From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: stable@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
patches@lists.linux.dev, Eduard Zingerman <eddyz87@gmail.com>,
Jiri Olsa <jolsa@kernel.org>,
Kumar Kartikeya Dwivedi <memxor@gmail.com>,
Alexei Starovoitov <ast@kernel.org>,
Juri Lelli <juri.lelli@redhat.com>,
Manu Bretelle <chantra@meta.com>
Subject: [PATCH 6.12 081/172] bpf: Augment raw_tp arguments with PTR_MAYBE_NULL
Date: Tue, 17 Dec 2024 18:07:17 +0100 [thread overview]
Message-ID: <20241217170549.646884318@linuxfoundation.org> (raw)
In-Reply-To: <20241217170546.209657098@linuxfoundation.org>
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kumar Kartikeya Dwivedi <memxor@gmail.com>
commit 838a10bd2ebfe11a60dd67687533a7cfc220cc86 upstream.
Arguments to a raw tracepoint are tagged as trusted, which carries the
semantics that the pointer will be non-NULL. However, in certain cases,
a raw tracepoint argument may end up being NULL. More context about this
issue is available in [0].
Thus, there is a discrepancy between the reality, that raw_tp arguments can
actually be NULL, and the verifier's knowledge, that they are never NULL,
causing explicit NULL check branch to be dead code eliminated.
A previous attempt [1], i.e. the second fixed commit, was made to
simulate symbolic execution as if in most accesses, the argument is a
non-NULL raw_tp, except for conditional jumps. This tried to suppress
branch prediction while preserving compatibility, but surfaced issues
with production programs that were difficult to solve without increasing
verifier complexity. A more complete discussion of issues and fixes is
available at [2].
Fix this by maintaining an explicit list of tracepoints where the
arguments are known to be NULL, and mark the positional arguments as
PTR_MAYBE_NULL. Additionally, capture the tracepoints where arguments
are known to be ERR_PTR, and mark these arguments as scalar values to
prevent potential dereference.
Each hex digit is used to encode NULL-ness (0x1) or ERR_PTR-ness (0x2),
shifted by the zero-indexed argument number x 4. This can be represented
as follows:
1st arg: 0x1
2nd arg: 0x10
3rd arg: 0x100
... and so on (likewise for ERR_PTR case).
In the future, an automated pass will be used to produce such a list, or
insert __nullable annotations automatically for tracepoints. Each
compilation unit will be analyzed and results will be collated to find
whether a tracepoint pointer is definitely not null, maybe null, or an
unknown state where verifier conservatively marks it PTR_MAYBE_NULL.
A proof of concept of this tool from Eduard is available at [3].
Note that in case we don't find a specification in the raw_tp_null_args
array and the tracepoint belongs to a kernel module, we will
conservatively mark the arguments as PTR_MAYBE_NULL. This is because
unlike for in-tree modules, out-of-tree module tracepoints may pass NULL
freely to the tracepoint. We don't protect against such tracepoints
passing ERR_PTR (which is uncommon anyway), lest we mark all such
arguments as SCALAR_VALUE.
While we are it, let's adjust the test raw_tp_null to not perform
dereference of the skb->mark, as that won't be allowed anymore, and make
it more robust by using inline assembly to test the dead code
elimination behavior, which should still stay the same.
