1. Oct 10, 2022
    • Duoming Zhou's avatar
      mISDN: hfcpci: Fix use-after-free bug in hfcpci_softirq · 175302f6
      Duoming Zhou authored
      The function hfcpci_softirq() is a timer handler. If it
      is running, the timer_pending() will return 0 and the
      del_timer_sync() in HFC_cleanup() will not be executed.
      As a result, the use-after-free bug will happen. The
      process is shown below:
      
          (cleanup routine)          |        (timer handler)
      HFC_cleanup()                  | hfcpci_softirq()
       if (timer_pending(&hfc_tl))   |
         del_timer_sync()            |
       ...                           | ...
       pci_unregister_driver(hc)     |
        driver_unregister            |  driver_for_each_device
         bus_remove_driver           |   _hfcpci_softirq
          driver_detach              |   ...
           put_device(dev) //[1]FREE |
                                     |    dev_get_drvdata(dev) //[2]USE
      
      The device is deallocated is position [1] and used in
      position [2].
      
      Fix by removing the "timer_pending" check in HFC_cleanup(),
      which makes sure that the hfcpci_softirq() have finished
      before the resource is deallocated.
      
      Fixes: 009fc857
      
       ("mISDN: fix possible use-after-free in HFC_cleanup()")
      Signed-off-by: default avatarDuoming Zhou <duoming@zju.edu.cn>
      Signed-off-by: default avatarDavid S. Miller <davem@davemloft.net>
      175302f6
  2. Oct 07, 2022
  3. Oct 06, 2022
    • Jakub Kicinski's avatar
      Merge tag 'ieee802154-for-net-2022-10-05' of... · 1d22f78d
      Jakub Kicinski authored
      Merge tag 'ieee802154-for-net-2022-10-05' of git://git.kernel.org/pub/scm/linux/kernel/git/sschmidt/wpan
      
      Stefan Schmidt says:
      
      ====================
      pull-request: ieee802154 for net 2022-10-05
      
      Only two patches this time around. A revert from Alexander Aring to a patch
      that hit net and the updated patch to fix the problem from Tetsuo Handa.
      
      * tag 'ieee802154-for-net-2022-10-05' of git://git.kernel.org/pub/scm/linux/kernel/git/sschmidt/wpan:
        net/ieee802154: don't warn zero-sized raw_sendmsg()
        Revert "net/ieee802154: reject zero-sized raw_sendmsg()"
      ====================
      
      Link: https://lore.kernel.org/r/20221005144508.787376-1-stefan@datenfreihafen.org
      
      
      Signed-off-by: default avatarJakub Kicinski <kuba@kernel.org>
      1d22f78d
    • Alexandru Tachici's avatar
      net: ethernet: adi: adin1110: Add check in netdev_event · f9371935
      Alexandru Tachici authored
      Check whether this driver actually is the intended recipient of
      upper change event.
      
      Fixes: bc93e19d
      
       ("net: ethernet: adi: Add ADIN1110 support")
      Signed-off-by: default avatarAlexandru Tachici <alexandru.tachici@analog.com>
      Link: https://lore.kernel.org/r/20221003111636.54973-1-alexandru.tachici@analog.com
      
      
      Signed-off-by: default avatarJakub Kicinski <kuba@kernel.org>
      f9371935
    • Casper Andersson's avatar
      229a0027
    • Geert Uytterhoeven's avatar
      net: pse-pd: PSE_REGULATOR should depend on REGULATOR · 304ee24b
      Geert Uytterhoeven authored
      The Regulator based PSE controller driver relies on regulator support to
      be enabled.  If regulator support is disabled, it will still compile
      fine, but won't operate correctly.
      
      Hence add a dependency on REGULATOR, to prevent asking the user about
      this driver when configuring a kernel without regulator support.
      
      Fixes: 66741b4e
      
       ("net: pse-pd: add regulator based PSE driver")
      Signed-off-by: default avatarGeert Uytterhoeven <geert+renesas@glider.be>
      Reviewed-by: default avatarOleksij Rempel <o.rempel@pengutronix.de>
      Link: https://lore.kernel.org/r/709caac8873ff2a8b72b92091429be7c1a939959.1664900558.git.geert+renesas@glider.be
      
      
      Signed-off-by: default avatarJakub Kicinski <kuba@kernel.org>
      304ee24b
    • Vladimir Oltean's avatar
      Revert "net/sched: taprio: make qdisc_leaf() see the per-netdev-queue pfifo child qdiscs" · af7b29b1
      Vladimir Oltean authored
      taprio_attach() has this logic at the end, which should have been
      removed with the blamed patch (which is now being reverted):
      
      	/* access to the child qdiscs is not needed in offload mode */
      	if (FULL_OFFLOAD_IS_ENABLED(q->flags)) {
      		kfree(q->qdiscs);
      		q->qdiscs = NULL;
      	}
      
      because otherwise, we make use of q->qdiscs[] even after this array was
      deallocated, namely in taprio_leaf(). Therefore, whenever one would try
      to attach a valid child qdisc to a fully offloaded taprio root, one
      would immediately dereference a NULL pointer.
      
      $ tc qdisc replace dev eno0 handle 8001: parent root taprio \
      	num_tc 8 \
      	map 0 1 2 3 4 5 6 7 \
      	queues 1@0 1@1 1@2 1@3 1@4 1@5 1@6 1@7 \
      	max-sdu 0 0 0 0 0 200 0 0 \
      	base-time 200 \
      	sched-entry S 80 20000 \
      	sched-entry S a0 20000 \
      	sched-entry S 5f 60000 \
      	flags 2
      $ max_frame_size=1500
      $ data_rate_kbps=20000
      $ port_transmit_rate_kbps=1000000
      $ idleslope=$data_rate_kbps
      $ sendslope=$(($idleslope - $port_transmit_rate_kbps))
      $ locredit=$(($max_frame_size * $sendslope / $port_transmit_rate_kbps))
      $ hicredit=$(($max_frame_size * $idleslope / $port_transmit_rate_kbps))
      $ tc qdisc replace dev eno0 parent 8001:7 cbs \
      	idleslope $idleslope \
      	sendslope $sendslope \
      	hicredit $hicredit \
      	locredit $locredit \
      	offload 0
      
      Unable to handle kernel NULL pointer dereference at virtual address 0000000000000030
      pc : taprio_leaf+0x28/0x40
      lr : qdisc_leaf+0x3c/0x60
      Call trace:
       taprio_leaf+0x28/0x40
       tc_modify_qdisc+0xf0/0x72c
       rtnetlink_rcv_msg+0x12c/0x390
       netlink_rcv_skb+0x5c/0x130
       rtnetlink_rcv+0x1c/0x2c
      
      The solution is not as obvious as the problem. The code which deallocates
      q->qdiscs[] is in fact copied and pasted from mqprio, which also
      deallocates the array in mqprio_attach() and never uses it afterwards.
      
      Therefore, the identical cleanup logic of priv->qdiscs[] that
      mqprio_destroy() has is deceptive because it will never take place at
      qdisc_destroy() time, but just at raw ops->destroy() time (otherwise
      said, priv->qdiscs[] do not last for the entire lifetime of the mqprio
      root), but rather, this is just the twisted way in which the Qdisc API
      understands error path cleanup should be done (Qdisc_ops :: destroy() is
      called even when Qdisc_ops :: init() never succeeded).
      
      Side note, in fact this is also what the comment in mqprio_init() says:
      
      	/* pre-allocate qdisc, attachment can't fail */
      
      Or reworded, mqprio's priv->qdiscs[] scheme is only meant to serve as
      data passing between Qdisc_ops :: init() and Qdisc_ops :: attach().
      
      [ this comment was also copied and pasted into the initial taprio
        commit, even though taprio_attach() came way later ]
      
      The problem is that taprio also makes extensive use of the q->qdiscs[]
      array in the software fast path (taprio_enqueue() and taprio_dequeue()),
      but it does not keep a reference of its own on q->qdiscs[i] (you'd think
      that since it creates these Qdiscs, it holds the reference, but nope,
      this is not completely true).
      
      To understand the difference between taprio_destroy() and mqprio_destroy()
      one must look before commit 13511704 ("net: taprio offload: enforce
      qdisc to netdev queue mapping"), because that just muddied the waters.
      
      In the "original" taprio design, taprio always attached itself (the root
      Qdisc) to all netdev TX queues, so that dev_qdisc_enqueue() would go
      through taprio_enqueue().
      
