11810a5.1710877680.git.yan@cloudflare.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Stable-dep-of: 00bf63122459 ("bpf: report RCU QS in cpumap kthread")
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:25 -04:00
Pablo Neira Ayuso
2531f907d3 netfilter: nf_tables: do not compare internal table flags on updates
[ Upstream commit 4a0e7f2decbf9bd72461226f1f5f7dcc4b08f139 ]

Restore skipping transaction if table update does not modify flags.

Fixes: 179d9ba5559a ("netfilter: nf_tables: fix table flag updates")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:25 -04:00
Michael Klein
71002d9eb1 ARM: dts: sun8i-h2-plus-bananapi-m2-zero: add regulator nodes vcc-dram and vcc1v2
[ Upstream commit 23e85be1ec81647374055f731488cc9a7c013a5c ]

Add regulator nodes vcc-dram and vcc1v2 to the devicetree. These
regulators correspond to U4 and U5 in the schematics:

http://forum.banana-pi.org/t/bpi-m2-zero-schematic-diagram-public/4111

Signed-off-by: Michael Klein <michael@fossekall.de>
Signed-off-by: Maxime Ripard <maxime@cerno.tech>
Link: https://lore.kernel.org/r/20201130183841.136708-1-michael@fossekall.de
Stable-dep-of: 4a0e7f2decbf ("netfilter: nf_tables: do not compare internal table flags on updates")
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:25 -04:00
Subbaraya Sundeep
94cb17e5cf octeontx2-af: Use separate handlers for interrupts
[ Upstream commit 50e60de381c342008c0956fd762e1c26408f372c ]

For PF to AF interrupt vector and VF to AF vector same
interrupt handler is registered which is causing race condition.
When two interrupts are raised to two CPUs at same time
then two cores serve same event corrupting the data.

Fixes: 7304ac4567 ("octeontx2-af: Add mailbox IRQ and msg handlers")
Signed-off-by: Subbaraya Sundeep <sbhatta@marvell.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:25 -04:00
Thinh Tran
4f37d3a7e0 net/bnx2x: Prevent access to a freed page in page_pool
[ Upstream commit d27e2da94a42655861ca4baea30c8cd65546f25d ]

Fix race condition leading to system crash during EEH error handling

During EEH error recovery, the bnx2x driver's transmit timeout logic
could cause a race condition when handling reset tasks. The
bnx2x_tx_timeout() schedules reset tasks via bnx2x_sp_rtnl_task(),
which ultimately leads to bnx2x_nic_unload(). In bnx2x_nic_unload()
SGEs are freed using bnx2x_free_rx_sge_range(). However, this could
overlap with the EEH driver's attempt to reset the device using
bnx2x_io_slot_reset(), which also tries to free SGEs. This race
condition can result in system crashes due to accessing freed memory
locations in bnx2x_free_rx_sge()

799  static inline void bnx2x_free_rx_sge(struct bnx2x *bp,
800				struct bnx2x_fastpath *fp, u16 index)
801  {
802	struct sw_rx_page *sw_buf = &fp->rx_page_ring[index];
803     struct page *page = sw_buf->page;
....
where sw_buf was set to NULL after the call to dma_unmap_page()
by the preceding thread.

    EEH: Beginning: 'slot_reset'
    PCI 0011:01:00.0#10000: EEH: Invoking bnx2x->slot_reset()
    bnx2x: [bnx2x_io_slot_reset:14228(eth1)]IO slot reset initializing...
    bnx2x 0011:01:00.0: enabling device (0140 -> 0142)
    bnx2x: [bnx2x_io_slot_reset:14244(eth1)]IO slot reset --> driver unload
    Kernel attempted to read user page (0) - exploit attempt? (uid: 0)
    BUG: Kernel NULL pointer dereference on read at 0x00000000
    Faulting instruction address: 0xc0080000025065fc
    Oops: Kernel access of bad area, sig: 11 [#1]
    .....
    Call Trace:
    [c000000003c67a20] [c00800000250658c] bnx2x_io_slot_reset+0x204/0x610 [bnx2x] (unreliable)
    [c000000003c67af0] [c0000000000518a8] eeh_report_reset+0xb8/0xf0
    [c000000003c67b60] [c000000000052130] eeh_pe_report+0x180/0x550
    [c000000003c67c70] [c00000000005318c] eeh_handle_normal_event+0x84c/0xa60
    [c000000003c67d50] [c000000000053a84] eeh_event_handler+0xf4/0x170
    [c000000003c67da0] [c000000000194c58] kthread+0x1c8/0x1d0
    [c000000003c67e10] [c00000000000cf64] ret_from_kernel_thread+0x5c/0x64

To solve this issue, we need to verify page pool allocations before
freeing.

Fixes: 4cace675d6 ("bnx2x: Alloc 4k fragment for each rx ring buffer element")
Signed-off-by: Thinh Tran <thinhtr@linux.ibm.com>
Reviewed-by: Jiri Pirko <jiri@nvidia.com>
Link: https://lore.kernel.org/r/20240315205535.1321-1-thinhtr@linux.ibm.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:25 -04:00
Felix Maurer
69f9f55891 hsr: Handle failures in module init
[ Upstream commit 3cf28cd492308e5f63ed00b29ea03ca016264376 ]

A failure during registration of the netdev notifier was not handled at
all. A failure during netlink initialization did not unregister the netdev
notifier.

