]> git.ipfire.org Git - thirdparty/kernel/stable-queue.git/commitdiff
5.4-stable patches
authorGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Thu, 30 Apr 2020 07:13:17 +0000 (09:13 +0200)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Thu, 30 Apr 2020 07:13:17 +0000 (09:13 +0200)
added patches:
remoteproc-fix-wrong-rvring-index-computation.patch
ubifs-fix-ubifs_tnc_lookup-usage-in-do_kill_orphans.patch

queue-5.4/remoteproc-fix-wrong-rvring-index-computation.patch [new file with mode: 0644]
queue-5.4/series [new file with mode: 0644]
queue-5.4/ubifs-fix-ubifs_tnc_lookup-usage-in-do_kill_orphans.patch [new file with mode: 0644]

diff --git a/queue-5.4/remoteproc-fix-wrong-rvring-index-computation.patch b/queue-5.4/remoteproc-fix-wrong-rvring-index-computation.patch
new file mode 100644 (file)
index 0000000..35b781b
--- /dev/null
@@ -0,0 +1,35 @@
+From 00a0eec59ddbb1ce966b19097d8a8d2f777e726a Mon Sep 17 00:00:00 2001
+From: Clement Leger <cleger@kalray.eu>
+Date: Fri, 4 Oct 2019 09:37:36 +0200
+Subject: remoteproc: Fix wrong rvring index computation
+
+From: Clement Leger <cleger@kalray.eu>
+
+commit 00a0eec59ddbb1ce966b19097d8a8d2f777e726a upstream.
+
+Index of rvring is computed using pointer arithmetic. However, since
+rvring->rvdev->vring is the base of the vring array, computation
+of rvring idx should be reversed. It previously lead to writing at negative
+indices in the resource table.
+
+Signed-off-by: Clement Leger <cleger@kalray.eu>
+Link: https://lore.kernel.org/r/20191004073736.8327-1-cleger@kalray.eu
+Signed-off-by: Bjorn Andersson <bjorn.andersson@linaro.org>
+Cc: Doug Anderson <dianders@chromium.org>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+
+---
+ drivers/remoteproc/remoteproc_core.c |    2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+--- a/drivers/remoteproc/remoteproc_core.c
++++ b/drivers/remoteproc/remoteproc_core.c
+@@ -400,7 +400,7 @@ rproc_parse_vring(struct rproc_vdev *rvd
+ void rproc_free_vring(struct rproc_vring *rvring)
+ {
+       struct rproc *rproc = rvring->rvdev->rproc;
+-      int idx = rvring->rvdev->vring - rvring;
++      int idx = rvring - rvring->rvdev->vring;
+       struct fw_rsc_vdev *rsc;
+       idr_remove(&rproc->notifyids, rvring->notifyid);
diff --git a/queue-5.4/series b/queue-5.4/series
new file mode 100644 (file)
index 0000000..967b47d
--- /dev/null
@@ -0,0 +1,2 @@
+remoteproc-fix-wrong-rvring-index-computation.patch
+ubifs-fix-ubifs_tnc_lookup-usage-in-do_kill_orphans.patch
diff --git a/queue-5.4/ubifs-fix-ubifs_tnc_lookup-usage-in-do_kill_orphans.patch b/queue-5.4/ubifs-fix-ubifs_tnc_lookup-usage-in-do_kill_orphans.patch
new file mode 100644 (file)
index 0000000..bdfad01
--- /dev/null
@@ -0,0 +1,47 @@
+From 4ab25ac8b2b5514151d5f91cf9514df08dd26938 Mon Sep 17 00:00:00 2001
+From: Richard Weinberger <richard@nod.at>
+Date: Sun, 19 Jan 2020 22:52:33 +0100
+Subject: ubifs: Fix ubifs_tnc_lookup() usage in do_kill_orphans()
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+From: Richard Weinberger <richard@nod.at>
+
+commit 4ab25ac8b2b5514151d5f91cf9514df08dd26938 upstream.
+
+Orphans are allowed to point to deleted inodes.
+So -ENOENT is not a fatal error.
+
+Reported-by: Кочетков Максим <fido_max@inbox.ru>
+Reported-and-tested-by: "Christian Berger" <Christian.Berger@de.bosch.com>
+Tested-by: Karl Olsen <karl@micro-technic.com>
+Tested-by: Jef Driesen <jef.driesen@niko.eu>
+Fixes: ee1438ce5dc4 ("ubifs: Check link count of inodes when killing orphans.")
+Signed-off-by: Richard Weinberger <richard@nod.at>
+Cc: Christian Eggers <ceggers@arri.de>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+
+---
+ fs/ubifs/orphan.c |    4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+--- a/fs/ubifs/orphan.c
++++ b/fs/ubifs/orphan.c
+@@ -688,14 +688,14 @@ static int do_kill_orphans(struct ubifs_
+                       ino_key_init(c, &key1, inum);
+                       err = ubifs_tnc_lookup(c, &key1, ino);
+-                      if (err)
++                      if (err && err != -ENOENT)
+                               goto out_free;
+                       /*
+                        * Check whether an inode can really get deleted.
+                        * linkat() with O_TMPFILE allows rebirth of an inode.
+                        */
+-                      if (ino->nlink == 0) {
++                      if (err == 0 && ino->nlink == 0) {
+                               dbg_rcvry("deleting orphaned inode %lu",
+                                         (unsigned long)inum);