Commit graph

904,203 commits

Author SHA1 Message Date
Hangyu Hua
ef9a17e64f UPSTREAM: net: sched: sch_multiq: fix possible OOB write in multiq_tune()
[ Upstream commit affc18fdc694190ca7575b9a86632a73b9fe043d ]

q->bands will be assigned to qopt->bands to execute subsequent code logic
after kmalloc. So the old q->bands should not be used in kmalloc.
Otherwise, an out-of-bounds write will occur.

Bug: 349777785
Fixes: c2999f7fb0 ("net: sched: multiq: don't call qdisc_put() while holding tree lock")
Signed-off-by: Hangyu Hua <hbh25y@gmail.com>
Acked-by: Cong Wang <cong.wang@bytedance.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
(cherry picked from commit 0f208fad86631e005754606c3ec80c0d44a11882)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: Iec8413c39878596795420ae58bbe6974890cf2de
2024-08-27 09:59:25 +01:00
Carlos Llamas
f4e5b5151e FROMLIST: binder: fix UAF caused by offsets overwrite
Binder objects are processed and copied individually into the target
buffer during transactions. Any raw data in-between these objects is
copied as well. However, this raw data copy lacks an out-of-bounds
check. If the raw data exceeds the data section size then the copy
overwrites the offsets section. This eventually triggers an error that
attempts to unwind the processed objects. However, at this point the
offsets used to index these objects are now corrupted.

Unwinding with corrupted offsets can result in decrements of arbitrary
nodes and lead to their premature release. Other users of such nodes are
left with a dangling pointer triggering a use-after-free. This issue is
made evident by the following KASAN report (trimmed):

  ==================================================================
  BUG: KASAN: slab-use-after-free in _raw_spin_lock+0xe4/0x19c
  Write of size 4 at addr ffff47fc91598f04 by task binder-util/743

  CPU: 9 UID: 0 PID: 743 Comm: binder-util Not tainted 6.11.0-rc4 #1
  Hardware name: linux,dummy-virt (DT)
  Call trace:
   _raw_spin_lock+0xe4/0x19c
   binder_free_buf+0x128/0x434
   binder_thread_write+0x8a4/0x3260
   binder_ioctl+0x18f0/0x258c
  [...]

  Allocated by task 743:
   __kmalloc_cache_noprof+0x110/0x270
   binder_new_node+0x50/0x700
   binder_transaction+0x413c/0x6da8
   binder_thread_write+0x978/0x3260
   binder_ioctl+0x18f0/0x258c
  [...]

  Freed by task 745:
   kfree+0xbc/0x208
   binder_thread_read+0x1c5c/0x37d4
   binder_ioctl+0x16d8/0x258c
  [...]
  ==================================================================

To avoid this issue, let's check that the raw data copy is within the
boundaries of the data section.

Fixes: 6d98eb95b450 ("binder: avoid potential data leakage when copying txn")
Cc: Todd Kjos <tkjos@google.com>
Cc: stable@vger.kernel.org
Signed-off-by: Carlos Llamas <cmllamas@google.com>

Bug: 352520660
Link: https://lore.kernel.org/all/20240822182353.2129600-1-cmllamas@google.com/
Change-Id: I1b2dd8403b63e5eeb58904558b7b542141c83fc2
Signed-off-by: Carlos Llamas <cmllamas@google.com>
2024-08-23 16:47:50 +00:00
Lee Jones
7453ecf4d1 UPSTREAM: usb: gadget: configfs: Prevent OOB read/write in usb_string_copy()
commit 6d3c721e686ea6c59e18289b400cc95c76e927e0 upstream.

Userspace provided string 's' could trivially have the length zero. Left
unchecked this will firstly result in an OOB read in the form
`if (str[0 - 1] == '\n') followed closely by an OOB write in the form
`str[0 - 1] = '\0'`.

There is already a validating check to catch strings that are too long.
Let's supply an additional check for invalid strings that are too short.

Bug: 346754046
Signed-off-by: Lee Jones <lee@kernel.org>
Cc: stable <stable@kernel.org>
Link: https://lore.kernel.org/r/20240705074339.633717-1-lee@kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit d1205033e912f9332c1dbefa812e6ceb0575ce0a)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: Id9a34f3e5495aef0d2a800a1386210f4d9fa8116
2024-07-22 16:28:44 +01:00
Greg Kroah-Hartman
56e07d95b5 Merge tag 'android11-5.4.278_r00' into android11-5.4
This catches android11-5.4 up to the 5.4.278 LTS release.  Included in
here are the following commits:

* 06b018ca42 Revert "drm/panel: simple: Add missing Innolux G121X1-L03 format, flags, connector"
*   eb1a0358d1 Merge 5.4.278 into android11-5.4-lts
|\
| * 189ee9735a Linux 5.4.278
| * 2997e2fb1c nfs: fix undefined behavior in nfs_block_bits()
| * 7c72af16ab s390/ap: Fix crash in AP internal function modify_bitmap()
| * 896a7e7d0d ext4: fix mb_cache_entry's e_refcnt leak in ext4_xattr_block_cache_find()
| * 95572c6b8e sparc: move struct termio to asm/termios.h
| * 0b45c25d60 xsk: validate user input for XDP_{UMEM|COMPLETION}_FILL_RING
| * db00828250 net: fix __dst_negative_advice() race
| * 6b84387afe kdb: Use format-specifiers rather than memset() for padding in kdb_read()
| * 147bac05f2 kdb: Merge identical case statements in kdb_read()
| * 084e84ede9 kdb: Fix console handling when editing and tab-completing commands
| * 6a3836f29b kdb: Use format-strings rather than '\0' injection in kdb_read()
| * ddd2972d8e kdb: Fix buffer overflow during tab-complete
| * 2098b237ba sparc64: Fix number of online CPUs
| * 68682329fc intel_th: pci: Add Meteor Lake-S CPU support
| * 2101901dd5 net/9p: fix uninit-value in p9_client_rpc()
| * 636438dd9d net/ipv6: Fix route deleting failure when metric equals 0
| * 6396b33e98 crypto: qat - Fix ADF_DEV_RESET_SYNC memory leak
| * 95abba5168 crypto: ecrdsa - Fix module auto-load on add_key
| * a2579c802c KVM: arm64: Allow AArch32 PSTATE.M to be restored as System mode
| * 86435f39c1 fbdev: savage: Handle err return when savagefb_check_var failed
| * bec5fe171f media: v4l2-core: hold videodev_lock until dev reg, finishes
| * 0dcb04014f media: mxl5xx: Move xpt structures off stack
| * 6ac608af7b media: mc: mark the media devnode as registered from the, start
| * c125ebaf03 arm64: dts: hi3798cv200: fix the size of GICR
| * 6649fea036 wifi: rtl8xxxu: Fix the TX power of RTL8192CU, RTL8723AU
| * 634ba3c97e md/raid5: fix deadlock that raid5d() wait for itself to clear MD_SB_CHANGE_PENDING
| * fe60a7bc34 arm64: tegra: Correct Tegra132 I2C alias
| * 68edebd1ff ACPI: resource: Do IRQ override on TongFang GXxHRXx and GMxHGxx
| * 3b472ad39c ata: pata_legacy: make legacy_exit() work again
| * 5594971e02 drm/amdgpu: add error handle to avoid out-of-bounds
| * 8915dcd29a media: lgdt3306a: Add a check against null-pointer-def
| * c559a8d840 f2fs: fix to do sanity check on i_xattr_nid in sanity_check_inode()
| * 27fba38ddd x86/mm: Remove broken vsyscall emulation code from the page fault code
| * 9a7f481f3e vxlan: Fix regression when dropping packets due to invalid src addresses
| * 82933c84f1 nilfs2: fix use-after-free of timer for log writer thread
| * ffbda400b2 afs: Don't cross .backup mountpoint from backup volume
| * 6e23457791 io_uring: fail NOP if non-zero op flags is passed in
| * 63664389b6 mmc: core: Do not force a retune before RPMB switch
| * e4daa1a1ff binder: fix max_thread type inconsistency
| * 6ed45d20d3 SUNRPC: Fix loop termination condition in gss_free_in_token_pages()
| * f5f4675960 genirq/cpuhotplug, x86/vector: Prevent vector leak during CPU offline
| * 74bfb8d90f ALSA: timer: Set lower bound of start tick time
| * 54768bacfd ipvlan: Dont Use skb->sk in ipvlan_process_v{4,6}_outbound
| * ce05d4a3b0 spi: stm32: Don't warn about spurious interrupts
| * f13fc5113d kconfig: fix comparison to constant symbols, 'm', 'n'
| * 10f0af5234 netfilter: tproxy: bail out if IP has been disabled on the device
| * 582233516a net:fec: Add fec_enet_deinit()
| * 00a762ee6b net: usb: smsc95xx: fix changing LED_SEL bit value updated from EEPROM
| * 2be4ac3d99 smsc95xx: use usbnet->driver_priv
| * a4ecfe6a98 smsc95xx: remove redundant function arguments
| * ca63fb7af9 enic: Validate length of nl attributes in enic_set_vf_port
| * 165b25e3ee dma-buf/sw-sync: don't enable IRQ from sync_print_obj()
| * a921cd1f0c net/mlx5e: Use rx_missed_errors instead of rx_dropped for reporting buffer exhaustion
| * 5f4278f151 nvmet: fix ns enable/disable possible hang
| * 27a6986af2 spi: Don't mark message DMA mapped when no transfer in it is
| * 3989b81785 netfilter: nfnetlink_queue: acquire rcu_read_lock() in instance_destroy_rcu()
| * 2271803d9f nfc: nci: Fix handling of zero-length payload packets in nci_rx_work()
| * db58c41b51 nfc: nci: Fix kcov check in nci_rx_work()
| * 4b179b0cfc net: fec: avoid lock evasion when reading pps_enable
| * 43a9aaf632 virtio: delete vq in vp_find_vqs_msix() when request_irq() fails
| * 22469a0335 arm64: asm-bug: Add .align 2 to the end of __BUG_ENTRY
| * 09ef5c5e36 openvswitch: Set the skbuff pkt_type for proper pmtud support.
| * 6aacaa80d9 tcp: Fix shift-out-of-bounds in dctcp_update_alpha().
| * 07b002723c params: lift param_set_uint_minmax to common code
| * 4a3fcf5372 ipv6: sr: fix memleak in seg6_hmac_init_algo
| * b1589a6eef sunrpc: fix NFSACL RPC retry on soft mount
| * 485ded868e nfc: nci: Fix uninit-value in nci_rx_work
| * eae8e2dcb0 x86/kconfig: Select ARCH_WANT_FRAME_POINTERS again when UNWINDER_FRAME_POINTER=y
| * f5acbae737 null_blk: Fix the WARNING: modpost: missing MODULE_DESCRIPTION()
| * 2990b6c0a6 media: cec: cec-api: add locking in cec_release()
| * 8890dd70fa media: cec: cec-adap: always cancel work in cec_transmit_msg_fh
| * 3f5c5d869e um: Fix the -Wmissing-prototypes warning for __switch_mm
| * 5b1796345d powerpc/pseries: Add failure related checks for h_get_mpp and h_get_ppp
| * b648756eb9 scsi: qla2xxx: Replace all non-returning strlcpy() with strscpy()
| * ecf4ddc3ae media: stk1160: fix bounds checking in stk1160_copy_video()
| * dc1ff95602 um: Add winch to winch_handlers before registering winch IRQ
| * 94bf61b291 um: Fix return value in ubd_init()
| * 0a5ad8dc33 drm/msm/dpu: Always flush the slave INTF on the CTL
| * 2b486d2306 Input: pm8xxx-vibrator - correct VIB_MAX_LEVELS calculation
| * 33d148cdb1 Input: ims-pcu - fix printf string overflow
| * b01d29acc8 libsubcmd: Fix parse-options memory leak
| * d9754fc9c0 serial: sh-sci: protect invalidating RXDMA on shutdown
| * cd97dcd412 f2fs: fix to release node block count in error path of f2fs_new_node_page()
| * 7420402619 extcon: max8997: select IRQ_DOMAIN instead of depending on it
| * b8c6b83cc3 ppdev: Add an error check in register_device
| * 5f3c34b719 ppdev: Remove usage of the deprecated ida_simple_xx() API
| * a0450d3f38 stm class: Fix a double free in stm_register_device()
| * 4591a1764a usb: gadget: u_audio: Clear uac pointer when freed.
| * eba6b40877 microblaze: Remove early printk call from cpuinfo-static.c
| * 0df1153511 microblaze: Remove gcc flag for non existing early_printk.c file
| * 463d714a58 iio: pressure: dps310: support negative temperature values
| * c0e9a72845 greybus: arche-ctrl: move device table to its right location
| * e728f8dfff serial: max3100: Fix bitwise types
| * 9db4222ed8 serial: max3100: Update uart_driver_registered on driver removal
| * ea9b35372b serial: max3100: Lock port->lock when calling uart_handle_cts_change()
| * 4ba0e40fdd firmware: dmi-id: add a release callback function
| * 7481337ab7 dmaengine: idma64: Add check for dma_set_max_seg_size
| * 002364b2d5 soundwire: cadence: fix invalid PDI offset
| * 98a649463a soundwire: cadence_master: improve PDI allocation
| * 6584388c03 soundwire: intel: don't filter out PDI0/1
| * 10568e442c soundwire: cadence/intel: simplify PDI/port mapping
| * e2c64246e5 greybus: lights: check return of get_channel_from_mode
| * 5c05727363 sched/fair: Allow disabling sched_balance_newidle with sched_relax_domain_level
| * 2137d07adb sched/topology: Don't set SD_BALANCE_WAKE on cpuset domain relax
| * b5b2d42bb3 af_packet: do not call packet_read_pending() from tpacket_destruct_skb()
| * 1fbfb483c1 netrom: fix possible dead-lock in nr_rt_ioctl()
| * fdee55c429 RDMA/IPoIB: Fix format truncation compilation errors
| * a7d9afa3dd selftests/kcmp: remove unused open mode
| * e7af24598d selftests/kcmp: Make the test output consistent and clear
| * 4420b73c7f SUNRPC: Fix gss_free_in_token_pages()
| * ff15f1100c sunrpc: removed redundant procp check
| * 9462d82504 ext4: avoid excessive credit estimate in ext4_tmpfile()
| * ce366a2c94 x86/insn: Fix PUSH instruction in x86 instruction decoder opcode map
| * 2679ddbf08 RDMA/hns: Use complete parentheses in macros
| * f5734138fb drm/panel: simple: Add missing Innolux G121X1-L03 format, flags, connector
| * bab3a580ee ASoC: tracing: Export SND_SOC_DAPM_DIR_OUT to its value
| * 565d9ad7e5 drm/arm/malidp: fix a possible null pointer dereference
| * a790c8a742 fbdev: sh7760fb: allow modular build
| * a8c15b9f30 platform/x86: wmi: Make two functions static
| * 51184b721d media: radio-shark2: Avoid led_names truncations
| * 166e0d4d79 media: ngene: Add dvb_ca_en50221_init return value check
| * 472e95f220 fbdev: sisfb: hide unused variables
| * e8d37421d4 powerpc/fsl-soc: hide unused const variable
| * be34a1b351 drm/mediatek: Add 0 size check to mtk_drm_gem_obj
| * 9b8deba36a fbdev: shmobile: fix snprintf truncation
| * 6658e44858 mtd: rawnand: hynix: fixed typo
| * e280ab978c drm/amd/display: Fix potential index out of bounds in color transformation function
| * 646cd236c5 ipv6: sr: fix invalid unregister error path
| * 6d7723bdc7 ipv6: sr: fix incorrect unregister order
| * 08094420c6 ipv6: sr: add missing seg6_local_exit
| * 0b532f5943 net: openvswitch: fix overwriting ct original tuple for ICMPv6
| * 90fa1b38c3 net: usb: smsc95xx: stop lying about skb->truesize
| * de6641d213 af_unix: Fix data races in unix_release_sock/unix_stream_sendmsg
| * 3cd46d51a4 net: ethernet: cortina: Locking fixes
| * c03effc478 m68k: mac: Fix reboot hang on Mac IIci
| * 5213cc01d0 m68k: Fix spinlock race in kernel thread creation
| * 85f70f8aeb net: usb: sr9700: stop lying about skb->truesize
| * 43b78d06e7 usb: aqc111: stop lying about skb->truesize
| * d0209bbac2 wifi: mwl8k: initialize cmd->addr[] properly
| * a75001678e scsi: qedf: Ensure the copied buf is NUL terminated
| * 595a6b98de scsi: bfa: Ensure the copied buf is NUL terminated
| * c5d19837cc HID: intel-ish-hid: ipc: Add check for pci_alloc_irq_vectors
| * 2bdad9da45 Revert "sh: Handle calling csum_partial with misaligned data"
| * deb3c6e64b sh: kprobes: Merge arch_copy_kprobe() into arch_prepare_kprobe()
| * 68a5a00c5d wifi: ar5523: enable proper endpoint verification
| * ac3ed46a87 wifi: carl9170: add a proper sanity check for endpoints
| * 1e9c3f2cae macintosh/via-macii: Fix "BUG: sleeping function called from invalid context"
| * 31e1da773a tcp: avoid premature drops in tcp_add_backlog()
| * 9d04b4d0fe tcp: fix a signed-integer-overflow bug in tcp_add_backlog()
| * 527eaa5aa6 tcp: minor optimization in tcp_add_backlog()
| * 539c4bf754 wifi: ath10k: populate board data for WCN3990
| * 9e16d735c6 wifi: ath10k: Fix an error code problem in ath10k_dbg_sta_write_peer_debug_trigger()
| * 15650ffd47 x86/purgatory: Switch to the position-independent small code model
| * e3a45d8134 scsi: hpsa: Fix allocation size for Scsi_Host private data
| * e999155c60 scsi: libsas: Fix the failure of adding phy with zero-address to port
| * 2d730b465e cpufreq: exit() callback is optional
| * e660a2e670 cpufreq: Rearrange locking in cpufreq_remove_dev()
| * 14bef1ad61 cpufreq: Split cpufreq_offline()
| * 458965e83c cpufreq: Reorganize checks in cpufreq_offline()
| * a65066c520 ACPI: disable -Wstringop-truncation
| * 8e44605294 irqchip/alpine-msi: Fix off-by-one in allocation error path
| * 0dba8fd01a scsi: ufs: core: Perform read back after disabling UIC_COMMAND_COMPL
| * 14baa35711 scsi: ufs: core: Perform read back after disabling interrupts
| * db5e443d5a scsi: ufs: cdns-pltfrm: Perform read back after writing HCLKDIV
| * 50b2cebe33 scsi: ufs: qcom: Perform read back after writing reset bit
| * 8cff599e2f qed: avoid truncating work queue length
| * 6dde0c15c5 x86/boot: Ignore relocations in .notes sections in walk_relocs() too
| * a50b7aae18 wifi: ath10k: poll service ready message before failing
| * 43771597fe md: fix resync softlockup when bitmap size is less than array size
| * 0f306d16ff null_blk: Fix missing mutex_destroy() at module removal
| * 526235dffc jffs2: prevent xattr node from overflowing the eraseblock
| * f84dd50f91 s390/cio: fix tracepoint subchannel type field
| * 2246880d90 crypto: ccp - drop platform ifdef checks
| * 3a7c49e101 parisc: add missing export of __cmpxchg_u8()
| * 354bc3231f nilfs2: fix out-of-range warning
| * 235b859810 ecryptfs: Fix buffer size for tag 66 packet
| * 94ac93159b firmware: raspberrypi: Use correct device for DMA mappings
| * e719c8991c crypto: bcm - Fix pointer arithmetic
| * 281ccb2a54 openpromfs: finish conversion to the new mount API
| * fce3de55e8 nvme: find numa distance only if controller has valid numa id
| * 74d98cccea drm/amdkfd: Flush the process wq before creating a kfd_process
| * 7e44593de9 ASoC: da7219-aad: fix usage of device_get_named_child_node()
| * b159bd7fa8 ASoC: dt-bindings: rt5645: add cbj sleeve gpio property
| * 63175250af ASoC: rt5645: Fix the electric noise due to the CBJ contacts floating
| * 07191510c3 drm/amd/display: Set color_mgmt_changed to true on unsuspend
| * 47bce5529c net: usb: qmi_wwan: add Telit FN920C04 compositions
| * 917c553186 wifi: cfg80211: fix the order of arguments for trace events of the tx_rx_evt class
| * bc9cee50a4 nilfs2: fix potential hang in nilfs_detach_log_writer()
| * bcb5016559 nilfs2: fix unexpected freezing of nilfs_segctor_sync()
| * 8cd4b29283 net: smc91x: Fix m68k kernel compilation for ColdFire CPU
| * c68b7a442e ring-buffer: Fix a race between readers and resize checks
| * cd7f3978c2 speakup: Fix sizeof() vs ARRAY_SIZE() bug
| * b229bc6c6e tty: n_gsm: fix possible out-of-bounds in gsm0_receive()
| * 491bd4d7aa x86/tsc: Trust initial offset in architectural TSC-adjust MSRs
* | 5c67c52b0d Merge branch 'android11-5.4' into branch 'android11-5.4-lts'
* | 4b533a5511 Merge 5.4.277 into android11-5.4-lts
|\|
| * 4a548b29cd Linux 5.4.277
| * 2b21f3095b docs: kernel_include.py: Cope with docutils 0.21
| * ecef5df796 serial: kgdboc: Fix NMI-safety problems from keyboard reset code
| * 6b40d4c262 usb: typec: ucsi: displayport: Fix potential deadlock
| * 467139546f drm/amdgpu: Fix possible NULL dereference in amdgpu_ras_query_error_status_helper()
| * 791d236a68 btrfs: add missing mutex_unlock in btrfs_relocate_sys_chunks()
| * ea4105d991 arm64: dts: qcom: Fix 'interrupt-map' parent address cells
| * 7184491fc5 firmware: arm_scmi: Harden accesses to the reset domains
| * 6726429c18 smb: client: fix potential OOBs in smb2_parse_contexts()
| * db389e74d3 net: bcmgenet: synchronize UMAC_CMD access
| * ae59f1f444 net: bcmgenet: synchronize use of bcmgenet_set_rx_mode()
| * 40fc58f86b net: bcmgenet: synchronize EXT_RGMII_OOB_CTRL access
| * 4f470a80ce net: bcmgenet: keep MAC in reset until PHY is up
| * bf3ace5c10 Revert "net: bcmgenet: use RGMII loopback for MAC reset"
| * 44f0418482 Revert "selftests: mm: fix map_hugetlb failure on 64K page size systems"
| * d0083459e2 ext4: fix bug_on in __es_tree_search
| * c9e7f98f55 pinctrl: core: handle radix_tree_insert() errors in pinctrl_register_one_pin()
* 18ae7bded0 Merge branch 'android11-5.4' into branch 'android11-5.4-lts'

