mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-07 04:12:04 -04:00
* refs/heads/tmp-75c93eb: Revert one chunk from37432a83facommit Revert "rpmsg: glink: Use complete_all for open states" ANDROID: Incremental fs: Fix selinux issues ANDROID: Incremental fs: Set credentials before reading/writing ANDROID: Incremental fs: Fix memory leak on closing file ANDROID: GKI: update Sony KMI symbol list ANDROID: ABI updates for db845c (enabling wifi) ANDROID: db845c_gki.fragment: Enable wifi on db845c w/ android-5.4 UPSTREAM: arm64: dts: qcom: sdm845: Add APSS watchdog node UPSTREAM: arm64: dts: qcom: db845c: Move remoteproc firmware to sdm845 UPSTREAM: ath10k: qmi: Sleep for a while before assigning MSA memory UPSTREAM: soc: qcom: qmi: Return EPROBE_DEFER if no address family ANDROID: ABI: Update allowed list for QCOM ANDROID: GKI: update Sony symbol list for texfat ANDROID: GKI: update KMI for db845c with idr_alloc_u32 added ANDROID: ABI: Update allowed list for QCOM ANDROID: ABI: update allowed list for QCOM Revert "media: v4l2-fwnode: Return -EINVAL for invalid bus-type" Revert "seq_buf: Avoid type mismatch for seq_buf_init" Linux 5.4.86 x86/CPU/AMD: Save AMD NodeId as cpu_die_id Revert: "ring-buffer: Remove HAVE_64BIT_ALIGNED_ACCESS" rtc: ep93xx: Fix NULL pointer dereference in ep93xx_rtc_read_time regulator: axp20x: Fix DLDO2 voltage control register mask for AXP22x PCI: Fix pci_slot_release() NULL pointer dereference platform/x86: intel-vbtn: Allow switch events on Acer Switch Alpha 12 libnvdimm/namespace: Fix reaping of invalidated block-window-namespace labels xenbus/xenbus_backend: Disallow pending watch messages xen/xenbus: Count pending messages for each watch xen/xenbus/xen_bus_type: Support will_handle watch callback xen/xenbus: Add 'will_handle' callback support in xenbus_watch_path() xen/xenbus: Allow watches discard events before queueing xen-blkback: set ring->xenblkd to NULL after kthread_stop() dma-buf/dma-resv: Respect num_fences when initializing the shared fence list. device-dax/core: Fix memory leak when rmmod dax.ko clk: tegra: Do not return 0 on failure clk: mvebu: a3700: fix the XTAL MODE pin to MPP1_9 clk: ingenic: Fix divider calculation with div tables pinctrl: sunxi: Always call chained_irq_{enter, exit} in sunxi_pinctrl_irq_handler md/cluster: fix deadlock when node is doing resync job md/cluster: block reshape with remote resync job iio:adc:ti-ads124s08: Fix alignment and data leak issues. iio:adc:ti-ads124s08: Fix buffer being too long. iio:imu:bmi160: Fix too large a buffer. iio:pressure:mpl3115: Force alignment of buffer iio:magnetometer:mag3110: Fix alignment and data leak issues. iio:light:st_uvis25: Fix timestamp alignment and prevent data leak. iio:light:rpr0521: Fix timestamp alignment and prevent data leak. iio: adc: rockchip_saradc: fix missing clk_disable_unprepare() on error in rockchip_saradc_resume iio: buffer: Fix demux update scsi: lpfc: Re-fix use after free in lpfc_rq_buf_free() scsi: lpfc: Fix invalid sleeping context in lpfc_sli4_nvmet_alloc() scsi: qla2xxx: Fix crash during driver load on big endian machines mtd: rawnand: meson: fix meson_nfc_dma_buffer_release() arguments mtd: rawnand: qcom: Fix DMA sync on FLASH_STATUS register read mtd: parser: cmdline: Fix parsing of part-names with colons mtd: spinand: Fix OOB read soc: qcom: smp2p: Safely acquire spinlock without IRQs spi: atmel-quadspi: Fix AHB memory accesses spi: atmel-quadspi: Disable clock in probe error path spi: mt7621: Don't leak SPI master in probe error path spi: mt7621: Disable clock in probe error path spi: synquacer: Disable clock in probe error path spi: st-ssc4: Fix unbalanced pm_runtime_disable() in probe error path spi: sc18is602: Don't leak SPI master in probe error path spi: rb4xx: Don't leak SPI master in probe error path spi: pic32: Don't leak DMA channels in probe error path spi: mxic: Don't leak SPI master in probe error path spi: gpio: Don't leak SPI master in probe error path spi: fsl: fix use of spisel_boot signal on MPC8309 spi: davinci: Fix use-after-free on unbind spi: atmel-quadspi: Fix use-after-free on unbind spi: spi-sh: Fix use-after-free on unbind spi: pxa2xx: Fix use-after-free on unbind drm/i915: Fix mismatch between misplaced vma check and vma insert drm/dp_aux_dev: check aux_dev before use in drm_dp_aux_dev_get_by_minor() drm/amd/display: Fix memory leaks in S3 resume platform/x86: mlx-platform: remove an unused variable jfs: Fix array index bounds check in dbAdjTree jffs2: Fix ignoring mounting options problem during remounting jffs2: Fix GC exit abnormally ubifs: wbuf: Don't leak kernel memory to flash SMB3: avoid confusing warning message on mount to Azure ceph: fix race in concurrent __ceph_remove_cap invocations um: Remove use of asprinf in umid.c ima: Don't modify file descriptor mode on the fly powerpc/powernv/memtrace: Fix crashing the kernel when enabling concurrently powerpc/powernv/memtrace: Don't leak kernel memory to user space powerpc/powernv/npu: Do not attempt NPU2 setup on POWER8NVL NPU powerpc/mm: Fix verification of MMU_FTR_TYPE_44x powerpc/8xx: Fix early debug when SMC1 is relocated powerpc/xmon: Change printk() to pr_cont() powerpc/feature: Add CPU_FTR_NOEXECUTE to G2_LE powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter powerpc: Fix incorrect stw{, ux, u, x} instructions in __set_pte_at xprtrdma: Fix XDRBUF_SPARSE_PAGES support ARM: dts: at91: sama5d2: fix CAN message ram offset and size ARM: dts: pandaboard: fix pinmux for gpio user button of Pandaboard ES KVM: arm64: Introduce handling of AArch32 TTBCR2 traps ext4: fix deadlock with fs freezing and EA inodes ext4: fix a memory leak of ext4_free_data btrfs: trim: fix underflow in trim length to prevent access beyond device boundary btrfs: do not shorten unpin len for caching block groups USB: serial: keyspan_pda: fix write unthrottling USB: serial: keyspan_pda: fix tx-unthrottle use-after-free USB: serial: keyspan_pda: fix write-wakeup use-after-free USB: serial: keyspan_pda: fix stalled writes USB: serial: keyspan_pda: fix write deadlock USB: serial: keyspan_pda: fix dropped unthrottle interrupts USB: serial: digi_acceleport: fix write-wakeup deadlocks USB: serial: mos7720: fix parallel-port state restore cpuset: fix race between hotplug work and later CPU offline EDAC/amd64: Fix PCI component registration EDAC/i10nm: Use readl() to access MMIO registers crypto: arm/aes-ce - work around Cortex-A57/A72 silion errata crypto: ecdh - avoid unaligned accesses in ecdh_set_secret() powerpc/perf: Exclude kernel samples while counting events in user space. perf/x86/intel: Fix rtm_abort_event encoding on Ice Lake perf/x86/intel: Add event constraint for CYCLE_ACTIVITY.STALLS_MEM_ANY staging: comedi: mf6x4: Fix AI end-of-conversion detection ASoC: cx2072x: Fix doubly definitions of Playback and Capture streams binder: add flag to clear buffer on txn complete s390/dasd: fix list corruption of lcu list s390/dasd: fix list corruption of pavgroup group list s390/dasd: prevent inconsistent LCU device data s390/dasd: fix hanging device offline processing s390/kexec_file: fix diag308 subcode when loading crash kernel s390/smp: perform initial CPU reset also for SMT siblings ALSA: core: memalloc: add page alignment for iram ALSA: usb-audio: Disable sample read check if firmware doesn't give back ALSA: usb-audio: Add VID to support native DSD reproduction on FiiO devices ALSA: hda/realtek: Apply jack fixup for Quanta NL3 ALSA: hda/realtek: Add quirk for MSI-GP73 ALSA/hda: apply jack fixup for the Acer Veriton N4640G/N6640G/N2510G ALSA: pcm: oss: Fix a few more UBSAN fixes ALSA: hda/realtek - Add supported for more Lenovo ALC285 Headset Button ALSA: hda/realtek - Enable headset mic of ASUS Q524UQK with ALC255 ALSA: hda/realtek - Enable headset mic of ASUS X430UN with ALC256 ALSA: hda/realtek: make bass spk volume adjustable on a yoga laptop ALSA: hda/ca0132 - Fix AE-5 rear headphone pincfg. ALSA: hda: Fix regressions on clear and reconfig sysfs ACPI: PNP: compare the string length in the matching_id() Revert "ACPI / resources: Use AE_CTRL_TERMINATE to terminate resources walks" PM: ACPI: PCI: Drop acpi_pm_set_bridge_wakeup() ALSA: hda/ca0132 - Change Input Source enum strings. Input: cyapa_gen6 - fix out-of-bounds stack access media: ipu3-cio2: Make the field on subdev format V4L2_FIELD_NONE media: ipu3-cio2: Validate mbus format in setting subdev format media: ipu3-cio2: Serialise access to pad format media: ipu3-cio2: Return actual subdev format media: ipu3-cio2: Remove traces of returned buffers media: netup_unidvb: Don't leak SPI master in probe error path media: sunxi-cir: ensure IR is handled when it is continuous media: gspca: Fix memory leak in probe vfio/pci/nvlink2: Do not attempt NPU2 setup on POWER8NVL NPU Input: goodix - add upside-down quirk for Teclast X98 Pro tablet initramfs: fix clang build failure Input: cros_ec_keyb - send 'scancodes' in addition to key events drm/amdkfd: Fix leak in dmabuf import drm/amd/display: Prevent bandwidth overflow lwt: Disable BH too in run_lwt_bpf() fix namespaced fscaps when !CONFIG_SECURITY cfg80211: initialize rekey_data ARM: sunxi: Add machine match for the Allwinner V3 SoC perf probe: Fix memory leak when synthesizing SDT probes kconfig: fix return value of do_error_if() clk: sunxi-ng: Make sure divider tables have sentinel clk: s2mps11: Fix a resource leak in error handling paths in the probe function clk: at91: sam9x60: remove atmel,osc-bypass support virtio_ring: Fix two use after free bugs virtio_net: Fix error code in probe() virtio_ring: Cut and paste bugs in vring_create_virtqueue_packed() qlcnic: Fix error code in probe perf record: Fix memory leak when using '--user-regs=?' to list registers pwm: lp3943: Dynamically allocate PWM chip base pwm: zx: Add missing cleanup in error path clk: ti: Fix memleak in ti_fapll_synth_setup watchdog: coh901327: add COMMON_CLK dependency watchdog: qcom: Avoid context switch in restart handler libnvdimm/label: Return -ENXIO for no slot in __blk_label_update net: korina: fix return value net: allwinner: Fix some resources leak in the error handling path of the probe and in the remove function net: bcmgenet: Fix a resource leak in an error handling path in the probe functin lan743x: fix rx_napi_poll/interrupt ping-pong checkpatch: fix unescaped left brace mm: don't wake kswapd prematurely when watermark boosting is disabled sparc: fix handling of page table constructor failure powerpc/ps3: use dma_mapping_error() nfc: s3fwrn5: Release the nfc firmware RDMA/cma: Don't overwrite sgid_attr after device is released sunrpc: fix xs_read_xdr_buf for partial pages receive um: chan_xterm: Fix fd leak um: tty: Fix handling of close in tty lines um: Monitor error events in IRQ controller ubifs: Fix error return code in ubifs_init_authentication() watchdog: Fix potential dereferencing of null pointer watchdog: sprd: check busy bit before new loading rather than after that watchdog: sprd: remove watchdog disable from resume fail path watchdog: sirfsoc: Add missing dependency on HAS_IOMEM watchdog: armada_37xx: Add missing dependency on HAS_IOMEM irqchip/alpine-msi: Fix freeing of interrupts on allocation error path ASoC: wm_adsp: remove "ctl" from list on error in wm_adsp_create_control() mac80211: don't set set TDLS STA bandwidth wider than possible crypto: atmel-i2c - select CONFIG_BITREVERSE extcon: max77693: Fix modalias string mtd: rawnand: gpmi: Fix the random DMA timeout issue mtd: rawnand: meson: Fix a resource leak in init mtd: rawnand: gpmi: fix reference count leak in gpmi ops clk: tegra: Fix duplicated SE clock entry remoteproc: qcom: Fix potential NULL dereference in adsp_init_mmio() remoteproc: qcom: fix reference leak in adsp_start remoteproc: q6v5-mss: fix error handling in q6v5_pds_enable RDMA/core: Do not indicate device ready when device enablement fails can: m_can: m_can_config_endisable(): remove double clearing of clock stop request bit erofs: avoid using generic_block_bmap iwlwifi: mvm: hook up missing RX handlers s390/cio: fix use-after-free in ccw_device_destroy_console bus: fsl-mc: fix error return code in fsl_mc_object_allocate() platform/chrome: cros_ec_spi: Don't overwrite spi::mode x86/kprobes: Restore BTF if the single-stepping is cancelled nfs_common: need lock during iterate through the list nfsd: Fix message level for normal termination speakup: fix uninitialized flush_lock usb: oxu210hp-hcd: Fix memory leak in oxu_create usb: ehci-omap: Fix PM disable depth umbalance in ehci_hcd_omap_probe powerpc/mm: sanity_check_fault() should work for all, not only BOOK3S ASoC: amd: change clk_get() to devm_clk_get() and add missed checks drm/mediatek: avoid dereferencing a null hdmi_phy on an error message powerpc/pseries/hibernation: remove redundant cacheinfo update powerpc/pseries/hibernation: drop pseries_suspend_begin() from suspend ops platform/x86: mlx-platform: Fix item counter assignment for MSN2700, MSN24xx systems scsi: fnic: Fix error return code in fnic_probe() seq_buf: Avoid type mismatch for seq_buf_init scsi: pm80xx: Fix error return in pm8001_pci_probe() scsi: qedi: Fix missing destroy_workqueue() on error in __qedi_probe arm64: dts: meson: g12a: x96-max: fix PHY deassert timing requirements ARM: dts: meson: fix PHY deassert timing requirements arm64: dts: meson: fix PHY deassert timing requirements Bluetooth: btmtksdio: Add the missed release_firmware() in mtk_setup_firmware() Bluetooth: btusb: Add the missed release_firmware() in btusb_mtk_setup_firmware() cpufreq: scpi: Add missing MODULE_ALIAS cpufreq: loongson1: Add missing MODULE_ALIAS cpufreq: sun50i: Add missing MODULE_DEVICE_TABLE cpufreq: st: Add missing MODULE_DEVICE_TABLE cpufreq: qcom: Add missing MODULE_DEVICE_TABLE cpufreq: mediatek: Add missing MODULE_DEVICE_TABLE cpufreq: highbank: Add missing MODULE_DEVICE_TABLE cpufreq: ap806: Add missing MODULE_DEVICE_TABLE clocksource/drivers/arm_arch_timer: Correct fault programming of CNTKCTL_EL1.EVNTI clocksource/drivers/arm_arch_timer: Use stable count reader in erratum sne phy: renesas: rcar-gen3-usb2: disable runtime pm in case of failure dm ioctl: fix error return code in target_message ASoC: jz4740-i2s: add missed checks for clk_get() net/mlx5: Properly convey driver version to firmware MIPS: Don't round up kernel sections size for memblock_add() memstick: r592: Fix error return in r592_probe() arm64: dts: rockchip: Fix UART pull-ups on rk3328 pinctrl: falcon: add missing put_device() call in pinctrl_falcon_probe() bpf: Fix bpf_put_raw_tracepoint()'s use of __module_address() ARM: dts: at91: sama5d2: map securam as device iio: hrtimer-trigger: Mark hrtimer to expire in hard interrupt context clocksource/drivers/cadence_ttc: Fix memory leak in ttc_setup_clockevent() clocksource/drivers/orion: Add missing clk_disable_unprepare() on error path powerpc/64: Fix an EMIT_BUG_ENTRY in head_64.S powerpc/perf: Fix crash with is_sier_available when pmu is not set media: saa7146: fix array overflow in vidioc_s_audio() hwmon: (ina3221) Fix PM usage counter unbalance in ina3221_write_enable vfio-pci: Use io_remap_pfn_range() for PCI IO memory selftests/seccomp: Update kernel config NFS: switch nfsiod to be an UNBOUND workqueue. lockd: don't use interval-based rebinding over TCP net: sunrpc: Fix 'snprintf' return value check in 'do_xprt_debugfs' NFSv4: Fix the alignment of page data in the getdeviceinfo reply SUNRPC: xprt_load_transport() needs to support the netid "rdma6" NFSv4.2: condition READDIR's mask for security label based on LSM state SUNRPC: rpc_wake_up() should wake up tasks in the correct order ath10k: Release some resources in an error handling path ath10k: Fix an error handling path ath10k: Fix the parsing error in service available event platform/x86: dell-smbios-base: Fix error return code in dell_smbios_init ARM: dts: at91: at91sam9rl: fix ADC triggers soc: amlogic: canvas: add missing put_device() call in meson_canvas_get() arm64: dts: meson-sm1: fix typo in opp table arm64: dts: meson: fix spi-max-frequency on Khadas VIM2 PCI: iproc: Fix out-of-bound array accesses PCI: Fix overflow in command-line resource alignment requests PCI: Bounds-check command-line resource alignment requests arm64: dts: qcom: c630: Polish i2c-hid devices arm64: dts: ls1028a: fix ENETC PTP clock input genirq/irqdomain: Don't try to free an interrupt that has no mapping power: supply: bq24190_charger: fix reference leak power: supply: axp288_charger: Fix HP Pavilion x2 10 DMI matching arm64: dts: rockchip: Set dr_mode to "host" for OTG on rk3328-roc-cc arm64: dts: armada-3720-turris-mox: update ethernet-phy handle name ARM: dts: Remove non-existent i2c1 from 98dx3236 HSI: omap_ssi: Don't jump to free ID in ssi_add_controller() slimbus: qcom-ngd-ctrl: Avoid sending power requests without QMI media: max2175: fix max2175_set_csm_mode() error code mips: cdmm: fix use-after-free in mips_cdmm_bus_discover media: imx214: Fix stop streaming samples: bpf: Fix lwt_len_hist reusing previous BPF map platform/x86: mlx-platform: Remove PSU EEPROM from MSN274x platform configuration platform/x86: mlx-platform: Remove PSU EEPROM from default platform configuration media: siano: fix memory leak of debugfs members in smsdvb_hotplug arm64: tegra: Fix DT binding for IO High Voltage entry dmaengine: mv_xor_v2: Fix error return code in mv_xor_v2_probe() cw1200: fix missing destroy_workqueue() on error in cw1200_init_common rsi: fix error return code in rsi_reset_card() qtnfmac: fix error return code in qtnf_pcie_probe() orinoco: Move context allocation after processing the skb mmc: pxamci: Fix error return code in pxamci_probe ARM: dts: at91: sama5d3_xplained: add pincontrol for USB Host ARM: dts: at91: sama5d4_xplained: add pincontrol for USB Host memstick: fix a double-free bug in memstick_check RDMA/cxgb4: Validate the number of CQEs clk: meson: Kconfig: fix dependency for G12A Input: omap4-keypad - fix runtime PM error handling drivers: soc: ti: knav_qmss_queue: Fix error return code in knav_queue_probe soc: ti: Fix reference imbalance in knav_dma_probe soc: ti: knav_qmss: fix reference leak in knav_queue_probe spi: fix resource leak for drivers without .remove callback crypto: omap-aes - Fix PM disable depth imbalance in omap_aes_probe crypto: crypto4xx - Replace bitwise OR with logical OR in crypto4xx_build_pd EDAC/mce_amd: Use struct cpuinfo_x86.cpu_die_id for AMD NodeId powerpc/feature: Fix CPU_FTRS_ALWAYS by removing CPU_FTRS_GENERIC_32 powerpc: Avoid broken GCC __attribute__((optimize)) selftests/bpf: Fix broken riscv build spi: mxs: fix reference leak in mxs_spi_probe usb/max3421: fix return error code in max3421_probe() Input: ads7846 - fix unaligned access on 7845 Input: ads7846 - fix integer overflow on Rt calculation Input: ads7846 - fix race that causes missing releases drm/omap: dmm_tiler: fix return error code in omap_dmm_probe() video: fbdev: atmel_lcdfb: fix return error code in atmel_lcdfb_of_init() media: solo6x10: fix missing snd_card_free in error handling case scsi: core: Fix VPD LUN ID designator priorities ASoC: meson: fix COMPILE_TEST error media: v4l2-fwnode: Return -EINVAL for invalid bus-type media: mtk-vcodec: add missing put_device() call in mtk_vcodec_init_enc_pm() media: mtk-vcodec: add missing put_device() call in mtk_vcodec_release_dec_pm() media: mtk-vcodec: add missing put_device() call in mtk_vcodec_init_dec_pm() media: tm6000: Fix sizeof() mismatches staging: gasket: interrupt: fix the missed eventfd_ctx_put() in gasket_interrupt.c staging: greybus: codecs: Fix reference counter leak in error handling crypto: qat - fix status check in qat_hal_put_rel_rd_xfer() MIPS: BCM47XX: fix kconfig dependency bug for BCM47XX_BCMA RDMa/mthca: Work around -Wenum-conversion warning ASoC: arizona: Fix a wrong free in wm8997_probe spi: sprd: fix reference leak in sprd_spi_remove ASoC: wm8998: Fix PM disable depth imbalance on error selftest/bpf: Add missed ip6ip6 test back mwifiex: fix mwifiex_shutdown_sw() causing sw reset failure spi: bcm63xx-hsspi: fix missing clk_disable_unprepare() on error in bcm63xx_hsspi_resume spi: tegra114: fix reference leak in tegra spi ops spi: tegra20-sflash: fix reference leak in tegra_sflash_resume spi: tegra20-slink: fix reference leak in slink ops of tegra20 spi: mt7621: fix missing clk_disable_unprepare() on error in mt7621_spi_probe spi: spi-ti-qspi: fix reference leak in ti_qspi_setup Bluetooth: hci_h5: fix memory leak in h5_close Bluetooth: Fix null pointer dereference in hci_event_packet() arm64: dts: exynos: Correct psci compatible used on Exynos7 arm64: dts: exynos: Include common syscon restart/poweroff for Exynos7 brcmfmac: Fix memory leak for unpaired brcmf_{alloc/free} spi: stm32: fix reference leak in stm32_spi_resume selinux: fix inode_doinit_with_dentry() LABEL_INVALID error handling ASoC: pcm: DRAIN support reactivation spi: spi-mem: fix reference leak in spi_mem_access_start drm/msm/dsi_pll_10nm: restore VCO rate during restore_state f2fs: call f2fs_get_meta_page_retry for nat page spi: img-spfi: fix reference leak in img_spfi_resume powerpc/64: Set up a kernel stack for secondaries before cpu_restore() drm/amdgpu: fix build_coefficients() argument ARM: dts: aspeed: tiogapass: Remove vuart ASoC: sun4i-i2s: Fix lrck_period computation for I2S justified mode crypto: inside-secure - Fix sizeof() mismatch crypto: talitos - Fix return type of current_desc_hdr() crypto: talitos - Endianess in current_desc_hdr() drm/amdgpu: fix incorrect enum type sched: Reenable interrupts in do_sched_yield() sched/deadline: Fix sched_dl_global_validate() x86/apic: Fix x2apic enablement without interrupt remapping ARM: p2v: fix handling of LPAE translation in BE mode x86/mm/ident_map: Check for errors from ident_pud_init() RDMA/rxe: Compute PSN windows correctly ARM: dts: aspeed: s2600wf: Fix VGA memory region location selinux: fix error initialization in inode_doinit_with_dentry() rtc: pcf2127: fix pcf2127_nvmem_read/write() returns RDMA/bnxt_re: Set queue pair state when being queried Revert "i2c: i2c-qcom-geni: Fix DMA transfer race" soc: qcom: geni: More properly switch to DMA mode soc: mediatek: Check if power domains can be powered on at boot time soc: renesas: rmobile-sysc: Fix some leaks in rmobile_init_pm_domains() arm64: dts: renesas: cat875: Remove rxc-skew-ps from ethernet-phy node arm64: dts: renesas: hihope-rzg2-ex: Drop rxc-skew-ps from ethernet-phy node drm/tve200: Fix handling of platform_get_irq() error drm/mcde: Fix handling of platform_get_irq() error drm/aspeed: Fix Kconfig warning & subsequent build errors drm/gma500: fix double free of gma_connector md: fix a warning caused by a race between concurrent md_ioctl()s crypto: af_alg - avoid undefined behavior accessing salg_name media: msi2500: assign SPI bus number dynamically quota: Sanity-check quota file headers on load Bluetooth: Fix slab-out-of-bounds read in hci_le_direct_adv_report_evt() serial_core: Check for port state when tty is in error state HID: i2c-hid: add Vero K147 to descriptor override scsi: megaraid_sas: Check user-provided offsets coresight: etb10: Fix possible NULL ptr dereference in etb_enable_perf() coresight: tmc-etr: Fix barrier packet insertion for perf buffer coresight: tmc-etr: Check if page is valid before dma_map_page() coresight: tmc-etf: Fix NULL ptr dereference in tmc_enable_etf_sink_perf() ARM: dts: exynos: fix USB 3.0 pins supply being turned off on Odroid XU ARM: dts: exynos: fix USB 3.0 VBUS control and over-current pins on Exynos5410 ARM: dts: exynos: fix roles of USB 3.0 ports on Odroid XU usb: chipidea: ci_hdrc_imx: Pass DISABLE_DEVICE_STREAMING flag to imx6ul USB: gadget: f_rndis: fix bitrate for SuperSpeed and above usb: gadget: f_fs: Re-use SS descriptors for SuperSpeedPlus USB: gadget: f_midi: setup SuperSpeed Plus descriptors USB: gadget: f_acm: add support for SuperSpeed Plus USB: serial: option: add interface-number sanity check to flag handling usb: mtu3: fix memory corruption in mtu3_debugfs_regset() soc/tegra: fuse: Fix index bug in get_process_id kbuild: avoid split lines in .mod files perf/x86/intel: Check PEBS status correctly drm/amd/display: Init clock value by current vbios CLKs iwlwifi: pcie: add one missing entry for AX210 dm table: Remove BUG_ON(in_interrupt()) scsi: mpt3sas: Increase IOCInit request timeout to 30s vxlan: Copy needed_tailroom from lowerdev vxlan: Add needed_headroom for lower device arm64: syscall: exit userspace before unmasking exceptions habanalabs: put devices before driver removal drm/tegra: sor: Disable clocks on error in tegra_sor_init() kernel/cpu: add arch override for clear_tasks_mm_cpumask() mm handling drm/tegra: replace idr_init() by idr_init_base() net: mvpp2: add mvpp2_phylink_to_port() helper selftests: fix poll error in udpgro.sh ixgbe: avoid premature Rx buffer reuse i40e: avoid premature Rx buffer reuse i40e: optimise prefetch page refcount i40e: Refactor rx_bi accesses RDMA/cm: Fix an attempt to use non-valid pointer when cleaning timewait selftests/bpf/test_offload.py: Reset ethtool features after failed setting netfilter: nft_ct: Remove confirmation check for NFT_CT_ID gpio: eic-sprd: break loop when getting NULL device resource Revert "gpio: eic-sprd: Use devm_platform_ioremap_resource()" afs: Fix memory leak when mounting with multiple source parameters netfilter: nft_dynset: fix timeouts later than 23 days netfilter: nft_compat: make sure xtables destructors have run netfilter: x_tables: Switch synchronization to RCU pinctrl: aspeed: Fix GPIO requests on pass-through banks blk-mq: In blk_mq_dispatch_rq_list() "no budget" is a reason to kick block: factor out requeue handling from dispatch code block: Simplify REQ_OP_ZONE_RESET_ALL handling clk: renesas: r9a06g032: Drop __packed for portability can: softing: softing_netdev_open(): fix error handling xsk: Replace datagram_poll by sock_poll_wait xsk: Fix xsk_poll()'s return type scsi: bnx2i: Requires MMU gpio: mvebu: fix potential user-after-free on probe gpio: zynq: fix reference leak in zynq_gpio functions PM: runtime: Add pm_runtime_resume_and_get to deal with usage counter ARM: dts: imx6qdl-kontron-samx6i: fix I2C_PM scl pin ARM: dts: imx6qdl-wandboard-revd1: Remove PAD_GPIO_6 from enetgrp ARM: dts: sun7i: pcduino3-nano: enable RGMII RX/TX delay on PHY ARM: dts: sun8i: v3s: fix GIC node memory range pinctrl: baytrail: Avoid clearing debounce value when turning it off pinctrl: merrifield: Set default bias in case no particular value given ARM: dts: sun8i: v40: bananapi-m2-berry: Fix ethernet node ARM: dts: sun8i: r40: bananapi-m2-berry: Fix dcdc1 regulator ARM: dts: sun7i: bananapi: Enable RGMII RX/TX delay on Ethernet PHY Linux 5.4.85 x86/resctrl: Fix incorrect local bandwidth when mba_sc is enabled x86/resctrl: Remove unused struct mbm_state::chunks_bw membarrier: Explicitly sync remote cores when SYNC_CORE is requested Revert "selftests/ftrace: check for do_sys_openat2 in user-memory test" KVM: mmu: Fix SPTE encoding of MMIO generation upper half serial: 8250_omap: Avoid FIFO corruption caused by MDR1 access ALSA: pcm: oss: Fix potential out-of-bounds shift USB: sisusbvga: Make console support depend on BROKEN USB: UAS: introduce a quirk to set no_write_same xhci-pci: Allow host runtime PM as default for Intel Alpine Ridge LP xhci: Give USB2 ports time to enter U3 in bus suspend ALSA: usb-audio: Fix control 'access overflow' errors from chmap ALSA: usb-audio: Fix potential out-of-bounds shift USB: add RESET_RESUME quirk for Snapscan 1212 USB: dummy-hcd: Fix uninitialized array use in init() ktest.pl: If size of log is too big to email, email error message net: stmmac: delete the eee_ctrl_timer after napi disabled net: stmmac: dwmac-meson8b: fix mask definition of the m250_sel mux net: ll_temac: Fix potential NULL dereference in temac_probe() net/mlx4_en: Handle TX error CQE lan743x: fix for potential NULL pointer dereference with bare card net/mlx4_en: Avoid scheduling restart task if it is already running tcp: fix cwnd-limited bug for TSO deferral where we send nothing tcp: select sane initial rcvq_space.space for big MSS net: stmmac: free tx skb buffer in stmmac_resume() bridge: Fix a deadlock when enabling multicast snooping enetc: Fix reporting of h/w packet counters udp: fix the proto value passed to ip_protocol_deliver_rcu for the segments net: hns3: remove a misused pragma packed vrf: packets with lladdr src needs dst at input with orig_iif when needs strict net: bridge: vlan: fix error return code in __vlan_add() mac80211: mesh: fix mesh_pathtbl_init() error path ipv4: fix error return code in rtm_to_fib_config() ptrace: Prevent kernel-infoleak in ptrace_get_syscall_info() Linux 5.4.84 compiler.h: fix barrier_data() on clang mm/zsmalloc.c: drop ZSMALLOC_PGTABLE_MAPPING x86/apic/vector: Fix ordering in vector assignment x86/membarrier: Get rid of a dubious optimization x86/mm/mem_encrypt: Fix definition of PMD_FLAGS_DEC_WP scsi: be2iscsi: Revert "Fix a theoretical leak in beiscsi_create_eqs()" proc: use untagged_addr() for pagemap_read addresses kbuild: avoid static_assert for genksyms drm/i915/display/dp: Compute the correct slice count for VDSC on DP mmc: block: Fixup condition for CMD13 polling for RPMB requests pinctrl: amd: remove debounce filter setting in IRQ type setting Input: i8042 - add Acer laptops to the i8042 reset list Input: cm109 - do not stomp on control URB ktest.pl: Fix incorrect reboot for grub2bls can: m_can: m_can_dev_setup(): add support for bosch mcan version 3.3.0 platform/x86: touchscreen_dmi: Add info for the Irbis TW118 tablet platform/x86: intel-vbtn: Support for tablet mode on HP Pavilion 13 x360 PC platform/x86: acer-wmi: add automatic keyboard background light toggle key as KEY_LIGHTS_TOGGLE platform/x86: thinkpad_acpi: Add BAT1 is primary battery quirk for Thinkpad Yoga 11e 4th gen platform/x86: thinkpad_acpi: Do not report SW_TABLET_MODE on Yoga 11e arm64: tegra: Disable the ACONNECT for Jetson TX2 soc: fsl: dpio: Get the cpumask through cpumask_of(cpu) spi: spi-nxp-fspi: fix fspi panic by unexpected interrupts irqchip/gic-v3-its: Unconditionally save/restore the ITS state on suspend ibmvnic: skip tx timeout reset while in resetting interconnect: qcom: qcs404: Remove GPU and display RPM IDs scsi: ufs: Make sure clk scaling happens only when HBA is runtime ACTIVE ARC: stack unwinding: don't assume non-current task is sleeping arm64: dts: broadcom: clear the warnings caused by empty dma-ranges powerpc: Drop -me200 addition to build flags iwlwifi: mvm: fix kernel panic in case of assert during CSA iwlwifi: pcie: set LTR to avoid completion timeout arm64: dts: rockchip: Assign a fixed index to mmc devices on rk3399 boards. iwlwifi: pcie: limit memory read spin time x86/lib: Change .weak to SYM_FUNC_START_WEAK for arch/x86/lib/mem*_64.S Kbuild: do not emit debug info for assembly with LLVM_IAS=1 ANDROID: GKI: bring back irq_create_mapping() Linux 5.4.83 Revert "geneve: pull IP header before ECN decapsulation" x86/insn-eval: Use new for_each_insn_prefix() macro to loop over prefixes bytes netfilter: nftables_offload: set address type in control dissector netfilter: nf_tables: avoid false-postive lockdep splat Input: i8042 - fix error return code in i8042_setup_aux() dm writecache: remove BUG() and fail gracefully instead i2c: qup: Fix error return code in qup_i2c_bam_schedule_desc() rtw88: debug: Fix uninitialized memory in debugfs code ASoC: wm_adsp: fix error return code in wm_adsp_load() tipc: fix a deadlock when flushing scheduled work netfilter: ipset: prevent uninit-value in hash_ip6_add gfs2: check for empty rgrp tree in gfs2_ri_update can: af_can: can_rx_unregister(): remove WARN() statement from list operation sanity check lib/syscall: fix syscall registers retrieval on 32-bit platforms tracing: Fix userstacktrace option for instances iommu/amd: Set DTE[IntTabLen] to represent 512 IRTEs spi: bcm2835: Release the DMA channel if probe fails after dma_init i2c: imx: Check for I2SR_IAL after every byte i2c: imx: Fix reset of I2SR_IAL flag speakup: Reject setting the speakup line discipline outside of speakup mm/swapfile: do not sleep with a spin lock held mm: list_lru: set shrinker map bit when child nr_items is not zero coredump: fix core_pattern parse error x86/uprobes: Do not use prefixes.nbytes when looping over prefixes.bytes dm: remove invalid sparse __acquires and __releases annotations dm: fix bug with RCU locking in dm_blk_report_zones powerpc/pseries: Pass MSI affinity to irq_create_mapping() genirq/irqdomain: Add an irq_create_mapping_affinity() function powerpc/64s/powernv: Fix memory corruption when saving SLB entries on MCE dm writecache: fix the maximum number of arguments scsi: mpt3sas: Fix ioctl timeout drm/i915/gt: Program mocs:63 for cache eviction on gen9 thunderbolt: Fix use-after-free in remove_unplugged_switch() i2c: imx: Don't generate STOP condition if arbitration has been lost cifs: fix potential use-after-free in cifs_echo_request() cifs: allow syscalls to be restarted in __smb_send_rqst() ftrace: Fix updating FTRACE_FL_TRAMP ALSA: hda/generic: Add option to enforce preferred_dacs pairs ALSA: hda/realtek - Add new codec supported for ALC897 ALSA: hda/realtek: Enable headset of ASUS UX482EG & B9400CEA with ALC294 ALSA: hda/realtek: Add mute LED quirk to yet another HP x360 model ALSA: hda/realtek: Fix bass speaker DAC assignment on Asus Zephyrus G14 tty: Fix ->session locking tty: Fix ->pgrp locking in tiocspgrp() USB: serial: option: fix Quectel BG96 matching USB: serial: option: add support for Thales Cinterion EXS82 USB: serial: option: add Fibocom NL668 variants USB: serial: ch341: sort device-id entries USB: serial: ch341: add new Product ID for CH341A USB: serial: kl5kusb105: fix memleak on open usb: gadget: f_fs: Use local copy of descriptors for userspace copy Partially revert bpf: Zero-fill re-used per-cpu map element pinctrl: baytrail: Fix pin being driven low for a while on gpiod_get(..., GPIOD_OUT_HIGH) pinctrl: baytrail: Replace WARN with dev_info_once when setting direct-irq pin to output Linux 5.4.82 RDMA/i40iw: Address an mmap handler exploit in i40iw tracing: Remove WARN_ON in start_thread() Input: i8042 - add ByteSpeed touchpad to noloop table Input: xpad - support Ardwiino Controllers ALSA: usb-audio: US16x08: fix value count for level meters net/mlx5: Fix wrong address reclaim when command interface is down net/mlx5: DR, Proper handling of unsupported Connect-X6DX SW steering net/sched: act_mpls: ensure LSE is pullable before reading it net: openvswitch: ensure LSE is pullable before reading it net: skbuff: ensure LSE is pullable before decrementing the MPLS ttl net: mvpp2: Fix error return code in mvpp2_open() chelsio/chtls: fix a double free in chtls_setkey() vxlan: fix error return code in __vxlan_dev_create() net: pasemi: fix error return code in pasemi_mac_open() cxgb3: fix error return code in t3_sge_alloc_qset() net/x25: prevent a couple of overflows net: ip6_gre: set dev->hard_header_len when using header_ops geneve: pull IP header before ECN decapsulation inet_ecn: Fix endianness of checksum update when setting ECT(1) ibmvnic: Fix TX completion error handling ibmvnic: Ensure that SCRQ entry reads are correctly ordered chelsio/chtls: fix panic during unload reload chtls dt-bindings: net: correct interrupt flags in examples ipv4: Fix tos mask in inet_rtm_getroute() netfilter: bridge: reset skb->pkt_type after NF_INET_POST_ROUTING traversal sched/fair: Fix unthrottle_cfs_rq() for leaf_cfs_rq list ima: extend boot_aggregate with kernel measurements staging/octeon: fix up merge error bonding: wait for sysfs kobject destruction before freeing struct slave usbnet: ipheth: fix connectivity with iOS 14 tun: honor IOCB_NOWAIT flag tcp: Set INET_ECN_xmit configuration in tcp_reinit_congestion_control sock: set sk_err to ee_errno on dequeue from errq rose: Fix Null pointer dereference in rose_send_frame() net/tls: Protect from calling tls_dev_del for TLS RX twice net/tls: missing received data after fast remote close net/af_iucv: set correct sk_protocol for child sockets ipv6: addrlabel: fix possible memory leak in ip6addrlbl_net_init devlink: Hold rtnl lock while reading netdev attributes Linux 5.4.81 ASoC: Intel: Skylake: Automatic DMIC format configuration according to information from NHLT ASoC: Intel: Multiple I/O PCM format support for pipe ASoC: Intel: Skylake: Await purge request ack on CNL ASoC: Intel: Allow for ROM init retry on CNL platforms ASoC: Intel: Skylake: Shield against no-NHLT configurations ASoC: Intel: Skylake: Enable codec wakeup during chip init ASoC: Intel: Skylake: Select hda configuration permissively ASoC: Intel: Skylake: Remove superfluous chip initialization USB: core: Fix regression in Hercules audio card x86/resctrl: Add necessary kernfs_put() calls to prevent refcount leak x86/resctrl: Remove superfluous kernfs_get() calls to prevent refcount leak x86/speculation: Fix prctl() when spectre_v2_user={seccomp,prctl},ibpb x86/mce: Do not overwrite no_way_out if mce_end() fails irqchip/exiu: Fix the index of fwspec for IRQ type usb: gadget: Fix memleak in gadgetfs_fill_super USB: quirks: Add USB_QUIRK_DISCONNECT_SUSPEND quirk for Lenovo A630Z TIO built-in usb-audio card usb: gadget: f_midi: Fix memleak in f_midi_alloc USB: core: Change %pK for __user pointers to %px spi: bcm2835aux: Restore err assignment in bcm2835aux_spi_probe perf probe: Fix to die_entrypc() returns error correctly perf stat: Use proper cpu for shadow stats can: m_can: fix nominal bitiming tseg2 min for version >= 3.1 can: m_can: m_can_open(): remove IRQF_TRIGGER_FALLING from request_threaded_irq()'s flags RDMA/hns: Bugfix for memory window mtpt configuration RDMA/hns: Fix retry_cnt and rnr_cnt when querying QP platform/x86: toshiba_acpi: Fix the wrong variable assignment platform/x86: thinkpad_acpi: Send tablet mode switch at wakeup time can: gs_usb: fix endianess problem with candleLight firmware efi: EFI_EARLYCON should depend on EFI efivarfs: revert "fix memory leak in efivarfs_create()" arm64: tegra: Wrong AON HSP reg property size optee: add writeback to valid memory type ibmvnic: fix NULL pointer dereference in ibmvic_reset_crq ibmvnic: fix NULL pointer dereference in reset_sub_crq_queues net: ena: set initial DMA width to avoid intel iommu issue nfc: s3fwrn5: use signed integer for parsing GPIO numbers i40e: Fix removing driver while bare-metal VFs pass traffic IB/mthca: fix return value of error branch in mthca_init_cq() powerpc/64s: Fix allnoconfig build since uaccess flush ibmvnic: notify peers when failover and migration happen ibmvnic: fix call_netdevice_notifiers in do_reset s390/qeth: fix tear down of async TX buffers s390/qeth: fix af_iucv notification race s390/qeth: make af_iucv TX notification call more robust cxgb4: fix the panic caused by non smac rewrite bnxt_en: Release PCI regions when DMA mask setup fails during probe. video: hyperv_fb: Fix the cache type when mapping the VRAM bnxt_en: fix error return code in bnxt_init_board() bnxt_en: fix error return code in bnxt_init_one() scsi: ufs: Fix race between shutdown and runtime resume flow ARM: dts: dra76x: m_can: fix order of clocks arch: pgtable: define MAX_POSSIBLE_PHYSMEM_BITS where needed batman-adv: set .owner to THIS_MODULE iwlwifi: mvm: write queue_sync_state only for sync phy: tegra: xusb: Fix dangling pointer on probe failure ARM: OMAP2+: Manage MPU state properly for omap_enter_idle_coupled() bus: ti-sysc: Fix bogus resetdone warning on enable for cpsw net: dsa: mv88e6xxx: Wait for EEPROM done after HW reset xtensa: uaccess: Add missing __user to strncpy_from_user() prototype perf/x86: fix sysfs type mismatches scsi: target: iscsi: Fix cmd abort fabric stop race scsi: libiscsi: Fix NOP race condition dmaengine: pl330: _prep_dma_memcpy: Fix wrong burst size vhost scsi: fix cmd completion race nvme: free sq/cq dbbuf pointers when dbbuf set fails proc: don't allow async path resolution of /proc/self components HID: Add Logitech Dinovo Edge battery quirk HID: logitech-hidpp: Add HIDPP_CONSUMER_VENDOR_KEYS quirk for the Dinovo Edge x86/xen: don't unbind uninitialized lock_kicker_irq dmaengine: xilinx_dma: use readl_poll_timeout_atomic variant HID: add HID_QUIRK_INCREMENT_USAGE_ON_DUPLICATE for Gamevice devices staging: ralink-gdma: fix kconfig dependency bug for DMA_RALINK HID: hid-sensor-hub: Fix issue with devices with no report ID Input: i8042 - allow insmod to succeed on devices without an i8042 controller HID: add support for Sega Saturn HID: cypress: Support Varmilo Keyboards' media hotkeys HID: ite: Replace ABS_MISC 120/121 events with touchpad on/off keypresses HID: uclogic: Add ID for Trust Flex Design Tablet arm64: pgtable: Ensure dirty bit is preserved across pte_wrprotect() arm64: pgtable: Fix pte_accessible() trace: fix potenial dangerous pointer KVM: x86: Fix split-irqchip vs interrupt injection window request KVM: x86: handle !lapic_in_kernel case in kvm_cpu_*_extint KVM: arm64: vgic-v3: Drop the reporting of GICR_TYPER.Last for userspace KVM: PPC: Book3S HV: XIVE: Fix possible oops when accessing ESB page cifs: fix a memleak with modefromsid smb3: Handle error case during offload read path smb3: Avoid Mid pending list corruption smb3: Call cifs reconnect from demultiplex thread wireless: Use linux/stddef.h instead of stddef.h btrfs: fix lockdep splat when reading qgroup config on mount btrfs: don't access possibly stale fs_info data for printing duplicate device btrfs: tree-checker: add missing returns after data_ref alignment checks btrfs: tree-checker: add missing return after error in root_item netfilter: clear skb->next in NF_HOOK_LIST() ipv4: use IS_ENABLED instead of ifdef spi: bcm2835: Fix use-after-free on unbind spi: bcm-qspi: Fix use-after-free on unbind Revert "Exempt multicast addresses from five-second neighbor lifetime" Linux 5.4.80 sched/fair: Fix overutilized update in enqueue_task_fair() mm, page_alloc: skip ->waternark_boost for atomic order-0 allocations mm/userfaultfd: do not access vma->vm_mm after calling handle_userfault() mm: memcg/slab: fix root memcg vmstats x86/microcode/intel: Check patch signature before saving microcode for early loading seccomp: Set PF_SUPERPRIV when checking capability ptrace: Set PF_SUPERPRIV when checking capability mmc: sdhci-pci: Prefer SDR25 timing for High Speed mode for BYT-based Intel controllers drm/i915: Handle max_bpc==16 drm/amd/display: Add missing pflip irq for dcn2.0 Drivers: hv: vmbus: Allow cleanup of VMBUS_CONNECT_CPU if disconnected s390/dasd: fix null pointer dereference for ERP requests s390/cpum_sf.c: fix file permission for cpum_sfb_size mac80211: free sta in sta_info_insert_finish() on errors mac80211: minstrel: fix tx status processing corner case mac80211: minstrel: remove deferred sampling code xtensa: disable preemption around cache alias management calls xtensa: fix TLBTEMP area placement regulator: workaround self-referent regulators regulator: avoid resolve_supply() infinite recursion regulator: fix memory leak with repeated set_machine_constraints() regulator: pfuze100: limit pfuze-support-disable-sw to pfuze{100,200} spi: bcm2835aux: Fix use-after-free on unbind spi: npcm-fiu: Don't leak SPI master in probe error path spi: Introduce device-managed SPI controller allocation spi: lpspi: Fix use-after-free on unbind iio: adc: mediatek: fix unset field iio: accel: kxcjk1013: Add support for KIOX010A ACPI DSM for setting tablet-mode iio: accel: kxcjk1013: Replace is_smo8500_device with an acpi_type enum ext4: fix bogus warning in ext4_update_dx_flag() iio: light: fix kconfig dependency bug for VCNL4035 staging: rtl8723bs: Add 024c:0627 to the list of SDIO device-ids efivarfs: fix memory leak in efivarfs_create() HID: logitech-dj: Fix an error in mse_bluetooth_descriptor tty: serial: imx: keep console clocks always on tty: serial: imx: fix potential deadlock ALSA: hda/realtek: Add some Clove SSID in the ALC293(ALC1220) ALSA: hda/realtek - Add supported for Lenovo ThinkPad Headset Button ALSA: mixart: Fix mutex deadlock ALSA: ctl: fix error path at adding user-defined element set ALSA: usb-audio: Add delay quirk for all Logitech USB devices ALSA: firewire: Clean up a locking issue in copy_resp_to_buf() speakup: Do not let the line discipline be used several times HID: logitech-dj: Fix Dinovo Mini when paired with a MX5x00 receiver HID: logitech-dj: Handle quad/bluetooth keyboards with a builtin trackpad HID: logitech-hidpp: Add PID for MX Anywhere 2 libfs: fix error cast of negative value in simple_attr_write() efi/x86: Free efi_pgd with free_pages() bpf, sockmap: Avoid returning unneeded EAGAIN when redirecting to self bpf, sockmap: Use truesize with sk_rmem_schedule() bpf, sockmap: On receive programs try to fast track SK_PASS ingress bpf, sockmap: Skb verdict SK_PASS to self already checked rmem limits xfs: revert "xfs: fix rmap key and record comparison functions" fail_function: Remove a redundant mutex unlock regulator: ti-abb: Fix array out of bound read access on the first transition xfs: return corresponding errcode if xfs_initialize_perag() fail xfs: strengthen rmap record flags checking xfs: fix the minrecs logic when dealing with inode root child blocks can: m_can: process interrupt only when not runtime suspended can: flexcan: flexcan_chip_start(): fix erroneous flexcan_transceiver_enable() during bus-off recovery iommu/vt-d: Avoid panic if iommu init fails in tboot system iommu/vt-d: Move intel_iommu_gfx_mapped to Intel IOMMU header can: kvaser_usb: kvaser_usb_hydra: Fix KCAN bittiming limits can: kvaser_pciefd: Fix KCAN bittiming limits bpf, sockmap: Ensure SO_RCVBUF memory is observed on ingress redirect bpf, sockmap: Fix partial copy_page_to_iter so progress can still be made net/mlx5: E-Switch, Fail mlx5_esw_modify_vport_rate if qos disabled drm/sun4i: dw-hdmi: fix error return code in sun8i_dw_hdmi_bind() MIPS: Alchemy: Fix memleak in alchemy_clk_setup_cpu selftests/bpf: Fix error return code in run_getsockopt_test() ASoC: qcom: lpass-platform: Fix memory leak can: m_can: m_can_stop(): set device to software init mode before closing can: m_can: m_can_class_free_dev(): introduce new function can: m_can: m_can_handle_state_change(): fix state change can: tcan4x5x: tcan4x5x_can_remove(): fix order of deregistration can: tcan4x5x: tcan4x5x_can_probe(): add missing error checking for devm_regmap_init() can: tcan4x5x: replace depends on REGMAP_SPI with depends on SPI can: flexcan: fix failure handling of pm_runtime_get_sync() can: peak_usb: fix potential integer overflow on shift of a int can: mcba_usb: mcba_usb_start_xmit(): first fill skb, then pass to can_put_echo_skb() can: ti_hecc: Fix memleak in ti_hecc_probe can: dev: can_restart(): post buffer from the right context can: af_can: prevent potential access of uninitialized member in canfd_rcv() can: af_can: prevent potential access of uninitialized member in can_rcv() ip_tunnels: Set tunnel option flag when tunnel metadata is present tools, bpftool: Add missing close before bpftool net attach exit perf lock: Don't free "lock_seq_stat" if read_count isn't zero RMDA/sw: Don't allow drivers using dma_virt_ops on highmem configs RDMA/pvrdma: Fix missing kfree() in pvrdma_register_device() rfkill: Fix use-after-free in rfkill_resume() Input: resistive-adc-touch - fix kconfig dependency on IIO_BUFFER ARM: dts: imx50-evk: Fix the chip select 1 IOMUX arm64: dts: imx8mm: fix voltage for 1.6GHz CPU operating point swiotlb: using SIZE_MAX needs limits.h included arm: dts: imx6qdl-udoo: fix rgmii phy-mode for ksz9031 phy arm64: dts imx8mn: Remove non-existent USB OTG2 arm64: dts: allwinner: h5: OrangePi Prime: Fix ethernet node MIPS: export has_transparent_hugepage() for modules Input: adxl34x - clean up a data type in adxl34x_probe() arm64: dts: allwinner: a64: bananapi-m64: Enable RGMII RX/TX delay on PHY ARM: dts: sunxi: bananapi-m2-plus: Enable RGMII RX/TX delay on Ethernet PHY ARM: dts: sun9i: Enable both RGMII RX/TX delay on Ethernet PHY ARM: dts: sun8i: a83t: Enable both RGMII RX/TX delay on Ethernet PHY ARM: dts: sun8i: h3: orangepi-plus2e: Enable RGMII RX/TX delay on Ethernet PHY ARM: dts: sun7i: bananapi-m1-plus: Enable RGMII RX/TX delay on Ethernet PHY ARM: dts: sun7i: cubietruck: Enable RGMII RX/TX delay on Ethernet PHY ARM: dts: sun6i: a31-hummingbird: Enable RGMII RX/TX delay on Ethernet PHY Revert "arm: sun8i: orangepi-pc-plus: Set EMAC activity LEDs to active high" ARM: dts: sun8i: r40: bananapi-m2-ultra: Fix ethernet node arm64: dts: allwinner: h5: OrangePi PC2: Fix ethernet node arm64: dts: allwinner: a64: Pine64 Plus: Fix ethernet node arm64: dts: allwinner: a64: OrangePi Win: Fix ethernet node arm64: dts: allwinner: Pine H64: Enable both RGMII RX/TX delay arm64: dts: allwinner: beelink-gs1: Enable both RGMII RX/TX delay hwmon: (pwm-fan) Fix RPM calculation gfs2: fix possible reference leak in gfs2_check_blk_type vfs: remove lockdep bogosity in __sb_start_write arm64: smp: Tell RCU about CPUs that fail to come online arm64: psci: Avoid printing in cpu_psci_cpu_die() arm64: errata: Fix handling of1418040with late CPU onlining ACPI: button: Add DMI quirk for Medion Akoya E2228T selftests: kvm: Fix the segment descriptor layout to match the actual layout scsi: ufs: Fix unbalanced scsi_block_reqs_cnt caused by ufshcd_hold() pinctrl: rockchip: enable gpio pclk for rockchip_gpio_to_irq net: ftgmac100: Fix crash when removing driver net/ncsi: Fix netlink registration net: usb: qmi_wwan: Set DTR quirk for MR400 net/mlx5: Disable QoS when min_rates on all VFs are zero net/mlx5: Add handling of port type in rule deletion tcp: only postpone PROBE_RTT if RTT is < current min_rtt estimate sctp: change to hold/put transport for proto_unreach_timer qlcnic: fix error return code in qlcnic_83xx_restart_hw() qed: fix error return code in qed_iwarp_ll2_start() page_frag: Recover from memory pressure net: x25: Increase refcnt of "struct x25_neigh" in x25_rx_call_request net/tls: fix corrupted data in recvmsg net/smc: fix direct access to ib_gid_addr->ndev in smc_ib_determine_gid() net: qualcomm: rmnet: Fix incorrect receive packet handling during cleanup net/mlx4_core: Fix init_hca fields offset net: lantiq: Wait for the GPHY firmware to be ready netlabel: fix an uninitialized warning in netlbl_unlabel_staticlist() netlabel: fix our progress tracking in netlbl_unlabel_staticlist() net: Have netpoll bring-up DSA management interface net: ethernet: ti: cpsw: fix error return code in cpsw_probe() net: dsa: mv88e6xxx: Avoid VTU corruption on 6097 net: bridge: add missing counters to ndo_get_stats64 callback net: b44: fix error return code in b44_init_one() mlxsw: core: Use variable timeout for EMAD retries lan743x: prevent entire kernel HANG on open, for some platforms lan743x: fix issue causing intermittent kernel log warnings ipv6: Fix error path to cancel the meseage inet_diag: Fix error path to cancel the meseage in inet_req_diag_fill() Exempt multicast addresses from five-second neighbor lifetime devlink: Add missing genlmsg_cancel() in devlink_nl_sb_port_pool_fill() bnxt_en: read EEPROM A2h address using page 0 atm: nicstar: Unmap DMA on send error ah6: fix error return code in ah6_input() Linux 5.4.79 ACPI: GED: fix -Wformat KVM: x86: clflushopt should be treated as a no-op by emulation can: proc: can_remove_proc(): silence remove_proc_entry warning mac80211: always wind down STA state Input: sunkbd - avoid use-after-free in teardown paths net: lantiq: Add locking for TX DMA channel powerpc/8xx: Always fault when _PAGE_ACCESSED is not set net/mlx5: Add retry mechanism to the command entry index allocation net/mlx5: Fix a race when moving command interface to events mode net/mlx5: poll cmd EQ in case of command timeout net/mlx5: Use async EQ setup cleanup helpers for multiple EQs MIPS: PCI: Fix MIPS build selftests/powerpc: entry flush test powerpc: Only include kup-radix.h for 64-bit Book3S powerpc/64s: flush L1D after user accesses powerpc/64s: flush L1D on kernel entry selftests/powerpc: rfi_flush: disable entry flush if present Linux 5.4.78 Convert trailing spaces and periods in path components net: sch_generic: fix the missing new qdisc assignment bug perf/core: Fix race in the perf_mmap_close() function perf scripting python: Avoid declaring function pointers with a visibility attribute x86/speculation: Allow IBPB to be conditionally enabled on CPUs with always-on STIBP powerpc/603: Always fault when _PAGE_ACCESSED is not set drm/i915: Correctly set SFC capability for video engines r8169: fix potential skb double free in an error path tipc: fix memory leak in tipc_topsrv_start() net/x25: Fix null-ptr-deref in x25_connect net: Update window_clamp if SOCK_RCVBUF is set net: udp: fix UDP header access on Fast/frag0 UDP GRO net/af_iucv: fix null pointer dereference on shutdown IPv6: Set SIT tunnel hard_header_len to zero swiotlb: fix "x86: Don't panic if can not alloc buffer for swiotlb" pinctrl: amd: fix incorrect way to disable debounce filter pinctrl: amd: use higher precision for 512 RtcClk drm/gma500: Fix out-of-bounds access to struct drm_device.vblank[] don't dump the threads that had been already exiting when zapped. mmc: renesas_sdhi_core: Add missing tmio_mmc_host_free() at remove mmc: sdhci-of-esdhc: Handle pulse width detection erratum for more SoCs gpio: pcie-idio-24: Enable PEX8311 interrupts gpio: pcie-idio-24: Fix IRQ Enable Register value gpio: pcie-idio-24: Fix irq mask when masking selinux: Fix error return code in sel_ib_pkey_sid_slow() btrfs: fix potential overflow in cluster_pages_for_defrag on 32bit arch ocfs2: initialize ip_next_orphan reboot: fix overflow parsing reboot cpu number Revert "kernel/reboot.c: convert simple_strtoul to kstrtoint" mm/slub: fix panic in slab_alloc_node() jbd2: fix up sparse warnings in checkpoint code futex: Don't enable IRQs unconditionally in put_pi_state() mei: protect mei_cl_mtu from null dereference virtio: virtio_console: fix DMA memory allocation for rproc serial xhci: hisilicon: fix refercence leak in xhci_histb_probe usb: cdc-acm: Add DISABLE_ECHO for Renesas USB Download mode uio: Fix use-after-free in uio_unregister_device() thunderbolt: Add the missed ida_simple_remove() in ring_request_msix() thunderbolt: Fix memory leak if ida_simple_get() fails in enumerate_services() KVM: arm64: Don't hide ID registers from userspace btrfs: dev-replace: fail mount if we don't have replace item with target device btrfs: fix min reserved size calculation in merge_reloc_root btrfs: ref-verify: fix memory leak in btrfs_ref_tree_mod ext4: unlock xattr_sem properly in ext4_inline_data_truncate() ext4: correctly report "not supported" for {usr,grp}jquota when !CONFIG_QUOTA erofs: derive atime instead of leaving it empty perf: Fix get_recursion_context() vrf: Fix fast path output packet handling with async Netfilter rules cosa: Add missing kfree in error path of cosa_write of/address: Fix of_node memory leak in of_dma_is_coherent xfs: fix a missing unlock on error in xfs_fs_map_blocks lan743x: fix "BUG: invalid wait context" when setting rx mode xfs: fix brainos in the refcount scrubber's rmap fragment processor xfs: fix rmap key and record comparison functions xfs: set the unwritten bit in rmap lookup flags in xchk_bmap_get_rmapextents xfs: fix flags argument to rmap lookup when converting shared file rmaps igc: Fix returning wrong statistics nbd: fix a block_device refcount leak in nbd_release bpf: Zero-fill re-used per-cpu map element SUNRPC: Fix general protection fault in trace_rpc_xdr_overflow() net/mlx5: Fix deletion of duplicate rules pinctrl: aspeed: Fix GPI only function problem. bpf: Don't rely on GCC __attribute__((optimize)) to disable GCSE ARM: 9019/1: kprobes: Avoid fortify_panic() when copying optprobe template pinctrl: intel: Set default bias in case no particular value given mfd: sprd: Add wakeup capability for PMIC IRQ tick/common: Touch watchdog in tick_unfreeze() on all CPUs spi: bcm2835: remove use of uninitialized gpio flags variable tpm_tis: Disable interrupts on ThinkPad T490s i2c: sh_mobile: implement atomic transfers riscv: Set text_offset correctly for M-Mode selftests: proc: fix warning: _GNU_SOURCE redefined amd/amdgpu: Disable VCN DPG mode for Picasso i2c: mediatek: move dma reset before i2c reset vfio/pci: Bypass IGD init in case of -ENODEV vfio: platform: fix reference leak in vfio_platform_open s390/smp: move rcu_cpu_starting() earlier iommu/amd: Increase interrupt remapping table limit to 512 entries nvme-tcp: avoid repeated request completion nvme-rdma: avoid repeated request completion nvme-tcp: avoid race between time out and tear down nvme-rdma: avoid race between time out and tear down nvme: introduce nvme_sync_io_queues scsi: mpt3sas: Fix timeouts observed while reenabling IRQ scsi: scsi_dh_alua: Avoid crash during alua_bus_detach() tracing: Fix the checking of stackidx in __ftrace_trace_stack cfg80211: regulatory: Fix inconsistent format argument cfg80211: initialize wdev data earlier mac80211: fix use of skb payload instead of header drm/amd/pm: do not use ixFEATURE_STATUS for checking smc running drm/amd/pm: perform SMC reset on suspend/hibernation drm/amdgpu: perform srbm soft reset always on SDMA resume scsi: hpsa: Fix memory leak in hpsa_init_one() gfs2: check for live vs. read-only file system in gfs2_fitrim gfs2: Add missing truncate_inode_pages_final for sd_aspace gfs2: Free rd_bits later in gfs2_clear_rgrpd to fix use-after-free ALSA: hda: Reinstate runtime_allow() for all hda controllers ALSA: hda: Separate runtime and system suspend selftests: pidfd: fix compilation errors due to wait.h selftests/ftrace: check for do_sys_openat2 in user-memory test usb: gadget: goku_udc: fix potential crashes in probe opp: Reduce the size of critical section in _opp_table_kref_release() usb: dwc3: pci: add support for the Intel Alder Lake-S ASoC: cs42l51: manage mclk shutdown delay ASoC: qcom: sdm845: set driver name correctly ath9k_htc: Use appropriate rs_datalen type KVM: x86: don't expose MSR_IA32_UMWAIT_CONTROL unconditionally KVM: arm64: ARM_SMCCC_ARCH_WORKAROUND_1 doesn't return SMCCC_RET_NOT_REQUIRED random32: make prandom_u32() output unpredictable tpm: efi: Don't create binary_bios_measurements file for an empty log xfs: fix scrub flagging rtinherit even if there is no rt device xfs: flush new eof page on truncate to avoid post-eof corruption can: flexcan: flexcan_remove(): disable wakeup completely can: flexcan: remove FLEXCAN_QUIRK_DISABLE_MECR quirk for LS1021A can: peak_canfd: pucan_handle_can_rx(): fix echo management when loopback is on can: peak_usb: peak_usb_get_ts_time(): fix timestamp wrapping can: peak_usb: add range checking in decode operations can: xilinx_can: handle failure cases of pm_runtime_get_sync can: ti_hecc: ti_hecc_probe(): add missed clk_disable_unprepare() in error path can: j1939: j1939_sk_bind(): return failure if netdev is down can: j1939: swap addr and pgn in the send example can: can_create_echo_skb(): fix echo skb generation: always use skb_clone() can: dev: __can_get_echo_skb(): fix real payload length return value for RTR frames can: dev: can_get_echo_skb(): prevent call to kfree_skb() in hard IRQ context can: rx-offload: don't call kfree_skb() from IRQ context afs: Fix warning due to unadvanced marshalling pointer iommu/vt-d: Fix a bug for PDP check in prq_event_thread ALSA: hda: prevent undefined shift in snd_hdac_ext_bus_get_link() perf tools: Add missing swap for ino_generation perf trace: Fix segfault when trying to trace events by cgroup powerpc/eeh_cache: Fix a possible debugfs deadlock netfilter: ipset: Update byte and packet counters regardless of whether they match netfilter: nf_tables: missing validation from the abort path netfilter: use actual socket sk rather than skb sk when routing harder xfs: set xefi_discard when creating a deferred agfl free log intent item ASoC: codecs: wcd9335: Set digital gain range correctly net: xfrm: fix a race condition during allocing spi hv_balloon: disable warning when floor reached genirq: Let GENERIC_IRQ_IPI select IRQ_DOMAIN_HIERARCHY ASoC: Intel: kbl_rt5663_max98927: Fix kabylake_ssp_fixup function btrfs: reschedule when cloning lots of extents btrfs: sysfs: init devices outside of the chunk_mutex btrfs: tracepoints: output proper root owner for trace_find_free_extent() usb: dwc3: gadget: Reclaim extra TRBs after request completion usb: dwc3: gadget: Continue to process pending requests PCI: qcom: Make sure PCIe is reset before init for rev 2.1.0 KVM: arm64: Force PTE mapping on fault resulting in a device mapping nbd: don't update block size after device is started time: Prevent undefined behaviour in timespec64_to_ns() drm/i915/gem: Flush coherency domains on first set-domain-ioctl Linux 5.4.77 powercap: restrict energy meter to root access Linux 5.4.76 arm64: dts: marvell: espressobin: Add ethernet switch aliases perf/core: Fix a memory leak in perf_event_parse_addr_filter() xfs: flush for older, xfs specific ioctls PM: runtime: Resume the device earlier in __device_release_driver() PM: runtime: Drop pm_runtime_clean_up_links() PM: runtime: Drop runtime PM references to supplier on link removal ARC: stack unwinding: avoid indefinite looping drm/panfrost: Fix a deadlock between the shrinker and madvise path usb: mtu3: fix panic in mtu3_gadget_stop() USB: Add NO_LPM quirk for Kingston flash drive usb: dwc3: ep0: Fix delay status handling tty: serial: fsl_lpuart: LS1021A has a FIFO size of 16 words, like LS1028A tty: serial: fsl_lpuart: add LS1028A support USB: serial: option: add Telit FN980 composition 0x1055 USB: serial: option: add LE910Cx compositions 0x1203, 0x1230, 0x1231 USB: serial: option: add Quectel EC200T module support USB: serial: cyberjack: fix write-URB completion race serial: txx9: add missing platform_driver_unregister() on error in serial_txx9_init serial: 8250_mtk: Fix uart_get_baud_rate warning s390/pkey: fix paes selftest failure with paes and pkey static build fork: fix copy_process(CLONE_PARENT) race with the exiting ->real_parent vt: Disable KD_FONT_OP_COPY Revert "coresight: Make sysfs functional on topologies with per core sink" arm64/smp: Move rcu_cpu_starting() earlier drm/nouveau/gem: fix "refcount_t: underflow; use-after-free" drm/nouveau/nouveau: fix the start/end range for migration usb: cdns3: gadget: suspicious implicit sign extension ACPI: NFIT: Fix comparison to '-ENXIO' drm/vc4: drv: Add error handding for bind nvmet: fix a NULL pointer dereference when tracing the flush command nvme-rdma: handle unexpected nvme completion data length vsock: use ns_capable_noaudit() on socket create scsi: ibmvscsi: Fix potential race after loss of transport drm/amdgpu: add DID for navi10 blockchain SKU scsi: core: Don't start concurrent async scan on same host blk-cgroup: Pre-allocate tree node on blkg_conf_prep blk-cgroup: Fix memleak on error path drm/sun4i: frontend: Fix the scaler phase on A33 drm/sun4i: frontend: Reuse the ch0 phase for RGB formats drm/sun4i: frontend: Rework a bit the phase data of: Fix reserved-memory overlap detection x86/kexec: Use up-to-dated screen_info copy to fill boot params arm64: dts: meson: add missing g12 rng clock ARM: dts: sun4i-a10: fix cpu_alert temperature futex: Handle transient "ownerless" rtmutex state correctly tracing: Fix out of bounds write in get_trace_buf spi: bcm2835: fix gpio cs level inversion regulator: defer probe when trying to get voltage from unresolved supply ftrace: Handle tracing when switching between context ftrace: Fix recursion check for NMI test mtd: spi-nor: Don't copy self-pointing struct around ring-buffer: Fix recursion protection transitions between interrupt context gfs2: Wake up when sd_glock_disposal becomes zero mm: always have io_remap_pfn_range() set pgprot_decrypted() kthread_worker: prevent queuing delayed work from timer_fn when it is being canceled lib/crc32test: remove extra local_irq_disable/enable mm: mempolicy: fix potential pte_unmap_unlock pte error ALSA: usb-audio: Add implicit feedback quirk for MODX ALSA: usb-audio: Add implicit feedback quirk for Qu-16 ALSA: usb-audio: add usb vendor id as DSD-capable for Khadas devices ALSA: usb-audio: Add implicit feedback quirk for Zoom UAC-2 ALSA: hda/realtek - Enable headphone for ASUS TM420 ALSA: hda/realtek - Fixed HP headset Mic can't be detected Fonts: Replace discarded const qualifier sfp: Fix error handing in sfp_probe() sctp: Fix COMM_LOST/CANT_STR_ASSOC err reporting on big-endian platforms powerpc/vnic: Extend "failover pending" window net: usb: qmi_wwan: add Telit LE910Cx 0x1230 composition ip_tunnel: fix over-mtu packet send fail without TUNNEL_DONT_FRAGMENT flags ionic: check port ptr before use gianfar: Account for Tx PTP timestamp in the skb headroom gianfar: Replace skb_realloc_headroom with skb_cow_head for PTP chelsio/chtls: fix always leaking ctrl_skb chelsio/chtls: fix memory leaks caused by a race cadence: force nonlinear buffers to be cloned ptrace: fix task_join_group_stop() for the case when current is traced tipc: fix use-after-free in tipc_bcast_get_mode arm64: Change .weak to SYM_FUNC_START_WEAK_PI for arch/arm64/lib/mem*.S arm64: lib: Use modern annotations for assembly functions arm64: asm: Add new-style position independent function annotations linkage: Introduce new macros for assembler symbols ASoC: Intel: Skylake: Add alternative topology binary name drm/i915: Drop runtime-pm assert from vgpu io accessors drm/i915/gt: Delay execlist processing for tgl drm/i915: Break up error capture compression loops with cond_resched() Linux 5.4.75 staging: octeon: Drop on uncorrectable alignment or FCS error staging: octeon: repair "fixed-link" support staging: comedi: cb_pcidas: Allow 2-channel commands for AO subdevice staging: fieldbus: anybuss: jump to correct label in an error path KVM: arm64: Fix AArch32 handling of DBGD{CCINT,SCRext} and DBGVCR device property: Don't clear secondary pointer for shared primary firmware node device property: Keep secondary firmware node secondary by type ARM: s3c24xx: fix missing system reset ARM: samsung: fix PM debug build with DEBUG_LL but !MMU arm: dts: mt7623: add missing pause for switchport hil/parisc: Disable HIL driver when it gets stuck cachefiles: Handle readpage error correctly arm64: berlin: Select DW_APB_TIMER_OF tty: make FONTX ioctl use the tty pointer they were actually passed drm/amd/pm: increase mclk switch threshold to 200 us mmc: sdhci: Use Auto CMD Auto Select only when v4_mode is true mmc: sdhci-of-esdhc: set timeout to max before tuning drm/ttm: fix eviction valuable range check. ext4: fix invalid inode checksum ext4: fix error handling code in add_new_gdb ext4: fix leaking sysfs kobject after failed mount vringh: fix __vringh_iov() when riov and wiov are different ring-buffer: Return 0 on success from ring_buffer_resize() 9P: Cast to loff_t before multiplying libceph: clear con->out_msg on Policy::stateful_server faults ceph: promote to unsigned long long before shifting drm/amd/display: Fix kernel panic by dal_gpio_open() error drm/amd/display: Don't invoke kgdb_breakpoint() unconditionally drm/amdgpu: increase the reserved VM size to 2MB drm/amd/display: Avoid MST manager resource leak. drm/amdkfd: Use same SQ prefetch setting as amdgpu drm/amdgpu: correct the gpu reset handling for job != NULL case drm/amd/display: Increase timeout for DP Disable drm/amdgpu: don't map BO in reserved region i2c: imx: Fix external abort on interrupt in exit paths rtc: rx8010: don't modify the global rtc ops ia64: fix build error with !COREDUMP ubi: check kthread_should_stop() after the setting of task state ARC: perf: redo the pct irq missing in device-tree handling perf python scripting: Fix printable strings in python3 scripts ubifs: mount_ubifs: Release authentication resource in error handling path ubifs: Don't parse authentication mount options in remount process ubifs: Fix a memleak after dumping authentication mount options ubifs: journal: Make sure to not dirty twice for auth nodes ubifs: xattr: Fix some potential memory leaks while iterating entries ubifs: dent: Fix some potential memory leaks while iterating entries NFSD: Add missing NFSv2 .pc_func methods NFSv4.2: support EXCHGID4_FLAG_SUPP_FENCE_OPS 4.2 EXCHANGE_ID flag NFSv4: Wait for stateid updates after CLOSE/OPEN_DOWNGRADE powerpc: Fix undetected data corruption with P9N DD2.1 VSX CI load emulation powerpc/powermac: Fix low_sleep_handler with KUAP and KUEP powerpc/powernv/elog: Fix race while processing OPAL error log event. powerpc/memhotplug: Make lmb size 64bit powerpc: Warn about use of smt_snooze_delay powerpc/rtas: Restrict RTAS requests from userspace s390/stp: add locking to sysfs functions MIPS: DEC: Restore bootmem reservation for firmware working memory area powerpc/drmem: Make lmb_size 64 bit iio:gyro:itg3200: Fix timestamp alignment and prevent data leak. iio:adc:ti-adc12138 Fix alignment issue with timestamp iio:adc:ti-adc0832 Fix alignment issue with timestamp iio: adc: gyroadc: fix leak of device node iterator iio:light:si1145: Fix timestamp alignment and prevent data leak. dmaengine: dma-jz4780: Fix race in jz4780_dma_tx_status udf: Fix memory leak when mounting HID: wacom: Avoid entering wacom_wac_pen_report for pad / battery vt: keyboard, extend func_buf_lock to readers vt: keyboard, simplify vt_kdgkbsent drm/i915: Force VT'd workarounds when running as a guest OS usb: host: fsl-mph-dr-of: check return of dma_set_mask() usb: typec: tcpm: reset hard_reset_count for any disconnect usb: cdc-acm: fix cooldown mechanism usb: dwc3: gadget: END_TRANSFER before CLEAR_STALL command usb: dwc3: gadget: Resume pending requests after CLEAR_STALL usb: dwc3: core: don't trigger runtime pm when remove driver usb: dwc3: core: add phy cleanup for probe error handling usb: dwc3: gadget: Check MPS of the request length usb: dwc3: ep0: Fix ZLP for OUT ep0 requests usb: dwc3: pci: Allow Elkhart Lake to utilize DSM method for PM functionality usb: xhci: Workaround for S3 issue on AMD SNPS 3.0 xHC btrfs: fix readahead hang and use-after-free after removing a device btrfs: fix use-after-free on readahead extent after failure to create it btrfs: tree-checker: validate number of chunk stripes and parity btrfs: cleanup cow block on error btrfs: tree-checker: fix false alert caused by legacy btrfs root item btrfs: use kvzalloc() to allocate clone_roots in btrfs_ioctl_send() btrfs: send, recompute reference path after orphanization of a directory btrfs: send, orphanize first all conflicting inodes when processing references btrfs: reschedule if necessary when logging directory items btrfs: improve device scanning messages btrfs: qgroup: fix wrong qgroup metadata reserve for delayed inode PM: runtime: Remove link state checks in rpm_get/put_supplier() scsi: qla2xxx: Fix crash on session cleanup with unload scsi: mptfusion: Fix null pointer dereferences in mptscsih_remove() w1: mxc_w1: Fix timeout resolution problem leading to bus error acpi-cpufreq: Honor _PSD table setting on new AMD CPUs ACPI: EC: PM: Drop ec_no_wakeup check from acpi_ec_dispatch_gpe() ACPI: EC: PM: Flush EC work unconditionally after wakeup PCI/ACPI: Whitelist hotplug ports for D3 if power managed by ACPI ACPI: debug: don't allow debugging when ACPI is disabled ACPI: video: use ACPI backlight for HP 635 Notebook ACPI / extlog: Check for RDMSR failure ACPI: button: fix handling lid state changes when input device closed NFS: fix nfs_path in case of a rename retry fs: Don't invalidate page buffers in block_write_full_page() media: uvcvideo: Fix uvc_ctrl_fixup_xu_info() not having any effect leds: bcm6328, bcm6358: use devres LED registering function extcon: ptn5150: Fix usage of atomic GPIO with sleeping GPIO chips spi: sprd: Release DMA channel also on probe deferral perf/x86/amd/ibs: Fix raw sample data accumulation perf/x86/amd/ibs: Don't include randomized bits in get_ibs_op_count() perf/x86/intel: Fix Ice Lake event constraint table selftests/x86/fsgsbase: Test PTRACE_PEEKUSER for GSBASE with invalid LDT GS seccomp: Make duplicate listener detection non-racy mmc: sdhci-acpi: AMDI0040: Set SDHCI_QUIRK2_PRESET_VALUE_BROKEN mmc: sdhci: Add LTR support for some Intel BYT based controllers md/raid5: fix oops during stripe resizing nvme-rdma: fix crash when connect rejected sgl_alloc_order: fix memory leak nbd: make the config put is called before the notifying the waiter ARM: dts: s5pv210: remove dedicated 'audio-subsystem' node ARM: dts: s5pv210: move PMU node out of clock controller ARM: dts: s5pv210: move fixed clocks under root node ARM: dts: s5pv210: remove DMA controller bus node name to fix dtschema warnings memory: emif: Remove bogus debugfs error handling ARM: dts: omap4: Fix sgx clock rate for 4430 arm64: dts: renesas: ulcb: add full-pwr-cycle-in-suspend into eMMC nodes cifs: handle -EINTR in cifs_setattr gfs2: add validation checks for size of superblock gfs2: use-after-free in sysfs deregistration KVM: PPC: Book3S HV: Do not allocate HPT for a nested guest ext4: Detect already used quota file early drivers: watchdog: rdc321x_wdt: Fix race condition bugs net: 9p: initialize sun_server.sun_path to have addr's value only when addr is valid clk: ti: clockdomain: fix static checker warning rpmsg: glink: Use complete_all for open states bnxt_en: Log unknown link speed appropriately. md/bitmap: md_bitmap_get_counter returns wrong blocks btrfs: fix replace of seed device ARC: [dts] fix the errors detected by dtbs_check drm/amd/display: HDMI remote sink need mode validation for Linux power: supply: test_power: add missing newlines when printing parameters by sysfs ACPI: HMAT: Fix handling of changes from ACPI 6.2 to ACPI 6.3 bus/fsl_mc: Do not rely on caller to provide non NULL mc_io drivers/net/wan/hdlc_fr: Correctly handle special skb->protocol values brcmfmac: Fix warning message after dongle setup failed ACPI: Add out of bounds and numa_off protections to pxm_to_node() xfs: don't free rt blocks when we're doing a REMAP bunmapi call can: flexcan: disable clocks during stop mode arm64/mm: return cpu_all_mask when node is NUMA_NO_NODE SUNRPC: Mitigate cond_resched() in xprt_transmit() usb: xhci: omit duplicate actions when suspending a runtime suspended host. coresight: Make sysfs functional on topologies with per core sink uio: free uio id after uio file node is freed USB: adutux: fix debugging cpufreq: sti-cpufreq: add stih418 support riscv: Define AT_VECTOR_SIZE_ARCH for ARCH_DLINFO samples/bpf: Fix possible deadlock in xdpsock selftests/bpf: Define string const as global for test_sysctl_prog.c media: uvcvideo: Fix dereference of out-of-bound list iterator bpf: Permit map_ptr arithmetic with opcode add and offset 0 kgdb: Make "kgdbcon" work properly with "kgdb_earlycon" ia64: kprobes: Use generic kretprobe trampoline handler printk: reduce LOG_BUF_SHIFT range for H8300 arm64: topology: Stop using MPIDR for topology information drm/bridge/synopsys: dsi: add support for non-continuous HS clock mmc: via-sdmmc: Fix data race bug media: imx274: fix frame interval handling media: tw5864: check status of tw5864_frameinterval_get usb: typec: tcpm: During PR_SWAP, source caps should be sent only after tSwapSourceStart media: platform: Improve queue set up flow for bug fixing media: videodev2.h: RGB BT2020 and HSV are always full range selftests/x86/fsgsbase: Reap a forgotten child drm/brige/megachips: Add checking if ge_b850v3_lvds_init() is working correctly ath10k: fix VHT NSS calculation when STBC is enabled ath10k: start recovery process when payload length exceeds max htc length for sdio video: fbdev: pvr2fb: initialize variables xfs: fix realtime bitmap/summary file truncation when growing rt volume power: supply: bq27xxx: report "not charging" on all types NFS4: Fix oops when copy_file_range is attempted with NFS4.0 source ARM: 8997/2: hw_breakpoint: Handle inexact watchpoint addresses f2fs: handle errors of f2fs_get_meta_page_nofail um: change sigio_spinlock to a mutex s390/startup: avoid save_area_sync overflow f2fs: fix to check segment boundary during SIT page readahead f2fs: fix uninit-value in f2fs_lookup f2fs: add trace exit in exception path sparc64: remove mm_cpumask clearing to fix kthread_use_mm race powerpc: select ARCH_WANT_IRQS_OFF_ACTIVATE_MM mm: fix exec activate_mm vs TLB shootdown and lazy tlb switching race powerpc/powernv/smp: Fix spurious DBG() warning futex: Fix incorrect should_fail_futex() handling ata: sata_nv: Fix retrieving of active qcs RDMA/qedr: Fix memory leak in iWARP CM mlxsw: core: Fix use-after-free in mlxsw_emad_trans_finish() x86/unwind/orc: Fix inactive tasks with stack pointer in %sp on GCC 10 compiled kernels firmware: arm_scmi: Add missing Rx size re-initialisation firmware: arm_scmi: Fix ARCH_COLD_RESET xen/events: block rogue events for some time xen/events: defer eoi in case of excessive number of events xen/events: use a common cpu hotplug hook for event channels xen/events: switch user event channels to lateeoi model xen/pciback: use lateeoi irq binding xen/pvcallsback: use lateeoi irq binding xen/scsiback: use lateeoi irq binding xen/netback: use lateeoi irq binding xen/blkback: use lateeoi irq binding xen/events: add a new "late EOI" evtchn framework xen/events: fix race in evtchn_fifo_unmask() xen/events: add a proper barrier to 2-level uevent unmasking xen/events: avoid removing an event channel while handling it ANDROID: GKI: fix up include/linux/pm.h to handle some abi changes Linux 5.4.74 phy: marvell: comphy: Convert internal SMCC firmware return codes to errno misc: rtsx: do not setting OC_POWER_DOWN reg in rtsx_pci_init_ocp() openrisc: Fix issue with get_user for 64-bit values crypto: x86/crc32c - fix building with clang ias xen/gntdev.c: Mark pages as dirty ata: sata_rcar: Fix DMA boundary mask PM: runtime: Fix timer_expires data type on 32-bit arches serial: pl011: Fix lockdep splat when handling magic-sysrq interrupt serial: qcom_geni_serial: To correct QUP Version detection logic mtd: lpddr: Fix bad logic in print_drs_error RDMA/addr: Fix race with netevent_callback()/rdma_addr_cancel() cxl: Rework error message for incompatible slots p54: avoid accessing the data mapped to streaming DMA evm: Check size of security.evm before using it bpf: Fix comment for helper bpf_current_task_under_cgroup() fuse: fix page dereference after free ata: ahci: mvebu: Make SATA PHY optional for Armada 3720 x86/xen: disable Firmware First mode for correctable memory errors arch/x86/amd/ibs: Fix re-arming IBS Fetch erofs: avoid duplicated permission check for "trusted." xattrs bnxt_en: Invoke cancel_delayed_work_sync() for PFs also. bnxt_en: Fix regression in workqueue cleanup logic in bnxt_remove_one(). bnxt_en: Re-write PCI BARs after PCI fatal error. net: hns3: Clear the CMDQ registers before unmapping BAR region tipc: fix memory leak caused by tipc_buf_append() tcp: Prevent low rmem stalls with SO_RCVLOWAT. ravb: Fix bit fields checking in ravb_hwtstamp_get() r8169: fix issue with forced threading in combination with shared interrupts net/sched: act_mpls: Add softdep on mpls_gso.ko netem: fix zero division in tabledist mlxsw: core: Fix memory leak on module removal ibmvnic: fix ibmvnic_set_mac gtp: fix an use-before-init in gtp_newlink() cxgb4: set up filter action after rewrites chelsio/chtls: fix tls record info to user chelsio/chtls: fix memory leaks in CPL handlers chelsio/chtls: fix deadlock issue bnxt_en: Send HWRM_FUNC_RESET fw command unconditionally. bnxt_en: Check abort error state in bnxt_open_nic(). efivarfs: Replace invalid slashes with exclamation marks in dentries. x86/PCI: Fix intel_mid_pci.c build error when ACPI is not enabled arm64: link with -z norelro regardless of CONFIG_RELOCATABLE arm64: Run ARCH_WORKAROUND_2 enabling code on all CPUs arm64: Run ARCH_WORKAROUND_1 enabling code on all CPUs scripts/setlocalversion: make git describe output more reliable objtool: Support Clang non-section symbols in ORC generation socket: don't clear SOCK_TSTAMP_NEW when SO_TIMESTAMPNS is disabled netfilter: nftables_offload: KASAN slab-out-of-bounds Read in nft_flow_rule_create Revert "PCI/IOV: Mark VFs as not implementing PCI_COMMAND_MEMORY" Revert "vfio/pci: Decouple PCI_COMMAND_MEMORY bit checks from is_virtfn" Linux 5.4.73 usb: gadget: f_ncm: allow using NCM in SuperSpeed Plus gadgets. eeprom: at25: set minimum read/write access stride to 1 usb: cdns3: gadget: free interrupt after gadget has deleted USB: cdc-wdm: Make wdm_flush() interruptible and add wdm_fsync(). usb: cdc-acm: add quirk to blacklist ETAS ES58X devices tty: serial: fsl_lpuart: fix lpuart32_poll_get_char tty: serial: lpuart: fix lpuart32_write usage s390/qeth: don't let HW override the configured port role net: korina: cast KSEG0 address to pointer in kfree ath10k: check idx validity in __ath10k_htt_rx_ring_fill_n() dmaengine: dw: Activate FIFO-mode for memory peripherals only dmaengine: dw: Add DMA-channels mask cell support scsi: ufs: ufs-qcom: Fix race conditions caused by ufs_qcom_testbus_config() usb: core: Solve race condition in anchor cleanup functions brcm80211: fix possible memleak in brcmf_proto_msgbuf_attach scsi: smartpqi: Avoid crashing kernel for controller issues ALSA: hda/ca0132 - Add new quirk ID for SoundBlaster AE-7. ALSA: hda/ca0132 - Add AE-7 microphone selection commands. mwifiex: don't call del_timer_sync() on uninitialized timer reiserfs: Fix memory leak in reiserfs_parse_options() ipvs: Fix uninit-value in do_ip_vs_set_ctl() Bluetooth: btusb: Fix memleak in btusb_mtk_submit_wmt_recv_urb tty: ipwireless: fix error handling fbmem: add margin check to fb_check_caps() scsi: qedi: Fix list_del corruption while removing active I/O scsi: qedi: Protect active command list to avoid list corruption scsi: qedf: Return SUCCESS if stale rport is encountered HID: ite: Add USB id match for Acer One S1003 keyboard dock Fix use after free in get_capset_info callback. rtl8xxxu: prevent potential memory leak brcmsmac: fix memory leak in wlc_phy_attach_lcnphy selftests/bpf: Fix test_sysctl_loop{1, 2} failure due to clang change scsi: qla2xxx: Warn if done() or free() are called on an already freed srb scsi: ibmvfc: Fix error return in ibmvfc_probe() iomap: fix WARN_ON_ONCE() from unprivileged users drm/msm/a6xx: fix a potential overflow issue Bluetooth: Only mark socket zapped after unlocking usb: ohci: Default to per-port over-current protection xfs: make sure the rt allocator doesn't run off the end opp: Prevent memory leak in dev_pm_opp_attach_genpd() reiserfs: only call unlock_new_inode() if I_NEW misc: rtsx: Fix memory leak in rtsx_pci_probe bpf: Limit caller's stack depth 256 for subprogs with tailcalls drm/panfrost: add amlogic reset quirk callback ath9k: hif_usb: fix race condition between usb_get_urb() and usb_kill_anchored_urbs() can: flexcan: flexcan_chip_stop(): add error handling and propagate error value usb: dwc3: simple: add support for Hikey 970 USB: cdc-acm: handle broken union descriptors rtw88: increse the size of rx buffer size udf: Avoid accessing uninitialized data on failed inode read udf: Limit sparing table size usb: gadget: function: printer: fix use-after-free in __lock_acquire usb: dwc3: Add splitdisable quirk for Hisilicon Kirin Soc misc: vop: add round_up(x,4) for vring_size to avoid kernel panic mic: vop: copy data to kernel space then write to io memory scsi: target: core: Add CONTROL field for trace events scsi: mvumi: Fix error return in mvumi_io_attach() PM: hibernate: remove the bogus call to get_gendisk() in software_resume() mac80211: handle lack of sband->bitrates in rates ip_gre: set dev->hard_header_len and dev->needed_headroom properly ntfs: add check for mft record size in superblock media: venus: core: Fix runtime PM imbalance in venus_probe fs: dlm: fix configfs memory leak media: venus: fixes for list corruption media: saa7134: avoid a shift overflow mmc: sdio: Check for CISTPL_VERS_1 buffer size media: uvcvideo: Ensure all probed info is returned to v4l2 x86/mce: Make mce_rdmsrl() panic on an inaccessible MSR media: media/pci: prevent memory leak in bttv_probe media: bdisp: Fix runtime PM imbalance on error media: platform: sti: hva: Fix runtime PM imbalance on error media: platform: s3c-camif: Fix runtime PM imbalance on error media: vsp1: Fix runtime PM imbalance on error media: exynos4-is: Fix a reference count leak media: exynos4-is: Fix a reference count leak due to pm_runtime_get_sync media: exynos4-is: Fix several reference count leaks due to pm_runtime_get_sync media: sti: Fix reference count leaks media: st-delta: Fix reference count leak in delta_run_work media: ati_remote: sanity check for both endpoints media: firewire: fix memory leak x86/mce: Add Skylake quirk for patrol scrub reported errors x86/asm: Replace __force_order with a memory clobber crypto: ccp - fix error handling block: ratelimit handle_bad_sector() message md/bitmap: fix memory leak of temporary bitmap i2c: core: Restore acpi_walk_dep_device_list() getting called after registering the ACPI i2c devs perf: correct SNOOPX field offset sched/features: Fix !CONFIG_JUMP_LABEL case NTB: hw: amd: fix an issue about leak system resources nvmet: fix uninitialized work for zero kato powerpc/pseries: Avoid using addr_to_pfn in real mode powerpc/powernv/dump: Fix race while processing OPAL dump lightnvm: fix out-of-bounds write to array devices->info[] ARM: dts: meson8: remove two invalid interrupt lines from the GPU node arm64: dts: zynqmp: Remove additional compatible string for i2c IPs ARM: OMAP2+: Restore MPU power domain if cpu_cluster_pm_enter() fails soc: fsl: qbman: Fix return value on success ARM: dts: owl-s500: Fix incorrect PPI interrupt specifiers arm64: dts: actions: limit address range for pinctrl node arm64: dts: renesas: r8a774c0: Fix MSIOF1 DMA channels arm64: dts: renesas: r8a77990: Fix MSIOF1 DMA channels arm64: dts: qcom: msm8916: Fix MDP/DSI interrupts arm64: dts: qcom: pm8916: Remove invalid reg size from wcd_codec arm64: dts: qcom: msm8916: Remove one more thermal trip point unit name arm64: dts: imx8mq: Add missing interrupts to GPC memory: fsl-corenet-cf: Fix handling of platform_get_irq() error memory: omap-gpmc: Fix build error without CONFIG_OF memory: omap-gpmc: Fix a couple off by ones arm64: dts: allwinner: h5: remove Mali GPU PMU module ARM: dts: sun8i: r40: bananapi-m2-ultra: Fix dcdc1 regulator ARM: s3c24xx: fix mmc gpio lookup tables ARM: at91: pm: of_node_put() after its usage ARM: dts: imx6sl: fix rng node arm64: dts: meson: vim3: correct led polarity netfilter: nf_fwd_netdev: clear timestamp in forwarding path netfilter: ebtables: Fixes dropping of small packets in bridge nat netfilter: conntrack: connection timeout after re-register scsi: bfa: Fix error return in bfad_pci_init() KVM: x86: emulating RDPID failure shall return #UD rather than #GP Input: sun4i-ps2 - fix handling of platform_get_irq() error Input: twl4030_keypad - fix handling of platform_get_irq() error Input: omap4-keypad - fix handling of platform_get_irq() error Input: ep93xx_keypad - fix handling of platform_get_irq() error Input: stmfts - fix a & vs && typo Input: imx6ul_tsc - clean up some errors in imx6ul_tsc_resume() SUNRPC: fix copying of multiple pages in gss_read_proxy_verf() clk: imx8mq: Fix usdhc parents order vfio iommu type1: Fix memory leak in vfio_iommu_type1_pin_pages vfio/pci: Clear token on bypass registration failure ext4: limit entries returned when counting fsmap records svcrdma: fix bounce buffers for unaligned offsets and multiple pages watchdog: sp5100: Fix definition of EFCH_PM_DECODEEN3 watchdog: Use put_device on error watchdog: Fix memleak in watchdog_cdev_register clk: bcm2835: add missing release if devm_clk_hw_register fails clk: at91: clk-main: update key before writing AT91_CKGR_MOR module: statically initialize init section freeing data clk: mediatek: add UART0 clock support clk: rockchip: Initialize hw to error to avoid undefined behavior pwm: img: Fix null pointer access in probe clk: keystone: sci-clk: fix parsing assigned-clock data during probe clk: qcom: gcc-sdm660: Fix wrong parent_map vfio/pci: Decouple PCI_COMMAND_MEMORY bit checks from is_virtfn PCI/IOV: Mark VFs as not implementing PCI_COMMAND_MEMORY rpmsg: smd: Fix a kobj leak in in qcom_smd_parse_edge() PCI: iproc: Set affinity mask on MSI interrupts PCI: aardvark: Check for errors from pci_bridge_emul_init() call clk: meson: g12a: mark fclk_div2 as critical i2c: rcar: Auto select RESET_CONTROLLER mailbox: avoid timer start from callback rapidio: fix the missed put_device() for rio_mport_add_riodev rapidio: fix error handling path ramfs: fix nommu mmap with gaps in the page cache lib/crc32.c: fix trivial typo in preprocessor condition mm/page_owner: change split_page_owner to take a count RDMA/rxe: Handle skb_clone() failure in rxe_recv.c f2fs: wait for sysfs kobject removal before freeing f2fs_sb_info selftests/powerpc: Fix eeh-basic.sh exit codes maiblox: mediatek: Fix handling of platform_get_irq() error RDMA/rxe: Fix skb lifetime in rxe_rcv_mcast_pkt() IB/rdmavt: Fix sizeof mismatch cpufreq: powernv: Fix frame-size-overflow in powernv_cpufreq_reboot_notifier i3c: master: Fix error return in cdns_i3c_master_probe() powerpc/perf/hv-gpci: Fix starting index value powerpc/perf: Exclude pmc5/6 from the irrelevant PMU group constraints RDMA/ipoib: Set rtnl_link_ops for ipoib interfaces overflow: Include header file with SIZE_MAX declaration kdb: Fix pager search for multi-line strings mtd: spinand: gigadevice: Add QE Bit mtd: spinand: gigadevice: Only one dummy byte in QUADIO mtd: rawnand: vf610: disable clk on error handling path in probe RDMA/hns: Fix missing sq_sig_type when querying QP RDMA/hns: Fix the wrong value of rnr_retry when querying qp perf stat: Skip duration_time in setup_system_wide i40iw: Add support to make destroy QP synchronous RDMA/mlx5: Disable IB_DEVICE_MEM_MGT_EXTENSIONS if IB_WR_REG_MR can't work RDMA/hns: Set the unsupported wr opcode perf intel-pt: Fix "context_switch event has no tid" error RDMA/cma: Consolidate the destruction of a cma_multicast in one place RDMA/cma: Remove dead code for kernel rdmacm multicast powerpc/64s/radix: Fix mm_cpumask trimming race vs kthread_use_mm powerpc/tau: Disable TAU between measurements powerpc/tau: Check processor type before enabling TAU interrupt powerpc/tau: Remove duplicated set_thresholds() call powerpc/tau: Convert from timer to workqueue powerpc/tau: Use appropriate temperature sample interval powerpc/book3s64/hash/4k: Support large linear mapping range with 4K RDMA/qedr: Fix inline size returned for iWARP RDMA/qedr: Fix return code if accept is called on a destroyed qp RDMA/qedr: Fix use of uninitialized field RDMA/qedr: Fix qp structure memory leak RDMA/umem: Prevent small pages from being returned by ib_umem_find_best_pgsz() RDMA/umem: Fix ib_umem_find_best_pgsz() for mappings that cross a page boundary xfs: fix high key handling in the rt allocator's query_range function xfs: fix deadlock and streamline xfs_getfsmap performance xfs: limit entries returned when counting fsmap records ida: Free allocated bitmap in error path arc: plat-hsdk: fix kconfig dependency warning when !RESET_CONTROLLER ARM: 9007/1: l2c: fix prefetch bits init in L2X0_AUX_CTRL using DT values mtd: mtdoops: Don't write panic data twice RDMA/mlx5: Fix potential race between destroy and CQE poll pseries/drmem: don't cache node id in drmem_lmb struct powerpc/pseries: explicitly reschedule during drmem_lmb list traversal RDMA/umem: Fix signature of stub ib_umem_find_best_pgsz() RDMA/hns: Add a check for current state before modifying QP mtd: lpddr: fix excessive stack usage with clang RDMA/ucma: Add missing locking around rdma_leave_multicast() RDMA/ucma: Fix locking for ctx->events_reported powerpc/icp-hv: Fix missing of_node_put() in success path powerpc/pseries: Fix missing of_node_put() in rng_init() IB/mlx4: Adjust delayed work when a dup is observed IB/mlx4: Fix starvation in paravirt mux/demux i3c: master add i3c_master_attach_boardinfo to preserve boardinfo selftests/ftrace: Change synthetic event name for inter-event-combined test fs: fix NULL dereference due to data race in prepend_path() mm, oom_adj: don't loop through tasks in __set_oom_adj when not necessary mm/memcg: fix device private memcg accounting mm/swapfile.c: fix potential memory leak in sys_swapon netfilter: nf_log: missing vlan offload tag and proto net: korina: fix kfree of rx/tx descriptor array ipvs: clear skb->tstamp in forwarding path mwifiex: fix double free platform/x86: mlx-platform: Remove PSU EEPROM configuration ipmi_si: Fix wrong return value in try_smi_init() scsi: be2iscsi: Fix a theoretical leak in beiscsi_create_eqs() scsi: target: tcmu: Fix warning: 'page' may be used uninitialized usb: dwc2: Fix INTR OUT transfers in DDMA mode. nl80211: fix non-split wiphy information usb: gadget: u_ether: enable qmult on SuperSpeed Plus as well usb: gadget: f_ncm: fix ncm_bitrate for SuperSpeed and above. iwlwifi: mvm: split a print to avoid a WARNING in ROC mfd: sm501: Fix leaks in probe() net: enic: Cure the enic api locking trainwreck iio: adc: stm32-adc: fix runtime autosuspend delay when slow polling qtnfmac: fix resource leaks on unsupported iftype error return path ibmvnic: set up 200GBPS speed coresight: etm: perf: Fix warning caused by etm_setup_aux failure nl80211: fix OBSS PD min and max offset validation nvmem: core: fix possibly memleak when use nvmem_cell_info_to_nvmem_cell() HID: hid-input: fix stylus battery reporting ASoC: fsl_sai: Instantiate snd_soc_dai_driver slimbus: qcom-ngd-ctrl: disable ngd in qmi server down callback slimbus: core: do not enter to clock pause mode in core slimbus: core: check get_addr before removing laddr ida quota: clear padding in v2r1_mem2diskdqb() usb: dwc2: Fix parameter type in function pointer prototype ALSA: seq: oss: Avoid mutex lock for a long-time ioctl misc: mic: scif: Fix error handling path dmaengine: dmatest: Check list for emptiness before access its last entry ath6kl: wmi: prevent a shift wrapping bug in ath6kl_wmi_delete_pstream_cmd() spi: omap2-mcspi: Improve performance waiting for CHSTAT net: dsa: rtl8366rb: Support all 4096 VLANs ASoC: tlv320aic32x4: Fix bdiv clock rate derivation net: wilc1000: clean up resource in error path of init mon interface net: dsa: rtl8366: Skip PVID setting if not requested net: dsa: rtl8366: Refactor VLAN/PVID init net: dsa: rtl8366: Check validity of passed VLANs xhci: don't create endpoint debugfs entry before ring buffer is set. coresight: etm4x: Handle unreachable sink in perf mode drm: mxsfb: check framebuffer pitch cpufreq: armada-37xx: Add missing MODULE_DEVICE_TABLE net: stmmac: use netif_tx_start|stop_all_queues() function scsi: mpt3sas: Fix sync irqs net/mlx5: Don't call timecounter cyc2time directly from 1PPS flow pinctrl: mcp23s08: Fix mcp23x17 precious range pinctrl: mcp23s08: Fix mcp23x17_regmap initialiser iomap: Clear page error before beginning a write drm/panfrost: Ensure GPU quirks are always initialised drm/msm: Avoid div-by-zero in dpu_crtc_atomic_check() HID: roccat: add bounds checking in kone_sysfs_write_settings() ASoC: fsl: imx-es8328: add missing put_device() call in imx_es8328_probe() video: fbdev: radeon: Fix memleak in radeonfb_pci_register video: fbdev: sis: fix null ptr dereference video: fbdev: vga16fb: fix setting of pixclock because a pass-by-value error drivers/virt/fsl_hypervisor: Fix error handling path pwm: lpss: Add range limit check for the base_unit register value pwm: lpss: Fix off by one error in base_unit math in pwm_lpss_prepare() pty: do tty_flip_buffer_push without port->lock in pty_write tty: hvcs: Don't NULL tty->driver_data until hvcs_cleanup() tty: serial: earlycon dependency binder: Remove bogus warning on failed same-process transaction drm/crc-debugfs: Fix memleak in crc_control_write drm: panel: Fix bpc for OrtusTech COM43H4M85ULC panel mm/error_inject: Fix allow_error_inject function signatures. VMCI: check return value of get_user_pages_fast() for errors staging: emxx_udc: Fix passing of NULL to dma_alloc_coherent() backlight: sky81452-backlight: Fix refcount imbalance on error scsi: csiostor: Fix wrong return value in csio_hw_prep_fw() scsi: qla2xxx: Fix wrong return value in qla_nvme_register_hba() scsi: qla2xxx: Fix wrong return value in qlt_chk_unresolv_exchg() scsi: qla4xxx: Fix an error handling path in 'qla4xxx_get_host_stats()' drm/gma500: fix error check staging: rtl8192u: Do not use GFP_KERNEL in atomic context mwifiex: Do not use GFP_KERNEL in atomic context brcmfmac: check ndev pointer ASoC: qcom: lpass-cpu: fix concurrency issue ASoC: qcom: lpass-platform: fix memory leak wcn36xx: Fix reported 802.11n rx_highest rate wcn3660/wcn3680 ath10k: Fix the size used in a 'dma_free_coherent()' call in an error handling path ath9k: Fix potential out of bounds in ath9k_htc_txcompletion_cb() ath6kl: prevent potential array overflow in ath6kl_add_new_sta() drm: panel: Fix bus format for OrtusTech COM43H4M85ULC panel drm/amd/display: Fix wrong return value in dm_update_plane_state() Bluetooth: hci_uart: Cancel init work before unregistering drm/vkms: fix xrgb on compute crc ath10k: provide survey info as accumulated data blk-mq: move cancel of hctx->run_work to the front of blk_exit_queue spi: spi-s3c64xx: Check return values spi: spi-s3c64xx: swap s3c64xx_spi_set_cs() and s3c64xx_enable_datapath() pinctrl: bcm: fix kconfig dependency warning when !GPIOLIB regulator: resolve supply after creating regulator media: ti-vpe: Fix a missing check and reference count leak media: stm32-dcmi: Fix a reference count leak media: s5p-mfc: Fix a reference count leak media: camss: Fix a reference count leak. media: platform: fcp: Fix a reference count leak. media: rockchip/rga: Fix a reference count leak. media: rcar-vin: Fix a reference count leak. media: tc358743: cleanup tc358743_cec_isr media: tc358743: initialize variable media: mx2_emmaprp: Fix memleak in emmaprp_probe cypto: mediatek - fix leaks in mtk_desc_ring_alloc hwmon: (pmbus/max34440) Fix status register reads for MAX344{51,60,61} crypto: omap-sham - fix digcnt register handling with export/import media: rcar-csi2: Allocate v4l2_async_subdev dynamically media: rcar_drif: Allocate v4l2_async_subdev dynamically media: rcar_drif: Fix fwnode reference leak when parsing DT media: i2c: ov5640: Enable data pins on poweron for DVP mode media: i2c: ov5640: Separate out mipi configuration from s_power media: i2c: ov5640: Remain in power down for DVP mode unless streaming media: omap3isp: Fix memleak in isp_probe media: staging/intel-ipu3: css: Correctly reset some memory media: uvcvideo: Silence shift-out-of-bounds warning media: uvcvideo: Set media controller entity functions media: m5mols: Check function pointer in m5mols_sensor_power media: ov5640: Correct Bit Div register in clock tree diagram media: Revert "media: exynos4-is: Add missed check for pinctrl_lookup_state()" media: tuner-simple: fix regression in simple_set_radio_freq crypto: picoxcell - Fix potential race condition bug crypto: ixp4xx - Fix the size used in a 'dma_free_coherent()' call crypto: mediatek - Fix wrong return value in mtk_desc_ring_alloc() crypto: algif_skcipher - EBUSY on aio should be an error x86/events/amd/iommu: Fix sizeof mismatch x86/nmi: Fix nmi_handle() duration miscalculation perf/x86/intel/uncore: Reduce the number of CBOX counters perf/x86/intel/uncore: Update Ice Lake uncore units sched/fair: Fix wrong cpu selecting from isolated domain drivers/perf: thunderx2_pmu: Fix memory resource error handling drivers/perf: xgene_pmu: Fix uninitialized resource struct x86/fpu: Allow multiple bits in clearcpuid= parameter perf/x86/intel/ds: Fix x86_pmu_stop warning for large PEBS EDAC/ti: Fix handling of platform_get_irq() error EDAC/aspeed: Fix handling of platform_get_irq() error EDAC/i5100: Fix error handling order in i5100_init_one() crypto: caam/qi - add fallback for XTS with more than 8B IV crypto: algif_aead - Do not set MAY_BACKLOG on the async path ima: Don't ignore errors from crypto_shash_update() KVM: SVM: Initialize prev_ga_tag before use KVM: x86/mmu: Commit zap of remaining invalid pages when recovering lpages KVM: nVMX: Reload vmcs01 if getting vmcs12's pages fails KVM: nVMX: Reset the segment cache when stuffing guest segs SMB3: Resolve data corruption of TCP server info fields cifs: Return the error from crypt_message when enc/dec key not found. cifs: remove bogus debug code ALSA: hda/realtek: Enable audio jacks of ASUS D700SA with ALC887 ALSA: hda/realtek - Add mute Led support for HP Elitebook 845 G7 ALSA: hda/realtek - set mic to auto detect on a HP AIO machine ALSA: hda/realtek - The front Mic on a HP machine doesn't work icmp: randomize the global rate limiter tcp: fix to update snd_wl1 in bulk receiver fast path selftests: rtnetlink: load fou module for kci_test_encap_fou() test selftests: forwarding: Add missing 'rp_filter' configuration r8169: fix operation under forced interrupt threading nfc: Ensure presence of NFC_ATTR_FIRMWARE_NAME attribute in nfc_genl_fw_download() nexthop: Fix performance regression in nexthop deletion net/sched: act_tunnel_key: fix OOB write in case of IPv6 ERSPAN tunnels net: Properly typecast int values to set sk_max_pacing_rate net: hdlc_raw_eth: Clear the IFF_TX_SKB_SHARING flag after calling ether_setup net: hdlc: In hdlc_rcv, check to make sure dev is an HDLC device net: ftgmac100: Fix Aspeed ast2600 TX hang issue ibmvnic: save changed mac address to adapter->mac_addr chelsio/chtls: correct function return and return type chelsio/chtls: correct netdevice for vlan interface chelsio/chtls: fix socket lock nvme-pci: disable the write zeros command for Intel 600P/P3100 ALSA: hda/hdmi: fix incorrect locking in hdmi_pcm_close ALSA: hda: fix jack detection with Realtek codecs when in D3 ALSA: bebob: potential info leak in hwdep_read() binder: fix UAF when releasing todo list cxgb4: handle 4-tuple PEDIT to NAT mode translation r8169: fix data corruption issue on RTL8402 net_sched: remove a redundant goto chain check net/ipv4: always honour route mtu during forwarding net: j1939: j1939_session_fresh_new(): fix missing initialization of skbcnt can: j1935: j1939_tp_tx_dat_new(): fix missing initialization of skbcnt can: m_can_platform: don't call m_can_class_suspend in runtime suspend socket: fix option SO_TIMESTAMPING_NEW tipc: fix the skb_unshare() in tipc_buf_append() net: usb: qmi_wwan: add Cellient MPL200 card net/tls: sendfile fails with ktls offload net/smc: fix valid DMBE buffer sizes net: fix pos incrementment in ipv6_route_seq_next net: fec: Fix PHY init after phy_reset_after_clk_enable() net: fec: Fix phy_device lookup for phy_reset_after_clk_enable() mlx4: handle non-napi callers to napi_poll ipv4: Restore flowi4_oif update before call to xfrm_lookup_route ibmveth: Identify ingress large send packets. ibmveth: Switch order of ibmveth_helper calls. Linux 5.4.72 crypto: qat - check cipher length for aead AES-CBC-HMAC-SHA crypto: bcm - Verify GCM/CCM key length in setkey xen/events: don't use chip_data for legacy IRQs reiserfs: Fix oops during mount reiserfs: Initialize inode keys properly USB: serial: ftdi_sio: add support for FreeCalypso JTAG+UART adapters USB: serial: pl2303: add device-id for HP GC device staging: comedi: check validity of wMaxPacketSize of usb endpoints found USB: serial: option: Add Telit FT980-KS composition USB: serial: option: add Cellient MPL200 card media: usbtv: Fix refcounting mixup Bluetooth: Disconnect if E0 is used for Level 4 Bluetooth: Fix update of connection state in `hci_encrypt_cfm` Bluetooth: Consolidate encryption handling in hci_encrypt_cfm Bluetooth: MGMT: Fix not checking if BT_HS is enabled Bluetooth: L2CAP: Fix calling sk_filter on non-socket based channel Bluetooth: A2MP: Fix not initializing all members ACPI: Always build evged in ARM: 8939/1: kbuild: use correct nm executable btrfs: take overcommit into account in inc_block_group_ro btrfs: don't pass system_chunk into can_overcommit perf cs-etm: Move definition of 'traceid_list' global variable from header file Linux 5.4.71 net_sched: commit action insertions together net_sched: defer tcf_idr_insert() in tcf_action_init_1() net: usb: rtl8150: set random MAC address when set_ethernet_addr() fails Input: ati_remote2 - add missing newlines when printing module parameters net/mlx5e: Fix driver's declaration to support GRE offload net/tls: race causes kernel panic net/core: check length before updating Ethertype in skb_mpls_{push,pop} tcp: fix receive window update in tcp_add_backlog() mm: khugepaged: recalculate min_free_kbytes after memory hotplug as expected by khugepaged mmc: core: don't set limits.discard_granularity as 0 perf: Fix task_function_call() error handling rxrpc: Fix server keyring leak rxrpc: The server keyring isn't network-namespaced rxrpc: Fix some missing _bh annotations on locking conn->state_lock rxrpc: Downgrade the BUG() for unsupported token type in rxrpc_read() rxrpc: Fix rxkad token xdr encoding net/mlx5e: Fix VLAN create flow net/mlx5e: Fix VLAN cleanup flow net/mlx5e: Add resiliency in Striding RQ mode for packets larger than MTU net/mlx5: Fix request_irqs error flow net/mlx5: Avoid possible free of command entry while timeout comp handler virtio-net: don't disable guest csum when disable LRO net: usb: ax88179_178a: fix missing stop entry in driver_info r8169: fix RTL8168f/RTL8411 EPHY config mlxsw: spectrum_acl: Fix mlxsw_sp_acl_tcam_group_add()'s error path mdio: fix mdio-thunder.c dependency & build error bonding: set dev->needed_headroom in bond_setup_by_slave() net: ethernet: cavium: octeon_mgmt: use phy_start and phy_stop iavf: Fix incorrect adapter get in iavf_resume iavf: use generic power management xfrm: Use correct address family in xfrm_state_find platform/x86: fix kconfig dependency warning for FUJITSU_LAPTOP net: stmmac: removed enabling eee in EEE set callback xfrm: clone whole liftime_cur structure in xfrm_do_migrate xfrm: clone XFRMA_SEC_CTX in xfrm_do_migrate xfrm: clone XFRMA_REPLAY_ESN_VAL in xfrm_do_migrate xfrm: clone XFRMA_SET_MARK in xfrm_do_migrate iommu/vt-d: Fix lockdep splat in iommu_flush_dev_iotlb() drm/amdgpu: prevent double kfree ttm->sg openvswitch: handle DNAT tuple collision net: team: fix memory leak in __team_options_register team: set dev->needed_headroom in team_setup_by_port() sctp: fix sctp_auth_init_hmacs() error path i2c: owl: Clear NACK and BUS error bits i2c: meson: fixup rate calculation with filter delay i2c: meson: fix clock setting overwrite cifs: Fix incomplete memory allocation on setxattr path xfrmi: drop ignore_df check before updating pmtu nvme-tcp: check page by sendpage_ok() before calling kernel_sendpage() tcp: use sendpage_ok() to detect misused .sendpage net: introduce helper sendpage_ok() in include/linux/net.h mm/khugepaged: fix filemap page_to_pgoff(page) != offset macsec: avoid use-after-free in macsec_handle_frame() nvme-core: put ctrl ref when module ref get fail btrfs: allow btrfs_truncate_block() to fallback to nocow for data space reservation btrfs: fix RWF_NOWAIT write not failling when we need to cow btrfs: Ensure we trim ranges across block group boundary btrfs: volumes: Use more straightforward way to calculate map length Btrfs: send, fix emission of invalid clone operations within the same file Btrfs: send, allow clone operations within the same file arm64: dts: stratix10: add status to qspi dts node i2c: i801: Exclude device from suspend direct complete optimization perf top: Fix stdio interface input handling with glibc 2.28+ perf test session topology: Fix data path driver core: Fix probe_count imbalance in really_probe() platform/x86: thinkpad_acpi: re-initialize ACPI buffer size when reuse platform/x86: intel-vbtn: Switch to an allow-list for SW_TABLET_MODE reporting bpf: Prevent .BTF section elimination bpf: Fix sysfs export of empty BTF section platform/x86: thinkpad_acpi: initialize tp_nvram_state variable platform/x86: intel-vbtn: Fix SW_TABLET_MODE always reporting 1 on the HP Pavilion 11 x360 Platform: OLPC: Fix memleak in olpc_ec_probe usermodehelper: reset umask to default before executing user process vhost: Use vhost_get_used_size() in vhost_vring_set_addr() vhost: Don't call access_ok() when using IOTLB drm/nouveau/mem: guard against NULL pointer access in mem_del net: wireless: nl80211: fix out-of-bounds access in nl80211_del_key() io_uring: Fix double list add in io_queue_async_work() io_uring: Fix remove irrelevant req from the task_list io_uring: Fix missing smp_mb() in io_cancel_async_work() io_uring: Fix resource leaking when kill the process Revert "ravb: Fixed to be able to unload modules" fbcon: Fix global-out-of-bounds read in fbcon_get_font() Fonts: Support FONT_EXTRA_WORDS macros for built-in fonts fbdev, newport_con: Move FONT_EXTRA_WORDS macros into linux/font.h Linux 5.4.70 netfilter: ctnetlink: add a range check for l3/l4 protonum ep_create_wakeup_source(): dentry name can change under you... epoll: EPOLL_CTL_ADD: close the race in decision to take fast path epoll: replace ->visited/visited_list with generation count epoll: do not insert into poll queues until all sanity checks are done nvme: consolidate chunk_sectors settings nvme: Introduce nvme_lba_to_sect() nvme: Cleanup and rename nvme_block_nr() mm: don't rely on system state to detect hot-plug operations mm: replace memmap_context by meminit_context block/diskstats: more accurate approximation of io_ticks for slow disks random32: Restore __latent_entropy attribute on net_rand_state scripts/dtc: only append to HOST_EXTRACFLAGS instead of overwriting Input: trackpoint - enable Synaptics trackpoints i2c: cpm: Fix i2c_ram structure gpio: aspeed: fix ast2600 bank properties gpio/aspeed-sgpio: don't enable all interrupts by default gpio/aspeed-sgpio: enable access to all 80 input & output sgpios iommu/exynos: add missing put_device() call in exynos_iommu_of_xlate() clk: samsung: exynos4: mark 'chipid' clock as CLK_IGNORE_UNUSED clk: tegra: Always program PLL_E when enabled nfs: Fix security label length not being reset pinctrl: mvebu: Fix i2c sda definition for 98DX3236 phy: ti: am654: Fix a leak in serdes_am654_probe() gpio: sprd: Clear interrupt when setting the type as edge nvme-fc: fail new connections to a deleted host or remote port nvme-pci: fix NULL req in completion handler spi: fsl-espi: Only process interrupts for expected events tools/io_uring: fix compile breakage tracing: Make the space reserved for the pid wider mac80211: do not allow bigger VHT MPDUs than the hardware supports mac80211: Fix radiotap header channel flag for 6GHz band drivers/net/wan/hdlc: Set skb->protocol before transmitting drivers/net/wan/lapbether: Make skb->protocol consistent with the header fuse: fix the ->direct_IO() treatment of iov_iter nvme-core: get/put ctrl and transport module in nvme_dev_open/release() rndis_host: increase sleep time in the query-response loop net: dec: de2104x: Increase receive ring size for Tulip drm/sun4i: mixer: Extend regmap max_register drivers/net/wan/hdlc_fr: Add needed_headroom for PVC devices libbpf: Remove arch-specific include path in Makefile clocksource/drivers/timer-gx6605s: Fixup counter reload drm/amdgpu: restore proper ref count in amdgpu_display_crtc_set_config memstick: Skip allocating card when removing host ftrace: Move RCU is watching check after recursion check iio: adc: qcom-spmi-adc5: fix driver name Input: i8042 - add nopnp quirk for Acer Aspire 5 A515 xfs: trim IO to found COW extent limit net: virtio_vsock: Enhance connection semantics vsock/virtio: add transport parameter to the virtio_transport_reset_no_sock() clk: socfpga: stratix10: fix the divider for the emac_ptp_free_clk gpio: tc35894: fix up tc35894 interrupt configuration gpio: mockup: fix resource leak in error path gpio: siox: explicitly support only threaded irqs USB: gadget: f_ncm: Fix NDP16 datagram validation mmc: sdhci: Workaround broken command queuing on Intel GLK based IRBIS models btrfs: fix filesystem corruption after a device replace Revert "opp: Replace list_kref with a local counter" Revert "opp: Increase parsed_static_opps in _of_add_opp_table_v1()" Revert "mmc: core: Fix size overflow for mmc partitions" Revert "exec: Add exec_update_mutex to replace cred_guard_mutex" Revert "exec: Fix a deadlock in strace" Revert "selftests/ptrace: add test cases for dead-locks" Revert "kernel/kcmp.c: Use new infrastructure to fix deadlocks in execve" Revert "proc: Use new infrastructure to fix deadlocks in execve" Revert "proc: io_accounting: Use new infrastructure to fix deadlocks in execve" Revert "perf: Use new infrastructure to fix deadlocks in execve" Linux 5.4.69 ata: sata_mv, avoid trigerrable BUG_ON ata: make qc_prep return ata_completion_errors ata: define AC_ERR_OK kprobes: Fix compiler warning for !CONFIG_KPROBES_ON_FTRACE dm: fix bio splitting and its bio completion order for regular IO KVM: arm64: Assume write fault on S1PTW permission fault on instruction fetch s390/zcrypt: Fix ZCRYPT_PERDEV_REQCNT ioctl mm/gup: fix gup_fast with dynamic page table folding mm, THP, swap: fix allocating cluster for swapfile by mistake dmabuf: fix NULL pointer dereference in dma_buf_release() btrfs: fix overflow when copying corrupt csums for a message kprobes: tracing/kprobes: Fix to kill kprobes on initmem after boot kprobes: Fix to check probe enabled before disarm_kprobe_ftrace() s390/dasd: Fix zero write for FBA devices tracing: fix double free lib/string.c: implement stpcpy ALSA: hda/realtek: Enable front panel headset LED on Lenovo ThinkStation P520 ALSA: hda/realtek - Couldn't detect Mic if booting with headset plugged ALSA: usb-audio: Add delay quirk for H570e USB headsets scsi: lpfc: Fix initial FLOGI failure due to BBSCN not supported x86/ioapic: Unbreak check_timer() arch/x86/lib/usercopy_64.c: fix __copy_user_flushcache() cache writeback mm: validate pmd after splitting KVM: SVM: Add a dedicated INVD intercept routine KVM: x86: Reset MMU context if guest toggles CR4.SMAP or CR4.PKE regulator: axp20x: fix LDO2/4 description MIPS: Add the missing 'CPU_1074K' into __get_cpu_type() regmap: fix page selection for noinc writes regmap: fix page selection for noinc reads ALSA: asihpi: fix iounmap in error handler lib80211: fix unmet direct dependendices config warning when !CRYPTO bpf: Fix a rcu warning for bpffs map pretty-print batman-adv: mcast: fix duplicate mcast packets from BLA backbone to mesh batman-adv: mcast: fix duplicate mcast packets in BLA backbone from mesh batman-adv: mcast: fix duplicate mcast packets in BLA backbone from LAN nvme-tcp: fix kconfig dependency warning when !CRYPTO batman-adv: Add missing include for in_interrupt() drm/sun4i: sun8i-csc: Secondary CSC register correction net: qed: RDMA personality shouldn't fail VF load net: qede: Disable aRFS for NPAR and 100G net: qed: Disable aRFS for NPAR and 100G drm/vc4/vc4_hdmi: fill ASoC card owner bpf: Fix clobbering of r2 in bpf_gen_ld_abs mac802154: tx: fix use-after-free netfilter: conntrack: nf_conncount_init is failing with IPv6 disabled batman-adv: mcast/TT: fix wrongly dropped or rerouted packets atm: eni: fix the missed pci_disable_device() for eni_init_one() batman-adv: bla: fix type misuse for backbone_gw hash indexing mwifiex: Increase AES key storage size to 256 bits clocksource/drivers/h8300_timer8: Fix wrong return value in h8300_8timer_init() ieee802154/adf7242: check status of adf7242_read_reg ieee802154: fix one possible memleak in ca8210_dev_com_init objtool: Fix noreturn detection for ignored functions i2c: core: Call i2c_acpi_install_space_handler() before i2c_acpi_register_devices() drm/amdgpu/dc: Require primary plane to be enabled whenever the CRTC is drm/amd/display: update nv1x stutter latencies drm/amdkfd: fix a memory leak issue EDAC/ghes: Check whether the driver is on the safe list correctly lockdep: fix order in trace_hardirqs_off_caller() s390/init: add missing __init annotations i2c: aspeed: Mask IRQ status to relevant bits RISC-V: Take text_mutex in ftrace_init_nop() ASoC: Intel: bytcr_rt5640: Add quirk for MPMAN Converter9 2-in-1 ASoC: wm8994: Ensure the device is resumed in wm89xx_mic_detect functions ASoC: wm8994: Skip setting of the WM8994_MICBIAS register for WM1811 ASoC: pcm3168a: ignore 0 Hz settings device_cgroup: Fix RCU list debugging warning nvme: explicitly update mpath disk capacity on revalidation net: openvswitch: use div_u64() for 64-by-32 divisions ALSA: hda: Workaround for spurious wakeups on some Intel platforms ALSA: hda: Always use jackpoll helper for jack update after resume perf parse-events: Use strcmp() to compare the PMU name opp: Increase parsed_static_opps in _of_add_opp_table_v1() mt76: fix LED link time failure ubi: fastmap: Free unused fastmap anchor peb during detach scsi: qla2xxx: Retry PLOGI on FC-NVMe PRLI failure perf tests: Fix test 68 zstd compression for s390 btrfs: qgroup: fix data leak caused by race between writeback and truncate vfio/pci: fix racy on error and request eventfd ctx selftests/x86/syscall_nt: Clear weird flags after each test scsi: libfc: Skip additional kref updating work event scsi: libfc: Handling of extra kref mac80211: skip mpath lookup also for control port tx nvme: fix possible deadlock when I/O is blocked cifs: Fix double add page to memcg when cifs_readpages vfio/pci: Clear error and request eventfd ctx after releasing NFS: nfs_xdr_status should record the procedure name x86/speculation/mds: Mark mds_user_clear_cpu_buffers() __always_inline mtd: parser: cmdline: Support MTD names containing one or more colons rapidio: avoid data race between file operation callbacks and mport_cdev_add(). mm: memcontrol: fix stat-corrupting race in charge moving mm/swap_state: fix a data race in swapin_nr_pages ceph: fix potential race in ceph_check_caps PCI: tegra: Fix runtime PM imbalance on error mtd: rawnand: omap_elm: Fix runtime PM imbalance on error mtd: rawnand: gpmi: Fix runtime PM imbalance on error wlcore: fix runtime pm imbalance in wlcore_regdomain_config wlcore: fix runtime pm imbalance in wl1271_tx_work ASoC: img-i2s-out: Fix runtime PM imbalance on error PCI: tegra194: Fix runtime PM imbalance on error perf kcore_copy: Fix module map when there are no modules loaded perf metricgroup: Free metric_events on error perf util: Fix memory leak of prefix_if_not_in perf stat: Fix duration_time value for higher intervals perf trace: Fix the selection for architectures to generate the errno name tables perf evsel: Fix 2 memory leaks KVM: PPC: Book3S HV: Close race with page faults around memslot flushes vfio/pci: fix memory leaks of eventfd ctx gpio: rcar: Fix runtime PM imbalance on error btrfs: fix double __endio_write_update_ordered in direct I/O btrfs: don't force read-only after error in drop snapshot usb: dwc3: Increase timeout for CmdAct cleared by device controller printk: handle blank console arguments passed in. drm/nouveau/dispnv50: fix runtime pm imbalance on error drm/nouveau: fix runtime pm imbalance on error drm/nouveau/debugfs: fix runtime pm imbalance on error e1000: Do not perform reset in reset_task if we are already down drm/amdkfd: fix restore worker race condition arm64/cpufeature: Drop TraceFilt feature exposure from ID_DFR0 register scsi: cxlflash: Fix error return code in cxlflash_probe() arm64: acpi: Make apei_claim_sea() synchronise with APEI's irq work coresight: etm4x: Fix use-after-free of per-cpu etm drvdata USB: EHCI: ehci-mv: fix less than zero comparison of an unsigned int fuse: update attr_version counter on fuse_notify_inval_inode() fuse: don't check refcount after stealing page svcrdma: Fix backchannel return code powerpc/traps: Make unrecoverable NMIs die instead of panic ipmi:bt-bmc: Fix error handling and status check drm/exynos: dsi: Remove bridge node reference in error handling path in probe function ALSA: hda: Fix potential race in unsol event handler tty: serial: samsung: Correct clock selection logic tipc: fix memory leak in service subscripting KVM: x86: handle wrap around 32-bit address space USB: EHCI: ehci-mv: fix error handling in mv_ehci_probe() Bluetooth: Handle Inquiry Cancel error after Inquiry Complete phy: samsung: s5pv210-usb2: Add delay after reset power: supply: max17040: Correct voltage reading i2c: tegra: Restore pinmux on system resume mm/slub: fix incorrect interpretation of s->offset perf mem2node: Avoid double free related to realloc media: venus: vdec: Init registered list unconditionally atm: fix a memory leak of vcc->user_back devlink: Fix reporter's recovery condition dt-bindings: sound: wm8994: Correct required supplies based on actual implementaion dpaa2-eth: fix error return code in setup_dpni() sched/fair: Eliminate bandwidth race between throttling and distribution arm64: cpufeature: Relax checks for AArch32 support at EL[0-2] sparc64: vcc: Fix error return code in vcc_probe() staging:r8188eu: avoid skb_clone for amsdu to msdu conversion scsi: aacraid: Fix error handling paths in aac_probe_one() net: openvswitch: use u64 for meter bucket KVM: arm64: vgic-its: Fix memory leak on the error path of vgic_add_lpi() KVM: arm64: vgic-v3: Retire all pending LPIs on vcpu destroy drivers: char: tlclk.c: Avoid data race between init and interrupt handler bdev: Reduce time holding bd_mutex in sync in blkdev_close() perf stat: Force error in fallback on :k events KVM: Remove CREATE_IRQCHIP/SET_PIT2 race btrfs: fix setting last_trans for reloc roots serial: uartps: Wait for tx_empty in console setup scsi: qedi: Fix termination timeouts in session logout ALSA: hda: Skip controller resume if not needed mm/mmap.c: initialize align_offset explicitly for vm_unmapped_area drm/amdgpu/sriov add amdgpu_amdkfd_pre_reset in gpu reset workqueue: Remove the warning in wq_worker_sleeping() nvmet-rdma: fix double free of rdma queue SUNRPC: Don't start a timer on an already queued rpc task mm/vmscan.c: fix data races using kswapd_classzone_idx mm/swapfile: fix data races in try_to_unuse() mm/filemap.c: clear page error before actual read mm/kmemleak.c: use address-of operator on section symbols powerpc/perf: Implement a global lock to avoid races between trace, core and thread imc events. drm/amdgpu/vcn2.0: stall DPG when WPTR/RPTR reset NFS: Fix races nfs_page_group_destroy() vs nfs_destroy_unlinked_subrequests() PCI: pciehp: Fix MSI interrupt race ALSA: usb-audio: Fix case when USB MIDI interface has more than one extra endpoint descriptor ubifs: Fix out-of-bounds memory access caused by abnormal value of node_len ubifs: ubifs_add_orphan: Fix a memory leak bug ubifs: ubifs_jnl_write_inode: Fix a memory leak bug PCI: Use ioremap(), not phys_to_virt() for platform ROM netfilter: nf_tables: silence a RCU-list warning in nft_table_lookup() svcrdma: Fix leak of transport addresses SUNRPC: Fix a potential buffer overflow in 'svc_print_xprts()' scsi: hpsa: correct race condition in offload enabled IB/iser: Always check sig MR before putting it to the free pool RDMA/rxe: Set sys_image_guid to be aligned with HW IB devices xfs: prohibit fs freezing when using empty transactions brcmfmac: Fix double freeing in the fmac usb data path nvme: Fix controller creation races with teardown flow nvme: Fix ctrl use-after-free during sysfs deletion nvme-multipath: do not reset on unknown status perf: Use new infrastructure to fix deadlocks in execve proc: io_accounting: Use new infrastructure to fix deadlocks in execve proc: Use new infrastructure to fix deadlocks in execve kernel/kcmp.c: Use new infrastructure to fix deadlocks in execve selftests/ptrace: add test cases for dead-locks exec: Fix a deadlock in strace exec: Add exec_update_mutex to replace cred_guard_mutex tools: gpio-hammer: Avoid potential overflow in main cpufreq: powernv: Fix frame-size-overflow in powernv_cpufreq_work_fn net: axienet: Propagate failure of DMA descriptor setup net: axienet: Convert DMA error handler to a work queue perf cpumap: Fix snprintf overflow check serial: 8250: 8250_omap: Terminate DMA before pushing data on RX timeout serial: 8250_omap: Fix sleeping function called from invalid context during probe serial: 8250_port: Don't service RX FIFO if throttled r8169: improve RTL8168b FIFO overflow workaround btrfs: free the reloc_control in a consistent way btrfs: do not init a reloc root if we aren't relocating perf parse-events: Fix 3 use after frees found with clang ASAN KVM: LAPIC: Mark hrtimer for period or oneshot mode to expire in hard interrupt context thermal: rcar_thermal: Handle probe error gracefully tracing: Use address-of operator on section symbols drm/msm/a5xx: Always set an OPP supported hardware value drm/msm: fix leaks if initialization fails KVM: PPC: Book3S HV: Treat TM-related invalid form instructions on P9 like the valid ones intel_th: Disallow multi mode on devices where it's broken RDMA/cm: Remove a race freeing timewait_info nfsd: Don't add locks to closed or closing open stateids rtc: ds1374: fix possible race condition rtc: sa1100: fix possible race condition tpm: ibmvtpm: Wait for buffer to be set before proceeding ext4: mark block bitmap corrupted when found instead of BUGON xfs: mark dir corrupt when lookup-by-hash fails xfs: don't ever return a stale pointer from __xfs_dir3_free_read tty: sifive: Finish transmission before changing the clock media: tda10071: fix unsigned sign extension overflow Bluetooth: L2CAP: handle l2cap config request during open state scsi: aacraid: Disabling TM path and only processing IOP reset ath10k: use kzalloc to read for ath10k_sdio_hif_diag_read perf cs-etm: Correct synthesizing instruction samples perf cs-etm: Swap packets for instruction samples s390/irq: replace setup_irq() by request_irq() cpu-topology: Fix the potential data corruption clk: imx: Fix division by zero warning on pfdv2 drm/amd/display: Stop if retimer is not available ARM: OMAP2+: Handle errors for cpu_pm drm/amdgpu: increase atombios cmd timeout mm: avoid data corruption on CoW fault into PFN-mapped VMA perf jevents: Fix leak of mapfile memory ext4: fix a data race at inode->i_disksize drm/amd/display: fix image corruption with ODM 2:1 DSC 2 slice powerpc/book3s64: Fix error handling in mm_iommu_do_alloc() timekeeping: Prevent 32bit truncation in scale64_check_overflow() Bluetooth: guard against controllers sending zero'd events media: go7007: Fix URB type for interrupt handling ASoC: SOF: ipc: check ipc return value before data copy bus: hisi_lpc: Fixup IO ports addresses to avoid use-after-free in host removal random: fix data races at timer_rand_state firmware: arm_sdei: Use cpus_read_lock() to avoid races with cpuhp iavf: use tc_cls_can_offload_and_chain0() instead of chain check drm/omap: dss: Cleanup DSS ports on initialisation failure drm/amd/display: dal_ddc_i2c_payloads_create can fail causing panic soundwire: bus: disable pm_runtime in sdw_slave_delete dmaengine: tegra-apb: Prevent race conditions on channel's freeing dmaengine: stm32-dma: use vchan_terminate_vdesc() in .terminate_all bpf: Remove recursion prevention from rcu free callback x86/pkeys: Add check for pkey "overflow" media: staging/imx: Missing assignment in imx_media_capture_device_register() dmaengine: stm32-mdma: use