1. Jan 31, 2024
    • Greg Kroah-Hartman's avatar
      driver core: cpu: make cpu_subsys const · 3a480d4b
      Greg Kroah-Hartman authored
      Now that the driver core can properly handle constant struct bus_type,
      move the cpu_subsys variable to be a constant structure as well, placing
      it into read-only memory which can not be modified at runtime.
      
      Cc: "Rafael J. Wysocki" <rafael@kernel.org>
      Link: https://lore.kernel.org/r/2024010548-crane-snooze-a871@gregkh
      
      
      Signed-off-by: default avatarGreg Kroah-Hartman <gregkh@linuxfoundation.org>
      3a480d4b
    • Neel Natu's avatar
      kernfs: fix false-positive WARN(nr_mmapped) in kernfs_drain_open_files · 05d8f255
      Neel Natu authored
      
      
      Prior to this change 'on->nr_mmapped' tracked the total number of
      mmaps across all of its associated open files via kernfs_fop_mmap().
      Thus if the file descriptor associated with a kernfs_open_file was
      mmapped 10 times then we would have: 'of->mmapped = true' and
      'of_on(of)->nr_mmapped = 10'.
      
      The problem is that closing or draining a 'of->mmapped' file would
      only decrement one from the 'of_on(of)->nr_mmapped' counter.
      
      For e.g. we have this from kernfs_unlink_open_file():
              if (of->mmapped)
                      on->nr_mmapped--;
      
      The WARN_ON_ONCE(on->nr_mmapped) in kernfs_drain_open_files() is
      easy to reproduce by:
      1. opening a (mmap-able) kernfs file.
      2. mmap-ing that file more than once (mapping just once masks the issue).
      3. trigger a drain of that kernfs file.
      
      Modulo out-of-tree patches I was able to trigger this reliably by
      identifying pci device nodes in sysfs that have resource regions
      that are mmap-able and that don't have any driver attached to them
      (steps 1 and 2). For step 3 we can "echo 1 > remove" to trigger a
      kernfs_drain.
      
      Signed-off-by: default avatarNeel Natu <neelnatu@google.com>
      Link: https://lore.kernel.org/r/20240127234636.609265-1-neelnatu@google.com
      
      
      Signed-off-by: default avatarGreg Kroah-Hartman <gregkh@linuxfoundation.org>
      05d8f255
    • Tejun Heo's avatar
      kernfs: RCU protect kernfs_nodes and avoid kernfs_idr_lock in kernfs_find_and_get_node_by_id() · 4207b556
      Tejun Heo authored
      
      
      The BPF helper bpf_cgroup_from_id() calls kernfs_find_and_get_node_by_id()
      which acquires kernfs_idr_lock, which is an non-raw non-IRQ-safe lock. This
      can lead to deadlocks as bpf_cgroup_from_id() can be called from any BPF
      programs including e.g. the ones that attach to functions which are holding
      the scheduler rq lock.
      
      Consider the following BPF program:
      
        SEC("fentry/__set_cpus_allowed_ptr_locked")
        int BPF_PROG(__set_cpus_allowed_ptr_locked, struct task_struct *p,
      	       struct affinity_context *affn_ctx, struct rq *rq, struct rq_flags *rf)
        {
      	  struct cgroup *cgrp = bpf_cgroup_from_id(p->cgroups->dfl_cgrp->kn->id);
      
      	  if (cgrp) {
      		  bpf_printk("%d[%s] in %s", p->pid, p->comm, cgrp->kn->name);
      		  bpf_cgroup_release(cgrp);
      	  }
      	  return 0;
        }
      
      __set_cpus_allowed_ptr_locked() is called with rq lock held and the above
      BPF program calls bpf_cgroup_from_id() within leading to the following
      lockdep warning:
      
        =====================================================
        WARNING: HARDIRQ-safe -> HARDIRQ-unsafe lock order detected
        6.7.0-rc3-work-00053-g07124366a1d7-dirty #147 Not tainted
        -----------------------------------------------------
        repro/1620 [HC0[0]:SC0[0]:HE0:SE1] is trying to acquire:
        ffffffff833b3688 (kernfs_idr_lock){+.+.}-{2:2}, at: kernfs_find_and_get_node_by_id+0x1e/0x70
      
      		and this task is already holding:
        ffff888237ced698 (&rq->__lock){-.-.}-{2:2}, at: task_rq_lock+0x4e/0xf0
        which would create a new lock dependency:
         (&rq->__lock){-.-.}-{2:2} -> (kernfs_idr_lock){+.+.}-{2:2}
        ...
         Possible interrupt unsafe locking scenario:
      
      	 CPU0                    CPU1
      	 ----                    ----
          lock(kernfs_idr_lock);
      				 local_irq_disable();
      				 lock(&rq->__lock);
      				 lock(kernfs_idr_lock);
          <Interrupt>
            lock(&rq->__lock);
      
