Patch "xen-netback: remove skb in xen_netbk_alloc_page" has been added to the 3.9-stable tree

2013-06-04 Thread gregkh
This is a note to let you know that I've just added the patch titled xen-netback: remove skb in xen_netbk_alloc_page to the 3.9-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the patch is: xen-netb

Patch "drm/nvc0/ce: disable ce1 on a number of chipsets" has been added to the 3.9-stable tree

2013-06-04 Thread gregkh
This is a note to let you know that I've just added the patch titled drm/nvc0/ce: disable ce1 on a number of chipsets to the 3.9-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the patch is: drm-nvc

Patch "ACPI / PM: Allow device power states to be used for CONFIG_PM unset" has been added to the 3.9-stable tree

2013-06-04 Thread gregkh
This is a note to let you know that I've just added the patch titled ACPI / PM: Allow device power states to be used for CONFIG_PM unset to the 3.9-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the pat

Patch "ALSA: usb-audio: avoid integer overflow in create_fixed_stream_quirk()" has been added to the 3.0-stable tree

2013-06-04 Thread gregkh
This is a note to let you know that I've just added the patch titled ALSA: usb-audio: avoid integer overflow in create_fixed_stream_quirk() to the 3.0-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the

Patch "jfs: fix a couple races" has been added to the 3.9-stable tree

2013-06-04 Thread gregkh
This is a note to let you know that I've just added the patch titled jfs: fix a couple races to the 3.9-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the patch is: jfs-fix-a-couple-races.patch and

Patch "iommu/amd: Re-enable IOMMU event log interrupt after handling." has been added to the 3.9-stable tree

2013-06-04 Thread gregkh
This is a note to let you know that I've just added the patch titled iommu/amd: Re-enable IOMMU event log interrupt after handling. to the 3.9-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the patch is

Patch "ACPI / video: Add "Asus UL30A" to ACPI video detect blacklist" has been added to the 3.9-stable tree

2013-06-04 Thread gregkh
This is a note to let you know that I've just added the patch titled ACPI / video: Add "Asus UL30A" to ACPI video detect blacklist to the 3.9-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the patch is:

Patch "ALSA: usb-audio: fix possible hang and overflow in parse_uac2_sample_rate_range()" has been added to the 3.0-stable tree

2013-06-04 Thread gregkh
This is a note to let you know that I've just added the patch titled ALSA: usb-audio: fix possible hang and overflow in parse_uac2_sample_rate_range() to the 3.0-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The file

Patch "iommu/amd: Workaround for ERBT1312" has been added to the 3.9-stable tree

2013-06-04 Thread gregkh
This is a note to let you know that I've just added the patch titled iommu/amd: Workaround for ERBT1312 to the 3.9-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the patch is: iommu-amd-workaround-

Patch "iwlwifi: mvm: fix aggregation drain flow" has been added to the 3.9-stable tree

2013-06-04 Thread gregkh
This is a note to let you know that I've just added the patch titled iwlwifi: mvm: fix aggregation drain flow to the 3.9-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the patch is: iwlwifi-mvm-fix

Patch "jfs: fix a couple races" has been added to the 3.0-stable tree

2013-06-04 Thread gregkh
This is a note to let you know that I've just added the patch titled jfs: fix a couple races to the 3.0-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the patch is: jfs-fix-a-couple-races.patch and

Patch "x86, um: Correct syscall table type attributes breaking gcc 4.8" has been added to the 3.4-stable tree

2013-06-04 Thread gregkh
This is a note to let you know that I've just added the patch titled x86, um: Correct syscall table type attributes breaking gcc 4.8 to the 3.4-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the patch i

Patch "iommu/amd: Re-enable IOMMU event log interrupt after handling." has been added to the 3.4-stable tree

2013-06-04 Thread gregkh
This is a note to let you know that I've just added the patch titled iommu/amd: Re-enable IOMMU event log interrupt after handling. to the 3.4-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the patch is

Patch "jfs: fix a couple races" has been added to the 3.4-stable tree

2013-06-04 Thread gregkh
This is a note to let you know that I've just added the patch titled jfs: fix a couple races to the 3.4-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the patch is: jfs-fix-a-couple-races.patch and

Patch "iommu/amd: Workaround for ERBT1312" has been added to the 3.4-stable tree

2013-06-04 Thread gregkh
This is a note to let you know that I've just added the patch titled iommu/amd: Workaround for ERBT1312 to the 3.4-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the patch is: iommu-amd-workaround-

Patch "xen-netback: remove skb in xen_netbk_alloc_page" has been added to the 3.4-stable tree

2013-06-04 Thread gregkh
This is a note to let you know that I've just added the patch titled xen-netback: remove skb in xen_netbk_alloc_page to the 3.4-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the patch is: xen-netb

Re: [stable request 3.4] xen-pciback: rate limit error messages from xen_pcibk_enable_msi{,x}()

2013-06-04 Thread Greg KH
On Tue, Jun 04, 2013 at 02:02:50PM -0700, Vinson Lee wrote: > Hi, > > This patch, which addresses CVE-2013-0231 and originally backported to > 3.7.10, seems to have been missed for the 3.4 kernel. This patch is > already in 3.7.5.z and 3.2.y. > > commit 51ac8893a7a51b196501164e645583bf78138699 >

Re: Please add to stable: module: don't unlink the module until we've removed all exposure.

2013-06-04 Thread Greg KH
On Mon, Jun 03, 2013 at 10:17:17AM -0400, Joe Lawrence wrote: > [Cc: stable@vger.kernel.org] > > Third time is a charm? The stable address was incorrect from the first > msg in this thread, but the relevant bits remain quoted below... Really? I'm totally confused... > On Mon, 3 Jun 2013, Joe

Re: FAILED: patch "[PATCH] iommu/amd: Workaround for ERBT1312" failed to apply to 3.9-stable tree

2013-06-04 Thread Greg KH
On Mon, May 27, 2013 at 11:48:11AM +0800, Lingzhu Xiang wrote: > On 05/09/2013 06:26 AM, gre...@linuxfoundation.org wrote: > > > >The patch below does not apply to the 3.9-stable tree. > >If someone wants it applied there, or to any other stable or longterm > >tree, then please email the backport,

Re: xen-netback stable backports request (regression fixes)

2013-06-04 Thread Greg KH
On Tue, May 28, 2013 at 10:47:45AM +0100, Ian Campbell wrote: > Hi Dave, stable folks, > > The following set of patches fix a xen netback regression caused by the > fixes for CVE-2013-0216 / CVE-2013-0217 / XSA-39 (the original change > was several patches starting at 48856286b64e), we'd like to s

Patch "reiserfs: fix spurious multiple-fill in reiserfs_readdir_dentry" has been added to the 3.9-stable tree

2013-06-04 Thread gregkh
This is a note to let you know that I've just added the patch titled reiserfs: fix spurious multiple-fill in reiserfs_readdir_dentry to the 3.9-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the patch i

Patch "powerpc/pseries: Always enable CONFIG_HOTPLUG_CPU on PSERIES SMP" has been added to the 3.9-stable tree

2013-06-04 Thread gregkh
This is a note to let you know that I've just added the patch titled powerpc/pseries: Always enable CONFIG_HOTPLUG_CPU on PSERIES SMP to the 3.9-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the patch

Patch "reiserfs: fix problems with chowning setuid file w/ xattrs" has been added to the 3.9-stable tree

2013-06-04 Thread gregkh
This is a note to let you know that I've just added the patch titled reiserfs: fix problems with chowning setuid file w/ xattrs to the 3.9-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the patch is:

Re: Please add to stable: module: don't unlink the module until we've removed all exposure.

2013-06-04 Thread Rusty Russell
Ben Greear writes: > On 06/04/2013 09:53 AM, Ben Greear wrote: >> On 06/04/2013 07:07 AM, Joe Lawrence wrote: >>> On Tue, 04 Jun 2013 15:26:28 +0930 >>> Rusty Russell wrote: >>> Do you have a backtrace of the 3.9.4 crash? You can add "CFLAGS_module.o = -O0" to get a clearer backtrace i

Patch "xen/events: Handle VIRQ_TIMER before any other hardirq in event loop." has been added to the 3.4-stable tree

2013-06-04 Thread gregkh
This is a note to let you know that I've just added the patch titled xen/events: Handle VIRQ_TIMER before any other hardirq in event loop. to the 3.4-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the p

Patch "reiserfs: fix deadlock with nfs racing on create/lookup" has been added to the 3.9-stable tree

2013-06-04 Thread gregkh
This is a note to let you know that I've just added the patch titled reiserfs: fix deadlock with nfs racing on create/lookup to the 3.9-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the patch is:

Re: Please add to stable: module: don't unlink the module until we've removed all exposure.

2013-06-04 Thread Rusty Russell
Joe Lawrence writes: > On Tue, 04 Jun 2013 15:26:28 +0930 > Rusty Russell wrote: > >> Do you have a backtrace of the 3.9.4 crash? You can add "CFLAGS_module.o >> = -O0" to get a clearer backtrace if you want... > > Hi Rusty, > > See my 3.9 stack traces below, which may or may not be what Ben had

Patch "xen/events: Handle VIRQ_TIMER before any other hardirq in event loop." has been added to the 3.0-stable tree

2013-06-04 Thread gregkh
This is a note to let you know that I've just added the patch titled xen/events: Handle VIRQ_TIMER before any other hardirq in event loop. to the 3.0-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the p

Re: Please backport bee980d9e9642e96351fa3ca9077b853ecf62f57 (xen/events: Handle VIRQ_TIMER before any other hardirq in event loop.) to earlier kernels v3.8...and so on

2013-06-04 Thread Greg KH
On Mon, Jun 03, 2013 at 08:02:32AM -0400, Konrad Rzeszutek Wilk wrote: > Hey Greg, > > I hadn't (by mistake) put the CC: stable@vger.kernel.org on said patch > (Which is in the Linux kernel). > > If possible please back-port said patch to the existing stable trees. > Attached is a version that ap

Patch "KVM: Emulate multibyte NOP" has been added to the 3.9-stable tree

2013-06-04 Thread gregkh
This is a note to let you know that I've just added the patch titled KVM: Emulate multibyte NOP to the 3.9-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the patch is: kvm-emulate-multibyte-nop.pat

Patch "KVM: fix sil/dil/bpl/spl in the mod/rm fields" has been added to the 3.9-stable tree

2013-06-04 Thread gregkh
This is a note to let you know that I've just added the patch titled KVM: fix sil/dil/bpl/spl in the mod/rm fields to the 3.9-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the patch is: kvm-fix-si

Patch "regulator: palmas: Fix "enable_reg" to point to the correct reg for SMPS10" has been added to the 3.9-stable tree

2013-06-04 Thread gregkh
This is a note to let you know that I've just added the patch titled regulator: palmas: Fix "enable_reg" to point to the correct reg for SMPS10 to the 3.9-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of

FAILED: patch "[PATCH] fuse: fix readdirplus Oops in fuse_dentry_revalidate" failed to apply to 3.9-stable tree

2013-06-04 Thread gregkh
The patch below does not apply to the 3.9-stable tree. If someone wants it applied there, or to any other stable or longterm tree, then please email the backport, including the original git commit id to . thanks, greg k-h -- original commit in Linus's tree -- >F

Re: [PATCH] sctp: set association state to established in dupcook_a handler

2013-06-04 Thread Xufeng Zhang
On 06/03/2013 03:52 PM, Xufeng Zhang wrote: 3.4-stable review patch. If anyone has any objections, please let me know. Sorry Greg, David -- I did not fully understand all the details of the stable kernel process earlier. I have since checked the networking stable queue here: http://patchw

[PATCH V2 1/2] ACPI: Add CMOS RTC Operation Region handler support

2013-06-04 Thread Lan Tianyu
On HP Folio 13-2000, the BIOS defines a CMOS RTC Operation Region and the EC's _REG methord accesses that region. Thus an appropriate address space handler must be registered for that region before the EC driver is loaded. Introduce a mechanism for adding CMOS RTC address space handlers. Register

[PATCH V2 2/2] ACPI / EC: Add HP Folio 13 to ec_dmi_table in order to skip DSDT scan