Handle failures of netdev notifier registration and netlink initialization.
Both functions should only return negative values on failure and thereby
lead to the hsr module not being loaded.

Fixes: f421436a59 ("net/hsr: Add support for the High-availability Seamless Redundancy protocol (HSRv0)")
Signed-off-by: Felix Maurer <fmaurer@redhat.com>
Reviewed-by: Shigeru Yoshida <syoshida@redhat.com>
Reviewed-by: Breno Leitao <leitao@debian.org>
Link: https://lore.kernel.org/r/3ce097c15e3f7ace98fc7fd9bcbf299f092e63d1.1710504184.git.fmaurer@redhat.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:25 -04:00
Yewon Choi
f781fb5177 rds: introduce acquire/release ordering in acquire/release_in_xmit()
[ Upstream commit 1422f28826d2a0c11e5240b3e951c9e214d8656e ]

acquire/release_in_xmit() work as bit lock in rds_send_xmit(), so they
are expected to ensure acquire/release memory ordering semantics.
However, test_and_set_bit/clear_bit() don't imply such semantics, on
top of this, following smp_mb__after_atomic() does not guarantee release
ordering (memory barrier actually should be placed before clear_bit()).

Instead, we use clear_bit_unlock/test_and_set_bit_lock() here.

Fixes: 0f4b1c7e89 ("rds: fix rds_send_xmit() serialization")
Fixes: 1f9ecd7eac ("RDS: Pass rds_conn_path to rds_send_xmit()")
Signed-off-by: Yewon Choi <woni9911@gmail.com>
Reviewed-by: Michal Kubiak <michal.kubiak@intel.com>
Link: https://lore.kernel.org/r/ZfQUxnNTO9AJmzwc@libra05
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:25 -04:00
Eric Dumazet
84c510411e packet: annotate data-races around ignore_outgoing
[ Upstream commit 6ebfad33161afacb3e1e59ed1c2feefef70f9f97 ]

ignore_outgoing is read locklessly from dev_queue_xmit_nit()
and packet_getsockopt()

Add appropriate READ_ONCE()/WRITE_ONCE() annotations.

syzbot reported:

BUG: KCSAN: data-race in dev_queue_xmit_nit / packet_setsockopt

write to 0xffff888107804542 of 1 bytes by task 22618 on cpu 0:
 packet_setsockopt+0xd83/0xfd0 net/packet/af_packet.c:4003
 do_sock_setsockopt net/socket.c:2311 [inline]
 __sys_setsockopt+0x1d8/0x250 net/socket.c:2334
 __do_sys_setsockopt net/socket.c:2343 [inline]
 __se_sys_setsockopt net/socket.c:2340 [inline]
 __x64_sys_setsockopt+0x66/0x80 net/socket.c:2340
 do_syscall_64+0xd3/0x1d0
 entry_SYSCALL_64_after_hwframe+0x6d/0x75

read to 0xffff888107804542 of 1 bytes by task 27 on cpu 1:
 dev_queue_xmit_nit+0x82/0x620 net/core/dev.c:2248
 xmit_one net/core/dev.c:3527 [inline]
 dev_hard_start_xmit+0xcc/0x3f0 net/core/dev.c:3547
 __dev_queue_xmit+0xf24/0x1dd0 net/core/dev.c:4335
 dev_queue_xmit include/linux/netdevice.h:3091 [inline]
 batadv_send_skb_packet+0x264/0x300 net/batman-adv/send.c:108
 batadv_send_broadcast_skb+0x24/0x30 net/batman-adv/send.c:127
 batadv_iv_ogm_send_to_if net/batman-adv/bat_iv_ogm.c:392 [inline]
 batadv_iv_ogm_emit net/batman-adv/bat_iv_ogm.c:420 [inline]
 batadv_iv_send_outstanding_bat_ogm_packet+0x3f0/0x4b0 net/batman-adv/bat_iv_ogm.c:1700
 process_one_work kernel/workqueue.c:3254 [inline]
 process_scheduled_works+0x465/0x990 kernel/workqueue.c:3335
 worker_thread+0x526/0x730 kernel/workqueue.c:3416
 kthread+0x1d1/0x210 kernel/kthread.c:388
 ret_from_fork+0x4b/0x60 arch/x86/kernel/process.c:147
 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:243

value changed: 0x00 -> 0x01

Reported by Kernel Concurrency Sanitizer on:
CPU: 1 PID: 27 Comm: kworker/u8:1 Tainted: G        W          6.8.0-syzkaller-08073-g480e035fc4c7 #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/29/2024
Workqueue: bat_events batadv_iv_send_outstanding_bat_ogm_packet

Fixes: fa788d986a ("packet: add sockopt to ignore outgoing packets")
Reported-by: syzbot+c669c1136495a2e7c31f@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/netdev/CANn89i+Z7MfbkBLOv=p7KZ7=K1rKHO4P1OL5LYDCtBiyqsa9oQ@mail.gmail.com/T/#t
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Willem de Bruijn <willemdebruijn.kernel@gmail.com>
Reviewed-by: Willem de Bruijn <willemb@google.com>
Reviewed-by: Jason Xing <kerneljasonxing@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:25 -04:00
Shigeru Yoshida
889ed056ea hsr: Fix uninit-value access in hsr_get_node()
[ Upstream commit ddbec99f58571301679addbc022256970ca3eac6 ]

KMSAN reported the following uninit-value access issue [1]:

=====================================================
BUG: KMSAN: uninit-value in hsr_get_node+0xa2e/0xa40 net/hsr/hsr_framereg.c:246
 hsr_get_node+0xa2e/0xa40 net/hsr/hsr_framereg.c:246
 fill_frame_info net/hsr/hsr_forward.c:577 [inline]
 hsr_forward_skb+0xe12/0x30e0 net/hsr/hsr_forward.c:615
 hsr_dev_xmit+0x1a1/0x270 net/hsr/hsr_device.c:223
 __netdev_start_xmit include/linux/netdevice.h:4940 [inline]
 netdev_start_xmit include/linux/netdevice.h:4954 [inline]
 xmit_one net/core/dev.c:3548 [inline]
 dev_hard_start_xmit+0x247/0xa10 net/core/dev.c:3564
 __dev_queue_xmit+0x33b8/0x5130 net/core/dev.c:4349
 dev_queue_xmit include/linux/netdevice.h:3134 [inline]
 packet_xmit+0x9c/0x6b0 net/packet/af_packet.c:276
 packet_snd net/packet/af_packet.c:3087 [inline]
 packet_sendmsg+0x8b1d/0x9f30 net/packet/af_packet.c:3119
 sock_sendmsg_nosec net/socket.c:730 [inline]
 __sock_sendmsg net/socket.c:745 [inline]
 __sys_sendto+0x735/0xa10 net/socket.c:2191
 __do_sys_sendto net/socket.c:2203 [inline]
 __se_sys_sendto net/socket.c:2199 [inline]
 __x64_sys_sendto+0x125/0x1c0 net/socket.c:2199
 do_syscall_x64 arch/x86/entry/common.c:52 [inline]
 do_syscall_64+0x6d/0x140 arch/x86/entry/common.c:83
 entry_SYSCALL_64_after_hwframe+0x63/0x6b

Uninit was created at:
 slab_post_alloc_hook+0x129/0xa70 mm/slab.h:768
 slab_alloc_node mm/slub.c:3478 [inline]
 kmem_cache_alloc_node+0x5e9/0xb10 mm/slub.c:3523
 kmalloc_reserve+0x13d/0x4a0 net/core/skbuff.c:560
 __alloc_skb+0x318/0x740 net/core/skbuff.c:651
 alloc_skb include/linux/skbuff.h:1286 [inline]
 alloc_skb_with_frags+0xc8/0xbd0 net/core/skbuff.c:6334
 sock_alloc_send_pskb+0xa80/0xbf0 net/core/sock.c:2787
 packet_alloc_skb net/packet/af_packet.c:2936 [inline]
 packet_snd net/packet/af_packet.c:3030 [inline]
 packet_sendmsg+0x70e8/0x9f30 net/packet/af_packet.c:3119
 sock_sendmsg_nosec net/socket.c:730 [inline]
 __sock_sendmsg net/socket.c:745 [inline]
 __sys_sendto+0x735/0xa10 net/socket.c:2191
 __do_sys_sendto net/socket.c:2203 [inline]
 __se_sys_sendto net/socket.c:2199 [inline]
 __x64_sys_sendto+0x125/0x1c0 net/socket.c:2199
 do_syscall_x64 arch/x86/entry/common.c:52 [inline]
 do_syscall_64+0x6d/0x140 arch/x86/entry/common.c:83
 entry_SYSCALL_64_after_hwframe+0x63/0x6b

CPU: 1 PID: 5033 Comm: syz-executor334 Not tainted 6.7.0-syzkaller-00562-g9f8413c4a66f #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 11/17/2023
=====================================================

If the packet type ID field in the Ethernet header is either ETH_P_PRP or
ETH_P_HSR, but it is not followed by an HSR tag, hsr_get_skb_sequence_nr()
reads an invalid value as a sequence number. This causes the above issue.

This patch fixes the issue by returning NULL if the Ethernet header is not
followed by an HSR tag.

Fixes: f266a683a4 ("net/hsr: Better frame dispatch")
Reported-and-tested-by: syzbot+2ef3a8ce8e91b5a50098@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=2ef3a8ce8e91b5a50098 [1]
Signed-off-by: Shigeru Yoshida <syoshida@redhat.com>
Link: https://lore.kernel.org/r/20240312152719.724530-1-syoshida@redhat.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:24 -04:00
Mete Durlu
48cef94b69 s390/vtime: fix average steal time calculation
[ Upstream commit 367c50f78451d3bd7ad70bc5c89f9ba6dec46ca9 ]

Current average steal timer calculation produces volatile and inflated
values. The only user of this value is KVM so far and it uses that to
decide whether or not to yield the vCPU which is seeing steal time.
KVM compares average steal timer to a threshold and if the threshold
is past then it does not allow CPU polling and yields it to host, else
it keeps the CPU by polling.
Since KVM's steal time threshold is very low by default (%10) it most
likely is not effected much by the bloated average steal timer values
because the operating region is pretty small. However there might be
new users in the future who might rely on this number. Fix average
steal timer calculation by changing the formula from:

	avg_steal_timer = avg_steal_timer / 2 + steal_timer;

to the following:

	avg_steal_timer = (avg_steal_timer + steal_timer) / 2;

This ensures that avg_steal_timer is actually a naive average of steal
timer values. It now closely follows steal timer values but of course
in a smoother manner.