Change-Id: I77842e63e44ae93d7f0cdc0022f1f43edc1dc89e
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-07-20 13:35:08 +00:00
Kalesh Singh
adc9210e7e ANDROID: 16K: Don't set padding vm_flags on 32-bit archs
vma_pad_fixup_flags() and is_mergable_pad_vma() were inadvertently
affecting the vm_flags on 32-bit arch, making some VMAs not mergable.

This causes zygote to crash as the Art GC's heap compaction fails.

The compaction depends on mremap() which will fail when operating on
a range that spans multiple VMAs [1]. This can happen now due to the
incorrect is_mergable_pad_vma() check.

Make all the pgsize_migration APIs no-ops in 32-bit architectures,
since Android only performs ELF segment extension in 64-bit archs.

[1] https://github.com/torvalds/linux/blob/v6.9/mm/mremap.c#L841-L843

Bug: 353667356
Change-Id: Id9b0076ef173d75a4afc85577355d340fce03e65
Signed-off-by: Kalesh Singh <kaleshsingh@google.com>
(cherry picked from commit f3437db87063f624f189e1cd38347a971fdd3fa0)
2024-07-18 20:00:41 +00:00
Giuliano Procida
dc1385281a ANDROID: GKI: refresh ABI to include kimage_vaddr
This symbol is now recognised by ABI tooling.

Bug: 352610488
Change-Id: I2136a106eaf1c194d49c891ef0d27d0b40b780ba
Signed-off-by: Giuliano Procida <gprocida@google.com>
2024-07-12 15:32:13 +01:00
Remi Denis-Courmont
9ace17ce18 BACKPORT: arm64: move kimage_vaddr to .rodata
Clean backport.

This datum is not referenced from .idmap.text: it does not need to be
mapped in idmap. Lets move it to .rodata as it is never written to after
early boot of the primary CPU.
(Maybe .data.ro_after_init would be cleaner though?)

Bug: 352610488
Change-Id: I83bc69358eca7eca1a5e9916bc6fe477f1c6ef96
Signed-off-by: Rémi Denis-Courmont <remi@remlab.net>
Acked-by: Will Deacon <will@kernel.org>
Signed-off-by: Catalin Marinas <catalin.marinas@arm.com>
(cherry picked from commit 6cf9a2dce6bd10cf454cf6299c1c23182cb486e7)
Signed-off-by: Giuliano Procida <gprocida@google.com>
2024-07-12 15:32:07 +01:00
Mark Brown
db0d3aeed9 BACKPORT: arm64: kernel: Convert to modern annotations for assembly data
This backport excludes the changes to entry.S due to unresolvable merge
conflicts. They are not needed as no symbols there are exported. The
changes to head.S merged cleanly.

In an effort to clarify and simplify the annotation of assembly functions
in the kernel new macros have been introduced. These include specific
annotations for the start and end of data, update symbols for data to use
these.

Bug: 352610488
Change-Id: I53ed408ccd7bc96af9221a9ba7ed4450ffcd6299
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Catalin Marinas <catalin.marinas@arm.com>
(cherry picked from commit a5d4420b26b5068a98ce75210b07d2e083f5f691)
Signed-off-by: Giuliano Procida <gprocida@google.com>
2024-07-12 15:31:35 +01:00
Todd Kjos
7f5fa80716 ANDROID: fix kernelci build breaks due to hid/uhid cyclic dependency
An android-only patch to work around frozen KMI for android14 kernels
allows a dependency between hid and uhid if both modules are enabled:

if (IS_ENABLED(CONFIG_UHID) && parser->device->ll_driver == &uhid_hid_driver)
    max_buffer_size = UHID_DATA_MAX;

For allmodconfig builds, both hid and uhid are modules so this creates
a cyclic dependancy and we see this error in kernelci tests:

    ERROR: Cycle detected: hid -> uhid -> hid

Fix by changeing to IS_BUILTIN() instead of IS_ENABLED() since Android
builds always build uhid into the core kernel.

Fixes: 7668cef28386 ("ANDROID: HID: Only utilise UHID provided exports if UHID is enabled")
Signed-off-by: Todd Kjos <tkjos@google.com>
Change-Id: I622466a42ad94e3606820cf506188bd679078cbf
2024-07-01 17:33:09 +00:00
Greg Kroah-Hartman
6aff87f48c Merge tag 'android11-5.4.276_r00' into android11-5.4
This merges the 5.4.276 LTS release into android11-5.4.  Included in
here are the following commits:

*   7b99a72942 Merge 5.4.276 into android11-5.4-lts
|\
| * 24d2be3797 Linux 5.4.276
| * ef9ea1c4a7 pinctrl: mediatek: paris: Fix PIN_CONFIG_INPUT_SCHMITT_ENABLE readback
| * 20c17102aa pinctrl: mediatek: remove set but not used variable 'e'
| * fa812e30c9 pinctrl: mediatek: Fix some off by one bugs
| * 1c86f75da0 pinctrl: mediatek: Fix fallback behavior for bias_set_combo
| * 3bbbcafb0d regulator: core: fix debugfs creation regression
| * 7b0e64583e net: fix out-of-bounds access in ops_init
| * cef0962f2d drm/vmwgfx: Fix invalid reads in fence signaled events
| * 343081c21e dyndbg: fix old BUG_ON in >control parser
| * 93bc2d6d16 tipc: fix UAF in error path
| * 77e49fb4bf usb: gadget: f_fs: Fix a race condition when processing setup packets.
| * 567fed8d82 usb: gadget: composite: fix OS descriptors w_value logic
| * 7b8c7bd229 firewire: nosy: ensure user_length is taken into account when fetching packet contents
| * e44d406388 net: qede: use return from qede_parse_flow_attr() for flower
| * e4bb83fb87 net: qede: sanitize 'rc' in qede_add_tc_flower_fltr()
| * ddec23f206 ipv6: fib6_rules: avoid possible NULL dereference in fib6_rule_action()
| * 2c110b4520 net: bridge: fix corrupted ethernet header on multicast-to-unicast
| * dc6beac059 phonet: fix rtm_phonet_notify() skb allocation
| * 5e7ef2d886 rtnetlink: Correct nested IFLA_VF_VLAN_LIST attribute validation
| * 6466ee65e5 Bluetooth: l2cap: fix null-ptr-deref in l2cap_chan_timeout
| * 3212afd00e Bluetooth: Fix use-after-free bugs caused by sco_sock_timeout
| * 1796ca9c6f tcp: Use refcount_inc_not_zero() in tcp_twsk_unique().
| * ed5e279b69 tcp: defer shutdown(SEND_SHUTDOWN) for TCP_SYN_RECV sockets
| * 810e964dd2 xfrm: Preserve vlan tags for transport mode software GRO
| * 4cc43efca9 pinctrl: mediatek: Fix fallback call path
| * d23431fc4e net:usb:qmi_wwan: support Rolling modules
| * 69a0fae3a8 fs/9p: drop inodes immediately on non-.L too
| * b187728541 clk: Don't hold prepare_lock when calling kref_put()
| * e29234b7c5 gpio: crystalcove: Use -ENOTSUPP consistently
| * aa4df1ee85 gpio: wcove: Use -ENOTSUPP consistently
| * f633cf1da1 9p: explicitly deny setlease attempts
| * 09335c69da fs/9p: translate O_TRUNC into OTRUNC
| * df1962a199 fs/9p: only translate RWX permissions for plain 9P2000
| * 19e8d8df9c selftests: timers: Fix valid-adjtimex signed left-shift undefined behavior
| * 43efb3f09d MIPS: scall: Save thread_info.syscall unconditionally on entry
| * 2cd614ba0e gpu: host1x: Do not setup DMA for virtual devices
| * a66018780c scsi: target: Fix SELinux error when systemd-modules loads the target module
| * e52f7c2d0f btrfs: always clear PERTRANS metadata during commit
| * 50fe716ced btrfs: make btrfs_clear_delalloc_extent() free delalloc reserve
| * 0ef9d9c3ee tools/power turbostat: Fix Bzy_MHz documentation typo
| * ab1931d6f8 tools/power turbostat: Fix added raw MSR output
| * 31279bbca4 firewire: ohci: mask bus reset interrupts between ISR and bottom half
| * 63f6a1a4d5 ata: sata_gemini: Check clk_enable() result
| * c0edb6797b net: bcmgenet: Reset RBUF on first open
| * 909859ed13 ALSA: line6: Zero-initialize message buffers
| * acd370c1fb scsi: bnx2fc: Remove spin_lock_bh while releasing resources after upload
| * ea668eff28 net: mark racy access on sk->sk_rcvbuf
| * 5492c86dbb wifi: cfg80211: fix rdev_dump_mpp() arguments order
| * e394ea8af5 wifi: mac80211: fix ieee80211_bss_*_flags kernel-doc
| * a93f5806e7 gfs2: Fix invalid metadata access in punch_hole
| * 2ffd47deca scsi: lpfc: Update lpfc_ramp_down_queue_handler() logic
| * fe11826ffa clk: sunxi-ng: h6: Reparent CPUX during PLL CPUX rate change
| * 2f87fd9476 tipc: fix a possible memleak in tipc_buf_append
| * 4945c046ae net: bridge: fix multicast-to-unicast with fraglist GSO
| * 37a067e22f net: dsa: mv88e6xxx: Fix number of databases for 88E6141 / 88E6341
| * c82ac8fbf6 net: dsa: mv88e6xxx: Add number of MACs in the ATU
| * 049b4d1013 net: qede: use return from qede_parse_flow_attr() for flow_spec
| * 8155d5a540 net l2tp: drop flow hash on forward
| * 46134031c2 nsh: Restore skb->{protocol,data,mac_header} for outer header in nsh_gso_segment().
| * 80578ec103 bna: ensure the copied buf is NUL terminated
| * 74f677ab16 s390/mm: Fix clearing storage keys for huge pages
| * 8e63d2ba48 s390/mm: Fix storage key clearing for guest huge pages
| * 47d253c485 pinctrl: devicetree: fix refcount leak in pinctrl_dt_to_map()
| * 8ade209260 power: rt9455: hide unused rt9455_boost_voltage_values
| * b33ca18c3a nfs: Handle error of rpc_proc_register() in nfs_net_init().
| * 19f51adc77 nfs: make the rpc_stat per net namespace
| * 31dd0cda5a nfs: expose /proc/net/sunrpc/nfs in net namespaces
| * 0ce8590992 sunrpc: add a struct rpc_stats arg to rpc_create_args
| * 54834d07d9 pinctrl: mediatek: paris: Rework support for PIN_CONFIG_{INPUT,OUTPUT}_ENABLE
| * 43fa2f6bf5 pinctrl: mediatek: paris: Rework mtk_pinconf_{get,set} switch/case logic
| * 8840d7ff0d pinctrl: mediatek: paris: Fix PIN_CONFIG_BIAS_* readback
| * b06391309a pinctrl: mediatek: remove shadow variable declaration
| * 79be366d98 pinctrl: mediatek: Backward compatible to previous Mediatek's bias-pull usage
| * 20ea2b1e13 pinctrl: mediatek: Refine mtk_pinconf_get()
| * 22fddbacb9 pinctrl: mediatek: Refine mtk_pinconf_get() and mtk_pinconf_set()
| * 3d7b213d92 pinctrl: mediatek: Supporting driving setting without mapping current to register value
| * 61754e3351 pinctrl: mediatek: Check gpio pin number and use binary search in mtk_hw_pin_field_lookup()
| * cdaa171473 pinctrl: core: delete incorrect free in pinctrl_enable()
| * 97792d0611 wifi: nl80211: don't free NULL coalescing rule
| * 3762017ca5 dmaengine: Revert "dmaengine: pl330: issue_pending waits until WFP state"
| * 6e23e7e3a3 dmaengine: pl330: issue_pending waits until WFP state
* | b9e6f92358 Revert "clk: Get runtime PM before walking tree during disable_unused"
* | 65d8957031 Merge 5.4.275 into android11-5.4-lts
|/
* 936e689eae Linux 5.4.275
* 7ae3c1fbc4 serial: core: fix kernel-doc for uart_port_unlock_irqrestore()
* 06fdb177a0 udp: preserve the connected status if only UDP cmsg
* 86f4a49f32 dm: limit the number of targets and parameter size area
* d34a516f26 bounds: Use the right number of bits for power-of-two CONFIG_NR_CPUS
* c448a9fd50 HID: i2c-hid: remove I2C_HID_READ_PENDING flag to prevent lock-up
* ad3c3ac7a0 i2c: smbus: fix NULL function pointer dereference
* 65a241aac3 idma64: Don't try to serve interrupts when device is powered off
* abfe16c8e7 dmaengine: owl: fix register access functions
* fc5bb10173 tcp: Fix NEW_SYN_RECV handling in inet_twsk_purge()
* 53fab9cec2 tcp: Clean up kernel listener's reqsk in inet_twsk_purge()
* 672c5715b6 mtd: diskonchip: work around ubsan link failure
* 7d3996c74c stackdepot: respect __GFP_NOLOCKDEP allocation flag
* 90be0c7757 net: b44: set pause params only when interface is up
* 53c9574bb0 ethernet: Add helper for assigning packet type when dest address does not match device address
* b72d2b1448 irqchip/gic-v3-its: Prevent double free on error
* 851a52eb9b drm/amdgpu: Fix leak when GPU memory allocation fails
* 21722c0b07 arm64: dts: rockchip: enable internal pull-up for Q7_THRM# on RK3399 Puma
* 73db209dcd btrfs: fix information leak in btrfs_ioctl_logical_to_ino()
* 344972770c Bluetooth: btusb: Add Realtek RTL8852BE support ID 0x0bda:0x4853
* 9c25b42905 Bluetooth: Fix type of len in {l2cap,sco}_sock_getsockopt_old()
* 049f36ee98 tracing: Increase PERF_MAX_TRACE_SIZE to handle Sentinel1 and docker together
* 92e64e2675 tracing: Show size of requested perf buffer
* c9e38f7ad6 net/mlx5e: Fix a race in command alloc flow
* 62c724e5ec Revert "crypto: api - Disallow identical driver names"
* f68039375d drm/amdgpu: validate the parameters of bo mapping operations more clearly
* d83c337e65 amdgpu: validate offset_in_bo of drm_amdgpu_gem_va
* 3b418dca9a drm/amdgpu: restrict bo mapping within gpu address limits
* 21535ef0ac serial: mxs-auart: add spinlock around changing cts state
* e8646f5d34 serial: core: Provide port lock wrappers
* eb27704f0d af_unix: Suppress false-positive lockdep splat for spin_lock() in __unix_gc().
* 4077b864ff iavf: Fix TC config comparison with existing adapter TC config
* 546d0fe9d7 i40e: Do not use WQ_MEM_RECLAIM flag for workqueue
* 51cefc9da4 mlxsw: spectrum_acl_tcam: Fix memory leak when canceling rehash work
* 0b2c13b670 mlxsw: spectrum_acl_tcam: Fix incorrect list API usage
* 0b88631855 mlxsw: spectrum_acl_tcam: Fix warning during rehash
* c6f3fa7f5a mlxsw: spectrum_acl_tcam: Fix memory leak during rehash
* a43a0423e4 mlxsw: spectrum_acl_tcam: Rate limit error message
* e118e7ea24 mlxsw: spectrum_acl_tcam: Fix possible use-after-free during rehash
* 1b73f6e4ea mlxsw: spectrum_acl_tcam: Fix possible use-after-free during activity update
* 40bdd69f74 mlxsw: spectrum_acl_tcam: Fix race during rehash delayed work
* 589523cf0b net: openvswitch: Fix Use-After-Free in ovs_ct_exit
* 3606e77b54 ipvs: Fix checksumming on GSO of SCTP packets
* 718df1bc22 net: gtp: Fix Use-After-Free in gtp_dellink
* b51177e40e net: usb: ax88179_178a: stop lying about skb->truesize
* 380bf47752 NFC: trf7970a: disable all regulators on removal
* 42de7aa391 mlxsw: core: Unregister EMAD trap using FORWARD action
* 51cf144f9c vxlan: drop packets from invalid src-address
* ef3c87d540 ARC: [plat-hsdk]: Remove misplaced interrupt-cells property
* 8378341b21 arm64: dts: mediatek: mt2712: fix validation errors
* 8f70bcc88d arm64: dts: mt2712: add ethernet device node
* 73556b2101 arm64: dts: mediatek: mt7622: drop "reset-names" from thermal block
* 1e4ce3ba7f arm64: dts: mediatek: mt7622: fix ethernet controller "compatible"
* dcc04db701 arm64: dts: mediatek: mt7622: fix IR nodename
* 55f3e91e91 arm64: dts: rockchip: enable internal pull-up on PCIE_WAKE# for RK3399 Puma
* 2d7d80942e arm64: dts: rockchip: fix alphabetical ordering RK3399 puma
* 7dc6e67f51 KVM: async_pf: Cleanup kvm_setup_async_pf()
* 90f43980ea nilfs2: fix OOB in nilfs_set_de_type
* 1bc4825d4c nouveau: fix instmem race condition around ptr stores
* 57baab0f37 fs: sysfs: Fix reference leak in sysfs_break_active_protection()
* 8f6b62125b speakup: Avoid crash on very long word
* c64704f080 usb: Disable USB3 LPM at shutdown
* 75bf5e78b2 usb: dwc2: host: Fix dereference issue in DDMA completion flow.
* 164be0a824 Revert "usb: cdc-wdm: close race between read and workqueue"
* 11a3e5c76e USB: serial: option: add Telit FN920C04 rmnet compositions
* 3a7fca20cb USB: serial: option: add Rolling RW101-GL and RW135-GL support
* 386fb39ea3 USB: serial: option: support Quectel EM060K sub-models
* 1224818578 USB: serial: option: add Lonsung U8300/U9300 product
* 8e5ddf4a8a USB: serial: option: add support for Fibocom FM650/FG650
* fc693ec145 USB: serial: option: add Fibocom FM135-GL variants
* d679c81692 serial/pmac_zilog: Remove flawed mitigation for rx irq flood
* a3b8ae7e92 comedi: vmk80xx: fix incomplete endpoint checking
* 68a28f551e binder: check offset alignment in binder_get_object()
* 58ecead174 x86/cpufeatures: Fix dependencies for GFNI, VAES, and VPCLMULQDQ
* 253ab38d1e clk: Get runtime PM before walking tree during disable_unused
* 8cf77c61a8 clk: Initialize struct clk_core kref earlier
* 1d09f800f2 clk: Print an info line before disabling unused clocks
* 25ce8c7114 clk: remove extra empty line
* fdd3437c7b clk: Mark 'all_lists' as const
* b9ef935c0a clk: Remove prepare_lock hold assertion in __clk_release()
* 5050ae879a drm: nv04: Fix out of bounds access
* 4b1930bd42 RDMA/mlx5: Fix port number for counter query in multi-port configuration
* 80997511b9 RDMA/rxe: Fix the problem "mutex_destroy missing"
* 4b0dcae5c4 tun: limit printing rate when illegal packet received by tun dev
* b38a133d37 netfilter: nf_tables: Fix potential data-race in __nft_expr_type_get()
* 2450a69d2e Revert "tracing/trigger: Fix to return error if failed to alloc snapshot"
* 93eb31e7c3 kprobes: Fix possible use-after-free issue on kprobe registration
* 49cacd34e3 selftests/ftrace: Limit length in subsystem-enable tests
* 14b74fc24c btrfs: record delayed inode root in transaction
* b282473af7 x86/apic: Force native_apic_mem_read() to use the MOV instruction
* ed180e21c2 selftests: timers: Fix abs() warning in posix_timers test
* 5fd4f81421 vhost: Add smp_rmb() in vhost_vq_avail_empty()
* 5a2f957e3c drm/client: Fully protect modes[] with dev->mode_config.mutex
* 70040ce92e btrfs: qgroup: correctly model root qgroup rsv in convert
* 1cb6c82d11 net: ena: Fix potential sign extension issue
* 343c5372d5 af_unix: Fix garbage collector racing against connect()
* 7f4c391d3b af_unix: Do not use atomic ops for unix_sk(sk)->inflight.
* 1263b0b260 net/mlx5: Properly link new fs rules into the tree
* cca606e142 ipv6: fix race condition between ipv6_get_ifaddr and ipv6_del_addr
* 3af3f21d01 ipv4/route: avoid unused-but-set-variable warning
* e9f4cfe42f ipv6: fib: hide unused 'pn' variable
* d3adf11d79 geneve: fix header validation in geneve[6]_xmit_skb
* 2f75517633 u64_stats: fix u64_stats_init() for lockdep when used repeatedly in one file
* e7d818b8cc net: openvswitch: fix unwanted error log on timeout policy probing
* ccabbf1d9d nouveau: fix function cast warning
* 4beab84fbb Bluetooth: Fix memory leak in hci_req_sync_complete()
* b3ddf69040 batman-adv: Avoid infinite loop trying to resize local TT

Change-Id: Ic74fa9cbcfafb5458436712aba76731401e099a3
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-06-28 16:05:40 +00:00
Michal Luczaj
5727972f15 UPSTREAM: af_unix: Fix garbage collector racing against connect()
[ Upstream commit 47d8ac011fe1c9251070e1bd64cb10b48193ec51 ]

Garbage collector does not take into account the risk of embryo getting
enqueued during the garbage collection. If such embryo has a peer that
carries SCM_RIGHTS, two consecutive passes of scan_children() may see a
different set of children. Leading to an incorrectly elevated inflight
count, and then a dangling pointer within the gc_inflight_list.

sockets are AF_UNIX/SOCK_STREAM
S is an unconnected socket
L is a listening in-flight socket bound to addr, not in fdtable
V's fd will be passed via sendmsg(), gets inflight count bumped

connect(S, addr)	sendmsg(S, [V]); close(V)	__unix_gc()
----------------	-------------------------	-----------

NS = unix_create1()
skb1 = sock_wmalloc(NS)
L = unix_find_other(addr)
unix_state_lock(L)
unix_peer(S) = NS
			// V count=1 inflight=0

 			NS = unix_peer(S)
 			skb2 = sock_alloc()
			skb_queue_tail(NS, skb2[V])

			// V became in-flight
			// V count=2 inflight=1

			close(V)

			// V count=1 inflight=1
			// GC candidate condition met

						for u in gc_inflight_list:
						  if (total_refs == inflight_refs)
						    add u to gc_candidates

						// gc_candidates={L, V}

						for u in gc_candidates:
						  scan_children(u, dec_inflight)

						// embryo (skb1) was not
						// reachable from L yet, so V's
						// inflight remains unchanged
__skb_queue_tail(L, skb1)
unix_state_unlock(L)
						for u in gc_candidates:
						  if (u.inflight)
						    scan_children(u, inc_inflight_move_tail)

						// V count=1 inflight=2 (!)

If there is a GC-candidate listening socket, lock/unlock its state. This
makes GC wait until the end of any ongoing connect() to that socket. After
flipping the lock, a possibly SCM-laden embryo is already enqueued. And if
there is another embryo coming, it can not possibly carry SCM_RIGHTS. At
this point, unix_inflight() can not happen because unix_gc_lock is already
taken. Inflight graph remains unaffected.

Bug: 336226035
Fixes: 1fd05ba5a2 ("[AF_UNIX]: Rewrite garbage collector, fixes race.")
Signed-off-by: Michal Luczaj <mhal@rbox.co>
Reviewed-by: Kuniyuki Iwashima <kuniyu@amazon.com>
Link: https://lore.kernel.org/r/20240409201047.1032217-1-mhal@rbox.co
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Oleksiy Avramchenko <oleksiy.avramchenko@sony.com>
Change-Id: If321f78b8b3220f5a1caea4b5e9450f1235b0770
(cherry picked from commit 2e2a03787f4f0abc0072350654ab0ef3324d9db3)
Signed-off-by: Lee Jones <joneslee@google.com>
2024-06-28 14:45:04 +01:00
Greg Kroah-Hartman
06b018ca42 Revert "drm/panel: simple: Add missing Innolux G121X1-L03 format, flags, connector"
This reverts commit f5734138fb which is
commit 11ac72d033b9f577e8ba0c7a41d1c312bb232593 upstream.