2013-06-04 Thread Lan Tianyu
HP Folio 13's BIOS defines CMOS RTC Operation Region and the EC's _REG method will access that region. To allow the CMOS RTC region handler to be installed before the EC _REG method is first invoked, add ec_skip_dsdt_scan() as HP Folio 13's callback to ec_dmi_table. [rjw: Changelog] References: h

Re: [PATCH] sctp: set association state to established in dupcook_a handler

2013-06-04 Thread Xufeng Zhang
On 06/05/2013 08:13 AM, Ben Hutchings wrote: On Tue, 2013-06-04 at 10:00 +0800, Xufeng Zhang wrote: On 06/03/2013 10:28 PM, Greg KH wrote: On Mon, Jun 03, 2013 at 03:52:58PM +0800, Xufeng Zhang wrote: 3.4-stable review patch. If anyone has any objections, please let me know

Re: [PATCH 1/6] UPSTREAM: regmap: Initialize `map->debugfs' before regcache

2013-06-04 Thread Ben Hutchings
On Mon, 2013-06-03 at 10:07 -0700, Stephen Warren wrote: > Stephen Warren wrote at Monday, June 03, 2013 11:03 AM: > > From: Dimitris Papastamos > > > > In the rbtree code we are exposing statistics relating to the > > number of nodes/registers of the rbtree cache for each of the > > devices. En

Re: [PATCH net] tg3: Add read dma workaround for 5720

2013-06-04 Thread David Miller
From: "Nithin Nayak Sujir" Date: Mon, 3 Jun 2013 12:19:34 -0700 > Commit 091f0ea30074bc43f9250961b3247af713024bc6 "tg3: Add New 5719 Read > DMA workaround" added a workaround for TX DMA stall on the 5719. This > workaround needs to be applied to the 5720 as well. > > Cc: stable@vger.kernel.org >

Re: [PATCH] sctp: set association state to established in dupcook_a handler

2013-06-04 Thread Ben Hutchings
On Tue, 2013-06-04 at 10:00 +0800, Xufeng Zhang wrote: > On 06/03/2013 10:28 PM, Greg KH wrote: > > On Mon, Jun 03, 2013 at 03:52:58PM +0800, Xufeng Zhang wrote: > > > >> 3.4-stable review patch. If anyone has any objections, please let me know. > >> > > Really? What are you going to do

[ 012/184] usermodehelper: ____call_usermodehelper() doesnt

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- need do_exit() From: Oleg Nesterov commit 5b9bd473e3b8a8c6c4ae99be475e6e9b27568555 upstream Minor cleanup. call_usermodehelper() can simply return, no need to call do_exit() explicitely.

[ 025/184] coredump: prevent double-free on an error path in

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- core dumper From: Denys Vlasenko commit f34f9d186df35e5c39163444c43b4fc6255e39c5 upstream. In !CORE_DUMP_USE_REGSET case, if elf_note_info_init fails to allocate memory for info->fields, it fre

[ 024/184] wake_up_process() should be never used to wakeup a

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- TASK_STOPPED/TRACED task From: Oleg Nesterov wake_up_process() should be never used to wakeup a TASK_STOPPED/TRACED task CVE-2013-0871 BugLink: http://bugs.launchpad.net/bugs/1129192 wake_up_

[ 006/184] timer: Dont reinitialize the cpu base lock during

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- CPU_UP_PREPARE From: Tirupathi Reddy commit 42a5cf46cd56f46267d2a9fcf2655f4078cd3042 upstream. An inactive timer's base can refer to a offline cpu's base. In the current code, cpu_base's lock

[ 034/184] tracing: Fix double free when function profile init

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- failed From: Namhyung Kim commit 83e03b3fe4daffdebbb42151d5410d730ae50bd1 upstream. On the failure path, stat->start and stat->pages will refer same page. So it'll attempt to free the same page

[ 002/184] Revert "block: improve queue_should_plug() by

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- looking at IO depths" From: Jens Axboe This reverts commit fb1e75389bd06fd5987e9cda1b4e0305c782f854. "Benjamin S." reports that the patch in question causes a big drop in sequential throughput

[ 042/184] ALSA: hda - Add a pin-fix for FSC Amilo Pi1505

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- From: Takashi Iwai FSC Amilo Pi 1505 has a buggy BIOS and doesn't set up the HP and speaker pins properly. Add the pinfix entry for that. Reference: Novell bnc#557403 https://bugzilla.novell

[ 022/184] signal: Define __ARCH_HAS_SA_RESTORER so we know

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- whether to clear sa_restorer From: Ben Hutchings Vaguely based on upstream commit 574c4866e33d 'consolidate kernel-side struct sigaction declarations'. flush_signal_handlers() needs to know whe

[ 017/184] signal: always clear sa_restorer on execve

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- From: Kees Cook commit 2ca39528c01a933f6689cd6505ce65bd6d68a530 upstream. When the new signal handlers are set up, the location of sa_restorer is not cleared, leaking a parent process's address

[ 018/184] ptrace: ptrace_resume() shouldnt wake up

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- !TASK_TRACED thread From: Oleg Nesterov ptrace: ptrace_resume() shouldn't wake up !TASK_TRACED thread CVE-2013-0871 BugLink: http://bugs.launchpad.net/bugs/1129192 It is not clear why ptrace_

[ 049/184] x86/xen: dont assume %ds is usable in xen_iret for

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- 32-bit PVOPS. From: Jan Beulich This fixes CVE-2013-0228 / XSA-42 Drew Jones while working on CVE-2013-0190 found that that unprivileged guest user in 32bit PV guest can use to crash the > gue

[ 043/184] ALSA: seq: Fix missing error handling in

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- snd_seq_timer_open() From: Takashi Iwai commit 66efdc71d95887b652a742a5dae51fa834d71465 upstream. snd_seq_timer_open() didn't catch the whole error path but let through if the timer id is a sla

[ 052/184] x86, mm, paravirt: Fix vmalloc_fault oops during

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- lazy MMU updates From: Samu Kallio commit 1160c2779b826c6f5c08e5cc542de58fd1f667d5 upstream. In paravirtualized x86_64 kernels, vmalloc_fault may cause an oops when lazy MMU updates are enabled

[ 003/184] 2.6.32.y: timekeeping: Fix nohz issue with commit

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- 61b76840ddee647c0c223365378c3f394355b7d7 From: John Stultz Commit 61b76840ddee647c0c223365378c3f394355b7d7 ("time: Avoid making adjustments if we haven't accumulated anything") introduced a regr

[ 037/184] mm: Fix PageHead when !CONFIG_PAGEFLAGS_EXTENDED

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- From: Christoffer Dall commit ad4b3fb7ff9940bcdb1e4cd62bd189d10fa636ba upstream. Unfortunately with !CONFIG_PAGEFLAGS_EXTENDED, (!PageHead) is false, and (PageHead) is true, for tail pages. If

[ 014/184] kmod: make __request_module() killable

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- From: Oleg Nesterov commit 1cc684ab75123efe7ff446eb821d44375ba8fa30 upstream As Tetsuo Handa pointed out, request_module() can stress the system while the oom-killed caller sleeps in TASK_UNINTE

[ 041/184] ALSA: hda - More ALC663 fixes and support of

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- compatible chips From: Kailang Yang commit ebb83eeb6469bedda83b4dc6f23ddf93eb32b347 upstream. 1. Add more ASUS NB model. 2. Fixed alc663_m51va_setup M51VA has Digital Mic that NID is 0x12. T

[ 048/184] x86, random: make ARCH_RANDOM prompt if EMBEDDED,

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- not EXPERT From: Romain Francoise Before v2.6.38 CONFIG_EXPERT was known as CONFIG_EMBEDDED but the Kconfig entry was not changed to match when upstream commit 628c6246d47b85f5357298601df2444d7f

[ 055/184] KVM: x86: fix for buffer overflow in handling of

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- MSR_KVM_SYSTEM_TIME (CVE-2013-1796) From: Andy Honig commit c300aa64ddf57d9c5d9c898a64b36877345dd4a9 upstream. If the guest sets the GPA of the time_page so that the request to update the time

[ 010/184] usermodehelper: introduce umh_complete(sub_info)

