mailweb.openeuler.org
Manage this list

Keyboard Shortcuts

Thread View

  • j: Next unread message
  • k: Previous unread message
  • j a: Jump to all threads
  • j l: Jump to MailingList overview

Kernel

Threads by month
  • ----- 2026 -----
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2025 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2024 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2023 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2022 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2021 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2020 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2019 -----
  • December
kernel@openeuler.org

  • 8 participants
  • 25076 discussions
[PATCH OLK-5.10] mmc: via-sdmmc: stop card-detect handling on probe failure
by Gu Bowen 08 Oct '26

08 Oct '26
From: Fan Wu <fanwu01(a)zju.edu.cn> stable inclusion from stable-v5.10.270 commit 5bb5327b92aae17e91c7228953c350a6ee3c94e8 category: bugfix bugzilla: https://atomgit.com/src-openeuler/kernel/issues/18835 CVE: CVE-2026-89440 Reference: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id… -------------------------------- commit 088eaa92fcebaa6b957ccf9635afdf39643a577d upstream. request_irq() registers the SD card-detect interrupt and the probe enables it before mmc_add_host() runs. If mmc_add_host() fails, the error path only unmaps the registers and returns: the interrupt stays registered, so the handler keeps running against the host once it is freed. via_sdc_isr() dereferences sdhost and its MMIO base and schedules carddet_work, which via_sdc_card_detect() also runs against freed memory through its container_of() dereference. Add a probe-error path that disables and frees the interrupt and cancels carddet_work before unmapping. carddet_work can re-enable the device interrupt via via_reset_pcictrl(), which restores PCIINTCTRL, so mask it again after cancelling the work. This issue was found by an in-house static analysis tool and confirmed by manual code review. Fixes: e4e46fb61e3b ("mmc: via-sdmmc: fix return value check of mmc_add_host()") Cc: stable(a)vger.kernel.org Assisted-by: Codex:gpt-5.6 Signed-off-by: Fan Wu <fanwu01(a)zju.edu.cn> Signed-off-by: Ulf Hansson <ulfh(a)kernel.org> Signed-off-by: Greg Kroah-Hartman <gregkh(a)linuxfoundation.org> Signed-off-by: Gu Bowen <gubowen5(a)huawei.com> --- drivers/mmc/host/via-sdmmc.c | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/drivers/mmc/host/via-sdmmc.c b/drivers/mmc/host/via-sdmmc.c index f6b525fb5c0e..6ec1e94c9f14 100644 --- a/drivers/mmc/host/via-sdmmc.c +++ b/drivers/mmc/host/via-sdmmc.c @@ -1156,10 +1156,16 @@ static int via_sd_probe(struct pci_dev *pcidev, ret = mmc_add_host(mmc); if (ret) - goto unmap; + goto free_irq; return 0; +free_irq: + writeb(0x0, sdhost->pcictrl_mmiobase + VIA_CRDR_PCIINTCTRL); + free_irq(pcidev->irq, sdhost); + cancel_work_sync(&sdhost->carddet_work); + /* carddet_work may re-enable the interrupt via via_reset_pcictrl(). */ + writeb(0x0, sdhost->pcictrl_mmiobase + VIA_CRDR_PCIINTCTRL); unmap: iounmap(sdhost->mmiobase); free_mmc_host: -- 2.43.0
2 1
0 0
[PATCH OLK-5.10] openvswitch: only skb_tx_error() a packet we are about to drop
by Gu Bowen 08 Oct '26

