1. Feb 24, 2024
    • John Garry's avatar
      rocker: Don't bother filling in ethtool driver version · 23fe265f
      John Garry authored
      
      
      The version is same as the default, so don't bother filling it in.
      
      Signed-off-by: default avatarJohn Garry <john.g.garry@oracle.com>
      Reviewed-by: default avatarJiri Pirko <jiri@nvidia.com>
      Link: https://lore.kernel.org/r/20240222090042.12609-2-john.g.garry@oracle.com
      
      
      Signed-off-by: default avatarJakub Kicinski <kuba@kernel.org>
      23fe265f
    • Simon Horman's avatar
      ps3/gelic: minor Kernel Doc corrections · 3e596599
      Simon Horman authored
      
      
      * Update the Kernel Doc for gelic_descr_set_tx_cmdstat()
        and gelic_net_setup_netdev() so that documented name
        and the actual name of the function match.
      
      * Move define of GELIC_ALIGN() so that it is no longer
        between gelic_alloc_card_net() and it's Kernel Doc.
      
      * Document netdev parameter of gelic_alloc_card_net()
        in a way consistent to the documentation of other netdev parameters
        in this file.
      
      Addresses the following warnings flagged by ./scripts/kernel-doc -none:
      
        .../ps3_gelic_net.c:711: warning: expecting prototype for gelic_net_set_txdescr_cmdstat(). Prototype was for gelic_descr_set_tx_cmdstat() instead
        .../ps3_gelic_net.c:1474: warning: expecting prototype for gelic_ether_setup_netdev(). Prototype was for gelic_net_setup_netdev() instead
        .../ps3_gelic_net.c:1528: warning: expecting prototype for gelic_alloc_card_net(). Prototype was for GELIC_ALIGN() instead
        .../ps3_gelic_net.c:1531: warning: Function parameter or struct member 'netdev' not described in 'gelic_alloc_card_net'
      
      Signed-off-by: default avatarSimon Horman <horms@kernel.org>
      Acked-by: default avatarGeoff Levand <geoff@infradead.org>
      Link: https://lore.kernel.org/r/20240221-ps3-gelic-kdoc-v1-1-7629216d1340@kernel.org
      
      
      Signed-off-by: default avatarJakub Kicinski <kuba@kernel.org>
      3e596599
    • Florian Westphal's avatar
      net: mpls: error out if inner headers are not set · 025f8ad2
      Florian Westphal authored
      mpls_gso_segment() assumes skb_inner_network_header() returns
      a valid result:
      
        mpls_hlen = skb_inner_network_header(skb) - skb_network_header(skb);
        if (unlikely(!mpls_hlen || mpls_hlen % MPLS_HLEN))
              goto out;
        if (unlikely(!pskb_may_pull(skb, mpls_hlen)))
      
      With syzbot reproducer, skb_inner_network_header() yields 0,
      skb_network_header() returns 108, so this will
      "pskb_may_pull(skb, -108)))" which triggers a newly added
      DEBUG_NET_WARN_ON_ONCE() check:
      
      ------------[ cut here ]------------
      WARNING: CPU: 0 PID: 5068 at include/linux/skbuff.h:2723 pskb_may_pull_reason include/linux/skbuff.h:2723 [inline]
      WARNING: CPU: 0 PID: 5068 at include/linux/skbuff.h:2723 pskb_may_pull include/linux/skbuff.h:2739 [inline]
      WARNING: CPU: 0 PID: 5068 at include/linux/skbuff.h:2723 mpls_gso_segment+0x773/0xaa0 net/mpls/mpls_gso.c:34
      [..]
       skb_mac_gso_segment+0x383/0x740 net/core/gso.c:53
       nsh_gso_segment+0x40a/0xad0 net/nsh/nsh.c:108
       skb_mac_gso_segment+0x383/0x740 net/core/gso.c:53
       __skb_gso_segment+0x324/0x4c0 net/core/gso.c:124
       skb_gso_segment include/net/gso.h:83 [inline]
       [..]
       sch_direct_xmit+0x11a/0x5f0 net/sched/sch_generic.c:327
       [..]
       packet_sendmsg+0x46a9/0x6130 net/packet/af_packet.c:3113
       [..]
      
      First iteration of this patch made mpls_hlen signed and changed
      test to error out to "mpls_hlen <= 0 || ..".
      
