]> git.ipfire.org Git - thirdparty/kernel/stable-queue.git/commitdiff
Fixes for 5.10
authorSasha Levin <sashal@kernel.org>
Thu, 30 Dec 2021 02:22:47 +0000 (21:22 -0500)
committerSasha Levin <sashal@kernel.org>
Thu, 30 Dec 2021 02:22:47 +0000 (21:22 -0500)
Signed-off-by: Sasha Levin <sashal@kernel.org>
queue-5.10/input-i8042-add-deferred-probe-support.patch [new file with mode: 0644]
queue-5.10/input-i8042-enable-deferred-probe-quirk-for-asus-um3.patch [new file with mode: 0644]
queue-5.10/memblock-fix-memblock_phys_alloc-section-mismatch-er.patch [new file with mode: 0644]
queue-5.10/parisc-clear-stale-iir-value-on-instruction-access-r.patch [new file with mode: 0644]
queue-5.10/platform-x86-apple-gmux-use-resource_size-with-res.patch [new file with mode: 0644]
queue-5.10/series
queue-5.10/tomoyo-check-exceeded-quota-early-in-tomoyo_domain_q.patch [new file with mode: 0644]
queue-5.10/tomoyo-use-hwight16-in-tomoyo_domain_quota_is_ok.patch [new file with mode: 0644]

diff --git a/queue-5.10/input-i8042-add-deferred-probe-support.patch b/queue-5.10/input-i8042-add-deferred-probe-support.patch
new file mode 100644 (file)
index 0000000..4506525
--- /dev/null
@@ -0,0 +1,276 @@
+From c21db216683ae7d596d579794c11076c09c14cd0 Mon Sep 17 00:00:00 2001
+From: Sasha Levin <sashal@kernel.org>
+Date: Sun, 28 Nov 2021 23:21:41 -0800
+Subject: Input: i8042 - add deferred probe support
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+From: Takashi Iwai <tiwai@suse.de>
+
+[ Upstream commit 9222ba68c3f4065f6364b99cc641b6b019ef2d42 ]
+
+We've got a bug report about the non-working keyboard on ASUS ZenBook
+UX425UA.  It seems that the PS/2 device isn't ready immediately at
+boot but takes some seconds to get ready.  Until now, the only
+workaround is to defer the probe, but it's available only when the
+driver is a module.  However, many distros, including openSUSE as in
+the original report, build the PS/2 input drivers into kernel, hence
+it won't work easily.
+
+This patch adds the support for the deferred probe for i8042 stuff as
+a workaround of the problem above.  When the deferred probe mode is
+enabled and the device couldn't be probed, it'll be repeated with the
+standard deferred probe mechanism.
+
+The deferred probe mode is enabled either via the new option
+i8042.probe_defer or via the quirk table entry.  As of this patch, the
+quirk table contains only ASUS ZenBook UX425UA.
+
+The deferred probe part is based on Fabio's initial work.
