diff --git a/kernel/kernel/files/configs/kernel-x86_64-config b/kernel/kernel/files/configs/kernel-x86_64-config index 13f209a1..b3d3edeb 100644 --- a/kernel/kernel/files/configs/kernel-x86_64-config +++ b/kernel/kernel/files/configs/kernel-x86_64-config @@ -173,7 +173,7 @@ CONFIG_CGROUP_WRITEBACK=y CONFIG_NAMESPACES=y CONFIG_UTS_NS=y CONFIG_IPC_NS=y -# CONFIG_USER_NS is not set +CONFIG_USER_NS=y CONFIG_PID_NS=y CONFIG_NET_NS=y CONFIG_SCHED_AUTOGROUP=y @@ -644,16 +644,16 @@ CONFIG_CPU_FREQ=y CONFIG_CPU_FREQ_GOV_COMMON=y CONFIG_CPU_FREQ_STAT=m CONFIG_CPU_FREQ_STAT_DETAILS=y -# CONFIG_CPU_FREQ_DEFAULT_GOV_PERFORMANCE is not set +CONFIG_CPU_FREQ_DEFAULT_GOV_PERFORMANCE=y # CONFIG_CPU_FREQ_DEFAULT_GOV_POWERSAVE is not set # CONFIG_CPU_FREQ_DEFAULT_GOV_USERSPACE is not set -CONFIG_CPU_FREQ_DEFAULT_GOV_ONDEMAND=y +# CONFIG_CPU_FREQ_DEFAULT_GOV_ONDEMAND is not set # CONFIG_CPU_FREQ_DEFAULT_GOV_CONSERVATIVE is not set CONFIG_CPU_FREQ_GOV_PERFORMANCE=y -CONFIG_CPU_FREQ_GOV_POWERSAVE=y +CONFIG_CPU_FREQ_GOV_POWERSAVE=m CONFIG_CPU_FREQ_GOV_USERSPACE=y -CONFIG_CPU_FREQ_GOV_ONDEMAND=y -CONFIG_CPU_FREQ_GOV_CONSERVATIVE=y +CONFIG_CPU_FREQ_GOV_ONDEMAND=m +CONFIG_CPU_FREQ_GOV_CONSERVATIVE=m # # CPU frequency scaling drivers @@ -1365,7 +1365,7 @@ CONFIG_HSR=m CONFIG_RPS=y CONFIG_RFS_ACCEL=y CONFIG_XPS=y -# CONFIG_CGROUP_NET_PRIO is not set +CONFIG_CGROUP_NET_PRIO=y CONFIG_CGROUP_NET_CLASSID=y CONFIG_NET_RX_BUSY_POLL=y CONFIG_BQL=y @@ -5806,7 +5806,8 @@ CONFIG_EXT2_FS_XATTR=y # CONFIG_EXT2_FS_POSIX_ACL is not set CONFIG_EXT2_FS_SECURITY=y CONFIG_EXT3_FS=m -# CONFIG_EXT3_FS_POSIX_ACL is not set +CONFIG_EXT3_FS_POSIX_ACL=y +CONFIG_EXT3_FS_XATTR=y CONFIG_EXT3_FS_SECURITY=y CONFIG_EXT4_FS=y CONFIG_EXT4_FS_POSIX_ACL=y diff --git a/kernel/kernel/files/patches/linux/patch-4.4.1.xz b/kernel/kernel/files/patches/linux/patch-4.4.1.xz new file mode 100644 index 00000000..7a414d5b Binary files /dev/null and b/kernel/kernel/files/patches/linux/patch-4.4.1.xz differ diff --git a/kernel/kernel/files/patches/mageia/fs-ovl-allow-zero-size-xattr.patch b/kernel/kernel/files/patches/mageia/fs-ovl-allow-zero-size-xattr.patch new file mode 100644 index 00000000..e506728f --- /dev/null +++ b/kernel/kernel/files/patches/mageia/fs-ovl-allow-zero-size-xattr.patch @@ -0,0 +1,31 @@ +From 97daf8b97ad6f913a34c82515be64dc9ac08d63e Mon Sep 17 00:00:00 2001 +From: Miklos Szeredi +Date: Tue, 10 Nov 2015 17:08:41 +0100 +Subject: [PATCH 1/6] ovl: allow zero size xattr + +When ovl_copy_xattr() encountered a zero size xattr no more xattrs were +copied and the function returned success. This is clearly not the desired +behavior. + +Signed-off-by: Miklos Szeredi +Cc: +--- + fs/overlayfs/copy_up.