[0]: https://lore.kernel.org/bpf/ZrCZS6nisraEqehw@jlelli-thinkpadt14gen4.remote.csb
[1]: https://lore.kernel.org/all/20241104171959.2938862-1-memxor@gmail.com
[2]: https://lore.kernel.org/bpf/20241206161053.809580-1-memxor@gmail.com
[3]: https://github.com/eddyz87/llvm-project/tree/nullness-for-tracepoint-params
Reported-by: Juri Lelli <juri.lelli@redhat.com> # original bug
Reported-by: Manu Bretelle <chantra@meta.com> # bugs in masking fix
Fixes: 3f00c5239344 ("bpf: Allow trusted pointers to be passed to KF_TRUSTED_ARGS kfuncs")
Fixes: cb4158ce8ec8 ("bpf: Mark raw_tp arguments with PTR_MAYBE_NULL")
Reviewed-by: Eduard Zingerman <eddyz87@gmail.com>
Co-developed-by: Jiri Olsa <jolsa@kernel.org>
Signed-off-by: Jiri Olsa <jolsa@kernel.org>
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Link: https://lore.kernel.org/r/20241213221929.3495062-3-memxor@gmail.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/bpf/btf.c | 138 +++++++++++++++++++++++++++++++++++++++++++++++++++++++
1 file changed, 138 insertions(+)
--- a/kernel/bpf/btf.c
+++ b/kernel/bpf/btf.c
@@ -6415,6 +6415,101 @@ int btf_ctx_arg_offset(const struct btf
return off;
}
+struct bpf_raw_tp_null_args {
+ const char *func;
+ u64 mask;
+};
+
+static const struct bpf_raw_tp_null_args raw_tp_null_args[] = {
+ /* sched */
+ { "sched_pi_setprio", 0x10 },
+ /* ... from sched_numa_pair_template event class */
+ { "sched_stick_numa", 0x100 },
+ { "sched_swap_numa", 0x100 },
+ /* afs */
+ { "afs_make_fs_call", 0x10 },
+ { "afs_make_fs_calli", 0x10 },
+ { "afs_make_fs_call1", 0x10 },
+ { "afs_make_fs_call2", 0x10 },
+ { "afs_protocol_error", 0x1 },
+ { "afs_flock_ev", 0x10 },
+ /* cachefiles */
+ { "cachefiles_lookup", 0x1 | 0x200 },
+ { "cachefiles_unlink", 0x1 },
+ { "cachefiles_rename", 0x1 },
+ { "cachefiles_prep_read", 0x1 },
+ { "cachefiles_mark_active", 0x1 },
+ { "cachefiles_mark_failed", 0x1 },
+ { "cachefiles_mark_inactive", 0x1 },
+ { "cachefiles_vfs_error", 0x1 },
+ { "cachefiles_io_error", 0x1 },
+ { "cachefiles_ondemand_open", 0x1 },
+ { "cachefiles_ondemand_copen", 0x1 },
+ { "cachefiles_ondemand_close", 0x1 },
+ { "cachefiles_ondemand_read", 0x1 },
+ { "cachefiles_ondemand_cread", 0x1 },
+ { "cachefiles_ondemand_fd_write", 0x1 },
+ { "cachefiles_ondemand_fd_release", 0x1 },
+ /* ext4, from ext4__mballoc event class */
+ { "ext4_mballoc_discard", 0x10 },
+ { "ext4_mballoc_free", 0x10 },
+ /* fib */
+ { "fib_table_lookup", 0x100 },
+ /* filelock */
+ /* ... from filelock_lock event class */
+ { "posix_lock_inode", 0x10 },
+ { "fcntl_setlk", 0x10 },
+ { "locks_remove_posix", 0x10 },
+ { "flock_lock_inode", 0x10 },
+ /* ... from filelock_lease event class */
+ { "break_lease_noblock", 0x10 },
+ { "break_lease_block", 0x10 },
+ { "break_lease_unblock", 0x10 },
+ { "generic_delete_lease", 0x10 },
+ { "time_out_leases", 0x10 },
+ /* host1x */
+ { "host1x_cdma_push_gather", 0x10000 },
+ /* huge_memory */
+ { "mm_khugepaged_scan_pmd", 0x10 },
+ { "mm_collapse_huge_page_isolate", 0x1 },
+ { "mm_khugepaged_scan_file", 0x10 },