+
+BugLink: https://bugzilla.suse.com/show_bug.cgi?id=1190256
+Signed-off-by: Takashi Iwai <tiwai@suse.de>
+Tested-by: Samuel Čavoj <samuel@cavoj.net>
+Link: https://lore.kernel.org/r/20211117063757.11380-1-tiwai@suse.de
+
+Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
+Signed-off-by: Sasha Levin <sashal@kernel.org>
+---
+ .../admin-guide/kernel-parameters.txt         |  2 +
+ drivers/input/serio/i8042-x86ia64io.h         | 14 +++++
+ drivers/input/serio/i8042.c                   | 54 ++++++++++++-------
+ 3 files changed, 51 insertions(+), 19 deletions(-)
+
+diff --git a/Documentation/admin-guide/kernel-parameters.txt b/Documentation/admin-guide/kernel-parameters.txt
+index ccaa72562538e..d00618967854d 100644
+--- a/Documentation/admin-guide/kernel-parameters.txt
++++ b/Documentation/admin-guide/kernel-parameters.txt
+@@ -1617,6 +1617,8 @@
+                       architectures force reset to be always executed
+       i8042.unlock    [HW] Unlock (ignore) the keylock
+       i8042.kbdreset  [HW] Reset device connected to KBD port
++      i8042.probe_defer
++                      [HW] Allow deferred probing upon i8042 probe errors
+       i810=           [HW,DRM]
+diff --git a/drivers/input/serio/i8042-x86ia64io.h b/drivers/input/serio/i8042-x86ia64io.h
+index aedd055410443..1acc7c8449294 100644
+--- a/drivers/input/serio/i8042-x86ia64io.h
++++ b/drivers/input/serio/i8042-x86ia64io.h
+@@ -995,6 +995,17 @@ static const struct dmi_system_id __initconst i8042_dmi_kbdreset_table[] = {
+       { }
+ };
++static const struct dmi_system_id i8042_dmi_probe_defer_table[] __initconst = {
++      {
++              /* ASUS ZenBook UX425UA */
++              .matches = {
++                      DMI_MATCH(DMI_SYS_VENDOR, "ASUSTeK COMPUTER INC."),
++                      DMI_MATCH(DMI_PRODUCT_NAME, "ZenBook UX425UA"),
++              },
++      },
++      { }
++};
++
+ #endif /* CONFIG_X86 */
+ #ifdef CONFIG_PNP
+@@ -1315,6 +1326,9 @@ static int __init i8042_platform_init(void)
+       if (dmi_check_system(i8042_dmi_kbdreset_table))
+               i8042_kbdreset = true;
++      if (dmi_check_system(i8042_dmi_probe_defer_table))
++              i8042_probe_defer = true;
++
+       /*
+        * A20 was already enabled during early kernel init. But some buggy
+        * BIOSes (in MSI Laptops) require A20 to be enabled using 8042 to
+diff --git a/drivers/input/serio/i8042.c b/drivers/input/serio/i8042.c
+index abae23af0791e..a9f68f535b727 100644
+--- a/drivers/input/serio/i8042.c
++++ b/drivers/input/serio/i8042.c
+@@ -45,6 +45,10 @@ static bool i8042_unlock;
+ module_param_named(unlock, i8042_unlock, bool, 0);
+ MODULE_PARM_DESC(unlock, "Ignore keyboard lock.");
++static bool i8042_probe_defer;
++module_param_named(probe_defer, i8042_probe_defer, bool, 0);
++MODULE_PARM_DESC(probe_defer, "Allow deferred probing.");
++
+ enum i8042_controller_reset_mode {
+       I8042_RESET_NEVER,
+       I8042_RESET_ALWAYS,
+@@ -711,7 +715,7 @@ static int i8042_set_mux_mode(bool multiplex, unsigned char *mux_version)
+  * LCS/Telegraphics.
+  */
+-static int __init i8042_check_mux(void)
++static int i8042_check_mux(void)
+ {
+       unsigned char mux_version;
+@@ -740,10 +744,10 @@ static int __init i8042_check_mux(void)
+ /*
+  * The following is used to test AUX IRQ delivery.
+  */
+-static struct completion i8042_aux_irq_delivered __initdata;
+-static bool i8042_irq_being_tested __initdata;
++static struct completion i8042_aux_irq_delivered;
++static bool i8042_irq_being_tested;
+-static irqreturn_t __init i8042_aux_test_irq(int irq, void *dev_id)
++static irqreturn_t i8042_aux_test_irq(int irq, void *dev_id)
+ {
+       unsigned long flags;
+       unsigned char str, data;
+@@ -770,7 +774,7 @@ static irqreturn_t __init i8042_aux_test_irq(int irq, void *dev_id)
+  * verifies success by readinng CTR. Used when testing for presence of AUX
+  * port.
+  */
+-static int __init i8042_toggle_aux(bool on)
++static int i8042_toggle_aux(bool on)
+ {
+       unsigned char param;
+       int i;
+@@ -798,7 +802,7 @@ static int __init i8042_toggle_aux(bool on)
+  * the presence of an AUX interface.