      		 *** DEADLOCK ***
        ...
        Call Trace:
         dump_stack_lvl+0x55/0x70
         dump_stack+0x10/0x20
         __lock_acquire+0x781/0x2a40
         lock_acquire+0xbf/0x1f0
         _raw_spin_lock+0x2f/0x40
         kernfs_find_and_get_node_by_id+0x1e/0x70
         cgroup_get_from_id+0x21/0x240
         bpf_cgroup_from_id+0xe/0x20
         bpf_prog_98652316e9337a5a___set_cpus_allowed_ptr_locked+0x96/0x11a
         bpf_trampoline_6442545632+0x4f/0x1000
         __set_cpus_allowed_ptr_locked+0x5/0x5a0
         sched_setaffinity+0x1b3/0x290
         __x64_sys_sched_setaffinity+0x4f/0x60
         do_syscall_64+0x40/0xe0
         entry_SYSCALL_64_after_hwframe+0x46/0x4e
      
      Let's fix it by protecting kernfs_node and kernfs_root with RCU and making
      kernfs_find_and_get_node_by_id() acquire rcu_read_lock() instead of
      kernfs_idr_lock.
      
      This adds an rcu_head to kernfs_node making it larger by 16 bytes on 64bit.
      Combined with the preceding rearrange patch, the net increase is 8 bytes.
      
      Signed-off-by: default avatarTejun Heo <tj@kernel.org>
      Cc: Andrea Righi <andrea.righi@canonical.com>
      Cc: Geert Uytterhoeven <geert@linux-m68k.org>
      Link: https://lore.kernel.org/r/20240109214828.252092-4-tj@kernel.org
      
      
      Signed-off-by: default avatarGreg Kroah-Hartman <gregkh@linuxfoundation.org>
      4207b556
    • Tejun Heo's avatar
      kernfs: Rearrange kernfs_node fields to reduce its size on 64bit · 1c9f2c76
      Tejun Heo authored
      
      
      Moving .flags and .mode right below .hash makes kernfs_node smaller by 8
      bytes on 64bit. To avoid creating a hole from 8 bytes alignment on 32bit
      archs, .priv is moved below so that there are two 32bit pointers after the
      64bit .id field.
      
      v2: Updated to avoid size increase on 32bit noticed by Geert.
      
      Signed-off-by: default avatarTejun Heo <tj@kernel.org>
      Cc: Geert Uytterhoeven <geert@linux-m68k.org>
      Link: https://lore.kernel.org/r/ZZ7hwA18nfmFjYpj@slm.duckdns.org
      
      
      Signed-off-by: default avatarGreg Kroah-Hartman <gregkh@linuxfoundation.org>
      1c9f2c76
  2. Jan 29, 2024
  3. Jan 28, 2024
    • Linus Torvalds's avatar
      Merge tag 'platform-drivers-x86-v6.8-2' of... · 8a696a29
      Linus Torvalds authored
      Merge tag 'platform-drivers-x86-v6.8-2' of git://git.kernel.org/pub/scm/linux/kernel/git/pdx86/platform-drivers-x86
      
      Pull x86 platform driver fixes from Hans de Goede:
      
       - WMI bus driver fixes
      
       - Second attempt (previously reverted) at P2SB PCI rescan deadlock fix
      
       - AMD PMF driver improvements
      
       - MAINTAINERS updates
      
       - Misc other small fixes and hw-id additions
      
      * tag 'platform-drivers-x86-v6.8-2' of git://git.kernel.org/pub/scm/linux/kernel/git/pdx86/platform-drivers-x86:
        platform/x86: touchscreen_dmi: Add info for the TECLAST X16 Plus tablet
        platform/x86/intel/ifs: Call release_firmware() when handling errors.
        platform/x86/amd/pmf: Fix memory leak in amd_pmf_get_pb_data()
        platform/x86/amd/pmf: Get ambient light information from AMD SFH driver
        platform/x86/amd/pmf: Get Human presence information from AMD SFH driver
        platform/mellanox: mlxbf-pmc: Fix offset calculation for crspace events
        platform/mellanox: mlxbf-tmfifo: Drop Tx network packet when Tx TmFIFO is full
        MAINTAINERS: remove defunct acpi4asus project info from asus notebooks section
        MAINTAINERS: add Luke Jones as maintainer for asus notebooks
        MAINTAINERS: Remove Perry Yuan as DELL WMI HARDWARE PRIVACY SUPPORT maintainer
        platform/x86: silicom-platform: Add missing "Description:" for power_cycle sysfs attr
        platform/x86: intel-wmi-sbl-fw-update: Fix function name in error message
        platform/x86: p2sb: Use pci_resource_n() in p2sb_read_bar0()
        platform/x86: p2sb: Allow p2sb_bar() calls during PCI device probe
        platform/x86: intel-uncore-freq: Fix types in sysfs callbacks
        platform/x86: wmi: Fix wmi_dev_probe()
        platform/x86: wmi: Fix notify callback locking
        platform/x86: wmi: Decouple legacy WMI notify handlers from wmi_block_list
        platform/x86: wmi: Return immediately if an suitable WMI event is found
        platform/x86: wmi: Fix error handling in legacy WMI notify handler functions
      8a696a29
    • Linus Torvalds's avatar
      Merge tag 'loongarch-fixes-6.8-1' of... · 95534043
      Linus Torvalds authored
      Merge tag 'loongarch-fixes-6.8-1' of git://git.kernel.org/pub/scm/linux/kernel/git/chenhuacai/linux-loongson
      
