diff options
Diffstat (limited to 'net')
32 files changed, 347 insertions, 162 deletions
diff --git a/net/atm/pppoatm.c b/net/atm/pppoatm.c index e49bb6d948a1..e9aced0ec56b 100644 --- a/net/atm/pppoatm.c +++ b/net/atm/pppoatm.c | |||
| @@ -260,7 +260,7 @@ static int pppoatm_devppp_ioctl(struct ppp_channel *chan, unsigned int cmd, | |||
| 260 | return -ENOTTY; | 260 | return -ENOTTY; |
| 261 | } | 261 | } |
| 262 | 262 | ||
| 263 | static /*const*/ struct ppp_channel_ops pppoatm_ops = { | 263 | static const struct ppp_channel_ops pppoatm_ops = { |
| 264 | .start_xmit = pppoatm_send, | 264 | .start_xmit = pppoatm_send, |
| 265 | .ioctl = pppoatm_devppp_ioctl, | 265 | .ioctl = pppoatm_devppp_ioctl, |
| 266 | }; | 266 | }; |
diff --git a/net/bluetooth/hci_core.c b/net/bluetooth/hci_core.c index 8303f1c9ef54..c52f091ee6de 100644 --- a/net/bluetooth/hci_core.c +++ b/net/bluetooth/hci_core.c | |||
| @@ -924,7 +924,7 @@ int hci_register_dev(struct hci_dev *hdev) | |||
| 924 | 924 | ||
| 925 | hci_conn_hash_init(hdev); | 925 | hci_conn_hash_init(hdev); |
| 926 | 926 | ||
| 927 | INIT_LIST_HEAD(&hdev->blacklist.list); | 927 | INIT_LIST_HEAD(&hdev->blacklist); |
| 928 | 928 | ||
| 929 | memset(&hdev->stat, 0, sizeof(struct hci_dev_stats)); | 929 | memset(&hdev->stat, 0, sizeof(struct hci_dev_stats)); |
| 930 | 930 | ||
diff --git a/net/bluetooth/hci_sock.c b/net/bluetooth/hci_sock.c index 4f170a595934..83acd164d39e 100644 --- a/net/bluetooth/hci_sock.c +++ b/net/bluetooth/hci_sock.c | |||
| @@ -168,9 +168,8 @@ static int hci_sock_release(struct socket *sock) | |||
| 168 | struct bdaddr_list *hci_blacklist_lookup(struct hci_dev *hdev, bdaddr_t *bdaddr) | 168 | struct bdaddr_list *hci_blacklist_lookup(struct hci_dev *hdev, bdaddr_t *bdaddr) |
| 169 | { | 169 | { |
| 170 | struct list_head *p; | 170 | struct list_head *p; |
| 171 | struct bdaddr_list *blacklist = &hdev->blacklist; | ||
| 172 | 171 | ||
| 173 | list_for_each(p, &blacklist->list) { | 172 | list_for_each(p, &hdev->blacklist) { |
| 174 | struct bdaddr_list *b; | 173 | struct bdaddr_list *b; |
| 175 | 174 | ||
| 176 | b = list_entry(p, struct bdaddr_list, list); | 175 | b = list_entry(p, struct bdaddr_list, list); |
| @@ -202,7 +201,7 @@ static int hci_blacklist_add(struct hci_dev *hdev, void __user *arg) | |||
| 202 | 201 | ||
| 203 | bacpy(&entry->bdaddr, &bdaddr); | 202 | bacpy(&entry->bdaddr, &bdaddr); |
| 204 | 203 | ||
| 205 | list_add(&entry->list, &hdev->blacklist.list); | 204 | list_add(&entry->list, &hdev->blacklist); |
| 206 | 205 | ||
| 207 | return 0; | 206 | return 0; |
| 208 | } | 207 | } |
| @@ -210,9 +209,8 @@ static int hci_blacklist_add(struct hci_dev *hdev, void __user *arg) | |||
| 210 | int hci_blacklist_clear(struct hci_dev *hdev) | 209 | int hci_blacklist_clear(struct hci_dev *hdev) |
| 211 | { | 210 | { |
| 212 | struct list_head *p, *n; | 211 | struct list_head *p, *n; |
| 213 | struct bdaddr_list *blacklist = &hdev->blacklist; | ||
| 214 | 212 | ||
| 215 | list_for_each_safe(p, n, &blacklist->list) { | 213 | list_for_each_safe(p, n, &hdev->blacklist) { |
| 216 | struct bdaddr_list *b; | 214 | struct bdaddr_list *b; |
| 217 | 215 | ||
| 218 | b = list_entry(p, struct bdaddr_list, list); | 216 | b = list_entry(p, struct bdaddr_list, list); |
diff --git a/net/bluetooth/hci_sysfs.c b/net/bluetooth/hci_sysfs.c index ce44c47eeac1..8fb967beee80 100644 --- a/net/bluetooth/hci_sysfs.c +++ b/net/bluetooth/hci_sysfs.c | |||
| @@ -439,12 +439,11 @@ static const struct file_operations inquiry_cache_fops = { | |||
| 439 | static int blacklist_show(struct seq_file *f, void *p) | 439 | static int blacklist_show(struct seq_file *f, void *p) |
| 440 | { | 440 | { |
| 441 | struct hci_dev *hdev = f->private; | 441 | struct hci_dev *hdev = f->private; |
| 442 | struct bdaddr_list *blacklist = &hdev->blacklist; | ||
| 443 | struct list_head *l; | 442 | struct list_head *l; |
| 444 | 443 | ||
| 445 | hci_dev_lock_bh(hdev); | 444 | hci_dev_lock_bh(hdev); |
| 446 | 445 | ||
| 447 | list_for_each(l, &blacklist->list) { | 446 | list_for_each(l, &hdev->blacklist) { |
| 448 | struct bdaddr_list *b; | 447 | struct bdaddr_list *b; |
| 449 | bdaddr_t bdaddr; | 448 | bdaddr_t bdaddr; |
| 450 | 449 | ||
diff --git a/net/bluetooth/l2cap.c b/net/bluetooth/l2cap.c index 9ba1e8eee37c..fadf26b4ed7c 100644 --- a/net/bluetooth/l2cap.c +++ b/net/bluetooth/l2cap.c | |||
| @@ -2527,6 +2527,10 @@ done: | |||
| 2527 | if (pi->imtu != L2CAP_DEFAULT_MTU) | 2527 | if (pi->imtu != L2CAP_DEFAULT_MTU) |
| 2528 | l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, pi->imtu); | 2528 | l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, pi->imtu); |
| 2529 | 2529 | ||
| 2530 | if (!(pi->conn->feat_mask & L2CAP_FEAT_ERTM) && | ||
| 2531 | !(pi->conn->feat_mask & L2CAP_FEAT_STREAMING)) | ||
| 2532 | break; | ||
| 2533 | |||
| 2530 | rfc.mode = L2CAP_MODE_BASIC; | 2534 | rfc.mode = L2CAP_MODE_BASIC; |
| 2531 | rfc.txwin_size = 0; | 2535 | rfc.txwin_size = 0; |
| 2532 | rfc.max_transmit = 0; | 2536 | rfc.max_transmit = 0; |
| @@ -2534,6 +2538,8 @@ done: | |||
| 2534 | rfc.monitor_timeout = 0; | 2538 | rfc.monitor_timeout = 0; |
| 2535 | rfc.max_pdu_size = 0; | 2539 | rfc.max_pdu_size = 0; |
| 2536 | 2540 | ||
| 2541 | l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc), | ||
| 2542 | (unsigned long) &rfc); | ||
| 2537 | break; | 2543 | break; |
| 2538 | 2544 | ||
| 2539 | case L2CAP_MODE_ERTM: | 2545 | case L2CAP_MODE_ERTM: |
| @@ -2546,6 +2552,9 @@ done: | |||
| 2546 | if (L2CAP_DEFAULT_MAX_PDU_SIZE > pi->conn->mtu - 10) | 2552 | if (L2CAP_DEFAULT_MAX_PDU_SIZE > pi->conn->mtu - 10) |
| 2547 | rfc.max_pdu_size = cpu_to_le16(pi->conn->mtu - 10); | 2553 | rfc.max_pdu_size = cpu_to_le16(pi->conn->mtu - 10); |
| 2548 | 2554 | ||
| 2555 | l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc), | ||
| 2556 | (unsigned long) &rfc); | ||
| 2557 | |||
| 2549 | if (!(pi->conn->feat_mask & L2CAP_FEAT_FCS)) | 2558 | if (!(pi->conn->feat_mask & L2CAP_FEAT_FCS)) |
| 2550 | break; | 2559 | break; |
| 2551 | 2560 | ||
| @@ -2566,6 +2575,9 @@ done: | |||
| 2566 | if (L2CAP_DEFAULT_MAX_PDU_SIZE > pi->conn->mtu - 10) | 2575 | if (L2CAP_DEFAULT_MAX_PDU_SIZE > pi->conn->mtu - 10) |
| 2567 | rfc.max_pdu_size = cpu_to_le16(pi->conn->mtu - 10); | 2576 | rfc.max_pdu_size = cpu_to_le16(pi->conn->mtu - 10); |
| 2568 | 2577 | ||
| 2578 | l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc), | ||
| 2579 | (unsigned long) &rfc); | ||
| 2580 | |||
| 2569 | if (!(pi->conn->feat_mask & L2CAP_FEAT_FCS)) | 2581 | if (!(pi->conn->feat_mask & L2CAP_FEAT_FCS)) |
| 2570 | break; | 2582 | break; |
| 2571 | 2583 | ||
| @@ -2577,9 +2589,6 @@ done: | |||
| 2577 | break; | 2589 | break; |
| 2578 | } | 2590 | } |
| 2579 | 2591 | ||
| 2580 | l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc), | ||
| 2581 | (unsigned long) &rfc); | ||
| 2582 | |||
| 2583 | /* FIXME: Need actual value of the flush timeout */ | 2592 | /* FIXME: Need actual value of the flush timeout */ |
| 2584 | //if (flush_to != L2CAP_DEFAULT_FLUSH_TO) | 2593 | //if (flush_to != L2CAP_DEFAULT_FLUSH_TO) |
| 2585 | // l2cap_add_conf_opt(&ptr, L2CAP_CONF_FLUSH_TO, 2, pi->flush_to); | 2594 | // l2cap_add_conf_opt(&ptr, L2CAP_CONF_FLUSH_TO, 2, pi->flush_to); |
| @@ -2696,8 +2705,9 @@ done: | |||
| 2696 | case L2CAP_MODE_ERTM: | 2705 | case L2CAP_MODE_ERTM: |
| 2697 | pi->remote_tx_win = rfc.txwin_size; | 2706 | pi->remote_tx_win = rfc.txwin_size; |
| 2698 | pi->remote_max_tx = rfc.max_transmit; | 2707 | pi->remote_max_tx = rfc.max_transmit; |
| 2699 | if (rfc.max_pdu_size > pi->conn->mtu - 10) | 2708 | |
| 2700 | rfc.max_pdu_size = le16_to_cpu(pi->conn->mtu - 10); | 2709 | if (le16_to_cpu(rfc.max_pdu_size) > pi->conn->mtu - 10) |
| 2710 | rfc.max_pdu_size = cpu_to_le16(pi->conn->mtu - 10); | ||
| 2701 | 2711 | ||
| 2702 | pi->remote_mps = le16_to_cpu(rfc.max_pdu_size); | 2712 | pi->remote_mps = le16_to_cpu(rfc.max_pdu_size); |
| 2703 | 2713 | ||
| @@ -2714,8 +2724,8 @@ done: | |||
| 2714 | break; | 2724 | break; |
| 2715 | 2725 | ||
| 2716 | case L2CAP_MODE_STREAMING: | 2726 | case L2CAP_MODE_STREAMING: |
| 2717 | if (rfc.max_pdu_size > pi->conn->mtu - 10) | 2727 | if (le16_to_cpu(rfc.max_pdu_size) > pi->conn->mtu - 10) |
| 2718 | rfc.max_pdu_size = le16_to_cpu(pi->conn->mtu - 10); | 2728 | rfc.max_pdu_size = cpu_to_le16(pi->conn->mtu - 10); |
| 2719 | 2729 | ||
| 2720 | pi->remote_mps = le16_to_cpu(rfc.max_pdu_size); | 2730 | pi->remote_mps = le16_to_cpu(rfc.max_pdu_size); |
| 2721 | 2731 | ||
| @@ -2797,7 +2807,6 @@ static int l2cap_parse_conf_rsp(struct sock *sk, void *rsp, int len, void *data, | |||
| 2797 | if (*result == L2CAP_CONF_SUCCESS) { | 2807 | if (*result == L2CAP_CONF_SUCCESS) { |
| 2798 | switch (rfc.mode) { | 2808 | switch (rfc.mode) { |