Fixes: 152e9b8676 ("s390/vtime: steal time exponential moving average")
Signed-off-by: Mete Durlu <meted@linux.ibm.com>
Acked-by: Heiko Carstens <hca@linux.ibm.com>
Acked-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Signed-off-by: Heiko Carstens <hca@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:24 -04:00
Linu Cherian
305c31b970 octeontx2-af: Use matching wake_up API variant in CGX command interface
[ Upstream commit e642921dfeed1e15e73f78f2c3b6746f72b6deb2 ]

Use wake_up API instead of wake_up_interruptible, since
wait_event_timeout API is used for waiting on command completion.

Fixes: 1463f382f5 ("octeontx2-af: Add support for CGX link management")
Signed-off-by: Linu Cherian <lcherian@marvell.com>
Signed-off-by: Sunil Goutham <sgoutham@marvell.com>
Signed-off-by: Subbaraya Sundeep <sbhatta@marvell.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:24 -04:00
Colin Ian King
b63362b317 usb: gadget: net2272: Use irqflags in the call to net2272_probe_fin
[ Upstream commit 600556809f04eb3bbccd05218215dcd7b285a9a9 ]

Currently the variable irqflags is being set but is not being used,
it appears it should be used in the call to net2272_probe_fin
rather than IRQF_TRIGGER_LOW being used. Kudos to Uwe Kleine-König
for suggesting the fix.

Cleans up clang scan build warning:
drivers/usb/gadget/udc/net2272.c:2610:15: warning: variable 'irqflags'
set but not used [-Wunused-but-set-variable]

Fixes: ceb80363b2 ("USB: net2272: driver for PLX NET2272 USB device controller")
Signed-off-by: Colin Ian King <colin.i.king@gmail.com>
Acked-by: Alan Stern <stern@rowland.harvard.edu>
Link: https://lore.kernel.org/r/20240307181734.2034407-1-colin.i.king@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:24 -04:00
Dan Carpenter
254b27c4ae staging: greybus: fix get_channel_from_mode() failure path
[ Upstream commit 34164202a5827f60a203ca9acaf2d9f7d432aac8 ]

The get_channel_from_mode() function is supposed to return the channel
which matches the mode.  But it has a bug where if it doesn't find a
matching channel then it returns the last channel.  It should return
NULL instead.

Also remove an unnecessary NULL check on "channel".

Fixes: 2870b52bae ("greybus: lights: add lights implementation")
Signed-off-by: Dan Carpenter <dan.carpenter@linaro.org>
Reviewed-by: Rui Miguel Silva <rmfrfs@gmail.com>
Reviewed-by: Alex Elder <elder@linaro.org>
Link: https://lore.kernel.org/r/379c0cb4-39e0-4293-8a18-c7b1298e5420@moroto.mountain
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:24 -04:00
Andy Shevchenko
f6bf49e76f serial: 8250_exar: Don't remove GPIO device on suspend
[ Upstream commit 73b5a5c00be39e23b194bad10e1ea8bb73eee176 ]

It seems a copy&paste mistake that suspend callback removes the GPIO
device. There is no counterpart of this action, means once suspended
there is no more GPIO device available untile full unbind-bind cycle
is performed. Remove suspicious GPIO device removal in suspend.

Fixes: d0aeaa83f0 ("serial: exar: split out the exar code from 8250_pci")
Signed-off-by: Andy Shevchenko <andriy.shevchenko@linux.intel.com>
Link: https://lore.kernel.org/r/20240219150627.2101198-2-andriy.shevchenko@linux.intel.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:24 -04:00
Randy Dunlap
8dd52ab78f rtc: mt6397: select IRQ_DOMAIN instead of depending on it
[ Upstream commit 544c42f798e1651dcb04fb0395219bf0f1c2607e ]

IRQ_DOMAIN is a hidden (not user visible) symbol. Users cannot set
it directly thru "make *config", so drivers should select it instead
of depending on it if they need it.
Relying on it being set for a dependency is risky.

Consistently using "select" or "depends on" can also help reduce
Kconfig circular dependency issues.

Therefore, change the use of "depends on" for IRQ_DOMAIN to
"select" for RTC_DRV_MT6397.

Fixes: 04d3ba70a3 ("rtc: mt6397: add IRQ domain dependency")
Cc: Arnd Bergmann <arnd@arndb.de>
Cc: Eddie Huang <eddie.huang@mediatek.com>
Cc: Sean Wang <sean.wang@mediatek.com>
Cc: Matthias Brugger <matthias.bgg@gmail.com>
Cc: linux-arm-kernel@lists.infradead.org
Cc: linux-mediatek@lists.infradead.org
Cc: Alessandro Zummo <a.zummo@towertech.it>
Cc: Alexandre Belloni <alexandre.belloni@bootlin.com>
Cc: linux-rtc@vger.kernel.org
Cc: Marc Zyngier <maz@kernel.org>
Cc: Philipp Zabel <p.zabel@pengutronix.de>
Cc: Peter Rosin <peda@axentia.se>
Reviewed-by: AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
Signed-off-by: Randy Dunlap <rdunlap@infradead.org>
Link: https://lore.kernel.org/r/20240213050258.6167-1-rdunlap@infradead.org
Signed-off-by: Alexandre Belloni <alexandre.belloni@bootlin.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:24 -04:00
Masahiro Yamada
ca6279d1a1 kconfig: fix infinite loop when expanding a macro at the end of file
[ Upstream commit af8bbce92044dc58e4cc039ab94ee5d470a621f5 ]

A macro placed at the end of a file with no newline causes an infinite
loop.

[Test Kconfig]
  $(info,hello)
  \ No newline at end of file

I realized that flex-provided input() returns 0 instead of EOF when it
reaches the end of a file.

Fixes: 104daea149 ("kconfig: reference environment variables directly and remove 'option env='")
Signed-off-by: Masahiro Yamada <masahiroy@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:24 -04:00
Tudor Ambarus
a8cc354a81 tty: serial: samsung: fix tx_empty() to return TIOCSER_TEMT
[ Upstream commit 314c2b399288f0058a8c5b6683292cbde5f1531b ]

The core expects for tx_empty() either TIOCSER_TEMT when the tx is
empty or 0 otherwise. s3c24xx_serial_txempty_nofifo() might return
0x4, and at least uart_get_lsr_info() tries to clear exactly
TIOCSER_TEMT (BIT(1)). Fix tx_empty() to return TIOCSER_TEMT.

Fixes: 1da177e4c3 ("Linux-2.6.12-rc2")
Signed-off-by: Tudor Ambarus <tudor.ambarus@linaro.org>
Reviewed-by: Sam Protsenko <semen.protsenko@linaro.org>
Link: https://lore.kernel.org/r/20240119104526.1221243-2-tudor.ambarus@linaro.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:24 -04:00
Hugo Villeneuve
f1c9a0c338 serial: max310x: fix syntax error in IRQ error message
[ Upstream commit 8ede8c6f474255b2213cccd7997b993272a8e2f9 ]

Replace g with q.

Helpful when grepping thru source code or logs for
"request" keyword.

Fixes: f65444187a ("serial: New serial driver MAX310X")
Reviewed-by: Andy Shevchenko <andy.shevchenko@gmail.com>
Signed-off-by: Hugo Villeneuve <hvilleneuve@dimonoff.com>
Link: https://lore.kernel.org/r/20240118152213.2644269-6-hugo@hugovil.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:24 -04:00
Jiri Slaby (SUSE)
bd2f4df259 tty: vt: fix 20 vs 0x20 typo in EScsiignore
[ Upstream commit 0e6a92f67c8a94707f7bb27ac29e2bdf3e7c167d ]

The if (c >= 20 && c <= 0x3f) test added in commit 7a99565f87 is
wrong.  20 is DC4 in ascii and it makes no sense to consider that as the
bottom limit. Instead, it should be 0x20 as in the other test in
the commit above. This is supposed to NOT change anything as we handle
interesting 20-0x20 asciis far before this if.

So for sakeness, change to 0x20 (which is SPACE).

Signed-off-by: "Jiri Slaby (SUSE)" <jirislaby@kernel.org>
Fixes: 7a99565f87 ("vt: ignore csi sequences with intermediate characters.")
Cc: Martin Hostettler <textshell@uchuujin.de>
Link: https://lore.kernel.org/all/ZaP45QY2WEsDqoxg@neutronstar.dyndns.org/
Tested-by: Helge Deller <deller@gmx.de> # parisc STI console
Link: https://lore.kernel.org/r/20240122110401.7289-4-jirislaby@kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:24 -04:00
David Howells
854ebf45a4 afs: Revert "afs: Hide silly-rename files from userspace"
[ Upstream commit 0aec3847d044273733285dcff90afda89ad461d2 ]

This reverts commit 57e9d49c54528c49b8bffe6d99d782ea051ea534.

This undoes the hiding of .__afsXXXX silly-rename files.  The problem with
hiding them is that rm can't then manually delete them.

This also reverts commit 5f7a07646655fb4108da527565dcdc80124b14c4 ("afs: Fix
endless loop in directory parsing") as that's a bugfix for the above.

Fixes: 57e9d49c5452 ("afs: Hide silly-rename files from userspace")
Reported-by: Markus Suvanto <markus.suvanto@gmail.com>
Link: https://lists.infradead.org/pipermail/linux-afs/2024-February/008102.html
Signed-off-by: David Howells <dhowells@redhat.com>
Link: https://lore.kernel.org/r/3085695.1710328121@warthog.procyon.org.uk
Reviewed-by: Jeffrey E Altman <jaltman@auristor.com>
cc: Marc Dionne <marc.dionne@auristor.com>
cc: linux-afs@lists.infradead.org
Signed-off-by: Christian Brauner <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:24 -04:00
Christophe JAILLET
afcbba70bf NFS: Fix an off by one in root_nfs_cat()
[ Upstream commit 698ad1a538da0b6bf969cfee630b4e3a026afb87 ]

The intent is to check if 'dest' is truncated or not. So, >= should be
used instead of >, because strlcat() returns the length of 'dest' and 'src'
excluding the trailing NULL.

Fixes: 56463e50d1 ("NFS: Use super.c for NFSROOT mount option parsing")
Signed-off-by: Christophe JAILLET <christophe.jaillet@wanadoo.fr>
Reviewed-by: Benjamin Coddington <bcodding@redhat.com>
Signed-off-by: Trond Myklebust <trond.myklebust@hammerspace.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:24 -04:00
Ben Wolsieffer
bcc3ec2bdb watchdog: stm32_iwdg: initialize default timeout
[ Upstream commit dbd7c0088b7f44aa0b9276ed3449df075a7b5b54 ]

The driver never sets a default timeout value, therefore it is
initialized to zero. When CONFIG_WATCHDOG_HANDLE_BOOT_ENABLED is
enabled, the watchdog is started during probe. The kernel is supposed to
automatically ping the watchdog from this point until userspace takes
over, but this does not happen if the configured timeout is zero. A zero
timeout causes watchdog_need_worker() to return false, so the heartbeat
worker does not run and the system therefore resets soon after the
driver is probed.

This patch fixes this by setting an arbitrary non-zero default timeout.
The default could be read from the hardware instead, but I didn't see
any reason to add this complexity.

This has been tested on an STM32F746.

Fixes: 85fdc63fe256 ("drivers: watchdog: stm32_iwdg: set WDOG_HW_RUNNING at probe")
Signed-off-by: Ben Wolsieffer <ben.wolsieffer@hefring.com>
Reviewed-by: Guenter Roeck <linux@roeck-us.net>
Link: https://lore.kernel.org/r/20240228182723.12855-1-ben.wolsieffer@hefring.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Wim Van Sebroeck <wim@linux-watchdog.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:24 -04:00
Christophe JAILLET
e95eeb7f7d net: sunrpc: Fix an off by one in rpc_sockaddr2uaddr()
[ Upstream commit d6f4de70f73a106986ee315d7d512539f2f3303a ]

The intent is to check if the strings' are truncated or not. So, >= should
be used instead of >, because strlcat() and snprintf() return the length of
the output, excluding the trailing NULL.

Fixes: a02d692611 ("SUNRPC: Provide functions for managing universal addresses")
Signed-off-by: Christophe JAILLET <christophe.jaillet@wanadoo.fr>
Reviewed-by: Benjamin Coddington <bcodding@redhat.com>
Signed-off-by: Trond Myklebust <trond.myklebust@hammerspace.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:23 -04:00
Arnd Bergmann
3b8415daaa scsi: bfa: Fix function pointer type mismatch for hcb_qe->cbfn
[ Upstream commit b69600231f751304db914c63b937f7098ed2895c ]

Some callback functions used here take a boolean argument, others take a
status argument. This breaks KCFI type checking, so clang now warns about
the function pointer cast:

drivers/scsi/bfa/bfad_bsg.c:2138:29: error: cast from 'void (*)(void *, enum bfa_status)' to 'bfa_cb_cbfn_t' (aka 'void (*)(void *, enum bfa_boolean)') converts to incompatible function type [-Werror,-Wcast-function-type-strict]

Assuming the code is actually correct here and the callers always match the
argument types of the callee, rework this to replace the explicit cast with
a union of the two pointer types. This does not change the behavior of the
code, so if something is actually broken here, a larger rework may be
necessary.

Fixes: 37ea0558b8 ("[SCSI] bfa: Added support to collect and reset fcport stats")
Fixes: 3ec4f2c8bf ("[SCSI] bfa: Added support to configure QOS and collect stats.")
Reviewed-by: Kees Cook <keescook@chromium.org>
Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Link: https://lore.kernel.org/r/20240222124433.2046570-1-arnd@kernel.org
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:23 -04:00
Shifeng Li
2b38dbd7fa RDMA/device: Fix a race between mad_client and cm_client init
[ Upstream commit 7a8bccd8b29c321ac181369b42b04fecf05f98e2 ]

The mad_client will be initialized in enable_device_and_get(), while the
devices_rwsem will be downgraded to a read semaphore. There is a window
that leads to the failed initialization for cm_client, since it can not
get matched mad port from ib_mad_port_list, and the matched mad port will
be added to the list after that.

    mad_client    |                       cm_client
------------------|--------------------------------------------------------
ib_register_device|
enable_device_and_get
down_write(&devices_rwsem)
xa_set_mark(&devices, DEVICE_REGISTERED)
downgrade_write(&devices_rwsem)
                  |
                  |ib_cm_init
                  |ib_register_client(&cm_client)
                  |down_read(&devices_rwsem)
                  |xa_for_each_marked (&devices, DEVICE_REGISTERED)
                  |add_client_context
                  |cm_add_one
                  |ib_register_mad_agent
                  |ib_get_mad_port
                  |__ib_get_mad_port
                  |list_for_each_entry(entry, &ib_mad_port_list, port_list)
                  |return NULL
                  |up_read(&devices_rwsem)
                  |
add_client_context|
ib_mad_init_device|
ib_mad_port_open  |
list_add_tail(&port_priv->port_list, &ib_mad_port_list)
up_read(&devices_rwsem)
                  |

Fix it by using down_write(&devices_rwsem) in ib_register_client().

Fixes: d0899892ed ("RDMA/device: Provide APIs from the core code to help unregistration")
Link: https://lore.kernel.org/r/20240203035313.98991-1-lishifeng@sangfor.com.cn
Suggested-by: Jason Gunthorpe <jgg@ziepe.ca>
Signed-off-by: Shifeng Li <lishifeng@sangfor.com.cn>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:23 -04:00
Arnd Bergmann
39b1af7bc9 scsi: csiostor: Avoid function pointer casts
[ Upstream commit 9f3dbcb5632d6876226031d552ef6163bb3ad215 ]

csiostor uses function pointer casts to keep the csio_ln_ev state machine
hidden, but this causes warnings about control flow integrity (KCFI)
violations in clang-16 and higher:

drivers/scsi/csiostor/csio_lnode.c:1098:33: error: cast from 'void (*)(struct csio_lnode *, enum csio_ln_ev)' to 'csio_sm_state_t' (aka 'void (*)(void *, unsigned int)') converts to incompatible function type [-Werror,-Wcast-function-type-strict]
 1098 |         return (csio_get_state(ln) == ((csio_sm_state_t)csio_lns_ready));
      |                                        ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
drivers/scsi/csiostor/csio_lnode.c:1369:29: error: cast from 'void (*)(struct csio_lnode *, enum csio_ln_ev)' to 'csio_sm_state_t' (aka 'void (*)(void *, unsigned int)') converts to incompatible function type [-Werror,-Wcast-function-type-strict]
 1369 |         if (csio_get_state(ln) == ((csio_sm_state_t)csio_lns_uninit)) {
      |                                    ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
drivers/scsi/csiostor/csio_lnode.c:1373:29: error: cast from 'void (*)(struct csio_lnode *, enum csio_ln_ev)' to 'csio_sm_state_t' (aka 'void (*)(void *, unsigned int)') converts to incompatible function type [-Werror,-Wcast-function-type-strict]
 1373 |         if (csio_get_state(ln) == ((csio_sm_state_t)csio_lns_ready)) {
      |                                    ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
drivers/scsi/csiostor/csio_lnode.c:1377:29: error: cast from 'void (*)(struct csio_lnode *, enum csio_ln_ev)' to 'csio_sm_state_t' (aka 'void (*)(void *, unsigned int)') converts to incompatible function type [-Werror,-Wcast-function-type-strict]
 1377 |         if (csio_get_state(ln) == ((csio_sm_state_t)csio_lns_offline)) {
      |                                    ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Move the enum into a shared header so the correct types can be used without
the need for casts.

Fixes: a3667aaed5 ("[SCSI] csiostor: Chelsio FCoE offload driver")
Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Link: https://lore.kernel.org/r/20240213100518.457623-1-arnd@kernel.org
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:23 -04:00
Johan Carlsson
6d5dc96b15 ALSA: usb-audio: Stop parsing channels bits when all channels are found.
[ Upstream commit a39d51ff1f52cd0b6fe7d379ac93bd8b4237d1b7 ]

If a usb audio device sets more bits than the amount of channels
it could write outside of the map array.

Signed-off-by: Johan Carlsson <johan.carlsson@teenage.engineering>
Fixes: 04324ccc75 ("ALSA: usb-audio: add channel map support")
Message-ID: <20240313081509.9801-1-johan.carlsson@teenage.engineering>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:23 -04:00
Bryan O'Donoghue
d7ae7d1265 clk: Fix clk_core_get NULL dereference
[ Upstream commit e97fe4901e0f59a0bfd524578fe3768f8ca42428 ]

It is possible for clk_core_get to dereference a NULL in the following
sequence:

clk_core_get()
    of_clk_get_hw_from_clkspec()
        __of_clk_get_hw_from_provider()
            __clk_get_hw()

__clk_get_hw() can return NULL which is dereferenced by clk_core_get() at
hw->core.

Prior to commit dde4eff47c ("clk: Look for parents with clkdev based
clk_lookups") the check IS_ERR_OR_NULL() was performed which would have
caught the NULL.

Reading the description of this function it talks about returning NULL but
that cannot be so at the moment.

Update the function to check for hw before dereferencing it and return NULL
if hw is NULL.

Fixes: dde4eff47c ("clk: Look for parents with clkdev based clk_lookups")
Signed-off-by: Bryan O'Donoghue <bryan.odonoghue@linaro.org>
Link: https://lore.kernel.org/r/20240302-linux-next-24-03-01-simple-clock-fixes-v1-1-25f348a5982b@linaro.org
Signed-off-by: Stephen Boyd <sboyd@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:23 -04:00
Sam Ravnborg
a1129b0922 sparc32: Fix section mismatch in leon_pci_grpci
[ Upstream commit 24338a6ae13cb743ced77da1b3a12c83f08a0c96 ]

Passing a datastructre marked _initconst to platform_driver_register()
is wrong. Drop the __initconst notation.

This fixes the following warnings:

WARNING: modpost: vmlinux: section mismatch in reference: grpci1_of_driver+0x30 (section: .data) -> grpci1_of_match (section: .init.rodata)
WARNING: modpost: vmlinux: section mismatch in reference: grpci2_of_driver+0x30 (section: .data) -> grpci2_of_match (section: .init.rodata)

Signed-off-by: Sam Ravnborg <sam@ravnborg.org>
Cc: "David S. Miller" <davem@davemloft.net>
Cc: Andreas Larsson <andreas@gaisler.com>
Fixes: 4154bb821f ("sparc: leon: grpci1: constify of_device_id")
Fixes: 03949b1cb9 ("sparc: leon: grpci2: constify of_device_id")
Tested-by: Randy Dunlap <rdunlap@infradead.org> # build-tested
Reviewed-by: Andreas Larsson <andreas@gaisler.com>
Tested-by: Andreas Larsson <andreas@gaisler.com>
Signed-off-by: Andreas Larsson <andreas@gaisler.com>
Link: https://lore.kernel.org/r/20240224-sam-fix-sparc32-all-builds-v2-7-1f186603c5c4@ravnborg.org
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:23 -04:00
Daniel Thompson
c8c038beb4 backlight: lp8788: Fully initialize backlight_properties during probe
[ Upstream commit 392346827fbe8a7fd573dfb145170d7949f639a6 ]

props is stack allocated and the fields that are not explcitly set
by the probe function need to be zeroed or we'll get undefined behaviour
(especially so power/blank states)!

