Commit graph

897,966 commits

Author SHA1 Message Date
Takashi Iwai
e55bdca2cb UPSTREAM: media: dvb-core: Fix UAF due to refcount races at releasing
commit fd3d91ab1c6ab0628fe642dd570b56302c30a792 upstream.

The dvb-core tries to sync the releases of opened files at
dvb_dmxdev_release() with two refcounts: dvbdev->users and
dvr_dvbdev->users.  A problem is present in those two syncs: when yet
another dvb_demux_open() is called during those sync waits,
dvb_demux_open() continues to process even if the device is being
closed.  This includes the increment of the former refcount, resulting
in the leftover refcount after the sync of the latter refcount at
dvb_dmxdev_release().  It ends up with use-after-free, since the
function believes that all usages were gone and releases the
resources.

This patch addresses the problem by adding the check of dmxdev->exit
flag at dvb_demux_open(), just like dvb_dvr_open() already does.  With
the exit flag check, the second call of dvb_demux_open() fails, hence
the further corruption can be avoided.

Also for avoiding the races of the dmxdev->exit flag reference, this
patch serializes the dmxdev->exit set up and the sync waits with the
dmxdev->mutex lock at dvb_dmxdev_release().  Without the mutex lock,
dvb_demux_open() (or dvb_dvr_open()) may run concurrently with
dvb_dmxdev_release(), which allows to skip the exit flag check and
continue the open process that is being closed.

CVE-2022-41218 is assigned to those bugs above.

Bug: 248356119
Reported-by: Hyunwoo Kim <imv4bel@gmail.com>
Cc: <stable@vger.kernel.org>
Link: https://lore.kernel.org/20220908132754.30532-1-tiwai@suse.de
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Hans Verkuil <hverkuil-cisco@xs4all.nl>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I5a0dd4444ca25d07a050dcb07609c7c7ccf658af
2023-01-31 09:43:30 +00:00
Srinivasarao Pathipati
d72fdcc709 ANDROID: abi_gki_aarch64_qcom: Add hrtimer_sleeper_start_expires
The commit bd80dd86f9 (wait: Fix __wait_event_hrtimeout
for RT/DL tasks) uses function hrtimer_sleeper_start_expires().
This symbol is needed for vendor modules that uses macro
__wait_event_hrtimeout so adding it to the symbol list.

Leaf changes summary: 1 artifact changed
Changed leaf types summary: 0 leaf type changed
Removed/Changed/Added functions summary: 0 Removed, 0 Changed, 1 Added function
Removed/Changed/Added variables summary: 0 Removed, 0 Changed, 0 Added variable

1 Added function:

  [A] 'function void hrtimer_sleeper_start_expires(hrtimer_sleeper*, hrtimer_mode)'

Bug: 266792382
Change-Id: Ice46d311ccf16def0e5edbea8fc464ad63c8d94f
Signed-off-by: Srinivasarao Pathipati <quic_spathi@quicinc.com>
2023-01-26 19:14:11 +00:00
Clement Lecigne
b63a7aff8a UPSTREAM: ALSA: pcm: Move rwsem lock inside snd_ctl_elem_read to prevent UAF
[ Note: this is a fix that works around the bug equivalently as the
  two upstream commits:
   1fa4445f9adf ("ALSA: control - introduce snd_ctl_notify_one() helper")
   56b88b50565c ("ALSA: pcm: Move rwsem lock inside snd_ctl_elem_read to prevent UAF")
  but in a simpler way to fit with older stable trees -- tiwai ]

Add missing locking in ctl_elem_read_user/ctl_elem_write_user which can be
easily triggered and turned into an use-after-free.

Example code paths with SNDRV_CTL_IOCTL_ELEM_READ:

64-bits:
snd_ctl_ioctl
  snd_ctl_elem_read_user
    [takes controls_rwsem]
    snd_ctl_elem_read [lock properly held, all good]
    [drops controls_rwsem]

32-bits (compat):
snd_ctl_ioctl_compat
  snd_ctl_elem_write_read_compat
    ctl_elem_write_read
      snd_ctl_elem_read [missing lock, not good]

CVE-2023-0266 was assigned for this issue.

Bug: 265303544
Signed-off-by: Clement Lecigne <clecigne@google.com>
Cc: stable@kernel.org # 5.12 and older
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Reviewed-by: Jaroslav Kysela <perex@perex.cz>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit df02234e6b87d2a9a82acd3198e44bdeff8488c7)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: Ibe891cdcb9eaf0dfc7bd771689c85c32b5c0d1f7
2023-01-26 11:54:02 +00:00
Lee Jones
d0f21836e3 ANDROID: Revert "tracing/ring-buffer: Have polling block on watermark"
This reverts commit e65ac2bdda.

Bug: 263508491
Change-Id: I0acf7869b0d4a3977787c9280a4d8f39041b354b
Signed-off-by: Lee Jones <joneslee@google.com>
2023-01-25 16:32:06 +00:00
Treehugger Robot
5a8d108cc6 Merge "Merge tag 'android11-5.4.226_r00' into android11-5.4" into android11-5.4 2023-01-25 16:32:06 +00:00
John Keeping
c429b23536 UPSTREAM: usb: gadget: f_hid: fix f_hidg lifetime vs cdev
[ Upstream commit 89ff3dfac604614287ad5aad9370c3f984ea3f4b ]

The embedded struct cdev does not have its lifetime correctly tied to
the enclosing struct f_hidg, so there is a use-after-free if /dev/hidgN
is held open while the gadget is deleted.

This can readily be replicated with libusbgx's example programs (for
conciseness - operating directly via configfs is equivalent):

	gadget-hid
	exec 3<> /dev/hidg0
	gadget-vid-pid-remove
	exec 3<&-

Pull the existing device up in to struct f_hidg and make use of the
cdev_device_{add,del}() helpers.  This changes the lifetime of the
device object to match struct f_hidg, but note that it is still added
and deleted at the same time.

Bug: 176850153
Fixes: 71adf11894 ("USB: gadget: add HID gadget driver")
Tested-by: Lee Jones <lee@kernel.org>
Reviewed-by: Andrzej Pietrasiewicz <andrzej.p@collabora.com>
Reviewed-by: Lee Jones <lee@kernel.org>
Signed-off-by: John Keeping <john@metanate.com>
Link: https://lore.kernel.org/r/20221122123523.3068034-2-john@metanate.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I5d37ca47c5f087d5b1b303b4e8a1614ea3f50159
Signed-off-by: Lee Jones <joneslee@google.com>
2023-01-24 10:11:02 +00:00
Maxim Devaev
28b985f146 UPSTREAM: usb: gadget: f_hid: optional SETUP/SET_REPORT mode
[ Upstream commit d7428bc26fc767942c38d74b80299bcd4f01e7cb ]

f_hid provides the OUT Endpoint as only way for receiving reports
from the host. SETUP/SET_REPORT method is not supported, and this causes
a number of compatibility problems with various host drivers, especially
in the case of keyboard emulation using f_hid.

  - Some hosts do not support the OUT Endpoint and ignore it,
    so it becomes impossible for the gadget to receive a report
    from the host. In the case of a keyboard, the gadget loses
    the ability to receive the status of the LEDs.

  - Some BIOSes/UEFIs can't work with HID devices with the OUT Endpoint
    at all. This may be due to their bugs or incomplete implementation
    of the HID standard.
    For example, absolutely all Apple UEFIs can't handle the OUT Endpoint
    if it goes after IN Endpoint in the descriptor and require the reverse
    order (OUT, IN) which is a violation of the standard.
    Other hosts either do not initialize gadgets with a descriptor
    containing the OUT Endpoint completely (like some HP and DELL BIOSes
    and embedded firmwares like on KVM switches), or initialize them,
    but will not poll the IN Endpoint.

This patch adds configfs option no_out_endpoint=1 to disable
the OUT Endpoint and allows f_hid to receive reports from the host
via SETUP/SET_REPORT.

Previously, there was such a feature in f_hid, but it was replaced
by the OUT Endpoint [1] in the commit 99c5150058 ("usb: gadget: hidg:
register OUT INT endpoint for SET_REPORT"). So this patch actually
returns the removed functionality while making it optional.
For backward compatibility reasons, the OUT Endpoint mode remains
the default behaviour.

  - The OUT Endpoint mode provides the report queue and reduces
    USB overhead (eliminating SETUP routine) on transmitting a report
    from the host.

  - If the SETUP/SET_REPORT mode is used, there is no report queue,
    so the userspace will only read last report. For classic HID devices
    like keyboards this is not a problem, since it's intended to transmit
    the status of the LEDs and only the last report is important.
    This mode provides better compatibility with strange and buggy
    host drivers.

Both modes passed USBCV tests. Checking with the USB protocol analyzer
also confirmed that everything is working as it should and the new mode
ensures operability in all of the described cases.

Bug: 176850153
Link: https://www.spinics.net/lists/linux-usb/msg65494.html [1]
Reviewed-by: Maciej Żenczykowski <zenczykowski@gmail.com>
Acked-by: Felipe Balbi <balbi@kernel.org>
Signed-off-by: Maxim Devaev <mdevaev@gmail.com>
Link: https://lore.kernel.org/r/20210821134004.363217-1-mdevaev@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Stable-dep-of: 89ff3dfac604 ("usb: gadget: f_hid: fix f_hidg lifetime vs cdev")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I0f5759015f17661fe4fe23a1216f1047978c79b1
Signed-off-by: Lee Jones <joneslee@google.com>
2023-01-24 10:10:58 +00:00
Steve Muckle
15a5e4ad4f ANDROID: add TEST_MAPPING for net/, include/net
Run CtsNetTestCases in presubmit for changes in net/ and
include/net/.

Bug: 186664401
Change-Id: I3cf942bd0418ad55a6559d6933927b0da86da595
Signed-off-by: Steve Muckle <smuckle@google.com>
(cherry picked from commit 55415d7022a8835d8979e09a74da3df29c9091ec)
2023-01-23 17:54:01 +00:00
Jialiang Wang
f5b4a7be57 UPSTREAM: nfp: fix use-after-free in area_cache_get()
commit 02e1a114fdb71e59ee6770294166c30d437bf86a upstream.

area_cache_get() is used to distribute cache->area and set cache->id,
 and if cache->id is not 0 and cache->area->kref refcount is 0, it will
 release the cache->area by nfp_cpp_area_release(). area_cache_get()
 set cache->id before cpp->op->area_init() and nfp_cpp_area_acquire().

But if area_init() or nfp_cpp_area_acquire() fails, the cache->id is
 is already set but the refcount is not increased as expected. At this
 time, calling the nfp_cpp_area_release() will cause use-after-free.

To avoid the use-after-free, set cache->id after area_init() and
 nfp_cpp_area_acquire() complete successfully.

Note: This vulnerability is triggerable by providing emulated device
 equipped with specified configuration.

 BUG: KASAN: use-after-free in nfp6000_area_init (drivers/net/ethernet/netronome/nfp/nfpcore/nfp6000_pcie.c:760)
  Write of size 4 at addr ffff888005b7f4a0 by task swapper/0/1

 Call Trace:
  <TASK>
 nfp6000_area_init (drivers/net/ethernet/netronome/nfp/nfpcore/nfp6000_pcie.c:760)
 area_cache_get.constprop.8 (drivers/net/ethernet/netronome/nfp/nfpcore/nfp_cppcore.c:884)

 Allocated by task 1:
 nfp_cpp_area_alloc_with_name (drivers/net/ethernet/netronome/nfp/nfpcore/nfp_cppcore.c:303)
 nfp_cpp_area_cache_add (drivers/net/ethernet/netronome/nfp/nfpcore/nfp_cppcore.c:802)
 nfp6000_init (drivers/net/ethernet/netronome/nfp/nfpcore/nfp6000_pcie.c:1230)
 nfp_cpp_from_operations (drivers/net/ethernet/netronome/nfp/nfpcore/nfp_cppcore.c:1215)
 nfp_pci_probe (drivers/net/ethernet/netronome/nfp/nfp_main.c:744)

 Freed by task 1:
 kfree (mm/slub.c:4562)
 area_cache_get.constprop.8 (drivers/net/ethernet/netronome/nfp/nfpcore/nfp_cppcore.c:873)
 nfp_cpp_read (drivers/net/ethernet/netronome/nfp/nfpcore/nfp_cppcore.c:924 drivers/net/ethernet/netronome/nfp/nfpcore/nfp_cppcore.c:973)
 nfp_cpp_readl (drivers/net/ethernet/netronome/nfp/nfpcore/nfp_cpplib.c:48)

Bug: 254471126
Signed-off-by: Jialiang Wang <wangjialiang0806@163.com>
Reviewed-by: Yinjun Zhang <yinjun.zhang@corigine.com>
Acked-by: Simon Horman <simon.horman@corigine.com>
Link: https://lore.kernel.org/r/20220810073057.4032-1-wangjialiang0806@163.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: Iad626deee45edc6bdf7a095d3de1defc5c6ad996
Signed-off-by: Lee Jones <joneslee@google.com>
2023-01-23 17:42:44 +00:00
Linus Torvalds
5a9d35543f UPSTREAM: proc: avoid integer type confusion in get_proc_long
commit e6cfaf34be9fcd1a8285a294e18986bfc41a409c upstream.

proc_get_long() is passed a size_t, but then assigns it to an 'int'
variable for the length.  Let's not do that, even if our IO paths are
limited to MAX_RW_COUNT (exactly because of these kinds of type errors).

So do the proper test in the rigth type.

Bug: 261488859
Reported-by: Kyle Zeng <zengyhkyle@gmail.com>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I75a06fe777c638b82ef3fbd1346e985065ab17f2
Signed-off-by: Lee Jones <joneslee@google.com>
2023-01-23 15:18:03 +00:00
Linus Torvalds
cffda199e1 UPSTREAM: proc: proc_skip_spaces() shouldn't think it is working on C strings
commit bce9332220bd677d83b19d21502776ad555a0e73 upstream.

proc_skip_spaces() seems to think it is working on C strings, and ends
up being just a wrapper around skip_spaces() with a really odd calling
convention.

Instead of basing it on skip_spaces(), it should have looked more like
proc_skip_char(), which really is the exact same function (except it
skips a particular character, rather than whitespace).  So use that as
inspiration, odd coding and all.

Now the calling convention actually makes sense and works for the
intended purpose.

Bug: 261488859
Reported-and-tested-by: Kyle Zeng <zengyhkyle@gmail.com>
Acked-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: Ie21bf20f3b92b78c5f31093b354a77b4133810e7
Signed-off-by: Lee Jones <joneslee@google.com>
2023-01-23 15:17:59 +00:00
Lee Jones
e418b27c0c ANDROID: usb: f_accessory: Check buffer size when initialised via composite
When communicating with accessory devices via USBFS, the initialisation
call-stack looks like:

  ConfigFS > Gadget ConfigFS > UDC > Gadget ConfigFS > Composite

Eventually ending up in composite_dev_prepare() where memory for the
data buffer is allocated and initialised.  The default size used for the
allocation is USB_COMP_EP0_BUFSIZ (4k).  When handling bulk transfers,
acc_ctrlrequest() needs to be able to handle buffers up to
BULK_BUFFER_SIZE (16k).  Instead of adding new generic attributes to
'struct usb_request' to track the size of the allocated buffer, we can
simply split off the affected thread of execution to travel via a
knowledgeable abstracted function acc_ctrlrequest_composite() where we
can complete the necessary specific checks.

Bug: 264029575
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: Ia1280f85499621d3fa57f7262b4a2c80f4be7773
Signed-off-by: Lee Jones <joneslee@google.com>
2023-01-23 10:39:10 +00:00
Greg Kroah-Hartman
98d8600199 Merge tag 'android11-5.4.226_r00' into android11-5.4
This is the merge of the upstream LTS release of 5.4.226 into the
android11-5.4 branch.

