1. Dec 22, 2023
    • Randy Dunlap's avatar
      efi: memmap: fix kernel-doc warnings · 4afa688d
      Randy Dunlap authored
      
      
      Correct all kernel-doc notation to repair warnings that are
      reported by scripts/kernel-doc:
      
      memmap.c:38: warning: No description found for return value of '__efi_memmap_init'
      memmap.c:82: warning: No description found for return value of 'efi_memmap_init_early'
      memmap.c:132: warning: Function parameter or member 'addr' not described in 'efi_memmap_init_late'
      memmap.c:132: warning: Excess function parameter 'phys_addr' description in 'efi_memmap_init_late'
      memmap.c:132: warning: No description found for return value of 'efi_memmap_init_late'
      
      Signed-off-by: default avatarRandy Dunlap <rdunlap@infradead.org>
      Cc: Ard Biesheuvel <ardb@kernel.org>
      Cc: linux-efi@vger.kernel.org
      Signed-off-by: default avatarArd Biesheuvel <ardb@kernel.org>
      4afa688d
  2. Dec 19, 2023
  3. Dec 12, 2023
    • Ard Biesheuvel's avatar
      efi/x86: Avoid physical KASLR on older Dell systems · 50d7cdf7
      Ard Biesheuvel authored
      River reports boot hangs with v6.6 and v6.7, and the bisect points to
      commit
      
        a1b87d54 ("x86/efistub: Avoid legacy decompressor when doing EFI boot")
      
      which moves the memory allocation and kernel decompression from the
      legacy decompressor (which executes *after* ExitBootServices()) to the
      EFI stub, using boot services for allocating the memory. The memory
      allocation succeeds but the subsequent call to decompress_kernel() never
      returns, resulting in a failed boot and a hanging system.
      
      As it turns out, this issue only occurs when physical address
      randomization (KASLR) is enabled, and given that this is a feature we
      can live without (virtual KASLR is much more important), let's disable
      the physical part of KASLR when booting on AMI UEFI firmware claiming to
      implement revision v2.0 of the specification (which was released in
      2006), as this is the version these systems advertise.
      
      Fixes: a1b87d54 ("x86/efistub: Avoid legacy decompressor when doing EFI boot")
      Closes: https://bugzilla.kernel.org/show_bug.cgi?id=218173
      
      
      Signed-off-by: default avatarArd Biesheuvel <ardb@kernel.org>
      50d7cdf7
  4. Dec 11, 2023
    • Masahisa Kojima's avatar
      efivarfs: automatically update super block flag · 94f7f618
      Masahisa Kojima authored
      
      
      efivar operation is updated when the tee_stmm_efi module is probed.
      tee_stmm_efi module supports SetVariable runtime service, but user needs
      to manually remount the efivarfs as RW to enable the write access if the
      previous efivar operation does not support SetVariable and efivarfs is
      mounted as read-only.
      
      This commit notifies the update of efivar operation to efivarfs
      subsystem, then drops SB_RDONLY flag if the efivar operation supports
      SetVariable.
      
      Signed-off-by: default avatarMasahisa Kojima <masahisa.kojima@linaro.org>
      [ardb: use per-superblock instance of the notifier block]
      Signed-off-by: default avatarArd Biesheuvel <ardb@kernel.org>
      94f7f618
    • Masahisa Kojima's avatar
      efi: Add tee-based EFI variable driver · c44b6be6
      Masahisa Kojima authored
      
      
      When the flash is not owned by the non-secure world, accessing the EFI
      variables is straight-forward and done via EFI Runtime Variable
      Services.  In this case, critical variables for system integrity and
      security are normally stored in the dedicated secure storage and can
      only be manipulated directly from the secure world.
      
      Usually, small embedded devices don't have the special dedicated secure
      storage. The eMMC device with an RPMB partition is becoming more common,
      and we can use this RPMB partition to store the EFI Variables.
      
      The eMMC device is typically owned by the non-secure world (Linux in our
      case). There is an existing solution utilizing eMMC RPMB partition for
      EFI Variables, it is implemented by interacting with TEE (OP-TEE in this
      case), StandaloneMM (as EFI Variable Service Pseudo TA), eMMC driver and
      tee-supplicant. The last piece is the tee-based variable access driver
      to interact with TEE and StandaloneMM.
      
      So let's add the kernel functions needed.
      
      This feature is implemented as a kernel module.  StMM PTA has
      TA_FLAG_DEVICE_ENUM_SUPP flag when registered to OP-TEE so that this
      tee_stmm_efi module is probed after tee-supplicant starts, since
      "SetVariable" EFI Runtime Variable Service requires to interact with
      tee-supplicant.
      