+ { "mm_khugepaged_collapse_file", 0x10 },
+ /* kmem */
+ { "mm_page_alloc", 0x1 },
+ { "mm_page_pcpu_drain", 0x1 },
+ /* .. from mm_page event class */
+ { "mm_page_alloc_zone_locked", 0x1 },
+ /* netfs */
+ { "netfs_failure", 0x10 },
+ /* power */
+ { "device_pm_callback_start", 0x10 },
+ /* qdisc */
+ { "qdisc_dequeue", 0x1000 },
+ /* rxrpc */
+ { "rxrpc_recvdata", 0x1 },
+ { "rxrpc_resend", 0x10 },
+ /* sunrpc */
+ { "xs_stream_read_data", 0x1 },
+ /* ... from xprt_cong_event event class */
+ { "xprt_reserve_cong", 0x10 },
+ { "xprt_release_cong", 0x10 },
+ { "xprt_get_cong", 0x10 },
+ { "xprt_put_cong", 0x10 },
+ /* tcp */
+ { "tcp_send_reset", 0x11 },
+ /* tegra_apb_dma */
+ { "tegra_dma_tx_status", 0x100 },
+ /* timer_migration */
+ { "tmigr_update_events", 0x1 },
+ /* writeback, from writeback_folio_template event class */
+ { "writeback_dirty_folio", 0x10 },
+ { "folio_wait_writeback", 0x10 },
+ /* rdma */
+ { "mr_integ_alloc", 0x2000 },
+ /* bpf_testmod */
+ { "bpf_testmod_test_read", 0x0 },
+};
+
bool btf_ctx_access(int off, int size, enum bpf_access_type type,
const struct bpf_prog *prog,
struct bpf_insn_access_aux *info)
@@ -6425,6 +6520,7 @@ bool btf_ctx_access(int off, int size, e
const char *tname = prog->aux->attach_func_name;
struct bpf_verifier_log *log = info->log;
const struct btf_param *args;
+ bool ptr_err_raw_tp = false;
const char *tag_value;
u32 nr_args, arg;
int i, ret;
@@ -6573,6 +6669,39 @@ bool btf_ctx_access(int off, int size, e
if (btf_param_match_suffix(btf, &args[arg], "__nullable"))
info->reg_type |= PTR_MAYBE_NULL;
+ if (prog->expected_attach_type == BPF_TRACE_RAW_TP) {
+ struct btf *btf = prog->aux->attach_btf;
+ const struct btf_type *t;
+ const char *tname;
+
+ /* BTF lookups cannot fail, return false on error */
+ t = btf_type_by_id(btf, prog->aux->attach_btf_id);
+ if (!t)
+ return false;
+ tname = btf_name_by_offset(btf, t->name_off);
+ if (!tname)
+ return false;
+ /* Checked by bpf_check_attach_target */
+ tname += sizeof("btf_trace_") - 1;
+ for (i = 0; i < ARRAY_SIZE(raw_tp_null_args); i++) {
+ /* Is this a func with potential NULL args? */
+ if (strcmp(tname, raw_tp_null_args[i].func))
+ continue;
+ if (raw_tp_null_args[i].mask & (0x1 << (arg * 4)))
+ info->reg_type |= PTR_MAYBE_NULL;
+ /* Is the current arg IS_ERR? */
+ if (raw_tp_null_args[i].mask & (0x2 << (arg * 4)))
+ ptr_err_raw_tp = true;
+ break;
+ }
+ /* If we don't know NULL-ness specification and the tracepoint
+ * is coming from a loadable module, be conservative and mark
+ * argument as PTR_MAYBE_NULL.
+ */
+ if (i == ARRAY_SIZE(raw_tp_null_args) && btf_is_module(btf))
+ info->reg_type |= PTR_MAYBE_NULL;
+ }
+
if (tgt_prog) {
enum bpf_prog_type tgt_type;
@@ -6617,6 +6746,15 @@ bool btf_ctx_access(int off, int size, e
bpf_log(log, "func '%s' arg%d has btf_id %d type %s '%s'\n",
tname, arg, info->btf_id, btf_type_str(t),
__btf_name_by_offset(btf, t->name_off));
+
+ /* Perform all checks on the validity of type for this argument, but if
+ * we know it can be IS_ERR at runtime, scrub pointer type and mark as
+ * scalar.