08 Oct '26
From: Norbert Szetei <norbert(a)doyensec.com> stable inclusion from stable-v5.10.270 commit 5de5d554141a15b3f1f5c978fd9f7f4fd6d0600a category: bugfix bugzilla: https://atomgit.com/src-openeuler/kernel/issues/18851 CVE: CVE-2026-89487 Reference: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id… -------------------------------- commit 0dbc2398fca3bb33eda963849f865ddb1b3aa05e upstream. queue_userspace_packet() borrows the packet skb -- it only copies it into a private netlink message (user_skb) and does not own it; on return do_execute_actions() keeps forwarding it through the flow's remaining actions. Its error path nevertheless calls skb_tx_error(skb), which via skb_zcopy_clear() does skb_shinfo(skb)->flags &= ~SKBFL_ALL_ZEROCOPY, stripping SKBFL_SHARED_FRAG from that live skb (skb_tx_error()'s kerneldoc says "skb must be freed afterwards"). For a MSG_ZEROCOPY skb carrying page-cache frags, SKBFL_SHARED_FRAG is what makes esp_input() skb_cow_data() before in-place AEAD; once it is stripped a later local ESP-in-UDP delivery decrypts in place over pages the sender does not own -- an unprivileged page-cache write (the "Fragnesia" primitive). do_execute_actions() ignores output_userspace()'s return value, so any action after a failed USERSPACE upcall inherits the stripped skb. Move the skb_tx_error() to the flow-miss drop path - the "default" branch of ovs_dp_process_packet()'s switch(error), before kfree_skb(). The call has been here since commit 36d5fe6a0007 ("core, nfqueue, openvswitch: Orphan frags in skb_zerocopy and handle errors") but was harmless until esp_input() began relying on SKBFL_SHARED_FRAG to gate in-place decrypt; only then did stripping it on a still-forwarded skb become a page-cache write primitive. Fixes: 36d5fe6a0007 ("core, nfqueue, openvswitch: Orphan frags in skb_zerocopy and handle errors") Fixes: f4c50a4034e6 ("xfrm: esp: avoid in-place decrypt on shared skb frags") Cc: stable(a)vger.kernel.org Assisted-by: Claude:claude-opus-5 Signed-off-by: Norbert Szetei <norbert(a)doyensec.com> Reviewed-by: Ilya Maximets <i.maximets(a)ovn.org> Tested-by: Jongmin Jang <payload.jang(a)gmail.com> Link: https://patch.msgid.link/55A52703-7548-4A55-A9CE-2A37145BDCAD@doyensec.com Signed-off-by: Paolo Abeni <pabeni(a)redhat.com> Signed-off-by: Greg Kroah-Hartman <gregkh(a)linuxfoundation.org> Signed-off-by: Gu Bowen <gubowen5(a)huawei.com> --- net/openvswitch/datapath.c | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/net/openvswitch/datapath.c b/net/openvswitch/datapath.c index b6d5dddaf35d..ec1e4af1dec0 100644 --- a/net/openvswitch/datapath.c +++ b/net/openvswitch/datapath.c @@ -249,6 +249,7 @@ void ovs_dp_process_packet(struct sk_buff *skb, struct sw_flow_key *key) consume_skb(skb); break; default: + skb_tx_error(skb); kfree_skb(skb); break; } @@ -544,8 +545,6 @@ static int queue_userspace_packet(struct datapath *dp, struct sk_buff *skb, err = genlmsg_unicast(ovs_dp_get_net(dp), user_skb, upcall_info->portid); user_skb = NULL; out: - if (err) - skb_tx_error(skb); consume_skb(user_skb); consume_skb(nskb); -- 2.43.0
2 1
0 0
[PATCH OLK-6.6] mm: memcg: stop reclaim when a limit update is superseded
by Yi Yang 08 Oct '26