      It also called qdisc_refcount_inc() on itself for as many times as there
      were netdev TX queues, in order to counter-balance what tc_get_qdisc()
      does when destroying a Qdisc (simplified for brevity below):
      
      	if (n->nlmsg_type == RTM_DELQDISC)
      		err = qdisc_graft(dev, parent=NULL, new=NULL, q, extack);
      
      qdisc_graft(where "new" is NULL so this deletes the Qdisc):
      
      	for (i = 0; i < num_q; i++) {
      		struct netdev_queue *dev_queue;
      
      		dev_queue = netdev_get_tx_queue(dev, i);
      
      		old = dev_graft_qdisc(dev_queue, new);
      		if (new && i > 0)
      			qdisc_refcount_inc(new);
      
      		qdisc_put(old);
      		~~~~~~~~~~~~~~
      		this decrements taprio's refcount once for each TX queue
      	}
      
      	notify_and_destroy(net, skb, n, classid,
      			   rtnl_dereference(dev->qdisc), new);
      			   ~~~~~~~~~~~~~~~~~~~~~~~~~~~~
      			   and this finally decrements it to zero,
      			   making qdisc_put() call qdisc_destroy()
      
      The q->qdiscs[] created using qdisc_create_dflt() (or their
      replacements, if taprio_graft() was ever to get called) were then
      privately freed by taprio_destroy().
      
      This is still what is happening after commit 13511704 ("net: taprio
      offload: enforce qdisc to netdev queue mapping"), but only for software
      mode.
      
      In full offload mode, the per-txq "qdisc_put(old)" calls from
      qdisc_graft() now deallocate the child Qdiscs rather than decrement
      taprio's refcount. So when notify_and_destroy(taprio) finally calls
      taprio_destroy(), the difference is that the child Qdiscs were already
      deallocated.
      
      And this is exactly why the taprio_attach() comment "access to the child
      qdiscs is not needed in offload mode" is deceptive too. Not only the
      q->qdiscs[] array is not needed, but it is also necessary to get rid of
      it as soon as possible, because otherwise, we will also call qdisc_put()
      on the child Qdiscs in qdisc_destroy() -> taprio_destroy(), and this
      will cause a nasty use-after-free/refcount-saturate/whatever.
      
      In short, the problem is that since the blamed commit, taprio_leaf()
      needs q->qdiscs[] to not be freed by taprio_attach(), while qdisc_destroy()
      -> taprio_destroy() does need q->qdiscs[] to be freed by taprio_attach()
      for full offload. Fixing one problem triggers the other.
      
      All of this can be solved by making taprio keep its q->qdiscs[i] with a
      refcount elevated at 2 (in offloaded mode where they are attached to the
      netdev TX queues), both in taprio_attach() and in taprio_graft(). The
      generic qdisc_graft() would just decrement the child qdiscs' refcounts
      to 1, and taprio_destroy() would give them the final coup de grace.
      
      However the rabbit hole of changes is getting quite deep, and the
      complexity increases. The blamed commit was supposed to be a bug fix in
      the first place, and the bug it addressed is not so significant so as to
      justify further rework in stable trees. So I'd rather just revert it.
      I don't know enough about multi-queue Qdisc design to make a proper
      judgement right now regarding what is/isn't idiomatic use of Qdisc
      concepts in taprio. I will try to study the problem more and come with a
      different solution in net-next.
      
      Fixes: 1461d212
      
       ("net/sched: taprio: make qdisc_leaf() see the per-netdev-queue pfifo child qdiscs")
      Reported-by: default avatarMuhammad Husaini Zulkifli <muhammad.husaini.zulkifli@intel.com>
      Reported-by: default avatarVinicius Costa Gomes <vinicius.gomes@intel.com>
      Signed-off-by: default avatarVladimir Oltean <vladimir.oltean@nxp.com>
      Reviewed-by: default avatarVinicius Costa Gomes <vinicius.gomes@intel.com>
      Link: https://lore.kernel.org/r/20221004220100.1650558-1-vladimir.oltean@nxp.com
      
      
      Signed-off-by: default avatarJakub Kicinski <kuba@kernel.org>
      af7b29b1
  4. Oct 05, 2022
  5. Oct 04, 2022
    • Linus Torvalds's avatar
      Merge tag 'edac_updates_for_v6.1' of git://git.kernel.org/pub/scm/linux/kernel/git/ras/ras · bf767625
      Linus Torvalds authored
      Pull EDAC updates from Borislav Petkov:
      