+ */
+ if (ptr_err_raw_tp) {
+ bpf_log(log, "marking pointer arg%d as scalar as it may encode error", arg);
+ info->reg_type = SCALAR_VALUE;
+ }
return true;
}
EXPORT_SYMBOL_GPL(btf_ctx_access);
next prev parent reply other threads:[~2024-12-17 17:30 UTC|newest]
Thread overview: 195+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-12-17 17:05 [PATCH 6.12 000/172] 6.12.6-rc1 review Greg Kroah-Hartman
2024-12-17 17:05 ` [PATCH 6.12 001/172] usb: misc: onboard_usb_dev: skip suspend/resume sequence for USB5744 SMBus support Greg Kroah-Hartman
2024-12-17 17:05 ` [PATCH 6.12 002/172] serial: sh-sci: Check if TX data was written to device in .tx_empty() Greg Kroah-Hartman
2024-12-17 17:05 ` [PATCH 6.12 003/172] bpf: Fix UAF via mismatching bpf_prog/attachment RCU flavors Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 004/172] sched/deadline: Fix replenish_dl_new_period dl_server condition Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 005/172] perf/x86/intel/ds: Unconditionally drain PEBS DS when changing PEBS_DATA_CFG Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 006/172] clk: en7523: Fix wrong BUS clock for EN7581 Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 007/172] ksmbd: fix racy issue from session lookup and expire Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 008/172] splice: do not checksum AF_UNIX sockets Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 009/172] tcp: check space before adding MPTCP SYN options Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 010/172] perf ftrace: Fix undefined behavior in cmp_profile_data() Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 011/172] virtio_net: correct netdev_tx_reset_queue() invocation point Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 012/172] virtio_ring: add a func argument recycle_done to virtqueue_resize() Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 013/172] virtio_net: ensure netdev_tx_reset_queue is called on tx ring resize Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 014/172] riscv: mm: Do not call pmd dtor on vmemmap page table teardown Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 015/172] riscv: Fix wrong usage of __pa() on a fixmap address Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 016/172] blk-cgroup: Fix UAF in blkcg_unpin_online() Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 017/172] block: Switch to using refcount_t for zone write plugs Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 018/172] block: Use a zone write plug BIO work for REQ_NOWAIT BIOs Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 019/172] dm: Fix dm-zoned-reclaim zone write pointer alignment Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 020/172] block: Prevent potential deadlocks in zone write plug error recovery Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 021/172] gpio: graniterapids: Fix GPIO Ack functionality Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 022/172] memcg: slub: fix SUnreclaim for post charged objects Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 023/172] spi: rockchip: Fix PM runtime count on no-op cs Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 024/172] gpio: ljca: Initialize num before accessing item in ljca_gpio_config Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 025/172] ALSA: usb-audio: Add implicit feedback quirk for Yamaha THR5 Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 026/172] ALSA: hda/realtek: Fix headset mic on Acer Nitro 5 Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 027/172] riscv: Fix IPIs usage in kfence_protect_page() Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 028/172] crypto: hisilicon/debugfs - fix the struct pointer incorrectly offset problem Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 029/172] drm/panic: remove spurious empty line to clean warning Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 030/172] usb: host: max3421-hcd: Correctly abort a USB request Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 031/172] block: Ignore REQ_NOWAIT for zone reset and zone finish operations Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 032/172] gpio: graniterapids: Fix vGPIO driver crash Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 033/172] gpio: graniterapids: Fix incorrect BAR assignment Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 034/172] gpio: graniterapids: Fix invalid GPI_IS register offset Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 035/172] gpio: graniterapids: Fix invalid RXEVCFG register bitmask Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 036/172] gpio: graniterapids: Determine if GPIO pad can be used by driver Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 037/172] gpio: graniterapids: Check if GPIO line can be used for IRQs Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 038/172] usb: core: hcd: only check primary hcd skip_phy_initialization Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 039/172] bpf: Revert "bpf: Mark raw_tp arguments with PTR_MAYBE_NULL" Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 040/172] ata: sata_highbank: fix OF node reference leak in highbank_initialize_phys() Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 041/172] usb: dwc2: Fix HCD resume Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 042/172] usb: dwc2: hcd: Fix GetPortStatus & SetPortFeature Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 043/172] usb: dwc2: Fix HCD