08 Oct '26
From: Guopeng Zhang <zhangguopeng(a)kylinos.cn> stable inclusion from stable-v6.6.157 commit 8bf21ad3657305e28deafd9ef16a121407496bc3 category: bugfix bugzilla: https://atomgit.com/src-openeuler/kernel/issues/18797 CVE: CVE-2026-89752 Reference: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id… -------------------------------- commit 9477820c63cbf4d97114238f3d1ff10dfd6bee3f upstream. kernfs serializes file operations only per open file, so separate open files can update the same memory.high or memory.max file concurrently. Both handlers store the new limit before synchronous reclaim, but continue to use the writer's local target in the reclaim loop. If another writer raises or removes the limit, the first writer can continue reclaiming toward a stale target. For memory.max, this can leave the writer looping indefinitely once reclaim retries are exhausted. The OOM path sees sufficient margin under the current limit and returns true without killing, while the writer still compares usage against its stale target and records another OOM event. Check the current limit at the start of each reclaim iteration and stop if it no longer matches the writer's target. Reproducer: Populate a cgroup with anonymous memory and disable swapping. Lower memory.max from one open file, then restore it to "max" through another open file after the new limit becomes visible. Without the patch, the first writer remains blocked and repeatedly increments the OOM event counter. With the patch, it returns normally. This was not motivated by a reported production workload. We found it through automated randomized testing for our cgroup observability work and reduced it to the reproducer above. Link: https://lore.kernel.org/20260724021805.1234583-1-guopeng.zhang@linux.dev Fixes: 8c8c383c04f6 ("mm: memcontrol: try harder to set a new memory.high") Fixes: b6e6edcfa405 ("mm: memcontrol: reclaim and OOM kill when shrinking memory.max below usage") Signed-off-by: Guopeng Zhang <zhangguopeng(a)kylinos.cn> Acked-by: Tao Cui <cuitao(a)kylinos.cn> Acked-by: Johannes Weiner <hannes(a)cmpxchg.org> Cc: Michal Hocko <mhocko(a)kernel.org> Cc: Muchun Song <muchun.song(a)linux.dev> Cc: Roman Gushchin <roman.gushchin(a)linux.dev> Cc: Shakeel Butt <shakeel.butt(a)linux.dev> Cc: <stable(a)vger.kernel.org> Signed-off-by: Andrew Morton <akpm(a)linux-foundation.org> Signed-off-by: Greg Kroah-Hartman <gregkh(a)linuxfoundation.org> Signed-off-by: Yi Yang <yiyang13(a)huawei.com> --- mm/memcontrol.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/mm/memcontrol.c b/mm/memcontrol.c index 148e7f499bea..4ed54affdfa9 100644 --- a/mm/memcontrol.c +++ b/mm/memcontrol.c @@ -7985,6 +7985,9 @@ static ssize_t memory_high_write(struct kernfs_open_file *of, unsigned long nr_pages = page_counter_read(&memcg->memory); unsigned long reclaimed; + if (high != READ_ONCE(memcg->memory.high)) + break; + if (nr_pages <= high) break; @@ -8033,6 +8036,9 @@ static ssize_t memory_max_write(struct kernfs_open_file *of, for (;;) { unsigned long nr_pages = page_counter_read(&memcg->memory); + if (max != READ_ONCE(memcg->memory.max)) + break; + if (nr_pages <= max) break; -- 2.25.1
2 1
0 0
[PATCH openEuler-1.0-LTS 0/2] fix CVE-2026-89786 CVE-2026-89778
by Lin Yujun 08 Oct '26

08 Oct '26
Xiang Mei (2): ext4: fix out-of-bounds read in ext4_read_inline_dir() isofs: fix out-of-bounds page array access on empty zisofs block fs/ext4/inline.c | 11 ++++++++++- fs/isofs/compress.c | 6 ++++-- 2 files changed, 14 insertions(+), 3 deletions(-) -- 2.34.1
2 3
0 0
[PATCH OLK-6.6] drm/amd/display: avoid divide-by-zero in __is_lut_linear()
by Zhang Yuwei 08 Oct '26

08 Oct '26
From: Harry Wentland <harry.wentland(a)amd.com> stable inclusion from stable-6.6.157 commit 4d5ee095a58461b2446d7a6eb0c14c2fe3eaab44 category: bugfix bugzilla: https://atomgit.com/src-openeuler/kernel/issues/19551 CVE: CVE-2026-89821 Reference: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id… ------------------------------ commit 4f40873f8a4107df2b9c8e68c947c4fd0cd519d2 upstream. __is_lut_linear() computes the expected value of each entry with expected = i * MAX_DRM_LUT_VALUE / (size - 1); If it is ever called with a single-entry LUT, size - 1 is zero and the kernel takes a divide error (#DE). A LUT with fewer than two entries cannot describe a linear mapping anyway, so return false early instead of dividing by zero. Fixes: 086247a4b2fb ("drm/amd/display: Use 4096 lut entries") Cc: stable(a)vger.kernel.org Signed-off-by: Harry Wentland <harry.wentland(a)amd.com> Reviewed-by: Melissa Wen <mwen(a)igalia.com> Tested-by: Daniel Wheeler <daniel.wheeler(a)amd.com> Signed-off-by: Alex Deucher <alexander.deucher(a)amd.com> Signed-off-by: Greg Kroah-Hartman <gregkh(a)linuxfoundation.org> Signed-off-by: Hulk Robot <hulkrobot(a)huawei.com> --- drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_color.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_color.c b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_color.c index a4cb23d059bd..191a3c5cded5 100644 --- a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_color.c +++ b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_color.c @@ -118,6 +118,12 @@ static bool __is_lut_linear(const struct drm_color_lut *lut, uint32_t size) uint32_t expected; int delta; + /* A LUT with fewer than two entries can't be interpolated and would + * divide by zero below (size - 1); it can't be treated as linear. + */ + if (size < 2) + return false; + for (i = 0; i < size; i++) { /* All color values should equal */ if ((lut[i].red != lut[i].green) || (lut[i].green != lut[i].blue)) -- 2.22.0
2 1
0 0
[PATCH OLK-5.10] drm: fix race between partial drm_dev_register() failure and ioctl
by Zhang Yuwei 08 Oct '26