      Acked-by: default avatarSumit Garg <sumit.garg@linaro.org>
      Co-developed-by: default avatarIlias Apalodimas <ilias.apalodimas@linaro.org>
      Signed-off-by: default avatarIlias Apalodimas <ilias.apalodimas@linaro.org>
      Signed-off-by: default avatarMasahisa Kojima <masahisa.kojima@linaro.org>
      Signed-off-by: default avatarArd Biesheuvel <ardb@kernel.org>
      c44b6be6
    • Masahisa Kojima's avatar
      efi: Add EFI_ACCESS_DENIED status code · 1f71f37f
      Masahisa Kojima authored
      
      
      This commit adds the EFI_ACCESS_DENIED status code.
      
      Acked-by: default avatarSumit Garg <sumit.garg@linaro.org>
      Co-developed-by: default avatarIlias Apalodimas <ilias.apalodimas@linaro.org>
      Signed-off-by: default avatarIlias Apalodimas <ilias.apalodimas@linaro.org>
      Signed-off-by: default avatarMasahisa Kojima <masahisa.kojima@linaro.org>
      Signed-off-by: default avatarArd Biesheuvel <ardb@kernel.org>
      1f71f37f
    • Masahisa Kojima's avatar
      efi: expose efivar generic ops register function · 6bb3703a
      Masahisa Kojima authored
      
      
      This is a preparation for supporting efivar operations provided by other
      than efi subsystem.  Both register and unregister functions are exposed
      so that non-efi subsystem can revert the efi generic operation.
      
      Acked-by: default avatarSumit Garg <sumit.garg@linaro.org>
      Co-developed-by: default avatarIlias Apalodimas <ilias.apalodimas@linaro.org>
      Signed-off-by: default avatarIlias Apalodimas <ilias.apalodimas@linaro.org>
      Signed-off-by: default avatarMasahisa Kojima <masahisa.kojima@linaro.org>
      Signed-off-by: default avatarArd Biesheuvel <ardb@kernel.org>
      6bb3703a
    • Ard Biesheuvel's avatar
      efivarfs: Move efivarfs list into superblock s_fs_info · cdb46a8a
      Ard Biesheuvel authored
      
      
      syzbot reports issues with concurrent fsopen()/fsconfig() invocations on
      efivarfs, which are the result of the fact that the efivarfs list (which
      caches the names and GUIDs of existing EFI variables) is a global
      structure. In normal use, these issues are unlikely to trigger, even in
      the presence of multiple mounts of efivarfs, but the execution pattern
      used by the syzkaller reproducer may result in multiple instances of the
      superblock that share the global efivarfs list, and this causes list
      corruption when the list is reinitialized by one user while another is
      traversing it.
      
      So let's move the list head into the superblock s_fs_info field, so that
      it will never be shared between distinct instances of the superblock. In
      the common case, there will still be a single instance of this list, but
      in the artificial syzkaller case, no list corruption can occur any
      longer.
      
      Reported-by: default avatar <syzbot+1902c359bfcaf39c46f2@syzkaller.appspotmail.com>
      Signed-off-by: default avatarArd Biesheuvel <ardb@kernel.org>
      cdb46a8a
    • Ard Biesheuvel's avatar
      efivarfs: Free s_fs_info on unmount · 547713d5
      Ard Biesheuvel authored
      Now that we allocate a s_fs_info struct on fs context creation, we
      should ensure that we free it again when the superblock goes away.
      
      Fixes: 5329aa51
      
       ("efivarfs: Add uid/gid mount options")
      Signed-off-by: default avatarArd Biesheuvel <ardb@kernel.org>
      547713d5
    • Ard Biesheuvel's avatar
      efivarfs: Move efivar availability check into FS context init · d28076dd
      Ard Biesheuvel authored
      
      
      Instead of checking whether or not EFI variables are available when
      creating the superblock, check it one step earlier, when initializing
      the FS context for the mount. This way, no FS context will be created at
      all, and we can drop the second check at .kill_sb() time entirely.
      
      Signed-off-by: default avatarArd Biesheuvel <ardb@kernel.org>
      d28076dd
    • Ilias Apalodimas's avatar
      efivarfs: force RO when remounting if SetVariable is not supported · 0e8d2444
      Ilias Apalodimas authored
      If SetVariable at runtime is not supported by the firmware we never assign
      a callback for that function. At the same time mount the efivarfs as
      RO so no one can call that.  However, we never check the permission flags
      when someone remounts the filesystem as RW. As a result this leads to a
      crash looking like this:
      
      $ mount -o remount,rw /sys/firmware/efi/efivars
      $ efi-updatevar -f PK.auth PK
      