port connection race Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 044/172] scsi: ufs: core: Update compl_time_stamp_local_clock after completing a cqe Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 045/172] usb: gadget: midi2: Fix interpretation of is_midi1 bits Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 046/172] usb: ehci-hcd: fix call balance of clocks handling routines Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 047/172] usb: typec: anx7411: fix fwnode_handle reference leak Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 048/172] usb: dwc3: imx8mp: fix software node kernel dump Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 049/172] usb: typec: anx7411: fix OF node reference leaks in anx7411_typec_switch_probe() Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 050/172] usb: gadget: u_serial: Fix the issue that gs_start_io crashed due to accessing null pointer Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 051/172] usb: typec: ucsi: Fix completion notifications Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 052/172] usb: dwc3: xilinx: make sure pipe clock is deselected in usb2 only mode Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 053/172] iommu/tegra241-cmdqv: do not use smp_processor_id in preemptible context Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 054/172] iommu/vt-d: Remove cache tags before disabling ATS Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 055/172] iommu/vt-d: Fix qi_batch NULL pointer with nested parent domain Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 056/172] drm/xe: Call invalidation_fence_fini for PT inval fences in error state Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 057/172] drm/amdkfd: pause autosuspend when creating pdd Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 058/172] drm/i915: Fix memory leak by correcting cache object name in error handler Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 059/172] drm/i915/color: Stop using non-posted DSB writes for legacy LUT Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 060/172] drm/i915: Fix NULL pointer dereference in capture_engine Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 061/172] drm/amdgpu: fix UVD contiguous CS mapping problem Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 062/172] drm/amd/pm: Set SMU v13.0.7 default workload type Greg Kroah-Hartman
2024-12-17 17:06 ` [PATCH 6.12 063/172] drm/amdgpu: fix when the cleaner shader is emitted Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 064/172] drm/amdkfd: Dereference null return value Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 065/172] drm/amdkfd: hard-code cacheline size for gfx11 Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 066/172] drm/amdkfd: hard-code MALL cacheline size for gfx11, gfx12 Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 067/172] xfs: set XFS_SICK_INO_SYMLINK_ZAPPED explicitly when zapping a symlink Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 068/172] xfs: update btree keys correctly when _insrec splits an inode root block Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 069/172] xfs: dont drop errno values when we fail to ficlone the entire range Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 070/172] xfs: return a 64-bit block count from xfs_btree_count_blocks Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 071/172] xfs: fix null bno_hint handling in xfs_rtallocate_rtg Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 072/172] xfs: return from xfs_symlink_verify early on V4 filesystems Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 073/172] xfs: fix scrub tracepoints when inode-rooted btrees are involved Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 074/172] xfs: only run precommits once per transaction object Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 075/172] xfs: unlock inodes when erroring out of xfs_trans_alloc_dir Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 076/172] bpf: Check size for BTF-based ctx access of pointer members Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 077/172] bpf: Fix theoretical prog_array UAF in __uprobe_perf_func() Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 078/172] bpf,perf: Fix invalid prog_array access in perf_event_detach_bpf_prog Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 079/172] bpf, sockmap: Fix race between element replace and close() Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 080/172] bpf, sockmap: Fix update element with same Greg Kroah-Hartman
2024-12-17 17:07 ` Greg Kroah-Hartman [this message]
2024-12-17 17:07 ` [PATCH 6.12 082/172] perf tools: Fix build-id event recording Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 083/172] wifi: nl80211: fix NL80211_ATTR_MLO_LINK_ID off-by-one Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 084/172] wifi: mac80211: init cnt before accessing elem in ieee80211_copy_mbssid_beacon Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 085/172] wifi: mac80211: fix a queue stall in certain cases of CSA Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 086/172] wifi: mac80211: fix station NSS capability initialization order Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 087/172] perf machine: Initialize machine->env to address a segfault Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 088/172] acpi: nfit: vmalloc-out-of-bounds Read in acpi_nfit_ctl Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 