1. Sep 16, 2019
    • Wenwen Wang's avatar
      ubifs: Fix memory leak in read_znode() error path · ce4d8b16
      Wenwen Wang authored
      In read_znode(), the indexing node 'idx' is allocated by kmalloc().
      However, it is not deallocated in the following execution if
      ubifs_node_check_hash() fails, leading to a memory leak bug. To fix this
      issue, free 'idx' before returning the error.
      
      Fixes: 16a26b20
      
       ("ubifs: authentication: Add hashes to index nodes")
      Signed-off-by: default avatarWenwen Wang <wenwen@cs.uga.edu>
      Signed-off-by: default avatarRichard Weinberger <richard@nod.at>
      ce4d8b16
    • Zhihao Cheng's avatar
      ubi: ubi_wl_get_peb: Increase the number of attempts while getting PEB · 8615b94f
      Zhihao Cheng authored
      
      
      Running stress test io_paral (A pressure ubi test in mtd-utils) on an
      UBI device with fewer PEBs (fastmap enabled) may cause ENOSPC errors and
      make UBI device read-only, but there are still free PEBs on the UBI
      device. This problem can be easily reproduced by performing the following
      steps on a 2-core machine:
        $ modprobe nandsim first_id_byte=0x20 second_id_byte=0x33 parts=80
        $ modprobe ubi mtd="0,0" fm_autoconvert
        $ ./io_paral /dev/ubi0
      
      We may see the following verbose:
      (output)
        [io_paral] update_volume():108: failed to write 380 bytes at offset
        95920 of volume 2
        [io_paral] update_volume():109: update: 97088 bytes
        [io_paral] write_thread():227: function pwrite() failed with error 28
        (No space left on device)
        [io_paral] write_thread():229: cannot write 15872 bytes to offs 31744,
        wrote -1
      (dmesg)
        ubi0 error: ubi_wl_get_peb [ubi]: Unable to get a free PEB from user WL
        pool
        ubi0 warning: ubi_eba_write_leb [ubi]: switch to read-only mode
        CPU: 0 PID: 2027 Comm: io_paral Not tainted 5.3.0-rc2-00001-g5986cd0 #9
        ubi0 warning: try_write_vid_and_data [ubi]: failed to write VID header
        to LEB 2:5, PEB 18
        Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.12.0
        -0-ga698c8995f-prebuilt.qemu.org 04/01/2014
        Call Trace:
          dump_stack+0x85/0xba
          ubi_eba_write_leb+0xa1e/0xa40 [ubi]
          vol_cdev_write+0x307/0x520 [ubi]
          vfs_write+0xfa/0x280
          ksys_pwrite64+0xc5/0xe0
          __x64_sys_pwrite64+0x22/0x30
          do_syscall_64+0xbf/0x440
      
      In function ubi_wl_get_peb, the operation of filling the pool
      (ubi_update_fastmap) with free PEBs and fetching a free PEB from the pool
      is not atomic. After thread A filling the pool with free PEB, free PEB may
      be taken away by thread B. When thread A checks the expression again, the
      condition is still unsatisfactory. At this time, there may still be free
      PEBs on UBI that can be filled into the pool.
      
      This patch increases the number of attempts to obtain PEB. An extreme
      case (No free PEBs left after creating test volumes) has been tested on
      different type of machines for 100 times. The biggest number of attempts
      are shown below:
      
                   x86_64     arm64
        2-core        4         4
        4-core        8         4
        8-core        4         4
      
      Signed-off-by: default avatarZhihao Cheng <chengzhihao1@huawei.com>
      Signed-off-by: default avatarRichard Weinberger <richard@nod.at>
      8615b94f
    • Richard Weinberger's avatar
      ubi: Don't do anchor move within fastmap area · 8596813a
      Richard Weinberger authored
      
      
      To make sure that Fastmap can use a PEB within the first 64
      PEBs, UBI moves blocks away from that area.
      It uses regular wear-leveling for that job.
      
      An anchor move can be triggered if no PEB is free in this area
      or because of anticipation. In the latter case it can happen
      that UBI decides to move a block but finds a free PEB
      within the same area.
      This case is in vain an increases only erase counters.
      
      Catch this case and cancel wear-leveling if this happens.
      
