Import of kernel-5.14.0-687.23.1.el9_8
This commit is contained in:
parent
2137afdebb
commit
5d5389c372
@ -128,25 +128,27 @@ stable kernels.
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Cortex-A76 | #3324349 | ARM64_ERRATUM_3194386 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Cortex-A76 | #4193800 | ARM64_ERRATUM_4118414 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Cortex-A76AE | #4193801 | ARM64_ERRATUM_4118414 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Cortex-A77 | #1491015 | N/A |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Cortex-A77 | #1508412 | ARM64_ERRATUM_1508412 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
<<<<<<< HEAD:Documentation/arm64/silicon-errata.rst
|
||||
| ARM | Cortex-A510 | #2051678 | ARM64_ERRATUM_2051678 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Cortex-A510 | #2077057 | ARM64_ERRATUM_2077057 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Cortex-A510 | #2441009 | ARM64_ERRATUM_2441009 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Cortex-A510 | #2658417 | ARM64_ERRATUM_2658417 |
|
||||
=======
|
||||
| ARM | Cortex-A77 | #3324348 | ARM64_ERRATUM_3194386 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Cortex-A77 | #4193798 | ARM64_ERRATUM_4118414 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Cortex-A78 | #3324344 | ARM64_ERRATUM_3194386 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Cortex-A78 | #4193791 | ARM64_ERRATUM_4118414 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Cortex-A78AE | #4193793 | ARM64_ERRATUM_4118414 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Cortex-A78C | #3324346,3324347| ARM64_ERRATUM_3194386 |
|
||||
>>>>>>> adeec61a4723 (arm64: errata: Expand speculative SSBS workaround (again)):Documentation/arch/arm64/silicon-errata.rst
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Cortex-A78C | #4193794 | ARM64_ERRATUM_4118414 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Cortex-A710 | #2119858 | ARM64_ERRATUM_2119858 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
@ -156,6 +158,8 @@ stable kernels.
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Cortex-A710 | #3324338 | ARM64_ERRATUM_3194386 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Cortex-A710 | #4193788 | ARM64_ERRATUM_4118414 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Cortex-A715 | #2645198 | ARM64_ERRATUM_2645198 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Cortex-A715 | #3456084 | ARM64_ERRATUM_3194386 |
|
||||
@ -168,20 +172,32 @@ stable kernels.
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Cortex-X1 | #3324344 | ARM64_ERRATUM_3194386 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Cortex-X1 | #4193791 | ARM64_ERRATUM_4118414 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Cortex-X1C | #3324346 | ARM64_ERRATUM_3194386 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Cortex-X1C | #4193792 | ARM64_ERRATUM_4118414 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Cortex-X2 | #2119858 | ARM64_ERRATUM_2119858 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Cortex-X2 | #2224489 | ARM64_ERRATUM_2224489 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Cortex-X2 | #3324338 | ARM64_ERRATUM_3194386 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Cortex-X2 | #4193788 | ARM64_ERRATUM_4118414 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Cortex-X3 | #3324335 | ARM64_ERRATUM_3194386 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Cortex-X3 | #4193786 | ARM64_ERRATUM_4118414 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Cortex-X4 | #3194386 | ARM64_ERRATUM_3194386 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Cortex-X4 | #4118414 | ARM64_ERRATUM_4118414 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Cortex-X925 | #3324334 | ARM64_ERRATUM_3194386 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Cortex-X925 | #4193781 | ARM64_ERRATUM_4118414 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Neoverse-N1 | #1188873,1418040| ARM64_ERRATUM_1418040 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Neoverse-N1 | #1349291 | N/A |
|
||||
@ -192,6 +208,8 @@ stable kernels.
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Neoverse-N1 | #3324349 | ARM64_ERRATUM_3194386 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Neoverse-N1 | #4193800 | ARM64_ERRATUM_4118414 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Neoverse-N2 | #2139208 | ARM64_ERRATUM_2139208 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Neoverse-N2 | #2067961 | ARM64_ERRATUM_2067961 |
|
||||
@ -200,16 +218,32 @@ stable kernels.
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Neoverse-N2 | #3324339 | ARM64_ERRATUM_3194386 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Neoverse-N2 | #4193789 | ARM64_ERRATUM_4118414 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Neoverse-N3 | #3456111 | ARM64_ERRATUM_3194386 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Neoverse-V1 | #1619801 | N/A |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Neoverse-V1 | #3324341 | ARM64_ERRATUM_3194386 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Neoverse-V1 | #4193790 | ARM64_ERRATUM_4118414 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Neoverse-V2 | #3324336 | ARM64_ERRATUM_3194386 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Neoverse-V2 | #4193787 | ARM64_ERRATUM_4118414 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Neoverse-V3 | #3312417 | ARM64_ERRATUM_3194386 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Neoverse-V3 | #4193784 | ARM64_ERRATUM_4118414 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Neoverse-V3AE | #3312417 | ARM64_ERRATUM_3194386 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | Neoverse-V3AE | #4193784 | ARM64_ERRATUM_4118414 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | C1-Premium | #4193780 | ARM64_ERRATUM_4118414 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | C1-Ultra | #4193780 | ARM64_ERRATUM_4118414 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| ARM | MMU-500 | #841119,826419 | ARM_SMMU_MMU_500_CPRE_ERRATA|
|
||||
| | | #562869,1047329 | |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
@ -252,6 +286,8 @@ stable kernels.
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| NVIDIA | Carmel Core | N/A | NVIDIA_CARMEL_CNP_ERRATUM |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| NVIDIA | Olympus core | T410-OLY-1029 | ARM64_ERRATUM_4118414 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| NVIDIA | T241 GICv3/4.x | T241-FABRIC-4 | N/A |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
@ -308,3 +344,5 @@ stable kernels.
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| Microsoft | Azure Cobalt 100| #3324339 | ARM64_ERRATUM_3194386 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
| Microsoft | Azure Cobalt 100| #4193789 | ARM64_ERRATUM_4118414 |
|
||||
+----------------+-----------------+-----------------+-----------------------------+
|
||||
|
||||
@ -1106,6 +1106,7 @@ config ARM64_ERRATUM_3194386
|
||||
* ARM Neoverse-V1 erratum 3324341
|
||||
* ARM Neoverse V2 erratum 3324336
|
||||
* ARM Neoverse-V3 erratum 3312417
|
||||
* ARM Neoverse-V3AE erratum 3312417
|
||||
|
||||
On affected cores "MSR SSBS, #0" instructions may not affect
|
||||
subsequent speculative instructions, which may permit unexepected
|
||||
@ -1119,6 +1120,44 @@ config ARM64_ERRATUM_3194386
|
||||
|
||||
If unsure, say Y.