vchan_terminate_vdesc() in .terminate_all KVM: nVMX: Hold KVM's srcu lock when syncing vmcs12->shadow KVM: x86: fix incorrect comparison in trace event RDMA/rxe: Fix configuration of atomic queue pair attributes perf test: Fix test trace+probe_vfs_getname.sh on s390 ALSA: usb-audio: Don't create a mixer element with bogus volume range mt76: fix handling full tx queues in mt76_dma_tx_queue_skb_raw mt76: clear skb pointers from rx aggregation reorder buffer during cleanup crypto: chelsio - This fixes the kernel panic which occurs during a libkcapi test clk: stratix10: use do_div() for 64-bit calculation locking/lockdep: Decrement IRQ context counters when removing lock chain drm/omap: fix possible object reference leak scsi: lpfc: Fix coverity errors in fmdi attribute handling scsi: lpfc: Fix release of hwq to clear the eq relationship scsi: lpfc: Fix RQ buffer leakage when no IOCBs available selinux: sel_avc_get_stat_idx should increase position index audit: CONFIG_CHANGE don't log internal bookkeeping as an event drm/amd/display: fix workaround for incorrect double buffer register for DLG ADL and TTU nfsd: Fix a perf warning skbuff: fix a data race in skb_queue_len() ALSA: hda: Clear RIRB status before reading WP KVM: fix overflow of zero page refcount with ksm running Bluetooth: prefetch channel before killing sock mm: pagewalk: fix termination condition in walk_pte_range() mm/swapfile.c: swap_next should increase position index Bluetooth: Fix refcount use-after-free issue tools/power/x86/intel_pstate_tracer: changes for python 3 compatibility selftests/ftrace: fix glob selftest ceph: ensure we have a new cap before continuing in fill_inode ar5523: Add USB ID of SMCWUSBT-G2 wireless adapter ARM: 8948/1: Prevent OOB access in stacktrace tracing: Set kernel_stack's caller size properly Bluetooth: btrtl: Use kvmalloc for FW allocations powerpc/eeh: Only dump stack once if an MMIO loop is detected nfsd: Fix a soft lockup race in nfsd_file_mark_find_or_create() s390/cpum_sf: Use kzalloc and minor changes dmaengine: zynqmp_dma: fix burst length configuration btrfs: tree-checker: Check leaf chunk item size i2c: tegra: Prevent interrupt triggering after transfer timeout drm/amd/display: Initialize DSC PPS variables to 0 scsi: ufs: Fix a race condition in the tracing code scsi: ufs: Make ufshcd_add_command_trace() easier to read ACPI: EC: Reference count query handlers under lock sctp: move trace_sctp_probe_path into sctp_outq_sack scsi: lpfc: Fix incomplete NVME discovery when target scsi: qla2xxx: Fix stuck session in GNL opp: Replace list_kref with a local counter media: ti-vpe: cal: Restrict DMA to avoid memory corruption drm/scheduler: Avoid accessing freed bad job. seqlock: Require WRITE_ONCE surrounding raw_seqcount_barrier drm/mcde: Handle pending vblank while disabling display ipv6_route_seq_next should increase position index rt_cpu_seq_next should increase position index neigh_stat_seq_next() should increase position index vcc_seq_next should increase position index tipc: fix link overflow issue at socket shutdown ALSA: hda: enable regmap internal locking xfs: fix log reservation overflows when allocating large rt extents module: Remove accidental change of module_enable_x() KVM: arm/arm64: vgic: Fix potential double free dist->spis in __kvm_vgic_destroy() kernel/sys.c: avoid copying possible padding bytes in copy_to_user kernel/notifier.c: intercept duplicate registrations to avoid infinite loops selftests/bpf: De-flake test_tcpbpf arm64: insn: consistently handle exit text drm/amdgpu: fix calltrace during kmd unload(v3) xfs: fix realtime file data space leak s390: avoid misusing CALL_ON_STACK for task stack setup xtensa: fix system_call interaction with ptrace ASoC: max98090: remove msleep in PLL unlocked workaround f2fs: stop GC when the victim becomes fully valid CIFS: Properly process SMB3 lease breaks CIFS: Use common error handling code in smb2_ioctl_query_info() SUNRPC: Capture completion of all RPC tasks debugfs: Fix !DEBUG_FS debugfs_create_automount mt76: add missing locking around ampdu action mt76: do not use devm API for led classdev scsi: pm80xx: Cleanup command when a reset times out gfs2: clean up iopen glock mess in gfs2_create_inode mmc: core: Fix size overflow for mmc partitions ubi: Fix producing anchor PEBs RDMA/iw_cgxb4: Fix an error handling path in 'c4iw_connect()' xfs: fix attr leaf header freemap.size underflow fix dget_parent() fastpath race PCI: Avoid double hpmemsize MMIO window assignment RDMA/i40iw: Fix potential use after free RDMA/qedr: Fix potential use after free x86/kdump: Always reserve the low 1M when the crashkernel option is specified dmaengine: mediatek: hsdma_probe: fixed a memory leak when devm_request_irq fails bcache: fix a lost wake-up problem caused by mca_cannibalize_lock tracing: Adding NULL checks for trace_array descriptor pointer tracing: Verify if trace array exists before destroying it. tpm_crb: fix fTPM on AMD Zen+ CPUs drm/amdgpu/powerplay/smu7: fix AVFS handling with custom powerplay table mfd: mfd-core: Protect against NULL call-back function pointer mtd: cfi_cmdset_0002: don't free cfi->cfiq in error path of cfi_amdstd_setup() ice: Fix to change Rx/Tx ring descriptor size via ethtool with DCBx drm/amdgpu/powerplay: fix AVFS handling with custom powerplay table clk/ti/adpll: allocate room for terminating null f2fs: avoid kernel panic on corruption test iomap: Fix overflow in iomap_page_mkwrite dax: Fix alloc_dax_region() compile warning net: silence data-races on sk_backlog.tail powerpc/64s: Always disable branch profiling for prom_init.o scsi: lpfc: Fix kernel crash at lpfc_nvme_info_show during remote port bounce scsi: fnic: fix use after free PM / devfreq: tegra30: Fix integer overflow on CPU's freq max out dm table: do not allow request-based DM to stack on partitions leds: mlxreg: Fix possible buffer overflow xfs: properly serialise fallocate against AIO+DIO drm/amd/display: Free gamma after calculating legacy transfer function media: smiapp: Fix error handling at NVM reading soundwire: intel/cadence: fix startup sequence ASoC: kirkwood: fix IRQ error handling gma/gma500: fix a memory disclosure bug due to uninitialized bytes xfs: fix inode fork extent count overflow m68k: q40: Fix info-leak in rtc_ioctl scsi: aacraid: fix illegal IO beyond last LBA mm: fix double page fault on arm64 if PTE_AF is cleared PCI/IOV: Serialize sysfs sriov_numvfs reads vs writes ath10k: fix memory leak for tpc_stats_final ath10k: fix array out-of-bounds access scsi: qla2xxx: Add error handling for PLOGI ELS passthrough dma-fence: Serialise signal enabling (dma_fence_enable_sw_signaling) drm/amdkfd: Fix race in gfx10 context restore handler drm/amd/display: Do not double-buffer DTO adjustments media: mc-device.c: fix memleak in media_device_register_entity selinux: allow labeling before policy is loaded scsi: mpt3sas: Free diag buffer without any status check scsi: lpfc: Fix pt2pt discovery on SLI3 HBAs kernel/sysctl-test: Add null pointer test for sysctl.c:proc_dointvec() Linux 5.4.68 iommu/amd: Use cmpxchg_double() when updating 128-bit IRTE mm: memcg: fix memcg reclaim soft lockup net: add __must_check to skb_put_padto() net: qrtr: check skb_put_padto() return value net: phy: Do not warn in phy_stop() on PHY_DOWN net: phy: Avoid NPD upon phy_detach() when driver is unbound net: lantiq: Disable IRQs only if NAPI gets scheduled net: lantiq: Use napi_complete_done() net: lantiq: use netif_tx_napi_add() for TX NAPI net: lantiq: Wake TX queue again bnxt_en: Protect bnxt_set_eee() and bnxt_set_pauseparam() with mutex. bnxt_en: return proper error codes in bnxt_show_temp net/mlx5e: TLS, Do not expose FPGA TLS counter if not supported net/mlx5e: Enable adding peer miss rules only if merged eswitch is supported tipc: use skb_unshare() instead in tipc_buf_append() tipc: fix shutdown() of connection oriented socket tipc: Fix memory leak in tipc_group_create_member() taprio: Fix allowing too small intervals nfp: use correct define to return NONE fec net: sctp: Fix IPv6 ancestor_size calc in sctp_copy_descendant net: sch_generic: aviod concurrent reset and enqueue op for lockless qdisc net/mlx5: Fix FTE cleanup net: ipv6: fix kconfig dependency warning for IPV6_SEG6_HMAC net: Fix bridge enslavement failure net: dsa: rtl8366: Properly clear member config net: DCB: Validate DCB_ATTR_DCB_BUFFER argument net: bridge: br_vlan_get_pvid_rcu() should dereference the VLAN group under RCU ipv6: avoid lockdep issue in fib6_del() ipv4: Update exception handling for multipath routes via same device ipv4: Initialize flowi4_multipath_hash in data path ip: fix tos reflection in ack and reset packets hdlc_ppp: add range checks in ppp_cp_parse_cr() geneve: add transport ports in route lookup for geneve cxgb4: Fix offset when clearing filter byte counters cxgb4: fix memory leak during module unload bnxt_en: Fix NULL ptr dereference crash in bnxt_fw_reset_task() bnxt_en: Avoid sending firmware messages when AER error is detected. act_ife: load meta modules before tcf_idr_check_alloc() mm/thp: fix __split_huge_pmd_locked() for migration PMD kprobes: fix kill kprobe which has been marked as gone ibmvnic: add missing parenthesis in do_reset() ibmvnic fix NULL tx_pools and rx_tools issue at do_reset af_key: pfkey_dump needs parameter validation Revert "ehci-hcd: Move include to keep CRC stable" Linux 5.4.67 dax: Fix compilation for CONFIG_DAX && !CONFIG_FS_DAX dm: Call proper helper to determine dax support mm/memory_hotplug: drain per-cpu pages again during memory offline dm/dax: Fix table reference counts selftests/vm: fix display of page size in map_hugetlb powerpc/dma: Fix dma_map_ops::get_required_mask ehci-hcd: Move include to keep CRC stable s390/zcrypt: fix kmalloc 256k failure x86/boot/compressed: Disable relocation relaxation serial: 8250_pci: Add Realtek 816a and 816b Input: i8042 - add Entroware Proteus EL07R4 to nomux and reset lists Input: trackpoint - add new trackpoint variant IDs percpu: fix first chunk size calculation for populated bitmap ALSA: hda/realtek - The Mic on a RedmiBook doesn't work ALSA: hda: fixup headset for ASUS GX502 laptop Revert "ALSA: hda - Fix silent audio output and corrupted input on MSI X570-A PRO" i2c: i801: Fix resume bug usb: typec: ucsi: Prevent mode overrun usblp: fix race between disconnect() and read() USB: UAS: fix disconnect by unplugging a hub USB: quirks: Add USB_QUIRK_IGNORE_REMOTE_WAKEUP quirk for BYD zhaoxin notebook drm/i915: Filter wake_flags passed to default_wake_function riscv: Add sfence.vma after early page table changes i2c: mxs: use MXS_DMA_CTRL_WAIT4END instead of DMA_CTRL_ACK iommu/amd: Fix potential @entry null deref arm64: bpf: Fix branch offset in JIT drm/mediatek: Add missing put_device() call in mtk_hdmi_dt_parse_pdata() drm/mediatek: Add exception handing in mtk_drm_probe() if component init fail MIPS: SNI: Fix spurious interrupts fbcon: Fix user font detection test at fbcon_resize(). perf test: Free formats for perf pmu parse test perf parse-event: Fix memory leak in evsel->unit perf evlist: Fix cpu/thread map leak MIPS: SNI: Fix MIPS_L1_CACHE_SHIFT perf test: Fix the "signal" test inline assembly Drivers: hv: vmbus: Add timeout to vmbus_wait_for_unload arm64: Allow CPUs unffected by ARM erratum1418040to come in late scsi: libsas: Fix error path in sas_notify_lldd_dev_found() Drivers: hv: vmbus: hibernation: do not hang forever in vmbus_bus_resume() ASoC: meson: axg-toddr: fix channel order on g12 platforms powerpc/book3s64/radix: Fix boot failure with large amount of guest memory ASoC: qcom: common: Fix refcount imbalance on error ASoC: qcom: Set card->owner to avoid warnings clk: rockchip: Fix initialization of mux_pll_src_4plls_p clk: davinci: Use the correct size when allocating memory KVM: MIPS: Change the definition of kvm type spi: Fix memory leak on splited transfers i2c: algo: pca: Reapply i2c bus settings after reset f2fs: Return EOF on unaligned end of file DIO read f2fs: fix indefinite loop scanning for free nid block: only call sched requeue_request() for scheduled requests nvme-tcp: cancel async events before freeing event struct nvme-rdma: cancel async events before freeing event struct nvme-fc: cancel async events before freeing event struct openrisc: Fix cache API compile issue when not inlining cifs: fix DFS mount with cifsacl/modefromsid rapidio: Replace 'select' DMAENGINES 'with depends on' SUNRPC: stop printk reading past end of string NFS: Zero-stateid SETATTR should first return delegation spi: spi-loopback-test: Fix out-of-bounds read regulator: pwm: Fix machine constraints application scsi: lpfc: Fix FLOGI/PLOGI receive race condition in pt2pt discovery scsi: libfc: Fix for double free() scsi: pm8001: Fix memleak in pm8001_exec_internal_task_abort NFSv4.1 handle ERR_DELAY error reclaiming locking state on delegation recall firmware_loader: fix memory leak for paged buffer hv_netvsc: Remove "unlikely" from netvsc_select_queue net: handle the return value of pskb_carve_frag_list() correctly dsa: Allow forwarding of redirected IGMP traffic e1000e: Add support for Comet Lake RDMA/bnxt_re: Restrict the max_gids to 256 gfs2: initialize transaction tr_ailX_lists earlier Revert "netfilter: conntrack: allow sctp hearbeat after connection re-use" Linux 5.4.66 gcov: add support for GCC 10.1 drm/msm: Disable the RPTR shadow drm/msm/gpu: make ringbuffer readonly usb: typec: ucsi: acpi: Check the _DEP dependencies usb: Fix out of sync data toggle if a configured device is reconfigured USB: serial: option: add support for SIM7070/SIM7080/SIM7090 modules USB: serial: option: support dynamic Quectel USB compositions USB: serial: ftdi_sio: add IDs for Xsens Mti USB converter usb: core: fix slab-out-of-bounds Read in read_descriptors phy: qcom-qmp: Use correct values for ipq8074 PCIe Gen2 PHY init staging: greybus: audio: fix uninitialized value issue video: fbdev: fix OOB read in vga_8planes_imageblit() ARM: dts: vfxxx: Add syscon compatible with OCOTP debugfs: Fix module state check condition KVM: fix memory leak in kvm_io_bus_unregister_dev() KVM: arm64: Do not try to map PUDs when they are folded into PMD KVM: VMX: Don't freeze guest when event delivery causes an APIC-access exit vgacon: remove software scrollback support fbcon: remove now unusued 'softback_lines' cursor() argument fbcon: remove soft scrollback code RDMA/mlx4: Read pkey table length instead of hardcoded value RDMA/rxe: Fix the parent sysfs read when the interface has 15 chars rbd: require global CAP_SYS_ADMIN for mapping and unmapping mmc: sdhci-of-esdhc: Don't walk device-tree on every interrupt mmc: sdio: Use mmc_pre_req() / mmc_post_req() drm/msm: Disable preemption on all 5xx targets drm/tve200: Stabilize enable/disable drm/i915/gvt: do not check len & max_len for lri scsi: target: iscsi: Fix hang in iscsit_access_np() when getting tpg->np_login_sem scsi: target: iscsi: Fix data digest calculation regulator: core: Fix slab-out-of-bounds in regulator_unlock_recursive() regulator: plug of_node leak in regulator_register()'s error path regulator: push allocation in set_consumer_device_supply() out of lock regulator: push allocations in create_regulator() outside of lock regulator: push allocation in regulator_init_coupling() outside of lock kobject: Restore old behaviour of kobject_del(NULL) btrfs: fix wrong address when faulting in pages in the search ioctl btrfs: fix lockdep splat in add_missing_dev btrfs: require only sector size alignment for parent eb bytenr staging: wlan-ng: fix out of bounds read in prism2sta_probe_usb() iio:accel:mma8452: Fix timestamp alignment and prevent data leak. iio:accel:mma7455: Fix timestamp alignment and prevent data leak. iio: accel: kxsd9: Fix alignment of local buffer. iio:chemical:ccs811: Fix timestamp alignment and prevent data leak. iio:light:max44000 Fix timestamp alignment and prevent data leak. iio:magnetometer:ak8975 Fix alignment and data leak issues. iio:adc:ti-adc081c Fix alignment and data leak issues iio:adc:max1118 Fix alignment of timestamp and data leak issues iio:adc:ina2xx Fix timestamp alignment issue. iio:adc:ti-adc084s021 Fix alignment and data leak issues. iio:accel:bmc150-accel: Fix timestamp alignment and prevent data leak. iio:proximity:mb1232: Fix timestamp alignment and prevent data leak. iio:light:ltr501 Fix timestamp alignment issue. iio: cros_ec: Set Gyroscope default frequency to 25Hz iio: adc: ti-ads1015: fix conversion when CONFIG_PM is not set gcov: Disable gcov build with GCC 10 iommu/amd: Do not use IOMMUv2 functionality when SME is active drm/amdgpu: Fix bug in reporting voltage for CIK ALSA: hda: fix a runtime pm issue in SOF when integrated GPU is disabled ALSA: hda: hdmi - add Rocketlake support arm64/module: set trampoline section flags regardless of CONFIG_DYNAMIC_FTRACE cpufreq: intel_pstate: Fix intel_pstate_get_hwp_max() for turbo disabled cpufreq: intel_pstate: Refuse to turn off with HWP enabled ARC: [plat-hsdk]: Switch ethernet phy-mode to rgmii-id HID: elan: Fix memleak in elan_input_configured drivers/net/wan/hdlc_cisco: Add hard_header_len HID: microsoft: Add rumble support for the 8bitdo SN30 Pro+ controller HID: quirks: Set INCREMENT_USAGE_ON_DUPLICATE for all Saitek X52 devices nvme-pci: cancel nvme device request before disabling nvme-rdma: fix reset hang if controller died in the middle of a reset nvme-rdma: fix timeout handler nvme-rdma: serialize controller teardown sequences nvme-tcp: fix reset hang if controller died in the middle of a reset nvme-tcp: fix timeout handler nvme-tcp: serialize controller teardown sequences nvme: have nvme_wait_freeze_timeout return if it timed out nvme-fabrics: don't check state NVME_CTRL_NEW for request acceptance nvmet-tcp: Fix NULL dereference when a connect data comes in h2cdata pdu irqchip/eznps: Fix build error for !ARC700 builds xfs: initialize the shortform attr header padding entry cfg80211: Adjust 6 GHz frequency to channel conversion drivers/net/wan/lapbether: Set network_header before transmitting xfs: fix off-by-one in inode alloc block reservation calculation net: hns3: Fix for geneve tx checksum bug drivers/dma/dma-jz4780: Fix race condition between probe and irq handler ALSA: hda/tegra: Program WAKEEN register for Tegra ALSA: hda: Fix 2 channel swapping for Tegra firestream: Fix memleak in fs_open NFC: st95hf: Fix memleak in st95hf_in_send_cmd drivers/net/wan/lapbether: Added needed_tailroom netfilter: conntrack: allow sctp hearbeat after connection re-use dmaengine: acpi: Put the CSRT table after using it ARC: HSDK: wireup perf irq arm64: dts: ns2: Fixed QSPI compatible string ARM: dts: BCM5301X: Fixed QSPI compatible string ARM: dts: NSP: Fixed QSPI compatible string ARM: dts: bcm: HR2: Fixed QSPI compatible string IB/isert: Fix unaligned immediate-data handling block: Set same_page to false in __bio_try_merge_page if ret is false spi: stm32: fix pm_runtime_get_sync() error checking nvme-fabrics: allow to queue requests for live queues spi: stm32: Rate-limit the 'Communication suspended' message mmc: sdhci-msm: Add retries when all tuning phases are found valid mmc: sdhci-acpi: Clear amd_sdhci_host on reset drm/sun4i: backend: Disable alpha on the lowest plane on the A20 drm/sun4i: backend: Support alpha property on lowest plane soundwire: fix double free of dangling pointer scsi: mpt3sas: Don't call disable_irq from IRQ poll handler scsi: megaraid_sas: Don't call disable_irq from process IRQ poll RDMA/core: Fix reported speed and width scsi: libsas: Set data_dir as DMA_NONE if libata marks qc as NODATA iio: adc: mcp3422: fix locking scope iio: adc: mcp3422: fix locking on error path drm/sun4i: Fix dsi dcs long write function arm64: dts: imx8mq: Fix TMU interrupt property drm/sun4i: add missing put_device() call in sun8i_r40_tcon_tv_set_mux() RDMA/bnxt_re: Do not report transparent vlan from QP1 RDMA/rxe: Fix panic when calling kmem_cache_create() RDMA/rxe: Drop pointless checks in rxe_init_ports RDMA/rxe: Fix memleak in rxe_mem_init_user ARM: dts: imx7ulp: Correct gpio ranges ARM: dts: ls1021a: fix QuadSPI-memory reg range selftests/timers: Turn off timeout setting ARM: dts: socfpga: fix register entry for timer3 on Arria10 regulator: remove superfluous lock in regulator_resolve_coupling() regulator: push allocation in regulator_ena_gpio_request() out of lock ARM: dts: logicpd-som-lv-baseboard: Fix missing video ARM: dts: logicpd-som-lv-baseboard: Fix broken audio ARM: dts: logicpd-torpedo-baseboard: Fix broken audio Linux 5.4.65 net: disable netpoll on fresh napis tipc: fix shutdown() of connectionless socket taprio: Fix using wrong queues in gate mask sctp: not disable bh in the whole sctp_get_port_local() net: usb: dm9601: Add USB ID of Keenetic Plus DSL netlabel: fix problems with mapping removal ipv6: Fix sysctl max for fib_multipath_hash_policy ipv4: Silence suspicious RCU usage warning Linux 5.4.64 net: usb: Fix uninit-was-stored issue in asix_read_phy_addr() cfg80211: regulatory: reject invalid hints mm/khugepaged.c: fix khugepaged's request size in collapse_file mm/hugetlb: fix a race between hugetlb sysctl handlers checkpatch: fix the usage of capture group ( ... ) sdhci: tegra: Add missing TMCLK for data timeout perf record: Correct the help info of option "--no-bpf-event" vfio/pci: Fix SR-IOV VF handling with MMIO blocking mm: madvise: fix vma user-after-free mm: slub: fix conversion of freelist_corrupted() dm thin metadata: Fix use-after-free in dm_bm_set_read_only dm thin metadata: Avoid returning cmd->bm wild pointer on error dm cache metadata: Avoid returning cmd->bm wild pointer on error dm crypt: Initialize crypto wait structures dm integrity: fix error reporting in bitmap mode after creation dm mpath: fix racey management of PG initialization dm writecache: handle DAX to partitions on persistent memory correctly drm/amd/pm: avoid false alarm due to confusing softwareshutdowntemp setting dmaengine: dw-edma: Fix scatter-gather address calculation blk-iocost: ioc_pd_free() shouldn't assume irq disabled libata: implement ATA_HORKAGE_MAX_TRIM_128M and apply to Sandisks block: ensure bdi->io_pages is always initialized block: allow for_each_bvec to support zero len bvec affs: fix basic permission bits to actually work media: rc: uevent sysfs file races with rc_unregister_device() media: rc: do not access device via sysfs after rc_unregister_device() mmc: sdhci-pci: Fix SDHCI_RESET_ALL for CQHCI for Intel GLK-based controllers mmc: cqhci: Add cqhci_deactivate() mmc: dt-bindings: Add resets/reset-names for Mediatek MMC bindings mmc: mediatek: add optional module reset property arm64: dts: mt7622: add reset node for mmc device ALSA: hda/realtek - Improved routing for Thinkpad X1 7th/8th Gen ALSA: hda/realtek: Add quirk for Samsung Galaxy Book Ion NT950XCJ-X716A ALSA; firewire-tascam: exclude Tascam FE-8 from detection ALSA: hda - Fix silent audio output and corrupted input on MSI X570-A PRO ALSA: firewire-digi00x: exclude Avid Adrenaline from detection ALSA: hda/hdmi: always check pin power status in i915 pin fixup ALSA: pcm: oss: Remove superfluous WARN_ON() for mulaw sanity check ALSA: usb-audio: Add implicit feedback quirk for UR22C ALSA: ca0106: fix error code handling Revert "ALSA: hda: Add support for Loongson 7A1000 controller" Revert "net: dsa: microchip: set the correct number of ports" btrfs: fix potential deadlock in the search ioctl net: core: use listified Rx for GRO_NORMAL in napi_gro_receive() btrfs: tree-checker: fix the error message for transid error btrfs: set the lockdep class for log tree extent buffers btrfs: set the correct lockdep class for new nodes btrfs: allocate scrub workqueues outside of locks btrfs: drop path before adding new uuid tree entry ARC: perf: don't bail setup if pct irq missing in device-tree xfs: don't update mtime on COW faults ext2: don't update mtime on COW faults tracing/kprobes, x86/ptrace: Fix regs argument order for i386 iommu/vt-d: Handle 36bit addressing for x86-32 vfio-pci: Invalidate mmaps and block MMIO access on disabled memory vfio-pci: Fault mmaps to enable vma tracking vfio/type1: Support faulting PFNMAP vmas include/linux/log2.h: add missing () around n in roundup_pow_of_two() net/packet: fix overflow in tpacket_rcv iommu/amd: Restore IRTE.RemapEn bit after programming IRTE thermal: qcom-spmi-temp-alarm: Don't suppress negative temp thermal: ti-soc-thermal: Fix bogus thermal shutdowns for omap4430 iommu/vt-d: Serialize IOMMU GCMD register modifications x86, fakenuma: Fix invalid starting node ID tg3: Fix soft lockup when tg3_reset_task() fails. perf jevents: Fix suspicious code in fixregex() xfs: fix xfs_bmap_validate_extent_raw when checking attr fork of rt files MIPS: add missing MSACSR and upper MSA initialization net: gemini: Fix another missing clk_disable_unprepare() in probe fix regression in "epoll: Keep a reference on files added to the check list" net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() perf tools: Correct SNOOPX field offset cxgb4: fix thermal zone device registration nvme: fix controller instance leak nvmet-fc: Fix a missed _irqsave version of spin_lock in 'nvmet_fc_fod_op_done()' netfilter: nfnetlink: nfnetlink_unicast() reports EAGAIN instead of ENOBUFS net: dsa: mt7530: fix advertising unsupported 1000baseT_Half selftests/bpf: Fix massive output from test_maps media: cedrus: Add missing v4l2_ctrl_request_hdl_put() media: vicodec: add missing v4l2_ctrl_request_hdl_put() bnxt: don't enable NAPI until rings are ready xfs: fix boundary test in xfs_attr_shortform_verify bnxt_en: fix HWRM error when querying VF temperature bnxt_en: Fix possible crash in bnxt_fw_reset_task(). bnxt_en: Fix PCI AER error recovery flow bnxt_en: Check for zero dir entries in NVRAM. bnxt_en: Don't query FW when netif_running() is false. net: ethernet: ti: cpsw: fix clean up of vlan mc entries for host port gtp: add GTPA_LINK info to msg sent to userspace dmaengine: pl330: Fix burst length if burst size is smaller than bus width net: arc_emac: Fix memleak in arc_mdio_probe ravb: Fixed to be able to unload modules net: systemport: Fix memleak in bcm_sysport_probe net: hns: Fix memleak in hns_nic_dev_probe netfilter: nf_tables: fix destination register zeroing netfilter: nf_tables: incorrect enum nft_list_attributes definition netfilter: nf_tables: add NFTA_SET_USERDATA if not null mmc: sdhci-acpi: Fix HS400 tuning for AMDI0040 MIPS: BMIPS: Also call bmips_cpu_setup() for secondary cores MIPS: mm: BMIPS5000 has inclusive physical caches rxrpc: Make rxrpc_kernel_get_srtt() indicate validity rxrpc: Keep the ACK serial in a var in rxrpc_input_ack() dmaengine: at_hdmac: check return value of of_find_device_by_node() in at_dma_xlate() batman-adv: bla: use netif_rx_ni when not in interrupt context batman-adv: Fix own OGM check in aggregated OGMs batman-adv: Avoid uninitialized chaddr when handling DHCP dmaengine: of-dma: Fix of_dma_router_xlate's of_dma_xlate handling fsldma: fix very broken 32-bit ppc ioread64 functionality xen/xenbus: Fix granting of vmalloc'd memory drm/amd/display: Fix memleak in amdgpu_dm_mode_config_init drm/amd/display: Retry AUX write when fail occurs drivers: gpu: amd: Initialize amdgpu_dm_backlight_caps object to 0 in amdgpu_dm_update_backlight_caps drm/amd/display: Reject overlay plane configurations in multi-display scenarios s390: don't trace preemption in percpu macros nbd: restore default timeout when setting it to zero cpuidle: Fixup IRQ state drm/omap: fix incorrect lock state ceph: don't allow setlease on cephfs drm/msm/a6xx: fix gmu start on newer firmware habanalabs: check correct vmalloc return code habanalabs: validate FW file size drm/msm: enable vblank during atomic commits nvmet: Disable keep-alive timer when kato is cleared to 0h hwmon: (applesmc) check status earlier. drm/msm: add shutdown support for display platform_driver tty: serial: qcom_geni_serial: Drop __init from qcom_geni_console_setup drm/msm/dpu: Fix scale params in plane validation HID: quirks: Always poll three more Lenovo PixArt mice Linux 5.4.63 scsi: target: tcmu: Optimize use of flush_dcache_page scsi: target: tcmu: Fix size in calls to tcmu_flush_dcache_range sdhci: tegra: Remove SDHCI_QUIRK_DATA_TIMEOUT_USES_SDCLK for Tegra186 sdhci: tegra: Remove SDHCI_QUIRK_DATA_TIMEOUT_USES_SDCLK for Tegra210 arm64: tegra: Add missing timeout clock to Tegra210 SDMMC arm64: tegra: Add missing timeout clock to Tegra186 SDMMC nodes arm64: tegra: Add missing timeout clock to Tegra194 SDMMC nodes dt-bindings: mmc: tegra: Add tmclk for Tegra210 and later KVM: arm64: Set HCR_EL2.PTW to prevent AT taking synchronous exception KVM: arm64: Survive synchronous exceptions caused by AT instructions KVM: arm64: Add kvm_extable for vaxorcism code drm/etnaviv: fix TS cache flushing on GPUs with BLT engine drm/sched: Fix passing zero to 'PTR_ERR' warning v2 perf record/stat: Explicitly call out event modifiers in the documentation HID: core: Sanitize event code and type when mapping input HID: core: Correctly handle ReportSize being zero Linux 5.4.62 io_uring: Fix NULL pointer dereference in io_sq_wq_submit_work() ALSA: usb-audio: Update documentation comment for MS2109 quirk HID: hiddev: Fix slab-out-of-bounds write in hiddev_ioctl_usage() kbuild: fix broken builds because of GZIP,BZIP2,LZOP variables kbuild: add variables for compression tools kheaders: explain why include/config/autoconf.h is excluded from md5sum kheaders: remove the last bashism to allow sh to run it kheaders: optimize header copy for in-tree builds kheaders: optimize md5sum calculation for in-tree builds kheaders: remove unneeded 'cat' command piped to 'head' / 'tail' fbmem: pull fbcon_update_vcs() out of fb_set_var() usb: dwc3: gadget: Handle ZLP for sg requests usb: dwc3: gadget: Fix handling ZLP usb: dwc3: gadget: Don't setup more than requested drm/i915: Fix cmd parser desc matching with masks usb: storage: Add unusual_uas entry for Sony PSZ drives USB: cdc-acm: rework notification_buffer resizing USB: gadget: u_f: Unbreak offset calculation in VLAs USB: gadget: f_ncm: add bounds checks to ncm_unwrap_ntb() USB: gadget: u_f: add overflow checks to VLA macros usb: host: ohci-exynos: Fix error handling in exynos_ohci_probe() USB: Ignore UAS for JMicron JMS567 ATA/ATAPI Bridge USB: quirks: Ignore duplicate endpoint on Sound Devices MixPre-D USB: quirks: Add no-lpm quirk for another Raydium touchscreen usb: uas: Add quirk for PNY Pro Elite USB: yurex: Fix bad gfp argument drm/amd/pm: correct the thermal alert temperature limit settings drm/amd/pm: correct Vega20 swctf limit setting drm/amd/pm: correct Vega12 swctf limit setting drm/amd/pm: correct Vega10 swctf limit setting drm/amd/powerplay: Fix hardmins not being sent to SMU for RV drm/amdgpu/gfx10: refine mgcg setting drm/amdgpu: Fix buffer overflow in INFO ioctl x86/hotplug: Silence APIC only after all interrupts are migrated irqchip/stm32-exti: Avoid losing interrupts due to clearing pending bits by mistake genirq/matrix: Deal with the sillyness of for_each_cpu() on UP crypto: af_alg - Work around empty control messages without MSG_MORE device property: Fix the secondary firmware node handling in set_primary_fwnode() powerpc/perf: Fix crashes with generic_compat_pmu & BHRB PM: sleep: core: Fix the handling of pending runtime resume requests arm64: vdso32: make vdso32 install conditional xhci: Always restore EP_SOFT_CLEAR_TOGGLE even if ep reset failed xhci: Do warm-reset when both CAS and XDEV_RESUME are set usb: host: xhci: fix ep context print mismatch in debugfs XEN uses irqdesc::irq_data_common::handler_data to store a per interrupt XEN data pointer which contains XEN specific information. writeback: Fix sync livelock due to b_dirty_time processing writeback: Avoid skipping inode writeback writeback: Protect inode->i_io_list with inode->i_lock serial: 8250: change lock order in serial8250_do_startup() serial: 8250_exar: Fix number of ports for Commtech PCIe cards serial: stm32: avoid kernel warning on absence of optional IRQ serial: pl011: Don't leak amba_ports entry on driver register error serial: pl011: Fix oops on -EPROBE_DEFER serial: samsung: Removes the IRQ not found warning vt_ioctl: change VT_RESIZEX ioctl to check for error return from vc_resize() vt: defer kfree() of vc_screenbuf in vc_do_resize() USB: lvtest: return proper error code in probe fbcon: prevent user font height or width change from causing potential out-of-bounds access btrfs: detect nocow for swap after snapshot delete btrfs: fix space cache memory leak after transaction abort btrfs: check the right error variable in btrfs_del_dir_entries_in_log btrfs: reset compression level for lzo on remount blk-mq: order adding requests to hctx->dispatch and checking SCHED_RESTART HID: i2c-hid: Always sleep 60ms after I2C_HID_PWR_ON commands block: loop: set discard granularity and alignment for block device backed loop block: fix get_max_io_size() arm64: Allow booting of late CPUs affected by erratum1418040arm64: Move handling of erratum1418040into C code powerpc/perf: Fix soft lockups due to missed interrupt accounting net: gianfar: Add of_node_put() before goto statement macvlan: validate setting of multiple remote source MAC addresses Revert "scsi: qla2xxx: Fix crash on qla2x00_mailbox_command" scsi: qla2xxx: Fix null pointer access during disconnect from subsystem scsi: qla2xxx: Check if FW supports MQ before enabling scsi: qla2xxx: Fix login timeout scsi: ufs: Clean up completed request without interrupt notification scsi: ufs: Improve interrupt handling for shared interrupts scsi: ufs: Fix possible infinite loop in ufshcd_hold scsi: fcoe: Fix I/O path allocation selftests: disable rp_filter for icmp_redirect.sh ASoC: wm8994: Avoid attempts to read unreadable registers s390/cio: add cond_resched() in the slow_eval_known_fn() loop ALSA: hda/realtek: Add model alc298-samsung-headphone can: j1939: transport: j1939_xtp_rx_dat_one(): compare own packets to detect corruptions netfilter: avoid ipv6 -> nf_defrag_ipv6 module dependency drm/amd/display: Switch to immediate mode for updating infopackets drm/amd/powerplay: correct UVD/VCE PG state on custom pptable uploading drm/amd/powerplay: correct Vega20 cached smu feature state spi: stm32: always perform registers configuration prior to transfer spi: stm32: fix stm32_spi_prepare_mbr in case of odd clk_rate spi: stm32: fix fifo threshold level in case of short transfer spi: stm32h7: fix race condition at end of transfer fs: prevent BUG_ON in submit_bh_wbc() ext4: correctly restore system zone info when remount fails ext4: handle error of ext4_setup_system_zone() on remount ext4: handle option set by mount flags correctly jbd2: abort journal if free a async write error metadata buffer ext4: handle read only external journal device ext4: don't BUG on inconsistent journal feature jbd2: make sure jh have b_transaction set in refile/unfile_buffer spi: stm32: clear only asserted irq flags on interrupt usb: gadget: f_tcm: Fix some resource leaks in some error paths i2c: rcar: in slave mode, clear NACK earlier i2c: core: Don't fail PRP0001 enumeration when no ID table exist null_blk: fix passing of REQ_FUA flag in null_handle_rq nvme: multipath: round-robin: fix single non-optimized path case nvme-fc: Fix wrong return value in __nvme_fc_init_request() blkcg: fix memleak for iolatency blk-mq: insert request not through ->queue_rq into sw/scheduler queue hwmon: (nct7904) Correct divide by 0 bfq: fix blkio cgroup leakage v4 block: Fix page_is_mergeable() for compound pages drm/msm/adreno: fix updating ring fence block: virtio_blk: fix handling single range discard request block: respect queue limit of max discard segment media: gpio-ir-tx: improve precision of transmitted signal due to scheduling ALSA: usb-audio: Add capture support for Saffire 6 (USB 1.1) cpufreq: intel_pstate: Fix EPP setting via sysfs in active mode PCI: qcom: Add missing reset for ipq806x PCI: qcom: Change duplicate PCI reset to phy reset PCI: qcom: Add missing ipq806x clocks in PCIe driver EDAC/{i7core,sb,pnd2,skx}: Fix error event severity EDAC: skx_common: get rid of unused type var EDAC: sb_edac: get rid of unused vars mm/vunmap: add cond_resched() in vunmap_pmd_range drm/amd/display: Fix dmesg warning from setting abm level drm/amd/display: Add additional config guards for DCN drm/amd/display: Trigger modesets on MST DSC connectors drm/ingenic: Fix incorrect assumption about plane->index gpu/drm: ingenic: Use the plane's src_[x,y] to configure DMA length cma: don't quit at first error when activating reserved areas mm/cma.c: switch to bitmap_zalloc() for cma bitmap allocation mm: fix kthread_use_mm() vs TLB invalidate mm/shuffle: don't move pages between zones and don't read garbage memmaps btrfs: only commit delayed items at fsync if we are logging a directory btrfs: only commit the delayed inode when doing a full fsync btrfs: factor out inode items copy loop from btrfs_log_inode() s390/numa: set node distance to LOCAL_DISTANCE drm/xen-front: Fix misused IS_ERR_OR_NULL checks drm/xen: fix passing zero to 'PTR_ERR' warning PM / devfreq: rk3399_dmc: Fix kernel oops when rockchip,pmu is absent PM / devfreq: rk3399_dmc: Disable devfreq-event device when fails PM / devfreq: rk3399_dmc: Add missing of_node_put() usb: cdns3: gadget: always zeroed TRB buffer when enable endpoint sched/uclamp: Fix a deadlock when enabling uclamp static key sched/uclamp: Protect uclamp fast path code with static key Revert "ath10k: fix DMA related firmware crashes on multiple devices" arm64: Fix __cpu_logical_map undefined issue efi: provide empty efi_enter_virtual_mode implementation brcmfmac: Set timeout value when configuring power save USB: sisusbvga: Fix a potential UB casued by left shifting a negative value powerpc/spufs: add CONFIG_COREDUMP dependency KVM: arm64: Fix symbol dependency in __hyp_call_panic_nvhe media: davinci: vpif_capture: fix potential double free hugetlbfs: prevent filesystem stacking of hugetlbfs EDAC/ie31200: Fallback if host bridge device is already initialized scsi: fcoe: Memory leak fix in fcoe_sysfs_fcf_del() ceph: do not access the kiocb after aio requests ceph: fix potential mdsc use-after-free crash scsi: iscsi: Do not put host in iscsi_set_flashnode_param() btrfs: make btrfs_qgroup_check_reserved_leak take btrfs_inode btrfs: file: reserve qgroup space after the hole punch range is locked locking/lockdep: Fix overflow in presentation of average lock-time drm/nouveau: Fix reference count leak in nouveau_connector_detect drm/nouveau: fix reference count leak in nv50_disp_atomic_commit drm/nouveau/drm/noveau: fix reference count leak in nouveau_fbcon_open f2fs: fix use-after-free issue HID: quirks: add NOGET quirk for Logitech GROUP cec-api: prevent leaking memory through hole in structure ALSA: hda: Add support for Loongson 7A1000 controller mips/vdso: Fix resource leaks in genvdso.c rtlwifi: rtl8192cu: Prevent leaking urb ARM: dts: ls1021a: output PPS signal on FIPER2 PCI: Fix pci_create_slot() reference count leak omapfb: fix multiple reference count leaks due to pm_runtime_get_sync f2fs: fix error path in do_recover_data() selftests/powerpc: Purge extra count_pmc() calls of ebb selftests scsi: target: Fix xcopy sess release leak xfs: Don't allow logging of XFS_ISTALE inodes scsi: lpfc: Fix shost refcount mismatch when deleting vport drm/amdgpu/display: fix ref count leak when pm_runtime_get_sync fails drm/amdgpu: fix ref count leak in amdgpu_display_crtc_set_config drm/amd/display: fix ref count leak in amdgpu_drm_ioctl drm/amdgpu: fix ref count leak in amdgpu_driver_open_kms drm/radeon: fix multiple reference count leak drm/amdkfd: Fix reference count leaks. iommu/iova: Don't BUG on invalid PFNs mfd: intel-lpss: Add Intel Tiger Lake PCH-H PCI IDs scsi: target: tcmu: Fix crash on ARM during cmd completion blktrace: ensure our debugfs dir exists media: pci: ttpci: av7110: fix possible buffer overflow caused by bad DMA value in debiirq() powerpc/xive: Ignore kmemleak false positives arm64: dts: qcom: msm8916: Pull down PDM GPIOs during sleep mfd: intel-lpss: Add Intel Emmitsburg PCH PCI IDs ASoC: tegra: Fix reference count leaks. ASoC: img-parallel-out: Fix a reference count leak ASoC: img: Fix a reference count leak in img_i2s_in_set_fmt ALSA: hda/hdmi: Use force connectivity quirk on another HP desktop ALSA: hda/realtek: Fix pin default on Intel NUC 8 Rugged ALSA: pci: delete repeated words in comments ALSA: hda/hdmi: Add quirk to force connectivity ipvlan: fix device features net/sched: act_ct: Fix skb double-free in tcf_ct_handle_fragments() error flow net: ena: Make missed_tx stat incremental tipc: fix uninit skb->data in tipc_nl_compat_dumpit() net/smc: Prevent kernel-infoleak in __smc_diag_dump() net: sctp: Fix negotiation of the number of data streams. net: qrtr: fix usage of idr in port assignment to socket net: nexthop: don't allow empty NHA_GROUP net: Fix potential wrong skb->protocol in skb_vlan_untag() gre6: Fix reception with IP6_TNL_F_RCV_DSCP_COPY binfmt_flat: revert "binfmt_flat: don't offset the data start" powerpc/64s: Don't init FSCR_DSCR in __init_FSCR() Conflicts: Documentation/devicetree/bindings Documentation/devicetree/bindings/gpio/sgpio-aspeed.txt Documentation/devicetree/bindings/mmc/mtk-sd.txt Documentation/devicetree/bindings/mmc/nvidia,tegra20-sdhci.txt Documentation/devicetree/bindings/net/can/tcan4x5x.txt Documentation/devicetree/bindings/net/nfc/nxp-nci.txt Documentation/devicetree/bindings/net/nfc/pn544.txt Documentation/devicetree/bindings/sound/wm8994.txt block/bio.c block/blk-mq-sysfs.c block/blk-sysfs.c drivers/hid/hid-quirks.c drivers/mailbox/mailbox.c drivers/mmc/host/cqhci.c drivers/scsi/ufs/ufshcd.c drivers/soc/qcom/smp2p.c drivers/usb/dwc3/core.c drivers/usb/dwc3/core.h drivers/usb/dwc3/ep0.c drivers/usb/dwc3/gadget.c drivers/usb/dwc3/gadget.h drivers/usb/gadget/function/f_fs.c drivers/usb/host/xhci.c kernel/sched/cpufreq_schedutil.c mm/cma.c mm/madvise.c mm/memory.c mm/page_alloc.c net/qrtr/qrtr.c Change-Id: I5d64dc5428045e92d5d1ce73dd55f78b36e83371 Signed-off-by: Srinivasarao P <spathi@codeaurora.org>
4632 lines
118 KiB
C
4632 lines
118 KiB
C
// SPDX-License-Identifier: GPL-2.0-only
|
|
/*
|
|
* linux/kernel/signal.c
|
|
*
|
|
* Copyright (C) 1991, 1992 Linus Torvalds
|
|
*
|
|
* 1997-11-02 Modified for POSIX.1b signals by Richard Henderson
|
|
*
|
|
* 2003-06-02 Jim Houston - Concurrent Computer Corp.
|
|
* Changes to use preallocated sigqueue structures
|
|
* to allow signals to be sent reliably.
|
|
*/
|
|
|
|
#include <linux/slab.h>
|
|
#include <linux/export.h>
|
|
#include <linux/init.h>
|
|
#include <linux/sched/mm.h>
|
|
#include <linux/sched/user.h>
|
|
#include <linux/sched/debug.h>
|
|
#include <linux/sched/task.h>
|
|
#include <linux/sched/task_stack.h>
|
|
#include <linux/sched/cputime.h>
|
|
#include <linux/file.h>
|
|
#include <linux/fs.h>
|
|
#include <linux/proc_fs.h>
|
|
#include <linux/tty.h>
|
|
#include <linux/binfmts.h>
|
|
#include <linux/coredump.h>
|
|
#include <linux/security.h>
|
|
#include <linux/syscalls.h>
|
|
#include <linux/ptrace.h>
|
|
#include <linux/signal.h>
|
|
#include <linux/signalfd.h>
|
|
#include <linux/ratelimit.h>
|
|
#include <linux/tracehook.h>
|
|
#include <linux/capability.h>
|
|
#include <linux/freezer.h>
|
|
#include <linux/pid_namespace.h>
|
|
#include <linux/nsproxy.h>
|
|
#include <linux/user_namespace.h>
|
|
#include <linux/uprobes.h>
|
|
#include <linux/compat.h>
|
|
#include <linux/cn_proc.h>
|
|
#include <linux/compiler.h>
|
|
#include <linux/posix-timers.h>
|
|
#include <linux/livepatch.h>
|
|
#include <linux/cgroup.h>
|
|
#include <linux/audit.h>
|
|
#include <linux/oom.h>
|
|
|
|
#define CREATE_TRACE_POINTS
|
|
#include <trace/events/signal.h>
|
|
|
|
#include <asm/param.h>
|
|
#include <linux/uaccess.h>
|
|
#include <asm/unistd.h>
|
|
#include <asm/siginfo.h>
|
|
#include <asm/cacheflush.h>
|
|
|
|
/*
|
|
* SLAB caches for signal bits.
|
|
*/
|
|
|
|
static struct kmem_cache *sigqueue_cachep;
|
|
|
|
int print_fatal_signals __read_mostly;
|
|
|
|
static void __user *sig_handler(struct task_struct *t, int sig)
|
|
{
|
|
return t->sighand->action[sig - 1].sa.sa_handler;
|
|
}
|
|
|
|
static inline bool sig_handler_ignored(void __user *handler, int sig)
|
|
{
|
|
/* Is it explicitly or implicitly ignored? */
|
|
return handler == SIG_IGN ||
|
|
(handler == SIG_DFL && sig_kernel_ignore(sig));
|
|
}
|
|
|
|
static bool sig_task_ignored(struct task_struct *t, int sig, bool force)
|
|
{
|
|
void __user *handler;
|
|
|
|
handler = sig_handler(t, sig);
|
|
|
|
/* SIGKILL and SIGSTOP may not be sent to the global init */
|
|
if (unlikely(is_global_init(t) && sig_kernel_only(sig)))
|
|
return true;
|
|
|
|
if (unlikely(t->signal->flags & SIGNAL_UNKILLABLE) &&
|
|
handler == SIG_DFL && !(force && sig_kernel_only(sig)))
|
|
return true;
|
|
|
|
/* Only allow kernel generated signals to this kthread */
|
|
if (unlikely((t->flags & PF_KTHREAD) &&
|
|
(handler == SIG_KTHREAD_KERNEL) && !force))
|
|
return true;
|
|
|
|
return sig_handler_ignored(handler, sig);
|
|
}
|
|
|
|
static bool sig_ignored(struct task_struct *t, int sig, bool force)
|
|
{
|
|
/*
|
|
* Blocked signals are never ignored, since the
|
|
* signal handler may change by the time it is
|
|
* unblocked.
|
|
*/
|
|
if (sigismember(&t->blocked, sig) || sigismember(&t->real_blocked, sig))
|
|
return false;
|
|
|
|
/*
|
|
* Tracers may want to know about even ignored signal unless it
|
|
* is SIGKILL which can't be reported anyway but can be ignored
|
|
* by SIGNAL_UNKILLABLE task.
|
|
*/
|
|
if (t->ptrace && sig != SIGKILL)
|
|
return false;
|
|
|
|
return sig_task_ignored(t, sig, force);
|
|
}
|
|
|
|
/*
|
|
* Re-calculate pending state from the set of locally pending
|
|
* signals, globally pending signals, and blocked signals.
|
|
*/
|
|
static inline bool has_pending_signals(sigset_t *signal, sigset_t *blocked)
|
|
{
|
|
unsigned long ready;
|
|
long i;
|
|
|
|
switch (_NSIG_WORDS) {
|
|
default:
|
|
for (i = _NSIG_WORDS, ready = 0; --i >= 0 ;)
|
|
ready |= signal->sig[i] &~ blocked->sig[i];
|
|
break;
|
|
|
|
case 4: ready = signal->sig[3] &~ blocked->sig[3];
|
|
ready |= signal->sig[2] &~ blocked->sig[2];
|
|
ready |= signal->sig[1] &~ blocked->sig[1];
|
|
ready |= signal->sig[0] &~ blocked->sig[0];
|
|
break;
|
|
|
|
case 2: ready = signal->sig[1] &~ blocked->sig[1];
|
|
ready |= signal->sig[0] &~ blocked->sig[0];
|
|
break;
|
|
|
|
case 1: ready = signal->sig[0] &~ blocked->sig[0];
|
|
}
|
|
return ready != 0;
|
|
}
|
|
|
|
#define PENDING(p,b) has_pending_signals(&(p)->signal, (b))
|
|
|
|
static bool recalc_sigpending_tsk(struct task_struct *t)
|
|
{
|
|
if ((t->jobctl & (JOBCTL_PENDING_MASK | JOBCTL_TRAP_FREEZE)) ||
|
|
PENDING(&t->pending, &t->blocked) ||
|
|
PENDING(&t->signal->shared_pending, &t->blocked) ||
|
|
cgroup_task_frozen(t)) {
|
|
set_tsk_thread_flag(t, TIF_SIGPENDING);
|
|
return true;
|
|
}
|
|
|
|
/*
|
|
* We must never clear the flag in another thread, or in current
|
|
* when it's possible the current syscall is returning -ERESTART*.
|
|
* So we don't clear it here, and only callers who know they should do.
|
|
*/
|
|
return false;
|
|
}
|
|
|
|
/*
|
|
* After recalculating TIF_SIGPENDING, we need to make sure the task wakes up.
|
|
* This is superfluous when called on current, the wakeup is a harmless no-op.
|
|
*/
|
|
void recalc_sigpending_and_wake(struct task_struct *t)
|
|
{
|
|
if (recalc_sigpending_tsk(t))
|
|
signal_wake_up(t, 0);
|
|
}
|
|
|
|
void recalc_sigpending(void)
|
|
{
|
|
if (!recalc_sigpending_tsk(current) && !freezing(current) &&
|
|
!klp_patch_pending(current))
|
|
clear_thread_flag(TIF_SIGPENDING);
|
|
|
|
}
|
|
EXPORT_SYMBOL(recalc_sigpending);
|
|
|
|
void calculate_sigpending(void)
|
|
{
|
|
/* Have any signals or users of TIF_SIGPENDING been delayed
|
|
* until after fork?
|
|
*/
|
|
spin_lock_irq(¤t->sighand->siglock);
|
|
set_tsk_thread_flag(current, TIF_SIGPENDING);
|
|
recalc_sigpending();
|
|
spin_unlock_irq(¤t->sighand->siglock);
|
|
}
|
|
|
|
/* Given the mask, find the first available signal that should be serviced. */
|
|
|
|
#define SYNCHRONOUS_MASK \
|
|
(sigmask(SIGSEGV) | sigmask(SIGBUS) | sigmask(SIGILL) | \
|
|
sigmask(SIGTRAP) | sigmask(SIGFPE) | sigmask(SIGSYS))
|
|
|
|
int next_signal(struct sigpending *pending, sigset_t *mask)
|
|
{
|
|
unsigned long i, *s, *m, x;
|
|
int sig = 0;
|
|
|
|
s = pending->signal.sig;
|
|
m = mask->sig;
|
|
|
|
/*
|
|
* Handle the first word specially: it contains the
|
|
* synchronous signals that need to be dequeued first.
|
|
*/
|
|
x = *s &~ *m;
|
|
if (x) {
|
|
if (x & SYNCHRONOUS_MASK)
|
|
x &= SYNCHRONOUS_MASK;
|
|
sig = ffz(~x) + 1;
|
|
return sig;
|
|
}
|
|
|
|
switch (_NSIG_WORDS) {
|
|
default:
|
|
for (i = 1; i < _NSIG_WORDS; ++i) {
|
|
x = *++s &~ *++m;
|
|
if (!x)
|
|
continue;
|
|
sig = ffz(~x) + i*_NSIG_BPW + 1;
|
|
break;
|
|
}
|
|
break;
|
|
|
|
case 2:
|
|
x = s[1] &~ m[1];
|
|
if (!x)
|
|
break;
|
|
sig = ffz(~x) + _NSIG_BPW + 1;
|
|
break;
|
|
|
|
case 1:
|
|
/* Nothing to do */
|
|
break;
|
|
}
|
|
|
|
return sig;
|
|
}
|
|
|
|
static inline void print_dropped_signal(int sig)
|
|
{
|
|
static DEFINE_RATELIMIT_STATE(ratelimit_state, 5 * HZ, 10);
|
|
|
|
if (!print_fatal_signals)
|
|
return;
|
|
|
|
if (!__ratelimit(&ratelimit_state))
|
|
return;
|
|
|
|
pr_info("%s/%d: reached RLIMIT_SIGPENDING, dropped signal %d\n",
|
|
current->comm, current->pid, sig);
|
|
}
|
|
|
|
/**
|
|
* task_set_jobctl_pending - set jobctl pending bits
|
|
* @task: target task
|
|
* @mask: pending bits to set
|
|
*
|
|
* Clear @mask from @task->jobctl. @mask must be subset of
|
|
* %JOBCTL_PENDING_MASK | %JOBCTL_STOP_CONSUME | %JOBCTL_STOP_SIGMASK |
|
|
* %JOBCTL_TRAPPING. If stop signo is being set, the existing signo is
|
|
* cleared. If @task is already being killed or exiting, this function
|
|
* becomes noop.
|
|
*
|
|
* CONTEXT:
|
|
* Must be called with @task->sighand->siglock held.
|
|
*
|
|
* RETURNS:
|
|
* %true if @mask is set, %false if made noop because @task was dying.
|
|
*/
|
|
bool task_set_jobctl_pending(struct task_struct *task, unsigned long mask)
|
|
{
|
|
BUG_ON(mask & ~(JOBCTL_PENDING_MASK | JOBCTL_STOP_CONSUME |
|
|
JOBCTL_STOP_SIGMASK | JOBCTL_TRAPPING));
|
|
BUG_ON((mask & JOBCTL_TRAPPING) && !(mask & JOBCTL_PENDING_MASK));
|
|
|
|
if (unlikely(fatal_signal_pending(task) || (task->flags & PF_EXITING)))
|
|
return false;
|
|
|
|
if (mask & JOBCTL_STOP_SIGMASK)
|
|
task->jobctl &= ~JOBCTL_STOP_SIGMASK;
|
|
|
|
task->jobctl |= mask;
|
|
return true;
|
|
}
|
|
|
|
/**
|
|
* task_clear_jobctl_trapping - clear jobctl trapping bit
|
|
* @task: target task
|
|
*
|
|
* If JOBCTL_TRAPPING is set, a ptracer is waiting for us to enter TRACED.
|
|
* Clear it and wake up the ptracer. Note that we don't need any further
|
|
* locking. @task->siglock guarantees that @task->parent points to the
|
|
* ptracer.
|
|
*
|
|
* CONTEXT:
|
|
* Must be called with @task->sighand->siglock held.
|
|
*/
|
|
void task_clear_jobctl_trapping(struct task_struct *task)
|
|
{
|
|
if (unlikely(task->jobctl & JOBCTL_TRAPPING)) {
|
|
task->jobctl &= ~JOBCTL_TRAPPING;
|
|
smp_mb(); /* advised by wake_up_bit() */
|
|
wake_up_bit(&task->jobctl, JOBCTL_TRAPPING_BIT);
|
|
}
|
|
}
|
|
|
|
/**
|
|
* task_clear_jobctl_pending - clear jobctl pending bits
|
|
* @task: target task
|
|
* @mask: pending bits to clear
|
|
*
|
|
* Clear @mask from @task->jobctl. @mask must be subset of
|
|
* %JOBCTL_PENDING_MASK. If %JOBCTL_STOP_PENDING is being cleared, other
|
|
* STOP bits are cleared together.
|
|
*
|
|
* If clearing of @mask leaves no stop or trap pending, this function calls
|
|
* task_clear_jobctl_trapping().
|
|
*
|
|
* CONTEXT:
|
|
* Must be called with @task->sighand->siglock held.
|
|
*/
|
|
void task_clear_jobctl_pending(struct task_struct *task, unsigned long mask)
|
|
{
|
|
BUG_ON(mask & ~JOBCTL_PENDING_MASK);
|
|
|
|
if (mask & JOBCTL_STOP_PENDING)
|
|
mask |= JOBCTL_STOP_CONSUME | JOBCTL_STOP_DEQUEUED;
|
|
|
|
task->jobctl &= ~mask;
|
|
|
|
if (!(task->jobctl & JOBCTL_PENDING_MASK))
|
|
task_clear_jobctl_trapping(task);
|
|
}
|
|
|
|
/**
|
|
* task_participate_group_stop - participate in a group stop
|
|
* @task: task participating in a group stop
|
|
*
|
|
* @task has %JOBCTL_STOP_PENDING set and is participating in a group stop.
|
|
* Group stop states are cleared and the group stop count is consumed if
|
|
* %JOBCTL_STOP_CONSUME was set. If the consumption completes the group
|
|
* stop, the appropriate `SIGNAL_*` flags are set.
|
|
*
|
|
* CONTEXT:
|
|
* Must be called with @task->sighand->siglock held.
|
|
*
|
|
* RETURNS:
|
|
* %true if group stop completion should be notified to the parent, %false
|
|
* otherwise.
|
|
*/
|
|
static bool task_participate_group_stop(struct task_struct *task)
|
|
{
|
|
struct signal_struct *sig = task->signal;
|
|
bool consume = task->jobctl & JOBCTL_STOP_CONSUME;
|
|
|
|
WARN_ON_ONCE(!(task->jobctl & JOBCTL_STOP_PENDING));
|
|
|
|
task_clear_jobctl_pending(task, JOBCTL_STOP_PENDING);
|
|
|
|
if (!consume)
|
|
return false;
|
|
|
|
if (!WARN_ON_ONCE(sig->group_stop_count == 0))
|
|
sig->group_stop_count--;
|
|
|
|
/*
|
|
* Tell the caller to notify completion iff we are entering into a
|
|
* fresh group stop. Read comment in do_signal_stop() for details.
|
|
*/
|
|
if (!sig->group_stop_count && !(sig->flags & SIGNAL_STOP_STOPPED)) {
|
|
signal_set_stop_flags(sig, SIGNAL_STOP_STOPPED);
|
|
return true;
|
|
}
|
|
return false;
|
|
}
|
|
|
|
void task_join_group_stop(struct task_struct *task)
|
|
{
|
|
unsigned long mask = current->jobctl & JOBCTL_STOP_SIGMASK;
|
|
struct signal_struct *sig = current->signal;
|
|
|
|
if (sig->group_stop_count) {
|
|
sig->group_stop_count++;
|
|
mask |= JOBCTL_STOP_CONSUME;
|
|
} else if (!(sig->flags & SIGNAL_STOP_STOPPED))
|
|
return;
|
|
|
|
/* Have the new thread join an on-going signal group stop */
|
|
task_set_jobctl_pending(task, mask | JOBCTL_STOP_PENDING);
|
|
}
|
|
|
|
/*
|
|
* allocate a new signal queue record
|
|
* - this may be called without locks if and only if t == current, otherwise an
|
|
* appropriate lock must be held to stop the target task from exiting
|
|
*/
|
|
static struct sigqueue *
|
|
__sigqueue_alloc(int sig, struct task_struct *t, gfp_t flags, int override_rlimit)
|
|
{
|
|
struct sigqueue *q = NULL;
|
|
struct user_struct *user;
|
|
int sigpending;
|
|
|
|
/*
|
|
* Protect access to @t credentials. This can go away when all
|
|
* callers hold rcu read lock.
|
|
*
|
|
* NOTE! A pending signal will hold on to the user refcount,
|
|
* and we get/put the refcount only when the sigpending count
|
|
* changes from/to zero.
|
|
*/
|
|
rcu_read_lock();
|
|
user = __task_cred(t)->user;
|
|
sigpending = atomic_inc_return(&user->sigpending);
|
|
if (sigpending == 1)
|
|
get_uid(user);
|
|
rcu_read_unlock();
|
|
|
|
if (override_rlimit || likely(sigpending <= task_rlimit(t, RLIMIT_SIGPENDING))) {
|
|
q = kmem_cache_alloc(sigqueue_cachep, flags);
|
|
} else {
|
|
print_dropped_signal(sig);
|
|
}
|
|
|
|
if (unlikely(q == NULL)) {
|
|
if (atomic_dec_and_test(&user->sigpending))
|
|
free_uid(user);
|
|
} else {
|
|
INIT_LIST_HEAD(&q->list);
|
|
q->flags = 0;
|
|
q->user = user;
|
|
}
|
|
|
|
return q;
|
|
}
|
|
|
|
static void __sigqueue_free(struct sigqueue *q)
|
|
{
|
|
if (q->flags & SIGQUEUE_PREALLOC)
|
|
return;
|
|
if (atomic_dec_and_test(&q->user->sigpending))
|
|
free_uid(q->user);
|
|
kmem_cache_free(sigqueue_cachep, q);
|
|
}
|
|
|
|
void flush_sigqueue(struct sigpending *queue)
|
|
{
|
|
struct sigqueue *q;
|
|
|
|
sigemptyset(&queue->signal);
|
|
while (!list_empty(&queue->list)) {
|
|
q = list_entry(queue->list.next, struct sigqueue , list);
|
|
list_del_init(&q->list);
|
|
__sigqueue_free(q);
|
|
}
|
|
}
|
|
|
|
/*
|
|
* Flush all pending signals for this kthread.
|
|
*/
|
|
void flush_signals(struct task_struct *t)
|
|
{
|
|
unsigned long flags;
|
|
|
|
spin_lock_irqsave(&t->sighand->siglock, flags);
|
|
clear_tsk_thread_flag(t, TIF_SIGPENDING);
|
|
flush_sigqueue(&t->pending);
|
|
flush_sigqueue(&t->signal->shared_pending);
|
|
spin_unlock_irqrestore(&t->sighand->siglock, flags);
|
|
}
|
|
EXPORT_SYMBOL(flush_signals);
|
|
|
|
#ifdef CONFIG_POSIX_TIMERS
|
|
static void __flush_itimer_signals(struct sigpending *pending)
|
|
{
|
|
sigset_t signal, retain;
|
|
struct sigqueue *q, *n;
|
|
|
|
signal = pending->signal;
|
|
sigemptyset(&retain);
|
|
|
|
list_for_each_entry_safe(q, n, &pending->list, list) {
|
|
int sig = q->info.si_signo;
|
|
|
|
if (likely(q->info.si_code != SI_TIMER)) {
|
|
sigaddset(&retain, sig);
|
|
} else {
|
|
sigdelset(&signal, sig);
|
|
list_del_init(&q->list);
|
|
__sigqueue_free(q);
|
|
}
|
|
}
|
|
|
|
sigorsets(&pending->signal, &signal, &retain);
|
|
}
|
|
|
|
void flush_itimer_signals(void)
|
|
{
|
|
struct task_struct *tsk = current;
|
|
unsigned long flags;
|
|
|
|
spin_lock_irqsave(&tsk->sighand->siglock, flags);
|
|
__flush_itimer_signals(&tsk->pending);
|
|
__flush_itimer_signals(&tsk->signal->shared_pending);
|
|
spin_unlock_irqrestore(&tsk->sighand->siglock, flags);
|
|
}
|
|
#endif
|
|
|
|
void ignore_signals(struct task_struct *t)
|
|
{
|
|
int i;
|
|
|
|
for (i = 0; i < _NSIG; ++i)
|
|
t->sighand->action[i].sa.sa_handler = SIG_IGN;
|
|
|
|
flush_signals(t);
|
|
}
|
|
|
|
/*
|
|
* Flush all handlers for a task.
|
|
*/
|
|
|
|
void
|
|
flush_signal_handlers(struct task_struct *t, int force_default)
|
|
{
|
|
int i;
|
|
struct k_sigaction *ka = &t->sighand->action[0];
|
|
for (i = _NSIG ; i != 0 ; i--) {
|
|
if (force_default || ka->sa.sa_handler != SIG_IGN)
|
|
ka->sa.sa_handler = SIG_DFL;
|
|
ka->sa.sa_flags = 0;
|
|
#ifdef __ARCH_HAS_SA_RESTORER
|
|
ka->sa.sa_restorer = NULL;
|
|
#endif
|
|
sigemptyset(&ka->sa.sa_mask);
|
|
ka++;
|
|
}
|
|
}
|
|
|
|
bool unhandled_signal(struct task_struct *tsk, int sig)
|
|
{
|
|
void __user *handler = tsk->sighand->action[sig-1].sa.sa_handler;
|
|
if (is_global_init(tsk))
|
|
return true;
|
|
|
|
if (handler != SIG_IGN && handler != SIG_DFL)
|
|
return false;
|
|
|
|
/* if ptraced, let the tracer determine */
|
|
return !tsk->ptrace;
|
|
}
|
|
|
|
static void collect_signal(int sig, struct sigpending *list, kernel_siginfo_t *info,
|
|
bool *resched_timer)
|
|
{
|
|
struct sigqueue *q, *first = NULL;
|
|
|
|
/*
|
|
* Collect the siginfo appropriate to this signal. Check if
|
|
* there is another siginfo for the same signal.
|
|
*/
|
|
list_for_each_entry(q, &list->list, list) {
|
|
if (q->info.si_signo == sig) {
|
|
if (first)
|
|
goto still_pending;
|
|
first = q;
|
|
}
|
|
}
|
|
|
|
sigdelset(&list->signal, sig);
|
|
|
|
if (first) {
|
|
still_pending:
|
|
list_del_init(&first->list);
|
|
copy_siginfo(info, &first->info);
|
|
|
|
*resched_timer =
|
|
(first->flags & SIGQUEUE_PREALLOC) &&
|
|
(info->si_code == SI_TIMER) &&
|
|
(info->si_sys_private);
|
|
|
|
__sigqueue_free(first);
|
|
} else {
|
|
/*
|
|
* Ok, it wasn't in the queue. This must be
|
|
* a fast-pathed signal or we must have been
|
|
* out of queue space. So zero out the info.
|
|
*/
|
|
clear_siginfo(info);
|
|
info->si_signo = sig;
|
|
info->si_errno = 0;
|
|
info->si_code = SI_USER;
|
|
info->si_pid = 0;
|
|
info->si_uid = 0;
|
|
}
|
|
}
|
|
|
|
static int __dequeue_signal(struct sigpending *pending, sigset_t *mask,
|
|
kernel_siginfo_t *info, bool *resched_timer)
|
|
{
|
|
int sig = next_signal(pending, mask);
|
|
|
|
if (sig)
|
|
collect_signal(sig, pending, info, resched_timer);
|
|
return sig;
|
|
}
|
|
|
|
/*
|
|
* Dequeue a signal and return the element to the caller, which is
|
|
* expected to free it.
|
|
*
|
|
* All callers have to hold the siglock.
|
|
*/
|
|
int dequeue_signal(struct task_struct *tsk, sigset_t *mask, kernel_siginfo_t *info)
|
|
{
|
|
bool resched_timer = false;
|
|
int signr;
|
|
|
|
/* We only dequeue private signals from ourselves, we don't let
|
|
* signalfd steal them
|
|
*/
|
|
signr = __dequeue_signal(&tsk->pending, mask, info, &resched_timer);
|
|
if (!signr) {
|
|
signr = __dequeue_signal(&tsk->signal->shared_pending,
|
|
mask, info, &resched_timer);
|
|
#ifdef CONFIG_POSIX_TIMERS
|
|
/*
|
|
* itimer signal ?
|
|
*
|
|
* itimers are process shared and we restart periodic
|
|
* itimers in the signal delivery path to prevent DoS
|
|
* attacks in the high resolution timer case. This is
|
|
* compliant with the old way of self-restarting
|
|
* itimers, as the SIGALRM is a legacy signal and only
|
|
* queued once. Changing the restart behaviour to
|
|
* restart the timer in the signal dequeue path is
|
|
* reducing the timer noise on heavy loaded !highres
|
|
* systems too.
|
|
*/
|
|
if (unlikely(signr == SIGALRM)) {
|
|
struct hrtimer *tmr = &tsk->signal->real_timer;
|
|
|
|
if (!hrtimer_is_queued(tmr) &&
|
|
tsk->signal->it_real_incr != 0) {
|
|
hrtimer_forward(tmr, tmr->base->get_time(),
|
|
tsk->signal->it_real_incr);
|
|
hrtimer_restart(tmr);
|
|
}
|
|
}
|
|
#endif
|
|
}
|
|
|
|
recalc_sigpending();
|
|
if (!signr)
|
|
return 0;
|
|
|
|
if (unlikely(sig_kernel_stop(signr))) {
|
|
/*
|
|
* Set a marker that we have dequeued a stop signal. Our
|
|
* caller might release the siglock and then the pending
|
|
* stop signal it is about to process is no longer in the
|
|
* pending bitmasks, but must still be cleared by a SIGCONT
|
|
* (and overruled by a SIGKILL). So those cases clear this
|
|
* shared flag after we've set it. Note that this flag may
|
|
* remain set after the signal we return is ignored or
|
|
* handled. That doesn't matter because its only purpose
|
|
* is to alert stop-signal processing code when another
|
|
* processor has come along and cleared the flag.
|
|
*/
|
|
current->jobctl |= JOBCTL_STOP_DEQUEUED;
|
|
}
|
|
#ifdef CONFIG_POSIX_TIMERS
|
|
if (resched_timer) {
|
|
/*
|
|
* Release the siglock to ensure proper locking order
|
|
* of timer locks outside of siglocks. Note, we leave
|
|
* irqs disabled here, since the posix-timers code is
|
|
* about to disable them again anyway.
|
|
*/
|
|
spin_unlock(&tsk->sighand->siglock);
|
|
posixtimer_rearm(info);
|
|
spin_lock(&tsk->sighand->siglock);
|
|
|
|
/* Don't expose the si_sys_private value to userspace */
|
|
info->si_sys_private = 0;
|
|
}
|
|
#endif
|
|
return signr;
|
|
}
|
|
EXPORT_SYMBOL_GPL(dequeue_signal);
|
|
|
|
static int dequeue_synchronous_signal(kernel_siginfo_t *info)
|
|
{
|
|
struct task_struct *tsk = current;
|
|
struct sigpending *pending = &tsk->pending;
|
|
struct sigqueue *q, *sync = NULL;
|
|
|
|
/*
|
|
* Might a synchronous signal be in the queue?
|
|
*/
|
|
if (!((pending->signal.sig[0] & ~tsk->blocked.sig[0]) & SYNCHRONOUS_MASK))
|
|
return 0;
|
|
|
|
/*
|
|
* Return the first synchronous signal in the queue.
|
|
*/
|
|
list_for_each_entry(q, &pending->list, list) {
|
|
/* Synchronous signals have a postive si_code */
|
|
if ((q->info.si_code > SI_USER) &&
|
|
(sigmask(q->info.si_signo) & SYNCHRONOUS_MASK)) {
|
|
sync = q;
|
|
goto next;
|
|
}
|
|
}
|
|
return 0;
|
|
next:
|
|
/*
|
|
* Check if there is another siginfo for the same signal.
|
|
*/
|
|
list_for_each_entry_continue(q, &pending->list, list) {
|
|
if (q->info.si_signo == sync->info.si_signo)
|
|
goto still_pending;
|
|
}
|
|
|
|
sigdelset(&pending->signal, sync->info.si_signo);
|
|
recalc_sigpending();
|
|
still_pending:
|
|
list_del_init(&sync->list);
|
|
copy_siginfo(info, &sync->info);
|
|
__sigqueue_free(sync);
|
|
return info->si_signo;
|
|
}
|
|
|
|
/*
|
|
* Tell a process that it has a new active signal..
|
|
*
|
|
* NOTE! we rely on the previous spin_lock to
|
|
* lock interrupts for us! We can only be called with
|
|
* "siglock" held, and the local interrupt must
|
|
* have been disabled when that got acquired!
|
|
*
|
|
* No need to set need_resched since signal event passing
|
|
* goes through ->blocked
|
|
*/
|
|
void signal_wake_up_state(struct task_struct *t, unsigned int state)
|
|
{
|
|
set_tsk_thread_flag(t, TIF_SIGPENDING);
|
|
/*
|
|
* TASK_WAKEKILL also means wake it up in the stopped/traced/killable
|
|
* case. We don't check t->state here because there is a race with it
|
|
* executing another processor and just now entering stopped state.
|
|
* By using wake_up_state, we ensure the process will wake up and
|
|
* handle its death signal.
|
|
*/
|
|
if (!wake_up_state(t, state | TASK_INTERRUPTIBLE))
|
|
kick_process(t);
|
|
}
|
|
|
|
/*
|
|
* Remove signals in mask from the pending set and queue.
|
|
* Returns 1 if any signals were found.
|
|
*
|
|
* All callers must be holding the siglock.
|
|
*/
|
|
static void flush_sigqueue_mask(sigset_t *mask, struct sigpending *s)
|
|
{
|
|
struct sigqueue *q, *n;
|
|
sigset_t m;
|
|
|
|
sigandsets(&m, mask, &s->signal);
|
|
if (sigisemptyset(&m))
|
|
return;
|
|
|
|
sigandnsets(&s->signal, &s->signal, mask);
|
|
list_for_each_entry_safe(q, n, &s->list, list) {
|
|
if (sigismember(mask, q->info.si_signo)) {
|
|
list_del_init(&q->list);
|
|
__sigqueue_free(q);
|
|
}
|
|
}
|
|
}
|
|
|
|
static inline int is_si_special(const struct kernel_siginfo *info)
|
|
{
|
|
return info <= SEND_SIG_PRIV;
|
|
}
|
|
|
|
static inline bool si_fromuser(const struct kernel_siginfo *info)
|
|
{
|
|
return info == SEND_SIG_NOINFO ||
|
|
(!is_si_special(info) && SI_FROMUSER(info));
|
|
}
|
|
|
|
/*
|
|
* called with RCU read lock from check_kill_permission()
|
|
*/
|
|
static bool kill_ok_by_cred(struct task_struct *t)
|
|
{
|
|
const struct cred *cred = current_cred();
|
|
const struct cred *tcred = __task_cred(t);
|
|
|
|
return uid_eq(cred->euid, tcred->suid) ||
|
|
uid_eq(cred->euid, tcred->uid) ||
|
|
uid_eq(cred->uid, tcred->suid) ||
|
|
uid_eq(cred->uid, tcred->uid) ||
|
|
ns_capable(tcred->user_ns, CAP_KILL);
|
|
}
|
|
|
|
/*
|
|
* Bad permissions for sending the signal
|
|
* - the caller must hold the RCU read lock
|
|
*/
|
|
static int check_kill_permission(int sig, struct kernel_siginfo *info,
|
|
struct task_struct *t)
|
|
{
|
|
struct pid *sid;
|
|
int error;
|
|
|
|
if (!valid_signal(sig))
|
|
return -EINVAL;
|
|
|
|
if (!si_fromuser(info))
|
|
return 0;
|
|
|
|
error = audit_signal_info(sig, t); /* Let audit system see the signal */
|
|
if (error)
|
|
return error;
|
|
|
|
if (!same_thread_group(current, t) &&
|
|
!kill_ok_by_cred(t)) {
|
|
switch (sig) {
|
|
case SIGCONT:
|
|
sid = task_session(t);
|
|
/*
|
|
* We don't return the error if sid == NULL. The
|
|
* task was unhashed, the caller must notice this.
|
|
*/
|
|
if (!sid || sid == task_session(current))
|
|
break;
|
|
/* fall through */
|
|
default:
|
|
return -EPERM;
|
|
}
|
|
}
|
|
|
|
return security_task_kill(t, info, sig, NULL);
|
|
}
|
|
|
|
/**
|
|
* ptrace_trap_notify - schedule trap to notify ptracer
|
|
* @t: tracee wanting to notify tracer
|
|
*
|
|
* This function schedules sticky ptrace trap which is cleared on the next
|
|
* TRAP_STOP to notify ptracer of an event. @t must have been seized by
|
|
* ptracer.
|
|
*
|
|
* If @t is running, STOP trap will be taken. If trapped for STOP and
|
|
* ptracer is listening for events, tracee is woken up so that it can
|
|
* re-trap for the new event. If trapped otherwise, STOP trap will be
|
|
* eventually taken without returning to userland after the existing traps
|
|
* are finished by PTRACE_CONT.
|
|
*
|
|
* CONTEXT:
|
|
* Must be called with @task->sighand->siglock held.
|
|
*/
|
|
static void ptrace_trap_notify(struct task_struct *t)
|
|
{
|
|
WARN_ON_ONCE(!(t->ptrace & PT_SEIZED));
|
|
assert_spin_locked(&t->sighand->siglock);
|
|
|
|
task_set_jobctl_pending(t, JOBCTL_TRAP_NOTIFY);
|
|
ptrace_signal_wake_up(t, t->jobctl & JOBCTL_LISTENING);
|
|
}
|
|
|
|
/*
|
|
* Handle magic process-wide effects of stop/continue signals. Unlike
|
|
* the signal actions, these happen immediately at signal-generation
|
|
* time regardless of blocking, ignoring, or handling. This does the
|
|
* actual continuing for SIGCONT, but not the actual stopping for stop
|
|
* signals. The process stop is done as a signal action for SIG_DFL.
|
|
*
|
|
* Returns true if the signal should be actually delivered, otherwise
|
|
* it should be dropped.
|
|
*/
|
|
static bool prepare_signal(int sig, struct task_struct *p, bool force)
|
|
{
|
|
struct signal_struct *signal = p->signal;
|
|
struct task_struct *t;
|
|
sigset_t flush;
|
|
|
|
if (signal->flags & (SIGNAL_GROUP_EXIT | SIGNAL_GROUP_COREDUMP)) {
|
|
if (!(signal->flags & SIGNAL_GROUP_EXIT))
|
|
return sig == SIGKILL;
|
|
/*
|
|
* The process is in the middle of dying, nothing to do.
|
|
*/
|
|
} else if (sig_kernel_stop(sig)) {
|
|
/*
|
|
* This is a stop signal. Remove SIGCONT from all queues.
|
|
*/
|
|
siginitset(&flush, sigmask(SIGCONT));
|
|
flush_sigqueue_mask(&flush, &signal->shared_pending);
|
|
for_each_thread(p, t)
|
|
flush_sigqueue_mask(&flush, &t->pending);
|
|
} else if (sig == SIGCONT) {
|
|
unsigned int why;
|
|
/*
|
|
* Remove all stop signals from all queues, wake all threads.
|
|
*/
|
|
siginitset(&flush, SIG_KERNEL_STOP_MASK);
|
|
flush_sigqueue_mask(&flush, &signal->shared_pending);
|
|
for_each_thread(p, t) {
|
|
flush_sigqueue_mask(&flush, &t->pending);
|
|
task_clear_jobctl_pending(t, JOBCTL_STOP_PENDING);
|
|
if (likely(!(t->ptrace & PT_SEIZED)))
|
|
wake_up_state(t, __TASK_STOPPED);
|
|
else
|
|
ptrace_trap_notify(t);
|
|
}
|
|
|
|
/*
|
|
* Notify the parent with CLD_CONTINUED if we were stopped.
|
|
*
|
|
* If we were in the middle of a group stop, we pretend it
|
|
* was already finished, and then continued. Since SIGCHLD
|
|
* doesn't queue we report only CLD_STOPPED, as if the next
|
|
* CLD_CONTINUED was dropped.
|
|
*/
|
|
why = 0;
|
|
if (signal->flags & SIGNAL_STOP_STOPPED)
|
|
why |= SIGNAL_CLD_CONTINUED;
|
|
else if (signal->group_stop_count)
|
|
why |= SIGNAL_CLD_STOPPED;
|
|
|
|
if (why) {
|
|
/*
|
|
* The first thread which returns from do_signal_stop()
|
|
* will take ->siglock, notice SIGNAL_CLD_MASK, and
|
|
* notify its parent. See get_signal().
|
|
*/
|
|
signal_set_stop_flags(signal, why | SIGNAL_STOP_CONTINUED);
|
|
signal->group_stop_count = 0;
|
|
signal->group_exit_code = 0;
|
|
}
|
|
}
|
|
|
|
return !sig_ignored(p, sig, force);
|
|
}
|
|
|
|
/*
|
|
* Test if P wants to take SIG. After we've checked all threads with this,
|
|
* it's equivalent to finding no threads not blocking SIG. Any threads not
|
|
* blocking SIG were ruled out because they are not running and already
|
|
* have pending signals. Such threads will dequeue from the shared queue
|
|
* as soon as they're available, so putting the signal on the shared queue
|
|
* will be equivalent to sending it to one such thread.
|
|
*/
|
|
static inline bool wants_signal(int sig, struct task_struct *p)
|
|
{
|
|
if (sigismember(&p->blocked, sig))
|
|
return false;
|
|
|
|
if (p->flags & PF_EXITING)
|
|
return false;
|
|
|
|
if (sig == SIGKILL)
|
|
return true;
|
|
|
|
if (task_is_stopped_or_traced(p))
|
|
return false;
|
|
|
|
return task_curr(p) || !signal_pending(p);
|
|
}
|
|
|
|
static void complete_signal(int sig, struct task_struct *p, enum pid_type type)
|
|
{
|
|
struct signal_struct *signal = p->signal;
|
|
struct task_struct *t;
|
|
|
|
/*
|
|
* Now find a thread we can wake up to take the signal off the queue.
|
|
*
|
|
* If the main thread wants the signal, it gets first crack.
|
|
* Probably the least surprising to the average bear.
|
|
*/
|
|
if (wants_signal(sig, p))
|
|
t = p;
|
|
else if ((type == PIDTYPE_PID) || thread_group_empty(p))
|
|
/*
|
|
* There is just one thread and it does not need to be woken.
|
|
* It will dequeue unblocked signals before it runs again.
|
|
*/
|
|
return;
|
|
else {
|
|
/*
|
|
* Otherwise try to find a suitable thread.
|
|
*/
|
|
t = signal->curr_target;
|
|
while (!wants_signal(sig, t)) {
|
|
t = next_thread(t);
|
|
if (t == signal->curr_target)
|
|
/*
|
|
* No thread needs to be woken.
|
|
* Any eligible threads will see
|
|
* the signal in the queue soon.
|
|
*/
|
|
return;
|
|
}
|
|
signal->curr_target = t;
|
|
}
|
|
|
|
/*
|
|
* Found a killable thread. If the signal will be fatal,
|
|
* then start taking the whole group down immediately.
|
|
*/
|
|
if (sig_fatal(p, sig) &&
|
|
!(signal->flags & SIGNAL_GROUP_EXIT) &&
|
|
!sigismember(&t->real_blocked, sig) &&
|
|
(sig == SIGKILL || !p->ptrace)) {
|
|
/*
|
|
* This signal will be fatal to the whole group.
|
|
*/
|
|
if (!sig_kernel_coredump(sig)) {
|
|
/*
|
|
* Start a group exit and wake everybody up.
|
|
* This way we don't have other threads
|
|
* running and doing things after a slower
|
|
* thread has the fatal signal pending.
|
|
*/
|
|
signal->flags = SIGNAL_GROUP_EXIT;
|
|
signal->group_exit_code = sig;
|
|
signal->group_stop_count = 0;
|
|
t = p;
|
|
do {
|
|
task_clear_jobctl_pending(t, JOBCTL_PENDING_MASK);
|
|
sigaddset(&t->pending.signal, SIGKILL);
|
|
signal_wake_up(t, 1);
|
|
} while_each_thread(p, t);
|
|
return;
|
|
}
|
|
}
|
|
|
|
/*
|
|
* The signal is already in the shared-pending queue.
|
|
* Tell the chosen thread to wake up and dequeue it.
|
|
*/
|
|
signal_wake_up(t, sig == SIGKILL);
|
|
return;
|
|
}
|
|
|
|
static inline bool legacy_queue(struct sigpending *signals, int sig)
|
|
{
|
|
return (sig < SIGRTMIN) && sigismember(&signals->signal, sig);
|
|
}
|
|
|
|
static int __send_signal(int sig, struct kernel_siginfo *info, struct task_struct *t,
|
|
enum pid_type type, bool force)
|
|
{
|
|
struct sigpending *pending;
|
|
struct sigqueue *q;
|
|
int override_rlimit;
|
|
int ret = 0, result;
|
|
|
|
assert_spin_locked(&t->sighand->siglock);
|
|
|
|
result = TRACE_SIGNAL_IGNORED;
|
|
if (!prepare_signal(sig, t, force))
|
|
goto ret;
|
|
|
|
pending = (type != PIDTYPE_PID) ? &t->signal->shared_pending : &t->pending;
|
|
/*
|
|
* Short-circuit ignored signals and support queuing
|
|
* exactly one non-rt signal, so that we can get more
|
|
* detailed information about the cause of the signal.
|
|
*/
|
|
result = TRACE_SIGNAL_ALREADY_PENDING;
|
|
if (legacy_queue(pending, sig))
|
|
goto ret;
|
|
|
|
result = TRACE_SIGNAL_DELIVERED;
|
|
/*
|
|
* Skip useless siginfo allocation for SIGKILL and kernel threads.
|
|
*/
|
|
if ((sig == SIGKILL) || (t->flags & PF_KTHREAD))
|
|
goto out_set;
|
|
|
|
/*
|
|
* Real-time signals must be queued if sent by sigqueue, or
|
|
* some other real-time mechanism. It is implementation
|
|
* defined whether kill() does so. We attempt to do so, on
|
|
* the principle of least surprise, but since kill is not
|
|
* allowed to fail with EAGAIN when low on memory we just
|
|
* make sure at least one signal gets delivered and don't
|
|
* pass on the info struct.
|
|
*/
|
|
if (sig < SIGRTMIN)
|
|
override_rlimit = (is_si_special(info) || info->si_code >= 0);
|
|
else
|
|
override_rlimit = 0;
|
|
|
|
q = __sigqueue_alloc(sig, t, GFP_ATOMIC, override_rlimit);
|
|
if (q) {
|
|
list_add_tail(&q->list, &pending->list);
|
|
switch ((unsigned long) info) {
|
|
case (unsigned long) SEND_SIG_NOINFO:
|
|
clear_siginfo(&q->info);
|
|
q->info.si_signo = sig;
|
|
q->info.si_errno = 0;
|
|
q->info.si_code = SI_USER;
|
|
q->info.si_pid = task_tgid_nr_ns(current,
|
|
task_active_pid_ns(t));
|
|
rcu_read_lock();
|
|
q->info.si_uid =
|
|
from_kuid_munged(task_cred_xxx(t, user_ns),
|
|
current_uid());
|
|
rcu_read_unlock();
|
|
break;
|
|
case (unsigned long) SEND_SIG_PRIV:
|
|
clear_siginfo(&q->info);
|
|
q->info.si_signo = sig;
|
|
q->info.si_errno = 0;
|
|
q->info.si_code = SI_KERNEL;
|
|
q->info.si_pid = 0;
|
|
q->info.si_uid = 0;
|
|
break;
|
|
default:
|
|
copy_siginfo(&q->info, info);
|
|
break;
|
|
}
|
|
} else if (!is_si_special(info) &&
|
|
sig >= SIGRTMIN && info->si_code != SI_USER) {
|
|
/*
|
|
* Queue overflow, abort. We may abort if the
|
|
* signal was rt and sent by user using something
|
|
* other than kill().
|
|
*/
|
|
result = TRACE_SIGNAL_OVERFLOW_FAIL;
|
|
ret = -EAGAIN;
|
|
goto ret;
|
|
} else {
|
|
/*
|
|
* This is a silent loss of information. We still
|
|
* send the signal, but the *info bits are lost.