      Eric Dumazet said:
       > I was thinking about adding a debug check in skb_inner_network_header()
       > if inner_network_header is zero (that would mean it is not 'set' yet),
       > but this would trigger even after your patch.
      
      So add new skb_inner_network_header_was_set() helper and use that.
      
      The syzbot reproducer injects data via packet socket. The skb that gets
      allocated and passed down the stack has ->protocol set to NSH (0x894f)
      and gso_type set to SKB_GSO_UDP | SKB_GSO_DODGY.
      
      This gets passed to skb_mac_gso_segment(), which sees NSH as ptype to
      find a callback for.  nsh_gso_segment() retrieves next type:
      
              proto = tun_p_to_eth_p(nsh_hdr(skb)->np);
      
      ... which is MPLS (TUN_P_MPLS_UC). It updates skb->protocol and then
      calls mpls_gso_segment().  Inner offsets are all 0, so mpls_gso_segment()
      ends up with a negative header size.
      
      In case more callers rely on silent handling of such large may_pull values
      we could also 'legalize' this behaviour, either replacing the debug check
      with (len > INT_MAX) test or removing it and instead adding a comment
      before existing
      
       if (unlikely(len > skb->len))
          return SKB_DROP_REASON_PKT_TOO_SMALL;
      
      test in pskb_may_pull_reason(), saying that this check also implicitly
      takes care of callers that miscompute header sizes.
      
      Cc: Simon Horman <horms@kernel.org>
      Fixes: 219eee9c
      
       ("net: skbuff: add overflow debug check to pull/push helpers")
      Reported-by: default avatar <syzbot+99d15fcdb0132a1e1a82@syzkaller.appspotmail.com>
      Closes: https://lore.kernel.org/netdev/00000000000043b1310611e388aa@google.com/raw
      
      
      Signed-off-by: default avatarFlorian Westphal <fw@strlen.de>
      Link: https://lore.kernel.org/r/20240222140321.14080-1-fw@strlen.de
      
      
      Signed-off-by: default avatarJakub Kicinski <kuba@kernel.org>
      025f8ad2
    • Jann Horn's avatar
      net: ethtool: avoid rebuilds on UTS_RELEASE change · d2efeb52
      Jann Horn authored
      
      
      Currently, when you switch between branches or something like that and
      rebuild, net/ethtool/ioctl.c has to be built again because it depends
      on UTS_RELEASE.
      
      By instead referencing a string variable stored in another object file,
      this can be avoided.
      
      Signed-off-by: default avatarJann Horn <jannh@google.com>
      Reviewed-by: default avatarJohn Garry <john.g.garry@oracle.com>
      Link: https://lore.kernel.org/r/20240220194244.2056384-1-jannh@google.com
      
      
      Signed-off-by: default avatarJakub Kicinski <kuba@kernel.org>
      d2efeb52
  2. Feb 23, 2024
    • Sneh Shah's avatar
      net: stmmac: dwmac-qcom-ethqos: Add support for 2.5G SGMII · a818bd12
      Sneh Shah authored
      
      
      Serdes phy needs to operate at 2500 mode for 2.5G speed and 1000
      mode for 1G/100M/10M speed.
      Added changes to configure serdes phy and mac based on link speed.
      Changing serdes phy speed involves multiple register writes for
      serdes block. To avoid redundant write operations only update serdes
      phy when new speed is different.
      For 2500 speed MAC PCS autoneg needs to disabled. Added changes to
      disable MAC PCS autoneg if ANE parameter is not set.
      
      Signed-off-by: default avatarSneh Shah <quic_snehshah@quicinc.com>
      Tested-by: Abhishek Chauhan <quic_abchauha@quicinc.com> # sa8775p-ride
      Reviewed-by: default avatarAbhishek Chauhan <quic_abchauha@quicinc.com>
      Signed-off-by: default avatarDavid S. Miller <davem@davemloft.net>
      a818bd12
    • Praveen Kumar Kannoju's avatar
      bonding: rate-limit bonding driver inspect messages · a4634aa7
      Praveen Kumar Kannoju authored
      
      
      Through the routine bond_mii_monitor(), bonding driver inspects and commits
      the slave state changes. During the times when slave state change and
      failure in aqcuiring rtnl lock happen at the same time, the routine
      bond_mii_monitor() reschedules itself to come around after 1 msec to commit
      the new state.
      
      During this, it executes the routine bond_miimon_inspect() to re-inspect
      the state chane and prints the corresponding slave state on to the console.
      Hence we do see a message at every 1 msec till the rtnl lock is acquired
      and state chage is committed.
      