089/172] amdgpu/uvd: get ring reference from rq scheduler Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 090/172] batman-adv: Do not send uninitialized TT changes Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 091/172] batman-adv: Remove uninitialized data in full table TT response Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 092/172] batman-adv: Do not let TT changes list grows indefinitely Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 093/172] tipc: fix NULL deref in cleanup_bearer() Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 094/172] net/mlx5: DR, prevent potential error pointer dereference Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 095/172] wifi: cfg80211: sme: init n_channels before channels[] access Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 096/172] selftests: mlxsw: sharedbuffer: Remove h1 ingress test case Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 097/172] selftests: mlxsw: sharedbuffer: Remove duplicate test cases Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 098/172] selftests: mlxsw: sharedbuffer: Ensure no extra packets are counted Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 099/172] ptp: kvm: x86: Return EOPNOTSUPP instead of ENODEV from kvm_arch_ptp_init() Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 100/172] bnxt_en: Fix GSO type for HW GRO packets on 5750X chips Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 101/172] net: lapb: increase LAPB_HEADER_LEN Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 102/172] net: defer final struct net free in netns dismantle Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 103/172] net: mscc: ocelot: fix memory leak on ocelot_port_add_txtstamp_skb() Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 104/172] net: mscc: ocelot: improve handling of TX timestamp for unknown skb Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 105/172] net: mscc: ocelot: ocelot->ts_id_lock and ocelot_port->tx_skbs.lock are IRQ-safe Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 106/172] net: mscc: ocelot: be resilient to loss of PTP packets during transmission Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 107/172] net: mscc: ocelot: perform error cleanup in ocelot_hwstamp_set() Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 108/172] regulator: axp20x: AXP717: set ramp_delay Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 109/172] spi: aspeed: Fix an error handling path in aspeed_spi_[read|write]_user() Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 110/172] net: sparx5: fix FDMA performance issue Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 111/172] net: sparx5: fix the maximum frame length register Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 112/172] ACPI: resource: Fix memory resource type union access Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 113/172] cxgb4: use port number to set mac addr Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 114/172] qca_spi: Fix clock speed for multiple QCA7000 Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 115/172] qca_spi: Make driver probing reliable Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 116/172] ALSA: control: Avoid WARN() for symlink errors Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 117/172] ASoC: amd: yc: Fix the wrong return value Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 118/172] Documentation: PM: Clarify pm_runtime_resume_and_get() " Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 119/172] block: get wp_offset by bdev_offset_from_zone_start Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 120/172] bnxt_en: Fix aggregation ID mask to prevent oops on 5760X chips Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 121/172] Documentation: networking: Add a caveat to nexthop_compat_mode sysctl Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 122/172] cifs: Fix rmdir failure due to ongoing I/O on deleted file Greg Kroah-Hartman
2024-12-17 17:07 ` [PATCH 6.12 123/172] net: renesas: rswitch: fix possible early skb release Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 124/172] net: renesas: rswitch: fix race window between tx start and complete Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 125/172] net: renesas: rswitch: fix leaked pointer on error path Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 126/172] net: renesas: rswitch: avoid use-after-put for a device tree node Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 127/172] net: renesas: rswitch: handle stop vs interrupt race Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 128/172] ASoC: tas2781: Fix calibration issue in stress test Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 129/172] Bluetooth: Improve setsockopt() handling of malformed user input Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 130/172] libperf: evlist: Fix --cpu argument on hybrid platform Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 131/172] ASoC: fsl_xcvr: change IFACE_PCM to IFACE_MIXER Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 132/172] ASoC: fsl_spdif: " Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 133/172] selftests: netfilter: Stabilize rpath.sh Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 134/172] netfilter: IDLETIMER: Fix for possible ABBA deadlock Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 135/172] netfilter: nf_tables: do not defer rule destruction via call_rcu Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 