+  */
+-static int __init i8042_check_aux(void)
++static int i8042_check_aux(void)
+ {
+       int retval = -1;
+       bool irq_registered = false;
+@@ -1005,7 +1009,7 @@ static int i8042_controller_init(void)
+               if (i8042_command(&ctr[n++ % 2], I8042_CMD_CTL_RCTR)) {
+                       pr_err("Can't read CTR while initializing i8042\n");
+-                      return -EIO;
++                      return i8042_probe_defer ? -EPROBE_DEFER : -EIO;
+               }
+       } while (n < 2 || ctr[0] != ctr[1]);
+@@ -1320,7 +1324,7 @@ static void i8042_shutdown(struct platform_device *dev)
+       i8042_controller_reset(false);
+ }
+-static int __init i8042_create_kbd_port(void)
++static int i8042_create_kbd_port(void)
+ {
+       struct serio *serio;
+       struct i8042_port *port = &i8042_ports[I8042_KBD_PORT_NO];
+@@ -1349,7 +1353,7 @@ static int __init i8042_create_kbd_port(void)
+       return 0;
+ }
+-static int __init i8042_create_aux_port(int idx)
++static int i8042_create_aux_port(int idx)
+ {
+       struct serio *serio;
+       int port_no = idx < 0 ? I8042_AUX_PORT_NO : I8042_MUX_PORT_NO + idx;
+@@ -1386,13 +1390,13 @@ static int __init i8042_create_aux_port(int idx)
+       return 0;
+ }
+-static void __init i8042_free_kbd_port(void)
++static void i8042_free_kbd_port(void)
+ {
+       kfree(i8042_ports[I8042_KBD_PORT_NO].serio);
+       i8042_ports[I8042_KBD_PORT_NO].serio = NULL;
+ }
+-static void __init i8042_free_aux_ports(void)
++static void i8042_free_aux_ports(void)
+ {
+       int i;
+@@ -1402,7 +1406,7 @@ static void __init i8042_free_aux_ports(void)
+       }
+ }
+-static void __init i8042_register_ports(void)
++static void i8042_register_ports(void)
+ {
+       int i;
+@@ -1443,7 +1447,7 @@ static void i8042_free_irqs(void)
+       i8042_aux_irq_registered = i8042_kbd_irq_registered = false;
+ }
+-static int __init i8042_setup_aux(void)
++static int i8042_setup_aux(void)
+ {
+       int (*aux_enable)(void);
+       int error;
+@@ -1485,7 +1489,7 @@ static int __init i8042_setup_aux(void)
+       return error;
+ }
+-static int __init i8042_setup_kbd(void)
++static int i8042_setup_kbd(void)
+ {
+       int error;
+@@ -1535,7 +1539,7 @@ static int i8042_kbd_bind_notifier(struct notifier_block *nb,
+       return 0;
+ }
+-static int __init i8042_probe(struct platform_device *dev)
++static int i8042_probe(struct platform_device *dev)
+ {
+       int error;
+@@ -1600,6 +1604,7 @@ static struct platform_driver i8042_driver = {
+               .pm     = &i8042_pm_ops,
+ #endif
+       },
++      .probe          = i8042_probe,
+       .remove         = i8042_remove,
+       .shutdown       = i8042_shutdown,
+ };
+@@ -1610,7 +1615,6 @@ static struct notifier_block i8042_kbd_bind_notifier_block = {
+ static int __init i8042_init(void)
+ {
+-      struct platform_device *pdev;
+       int err;
+       dbg_init();
+@@ -1626,17 +1630,29 @@ static int __init i8042_init(void)
+       /* Set this before creating the dev to allow i8042_command to work right away */
+       i8042_present = true;
+-      pdev = platform_create_bundle(&i8042_driver, i8042_probe, NULL, 0, NULL, 0);
+-      if (IS_ERR(pdev)) {
+-              err = PTR_ERR(pdev);
++      err = platform_driver_register(&i8042_driver);
++      if (err)
+               goto err_platform_exit;
++
++      i8042_platform_device = platform_device_alloc("i8042", -1);
++      if (!i8042_platform_device) {
++              err = -ENOMEM;
++              goto err_unregister_driver;
+       }
++      err = platform_device_add(i8042_platform_device);
++      if (err)
++              goto err_free_device;
++
+       bus_register_notifier(&serio_bus, &i8042_kbd_bind_notifier_block);
+       panic_blink = i8042_panic_blink;
+       return 0;
++err_free_device:
++      platform_device_put(i8042_platform_device);
++err_unregister_driver:
++      platform_driver_unregister(&i8042_driver);
+  err_platform_exit:
+       i8042_platform_exit();
+       return err;
+-- 
+2.34.1
+
diff --git a/queue-5.10/input-i8042-enable-deferred-probe-quirk-for-asus-um3.patch b/queue-5.10/input-i8042-enable-deferred-probe-quirk-for-asus-um3.patch
new file mode 100644 (file)
index 0000000..646b6d6
--- /dev/null
@@ -0,0 +1,48 @@
+From 41e9e8e23dc284e22ee49173180ee19e6d756831 Mon Sep 17 00:00:00 2001
+From: Sasha Levin <sashal@kernel.org>
+Date: Sat, 4 Dec 2021 13:17:36 -0800
+Subject: Input: i8042 - enable deferred probe quirk for ASUS UM325UA
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+From: Samuel Čavoj <samuel@cavoj.net>
+
+[ Upstream commit 44ee250aeeabb28b52a10397ac17ffb8bfe94839 ]
+
+The ASUS UM325UA suffers from the same issue as the ASUS UX425UA, which
+is a very similar laptop. The i8042 device is not usable immediately
+after boot and fails to initialize, requiring a deferred retry.
+
+Enable the deferred probe quirk for the UM325UA.
+
+BugLink: https://bugzilla.suse.com/show_bug.cgi?id=1190256
+Signed-off-by: Samuel Čavoj <samuel@cavoj.net>
+Link: https://lore.kernel.org/r/20211204015615.232948-1-samuel@cavoj.net
+Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
+Signed-off-by: Sasha Levin <sashal@kernel.org>
+---
+ drivers/input/serio/i8042-x86ia64io.h | 7 +++++++
+ 1 file changed, 7 insertions(+)
+
+diff --git a/drivers/input/serio/i8042-x86ia64io.h b/drivers/input/serio/i8042-x86ia64io.h
+index 1acc7c8449294..148a7c5fd0e22 100644
+--- a/drivers/input/serio/i8042-x86ia64io.h
++++ b/drivers/input/serio/i8042-x86ia64io.h
+@@ -1003,6 +1003,13 @@ static const struct dmi_system_id i8042_dmi_probe_defer_table[] __initconst = {
+                       DMI_MATCH(DMI_PRODUCT_NAME, "ZenBook UX425UA"),
+               },
+       },
++      {
++              /* ASUS ZenBook UM325UA */
++              .matches = {
++                      DMI_MATCH(DMI_SYS_VENDOR, "ASUSTeK COMPUTER INC."),
++                      DMI_MATCH(DMI_PRODUCT_NAME, "ZenBook UX325UA_UM325UA"),
++              },
++      },
+       { }
+ };
+-- 
+2.34.1
+
diff --git a/queue-5.10/memblock-fix-memblock_phys_alloc-section-mismatch-er.patch b/queue-5.10/memblock-fix-memblock_phys_alloc-section-mismatch-er.patch
new file mode 100644 (file)
index 0000000..91d872f
--- /dev/null
@@ -0,0 +1,55 @@
+From 39757126d987f1689e9ed40a836fb02fabf29405 Mon Sep 17 00:00:00 2001
+From: Sasha Levin <sashal@kernel.org>
+Date: Fri, 17 Dec 2021 10:07:54 +0800
+Subject: memblock: fix memblock_phys_alloc() section mismatch error
+
+From: Jackie Liu <liuyun01@kylinos.cn>
+
+[ Upstream commit d7f55471db2719629f773c2d6b5742a69595bfd3 ]
+
+Fix modpost Section mismatch error in memblock_phys_alloc()
+
+[...]
+WARNING: modpost: vmlinux.o(.text.unlikely+0x1dcc): Section mismatch in reference
+from the function memblock_phys_alloc() to the function .init.text:memblock_phys_alloc_range()
+The function memblock_phys_alloc() references
+the function __init memblock_phys_alloc_range().
+This is often because memblock_phys_alloc lacks a __init
+annotation or the annotation of memblock_phys_alloc_range is wrong.
+
+ERROR: modpost: Section mismatches detected.
+Set CONFIG_SECTION_MISMATCH_WARN_ONLY=y to allow them.
+[...]
+
+memblock_phys_alloc() is a one-line wrapper, make it __always_inline to
+avoid these section mismatches.
+
+Reported-by: k2ci <kernel-bot@kylinos.cn>
+Suggested-by: Mike Rapoport <rppt@kernel.org>
+Signed-off-by: Jackie Liu <liuyun01@kylinos.cn>
+[rppt: slightly massaged changelog ]
+Signed-off-by: Mike Rapoport <rppt@linux.ibm.com>
+Link: https://lore.kernel.org/r/20211217020754.2874872-1-liu.yun@linux.dev
+Signed-off-by: Sasha Levin <sashal@kernel.org>
+---
+ include/linux/memblock.h | 4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+diff --git a/include/linux/memblock.h b/include/linux/memblock.h
+index 1a8d25f2e0412..3baea2ef33fbb 100644
+--- a/include/linux/memblock.h
++++ b/include/linux/memblock.h
+@@ -387,8 +387,8 @@ phys_addr_t memblock_alloc_range_nid(phys_addr_t size,
+                                     phys_addr_t end, int nid, bool exact_nid);
+ phys_addr_t memblock_phys_alloc_try_nid(phys_addr_t size, phys_addr_t align, int nid);
+-static inline phys_addr_t memblock_phys_alloc(phys_addr_t size,
+-                                            phys_addr_t align)
++static __always_inline phys_addr_t memblock_phys_alloc(phys_addr_t size,
++                                                     phys_addr_t align)
+ {
+       return memblock_phys_alloc_range(size, align, 0,
+                                        MEMBLOCK_ALLOC_ACCESSIBLE);
+-- 
+2.34.1
+
diff --git a/queue-5.10/parisc-clear-stale-iir-value-on-instruction-access-r.patch b/queue-5.10/parisc-clear-stale-iir-value-on-instruction-access-r.patch
new file mode 100644 (file)
index 0000000..525170b
--- /dev/null
@@ -0,0 +1,43 @@
+From 0896c841802374350db1d2a827cb1aceb4b3ccc7 Mon Sep 17 00:00:00 2001
+From: Sasha Levin <sashal@kernel.org>
+Date: Wed, 8 Dec 2021 11:06:52 +0100
+Subject: parisc: Clear stale IIR value on instruction access rights trap
+
+From: Helge Deller <deller@gmx.de>
+
+[ Upstream commit 484730e5862f6b872dca13840bed40fd7c60fa26 ]
+
+When a trap 7 (Instruction access rights) occurs, this means the CPU
+couldn't execute an instruction due to missing execute permissions on
+the memory region.  In this case it seems the CPU didn't even fetched
+the instruction from memory and thus did not store it in the cr19 (IIR)
+register before calling the trap handler. So, the trap handler will find
+some random old stale value in cr19.
+
+This patch simply overwrites the stale IIR value with a constant magic
+"bad food" value (0xbaadf00d), in the hope people don't start to try to
+understand the various random IIR values in trap 7 dumps.