      [  303.279166] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000
      [  303.280482] Mem abort info:
      [  303.280854]   ESR = 0x0000000086000004
      [  303.281338]   EC = 0x21: IABT (current EL), IL = 32 bits
      [  303.282016]   SET = 0, FnV = 0
      [  303.282414]   EA = 0, S1PTW = 0
      [  303.282821]   FSC = 0x04: level 0 translation fault
      [  303.283771] user pgtable: 4k pages, 48-bit VAs, pgdp=000000004258c000
      [  303.284913] [0000000000000000] pgd=0000000000000000, p4d=0000000000000000
      [  303.286076] Internal error: Oops: 0000000086000004 [#1] PREEMPT SMP
      [  303.286936] Modules linked in: qrtr tpm_tis tpm_tis_core crct10dif_ce arm_smccc_trng rng_core drm fuse ip_tables x_tables ipv6
      [  303.288586] CPU: 1 PID: 755 Comm: efi-updatevar Not tainted 6.3.0-rc1-00108-gc7d0c4695c68 #1
      [  303.289748] Hardware name: Unknown Unknown Product/Unknown Product, BIOS 2023.04-00627-g88336918701d 04/01/2023
      [  303.291150] pstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
      [  303.292123] pc : 0x0
      [  303.292443] lr : efivar_set_variable_locked+0x74/0xec
      [  303.293156] sp : ffff800008673c10
      [  303.293619] x29: ffff800008673c10 x28: ffff0000037e8000 x27: 0000000000000000
      [  303.294592] x26: 0000000000000800 x25: ffff000002467400 x24: 0000000000000027
      [  303.295572] x23: ffffd49ea9832000 x22: ffff0000020c9800 x21: ffff000002467000
      [  303.296566] x20: 0000000000000001 x19: 00000000000007fc x18: 0000000000000000
      [  303.297531] x17: 0000000000000000 x16: 0000000000000000 x15: 0000aaaac807ab54
      [  303.298495] x14: ed37489f673633c0 x13: 71c45c606de13f80 x12: 47464259e219acf4
      [  303.299453] x11: ffff000002af7b01 x10: 0000000000000003 x9 : 0000000000000002
      [  303.300431] x8 : 0000000000000010 x7 : ffffd49ea8973230 x6 : 0000000000a85201
      [  303.301412] x5 : 0000000000000000 x4 : ffff0000020c9800 x3 : 00000000000007fc
      [  303.302370] x2 : 0000000000000027 x1 : ffff000002467400 x0 : ffff000002467000
      [  303.303341] Call trace:
      [  303.303679]  0x0
      [  303.303938]  efivar_entry_set_get_size+0x98/0x16c
      [  303.304585]  efivarfs_file_write+0xd0/0x1a4
      [  303.305148]  vfs_write+0xc4/0x2e4
      [  303.305601]  ksys_write+0x70/0x104
      [  303.306073]  __arm64_sys_write+0x1c/0x28
      [  303.306622]  invoke_syscall+0x48/0x114
      [  303.307156]  el0_svc_common.constprop.0+0x44/0xec
      [  303.307803]  do_el0_svc+0x38/0x98
      [  303.308268]  el0_svc+0x2c/0x84
      [  303.308702]  el0t_64_sync_handler+0xf4/0x120
      [  303.309293]  el0t_64_sync+0x190/0x194
      [  303.309794] Code: ???????? ???????? ???????? ???????? (????????)
      [  303.310612] ---[ end trace 0000000000000000 ]---
      
      Fix this by adding a .reconfigure() function to the fs operations which
      we can use to check the requested flags and deny anything that's not RO
      if the firmware doesn't implement SetVariable at runtime.
      
      Fixes: f88814cc
      
       ("efi/efivars: Expose RT service availability via efivars abstraction")
      Signed-off-by: default avatarIlias Apalodimas <ilias.apalodimas@linaro.org>
      Signed-off-by: default avatarArd Biesheuvel <ardb@kernel.org>
      0e8d2444
    • Wang Yao's avatar
      efi/loongarch: Use load address to calculate kernel entry address · 271f2a4a
      Wang Yao authored
      
      
      The efi_relocate_kernel() may load the PIE kernel to anywhere, the
      loaded address may not be equal to link address or
      EFI_KIMG_PREFERRED_ADDRESS.
      
      Acked-by: default avatarHuacai Chen <chenhuacai@loongson.cn>
      Signed-off-by: default avatarWang Yao <wangyao@lemote.com>
      Signed-off-by: default avatarArd Biesheuvel <ardb@kernel.org>
      271f2a4a
  5. Nov 28, 2023
  6. Nov 27, 2023
    • Linus Torvalds's avatar
      Linux 6.7-rc3 · 2cc14f52
      Linus Torvalds authored
      2cc14f52
    • Linus Torvalds's avatar
      Merge tag 'trace-v6.7-rc2' of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace · 5b2b1173
      Linus Torvalds authored
      Pull tracing fixes from Steven Rostedt::
       "Eventfs fixes:
      
         - With the usage of simple_recursive_remove() recommended by Al Viro,
           the code should not be calling "d_invalidate()" itself. Doing so is
           causing crashes. The code was calling d_invalidate() on the race of
           trying to look up a file while the parent was being deleted. This
           was detected, and the added dentry was having d_invalidate() called
           on it, but the deletion of the directory was also calling
           d_invalidate() on that same dentry.
      
         - A fix to not free the eventfs_inode (ei) until the last dput() was
           called on its ei->dentry made the ei->dentry exist even after it
           was marked for free by setting the ei->is_freed. But code elsewhere
           still was checking if ei->dentry was NULL if ei->is_freed is set
           and would trigger WARN_ON if that was the case. That's no longer
           true and there should not be any warnings when it is true.
      
         - Use GFP_NOFS for allocations done under eventfs_mutex. The
           eventfs_mutex can be taken on file system reclaim, make sure that
           allocations done under that mutex do not trigger file system
           reclaim.
      
         - Clean up code by moving the taking of inode_lock out of the helper
           functions and into where they are needed, and not use the parameter
           to know to take it or not. It must always be held but some callers
           of the helper function have it taken when they were called.
      
         - Warn if the inode_lock is not held in the helper functions.
      
         - Warn if eventfs_start_creating() is called without a parent. As
           eventfs is underneath tracefs, all files created will have a parent
           (the top one will have a tracefs parent).
      
        Tracing update:
      
         - Add Mathieu Desnoyers as an official reviewer of the tracing subsystem"
      
      * tag 'trace-v6.7-rc2' of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace:
        MAINTAINERS: TRACING: Add Mathieu Desnoyers as Reviewer
        eventfs: Make sure that parent->d_inode is locked in creating files/dirs
        eventfs: Do not allow NULL parent to eventfs_start_creating()
        eventfs: Move taking of inode_lock into dcache_dir_open_wrapper()
        eventfs: Use GFP_NOFS for allocation when eventfs_mutex is held
        eventfs: Do not invalidate dentry in create_file/dir_dentry()
        eventfs: Remove expectation that ei->is_freed means ei->dentry == NULL
      5b2b1173
    • Linus Torvalds's avatar
      Merge tag 'parisc-for-6.7-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/deller/parisc-linux · d2da77f4
      Linus Torvalds authored
      Pull parisc architecture fixes from Helge Deller:
       "This patchset fixes and enforces correct section alignments for the
        ex_table, altinstructions, parisc_unwind, jump_table and bug_table
        which are created by inline assembly.
      
        Due to not being correctly aligned at link & load time they can
        trigger unnecessarily the kernel unaligned exception handler at
        runtime. While at it, I switched the bug table to use relative
        addresses which reduces the size of the table by half on 64-bit.
      
        We still had the ENOSYM and EREMOTERELEASE errno symbols as left-overs
        from HP-UX, which now trigger build-issues with glibc. We can simply
        remove them.
      
        Most of the patches are tagged for stable kernel series.
      
        Summary:
      
         - Drop HP-UX ENOSYM and EREMOTERELEASE return codes to avoid glibc
           build issues
      
         - Fix section alignments for ex_table, altinstructions, parisc unwind
           table, jump_table and bug_table
      
         - Reduce size of bug_table on 64-bit kernel by using relative
           pointers"
      
      * tag 'parisc-for-6.7-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/deller/parisc-linux:
        parisc: Reduce size of the bug_table on 64-bit kernel by half
        parisc: Drop the HP-UX ENOSYM and EREMOTERELEASE error codes
        parisc: Use natural CPU alignment for bug_table
        parisc: Ensure 32-bit alignment on parisc unwind section
        parisc: Mark lock_aligned variables 16-byte aligned on SMP
        parisc: Mark jump_table naturally aligned
        parisc: Mark altinstructions read-only and 32-bit aligned
        parisc: Mark ex_table entries 32-bit aligned in uaccess.h
        parisc: Mark ex_table entries 32-bit aligned in assembly.h
      d2da77f4
    • Linus Torvalds's avatar
      Merge tag 'x86-urgent-2023-11-26' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip · 4892711a
      Linus Torvalds authored
      Pull x86 microcode fixes from Ingo Molnar:
       "Fix/enhance x86 microcode version reporting: fix the bootup log spam,
        and remove the driver version announcement to avoid version confusion
        when distros backport fixes"
      
      * tag 'x86-urgent-2023-11-26' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
        x86/microcode: Rework early revisions reporting
        x86/microcode: Remove the driver announcement and version
      4892711a
    • Linus Torvalds's avatar
      Merge tag 'perf-urgent-2023-11-26' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip · e81fe505
      Linus Torvalds authored
      Pull x86 perf event fix from Ingo Molnar:
       "Fix a bug in the Intel hybrid CPUs hardware-capabilities enumeration
        code resulting in non-working events on those platforms"
      
      * tag 'perf-urgent-2023-11-26' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
        perf/x86/intel: Correct incorrect 'or' operation for PMU capabilities
      e81fe505
    • Linus Torvalds's avatar
      Merge tag 'locking-urgent-2023-11-26' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip · 1d0dbc3d
      Linus Torvalds authored
      Pull locking fix from Ingo Molnar:
       "Fix lockdep block chain corruption resulting in KASAN warnings"
      
      * tag 'locking-urgent-2023-11-26' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
        lockdep: Fix block chain corruption
      1d0dbc3d
    • Linus Torvalds's avatar
      Merge tag '6.7-rc2-smb3-client-fixes' of git://git.samba.org/sfrench/cifs-2.6 · 4515866d
      Linus Torvalds authored
      Pull smb client fixes from Steve French:
      
       - use after free fix in releasing multichannel interfaces
      
       - fixes for special file types (report char, block, FIFOs properly when
         created e.g. by NFS to Windows)
      
       - fixes for reporting various special file types and symlinks properly
         when using SMB1
      
      * tag '6.7-rc2-smb3-client-fixes' of git://git.samba.org/sfrench/cifs-2.6:
        smb: client: introduce cifs_sfu_make_node()
        smb: client: set correct file type from NFS reparse points
        smb: client: introduce ->parse_reparse_point()
        smb: client: implement ->query_reparse_point() for SMB1
        cifs: fix use after free for iface while disabling secondary channels
      4515866d
  7. Nov 26, 2023
    • Linus Torvalds's avatar
      Merge tag 'usb-6.7-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/usb · 090472ed
      Linus Torvalds authored
      Pull USB / PHY / Thunderbolt fixes from Greg KH:
       "Here are a number of reverts, fixes, and new device ids for 6.7-rc3
        for the USB, PHY, and Thunderbolt driver subsystems. Include in here
        are:
      
         - reverts of some PHY drivers that went into 6.7-rc1 that shouldn't
           have been merged yet, the author is reworking them based on review
           comments as they were using older apis that shouldn't be used
           anymore for newer drivers
      
         - small thunderbolt driver fixes for reported issues
      
         - USB driver fixes for a variety of small issues in dwc3, typec,
           xhci, and other smaller drivers.
      
         - new device ids for usb-serial and onboard_usb_hub drivers.
      
        All of these have been in linux-next with no reported issues"
      
      * tag 'usb-6.7-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/usb: (33 commits)
        USB: serial: option: add Luat Air72*U series products
        USB: dwc3: qcom: fix ACPI platform device leak
        USB: dwc3: qcom: fix software node leak on probe errors
        USB: dwc3: qcom: fix resource leaks on probe deferral
        USB: dwc3: qcom: simplify wakeup interrupt setup
        USB: dwc3: qcom: fix wakeup after probe deferral
        dt-bindings: usb: qcom,dwc3: fix example wakeup interrupt types
        usb: misc: onboard-hub: add support for Microchip USB5744
        dt-bindings: usb: microchip,usb5744: Add second supply
        usb: misc: ljca: Fix enumeration error on Dell Latitude 9420
        USB: serial: option: add Fibocom L7xx modules
        USB: xhci-plat: fix legacy PHY double init
        usb: typec: tipd: Supply also I2C driver data
        usb: xhci-mtk: fix in-ep's start-split check failure
        usb: dwc3: set the dma max_seg_size
        usb: config: fix iteration issue in 'usb_get_bos_descriptor()'
        usb: dwc3: add missing of_node_put and platform_device_put
        USB: dwc2: write HCINT with INTMASK applied
        usb: misc: ljca: Drop _ADR support to get ljca children devices
        usb: cdnsp: Fix deadlock issue during using NCM gadget
        ...
      090472ed
    • Linus Torvalds's avatar
      Merge tag 'xfs-6.7-fixes-3' of git://git.kernel.org/pub/scm/fs/xfs/xfs-linux · b46ae77f
      Linus Torvalds authored
      Pull xfs fix from Chandan Babu:
      
       - Validate quota records recovered from the log before writing them to
         the disk.
      
      * tag 'xfs-6.7-fixes-3' of git://git.kernel.org/pub/scm/fs/xfs/xfs-linux:
        xfs: dquot recovery does not validate the recovered dquot
        xfs: clean up dqblk extraction
      b46ae77f
    • Linus Torvalds's avatar
      Merge tag 'arm64-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux · 2821c393
      Linus Torvalds authored
      Pull arm64 fixes from Catalin Marinas:
      
       - Fix "rodata=on" not disabling "rodata=full" on arm64
      
       - Add arm64 make dependency between vmlinuz.efi and Image, leading to
         occasional build failures previously (with parallel building)
      
       - Add newline to the output formatting of the za-fork kselftest
      
      * tag 'arm64-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux:
        arm64: add dependency between vmlinuz.efi and Image
        kselftest/arm64: Fix output formatting for za-fork
        arm64: mm: Fix "rodata=on" when CONFIG_RODATA_FULL_DEFAULT_ENABLED=y
      2821c393
    • Linus Torvalds's avatar
      Merge tag 'for-linus-6.7a-rc3-tag' of git://git.kernel.org/pub/scm/linux/kernel/git/xen/tip · 00cff7b2
      Linus Torvalds authored
      Pull xen fixes from Juergen Gross:
      
       - A small cleanup patch for the Xen privcmd driver
      
       - A fix for the swiotlb-xen driver which was missing the advertising of
         the maximum mapping length
      
       - A fix for Xen on Arm for a longstanding bug, which happened to occur
         only recently: a structure in percpu memory crossed a page boundary,
         which was rejected by the hypervisor
      
      * tag 'for-linus-6.7a-rc3-tag' of git://git.kernel.org/pub/scm/linux/kernel/git/xen/tip:
        arm/xen: fix xen_vcpu_info allocation alignment
        xen: privcmd: Replace zero-length array with flex-array member and use __counted_by
        swiotlb-xen: provide the "max_mapping_size" method
      00cff7b2
  8. Nov 25, 2023
    • Helge Deller's avatar
      parisc: Reduce size of the bug_table on 64-bit kernel by half · 43266838
      Helge Deller authored
      
      
      Enable GENERIC_BUG_RELATIVE_POINTERS which will store 32-bit relative
      offsets to the bug address and the source file name instead of 64-bit
      absolute addresses. This effectively reduces the size of the
      bug_table[] array by half on 64-bit kernels.
      
      Signed-off-by: default avatarHelge Deller <deller@gmx.de>
      43266838
    • Helge Deller's avatar
      parisc: Drop the HP-UX ENOSYM and EREMOTERELEASE error codes · e5f3e299
      Helge Deller authored
      
      
      Those return codes are only defined for the parisc architecture and
      are leftovers from when we wanted to be HP-UX compatible.
      
      They are not returned by any Linux kernel syscall but do trigger
      problems with the glibc strerrorname_np() and strerror() functions as
      reported in glibc issue #31080.
      
      There is no need to keep them, so simply remove them.
      
      Signed-off-by: default avatarHelge Deller <deller@gmx.de>
      Reported-by: default avatarBruno Haible <bruno@clisp.org>
      Closes: https://sourceware.org/bugzilla/show_bug.cgi?id=31080
      Cc: stable@vger.kernel.org
      e5f3e299
    • Helge Deller's avatar
      parisc: Use natural CPU alignment for bug_table · fe76a134
      Helge Deller authored
      
      
      Make sure that the __bug_table section gets 32- or 64-bit aligned,
      depending if a 32- or 64-bit kernel is being built.
      Mark it non-writeable and use .blockz instead of the .org assembler
      directive to pad the struct.
      
      Signed-off-by: default avatarHelge Deller <deller@gmx.de>
      Cc: stable@vger.kernel.org   # v6.0+
      fe76a134
    • Helge Deller's avatar
      parisc: Ensure 32-bit alignment on parisc unwind section · c9fcb2b6
      Helge Deller authored
      
      
      Make sure the .PARISC.unwind section will be 32-bit aligned.
      
      Signed-off-by: default avatarHelge Deller <deller@gmx.de>
      Cc: stable@vger.kernel.org   # v6.0+
      c9fcb2b6
    • Helge Deller's avatar
      parisc: Mark lock_aligned variables 16-byte aligned on SMP · b28fc0d8
      Helge Deller authored
      
      
      On parisc we need 16-byte alignment for variables which are used for
      locking. Mark the __lock_aligned attribute acordingly so that the
      .data..lock_aligned section will get that alignment in the generated
      object files.
      
      Signed-off-by: default avatarHelge Deller <deller@gmx.de>
      Cc: stable@vger.kernel.org   # v6.0+
      b28fc0d8
    • Helge Deller's avatar
      parisc: Mark jump_table naturally aligned · 07eecff8
      Helge Deller authored
      
      
      The jump_table stores two 32-bit words and one 32- (on 32-bit kernel)
      or one 64-bit word (on 64-bit kernel).
      Ensure that the last word is always 64-bit aligned on a 64-bit kernel
      by aligning the whole structure on sizeof(long).
      
