Commit graph

899,837 commits

Author SHA1 Message Date
Tudor Ambarus
d4fabc5cbb UPSTREAM: net: cdc_ncm: Deal with too low values of dwNtbOutMaxSize
commit 7e01c7f7046efc2c7c192c3619db43292b98e997 upstream.

Currently in cdc_ncm_check_tx_max(), if dwNtbOutMaxSize is lower than
the calculated "min" value, but greater than zero, the logic sets
tx_max to dwNtbOutMaxSize. This is then used to allocate a new SKB in
cdc_ncm_fill_tx_frame() where all the data is handled.

For small values of dwNtbOutMaxSize the memory allocated during
alloc_skb(dwNtbOutMaxSize, GFP_ATOMIC) will have the same size, due to
how size is aligned at alloc time:
	size = SKB_DATA_ALIGN(size);
        size += SKB_DATA_ALIGN(sizeof(struct skb_shared_info));
Thus we hit the same bug that we tried to squash with
commit 2be6d4d16a084 ("net: cdc_ncm: Allow for dwNtbOutMaxSize to be unset or zero")

Low values of dwNtbOutMaxSize do not cause an issue presently because at
alloc_skb() time more memory (512b) is allocated than required for the
SKB headers alone (320b), leaving some space (512b - 320b = 192b)
for CDC data (172b).

However, if more elements (for example 3 x u64 = [24b]) were added to
one of the SKB header structs, say 'struct skb_shared_info',
increasing its original size (320b [320b aligned]) to something larger
(344b [384b aligned]), then suddenly the CDC data (172b) no longer
fits in the spare SKB data area (512b - 384b = 128b).

Consequently the SKB bounds checking semantics fails and panics:

skbuff: skb_over_panic: text:ffffffff831f755b len:184 put:172 head:ffff88811f1c6c00 data:ffff88811f1c6c00 tail:0xb8 end:0x80 dev:<NULL>
------------[ cut here ]------------
kernel BUG at net/core/skbuff.c:113!
invalid opcode: 0000 [#1] PREEMPT SMP KASAN
CPU: 0 PID: 57 Comm: kworker/0:2 Not tainted 5.15.106-syzkaller-00249-g19c0ed55a470 #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/14/2023
Workqueue: mld mld_ifc_work
RIP: 0010:skb_panic net/core/skbuff.c:113 [inline]
RIP: 0010:skb_over_panic+0x14c/0x150 net/core/skbuff.c:118
[snip]
Call Trace:
 <TASK>
 skb_put+0x151/0x210 net/core/skbuff.c:2047
 skb_put_zero include/linux/skbuff.h:2422 [inline]
 cdc_ncm_ndp16 drivers/net/usb/cdc_ncm.c:1131 [inline]
 cdc_ncm_fill_tx_frame+0x11ab/0x3da0 drivers/net/usb/cdc_ncm.c:1308
 cdc_ncm_tx_fixup+0xa3/0x100

Deal with too low values of dwNtbOutMaxSize, clamp it in the range
[USB_CDC_NCM_NTB_MIN_OUT_SIZE, CDC_NCM_NTB_MAX_SIZE_TX]. We ensure
enough data space is allocated to handle CDC data by making sure
dwNtbOutMaxSize is not smaller than USB_CDC_NCM_NTB_MIN_OUT_SIZE.

Fixes: 289507d336 ("net: cdc_ncm: use sysfs for rx/tx aggregation tuning")
Cc: stable@vger.kernel.org
Reported-by: syzbot+9f575a1f15fc0c01ed69@syzkaller.appspotmail.com
Link: https://syzkaller.appspot.com/bug?extid=b982f1059506db48409d
Link: https://lore.kernel.org/all/20211202143437.1411410-1-lee.jones@linaro.org/
Signed-off-by: Tudor Ambarus <tudor.ambarus@linaro.org>
Reviewed-by: Simon Horman <simon.horman@corigine.com>
Link: https://lore.kernel.org/r/20230517133808.1873695-2-tudor.ambarus@linaro.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Bug: 281604646
Bug: 281606231
Change-Id: Ic1d912e7bf2ba53620eb8293b68ec6046422e047
Signed-off-by: Tudor Ambarus <tudor.ambarus@linaro.org>
2023-06-05 12:35:12 +00:00
Alexander Bersenev
a9515e06cb UPSTREAM: cdc_ncm: Fix the build warning
[ Upstream commit 5d0ab06b63fc9c727a7bb72c81321c0114be540b ]

The ndp32->wLength is two bytes long, so replace cpu_to_le32 with cpu_to_le16.

Fixes: 0fa81b304a79 ("cdc_ncm: Implement the 32-bit version of NCM Transfer Block")
Signed-off-by: Alexander Bersenev <bay@hackerdom.ru>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Bug: 281604646
Bug: 281606231
Change-Id: I333ba662c27baffd30659429d160dab7e96b6f26
Signed-off-by: Tudor Ambarus <tudor.ambarus@linaro.org>
2023-06-05 12:35:12 +00:00
Alexander Bersenev
e8448852f1 UPSTREAM: cdc_ncm: Implement the 32-bit version of NCM Transfer Block
[ Upstream commit 0fa81b304a7973a499f844176ca031109487dd31 ]

The NCM specification defines two formats of transfer blocks: with 16-bit
fields (NTB-16) and with 32-bit fields (NTB-32). Currently only NTB-16 is
implemented.

This patch adds the support of NTB-32. The motivation behind this is that
some devices such as E5785 or E5885 from the current generation of Huawei
LTE routers do not support NTB-16. The previous generations of Huawei
devices are also use NTB-32 by default.

Also this patch enables NTB-32 by default for Huawei devices.

During the 2019 ValdikSS made five attempts to contact Huawei to add the
NTB-16 support to their router firmware, but they were unsuccessful.

Signed-off-by: Alexander Bersenev <bay@hackerdom.ru>
Signed-off-by: David S. Miller <davem@davemloft.net>
Stable-dep-of: 7e01c7f7046e ("net: cdc_ncm: Deal with too low values of dwNtbOutMaxSize")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Bug: 281604646
Bug: 281606231
Change-Id: Ib0ed53e78197fbc5198368814f91c197ac7e8b97
Signed-off-by: Tudor Ambarus <tudor.ambarus@linaro.org>
2023-06-05 12:35:12 +00:00
Todd Kjos
25dcbf92d4 Merge "Merge tag 'android11-5.4.242_r00' into android11-5.4" into android11-5.4 2023-05-26 17:07:00 +00:00
Greg Kroah-Hartman
3b9196f720 Merge tag 'android11-5.4.242_r00' into android11-5.4
This is the merge of the upstream LTS release of 5.4.242 into the
android11-5.4 branch.

It contains the following commits:

b57981e17b4b Merge tag 'android11-5.4.242_r00' into android11-5.4
734577d21e Merge 5.4.242 into android11-5.4-lts
ea7862c507 Linux 5.4.242
d54a9f999e ASN.1: Fix check for strdup() success
2500d7edeb iio: adc: at91-sama5d2_adc: fix an error code in at91_adc_allocate_trigger()
760c2e6dee pwm: meson: Explicitly set .polarity in .get_state()
7f2b8046da xfs: fix forkoff miscalculation related to XFS_LITINO(mp)
c27a6bb178 sctp: Call inet6_destroy_sock() via sk->sk_destruct().
97ce6cde1f dccp: Call inet6_destroy_sock() via sk->sk_destruct().
a01b75620e inet6: Remove inet6_destroy_sock() in sk->sk_prot->destroy().
9374db5bd1 tcp/udp: Call inet6_destroy_sock() in IPv6 sk->sk_destruct().
2ac4697b77 udp: Call inet6_destroy_sock() in setsockopt(IPV6_ADDRFORM).
5a62248c58 ext4: fix use-after-free in ext4_xattr_set_entry
3b0044cb28 ext4: remove duplicate definition of ext4_xattr_ibody_inline_set()
3c4fdbf368 Revert "ext4: fix use-after-free in ext4_xattr_set_entry"
ef2aab86c3 x86/purgatory: Don't generate debug info for purgatory.ro
c22aefaef8 MIPS: Define RUNTIME_DISCARD_EXIT in LD script
a5167e902b mmc: sdhci_am654: Set HIGH_SPEED_ENA for SDR12 and SDR25
1b8b54fc55 memstick: fix memory leak if card device is never registered
5ad61a5268 nilfs2: initialize unused bytes in segment summary blocks
988766b9d1 iio: light: tsl2772: fix reading proximity-diodes from device tree
5cb867f1ec xen/netback: use same error messages for same errors
903f82b1a6 nvme-tcp: fix a possible UAF when failing to allocate an io queue
34b74c32ff s390/ptrace: fix PTRACE_GET_LAST_BREAK error handling
64cd99da25 net: dsa: b53: mmap: add phy ops
89dcf0dd7a scsi: core: Improve scsi_vpd_inquiry() checks
f729b74bb4 scsi: megaraid_sas: Fix fw_crash_buffer_show()
4f4ef354f9 selftests: sigaltstack: fix -Wuninitialized
a725dddf21 Input: i8042 - add quirk for Fujitsu Lifebook A574/H
9df3f502e3 f2fs: Fix f2fs_truncate_partial_nodes ftrace event
2f3730f182 e1000e: Disable TSO on i219-LM card to increase speed
0f0a291cc5 bpf: Fix incorrect verifier pruning due to missing register precision taints
ba610df83b mlxfw: fix null-ptr-deref in mlxfw_mfa2_tlv_next()
d8e120057c i40e: fix i40e_setup_misc_vector() error handling
59fba01b6c i40e: fix accessing vsi->active_filters without holding lock
01125379e2 netfilter: nf_tables: fix ifdef to also consider nf_tables=m
7c1019391b virtio_net: bugfix overflow inside xdp_linearize_page()
35dceaeab9 net: sched: sch_qfq: prevent slab-out-of-bounds in qfq_activate_agg
d61f24a454 regulator: fan53555: Explicitly include bits header
36f098e1e4 netfilter: br_netfilter: fix recent physdev match breakage
375e445b10 arm64: dts: meson-g12-common: specify full DMC range
cb1f89fe93 ARM: dts: rockchip: fix a typo error for rk3288 spdif node
da8b283c08 Merge 5.4.241 into android11-5.4-lts
58f42ed1cd Linux 5.4.241
8795936437 xfs: force log and push AIL to clear pinned inodes when aborting mount
c76dd36875 xfs: don't reuse busy extents on extent trim
4679b73a8e xfs: consider shutdown in bmapbt cursor delete assert
9355fd118b xfs: shut down the filesystem if we screw up quota reservation
48f75df5b3 xfs: report corruption only as a regular error
3cce34ceb2 xfs: set inode size after creating symlink
e76bd6da51 xfs: fix up non-directory creation in SGID directories
ad6613c984 xfs: remove the di_version field from struct icdinode
ca4533c951 xfs: simplify a check in xfs_ioctl_setattr_check_cowextsize
e078b3de3e xfs: simplify di_flags2 inheritance in xfs_ialloc
0c553917b6 xfs: only check the superblock version for dinode size calculation
90aab52d06 xfs: add a new xfs_sb_version_has_v3inode helper
edd36a57b4 xfs: remove the kuid/kgid conversion wrappers
3ef81874f7 xfs: remove the icdinode di_uid/di_gid members
cc508a41ae xfs: ensure that the inode uid/gid match values match the icdinode ones
7a9dc79771 xfs: merge the projid fields in struct xfs_icdinode
4f3252e7e1 xfs: show the proper user quota options
799cafa4f3 coresight-etm4: Fix for() loop drvdata->nr_addr_cmp range bug
440bdc49f7 watchdog: sbsa_wdog: Make sure the timeout programming is within the limits
70ca826d3d i2c: ocores: generate stop condition after timeout in polling mode
5fb5bdcdcd ubi: Fix deadlock caused by recursively holding work_sem
0b27716f2d mtd: ubi: wl: Fix a couple of kernel-doc issues
e55588c442 ubi: Fix failure attaching when vid_hdr offset equals to (sub)page size
a652c30fa2 asymmetric_keys: log on fatal failures in PE/pkcs7
5809dbacc4 verify_pefile: relax wrapper length check
0213f027d0 drm: panel-orientation-quirks: Add quirk for Lenovo Yoga Book X90F
b3052e5d46 efi: sysfb_efi: Add quirk for Lenovo Yoga Book X91F/L
02a78e6539 i2c: imx-lpi2c: clean rx/tx buffers upon new message
1ef5639744 power: supply: cros_usbpd: reclassify "default case!" as debug
7169d16388 net: macb: fix a memory corruption in extended buffer descriptor mode
c39fa0398a udp6: fix potential access to stale information
9c46c49ad3 RDMA/core: Fix GID entry ref leak when create_ah fails
ad831a7079 sctp: fix a potential overflow in sctp_ifwdtsn_skip
afffe0d1e6 qlcnic: check pci_reset_function result
a841f6a0a3 niu: Fix missing unwind goto in niu_alloc_channels()
fcd084e199 9p/xen : Fix use after free bug in xen_9pfs_front_remove due to race condition
1b77cb6f5e mtd: rawnand: stm32_fmc2: remove unsupported EDO mode
4c1d882b53 mtd: rawnand: meson: fix bitmask for length in command word
2667460034 mtdblock: tolerate corrected bit-flips
50dbfd9dac btrfs: fix fast csum implementation detection
c6db5f2a31 btrfs: print checksum type and implementation at mount time
8a99e6200c Bluetooth: Fix race condition in hidp_session_thread
c024219925 Bluetooth: L2CAP: Fix use-after-free in l2cap_disconnect_{req,rsp}
9025cea8e0 ALSA: hda/sigmatel: fix S/PDIF out on Intel D*45* motherboards
4d419195d6 ALSA: firewire-tascam: add missing unwind goto in snd_tscm_stream_start_duplex()
fe158eeccc ALSA: i2c/cs8427: fix iec958 mixer control deactivation
aa23fa32e5 ALSA: hda/sigmatel: add pin overrides for Intel DP45SG motherboard
62ccf2e0b1 ALSA: emu10k1: fix capture interrupt handler unlinking
9a3ba7b24d Revert "pinctrl: amd: Disable and mask interrupts on resume"
2945f948aa irqdomain: Fix mapping-creation race
e8f3aea716 irqdomain: Refactor __irq_domain_alloc_irqs()
3804f265c1 irqdomain: Look for existing mapping only once
e7bba7ddb4 mm/swap: fix swap_info_struct race between swapoff and get_swap_pages()
fd644712bc ring-buffer: Fix race while reader and writer are on the same page
c208b4321e drm/panfrost: Fix the panfrost_mmu_map_fault_addr() error path
c381527918 net_sched: prevent NULL dereference if default qdisc setup failed
987f599fc5 tracing: Free error logs of tracing instances
d2136f0569 can: j1939: j1939_tp_tx_dat_new(): fix out-of-bounds memory access
5a74a75fc3 ftrace: Mark get_lock_parent_ip() __always_inline
95bbfeb4ff perf/core: Fix the same task check in perf_event_set_output
666c25d35e ALSA: hda/realtek: Add quirk for Clevo X370SNW
83b16a60e4 nilfs2: fix sysfs interface lifetime
613bf23c07 nilfs2: fix potential UAF of struct nilfs_sc_info in nilfs_segctor_thread()
aa8e50688d tty: serial: fsl_lpuart: avoid checking for transfer complete when UARTCTRL_SBK is asserted in lpuart32_tx_empty
aabba44404 tty: serial: sh-sci: Fix Rx on RZ/G2L SCI
209ab5c234 tty: serial: sh-sci: Fix transmit end interrupt handler
9a2a6443d6 iio: dac: cio-dac: Fix max DAC write value check for 12-bit
e469ebb28d iio: adc: ti-ads7950: Set `can_sleep` flag for GPIO chip
abc5b4f8cd USB: serial: option: add Quectel RM500U-CN modem
b9c11537ef USB: serial: option: add Telit FE990 compositions
38c00a22d6 usb: typec: altmodes/displayport: Fix configure initial pin assignment
f417d3fea3 USB: serial: cp210x: add Silicon Labs IFS-USB-DATACABLE IDs
47132be17d xhci: also avoid the XHCI_ZERO_64B_REGS quirk with a passthrough iommu
5fccf2c546 NFSD: callback request does not use correct credential for AUTH_SYS
3686380d9d sunrpc: only free unix grouplist after RCU settles
1627119153 gpio: davinci: Add irq chip flag to skip set wake
0cf600ca1b ipv6: Fix an uninit variable access bug in __ip6_make_skb()
0443fff49d sctp: check send stream number after wait_for_sndbuf
93f3885211 net: don't let netpoll invoke NAPI if in xmit context
0d2fa30078 icmp: guard against too small mtu
a3593082e0 wifi: mac80211: fix invalid drv_sta_pre_rcu_remove calls for non-uploaded sta
4220f83b9f pwm: sprd: Explicitly set .polarity in .get_state()
6e1f29397d pwm: cros-ec: Explicitly set .polarity in .get_state()
dbd764e9d4 pinctrl: amd: Disable and mask interrupts on resume
dd7e19f97f pinctrl: amd: disable and mask interrupts on probe
3f3e4bd3f0 pinctrl: amd: Use irqchip template
387236b9e0 smb3: fix problem with null cifs super block with previous patch
2e64d7b182 treewide: Replace DECLARE_TASKLET() with DECLARE_TASKLET_OLD()
199197660b Revert "treewide: Replace DECLARE_TASKLET() with DECLARE_TASKLET_OLD()"
522af69af2 cgroup/cpuset: Wake up cpuset_attach_wq tasks in cpuset_cancel_attach()
4311ae04b3 x86/PCI: Add quirk for AMD XHCI controller that loses MSI-X state in D3hot
110d425cdf scsi: ses: Handle enclosure with just a primary component gracefully
974e2ad014 Merge 5.4.240 into android11-5.4-lts
32bea3bac5 Linux 5.4.240
4d4cb76636 gfs2: Always check inode size of inline inodes
928240c368 firmware: arm_scmi: Fix device node validation for mailbox transport
0f5c0e0a4c net: sched: fix race condition in qdisc_graft()
22d95b5449 net_sched: add __rcu annotation to netdev->qdisc
14b6ad56df ext4: fix kernel BUG in 'ext4_write_inline_data_end()'
9b189af357 btrfs: scan device in non-exclusive mode
45a9877d6c s390/uaccess: add missing earlyclobber annotations to __clear_user()
0c6df53647 drm/etnaviv: fix reference leak when mmaping imported buffer
37958ac31f ALSA: usb-audio: Fix regression on detection of Roland VS-100
6dabafd829 ALSA: hda/conexant: Partial revert of a quirk for Lenovo
f3a6726878 NFSv4: Fix hangs when recovering open state after a server reboot
c81e2965a9 pinctrl: at91-pio4: fix domain name assignment
82c25ac3a2 xen/netback: don't do grant copy across page boundary
99c8ba920f Input: goodix - add Lenovo Yoga Book X90F to nine_bytes_report DMI table
657d7c215c cifs: fix DFS traversal oops without CONFIG_CIFS_DFS_UPCALL
03af69bd67 cifs: prevent infinite recursion in CIFSGetDFSRefer()
51d6573711 Input: focaltech - use explicitly signed char type
f0f85f5e40 Input: alps - fix compatibility with -funsigned-char
7e71d4d190 pinctrl: ocelot: Fix alt mode for ocelot
70728d639e net: mvneta: make tx buffer array agnostic
704e06b979 net: dsa: mv88e6xxx: Enable IGMP snooping on user ports only
fd7cff5066 bnxt_en: Fix typo in PCI id to device description string mapping
58279cea0b i40e: fix registers dump after run ethtool adapter self test
5195de1d5f s390/vfio-ap: fix memory leak in vfio_ap device driver
78bc7f0ab9 can: bcm: bcm_tx_setup(): fix KMSAN uninit-value in vfs_write
105cc26832 net/net_failover: fix txq exceeding warning
e633fd26ab regulator: Handle deferred clk
be7b622cd6 regulator: fix spelling mistake "Cant" -> "Can't"
46c4993a15 ptp_qoriq: fix memory leak in probe()
c122daa0fa scsi: megaraid_sas: Fix crash after a double completion
317c07d382 mtd: rawnand: meson: invalidate cache on polling ECC bit
d65de5ee8b mips: bmips: BCM6358: disable RAC flush for TP1
9690e34f22 dma-mapping: drop the dev argument to arch_sync_dma_for_*
f6e2d76aa3 ca8210: Fix unsigned mac_len comparison with zero in ca8210_skb_tx()
856fb74f60 fbdev: au1200fb: Fix potential divide by zero
deef33c081 fbdev: lxfb: Fix potential divide by zero
4f5cc5ffa8 fbdev: intelfb: Fix potential divide by zero
868f247e47 fbdev: nvidia: Fix potential divide by zero
f3359f5fc9 sched_getaffinity: don't assume 'cpumask_size()' is fully initialized
521877bf26 fbdev: tgafb: Fix potential divide by zero
7f12f99b80 ALSA: hda/ca0132: fixup buffer overrun at tuning_ctl_set()
9155a5958e ALSA: asihpi: check pao in control_message()
88a3c63a96 md: avoid signed overflow in slot_store()
9966fc59d3 bus: imx-weim: fix branch condition evaluates to a garbage value
d121f7883a fsverity: don't drop pagecache at end of FS_IOC_ENABLE_VERITY
4c24eb49ab ocfs2: fix data corruption after failed write
0c0e566f03 tun: avoid double free in tun_free_netdev
d253120a58 sched/fair: Sanitize vruntime of entity being migrated
c23928c70b sched/fair: sanitize vruntime of entity being placed
885c28ceae dm crypt: add cond_resched() to dmcrypt_write()
4a32a9a818 dm stats: check for and propagate alloc_percpu failure
f8cbad984b i2c: xgene-slimpro: Fix out-of-bounds bug in xgene_slimpro_i2c_xfer()
8f5cbf6a8c nilfs2: fix kernel-infoleak in nilfs_ioctl_wrap_copy()
4ae966a7f6 wifi: mac80211: fix qos on mesh interfaces
f558789a88 usb: chipidea: core: fix possible concurrent when switch role
6b3287b147 usb: chipdea: core: fix return -EINVAL if request role is the same with current role
0b2a56fe46 usb: cdns3: Fix issue with using incorrect PCI device function
e9e93fdfce dm thin: fix deadlock when swapping to thin device
cd1e320ac0 igb: revert rtnl_lock() that causes deadlock
123698a5c6 fsverity: Remove WQ_UNBOUND from fsverity read workqueue
0eda2004f3 usb: gadget: u_audio: don't let userspace block driver unbind
44f080d7d7 scsi: core: Add BLIST_SKIP_VPD_PAGES for SKhynix H28U74301AMR
223274d5c3 cifs: empty interface list when server doesn't support query interfaces
299a309b98 sh: sanitize the flags on sigreturn
f4c610f6ca net: usb: qmi_wwan: add Telit 0x1080 composition
e6b1fa6d06 net: usb: cdc_mbim: avoid altsetting toggling for Telit FE990
04f4a1aa94 scsi: lpfc: Avoid usage of list iterator variable after loop
11cdced6a0 scsi: ufs: core: Add soft dependency on governor_simpleondemand
54ec697e3c scsi: target: iscsi: Fix an error message in iscsi_check_key()
9711522191 selftests/bpf: check that modifier resolves after pointer
2100e37425 m68k: Only force 030 bus error if PC not in exception table
d2b3bd0d4c ca8210: fix mac_len negative array access
9e7723b684 riscv: Bump COMMAND_LINE_SIZE value to 1024
32518cd0fc thunderbolt: Use const qualifier for `ring_interrupt_index`
b40fe2e1f9 uas: Add US_FL_NO_REPORT_OPCODES for JMicron JMS583Gen 2
9189f20b4c scsi: qla2xxx: Perform lockless command completion in abort path
da0383f0e8 hwmon (it87): Fix voltage scaling for chips with 10.9mV ADCs
13493ad6a2 platform/chrome: cros_ec_chardev: fix kernel data leak from ioctl
a18fb433ce Bluetooth: btsdio: fix use after free bug in btsdio_remove due to unfinished work
b517808795 Bluetooth: btqcomsmd: Fix command timeout after setting BD address
dcd4d36462 net: mdio: thunder: Add missing fwnode_handle_put()
707335918f hvc/xen: prevent concurrent accesses to the shared ring
83e442eba3 nvme-tcp: fix nvme_tcp_term_pdu to match spec
d673ae1840 net/sonic: use dma_mapping_error() for error check
b72f453e88 erspan: do not use skb_mac_header() in ndo_start_xmit()
82e07cc5a6 atm: idt77252: fix kmemleak when rmmod idt77252
fd6f643dea net/mlx5: Read the TC mapping of all priorities on ETS query
d69c2ded95 bpf: Adjust insufficient default bpf_jit_limit
97674f4cd0 keys: Do not cache key in task struct if key is requested from kernel thread
f8ee2c8b0d net/ps3_gelic_net: Use dma_mapping_error
6d7e18b1d0 net/ps3_gelic_net: Fix RX sk_buff length
0e5c7d00ec net: qcom/emac: Fix use after free bug in emac_remove due to race condition
a07ec453e8 xirc2ps_cs: Fix use after free bug in xirc2ps_detach
42d72c6d1e qed/qed_sriov: guard against NULL derefs from qed_iov_get_vf_info
f2111c791d net: usb: smsc95xx: Limit packet length to skb->len
5c4d71424d scsi: scsi_dh_alua: Fix memleak for 'qdata' in alua_activate()
283fdc5cfb i2c: imx-lpi2c: check only for enabled interrupt flags
90116b8289 igbvf: Regard vf reset nack as success
584771762c intel/igbvf: free irq on the error path in igbvf_request_msix()
6999f85418 iavf: fix non-tunneled IPv6 UDP packet type and hashing
4e752d2bae iavf: fix inverted Rx hash condition leading to disabled hash
6fe078c286 power: supply: da9150: Fix use after free bug in da9150_charger_remove due to race condition
754838aa02 net: tls: fix possible race condition between do_tls_getsockopt_conf() and do_tls_setsockopt_conf()
a03da9c9ae Merge 5.4.239 into android11-5.4-lts
09b1a76e78 Linux 5.4.239
f0c95f229a selftests: Fix the executable permissions for fib_tests.sh
1221512b02 BACKPORT: mac80211_hwsim: notify wmediumd of used MAC addresses
8ac436fa26 FROMGIT: mac80211_hwsim: add concurrent channels scanning support over virtio
b6d6caabaf Merge branch 'android11-5.4' into android11-5.4-lts
5fd4376e12 Revert "HID: core: Provide new max_buffer_size attribute to over-ride the default"
6efc429d3f Revert "HID: uhid: Over-ride the default maximum data buffer value with our own"
1e58c0c8e9 Merge 5.4.238 into android11-5.4-lts
6849d8c4a6 Linux 5.4.238
eb7716a054 HID: uhid: Over-ride the default maximum data buffer value with our own
b687ac70e6 HID: core: Provide new max_buffer_size attribute to over-ride the default
144019e813 PCI: Unify delay handling for reset and resume
d2130f37a4 s390/ipl: add missing intersection check to ipl_report handling
3f5a833dca serial: 8250_em: Fix UART port type
c5afb97d1b drm/i915: Don't use stolen memory for ring buffers with LLC
8d26a4fecc x86/mm: Fix use of uninitialized buffer in sme_enable()
a976ff743e fbdev: stifb: Provide valid pixelclock and add fb_check_var() checks
ac58b88ccb ftrace: Fix invalid address access in lookup_rec() when index is 0
65e4c9a6d0 KVM: nVMX: add missing consistency checks for CR0 and CR4
6fe55dce9d tracing: Make tracepoint lockdep check actually test something
780f69a268 tracing: Check field value in hist_field_name()
f1e3a20c60 interconnect: fix mem leak when freeing nodes
325608ab60 tty: serial: fsl_lpuart: skip waiting for transmission complete when UARTCTRL_SBK is asserted
c16cbd8233 ext4: fix possible double unlock when moving a directory
6a1bd14d5e sh: intc: Avoid spurious sizeof-pointer-div warning
bbf5eada43 drm/amdkfd: Fix an illegal memory access
2c96c52aea ext4: fix task hung in ext4_xattr_delete_inode
20ba6f8a80 ext4: fail ext4_iget if special inode unallocated
ab519e2989 jffs2: correct logic when creating a hole in jffs2_write_begin
00bfc67c65 mmc: atmel-mci: fix race between stop command and start of next command
75f6faae2d media: m5mols: fix off-by-one loop termination error
9eb394919c hwmon: (ina3221) return prober error code
26c176ce90 hwmon: (xgene) Fix use after free bug in xgene_hwmon_remove due to race condition
13efd488d3 hwmon: (adt7475) Fix masking of hysteresis registers
0d3095e958 hwmon: (adt7475) Display smoothing attributes in correct order
674fce59d6 ethernet: sun: add check for the mdesc_grab()
71da5991b6 net/iucv: Fix size of interrupt data
e0d07a3203 net: usb: smsc75xx: Move packet length check to prevent kernel panic in skb_pull
5c06bd3de1 ipv4: Fix incorrect table ID in IOCTL path
c4fcfbf80c block: sunvdc: add check for mdesc_grab() returning NULL
04c3942088 nvmet: avoid potential UAF in nvmet_req_complete()
9fabdd7905 net: usb: smsc75xx: Limit packet length to skb->len
b0c202a8dc nfc: st-nci: Fix use after free bug in ndlc_remove due to race condition
668de67d41 net: phy: smsc: bail out in lan87xx_read_status if genphy_read_status fails
5aaab217c8 net: tunnels: annotate lockless accesses to dev->needed_headroom
cba20ade78 qed/qed_dev: guard against a possible division by zero
6e18f66b70 i40e: Fix kernel crash during reboot when adapter is in recovery mode
f0216046ae ipvlan: Make skb->skb_iif track skb->dev for l3s mode
0f9c1f26d4 nfc: pn533: initialize struct pn533_out_arg properly
442aa78ed7 tcp: tcp_make_synack() can be called from process context
88c3d3bb64 scsi: core: Fix a procfs host directory removal regression
4b4f5e34f0 scsi: core: Fix a comment in function scsi_host_dev_release()
0d59732f2a netfilter: nft_redir: correct value of inet type `.maxattrs`
90279211e9 ALSA: hda: Match only Intel devices with CONTROLLER_IN_GPU()
0b7057c523 ALSA: hda: Add Intel DG2 PCI ID and HDMI codec vid
5bb9fcaadb ALSA: hda: Add Alderlake-S PCI ID and HDMI codec vid
9efbdc743d ALSA: hda - controller is in GPU on the DG1
fc52e51c2c ALSA: hda - add Intel DG1 PCI and HDMI ids
090305c361 scsi: mpt3sas: Fix NULL pointer access in mpt3sas_transport_port_add()
b8849e31a0 docs: Correct missing "d_" prefix for dentry_operations member d_weak_revalidate
9e45e45715 clk: HI655X: select REGMAP instead of depending on it
dac08e46f0 drm/meson: fix 1px pink line on GXM when scaling video overlay
d7e48aa17a cifs: Move the in_send statistic to __smb_send_rqst()
06c208002d drm/panfrost: Don't sync rpm suspension after mmu flushing
c9900d1d86 xfrm: Allow transport-mode states with AF_UNSPEC selector
4008fb9ad4 ext4: fix cgroup writeback accounting with fs-layer encryption
6eb1bfc752 ANDROID: preserve CRC for __irq_domain_add()
812963276d Merge 5.4.237 into android11-5.4-lts
fd02046fbd Merge 5.4.236 into android11-5.4-lts
48b8328041 Revert "drm/exynos: Don't reset bridge->next"
7edc66298a Revert "drm/bridge: Rename bridge helpers targeting a bridge chain"
8d15e5fac1 Revert "drm/bridge: Introduce drm_bridge_get_next_bridge()"
aac98e0c73 Revert "drm: Initialize struct drm_crtc_state.no_vblank from device settings"
af8848e0d9 Revert "drm/msm/mdp5: Add check for kzalloc"
e4b5c766f5 Linux 5.4.237
6a16810068 s390/dasd: add missing discipline function
7a934a77f1 UML: define RUNTIME_DISCARD_EXIT
87fcce7a6f sh: define RUNTIME_DISCARD_EXIT
eb9dbb70cd s390: define RUNTIME_DISCARD_EXIT to fix link error with GNU ld < 2.36
219cc98501 powerpc/vmlinux.lds: Don't discard .rela* for relocatable builds
4eede1173f powerpc/vmlinux.lds: Define RUNTIME_DISCARD_EXIT
d0fcf59038 arch: fix broken BuildID for arm64 and riscv
a4bd6d4df3 x86, vmlinux.lds: Add RUNTIME_DISCARD_EXIT to generic DISCARDS
1aed78cfda drm/i915: Don't use BAR mappings for ring buffers with LLC
52fc917855 ipmi:watchdog: Set panic count to proper value on a panic
dbfae25b01 ipmi/watchdog: replace atomic_add() and atomic_sub()
f266cdd679 media: ov5640: Fix analogue gain control
fc9bc83150 PCI: Add SolidRun vendor ID
094a073605 macintosh: windfarm: Use unsigned type for 1-bit bitfields
737985dbcb alpha: fix R_ALPHA_LITERAL reloc for large modules
2fea235ef0 MIPS: Fix a compilation issue
6b06c4ae64 ext4: Fix deadlock during directory rename
a99a61d9e1 riscv: Use READ_ONCE_NOCHECK in imprecise unwinding stack mode
1a517302db net/smc: fix fallback failed while sendmsg with fastopen
3a747490f9 scsi: megaraid_sas: Update max supported LD IDs to 240
d800996fcf btf: fix resolving BTF_KIND_VAR after ARRAY, STRUCT, UNION, PTR
9f2e063dcb netfilter: tproxy: fix deadlock due to missing BH disable
16f3aae1aa bnxt_en: Avoid order-5 memory allocation for TPA data
9dc16be373 net: caif: Fix use-after-free in cfusbl_device_notify()
8018aa0863 net: lan78xx: fix accessing the LAN7800's internal phy specific registers from the MAC driver
1c618f150c net: usb: lan78xx: Remove lots of set but unused 'ret' variables
e4e5006c13 selftests: nft_nat: ensuring the listening side is up before starting the client
783f218940 ila: do not generate empty messages in ila_xlat_nl_cmd_get_mapping()
0a3664a105 nfc: fdp: add null check of devm_kmalloc_array in fdp_nci_i2c_read_device_properties
43f33642f2 drm/msm/a5xx: fix setting of the CP_PREEMPT_ENABLE_LOCAL register
8dac5a63cf ext4: Fix possible corruption when moving a directory
891a3cba42 scsi: core: Remove the /proc/scsi/${proc_name} directory earlier
57f78226b1 cifs: Fix uninitialized memory read in smb3_qfs_tcon()
a6e44cb215 SMB3: Backup intent flag missing from some more ops
1b48c70fee iommu/vt-d: Fix PASID directory pointer coherency
985d9fa06b irqdomain: Fix domain registration race
01ed8ff22a irqdomain: Change the type of 'size' in __irq_domain_add() to be consistent
36c5682cbb ipmi:ssif: Add a timer between request retries
e8ba1b693a ipmi:ssif: Increase the message retry time
89fb3fa848 ipmi:ssif: Remove rtc_us_timer
d1a7f56b20 ipmi:ssif: resend_msg() cannot fail
59349bfcff ipmi:ssif: make ssif_i2c_send() void
5e97dc748d iommu/amd: Add a length limitation for the ivrs_acpihid command-line parameter
774c63f536 iommu/amd: Fix ill-formed ivrs_ioapic, ivrs_hpet and ivrs_acpihid options
11852cc78f iommu/amd: Add PCI segment support for ivrs_[ioapic/hpet/acpihid] commands
3cdf19a29c nfc: change order inside nfc_se_io error path
0d8a6c9a64 ext4: zero i_disksize when initializing the bootloader inode
74d775083e ext4: fix WARNING in ext4_update_inline_data
b36093c6f7 ext4: move where set the MAY_INLINE_DATA flag is set
c24f838493 ext4: fix another off-by-one fsmap error on 1k block filesystems
aee90b0278 ext4: fix RENAME_WHITEOUT handling for inline directories
1277ba3db6 drm/connector: print max_requested_bpc in state debugfs
e40c1e9da1 x86/CPU/AMD: Disable XSAVES on AMD family 0x17
6631c8da02 fs: prevent out-of-bounds array speculation when closing a file descriptor
b829e8b6e1 Linux 5.4.236
6e55d84223 staging: rtl8192e: Remove call_usermodehelper starting RadioPower.sh
9498448b9e staging: rtl8192e: Remove function ..dm_check_ac_dc_power calling a script
6ee84b8b79 wifi: cfg80211: Partial revert "wifi: cfg80211: Fix use after free for wext"
0d9d32f54c Merge 5.4.235 into android11-5.4-lts
126ee8982b Linux 5.4.235
d03bc164f3 dt-bindings: rtc: sun6i-a31-rtc: Loosen the requirements on the clocks
6ab6705463 media: uvcvideo: Fix race condition with usb_kill_urb
0b8962c64b media: uvcvideo: Provide sync and async uvc_ctrl_status_event
2b1c5145b0 tcp: Fix listen() regression in 5.4.229.
800a1c4c8a Bluetooth: hci_sock: purge socket queues in the destruct() callback
27c64d90d9 x86/resctl: fix scheduler confusion with 'current'
81da72aaf5 x86/resctrl: Apply READ_ONCE/WRITE_ONCE to task_struct.{rmid,closid}
bde541a57b net: tls: avoid hanging tasks on the tx_lock
d94fbfcd9a phy: rockchip-typec: Fix unsigned comparison with less than zero
f0ee43d61d PCI: Add ACS quirk for Wangxun NICs
f6d3aee1c6 kernel/fail_function: fix memory leak with using debugfs_lookup()
195c1e9f45 usb: uvc: Enumerate valid values for color matching
da4e715a46 USB: ene_usb6250: Allocate enough memory for full object
1170979668 usb: host: xhci: mvebu: Iterate over array indexes instead of using pointer math
f5b76a8166 iio: accel: mma9551_core: Prevent uninitialized variable in mma9551_read_config_word()
11b4b3b769 iio: accel: mma9551_core: Prevent uninitialized variable in mma9551_read_status_word()
b854c66dd7 tools/iio/iio_utils:fix memory leak
ea9b587896 mei: bus-fixup:upon error print return values of send and receive
c7ca2ca12a tty: serial: fsl_lpuart: disable the CTS when send break signal
953a4a352a tty: fix out-of-bounds access in tty_driver_lookup_tty()
70369a1117 staging: emxx_udc: Add checks for dma_alloc_coherent()
2072ed7c1a media: uvcvideo: Silence memcpy() run-time false positive warnings
e2cc773f1f media: uvcvideo: Quirk for autosuspend in Logitech B910 and C910
e4c535ecce media: uvcvideo: Handle errors from calls to usb_string
4e4e6ca62e media: uvcvideo: Handle cameras with invalid descriptors
7195e642b4 mfd: arizona: Use pm_runtime_resume_and_get() to prevent refcnt leak
fde59e273b firmware/efi sysfb_efi: Add quirk for Lenovo IdeaPad Duet 3
2cc6a3e98f tracing: Add NULL checks for buffer in ring_buffer_free_read_page()
4cfeb55a10 thermal: intel: BXT_PMIC: select REGMAP instead of depending on it
e23f1d9e6e thermal: intel: quark_dts: fix error pointer dereference
584f664c57 scsi: ipr: Work around fortify-string warning
e93bda4ebb rtc: sun6i: Always export the internal oscillator
728b047f4c rtc: sun6i: Make external 32k oscillator optional
9c7c1cf29f vc_screen: modify vcs_size() handling in vcs_read()
821362a2df tcp: tcp_check_req() can be called from process context
77606e383e ARM: dts: spear320-hmi: correct STMPE GPIO compatible
dda4f0a424 net/sched: act_sample: fix action bind logic
271eed1736 nfc: fix memory leak of se_io context in nfc_genl_se_io
f81af781f9 net/mlx5: Geneve, Fix handling of Geneve object id as error code
4b71f2b543 9p/rdma: unmap receive dma buffer in rdma_request()/post_recv()
7cc9dbae8a 9p/xen: fix connection sequence
9d1c625c99 9p/xen: fix version parsing
edfba7b322 net: fix __dev_kfree_skb_any() vs drop monitor
cec326443f sctp: add a refcnt in sctp_stream_priorities to avoid a nested loop
aba298b356 ipv6: Add lwtunnel encap size of all siblings in nexthop calculation
5d0d38805d netfilter: ctnetlink: fix possible refcount leak in ctnetlink_create_conntrack()
fe65d6f26b watchdog: pcwd_usb: Fix attempting to access uninitialized memory
59e391b3fc watchdog: Fix kmemleak in watchdog_cdev_register
7c428fc974 watchdog: at91sam9_wdt: use devm_request_irq to avoid missing free_irq() in error path
a8816afcaf x86: um: vdso: Add '%rcx' and '%r11' to the syscall clobber list
b5be23f6ae ubi: ubi_wl_put_peb: Fix infinite loop when wear-leveling work failed
1cb14c06d6 ubi: Fix UAF wear-leveling entry in eraseblk_count_seq_show()
7fcbc41d76 ubifs: ubifs_writepage: Mark page dirty after writing inode failed
510b80abe8 ubifs: dirty_cow_znode: Fix memleak in error handling path
0875edcad4 ubifs: Re-statistic cleaned znode count if commit failed
234c53e574 ubi: Fix possible null-ptr-deref in ubi_free_volume()
1f206002c6 ubifs: Fix memory leak in alloc_wbufs()
07b60f7452 ubi: Fix unreferenced object reported by kmemleak in ubi_resize_volume()
9c8be1f165 ubi: Fix use-after-free when volume resizing failed
e86d1b2bb7 ubifs: Reserve one leb for each journal head while doing budget
82c096d0c9 ubifs: do_rename: Fix wrong space budget when target inode's nlink > 1
bf8f549584 ubifs: Fix wrong dirty space budget for dirty inode
f29168fb52 ubifs: Rectify space budget for ubifs_xrename()
8666030627 ubifs: Rectify space budget for ubifs_symlink() if symlink is encrypted
4ca0d74622 ubifs: Fix build errors as symbol undefined
f7adb740f9 ubi: ensure that VID header offset + VID header size <= alloc, size
6480c3a127 um: vector: Fix memory leak in vector_config
01c92f033b fs: f2fs: initialize fsdata in pagecache_write()
c4a89ebe92 f2fs: use memcpy_{to,from}_page() where possible
b915fac020 pwm: stm32-lp: fix the check on arr and cmp registers update
1abd385802 pwm: sifive: Always let the first pwm_apply_state succeed
30a3636fe6 pwm: sifive: Reduce time the controller lock is held
62462a5b4f fs/jfs: fix shift exponent db_agl2size negative
7a6fb69bbc net/sched: Retire tcindex classifier
b3d346ece9 kbuild: Port silent mode detection to future gnu make.
68b0cdcfa1 wifi: ath9k: use proper statements in conditionals
96a8424a27 drm/radeon: Fix eDP for single-display iMac11,2
6e6173886f drm/i915/quirks: Add inverted backlight quirk for HP 14-r206nv
efc72cceb7 PCI: Avoid FLR for AMD FCH AHCI adapters
bcc1bafb06 PCI: hotplug: Allow marking devices as disconnected during bind/unbind
2a50583117 PCI/PM: Observe reset delay irrespective of bridge_d3
40af9a6dee scsi: ses: Fix slab-out-of-bounds in ses_intf_remove()
79ec5dd5fb scsi: ses: Fix possible desc_ptr out-of-bounds accesses
8e454aba72 scsi: ses: Fix possible addl_desc_ptr out-of-bounds accesses
467afb1dd6 scsi: ses: Fix slab-out-of-bounds in ses_enclosure_data_process()
6069e04a92 scsi: ses: Don't attach if enclosure has no components
70e9a93f09 scsi: qla2xxx: Fix erroneous link down
3a564de3a2 scsi: qla2xxx: Fix DMA-API call trace on NVMe LS requests
05a0f6fa52 scsi: qla2xxx: Fix link failure in NPIV environment
18d347d1b0 ktest.pl: Add RUN_TIMEOUT option with default unlimited
150ee1fc90 ktest.pl: Fix missing "end_monitor" when machine check fails
2f42bfc54d ktest.pl: Give back console on Ctrt^C on monitor
b53d209d71 mm/thp: check and bail out if page in deferred queue already
24900f3596 mm: memcontrol: deprecate charge moving
964e9e1288 media: ipu3-cio2: Fix PM runtime usage_count in driver unbind
58c0d0b2d4 mips: fix syscall_get_nr
229edf8d7b alpha: fix FEN fault handling
9787b328c4 rbd: avoid use-after-free in do_rbd_add() when rbd_dev_create() fails
7055754dd0 ARM: dts: exynos: correct TMU phandle in Odroid XU
7b6707d66e ARM: dts: exynos: correct TMU phandle in Exynos4
3c4a56ef7c dm flakey: don't corrupt the zero page
a2be4225c3 dm flakey: fix logic when corrupting a bio
64fbe39232 thermal: intel: powerclamp: Fix cur_state for multi package system
6f1959c17d wifi: cfg80211: Fix use after free for wext
342cb34c52 wifi: rtl8xxxu: Use a longer retry limit of 48
a92b67e768 ext4: refuse to create ea block when umounted
3b28c799a1 ext4: optimize ea_inode block expansion
87005d0ab5 ALSA: hda/realtek: Add quirk for HP EliteDesk 800 G6 Tower PC
84ed1ade54 ALSA: ice1712: Do not left ice->gpio_mutex locked in aureon_add_controls()
df129eaa2b irqdomain: Drop bogus fwspec-mapping error handling
72232dbe14 irqdomain: Fix disassociation race
2101663687 irqdomain: Fix association race
f9d9320189 ima: Align ima_file_mmap() parameters with mmap_file LSM hook
4d47cba074 Documentation/hw-vuln: Document the interaction between IBRS and STIBP
34c1b60e7a x86/speculation: Allow enabling STIBP with legacy IBRS
979e197968 x86/microcode/AMD: Fix mixed steppings support
727bc2c285 x86/microcode/AMD: Add a @cpu parameter to the reloading functions
4c26edf2ea x86/microcode/amd: Remove load_microcode_amd()'s bsp parameter
a0415b79dd x86/kprobes: Fix arch_check_optimized_kprobe check within optimized_kprobe range
ec206a38d3 x86/kprobes: Fix __recover_optprobed_insn check optimizing logic
e4ce333cc6 x86/reboot: Disable SVM, not just VMX, when stopping CPUs
37459195d9 x86/reboot: Disable virtualization in an emergency if SVM is supported
87459b9fce x86/crash: Disable virt in core NMI crash handler to avoid double shootdown
ee80fb1dca x86/virt: Force GIF=1 prior to disabling SVM (for reboot flows)
4c9812d989 KVM: s390: disable migration mode when dirty tracking is disabled
10c2a20d73 KVM: Destroy target device if coalesced MMIO unregistration fails
38a1f5e9fc udf: Fix file corruption when appending just after end of preallocated extent
d747b31e29 udf: Detect system inodes linked into directory hierarchy
ce17ef97de udf: Preserve link count of system files
7bd8d9e1cf udf: Do not update file length for failed writes to inline files
3d20e3b768 udf: Do not bother merging very long extents
4e41b1c5a2 udf: Truncate added extents on failed expansion
dee96928d8 ocfs2: fix non-auto defrag path not working issue
669134a66d ocfs2: fix defrag path triggering jbd2 ASSERT
68a47ca958 f2fs: fix cgroup writeback accounting with fs-layer encryption
2bef8314fc f2fs: fix information leak in f2fs_move_inline_dirents()
3776ef785e fs: hfsplus: fix UAF issue in hfsplus_put_super
eda6879272 hfs: fix missing hfs_bnode_get() in __hfs_bnode_create
8ecde537ed ARM: dts: exynos: correct HDMI phy compatible in Exynos4
e71e6fa07f s390/kprobes: fix current_kprobe never cleared after kprobes reenter
18075c0dc3 s390/kprobes: fix irq mask clobbering on kprobe reenter from post_handler
c5db76fcdd s390: discard .interp section
a9391f8bc9 ipmi_ssif: Rename idle state and check
0ff4c222bd rtc: pm8xxx: fix set-alarm race
69b8af77ef firmware: coreboot: framebuffer: Ignore reserved pixel color bits
791402dd05 wifi: rtl8xxxu: fixing transmisison failure for rtl8192eu
3132aa35cf nfsd: zero out pointers after putting nfsd_files on COPY setup error
38b4d3eacb dm cache: add cond_resched() to various workqueue loops
3b46b2cb91 dm thin: add cond_resched() to various workqueue loops
2c055b6a07 drm: panel-orientation-quirks: Add quirk for Lenovo IdeaPad Duet 3 10IGL5
718ce68b3a pinctrl: at91: use devm_kasprintf() to avoid potential leaks
4000384684 hwmon: (coretemp) Simplify platform device handling
5026260ac2 regulator: s5m8767: Bounds check id indexing into arrays
12527ae49d regulator: max77802: Bounds check regulator id against opmode
7fae534a30 ASoC: kirkwood: Iterate over array indexes instead of using pointer math
90c278c6d0 docs/scripts/gdb: add necessary make scripts_gdb step
3a9a4a9725 drm/msm/dsi: Add missing check for alloc_ordered_workqueue
f9f55fc649 drm/radeon: free iio for atombios when driver shutdown
5ccd8d09fe HID: Add Mapping for System Microphone Mute
341a4c04ed drm/omap: dsi: Fix excessive stack usage
d236103782 drm/amd/display: Fix potential null-deref in dm_resume
5bc391944d uaccess: Add minimum bounds check on kernel buffer size
0467681f09 coda: Avoid partial allocation of sig_inputArgs
1a98c4d926 net/mlx5: fw_tracer: Fix debug print
21856d5615 ACPI: video: Fix Lenovo Ideapad Z570 DMI match
c727c1eb58 wifi: mt76: dma: free rx_head in mt76_dma_rx_cleanup
51c0dca573 m68k: Check syscall_trace_enter() return code
87363d1ab5 net: bcmgenet: Add a check for oversized packets
fe00ab1eb3 ACPI: Don't build ACPICA with '-Os'
8ec82cfe4e ice: add missing checks for PF vsi type
f81c0d484a inet: fix fast path in __inet_hash_connect()
67e4519afb wifi: mt7601u: fix an integer underflow
423a1297ea wifi: brcmfmac: ensure CLM version is null-terminated to prevent stack-out-of-bounds
f3a324362b x86/bugs: Reset speculation control settings on init
c8157f67b0 timers: Prevent union confusion from unexpected restart_syscall()
f570968d01 thermal: intel: Fix unsigned comparison with less than zero
596d1fea05 rcu: Suppress smp_processor_id() complaint in synchronize_rcu_expedited_wait()
17dbe90e13 wifi: brcmfmac: Fix potential stack-out-of-bounds in brcmf_c_preinit_dcmds()
9e8bf9f95f blk-iocost: fix divide by 0 error in calc_lcoefs()
f10001af0f ARM: dts: exynos: Use Exynos5420 compatible for the MIPI video phy
dae4d5ae6b udf: Define EFSCORRUPTED error code
824b167fa8 rpmsg: glink: Avoid infinite loop on intent for missing channel
a41bb59eff media: usb: siano: Fix use after free bugs caused by do_submit_urb
2a72e3b6bb media: i2c: ov7670: 0 instead of -EINVAL was returned
d120334278 media: rc: Fix use-after-free bugs caused by ene_tx_irqsim()
448ce1cd50 media: i2c: ov772x: Fix memleak in ov772x_probe()
086a80b842 media: ov5675: Fix memleak in ov5675_init_controls()
ec6bd0dccd powerpc: Remove linker flag from KBUILD_AFLAGS
44aef56083 media: platform: ti: Add missing check for devm_regulator_get
fc85fb5763 remoteproc: qcom_q6v5_mss: Use a carveout to authenticate modem headers
3acbec356d MIPS: vpe-mt: drop physical_memsize
a3c9200405 MIPS: SMP-CPS: fix build error when HOTPLUG_CPU not set
1abc7be57c powerpc/eeh: Set channel state after notifying the drivers
7719aba7a3 powerpc/eeh: Small refactor of eeh_handle_normal_event()
a39becb905 powerpc/rtas: ensure 4KB alignment for rtas_data_buf
0616586eef powerpc/rtas: make all exports GPL
d8ca498591 powerpc/pseries/lparcfg: add missing RTAS retry status handling
421c59c23a powerpc/pseries/lpar: add missing RTAS retry status handling
2c5ad2d642 clk: Honor CLK_OPS_PARENT_ENABLE in clk_core_is_enabled()
4d178dc25f powerpc/powernv/ioda: Skip unallocated resources when mapping to PE
b1c1b6da5a clk: qcom: gpucc-sdm845: fix clk_dis_wait being programmed for CX GDSC
e3617778eb Input: ads7846 - don't check penirq immediately for 7845
ea9c4fbfda Input: ads7846 - don't report pressure for ads7845
17761a1c7f clk: renesas: cpg-mssr: Remove superfluous check in resume code
8ff19db903 clk: renesas: cpg-mssr: Use enum clk_reg_layout instead of a boolean flag
330b70949c clk: renesas: cpg-mssr: Fix use after free if cpg_mssr_common_init() failed
f34eb1e433 mtd: rawnand: sunxi: Fix the size of the last OOB region
cdfdd882fa clk: qcom: gcc-qcs404: fix names of the DSI clocks used as parents
b419e91378 clk: qcom: gcc-qcs404: disable gpll[04]_out_aux parents
588edb4fb1 mfd: pcf50633-adc: Fix potential memleak in pcf50633_adc_async_read()
6e0a0eb18e selftests/ftrace: Fix bash specific "==" operator
16a35042ff sparc: allow PM configs for sparc32 COMPILE_TEST
090a22f599 perf tools: Fix auto-complete on aarch64
5d32f3e922 perf llvm: Fix inadvertent file creation
ce43565a6c gfs2: jdata writepage fix
3524d6da0f cifs: Fix warning and UAF when destroy the MR list
324c0c34ff cifs: Fix lost destroy smbd connection when MR allocate failed
a22f1ecab6 nfsd: fix race to check ls_layouts
5a195fa41d hid: bigben_probe(): validate report count
9f525559ea HID: asus: Fix mute and touchpad-toggle keys on Medion Akoya E1239T
bc786dfeb7 HID: asus: Add support for multi-touch touchpad on Medion Akoya E1239T
bad4a822a1 HID: asus: Add report_size to struct asus_touchpad_info
63792d0ae9 HID: asus: Only set EV_REP if we are adding a mapping
25e14bf0c8 HID: bigben: use spinlock to safely schedule workers
715edb0109 HID: bigben_worker() remove unneeded check on report_field
12533ad854 HID: bigben: use spinlock to protect concurrent accesses
05cb432c09 ASoC: soc-dapm.h: fixup warning struct snd_pcm_substream not declared
84beaa3e2e ASoC: dapm: declare missing structure prototypes
d6250e00bf spi: synquacer: Fix timeout handling in synquacer_spi_transfer_one()
b89d2ed564 dm: remove flush_scheduled_work() during local_exit()
e6d9a876d9 hwmon: (mlxreg-fan) Return zero speed for broken fan
870a0f519a spi: bcm63xx-hsspi: Fix multi-bit mode setting
dd271f1798 spi: bcm63xx-hsspi: fix pm_runtime
904b717bb5 scsi: aic94xx: Add missing check for dma_map_single()
3414be1c8c hwmon: (ltc2945) Handle error case in ltc2945_value_store
75a1c3f822 gpio: vf610: connect GPIO label to dev name
584cb84e2c ASoC: soc-compress.c: fixup private_data on snd_soc_new_compress()
a161f1d92a drm/mediatek: Clean dangling pointer on bind error path
b8b166db78 drm/mediatek: Drop unbalanced obj unref
367c80fb34 drm/mediatek: Use NULL instead of 0 for NULL pointer
a0555f90d8 drm/mediatek: remove cast to pointers passed to kfree
2b59e87c92 gpu: host1x: Don't skip assigning syncpoints to channels
3975ea6eaf drm/msm/mdp5: Add check for kzalloc
2a8bb9dce7 drm: Initialize struct drm_crtc_state.no_vblank from device settings
9b2f584490 drm/bridge: Introduce drm_bridge_get_next_bridge()
bb08be7232 drm/bridge: Rename bridge helpers targeting a bridge chain
2c33a6141d drm/exynos: Don't reset bridge->next
dadd30fcc7 drm/msm/dpu: Add check for pstates
a6afb8293e drm/msm/dpu: Add check for cstate
8f9fdc830d drm/msm: use strscpy instead of strncpy
d7ea84cddf drm/mipi-dsi: Fix byte order of 16-bit DCS set/get brightness
a9eafb0448 ALSA: hda/ca0132: minor fix for allocation size
a80767caed ASoC: fsl_sai: initialize is_dsp_mode flag
95ab6d7905 pinctrl: stm32: Fix refcount leak in stm32_pctrl_get_irq_domain
fc34608fa2 drm/msm/hdmi: Add missing check for alloc_ordered_workqueue
62430b3210 gpu: ipu-v3: common: Add of_node_put() for reference returned by of_graph_get_port_by_id()
31701e54d3 drm/vc4: dpi: Fix format mapping for RGB565
d66f26b93c drm/vc4: dpi: Add option for inverting pixel clock and output enable
7ddd8a5ecf drm/bridge: megachips: Fix error handling in i2c_register_driver()
d56e589f8b drm: mxsfb: DRM_MXSFB should depend on ARCH_MXS || ARCH_MXC
c879003a6f drm/fourcc: Add missing big-endian XRGB1555 and RGB565 formats
c82ca67ca0 selftest: fib_tests: Always cleanup before exit
c31985922e selftests/net: Interpret UDP_GRO cmsg data as an int value
6165747888 irqchip/irq-bcm7120-l2: Set IRQ_LEVEL for level triggered interrupts
3947b16613 irqchip/irq-brcmstb-l2: Set IRQ_LEVEL for level triggered interrupts
d772090078 can: esd_usb: Move mislocated storage of SJA1000_ECC_SEG bits in case of a bus error
3cf2181e43 thermal/drivers/hisi: Drop second sensor hi3660
21c701cbc8 wifi: mac80211: make rate u32 in sta_set_rate_info_rx()
b70d56e728 crypto: crypto4xx - Call dma_unmap_page when done
a3b75b1e76 wifi: mwifiex: fix loop iterator in mwifiex_update_ampdu_txwinsize()
c002d27414 wifi: iwl4965: Add missing check for create_singlethread_workqueue()
7e594abc04 wifi: iwl3945: Add missing check for create_singlethread_workqueue
5de7a4254e treewide: Replace DECLARE_TASKLET() with DECLARE_TASKLET_OLD()
9198eefd10 usb: gadget: udc: Avoid tasklet passing a global
cf04507f42 RISC-V: time: initialize hrtimer based broadcast clock event device
142bcf7240 m68k: /proc/hardware should depend on PROC_FS
c4d8c23efe crypto: rsa-pkcs1pad - Use akcipher_request_complete
8c1447495f rds: rds_rm_zerocopy_callback() correct order for list_add_tail()
291e6a6820 libbpf: Fix alen calculation in libbpf_nla_dump_errormsg()
60aaccf16d Bluetooth: L2CAP: Fix potential user-after-free
d19bd48535 OPP: fix error checking in opp_migrate_dentry()
522d319cda tap: tap_open(): correctly initialize socket uid
d92d87000e tun: tun_chr_open(): correctly initialize socket uid
11c9c72272 net: add sock_init_data_uid()
276ccbc15f mptcp: add sk_stop_timer_sync helper
07fceab320 irqchip/ti-sci: Fix refcount leak in ti_sci_intr_irq_domain_probe
c7d78d36e1 irqchip/irq-mvebu-gicp: Fix refcount leak in mvebu_gicp_probe
9e79ac4f70 irqchip/alpine-msi: Fix refcount leak in alpine_msix_init_domains
7cce0c9fdd net/mlx5: Enhance debug print in page allocation failure
dbd6ae0956 powercap: fix possible name leak in powercap_register_zone()
63551e4b7c crypto: seqiv - Handle EBUSY correctly
c61e7d182e crypto: essiv - Handle EBUSY correctly
bfef5e3e73 crypto: essiv - remove redundant null pointer check before kfree
2d1ac2f2e2 crypto: ccp - Failure on re-initialization due to duplicate sysfs filename
40627e6e29 ACPI: battery: Fix missing NUL-termination with large strings
bf6dc175a2 wifi: ath9k: Fix potential stack-out-of-bounds write in ath9k_wmi_rsp_callback()
cd83167670 wifi: ath9k: hif_usb: clean up skbs if ath9k_hif_usb_rx_stream() fails
c3ff385b94 ath9k: htc: clean up statistics macros
a49c13ecce ath9k: hif_usb: simplify if-if to if-else
564bc2222b wifi: ath9k: htc_hst: free skb in ath9k_htc_rx_msg() if there is no callback function
17a0e61cd9 wifi: orinoco: check return value of hermes_write_wordrec()
573dfeba2d ACPICA: nsrepair: handle cases without a return value correctly
987b0ff1b9 lib/mpi: Fix buffer overrun when SG is too long
b55ada30b5 genirq: Fix the return type of kstat_cpu_irqs_sum()
6b9f61c8b8 ACPICA: Drop port I/O validation for some regions
c300697690 crypto: x86/ghash - fix unaligned access in ghash_setkey()
0c4f20c8fc wifi: wl3501_cs: don't call kfree_skb() under spin_lock_irqsave()
14ba31bb1b wifi: libertas: cmdresp: don't call kfree_skb() under spin_lock_irqsave()
38ef777203 wifi: libertas: main: don't call kfree_skb() under spin_lock_irqsave()
1879fe9e40 wifi: libertas: if_usb: don't call kfree_skb() under spin_lock_irqsave()
0b7b734744 wifi: libertas_tf: don't call kfree_skb() under spin_lock_irqsave()
318005127c wifi: brcmfmac: unmap dma buffer in brcmf_msgbuf_alloc_pktid()
d869a18950 wifi: brcmfmac: fix potential memory leak in brcmf_netdev_start_xmit()
a12610e837 wifi: wilc1000: fix potential memory leak in wilc_mac_xmit()
a6059cf02a wilc1000: let wilc_mac_xmit() return NETDEV_TX_OK
112c1af02b wifi: ipw2200: fix memory leak in ipw_wdev_init()
ba1d3623fe wifi: ipw2x00: don't call dev_kfree_skb() under spin_lock_irqsave()
0d438ae7ba ipw2x00: switch from 'pci_' to 'dma_' API
28ea268d95 wifi: rtlwifi: Fix global-out-of-bounds bug in _rtl8812ae_phy_set_txpower_limit()
5d171ab48b rtlwifi: fix -Wpointer-sign warning
5dd30d1acc wifi: rtl8xxxu: don't call dev_kfree_skb() under spin_lock_irqsave()
23b34e08de wifi: libertas: fix memory leak in lbs_init_adapter()
1864b22e23 wifi: iwlegacy: common: don't call dev_kfree_skb() under spin_lock_irqsave()
9004aa391a net/wireless: Delete unnecessary checks before the macro call “dev_kfree_skb”
fe4d7280cf wifi: rsi: Fix memory leak in rsi_coex_attach()
82d68c3244 block: bio-integrity: Copy flags when bio_integrity_payload is cloned
084cd75643 sched/rt: pick_next_rt_entity(): check list_entry
0ff7ba5e8b sched/deadline,rt: Remove unused parameter from pick_next_[rt|dl]_entity()
ee986d80ac s390/dasd: Fix potential memleak in dasd_eckd_init()
8bc5a76268 s390/dasd: Prepare for additional path event handling
946515fad4 blk-mq: correct stale comment of .get_budget
2dc5f68fe6 blk-mq: wait on correct sbitmap_queue in blk_mq_mark_tag_wait
8c225150ea blk-mq: remove stale comment for blk_mq_sched_mark_restart_hctx
260dcf1ccd block: Limit number of items taken from the I/O scheduler in one go
578c8f09c0 Revert "scsi: core: run queue if SCSI device queue isn't ready and queue is idle"
2d3c3aa412 arm64: dts: mediatek: mt7622: Add missing pwm-cells to pwm node
38af86810d ARM: dts: imx7s: correct iomuxc gpr mux controller cells
7fe5dc2fee arm64: dts: amlogic: meson-gxl-s905d-phicomm-n1: fix led node name
8b7aa62f4a arm64: dts: amlogic: meson-gxl: add missing unit address to eth-phy-mux node name
d5fbeae6d6 arm64: dts: amlogic: meson-gx: add missing unit address to rng node name
c5cd41bd10 arm64: dts: amlogic: meson-gx: add missing SCPI sensors compatible
1e3ec4d1d7 arm64: dts: amlogic: meson-axg: fix SCPI clock dvfs node name
e515d41185 arm64: dts: amlogic: meson-gx: fix SCPI clock dvfs node name
1e1b84b022 ARM: imx: Call ida_simple_remove() for ida_simple_get
b0a1b2f3ef ARM: dts: exynos: correct wr-active property in Exynos3250 Rinato
91ac4bf35a ARM: OMAP1: call platform_device_put() in error case in omap1_dm_timer_init()
af3352c16e arm64: dts: meson: remove CPU opps below 1GHz for G12A boards
9dd61d9542 arm64: dts: meson-gx: Fix the SCPI DVFS node name and unit address
cba890c4bd arm64: dts: meson-g12a: Fix internal Ethernet PHY unit name
69bdc5d014 arm64: dts: meson-gx: Fix Ethernet MAC address unit name
ede0334bf4 ARM: zynq: Fix refcount leak in zynq_early_slcr_init
45b44ba5df arm64: dts: qcom: qcs404: use symbol names for PCIe resets
8041f9a2a9 ARM: OMAP2+: Fix memory leak in realtime_counter_init()
dd08e68d04 HID: asus: use spinlock to safely schedule workers
136a9bcc0e HID: asus: use spinlock to protect concurrent accesses
9a25b22fd5 HID: asus: Remove check for same LED brightness on set
f9c844d00d Merge 5.4.234 into android11-5.4-lts
a103859aaa Linux 5.4.234
a1e89c8b29 USB: core: Don't hold device lock while reading the "descriptors" sysfs file
96d380d2ae USB: serial: option: add support for VW/Skoda "Carstick LTE"
91c877d431 dmaengine: sh: rcar-dmac: Check for error num after dma_set_max_seg_size
465ce31a2b vc_screen: don't clobber return value in vcs_read
ee8cd3abe7 net: Remove WARN_ON_ONCE(sk->sk_forward_alloc) from sk_stream_kill_queues().
db25b41eb5 bpf: bpf_fib_lookup should not return neigh in NUD_FAILED state
23affaed76 HID: core: Fix deadloop in hid_apply_multiplier.
93b17c7e1e neigh: make sure used and confirmed times are valid
bc4601ad97 IB/hfi1: Assign npages earlier
98e626c115 btrfs: send: limit number of clones and allocated memory size
ae03fa7ad3 ACPI: NFIT: fix a potential deadlock during NFIT teardown
785bde8459 ARM: dts: rockchip: add power-domains property to dp node on rk3288
da2bba879e arm64: dts: rockchip: drop unused LED mode property from rk3328-roc-cc

And update the .xml file due to the __irq_domain_add() change that came
into this branch.

Change-Id: Ia973c369a8bb9da89df14007cd6b820c9a7a2155
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2023-05-25 17:49:55 +00:00
Tudor Ambarus
02293ac0e1 UPSTREAM: ext4: avoid a potential slab-out-of-bounds in ext4_group_desc_csum
commit 4f04351888a83e595571de672e0a4a8b74f4fb31 upstream.

When modifying the block device while it is mounted by the filesystem,
syzbot reported the following:

BUG: KASAN: slab-out-of-bounds in crc16+0x206/0x280 lib/crc16.c:58
Read of size 1 at addr ffff888075f5c0a8 by task syz-executor.2/15586

CPU: 1 PID: 15586 Comm: syz-executor.2 Not tainted 6.2.0-rc5-syzkaller-00205-gc96618275234 #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/12/2023
Call Trace:
 <TASK>
 __dump_stack lib/dump_stack.c:88 [inline]
 dump_stack_lvl+0x1b1/0x290 lib/dump_stack.c:106
 print_address_description+0x74/0x340 mm/kasan/report.c:306
 print_report+0x107/0x1f0 mm/kasan/report.c:417
 kasan_report+0xcd/0x100 mm/kasan/report.c:517
 crc16+0x206/0x280 lib/crc16.c:58
 ext4_group_desc_csum+0x81b/0xb20 fs/ext4/super.c:3187
 ext4_group_desc_csum_set+0x195/0x230 fs/ext4/super.c:3210
 ext4_mb_clear_bb fs/ext4/mballoc.c:6027 [inline]
 ext4_free_blocks+0x191a/0x2810 fs/ext4/mballoc.c:6173
 ext4_remove_blocks fs/ext4/extents.c:2527 [inline]
 ext4_ext_rm_leaf fs/ext4/extents.c:2710 [inline]
 ext4_ext_remove_space+0x24ef/0x46a0 fs/ext4/extents.c:2958
 ext4_ext_truncate+0x177/0x220 fs/ext4/extents.c:4416
 ext4_truncate+0xa6a/0xea0 fs/ext4/inode.c:4342
 ext4_setattr+0x10c8/0x1930 fs/ext4/inode.c:5622
 notify_change+0xe50/0x1100 fs/attr.c:482
 do_truncate+0x200/0x2f0 fs/open.c:65
 handle_truncate fs/namei.c:3216 [inline]
 do_open fs/namei.c:3561 [inline]
 path_openat+0x272b/0x2dd0 fs/namei.c:3714
 do_filp_open+0x264/0x4f0 fs/namei.c:3741
 do_sys_openat2+0x124/0x4e0 fs/open.c:1310
 do_sys_open fs/open.c:1326 [inline]
 __do_sys_creat fs/open.c:1402 [inline]
 __se_sys_creat fs/open.c:1396 [inline]
 __x64_sys_creat+0x11f/0x160 fs/open.c:1396
 do_syscall_x64 arch/x86/entry/common.c:50 [inline]
 do_syscall_64+0x3d/0xb0 arch/x86/entry/common.c:80
 entry_SYSCALL_64_after_hwframe+0x63/0xcd
RIP: 0033:0x7f72f8a8c0c9
Code: 28 00 00 00 75 05 48 83 c4 28 c3 e8 f1 19 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f72f97e3168 EFLAGS: 00000246 ORIG_RAX: 0000000000000055
RAX: ffffffffffffffda RBX: 00007f72f8bac050 RCX: 00007f72f8a8c0c9
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000020000280
RBP: 00007f72f8ae7ae9 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007ffd165348bf R14: 00007f72f97e3300 R15: 0000000000022000

Replace
	le16_to_cpu(sbi->s_es->s_desc_size)
with
	sbi->s_desc_size

It reduces ext4's compiled text size, and makes the code more efficient
(we remove an extra indirect reference and a potential byte
swap on big endian systems), and there is no downside. It also avoids the
potential KASAN / syzkaller failure, as a bonus.

Reported-by: syzbot+fc51227e7100c9294894@syzkaller.appspotmail.com
Reported-by: syzbot+8785e41224a3afd04321@syzkaller.appspotmail.com
Link: https://syzkaller.appspot.com/bug?id=70d28d11ab14bd7938f3e088365252aa923cff42
Link: https://syzkaller.appspot.com/bug?id=b85721b38583ecc6b5e72ff524c67302abbc30f3
Link: https://lore.kernel.org/all/000000000000ece18705f3b20934@google.com/
Fixes: 717d50e497 ("Ext4: Uninitialized Block Groups")
Cc: stable@vger.kernel.org
Signed-off-by: Tudor Ambarus <tudor.ambarus@linaro.org>
Link: https://lore.kernel.org/r/20230504121525.3275886-1-tudor.ambarus@linaro.org
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Bug: 269155298
Bug: 270466805
Change-Id: Id14192ab0905c36e154d07d461afb56af7b61488
Signed-off-by: Tudor Ambarus <tudor.ambarus@linaro.org>
2023-05-25 16:50:36 +00:00
Theodore Ts'o
419a816b34 UPSTREAM: ext4: fix invalid free tracking in ext4_xattr_move_to_block()
commit b87c7cdf2bed4928b899e1ce91ef0d147017ba45 upstream.

In ext4_xattr_move_to_block(), the value of the extended attribute
which we need to move to an external block may be allocated by
kvmalloc() if the value is stored in an external inode.  So at the end
of the function the code tried to check if this was the case by
testing entry->e_value_inum.

However, at this point, the pointer to the xattr entry is no longer
valid, because it was removed from the original location where it had
been stored.  So we could end up calling kvfree() on a pointer which
was not allocated by kvmalloc(); or we could also potentially leak
memory by not freeing the buffer when it should be freed.  Fix this by
storing whether it should be freed in a separate variable.

Cc: stable@kernel.org
Link: https://lore.kernel.org/r/20230430160426.581366-1-tytso@mit.edu
Link: https://syzkaller.appspot.com/bug?id=5c2aee8256e30b55ccf57312c16d88417adbd5e1
Link: https://syzkaller.appspot.com/bug?id=41a6b5d4917c0412eb3b3c3c604965bed7d7420b
Reported-by: syzbot+64b645917ce07d89bde5@syzkaller.appspotmail.com
Reported-by: syzbot+0d042627c4f2ad332195@syzkaller.appspotmail.com
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Bug: 281332515
Bug: 281333738
Change-Id: Id1fbcc337821d66df53c2826bf3158963f8b0673
Signed-off-by: Tudor Ambarus <tudor.ambarus@linaro.org>
2023-05-17 15:12:38 +00:00
Lee Jones
8177b9d924 Revert "Revert "mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse""
This reverts commit 4f35cec76058557d9eaec0d501d03c7657eb56b4 and does so
in an abi-safe way.

This is done by adding the new fields only to the end of the structure
and this structure is only passed around to other functions as a
pointer, the internal structure layout is only touched by the core
kernel, so adding it to the end is safe.

ABI differences manually updated:

Leaf changes summary: 1 artifact changed
Changed leaf types summary: 1 leaf type changed
Removed/Changed/Added functions summary: 0 Removed, 0 Changed, 0 Added function
Removed/Changed/Added variables summary: 0 Removed, 0 Changed, 0 Added variable

'struct anon_vma at rmap.h:29:1' changed:
  type size changed from 704 to 832 (in bits)
  2 data member insertions:
    'unsigned long int num_children', at offset 704 (in bits) at rmap.h:70:1
    'unsigned long int num_active_vmas', at offset 768 (in bits) at rmap.h:72:1
  3868 impacted interfaces

Bug: 260678056
Bug: 253167854
Change-Id: Ib1d45625cbc2e0b21330ca3dc2aa7aff34666d31
Signed-off-by: Lee Jones <joneslee@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
(cherry picked from commit d3e1a50cba092fa9c56fc642ee74f360c4b40a17)
2023-05-11 12:43:07 +00:00
Carlos Llamas
6d5e0c7837 FROMLIST: binder: fix UAF caused by faulty buffer cleanup
In binder_transaction_buffer_release() the 'failed_at' offset indicates
the number of objects to clean up. However, this function was changed by
commit 44d8047f1d ("binder: use standard functions to allocate fds"),
to release all the objects in the buffer when 'failed_at' is zero.

This introduced an issue when a transaction buffer is released without
any objects having been processed so far. In this case, 'failed_at' is
indeed zero yet it is misinterpreted as releasing the entire buffer.

This leads to use-after-free errors where nodes are incorrectly freed
and subsequently accessed. Such is the case in the following KASAN
report:

  ==================================================================
  BUG: KASAN: slab-use-after-free in binder_thread_read+0xc40/0x1f30
  Read of size 8 at addr ffff4faf037cfc58 by task poc/474

  CPU: 6 PID: 474 Comm: poc Not tainted 6.3.0-12570-g7df047b3f0aa #5
  Hardware name: linux,dummy-virt (DT)
  Call trace:
   dump_backtrace+0x94/0xec
   show_stack+0x18/0x24
   dump_stack_lvl+0x48/0x60
   print_report+0xf8/0x5b8
   kasan_report+0xb8/0xfc
   __asan_load8+0x9c/0xb8
   binder_thread_read+0xc40/0x1f30
   binder_ioctl+0xd9c/0x1768
   __arm64_sys_ioctl+0xd4/0x118
   invoke_syscall+0x60/0x188
  [...]

  Allocated by task 474:
   kasan_save_stack+0x3c/0x64
   kasan_set_track+0x2c/0x40
   kasan_save_alloc_info+0x24/0x34
   __kasan_kmalloc+0xb8/0xbc
   kmalloc_trace+0x48/0x5c
   binder_new_node+0x3c/0x3a4
   binder_transaction+0x2b58/0x36f0
   binder_thread_write+0x8e0/0x1b78
   binder_ioctl+0x14a0/0x1768
   __arm64_sys_ioctl+0xd4/0x118
   invoke_syscall+0x60/0x188
  [...]

  Freed by task 475:
   kasan_save_stack+0x3c/0x64
   kasan_set_track+0x2c/0x40
   kasan_save_free_info+0x38/0x5c
   __kasan_slab_free+0xe8/0x154
   __kmem_cache_free+0x128/0x2bc
   kfree+0x58/0x70
   binder_dec_node_tmpref+0x178/0x1fc
   binder_transaction_buffer_release+0x430/0x628
   binder_transaction+0x1954/0x36f0
   binder_thread_write+0x8e0/0x1b78
   binder_ioctl+0x14a0/0x1768
   __arm64_sys_ioctl+0xd4/0x118
   invoke_syscall+0x60/0x188
  [...]
  ==================================================================

In order to avoid these issues, let's always calculate the intended
'failed_at' offset beforehand. This is renamed and wrapped in a helper
function to make it clear and convenient.

Fixes: 32e9f56a96d8 ("binder: don't detect sender/target during buffer cleanup")
Reported-by: Zi Fan Tan <zifantan@google.com>
Link: https://b.corp.google.com/issues/275041864
Cc: stable@vger.kernel.org
Signed-off-by: Carlos Llamas <cmllamas@google.com>

Bug: 275041864
Link: https://lore.kernel.org/all/20230505203020.4101154-1-cmllamas@google.com
Change-Id: I4bcc8bde77a8118872237d100cccb5caf95d99a1
[cmllamas: drop hunk for missing commit 9864bb480133]
Signed-off-by: Carlos Llamas <cmllamas@google.com>
2023-05-08 14:22:01 +00:00
Dan Carpenter
0779e2b555 UPSTREAM: usb: musb: mediatek: don't unregister something that wasn't registered
This function only calls mtk_otg_switch_init() when the ->port_mode
is MUSB_OTG so the clean up code should only call mtk_otg_switch_exit()
for that mode.

Bug: 254441685
Fixes: 0990366bab3c ("usb: musb: Add support for MediaTek musb controller")
Signed-off-by: Dan Carpenter <error27@gmail.com>
Link: https://lore.kernel.org/r/Y8/3TqpqiSr0RxFH@kili
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit ba883de971d1ad018f3083d9195b8abe54d87407)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I042338f3749eaca3aab1a9c8f4be130b4855358e
2023-05-04 16:25:21 +01:00
Yan Zhai
e3280136fb UPSTREAM: net: fix NULL pointer in skb_segment_list
Commit 3a1296a38d0c ("net: Support GRO/GSO fraglist chaining.")
introduced UDP listifyed GRO. The segmentation relies on frag_list being
untouched when passing through the network stack. This assumption can be
broken sometimes, where frag_list itself gets pulled into linear area,
leaving frag_list being NULL. When this happens it can trigger
following NULL pointer dereference, and panic the kernel. Reverse the
test condition should fix it.

[19185.577801][    C1] BUG: kernel NULL pointer dereference, address:
...
[19185.663775][    C1] RIP: 0010:skb_segment_list+0x1cc/0x390
...
[19185.834644][    C1] Call Trace:
[19185.841730][    C1]  <TASK>
[19185.848563][    C1]  __udp_gso_segment+0x33e/0x510
[19185.857370][    C1]  inet_gso_segment+0x15b/0x3e0
[19185.866059][    C1]  skb_mac_gso_segment+0x97/0x110
[19185.874939][    C1]  __skb_gso_segment+0xb2/0x160
[19185.883646][    C1]  udp_queue_rcv_skb+0xc3/0x1d0
[19185.892319][    C1]  udp_unicast_rcv_skb+0x75/0x90
[19185.900979][    C1]  ip_protocol_deliver_rcu+0xd2/0x200
[19185.910003][    C1]  ip_local_deliver_finish+0x44/0x60
[19185.918757][    C1]  __netif_receive_skb_one_core+0x8b/0xa0
[19185.927834][    C1]  process_backlog+0x88/0x130
[19185.935840][    C1]  __napi_poll+0x27/0x150
[19185.943447][    C1]  net_rx_action+0x27e/0x5f0
[19185.951331][    C1]  ? mlx5_cq_tasklet_cb+0x70/0x160 [mlx5_core]
[19185.960848][    C1]  __do_softirq+0xbc/0x25d
[19185.968607][    C1]  irq_exit_rcu+0x83/0xb0
[19185.976247][    C1]  common_interrupt+0x43/0xa0
[19185.984235][    C1]  asm_common_interrupt+0x22/0x40
...
[19186.094106][    C1]  </TASK>

Bug: 254441685
Fixes: 3a1296a38d0c ("net: Support GRO/GSO fraglist chaining.")
Suggested-by: Daniel Borkmann <daniel@iogearbox.net>
Reviewed-by: Willem de Bruijn <willemb@google.com>
Signed-off-by: Yan Zhai <yan@cloudflare.com>
Acked-by: Daniel Borkmann <daniel@iogearbox.net>
Link: https://lore.kernel.org/r/Y9gt5EUizK1UImEP@debian
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 876e8ca8366735a604bac86ff7e2732fc9d85d2d)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: Ifa2bdf83bda331cba48d6403ea76cafdbcad5e6f
2023-05-04 16:25:21 +01:00
Eric Dumazet
7fcf9449ae UPSTREAM: xfrm/compat: prevent potential spectre v1 gadget in xfrm_xlate32_attr()
int type = nla_type(nla);

  if (type > XFRMA_MAX) {
            return -EOPNOTSUPP;
  }

@type is then used as an array index and can be used
as a Spectre v1 gadget.

  if (nla_len(nla) < compat_policy[type].len) {

array_index_nospec() can be used to prevent leaking
content of kernel memory to malicious users.

Bug: 254441685
Fixes: 5106f4a8acff ("xfrm/compat: Add 32=>64-bit messages translator")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Dmitry Safonov <dima@arista.com>
Cc: Steffen Klassert <steffen.klassert@secunet.com>
Reviewed-by: Dmitry Safonov <dima@arista.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
(cherry picked from commit b6ee896385380aa621102e8ea402ba12db1cabff)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I7d3122e26c8ff3a34c04d2431cf6f888ae940f07
2023-05-04 16:25:21 +01:00
Anastasia Belova
79f59b0d69 UPSTREAM: xfrm: compat: change expression for switch in xfrm_xlate64
Compare XFRM_MSG_NEWSPDINFO (value from netlink
configuration messages enum) with nlh_src->nlmsg_type
instead of nlh_src->nlmsg_type - XFRM_MSG_BASE.

Found by Linux Verification Center (linuxtesting.org) with SVACE.

Bug: 254441685
Fixes: 4e9505064f58 ("net/xfrm/compat: Copy xfrm_spdattr_type_t atributes")
Signed-off-by: Anastasia Belova <abelova@astralinux.ru>
Acked-by: Dmitry Safonov <0x7f454c46@gmail.com>
Tested-by: Dmitry Safonov <0x7f454c46@gmail.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
(cherry picked from commit eb6c59b735aa6cca77cdbb59cc69d69a0d63d986)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I3f765d0dea1fd3fc431c09f4e6e3f2f98a8f8158
2023-05-04 16:25:21 +01:00
Namhyung Kim
35093f38c4 UPSTREAM: perf/core: Call LSM hook after copying perf_event_attr
It passes the attr struct to the security_perf_event_open() but it's
not initialized yet.

Bug: 254441685
Fixes: da97e18458fb ("perf_event: Add support for LSM and SELinux checks")
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Reviewed-by: Joel Fernandes (Google) <joel@joelfernandes.org>
Cc: stable@vger.kernel.org
Link: https://lkml.kernel.org/r/20221220223140.4020470-1-namhyung@kernel.org
(cherry picked from commit 0a041ebca4956292cadfb14a63ace3a9c1dcb0a3)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I99add105e7ef0a34b201e970c6a938f799aefdc1
2023-05-04 16:25:21 +01:00
Baokun Li
edbf3d0e06 UPSTREAM: ext4: fix use-after-free in ext4_xattr_set_entry
[ Upstream commit 67d7d8ad99beccd9fe92d585b87f1760dc9018e3 ]

Hulk Robot reported a issue:
==================================================================
BUG: KASAN: use-after-free in ext4_xattr_set_entry+0x18ab/0x3500
Write of size 4105 at addr ffff8881675ef5f4 by task syz-executor.0/7092

CPU: 1 PID: 7092 Comm: syz-executor.0 Not tainted 4.19.90-dirty #17
Call Trace:
[...]
 memcpy+0x34/0x50 mm/kasan/kasan.c:303
 ext4_xattr_set_entry+0x18ab/0x3500 fs/ext4/xattr.c:1747
 ext4_xattr_ibody_inline_set+0x86/0x2a0 fs/ext4/xattr.c:2205
 ext4_xattr_set_handle+0x940/0x1300 fs/ext4/xattr.c:2386
 ext4_xattr_set+0x1da/0x300 fs/ext4/xattr.c:2498
 __vfs_setxattr+0x112/0x170 fs/xattr.c:149
 __vfs_setxattr_noperm+0x11b/0x2a0 fs/xattr.c:180
 __vfs_setxattr_locked+0x17b/0x250 fs/xattr.c:238
 vfs_setxattr+0xed/0x270 fs/xattr.c:255
 setxattr+0x235/0x330 fs/xattr.c:520
 path_setxattr+0x176/0x190 fs/xattr.c:539
 __do_sys_lsetxattr fs/xattr.c:561 [inline]
 __se_sys_lsetxattr fs/xattr.c:557 [inline]
 __x64_sys_lsetxattr+0xc2/0x160 fs/xattr.c:557
 do_syscall_64+0xdf/0x530 arch/x86/entry/common.c:298
 entry_SYSCALL_64_after_hwframe+0x44/0xa9
RIP: 0033:0x459fe9
RSP: 002b:00007fa5e54b4c08 EFLAGS: 00000246 ORIG_RAX: 00000000000000bd
RAX: ffffffffffffffda RBX: 000000000051bf60 RCX: 0000000000459fe9
RDX: 00000000200003c0 RSI: 0000000020000180 RDI: 0000000020000140
RBP: 000000000051bf60 R08: 0000000000000001 R09: 0000000000000000
R10: 0000000000001009 R11: 0000000000000246 R12: 0000000000000000
R13: 00007ffc73c93fc0 R14: 000000000051bf60 R15: 00007fa5e54b4d80
[...]
==================================================================

Above issue may happen as follows:
-------------------------------------
ext4_xattr_set
  ext4_xattr_set_handle
    ext4_xattr_ibody_find
      >> s->end < s->base
      >> no EXT4_STATE_XATTR
      >> xattr_check_inode is not executed
    ext4_xattr_ibody_set
      ext4_xattr_set_entry
       >> size_t min_offs = s->end - s->base
       >> UAF in memcpy

we can easily reproduce this problem with the following commands:
    mkfs.ext4 -F /dev/sda
    mount -o debug_want_extra_isize=128 /dev/sda /mnt
    touch /mnt/file
    setfattr -n user.cat -v `seq -s z 4096|tr -d '[:digit:]'` /mnt/file

In ext4_xattr_ibody_find, we have the following assignment logic:
  header = IHDR(inode, raw_inode)
         = raw_inode + EXT4_GOOD_OLD_INODE_SIZE + i_extra_isize
  is->s.base = IFIRST(header)
             = header + sizeof(struct ext4_xattr_ibody_header)
  is->s.end = raw_inode + s_inode_size

In ext4_xattr_set_entry
  min_offs = s->end - s->base
           = s_inode_size - EXT4_GOOD_OLD_INODE_SIZE - i_extra_isize -
	     sizeof(struct ext4_xattr_ibody_header)
  last = s->first
  free = min_offs - ((void *)last - s->base) - sizeof(__u32)
       = s_inode_size - EXT4_GOOD_OLD_INODE_SIZE - i_extra_isize -
         sizeof(struct ext4_xattr_ibody_header) - sizeof(__u32)

In the calculation formula, all values except s_inode_size and
i_extra_size are fixed values. When i_extra_size is the maximum value
s_inode_size - EXT4_GOOD_OLD_INODE_SIZE, min_offs is -4 and free is -8.
The value overflows. As a result, the preceding issue is triggered when
memcpy is executed.

Therefore, when finding xattr or setting xattr, check whether
there is space for storing xattr in the inode to resolve this issue.

Cc: stable@kernel.org
Reported-by: Hulk Robot <hulkci@huawei.com>
Signed-off-by: Baokun Li <libaokun1@huawei.com>
Reviewed-by: Ritesh Harjani (IBM) <ritesh.list@gmail.com>
Reviewed-by: Jan Kara <jack@suse.cz>
Link: https://lore.kernel.org/r/20220616021358.2504451-3-libaokun1@huawei.com
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Tudor Ambarus <tudor.ambarus@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Bug: 253759004
Change-Id: Ib0e74eb2b13884e6ee773748b62cd8a0bcfab3f3
Signed-off-by: Tudor Ambarus <tudor.ambarus@linaro.org>
2023-05-01 09:20:52 +00:00
Ritesh Harjani
ed2290e360 UPSTREAM: ext4: remove duplicate definition of ext4_xattr_ibody_inline_set()
[ Upstream commit 310c097c2bdbea253d6ee4e064f3e65580ef93ac ]

ext4_xattr_ibody_inline_set() & ext4_xattr_ibody_set() have the exact
same definition.  Hence remove ext4_xattr_ibody_inline_set() and all
its call references. Convert the callers of it to call
ext4_xattr_ibody_set() instead.

[ Modified to preserve ext4_xattr_ibody_set() and remove
  ext4_xattr_ibody_inline_set() instead. -- TYT ]

Signed-off-by: Ritesh Harjani <riteshh@linux.ibm.com>
Link: https://lore.kernel.org/r/fd566b799bbbbe9b668eb5eecde5b5e319e3694f.1622685482.git.riteshh@linux.ibm.com
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Tudor Ambarus <tudor.ambarus@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Bug: 253759004
Change-Id: Iaf02894c4f88d79d85ed00363fc83d4b3ba8c575
Signed-off-by: Tudor Ambarus <tudor.ambarus@linaro.org>
2023-05-01 09:20:52 +00:00
Tudor Ambarus
df0f6ba0c5 UPSTREAM: Revert "ext4: fix use-after-free in ext4_xattr_set_entry"
This reverts commit bb8592efcf8ef2f62947745d3182ea05b5256a15 which is
commit 67d7d8ad99beccd9fe92d585b87f1760dc9018e3 upstream.

The order in which patches are queued to stable matters. This patch
has a logical dependency on commit 310c097c2bdbea253d6ee4e064f3e65580ef93ac
upstream, and failing to queue the latter results in a null-ptr-deref
reported at the Link below.

In order to avoid conflicts on stable, revert the commit just so that we
can queue its prerequisite patch first and then queue the same after.

Link: https://syzkaller.appspot.com/bug?extid=d5ebf56f3b1268136afd
Signed-off-by: Tudor Ambarus <tudor.ambarus@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Bug: 253759004
Change-Id: I0e09ac2e68c2b21834ccd620c79f73fadc420170
(cherry picked from commit 9400206d9d5eebc0317da4151364ade32d28944f)
Signed-off-by: Tudor Ambarus <tudor.ambarus@linaro.org>
2023-05-01 09:20:52 +00:00
Greg Kroah-Hartman
734577d21e This is the 5.4.242 stable release
-----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCAAdFiEEZH8oZUiU471FcZm+ONu9yGCSaT4FAmRI7cMACgkQONu9yGCS
 aT4KYhAA11Pj8JrPzyk0LSUHlFmZ6LRUA1/0aAog2V4wIY0tSODHiYMqcqsgiay9
 SGg+eGlHU5+6FL36BGHneg8iLVwX/HHERPdRrOrTJO8YUe/GumFkgz0h2O7+ILOa
 QAao9FB9OBCNaR0guQjTZk+8QQtgfj3X381mBbzoFIIprNUw9/P3lYowyVPSWjHZ
 Ax+ptL2oxfBTGylrU543q7Vfzvy56DSNeDnCNyAHHVAXpQU3YhsWqW5pXcxQhtDh
 aEt21YB0CVBs4BF2sdSpUSXlQYS9NsH814lK3T1pEYONRJ/Osxl9QpdZ077avhTA
 7pS9oKUMNfak8BoK4aRsSy51UrKBnb6IOflJVQiXYRft0GvF630qra47hwZLeZOf
 Sl1tIW0cwlzJcv7H5tsg2eWXsZBCfmvd2MtDHjdYD/fxED7NSvPXjCyO4Qs1UqB9
 vq2cTU0CiCBQPL0UzKeuhPXfSwpbDXYmCMpH2GfHVtlYA1g+zPOlLA9HfGBR0pzH
 X1tdZ9hjUYSBdD5PoaTJzMcg+cME+tPq2kN09dECM+cTdlB/s5cKj8OcNLIv6jVD
 PfFXjJCL1CJk93C4UaHlO7efdQbferEVViu6hmfhGIAYOd3S400/5p71b22rfViH
 9CwkhhlafZ25/AF2NCfhvK5gjRTFH+gOtw0JmG2AQ4f1z44joWw=
 =4sA8
 -----END PGP SIGNATURE-----

Merge 5.4.242 into android11-5.4-lts

Changes in 5.4.242
	ARM: dts: rockchip: fix a typo error for rk3288 spdif node
	arm64: dts: meson-g12-common: specify full DMC range
	netfilter: br_netfilter: fix recent physdev match breakage
	regulator: fan53555: Explicitly include bits header
	net: sched: sch_qfq: prevent slab-out-of-bounds in qfq_activate_agg
	virtio_net: bugfix overflow inside xdp_linearize_page()
	netfilter: nf_tables: fix ifdef to also consider nf_tables=m
	i40e: fix accessing vsi->active_filters without holding lock
	i40e: fix i40e_setup_misc_vector() error handling
	mlxfw: fix null-ptr-deref in mlxfw_mfa2_tlv_next()
	bpf: Fix incorrect verifier pruning due to missing register precision taints
	e1000e: Disable TSO on i219-LM card to increase speed
	f2fs: Fix f2fs_truncate_partial_nodes ftrace event
	Input: i8042 - add quirk for Fujitsu Lifebook A574/H
	selftests: sigaltstack: fix -Wuninitialized
	scsi: megaraid_sas: Fix fw_crash_buffer_show()
	scsi: core: Improve scsi_vpd_inquiry() checks
	net: dsa: b53: mmap: add phy ops
	s390/ptrace: fix PTRACE_GET_LAST_BREAK error handling
	nvme-tcp: fix a possible UAF when failing to allocate an io queue
	xen/netback: use same error messages for same errors
	iio: light: tsl2772: fix reading proximity-diodes from device tree
	nilfs2: initialize unused bytes in segment summary blocks
	memstick: fix memory leak if card device is never registered
	mmc: sdhci_am654: Set HIGH_SPEED_ENA for SDR12 and SDR25
	MIPS: Define RUNTIME_DISCARD_EXIT in LD script
	x86/purgatory: Don't generate debug info for purgatory.ro
	Revert "ext4: fix use-after-free in ext4_xattr_set_entry"
	ext4: remove duplicate definition of ext4_xattr_ibody_inline_set()
	ext4: fix use-after-free in ext4_xattr_set_entry
	udp: Call inet6_destroy_sock() in setsockopt(IPV6_ADDRFORM).
	tcp/udp: Call inet6_destroy_sock() in IPv6 sk->sk_destruct().
	inet6: Remove inet6_destroy_sock() in sk->sk_prot->destroy().
	dccp: Call inet6_destroy_sock() via sk->sk_destruct().
	sctp: Call inet6_destroy_sock() via sk->sk_destruct().
	xfs: fix forkoff miscalculation related to XFS_LITINO(mp)
	pwm: meson: Explicitly set .polarity in .get_state()
	iio: adc: at91-sama5d2_adc: fix an error code in at91_adc_allocate_trigger()
	ASN.1: Fix check for strdup() success
	Linux 5.4.242

Change-Id: Id72de17865bf93d2a6d39009fbc46cb3f8f7b6ca
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2023-04-26 13:21:48 +00:00
Greg Kroah-Hartman
ea7862c507 Linux 5.4.242
Link: https://lore.kernel.org/r/20230424131123.040556994@linuxfoundation.org
Tested-by: Guenter Roeck <linux@roeck-us.net>
Tested-by: Jon Hunter <jonathanh@nvidia.com>
Tested-by: Linux Kernel Functional Testing <lkft@linaro.org>
Tested-by: Chris Paterson (CIP) <chris.paterson2@renesas.com>
Tested-by: Harshit Mogalapalli <harshit.m.mogalapalli@oracle.com>
Tested-by: Florian Fainelli <f.fainelli@gmail.com>
Tested-by: Shuah Khan <skhan@linuxfoundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2023-04-26 11:24:06 +02:00
Ekaterina Orlova
d54a9f999e ASN.1: Fix check for strdup() success
commit 5a43001c01691dcbd396541e6faa2c0077378f48 upstream.

It seems there is a misprint in the check of strdup() return code that
can lead to NULL pointer dereference.

Found by Linux Verification Center (linuxtesting.org) with SVACE.

Fixes: 4520c6a49a ("X.509: Add simple ASN.1 grammar compiler")
Signed-off-by: Ekaterina Orlova <vorobushek.ok@gmail.com>
Cc: David Woodhouse <dwmw2@infradead.org>
Cc: James Bottomley <jejb@linux.ibm.com>
Cc: Jarkko Sakkinen <jarkko@kernel.org>
Cc: keyrings@vger.kernel.org
Cc: linux-kbuild@vger.kernel.org
Link: https://lore.kernel.org/r/20230315172130.140-1-vorobushek.ok@gmail.com/
Signed-off-by: David Howells <dhowells@redhat.com>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2023-04-26 11:24:06 +02:00
Dan Carpenter
2500d7edeb iio: adc: at91-sama5d2_adc: fix an error code in at91_adc_allocate_trigger()
commit 73a428b37b9b538f8f8fe61caa45e7f243bab87c upstream.

The at91_adc_allocate_trigger() function is supposed to return error
pointers.  Returning a NULL will cause an Oops.

Fixes: 5e1a1da0f8 ("iio: adc: at91-sama5d2_adc: add hw trigger and buffer support")
Signed-off-by: Dan Carpenter <error27@gmail.com>
Link: https://lore.kernel.org/r/5d728f9d-31d1-410d-a0b3-df6a63a2c8ba@kili.mountain
Signed-off-by: Jonathan Cameron <Jonathan.Cameron@huawei.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2023-04-26 11:24:06 +02:00
Uwe Kleine-König
760c2e6dee pwm: meson: Explicitly set .polarity in .get_state()
commit 8caa81eb950cb2e9d2d6959b37d853162d197f57 upstream.

The driver only supports normal polarity. Complete the implementation of
.get_state() by setting .polarity accordingly.

This fixes a regression that was possible since commit c73a3107624d
("pwm: Handle .get_state() failures") which stopped to zero-initialize
the state passed to the .get_state() callback. This was reported at
https://forum.odroid.com/viewtopic.php?f=177&t=46360 . While this was an
unintended side effect, the real issue is the driver's callback not
setting the polarity.

There is a complicating fact, that the .apply() callback fakes support
for inversed polarity. This is not (and cannot) be matched by
.get_state(). As fixing this isn't easy, only point it out in a comment
to prevent authors of other drivers from copying that approach.

Fixes: c375bcbaab ("pwm: meson: Read the full hardware state in meson_pwm_get_state()")
Reported-by: Munehisa Kamata <kamatam@amazon.com>
Acked-by: Martin Blumenstingl <martin.blumenstingl@googlemail.com>
Link: https://lore.kernel.org/r/20230310191405.2606296-1-u.kleine-koenig@pengutronix.de
Signed-off-by: Uwe Kleine-König <u.kleine-koenig@pengutronix.de>
Signed-off-by: Thierry Reding <thierry.reding@gmail.com>
Signed-off-by: Uwe Kleine-König <u.kleine-koenig@pengutronix.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2023-04-26 11:24:06 +02:00
Gao Xiang
7f2b8046da xfs: fix forkoff miscalculation related to XFS_LITINO(mp)
commit ada49d64fb3538144192181db05de17e2ffc3551 upstream.

Currently, commit e9e2eae89ddb dropped a (int) decoration from
XFS_LITINO(mp), and since sizeof() expression is also involved,
the result of XFS_LITINO(mp) is simply as the size_t type
(commonly unsigned long).

Considering the expression in xfs_attr_shortform_bytesfit():
  offset = (XFS_LITINO(mp) - bytes) >> 3;
let "bytes" be (int)340, and
    "XFS_LITINO(mp)" be (unsigned long)336.

on 64-bit platform, the expression is
  offset = ((unsigned long)336 - (int)340) >> 3 =
           (int)(0xfffffffffffffffcUL >> 3) = -1

but on 32-bit platform, the expression is
  offset = ((unsigned long)336 - (int)340) >> 3 =
           (int)(0xfffffffcUL >> 3) = 0x1fffffff
instead.

so offset becomes a large positive number on 32-bit platform, and
cause xfs_attr_shortform_bytesfit() returns maxforkoff rather than 0.

Therefore, one result is
  "ASSERT(new_size <= XFS_IFORK_SIZE(ip, whichfork));"

assertion failure in xfs_idata_realloc(), which was also the root
cause of the original bugreport from Dennis, see:
   https://bugzilla.redhat.com/show_bug.cgi?id=1894177

And it can also be manually triggered with the following commands:
  $ touch a;
  $ setfattr -n user.0 -v "`seq 0 80`" a;
  $ setfattr -n user.1 -v "`seq 0 80`" a

on 32-bit platform.

Fix the case in xfs_attr_shortform_bytesfit() by bailing out
"XFS_LITINO(mp) < bytes" in advance suggested by Eric and a misleading
comment together with this bugfix suggested by Darrick. It seems the
other users of XFS_LITINO(mp) are not impacted.

Fixes: e9e2eae89ddb ("xfs: only check the superblock version for dinode size calculation")
Cc: <stable@vger.kernel.org> # 5.7+
Reported-and-tested-by: Dennis Gilmore <dgilmore@redhat.com>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Gao Xiang <hsiangkao@redhat.com>
Reviewed-by: Darrick J. Wong <darrick.wong@oracle.com>
Signed-off-by: Darrick J. Wong <darrick.wong@oracle.com>
Signed-off-by: Chandan Babu R <chandan.babu@oracle.com>
Acked-by: Darrick J. Wong <djwong@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2023-04-26 11:24:06 +02:00
Kuniyuki Iwashima
c27a6bb178 sctp: Call inet6_destroy_sock() via sk->sk_destruct().
commit 6431b0f6ff1633ae598667e4cdd93830074a03e8 upstream.

After commit d38afeec26ed ("tcp/udp: Call inet6_destroy_sock()
in IPv6 sk->sk_destruct()."), we call inet6_destroy_sock() in
sk->sk_destruct() by setting inet6_sock_destruct() to it to make
sure we do not leak inet6-specific resources.

SCTP sets its own sk->sk_destruct() in the sctp_init_sock(), and
SCTPv6 socket reuses it as the init function.

To call inet6_sock_destruct() from SCTPv6 sk->sk_destruct(), we
set sctp_v6_destruct_sock() in a new init function.

Signed-off-by: Kuniyuki Iwashima <kuniyu@amazon.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Ziyang Xuan <william.xuanziyang@huawei.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2023-04-26 11:24:05 +02:00
Kuniyuki Iwashima
97ce6cde1f dccp: Call inet6_destroy_sock() via sk->sk_destruct().
commit 1651951ebea54970e0bda60c638fc2eee7a6218f upstream.

After commit d38afeec26ed ("tcp/udp: Call inet6_destroy_sock()
in IPv6 sk->sk_destruct()."), we call inet6_destroy_sock() in
sk->sk_destruct() by setting inet6_sock_destruct() to it to make
sure we do not leak inet6-specific resources.

DCCP sets its own sk->sk_destruct() in the dccp_init_sock(), and
DCCPv6 socket shares it by calling the same init function via
dccp_v6_init_sock().

To call inet6_sock_destruct() from DCCPv6 sk->sk_destruct(), we
export it and set dccp_v6_sk_destruct() in the init function.

Signed-off-by: Kuniyuki Iwashima <kuniyu@amazon.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Ziyang Xuan <william.xuanziyang@huawei.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2023-04-26 11:24:05 +02:00
Kuniyuki Iwashima
a01b75620e inet6: Remove inet6_destroy_sock() in sk->sk_prot->destroy().
commit b5fc29233d28be7a3322848ebe73ac327559cdb9 upstream.

After commit d38afeec26ed ("tcp/udp: Call inet6_destroy_sock()
in IPv6 sk->sk_destruct()."), we call inet6_destroy_sock() in
sk->sk_destruct() by setting inet6_sock_destruct() to it to make
sure we do not leak inet6-specific resources.

Now we can remove unnecessary inet6_destroy_sock() calls in
sk->sk_prot->destroy().

DCCP and SCTP have their own sk->sk_destruct() function, so we
change them separately in the following patches.

Signed-off-by: Kuniyuki Iwashima <kuniyu@amazon.com>
Reviewed-by: Matthieu Baerts <matthieu.baerts@tessares.net>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Ziyang Xuan <william.xuanziyang@huawei.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2023-04-26 11:24:05 +02:00
Kuniyuki Iwashima
9374db5bd1 tcp/udp: Call inet6_destroy_sock() in IPv6 sk->sk_destruct().
commit d38afeec26ed4739c640bf286c270559aab2ba5f upstream.

Originally, inet6_sk(sk)->XXX were changed under lock_sock(), so we were
able to clean them up by calling inet6_destroy_sock() during the IPv6 ->
IPv4 conversion by IPV6_ADDRFORM.  However, commit 03485f2adc ("udpv6:
Add lockless sendmsg() support") added a lockless memory allocation path,
which could cause a memory leak:

setsockopt(IPV6_ADDRFORM)                 sendmsg()
+-----------------------+                 +-------+
- do_ipv6_setsockopt(sk, ...)             - udpv6_sendmsg(sk, ...)
  - sockopt_lock_sock(sk)                   ^._ called via udpv6_prot
    - lock_sock(sk)                             before WRITE_ONCE()
  - WRITE_ONCE(sk->sk_prot, &tcp_prot)
  - inet6_destroy_sock()                    - if (!corkreq)
  - sockopt_release_sock(sk)                  - ip6_make_skb(sk, ...)
    - release_sock(sk)                          ^._ lockless fast path for
                                                    the non-corking case

                                                - __ip6_append_data(sk, ...)
                                                  - ipv6_local_rxpmtu(sk, ...)
                                                    - xchg(&np->rxpmtu, skb)
                                                      ^._ rxpmtu is never freed.

                                                - goto out_no_dst;

                                            - lock_sock(sk)

For now, rxpmtu is only the case, but not to miss the future change
and a similar bug fixed in commit e27326009a3d ("net: ping6: Fix
memleak in ipv6_renew_options()."), let's set a new function to IPv6
sk->sk_destruct() and call inet6_cleanup_sock() there.  Since the
conversion does not change sk->sk_destruct(), we can guarantee that
we can clean up IPv6 resources finally.

We can now remove all inet6_destroy_sock() calls from IPv6 protocol
specific ->destroy() functions, but such changes are invasive to
backport.  So they can be posted as a follow-up later for net-next.

Fixes: 03485f2adc ("udpv6: Add lockless sendmsg() support")
Signed-off-by: Kuniyuki Iwashima <kuniyu@amazon.com>
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Ziyang Xuan <william.xuanziyang@huawei.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2023-04-26 11:24:05 +02:00
Kuniyuki Iwashima
2ac4697b77 udp: Call inet6_destroy_sock() in setsockopt(IPV6_ADDRFORM).
commit 21985f43376cee092702d6cb963ff97a9d2ede68 upstream.

Commit 4b340ae20d ("IPv6: Complete IPV6_DONTFRAG support") forgot
to add a change to free inet6_sk(sk)->rxpmtu while converting an IPv6
socket into IPv4 with IPV6_ADDRFORM.  After conversion, sk_prot is
changed to udp_prot and ->destroy() never cleans it up, resulting in
a memory leak.

This is due to the discrepancy between inet6_destroy_sock() and
IPV6_ADDRFORM, so let's call inet6_destroy_sock() from IPV6_ADDRFORM
to remove the difference.

However, this is not enough for now because rxpmtu can be changed
without lock_sock() after commit 03485f2adc ("udpv6: Add lockless
sendmsg() support").  We will fix this case in the following patch.

Note we will rename inet6_destroy_sock() to inet6_cleanup_sock() and
remove unnecessary inet6_destroy_sock() calls in sk_prot->destroy()
in the future.

Fixes: 4b340ae20d ("IPv6: Complete IPV6_DONTFRAG support")
Signed-off-by: Kuniyuki Iwashima <kuniyu@amazon.com>
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Ziyang Xuan <william.xuanziyang@huawei.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2023-04-26 11:24:05 +02:00
Baokun Li
5a62248c58 ext4: fix use-after-free in ext4_xattr_set_entry
[ Upstream commit 67d7d8ad99beccd9fe92d585b87f1760dc9018e3 ]

Hulk Robot reported a issue:
==================================================================
BUG: KASAN: use-after-free in ext4_xattr_set_entry+0x18ab/0x3500
Write of size 4105 at addr ffff8881675ef5f4 by task syz-executor.0/7092

CPU: 1 PID: 7092 Comm: syz-executor.0 Not tainted 4.19.90-dirty #17
Call Trace:
[...]
 memcpy+0x34/0x50 mm/kasan/kasan.c:303
 ext4_xattr_set_entry+0x18ab/0x3500 fs/ext4/xattr.c:1747
 ext4_xattr_ibody_inline_set+0x86/0x2a0 fs/ext4/xattr.c:2205
 ext4_xattr_set_handle+0x940/0x1300 fs/ext4/xattr.c:2386
 ext4_xattr_set+0x1da/0x300 fs/ext4/xattr.c:2498
 __vfs_setxattr+0x112/0x170 fs/xattr.c:149
 __vfs_setxattr_noperm+0x11b/0x2a0 fs/xattr.c:180
 __vfs_setxattr_locked+0x17b/0x250 fs/xattr.c:238
 vfs_setxattr+0xed/0x270 fs/xattr.c:255
 setxattr+0x235/0x330 fs/xattr.c:520
 path_setxattr+0x176/0x190 fs/xattr.c:539
 __do_sys_lsetxattr fs/xattr.c:561 [inline]
 __se_sys_lsetxattr fs/xattr.c:557 [inline]
 __x64_sys_lsetxattr+0xc2/0x160 fs/xattr.c:557
 do_syscall_64+0xdf/0x530 arch/x86/entry/common.c:298
 entry_SYSCALL_64_after_hwframe+0x44/0xa9
RIP: 0033:0x459fe9
RSP: 002b:00007fa5e54b4c08 EFLAGS: 00000246 ORIG_RAX: 00000000000000bd
RAX: ffffffffffffffda RBX: 000000000051bf60 RCX: 0000000000459fe9
RDX: 00000000200003c0 RSI: 0000000020000180 RDI: 0000000020000140
RBP: 000000000051bf60 R08: 0000000000000001 R09: 0000000000000000
R10: 0000000000001009 R11: 0000000000000246 R12: 0000000000000000
R13: 00007ffc73c93fc0 R14: 000000000051bf60 R15: 00007fa5e54b4d80
[...]
==================================================================

Above issue may happen as follows:
-------------------------------------
ext4_xattr_set
  ext4_xattr_set_handle
    ext4_xattr_ibody_find
      >> s->end < s->base
      >> no EXT4_STATE_XATTR
      >> xattr_check_inode is not executed
    ext4_xattr_ibody_set
      ext4_xattr_set_entry
       >> size_t min_offs = s->end - s->base
       >> UAF in memcpy

we can easily reproduce this problem with the following commands:
    mkfs.ext4 -F /dev/sda
    mount -o debug_want_extra_isize=128 /dev/sda /mnt
    touch /mnt/file
    setfattr -n user.cat -v `seq -s z 4096|tr -d '[:digit:]'` /mnt/file

In ext4_xattr_ibody_find, we have the following assignment logic:
  header = IHDR(inode, raw_inode)
         = raw_inode + EXT4_GOOD_OLD_INODE_SIZE + i_extra_isize
  is->s.base = IFIRST(header)
             = header + sizeof(struct ext4_xattr_ibody_header)
  is->s.end = raw_inode + s_inode_size

In ext4_xattr_set_entry
  min_offs = s->end - s->base
           = s_inode_size - EXT4_GOOD_OLD_INODE_SIZE - i_extra_isize -
	     sizeof(struct ext4_xattr_ibody_header)
  last = s->first
  free = min_offs - ((void *)last - s->base) - sizeof(__u32)
       = s_inode_size - EXT4_GOOD_OLD_INODE_SIZE - i_extra_isize -
         sizeof(struct ext4_xattr_ibody_header) - sizeof(__u32)

In the calculation formula, all values except s_inode_size and
i_extra_size are fixed values. When i_extra_size is the maximum value
s_inode_size - EXT4_GOOD_OLD_INODE_SIZE, min_offs is -4 and free is -8.
The value overflows. As a result, the preceding issue is triggered when
memcpy is executed.

Therefore, when finding xattr or setting xattr, check whether
there is space for storing xattr in the inode to resolve this issue.

Cc: stable@kernel.org
Reported-by: Hulk Robot <hulkci@huawei.com>
Signed-off-by: Baokun Li <libaokun1@huawei.com>
Reviewed-by: Ritesh Harjani (IBM) <ritesh.list@gmail.com>
Reviewed-by: Jan Kara <jack@suse.cz>
Link: https://lore.kernel.org/r/20220616021358.2504451-3-libaokun1@huawei.com
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Tudor Ambarus <tudor.ambarus@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2023-04-26 11:24:05 +02:00
Ritesh Harjani
3b0044cb28 ext4: remove duplicate definition of ext4_xattr_ibody_inline_set()
[ Upstream commit 310c097c2bdbea253d6ee4e064f3e65580ef93ac ]

ext4_xattr_ibody_inline_set() & ext4_xattr_ibody_set() have the exact
same definition.  Hence remove ext4_xattr_ibody_inline_set() and all
its call references. Convert the callers of it to call
ext4_xattr_ibody_set() instead.

[ Modified to preserve ext4_xattr_ibody_set() and remove
  ext4_xattr_ibody_inline_set() instead. -- TYT ]

Signed-off-by: Ritesh Harjani <riteshh@linux.ibm.com>
Link: https://lore.kernel.org/r/fd566b799bbbbe9b668eb5eecde5b5e319e3694f.1622685482.git.riteshh@linux.ibm.com
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Tudor Ambarus <tudor.ambarus@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2023-04-26 11:24:05 +02:00
Tudor Ambarus
3c4fdbf368 Revert "ext4: fix use-after-free in ext4_xattr_set_entry"
This reverts commit bb8592efcf8ef2f62947745d3182ea05b5256a15 which is
commit 67d7d8ad99beccd9fe92d585b87f1760dc9018e3 upstream.

The order in which patches are queued to stable matters. This patch
has a logical dependency on commit 310c097c2bdbea253d6ee4e064f3e65580ef93ac
upstream, and failing to queue the latter results in a null-ptr-deref
reported at the Link below.

In order to avoid conflicts on stable, revert the commit just so that we
can queue its prerequisite patch first and then queue the same after.

Link: https://syzkaller.appspot.com/bug?extid=d5ebf56f3b1268136afd
Signed-off-by: Tudor Ambarus <tudor.ambarus@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2023-04-26 11:24:04 +02:00
Pingfan Liu
ef2aab86c3 x86/purgatory: Don't generate debug info for purgatory.ro
commit 52416ffcf823ee11aa19792715664ab94757f111 upstream.

Purgatory.ro is a standalone binary that is not linked against the rest of
the kernel.  Its image is copied into an array that is linked to the
kernel, and from there kexec relocates it wherever it desires.

Unlike the debug info for vmlinux, which can be used for analyzing crash
such info is useless in purgatory.ro. And discarding them can save about
200K space.

 Original:
   259080  kexec-purgatory.o
 Stripped debug info:
    29152  kexec-purgatory.o

Signed-off-by: Pingfan Liu <kernelfans@gmail.com>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Reviewed-by: Nick Desaulniers <ndesaulniers@google.com>
Reviewed-by: Steve Wahl <steve.wahl@hpe.com>
Acked-by: Dave Young <dyoung@redhat.com>
Link: https://lore.kernel.org/r/1596433788-3784-1-git-send-email-kernelfans@gmail.com
[Alyssa: fixed for LLVM_IAS=1 by adding -g to AFLAGS_REMOVE_*]
Signed-off-by: Alyssa Ross <hi@alyssa.is>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2023-04-26 11:24:04 +02:00
Jiaxun Yang
c22aefaef8 MIPS: Define RUNTIME_DISCARD_EXIT in LD script
commit 6dcbd0a69c84a8ae7a442840a8cf6b1379dc8f16 upstream.

MIPS's exit sections are discarded at runtime as well.

Fixes link error:
`.exit.text' referenced in section `__jump_table' of fs/fuse/inode.o:
defined in discarded section `.exit.text' of fs/fuse/inode.o

Fixes: 99cb0d917ffa ("arch: fix broken BuildID for arm64 and riscv")
Reported-by: "kernelci.org bot" <bot@kernelci.org>
Signed-off-by: Jiaxun Yang <jiaxun.yang@flygoat.com>
Signed-off-by: Thomas Bogendoerfer <tsbogend@alpha.franken.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2023-04-26 11:24:04 +02:00
Bhavya Kapoor
a5167e902b mmc: sdhci_am654: Set HIGH_SPEED_ENA for SDR12 and SDR25
commit 2265098fd6a6272fde3fd1be5761f2f5895bd99a upstream.

Timing Information in Datasheet assumes that HIGH_SPEED_ENA=1 should be
set for SDR12 and SDR25 modes. But sdhci_am654 driver clears
HIGH_SPEED_ENA register. Thus, Modify sdhci_am654 to not clear
HIGH_SPEED_ENA (HOST_CONTROL[2]) bit for SDR12 and SDR25 speed modes.

Fixes: e374e87538 ("mmc: sdhci_am654: Clear HISPD_ENA in some lower speed modes")
Signed-off-by: Bhavya Kapoor <b-kapoor@ti.com>
Cc: stable@vger.kernel.org
Link: https://lore.kernel.org/r/20230317092711.660897-1-b-kapoor@ti.com
Signed-off-by: Ulf Hansson <ulf.hansson@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2023-04-26 11:24:04 +02:00
Greg Kroah-Hartman
1b8b54fc55 memstick: fix memory leak if card device is never registered
commit 4b6d621c9d859ff89e68cebf6178652592676013 upstream.

When calling dev_set_name() memory is allocated for the name for the
struct device.  Once that structure device is registered, or attempted
to be registerd, with the driver core, the driver core will handle
cleaning up that memory when the device is removed from the system.

Unfortunatly for the memstick code, there is an error path that causes
the struct device to never be registered, and so the memory allocated in
dev_set_name will be leaked.  Fix that leak by manually freeing it right
before the memory for the device is freed.

Cc: Maxim Levitsky <maximlevitsky@gmail.com>
Cc: Alex Dubov <oakad@yahoo.com>
Cc: Ulf Hansson <ulf.hansson@linaro.org>
Cc: "Rafael J. Wysocki" <rafael@kernel.org>
Cc: Hans de Goede <hdegoede@redhat.com>
Cc: Kay Sievers <kay.sievers@vrfy.org>
Cc: linux-mmc@vger.kernel.org
Fixes: 0252c3b4f0 ("memstick: struct device - replace bus_id with dev_name(), dev_set_name()")
Cc: stable <stable@kernel.org>
Co-developed-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Co-developed-by: Mirsad Goran Todorovac <mirsad.todorovac@alu.unizg.hr>
Signed-off-by: Mirsad Goran Todorovac <mirsad.todorovac@alu.unizg.hr>
Link: https://lore.kernel.org/r/20230401200327.16800-1-gregkh@linuxfoundation.org
Signed-off-by: Ulf Hansson <ulf.hansson@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2023-04-26 11:24:04 +02:00
Ryusuke Konishi
5ad61a5268 nilfs2: initialize unused bytes in segment summary blocks
commit ef832747a82dfbc22a3702219cc716f449b24e4a upstream.

Syzbot still reports uninit-value in nilfs_add_checksums_on_logs() for
KMSAN enabled kernels after applying commit 7397031622e0 ("nilfs2:
initialize "struct nilfs_binfo_dat"->bi_pad field").

This is because the unused bytes at the end of each block in segment
summaries are not initialized.  So this fixes the issue by padding the
unused bytes with null bytes.

Link: https://lkml.kernel.org/r/20230417173513.12598-1-konishi.ryusuke@gmail.com
Signed-off-by: Ryusuke Konishi <konishi.ryusuke@gmail.com>
Tested-by: Ryusuke Konishi <konishi.ryusuke@gmail.com>
Reported-by: syzbot+048585f3f4227bb2b49b@syzkaller.appspotmail.com
  Link: https://syzkaller.appspot.com/bug?extid=048585f3f4227bb2b49b
Cc: Alexander Potapenko <glider@google.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2023-04-26 11:24:04 +02:00
Brian Masney
988766b9d1 iio: light: tsl2772: fix reading proximity-diodes from device tree
commit b1cb00d51e361cf5af93649917d9790e1623647e upstream.

tsl2772_read_prox_diodes() will correctly parse the properties from
device tree to determine which proximity diode(s) to read from, however
it didn't actually set this value on the struct tsl2772_settings. Let's
go ahead and fix that.

Reported-by: Tom Rix <trix@redhat.com>
Link: https://lore.kernel.org/lkml/20230327120823.1369700-1-trix@redhat.com/
Fixes: 94cd1113aa ("iio: tsl2772: add support for reading proximity led settings from device tree")
Signed-off-by: Brian Masney <bmasney@redhat.com>
Link: https://lore.kernel.org/r/20230404011455.339454-1-bmasney@redhat.com
Cc: <Stable@vger.kernel.org>
Signed-off-by: Jonathan Cameron <Jonathan.Cameron@huawei.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2023-04-26 11:24:04 +02:00
Juergen Gross
5cb867f1ec xen/netback: use same error messages for same errors
[ Upstream commit 2eca98e5b24d01c02b46c67be05a5f98cc9789b1 ]

Issue the same error message in case an illegal page boundary crossing
has been detected in both cases where this is tested.

Suggested-by: Jan Beulich <jbeulich@suse.com>
Signed-off-by: Juergen Gross <jgross@suse.com>
Reviewed-by: Jan Beulich <jbeulich@suse.com>
Link: https://lore.kernel.org/r/20230329080259.14823-1-jgross@suse.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2023-04-26 11:24:04 +02:00
Sagi Grimberg
903f82b1a6 nvme-tcp: fix a possible UAF when failing to allocate an io queue
[ Upstream commit 88eaba80328b31ef81813a1207b4056efd7006a6 ]

When we allocate a nvme-tcp queue, we set the data_ready callback before
we actually need to use it. This creates the potential that if a stray
controller sends us data on the socket before we connect, we can trigger
the io_work and start consuming the socket.

In this case reported: we failed to allocate one of the io queues, and
as we start releasing the queues that we already allocated, we get
a UAF [1] from the io_work which is running before it should really.

Fix this by setting the socket ops callbacks only before we start the
queue, so that we can't accidentally schedule the io_work in the
initialization phase before the queue started. While we are at it,
rename nvme_tcp_restore_sock_calls to pair with nvme_tcp_setup_sock_ops.

[1]:
[16802.107284] nvme nvme4: starting error recovery
[16802.109166] nvme nvme4: Reconnecting in 10 seconds...
[16812.173535] nvme nvme4: failed to connect socket: -111
[16812.173745] nvme nvme4: Failed reconnect attempt 1
[16812.173747] nvme nvme4: Reconnecting in 10 seconds...
[16822.413555] nvme nvme4: failed to connect socket: -111
[16822.413762] nvme nvme4: Failed reconnect attempt 2
[16822.413765] nvme nvme4: Reconnecting in 10 seconds...
[16832.661274] nvme nvme4: creating 32 I/O queues.
[16833.919887] BUG: kernel NULL pointer dereference, address: 0000000000000088
[16833.920068] nvme nvme4: Failed reconnect attempt 3
[16833.920094] #PF: supervisor write access in kernel mode
[16833.920261] nvme nvme4: Reconnecting in 10 seconds...
[16833.920368] #PF: error_code(0x0002) - not-present page
[16833.921086] Workqueue: nvme_tcp_wq nvme_tcp_io_work [nvme_tcp]
[16833.921191] RIP: 0010:_raw_spin_lock_bh+0x17/0x30
...
[16833.923138] Call Trace:
[16833.923271]  <TASK>
[16833.923402]  lock_sock_nested+0x1e/0x50
[16833.923545]  nvme_tcp_try_recv+0x40/0xa0 [nvme_tcp]
[16833.923685]  nvme_tcp_io_work+0x68/0xa0 [nvme_tcp]
[16833.923824]  process_one_work+0x1e8/0x390
[16833.923969]  worker_thread+0x53/0x3d0
[16833.924104]  ? process_one_work+0x390/0x390
[16833.924240]  kthread+0x124/0x150
[16833.924376]  ? set_kthread_struct+0x50/0x50
[16833.924518]  ret_from_fork+0x1f/0x30
[16833.924655]  </TASK>

Reported-by: Yanjun Zhang <zhangyanjun@cestc.cn>
Signed-off-by: Sagi Grimberg <sagi@grimberg.me>
Tested-by: Yanjun Zhang <zhangyanjun@cestc.com>
Signed-off-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2023-04-26 11:24:03 +02:00
Heiko Carstens
34b74c32ff s390/ptrace: fix PTRACE_GET_LAST_BREAK error handling
[ Upstream commit f9bbf25e7b2b74b52b2f269216a92657774f239c ]

Return -EFAULT if put_user() for the PTRACE_GET_LAST_BREAK
request fails, instead of silently ignoring it.

Reviewed-by: Sven Schnelle <svens@linux.ibm.com>
Signed-off-by: Heiko Carstens <hca@linux.ibm.com>
Signed-off-by: Vasily Gorbik <gor@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2023-04-26 11:24:03 +02:00
Álvaro Fernández Rojas
64cd99da25 net: dsa: b53: mmap: add phy ops
[ Upstream commit 45977e58ce65ed0459edc9a0466d9dfea09463f5 ]

Implement phy_read16() and phy_write16() ops for B53 MMAP to avoid accessing
B53_PORT_MII_PAGE registers which hangs the device.
This access should be done through the MDIO Mux bus controller.

Signed-off-by: Álvaro Fernández Rojas <noltari@gmail.com>
Acked-by: Florian Fainelli <f.fainelli@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2023-04-26 11:24:03 +02:00
Damien Le Moal
89dcf0dd7a scsi: core: Improve scsi_vpd_inquiry() checks
[ Upstream commit f0aa59a33d2ac2267d260fe21eaf92500df8e7b4 ]

Some USB-SATA adapters have broken behavior when an unsupported VPD page is
probed: Depending on the VPD page number, a 4-byte header with a valid VPD
page number but with a 0 length is returned. Currently, scsi_vpd_inquiry()
only checks that the page number is valid to determine if the page is
valid, which results in receiving only the 4-byte header for the
non-existent page. This error manifests itself very often with page 0xb9
for the Concurrent Positioning Ranges detection done by sd_read_cpr(),
resulting in the following error message:

sd 0:0:0:0: [sda] Invalid Concurrent Positioning Ranges VPD page

Prevent such misleading error message by adding a check in
scsi_vpd_inquiry() to verify that the page length is not 0.

Signed-off-by: Damien Le Moal <damien.lemoal@opensource.wdc.com>
Link: https://lore.kernel.org/r/20230322022211.116327-1-damien.lemoal@opensource.wdc.com
Reviewed-by: Benjamin Block <bblock@linux.ibm.com>
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2023-04-26 11:24:03 +02:00
Tomas Henzl
f729b74bb4 scsi: megaraid_sas: Fix fw_crash_buffer_show()
[ Upstream commit 0808ed6ebbc292222ca069d339744870f6d801da ]

If crash_dump_buf is not allocated then crash dump can't be available.
Replace logical 'and' with 'or'.

Signed-off-by: Tomas Henzl <thenzl@redhat.com>
Link: https://lore.kernel.org/r/20230324135249.9733-1-thenzl@redhat.com
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2023-04-26 11:24:03 +02:00
Nick Desaulniers
4f4ef354f9 selftests: sigaltstack: fix -Wuninitialized
[ Upstream commit 05107edc910135d27fe557267dc45be9630bf3dd ]

Building sigaltstack with clang via:
$ ARCH=x86 make LLVM=1 -C tools/testing/selftests/sigaltstack/

produces the following warning:
  warning: variable 'sp' is uninitialized when used here [-Wuninitialized]
  if (sp < (unsigned long)sstack ||
      ^~

Clang expects these to be declared at global scope; we've fixed this in
the kernel proper by using the macro `current_stack_pointer`. This is
defined in different headers for different target architectures, so just
create a new header that defines the arch-specific register names for
the stack pointer register, and define it for more targets (at least the
ones that support current_stack_pointer/ARCH_HAS_CURRENT_STACK_POINTER).

Reported-by: Linux Kernel Functional Testing <lkft@linaro.org>
Link: https://lore.kernel.org/lkml/CA+G9fYsi3OOu7yCsMutpzKDnBMAzJBCPimBp86LhGBa0eCnEpA@mail.gmail.com/
Signed-off-by: Nick Desaulniers <ndesaulniers@google.com>
Reviewed-by: Kees Cook <keescook@chromium.org>
Tested-by: Linux Kernel Functional Testing <lkft@linaro.org>
Tested-by: Anders Roxell <anders.roxell@linaro.org>
Signed-off-by: Shuah Khan <skhan@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2023-04-26 11:24:03 +02:00
Jonathan Denose
a725dddf21 Input: i8042 - add quirk for Fujitsu Lifebook A574/H
[ Upstream commit f5bad62f9107b701a6def7cac1f5f65862219b83 ]

Fujitsu Lifebook A574/H requires the nomux option to properly
probe the touchpad, especially when waking from sleep.

Signed-off-by: Jonathan Denose <jdenose@google.com>
Reviewed-by: Hans de Goede <hdegoede@redhat.com>
Link: https://lore.kernel.org/r/20230303152623.45859-1-jdenose@google.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2023-04-26 11:24:03 +02:00
Douglas Raillard
9df3f502e3 f2fs: Fix f2fs_truncate_partial_nodes ftrace event
[ Upstream commit 0b04d4c0542e8573a837b1d81b94209e48723b25 ]

Fix the nid_t field so that its size is correctly reported in the text
format embedded in trace.dat files. As it stands, it is reported as
being of size 4:

        field:nid_t nid[3];     offset:24;      size:4; signed:0;

Instead of 12:

        field:nid_t nid[3];     offset:24;      size:12;        signed:0;

This also fixes the reported offset of subsequent fields so that they
match with the actual struct layout.

Signed-off-by: Douglas Raillard <douglas.raillard@arm.com>
Reviewed-by: Mukesh Ojha <quic_mojha@quicinc.com>
Reviewed-by: Chao Yu <chao@kernel.org>
Signed-off-by: Jaegeuk Kim <jaegeuk@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2023-04-26 11:24:03 +02:00
Sebastian Basierski
2f3730f182 e1000e: Disable TSO on i219-LM card to increase speed
[ Upstream commit 67d47b95119ad589b0a0b16b88b1dd9a04061ced ]

While using i219-LM card currently it was only possible to achieve
about 60% of maximum speed due to regression introduced in Linux 5.8.
This was caused by TSO not being disabled by default despite commit
f29801030ac6 ("e1000e: Disable TSO for buffer overrun workaround").
Fix that by disabling TSO during driver probe.

Fixes: f29801030ac6 ("e1000e: Disable TSO for buffer overrun workaround")
Signed-off-by: Sebastian Basierski <sebastianx.basierski@intel.com>
Signed-off-by: Mateusz Palczewski <mateusz.palczewski@intel.com>
Tested-by: Naama Meir <naamax.meir@linux.intel.com>
Signed-off-by: Tony Nguyen <anthony.l.nguyen@intel.com>
Reviewed-by: Simon Horman <simon.horman@corigine.com>
Link: https://lore.kernel.org/r/20230417205345.1030801-1-anthony.l.nguyen@intel.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2023-04-26 11:24:02 +02:00
Daniel Borkmann
0f0a291cc5 bpf: Fix incorrect verifier pruning due to missing register precision taints
[ Upstream commit 71b547f561247897a0a14f3082730156c0533fed ]

Juan Jose et al reported an issue found via fuzzing where the verifier's
pruning logic prematurely marks a program path as safe.

Consider the following program:

   0: (b7) r6 = 1024
   1: (b7) r7 = 0
   2: (b7) r8 = 0
   3: (b7) r9 = -2147483648
   4: (97) r6 %= 1025
   5: (05) goto pc+0
   6: (bd) if r6 <= r9 goto pc+2
   7: (97) r6 %= 1
   8: (b7) r9 = 0
   9: (bd) if r6 <= r9 goto pc+1
  10: (b7) r6 = 0
  11: (b7) r0 = 0
  12: (63) *(u32 *)(r10 -4) = r0
  13: (18) r4 = 0xffff888103693400 // map_ptr(ks=4,vs=48)
  15: (bf) r1 = r4
  16: (bf) r2 = r10
  17: (07) r2 += -4
  18: (85) call bpf_map_lookup_elem#1
  19: (55) if r0 != 0x0 goto pc+1
  20: (95) exit
  21: (77) r6 >>= 10
  22: (27) r6 *= 8192
  23: (bf) r1 = r0
  24: (0f) r0 += r6
  25: (79) r3 = *(u64 *)(r0 +0)
  26: (7b) *(u64 *)(r1 +0) = r3
  27: (95) exit

The verifier treats this as safe, leading to oob read/write access due
to an incorrect verifier conclusion:

  func#0 @0
  0: R1=ctx(off=0,imm=0) R10=fp0
  0: (b7) r6 = 1024                     ; R6_w=1024
  1: (b7) r7 = 0                        ; R7_w=0
  2: (b7) r8 = 0                        ; R8_w=0
  3: (b7) r9 = -2147483648              ; R9_w=-2147483648
  4: (97) r6 %= 1025                    ; R6_w=scalar()
  5: (05) goto pc+0
  6: (bd) if r6 <= r9 goto pc+2         ; R6_w=scalar(umin=18446744071562067969,var_off=(0xffffffff00000000; 0xffffffff)) R9_w=-2147483648
  7: (97) r6 %= 1                       ; R6_w=scalar()
  8: (b7) r9 = 0                        ; R9=0
  9: (bd) if r6 <= r9 goto pc+1         ; R6=scalar(umin=1) R9=0
  10: (b7) r6 = 0                       ; R6_w=0
  11: (b7) r0 = 0                       ; R0_w=0
  12: (63) *(u32 *)(r10 -4) = r0
  last_idx 12 first_idx 9
  regs=1 stack=0 before 11: (b7) r0 = 0
  13: R0_w=0 R10=fp0 fp-8=0000????
  13: (18) r4 = 0xffff8ad3886c2a00      ; R4_w=map_ptr(off=0,ks=4,vs=48,imm=0)
  15: (bf) r1 = r4                      ; R1_w=map_ptr(off=0,ks=4,vs=48,imm=0) R4_w=map_ptr(off=0,ks=4,vs=48,imm=0)
  16: (bf) r2 = r10                     ; R2_w=fp0 R10=fp0
  17: (07) r2 += -4                     ; R2_w=fp-4
  18: (85) call bpf_map_lookup_elem#1   ; R0=map_value_or_null(id=1,off=0,ks=4,vs=48,imm=0)
  19: (55) if r0 != 0x0 goto pc+1       ; R0=0
  20: (95) exit

  from 19 to 21: R0=map_value(off=0,ks=4,vs=48,imm=0) R6=0 R7=0 R8=0 R9=0 R10=fp0 fp-8=mmmm????
  21: (77) r6 >>= 10                    ; R6_w=0
  22: (27) r6 *= 8192                   ; R6_w=0
  23: (bf) r1 = r0                      ; R0=map_value(off=0,ks=4,vs=48,imm=0) R1_w=map_value(off=0,ks=4,vs=48,imm=0)
  24: (0f) r0 += r6
  last_idx 24 first_idx 19
  regs=40 stack=0 before 23: (bf) r1 = r0
  regs=40 stack=0 before 22: (27) r6 *= 8192
  regs=40 stack=0 before 21: (77) r6 >>= 10
  regs=40 stack=0 before 19: (55) if r0 != 0x0 goto pc+1
  parent didn't have regs=40 stack=0 marks: R0_rw=map_value_or_null(id=1,off=0,ks=4,vs=48,imm=0) R6_rw=P0 R7=0 R8=0 R9=0 R10=fp0 fp-8=mmmm????
  last_idx 18 first_idx 9
  regs=40 stack=0 before 18: (85) call bpf_map_lookup_elem#1
  regs=40 stack=0 before 17: (07) r2 += -4
  regs=40 stack=0 before 16: (bf) r2 = r10
  regs=40 stack=0 before 15: (bf) r1 = r4
  regs=40 stack=0 before 13: (18) r4 = 0xffff8ad3886c2a00
  regs=40 stack=0 before 12: (63) *(u32 *)(r10 -4) = r0
  regs=40 stack=0 before 11: (b7) r0 = 0
  regs=40 stack=0 before 10: (b7) r6 = 0
  25: (79) r3 = *(u64 *)(r0 +0)         ; R0_w=map_value(off=0,ks=4,vs=48,imm=0) R3_w=scalar()
  26: (7b) *(u64 *)(r1 +0) = r3         ; R1_w=map_value(off=0,ks=4,vs=48,imm=0) R3_w=scalar()
  27: (95) exit

  from 9 to 11: R1=ctx(off=0,imm=0) R6=0 R7=0 R8=0 R9=0 R10=fp0
  11: (b7) r0 = 0                       ; R0_w=0
  12: (63) *(u32 *)(r10 -4) = r0
  last_idx 12 first_idx 11
  regs=1 stack=0 before 11: (b7) r0 = 0
  13: R0_w=0 R10=fp0 fp-8=0000????
  13: (18) r4 = 0xffff8ad3886c2a00      ; R4_w=map_ptr(off=0,ks=4,vs=48,imm=0)
  15: (bf) r1 = r4                      ; R1_w=map_ptr(off=0,ks=4,vs=48,imm=0) R4_w=map_ptr(off=0,ks=4,vs=48,imm=0)
  16: (bf) r2 = r10                     ; R2_w=fp0 R10=fp0
  17: (07) r2 += -4                     ; R2_w=fp-4
  18: (85) call bpf_map_lookup_elem#1
  frame 0: propagating r6
  last_idx 19 first_idx 11
  regs=40 stack=0 before 18: (85) call bpf_map_lookup_elem#1
  regs=40 stack=0 before 17: (07) r2 += -4
  regs=40 stack=0 before 16: (bf) r2 = r10
  regs=40 stack=0 before 15: (bf) r1 = r4
  regs=40 stack=0 before 13: (18) r4 = 0xffff8ad3886c2a00
  regs=40 stack=0 before 12: (63) *(u32 *)(r10 -4) = r0
  regs=40 stack=0 before 11: (b7) r0 = 0
  parent didn't have regs=40 stack=0 marks: R1=ctx(off=0,imm=0) R6_r=P0 R7=0 R8=0 R9=0 R10=fp0
  last_idx 9 first_idx 9
  regs=40 stack=0 before 9: (bd) if r6 <= r9 goto pc+1
  parent didn't have regs=40 stack=0 marks: R1=ctx(off=0,imm=0) R6_rw=Pscalar() R7_w=0 R8_w=0 R9_rw=0 R10=fp0
  last_idx 8 first_idx 0
  regs=40 stack=0 before 8: (b7) r9 = 0
  regs=40 stack=0 before 7: (97) r6 %= 1
  regs=40 stack=0 before 6: (bd) if r6 <= r9 goto pc+2
  regs=40 stack=0 before 5: (05) goto pc+0
  regs=40 stack=0 before 4: (97) r6 %= 1025
  regs=40 stack=0 before 3: (b7) r9 = -2147483648
  regs=40 stack=0 before 2: (b7) r8 = 0
  regs=40 stack=0 before 1: (b7) r7 = 0
  regs=40 stack=0 before 0: (b7) r6 = 1024
  19: safe
  frame 0: propagating r6
  last_idx 9 first_idx 0
  regs=40 stack=0 before 6: (bd) if r6 <= r9 goto pc+2
  regs=40 stack=0 before 5: (05) goto pc+0
  regs=40 stack=0 before 4: (97) r6 %= 1025
  regs=40 stack=0 before 3: (b7) r9 = -2147483648
  regs=40 stack=0 before 2: (b7) r8 = 0
  regs=40 stack=0 before 1: (b7) r7 = 0
  regs=40 stack=0 before 0: (b7) r6 = 1024

  from 6 to 9: safe
  verification time 110 usec
  stack depth 4
  processed 36 insns (limit 1000000) max_states_per_insn 0 total_states 3 peak_states 3 mark_read 2

The verifier considers this program as safe by mistakenly pruning unsafe
code paths. In the above func#0, code lines 0-10 are of interest. In line
0-3 registers r6 to r9 are initialized with known scalar values. In line 4
the register r6 is reset to an unknown scalar given the verifier does not
track modulo operations. Due to this, the verifier can also not determine
precisely which branches in line 6 and 9 are taken, therefore it needs to
explore them both.

As can be seen, the verifier starts with exploring the false/fall-through
paths first. The 'from 19 to 21' path has both r6=0 and r9=0 and the pointer
arithmetic on r0 += r6 is therefore considered safe. Given the arithmetic,
r6 is correctly marked for precision tracking where backtracking kicks in
where it walks back the current path all the way where r6 was set to 0 in
the fall-through branch.

Next, the pruning logics pops the path 'from 9 to 11' from the stack. Also
here, the state of the registers is the same, that is, r6=0 and r9=0, so
that at line 19 the path can be pruned as it is considered safe. It is
interesting to note that the conditional in line 9 turned r6 into a more
precise state, that is, in the fall-through path at the beginning of line
10, it is R6=scalar(umin=1), and in the branch-taken path (which is analyzed
here) at the beginning of line 11, r6 turned into a known const r6=0 as
r9=0 prior to that and therefore (unsigned) r6 <= 0 concludes that r6 must
be 0 (**):

  [...]                                 ; R6_w=scalar()
  9: (bd) if r6 <= r9 goto pc+1         ; R6=scalar(umin=1) R9=0
  [...]

  from 9 to 11: R1=ctx(off=0,imm=0) R6=0 R7=0 R8=0 R9=0 R10=fp0
  [...]

The next path is 'from 6 to 9'. The verifier considers the old and current
state equivalent, and therefore prunes the search incorrectly. Looking into
the two states which are being compared by the pruning logic at line 9, the
old state consists of R6_rwD=Pscalar() R9_rwD=0 R10=fp0 and the new state
consists of R1=ctx(off=0,imm=0) R6_w=scalar(umax=18446744071562067968)
R7_w=0 R8_w=0 R9_w=-2147483648 R10=fp0. While r6 had the reg->precise flag
correctly set in the old state, r9 did not. Both r6'es are considered as
equivalent given the old one is a superset of the current, more precise one,
however, r9's actual values (0 vs 0x80000000) mismatch. Given the old r9
did not have reg->precise flag set, the verifier does not consider the
register as contributing to the precision state of r6, and therefore it
considered both r9 states as equivalent. However, for this specific pruned
path (which is also the actual path taken at runtime), register r6 will be
0x400 and r9 0x80000000 when reaching line 21, thus oob-accessing the map.

The purpose of precision tracking is to initially mark registers (including
spilled ones) as imprecise to help verifier's pruning logic finding equivalent
states it can then prune if they don't contribute to the program's safety
aspects. For example, if registers are used for pointer arithmetic or to pass
constant length to a helper, then the verifier sets reg->precise flag and
backtracks the BPF program instruction sequence and chain of verifier states
to ensure that the given register or stack slot including their dependencies
are marked as precisely tracked scalar. This also includes any other registers
and slots that contribute to a tracked state of given registers/stack slot.
This backtracking relies on recorded jmp_history and is able to traverse
entire chain of parent states. This process ends only when all the necessary
registers/slots and their transitive dependencies are marked as precise.

The backtrack_insn() is called from the current instruction up to the first
instruction, and its purpose is to compute a bitmask of registers and stack
slots that need precision tracking in the parent's verifier state. For example,
if a current instruction is r6 = r7, then r6 needs precision after this
instruction and r7 needs precision before this instruction, that is, in the
parent state. Hence for the latter r7 is marked and r6 unmarked.

For the class of jmp/jmp32 instructions, backtrack_insn() today only looks
at call and exit instructions and for all other conditionals the masks
remain as-is. However, in the given situation register r6 has a dependency
on r9 (as described above in **), so also that one needs to be marked for
precision tracking. In other words, if an imprecise register influences a
precise one, then the imprecise register should also be marked precise.
Meaning, in the parent state both dest and src register need to be tracked
for precision and therefore the marking must be more conservative by setting
reg->precise flag for both. The precision propagation needs to cover both
for the conditional: if the src reg was marked but not the dst reg and vice
versa.

After the fix the program is correctly rejected:

  func#0 @0
  0: R1=ctx(off=0,imm=0) R10=fp0
  0: (b7) r6 = 1024                     ; R6_w=1024
  1: (b7) r7 = 0                        ; R7_w=0
  2: (b7) r8 = 0                        ; R8_w=0
  3: (b7) r9 = -2147483648              ; R9_w=-2147483648
  4: (97) r6 %= 1025                    ; R6_w=scalar()
  5: (05) goto pc+0
  6: (bd) if r6 <= r9 goto pc+2         ; R6_w=scalar(umin=18446744071562067969,var_off=(0xffffffff80000000; 0x7fffffff),u32_min=-2147483648) R9_w=-2147483648
  7: (97) r6 %= 1                       ; R6_w=scalar()
  8: (b7) r9 = 0                        ; R9=0
  9: (bd) if r6 <= r9 goto pc+1         ; R6=scalar(umin=1) R9=0
  10: (b7) r6 = 0                       ; R6_w=0
  11: (b7) r0 = 0                       ; R0_w=0
  12: (63) *(u32 *)(r10 -4) = r0
  last_idx 12 first_idx 9
  regs=1 stack=0 before 11: (b7) r0 = 0
  13: R0_w=0 R10=fp0 fp-8=0000????
  13: (18) r4 = 0xffff9290dc5bfe00      ; R4_w=map_ptr(off=0,ks=4,vs=48,imm=0)
  15: (bf) r1 = r4                      ; R1_w=map_ptr(off=0,ks=4,vs=48,imm=0) R4_w=map_ptr(off=0,ks=4,vs=48,imm=0)
  16: (bf) r2 = r10                     ; R2_w=fp0 R10=fp0
  17: (07) r2 += -4                     ; R2_w=fp-4
  18: (85) call bpf_map_lookup_elem#1   ; R0=map_value_or_null(id=1,off=0,ks=4,vs=48,imm=0)
  19: (55) if r0 != 0x0 goto pc+1       ; R0=0
  20: (95) exit

  from 19 to 21: R0=map_value(off=0,ks=4,vs=48,imm=0) R6=0 R7=0 R8=0 R9=0 R10=fp0 fp-8=mmmm????
  21: (77) r6 >>= 10                    ; R6_w=0
  22: (27) r6 *= 8192                   ; R6_w=0
  23: (bf) r1 = r0                      ; R0=map_value(off=0,ks=4,vs=48,imm=0) R1_w=map_value(off=0,ks=4,vs=48,imm=0)
  24: (0f) r0 += r6
  last_idx 24 first_idx 19
  regs=40 stack=0 before 23: (bf) r1 = r0
  regs=40 stack=0 before 22: (27) r6 *= 8192
  regs=40 stack=0 before 21: (77) r6 >>= 10
  regs=40 stack=0 before 19: (55) if r0 != 0x0 goto pc+1
  parent didn't have regs=40 stack=0 marks: R0_rw=map_value_or_null(id=1,off=0,ks=4,vs=48,imm=0) R6_rw=P0 R7=0 R8=0 R9=0 R10=fp0 fp-8=mmmm????
  last_idx 18 first_idx 9
  regs=40 stack=0 before 18: (85) call bpf_map_lookup_elem#1
  regs=40 stack=0 before 17: (07) r2 += -4
  regs=40 stack=0 before 16: (bf) r2 = r10
  regs=40 stack=0 before 15: (bf) r1 = r4
  regs=40 stack=0 before 13: (18) r4 = 0xffff9290dc5bfe00
  regs=40 stack=0 before 12: (63) *(u32 *)(r10 -4) = r0
  regs=40 stack=0 before 11: (b7) r0 = 0
  regs=40 stack=0 before 10: (b7) r6 = 0
  25: (79) r3 = *(u64 *)(r0 +0)         ; R0_w=map_value(off=0,ks=4,vs=48,imm=0) R3_w=scalar()
  26: (7b) *(u64 *)(r1 +0) = r3         ; R1_w=map_value(off=0,ks=4,vs=48,imm=0) R3_w=scalar()
  27: (95) exit

  from 9 to 11: R1=ctx(off=0,imm=0) R6=0 R7=0 R8=0 R9=0 R10=fp0
  11: (b7) r0 = 0                       ; R0_w=0
  12: (63) *(u32 *)(r10 -4) = r0
  last_idx 12 first_idx 11
  regs=1 stack=0 before 11: (b7) r0 = 0
  13: R0_w=0 R10=fp0 fp-8=0000????
  13: (18) r4 = 0xffff9290dc5bfe00      ; R4_w=map_ptr(off=0,ks=4,vs=48,imm=0)
  15: (bf) r1 = r4                      ; R1_w=map_ptr(off=0,ks=4,vs=48,imm=0) R4_w=map_ptr(off=0,ks=4,vs=48,imm=0)
  16: (bf) r2 = r10                     ; R2_w=fp0 R10=fp0
  17: (07) r2 += -4                     ; R2_w=fp-4
  18: (85) call bpf_map_lookup_elem#1
  frame 0: propagating r6
  last_idx 19 first_idx 11
  regs=40 stack=0 before 18: (85) call bpf_map_lookup_elem#1
  regs=40 stack=0 before 17: (07) r2 += -4
  regs=40 stack=0 before 16: (bf) r2 = r10
  regs=40 stack=0 before 15: (bf) r1 = r4
  regs=40 stack=0 before 13: (18) r4 = 0xffff9290dc5bfe00
  regs=40 stack=0 before 12: (63) *(u32 *)(r10 -4) = r0
  regs=40 stack=0 before 11: (b7) r0 = 0
  parent didn't have regs=40 stack=0 marks: R1=ctx(off=0,imm=0) R6_r=P0 R7=0 R8=0 R9=0 R10=fp0
  last_idx 9 first_idx 9
  regs=40 stack=0 before 9: (bd) if r6 <= r9 goto pc+1
  parent didn't have regs=240 stack=0 marks: R1=ctx(off=0,imm=0) R6_rw=Pscalar() R7_w=0 R8_w=0 R9_rw=P0 R10=fp0
  last_idx 8 first_idx 0
  regs=240 stack=0 before 8: (b7) r9 = 0
  regs=40 stack=0 before 7: (97) r6 %= 1
  regs=40 stack=0 before 6: (bd) if r6 <= r9 goto pc+2
  regs=240 stack=0 before 5: (05) goto pc+0
  regs=240 stack=0 before 4: (97) r6 %= 1025
  regs=240 stack=0 before 3: (b7) r9 = -2147483648
  regs=40 stack=0 before 2: (b7) r8 = 0
  regs=40 stack=0 before 1: (b7) r7 = 0
  regs=40 stack=0 before 0: (b7) r6 = 1024
  19: safe

  from 6 to 9: R1=ctx(off=0,imm=0) R6_w=scalar(umax=18446744071562067968) R7_w=0 R8_w=0 R9_w=-2147483648 R10=fp0
  9: (bd) if r6 <= r9 goto pc+1
  last_idx 9 first_idx 0
  regs=40 stack=0 before 6: (bd) if r6 <= r9 goto pc+2
  regs=240 stack=0 before 5: (05) goto pc+0
  regs=240 stack=0 before 4: (97) r6 %= 1025
  regs=240 stack=0 before 3: (b7) r9 = -2147483648
  regs=40 stack=0 before 2: (b7) r8 = 0
  regs=40 stack=0 before 1: (b7) r7 = 0
  regs=40 stack=0 before 0: (b7) r6 = 1024
  last_idx 9 first_idx 0
  regs=200 stack=0 before 6: (bd) if r6 <= r9 goto pc+2
  regs=240 stack=0 before 5: (05) goto pc+0
  regs=240 stack=0 before 4: (97) r6 %= 1025
  regs=240 stack=0 before 3: (b7) r9 = -2147483648
  regs=40 stack=0 before 2: (b7) r8 = 0
  regs=40 stack=0 before 1: (b7) r7 = 0
  regs=40 stack=0 before 0: (b7) r6 = 1024
  11: R6=scalar(umax=18446744071562067968) R9=-2147483648
  11: (b7) r0 = 0                       ; R0_w=0
  12: (63) *(u32 *)(r10 -4) = r0
  last_idx 12 first_idx 11
  regs=1 stack=0 before 11: (b7) r0 = 0
  13: R0_w=0 R10=fp0 fp-8=0000????
  13: (18) r4 = 0xffff9290dc5bfe00      ; R4_w=map_ptr(off=0,ks=4,vs=48,imm=0)
  15: (bf) r1 = r4                      ; R1_w=map_ptr(off=0,ks=4,vs=48,imm=0) R4_w=map_ptr(off=0,ks=4,vs=48,imm=0)
  16: (bf) r2 = r10                     ; R2_w=fp0 R10=fp0
  17: (07) r2 += -4                     ; R2_w=fp-4
  18: (85) call bpf_map_lookup_elem#1   ; R0_w=map_value_or_null(id=3,off=0,ks=4,vs=48,imm=0)
  19: (55) if r0 != 0x0 goto pc+1       ; R0_w=0
  20: (95) exit

  from 19 to 21: R0=map_value(off=0,ks=4,vs=48,imm=0) R6=scalar(umax=18446744071562067968) R7=0 R8=0 R9=-2147483648 R10=fp0 fp-8=mmmm????
  21: (77) r6 >>= 10                    ; R6_w=scalar(umax=18014398507384832,var_off=(0x0; 0x3fffffffffffff))
  22: (27) r6 *= 8192                   ; R6_w=scalar(smax=9223372036854767616,umax=18446744073709543424,var_off=(0x0; 0xffffffffffffe000),s32_max=2147475456,u32_max=-8192)
  23: (bf) r1 = r0                      ; R0=map_value(off=0,ks=4,vs=48,imm=0) R1_w=map_value(off=0,ks=4,vs=48,imm=0)
  24: (0f) r0 += r6
  last_idx 24 first_idx 21
  regs=40 stack=0 before 23: (bf) r1 = r0
  regs=40 stack=0 before 22: (27) r6 *= 8192
  regs=40 stack=0 before 21: (77) r6 >>= 10
  parent didn't have regs=40 stack=0 marks: R0_rw=map_value(off=0,ks=4,vs=48,imm=0) R6_r=Pscalar(umax=18446744071562067968) R7=0 R8=0 R9=-2147483648 R10=fp0 fp-8=mmmm????
  last_idx 19 first_idx 11
  regs=40 stack=0 before 19: (55) if r0 != 0x0 goto pc+1
  regs=40 stack=0 before 18: (85) call bpf_map_lookup_elem#1
  regs=40 stack=0 before 17: (07) r2 += -4
  regs=40 stack=0 before 16: (bf) r2 = r10
  regs=40 stack=0 before 15: (bf) r1 = r4
  regs=40 stack=0 before 13: (18) r4 = 0xffff9290dc5bfe00
  regs=40 stack=0 before 12: (63) *(u32 *)(r10 -4) = r0
  regs=40 stack=0 before 11: (b7) r0 = 0
  parent didn't have regs=40 stack=0 marks: R1=ctx(off=0,imm=0) R6_rw=Pscalar(umax=18446744071562067968) R7_w=0 R8_w=0 R9_w=-2147483648 R10=fp0
  last_idx 9 first_idx 0
  regs=40 stack=0 before 9: (bd) if r6 <= r9 goto pc+1
  regs=240 stack=0 before 6: (bd) if r6 <= r9 goto pc+2
  regs=240 stack=0 before 5: (05) goto pc+0
  regs=240 stack=0 before 4: (97) r6 %= 1025
  regs=240 stack=0 before 3: (b7) r9 = -2147483648
  regs=40 stack=0 before 2: (b7) r8 = 0
  regs=40 stack=0 before 1: (b7) r7 = 0
  regs=40 stack=0 before 0: (b7) r6 = 1024
  math between map_value pointer and register with unbounded min value is not allowed
  verification time 886 usec
  stack depth 4
  processed 49 insns (limit 1000000) max_states_per_insn 1 total_states 5 peak_states 5 mark_read 2

Fixes: b5dc0163d8 ("bpf: precise scalar_value tracking")
Reported-by: Juan Jose Lopez Jaimez <jjlopezjaimez@google.com>
Reported-by: Meador Inge <meadori@google.com>
Reported-by: Simon Scannell <simonscannell@google.com>
Reported-by: Nenad Stojanovski <thenenadx@google.com>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Co-developed-by: Andrii Nakryiko <andrii@kernel.org>
Signed-off-by: Andrii Nakryiko <andrii@kernel.org>
Reviewed-by: John Fastabend <john.fastabend@gmail.com>
Reviewed-by: Juan Jose Lopez Jaimez <jjlopezjaimez@google.com>
Reviewed-by: Meador Inge <meadori@google.com>
Reviewed-by: Simon Scannell <simonscannell@google.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2023-04-26 11:24:02 +02:00
Nikita Zhandarovich
ba610df83b mlxfw: fix null-ptr-deref in mlxfw_mfa2_tlv_next()
[ Upstream commit c0e73276f0fcbbd3d4736ba975d7dc7a48791b0c ]

Function mlxfw_mfa2_tlv_multi_get() returns NULL if 'tlv' in
question does not pass checks in mlxfw_mfa2_tlv_payload_get(). This
behaviour may lead to NULL pointer dereference in 'multi->total_len'.
Fix this issue by testing mlxfw_mfa2_tlv_multi_get()'s return value
against NULL.

Found by Linux Verification Center (linuxtesting.org) with static
analysis tool SVACE.

Fixes: 410ed13cae ("Add the mlxfw module for Mellanox firmware flash process")
Co-developed-by: Natalia Petrova <n.petrova@fintech.ru>
Signed-off-by: Nikita Zhandarovich <n.zhandarovich@fintech.ru>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://lore.kernel.org/r/20230417120718.52325-1-n.zhandarovich@fintech.ru
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2023-04-26 11:24:02 +02:00
Aleksandr Loktionov
d8e120057c i40e: fix i40e_setup_misc_vector() error handling
[ Upstream commit c86c00c6935505929cc9adb29ddb85e48c71f828 ]

Add error handling of i40e_setup_misc_vector() in i40e_rebuild().
In case interrupt vectors setup fails do not re-open vsi-s and
do not bring up vf-s, we have no interrupts to serve a traffic
anyway.

Fixes: 41c445ff0f ("i40e: main driver core")
Signed-off-by: Aleksandr Loktionov <aleksandr.loktionov@intel.com>
Tested-by: Pucha Himasekhar Reddy <himasekharx.reddy.pucha@intel.com> (A Contingent worker at Intel)
Signed-off-by: Tony Nguyen <anthony.l.nguyen@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2023-04-26 11:24:02 +02:00