+
+Noticed-by: John David Anglin <dave.anglin@bell.net>
+Signed-off-by: Helge Deller <deller@gmx.de>
+Signed-off-by: Sasha Levin <sashal@kernel.org>
+---
+ arch/parisc/kernel/traps.c | 2 ++
+ 1 file changed, 2 insertions(+)
+
+diff --git a/arch/parisc/kernel/traps.c b/arch/parisc/kernel/traps.c
+index a52c7abf2ca49..43f56335759a4 100644
+--- a/arch/parisc/kernel/traps.c
++++ b/arch/parisc/kernel/traps.c
+@@ -729,6 +729,8 @@ void notrace handle_interruption(int code, struct pt_regs *regs)
+                       }
+                       mmap_read_unlock(current->mm);
+               }
++              /* CPU could not fetch instruction, so clear stale IIR value. */
++              regs->iir = 0xbaadf00d;
+               fallthrough;
+       case 27: 
+               /* Data memory protection ID trap */
+-- 
+2.34.1
+
diff --git a/queue-5.10/platform-x86-apple-gmux-use-resource_size-with-res.patch b/queue-5.10/platform-x86-apple-gmux-use-resource_size-with-res.patch
new file mode 100644 (file)
index 0000000..7983735
--- /dev/null
@@ -0,0 +1,37 @@
+From 1a4dc8a5f27a33b85cf908177417a1d780c0d65e Mon Sep 17 00:00:00 2001
+From: Sasha Levin <sashal@kernel.org>
+Date: Tue, 14 Dec 2021 04:18:36 -0800
+Subject: platform/x86: apple-gmux: use resource_size() with res
+
+From: Wang Qing <wangqing@vivo.com>
+
+[ Upstream commit eb66fb03a727cde0ab9b1a3858de55c26f3007da ]
+
+This should be (res->end - res->start + 1) here actually,
+use resource_size() derectly.
+
+Signed-off-by: Wang Qing <wangqing@vivo.com>
+Link: https://lore.kernel.org/r/1639484316-75873-1-git-send-email-wangqing@vivo.com
+Reviewed-by: Hans de Goede <hdegoede@redhat.com>
+Signed-off-by: Hans de Goede <hdegoede@redhat.com>
+Signed-off-by: Sasha Levin <sashal@kernel.org>
+---
+ drivers/platform/x86/apple-gmux.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/drivers/platform/x86/apple-gmux.c b/drivers/platform/x86/apple-gmux.c
+index 9aae45a452002..57553f9b4d1dc 100644
+--- a/drivers/platform/x86/apple-gmux.c
++++ b/drivers/platform/x86/apple-gmux.c
+@@ -625,7 +625,7 @@ static int gmux_probe(struct pnp_dev *pnp, const struct pnp_device_id *id)
+       }
+       gmux_data->iostart = res->start;
+-      gmux_data->iolen = res->end - res->start;
++      gmux_data->iolen = resource_size(res);
+       if (gmux_data->iolen < GMUX_MIN_IO_LEN) {
+               pr_err("gmux I/O region too small (%lu < %u)\n",
+-- 
+2.34.1
+
index e69de29bb2d1d6434b8b29ae775ad8c2e48c5391..8811f6e3aaf9603b46c10e08a4b51336649eed27 100644 (file)
@@ -0,0 +1,7 @@
+input-i8042-add-deferred-probe-support.patch
+input-i8042-enable-deferred-probe-quirk-for-asus-um3.patch
+tomoyo-check-exceeded-quota-early-in-tomoyo_domain_q.patch
+tomoyo-use-hwight16-in-tomoyo_domain_quota_is_ok.patch
+parisc-clear-stale-iir-value-on-instruction-access-r.patch
+platform-x86-apple-gmux-use-resource_size-with-res.patch
+memblock-fix-memblock_phys_alloc-section-mismatch-er.patch
diff --git a/queue-5.10/tomoyo-check-exceeded-quota-early-in-tomoyo_domain_q.patch b/queue-5.10/tomoyo-check-exceeded-quota-early-in-tomoyo_domain_q.patch
new file mode 100644 (file)
index 0000000..5ae2feb
--- /dev/null
@@ -0,0 +1,69 @@
+From 9ae09de077f3e632a36cd3f18aa863d681697d5c Mon Sep 17 00:00:00 2001
+From: Sasha Levin <sashal@kernel.org>
+Date: Tue, 14 Dec 2021 10:45:26 +0100
+Subject: tomoyo: Check exceeded quota early in tomoyo_domain_quota_is_ok().