      Pull LoongArch fixes from Huacai Chen:
       "Fix boot failure on machines with more than 8 nodes, and fix two build
        errors about KVM"
      
      * tag 'loongarch-fixes-6.8-1' of git://git.kernel.org/pub/scm/linux/kernel/git/chenhuacai/linux-loongson:
        LoongArch: KVM: Add returns to SIMD stubs
        LoongArch: KVM: Fix build due to API changes
        LoongArch/smp: Call rcutree_report_cpu_starting() at tlb_init()
      95534043
    • Linus Torvalds's avatar
      Merge tag 'xfs-6.8-fixes-1' of git://git.kernel.org/pub/scm/fs/xfs/xfs-linux · cd2286fc
      Linus Torvalds authored
      Pull xfs fix from Chandan Babu:
      
       - Fix read only mounts when using fsopen mount API
      
      * tag 'xfs-6.8-fixes-1' of git://git.kernel.org/pub/scm/fs/xfs/xfs-linux:
        xfs: read only mounts with fsopen mount API are busted
      cd2286fc
    • Linus Torvalds's avatar
      Merge tag 'bcachefs-2024-01-26' of https://evilpiepirate.org/git/bcachefs · 064a4a5b
      Linus Torvalds authored
      Pull bcachefs fixes from Kent Overstreet:
      
       - fix for REQ_OP_FLUSH usage; this fixes filesystems going read only
         with -EOPNOTSUPP from the block layer.
      
         (this really should have gone in with the block layer patch causing
         the -EOPNOTSUPP, or should have gone in before).
      
       - fix an allocation in non-sleepable context
      
       - fix one source of srcu lock latency, on devices with terrible discard
         latency
      
       - fix a reattach_inode() issue in fsck
      
      * tag 'bcachefs-2024-01-26' of https://evilpiepirate.org/git/bcachefs:
        bcachefs: __lookup_dirent() works in snapshot, not subvol
        bcachefs: discard path uses unlock_long()
        bcachefs: fix incorrect usage of REQ_OP_FLUSH
        bcachefs: Add gfp flags param to bch2_prt_task_backtrace()
      064a4a5b
    • Linus Torvalds's avatar
      Merge tag '6.8-rc2-smb3-server-fixes' of git://git.samba.org/ksmbd · 8c6f6a76
      Linus Torvalds authored
      Pull smb server fixes from Steve French:
      
       - Fix netlink OOB
      
       - Minor kernel doc fix
      
      * tag '6.8-rc2-smb3-server-fixes' of git://git.samba.org/ksmbd:
        ksmbd: fix global oob in ksmbd_nl_policy
        smb: Fix some kernel-doc comments
      8c6f6a76
    • Linus Torvalds's avatar
      Merge tag '6.8-rc1-smb3-client-fixes' of git://git.samba.org/sfrench/cifs-2.6 · d1bba17e
      Linus Torvalds authored
      Pull smb client fixes from Steve French:
       "Nine cifs/smb client fixes
      
         - Four network error fixes (three relating to replays of requests
           that need to be retried, and one fixing some places where we were
           returning the wrong rc up the stack on network errors)
      
         - Two multichannel fixes including locking fix and case where subset
           of channels need reconnect
      
         - netfs integration fixup: share remote i_size with netfslib
      
         - Two small cleanups (one for addressing a clang warning)"
      
      * tag '6.8-rc1-smb3-client-fixes' of git://git.samba.org/sfrench/cifs-2.6:
        cifs: fix stray unlock in cifs_chan_skip_or_disable
        cifs: set replay flag for retries of write command
        cifs: commands that are retried should have replay flag set
        cifs: helper function to check replayable error codes
        cifs: translate network errors on send to -ECONNABORTED
        cifs: cifs_pick_channel should try selecting active channels
        cifs: Share server EOF pos with netfslib
        smb: Work around Clang __bdos() type confusion
        smb: client: delete "true", "false" defines
      d1bba17e
  4. Jan 27, 2024