|
|
*/
|
|
result = TRACE_SIGNAL_LOSE_INFO;
|
|
}
|
|
|
|
out_set:
|
|
signalfd_notify(t, sig);
|
|
sigaddset(&pending->signal, sig);
|
|
|
|
/* Let multiprocess signals appear after on-going forks */
|
|
if (type > PIDTYPE_TGID) {
|
|
struct multiprocess_signals *delayed;
|
|
hlist_for_each_entry(delayed, &t->signal->multiprocess, node) {
|
|
sigset_t *signal = &delayed->signal;
|
|
/* Can't queue both a stop and a continue signal */
|
|
if (sig == SIGCONT)
|
|
sigdelsetmask(signal, SIG_KERNEL_STOP_MASK);
|
|
else if (sig_kernel_stop(sig))
|
|
sigdelset(signal, SIGCONT);
|
|
sigaddset(signal, sig);
|
|
}
|
|
}
|
|
|
|
complete_signal(sig, t, type);
|
|
ret:
|
|
trace_signal_generate(sig, info, t, type != PIDTYPE_PID, result);
|
|
return ret;
|
|
}
|
|
|
|
static inline bool has_si_pid_and_uid(struct kernel_siginfo *info)
|
|
{
|
|
bool ret = false;
|
|
switch (siginfo_layout(info->si_signo, info->si_code)) {
|
|
case SIL_KILL:
|
|
case SIL_CHLD:
|
|
case SIL_RT:
|
|
ret = true;
|
|
break;
|
|
case SIL_TIMER:
|
|
case SIL_POLL:
|
|
case SIL_FAULT:
|
|
case SIL_FAULT_MCEERR:
|
|
case SIL_FAULT_BNDERR:
|
|
case SIL_FAULT_PKUERR:
|
|
case SIL_SYS:
|
|
ret = false;
|
|
break;
|
|
}
|
|
return ret;
|
|
}
|
|
|
|
static int send_signal(int sig, struct kernel_siginfo *info, struct task_struct *t,
|
|
enum pid_type type)
|
|
{
|
|
/* Should SIGKILL or SIGSTOP be received by a pid namespace init? */
|
|
bool force = false;
|
|
|
|
if (info == SEND_SIG_NOINFO) {
|
|
/* Force if sent from an ancestor pid namespace */
|
|
force = !task_pid_nr_ns(current, task_active_pid_ns(t));
|
|
} else if (info == SEND_SIG_PRIV) {
|
|
/* Don't ignore kernel generated signals */
|
|
force = true;
|
|
} else if (has_si_pid_and_uid(info)) {
|
|
/* SIGKILL and SIGSTOP is special or has ids */
|
|
struct user_namespace *t_user_ns;
|
|
|
|
rcu_read_lock();
|
|
t_user_ns = task_cred_xxx(t, user_ns);
|
|
if (current_user_ns() != t_user_ns) {
|
|
kuid_t uid = make_kuid(current_user_ns(), info->si_uid);
|
|
info->si_uid = from_kuid_munged(t_user_ns, uid);
|
|
}
|
|
rcu_read_unlock();
|
|
|
|
/* A kernel generated signal? */
|
|
force = (info->si_code == SI_KERNEL);
|
|
|
|
/* From an ancestor pid namespace? */
|
|
if (!task_pid_nr_ns(current, task_active_pid_ns(t))) {
|
|
info->si_pid = 0;
|
|
force = true;
|
|
}
|
|
}
|
|
return __send_signal(sig, info, t, type, force);
|
|
}
|
|
|
|
static void print_fatal_signal(int signr)
|
|
{
|
|
struct pt_regs *regs = signal_pt_regs();
|
|
pr_info("potentially unexpected fatal signal %d.\n", signr);
|
|
|
|
#if defined(__i386__) && !defined(__arch_um__)
|
|
pr_info("code at %08lx: ", regs->ip);
|
|
{
|
|
int i;
|
|
for (i = 0; i < 16; i++) {
|
|
unsigned char insn;
|
|
|
|
if (get_user(insn, (unsigned char *)(regs->ip + i)))
|
|
break;
|
|
pr_cont("%02x ", insn);
|
|
}
|
|
}
|
|
pr_cont("\n");
|
|
#endif
|
|
preempt_disable();
|
|
show_regs(regs);
|
|
preempt_enable();
|
|
}
|
|
|
|
static int __init setup_print_fatal_signals(char *str)
|
|
{
|
|
get_option (&str, &print_fatal_signals);
|
|
|
|
return 1;
|
|
}
|
|
|
|
__setup("print-fatal-signals=", setup_print_fatal_signals);
|
|
|
|
int
|
|
__group_send_sig_info(int sig, struct kernel_siginfo *info, struct task_struct *p)
|
|
{
|
|
return send_signal(sig, info, p, PIDTYPE_TGID);
|
|
}
|
|
|
|
int do_send_sig_info(int sig, struct kernel_siginfo *info, struct task_struct *p,
|
|
enum pid_type type)
|
|
{
|
|
unsigned long flags;
|
|
int ret = -ESRCH;
|
|
|
|
if (lock_task_sighand(p, &flags)) {
|
|
ret = send_signal(sig, info, p, type);
|
|
unlock_task_sighand(p, &flags);
|
|
}
|
|
|
|
return ret;
|
|
}
|
|
|
|
/*
|
|
* Force a signal that the process can't ignore: if necessary
|
|
* we unblock the signal and change any SIG_IGN to SIG_DFL.
|
|
*
|
|
* Note: If we unblock the signal, we always reset it to SIG_DFL,
|
|
* since we do not want to have a signal handler that was blocked
|
|
* be invoked when user space had explicitly blocked it.
|
|
*
|
|
* We don't want to have recursive SIGSEGV's etc, for example,
|
|
* that is why we also clear SIGNAL_UNKILLABLE.
|
|
*/
|
|
static int
|
|
force_sig_info_to_task(struct kernel_siginfo *info, struct task_struct *t)
|
|
{
|
|
unsigned long int flags;
|
|
int ret, blocked, ignored;
|
|
struct k_sigaction *action;
|
|
int sig = info->si_signo;
|
|
|
|
spin_lock_irqsave(&t->sighand->siglock, flags);
|
|
action = &t->sighand->action[sig-1];
|
|
ignored = action->sa.sa_handler == SIG_IGN;
|
|
blocked = sigismember(&t->blocked, sig);
|
|
if (blocked || ignored) {
|
|
action->sa.sa_handler = SIG_DFL;
|
|
if (blocked) {
|
|
sigdelset(&t->blocked, sig);
|
|
recalc_sigpending_and_wake(t);
|
|
}
|
|
}
|
|
/*
|
|
* Don't clear SIGNAL_UNKILLABLE for traced tasks, users won't expect
|
|
* debugging to leave init killable.
|
|
*/
|
|
if (action->sa.sa_handler == SIG_DFL && !t->ptrace)
|
|
t->signal->flags &= ~SIGNAL_UNKILLABLE;
|
|
ret = send_signal(sig, info, t, PIDTYPE_PID);
|
|
spin_unlock_irqrestore(&t->sighand->siglock, flags);
|
|
|
|
return ret;
|
|
}
|
|
|
|
int force_sig_info(struct kernel_siginfo *info)
|
|
{
|
|
return force_sig_info_to_task(info, current);
|
|
}
|
|
|
|
/*
|
|
* Nuke all other threads in the group.
|
|
*/
|
|
int zap_other_threads(struct task_struct *p)
|
|
{
|
|
struct task_struct *t = p;
|
|
int count = 0;
|
|
|
|
p->signal->group_stop_count = 0;
|
|
|
|
while_each_thread(p, t) {
|
|
task_clear_jobctl_pending(t, JOBCTL_PENDING_MASK);
|
|
count++;
|
|
|
|
/* Don't bother with already dead threads */
|
|
if (t->exit_state)
|
|
continue;
|
|
sigaddset(&t->pending.signal, SIGKILL);
|
|
signal_wake_up(t, 1);
|
|
}
|
|
|
|
return count;
|
|
}
|
|
|
|
struct sighand_struct *__lock_task_sighand(struct task_struct *tsk,
|
|
unsigned long *flags)
|
|
{
|
|
struct sighand_struct *sighand;
|
|
|
|
rcu_read_lock();
|
|
for (;;) {
|
|
sighand = rcu_dereference(tsk->sighand);
|
|
if (unlikely(sighand == NULL))
|
|
break;
|
|
|
|
/*
|
|
* This sighand can be already freed and even reused, but
|
|
* we rely on SLAB_TYPESAFE_BY_RCU and sighand_ctor() which
|
|
* initializes ->siglock: this slab can't go away, it has
|
|
* the same object type, ->siglock can't be reinitialized.
|
|
*
|
|
* We need to ensure that tsk->sighand is still the same
|
|
* after we take the lock, we can race with de_thread() or
|
|
* __exit_signal(). In the latter case the next iteration
|
|
* must see ->sighand == NULL.
|
|
*/
|
|
spin_lock_irqsave(&sighand->siglock, *flags);
|
|
if (likely(sighand == tsk->sighand))
|
|
break;
|
|
spin_unlock_irqrestore(&sighand->siglock, *flags);
|
|
}
|
|
rcu_read_unlock();
|
|
|
|
return sighand;
|
|
}
|
|
EXPORT_SYMBOL_GPL(__lock_task_sighand);
|
|
|
|
/*
|
|
* send signal info to all the members of a group
|
|
*/
|
|
int group_send_sig_info(int sig, struct kernel_siginfo *info,
|
|
struct task_struct *p, enum pid_type type)
|
|
{
|
|
int ret;
|
|
|
|
rcu_read_lock();
|
|
ret = check_kill_permission(sig, info, p);
|
|
rcu_read_unlock();
|
|
|
|
if (!ret && sig) {
|
|
check_panic_on_foreground_kill(p);
|
|
ret = do_send_sig_info(sig, info, p, type);
|
|
if (capable(CAP_KILL) && sig == SIGKILL)
|
|
if (!strcmp(current->comm, ULMK_MAGIC))
|
|
add_to_oom_reaper(p);
|
|
}
|
|
|
|
return ret;
|
|
}
|
|
|
|
/*
|
|
* __kill_pgrp_info() sends a signal to a process group: this is what the tty
|
|
* control characters do (^C, ^Z etc)
|
|
* - the caller must hold at least a readlock on tasklist_lock
|
|
*/
|
|
int __kill_pgrp_info(int sig, struct kernel_siginfo *info, struct pid *pgrp)
|
|
{
|
|
struct task_struct *p = NULL;
|
|
int retval, success;
|
|
|
|
success = 0;
|
|
retval = -ESRCH;
|
|
do_each_pid_task(pgrp, PIDTYPE_PGID, p) {
|
|
int err = group_send_sig_info(sig, info, p, PIDTYPE_PGID);
|
|
success |= !err;
|
|
retval = err;
|
|
} while_each_pid_task(pgrp, PIDTYPE_PGID, p);
|
|
return success ? 0 : retval;
|
|
}
|
|
|
|
int kill_pid_info(int sig, struct kernel_siginfo *info, struct pid *pid)
|
|
{
|
|
int error = -ESRCH;
|
|
struct task_struct *p;
|
|
|
|
for (;;) {
|
|
rcu_read_lock();
|
|
p = pid_task(pid, PIDTYPE_PID);
|
|
if (p)
|
|
error = group_send_sig_info(sig, info, p, PIDTYPE_TGID);
|
|
rcu_read_unlock();
|
|
if (likely(!p || error != -ESRCH))
|
|
return error;
|
|
|
|
/*
|
|
* The task was unhashed in between, try again. If it
|
|
* is dead, pid_task() will return NULL, if we race with
|
|
* de_thread() it will find the new leader.
|
|
*/
|
|
}
|
|
}
|
|
|
|
static int kill_proc_info(int sig, struct kernel_siginfo *info, pid_t pid)
|
|
{
|
|
int error;
|
|
rcu_read_lock();
|
|
error = kill_pid_info(sig, info, find_vpid(pid));
|
|
rcu_read_unlock();
|
|
return error;
|
|
}
|
|
|
|
static inline bool kill_as_cred_perm(const struct cred *cred,
|
|
struct task_struct *target)
|
|
{
|
|
const struct cred *pcred = __task_cred(target);
|
|
|
|
return uid_eq(cred->euid, pcred->suid) ||
|
|
uid_eq(cred->euid, pcred->uid) ||
|
|
uid_eq(cred->uid, pcred->suid) ||
|
|
uid_eq(cred->uid, pcred->uid);
|
|
}
|
|
|
|
/*
|
|
* The usb asyncio usage of siginfo is wrong. The glibc support
|
|
* for asyncio which uses SI_ASYNCIO assumes the layout is SIL_RT.
|
|
* AKA after the generic fields:
|
|
* kernel_pid_t si_pid;
|
|
* kernel_uid32_t si_uid;
|
|
* sigval_t si_value;
|
|
*
|
|
* Unfortunately when usb generates SI_ASYNCIO it assumes the layout
|
|
* after the generic fields is:
|
|
* void __user *si_addr;
|
|
*
|
|
* This is a practical problem when there is a 64bit big endian kernel
|
|
* and a 32bit userspace. As the 32bit address will encoded in the low
|
|
* 32bits of the pointer. Those low 32bits will be stored at higher
|
|
* address than appear in a 32 bit pointer. So userspace will not
|
|
* see the address it was expecting for it's completions.
|
|
*
|
|
* There is nothing in the encoding that can allow
|
|
* copy_siginfo_to_user32 to detect this confusion of formats, so
|
|
* handle this by requiring the caller of kill_pid_usb_asyncio to
|
|
* notice when this situration takes place and to store the 32bit
|
|
* pointer in sival_int, instead of sival_addr of the sigval_t addr
|
|
* parameter.
|
|
*/
|
|
int kill_pid_usb_asyncio(int sig, int errno, sigval_t addr,
|
|
struct pid *pid, const struct cred *cred)
|
|
{
|
|
struct kernel_siginfo info;
|
|
struct task_struct *p;
|
|
unsigned long flags;
|
|
int ret = -EINVAL;
|
|
|
|
if (!valid_signal(sig))
|
|
return ret;
|
|
|
|
clear_siginfo(&info);
|
|
info.si_signo = sig;
|
|
info.si_errno = errno;
|
|
info.si_code = SI_ASYNCIO;
|
|
*((sigval_t *)&info.si_pid) = addr;
|
|
|
|
rcu_read_lock();
|
|
p = pid_task(pid, PIDTYPE_PID);
|
|
if (!p) {
|
|
ret = -ESRCH;
|
|
goto out_unlock;
|
|
}
|
|
if (!kill_as_cred_perm(cred, p)) {
|
|
ret = -EPERM;
|
|
goto out_unlock;
|
|
}
|
|
ret = security_task_kill(p, &info, sig, cred);
|
|
if (ret)
|
|
goto out_unlock;
|
|
|
|
if (sig) {
|
|
if (lock_task_sighand(p, &flags)) {
|
|
ret = __send_signal(sig, &info, p, PIDTYPE_TGID, false);
|
|
unlock_task_sighand(p, &flags);
|
|
} else
|
|
ret = -ESRCH;
|
|
}
|
|
out_unlock:
|
|
rcu_read_unlock();
|
|
return ret;
|
|
}
|
|
EXPORT_SYMBOL_GPL(kill_pid_usb_asyncio);
|
|
|
|
/*
|
|
* kill_something_info() interprets pid in interesting ways just like kill(2).
|
|
*
|
|
* POSIX specifies that kill(-1,sig) is unspecified, but what we have
|
|
* is probably wrong. Should make it like BSD or SYSV.
|
|
*/
|
|
|
|
static int kill_something_info(int sig, struct kernel_siginfo *info, pid_t pid)
|
|
{
|
|
int ret;
|
|
|
|
if (pid > 0) {
|
|
rcu_read_lock();
|
|
ret = kill_pid_info(sig, info, find_vpid(pid));
|
|
rcu_read_unlock();
|
|
return ret;
|
|
}
|
|
|
|
/* -INT_MIN is undefined. Exclude this case to avoid a UBSAN warning */
|
|
if (pid == INT_MIN)
|
|
return -ESRCH;
|
|
|
|
read_lock(&tasklist_lock);
|
|
if (pid != -1) {
|
|
ret = __kill_pgrp_info(sig, info,
|
|
pid ? find_vpid(-pid) : task_pgrp(current));
|
|
} else {
|
|
int retval = 0, count = 0;
|
|
struct task_struct * p;
|
|
|
|
for_each_process(p) {
|
|
if (task_pid_vnr(p) > 1 &&
|
|
!same_thread_group(p, current)) {
|
|
int err = group_send_sig_info(sig, info, p,
|
|
PIDTYPE_MAX);
|
|
++count;
|
|
if (err != -EPERM)
|
|
retval = err;
|
|
}
|
|
}
|
|
ret = count ? retval : -ESRCH;
|
|
}
|
|
read_unlock(&tasklist_lock);
|
|
|
|
return ret;
|
|
}
|
|
|
|
/*
|
|
* These are for backward compatibility with the rest of the kernel source.
|
|
*/
|
|
|
|
int send_sig_info(int sig, struct kernel_siginfo *info, struct task_struct *p)
|
|
{
|
|
/*
|
|
* Make sure legacy kernel users don't send in bad values
|
|
* (normal paths check this in check_kill_permission).
|
|
*/
|
|
if (!valid_signal(sig))
|
|
return -EINVAL;
|
|
|
|
return do_send_sig_info(sig, info, p, PIDTYPE_PID);
|
|
}
|
|
EXPORT_SYMBOL(send_sig_info);
|
|
|
|
#define __si_special(priv) \
|
|
((priv) ? SEND_SIG_PRIV : SEND_SIG_NOINFO)
|
|
|
|
int
|
|
send_sig(int sig, struct task_struct *p, int priv)
|
|
{
|
|
return send_sig_info(sig, __si_special(priv), p);
|
|
}
|
|
EXPORT_SYMBOL(send_sig);
|
|
|
|
void force_sig(int sig)
|
|
{
|
|
struct kernel_siginfo info;
|
|
|
|
clear_siginfo(&info);
|
|
info.si_signo = sig;
|
|
info.si_errno = 0;
|
|
info.si_code = SI_KERNEL;
|
|
info.si_pid = 0;
|
|
info.si_uid = 0;
|
|
force_sig_info(&info);
|
|
}
|
|
EXPORT_SYMBOL(force_sig);
|
|
|
|
/*
|
|
* When things go south during signal handling, we
|
|
* will force a SIGSEGV. And if the signal that caused
|
|
* the problem was already a SIGSEGV, we'll want to
|
|
* make sure we don't even try to deliver the signal..
|
|
*/
|
|
void force_sigsegv(int sig)
|
|
{
|
|
struct task_struct *p = current;
|
|
|
|
if (sig == SIGSEGV) {
|
|
unsigned long flags;
|
|
spin_lock_irqsave(&p->sighand->siglock, flags);
|
|
p->sighand->action[sig - 1].sa.sa_handler = SIG_DFL;
|
|
spin_unlock_irqrestore(&p->sighand->siglock, flags);
|
|
}
|
|
force_sig(SIGSEGV);
|
|
}
|
|
|
|
int force_sig_fault_to_task(int sig, int code, void __user *addr
|
|
___ARCH_SI_TRAPNO(int trapno)
|
|
___ARCH_SI_IA64(int imm, unsigned int flags, unsigned long isr)
|
|
, struct task_struct *t)
|
|
{
|
|
struct kernel_siginfo info;
|
|
|
|
clear_siginfo(&info);
|
|
info.si_signo = sig;
|
|
info.si_errno = 0;
|
|
info.si_code = code;
|
|
info.si_addr = addr;
|
|
#ifdef __ARCH_SI_TRAPNO
|
|
info.si_trapno = trapno;
|
|
#endif
|
|
#ifdef __ia64__
|
|
info.si_imm = imm;
|
|
info.si_flags = flags;
|
|
info.si_isr = isr;
|
|
#endif
|
|
return force_sig_info_to_task(&info, t);
|
|
}
|
|
|
|
int force_sig_fault(int sig, int code, void __user *addr
|
|
___ARCH_SI_TRAPNO(int trapno)
|
|
___ARCH_SI_IA64(int imm, unsigned int flags, unsigned long isr))
|
|
{
|
|
return force_sig_fault_to_task(sig, code, addr
|
|
___ARCH_SI_TRAPNO(trapno)
|
|
___ARCH_SI_IA64(imm, flags, isr), current);
|
|
}
|
|
|
|
int send_sig_fault(int sig, int code, void __user *addr
|
|
___ARCH_SI_TRAPNO(int trapno)
|
|
___ARCH_SI_IA64(int imm, unsigned int flags, unsigned long isr)
|
|
, struct task_struct *t)
|
|
{
|
|
struct kernel_siginfo info;
|
|
|
|
clear_siginfo(&info);
|
|
info.si_signo = sig;
|
|
info.si_errno = 0;
|
|
info.si_code = code;
|
|
info.si_addr = addr;
|
|
#ifdef __ARCH_SI_TRAPNO
|
|
info.si_trapno = trapno;
|
|
#endif
|
|
#ifdef __ia64__
|
|
info.si_imm = imm;
|
|
info.si_flags = flags;
|
|
info.si_isr = isr;
|
|
#endif
|
|
return send_sig_info(info.si_signo, &info, t);
|
|
}
|
|
|
|
int force_sig_mceerr(int code, void __user *addr, short lsb)
|
|
{
|
|
struct kernel_siginfo info;
|
|
|
|
WARN_ON((code != BUS_MCEERR_AO) && (code != BUS_MCEERR_AR));
|
|
clear_siginfo(&info);
|
|
info.si_signo = SIGBUS;
|
|
info.si_errno = 0;
|
|
info.si_code = code;
|
|
info.si_addr = addr;
|
|
info.si_addr_lsb = lsb;
|
|
return force_sig_info(&info);
|
|
}
|
|
|
|
int send_sig_mceerr(int code, void __user *addr, short lsb, struct task_struct *t)
|
|
{
|
|
struct kernel_siginfo info;
|
|
|
|
WARN_ON((code != BUS_MCEERR_AO) && (code != BUS_MCEERR_AR));
|
|
clear_siginfo(&info);
|
|
info.si_signo = SIGBUS;
|
|
info.si_errno = 0;
|
|
info.si_code = code;
|
|
info.si_addr = addr;
|
|
info.si_addr_lsb = lsb;
|
|
return send_sig_info(info.si_signo, &info, t);
|
|
}
|
|
EXPORT_SYMBOL(send_sig_mceerr);
|
|
|
|
int force_sig_bnderr(void __user *addr, void __user *lower, void __user *upper)
|
|
{
|
|
struct kernel_siginfo info;
|
|
|
|
clear_siginfo(&info);
|
|
info.si_signo = SIGSEGV;
|
|
info.si_errno = 0;
|
|
info.si_code = SEGV_BNDERR;
|
|
info.si_addr = addr;
|
|
info.si_lower = lower;
|
|
info.si_upper = upper;
|
|
return force_sig_info(&info);
|
|
}
|
|
|
|
#ifdef SEGV_PKUERR
|
|
int force_sig_pkuerr(void __user *addr, u32 pkey)
|
|
{
|
|
struct kernel_siginfo info;
|
|
|
|
clear_siginfo(&info);
|
|
info.si_signo = SIGSEGV;
|
|
info.si_errno = 0;
|
|
info.si_code = SEGV_PKUERR;
|
|
info.si_addr = addr;
|
|
info.si_pkey = pkey;
|
|
return force_sig_info(&info);
|
|
}
|
|
#endif
|
|
|
|
/* For the crazy architectures that include trap information in
|
|
* the errno field, instead of an actual errno value.
|
|
*/
|
|
int force_sig_ptrace_errno_trap(int errno, void __user *addr)
|
|
{
|
|
struct kernel_siginfo info;
|
|
|
|
clear_siginfo(&info);
|
|
info.si_signo = SIGTRAP;
|
|
info.si_errno = errno;
|
|
info.si_code = TRAP_HWBKPT;
|
|
info.si_addr = addr;
|
|
return force_sig_info(&info);
|
|
}
|
|
|
|
int kill_pgrp(struct pid *pid, int sig, int priv)
|
|
{
|
|
int ret;
|
|
|
|
read_lock(&tasklist_lock);
|
|
ret = __kill_pgrp_info(sig, __si_special(priv), pid);
|
|
read_unlock(&tasklist_lock);
|
|
|
|
return ret;
|
|
}
|
|
EXPORT_SYMBOL(kill_pgrp);
|
|
|
|
int kill_pid(struct pid *pid, int sig, int priv)
|
|
{
|
|
return kill_pid_info(sig, __si_special(priv), pid);
|
|
}
|
|
EXPORT_SYMBOL(kill_pid);
|
|
|
|
/*
|
|
* These functions support sending signals using preallocated sigqueue
|
|
* structures. This is needed "because realtime applications cannot
|
|
* afford to lose notifications of asynchronous events, like timer
|
|
* expirations or I/O completions". In the case of POSIX Timers
|
|
* we allocate the sigqueue structure from the timer_create. If this
|
|
* allocation fails we are able to report the failure to the application
|
|
* with an EAGAIN error.
|
|
*/
|
|
struct sigqueue *sigqueue_alloc(void)
|
|
{
|
|
struct sigqueue *q = __sigqueue_alloc(-1, current, GFP_KERNEL, 0);
|
|
|
|
if (q)
|
|
q->flags |= SIGQUEUE_PREALLOC;
|
|
|
|
return q;
|
|
}
|
|
|
|
void sigqueue_free(struct sigqueue *q)
|
|
{
|
|
unsigned long flags;
|
|
spinlock_t *lock = ¤t->sighand->siglock;
|
|
|
|
BUG_ON(!(q->flags & SIGQUEUE_PREALLOC));
|
|
/*
|
|
* We must hold ->siglock while testing q->list
|
|
* to serialize with collect_signal() or with
|
|
* __exit_signal()->flush_sigqueue().
|
|
*/
|
|
spin_lock_irqsave(lock, flags);
|
|
q->flags &= ~SIGQUEUE_PREALLOC;
|
|
/*
|
|
* If it is queued it will be freed when dequeued,
|
|
* like the "regular" sigqueue.
|
|
*/
|
|
if (!list_empty(&q->list))
|
|
q = NULL;
|
|
spin_unlock_irqrestore(lock, flags);
|
|
|
|
if (q)
|
|
__sigqueue_free(q);
|
|
}
|
|
|
|
int send_sigqueue(struct sigqueue *q, struct pid *pid, enum pid_type type)
|
|
{
|
|
int sig = q->info.si_signo;
|
|
struct sigpending *pending;
|
|
struct task_struct *t;
|
|
unsigned long flags;
|
|
int ret, result;
|
|
|
|
BUG_ON(!(q->flags & SIGQUEUE_PREALLOC));
|
|
|
|
ret = -1;
|
|
rcu_read_lock();
|
|
t = pid_task(pid, type);
|
|
if (!t || !likely(lock_task_sighand(t, &flags)))
|
|
goto ret;
|
|
|
|
ret = 1; /* the signal is ignored */
|
|
result = TRACE_SIGNAL_IGNORED;
|
|
if (!prepare_signal(sig, t, false))
|
|
goto out;
|
|
|
|
ret = 0;
|
|
if (unlikely(!list_empty(&q->list))) {
|
|
/*
|
|
* If an SI_TIMER entry is already queue just increment
|
|
* the overrun count.
|
|
*/
|
|
BUG_ON(q->info.si_code != SI_TIMER);
|
|
q->info.si_overrun++;
|
|
result = TRACE_SIGNAL_ALREADY_PENDING;
|
|
goto out;
|
|
}
|
|
q->info.si_overrun = 0;
|
|
|
|
signalfd_notify(t, sig);
|
|
pending = (type != PIDTYPE_PID) ? &t->signal->shared_pending : &t->pending;
|
|
list_add_tail(&q->list, &pending->list);
|
|
sigaddset(&pending->signal, sig);
|
|
complete_signal(sig, t, type);
|
|
result = TRACE_SIGNAL_DELIVERED;
|
|
out:
|
|
trace_signal_generate(sig, &q->info, t, type != PIDTYPE_PID, result);
|
|
unlock_task_sighand(t, &flags);
|
|
ret:
|
|
rcu_read_unlock();
|
|
return ret;
|
|
}
|
|
|
|
static void do_notify_pidfd(struct task_struct *task)
|
|
{
|
|
struct pid *pid;
|
|
|
|
WARN_ON(task->exit_state == 0);
|
|
pid = task_pid(task);
|
|
wake_up_all(&pid->wait_pidfd);
|
|
}
|
|
|
|
/*
|
|
* Let a parent know about the death of a child.
|
|
* For a stopped/continued status change, use do_notify_parent_cldstop instead.
|
|
*
|
|
* Returns true if our parent ignored us and so we've switched to
|
|
* self-reaping.
|
|
*/
|
|
bool do_notify_parent(struct task_struct *tsk, int sig)
|
|
{
|
|
struct kernel_siginfo info;
|
|
unsigned long flags;
|
|
struct sighand_struct *psig;
|
|
bool autoreap = false;
|
|
u64 utime, stime;
|
|
|
|
BUG_ON(sig == -1);
|
|
|
|
/* do_notify_parent_cldstop should have been called instead. */
|
|
BUG_ON(task_is_stopped_or_traced(tsk));
|
|
|
|
BUG_ON(!tsk->ptrace &&
|
|
(tsk->group_leader != tsk || !thread_group_empty(tsk)));
|
|
|
|
/* Wake up all pidfd waiters */
|
|
do_notify_pidfd(tsk);
|
|
|
|
if (sig != SIGCHLD) {
|
|
/*
|
|
* This is only possible if parent == real_parent.
|
|
* Check if it has changed security domain.
|
|
*/
|
|
if (tsk->parent_exec_id != READ_ONCE(tsk->parent->self_exec_id))
|
|
sig = SIGCHLD;
|
|
}
|
|
|
|
clear_siginfo(&info);
|
|
info.si_signo = sig;
|
|
info.si_errno = 0;
|
|
/*
|
|
* We are under tasklist_lock here so our parent is tied to
|
|
* us and cannot change.
|
|
*
|
|
* task_active_pid_ns will always return the same pid namespace
|
|
* until a task passes through release_task.
|
|
*
|
|
* write_lock() currently calls preempt_disable() which is the
|
|
* same as rcu_read_lock(), but according to Oleg, this is not
|
|
* correct to rely on this
|
|
*/
|
|
rcu_read_lock();
|
|
info.si_pid = task_pid_nr_ns(tsk, task_active_pid_ns(tsk->parent));
|
|
info.si_uid = from_kuid_munged(task_cred_xxx(tsk->parent, user_ns),
|
|
task_uid(tsk));
|
|
rcu_read_unlock();
|
|
|
|
task_cputime(tsk, &utime, &stime);
|
|
info.si_utime = nsec_to_clock_t(utime + tsk->signal->utime);
|
|
info.si_stime = nsec_to_clock_t(stime + tsk->signal->stime);
|
|
|
|
info.si_status = tsk->exit_code & 0x7f;
|
|
if (tsk->exit_code & 0x80)
|
|
info.si_code = CLD_DUMPED;
|
|
else if (tsk->exit_code & 0x7f)
|
|
info.si_code = CLD_KILLED;
|
|
else {
|
|
info.si_code = CLD_EXITED;
|
|
info.si_status = tsk->exit_code >> 8;
|
|
}
|
|
|
|
psig = tsk->parent->sighand;
|
|
spin_lock_irqsave(&psig->siglock, flags);
|
|
if (!tsk->ptrace && sig == SIGCHLD &&
|
|
(psig->action[SIGCHLD-1].sa.sa_handler == SIG_IGN ||
|
|
(psig->action[SIGCHLD-1].sa.sa_flags & SA_NOCLDWAIT))) {
|
|
/*
|
|
* We are exiting and our parent doesn't care. POSIX.1
|
|
* defines special semantics for setting SIGCHLD to SIG_IGN
|
|
* or setting the SA_NOCLDWAIT flag: we should be reaped
|
|
* automatically and not left for our parent's wait4 call.
|
|
* Rather than having the parent do it as a magic kind of
|
|
* signal handler, we just set this to tell do_exit that we
|
|
* can be cleaned up without becoming a zombie. Note that
|
|
* we still call __wake_up_parent in this case, because a
|
|
* blocked sys_wait4 might now return -ECHILD.
|
|
*
|
|
* Whether we send SIGCHLD or not for SA_NOCLDWAIT
|
|
* is implementation-defined: we do (if you don't want
|
|
* it, just use SIG_IGN instead).
|
|
*/
|
|
autoreap = true;
|
|
if (psig->action[SIGCHLD-1].sa.sa_handler == SIG_IGN)
|
|
sig = 0;
|
|
}
|
|
/*
|
|
* Send with __send_signal as si_pid and si_uid are in the
|
|
* parent's namespaces.
|
|
*/
|
|
if (valid_signal(sig) && sig)
|
|
__send_signal(sig, &info, tsk->parent, PIDTYPE_TGID, false);
|
|
__wake_up_parent(tsk, tsk->parent);
|
|
spin_unlock_irqrestore(&psig->siglock, flags);
|
|
|
|
return autoreap;
|
|
}
|
|
|
|
/**
|
|
* do_notify_parent_cldstop - notify parent of stopped/continued state change
|
|
* @tsk: task reporting the state change
|
|
* @for_ptracer: the notification is for ptracer
|
|
* @why: CLD_{CONTINUED|STOPPED|TRAPPED} to report
|
|
*
|
|
* Notify @tsk's parent that the stopped/continued state has changed. If
|
|
* @for_ptracer is %false, @tsk's group leader notifies to its real parent.
|
|
* If %true, @tsk reports to @tsk->parent which should be the ptracer.
|
|
*
|
|
* CONTEXT:
|
|
* Must be called with tasklist_lock at least read locked.
|
|
*/
|
|
static void do_notify_parent_cldstop(struct task_struct *tsk,
|
|
bool for_ptracer, int why)
|
|
{
|
|
struct kernel_siginfo info;
|
|
unsigned long flags;
|
|
struct task_struct *parent;
|
|
struct sighand_struct *sighand;
|
|
u64 utime, stime;
|
|
|
|
if (for_ptracer) {
|
|
parent = tsk->parent;
|
|
} else {
|
|
tsk = tsk->group_leader;
|
|
parent = tsk->real_parent;
|
|
}
|
|
|
|
clear_siginfo(&info);
|
|
info.si_signo = SIGCHLD;
|
|
info.si_errno = 0;
|
|
/*
|
|
* see comment in do_notify_parent() about the following 4 lines
|
|
*/
|
|
rcu_read_lock();
|
|
info.si_pid = task_pid_nr_ns(tsk, task_active_pid_ns(parent));
|
|
info.si_uid = from_kuid_munged(task_cred_xxx(parent, user_ns), task_uid(tsk));
|
|
rcu_read_unlock();
|
|
|
|
task_cputime(tsk, &utime, &stime);
|
|
info.si_utime = nsec_to_clock_t(utime);
|
|
info.si_stime = nsec_to_clock_t(stime);
|
|
|
|
info.si_code = why;
|
|
switch (why) {
|
|
case CLD_CONTINUED:
|
|
info.si_status = SIGCONT;
|
|
break;
|
|
case CLD_STOPPED:
|
|
info.si_status = tsk->signal->group_exit_code & 0x7f;
|
|
break;
|
|
case CLD_TRAPPED:
|
|
info.si_status = tsk->exit_code & 0x7f;
|
|
break;
|
|
default:
|
|
BUG();
|
|
}
|
|
|
|
sighand = parent->sighand;
|
|
spin_lock_irqsave(&sighand->siglock, flags);
|
|
if (sighand->action[SIGCHLD-1].sa.sa_handler != SIG_IGN &&
|
|
!(sighand->action[SIGCHLD-1].sa.sa_flags & SA_NOCLDSTOP))
|
|
__group_send_sig_info(SIGCHLD, &info, parent);
|
|
/*
|
|
* Even if SIGCHLD is not generated, we must wake up wait4 calls.
|
|
*/
|
|
__wake_up_parent(tsk, parent);
|
|
spin_unlock_irqrestore(&sighand->siglock, flags);
|
|
}
|
|
|
|
static inline bool may_ptrace_stop(void)
|
|
{
|
|
if (!likely(current->ptrace))
|
|
return false;
|
|
/*
|
|
* Are we in the middle of do_coredump?
|
|
* If so and our tracer is also part of the coredump stopping
|
|
* is a deadlock situation, and pointless because our tracer
|
|
* is dead so don't allow us to stop.
|
|
* If SIGKILL was already sent before the caller unlocked
|
|
* ->siglock we must see ->core_state != NULL. Otherwise it
|
|
* is safe to enter schedule().
|
|
*
|
|
* This is almost outdated, a task with the pending SIGKILL can't
|
|
* block in TASK_TRACED. But PTRACE_EVENT_EXIT can be reported
|
|
* after SIGKILL was already dequeued.
|
|
*/
|
|
if (unlikely(current->mm->core_state) &&
|
|
unlikely(current->mm == current->parent->mm))
|
|
return false;
|
|
|
|
return true;
|
|
}
|
|
|
|
/*
|
|
* Return non-zero if there is a SIGKILL that should be waking us up.
|
|
* Called with the siglock held.
|
|
*/
|
|
static bool sigkill_pending(struct task_struct *tsk)
|
|
{
|
|
return sigismember(&tsk->pending.signal, SIGKILL) ||
|
|
sigismember(&tsk->signal->shared_pending.signal, SIGKILL);
|
|
}
|
|
|
|
/*
|
|
* This must be called with current->sighand->siglock held.
|
|
*
|
|
* This should be the path for all ptrace stops.
|
|
* We always set current->last_siginfo while stopped here.
|
|
* That makes it a way to test a stopped process for
|
|
* being ptrace-stopped vs being job-control-stopped.
|
|
*
|
|
* If we actually decide not to stop at all because the tracer
|
|
* is gone, we keep current->exit_code unless clear_code.
|
|
*/
|
|
static void ptrace_stop(int exit_code, int why, int clear_code, kernel_siginfo_t *info)
|
|
__releases(¤t->sighand->siglock)
|
|
__acquires(¤t->sighand->siglock)
|
|
{
|
|
bool gstop_done = false;
|
|
|
|
if (arch_ptrace_stop_needed(exit_code, info)) {
|
|
/*
|
|
* The arch code has something special to do before a
|
|
* ptrace stop. This is allowed to block, e.g. for faults
|
|
* on user stack pages. We can't keep the siglock while
|
|
* calling arch_ptrace_stop, so we must release it now.
|
|
* To preserve proper semantics, we must do this before
|
|
* any signal bookkeeping like checking group_stop_count.
|
|
* Meanwhile, a SIGKILL could come in before we retake the
|
|
* siglock. That must prevent us from sleeping in TASK_TRACED.
|
|
* So after regaining the lock, we must check for SIGKILL.
|
|
*/
|
|
spin_unlock_irq(¤t->sighand->siglock);
|
|
arch_ptrace_stop(exit_code, info);
|
|
spin_lock_irq(¤t->sighand->siglock);
|
|
if (sigkill_pending(current))
|
|
return;
|
|
}
|
|
|
|
set_special_state(TASK_TRACED);
|
|
|
|
/*
|
|
* We're committing to trapping. TRACED should be visible before
|
|
* TRAPPING is cleared; otherwise, the tracer might fail do_wait().
|
|
* Also, transition to TRACED and updates to ->jobctl should be
|
|
* atomic with respect to siglock and should be done after the arch
|
|
* hook as siglock is released and regrabbed across it.
|
|
*
|
|
* TRACER TRACEE
|
|
*
|
|
* ptrace_attach()
|
|
* [L] wait_on_bit(JOBCTL_TRAPPING) [S] set_special_state(TRACED)
|
|
* do_wait()
|
|
* set_current_state() smp_wmb();
|
|
* ptrace_do_wait()
|
|
* wait_task_stopped()
|
|
* task_stopped_code()
|
|
* [L] task_is_traced() [S] task_clear_jobctl_trapping();
|
|
*/
|
|
smp_wmb();
|
|
|
|
current->last_siginfo = info;
|
|
current->exit_code = exit_code;
|
|
|
|
/*
|
|
* If @why is CLD_STOPPED, we're trapping to participate in a group
|
|
* stop. Do the bookkeeping. Note that if SIGCONT was delievered
|
|
* across siglock relocks since INTERRUPT was scheduled, PENDING
|
|
* could be clear now. We act as if SIGCONT is received after
|
|
* TASK_TRACED is entered - ignore it.
|
|
*/
|
|
if (why == CLD_STOPPED && (current->jobctl & JOBCTL_STOP_PENDING))
|
|
gstop_done = task_participate_group_stop(current);
|
|
|
|
/* any trap clears pending STOP trap, STOP trap clears NOTIFY */
|
|
task_clear_jobctl_pending(current, JOBCTL_TRAP_STOP);
|
|
if (info && info->si_code >> 8 == PTRACE_EVENT_STOP)
|
|
task_clear_jobctl_pending(current, JOBCTL_TRAP_NOTIFY);
|
|
|
|
/* entering a trap, clear TRAPPING */
|
|
task_clear_jobctl_trapping(current);
|
|
|
|
spin_unlock_irq(¤t->sighand->siglock);
|
|
read_lock(&tasklist_lock);
|
|
if (may_ptrace_stop()) {
|
|
/*
|
|
* Notify parents of the stop.
|
|
*
|
|
* While ptraced, there are two parents - the ptracer and
|
|
* the real_parent of the group_leader. The ptracer should
|
|
* know about every stop while the real parent is only
|
|
* interested in the completion of group stop. The states
|
|
* for the two don't interact with each other. Notify
|
|
* separately unless they're gonna be duplicates.
|
|
*/
|
|
do_notify_parent_cldstop(current, true, why);
|
|
if (gstop_done && ptrace_reparented(current))
|
|
do_notify_parent_cldstop(current, false, why);
|
|
|
|
/*
|
|
* Don't want to allow preemption here, because
|
|
* sys_ptrace() needs this task to be inactive.
|
|
*
|
|
* XXX: implement read_unlock_no_resched().
|
|
*/
|
|
preempt_disable();
|
|
read_unlock(&tasklist_lock);
|
|
cgroup_enter_frozen();
|
|
preempt_enable_no_resched();
|
|
freezable_schedule();
|
|
cgroup_leave_frozen(true);
|
|
} else {
|
|
/*
|
|
* By the time we got the lock, our tracer went away.
|
|
* Don't drop the lock yet, another tracer may come.
|
|
*
|
|
* If @gstop_done, the ptracer went away between group stop
|
|
* completion and here. During detach, it would have set
|
|
* JOBCTL_STOP_PENDING on us and we'll re-enter
|
|
* TASK_STOPPED in do_signal_stop() on return, so notifying
|
|
* the real parent of the group stop completion is enough.
|
|
*/
|
|
if (gstop_done)
|
|
do_notify_parent_cldstop(current, false, why);
|
|
|
|
/* tasklist protects us from ptrace_freeze_traced() */
|
|
__set_current_state(TASK_RUNNING);
|
|
if (clear_code)
|
|
current->exit_code = 0;
|
|
read_unlock(&tasklist_lock);
|
|
}
|
|
|
|
/*
|
|
* We are back. Now reacquire the siglock before touching
|
|
* last_siginfo, so that we are sure to have synchronized with
|
|
* any signal-sending on another CPU that wants to examine it.
|
|
*/
|
|
spin_lock_irq(¤t->sighand->siglock);
|
|
current->last_siginfo = NULL;
|
|
|
|
/* LISTENING can be set only during STOP traps, clear it */
|
|
current->jobctl &= ~JOBCTL_LISTENING;
|
|
|
|
/*
|
|
* Queued signals ignored us while we were stopped for tracing.
|
|
* So check for any that we should take before resuming user mode.
|
|
* This sets TIF_SIGPENDING, but never clears it.
|
|
*/
|
|
recalc_sigpending_tsk(current);
|
|
}
|
|
|
|
static void ptrace_do_notify(int signr, int exit_code, int why)
|
|
{
|
|
kernel_siginfo_t info;
|
|
|
|
clear_siginfo(&info);
|
|
info.si_signo = signr;
|
|
info.si_code = exit_code;
|
|
info.si_pid = task_pid_vnr(current);
|
|
info.si_uid = from_kuid_munged(current_user_ns(), current_uid());
|
|
|
|
/* Let the debugger run. */
|
|
ptrace_stop(exit_code, why, 1, &info);
|
|
}
|
|
|
|
void ptrace_notify(int exit_code)
|
|
{
|
|
BUG_ON((exit_code & (0x7f | ~0xffff)) != SIGTRAP);
|
|
if (unlikely(current->task_works))
|
|
task_work_run();
|
|
|
|
spin_lock_irq(¤t->sighand->siglock);
|
|
ptrace_do_notify(SIGTRAP, exit_code, CLD_TRAPPED);
|
|
spin_unlock_irq(¤t->sighand->siglock);
|
|
}
|
|
|
|
/**
|
|
* do_signal_stop - handle group stop for SIGSTOP and other stop signals
|
|
* @signr: signr causing group stop if initiating
|
|
*
|
|
* If %JOBCTL_STOP_PENDING is not set yet, initiate group stop with @signr
|
|
* and participate in it. If already set, participate in the existing
|
|
* group stop. If participated in a group stop (and thus slept), %true is
|
|
* returned with siglock released.
|
|
*
|
|
* If ptraced, this function doesn't handle stop itself. Instead,
|
|
* %JOBCTL_TRAP_STOP is scheduled and %false is returned with siglock
|
|
* untouched. The caller must ensure that INTERRUPT trap handling takes
|
|
* places afterwards.
|
|
*
|
|
* CONTEXT:
|
|
* Must be called with @current->sighand->siglock held, which is released
|
|
* on %true return.
|
|
*
|
|
* RETURNS:
|
|
* %false if group stop is already cancelled or ptrace trap is scheduled.
|
|
* %true if participated in group stop.
|
|
*/
|
|
static bool do_signal_stop(int signr)
|
|
__releases(¤t->sighand->siglock)
|
|
{
|
|
struct signal_struct *sig = current->signal;
|
|
|
|
if (!(current->jobctl & JOBCTL_STOP_PENDING)) {
|
|
unsigned long gstop = JOBCTL_STOP_PENDING | JOBCTL_STOP_CONSUME;
|
|
struct task_struct *t;
|
|
|
|
/* signr will be recorded in task->jobctl for retries */
|
|
WARN_ON_ONCE(signr & ~JOBCTL_STOP_SIGMASK);
|
|
|
|
if (!likely(current->jobctl & JOBCTL_STOP_DEQUEUED) ||
|
|
unlikely(signal_group_exit(sig)))
|
|
return false;
|
|
/*
|
|
* There is no group stop already in progress. We must
|
|
* initiate one now.
|
|
*
|
|
* While ptraced, a task may be resumed while group stop is
|
|
* still in effect and then receive a stop signal and
|
|
* initiate another group stop. This deviates from the
|
|
* usual behavior as two consecutive stop signals can't
|
|
* cause two group stops when !ptraced. That is why we
|
|
* also check !task_is_stopped(t) below.
|
|
*
|
|
* The condition can be distinguished by testing whether
|
|
* SIGNAL_STOP_STOPPED is already set. Don't generate
|
|
* group_exit_code in such case.
|
|
*
|
|
* This is not necessary for SIGNAL_STOP_CONTINUED because
|
|
* an intervening stop signal is required to cause two
|
|
* continued events regardless of ptrace.
|
|
*/
|
|
if (!(sig->flags & SIGNAL_STOP_STOPPED))
|
|
sig->group_exit_code = signr;
|
|
|
|
sig->group_stop_count = 0;
|
|
|
|
if (task_set_jobctl_pending(current, signr | gstop))
|
|
sig->group_stop_count++;
|
|
|
|
t = current;
|
|
while_each_thread(current, t) {
|
|
/*
|
|
* Setting state to TASK_STOPPED for a group
|
|
* stop is always done with the siglock held,
|
|
* so this check has no races.
|
|
*/
|
|
if (!task_is_stopped(t) &&
|
|
task_set_jobctl_pending(t, signr | gstop)) {
|
|
sig->group_stop_count++;
|
|
if (likely(!(t->ptrace & PT_SEIZED)))
|
|
signal_wake_up(t, 0);
|
|
else
|
|
ptrace_trap_notify(t);
|
|
}
|
|
}
|
|
}
|
|
|
|
if (likely(!current->ptrace)) {
|
|
int notify = 0;
|
|
|
|
/*
|
|
* If there are no other threads in the group, or if there
|
|
* is a group stop in progress and we are the last to stop,
|
|
* report to the parent.
|
|
*/
|
|
if (task_participate_group_stop(current))
|
|
notify = CLD_STOPPED;
|
|
|
|
set_special_state(TASK_STOPPED);
|
|
spin_unlock_irq(¤t->sighand->siglock);
|
|
|
|
/*
|
|
* Notify the parent of the group stop completion. Because
|
|
* we're not holding either the siglock or tasklist_lock
|
|
* here, ptracer may attach inbetween; however, this is for
|
|
* group stop and should always be delivered to the real
|
|
* parent of the group leader. The new ptracer will get
|
|
* its notification when this task transitions into
|
|
* TASK_TRACED.
|
|
*/
|
|
if (notify) {
|
|
read_lock(&tasklist_lock);
|
|
do_notify_parent_cldstop(current, false, notify);
|
|
read_unlock(&tasklist_lock);
|
|
}
|
|
|
|
/* Now we don't run again until woken by SIGCONT or SIGKILL */
|
|
cgroup_enter_frozen();
|
|
freezable_schedule();
|
|
return true;
|
|
} else {
|
|
/*
|
|
* While ptraced, group stop is handled by STOP trap.
|
|
* Schedule it and let the caller deal with it.
|
|
*/
|
|
task_set_jobctl_pending(current, JOBCTL_TRAP_STOP);
|
|
return false;
|
|
}
|
|
}
|
|
|
|
/**
|
|
* do_jobctl_trap - take care of ptrace jobctl traps
|
|
*
|
|
* When PT_SEIZED, it's used for both group stop and explicit
|
|
* SEIZE/INTERRUPT traps. Both generate PTRACE_EVENT_STOP trap with
|
|
* accompanying siginfo. If stopped, lower eight bits of exit_code contain
|
|
* the stop signal; otherwise, %SIGTRAP.
|
|
*
|
|
* When !PT_SEIZED, it's used only for group stop trap with stop signal
|
|
* number as exit_code and no siginfo.
|
|
*
|
|
* CONTEXT:
|
|
* Must be called with @current->sighand->siglock held, which may be
|
|
* released and re-acquired before returning with intervening sleep.
|
|
*/
|
|
static void do_jobctl_trap(void)
|
|
{
|
|
struct signal_struct *signal = current->signal;
|
|
int signr = current->jobctl & JOBCTL_STOP_SIGMASK;
|
|
|
|
if (current->ptrace & PT_SEIZED) {
|
|
if (!signal->group_stop_count &&
|
|
!(signal->flags & SIGNAL_STOP_STOPPED))
|
|
signr = SIGTRAP;
|
|
WARN_ON_ONCE(!signr);
|
|
ptrace_do_notify(signr, signr | (PTRACE_EVENT_STOP << 8),
|
|
CLD_STOPPED);
|
|
} else {
|
|
WARN_ON_ONCE(!signr);
|
|
ptrace_stop(signr, CLD_STOPPED, 0, NULL);
|
|
current->exit_code = 0;
|
|
}
|
|
}
|
|
|
|
/**
|
|
* do_freezer_trap - handle the freezer jobctl trap
|
|
*
|
|
* Puts the task into frozen state, if only the task is not about to quit.
|
|
* In this case it drops JOBCTL_TRAP_FREEZE.
|
|
*
|
|
* CONTEXT:
|
|
* Must be called with @current->sighand->siglock held,
|
|
* which is always released before returning.
|
|
*/
|
|
static void do_freezer_trap(void)
|
|
__releases(¤t->sighand->siglock)
|
|
{
|
|
/*
|
|
* If there are other trap bits pending except JOBCTL_TRAP_FREEZE,
|
|
* let's make another loop to give it a chance to be handled.
|
|
* In any case, we'll return back.
|
|
*/
|
|
if ((current->jobctl & (JOBCTL_PENDING_MASK | JOBCTL_TRAP_FREEZE)) !=
|
|
JOBCTL_TRAP_FREEZE) {
|
|
spin_unlock_irq(¤t->sighand->siglock);
|
|
return;
|
|
}
|
|
|
|
/*
|
|
* Now we're sure that there is no pending fatal signal and no
|
|
* pending traps. Clear TIF_SIGPENDING to not get out of schedule()
|
|
* immediately (if there is a non-fatal signal pending), and
|
|
* put the task into sleep.
|
|
*/
|
|
__set_current_state(TASK_INTERRUPTIBLE);
|
|
clear_thread_flag(TIF_SIGPENDING);
|
|
spin_unlock_irq(¤t->sighand->siglock);
|
|
cgroup_enter_frozen();
|
|
freezable_schedule();
|
|
}
|
|
|
|
static int ptrace_signal(int signr, kernel_siginfo_t *info)
|
|
{
|
|
/*
|
|
* We do not check sig_kernel_stop(signr) but set this marker
|
|
* unconditionally because we do not know whether debugger will
|
|
* change signr. This flag has no meaning unless we are going
|
|
* to stop after return from ptrace_stop(). In this case it will
|
|
* be checked in do_signal_stop(), we should only stop if it was
|
|
* not cleared by SIGCONT while we were sleeping. See also the
|
|
* comment in dequeue_signal().
|
|
*/
|
|
current->jobctl |= JOBCTL_STOP_DEQUEUED;
|
|
ptrace_stop(signr, CLD_TRAPPED, 0, info);
|
|
|
|
/* We're back. Did the debugger cancel the sig? */
|
|
signr = current->exit_code;
|
|
if (signr == 0)
|
|
return signr;
|
|
|
|
current->exit_code = 0;
|
|
|
|
/*
|
|
* Update the siginfo structure if the signal has
|
|
* changed. If the debugger wanted something
|
|
* specific in the siginfo structure then it should
|
|
* have updated *info via PTRACE_SETSIGINFO.
|
|
*/
|
|
if (signr != info->si_signo) {
|
|
clear_siginfo(info);
|
|
info->si_signo = signr;
|
|
info->si_errno = 0;
|
|
info->si_code = SI_USER;
|
|
rcu_read_lock();
|
|
info->si_pid = task_pid_vnr(current->parent);
|
|
info->si_uid = from_kuid_munged(current_user_ns(),
|
|
task_uid(current->parent));
|
|
rcu_read_unlock();
|
|
}
|
|
|
|
/* If the (new) signal is now blocked, requeue it. */
|
|
if (sigismember(¤t->blocked, signr)) {
|
|
send_signal(signr, info, current, PIDTYPE_PID);
|
|
signr = 0;
|
|
}
|
|
|
|
return signr;
|
|
}
|
|
|
|
bool get_signal(struct ksignal *ksig)
|
|
{
|
|
struct sighand_struct *sighand = current->sighand;
|
|
struct signal_struct *signal = current->signal;
|
|
int signr;
|
|
|
|
if (unlikely(current->task_works))
|
|
task_work_run();
|
|
|
|
if (unlikely(uprobe_deny_signal()))
|
|
return false;
|
|
|
|
/*
|
|
* Do this once, we can't return to user-mode if freezing() == T.
|
|
* do_signal_stop() and ptrace_stop() do freezable_schedule() and
|
|
* thus do not need another check after return.
|
|
*/
|
|
try_to_freeze();
|
|
|
|
relock:
|
|
spin_lock_irq(&sighand->siglock);
|
|
/*
|
|
* Every stopped thread goes here after wakeup. Check to see if
|
|
* we should notify the parent, prepare_signal(SIGCONT) encodes
|
|
* the CLD_ si_code into SIGNAL_CLD_MASK bits.
|
|
*/
|
|
if (unlikely(signal->flags & SIGNAL_CLD_MASK)) {
|
|
int why;
|
|
|
|
if (signal->flags & SIGNAL_CLD_CONTINUED)
|
|
why = CLD_CONTINUED;
|
|
else
|
|
why = CLD_STOPPED;
|
|
|
|
signal->flags &= ~SIGNAL_CLD_MASK;
|
|
|
|
spin_unlock_irq(&sighand->siglock);
|
|
|
|
/*
|
|
* Notify the parent that we're continuing. This event is
|
|
* always per-process and doesn't make whole lot of sense
|
|
* for ptracers, who shouldn't consume the state via
|
|
* wait(2) either, but, for backward compatibility, notify
|
|
* the ptracer of the group leader too unless it's gonna be
|
|
* a duplicate.
|
|
*/
|
|
read_lock(&tasklist_lock);
|
|
do_notify_parent_cldstop(current, false, why);
|
|
|
|
if (ptrace_reparented(current->group_leader))
|
|
do_notify_parent_cldstop(current->group_leader,
|
|
true, why);
|
|
read_unlock(&tasklist_lock);
|
|
|
|
goto relock;
|
|
}
|
|
|
|
/* Has this task already been marked for death? */
|
|
if (signal_group_exit(signal)) {
|
|
ksig->info.si_signo = signr = SIGKILL;
|
|
sigdelset(¤t->pending.signal, SIGKILL);
|
|
trace_signal_deliver(SIGKILL, SEND_SIG_NOINFO,
|
|
&sighand->action[SIGKILL - 1]);
|
|
recalc_sigpending();
|
|
goto fatal;
|
|
}
|
|
|
|
for (;;) {
|
|
struct k_sigaction *ka;
|
|
|
|
if (unlikely(current->jobctl & JOBCTL_STOP_PENDING) &&
|
|
do_signal_stop(0))
|
|
goto relock;
|
|
|
|
if (unlikely(current->jobctl &
|
|
(JOBCTL_TRAP_MASK | JOBCTL_TRAP_FREEZE))) {
|
|
if (current->jobctl & JOBCTL_TRAP_MASK) {
|
|
do_jobctl_trap();
|
|
spin_unlock_irq(&sighand->siglock);
|
|
} else if (current->jobctl & JOBCTL_TRAP_FREEZE)
|
|
do_freezer_trap();
|
|
|
|
goto relock;
|
|
}
|
|
|
|
/*
|
|
* If the task is leaving the frozen state, let's update
|
|
* cgroup counters and reset the frozen bit.
|
|
*/
|
|
if (unlikely(cgroup_task_frozen(current))) {
|
|
spin_unlock_irq(&sighand->siglock);
|
|
cgroup_leave_frozen(false);
|
|
goto relock;
|
|
}
|
|
|
|
/*
|
|
* Signals generated by the execution of an instruction
|
|
* need to be delivered before any other pending signals
|
|
* so that the instruction pointer in the signal stack
|
|
* frame points to the faulting instruction.
|
|
*/
|
|
signr = dequeue_synchronous_signal(&ksig->info);
|
|
if (!signr)
|
|
signr = dequeue_signal(current, ¤t->blocked, &ksig->info);
|
|
|
|
if (!signr)
|
|
break; /* will return 0 */
|
|
|
|
if (unlikely(current->ptrace) && signr != SIGKILL) {
|
|
signr = ptrace_signal(signr, &ksig->info);
|
|
if (!signr)
|
|
continue;
|
|
}
|
|
|
|
ka = &sighand->action[signr-1];
|
|
|
|
/* Trace actually delivered signals. */
|
|
trace_signal_deliver(signr, &ksig->info, ka);
|
|
|
|
if (ka->sa.sa_handler == SIG_IGN) /* Do nothing. */
|
|
continue;
|
|
if (ka->sa.sa_handler != SIG_DFL) {
|
|
/* Run the handler. */
|
|
ksig->ka = *ka;
|
|
|
|
if (ka->sa.sa_flags & SA_ONESHOT)
|
|
ka->sa.sa_handler = SIG_DFL;
|
|
|
|
break; /* will return non-zero "signr" value */
|
|
}
|
|
|
|
/*
|
|
* Now we are doing the default action for this signal.
|
|
*/
|
|
if (sig_kernel_ignore(signr)) /* Default is nothing. */
|
|
continue;
|
|
|
|
/*
|
|
* Global init gets no signals it doesn't want.
|
|
* Container-init gets no signals it doesn't want from same
|
|
* container.
|
|
*
|
|
* Note that if global/container-init sees a sig_kernel_only()
|
|
* signal here, the signal must have been generated internally
|
|
* or must have come from an ancestor namespace. In either
|
|
* case, the signal cannot be dropped.
|
|
*/
|
|
if (unlikely(signal->flags & SIGNAL_UNKILLABLE) &&
|
|
!sig_kernel_only(signr))
|
|
continue;
|
|
|
|
if (sig_kernel_stop(signr)) {
|
|
/*
|
|
* The default action is to stop all threads in
|
|
* the thread group. The job control signals
|
|
* do nothing in an orphaned pgrp, but SIGSTOP
|
|
* always works. Note that siglock needs to be
|
|
* dropped during the call to is_orphaned_pgrp()
|
|
* because of lock ordering with tasklist_lock.
|
|
* This allows an intervening SIGCONT to be posted.
|
|
* We need to check for that and bail out if necessary.
|
|
*/
|
|
if (signr != SIGSTOP) {
|
|
spin_unlock_irq(&sighand->siglock);
|
|
|
|
/* signals can be posted during this window */
|
|
|
|
if (is_current_pgrp_orphaned())
|
|
goto relock;
|
|
|
|
spin_lock_irq(&sighand->siglock);
|
|
}
|
|
|
|
if (likely(do_signal_stop(ksig->info.si_signo))) {
|
|
/* It released the siglock. */
|
|
goto relock;
|
|
}
|
|
|
|
/*
|
|
* We didn't actually stop, due to a race
|
|
* with SIGCONT or something like that.
|
|
*/
|
|
continue;
|
|
}
|
|
|
|
fatal:
|
|
spin_unlock_irq(&sighand->siglock);
|
|
if (unlikely(cgroup_task_frozen(current)))
|
|
cgroup_leave_frozen(true);
|
|
|
|
/*
|
|
* Anything else is fatal, maybe with a core dump.
|
|
*/
|
|
current->flags |= PF_SIGNALED;
|
|
|
|
if (sig_kernel_coredump(signr)) {
|
|
if (print_fatal_signals)
|
|
print_fatal_signal(ksig->info.si_signo);
|
|
proc_coredump_connector(current);
|
|
/*
|
|
* If it was able to dump core, this kills all
|
|
* other threads in the group and synchronizes with
|
|
* their demise. If we lost the race with another
|
|
* thread getting here, it set group_exit_code
|
|
* first and our do_group_exit call below will use
|
|
* that value and ignore the one we pass it.
|
|
*/
|
|
do_coredump(&ksig->info);
|
|
}
|
|
|
|
/*
|
|
* Death signals, no core dump.
|
|
*/
|
|
do_group_exit(ksig->info.si_signo);
|
|
/* NOTREACHED */
|
|
}
|
|
spin_unlock_irq(&sighand->siglock);
|
|
|
|
ksig->sig = signr;
|
|
return ksig->sig > 0;
|
|
}
|
|
|
|
/**
|
|
* signal_delivered -
|
|
* @ksig: kernel signal struct
|
|
* @stepping: nonzero if debugger single-step or block-step in use
|
|
*
|
|
* This function should be called when a signal has successfully been
|
|
* delivered. It updates the blocked signals accordingly (@ksig->ka.sa.sa_mask
|
|
* is always blocked, and the signal itself is blocked unless %SA_NODEFER
|
|
* is set in @ksig->ka.sa.sa_flags. Tracing is notified.
|
|
*/
|
|
static void signal_delivered(struct ksignal *ksig, int stepping)
|
|
{
|
|
sigset_t blocked;
|
|
|
|
/* A signal was successfully delivered, and the
|
|
saved sigmask was stored on the signal frame,
|
|
and will be restored by sigreturn. So we can
|
|
simply clear the restore sigmask flag. */
|
|
clear_restore_sigmask();
|
|
|
|
sigorsets(&blocked, ¤t->blocked, &ksig->ka.sa.sa_mask);
|
|
if (!(ksig->ka.sa.sa_flags & SA_NODEFER))
|
|
sigaddset(&blocked, ksig->sig);
|
|
set_current_blocked(&blocked);
|
|
tracehook_signal_handler(stepping);
|
|
}
|
|
|
|
void signal_setup_done(int failed, struct ksignal *ksig, int stepping)
|
|
{
|
|
if (failed)
|
|
force_sigsegv(ksig->sig);
|
|
else
|
|
signal_delivered(ksig, stepping);
|
|
}
|
|
|
|
/*
|
|
* It could be that complete_signal() picked us to notify about the
|
|
* group-wide signal. Other threads should be notified now to take
|
|
* the shared signals in @which since we will not.
|
|
*/
|
|
static void retarget_shared_pending(struct task_struct *tsk, sigset_t *which)
|
|
{
|
|
sigset_t retarget;
|
|
struct task_struct *t;
|
|
|
|
sigandsets(&retarget, &tsk->signal->shared_pending.signal, which);
|
|
if (sigisemptyset(&retarget))
|
|
return;
|
|
|
|
t = tsk;
|
|
while_each_thread(tsk, t) {
|
|
if (t->flags & PF_EXITING)
|
|
continue;
|
|
|
|
if (!has_pending_signals(&retarget, &t->blocked))
|
|
continue;
|
|
/* Remove the signals this thread can handle. */
|
|
sigandsets(&retarget, &retarget, &t->blocked);
|
|
|
|
if (!signal_pending(t))
|
|
signal_wake_up(t, 0);
|
|
|
|
if (sigisemptyset(&retarget))
|
|
break;
|
|
}
|
|
}
|
|
|
|
void exit_signals(struct task_struct *tsk)
|
|
{
|
|
int group_stop = 0;
|
|
sigset_t unblocked;
|
|
|
|
/*
|
|
* @tsk is about to have PF_EXITING set - lock out users which
|
|
* expect stable threadgroup.
|
|
*/
|
|
cgroup_threadgroup_change_begin(tsk);
|
|
|
|
if (thread_group_empty(tsk) || signal_group_exit(tsk->signal)) {
|
|
tsk->flags |= PF_EXITING;
|
|
cgroup_threadgroup_change_end(tsk);
|
|
return;
|
|
}
|
|
|
|
spin_lock_irq(&tsk->sighand->siglock);
|
|
/*
|
|
* From now this task is not visible for group-wide signals,
|
|
* see wants_signal(), do_signal_stop().
|
|
*/
|
|
tsk->flags |= PF_EXITING;
|
|
|
|
cgroup_threadgroup_change_end(tsk);
|
|
|
|
if (!signal_pending(tsk))
|
|
goto out;
|
|
|
|
unblocked = tsk->blocked;
|
|
signotset(&unblocked);
|
|
retarget_shared_pending(tsk, &unblocked);
|
|
|
|
if (unlikely(tsk->jobctl & JOBCTL_STOP_PENDING) &&
|
|
task_participate_group_stop(tsk))
|
|
group_stop = CLD_STOPPED;
|
|
out:
|
|
spin_unlock_irq(&tsk->sighand->siglock);
|
|
|
|
/*
|
|
* If group stop has completed, deliver the notification. This
|
|
* should always go to the real parent of the group leader.
|
|
*/
|
|
if (unlikely(group_stop)) {
|
|
read_lock(&tasklist_lock);
|
|
do_notify_parent_cldstop(tsk, false, group_stop);
|
|
read_unlock(&tasklist_lock);
|
|
}
|
|
}
|
|
|
|
/*
|
|
* System call entry points.
|
|
*/
|
|
|
|
/**
|
|
* sys_restart_syscall - restart a system call
|
|
*/
|
|
SYSCALL_DEFINE0(restart_syscall)
|
|
{
|
|
struct restart_block *restart = ¤t->restart_block;
|
|
return restart->fn(restart);
|
|
}
|
|
|
|
long do_no_restart_syscall(struct restart_block *param)
|
|
{
|
|
return -EINTR;
|
|
}
|
|
|
|
static void __set_task_blocked(struct task_struct *tsk, const sigset_t *newset)
|
|
{
|
|
if (signal_pending(tsk) && !thread_group_empty(tsk)) {
|
|
sigset_t newblocked;
|
|
/* A set of now blocked but previously unblocked signals. */
|
|
sigandnsets(&newblocked, newset, ¤t->blocked);
|
|
retarget_shared_pending(tsk, &newblocked);
|
|
}
|
|
tsk->blocked = *newset;
|
|
recalc_sigpending();
|
|
}
|
|
|
|
/**
|
|
* set_current_blocked - change current->blocked mask
|
|
* @newset: new mask
|
|
*
|
|
* It is wrong to change ->blocked directly, this helper should be used
|
|
* to ensure the process can't miss a shared signal we are going to block.
|
|
*/
|
|
void set_current_blocked(sigset_t *newset)
|
|
{
|
|
sigdelsetmask(newset, sigmask(SIGKILL) | sigmask(SIGSTOP));
|
|
__set_current_blocked(newset);
|
|
}
|
|
|
|
void __set_current_blocked(const sigset_t *newset)
|
|
{
|
|
struct task_struct *tsk = current;
|
|
|
|
/*
|
|
* In case the signal mask hasn't changed, there is nothing we need
|
|
* to do. The current->blocked shouldn't be modified by other task.
|
|
*/
|
|
if (sigequalsets(&tsk->blocked, newset))
|
|
return;
|
|
|
|
spin_lock_irq(&tsk->sighand->siglock);
|
|
__set_task_blocked(tsk, newset);
|
|
spin_unlock_irq(&tsk->sighand->siglock);
|
|
}
|
|
|
|
/*
|
|
* This is also useful for kernel threads that want to temporarily
|
|
* (or permanently) block certain signals.
|
|
*
|
|
* NOTE! Unlike the user-mode sys_sigprocmask(), the kernel
|
|
* interface happily blocks "unblockable" signals like SIGKILL
|
|
* and friends.
|
|
*/
|
|
int sigprocmask(int how, sigset_t *set, sigset_t *oldset)
|
|
{
|
|
struct task_struct *tsk = current;
|
|
sigset_t newset;
|
|
|
|
/* Lockless, only current can change ->blocked, never from irq */
|
|
if (oldset)
|
|
*oldset = tsk->blocked;
|
|
|
|
switch (how) {
|
|
case SIG_BLOCK:
|
|
sigorsets(&newset, &tsk->blocked, set);
|
|
break;
|
|
case SIG_UNBLOCK:
|
|
sigandnsets(&newset, &tsk->blocked, set);
|
|
break;
|
|
case SIG_SETMASK:
|
|
newset = *set;
|
|
break;
|
|
default:
|
|
return -EINVAL;
|
|
}
|
|
|
|
__set_current_blocked(&newset);
|
|
return 0;
|
|
}
|
|
EXPORT_SYMBOL(sigprocmask);
|
|
|
|
/*
|
|
* The api helps set app-provided sigmasks.
|
|
*
|
|
* This is useful for syscalls such as ppoll, pselect, io_pgetevents and
|
|
* epoll_pwait where a new sigmask is passed from userland for the syscalls.
|
|
*
|
|
* Note that it does set_restore_sigmask() in advance, so it must be always
|
|
* paired with restore_saved_sigmask_unless() before return from syscall.
|
|
*/
|
|
int set_user_sigmask(const sigset_t __user *umask, size_t sigsetsize)
|
|
{
|
|
sigset_t kmask;
|
|
|
|
if (!umask)
|
|
return 0;
|
|
if (sigsetsize != sizeof(sigset_t))
|
|
return -EINVAL;
|
|
if (copy_from_user(&kmask, umask, sizeof(sigset_t)))
|
|
return -EFAULT;
|
|
|
|
set_restore_sigmask();
|
|
current->saved_sigmask = current->blocked;
|
|
set_current_blocked(&kmask);
|
|
|
|
return 0;
|
|
}
|
|
|
|
#ifdef CONFIG_COMPAT
|
|
int set_compat_user_sigmask(const compat_sigset_t __user *umask,
|
|
size_t sigsetsize)
|
|
{
|
|
sigset_t kmask;
|
|
|
|
if (!umask)
|
|
return 0;
|
|
if (sigsetsize != sizeof(compat_sigset_t))
|
|
return -EINVAL;
|
|
if (get_compat_sigset(&kmask, umask))
|
|
return -EFAULT;
|
|
|
|
set_restore_sigmask();
|
|
current->saved_sigmask = current->blocked;
|
|
set_current_blocked(&kmask);
|
|
|
|
return 0;
|
|
}
|
|
#endif
|
|
|
|
/**
|
|
* sys_rt_sigprocmask - change the list of currently blocked signals
|
|
* @how: whether to add, remove, or set signals
|
|
* @nset: stores pending signals
|
|
* @oset: previous value of signal mask if non-null
|
|
* @sigsetsize: size of sigset_t type
|
|
*/
|
|
SYSCALL_DEFINE4(rt_sigprocmask, int, how, sigset_t __user *, nset,
|
|
sigset_t __user *, oset, size_t, sigsetsize)
|
|
{
|
|
sigset_t old_set, new_set;
|
|
int error;
|
|
|
|
/* XXX: Don't preclude handling different sized sigset_t's. */
|
|
if (sigsetsize != sizeof(sigset_t))
|
|
return -EINVAL;
|
|
|
|
old_set = current->blocked;
|
|
|
|
if (nset) {
|
|
if (copy_from_user(&new_set, nset, sizeof(sigset_t)))
|
|
return -EFAULT;
|
|
sigdelsetmask(&new_set, sigmask(SIGKILL)|sigmask(SIGSTOP));
|
|
|
|
error = sigprocmask(how, &new_set, NULL);
|
|
if (error)
|
|
return error;
|
|
}
|
|
|
|
if (oset) {
|
|
if (copy_to_user(oset, &old_set, sizeof(sigset_t)))
|
|
return -EFAULT;
|
|
}
|
|
|
|
return 0;
|
|
}
|
|
|
|
#ifdef CONFIG_COMPAT
|
|
COMPAT_SYSCALL_DEFINE4(rt_sigprocmask, int, how, compat_sigset_t __user *, nset,
|
|
compat_sigset_t __user *, oset, compat_size_t, sigsetsize)
|
|
{
|
|
sigset_t old_set = current->blocked;
|
|
|
|
/* XXX: Don't preclude handling different sized sigset_t's. */
|
|
if (sigsetsize != sizeof(sigset_t))
|
|
return -EINVAL;
|
|
|
|
if (nset) {
|
|
sigset_t new_set;
|
|
int error;
|
|
if (get_compat_sigset(&new_set, nset))
|
|
return -EFAULT;
|
|
sigdelsetmask(&new_set, sigmask(SIGKILL)|sigmask(SIGSTOP));
|
|
|
|
error = sigprocmask(how, &new_set, NULL);
|
|
if (error)
|
|
return error;
|
|
}
|
|
return oset ? put_compat_sigset(oset, &old_set, sizeof(*oset)) : 0;
|
|
}
|
|
#endif
|
|
|
|
static void do_sigpending(sigset_t *set)
|
|
{
|
|
spin_lock_irq(¤t->sighand->siglock);
|
|
sigorsets(set, ¤t->pending.signal,
|
|
¤t->signal->shared_pending.signal);
|
|
spin_unlock_irq(¤t->sighand->siglock);
|
|
|
|
/* Outside the lock because only this thread touches it. */
|
|
sigandsets(set, ¤t->blocked, set);
|
|
}
|
|
|
|
/**
|
|
* sys_rt_sigpending - examine a pending signal that has been raised
|
|
* while blocked
|
|
* @uset: stores pending signals
|
|
* @sigsetsize: size of sigset_t type or larger
|
|
*/
|
|
SYSCALL_DEFINE2(rt_sigpending, sigset_t __user *, uset, size_t, sigsetsize)
|
|
{
|
|
sigset_t set;
|
|
|
|
if (sigsetsize > sizeof(*uset))
|
|
return -EINVAL;
|
|
|
|
do_sigpending(&set);
|
|
|
|
if (copy_to_user(uset, &set, sigsetsize))
|
|
return -EFAULT;
|
|
|
|
return 0;
|
|
}
|
|
|
|
#ifdef CONFIG_COMPAT
|
|
COMPAT_SYSCALL_DEFINE2(rt_sigpending, compat_sigset_t __user *, uset,
|
|
compat_size_t, sigsetsize)
|
|
{
|
|
sigset_t set;
|
|
|
|
if (sigsetsize > sizeof(*uset))
|
|
return -EINVAL;
|
|
|
|
do_sigpending(&set);
|
|
|
|
return put_compat_sigset(uset, &set, sigsetsize);
|
|
}
|
|
#endif
|
|
|
|
static const struct {
|
|
unsigned char limit, layout;
|
|
} sig_sicodes[] = {
|
|
[SIGILL] = { NSIGILL, SIL_FAULT },
|
|
[SIGFPE] = { NSIGFPE, SIL_FAULT },
|
|
[SIGSEGV] = { NSIGSEGV, SIL_FAULT },
|
|
[SIGBUS] = { NSIGBUS, SIL_FAULT },
|
|
[SIGTRAP] = { NSIGTRAP, SIL_FAULT },
|
|
#if defined(SIGEMT)
|
|
[SIGEMT] = { NSIGEMT, SIL_FAULT },
|
|
#endif
|
|
[SIGCHLD] = { NSIGCHLD, SIL_CHLD },
|
|
[SIGPOLL] = { NSIGPOLL, SIL_POLL },
|
|
[SIGSYS] = { NSIGSYS, SIL_SYS },
|
|
};
|
|
|
|
static bool known_siginfo_layout(unsigned sig, int si_code)
|
|
{
|
|
if (si_code == SI_KERNEL)
|
|
return true;
|
|
else if ((si_code > SI_USER)) {
|
|
if (sig_specific_sicodes(sig)) {
|
|
if (si_code <= sig_sicodes[sig].limit)
|
|
return true;
|
|
}
|
|
else if (si_code <= NSIGPOLL)
|
|
return true;
|
|
}
|
|
else if (si_code >= SI_DETHREAD)
|
|
return true;
|
|
else if (si_code == SI_ASYNCNL)
|
|
return true;
|
|
return false;
|
|
}
|
|
|
|
enum siginfo_layout siginfo_layout(unsigned sig, int si_code)
|
|
{
|
|
enum siginfo_layout layout = SIL_KILL;
|
|
if ((si_code > SI_USER) && (si_code < SI_KERNEL)) {
|
|
if ((sig < ARRAY_SIZE(sig_sicodes)) &&
|
|
(si_code <= sig_sicodes[sig].limit)) {
|
|
layout = sig_sicodes[sig].layout;
|
|
/* Handle the exceptions */
|
|
if ((sig == SIGBUS) &&
|
|
(si_code >= BUS_MCEERR_AR) && (si_code <= BUS_MCEERR_AO))
|
|
layout = SIL_FAULT_MCEERR;
|
|
else if ((sig == SIGSEGV) && (si_code == SEGV_BNDERR))
|
|
layout = SIL_FAULT_BNDERR;
|
|
#ifdef SEGV_PKUERR
|
|
else if ((sig == SIGSEGV) && (si_code == SEGV_PKUERR))
|
|
layout = SIL_FAULT_PKUERR;
|
|
#endif
|
|
}
|
|
else if (si_code <= NSIGPOLL)
|
|
layout = SIL_POLL;
|
|
} else {
|
|
if (si_code == SI_TIMER)
|
|
layout = SIL_TIMER;
|
|
else if (si_code == SI_SIGIO)
|
|
layout = SIL_POLL;
|
|
else if (si_code < 0)
|
|
layout = SIL_RT;
|
|
}
|
|
return layout;
|
|
}
|
|
|
|
static inline char __user *si_expansion(const siginfo_t __user *info)
|
|
{
|
|
return ((char __user *)info) + sizeof(struct kernel_siginfo);
|
|
}
|
|
|
|
int copy_siginfo_to_user(siginfo_t __user *to, const kernel_siginfo_t *from)
|
|
{
|
|
char __user *expansion = si_expansion(to);
|
|
if (copy_to_user(to, from , sizeof(struct kernel_siginfo)))
|
|
return -EFAULT;
|
|
if (clear_user(expansion, SI_EXPANSION_SIZE))
|
|
return -EFAULT;
|
|
return 0;
|
|
}
|
|
|
|
static int post_copy_siginfo_from_user(kernel_siginfo_t *info,
|
|
const siginfo_t __user *from)
|
|
{
|
|
if (unlikely(!known_siginfo_layout(info->si_signo, info->si_code))) {
|
|
char __user *expansion = si_expansion(from);
|
|
char buf[SI_EXPANSION_SIZE];
|
|
int i;
|
|
/*
|
|
* An unknown si_code might need more than
|
|
* sizeof(struct kernel_siginfo) bytes. Verify all of the
|
|
* extra bytes are 0. This guarantees copy_siginfo_to_user
|
|
* will return this data to userspace exactly.
|
|
*/
|
|
if (copy_from_user(&buf, expansion, SI_EXPANSION_SIZE))
|
|
return -EFAULT;
|
|
for (i = 0; i < SI_EXPANSION_SIZE; i++) {
|
|
if (buf[i] != 0)
|
|
return -E2BIG;
|
|
}
|
|
}
|
|
return 0;
|
|
}
|
|
|
|
static int __copy_siginfo_from_user(int signo, kernel_siginfo_t *to,
|
|
const siginfo_t __user *from)
|
|
{
|
|
if (copy_from_user(to, from, sizeof(struct kernel_siginfo)))
|
|
return -EFAULT;
|
|
to->si_signo = signo;
|
|
return post_copy_siginfo_from_user(to, from);
|
|
}
|
|
|
|
int copy_siginfo_from_user(kernel_siginfo_t *to, const siginfo_t __user *from)
|
|
{
|
|
if (copy_from_user(to, from, sizeof(struct kernel_siginfo)))
|
|
return -EFAULT;
|
|
return post_copy_siginfo_from_user(to, from);
|
|
}
|
|
|
|
#ifdef CONFIG_COMPAT
|
|
int copy_siginfo_to_user32(struct compat_siginfo __user *to,
|
|
const struct kernel_siginfo *from)
|
|
#if defined(CONFIG_X86_X32_ABI) || defined(CONFIG_IA32_EMULATION)
|
|
{
|
|
return __copy_siginfo_to_user32(to, from, in_x32_syscall());
|
|
}
|
|
int __copy_siginfo_to_user32(struct compat_siginfo __user *to,
|
|
const struct kernel_siginfo *from, bool x32_ABI)
|
|
#endif
|
|
{
|
|
struct compat_siginfo new;
|
|
memset(&new, 0, sizeof(new));
|
|
|
|
new.si_signo = from->si_signo;
|
|
new.si_errno = from->si_errno;
|
|
new.si_code = from->si_code;
|
|
switch(siginfo_layout(from->si_signo, from->si_code)) {
|
|
case SIL_KILL:
|
|
new.si_pid = from->si_pid;
|
|
new.si_uid = from->si_uid;
|
|
break;
|
|
case SIL_TIMER:
|
|
new.si_tid = from->si_tid;
|
|
new.si_overrun = from->si_overrun;
|
|
new.si_int = from->si_int;
|
|
break;
|
|
case SIL_POLL:
|
|
new.si_band = from->si_band;
|
|
new.si_fd = from->si_fd;
|
|
break;
|
|
case SIL_FAULT:
|
|
new.si_addr = ptr_to_compat(from->si_addr);
|
|
#ifdef __ARCH_SI_TRAPNO
|
|
new.si_trapno = from->si_trapno;
|
|
#endif
|
|
break;
|
|
case SIL_FAULT_MCEERR:
|
|
new.si_addr = ptr_to_compat(from->si_addr);
|
|
#ifdef __ARCH_SI_TRAPNO
|
|
new.si_trapno = from->si_trapno;
|
|
#endif
|
|
new.si_addr_lsb = from->si_addr_lsb;
|
|
break;
|
|
case SIL_FAULT_BNDERR:
|
|
new.si_addr = ptr_to_compat(from->si_addr);
|
|
#ifdef __ARCH_SI_TRAPNO
|
|
new.si_trapno = from->si_trapno;
|
|
#endif
|
|
new.si_lower = ptr_to_compat(from->si_lower);
|
|
new.si_upper = ptr_to_compat(from->si_upper);
|
|
break;
|
|
case SIL_FAULT_PKUERR:
|
|
new.si_addr = ptr_to_compat(from->si_addr);
|
|
#ifdef __ARCH_SI_TRAPNO
|
|
new.si_trapno = from->si_trapno;
|
|
#endif
|
|
new.si_pkey = from->si_pkey;
|
|
break;
|
|
case SIL_CHLD:
|
|
new.si_pid = from->si_pid;
|
|
new.si_uid = from->si_uid;
|
|
new.si_status = from->si_status;
|
|
#ifdef CONFIG_X86_X32_ABI
|
|
if (x32_ABI) {
|
|
new._sifields._sigchld_x32._utime = from->si_utime;
|
|
new._sifields._sigchld_x32._stime = from->si_stime;
|
|
} else
|
|
#endif
|
|
{
|
|
new.si_utime = from->si_utime;
|
|
new.si_stime = from->si_stime;
|
|
}
|
|
break;
|
|
case SIL_RT:
|
|
new.si_pid = from->si_pid;
|
|
new.si_uid = from->si_uid;
|
|
new.si_int = from->si_int;
|
|
break;
|
|
case SIL_SYS:
|
|
new.si_call_addr = ptr_to_compat(from->si_call_addr);
|
|
new.si_syscall = from->si_syscall;
|
|
new.si_arch = from->si_arch;
|
|
break;
|
|
}
|
|
|
|
if (copy_to_user(to, &new, sizeof(struct compat_siginfo)))
|
|
return -EFAULT;
|
|
|
|
return 0;
|
|
}
|
|
|
|
static int post_copy_siginfo_from_user32(kernel_siginfo_t *to,
|
|
const struct compat_siginfo *from)
|
|
{
|
|
clear_siginfo(to);
|
|
to->si_signo = from->si_signo;
|
|
to->si_errno = from->si_errno;
|
|
to->si_code = from->si_code;
|
|
switch(siginfo_layout(from->si_signo, from->si_code)) {
|
|
case SIL_KILL:
|
|
to->si_pid = from->si_pid;
|
|
to->si_uid = from->si_uid;
|
|
break;
|
|
case SIL_TIMER:
|
|
to->si_tid = from->si_tid;
|
|
to->si_overrun = from->si_overrun;
|
|
to->si_int = from->si_int;
|
|
break;
|
|
case SIL_POLL:
|
|
to->si_band = from->si_band;
|
|
to->si_fd = from->si_fd;
|
|
break;
|
|
case SIL_FAULT:
|
|
to->si_addr = compat_ptr(from->si_addr);
|
|
#ifdef __ARCH_SI_TRAPNO
|
|
to->si_trapno = from->si_trapno;
|
|
#endif
|
|
break;
|
|
case SIL_FAULT_MCEERR:
|
|
to->si_addr = compat_ptr(from->si_addr);
|
|
#ifdef __ARCH_SI_TRAPNO
|
|
to->si_trapno = from->si_trapno;
|
|
#endif
|
|
to->si_addr_lsb = from->si_addr_lsb;
|
|
break;
|
|
case SIL_FAULT_BNDERR:
|
|
to->si_addr = compat_ptr(from->si_addr);
|
|
#ifdef __ARCH_SI_TRAPNO
|
|
to->si_trapno = from->si_trapno;
|
|
#endif
|
|
to->si_lower = compat_ptr(from->si_lower);
|
|
to->si_upper = compat_ptr(from->si_upper);
|
|
break;
|
|
case SIL_FAULT_PKUERR:
|
|
to->si_addr = compat_ptr(from->si_addr);
|
|
#ifdef __ARCH_SI_TRAPNO
|
|
to->si_trapno = from->si_trapno;
|
|
#endif
|
|
to->si_pkey = from->si_pkey;
|
|
break;
|
|
case SIL_CHLD:
|
|
to->si_pid = from->si_pid;
|
|
to->si_uid = from->si_uid;
|
|
to->si_status = from->si_status;
|
|
#ifdef CONFIG_X86_X32_ABI
|
|
if (in_x32_syscall()) {
|
|
to->si_utime = from->_sifields._sigchld_x32._utime;
|
|
to->si_stime = from->_sifields._sigchld_x32._stime;
|
|
} else
|
|
#endif
|
|
{
|
|
to->si_utime = from->si_utime;
|
|
to->si_stime = from->si_stime;
|
|
}
|
|
break;
|
|
case SIL_RT:
|
|
to->si_pid = from->si_pid;
|
|
to->si_uid = from->si_uid;
|
|
to->si_int = from->si_int;
|
|
break;
|
|
case SIL_SYS:
|
|
to->si_call_addr = compat_ptr(from->si_call_addr);
|
|
to->si_syscall = from->si_syscall;
|
|
to->si_arch = from->si_arch;
|
|
break;
|
|
}
|
|
return 0;
|
|
}
|
|
|
|
static int __copy_siginfo_from_user32(int signo, struct kernel_siginfo *to,
|
|
const struct compat_siginfo __user *ufrom)
|
|
{
|
|
struct compat_siginfo from;
|
|
|
|
if (copy_from_user(&from, ufrom, sizeof(struct compat_siginfo)))
|
|
return -EFAULT;
|
|
|
|
from.si_signo = signo;
|
|
return post_copy_siginfo_from_user32(to, &from);
|
|
}
|
|
|
|
int copy_siginfo_from_user32(struct kernel_siginfo *to,
|
|
const struct compat_siginfo __user *ufrom)
|
|
{
|
|
struct compat_siginfo from;
|
|
|
|
if (copy_from_user(&from, ufrom, sizeof(struct compat_siginfo)))
|
|
return -EFAULT;
|
|
|
|
return post_copy_siginfo_from_user32(to, &from);
|
|
}
|
|
#endif /* CONFIG_COMPAT */
|
|
|
|
/**
|
|
* do_sigtimedwait - wait for queued signals specified in @which
|
|
* @which: queued signals to wait for
|
|
* @info: if non-null, the signal's siginfo is returned here
|
|
* @ts: upper bound on process time suspension
|
|
*/
|
|
static int do_sigtimedwait(const sigset_t *which, kernel_siginfo_t *info,
|
|
const struct timespec64 *ts)
|
|
{
|
|
ktime_t *to = NULL, timeout = KTIME_MAX;
|
|
struct task_struct *tsk = current;
|
|
sigset_t mask = *which;
|
|
int sig, ret = 0;
|
|
|
|
if (ts) {
|
|
if (!timespec64_valid(ts))
|
|
return -EINVAL;
|
|
timeout = timespec64_to_ktime(*ts);
|
|
to = &timeout;
|
|
}
|
|
|
|
/*
|
|
* Invert the set of allowed signals to get those we want to block.
|
|
*/
|
|
sigdelsetmask(&mask, sigmask(SIGKILL) | sigmask(SIGSTOP));
|
|
signotset(&mask);
|
|
|
|
spin_lock_irq(&tsk->sighand->siglock);
|
|
sig = dequeue_signal(tsk, &mask, info);
|
|
if (!sig && timeout) {
|
|
/*
|
|
* None ready, temporarily unblock those we're interested
|
|
* while we are sleeping in so that we'll be awakened when
|
|
* they arrive. Unblocking is always fine, we can avoid
|
|
* set_current_blocked().
|
|
*/
|
|
tsk->real_blocked = tsk->blocked;
|
|
sigandsets(&tsk->blocked, &tsk->blocked, &mask);
|
|
recalc_sigpending();
|
|
spin_unlock_irq(&tsk->sighand->siglock);
|
|
|
|
__set_current_state(TASK_INTERRUPTIBLE);
|
|
ret = freezable_schedule_hrtimeout_range(to, tsk->timer_slack_ns,
|
|
HRTIMER_MODE_REL);
|
|
spin_lock_irq(&tsk->sighand->siglock);
|
|
__set_task_blocked(tsk, &tsk->real_blocked);
|
|
sigemptyset(&tsk->real_blocked);
|
|
sig = dequeue_signal(tsk, &mask, info);
|
|
}
|
|
spin_unlock_irq(&tsk->sighand->siglock);
|
|
|
|
if (sig)
|
|
return sig;
|
|
return ret ? -EINTR : -EAGAIN;
|
|
}
|
|
|
|
/**
|
|
* sys_rt_sigtimedwait - synchronously wait for queued signals specified
|
|
* in @uthese
|
|
* @uthese: queued signals to wait for
|
|
* @uinfo: if non-null, the signal's siginfo is returned here
|
|
* @uts: upper bound on process time suspension
|
|
* @sigsetsize: size of sigset_t type
|
|
*/
|
|
SYSCALL_DEFINE4(rt_sigtimedwait, const sigset_t __user *, uthese,
|
|
siginfo_t __user *, uinfo,
|
|
const struct __kernel_timespec __user *, uts,
|
|
size_t, sigsetsize)
|
|
{
|
|
sigset_t these;
|
|
struct timespec64 ts;
|
|
kernel_siginfo_t info;
|
|
int ret;
|
|
|
|
/* XXX: Don't preclude handling different sized sigset_t's. */
|
|
if (sigsetsize != sizeof(sigset_t))
|
|
return -EINVAL;
|
|
|
|
if (copy_from_user(&these, uthese, sizeof(these)))
|
|
return -EFAULT;
|
|
|
|
if (uts) {
|
|
if (get_timespec64(&ts, uts))
|
|
return -EFAULT;
|
|
}
|
|
|
|
ret = do_sigtimedwait(&these, &info, uts ? &ts : NULL);
|
|
|
|
if (ret > 0 && uinfo) {
|
|
if (copy_siginfo_to_user(uinfo, &info))
|
|
ret = -EFAULT;
|
|
}
|
|
|
|
return ret;
|
|
}
|
|
|
|
#ifdef CONFIG_COMPAT_32BIT_TIME
|
|
SYSCALL_DEFINE4(rt_sigtimedwait_time32, const sigset_t __user *, uthese,
|
|
siginfo_t __user *, uinfo,
|
|
const struct old_timespec32 __user *, uts,
|
|
size_t, sigsetsize)
|
|
{
|
|
sigset_t these;
|
|
struct timespec64 ts;
|
|
kernel_siginfo_t info;
|
|
int ret;
|
|
|
|
if (sigsetsize != sizeof(sigset_t))
|
|
return -EINVAL;
|
|
|
|
if (copy_from_user(&these, uthese, sizeof(these)))
|
|
return -EFAULT;
|
|
|
|
if (uts) {
|
|
if (get_old_timespec32(&ts, uts))
|
|
return -EFAULT;
|
|
}
|
|
|
|
ret = do_sigtimedwait(&these, &info, uts ? &ts : NULL);
|
|
|
|
if (ret > 0 && uinfo) {
|
|
if (copy_siginfo_to_user(uinfo, &info))
|
|
ret = -EFAULT;
|
|
}
|
|
|
|
return ret;
|
|
}
|
|
#endif
|
|
|
|
#ifdef CONFIG_COMPAT
|
|
COMPAT_SYSCALL_DEFINE4(rt_sigtimedwait_time64, compat_sigset_t __user *, uthese,
|
|
struct compat_siginfo __user *, uinfo,
|
|
struct __kernel_timespec __user *, uts, compat_size_t, sigsetsize)
|
|
{
|
|
sigset_t s;
|
|
struct timespec64 t;
|
|
kernel_siginfo_t info;
|
|
long ret;
|
|
|
|
if (sigsetsize != sizeof(sigset_t))
|
|
return -EINVAL;
|
|
|
|
if (get_compat_sigset(&s, uthese))
|
|
return -EFAULT;
|
|
|
|
if (uts) {
|
|
if (get_timespec64(&t, uts))
|
|
return -EFAULT;
|
|
}
|
|
|
|
ret = do_sigtimedwait(&s, &info, uts ? &t : NULL);
|
|
|
|
if (ret > 0 && uinfo) {
|
|
if (copy_siginfo_to_user32(uinfo, &info))
|
|
ret = -EFAULT;
|
|
}
|
|
|
|
return ret;
|
|
}
|
|
|
|
#ifdef CONFIG_COMPAT_32BIT_TIME
|
|
COMPAT_SYSCALL_DEFINE4(rt_sigtimedwait_time32, compat_sigset_t __user *, uthese,
|
|
struct compat_siginfo __user *, uinfo,
|
|
struct old_timespec32 __user *, uts, compat_size_t, sigsetsize)
|
|
{
|
|
sigset_t s;
|
|
struct timespec64 t;
|
|
kernel_siginfo_t info;
|
|
long ret;
|
|
|
|
if (sigsetsize != sizeof(sigset_t))
|
|
return -EINVAL;
|
|
|
|
if (get_compat_sigset(&s, uthese))
|
|
return -EFAULT;
|
|
|
|
if (uts) {
|
|
if (get_old_timespec32(&t, uts))
|
|
return -EFAULT;
|
|
}
|
|
|
|
ret = do_sigtimedwait(&s, &info, uts ? &t : NULL);
|
|
|
|
if (ret > 0 && uinfo) {
|
|
if (copy_siginfo_to_user32(uinfo, &info))
|
|
ret = -EFAULT;
|
|
}
|
|
|
|
return ret;
|
|
}
|
|
#endif
|
|
#endif
|
|
|
|
static inline void prepare_kill_siginfo(int sig, struct kernel_siginfo *info)
|
|
{
|
|
clear_siginfo(info);
|
|
info->si_signo = sig;
|
|
info->si_errno = 0;
|
|
info->si_code = SI_USER;
|
|
info->si_pid = task_tgid_vnr(current);
|
|
info->si_uid = from_kuid_munged(current_user_ns(), current_uid());
|
|
}
|
|
|
|
/**
|
|
* sys_kill - send a signal to a process
|
|
* @pid: the PID of the process
|
|
* @sig: signal to be sent
|
|
*/
|
|
SYSCALL_DEFINE2(kill, pid_t, pid, int, sig)
|
|
{
|
|
struct kernel_siginfo info;
|
|
|
|
prepare_kill_siginfo(sig, &info);
|
|
|
|
return kill_something_info(sig, &info, pid);
|
|
}
|
|
|
|
/*
|
|
* Verify that the signaler and signalee either are in the same pid namespace
|
|
* or that the signaler's pid namespace is an ancestor of the signalee's pid
|
|
* namespace.
|
|
*/
|
|
static bool access_pidfd_pidns(struct pid *pid)
|
|
{
|
|
struct pid_namespace *active = task_active_pid_ns(current);
|
|
struct pid_namespace *p = ns_of_pid(pid);
|
|
|
|
for (;;) {
|
|
if (!p)
|
|
return false;
|
|
if (p == active)
|
|
break;
|
|
p = p->parent;
|
|
}
|
|
|
|
return true;
|
|
}
|
|
|
|
static int copy_siginfo_from_user_any(kernel_siginfo_t *kinfo, siginfo_t *info)
|
|
{
|
|
#ifdef CONFIG_COMPAT
|
|
/*
|
|
* Avoid hooking up compat syscalls and instead handle necessary
|
|
* conversions here. Note, this is a stop-gap measure and should not be
|
|
* considered a generic solution.
|
|
*/
|
|
if (in_compat_syscall())
|
|
return copy_siginfo_from_user32(
|
|
kinfo, (struct compat_siginfo __user *)info);
|
|
#endif
|
|
return copy_siginfo_from_user(kinfo, info);
|
|
}
|
|
|
|
static struct pid *pidfd_to_pid(const struct file *file)
|
|
{
|
|
struct pid *pid;
|
|
|
|
pid = pidfd_pid(file);
|
|
if (!IS_ERR(pid))
|
|
return pid;
|
|
|
|
return tgid_pidfd_to_pid(file);
|
|
}
|
|
|
|
/**
|
|
* sys_pidfd_send_signal - Signal a process through a pidfd
|
|
* @pidfd: file descriptor of the process
|
|
* @sig: signal to send
|
|
* @info: signal info
|
|
* @flags: future flags
|
|
*
|
|
* The syscall currently only signals via PIDTYPE_PID which covers
|
|
* kill(<positive-pid>, <signal>. It does not signal threads or process
|
|
* groups.
|
|
* In order to extend the syscall to threads and process groups the @flags
|
|
* argument should be used. In essence, the @flags argument will determine
|
|
* what is signaled and not the file descriptor itself. Put in other words,
|
|
* grouping is a property of the flags argument not a property of the file
|
|
* descriptor.
|
|
*
|
|
* Return: 0 on success, negative errno on failure
|
|
*/
|
|
SYSCALL_DEFINE4(pidfd_send_signal, int, pidfd, int, sig,
|
|
siginfo_t __user *, info, unsigned int, flags)
|
|
{
|
|
int ret;
|
|
struct fd f;
|
|
struct pid *pid;
|
|
kernel_siginfo_t kinfo;
|
|
|
|
/* Enforce flags be set to 0 until we add an extension. */
|
|
if (flags)
|
|
return -EINVAL;
|
|
|
|
f = fdget(pidfd);
|
|
if (!f.file)
|
|
return -EBADF;
|
|
|
|
/* Is this a pidfd? */
|
|
pid = pidfd_to_pid(f.file);
|
|
if (IS_ERR(pid)) {
|
|
ret = PTR_ERR(pid);
|
|
goto err;
|
|
}
|
|
|
|
ret = -EINVAL;
|
|
if (!access_pidfd_pidns(pid))
|
|
goto err;
|
|
|
|
if (info) {
|
|
ret = copy_siginfo_from_user_any(&kinfo, info);
|
|
if (unlikely(ret))
|
|
goto err;
|
|
|
|
ret = -EINVAL;
|
|
if (unlikely(sig != kinfo.si_signo))
|
|
goto err;
|
|
|
|
/* Only allow sending arbitrary signals to yourself. */
|
|
ret = -EPERM;
|
|
if ((task_pid(current) != pid) &&
|
|
(kinfo.si_code >= 0 || kinfo.si_code == SI_TKILL))
|
|
goto err;
|
|
} else {
|
|
prepare_kill_siginfo(sig, &kinfo);
|
|
}
|
|
|
|
ret = kill_pid_info(sig, &kinfo, pid);
|
|
|
|
err:
|
|
fdput(f);
|
|
return ret;
|
|
}
|
|
|
|
static int
|
|
do_send_specific(pid_t tgid, pid_t pid, int sig, struct kernel_siginfo *info)
|
|
{
|
|
struct task_struct *p;
|
|
int error = -ESRCH;
|
|
|
|
rcu_read_lock();
|
|
p = find_task_by_vpid(pid);
|
|
if (p && (tgid <= 0 || task_tgid_vnr(p) == tgid)) {
|
|
error = check_kill_permission(sig, info, p);
|
|
/*
|
|
* The null signal is a permissions and process existence
|
|
* probe. No signal is actually delivered.
|
|
*/
|
|
if (!error && sig) {
|
|
error = do_send_sig_info(sig, info, p, PIDTYPE_PID);
|
|
/*
|
|
* If lock_task_sighand() failed we pretend the task
|
|
* dies after receiving the signal. The window is tiny,
|
|
* and the signal is private anyway.
|
|
*/
|
|
if (unlikely(error == -ESRCH))
|
|
error = 0;
|
|
}
|
|
}
|
|
rcu_read_unlock();
|
|
|
|
return error;
|
|
}
|
|
|
|
static int do_tkill(pid_t tgid, pid_t pid, int sig)
|
|
{
|
|
struct kernel_siginfo info;
|
|
|
|
clear_siginfo(&info);
|
|
info.si_signo = sig;
|
|
info.si_errno = 0;
|
|
info.si_code = SI_TKILL;
|
|
info.si_pid = task_tgid_vnr(current);
|
|
info.si_uid = from_kuid_munged(current_user_ns(), current_uid());
|
|
|
|
return do_send_specific(tgid, pid, sig, &info);
|
|
}
|
|
|
|
/**
|
|
* sys_tgkill - send signal to one specific thread
|
|
* @tgid: the thread group ID of the thread
|
|
* @pid: the PID of the thread
|
|
* @sig: signal to be sent
|
|
*
|
|
* This syscall also checks the @tgid and returns -ESRCH even if the PID
|
|
* exists but it's not belonging to the target process anymore. This
|
|
* method solves the problem of threads exiting and PIDs getting reused.
|
|
*/
|
|
SYSCALL_DEFINE3(tgkill, pid_t, tgid, pid_t, pid, int, sig)
|
|
{
|
|
/* This is only valid for single tasks */
|
|
if (pid <= 0 || tgid <= 0)
|
|
return -EINVAL;
|
|
|
|
return do_tkill(tgid, pid, sig);
|
|
}
|
|
|
|
/**
|
|
* sys_tkill - send signal to one specific task
|
|
* @pid: the PID of the task
|
|
* @sig: signal to be sent
|
|
*
|
|
* Send a signal to only one task, even if it's a CLONE_THREAD task.
|
|
*/
|
|
SYSCALL_DEFINE2(tkill, pid_t, pid, int, sig)
|
|
{
|
|
/* This is only valid for single tasks */
|
|
if (pid <= 0)
|
|
return -EINVAL;
|
|
|
|
return do_tkill(0, pid, sig);
|
|
}
|
|
|
|
static int do_rt_sigqueueinfo(pid_t pid, int sig, kernel_siginfo_t *info)
|
|
{
|
|
/* Not even root can pretend to send signals from the kernel.
|
|
* Nor can they impersonate a kill()/tgkill(), which adds source info.
|
|
*/
|
|
if ((info->si_code >= 0 || info->si_code == SI_TKILL) &&
|
|
(task_pid_vnr(current) != pid))
|
|
return -EPERM;
|
|
|
|
/* POSIX.1b doesn't mention process groups. */
|
|
return kill_proc_info(sig, info, pid);
|
|
}
|
|
|
|
/**
|
|
* sys_rt_sigqueueinfo - send signal information to a signal
|
|
* @pid: the PID of the thread
|
|
* @sig: signal to be sent
|
|
* @uinfo: signal info to be sent
|
|
*/
|
|
SYSCALL_DEFINE3(rt_sigqueueinfo, pid_t, pid, int, sig,
|
|
siginfo_t __user *, uinfo)
|
|
{
|
|
kernel_siginfo_t info;
|
|
int ret = __copy_siginfo_from_user(sig, &info, uinfo);
|
|
if (unlikely(ret))
|
|
return ret;
|
|
return do_rt_sigqueueinfo(pid, sig, &info);
|
|
}
|
|
|
|
#ifdef CONFIG_COMPAT
|
|
COMPAT_SYSCALL_DEFINE3(rt_sigqueueinfo,
|
|
compat_pid_t, pid,
|
|
int, sig,
|
|
struct compat_siginfo __user *, uinfo)
|
|
{
|
|
kernel_siginfo_t info;
|
|
int ret = __copy_siginfo_from_user32(sig, &info, uinfo);
|
|
if (unlikely(ret))
|
|
return ret;
|
|
return do_rt_sigqueueinfo(pid, sig, &info);
|
|
}
|
|
#endif
|
|
|
|
static int do_rt_tgsigqueueinfo(pid_t tgid, pid_t pid, int sig, kernel_siginfo_t *info)
|
|
{
|
|
/* This is only valid for single tasks */
|
|
if (pid <= 0 || tgid <= 0)
|
|
return -EINVAL;
|
|
|
|
/* Not even root can pretend to send signals from the kernel.
|
|
* Nor can they impersonate a kill()/tgkill(), which adds source info.
|
|
*/
|
|
if ((info->si_code >= 0 || info->si_code == SI_TKILL) &&
|
|
(task_pid_vnr(current) != pid))
|
|
return -EPERM;
|
|
|
|
return do_send_specific(tgid, pid, sig, info);
|
|
}
|
|
|
|
SYSCALL_DEFINE4(rt_tgsigqueueinfo, pid_t, tgid, pid_t, pid, int, sig,
|
|
siginfo_t __user *, uinfo)
|
|
{
|
|
kernel_siginfo_t info;
|
|
int ret = __copy_siginfo_from_user(sig, &info, uinfo);
|
|
if (unlikely(ret))
|
|
return ret;
|
|
return do_rt_tgsigqueueinfo(tgid, pid, sig, &info);
|
|
}
|
|
|
|
#ifdef CONFIG_COMPAT
|
|
COMPAT_SYSCALL_DEFINE4(rt_tgsigqueueinfo,
|
|
compat_pid_t, tgid,
|
|
compat_pid_t, pid,
|
|
int, sig,
|
|
struct compat_siginfo __user *, uinfo)
|
|
{
|
|
kernel_siginfo_t info;
|
|
int ret = __copy_siginfo_from_user32(sig, &info, uinfo);
|
|
if (unlikely(ret))
|
|
return ret;
|
|
return do_rt_tgsigqueueinfo(tgid, pid, sig, &info);
|
|
}
|
|
#endif
|
|
|
|
/*
|
|
* For kthreads only, must not be used if cloned with CLONE_SIGHAND
|
|
*/
|
|
void kernel_sigaction(int sig, __sighandler_t action)
|
|
{
|
|
spin_lock_irq(¤t->sighand->siglock);
|
|
current->sighand->action[sig - 1].sa.sa_handler = action;
|
|
if (action == SIG_IGN) {
|
|
sigset_t mask;
|
|
|
|
sigemptyset(&mask);
|
|
sigaddset(&mask, sig);
|
|
|
|
flush_sigqueue_mask(&mask, ¤t->signal->shared_pending);
|
|
flush_sigqueue_mask(&mask, ¤t->pending);
|
|
recalc_sigpending();
|
|
}
|
|
spin_unlock_irq(¤t->sighand->siglock);
|
|
}
|
|
EXPORT_SYMBOL(kernel_sigaction);
|
|
|
|
void __weak sigaction_compat_abi(struct k_sigaction *act,
|
|
struct k_sigaction *oact)
|
|
{
|
|
}
|
|
|
|
int do_sigaction(int sig, struct k_sigaction *act, struct k_sigaction *oact)
|
|
{
|
|
struct task_struct *p = current, *t;
|
|
struct k_sigaction *k;
|
|
sigset_t mask;
|
|
|
|
if (!valid_signal(sig) || sig < 1 || (act && sig_kernel_only(sig)))
|
|
return -EINVAL;
|
|
|
|
k = &p->sighand->action[sig-1];
|
|
|
|
spin_lock_irq(&p->sighand->siglock);
|
|
if (oact)
|
|
*oact = *k;
|
|
|
|
sigaction_compat_abi(act, oact);
|
|
|
|
if (act) {
|
|
sigdelsetmask(&act->sa.sa_mask,
|
|
sigmask(SIGKILL) | sigmask(SIGSTOP));
|
|
*k = *act;
|
|
/*
|
|
* POSIX 3.3.1.3:
|
|
* "Setting a signal action to SIG_IGN for a signal that is
|
|
* pending shall cause the pending signal to be discarded,
|
|
* whether or not it is blocked."
|
|
*
|
|
* "Setting a signal action to SIG_DFL for a signal that is
|
|
* pending and whose default action is to ignore the signal
|
|
* (for example, SIGCHLD), shall cause the pending signal to
|
|
* be discarded, whether or not it is blocked"
|
|
*/
|
|
if (sig_handler_ignored(sig_handler(p, sig), sig)) {
|
|
sigemptyset(&mask);
|
|
sigaddset(&mask, sig);
|
|
flush_sigqueue_mask(&mask, &p->signal->shared_pending);
|
|
for_each_thread(p, t)
|
|
flush_sigqueue_mask(&mask, &t->pending);
|
|
}
|
|
}
|
|
|
|
spin_unlock_irq(&p->sighand->siglock);
|
|
return 0;
|
|
}
|
|
|
|
static int
|
|
do_sigaltstack (const stack_t *ss, stack_t *oss, unsigned long sp,
|
|
size_t min_ss_size)
|
|
{
|
|
struct task_struct *t = current;
|
|
|
|
if (oss) {
|
|
memset(oss, 0, sizeof(stack_t));
|
|
oss->ss_sp = (void __user *) t->sas_ss_sp;
|
|
oss->ss_size = t->sas_ss_size;
|
|
oss->ss_flags = sas_ss_flags(sp) |
|
|
(current->sas_ss_flags & SS_FLAG_BITS);
|
|
}
|
|
|
|
if (ss) {
|
|
void __user *ss_sp = ss->ss_sp;
|
|
size_t ss_size = ss->ss_size;
|
|
unsigned ss_flags = ss->ss_flags;
|
|
int ss_mode;
|
|
|
|
if (unlikely(on_sig_stack(sp)))
|
|
return -EPERM;
|
|
|
|
ss_mode = ss_flags & ~SS_FLAG_BITS;
|
|
if (unlikely(ss_mode != SS_DISABLE && ss_mode != SS_ONSTACK &&
|
|
ss_mode != 0))
|
|
return -EINVAL;
|
|
|
|
if (ss_mode == SS_DISABLE) {
|
|
ss_size = 0;
|
|
ss_sp = NULL;
|
|
} else {
|
|
if (unlikely(ss_size < min_ss_size))
|
|
return -ENOMEM;
|
|
}
|
|
|
|
t->sas_ss_sp = (unsigned long) ss_sp;
|
|
t->sas_ss_size = ss_size;
|
|
t->sas_ss_flags = ss_flags;
|
|
}
|
|
return 0;
|
|
}
|
|
|
|
SYSCALL_DEFINE2(sigaltstack,const stack_t __user *,uss, stack_t __user *,uoss)
|
|
{
|
|
stack_t new, old;
|
|
int err;
|
|
if (uss && copy_from_user(&new, uss, sizeof(stack_t)))
|
|
return -EFAULT;
|
|
err = do_sigaltstack(uss ? &new : NULL, uoss ? &old : NULL,
|
|
current_user_stack_pointer(),
|
|
MINSIGSTKSZ);
|
|
if (!err && uoss && copy_to_user(uoss, &old, sizeof(stack_t)))
|
|
err = -EFAULT;
|
|
return err;
|
|
}
|
|
|
|
int restore_altstack(const stack_t __user *uss)
|
|
{
|
|
stack_t new;
|
|
if (copy_from_user(&new, uss, sizeof(stack_t)))
|
|
return -EFAULT;
|
|
(void)do_sigaltstack(&new, NULL, current_user_stack_pointer(),
|
|
MINSIGSTKSZ);
|
|
/* squash all but EFAULT for now */
|
|
return 0;
|
|
}
|
|
|
|
int __save_altstack(stack_t __user *uss, unsigned long sp)
|
|
{
|
|
struct task_struct *t = current;
|
|
int err = __put_user((void __user *)t->sas_ss_sp, &uss->ss_sp) |
|
|
__put_user(t->sas_ss_flags, &uss->ss_flags) |
|
|
__put_user(t->sas_ss_size, &uss->ss_size);
|
|
if (err)
|
|
return err;
|
|
if (t->sas_ss_flags & SS_AUTODISARM)
|
|
sas_ss_reset(t);
|
|
return 0;
|
|
}
|
|
|
|
#ifdef CONFIG_COMPAT
|
|
static int do_compat_sigaltstack(const compat_stack_t __user *uss_ptr,
|
|
compat_stack_t __user *uoss_ptr)
|
|
{
|
|
stack_t uss, uoss;
|
|
int ret;
|
|
|
|
if (uss_ptr) {
|
|
compat_stack_t uss32;
|
|
if (copy_from_user(&uss32, uss_ptr, sizeof(compat_stack_t)))
|
|
return -EFAULT;
|
|
uss.ss_sp = compat_ptr(uss32.ss_sp);
|
|
uss.ss_flags = uss32.ss_flags;
|
|
uss.ss_size = uss32.ss_size;
|
|
}
|
|
ret = do_sigaltstack(uss_ptr ? &uss : NULL, &uoss,
|
|
compat_user_stack_pointer(),
|
|
COMPAT_MINSIGSTKSZ);
|
|
if (ret >= 0 && uoss_ptr) {
|
|
compat_stack_t old;
|
|
memset(&old, 0, sizeof(old));
|
|
old.ss_sp = ptr_to_compat(uoss.ss_sp);
|
|
old.ss_flags = uoss.ss_flags;
|
|
old.ss_size = uoss.ss_size;
|
|
if (copy_to_user(uoss_ptr, &old, sizeof(compat_stack_t)))
|
|
ret = -EFAULT;
|
|
}
|
|
return ret;
|
|
}
|
|
|
|
COMPAT_SYSCALL_DEFINE2(sigaltstack,
|
|
const compat_stack_t __user *, uss_ptr,
|
|
compat_stack_t __user *, uoss_ptr)
|
|
{
|
|
return do_compat_sigaltstack(uss_ptr, uoss_ptr);
|
|
}
|
|
|
|
int compat_restore_altstack(const compat_stack_t __user *uss)
|
|
{
|
|
int err = do_compat_sigaltstack(uss, NULL);
|
|
/* squash all but -EFAULT for now */
|
|
return err == -EFAULT ? err : 0;
|
|
}
|
|
|
|
int __compat_save_altstack(compat_stack_t __user *uss, unsigned long sp)
|
|
{
|
|
int err;
|
|
struct task_struct *t = current;
|
|
err = __put_user(ptr_to_compat((void __user *)t->sas_ss_sp),
|
|
&uss->ss_sp) |
|
|
__put_user(t->sas_ss_flags, &uss->ss_flags) |
|
|
__put_user(t->sas_ss_size, &uss->ss_size);
|
|
if (err)
|
|
return err;
|
|
if (t->sas_ss_flags & SS_AUTODISARM)
|
|
sas_ss_reset(t);
|
|
return 0;
|
|
}
|
|
#endif
|
|
|
|
#ifdef __ARCH_WANT_SYS_SIGPENDING
|
|
|
|
/**
|
|
* sys_sigpending - examine pending signals
|
|
* @uset: where mask of pending signal is returned
|
|
*/
|
|
SYSCALL_DEFINE1(sigpending, old_sigset_t __user *, uset)
|
|
{
|
|
sigset_t set;
|
|
|
|
if (sizeof(old_sigset_t) > sizeof(*uset))
|
|
return -EINVAL;
|
|
|
|
do_sigpending(&set);
|
|
|
|
if (copy_to_user(uset, &set, sizeof(old_sigset_t)))
|
|
return -EFAULT;
|
|
|
|
return 0;
|
|
}
|
|
|
|
#ifdef CONFIG_COMPAT
|
|
COMPAT_SYSCALL_DEFINE1(sigpending, compat_old_sigset_t __user *, set32)
|
|
{
|
|
sigset_t set;
|
|
|
|
do_sigpending(&set);
|
|
|
|
return put_user(set.sig[0], set32);
|
|
}
|
|
#endif
|
|
|
|
#endif
|
|
|
|
#ifdef __ARCH_WANT_SYS_SIGPROCMASK
|
|
/**
|
|
* sys_sigprocmask - examine and change blocked signals
|
|
* @how: whether to add, remove, or set signals
|
|
* @nset: signals to add or remove (if non-null)
|
|
* @oset: previous value of signal mask if non-null
|
|
*
|
|
* Some platforms have their own version with special arguments;
|
|
* others support only sys_rt_sigprocmask.
|
|
*/
|
|
|
|
SYSCALL_DEFINE3(sigprocmask, int, how, old_sigset_t __user *, nset,
|
|
old_sigset_t __user *, oset)
|
|
{
|
|
old_sigset_t old_set, new_set;
|
|
sigset_t new_blocked;
|
|
|
|
old_set = current->blocked.sig[0];
|
|
|
|
if (nset) {
|
|
if (copy_from_user(&new_set, nset, sizeof(*nset)))
|
|
return -EFAULT;
|
|
|
|
new_blocked = current->blocked;
|
|
|
|
switch (how) {
|
|
case SIG_BLOCK:
|
|
sigaddsetmask(&new_blocked, new_set);
|
|
break;
|
|
case SIG_UNBLOCK:
|
|
sigdelsetmask(&new_blocked, new_set);
|
|
break;
|
|
case SIG_SETMASK:
|
|
new_blocked.sig[0] = new_set;
|
|
break;
|
|
default:
|
|
return -EINVAL;
|
|
}
|
|
|
|
set_current_blocked(&new_blocked);
|
|
}
|
|
|
|
if (oset) {
|
|
if (copy_to_user(oset, &old_set, sizeof(*oset)))
|
|
return -EFAULT;
|
|
}
|
|
|
|
return 0;
|
|
}
|
|
#endif /* __ARCH_WANT_SYS_SIGPROCMASK */
|
|
|
|
#ifndef CONFIG_ODD_RT_SIGACTION
|
|
/**
|
|
* sys_rt_sigaction - alter an action taken by a process
|
|
* @sig: signal to be sent
|
|
* @act: new sigaction
|
|
* @oact: used to save the previous sigaction
|
|
* @sigsetsize: size of sigset_t type
|
|
*/
|
|
SYSCALL_DEFINE4(rt_sigaction, int, sig,
|
|
const struct sigaction __user *, act,
|
|
struct sigaction __user *, oact,
|
|
size_t, sigsetsize)
|
|
{
|
|
struct k_sigaction new_sa, old_sa;
|
|
int ret;
|
|
|
|
/* XXX: Don't preclude handling different sized sigset_t's. */
|
|
if (sigsetsize != sizeof(sigset_t))
|
|
return -EINVAL;
|
|
|
|
if (act && copy_from_user(&new_sa.sa, act, sizeof(new_sa.sa)))
|
|
return -EFAULT;
|
|
|
|
ret = do_sigaction(sig, act ? &new_sa : NULL, oact ? &old_sa : NULL);
|
|
if (ret)
|
|
return ret;
|
|
|
|
if (oact && copy_to_user(oact, &old_sa.sa, sizeof(old_sa.sa)))
|
|
return -EFAULT;
|
|
|
|
return 0;
|
|
}
|
|
#ifdef CONFIG_COMPAT
|
|
COMPAT_SYSCALL_DEFINE4(rt_sigaction, int, sig,
|
|
const struct compat_sigaction __user *, act,
|
|
struct compat_sigaction __user *, oact,
|
|
compat_size_t, sigsetsize)
|
|
{
|
|
struct k_sigaction new_ka, old_ka;
|
|
#ifdef __ARCH_HAS_SA_RESTORER
|
|
compat_uptr_t restorer;
|
|
#endif
|
|
int ret;
|
|
|
|
/* XXX: Don't preclude handling different sized sigset_t's. */
|
|
if (sigsetsize != sizeof(compat_sigset_t))
|
|
return -EINVAL;
|
|
|
|
if (act) {
|
|
compat_uptr_t handler;
|
|
ret = get_user(handler, &act->sa_handler);
|
|
new_ka.sa.sa_handler = compat_ptr(handler);
|
|
#ifdef __ARCH_HAS_SA_RESTORER
|
|
ret |= get_user(restorer, &act->sa_restorer);
|
|
new_ka.sa.sa_restorer = compat_ptr(restorer);
|
|
#endif
|
|
ret |= get_compat_sigset(&new_ka.sa.sa_mask, &act->sa_mask);
|
|
ret |= get_user(new_ka.sa.sa_flags, &act->sa_flags);
|
|
if (ret)
|
|
return -EFAULT;
|
|
}
|
|
|
|
ret = do_sigaction(sig, act ? &new_ka : NULL, oact ? &old_ka : NULL);
|
|
if (!ret && oact) {
|
|
ret = put_user(ptr_to_compat(old_ka.sa.sa_handler),
|
|
&oact->sa_handler);
|
|
ret |= put_compat_sigset(&oact->sa_mask, &old_ka.sa.sa_mask,
|
|
sizeof(oact->sa_mask));
|
|
ret |= put_user(old_ka.sa.sa_flags, &oact->sa_flags);
|
|
#ifdef __ARCH_HAS_SA_RESTORER
|
|
ret |= put_user(ptr_to_compat(old_ka.sa.sa_restorer),
|
|
&oact->sa_restorer);
|
|
#endif
|
|
}
|
|
return ret;
|
|
}
|
|
#endif
|
|
#endif /* !CONFIG_ODD_RT_SIGACTION */
|
|
|
|
#ifdef CONFIG_OLD_SIGACTION
|
|
SYSCALL_DEFINE3(sigaction, int, sig,
|
|
const struct old_sigaction __user *, act,
|
|
struct old_sigaction __user *, oact)
|
|
{
|
|
struct k_sigaction new_ka, old_ka;
|
|
int ret;
|
|
|
|
if (act) {
|
|
old_sigset_t mask;
|
|
if (!access_ok(act, sizeof(*act)) ||
|
|
__get_user(new_ka.sa.sa_handler, &act->sa_handler) ||
|
|
__get_user(new_ka.sa.sa_restorer, &act->sa_restorer) ||
|
|
__get_user(new_ka.sa.sa_flags, &act->sa_flags) ||
|
|
__get_user(mask, &act->sa_mask))
|
|
return -EFAULT;
|
|
#ifdef __ARCH_HAS_KA_RESTORER
|
|
new_ka.ka_restorer = NULL;
|
|
#endif
|
|
siginitset(&new_ka.sa.sa_mask, mask);
|
|
}
|
|
|
|
ret = do_sigaction(sig, act ? &new_ka : NULL, oact ? &old_ka : NULL);
|
|
|
|
if (!ret && oact) {
|
|
if (!access_ok(oact, sizeof(*oact)) ||
|
|
__put_user(old_ka.sa.sa_handler, &oact->sa_handler) ||
|
|
__put_user(old_ka.sa.sa_restorer, &oact->sa_restorer) ||
|
|
__put_user(old_ka.sa.sa_flags, &oact->sa_flags) ||
|
|
__put_user(old_ka.sa.sa_mask.sig[0], &oact->sa_mask))
|
|
return -EFAULT;
|
|
}
|
|
|
|
return ret;
|
|
}
|
|
#endif
|
|
#ifdef CONFIG_COMPAT_OLD_SIGACTION
|
|
COMPAT_SYSCALL_DEFINE3(sigaction, int, sig,
|
|
const struct compat_old_sigaction __user *, act,
|
|
struct compat_old_sigaction __user *, oact)
|
|
{
|
|
struct k_sigaction new_ka, old_ka;
|
|
int ret;
|
|
compat_old_sigset_t mask;
|
|
compat_uptr_t handler, restorer;
|
|
|
|
if (act) {
|
|
if (!access_ok(act, sizeof(*act)) ||
|
|
__get_user(handler, &act->sa_handler) ||
|
|
__get_user(restorer, &act->sa_restorer) ||
|
|
__get_user(new_ka.sa.sa_flags, &act->sa_flags) ||
|
|
__get_user(mask, &act->sa_mask))
|
|
return -EFAULT;
|
|
|
|
#ifdef __ARCH_HAS_KA_RESTORER
|
|
new_ka.ka_restorer = NULL;
|
|
#endif
|
|
new_ka.sa.sa_handler = compat_ptr(handler);
|
|
new_ka.sa.sa_restorer = compat_ptr(restorer);
|
|
siginitset(&new_ka.sa.sa_mask, mask);
|
|
}
|
|
|
|
ret = do_sigaction(sig, act ? &new_ka : NULL, oact ? &old_ka : NULL);
|
|
|
|
if (!ret && oact) {
|
|
if (!access_ok(oact, sizeof(*oact)) ||
|
|
__put_user(ptr_to_compat(old_ka.sa.sa_handler),
|
|
&oact->sa_handler) ||
|
|
__put_user(ptr_to_compat(old_ka.sa.sa_restorer),
|
|
&oact->sa_restorer) ||
|
|
__put_user(old_ka.sa.sa_flags, &oact->sa_flags) ||
|
|
__put_user(old_ka.sa.sa_mask.sig[0], &oact->sa_mask))
|
|
return -EFAULT;
|
|
}
|
|
return ret;
|
|
}
|
|
#endif
|
|
|
|
#ifdef CONFIG_SGETMASK_SYSCALL
|
|
|
|
/*
|
|
* For backwards compatibility. Functionality superseded by sigprocmask.
|
|
*/
|
|
SYSCALL_DEFINE0(sgetmask)
|
|
{
|
|
/* SMP safe */
|
|
return current->blocked.sig[0];
|
|
}
|
|
|
|
SYSCALL_DEFINE1(ssetmask, int, newmask)
|
|
{
|
|
int old = current->blocked.sig[0];
|
|
sigset_t newset;
|
|
|
|
siginitset(&newset, newmask);
|
|
set_current_blocked(&newset);
|
|
|
|
return old;
|
|
}
|
|
#endif /* CONFIG_SGETMASK_SYSCALL */
|
|
|
|
#ifdef __ARCH_WANT_SYS_SIGNAL
|
|
/*
|
|
* For backwards compatibility. Functionality superseded by sigaction.
|
|
*/
|
|
SYSCALL_DEFINE2(signal, int, sig, __sighandler_t, handler)
|
|
{
|
|
struct k_sigaction new_sa, old_sa;
|
|
int ret;
|
|
|
|
new_sa.sa.sa_handler = handler;
|
|
new_sa.sa.sa_flags = SA_ONESHOT | SA_NOMASK;
|
|
sigemptyset(&new_sa.sa.sa_mask);
|
|
|
|
ret = do_sigaction(sig, &new_sa, &old_sa);
|
|
|
|
return ret ? ret : (unsigned long)old_sa.sa.sa_handler;
|
|
}
|
|
#endif /* __ARCH_WANT_SYS_SIGNAL */
|
|
|
|
#ifdef __ARCH_WANT_SYS_PAUSE
|
|
|
|
SYSCALL_DEFINE0(pause)
|
|
{
|
|
while (!signal_pending(current)) {
|
|
__set_current_state(TASK_INTERRUPTIBLE);
|
|
schedule();
|
|
}
|
|
return -ERESTARTNOHAND;
|
|
}
|
|
|
|
#endif
|
|
|
|
static int sigsuspend(sigset_t *set)
|
|
{
|
|
current->saved_sigmask = current->blocked;
|
|
set_current_blocked(set);
|
|
|
|
while (!signal_pending(current)) {
|
|
__set_current_state(TASK_INTERRUPTIBLE);
|
|
schedule();
|
|
}
|
|
set_restore_sigmask();
|
|
return -ERESTARTNOHAND;
|
|
}
|
|
|
|
/**
|
|
* sys_rt_sigsuspend - replace the signal mask for a value with the
|
|
* @unewset value until a signal is received
|
|
* @unewset: new signal mask value
|
|
* @sigsetsize: size of sigset_t type
|
|
*/
|
|
SYSCALL_DEFINE2(rt_sigsuspend, sigset_t __user *, unewset, size_t, sigsetsize)
|
|
{
|
|
sigset_t newset;
|
|
|
|
/* XXX: Don't preclude handling different sized sigset_t's. */
|
|
if (sigsetsize != sizeof(sigset_t))
|
|
return -EINVAL;
|
|
|
|
if (copy_from_user(&newset, unewset, sizeof(newset)))
|
|
return -EFAULT;
|
|
return sigsuspend(&newset);
|
|
}
|
|
|
|
#ifdef CONFIG_COMPAT
|
|
COMPAT_SYSCALL_DEFINE2(rt_sigsuspend, compat_sigset_t __user *, unewset, compat_size_t, sigsetsize)
|
|
{
|
|
sigset_t newset;
|
|
|
|
/* XXX: Don't preclude handling different sized sigset_t's. */
|
|
if (sigsetsize != sizeof(sigset_t))
|
|
return -EINVAL;
|
|
|
|
if (get_compat_sigset(&newset, unewset))
|
|
return -EFAULT;
|
|
return sigsuspend(&newset);
|
|
}
|
|
#endif
|
|
|
|
#ifdef CONFIG_OLD_SIGSUSPEND
|
|
SYSCALL_DEFINE1(sigsuspend, old_sigset_t, mask)
|
|
{
|
|
sigset_t blocked;
|
|
siginitset(&blocked, mask);
|
|
return sigsuspend(&blocked);
|
|
}
|
|
#endif
|
|
#ifdef CONFIG_OLD_SIGSUSPEND3
|
|
SYSCALL_DEFINE3(sigsuspend, int, unused1, int, unused2, old_sigset_t, mask)
|
|
{
|
|
sigset_t blocked;
|
|
siginitset(&blocked, mask);
|
|
return sigsuspend(&blocked);
|
|
}
|
|
#endif
|
|
|
|
__weak const char *arch_vma_name(struct vm_area_struct *vma)
|
|
{
|
|
return NULL;
|
|
}
|
|
|
|
static inline void siginfo_buildtime_checks(void)
|
|
{
|
|
BUILD_BUG_ON(sizeof(struct siginfo) != SI_MAX_SIZE);
|
|
|
|
/* Verify the offsets in the two siginfos match */
|
|
#define CHECK_OFFSET(field) \
|
|
BUILD_BUG_ON(offsetof(siginfo_t, field) != offsetof(kernel_siginfo_t, field))
|
|
|
|
/* kill */
|
|
CHECK_OFFSET(si_pid);
|
|
CHECK_OFFSET(si_uid);
|
|
|
|
/* timer */
|
|
CHECK_OFFSET(si_tid);
|
|
CHECK_OFFSET(si_overrun);
|
|
CHECK_OFFSET(si_value);
|
|
|
|
/* rt */
|
|
CHECK_OFFSET(si_pid);
|
|
CHECK_OFFSET(si_uid);
|
|
CHECK_OFFSET(si_value);
|
|
|
|
/* sigchld */
|
|
CHECK_OFFSET(si_pid);
|
|
CHECK_OFFSET(si_uid);
|
|
CHECK_OFFSET(si_status);
|
|
CHECK_OFFSET(si_utime);
|
|
CHECK_OFFSET(si_stime);
|
|
|
|
/* sigfault */
|
|
CHECK_OFFSET(si_addr);
|
|
CHECK_OFFSET(si_addr_lsb);
|
|
CHECK_OFFSET(si_lower);
|
|
CHECK_OFFSET(si_upper);
|
|
CHECK_OFFSET(si_pkey);
|
|
|
|
/* sigpoll */
|
|
CHECK_OFFSET(si_band);
|
|
CHECK_OFFSET(si_fd);
|
|
|
|
/* sigsys */
|
|
CHECK_OFFSET(si_call_addr);
|
|
CHECK_OFFSET(si_syscall);
|
|
CHECK_OFFSET(si_arch);
|
|
#undef CHECK_OFFSET
|
|
|
|
/* usb asyncio */
|
|
BUILD_BUG_ON(offsetof(struct siginfo, si_pid) !=
|
|
offsetof(struct siginfo, si_addr));
|
|
if (sizeof(int) == sizeof(void __user *)) {
|
|
BUILD_BUG_ON(sizeof_field(struct siginfo, si_pid) !=
|
|
sizeof(void __user *));
|
|
} else {
|
|
BUILD_BUG_ON((sizeof_field(struct siginfo, si_pid) +
|
|
sizeof_field(struct siginfo, si_uid)) !=
|
|
sizeof(void __user *));
|
|
BUILD_BUG_ON(offsetofend(struct siginfo, si_pid) !=
|
|
offsetof(struct siginfo, si_uid));
|
|
}
|
|
#ifdef CONFIG_COMPAT
|
|
BUILD_BUG_ON(offsetof(struct compat_siginfo, si_pid) !=
|
|
offsetof(struct compat_siginfo, si_addr));
|
|
BUILD_BUG_ON(sizeof_field(struct compat_siginfo, si_pid) !=
|
|
sizeof(compat_uptr_t));
|
|
BUILD_BUG_ON(sizeof_field(struct compat_siginfo, si_pid) !=
|
|
sizeof_field(struct siginfo, si_pid));
|
|
#endif
|
|
}
|
|
|
|
void __init signals_init(void)
|
|
{
|
|
siginfo_buildtime_checks();
|
|
|
|
sigqueue_cachep = KMEM_CACHE(sigqueue, SLAB_PANIC);
|
|
}
|
|
|
|
#ifdef CONFIG_KGDB_KDB
|
|
#include <linux/kdb.h>
|
|
/*
|
|
* kdb_send_sig - Allows kdb to send signals without exposing
|
|
* signal internals. This function checks if the required locks are
|
|
* available before calling the main signal code, to avoid kdb
|
|
* deadlocks.
|
|
*/
|
|
void kdb_send_sig(struct task_struct *t, int sig)
|
|
{
|
|
static struct task_struct *kdb_prev_t;
|
|
int new_t, ret;
|
|
if (!spin_trylock(&t->sighand->siglock)) {
|
|
kdb_printf("Can't do kill command now.\n"
|
|
"The sigmask lock is held somewhere else in "
|
|
"kernel, try again later\n");
|
|
return;
|
|
}
|
|
new_t = kdb_prev_t != t;
|
|
kdb_prev_t = t;
|
|
if (t->state != TASK_RUNNING && new_t) {
|
|
spin_unlock(&t->sighand->siglock);
|
|
kdb_printf("Process is not RUNNING, sending a signal from "
|
|
"kdb risks deadlock\n"
|
|
"on the run queue locks. "
|
|
"The signal has _not_ been sent.\n"
|
|
"Reissue the kill command if you want to risk "
|
|
"the deadlock.\n");
|
|
return;
|
|
}
|
|
ret = send_signal(sig, SEND_SIG_PRIV, t, PIDTYPE_PID);
|
|
spin_unlock(&t->sighand->siglock);
|
|
if (ret)
|
|
kdb_printf("Fail to deliver Signal %d to process %d.\n",
|
|
sig, t->pid);
|
|
else
|
|
kdb_printf("Signal %d is sent to process %d.\n", sig, t->pid);
|
|
}
|
|
#endif /* CONFIG_KGDB_KDB */
|