<feed xmlns='http://www.w3.org/2005/Atom'>
<title>linux-stable.git/drivers/char, branch linux-4.17.y</title>
<subtitle>Linux kernel stable tree</subtitle>
<link rel='alternate' type='text/html' href='https://git.tavy.me/linux-stable.git/'/>
<entry>
<title>ipmi: kcs_bmc: fix IRQ exception if the channel is not open</title>
<updated>2018-08-24T11:06:49+00:00</updated>
<author>
<name>Haiyue Wang</name>
<email>haiyue.wang@linux.intel.com</email>
</author>
<published>2018-06-23T13:51:13+00:00</published>
<link rel='alternate' type='text/html' href='https://git.tavy.me/linux-stable.git/commit/?id=9d8dc2ca73373aa2d8c80fad300267d7a6d349ed'/>
<id>9d8dc2ca73373aa2d8c80fad300267d7a6d349ed</id>
<content type='text'>
[ Upstream commit dc0f0a026d33819bb82d5c26ab2fca838e2004be ]

When kcs_bmc_handle_event calls kcs_force_abort function to handle the
not open (no user running) KCS channel transaction, the returned status
value -ENODEV causes the low level IRQ handler indicating that the irq
was not for him by returning IRQ_NONE. After some time, this IRQ will
be treated to be spurious one, and the exception dump happens.

   irq 30: nobody cared (try booting with the "irqpoll" option)
   CPU: 0 PID: 0 Comm: swapper/0 Not tainted 4.10.15-npcm750 #1
   Hardware name: NPCMX50 Chip family
   [&lt;c010b264&gt;] (unwind_backtrace) from [&lt;c0106930&gt;] (show_stack+0x20/0x24)
   [&lt;c0106930&gt;] (show_stack) from [&lt;c03dad38&gt;] (dump_stack+0x8c/0xa0)
   [&lt;c03dad38&gt;] (dump_stack) from [&lt;c0168810&gt;] (__report_bad_irq+0x3c/0xdc)
   [&lt;c0168810&gt;] (__report_bad_irq) from [&lt;c0168c34&gt;] (note_interrupt+0x29c/0x2ec)
   [&lt;c0168c34&gt;] (note_interrupt) from [&lt;c0165c80&gt;] (handle_irq_event_percpu+0x5c/0x68)
   [&lt;c0165c80&gt;] (handle_irq_event_percpu) from [&lt;c0165cd4&gt;] (handle_irq_event+0x48/0x6c)
   [&lt;c0165cd4&gt;] (handle_irq_event) from [&lt;c0169664&gt;] (handle_fasteoi_irq+0xc8/0x198)
   [&lt;c0169664&gt;] (handle_fasteoi_irq) from [&lt;c016529c&gt;] (__handle_domain_irq+0x90/0xe8)
   [&lt;c016529c&gt;] (__handle_domain_irq) from [&lt;c01014bc&gt;] (gic_handle_irq+0x58/0x9c)
   [&lt;c01014bc&gt;] (gic_handle_irq) from [&lt;c010752c&gt;] (__irq_svc+0x6c/0x90)
   Exception stack(0xc0a01de8 to 0xc0a01e30)
   1de0:                   00002080 c0a6fbc0 00000000 00000000 00000000 c096d294
   1e00: 00000000 00000001 dc406400 f03ff100 00000082 c0a01e94 c0a6fbc0 c0a01e38
   1e20: 00200102 c01015bc 60000113 ffffffff
   [&lt;c010752c&gt;] (__irq_svc) from [&lt;c01015bc&gt;] (__do_softirq+0xbc/0x358)
   [&lt;c01015bc&gt;] (__do_softirq) from [&lt;c011c798&gt;] (irq_exit+0xb8/0xec)
   [&lt;c011c798&gt;] (irq_exit) from [&lt;c01652a0&gt;] (__handle_domain_irq+0x94/0xe8)
   [&lt;c01652a0&gt;] (__handle_domain_irq) from [&lt;c01014bc&gt;] (gic_handle_irq+0x58/0x9c)
   [&lt;c01014bc&gt;] (gic_handle_irq) from [&lt;c010752c&gt;] (__irq_svc+0x6c/0x90)
   Exception stack(0xc0a01ef8 to 0xc0a01f40)
   1ee0:                                                       00000000 000003ae
   1f00: dcc0f338 c0111060 c0a00000 c0a0cc44 c0a0cbe4 c0a1c22b c07bc218 00000001
   1f20: dcffca40 c0a01f54 c0a01f58 c0a01f48 c0103524 c0103528 60000013 ffffffff
   [&lt;c010752c&gt;] (__irq_svc) from [&lt;c0103528&gt;] (arch_cpu_idle+0x48/0x4c)
   [&lt;c0103528&gt;] (arch_cpu_idle) from [&lt;c0681390&gt;] (default_idle_call+0x30/0x3c)
   [&lt;c0681390&gt;] (default_idle_call) from [&lt;c0156f24&gt;] (do_idle+0xc8/0x134)
   [&lt;c0156f24&gt;] (do_idle) from [&lt;c015722c&gt;] (cpu_startup_entry+0x28/0x2c)
   [&lt;c015722c&gt;] (cpu_startup_entry) from [&lt;c067ad74&gt;] (rest_init+0x84/0x88)
   [&lt;c067ad74&gt;] (rest_init) from [&lt;c0900d44&gt;] (start_kernel+0x388/0x394)
   [&lt;c0900d44&gt;] (start_kernel) from [&lt;0000807c&gt;] (0x807c)
   handlers:
   [&lt;c041c5dc&gt;] npcm7xx_kcs_irq
   Disabling IRQ #30