       - Add support for Skylake-S CPUs to ie31200_edac
      
       - Improve error decoding speed of the Intel drivers by avoiding the
         ACPI facilities but doing decoding in the driver itself
      
       - Other misc improvements to the Intel drivers
      
       - The usual cleanups and fixlets all over EDAC land
      
      * tag 'edac_updates_for_v6.1' of git://git.kernel.org/pub/scm/linux/kernel/git/ras/ras:
        EDAC/i7300: Correct the i7300_exit() function name in comment
        x86/sb_edac: Add row column translation for Broadwell
        EDAC/i10nm: Print an extra register set of retry_rd_err_log
        EDAC/i10nm: Retrieve and print retry_rd_err_log registers for HBM
        EDAC/skx_common: Add ChipSelect ADXL component
        EDAC/ppc_4xx: Reorder symbols to get rid of a few forward declarations
        EDAC: Remove obsolete declarations in edac_module.h
        EDAC/i10nm: Add driver decoder for Ice Lake and Tremont CPUs
        EDAC/skx_common: Make output format similar
        EDAC/skx_common: Use driver decoder first
        EDAC/mc: Drop duplicated dimm->nr_pages debug printout
        EDAC/mc: Replace spaces with tabs in memtype flags definition
        EDAC/wq: Remove unneeded flush_workqueue()
        EDAC/ie31200: Add Skylake-S support
      bf767625
    • Borislav Petkov's avatar
      Merge branches 'edac-drivers' and 'edac-misc' into edac-updates-for-v6.1 · c2577956
      Borislav Petkov authored
      
      
      Combine all queued EDAC changes for submission into v6.1:
      
      * edac-drivers:
        EDAC/ie31200: Add Skylake-S support
      
      * edac-misc:
        EDAC/i7300: Correct the i7300_exit() function name in comment
        x86/sb_edac: Add row column translation for Broadwell
        EDAC/i10nm: Print an extra register set of retry_rd_err_log
        EDAC/i10nm: Retrieve and print retry_rd_err_log registers for HBM
        EDAC/skx_common: Add ChipSelect ADXL component
        EDAC/ppc_4xx: Reorder symbols to get rid of a few forward declarations
        EDAC: Remove obsolete declarations in edac_module.h
        EDAC/i10nm: Add driver decoder for Ice Lake and Tremont CPUs
        EDAC/skx_common: Make output format similar
        EDAC/skx_common: Use driver decoder first
        EDAC/mc: Drop duplicated dimm->nr_pages debug printout
        EDAC/mc: Replace spaces with tabs in memtype flags definition
        EDAC/wq: Remove unneeded flush_workqueue()
      
      Signed-off-by: default avatarBorislav Petkov <bp@suse.de>
      c2577956
    • Jakub Kicinski's avatar
      eth: pse: add missing static inlines · 681bf011
      Jakub Kicinski authored
      
      
      build bot reports missing 'static inline' qualifiers in the header.
      
      Reported-by: default avatarkernel test robot <lkp@intel.com>
      Fixes: 18ff0bcd
      
       ("ethtool: add interface to interact with Ethernet Power Equipment")
      Reviewed-by: default avatarOleksij Rempel <o.rempel@pengutronix.de>
      Link: https://lore.kernel.org/r/20221004040327.2034878-1-kuba@kernel.org
      
      
      Signed-off-by: default avatarJakub Kicinski <kuba@kernel.org>
      681bf011
    • Linus Torvalds's avatar
      Merge tag 'statx-dioalign-for-linus' of... · 725737e7
      Linus Torvalds authored
      Merge tag 'statx-dioalign-for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/ebiggers/linux
      
      Pull STATX_DIOALIGN support from Eric Biggers:
       "Make statx() support reporting direct I/O (DIO) alignment information.
      
        This provides a generic interface for userspace programs to determine
        whether a file supports DIO, and if so with what alignment
        restrictions. Specifically, STATX_DIOALIGN works on block devices, and
        on regular files when their containing filesystem has implemented
        support.
      
        An interface like this has been requested for years, since the
        conditions for when DIO is supported in Linux have gotten increasingly
        complex over time. Today, DIO support and alignment requirements can
        be affected by various filesystem features such as multi-device
        support, data journalling, inline data, encryption, verity,
        compression, checkpoint disabling, log-structured mode, etc.
      