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- From: Oleg Nesterov commit b3449922502f5a161ee2b5022a33aec8472fbf18 upstream Preparation. Add the new trivial helper, umh_complete(). Currently it simply does complete(sub_info->complete). Si

[ 019/184] ptrace: introduce signal_wake_up_state() and

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- ptrace_signal_wake_up() From: Oleg Nesterov ptrace: introduce signal_wake_up_state() and ptrace_signal_wake_up() CVE-2013-0871 BugLink: http://bugs.launchpad.net/bugs/1129192 Cleanup and prep

[ 050/184] x86/msr: Add capabilities check

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- From: Alan Cox commit c903f0456bc69176912dee6dd25c6a66ee1aed00 upstream At the moment the MSR driver only relies upon file system checks. This means that anything as root with any capability set

[ 044/184] ALSA: ice1712: Initialize card->private_data

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- properly From: Sean Connor commit 69a4cfdd444d1fe5c24d29b3a063964ac165d2cd upstream. Set card->private_data in snd_ice1712_create for fixing NULL dereference in snd_ice1712_remove(). Signed-of

[ 033/184] tracing: Dont call page_to_pfn() if page is NULL

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- From: Wen Congyang commit 85f2a2ef1d0ab99523e0b947a2b723f5650ed6aa upstream. When allocating memory fails, page is NULL. page_to_pfn() will cause the kernel panicked if we don't use sparsemem vm

[ 040/184] mempolicy: fix a race in shared_policy_replace()

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- From: Mel Gorman commit b22d127a39ddd10d93deee3d96e643657ad53a49 upstream. shared_policy_replace() use of sp_alloc() is unsafe. 1) sp_node cannot be dereferenced if sp->lock is not held and 2)

[ 054/184] xen/bootup: allow {read|write}_cr8 pvops call.

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- From: Konrad Rzeszutek Wilk commit 1a7bbda5b1ab0e02622761305a32dc38735b90b2 upstream. We actually do not do anything about it. Just return a default value of zero and if the kernel tries to writ

[ 061/184] PCI/PM: Clean up PME state when removing a device

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- From: "Rafael J. Wysocki" commit 249bfb83cf8ba658955f0245ac3981d941f746ee upstream. Devices are added to pci_pme_list when drivers use pci_enable_wake() or pci_wake_from_d3(), but they aren't re

[ 031/184] cgroup: remove incorrect dget/dput() pair in

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- cgroup_create_dir() From: Tejun Heo commit 175431635ec09b1d1bba04979b006b99e8305a83 upstream. cgroup_create_dir() does weird dancing with dentry refcnt. On success, it gets and then puts it ac

[ 064/184] serial: 8250, increase PASS_LIMIT

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- From: Jiri Slaby With virtual machines like qemu, it's pretty common to see "too much work for irq4" messages nowadays. This happens when a bunch of output is printed on the emulated serial conso

[ 063/184] PARISC: fix user-triggerable panic on parisc

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- From: Al Viro commit 441a179dafc0f99fc8b3a8268eef66958621082e upstream. int sys32_rt_sigprocmask(int how, compat_sigset_t __user *set, compat_sigset_t __user *oset,

[ 004/184] clockevents: Dont allow dummy broadcast timers

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- From: Mark Rutland commit a7dc19b8652c862d5b7c4d2339bd3c428bd29c4a upstream. Currently tick_check_broadcast_device doesn't reject clock_event_devices with CLOCK_EVT_FEAT_DUMMY, and may select th

[ 005/184] posix-cpu-timers: Fix nanosleep task_struct leak

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- From: Stanislaw Gruszka commit e6c42c295e071dd74a66b5a9fcf4f44049888ed8 upstream. The trinity fuzzer triggered a task_struct reference leak via clock_nanosleep with CPU_TIMERs. do_cpu_nanosleep(

[ 057/184] KVM: Fix bounds checking in ioapic indirect register

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- reads (CVE-2013-1798) From: Andy Honig commit a2c118bfab8bc6b8bb213abfc35201e441693d55 upstream. If the guest specifies a IOAPIC_REG_SELECT with an invalid value and follows that with a read of

[ 020/184] ptrace: ensure arch_ptrace/ptrace_request can never

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- race with SIGKILL From: Oleg Nesterov ptrace: ensure arch_ptrace/ptrace_request can never race with SIGKILL CVE-2013-0871 BugLink: http://bugs.launchpad.net/bugs/1129192 putreg() assumes that

[ 051/184] x86/mm: Check if PUD is large when validating a

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- kernel address From: Mel Gorman commit 0ee364eb316348ddf3e0dfcd986f5f13f528f821 upstream. A user reported the following oops when a backup process reads /proc/kcore: BUG: unable to handle ker

[ 067/184] staging: comedi: ni_labpc: correct differential

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- channel sequence for AI commands From: Ian Abbott Commit 4c4bc25d0fa6beaf054c0b4c3b324487f266c820 upstream. Tuomas reported problems getting meaningful output from a Lab-PC+ in differential mo

[ 028/184] genalloc: stop crashing the system when destroying a

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- pool From: Thadeu Lima de Souza Cascardo commit eedce141cd2dad8d0cefc5468ef41898949a7031 upstream. The genalloc code uses the bitmap API from include/linux/bitmap.h and lib/bitmap.c, which is b

[ 059/184] MCE: Fix vm86 handling for 32bit mce handler

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- From: Andi Kleen commit a129a7c84582629741e5fa6f40026efcd7a65bd4 upstream. When running on 32bit the mce handler could misinterpret vm86 mode as ring 0. This can affect whether it does recovery

[ 038/184] mm: bugfix: set current->reclaim_state to NULL while

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- returning from kswapd() From: Takamori Yamaguchi commit b0a8cc58e6b9aaae3045752059e5e6260c0b94bc upstream. In kswapd(), set current->reclaim_state to NULL before returning, as current->reclaim_

[ 013/184] kmod: introduce call_modprobe() helper

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- From: Oleg Nesterov commit 3e63a93b987685f02421e18b2aa452d20553a88b upstream No functional changes. Move the call_usermodehelper code from __request_module() into the new simple helper, call_mo

[ 021/184] kernel/signal.c: stop info leak via the tkill and

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- the tgkill syscalls From: Emese Revfy commit b9e146d8eb3b9ecae5086d373b50fa0c1f3e7f0f upstream. This fixes a kernel memory contents leak via the tkill and tgkill syscalls for compat processes.

[ 035/184] hugetlb: fix resv_map leak in error path

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- From: Dave Hansen commit c50ac050811d6485616a193eb0f37bfbd191cc89 upstream When called for anonymous (non-shared) mappings, hugetlb_reserve_pages() does a resv_map_alloc(). It depends on code i

[ 065/184] drivers/char/ipmi: memcpy, need additional 2 bytes

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- to avoid memory overflow From: Chen Gang commit a5f2b3d6a738e7d4180012fe7b541172f8c8dcea upstream. When calling memcpy, read_data and write_data need additional 2 bytes. write_data: for

[ 076/184] staging: vt6656: [BUG] out of bound array reference

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- in RFbSetPower. From: Malcolm Priestley commit ab1dd9963137a1e122004d5378a581bf16ae9bc8 upstream. Calling RFbSetPower with uCH zero value will cause out of bound array reference. This causes 6

[ 060/184] ACPI / cpuidle: Fix NULL pointer issues when cpuidle

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- is disabled From: Konrad Rzeszutek Wilk commit b88a634a903d9670aa5f2f785aa890628ce0dece upstream. If cpuidle is disabled, that means that: per_cpu(acpi_cpuidle_device, pr->id) is set

[ 039/184] mm: fix invalidate_complete_page2() lock ordering

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- From: Hugh Dickins commit ec4d9f626d5908b6052c2973f37992f1db52e967 upstream. In fuzzing with trinity, lockdep protested "possible irq lock inversion dependency detected" when isolate_lru_page()

[ 075/184] staging: comedi: das08: Correct AO output for

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- das08jr-16-ao From: Ian Abbott commit 61ed59ed09e6ad2b8395178ea5ad5f653bba08e3 upstream. Don't zero out bits 15..12 of the data value in `das08jr_ao_winsn()` as that knobbles the upper three-qu

