Changes in 4.9.208 btrfs: skip log replay on orphaned roots btrfs: do not leak reloc root if we fail to read the fs root btrfs: handle ENOENT in btrfs_uuid_tree_iterate ALSA: pcm: Avoid possible info leaks from PCM stream buffers ALSA: hda/ca0132 - Keep power on during processing DSP response ALSA: hda/ca0132 - Avoid endless loop drm: mst: Fix query_payload ack reply struct drm/bridge: analogix-anx78xx: silence -EPROBE_DEFER warnings iio: light: bh1750: Resolve compiler warning and make code more readable spi: Add call to spi_slave_abort() function when spidev driver is released staging: rtl8192u: fix multiple memory leaks on error path staging: rtl8188eu: fix possible null dereference rtlwifi: prevent memory leak in rtl_usb_probe libertas: fix a potential NULL pointer dereference IB/iser: bound protection_sg size by data_sg size media: am437x-vpfe: Setting STD to current value is not an error media: i2c: ov2659: fix s_stream return value media: i2c: ov2659: Fix missing 720p register config media: ov6650: Fix stored frame format not in sync with hardware tools/power/cpupower: Fix initializer override in hsw_ext_cstates usb: renesas_usbhs: add suspend event support in gadget mode hwrng: omap3-rom - Call clk_disable_unprepare() on exit only if not idled regulator: max8907: Fix the usage of uninitialized variable in max8907_regulator_probe() media: flexcop-usb: fix NULL-ptr deref in flexcop_usb_transfer_init() media: cec-funcs.h: add status_req checks samples: pktgen: fix proc_cmd command result check logic mwifiex: pcie: Fix memory leak in mwifiex_pcie_init_evt_ring media: ti-vpe: vpe: fix a v4l2-compliance warning about invalid pixel format media: ti-vpe: vpe: fix a v4l2-compliance failure about frame sequence number media: ti-vpe: vpe: Make sure YUYV is set as default format extcon: sm5502: Reset registers during initialization x86/mm: Use the correct function type for native_set_fixmap() perf test: Report failure for mmap events perf report: Add warning when libunwind not compiled in usb: usbfs: Suppress problematic bind and unbind uevents. iio: adc: max1027: Reset the device at probe time Bluetooth: hci_core: fix init for HCI_USER_CHANNEL x86/mce: Lower throttling MCE messages' priority to warning drm/gma500: fix memory disclosures due to uninitialized bytes rtl8xxxu: fix RTL8723BU connection failure issue after warm reboot x86/ioapic: Prevent inconsistent state when moving an interrupt arm64: psci: Reduce the waiting time for cpu_psci_cpu_kill() libata: Ensure ata_port probe has completed before detach pinctrl: sh-pfc: sh7734: Fix duplicate TCLK1_B Bluetooth: Fix advertising duplicated flags bnx2x: Fix PF-VF communication over multi-cos queues. spi: img-spfi: fix potential double release ALSA: timer: Limit max amount of slave instances rtlwifi: fix memory leak in rtl92c_set_fw_rsvdpagepkt() perf probe: Fix to find range-only function instance perf probe: Fix to list probe event with correct line number perf probe: Walk function lines in lexical blocks perf probe: Fix to probe an inline function which has no entry pc perf probe: Fix to show ranges of variables in functions without entry_pc perf probe: Fix to show inlined function callsite without entry_pc perf probe: Fix to probe a function which has no entry pc perf probe: Skip overlapped location on searching variables perf probe: Return a better scope DIE if there is no best scope perf probe: Fix to show calling lines of inlined functions perf probe: Skip end-of-sequence and non statement lines perf probe: Filter out instances except for inlined subroutine and subprogram ath10k: fix get invalid tx rate for Mesh metric media: pvrusb2: Fix oops on tear-down when radio support is not present media: si470x-i2c: add missed operations in remove EDAC/ghes: Fix grain calculation spi: pxa2xx: Add missed security checks ASoC: rt5677: Mark reg RT5677_PWR_ANLG2 as volatile s390/disassembler: don't hide instruction addresses parport: load lowlevel driver if ports not found cpufreq: Register drivers only after CPU devices have been registered x86/crash: Add a forward declaration of struct kimage iwlwifi: mvm: fix unaligned read of rx_pkt_status spi: tegra20-slink: add missed clk_unprepare mmc: tmio: Add MMC_CAP_ERASE to allow erase/discard/trim requests btrfs: don't prematurely free work in end_workqueue_fn() btrfs: don't prematurely free work in run_ordered_work() spi: st-ssc4: add missed pm_runtime_disable x86/insn: Add some Intel instructions to the opcode map iwlwifi: check kasprintf() return value fbtft: Make sure string is NULL terminated crypto: sun4i-ss - Fix 64-bit size_t warnings on sun4i-ss-hash.c crypto: vmx - Avoid weird build failures libtraceevent: Fix memory leakage in copy_filter_type net: phy: initialise phydev speed and duplex sanely btrfs: don't prematurely free work in reada_start_machine_worker() Revert "mmc: sdhci: Fix incorrect switch to HS mode" usb: xhci: Fix build warning seen with CONFIG_PM=n btrfs: don't double lock the subvol_sem for rename exchange btrfs: do not call synchronize_srcu() in inode_tree_del btrfs: return error pointer from alloc_test_extent_buffer btrfs: abort transaction after failed inode updates in create_subvol Btrfs: fix removal logic of the tree mod log that leads to use-after-free issues af_packet: set defaule value for tmo fjes: fix missed check in fjes_acpi_add mod_devicetable: fix PHY module format net: hisilicon: Fix a BUG trigered by wrong bytes_compl net: nfc: nci: fix a possible sleep-in-atomic-context bug in nci_uart_tty_receive() net: qlogic: Fix error paths in ql_alloc_large_buffers() net: usb: lan78xx: Fix suspend/resume PHY register access error sctp: fully initialize v4 addr in some functions net: dst: Force 4-byte alignment of dst_metrics usbip: Fix error path of vhci_recv_ret_submit() USB: EHCI: Do not return -EPIPE when hub is disconnected platform/x86: hp-wmi: Make buffer for HPWMI_FEATURE2_QUERY 128 bytes staging: comedi: gsc_hpdi: check dma_alloc_coherent() return value ext4: fix ext4_empty_dir() for directories with holes ext4: check for directory entries too close to block end powerpc/irq: fix stack overflow verification mmc: sdhci-of-esdhc: fix P2020 errata handling perf probe: Fix to show function entry line as probe-able scsi: mpt3sas: Fix clear pending bit in ioctl status scsi: lpfc: Fix locking on mailbox command completion Input: atmel_mxt_ts - disable IRQ across suspend iommu/tegra-smmu: Fix page tables in > 4 GiB memory scsi: target: compare full CHAP_A Algorithm strings scsi: lpfc: Fix SLI3 hba in loop mode not discovering devices scsi: csiostor: Don't enable IRQs too early powerpc/pseries: Mark accumulate_stolen_time() as notrace powerpc/pseries: Don't fail hash page table insert for bolted mapping dma-debug: add a schedule point in debug_dma_dump_mappings() clocksource/drivers/asm9260: Add a check for of_clk_get powerpc/security/book3s64: Report L1TF status in sysfs powerpc/book3s64/hash: Add cond_resched to avoid soft lockup warning jbd2: Fix statistics for the number of logged blocks scsi: tracing: Fix handling of TRANSFER LENGTH == 0 for READ(6) and WRITE(6) scsi: lpfc: Fix duplicate unreg_rpi error in port offline flow clk: qcom: Allow constant ratio freq tables for rcg irqchip/irq-bcm7038-l1: Enable parent IRQ if necessary irqchip: ingenic: Error out if IRQ domain creation failed fs/quota: handle overflows of sysctl fs.quota.* and report as unsigned long scsi: lpfc: fix: Coverity: lpfc_cmpl_els_rsp(): Null pointer dereferences scsi: ufs: fix potential bug which ends in system hang powerpc/pseries/cmm: Implement release() function for sysfs device powerpc/security: Fix wrong message when RFI Flush is disable scsi: atari_scsi: sun3_scsi: Set sg_tablesize to 1 instead of SG_NONE clk: pxa: fix one of the pxa RTC clocks bcache: at least try to shrink 1 node in bch_mca_scan() HID: Improve Windows Precision Touchpad detection. ext4: work around deleting a file with i_nlink == 0 safely scsi: pm80xx: Fix for SATA device discovery scsi: scsi_debug: num_tgts must be >= 0 scsi: target: iscsi: Wait for all commands to finish before freeing a session gpio: mpc8xxx: Don't overwrite default irq_set_type callback scripts/kallsyms: fix definitely-lost memory leak cdrom: respect device capabilities during opening action perf regs: Make perf_reg_name() return "unknown" instead of NULL libfdt: define INT32_MAX and UINT32_MAX in libfdt_env.h s390/cpum_sf: Check for SDBT and SDB consistency ocfs2: fix passing zero to 'PTR_ERR' warning kernel: sysctl: make drop_caches write-only x86/mce: Fix possibly incorrect severity calculation on AMD net, sysctl: Fix compiler warning when only cBPF is present ALSA: hda - Downgrade error message for single-cmd fallback perf strbuf: Remove redundant va_end() in strbuf_addv() Make filldir[64]() verify the directory entry filename is valid filldir[64]: remove WARN_ON_ONCE() for bad directory entries netfilter: ebtables: compat: reject all padding in matches/watchers 6pack,mkiss: fix possible deadlock netfilter: bridge: make sure to pull arp header in br_nf_forward_arp() net: icmp: fix data-race in cmp_global_allow() hrtimer: Annotate lockless access to timer->state tty/serial: atmel: fix out of range clock divider handling pinctrl: baytrail: Really serialize all register accesses mmc: sdhci: Update the tuning failed messages to pr_debug level net: ena: fix napi handler misbehavior when the napi budget is zero vhost/vsock: accept only packets with the right dst_cid tcp/dccp: fix possible race __inet_lookup_established() tcp: do not send empty skb from tcp_write_xmit() gtp: fix wrong condition in gtp_genl_dump_pdp() gtp: avoid zero size hashtable Linux 4.9.208 Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
278 lines
6.6 KiB
C
278 lines
6.6 KiB
C
/*
|
|
* Copyright (C) 2003-2008 Takahiro Hirofuchi
|
|
*
|
|
* This is free software; you can redistribute it and/or modify
|
|
* it under the terms of the GNU General Public License as published by
|
|
* the Free Software Foundation; either version 2 of the License, or
|
|
* (at your option) any later version.
|
|
*
|
|
* This is distributed in the hope that it will be useful,
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
* GNU General Public License for more details.
|
|
*
|
|
* You should have received a copy of the GNU General Public License
|
|
* along with this program; if not, write to the Free Software
|
|
* Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307,
|
|
* USA.
|
|
*/
|
|
|
|
#include <linux/kthread.h>
|
|
#include <linux/slab.h>
|
|
|
|
#include "usbip_common.h"
|
|
#include "vhci.h"
|
|
|
|
/* get URB from transmitted urb queue. caller must hold vdev->priv_lock */
|
|
struct urb *pickup_urb_and_free_priv(struct vhci_device *vdev, __u32 seqnum)
|
|
{
|
|
struct vhci_priv *priv, *tmp;
|
|
struct urb *urb = NULL;
|
|
int status;
|
|
|
|
list_for_each_entry_safe(priv, tmp, &vdev->priv_rx, list) {
|
|
if (priv->seqnum != seqnum)
|
|
continue;
|
|
|
|
urb = priv->urb;
|
|
status = urb->status;
|
|
|
|
usbip_dbg_vhci_rx("find urb seqnum %u\n", seqnum);
|
|
|
|
switch (status) {
|
|
case -ENOENT:
|
|
/* fall through */
|
|
case -ECONNRESET:
|
|
dev_dbg(&urb->dev->dev,
|
|
"urb seq# %u was unlinked %ssynchronuously\n",
|
|
seqnum, status == -ENOENT ? "" : "a");
|
|
break;
|
|
case -EINPROGRESS:
|
|
/* no info output */
|
|
break;
|
|
default:
|
|
dev_dbg(&urb->dev->dev,
|
|
"urb seq# %u may be in a error, status %d\n",
|
|
seqnum, status);
|
|
}
|
|
|
|
list_del(&priv->list);
|
|
kfree(priv);
|
|
urb->hcpriv = NULL;
|
|
|
|
break;
|
|
}
|
|
|
|
return urb;
|
|
}
|
|
|
|
static void vhci_recv_ret_submit(struct vhci_device *vdev,
|
|
struct usbip_header *pdu)
|
|
{
|
|
struct vhci_hcd *vhci = vdev_to_vhci(vdev);
|
|
struct usbip_device *ud = &vdev->ud;
|
|
struct urb *urb;
|
|
unsigned long flags;
|
|
|
|
spin_lock_irqsave(&vdev->priv_lock, flags);
|
|
urb = pickup_urb_and_free_priv(vdev, pdu->base.seqnum);
|
|
spin_unlock_irqrestore(&vdev->priv_lock, flags);
|
|
|
|
if (!urb) {
|
|
pr_err("cannot find a urb of seqnum %u max seqnum %d\n",
|
|
pdu->base.seqnum,
|
|
atomic_read(&vhci->seqnum));
|
|
usbip_event_add(ud, VDEV_EVENT_ERROR_TCP);
|
|
return;
|
|
}
|
|
|
|
/* unpack the pdu to a urb */
|
|
usbip_pack_pdu(pdu, urb, USBIP_RET_SUBMIT, 0);
|
|
|
|
/* recv transfer buffer */
|
|
if (usbip_recv_xbuff(ud, urb) < 0) {
|
|
urb->status = -EPROTO;
|
|
goto error;
|
|
}
|
|
|
|
/* recv iso_packet_descriptor */
|
|
if (usbip_recv_iso(ud, urb) < 0) {
|
|
urb->status = -EPROTO;
|
|
goto error;
|
|
}
|
|
|
|
/* restore the padding in iso packets */
|
|
usbip_pad_iso(ud, urb);
|
|
|
|
error:
|
|
if (usbip_dbg_flag_vhci_rx)
|
|
usbip_dump_urb(urb);
|
|
|
|
usbip_dbg_vhci_rx("now giveback urb %u\n", pdu->base.seqnum);
|
|
|
|
spin_lock_irqsave(&vhci->lock, flags);
|
|
usb_hcd_unlink_urb_from_ep(vhci_to_hcd(vhci), urb);
|
|
spin_unlock_irqrestore(&vhci->lock, flags);
|
|
|
|
usb_hcd_giveback_urb(vhci_to_hcd(vhci), urb, urb->status);
|
|
|
|
usbip_dbg_vhci_rx("Leave\n");
|
|
}
|
|
|
|
static struct vhci_unlink *dequeue_pending_unlink(struct vhci_device *vdev,
|
|
struct usbip_header *pdu)
|
|
{
|
|
struct vhci_unlink *unlink, *tmp;
|
|
unsigned long flags;
|
|
|
|
spin_lock_irqsave(&vdev->priv_lock, flags);
|
|
|
|
list_for_each_entry_safe(unlink, tmp, &vdev->unlink_rx, list) {
|
|
pr_info("unlink->seqnum %lu\n", unlink->seqnum);
|
|
if (unlink->seqnum == pdu->base.seqnum) {
|
|
usbip_dbg_vhci_rx("found pending unlink, %lu\n",
|
|
unlink->seqnum);
|
|
list_del(&unlink->list);
|
|
|
|
spin_unlock_irqrestore(&vdev->priv_lock, flags);
|
|
return unlink;
|
|
}
|
|
}
|
|
|
|
spin_unlock_irqrestore(&vdev->priv_lock, flags);
|
|
|
|
return NULL;
|
|
}
|
|
|
|
static void vhci_recv_ret_unlink(struct vhci_device *vdev,
|
|
struct usbip_header *pdu)
|
|
{
|
|
struct vhci_hcd *vhci = vdev_to_vhci(vdev);
|
|
struct vhci_unlink *unlink;
|
|
struct urb *urb;
|
|
unsigned long flags;
|
|
|
|
usbip_dump_header(pdu);
|
|
|
|
unlink = dequeue_pending_unlink(vdev, pdu);
|
|
if (!unlink) {
|
|
pr_info("cannot find the pending unlink %u\n",
|
|
pdu->base.seqnum);
|
|
return;
|
|
}
|
|
|
|
spin_lock_irqsave(&vdev->priv_lock, flags);
|
|
urb = pickup_urb_and_free_priv(vdev, unlink->unlink_seqnum);
|
|
spin_unlock_irqrestore(&vdev->priv_lock, flags);
|
|
|
|
if (!urb) {
|
|
/*
|
|
* I get the result of a unlink request. But, it seems that I
|
|
* already received the result of its submit result and gave
|
|
* back the URB.
|
|
*/
|
|
pr_info("the urb (seqnum %d) was already given back\n",
|
|
pdu->base.seqnum);
|
|
} else {
|
|
usbip_dbg_vhci_rx("now giveback urb %d\n", pdu->base.seqnum);
|
|
|
|
/* If unlink is successful, status is -ECONNRESET */
|
|
urb->status = pdu->u.ret_unlink.status;
|
|
pr_info("urb->status %d\n", urb->status);
|
|
|
|
spin_lock_irqsave(&vhci->lock, flags);
|
|
usb_hcd_unlink_urb_from_ep(vhci_to_hcd(vhci), urb);
|
|
spin_unlock_irqrestore(&vhci->lock, flags);
|
|
|
|
usb_hcd_giveback_urb(vhci_to_hcd(vhci), urb, urb->status);
|
|
}
|
|
|
|
kfree(unlink);
|
|
}
|
|
|
|
static int vhci_priv_tx_empty(struct vhci_device *vdev)
|
|
{
|
|
int empty = 0;
|
|
unsigned long flags;
|
|
|
|
spin_lock_irqsave(&vdev->priv_lock, flags);
|
|
empty = list_empty(&vdev->priv_rx);
|
|
spin_unlock_irqrestore(&vdev->priv_lock, flags);
|
|
|
|
return empty;
|
|
}
|
|
|
|
/* recv a pdu */
|
|
static void vhci_rx_pdu(struct usbip_device *ud)
|
|
{
|
|
int ret;
|
|
struct usbip_header pdu;
|
|
struct vhci_device *vdev = container_of(ud, struct vhci_device, ud);
|
|
|
|
usbip_dbg_vhci_rx("Enter\n");
|
|
|
|
memset(&pdu, 0, sizeof(pdu));
|
|
|
|
/* receive a pdu header */
|
|
ret = usbip_recv(ud->tcp_socket, &pdu, sizeof(pdu));
|
|
if (ret < 0) {
|
|
if (ret == -ECONNRESET)
|
|
pr_info("connection reset by peer\n");
|
|
else if (ret == -EAGAIN) {
|
|
/* ignore if connection was idle */
|
|
if (vhci_priv_tx_empty(vdev))
|
|
return;
|
|
pr_info("connection timed out with pending urbs\n");
|
|
} else if (ret != -ERESTARTSYS)
|
|
pr_info("xmit failed %d\n", ret);
|
|
|
|
usbip_event_add(ud, VDEV_EVENT_ERROR_TCP);
|
|
return;
|
|
}
|
|
if (ret == 0) {
|
|
pr_info("connection closed");
|
|
usbip_event_add(ud, VDEV_EVENT_DOWN);
|
|
return;
|
|
}
|
|
if (ret != sizeof(pdu)) {
|
|
pr_err("received pdu size is %d, should be %d\n", ret,
|
|
(unsigned int)sizeof(pdu));
|
|
usbip_event_add(ud, VDEV_EVENT_ERROR_TCP);
|
|
return;
|
|
}
|
|
|
|
usbip_header_correct_endian(&pdu, 0);
|
|
|
|
if (usbip_dbg_flag_vhci_rx)
|
|
usbip_dump_header(&pdu);
|
|
|
|
switch (pdu.base.command) {
|
|
case USBIP_RET_SUBMIT:
|
|
vhci_recv_ret_submit(vdev, &pdu);
|
|
break;
|
|
case USBIP_RET_UNLINK:
|
|
vhci_recv_ret_unlink(vdev, &pdu);
|
|
break;
|
|
default:
|
|
/* NOT REACHED */
|
|
pr_err("unknown pdu %u\n", pdu.base.command);
|
|
usbip_dump_header(&pdu);
|
|
usbip_event_add(ud, VDEV_EVENT_ERROR_TCP);
|
|
break;
|
|
}
|
|
}
|
|
|
|
int vhci_rx_loop(void *data)
|
|
{
|
|
struct usbip_device *ud = data;
|
|
|
|
while (!kthread_should_stop()) {
|
|
if (usbip_event_happened(ud))
|
|
break;
|
|
|
|
vhci_rx_pdu(ud);
|
|
}
|
|
|
|
return 0;
|
|
}
|