It breaks the build, due to a previous abi change not being present in
the android kernel tree anymore and can be brought back in an abi-safe
way in the future if ever needed.

Bug: 161946584
Change-Id: I5739c83d45e0ec87f5dfe1e2f1d0c9e5982752e4
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-06-21 13:47:48 +00:00
Greg Kroah-Hartman
eb1a0358d1 This is the 5.4.278 stable release
-----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCAAdFiEEZH8oZUiU471FcZm+ONu9yGCSaT4FAmZuzHwACgkQONu9yGCS
 aT6M7xAAuCGja5JhZ7ciWjhdxIFxACHrSVm3l/i+bqNAXoDh2rJDKgOize1OTLGR
 R1Fq2qBEtfMsoKNa+3DyMCB8D1IsMUrhr8hdM56+AqDBbmaTsDmw+L6vzepwJKVV
 ksX2onT5tXdydH95IjqnM7vbadxnU9cLkHZIpckXkb2dDA2kjhMksWSfA+GJfRsY
 XReqFYfeQhLWv4c0OWZ//ssSmGWztSVaRCX22jemUJ5MYpQHt3TYQXVpFYkaQLYH
 FZHDxBFEr48Gt9bQtnBZ2fyurKX9NdzZF+WwNDuo0DShlEpJB99vYHQ/dIxzxl9R
 7VOs3Cj7vvUBSIRPY9DhuhBm7tQrpCvf4w3qUBc0TD+IdPPIIf0ZqDsVUvZGM9JE
 T54rnXppxNKlbW8HmYqefc2FBgjrZn08NprrAVqIVhNwFyq+8/ADqdSTTKlD9z1i
 S/3Pur7ES2e15YsrjOrDJIpGl3klMrEBbz9XyEHwrTY2vrDjdqOF0NHYUaugnjSd
 B+qmUtZxwSjzRok5wgQaf/EbrW78e9q1lTj97QRJfBr0A7MUpDMuQCvmsMoe2HUA
 vANx7ty/ubNk/9PLTGyBHUw4/F58Bk5osibAKRmulvlO5g80FsJXEU9WWqQmIkzp
 3df+cOL8ipqh0fg/PaUOBCoeVs2HqPHnewOlYRegN41FokQndsE=
 =XU0g
 -----END PGP SIGNATURE-----

Merge 5.4.278 into android11-5.4-lts

Changes in 5.4.278
	x86/tsc: Trust initial offset in architectural TSC-adjust MSRs
	tty: n_gsm: fix possible out-of-bounds in gsm0_receive()
	speakup: Fix sizeof() vs ARRAY_SIZE() bug
	ring-buffer: Fix a race between readers and resize checks
	net: smc91x: Fix m68k kernel compilation for ColdFire CPU
	nilfs2: fix unexpected freezing of nilfs_segctor_sync()
	nilfs2: fix potential hang in nilfs_detach_log_writer()
	wifi: cfg80211: fix the order of arguments for trace events of the tx_rx_evt class
	net: usb: qmi_wwan: add Telit FN920C04 compositions
	drm/amd/display: Set color_mgmt_changed to true on unsuspend
	ASoC: rt5645: Fix the electric noise due to the CBJ contacts floating
	ASoC: dt-bindings: rt5645: add cbj sleeve gpio property
	ASoC: da7219-aad: fix usage of device_get_named_child_node()
	drm/amdkfd: Flush the process wq before creating a kfd_process
	nvme: find numa distance only if controller has valid numa id
	openpromfs: finish conversion to the new mount API
	crypto: bcm - Fix pointer arithmetic
	firmware: raspberrypi: Use correct device for DMA mappings
	ecryptfs: Fix buffer size for tag 66 packet
	nilfs2: fix out-of-range warning
	parisc: add missing export of __cmpxchg_u8()
	crypto: ccp - drop platform ifdef checks
	s390/cio: fix tracepoint subchannel type field
	jffs2: prevent xattr node from overflowing the eraseblock
	null_blk: Fix missing mutex_destroy() at module removal
	md: fix resync softlockup when bitmap size is less than array size
	wifi: ath10k: poll service ready message before failing
	x86/boot: Ignore relocations in .notes sections in walk_relocs() too
	qed: avoid truncating work queue length
	scsi: ufs: qcom: Perform read back after writing reset bit
	scsi: ufs: cdns-pltfrm: Perform read back after writing HCLKDIV
	scsi: ufs: core: Perform read back after disabling interrupts
	scsi: ufs: core: Perform read back after disabling UIC_COMMAND_COMPL
	irqchip/alpine-msi: Fix off-by-one in allocation error path
	ACPI: disable -Wstringop-truncation
	cpufreq: Reorganize checks in cpufreq_offline()
	cpufreq: Split cpufreq_offline()
	cpufreq: Rearrange locking in cpufreq_remove_dev()
	cpufreq: exit() callback is optional
	scsi: libsas: Fix the failure of adding phy with zero-address to port
	scsi: hpsa: Fix allocation size for Scsi_Host private data
	x86/purgatory: Switch to the position-independent small code model
	wifi: ath10k: Fix an error code problem in ath10k_dbg_sta_write_peer_debug_trigger()
	wifi: ath10k: populate board data for WCN3990
	tcp: minor optimization in tcp_add_backlog()
	tcp: fix a signed-integer-overflow bug in tcp_add_backlog()
	tcp: avoid premature drops in tcp_add_backlog()
	macintosh/via-macii: Fix "BUG: sleeping function called from invalid context"
	wifi: carl9170: add a proper sanity check for endpoints
	wifi: ar5523: enable proper endpoint verification
	sh: kprobes: Merge arch_copy_kprobe() into arch_prepare_kprobe()
	Revert "sh: Handle calling csum_partial with misaligned data"
	HID: intel-ish-hid: ipc: Add check for pci_alloc_irq_vectors
	scsi: bfa: Ensure the copied buf is NUL terminated
	scsi: qedf: Ensure the copied buf is NUL terminated
	wifi: mwl8k: initialize cmd->addr[] properly
	usb: aqc111: stop lying about skb->truesize
	net: usb: sr9700: stop lying about skb->truesize
	m68k: Fix spinlock race in kernel thread creation
	m68k: mac: Fix reboot hang on Mac IIci
	net: ethernet: cortina: Locking fixes
	af_unix: Fix data races in unix_release_sock/unix_stream_sendmsg
	net: usb: smsc95xx: stop lying about skb->truesize
	net: openvswitch: fix overwriting ct original tuple for ICMPv6
	ipv6: sr: add missing seg6_local_exit
	ipv6: sr: fix incorrect unregister order
	ipv6: sr: fix invalid unregister error path
	drm/amd/display: Fix potential index out of bounds in color transformation function
	mtd: rawnand: hynix: fixed typo
	fbdev: shmobile: fix snprintf truncation
	drm/mediatek: Add 0 size check to mtk_drm_gem_obj
	powerpc/fsl-soc: hide unused const variable
	fbdev: sisfb: hide unused variables
	media: ngene: Add dvb_ca_en50221_init return value check
	media: radio-shark2: Avoid led_names truncations
	platform/x86: wmi: Make two functions static
	fbdev: sh7760fb: allow modular build
	drm/arm/malidp: fix a possible null pointer dereference
	ASoC: tracing: Export SND_SOC_DAPM_DIR_OUT to its value
	drm/panel: simple: Add missing Innolux G121X1-L03 format, flags, connector
	RDMA/hns: Use complete parentheses in macros
	x86/insn: Fix PUSH instruction in x86 instruction decoder opcode map
	ext4: avoid excessive credit estimate in ext4_tmpfile()
	sunrpc: removed redundant procp check
	SUNRPC: Fix gss_free_in_token_pages()
	selftests/kcmp: Make the test output consistent and clear
	selftests/kcmp: remove unused open mode
	RDMA/IPoIB: Fix format truncation compilation errors
	netrom: fix possible dead-lock in nr_rt_ioctl()
	af_packet: do not call packet_read_pending() from tpacket_destruct_skb()
	sched/topology: Don't set SD_BALANCE_WAKE on cpuset domain relax
	sched/fair: Allow disabling sched_balance_newidle with sched_relax_domain_level
	greybus: lights: check return of get_channel_from_mode
	soundwire: cadence/intel: simplify PDI/port mapping
	soundwire: intel: don't filter out PDI0/1
	soundwire: cadence_master: improve PDI allocation
	soundwire: cadence: fix invalid PDI offset
	dmaengine: idma64: Add check for dma_set_max_seg_size
	firmware: dmi-id: add a release callback function
	serial: max3100: Lock port->lock when calling uart_handle_cts_change()
	serial: max3100: Update uart_driver_registered on driver removal
	serial: max3100: Fix bitwise types
	greybus: arche-ctrl: move device table to its right location
	iio: pressure: dps310: support negative temperature values
	microblaze: Remove gcc flag for non existing early_printk.c file
	microblaze: Remove early printk call from cpuinfo-static.c
	usb: gadget: u_audio: Clear uac pointer when freed.
	stm class: Fix a double free in stm_register_device()
	ppdev: Remove usage of the deprecated ida_simple_xx() API
	ppdev: Add an error check in register_device
	extcon: max8997: select IRQ_DOMAIN instead of depending on it
	f2fs: fix to release node block count in error path of f2fs_new_node_page()
	serial: sh-sci: protect invalidating RXDMA on shutdown
	libsubcmd: Fix parse-options memory leak
	Input: ims-pcu - fix printf string overflow
	Input: pm8xxx-vibrator - correct VIB_MAX_LEVELS calculation
	drm/msm/dpu: Always flush the slave INTF on the CTL
	um: Fix return value in ubd_init()
	um: Add winch to winch_handlers before registering winch IRQ
	media: stk1160: fix bounds checking in stk1160_copy_video()
	scsi: qla2xxx: Replace all non-returning strlcpy() with strscpy()
	powerpc/pseries: Add failure related checks for h_get_mpp and h_get_ppp
	um: Fix the -Wmissing-prototypes warning for __switch_mm
	media: cec: cec-adap: always cancel work in cec_transmit_msg_fh
	media: cec: cec-api: add locking in cec_release()
	null_blk: Fix the WARNING: modpost: missing MODULE_DESCRIPTION()
	x86/kconfig: Select ARCH_WANT_FRAME_POINTERS again when UNWINDER_FRAME_POINTER=y
	nfc: nci: Fix uninit-value in nci_rx_work
	sunrpc: fix NFSACL RPC retry on soft mount
	ipv6: sr: fix memleak in seg6_hmac_init_algo
	params: lift param_set_uint_minmax to common code
	tcp: Fix shift-out-of-bounds in dctcp_update_alpha().
	openvswitch: Set the skbuff pkt_type for proper pmtud support.
	arm64: asm-bug: Add .align 2 to the end of __BUG_ENTRY
	virtio: delete vq in vp_find_vqs_msix() when request_irq() fails
	net: fec: avoid lock evasion when reading pps_enable
	nfc: nci: Fix kcov check in nci_rx_work()
	nfc: nci: Fix handling of zero-length payload packets in nci_rx_work()
	netfilter: nfnetlink_queue: acquire rcu_read_lock() in instance_destroy_rcu()
	spi: Don't mark message DMA mapped when no transfer in it is
	nvmet: fix ns enable/disable possible hang
	net/mlx5e: Use rx_missed_errors instead of rx_dropped for reporting buffer exhaustion
	dma-buf/sw-sync: don't enable IRQ from sync_print_obj()
	enic: Validate length of nl attributes in enic_set_vf_port
	smsc95xx: remove redundant function arguments
	smsc95xx: use usbnet->driver_priv
	net: usb: smsc95xx: fix changing LED_SEL bit value updated from EEPROM
	net:fec: Add fec_enet_deinit()
	netfilter: tproxy: bail out if IP has been disabled on the device
	kconfig: fix comparison to constant symbols, 'm', 'n'
	spi: stm32: Don't warn about spurious interrupts
	ipvlan: Dont Use skb->sk in ipvlan_process_v{4,6}_outbound
	ALSA: timer: Set lower bound of start tick time
	genirq/cpuhotplug, x86/vector: Prevent vector leak during CPU offline
	SUNRPC: Fix loop termination condition in gss_free_in_token_pages()
	binder: fix max_thread type inconsistency
	mmc: core: Do not force a retune before RPMB switch
	io_uring: fail NOP if non-zero op flags is passed in
	afs: Don't cross .backup mountpoint from backup volume
	nilfs2: fix use-after-free of timer for log writer thread
	vxlan: Fix regression when dropping packets due to invalid src addresses
	x86/mm: Remove broken vsyscall emulation code from the page fault code
	f2fs: fix to do sanity check on i_xattr_nid in sanity_check_inode()
	media: lgdt3306a: Add a check against null-pointer-def
	drm/amdgpu: add error handle to avoid out-of-bounds
	ata: pata_legacy: make legacy_exit() work again
	ACPI: resource: Do IRQ override on TongFang GXxHRXx and GMxHGxx
	arm64: tegra: Correct Tegra132 I2C alias
	md/raid5: fix deadlock that raid5d() wait for itself to clear MD_SB_CHANGE_PENDING
	wifi: rtl8xxxu: Fix the TX power of RTL8192CU, RTL8723AU
	arm64: dts: hi3798cv200: fix the size of GICR
	media: mc: mark the media devnode as registered from the, start
	media: mxl5xx: Move xpt structures off stack
	media: v4l2-core: hold videodev_lock until dev reg, finishes
	fbdev: savage: Handle err return when savagefb_check_var failed
	KVM: arm64: Allow AArch32 PSTATE.M to be restored as System mode
	crypto: ecrdsa - Fix module auto-load on add_key
	crypto: qat - Fix ADF_DEV_RESET_SYNC memory leak
	net/ipv6: Fix route deleting failure when metric equals 0
	net/9p: fix uninit-value in p9_client_rpc()
	intel_th: pci: Add Meteor Lake-S CPU support
	sparc64: Fix number of online CPUs
	kdb: Fix buffer overflow during tab-complete
	kdb: Use format-strings rather than '\0' injection in kdb_read()
	kdb: Fix console handling when editing and tab-completing commands
	kdb: Merge identical case statements in kdb_read()
	kdb: Use format-specifiers rather than memset() for padding in kdb_read()
	net: fix __dst_negative_advice() race
	xsk: validate user input for XDP_{UMEM|COMPLETION}_FILL_RING
	sparc: move struct termio to asm/termios.h
	ext4: fix mb_cache_entry's e_refcnt leak in ext4_xattr_block_cache_find()
	s390/ap: Fix crash in AP internal function modify_bitmap()
	nfs: fix undefined behavior in nfs_block_bits()
	Linux 5.4.278

Change-Id: I0cdcfac77f01b25b5790752b68d92f1eafaa9ddd
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-06-18 14:18:49 +00:00
Greg Kroah-Hartman
5c67c52b0d Merge branch 'android11-5.4' into branch 'android11-5.4-lts'
This catches the android11-5.4-lts branch up with recent changes made in
the android11-5.4 branch.  Changes included in here are:

* 564901bd7f ANDROID: 16K: Only check basename of linker context
* 73b793dd7d UPSTREAM: af_unix: Do not use atomic ops for unix_sk(sk)->inflight.
* ff29a6cf6e ANDROID: ABI fixup for abi break in struct dst_ops
* 8b6880fcb8 BACKPORT: net: fix __dst_negative_advice() race

Change-Id: I7fa20e52026e7bf98e973e632d9cedead8fb0aaf
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-06-18 07:28:30 +00:00
Greg Kroah-Hartman
189ee9735a Linux 5.4.278
Link: https://lore.kernel.org/r/20240613113227.759341286@linuxfoundation.org
Tested-by: Jon Hunter <jonathanh@nvidia.com>
Tested-by: Shuah Khan <skhan@linuxfoundation.org>
Tested-by: Linux Kernel Functional Testing <lkft@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-06-16 13:28:53 +02:00
Sergey Shtylyov
2997e2fb1c nfs: fix undefined behavior in nfs_block_bits()
commit 3c0a2e0b0ae661457c8505fecc7be5501aa7a715 upstream.