      This patch doesn't change how bond functions. It only simply limits this
      kind of log flood.
      
      Signed-off-by: default avatarPraveen Kumar Kannoju <praveen.kannoju@oracle.com>
      Reviewed-by: default avatarSimon Horman <horms@kernel.org>
      Reviewed-by: default avatarHangbin Liu <liuhangbin@gmail.com>
      Acked-by: default avatarJay Vosburgh <jay.vosburgh@canonical.com>
      Link: https://lore.kernel.org/r/20240221082752.4660-1-praveen.kannoju@oracle.com
      
      
      Signed-off-by: default avatarJakub Kicinski <kuba@kernel.org>
      a4634aa7
    • Jakub Kicinski's avatar
      Merge tag 'nf-next-24-02-21' of https://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf-next · 4679f4f1
      Jakub Kicinski authored
      Florian Westphal says:
      
      ====================
      netfilter updates for net-next
      
      1. Prefer KMEM_CACHE() macro to create kmem caches, from Kunwu Chan.
      
      Patches 2 and 3 consolidate nf_log NULL checks and introduces
      extra boundary checks on family and type to make it clear that no out
      of bounds access will happen.  No in-tree user currently passes such
      values, but thats not clear from looking at the function.
      From Pablo Neira Ayuso.
      
      Patch 4, also from Pablo, gets rid of unneeded conditional in
      nft_osf init function.
      
      Patch 5, from myself, fixes erroneous Kconfig dependencies that
      came in an earlier net-next pull request. This should get rid
      of the xtables related build failure reports.
      
      Patches 6 to 10 are an update to nftables' concatenated-ranges
      set type to speed up element insertions.  This series also
      compacts a few data structures and cleans up a few oddities such
      as reliance on ZERO_SIZE_PTR when asking to allocate a set with
      no elements. From myself.
      
      Patches 11 moves the nf_reinject function from the netfilter core
      (vmlinux) into the nfnetlink_queue backend, the only location where
      this is called from. Also from myself.
      
      Patch 12, from Kees Cook, switches xtables' compat layer to use
      unsafe_memcpy because xt_entry_target cannot easily get converted
      to a real flexible array (its UAPI and used inside other structs).
      
      * tag 'nf-next-24-02-21' of https://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf-next:
        netfilter: x_tables: Use unsafe_memcpy() for 0-sized destination
        netfilter: move nf_reinject into nfnetlink_queue modules
        netfilter: nft_set_pipapo: use GFP_KERNEL for insertions
        netfilter: nft_set_pipapo: speed up bulk element insertions
        netfilter: nft_set_pipapo: shrink data structures
        netfilter: nft_set_pipapo: do not rely on ZERO_SIZE_PTR
        netfilter: nft_set_pipapo: constify lookup fn args where possible
        netfilter: xtables: fix up kconfig dependencies
        netfilter: nft_osf: simplify init path
        netfilter: nf_log: validate nf_logger_find_get()
        netfilter: nf_log: consolidate check for NULL logger in lookup function
        netfilter: expect: Simplify the allocation of slab caches in nf_conntrack_expect_init
      ====================
      
      Link: https://lore.kernel.org/r/20240221112637.5396-1-fw@strlen.de
      
      
      Signed-off-by: default avatarJakub Kicinski <kuba@kernel.org>
      4679f4f1
    • Breno Leitao's avatar
      ipv6/sit: Do not allocate stats in the driver · 3e7a0dcc
      Breno Leitao authored
      With commit 34d21de9
      
       ("net: Move {l,t,d}stats allocation to core and
      convert veth & vrf"), stats allocation could be done on net core
      instead of this driver.
      
      With this new approach, the driver doesn't have to bother with error
      handling (allocation failure checking, making sure free happens in the
      right spot, etc). This is core responsibility now.
      
      Remove the allocation in the ipv6/sit driver and leverage the network
      core allocation.
      
      Signed-off-by: default avatarBreno Leitao <leitao@debian.org>
      Reviewed-by: default avatarSimon Horman <horms@kernel.org>
      Reviewed-by: default avatarDavid Ahern <dsahern@kernel.org>
      Link: https://lore.kernel.org/r/20240221161732.3026127-1-leitao@debian.org
      
      
      Signed-off-by: default avatarJakub Kicinski <kuba@kernel.org>
      3e7a0dcc
    • Geert Uytterhoeven's avatar
      bcc11576
    • Colin Ian King's avatar
      cbe30f99
    • Alexander Gordeev's avatar
      net/af_iucv: fix virtual vs physical address confusion · 9eda38dc
      Alexander Gordeev authored
      
      
      Fix virtual vs physical address confusion. This does not fix a bug
      since virtual and physical address spaces are currently the same.
      
      Signed-off-by: default avatarAlexander Gordeev <agordeev@linux.ibm.com>
      Reviewed-by: default avatarAlexandra Winter <wintera@linux.ibm.com>
      Link: https://lore.kernel.org/r/20240215080500.2616848-1-agordeev@linux.ibm.com
      
      
      Signed-off-by: default avatarJakub Kicinski <kuba@kernel.org>
      9eda38dc
    • Jakub Kicinski's avatar
      Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net · fecc5155
      Jakub Kicinski authored
      Cross-merge networking fixes after downstream PR.
      
      Conflicts:
      
      net/ipv4/udp.c
        f796feab ("udp: add local "peek offset enabled" flag")
        56667da7 ("net: implement lockless setsockopt(SO_PEEK_OFF)")
      
      Adjacent changes:
      
      net/unix/garbage.c
        aa82ac51 ("af_unix: Drop oob_skb ref before purging queue in GC.")
        11498715
      
       ("af_unix: Remove io_uring code for GC.")
      
      Signed-off-by: default avatarJakub Kicinski <kuba@kernel.org>
      fecc5155
    • Jakub Kicinski's avatar
      Merge tag 'wireless-next-2024-02-22' of... · 0fb848d1
      Jakub Kicinski authored
      Merge tag 'wireless-next-2024-02-22' of git://git.kernel.org/pub/scm/linux/kernel/git/wireless/wireless-next
      
      Kalle Valo says:
      
      ====================
      wireless-next patches for v6.9
      
      The third "new features" pull request for v6.9. This is a quick
      followup to send commit 04edb5dc ("wifi: ath12k: Fix uninitialized
      use of ret in ath12k_mac_allocate()") to fix the ath12k clang warning
      introduced in the previous pull request.
      
      We also have support for QCA2066 in ath11k, several new features in
      ath12k and few other changes in drivers. In stack it's mostly cleanup
      and refactoring.
      
      Major changes:
      
      ath12k
       * firmware-2.bin support
       * support having multiple identical PCI devices (firmware needs to
         have ATH12K_FW_FEATURE_MULTI_QRTR_ID)
       * QCN9274: support split-PHY devices
       * WCN7850: enable Power Save Mode in station mode
       * WCN7850: P2P support
      
      ath11k:
       * QCA6390 & WCN6855: support 2 concurrent station interfaces
       * QCA2066 support
      
      iwlwifi
       * mvm: support wider-bandwidth OFDMA
       * bump firmware API to 90 for BZ/SC devices
      
      brcmfmac
       * DMI nvram filename quirk for ACEPC W5 Pro
      
      * tag 'wireless-next-2024-02-22' of git://git.kernel.org/pub/scm/linux/kernel/git/wireless/wireless-next: (75 commits)
        wifi: wilc1000: revert reset line logic flip
        wifi: brcmfmac: Add DMI nvram filename quirk for ACEPC W5 Pro
        wifi: rtlwifi: set initial values for unexpected cases of USB endpoint priority
        wifi: rtl8xxxu: check vif before using in rtl8xxxu_tx()
        wifi: rtlwifi: rtl8192cu: Fix TX aggregation
        wifi: wilc1000: remove AKM suite be32 conversion for external auth request
        wifi: nl80211: refactor parsing CSA offsets
        wifi: nl80211: force WLAN_AKM_SUITE_SAE in big endian in NL80211_CMD_EXTERNAL_AUTH
        wifi: iwlwifi: load b0 version of ucode for HR1/HR2
        wifi: iwlwifi: handle per-phy statistics from fw
        wifi: iwlwifi: iwl-fh.h: fix kernel-doc issues
        wifi: iwlwifi: api: fix kernel-doc reference
        wifi: iwlwifi: mvm: unlock mvm if there is no primary link
        wifi: iwlwifi: bump FW API to 90 for BZ/SC devices
        wifi: iwlwifi: mvm: support PHY context version 6
        wifi: iwlwifi: mvm: partially support PHY context version 6
        wifi: iwlwifi: mvm: support wider-bandwidth OFDMA
        wifi: cfg80211: use ML element parsing helpers
        wifi: mac80211: align ieee80211_mle_get_bss_param_ch_cnt()
        wifi: cfg80211: refactor RNR parsing
        ...
      ====================
      
      Link: https://lore.kernel.org/r/20240222105205.CEC54C433F1@smtp.kernel.org
      
      
      Signed-off-by: default avatarJakub Kicinski <kuba@kernel.org>
      0fb848d1
    • Linus Torvalds's avatar
      Merge tag 'net-6.8.0-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net · 6714ebb9
      Linus Torvalds authored
      Pull networking fixes from Paolo Abeni:
       "Including fixes from bpf and netfilter.
      
        Current release - regressions:
      
         - af_unix: fix another unix GC hangup
      
        Previous releases - regressions:
      
         - core: fix a possible AF_UNIX deadlock
      
         - bpf: fix NULL pointer dereference in sk_psock_verdict_data_ready()
      
         - netfilter: nft_flow_offload: release dst in case direct xmit path
           is used
      
         - bridge: switchdev: ensure MDB events are delivered exactly once
      
         - l2tp: pass correct message length to ip6_append_data
      
         - dccp/tcp: unhash sk from ehash for tb2 alloc failure after
           check_estalblished()
      
         - tls: fixes for record type handling with PEEK
      
         - devlink: fix possible use-after-free and memory leaks in
           devlink_init()
      
        Previous releases - always broken:
      
         - bpf: fix an oops when attempting to read the vsyscall page through
           bpf_probe_read_kernel
      
         - sched: act_mirred: use the backlog for mirred ingress
      
         - netfilter: nft_flow_offload: fix dst refcount underflow
      
         - ipv6: sr: fix possible use-after-free and null-ptr-deref
      
         - mptcp: fix several data races
      
         - phonet: take correct lock to peek at the RX queue
      
        Misc:
      
         - handful of fixes and reliability improvements for selftests"
      
      * tag 'net-6.8.0-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net: (72 commits)
        l2tp: pass correct message length to ip6_append_data
        net: phy: realtek: Fix rtl8211f_config_init() for RTL8211F(D)(I)-VD-CG PHY
        selftests: ioam: refactoring to align with the fix
        Fix write to cloned skb in ipv6_hop_ioam()
        phonet/pep: fix racy skb_queue_empty() use
        phonet: take correct lock to peek at the RX queue
        net: sparx5: Add spinlock for frame transmission from CPU
        net/sched: flower: Add lock protection when remove filter handle
        devlink: fix port dump cmd type
        net: stmmac: Fix EST offset for dwmac 5.10
        tools: ynl: don't leak mcast_groups on init error
        tools: ynl: make sure we always pass yarg to mnl_cb_run
        net: mctp: put sock on tag allocation failure
        netfilter: nf_tables: use kzalloc for hook allocation
        netfilter: nf_tables: register hooks last when adding new chain/flowtable
        netfilter: nft_flow_offload: release dst in case direct xmit path is used
        netfilter: nft_flow_offload: reset dst in route object after setting up flow
        netfilter: nf_tables: set dormant flag on hook register failure
        selftests: tls: add test for peeking past a record of a different type
        selftests: tls: add test for merging of same-type control messages
        ...
      6714ebb9
    • Linus Torvalds's avatar
      Merge tag 'trace-v6.8-rc5' of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace · efa80dcb
      Linus Torvalds authored
      Pull tracing fix from Steven Rostedt:
      
       - While working on the ring buffer I noticed that the counter used for
         knowing where the end of the data is on a sub-buffer was not a full
         "int" but just 20 bits. It was masked out to 0xfffff.
      
         With the new code that allows the user to change the size of the
         sub-buffer, it is theoretically possible to ask for a size bigger
         than 2^20. If that happens, unexpected results may occur as there's
         no code checking if the counter overflowed the 20 bits of the write
         mask. There are other checks to make sure events fit in the
         sub-buffer, but if the sub-buffer itself is too big, that is not
         checked.
      
         Add a check in the resize of the sub-buffer to make sure that it
         never goes beyond the size of the counter that holds how much data is
         on it.
      
      * tag 'trace-v6.8-rc5' of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace:
        ring-buffer: Do not let subbuf be bigger than write mask
      efa80dcb
  3. Feb 22, 2024