[ 069/184] staging: comedi: comedi_test: fix race when

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- cancelling command From: Ian Abbott commit c0729eeefdcd76db338f635162bf0739fd2c5f6f upstream. Éric Piel reported a kernel oops in the "comedi_test" module. It was a NULL pointer dereference wi

[ 011/184] usermodehelper: implement UMH_KILLABLE

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- From: Oleg Nesterov commit d0bd587a80960d7ba7e0c8396e154028c9045c54 upstream Implement UMH_KILLABLE, should be used along with UMH_WAIT_EXEC/PROC. The caller must ensure that subprocess_info->pa

[ 068/184] staging: comedi: ni_labpc: set up command4 register

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- *after* command3 From: Ian Abbott Commit 22056e2b46246d97ff0f7c6e21a77b8daa07f02c upstream. Tuomas reported problems getting meaningful output from a Lab-PC+ in differential mode for AI cmds,

[ 047/184] x86: Dont use the EFI reboot method by default

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- From: Matthew Garrett Testing suggests that at least some Lenovos and some Intels will fail to reboot via EFI, attempting to jump to an unmapped physical address. In the long run we could handle

[ 066/184] w1: fix oops when w1_search is called from netlink

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- connector From: Marcin Jurkowski commit 9d1817cab2f030f6af360e961cc69bb1da8ad765 upstream. On Sat, Mar 02, 2013 at 10:45:10AM +0100, Sven Geggus wrote: > This is the bad commit I found doing gi

[ 089/184] r8169: correct settings of rtl8102e.

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- From: Hayes Wang Adjust and remove certain settings of RTL8102E which are for previous chips. Signed-off-by: Hayes Wang Acked-off-by: Francois Romieu (cherry picked from commit d24e9aafe5d5dfd

[ 078/184] scsi: Silence unnecessary warnings about ioctl to

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- partition From: Jan Kara commit 6d9359280753d2955f86d6411047516a9431eb51 upstream. Sometimes, warnings about ioctls to partition happen often enough that they form majority of the warnings in t

[ 083/184] crypto: cryptd - disable softirqs in

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- cryptd_queue_worker to prevent data corruption From: Jussi Kivilinna commit 9efade1b3e981f5064f9db9ca971b4dc7557ae42 upstream. cryptd_queue_worker attempts to prevent simultaneous accesses to c

[ 081/184] SCSI: bnx2i: Fixed NULL ptr deference for 1G bnx2

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- Linux iSCSI offload From: Eddie Wai commit d6532207116307eb7ecbfa7b9e02c53230096a50 upstream. This patch fixes the following kernel panic invoked by uninitialized fields in the chip initializat

[ 077/184] libata: fix Null pointer dereference on disk error

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- From: Xiaotian Feng commit 26cd4d65deba587f3cf2329b6869ce02bcbe68ec upstream. Following oops were observed when disk error happened: [ 4272.896937] sd 0:0:0:0: [sda] Unhandled error code [ 4272

[ 090/184] r8169: remove the obsolete and incorrect AMD

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- workaround From: =?latin1?q?Timo=20Ter=E4s?= [ Upstream commit 5d0feaff230c0abfe4a112e6f09f096ed99e0b2d ] This was introduced in commit 6dccd16 "r8169: merge with version 6.001.00 of Realtek's

[ 088/184] xfrm_user: return error pointer instead of NULL #2

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- From: Mathias Krause commit c25463722509fef0ed630b271576a8c9a70236f3 upstream. When dump_one_policy() returns an error, e.g. because of a too small buffer to dump the whole xfrm policy, xfrm_pol

[ 100/184] Bluetooth: RFCOMM - Fix missing msg_namelen update

2013-06-04 Thread Willy Tarreau
2.6.32-longterm review patch. If anyone has any objections, please let me know. -- in rfcomm_sock_recvmsg() From: Mathias Krause [ Upstream commit e11e0455c0d7d3d62276a0c55d9dfbc16779d691 ] If RFCOMM_DEFER_SETUP is set in the flags, rfcomm_sock_recvmsg() returns early with 0

  1   2   3   4   >