| 2799 | case L2CAP_MODE_ERTM: | 2809 | case L2CAP_MODE_ERTM: |
| 2800 | pi->remote_tx_win = rfc.txwin_size; | ||
| 2801 | pi->retrans_timeout = le16_to_cpu(rfc.retrans_timeout); | 2810 | pi->retrans_timeout = le16_to_cpu(rfc.retrans_timeout); |
| 2802 | pi->monitor_timeout = le16_to_cpu(rfc.monitor_timeout); | 2811 | pi->monitor_timeout = le16_to_cpu(rfc.monitor_timeout); |
| 2803 | pi->mps = le16_to_cpu(rfc.max_pdu_size); | 2812 | pi->mps = le16_to_cpu(rfc.max_pdu_size); |
| @@ -2853,7 +2862,6 @@ static void l2cap_conf_rfc_get(struct sock *sk, void *rsp, int len) | |||
| 2853 | done: | 2862 | done: |
| 2854 | switch (rfc.mode) { | 2863 | switch (rfc.mode) { |
| 2855 | case L2CAP_MODE_ERTM: | 2864 | case L2CAP_MODE_ERTM: |
| 2856 | pi->remote_tx_win = rfc.txwin_size; | ||
| 2857 | pi->retrans_timeout = le16_to_cpu(rfc.retrans_timeout); | 2865 | pi->retrans_timeout = le16_to_cpu(rfc.retrans_timeout); |
| 2858 | pi->monitor_timeout = le16_to_cpu(rfc.monitor_timeout); | 2866 | pi->monitor_timeout = le16_to_cpu(rfc.monitor_timeout); |
| 2859 | pi->mps = le16_to_cpu(rfc.max_pdu_size); | 2867 | pi->mps = le16_to_cpu(rfc.max_pdu_size); |
| @@ -3339,6 +3347,15 @@ static inline int l2cap_information_rsp(struct l2cap_conn *conn, struct l2cap_cm | |||
| 3339 | 3347 | ||
| 3340 | del_timer(&conn->info_timer); | 3348 | del_timer(&conn->info_timer); |
| 3341 | 3349 | ||
| 3350 | if (result != L2CAP_IR_SUCCESS) { | ||
| 3351 | conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE; | ||
| 3352 | conn->info_ident = 0; | ||
| 3353 | |||
| 3354 | l2cap_conn_start(conn); | ||
| 3355 | |||
| 3356 | return 0; | ||
| 3357 | } | ||
| 3358 | |||
| 3342 | if (type == L2CAP_IT_FEAT_MASK) { | 3359 | if (type == L2CAP_IT_FEAT_MASK) { |
| 3343 | conn->feat_mask = get_unaligned_le32(rsp->data); | 3360 | conn->feat_mask = get_unaligned_le32(rsp->data); |
| 3344 | 3361 | ||
diff --git a/net/bluetooth/rfcomm/tty.c b/net/bluetooth/rfcomm/tty.c index 026205c18b78..befc3a52aa04 100644 --- a/net/bluetooth/rfcomm/tty.c +++ b/net/bluetooth/rfcomm/tty.c | |||
| @@ -1183,7 +1183,7 @@ int __init rfcomm_init_ttys(void) | |||
| 1183 | return 0; | 1183 | return 0; |
| 1184 | } | 1184 | } |
| 1185 | 1185 | ||
| 1186 | void __exit rfcomm_cleanup_ttys(void) | 1186 | void rfcomm_cleanup_ttys(void) |
| 1187 | { | 1187 | { |
| 1188 | tty_unregister_driver(rfcomm_tty_driver); | 1188 | tty_unregister_driver(rfcomm_tty_driver); |
| 1189 | put_tty_driver(rfcomm_tty_driver); | 1189 | put_tty_driver(rfcomm_tty_driver); |
diff --git a/net/caif/cfpkt_skbuff.c b/net/caif/cfpkt_skbuff.c index 01f238ff2346..c49a6695793a 100644 --- a/net/caif/cfpkt_skbuff.c +++ b/net/caif/cfpkt_skbuff.c | |||
| @@ -9,7 +9,7 @@ | |||
| 9 | #include <linux/hardirq.h> | 9 | #include <linux/hardirq.h> |
| 10 | #include <net/caif/cfpkt.h> | 10 | #include <net/caif/cfpkt.h> |
| 11 | 11 | ||
| 12 | #define PKT_PREFIX 16 | 12 | #define PKT_PREFIX 48 |
| 13 | #define PKT_POSTFIX 2 | 13 | #define PKT_POSTFIX 2 |
| 14 | #define PKT_LEN_WHEN_EXTENDING 128 | 14 | #define PKT_LEN_WHEN_EXTENDING 128 |
| 15 | #define PKT_ERROR(pkt, errmsg) do { \ | 15 | #define PKT_ERROR(pkt, errmsg) do { \ |
diff --git a/net/can/bcm.c b/net/can/bcm.c index 9c65e9deb9c3..08ffe9e4be20 100644 --- a/net/can/bcm.c +++ b/net/can/bcm.c | |||
| @@ -60,6 +60,13 @@ | |||
| 60 | #include <net/sock.h> | 60 | #include <net/sock.h> |
| 61 | #include <net/net_namespace.h> | 61 | #include <net/net_namespace.h> |
| 62 | 62 | ||
| 63 | /* | ||
| 64 | * To send multiple CAN frame content within TX_SETUP or to filter | ||
| 65 | * CAN messages with multiplex index within RX_SETUP, the number of | ||
| 66 | * different filters is limited to 256 due to the one byte index value. | ||
| 67 | */ | ||
| 68 | #define MAX_NFRAMES 256 | ||
| 69 | |||
| 63 | /* use of last_frames[index].can_dlc */ | 70 | /* use of last_frames[index].can_dlc */ |
| 64 | #define RX_RECV 0x40 /* received data for this element */ | 71 | #define RX_RECV 0x40 /* received data for this element */ |
| 65 | #define RX_THR 0x80 /* element not been sent due to throttle feature */ | 72 | #define RX_THR 0x80 /* element not been sent due to throttle feature */ |
| @@ -89,16 +96,16 @@ struct bcm_op { | |||
| 89 | struct list_head list; | 96 | struct list_head list; |
| 90 | int ifindex; | 97 | int ifindex; |
| 91 | canid_t can_id; | 98 | canid_t can_id; |
| 92 | int flags; | 99 | u32 flags; |
| 93 | unsigned long frames_abs, frames_filtered; | 100 | unsigned long frames_abs, frames_filtered; |
| 94 | struct timeval ival1, ival2; | 101 | struct timeval ival1, ival2; |
| 95 | struct hrtimer timer, thrtimer; | 102 | struct hrtimer timer, thrtimer; |
| 96 | struct tasklet_struct tsklet, thrtsklet; | 103 | struct tasklet_struct tsklet, thrtsklet; |
| 97 | ktime_t rx_stamp, kt_ival1, kt_ival2, kt_lastmsg; | 104 | ktime_t rx_stamp, kt_ival1, kt_ival2, kt_lastmsg; |
| 98 | int rx_ifindex; | 105 | int rx_ifindex; |
| 99 | int count; | 106 | u32 count; |
| 100 | int nframes; | 107 | u32 nframes; |
| 101 | int currframe; | 108 | u32 currframe; |
| 102 | struct can_frame *frames; | 109 | struct can_frame *frames; |
| 103 | struct can_frame *last_frames; | 110 | struct can_frame *last_frames; |
| 104 | struct can_frame sframe; | 111 | struct can_frame sframe; |
| @@ -175,7 +182,7 @@ static int bcm_proc_show(struct seq_file *m, void *v) | |||
| 175 | 182 | ||
| 176 | seq_printf(m, "rx_op: %03X %-5s ", | 183 | seq_printf(m, "rx_op: %03X %-5s ", |
| 177 | op->can_id, bcm_proc_getifname(ifname, op->ifindex)); | 184 | op->can_id, bcm_proc_getifname(ifname, op->ifindex)); |
| 178 | seq_printf(m, "[%d]%c ", op->nframes, | 185 | seq_printf(m, "[%u]%c ", op->nframes, |
| 179 | (op->flags & RX_CHECK_DLC)?'d':' '); | 186 | (op->flags & RX_CHECK_DLC)?'d':' '); |
| 180 | if (op->kt_ival1.tv64) | 187 | if (op->kt_ival1.tv64) |
| 181 | seq_printf(m, "timeo=%lld ", | 188 | seq_printf(m, "timeo=%lld ", |
| @@ -198,7 +205,7 @@ static int bcm_proc_show(struct seq_file *m, void *v) | |||
| 198 | 205 | ||
| 199 | list_for_each_entry(op, &bo->tx_ops, list) { | 206 | list_for_each_entry(op, &bo->tx_ops, list) { |
| 200 | 207 | ||
| 201 | seq_printf(m, "tx_op: %03X %s [%d] ", | 208 | seq_printf(m, "tx_op: %03X %s [%u] ", |
| 202 | op->can_id, | 209 | op->can_id, |
| 203 | bcm_proc_getifname(ifname, op->ifindex), | 210 | bcm_proc_getifname(ifname, op->ifindex), |
| 204 | op->nframes); | 211 | op->nframes); |
| @@ -283,7 +290,7 @@ static void bcm_send_to_user(struct bcm_op *op, struct bcm_msg_head *head, | |||
| 283 | struct can_frame *firstframe; | 290 | struct can_frame *firstframe; |
| 284 | struct sockaddr_can *addr; | 291 | struct sockaddr_can *addr; |
| 285 | struct sock *sk = op->sk; | 292 | struct sock *sk = op->sk; |
| 286 | int datalen = head->nframes * CFSIZ; | 293 | unsigned int datalen = head->nframes * CFSIZ; |
| 287 | int err; | 294 | int err; |
| 288 | 295 | ||
| 289 | skb = alloc_skb(sizeof(*head) + datalen, gfp_any()); | 296 | skb = alloc_skb(sizeof(*head) + datalen, gfp_any()); |
| @@ -468,7 +475,7 @@ rx_changed_settime: | |||
| 468 | * bcm_rx_cmp_to_index - (bit)compares the currently received data to formerly | 475 | * bcm_rx_cmp_to_index - (bit)compares the currently received data to formerly |
| 469 | * received data stored in op->last_frames[] | 476 | * received data stored in op->last_frames[] |
| 470 | */ | 477 | */ |
| 471 | static void bcm_rx_cmp_to_index(struct bcm_op *op, int index, | 478 | static void bcm_rx_cmp_to_index(struct bcm_op *op, unsigned int index, |
| 472 | const struct can_frame *rxdata) | 479 | const struct can_frame *rxdata) |
| 473 | { | 480 | { |
| 474 | /* | 481 | /* |
| @@ -554,7 +561,8 @@ static enum hrtimer_restart bcm_rx_timeout_handler(struct hrtimer *hrtimer) | |||
| 554 | /* | 561 | /* |
| 555 | * bcm_rx_do_flush - helper for bcm_rx_thr_flush | 562 | * bcm_rx_do_flush - helper for bcm_rx_thr_flush |
| 556 | */ | 563 | */ |
| 557 | static inline int bcm_rx_do_flush(struct bcm_op *op, int update, int index) | 564 | static inline int bcm_rx_do_flush(struct bcm_op *op, int update, |
| 565 | unsigned int index) | ||
| 558 | { | 566 | { |
| 559 | if ((op->last_frames) && (op->last_frames[index].can_dlc & RX_THR)) { | 567 | if ((op->last_frames) && (op->last_frames[index].can_dlc & RX_THR)) { |
| 560 | if (update) | 568 | if (update) |
| @@ -575,7 +583,7 @@ static int bcm_rx_thr_flush(struct bcm_op *op, int update) | |||
| 575 | int updated = 0; | 583 | int updated = 0; |
| 576 | 584 | ||
| 577 | if (op->nframes > 1) { | 585 | if (op->nframes > 1) { |
| 578 | int i; | 586 | unsigned int i; |
| 579 | 587 | ||
| 580 | /* for MUX filter we start at index 1 */ | 588 | /* for MUX filter we start at index 1 */ |
| 581 | for (i = 1; i < op->nframes; i++) | 589 | for (i = 1; i < op->nframes; i++) |
| @@ -624,7 +632,7 @@ static void bcm_rx_handler(struct sk_buff *skb, void *data) | |||
| 624 | { | 632 | { |
| 625 | struct bcm_op *op = (struct bcm_op *)data; | 633 | struct bcm_op *op = (struct bcm_op *)data; |
| 626 | const struct can_frame *rxframe = (struct can_frame *)skb->data; | 634 | const struct can_frame *rxframe = (struct can_frame *)skb->data; |
| 627 | int i; | 635 | unsigned int i; |
| 628 | 636 | ||
| 629 | /* disable timeout */ | 637 | /* disable timeout */ |
| 630 | hrtimer_cancel(&op->timer); | 638 | hrtimer_cancel(&op->timer); |
| @@ -822,14 +830,15 @@ static int bcm_tx_setup(struct bcm_msg_head *msg_head, struct msghdr *msg, | |||
| 822 | { | 830 | { |
| 823 | struct bcm_sock *bo = bcm_sk(sk); | 831 | struct bcm_sock *bo = bcm_sk(sk); |
| 824 | struct bcm_op *op; | 832 | struct bcm_op *op; |
| 825 | int i, err; | 833 | unsigned int i; |
| 834 | int err; | ||
| 826 | 835 | ||
| 827 | /* we need a real device to send frames */ | 836 | /* we need a real device to send frames */ |
| 828 | if (!ifindex) | 837 | if (!ifindex) |
| 829 | return -ENODEV; | 838 | return -ENODEV; |
| 830 | 839 | ||
| 831 | /* we need at least one can_frame */ | 840 | /* check nframes boundaries - we need at least one can_frame */ |
| 832 | if (msg_head->nframes < 1) | 841 | if (msg_head->nframes < 1 || msg_head->nframes > MAX_NFRAMES) |
| 833 | return -EINVAL; | 842 | return -EINVAL; |
| 834 | 843 | ||
| 835 | /* check the given can_id */ | 844 | /* check the given can_id */ |
| @@ -993,6 +1002,10 @@ static int bcm_rx_setup(struct bcm_msg_head *msg_head, struct msghdr *msg, | |||
| 993 | msg_head->nframes = 0; | 1002 | msg_head->nframes = 0; |
| 994 | } | 1003 | } |
| 995 | 1004 | ||
| 1005 | /* the first element contains the mux-mask => MAX_NFRAMES + 1 */ | ||
| 1006 | if (msg_head->nframes > MAX_NFRAMES + 1) | ||
| 1007 | return -EINVAL; | ||
| 1008 | |||
| 996 | if ((msg_head->flags & RX_RTR_FRAME) && | 1009 | if ((msg_head->flags & RX_RTR_FRAME) && |
| 997 | ((msg_head->nframes != 1) || | 1010 | ((msg_head->nframes != 1) || |
| 998 | (!(msg_head->can_id & CAN_RTR_FLAG)))) | 1011 | (!(msg_head->can_id & CAN_RTR_FLAG)))) |
diff --git a/net/core/dev.c b/net/core/dev.c index e1c1cdcc2bb0..1ae654391442 100644 --- a/net/core/dev.c +++ b/net/core/dev.c | |||
| @@ -2517,6 +2517,7 @@ int netif_rx(struct sk_buff *skb) | |||
| 2517 | struct rps_dev_flow voidflow, *rflow = &voidflow; | 2517 | struct rps_dev_flow voidflow, *rflow = &voidflow; |
| 2518 | int cpu; | 2518 | int cpu; |
| 2519 | 2519 | ||
| 2520 | preempt_disable(); | ||
| 2520 | rcu_read_lock(); | 2521 | rcu_read_lock(); |
| 2521 | 2522 | ||
| 2522 | cpu = get_rps_cpu(skb->dev, skb, &rflow); | 2523 | cpu = get_rps_cpu(skb->dev, skb, &rflow); |
| @@ -2526,6 +2527,7 @@ int netif_rx(struct sk_buff *skb) | |||
| 2526 | ret = enqueue_to_backlog(skb, cpu, &rflow->last_qtail); | 2527 | ret = enqueue_to_backlog(skb, cpu, &rflow->last_qtail); |
| 2527 | 2528 | ||
| 2528 | rcu_read_unlock(); | 2529 | rcu_read_unlock(); |
| 2530 | preempt_enable(); | ||
| 2529 | } | 2531 | } |
| 2530 | #else | 2532 | #else |
| 2531 | { | 2533 | { |
| @@ -3072,7 +3074,7 @@ enum gro_result dev_gro_receive(struct napi_struct *napi, struct sk_buff *skb) | |||
| 3072 | int mac_len; | 3074 | int mac_len; |
| 3073 | enum gro_result ret; | 3075 | enum gro_result ret; |
| 3074 | 3076 | ||
| 3075 | if (!(skb->dev->features & NETIF_F_GRO)) | 3077 | if (!(skb->dev->features & NETIF_F_GRO) || netpoll_rx_on(skb)) |
| 3076 | goto normal; | 3078 | goto normal; |
| 3077 | 3079 | ||
| 3078 | if (skb_is_gso(skb) || skb_has_frags(skb)) | 3080 | if (skb_is_gso(skb) || skb_has_frags(skb)) |
| @@ -3159,9 +3161,6 @@ __napi_gro_receive(struct napi_struct *napi, struct sk_buff *skb) | |||
| 3159 | { | 3161 | { |
| 3160 | struct sk_buff *p; | 3162 | struct sk_buff *p; |
| 3161 | 3163 | ||
| 3162 | if (netpoll_rx_on(skb)) | ||
| 3163 | return GRO_NORMAL; | ||
| 3164 | |||
| 3165 | for (p = napi->gro_list; p; p = p->next) { | 3164 | for (p = napi->gro_list; p; p = p->next) { |
| 3166 | NAPI_GRO_CB(p)->same_flow = | 3165 | NAPI_GRO_CB(p)->same_flow = |
| 3167 | (p->dev == skb->dev) && | 3166 | (p->dev == skb->dev) && |
diff --git a/net/dns_resolver/dns_key.c b/net/dns_resolver/dns_key.c index 400a04d5c9a1..739435a6af39 100644 --- a/net/dns_resolver/dns_key.c +++ b/net/dns_resolver/dns_key.c | |||
| @@ -29,6 +29,7 @@ | |||
| 29 | #include <linux/kernel.h> | 29 | #include <linux/kernel.h> |
| 30 | #include <linux/keyctl.h> | 30 | #include <linux/keyctl.h> |
| 31 | #include <linux/err.h> | 31 | #include <linux/err.h> |
| 32 | #include <linux/seq_file.h> | ||
| 32 | #include <keys/dns_resolver-type.h> | 33 | #include <keys/dns_resolver-type.h> |
| 33 | #include <keys/user-type.h> | 34 | #include <keys/user-type.h> |
| 34 | #include "internal.h" | 35 | #include "internal.h" |
| @@ -43,6 +44,8 @@ MODULE_PARM_DESC(debug, "DNS Resolver debugging mask"); | |||
| 43 | 44 | ||
| 44 | const struct cred *dns_resolver_cache; | 45 | const struct cred *dns_resolver_cache; |
| 45 | 46 | ||
| 47 | #define DNS_ERRORNO_OPTION "dnserror" | ||
| 48 | |||
| 46 | /* | 49 | /* |
| 47 | * Instantiate a user defined key for dns_resolver. | 50 | * Instantiate a user defined key for dns_resolver. |
| 48 | * | 51 | * |
| @@ -59,9 +62,10 @@ static int | |||
| 59 | dns_resolver_instantiate(struct key *key, const void *_data, size_t datalen) | 62 | dns_resolver_instantiate(struct key *key, const void *_data, size_t datalen) |
| 60 | { | 63 | { |
| 61 | struct user_key_payload *upayload; | 64 | struct user_key_payload *upayload; |
| 65 | unsigned long derrno; | ||
| 62 | int ret; | 66 | int ret; |
| 63 | size_t result_len = 0; | 67 | size_t result_len = 0; |
| 64 | const char *data = _data, *opt; | 68 | const char *data = _data, *end, *opt; |
| 65 | 69 | ||
| 66 | kenter("%%%d,%s,'%s',%zu", | 70 | kenter("%%%d,%s,'%s',%zu", |
| 67 | key->serial, key->description, data, datalen); | 71 | key->serial, key->description, data, datalen); |
| @@ -71,13 +75,77 @@ dns_resolver_instantiate(struct key *key, const void *_data, size_t datalen) | |||
| 71 | datalen--; | 75 | datalen--; |
| 72 | 76 | ||
| 73 | /* deal with any options embedded in the data */ | 77 | /* deal with any options embedded in the data */ |
| 78 | end = data + datalen; | ||
| 74 | opt = memchr(data, '#', datalen); | 79 | opt = memchr(data, '#', datalen); |
| 75 | if (!opt) { | 80 | if (!opt) { |
| 76 | kdebug("no options currently supported"); | 81 | /* no options: the entire data is the result */ |
| 77 | return -EINVAL; | 82 | kdebug("no options"); |
| 83 | result_len = datalen; | ||
| 84 | } else { | ||
| 85 | const char *next_opt; | ||
| 86 | |||
| 87 | result_len = opt - data; | ||
| 88 | opt++; | ||
| 89 | kdebug("options: '%s'", opt); | ||
| 90 | do { | ||
| 91 | const char *eq; | ||
| 92 | int opt_len, opt_nlen, opt_vlen, tmp; | ||
| 93 | |||
| 94 | next_opt = memchr(opt, '#', end - opt) ?: end; | ||
| 95 | opt_len = next_opt - opt; | ||
| 96 | if (!opt_len) { | ||
| 97 | printk(KERN_WARNING | ||
| 98 | "Empty option to dns_resolver key %d\n", | ||
| 99 | key->serial); | ||
| 100 | return -EINVAL; | ||
| 101 | } | ||
| 102 | |||
| 103 | eq = memchr(opt, '=', opt_len) ?: end; | ||
| 104 | opt_nlen = eq - opt; | ||
| 105 | eq++; | ||
| 106 | opt_vlen = next_opt - eq; /* will be -1 if no value */ | ||
| 107 | |||
| 108 | tmp = opt_vlen >= 0 ? opt_vlen : 0; | ||
| 109 | kdebug("option '%*.*s' val '%*.*s'", | ||
| 110 | opt_nlen, opt_nlen, opt, tmp, tmp, eq); | ||
| 111 | |||
| 112 | /* see if it's an error number representing a DNS error | ||
| 113 | * that's to be recorded as the result in this key */ | ||
| 114 | if (opt_nlen == sizeof(DNS_ERRORNO_OPTION) - 1 && | ||
| 115 | memcmp(opt, DNS_ERRORNO_OPTION, opt_nlen) == 0) { | ||
| 116 | kdebug("dns error number option"); | ||
| 117 | if (opt_vlen <= 0) | ||
| 118 | goto bad_option_value; | ||
| 119 | |||
| 120 | ret = strict_strtoul(eq, 10, &derrno); | ||
| 121 | if (ret < 0) | ||
| 122 | goto bad_option_value; | ||
| 123 | |||
| 124 | if (derrno < 1 || derrno > 511) | ||
| 125 | goto bad_option_value; | ||
| 126 | |||
| 127 | kdebug("dns error no. = %lu", derrno); | ||
| 128 | key->type_data.x[0] = -derrno; | ||
| 129 | continue; | ||
| 130 | } | ||
| 131 | |||
| 132 | bad_option_value: | ||
| 133 | printk(KERN_WARNING | ||
| 134 | "Option '%*.*s' to dns_resolver key %d:" | ||
| 135 | " bad/missing value\n", | ||
| 136 | opt_nlen, opt_nlen, opt, key->serial); | ||
| 137 | return -EINVAL; | ||
| 138 | } while (opt = next_opt + 1, opt < end); | ||
| 139 | } | ||
| 140 | |||
| 141 | /* don't cache the result if we're caching an error saying there's no | ||
| 142 | * result */ | ||
| 143 | if (key->type_data.x[0]) { | ||
| 144 | kleave(" = 0 [h_error %ld]", key->type_data.x[0]); | ||
| 145 | return 0; | ||
| 78 | } | 146 | } |
| 79 | 147 | ||
| 80 | result_len = datalen; | 148 | kdebug("store result"); |
| 81 | ret = key_payload_reserve(key, result_len); | 149 | ret = key_payload_reserve(key, result_len); |
| 82 | if (ret < 0) | 150 | if (ret < 0) |
| 83 | return -EINVAL; | 151 | return -EINVAL; |
| @@ -135,13 +203,27 @@ no_match: | |||
| 135 | return ret; | 203 | return ret; |
| 136 | } | 204 | } |
| 137 | 205 | ||
| 206 | /* | ||
| 207 | * Describe a DNS key | ||
| 208 | */ | ||
| 209 | static void dns_resolver_describe(const struct key *key, struct seq_file *m) | ||
| 210 | { | ||
| 211 | int err = key->type_data.x[0]; | ||
| 212 | |||
| 213 | seq_puts(m, key->description); | ||
| 214 | if (err) | ||
| 215 | seq_printf(m, ": %d", err); | ||
| 216 | else | ||
| 217 | seq_printf(m, ": %u", key->datalen); | ||
| 218 | } | ||
| 219 | |||
| 138 | struct key_type key_type_dns_resolver = { | 220 | struct key_type key_type_dns_resolver = { |
| 139 | .name = "dns_resolver", | 221 | .name = "dns_resolver", |
| 140 | .instantiate = dns_resolver_instantiate, | 222 | .instantiate = dns_resolver_instantiate, |
| 141 | .match = dns_resolver_match, | 223 | .match = dns_resolver_match, |
| 142 | .revoke = user_revoke, | 224 | .revoke = user_revoke, |
| 143 | .destroy = user_destroy, | 225 | .destroy = user_destroy, |
| 144 | .describe = user_describe, | 226 | .describe = dns_resolver_describe, |
| 145 | .read = user_read, | 227 | .read = user_read, |
| 146 | }; | 228 | }; |
| 147 | 229 | ||
diff --git a/net/dns_resolver/dns_query.c b/net/dns_resolver/dns_query.c index 03d5255f5cf2..c32be292c7e3 100644 --- a/net/dns_resolver/dns_query.c +++ b/net/dns_resolver/dns_query.c | |||
| @@ -136,6 +136,11 @@ int dns_query(const char *type, const char *name, size_t namelen, | |||
| 136 | if (ret < 0) | 136 | if (ret < 0) |
| 137 | goto put; | 137 | goto put; |
| 138 | 138 | ||
| 139 | /* If the DNS server gave an error, return that to the caller */ | ||
| 140 | ret = rkey->type_data.x[0]; | ||
| 141 | if (ret) | ||
| 142 | goto put; | ||
| 143 | |||
| 139 | upayload = rcu_dereference_protected(rkey->payload.data, | 144 | upayload = rcu_dereference_protected(rkey->payload.data, |
| 140 | lockdep_is_held(&rkey->sem)); | 145 | lockdep_is_held(&rkey->sem)); |
| 141 | len = upayload->datalen; | 146 | len = upayload->datalen; |
diff --git a/net/dsa/Kconfig b/net/dsa/Kconfig index 11201784d29a..87bb5f4de0e8 100644 --- a/net/dsa/Kconfig +++ b/net/dsa/Kconfig | |||
| @@ -1,7 +1,7 @@ | |||
| 1 | menuconfig NET_DSA | 1 | menuconfig NET_DSA |
| 2 | bool "Distributed Switch Architecture support" | 2 | bool "Distributed Switch Architecture support" |
| 3 | default n | 3 | default n |
| 4 | depends on EXPERIMENTAL && NET_ETHERNET && !S390 | 4 | depends on EXPERIMENTAL && NETDEVICES && !S390 |
| 5 | select PHYLIB | 5 | select PHYLIB |
| 6 | ---help--- | 6 | ---help--- |
| 7 | This allows you to use hardware switch chips that use | 7 | This allows you to use hardware switch chips that use |
diff --git a/net/ipv4/tcp_input.c b/net/ipv4/tcp_input.c index 3c426cb318e7..e663b78a2ef6 100644 --- a/net/ipv4/tcp_input.c +++ b/net/ipv4/tcp_input.c | |||
| @@ -3930,7 +3930,7 @@ u8 *tcp_parse_md5sig_option(struct tcphdr *th) | |||
| 3930 | if (opsize < 2 || opsize > length) | 3930 | if (opsize < 2 || opsize > length) |
| 3931 | return NULL; | 3931 | return NULL; |
| 3932 | if (opcode == TCPOPT_MD5SIG) | 3932 | if (opcode == TCPOPT_MD5SIG) |
| 3933 | return ptr; | 3933 | return opsize == TCPOLEN_MD5SIG ? ptr : NULL; |
| 3934 | } | 3934 | } |
| 3935 | ptr += opsize - 2; | 3935 | ptr += opsize - 2; |
| 3936 | length -= opsize; | 3936 | length -= opsize; |
diff --git a/net/irda/irnet/irnet_ppp.c b/net/irda/irnet/irnet_ppp.c index 800bc53b7f63..dfe7b38dd4af 100644 --- a/net/irda/irnet/irnet_ppp.c +++ b/net/irda/irnet/irnet_ppp.c | |||
| @@ -20,7 +20,7 @@ | |||
| 20 | /* Please put other headers in irnet.h - Thanks */ | 20 | /* Please put other headers in irnet.h - Thanks */ |
| 21 | 21 | ||
| 22 | /* Generic PPP callbacks (to call us) */ | 22 | /* Generic PPP callbacks (to call us) */ |
| 23 | static struct ppp_channel_ops irnet_ppp_ops = { | 23 | static const struct ppp_channel_ops irnet_ppp_ops = { |
| 24 | .start_xmit = ppp_irnet_send, | 24 | .start_xmit = ppp_irnet_send, |
| 25 | .ioctl = ppp_irnet_ioctl | 25 | .ioctl = ppp_irnet_ioctl |
| 26 | }; | 26 | }; |
diff --git a/net/l2tp/l2tp_ppp.c b/net/l2tp/l2tp_ppp.c index 90d82b3f2889..ff954b3e94b6 100644 --- a/net/l2tp/l2tp_ppp.c +++ b/net/l2tp/l2tp_ppp.c | |||
| @@ -135,7 +135,10 @@ struct pppol2tp_session { | |||
| 135 | 135 | ||
| 136 | static int pppol2tp_xmit(struct ppp_channel *chan, struct sk_buff *skb); | 136 | static int pppol2tp_xmit(struct ppp_channel *chan, struct sk_buff *skb); |
| 137 | 137 | ||
| 138 | static struct ppp_channel_ops pppol2tp_chan_ops = { pppol2tp_xmit , NULL }; | 138 | static const struct ppp_channel_ops pppol2tp_chan_ops = { |
| 139 | .start_xmit = pppol2tp_xmit, | ||
| 140 | }; | ||
| 141 | |||
| 139 | static const struct proto_ops pppol2tp_ops; | 142 | static const struct proto_ops pppol2tp_ops; |
| 140 | 143 | ||
| 141 | /* Helpers to obtain tunnel/session contexts from sockets. | 144 | /* Helpers to obtain tunnel/session contexts from sockets. |
diff --git a/net/mac80211/main.c b/net/mac80211/main.c index 7cc4f913a431..798a91b100cc 100644 --- a/net/mac80211/main.c +++ b/net/mac80211/main.c | |||
| @@ -685,10 +685,12 @@ int ieee80211_register_hw(struct ieee80211_hw *hw) | |||
| 685 | 685 | ||
| 686 | return 0; | 686 | return 0; |
| 687 | 687 | ||
| 688 | #ifdef CONFIG_INET | ||
| 688 | fail_ifa: | 689 | fail_ifa: |
| 689 | pm_qos_remove_notifier(PM_QOS_NETWORK_LATENCY, | 690 | pm_qos_remove_notifier(PM_QOS_NETWORK_LATENCY, |
| 690 | &local->network_latency_notifier); | 691 | &local->network_latency_notifier); |
| 691 | rtnl_lock(); | 692 | rtnl_lock(); |
| 693 | #endif | ||
| 692 | fail_pm_qos: | 694 | fail_pm_qos: |
| 693 | ieee80211_led_exit(local); | 695 | ieee80211_led_exit(local); |
| 694 | ieee80211_remove_interfaces(local); | 696 | ieee80211_remove_interfaces(local); |
diff --git a/net/mac80211/rate.c b/net/mac80211/rate.c index 6d0bd198af19..be04d46110fe 100644 --- a/net/mac80211/rate.c +++ b/net/mac80211/rate.c | |||
| @@ -103,6 +103,7 @@ ieee80211_rate_control_ops_get(const char *name) | |||
| 103 | struct rate_control_ops *ops; | 103 | struct rate_control_ops *ops; |
| 104 | const char *alg_name; | 104 | const char *alg_name; |
| 105 | 105 | ||
| 106 | kparam_block_sysfs_write(ieee80211_default_rc_algo); | ||
| 106 | if (!name) | 107 | if (!name) |
| 107 | alg_name = ieee80211_default_rc_algo; | 108 | alg_name = ieee80211_default_rc_algo; |
| 108 | else | 109 | else |
| @@ -120,6 +121,7 @@ ieee80211_rate_control_ops_get(const char *name) | |||
| 120 | /* try built-in one if specific alg requested but not found */ | 121 | /* try built-in one if specific alg requested but not found */ |
| 121 | if (!ops && strlen(CONFIG_MAC80211_RC_DEFAULT)) | 122 | if (!ops && strlen(CONFIG_MAC80211_RC_DEFAULT)) |
| 122 | ops = ieee80211_try_rate_control_ops_get(CONFIG_MAC80211_RC_DEFAULT); | 123 | ops = ieee80211_try_rate_control_ops_get(CONFIG_MAC80211_RC_DEFAULT); |
| 124 | kparam_unblock_sysfs_write(ieee80211_default_rc_algo); | ||
| 123 | 125 | ||
| 124 | return ops; | 126 | return ops; |
| 125 | } | 127 | } |
diff --git a/net/mac80211/scan.c b/net/mac80211/scan.c index 41f20fb7e670..872d7b6ef6b3 100644 --- a/net/mac80211/scan.c +++ b/net/mac80211/scan.c | |||
| @@ -400,19 +400,7 @@ static int __ieee80211_start_scan(struct ieee80211_sub_if_data *sdata, | |||
| 400 | else | 400 | else |
| 401 | __set_bit(SCAN_SW_SCANNING, &local->scanning); | 401 | __set_bit(SCAN_SW_SCANNING, &local->scanning); |
| 402 | 402 | ||
| 403 | /* | ||
| 404 | * Kicking off the scan need not be protected, | ||
| 405 | * only the scan variable stuff, since now | ||
| 406 | * local->scan_req is assigned and other callers | ||
| 407 | * will abort their scan attempts. | ||
| 408 | * | ||
| 409 | * This avoids too many locking dependencies | ||
| 410 | * so that the scan completed calls have more | ||
| 411 | * locking freedom. | ||
| 412 | */ | ||
| 413 | |||
| 414 | ieee80211_recalc_idle(local); | 403 | ieee80211_recalc_idle(local); |
| 415 | mutex_unlock(&local->scan_mtx); | ||
| 416 | 404 | ||
| 417 | if (local->ops->hw_scan) { | 405 | if (local->ops->hw_scan) { |
| 418 | WARN_ON(!ieee80211_prep_hw_scan(local)); | 406 | WARN_ON(!ieee80211_prep_hw_scan(local)); |
| @@ -420,8 +408,6 @@ static int __ieee80211_start_scan(struct ieee80211_sub_if_data *sdata, | |||
| 420 | } else | 408 | } else |
| 421 | rc = ieee80211_start_sw_scan(local); | 409 | rc = ieee80211_start_sw_scan(local); |
| 422 | 410 | ||
| 423 | mutex_lock(&local->scan_mtx); | ||
| 424 | |||
| 425 | if (rc) { | 411 | if (rc) { |
| 426 | kfree(local->hw_scan_req); | 412 | kfree(local->hw_scan_req); |
| 427 | local->hw_scan_req = NULL; | 413 | local->hw_scan_req = NULL; |
diff --git a/net/rxrpc/ar-ack.c b/net/rxrpc/ar-ack.c index 2714da167fb8..b6ffe4e1b84a 100644 --- a/net/rxrpc/ar-ack.c +++ b/net/rxrpc/ar-ack.c | |||
| @@ -245,6 +245,9 @@ static void rxrpc_resend_timer(struct rxrpc_call *call) | |||
| 245 | _enter("%d,%d,%d", | 245 | _enter("%d,%d,%d", |
| 246 | call->acks_tail, call->acks_unacked, call->acks_head); | 246 | call->acks_tail, call->acks_unacked, call->acks_head); |
| 247 | 247 | ||
| 248 | if (call->state >= RXRPC_CALL_COMPLETE) | ||
| 249 | return; | ||
| 250 | |||
| 248 | resend = 0; | 251 | resend = 0; |
| 249 | resend_at = 0; | 252 | resend_at = 0; |
| 250 | 253 | ||
diff --git a/net/rxrpc/ar-call.c b/net/rxrpc/ar-call.c index 909d092de9f4..bf656c230ba9 100644 --- a/net/rxrpc/ar-call.c +++ b/net/rxrpc/ar-call.c | |||
| @@ -786,6 +786,7 @@ static void rxrpc_call_life_expired(unsigned long _call) | |||
| 786 | 786 | ||
| 787 | /* | 787 | /* |
| 788 | * handle resend timer expiry | 788 | * handle resend timer expiry |
| 789 | * - may not take call->state_lock as this can deadlock against del_timer_sync() | ||
| 789 | */ | 790 | */ |
| 790 | static void rxrpc_resend_time_expired(unsigned long _call) | 791 | static void rxrpc_resend_time_expired(unsigned long _call) |
| 791 | { | 792 | { |
| @@ -796,12 +797,9 @@ static void rxrpc_resend_time_expired(unsigned long _call) | |||
| 796 | if (call->state >= RXRPC_CALL_COMPLETE) | 797 | if (call->state >= RXRPC_CALL_COMPLETE) |
| 797 | return; | 798 | return; |
| 798 | 799 | ||
| 799 | read_lock_bh(&call->state_lock); | ||
| 800 | clear_bit(RXRPC_CALL_RUN_RTIMER, &call->flags); | 800 | clear_bit(RXRPC_CALL_RUN_RTIMER, &call->flags); |
| 801 | if (call->state < RXRPC_CALL_COMPLETE && | 801 | if (!test_and_set_bit(RXRPC_CALL_RESEND_TIMER, &call->events)) |
| 802 | !test_and_set_bit(RXRPC_CALL_RESEND_TIMER, &call->events)) | ||
| 803 | rxrpc_queue_call(call); | 802 | rxrpc_queue_call(call); |
| 804 | read_unlock_bh(&call->state_lock); | ||
| 805 | } | 803 | } |
| 806 | 804 | ||
| 807 | /* | 805 | /* |
diff --git a/net/rxrpc/ar-internal.h b/net/rxrpc/ar-internal.h index 7043b294bb67..8e22bd345e71 100644 --- a/net/rxrpc/ar-internal.h +++ b/net/rxrpc/ar-internal.h | |||
| @@ -597,12 +597,6 @@ extern unsigned rxrpc_debug; | |||
| 597 | #define dbgprintk(FMT,...) \ | 597 | #define dbgprintk(FMT,...) \ |
| 598 | printk("[%-6.6s] "FMT"\n", current->comm ,##__VA_ARGS__) | 598 | printk("[%-6.6s] "FMT"\n", current->comm ,##__VA_ARGS__) |
| 599 | 599 | ||
| 600 | /* make sure we maintain the format strings, even when debugging is disabled */ | ||
| 601 | static inline __attribute__((format(printf,1,2))) | ||
| 602 | void _dbprintk(const char *fmt, ...) | ||
| 603 | { | ||
| 604 | } | ||
| 605 | |||
| 606 | #define kenter(FMT,...) dbgprintk("==> %s("FMT")",__func__ ,##__VA_ARGS__) | 600 | #define kenter(FMT,...) dbgprintk("==> %s("FMT")",__func__ ,##__VA_ARGS__) |
| 607 | #define kleave(FMT,...) dbgprintk("<== %s()"FMT"",__func__ ,##__VA_ARGS__) | 601 | #define kleave(FMT,...) dbgprintk("<== %s()"FMT"",__func__ ,##__VA_ARGS__) |
| 608 | #define kdebug(FMT,...) dbgprintk(" "FMT ,##__VA_ARGS__) | 602 | #define kdebug(FMT,...) dbgprintk(" "FMT ,##__VA_ARGS__) |
| @@ -655,11 +649,11 @@ do { \ | |||
| 655 | } while (0) | 649 | } while (0) |
| 656 | 650 | ||
| 657 | #else | 651 | #else |
| 658 | #define _enter(FMT,...) _dbprintk("==> %s("FMT")",__func__ ,##__VA_ARGS__) | 652 | #define _enter(FMT,...) no_printk("==> %s("FMT")",__func__ ,##__VA_ARGS__) |
| 659 | #define _leave(FMT,...) _dbprintk("<== %s()"FMT"",__func__ ,##__VA_ARGS__) | 653 | #define _leave(FMT,...) no_printk("<== %s()"FMT"",__func__ ,##__VA_ARGS__) |
| 660 | #define _debug(FMT,...) _dbprintk(" "FMT ,##__VA_ARGS__) | 654 | #define _debug(FMT,...) no_printk(" "FMT ,##__VA_ARGS__) |
| 661 | #define _proto(FMT,...) _dbprintk("### "FMT ,##__VA_ARGS__) | 655 | #define _proto(FMT,...) no_printk("### "FMT ,##__VA_ARGS__) |
| 662 | #define _net(FMT,...) _dbprintk("@@@ "FMT ,##__VA_ARGS__) | 656 | #define _net(FMT,...) no_printk("@@@ "FMT ,##__VA_ARGS__) |
| 663 | #endif | 657 | #endif |
| 664 | 658 | ||
| 665 | /* | 659 | /* |
diff --git a/net/sched/act_nat.c b/net/sched/act_nat.c index d0386a413e8d..509a2d53a99d 100644 --- a/net/sched/act_nat.c +++ b/net/sched/act_nat.c | |||
| @@ -114,6 +114,7 @@ static int tcf_nat(struct sk_buff *skb, struct tc_action *a, | |||
| 114 | int egress; | 114 | int egress; |
| 115 | int action; | 115 | int action; |
| 116 | int ihl; | 116 | int ihl; |
| 117 | int noff; | ||
| 117 | 118 | ||
| 118 | spin_lock(&p->tcf_lock); | 119 | spin_lock(&p->tcf_lock); |
| 119 | 120 | ||
| @@ -132,7 +133,8 @@ static int tcf_nat(struct sk_buff *skb, struct tc_action *a, | |||
| 132 | if (unlikely(action == TC_ACT_SHOT)) | 133 | if (unlikely(action == TC_ACT_SHOT)) |
| 133 | goto drop; | 134 | goto drop; |
| 134 | 135 | ||
| 135 | if (!pskb_may_pull(skb, sizeof(*iph))) | 136 | noff = skb_network_offset(skb); |
| 137 | if (!pskb_may_pull(skb, sizeof(*iph) + noff)) | ||
| 136 | goto drop; | 138 | goto drop; |
| 137 | 139 | ||
| 138 | iph = ip_hdr(skb); | 140 | iph = ip_hdr(skb); |
| @@ -144,7 +146,7 @@ static int tcf_nat(struct sk_buff *skb, struct tc_action *a, | |||
| 144 | 146 | ||
| 145 | if (!((old_addr ^ addr) & mask)) { | 147 | if (!((old_addr ^ addr) & mask)) { |
| 146 | if (skb_cloned(skb) && | 148 | if (skb_cloned(skb) && |
| 147 | !skb_clone_writable(skb, sizeof(*iph)) && | 149 | !skb_clone_writable(skb, sizeof(*iph) + noff) && |
| 148 | pskb_expand_head(skb, 0, 0, GFP_ATOMIC)) | 150 | pskb_expand_head(skb, 0, 0, GFP_ATOMIC)) |
| 149 | goto drop; | 151 | goto drop; |
| 150 | 152 | ||
| @@ -172,9 +174,9 @@ static int tcf_nat(struct sk_buff *skb, struct tc_action *a, | |||
| 172 | { | 174 | { |
| 173 | struct tcphdr *tcph; | 175 | struct tcphdr *tcph; |
| 174 | 176 | ||
| 175 | if (!pskb_may_pull(skb, ihl + sizeof(*tcph)) || | 177 | if (!pskb_may_pull(skb, ihl + sizeof(*tcph) + noff) || |
| 176 | (skb_cloned(skb) && | 178 | (skb_cloned(skb) && |
| 177 | !skb_clone_writable(skb, ihl + sizeof(*tcph)) && | 179 | !skb_clone_writable(skb, ihl + sizeof(*tcph) + noff) && |
| 178 | pskb_expand_head(skb, 0, 0, GFP_ATOMIC))) | 180 | pskb_expand_head(skb, 0, 0, GFP_ATOMIC))) |
| 179 | goto drop; | 181 | goto drop; |
| 180 | 182 | ||
| @@ -186,9 +188,9 @@ static int tcf_nat(struct sk_buff *skb, struct tc_action *a, | |||
| 186 | { | 188 | { |
| 187 | struct udphdr *udph; | 189 | struct udphdr *udph; |
| 188 | 190 | ||
| 189 | if (!pskb_may_pull(skb, ihl + sizeof(*udph)) || | 191 | if (!pskb_may_pull(skb, ihl + sizeof(*udph) + noff) || |
| 190 | (skb_cloned(skb) && | 192 | (skb_cloned(skb) && |
| 191 | !skb_clone_writable(skb, ihl + sizeof(*udph)) && | 193 | !skb_clone_writable(skb, ihl + sizeof(*udph) + noff) && |
| 192 | pskb_expand_head(skb, 0, 0, GFP_ATOMIC))) | 194 | pskb_expand_head(skb, 0, 0, GFP_ATOMIC))) |
| 193 | goto drop; | 195 | goto drop; |
| 194 | 196 | ||
| @@ -205,7 +207,7 @@ static int tcf_nat(struct sk_buff *skb, struct tc_action *a, | |||
| 205 | { | 207 | { |
| 206 | struct icmphdr *icmph; | 208 | struct icmphdr *icmph; |
| 207 | 209 | ||
| 208 | if (!pskb_may_pull(skb, ihl + sizeof(*icmph))) | 210 | if (!pskb_may_pull(skb, ihl + sizeof(*icmph) + noff)) |
| 209 | goto drop; | 211 | goto drop; |
| 210 | 212 | ||
| 211 | icmph = (void *)(skb_network_header(skb) + ihl); | 213 | icmph = (void *)(skb_network_header(skb) + ihl); |
| @@ -215,7 +217,8 @@ static int tcf_nat(struct sk_buff *skb, struct tc_action *a, | |||
| 215 | (icmph->type != ICMP_PARAMETERPROB)) | 217 | (icmph->type != ICMP_PARAMETERPROB)) |
| 216 | break; | 218 | break; |
| 217 | 219 | ||
| 218 | if (!pskb_may_pull(skb, ihl + sizeof(*icmph) + sizeof(*iph))) | 220 | if (!pskb_may_pull(skb, ihl + sizeof(*icmph) + sizeof(*iph) + |
| 221 | noff)) | ||
| 219 | goto drop; | 222 | goto drop; |
| 220 | 223 | ||
| 221 | icmph = (void *)(skb_network_header(skb) + ihl); | 224 | icmph = (void *)(skb_network_header(skb) + ihl); |
| @@ -229,8 +232,8 @@ static int tcf_nat(struct sk_buff *skb, struct tc_action *a, | |||
| 229 | break; | 232 | break; |
| 230 | 233 | ||
| 231 | if (skb_cloned(skb) && | 234 | if (skb_cloned(skb) && |
| 232 | !skb_clone_writable(skb, | 235 | !skb_clone_writable(skb, ihl + sizeof(*icmph) + |
| 233 | ihl + sizeof(*icmph) + sizeof(*iph)) && | 236 | sizeof(*iph) + noff) && |
| 234 | pskb_expand_head(skb, 0, 0, GFP_ATOMIC)) | 237 | pskb_expand_head(skb, 0, 0, GFP_ATOMIC)) |
| 235 | goto drop; | 238 | goto drop; |
| 236 | 239 | ||
diff --git a/net/sched/cls_flow.c b/net/sched/cls_flow.c index f73542d2cdd0..e17096e3913c 100644 --- a/net/sched/cls_flow.c +++ b/net/sched/cls_flow.c | |||
| @@ -65,37 +65,47 @@ static inline u32 addr_fold(void *addr) | |||
| 65 | return (a & 0xFFFFFFFF) ^ (BITS_PER_LONG > 32 ? a >> 32 : 0); | 65 | return (a & 0xFFFFFFFF) ^ (BITS_PER_LONG > 32 ? a >> 32 : 0); |
| 66 | } | 66 | } |
| 67 | 67 | ||
| 68 | static u32 flow_get_src(const struct sk_buff *skb) | 68 | static u32 flow_get_src(struct sk_buff *skb) |
| 69 | { | 69 | { |
| 70 | switch (skb->protocol) { | 70 | switch (skb->protocol) { |
| 71 | case htons(ETH_P_IP): | 71 | case htons(ETH_P_IP): |
| 72 | return ntohl(ip_hdr(skb)->saddr); | 72 | if (pskb_network_may_pull(skb, sizeof(struct iphdr))) |
| 73 | return ntohl(ip_hdr(skb)->saddr); | ||
| 74 | break; | ||
| 73 | case htons(ETH_P_IPV6): | 75 | case htons(ETH_P_IPV6): |
| 74 | return ntohl(ipv6_hdr(skb)->saddr.s6_addr32[3]); | 76 | if (pskb_network_may_pull(skb, sizeof(struct ipv6hdr))) |
| 75 | default: | 77 | return ntohl(ipv6_hdr(skb)->saddr.s6_addr32[3]); |
| 76 | return addr_fold(skb->sk); | 78 | break; |
| 77 | } | 79 | } |
| 80 | |||
| 81 | return addr_fold(skb->sk); | ||
| 78 | } | 82 | } |
| 79 | 83 | ||
| 80 | static u32 flow_get_dst(const struct sk_buff *skb) | 84 | static u32 flow_get_dst(struct sk_buff *skb) |
| 81 | { | 85 | { |
| 82 | switch (skb->protocol) { | 86 | switch (skb->protocol) { |
| 83 | case htons(ETH_P_IP): | 87 | case htons(ETH_P_IP): |
| 84 | return ntohl(ip_hdr(skb)->daddr); | 88 | if (pskb_network_may_pull(skb, sizeof(struct iphdr))) |
| 89 | return ntohl(ip_hdr(skb)->daddr); | ||
| 90 | break; | ||
| 85 | case htons(ETH_P_IPV6): | 91 | case htons(ETH_P_IPV6): |
| 86 | return ntohl(ipv6_hdr(skb)->daddr.s6_addr32[3]); | 92 | if (pskb_network_may_pull(skb, sizeof(struct ipv6hdr))) |
| 87 | default: | 93 | return ntohl(ipv6_hdr(skb)->daddr.s6_addr32[3]); |
| 88 | return addr_fold(skb_dst(skb)) ^ (__force u16)skb->protocol; | 94 | break; |
| 89 | } | 95 | } |
| 96 | |||
| 97 | return addr_fold(skb_dst(skb)) ^ (__force u16)skb->protocol; | ||
| 90 | } | 98 | } |
| 91 | 99 | ||
| 92 | static u32 flow_get_proto(const struct sk_buff *skb) | 100 | static u32 flow_get_proto(struct sk_buff *skb) |
| 93 | { | 101 | { |
| 94 | switch (skb->protocol) { | 102 | switch (skb->protocol) { |
| 95 | case htons(ETH_P_IP): | 103 | case htons(ETH_P_IP): |
| 96 | return ip_hdr(skb)->protocol; | 104 | return pskb_network_may_pull(skb, sizeof(struct iphdr)) ? |
| 105 | ip_hdr(skb)->protocol : 0; | ||
| 97 | case htons(ETH_P_IPV6): | 106 | case htons(ETH_P_IPV6): |
| 98 | return ipv6_hdr(skb)->nexthdr; | 107 | return pskb_network_may_pull(skb, sizeof(struct ipv6hdr)) ? |
| 108 | ipv6_hdr(skb)->nexthdr : 0; | ||
| 99 | default: | 109 | default: |
| 100 | return 0; | 110 | return 0; |
| 101 | } | 111 | } |
| @@ -116,58 +126,64 @@ static int has_ports(u8 protocol) | |||
| 116 | } | 126 | } |
| 117 | } | 127 | } |
| 118 | 128 | ||
| 119 | static u32 flow_get_proto_src(const struct sk_buff *skb) | 129 | static u32 flow_get_proto_src(struct sk_buff *skb) |
| 120 | { | 130 | { |
| 121 | u32 res = 0; | ||
| 122 | |||
| 123 | switch (skb->protocol) { | 131 | switch (skb->protocol) { |
| 124 | case htons(ETH_P_IP): { | 132 | case htons(ETH_P_IP): { |
| 125 | struct iphdr *iph = ip_hdr(skb); | 133 | struct iphdr *iph; |
| 126 | 134 | ||
| 135 | if (!pskb_network_may_pull(skb, sizeof(*iph))) | ||
| 136 | break; | ||
| 137 | iph = ip_hdr(skb); | ||
| 127 | if (!(iph->frag_off&htons(IP_MF|IP_OFFSET)) && | 138 | if (!(iph->frag_off&htons(IP_MF|IP_OFFSET)) && |
| 128 | has_ports(iph->protocol)) | 139 | has_ports(iph->protocol) && |
| 129 | res = ntohs(*(__be16 *)((void *)iph + iph->ihl * 4)); | 140 | pskb_network_may_pull(skb, iph->ihl * 4 + 2)) |
| 141 | return ntohs(*(__be16 *)((void *)iph + iph->ihl * 4)); | ||
| 130 | break; | 142 | break; |
| 131 | } | 143 | } |
| 132 | case htons(ETH_P_IPV6): { | 144 | case htons(ETH_P_IPV6): { |
| 133 | struct ipv6hdr *iph = ipv6_hdr(skb); | 145 | struct ipv6hdr *iph; |
| 134 | 146 | ||
| 147 | if (!pskb_network_may_pull(skb, sizeof(*iph) + 2)) | ||
| 148 | break; | ||
| 149 | iph = ipv6_hdr(skb); | ||
| 135 | if (has_ports(iph->nexthdr)) | 150 | if (has_ports(iph->nexthdr)) |
| 136 | res = ntohs(*(__be16 *)&iph[1]); | 151 | return ntohs(*(__be16 *)&iph[1]); |
| 137 | break; | 152 | break; |
| 138 | } | 153 | } |
| 139 | default: | ||
| 140 | res = addr_fold(skb->sk); | ||
| 141 | } | 154 | } |
| 142 | 155 | ||
| 143 | return res; | 156 | return addr_fold(skb->sk); |
| 144 | } | 157 | } |
| 145 | 158 | ||
| 146 | static u32 flow_get_proto_dst(const struct sk_buff *skb) | 159 | static u32 flow_get_proto_dst(struct sk_buff *skb) |
| 147 | { | 160 | { |
| 148 | u32 res = 0; | ||
| 149 | |||
| 150 | switch (skb->protocol) { | 161 | switch (skb->protocol) { |
| 151 | case htons(ETH_P_IP): { | 162 | case htons(ETH_P_IP): { |
| 152 | struct iphdr *iph = ip_hdr(skb); | 163 | struct iphdr *iph; |
| 153 | 164 | ||
| 165 | if (!pskb_network_may_pull(skb, sizeof(*iph))) | ||
| 166 | break; | ||
| 167 | iph = ip_hdr(skb); | ||
| 154 | if (!(iph->frag_off&htons(IP_MF|IP_OFFSET)) && | 168 | if (!(iph->frag_off&htons(IP_MF|IP_OFFSET)) && |
| 155 | has_ports(iph->protocol)) | 169 | has_ports(iph->protocol) && |
| 156 | res = ntohs(*(__be16 *)((void *)iph + iph->ihl * 4 + 2)); | 170 | pskb_network_may_pull(skb, iph->ihl * 4 + 4)) |
| 171 | return ntohs(*(__be16 *)((void *)iph + iph->ihl * 4 + 2)); | ||
| 157 | break; | 172 | break; |
| 158 | } | 173 | } |
| 159 | case htons(ETH_P_IPV6): { | 174 | case htons(ETH_P_IPV6): { |
| 160 | struct ipv6hdr *iph = ipv6_hdr(skb); | 175 | struct ipv6hdr *iph; |
| 161 | 176 | ||
| 177 | if (!pskb_network_may_pull(skb, sizeof(*iph) + 4)) | ||
| 178 | break; | ||
| 179 | iph = ipv6_hdr(skb); | ||
| 162 | if (has_ports(iph->nexthdr)) | 180 | if (has_ports(iph->nexthdr)) |
| 163 | res = ntohs(*(__be16 *)((void *)&iph[1] + 2)); | 181 | return ntohs(*(__be16 *)((void *)&iph[1] + 2)); |
| 164 | break; | 182 | break; |
| 165 | } | 183 | } |
| 166 | default: | ||
| 167 | res = addr_fold(skb_dst(skb)) ^ (__force u16)skb->protocol; | ||
| 168 | } | 184 | } |
| 169 | 185 | ||
| 170 | return res; | 186 | return addr_fold(skb_dst(skb)) ^ (__force u16)skb->protocol; |
| 171 | } | 187 | } |
| 172 | 188 | ||
| 173 | static u32 flow_get_iif(const struct sk_buff *skb) | 189 | static u32 flow_get_iif(const struct sk_buff *skb) |
| @@ -211,7 +227,7 @@ static u32 flow_get_nfct(const struct sk_buff *skb) | |||
| 211 | }) | 227 | }) |
| 212 | #endif | 228 | #endif |
| 213 | 229 | ||
| 214 | static u32 flow_get_nfct_src(const struct sk_buff *skb) | 230 | static u32 flow_get_nfct_src(struct sk_buff *skb) |
| 215 | { | 231 | { |
| 216 | switch (skb->protocol) { | 232 | switch (skb->protocol) { |
| 217 | case htons(ETH_P_IP): | 233 | case htons(ETH_P_IP): |
| @@ -223,7 +239,7 @@ fallback: | |||
| 223 | return flow_get_src(skb); | 239 | return flow_get_src(skb); |
| 224 | } | 240 | } |
| 225 | 241 | ||
| 226 | static u32 flow_get_nfct_dst(const struct sk_buff *skb) | 242 | static u32 flow_get_nfct_dst(struct sk_buff *skb) |
| 227 | { | 243 | { |
| 228 | switch (skb->protocol) { | 244 | switch (skb->protocol) { |
| 229 | case htons(ETH_P_IP): | 245 | case htons(ETH_P_IP): |
| @@ -235,14 +251,14 @@ fallback: | |||
| 235 | return flow_get_dst(skb); | 251 | return flow_get_dst(skb); |
| 236 | } | 252 | } |
| 237 | 253 | ||
| 238 | static u32 flow_get_nfct_proto_src(const struct sk_buff *skb) | 254 | static u32 flow_get_nfct_proto_src(struct sk_buff *skb) |
| 239 | { | 255 | { |
| 240 | return ntohs(CTTUPLE(skb, src.u.all)); | 256 | return ntohs(CTTUPLE(skb, src.u.all)); |
| 241 | fallback: | 257 | fallback: |
| 242 | return flow_get_proto_src(skb); | 258 | return flow_get_proto_src(skb); |
| 243 | } | 259 | } |
| 244 | 260 | ||
| 245 | static u32 flow_get_nfct_proto_dst(const struct sk_buff *skb) | 261 | static u32 flow_get_nfct_proto_dst(struct sk_buff *skb) |
| 246 | { | 262 | { |
| 247 | return ntohs(CTTUPLE(skb, dst.u.all)); | 263 | return ntohs(CTTUPLE(skb, dst.u.all)); |
| 248 | fallback: | 264 | fallback: |
| @@ -281,7 +297,7 @@ static u32 flow_get_vlan_tag(const struct sk_buff *skb) | |||
| 281 | return tag & VLAN_VID_MASK; | 297 | return tag & VLAN_VID_MASK; |
| 282 | } | 298 | } |
| 283 | 299 | ||
| 284 | static u32 flow_key_get(const struct sk_buff *skb, int key) | 300 | static u32 flow_key_get(struct sk_buff *skb, int key) |
| 285 | { | 301 | { |
| 286 | switch (key) { | 302 | switch (key) { |
| 287 | case FLOW_KEY_SRC: | 303 | case FLOW_KEY_SRC: |
diff --git a/net/sched/cls_rsvp.h b/net/sched/cls_rsvp.h index dd9414e44200..425a1790b048 100644 --- a/net/sched/cls_rsvp.h +++ b/net/sched/cls_rsvp.h | |||
| @@ -143,9 +143,17 @@ static int rsvp_classify(struct sk_buff *skb, struct tcf_proto *tp, | |||
| 143 | u8 tunnelid = 0; | 143 | u8 tunnelid = 0; |
| 144 | u8 *xprt; | 144 | u8 *xprt; |
| 145 | #if RSVP_DST_LEN == 4 | 145 | #if RSVP_DST_LEN == 4 |
| 146 | struct ipv6hdr *nhptr = ipv6_hdr(skb); | 146 | struct ipv6hdr *nhptr; |
| 147 | |||
| 148 | if (!pskb_network_may_pull(skb, sizeof(*nhptr))) | ||
| 149 | return -1; | ||
| 150 | nhptr = ipv6_hdr(skb); | ||
| 147 | #else | 151 | #else |
| 148 | struct iphdr *nhptr = ip_hdr(skb); | 152 | struct iphdr *nhptr; |
| 153 | |||
| 154 | if (!pskb_network_may_pull(skb, sizeof(*nhptr))) | ||
| 155 | return -1; | ||
| 156 | nhptr = ip_hdr(skb); | ||
| 149 | #endif | 157 | #endif |
| 150 | 158 | ||
| 151 | restart: | 159 | restart: |
diff --git a/net/sched/sch_api.c b/net/sched/sch_api.c index b9e8c3b7d406..408eea7086aa 100644 --- a/net/sched/sch_api.c +++ b/net/sched/sch_api.c | |||
| @@ -150,22 +150,34 @@ int register_qdisc(struct Qdisc_ops *qops) | |||
| 150 | if (qops->enqueue == NULL) | 150 | if (qops->enqueue == NULL) |
| 151 | qops->enqueue = noop_qdisc_ops.enqueue; | 151 | qops->enqueue = noop_qdisc_ops.enqueue; |
| 152 | if (qops->peek == NULL) { | 152 | if (qops->peek == NULL) { |
| 153 | if (qops->dequeue == NULL) { | 153 | if (qops->dequeue == NULL) |
| 154 | qops->peek = noop_qdisc_ops.peek; | 154 | qops->peek = noop_qdisc_ops.peek; |
| 155 | } else { | 155 | else |
| 156 | rc = -EINVAL; | 156 | goto out_einval; |
| 157 | goto out; | ||
| 158 | } | ||
| 159 | } | 157 | } |
| 160 | if (qops->dequeue == NULL) | 158 | if (qops->dequeue == NULL) |
| 161 | qops->dequeue = noop_qdisc_ops.dequeue; | 159 | qops->dequeue = noop_qdisc_ops.dequeue; |
| 162 | 160 | ||
| 161 | if (qops->cl_ops) { | ||
| 162 | const struct Qdisc_class_ops *cops = qops->cl_ops; | ||
| 163 | |||
| 164 | if (!(cops->get && cops->put && cops->walk && cops->leaf)) | ||
| 165 | goto out_einval; | ||
| 166 | |||
| 167 | if (cops->tcf_chain && !(cops->bind_tcf && cops->unbind_tcf)) | ||
| 168 | goto out_einval; | ||
| 169 | } | ||
| 170 | |||
| 163 | qops->next = NULL; | 171 | qops->next = NULL; |
| 164 | *qp = qops; | 172 | *qp = qops; |
| 165 | rc = 0; | 173 | rc = 0; |
| 166 | out: | 174 | out: |
| 167 | write_unlock(&qdisc_mod_lock); | 175 | write_unlock(&qdisc_mod_lock); |
| 168 | return rc; | 176 | return rc; |
| 177 | |||
| 178 | out_einval: | ||
| 179 | rc = -EINVAL; | ||
| 180 | goto out; | ||
| 169 | } | 181 | } |
| 170 | EXPORT_SYMBOL(register_qdisc); | 182 | EXPORT_SYMBOL(register_qdisc); |
| 171 | 183 | ||
diff --git a/net/sched/sch_atm.c b/net/sched/sch_atm.c index e114f23d5eae..340662789529 100644 --- a/net/sched/sch_atm.c +++ b/net/sched/sch_atm.c | |||
| @@ -418,7 +418,7 @@ static int atm_tc_enqueue(struct sk_buff *skb, struct Qdisc *sch) | |||
| 418 | } | 418 | } |
| 419 | 419 | ||
| 420 | ret = qdisc_enqueue(skb, flow->q); | 420 | ret = qdisc_enqueue(skb, flow->q); |
| 421 | if (ret != 0) { | 421 | if (ret != NET_XMIT_SUCCESS) { |
| 422 | drop: __maybe_unused | 422 | drop: __maybe_unused |
| 423 | if (net_xmit_drop_count(ret)) { | 423 | if (net_xmit_drop_count(ret)) { |
| 424 | sch->qstats.drops++; | 424 | sch->qstats.drops++; |
| @@ -442,7 +442,7 @@ drop: __maybe_unused | |||
| 442 | */ | 442 | */ |
| 443 | if (flow == &p->link) { | 443 | if (flow == &p->link) { |
| 444 | sch->q.qlen++; | 444 | sch->q.qlen++; |
| 445 | return 0; | 445 | return NET_XMIT_SUCCESS; |
| 446 | } | 446 | } |
| 447 | tasklet_schedule(&p->task); | 447 | tasklet_schedule(&p->task); |
| 448 | return NET_XMIT_SUCCESS | __NET_XMIT_BYPASS; | 448 | return NET_XMIT_SUCCESS | __NET_XMIT_BYPASS; |
diff --git a/net/sched/sch_sfq.c b/net/sched/sch_sfq.c index c65762823f5e..201cbac2b32c 100644 --- a/net/sched/sch_sfq.c +++ b/net/sched/sch_sfq.c | |||
| @@ -122,7 +122,11 @@ static unsigned sfq_hash(struct sfq_sched_data *q, struct sk_buff *skb) | |||
| 122 | switch (skb->protocol) { | 122 | switch (skb->protocol) { |
| 123 | case htons(ETH_P_IP): | 123 | case htons(ETH_P_IP): |
| 124 | { | 124 | { |
| 125 | const struct iphdr *iph = ip_hdr(skb); | 125 | const struct iphdr *iph; |
| 126 | |||
| 127 | if (!pskb_network_may_pull(skb, sizeof(*iph))) | ||
| 128 | goto err; | ||
| 129 | iph = ip_hdr(skb); | ||
| 126 | h = (__force u32)iph->daddr; | 130 | h = (__force u32)iph->daddr; |
| 127 | h2 = (__force u32)iph->saddr ^ iph->protocol; | 131 | h2 = (__force u32)iph->saddr ^ iph->protocol; |
| 128 | if (!(iph->frag_off&htons(IP_MF|IP_OFFSET)) && | 132 | if (!(iph->frag_off&htons(IP_MF|IP_OFFSET)) && |
| @@ -131,25 +135,32 @@ static unsigned sfq_hash(struct sfq_sched_data *q, struct sk_buff *skb) | |||
| 131 | iph->protocol == IPPROTO_UDPLITE || | 135 | iph->protocol == IPPROTO_UDPLITE || |
| 132 | iph->protocol == IPPROTO_SCTP || | 136 | iph->protocol == IPPROTO_SCTP || |
| 133 | iph->protocol == IPPROTO_DCCP || | 137 | iph->protocol == IPPROTO_DCCP || |
| 134 | iph->protocol == IPPROTO_ESP)) | 138 | iph->protocol == IPPROTO_ESP) && |
| 139 | pskb_network_may_pull(skb, iph->ihl * 4 + 4)) | ||
| 135 | h2 ^= *(((u32*)iph) + iph->ihl); | 140 | h2 ^= *(((u32*)iph) + iph->ihl); |
| 136 | break; | 141 | break; |
| 137 | } | 142 | } |
| 138 | case htons(ETH_P_IPV6): | 143 | case htons(ETH_P_IPV6): |
| 139 | { | 144 | { |
| 140 | struct ipv6hdr *iph = ipv6_hdr(skb); | 145 | struct ipv6hdr *iph; |
| 146 | |||
| 147 | if (!pskb_network_may_pull(skb, sizeof(*iph))) | ||
| 148 | goto err; | ||
| 149 | iph = ipv6_hdr(skb); | ||
| 141 | h = (__force u32)iph->daddr.s6_addr32[3]; | 150 | h = (__force u32)iph->daddr.s6_addr32[3]; |
| 142 | h2 = (__force u32)iph->saddr.s6_addr32[3] ^ iph->nexthdr; | 151 | h2 = (__force u32)iph->saddr.s6_addr32[3] ^ iph->nexthdr; |
| 143 | if (iph->nexthdr == IPPROTO_TCP || | 152 | if ((iph->nexthdr == IPPROTO_TCP || |
| 144 | iph->nexthdr == IPPROTO_UDP || | 153 | iph->nexthdr == IPPROTO_UDP || |
| 145 | iph->nexthdr == IPPROTO_UDPLITE || | 154 | iph->nexthdr == IPPROTO_UDPLITE || |
| 146 | iph->nexthdr == IPPROTO_SCTP || | 155 | iph->nexthdr == IPPROTO_SCTP || |
| 147 | iph->nexthdr == IPPROTO_DCCP || | 156 | iph->nexthdr == IPPROTO_DCCP || |
| 148 | iph->nexthdr == IPPROTO_ESP) | 157 | iph->nexthdr == IPPROTO_ESP) && |
| 158 | pskb_network_may_pull(skb, sizeof(*iph) + 4)) | ||
| 149 | h2 ^= *(u32*)&iph[1]; | 159 | h2 ^= *(u32*)&iph[1]; |
| 150 | break; | 160 | break; |
| 151 | } | 161 | } |
| 152 | default: | 162 | default: |
| 163 | err: | ||
| 153 | h = (unsigned long)skb_dst(skb) ^ (__force u32)skb->protocol; | 164 | h = (unsigned long)skb_dst(skb) ^ (__force u32)skb->protocol; |
| 154 | h2 = (unsigned long)skb->sk; | 165 | h2 = (unsigned long)skb->sk; |
| 155 | } | 166 | } |
| @@ -323,7 +334,7 @@ sfq_enqueue(struct sk_buff *skb, struct Qdisc *sch) | |||
| 323 | if (++sch->q.qlen <= q->limit) { | 334 | if (++sch->q.qlen <= q->limit) { |
| 324 | sch->bstats.bytes += qdisc_pkt_len(skb); | 335 | sch->bstats.bytes += qdisc_pkt_len(skb); |
| 325 | sch->bstats.packets++; | 336 | sch->bstats.packets++; |
| 326 | return 0; | 337 | return NET_XMIT_SUCCESS; |
| 327 | } | 338 | } |
| 328 | 339 | ||
| 329 | sfq_drop(sch); | 340 | sfq_drop(sch); |
| @@ -497,11 +508,26 @@ nla_put_failure: | |||
| 497 | return -1; | 508 | return -1; |
| 498 | } | 509 | } |
| 499 | 510 | ||
| 511 | static struct Qdisc *sfq_leaf(struct Qdisc *sch, unsigned long arg) | ||
| 512 | { | ||
| 513 | return NULL; | ||
| 514 | } | ||
| 515 | |||
| 500 | static unsigned long sfq_get(struct Qdisc *sch, u32 classid) | 516 | static unsigned long sfq_get(struct Qdisc *sch, u32 classid) |
| 501 | { | 517 | { |
| 502 | return 0; | 518 | return 0; |
| 503 | } | 519 | } |
| 504 | 520 | ||
| 521 | static unsigned long sfq_bind(struct Qdisc *sch, unsigned long parent, | ||
| 522 | u32 classid) | ||
| 523 | { | ||
| 524 | return 0; | ||
| 525 | } | ||
| 526 | |||
| 527 | static void sfq_put(struct Qdisc *q, unsigned long cl) | ||
| 528 | { | ||
| 529 | } | ||
| 530 | |||
| 505 | static struct tcf_proto **sfq_find_tcf(struct Qdisc *sch, unsigned long cl) | 531 | static struct tcf_proto **sfq_find_tcf(struct Qdisc *sch, unsigned long cl) |
| 506 | { | 532 | { |
| 507 | struct sfq_sched_data *q = qdisc_priv(sch); | 533 | struct sfq_sched_data *q = qdisc_priv(sch); |
| @@ -554,8 +580,12 @@ static void sfq_walk(struct Qdisc *sch, struct qdisc_walker *arg) | |||
| 554 | } | 580 | } |
| 555 | 581 | ||
| 556 | static const struct Qdisc_class_ops sfq_class_ops = { | 582 | static const struct Qdisc_class_ops sfq_class_ops = { |
| 583 | .leaf = sfq_leaf, | ||
| 557 | .get = sfq_get, | 584 | .get = sfq_get, |
| 585 | .put = sfq_put, | ||
| 558 | .tcf_chain = sfq_find_tcf, | 586 | .tcf_chain = sfq_find_tcf, |
| 587 | .bind_tcf = sfq_bind, | ||
| 588 | .unbind_tcf = sfq_put, | ||
| 559 | .dump = sfq_dump_class, | 589 | .dump = sfq_dump_class, |
| 560 | .dump_stats = sfq_dump_class_stats, | 590 | .dump_stats = sfq_dump_class_stats, |
| 561 | .walk = sfq_walk, | 591 | .walk = sfq_walk, |
diff --git a/net/sched/sch_tbf.c b/net/sched/sch_tbf.c index 0991c640cd3e..641a30d64635 100644 --- a/net/sched/sch_tbf.c +++ b/net/sched/sch_tbf.c | |||
| @@ -127,7 +127,7 @@ static int tbf_enqueue(struct sk_buff *skb, struct Qdisc* sch) | |||
| 127 | return qdisc_reshape_fail(skb, sch); | 127 | return qdisc_reshape_fail(skb, sch); |
| 128 | 128 | ||
| 129 | ret = qdisc_enqueue(skb, q->qdisc); | 129 | ret = qdisc_enqueue(skb, q->qdisc); |
| 130 | if (ret != 0) { | 130 | if (ret != NET_XMIT_SUCCESS) { |
| 131 | if (net_xmit_drop_count(ret)) | 131 | if (net_xmit_drop_count(ret)) |
| 132 | sch->qstats.drops++; | 132 | sch->qstats.drops++; |
| 133 | return ret; | 133 | return ret; |
| @@ -136,7 +136,7 @@ static int tbf_enqueue(struct sk_buff *skb, struct Qdisc* sch) | |||
| 136 | sch->q.qlen++; | 136 | sch->q.qlen++; |
| 137 | sch->bstats.bytes += qdisc_pkt_len(skb); | 137 | sch->bstats.bytes += qdisc_pkt_len(skb); |
| 138 | sch->bstats.packets++; | 138 | sch->bstats.packets++; |
| 139 | return 0; | 139 | return NET_XMIT_SUCCESS; |
| 140 | } | 140 | } |
| 141 | 141 | ||
| 142 | static unsigned int tbf_drop(struct Qdisc* sch) | 142 | static unsigned int tbf_drop(struct Qdisc* sch) |
diff --git a/net/sched/sch_teql.c b/net/sched/sch_teql.c index 807643bdcbac..feaabc103ce6 100644 --- a/net/sched/sch_teql.c +++ b/net/sched/sch_teql.c | |||
| @@ -85,7 +85,7 @@ teql_enqueue(struct sk_buff *skb, struct Qdisc* sch) | |||
| 85 | __skb_queue_tail(&q->q, skb); | 85 | __skb_queue_tail(&q->q, skb); |
| 86 | sch->bstats.bytes += qdisc_pkt_len(skb); | 86 | sch->bstats.bytes += qdisc_pkt_len(skb); |
| 87 | sch->bstats.packets++; | 87 | sch->bstats.packets++; |
| 88 | return 0; | 88 | return NET_XMIT_SUCCESS; |
| 89 | } | 89 | } |
| 90 | 90 | ||
| 91 | kfree_skb(skb); | 91 | kfree_skb(skb); |
diff --git a/net/sunrpc/auth.c b/net/sunrpc/auth.c index 880d0de3f50f..36cb66022a27 100644 --- a/net/sunrpc/auth.c +++ b/net/sunrpc/auth.c | |||
| @@ -39,7 +39,7 @@ static LIST_HEAD(cred_unused); | |||
| 39 | static unsigned long number_cred_unused; | 39 | static unsigned long number_cred_unused; |
| 40 | 40 | ||
| 41 | #define MAX_HASHTABLE_BITS (10) | 41 | #define MAX_HASHTABLE_BITS (10) |
| 42 | static int param_set_hashtbl_sz(const char *val, struct kernel_param *kp) | 42 | static int param_set_hashtbl_sz(const char *val, const struct kernel_param *kp) |
| 43 | { | 43 | { |
| 44 | unsigned long num; | 44 | unsigned long num; |
| 45 | unsigned int nbits; | 45 | unsigned int nbits; |
| @@ -61,7 +61,7 @@ out_inval: | |||
| 61 | return -EINVAL; | 61 | return -EINVAL; |
| 62 | } | 62 | } |
| 63 | 63 | ||
| 64 | static int param_get_hashtbl_sz(char *buffer, struct kernel_param *kp) | 64 | static int param_get_hashtbl_sz(char *buffer, const struct kernel_param *kp) |
| 65 | { | 65 | { |
| 66 | unsigned int nbits; | 66 | unsigned int nbits; |
| 67 | 67 | ||
| @@ -71,6 +71,11 @@ static int param_get_hashtbl_sz(char *buffer, struct kernel_param *kp) | |||
| 71 | 71 | ||
| 72 | #define param_check_hashtbl_sz(name, p) __param_check(name, p, unsigned int); | 72 | #define param_check_hashtbl_sz(name, p) __param_check(name, p, unsigned int); |
| 73 | 73 | ||
| 74 | static struct kernel_param_ops param_ops_hashtbl_sz = { | ||
| 75 | .set = param_set_hashtbl_sz, | ||
| 76 | .get = param_get_hashtbl_sz, | ||
| 77 | }; | ||
| 78 | |||
| 74 | module_param_named(auth_hashtable_size, auth_hashbits, hashtbl_sz, 0644); | 79 | module_param_named(auth_hashtable_size, auth_hashbits, hashtbl_sz, 0644); |
| 75 | MODULE_PARM_DESC(auth_hashtable_size, "RPC credential cache hashtable size"); | 80 | MODULE_PARM_DESC(auth_hashtable_size, "RPC credential cache hashtable size"); |
| 76 | 81 | ||
diff --git a/net/sunrpc/xprtsock.c b/net/sunrpc/xprtsock.c index 7ca65c7005ea..49a62f0c4b87 100644 --- a/net/sunrpc/xprtsock.c +++ b/net/sunrpc/xprtsock.c | |||
| @@ -2577,7 +2577,8 @@ void cleanup_socket_xprt(void) | |||
| 2577 | xprt_unregister_transport(&xs_bc_tcp_transport); | 2577 | xprt_unregister_transport(&xs_bc_tcp_transport); |
| 2578 | } | 2578 | } |
| 2579 | 2579 | ||
| 2580 | static int param_set_uint_minmax(const char *val, struct kernel_param *kp, | 2580 | static int param_set_uint_minmax(const char *val, |
| 2581 | const struct kernel_param *kp, | ||
| 2581 | unsigned int min, unsigned int max) | 2582 | unsigned int min, unsigned int max) |
| 2582 | { | 2583 | { |
| 2583 | unsigned long num; | 2584 | unsigned long num; |
| @@ -2592,34 +2593,37 @@ static int param_set_uint_minmax(const char *val, struct kernel_param *kp, | |||
| 2592 | return 0; | 2593 | return 0; |
| 2593 | } | 2594 | } |
| 2594 | 2595 | ||
| 2595 | static int param_set_portnr(const char *val, struct kernel_param *kp) | 2596 | static int param_set_portnr(const char *val, const struct kernel_param *kp) |
| 2596 | { | 2597 | { |
| 2597 | return param_set_uint_minmax(val, kp, | 2598 | return param_set_uint_minmax(val, kp, |
| 2598 | RPC_MIN_RESVPORT, | 2599 | RPC_MIN_RESVPORT, |
| 2599 | RPC_MAX_RESVPORT); | 2600 | RPC_MAX_RESVPORT); |
| 2600 | } | 2601 | } |
| 2601 | 2602 | ||
| 2602 | static int param_get_portnr(char *buffer, struct kernel_param *kp) | 2603 | static struct kernel_param_ops param_ops_portnr = { |
| 2603 | { | 2604 | .set = param_set_portnr, |
| 2604 | return param_get_uint(buffer, kp); | 2605 | .get = param_get_uint, |
| 2605 | } | 2606 | }; |
| 2607 | |||
| 2606 | #define param_check_portnr(name, p) \ | 2608 | #define param_check_portnr(name, p) \ |
| 2607 | __param_check(name, p, unsigned int); | 2609 | __param_check(name, p, unsigned int); |
| 2608 | 2610 | ||
| 2609 | module_param_named(min_resvport, xprt_min_resvport, portnr, 0644); | 2611 | module_param_named(min_resvport, xprt_min_resvport, portnr, 0644); |
| 2610 | module_param_named(max_resvport, xprt_max_resvport, portnr, 0644); | 2612 | module_param_named(max_resvport, xprt_max_resvport, portnr, 0644); |
| 2611 | 2613 | ||
| 2612 | static int param_set_slot_table_size(const char *val, struct kernel_param *kp) | 2614 | static int param_set_slot_table_size(const char *val, |
| 2615 | const struct kernel_param *kp) | ||
| 2613 | { | 2616 | { |
| 2614 | return param_set_uint_minmax(val, kp, | 2617 | return param_set_uint_minmax(val, kp, |
| 2615 | RPC_MIN_SLOT_TABLE, | 2618 | RPC_MIN_SLOT_TABLE, |
| 2616 | RPC_MAX_SLOT_TABLE); | 2619 | RPC_MAX_SLOT_TABLE); |
| 2617 | } | 2620 | } |
| 2618 | 2621 | ||
| 2619 | static int param_get_slot_table_size(char *buffer, struct kernel_param *kp) | 2622 | static struct kernel_param_ops param_ops_slot_table_size = { |
| 2620 | { | 2623 | .set = param_set_slot_table_size, |
| 2621 | return param_get_uint(buffer, kp); | 2624 | .get = param_get_uint, |
| 2622 | } | 2625 | }; |
| 2626 | |||
| 2623 | #define param_check_slot_table_size(name, p) \ | 2627 | #define param_check_slot_table_size(name, p) \ |
| 2624 | __param_check(name, p, unsigned int); | 2628 | __param_check(name, p, unsigned int); |
| 2625 | 2629 | ||
diff --git a/net/wireless/mlme.c b/net/wireless/mlme.c index e74a1a2119d3..d1a3fb99fdf2 100644 --- a/net/wireless/mlme.c +++ b/net/wireless/mlme.c | |||
| @@ -843,13 +843,19 @@ int cfg80211_mlme_action(struct cfg80211_registered_device *rdev, | |||
| 843 | return -EINVAL; | 843 | return -EINVAL; |
| 844 | if (mgmt->u.action.category != WLAN_CATEGORY_PUBLIC) { | 844 | if (mgmt->u.action.category != WLAN_CATEGORY_PUBLIC) { |
| 845 | /* Verify that we are associated with the destination AP */ | 845 | /* Verify that we are associated with the destination AP */ |
| 846 | wdev_lock(wdev); | ||
| 847 | |||
| 846 | if (!wdev->current_bss || | 848 | if (!wdev->current_bss || |
| 847 | memcmp(wdev->current_bss->pub.bssid, mgmt->bssid, | 849 | memcmp(wdev->current_bss->pub.bssid, mgmt->bssid, |
| 848 | ETH_ALEN) != 0 || | 850 | ETH_ALEN) != 0 || |
| 849 | (wdev->iftype == NL80211_IFTYPE_STATION && | 851 | (wdev->iftype == NL80211_IFTYPE_STATION && |
| 850 | memcmp(wdev->current_bss->pub.bssid, mgmt->da, | 852 | memcmp(wdev->current_bss->pub.bssid, mgmt->da, |
| 851 | ETH_ALEN) != 0)) | 853 | ETH_ALEN) != 0)) { |
| 854 | wdev_unlock(wdev); | ||
| 852 | return -ENOTCONN; | 855 | return -ENOTCONN; |
| 856 | } | ||
| 857 | |||
| 858 | wdev_unlock(wdev); | ||
| 853 | } | 859 | } |
| 854 | 860 | ||
| 855 | if (memcmp(mgmt->sa, dev->dev_addr, ETH_ALEN) != 0) | 861 | if (memcmp(mgmt->sa, dev->dev_addr, ETH_ALEN) != 0) |