|
||||
|
||||
config ARM64_ERRATUM_4118414
|
||||
bool "Various: Completion of affected memory accesses might not be guaranteed by completion of a TLBI"
|
||||
default y
|
||||
select ARM64_WORKAROUND_REPEAT_TLBI
|
||||
help
|
||||
This option adds a workaround for the following errata:
|
||||
|
||||
* ARM C1-Premium erratum 4193780
|
||||
* ARM C1-Ultra erratum 4193780
|
||||
* ARM Cortex-A76 erratum 4193800
|
||||
* ARM Cortex-A76AE erratum 4193801
|
||||
* ARM Cortex-A77 erratum 4193798
|
||||
* ARM Cortex-A78 erratum 4193791
|
||||
* ARM Cortex-A78AE erratum 4193793
|
||||
* ARM Cortex-A78C erratum 4193794
|
||||
* ARM Cortex-A710 erratum 4193788
|
||||
* ARM Cortex-X1 erratum 4193791
|
||||
* ARM Cortex-X1C erratum 4193792
|
||||
* ARM Cortex-X2 erratum 4193788
|
||||
* ARM Cortex-X3 erratum 4193786
|
||||
* ARM Cortex-X4 erratum 4118414
|
||||
* ARM Cortex-X925 erratum 4193781
|
||||
* ARM Neoverse-N1 erratum 4193800
|
||||
* ARM Neoverse-N2 erratum 4193789
|
||||
* ARM Neoverse-V1 erratum 4193790
|
||||
* ARM Neoverse-V2 erratum 4193787
|
||||
* ARM Neoverse-V3 erratum 4193784
|
||||
* ARM Neoverse-V3AE erratum 4193784
|
||||
* Microsoft Azure Cobalt 100 4193789
|
||||
* NVIDIA Olympus erratum T410-OLY-1029
|
||||
|
||||
On affected cores, some memory accesses might not be completed by
|
||||
broadcast TLB invalidation.
|
||||
|
||||
This issue is also known as CVE-2025-10263.
|
||||
|
||||
If unsure, say Y.
|
||||
|
||||
config CAVIUM_ERRATUM_22375
|
||||
bool "Cavium erratum 22375, 24313"
|
||||
default y
|
||||
|
||||
@ -93,11 +93,15 @@
|
||||
#define ARM_CPU_PART_NEOVERSE_V2 0xD4F
|
||||
#define ARM_CPU_PART_CORTEX_A720 0xD81
|
||||
#define ARM_CPU_PART_CORTEX_X4 0xD82
|
||||
#define ARM_CPU_PART_NEOVERSE_V3AE 0xD83
|
||||
#define ARM_CPU_PART_NEOVERSE_V3 0xD84
|
||||
#define ARM_CPU_PART_CORTEX_X925 0xD85
|
||||
#define ARM_CPU_PART_CORTEX_A725 0xD87
|
||||
#define ARM_CPU_PART_CORTEX_A720AE 0xD89
|
||||
#define ARM_CPU_PART_C1_ULTRA 0xD8C
|
||||
#define ARM_CPU_PART_NEOVERSE_N3 0xD8E
|
||||
#define ARM_CPU_PART_C1_PRO 0xD8B
|
||||
#define ARM_CPU_PART_C1_PREMIUM 0xD90
|
||||
|
||||
#define APM_CPU_PART_XGENE 0x000
|
||||
#define APM_CPU_VAR_POTENZA 0x00
|
||||
@ -128,6 +132,7 @@
|
||||
|
||||
#define NVIDIA_CPU_PART_DENVER 0x003
|
||||
#define NVIDIA_CPU_PART_CARMEL 0x004
|
||||
#define NVIDIA_CPU_PART_OLYMPUS 0x010
|
||||
|
||||
#define FUJITSU_CPU_PART_A64FX 0x001
|
||||
|
||||
@ -180,11 +185,15 @@
|
||||
#define MIDR_NEOVERSE_V2 MIDR_CPU_MODEL(ARM_CPU_IMP_ARM, ARM_CPU_PART_NEOVERSE_V2)
|
||||
#define MIDR_CORTEX_A720 MIDR_CPU_MODEL(ARM_CPU_IMP_ARM, ARM_CPU_PART_CORTEX_A720)
|
||||
#define MIDR_CORTEX_X4 MIDR_CPU_MODEL(ARM_CPU_IMP_ARM, ARM_CPU_PART_CORTEX_X4)
|
||||
#define MIDR_NEOVERSE_V3AE MIDR_CPU_MODEL(ARM_CPU_IMP_ARM, ARM_CPU_PART_NEOVERSE_V3AE)
|
||||
#define MIDR_NEOVERSE_V3 MIDR_CPU_MODEL(ARM_CPU_IMP_ARM, ARM_CPU_PART_NEOVERSE_V3)
|
||||
#define MIDR_CORTEX_X925 MIDR_CPU_MODEL(ARM_CPU_IMP_ARM, ARM_CPU_PART_CORTEX_X925)
|
||||
#define MIDR_CORTEX_A725 MIDR_CPU_MODEL(ARM_CPU_IMP_ARM, ARM_CPU_PART_CORTEX_A725)
|
||||
#define MIDR_CORTEX_A720AE MIDR_CPU_MODEL(ARM_CPU_IMP_ARM, ARM_CPU_PART_CORTEX_A720AE)
|
||||
#define MIDR_C1_ULTRA MIDR_CPU_MODEL(ARM_CPU_IMP_ARM, ARM_CPU_PART_C1_ULTRA)
|
||||
#define MIDR_NEOVERSE_N3 MIDR_CPU_MODEL(ARM_CPU_IMP_ARM, ARM_CPU_PART_NEOVERSE_N3)
|
||||
#define MIDR_C1_PRO MIDR_CPU_MODEL(ARM_CPU_IMP_ARM, ARM_CPU_PART_C1_PRO)
|
||||
#define MIDR_C1_PREMIUM MIDR_CPU_MODEL(ARM_CPU_IMP_ARM, ARM_CPU_PART_C1_PREMIUM)
|
||||
#define MIDR_THUNDERX MIDR_CPU_MODEL(ARM_CPU_IMP_CAVIUM, CAVIUM_CPU_PART_THUNDERX)
|
||||
#define MIDR_THUNDERX_81XX MIDR_CPU_MODEL(ARM_CPU_IMP_CAVIUM, CAVIUM_CPU_PART_THUNDERX_81XX)
|
||||
#define MIDR_THUNDERX_83XX MIDR_CPU_MODEL(ARM_CPU_IMP_CAVIUM, CAVIUM_CPU_PART_THUNDERX_83XX)
|
||||
@ -207,6 +216,7 @@
|
||||
#define MIDR_QCOM_KRYO_4XX_SILVER MIDR_CPU_MODEL(ARM_CPU_IMP_QCOM, QCOM_CPU_PART_KRYO_4XX_SILVER)
|
||||
#define MIDR_NVIDIA_DENVER MIDR_CPU_MODEL(ARM_CPU_IMP_NVIDIA, NVIDIA_CPU_PART_DENVER)
|
||||
#define MIDR_NVIDIA_CARMEL MIDR_CPU_MODEL(ARM_CPU_IMP_NVIDIA, NVIDIA_CPU_PART_CARMEL)
|
||||
#define MIDR_NVIDIA_OLYMPUS MIDR_CPU_MODEL(ARM_CPU_IMP_NVIDIA, NVIDIA_CPU_PART_OLYMPUS)
|
||||
#define MIDR_FUJITSU_A64FX MIDR_CPU_MODEL(ARM_CPU_IMP_FUJITSU, FUJITSU_CPU_PART_A64FX)
|
||||
#define MIDR_HISI_TSV110 MIDR_CPU_MODEL(ARM_CPU_IMP_HISI, HISI_CPU_PART_TSV110)
|
||||
#define MIDR_HISI_HIP09 MIDR_CPU_MODEL(ARM_CPU_IMP_HISI, HISI_CPU_PART_HIP09)
|
||||
|
||||
@ -225,7 +225,37 @@ static const struct arm64_cpu_capabilities arm64_repeat_tlbi_list[] = {
|
||||
ERRATA_MIDR_RANGE(MIDR_CORTEX_A510, 0, 0, 1, 1),
|
||||
},
|
||||
#endif
|
||||
{},
|
||||
#ifdef CONFIG_ARM64_ERRATUM_4118414
|
||||
{
|
||||
ERRATA_MIDR_RANGE_LIST(((const struct midr_range[]) {
|
||||
MIDR_ALL_VERSIONS(MIDR_C1_PREMIUM),
|
||||
MIDR_ALL_VERSIONS(MIDR_C1_ULTRA),
|
||||
MIDR_ALL_VERSIONS(MIDR_CORTEX_A76),
|
||||
MIDR_ALL_VERSIONS(MIDR_CORTEX_A76AE),
|
||||
MIDR_ALL_VERSIONS(MIDR_CORTEX_A77),
|
||||
MIDR_ALL_VERSIONS(MIDR_CORTEX_A78),
|
||||
MIDR_ALL_VERSIONS(MIDR_CORTEX_A78AE),
|
||||
MIDR_ALL_VERSIONS(MIDR_CORTEX_A78C),
|
||||
MIDR_ALL_VERSIONS(MIDR_CORTEX_A710),
|
||||
MIDR_ALL_VERSIONS(MIDR_CORTEX_X1),
|
||||
MIDR_ALL_VERSIONS(MIDR_CORTEX_X1C),
|
||||
MIDR_ALL_VERSIONS(MIDR_CORTEX_X2),
|
||||
MIDR_ALL_VERSIONS(MIDR_CORTEX_X3),
|
||||
MIDR_ALL_VERSIONS(MIDR_CORTEX_X4),
|
||||
MIDR_ALL_VERSIONS(MIDR_CORTEX_X925),
|
||||
MIDR_ALL_VERSIONS(MIDR_NEOVERSE_N1),
|
||||
MIDR_ALL_VERSIONS(MIDR_NEOVERSE_N2),
|
||||
MIDR_ALL_VERSIONS(MIDR_NEOVERSE_V1),
|
||||
MIDR_ALL_VERSIONS(MIDR_NEOVERSE_V2),
|
||||
MIDR_ALL_VERSIONS(MIDR_NEOVERSE_V3),
|
||||
MIDR_ALL_VERSIONS(MIDR_NEOVERSE_V3AE),
|
||||
MIDR_ALL_VERSIONS(MIDR_NVIDIA_OLYMPUS),
|
||||
MIDR_ALL_VERSIONS(MIDR_MICROSOFT_AZURE_COBALT_100),
|
||||
{}
|
||||
})),
|
||||
},
|
||||
#endif
|
||||
{}
|
||||
};
|
||||
#endif
|
||||
|
||||
@ -456,6 +486,7 @@ static const struct midr_range erratum_spec_ssbs_list[] = {
|
||||
MIDR_ALL_VERSIONS(MIDR_NEOVERSE_V1),
|
||||
MIDR_ALL_VERSIONS(MIDR_NEOVERSE_V2),
|
||||
MIDR_ALL_VERSIONS(MIDR_NEOVERSE_V3),
|
||||
MIDR_ALL_VERSIONS(MIDR_NEOVERSE_V3AE),
|
||||
{}
|
||||
};
|
||||
#endif
|
||||
@ -560,7 +591,7 @@ const struct arm64_cpu_capabilities arm64_errata[] = {
|
||||
#endif
|
||||
#ifdef CONFIG_ARM64_WORKAROUND_REPEAT_TLBI
|
||||
{
|
||||
.desc = "Qualcomm erratum 1009, or ARM erratum 1286807, 2441009",
|
||||
.desc = "Broken broadcast TLBI completion",
|
||||
.capability = ARM64_WORKAROUND_REPEAT_TLBI,
|
||||
.type = ARM64_CPUCAP_LOCAL_CPU_ERRATUM,
|
||||
.matches = cpucap_multi_entry_cap_matches,
|
||||
|
||||
@ -183,6 +183,8 @@ struct kmem_cache *mmu_page_header_cache;
|
||||
static struct percpu_counter kvm_total_used_mmu_pages;
|
||||
|
||||
static void mmu_spte_set(u64 *sptep, u64 spte);
|
||||
static int mmu_page_zap_pte(struct kvm *kvm, struct kvm_mmu_page *sp,
|
||||
u64 *spte, struct list_head *invalid_list);
|
||||
|
||||
struct kvm_mmu_role_regs {
|
||||
const unsigned long cr0;
|
||||
@ -1220,19 +1222,6 @@ static void drop_spte(struct kvm *kvm, u64 *sptep)
|
||||
rmap_remove(kvm, sptep);
|
||||
}
|
||||
|
||||
static void drop_large_spte(struct kvm *kvm, u64 *sptep, bool flush)
|
||||
{
|
||||
struct kvm_mmu_page *sp;
|
||||
|
||||
sp = sptep_to_sp(sptep);
|
||||
WARN_ON_ONCE(sp->role.level == PG_LEVEL_4K);
|
||||
|
||||
drop_spte(kvm, sptep);
|
||||
|
||||
if (flush)
|
||||
kvm_flush_remote_tlbs_sptep(kvm, sptep);
|
||||
}
|
||||
|
||||
/*
|
||||
* Write-protect on the specified @sptep, @pt_protect indicates whether
|
||||
* spte write-protection is caused by protecting shadow page table.
|
||||
@ -2326,12 +2315,15 @@ static struct kvm_mmu_page *kvm_mmu_get_child_sp(struct kvm_vcpu *vcpu,
|
||||
u64 *sptep, gfn_t gfn,
|
||||
bool direct, unsigned int access)
|
||||
{
|
||||
union kvm_mmu_page_role role;
|
||||
union kvm_mmu_page_role role = kvm_mmu_child_role(sptep, direct, access);
|
||||
|
||||
if (is_shadow_present_pte(*sptep) && !is_large_pte(*sptep))
|
||||
if (is_shadow_present_pte(*sptep) &&
|
||||
!is_large_pte(*sptep) &&
|
||||
spte_to_child_sp(*sptep) &&
|
||||
spte_to_child_sp(*sptep)->gfn == gfn &&
|
||||
spte_to_child_sp(*sptep)->role.word == role.word)
|
||||
return ERR_PTR(-EEXIST);
|
||||
|
||||
role = kvm_mmu_child_role(sptep, direct, access);
|
||||
return kvm_mmu_get_shadow_page(vcpu, gfn, role);
|
||||
}
|
||||
|
||||
@ -2406,13 +2398,16 @@ static void __link_shadow_page(struct kvm *kvm,
|
||||
|
||||
BUILD_BUG_ON(VMX_EPT_WRITABLE_MASK != PT_WRITABLE_MASK);
|
||||
|
||||
/*
|
||||
* If an SPTE is present already, it must be a leaf and therefore
|
||||
* a large one. Drop it, and flush the TLB if needed, before
|
||||
* installing sp.