08 Oct '26
From: Danilo Krummrich <dakr(a)kernel.org> stable inclusion from stable-v5.10.270 commit 26d9162213952927cd59c0d94b7e0e992b347bec category: bugfix bugzilla: https://atomgit.com/src-openeuler/kernel/issues/19060 CVE: CVE-2026-89823 Reference: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id… -------------------------------- commit eb197f7d60f00d0f5b1b3505dfc86a7e36045a3e upstream. If drm_dev_register() fails after registering a minor (e.g. render minor registered, primary minor fails), userspace could have opened the first minor and entered a drm_dev_enter() critical section. Since the unplugged flag was never set, the ioctl proceeds while the error path tears down device resources. Fix this by introducing drm_dev_synchronize_unplug(), which sets the unplugged flag and waits for the SRCU barrier, ensuring all in-flight drm_dev_enter() critical sections complete before cleanup proceeds; call it on the error path of drm_dev_register(). Fixes: bee330f3d672 ("drm: Use srcu to protect drm_device.unplugged") Cc: stable(a)vger.kernel.org Reported-by: sashiko-bot(a)kernel.org Closes: https://lore.kernel.org/all/20260620190648.2E9F61F000E9@smtp.kernel.org/ Reviewed-by: Alexandre Courbot <acourbot(a)nvidia.com> Reviewed-by: Lyude Paul <lyude(a)redhat.com> Tested-by: Deborah Brouwer <deborah.brouwer(a)collabora.com> Link: https://patch.msgid.link/20260628145406.2107056-17-dakr@kernel.org Signed-off-by: Danilo Krummrich <dakr(a)kernel.org> Signed-off-by: Greg Kroah-Hartman <gregkh(a)linuxfoundation.org> Signed-off-by: Hulk Robot <hulkrobot(a)huawei.com> --- drivers/gpu/drm/drm_drv.c | 34 +++++++++++++++++++++++++--------- 1 file changed, 25 insertions(+), 9 deletions(-) diff --git a/drivers/gpu/drm/drm_drv.c b/drivers/gpu/drm/drm_drv.c index 10831d8d7148..63a0fa8054b1 100644 --- a/drivers/gpu/drm/drm_drv.c +++ b/drivers/gpu/drm/drm_drv.c @@ -447,6 +447,22 @@ void drm_dev_exit(int idx) } EXPORT_SYMBOL(drm_dev_exit); +/* + * Mark the device as unplugged and wait for any in-flight drm_dev_enter() + * critical sections to complete. + */ +static void drm_dev_synchronize_unplug(struct drm_device *dev) +{ + /* + * After synchronizing any critical read section is guaranteed to see + * the new value of ->unplugged, and any critical section which might + * still have seen the old value of ->unplugged is guaranteed to have + * finished. + */ + dev->unplugged = true; + synchronize_srcu(&drm_unplug_srcu); +} + /** * drm_dev_unplug - unplug a DRM device * @dev: DRM device @@ -459,15 +475,7 @@ EXPORT_SYMBOL(drm_dev_exit); */ void drm_dev_unplug(struct drm_device *dev) { - /* - * After synchronizing any critical read section is guaranteed to see - * the new value of ->unplugged, and any critical section which might - * still have seen the old value of ->unplugged is guaranteed to have - * finished. - */ - dev->unplugged = true; - synchronize_srcu(&drm_unplug_srcu); - + drm_dev_synchronize_unplug(dev); drm_dev_unregister(dev); } EXPORT_SYMBOL(drm_dev_unplug); @@ -885,6 +893,7 @@ int drm_dev_register(struct drm_device *dev, unsigned long flags) goto err_minors; dev->registered = true; + dev->unplugged = false; if (dev->driver->load) { ret = dev->driver->load(dev, flags); @@ -912,6 +921,13 @@ int drm_dev_register(struct drm_device *dev, unsigned long flags) if (dev->driver->unload) dev->driver->unload(dev); err_minors: + /* + * If a minor was registered before the failure, userspace could have + * opened it and entered a drm_dev_enter() critical section. Ensure all + * such sections complete before we clean up. + */ + drm_dev_synchronize_unplug(dev); + remove_compat_control_link(dev); drm_minor_unregister(dev, DRM_MINOR_PRIMARY); drm_minor_unregister(dev, DRM_MINOR_RENDER); -- 2.22.0
2 1
0 0
[PATCH OLK-6.6] tracing: Fix hist trigger timestamps for buffered events
by Tengda Wu 08 Oct '26

