From: Greg Kroah-Hartman Date: Thu, 30 Apr 2020 09:47:17 +0000 (+0200) Subject: 4.9-stable patches X-Git-Tag: v5.4.37~52 X-Git-Url: http://git.ipfire.org/gitweb/index.cgi?a=commitdiff_plain;h=9471bb2575c5de5fe9b786f56d81859c7bd9be28;p=thirdparty%2Fkernel%2Fstable-queue.git 4.9-stable patches added patches: fuse-fix-possibly-missed-wake-up-after-abort.patch mtd-cfi-fix-deadloop-in-cfi_cmdset_0002.c-do_write_buffer.patch --- diff --git a/queue-4.9/fuse-fix-possibly-missed-wake-up-after-abort.patch b/queue-4.9/fuse-fix-possibly-missed-wake-up-after-abort.patch new file mode 100644 index 00000000000..84f05b3ebc2 --- /dev/null +++ b/queue-4.9/fuse-fix-possibly-missed-wake-up-after-abort.patch @@ -0,0 +1,61 @@ +From 2d84a2d19b6150c6dbac1e6ebad9c82e4c123772 Mon Sep 17 00:00:00 2001 +From: Miklos Szeredi +Date: Fri, 9 Nov 2018 15:52:16 +0100 +Subject: fuse: fix possibly missed wake-up after abort + +From: Miklos Szeredi + +commit 2d84a2d19b6150c6dbac1e6ebad9c82e4c123772 upstream. + +In current fuse_drop_waiting() implementation it's possible that +fuse_wait_aborted() will not be woken up in the unlikely case that +fuse_abort_conn() + fuse_wait_aborted() runs in between checking +fc->connected and calling atomic_dec(&fc->num_waiting). + +Do the atomic_dec_and_test() unconditionally, which also provides the +necessary barrier against reordering with the fc->connected check. + +The explicit smp_mb() in fuse_wait_aborted() is not actually needed, since +the spin_unlock() in fuse_abort_conn() provides the necessary RELEASE +barrier after resetting fc->connected. However, this is not a performance +sensitive path, and adding the explicit barrier makes it easier to +document. + +Signed-off-by: Miklos Szeredi +Fixes: b8f95e5d13f5 ("fuse: umount should wait for all requests") +Cc: #v4.19 +Cc: Guenter Roeck +Signed-off-by: Greg Kroah-Hartman + +--- + fs/fuse/dev.c | 12 +++++++++--- + 1 file changed, 9 insertions(+), 3 deletions(-) + +--- a/fs/fuse/dev.c ++++ b/fs/fuse/dev.c +@@ -132,9 +132,13 @@ static bool fuse_block_alloc(struct fuse + + static void fuse_drop_waiting(struct fuse_conn *fc) + { +- if (fc->connected) { +- atomic_dec(&fc->num_waiting); +- } else if (atomic_dec_and_test(&fc->num_waiting)) { ++ /* ++ * lockess check of fc->connected is okay, because atomic_dec_and_test() ++ * provides a memory barrier mached with the one in fuse_wait_aborted() ++ * to ensure no wake-up is missed. ++ */ ++ if (atomic_dec_and_test(&fc->num_waiting) && ++ !READ_ONCE(fc->connected)) { + /* wake up aborters */ + wake_up_all(&fc->blocked_waitq); + } +@@ -2164,6 +2168,8 @@ EXPORT_SYMBOL_GPL(fuse_abort_conn); + + void fuse_wait_aborted(struct fuse_conn *fc) + { ++ /* matches implicit memory barrier in fuse_drop_waiting() */ ++ smp_mb(); + wait_event(fc->blocked_waitq, atomic_read(&fc->num_waiting) == 0); + } + diff --git a/queue-4.9/mtd-cfi-fix-deadloop-in-cfi_cmdset_0002.c-do_write_buffer.patch b/queue-4.9/mtd-cfi-fix-deadloop-in-cfi_cmdset_0002.c-do_write_buffer.patch new file mode 100644 index 00000000000..f3c3b549019 --- /dev/null +++ b/queue-4.9/mtd-cfi-fix-deadloop-in-cfi_cmdset_0002.c-do_write_buffer.patch @@ -0,0 +1,42 @@ +From d9b8a67b3b95a5c5aae6422b8113adc1c2485f2b Mon Sep 17 00:00:00 2001 +From: Liu Jian +Date: Sun, 3 Mar 2019 15:04:18 +0800 +Subject: mtd: cfi: fix deadloop in cfi_cmdset_0002.c do_write_buffer + +From: Liu Jian + +commit d9b8a67b3b95a5c5aae6422b8113adc1c2485f2b upstream. + +In function do_write_buffer(), in the for loop, there is a case +chip_ready() returns 1 while chip_good() returns 0, so it never +break the loop. +To fix this, chip_good() is enough and it should timeout if it stay +bad for a while. + +Fixes: dfeae1073583("mtd: cfi_cmdset_0002: Change write buffer to check correct value") +Signed-off-by: Yi Huaijie +Signed-off-by: Liu Jian +Reviewed-by: Tokunori Ikegami +Signed-off-by: Richard Weinberger +Cc: Guenter Roeck +Signed-off-by: Greg Kroah-Hartman + +--- + drivers/mtd/chips/cfi_cmdset_0002.c | 6 +++++- + 1 file changed, 5 insertions(+), 1 deletion(-) + +--- a/drivers/mtd/chips/cfi_cmdset_0002.c ++++ b/drivers/mtd/chips/cfi_cmdset_0002.c +@@ -1879,7 +1879,11 @@ static int __xipram do_write_buffer(stru + continue; + } + +- if (time_after(jiffies, timeo) && !chip_ready(map, adr)) ++ /* ++ * We check "time_after" and "!chip_good" before checking "chip_good" to avoid ++ * the failure due to scheduling. ++ */ ++ if (time_after(jiffies, timeo) && !chip_good(map, adr, datum)) + break; + + if (chip_good(map, adr, datum)) { diff --git a/queue-4.9/series b/queue-4.9/series index 209e420b14c..2c144a5f8e6 100644 --- a/queue-4.9/series +++ b/queue-4.9/series @@ -57,3 +57,5 @@ uas-no-use-logging-any-details-in-case-of-enodev.patch uas-fix-deadlock-in-error-handling-and-pm-flushing-work.patch usb-f_fs-clear-os-extended-descriptor-counts-to-zero-in-ffs_data_reset.patch remoteproc-fix-wrong-rvring-index-computation.patch +fuse-fix-possibly-missed-wake-up-after-abort.patch +mtd-cfi-fix-deadloop-in-cfi_cmdset_0002.c-do_write_buffer.patch