It needs to change the returned status from -ENODEV to 0. The -ENODEV
was originally used to tell the low level IRQ handler that no user was
running, but not consider the IRQ handling desgin.

And multiple KCS channels share one IRQ handler, it needs to check the
IBF flag before doing force abort. If the IBF is set, after handling,
return 0 to low level IRQ handler to indicate that the IRQ is handled.

Signed-off-by: Haiyue Wang &lt;haiyue.wang@linux.intel.com&gt;
Signed-off-by: Corey Minyard &lt;cminyard@mvista.com&gt;
Signed-off-by: Sasha Levin &lt;alexander.levin@microsoft.com&gt;
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
[ Upstream commit dc0f0a026d33819bb82d5c26ab2fca838e2004be ]

When kcs_bmc_handle_event calls kcs_force_abort function to handle the
not open (no user running) KCS channel transaction, the returned status
value -ENODEV causes the low level IRQ handler indicating that the irq
was not for him by returning IRQ_NONE. After some time, this IRQ will
be treated to be spurious one, and the exception dump happens.

   irq 30: nobody cared (try booting with the "irqpoll" option)
   CPU: 0 PID: 0 Comm: swapper/0 Not tainted 4.10.15-npcm750 #1
   Hardware name: NPCMX50 Chip family
   [&lt;c010b264&gt;] (unwind_backtrace) from [&lt;c0106930&gt;] (show_stack+0x20/0x24)
   [&lt;c0106930&gt;] (show_stack) from [&lt;c03dad38&gt;] (dump_stack+0x8c/0xa0)
   [&lt;c03dad38&gt;] (dump_stack) from [&lt;c0168810&gt;] (__report_bad_irq+0x3c/0xdc)
   [&lt;c0168810&gt;] (__report_bad_irq) from [&lt;c0168c34&gt;] (note_interrupt+0x29c/0x2ec)
   [&lt;c0168c34&gt;] (note_interrupt) from [&lt;c0165c80&gt;] (handle_irq_event_percpu+0x5c/0x68)
   [&lt;c0165c80&gt;] (handle_irq_event_percpu) from [&lt;c0165cd4&gt;] (handle_irq_event+0x48/0x6c)
   [&lt;c0165cd4&gt;] (handle_irq_event) from [&lt;c0169664&gt;] (handle_fasteoi_irq+0xc8/0x198)
   [&lt;c0169664&gt;] (handle_fasteoi_irq) from [&lt;c016529c&gt;] (__handle_domain_irq+0x90/0xe8)
   [&lt;c016529c&gt;] (__handle_domain_irq) from [&lt;c01014bc&gt;] (gic_handle_irq+0x58/0x9c)
   [&lt;c01014bc&gt;] (gic_handle_irq) from [&lt;c010752c&gt;] (__irq_svc+0x6c/0x90)
   Exception stack(0xc0a01de8 to 0xc0a01e30)
   1de0:                   00002080 c0a6fbc0 00000000 00000000 00000000 c096d294
   1e00: 00000000 00000001 dc406400 f03ff100 00000082 c0a01e94 c0a6fbc0 c0a01e38
   1e20: 00200102 c01015bc 60000113 ffffffff
   [&lt;c010752c&gt;] (__irq_svc) from [&lt;c01015bc&gt;] (__do_softirq+0xbc/0x358)
   [&lt;c01015bc&gt;] (__do_softirq) from [&lt;c011c798&gt;] (irq_exit+0xb8/0xec)
   [&lt;c011c798&gt;] (irq_exit) from [&lt;c01652a0&gt;] (__handle_domain_irq+0x94/0xe8)
   [&lt;c01652a0&gt;] (__handle_domain_irq) from [&lt;c01014bc&gt;] (gic_handle_irq+0x58/0x9c)
   [&lt;c01014bc&gt;] (gic_handle_irq) from [&lt;c010752c&gt;] (__irq_svc+0x6c/0x90)
   Exception stack(0xc0a01ef8 to 0xc0a01f40)
   1ee0:                                                       00000000 000003ae
   1f00: dcc0f338 c0111060 c0a00000 c0a0cc44 c0a0cbe4 c0a1c22b c07bc218 00000001
   1f20: dcffca40 c0a01f54 c0a01f58 c0a01f48 c0103524 c0103528 60000013 ffffffff
   [&lt;c010752c&gt;] (__irq_svc) from [&lt;c0103528&gt;] (arch_cpu_idle+0x48/0x4c)
   [&lt;c0103528&gt;] (arch_cpu_idle) from [&lt;c0681390&gt;] (default_idle_call+0x30/0x3c)
   [&lt;c0681390&gt;] (default_idle_call) from [&lt;c0156f24&gt;] (do_idle+0xc8/0x134)
   [&lt;c0156f24&gt;] (do_idle) from [&lt;c015722c&gt;] (cpu_startup_entry+0x28/0x2c)
   [&lt;c015722c&gt;] (cpu_startup_entry) from [&lt;c067ad74&gt;] (rest_init+0x84/0x88)
   [&lt;c067ad74&gt;] (rest_init) from [&lt;c0900d44&gt;] (start_kernel+0x388/0x394)
   [&lt;c0900d44&gt;] (start_kernel) from [&lt;0000807c&gt;] (0x807c)
   handlers:
   [&lt;c041c5dc&gt;] npcm7xx_kcs_irq
   Disabling IRQ #30

It needs to change the returned status from -ENODEV to 0. The -ENODEV
was originally used to tell the low level IRQ handler that no user was
running, but not consider the IRQ handling desgin.

And multiple KCS channels share one IRQ handler, it needs to check the
IBF flag before doing force abort. If the IBF is set, after handling,
return 0 to low level IRQ handler to indicate that the IRQ is handled.

Signed-off-by: Haiyue Wang &lt;haiyue.wang@linux.intel.com&gt;
Signed-off-by: Corey Minyard &lt;cminyard@mvista.com&gt;
Signed-off-by: Sasha Levin &lt;alexander.levin@microsoft.com&gt;
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>random: mix rdrand with entropy sent in from userspace</title>
<updated>2018-08-03T05:48:03+00:00</updated>
<author>
<name>Theodore Ts'o</name>
<email>tytso@mit.edu</email>
</author>
<published>2018-07-15T03:55:57+00:00</published>
<link rel='alternate' type='text/html' href='https://git.tavy.me/linux-stable.git/commit/?id=a0c1006b354ce44eeada03f8bc9ac68de3bbc454'/>
<id>a0c1006b354ce44eeada03f8bc9ac68de3bbc454</id>
<content type='text'>
commit 81e69df38e2911b642ec121dec319fad2a4782f3 upstream.

Fedora has integrated the jitter entropy daemon to work around slow
boot problems, especially on VM's that don't support virtio-rng:

    https://bugzilla.redhat.com/show_bug.cgi?id=1572944

It's understandable why they did this, but the Jitter entropy daemon
works fundamentally on the principle: "the CPU microarchitecture is
**so** complicated and we can't figure it out, so it *must* be
random".  Yes, it uses statistical tests to "prove" it is secure, but
AES_ENCRYPT(NSA_KEY, COUNTER++) will also pass statistical tests with
flying colors.

So if RDRAND is available, mix it into entropy submitted from
userspace.  It can't hurt, and if you believe the NSA has backdoored
RDRAND, then they probably have enough details about the Intel
microarchitecture that they can reverse engineer how the Jitter
entropy daemon affects the microarchitecture, and attack its output
stream.  And if RDRAND is in fact an honest DRNG, it will immeasurably
improve on what the Jitter entropy daemon might produce.

This also provides some protection against someone who is able to read
or set the entropy seed file.

Signed-off-by: Theodore Ts'o &lt;tytso@mit.edu&gt;
Cc: stable@vger.kernel.org
Cc: Arnd Bergmann &lt;arnd@arndb.de&gt;
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;

</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
commit 81e69df38e2911b642ec121dec319fad2a4782f3 upstream.

Fedora has integrated the jitter entropy daemon to work around slow
boot problems, especially on VM's that don't support virtio-rng:

    https://bugzilla.redhat.com/show_bug.cgi?id=1572944

It's understandable why they did this, but the Jitter entropy daemon
works fundamentally on the principle: "the CPU microarchitecture is
**so** complicated and we can't figure it out, so it *must* be
random".  Yes, it uses statistical tests to "prove" it is secure, but
AES_ENCRYPT(NSA_KEY, COUNTER++) will also pass statistical tests with
flying colors.

So if RDRAND is available, mix it into entropy submitted from
userspace.  It can't hurt, and if you believe the NSA has backdoored
RDRAND, then they probably have enough details about the Intel
microarchitecture that they can reverse engineer how the Jitter
entropy daemon affects the microarchitecture, and attack its output
stream.  And if RDRAND is in fact an honest DRNG, it will immeasurably
improve on what the Jitter entropy daemon might produce.

This also provides some protection against someone who is able to read
or set the entropy seed file.

Signed-off-by: Theodore Ts'o &lt;tytso@mit.edu&gt;
Cc: stable@vger.kernel.org
Cc: Arnd Bergmann &lt;arnd@arndb.de&gt;
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;

</pre>
</div>
</content>
</entry>
<entry>
<title>tpm: fix race condition in tpm_common_write()</title>
<updated>2018-07-03T09:26:54+00:00</updated>
<author>
<name>Tadeusz Struk</name>
<email>tadeusz.struk@intel.com</email>
</author>
<published>2018-05-22T21:37:18+00:00</published>
<link rel='alternate' type='text/html' href='https://git.tavy.me/linux-stable.git/commit/?id=ba19d312979fbfe361306df85bb7b755e1ae472c'/>
<id>ba19d312979fbfe361306df85bb7b755e1ae472c</id>
<content type='text'>
commit 3ab2011ea368ec3433ad49e1b9e1c7b70d2e65df upstream.

There is a race condition in tpm_common_write function allowing
two threads on the same /dev/tpm&lt;N&gt;, or two different applications
on the same /dev/tpmrm&lt;N&gt; to overwrite each other commands/responses.
Fixed this by taking the priv-&gt;buffer_mutex early in the function.

Also converted the priv-&gt;data_pending from atomic to a regular size_t
type. There is no need for it to be atomic since it is only touched
under the protection of the priv-&gt;buffer_mutex.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Cc: stable@vger.kernel.org
Signed-off-by: Tadeusz Struk &lt;tadeusz.struk@intel.com&gt;
Reviewed-by: Jarkko Sakkinen &lt;jarkko.sakkinen@linux.intel.com&gt;
Signed-off-by: Jarkko Sakkinen &lt;jarkko.sakkinen@linux.intel.com&gt;
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;

</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
commit 3ab2011ea368ec3433ad49e1b9e1c7b70d2e65df upstream.

There is a race condition in tpm_common_write function allowing
two threads on the same /dev/tpm&lt;N&gt;, or two different applications
on the same /dev/tpmrm&lt;N&gt; to overwrite each other commands/responses.
Fixed this by taking the priv-&gt;buffer_mutex early in the function.

Also converted the priv-&gt;data_pending from atomic to a regular size_t
type. There is no need for it to be atomic since it is only touched
under the protection of the priv-&gt;buffer_mutex.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Cc: stable@vger.kernel.org
Signed-off-by: Tadeusz Struk &lt;tadeusz.struk@intel.com&gt;
Reviewed-by: Jarkko Sakkinen &lt;jarkko.sakkinen@linux.intel.com&gt;
Signed-off-by: Jarkko Sakkinen &lt;jarkko.sakkinen@linux.intel.com&gt;
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;

</pre>
</div>
</content>
</entry>
<entry>
<title>tpm: fix use after free in tpm2_load_context()</title>
<updated>2018-07-03T09:26:54+00:00</updated>
<author>
<name>Tadeusz Struk</name>
<email>tadeusz.struk@intel.com</email>
</author>
<published>2018-05-09T18:55:35+00:00</published>
<link rel='alternate' type='text/html' href='https://git.tavy.me/linux-stable.git/commit/?id=2dd75ec3c29bac0f0cfafde9069a30af7a3ab778'/>
<id>2dd75ec3c29bac0f0cfafde9069a30af7a3ab778</id>
<content type='text'>
commit 8c81c24758ffbf17cf06c6835d361ffa57be2f0e upstream.

If load context command returns with TPM2_RC_HANDLE or TPM2_RC_REFERENCE_H0
then we have use after free in line 114 and double free in 117.

Fixes: 4d57856a21ed2 ("tpm2: add session handle context saving and restoring to the space code")
Cc: stable@vger.kernel.org
Signed-off-by: Tadeusz Struk &lt;tadeusz.struk@intel.com&gt;
Reviewed-by: Jarkko Sakkinen &lt;jarkko.sakkinen@linux.intel.com&gt;
Signed-off--by: Jarkko Sakkinen &lt;jarkko.sakkinen@linux.intel.com&gt;
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;

</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
commit 8c81c24758ffbf17cf06c6835d361ffa57be2f0e upstream.

If load context command returns with TPM2_RC_HANDLE or TPM2_RC_REFERENCE_H0
then we have use after free in line 114 and double free in 117.

Fixes: 4d57856a21ed2 ("tpm2: add session handle context saving and restoring to the space code")
Cc: stable@vger.kernel.org
Signed-off-by: Tadeusz Struk &lt;tadeusz.struk@intel.com&gt;
Reviewed-by: Jarkko Sakkinen &lt;jarkko.sakkinen@linux.intel.com&gt;
Signed-off--by: Jarkko Sakkinen &lt;jarkko.sakkinen@linux.intel.com&gt;
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;

</pre>
</div>
</content>
</entry>
<entry>
<title>hwrng: core - Always drop the RNG in hwrng_unregister()</title>
<updated>2018-07-03T09:26:53+00:00</updated>
<author>
<name>Michael Buesch</name>
<email>m@bues.ch</email>
</author>
<published>2018-06-14T18:08:11+00:00</published>
<link rel='alternate' type='text/html' href='https://git.tavy.me/linux-stable.git/commit/?id=1a371b889a7dd3d5814c845aaf9e09d1df2a47f5'/>
<id>1a371b889a7dd3d5814c845aaf9e09d1df2a47f5</id>
<content type='text'>
commit 837bf7cc3b7504385ae0e829c72e470dfc27cf6c upstream.

enable_best_rng() is used in hwrng_unregister() to switch away from the
currently active RNG, if that is the one currently being removed.
However enable_best_rng() might fail, if the next RNG's init routine
fails. In that case enable_best_rng() will return an error code and
the currently active RNG will remain active.
After unregistering this might lead to crashes due to use-after-free.

Fix this by dropping the currently active RNG, if enable_best_rng()
failed. This will result in no RNG to be active, if the next-best
one failed to initialize.

This problem was introduced by 142a27f0a731ddcf467546960a5585970ca98e21

Fixes: 142a27f0a731 ("hwrng: core - Reset user selected rng by...")
Reported-by: Wirz &lt;spam@lukas-wirz.de&gt;
Tested-by: Wirz &lt;spam@lukas-wirz.de&gt;
Signed-off-by: Michael Büsch &lt;m@bues.ch&gt;
Cc: stable@vger.kernel.org
Signed-off-by: Herbert Xu &lt;herbert@gondor.apana.org.au&gt;
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;

</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
commit 837bf7cc3b7504385ae0e829c72e470dfc27cf6c upstream.

enable_best_rng() is used in hwrng_unregister() to switch away from the
currently active RNG, if that is the one currently being removed.
However enable_best_rng() might fail, if the next RNG's init routine
fails. In that case enable_best_rng() will return an error code and
the currently active RNG will remain active.
After unregistering this might lead to crashes due to use-after-free.

Fix this by dropping the currently active RNG, if enable_best_rng()
failed. This will result in no RNG to be active, if the next-best
one failed to initialize.

This problem was introduced by 142a27f0a731ddcf467546960a5585970ca98e21

Fixes: 142a27f0a731 ("hwrng: core - Reset user selected rng by...")
Reported-by: Wirz &lt;spam@lukas-wirz.de&gt;
Tested-by: Wirz &lt;spam@lukas-wirz.de&gt;
Signed-off-by: Michael Büsch &lt;m@bues.ch&gt;
Cc: stable@vger.kernel.org
Signed-off-by: Herbert Xu &lt;herbert@gondor.apana.org.au&gt;
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;

</pre>
</div>
</content>
</entry>
<entry>
<title>ipmi:bt: Set the timeout before doing a capabilities check</title>
<updated>2018-07-03T09:26:49+00:00</updated>
<author>
<name>Corey Minyard</name>
<email>cminyard@mvista.com</email>
</author>
<published>2018-05-22T13:14:51+00:00</published>
<link rel='alternate' type='text/html' href='https://git.tavy.me/linux-stable.git/commit/?id=52ba3606a808c433c2a03fd9ad144129ddbdbd7f'/>
<id>52ba3606a808c433c2a03fd9ad144129ddbdbd7f</id>
<content type='text'>
commit fe50a7d0393a552e4539da2d31261a59d6415950 upstream.

There was one place where the timeout value for an operation was
not being set, if a capabilities request was done from idle.  Move
the timeout value setting to before where that change might be
requested.

IMHO the cause here is the invisible returns in the macros.  Maybe
that's a job for later, though.

Reported-by: Nordmark Claes &lt;Claes.Nordmark@tieto.com&gt;
Signed-off-by: Corey Minyard &lt;cminyard@mvista.com&gt;
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;

</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
commit fe50a7d0393a552e4539da2d31261a59d6415950 upstream.

There was one place where the timeout value for an operation was
not being set, if a capabilities request was done from idle.  Move
the timeout value setting to before where that change might be
requested.

IMHO the cause here is the invisible returns in the macros.  Maybe
that's a job for later, though.

Reported-by: Nordmark Claes &lt;Claes.Nordmark@tieto.com&gt;
Signed-off-by: Corey Minyard &lt;cminyard@mvista.com&gt;
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;

</pre>
</div>
</content>
</entry>
<entry>
<title>agp: uninorth: make two functions static</title>
<updated>2018-05-10T01:26:08+00:00</updated>
<author>
<name>Mathieu Malaterre</name>
<email>malat@debian.org</email>
</author>
<published>2018-05-05T19:54:05+00:00</published>
<link rel='alternate' type='text/html' href='https://git.tavy.me/linux-stable.git/commit/?id=dec60f3a9b7251f2657d743d96ba9a83dca02351'/>
<id>dec60f3a9b7251f2657d743d96ba9a83dca02351</id>
<content type='text'>
Both ‘uninorth_remove_memory’ and ‘null_cache_flush’ can be made
static. So make them.

Silence the following gcc warning (W=1):

  drivers/char/agp/uninorth-agp.c:198:5: warning: no previous prototype for ‘uninorth_remove_memory’ [-Wmissing-prototypes]

and

  drivers/char/agp/uninorth-agp.c:473:6: warning: no previous prototype for ‘null_cache_flush’ [-Wmissing-prototypes]

Signed-off-by: Mathieu Malaterre &lt;malat@debian.org&gt;
Signed-off-by: Dave Airlie &lt;airlied@redhat.com&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Both ‘uninorth_remove_memory’ and ‘null_cache_flush’ can be made
static. So make them.

Silence the following gcc warning (W=1):

  drivers/char/agp/uninorth-agp.c:198:5: warning: no previous prototype for ‘uninorth_remove_memory’ [-Wmissing-prototypes]

and

  drivers/char/agp/uninorth-agp.c:473:6: warning: no previous prototype for ‘null_cache_flush’ [-Wmissing-prototypes]

Signed-off-by: Mathieu Malaterre &lt;malat@debian.org&gt;
Signed-off-by: Dave Airlie &lt;airlied@redhat.com&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>Merge tag 'for_linus' of git://git.kernel.org/pub/scm/linux/kernel/git/mst/vhost</title>
<updated>2018-04-26T23:36:11+00:00</updated>
<author>
<name>Linus Torvalds</name>
<email>torvalds@linux-foundation.org</email>
</author>
<published>2018-04-26T23:36:11+00:00</published>
<link rel='alternate' type='text/html' href='https://git.tavy.me/linux-stable.git/commit/?id=0644f186fc9d77bb5bd198369e59fb28927a3692'/>
<id>0644f186fc9d77bb5bd198369e59fb28927a3692</id>
<content type='text'>
Pull virtio fixups from Michael Tsirkin:

 - Latest header update will break QEMU (if it's rebuilt with the new
   header) - and it seems that the code there is so fragile that any
   change in this header will break it. Add a better interface so users
   do not need to change their code every time that header changes.

 - Fix virtio console for spec compliance.

* tag 'for_linus' of git://git.kernel.org/pub/scm/linux/kernel/git/mst/vhost:
  virtio_console: reset on out of memory
  virtio_console: move removal code
  virtio_console: drop custom control queue cleanup
  virtio_console: free buffers after reset
  virtio: add ability to iterate over vqs
  virtio_console: don't tie bufs to a vq
  virtio_balloon: add array of stat names
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Pull virtio fixups from Michael Tsirkin:

 - Latest header update will break QEMU (if it's rebuilt with the new
   header) - and it seems that the code there is so fragile that any
   change in this header will break it. Add a better interface so users
   do not need to change their code every time that header changes.

 - Fix virtio console for spec compliance.

* tag 'for_linus' of git://git.kernel.org/pub/scm/linux/kernel/git/mst/vhost:
  virtio_console: reset on out of memory
  virtio_console: move removal code
  virtio_console: drop custom control queue cleanup
  virtio_console: free buffers after reset
  virtio: add ability to iterate over vqs
  virtio_console: don't tie bufs to a vq
  virtio_balloon: add array of stat names
</pre>
</div>
</content>
</entry>
<entry>
<title>Merge tag 'random_for_linus_stable' of git://git.kernel.org/pub/scm/linux/kernel/git/tytso/random</title>
<updated>2018-04-26T17:59:56+00:00</updated>
<author>
<name>Linus Torvalds</name>
<email>torvalds@linux-foundation.org</email>
</author>
<published>2018-04-26T17:59:56+00:00</published>
<link rel='alternate' type='text/html' href='https://git.tavy.me/linux-stable.git/commit/?id=665fa0000aedb5f3d6b4d3b040d323074e1b7c40'/>
<id>665fa0000aedb5f3d6b4d3b040d323074e1b7c40</id>
<content type='text'>
Pull /dev/random fixes from Ted Ts'o:
 "Fix a regression on NUMA kernels and suppress excess unseeded entropy
  pool warnings"

* tag 'random_for_linus_stable' of git://git.kernel.org/pub/scm/linux/kernel/git/tytso/random:
  random: rate limit unseeded randomness warnings
  random: fix possible sleeping allocation from irq context
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Pull /dev/random fixes from Ted Ts'o:
 "Fix a regression on NUMA kernels and suppress excess unseeded entropy
  pool warnings"

* tag 'random_for_linus_stable' of git://git.kernel.org/pub/scm/linux/kernel/git/tytso/random:
  random: rate limit unseeded randomness warnings
  random: fix possible sleeping allocation from irq context
</pre>
</div>
</content>
</entry>
<entry>
<title>virtio_console: reset on out of memory</title>
<updated>2018-04-25T17:41:29+00:00</updated>
<author>
<name>Michael S. Tsirkin</name>
<email>mst@redhat.com</email>
</author>
<published>2018-04-20T18:00:13+00:00</published>
<link rel='alternate' type='text/html' href='https://git.tavy.me/linux-stable.git/commit/?id=5c60300d68da32ca77f7f978039dc72bfc78b06b'/>
<id>5c60300d68da32ca77f7f978039dc72bfc78b06b</id>
<content type='text'>
When out of memory and we can't add ctrl vq buffers,
probe fails. Unfortunately the error handling is
out of spec: it calls del_vqs without bothering
to reset the device first.

To fix, call the full cleanup function in this case.

Cc: stable@vger.kernel.org
Signed-off-by: Michael S. Tsirkin &lt;mst@redhat.com&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
When out of memory and we can't add ctrl vq buffers,
probe fails. Unfortunately the error handling is
out of spec: it calls del_vqs without bothering
to reset the device first.

To fix, call the full cleanup function in this case.

Cc: stable@vger.kernel.org
Signed-off-by: Michael S. Tsirkin &lt;mst@redhat.com&gt;
</pre>
</div>
</content>
</entry>
</feed>