        Further complicating things, Linux v6.0 relaxed the traditional rule
        of DIO needing to be aligned to the block device's logical block size;
        now user buffers (but not file offsets) only need to be aligned to the
        DMA alignment.
      
        The approach of uplifting the XFS specific ioctl XFS_IOC_DIOINFO was
        discarded in favor of creating a clean new interface with statx().
      
        For more information, see the individual commits and the man page
        update[1]"
      
      Link: https://lore.kernel.org/r/20220722074229.148925-1-ebiggers@kernel.org [1]
      
      * tag 'statx-dioalign-for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/ebiggers/linux:
        xfs: support STATX_DIOALIGN
        f2fs: support STATX_DIOALIGN
        f2fs: simplify f2fs_force_buffered_io()
        f2fs: move f2fs_force_buffered_io() into file.c
        ext4: support STATX_DIOALIGN
        fscrypt: change fscrypt_dio_supported() to prepare for STATX_DIOALIGN
        vfs: support STATX_DIOALIGN on block devices
        statx: add direct I/O alignment information
      725737e7
    • Linus Torvalds's avatar
      Merge tag 'fsverity-for-linus' of git://git.kernel.org/pub/scm/fs/fscrypt/fscrypt · 5779aa2d
      Linus Torvalds authored
      Pull fsverity updates from Eric Biggers:
       "Minor changes to convert uses of kmap() to kmap_local_page()"
      
      * tag 'fsverity-for-linus' of git://git.kernel.org/pub/scm/fs/fscrypt/fscrypt:
        fs-verity: use kmap_local_page() instead of kmap()
        fs-verity: use memcpy_from_page()
      5779aa2d
    • Linus Torvalds's avatar
      Merge tag 'fscrypt-for-linus' of git://git.kernel.org/pub/scm/fs/fscrypt/fscrypt · 438b2cdd
      Linus Torvalds authored
      Pull fscrypt updates from Eric Biggers:
       "This release contains some implementation changes, but no new
        features:
      
         - Rework the implementation of the fscrypt filesystem-level keyring
           to not be as tightly coupled to the keyrings subsystem. This
           resolves several issues.
      
         - Eliminate most direct uses of struct request_queue from fs/crypto/,
           since struct request_queue is considered to be a block layer
           implementation detail.
      
         - Stop using the PG_error flag to track decryption failures. This is
           a prerequisite for freeing up PG_error for other uses"
      
      * tag 'fscrypt-for-linus' of git://git.kernel.org/pub/scm/fs/fscrypt/fscrypt:
        fscrypt: work on block_devices instead of request_queues
        fscrypt: stop holding extra request_queue references
        fscrypt: stop using keyrings subsystem for fscrypt_master_key
        fscrypt: stop using PG_error to track error status
        fscrypt: remove fscrypt_set_test_dummy_encryption()
      438b2cdd
    • Linus Torvalds's avatar
      Merge tag 'dlm-6.1' of git://git.kernel.org/pub/scm/linux/kernel/git/teigland/linux-dlm · f4309528
      Linus Torvalds authored
      Pull dlm updates from David Teigland:
      
       - Fix a couple races found with a new torture test
      
       - Improve errors when api functions are used incorrectly
      
       - Improve tracing for lock requests from user space
      
       - Fix use after free in recently added tracing cod.
      
       - Small internal code cleanups
      
      * tag 'dlm-6.1' of git://git.kernel.org/pub/scm/linux/kernel/git/teigland/linux-dlm:
        fs: dlm: fix possible use after free if tracing
        fs: dlm: const void resource name parameter
        fs: dlm: LSFL_CB_DELAY only for kernel lockspaces
        fs: dlm: remove DLM_LSFL_FS from uapi
        fs: dlm: trace user space callbacks
        fs: dlm: change ls_clear_proc_locks to spinlock
        fs: dlm: remove dlm_del_ast prototype
        fs: dlm: handle rcom in else if branch
        fs: dlm: allow lockspaces have zero lvblen
        fs: dlm: fix invalid derefence of sb_lvbptr
        fs: dlm: handle -EINVAL as log_error()
        fs: dlm: use __func__ for function name
        fs: dlm: handle -EBUSY first in unlock validation
        fs: dlm: handle -EBUSY first in lock arg validation
        fs: dlm: fix race between test_bit() and queue_work()
        fs: dlm: fix race in lowcomms
      f4309528