It contains the following commits:

94bdbb0042 Revert "mmc: sdhci: Fix voltage switch delay"
b0e3bda187 ANDROID: gki_defconfig: add CONFIG_FUNCTION_ERROR_INJECTION
39c4c9c65c Merge 5.4.226 into android11-5.4-lts
316cdfc48d Linux 5.4.226
3ab84e8913 ipc/sem: Fix dangling sem_array access in semtimedop race
210f96fb7e v4l2: don't fall back to follow_pfn() if pin_user_pages_fast() fails
0390da0565 proc: proc_skip_spaces() shouldn't think it is working on C strings
dd3124a051 proc: avoid integer type confusion in get_proc_long
1061bf5d01 mmc: sdhci: Fix voltage switch delay
9a5f49c0f5 mmc: sdhci: use FIELD_GET for preset value bit masks
d699373ac5 char: tpm: Protect tpm_pm_suspend with locks
9decec2993 Revert "clocksource/drivers/riscv: Events are stopped during CPU suspend"
e67e119adf x86/ioremap: Fix page aligned size calculation in __ioremap_caller()
0d87bb6070 Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM
b5041a3daa x86/pm: Add enumeration check before spec MSRs save/restore setup
3b28594576 x86/tsx: Add a feature bit for TSX control MSR support
99c59256ea nvme: ensure subsystem reset is single threaded
dc85ff0a5f nvme: restrict management ioctls to admin
c41a89af7b epoll: check for events when removing a timed out thread from the wait queue
b8e803cda5 epoll: call final ep_events_available() check under the lock
e65ac2bdda tracing/ring-buffer: Have polling block on watermark
899e148171 ipv4: Fix route deletion when nexthop info is not specified
cc3cd130ec ipv4: Handle attempt to delete multipath route when fib_info contains an nh reference
a14f1a9c53 selftests: net: fix nexthop warning cleanup double ip typo
8aefb93295 selftests: net: add delete nexthop route warning test
dd6d2d82f0 Kconfig.debug: provide a little extra FRAME_WARN leeway when KASAN is enabled
7da3a10f39 parisc: Increase FRAME_WARN to 2048 bytes on parisc
15568cdbe5 xtensa: increase size of gcc stack frame check
76f48511a1 parisc: Increase size of gcc stack frame check
cbdd83bd2f iommu/vt-d: Fix PCI device refcount leak in dmar_dev_scope_init()
0090231df2 pinctrl: single: Fix potential division by zero
73dce3c1d4 ASoC: ops: Fix bounds check for _sx controls
ced17a55a8 mm: Fix '.data.once' orphan section warning
c9ecc42094 arm64: errata: Fix KVM Spectre-v2 mitigation selection for Cortex-A57/A72
44ccd8c52f arm64: Fix panic() when Spectre-v2 causes Spectre-BHB to re-allocate KVM vectors
1603feac15 tracing: Free buffers when a used dynamic event is removed
dcd1daad31 mmc: sdhci-sprd: Fix no reset data and command after voltage switch
9e5581c772 mmc: sdhci-esdhc-imx: correct CQHCI exit halt state check
bfdfe86d83 mmc: core: Fix ambiguous TRIM and DISCARD arg
040d08c996 mmc: mmc_test: Fix removal of debugfs file
eb5001ecfb pinctrl: intel: Save and restore pins in "direct IRQ" mode
ae34a4f4a2 x86/bugs: Make sure MSR_SPEC_CTRL is updated properly upon resume from S3
9a130b72e6 nilfs2: fix NULL pointer dereference in nilfs_palloc_commit_free_entry()
3ae3bb33c4 tools/vm/slabinfo-gnuplot: use "grep -E" instead of "egrep"
cf1c12bc5c error-injection: Add prompt for function error injection
2f6fd2de72 net/mlx5: DR, Fix uninitialized var warning
ea5844f946 hwmon: (coretemp) fix pci device refcount leak in nv1a_ram_new()
89eecabe6a hwmon: (coretemp) Check for null before removing sysfs attrs
0aacac75b8 net: ethernet: renesas: ravb: Fix promiscuous mode after system resumed
a7555681e5 sctp: fix memory leak in sctp_stream_outq_migrate()
168de4096b packet: do not set TP_STATUS_CSUM_VALID on CHECKSUM_COMPLETE
16c244bc65 net: tun: Fix use-after-free in tun_detach()
1c1d4830a9 afs: Fix fileserver probe RTT handling
53a62c5efe net: hsr: Fix potential use-after-free
ae633816dd dsa: lan9303: Correct stat name
910c0264b6 net: ethernet: nixge: fix NULL dereference
2d24d91b9f net/9p: Fix a potential socket leak in p9_socket_open
4720725e22 net: net_netdev: Fix error handling in ntb_netdev_init_module()
3e21f85d87 net: phy: fix null-ptr-deref while probe() failed
f5c2ec288a wifi: cfg80211: fix buffer overflow in elem comparison
06785845e1 qlcnic: fix sleep-in-atomic-context bugs caused by msleep
78f8a34b37 can: cc770: cc770_isa_probe(): add missing free_cc770dev()
e4b474fa78 can: sja1000_isa: sja1000_isa_probe(): add missing free_sja1000dev()
0a2d73a770 net/mlx5e: Fix use-after-free when reverting termination table
093ccc2f84 net/mlx5: Fix uninitialized variable bug in outlen_write()
b10dd3bd14 of: property: decrement node refcount in of_fwnode_get_reference_args()
7b2b67fe13 hwmon: (ibmpex) Fix possible UAF when ibmpex_register_bmc() fails
45a6437834 hwmon: (i5500_temp) fix missing pci_disable_device()
dbcc339001 scripts/faddr2line: Fix regression in name resolution on ppc64le
2b916ee1d3 iio: light: rpr0521: add missing Kconfig dependencies
3f566b6260 iio: health: afe4404: Fix oob read in afe4404_[read|write]_raw
2d6a437064 iio: health: afe4403: Fix oob read in afe4403_read_raw
8eb912af52 btrfs: qgroup: fix sleep from invalid context bug in btrfs_qgroup_inherit()
7e88a416ed drm/amdgpu: Partially revert "drm/amdgpu: update drm_display_info correctly when the edid is read"
41f0abeadc drm/amdgpu: update drm_display_info correctly when the edid is read
787138e4b9 btrfs: move QUOTA_ENABLED check to rescan_should_stop from btrfs_qgroup_rescan_worker
255289adce spi: spi-imx: Fix spi_bus_clk if requested clock is higher than input clock
83aae3204e btrfs: free btrfs_path before copying inodes to userspace
9fd11e2de7 fuse: lock inode unconditionally in fuse_fallocate()
3659e33c1e drm/i915: fix TLB invalidation for Gen12 video and compute engines
0d1cad5971 drm/amdgpu: always register an MMU notifier for userptr
d4e9bab771 drm/amd/dc/dce120: Fix audio register mapping, stop triggering KASAN
a541f1f0ce btrfs: sysfs: normalize the error handling branch in btrfs_init_sysfs()
d037681515 btrfs: free btrfs_path before copying subvol info to userspace
69e2f1dd93 btrfs: free btrfs_path before copying fspath to userspace
3cde2bc708 btrfs: free btrfs_path before copying root refs to userspace
4741b00cac binder: Gracefully handle BINDER_TYPE_FDA objects with num_fds=0
4e682ce560 binder: Address corner cases in deferred copy and fixup
15e098ab1d binder: fix pointer cast warning
74e7f1828a binder: defer copies of pre-patched txn data
7b31ab0d9e binder: read pre-translated fds from sender buffer
c056a6ba35 binder: avoid potential data leakage when copying txn
f8fee36515 dm integrity: flush the journal on suspend
096e1bd659 net: usb: qmi_wwan: add Telit 0x103a composition
86136bf623 tcp: configurable source port perturb table size
07da8fca30 platform/x86: hp-wmi: Ignore Smart Experience App event
82d758c9da platform/x86: acer-wmi: Enable SW_TABLET_MODE on Switch V 10 (SW5-017)
846c0f9cd0 platform/x86: asus-wmi: add missing pci_dev_put() in asus_wmi_set_xusb2pr()
6579436fd1 xen/platform-pci: add missing free_irq() in error path
375e79c571 serial: 8250: 8250_omap: Avoid RS485 RTS glitch on ->set_termios()
e3a2211fe1 ASoC: Intel: bytcht_es8316: Add quirk for the Nanote UMPC-01
3e2452cbc6 Input: synaptics - switch touchpad on HP Laptop 15-da3001TU to RMI mode
47b4949335 gcov: clang: fix the buffer overflow issue
ecbde4222e nilfs2: fix nilfs_sufile_mark_dirty() not set segment usage as dirty
7d08b4eba1 firmware: coreboot: Register bus in module init
a2012335aa firmware: google: Release devices before unregistering the bus
cb7495fe95 ceph: avoid putting the realm twice when decoding snaps fails
12a93545b2 ceph: do not update snapshot context when there is no new snapshot
0528b19d57 iio: pressure: ms5611: fixed value compensation bug
562f415bb3 iio: ms5611: Simplify IO callback parameters
def48fbbac nios2: add FORCE for vmlinuz.gz
da849abded init/Kconfig: fix CC_HAS_ASM_GOTO_TIED_OUTPUT test with dash
03949acb58 iio: core: Fix entry not deleted when iio_register_sw_trigger_type() fails
f8a76c28e9 iio: light: apds9960: fix wrong register for gesture gain
d3ad47426a arm64: dts: rockchip: lower rk3399-puma-haikou SD controller clock frequency
ae6bcb2698 usb: dwc3: exynos: Fix remove() function
15f8b52523 lib/vdso: use "grep -E" instead of "egrep"
960cf3c7ff s390/crashdump: fix TOD programmable field size
fabd3ab6a1 net: thunderx: Fix the ACPI memory leak
1633e6d6aa nfc: st-nci: fix memory leaks in EVT_TRANSACTION
0e2a4560db nfc: st-nci: fix incorrect validating logic in EVT_TRANSACTION
420b21235d s390/dasd: fix no record found for raw_track_access
9d1264c914 dccp/tcp: Reset saddr on failure after inet6?_hash_connect().
08f25427d8 bnx2x: fix pci device refcount leak in bnx2x_vf_is_pcie_pending()
59612acf6b regulator: twl6030: re-add TWL6032_SUBCLASS
1c12909a78 NFC: nci: fix memory leak in nci_rx_data_packet()
23b83a3c76 xfrm: Fix ignored return value in xfrm6_init()
23ba1997eb tipc: check skb_linearize() return value in tipc_disc_rcv()
59f9aad22f tipc: add an extra conn_get in tipc_conn_alloc
30f91687fa tipc: set con sock in tipc_conn_alloc
5c12136c00 net/mlx5: Fix FW tracer timestamp calculation
00492f823f Drivers: hv: vmbus: fix possible memory leak in vmbus_device_register()
e0d5becab1 Drivers: hv: vmbus: fix double free in the error path of vmbus_add_channel_work()
ec3d7202e9 nfp: add port from netdev validation for EEPROM access
9b8061a6db net: pch_gbe: fix pci device refcount leak while module exiting
9a39ea43f1 net/qla3xxx: fix potential memleak in ql3xxx_send()
a07149c10b net/mlx4: Check retval of mlx4_bitmap_init
bbf6d1bc07 ARM: mxs: fix memory leak in mxs_machine_init()
3afa86449e 9p/fd: fix issue of list_del corruption in p9_fd_cancel()
bfadcbf5ba net: pch_gbe: fix potential memleak in pch_gbe_tx_queue()
e00b42cbec nfc/nci: fix race with opening and closing
04ffa53ab7 net: liquidio: simplify if expression
79c55e66ca ARM: dts: at91: sam9g20ek: enable udc vbus gpio pinctrl
897f6a3091 tee: optee: fix possible memory leak in optee_register_device()
9c1fbac623 bus: sunxi-rsb: Support atomic transfers
347875ff9a regulator: core: fix UAF in destroy_regulator()
5561211031 regulator: core: fix kobject release warning and memory leak in regulator_register()
c062676528 ASoC: sgtl5000: Reset the CHIP_CLK_CTRL reg on remove
168d59f7f7 ARM: dts: am335x-pcm-953: Define fixed regulators in root node
dd56c671cc af_key: Fix send_acquire race with pfkey_register
9221a53bfc MIPS: pic32: treat port as signed integer
dff9b25cb9 RISC-V: vdso: Do not add missing symbols to version section in linker script
b0e025dd87 arm64/syscall: Include asm/ptrace.h in syscall_wrapper header.
0ba7c091f7 block, bfq: fix null pointer dereference in bfq_bio_bfqg()
b848811655 drm: panel-orientation-quirks: Add quirk for Acer Switch V 10 (SW5-017)
5dfbb54fe1 spi: stm32: fix stm32_spi_prepare_mbr() that halves spi clk for every run
9029aee874 wifi: mac80211: Fix ack frame idr leak when mesh has no route
1f75f9c1af audit: fix undefined behavior in bit shift for AUDIT_BIT
3129cec05f wifi: mac80211_hwsim: fix debugfs attribute ps with rc table support
b4cb3dc111 wifi: mac80211: fix memory free error when registering wiphy fail
b1dfc3f888 Revert "can: af_can: fix NULL pointer dereference in can_rx_register()"
17d66a1fd0 Merge 5.4.225 into android11-5.4-lts
d3df1dbcb2 Merge branch 'android11-5.4' into branch 'android11-5.4-lts'
4d2a309b5c Linux 5.4.225
b612f924f2 ntfs: check overflow when iterating ATTR_RECORDs
0e2ce0954b ntfs: fix out-of-bounds read in ntfs_attr_find()
266bd53062 ntfs: fix use-after-free in ntfs_attr_find()
ed8b990e89 mm: fs: initialize fsdata passed to write_begin/write_end interface
b1ad04da7f 9p/trans_fd: always use O_NONBLOCK read/write
179236a122 gfs2: Switch from strlcpy to strscpy
8b6534c9ae gfs2: Check sb_bsize_shift after reading superblock
96760723aa 9p: trans_fd/p9_conn_cancel: drop client lock earlier
ce57d6474a kcm: close race conditions on sk_receive_queue
7a704dbfd3 bpf, test_run: Fix alignment problem in bpf_prog_test_run_skb()
ad39d09190 kcm: avoid potential race in kcm_tx_work
78be2ee011 tcp: cdg: allow tcp_cdg_release() to be called multiple times
a62aa84fe1 macvlan: enforce a consistent minimal mtu
4f348b60c7 Input: i8042 - fix leaking of platform device on module removal
7b0007b28d kprobes: Skip clearing aggrprobe's post_handler in kprobe-on-ftrace case
28f7ff5e75 scsi: target: tcm_loop: Fix possible name leak in tcm_loop_setup_hba_bus()
ec59a13252 ring-buffer: Include dropped pages in counting dirty patches
32a7f06451 serial: 8250: Flush DMA Rx on RLSI
e7061dd1fe misc/vmw_vmci: fix an infoleak in vmci_host_do_receive_datagram()
3da7098e8f docs: update mediator contact information in CoC doc
27f712cd47 mmc: sdhci-pci: Fix possible memory leak caused by missing pci_dev_put()
616c6695dd mmc: sdhci-pci-o2micro: fix card detect fail issue caused by CD# debounce timeout
076712ff50 mmc: core: properly select voltage range without power cycle
1bf8ed5855 scsi: zfcp: Fix double free of FSF request when qdio send fails
5d53797ce7 Input: iforce - invert valid length check when fetching device IDs
89c0c27ab3 serial: 8250_lpss: Configure DMA also w/o DMA filter
d6ebe11ad3 serial: 8250: Fall back to non-DMA Rx if IIR_RDI occurs
b545c0e1e4 dm ioctl: fix misbehavior if list_versions races with module loading
1c5866b4dd iio: pressure: ms5611: changed hardcoded SPI speed to value limited
0dd52e141a iio: trigger: sysfs: fix possible memory leak in iio_sysfs_trig_init()
7b75515728 iio: adc: at91_adc: fix possible memory leak in at91_adc_allocate_trigger()
c025c4505f usb: chipidea: fix deadlock in ci_otg_del_timer
8c8039ede2 usb: add NO_LPM quirk for Realforce 87U Keyboard
bec9f91f7b USB: serial: option: add Fibocom FM160 0x0111 composition
1972f20f36 USB: serial: option: add u-blox LARA-L6 modem
089839cccf USB: serial: option: add u-blox LARA-R6 00B modem
31e6aba26b USB: serial: option: remove old LARA-R6 PID
5ee0a017e5 USB: serial: option: add Sierra Wireless EM9191
0410c2ae21 speakup: fix a segfault caused by switching consoles
6ed6a5dfa3 slimbus: stream: correct presence rate frequencies
56607f0bfc Revert "usb: dwc3: disable USB core PHY management"
e7dc436aea ALSA: usb-audio: Drop snd_BUG_ON() from snd_usbmidi_output_open()
72c2ea34fa ring_buffer: Do not deactivate non-existant pages
f715f31559 ftrace: Fix null pointer dereference in ftrace_add_mod()
c50e0bcf4a ftrace: Optimize the allocation for mcount entries
3041feeedb ftrace: Fix the possible incorrect kernel message
04e9e5eb45 cifs: add check for returning value of SMB2_set_info_init
293c0d7182 net: thunderbolt: Fix error handling in tbnet_init()
e6546d5412 cifs: Fix wrong return value checking when GETFLAGS
e109b41870 net/x25: Fix skb leak in x25_lapb_receive_frame()
e313efddce platform/x86/intel: pmc: Don't unconditionally attach Intel PMC when virtualized
813a8dd9c4 drbd: use after free in drbd_create_device()
0199bf0a8f xen/pcpu: fix possible memory leak in register_pcpu()
aa2ba35650 bnxt_en: Remove debugfs when pci_register_driver failed
6134357f56 net: caif: fix double disconnect client in chnl_net_open()
90638373f1 net: macvlan: Use built-in RCU list checking
83672c1b83 mISDN: fix misuse of put_device() in mISDN_register_device()
8c85770d1a net: liquidio: release resources when liquidio driver open failed
0f2c681900 mISDN: fix possible memory leak in mISDN_dsp_element_register()
d697f78cab net: bgmac: Drop free_netdev() from bgmac_enet_remove()
bec9ded540 ata: libata-transport: fix double ata_host_put() in ata_tport_add()
2ff7e852bd arm64: dts: imx8mn: Fix NAND controller size-cells
bb4a2f898e arm64: dts: imx8mm: Fix NAND controller size-cells
040f726fec pinctrl: devicetree: fix null pointer dereferencing in pinctrl_dt_to_map
5b3d6d510b parport_pc: Avoid FIFO port location truncation
f9fe7ba4ea siox: fix possible memory leak in siox_device_add()
6bb50c14c9 block: sed-opal: kmalloc the cmd/resp buffers
8555c6c112 ASoC: soc-utils: Remove __exit for snd_soc_util_exit()
b768afc68b tty: n_gsm: fix sleep-in-atomic-context bug in gsm_control_send
476b09e07b serial: imx: Add missing .thaw_noirq hook
b7c6033a8f serial: 8250: omap: Flush PM QOS work on remove
2d66412563 serial: 8250: omap: Fix unpaired pm_runtime_put_sync() in omap8250_remove()
747e76f4cc serial: 8250_omap: remove wait loop from Errata i202 workaround
2ec3f558db ASoC: core: Fix use-after-free in snd_soc_exit()
ee31abd047 spi: stm32: Print summary 'callbacks suppressed' message
a39357b4ec ASoC: codecs: jz4725b: Fix spelling mistake "Sourc" -> "Source", "Routee" -> "Route"
1a5f13b0c5 Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm
6fa082ad96 btrfs: remove pointless and double ulist frees in error paths of qgroup tests
741bded210 drm/imx: imx-tve: Fix return type of imx_tve_connector_mode_valid
761976a617 i2c: i801: add lis3lv02d's I2C address for Vostro 5568
18a501e5c7 NFSv4: Retry LOCK on OLD_STATEID during delegation return
281b93e42e selftests/intel_pstate: fix build for ARCH=x86_64
2cce0a36ce selftests/futex: fix build for clang
c81ab3d7d1 ASoC: codecs: jz4725b: fix capture selector naming
5b94d1bb1e ASoC: codecs: jz4725b: use right control for Capture Volume
21b6fbb934 ASoC: codecs: jz4725b: fix reported volume for Master ctl
c9fb6a0311 ASoC: codecs: jz4725b: add missed Line In power control bit
1719b9c0fb spi: intel: Fix the offset to get the 64K erase opcode
af93d7c9d9 ASoC: wm8962: Add an event handler for TEMP_HP and TEMP_SPK
a3b07bb0b3 ASoC: wm8997: Revert "ASoC: wm8997: Fix PM disable depth imbalance in wm8997_probe"
4d487873ba ASoC: wm5110: Revert "ASoC: wm5110: Fix PM disable depth imbalance in wm5110_probe"
f0901e1551 ASoC: wm5102: Revert "ASoC: wm5102: Fix PM disable depth imbalance in wm5102_probe"
