* remotes/origin/tmp-2f0de51: Linux 4.4.38 esp6: Fix integrity verification when ESN are used esp4: Fix integrity verification when ESN are used ipv4: Set skb->protocol properly for local output ipv6: Set skb->protocol properly for local output Don't feed anything but regular iovec's to blk_rq_map_user_iov constify iov_iter_count() and iter_is_iovec() sparc64: fix compile warning section mismatch in find_node() sparc64: Fix find_node warning if numa node cannot be found sparc32: Fix inverted invalid_frame_pointer checks on sigreturns net: ping: check minimum size on ICMP header length net: avoid signed overflows for SO_{SND|RCV}BUFFORCE geneve: avoid use-after-free of skb->data sh_eth: remove unchecked interrupts for RZ/A1 net: bcmgenet: Utilize correct struct device for all DMA operations packet: fix race condition in packet_set_ring net/dccp: fix use-after-free in dccp_invalid_packet netlink: Do not schedule work from sk_destruct netlink: Call cb->done from a worker thread net/sched: pedit: make sure that offset is valid net, sched: respect rcu grace period on cls destruction net: dsa: bcm_sf2: Ensure we re-negotiate EEE during after link change l2tp: fix racy SOCK_ZAPPED flag check in l2tp_ip{,6}_bind() rtnetlink: fix FDB size computation af_unix: conditionally use freezable blocking calls in read net: sky2: Fix shutdown crash ip6_tunnel: disable caching when the traffic class is inherited net: check dead netns for peernet2id_alloc() virtio-net: add a missing synchronize_net() Linux 4.4.37 arm64: suspend: Reconfigure PSTATE after resume from idle arm64: mm: Set PSTATE.PAN from the cpu_enable_pan() call arm64: cpufeature: Schedule enable() calls instead of calling them via IPI pwm: Fix device reference leak mwifiex: printk() overflow with 32-byte SSIDs PCI: Set Read Completion Boundary to 128 iff Root Port supports it (_HPX) PCI: Export pcie_find_root_port rcu: Fix soft lockup for rcu_nocb_kthread ALSA: pcm : Call kill_fasync() in stream lock x86/traps: Ignore high word of regs->cs in early_fixup_exception() kasan: update kasan_global for gcc 7 zram: fix unbalanced idr management at hot removal ARC: Don't use "+l" inline asm constraint Linux 4.4.36 scsi: mpt3sas: Unblock device after controller reset flow_dissect: call init_default_flow_dissectors() earlier mei: fix return value on disconnection mei: me: fix place for kaby point device ids. mei: me: disable driver on SPT SPS firmware drm/radeon: Ensure vblank interrupt is enabled on DPMS transition to on mpi: Fix NULL ptr dereference in mpi_powm() [ver #3] parisc: Also flush data TLB in flush_icache_page_asm parisc: Fix race in pci-dma.c parisc: Fix races in parisc_setup_cache_timing() NFSv4.x: hide array-bounds warning apparmor: fix change_hat not finding hat after policy replacement cfg80211: limit scan results cache size tile: avoid using clocksource_cyc2ns with absolute cycle count scsi: mpt3sas: Fix secure erase premature termination Fix USB CB/CBI storage devices with CONFIG_VMAP_STACK=y USB: serial: ftdi_sio: add support for TI CC3200 LaunchPad USB: serial: cp210x: add ID for the Zone DPMX usb: chipidea: move the lock initialization to core file KVM: x86: check for pic and ioapic presence before use KVM: x86: drop error recovery in em_jmp_far and em_ret_far iommu/vt-d: Fix IOMMU lookup for SR-IOV Virtual Functions iommu/vt-d: Fix PASID table allocation sched: tune: Fix lacking spinlock initialization UPSTREAM: trace: Update documentation for mono, mono_raw and boot clock UPSTREAM: trace: Add an option for boot clock as trace clock UPSTREAM: timekeeping: Add a fast and NMI safe boot clock ANDROID: goldfish_pipe: fix allmodconfig build ANDROID: goldfish: goldfish_pipe: fix locking errors ANDROID: video: goldfishfb: fix platform_no_drv_owner.cocci warnings ANDROID: goldfish_pipe: fix call_kern.cocci warnings arm64: rename ranchu defconfig to ranchu64 ANDROID: arch: x86: disable pic for Android toolchain ANDROID: goldfish_pipe: An implementation of more parallel pipe ANDROID: goldfish_pipe: bugfixes and performance improvements. ANDROID: goldfish: Add goldfish sync driver ANDROID: goldfish: add ranchu defconfigs ANDROID: goldfish_audio: Clear audio read buffer status after each read ANDROID: goldfish_events: no extra EV_SYN; register goldfish ANDROID: goldfish_fb: Set pixclock = 0 ANDROID: goldfish: Enable ACPI-based enumeration for goldfish audio ANDROID: goldfish: Enable ACPI-based enumeration for goldfish framebuffer ANDROID: video: goldfishfb: add devicetree bindings BACKPORT: staging: goldfish: audio: fix compiliation on arm BACKPORT: Input: goldfish_events - enable ACPI-based enumeration for goldfish events BACKPORT: goldfish: Enable ACPI-based enumeration for goldfish battery BACKPORT: drivers: tty: goldfish: Add device tree bindings BACKPORT: tty: goldfish: support platform_device with id -1 BACKPORT: Input: goldfish_events - add devicetree bindings BACKPORT: power: goldfish_battery: add devicetree bindings BACKPORT: staging: goldfish: audio: add devicetree bindings ANDROID: usb: gadget: function: cleanup: Add blank line after declaration cpufreq: sched: Fix kernel crash on accessing sysfs file usb: gadget: f_mtp: simplify ptp NULL pointer check cgroup: replace unified-hierarchy.txt with a proper cgroup v2 documentation cgroup: rename Documentation/cgroups/ to Documentation/cgroup-legacy/ cgroup: replace __DEVEL__sane_behavior with cgroup2 fs type writeback: initialize inode members that track writeback history mm: page_alloc: generalize the dirty balance reserve block: fix module reference leak on put_disk() call for cgroups throttle Linux 4.4.35 netfilter: nft_dynset: fix element timeout for HZ != 1000 IB/cm: Mark stale CM id's whenever the mad agent was unregistered IB/uverbs: Fix leak of XRC target QPs IB/core: Avoid unsigned int overflow in sg_alloc_table IB/mlx5: Fix fatal error dispatching IB/mlx5: Use cache line size to select CQE stride IB/mlx4: Fix create CQ error flow IB/mlx4: Check gid_index return value PM / sleep: don't suspend parent when async child suspend_{noirq, late} fails PM / sleep: fix device reference leak in test_suspend uwb: fix device reference leaks mfd: core: Fix device reference leak in mfd_clone_cell iwlwifi: pcie: fix SPLC structure parsing rtc: omap: Fix selecting external osc clk: mmp: mmp2: fix return value check in mmp2_clk_init() clk: mmp: pxa168: fix return value check in pxa168_clk_init() clk: mmp: pxa910: fix return value check in pxa910_clk_init() drm/amdgpu: Attach exclusive fence to prime exported bo's. (v5) crypto: caam - do not register AES-XTS mode on LP units ext4: sanity check the block and cluster size at mount time kbuild: Steal gcc's pie from the very beginning x86/kexec: add -fno-PIE scripts/has-stack-protector: add -fno-PIE kbuild: add -fno-PIE i2c: mux: fix up dependencies can: bcm: fix warning in bcm_connect/proc_register mfd: intel-lpss: Do not put device in reset state on suspend fuse: fix fuse_write_end() if zero bytes were copied KVM: Disable irq while unregistering user notifier KVM: x86: fix missed SRCU usage in kvm_lapic_set_vapic_addr x86/cpu/AMD: Fix cpu_llc_id for AMD Fam17h systems Linux 4.4.34 sparc64: Delete now unused user copy fixup functions. sparc64: Delete now unused user copy assembler helpers. sparc64: Convert U3copy_{from,to}_user to accurate exception reporting. sparc64: Convert NG2copy_{from,to}_user to accurate exception reporting. sparc64: Convert NGcopy_{from,to}_user to accurate exception reporting. sparc64: Convert NG4copy_{from,to}_user to accurate exception reporting. sparc64: Convert U1copy_{from,to}_user to accurate exception reporting. sparc64: Convert GENcopy_{from,to}_user to accurate exception reporting. sparc64: Convert copy_in_user to accurate exception reporting. sparc64: Prepare to move to more saner user copy exception handling. sparc64: Delete __ret_efault. sparc64: Handle extremely large kernel TLB range flushes more gracefully. sparc64: Fix illegal relative branches in hypervisor patched TLB cross-call code. sparc64: Fix instruction count in comment for __hypervisor_flush_tlb_pending. sparc64: Fix illegal relative branches in hypervisor patched TLB code. sparc64: Handle extremely large kernel TSB range flushes sanely. sparc: Handle negative offsets in arch_jump_label_transform sparc64 mm: Fix base TSB sizing when hugetlb pages are used sparc: serial: sunhv: fix a double lock bug sparc: Don't leak context bits into thread->fault_address tty: Prevent ldisc drivers from re-using stale tty fields tcp: take care of truncations done by sk_filter() ipv4: use new_gw for redirect neigh lookup net: __skb_flow_dissect() must cap its return value sock: fix sendmmsg for partial sendmsg fib_trie: Correct /proc/net/route off by one error sctp: assign assoc_id earlier in __sctp_connect ipv6: dccp: add missing bind_conflict to dccp_ipv6_mapped ipv6: dccp: fix out of bound access in dccp_v6_err() dccp: fix out of bound access in dccp_v4_err() dccp: do not send reset to already closed sockets tcp: fix potential memory corruption ip6_tunnel: Clear IP6CB in ip6tunnel_xmit() bgmac: stop clearing DMA receive control register right after it is set net: mangle zero checksum in skb_checksum_help() net: clear sk_err_soft in sk_clone_lock() dctcp: avoid bogus doubling of cwnd after loss ARM: 8485/1: cpuidle: remove cpu parameter from the cpuidle_ops suspend hook Linux 4.4.33 netfilter: fix namespace handling in nf_log_proc_dostring btrfs: qgroup: Prevent qgroup->reserved from going subzero mmc: mxs: Initialize the spinlock prior to using it ASoC: sun4i-codec: return error code instead of NULL when create_card fails ACPI / APEI: Fix incorrect return value of ghes_proc() i40e: fix call of ndo_dflt_bridge_getlink() hwrng: core - Don't use a stack buffer in add_early_randomness() lib/genalloc.c: start search from start of chunk mei: bus: fix received data size check in NFC fixup iommu/vt-d: Fix dead-locks in disable_dmar_iommu() path iommu/amd: Free domain id when free a domain of struct dma_ops_domain tty/serial: at91: fix hardware handshake on Atmel platforms dmaengine: at_xdmac: fix spurious flag status for mem2mem transfers drm/i915: Respect alternate_ddc_pin for all DDI ports KVM: MIPS: Precalculate MMIO load resume PC scsi: mpt3sas: Fix for block device of raid exists even after deleting raid disk scsi: qla2xxx: Fix scsi scan hang triggered if adapter fails during init iio: orientation: hid-sensor-rotation: Add PM function (fix non working driver) iio: hid-sensors: Increase the precision of scale to fix wrong reading interpretation. clk: qoriq: Don't allow CPU clocks higher than starting value toshiba-wmi: Fix loading the driver on non Toshiba laptops drbd: Fix kernel_sendmsg() usage - potential NULL deref usb: gadget: u_ether: remove interrupt throttling USB: cdc-acm: fix TIOCMIWAIT staging: nvec: remove managed resource from PS2 driver Revert "staging: nvec: ps2: change serio type to passthrough" drivers: staging: nvec: remove bogus reset command for PS/2 interface staging: iio: ad5933: avoid uninitialized variable in error case pinctrl: cherryview: Prevent possible interrupt storm on resume pinctrl: cherryview: Serialize register access in suspend/resume ARC: timer: rtc: implement read loop in "C" vs. inline asm s390/hypfs: Use get_free_page() instead of kmalloc to ensure page alignment coredump: fix unfreezable coredumping task swapfile: fix memory corruption via malformed swapfile dib0700: fix nec repeat handling ASoC: cs4270: fix DAPM stream name mismatch ALSA: info: Limit the proc text input size ALSA: info: Return error for invalid read/write arm64: Enable KPROBES/HIBERNATION/CORESIGHT in defconfig arm64: kvm: allows kvm cpu hotplug arm64: KVM: Register CPU notifiers when the kernel runs at HYP arm64: KVM: Skip HYP setup when already running in HYP arm64: hyp/kvm: Make hyp-stub reject kvm_call_hyp() arm64: hyp/kvm: Make hyp-stub extensible arm64: kvm: Move lr save/restore from do_el2_call into EL1 arm64: kvm: deal with kernel symbols outside of linear mapping arm64: introduce KIMAGE_VADDR as the virtual base of the kernel region ANDROID: video: adf: Avoid directly referencing user pointers ANDROID: usb: gadget: audio_source: fix comparison of distinct pointer types android: binder: support for file-descriptor arrays. android: binder: support for scatter-gather. android: binder: add extra size to allocator. android: binder: refactor binder_transact() android: binder: support multiple /dev instances. android: binder: deal with contexts in debugfs. android: binder: support multiple context managers. android: binder: split flat_binder_object. disable aio support in recommended configuration Linux 4.4.32 scsi: megaraid_sas: fix macro MEGASAS_IS_LOGICAL to avoid regression drm/radeon: fix DP mode validation drm/radeon/dp: add back special handling for NUTMEG drm/amdgpu: fix DP mode validation drm/amdgpu/dp: add back special handling for NUTMEG KVM: MIPS: Drop other CPU ASIDs on guest MMU changes Revert KVM: MIPS: Drop other CPU ASIDs on guest MMU changes of: silence warnings due to max() usage packet: on direct_xmit, limit tso and csum to supported devices sctp: validate chunk len before actually using it net sched filters: fix notification of filter delete with proper handle udp: fix IP_CHECKSUM handling net: sctp, forbid negative length ipv4: use the right lock for ping_group_range ipv4: disable BH in set_ping_group_range() net: add recursion limit to GRO rtnetlink: Add rtnexthop offload flag to compare mask bridge: multicast: restore perm router ports on multicast enable net: pktgen: remove rcu locking in pktgen_change_name() ipv6: correctly add local routes when lo goes up ip6_tunnel: fix ip6_tnl_lookup ipv6: tcp: restore IP6CB for pktoptions skbs netlink: do not enter direct reclaim from netlink_dump() packet: call fanout_release, while UNREGISTERING a netdev net: Add netdev all_adj_list refcnt propagation to fix panic net/sched: act_vlan: Push skb->data to mac_header prior calling skb_vlan_*() functions net: pktgen: fix pkt_size net: fec: set mac address unconditionally tg3: Avoid NULL pointer dereference in tg3_io_error_detected() ipmr, ip6mr: fix scheduling while atomic and a deadlock with ipmr_get_route ip6_gre: fix flowi6_proto value in ip6gre_xmit_other() tcp: fix a compile error in DBGUNDO() tcp: fix wrong checksum calculation on MTU probing net: avoid sk_forward_alloc overflows tcp: fix overflow in __tcp_retransmit_skb() arm64/kvm: fix build issue on kvm debug arm64: ptdump: Indicate whether memory should be faulting arm64: Add support for ARCH_SUPPORTS_DEBUG_PAGEALLOC arm64: Drop alloc function from create_mapping arm64: allow vmalloc regions to be set with set_memory_* arm64: kernel: implement ACPI parking protocol arm64: mm: create new fine-grained mappings at boot arm64: ensure _stext and _etext are page-aligned arm64: mm: allow passing a pgdir to alloc_init_* arm64: mm: allocate pagetables anywhere arm64: mm: use fixmap when creating page tables arm64: mm: add functions to walk tables in fixmap arm64: mm: add __{pud,pgd}_populate arm64: mm: avoid redundant __pa(__va(x)) Linux 4.4.31 HID: usbhid: add ATEN CS962 to list of quirky devices ubi: fastmap: Fix add_vol() return value test in ubi_attach_fastmap() kvm: x86: Check memopp before dereference (CVE-2016-8630) tty: vt, fix bogus division in csi_J usb: dwc3: Fix size used in dma_free_coherent() pwm: Unexport children before chip removal UBI: fastmap: scrub PEB when bitflips are detected in a free PEB EC header Disable "frame-address" warning smc91x: avoid self-comparison warning cgroup: avoid false positive gcc-6 warning drm/exynos: fix error handling in exynos_drm_subdrv_open mm/cma: silence warnings due to max() usage ARM: 8584/1: floppy: avoid gcc-6 warning powerpc/ptrace: Fix out of bounds array access warning x86/xen: fix upper bound of pmd loop in xen_cleanhighmap() perf build: Fix traceevent plugins build race drm/dp/mst: Check peer device type before attempting EDID read drm/radeon: drop register readback in cayman_cp_int_cntl_setup drm/radeon/si_dpm: workaround for SI kickers drm/radeon/si_dpm: Limit clocks on HD86xx part Revert "drm/radeon: fix DP link training issue with second 4K monitor" mmc: dw_mmc-pltfm: fix the potential NULL pointer dereference scsi: arcmsr: Send SYNCHRONIZE_CACHE command to firmware scsi: scsi_debug: Fix memory leak if LBP enabled and module is unloaded scsi: megaraid_sas: Fix data integrity failure for JBOD (passthrough) devices mac80211: discard multicast and 4-addr A-MSDUs firewire: net: fix fragmented datagram_size off-by-one firewire: net: guard against rx buffer overflows Input: i8042 - add XMG C504 to keyboard reset table dm mirror: fix read error on recovery after default leg failure virtio: console: Unlock vqs while freeing buffers virtio_ring: Make interrupt suppression spec compliant parisc: Ensure consistent state when switching to kernel stack at syscall entry ovl: fsync after copy-up KVM: MIPS: Make ERET handle ERL before EXL KVM: x86: fix wbinvd_dirty_mask use-after-free dm: free io_barrier after blk_cleanup_queue call USB: serial: cp210x: fix tiocmget error handling tty: limit terminal size to 4M chars xhci: add restart quirk for Intel Wildcatpoint PCH hv: do not lose pending heartbeat vmbus packets vt: clear selection before resizing Fix potential infoleak in older kernels GenWQE: Fix bad page access during abort of resource allocation usb: increase ohci watchdog delay to 275 msec xhci: use default USB_RESUME_TIMEOUT when resuming ports. USB: serial: ftdi_sio: add support for Infineon TriBoard TC2X7 USB: serial: fix potential NULL-dereference at probe usb: gadget: function: u_ether: don't starve tx request queue mei: txe: don't clean an unprocessed interrupt cause. ubifs: Fix regression in ubifs_readdir() ubifs: Abort readdir upon error btrfs: fix races on root_log_ctx lists ANDROID: binder: Clear binder and cookie when setting handle in flat binder struct ANDROID: binder: Add strong ref checks ALSA: hda - Fix headset mic detection problem for two Dell laptops ALSA: hda - Adding a new group of pin cfg into ALC295 pin quirk table ALSA: hda - allow 40 bit DMA mask for NVidia devices ALSA: hda - Raise AZX_DCAPS_RIRB_DELAY handling into top drivers ALSA: hda - Merge RIRB_PRE_DELAY into CTX_WORKAROUND caps ALSA: usb-audio: Add quirk for Syntek STK1160 KEYS: Fix short sprintf buffer in /proc/keys show function mm: memcontrol: do not recurse in direct reclaim mm/list_lru.c: avoid error-path NULL pointer deref libxfs: clean up _calc_dquots_per_chunk h8300: fix syscall restarting drm/dp/mst: Clear port->pdt when tearing down the i2c adapter i2c: core: fix NULL pointer dereference under race condition i2c: xgene: Avoid dma_buffer overrun arm64:cpufeature ARM64_NCAPS is the indicator of last feature arm64: hibernate: Refuse to hibernate if the boot cpu is offline PM / sleep: Add support for read-only sysfs attributes arm64: kernel: Add support for hibernate/suspend-to-disk arm64: mm: add functions to walk page tables by PA arm64: mm: move pte_* macros PM / Hibernate: Call flush_icache_range() on pages restored in-place arm64: Add new asm macro copy_page arm64: Promote KERNEL_START/KERNEL_END definitions to a header file arm64: kernel: Include _AC definition in page.h arm64: Change cpu_resume() to enable mmu early then access sleep_sp by va arm64: kernel: Rework finisher callback out of __cpu_suspend_enter() arm64: Cleanup SCTLR flags arm64: Fold proc-macros.S into assembler.h arm/arm64: KVM: Add hook for C-based stage2 init arm/arm64: KVM: Detect vGIC presence at runtime arm64: KVM: Add support for 16-bit VMID arm: KVM: Make kvm_arm.h friendly to assembly code arm/arm64: KVM: Remove unreferenced S2_PGD_ORDER arm64: KVM: debug: Remove spurious inline attributes ARM: KVM: Cleanup exception injection arm64: KVM: Remove weak attributes arm64: KVM: Cleanup asm-offset.c arm64: KVM: Turn system register numbers to an enum arm64: KVM: VHE: Patch out use of HVC arm64: Add ARM64_HAS_VIRT_HOST_EXTN feature arm/arm64: Add new is_kernel_in_hyp_mode predicate arm64: KVM: Move away from the assembly version of the world switch arm64: KVM: Map the kernel RO section into HYP arm64: KVM: Add compatibility aliases arm64: KVM: Implement vgic-v3 save/restore arm64: KVM: Add panic handling arm64: KVM: HYP mode entry points arm64: KVM: Implement TLB handling arm64: KVM: Implement fpsimd save/restore arm64: KVM: Implement the core world switch arm64: KVM: Add patchable function selector arm64: KVM: Implement guest entry arm64: KVM: Implement debug save/restore arm64: KVM: Implement 32bit system register save/restore arm64: KVM: Implement system register save/restore arm64: KVM: Implement timer save/restore arm64: KVM: Implement vgic-v2 save/restore arm64: KVM: Add a HYP-specific header file KVM: arm/arm64: vgic-v3: Make the LR indexing macro public arm64: Add macros to read/write system registers Linux 4.4.30 Revert "fix minor infoleak in get_user_ex()" Revert "x86/mm: Expand the exception table logic to allow new handling options" Linux 4.4.29 ARM: pxa: pxa_cplds: fix interrupt handling powerpc/nvram: Fix an incorrect partition merge mpt3sas: Don't spam logs if logging level is 0 perf symbols: Fixup symbol sizes before picking best ones perf symbols: Check symbol_conf.allow_aliases for kallsyms loading too perf hists browser: Fix event group display clk: divider: Fix clk_divider_round_rate() to use clk_readl() clk: qoriq: fix a register offset error s390/con3270: fix insufficient space padding s390/con3270: fix use of uninitialised data s390/cio: fix accidental interrupt enabling during resume x86/mm: Expand the exception table logic to allow new handling options dmaengine: ipu: remove bogus NO_IRQ reference power: bq24257: Fix use of uninitialized pointer bq->charger staging: r8188eu: Fix scheduling while atomic splat ASoC: dapm: Fix kcontrol creation for output driver widget ASoC: dapm: Fix value setting for _ENUM_DOUBLE MUX's second channel ASoC: dapm: Fix possible uninitialized variable in snd_soc_dapm_get_volsw() ASoC: topology: Fix error return code in soc_tplg_dapm_widget_create() hwrng: omap - Only fail if pm_runtime_get_sync returns < 0 crypto: arm/ghash-ce - add missing async import/export crypto: gcm - Fix IV buffer size in crypto_gcm_setkey mwifiex: correct aid value during tdls setup spi: spi-fsl-dspi: Drop extra spi_master_put in device remove function ARM: clk-imx35: fix name for ckil clk uio: fix dmem_region_start computation genirq/generic_chip: Add irq_unmap callback perf stat: Fix interval output values powerpc/eeh: Null check uses of eeh_pe_bus_get tunnels: Remove encapsulation offloads on decap. tunnels: Don't apply GRO to multiple layers of encapsulation. ipip: Properly mark ipip GRO packets as encapsulated. posix_acl: Clear SGID bit when setting file permissions brcmfmac: avoid potential stack overflow in brcmf_cfg80211_start_ap() mm/hugetlb: fix memory offline with hugepage size > memory block size drm/i915: Unalias obj->phys_handle and obj->userptr drm/i915: Account for TSEG size when determining 865G stolen base Revert "drm/i915: Check live status before reading edid" drm/i915/gen9: fix the WaWmMemoryReadLatency implementation xenbus: don't look up transaction IDs for ordinary writes drm/vmwgfx: Limit the user-space command buffer size drm/radeon: change vblank_time's calculation method to reduce computational error. drm/radeon/si/dpm: fix phase shedding setup drm/radeon: narrow asic_init for virtualization drm/amdgpu: change vblank_time's calculation method to reduce computational error. drm/amdgpu/dce11: add missing drm_mode_config_cleanup call drm/amdgpu/dce11: disable hpd on local panels drm/amdgpu/dce8: disable hpd on local panels drm/amdgpu/dce10: disable hpd on local panels drm/amdgpu: fix IB alignment for UVD drm/prime: Pass the right module owner through to dma_buf_export() Linux 4.4.28 target: Don't override EXTENDED_COPY xcopy_pt_cmd SCSI status code target: Make EXTENDED_COPY 0xe4 failure return COPY TARGET DEVICE NOT REACHABLE target: Re-add missing SCF_ACK_KREF assignment in v4.1.y ubifs: Fix xattr_names length in exit paths jbd2: fix incorrect unlock on j_list_lock ext4: do not advertise encryption support when disabled mmc: rtsx_usb_sdmmc: Handle runtime PM while changing the led mmc: rtsx_usb_sdmmc: Avoid keeping the device runtime resumed when unused mmc: core: Annotate cmd_hdr as __le32 powerpc/mm: Prevent unlikely crash in copro_calculate_slb() ceph: fix error handling in ceph_read_iter arm64: kernel: Init MDCR_EL2 even in the absence of a PMU arm64: percpu: rewrite ll/sc loops in assembly memstick: rtsx_usb_ms: Manage runtime PM when accessing the device memstick: rtsx_usb_ms: Runtime resume the device when polling for cards isofs: Do not return EACCES for unknown filesystems irqchip/gic-v3-its: Fix entry size mask for GITS_BASER s390/mm: fix gmap tlb flush issues Using BUG_ON() as an assert() is _never_ acceptable mm: filemap: fix mapping->nrpages double accounting in fuse mm: workingset: fix crash in shadow node shrinker caused by replace_page_cache_page() acpi, nfit: check for the correct event code in notifications net/mlx4_core: Allow resetting VF admin mac to zero bnx2x: Prevent false warning for lack of FC NPIV PKCS#7: Don't require SpcSpOpusInfo in Authenticode pkcs7 signatures hpsa: correct skipping masked peripherals sd: Fix rw_max for devices that report an optimal xfer size irqchip/gicv3: Handle loop timeout proper kvm: x86: memset whole irq_eoi x86/e820: Don't merge consecutive E820_PRAM ranges blkcg: Unlock blkcg_pol_mutex only once when cpd == NULL Fix regression which breaks DFS mounting Cleanup missing frees on some ioctls Do not send SMB3 SET_INFO request if nothing is changing SMB3: GUIDs should be constructed as random but valid uuids Set previous session id correctly on SMB3 reconnect Display number of credits available Clarify locking of cifs file and tcon structures and make more granular fs/cifs: keep guid when assigning fid to fileinfo cifs: Limit the overall credit acquired fs/super.c: fix race between freeze_super() and thaw_super() arc: don't leak bits of kernel stack into coredump lightnvm: ensure that nvm_dev_ops can be used without CONFIG_NVM ipc/sem.c: fix complex_count vs. simple op race mm: filemap: don't plant shadow entries without radix tree node metag: Only define atomic_dec_if_positive conditionally scsi: Fix use-after-free NFSv4.2: Fix a reference leak in nfs42_proc_layoutstats_generic NFSv4: Open state recovery must account for file permission changes NFSv4: nfs4_copy_delegation_stateid() must fail if the delegation is invalid NFSv4: Don't report revoked delegations as valid in nfs_have_delegation() sunrpc: fix write space race causing stalls Input: elantech - add Fujitsu Lifebook E556 to force crc_enabled Input: elantech - force needed quirks on Fujitsu H760 Input: i8042 - skip selftest on ASUS laptops lib: add "on"/"off" support to kstrtobool lib: update single-char callers of strtobool() lib: move strtobool() to kstrtobool() MIPS: ptrace: Fix regs_return_value for kernel context MIPS: Fix -mabi=64 build of vdso.lds ALSA: hda - Fix a failure of micmute led when having multi adcs cx231xx: fix GPIOs for Pixelview SBTVD hybrid cx231xx: don't return error on success mb86a20s: fix demod settings mb86a20s: fix the locking logic ovl: copy_up_xattr(): use strnlen ovl: Fix info leak in ovl_lookup_temp() fbdev/efifb: Fix 16 color palette entry calculation scsi: zfcp: spin_lock_irqsave() is not nestable zfcp: trace full payload of all SAN records (req,resp,iels) zfcp: fix payload trace length for SAN request&response zfcp: fix D_ID field with actual value on tracing SAN responses zfcp: restore tracing of handle for port and LUN with HBA records zfcp: trace on request for open and close of WKA port zfcp: restore: Dont use 0 to indicate invalid LUN in rec trace zfcp: retain trace level for SCSI and HBA FSF response records zfcp: close window with unblocked rport during rport gone zfcp: fix ELS/GS request&response length for hardware data router zfcp: fix fc_host port_type with NPIV ubi: Deal with interrupted erasures in WL powerpc/pseries: Fix stack corruption in htpe code powerpc/64: Fix incorrect return value from __copy_tofrom_user powerpc/powernv: Use CPU-endian PEST in pnv_pci_dump_p7ioc_diag_data() powerpc/powernv: Use CPU-endian hub diag-data type in pnv_eeh_get_and_dump_hub_diag() powerpc/powernv: Pass CPU-endian PE number to opal_pci_eeh_freeze_clear() powerpc/vdso64: Use double word compare on pointers dm crypt: fix crash on exit dm mpath: check if path's request_queue is dying in activate_path() dm: return correct error code in dm_resume()'s retry loop dm: mark request_queue dead before destroying the DM device perf intel-pt: Fix MTC timestamp calculation for large MTC periods perf intel-pt: Fix estimated timestamps for cycle-accurate mode perf intel-pt: Fix snapshot overlap detection decoder errors pstore/ram: Use memcpy_fromio() to save old buffer pstore/ram: Use memcpy_toio instead of memcpy pstore/core: drop cmpxchg based updates pstore/ramoops: fixup driver removal parisc: Increase initial kernel mapping size parisc: Fix kernel memory layout regarding position of __gp parisc: Increase KERNEL_INITIAL_SIZE for 32-bit SMP kernels cpufreq: intel_pstate: Fix unsafe HWP MSR access platform: don't return 0 from platform_get_irq[_byname]() on error PCI: Mark Atheros AR9580 to avoid bus reset mmc: sdhci: cast unsigned int to unsigned long long to avoid unexpeted error mmc: block: don't use CMD23 with very old MMC cards rtlwifi: Fix missing country code for Great Britain PM / devfreq: event: remove duplicate devfreq_event_get_drvdata() clk: imx6: initialize GPU clocks regulator: tps65910: Work around silicon erratum SWCZ010 mei: me: add kaby point device ids gpio: mpc8xxx: Correct irq handler function cgroup: Change from CAP_SYS_NICE to CAP_SYS_RESOURCE for cgroup migration permissions UPSTREAM: cpu/hotplug: Handle unbalanced hotplug enable/disable UPSTREAM: arm64: kaslr: fix breakage with CONFIG_MODVERSIONS=y UPSTREAM: arm64: kaslr: keep modules close to the kernel when DYNAMIC_FTRACE=y cgroup: Remove leftover instances of allow_attach BACKPORT: lib: harden strncpy_from_user CHROMIUM: cgroups: relax permissions on moving tasks between cgroups CHROMIUM: remove Android's cgroup generic permissions checks Linux 4.4.27 cfq: fix starvation of asynchronous writes vfs: move permission checking into notify_change() for utimes(NULL) dlm: free workqueues after the connections crypto: vmx - Fix memory corruption caused by p8_ghash crypto: ghash-generic - move common definitions to a new header file ext4: release bh in make_indexed_dir ext4: allow DAX writeback for hole punch ext4: fix memory leak in ext4_insert_range() ext4: reinforce check of i_dtime when clearing high fields of uid and gid ext4: enforce online defrag restriction for encrypted files scsi: ibmvfc: Fix I/O hang when port is not mapped scsi: arcmsr: Simplify user_len checking scsi: arcmsr: Buffer overflow in arcmsr_iop_message_xfer() async_pq_val: fix DMA memory leak reiserfs: switch to generic_{get,set,remove}xattr() reiserfs: Unlock superblock before calling reiserfs_quota_on_mount() ASoC: Intel: Atom: add a missing star in a memcpy call brcmfmac: fix memory leak in brcmf_fill_bss_param i40e: avoid NULL pointer dereference and recursive errors on early PCI error fuse: fix killing s[ug]id in setattr fuse: invalidate dir dentry after chmod fuse: listxattr: verify xattr list drivers: base: dma-mapping: page align the size when unmap_kernel_range btrfs: assign error values to the correct bio structs serial: 8250_dw: Check the data->pclk when get apb_pclk arm64: Use PoU cache instr for I/D coherency arm64: mm: add code to safely replace TTBR1_EL1 arm64: mm: place __cpu_setup in .text arm64: add function to install the idmap arm64: unmap idmap earlier arm64: unify idmap removal arm64: mm: place empty_zero_page in bss arm64: head.S: use memset to clear BSS arm64: mm: specialise pagetable allocators arm64: mm: remove pointless PAGE_MASKing asm-generic: Fix local variable shadow in __set_fixmap_offset arm64: mm: fold alternatives into .init ARM: 8511/1: ARM64: kernel: PSCI: move PSCI idle management code to drivers/firmware ARM: 8481/2: drivers: psci: replace psci firmware calls ARM: 8480/2: arm64: add implementation for arm-smccc ARM: 8479/2: add implementation for arm-smccc ARM: 8478/2: arm/arm64: add arm-smccc ARM: 8510/1: rework ARM_CPU_SUSPEND dependencies ARM: 8458/1: bL_switcher: add GIC dependency Linux 4.4.26 mm: remove gup_flags FOLL_WRITE games from __get_user_pages() x86/build: Build compressed x86 kernels as PIE arm64: Remove stack duplicating code from jprobes arm64: kprobes: Add KASAN instrumentation around stack accesses arm64: kprobes: Cleanup jprobe_return arm64: kprobes: Fix overflow when saving stack arm64: kprobes: WARN if attempting to step with PSTATE.D=1 kprobes: Add arm64 case in kprobe example module arm64: Add kernel return probes support (kretprobes) arm64: Add trampoline code for kretprobes arm64: kprobes instruction simulation support arm64: Treat all entry code as non-kprobe-able arm64: Blacklist non-kprobe-able symbol arm64: Kprobes with single stepping support arm64: add conditional instruction simulation support arm64: Add more test functions to insn.c arm64: Add HAVE_REGS_AND_STACK_ACCESS_API feature Linux 4.4.25 tpm_crb: fix crb_req_canceled behavior tpm: fix a race condition in tpm2_unseal_trusted() ima: use file_dentry() ARM: cpuidle: Fix error return code ARM: dts: MSM8064 remove flags from SPMI/MPP IRQs ARM: dts: mvebu: armada-390: add missing compatibility string and bracket x86/dumpstack: Fix x86_32 kernel_stack_pointer() previous stack access x86/irq: Prevent force migration of irqs which are not in the vector domain x86/boot: Fix kdump, cleanup aborted E820_PRAM max_pfn manipulation KVM: PPC: BookE: Fix a sanity check KVM: MIPS: Drop other CPU ASIDs on guest MMU changes KVM: PPC: Book3s PR: Allow access to unprivileged MMCR2 register mfd: wm8350-i2c: Make sure the i2c regmap functions are compiled mfd: 88pm80x: Double shifting bug in suspend/resume mfd: atmel-hlcdc: Do not sleep in atomic context mfd: rtsx_usb: Avoid setting ucr->current_sg.status ALSA: usb-line6: use the same declaration as definition in header for MIDI manufacturer ID ALSA: usb-audio: Extend DragonFly dB scale quirk to cover other variants ALSA: ali5451: Fix out-of-bound position reporting timekeeping: Fix __ktime_get_fast_ns() regression time: Add cycles to nanoseconds translation mm: Fix build for hardened usercopy ANDROID: binder: Clear binder and cookie when setting handle in flat binder struct ANDROID: binder: Add strong ref checks UPSTREAM: staging/android/ion : fix a race condition in the ion driver ANDROID: android-base: CONFIG_HARDENED_USERCOPY=y UPSTREAM: fs/proc/kcore.c: Add bounce buffer for ktext data UPSTREAM: fs/proc/kcore.c: Make bounce buffer global for read BACKPORT: arm64: Correctly bounds check virt_addr_valid Fix a build breakage in IO latency hist code. UPSTREAM: efi: include asm/early_ioremap.h not asm/efi.h to get early_memremap UPSTREAM: ia64: split off early_ioremap() declarations into asm/early_ioremap.h FROMLIST: arm64: Enable CONFIG_ARM64_SW_TTBR0_PAN FROMLIST: arm64: xen: Enable user access before a privcmd hvc call FROMLIST: arm64: Handle faults caused by inadvertent user access with PAN enabled FROMLIST: arm64: Disable TTBR0_EL1 during normal kernel execution FROMLIST: arm64: Introduce uaccess_{disable,enable} functionality based on TTBR0_EL1 FROMLIST: arm64: Factor out TTBR0_EL1 post-update workaround into a specific asm macro FROMLIST: arm64: Factor out PAN enabling/disabling into separate uaccess_* macros UPSTREAM: arm64: Handle el1 synchronous instruction aborts cleanly UPSTREAM: arm64: include alternative handling in dcache_by_line_op UPSTREAM: arm64: fix "dc cvau" cache operation on errata-affected core UPSTREAM: Revert "arm64: alternatives: add enable parameter to conditional asm macros" UPSTREAM: arm64: Add new asm macro copy_page UPSTREAM: arm64: kill ESR_LNX_EXEC UPSTREAM: arm64: add macro to extract ESR_ELx.EC UPSTREAM: arm64: mm: mark fault_info table const UPSTREAM: arm64: fix dump_instr when PAN and UAO are in use BACKPORT: arm64: Fold proc-macros.S into assembler.h UPSTREAM: arm64: choose memstart_addr based on minimum sparsemem section alignment UPSTREAM: arm64/mm: ensure memstart_addr remains sufficiently aligned UPSTREAM: arm64/kernel: fix incorrect EL0 check in inv_entry macro UPSTREAM: arm64: Add macros to read/write system registers UPSTREAM: arm64/efi: refactor EFI init and runtime code for reuse by 32-bit ARM UPSTREAM: arm64/efi: split off EFI init and runtime code for reuse by 32-bit ARM UPSTREAM: arm64/efi: mark UEFI reserved regions as MEMBLOCK_NOMAP BACKPORT: arm64: only consider memblocks with NOMAP cleared for linear mapping UPSTREAM: mm/memblock: add MEMBLOCK_NOMAP attribute to memblock memory table ANDROID: dm: android-verity: Remove fec_header location constraint BACKPORT: audit: consistently record PIDs with task_tgid_nr() android-base.cfg: Enable kernel ASLR UPSTREAM: vmlinux.lds.h: allow arch specific handling of ro_after_init data section UPSTREAM: arm64: spinlock: fix spin_unlock_wait for LSE atomics UPSTREAM: arm64: avoid TLB conflict with CONFIG_RANDOMIZE_BASE UPSTREAM: arm64: Only select ARM64_MODULE_PLTS if MODULES=y sched: Add Kconfig option DEFAULT_USE_ENERGY_AWARE to set ENERGY_AWARE feature flag sched/fair: remove printk while schedule is in progress ANDROID: fs: FS tracepoints to track IO. sched/walt: Drop arch-specific timer access ANDROID: fiq_debugger: Pass task parameter to unwind_frame() eas/sched/fair: Fixing comments in find_best_target. input: keyreset: switch to orderly_reboot UPSTREAM: tun: fix transmit timestamp support UPSTREAM: arch/arm/include/asm/pgtable-3level.h: add pmd_mkclean for THP net: inet: diag: expose the socket mark to privileged processes. net: diag: make udp_diag_destroy work for mapped addresses. net: diag: support SOCK_DESTROY for UDP sockets net: diag: allow socket bytecode filters to match socket marks net: diag: slightly refactor the inet_diag_bc_audit error checks. net: diag: Add support to filter on device index UPSTREAM: brcmfmac: avoid potential stack overflow in brcmf_cfg80211_start_ap() Linux 4.4.24 ALSA: hda - Add the top speaker pin config for HP Spectre x360 ALSA: hda - Fix headset mic detection problem for several Dell laptops ACPICA: acpi_get_sleep_type_data: Reduce warnings ALSA: hda - Adding one more ALC255 pin definition for headset problem Revert "usbtmc: convert to devm_kzalloc" USB: serial: cp210x: Add ID for a Juniper console Staging: fbtft: Fix bug in fbtft-core usb: misc: legousbtower: Fix NULL pointer deference USB: serial: cp210x: fix hardware flow-control disable dm log writes: fix bug with too large bios clk: xgene: Add missing parenthesis when clearing divider value aio: mark AIO pseudo-fs noexec batman-adv: remove unused callback from batadv_algo_ops struct IB/mlx4: Use correct subnet-prefix in QP1 mads under SR-IOV IB/mlx4: Fix code indentation in QP1 MAD flow IB/mlx4: Fix incorrect MC join state bit-masking on SR-IOV IB/ipoib: Don't allow MC joins during light MC flush IB/core: Fix use after free in send_leave function IB/ipoib: Fix memory corruption in ipoib cm mode connect flow KVM: nVMX: postpone VMCS changes on MSR_IA32_APICBASE write dmaengine: at_xdmac: fix to pass correct device identity to free_irq() kernel/fork: fix CLONE_CHILD_CLEARTID regression in nscd ASoC: omap-mcpdm: Fix irq resource handling sysctl: handle error writing UINT_MAX to u32 fields powerpc/prom: Fix sub-processor option passed to ibm, client-architecture-support brcmsmac: Initialize power in brcms_c_stf_ss_algo_channel_get() brcmsmac: Free packet if dma_mapping_error() fails in dma_rxfill brcmfmac: Fix glob_skb leak in brcmf_sdiod_recv_chain ASoC: Intel: Skylake: Fix error return code in skl_probe() pNFS/flexfiles: Fix layoutcommit after a commit to DS pNFS/files: Fix layoutcommit after a commit to DS NFS: Don't drop CB requests with invalid principals svc: Avoid garbage replies when pc_func() returns rpc_drop_reply dmaengine: at_xdmac: fix debug string fnic: pci_dma_mapping_error() doesn't return an error code avr32: off by one in at32_init_pio() ath9k: Fix programming of minCCA power threshold gspca: avoid unused variable warnings em28xx-i2c: rt_mutex_trylock() returns zero on failure NFC: fdp: Detect errors from fdp_nci_create_conn() iwlmvm: mvm: set correct state in smart-fifo configuration tile: Define AT_VECTOR_SIZE_ARCH for ARCH_DLINFO pstore: drop file opened reference count blk-mq: actually hook up defer list when running requests hwrng: omap - Fix assumption that runtime_get_sync will always succeed ARM: sa1111: fix pcmcia suspend/resume ARM: shmobile: fix regulator quirk for Gen2 ARM: sa1100: clear reset status prior to reboot ARM: sa1100: fix 3.6864MHz clock ARM: sa1100: register clocks early ARM: sun5i: Fix typo in trip point temperature regulator: qcom_smd: Fix voltage ranges for pm8x41 regulator: qcom_spmi: Update mvs1/mvs2 switches on pm8941 regulator: qcom_spmi: Add support for get_mode/set_mode on switches regulator: qcom_spmi: Add support for S4 supply on pm8941 tpm: fix byte-order for the value read by tpm2_get_tpm_pt printk: fix parsing of "brl=" option MIPS: uprobes: fix use of uninitialised variable MIPS: Malta: Fix IOCU disable switch read for MIPS64 MIPS: fix uretprobe implementation MIPS: uprobes: remove incorrect set_orig_insn arm64: debug: avoid resetting stepping state machine when TIF_SINGLESTEP ARM: 8618/1: decompressor: reset ttbcr fields to use TTBR0 on ARMv7 irqchip/gicv3: Silence noisy DEBUG_PER_CPU_MAPS warning gpio: sa1100: fix irq probing for ucb1x00 usb: gadget: fsl_qe_udc: signedness bug in qe_get_frame() ceph: fix race during filling readdir cache iwlwifi: mvm: don't use ret when not initialised iwlwifi: pcie: fix access to scratch buffer spi: sh-msiof: Avoid invalid clock generator parameters hwmon: (adt7411) set bit 3 in CFG1 register nvmem: Declare nvmem_cell_read() consistently ipvs: fix bind to link-local mcast IPv6 address in backup tools/vm/slabinfo: fix an unintentional printf mmc: pxamci: fix potential oops drivers/perf: arm_pmu: Fix leak in error path pinctrl: Flag strict is a field in struct pinmux_ops pinctrl: uniphier: fix .pin_dbg_show() callback i40e: avoid null pointer dereference perf/core: Fix pmu::filter_match for SW-led groups iwlwifi: mvm: fix a few firmware capability checks usb: musb: fix DMA for host mode usb: musb: Fix DMA desired mode for Mentor DMA engine ARM: 8617/1: dma: fix dma_max_pfn() ARM: 8616/1: dt: Respect property size when parsing CPUs drm/radeon/si/dpm: add workaround for for Jet parts drm/nouveau/fifo/nv04: avoid ramht race against cookie insertion x86/boot: Initialize FPU and X86_FEATURE_ALWAYS even if we don't have CPUID x86/init: Fix cr4_init_shadow() on CR4-less machines can: dev: fix deadlock reported after bus-off mm,ksm: fix endless looping in allocating memory when ksm enable mtd: nand: davinci: Reinitialize the HW ECC engine in 4bit hwctl cpuset: handle race between CPU hotplug and cpuset_hotplug_work usercopy: fold builtin_const check into inline function Linux 4.4.23 hostfs: Freeing an ERR_PTR in hostfs_fill_sb_common() qxl: check for kmap failures power: supply: max17042_battery: fix model download bug. power_supply: tps65217-charger: fix missing platform_set_drvdata() PM / hibernate: Fix rtree_next_node() to avoid walking off list ends PM / hibernate: Restore processor state before using per-CPU variables MIPS: paravirt: Fix undefined reference to smp_bootstrap MIPS: Add a missing ".set pop" in an early commit MIPS: Avoid a BUG warning during prctl(PR_SET_FP_MODE, ...) MIPS: Remove compact branch policy Kconfig entries MIPS: vDSO: Fix Malta EVA mapping to vDSO page structs MIPS: SMP: Fix possibility of deadlock when bringing CPUs online MIPS: Fix pre-r6 emulation FPU initialisation i2c: qup: skip qup_i2c_suspend if the device is already runtime suspended i2c-eg20t: fix race between i2c init and interrupt enable btrfs: ensure that file descriptor used with subvol ioctls is a dir nl80211: validate number of probe response CSA counters can: flexcan: fix resume function mm: delete unnecessary and unsafe init_tlb_ubc() tracing: Move mutex to protect against resetting of seq data fix memory leaks in tracing_buffers_splice_read() power: reset: hisi-reboot: Unmap region obtained by of_iomap mtd: pmcmsp-flash: Allocating too much in init_msp_flash() mtd: maps: sa1100-flash: potential NULL dereference fix fault_in_multipages_...() on architectures with no-op access_ok() fanotify: fix list corruption in fanotify_get_response() fsnotify: add a way to stop queueing events on group shutdown xfs: prevent dropping ioend completions during buftarg wait autofs: use dentry flags to block walks during expire autofs races pwm: Mark all devices as "might sleep" bridge: re-introduce 'fix parsing of MLDv2 reports' net: smc91x: fix SMC accesses Revert "phy: IRQ cannot be shared" net: dsa: bcm_sf2: Fix race condition while unmasking interrupts net/mlx5: Added missing check of msg length in verifying its signature tipc: fix NULL pointer dereference in shutdown() net/irda: handle iriap_register_lsap() allocation failure vti: flush x-netns xfrm cache when vti interface is removed af_unix: split 'u->readlock' into two: 'iolock' and 'bindlock' Revert "af_unix: Fix splice-bind deadlock" bonding: Fix bonding crash megaraid: fix null pointer check in megasas_detach_one(). nouveau: fix nv40_perfctr_next() cleanup regression Staging: iio: adc: fix indent on break statement iwlegacy: avoid warning about missing braces ath9k: fix misleading indentation am437x-vfpe: fix typo in vpfe_get_app_input_index Add braces to avoid "ambiguous ‘else’" compiler warnings net: caif: fix misleading indentation Makefile: Mute warning for __builtin_return_address(>0) for tracing only Disable "frame-address" warning Disable "maybe-uninitialized" warning globally gcov: disable -Wmaybe-uninitialized warning Kbuild: disable 'maybe-uninitialized' warning for CONFIG_PROFILE_ALL_BRANCHES kbuild: forbid kernel directory to contain spaces and colons tools: Support relative directory path for 'O=' Makefile: revert "Makefile: Document ability to make file.lst and file.S" partially kbuild: Do not run modules_install and install in paralel ocfs2: fix start offset to ocfs2_zero_range_for_truncate() ocfs2/dlm: fix race between convert and migration crypto: echainiv - Replace chaining with multiplication crypto: skcipher - Fix blkcipher walk OOM crash crypto: arm/aes-ctr - fix NULL dereference in tail processing crypto: arm64/aes-ctr - fix NULL dereference in tail processing tcp: properly scale window in tcp_v[46]_reqsk_send_ack() tcp: fix use after free in tcp_xmit_retransmit_queue() tcp: cwnd does not increase in TCP YeAH ipv6: release dst in ping_v6_sendmsg ipv4: panic in leaf_walk_rcu due to stale node pointer reiserfs: fix "new_insert_key may be used uninitialized ..." Fix build warning in kernel/cpuset.c include/linux/kernel.h: change abs() macro so it uses consistent return type Linux 4.4.22 openrisc: fix the fix of copy_from_user() avr32: fix 'undefined reference to `___copy_from_user' ia64: copy_from_user() should zero the destination on access_ok() failure genirq/msi: Fix broken debug output ppc32: fix copy_from_user() sparc32: fix copy_from_user() mn10300: copy_from_user() should zero on access_ok() failure... nios2: copy_from_user() should zero the tail of destination openrisc: fix copy_from_user() parisc: fix copy_from_user() metag: copy_from_user() should zero the destination on access_ok() failure alpha: fix copy_from_user() asm-generic: make copy_from_user() zero the destination properly mips: copy_from_user() must zero the destination on access_ok() failure hexagon: fix strncpy_from_user() error return sh: fix copy_from_user() score: fix copy_from_user() and friends blackfin: fix copy_from_user() cris: buggered copy_from_user/copy_to_user/clear_user frv: fix clear_user() asm-generic: make get_user() clear the destination on errors ARC: uaccess: get_user to zero out dest in cause of fault s390: get_user() should zero on failure score: fix __get_user/get_user nios2: fix __get_user() sh64: failing __get_user() should zero m32r: fix __get_user() mn10300: failing __get_user() and get_user() should zero fix minor infoleak in get_user_ex() microblaze: fix copy_from_user() avr32: fix copy_from_user() microblaze: fix __get_user() fix iov_iter_fault_in_readable() irqchip/atmel-aic: Fix potential deadlock in ->xlate() genirq: Provide irq_gc_{lock_irqsave,unlock_irqrestore}() helpers drm: Only use compat ioctl for addfb2 on X86/IA64 drm: atmel-hlcdc: Fix vertical scaling net: simplify napi_synchronize() to avoid warnings kconfig: tinyconfig: provide whole choice blocks to avoid warnings soc: qcom/spm: shut up uninitialized variable warning pinctrl: at91-pio4: use %pr format string for resource mmc: dw_mmc: use resource_size_t to store physical address drm/i915: Avoid pointer arithmetic in calculating plane surface offset mpssd: fix buffer overflow warning gma500: remove annoying deprecation warning ipv6: addrconf: fix dev refcont leak when DAD failed sched/core: Fix a race between try_to_wake_up() and a woken up task Revert "wext: Fix 32 bit iwpriv compatibility issue with 64 bit Kernel" ath9k: fix using sta->drv_priv before initializing it md-cluster: make md-cluster also can work when compiled into kernel xhci: fix null pointer dereference in stop command timeout function fuse: direct-io: don't dirty ITER_BVEC pages Btrfs: remove root_log_ctx from ctx list before btrfs_sync_log returns crypto: cryptd - initialize child shash_desc on import arm64: spinlocks: implement smp_mb__before_spinlock() as smp_mb() pinctrl: sunxi: fix uart1 CTS/RTS pins at PG on A23/A33 pinctrl: pistachio: fix mfio pll_lock pinmux dm crypt: fix error with too large bios dm log writes: move IO accounting earlier to fix error path dm log writes: fix check of kthread_run() return value bus: arm-ccn: Fix XP watchpoint settings bitmask bus: arm-ccn: Do not attempt to configure XPs for cycle counter bus: arm-ccn: Fix PMU handling of MN ARM: dts: STiH407-family: Provide interconnect clock for consumption in ST SDHCI ARM: dts: overo: fix gpmc nand on boards with ethernet ARM: dts: overo: fix gpmc nand cs0 range ARM: dts: imx6qdl: Fix SPDIF regression ARM: OMAP3: hwmod data: Add sysc information for DSI ARM: kirkwood: ib62x0: fix size of u-boot environment partition ARM: imx6: add missing BM_CLPCR_BYPASS_PMIC_READY setting for imx6sx ARM: imx6: add missing BM_CLPCR_BYP_MMDC_CH0_LPM_HS setting for imx6ul ARM: AM43XX: hwmod: Fix RSTST register offset for pruss cpuset: make sure new tasks conform to the current config of the cpuset net: thunderx: Fix OOPs with ethtool --register-dump USB: change bInterval default to 10 ms ARM: dts: STiH410: Handle interconnect clock required by EHCI/OHCI (USB) usb: chipidea: udc: fix NULL ptr dereference in isr_setup_status_phase usb: renesas_usbhs: fix clearing the {BRDY,BEMP}STS condition USB: serial: simple: add support for another Infineon flashloader serial: 8250: added acces i/o products quad and octal serial cards serial: 8250_mid: fix divide error bug if baud rate is 0 iio: ensure ret is initialized to zero before entering do loop iio:core: fix IIO_VAL_FRACTIONAL sign handling iio: accel: kxsd9: Fix scaling bug iio: fix pressure data output unit in hid-sensor-attributes iio: accel: bmc150: reset chip at init time iio: adc: at91: unbreak channel adc channel 3 iio: ad799x: Fix buffered capture for ad7991/ad7995/ad7999 iio: adc: ti_am335x_adc: Increase timeout value waiting for ADC sample iio: adc: ti_am335x_adc: Protect FIFO1 from concurrent access iio: adc: rockchip_saradc: reset saradc controller before programming it iio: proximity: as3935: set up buffer timestamps for non-zero values iio: accel: kxsd9: Fix raw read return kvm-arm: Unmap shadow pagetables properly x86/AMD: Apply erratum 665 on machines without a BIOS fix x86/paravirt: Do not trace _paravirt_ident_*() functions ARC: mm: fix build breakage with STRICT_MM_TYPECHECKS IB/uverbs: Fix race between uverbs_close and remove_one dm flakey: fix reads to be issued if drop_writes configured audit: fix exe_file access in audit_exe_compare mm: introduce get_task_exe_file kexec: fix double-free when failing to relocate the purgatory NFSv4.1: Fix the CREATE_SESSION slot number accounting pNFS: Ensure LAYOUTGET and LAYOUTRETURN are properly serialised nfsd: Close race between nfsd4_release_lockowner and nfsd4_lock NFSv4.x: Fix a refcount leak in nfs_callback_up_net pNFS: The client must not do I/O to the DS if it's lease has expired kernfs: don't depend on d_find_any_alias() when generating notifications powerpc/mm: Don't alias user region to other regions below PAGE_OFFSET powerpc/powernv : Drop reference added by kset_find_obj() powerpc/tm: do not use r13 for tabort_syscall tipc: move linearization of buffers to generic code lightnvm: put bio before return fscrypto: require write access to mount to set encryption policy Revert "KVM: x86: fix missed hardware breakpoints" MIPS: KVM: Check for pfn noslot case clocksource/drivers/sun4i: Clear interrupts after stopping timer in probe function fscrypto: add authorization check for setting encryption policy ext4: use __GFP_NOFAIL in ext4_free_blocks() Conflicts: arch/arm/kernel/devtree.c arch/arm64/Kconfig arch/arm64/kernel/arm64ksyms.c arch/arm64/kernel/psci.c arch/arm64/mm/fault.c drivers/android/binder.c drivers/usb/host/xhci-hub.c fs/ext4/readpage.c include/linux/mmc/core.h include/linux/mmzone.h mm/memcontrol.c net/core/filter.c net/netlink/af_netlink.c net/netlink/af_netlink.h Change-Id: I99fe7a0914e83e284b11b33185b71448a8999d1f Signed-off-by: Runmin Wang <runminw@codeaurora.org> Signed-off-by: Blagovest Kolenichev <bkolenichev@codeaurora.org>
1747 lines
43 KiB
C
1747 lines
43 KiB
C
/*
|
|
* An async IO implementation for Linux
|
|
* Written by Benjamin LaHaise <bcrl@kvack.org>
|
|
*
|
|
* Implements an efficient asynchronous io interface.
|
|
*
|
|
* Copyright 2000, 2001, 2002 Red Hat, Inc. All Rights Reserved.
|
|
*
|
|
* See ../COPYING for licensing terms.
|
|
*/
|
|
#define pr_fmt(fmt) "%s: " fmt, __func__
|
|
|
|
#include <linux/kernel.h>
|
|
#include <linux/init.h>
|
|
#include <linux/errno.h>
|
|
#include <linux/time.h>
|
|
#include <linux/aio_abi.h>
|
|
#include <linux/export.h>
|
|
#include <linux/syscalls.h>
|
|
#include <linux/backing-dev.h>
|
|
#include <linux/uio.h>
|
|
|
|
#include <linux/sched.h>
|
|
#include <linux/fs.h>
|
|
#include <linux/file.h>
|
|
#include <linux/mm.h>
|
|
#include <linux/mman.h>
|
|
#include <linux/mmu_context.h>
|
|
#include <linux/percpu.h>
|
|
#include <linux/slab.h>
|
|
#include <linux/timer.h>
|
|
#include <linux/aio.h>
|
|
#include <linux/highmem.h>
|
|
#include <linux/workqueue.h>
|
|
#include <linux/security.h>
|
|
#include <linux/eventfd.h>
|
|
#include <linux/blkdev.h>
|
|
#include <linux/compat.h>
|
|
#include <linux/migrate.h>
|
|
#include <linux/ramfs.h>
|
|
#include <linux/percpu-refcount.h>
|
|
#include <linux/mount.h>
|
|
|
|
#include <asm/kmap_types.h>
|
|
#include <asm/uaccess.h>
|
|
|
|
#include "internal.h"
|
|
|
|
#define AIO_RING_MAGIC 0xa10a10a1
|
|
#define AIO_RING_COMPAT_FEATURES 1
|
|
#define AIO_RING_INCOMPAT_FEATURES 0
|
|
struct aio_ring {
|
|
unsigned id; /* kernel internal index number */
|
|
unsigned nr; /* number of io_events */
|
|
unsigned head; /* Written to by userland or under ring_lock
|
|
* mutex by aio_read_events_ring(). */
|
|
unsigned tail;
|
|
|
|
unsigned magic;
|
|
unsigned compat_features;
|
|
unsigned incompat_features;
|
|
unsigned header_length; /* size of aio_ring */
|
|
|
|
|
|
struct io_event io_events[0];
|
|
}; /* 128 bytes + ring size */
|
|
|
|
#define AIO_RING_PAGES 8
|
|
|
|
struct kioctx_table {
|
|
struct rcu_head rcu;
|
|
unsigned nr;
|
|
struct kioctx *table[];
|
|
};
|
|
|
|
struct kioctx_cpu {
|
|
unsigned reqs_available;
|
|
};
|
|
|
|
struct ctx_rq_wait {
|
|
struct completion comp;
|
|
atomic_t count;
|
|
};
|
|
|
|
struct kioctx {
|
|
struct percpu_ref users;
|
|
atomic_t dead;
|
|
|
|
struct percpu_ref reqs;
|
|
|
|
unsigned long user_id;
|
|
|
|
struct __percpu kioctx_cpu *cpu;
|
|
|
|
/*
|
|
* For percpu reqs_available, number of slots we move to/from global
|
|
* counter at a time:
|
|
*/
|
|
unsigned req_batch;
|
|
/*
|
|
* This is what userspace passed to io_setup(), it's not used for
|
|
* anything but counting against the global max_reqs quota.
|
|
*
|
|
* The real limit is nr_events - 1, which will be larger (see
|
|
* aio_setup_ring())
|
|
*/
|
|
unsigned max_reqs;
|
|
|
|
/* Size of ringbuffer, in units of struct io_event */
|
|
unsigned nr_events;
|
|
|
|
unsigned long mmap_base;
|
|
unsigned long mmap_size;
|
|
|
|
struct page **ring_pages;
|
|
long nr_pages;
|
|
|
|
struct work_struct free_work;
|
|
|
|
/*
|
|
* signals when all in-flight requests are done
|
|
*/
|
|
struct ctx_rq_wait *rq_wait;
|
|
|
|
struct {
|
|
/*
|
|
* This counts the number of available slots in the ringbuffer,
|
|
* so we avoid overflowing it: it's decremented (if positive)
|
|
* when allocating a kiocb and incremented when the resulting
|
|
* io_event is pulled off the ringbuffer.
|
|
*
|
|
* We batch accesses to it with a percpu version.
|
|
*/
|
|
atomic_t reqs_available;
|
|
} ____cacheline_aligned_in_smp;
|
|
|
|
struct {
|
|
spinlock_t ctx_lock;
|
|
struct list_head active_reqs; /* used for cancellation */
|
|
} ____cacheline_aligned_in_smp;
|
|
|
|
struct {
|
|
struct mutex ring_lock;
|
|
wait_queue_head_t wait;
|
|
} ____cacheline_aligned_in_smp;
|
|
|
|
struct {
|
|
unsigned tail;
|
|
unsigned completed_events;
|
|
spinlock_t completion_lock;
|
|
} ____cacheline_aligned_in_smp;
|
|
|
|
struct page *internal_pages[AIO_RING_PAGES];
|
|
struct file *aio_ring_file;
|
|
|
|
unsigned id;
|
|
};
|
|
|
|
/*
|
|
* We use ki_cancel == KIOCB_CANCELLED to indicate that a kiocb has been either
|
|
* cancelled or completed (this makes a certain amount of sense because
|
|
* successful cancellation - io_cancel() - does deliver the completion to
|
|
* userspace).
|
|
*
|
|
* And since most things don't implement kiocb cancellation and we'd really like
|
|
* kiocb completion to be lockless when possible, we use ki_cancel to
|
|
* synchronize cancellation and completion - we only set it to KIOCB_CANCELLED
|
|
* with xchg() or cmpxchg(), see batch_complete_aio() and kiocb_cancel().
|
|
*/
|
|
#define KIOCB_CANCELLED ((void *) (~0ULL))
|
|
|
|
struct aio_kiocb {
|
|
struct kiocb common;
|
|
|
|
struct kioctx *ki_ctx;
|
|
kiocb_cancel_fn *ki_cancel;
|
|
|
|
struct iocb __user *ki_user_iocb; /* user's aiocb */
|
|
__u64 ki_user_data; /* user's data for completion */
|
|
|
|
struct list_head ki_list; /* the aio core uses this
|
|
* for cancellation */
|
|
|
|
/*
|
|
* If the aio_resfd field of the userspace iocb is not zero,
|
|
* this is the underlying eventfd context to deliver events to.
|
|
*/
|
|
struct eventfd_ctx *ki_eventfd;
|
|
};
|
|
|
|
/*------ sysctl variables----*/
|
|
static DEFINE_SPINLOCK(aio_nr_lock);
|
|
unsigned long aio_nr; /* current system wide number of aio requests */
|
|
unsigned long aio_max_nr = 0x10000; /* system wide maximum number of aio requests */
|
|
/*----end sysctl variables---*/
|
|
|
|
static struct kmem_cache *kiocb_cachep;
|
|
static struct kmem_cache *kioctx_cachep;
|
|
|
|
static struct vfsmount *aio_mnt;
|
|
|
|
static const struct file_operations aio_ring_fops;
|
|
static const struct address_space_operations aio_ctx_aops;
|
|
|
|
static struct file *aio_private_file(struct kioctx *ctx, loff_t nr_pages)
|
|
{
|
|
struct qstr this = QSTR_INIT("[aio]", 5);
|
|
struct file *file;
|
|
struct path path;
|
|
struct inode *inode = alloc_anon_inode(aio_mnt->mnt_sb);
|
|
if (IS_ERR(inode))
|
|
return ERR_CAST(inode);
|
|
|
|
inode->i_mapping->a_ops = &aio_ctx_aops;
|
|
inode->i_mapping->private_data = ctx;
|
|
inode->i_size = PAGE_SIZE * nr_pages;
|
|
|
|
path.dentry = d_alloc_pseudo(aio_mnt->mnt_sb, &this);
|
|
if (!path.dentry) {
|
|
iput(inode);
|
|
return ERR_PTR(-ENOMEM);
|
|
}
|
|
path.mnt = mntget(aio_mnt);
|
|
|
|
d_instantiate(path.dentry, inode);
|
|
file = alloc_file(&path, FMODE_READ | FMODE_WRITE, &aio_ring_fops);
|
|
if (IS_ERR(file)) {
|
|
path_put(&path);
|
|
return file;
|
|
}
|
|
|
|
file->f_flags = O_RDWR;
|
|
return file;
|
|
}
|
|
|
|
static struct dentry *aio_mount(struct file_system_type *fs_type,
|
|
int flags, const char *dev_name, void *data)
|
|
{
|
|
static const struct dentry_operations ops = {
|
|
.d_dname = simple_dname,
|
|
};
|
|
struct dentry *root = mount_pseudo(fs_type, "aio:", NULL, &ops,
|
|
AIO_RING_MAGIC);
|
|
|
|
if (!IS_ERR(root))
|
|
root->d_sb->s_iflags |= SB_I_NOEXEC;
|
|
return root;
|
|
}
|
|
|
|
/* aio_setup
|
|
* Creates the slab caches used by the aio routines, panic on
|
|
* failure as this is done early during the boot sequence.
|
|
*/
|
|
static int __init aio_setup(void)
|
|
{
|
|
static struct file_system_type aio_fs = {
|
|
.name = "aio",
|
|
.mount = aio_mount,
|
|
.kill_sb = kill_anon_super,
|
|
};
|
|
aio_mnt = kern_mount(&aio_fs);
|
|
if (IS_ERR(aio_mnt))
|
|
panic("Failed to create aio fs mount.");
|
|
aio_mnt->mnt_flags |= MNT_NOEXEC;
|
|
|
|
kiocb_cachep = KMEM_CACHE(aio_kiocb, SLAB_HWCACHE_ALIGN|SLAB_PANIC);
|
|
kioctx_cachep = KMEM_CACHE(kioctx,SLAB_HWCACHE_ALIGN|SLAB_PANIC);
|
|
|
|
pr_debug("sizeof(struct page) = %zu\n", sizeof(struct page));
|
|
|
|
return 0;
|
|
}
|
|
__initcall(aio_setup);
|
|
|
|
static void put_aio_ring_file(struct kioctx *ctx)
|
|
{
|
|
struct file *aio_ring_file = ctx->aio_ring_file;
|
|
if (aio_ring_file) {
|
|
truncate_setsize(aio_ring_file->f_inode, 0);
|
|
|
|
/* Prevent further access to the kioctx from migratepages */
|
|
spin_lock(&aio_ring_file->f_inode->i_mapping->private_lock);
|
|
aio_ring_file->f_inode->i_mapping->private_data = NULL;
|
|
ctx->aio_ring_file = NULL;
|
|
spin_unlock(&aio_ring_file->f_inode->i_mapping->private_lock);
|
|
|
|
fput(aio_ring_file);
|
|
}
|
|
}
|
|
|
|
static void aio_free_ring(struct kioctx *ctx)
|
|
{
|
|
int i;
|
|
|
|
/* Disconnect the kiotx from the ring file. This prevents future
|
|
* accesses to the kioctx from page migration.
|
|
*/
|
|
put_aio_ring_file(ctx);
|
|
|
|
for (i = 0; i < ctx->nr_pages; i++) {
|
|
struct page *page;
|
|
pr_debug("pid(%d) [%d] page->count=%d\n", current->pid, i,
|
|
page_count(ctx->ring_pages[i]));
|
|
page = ctx->ring_pages[i];
|
|
if (!page)
|
|
continue;
|
|
ctx->ring_pages[i] = NULL;
|
|
put_page(page);
|
|
}
|
|
|
|
if (ctx->ring_pages && ctx->ring_pages != ctx->internal_pages) {
|
|
kfree(ctx->ring_pages);
|
|
ctx->ring_pages = NULL;
|
|
}
|
|
}
|
|
|
|
static int aio_ring_mremap(struct vm_area_struct *vma)
|
|
{
|
|
struct file *file = vma->vm_file;
|
|
struct mm_struct *mm = vma->vm_mm;
|
|
struct kioctx_table *table;
|
|
int i, res = -EINVAL;
|
|
|
|
spin_lock(&mm->ioctx_lock);
|
|
rcu_read_lock();
|
|
table = rcu_dereference(mm->ioctx_table);
|
|
for (i = 0; i < table->nr; i++) {
|
|
struct kioctx *ctx;
|
|
|
|
ctx = table->table[i];
|
|
if (ctx && ctx->aio_ring_file == file) {
|
|
if (!atomic_read(&ctx->dead)) {
|
|
ctx->user_id = ctx->mmap_base = vma->vm_start;
|
|
res = 0;
|
|
}
|
|
break;
|
|
}
|
|
}
|
|
|
|
rcu_read_unlock();
|
|
spin_unlock(&mm->ioctx_lock);
|
|
return res;
|
|
}
|
|
|
|
static const struct vm_operations_struct aio_ring_vm_ops = {
|
|
.mremap = aio_ring_mremap,
|
|
#if IS_ENABLED(CONFIG_MMU)
|
|
.fault = filemap_fault,
|
|
.map_pages = filemap_map_pages,
|
|
.page_mkwrite = filemap_page_mkwrite,
|
|
#endif
|
|
};
|
|
|
|
static int aio_ring_mmap(struct file *file, struct vm_area_struct *vma)
|
|
{
|
|
vma->vm_flags |= VM_DONTEXPAND;
|
|
vma->vm_ops = &aio_ring_vm_ops;
|
|
return 0;
|
|
}
|
|
|
|
static const struct file_operations aio_ring_fops = {
|
|
.mmap = aio_ring_mmap,
|
|
};
|
|
|
|
#if IS_ENABLED(CONFIG_MIGRATION)
|
|
static int aio_migratepage(struct address_space *mapping, struct page *new,
|
|
struct page *old, enum migrate_mode mode)
|
|
{
|
|
struct kioctx *ctx;
|
|
unsigned long flags;
|
|
pgoff_t idx;
|
|
int rc;
|
|
|
|
rc = 0;
|
|
|
|
/* mapping->private_lock here protects against the kioctx teardown. */
|
|
spin_lock(&mapping->private_lock);
|
|
ctx = mapping->private_data;
|
|
if (!ctx) {
|
|
rc = -EINVAL;
|
|
goto out;
|
|
}
|
|
|
|
/* The ring_lock mutex. The prevents aio_read_events() from writing
|
|
* to the ring's head, and prevents page migration from mucking in
|
|
* a partially initialized kiotx.
|
|
*/
|
|
if (!mutex_trylock(&ctx->ring_lock)) {
|
|
rc = -EAGAIN;
|
|
goto out;
|
|
}
|
|
|
|
idx = old->index;
|
|
if (idx < (pgoff_t)ctx->nr_pages) {
|
|
/* Make sure the old page hasn't already been changed */
|
|
if (ctx->ring_pages[idx] != old)
|
|
rc = -EAGAIN;
|
|
} else
|
|
rc = -EINVAL;
|
|
|
|
if (rc != 0)
|
|
goto out_unlock;
|
|
|
|
/* Writeback must be complete */
|
|
BUG_ON(PageWriteback(old));
|
|
get_page(new);
|
|
|
|
rc = migrate_page_move_mapping(mapping, new, old, NULL, mode, 1);
|
|
if (rc != MIGRATEPAGE_SUCCESS) {
|
|
put_page(new);
|
|
goto out_unlock;
|
|
}
|
|
|
|
/* Take completion_lock to prevent other writes to the ring buffer
|
|
* while the old page is copied to the new. This prevents new
|
|
* events from being lost.
|
|
*/
|
|
spin_lock_irqsave(&ctx->completion_lock, flags);
|
|
migrate_page_copy(new, old);
|
|
BUG_ON(ctx->ring_pages[idx] != old);
|
|
ctx->ring_pages[idx] = new;
|
|
spin_unlock_irqrestore(&ctx->completion_lock, flags);
|
|
|
|
/* The old page is no longer accessible. */
|
|
put_page(old);
|
|
|
|
out_unlock:
|
|
mutex_unlock(&ctx->ring_lock);
|
|
out:
|
|
spin_unlock(&mapping->private_lock);
|
|
return rc;
|
|
}
|
|
#endif
|
|
|
|
static const struct address_space_operations aio_ctx_aops = {
|
|
.set_page_dirty = __set_page_dirty_no_writeback,
|
|
#if IS_ENABLED(CONFIG_MIGRATION)
|
|
.migratepage = aio_migratepage,
|
|
#endif
|
|
};
|
|
|
|
static int aio_setup_ring(struct kioctx *ctx)
|
|
{
|
|
struct aio_ring *ring;
|
|
unsigned nr_events = ctx->max_reqs;
|
|
struct mm_struct *mm = current->mm;
|
|
unsigned long size, unused;
|
|
int nr_pages;
|
|
int i;
|
|
struct file *file;
|
|
|
|
/* Compensate for the ring buffer's head/tail overlap entry */
|
|
nr_events += 2; /* 1 is required, 2 for good luck */
|
|
|
|
size = sizeof(struct aio_ring);
|
|
size += sizeof(struct io_event) * nr_events;
|
|
|
|
nr_pages = PFN_UP(size);
|
|
if (nr_pages < 0)
|
|
return -EINVAL;
|
|
|
|
file = aio_private_file(ctx, nr_pages);
|
|
if (IS_ERR(file)) {
|
|
ctx->aio_ring_file = NULL;
|
|
return -ENOMEM;
|
|
}
|
|
|
|
ctx->aio_ring_file = file;
|
|
nr_events = (PAGE_SIZE * nr_pages - sizeof(struct aio_ring))
|
|
/ sizeof(struct io_event);
|
|
|
|
ctx->ring_pages = ctx->internal_pages;
|
|
if (nr_pages > AIO_RING_PAGES) {
|
|
ctx->ring_pages = kcalloc(nr_pages, sizeof(struct page *),
|
|
GFP_KERNEL);
|
|
if (!ctx->ring_pages) {
|
|
put_aio_ring_file(ctx);
|
|
return -ENOMEM;
|
|
}
|
|
}
|
|
|
|
for (i = 0; i < nr_pages; i++) {
|
|
struct page *page;
|
|
page = find_or_create_page(file->f_inode->i_mapping,
|
|
i, GFP_HIGHUSER | __GFP_ZERO);
|
|
if (!page)
|
|
break;
|
|
pr_debug("pid(%d) page[%d]->count=%d\n",
|
|
current->pid, i, page_count(page));
|
|
SetPageUptodate(page);
|
|
unlock_page(page);
|
|
|
|
ctx->ring_pages[i] = page;
|
|
}
|
|
ctx->nr_pages = i;
|
|
|
|
if (unlikely(i != nr_pages)) {
|
|
aio_free_ring(ctx);
|
|
return -ENOMEM;
|
|
}
|
|
|
|
ctx->mmap_size = nr_pages * PAGE_SIZE;
|
|
pr_debug("attempting mmap of %lu bytes\n", ctx->mmap_size);
|
|
|
|
down_write(&mm->mmap_sem);
|
|
ctx->mmap_base = do_mmap_pgoff(ctx->aio_ring_file, 0, ctx->mmap_size,
|
|
PROT_READ | PROT_WRITE,
|
|
MAP_SHARED, 0, &unused);
|
|
up_write(&mm->mmap_sem);
|
|
if (IS_ERR((void *)ctx->mmap_base)) {
|
|
ctx->mmap_size = 0;
|
|
aio_free_ring(ctx);
|
|
return -ENOMEM;
|
|
}
|
|
|
|
pr_debug("mmap address: 0x%08lx\n", ctx->mmap_base);
|
|
|
|
ctx->user_id = ctx->mmap_base;
|
|
ctx->nr_events = nr_events; /* trusted copy */
|
|
|
|
ring = kmap_atomic(ctx->ring_pages[0]);
|
|
ring->nr = nr_events; /* user copy */
|
|
ring->id = ~0U;
|
|
ring->head = ring->tail = 0;
|
|
ring->magic = AIO_RING_MAGIC;
|
|
ring->compat_features = AIO_RING_COMPAT_FEATURES;
|
|
ring->incompat_features = AIO_RING_INCOMPAT_FEATURES;
|
|
ring->header_length = sizeof(struct aio_ring);
|
|
kunmap_atomic(ring);
|
|
flush_dcache_page(ctx->ring_pages[0]);
|
|
|
|
return 0;
|
|
}
|
|
|
|
#define AIO_EVENTS_PER_PAGE (PAGE_SIZE / sizeof(struct io_event))
|
|
#define AIO_EVENTS_FIRST_PAGE ((PAGE_SIZE - sizeof(struct aio_ring)) / sizeof(struct io_event))
|
|
#define AIO_EVENTS_OFFSET (AIO_EVENTS_PER_PAGE - AIO_EVENTS_FIRST_PAGE)
|
|
|
|
void kiocb_set_cancel_fn(struct kiocb *iocb, kiocb_cancel_fn *cancel)
|
|
{
|
|
struct aio_kiocb *req = container_of(iocb, struct aio_kiocb, common);
|
|
struct kioctx *ctx = req->ki_ctx;
|
|
unsigned long flags;
|
|
|
|
spin_lock_irqsave(&ctx->ctx_lock, flags);
|
|
|
|
if (!req->ki_list.next)
|
|
list_add(&req->ki_list, &ctx->active_reqs);
|
|
|
|
req->ki_cancel = cancel;
|
|
|
|
spin_unlock_irqrestore(&ctx->ctx_lock, flags);
|
|
}
|
|
EXPORT_SYMBOL(kiocb_set_cancel_fn);
|
|
|
|
static int kiocb_cancel(struct aio_kiocb *kiocb)
|
|
{
|
|
kiocb_cancel_fn *old, *cancel;
|
|
|
|
/*
|
|
* Don't want to set kiocb->ki_cancel = KIOCB_CANCELLED unless it
|
|
* actually has a cancel function, hence the cmpxchg()
|
|
*/
|
|
|
|
cancel = ACCESS_ONCE(kiocb->ki_cancel);
|
|
do {
|
|
if (!cancel || cancel == KIOCB_CANCELLED)
|
|
return -EINVAL;
|
|
|
|
old = cancel;
|
|
cancel = cmpxchg(&kiocb->ki_cancel, old, KIOCB_CANCELLED);
|
|
} while (cancel != old);
|
|
|
|
return cancel(&kiocb->common);
|
|
}
|
|
|
|
static void free_ioctx(struct work_struct *work)
|
|
{
|
|
struct kioctx *ctx = container_of(work, struct kioctx, free_work);
|
|
|
|
pr_debug("freeing %p\n", ctx);
|
|
|
|
aio_free_ring(ctx);
|
|
free_percpu(ctx->cpu);
|
|
percpu_ref_exit(&ctx->reqs);
|
|
percpu_ref_exit(&ctx->users);
|
|
kmem_cache_free(kioctx_cachep, ctx);
|
|
}
|
|
|
|
static void free_ioctx_reqs(struct percpu_ref *ref)
|
|
{
|
|
struct kioctx *ctx = container_of(ref, struct kioctx, reqs);
|
|
|
|
/* At this point we know that there are no any in-flight requests */
|
|
if (ctx->rq_wait && atomic_dec_and_test(&ctx->rq_wait->count))
|
|
complete(&ctx->rq_wait->comp);
|
|
|
|
INIT_WORK(&ctx->free_work, free_ioctx);
|
|
schedule_work(&ctx->free_work);
|
|
}
|
|
|
|
/*
|
|
* When this function runs, the kioctx has been removed from the "hash table"
|
|
* and ctx->users has dropped to 0, so we know no more kiocbs can be submitted -
|
|
* now it's safe to cancel any that need to be.
|
|
*/
|
|
static void free_ioctx_users(struct percpu_ref *ref)
|
|
{
|
|
struct kioctx *ctx = container_of(ref, struct kioctx, users);
|
|
struct aio_kiocb *req;
|
|
|
|
spin_lock_irq(&ctx->ctx_lock);
|
|
|
|
while (!list_empty(&ctx->active_reqs)) {
|
|
req = list_first_entry(&ctx->active_reqs,
|
|
struct aio_kiocb, ki_list);
|
|
|
|
list_del_init(&req->ki_list);
|
|
kiocb_cancel(req);
|
|
}
|
|
|
|
spin_unlock_irq(&ctx->ctx_lock);
|
|
|
|
percpu_ref_kill(&ctx->reqs);
|
|
percpu_ref_put(&ctx->reqs);
|
|
}
|
|
|
|
static int ioctx_add_table(struct kioctx *ctx, struct mm_struct *mm)
|
|
{
|
|
unsigned i, new_nr;
|
|
struct kioctx_table *table, *old;
|
|
struct aio_ring *ring;
|
|
|
|
spin_lock(&mm->ioctx_lock);
|
|
table = rcu_dereference_raw(mm->ioctx_table);
|
|
|
|
while (1) {
|
|
if (table)
|
|
for (i = 0; i < table->nr; i++)
|
|
if (!table->table[i]) {
|
|
ctx->id = i;
|
|
table->table[i] = ctx;
|
|
spin_unlock(&mm->ioctx_lock);
|
|
|
|
/* While kioctx setup is in progress,
|
|
* we are protected from page migration
|
|
* changes ring_pages by ->ring_lock.
|
|
*/
|
|
ring = kmap_atomic(ctx->ring_pages[0]);
|
|
ring->id = ctx->id;
|
|
kunmap_atomic(ring);
|
|
return 0;
|
|
}
|
|
|
|
new_nr = (table ? table->nr : 1) * 4;
|
|
spin_unlock(&mm->ioctx_lock);
|
|
|
|
table = kzalloc(sizeof(*table) + sizeof(struct kioctx *) *
|
|
new_nr, GFP_KERNEL);
|
|
if (!table)
|
|
return -ENOMEM;
|
|
|
|
table->nr = new_nr;
|
|
|
|
spin_lock(&mm->ioctx_lock);
|
|
old = rcu_dereference_raw(mm->ioctx_table);
|
|
|
|
if (!old) {
|
|
rcu_assign_pointer(mm->ioctx_table, table);
|
|
} else if (table->nr > old->nr) {
|
|
memcpy(table->table, old->table,
|
|
old->nr * sizeof(struct kioctx *));
|
|
|
|
rcu_assign_pointer(mm->ioctx_table, table);
|
|
kfree_rcu(old, rcu);
|
|
} else {
|
|
kfree(table);
|
|
table = old;
|
|
}
|
|
}
|
|
}
|
|
|
|
static void aio_nr_sub(unsigned nr)
|
|
{
|
|
spin_lock(&aio_nr_lock);
|
|
if (WARN_ON(aio_nr - nr > aio_nr))
|
|
aio_nr = 0;
|
|
else
|
|
aio_nr -= nr;
|
|
spin_unlock(&aio_nr_lock);
|
|
}
|
|
|
|
/* ioctx_alloc
|
|
* Allocates and initializes an ioctx. Returns an ERR_PTR if it failed.
|
|
*/
|
|
static struct kioctx *ioctx_alloc(unsigned nr_events)
|
|
{
|
|
struct mm_struct *mm = current->mm;
|
|
struct kioctx *ctx;
|
|
int err = -ENOMEM;
|
|
|
|
/*
|
|
* We keep track of the number of available ringbuffer slots, to prevent
|
|
* overflow (reqs_available), and we also use percpu counters for this.
|
|
*
|
|
* So since up to half the slots might be on other cpu's percpu counters
|
|
* and unavailable, double nr_events so userspace sees what they
|
|
* expected: additionally, we move req_batch slots to/from percpu
|
|
* counters at a time, so make sure that isn't 0:
|
|
*/
|
|
nr_events = max(nr_events, num_possible_cpus() * 4);
|
|
nr_events *= 2;
|
|
|
|
/* Prevent overflows */
|
|
if (nr_events > (0x10000000U / sizeof(struct io_event))) {
|
|
pr_debug("ENOMEM: nr_events too high\n");
|
|
return ERR_PTR(-EINVAL);
|
|
}
|
|
|
|
if (!nr_events || (unsigned long)nr_events > (aio_max_nr * 2UL))
|
|
return ERR_PTR(-EAGAIN);
|
|
|
|
ctx = kmem_cache_zalloc(kioctx_cachep, GFP_KERNEL);
|
|
if (!ctx)
|
|
return ERR_PTR(-ENOMEM);
|
|
|
|
ctx->max_reqs = nr_events;
|
|
|
|
spin_lock_init(&ctx->ctx_lock);
|
|
spin_lock_init(&ctx->completion_lock);
|
|
mutex_init(&ctx->ring_lock);
|
|
/* Protect against page migration throughout kiotx setup by keeping
|
|
* the ring_lock mutex held until setup is complete. */
|
|
mutex_lock(&ctx->ring_lock);
|
|
init_waitqueue_head(&ctx->wait);
|
|
|
|
INIT_LIST_HEAD(&ctx->active_reqs);
|
|
|
|
if (percpu_ref_init(&ctx->users, free_ioctx_users, 0, GFP_KERNEL))
|
|
goto err;
|
|
|
|
if (percpu_ref_init(&ctx->reqs, free_ioctx_reqs, 0, GFP_KERNEL))
|
|
goto err;
|
|
|
|
ctx->cpu = alloc_percpu(struct kioctx_cpu);
|
|
if (!ctx->cpu)
|
|
goto err;
|
|
|
|
err = aio_setup_ring(ctx);
|
|
if (err < 0)
|
|
goto err;
|
|
|
|
atomic_set(&ctx->reqs_available, ctx->nr_events - 1);
|
|
ctx->req_batch = (ctx->nr_events - 1) / (num_possible_cpus() * 4);
|
|
if (ctx->req_batch < 1)
|
|
ctx->req_batch = 1;
|
|
|
|
/* limit the number of system wide aios */
|
|
spin_lock(&aio_nr_lock);
|
|
if (aio_nr + nr_events > (aio_max_nr * 2UL) ||
|
|
aio_nr + nr_events < aio_nr) {
|
|
spin_unlock(&aio_nr_lock);
|
|
err = -EAGAIN;
|
|
goto err_ctx;
|
|
}
|
|
aio_nr += ctx->max_reqs;
|
|
spin_unlock(&aio_nr_lock);
|
|
|
|
percpu_ref_get(&ctx->users); /* io_setup() will drop this ref */
|
|
percpu_ref_get(&ctx->reqs); /* free_ioctx_users() will drop this */
|
|
|
|
err = ioctx_add_table(ctx, mm);
|
|
if (err)
|
|
goto err_cleanup;
|
|
|
|
/* Release the ring_lock mutex now that all setup is complete. */
|
|
mutex_unlock(&ctx->ring_lock);
|
|
|
|
pr_debug("allocated ioctx %p[%ld]: mm=%p mask=0x%x\n",
|
|
ctx, ctx->user_id, mm, ctx->nr_events);
|
|
return ctx;
|
|
|
|
err_cleanup:
|
|
aio_nr_sub(ctx->max_reqs);
|
|
err_ctx:
|
|
atomic_set(&ctx->dead, 1);
|
|
if (ctx->mmap_size)
|
|
vm_munmap(ctx->mmap_base, ctx->mmap_size);
|
|
aio_free_ring(ctx);
|
|
err:
|
|
mutex_unlock(&ctx->ring_lock);
|
|
free_percpu(ctx->cpu);
|
|
percpu_ref_exit(&ctx->reqs);
|
|
percpu_ref_exit(&ctx->users);
|
|
kmem_cache_free(kioctx_cachep, ctx);
|
|
pr_debug("error allocating ioctx %d\n", err);
|
|
return ERR_PTR(err);
|
|
}
|
|
|
|
/* kill_ioctx
|
|
* Cancels all outstanding aio requests on an aio context. Used
|
|
* when the processes owning a context have all exited to encourage
|
|
* the rapid destruction of the kioctx.
|
|
*/
|
|
static int kill_ioctx(struct mm_struct *mm, struct kioctx *ctx,
|
|
struct ctx_rq_wait *wait)
|
|
{
|
|
struct kioctx_table *table;
|
|
|
|
spin_lock(&mm->ioctx_lock);
|
|
if (atomic_xchg(&ctx->dead, 1)) {
|
|
spin_unlock(&mm->ioctx_lock);
|
|
return -EINVAL;
|
|
}
|
|
|
|
table = rcu_dereference_raw(mm->ioctx_table);
|
|
WARN_ON(ctx != table->table[ctx->id]);
|
|
table->table[ctx->id] = NULL;
|
|
spin_unlock(&mm->ioctx_lock);
|
|
|
|
/* percpu_ref_kill() will do the necessary call_rcu() */
|
|
wake_up_all(&ctx->wait);
|
|
|
|
/*
|
|
* It'd be more correct to do this in free_ioctx(), after all
|
|
* the outstanding kiocbs have finished - but by then io_destroy
|
|
* has already returned, so io_setup() could potentially return
|
|
* -EAGAIN with no ioctxs actually in use (as far as userspace
|
|
* could tell).
|
|
*/
|
|
aio_nr_sub(ctx->max_reqs);
|
|
|
|
if (ctx->mmap_size)
|
|
vm_munmap(ctx->mmap_base, ctx->mmap_size);
|
|
|
|
ctx->rq_wait = wait;
|
|
percpu_ref_kill(&ctx->users);
|
|
return 0;
|
|
}
|
|
|
|
/*
|
|
* exit_aio: called when the last user of mm goes away. At this point, there is
|
|
* no way for any new requests to be submited or any of the io_* syscalls to be
|
|
* called on the context.
|
|
*
|
|
* There may be outstanding kiocbs, but free_ioctx() will explicitly wait on
|
|
* them.
|
|
*/
|
|
void exit_aio(struct mm_struct *mm)
|
|
{
|
|
struct kioctx_table *table = rcu_dereference_raw(mm->ioctx_table);
|
|
struct ctx_rq_wait wait;
|
|
int i, skipped;
|
|
|
|
if (!table)
|
|
return;
|
|
|
|
atomic_set(&wait.count, table->nr);
|
|
init_completion(&wait.comp);
|
|
|
|
skipped = 0;
|
|
for (i = 0; i < table->nr; ++i) {
|
|
struct kioctx *ctx = table->table[i];
|
|
|
|
if (!ctx) {
|
|
skipped++;
|
|
continue;
|
|
}
|
|
|
|
/*
|
|
* We don't need to bother with munmap() here - exit_mmap(mm)
|
|
* is coming and it'll unmap everything. And we simply can't,
|
|
* this is not necessarily our ->mm.
|
|
* Since kill_ioctx() uses non-zero ->mmap_size as indicator
|
|
* that it needs to unmap the area, just set it to 0.
|
|
*/
|
|
ctx->mmap_size = 0;
|
|
kill_ioctx(mm, ctx, &wait);
|
|
}
|
|
|
|
if (!atomic_sub_and_test(skipped, &wait.count)) {
|
|
/* Wait until all IO for the context are done. */
|
|
wait_for_completion(&wait.comp);
|
|
}
|
|
|
|
RCU_INIT_POINTER(mm->ioctx_table, NULL);
|
|
kfree(table);
|
|
}
|
|
|
|
static void put_reqs_available(struct kioctx *ctx, unsigned nr)
|
|
{
|
|
struct kioctx_cpu *kcpu;
|
|
unsigned long flags;
|
|
|
|
local_irq_save(flags);
|
|
kcpu = this_cpu_ptr(ctx->cpu);
|
|
kcpu->reqs_available += nr;
|
|
|
|
while (kcpu->reqs_available >= ctx->req_batch * 2) {
|
|
kcpu->reqs_available -= ctx->req_batch;
|
|
atomic_add(ctx->req_batch, &ctx->reqs_available);
|
|
}
|
|
|
|
local_irq_restore(flags);
|
|
}
|
|
|
|
static bool get_reqs_available(struct kioctx *ctx)
|
|
{
|
|
struct kioctx_cpu *kcpu;
|
|
bool ret = false;
|
|
unsigned long flags;
|
|
|
|
local_irq_save(flags);
|
|
kcpu = this_cpu_ptr(ctx->cpu);
|
|
if (!kcpu->reqs_available) {
|
|
int old, avail = atomic_read(&ctx->reqs_available);
|
|
|
|
do {
|
|
if (avail < ctx->req_batch)
|
|
goto out;
|
|
|
|
old = avail;
|
|
avail = atomic_cmpxchg(&ctx->reqs_available,
|
|
avail, avail - ctx->req_batch);
|
|
} while (avail != old);
|
|
|
|
kcpu->reqs_available += ctx->req_batch;
|
|
}
|
|
|
|
ret = true;
|
|
kcpu->reqs_available--;
|
|
out:
|
|
local_irq_restore(flags);
|
|
return ret;
|
|
}
|
|
|
|
/* refill_reqs_available
|
|
* Updates the reqs_available reference counts used for tracking the
|
|
* number of free slots in the completion ring. This can be called
|
|
* from aio_complete() (to optimistically update reqs_available) or
|
|
* from aio_get_req() (the we're out of events case). It must be
|
|
* called holding ctx->completion_lock.
|
|
*/
|
|
static void refill_reqs_available(struct kioctx *ctx, unsigned head,
|
|
unsigned tail)
|
|
{
|
|
unsigned events_in_ring, completed;
|
|
|
|
/* Clamp head since userland can write to it. */
|
|
head %= ctx->nr_events;
|
|
if (head <= tail)
|
|
events_in_ring = tail - head;
|
|
else
|
|
events_in_ring = ctx->nr_events - (head - tail);
|
|
|
|
completed = ctx->completed_events;
|
|
if (events_in_ring < completed)
|
|
completed -= events_in_ring;
|
|
else
|
|
completed = 0;
|
|
|
|
if (!completed)
|
|
return;
|
|
|
|
ctx->completed_events -= completed;
|
|
put_reqs_available(ctx, completed);
|
|
}
|
|
|
|
/* user_refill_reqs_available
|
|
* Called to refill reqs_available when aio_get_req() encounters an
|
|
* out of space in the completion ring.
|
|
*/
|
|
static void user_refill_reqs_available(struct kioctx *ctx)
|
|
{
|
|
spin_lock_irq(&ctx->completion_lock);
|
|
if (ctx->completed_events) {
|
|
struct aio_ring *ring;
|
|
unsigned head;
|
|
|
|
/* Access of ring->head may race with aio_read_events_ring()
|
|
* here, but that's okay since whether we read the old version
|
|
* or the new version, and either will be valid. The important
|
|
* part is that head cannot pass tail since we prevent
|
|
* aio_complete() from updating tail by holding
|
|
* ctx->completion_lock. Even if head is invalid, the check
|
|
* against ctx->completed_events below will make sure we do the
|
|
* safe/right thing.
|
|
*/
|
|
ring = kmap_atomic(ctx->ring_pages[0]);
|
|
head = ring->head;
|
|
kunmap_atomic(ring);
|
|
|
|
refill_reqs_available(ctx, head, ctx->tail);
|
|
}
|
|
|
|
spin_unlock_irq(&ctx->completion_lock);
|
|
}
|
|
|
|
/* aio_get_req
|
|
* Allocate a slot for an aio request.
|
|
* Returns NULL if no requests are free.
|
|
*/
|
|
static inline struct aio_kiocb *aio_get_req(struct kioctx *ctx)
|
|
{
|
|
struct aio_kiocb *req;
|
|
|
|
if (!get_reqs_available(ctx)) {
|
|
user_refill_reqs_available(ctx);
|
|
if (!get_reqs_available(ctx))
|
|
return NULL;
|
|
}
|
|
|
|
req = kmem_cache_alloc(kiocb_cachep, GFP_KERNEL|__GFP_ZERO);
|
|
if (unlikely(!req))
|
|
goto out_put;
|
|
|
|
percpu_ref_get(&ctx->reqs);
|
|
|
|
req->ki_ctx = ctx;
|
|
return req;
|
|
out_put:
|
|
put_reqs_available(ctx, 1);
|
|
return NULL;
|
|
}
|
|
|
|
static void kiocb_free(struct aio_kiocb *req)
|
|
{
|
|
if (req->common.ki_filp)
|
|
fput(req->common.ki_filp);
|
|
if (req->ki_eventfd != NULL)
|
|
eventfd_ctx_put(req->ki_eventfd);
|
|
kmem_cache_free(kiocb_cachep, req);
|
|
}
|
|
|
|
static struct kioctx *lookup_ioctx(unsigned long ctx_id)
|
|
{
|
|
struct aio_ring __user *ring = (void __user *)ctx_id;
|
|
struct mm_struct *mm = current->mm;
|
|
struct kioctx *ctx, *ret = NULL;
|
|
struct kioctx_table *table;
|
|
unsigned id;
|
|
|
|
if (get_user(id, &ring->id))
|
|
return NULL;
|
|
|
|
rcu_read_lock();
|
|
table = rcu_dereference(mm->ioctx_table);
|
|
|
|
if (!table || id >= table->nr)
|
|
goto out;
|
|
|
|
ctx = table->table[id];
|
|
if (ctx && ctx->user_id == ctx_id) {
|
|
percpu_ref_get(&ctx->users);
|
|
ret = ctx;
|
|
}
|
|
out:
|
|
rcu_read_unlock();
|
|
return ret;
|
|
}
|
|
|
|
/* aio_complete
|
|
* Called when the io request on the given iocb is complete.
|
|
*/
|
|
static void aio_complete(struct kiocb *kiocb, long res, long res2)
|
|
{
|
|
struct aio_kiocb *iocb = container_of(kiocb, struct aio_kiocb, common);
|
|
struct kioctx *ctx = iocb->ki_ctx;
|
|
struct aio_ring *ring;
|
|
struct io_event *ev_page, *event;
|
|
unsigned tail, pos, head;
|
|
unsigned long flags;
|
|
|
|
/*
|
|
* Special case handling for sync iocbs:
|
|
* - events go directly into the iocb for fast handling
|
|
* - the sync task with the iocb in its stack holds the single iocb
|
|
* ref, no other paths have a way to get another ref
|
|
* - the sync task helpfully left a reference to itself in the iocb
|
|
*/
|
|
BUG_ON(is_sync_kiocb(kiocb));
|
|
|
|
if (iocb->ki_list.next) {
|
|
unsigned long flags;
|
|
|
|
spin_lock_irqsave(&ctx->ctx_lock, flags);
|
|
list_del(&iocb->ki_list);
|
|
spin_unlock_irqrestore(&ctx->ctx_lock, flags);
|
|
}
|
|
|
|
/*
|
|
* Add a completion event to the ring buffer. Must be done holding
|
|
* ctx->completion_lock to prevent other code from messing with the tail
|
|
* pointer since we might be called from irq context.
|
|
*/
|
|
spin_lock_irqsave(&ctx->completion_lock, flags);
|
|
|
|
tail = ctx->tail;
|
|
pos = tail + AIO_EVENTS_OFFSET;
|
|
|
|
if (++tail >= ctx->nr_events)
|
|
tail = 0;
|
|
|
|
ev_page = kmap_atomic(ctx->ring_pages[pos / AIO_EVENTS_PER_PAGE]);
|
|
event = ev_page + pos % AIO_EVENTS_PER_PAGE;
|
|
|
|
event->obj = (u64)(unsigned long)iocb->ki_user_iocb;
|
|
event->data = iocb->ki_user_data;
|
|
event->res = res;
|
|
event->res2 = res2;
|
|
|
|
kunmap_atomic(ev_page);
|
|
flush_dcache_page(ctx->ring_pages[pos / AIO_EVENTS_PER_PAGE]);
|
|
|
|
pr_debug("%p[%u]: %p: %p %Lx %lx %lx\n",
|
|
ctx, tail, iocb, iocb->ki_user_iocb, iocb->ki_user_data,
|
|
res, res2);
|
|
|
|
/* after flagging the request as done, we
|
|
* must never even look at it again
|
|
*/
|
|
smp_wmb(); /* make event visible before updating tail */
|
|
|
|
ctx->tail = tail;
|
|
|
|
ring = kmap_atomic(ctx->ring_pages[0]);
|
|
head = ring->head;
|
|
ring->tail = tail;
|
|
kunmap_atomic(ring);
|
|
flush_dcache_page(ctx->ring_pages[0]);
|
|
|
|
ctx->completed_events++;
|
|
if (ctx->completed_events > 1)
|
|
refill_reqs_available(ctx, head, tail);
|
|
spin_unlock_irqrestore(&ctx->completion_lock, flags);
|
|
|
|
pr_debug("added to ring %p at [%u]\n", iocb, tail);
|
|
|
|
/*
|
|
* Check if the user asked us to deliver the result through an
|
|
* eventfd. The eventfd_signal() function is safe to be called
|
|
* from IRQ context.
|
|
*/
|
|
if (iocb->ki_eventfd != NULL)
|
|
eventfd_signal(iocb->ki_eventfd, 1);
|
|
|
|
/* everything turned out well, dispose of the aiocb. */
|
|
kiocb_free(iocb);
|
|
|
|
/*
|
|
* We have to order our ring_info tail store above and test
|
|
* of the wait list below outside the wait lock. This is
|
|
* like in wake_up_bit() where clearing a bit has to be
|
|
* ordered with the unlocked test.
|
|
*/
|
|
smp_mb();
|
|
|
|
if (waitqueue_active(&ctx->wait))
|
|
wake_up(&ctx->wait);
|
|
|
|
percpu_ref_put(&ctx->reqs);
|
|
}
|
|
|
|
/* aio_read_events_ring
|
|
* Pull an event off of the ioctx's event ring. Returns the number of
|
|
* events fetched
|
|
*/
|
|
static long aio_read_events_ring(struct kioctx *ctx,
|
|
struct io_event __user *event, long nr)
|
|
{
|
|
struct aio_ring *ring;
|
|
unsigned head, tail, pos;
|
|
long ret = 0;
|
|
int copy_ret;
|
|
|
|
/*
|
|
* The mutex can block and wake us up and that will cause
|
|
* wait_event_interruptible_hrtimeout() to schedule without sleeping
|
|
* and repeat. This should be rare enough that it doesn't cause
|
|
* peformance issues. See the comment in read_events() for more detail.
|
|
*/
|
|
sched_annotate_sleep();
|
|
mutex_lock(&ctx->ring_lock);
|
|
|
|
/* Access to ->ring_pages here is protected by ctx->ring_lock. */
|
|
ring = kmap_atomic(ctx->ring_pages[0]);
|
|
head = ring->head;
|
|
tail = ring->tail;
|
|
kunmap_atomic(ring);
|
|
|
|
/*
|
|
* Ensure that once we've read the current tail pointer, that
|
|
* we also see the events that were stored up to the tail.
|
|
*/
|
|
smp_rmb();
|
|
|
|
pr_debug("h%u t%u m%u\n", head, tail, ctx->nr_events);
|
|
|
|
if (head == tail)
|
|
goto out;
|
|
|
|
head %= ctx->nr_events;
|
|
tail %= ctx->nr_events;
|
|
|
|
while (ret < nr) {
|
|
long avail;
|
|
struct io_event *ev;
|
|
struct page *page;
|
|
|
|
avail = (head <= tail ? tail : ctx->nr_events) - head;
|
|
if (head == tail)
|
|
break;
|
|
|
|
avail = min(avail, nr - ret);
|
|
avail = min_t(long, avail, AIO_EVENTS_PER_PAGE -
|
|
((head + AIO_EVENTS_OFFSET) % AIO_EVENTS_PER_PAGE));
|
|
|
|
pos = head + AIO_EVENTS_OFFSET;
|
|
page = ctx->ring_pages[pos / AIO_EVENTS_PER_PAGE];
|
|
pos %= AIO_EVENTS_PER_PAGE;
|
|
|
|
ev = kmap(page);
|
|
copy_ret = copy_to_user(event + ret, ev + pos,
|
|
sizeof(*ev) * avail);
|
|
kunmap(page);
|
|
|
|
if (unlikely(copy_ret)) {
|
|
ret = -EFAULT;
|
|
goto out;
|
|
}
|
|
|
|
ret += avail;
|
|
head += avail;
|
|
head %= ctx->nr_events;
|
|
}
|
|
|
|
ring = kmap_atomic(ctx->ring_pages[0]);
|
|
ring->head = head;
|
|
kunmap_atomic(ring);
|
|
flush_dcache_page(ctx->ring_pages[0]);
|
|
|
|
pr_debug("%li h%u t%u\n", ret, head, tail);
|
|
out:
|
|
mutex_unlock(&ctx->ring_lock);
|
|
|
|
return ret;
|
|
}
|
|
|
|
static bool aio_read_events(struct kioctx *ctx, long min_nr, long nr,
|
|
struct io_event __user *event, long *i)
|
|
{
|
|
long ret = aio_read_events_ring(ctx, event + *i, nr - *i);
|
|
|
|
if (ret > 0)
|
|
*i += ret;
|
|
|
|
if (unlikely(atomic_read(&ctx->dead)))
|
|
ret = -EINVAL;
|
|
|
|
if (!*i)
|
|
*i = ret;
|
|
|
|
return ret < 0 || *i >= min_nr;
|
|
}
|
|
|
|
static long read_events(struct kioctx *ctx, long min_nr, long nr,
|
|
struct io_event __user *event,
|
|
struct timespec __user *timeout)
|
|
{
|
|
ktime_t until = { .tv64 = KTIME_MAX };
|
|
long ret = 0;
|
|
|
|
if (timeout) {
|
|
struct timespec ts;
|
|
|
|
if (unlikely(copy_from_user(&ts, timeout, sizeof(ts))))
|
|
return -EFAULT;
|
|
|
|
until = timespec_to_ktime(ts);
|
|
}
|
|
|
|
/*
|
|
* Note that aio_read_events() is being called as the conditional - i.e.
|
|
* we're calling it after prepare_to_wait() has set task state to
|
|
* TASK_INTERRUPTIBLE.
|
|
*
|
|
* But aio_read_events() can block, and if it blocks it's going to flip
|
|
* the task state back to TASK_RUNNING.
|
|
*
|
|
* This should be ok, provided it doesn't flip the state back to
|
|
* TASK_RUNNING and return 0 too much - that causes us to spin. That
|
|
* will only happen if the mutex_lock() call blocks, and we then find
|
|
* the ringbuffer empty. So in practice we should be ok, but it's
|
|
* something to be aware of when touching this code.
|
|
*/
|
|
if (until.tv64 == 0)
|
|
aio_read_events(ctx, min_nr, nr, event, &ret);
|
|
else
|
|
wait_event_interruptible_hrtimeout(ctx->wait,
|
|
aio_read_events(ctx, min_nr, nr, event, &ret),
|
|
until);
|
|
|
|
if (!ret && signal_pending(current))
|
|
ret = -EINTR;
|
|
|
|
return ret;
|
|
}
|
|
|
|
/* sys_io_setup:
|
|
* Create an aio_context capable of receiving at least nr_events.
|
|
* ctxp must not point to an aio_context that already exists, and
|
|
* must be initialized to 0 prior to the call. On successful
|
|
* creation of the aio_context, *ctxp is filled in with the resulting
|
|
* handle. May fail with -EINVAL if *ctxp is not initialized,
|
|
* if the specified nr_events exceeds internal limits. May fail
|
|
* with -EAGAIN if the specified nr_events exceeds the user's limit
|
|
* of available events. May fail with -ENOMEM if insufficient kernel
|
|
* resources are available. May fail with -EFAULT if an invalid
|
|
* pointer is passed for ctxp. Will fail with -ENOSYS if not
|
|
* implemented.
|
|
*/
|
|
SYSCALL_DEFINE2(io_setup, unsigned, nr_events, aio_context_t __user *, ctxp)
|
|
{
|
|
struct kioctx *ioctx = NULL;
|
|
unsigned long ctx = 0;
|
|
long ret;
|
|
|
|
ret = get_user(ctx, ctxp);
|
|
if (unlikely(ret))
|
|
goto out;
|
|
|
|
ret = -EINVAL;
|
|
if (unlikely(ctx || nr_events == 0)) {
|
|
pr_debug("EINVAL: ctx %lu nr_events %u\n",
|
|
ctx, nr_events);
|
|
goto out;
|
|
}
|
|
|
|
ioctx = ioctx_alloc(nr_events);
|
|
ret = PTR_ERR(ioctx);
|
|
if (!IS_ERR(ioctx)) {
|
|
ret = put_user(ioctx->user_id, ctxp);
|
|
if (ret)
|
|
kill_ioctx(current->mm, ioctx, NULL);
|
|
percpu_ref_put(&ioctx->users);
|
|
}
|
|
|
|
out:
|
|
return ret;
|
|
}
|
|
|
|
/* sys_io_destroy:
|
|
* Destroy the aio_context specified. May cancel any outstanding
|
|
* AIOs and block on completion. Will fail with -ENOSYS if not
|
|
* implemented. May fail with -EINVAL if the context pointed to
|
|
* is invalid.
|
|
*/
|
|
SYSCALL_DEFINE1(io_destroy, aio_context_t, ctx)
|
|
{
|
|
struct kioctx *ioctx = lookup_ioctx(ctx);
|
|
if (likely(NULL != ioctx)) {
|
|
struct ctx_rq_wait wait;
|
|
int ret;
|
|
|
|
init_completion(&wait.comp);
|
|
atomic_set(&wait.count, 1);
|
|
|
|
/* Pass requests_done to kill_ioctx() where it can be set
|
|
* in a thread-safe way. If we try to set it here then we have
|
|
* a race condition if two io_destroy() called simultaneously.
|
|
*/
|
|
ret = kill_ioctx(current->mm, ioctx, &wait);
|
|
percpu_ref_put(&ioctx->users);
|
|
|
|
/* Wait until all IO for the context are done. Otherwise kernel
|
|
* keep using user-space buffers even if user thinks the context
|
|
* is destroyed.
|
|
*/
|
|
if (!ret)
|
|
wait_for_completion(&wait.comp);
|
|
|
|
return ret;
|
|
}
|
|
pr_debug("EINVAL: invalid context id\n");
|
|
return -EINVAL;
|
|
}
|
|
|
|
typedef ssize_t (rw_iter_op)(struct kiocb *, struct iov_iter *);
|
|
|
|
static int aio_setup_vectored_rw(int rw, char __user *buf, size_t len,
|
|
struct iovec **iovec,
|
|
bool compat,
|
|
struct iov_iter *iter)
|
|
{
|
|
#ifdef CONFIG_COMPAT
|
|
if (compat)
|
|
return compat_import_iovec(rw,
|
|
(struct compat_iovec __user *)buf,
|
|
len, UIO_FASTIOV, iovec, iter);
|
|
#endif
|
|
return import_iovec(rw, (struct iovec __user *)buf,
|
|
len, UIO_FASTIOV, iovec, iter);
|
|
}
|
|
|
|
/*
|
|
* aio_run_iocb:
|
|
* Performs the initial checks and io submission.
|
|
*/
|
|
static ssize_t aio_run_iocb(struct kiocb *req, unsigned opcode,
|
|
char __user *buf, size_t len, bool compat)
|
|
{
|
|
struct file *file = req->ki_filp;
|
|
ssize_t ret;
|
|
int rw;
|
|
fmode_t mode;
|
|
rw_iter_op *iter_op;
|
|
struct iovec inline_vecs[UIO_FASTIOV], *iovec = inline_vecs;
|
|
struct iov_iter iter;
|
|
|
|
switch (opcode) {
|
|
case IOCB_CMD_PREAD:
|
|
case IOCB_CMD_PREADV:
|
|
mode = FMODE_READ;
|
|
rw = READ;
|
|
iter_op = file->f_op->read_iter;
|
|
goto rw_common;
|
|
|
|
case IOCB_CMD_PWRITE:
|
|
case IOCB_CMD_PWRITEV:
|
|
mode = FMODE_WRITE;
|
|
rw = WRITE;
|
|
iter_op = file->f_op->write_iter;
|
|
goto rw_common;
|
|
rw_common:
|
|
if (unlikely(!(file->f_mode & mode)))
|
|
return -EBADF;
|
|
|
|
if (!iter_op)
|
|
return -EINVAL;
|
|
|
|
if (opcode == IOCB_CMD_PREADV || opcode == IOCB_CMD_PWRITEV)
|
|
ret = aio_setup_vectored_rw(rw, buf, len,
|
|
&iovec, compat, &iter);
|
|
else {
|
|
ret = import_single_range(rw, buf, len, iovec, &iter);
|
|
iovec = NULL;
|
|
}
|
|
if (!ret)
|
|
ret = rw_verify_area(rw, file, &req->ki_pos,
|
|
iov_iter_count(&iter));
|
|
if (ret < 0) {
|
|
kfree(iovec);
|
|
return ret;
|
|
}
|
|
|
|
len = ret;
|
|
|
|
if (rw == WRITE)
|
|
file_start_write(file);
|
|
|
|
ret = iter_op(req, &iter);
|
|
|
|
if (rw == WRITE)
|
|
file_end_write(file);
|
|
kfree(iovec);
|
|
break;
|
|
|
|
case IOCB_CMD_FDSYNC:
|
|
if (!file->f_op->aio_fsync)
|
|
return -EINVAL;
|
|
|
|
ret = file->f_op->aio_fsync(req, 1);
|
|
break;
|
|
|
|
case IOCB_CMD_FSYNC:
|
|
if (!file->f_op->aio_fsync)
|
|
return -EINVAL;
|
|
|
|
ret = file->f_op->aio_fsync(req, 0);
|
|
break;
|
|
|
|
default:
|
|
pr_debug("EINVAL: no operation provided\n");
|
|
return -EINVAL;
|
|
}
|
|
|
|
if (ret != -EIOCBQUEUED) {
|
|
/*
|
|
* There's no easy way to restart the syscall since other AIO's
|
|
* may be already running. Just fail this IO with EINTR.
|
|
*/
|
|
if (unlikely(ret == -ERESTARTSYS || ret == -ERESTARTNOINTR ||
|
|
ret == -ERESTARTNOHAND ||
|
|
ret == -ERESTART_RESTARTBLOCK))
|
|
ret = -EINTR;
|
|
aio_complete(req, ret, 0);
|
|
}
|
|
|
|
return 0;
|
|
}
|
|
|
|
static int io_submit_one(struct kioctx *ctx, struct iocb __user *user_iocb,
|
|
struct iocb *iocb, bool compat)
|
|
{
|
|
struct aio_kiocb *req;
|
|
ssize_t ret;
|
|
|
|
/* enforce forwards compatibility on users */
|
|
if (unlikely(iocb->aio_reserved1 || iocb->aio_reserved2)) {
|
|
pr_debug("EINVAL: reserve field set\n");
|
|
return -EINVAL;
|
|
}
|
|
|
|
/* prevent overflows */
|
|
if (unlikely(
|
|
(iocb->aio_buf != (unsigned long)iocb->aio_buf) ||
|
|
(iocb->aio_nbytes != (size_t)iocb->aio_nbytes) ||
|
|
((ssize_t)iocb->aio_nbytes < 0)
|
|
)) {
|
|
pr_debug("EINVAL: overflow check\n");
|
|
return -EINVAL;
|
|
}
|
|
|
|
req = aio_get_req(ctx);
|
|
if (unlikely(!req))
|
|
return -EAGAIN;
|
|
|
|
req->common.ki_filp = fget(iocb->aio_fildes);
|
|
if (unlikely(!req->common.ki_filp)) {
|
|
ret = -EBADF;
|
|
goto out_put_req;
|
|
}
|
|
req->common.ki_pos = iocb->aio_offset;
|
|
req->common.ki_complete = aio_complete;
|
|
req->common.ki_flags = iocb_flags(req->common.ki_filp);
|
|
|
|
if (iocb->aio_flags & IOCB_FLAG_RESFD) {
|
|
/*
|
|
* If the IOCB_FLAG_RESFD flag of aio_flags is set, get an
|
|
* instance of the file* now. The file descriptor must be
|
|
* an eventfd() fd, and will be signaled for each completed
|
|
* event using the eventfd_signal() function.
|
|
*/
|
|
req->ki_eventfd = eventfd_ctx_fdget((int) iocb->aio_resfd);
|
|
if (IS_ERR(req->ki_eventfd)) {
|
|
ret = PTR_ERR(req->ki_eventfd);
|
|
req->ki_eventfd = NULL;
|
|
goto out_put_req;
|
|
}
|
|
|
|
req->common.ki_flags |= IOCB_EVENTFD;
|
|
}
|
|
|
|
ret = put_user(KIOCB_KEY, &user_iocb->aio_key);
|
|
if (unlikely(ret)) {
|
|
pr_debug("EFAULT: aio_key\n");
|
|
goto out_put_req;
|
|
}
|
|
|
|
req->ki_user_iocb = user_iocb;
|
|
req->ki_user_data = iocb->aio_data;
|
|
|
|
ret = aio_run_iocb(&req->common, iocb->aio_lio_opcode,
|
|
(char __user *)(unsigned long)iocb->aio_buf,
|
|
iocb->aio_nbytes,
|
|
compat);
|
|
if (ret)
|
|
goto out_put_req;
|
|
|
|
return 0;
|
|
out_put_req:
|
|
put_reqs_available(ctx, 1);
|
|
percpu_ref_put(&ctx->reqs);
|
|
kiocb_free(req);
|
|
return ret;
|
|
}
|
|
|
|
long do_io_submit(aio_context_t ctx_id, long nr,
|
|
struct iocb __user *__user *iocbpp, bool compat)
|
|
{
|
|
struct kioctx *ctx;
|
|
long ret = 0;
|
|
int i = 0;
|
|
struct blk_plug plug;
|
|
|
|
if (unlikely(nr < 0))
|
|
return -EINVAL;
|
|
|
|
if (unlikely(nr > LONG_MAX/sizeof(*iocbpp)))
|
|
nr = LONG_MAX/sizeof(*iocbpp);
|
|
|
|
if (unlikely(!access_ok(VERIFY_READ, iocbpp, (nr*sizeof(*iocbpp)))))
|
|
return -EFAULT;
|
|
|
|
ctx = lookup_ioctx(ctx_id);
|
|
if (unlikely(!ctx)) {
|
|
pr_debug("EINVAL: invalid context id\n");
|
|
return -EINVAL;
|
|
}
|
|
|
|
blk_start_plug(&plug);
|
|
|
|
/*
|
|
* AKPM: should this return a partial result if some of the IOs were
|
|
* successfully submitted?
|
|
*/
|
|
for (i=0; i<nr; i++) {
|
|
struct iocb __user *user_iocb;
|
|
struct iocb tmp;
|
|
|
|
if (unlikely(__get_user(user_iocb, iocbpp + i))) {
|
|
ret = -EFAULT;
|
|
break;
|
|
}
|
|
|
|
if (unlikely(copy_from_user(&tmp, user_iocb, sizeof(tmp)))) {
|
|
ret = -EFAULT;
|
|
break;
|
|
}
|
|
|
|
ret = io_submit_one(ctx, user_iocb, &tmp, compat);
|
|
if (ret)
|
|
break;
|
|
}
|
|
blk_finish_plug(&plug);
|
|
|
|
percpu_ref_put(&ctx->users);
|
|
return i ? i : ret;
|
|
}
|
|
|
|
/* sys_io_submit:
|
|
* Queue the nr iocbs pointed to by iocbpp for processing. Returns
|
|
* the number of iocbs queued. May return -EINVAL if the aio_context
|
|
* specified by ctx_id is invalid, if nr is < 0, if the iocb at
|
|
* *iocbpp[0] is not properly initialized, if the operation specified
|
|
* is invalid for the file descriptor in the iocb. May fail with
|
|
* -EFAULT if any of the data structures point to invalid data. May
|
|
* fail with -EBADF if the file descriptor specified in the first
|
|
* iocb is invalid. May fail with -EAGAIN if insufficient resources
|
|
* are available to queue any iocbs. Will return 0 if nr is 0. Will
|
|
* fail with -ENOSYS if not implemented.
|
|
*/
|
|
SYSCALL_DEFINE3(io_submit, aio_context_t, ctx_id, long, nr,
|
|
struct iocb __user * __user *, iocbpp)
|
|
{
|
|
return do_io_submit(ctx_id, nr, iocbpp, 0);
|
|
}
|
|
|
|
/* lookup_kiocb
|
|
* Finds a given iocb for cancellation.
|
|
*/
|
|
static struct aio_kiocb *
|
|
lookup_kiocb(struct kioctx *ctx, struct iocb __user *iocb, u32 key)
|
|
{
|
|
struct aio_kiocb *kiocb;
|
|
|
|
assert_spin_locked(&ctx->ctx_lock);
|
|
|
|
if (key != KIOCB_KEY)
|
|
return NULL;
|
|
|
|
/* TODO: use a hash or array, this sucks. */
|
|
list_for_each_entry(kiocb, &ctx->active_reqs, ki_list) {
|
|
if (kiocb->ki_user_iocb == iocb)
|
|
return kiocb;
|
|
}
|
|
return NULL;
|
|
}
|
|
|
|
/* sys_io_cancel:
|
|
* Attempts to cancel an iocb previously passed to io_submit. If
|
|
* the operation is successfully cancelled, the resulting event is
|
|
* copied into the memory pointed to by result without being placed
|
|
* into the completion queue and 0 is returned. May fail with
|
|
* -EFAULT if any of the data structures pointed to are invalid.
|
|
* May fail with -EINVAL if aio_context specified by ctx_id is
|
|
* invalid. May fail with -EAGAIN if the iocb specified was not
|
|
* cancelled. Will fail with -ENOSYS if not implemented.
|
|
*/
|
|
SYSCALL_DEFINE3(io_cancel, aio_context_t, ctx_id, struct iocb __user *, iocb,
|
|
struct io_event __user *, result)
|
|
{
|
|
struct kioctx *ctx;
|
|
struct aio_kiocb *kiocb;
|
|
u32 key;
|
|
int ret;
|
|
|
|
ret = get_user(key, &iocb->aio_key);
|
|
if (unlikely(ret))
|
|
return -EFAULT;
|
|
|
|
ctx = lookup_ioctx(ctx_id);
|
|
if (unlikely(!ctx))
|
|
return -EINVAL;
|
|
|
|
spin_lock_irq(&ctx->ctx_lock);
|
|
|
|
kiocb = lookup_kiocb(ctx, iocb, key);
|
|
if (kiocb)
|
|
ret = kiocb_cancel(kiocb);
|
|
else
|
|
ret = -EINVAL;
|
|
|
|
spin_unlock_irq(&ctx->ctx_lock);
|
|
|
|
if (!ret) {
|
|
/*
|
|
* The result argument is no longer used - the io_event is
|
|
* always delivered via the ring buffer. -EINPROGRESS indicates
|
|
* cancellation is progress:
|
|
*/
|
|
ret = -EINPROGRESS;
|
|
}
|
|
|
|
percpu_ref_put(&ctx->users);
|
|
|
|
return ret;
|
|
}
|
|
|
|
/* io_getevents:
|
|
* Attempts to read at least min_nr events and up to nr events from
|
|
* the completion queue for the aio_context specified by ctx_id. If
|
|
* it succeeds, the number of read events is returned. May fail with
|
|
* -EINVAL if ctx_id is invalid, if min_nr is out of range, if nr is
|
|
* out of range, if timeout is out of range. May fail with -EFAULT
|
|
* if any of the memory specified is invalid. May return 0 or
|
|
* < min_nr if the timeout specified by timeout has elapsed
|
|
* before sufficient events are available, where timeout == NULL
|
|
* specifies an infinite timeout. Note that the timeout pointed to by
|
|
* timeout is relative. Will fail with -ENOSYS if not implemented.
|
|
*/
|
|
SYSCALL_DEFINE5(io_getevents, aio_context_t, ctx_id,
|
|
long, min_nr,
|
|
long, nr,
|
|
struct io_event __user *, events,
|
|
struct timespec __user *, timeout)
|
|
{
|
|
struct kioctx *ioctx = lookup_ioctx(ctx_id);
|
|
long ret = -EINVAL;
|
|
|
|
if (likely(ioctx)) {
|
|
if (likely(min_nr <= nr && min_nr >= 0))
|
|
ret = read_events(ioctx, min_nr, nr, events, timeout);
|
|
percpu_ref_put(&ioctx->users);
|
|
}
|
|
return ret;
|
|
}
|