      Signed-off-by: default avatarHelge Deller <deller@gmx.de>
      Cc: stable@vger.kernel.org   # v6.0+
      07eecff8
    • Helge Deller's avatar
      parisc: Mark altinstructions read-only and 32-bit aligned · 33f806da
      Helge Deller authored
      
      
      Signed-off-by: default avatarHelge Deller <deller@gmx.de>
      Cc: stable@vger.kernel.org   # v6.0+
      33f806da
    • Helge Deller's avatar
      parisc: Mark ex_table entries 32-bit aligned in uaccess.h · a80aeb86
      Helge Deller authored
      
      
      Add an align statement to tell the linker that all ex_table entries and as
      such the whole ex_table section should be 32-bit aligned in vmlinux and modules.
      
      Signed-off-by: default avatarHelge Deller <deller@gmx.de>
      Cc: stable@vger.kernel.org   # v6.0+
      a80aeb86
    • Helge Deller's avatar
      parisc: Mark ex_table entries 32-bit aligned in assembly.h · e11d4ccc
      Helge Deller authored
      
      
      Add an align statement to tell the linker that all ex_table entries and as
      such the whole ex_table section should be 32-bit aligned in vmlinux and modules.
      
      Signed-off-by: default avatarHelge Deller <deller@gmx.de>
      Cc: stable@vger.kernel.org   # v6.0+
      e11d4ccc
    • Linus Torvalds's avatar
      Merge tag 's390-6.7-3' of git://git.kernel.org/pub/scm/linux/kernel/git/s390/linux · 0f5cc96c
      Linus Torvalds authored
      Pull s390 updates from Alexander Gordeev:
      
       - Remove unnecessary assignment of the performance event last_tag.
      
       - Create missing /sys/firmware/ipl/* attributes when kernel is booted
         in dump mode using List-directed ECKD IPL.
      
       - Remove odd comment.
      
       - Fix s390-specific part of scripts/checkstack.pl script that only
         matches three-digit numbers starting with 3 or any higher number and
         skips any stack sizes smaller than 304 bytes.
      
      * tag 's390-6.7-3' of git://git.kernel.org/pub/scm/linux/kernel/git/s390/linux:
        scripts/checkstack.pl: match all stack sizes for s390
        s390: remove odd comment
        s390/ipl: add missing IPL_TYPE_ECKD_DUMP case to ipl_init()
        s390/pai: cleanup event initialization
      0f5cc96c
    • Linus Torvalds's avatar
      Merge tag 'acpi-6.7-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/rafael/linux-pm · 1bcc6897
      Linus Torvalds authored
      Pull ACPI fixes from Rafael Wysocki:
       "These add an ACPI IRQ override quirk for ASUS ExpertBook B1402CVA and
        fix an ACPI processor idle issue leading to triple-faults in Xen HVM
        guests and an ACPI backlight driver issue that causes GPUs to
        misbehave while their children power is being fixed up.
      
        Specifics:
      
         - Avoid powering up GPUs while attempting to fix up power for their
           children (Hans de Goede)
      
         - Use raw_safe_halt() instead of safe_halt() in acpi_idle_play_dead()
           so as to avoid triple-falts during CPU online in Xen HVM guests due
           to the setting of the hardirqs_enabled flag in safe_halt() (David
           Woodhouse)
      
         - Add an ACPI IRQ override quirk for ASUS ExpertBook B1402CVA (Hans
           de Goede)"
      
      * tag 'acpi-6.7-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/rafael/linux-pm:
        ACPI: resource: Skip IRQ override on ASUS ExpertBook B1402CVA
        ACPI: video: Use acpi_device_fix_up_power_children()
        ACPI: PM: Add acpi_device_fix_up_power_children() function
        ACPI: processor_idle: use raw_safe_halt() in acpi_idle_play_dead()
      1bcc6897
    • Linus Torvalds's avatar
      Merge tag 'pm-6.7-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/rafael/linux-pm · b345fd55
      Linus Torvalds authored
      Pull power management fix from Rafael Wysocki:
       "Fix a syntax error in the sleepgraph utility which causes it to exit
        early on every invocation (David Woodhouse)"
      
      * tag 'pm-6.7-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/rafael/linux-pm:
        PM: tools: Fix sleepgraph syntax error
      b345fd55
    • Linus Torvalds's avatar
      Merge tag 'afs-fixes-20231124' of git://git.kernel.org/pub/scm/linux/kernel/git/dhowells/linux-fs · 5b7ad877
      Linus Torvalds authored
      Pull AFS fixes from David Howells:
      
       - Fix the afs_server_list struct to be cleaned up with RCU
      
       - Fix afs to translate a no-data result from a DNS lookup into ENOENT,
         not EDESTADDRREQ for consistency with OpenAFS
      
       - Fix afs to translate a negative DNS lookup result into ENOENT rather
         than EDESTADDRREQ
      
       - Fix file locking on R/O volumes to operate in local mode as the
         server doesn't handle exclusive locks on such files
      
       - Set SB_RDONLY on superblocks for RO and Backup volumes so that the
         VFS can see that they're read only
      
