From: Greg Kroah-Hartman Date: Sat, 9 Oct 2021 13:42:11 +0000 (+0200) Subject: 4.14-stable patches X-Git-Tag: v5.14.12~44 X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=b099b61193a366acd1dcfca5bf8ac10bad7e6393;p=thirdparty%2Fkernel%2Fstable-queue.git 4.14-stable patches added patches: partially-revert-usb-kconfig-using-select-for-usb_common-dependency.patch usb-cdc-acm-fix-break-reporting.patch usb-cdc-acm-fix-racy-tty-buffer-accesses.patch --- diff --git a/queue-4.14/partially-revert-usb-kconfig-using-select-for-usb_common-dependency.patch b/queue-4.14/partially-revert-usb-kconfig-using-select-for-usb_common-dependency.patch new file mode 100644 index 00000000000..5c16152b544 --- /dev/null +++ b/queue-4.14/partially-revert-usb-kconfig-using-select-for-usb_common-dependency.patch @@ -0,0 +1,36 @@ +From 4d1aa9112c8e6995ef2c8a76972c9671332ccfea Mon Sep 17 00:00:00 2001 +From: Ben Hutchings +Date: Tue, 21 Sep 2021 16:34:42 +0200 +Subject: Partially revert "usb: Kconfig: using select for USB_COMMON dependency" + +From: Ben Hutchings + +commit 4d1aa9112c8e6995ef2c8a76972c9671332ccfea upstream. + +This reverts commit cb9c1cfc86926d0e86d19c8e34f6c23458cd3478 for +USB_LED_TRIG. This config symbol has bool type and enables extra code +in usb_common itself, not a separate driver. Enabling it should not +force usb_common to be built-in! + +Fixes: cb9c1cfc8692 ("usb: Kconfig: using select for USB_COMMON dependency") +Cc: stable +Signed-off-by: Ben Hutchings +Signed-off-by: Salvatore Bonaccorso +Link: https://lore.kernel.org/r/20210921143442.340087-1-carnil@debian.org +Signed-off-by: Greg Kroah-Hartman +--- + drivers/usb/Kconfig | 3 +-- + 1 file changed, 1 insertion(+), 2 deletions(-) + +--- a/drivers/usb/Kconfig ++++ b/drivers/usb/Kconfig +@@ -174,8 +174,7 @@ source "drivers/usb/typec/Kconfig" + + config USB_LED_TRIG + bool "USB LED Triggers" +- depends on LEDS_CLASS && LEDS_TRIGGERS +- select USB_COMMON ++ depends on LEDS_CLASS && USB_COMMON && LEDS_TRIGGERS + help + This option adds LED triggers for USB host and/or gadget activity. + diff --git a/queue-4.14/series b/queue-4.14/series index 1a426a5c648..e33b831595d 100644 --- a/queue-4.14/series +++ b/queue-4.14/series @@ -1 +1,3 @@ partially-revert-usb-kconfig-using-select-for-usb_common-dependency.patch +usb-cdc-acm-fix-racy-tty-buffer-accesses.patch +usb-cdc-acm-fix-break-reporting.patch diff --git a/queue-4.14/usb-cdc-acm-fix-break-reporting.patch b/queue-4.14/usb-cdc-acm-fix-break-reporting.patch new file mode 100644 index 00000000000..c250ece787f --- /dev/null +++ b/queue-4.14/usb-cdc-acm-fix-break-reporting.patch @@ -0,0 +1,36 @@ +From 58fc1daa4d2e9789b9ffc880907c961ea7c062cc Mon Sep 17 00:00:00 2001 +From: Johan Hovold +Date: Wed, 29 Sep 2021 11:09:37 +0200 +Subject: USB: cdc-acm: fix break reporting + +From: Johan Hovold + +commit 58fc1daa4d2e9789b9ffc880907c961ea7c062cc upstream. + +A recent change that started reporting break events forgot to push the +event to the line discipline, which meant that a detected break would +not be reported until further characters had been receive (the port +could even have been closed and reopened in between). + +Fixes: 08dff274edda ("cdc-acm: fix BREAK rx code path adding necessary calls") +Cc: stable@vger.kernel.org +Acked-by: Oliver Neukum +Signed-off-by: Johan Hovold +Link: https://lore.kernel.org/r/20210929090937.7410-3-johan@kernel.org +Signed-off-by: Greg Kroah-Hartman +--- + drivers/usb/class/cdc-acm.c | 3 +++ + 1 file changed, 3 insertions(+) + +--- a/drivers/usb/class/cdc-acm.c ++++ b/drivers/usb/class/cdc-acm.c +@@ -351,6 +351,9 @@ static void acm_process_notification(str + acm->iocount.overrun++; + spin_unlock(&acm->read_lock); + ++ if (newctrl & ACM_CTRL_BRK) ++ tty_flip_buffer_push(&acm->port); ++ + if (difference) + wake_up_all(&acm->wioctl); + diff --git a/queue-4.14/usb-cdc-acm-fix-racy-tty-buffer-accesses.patch b/queue-4.14/usb-cdc-acm-fix-racy-tty-buffer-accesses.patch new file mode 100644 index 00000000000..5d39f8062f6 --- /dev/null +++ b/queue-4.14/usb-cdc-acm-fix-racy-tty-buffer-accesses.patch @@ -0,0 +1,53 @@ +From 65a205e6113506e69a503b61d97efec43fc10fd7 Mon Sep 17 00:00:00 2001 +From: Johan Hovold +Date: Wed, 29 Sep 2021 11:09:36 +0200 +Subject: USB: cdc-acm: fix racy tty buffer accesses + +From: Johan Hovold + +commit 65a205e6113506e69a503b61d97efec43fc10fd7 upstream. + +A recent change that started reporting break events to the line +discipline caused the tty-buffer insertions to no longer be serialised +by inserting events also from the completion handler for the interrupt +endpoint. + +Completion calls for distinct endpoints are not guaranteed to be +serialised. For example, in case a host-controller driver uses +bottom-half completion, the interrupt and bulk-in completion handlers +can end up running in parallel on two CPUs (high-and low-prio tasklets, +respectively) thereby breaking the tty layer's single producer +assumption. + +Fix this by holding the read lock also when inserting characters from +the bulk endpoint. + +Fixes: 08dff274edda ("cdc-acm: fix BREAK rx code path adding necessary calls") +Cc: stable@vger.kernel.org +Acked-by: Oliver Neukum +Signed-off-by: Johan Hovold +Link: https://lore.kernel.org/r/20210929090937.7410-2-johan@kernel.org +Signed-off-by: Greg Kroah-Hartman +--- + drivers/usb/class/cdc-acm.c | 5 +++++ + 1 file changed, 5 insertions(+) + +--- a/drivers/usb/class/cdc-acm.c ++++ b/drivers/usb/class/cdc-acm.c +@@ -486,11 +486,16 @@ static int acm_submit_read_urbs(struct a + + static void acm_process_read_urb(struct acm *acm, struct urb *urb) + { ++ unsigned long flags; ++ + if (!urb->actual_length) + return; + ++ spin_lock_irqsave(&acm->read_lock, flags); + tty_insert_flip_string(&acm->port, urb->transfer_buffer, + urb->actual_length); ++ spin_unlock_irqrestore(&acm->read_lock, flags); ++ + tty_flip_buffer_push(&acm->port); + } +