08 Oct '26
hulk inclusion category: bugfix bugzilla: https://atomgit.com/openeuler/kernel/issues/10071 ---------------------------------------- Syzkaller triggered a WARN_ON_ONCE(!nest) warning: WARNING: kernel/trace/ring_buffer.c:821 at ring_buffer_event_time_stamp Call trace: ring_buffer_event_time_stamp hist_field_timestamp hist_fn_call event_hist_trigger event_triggers_call __event_trigger_test_discard trace_event_buffer_commit do_trace_event_raw_event_sched_switch trace_event_raw_event_sched_switch The warning is probabilistically reproducible and is related to syzkaller executing the following commands: echo 'prev_pid == 999999' > events/sched/sched_switch/filter echo 'hist:keys=common_timestamp' > events/sched/sched_switch/trigger The specific triggering process is as follows: CPU 0 CPU 1 (context switching) (echo 'hist:keys=common_timestamp' > \ events/sched/sched_switch/trigger) do_trace_event_raw_event_##call trace_event_buffer_lock_reserve if (!tr->no_filter_buffering_ref && trace_file->flags & EVENT_FILE_FL_FILTERED) return entry; // return directly event_hist_trigger_parse hist_register_trigger tracing_set_filter_buffering(file->tr, true); tr->no_filter_buffering_ref++; __trace_buffer_lock_reserve rb_start_commit local_inc(&cpu_buffer->committing); // skipped and not executed trace_event_buffer_commit __event_trigger_test_discard event_triggers_call event_hist_trigger hist_fn_call hist_field_timestamp ring_buffer_event_time_stamp nest = local_read(&cpu_buffer->committing); WARN_ON_ONCE(!nest) // trigger warning The root cause is that when an event file has a filter attached and the hist trigger has not yet been attached, trace_event_buffer_lock_reserve() writes the event into the per-CPU trace_buffered_event temp buffer instead of reserving it in the ring buffer, so cpu_buffer->committing is not incremented. When the event is later processed at commit time by a hist trigger, hist_field_timestamp() -> ring_buffer_event_time_stamp() sees a zero committing count, triggering WARN_ON_ONCE(!nest). tracing_event_time_stamp() was added by commit d8279bfc5e959 ("tracing: Add tracing_event_time_stamp() API") for exactly this case: if the event is the per-CPU trace_buffered_event, it returns the current ring buffer timestamp. But it never gained a caller. Use it in hist_field_timestamp(), so that a hist trigger that races onto a buffered event records the current time, which is only marginally later than when the event was recorded, instead of warning and recording a bogus timestamp. Fixes: b94bc80df648 ("tracing: Use a no_filter_buffering_ref to stop using the filter buffer") Signed-off-by: Tengda Wu <wutengda2(a)huawei.com> --- kernel/trace/trace_events_hist.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/kernel/trace/trace_events_hist.c b/kernel/trace/trace_events_hist.c index d5602a4c6eb5..856d75942581 100644 --- a/kernel/trace/trace_events_hist.c +++ b/kernel/trace/trace_events_hist.c @@ -874,7 +874,7 @@ static u64 hist_field_timestamp(struct hist_field *hist_field, struct hist_trigger_data *hist_data = hist_field->hist_data; struct trace_array *tr = hist_data->event_file->tr; - u64 ts = ring_buffer_event_time_stamp(buffer, rbe); + u64 ts = tracing_event_time_stamp(buffer, rbe); if (hist_data->attrs->ts_in_usecs && trace_clock_in_ns(tr)) ts = ns2usecs(ts); -- 2.34.1
2 1
0 0
[PATCH OLK-6.6] nfsd: fix redeclaration of 'clp' in nfs4_laundromat()
by Tengda Wu 08 Oct '26