      Signed-off-by: default avatarRichard Weinberger <richard@nod.at>
      8596813a
    • Colin Ian King's avatar
      ubifs: Remove redundant assignment to pointer fname · cbc898d5
      Colin Ian King authored
      
      
      The pointer fname is being assigned with a value that is never
      read because the function returns after the assignment. The assignment
      is redundant and can be removed.
      
      Addresses-Coverity: ("Unused value")
      Signed-off-by: default avatarColin Ian King <colin.king@canonical.com>
      Signed-off-by: default avatarRichard Weinberger <richard@nod.at>
      cbc898d5
  2. Sep 03, 2019
    • Linus Torvalds's avatar
      Linux 5.3-rc7 · 089cf7f6
      Linus Torvalds authored
      089cf7f6
    • Linus Torvalds's avatar
      Merge tag 'char-misc-5.3-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc · 49ffdb4c
      Linus Torvalds authored
      Pull char/misc driver fixes from Greg KH:
       "Here are some small char and misc driver fixes for reported issues for
        5.3-rc7
      
        Also included in here is the documentation for how we are handling
        hardware issues under embargo that everyone has finally agreed on, as
        well as a MAINTAINERS update for the suckers who agreed to handle the
        LICENSES/ files.
      
        All of these have been in linux-next last week with no reported
        issues"
      
      * tag 'char-misc-5.3-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc:
        fsi: scom: Don't abort operations for minor errors
        vmw_balloon: Fix offline page marking with compaction
        VMCI: Release resource if the work is already queued
        Documentation/process: Embargoed hardware security issues
        lkdtm/bugs: fix build error in lkdtm_EXHAUST_STACK
        mei: me: add Tiger Lake point LP device ID
        intel_th: pci: Add Tiger Lake support
        intel_th: pci: Add support for ...
      49ffdb4c
    • Linus Torvalds's avatar
      Merge tag 'usb-5.3-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/usb · 2c248f92
      Linus Torvalds authored
      Pull USB fixes from Greg KH:
       "Here are some small USB fixes that have been in linux-next this past
        week for 5.3-rc7
      
        They fix the usual xhci, syzbot reports, and other small issues that
        have come up last week.
      
        All have been in linux-next with no reported issues"
      
      * tag 'usb-5.3-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/usb:
        USB: cdc-wdm: fix race between write and disconnect due to flag abuse
        usb: host: xhci: rcar: Fix typo in compatible string matching
        usb: host: xhci-tegra: Set DMA mask correctly
        USB: storage: ums-realtek: Whitelist auto-delink support
        USB: storage: ums-realtek: Update module parameter description for auto_delink_en
        usb: host: ohci: fix a race condition between shutdown and irq
        usb: hcd: use managed device resources
        typec: tcpm: fix a typo in the comparison of pdo_max_voltage
        usb-storage: Add new JMS567 revision to unusual_devs
        usb: chipidea: udc: don't do hardware access if gadget has stopped
        usbtmc: more sanity checking for packet size
        usb: udc: lpc32xx: silence fall-through warning
      2c248f92
  3. Sep 02, 2019
    • Linus Torvalds's avatar
      Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net · 345464fb
      Linus Torvalds authored
      Pull networking fixes from David Miller:
      
       1) Fix some length checks during OGM processing in batman-adv, from
          Sven Eckelmann.
      
       2) Fix regression that caused netfilter conntrack sysctls to not be
          per-netns any more. From Florian Westphal.
      
       3) Use after free in netpoll, from Feng Sun.
      
       4) Guard destruction of pfifo_fast per-cpu qdisc stats with
          qdisc_is_percpu_stats(), from Davide Caratti. Similar bug is fixed
          in pfifo_fast_enqueue().
      
       5) Fix memory leak in mld_del_delrec(), from Eric Dumazet.
      
       6) Handle neigh events on internal ports correctly in nfp, from John
          Hurley.
      
       7) Clear SKB timestamp in NF flow table code so that it does not
          confuse fq scheduler. From Florian Westphal.
      
       8) taprio destroy can crash if it is invoked in a failure path of
          taprio_init(), because the list head isn't setup properly yet and
          the list del is unconditional. Perform the list add earlier to
          address this. From Vladimir Olt...
      345464fb
    • Christophe JAILLET's avatar
      net: seeq: Fix the function used to release some memory in an error handling path · e1e54ec7
      Christophe JAILLET authored
      In commit 99cd149e ("sgiseeq: replace use of dma_cache_wback_inv"),
      a call to 'get_zeroed_page()' has been turned into a call to
      'dma_alloc_coherent()'. Only the remove function has been updated to turn
      the corresponding 'free_page()' into 'dma_free_attrs()'.
      The error hndling path of the probe function has not been updated.
      
      Fix it now.
      
      Rename the corresponding label to something more in line.
      
      Fixes: 99cd149e
      
       ("sgiseeq: replace use of dma_cache_wback_inv")
      Signed-off-by: default avatarChristophe JAILLET <christophe.jaillet@wanadoo.fr>
      Reviewed-by: default avatarThomas Bogendoerfer <tbogendoerfer@suse.de>
      Signed-off-by: default avatarDavid S. Miller <davem@davemloft.net>
      e1e54ec7
    • Linus Torvalds's avatar
      Merge branch 'x86-urgent-for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip · 9f159ae0
      Linus Torvalds authored
      Pull x86 fixes from Thomas Gleixner:
       "A set of fixes for x86:
      
         - Fix the bogus detection of 32bit user mode for uretprobes which
           caused corruption of the user return address resulting in
           application crashes. In the uprobes handler in_ia32_syscall() is
           obviously always returning false on a 64bit kernel. Use
           user_64bit_mode() instead which works correctly.
      
         - Prevent large page splitting when ftrace flips RW/RO on the kernel
           text which caused iTLB performance issues. Ftrace wants to be
           converted to text_poke() which avoids the problem, but for now
           allow large page preservation in the static protections check when
           the change request spawns a full large page.
      
         - Prevent arch_dynirq_lower_bound() from returning 0 when the IOAPIC
           is configured via device tree. In the device tree case the GSI 1:1
           mapping is meaningless therefore the lower bound which protects th...
      9f159ae0
    • Linus Torvalds's avatar
      Merge branch 'perf-urgent-for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip · 5fb181cb
      Linus Torvalds authored
      Pull perf fixes from Thomas Gleixner:
       "Two fixes for perf x86 hardware implementations:
      
         - Restrict the period on Nehalem machines to prevent perf from
           hogging the CPU
      
         - Prevent the AMD IBS driver from overwriting the hardwre controlled
           and pre-seeded reserved bits (0-6) in the count register which
           caused a sample bias for dispatched micro-ops"
      
      * 'perf-urgent-for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
        perf/x86/amd/ibs: Fix sample bias for dispatched micro-ops
        perf/x86/intel: Restrict period on Nehalem
      5fb181cb
    • Linus Torvalds's avatar
      Merge branch 'turbostat' of git://git.kernel.org/pub/scm/linux/kernel/git/lenb/linux · 5358e6e7
      Linus Torvalds authored
      Pull turbostat updates from Len Brown:
       "User-space turbostat (and x86_energy_perf_policy) patches.
      
        They are primarily bug fixes from users"
      
      * 'turbostat' of git://git.kernel.org/pub/scm/linux/kernel/git/lenb/linux:
        tools/power turbostat: update version number
        tools/power turbostat: Add support for Hygon Fam 18h (Dhyana) RAPL
        tools/power turbostat: Fix caller parameter of get_tdp_amd()
        tools/power turbostat: Fix CPU%C1 display value
        tools/power turbostat: do not enforce 1ms
        tools/power turbostat: read from pipes too
        tools/power turbostat: Add Ice Lake NNPI support
        tools/power turbostat: rename has_hsw_msrs()
        tools/power turbostat: Fix Haswell Core systems
        tools/power turbostat: add Jacobsville support
        tools/power turbostat: fix buffer overrun
        tools/power turbostat: fix file descriptor leaks
        tools/power turbostat: fix leak of file descriptor on error return path
        tools/power turbostat: Make interval calculation per thread to reduce jitter
        tools/power turbostat: remove duplicate pc10 column
        tools/power x86_energy_perf_policy: Fix argument parsing
        tools/power: Fix typo in man page
        tools/power/x86: Enable compiler optimisations and Fortify by default
        tools/power x86_energy_perf_policy: Fix "uninitialized variable" warnings at -O2
      5358e6e7
  4. Sep 01, 2019