|
||||
*/
|
||||
if (is_shadow_present_pte(*sptep))
|
||||
drop_large_spte(kvm, sptep, flush);
|
||||
if (is_shadow_present_pte(*sptep)) {
|
||||
struct kvm_mmu_page *parent_sp;
|
||||
LIST_HEAD(invalid_list);
|
||||
|
||||
parent_sp = sptep_to_sp(sptep);
|
||||
WARN_ON_ONCE(parent_sp->role.level == PG_LEVEL_4K);
|
||||
|
||||
mmu_page_zap_pte(kvm, parent_sp, sptep, &invalid_list);
|
||||
kvm_mmu_remote_flush_or_zap(kvm, &invalid_list, true);
|
||||
}
|
||||
|
||||
spte = make_nonleaf_spte(sp->spt, sp_ad_disabled(sp));
|
||||
|
||||
|
||||
@ -431,6 +431,7 @@ CONFIG_ARM64_WORKAROUND_SPECULATIVE_UNPRIV_LOAD=y
|
||||
CONFIG_ARM64_ERRATUM_2966298=y
|
||||
CONFIG_ARM64_ERRATUM_3117295=y
|
||||
CONFIG_ARM64_ERRATUM_3194386=y
|
||||
CONFIG_ARM64_ERRATUM_4118414=y
|
||||
CONFIG_CAVIUM_ERRATUM_22375=y
|
||||
CONFIG_CAVIUM_ERRATUM_23144=y
|
||||
CONFIG_CAVIUM_ERRATUM_23154=y
|
||||
|
||||
@ -428,6 +428,7 @@ CONFIG_ARM64_WORKAROUND_SPECULATIVE_UNPRIV_LOAD=y
|
||||
CONFIG_ARM64_ERRATUM_2966298=y
|
||||
CONFIG_ARM64_ERRATUM_3117295=y
|
||||
CONFIG_ARM64_ERRATUM_3194386=y
|
||||
CONFIG_ARM64_ERRATUM_4118414=y
|
||||
CONFIG_CAVIUM_ERRATUM_22375=y
|
||||
CONFIG_CAVIUM_ERRATUM_23144=y
|
||||
CONFIG_CAVIUM_ERRATUM_23154=y
|
||||
|
||||
@ -431,6 +431,7 @@ CONFIG_ARM64_WORKAROUND_SPECULATIVE_UNPRIV_LOAD=y
|
||||
CONFIG_ARM64_ERRATUM_2966298=y
|
||||
CONFIG_ARM64_ERRATUM_3117295=y
|
||||
CONFIG_ARM64_ERRATUM_3194386=y
|
||||
CONFIG_ARM64_ERRATUM_4118414=y
|
||||
CONFIG_CAVIUM_ERRATUM_22375=y
|
||||
CONFIG_CAVIUM_ERRATUM_23144=y
|
||||
CONFIG_CAVIUM_ERRATUM_23154=y
|
||||
|
||||
@ -433,6 +433,7 @@ CONFIG_ARM64_WORKAROUND_SPECULATIVE_UNPRIV_LOAD=y
|
||||
CONFIG_ARM64_ERRATUM_2966298=y
|
||||
CONFIG_ARM64_ERRATUM_3117295=y
|
||||
CONFIG_ARM64_ERRATUM_3194386=y
|
||||
CONFIG_ARM64_ERRATUM_4118414=y
|
||||
CONFIG_CAVIUM_ERRATUM_22375=y
|
||||
CONFIG_CAVIUM_ERRATUM_23144=y
|
||||
CONFIG_CAVIUM_ERRATUM_23154=y
|
||||
|
||||
@ -432,6 +432,7 @@ CONFIG_ARM64_WORKAROUND_SPECULATIVE_UNPRIV_LOAD=y
|
||||
CONFIG_ARM64_ERRATUM_2966298=y
|
||||
CONFIG_ARM64_ERRATUM_3117295=y
|
||||
CONFIG_ARM64_ERRATUM_3194386=y
|
||||
CONFIG_ARM64_ERRATUM_4118414=y
|
||||
CONFIG_CAVIUM_ERRATUM_22375=y
|
||||
CONFIG_CAVIUM_ERRATUM_23144=y
|
||||
CONFIG_CAVIUM_ERRATUM_23154=y
|
||||
|
||||
@ -433,6 +433,7 @@ CONFIG_ARM64_WORKAROUND_SPECULATIVE_UNPRIV_LOAD=y
|
||||
CONFIG_ARM64_ERRATUM_2966298=y
|
||||
CONFIG_ARM64_ERRATUM_3117295=y
|
||||
CONFIG_ARM64_ERRATUM_3194386=y
|
||||
CONFIG_ARM64_ERRATUM_4118414=y
|
||||
CONFIG_CAVIUM_ERRATUM_22375=y
|
||||
CONFIG_CAVIUM_ERRATUM_23144=y
|
||||
CONFIG_CAVIUM_ERRATUM_23154=y
|
||||
|
||||
@ -432,6 +432,7 @@ CONFIG_ARM64_WORKAROUND_SPECULATIVE_UNPRIV_LOAD=y
|
||||
CONFIG_ARM64_ERRATUM_2966298=y
|
||||
CONFIG_ARM64_ERRATUM_3117295=y
|
||||
CONFIG_ARM64_ERRATUM_3194386=y
|
||||
CONFIG_ARM64_ERRATUM_4118414=y
|
||||
CONFIG_CAVIUM_ERRATUM_22375=y
|
||||
CONFIG_CAVIUM_ERRATUM_23144=y
|
||||
CONFIG_CAVIUM_ERRATUM_23154=y
|
||||
|
||||
@ -428,6 +428,7 @@ CONFIG_ARM64_WORKAROUND_SPECULATIVE_UNPRIV_LOAD=y
|
||||
CONFIG_ARM64_ERRATUM_2966298=y
|
||||
CONFIG_ARM64_ERRATUM_3117295=y
|
||||
CONFIG_ARM64_ERRATUM_3194386=y
|
||||
CONFIG_ARM64_ERRATUM_4118414=y
|
||||
CONFIG_CAVIUM_ERRATUM_22375=y
|
||||
CONFIG_CAVIUM_ERRATUM_23144=y
|
||||
CONFIG_CAVIUM_ERRATUM_23154=y
|
||||
|
||||
@ -171,8 +171,8 @@ int drm_gem_fb_init_with_funcs(struct drm_device *dev,
|
||||
}
|
||||
|
||||
for (i = 0; i < info->num_planes; i++) {
|
||||
unsigned int width = mode_cmd->width / (i ? info->hsub : 1);
|
||||
unsigned int height = mode_cmd->height / (i ? info->vsub : 1);
|
||||
unsigned int width = drm_format_info_plane_width(info, mode_cmd->width, i);
|
||||
unsigned int height = drm_format_info_plane_height(info, mode_cmd->height, i);
|
||||
unsigned int min_size;
|
||||
|
||||
objs[i] = drm_gem_object_lookup(file, mode_cmd->handles[i]);
|
||||
|
||||
@ -737,8 +737,8 @@ r535_gsp_acpi_caps(acpi_handle handle, CAPS_METHOD_DATA *caps)
|
||||
if (!obj)
|
||||
goto done;
|
||||
|
||||
if (WARN_ON(obj->type != ACPI_TYPE_BUFFER) ||
|
||||
WARN_ON(obj->buffer.length != 4))
|
||||
if (obj->type != ACPI_TYPE_BUFFER ||
|
||||
obj->buffer.length != 4)
|
||||
goto done;
|
||||
|
||||
caps->status = 0;
|
||||
@ -773,8 +773,8 @@ r535_gsp_acpi_jt(acpi_handle handle, JT_METHOD_DATA *jt)
|
||||
if (!obj)
|
||||
goto done;
|
||||
|
||||
if (WARN_ON(obj->type != ACPI_TYPE_BUFFER) ||
|
||||
WARN_ON(obj->buffer.length != 4))
|
||||
if (obj->type != ACPI_TYPE_BUFFER ||
|
||||
obj->buffer.length != 4)
|
||||
goto done;
|
||||
|
||||
jt->status = 0;
|
||||
@ -861,8 +861,8 @@ r535_gsp_acpi_dod(acpi_handle handle, DOD_METHOD_DATA *dod)
|
||||
|
||||
_DOD = output.pointer;
|
||||
|
||||
if (WARN_ON(_DOD->type != ACPI_TYPE_PACKAGE) ||
|
||||
WARN_ON(_DOD->package.count > ARRAY_SIZE(dod->acpiIdList)))
|
||||
if (_DOD->type != ACPI_TYPE_PACKAGE ||
|
||||
_DOD->package.count > ARRAY_SIZE(dod->acpiIdList))
|
||||
return;
|
||||
|
||||
for (int i = 0; i < _DOD->package.count; i++) {
|
||||
|
||||
@ -12289,7 +12289,7 @@ static int tg3_get_link_ksettings(struct net_device *dev,
|
||||
ethtool_convert_legacy_u32_to_link_mode(cmd->link_modes.advertising,
|
||||
advertising);
|
||||
|
||||
if (netif_running(dev) && tp->link_up) {
|
||||
if (netif_running(dev) && netif_carrier_ok(dev)) {
|
||||
cmd->base.speed = tp->link_config.active_speed;
|
||||
cmd->base.duplex = tp->link_config.active_duplex;
|
||||
ethtool_convert_legacy_u32_to_link_mode(
|
||||
|
||||
@ -1935,6 +1935,7 @@ remove_irq:
|
||||
mana_gd_remove_irqs(pdev);
|
||||
free_workqueue:
|
||||
destroy_workqueue(gc->service_wq);
|
||||
gc->service_wq = NULL;
|
||||
dev_err(&pdev->dev, "%s failed (error %d)\n", __func__, err);
|
||||
return err;
|
||||
}
|
||||
@ -1947,7 +1948,10 @@ static void mana_gd_cleanup(struct pci_dev *pdev)
|
||||
|
||||
mana_gd_remove_irqs(pdev);
|
||||
|
||||
destroy_workqueue(gc->service_wq);
|
||||
if (gc->service_wq) {
|
||||
destroy_workqueue(gc->service_wq);
|
||||
gc->service_wq = NULL;
|
||||
}
|
||||
dev_dbg(&pdev->dev, "mana gdma cleanup successful\n");
|
||||
}
|
||||
|
||||
|
||||
@ -3525,7 +3525,9 @@ void mana_rdma_remove(struct gdma_dev *gd)
|
||||
}
|
||||
|
||||
WRITE_ONCE(gd->rdma_teardown, true);
|
||||
flush_workqueue(gc->service_wq);
|
||||
|
||||
if (gc->service_wq)
|
||||
flush_workqueue(gc->service_wq);
|
||||
|
||||
if (gd->adev)
|
||||
remove_adev(gd);
|
||||
|
||||
182
fs/eventpoll.c
182
fs/eventpoll.c
@ -147,13 +147,6 @@ struct epitem {
|
||||
/* The file descriptor information this item refers to */
|
||||
struct epoll_filefd ffd;
|
||||
|
||||
/*
|
||||
* Protected by file->f_lock, true for to-be-released epitem already
|
||||
* removed from the "struct file" items list; together with
|
||||
* eventpoll->refcount orchestrates "struct eventpoll" disposal
|
||||
*/
|
||||
bool dying;
|
||||
|
||||
/* List containing poll wait queues */
|
||||
struct eppoll_entry *pwqlist;
|
||||
|
||||
@ -219,12 +212,12 @@ struct eventpoll {
|
||||
struct hlist_head refs;
|
||||
u8 loop_check_depth;
|
||||
|
||||
/*
|
||||
* usage count, used together with epitem->dying to
|
||||
* orchestrate the disposal of this struct
|
||||
*/
|
||||
/* usage count, orchestrates "struct eventpoll" disposal */
|
||||
refcount_t refcount;
|
||||
|
||||
/* used to defer freeing past ep_get_upwards_depth_proc() RCU walk */
|
||||
struct rcu_head rcu;
|
||||
|
||||
#ifdef CONFIG_NET_RX_BUSY_POLL
|
||||
/* used to track busy poll napi_id */
|
||||
unsigned int napi_id;
|
||||
@ -708,41 +701,61 @@ static void ep_free(struct eventpoll *ep)
|
||||
mutex_destroy(&ep->mtx);
|
||||
free_uid(ep->user);
|
||||
wakeup_source_unregister(ep->ws);
|
||||
kfree(ep);
|
||||
/* ep_get_upwards_depth_proc() may still hold epi->ep under RCU */
|
||||
kfree_rcu(ep, rcu);
|
||||
}
|
||||
|
||||
/*
|
||||
* Removes a "struct epitem" from the eventpoll RB tree and deallocates
|
||||
* all the associated resources. Must be called with "mtx" held.
|
||||
* If the dying flag is set, do the removal only if force is true.
|
||||
* This prevents ep_clear_and_put() from dropping all the ep references
|
||||
* while running concurrently with eventpoll_release_file().
|
||||
* Returns true if the eventpoll can be disposed.
|
||||
* Pin @epi->ffd.file for operations that require both safe dereference
|
||||
* and exclusion from __fput().
|
||||
*
|
||||
* struct file uses SLAB_TYPESAFE_BY_RCU, so a freed slot can be
|
||||
* reassigned at any time. The bare load of epi->ffd.file is safe here
|
||||
* because the caller holds ep->mtx and eventpoll_release_file() blocks
|
||||
* on that mutex while tearing down the epi, so the backing file
|
||||
* allocation cannot be freed and reused under us. An rcu_read_lock()
|
||||
* is therefore unnecessary for the load.
|
||||
*
|
||||
* A successful file_ref_get() additionally blocks __fput() from
|
||||
* starting on this file: once the refcount has reached zero it cannot
|
||||
* come back. ep_remove() relies on that to touch file->f_lock and
|
||||
* file->f_ep without racing eventpoll_release_file() (see commit
|
||||
* a6dc643c6931). A NULL return means __fput() is already in flight;
|
||||
* the caller must bail without touching the file, and
|
||||
* eventpoll_release_file() will clean the epi up from its side.
|
||||
*/
|
||||
static bool __ep_remove(struct eventpoll *ep, struct epitem *epi, bool force)
|
||||
static struct file *epi_fget(const struct epitem *epi)
|
||||
{
|
||||
struct file *file = epi->ffd.file;
|
||||
struct epitems_head *to_free;
|
||||
struct file *file;
|
||||
|
||||
file = epi->ffd.file;
|
||||
if (!atomic_long_inc_not_zero(&file->f_count))
|
||||
file = NULL;
|
||||
return file;
|
||||
}
|
||||
|
||||
/*
|
||||
* Takes &file->f_lock; returns with it released.
|
||||
*/
|
||||
static void ep_remove_file(struct eventpoll *ep, struct epitem *epi,
|
||||
struct file *file)
|
||||
{
|
||||
struct epitems_head *to_free = NULL;
|
||||
struct hlist_head *head;
|
||||
|
||||
lockdep_assert_irqs_enabled();
|
||||
lockdep_assert_held(&ep->mtx);
|
||||
|
||||
/*
|
||||
* Removes poll wait queue hooks.
|
||||
*/
|
||||
ep_unregister_pollwait(ep, epi);
|
||||
|
||||
/* Remove the current item from the list of epoll hooks */
|
||||
spin_lock(&file->f_lock);
|
||||
if (epi->dying && !force) {
|
||||
spin_unlock(&file->f_lock);
|
||||
return false;
|
||||
}
|
||||
|
||||
to_free = NULL;
|
||||
head = file->f_ep;
|
||||
if (head->first == &epi->fllink && !epi->fllink.next) {
|
||||
file->f_ep = NULL;
|
||||
if (hlist_is_singular_node(&epi->fllink, head)) {
|
||||
/*
|
||||
* Last watcher: publish NULL so the eventpoll_release()
|
||||
* fastpath in include/linux/eventpoll.h can skip the slow
|
||||
* path on a future __fput(). Safe because every f_ep writer
|
||||
* either holds a pin on @file via epi_fget() or is __fput()
|
||||
* itself -- see the comment in eventpoll_release().
|
||||
*/
|
||||
WRITE_ONCE(file->f_ep, NULL);
|
||||
if (!is_file_epoll(file)) {
|
||||
struct epitems_head *v;
|
||||
v = container_of(head, struct epitems_head, epitems);
|
||||
@ -753,6 +766,11 @@ static bool __ep_remove(struct eventpoll *ep, struct epitem *epi, bool force)
|
||||
hlist_del_rcu(&epi->fllink);
|
||||
spin_unlock(&file->f_lock);
|
||||
free_ephead(to_free);
|
||||
}
|
||||
|
||||
static void ep_remove_epi(struct eventpoll *ep, struct epitem *epi)
|
||||
{
|
||||
lockdep_assert_held(&ep->mtx);
|
||||
|
||||
rb_erase_cached(&epi->rbn, &ep->rbr);
|
||||
|
||||
@ -772,16 +790,32 @@ static bool __ep_remove(struct eventpoll *ep, struct epitem *epi, bool force)
|
||||
call_rcu(&epi->rcu, epi_rcu_free);
|
||||
|
||||
percpu_counter_dec(&ep->user->epoll_watches);
|
||||
return true;
|
||||
}
|
||||
|
||||
/*
|
||||
* ep_remove variant for callers owing an additional reference to the ep
|
||||
*/
|
||||
static void ep_remove_safe(struct eventpoll *ep, struct epitem *epi)
|
||||
static void ep_remove(struct eventpoll *ep, struct epitem *epi)
|
||||
{
|
||||
if (__ep_remove(ep, epi, false))
|
||||
WARN_ON_ONCE(ep_refcount_dec_and_test(ep));
|
||||
struct file *file __free(fput) = NULL;
|
||||
|
||||
lockdep_assert_irqs_enabled();
|
||||
lockdep_assert_held(&ep->mtx);
|
||||
|
||||
ep_unregister_pollwait(ep, epi);
|
||||
|
||||
/*
|
||||
* If we manage to grab a reference it means we're not in
|
||||
* eventpoll_release_file() and aren't going to be: once @file's
|
||||
* refcount has reached zero, file_ref_get() cannot bring it back.
|
||||
*/
|
||||
file = epi_fget(epi);
|
||||
if (!file)
|
||||
return;
|
||||
|
||||
ep_remove_file(ep, epi, file);
|
||||
ep_remove_epi(ep, epi);
|
||||
WARN_ON_ONCE(ep_refcount_dec_and_test(ep));
|
||||
}
|
||||
|
||||
static void ep_clear_and_put(struct eventpoll *ep)
|
||||
@ -807,7 +841,7 @@ static void ep_clear_and_put(struct eventpoll *ep)
|
||||
|
||||
/*
|
||||
* Walks through the whole tree and try to free each "struct epitem".
|
||||
* Note that ep_remove_safe() will not remove the epitem in case of a
|
||||
* Note that ep_remove() will not remove the epitem in case of a
|
||||
* racing eventpoll_release_file(); the latter will do the removal.
|
||||
* At this point we are sure no poll callbacks will be lingering around.
|
||||
* Since we still own a reference to the eventpoll struct, the loop can't
|
||||
@ -816,7 +850,7 @@ static void ep_clear_and_put(struct eventpoll *ep)
|
||||
for (rbp = rb_first_cached(&ep->rbr); rbp; rbp = next) {
|
||||
next = rb_next(rbp);
|
||||
epi = rb_entry(rbp, struct epitem, rbn);
|
||||
ep_remove_safe(ep, epi);
|
||||
ep_remove(ep, epi);
|
||||
cond_resched();
|
||||
}
|
||||
|
||||
@ -875,34 +909,6 @@ static __poll_t __ep_eventpoll_poll(struct file *file, poll_table *wait, int dep
|
||||
return res;
|
||||
}
|
||||
|
||||
/*
|
||||
* The ffd.file pointer may be in the process of being torn down due to
|
||||
* being closed, but we may not have finished eventpoll_release() yet.
|
||||
*
|
||||
* Normally, even with the atomic_long_inc_not_zero, the file may have
|
||||
* been free'd and then gotten re-allocated to something else (since
|
||||
* files are not RCU-delayed, they are SLAB_TYPESAFE_BY_RCU).
|
||||
*
|
||||
* But for epoll, users hold the ep->mtx mutex, and as such any file in
|
||||
* the process of being free'd will block in eventpoll_release_file()
|
||||
* and thus the underlying file allocation will not be free'd, and the
|
||||
* file re-use cannot happen.
|
||||
*
|
||||
* For the same reason we can avoid a rcu_read_lock() around the
|
||||
* operation - 'ffd.file' cannot go away even if the refcount has
|
||||
* reached zero (but we must still not call out to ->poll() functions
|
||||
* etc).
|
||||
*/
|
||||
static struct file *epi_fget(const struct epitem *epi)
|
||||
{
|
||||
struct file *file;
|
||||
|
||||
file = epi->ffd.file;
|
||||
if (!atomic_long_inc_not_zero(&file->f_count))
|
||||
file = NULL;
|
||||
return file;
|
||||
}
|
||||
|
||||
/*
|
||||
* Differs from ep_eventpoll_poll() in that internal callers already have
|
||||
* the ep->mtx so we need to start from depth=1, such that mutex_lock_nested()
|
||||
@ -978,18 +984,17 @@ void eventpoll_release_file(struct file *file)
|
||||
{
|
||||
struct eventpoll *ep;
|
||||
struct epitem *epi;
|
||||
bool dispose;
|
||||
|
||||
/*
|
||||
* Use the 'dying' flag to prevent a concurrent ep_clear_and_put() from
|
||||
* touching the epitems list before eventpoll_release_file() can access
|
||||
* the ep->mtx.
|
||||
* A concurrent ep_remove() cannot outrace us: it pins @file via
|
||||
* epi_fget(), which fails once __fput() has dropped the refcount
|
||||
* to zero -- the path we're on. So any racing ep_remove() bails
|
||||
* and leaves the epi for us to clean up here.
|
||||
*/
|
||||
again:
|
||||
spin_lock(&file->f_lock);
|
||||
if (file->f_ep && file->f_ep->first) {
|
||||
epi = hlist_entry(file->f_ep->first, struct epitem, fllink);
|
||||
epi->dying = true;
|
||||
spin_unlock(&file->f_lock);
|
||||
|
||||
/*
|
||||
@ -998,10 +1003,15 @@ again:
|
||||
*/
|
||||
ep = epi->ep;
|
||||
mutex_lock(&ep->mtx);
|
||||
dispose = __ep_remove(ep, epi, true);
|
||||
|
||||
ep_unregister_pollwait(ep, epi);
|
||||
|
||||
ep_remove_file(ep, epi, file);
|
||||
ep_remove_epi(ep, epi);
|
||||
|
||||
mutex_unlock(&ep->mtx);
|
||||
|
||||
if (dispose && ep_refcount_dec_and_test(ep))
|
||||
if (ep_refcount_dec_and_test(ep))
|
||||
ep_free(ep);
|
||||
goto again;
|
||||
}
|
||||
@ -1505,7 +1515,8 @@ allocate:
|
||||
spin_unlock(&file->f_lock);
|
||||
goto allocate;
|
||||
}
|
||||
file->f_ep = head;
|
||||
/* See eventpoll_release() for details. */
|
||||
WRITE_ONCE(file->f_ep, head);
|
||||
to_free = NULL;
|
||||
}
|
||||
hlist_add_head_rcu(&epi->fllink, file->f_ep);
|
||||
@ -1571,21 +1582,21 @@ static int ep_insert(struct eventpoll *ep, const struct epoll_event *event,
|
||||
mutex_unlock(&tep->mtx);
|
||||
|
||||
/*
|
||||
* ep_remove_safe() calls in the later error paths can't lead to
|
||||
* ep_remove() calls in the later error paths can't lead to
|
||||
* ep_free() as the ep file itself still holds an ep reference.
|
||||
*/
|
||||
ep_get(ep);
|
||||
|
||||
/* now check if we've created too many backpaths */
|
||||
if (unlikely(full_check && reverse_path_check())) {
|
||||
ep_remove_safe(ep, epi);
|
||||
ep_remove(ep, epi);
|
||||
return -EINVAL;
|
||||
}
|
||||
|
||||
if (epi->event.events & EPOLLWAKEUP) {
|
||||
error = ep_create_wakeup_source(epi);
|
||||
if (error) {
|
||||
ep_remove_safe(ep, epi);
|
||||
ep_remove(ep, epi);
|
||||
return error;
|
||||
}
|
||||
}
|
||||
@ -1609,7 +1620,7 @@ static int ep_insert(struct eventpoll *ep, const struct epoll_event *event,
|
||||
* high memory pressure.
|
||||
*/
|
||||
if (unlikely(!epq.epi)) {
|
||||
ep_remove_safe(ep, epi);
|
||||
ep_remove(ep, epi);
|
||||
return -ENOMEM;
|
||||
}
|
||||
|
||||
@ -1972,7 +1983,8 @@ static int ep_poll(struct eventpoll *ep, struct epoll_event __user *events,
|
||||
* @ep: the &struct eventpoll to be currently checked.
|
||||
* @depth: Current depth of the path being checked.
|
||||
*
|
||||
* Return: depth of the subtree, or INT_MAX if we found a loop or went too deep.
|
||||
* Return: depth of the subtree, or a value bigger than EP_MAX_NESTS if we found
|
||||
* a loop or went too deep.
|
||||
*/
|
||||
static int ep_loop_check_proc(struct eventpoll *ep, int depth)
|
||||
{
|
||||
@ -1991,7 +2003,7 @@ static int ep_loop_check_proc(struct eventpoll *ep, int depth)
|
||||
struct eventpoll *ep_tovisit;
|
||||
ep_tovisit = epi->ffd.file->private_data;
|
||||
if (ep_tovisit == inserting_into || depth > EP_MAX_NESTS)
|
||||
result = INT_MAX;
|
||||
result = EP_MAX_NESTS+1;
|
||||
else
|
||||
result = max(result, ep_loop_check_proc(ep_tovisit, depth + 1) + 1);
|
||||
if (result > EP_MAX_NESTS)
|
||||
@ -2262,7 +2274,7 @@ int do_epoll_ctl(int epfd, int op, int fd, struct epoll_event *epds,
|
||||
* The eventpoll itself is still alive: the refcount
|
||||
* can't go to zero here.
|
||||
*/
|
||||
ep_remove_safe(ep, epi);
|
||||
ep_remove(ep, epi);
|
||||
error = 0;
|
||||
} else {
|
||||
error = -ENOENT;
|
||||
|
||||
@ -539,7 +539,7 @@ static int do_task_stat(struct seq_file *m, struct pid_namespace *ns,
|
||||
}
|
||||
|
||||
sid = task_session_nr_ns(task, ns);
|
||||
ppid = task_tgid_nr_ns(task->real_parent, ns);
|
||||
ppid = task_ppid_nr_ns(task, ns);
|
||||
pgid = task_pgrp_nr_ns(task, ns);
|
||||
|
||||
unlock_task_sighand(task, &flags);
|
||||
|
||||
@ -587,6 +587,10 @@ char *cifs_sanitize_prepath(char *prepath, gfp_t gfp)
|
||||
while (IS_DELIM(*cursor1))
|
||||
cursor1++;
|
||||
|
||||
/* exit in case of only delimiters */
|
||||
if (!*cursor1)
|
||||
return NULL;
|
||||
|
||||
/* copy the first letter */
|
||||
*cursor2 = *cursor1;
|
||||
|
||||
|
||||
@ -107,7 +107,7 @@ static int check_wsl_eas(struct kvec *rsp_iov)
|
||||
u32 outlen, next;
|
||||
u16 vlen;
|
||||
u8 nlen;
|
||||
u8 *end;
|
||||
u8 *ea_end, *iov_end;
|
||||
|
||||
outlen = le32_to_cpu(rsp->OutputBufferLength);
|
||||
if (outlen < SMB2_WSL_MIN_QUERY_EA_RESP_SIZE ||
|
||||
@ -116,15 +116,19 @@ static int check_wsl_eas(struct kvec *rsp_iov)
|
||||
|
||||
ea = (void *)((u8 *)rsp_iov->iov_base +
|
||||
le16_to_cpu(rsp->OutputBufferOffset));
|
||||
end = (u8 *)rsp_iov->iov_base + rsp_iov->iov_len;
|
||||
ea_end = (u8 *)ea + outlen;
|
||||
iov_end = (u8 *)rsp_iov->iov_base + rsp_iov->iov_len;
|
||||
if (ea_end > iov_end)
|
||||
return -EINVAL;
|
||||
|
||||
for (;;) {
|
||||
if ((u8 *)ea > end - sizeof(*ea))
|
||||
if ((u8 *)ea > ea_end - sizeof(*ea))
|
||||
return -EINVAL;
|
||||
|
||||
nlen = ea->ea_name_length;
|
||||
vlen = le16_to_cpu(ea->ea_value_length);
|
||||
if (nlen != SMB2_WSL_XATTR_NAME_LEN ||
|
||||
(u8 *)ea + nlen + 1 + vlen > end)
|
||||
(u8 *)ea->ea_data + nlen + 1 + vlen > ea_end)
|
||||
return -EINVAL;
|
||||
|
||||
switch (vlen) {
|
||||
|
||||
0
include/config/ARM64_ERRATUM_4118414
Normal file
0
include/config/ARM64_ERRATUM_4118414
Normal file
@ -1881,6 +1881,7 @@ CONFIG_BLK_DEV_IO_TRACE=y
|
||||
CONFIG_PHY_BRCM_SATA=y
|
||||
CONFIG_XPS=y
|
||||
CONFIG_SOC_TEGRA_PMC=y
|
||||
CONFIG_ARM64_ERRATUM_4118414=y
|
||||
CONFIG_NET_ACT_SKBEDIT=m
|
||||
CONFIG_INET_ESP=m
|
||||
CONFIG_SECURITY_SELINUX_DEVELOP=y
|
||||
|
||||
@ -1883,6 +1883,7 @@
|
||||
#define CONFIG_PHY_BRCM_SATA 1
|
||||
#define CONFIG_XPS 1
|
||||
#define CONFIG_SOC_TEGRA_PMC 1
|
||||
#define CONFIG_ARM64_ERRATUM_4118414 1
|
||||
#define CONFIG_NET_ACT_SKBEDIT_MODULE 1
|
||||
#define CONFIG_INET_ESP_MODULE 1
|
||||
#define CONFIG_SECURITY_SELINUX_DEVELOP 1
|
||||
|
||||
@ -35,14 +35,18 @@ static inline void eventpoll_release(struct file *file)
|
||||
{
|
||||
|
||||
/*
|
||||
* Fast check to avoid the get/release of the semaphore. Since
|
||||
* we're doing this outside the semaphore lock, it might return
|
||||
* false negatives, but we don't care. It'll help in 99.99% of cases
|
||||
* to avoid the semaphore lock. False positives simply cannot happen
|
||||
* because the file in on the way to be removed and nobody ( but
|
||||
* eventpoll ) has still a reference to this file.
|
||||
* Fast check to skip the slow path in the common case where the
|
||||
* file was never attached to an epoll. Safe without file->f_lock
|
||||
* because every f_ep writer excludes a concurrent __fput() on
|
||||
* @file:
|
||||
* - ep_insert() requires the file alive (refcount > 0);
|
||||
* - ep_remove() holds @file pinned via epi_fget() across the
|
||||
* write;
|
||||
* - eventpoll_release_file() runs from __fput() itself.
|
||||
* We are in __fput() here, so none of those can race us: a NULL
|
||||
* observation truly means no epoll path has work left on @file.
|
||||
*/
|
||||
if (likely(!file->f_ep))
|
||||
if (likely(!READ_ONCE(file->f_ep)))
|
||||
return;
|
||||
|
||||
/*
|
||||
|
||||
@ -1,3 +1,3 @@
|
||||
sbat,1,SBAT Version,sbat,1,https://github.com/rhboot/shim/blob/main/SBAT.md
|
||||
kernel.rhel,1,Red Hat,kernel-core,5.14.0-687.20.1.el9.x86_64,mailto:secalert@redhat.com
|
||||
kernel.almalinux,1,AlmaLinux,kernel-core,5.14.0-687.20.1.el9.x86_64,mailto:security@almalinux.org
|
||||
kernel.rhel,1,Red Hat,kernel-core,5.14.0-687.23.1.el9.x86_64,mailto:secalert@redhat.com
|
||||
kernel.almalinux,1,AlmaLinux,kernel-core,5.14.0-687.23.1.el9.x86_64,mailto:security@almalinux.org
|
||||
|
||||
@ -31,6 +31,9 @@ ebt_snat_tg(struct sk_buff *skb, const struct xt_action_param *par)
|
||||
const struct arphdr *ap;
|
||||
struct arphdr _ah;
|
||||
|
||||
if (skb_ensure_writable(skb, sizeof(_ah) + ETH_ALEN))
|
||||
return EBT_DROP;
|
||||
|
||||
ap = skb_header_pointer(skb, 0, sizeof(_ah), &_ah);
|
||||
if (ap == NULL)
|
||||
return EBT_DROP;
|
||||
|
||||
@ -113,6 +113,9 @@ int skb_gro_receive(struct sk_buff *p, struct sk_buff *skb)
|
||||
if (p->pp_recycle != skb->pp_recycle)
|
||||
return -ETOOMANYREFS;
|
||||
|
||||
if (skb_zcopy(p) || skb_zcopy(skb))
|
||||
return -ETOOMANYREFS;
|
||||
|
||||
/* pairs with WRITE_ONCE() in netif_set_gro(_ipv4)_max_size() */
|
||||
gro_max_size = p->protocol == htons(ETH_P_IPV6) ?
|
||||
READ_ONCE(p->dev->gro_max_size) :
|
||||
|
||||
@ -156,7 +156,6 @@ static int nft_inner_parse_l2l3(const struct nft_inner *priv,
|
||||
return -1;
|
||||
|
||||
if (fragoff == 0) {
|
||||
thoff = nhoff + sizeof(_ip6h);
|
||||
ctx->flags |= NFT_PAYLOAD_CTX_INNER_TH;
|
||||
ctx->inner_thoff = thoff;
|
||||
ctx->l4proto = l4proto;
|
||||
|
||||
@ -1988,6 +1988,15 @@ static int sctp_sendmsg(struct sock *sk, struct msghdr *msg, size_t msg_len)
|
||||
goto out_unlock;
|
||||
|
||||
iov_iter_revert(&msg->msg_iter, err);
|
||||
|
||||
/* sctp_sendmsg_to_asoc() may have released the socket
|
||||
* lock (sctp_wait_for_sndbuf), during which other
|
||||
* associations on ep->asocs could have been peeled
|
||||
* off or freed. @asoc itself is revalidated by the
|
||||
* base.dead and base.sk checks in sctp_wait_for_sndbuf,
|
||||
* so re-derive the cached cursor from it.
|
||||
*/
|
||||
tmp = list_next_entry(asoc, asocs);
|
||||
}
|
||||
|
||||
goto out_unlock;
|
||||
|
||||
@ -751,12 +751,12 @@ int __xfrm_state_delete(struct xfrm_state *x)
|
||||
x->km.state = XFRM_STATE_DEAD;
|
||||
spin_lock(&net->xfrm.xfrm_state_lock);
|
||||
list_del(&x->km.all);
|
||||
hlist_del_rcu(&x->bydst);
|
||||
hlist_del_rcu(&x->bysrc);
|
||||
if (x->km.seq)
|
||||
hlist_del_rcu(&x->byseq);
|
||||
if (x->id.spi)
|
||||
hlist_del_rcu(&x->byspi);
|
||||
hlist_del_init_rcu(&x->bydst);
|
||||
hlist_del_init_rcu(&x->bysrc);
|
||||
if (!hlist_unhashed(&x->byseq))
|
||||
hlist_del_init_rcu(&x->byseq);
|
||||
if (!hlist_unhashed(&x->byspi))
|
||||
hlist_del_init_rcu(&x->byspi);
|
||||
net->xfrm.state_num--;
|
||||
spin_unlock(&net->xfrm.xfrm_state_lock);
|
||||
|
||||
|
||||
Loading…
Reference in New Issue
Block a user