136/172] net: mana: Fix memory leak in mana_gd_setup_irqs Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 137/172] net: mana: Fix irq_contexts " Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 138/172] net: dsa: felix: fix stuck CPU-injected packets with short taprio windows Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 139/172] net/sched: netem: account for backlog updates from child qdisc Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 140/172] net, team, bonding: Add netdev_base_features helper Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 141/172] bonding: Fix initial {vlan,mpls}_feature set in bond_compute_features Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 142/172] bonding: Fix feature propagation of NETIF_F_GSO_ENCAP_ALL Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 143/172] team: Fix initial vlan_feature set in __team_compute_features Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 144/172] team: Fix feature propagation of NETIF_F_GSO_ENCAP_ALL Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 145/172] ASoC: Intel: sof_sdw: Add space for a terminator into DAIs array Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 146/172] ACPICA: events/evxfregn: dont release the ContextMutex that was never acquired Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 147/172] Bluetooth: hci_event: Fix using rcu_read_(un)lock while iterating Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 148/172] Bluetooth: iso: Always release hdev at the end of iso_listen_bis Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 149/172] Bluetooth: iso: Fix recursive locking warning Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 150/172] Bluetooth: SCO: Add support for 16 bits transparent voice setting Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 151/172] Bluetooth: iso: Fix circular lock in iso_listen_bis Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 152/172] Bluetooth: iso: Fix circular lock in iso_conn_big_sync Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 153/172] Bluetooth: btmtk: avoid UAF in btmtk_process_coredump Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 154/172] net: renesas: rswitch: fix initial MPIC register setting Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 155/172] net: dsa: microchip: KSZ9896 register regmap alignment to 32 bit boundaries Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 156/172] net: dsa: tag_ocelot_8021q: fix broken reception Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 157/172] drm/xe: fix the ERR_PTR() returned on failure to allocate tiny pt Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 158/172] drm/xe/reg_sr: Remove register pool Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 159/172] blk-iocost: Avoid using clamp() on inuse in __propagate_weights() Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 160/172] kselftest/arm64: abi: fix SVCR detection Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 161/172] blk-mq: move cpuhp callback registering out of q->sysfs_lock Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 162/172] block: Fix potential deadlock while freezing queue and acquiring sysfs_lock Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 163/172] rust: kbuild: set `bindgen`s Rust target version Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 164/172] KVM: arm64: Disable MPAM visibility by default and ignore VMM writes Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 165/172] xen/netfront: fix crash when removing device Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 166/172] x86: make get_cpu_vendor() accessible from Xen code Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 167/172] objtool/x86: allow syscall instruction Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 168/172] x86/static-call: provide a way to do very early static-call updates Greg Kroah-Hartman
2024-12-18 8:37 ` Jiri Slaby
2024-12-18 8:53 ` Jürgen Groß
2024-12-19 15:40 ` Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 169/172] x86/xen: dont do PV iret hypercall through hypercall page Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 170/172] x86/xen: add central hypercall functions Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 171/172] x86/xen: use new hypercall functions instead of hypercall page Greg Kroah-Hartman
2024-12-17 17:08 ` [PATCH 6.12 172/172] x86/xen: remove " Greg Kroah-Hartman
2024-12-17 20:21 ` [PATCH 6.12 000/172] 6.12.6-rc1 review Florian Fainelli
2024-12-17 22:58 ` Shuah Khan
2024-12-17 23:43 ` Christian Heusel
2024-12-18 0:58 ` Guenter Roeck
2024-12-18 6:42 ` Ron Economos
2024-12-18 12:16 ` Takeshi Ogasawara
2024-12-18 12:32 ` Mark Brown
2024-12-18 13:03 ` Peter Schneider
2024-12-18 13:19 ` Naresh Kamboju
2024-12-18 14:56 ` Jiri Slaby
2024-12-18 16:53 ` Guenter Roeck
2024-12-18 16:54 ` Peter Zijlstra
2024-12-18 17:48 ` Jiri Slaby
2024-12-19 5:56 ` Guenter Roeck
2025-01-13 11:00 ` Pavel Machek
2024-12-18 17:21 ` Jon Hunter
2024-12-18 17:57 ` Justin Forbes
2024-12-19 6:35 ` Harshit Mogalapalli
2024-12-19 18:29 ` Miguel Ojeda
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20241217170549.646884318@linuxfoundation.org \
--to=gregkh@linuxfoundation.org \
--cc=ast@kernel.org \
--cc=chantra@meta.com \
--cc=eddyz87@gmail.com \
--cc=jolsa@kernel.org \
--cc=juri.lelli@redhat.com \
--cc=memxor@gmail.com \
--cc=patches@lists.linux.dev \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox