From: Greg Kroah-Hartman Date: Thu, 30 Apr 2020 13:10:37 +0000 (+0200) Subject: 4.9-stable patches X-Git-Tag: v5.4.37~47 X-Git-Url: http://git.ipfire.org/gitweb/index.cgi?a=commitdiff_plain;h=97fdc04a459c277b03bb18b8e838ae5416e9bb1f;p=thirdparty%2Fkernel%2Fstable-queue.git 4.9-stable patches added patches: nfsd-memory-corruption-in-nfsd4_lock.patch usb-gadget-udc-bdc-remove-unnecessary-null-checks-in-bdc_req_complete.patch --- diff --git a/queue-4.9/nfsd-memory-corruption-in-nfsd4_lock.patch b/queue-4.9/nfsd-memory-corruption-in-nfsd4_lock.patch new file mode 100644 index 00000000000..e9460cb6c37 --- /dev/null +++ b/queue-4.9/nfsd-memory-corruption-in-nfsd4_lock.patch @@ -0,0 +1,37 @@ +From e1e8399eee72e9d5246d4d1bcacd793debe34dd3 Mon Sep 17 00:00:00 2001 +From: Vasily Averin +Date: Fri, 27 Mar 2020 07:50:40 +0300 +Subject: nfsd: memory corruption in nfsd4_lock() + +From: Vasily Averin + +commit e1e8399eee72e9d5246d4d1bcacd793debe34dd3 upstream. + +New struct nfsd4_blocked_lock allocated in find_or_allocate_block() +does not initialized nbl_list and nbl_lru. +If conflock allocation fails rollback can call list_del_init() +access uninitialized fields and corrupt memory. + +v2: just initialize nbl_list and nbl_lru right after nbl allocation. + +Fixes: 76d348fadff5 ("nfsd: have nfsd4_lock use blocking locks for v4.1+ lock") +Signed-off-by: Vasily Averin +Reviewed-by: Jeff Layton +Signed-off-by: Chuck Lever +Signed-off-by: Greg Kroah-Hartman + +--- + fs/nfsd/nfs4state.c | 2 ++ + 1 file changed, 2 insertions(+) + +--- a/fs/nfsd/nfs4state.c ++++ b/fs/nfsd/nfs4state.c +@@ -246,6 +246,8 @@ find_or_allocate_block(struct nfs4_locko + if (!nbl) { + nbl= kmalloc(sizeof(*nbl), GFP_KERNEL); + if (nbl) { ++ INIT_LIST_HEAD(&nbl->nbl_list); ++ INIT_LIST_HEAD(&nbl->nbl_lru); + fh_copy_shallow(&nbl->nbl_fh, fh); + locks_init_lock(&nbl->nbl_lock); + nfsd4_init_cb(&nbl->nbl_cb, lo->lo_owner.so_client, diff --git a/queue-4.9/series b/queue-4.9/series index 2c144a5f8e6..cf40f61c462 100644 --- a/queue-4.9/series +++ b/queue-4.9/series @@ -59,3 +59,5 @@ usb-f_fs-clear-os-extended-descriptor-counts-to-zero-in-ffs_data_reset.patch remoteproc-fix-wrong-rvring-index-computation.patch fuse-fix-possibly-missed-wake-up-after-abort.patch mtd-cfi-fix-deadloop-in-cfi_cmdset_0002.c-do_write_buffer.patch +usb-gadget-udc-bdc-remove-unnecessary-null-checks-in-bdc_req_complete.patch +nfsd-memory-corruption-in-nfsd4_lock.patch diff --git a/queue-4.9/usb-gadget-udc-bdc-remove-unnecessary-null-checks-in-bdc_req_complete.patch b/queue-4.9/usb-gadget-udc-bdc-remove-unnecessary-null-checks-in-bdc_req_complete.patch new file mode 100644 index 00000000000..f678638967d --- /dev/null +++ b/queue-4.9/usb-gadget-udc-bdc-remove-unnecessary-null-checks-in-bdc_req_complete.patch @@ -0,0 +1,47 @@ +From 09b04abb70f096333bef6bc95fa600b662e7ee13 Mon Sep 17 00:00:00 2001 +From: Nathan Chancellor +Date: Sat, 28 Mar 2020 18:12:46 -0700 +Subject: usb: gadget: udc: bdc: Remove unnecessary NULL checks in bdc_req_complete + +From: Nathan Chancellor + +commit 09b04abb70f096333bef6bc95fa600b662e7ee13 upstream. + +When building with Clang + -Wtautological-pointer-compare: + +drivers/usb/gadget/udc/bdc/bdc_ep.c:543:28: warning: comparison of +address of 'req->queue' equal to a null pointer is always false +[-Wtautological-pointer-compare] + if (req == NULL || &req->queue == NULL || &req->usb_req == NULL) + ~~~~~^~~~~ ~~~~ +drivers/usb/gadget/udc/bdc/bdc_ep.c:543:51: warning: comparison of +address of 'req->usb_req' equal to a null pointer is always false +[-Wtautological-pointer-compare] + if (req == NULL || &req->queue == NULL || &req->usb_req == NULL) + ~~~~~^~~~~~~ ~~~~ +2 warnings generated. + +As it notes, these statements will always evaluate to false so remove +them. + +Fixes: efed421a94e6 ("usb: gadget: Add UDC driver for Broadcom USB3.0 device controller IP BDC") +Link: https://github.com/ClangBuiltLinux/linux/issues/749 +Signed-off-by: Nathan Chancellor +Signed-off-by: Felipe Balbi +Signed-off-by: Greg Kroah-Hartman + +--- + drivers/usb/gadget/udc/bdc/bdc_ep.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +--- a/drivers/usb/gadget/udc/bdc/bdc_ep.c ++++ b/drivers/usb/gadget/udc/bdc/bdc_ep.c +@@ -546,7 +546,7 @@ static void bdc_req_complete(struct bdc_ + { + struct bdc *bdc = ep->bdc; + +- if (req == NULL || &req->queue == NULL || &req->usb_req == NULL) ++ if (req == NULL) + return; + + dev_dbg(bdc->dev, "%s ep:%s status:%d\n", __func__, ep->name, status);