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/fs/overlayfs/copy_up.c b/fs/overlayfs/copy_up.c +index 871fcb6..394e87f 100644 +--- a/fs/overlayfs/copy_up.c ++++ b/fs/overlayfs/copy_up.c +@@ -54,7 +54,7 @@ int ovl_copy_xattr(struct dentry *old, struct dentry *new) + + for (name = buf; name < (buf + list_size); name += strlen(name) + 1) { + size = vfs_getxattr(old, name, value, XATTR_SIZE_MAX); +- if (size <= 0) { ++ if (size < 0) { + error = size; + goto out_free_value; + } +-- +2.7.0 + diff --git a/kernel/kernel/files/patches/mageia/fs-ovl-check-dentry-positiveness-in-ovl_cleanup_whiteou.patch b/kernel/kernel/files/patches/mageia/fs-ovl-check-dentry-positiveness-in-ovl_cleanup_whiteou.patch new file mode 100644 index 00000000..d2c30236 --- /dev/null +++ b/kernel/kernel/files/patches/mageia/fs-ovl-check-dentry-positiveness-in-ovl_cleanup_whiteou.patch @@ -0,0 +1,44 @@ +From 84889d49335627bc770b32787c1ef9ebad1da232 Mon Sep 17 00:00:00 2001 +From: Konstantin Khlebnikov +Date: Mon, 16 Nov 2015 18:44:11 +0300 +Subject: [PATCH 6/6] ovl: check dentry positiveness in ovl_cleanup_whiteouts() + +This patch fixes kernel crash at removing directory which contains +whiteouts from lower layers. + +Cache of directory content passed as "list" contains entries from all +layers, including whiteouts from lower layers. So, lookup in upper dir +(moved into work at this stage) will return negative entry. Plus this +cache is filled long before and we can race with external removal. + +Example: + mkdir -p lower0/dir lower1/dir upper work overlay + touch lower0/dir/a lower0/dir/b + mknod lower1/dir/a c 0 0 + mount -t overlay none overlay -o lowerdir=lower1:lower0,upperdir=upper,workdir=work + rm -fr overlay/dir + +Signed-off-by: Konstantin Khlebnikov +Signed-off-by: Miklos Szeredi +Cc: # 3.18+ +--- + fs/overlayfs/readdir.c | 3 ++- + 1 file changed, 2 insertions(+), 1 deletion(-) + +diff --git a/fs/overlayfs/readdir.c b/fs/overlayfs/readdir.c +index 70e9af5..adcb139 100644 +--- a/fs/overlayfs/readdir.c ++++ b/fs/overlayfs/readdir.c +@@ -571,7 +571,8 @@ void ovl_cleanup_whiteouts(struct dentry *upper, struct list_head *list) + (int) PTR_ERR(dentry)); + continue; + } +- ovl_cleanup(upper->d_inode, dentry); ++ if (dentry->d_inode) ++ ovl_cleanup(upper->d_inode, dentry); + dput(dentry); + } + mutex_unlock(&upper->d_inode->i_mutex); +-- +2.7.0 + diff --git a/kernel/kernel/files/patches/mageia/fs-ovl-move-super-block-magic-number-to-magic.h.patch b/kernel/kernel/files/patches/mageia/fs-ovl-move-super-block-magic-number-to-magic.h.patch new file mode 100644 index 00000000..87d5c18f --- /dev/null +++ b/kernel/kernel/files/patches/mageia/fs-ovl-move-super-block-magic-number-to-magic.h.patch @@ -0,0 +1,46 @@ +From 257f871993474e2bde6c497b54022c362cf398e1 Mon Sep 17 00:00:00 2001 +From: Stephen Hemminger +Date: Wed, 4 Nov 2015 10:59:52 -0800 +Subject: [PATCH 3/6] ovl: move super block magic number to magic.h + +The overlayfs file system is not recognized by programs +like tail because the magic number is not in standard header location. + +Move it so that the value will propagate on for the GNU library +and utilities. Needs to go in the fstatfs manual page as well. + +Signed-off-by: Stephen Hemminger +Signed-off-by: Miklos Szeredi +--- + fs/overlayfs/super.c | 2 -- + include/uapi/linux/magic.h | 1 + + 2 files changed, 1 insertion(+), 2 deletions(-) + +diff --git a/fs/overlayfs/super.c b/fs/overlayfs/super.c +index 97cacb5..32f3124 100644 +--- a/fs/overlayfs/super.c ++++ b/fs/overlayfs/super.c +@@ -24,8 +24,6 @@ MODULE_AUTHOR("Miklos Szeredi "); + MODULE_DESCRIPTION("Overlay filesystem"); + MODULE_LICENSE("GPL"); + +-#define OVERLAYFS_SUPER_MAGIC 0x794c7630 +- + struct ovl_config { + char *lowerdir; + char *upperdir; +diff --git a/include/uapi/linux/magic.h b/include/uapi/linux/magic.h +index 7b1425a..eec4389 100644 +--- a/include/uapi/linux/magic.h ++++ b/include/uapi/linux/magic.h +@@ -31,6 +31,7 @@ + #define PSTOREFS_MAGIC 0x6165676C + #define EFIVARFS_MAGIC 0xde5e81e4 + #define HOSTFS_SUPER_MAGIC 0x00c0ffee ++#define OVERLAYFS_SUPER_MAGIC 0x794c7630 + + #define MINIX_SUPER_MAGIC 0x137F /* minix v1 fs, 14 char names */ + #define MINIX_SUPER_MAGIC2 0x138F /* minix v1 fs, 30 char names */ +-- +2.7.0 + diff --git a/kernel/kernel/files/patches/mageia/fs-ovl-root-copy-attr.patch b/kernel/kernel/files/patches/mageia/fs-ovl-root-copy-attr.patch new file mode 100644 index 00000000..73613b7e --- /dev/null +++ b/kernel/kernel/files/patches/mageia/fs-ovl-root-copy-attr.patch @@ -0,0 +1,33 @@ +From ed06e069775ad9236087594a1c1667367e983fb5 Mon Sep 17 00:00:00 2001 +From: Miklos Szeredi +Date: Wed, 9 Dec 2015 16:11:59 +0100 +Subject: [PATCH 4/6] ovl: root: copy attr + +We copy i_uid and i_gid of underlying inode into overlayfs inode. Except +for the root inode. + +Fix this omission. + +Signed-off-by: Miklos Szeredi +Cc: +--- + fs/overlayfs/super.c | 3 +++ + 1 file changed, 3 insertions(+) + +diff --git a/fs/overlayfs/super.c b/fs/overlayfs/super.c +index 32f3124..ec31711 100644 +--- a/fs/overlayfs/super.c ++++ b/fs/overlayfs/super.c +@@ -1079,6 +1079,9 @@ static int ovl_fill_super(struct super_block *sb, void *data, int silent) + + root_dentry->d_fsdata = oe; + ++ ovl_copyattr(ovl_dentry_real(root_dentry)->d_inode, ++ root_dentry->d_inode); ++ + sb->s_magic = OVERLAYFS_SUPER_MAGIC; + sb->s_op = &ovl_super_operations; + sb->s_root = root_dentry; +-- +2.7.0 + diff --git a/kernel/kernel/files/patches/mageia/fs-ovl-setattr-check-permissions-before-copy-up.patch b/kernel/kernel/files/patches/mageia/fs-ovl-setattr-check-permissions-before-copy-up.patch new file mode 100644 index 00000000..91014154 --- /dev/null +++ b/kernel/kernel/files/patches/mageia/fs-ovl-setattr-check-permissions-before-copy-up.patch @@ -0,0 +1,65 @@ +From cf9a6784f7c1b5ee2b9159a1246e327c331c5697 Mon Sep 17 00:00:00 2001 +From: Miklos Szeredi +Date: Fri, 11 Dec 2015 16:30:49 +0100 +Subject: [PATCH 5/6] ovl: setattr: check permissions before copy-up + +Without this copy-up of a file can be forced, even without actually being +allowed to do anything on the file. + +[Arnd Bergmann] include for PAGE_CACHE_SIZE (used by +MAX_LFS_FILESIZE definition). + +Signed-off-by: Miklos Szeredi +Cc: +--- + fs/overlayfs/inode.c | 13 +++++++++++++ + fs/overlayfs/super.c | 2 ++ + 2 files changed, 15 insertions(+) + +diff --git a/fs/overlayfs/inode.c b/fs/overlayfs/inode.c +index 7654631..213a726 100644 +--- a/fs/overlayfs/inode.c ++++ b/fs/overlayfs/inode.c +@@ -45,6 +45,19 @@ int ovl_setattr(struct dentry *dentry, struct iattr *attr) + int err; + struct dentry *upperdentry; + ++ /* ++ * Check for permissions before trying to copy-up. This is redundant ++ * since it will be rechecked later by ->setattr() on upper dentry. But ++ * without this, copy-up can be triggered by just about anybody. ++ * ++ * We don't initialize inode->size, which just means that ++ * inode_newsize_ok() will always check against MAX_LFS_FILESIZE and not ++ * check for a swapfile (which this won't be anyway). ++ */ ++ err = inode_change_ok(dentry->d_inode, attr); ++ if (err) ++ return err; ++ + err = ovl_want_write(dentry); + if (err) + goto out; +diff --git a/fs/overlayfs/super.c b/fs/overlayfs/super.c +index ec31711..b08bf4d 100644 +--- a/fs/overlayfs/super.c ++++ b/fs/overlayfs/super.c +@@ -9,6 +9,7 @@ + + #include + #include ++#include + #include + #include + #include +@@ -936,6 +937,7 @@ static int ovl_fill_super(struct super_block *sb, void *data, int silent) + } + + sb->s_stack_depth = 0; ++ sb->s_maxbytes = MAX_LFS_FILESIZE; + if (ufs->config.upperdir) { + if (!ufs->config.workdir) { + pr_err("overlayfs: missing 'workdir'\n"); +-- +2.7.0 + diff --git a/kernel/kernel/files/patches/mageia/fs-ovl-use-a-minimal-buffer-in-ovl_copy_xattr.patch b/kernel/kernel/files/patches/mageia/fs-ovl-use-a-minimal-buffer-in-ovl_copy_xattr.patch new file mode 100644 index 00000000..59eb828b --- /dev/null +++ b/kernel/kernel/files/patches/mageia/fs-ovl-use-a-minimal-buffer-in-ovl_copy_xattr.patch @@ -0,0 +1,89 @@ +From e4ad29fa0d224d05e08b2858e65f112fd8edd4fe Mon Sep 17 00:00:00 2001 +From: Vito Caputo +Date: Sat, 24 Oct 2015 07:19:46 -0500 +Subject: [PATCH 2/6] ovl: use a minimal buffer in ovl_copy_xattr + +Rather than always allocating the high-order XATTR_SIZE_MAX buffer +which is costly and prone to failure, only allocate what is needed and +realloc if necessary. + +Fixes https://github.com/coreos/bugs/issues/489 + +Signed-off-by: Miklos Szeredi +Cc: +--- + fs/overlayfs/copy_up.c | 39 +++++++++++++++++++++++++-------------- + 1 file changed, 25 insertions(+), 14 deletions(-) + +diff --git a/fs/overlayfs/copy_up.c b/fs/overlayfs/copy_up.c +index 394e87f..758012b 100644 +--- a/fs/overlayfs/copy_up.c ++++ b/fs/overlayfs/copy_up.c +@@ -22,9 +22,9 @@ + + int ovl_copy_xattr(struct dentry *old, struct dentry *new) + { +- ssize_t list_size, size; +- char *buf, *name, *value; +- int error; ++ ssize_t list_size, size, value_size = 0; ++ char *buf, *name, *value = NULL; ++ int uninitialized_var(error); + + if (!old->d_inode->i_op->getxattr || + !new->d_inode->i_op->getxattr) +@@ -41,29 +41,40 @@ int ovl_copy_xattr(struct dentry *old, struct dentry *new) + if (!buf) + return -ENOMEM; + +- error = -ENOMEM; +- value = kmalloc(XATTR_SIZE_MAX, GFP_KERNEL); +- if (!value) +- goto out; +- + list_size = vfs_listxattr(old, buf, list_size); + if (list_size <= 0) { + error = list_size; +- goto out_free_value; ++ goto out; + } + + for (name = buf; name < (buf + list_size); name += strlen(name) + 1) { +- size = vfs_getxattr(old, name, value, XATTR_SIZE_MAX); ++retry: ++ size = vfs_getxattr(old, name, value, value_size); ++ if (size == -ERANGE) ++ size = vfs_getxattr(old, name, NULL, 0); ++ + if (size < 0) { + error = size; +- goto out_free_value; ++ break; ++ } ++ ++ if (size > value_size) { ++ void *new; ++ ++ new = krealloc(value, size, GFP_KERNEL); ++ if (!new) { ++ error = -ENOMEM; ++ break; ++ } ++ value = new; ++ value_size = size; ++ goto retry; + } ++ + error = vfs_setxattr(new, name, value, size, 0); + if (error) +- goto out_free_value; ++ break; + } +- +-out_free_value: + kfree(value); + out: + kfree(buf); +-- +2.7.0 + diff --git a/kernel/kernel/files/patches/mageia/gpu-drm-radeon-Drop-unnecessary-unsigned-int-0-check.patch b/kernel/kernel/files/patches/mageia/gpu-drm-radeon-Drop-unnecessary-unsigned-int-0-check.patch new file mode 100644 index 00000000..3303a75a --- /dev/null +++ b/kernel/kernel/files/patches/mageia/gpu-drm-radeon-Drop-unnecessary-unsigned-int-0-check.patch @@ -0,0 +1,34 @@ +From 85a21eafbc2218ffba59b1dda2ce9d7148bf43d2 Mon Sep 17 00:00:00 2001 +From: Thierry Reding +Date: Mon, 4 Jan 2016 18:19:12 +0100 +Subject: [PATCH] drm/radeon: Drop unnecessary unsigned int < 0 check +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +Unsigned integers can never be negative, so drop this check. + +Cc: Christian König +Cc: Alex Deucher +Signed-off-by: Thierry Reding +Signed-off-by: Alex Deucher +--- + drivers/gpu/drm/radeon/radeon_kms.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/drivers/gpu/drm/radeon/radeon_kms.c b/drivers/gpu/drm/radeon/radeon_kms.c +index 4fab44e..414953c 100644 +--- a/drivers/gpu/drm/radeon/radeon_kms.c ++++ b/drivers/gpu/drm/radeon/radeon_kms.c +@@ -759,7 +759,7 @@ u32 radeon_get_vblank_counter_kms(struct drm_device *dev, unsigned int pipe) + u32 count; + struct radeon_device *rdev = dev->dev_private; + +- if (pipe < 0 || pipe >= rdev->num_crtc) { ++ if (pipe >= rdev->num_crtc) { + DRM_ERROR("Invalid crtc %u\n", pipe); + return -EINVAL; + } +-- +2.3.10 + diff --git a/kernel/kernel/files/patches/mageia/gpu-drm-radeon-Update-radeon_get_vblank_counter_kms.patch b/kernel/kernel/files/patches/mageia/gpu-drm-radeon-Update-radeon_get_vblank_counter_kms.patch new file mode 100644 index 00000000..28fe862a --- /dev/null +++ b/kernel/kernel/files/patches/mageia/gpu-drm-radeon-Update-radeon_get_vblank_counter_kms.patch @@ -0,0 +1,106 @@ +From 4e926d2db58244fca9845c78a5d6f873ac73795b Mon Sep 17 00:00:00 2001 +From: Thierry Reding +Date: Wed, 16 Dec 2015 15:31:47 +0100 +Subject: [PATCH] drm/radeon: Update radeon_get_vblank_counter_kms() +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +Commit 88e72717c2de ("drm/irq: Use unsigned int pipe in public API") +updated the prototype of this function but not the implementation. This +wasn't noticed even through compile tests because the prototype is part +of the source file that uses it and hence the compiler won't know the +prototype when it compiles the implementation. + +The right thing would've been to move the prototype to a header that's +included in radeon_kms.c so that the implementation signature could be +checked against it, but the closest thing would've been radeon_drv.h +and including that results in a lot of build errors, so we'll leave it +as is for now. + +Cc: Christian König +Cc: Alex Deucher +Reviewed-by: Christian König +Signed-off-by: Thierry Reding +Signed-off-by: Alex Deucher +--- + drivers/gpu/drm/radeon/radeon_kms.c | 24 ++++++++++++------------ + 1 file changed, 12 insertions(+), 12 deletions(-) + +diff --git a/drivers/gpu/drm/radeon/radeon_kms.c b/drivers/gpu/drm/radeon/radeon_kms.c +index d290a8a..4fab44e 100644 +--- a/drivers/gpu/drm/radeon/radeon_kms.c ++++ b/drivers/gpu/drm/radeon/radeon_kms.c +@@ -748,19 +748,19 @@ void radeon_driver_preclose_kms(struct drm_device *dev, + * radeon_get_vblank_counter_kms - get frame count + * + * @dev: drm dev pointer +- * @crtc: crtc to get the frame count from ++ * @pipe: crtc to get the frame count from + * + * Gets the frame count on the requested crtc (all asics). + * Returns frame count on success, -EINVAL on failure. + */ +-u32 radeon_get_vblank_counter_kms(struct drm_device *dev, int crtc) ++u32 radeon_get_vblank_counter_kms(struct drm_device *dev, unsigned int pipe) + { + int vpos, hpos, stat; + u32 count; + struct radeon_device *rdev = dev->dev_private; + +- if (crtc < 0 || crtc >= rdev->num_crtc) { +- DRM_ERROR("Invalid crtc %d\n", crtc); ++ if (pipe < 0 || pipe >= rdev->num_crtc) { ++ DRM_ERROR("Invalid crtc %u\n", pipe); + return -EINVAL; + } + +@@ -772,29 +772,29 @@ u32 radeon_get_vblank_counter_kms(struct drm_device *dev, int crtc) + * and start of vsync, so vpos >= 0 means to bump the hw frame counter + * result by 1 to give the proper appearance to caller. + */ +- if (rdev->mode_info.crtcs[crtc]) { ++ if (rdev->mode_info.crtcs[pipe]) { + /* Repeat readout if needed to provide stable result if + * we cross start of vsync during the queries. + */ + do { +- count = radeon_get_vblank_counter(rdev, crtc); ++ count = radeon_get_vblank_counter(rdev, pipe); + /* Ask radeon_get_crtc_scanoutpos to return vpos as + * distance to start of vblank, instead of regular + * vertical scanout pos. + */ + stat = radeon_get_crtc_scanoutpos( +- dev, crtc, GET_DISTANCE_TO_VBLANKSTART, ++ dev, pipe, GET_DISTANCE_TO_VBLANKSTART, + &vpos, &hpos, NULL, NULL, +- &rdev->mode_info.crtcs[crtc]->base.hwmode); +- } while (count != radeon_get_vblank_counter(rdev, crtc)); ++ &rdev->mode_info.crtcs[pipe]->base.hwmode); ++ } while (count != radeon_get_vblank_counter(rdev, pipe)); + + if (((stat & (DRM_SCANOUTPOS_VALID | DRM_SCANOUTPOS_ACCURATE)) != + (DRM_SCANOUTPOS_VALID | DRM_SCANOUTPOS_ACCURATE))) { + DRM_DEBUG_VBL("Query failed! stat %d\n", stat); + } + else { +- DRM_DEBUG_VBL("crtc %d: dist from vblank start %d\n", +- crtc, vpos); ++ DRM_DEBUG_VBL("crtc %u: dist from vblank start %d\n", ++ pipe, vpos); + + /* Bump counter if we are at >= leading edge of vblank, + * but before vsync where vpos would turn negative and +@@ -806,7 +806,7 @@ u32 radeon_get_vblank_counter_kms(struct drm_device *dev, int crtc) + } + else { + /* Fallback to use value as is. */ +- count = radeon_get_vblank_counter(rdev, crtc); ++ count = radeon_get_vblank_counter(rdev, pipe); + DRM_DEBUG_VBL("NULL mode info! Returned count may be wrong.\n"); + } + +-- +2.3.10 + diff --git a/kernel/kernel/files/patches/mageia/keys-fix-keyring-ref-leak-in-join_session_keyring.patch b/kernel/kernel/files/patches/mageia/keys-fix-keyring-ref-leak-in-join_session_keyring.patch deleted file mode 100644 index 6285e4cf..00000000 --- a/kernel/kernel/files/patches/mageia/keys-fix-keyring-ref-leak-in-join_session_keyring.patch +++ /dev/null @@ -1,82 +0,0 @@ -From 23567fd052a9abb6d67fe8e7a9ccdd9800a540f2 Mon Sep 17 00:00:00 2001 -From: Yevgeny Pats -Date: Tue, 19 Jan 2016 22:09:04 +0000 -Subject: KEYS: Fix keyring ref leak in join_session_keyring() - -From: Yevgeny Pats - -commit 23567fd052a9abb6d67fe8e7a9ccdd9800a540f2 upstream. - -This fixes CVE-2016-0728. - -If a thread is asked to join as a session keyring the keyring that's already -set as its session, we leak a keyring reference. - -This can be tested with the following program: - - #include - #include - #include - #include - - int main(int argc, const char *argv[]) - { - int i = 0; - key_serial_t serial; - - serial = keyctl(KEYCTL_JOIN_SESSION_KEYRING, - "leaked-keyring"); - if (serial < 0) { - perror("keyctl"); - return -1; - } - - if (keyctl(KEYCTL_SETPERM, serial, - KEY_POS_ALL | KEY_USR_ALL) < 0) { - perror("keyctl"); - return -1; - } - - for (i = 0; i < 100; i++) { - serial = keyctl(KEYCTL_JOIN_SESSION_KEYRING, - "leaked-keyring"); - if (serial < 0) { - perror("keyctl"); - return -1; - } - } - - return 0; - } - -If, after the program has run, there something like the following line in -/proc/keys: - -3f3d898f I--Q--- 100 perm 3f3f0000 0 0 keyring leaked-keyring: empty - -with a usage count of 100 * the number of times the program has been run, -then the kernel is malfunctioning. If leaked-keyring has zero usages or -has been garbage collected, then the problem is fixed. - -Reported-by: Yevgeny Pats -Signed-off-by: David Howells -Acked-by: Don Zickus -Acked-by: Prarit Bhargava -Acked-by: Jarod Wilson -Signed-off-by: James Morris -Signed-off-by: Greg Kroah-Hartman - ---- - security/keys/process_keys.c | 1 + - 1 file changed, 1 insertion(+) - ---- a/security/keys/process_keys.c -+++ b/security/keys/process_keys.c -@@ -794,6 +794,7 @@ long join_session_keyring(const char *na - ret = PTR_ERR(keyring); - goto error2; - } else if (keyring == new->session_keyring) { -+ key_put(keyring); - ret = 0; - goto error2; - } diff --git a/kernel/kernel/files/patches/mageia/series b/kernel/kernel/files/patches/mageia/series index 6c89e9a2..edc9f22b 100644 --- a/kernel/kernel/files/patches/mageia/series +++ b/kernel/kernel/files/patches/mageia/series @@ -133,6 +133,14 @@ ata-libata-disable-forced-PORTS_IMPL-for-AHCI-1.3.patch fs-aufs-4.4.patch fs-aufs-4.4-modular.patch +# ovl fixes +fs-ovl-allow-zero-size-xattr.patch +fs-ovl-use-a-minimal-buffer-in-ovl_copy_xattr.patch +fs-ovl-move-super-block-magic-number-to-magic.h.patch +fs-ovl-root-copy-attr.patch +fs-ovl-setattr-check-permissions-before-copy-up.patch +fs-ovl-check-dentry-positiveness-in-ovl_cleanup_whiteou.patch + ### ### FireWire ### @@ -188,6 +196,10 @@ gpu-drm-0107-drm-vc4-Add-support-for-drawing-3D-frames.patch gpu-drm-0108-drm-vc4-Add-support-for-async-pageflips.patch gpu-drm-0109-drm-vc4-Add-an-interface-for-capturing-the-GPU-state.patch +# radeon breakage fixes +gpu-drm-radeon-Update-radeon_get_vblank_counter_kms.patch +gpu-drm-radeon-Drop-unnecessary-unsigned-int-0-check.patch + ### ### Hardware Monitoring ### @@ -349,9 +361,6 @@ video-mageia-logo.patch ### Security ### -# CVE-2016-0728 -keys-fix-keyring-ref-leak-in-join_session_keyring.patch - ### ### Smack fixes ### diff --git a/kernel/kernel/pspec.xml b/kernel/kernel/pspec.xml index 27f3ebb9..f3ae3f4f 100644 --- a/kernel/kernel/pspec.xml +++ b/kernel/kernel/pspec.xml @@ -28,8 +28,8 @@ - - + patches/linux/patch-4.4.1.xz + patches/mageia/x86-pci-toshiba-equium-a60-assign-busses.patch @@ -59,6 +59,12 @@ patches/mageia/block-Make-CFQ-default-to-IOPS-mode-on-SSDs.patch patches/mageia/fs-aufs-4.4.patch patches/mageia/fs-aufs-4.4-modular.patch + patches/mageia/fs-ovl-allow-zero-size-xattr.patch + patches/mageia/fs-ovl-use-a-minimal-buffer-in-ovl_copy_xattr.patch + patches/mageia/fs-ovl-move-super-block-magic-number-to-magic.h.patch + patches/mageia/fs-ovl-root-copy-attr.patch + patches/mageia/fs-ovl-setattr-check-permissions-before-copy-up.patch + patches/mageia/fs-ovl-check-dentry-positiveness-in-ovl_cleanup_whiteou.patch patches/mageia/firewire-ieee1394-module-aliases.patch patches/mageia/char-agp-intel-new-Q57-id.patch patches/mageia/gpu-drm-mach64.patch @@ -94,6 +100,8 @@ patches/mageia/gpu-drm-0107-drm-vc4-Add-support-for-drawing-3D-frames.patch patches/mageia/gpu-drm-0108-drm-vc4-Add-support-for-async-pageflips.patch patches/mageia/gpu-drm-0109-drm-vc4-Add-an-interface-for-capturing-the-GPU-state.patch + patches/mageia/gpu-drm-radeon-Update-radeon_get_vblank_counter_kms.patch + patches/mageia/gpu-drm-radeon-Drop-unnecessary-unsigned-int-0-check.patch patches/mageia/input-i8042-quirks-for-Fujitsu-Lifebook-A544-and-Lif.patch patches/mageia/net-sis190-fix-list-usage.patch patches/mageia/net-netfilter-IFWLOG.patch @@ -142,7 +150,6 @@ patches/mageia/3rd-rtl8723bs.patch patches/mageia/ahci-add-new-Intel-device-IDs.patch patches/mageia/ata-libata-disable-forced-PORTS_IMPL-for-AHCI-1.3.patch - patches/mageia/keys-fix-keyring-ref-leak-in-join_session_keyring.patch patches/mageia/arm-0001-dt-bindings-Add-root-properties-for-Raspberry-Pi-2.patch patches/mageia/arm-0002-ARM-bcm2835-Add-a-compat-string-for-bcm2836-machine-.patch patches/mageia/arm-0003-ARM-bcm2835-Add-Kconfig-support-for-bcm2836.patch @@ -209,6 +216,17 @@ + + 2016-02-02 + 4.4.1 + Version bump to 4.4.1 https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.1 + security + + systemRestart + + Ertuğrul Erata + ertugrulerata@gmail.com + 2016-01-30 4.4.0