      * tag 'afs-fixes-20231124' of git://git.kernel.org/pub/scm/linux/kernel/git/dhowells/linux-fs:
        afs: Mark a superblock for an R/O or Backup volume as SB_RDONLY
        afs: Fix file locking on R/O volumes to operate in local mode
        afs: Return ENOENT if no cell DNS record can be found
        afs: Make error on cell lookup failure consistent with OpenAFS
        afs: Fix afs_server_list to be cleaned up with RCU
      5b7ad877
    • Rafael J. Wysocki's avatar
      Merge branches 'acpi-video' and 'acpi-processor' into acpi · e3747062
      Rafael J. Wysocki authored
      Merge ACPI backlight driver fixes and an ACPI processor driver fix for
      6.7-rc3:
      
       - Avoid powering up GPUs while attempting to fix up power for their
         children (Hans de Goede).
      
       - Use raw_safe_halt() instead of safe_halt() in acpi_idle_play_dead()
         so as to avoid triple-falts during CPU online in Xen HVM guests due
         to the setting of the hardirqs_enabled flag in safe_halt() (David
         Woodhouse).
      
      * acpi-video:
        ACPI: video: Use acpi_device_fix_up_power_children()
        ACPI: PM: Add acpi_device_fix_up_power_children() function
      
      * acpi-processor:
        ACPI: processor_idle: use raw_safe_halt() in acpi_idle_play_dead()
      e3747062
    • Linus Torvalds's avatar
      Merge tag 'vfs-6.7-rc3.fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/vfs/vfs · fa2b906f
      Linus Torvalds authored
      Pull vfs fixes from Christian Brauner:
      
       - Avoid calling back into LSMs from vfs_getattr_nosec() calls.
      
         IMA used to query inode properties accessing raw inode fields without
         dedicated helpers. That was finally fixed a few releases ago by
         forcing IMA to use vfs_getattr_nosec() helpers.
      
         The goal of the vfs_getattr_nosec() helper is to query for attributes
         without calling into the LSM layer which would be quite problematic
         because incredibly IMA is called from __fput()...
      
           __fput()
             -> ima_file_free()
      
         What it does is to call back into the filesystem to update the file's
         IMA xattr. Querying the inode without using vfs_getattr_nosec() meant
         that IMA didn't handle stacking filesystems such as overlayfs
         correctly. So the switch to vfs_getattr_nosec() is quite correct. But
         the switch to vfs_getattr_nosec() revealed another bug when used on
         stacking filesystems:
      
           __fput()
             -> ima_file_free()
                -> vfs_getattr_nosec()
                   -> i_op->getattr::ovl_getattr()
                      -> vfs_getattr()
                         -> i_op->getattr::$WHATEVER_UNDERLYING_FS_getattr()
                            -> security_inode_getattr() # calls back into LSMs
      
         Now, if that __fput() happens from task_work_run() of an exiting task
         current->fs and various other pointer could already be NULL. So
         anything in the LSM layer relying on that not being NULL would be
         quite surprised.
      
         Fix that by passing the information that this is a security request
         through to the stacking filesystem by adding a new internal
         ATT_GETATTR_NOSEC flag. Now the callchain becomes:
      
           __fput()
             -> ima_file_free()
                -> vfs_getattr_nosec()
                   -> i_op->getattr::ovl_getattr()
                      -> if (AT_GETATTR_NOSEC)
                                vfs_getattr_nosec()
                         else
                                vfs_getattr()
                         -> i_op->getattr::$WHATEVER_UNDERLYING_FS_getattr()
      
       - Fix a bug introduced with the iov_iter rework from last cycle.
      
         This broke /proc/kcore by copying too much and without the correct
         offset.
      
       - Add a missing NULL check when allocating the root inode in
         autofs_fill_super().
      
       - Fix stable writes for multi-device filesystems (xfs, btrfs etc) and
         the block device pseudo filesystem.
      
         Stable writes used to be a superblock flag only, making it a per
         filesystem property. Add an additional AS_STABLE_WRITES mapping flag
         to allow for fine-grained control.
      
       - Ensure that offset_iterate_dir() returns 0 after reaching the end of
         a directory so it adheres to getdents() convention.
      
      * tag 'vfs-6.7-rc3.fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/vfs/vfs:
        libfs: getdents() should return 0 after reaching EOD
        xfs: respect the stable writes flag on the RT device
        xfs: clean up FS_XFLAG_REALTIME handling in xfs_ioctl_setattr_xflags
        block: update the stable_writes flag in bdev_add
        filemap: add a per-mapping stable writes flag
        autofs: add: new_inode check in autofs_fill_super()
        iov_iter: fix copy_page_to_iter_nofault()
        fs: Pass AT_GETATTR_NOSEC flag to getattr interface function
      fa2b906f