08 Oct '26
hulk inclusion category: bugfix bugzilla: https://atomgit.com/openeuler/kernel/issues/10070 -------------------------------- Commit db4cef375f33 ("NFSD: Prevent client use-after-free during delegation revoke") introduced a second declaration of 'clp' in nfs4_laundromat(), causing a compilation error: fs/nfsd/nfs4state.c: In function ‘nfs4_laundromat’: fs/nfsd/nfs4state.c:6325:29: error: redeclaration of ‘clp’ with no linkage 6325 | struct nfs4_client *clp; | ^~~ fs/nfsd/nfs4state.c:6314:29: note: previous declaration of ‘clp’ with type ‘struct nfs4_client *’ 6314 | struct nfs4_client *clp; | ^~~ Remove the redundant declaration. Fixes: db4cef375f33 ("NFSD: Prevent client use-after-free during delegation revoke") Signed-off-by: Tengda Wu <wutengda2(a)huawei.com> --- fs/nfsd/nfs4state.c | 1 - 1 file changed, 1 deletion(-) diff --git a/fs/nfsd/nfs4state.c b/fs/nfsd/nfs4state.c index 775beac19656..770f9a8a18ce 100644 --- a/fs/nfsd/nfs4state.c +++ b/fs/nfsd/nfs4state.c @@ -6311,7 +6311,6 @@ nfs4_process_client_reaplist(struct list_head *reaplist) static time64_t nfs4_laundromat(struct nfsd_net *nn) { - struct nfs4_client *clp; struct nfs4_openowner *oo; struct nfs4_delegation *dp; struct nfs4_ol_stateid *stp; -- 2.34.1
2 1
0 0
[PATCH openEuler-1.0-LTS] [Backport] iommu/vt-d: Force requesting ACS when tboot is enabled
by Jiacheng Yu 08 Oct '26

08 Oct '26
From: Kevin Tian <kevin.tian(a)intel.com> mainline inclusion from mainline-v7.3-rc1 commit 607432b2618b61df81134be0ef2562b8300c1216 category: bugfix bugzilla: https://atomgit.com/src-openeuler/kernel/issues/18838 CVE: CVE-2026-89448 Reference: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?… -------------------------------- Currently the conditions of requesting ACS in detect_intel_iommu() don't include tboot, leading to a possible misconfiguration with ACS disabled (e.g. due to user opts) while iommu is later forced on by tboot_force_iommu(). Fix it by checking tboot in detect_intel_iommu(). Fixes: 5d990b627537 ("PCI: add pci_request_acs") Cc: stable(a)vger.kernel.org Signed-off-by: Kevin Tian <kevin.tian(a)intel.com> Signed-off-by: Lu Baolu <baolu.lu(a)linux.intel.com> Signed-off-by: Joerg Roedel <joerg.roedel(a)amd.com> Conflicts: drivers/iommu/intel/dmar.c drivers/iommu/dmar.c drivers/iommu/intel/iommu.c drivers/iommu/intel/iommu.h include/linux/dma_remapping.h [1. The upstream patch lives under drivers/iommu/intel/; this tree keeps the Intel IOMMU code at drivers/iommu/dmar.c and drivers/iommu/intel-iommu.c. 2. This tree has no dmar_platform_optin() in the detect_intel_iommu() condition, so dmar_required() keeps only the !dmar_disabled check to preserve the original behavior. 3. intel_iommu_tboot_noforce is already non-static in intel-iommu.c, so the drivers/iommu/intel/iommu.c change is dropped. 4. The extern int intel_iommu_tboot_noforce and the intel_iommu_tboot_noforce (0) fallback live in include/linux/dma_remapping.h instead of the upstream Intel IOMMU header.] Signed-off-by: Jiacheng Yu <yujiacheng3(a)huawei.com> --- drivers/iommu/dmar.c | 14 +++++++++++++- include/linux/dma_remapping.h | 1 + 2 files changed, 14 insertions(+), 1 deletion(-) diff --git a/drivers/iommu/dmar.c b/drivers/iommu/dmar.c index 6d608f71867c..27fdd4f220db 100644 --- a/drivers/iommu/dmar.c +++ b/drivers/iommu/dmar.c @@ -898,6 +898,18 @@ dmar_validate_one_drhd(struct acpi_dmar_header *entry, void *arg) return 0; } +static bool dmar_required(void) +{ + /* tboot supersedes any user/platform opt */ + if (!intel_iommu_tboot_noforce && tboot_enabled()) + return true; + + if (!no_iommu && !dmar_disabled) + return true; + + return false; +} + int __init detect_intel_iommu(void) { int ret; @@ -911,7 +923,7 @@ int __init detect_intel_iommu(void) if (!ret) ret = dmar_walk_dmar_table((struct acpi_table_dmar *)dmar_tbl, &validate_drhd_cb); - if (!ret && !no_iommu && !iommu_detected && !dmar_disabled) { + if (!ret && !iommu_detected && dmar_required()) { iommu_detected = 1; /* Make sure ACS will be enabled */ pci_request_acs(); diff --git a/include/linux/dma_remapping.h b/include/linux/dma_remapping.h index 21b3e7d33d68..5ce02d0f4688 100644 --- a/include/linux/dma_remapping.h +++ b/include/linux/dma_remapping.h @@ -52,6 +52,7 @@ static inline int iommu_calculate_max_sagaw(struct intel_iommu *iommu) } #define dmar_disabled (1) #define intel_iommu_enabled (0) +#define intel_iommu_tboot_noforce (0) #endif -- 2.34.1
2 1
0 0
[PATCH OLK-6.6] Fix duplicate variable definition in nfs4_laundromat()
by Zizhi Wo 08 Oct '26

08 Oct '26
hulk inclusion category: bugfix bugzilla: https://atomgit.com/openeuler/kernel/issues/10070 -------------------------------- Fix duplicate variable definition in nfs4_laundromat(), and modify the comment to adapt mainline. Fixes: db4cef375f330 ("[Backport] NFSD: Prevent client use-after-free during delegation revoke") Signed-off-by: Zizhi Wo <wozizhi(a)huawei.com> --- fs/nfsd/netns.h | 3 ++- fs/nfsd/nfs4state.c | 1 - 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/fs/nfsd/netns.h b/fs/nfsd/netns.h index eb8b8ebcb8b7..4a41645bb592 100644 --- a/fs/nfsd/netns.h +++ b/fs/nfsd/netns.h @@ -104,11 +104,12 @@ struct nfsd_net { /* protected by blocked_locks_lock */ struct list_head blocked_locks_lru; struct delayed_work laundromat_work; - /* client_lock protects the client lru list and session hash table */ + /* client_lock protects the client lru list and session hash + * table; nests inside deleg_lock */ spinlock_t client_lock; /* protects blocked_locks_lru */ spinlock_t blocked_locks_lock; diff --git a/fs/nfsd/nfs4state.c b/fs/nfsd/nfs4state.c index 775beac19656..770f9a8a18ce 100644 --- a/fs/nfsd/nfs4state.c +++ b/fs/nfsd/nfs4state.c @@ -6309,11 +6309,10 @@ nfs4_process_client_reaplist(struct list_head *reaplist) } static time64_t nfs4_laundromat(struct nfsd_net *nn) { - struct nfs4_client *clp; struct nfs4_openowner *oo; struct nfs4_delegation *dp; struct nfs4_ol_stateid *stp; struct nfsd4_blocked_lock *nbl; struct list_head *pos, *next, reaplist; -- 2.52.0
2 1
0 0
  • ← Newer
  • 1
  • 2
  • 3
  • 4
  • ...
  • 2508
  • Older →

HyperKitty Powered by HyperKitty