Linux kernel -stable discussions
 help / color / mirror / Atom feed
From: Kamal Mostafa <kamal@canonical.com>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org,
	kernel-team@lists.ubuntu.com
Cc: Mikulas Patocka <mpatocka@redhat.com>,
	Tomi Valkeinen <tomi.valkeinen@ti.com>,
	Kamal Mostafa <kamal@canonical.com>
Subject: [PATCH 3.8 032/133] framebuffer: fix cfb_copyarea
Date: Tue, 22 Apr 2014 13:12:50 -0700	[thread overview]
Message-ID: <1398197671-12786-33-git-send-email-kamal@canonical.com> (raw)
In-Reply-To: <1398197671-12786-1-git-send-email-kamal@canonical.com>

3.8.13.22 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mikulas Patocka <mpatocka@redhat.com>

commit 00a9d699bc85052d2d3ed56251cd928024ce06a3 upstream.

The function cfb_copyarea is buggy when the copy operation is not aligned on
long boundary (4 bytes on 32-bit machines, 8 bytes on 64-bit machines).

How to reproduce:
- use x86-64 machine
- use a framebuffer driver without acceleration (for example uvesafb)
- set the framebuffer to 8-bit depth
	(for example fbset -a 1024x768-60 -depth 8)
- load a font with character width that is not a multiple of 8 pixels
	note: the console-tools package cannot load a font that has
	width different from 8 pixels. You need to install the packages
	"kbd" and "console-terminus" and use the program "setfont" to
	set font width (for example: setfont Uni2-Terminus20x10)
- move some text left and right on the bash command line and you get a
	screen corruption

To expose more bugs, put this line to the end of uvesafb_init_info:
info->flags |= FBINFO_HWACCEL_COPYAREA | FBINFO_READS_FAST;
- Now framebuffer console will use cfb_copyarea for console scrolling.
You get a screen corruption when console is scrolled.

This patch is a rewrite of cfb_copyarea. It fixes the bugs, with this
patch, console scrolling in 8-bit depth with a font width that is not a
multiple of 8 pixels works fine.

The cfb_copyarea code was very buggy and it looks like it was written
and never tried with non-8-pixel font.

Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>
Signed-off-by: Tomi Valkeinen <tomi.valkeinen@ti.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/video/cfbcopyarea.c | 153 ++++++++++++++++++++++----------------------
 1 file changed, 78 insertions(+), 75 deletions(-)

diff --git a/drivers/video/cfbcopyarea.c b/drivers/video/cfbcopyarea.c
index bb5a96b..bcb5723 100644
--- a/drivers/video/cfbcopyarea.c
+++ b/drivers/video/cfbcopyarea.c
@@ -43,13 +43,22 @@
      */
 
 static void
-bitcpy(struct fb_info *p, unsigned long __iomem *dst, int dst_idx,
-		const unsigned long __iomem *src, int src_idx, int bits,
+bitcpy(struct fb_info *p, unsigned long __iomem *dst, unsigned dst_idx,
+		const unsigned long __iomem *src, unsigned src_idx, int bits,
 		unsigned n, u32 bswapmask)
 {
 	unsigned long first, last;
 	int const shift = dst_idx-src_idx;
-	int left, right;
+
+#if 0
+	/*
+	 * If you suspect bug in this function, compare it with this simple
+	 * memmove implementation.
+	 */
+	fb_memmove((char *)dst + ((dst_idx & (bits - 1))) / 8,
+		   (char *)src + ((src_idx & (bits - 1))) / 8, n / 8);
+	return;
+#endif
 
 	first = fb_shifted_pixels_mask_long(p, dst_idx, bswapmask);
 	last = ~fb_shifted_pixels_mask_long(p, (dst_idx+n) % bits, bswapmask);
@@ -98,9 +107,8 @@ bitcpy(struct fb_info *p, unsigned long __iomem *dst, int dst_idx,
 		unsigned long d0, d1;
 		int m;
 
-		right = shift & (bits - 1);
-		left = -shift & (bits - 1);
-		bswapmask &= shift;
+		int const left = shift & (bits - 1);
+		int const right = -shift & (bits - 1);
 
 		if (dst_idx+n <= bits) {
 			// Single destination word
@@ -110,15 +118,15 @@ bitcpy(struct fb_info *p, unsigned long __iomem *dst, int dst_idx,
 			d0 = fb_rev_pixels_in_long(d0, bswapmask);
 			if (shift > 0) {
 				// Single source word
-				d0 >>= right;
+				d0 <<= left;
 			} else if (src_idx+n <= bits) {
 				// Single source word
-				d0 <<= left;
+				d0 >>= right;
 			} else {
 				// 2 source words
 				d1 = FB_READL(src + 1);
 				d1 = fb_rev_pixels_in_long(d1, bswapmask);
-				d0 = d0<<left | d1>>right;
+				d0 = d0 >> right | d1 << left;
 			}
 			d0 = fb_rev_pixels_in_long(d0, bswapmask);
 			FB_WRITEL(comp(d0, FB_READL(dst), first), dst);
@@ -135,60 +143,59 @@ bitcpy(struct fb_info *p, unsigned long __iomem *dst, int dst_idx,
 			if (shift > 0) {
 				// Single source word
 				d1 = d0;
-				d0 >>= right;
-				dst++;
+				d0 <<= left;
 				n -= bits - dst_idx;
 			} else {
 				// 2 source words
 				d1 = FB_READL(src++);
 				d1 = fb_rev_pixels_in_long(d1, bswapmask);
 
-				d0 = d0<<left | d1>>right;
-				dst++;
+				d0 = d0 >> right | d1 << left;
 				n -= bits - dst_idx;
 			}
 			d0 = fb_rev_pixels_in_long(d0, bswapmask);
 			FB_WRITEL(comp(d0, FB_READL(dst), first), dst);
 			d0 = d1;
+			dst++;
 
 			// Main chunk
 			m = n % bits;
 			n /= bits;
 			while ((n >= 4) && !bswapmask) {
 				d1 = FB_READL(src++);
-				FB_WRITEL(d0 << left | d1 >> right, dst++);
+				FB_WRITEL(d0 >> right | d1 << left, dst++);
 				d0 = d1;
 				d1 = FB_READL(src++);
-				FB_WRITEL(d0 << left | d1 >> right, dst++);
+				FB_WRITEL(d0 >> right | d1 << left, dst++);
 				d0 = d1;
 				d1 = FB_READL(src++);
-				FB_WRITEL(d0 << left | d1 >> right, dst++);
+				FB_WRITEL(d0 >> right | d1 << left, dst++);
 				d0 = d1;
 				d1 = FB_READL(src++);
-				FB_WRITEL(d0 << left | d1 >> right, dst++);
+				FB_WRITEL(d0 >> right | d1 << left, dst++);
 				d0 = d1;
 				n -= 4;
 			}
 			while (n--) {
 				d1 = FB_READL(src++);
 				d1 = fb_rev_pixels_in_long(d1, bswapmask);
-				d0 = d0 << left | d1 >> right;
+				d0 = d0 >> right | d1 << left;
 				d0 = fb_rev_pixels_in_long(d0, bswapmask);
 				FB_WRITEL(d0, dst++);
 				d0 = d1;
 			}
 
 			// Trailing bits
-			if (last) {
-				if (m <= right) {
+			if (m) {
+				if (m <= bits - right) {
 					// Single source word
-					d0 <<= left;
+					d0 >>= right;
 				} else {
 					// 2 source words
 					d1 = FB_READL(src);
 					d1 = fb_rev_pixels_in_long(d1,
 								bswapmask);
-					d0 = d0<<left | d1>>right;
+					d0 = d0 >> right | d1 << left;
 				}
 				d0 = fb_rev_pixels_in_long(d0, bswapmask);
 				FB_WRITEL(comp(d0, FB_READL(dst), last), dst);
@@ -202,43 +209,46 @@ bitcpy(struct fb_info *p, unsigned long __iomem *dst, int dst_idx,
      */
 
 static void
-bitcpy_rev(struct fb_info *p, unsigned long __iomem *dst, int dst_idx,
-		const unsigned long __iomem *src, int src_idx, int bits,
+bitcpy_rev(struct fb_info *p, unsigned long __iomem *dst, unsigned dst_idx,
+		const unsigned long __iomem *src, unsigned src_idx, int bits,
 		unsigned n, u32 bswapmask)
 {
 	unsigned long first, last;
 	int shift;
 
-	dst += (n-1)/bits;
-	src += (n-1)/bits;
-	if ((n-1) % bits) {
-		dst_idx += (n-1) % bits;
-		dst += dst_idx >> (ffs(bits) - 1);
-		dst_idx &= bits - 1;
-		src_idx += (n-1) % bits;
-		src += src_idx >> (ffs(bits) - 1);
-		src_idx &= bits - 1;
-	}
+#if 0
+	/*
+	 * If you suspect bug in this function, compare it with this simple
+	 * memmove implementation.
+	 */
+	fb_memmove((char *)dst + ((dst_idx & (bits - 1))) / 8,
+		   (char *)src + ((src_idx & (bits - 1))) / 8, n / 8);
+	return;
+#endif
+
+	dst += (dst_idx + n - 1) / bits;
+	src += (src_idx + n - 1) / bits;
+	dst_idx = (dst_idx + n - 1) % bits;
+	src_idx = (src_idx + n - 1) % bits;
 
 	shift = dst_idx-src_idx;
 
-	first = fb_shifted_pixels_mask_long(p, bits - 1 - dst_idx, bswapmask);
-	last = ~fb_shifted_pixels_mask_long(p, bits - 1 - ((dst_idx-n) % bits),
-					    bswapmask);
+	first = ~fb_shifted_pixels_mask_long(p, (dst_idx + 1) % bits, bswapmask);
+	last = fb_shifted_pixels_mask_long(p, (bits + dst_idx + 1 - n) % bits, bswapmask);
 
 	if (!shift) {
 		// Same alignment for source and dest
 
 		if ((unsigned long)dst_idx+1 >= n) {
 			// Single word
-			if (last)
-				first &= last;
-			FB_WRITEL( comp( FB_READL(src), FB_READL(dst), first), dst);
+			if (first)
+				last &= first;
+			FB_WRITEL( comp( FB_READL(src), FB_READL(dst), last), dst);
 		} else {
 			// Multiple destination words
 
 			// Leading bits
-			if (first != ~0UL) {
+			if (first) {
 				FB_WRITEL( comp( FB_READL(src), FB_READL(dst), first), dst);
 				dst--;
 				src--;
@@ -262,7 +272,7 @@ bitcpy_rev(struct fb_info *p, unsigned long __iomem *dst, int dst_idx,
 				FB_WRITEL(FB_READL(src--), dst--);
 
 			// Trailing bits
-			if (last)
+			if (last != -1UL)
 				FB_WRITEL( comp( FB_READL(src), FB_READL(dst), last), dst);
 		}
 	} else {
@@ -270,29 +280,28 @@ bitcpy_rev(struct fb_info *p, unsigned long __iomem *dst, int dst_idx,
 		unsigned long d0, d1;
 		int m;
 
-		int const left = -shift & (bits-1);
-		int const right = shift & (bits-1);
-		bswapmask &= shift;
+		int const left = shift & (bits-1);
+		int const right = -shift & (bits-1);
 
 		if ((unsigned long)dst_idx+1 >= n) {
 			// Single destination word
-			if (last)
-				first &= last;
+			if (first)
+				last &= first;
 			d0 = FB_READL(src);
 			if (shift < 0) {
 				// Single source word
-				d0 <<= left;
+				d0 >>= right;
 			} else if (1+(unsigned long)src_idx >= n) {
 				// Single source word
-				d0 >>= right;
+				d0 <<= left;
 			} else {
 				// 2 source words
 				d1 = FB_READL(src - 1);
 				d1 = fb_rev_pixels_in_long(d1, bswapmask);
-				d0 = d0>>right | d1<<left;
+				d0 = d0 << left | d1 >> right;
 			}
 			d0 = fb_rev_pixels_in_long(d0, bswapmask);
-			FB_WRITEL(comp(d0, FB_READL(dst), first), dst);
+			FB_WRITEL(comp(d0, FB_READL(dst), last), dst);
 		} else {
 			// Multiple destination words
 			/** We must always remember the last value read, because in case
@@ -307,12 +316,12 @@ bitcpy_rev(struct fb_info *p, unsigned long __iomem *dst, int dst_idx,
 			if (shift < 0) {
 				// Single source word
 				d1 = d0;
-				d0 <<= left;
+				d0 >>= right;
 			} else {
 				// 2 source words
 				d1 = FB_READL(src--);
 				d1 = fb_rev_pixels_in_long(d1, bswapmask);
-				d0 = d0>>right | d1<<left;
+				d0 = d0 << left | d1 >> right;
 			}
 			d0 = fb_rev_pixels_in_long(d0, bswapmask);
 			FB_WRITEL(comp(d0, FB_READL(dst), first), dst);
@@ -325,39 +334,39 @@ bitcpy_rev(struct fb_info *p, unsigned long __iomem *dst, int dst_idx,
 			n /= bits;
 			while ((n >= 4) && !bswapmask) {
 				d1 = FB_READL(src--);
-				FB_WRITEL(d0 >> right | d1 << left, dst--);
+				FB_WRITEL(d0 << left | d1 >> right, dst--);
 				d0 = d1;
 				d1 = FB_READL(src--);
-				FB_WRITEL(d0 >> right | d1 << left, dst--);
+				FB_WRITEL(d0 << left | d1 >> right, dst--);
 				d0 = d1;
 				d1 = FB_READL(src--);
-				FB_WRITEL(d0 >> right | d1 << left, dst--);
+				FB_WRITEL(d0 << left | d1 >> right, dst--);
 				d0 = d1;
 				d1 = FB_READL(src--);
-				FB_WRITEL(d0 >> right | d1 << left, dst--);
+				FB_WRITEL(d0 << left | d1 >> right, dst--);
 				d0 = d1;
 				n -= 4;
 			}
 			while (n--) {
 				d1 = FB_READL(src--);
 				d1 = fb_rev_pixels_in_long(d1, bswapmask);
-				d0 = d0 >> right | d1 << left;
+				d0 = d0 << left | d1 >> right;
 				d0 = fb_rev_pixels_in_long(d0, bswapmask);
 				FB_WRITEL(d0, dst--);
 				d0 = d1;
 			}
 
 			// Trailing bits
-			if (last) {
-				if (m <= left) {
+			if (m) {
+				if (m <= bits - left) {
 					// Single source word
-					d0 >>= right;
+					d0 <<= left;
 				} else {
 					// 2 source words
 					d1 = FB_READL(src);
 					d1 = fb_rev_pixels_in_long(d1,
 								bswapmask);
-					d0 = d0>>right | d1<<left;
+					d0 = d0 << left | d1 >> right;
 				}
 				d0 = fb_rev_pixels_in_long(d0, bswapmask);
 				FB_WRITEL(comp(d0, FB_READL(dst), last), dst);
@@ -371,9 +380,9 @@ void cfb_copyarea(struct fb_info *p, const struct fb_copyarea *area)
 	u32 dx = area->dx, dy = area->dy, sx = area->sx, sy = area->sy;
 	u32 height = area->height, width = area->width;
 	unsigned long const bits_per_line = p->fix.line_length*8u;
-	unsigned long __iomem *dst = NULL, *src = NULL;
+	unsigned long __iomem *base = NULL;
 	int bits = BITS_PER_LONG, bytes = bits >> 3;
-	int dst_idx = 0, src_idx = 0, rev_copy = 0;
+	unsigned dst_idx = 0, src_idx = 0, rev_copy = 0;
 	u32 bswapmask = fb_compute_bswapmask(p);
 
 	if (p->state != FBINFO_STATE_RUNNING)
@@ -389,7 +398,7 @@ void cfb_copyarea(struct fb_info *p, const struct fb_copyarea *area)
 
 	// split the base of the framebuffer into a long-aligned address and the
 	// index of the first bit
-	dst = src = (unsigned long __iomem *)((unsigned long)p->screen_base & ~(bytes-1));
+	base = (unsigned long __iomem *)((unsigned long)p->screen_base & ~(bytes-1));
 	dst_idx = src_idx = 8*((unsigned long)p->screen_base & (bytes-1));
 	// add offset of source and target area
 	dst_idx += dy*bits_per_line + dx*p->var.bits_per_pixel;
@@ -402,20 +411,14 @@ void cfb_copyarea(struct fb_info *p, const struct fb_copyarea *area)
 		while (height--) {
 			dst_idx -= bits_per_line;
 			src_idx -= bits_per_line;
-			dst += dst_idx >> (ffs(bits) - 1);
-			dst_idx &= (bytes - 1);
-			src += src_idx >> (ffs(bits) - 1);
-			src_idx &= (bytes - 1);
-			bitcpy_rev(p, dst, dst_idx, src, src_idx, bits,
+			bitcpy_rev(p, base + (dst_idx / bits), dst_idx % bits,
+				base + (src_idx / bits), src_idx % bits, bits,
 				width*p->var.bits_per_pixel, bswapmask);
 		}
 	} else {
 		while (height--) {
-			dst += dst_idx >> (ffs(bits) - 1);
-			dst_idx &= (bytes - 1);
-			src += src_idx >> (ffs(bits) - 1);
-			src_idx &= (bytes - 1);
-			bitcpy(p, dst, dst_idx, src, src_idx, bits,
+			bitcpy(p, base + (dst_idx / bits), dst_idx % bits,
+				base + (src_idx / bits), src_idx % bits, bits,
 				width*p->var.bits_per_pixel, bswapmask);
 			dst_idx += bits_per_line;
 			src_idx += bits_per_line;
-- 
1.9.1


  parent reply	other threads:[~2014-04-22 20:12 UTC|newest]

Thread overview: 138+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-04-22 20:12 [3.8.y.z extended stable] Linux 3.8.13.22 stable review Kamal Mostafa
2014-04-22 20:12 ` [PATCH 3.8 001/133] net: sctp: fix skb leakage in COOKIE ECHO path of chunk->auth_chunk Kamal Mostafa
2014-04-22 20:12 ` [PATCH 3.8 002/133] bridge: multicast: add sanity check for query source addresses Kamal Mostafa
2014-04-22 20:12 ` [PATCH 3.8 003/133] net: unix: non blocking recvmsg() should not return -EINTR Kamal Mostafa
2014-04-22 20:12 ` [PATCH 3.8 004/133] ipv6: Fix exthdrs offload registration Kamal Mostafa
2014-04-22 20:12 ` [PATCH 3.8 005/133] ipv6: don't set DST_NOCOUNT for remotely added routes Kamal Mostafa
2014-04-22 20:12 ` [PATCH 3.8 006/133] vlan: Set correct source MAC address with TX VLAN offload enabled Kamal Mostafa
2014-04-22 20:12 ` [PATCH 3.8 007/133] tcp: tcp_release_cb() should release socket ownership Kamal Mostafa
2014-04-22 20:12 ` [PATCH 3.8 008/133] net: socket: error on a negative msg_namelen Kamal Mostafa
2014-04-22 20:12 ` [PATCH 3.8 009/133] ipv6: Avoid unnecessary temporary addresses being generated Kamal Mostafa
2014-04-22 20:12 ` [PATCH 3.8 010/133] ipv6: ip6_append_data_mtu do not handle the mtu of the second fragment properly Kamal Mostafa
2014-04-22 20:12 ` [PATCH 3.8 011/133] vxlan: fix potential NULL dereference in arp_reduce() Kamal Mostafa
2014-04-22 20:12 ` [PATCH 3.8 012/133] rtnetlink: fix fdb notification flags Kamal Mostafa
2014-04-22 20:12 ` [PATCH 3.8 013/133] ipmr: fix mfc " Kamal Mostafa
2014-04-22 20:12 ` [PATCH 3.8 014/133] ip6mr: " Kamal Mostafa
2014-04-22 20:12 ` [PATCH 3.8 015/133] usbnet: include wait queue head in device structure Kamal Mostafa
2014-04-22 20:12 ` [PATCH 3.8 016/133] vhost: fix total length when packets are too short Kamal Mostafa
2014-04-22 20:12 ` [PATCH 3.8 017/133] vhost: validate vhost_get_vq_desc return value Kamal Mostafa
2014-04-22 20:12 ` [PATCH 3.8 018/133] xen-netback: remove pointless clause from if statement Kamal Mostafa
2014-04-22 20:12 ` [PATCH 3.8 019/133] ipv6: some ipv6 statistic counters failed to disable bh Kamal Mostafa
2014-04-22 20:12 ` [PATCH 3.8 020/133] netlink: don't compare the nul-termination in nla_strcmp Kamal Mostafa
2014-04-22 20:12 ` [PATCH 3.8 021/133] isdnloop: Validate NUL-terminated strings from user Kamal Mostafa
2014-04-22 20:12 ` [PATCH 3.8 022/133] isdnloop: several buffer overflows Kamal Mostafa
2014-04-22 20:12 ` [PATCH 3.8 023/133] rds: prevent dereference of a NULL device in rds_iw_laddr_check Kamal Mostafa
2014-04-22 20:12 ` [PATCH 3.8 024/133] sparc: PCI: Fix incorrect address calculation of PCI Bridge windows on Simba-bridges Kamal Mostafa
2014-04-22 20:12 ` [PATCH 3.8 025/133] Revert "sparc64: Fix __copy_{to,from}_user_inatomic defines." Kamal Mostafa
2014-04-22 20:12 ` [PATCH 3.8 026/133] sparc32: fix build failure for arch_jump_label_transform Kamal Mostafa
2014-04-22 20:12 ` [PATCH 3.8 027/133] sparc64: don't treat 64-bit syscall return codes as 32-bit Kamal Mostafa
2014-04-22 20:12 ` [PATCH 3.8 028/133] drm/i915: quirk invert brightness for Acer Aspire 5336 Kamal Mostafa
2014-04-22 20:12 ` [PATCH 3.8 029/133] w1: fix w1_send_slave dropping a slave id Kamal Mostafa
2014-04-22 20:12 ` [PATCH 3.8 030/133] ARM: 7954/1: mm: remove remaining domain support from ARMv6 Kamal Mostafa
2014-04-22 20:12 ` [PATCH 3.8 031/133] matroxfb: restore the registers M_ACCESS and M_PITCH Kamal Mostafa
2014-04-22 20:12 ` Kamal Mostafa [this message]
2014-04-22 20:12 ` [PATCH 3.8 033/133] mach64: use unaligned access Kamal Mostafa
2014-04-22 20:12 ` [PATCH 3.8 034/133] mach64: fix cursor when character width is not a multiple of 8 pixels Kamal Mostafa
2014-04-22 20:12 ` [PATCH 3.8 035/133] tgafb: fix mode setting with fbset Kamal Mostafa
2014-04-22 20:12 ` [PATCH 3.8 036/133] tgafb: fix data copying Kamal Mostafa
2014-04-22 20:12 ` [PATCH 3.8 037/133] hvc: ensure hvc_init is only ever called once in hvc_console.c Kamal Mostafa
2014-04-22 20:12 ` [PATCH 3.8 038/133] usb: dwc3: fix wrong bit mask in dwc3_event_devt Kamal Mostafa
2014-04-22 20:12 ` [PATCH 3.8 039/133] x86, AVX-512: AVX-512 Feature Detection Kamal Mostafa
2014-04-22 20:12 ` [PATCH 3.8 040/133] [media] media: gspca: sn9c20x: add ID for Genius Look 1320 V2 Kamal Mostafa
2014-04-22 20:12 ` [PATCH 3.8 041/133] [media] m88rs2000: add caps FE_CAN_INVERSION_AUTO Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 042/133] [media] m88rs2000: prevent frontend crash on continuous transponder scans Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 043/133] tty: Set correct tty name in 'active' sysfs attribute Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 044/133] Bluetooth: Fix removing Long Term Key Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 045/133] [media] uvcvideo: Do not use usb_set_interface on bulk EP Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 046/133] usb: gadget: atmel_usba: fix crashed during stopping when DEBUG is enabled Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 047/133] blktrace: fix