+
+From: Dmitry Vyukov <dvyukov@google.com>
+
+[ Upstream commit 04e57a2d952bbd34bc45744e72be3eecdc344294 ]
+
+If tomoyo is used in a testing/fuzzing environment in learning mode,
+for lots of domains the quota will be exceeded and stay exceeded
+for prolonged periods of time. In such cases it's pointless (and slow)
+to walk the whole acl list again and again just to rediscover that
+the quota is exceeded. We already have the TOMOYO_DIF_QUOTA_WARNED flag
+that notes the overflow condition. Check it early to avoid the slowdown.
+
+[penguin-kernel]
+This patch causes a user visible change that the learning mode will not be
+automatically resumed after the quota is increased. To resume the learning
+mode, administrator will need to explicitly clear TOMOYO_DIF_QUOTA_WARNED
+flag after increasing the quota. But I think that this change is generally
+preferable, for administrator likely wants to optimize the acl list for
+that domain before increasing the quota, or that domain likely hits the
+quota again. Therefore, don't try to care to clear TOMOYO_DIF_QUOTA_WARNED
+flag automatically when the quota for that domain changed.
+
+Signed-off-by: Dmitry Vyukov <dvyukov@google.com>
+Signed-off-by: Tetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp>
+Signed-off-by: Sasha Levin <sashal@kernel.org>
+---
+ security/tomoyo/util.c | 14 +++++++-------
+ 1 file changed, 7 insertions(+), 7 deletions(-)
+
+diff --git a/security/tomoyo/util.c b/security/tomoyo/util.c
+index cd458e10cf2af..ee9c2aa0c8df9 100644
+--- a/security/tomoyo/util.c
++++ b/security/tomoyo/util.c
+@@ -1046,6 +1046,8 @@ bool tomoyo_domain_quota_is_ok(struct tomoyo_request_info *r)
+               return false;
+       if (!domain)
+               return true;
++      if (READ_ONCE(domain->flags[TOMOYO_DIF_QUOTA_WARNED]))
++              return false;
+       list_for_each_entry_rcu(ptr, &domain->acl_info_list, list,
+                               srcu_read_lock_held(&tomoyo_ss)) {
+               u16 perm;
+@@ -1091,14 +1093,12 @@ bool tomoyo_domain_quota_is_ok(struct tomoyo_request_info *r)
+       if (count < tomoyo_profile(domain->ns, domain->profile)->
+           pref[TOMOYO_PREF_MAX_LEARNING_ENTRY])
+               return true;
+-      if (!domain->flags[TOMOYO_DIF_QUOTA_WARNED]) {
+-              domain->flags[TOMOYO_DIF_QUOTA_WARNED] = true;
+-              /* r->granted = false; */
+-              tomoyo_write_log(r, "%s", tomoyo_dif[TOMOYO_DIF_QUOTA_WARNED]);
++      WRITE_ONCE(domain->flags[TOMOYO_DIF_QUOTA_WARNED], true);
++      /* r->granted = false; */
++      tomoyo_write_log(r, "%s", tomoyo_dif[TOMOYO_DIF_QUOTA_WARNED]);
+ #ifndef CONFIG_SECURITY_TOMOYO_INSECURE_BUILTIN_SETTING
+-              pr_warn("WARNING: Domain '%s' has too many ACLs to hold. Stopped learning mode.\n",
+-                      domain->domainname->name);
++      pr_warn("WARNING: Domain '%s' has too many ACLs to hold. Stopped learning mode.\n",
++              domain->domainname->name);
+ #endif
+-      }
+       return false;
+ }
+-- 
+2.34.1
+
diff --git a/queue-5.10/tomoyo-use-hwight16-in-tomoyo_domain_quota_is_ok.patch b/queue-5.10/tomoyo-use-hwight16-in-tomoyo_domain_quota_is_ok.patch
new file mode 100644 (file)
index 0000000..2df908e
--- /dev/null
@@ -0,0 +1,75 @@
+From 600b32fcaa9832d3a5d0ab0f4e2edfdc014c3179 Mon Sep 17 00:00:00 2001
+From: Sasha Levin <sashal@kernel.org>
+Date: Wed, 15 Dec 2021 20:13:55 +0900
+Subject: tomoyo: use hwight16() in tomoyo_domain_quota_is_ok()
+
+From: Tetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp>
+
+[ Upstream commit f702e1107601230eec707739038a89018ea3468d ]
+
+hwight16() is much faster. While we are at it, no need to include
+"perm =" part into data_race() macro, for perm is a local variable
+that cannot be accessed by other threads.
+
+Signed-off-by: Tetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp>
+Signed-off-by: Sasha Levin <sashal@kernel.org>
+---
+ security/tomoyo/util.c | 17 +++++++----------
+ 1 file changed, 7 insertions(+), 10 deletions(-)
+
+diff --git a/security/tomoyo/util.c b/security/tomoyo/util.c
+index ee9c2aa0c8df9..11dd8260c9cc7 100644
+--- a/security/tomoyo/util.c
++++ b/security/tomoyo/util.c
+@@ -1051,7 +1051,6 @@ bool tomoyo_domain_quota_is_ok(struct tomoyo_request_info *r)
+       list_for_each_entry_rcu(ptr, &domain->acl_info_list, list,
+                               srcu_read_lock_held(&tomoyo_ss)) {
+               u16 perm;
+-              u8 i;
+               if (ptr->is_deleted)
+                       continue;
+@@ -1062,23 +1061,23 @@ bool tomoyo_domain_quota_is_ok(struct tomoyo_request_info *r)
+                */
+               switch (ptr->type) {
+               case TOMOYO_TYPE_PATH_ACL:
+-                      data_race(perm = container_of(ptr, struct tomoyo_path_acl, head)->perm);
++                      perm = data_race(container_of(ptr, struct tomoyo_path_acl, head)->perm);
+                       break;
+               case TOMOYO_TYPE_PATH2_ACL:
+-                      data_race(perm = container_of(ptr, struct tomoyo_path2_acl, head)->perm);
++                      perm = data_race(container_of(ptr, struct tomoyo_path2_acl, head)->perm);
+                       break;
+               case TOMOYO_TYPE_PATH_NUMBER_ACL:
+-                      data_race(perm = container_of(ptr, struct tomoyo_path_number_acl, head)
++                      perm = data_race(container_of(ptr, struct tomoyo_path_number_acl, head)
+                                 ->perm);
+                       break;
+               case TOMOYO_TYPE_MKDEV_ACL:
+-                      data_race(perm = container_of(ptr, struct tomoyo_mkdev_acl, head)->perm);
++                      perm = data_race(container_of(ptr, struct tomoyo_mkdev_acl, head)->perm);
+                       break;
+               case TOMOYO_TYPE_INET_ACL:
+-                      data_race(perm = container_of(ptr, struct tomoyo_inet_acl, head)->perm);
++                      perm = data_race(container_of(ptr, struct tomoyo_inet_acl, head)->perm);
+                       break;
+               case TOMOYO_TYPE_UNIX_ACL:
+-                      data_race(perm = container_of(ptr, struct tomoyo_unix_acl, head)->perm);
++                      perm = data_race(container_of(ptr, struct tomoyo_unix_acl, head)->perm);
+                       break;
+               case TOMOYO_TYPE_MANUAL_TASK_ACL:
+                       perm = 0;
+@@ -1086,9 +1085,7 @@ bool tomoyo_domain_quota_is_ok(struct tomoyo_request_info *r)
+               default:
+                       perm = 1;
+               }
+-              for (i = 0; i < 16; i++)
+-                      if (perm & (1 << i))
+-                              count++;
++              count += hweight16(perm);
+       }
+       if (count < tomoyo_profile(domain->ns, domain->profile)->
+           pref[TOMOYO_PREF_MAX_LEARNING_ENTRY])
+-- 
+2.34.1
+