1fd66e3b02 x86/cpu: Restore AMD's DE_CFG MSR after resume
30b0263d03 net: tun: call napi_schedule_prep() to ensure we own a napi
7a6e564ff2 dmaengine: at_hdmac: Check return code of dma_async_device_register
966dd087de dmaengine: at_hdmac: Fix impossible condition
d6ce23165c dmaengine: at_hdmac: Don't allow CPU to reorder channel enable
a535247029 dmaengine: at_hdmac: Fix completion of unissued descriptor in case of errors
77b97ef490 dmaengine: at_hdmac: Don't start transactions at tx_submit level
3d35e36d7a dmaengine: at_hdmac: Fix at_lli struct definition
ab390c532e cert host tools: Stop complaining about deprecated OpenSSL functions
d0513b095e can: j1939: j1939_send_one(): fix missing CAN header initialization
d8971f4107 udf: Fix a slab-out-of-bounds write bug in udf_find_entry()
c914c56ac0 btrfs: selftests: fix wrong error check in btrfs_free_dummy_root()
aa05252ab4 platform/x86: hp_wmi: Fix rfkill causing soft blocked wifi
431b70544b drm/i915/dmabuf: fix sg_table handling in map_dma_buf
9b162e8104 nilfs2: fix use-after-free bug of ns_writer on remount
36ff974b03 nilfs2: fix deadlock in nilfs_count_free_blocks()
b4421e6d9a vmlinux.lds.h: Fix placement of '.data..decrypted' section
022d8696a7 ALSA: usb-audio: Add DSD support for Accuphase DAC-60
ded2d51b85 ALSA: usb-audio: Add quirk entry for M-Audio Micro
02dea987ec ALSA: hda: fix potential memleak in 'add_widget_node'
9ab40b1df6 ALSA: hda/ca0132: add quirk for EVGA Z390 DARK
d51861d291 mmc: sdhci-tegra: Fix SDHCI_RESET_ALL for CQHCI
d2cf28caf5 mmc: sdhci-of-arasan: Fix SDHCI_RESET_ALL for CQHCI
ae2aeee895 mmc: cqhci: Provide helper for resetting both SDHCI and CQHCI
9fbe020829 MIPS: jump_label: Fix compat branch range check
f967bbc72f arm64: efi: Fix handling of misaligned runtime regions and drop warning
c5c0b31675 riscv: process: fix kernel info leakage
685e73e3f7 net: macvlan: fix memory leaks of macvlan_common_newlink
d1dddadf4c ethernet: tundra: free irq when alloc ring failed in tsi108_open()
1b7a565143 net: mv643xx_eth: disable napi when init rxq or txq failed in mv643xx_eth_open()
ec8a47afc5 ethernet: s2io: disable napi when start nic failed in s2io_card_up()
b03f505c5d cxgb4vf: shut down the adapter when t4vf_update_port_info() failed in cxgb4vf_open()
834d2da28f net: cxgb3_main: disable napi when bind qsets failed in cxgb_up()
8344451681 net: cpsw: disable napi in cpsw_ndo_open()
3892c2d335 net/mlx5: Allow async trigger completion execution on single CPU systems
5b72cf7a40 net: nixge: disable napi when enable interrupts failed in nixge_open()
a8aade318d perf stat: Fix printing os->prefix in CSV metrics output
da4daa36ea drivers: net: xgene: disable napi when register irq failed in xgene_enet_open()
1d84887327 dmaengine: mv_xor_v2: Fix a resource leak in mv_xor_v2_remove()
7c77e272b4 dmaengine: pxa_dma: use platform_get_irq_optional
36769b9477 tipc: fix the msg->req tlv len check in tipc_nl_compat_name_table_dump_header
afab465575 can: af_can: fix NULL pointer dereference in can_rx_register()
58cd7fdc8c ipv6: addrlabel: fix infoleak when sending struct ifaddrlblmsg to network
3ad3414591 drm/vc4: Fix missing platform_unregister_drivers() call in vc4_drm_register()
831ea56c34 hamradio: fix issue of dev reference count leakage in bpq_device_event()
c7e0024852 net: lapbether: fix issue of dev reference count leakage in lapbeth_device_event()
5661f111a1 capabilities: fix undefined behavior in bit shift for CAP_TO_MASK
08c3d22f10 net: fman: Unregister ethernet device on removal
aa94d1a607 bnxt_en: fix potentially incorrect return value for ndo_rx_flow_steer
a5a05fbef4 bnxt_en: Fix possible crash in bnxt_hwrm_set_coal()
a4f73f6adc net: tun: Fix memory leaks of napi_get_frags
65ad047fd8 net: gso: fix panic on frag_list with mixed head alloc types
e29289d0d8 HID: hyperv: fix possible memory leak in mousevsc_probe()
d975bec1ea bpf, sockmap: Fix the sk->sk_forward_alloc warning of sk_stream_kill_queues
0ede1a9882 wifi: cfg80211: fix memory leak in query_regdb_file()
1c8d066317 wifi: cfg80211: silence a sparse RCU warning
c38ea83169 phy: stm32: fix an error code in probe
45a841719f xfs: drain the buf delwri queue before xfsaild idles
e107e953d2 xfs: preserve inode versioning across remounts
7d57979052 xfs: use MMAPLOCK around filemap_map_pages()
8b27e684a6 xfs: redesign the reflink remap loop to fix blkres depletion crash
ece1eb9957 xfs: rename xfs_bmap_is_real_extent to is_written_extent
d304fafb97 xfs: preserve rmapbt swapext block reservation from freed blocks
0bd6dcc07a Merge 5.4.224 into android11-5.4-lts
644fd1c691 Merge 5.4.223 into android11-5.4-lts
e05ac131e9 Merge 5.4.222 into android11-5.4-lts
3fc02367ac Merge 5.4.221 into android11-5.4-lts
f134fec530 ANDROID: properly copy the scm_io_uring field in struct sk_buff
771a8acbb8 Linux 5.4.224
3e0c1ab197 ipc: remove memcg accounting for sops objects in do_semtimedop()
a16415c8f1 wifi: brcmfmac: Fix potential buffer overflow in brcmf_fweh_event_worker()
a24bf3c317 drm/i915/sdvo: Setup DDC fully before output init
4dadd4b161 drm/i915/sdvo: Filter out invalid outputs more sensibly
57306fef4d drm/rockchip: dsi: Force synchronous probe
e09ff743e3 mtd: rawnand: gpmi: Set WAIT_FOR_READY timeout based on program/erase times
8b1174d058 KVM: x86: emulator: update the emulation mode after CR0 write
ac3bc06c9a KVM: x86: emulator: introduce emulator_recalc_and_set_mode
f159cd915d KVM: x86: emulator: em_sysexit should update ctxt->mode
ef3094c4e9 KVM: x86: Mask off reserved bits in CPUID.80000008H
da1bf3732d KVM: x86: Mask off reserved bits in CPUID.8000001AH
2fa24d0274 ext4: fix BUG_ON() when directory entry has invalid rec_len
72743d5598 ext4: fix warning in 'ext4_da_release_space'
eed040fd35 parisc: Avoid printing the hardware path twice
9e902284ee parisc: Export iosapic_serial_irq() symbol for serial port driver
506ae30167 parisc: Make 8250_gsc driver dependend on CONFIG_PARISC
c586068aad ALSA: usb-audio: Add quirks for MacroSilicon MS2100/MS2106 devices
4e8ee3cf74 perf/x86/intel: Add Cooper Lake stepping to isolation_ucodes[]
6ffa48150b perf/x86/intel: Fix pebs event constraints for ICL
fee896d453 efi: random: reduce seed size to 32 bytes
0c72757434 fuse: add file_modified() to fallocate
0c3e6288da capabilities: fix potential memleak on error path from vfs_getxattr_alloc()
4bc52ddf63 tracing/histogram: Update document for KEYS_MAX size
c8938263e6 tools/nolibc/string: Fix memcmp() implementation
993bd0de8b kprobe: reverse kp->flags when arm_kprobe failed
fe3da74428 tcp/udp: Make early_demux back namespacified.
4ae03c869c btrfs: fix type of parameter generation in btrfs_get_dentry
27a594bc7a binder: fix UAF of alloc->vma in race with munmap()
bad83d5513 memcg: enable accounting of ipc resources
92aaa5e8fe tcp/udp: Fix memory leak in ipv6_renew_options().
c494ae1498 block, bfq: protect 'bfqd->queued' by 'bfqd->lock'
6949400ec9 Bluetooth: L2CAP: Fix attempting to access uninitialized memory
ad18f624e3 xfs: Add the missed xfs_perag_put() for xfs_ifree_cluster()
0802130a4d xfs: don't fail unwritten extent conversion on writeback due to edquot
fef141f9e4 xfs: group quota should return EDQUOT when prj quota enabled
4267433dd3 xfs: gut error handling in xfs_trans_unreserve_and_mod_sb()
24e7e39353 xfs: use ordered buffers to initialize dquot buffers during quotacheck
52802e9a03 xfs: don't fail verifier on empty attr3 leaf block
71d487a82d i2c: xiic: Add platform module alias
cdd19e559a HID: saitek: add madcatz variant of MMO7 mouse device ID
efdcd1e32c scsi: core: Restrict legal sdev_state transitions via sysfs
7011975631 media: meson: vdec: fix possible refcount leak in vdec_probe()
bfa8ccf705 media: dvb-frontends/drxk: initialize err to 0
11c8f19e0f media: cros-ec-cec: limit msg.len to CEC_MAX_MSG_SIZE
4a449430ec media: s5p_cec: limit msg.len to CEC_MAX_MSG_SIZE
381453770f ipv6: fix WARNING in ip6_route_net_exit_late()
b49f6b2f21 net, neigh: Fix null-ptr-deref in neigh_table_clear()
4954b5359e net: mdio: fix undefined behavior in bit shift for __mdiobus_register
c1f594dddd Bluetooth: L2CAP: fix use-after-free in l2cap_conn_del()
4cd094fd5d Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu
5d1a47ebf8 btrfs: fix ulist leaks in error paths of qgroup self tests
6a6731a0df btrfs: fix inode list leak during backref walking at find_parent_nodes()
2c0329406b btrfs: fix inode list leak during backref walking at resolve_indirect_refs()
3d74329d8c isdn: mISDN: netjet: fix wrong check of device registration
2ff6b66952 mISDN: fix possible memory leak in mISDN_register_device()
b13be5e852 rose: Fix NULL pointer dereference in rose_send_frame()
8457a00c98 ipvs: fix WARNING in ip_vs_app_net_cleanup()
7effc4ce3d ipvs: fix WARNING in __ip_vs_cleanup_batch()
2cc523978f ipvs: use explicitly signed chars
74fd583946 netfilter: nf_tables: release flow rule object from commit path
ca791952d4 net: tun: fix bugs for oversize packet when napi frags enabled
52e0429471 net: sched: Fix use after free in red_enqueue()
d605da3e5f ata: pata_legacy: fix pdc20230_set_piomode()
704b92c51b net: fec: fix improper use of NETDEV_TX_BUSY
f30060efcf nfc: nfcmrvl: Fix potential memory leak in nfcmrvl_i2c_nci_send()
aef89b91c7 nfc: s3fwrn5: Fix potential memory leak in s3fwrn5_nci_send()
875082ae83 RDMA/qedr: clean up work queue on failure in qedr_alloc_resources()
af8fb5a060 RDMA/core: Fix null-ptr-deref in ib_core_cleanup()
bbc5d7b46a net: dsa: Fix possible memory leaks in dsa_loop_init()
925cb538bd nfs4: Fix kmemleak when allocate slot failed
0bc335d010 NFSv4.1: We must always send RECLAIM_COMPLETE after a reboot
405309d860 NFSv4.1: Handle RECLAIM_COMPLETE trunking errors
25760a41e3 IB/hfi1: Correctly move list in sc_disable()
6b5c87f9b3 RDMA/cma: Use output interface for net_dev check
a0d9384967 Linux 5.4.223
a0a2a4bdd1 can: rcar_canfd: rcar_canfd_handle_global_receive(): fix IRQ storm on global FIFO receive
fc0eecb8b4 net: enetc: survive memory pressure without crashing
69dd3ad406 net/mlx5: Fix possible use-after-free in async command interface
827e36a031 net/mlx5e: Do not increment ESN when updating IPsec ESN state
7dc6ce3ef2 nh: fix scope used to find saddr when adding non gw nh
ba6ee85355 net: ehea: fix possible memory leak in ehea_register_port()
4175d6381f openvswitch: switch from WARN to pr_warn
0667bb6000 ALSA: aoa: Fix I2S device accounting
5bdea67453 ALSA: aoa: i2sbus: fix possible memory leak in i2sbus_add_dev()
2a47cc2a3d PM: domains: Fix handling of unavailable/disabled idle states
a49e74cc74 net: ksz884x: fix missing pci_disable_device() on error in pcidev_init()
e46f699ac2 i40e: Fix flow-type by setting GL_HASH_INSET registers
e88c2a1e28 i40e: Fix VF hang when reset is triggered on another VF
28c47fd23c i40e: Fix ethtool rx-flow-hash setting for X722
d303dabe7e media: videodev2.h: V4L2_DV_BT_BLANKING_HEIGHT should check 'interlaced'
b4a3a01762 media: v4l2-dv-timings: add sanity checks for blanking values
d8f479c777 media: vivid: dev->bitmap_cap wasn't freed in all cases
9d6870949c media: vivid: s_fbuf: add more sanity checks
8e1592d415 PM: hibernate: Allow hybrid sleep to work with s2idle
77454bc744 can: mscan: mpc5xxx: mpc5xxx_can_probe(): add missing put_clock() in error path
f79de6451e tcp: fix indefinite deferral of RTO with SACK reneging
38e4516960 net: lantiq_etop: don't free skb when returning NETDEV_TX_BUSY
97ad240fd9 net: fix UAF issue in nfqnl_nf_hook_drop() when ops_init() failed
663682cd31 kcm: annotate data-races around kcm->rx_wait
e94395e916 kcm: annotate data-races around kcm->rx_psock
f85e54b4f3 amd-xgbe: add the bit rate quirk for Molex cables
71ba2a9566 amd-xgbe: fix the SFP compliance codes check for DAC cables
fe3fd27083 x86/unwind/orc: Fix unreliable stack dump with gcov
fda2d07234 net: netsec: fix error handling in netsec_register_mdio()
24b129aed8 tipc: fix a null-ptr-deref in tipc_topsrv_accept
758dbcc6fb ALSA: ac97: fix possible memory leak in snd_ac97_dev_register()
ccaeef126e arc: iounmap() arg is volatile
fa434a64a4 drm/msm: Fix return type of mdp4_lvds_connector_mode_valid
29a6902eb0 media: v4l2: Fix v4l2_i2c_subdev_set_name function documentation
6f3511eb86 net: ieee802154: fix error return code in dgram_bind()
11993652d0 mm,hugetlb: take hugetlb_lock before decrementing h->resv_huge_pages
5a2d7c93d9 cgroup-v1: add disabled controller check in cgroup1_parse_param()
3d056d81b9 xen/gntdev: Prevent leaking grants
8f589b5c0e Xen/gntdev: don't ignore kernel unmapping error
f45ee20384 xfs: force the log after remapping a synchronous-writes file
102de7717d xfs: clear XFS_DQ_FREEING if we can't lock the dquot buffer to flush
03b449a880 xfs: finish dfops on every insert range shift iteration
3d295076ba s390/pci: add missing EX_TABLE entries to __pcistg_mio_inuser()/__pcilg_mio_inuser()
344e1cb0ba s390/futex: add missing EX_TABLE entry to __futex_atomic_op()
4f969d0753 perf auxtrace: Fix address filter symbol name match for modules
c78b0dc6fb kernfs: fix use-after-free in __kernfs_remove
7a09c64b7d mmc: core: Fix kernel panic when remove non-standard SDIO card
ed7f1ff87a drm/msm/hdmi: fix memory corruption with too many bridges
f649ed0e1b drm/msm/dsi: fix memory corruption with too many bridges
e7348308f6 mac802154: Fix LQI recording
5385af2f89 fbdev: smscufx: Fix several use-after-free bugs
07ef3be6ca iio: light: tsl2583: Fix module unloading
cb972e6d01 tools: iio: iio_utils: fix digit calculation
8f1cd9633d xhci: Remove device endpoints from bandwidth list when freeing the device
914704e0d2 mtd: rawnand: marvell: Use correct logic for nand-keep-config
5d36037b22 usb: xhci: add XHCI_SPURIOUS_SUCCESS to ASM1042 despite being a V0.96 controller
7b7a0d5433 usb: bdc: change state when port disconnected
6827b58a95 usb: dwc3: gadget: Don't set IMI for no_interrupt
9aa0254303 usb: dwc3: gadget: Stop processing more requests on IMI
035dda2bfd USB: add RESET_RESUME quirk for NVIDIA Jetson devices in RCM
e4045fbcd9 ALSA: au88x0: use explicitly signed char
d853b43808 ALSA: Use del_timer_sync() before freeing timer
caea5b20ef can: kvaser_usb: Fix possible completions during init_completion
5437642f91 can: j1939: transport: j1939_session_skb_drop_old(): spin_unlock_irqrestore() before kfree_skb()
d1e6abc127 UPSTREAM: once: fix section mismatch on clang builds
5bb30ff63f ANDROID: fix up struct sk_buf ABI breakage
9470c670ee ANDROID: fix up CRC issue with struct tcp_sock
5282d4de78 Linux 5.4.222
59f89518f5 once: fix section mismatch on clang builds
34c78f8fb6 ANDROID: fix up 131287ff83 ("once: add DO_ONCE_SLOW() for sleepable contexts")
f4606e0bf2 Revert "serial: 8250: Fix restoring termios speed after suspend"
6b029aa535 Merge 5.4.220 into android11-5.4-lts
b70bfeb986 Linux 5.4.221
6bb8769326 mm: /proc/pid/smaps_rollup: fix no vma's null-deref
a351077e58 hv_netvsc: Fix race between VF offering and VF association message from host
2f1b3377b6 Makefile.debug: re-enable debug info for .S files
9220881831 ACPI: video: Force backlight native for more TongFang devices
8ad8fc82ee riscv: topology: fix default topology reporting
60dd3dc2ac arm64: topology: move store_cpu_topology() to shared code
724483b585 iommu/vt-d: Clean up si_domain in the init_dmars() error path
dfc0337c6d net: hns: fix possible memory leak in hnae_ae_register()
bc8301ea7e net: sched: cake: fix null pointer access issue when cake_init() fails
b87f88d58f net: phy: dp83867: Extend RX strap quirk for SGMII mode
6453077a00 net/atm: fix proc_mpc_write incorrect return value
4258c473ee HID: magicmouse: Do not set BTN_MOUSE on double report
567f8de358 tipc: fix an information leak in tipc_topsrv_kern_subscr
27ee73c119 tipc: Fix recognition of trial period
fa0676d94f ACPI: extlog: Handle multiple records
13a2719ec8 btrfs: fix processing of delayed tree block refs during backref walking
b397ce3477 btrfs: fix processing of delayed data refs during backref walking
96894a4fe6 r8152: add PID for the Lenovo OneLink+ Dock
7f6d2188ec arm64: errata: Remove AES hwcap for COMPAT tasks
aae3508163 media: venus: dec: Handle the case where find_format fails
fd596e7371 KVM: arm64: vgic: Fix exit condition in scan_its_table()
383b7c50f5 ata: ahci: Match EM_MAX_SLOTS with SATA_PMP_MAX_PORTS
da97931502 ata: ahci-imx: Fix MODULE_ALIAS
c00cdfc9bd hwmon/coretemp: Handle large core ID value
3ea7da6a97 x86/microcode/AMD: Apply the patch early on every logical thread
3064c74198 ocfs2: fix BUG when iput after ocfs2_mknod fails
c2489774a2 ocfs2: clear dinode links count in case of error
6391ed32b1 xfs: fix use-after-free on CIL context on shutdown
ac055fee25 xfs: move inode flush to the sync workqueue
d3eb14b8ea xfs: reflink should force the log out if mounted with wsync
05e2b279ea xfs: factor out a new xfs_log_force_inode helper
f1172b08bb xfs: trylock underlying buffer on dquot flush
890d7dfff7 xfs: don't write a corrupt unmount record to force summary counter recalc
8ebd3ba932 xfs: tail updates only need to occur when LSN changes
87b8a7fb62 xfs: factor common AIL item deletion code
4202b103d3 xfs: Throttle commits on delayed background CIL push
7a8f95bfb9 xfs: Lower CIL flush limit for large logs
f43ff28b01 xfs: preserve default grace interval during quotacheck
553e5c8031 xfs: fix unmount hang and memory leak on shutdown during quotaoff
835306dd3f xfs: factor out quotaoff intent AIL removal and memory free
a1e03f1600 xfs: Replace function declaration by actual definition
fdce40c8fd xfs: remove the xfs_qoff_logitem_t typedef
926ddf7846 xfs: remove the xfs_dq_logitem_t typedef
80f78aa76a xfs: remove the xfs_disk_dquot_t and xfs_dquot_t
4776ae328c xfs: Use scnprintf() for avoiding potential buffer overflow
2f55a03891 xfs: check owner of dir3 blocks
15b0651f38 xfs: check owner of dir3 data blocks
bc013efdcf xfs: fix buffer corruption reporting when xfs_dir3_free_header_check fails
6e204b9e67 xfs: xfs_buf_corruption_error should take __this_address
0213ee5f4c xfs: add a function to deal with corrupt buffers post-verifiers
3c88c3c00c xfs: rework collapse range into an atomic operation
3602df3f1f xfs: rework insert range into an atomic operation
7cd181cb23 xfs: open code insert range extent split helper
fe18f1af38 Linux 5.4.220
d9fdda5efe thermal: intel_powerclamp: Use first online CPU as control_cpu
c3bb4a7e8c inet: fully convert sk->sk_rx_dst to RCU rules
96e2e21284 efi: libstub: drop pointless get_memory_map() call
97238b8858 md: Replace snprintf with scnprintf
8b766dd707 ext4: continue to expand file system when the target size doesn't reach
4a36de8947 net/ieee802154: don't warn zero-sized raw_sendmsg()
cff6131217 Revert "net/ieee802154: reject zero-sized raw_sendmsg()"
1210359a68 net: ieee802154: return -EINVAL for unknown addr type
04df9719df io_uring/af_unix: defer registered files gc to io_uring release
f5dd24a664 perf intel-pt: Fix segfault in intel_pt_print_info() with uClibc
036b1f3bca clk: bcm2835: Make peripheral PLLC critical
1eae30c011 usb: idmouse: fix an uninit-value in idmouse_open
0d150ccd55 nvmet-tcp: add bounds check on Transfer Tag
3a3a8d75af nvme: copy firmware_rev on each init
e5d8f05edb staging: rtl8723bs: fix a potential memory leak in rtw_init_cmd_priv()
072b5a41c5 Revert "usb: storage: Add quirk for Samsung Fit flash"
d6afcab1b4 usb: musb: Fix musb_gadget.c rxstate overflow bug
9fa81cbd2d usb: host: xhci: Fix potential memory leak in xhci_alloc_stream_info()
1c00bb624c md/raid5: Wait for MD_SB_CHANGE_PENDING in raid5d
e30c3a9a88 HID: roccat: Fix use-after-free in roccat_read()
81247850b8 bcache: fix set_at_max_writeback_rate() for multiple attached devices
7cfc77f4fe ata: libahci_platform: Sanity check the DT child nodes number
16a45e78a6 staging: vt6655: fix potential memory leak
3376a0cf13 power: supply: adp5061: fix out-of-bounds read in adp5061_get_chg_type()
3575949513 nbd: Fix hung when signal interrupts nbd_start_device_ioctl()
22f49d9d6e scsi: 3w-9xxx: Avoid disabling device if failing to enable it
66de922076 clk: zynqmp: pll: rectify rate rounding in zynqmp_pll_round_rate
9181af2dbf media: cx88: Fix a null-ptr-deref bug in buffer_prepare()
5dbfcf7b08 clk: zynqmp: Fix stack-out-of-bounds in strncpy`
715fe15785 btrfs: scrub: try to fix super block errors
8054f824a7 ARM: dts: imx6sx: add missing properties for sram
05f789afaf ARM: dts: imx6sll: add missing properties for sram
48d1766b35 ARM: dts: imx6sl: add missing properties for sram
ef4a3baf00 ARM: dts: imx6qp: add missing properties for sram
ee239c0340 ARM: dts: imx6dl: add missing properties for sram
82e5191b12 ARM: dts: imx6q: add missing properties for sram
0b2013ace8 ARM: dts: imx7d-sdb: config the max pressure for tsc2046
aec01503ba mmc: sdhci-msm: add compatible string check for sdm670
e67c2cda3d drm/amdgpu: fix initial connector audio value
079f64a1ea platform/x86: msi-laptop: Change DMI match / alias strings to fix module autoloading
30a3601c2f drm: panel-orientation-quirks: Add quirk for Anbernic Win600
7de3e3514c drm/vc4: vec: Fix timings for VEC modes
8f6cad7c4b drm/amd/display: fix overflow on MIN_I64 definition
cdde55f972 drm: Prevent drm_copy_field() to attempt copying a NULL pointer
fb282b4e8a drm: Use size_t type for len variable in drm_copy_field()
1d0803b153 drm/nouveau/nouveau_bo: fix potential memory leak in nouveau_bo_alloc()
61fd56b0a1 r8152: Rate limit overflow messages
7d6f9cb24d Bluetooth: L2CAP: Fix user-after-free
a76462dbdd net: If sock is dead don't access sock's sk_wq in sk_stream_wait_memory
4037270ea6 wifi: rt2x00: correctly set BBP register 86 for MT7620
2021a5aaf8 wifi: rt2x00: set SoC wmac clock register
f9c053c3e4 wifi: rt2x00: set VGC gain for both chains of MT7620
0facbe6083 wifi: rt2x00: set correct TX_SW_CFG1 MAC register for MT7620
2f383edcb7 wifi: rt2x00: don't run Rt5592 IQ calibration on MT7620
fdcc57ef8c can: bcm: check the result of can_send() in bcm_can_tx()
6e85d2ad95 Bluetooth: hci_sysfs: Fix attempting to call device_add multiple times
776f33c12f Bluetooth: L2CAP: initialize delayed works at l2cap_chan_create()
49c742afd6 wifi: brcmfmac: fix use-after-free bug in brcmf_netdev_start_xmit()
18373ed500 xfrm: Update ipcomp_scratches with NULL when freed
2c485f4f2a wifi: ath9k: avoid uninit memory read in ath9k_htc_rx_msg()
42d579d910 tcp: annotate data-race around tcp_md5sig_pool_populated
ce25d7caf3 openvswitch: Fix overreporting of drops in dropwatch
a7fe12cea5 openvswitch: Fix double reporting of drops in dropwatch
06d73f4e6b bpftool: Clear errno after libcap's checks
56a0ac4863 wifi: brcmfmac: fix invalid address access when enabling SCAN log level
38ca9ece96 NFSD: Return nfserr_serverfault if splice_ok but buf->pages have data
5a646c38f6 thermal: intel_powerclamp: Use get_cpu() instead of smp_processor_id() to avoid crash
49a6ffdaed powercap: intel_rapl: fix UBSAN shift-out-of-bounds issue
ac84b26a16 MIPS: BCM47XX: Cast memcmp() of function to (void *)
13f4d3665b ACPI: video: Add Toshiba Satellite/Portege Z830 quirk
c5ed3a3789 f2fs: fix race condition on setting FI_NO_EXTENT flag
584561e942 crypto: cavium - prevent integer overflow loading firmware
00791e017b kbuild: remove the target in signal traps when interrupted
d59d36aa4c iommu/iova: Fix module config properly
0f224fde63 crypto: ccp - Release dma channels before dmaengine unrgister
95c4e20adc crypto: akcipher - default implementation for setting a private key
4010a1afaa iommu/omap: Fix buffer overflow in debugfs
b32a285998 cgroup/cpuset: Enable update_tasks_cpumask() on top_cpuset
3317c7d211 powerpc: Fix SPE Power ISA properties for e500v1 platforms
6191f0310e powerpc/64s: Fix GENERIC_CPU build flags for PPC970 / G5
f11bce700b x86/hyperv: Fix 'struct hv_enlightened_vmcs' definition
828d190380 powerpc/powernv: add missing of_node_put() in opal_export_attrs()
0a5cee97c0 powerpc/pci_dn: Add missing of_node_put()
1535e14731 powerpc/sysdev/fsl_msi: Add missing of_node_put()
85d23c4933 powerpc/math_emu/efp: Include module.h
e77a85c3fb mailbox: bcm-ferxrm-mailbox: Fix error check for dma_map_sg
f28eec4078 clk: ast2600: BCLK comes from EPLL
fc39ebf85d clk: ti: dra7-atl: Fix reference leak in of_dra7_atl_clk_probe
111369bb8c clk: bcm2835: fix bcm2835_clock_rate_from_divisor declaration
2ee652f072 spmi: pmic-arb: correct duplicate APID to PPID mapping logic
1ea4efc09f dmaengine: ioat: stop mod_timer from resurrecting deleted timer in __cleanup()
8498490b3c clk: mediatek: mt8183: mfgcfg: Propagate rate changes to parent
8542422192 mfd: sm501: Add check for platform_driver_register()
f95ba4aab6 mfd: fsl-imx25: Fix check for platform_get_irq() errors
6804b4fede mfd: lp8788: Fix an error handling path in lp8788_irq_init() and lp8788_irq_init()
595d077f3c mfd: lp8788: Fix an error handling path in lp8788_probe()
b75f4912b3 mfd: fsl-imx25: Fix an error handling path in mx25_tsadc_setup_irq()
1f4f8b6adb mfd: intel_soc_pmic: Fix an error handling path in intel_soc_pmic_i2c_probe()
b6c2c3059e fsi: core: Check error number after calling ida_simple_get
117331a2a5 scsi: libsas: Fix use-after-free bug in smp_execute_task_sg()
558a9fcb6c serial: 8250: Fix restoring termios speed after suspend
c969316eee firmware: google: Test spinlock on panic path to avoid lockups
88b9cc60f2 staging: vt6655: fix some erroneous memory clean-up loops
83d11dd92a phy: qualcomm: call clk_disable_unprepare in the error handling
29b897ac7b tty: serial: fsl_lpuart: disable dma rx/tx use flags in lpuart_dma_shutdown
744c2d33a8 drivers: serial: jsm: fix some leaks in probe
9fe0a8c069 usb: gadget: function: fix dangling pnp_string in f_printer.c
59e3d41265 xhci: Don't show warning for reinit on known broken suspend
f8ba29ae23 md/raid5: Ensure stripe_fill happens on non-read IO with journal
9b881a2ca0 mtd: rawnand: meson: fix bit map use in meson_nfc_ecc_correct()
22830560eb ata: fix ata_id_has_dipm()
10d52d8dd1 ata: fix ata_id_has_ncq_autosense()
99e7e64451 ata: fix ata_id_has_devslp()
6ea4b3303a ata: fix ata_id_sense_reporting_enabled() and ata_id_has_sense_reporting()
e09caa38e1 RDMA/siw: Always consume all skbuf data in sk_data_ready() upcall.
b21b0d17ad mtd: devices: docg3: check the return value of devm_ioremap() in the probe
3ca6939b5d dyndbg: let query-modname override actual module name
ad0a65517c dyndbg: fix module.dyndbg handling
fc797285c4 misc: ocxl: fix possible refcount leak in afu_ioctl()
7ed37be3a2 RDMA/rxe: Fix the error caused by qp->sk
0d773c58d7 RDMA/rxe: Fix "kernel NULL pointer dereference" error
59b3153532 media: xilinx: vipp: Fix refcount leak in xvip_graph_dma_init
80a955dabb tty: xilinx_uartps: Fix the ignore_status
3e77ac46f2 media: exynos4-is: fimc-is: Add of_node_put() when breaking out of loop
3baf53328a HSI: omap_ssi_port: Fix dma_map_sg error check
aa9c0598b1 HSI: omap_ssi: Fix refcount leak in ssi_probe
5d9fb09612 clk: tegra20: Fix refcount leak in tegra20_clock_init
5984b1d661 clk: tegra: Fix refcount leak in tegra114_clock_init
6d3ac23b95 clk: tegra: Fix refcount leak in tegra210_clock_init
aa3898dec1 clk: berlin: Add of_node_put() for of_get_parent()
fcaff9bc6b clk: oxnas: Hold reference returned by of_get_parent()
ad3a056982 clk: meson: Hold reference returned by of_get_parent()
633c574e0f iio: ABI: Fix wrong format of differential capacitance channel ABI.
0111032d9a iio: inkern: only release the device node when done with it
246af42163 iio: adc: at91-sama5d2_adc: lock around oversampling and sample freq
46778752bb iio: adc: at91-sama5d2_adc: check return status for pressure and touch
d50e3817a4 iio: adc: at91-sama5d2_adc: fix AT91_SAMA5D2_MR_TRACKTIM_MAX
c29c3d32bd ARM: dts: exynos: fix polarity of VBUS GPIO of Origen
e00480d42b ARM: Drop CMDLINE_* dependency on ATAGS
fcad2eef00 ARM: dts: exynos: correct s5k6a3 reset polarity on Midas family
6858d8599c ARM: dts: kirkwood: lsxl: remove first ethernet port
d45424d980 ARM: dts: kirkwood: lsxl: fix serial line
1edbceda07 ARM: dts: turris-omnia: Fix mpp26 pin name and comment
673db1cf4d soc: qcom: smem_state: Add refcounting for the 'state->of_node'
1e3ed59370 soc: qcom: smsm: Fix refcount leak bugs in qcom_smsm_probe()
85a40bfb8e memory: of: Fix refcount leak bug in of_get_ddr_timings()
b37f4a711e memory: pl353-smc: Fix refcount leak bug in pl353_smc_probe()
56c4299f76 ALSA: hda/hdmi: Don't skip notification handling during PM operation
45387ca422 ASoC: wm5102: Fix PM disable depth imbalance in wm5102_probe
371d4dbece ASoC: wm5110: Fix PM disable depth imbalance in wm5110_probe
aa182988c0 ASoC: wm8997: Fix PM disable depth imbalance in wm8997_probe
28a12e24d1 mmc: wmt-sdmmc: Fix an error handling path in wmt_mci_probe()
93c8628183 ALSA: dmaengine: increment buffer pointer atomically
6c85495e58 drm/msm/dpu: index dpu_kms->hw_vbif using vbif_idx
c240431717 ASoC: eureka-tlv320: Hold reference returned from of_find_xxx API
9e421bd9fd mmc: au1xmmc: Fix an error handling path in au1xmmc_probe()
9d7af9b162 drm/omap: dss: Fix refcount leak bugs
0c55618aaa ALSA: hda: beep: Simplify keep-power-at-enable behavior
3ac2045d04 ASoC: rsnd: Add check for rsnd_mod_power_on
1daf69228e drm/bridge: megachips: Fix a null pointer dereference bug
b33b60afa5 drm: fix drm_mipi_dbi build errors
a367b7a96a platform/x86: msi-laptop: Fix resource cleanup
a9b32c9fe5 platform/x86: msi-laptop: Fix old-ec check for backlight registering
e548f9503c platform/chrome: fix memory corruption in ioctl
783c1c5000 platform/chrome: fix double-free in chromeos_laptop_prepare()
8242167cfc drm/mipi-dsi: Detach devices when removing the host
4d4a58c9d4 drm: bridge: adv7511: fix CEC power down control register offset
72c0d36194 net: mvpp2: fix mvpp2 debugfs leak
131287ff83 once: add DO_ONCE_SLOW() for sleepable contexts
03ac583eef net/ieee802154: reject zero-sized raw_sendmsg()
71e0ab5b75 bnx2x: fix potential memory leak in bnx2x_tpa_stop()
360aa72192 net: rds: don't hold sock lock when cancelling work from rds_tcp_reset_callbacks()
3625b684a2 tcp: fix tcp_cwnd_validate() to not forget is_cwnd_limited
382ff44716 sctp: handle the error returned from sctp_auth_asoc_init_active_key
466ed722f2 mISDN: fix use-after-free bugs in l1oip timer handlers
e6d0152c95 vhost/vsock: Use kvmalloc/kvfree for larger packets.
c202ad048f spi: s3c64xx: Fix large transfers with DMA
60a7496b40 netfilter: nft_fib: Fix for rpath check with VRF devices
610798a58e spi/omap100k:Fix PM disable depth imbalance in omap1_spi100k_probe
1d8c928ed7 x86/microcode/AMD: Track patch allocation size explicitly
215c146b40 bpf: Ensure correct locking around vulnerable function find_vpid()
4017e91ff2 net: fs_enet: Fix wrong check in do_pd_setup
08a441a4ad wifi: rtl8xxxu: gen2: Fix mistake in path B IQ calibration
e0bab93245 bpf: btf: fix truncated last_member_type_id in btf_struct_resolve
374dd4e519 wifi: rtl8xxxu: Fix skb misuse in TX queue selection
df0b024ade spi: qup: add missing clk_disable_unprepare on error in spi_qup_pm_resume_runtime()
026ffbb07f spi: qup: add missing clk_disable_unprepare on error in spi_qup_resume()
321c51aa59 wifi: rtl8xxxu: tighten bounds checking in rtl8xxxu_read_efuse()
7993680752 x86/resctrl: Fix to restore to original value when re-enabling hardware prefetch register
bbe293db7e bpftool: Fix a wrong type cast in btf_dumper_int
9ee70c3cb4 wifi: mac80211: allow bw change during channel switch in mesh
4494ec1c0b wifi: ath10k: add peer map clean up for peer delete in ath10k_sta_state()
acc393aecd nfsd: Fix a memory leak in an error handling path
d7f1e7af1e ARM: 9247/1: mm: set readonly for MT_MEMORY_RO with ARM_LPAE
5abd2626ca sh: machvec: Use char[] for section boundaries
c0f4be8303 userfaultfd: open userfaultfds with O_RDONLY
29d0c45cf1 tracing: Disable interrupt or preemption before acquiring arch_spinlock_t
b0c2e34be9 selinux: use "grep -E" instead of "egrep"
56ee957791 drm/nouveau: fix a use-after-free in nouveau_gem_prime_import_sg_table()
16435e58e5 gcov: support GCC 12.1 and newer compilers
b6094c4829 KVM: VMX: Drop bits 31:16 when shoving exception error code into VMCS
7644786461 KVM: nVMX: Unconditionally purge queued/injected events on nested "exit"
45779be5ce KVM: x86/emulator: Fix handing of POP SS to correctly set interruptibility
c3a98fc6c2 media: cedrus: Set the platform driver data earlier
3cf2ef86e0 ring-buffer: Fix race between reset page and reading page
7e06ef0345 ring-buffer: Check pending waiters when doing wake ups as well
cc1f35733c ring-buffer: Have the shortest_full queue be the shortest not longest
22707f033d ring-buffer: Allow splice to read previous partially read pages
e755b65a47 ftrace: Properly unset FTRACE_HASH_FL_MOD
f66de70930 livepatch: fix race between fork and KLP transition
1211121f0e ext4: place buffer head allocation before handle start
52c7b8d3b7 ext4: make ext4_lazyinit_thread freezable
3638aa1c7d ext4: fix null-ptr-deref in ext4_write_info
a22f52d883 ext4: avoid crash when inline data creation follows DIO write
21ea616f1e jbd2: wake up journal waiters in FIFO order, not LIFO
d1c2d820a2 nilfs2: fix use-after-free bug of struct nilfs_root
c99860f9a7 f2fs: fix to do sanity check on summary info
68b1e60755 f2fs: fix to do sanity check on destination blkaddr during recovery
c5d8198ce8 f2fs: increase the limit for reserve_root
26b7c0ac49 btrfs: fix race between quota enable and quota rescan ioctl
3742e9fd55 fbdev: smscufx: Fix use-after-free in ufx_ops_open()
52895c495b powerpc/boot: Explicitly disable usage of SPE instructions
e3f7e99337 PCI: Sanitise firmware BAR assignments behind a PCI-PCI bridge
cd251d39b1 UM: cpuinfo: Fix a warning for CONFIG_CPUMASK_OFFSTACK
08f03b333c riscv: Pass -mno-relax only on lld < 15.0.0
c61f553ba8 riscv: Allow PROT_WRITE-only mmap()
09058e5ef7 parisc: fbdev/stifb: Align graphics memory size to 4MB
2c60db6869 RISC-V: Make port I/O string accessors actually work
14c06375c8 regulator: qcom_rpm: Fix circular deferral regression
79b7547eeb ASoC: wcd9335: fix order of Slimbus unprepare/disable
6927ee818f quota: Check next/prev free block number after reading from quota file
4cf9233eb1 HID: multitouch: Add memory barriers
477ac1d57f fs: dlm: handle -EBUSY first in lock arg validation
d3961f732d fs: dlm: fix race between test_bit() and queue_work()
4352db1e33 mmc: sdhci-sprd: Fix minimum clock limit
fbefc5cce4 can: kvaser_usb_leaf: Fix CAN state after restart
9948b80910 can: kvaser_usb_leaf: Fix TX queue out of sync after restart
76d9afd30e can: kvaser_usb_leaf: Fix overread with an invalid command
953bb1dfea can: kvaser_usb: Fix use of uninitialized completion
42f7d93396 usb: add quirks for Lenovo OneLink+ Dock
37daa23f28 iio: pressure: dps310: Reset chip after timeout
228348a9fe iio: pressure: dps310: Refactor startup procedure
974c1f15ac iio: dac: ad5593r: Fix i2c read protocol requirements
d0050ec3eb cifs: Fix the error length of VALIDATE_NEGOTIATE_INFO message
bd09adde67 cifs: destage dirty pages before re-reading them for cache=none
8298f20e11 mtd: rawnand: atmel: Unmap streaming DMA mappings
8d763c8e6c ALSA: hda/realtek: Add Intel Reference SSID to support headset keys
4c35410517 ALSA: hda/realtek: Add quirk for ASUS GV601R laptop
a943c4a16b ALSA: hda/realtek: Correct pin configs for ASUS G533Z
1973164962 ALSA: hda/realtek: remove ALC289_FIXUP_DUAL_SPK for Dell 5530
121fadc0ca ALSA: usb-audio: Fix NULL dererence at error path
988ec0cd0a ALSA: usb-audio: Fix potential memory leaks
de7d80d0fe ALSA: rawmidi: Drop register_mutex in snd_rawmidi_free()
afb507303e ALSA: oss: Fix potential deadlock at unregistration