accounting of partially completed requests Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 048/133] rtlwifi: rtl8192cu: Fix too long disable of IRQs Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 049/133] rtlwifi: rtl8192se: " Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 050/133] rtlwifi: rtl8723ae: " Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 051/133] xhci: Prevent runtime pm from autosuspending during initialization Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 052/133] staging:serqt_usb2: Fix sparse warning restricted __le16 degrades to integer Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 053/133] Btrfs: skip submitting barrier for missing device Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 054/133] jffs2: remove from wait queue after schedule() Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 055/133] jffs2: avoid soft-lockup in jffs2_reserve_space_gc() Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 056/133] jffs2: Fix segmentation fault found in stress test Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 057/133] jffs2: Fix crash due to truncation of csize Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 058/133] mtd: atmel_nand: Disable subpage NAND write when using Atmel PMECC Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 059/133] iwlwifi: dvm: take mutex when sending SYNC BT config command Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 060/133] virtio_balloon: don't softlockup on huge balloon changes Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 061/133] arm64: Use Normal NonCacheable memory for writecombine Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 062/133] arm64: Make DMA coherent and strongly ordered mappings not executable Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 063/133] arm64: Do not synchronise I and D caches for special ptes Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 064/133] ARM: OMAP2+: INTC: Acknowledge stuck active interrupts Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 065/133] mtip32xx: Set queue bounce limit Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 066/133] mtip32xx: Unmap the DMA segments before completing the IO request Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 067/133] ath9k: fix ready time of the multicast buffer queue Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 068/133] [SCSI] fix our current target reap infrastructure Kamal Mostafa
2014-04-25  2:03   ` Ben Hutchings
2014-04-27 19:46     ` Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 069/133] [SCSI] dual scan thread bug fix Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 070/133] usb: gadget: tcm_usb_gadget: stop format strings Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 071/133] USB: unbind all interfaces before rebinding any Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 072/133] IB/ipath: Fix potential buffer overrun in sending diag packet routine Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 073/133] IB/nes: Return an error on ib_copy_from_udata() failure instead of NULL Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 074/133] mfd: sec-core: Fix possible NULL pointer dereference when i2c_new_dummy error Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 075/133] regulator: arizona-ldo1: Correct default regulator init_data Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 076/133] ASoC: cs42l73: Fix mask bits for SOC_VALUE_ENUM_SINGLE Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 077/133] ASoC: cs42l52: " Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 078/133] mfd: Include all drivers in subsystem menu Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 079/133] mfd: max8997: Fix possible NULL pointer dereference on i2c_new_dummy error Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 080/133] mfd: max77686: " Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 081/133] mfd: max8998: " Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 082/133] mfd: max8925: " Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 083/133] mfd: 88pm860x: Fix I2C device resource leak on regmap init fail Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 084/133] mfd: 88pm860x: Fix possible NULL pointer dereference on i2c_new_dummy error Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 085/133] mfd: max77693: " Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 086/133] mfd: tps65910: Fix possible invalid pointer dereference on regmap_add_irq_chip fail Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 087/133] ASoC: cs42l51: Fix SOC_DOUBLE_R_SX_TLV shift values for ADC, PCM, and Analog kcontrols Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 088/133] pid: get pid_t ppid of task in init_pid_ns Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 089/133] audit: convert PPIDs to the inital PID namespace Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 090/133] Btrfs: fix deadlock with nested trans handles Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 091/133] gpio: mxs: Allow for recursive enable_irq_wake() call Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 092/133] x86, hyperv: Bypass the timer_irq_works() check Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 093/133] nfsd4: buffer-length check for SUPPATTR_EXCLCREAT Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 094/133] nfsd4: session needs room for following op to error out Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 095/133] nfsd4: leave reply buffer space for failed setattr Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 096/133] nfsd4: fix test_stateid error reply encoding Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 097/133] nfsd: notify_change needs elevated write count Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 098/133] dm transaction manager: fix corruption due to non-atomic transaction commit Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 099/133] dm: take care to copy the space map roots before locking the superblock Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 100/133] NFSD: Traverse unconfirmed client through hash-table Kamal Mostafa
2014-04-22 20:13 ` [PATCH 3.8 101/133] lockd: ensure we tear down any live sockets when socket creation fails during lockd_up Kamal Mostafa
2014-04-22 20:14 ` [PATCH 3.8 102/133] drm/i915/tv: fix gen4 composite s-video tv-out Kamal Mostafa
2014-04-22 20:14 ` [PATCH 3.8 103/133] dm thin: fix dangling bio in process_deferred_bios error path Kamal Mostafa
2014-04-22 20:14 ` [PATCH 3.8 104/133] NFSv4: Fix a use-after-free problem in open() Kamal Mostafa
2014-04-22 20:14 ` [PATCH 3.8 105/133] nfsd4: fix setclientid encode size Kamal Mostafa
2014-04-22 20:14 ` [PATCH 3.8 106/133] MIPS: Hibernate: Flush TLB entries in swsusp_arch_resume() Kamal Mostafa
2014-04-22 20:14 ` [PATCH 3.8 107/133] ALSA: hda - Enable beep for ASUS 1015E Kamal Mostafa
2014-04-22 20:14 ` [PATCH 3.8 108/133] x86: Adjust irq remapping quirk for older revisions of 5500/5520 chipsets Kamal Mostafa
2014-04-22 20:14 ` [PATCH 3.8 109/133] nfsd: check passed socket's net matches NFSd superblock's one Kamal Mostafa
2014-04-22 20:14 ` [PATCH 3.8 110/133] nfsd4: fix memory leak in nfsd4_encode_fattr() Kamal Mostafa
2014-04-23 10:56   ` Luis Henriques
2014-04-23 16:35     ` Kamal Mostafa
2014-04-22 20:14 ` [PATCH 3.8 111/133] IB/mthca: Return an error on ib_copy_to_udata() failure Kamal Mostafa
2014-04-22 20:14 ` [PATCH 3.8 112/133] IB/ehca: Returns " Kamal Mostafa
2014-04-22 20:14 ` [PATCH 3.8 113/133] don't bother with {get,put}_write_access() on non-regular files Kamal Mostafa
2014-04-22 20:14 ` [PATCH 3.8 114/133] reiserfs: fix race in readdir Kamal Mostafa
2014-04-22 20:14 ` [PATCH 3.8 115/133] pid_namespace: pidns_get() should check task_active_pid_ns() != NULL Kamal Mostafa
2014-04-22 20:14 ` [PATCH 3.8 116/133] drm/vmwgfx: correct fb_fix_screeninfo.line_length Kamal Mostafa
2014-04-22 20:14 ` [PATCH 3.8 117/133] drm/radeon: call drm_edid_to_eld when we update the edid Kamal Mostafa
2014-04-22 20:14 ` [PATCH 3.8 118/133] sh: fix format string bug in stack tracer Kamal Mostafa
2014-04-22 20:14 ` [PATCH 3.8 119/133] ocfs2: dlm: fix lock migration crash Kamal Mostafa
2014-04-22 20:14 ` [PATCH 3.8 120/133] ocfs2: dlm: fix recovery hung Kamal Mostafa
2014-04-22 20:14 ` [PATCH 3.8 121/133] ocfs2: do not put bh when buffer_uptodate failed Kamal Mostafa
2014-04-22 20:14 ` [PATCH 3.8 122/133] Skip intel_crt_init for Dell XPS 8700 Kamal Mostafa
2014-04-22 20:14 ` [PATCH 3.8 123/133] iscsi-target: Fix ERL=2 ASYNC_EVENT connection pointer bug Kamal Mostafa
2014-04-22 20:14 ` [PATCH 3.8 124/133] mm: try_to_unmap_cluster() should lock_page() before mlocking Kamal Mostafa
2014-04-22 20:14 ` [PATCH 3.8 125/133] mm: hugetlb: fix softlockup when a large number of hugepages are freed Kamal Mostafa
2014-04-22 20:14 ` [PATCH 3.8 126/133] wait: fix reparent_leader() vs EXIT_DEAD->EXIT_ZOMBIE race Kamal Mostafa
2014-04-22 20:14 ` [PATCH 3.8 127/133] hung_task: check the value of "sysctl_hung_task_timeout_sec" Kamal Mostafa
2014-04-22 20:14 ` [PATCH 3.8 128/133] ALSA: ice1712: Fix boundary checks in PCM pointer ops Kamal Mostafa
2014-04-22 20:14 ` [PATCH 3.8 129/133] lib/percpu_counter.c: fix bad percpu counter state during suspend Kamal Mostafa
2014-04-22 20:14 ` [PATCH 3.8 130/133] b43: Fix machine check error due to improper access of B43_MMIO_PSM_PHY_HDR Kamal Mostafa
2014-04-22 20:14 ` [PATCH 3.8 131/133] x86-64, modify_ldt: Ban 16-bit segments on 64-bit kernels Kamal Mostafa
2014-04-22 20:14 ` [PATCH 3.8 132/133] target/tcm_fc: Fix use-after-free of ft_tpg Kamal Mostafa
2014-04-22 20:14 ` [PATCH 3.8 133/133] ib_srpt: Use correct ib_sg_dma primitives Kamal Mostafa

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1398197671-12786-33-git-send-email-kamal@canonical.com \
    --to=kamal@canonical.com \
    --cc=kernel-team@lists.ubuntu.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mpatocka@redhat.com \
    --cc=stable@vger.kernel.org \
    --cc=tomi.valkeinen@ti.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox