Commit graph

905,061 commits

Author SHA1 Message Date
Greg Kroah-Hartman
ca48ea8b94 Merge tag 'android11-5.4.284_r00' into android11-5.4
This merges up to the 5.4.284 LTS release into the android11-5.4 branch.
Included in here are the following commits:

* 4cf36217bc Merge branch 'android11-5.4' into android11-5.4-lts
* 8ed9415215 Revert "clocksource/drivers/timer-of: Remove percpu irq related code"
* 97009b56c6 Merge 5.4.284 into android11-5.4-lts
* 661f109c05 Linux 5.4.284
* 7fcbb6aa50 Revert "parisc: Use irq_enter_rcu() to fix warning at kernel/context_tracking.c:367"
* 7c9be2c96c cx82310_eth: fix error return code in cx82310_bind()
* 934247ea65 net, sunrpc: Remap EPERM in case of connection failure in xs_tcp_setup_socket
* 6a976e9a47 rtmutex: Drop rt_mutex::wait_lock before scheduling
* 2120e07966 drm/i915/fence: Mark debug_fence_free() with __maybe_unused
* c4f8a84a2b drm/i915/fence: Mark debug_fence_init_onstack() with __maybe_unused
* 03e1fd0327 nvmet-tcp: fix kernel crash if commands allocation fails
* f57769ff6f arm64: acpi: Harden get_cpu_for_acpi_id() against missing CPU entry
* 28ac856039 arm64: acpi: Move get_cpu_for_acpi_id() to a header
* 9e81f6b3eb ACPI: processor: Fix memory leaks in error paths of processor_add()
* eaa995d0d5 ACPI: processor: Return an error if acpi_processor_get_info() fails in processor_add()
* ba97ba173f nilfs2: protect references to superblock parameters exposed in sysfs
* 9dffb618a6 nilfs2: replace snprintf in show functions with sysfs_emit
* 7195d0498d tracing: Avoid possible softlockup in tracing_iter_reset()
* 2feb2c351c ring-buffer: Rename ring_buffer_read() to read_buffer_iter_advance()
* c6011b495d uprobes: Use kzalloc to allocate xol area
* 302ac43e58 clocksource/drivers/timer-of: Remove percpu irq related code
* 6b0f357bf9 clocksource/drivers/imx-tpm: Fix next event not taking effect sometime
* d41b52a4f5 clocksource/drivers/imx-tpm: Fix return -ETIME when delta exceeds INT_MAX
* b243d52b5f VMCI: Fix use-after-free when removing resource in vmci_resource_remove()
* 9f0e663d83 Drivers: hv: vmbus: Fix rescind handling in uio_hv_generic
* f38f46da80 uio_hv_generic: Fix kernel NULL pointer dereference in hv_uio_rescind
* e8c5ba8941 nvmem: Fix return type of devm_nvmem_device_get() in kerneldoc
* 5a32bfd230 binder: fix UAF caused by offsets overwrite
* c8294c80b7 iio: fix scale application in iio_convert_raw_to_processed_unlocked
* 108e0ab0bc iio: buffer-dmaengine: fix releasing dma channel on error
* 0e727707a2 staging: iio: frequency: ad9834: Validate frequency parameter value
* d39fbfaf1a NFSv4: Add missing rescheduling points in nfs_client_return_marked_delegations
* 32c4fe1fd9 ata: pata_macio: Use WARN instead of BUG
* 0f27f4f445 lib/generic-radix-tree.c: Fix rare race in __genradix_ptr_alloc()
* defcaa426b of/irq: Prevent device address out-of-bounds read in interrupt map walk
* 1b9451ba6f Squashfs: sanity check symbolic link size
* 2cdbe9e5f5 usbnet: ipheth: race between ipheth_close and error handling
* 597ff93029 Input: uinput - reject requests with unreasonable number of slots
* fac3cb3c64 HID: cougar: fix slab-out-of-bounds Read in cougar_report_fixup
* 7ef29fada7 btrfs: initialize location to fix -Wmaybe-uninitialized in btrfs_lookup_dentry()
* df77a678c3 PCI: Add missing bridge lock to pci_bus_lock()
* 71291aa724 btrfs: clean up our handling of refs == 0 in snapshot delete
* 7fbbb8b2b3 btrfs: replace BUG_ON with ASSERT in walk_down_proc()
* 4e2c30e0df smp: Add missing destroy_work_on_stack() call in smp_call_on_cpu()
* d834433ff3 wifi: mwifiex: Do not return unused priv in mwifiex_get_priv_by_id()
* ed9cc6b6c3 libbpf: Add NULL checks to bpf_object__{prev_map,next_map}
* 77ab0fd231 hwmon: (w83627ehf) Fix underflows seen when writing limit attributes
* d6035c55fa hwmon: (nct6775-core) Fix underflows seen when writing limit attributes
* 438453dfbb hwmon: (lm95234) Fix underflows seen when writing limit attributes
* 7645d783df hwmon: (adc128d818) Fix underflows seen when writing limit attributes
* c4c681999d pci/hotplug/pnv_php: Fix hotplug driver crash on Powernv
* 7046afecc4 devres: Initialize an uninitialized struct member
* 96301fdc2d um: line: always fill *error_out in setup_one_line()
* 193f352631 cgroup: Protect css->cgroup write under css_set_lock
* 26cd726c32 iommu/vt-d: Handle volatile descriptor status read
* 4bfe58ae95 dm init: Handle minors larger than 255
* 01f7b90c64 ASoC: topology: Properly initialize soc_enum values
* 4bf22baba8 net: dsa: vsc73xx: fix possible subblocks range of CAPT block
* 608597018f net: bridge: br_fdb_external_learn_add(): always set EXT_LEARN
* 8c72b1cd0c net: bridge: fdb: convert added_by_external_learn to use bitops
* a021356aca net: bridge: fdb: convert added_by_user to bitops
* c2d2a39fab net: bridge: fdb: convert is_sticky to bitops
* 7d3a9267d5 net: bridge: fdb: convert is_static to bitops
* 3e28497e4d net: bridge: fdb: convert is_local to bitops
* 7d70e0b391 usbnet: modern method to get random MAC
* f3c54d6e06 net: usb: don't write directly to netdev->dev_addr
* 84a198ee61 drivers/net/usb: Remove all strcpy() uses
* c1b187a86a cx82310_eth: re-enable ethernet mode after router reboot
* 6f9fdf5806 tcp_bpf: fix return value of tcp_bpf_sendmsg()
* 82a9451ef8 platform/x86: dell-smbios: Fix error path in dell_smbios_init()
* b7387a7c77 igb: Fix not clearing TimeSync interrupts for 82580
* 33ed4ba73c can: bcm: Remove proc entry when dev is unregistered.
* 97daf3f475 pcmcia: Use resource_size function on resource object
* 3d883961e3 media: qcom: camss: Add check for v4l2_fwnode_endpoint_parse
* cfb006e185 PCI: keystone: Add workaround for Errata #i2037 (AM65x SR 1.0)
* dfeee99390 usb: uas: set host status byte on data completion error
* f7ffb098bd wifi: brcmsmac: advertise MFP_CAPABLE to enable WPA3
* 1497a4484c udf: Avoid excessive partition lengths
* 52d2172873 netfilter: nf_conncount: fix wrong variable type
* 37c60b3ff4 af_unix: Remove put_pid()/put_cred() in copy_peercred().
* 7c7ad414d4 irqchip/armada-370-xp: Do not allow mapping IRQ 0 and 1
* 2859267753 smack: unix sockets: fix accept()ed socket label
* f2a4fe8b3e ALSA: hda: Add input value sanity checks to HDMI channel map controls
* 036441e843 nilfs2: fix state management in error path of log writing function
* da02f9eb33 nilfs2: fix missing cleanup on rollforward recovery error
* 4a4eeefa51 sched: sch_cake: fix bulk flow accounting logic for host fairness
* dcaf4e2216 ila: call nf_unregister_net_hooks() sooner
* 0af2a13a37 clk: qcom: clk-alpha-pll: Fix the trion pll postdiv set rate API
* 2464ec897f clk: qcom: clk-alpha-pll: Fix the pll post div mask
* 04b2b4b416 clk: hi6220: use CLK_OF_DECLARE_DRIVER
* 065c48f9e1 reset: hi6220: Add support for AO reset controller
* 9f38784479 fuse: use unsigned type for getxattr/listxattr size truncation
* 20f3ae4e4d fuse: update stats for pages in dropped aux writeback list
* 54368655ab mmc: sdhci-of-aspeed: fix module autoloading
* b9ee16a20d mmc: dw_mmc: Fix IDMAC operation with pages bigger than 4K
* 03fb62294f irqchip/gic-v2m: Fix refcount leak in gicv2m_of_init()
* 3dd4e84c02 ata: libata: Fix memory leak for error path in ata_host_alloc()
* b7cec87c62 ALSA: hda/conexant: Add pincfg quirk to enable top speakers on Sirius devices
* 993b60c7f9 ASoC: dapm: Fix UAF for snd_soc_pcm_runtime object
* 295ad5afd9 sch/netem: fix use after free in netem_dequeue
* d24c9a466c i2c: Use IS_REACHABLE() for substituting empty ACPI functions
* 1b9666845f udf: Limit file size to 4TB
* d3af435e8a virtio_net: Fix napi_skb_cache_put warning
* e1d41cb9c0 net: set SOCK_RCU_FREE before inserting socket into hashtable
* 129f95948a block: initialize integrity buffer to zero before writing it to media
* 61fb1989ad media: uvcvideo: Enforce alignment of frame and interval
* 0364f1f17a drm/amd/display: Skip wbscl_set_scaler_filter if filter is null
* d7fc80b7f8 wifi: cfg80211: make hash table duplicates more survivable
* 5b4b304f19 smack: tcp: ipv4, fix incorrect labeling
* 8095bf0579 usb: typec: ucsi: Fix null pointer dereference in trace
* bf9502a1ae usbip: Don't submit special requests twice
* d87108bbcd ionic: fix potential irq name truncation
* 730ee2686a apparmor: fix possible NULL pointer dereference
* e0c2b19a97 drm/amdkfd: Reconcile the definition and use of oem_id in struct kfd_topology_device
* 2097edede7 drm/amdgpu: fix mc_data out-of-bounds read warning
* e789e05388 drm/amdgpu: fix ucode out-of-bounds read warning
* c1beebdfe7 drm/amd/display: Fix Coverity INTEGER_OVERFLOW within dal_gpio_service_create
* a72d499640 drm/amd/display: Check num_valid_sets before accessing reader_wm_sets[]
* d619b91d3c drm/amd/display: Stop amdgpu_dm initialize when stream nums greater than 6
* 8520fdc8ec drm/amd/display: Check gpio_id before used as array index
* 3d4d211d9b drm/amdgpu: fix overflowed array index read warning
* eb74cf33a3 drm/amdgpu: Fix uninitialized variable warning in amdgpu_afmt_acr
* e35c2b95fb net: usb: qmi_wwan: add MeiG Smart SRM825L
* 2da63ce188 i2c: Fix conditional for substituting empty ACPI functions
* d5cb4c88a3 drm: panel-orientation-quirks: Add quirk for OrangePi Neo

Change-Id: I7bc8fbb8195ce896375f9c48c82c60b29eeff399
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-10-28 10:32:58 +00:00
Gabriel Krisman Bertazi
425419e5b2 UPSTREAM: unicode: Don't special case ignorable code points
We don't need to handle them separately. Instead, just let them
decompose/casefold to themselves.

Change-Id: I01c3f2c98ae4d84269586cec09f18239cbee0abb
Signed-off-by: Gabriel Krisman Bertazi <krisman@suse.de>
(cherry picked from commit 5c26d2f1d3f5e4be3e196526bead29ecb139cf91)
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-10-14 16:22:12 +00:00
Kalesh Singh
171355878e ANDROID: 16K: Fixup padding vm_flags bits on VMA splits
In some cases VMAs are split without the mmap write lock held;
later the lock is taken to fixup vm_flags of the original VMA.
Since some uppper bits of vm_flags are used to encode the ELF
padding ranges, they need to be modified on splits. This is
usually handled correctly by __split_vma(). However in the above
case, the flags get over witten later under the write lock.

Preserve vm_flag bits on reset to correctly represent padding.

Bug: 357901498
Change-Id: I1cb75419e614791a47cbdb0341373f619daf0bf2
Signed-off-by: Kalesh Singh <kaleshsingh@google.com>
2024-10-10 16:13:35 -07:00
Kalesh Singh
f6da812ab6 ANDROID: 16K: Introduce pgsize_migration_inline.h
Introduce inline header to avoid circular dependency. This
will be used in a subsequent patch.

Also take opportunity to do some small noop refactor in
vma_pad_pages() and split_pad_vma() for more robust code.

Bug: 357901498
Change-Id: Ia5f447758d0d07ed3e1429ca1e35dcc0741cc22a
Signed-off-by: Kalesh Singh <kaleshsingh@google.com>
2024-10-10 16:13:30 -07:00
Greg Kroah-Hartman
4cf36217bc Merge branch 'android11-5.4' into android11-5.4-lts
Do a back-merge to catch the latest -lts merge sync with the
android11-5.4 branch.  Changes included in here are:

* b8b210d80a Merge tag 'android11-5.4.283_r00' into android11-5.4
* d62984adb1 ANDROID: delete tool added by mistake
* a03c6437cf ANDROID: fix ENOMEM check of binder_proc_ext
* be02156857 ANDROID: binder: fix KMI issues due to frozen notification
* 1063c2fa62 BACKPORT: FROMGIT: binder: frozen notification binder_features flag
* d1e87637cd BACKPORT: FROMGIT: binder: frozen notification
* 8c4165a043 BACKPORT: selftests/binderfs: add test for feature files
* 4d4f8b7a7f UPSTREAM: docs: binderfs: add section about feature files
* 460de65538 BACKPORT: binderfs: add support for feature files
* 31f1f4b2aa FROMLIST: binder: fix memory leaks of spam and pending work
* 334fe73bdd FROMGIT: Binder: add TF_UPDATE_TXN to replace outdated txn
* 2bfddf30aa BACKPORT: binder: tell userspace to dump current backtrace when detected oneway spamming

Change-Id: Ib371e14baa94e83eacd571123d27b80a4d569d36
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-09-27 14:14:06 +00:00
Greg Kroah-Hartman
8ed9415215 Revert "clocksource/drivers/timer-of: Remove percpu irq related code"
This reverts commit 302ac43e58 which is
commit 471ef0b5a8aaca4296108e756b970acfc499ede4 upstream.

It breaks the Android kernel abi and can be brought back in the future
in an abi-safe way if it is really needed.

Bug: 161946584
Change-Id: Ia9f22b51d4153ed7ffc4cf3f846df73e6f146511
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-09-12 13:54:50 +00:00
Greg Kroah-Hartman
b8b210d80a Merge tag 'android11-5.4.283_r00' into android11-5.4
This merges up to the 5.4.283 LTS release into android11-5.4.  Included
in here are the following commits:

*   ac0b99d778 Merge 5.4.283 into android11-5.4-lts
|\
| * 4826c62faf Linux 5.4.283
| * 564e1986b0 scsi: aacraid: Fix double-free on probe failure
| * 9a2d4f736c net: dsa: mv8e6xxx: Fix stub function parameters
| * 29957da407 usb: core: sysfs: Unmerge @usb3_hardware_lpm_attr_group in remove_power_attributes()
| * b1069a3765 usb: dwc3: st: add missing depopulate in probe error path
| * f3498650df usb: dwc3: st: fix probed platform device ref count on probe error path
| * d2afc2bffe usb: dwc3: core: Prevent USB core invalid event buffer address access
| * 1d16ac232f usb: dwc3: omap: add missing depopulate in probe error path
| * d035dd9986 USB: serial: option: add MeiG Smart SRM825L
| * aa06cdd280 cdc-acm: Add DISABLE_ECHO quirk for GE HealthCare UI Controller
| * 0ee9594c97 soc: qcom: cmd-db: Map shared memory as WC, not WB
| * c5e0523744 nfc: pn533: Add poll mod list filling check
| * cd0c823b3f nfc: pn533: Add autopoll capability
| * cb829e3352 nfc: pn533: Add dev_up/dev_down hooks to phy_ops
| * e7d364a5c7 net: busy-poll: use ktime_get_ns() instead of local_clock()
| * bdd99e5f0a gtp: fix a potential NULL pointer dereference
| * ec7b4f7f64 ethtool: check device is present when getting link settings
| * c9fe713b1a r8152: Factor out OOB link list waits
| * 902e15c9d4 soundwire: stream: fix programming slave ports for non-continous port maps
| * f1f77b1164 net:rds: Fix possible deadlock in rds_message_put
| * 10aeaa47e4 cgroup/cpuset: Prevent UAF in proc_cpuset_show()
| * 56e62977ea ata: libata-core: Fix null pointer dereference on error
| * 7aa9456288 media: uvcvideo: Fix integer overflow calculating timestamp
| * 9bb1d48f54 filelock: Correct the filelock owner in fcntl_setlk/fcntl_setlk64
| * 009c4d78bc drm/amdkfd: don't allow mapping the MMIO HDP page with large pages
| * 29a132d793 ipc: replace costly bailout check in sysvipc_find_ipc()
| * bf44f0e935 wifi: mwifiex: duplicate static structs used in driver instances
| * 2cea369a5c pinctrl: single: fix potential NULL dereference in pcs_get_function()
| * 3b50575944 drm/amdgpu: Using uninitialized value *size when calling amdgpu_vce_cs_reloc
| * d4bdddda97 tools: move alignment-related macros to new <linux/align.h>
| * 87f610a1a7 Input: MT - limit max slots
| * 7732c54f2b Bluetooth: hci_ldisc: check HCI_UART_PROTO_READY flag in HCIUARTGETPROTO
| * 01e07b0567 ALSA: timer: Relax start tick time check for slave timer elements
| * 931274b0c9 mmc: dw_mmc: allow biu and ciu clocks to defer
| * 11aa40b30b cxgb4: add forgotten u64 ivlan cast before shift
| * 2deb4543e9 HID: microsoft: Add rumble support to latest xbox controllers
| * b2c3dd788a HID: wacom: Defer calculation of resolution until resolution_code is known
| * 90e1ff1c15 Bluetooth: MGMT: Add error handling to pair_device()
| * 2b507b0399 mmc: mmc_test: Fix NULL dereference on allocation failure
| * 6590c49e98 drm/msm/dpu: don't play tricks with debug macros
| * bdb2969754 drm/msm: use drm_debug_enabled() to check for debug categories
| * 1573f51ef1 net: xilinx: axienet: Fix dangling multicast addresses
| * c66ed34257 net: xilinx: axienet: Always disable promiscuous mode
| * ce2f6cfab2 ipv6: prevent UAF in ip6_send_skb()
| * 759e3e8c4a netem: fix return value if duplicate enqueue fails
| * d39f5be62f net: dsa: mv88e6xxx: Fix out-of-bound access
| * 2c0f2a5244 net: dsa: mv88e6xxx: replace ATU violation prints with trace points
| * 0d9e6f3630 net: dsa: mv88e6xxx: read FID when handling ATU violations
| * c86fd1b4ce net: dsa: mv88e6xxx: global1_atu: Add helper for get next
| * 4d63207fa6 net: dsa: mv88e6xxx: global2: Expose ATU stats register
| * 963bfa5763 netfilter: nft_counter: Synchronize nft_counter_reset() against reader.
| * 6633b17840 kcm: Serialise kcm_sendmsg() for the same socket.
| * 0d3702c60f tc-testing: don't access non-existent variable on exception
| * 2b3e49f250 Bluetooth: hci_core: Fix LE quote calculation
| * 960d34e61a Bluetooth: hci_core: Fix not handling link timeouts propertly
| * a5ba18e68c Bluetooth: Make use of __check_timeout on hci_sched_le
| * 06a6aebeb0 dm suspend: return -ERESTARTSYS instead of -EINTR
| * c6e3c341cf dm: do not use waitqueue for request-based DM
| * 6a99ee6b99 dm mpath: pass IO start time to path selector
| * 8adc9ab5bd media: solo6x10: replace max(a, min(b, c)) by clamp(b, a, c)
| * 58f5626d1b block: use "unsigned long" for blk_validate_block_size().
| * f5dda8db38 gtp: pull network headers in gtp_dev_xmit()
| * 9d72b629a9 hrtimer: Prevent queuing of hrtimer without a function callback
| * ee440c8312 nvmet-rdma: fix possible bad dereference when freeing rsps
| * e378b7675d ext4: set the type of max_zeroout to unsigned int to avoid overflow
| * f162e1b7d6 irqchip/gic-v3-its: Remove BUG_ON in its_vpe_irq_domain_alloc
| * 31d59a2a81 usb: dwc3: core: Skip setting event buffers for host only controllers
| * 29fdfe9f2a s390/iucv: fix receive buffer virtual vs physical address confusion
| * b4bde02e00 openrisc: Call setup_memory() earlier in the init sequence
| * d8086fbabd NFS: avoid infinite loop in pnfs_update_layout.
| * 6168df74db nvmet-tcp: do not continue for invalid icreq
| * ea213d57f6 Bluetooth: bnep: Fix out-of-bound access
| * d037a1d1f5 nvme: clear caller pointer on identify failure
| * a98c91a49e usb: gadget: fsl: Increase size of name buffer for endpoints
| * 7026ba0a09 f2fs: fix to do sanity check in update_sit_entry
| * fe3f0f9af4 btrfs: delete pointless BUG_ON check on quota root in btrfs_qgroup_account_extent()
| * ffb87a8829 btrfs: send: handle unexpected data in header buffer in begin_cmd()
| * 76c5fd8dd0 btrfs: handle invalid root reference found in may_destroy_subvol()
| * 36f225da51 btrfs: change BUG_ON to assertion when checking for delayed_node root
| * 3d2598c317 powerpc/boot: Only free if realloc() succeeds
| * d921c88d1b powerpc/boot: Handle allocation failure in simple_realloc()
| * b62f96647b parisc: Use irq_enter_rcu() to fix warning at kernel/context_tracking.c:367
| * 03475167fd x86: Increase brk randomness entropy for 64-bit systems
| * 0f9d267011 md: clean up invalid BUG_ON in md_ioctl
| * 6ca28b54ad virtiofs: forbid newlines in tags
| * 5766a74fe6 drm/lima: set gp bus_stop bit before hard reset
| * 7bdf5df2bf net/sun3_82586: Avoid reading past buffer in debug output
| * 6ef9c38cd0 scsi: lpfc: Initialize status local variable in lpfc_sli4_repost_sgl_list()
| * e1c82f74b6 fs: binfmt_elf_efpic: don't use missing interpreter's properties
| * 199a42fc4c media: pci: cx23885: check cx23885_vdev_init() return
| * 1e3ca3ef9f quota: Remove BUG_ON from dqget()
| * 12f8698a84 ext4: do not trim the group with corrupted block bitmap
| * de71b478b2 nvmet-trace: avoid dereferencing pointer too early
| * 240fcfe119 powerpc/xics: Check return value of kasprintf in icp_native_map_one_cpu
| * 81c479fc35 IB/hfi1: Fix potential deadlock on &irq_src_lock and &dd->uctxt_lock
| * 7b31922f2a wifi: iwlwifi: abort scan when rfkill on but device enabled
| * 0137220b97 gfs2: setattr_chown: Add missing initialization
| * e997548575 scsi: spi: Fix sshdr use
| * 19c348fecf binfmt_misc: cleanup on filesystem umount
| * 11b776e3c9 staging: ks7010: disable bh on tx_dev_lock
| * 8b29a8dc6a media: radio-isa: use dev_name to fill in bus_info
| * 9a732aad7d i2c: riic: avoid potential division by zero
| * 47ff82181e wifi: cw1200: Avoid processing an invalid TIM IE
| * 5b6711094b ssb: Fix division by zero issue in ssb_calc_clock_rate
| * 4e0b0f085f ALSA: hda/realtek: Fix noise from speakers on Lenovo IdeaPad 3 15IAU7
| * 67492d4d10 net: hns3: fix a deadlock problem when config TC during resetting
| * 56bb1b3bf4 net: dsa: vsc73xx: pass value in phy_write operation
| * d7fa0c3582 net: axienet: Fix register defines comment description
| * 8b04b6b7c4 net: axienet: Autodetect 64-bit DMA capability
| * 46a5469f92 net: axienet: Upgrade descriptors to hold 64-bit addresses
| * 67527bcb0f net: axienet: Wrap DMA pointer writes to prepare for 64 bit
| * 2978228525 net: axienet: Drop MDIO interrupt registers from ethtools dump
| * d724554f8f net: axienet: Check for DMA mapping errors
| * 367ca46817 net: axienet: Factor out TX descriptor chain cleanup
| * c6ddc4c57b net: axienet: Improve DMA error handling
| * 8876a2ac1b net: axienet: Fix DMA descriptor cleanup path
| * 09e086a5f7 atm: idt77252: prevent use after free in dequeue_rx()
| * 3b999c528b net/mlx5e: Correctly report errors for ethtool rx flows
| * 37f3dafee1 s390/uv: Panic for set and remove shared access UVC errors
| * cd0aa417b8 btrfs: rename bitmap_set_bits() -> btrfs_bitmap_set_bits()
| * 2d34304bce s390/cio: rename bitmap_size() -> idset_bitmap_size()
| * 1ab137a90e overflow: Implement size_t saturating arithmetic helpers
| * 60f05081e0 overflow.h: Add flex_array_size() helper
| * 1b37ec85ad memcg_write_event_control(): fix a user-triggerable oops
| * a71a6db101 drm/amdgpu: Actually check flags for all context ops.
| * 374a0f8204 selinux: fix potential counting error in avc_add_xperms_decision()
| * e807487a1d fix bitmap corruption on close_range() with CLOSE_RANGE_UNSHARE
| * 463074c081 bitmap: introduce generic optimized bitmap_size()
| * 3525ad2524 vfs: Don't evict inode under the inode lru traversing context
| * 0f94cd0e02 dm persistent data: fix memory allocation failure
| * f75dec8417 dm resume: don't return EINVAL when signalled
| * 0936c758a2 arm64: ACPI: NUMA: initialize all values of acpi_early_node_map to NUMA_NO_NODE
| * 19f60a55b2 s390/dasd: fix error recovery leading to data corruption on ESE devices
| * a57b0ebabe xhci: Fix Panther point NULL pointer deref at full-speed re-enumeration
| * fa69434ecd ALSA: usb-audio: Support Yamaha P-125 quirk entry
| * 33168db352 fuse: Initialize beyond-EOF page contents before setting uptodate
* | f9764dcf97 Revert "genirq: Allow the PM device to originate from irq domain"
* | d131a10522 Revert "genirq: Allow irq_chip registration functions to take a const irq_chip"
* | e11b864e72 Revert "irqchip/imx-irqsteer: Constify irq_chip struct"
* | 8a7102ed4b Revert "irqchip/imx-irqsteer: Add runtime PM support"
* | 31cfc1a256 Revert "irqchip/imx-irqsteer: Handle runtime power management correctly"
* | 147724ba5f Merge 5.4.282 into android11-5.4-lts
|\|
| * 5bb3c84a11 Linux 5.4.282
| * 2f2f3c6a4d media: Revert "media: dvb-usb: Fix unexpected infinite loop in dvb_usb_read_remote_control()"
| * e7765ad4b4 ARM: dts: imx6qdl-kontron-samx6i: fix phy-mode
| * dc1d852277 nvme/pci: Add APST quirk for Lenovo N60z laptop
| * 368f6985d4 exec: Fix ToCToU between perm check and set-uid/gid usage
| * fdf2b10baf media: uvcvideo: Use entity get_cur in uvc_ctrl_set
| * f6a745c558 arm64: cpufeature: Fix the visibility of compat hwcaps
| * a256d019ea drm/i915/gem: Fix Virtual Memory mapping boundaries calculation
| * cd4348e0a5 netfilter: nf_tables: prefer nft_chain_validate
| * eaf1a29ea5 netfilter: nf_tables: use timestamp to check for set element timeout
| * cb56f8f06a netfilter: nf_tables: set element extended ACK reporting support
| * 53174ce02d kbuild: Fix '-S -c' in x86 stack protector scripts
| * af3948929b Fix gcc 4.9 build issue in 5.4.y
| * c7a28cb079 drm/mgag200: Set DDC timeout in milliseconds
| * ca75fa4ff8 drm/bridge: analogix_dp: properly handle zero sized AUX transactions
| * 06c1de44d3 x86/mtrr: Check if fixed MTRRs exist before saving them
| * d3e4dbc285 tracing: Fix overflow in get_free_elt()
| * f8fe71c649 power: supply: axp288_charger: Round constant_charge_voltage writes down
| * 1031a0e7c2 power: supply: axp288_charger: Fix constant_charge_voltage writes
| * da18145e7d genirq/irqdesc: Honor caller provided affinity in alloc_desc()
| * 55b2a5d331 serial: core: check uartclk for zero to avoid divide by zero
| * 881058e07b scsi: mpt3sas: Avoid IOMMU page faults on REPORT ZONES
| * 12608528f5 scsi: mpt3sas: Remove scsi_dma_map() error messages
| * 3f16bc776b ntp: Safeguard against time_constant overflow
| * dd98c9630b driver core: Fix uevent_show() vs driver detach race
| * 5cd98f82ec ntp: Clamp maxerror and esterror to operating range
| * f91fb47eca tick/broadcast: Move per CPU pointer access into the atomic section
| * 8f783731e3 scsi: ufs: core: Fix hba->last_dme_cmd_tstamp timestamp updating logic
| * df8e734ae5 usb: gadget: core: Check for unset descriptor
| * 55bb086ce9 USB: serial: debug: do not echo input by default
| * 9c3746ce8d usb: vhci-hcd: Do not drop references before new references are gained
| * 85f06d9634 ALSA: hda/hdmi: Yet more pin fix for HP EliteDesk 800 G4
| * 3c540f4200 ALSA: hda: Add HP MP9 G4 Retail System AMS to force connect list
| * 40f3d5cb0e ALSA: line6: Fix racy access to midibuf
| * 24ddda932c drm/client: fix null pointer dereference in drm_client_modeset_probe
| * 2c99fd5762 spi: spi-fsl-lpspi: Fix scldiv calculation
| * 3a5e84e6e4 spi: fsl-lpspi: remove unneeded array
| * abc71a9915 bpf: kprobe: remove unused declaring of bpf_kprobe_override
| * 6082250cca i2c: smbus: Send alert notifications to all devices if source not found
| * 54abe030df i2c: smbus: Improve handling of stuck alerts
| * 9bd5abd9d3 i2c: smbus: Don't filter out duplicate alerts
| * ba9a332d1e arm64: errata: Expand speculative SSBS workaround (again)
| * 76b4fbb661 arm64: cputype: Add Cortex-A725 definitions
| * 90f49639d4 arm64: cputype: Add Cortex-X1C definitions
| * d19a135ca2 arm64: errata: Expand speculative SSBS workaround
| * 31c04d3f68 arm64: errata: Unify speculative SSBS errata logic
| * 32480850c6 arm64: cputype: Add Cortex-X925 definitions
| * e890465ebf arm64: cputype: Add Cortex-A720 definitions
| * d58774b5f1 arm64: cputype: Add Cortex-X3 definitions
| * 60bb454974 arm64: errata: Add workaround for Arm errata 3194386 and 3312417
| * c4d3c615cf arm64: cputype: Add Neoverse-V3 definitions
| * 7e13067758 arm64: cputype: Add Cortex-X4 definitions
| * 4fecc9ed90 arm64: Add Neoverse-V2 part
| * 762dd597c7 arm64: cpufeature: Force HWCAP to be based on the sysreg visible to user-space
| * a61144525f ext4: fix wrong unit use in ext4_mb_find_by_goal
| * 0860bad4a4 SUNRPC: Fix a race to wake a sync task
| * 1ec5ea9e25 s390/sclp: Prevent release of buffer in I/O
| * 969d683bfe jbd2: avoid memleak in jbd2_journal_write_metadata_buffer
| * 87c2a57fdb media: uvcvideo: Fix the bandwdith quirk on USB 3.x
| * 0463702743 media: uvcvideo: Ignore empty TS packets
| * ff5c4eb71e drm/amdgpu: Fix the null pointer dereference to ras_manager
| * a8ca88d3d9 btrfs: fix bitmap leak when loading free space cache on duplicate entry
| * 4dd406a308 wifi: nl80211: don't give key data to userspace
| * 5def895b42 udf: prevent integer overflow in udf_bitmap_free_blocks()
| * 9d9e96dc56 PCI: Add Edimax Vendor ID to pci_ids.h
| * 0f82fcdc8e selftests/bpf: Fix send_signal test with nested CONFIG_PARAVIRT
| * d3eaa7fe11 ACPI: SBS: manage alarm sysfs attribute through psy core
| * 79b7f33d46 ACPI: battery: create alarm sysfs attribute atomically
| * 4c8f911560 clocksource/drivers/sh_cmt: Address race condition for clock events
| * 6b33c468d5 md/raid5: avoid BUG_ON() while continue reshape after reassembling
| * 6fdd36fba3 net: fec: Stop PPS on driver remove
| * d89b1a9387 Bluetooth: l2cap: always unlock channel in l2cap_conless_channel()
| * 96cc343c3f net: linkwatch: use system_unbound_wq
| * 37c0934497 net: usb: qmi_wwan: fix memory leak for not ip packets
| * c9b3fc4f15 sctp: Fix null-ptr-deref in reuseport_add_sock().
| * c2237ce58a sctp: move hlist_node and hashent out of sctp_ep_common
| * 25a727233a x86/mm: Fix pti_clone_pgtable() alignment assumption
| * 8243f41375 irqchip/mbigen: Fix mbigen node address layout
| * f19bf41e73 genirq: Allow irq_chip registration functions to take a const irq_chip
| * 922b824bb7 netfilter: ipset: Add list flush to cancel_gc
| * 869f240a5b net: usb: sr9700: fix uninitialized variable use in sr_mdio_read
| * 479335789d ALSA: usb-audio: Correct surround channels in UAC1 channel map
| * 41a6c31df7 protect the fetch of ->fd[fd] in do_dup2() from mispredictions
| * 04dcab03e6 HID: wacom: Modify pen IDs
| * ba35ce6480 ipv6: fix ndisc_is_useropt() handling for PIO
| * 9f96828b94 net/mlx5e: Add a check for the return value from mlx5_port_set_eth_ptys
| * 37652fbef9 net/iucv: fix use after free in iucv_sock_close()
| * e8e1c9b282 drm/vmwgfx: Fix overlay when using Screen Targets
| * 3bcb8bba72 drm/nouveau: prime: fix refcount underflow
| * 84beb77384 remoteproc: imx_rproc: Skip over memory region when node value is NULL
| * 66b47133bf remoteproc: imx_rproc: Fix ignoring mapping vdev regions
| * 8d1eca34ac remoteproc: imx_rproc: ignore mapping vdev regions
| * a590e8dea3 irqchip/imx-irqsteer: Handle runtime power management correctly
| * 294aa15e79 irqchip/imx-irqsteer: Add runtime PM support
| * ee1e002d17 irqchip/imx-irqsteer: Constify irq_chip struct
| * 9951e76f39 genirq: Allow the PM device to originate from irq domain
| * b044588a16 devres: Fix memory leakage caused by driver API devm_free_percpu()
| * 00d780681e driver core: Cast to (void *) with __force for __percpu pointer
| * 47b3dce100 dev/parport: fix the array out-of-bounds risk
| * fca2fe1670 parport: Standardize use of printmode
| * 92f405a7f1 parport: Convert printk(KERN_<LEVEL> to pr_<level>(
| * bbfcb2a4bc PCI: rockchip: Use GPIOD_OUT_LOW flag while requesting ep_gpio
| * c72ddaebcd PCI: rockchip: Make 'ep-gpios' DT property optional
| * 4d3817b64e mm: avoid overflows in dirty throttling logic
| * 3f8ec1d6b0 nvme-pci: add missing condition check for existence of mapped data
| * 035333dddd ASoC: Intel: use soc_intel_is_byt_cr() only when IOSF_MBI is reachable
| * 41aa8b71b5 ASoC: Intel: Move soc_intel_is_foo() helpers to a generic header
| * 9dff804bd8 ASoC: Intel: Convert to new X86 CPU match macros
| * d4001bd3b4 powerpc: fix a file leak in kvm_vcpu_ioctl_enable_cap()
| * 0abe35bc48 apparmor: Fix null pointer deref when receiving skb during sock creation
| * d3e4d4a98c mISDN: Fix a use after free in hfcmulti_tx()
| * a689f5eb13 bpf: Fix a segment issue when downgrading gso_size
| * fd06cb4a5f net: nexthop: Initialize all fields in dumped nexthops
| * 253405541b tipc: Return non-zero value from tipc_udp_addr2str() on error
| * 507bf56d42 net: bonding: correctly annotate RCU in bond_should_notify_peers()
| * 8ea16df99d ipv4: Fix incorrect source address in Record Route option
| * f19db930ae MIPS: SMP-CPS: Fix address for GCR_ACCESS register for CM3 and later
| * 2f7bbdc744 dma: fix call order in dmam_free_coherent
| * 6a8a0da4d8 libbpf: Fix no-args func prototype BTF dumping syntax
| * f4eee36072 um: time-travel: fix time-travel-start option
| * 9b3a434595 jfs: Fix array-index-out-of-bounds in diFree
| * c06023caca kdb: Use the passed prompt in kdb_position_cursor()
| * 1280375411 kdb: address -Wformat-security warnings
| * 02b87e6334 nilfs2: handle inconsistent state in nilfs_btnode_create_block()
| * 1729040114 Bluetooth: btusb: Add Realtek RTL8852BE support ID 0x13d3:0x3591
| * 3b5bcca858 Bluetooth: btusb: Add RTL8852BE device 0489:e125 to device tables
| * 46c0fa486b rbd: don't assume RBD_LOCK_STATE_LOCKED for exclusive mappings
| * 0a99aa6ca3 rbd: rename RBD_LOCK_STATE_RELEASING and releasing_wait
| * 7d8e5712f3 drm/panfrost: Mark simple_ondemand governor as softdep
| * f54a096195 rbd: don't assume rbd_is_lock_owner() for exclusive mappings
| * 796bdd9a9b selftests/sigaltstack: Fix ppc64 GCC build
| * 7f25f296fc RDMA/iwcm: Fix a use-after-free related to destroying CM IDs
| * 8e9e1b4b9d platform: mips: cpu_hwmon: Disable driver on unsupported hardware
| * 6e70fff02f watchdog/perf: properly initialize the turbo mode timestamp and rearm counter
| * 89b7c3d509 rtc: isl1208: Fix return value of nvmem callbacks
| * f6fe92535e perf/x86/intel/pt: Fix a topa_entry base address calculation
| * 8922d66df1 perf/x86/intel/pt: Fix topa_entry base length
| * e1f0108444 scsi: qla2xxx: validate nvme_local_port correctly
| * af46649304 scsi: qla2xxx: Complete command early within lock
| * dae67169cb scsi: qla2xxx: Fix for possible memory corruption
| * 171ac4b495 scsi: qla2xxx: During vport delete send async logout explicitly
| * 67b6d03dca rtc: cmos: Fix return value of nvmem callbacks
| * b59a5e86a3 kobject_uevent: Fix OOB access within zap_modalias_env()
| * 362ded08cc decompress_bunzip2: fix rare decompression failure
| * 8d4fc803ff ubi: eba: properly rollback inside self_check_eba
| * 02a29f6e3b clk: davinci: da8xx-cfgchip: Initialize clk_init_data before use
| * 54162974ae f2fs: fix to don't dirty inode for readonly filesystem
| * 5e5801888d scsi: qla2xxx: Return ENOBUFS if sg_cnt is more than one for ELS cmds
| * 46f1dea17b binder: fix hang of unregistered readers
| * 48b5730852 PCI: hv: Return zero, not garbage, when reading PCI_INTERRUPT_PIN
| * 2828b6fd83 hwrng: amd - Convert PCIBIOS_* return codes to errnos
| * 1ca78a7c47 tools/memory-model: Fix bug in lock.cat
| * 13d79c6489 leds: ss4200: Convert PCIBIOS_* return codes to errnos
| * 34293b8c12 wifi: mwifiex: Fix interface type change
| * e02f9941e8 ext4: make sure the first directory block is not a hole
| * 19e13b4d7f ext4: check dot and dotdot of dx_root before making dir indexed
| * ecc258fbdd m68k: amiga: Turn off Warp1260 interrupts during boot
| * cae9e59cc4 udf: Avoid using corrupted block bitmap buffer
| * 71dbf95359 drm/amd/display: Check for NULL pointer
| * d6ad202f73 drm/gma500: fix null pointer dereference in psb_intel_lvds_get_modes
| * a658ae2173 drm/gma500: fix null pointer dereference in cdv_intel_lvds_get_modes
| * 4a52861cd7 hfs: fix to initialize fields of hfs_inode_info after hfs_alloc_inode()
| * 72aff31119 media: venus: fix use after free in vdec_close
| * 375ff2a273 char: tpm: Fix possible memory leak in tpm_bios_measurements_open()
| * 2194b6a9bb ipv6: take care of scope when choosing the src addr
| * c77064e76c af_packet: Handle outgoing VLAN packets without hardware offloading
| * 5d7cea681d net: netconsole: Disable target before netpoll cleanup
| * 457a1c87d4 tick/broadcast: Make takeover of broadcast hrtimer reliable
| * 84033790be rtc: interface: Add RTC offset to alarm after fix-up
| * 680c7faee4 nilfs2: avoid undefined behavior in nilfs_cnt32_ge macro
| * a4b0c9fd15 fs/nilfs2: remove some unused macros to tame gcc
| * 10ba89c213 pinctrl: freescale: mxs: Fix refcount of child
| * b45432ce84 pinctrl: ti: ti-iodelay: fix possible memory leak when pinctrl_enable() fails
| * 932813248d pinctrl: ti: ti-iodelay: Drop if block with always false condition
| * 1a8e19cbc3 pinctrl: single: fix possible memory leak when pinctrl_enable() fails
| * 24d78662f1 pinctrl: core: fix possible memory leak when pinctrl_enable() fails
| * 64c0b8e64b netfilter: ctnetlink: use helper function to calculate expect ID
| * 55fa4883aa bnxt_re: Fix imm_data endianness
| * b8f7d8f4d5 macintosh/therm_windtunnel: fix module unload.
| * 38378074fa powerpc/xmon: Fix disassembly CPU feature checks
| * 28c5198369 MIPS: Octeron: remove source file executable bit
| * 8761992069 Input: elan_i2c - do not leave interrupt disabled on suspend failure
| * 6e1d3873ea RDMA/device: Return error earlier if port in not valid
| * 729109a0d5 mtd: make mtd_test.c a separate module
| * 638b75a19a ASoC: max98088: Check for clk_prepare_enable() error
| * 6e17530f5b RDMA/rxe: Don't set BTH_ACK_MASK for UC or UD QPs
| * 6607140c18 RDMA/mlx4: Fix truncated output warning in alias_GUID.c
| * 409ca91035 RDMA/mlx4: Fix truncated output warning in mad.c
| * 5e3f7847e6 Input: qt1050 - handle CHIP_ID reading error
| * 3881d0622c PCI: Fix resource double counting on remove & rescan
| * df5a9723b6 SUNRPC: Fixup gss_status tracepoint error output
| * 6922e03463 sparc64: Fix incorrect function signature and add prototype for prom_cif_init
| * 5f20a407ed ext4: avoid writing unitialized memory to disk in EA inodes
| * feed3fcb6f SUNRPC: avoid soft lockup when transmitting UDP to reachable server.
| * 72e06bedd5 mfd: omap-usb-tll: Use struct_size to allocate tll
| * 62ef8d7816 drm/qxl: Add check for drm_cvt_mode
| * 024e357a6f drm/etnaviv: fix DMA direction handling for cached RW buffers
| * 9e43e7212f perf report: Fix condition in sort__sym_cmp()
| * d1415125b7 leds: trigger: Unregister sysfs attributes before calling deactivate()
| * 3a2a9cc47d media: renesas: vsp1: Store RPF partition configuration per RPF instance
| * 4f33ef74ec media: renesas: vsp1: Fix _irqsave and _irq mix
| * 0063a2822d media: uvcvideo: Override default flags
| * c65fe17a49 media: uvcvideo: Allow entity-defined get_info and get_cur
| * f8bcdad286 saa7134: Unchecked i2c_transfer function result fixed
| * 031eda178e media: imon: Fix race getting ictx->lock
| * fce50a628e media: dvb-usb: Fix unexpected infinite loop in dvb_usb_read_remote_control()
| * 5f6aeae1e7 USB: move snd_usb_pipe_sanity_check into the USB core
| * db071a63d7 selftests: forwarding: devlink_lib: Wait for udev events after reloading
| * c90b1cd775 bna: adjust 'name' buf size of bna_tcb and bna_ccb structures
| * f071190ec3 wifi: virt_wifi: don't use strlen() in const context
| * 79957e626d gss_krb5: Fix the error handling path for crypto_sync_skcipher_setkey
| * 994fc2164a wifi: virt_wifi: avoid reporting connection success with wrong SSID
| * 94637e9927 qed: Improve the stack space of filter_config()
| * b54962dc4e perf: Prevent passing zero nr_pages to rb_alloc_aux()
| * 7d87d26bd1 perf: Fix perf_aux_size() for greater-than 32-bit size
| * 818c1f5ff3 perf/x86/intel/pt: Fix pt_topa_entry_for_page() address calculation
| * 4443bd2032 netfilter: nf_tables: rise cap on SELinux secmark context
| * 576d12ba53 ipvs: Avoid unnecessary calls to skb_is_gso_sctp
| * 8541b8ac35 net: fec: Fix FEC_ECR_EN1588 being cleared on link-down
| * c1df19258a net: fec: Refactor: #define magic constants
| * b289ebb051 wifi: cfg80211: handle 2x996 RU allocation in cfg80211_calculate_bitrate_he()
| * f0e93132c0 wifi: cfg80211: fix typo in cfg80211_calculate_bitrate_he()
| * 4dc09f6f26 mlxsw: spectrum_acl_erp: Fix object nesting warning
| * 8161263362 lib: objagg: Fix general protection fault
| * 32e4baeaae selftests/bpf: Check length of recv in test_sockmap
| * 130a1a9acb net/smc: set rmb's SG_MAX_SINGLE_ALLOC limitation only when CONFIG_ARCH_NO_SG_CHAIN is defined
| * 33749ad4da net/smc: Allow SMC-D 1MB DMB allocations
| * de9f06b37d wifi: brcmsmac: LCN PHY code is used for BCM4313 2G-only device
| * 5510183266 firmware: turris-mox-rwtm: Initialize completion before mailbox
| * 8ed886fbfb firmware: turris-mox-rwtm: Fix checking return value of wait_for_completion_timeout()
| * 65f083996e m68k: cmpxchg: Fix return value for default case in __arch_xchg()
| * 1b55044749 x86/xen: Convert comma to semicolon
| * c1588a2e51 m68k: atari: Fix TT bootup freeze / unexpected (SCU) interrupt messages
| * 5bded5a131 arm64: dts: amlogic: gx: correct hdmi clocks
| * 5c6820c5a7 arm64: dts: mediatek: mt7622: fix "emmc" pinctrl mux
| * b42123aa11 ARM: dts: imx6qdl-kontron-samx6i: fix PCIe reset polarity
| * 2623585eb5 ARM: dts: imx6qdl-kontron-samx6i: fix board reset
| * 748ee683ae ARM: dts: imx6qdl-kontron-samx6i: fix PHY reset
| * a64cd46cc2 ARM: dts: imx6qdl-kontron-samx6i: move phy reset into phy-node
| * 3ba50d9233 arm64: dts: rockchip: Increase VOP clk rate on RK3328
| * 3edf65be1f arm64: dts: qcom: msm8996: specify UFS core_clk frequencies
| * ad8c347732 arm64: dts: qcom: sdm845: add power-domain to UFS PHY
| * 5cd6721d78 hwmon: (max6697) Fix swapped temp{1,8} critical alarms
| * 9fe2069a95 hwmon: (max6697) Fix underflow when writing limit attributes
| * 47f4d2600f pwm: stm32: Always do lazy disabling
| * 894e544ba5 hwmon: (adt7475) Fix default duty on fan is disabled
| * 1df94156d9 x86/platform/iosf_mbi: Convert PCIBIOS_* return codes to errnos
| * 2ffb9d2d6f x86/pci/xen: Fix PCIBIOS_* return code handling
| * eb8baf546f x86/pci/intel_mid_pci: Fix PCIBIOS_* return code handling
| * 55942933a2 x86/of: Return consistent error type from x86_of_pci_irq_enable()
| * 2103341aef hfsplus: fix to avoid false alarm of circular locking
| * e4f2b5e6c4 platform/chrome: cros_ec_debugfs: fix wrong EC message version
| * c68d1dbfe3 EDAC, i10nm: make skx_common.o a separate module
| * 5dad7906e7 EDAC/skx_common: Add new ADXL components for 2-level memory
| * 87594d6d0e EDAC, skx: Retrieve and print retry_rd_err_log registers
| * 202f909495 EDAC, skx_common: Refactor so that we initialize "dev" in result of adxl decode.
* d82959916b Merge branch 'android11-5.4' into branch 'android11-5.4-lts'

Change-Id: Ifd78d1a1a94f7372bd77a260d7c43aaf0575b7b0
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-09-12 10:53:01 +00:00
Greg Kroah-Hartman
97009b56c6 This is the 5.4.284 stable release
-----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCAAdFiEEZH8oZUiU471FcZm+ONu9yGCSaT4FAmbirowACgkQONu9yGCS
 aT50ww//X5S6LV/0C9V3+lq0zLBl6X6D0yyNlV4KFISFWoFPo2N13uxQ6+ZQliB5
 gYNRH1b/RBJxa50LjydvCtkJTsWuraZ0uW+tx6GvsfjlC7HeRqGDzOAcFehM9Fjc
 d/nn7J32amJZ2un8Xnf/B16z+WEbBzIq8ca1K2iPb/1+JQsgDFn0LGmyzNUOrdet
 Q2fpsaAzdCa72v9CzKALpK/rgAv8PIcx2dObp3YOX7ccKumP2qWg8s4dLhzYgSZ2
 MQNy55IxBKM7xKlqDPwaBgZipfAUHPPZrHlWYwEVQNIukn9l5ymjfhj8Wv6AqbgO
 KxvSNNpOnsw7ShdczumTY0JimUxziPXVcrZMX04L1a65rWrILiCjLpWPKxIhIRyL
 MIjvVg7GOWjDes+zJaKAO/X0A9oMY/inVLVrQqfWF+igXKsfwaylEqHX/qrdALZL
 /TIE7LV3iVNRm7qq3f4T8lCOGiy+gIhEgnWomzo6caulgQtnm6qmRkAgq/Siuzj1
 AMQt8d/3RNU6EQIuBFGKtYdLo9ccU1BNW773ekF3+szvmGrwp9vlGHCLixIdJt/a
 bGp2+nBr7eOWCjj3Lcm1x3vt+GY5FHBeZJEFLQ+sgSJC16o6UxXFLJeiCLOnLmaA
 r1Q3CrCCawFWDz8MBvM6xX1/XWmattoaUilMRLkqmP0SRKWmgIg=
 =Ii83
 -----END PGP SIGNATURE-----

Merge 5.4.284 into android11-5.4-lts

Changes in 5.4.284
	drm: panel-orientation-quirks: Add quirk for OrangePi Neo
	i2c: Fix conditional for substituting empty ACPI functions
	net: usb: qmi_wwan: add MeiG Smart SRM825L
	drm/amdgpu: Fix uninitialized variable warning in amdgpu_afmt_acr
	drm/amdgpu: fix overflowed array index read warning
	drm/amd/display: Check gpio_id before used as array index
	drm/amd/display: Stop amdgpu_dm initialize when stream nums greater than 6
	drm/amd/display: Check num_valid_sets before accessing reader_wm_sets[]
	drm/amd/display: Fix Coverity INTEGER_OVERFLOW within dal_gpio_service_create
	drm/amdgpu: fix ucode out-of-bounds read warning
	drm/amdgpu: fix mc_data out-of-bounds read warning
	drm/amdkfd: Reconcile the definition and use of oem_id in struct kfd_topology_device
	apparmor: fix possible NULL pointer dereference
	ionic: fix potential irq name truncation
	usbip: Don't submit special requests twice
	usb: typec: ucsi: Fix null pointer dereference in trace
	smack: tcp: ipv4, fix incorrect labeling
	wifi: cfg80211: make hash table duplicates more survivable
	drm/amd/display: Skip wbscl_set_scaler_filter if filter is null
	media: uvcvideo: Enforce alignment of frame and interval
	block: initialize integrity buffer to zero before writing it to media
	net: set SOCK_RCU_FREE before inserting socket into hashtable
	virtio_net: Fix napi_skb_cache_put warning
	udf: Limit file size to 4TB
	i2c: Use IS_REACHABLE() for substituting empty ACPI functions
	sch/netem: fix use after free in netem_dequeue
	ASoC: dapm: Fix UAF for snd_soc_pcm_runtime object
	ALSA: hda/conexant: Add pincfg quirk to enable top speakers on Sirius devices
	ata: libata: Fix memory leak for error path in ata_host_alloc()
	irqchip/gic-v2m: Fix refcount leak in gicv2m_of_init()
	mmc: dw_mmc: Fix IDMAC operation with pages bigger than 4K
	mmc: sdhci-of-aspeed: fix module autoloading
	fuse: update stats for pages in dropped aux writeback list
	fuse: use unsigned type for getxattr/listxattr size truncation
	reset: hi6220: Add support for AO reset controller
	clk: hi6220: use CLK_OF_DECLARE_DRIVER
	clk: qcom: clk-alpha-pll: Fix the pll post div mask
	clk: qcom: clk-alpha-pll: Fix the trion pll postdiv set rate API
	ila: call nf_unregister_net_hooks() sooner
	sched: sch_cake: fix bulk flow accounting logic for host fairness
	nilfs2: fix missing cleanup on rollforward recovery error
	nilfs2: fix state management in error path of log writing function
	ALSA: hda: Add input value sanity checks to HDMI channel map controls
	smack: unix sockets: fix accept()ed socket label
	irqchip/armada-370-xp: Do not allow mapping IRQ 0 and 1
	af_unix: Remove put_pid()/put_cred() in copy_peercred().
	netfilter: nf_conncount: fix wrong variable type
	udf: Avoid excessive partition lengths
	wifi: brcmsmac: advertise MFP_CAPABLE to enable WPA3
	usb: uas: set host status byte on data completion error
	PCI: keystone: Add workaround for Errata #i2037 (AM65x SR 1.0)
	media: qcom: camss: Add check for v4l2_fwnode_endpoint_parse
	pcmcia: Use resource_size function on resource object
	can: bcm: Remove proc entry when dev is unregistered.
	igb: Fix not clearing TimeSync interrupts for 82580
	platform/x86: dell-smbios: Fix error path in dell_smbios_init()
	tcp_bpf: fix return value of tcp_bpf_sendmsg()
	cx82310_eth: re-enable ethernet mode after router reboot
	drivers/net/usb: Remove all strcpy() uses
	net: usb: don't write directly to netdev->dev_addr
	usbnet: modern method to get random MAC
	net: bridge: fdb: convert is_local to bitops
	net: bridge: fdb: convert is_static to bitops
	net: bridge: fdb: convert is_sticky to bitops
	net: bridge: fdb: convert added_by_user to bitops
	net: bridge: fdb: convert added_by_external_learn to use bitops
	net: bridge: br_fdb_external_learn_add(): always set EXT_LEARN
	net: dsa: vsc73xx: fix possible subblocks range of CAPT block
	ASoC: topology: Properly initialize soc_enum values
	dm init: Handle minors larger than 255
	iommu/vt-d: Handle volatile descriptor status read
	cgroup: Protect css->cgroup write under css_set_lock
	um: line: always fill *error_out in setup_one_line()
	devres: Initialize an uninitialized struct member
	pci/hotplug/pnv_php: Fix hotplug driver crash on Powernv
	hwmon: (adc128d818) Fix underflows seen when writing limit attributes
	hwmon: (lm95234) Fix underflows seen when writing limit attributes
	hwmon: (nct6775-core) Fix underflows seen when writing limit attributes
	hwmon: (w83627ehf) Fix underflows seen when writing limit attributes
	libbpf: Add NULL checks to bpf_object__{prev_map,next_map}
	wifi: mwifiex: Do not return unused priv in mwifiex_get_priv_by_id()
	smp: Add missing destroy_work_on_stack() call in smp_call_on_cpu()
	btrfs: replace BUG_ON with ASSERT in walk_down_proc()
	btrfs: clean up our handling of refs == 0 in snapshot delete
	PCI: Add missing bridge lock to pci_bus_lock()
	btrfs: initialize location to fix -Wmaybe-uninitialized in btrfs_lookup_dentry()
	HID: cougar: fix slab-out-of-bounds Read in cougar_report_fixup
	Input: uinput - reject requests with unreasonable number of slots
	usbnet: ipheth: race between ipheth_close and error handling
	Squashfs: sanity check symbolic link size
	of/irq: Prevent device address out-of-bounds read in interrupt map walk
	lib/generic-radix-tree.c: Fix rare race in __genradix_ptr_alloc()
	ata: pata_macio: Use WARN instead of BUG
	NFSv4: Add missing rescheduling points in nfs_client_return_marked_delegations
	staging: iio: frequency: ad9834: Validate frequency parameter value
	iio: buffer-dmaengine: fix releasing dma channel on error
	iio: fix scale application in iio_convert_raw_to_processed_unlocked
	binder: fix UAF caused by offsets overwrite
	nvmem: Fix return type of devm_nvmem_device_get() in kerneldoc
	uio_hv_generic: Fix kernel NULL pointer dereference in hv_uio_rescind
	Drivers: hv: vmbus: Fix rescind handling in uio_hv_generic
	VMCI: Fix use-after-free when removing resource in vmci_resource_remove()
	clocksource/drivers/imx-tpm: Fix return -ETIME when delta exceeds INT_MAX
	clocksource/drivers/imx-tpm: Fix next event not taking effect sometime
	clocksource/drivers/timer-of: Remove percpu irq related code
	uprobes: Use kzalloc to allocate xol area
	ring-buffer: Rename ring_buffer_read() to read_buffer_iter_advance()
	tracing: Avoid possible softlockup in tracing_iter_reset()
	nilfs2: replace snprintf in show functions with sysfs_emit
	nilfs2: protect references to superblock parameters exposed in sysfs
	ACPI: processor: Return an error if acpi_processor_get_info() fails in processor_add()
	ACPI: processor: Fix memory leaks in error paths of processor_add()
	arm64: acpi: Move get_cpu_for_acpi_id() to a header
	arm64: acpi: Harden get_cpu_for_acpi_id() against missing CPU entry
	nvmet-tcp: fix kernel crash if commands allocation fails
	drm/i915/fence: Mark debug_fence_init_onstack() with __maybe_unused
	drm/i915/fence: Mark debug_fence_free() with __maybe_unused
	rtmutex: Drop rt_mutex::wait_lock before scheduling
	net, sunrpc: Remap EPERM in case of connection failure in xs_tcp_setup_socket
	cx82310_eth: fix error return code in cx82310_bind()
	Revert "parisc: Use irq_enter_rcu() to fix warning at kernel/context_tracking.c:367"
	Linux 5.4.284

Change-Id: Iafe252fcdd21fee8cffd209d616f8af16c9f4153
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-09-12 10:37:37 +00:00
Greg Kroah-Hartman
661f109c05 Linux 5.4.284
Link: https://lore.kernel.org/r/20240910092545.737864202@linuxfoundation.org
Tested-by: Florian Fainelli <florian.fainelli@broadcom.com>
Tested-by: Harshit Mogalapalli <harshit.m.mogalapalli@oracle.com>
Tested-by: Linux Kernel Functional Testing <lkft@linaro.org>
Tested-by: Shuah Khan <skhan@linuxfoundation.org>
Link: https://lore.kernel.org/r/20240911130518.626277627@linuxfoundation.org
Tested-by: Florian Fainelli <florian.fainelli@broadcom.com>
Tested-by: Shuah Khan <skhan@linuxfoundation.org>
Tested-by: Jon Hunter <jonathanh@nvidia.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-09-12 11:03:57 +02:00
Greg Kroah-Hartman
7fcbb6aa50 Revert "parisc: Use irq_enter_rcu() to fix warning at kernel/context_tracking.c:367"
This reverts commit b62f96647b which is
commit 73cb4a2d8d7e0259f94046116727084f21e4599f upstream.

It breaks the build on parisc systems, so revert it.

Reported-by: Guenter Roeck <linux@roeck-us.net>
Link: https://lore.kernel.org/r/092aa55c-0538-41e5-8ed0-d0a96b06f32e@roeck-us.net
Reported-by: Helge Deller <deller@gmx.de>
Link: https://lore.kernel.org/r/72b133a6-c221-4906-9184-30b4e6ee4260@gmx.de
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-09-12 11:03:57 +02:00
Zhang Changzhong
7c9be2c96c cx82310_eth: fix error return code in cx82310_bind()
commit cfbaa8b33e022aca62a3f2815ffbc02874d4cb8b upstream.

Fix to return a negative error code from the error handling
case instead of 0, as done elsewhere in this function.

Fixes: ca139d76b0d9 ("cx82310_eth: re-enable ethernet mode after router reboot")
Reported-by: Hulk Robot <hulkci@huawei.com>
Signed-off-by: Zhang Changzhong <zhangchangzhong@huawei.com>
Link: https://lore.kernel.org/r/1605247627-15385-1-git-send-email-zhangchangzhong@huawei.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-09-12 11:03:57 +02:00
Daniel Borkmann
934247ea65 net, sunrpc: Remap EPERM in case of connection failure in xs_tcp_setup_socket
commit 626dfed5fa3bfb41e0dffd796032b555b69f9cde upstream.

When using a BPF program on kernel_connect(), the call can return -EPERM. This
causes xs_tcp_setup_socket() to loop forever, filling up the syslog and causing
the kernel to potentially freeze up.

Neil suggested:

  This will propagate -EPERM up into other layers which might not be ready
  to handle it. It might be safer to map EPERM to an error we would be more
  likely to expect from the network system - such as ECONNREFUSED or ENETDOWN.

ECONNREFUSED as error seems reasonable. For programs setting a different error
can be out of reach (see handling in 4fbac77d2d) in particular on kernels
which do not have f10d05966196 ("bpf: Make BPF_PROG_RUN_ARRAY return -err
instead of allow boolean"), thus given that it is better to simply remap for
consistent behavior. UDP does handle EPERM in xs_udp_send_request().

Fixes: d74bad4e74 ("bpf: Hooks for sys_connect")
Fixes: 4fbac77d2d ("bpf: Hooks for sys_bind")
Co-developed-by: Lex Siegel <usiegl00@gmail.com>
Signed-off-by: Lex Siegel <usiegl00@gmail.com>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Cc: Neil Brown <neilb@suse.de>
Cc: Trond Myklebust <trondmy@kernel.org>
Cc: Anna Schumaker <anna@kernel.org>
Link: https://github.com/cilium/cilium/issues/33395
Link: https://lore.kernel.org/bpf/171374175513.12877.8993642908082014881@noble.neil.brown.name
Link: https://patch.msgid.link/9069ec1d59e4b2129fc23433349fd5580ad43921.1720075070.git.daniel@iogearbox.net
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Hugo SIMELIERE <hsimeliere.opensource@witekio.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-09-12 11:03:57 +02:00
Roland Xu
6a976e9a47 rtmutex: Drop rt_mutex::wait_lock before scheduling
commit d33d26036a0274b472299d7dcdaa5fb34329f91b upstream.

rt_mutex_handle_deadlock() is called with rt_mutex::wait_lock held.  In the
good case it returns with the lock held and in the deadlock case it emits a
warning and goes into an endless scheduling loop with the lock held, which
triggers the 'scheduling in atomic' warning.

Unlock rt_mutex::wait_lock in the dead lock case before issuing the warning
and dropping into the schedule for ever loop.

[ tglx: Moved unlock before the WARN(), removed the pointless comment,
  	massaged changelog, added Fixes tag ]

Fixes: 3d5c9340d1 ("rtmutex: Handle deadlock detection smarter")
Signed-off-by: Roland Xu <mu001999@outlook.com>
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
Cc: stable@vger.kernel.org
Link: https://lore.kernel.org/all/ME0P300MB063599BEF0743B8FA339C2CECC802@ME0P300MB0635.AUSP300.PROD.OUTLOOK.COM
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-09-12 11:03:57 +02:00
Andy Shevchenko
2120e07966 drm/i915/fence: Mark debug_fence_free() with __maybe_unused
[ Upstream commit f99999536128b14b5d765a9982763b5134efdd79 ]

When debug_fence_free() is unused
(CONFIG_DRM_I915_SW_FENCE_DEBUG_OBJECTS=n), it prevents kernel builds
with clang, `make W=1` and CONFIG_WERROR=y:

.../i915_sw_fence.c:118:20: error: unused function 'debug_fence_free' [-Werror,-Wunused-function]
  118 | static inline void debug_fence_free(struct i915_sw_fence *fence)
      |                    ^~~~~~~~~~~~~~~~

Fix this by marking debug_fence_free() with __maybe_unused.

See also commit 6863f5643d ("kbuild: allow Clang to find unused static
inline functions for W=1 build").

Fixes: fc1584059d ("drm/i915: Integrate i915_sw_fence with debugobjects")
Signed-off-by: Andy Shevchenko <andriy.shevchenko@linux.intel.com>
Reviewed-by: Jani Nikula <jani.nikula@intel.com>
Link: https://patchwork.freedesktop.org/patch/msgid/20240829155950.1141978-3-andriy.shevchenko@linux.intel.com
Signed-off-by: Jani Nikula <jani.nikula@intel.com>
(cherry picked from commit 8be4dce5ea6f2368cc25edc71989c4690fa66964)
Signed-off-by: Joonas Lahtinen <joonas.lahtinen@linux.intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-12 11:03:57 +02:00
Andy Shevchenko
c4f8a84a2b drm/i915/fence: Mark debug_fence_init_onstack() with __maybe_unused
[ Upstream commit fcd9e8afd546f6ced378d078345a89bf346d065e ]

When debug_fence_init_onstack() is unused (CONFIG_DRM_I915_SELFTEST=n),
it prevents kernel builds with clang, `make W=1` and CONFIG_WERROR=y:

.../i915_sw_fence.c:97:20: error: unused function 'debug_fence_init_onstack' [-Werror,-Wunused-function]
   97 | static inline void debug_fence_init_onstack(struct i915_sw_fence *fence)
      |                    ^~~~~~~~~~~~~~~~~~~~~~~~

Fix this by marking debug_fence_init_onstack() with __maybe_unused.

See also commit 6863f5643d ("kbuild: allow Clang to find unused static
inline functions for W=1 build").

Fixes: 214707fc2c ("drm/i915/selftests: Wrap a timer into a i915_sw_fence")
Signed-off-by: Andy Shevchenko <andriy.shevchenko@linux.intel.com>
Reviewed-by: Jani Nikula <jani.nikula@intel.com>
Link: https://patchwork.freedesktop.org/patch/msgid/20240829155950.1141978-2-andriy.shevchenko@linux.intel.com
Signed-off-by: Jani Nikula <jani.nikula@intel.com>
(cherry picked from commit 5bf472058ffb43baf6a4cdfe1d7f58c4c194c688)
Signed-off-by: Joonas Lahtinen <joonas.lahtinen@linux.intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-12 11:03:56 +02:00
Maurizio Lombardi
03e1fd0327 nvmet-tcp: fix kernel crash if commands allocation fails
[ Upstream commit 5572a55a6f830ee3f3a994b6b962a5c327d28cb3 ]

If the commands allocation fails in nvmet_tcp_alloc_cmds()
the kernel crashes in nvmet_tcp_release_queue_work() because of
a NULL pointer dereference.

  nvmet: failed to install queue 0 cntlid 1 ret 6
  Unable to handle kernel NULL pointer dereference at
         virtual address 0000000000000008

Fix the bug by setting queue->nr_cmds to zero in case
nvmet_tcp_alloc_cmd() fails.

Fixes: 872d26a391 ("nvmet-tcp: add NVMe over TCP target driver")
Signed-off-by: Maurizio Lombardi <mlombard@redhat.com>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Keith Busch <kbusch@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-12 11:03:56 +02:00
Jonathan Cameron
f57769ff6f arm64: acpi: Harden get_cpu_for_acpi_id() against missing CPU entry
[ Upstream commit 2488444274c70038eb6b686cba5f1ce48ebb9cdd ]

In a review discussion of the changes to support vCPU hotplug where
a check was added on the GICC being enabled if was online, it was
noted that there is need to map back to the cpu and use that to index
into a cpumask. As such, a valid ID is needed.

If an MPIDR check fails in acpi_map_gic_cpu_interface() it is possible
for the entry in cpu_madt_gicc[cpu] == NULL.  This function would
then cause a NULL pointer dereference.   Whilst a path to trigger
this has not been established, harden this caller against the
possibility.

Reviewed-by: Gavin Shan <gshan@redhat.com>
Signed-off-by: Jonathan Cameron <Jonathan.Cameron@huawei.com>
Link: https://lore.kernel.org/r/20240529133446.28446-13-Jonathan.Cameron@huawei.com
Signed-off-by: Catalin Marinas <catalin.marinas@arm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-12 11:03:56 +02:00
James Morse
28ac856039 arm64: acpi: Move get_cpu_for_acpi_id() to a header
[ Upstream commit 8d34b6f17b9ac93faa2791eb037dcb08bdf755de ]

ACPI identifies CPUs by UID. get_cpu_for_acpi_id() maps the ACPI UID
to the Linux CPU number.

The helper to retrieve this mapping is only available in arm64's NUMA
code.

Move it to live next to get_acpi_id_for_cpu().

Signed-off-by: James Morse <james.morse@arm.com>
Reviewed-by: Jonathan Cameron <Jonathan.Cameron@huawei.com>
Reviewed-by: Gavin Shan <gshan@redhat.com>
Tested-by: Miguel Luis <miguel.luis@oracle.com>
Tested-by: Vishnu Pajjuri <vishnu@os.amperecomputing.com>
Tested-by: Jianyong Wu <jianyong.wu@arm.com>
Signed-off-by: Russell King (Oracle) <rmk+kernel@armlinux.org.uk>
Acked-by: Hanjun Guo <guohanjun@huawei.com>
Signed-off-by: Jonathan Cameron <Jonathan.Cameron@huawei.com>
Reviewed-by: Lorenzo Pieralisi <lpieralisi@kernel.org>
Link: https://lore.kernel.org/r/20240529133446.28446-12-Jonathan.Cameron@huawei.com
Signed-off-by: Catalin Marinas <catalin.marinas@arm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-12 11:03:56 +02:00
Jonathan Cameron
9e81f6b3eb ACPI: processor: Fix memory leaks in error paths of processor_add()
[ Upstream commit 47ec9b417ed9b6b8ec2a941cd84d9de62adc358a ]

If acpi_processor_get_info() returned an error, pr and the associated
pr->throttling.shared_cpu_map were leaked.