Change-Id: I06f42bac516b0d4c4bf2fd0794ea017548f7cbd9
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2023-01-21 10:51:25 +00:00
Minchan Kim
8912db2538 BACKPORT: mm: don't be stuck to rmap lock on reclaim path
The rmap locks(i_mmap_rwsem and anon_vma->root->rwsem) could be contended
under memory pressure if processes keep working on their vmas(e.g., fork,
mmap, munmap).  It makes reclaim path stuck.  In our real workload traces,
we see kswapd is waiting the lock for 300ms+(worst case, a sec) and it
makes other processes entering direct reclaim, which were also stuck on
the lock.

This patch makes lru aging path try_lock mode like shink_page_list so the
reclaim context will keep working with next lru pages without being stuck.
if it found the rmap lock contended, it rotates the page back to head of
lru in both active/inactive lrus to make them consistent behavior, which
is basic starting point rather than adding more heristic.

Since this patch introduces a new "contended" field as out-param along
with try_lock in-param in rmap_walk_control, it's not immutable any longer
if the try_lock is set so remove const keywords on rmap related functions.
Since rmap walking is already expensive operation, I doubt the const
would help sizable benefit( And we didn't have it until 5.17).

In a heavy app workload in Android, trace shows following statistics.  It
almost removes rmap lock contention from reclaim path.

Martin Liu reported:

Before:

   max_dur(ms)  min_dur(ms)  max-min(dur)ms  avg_dur(ms)  sum_dur(ms)  count blocked_function
         1632            0            1631   151.542173        31672    209  page_lock_anon_vma_read
          601            0             601   145.544681        28817    198  rmap_walk_file

After:

   max_dur(ms)  min_dur(ms)  max-min(dur)ms  avg_dur(ms)  sum_dur(ms)  count blocked_function
          NaN          NaN              NaN          NaN          NaN    0.0             NaN
            0            0                0     0.127645            1     12  rmap_walk_file

[minchan@kernel.org: add comment, per Matthew]
  Link: https://lkml.kernel.org/r/YnNqeB5tUf6LZ57b@google.com
Link: https://lkml.kernel.org/r/20220510215423.164547-1-minchan@kernel.org
Signed-off-by: Minchan Kim <minchan@kernel.org>
Acked-by: Johannes Weiner <hannes@cmpxchg.org>
Cc: Suren Baghdasaryan <surenb@google.com>
Cc: Michal Hocko <mhocko@suse.com>
Cc: John Dias <joaodias@google.com>
Cc: Tim Murray <timmurray@google.com>
Cc: Matthew Wilcox <willy@infradead.org>
Cc: Vladimir Davydov <vdavydov.dev@gmail.com>
Cc: Martin Liu <liumartin@google.com>
Cc: Minchan Kim <minchan@kernel.org>
Cc: Matthew Wilcox <willy@infradead.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>

Conflicts:
	folio->page

(cherry picked from commit 6d4675e601357834dadd2ba1d803f6484596015c)
Bug: 239681156
Bug: 252333201
Bug: 265247508
Signed-off-by: Minchan Kim <minchan@google.com>
Change-Id: I0c63e0291120c8a1b5f2d83b8a7b210cb56c27a2
Signed-off-by: chenxin <chenxinxin@xiaomi.corp-partner.google.com>
Signed-off-by: guchongchong <guchongchong@xiaomi.corp-partner.google.com>
(cherry picked from commit a0eae55f26a0cbdd828db226592093ad2142889c)
2023-01-13 08:56:32 +00:00
A. Cody Schuffelen
a69a8cd3c5 ANDROID: Add more hvc devices for virtio-console.
This allows creating more TTY devices bound to virtio-console devices.

Bug: 170149708
Test: ls /dev/hvc* on a cuttlefish device
Change-Id: Id07c25bded35dac5d17736731bfd8b8f4f1d463b
Signed-off-by: A. Cody Schuffelen <schuffelen@google.com>
2023-01-10 23:03:46 +00:00
Roderick Colenbrander
7b7c361b98 UPSTREAM: HID: playstation: support updated DualSense rumble mode.
Newer DualSense firmware supports a revised classic rumble mode,
which feels more similar to rumble as supported on previous PlayStation
controllers. It has been made the default on PlayStation and non-PlayStation
devices now (e.g. iOS and Windows). Default to this new mode when
supported.

Signed-off-by: Roderick Colenbrander <roderick.colenbrander@sony.com>
Signed-off-by: Benjamin Tissoires <benjamin.tissoires@redhat.com>
Link: https://lore.kernel.org/r/20221010212313.78275-4-roderick.colenbrander@sony.com

Bug: 260685629
(cherry picked from commit 9fecab247ed15e6145c126fc56ee1e89860741a7)
Change-Id: Icd330111a4d1b1e76a04cd11c623d0982ce3d66f
Signed-off-by: Farid Chahla <farid.chahla@sony.com>
2022-12-21 16:28:02 +00:00
Roderick Colenbrander
ff79b92f34 UPSTREAM: HID: playstation: add initial DualSense Edge controller support
Provide initial support for the DualSense Edge controller. The brings
support up to the level of the original DualSense, but won't yet provide
support for new features (e.g. reprogrammable buttons).

Signed-off-by: Roderick Colenbrander <roderick.colenbrander@sony.com>
CC: stable@vger.kernel.org
Signed-off-by: Benjamin Tissoires <benjamin.tissoires@redhat.com>
Link: https://lore.kernel.org/r/20221010212313.78275-3-roderick.colenbrander@sony.com

Bug: 260685629
(cherry picked from commit b8a968efab301743fd659b5649c5d7d3e30e63a6)
Change-Id: I5b95de806e823085d1144f016d8cfd76e4a933ef
Signed-off-by: Farid Chahla <farid.chahla@sony.com>
2022-12-21 16:28:02 +00:00
Roderick Colenbrander
9c127a4a06 UPSTREAM: HID: playstation: stop DualSense output work on remove.
Ensure we don't schedule any new output work on removal and wait
for any existing work to complete. If we don't do this e.g. rumble
work can get queued during deletion and we trigger a kernel crash.

Signed-off-by: Roderick Colenbrander <roderick.colenbrander@sony.com>
CC: stable@vger.kernel.org
Signed-off-by: Benjamin Tissoires <benjamin.tissoires@redhat.com>
Link: https://lore.kernel.org/r/20221010212313.78275-2-roderick.colenbrander@sony.com

Bug: 260685629
(cherry picked from commit 182934a1e93b17f4edf71f4fcc8d19b19a6fe67a)
Change-Id: I40cadfde5765cdabf45def929860258d6019bf10
Signed-off-by: Farid Chahla <farid.chahla@sony.com>
2022-12-21 16:28:02 +00:00
Greg Kroah-Hartman
b32bdd3e88 UPSTREAM: HID: playstation: convert to use dev_groups
There is no need for a driver to individually add/create device groups,
the driver core will do it automatically for you.  Convert the
hid-playstation driver to use the dev_groups pointer instead of manually
calling the driver core to create the group and have it be cleaned up
later on by the devm core.

Cc: Roderick Colenbrander <roderick.colenbrander@sony.com>
Cc: Jiri Kosina <jikos@kernel.org>
Cc: Benjamin Tissoires <benjamin.tissoires@redhat.com>
Cc: linux-input@vger.kernel.org
Cc: linux-kernel@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Acked-by: Roderick Colenbrander <roderick.colenbrander@sony.com>
Signed-off-by: Jiri Kosina <jkosina@suse.cz>

Bug: 260685629
(cherry picked from commit b4a9af9be628e4f9d09997e0bdef30f6718e88ec)
Change-Id: I516a1b0ef7f4f8545e0c1b9485b49879dd7a3136
Signed-off-by: Farid Chahla <farid.chahla@sony.com>
2022-12-21 16:28:02 +00:00
Jiri Kosina
c1ac1f8001 UPSTREAM: HID: playstation: fix return from dualsense_player_led_set_brightness()
brightness_set_blocking() callback expects function returning int. This fixes
the follwoing build failure:

drivers/hid/hid-playstation.c: In function ‘dualsense_player_led_set_brightness’:
drivers/hid/hid-playstation.c:885:1: error: no return statement in function returning non-void [-Werror=return-type]
 }
 ^

Signed-off-by: Jiri Kosina <jkosina@suse.cz>

Bug: 260685629
(cherry picked from commit 3c92cb4cb60c71b574e47108ead8b6f0470850db)
Change-Id: Id16b960826a26ac22c1a14572444f9af29689ed6
Signed-off-by: Farid Chahla <farid.chahla@sony.com>
2022-12-21 16:28:02 +00:00
Roderick Colenbrander
d44545535e UPSTREAM: HID: playstation: expose DualSense player LEDs through LED class.
The DualSense player LEDs were so far not adjustable from user-space.
This patch exposes each LED individually through the LED class. Each
LED uses the new 'player' function resulting in a name like:
'inputX:white:player-1' for the first LED.