Shifting *signed int* typed constant 1 left by 31 bits causes undefined
behavior. Specify the correct *unsigned long* type by using 1UL instead.

Found by Linux Verification Center (linuxtesting.org) with the Svace static
analysis tool.

Cc: stable@vger.kernel.org
Signed-off-by: Sergey Shtylyov <s.shtylyov@omp.ru>
Reviewed-by: Benjamin Coddington <bcodding@redhat.com>
Signed-off-by: Trond Myklebust <trond.myklebust@hammerspace.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-06-16 13:28:52 +02:00
Harald Freudenberger
7c72af16ab s390/ap: Fix crash in AP internal function modify_bitmap()
commit d4f9d5a99a3fd1b1c691b7a1a6f8f3f25f4116c9 upstream.

A system crash like this

  Failing address: 200000cb7df6f000 TEID: 200000cb7df6f403
  Fault in home space mode while using kernel ASCE.
  AS:00000002d71bc007 R3:00000003fe5b8007 S:000000011a446000 P:000000015660c13d
  Oops: 0038 ilc:3 [#1] PREEMPT SMP
  Modules linked in: mlx5_ib ...
  CPU: 8 PID: 7556 Comm: bash Not tainted 6.9.0-rc7 #8
  Hardware name: IBM 3931 A01 704 (LPAR)
  Krnl PSW : 0704e00180000000 0000014b75e7b606 (ap_parse_bitmap_str+0x10e/0x1f8)
  R:0 T:1 IO:1 EX:1 Key:0 M:1 W:0 P:0 AS:3 CC:2 PM:0 RI:0 EA:3
  Krnl GPRS: 0000000000000001 ffffffffffffffc0 0000000000000001 00000048f96b75d3
  000000cb00000100 ffffffffffffffff ffffffffffffffff 000000cb7df6fce0
  000000cb7df6fce0 00000000ffffffff 000000000000002b 00000048ffffffff
  000003ff9b2dbc80 200000cb7df6fcd8 0000014bffffffc0 000000cb7df6fbc8
  Krnl Code: 0000014b75e7b5fc: a7840047            brc     8,0000014b75e7b68a
  0000014b75e7b600: 18b2                lr      %r11,%r2
  #0000014b75e7b602: a7f4000a            brc     15,0000014b75e7b616
  >0000014b75e7b606: eb22d00000e6        laog    %r2,%r2,0(%r13)
  0000014b75e7b60c: a7680001            lhi     %r6,1
  0000014b75e7b610: 187b                lr      %r7,%r11
  0000014b75e7b612: 84960021            brxh    %r9,%r6,0000014b75e7b654
  0000014b75e7b616: 18e9                lr      %r14,%r9
  Call Trace:
  [<0000014b75e7b606>] ap_parse_bitmap_str+0x10e/0x1f8
  ([<0000014b75e7b5dc>] ap_parse_bitmap_str+0xe4/0x1f8)
  [<0000014b75e7b758>] apmask_store+0x68/0x140
  [<0000014b75679196>] kernfs_fop_write_iter+0x14e/0x1e8
  [<0000014b75598524>] vfs_write+0x1b4/0x448
  [<0000014b7559894c>] ksys_write+0x74/0x100
  [<0000014b7618a440>] __do_syscall+0x268/0x328
  [<0000014b761a3558>] system_call+0x70/0x98
  INFO: lockdep is turned off.
  Last Breaking-Event-Address:
  [<0000014b75e7b636>] ap_parse_bitmap_str+0x13e/0x1f8
  Kernel panic - not syncing: Fatal exception: panic_on_oops

occured when /sys/bus/ap/a[pq]mask was updated with a relative mask value
(like +0x10-0x12,+60,-90) with one of the numeric values exceeding INT_MAX.

The fix is simple: use unsigned long values for the internal variables. The
correct checks are already in place in the function but a simple int for
the internal variables was used with the possibility to overflow.

Reported-by: Marc Hartmayer <mhartmay@linux.ibm.com>
Signed-off-by: Harald Freudenberger <freude@linux.ibm.com>
Tested-by: Marc Hartmayer <mhartmay@linux.ibm.com>
Reviewed-by: Holger Dengler <dengler@linux.ibm.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Heiko Carstens <hca@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-06-16 13:28:52 +02:00
Baokun Li
896a7e7d0d ext4: fix mb_cache_entry's e_refcnt leak in ext4_xattr_block_cache_find()
commit 0c0b4a49d3e7f49690a6827a41faeffad5df7e21 upstream.

Syzbot reports a warning as follows:

============================================
WARNING: CPU: 0 PID: 5075 at fs/mbcache.c:419 mb_cache_destroy+0x224/0x290
Modules linked in:
CPU: 0 PID: 5075 Comm: syz-executor199 Not tainted 6.9.0-rc6-gb947cc5bf6d7
RIP: 0010:mb_cache_destroy+0x224/0x290 fs/mbcache.c:419
Call Trace:
 <TASK>
 ext4_put_super+0x6d4/0xcd0 fs/ext4/super.c:1375
 generic_shutdown_super+0x136/0x2d0 fs/super.c:641
 kill_block_super+0x44/0x90 fs/super.c:1675
 ext4_kill_sb+0x68/0xa0 fs/ext4/super.c:7327
[...]
============================================

This is because when finding an entry in ext4_xattr_block_cache_find(), if
ext4_sb_bread() returns -ENOMEM, the ce's e_refcnt, which has already grown
in the __entry_find(), won't be put away, and eventually trigger the above
issue in mb_cache_destroy() due to reference count leakage.

So call mb_cache_entry_put() on the -ENOMEM error branch as a quick fix.

Reported-by: syzbot+dd43bd0f7474512edc47@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=dd43bd0f7474512edc47
Fixes: fb265c9cb4 ("ext4: add ext4_sb_bread() to disambiguate ENOMEM cases")
Cc: stable@kernel.org
Signed-off-by: Baokun Li <libaokun1@huawei.com>
Reviewed-by: Jan Kara <jack@suse.cz>
Link: https://lore.kernel.org/r/20240504075526.2254349-2-libaokun@huaweicloud.com
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-06-16 13:28:52 +02:00
Mike Gilbert
95572c6b8e sparc: move struct termio to asm/termios.h
commit c32d18e7942d7589b62e301eb426b32623366565 upstream.

Every other arch declares struct termio in asm/termios.h, so make sparc
match them.

Resolves a build failure in the PPP software package, which includes
both bits/ioctl-types.h via sys/ioctl.h (glibc) and asm/termbits.h.

Closes: https://bugs.gentoo.org/918992
Signed-off-by: Mike Gilbert <floppym@gentoo.org>
Cc: stable@vger.kernel.org
Reviewed-by: Andreas Larsson <andreas@gaisler.com>
Tested-by: Andreas Larsson <andreas@gaisler.com>
Link: https://lore.kernel.org/r/20240306171149.3843481-1-floppym@gentoo.org
Signed-off-by: Andreas Larsson <andreas@gaisler.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-06-16 13:28:52 +02:00
Eric Dumazet
0b45c25d60 xsk: validate user input for XDP_{UMEM|COMPLETION}_FILL_RING
commit 237f3cf13b20db183d3706d997eedc3c49eacd44 upstream.

syzbot reported an illegal copy in xsk_setsockopt() [1]

Make sure to validate setsockopt() @optlen parameter.

[1]

 BUG: KASAN: slab-out-of-bounds in copy_from_sockptr_offset include/linux/sockptr.h:49 [inline]
 BUG: KASAN: slab-out-of-bounds in copy_from_sockptr include/linux/sockptr.h:55 [inline]
 BUG: KASAN: slab-out-of-bounds in xsk_setsockopt+0x909/0xa40 net/xdp/xsk.c:1420
Read of size 4 at addr ffff888028c6cde3 by task syz-executor.0/7549

CPU: 0 PID: 7549 Comm: syz-executor.0 Not tainted 6.8.0-syzkaller-08951-gfe46a7dd189e #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/27/2024
Call Trace:
 <TASK>
  __dump_stack lib/dump_stack.c:88 [inline]
  dump_stack_lvl+0x241/0x360 lib/dump_stack.c:114
  print_address_description mm/kasan/report.c:377 [inline]
  print_report+0x169/0x550 mm/kasan/report.c:488
  kasan_report+0x143/0x180 mm/kasan/report.c:601
  copy_from_sockptr_offset include/linux/sockptr.h:49 [inline]
  copy_from_sockptr include/linux/sockptr.h:55 [inline]
  xsk_setsockopt+0x909/0xa40 net/xdp/xsk.c:1420
  do_sock_setsockopt+0x3af/0x720 net/socket.c:2311
  __sys_setsockopt+0x1ae/0x250 net/socket.c:2334
  __do_sys_setsockopt net/socket.c:2343 [inline]
  __se_sys_setsockopt net/socket.c:2340 [inline]
  __x64_sys_setsockopt+0xb5/0xd0 net/socket.c:2340
 do_syscall_64+0xfb/0x240
 entry_SYSCALL_64_after_hwframe+0x6d/0x75
RIP: 0033:0x7fb40587de69
Code: 28 00 00 00 75 05 48 83 c4 28 c3 e8 e1 20 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b0 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007fb40665a0c8 EFLAGS: 00000246 ORIG_RAX: 0000000000000036
RAX: ffffffffffffffda RBX: 00007fb4059abf80 RCX: 00007fb40587de69
RDX: 0000000000000005 RSI: 000000000000011b RDI: 0000000000000006
RBP: 00007fb4058ca47a R08: 0000000000000002 R09: 0000000000000000
R10: 0000000020001980 R11: 0000000000000246 R12: 0000000000000000
R13: 000000000000000b R14: 00007fb4059abf80 R15: 00007fff57ee4d08
 </TASK>

Allocated by task 7549:
  kasan_save_stack mm/kasan/common.c:47 [inline]
  kasan_save_track+0x3f/0x80 mm/kasan/common.c:68
  poison_kmalloc_redzone mm/kasan/common.c:370 [inline]
  __kasan_kmalloc+0x98/0xb0 mm/kasan/common.c:387
  kasan_kmalloc include/linux/kasan.h:211 [inline]
  __do_kmalloc_node mm/slub.c:3966 [inline]
  __kmalloc+0x233/0x4a0 mm/slub.c:3979
  kmalloc include/linux/slab.h:632 [inline]
  __cgroup_bpf_run_filter_setsockopt+0xd2f/0x1040 kernel/bpf/cgroup.c:1869
  do_sock_setsockopt+0x6b4/0x720 net/socket.c:2293
  __sys_setsockopt+0x1ae/0x250 net/socket.c:2334
  __do_sys_setsockopt net/socket.c:2343 [inline]
  __se_sys_setsockopt net/socket.c:2340 [inline]
  __x64_sys_setsockopt+0xb5/0xd0 net/socket.c:2340
 do_syscall_64+0xfb/0x240
 entry_SYSCALL_64_after_hwframe+0x6d/0x75

The buggy address belongs to the object at ffff888028c6cde0
 which belongs to the cache kmalloc-8 of size 8
The buggy address is located 1 bytes to the right of
 allocated 2-byte region [ffff888028c6cde0, ffff888028c6cde2)

The buggy address belongs to the physical page:
page:ffffea0000a31b00 refcount:1 mapcount:0 mapping:0000000000000000 index:0xffff888028c6c9c0 pfn:0x28c6c
anon flags: 0xfff00000000800(slab|node=0|zone=1|lastcpupid=0x7ff)
page_type: 0xffffffff()
raw: 00fff00000000800 ffff888014c41280 0000000000000000 dead000000000001
raw: ffff888028c6c9c0 0000000080800057 00000001ffffffff 0000000000000000
page dumped because: kasan: bad access detected
page_owner tracks the page as allocated
page last allocated via order 0, migratetype Unmovable, gfp_mask 0x112cc0(GFP_USER|__GFP_NOWARN|__GFP_NORETRY), pid 6648, tgid 6644 (syz-executor.0), ts 133906047828, free_ts 133859922223
  set_page_owner include/linux/page_owner.h:31 [inline]
  post_alloc_hook+0x1ea/0x210 mm/page_alloc.c:1533
  prep_new_page mm/page_alloc.c:1540 [inline]
  get_page_from_freelist+0x33ea/0x3580 mm/page_alloc.c:3311
  __alloc_pages+0x256/0x680 mm/page_alloc.c:4569
  __alloc_pages_node include/linux/gfp.h:238 [inline]
  alloc_pages_node include/linux/gfp.h:261 [inline]
  alloc_slab_page+0x5f/0x160 mm/slub.c:2175
  allocate_slab mm/slub.c:2338 [inline]
  new_slab+0x84/0x2f0 mm/slub.c:2391
  ___slab_alloc+0xc73/0x1260 mm/slub.c:3525
  __slab_alloc mm/slub.c:3610 [inline]
  __slab_alloc_node mm/slub.c:3663 [inline]
  slab_alloc_node mm/slub.c:3835 [inline]
  __do_kmalloc_node mm/slub.c:3965 [inline]
  __kmalloc_node+0x2db/0x4e0 mm/slub.c:3973
  kmalloc_node include/linux/slab.h:648 [inline]
  __vmalloc_area_node mm/vmalloc.c:3197 [inline]
  __vmalloc_node_range+0x5f9/0x14a0 mm/vmalloc.c:3392
  __vmalloc_node mm/vmalloc.c:3457 [inline]
  vzalloc+0x79/0x90 mm/vmalloc.c:3530
  bpf_check+0x260/0x19010 kernel/bpf/verifier.c:21162
  bpf_prog_load+0x1667/0x20f0 kernel/bpf/syscall.c:2895
  __sys_bpf+0x4ee/0x810 kernel/bpf/syscall.c:5631
  __do_sys_bpf kernel/bpf/syscall.c:5738 [inline]
  __se_sys_bpf kernel/bpf/syscall.c:5736 [inline]
  __x64_sys_bpf+0x7c/0x90 kernel/bpf/syscall.c:5736
 do_syscall_64+0xfb/0x240
 entry_SYSCALL_64_after_hwframe+0x6d/0x75
page last free pid 6650 tgid 6647 stack trace:
  reset_page_owner include/linux/page_owner.h:24 [inline]
  free_pages_prepare mm/page_alloc.c:1140 [inline]
  free_unref_page_prepare+0x95d/0xa80 mm/page_alloc.c:2346
  free_unref_page_list+0x5a3/0x850 mm/page_alloc.c:2532
  release_pages+0x2117/0x2400 mm/swap.c:1042
  tlb_batch_pages_flush mm/mmu_gather.c:98 [inline]
  tlb_flush_mmu_free mm/mmu_gather.c:293 [inline]
  tlb_flush_mmu+0x34d/0x4e0 mm/mmu_gather.c:300
  tlb_finish_mmu+0xd4/0x200 mm/mmu_gather.c:392
  exit_mmap+0x4b6/0xd40 mm/mmap.c:3300
  __mmput+0x115/0x3c0 kernel/fork.c:1345
  exit_mm+0x220/0x310 kernel/exit.c:569
  do_exit+0x99e/0x27e0 kernel/exit.c:865
  do_group_exit+0x207/0x2c0 kernel/exit.c:1027
  get_signal+0x176e/0x1850 kernel/signal.c:2907
  arch_do_signal_or_restart+0x96/0x860 arch/x86/kernel/signal.c:310
  exit_to_user_mode_loop kernel/entry/common.c:105 [inline]
  exit_to_user_mode_prepare include/linux/entry-common.h:328 [inline]
  __syscall_exit_to_user_mode_work kernel/entry/common.c:201 [inline]
  syscall_exit_to_user_mode+0xc9/0x360 kernel/entry/common.c:212
  do_syscall_64+0x10a/0x240 arch/x86/entry/common.c:89
 entry_SYSCALL_64_after_hwframe+0x6d/0x75

Memory state around the buggy address:
 ffff888028c6cc80: fa fc fc fc fa fc fc fc fa fc fc fc fa fc fc fc
 ffff888028c6cd00: fa fc fc fc fa fc fc fc 00 fc fc fc 06 fc fc fc
>ffff888028c6cd80: fa fc fc fc fa fc fc fc fa fc fc fc 02 fc fc fc
                                                       ^
 ffff888028c6ce00: fa fc fc fc fa fc fc fc fa fc fc fc fa fc fc fc
 ffff888028c6ce80: fa fc fc fc fa fc fc fc fa fc fc fc fa fc fc fc

Fixes: 423f38329d ("xsk: add umem fill queue support and mmap")
Reported-by: syzbot <syzkaller@googlegroups.com>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: "Björn Töpel" <bjorn@kernel.org>
Cc: Magnus Karlsson <magnus.karlsson@intel.com>
Cc: Maciej Fijalkowski <maciej.fijalkowski@intel.com>
Cc: Jonathan Lemon <jonathan.lemon@gmail.com>
Acked-by: Daniel Borkmann <daniel@iogearbox.net>
Link: https://lore.kernel.org/r/20240404202738.3634547-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
[shung-hsi.yu:  copy_from_sockptr() in the context was replaced with
copy_from_usr() because commit a7b75c5a8c414
("net: pass a sockptr_t into ->setsockopt") was not present]
Signed-off-by: Shung-Hsi Yu <shung-hsi.yu@suse.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-06-16 13:28:52 +02:00
Eric Dumazet
db00828250 net: fix __dst_negative_advice() race
commit 92f1655aa2b2294d0b49925f3b875a634bd3b59e upstream.

__dst_negative_advice() does not enforce proper RCU rules when
sk->dst_cache must be cleared, leading to possible UAF.

RCU rules are that we must first clear sk->sk_dst_cache,
then call dst_release(old_dst).

Note that sk_dst_reset(sk) is implementing this protocol correctly,
while __dst_negative_advice() uses the wrong order.

Given that ip6_negative_advice() has special logic
against RTF_CACHE, this means each of the three ->negative_advice()
existing methods must perform the sk_dst_reset() themselves.

Note the check against NULL dst is centralized in
__dst_negative_advice(), there is no need to duplicate
it in various callbacks.

Many thanks to Clement Lecigne for tracking this issue.

This old bug became visible after the blamed commit, using UDP sockets.

Fixes: a87cb3e48e ("net: Facility to report route quality of connected sockets")
Reported-by: Clement Lecigne <clecigne@google.com>
Diagnosed-by: Clement Lecigne <clecigne@google.com>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Tom Herbert <tom@herbertland.com>
Reviewed-by: David Ahern <dsahern@kernel.org>
Link: https://lore.kernel.org/r/20240528114353.1794151-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
[Lee: Stable backport]
Signed-off-by: Lee Jones <lee@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-06-16 13:28:52 +02:00
Daniel Thompson
6b84387afe kdb: Use format-specifiers rather than memset() for padding in kdb_read()
commit c9b51ddb66b1d96e4d364c088da0f1dfb004c574 upstream.

Currently when the current line should be removed from the display
kdb_read() uses memset() to fill a temporary buffer with spaces.
The problem is not that this could be trivially implemented using a
format string rather than open coding it. The real problem is that
it is possible, on systems with a long kdb_prompt_str, to write past
the end of the tmpbuffer.

Happily, as mentioned above, this can be trivially implemented using a
format string. Make it so!

Cc: stable@vger.kernel.org
Reviewed-by: Douglas Anderson <dianders@chromium.org>
Tested-by: Justin Stitt <justinstitt@google.com>
Link: https://lore.kernel.org/r/20240424-kgdb_read_refactor-v3-5-f236dbe9828d@linaro.org
Signed-off-by: Daniel Thompson <daniel.thompson@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-06-16 13:28:52 +02:00
Daniel Thompson
147bac05f2 kdb: Merge identical case statements in kdb_read()
commit 6244917f377bf64719551b58592a02a0336a7439 upstream.

The code that handles case 14 (down) and case 16 (up) has been copy and
pasted despite being byte-for-byte identical. Combine them.

Cc: stable@vger.kernel.org # Not a bug fix but it is needed for later bug fixes
Reviewed-by: Douglas Anderson <dianders@chromium.org>
Tested-by: Justin Stitt <justinstitt@google.com>
Link: https://lore.kernel.org/r/20240424-kgdb_read_refactor-v3-4-f236dbe9828d@linaro.org
Signed-off-by: Daniel Thompson <daniel.thompson@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-06-16 13:28:52 +02:00
Daniel Thompson
084e84ede9 kdb: Fix console handling when editing and tab-completing commands
commit db2f9c7dc29114f531df4a425d0867d01e1f1e28 upstream.

Currently, if the cursor position is not at the end of the command buffer
and the user uses the Tab-complete functions, then the console does not
leave the cursor in the correct position.

For example consider the following buffer with the cursor positioned
at the ^:

md kdb_pro 10
          ^

Pressing tab should result in:

md kdb_prompt_str 10
                 ^

However this does not happen. Instead the cursor is placed at the end
(after then 10) and further cursor movement redraws incorrectly. The
same problem exists when we double-Tab but in a different part of the
code.

Fix this by sending a carriage return and then redisplaying the text to
the left of the cursor.

Cc: stable@vger.kernel.org
Reviewed-by: Douglas Anderson <dianders@chromium.org>
Tested-by: Justin Stitt <justinstitt@google.com>
Link: https://lore.kernel.org/r/20240424-kgdb_read_refactor-v3-3-f236dbe9828d@linaro.org
Signed-off-by: Daniel Thompson <daniel.thompson@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-06-16 13:28:52 +02:00
Daniel Thompson
6a3836f29b kdb: Use format-strings rather than '\0' injection in kdb_read()
commit 09b35989421dfd5573f0b4683c7700a7483c71f9 upstream.

Currently when kdb_read() needs to reposition the cursor it uses copy and
paste code that works by injecting an '\0' at the cursor position before
delivering a carriage-return and reprinting the line (which stops at the
'\0').

Tidy up the code by hoisting the copy and paste code into an appropriately
named function. Additionally let's replace the '\0' injection with a
proper field width parameter so that the string will be abridged during
formatting instead.

Cc: stable@vger.kernel.org # Not a bug fix but it is needed for later bug fixes
Tested-by: Justin Stitt <justinstitt@google.com>
Reviewed-by: Douglas Anderson <dianders@chromium.org>
Link: https://lore.kernel.org/r/20240424-kgdb_read_refactor-v3-2-f236dbe9828d@linaro.org
Signed-off-by: Daniel Thompson <daniel.thompson@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-06-16 13:28:51 +02:00
Daniel Thompson
ddd2972d8e kdb: Fix buffer overflow during tab-complete
commit e9730744bf3af04cda23799029342aa3cddbc454 upstream.

Currently, when the user attempts symbol completion with the Tab key, kdb
will use strncpy() to insert the completed symbol into the command buffer.
Unfortunately it passes the size of the source buffer rather than the
destination to strncpy() with predictably horrible results. Most obviously
if the command buffer is already full but cp, the cursor position, is in
the middle of the buffer, then we will write past the end of the supplied
buffer.

Fix this by replacing the dubious strncpy() calls with memmove()/memcpy()
calls plus explicit boundary checks to make sure we have enough space
before we start moving characters around.

Reported-by: Justin Stitt <justinstitt@google.com>
Closes: https://lore.kernel.org/all/CAFhGd8qESuuifuHsNjFPR-Va3P80bxrw+LqvC8deA8GziUJLpw@mail.gmail.com/
Cc: stable@vger.kernel.org
Reviewed-by: Douglas Anderson <dianders@chromium.org>
Reviewed-by: Justin Stitt <justinstitt@google.com>
Tested-by: Justin Stitt <justinstitt@google.com>
Link: https://lore.kernel.org/r/20240424-kgdb_read_refactor-v3-1-f236dbe9828d@linaro.org
Signed-off-by: Daniel Thompson <daniel.thompson@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-06-16 13:28:51 +02:00
Sam Ravnborg
2098b237ba sparc64: Fix number of online CPUs
commit 98937707fea8375e8acea0aaa0b68a956dd52719 upstream.

Nick Bowler reported:
    When using newer kernels on my Ultra 60 with dual 450MHz UltraSPARC-II
    CPUs, I noticed that only CPU 0 comes up, while older kernels (including
    4.7) are working fine with both CPUs.

      I bisected the failure to this commit:

      9b2f753ec2 is the first bad commit
      commit 9b2f753ec2
      Author: Atish Patra <atish.patra@oracle.com>
      Date:   Thu Sep 15 14:54:40 2016 -0600

      sparc64: Fix cpu_possible_mask if nr_cpus is set

    This is a small change that reverts very easily on top of 5.18: there is
    just one trivial conflict.  Once reverted, both CPUs work again.

    Maybe this is related to the fact that the CPUs on this system are
    numbered CPU0 and CPU2 (there is no CPU1)?

The current code that adjust cpu_possible based on nr_cpu_ids do not
take into account that CPU's may not come one after each other.
Move the chech to the function that setup the cpu_possible mask
so there is no need to adjust it later.

Signed-off-by: Sam Ravnborg <sam@ravnborg.org>
Fixes: 9b2f753ec2 ("sparc64: Fix cpu_possible_mask if nr_cpus is set")
Reported-by: Nick Bowler <nbowler@draconx.ca>
Tested-by: Nick Bowler <nbowler@draconx.ca>
Link: https://lore.kernel.org/sparclinux/20201009161924.c8f031c079dd852941307870@gmx.de/
Link: https://lore.kernel.org/all/CADyTPEwt=ZNams+1bpMB1F9w_vUdPsGCt92DBQxxq_VtaLoTdw@mail.gmail.com/
Cc: stable@vger.kernel.org # v4.8+
Cc: Andreas Larsson <andreas@gaisler.com>
Cc: David S. Miller <davem@davemloft.net>
Cc: Atish Patra <atish.patra@oracle.com>
Cc: Bob Picco <bob.picco@oracle.com>
Cc: Vijay Kumar <vijay.ac.kumar@oracle.com>
Cc: David S. Miller <davem@davemloft.net>
Reviewed-by: Andreas Larsson <andreas@gaisler.com>
Acked-by: Arnd Bergmann <arnd@arndb.de>
Link: https://lore.kernel.org/r/20240330-sparc64-warnings-v1-9-37201023ee2f@ravnborg.org
Signed-off-by: Andreas Larsson <andreas@gaisler.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-06-16 13:28:51 +02:00
Alexander Shishkin
68682329fc intel_th: pci: Add Meteor Lake-S CPU support
commit a4f813c3ec9d1c32bc402becd1f011b3904dd699 upstream.

Add support for the Trace Hub in Meteor Lake-S CPU.

Signed-off-by: Alexander Shishkin <alexander.shishkin@linux.intel.com>
Reviewed-by: Andy Shevchenko <andriy.shevchenko@linux.intel.com>
Cc: stable@kernel.org
Link: https://lore.kernel.org/r/20240429130119.1518073-15-alexander.shishkin@linux.intel.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-06-16 13:28:51 +02:00
Nikita Zhandarovich
2101901dd5 net/9p: fix uninit-value in p9_client_rpc()
commit 25460d6f39024cc3b8241b14c7ccf0d6f11a736a upstream.

Syzbot with the help of KMSAN reported the following error:

BUG: KMSAN: uninit-value in trace_9p_client_res include/trace/events/9p.h:146 [inline]
BUG: KMSAN: uninit-value in p9_client_rpc+0x1314/0x1340 net/9p/client.c:754
 trace_9p_client_res include/trace/events/9p.h:146 [inline]
 p9_client_rpc+0x1314/0x1340 net/9p/client.c:754
 p9_client_create+0x1551/0x1ff0 net/9p/client.c:1031
 v9fs_session_init+0x1b9/0x28e0 fs/9p/v9fs.c:410
 v9fs_mount+0xe2/0x12b0 fs/9p/vfs_super.c:122
 legacy_get_tree+0x114/0x290 fs/fs_context.c:662
 vfs_get_tree+0xa7/0x570 fs/super.c:1797
 do_new_mount+0x71f/0x15e0 fs/namespace.c:3352
 path_mount+0x742/0x1f20 fs/namespace.c:3679
 do_mount fs/namespace.c:3692 [inline]
 __do_sys_mount fs/namespace.c:3898 [inline]
 __se_sys_mount+0x725/0x810 fs/namespace.c:3875
 __x64_sys_mount+0xe4/0x150 fs/namespace.c:3875
 do_syscall_64+0xd5/0x1f0
 entry_SYSCALL_64_after_hwframe+0x6d/0x75

Uninit was created at:
 __alloc_pages+0x9d6/0xe70 mm/page_alloc.c:4598
 __alloc_pages_node include/linux/gfp.h:238 [inline]
 alloc_pages_node include/linux/gfp.h:261 [inline]
 alloc_slab_page mm/slub.c:2175 [inline]
 allocate_slab mm/slub.c:2338 [inline]
 new_slab+0x2de/0x1400 mm/slub.c:2391
 ___slab_alloc+0x1184/0x33d0 mm/slub.c:3525
 __slab_alloc mm/slub.c:3610 [inline]
 __slab_alloc_node mm/slub.c:3663 [inline]
 slab_alloc_node mm/slub.c:3835 [inline]
 kmem_cache_alloc+0x6d3/0xbe0 mm/slub.c:3852
 p9_tag_alloc net/9p/client.c:278 [inline]
 p9_client_prepare_req+0x20a/0x1770 net/9p/client.c:641
 p9_client_rpc+0x27e/0x1340 net/9p/client.c:688
 p9_client_create+0x1551/0x1ff0 net/9p/client.c:1031
 v9fs_session_init+0x1b9/0x28e0 fs/9p/v9fs.c:410
 v9fs_mount+0xe2/0x12b0 fs/9p/vfs_super.c:122
 legacy_get_tree+0x114/0x290 fs/fs_context.c:662
 vfs_get_tree+0xa7/0x570 fs/super.c:1797
 do_new_mount+0x71f/0x15e0 fs/namespace.c:3352
 path_mount+0x742/0x1f20 fs/namespace.c:3679
 do_mount fs/namespace.c:3692 [inline]
 __do_sys_mount fs/namespace.c:3898 [inline]
 __se_sys_mount+0x725/0x810 fs/namespace.c:3875
 __x64_sys_mount+0xe4/0x150 fs/namespace.c:3875
 do_syscall_64+0xd5/0x1f0
 entry_SYSCALL_64_after_hwframe+0x6d/0x75

If p9_check_errors() fails early in p9_client_rpc(), req->rc.tag
will not be properly initialized. However, trace_9p_client_res()
ends up trying to print it out anyway before p9_client_rpc()
finishes.

Fix this issue by assigning default values to p9_fcall fields
such as 'tag' and (just in case KMSAN unearths something new) 'id'
during the tag allocation stage.