The unwind code was in the wrong order wrt to setup, relying on
some unwind actions having no affect (clearing variables that were
never set etc).  That makes it harder to reason about so reorder
and add appropriate labels to only undo what was actually set up
in the first place.

Acked-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Reviewed-by: Gavin Shan <gshan@redhat.com>
Signed-off-by: Jonathan Cameron <Jonathan.Cameron@huawei.com>
Link: https://lore.kernel.org/r/20240529133446.28446-6-Jonathan.Cameron@huawei.com
Signed-off-by: Catalin Marinas <catalin.marinas@arm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-12 11:03:56 +02:00
Jonathan Cameron
eaa995d0d5 ACPI: processor: Return an error if acpi_processor_get_info() fails in processor_add()
[ Upstream commit fadf231f0a06a6748a7fc4a2c29ac9ef7bca6bfd ]

Rafael observed [1] that returning 0 from processor_add() will result in
acpi_default_enumeration() being called which will attempt to create a
platform device, but that makes little sense when the processor is known
to be not available.  So just return the error code from acpi_processor_get_info()
instead.

Link: https://lore.kernel.org/all/CAJZ5v0iKU8ra9jR+EmgxbuNm=Uwx2m1-8vn_RAZ+aCiUVLe3Pw@mail.gmail.com/ [1]
Suggested-by: Rafael J. Wysocki <rafael@kernel.org>
Acked-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Reviewed-by: Gavin Shan <gshan@redhat.com>
Signed-off-by: Jonathan Cameron <Jonathan.Cameron@huawei.com>
Link: https://lore.kernel.org/r/20240529133446.28446-5-Jonathan.Cameron@huawei.com
Signed-off-by: Catalin Marinas <catalin.marinas@arm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-12 11:03:56 +02:00
Ryusuke Konishi
ba97ba173f nilfs2: protect references to superblock parameters exposed in sysfs
[ Upstream commit 683408258917541bdb294cd717c210a04381931e ]

The superblock buffers of nilfs2 can not only be overwritten at runtime
for modifications/repairs, but they are also regularly swapped, replaced
during resizing, and even abandoned when degrading to one side due to
backing device issues.  So, accessing them requires mutual exclusion using
the reader/writer semaphore "nilfs->ns_sem".

Some sysfs attribute show methods read this superblock buffer without the
necessary mutual exclusion, which can cause problems with pointer
dereferencing and memory access, so fix it.

Link: https://lkml.kernel.org/r/20240811100320.9913-1-konishi.ryusuke@gmail.com
Fixes: da7141fb78 ("nilfs2: add /sys/fs/nilfs2/<device> group")
Signed-off-by: Ryusuke Konishi <konishi.ryusuke@gmail.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-12 11:03:56 +02:00
Qing Wang
9dffb618a6 nilfs2: replace snprintf in show functions with sysfs_emit
[ Upstream commit 3bcd6c5bd483287f4a09d3d59a012d47677b6edc ]

Patch series "nilfs2 updates".

This patch (of 2):

coccicheck complains about the use of snprintf() in sysfs show functions.

Fix the coccicheck warning:

  WARNING: use scnprintf or sprintf.

Use sysfs_emit instead of scnprintf or sprintf makes more sense.

Link: https://lkml.kernel.org/r/1635151862-11547-1-git-send-email-konishi.ryusuke@gmail.com
Link: https://lkml.kernel.org/r/1634095759-4625-1-git-send-email-wangqing@vivo.com
Link: https://lkml.kernel.org/r/1635151862-11547-2-git-send-email-konishi.ryusuke@gmail.com
Signed-off-by: Qing Wang <wangqing@vivo.com>
Signed-off-by: Ryusuke Konishi <konishi.ryusuke@gmail.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Stable-dep-of: 683408258917 ("nilfs2: protect references to superblock parameters exposed in sysfs")
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-12 11:03:56 +02:00
Zheng Yejian
7195d0498d tracing: Avoid possible softlockup in tracing_iter_reset()
[ Upstream commit 49aa8a1f4d6800721c7971ed383078257f12e8f9 ]

In __tracing_open(), when max latency tracers took place on the cpu,
the time start of its buffer would be updated, then event entries with
timestamps being earlier than start of the buffer would be skipped
(see tracing_iter_reset()).

Softlockup will occur if the kernel is non-preemptible and too many
entries were skipped in the loop that reset every cpu buffer, so add
cond_resched() to avoid it.

Cc: stable@vger.kernel.org
Fixes: 2f26ebd549 ("tracing: use timestamp to determine start of latency traces")
Link: https://lore.kernel.org/20240827124654.3817443-1-zhengyejian@huaweicloud.com
Suggested-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Zheng Yejian <zhengyejian@huaweicloud.com>
Signed-off-by: Steven Rostedt (Google) <rostedt@goodmis.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-12 11:03:56 +02:00
Steven Rostedt (VMware)
2feb2c351c ring-buffer: Rename ring_buffer_read() to read_buffer_iter_advance()
[ Upstream commit bc1a72afdc4a91844928831cac85731566e03bc6 ]

When the ring buffer was first created, the iterator followed the normal
producer/consumer operations where it had both a peek() operation, that just
returned the event at the current location, and a read(), that would return
the event at the current location and also increment the iterator such that
the next peek() or read() will return the next event.

The only use of the ring_buffer_read() is currently to move the iterator to
the next location and nothing now actually reads the event it returns.
Rename this function to its actual use case to ring_buffer_iter_advance(),
which also adds the "iter" part to the name, which is more meaningful. As
the timestamp returned by ring_buffer_read() was never used, there's no
reason that this new version should bother having returning it. It will also
become a void function.

Link: http://lkml.kernel.org/r/20200317213416.018928618@goodmis.org

Signed-off-by: Steven Rostedt (VMware) <rostedt@goodmis.org>
Stable-dep-of: 49aa8a1f4d68 ("tracing: Avoid possible softlockup in tracing_iter_reset()")
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-12 11:03:56 +02:00
Sven Schnelle
c6011b495d uprobes: Use kzalloc to allocate xol area
commit e240b0fde52f33670d1336697c22d90a4fe33c84 upstream.

To prevent unitialized members, use kzalloc to allocate
the xol area.

Fixes: b059a453b1 ("x86/vdso: Add mremap hook to vm_special_mapping")
Signed-off-by: Sven Schnelle <svens@linux.ibm.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Acked-by: Oleg Nesterov <oleg@redhat.com>
Link: https://lore.kernel.org/r/20240903102313.3402529-1-svens@linux.ibm.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-09-12 11:03:56 +02:00
Daniel Lezcano
302ac43e58 clocksource/drivers/timer-of: Remove percpu irq related code
commit 471ef0b5a8aaca4296108e756b970acfc499ede4 upstream.

GCC's named address space checks errors out with:

drivers/clocksource/timer-of.c: In function ‘timer_of_irq_exit’:
drivers/clocksource/timer-of.c:29:46: error: passing argument 2 of
‘free_percpu_irq’ from pointer to non-enclosed address space
  29 |                 free_percpu_irq(of_irq->irq, clkevt);
     |                                              ^~~~~~
In file included from drivers/clocksource/timer-of.c:8:
./include/linux/interrupt.h:201:43: note: expected ‘__seg_gs void *’
but argument is of type ‘struct clock_event_device *’
 201 | extern void free_percpu_irq(unsigned int, void __percpu *);
     |                                           ^~~~~~~~~~~~~~~
drivers/clocksource/timer-of.c: In function ‘timer_of_irq_init’:
drivers/clocksource/timer-of.c:74:51: error: passing argument 4 of
‘request_percpu_irq’ from pointer to non-enclosed address space
  74 |                                    np->full_name, clkevt) :
     |                                                   ^~~~~~
./include/linux/interrupt.h:190:56: note: expected ‘__seg_gs void *’
but argument is of type ‘struct clock_event_device *’
 190 |                    const char *devname, void __percpu *percpu_dev_id)

Sparse warns about:

timer-of.c:29:46: warning: incorrect type in argument 2 (different address spaces)
timer-of.c:29:46:    expected void [noderef] __percpu *
timer-of.c:29:46:    got struct clock_event_device *clkevt
timer-of.c:74:51: warning: incorrect type in argument 4 (different address spaces)
timer-of.c:74:51:    expected void [noderef] __percpu *percpu_dev_id
timer-of.c:74:51:    got struct clock_event_device *clkevt

It appears the code is incorrect as reported by Uros Bizjak:

"The referred code is questionable as it tries to reuse
the clkevent pointer once as percpu pointer and once as generic
pointer, which should be avoided."

This change removes the percpu related code as no drivers is using it.

[Daniel: Fixed the description]

Fixes: dc11bae785 ("clocksource/drivers: Add timer-of common init routine")
Reported-by: Uros Bizjak <ubizjak@gmail.com>
Tested-by: Uros Bizjak <ubizjak@gmail.com>
Link: https://lore.kernel.org/r/20240819100335.2394751-1-daniel.lezcano@linaro.org
Signed-off-by: Daniel Lezcano <daniel.lezcano@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-09-12 11:03:56 +02:00
Jacky Bai
6b0f357bf9 clocksource/drivers/imx-tpm: Fix next event not taking effect sometime
commit 3d5c2f8e75a55cfb11a85086c71996af0354a1fb upstream.

The value written into the TPM CnV can only be updated into the hardware
when the counter increases. Additional writes to the CnV write buffer are
ignored until the register has been updated. Therefore, we need to check
if the CnV has been updated before continuing. This may require waiting for
1 counter cycle in the worst case.

Cc: stable@vger.kernel.org
Fixes: 059ab7b82e ("clocksource/drivers/imx-tpm: Add imx tpm timer support")
Signed-off-by: Jacky Bai <ping.bai@nxp.com>
Reviewed-by: Peng Fan <peng.fan@nxp.com>
Reviewed-by: Ye Li <ye.li@nxp.com>
Reviewed-by: Jason Liu <jason.hui.liu@nxp.com>
Signed-off-by: Frank Li <Frank.Li@nxp.com>
Link: https://lore.kernel.org/r/20240725193355.1436005-2-Frank.Li@nxp.com
Signed-off-by: Daniel Lezcano <daniel.lezcano@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-09-12 11:03:56 +02:00
Jacky Bai
d41b52a4f5 clocksource/drivers/imx-tpm: Fix return -ETIME when delta exceeds INT_MAX
commit 5b8843fcd49827813da80c0f590a17ae4ce93c5d upstream.

In tpm_set_next_event(delta), return -ETIME by wrong cast to int when delta
is larger than INT_MAX.

For example:

tpm_set_next_event(delta = 0xffff_fffe)
{
        ...
        next = tpm_read_counter(); // assume next is 0x10
        next += delta; // next will 0xffff_fffe + 0x10 = 0x1_0000_000e
        now = tpm_read_counter();  // now is 0x10
        ...

        return (int)(next - now) <= 0 ? -ETIME : 0;
                     ^^^^^^^^^^
                     0x1_0000_000e - 0x10 = 0xffff_fffe, which is -2 when
                     cast to int. So return -ETIME.
}

To fix this, introduce a 'prev' variable and check if 'now - prev' is
larger than delta.

Cc: stable@vger.kernel.org
Fixes: 059ab7b82e ("clocksource/drivers/imx-tpm: Add imx tpm timer support")
Signed-off-by: Jacky Bai <ping.bai@nxp.com>
Reviewed-by: Peng Fan <peng.fan@nxp.com>
Reviewed-by: Ye Li <ye.li@nxp.com>
Reviewed-by: Jason Liu <jason.hui.liu@nxp.com>
Signed-off-by: Frank Li <Frank.Li@nxp.com>
Link: https://lore.kernel.org/r/20240725193355.1436005-1-Frank.Li@nxp.com
Signed-off-by: Daniel Lezcano <daniel.lezcano@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-09-12 11:03:56 +02:00
David Fernandez Gonzalez
b243d52b5f VMCI: Fix use-after-free when removing resource in vmci_resource_remove()
commit 48b9a8dabcc3cf5f961b2ebcd8933bf9204babb7 upstream.

When removing a resource from vmci_resource_table in
vmci_resource_remove(), the search is performed using the resource
handle by comparing context and resource fields.

It is possible though to create two resources with different types
but same handle (same context and resource fields).

When trying to remove one of the resources, vmci_resource_remove()
may not remove the intended one, but the object will still be freed
as in the case of the datagram type in vmci_datagram_destroy_handle().
vmci_resource_table will still hold a pointer to this freed resource
leading to a use-after-free vulnerability.

BUG: KASAN: use-after-free in vmci_handle_is_equal include/linux/vmw_vmci_defs.h:142 [inline]
BUG: KASAN: use-after-free in vmci_resource_remove+0x3a1/0x410 drivers/misc/vmw_vmci/vmci_resource.c:147
Read of size 4 at addr ffff88801c16d800 by task syz-executor197/1592
Call Trace:
 <TASK>
 __dump_stack lib/dump_stack.c:88 [inline]
 dump_stack_lvl+0x82/0xa9 lib/dump_stack.c:106
 print_address_description.constprop.0+0x21/0x366 mm/kasan/report.c:239
 __kasan_report.cold+0x7f/0x132 mm/kasan/report.c:425
 kasan_report+0x38/0x51 mm/kasan/report.c:442
 vmci_handle_is_equal include/linux/vmw_vmci_defs.h:142 [inline]
 vmci_resource_remove+0x3a1/0x410 drivers/misc/vmw_vmci/vmci_resource.c:147
 vmci_qp_broker_detach+0x89a/0x11b9 drivers/misc/vmw_vmci/vmci_queue_pair.c:2182
 ctx_free_ctx+0x473/0xbe1 drivers/misc/vmw_vmci/vmci_context.c:444
 kref_put include/linux/kref.h:65 [inline]
 vmci_ctx_put drivers/misc/vmw_vmci/vmci_context.c:497 [inline]
 vmci_ctx_destroy+0x170/0x1d6 drivers/misc/vmw_vmci/vmci_context.c:195
 vmci_host_close+0x125/0x1ac drivers/misc/vmw_vmci/vmci_host.c:143
 __fput+0x261/0xa34 fs/file_table.c:282
 task_work_run+0xf0/0x194 kernel/task_work.c:164
 tracehook_notify_resume include/linux/tracehook.h:189 [inline]
 exit_to_user_mode_loop+0x184/0x189 kernel/entry/common.c:187
 exit_to_user_mode_prepare+0x11b/0x123 kernel/entry/common.c:220
 __syscall_exit_to_user_mode_work kernel/entry/common.c:302 [inline]
 syscall_exit_to_user_mode+0x18/0x42 kernel/entry/common.c:313
 do_syscall_64+0x41/0x85 arch/x86/entry/common.c:86
 entry_SYSCALL_64_after_hwframe+0x6e/0x0

This change ensures the type is also checked when removing
the resource from vmci_resource_table in vmci_resource_remove().

Fixes: bc63dedb7d ("VMCI: resource object implementation.")
Cc: stable@vger.kernel.org
Reported-by: George Kennedy <george.kennedy@oracle.com>
Signed-off-by: David Fernandez Gonzalez <david.fernandez.gonzalez@oracle.com>
Link: https://lore.kernel.org/r/20240828154338.754746-1-david.fernandez.gonzalez@oracle.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-09-12 11:03:55 +02:00
Naman Jain
9f0e663d83 Drivers: hv: vmbus: Fix rescind handling in uio_hv_generic
commit 6fd28941447bf2c8ca0f26fda612a1cabc41663f upstream.

Rescind offer handling relies on rescind callbacks for some of the
resources cleanup, if they are registered. It does not unregister
vmbus device for the primary channel closure, when callback is
registered. Without it, next onoffer does not come, rescind flag
remains set and device goes to unusable state.

Add logic to unregister vmbus for the primary channel in rescind callback
to ensure channel removal and relid release, and to ensure that next
onoffer can be received and handled properly.

Cc: stable@vger.kernel.org
Fixes: ca3cda6fcf ("uio_hv_generic: add rescind support")
Signed-off-by: Naman Jain <namjain@linux.microsoft.com>
Reviewed-by: Saurabh Sengar <ssengar@linux.microsoft.com>
Link: https://lore.kernel.org/r/20240829071312.1595-3-namjain@linux.microsoft.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-09-12 11:03:55 +02:00
Saurabh Sengar
f38f46da80 uio_hv_generic: Fix kernel NULL pointer dereference in hv_uio_rescind
commit fb1adbd7e50f3d2de56d0a2bb0700e2e819a329e upstream.

For primary VM Bus channels, primary_channel pointer is always NULL. This
pointer is valid only for the secondary channels. Also, rescind callback
is meant for primary channels only.

Fix NULL pointer dereference by retrieving the device_obj from the parent
for the primary channel.

Cc: stable@vger.kernel.org
Fixes: ca3cda6fcf ("uio_hv_generic: add rescind support")
Signed-off-by: Saurabh Sengar <ssengar@linux.microsoft.com>
Signed-off-by: Naman Jain <namjain@linux.microsoft.com>
Link: https://lore.kernel.org/r/20240829071312.1595-2-namjain@linux.microsoft.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-09-12 11:03:55 +02:00
Geert Uytterhoeven
e8c5ba8941 nvmem: Fix return type of devm_nvmem_device_get() in kerneldoc
commit c69f37f6559a8948d70badd2b179db7714dedd62 upstream.

devm_nvmem_device_get() returns an nvmem device, not an nvmem cell.

Fixes: e2a5402ec7 ("nvmem: Add nvmem_device based consumer apis.")
Cc: stable <stable@kernel.org>
Signed-off-by: Geert Uytterhoeven <geert+renesas@glider.be>
Signed-off-by: Srinivas Kandagatla <srinivas.kandagatla@linaro.org>
Link: https://lore.kernel.org/r/20240902142510.71096-3-srinivas.kandagatla@linaro.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-09-12 11:03:55 +02:00
Carlos Llamas
5a32bfd230 binder: fix UAF caused by offsets overwrite
commit 4df153652cc46545722879415937582028c18af5 upstream.

Binder objects are processed and copied individually into the target
buffer during transactions. Any raw data in-between these objects is
copied as well. However, this raw data copy lacks an out-of-bounds
check. If the raw data exceeds the data section size then the copy
overwrites the offsets section. This eventually triggers an error that
attempts to unwind the processed objects. However, at this point the
offsets used to index these objects are now corrupted.

Unwinding with corrupted offsets can result in decrements of arbitrary
nodes and lead to their premature release. Other users of such nodes are
left with a dangling pointer triggering a use-after-free. This issue is
made evident by the following KASAN report (trimmed):

  ==================================================================
  BUG: KASAN: slab-use-after-free in _raw_spin_lock+0xe4/0x19c
  Write of size 4 at addr ffff47fc91598f04 by task binder-util/743

  CPU: 9 UID: 0 PID: 743 Comm: binder-util Not tainted 6.11.0-rc4 #1
  Hardware name: linux,dummy-virt (DT)
  Call trace:
   _raw_spin_lock+0xe4/0x19c
   binder_free_buf+0x128/0x434
   binder_thread_write+0x8a4/0x3260
   binder_ioctl+0x18f0/0x258c
  [...]

  Allocated by task 743:
   __kmalloc_cache_noprof+0x110/0x270
   binder_new_node+0x50/0x700
   binder_transaction+0x413c/0x6da8
   binder_thread_write+0x978/0x3260
   binder_ioctl+0x18f0/0x258c
  [...]

  Freed by task 745:
   kfree+0xbc/0x208
   binder_thread_read+0x1c5c/0x37d4
   binder_ioctl+0x16d8/0x258c
  [...]
  ==================================================================

To avoid this issue, let's check that the raw data copy is within the
boundaries of the data section.

Fixes: 6d98eb95b450 ("binder: avoid potential data leakage when copying txn")
Cc: Todd Kjos <tkjos@google.com>
Cc: stable@vger.kernel.org
Signed-off-by: Carlos Llamas <cmllamas@google.com>
Link: https://lore.kernel.org/r/20240822182353.2129600-1-cmllamas@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-09-12 11:03:55 +02:00
Matteo Martelli
c8294c80b7 iio: fix scale application in iio_convert_raw_to_processed_unlocked
commit 8a3dcc970dc57b358c8db2702447bf0af4e0d83a upstream.

When the scale_type is IIO_VAL_INT_PLUS_MICRO or IIO_VAL_INT_PLUS_NANO
the scale passed as argument is only applied to the fractional part of
the value. Fix it by also multiplying the integer part by the scale
provided.

Fixes: 48e44ce0f8 ("iio:inkern: Add function to read the processed value")
Signed-off-by: Matteo Martelli <matteomartelli3@gmail.com>
Link: https://patch.msgid.link/20240730-iio-fix-scale-v1-1-6246638c8daa@gmail.com
Cc: <Stable@vger.kernel.org>
Signed-off-by: Jonathan Cameron <Jonathan.Cameron@huawei.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-09-12 11:03:55 +02:00
David Lechner
108e0ab0bc iio: buffer-dmaengine: fix releasing dma channel on error
commit 84c65d8008764a8fb4e627ff02de01ec4245f2c4 upstream.

If dma_get_slave_caps() fails, we need to release the dma channel before
returning an error to avoid leaking the channel.

Fixes: 2d6ca60f32 ("iio: Add a DMAengine framework based buffer")
Signed-off-by: David Lechner <dlechner@baylibre.com>
Link: https://patch.msgid.link/20240723-iio-fix-dmaengine-free-on-error-v1-1-2c7cbc9b92ff@baylibre.com
Cc: <Stable@vger.kernel.org>
Signed-off-by: Jonathan Cameron <Jonathan.Cameron@huawei.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-09-12 11:03:55 +02:00
Aleksandr Mishin
0e727707a2 staging: iio: frequency: ad9834: Validate frequency parameter value
commit b48aa991758999d4e8f9296c5bbe388f293ef465 upstream.

In ad9834_write_frequency() clk_get_rate() can return 0. In such case
ad9834_calc_freqreg() call will lead to division by zero. Checking
'if (fout > (clk_freq / 2))' doesn't protect in case of 'fout' is 0.
ad9834_write_frequency() is called from ad9834_write(), where fout is
taken from text buffer, which can contain any value.

Modify parameters checking.

Found by Linux Verification Center (linuxtesting.org) with SVACE.

Fixes: 12b9d5bf76 ("Staging: IIO: DDS: AD9833 / AD9834 driver")
Suggested-by: Dan Carpenter <dan.carpenter@linaro.org>
Signed-off-by: Aleksandr Mishin <amishin@t-argos.ru>
Reviewed-by: Dan Carpenter <dan.carpenter@linaro.org>
Link: https://patch.msgid.link/20240703154506.25584-1-amishin@t-argos.ru
Cc: <Stable@vger.kernel.org>
Signed-off-by: Jonathan Cameron <Jonathan.Cameron@huawei.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-09-12 11:03:55 +02:00
Trond Myklebust
d39fbfaf1a NFSv4: Add missing rescheduling points in nfs_client_return_marked_delegations
[ Upstream commit a017ad1313fc91bdf235097fd0a02f673fc7bb11 ]

We're seeing reports of soft lockups when iterating through the loops,
so let's add rescheduling points.

Signed-off-by: Trond Myklebust <trond.myklebust@hammerspace.com>
Reviewed-by: Jeff Layton <jlayton@kernel.org>
Signed-off-by: Anna Schumaker <Anna.Schumaker@Netapp.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-12 11:03:55 +02:00
Michael Ellerman
32c4fe1fd9 ata: pata_macio: Use WARN instead of BUG
[ Upstream commit d4bc0a264fb482b019c84fbc7202dd3cab059087 ]

The overflow/underflow conditions in pata_macio_qc_prep() should never
happen. But if they do there's no need to kill the system entirely, a
WARN and failing the IO request should be sufficient and might allow the
system to keep running.

Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
Signed-off-by: Damien Le Moal <dlemoal@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-12 11:03:55 +02:00
Kent Overstreet
0f27f4f445 lib/generic-radix-tree.c: Fix rare race in __genradix_ptr_alloc()
[ Upstream commit b2f11c6f3e1fc60742673b8675c95b78447f3dae ]

If we need to increase the tree depth, allocate a new node, and then
race with another thread that increased the tree depth before us, we'll
still have a preallocated node that might be used later.

If we then use that node for a new non-root node, it'll still have a
pointer to the old root instead of being zeroed - fix this by zeroing it
in the cmpxchg failure path.

Signed-off-by: Kent Overstreet <kent.overstreet@linux.dev>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-12 11:03:55 +02:00
Stefan Wiehler
defcaa426b of/irq: Prevent device address out-of-bounds read in interrupt map walk
[ Upstream commit b739dffa5d570b411d4bdf4bb9b8dfd6b7d72305 ]

When of_irq_parse_raw() is invoked with a device address smaller than
the interrupt parent node (from #address-cells property), KASAN detects
the following out-of-bounds read when populating the initial match table
(dyndbg="func of_irq_parse_* +p"):

  OF: of_irq_parse_one: dev=/soc@0/picasso/watchdog, index=0
  OF:  parent=/soc@0/pci@878000000000/gpio0@17,0, intsize=2
  OF:  intspec=4
  OF: of_irq_parse_raw: ipar=/soc@0/pci@878000000000/gpio0@17,0, size=2
  OF:  -> addrsize=3
  ==================================================================
  BUG: KASAN: slab-out-of-bounds in of_irq_parse_raw+0x2b8/0x8d0
  Read of size 4 at addr ffffff81beca5608 by task bash/764

  CPU: 1 PID: 764 Comm: bash Tainted: G           O       6.1.67-484c613561-nokia_sm_arm64 #1
  Hardware name: Unknown Unknown Product/Unknown Product, BIOS 2023.01-12.24.03-dirty 01/01/2023
  Call trace:
   dump_backtrace+0xdc/0x130
   show_stack+0x1c/0x30
   dump_stack_lvl+0x6c/0x84
   print_report+0x150/0x448
   kasan_report+0x98/0x140
   __asan_load4+0x78/0xa0
   of_irq_parse_raw+0x2b8/0x8d0
   of_irq_parse_one+0x24c/0x270
   parse_interrupts+0xc0/0x120
   of_fwnode_add_links+0x100/0x2d0
   fw_devlink_parse_fwtree+0x64/0xc0
   device_add+0xb38/0xc30
   of_device_add+0x64/0x90
   of_platform_device_create_pdata+0xd0/0x170
   of_platform_bus_create+0x244/0x600
   of_platform_notify+0x1b0/0x254
   blocking_notifier_call_chain+0x9c/0xd0
   __of_changeset_entry_notify+0x1b8/0x230
   __of_changeset_apply_notify+0x54/0xe4
   of_overlay_fdt_apply+0xc04/0xd94
   ...

  The buggy address belongs to the object at ffffff81beca5600
   which belongs to the cache kmalloc-128 of size 128
  The buggy address is located 8 bytes inside of
   128-byte region [ffffff81beca5600, ffffff81beca5680)

  The buggy address belongs to the physical page:
  page:00000000230d3d03 refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x1beca4
  head:00000000230d3d03 order:1 compound_mapcount:0 compound_pincount:0
  flags: 0x8000000000010200(slab|head|zone=2)
  raw: 8000000000010200 0000000000000000 dead000000000122 ffffff810000c300
  raw: 0000000000000000 0000000000200020 00000001ffffffff 0000000000000000
  page dumped because: kasan: bad access detected

  Memory state around the buggy address:
   ffffff81beca5500: 04 fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
   ffffff81beca5580: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
  >ffffff81beca5600: 00 fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
                        ^
   ffffff81beca5680: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
   ffffff81beca5700: 00 00 00 00 00 00 fc fc fc fc fc fc fc fc fc fc
  ==================================================================
  OF:  -> got it !

Prevent the out-of-bounds read by copying the device address into a
buffer of sufficient size.

Signed-off-by: Stefan Wiehler <stefan.wiehler@nokia.com>
Link: https://lore.kernel.org/r/20240812100652.3800963-1-stefan.wiehler@nokia.com
Signed-off-by: Rob Herring (Arm) <robh@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-12 11:03:55 +02:00
Phillip Lougher
1b9451ba6f Squashfs: sanity check symbolic link size
[ Upstream commit 810ee43d9cd245d138a2733d87a24858a23f577d ]

Syzkiller reports a "KMSAN: uninit-value in pick_link" bug.

This is caused by an uninitialised page, which is ultimately caused
by a corrupted symbolic link size read from disk.

The reason why the corrupted symlink size causes an uninitialised
page is due to the following sequence of events:

1. squashfs_read_inode() is called to read the symbolic
   link from disk.  This assigns the corrupted value
   3875536935 to inode->i_size.

2. Later squashfs_symlink_read_folio() is called, which assigns
   this corrupted value to the length variable, which being a
   signed int, overflows producing a negative number.

3. The following loop that fills in the page contents checks that
   the copied bytes is less than length, which being negative means
   the loop is skipped, producing an uninitialised page.

This patch adds a sanity check which checks that the symbolic
link size is not larger than expected.

--

Signed-off-by: Phillip Lougher <phillip@squashfs.org.uk>
Link: https://lore.kernel.org/r/20240811232821.13903-1-phillip@squashfs.org.uk
Reported-by: Lizhi Xu <lizhi.xu@windriver.com>
Reported-by: syzbot+24ac24ff58dc5b0d26b9@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/all/000000000000a90e8c061e86a76b@google.com/
V2: fix spelling mistake.
Signed-off-by: Christian Brauner <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-12 11:03:55 +02:00
Oliver Neukum
2cdbe9e5f5 usbnet: ipheth: race between ipheth_close and error handling
[ Upstream commit e5876b088ba03a62124266fa20d00e65533c7269 ]

ipheth_sndbulk_callback() can submit carrier_work
as a part of its error handling. That means that
the driver must make sure that the work is cancelled
after it has made sure that no more URB can terminate
with an error condition.

Hence the order of actions in ipheth_close() needs
to be inverted.

Signed-off-by: Oliver Neukum <oneukum@suse.com>
Signed-off-by: Foster Snowhill <forst@pen.gy>
Tested-by: Georgi Valkov <gvalkov@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-12 11:03:55 +02:00
Dmitry Torokhov
597ff93029 Input: uinput - reject requests with unreasonable number of slots
[ Upstream commit 206f533a0a7c683982af473079c4111f4a0f9f5e ]

From: Dmitry Torokhov <dmitry.torokhov@gmail.com>

When exercising uinput interface syzkaller may try setting up device
with a really large number of slots, which causes memory allocation
failure in input_mt_init_slots(). While this allocation failure is
handled properly and request is rejected, it results in syzkaller
reports. Additionally, such request may put undue burden on the
system which will try to free a lot of memory for a bogus request.

Fix it by limiting allowed number of slots to 100. This can easily
be extended if we see devices that can track more than 100 contacts.

Reported-by: Tetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp>
Reported-by: syzbot <syzbot+0122fa359a69694395d5@syzkaller.appspotmail.com>
Closes: https://syzkaller.appspot.com/bug?extid=0122fa359a69694395d5
Link: https://lore.kernel.org/r/Zqgi7NYEbpRsJfa2@google.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-12 11:03:55 +02:00
Camila Alvarez
fac3cb3c64 HID: cougar: fix slab-out-of-bounds Read in cougar_report_fixup
[ Upstream commit a6e9c391d45b5865b61e569146304cff72821a5d ]

report_fixup for the Cougar 500k Gaming Keyboard was not verifying
that the report descriptor size was correct before accessing it

Reported-by: syzbot+24c0361074799d02c452@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=24c0361074799d02c452
Signed-off-by: Camila Alvarez <cam.alvarez.i@gmail.com>
Reviewed-by: Silvan Jegen <s.jegen@gmail.com>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-12 11:03:54 +02:00
David Sterba
7ef29fada7 btrfs: initialize location to fix -Wmaybe-uninitialized in btrfs_lookup_dentry()
[ Upstream commit b8e947e9f64cac9df85a07672b658df5b2bcff07 ]

Some arch + compiler combinations report a potentially unused variable
location in btrfs_lookup_dentry(). This is a false alert as the variable
is passed by value and always valid or there's an error. The compilers
cannot probably reason about that although btrfs_inode_by_name() is in
the same file.

   >  + /kisskb/src/fs/btrfs/inode.c: error: 'location.objectid' may be used
   +uninitialized in this function [-Werror=maybe-uninitialized]:  => 5603:9
   >  + /kisskb/src/fs/btrfs/inode.c: error: 'location.type' may be used
   +uninitialized in this function [-Werror=maybe-uninitialized]:  => 5674:5

   m68k-gcc8/m68k-allmodconfig
   mips-gcc8/mips-allmodconfig
   powerpc-gcc5/powerpc-all{mod,yes}config
   powerpc-gcc5/ppc64_defconfig

Initialize it to zero, this should fix the warnings and won't change the
behaviour as btrfs_inode_by_name() accepts only a root or inode item
types, otherwise returns an error.

Reported-by: Geert Uytterhoeven <geert@linux-m68k.org>
Tested-by: Geert Uytterhoeven <geert@linux-m68k.org>
Link: https://lore.kernel.org/linux-btrfs/bd4e9928-17b3-9257-8ba7-6b7f9bbb639a@linux-m68k.org/
Reviewed-by: Qu Wenruo <wqu@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-12 11:03:54 +02:00
Dan Williams
df77a678c3 PCI: Add missing bridge lock to pci_bus_lock()
[ Upstream commit a4e772898f8bf2e7e1cf661a12c60a5612c4afab ]

One of the true positives that the cfg_access_lock lockdep effort
identified is this sequence:

  WARNING: CPU: 14 PID: 1 at drivers/pci/pci.c:4886 pci_bridge_secondary_bus_reset+0x5d/0x70
  RIP: 0010:pci_bridge_secondary_bus_reset+0x5d/0x70
  Call Trace:
   <TASK>
   ? __warn+0x8c/0x190
   ? pci_bridge_secondary_bus_reset+0x5d/0x70
   ? report_bug+0x1f8/0x200
   ? handle_bug+0x3c/0x70
   ? exc_invalid_op+0x18/0x70
   ? asm_exc_invalid_op+0x1a/0x20
   ? pci_bridge_secondary_bus_reset+0x5d/0x70
   pci_reset_bus+0x1d8/0x270
   vmd_probe+0x778/0xa10
   pci_device_probe+0x95/0x120

Where pci_reset_bus() users are triggering unlocked secondary bus resets.
Ironically pci_bus_reset(), several calls down from pci_reset_bus(), uses
pci_bus_lock() before issuing the reset which locks everything *but* the
bridge itself.

For the same motivation as adding:

  bridge = pci_upstream_bridge(dev);
  if (bridge)
    pci_dev_lock(bridge);

to pci_reset_function() for the "bus" and "cxl_bus" reset cases, add
pci_dev_lock() for @bus->self to pci_bus_lock().

Link: https://lore.kernel.org/r/171711747501.1628941.15217746952476635316.stgit@dwillia2-xfh.jf.intel.com
Reported-by: Imre Deak <imre.deak@intel.com>
Closes: http://lore.kernel.org/r/6657833b3b5ae_14984b29437@dwillia2-xfh.jf.intel.com.notmuch
Signed-off-by: Dan Williams <dan.j.williams@intel.com>
Signed-off-by: Keith Busch <kbusch@kernel.org>
[bhelgaas: squash in recursive locking deadlock fix from Keith Busch:
https://lore.kernel.org/r/20240711193650.701834-1-kbusch@meta.com]
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Tested-by: Hans de Goede <hdegoede@redhat.com>
Tested-by: Kalle Valo <kvalo@kernel.org>
Reviewed-by: Dave Jiang <dave.jiang@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-12 11:03:54 +02:00
Josef Bacik
71291aa724 btrfs: clean up our handling of refs == 0 in snapshot delete
[ Upstream commit b8ccef048354074a548f108e51d0557d6adfd3a3 ]

In reada we BUG_ON(refs == 0), which could be unkind since we aren't
holding a lock on the extent leaf and thus could get a transient
incorrect answer.  In walk_down_proc we also BUG_ON(refs == 0), which
could happen if we have extent tree corruption.  Change that to return
-EUCLEAN.  In do_walk_down() we catch this case and handle it correctly,
however we return -EIO, which -EUCLEAN is a more appropriate error code.
Finally in walk_up_proc we have the same BUG_ON(refs == 0), so convert
that to proper error handling.  Also adjust the error message so we can
actually do something with the information.

Signed-off-by: Josef Bacik <josef@toxicpanda.com>
Reviewed-by: David Sterba <dsterba@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-12 11:03:54 +02:00
Josef Bacik
7fbbb8b2b3 btrfs: replace BUG_ON with ASSERT in walk_down_proc()
[ Upstream commit 1f9d44c0a12730a24f8bb75c5e1102207413cc9b ]

We have a couple of areas where we check to make sure the tree block is
locked before looking up or messing with references.  This is old code
so it has this as BUG_ON().  Convert this to ASSERT() for developers.

Signed-off-by: Josef Bacik <josef@toxicpanda.com>
Reviewed-by: David Sterba <dsterba@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-12 11:03:54 +02:00
Zqiang
4e2c30e0df smp: Add missing destroy_work_on_stack() call in smp_call_on_cpu()
[ Upstream commit 77aeb1b685f9db73d276bad4bb30d48505a6fd23 ]

For CONFIG_DEBUG_OBJECTS_WORK=y kernels sscs.work defined by
INIT_WORK_ONSTACK() is initialized by debug_object_init_on_stack() for
the debug check in __init_work() to work correctly.

But this lacks the counterpart to remove the tracked object from debug
objects again, which will cause a debug object warning once the stack is
freed.

Add the missing destroy_work_on_stack() invocation to cure that.

[ tglx: Massaged changelog ]

Signed-off-by: Zqiang <qiang.zhang1211@gmail.com>
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
Tested-by: Paul E. McKenney <paulmck@kernel.org>
Link: https://lore.kernel.org/r/20240704065213.13559-1-qiang.zhang1211@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-12 11:03:54 +02:00
Sascha Hauer
d834433ff3 wifi: mwifiex: Do not return unused priv in mwifiex_get_priv_by_id()
[ Upstream commit c145eea2f75ff7949392aebecf7ef0a81c1f6c14 ]

mwifiex_get_priv_by_id() returns the priv pointer corresponding to
the bss_num and bss_type, but without checking if the priv is actually
currently in use.
Unused priv pointers do not have a wiphy attached to them which can
lead to NULL pointer dereferences further down the callstack.  Fix
this by returning only used priv pointers which have priv->bss_mode
set to something else than NL80211_IFTYPE_UNSPECIFIED.

Said NULL pointer dereference happened when an Accesspoint was started
with wpa_supplicant -i mlan0 with this config:

network={
        ssid="somessid"
        mode=2
        frequency=2412
        key_mgmt=WPA-PSK WPA-PSK-SHA256
        proto=RSN
        group=CCMP
        pairwise=CCMP
        psk="12345678"
}

When waiting for the AP to be established, interrupting wpa_supplicant
with <ctrl-c> and starting it again this happens:

| Unable to handle kernel NULL pointer dereference at virtual address 0000000000000140
| Mem abort info:
|   ESR = 0x0000000096000004
|   EC = 0x25: DABT (current EL), IL = 32 bits
|   SET = 0, FnV = 0
|   EA = 0, S1PTW = 0
|   FSC = 0x04: level 0 translation fault
| Data abort info:
|   ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000
|   CM = 0, WnR = 0, TnD = 0, TagAccess = 0
|   GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0
| user pgtable: 4k pages, 48-bit VAs, pgdp=0000000046d96000
| [0000000000000140] pgd=0000000000000000, p4d=0000000000000000
| Internal error: Oops: 0000000096000004 [#1] PREEMPT SMP
| Modules linked in: caam_jr caamhash_desc spidev caamalg_desc crypto_engine authenc libdes mwifiex_sdio
+mwifiex crct10dif_ce cdc_acm onboard_usb_hub fsl_imx8_ddr_perf imx8m_ddrc rtc_ds1307 lm75 rtc_snvs
+imx_sdma caam imx8mm_thermal spi_imx error imx_cpufreq_dt fuse ip_tables x_tables ipv6
| CPU: 0 PID: 8 Comm: kworker/0:1 Not tainted 6.9.0-00007-g937242013fce-dirty #18
| Hardware name: somemachine (DT)
| Workqueue: events sdio_irq_work
| pstate: 00000005 (nzcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)
| pc : mwifiex_get_cfp+0xd8/0x15c [mwifiex]
| lr : mwifiex_get_cfp+0x34/0x15c [mwifiex]
| sp : ffff8000818b3a70
| x29: ffff8000818b3a70 x28: ffff000006bfd8a5 x27: 0000000000000004
| x26: 000000000000002c x25: 0000000000001511 x24: 0000000002e86bc9
| x23: ffff000006bfd996 x22: 0000000000000004 x21: ffff000007bec000
| x20: 000000000000002c x19: 0000000000000000 x18: 0000000000000000
| x17: 000000040044ffff x16: 00500072b5503510 x15: ccc283740681e517
| x14: 0201000101006d15 x13: 0000000002e8ff43 x12: 002c01000000ffb1
| x11: 0100000000000000 x10: 02e8ff43002c0100 x9 : 0000ffb100100157
| x8 : ffff000003d20000 x7 : 00000000000002f1 x6 : 00000000ffffe124
| x5 : 0000000000000001 x4 : 0000000000000003 x3 : 0000000000000000
| x2 : 0000000000000000 x1 : 0001000000011001 x0 : 0000000000000000
| Call trace:
|  mwifiex_get_cfp+0xd8/0x15c [mwifiex]
|  mwifiex_parse_single_response_buf+0x1d0/0x504 [mwifiex]
|  mwifiex_handle_event_ext_scan_report+0x19c/0x2f8 [mwifiex]
|  mwifiex_process_sta_event+0x298/0xf0c [mwifiex]
|  mwifiex_process_event+0x110/0x238 [mwifiex]
|  mwifiex_main_process+0x428/0xa44 [mwifiex]
|  mwifiex_sdio_interrupt+0x64/0x12c [mwifiex_sdio]
|  process_sdio_pending_irqs+0x64/0x1b8
|  sdio_irq_work+0x4c/0x7c
|  process_one_work+0x148/0x2a0
|  worker_thread+0x2fc/0x40c
|  kthread+0x110/0x114
|  ret_from_fork+0x10/0x20
| Code: a94153f3 a8c37bfd d50323bf d65f03c0 (f940a000)
| ---[ end trace 0000000000000000 ]---

Signed-off-by: Sascha Hauer <s.hauer@pengutronix.de>
Acked-by: Brian Norris <briannorris@chromium.org>
Reviewed-by: Francesco Dolcini <francesco.dolcini@toradex.com>
Signed-off-by: Kalle Valo <kvalo@kernel.org>
Link: https://patch.msgid.link/20240703072409.556618-1-s.hauer@pengutronix.de
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-12 11:03:54 +02:00