Signed-off-by: Roderick Colenbrander <roderick.colenbrander@sony.com>
Signed-off-by: Jiri Kosina <jkosina@suse.cz>

Bug: 260685629
(cherry picked from commit 8c0ab553b072025530308f74b2c0223ec50dffe5)
Change-Id: I49c699a99b0b8a7bb7980560e3ea7a12faf646aa
Signed-off-by: Farid Chahla <farid.chahla@sony.com>
2022-12-21 16:28:02 +00:00
Roderick Colenbrander
07dd46d289 BACKPORT: leds: add new LED_FUNCTION_PLAYER for player LEDs for game controllers.
Player LEDs are commonly found on game controllers from Nintendo and Sony
to indicate a player ID across a number of LEDs. For example, "Player 2"
might be indicated as "-x--" on a device with 4 LEDs where "x" means on.

This patch introduces LED_FUNCTION_PLAYER1-5 defines to properly indicate
player LEDs from the kernel. Until now there was no good standard, which
resulted in inconsistent behavior across xpad, hid-sony, hid-wiimote and
other drivers. Moving forward new drivers should use LED_FUNCTION_PLAYERx.

Note: management of Player IDs is left to user space, though a kernel
driver may pick a default value.

Signed-off-by: Roderick Colenbrander <roderick.colenbrander@sony.com>
Acked-by: Pavel Machek <pavel@ucw.cz>
Signed-off-by: Jiri Kosina <jkosina@suse.cz>

Bug: 260685629
(cherry picked from commit 61177c088a57bed259122f3c7bc6d61984936a12)
[Farid: Fixed minor conflict due to skipped commits outside scope of
hid-playstation]
Change-Id: I696f62cda377be1523e74e92b66b28f3c0716c43
Signed-off-by: Farid Chahla <farid.chahla@sony.com>
2022-12-21 16:28:02 +00:00
Roderick Colenbrander
f91c45c176 UPSTREAM: HID: playstation: expose DualSense lightbar through a multi-color LED.
The DualSense lightbar has so far been supported, but it was not yet
adjustable from user space. This patch exposes it through a multi-color
LED.

Signed-off-by: Roderick Colenbrander <roderick.colenbrander@sony.com>
Signed-off-by: Jiri Kosina <jkosina@suse.cz>

Bug: 260685629
(cherry picked from commit fc97b4d6a1a6d418fd4053fd7716eca746fdd163)
Change-Id: I48204113da804b13ad5bed2f651a5826ab5a86f7
Signed-off-by: Farid Chahla <farid.chahla@sony.com>
2022-12-21 16:28:02 +00:00
Gene Chen
749207d940 UPSTREAM: leds: flash: Fix multicolor no-ops registration by return 0
Fix multicolor no-ops registration by return 0,
and move the same registration functions outside of #ifdef block.

Signed-off-by: Gene Chen <gene_chen@richtek.com>
Acked-by: Jacek Anaszewski <jacek.anaszewski@gmail.com>
Signed-off-by: Pavel Machek <pavel@ucw.cz>

Bug: 260685629
(cherry picked from commit 6039b7e87be0b350a5f8fc135adfb5d1f4ba66ad)
Change-Id: Ieb8cace2978f61bd2de5c576e851987c6ba31e2c
Signed-off-by: Farid Chahla <farid.chahla@sony.com>
2022-12-21 16:28:02 +00:00
Dan Murphy
3e667a0854 UPSTREAM: leds: multicolor: Introduce a multicolor class definition
Introduce a multicolor class that groups colored LEDs
within a LED node.

The multicolor class groups monochrome LEDs and allows controlling two
aspects of the final combined color: hue and lightness. The former is
controlled via the intensity file and the latter is controlled
via brightness file.

Signed-off-by: Dan Murphy <dmurphy@ti.com>
Acked-by: Jacek Anaszewski <jacek.anaszewski@gmail.com>
Signed-off-by: Pavel Machek <pavel@ucw.cz>
[squashed leds: multicolor: Fix camel case in documentation in]

Bug: 260685629
(cherry picked from commit 55d5d3b46b08a4dc0b05343d24640744e7430ed7)
Change-Id: Ib1f41d74ace8e3a9c1071d52202c8d8b70a912e0
Signed-off-by: Farid Chahla <farid.chahla@sony.com>
2022-12-21 16:28:02 +00:00
Farid Chahla
0b5ee17e7d ANDROID: GKI: enable mulitcolor-led
To enable newer version of DualSense driver, i.e. hid-playstation, we
need to set LEDS_CLASS_MULTICOLOR to "y".

Bug: 260685629
Change-Id: I52b0b1b6a061457e009b62a6bd6b66a91c8c37a2
Signed-off-by: Farid Chahla <farid.chahla@sony.com>
2022-12-20 17:33:50 +00:00
Lee Jones
0ce03d1655 BACKPORT: Kconfig.debug: provide a little extra FRAME_WARN leeway when KASAN is enabled
[ Upstream commit 152fe65f300e1819d59b80477d3e0999b4d5d7d2 ]

When enabled, KASAN enlarges function's stack-frames.  Pushing quite a few
over the current threshold.  This can mainly be seen on 32-bit
architectures where the present limit (when !GCC) is a lowly 1024-Bytes.

Bug: 261962742
Link: https://lkml.kernel.org/r/20221125120750.3537134-3-lee@kernel.org
Signed-off-by: Lee Jones <lee@kernel.org>
Acked-by: Arnd Bergmann <arnd@arndb.de>
Cc: Alex Deucher <alexander.deucher@amd.com>
Cc: "Christian König" <christian.koenig@amd.com>
Cc: Daniel Vetter <daniel@ffwll.ch>
Cc: David Airlie <airlied@gmail.com>
Cc: Harry Wentland <harry.wentland@amd.com>
Cc: Leo Li <sunpeng.li@amd.com>
Cc: Maarten Lankhorst <maarten.lankhorst@linux.intel.com>
Cc: Maxime Ripard <mripard@kernel.org>
Cc: Nathan Chancellor <nathan@kernel.org>
Cc: Nick Desaulniers <ndesaulniers@google.com>
Cc: "Pan, Xinhui" <Xinhui.Pan@amd.com>
Cc: Rodrigo Siqueira <Rodrigo.Siqueira@amd.com>
Cc: Thomas Zimmermann <tzimmermann@suse.de>
Cc: Tom Rix <trix@redhat.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Change-Id: I505a5187220b426fe49c0f15bf1704198082f63d
Signed-off-by: Lee Jones <joneslee@google.com>
2022-12-09 12:18:58 +00:00
Greg Kroah-Hartman
94bdbb0042 Revert "mmc: sdhci: Fix voltage switch delay"
This reverts commit 1061bf5d01 which is
commit c981cdfb9925f64a364f13c2b4f98f877308a408 upstream.

It breaks the Android ABI so revert it for now.  If this is needed in
the future, it can be brought back in an ABI safe way.

Bug: 161946584
Change-Id: Ia5d24c9adcb06166546c42810759b9193d4eaceb
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2022-12-08 20:00:15 +00:00
Greg Kroah-Hartman
b0e3bda187 ANDROID: gki_defconfig: add CONFIG_FUNCTION_ERROR_INJECTION
Commit cf1c12bc5c ("error-injection: Add prompt for function error
injection") removed the "default y" selection for this option, so it
needs to be added manually to the gki_defconfig files in order to
preserve the option, AND to keep the stable ABI.

Fixes: cf1c12bc5c ("error-injection: Add prompt for function error injection")
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: Ie36b7bab650356d1bf24625961adf33a725258d2
2022-12-08 19:59:18 +00:00
Greg Kroah-Hartman
39c4c9c65c This is the 5.4.226 stable release
-----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCAAdFiEEZH8oZUiU471FcZm+ONu9yGCSaT4FAmORuw8ACgkQONu9yGCS
 aT4qeRAAjtp+p7ECcaXqZ4vHIka9IGcwRhjWbeB/xFCOgKKbOOLmZP9Cql1pJdEp
 grdcp/tjNAwi1ec80+G/3AaAWqGRFHYi/Tboe+ZSHIp4Oot78fSclMp6lCMh/bzC
 eR6niNNNlrEUC/lj0h5lWRJvQd6MK4orSCOCybeJ+HRmrLcm1pGSuJmssHoBn7Xk
 JHg3RR5OW4BU4UHQHmcJfeH+J5zfNH0ygu1L3MRqzoINWUJ7PtSrIdR5xCm/4ibr
 oyOH0nenC3hkOM4atui/92dX3HsNxazuA51Ch0AANFRiKYjJBIXMitapi1BvpqfB
 Ny1I95j37Tuys4OQhJhNlbvHgxdNmouEHH06SwY8+yaU6LPkrFtdD0AxIDofakBZ
 Npy9AkYmvj14ARAeyqzswxSQGWuuvlDjJR3dId/kIuP8wcRcNWsrFefHs0YZxhjn
 o0LKmpkw5QgjW7Gh8TKEdl4saAXZwLXV00gHN9DD6UOr4eYNHtBHUJg6zMN5aR19
 Dco+UTJj1NlmlEBDP6pFp9LTAcTsjVh6FVpX+uMRs18+kXS3SxzPgB9qEwjerU5m
 HA0pzc+BgZqHpu3LhkbC4JfGNJ9fHnVZe6fT6/kTt3SiaEtLx8JKvH6VsCHVgEv6
 whY3hlS4bWII8Jey0ZS8BtyKJiku3zfGDXAQ3rpwGbX1ddDn+d8=
 =qI32
 -----END PGP SIGNATURE-----

Merge 5.4.226 into android11-5.4-lts

Changes in 5.4.226
	wifi: mac80211: fix memory free error when registering wiphy fail
	wifi: mac80211_hwsim: fix debugfs attribute ps with rc table support
	audit: fix undefined behavior in bit shift for AUDIT_BIT
	wifi: mac80211: Fix ack frame idr leak when mesh has no route
	spi: stm32: fix stm32_spi_prepare_mbr() that halves spi clk for every run
	drm: panel-orientation-quirks: Add quirk for Acer Switch V 10 (SW5-017)
	block, bfq: fix null pointer dereference in bfq_bio_bfqg()
	arm64/syscall: Include asm/ptrace.h in syscall_wrapper header.
	RISC-V: vdso: Do not add missing symbols to version section in linker script
	MIPS: pic32: treat port as signed integer
	af_key: Fix send_acquire race with pfkey_register
	ARM: dts: am335x-pcm-953: Define fixed regulators in root node
	ASoC: sgtl5000: Reset the CHIP_CLK_CTRL reg on remove
	regulator: core: fix kobject release warning and memory leak in regulator_register()
	regulator: core: fix UAF in destroy_regulator()
	bus: sunxi-rsb: Support atomic transfers
	tee: optee: fix possible memory leak in optee_register_device()
	ARM: dts: at91: sam9g20ek: enable udc vbus gpio pinctrl
	net: liquidio: simplify if expression
	nfc/nci: fix race with opening and closing
	net: pch_gbe: fix potential memleak in pch_gbe_tx_queue()
	9p/fd: fix issue of list_del corruption in p9_fd_cancel()
	ARM: mxs: fix memory leak in mxs_machine_init()
	net/mlx4: Check retval of mlx4_bitmap_init
	net/qla3xxx: fix potential memleak in ql3xxx_send()
	net: pch_gbe: fix pci device refcount leak while module exiting
	nfp: add port from netdev validation for EEPROM access
	Drivers: hv: vmbus: fix double free in the error path of vmbus_add_channel_work()
	Drivers: hv: vmbus: fix possible memory leak in vmbus_device_register()
	net/mlx5: Fix FW tracer timestamp calculation
	tipc: set con sock in tipc_conn_alloc
	tipc: add an extra conn_get in tipc_conn_alloc
	tipc: check skb_linearize() return value in tipc_disc_rcv()
	xfrm: Fix ignored return value in xfrm6_init()
	NFC: nci: fix memory leak in nci_rx_data_packet()
	regulator: twl6030: re-add TWL6032_SUBCLASS
	bnx2x: fix pci device refcount leak in bnx2x_vf_is_pcie_pending()
	dccp/tcp: Reset saddr on failure after inet6?_hash_connect().
	s390/dasd: fix no record found for raw_track_access
	nfc: st-nci: fix incorrect validating logic in EVT_TRANSACTION
	nfc: st-nci: fix memory leaks in EVT_TRANSACTION
	net: thunderx: Fix the ACPI memory leak
	s390/crashdump: fix TOD programmable field size
	lib/vdso: use "grep -E" instead of "egrep"
	usb: dwc3: exynos: Fix remove() function
	arm64: dts: rockchip: lower rk3399-puma-haikou SD controller clock frequency
	iio: light: apds9960: fix wrong register for gesture gain
	iio: core: Fix entry not deleted when iio_register_sw_trigger_type() fails
	init/Kconfig: fix CC_HAS_ASM_GOTO_TIED_OUTPUT test with dash
	nios2: add FORCE for vmlinuz.gz
	iio: ms5611: Simplify IO callback parameters
	iio: pressure: ms5611: fixed value compensation bug
	ceph: do not update snapshot context when there is no new snapshot
	ceph: avoid putting the realm twice when decoding snaps fails
	firmware: google: Release devices before unregistering the bus
	firmware: coreboot: Register bus in module init
	nilfs2: fix nilfs_sufile_mark_dirty() not set segment usage as dirty
	gcov: clang: fix the buffer overflow issue
	Input: synaptics - switch touchpad on HP Laptop 15-da3001TU to RMI mode
	ASoC: Intel: bytcht_es8316: Add quirk for the Nanote UMPC-01
	serial: 8250: 8250_omap: Avoid RS485 RTS glitch on ->set_termios()
	xen/platform-pci: add missing free_irq() in error path
	platform/x86: asus-wmi: add missing pci_dev_put() in asus_wmi_set_xusb2pr()
	platform/x86: acer-wmi: Enable SW_TABLET_MODE on Switch V 10 (SW5-017)
	platform/x86: hp-wmi: Ignore Smart Experience App event
	tcp: configurable source port perturb table size
	net: usb: qmi_wwan: add Telit 0x103a composition
	dm integrity: flush the journal on suspend
	binder: avoid potential data leakage when copying txn
	binder: read pre-translated fds from sender buffer
	binder: defer copies of pre-patched txn data
	binder: fix pointer cast warning
	binder: Address corner cases in deferred copy and fixup
	binder: Gracefully handle BINDER_TYPE_FDA objects with num_fds=0
	btrfs: free btrfs_path before copying root refs to userspace
	btrfs: free btrfs_path before copying fspath to userspace
	btrfs: free btrfs_path before copying subvol info to userspace
	btrfs: sysfs: normalize the error handling branch in btrfs_init_sysfs()
	drm/amd/dc/dce120: Fix audio register mapping, stop triggering KASAN
	drm/amdgpu: always register an MMU notifier for userptr
	drm/i915: fix TLB invalidation for Gen12 video and compute engines
	fuse: lock inode unconditionally in fuse_fallocate()
	btrfs: free btrfs_path before copying inodes to userspace
	spi: spi-imx: Fix spi_bus_clk if requested clock is higher than input clock
	btrfs: move QUOTA_ENABLED check to rescan_should_stop from btrfs_qgroup_rescan_worker
	drm/amdgpu: update drm_display_info correctly when the edid is read
	drm/amdgpu: Partially revert "drm/amdgpu: update drm_display_info correctly when the edid is read"
	btrfs: qgroup: fix sleep from invalid context bug in btrfs_qgroup_inherit()
	iio: health: afe4403: Fix oob read in afe4403_read_raw
	iio: health: afe4404: Fix oob read in afe4404_[read|write]_raw
	iio: light: rpr0521: add missing Kconfig dependencies
	scripts/faddr2line: Fix regression in name resolution on ppc64le
	hwmon: (i5500_temp) fix missing pci_disable_device()
	hwmon: (ibmpex) Fix possible UAF when ibmpex_register_bmc() fails
	of: property: decrement node refcount in of_fwnode_get_reference_args()
	net/mlx5: Fix uninitialized variable bug in outlen_write()
	net/mlx5e: Fix use-after-free when reverting termination table
	can: sja1000_isa: sja1000_isa_probe(): add missing free_sja1000dev()
	can: cc770: cc770_isa_probe(): add missing free_cc770dev()
	qlcnic: fix sleep-in-atomic-context bugs caused by msleep
	wifi: cfg80211: fix buffer overflow in elem comparison
	net: phy: fix null-ptr-deref while probe() failed
	net: net_netdev: Fix error handling in ntb_netdev_init_module()
	net/9p: Fix a potential socket leak in p9_socket_open
	net: ethernet: nixge: fix NULL dereference
	dsa: lan9303: Correct stat name
	net: hsr: Fix potential use-after-free
	afs: Fix fileserver probe RTT handling
	net: tun: Fix use-after-free in tun_detach()
	packet: do not set TP_STATUS_CSUM_VALID on CHECKSUM_COMPLETE
	sctp: fix memory leak in sctp_stream_outq_migrate()
	net: ethernet: renesas: ravb: Fix promiscuous mode after system resumed
	hwmon: (coretemp) Check for null before removing sysfs attrs
	hwmon: (coretemp) fix pci device refcount leak in nv1a_ram_new()
	net/mlx5: DR, Fix uninitialized var warning
	error-injection: Add prompt for function error injection
	tools/vm/slabinfo-gnuplot: use "grep -E" instead of "egrep"
	nilfs2: fix NULL pointer dereference in nilfs_palloc_commit_free_entry()
	x86/bugs: Make sure MSR_SPEC_CTRL is updated properly upon resume from S3
	pinctrl: intel: Save and restore pins in "direct IRQ" mode
	mmc: mmc_test: Fix removal of debugfs file
	mmc: core: Fix ambiguous TRIM and DISCARD arg
	mmc: sdhci-esdhc-imx: correct CQHCI exit halt state check
	mmc: sdhci-sprd: Fix no reset data and command after voltage switch
	tracing: Free buffers when a used dynamic event is removed
	arm64: Fix panic() when Spectre-v2 causes Spectre-BHB to re-allocate KVM vectors
	arm64: errata: Fix KVM Spectre-v2 mitigation selection for Cortex-A57/A72
	mm: Fix '.data.once' orphan section warning
	ASoC: ops: Fix bounds check for _sx controls
	pinctrl: single: Fix potential division by zero
	iommu/vt-d: Fix PCI device refcount leak in dmar_dev_scope_init()
	parisc: Increase size of gcc stack frame check
	xtensa: increase size of gcc stack frame check
	parisc: Increase FRAME_WARN to 2048 bytes on parisc
	Kconfig.debug: provide a little extra FRAME_WARN leeway when KASAN is enabled
	selftests: net: add delete nexthop route warning test
	selftests: net: fix nexthop warning cleanup double ip typo
	ipv4: Handle attempt to delete multipath route when fib_info contains an nh reference
	ipv4: Fix route deletion when nexthop info is not specified
	tracing/ring-buffer: Have polling block on watermark
	epoll: call final ep_events_available() check under the lock
	epoll: check for events when removing a timed out thread from the wait queue
	nvme: restrict management ioctls to admin
	nvme: ensure subsystem reset is single threaded
	x86/tsx: Add a feature bit for TSX control MSR support
	x86/pm: Add enumeration check before spec MSRs save/restore setup
	Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM
	x86/ioremap: Fix page aligned size calculation in __ioremap_caller()
	Revert "clocksource/drivers/riscv: Events are stopped during CPU suspend"
	char: tpm: Protect tpm_pm_suspend with locks
	mmc: sdhci: use FIELD_GET for preset value bit masks
	mmc: sdhci: Fix voltage switch delay
	proc: avoid integer type confusion in get_proc_long
	proc: proc_skip_spaces() shouldn't think it is working on C strings
	v4l2: don't fall back to follow_pfn() if pin_user_pages_fast() fails
	ipc/sem: Fix dangling sem_array access in semtimedop race
	Linux 5.4.226

Change-Id: I20fe6cd332455ffff094b2be6afa8302b20db571
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2022-12-08 16:50:20 +00:00
Greg Kroah-Hartman
316cdfc48d Linux 5.4.226
Link: https://lore.kernel.org/r/20221205190808.733996403@linuxfoundation.org
Tested-by: Florian Fainelli <f.fainelli@gmail.com>
Tested-by: Shuah Khan <skhan@linuxfoundation.org>
Tested-by: Allen Pais <apais@linux.microsoft.com>
Link: https://lore.kernel.org/r/20221206124054.310184563@linuxfoundation.org
Tested-by: Jon Hunter <jonathanh@nvidia.com>
Tested-by: Florian Fainelli <f.fainelli@gmail.com>
Tested-by: Allen Pais <apais@linux.microsoft.com>
Tested-by: Linux Kernel Functional Testing <lkft@linaro.org>
Tested-by: Guenter Roeck <linux@roeck-us.net>
Tested-by: Hulk Robot <hulkrobot@huawei.com>
Tested-by: Sudip Mukherjee <sudip.mukherjee@codethink.co.uk>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-12-08 11:23:06 +01:00
Jann Horn
3ab84e8913 ipc/sem: Fix dangling sem_array access in semtimedop race
[ Upstream commit b52be557e24c47286738276121177a41f54e3b83 ]

When __do_semtimedop() goes to sleep because it has to wait for a
semaphore value becoming zero or becoming bigger than some threshold, it
links the on-stack sem_queue to the sem_array, then goes to sleep
without holding a reference on the sem_array.

When __do_semtimedop() comes back out of sleep, one of two things must
happen:

 a) We prove that the on-stack sem_queue has been disconnected from the
    (possibly freed) sem_array, making it safe to return from the stack
    frame that the sem_queue exists in.

 b) We stabilize our reference to the sem_array, lock the sem_array, and
    detach the sem_queue from the sem_array ourselves.

sem_array has RCU lifetime, so for case (b), the reference can be
stabilized inside an RCU read-side critical section by locklessly
checking whether the sem_queue is still connected to the sem_array.

However, the current code does the lockless check on sem_queue before
starting an RCU read-side critical section, so the result of the
lockless check immediately becomes useless.

Fix it by doing rcu_read_lock() before the lockless check.  Now RCU
ensures that if we observe the object being on our queue, the object
can't be freed until rcu_read_unlock().

This bug is only hittable on kernel builds with full preemption support
(either CONFIG_PREEMPT or PREEMPT_DYNAMIC with preempt=full).

Fixes: 370b262c89 ("ipc/sem: avoid idr tree lookup for interrupted semop")
Cc: stable@vger.kernel.org
Signed-off-by: Jann Horn <jannh@google.com>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2022-12-08 11:23:06 +01:00
Linus Torvalds
210f96fb7e v4l2: don't fall back to follow_pfn() if pin_user_pages_fast() fails
commit 6647e76ab623b2b3fb2efe03a86e9c9046c52c33 upstream.

The V4L2_MEMORY_USERPTR interface is long deprecated and shouldn't be
used (and is discouraged for any modern v4l drivers).  And Seth Jenkins
points out that the fallback to VM_PFNMAP/VM_IO is fundamentally racy
and dangerous.

Note that it's not even a case that should trigger, since any normal
user pointer logic ends up just using the pin_user_pages_fast() call
that does the proper page reference counting.  That's not the problem
case, only if you try to use special device mappings do you have any
issues.

Normally I'd just remove this during the merge window, but since Seth
pointed out the problem cases, we really want to know as soon as
possible if there are actually any users of this odd special case of a
legacy interface.  Neither Hans nor Mauro seem to think that such
mis-uses of the old legacy interface should exist.  As Mauro says:

 "See, V4L2 has actually 4 streaming APIs:
        - Kernel-allocated mmap (usually referred simply as just mmap);
        - USERPTR mmap;
        - read();
        - dmabuf;

  The USERPTR is one of the oldest way to use it, coming from V4L
  version 1 times, and by far the least used one"

And Hans chimed in on the USERPTR interface:

 "To be honest, I wouldn't mind if it goes away completely, but that's a
  bit of a pipe dream right now"

but while removing this legacy interface entirely may be a pipe dream we
can at least try to remove the unlikely (and actively broken) case of
using special device mappings for USERPTR accesses.

This replaces it with a WARN_ONCE() that we can remove once we've
hopefully confirmed that no actual users exist.

NOTE! Longer term, this means that a 'struct frame_vector' only ever
contains proper page pointers, and all the games we have with converting
them to pages can go away (grep for 'frame_vector_to_pages()' and the
uses of 'vec->is_pfns').  But this is just the first step, to verify
that this code really is all dead, and do so as quickly as possible.

Reported-by: Seth Jenkins <sethjenkins@google.com>
Acked-by: Hans Verkuil <hverkuil@xs4all.nl>
Acked-by: Mauro Carvalho Chehab <mchehab@kernel.org>
Cc: David Hildenbrand <david@redhat.com>
Cc: Jan Kara <jack@suse.cz>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Sergey Senozhatsky <senozhatsky@chromium.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-12-08 11:23:06 +01:00
Linus Torvalds
0390da0565 proc: proc_skip_spaces() shouldn't think it is working on C strings
commit bce9332220bd677d83b19d21502776ad555a0e73 upstream.

proc_skip_spaces() seems to think it is working on C strings, and ends
up being just a wrapper around skip_spaces() with a really odd calling
convention.

Instead of basing it on skip_spaces(), it should have looked more like
proc_skip_char(), which really is the exact same function (except it
skips a particular character, rather than whitespace).  So use that as
inspiration, odd coding and all.

Now the calling convention actually makes sense and works for the
intended purpose.

Reported-and-tested-by: Kyle Zeng <zengyhkyle@gmail.com>
Acked-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-12-08 11:23:06 +01:00
Linus Torvalds
dd3124a051 proc: avoid integer type confusion in get_proc_long
commit e6cfaf34be9fcd1a8285a294e18986bfc41a409c upstream.

proc_get_long() is passed a size_t, but then assigns it to an 'int'
variable for the length.  Let's not do that, even if our IO paths are
limited to MAX_RW_COUNT (exactly because of these kinds of type errors).

So do the proper test in the rigth type.

Reported-by: Kyle Zeng <zengyhkyle@gmail.com>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-12-08 11:23:06 +01:00
Adrian Hunter
1061bf5d01 mmc: sdhci: Fix voltage switch delay
commit c981cdfb9925f64a364f13c2b4f98f877308a408 upstream.

Commit 20b92a30b5 ("mmc: sdhci: update signal voltage switch code")
removed voltage switch delays from sdhci because mmc core had been
enhanced to support them. However that assumed that sdhci_set_ios()
did a single clock change, which it did not, and so the delays in mmc
core, which should have come after the first clock change, were not
effective.

Fix by avoiding re-configuring UHS and preset settings when the clock
is turning on and the settings have not changed. That then also avoids
the associated clock changes, so that then sdhci_set_ios() does a single
clock change when voltage switching, and the mmc core delays become
effective.

To do that has meant keeping track of driver strength (host->drv_type),
and cases of reinitialization (host->reinit_uhs).

Note also, the 'turning_on_clk' restriction should not be necessary
but is done to minimize the impact of the change on stable kernels.

Fixes: 20b92a30b5 ("mmc: sdhci: update signal voltage switch code")
Cc: stable@vger.kernel.org
Signed-off-by: Adrian Hunter <adrian.hunter@intel.com>
Link: https://lore.kernel.org/r/20221128133259.38305-2-adrian.hunter@intel.com
Signed-off-by: Ulf Hansson <ulf.hansson@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-12-08 11:23:06 +01:00
Masahiro Yamada
9a5f49c0f5 mmc: sdhci: use FIELD_GET for preset value bit masks
commit fa0910107a9fea170b817f31da2a65463e00e80e upstream.

Use the FIELD_GET macro to get access to the register fields.
Delete the shift macros.

Signed-off-by: Masahiro Yamada <yamada.masahiro@socionext.com>
Link: https://lore.kernel.org/r/20200312110050.21732-1-yamada.masahiro@socionext.com
Signed-off-by: Ulf Hansson <ulf.hansson@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-12-08 11:23:06 +01:00
Jan Dabros
d699373ac5 char: tpm: Protect tpm_pm_suspend with locks
commit 23393c6461422df5bf8084a086ada9a7e17dc2ba upstream.

Currently tpm transactions are executed unconditionally in
tpm_pm_suspend() function, which may lead to races with other tpm
accessors in the system.

Specifically, the hw_random tpm driver makes use of tpm_get_random(),
and this function is called in a loop from a kthread, which means it's
not frozen alongside userspace, and so can race with the work done
during system suspend:

  tpm tpm0: tpm_transmit: tpm_recv: error -52
  tpm tpm0: invalid TPM_STS.x 0xff, dumping stack for forensics
  CPU: 0 PID: 1 Comm: init Not tainted 6.1.0-rc5+ #135
  Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.0-20220807_005459-localhost 04/01/2014
  Call Trace:
   tpm_tis_status.cold+0x19/0x20
   tpm_transmit+0x13b/0x390
   tpm_transmit_cmd+0x20/0x80
   tpm1_pm_suspend+0xa6/0x110
   tpm_pm_suspend+0x53/0x80
   __pnp_bus_suspend+0x35/0xe0
   __device_suspend+0x10f/0x350

Fix this by calling tpm_try_get_ops(), which itself is a wrapper around
tpm_chip_start(), but takes the appropriate mutex.

Signed-off-by: Jan Dabros <jsd@semihalf.com>
Reported-by: Vlastimil Babka <vbabka@suse.cz>
Tested-by: Jason A. Donenfeld <Jason@zx2c4.com>
Tested-by: Vlastimil Babka <vbabka@suse.cz>
Link: https://lore.kernel.org/all/c5ba47ef-393f-1fba-30bd-1230d1b4b592@suse.cz/
Cc: stable@vger.kernel.org
Fixes: e891db1a18 ("tpm: turn on TPM on suspend for TPM 1.x")
[Jason: reworked commit message, added metadata]
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Reviewed-by: Jarkko Sakkinen <jarkko@kernel.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-12-08 11:23:06 +01:00
Conor Dooley
9decec2993 Revert "clocksource/drivers/riscv: Events are stopped during CPU suspend"
[ Upstream commit d9f15a9de44affe733e34f93bc184945ba277e6d ]

This reverts commit 232ccac1bd9b5bfe73895f527c08623e7fa0752d.

On the subject of suspend, the RISC-V SBI spec states:

  This does not cover whether any given events actually reach the hart or
  not, just what the hart will do if it receives an event. On PolarFire
  SoC, and potentially other SiFive based implementations, events from the
  RISC-V timer do reach a hart during suspend. This is not the case for the
  implementation on the Allwinner D1 - there timer events are not received
  during suspend.

To fix this, the CLOCK_EVT_FEAT_C3STOP (mis)feature was enabled for the
timer driver - but this has broken both RCU stall detection and timers
generally on PolarFire SoC and potentially other SiFive based
implementations.

If an AXI read to the PCIe controller on PolarFire SoC times out, the
system will stall, however, with CLOCK_EVT_FEAT_C3STOP active, the system
just locks up without RCU stalling:

	io scheduler mq-deadline registered
	io scheduler kyber registered
	microchip-pcie 2000000000.pcie: host bridge /soc/pcie@2000000000 ranges:
	microchip-pcie 2000000000.pcie:      MEM 0x2008000000..0x2087ffffff -> 0x0008000000
	microchip-pcie 2000000000.pcie: sec error in pcie2axi buffer
	microchip-pcie 2000000000.pcie: ded error in pcie2axi buffer
	microchip-pcie 2000000000.pcie: axi read request error
	microchip-pcie 2000000000.pcie: axi read timeout
	microchip-pcie 2000000000.pcie: sec error in pcie2axi buffer
	microchip-pcie 2000000000.pcie: ded error in pcie2axi buffer
	microchip-pcie 2000000000.pcie: sec error in pcie2axi buffer
	microchip-pcie 2000000000.pcie: ded error in pcie2axi buffer
	microchip-pcie 2000000000.pcie: sec error in pcie2axi buffer
	microchip-pcie 2000000000.pcie: ded error in pcie2axi buffer
	Freeing initrd memory: 7332K

Similarly issues were reported with clock_nanosleep() - with a test app
that sleeps each cpu for 6, 5, 4, 3 ms respectively, HZ=250 & the blamed
commit in place, the sleep times are rounded up to the next jiffy:

== CPU: 1 ==      == CPU: 2 ==      == CPU: 3 ==      == CPU: 4 ==
Mean: 7.974992    Mean: 7.976534    Mean: 7.962591    Mean: 3.952179
Std Dev: 0.154374 Std Dev: 0.156082 Std Dev: 0.171018 Std Dev: 0.076193
Hi: 9.472000      Hi: 10.495000     Hi: 8.864000      Hi: 4.736000
Lo: 6.087000      Lo: 6.380000      Lo: 4.872000      Lo: 3.403000
Samples: 521      Samples: 521      Samples: 521      Samples: 521

Fortunately, the D1 has a second timer, which is "currently used in
preference to the RISC-V/SBI timer driver" so a revert here does not
hurt operation of D1 in its current form.

Ultimately, a DeviceTree property (or node) will be added to encode the
behaviour of the timers, but until then revert the addition of
CLOCK_EVT_FEAT_C3STOP.

Fixes: 232ccac1bd9b ("clocksource/drivers/riscv: Events are stopped during CPU suspend")
Signed-off-by: Conor Dooley <conor.dooley@microchip.com>
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
Reviewed-by: Palmer Dabbelt <palmer@rivosinc.com>
Acked-by: Palmer Dabbelt <palmer@rivosinc.com>
Acked-by: Samuel Holland <samuel@sholland.org>
Link: https://lore.kernel.org/linux-riscv/YzYTNQRxLr7Q9JR0@spud/
Link: https://github.com/riscv-non-isa/riscv-sbi-doc/issues/98/
Link: https://lore.kernel.org/linux-riscv/bf6d3b1f-f703-4a25-833e-972a44a04114@sholland.org/
Link: https://lore.kernel.org/r/20221122121620.3522431-1-conor.dooley@microchip.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
2022-12-08 11:23:06 +01:00
Michael Kelley
e67e119adf x86/ioremap: Fix page aligned size calculation in __ioremap_caller()
[ Upstream commit 4dbd6a3e90e03130973688fd79e19425f720d999 ]

Current code re-calculates the size after aligning the starting and
ending physical addresses on a page boundary. But the re-calculation
also embeds the masking of high order bits that exceed the size of
the physical address space (via PHYSICAL_PAGE_MASK). If the masking
removes any high order bits, the size calculation results in a huge
value that is likely to immediately fail.

Fix this by re-calculating the page-aligned size first. Then mask any
high order bits using PHYSICAL_PAGE_MASK.

Fixes: ffa71f33a8 ("x86, ioremap: Fix incorrect physical address handling in PAE mode")
Signed-off-by: Michael Kelley <mikelley@microsoft.com>
Signed-off-by: Borislav Petkov <bp@suse.de>
Acked-by: Dave Hansen <dave.hansen@linux.intel.com>
Cc: <stable@kernel.org>
Link: https://lore.kernel.org/r/1668624097-14884-2-git-send-email-mikelley@microsoft.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
2022-12-08 11:23:06 +01:00
Luiz Augusto von Dentz
0d87bb6070 Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM
commit 711f8c3fb3db61897080468586b970c87c61d9e4 upstream.

The Bluetooth spec states that the valid range for SPSM is from
0x0001-0x00ff so it is invalid to accept values outside of this range:

  BLUETOOTH CORE SPECIFICATION Version 5.3 | Vol 3, Part A
  page 1059:
  Table 4.15: L2CAP_LE_CREDIT_BASED_CONNECTION_REQ SPSM ranges

CVE: CVE-2022-42896
CC: stable@vger.kernel.org
Reported-by: Tamás Koczka <poprdi@google.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Reviewed-by: Tedd Ho-Jeong An <tedd.an@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-12-08 11:23:05 +01:00
Pawan Gupta
b5041a3daa x86/pm: Add enumeration check before spec MSRs save/restore setup
commit 50bcceb7724e471d9b591803889df45dcbb584bc upstream.

pm_save_spec_msr() keeps a list of all the MSRs which _might_ need
to be saved and restored at hibernate and resume. However, it has
zero awareness of CPU support for these MSRs. It mostly works by
unconditionally attempting to manipulate these MSRs and relying on
rdmsrl_safe() being able to handle a #GP on CPUs where the support is
unavailable.

However, it's possible for reads (RDMSR) to be supported for a given MSR
while writes (WRMSR) are not. In this case, msr_build_context() sees
a successful read (RDMSR) and marks the MSR as valid. Then, later, a
write (WRMSR) fails, producing a nasty (but harmless) error message.
This causes restore_processor_state() to try and restore it, but writing
this MSR is not allowed on the Intel Atom N2600 leading to:

  unchecked MSR access error: WRMSR to 0x122 (tried to write 0x0000000000000002) \
     at rIP: 0xffffffff8b07a574 (native_write_msr+0x4/0x20)
  Call Trace:
   <TASK>
   restore_processor_state
   x86_acpi_suspend_lowlevel
   acpi_suspend_enter
   suspend_devices_and_enter
   pm_suspend.cold
   state_store
   kernfs_fop_write_iter
   vfs_write
   ksys_write
   do_syscall_64
   ? do_syscall_64
   ? up_read
   ? lock_is_held_type
   ? asm_exc_page_fault
   ? lockdep_hardirqs_on
   entry_SYSCALL_64_after_hwframe

To fix this, add the corresponding X86_FEATURE bit for each MSR.  Avoid
trying to manipulate the MSR when the feature bit is clear. This
required adding a X86_FEATURE bit for MSRs that do not have one already,
but it's a small price to pay.

  [ bp: Move struct msr_enumeration inside the only function that uses it. ]
  [Pawan: Resolve build issue in backport]

Fixes: 73924ec4d560 ("x86/pm: Save the MSR validity status at context setup")
Reported-by: Hans de Goede <hdegoede@redhat.com>
Signed-off-by: Pawan Gupta <pawan.kumar.gupta@linux.intel.com>
Signed-off-by: Borislav Petkov <bp@suse.de>
Reviewed-by: Dave Hansen <dave.hansen@linux.intel.com>
Acked-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Cc: <stable@kernel.org>
Link: https://lore.kernel.org/r/c24db75d69df6e66c0465e13676ad3f2837a2ed8.1668539735.git.pawan.kumar.gupta@linux.intel.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-12-08 11:23:05 +01:00
Pawan Gupta
3b28594576 x86/tsx: Add a feature bit for TSX control MSR support
commit aaa65d17eec372c6a9756833f3964ba05b05ea14 upstream.

Support for the TSX control MSR is enumerated in MSR_IA32_ARCH_CAPABILITIES.
This is different from how other CPU features are enumerated i.e. via
CPUID. Currently, a call to tsx_ctrl_is_supported() is required for
enumerating the feature. In the absence of a feature bit for TSX control,
any code that relies on checking feature bits directly will not work.

In preparation for adding a feature bit check in MSR save/restore
during suspend/resume, set a new feature bit X86_FEATURE_TSX_CTRL when
MSR_IA32_TSX_CTRL is present.

  [ bp: Remove tsx_ctrl_is_supported()]

  [Pawan: Resolved conflicts in backport; Removed parts of commit message
          referring to removed function tsx_ctrl_is_supported()]

Suggested-by: Andrew Cooper <andrew.cooper3@citrix.com>
Signed-off-by: Pawan Gupta <pawan.kumar.gupta@linux.intel.com>
Signed-off-by: Borislav Petkov <bp@suse.de>
Reviewed-by: Dave Hansen <dave.hansen@linux.intel.com>
Cc: <stable@kernel.org>
Link: https://lore.kernel.org/r/de619764e1d98afbb7a5fa58424f1278ede37b45.1668539735.git.pawan.kumar.gupta@linux.intel.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-12-08 11:23:05 +01:00
Keith Busch
99c59256ea nvme: ensure subsystem reset is single threaded
commit 1e866afd4bcdd01a70a5eddb4371158d3035ce03 upstream.

The subsystem reset writes to a register, so we have to ensure the
device state is capable of handling that otherwise the driver may access
unmapped registers. Use the state machine to ensure the subsystem reset
doesn't try to write registers on a device already undergoing this type
of reset.

Link: https://bugzilla.kernel.org/show_bug.cgi?id=214771
Signed-off-by: Keith Busch <kbusch@kernel.org>
Signed-off-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Ovidiu Panait <ovidiu.panait@windriver.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-12-08 11:23:05 +01:00
Keith Busch
dc85ff0a5f nvme: restrict management ioctls to admin
commit 23e085b2dead13b51fe86d27069895b740f749c0 upstream.

The passthrough commands already have this restriction, but the other
operations do not. Require the same capabilities for all users as all of
these operations, which include resets and rescans, can be disruptive.

Signed-off-by: Keith Busch <kbusch@kernel.org>
Signed-off-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Ovidiu Panait <ovidiu.panait@windriver.com>
2022-12-08 11:23:05 +01:00
Soheil Hassas Yeganeh
c41a89af7b epoll: check for events when removing a timed out thread from the wait queue
commit 289caf5d8f6c61c6d2b7fd752a7f483cd153f182 upstream.

Patch series "simplify ep_poll".

This patch series is a followup based on the suggestions and feedback by
Linus:
https://lkml.kernel.org/r/CAHk-=wizk=OxUyQPbO8MS41w2Pag1kniUV5WdD5qWL-gq1kjDA@mail.gmail.com

The first patch in the series is a fix for the epoll race in presence of
timeouts, so that it can be cleanly backported to all affected stable
kernels.

The rest of the patch series simplify the ep_poll() implementation.  Some
of these simplifications result in minor performance enhancements as well.
We have kept these changes under self tests and internal benchmarks for a
few days, and there are minor (1-2%) performance enhancements as a result.

This patch (of 8):

After abc610e01c ("fs/epoll: avoid barrier after an epoll_wait(2)
timeout"), we break out of the ep_poll loop upon timeout, without checking
whether there is any new events available.  Prior to that patch-series we
always called ep_events_available() after exiting the loop.

This can cause races and missed wakeups.  For example, consider the
following scenario reported by Guantao Liu:

Suppose we have an eventfd added using EPOLLET to an epollfd.

Thread 1: Sleeps for just below 5ms and then writes to an eventfd.
Thread 2: Calls epoll_wait with a timeout of 5 ms. If it sees an
          event of the eventfd, it will write back on that fd.
Thread 3: Calls epoll_wait with a negative timeout.

Prior to abc610e01c, it is guaranteed that Thread 3 will wake up either
by Thread 1 or Thread 2.  After abc610e01c, Thread 3 can be blocked
indefinitely if Thread 2 sees a timeout right before the write to the
eventfd by Thread 1.  Thread 2 will be woken up from
schedule_hrtimeout_range and, with evail 0, it will not call
ep_send_events().

To fix this issue:
1) Simplify the timed_out case as suggested by Linus.
2) while holding the lock, recheck whether the thread was woken up
   after its time out has reached.

Note that (2) is different from Linus' original suggestion: It do not set
"eavail = ep_events_available(ep)" to avoid unnecessary contention (when
there are too many timed-out threads and a small number of events), as
well as races mentioned in the discussion thread.

This is the first patch in the series so that the backport to stable
releases is straightforward.

Link: https://lkml.kernel.org/r/20201106231635.3528496-1-soheil.kdev@gmail.com
Link: https://lkml.kernel.org/r/CAHk-=wizk=OxUyQPbO8MS41w2Pag1kniUV5WdD5qWL-gq1kjDA@mail.gmail.com
Link: https://lkml.kernel.org/r/20201106231635.3528496-2-soheil.kdev@gmail.com
Fixes: abc610e01c ("fs/epoll: avoid barrier after an epoll_wait(2) timeout")
Signed-off-by: Soheil Hassas Yeganeh <soheil@google.com>
Tested-by: Guantao Liu <guantaol@google.com>
Suggested-by: Linus Torvalds <torvalds@linux-foundation.org>
Reported-by: Guantao Liu <guantaol@google.com>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Willem de Bruijn <willemb@google.com>
Reviewed-by: Khazhismel Kumykov <khazhy@google.com>
Reviewed-by: Davidlohr Bueso <dbueso@suse.de>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Acked-by: Thadeu Lima de Souza Cascardo <cascardo@canonical.com>
Signed-off-by: Rishabh Bhatnagar <risbhat@amazon.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-12-08 11:23:05 +01:00
Roman Penyaev
b8e803cda5 epoll: call final ep_events_available() check under the lock
commit 65759097d804d2a9ad2b687db436319704ba7019 upstream.

There is a possible race when ep_scan_ready_list() leaves ->rdllist and
->obflist empty for a short period of time although some events are
pending.  It is quite likely that ep_events_available() observes empty
lists and goes to sleep.

Since commit 339ddb53d373 ("fs/epoll: remove unnecessary wakeups of
nested epoll") we are conservative in wakeups (there is only one place
for wakeup and this is ep_poll_callback()), thus ep_events_available()
must always observe correct state of two lists.

The easiest and correct way is to do the final check under the lock.
This does not impact the performance, since lock is taken anyway for
adding a wait entry to the wait queue.

The discussion of the problem can be found here:

   https://lore.kernel.org/linux-fsdevel/a2f22c3c-c25a-4bda-8339-a7bdaf17849e@akamai.com/

In this patch barrierless __set_current_state() is used.  This is safe
since waitqueue_active() is called under the same lock on wakeup side.

Short-circuit for fatal signals (i.e.  fatal_signal_pending() check) is
moved to the line just before actual events harvesting routine.  This is
fully compliant to what is said in the comment of the patch where the
actual fatal_signal_pending() check was added: c257a340ed ("fs, epoll:
short circuit fetching events if thread has been killed").

Fixes: 339ddb53d373 ("fs/epoll: remove unnecessary wakeups of nested epoll")
Reported-by: Jason Baron <jbaron@akamai.com>
Reported-by: Randy Dunlap <rdunlap@infradead.org>
Signed-off-by: Roman Penyaev <rpenyaev@suse.de>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Reviewed-by: Jason Baron <jbaron@akamai.com>
Cc: Khazhismel Kumykov <khazhy@google.com>
Cc: Alexander Viro <viro@zeniv.linux.org.uk>
Cc: <stable@vger.kernel.org>
Link: http://lkml.kernel.org/r/20200505145609.1865152-1-rpenyaev@suse.de
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Acked-by: Thadeu Lima de Souza Cascardo <cascardo@canonical.com>
Signed-off-by: Rishabh Bhatnagar <risbhat@amazon.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-12-08 11:23:05 +01:00
Steven Rostedt (Google)
e65ac2bdda tracing/ring-buffer: Have polling block on watermark
commit 42fb0a1e84ff525ebe560e2baf9451ab69127e2b upstream.

Currently the way polling works on the ring buffer is broken. It will
return immediately if there's any data in the ring buffer whereas a read
will block until the watermark (defined by the tracefs buffer_percent file)
is hit.

That is, a select() or poll() will return as if there's data available,
but then the following read will block. This is broken for the way
select()s and poll()s are supposed to work.

Have the polling on the ring buffer also block the same way reads and
splice does on the ring buffer.

Link: https://lkml.kernel.org/r/20221020231427.41be3f26@gandalf.local.home

Cc: Linux Trace Kernel <linux-trace-kernel@vger.kernel.org>
Cc: Masami Hiramatsu <mhiramat@kernel.org>
Cc: Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
Cc: Primiano Tucci <primiano@google.com>
Cc: stable@vger.kernel.org
Fixes: 1e0d6714ac ("ring-buffer: Do not wake up a splice waiter when page is not full")
Signed-off-by: Steven Rostedt (Google) <rostedt@goodmis.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-12-08 11:23:05 +01:00
Ido Schimmel
899e148171 ipv4: Fix route deletion when nexthop info is not specified
[ Upstream commit d5082d386eee7e8ec46fa8581932c81a4961dcef ]

When the kernel receives a route deletion request from user space it
tries to delete a route that matches the route attributes specified in
the request.

If only prefix information is specified in the request, the kernel
should delete the first matching FIB alias regardless of its associated
FIB info. However, an error is currently returned when the FIB info is
backed by a nexthop object:

 # ip nexthop add id 1 via 192.0.2.2 dev dummy10
 # ip route add 198.51.100.0/24 nhid 1
 # ip route del 198.51.100.0/24
 RTNETLINK answers: No such process

Fix by matching on such a FIB info when legacy nexthop attributes are
not specified in the request. An earlier check already covers the case
where a nexthop ID is specified in the request.

Add tests that cover these flows. Before the fix:

 # ./fib_nexthops.sh -t ipv4_fcnal
 ...
 TEST: Delete route when not specifying nexthop attributes           [FAIL]

 Tests passed:  11
 Tests failed:   1

After the fix:

 # ./fib_nexthops.sh -t ipv4_fcnal
 ...
 TEST: Delete route when not specifying nexthop attributes           [ OK ]

 Tests passed:  12
 Tests failed:   0

No regressions in other tests:

 # ./fib_nexthops.sh
 ...
 Tests passed: 228
 Tests failed:   0

 # ./fib_tests.sh
 ...
 Tests passed: 186
 Tests failed:   0

Cc: stable@vger.kernel.org
Reported-by: Jonas Gorski <jonas.gorski@gmail.com>
Tested-by: Jonas Gorski <jonas.gorski@gmail.com>
Fixes: 493ced1ac4 ("ipv4: Allow routes to use nexthop objects")
Fixes: 6bf92d70e690 ("net: ipv4: fix route with nexthop object delete warning")
Fixes: 61b91eb33a69 ("ipv4: Handle attempt to delete multipath route when fib_info contains an nh reference")
Signed-off-by: Ido Schimmel <idosch@nvidia.com>
Reviewed-by: Nikolay Aleksandrov <razor@blackwall.org>
Reviewed-by: David Ahern <dsahern@kernel.org>
Link: https://lore.kernel.org/r/20221124210932.2470010-1-idosch@nvidia.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2022-12-08 11:23:05 +01:00
David Ahern
cc3cd130ec ipv4: Handle attempt to delete multipath route when fib_info contains an nh reference
[ Upstream commit 61b91eb33a69c3be11b259c5ea484505cd79f883 ]

Gwangun Jung reported a slab-out-of-bounds access in fib_nh_match:
    fib_nh_match+0xf98/0x1130 linux-6.0-rc7/net/ipv4/fib_semantics.c:961
    fib_table_delete+0x5f3/0xa40 linux-6.0-rc7/net/ipv4/fib_trie.c:1753
    inet_rtm_delroute+0x2b3/0x380 linux-6.0-rc7/net/ipv4/fib_frontend.c:874

Separate nexthop objects are mutually exclusive with the legacy
multipath spec. Fix fib_nh_match to return if the config for the
to be deleted route contains a multipath spec while the fib_info
is using a nexthop object.

Fixes: 493ced1ac4 ("ipv4: Allow routes to use nexthop objects")
Fixes: 6bf92d70e690 ("net: ipv4: fix route with nexthop object delete warning")
Reported-by: Gwangun Jung <exsociety@gmail.com>
Signed-off-by: David Ahern <dsahern@kernel.org>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Tested-by: Ido Schimmel <idosch@nvidia.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Stable-dep-of: d5082d386eee ("ipv4: Fix route deletion when nexthop info is not specified")
Signed-off-by: Sasha Levin <sashal@kernel.org>
2022-12-08 11:23:05 +01:00