Reported-and-tested-by: syzbot+ff14db38f56329ef68df@syzkaller.appspotmail.com
Fixes: 348b59012e ("net/9p: Convert net/9p protocol dumps to tracepoints")
Signed-off-by: Nikita Zhandarovich <n.zhandarovich@fintech.ru>
Reviewed-by: Christian Schoenebeck <linux_oss@crudebyte.com>
Cc: stable@vger.kernel.org
Message-ID: <20240408141039.30428-1-n.zhandarovich@fintech.ru>
Signed-off-by: Dominique Martinet <asmadeus@codewreck.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-06-16 13:28:51 +02:00
xu xin
636438dd9d net/ipv6: Fix route deleting failure when metric equals 0
commit bb487272380d120295e955ad8acfcbb281b57642 upstream.

Problem
=========
After commit 67f6951347 ("ipv6: Move setting default metric for routes"),
we noticed that the logic of assigning the default value of fc_metirc
changed in the ioctl process. That is, when users use ioctl(fd, SIOCADDRT,
rt) with a non-zero metric to add a route,  then they may fail to delete a
route with passing in a metric value of 0 to the kernel by ioctl(fd,
SIOCDELRT, rt). But iproute can succeed in deleting it.

As a reference, when using iproute tools by netlink to delete routes with
a metric parameter equals 0, like the command as follows:

	ip -6 route del fe80::/64 via fe81::5054:ff:fe11:3451 dev eth0 metric 0

the user can still succeed in deleting the route entry with the smallest
metric.

Root Reason
===========
After commit 67f6951347 ("ipv6: Move setting default metric for routes"),
When ioctl() pass in SIOCDELRT with a zero metric, rtmsg_to_fib6_config()
will set a defalut value (1024) to cfg->fc_metric in kernel, and in
ip6_route_del() and the line 4074 at net/ipv3/route.c, it will check by

	if (cfg->fc_metric && cfg->fc_metric != rt->fib6_metric)
		continue;

and the condition is true and skip the later procedure (deleting route)
because cfg->fc_metric != rt->fib6_metric. But before that commit,
cfg->fc_metric is still zero there, so the condition is false and it
will do the following procedure (deleting).

Solution
========
In order to keep a consistent behaviour across netlink() and ioctl(), we
should allow to delete a route with a metric value of 0. So we only do
the default setting of fc_metric in route adding.

CC: stable@vger.kernel.org # 5.4+
Fixes: 67f6951347 ("ipv6: Move setting default metric for routes")
Co-developed-by: Fan Yu <fan.yu9@zte.com.cn>
Signed-off-by: Fan Yu <fan.yu9@zte.com.cn>
Signed-off-by: xu xin <xu.xin16@zte.com.cn>
Reviewed-by: David Ahern <dsahern@kernel.org>
Link: https://lore.kernel.org/r/20240514201102055dD2Ba45qKbLlUMxu_DTHP@zte.com.cn
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-06-16 13:28:51 +02:00
Herbert Xu
6396b33e98 crypto: qat - Fix ADF_DEV_RESET_SYNC memory leak
commit d3b17c6d9dddc2db3670bc9be628b122416a3d26 upstream.

Using completion_done to determine whether the caller has gone
away only works after a complete call.  Furthermore it's still
possible that the caller has not yet called wait_for_completion,
resulting in another potential UAF.

Fix this by making the caller use cancel_work_sync and then freeing
the memory safely.

Fixes: 7d42e097607c ("crypto: qat - resolve race condition during AER recovery")
Cc: <stable@vger.kernel.org> #6.8+
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Reviewed-by: Giovanni Cabiddu <giovanni.cabiddu@intel.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-06-16 13:28:51 +02:00
Vitaly Chikunov
95abba5168 crypto: ecrdsa - Fix module auto-load on add_key
commit eb5739a1efbc9ff216271aeea0ebe1c92e5383e5 upstream.

Add module alias with the algorithm cra_name similar to what we have for
RSA-related and other algorithms.

The kernel attempts to modprobe asymmetric algorithms using the names
"crypto-$cra_name" and "crypto-$cra_name-all." However, since these
aliases are currently missing, the modules are not loaded. For instance,
when using the `add_key` function, the hash algorithm is typically
loaded automatically, but the asymmetric algorithm is not.

Steps to test:

1. Cert is generated usings ima-evm-utils test suite with
   `gen-keys.sh`, example cert is provided below:

  $ base64 -d >test-gost2012_512-A.cer <<EOF
  MIIB/DCCAWagAwIBAgIUK8+whWevr3FFkSdU9GLDAM7ure8wDAYIKoUDBwEBAwMFADARMQ8wDQYD
  VQQDDAZDQSBLZXkwIBcNMjIwMjAxMjIwOTQxWhgPMjA4MjEyMDUyMjA5NDFaMBExDzANBgNVBAMM
  BkNBIEtleTCBoDAXBggqhQMHAQEBAjALBgkqhQMHAQIBAgEDgYQABIGALXNrTJGgeErBUOov3Cfo
  IrHF9fcj8UjzwGeKCkbCcINzVUbdPmCopeJRHDJEvQBX1CQUPtlwDv6ANjTTRoq5nCk9L5PPFP1H
  z73JIXHT0eRBDVoWy0cWDRz1mmQlCnN2HThMtEloaQI81nTlKZOcEYDtDpi5WODmjEeRNQJMdqCj
  UDBOMAwGA1UdEwQFMAMBAf8wHQYDVR0OBBYEFCwfOITMbE9VisW1i2TYeu1tAo5QMB8GA1UdIwQY
  MBaAFCwfOITMbE9VisW1i2TYeu1tAo5QMAwGCCqFAwcBAQMDBQADgYEAmBfJCMTdC0/NSjz4BBiQ
  qDIEjomO7FEHYlkX5NGulcF8FaJW2jeyyXXtbpnub1IQ8af1KFIpwoS2e93LaaofxpWlpQLlju6m
  KYLOcO4xK3Whwa2hBAz9YbpUSFjvxnkS2/jpH2MsOSXuUEeCruG/RkHHB3ACef9umG6HCNQuAPY=
  EOF

2. Optionally, trace module requests with: trace-cmd stream -e module &

3. Trigger add_key call for the cert:

  # keyctl padd asymmetric "" @u <test-gost2012_512-A.cer
  939910969
  # lsmod | head -3
  Module                  Size  Used by
  ecrdsa_generic         16384  0
  streebog_generic       28672  0

Repored-by: Paul Wolneykien <manowar@altlinux.org>
Cc: stable@vger.kernel.org
Signed-off-by: Vitaly Chikunov <vt@altlinux.org>
Tested-by: Stefan Berger <stefanb@linux.ibm.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-06-16 13:28:51 +02:00
Marc Zyngier
a2579c802c KVM: arm64: Allow AArch32 PSTATE.M to be restored as System mode
commit dfe6d190f38fc5df5ff2614b463a5195a399c885 upstream.

It appears that we don't allow a vcpu to be restored in AArch32
System mode, as we *never* included it in the list of valid modes.

Just add it to the list of allowed modes.

Fixes: 0d854a60b1 ("arm64: KVM: enable initialization of a 32bit vcpu")
Cc: stable@vger.kernel.org
Acked-by: Oliver Upton <oliver.upton@linux.dev>
Link: https://lore.kernel.org/r/20240524141956.1450304-3-maz@kernel.org
Signed-off-by: Marc Zyngier <maz@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-06-16 13:28:50 +02:00
Cai Xinchen
86435f39c1 fbdev: savage: Handle err return when savagefb_check_var failed
commit 6ad959b6703e2c4c5d7af03b4cfd5ff608036339 upstream.

The commit 04e5eac8f3ab("fbdev: savage: Error out if pixclock equals zero")
checks the value of pixclock to avoid divide-by-zero error. However
the function savagefb_probe doesn't handle the error return of
savagefb_check_var. When pixclock is 0, it will cause divide-by-zero error.

Fixes: 04e5eac8f3ab ("fbdev: savage: Error out if pixclock equals zero")
Signed-off-by: Cai Xinchen <caixinchen1@huawei.com>
Cc: stable@vger.kernel.org
Signed-off-by: Helge Deller <deller@gmx.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-06-16 13:28:50 +02:00
Hans Verkuil
bec5fe171f media: v4l2-core: hold videodev_lock until dev reg, finishes
commit 1ed4477f2ea4743e7c5e1f9f3722152d14e6eeb1 upstream.

After the new V4L2 device node was registered, some additional
initialization was done before the device node was marked as
'registered'. During the time between creating the device node
and marking it as 'registered' it was possible to open the
device node, which would return -ENODEV since the 'registered'
flag was not yet set.

Hold the videodev_lock mutex from just before the device node
is registered until the 'registered' flag is set. Since v4l2_open
will take the same lock, it will wait until this registration
process is finished. This resolves this race condition.

Signed-off-by: Hans Verkuil <hverkuil-cisco@xs4all.nl>
Reviewed-by: Sakari Ailus <sakari.ailus@linux.intel.com>
Cc: <stable@vger.kernel.org>      # for vi4.18 and up
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-06-16 13:28:50 +02:00
Nathan Chancellor
0dcb04014f media: mxl5xx: Move xpt structures off stack
commit 526f4527545b2d4ce0733733929fac7b6da09ac6 upstream.

When building for LoongArch with clang 18.0.0, the stack usage of
probe() is larger than the allowed 2048 bytes:

  drivers/media/dvb-frontends/mxl5xx.c:1698:12: warning: stack frame size (2368) exceeds limit (2048) in 'probe' [-Wframe-larger-than]
   1698 | static int probe(struct mxl *state, struct mxl5xx_cfg *cfg)
        |            ^
  1 warning generated.

This is the result of the linked LLVM commit, which changes how the
arrays of structures in config_ts() get handled with
CONFIG_INIT_STACK_ZERO and CONFIG_INIT_STACK_PATTERN, which causes the
above warning in combination with inlining, as config_ts() gets inlined
into probe().

This warning can be easily fixed by moving the array of structures off
of the stackvia 'static const', which is a better location for these
variables anyways because they are static data that is only ever read
from, never modified, so allocating the stack space is wasteful.

This drops the stack usage from 2368 bytes to 256 bytes with the same
compiler and configuration.

Link: https://lore.kernel.org/linux-media/20240111-dvb-mxl5xx-move-structs-off-stack-v1-1-ca4230e67c11@kernel.org
Cc: stable@vger.kernel.org
Closes: https://github.com/ClangBuiltLinux/linux/issues/1977
Link: afe8b93ffd
Signed-off-by: Nathan Chancellor <nathan@kernel.org>
Reviewed-by: Miguel Ojeda <ojeda@kernel.org>
Tested-by: Miguel Ojeda <ojeda@kernel.org>
Signed-off-by: Mauro Carvalho Chehab <mchehab@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-06-16 13:28:50 +02:00
Hans Verkuil
6ac608af7b media: mc: mark the media devnode as registered from the, start
commit 4bc60736154bc9e0e39d3b88918f5d3762ebe5e0 upstream.

First the media device node was created, and if successful it was
marked as 'registered'. This leaves a small race condition where
an application can open the device node and get an error back
because the 'registered' flag was not yet set.

Change the order: first set the 'registered' flag, then actually
register the media device node. If that fails, then clear the flag.

Signed-off-by: Hans Verkuil <hverkuil-cisco@xs4all.nl>
Acked-by: Sakari Ailus <sakari.ailus@linux.intel.com>
Reviewed-by: Laurent Pinchart <laurent.pinchart@ideasonboard.com>
Fixes: cf4b9211b5 ("[media] media: Media device node support")
Cc: stable@vger.kernel.org
Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-06-16 13:28:50 +02:00
Yang Xiwen
c125ebaf03 arm64: dts: hi3798cv200: fix the size of GICR
commit 428a575dc9038846ad259466d5ba109858c0a023 upstream.

During boot, Linux kernel complains:

[    0.000000] GIC: GICv2 detected, but range too small and irqchip.gicv2_force_probe not set

This SoC is using a regular GIC-400 and the GICR space size should be
8KB rather than 256B.

With this patch:

[    0.000000] GIC: Using split EOI/Deactivate mode

So this should be the correct fix.

Fixes: 2f20182ed6 ("arm64: dts: hisilicon: add dts files for hi3798cv200-poplar board")
Signed-off-by: Yang Xiwen <forbidden405@outlook.com>
Cc: stable@vger.kernel.org
Link: https://lore.kernel.org/r/20240219-cache-v3-1-a33c57534ae9@outlook.com
Signed-off-by: Krzysztof Kozlowski <krzysztof.kozlowski@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-06-16 13:28:50 +02:00
Bitterblue Smith
6649fea036 wifi: rtl8xxxu: Fix the TX power of RTL8192CU, RTL8723AU
commit 08b5d052d17a89bb8706b2888277d0b682dc1610 upstream.

Don't subtract 1 from the power index. This was added in commit
2fc0b8e5a1 ("rtl8xxxu: Add TX power base values for gen1 parts")
for unknown reasons. The vendor drivers don't do this.

Also correct the calculations of values written to
REG_OFDM0_X{C,D}_TX_IQ_IMBALANCE. According to the vendor driver,
these are used for TX power training.

With these changes rtl8xxxu sets the TX power of RTL8192CU the same
as the vendor driver.

None of this appears to have any effect on my RTL8192CU device.

Cc: stable@vger.kernel.org
Signed-off-by: Bitterblue Smith <rtl8821cerfe2@gmail.com>
Reviewed-by: Ping-Ke Shih <pkshih@realtek.com>
Signed-off-by: Ping-Ke Shih <pkshih@realtek.com>
Link: https://msgid.link/6ae5945b-644e-45e4-a78f-4c7d9c987910@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-06-16 13:28:50 +02:00
Yu Kuai
634ba3c97e md/raid5: fix deadlock that raid5d() wait for itself to clear MD_SB_CHANGE_PENDING
commit 151f66bb618d1fd0eeb84acb61b4a9fa5d8bb0fa upstream.

Xiao reported that lvm2 test lvconvert-raid-takeover.sh can hang with
small possibility, the root cause is exactly the same as commit
bed9e27baf52 ("Revert "md/raid5: Wait for MD_SB_CHANGE_PENDING in raid5d"")

However, Dan reported another hang after that, and junxiao investigated
the problem and found out that this is caused by plugged bio can't issue
from raid5d().

Current implementation in raid5d() has a weird dependence:

1) md_check_recovery() from raid5d() must hold 'reconfig_mutex' to clear
   MD_SB_CHANGE_PENDING;
2) raid5d() handles IO in a deadloop, until all IO are issued;
3) IO from raid5d() must wait for MD_SB_CHANGE_PENDING to be cleared;

This behaviour is introduce before v2.6, and for consequence, if other
context hold 'reconfig_mutex', and md_check_recovery() can't update
super_block, then raid5d() will waste one cpu 100% by the deadloop, until
'reconfig_mutex' is released.

Refer to the implementation from raid1 and raid10, fix this problem by
skipping issue IO if MD_SB_CHANGE_PENDING is still set after
md_check_recovery(), daemon thread will be woken up when 'reconfig_mutex'
is released. Meanwhile, the hang problem will be fixed as well.

Fixes: 5e2cf333b7bd ("md/raid5: Wait for MD_SB_CHANGE_PENDING in raid5d")
Cc: stable@vger.kernel.org # v5.19+
Reported-and-tested-by: Dan Moulding <dan@danm.net>
Closes: https://lore.kernel.org/all/20240123005700.9302-1-dan@danm.net/
Investigated-by: Junxiao Bi <junxiao.bi@oracle.com>
Signed-off-by: Yu Kuai <yukuai3@huawei.com>
Link: https://lore.kernel.org/r/20240322081005.1112401-1-yukuai1@huaweicloud.com
Signed-off-by: Song Liu <song@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-06-16 13:28:50 +02:00
Krzysztof Kozlowski
fe60a7bc34 arm64: tegra: Correct Tegra132 I2C alias
commit 2633c58e1354d7de2c8e7be8bdb6f68a0a01bad7 upstream.

There is no such device as "as3722@40", because its name is "pmic".  Use
phandles for aliases to fix relying on full node path.  This corrects
aliases for RTC devices and also fixes dtc W=1 warning:

  tegra132-norrin.dts:12.3-36: Warning (alias_paths): /aliases:rtc0: aliases property is not a valid node (/i2c@7000d000/as3722@40)

Fixes: 0f279ebdf3 ("arm64: tegra: Add NVIDIA Tegra132 Norrin support")
Cc: stable@vger.kernel.org
Signed-off-by: Krzysztof Kozlowski <krzk@kernel.org>
Reviewed-by: Jon Hunter <jonathanh@nvidia.com>
Signed-off-by: Thierry Reding <treding@nvidia.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-06-16 13:28:50 +02:00
Christoffer Sandberg
68edebd1ff ACPI: resource: Do IRQ override on TongFang GXxHRXx and GMxHGxx
commit c81bf14f9db68311c2e75428eea070d97d603975 upstream.

Listed devices need the override for the keyboard to work.

Signed-off-by: Christoffer Sandberg <cs@tuxedo.de>
Signed-off-by: Werner Sembach <wse@tuxedocomputers.com>
Cc: All applicable <stable@vger.kernel.org>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-06-16 13:28:49 +02:00
Sergey Shtylyov
3b472ad39c ata: pata_legacy: make legacy_exit() work again
commit d4a89339f17c87c4990070e9116462d16e75894f upstream.

Commit defc9cd826 ("pata_legacy: resychronize with upstream changes and
resubmit") missed to update legacy_exit(), so that it now fails to do any
cleanup -- the loop body there can never be entered.  Fix that and finally
remove now useless nr_legacy_host variable...

Found by Linux Verification Center (linuxtesting.org) with the Svace static
analysis tool.

Fixes: defc9cd826 ("pata_legacy: resychronize with upstream changes and resubmit")
Cc: stable@vger.kernel.org
Signed-off-by: Sergey Shtylyov <s.shtylyov@omp.ru>
Reviewed-by: Niklas Cassel <cassel@kernel.org>
Signed-off-by: Damien Le Moal <dlemoal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-06-16 13:28:49 +02:00
Bob Zhou
5594971e02 drm/amdgpu: add error handle to avoid out-of-bounds
commit 8b2faf1a4f3b6c748c0da36cda865a226534d520 upstream.

if the sdma_v4_0_irq_id_to_seq return -EINVAL, the process should
be stop to avoid out-of-bounds read, so directly return -EINVAL.

Signed-off-by: Bob Zhou <bob.zhou@amd.com>
Acked-by: Christian König <christian.koenig@amd.com>
Reviewed-by: Le Ma <le.ma@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-06-16 13:28:49 +02:00
Zheyu Ma
8915dcd29a media: lgdt3306a: Add a check against null-pointer-def
commit c1115ddbda9c930fba0fdd062e7a8873ebaf898d upstream.

The driver should check whether the client provides the platform_data.

The following log reveals it:

[   29.610324] BUG: KASAN: null-ptr-deref in kmemdup+0x30/0x40
[   29.610730] Read of size 40 at addr 0000000000000000 by task bash/414
[   29.612820] Call Trace:
[   29.613030]  <TASK>
[   29.613201]  dump_stack_lvl+0x56/0x6f
[   29.613496]  ? kmemdup+0x30/0x40
[   29.613754]  print_report.cold+0x494/0x6b7
[   29.614082]  ? kmemdup+0x30/0x40
[   29.614340]  kasan_report+0x8a/0x190
[   29.614628]  ? kmemdup+0x30/0x40
[   29.614888]  kasan_check_range+0x14d/0x1d0
[   29.615213]  memcpy+0x20/0x60
[   29.615454]  kmemdup+0x30/0x40
[   29.615700]  lgdt3306a_probe+0x52/0x310
[   29.616339]  i2c_device_probe+0x951/0xa90

Link: https://lore.kernel.org/linux-media/20220405095018.3993578-1-zheyuma97@gmail.com
Signed-off-by: Zheyu Ma <zheyuma97@gmail.com>
Signed-off-by: Mauro Carvalho Chehab <mchehab@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-06-16 13:28:49 +02:00
Chao Yu
c559a8d840 f2fs: fix to do sanity check on i_xattr_nid in sanity_check_inode()
commit 20faaf30e55522bba2b56d9c46689233205d7717 upstream.

syzbot reports a kernel bug as below:

F2FS-fs (loop0): Mounted with checkpoint version = 48b305e4
==================================================================
BUG: KASAN: slab-out-of-bounds in f2fs_test_bit fs/f2fs/f2fs.h:2933 [inline]
BUG: KASAN: slab-out-of-bounds in current_nat_addr fs/f2fs/node.h:213 [inline]
BUG: KASAN: slab-out-of-bounds in f2fs_get_node_info+0xece/0x1200 fs/f2fs/node.c:600
Read of size 1 at addr ffff88807a58c76c by task syz-executor280/5076

CPU: 1 PID: 5076 Comm: syz-executor280 Not tainted 6.9.0-rc5-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/27/2024
Call Trace:
 <TASK>
 __dump_stack lib/dump_stack.c:88 [inline]
 dump_stack_lvl+0x241/0x360 lib/dump_stack.c:114
 print_address_description mm/kasan/report.c:377 [inline]
 print_report+0x169/0x550 mm/kasan/report.c:488
 kasan_report+0x143/0x180 mm/kasan/report.c:601
 f2fs_test_bit fs/f2fs/f2fs.h:2933 [inline]
 current_nat_addr fs/f2fs/node.h:213 [inline]
 f2fs_get_node_info+0xece/0x1200 fs/f2fs/node.c:600
 f2fs_xattr_fiemap fs/f2fs/data.c:1848 [inline]
 f2fs_fiemap+0x55d/0x1ee0 fs/f2fs/data.c:1925
 ioctl_fiemap fs/ioctl.c:220 [inline]
 do_vfs_ioctl+0x1c07/0x2e50 fs/ioctl.c:838
 __do_sys_ioctl fs/ioctl.c:902 [inline]
 __se_sys_ioctl+0x81/0x170 fs/ioctl.c:890
 do_syscall_x64 arch/x86/entry/common.c:52 [inline]
 do_syscall_64+0xf5/0x240 arch/x86/entry/common.c:83
 entry_SYSCALL_64_after_hwframe+0x77/0x7f

The root cause is we missed to do sanity check on i_xattr_nid during
f2fs_iget(), so that in fiemap() path, current_nat_addr() will access
nat_bitmap w/ offset from invalid i_xattr_nid, result in triggering
kasan bug report, fix it.

Reported-and-tested-by: syzbot+3694e283cf5c40df6d14@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/linux-f2fs-devel/00000000000094036c0616e72a1d@google.com
Signed-off-by: Chao Yu <chao@kernel.org>
Signed-off-by: Jaegeuk Kim <jaegeuk@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-06-16 13:28:49 +02:00
Linus Torvalds
27fba38ddd x86/mm: Remove broken vsyscall emulation code from the page fault code
commit 02b670c1f88e78f42a6c5aee155c7b26960ca054 upstream.

The syzbot-reported stack trace from hell in this discussion thread
actually has three nested page faults:

  https://lore.kernel.org/r/000000000000d5f4fc0616e816d4@google.com

... and I think that's actually the important thing here:

 - the first page fault is from user space, and triggers the vsyscall
   emulation.

 - the second page fault is from __do_sys_gettimeofday(), and that should
   just have caused the exception that then sets the return value to
   -EFAULT

 - the third nested page fault is due to _raw_spin_unlock_irqrestore() ->
   preempt_schedule() -> trace_sched_switch(), which then causes a BPF
   trace program to run, which does that bpf_probe_read_compat(), which
   causes that page fault under pagefault_disable().

It's quite the nasty backtrace, and there's a lot going on.

The problem is literally the vsyscall emulation, which sets

        current->thread.sig_on_uaccess_err = 1;

and that causes the fixup_exception() code to send the signal *despite* the
exception being caught.

And I think that is in fact completely bogus.  It's completely bogus
exactly because it sends that signal even when it *shouldn't* be sent -
like for the BPF user mode trace gathering.

In other words, I think the whole "sig_on_uaccess_err" thing is entirely
broken, because it makes any nested page-faults do all the wrong things.

Now, arguably, I don't think anybody should enable vsyscall emulation any
more, but this test case clearly does.

I think we should just make the "send SIGSEGV" be something that the
vsyscall emulation does on its own, not this broken per-thread state for
something that isn't actually per thread.

The x86 page fault code actually tried to deal with the "incorrect nesting"
by having that:

                if (in_interrupt())
                        return;

which ignores the sig_on_uaccess_err case when it happens in interrupts,
but as shown by this example, these nested page faults do not need to be
about interrupts at all.

IOW, I think the only right thing is to remove that horrendously broken
code.

The attached patch looks like the ObviouslyCorrect(tm) thing to do.

NOTE! This broken code goes back to this commit in 2011:

  4fc3490114 ("x86-64: Set siginfo and context on vsyscall emulation faults")

... and back then the reason was to get all the siginfo details right.
Honestly, I do not for a moment believe that it's worth getting the siginfo
details right here, but part of the commit says:

    This fixes issues with UML when vsyscall=emulate.

... and so my patch to remove this garbage will probably break UML in this
situation.

I do not believe that anybody should be running with vsyscall=emulate in
2024 in the first place, much less if you are doing things like UML. But
let's see if somebody screams.

Reported-and-tested-by: syzbot+83e7f982ca045ab4405c@syzkaller.appspotmail.com
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Tested-by: Jiri Olsa <jolsa@kernel.org>
Acked-by: Andy Lutomirski <luto@kernel.org>
Link: https://lore.kernel.org/r/CAHk-=wh9D6f7HUkDgZHKmDCHUQmp+Co89GP+b8+z+G56BKeyNg@mail.gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
[gpiccoli: Backport the patch due to differences in the trees. The main changes
 between 5.4.y and 5.15.y are due to renaming the fixup function, by
 commit 6456a2a69ee1 ("x86/fault: Rename no_context() to kernelmode_fixup_or_oops()"),
 and on processor.h thread_struct due to commit cf122cfba5b1 ("kill uaccess_try()").
 Following 2 commits cause divergence in the diffs too (in the removed lines):
 cd072dab453a ("x86/fault: Add a helper function to sanitize error code")
 d4ffd5df9d18 ("x86/fault: Fix wrong signal when vsyscall fails with pkey").]
Signed-off-by: Guilherme G. Piccoli <gpiccoli@igalia.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-06-16 13:28:49 +02:00
Daniel Borkmann
9a7f481f3e vxlan: Fix regression when dropping packets due to invalid src addresses
commit 1cd4bc987abb2823836cbb8f887026011ccddc8a upstream.

Commit f58f45c1e5b9 ("vxlan: drop packets from invalid src-address")
has recently been added to vxlan mainly in the context of source
address snooping/learning so that when it is enabled, an entry in the
FDB is not being created for an invalid address for the corresponding
tunnel endpoint.

Before commit f58f45c1e5b9 vxlan was similarly behaving as geneve in
that it passed through whichever macs were set in the L2 header. It
turns out that this change in behavior breaks setups, for example,
Cilium with netkit in L3 mode for Pods as well as tunnel mode has been
passing before the change in f58f45c1e5b9 for both vxlan and geneve.
After mentioned change it is only passing for geneve as in case of
vxlan packets are dropped due to vxlan_set_mac() returning false as
source and destination macs are zero which for E/W traffic via tunnel
is totally fine.

Fix it by only opting into the is_valid_ether_addr() check in
vxlan_set_mac() when in fact source address snooping/learning is
actually enabled in vxlan. This is done by moving the check into
vxlan_snoop(). With this change, the Cilium connectivity test suite
passes again for both tunnel flavors.

Fixes: f58f45c1e5b9 ("vxlan: drop packets from invalid src-address")
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Cc: David Bauer <mail@david-bauer.net>
Cc: Ido Schimmel <idosch@nvidia.com>
Cc: Nikolay Aleksandrov <razor@blackwall.org>
Cc: Martin KaFai Lau <martin.lau@kernel.org>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Reviewed-by: Nikolay Aleksandrov <razor@blackwall.org>
Reviewed-by: David Bauer <mail@david-bauer.net>
Signed-off-by: David S. Miller <davem@davemloft.net>
[ Backport note: vxlan snooping/learning not supported in 6.8 or older,
  so commit is simply a revert. ]
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-06-16 13:28:49 +02:00
Ryusuke Konishi
82933c84f1 nilfs2: fix use-after-free of timer for log writer thread
commit f5d4e04634c9cf68bdf23de08ada0bb92e8befe7 upstream.

Patch series "nilfs2: fix log writer related issues".

This bug fix series covers three nilfs2 log writer-related issues,
including a timer use-after-free issue and potential deadlock issue on
unmount, and a potential freeze issue in event synchronization found
during their analysis.  Details are described in each commit log.


This patch (of 3):

A use-after-free issue has been reported regarding the timer sc_timer on
the nilfs_sc_info structure.

The problem is that even though it is used to wake up a sleeping log
writer thread, sc_timer is not shut down until the nilfs_sc_info structure
is about to be freed, and is used regardless of the thread's lifetime.

Fix this issue by limiting the use of sc_timer only while the log writer
thread is alive.

Link: https://lkml.kernel.org/r/20240520132621.4054-1-konishi.ryusuke@gmail.com
Link: https://lkml.kernel.org/r/20240520132621.4054-2-konishi.ryusuke@gmail.com
Fixes: fdce895ea5 ("nilfs2: change sc_timer from a pointer to an embedded one in struct nilfs_sc_info")
Signed-off-by: Ryusuke Konishi <konishi.ryusuke@gmail.com>
Reported-by: "Bai, Shuangpeng" <sjb7183@psu.edu>
Closes: https://groups.google.com/g/syzkaller/c/MK_LYqtt8ko/m/8rgdWeseAwAJ
Tested-by: Ryusuke Konishi <konishi.ryusuke@gmail.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-06-16 13:28:49 +02:00
Marc Dionne
ffbda400b2 afs: Don't cross .backup mountpoint from backup volume
commit 29be9100aca2915fab54b5693309bc42956542e5 upstream.

Don't cross a mountpoint that explicitly specifies a backup volume
(target is <vol>.backup) when starting from a backup volume.

It it not uncommon to mount a volume's backup directly in the volume
itself.  This can cause tools that are not paying attention to get
into a loop mounting the volume onto itself as they attempt to
traverse the tree, leading to a variety of problems.

This doesn't prevent the general case of loops in a sequence of
mountpoints, but addresses a common special case in the same way
as other afs clients.

Reported-by: Jan Henrik Sylvester <jan.henrik.sylvester@uni-hamburg.de>
Link: http://lists.infradead.org/pipermail/linux-afs/2024-May/008454.html
Reported-by: Markus Suvanto <markus.suvanto@gmail.com>
Link: http://lists.infradead.org/pipermail/linux-afs/2024-February/008074.html
Signed-off-by: Marc Dionne <marc.dionne@auristor.com>
Signed-off-by: David Howells <dhowells@redhat.com>
Link: https://lore.kernel.org/r/768760.1716567475@warthog.procyon.org.uk
Reviewed-by: Jeffrey Altman <jaltman@auristor.com>
cc: linux-afs@lists.infradead.org
Signed-off-by: Christian Brauner <brauner@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-06-16 13:28:48 +02:00