Fixes: c5a51053cf ("backlight: add new lp8788 backlight driver")
Signed-off-by: Daniel Thompson <daniel.thompson@linaro.org>
Link: https://lore.kernel.org/r/20240220153532.76613-4-daniel.thompson@linaro.org
Signed-off-by: Lee Jones <lee@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:23 -04:00
Daniel Thompson
8c351a9ef5 backlight: lm3639: Fully initialize backlight_properties during probe
[ Upstream commit abb5a5d951fbea3feb5c4ba179b89bb96a1d3462 ]

props is stack allocated and the fields that are not explcitly set
by the probe function need to be zeroed or we'll get undefined behaviour
(especially so power/blank states)!

Fixes: 0f59858d51 ("backlight: add new lm3639 backlight driver")
Signed-off-by: Daniel Thompson <daniel.thompson@linaro.org>
Link: https://lore.kernel.org/r/20240220153532.76613-3-daniel.thompson@linaro.org
Signed-off-by: Lee Jones <lee@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:23 -04:00
Daniel Thompson
12a0153f78 backlight: da9052: Fully initialize backlight_properties during probe
[ Upstream commit 0285e9efaee8276305db5c52a59baf84e9731556 ]

props is stack allocated and the fields that are not explcitly set
by the probe function need to be zeroed or we'll get undefined behaviour
(especially so power/blank states)!

Fixes: 6ede3d832a ("backlight: add driver for DA9052/53 PMIC v1")
Signed-off-by: Daniel Thompson <daniel.thompson@linaro.org>
Link: https://lore.kernel.org/r/20240220153532.76613-2-daniel.thompson@linaro.org
Signed-off-by: Lee Jones <lee@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:23 -04:00
Luca Weiss
1c8d8c6b4e backlight: lm3630a: Don't set bl->props.brightness in get_brightness
[ Upstream commit 4bf7ddd2d2f0f8826f25f74c7eba4e2c323a1446 ]

There's no need to set bl->props.brightness, the get_brightness function
is just supposed to return the current brightness and not touch the
struct.

With that done we can also remove the 'goto out' and just return the
value.

Fixes: 0c2a665a64 ("backlight: add Backlight driver for lm3630 chip")
Signed-off-by: Luca Weiss <luca@z3ntu.xyz>
Reviewed-by: Daniel Thompson <daniel.thompson@linaro.org>
Link: https://lore.kernel.org/r/20240220-lm3630a-fixups-v1-2-9ca62f7e4a33@z3ntu.xyz
Signed-off-by: Lee Jones <lee@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:23 -04:00
Luca Weiss
40a89f1bc4 backlight: lm3630a: Initialize backlight_properties on init
[ Upstream commit ad9aeb0e3aa90ebdad5fabf9c21783740eb95907 ]

The backlight_properties struct should be initialized to zero before
using, otherwise there will be some random values in the struct.

Fixes: 0c2a665a64 ("backlight: add Backlight driver for lm3630 chip")
Signed-off-by: Luca Weiss <luca@z3ntu.xyz>
Reviewed-by: Daniel Thompson <daniel.thompson@linaro.org>
Link: https://lore.kernel.org/r/20240220-lm3630a-fixups-v1-1-9ca62f7e4a33@z3ntu.xyz
Signed-off-by: Lee Jones <lee@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:23 -04:00
Michael Ellerman
bb9981f915 powerpc/embedded6xx: Fix no previous prototype for avr_uart_send() etc.
[ Upstream commit 20933531be0577cdd782216858c26150dbc7936f ]

Move the prototypes into mpc10x.h which is included by all the relevant
C files, fixes:

  arch/powerpc/platforms/embedded6xx/ls_uart.c:59:6: error: no previous prototype for 'avr_uart_configure'
  arch/powerpc/platforms/embedded6xx/ls_uart.c:82:6: error: no previous prototype for 'avr_uart_send'

Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
Link: https://msgid.link/20240305123410.3306253-1-mpe@ellerman.id.au
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:23 -04:00
Paloma Arellano
a6e96cc265 drm/msm/dpu: add division of drm_display_mode's hskew parameter
[ Upstream commit 551ee0f210991d25f336bc27262353bfe99d3eed ]

Setting up the timing engine when the physical encoder has a split role
neglects dividing the drm_display_mode's hskew parameter. Let's fix this
since this must also be done in preparation for implementing YUV420 over
DP.

Fixes: 25fdd5933e ("drm/msm: Add SDM845 DPU support")
Signed-off-by: Paloma Arellano <quic_parellan@quicinc.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@linaro.org>
Patchwork: https://patchwork.freedesktop.org/patch/579605/
Link: https://lore.kernel.org/r/20240222194025.25329-3-quic_parellan@quicinc.com
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@linaro.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:22 -04:00