)]}'
{
  "log": [
    {
      "commit": "e23e2d978bf59068a8c7faaee6117f2434a59824",
      "tree": "14576c7d7086aaaafae06fb69c9da55e5630b301",
      "parents": [
        "06374eb9366cbad6860e6d3ab97ee5090178d7d8",
        "cb121ea9e86cd51e814cb50048fd64544e672bcc"
      ],
      "author": {
        "name": "William Bellavance",
        "email": "flintman@flintmancomputers.com",
        "time": "Wed Nov 01 10:46:21 2017 -0400"
      },
      "committer": {
        "name": "William Bellavance",
        "email": "flintman@flintmancomputers.com",
        "time": "Mon Nov 06 07:19:21 2017 -0500"
      },
      "message": "Merge remote-tracking branch \u0027lineage/cm-14.1\u0027 into HEAD\n\nChange-Id: I9e8cb7935bb224132ac69dd34cd232e47972a504\n"
    },
    {
      "commit": "e358a790dc5803d49eda89164107e7f0292e4bba",
      "tree": "bf36f4bf37849a082670966b4fdc3ca70008a0a1",
      "parents": [
        "9a6d1ae5fc3990b10494e1dce83785ebcfb60df2"
      ],
      "author": {
        "name": "Hannes Frederic Sowa",
        "email": "hannes@stressinduktion.org",
        "time": "Wed Feb 03 02:11:03 2016 +0100"
      },
      "committer": {
        "name": "Ethan Chen",
        "email": "intervigil@gmail.com",
        "time": "Tue Sep 19 05:26:21 2017 +0000"
      },
      "message": "unix: correctly track in-flight fds in sending process user_struct\n\ncommit 415e3d3e90ce9e18727e8843ae343eda5a58fad6 upstream.\n\nThe commit referenced in the Fixes tag incorrectly accounted the number\nof in-flight fds over a unix domain socket to the original opener\nof the file-descriptor. This allows another process to arbitrary\ndeplete the original file-openers resource limit for the maximum of\nopen files. Instead the sending processes and its struct cred should\nbe credited.\n\nTo do so, we add a reference counted struct user_struct pointer to the\nscm_fp_list and use it to account for the number of inflight unix fds.\n\nFixes: 712f4aad406bb1 (\"unix: properly account for FDs passed over unix sockets\")\nChange-Id: I98379047cfac33de9baa6e757c91eef046d80944\nReported-by: David Herrmann \u003cdh.herrmann@gmail.com\u003e\nCc: David Herrmann \u003cdh.herrmann@gmail.com\u003e\nCc: Willy Tarreau \u003cw@1wt.eu\u003e\nCc: Linus Torvalds \u003ctorvalds@linux-foundation.org\u003e\nSuggested-by: Linus Torvalds \u003ctorvalds@linux-foundation.org\u003e\nSigned-off-by: Hannes Frederic Sowa \u003channes@stressinduktion.org\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\n[bwh: Backported to 3.2: adjust context]\nSigned-off-by: Ben Hutchings \u003cben@decadent.org.uk\u003e\n"
    },
    {
      "commit": "cc9abe6b33df87d410b104e6b9908a87ed6dcf66",
      "tree": "7c3843c61f74133e22895504465b4db518391496",
      "parents": [
        "1cbe1bf096648d59e5515108d957948e4eb81a40"
      ],
      "author": {
        "name": "David S. Miller",
        "email": "davem@davemloft.net",
        "time": "Mon Jul 02 02:21:03 2012 -0700"
      },
      "committer": {
        "name": "William Bellavance",
        "email": "flintman@flintmancomputers.com",
        "time": "Thu Sep 07 06:00:20 2017 -0400"
      },
      "message": "net: Do delayed neigh confirmation.\n\nWhen a dst_confirm() happens, mark the confirmation as pending in the\ndst.  Then on the next packet out, when we have the neigh in-hand, do\nthe update.\n\nThis removes the dependency in dst_confirm() of dst\u0027s having an\nattached neigh.\n\nWhile we\u0027re here, remove the explicit \u0027dst\u0027 NULL check, all except 2\nor 3 call sites ensure it\u0027s not NULL.  So just fix those cases up.\n\nChange-Id: I75acf86d11c9125c8ce2c2144e4a0fb717b29f03\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\n"
    },
    {
      "commit": "1cbe1bf096648d59e5515108d957948e4eb81a40",
      "tree": "b736201a530e3b13b0ddfb25ae09365549f25e15",
      "parents": [
        "783960231027b64dee2f17bb75d43d2f98df02eb"
      ],
      "author": {
        "name": "Eldad Zack",
        "email": "eldad@fogrefinery.com",
        "time": "Sat Jun 16 15:14:49 2012 +0200"
      },
      "committer": {
        "name": "William Bellavance",
        "email": "flintman@flintmancomputers.com",
        "time": "Thu Sep 07 06:00:20 2017 -0400"
      },
      "message": "include/net/dst.h: neaten asterisk placement\n\nFix code style - place the asterisk where it belongs.\n\nChange-Id: Icf8c4e16bfa4fa4a10843202e2ad842dff08f94c\nSigned-off-by: Eldad Zack \u003celdad@fogrefinery.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\n"
    },
    {
      "commit": "40016cf9ab788c0243535d1e19134bb807a73570",
      "tree": "bc80b11c134895a987bce22ef318044be188757e",
      "parents": [
        "8d53288a5fce63795cc5794e246073ff9e9cbcce"
      ],
      "author": {
        "name": "Vladimir Kondratiev",
        "email": "qca_vkondrat@qca.qualcomm.com",
        "time": "Thu Jul 05 14:25:49 2012 +0300"
      },
      "committer": {
        "name": "William Bellavance",
        "email": "flintman@flintmancomputers.com",
        "time": "Thu Sep 07 06:00:09 2017 -0400"
      },
      "message": "BACKPORT: {nl,cfg}80211: support high bitrates\n\nUntil now, a u16 value was used to represent bitrate value.\nWith VHT bitrates this becomes too small.\n\nIntroduce a new 32-bit bitrate attribute. nl80211 will report\nboth the new and the old attribute, unless the bitrate doesn\u0027t\nfit into the old u16 attribute in which case only the new one\nwill be reported.\n\nUser space tools encouraged to prefer the 32-bit attribute, if\navailable (since it won\u0027t be available on older kernels.)\n\nSigned-off-by: Vladimir Kondratiev \u003cqca_vkondrat@qca.qualcomm.com\u003e\n[reword commit message and comments a bit]\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\n\n[AdrianDC] Includes if () improvements from commit\n           \"nl80211/cfg80211: add VHT MCS support\"\n           by Johannes Berg, Fri, 9 Nov 2012\n\nChange-Id: Ib5823475ba368954e51ac4129b400a58fd74e28d\nSigned-off-by: Adrian DC \u003cradian.dc@gmail.com\u003e\n"
    },
    {
      "commit": "8d53288a5fce63795cc5794e246073ff9e9cbcce",
      "tree": "49d88b7494be9e1dba7c4e8b98bb6e81ee289f70",
      "parents": [
        "be0e44a0a909edf2d77326c41b6578cfb9ebf2e3"
      ],
      "author": {
        "name": "Lorenzo Colitti",
        "email": "lorenzo@google.com",
        "time": "Fri Nov 04 02:23:42 2016 +0900"
      },
      "committer": {
        "name": "William Bellavance",
        "email": "flintman@flintmancomputers.com",
        "time": "Thu Sep 07 06:00:08 2017 -0400"
      },
      "message": "net: core: add UID to flows, rules, and routes\n\n- Define a new FIB rule attributes, FRA_UID_RANGE, to describe a\n  range of UIDs.\n- Define a RTA_UID attribute for per-UID route lookups and dumps.\n- Support passing these attributes to and from userspace via\n  rtnetlink. The value INVALID_UID indicates no UID was\n  specified.\n- Add a UID field to the flow structures.\n\n[Backport of net-next 622ec2c9d52405973c9f1ca5116eb1c393adfc7d]\n\nBug: 16355602\nChange-Id: Iea98e6fedd0fd4435a1f4efa3deb3629505619ab\nSigned-off-by: Lorenzo Colitti \u003clorenzo@google.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\n"
    },
    {
      "commit": "be0e44a0a909edf2d77326c41b6578cfb9ebf2e3",
      "tree": "5fc6347d6af7d1142801f234393880c3128986e1",
      "parents": [
        "2513d3a74263b55c1d7ba73a55e7089ead54e47f"
      ],
      "author": {
        "name": "Eric W. Biederman",
        "email": "ebiederm@xmission.com",
        "time": "Thu Jun 14 02:31:10 2012 -0700"
      },
      "committer": {
        "name": "William Bellavance",
        "email": "flintman@flintmancomputers.com",
        "time": "Thu Sep 07 06:00:08 2017 -0400"
      },
      "message": "userns: make each net (net_ns) belong to a user_ns\n\nThe user namespace which creates a new network namespace owns that\nnamespace and all resources created in it.  This way we can target\ncapability checks for privileged operations against network resources to\nthe user_ns which created the network namespace in which the resource\nlives.  Privilege to the user namespace which owns the network\nnamespace, or any parent user namespace thereof, provides the same\nprivilege to the network resource.\n\nThis patch is reworked from a version originally by\nSerge E. Hallyn \u003cserge.hallyn@canonical.com\u003e\n\nChange-Id: Ifa426537c47cce669099cc96e80b17e1d814457b\nAcked-by: Serge Hallyn \u003cserge.hallyn@canonical.com\u003e\nSigned-off-by: Eric W. Biederman \u003cebiederm@xmission.com\u003e\n"
    },
    {
      "commit": "6b0318336d740129ee9f8c28231db6355d0fe8e6",
      "tree": "2a80d15ec5c899856068602061c5031efef72333",
      "parents": [
        "e7578f3e49db9cf655786884b6c44ee0efd4f5cf"
      ],
      "author": {
        "name": "Dan Pasanen",
        "email": "dan.pasanen@gmail.com",
        "time": "Tue Aug 29 07:34:20 2017 -0500"
      },
      "committer": {
        "name": "William Bellavance",
        "email": "flintman@flintmancomputers.com",
        "time": "Thu Sep 07 06:00:07 2017 -0400"
      },
      "message": "Revert \"net: core: Support UID-based routing.\"\n\nThis reverts commit dbadd302523011ab746840885b93e8bd0b2ff499.\n"
    },
    {
      "commit": "e7578f3e49db9cf655786884b6c44ee0efd4f5cf",
      "tree": "3b34ffae7c4da53ab5bfe558bb39f78b4d87626b",
      "parents": [
        "a57da1b31ff4d5a8a6cb6629e82308c0f3af680e"
      ],
      "author": {
        "name": "Dan Pasanen",
        "email": "dan.pasanen@gmail.com",
        "time": "Tue Aug 29 07:34:16 2017 -0500"
      },
      "committer": {
        "name": "William Bellavance",
        "email": "flintman@flintmancomputers.com",
        "time": "Thu Sep 07 06:00:06 2017 -0400"
      },
      "message": "Revert \"Handle \u0027sk\u0027 being NULL in UID-based routing.\"\n\nThis reverts commit e701d03cd5e882c213ba3dad280bb4b551ebe2cb.\n"
    },
    {
      "commit": "c8096dd48dfa9277a4a0739d6b70908893bd43fd",
      "tree": "3b749204756cb177b15f11971cf8729b4252c707",
      "parents": [
        "c7222a2b570115867d5c1c043dd0fc2bb8736575"
      ],
      "author": {
        "name": "Lorenzo Colitti",
        "email": "lorenzo@google.com",
        "time": "Wed Dec 16 12:30:05 2015 +0900"
      },
      "committer": {
        "name": "Pavel Malyutin",
        "email": "pavel.malyutin@gmail.com",
        "time": "Sun Feb 26 18:09:17 2017 +0000"
      },
      "message": "net: diag: Support destroying TCP sockets.\n\nThis implements SOCK_DESTROY for TCP sockets. It causes all\nblocking calls on the socket to fail fast with ECONNABORTED and\ncauses a protocol close of the socket. It informs the other end\nof the connection by sending a RST, i.e., initiating a TCP ABORT\nas per RFC 793. ECONNABORTED was chosen for consistency with\nFreeBSD.\n\n[Backport of net-next c1e64e298b8cad309091b95d8436a0255c84f54a]\n\nChange-Id: Ic5410d3a2f39db28a322c30f4b3b2bffd35ec2de\nSigned-off-by: Lorenzo Colitti \u003clorenzo@google.com\u003e\nAcked-by: Eric Dumazet \u003cedumazet@google.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\n"
    },
    {
      "commit": "d918c755621bf34f0df62042f425b4ca6e554674",
      "tree": "cd91dd7215c08c4cd45447a859c0b94d00dc6454",
      "parents": [
        "ebf89eed0b871b2f62ed890306a29be2cede6337"
      ],
      "author": {
        "name": "Cong Wang",
        "email": "cwang@twopensource.com",
        "time": "Tue Apr 15 16:25:34 2014 -0700"
      },
      "committer": {
        "name": "Matt Mower",
        "email": "mowerm@gmail.com",
        "time": "Tue Feb 07 05:31:10 2017 +0000"
      },
      "message": "ipv4, fib: pass LOOPBACK_IFINDEX instead of 0 to flowi4_iif\n\nAs suggested by Julian:\n\n\tSimply, flowi4_iif must not contain 0, it does not\n\tlook logical to ignore all ip rules with specified iif.\n\nbecause in fib_rule_match() we do:\n\n        if (rule-\u003eiifindex \u0026\u0026 (rule-\u003eiifindex !\u003d fl-\u003eflowi_iif))\n                goto out;\n\nflowi4_iif should be LOOPBACK_IFINDEX by default.\n\nWe need to move LOOPBACK_IFINDEX to include/net/flow.h:\n\n1) It is mostly used by flowi_iif\n\n2) Fix the following compile error if we use it in flow.h\nby the patches latter:\n\nIn file included from include/linux/netfilter.h:277:0,\n                 from include/net/netns/netfilter.h:5,\n                 from include/net/net_namespace.h:21,\n                 from include/linux/netdevice.h:43,\n                 from include/linux/icmpv6.h:12,\n                 from include/linux/ipv6.h:61,\n                 from include/net/ipv6.h:16,\n                 from include/linux/sunrpc/clnt.h:27,\n                 from include/linux/nfs_fs.h:30,\n                 from init/do_mounts.c:32:\ninclude/net/flow.h: In function ‘flowi4_init_output’:\ninclude/net/flow.h:84:32: error: ‘LOOPBACK_IFINDEX’ undeclared (first use in this function)\n\n[Backport of net-next 6a662719c9868b3d6c7d26b3a085f0cd3cc15e64]\n\nChange-Id: Ib7a0a08d78c03800488afa1b2c170cb70e34cfd9\nCc: Eric Biederman \u003cebiederm@xmission.com\u003e\nCc: Julian Anastasov \u003cja@ssi.bg\u003e\nCc: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Cong Wang \u003cxiyou.wangcong@gmail.com\u003e\nSigned-off-by: Cong Wang \u003ccwang@twopensource.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Lorenzo Colitti \u003clorenzo@google.com\u003e\n"
    },
    {
      "commit": "96eeae7f0a885658bc49f68305e80c0e35d98728",
      "tree": "f961f399f7ba294fd468e23d72404880cd05e8e2",
      "parents": [
        "d195b72d8fc3162e45ed069233df55924e8b4b3b"
      ],
      "author": {
        "name": "Pavel Emelyanov",
        "email": "xemul@parallels.com",
        "time": "Wed Aug 08 21:53:36 2012 +0000"
      },
      "committer": {
        "name": "Matt Mower",
        "email": "mowerm@gmail.com",
        "time": "Tue Feb 07 05:30:50 2017 +0000"
      },
      "message": "net: Loopback ifindex is constant now\n\nAs pointed out, there are places, that access net-\u003eloopback_dev-\u003eifindex\nand after ifindex generation is made per-net this value becomes constant\nequals 1. So go ahead and introduce the LOOPBACK_IFINDEX constant and use\nit where appropriate.\n\nChange-Id: I29fd08fa01a9522240ab654d436b02a577bb610c\nSigned-off-by: Pavel Emelyanov \u003cxemul@parallels.com\u003e\nAcked-by: Eric Dumazet \u003cedumazet@google.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\n"
    },
    {
      "commit": "16a39eddb18a2daf21142a8fd1fd0cfde76a9397",
      "tree": "5f858f20e445c8a45078ca0ec5f61c4e088e1deb",
      "parents": [
        "e39192331424b6e0695038c1dd57f43efebe9355",
        "8d1988f838a95e836342b505398d38b223181f17"
      ],
      "author": {
        "name": "David Hays",
        "email": "dhays90@gmail.com",
        "time": "Fri Dec 30 09:42:57 2016 -0600"
      },
      "committer": {
        "name": "David Hays",
        "email": "dhays90@gmail.com",
        "time": "Fri Dec 30 10:00:46 2016 -0600"
      },
      "message": "Merge tag \u0027v3.4.113\u0027 into cm-14.1\n\nChange-Id: Ifa814958fd557299a5442731fc22fcb62139898b\n"
    },
    {
      "commit": "f82f895743ccb7e186e70dc2c515f6032bf0e9eb",
      "tree": "8f942507bdf3fe72bb6b26d7c4145be4d41f4026",
      "parents": [
        "6399a30734783b79d58ac4f8e3111672733f905b"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "edumazet@google.com",
        "time": "Fri Jun 08 05:03:21 2012 +0000"
      },
      "committer": {
        "name": "Nick Reuter",
        "email": "nreuter85@gmail.com",
        "time": "Thu Dec 08 21:17:15 2016 -0600"
      },
      "message": "af_unix: speedup /proc/net/unix\n\n/proc/net/unix has quadratic behavior, and can hold unix_table_lock for\na while if high number of unix sockets are alive. (90 ms for 200k\nsockets...)\n\nWe already have a hash table, so its quite easy to use it.\n\nProblem is unbound sockets are still hashed in a single hash slot\n(unix_socket_table[UNIX_HASH_TABLE])\n\nThis patch also spreads unbound sockets to 256 hash slots, to speedup\nboth /proc/net/unix and unix_diag.\n\nTime to read /proc/net/unix with 200k unix sockets :\n(time dd if\u003d/proc/net/unix of\u003d/dev/null bs\u003d4k)\n\nbefore : 520 secs\nafter : 2 secs\n\nChange-Id: Idf8ee4b6fe9c066483f4e1376714fa2b4ff573e6\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nCc: Steven Whitehouse \u003cswhiteho@redhat.com\u003e\nCc: Pavel Emelyanov \u003cxemul@parallels.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nGit-repo: http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git\nGit-commit: 7123aaa3a1416529ce461e98108e6b343b294643\n"
    },
    {
      "commit": "1ecd872aff65c28bc3abbcf5e7ee9ce3b9fc3d35",
      "tree": "269246b8f63a97e7519b3c5db6e986c1be6a5d22",
      "parents": [
        "0d73eaaeac1ca4f6bff788574fb8b99835527ae1"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "edumazet@google.com",
        "time": "Wed Aug 17 05:56:26 2016 -0700"
      },
      "committer": {
        "name": "Nick Reuter",
        "email": "nreuter85@gmail.com",
        "time": "Thu Dec 08 21:14:13 2016 -0600"
      },
      "message": "tcp: fix use after free in tcp_xmit_retransmit_queue()\n\nWhen tcp_sendmsg() allocates a fresh and empty skb, it puts it at the\ntail of the write queue using tcp_add_write_queue_tail()\n\nThen it attempts to copy user data into this fresh skb.\n\nIf the copy fails, we undo the work and remove the fresh skb.\n\nUnfortunately, this undo lacks the change done to tp-\u003ehighest_sack and\nwe can leave a dangling pointer (to a freed skb)\n\nLater, tcp_xmit_retransmit_queue() can dereference this pointer and\naccess freed memory. For regular kernels where memory is not unmapped,\nthis might cause SACK bugs because tcp_highest_sack_seq() is buggy,\nreturning garbage instead of tp-\u003esnd_nxt, but with various debug\nfeatures like CONFIG_DEBUG_PAGEALLOC, this can crash the kernel.\n\nThis bug was found by Marco Grassi thanks to syzkaller.\n\nChange-Id: I9cbd469da12d84ff331b331d125d14f77b34e87f\nFixes: 6859d49475d4 (\"[TCP]: Abstract tp-\u003ehighest_sack accessing \u0026 point to next skb\")\nReported-by: Marco Grassi \u003cmarco.gra@gmail.com\u003e\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nCc: Ilpo Järvinen \u003cilpo.jarvinen@helsinki.fi\u003e\nCc: Yuchung Cheng \u003cycheng@google.com\u003e\nCc: Neal Cardwell \u003cncardwell@google.com\u003e\nAcked-by: Neal Cardwell \u003cncardwell@google.com\u003e\nReviewed-by: Cong Wang \u003cxiyou.wangcong@gmail.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\n"
    },
    {
      "commit": "d9fcf079fd0c4d8ff606460f568fd843c93c35ad",
      "tree": "610a96bae117da7c7584fdee1099e6cf114a4e08",
      "parents": [
        "48dbe3b85500baafaee716802f77ffeb15cd1620"
      ],
      "author": {
        "name": "lucien",
        "email": "lucien.xin@gmail.com",
        "time": "Sat Dec 05 15:35:36 2015 +0800"
      },
      "committer": {
        "name": "William Bellavance",
        "email": "flintman@flintmancomputers.com",
        "time": "Sat Dec 03 10:43:51 2016 -0500"
      },
      "message": "sctp: start t5 timer only when peer rwnd is 0 and local state is SHUTDOWN_PENDING\n\ncommit 8a0d19c5ed417c78d03f4e0fa7215e58c40896d8 upstream.\n\nwhen A sends a data to B, then A close() and enter into SHUTDOWN_PENDING\nstate, if B neither claim his rwnd is 0 nor send SACK for this data, A\nwill keep retransmitting this data until t5 timeout, Max.Retrans times\ncan\u0027t work anymore, which is bad.\n\nif B\u0027s rwnd is not 0, it should send abort after Max.Retrans times, only\nwhen B\u0027s rwnd \u003d\u003d 0 and A\u0027s retransmitting beyonds Max.Retrans times, A\nwill start t5 timer, which is also commit f8d960524328 (\"sctp: Enforce\nretransmission limit during shutdown\") means, but it lacks the condition\npeer rwnd \u003d\u003d 0.\n\nso fix it by adding a bit (zero_window_announced) in peer to record if\nthe last rwnd is 0. If it was, zero_window_announced will be set. and use\nthis bit to decide if start t5 timer when local.state is SHUTDOWN_PENDING.\n\nFixes: commit f8d960524328 (\"sctp: Enforce retransmission limit during shutdown\")\nSigned-off-by: Xin Long \u003clucien.xin@gmail.com\u003e\nSigned-off-by: Marcelo Ricardo Leitner \u003cmarcelo.leitner@gmail.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\n[bwh: Backported to 3.2: change sack_needed to bitfield as done earlier upstream]\nSigned-off-by: Ben Hutchings \u003cben@decadent.org.uk\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "662543d872d0ced6c65e0147af9e4fcf6b8b0a93",
      "tree": "e972eb267c86c7328719e6071ed51ceeb43a4d85",
      "parents": [
        "cc7899af782af18ff8b6aa7cf4d6d0cbfb59edbd"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "eric.dumazet@gmail.com",
        "time": "Wed May 01 05:24:03 2013 +0000"
      },
      "committer": {
        "name": "William Bellavance",
        "email": "flintman@flintmancomputers.com",
        "time": "Sat Dec 03 10:26:48 2016 -0500"
      },
      "message": "af_unix: fix a fatal race with bit fields\n\ncommit 60bc851ae59bfe99be6ee89d6bc50008c85ec75d upstream.\n\nUsing bit fields is dangerous on ppc64/sparc64, as the compiler [1]\nuses 64bit instructions to manipulate them.\nIf the 64bit word includes any atomic_t or spinlock_t, we can lose\ncritical concurrent changes.\n\nThis is happening in af_unix, where unix_sk(sk)-\u003egc_candidate/\ngc_maybe_cycle/lock share the same 64bit word.\n\nThis leads to fatal deadlock, as one/several cpus spin forever\non a spinlock that will never be available again.\n\nA safer way would be to use a long to store flags.\nThis way we are sure compiler/arch wont do bad things.\n\nAs we own unix_gc_lock spinlock when clearing or setting bits,\nwe can use the non atomic __set_bit()/__clear_bit().\n\nrecursion_level can share the same 64bit location with the spinlock,\nas it is set only with this spinlock held.\n\n[1] bug fixed in gcc-4.8.0 :\nhttp://gcc.gnu.org/bugzilla/show_bug.cgi?id\u003d52080\n\nReported-by: Ambrose Feinstein \u003cambrose@google.com\u003e\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nCc: Benjamin Herrenschmidt \u003cbenh@kernel.crashing.org\u003e\nCc: Paul Mackerras \u003cpaulus@samba.org\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nCc: hejianet \u003chejianet@gmail.com\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "8fa1e63794248754d3b378703a22a6fd47370a7d",
      "tree": "f8c4e8a563a96b9b5d065699d77bd53e990ed16c",
      "parents": [
        "bc5fdbe391a6e0c713c99d69003f819837460a66"
      ],
      "author": {
        "name": "Michal Kubeček",
        "email": "mkubecek@suse.cz",
        "time": "Mon Sep 09 21:45:04 2013 +0200"
      },
      "committer": {
        "name": "William Bellavance",
        "email": "flintman@flintmancomputers.com",
        "time": "Sat Dec 03 10:24:59 2016 -0500"
      },
      "message": "ipv6: don\u0027t call fib6_run_gc() until routing is ready\n\ncommit 2c861cc65ef4604011a0082e4dcdba2819aa191a upstream.\n\nWhen loading the ipv6 module, ndisc_init() is called before\nip6_route_init(). As the former registers a handler calling\nfib6_run_gc(), this opens a window to run the garbage collector\nbefore necessary data structures are initialized. If a network\ndevice is initialized in this window, adding MAC address to it\ntriggers a NETDEV_CHANGEADDR event, leading to a crash in\nfib6_clean_all().\n\nTake the event handler registration out of ndisc_init() into a\nseparate function ndisc_late_init() and move it after\nip6_route_init().\n\nSigned-off-by: Michal Kubecek \u003cmkubecek@suse.cz\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "bc5fdbe391a6e0c713c99d69003f819837460a66",
      "tree": "4bb9f6ef2e5b4b7bb96d3374d6fe42a2d20bdde6",
      "parents": [
        "4dfa237ae075cda2bfdd2509eb265a4786993cc7"
      ],
      "author": {
        "name": "Nicolas Dichtel",
        "email": "nicolas.dichtel@6wind.com",
        "time": "Wed Sep 05 02:12:42 2012 +0000"
      },
      "committer": {
        "name": "William Bellavance",
        "email": "flintman@flintmancomputers.com",
        "time": "Sat Dec 03 10:24:46 2016 -0500"
      },
      "message": "ipv6: fix handling of blackhole and prohibit routes\n\ncommit ef2c7d7b59708d54213c7556a82d14de9a7e4475 upstream.\n\nWhen adding a blackhole or a prohibit route, they were handling like classic\nroutes. Moreover, it was only possible to add this kind of routes by specifying\nan interface.\n\nBug already reported here:\n  http://bugs.debian.org/cgi-bin/bugreport.cgi?bug\u003d498498\n\nBefore the patch:\n  $ ip route add blackhole 2001::1/128\n  RTNETLINK answers: No such device\n  $ ip route add blackhole 2001::1/128 dev eth0\n  $ ip -6 route | grep 2001\n  2001::1 dev eth0  metric 1024\n\nAfter:\n  $ ip route add blackhole 2001::1/128\n  $ ip -6 route | grep 2001\n  blackhole 2001::1 dev lo  metric 1024  error -22\n\nv2: wrong patch\nv3: add a field fc_type in struct fib6_config to store RTN_* type\n\nSigned-off-by: Nicolas Dichtel \u003cnicolas.dichtel@6wind.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "885fd32ea5abab0e338f2068d09ee80f659999c4",
      "tree": "4742569da9c4afb3e8cb4f3b14942cc72420756c",
      "parents": [
        "c97fe2418e51a47b1966fbdd60beb9d84f703bc0"
      ],
      "author": {
        "name": "Lorenzo Colitti",
        "email": "lorenzo@google.com",
        "time": "Wed Dec 16 12:30:03 2015 +0900"
      },
      "committer": {
        "name": "David Hays",
        "email": "dhays90@gmail.com",
        "time": "Wed Nov 23 09:30:01 2016 -0600"
      },
      "message": "net: diag: Add the ability to destroy a socket.\n\nThis patch adds a SOCK_DESTROY operation, a destroy function\npointer to sock_diag_handler, and a diag_destroy function\npointer.  It does not include any implementation code.\n\n[Backport of net-next 64be0aed59ad519d6f2160868734f7e278290ac1]\n\nChange-Id: I1d998e1c5f836b2f5638c0f79244c372c8d2d9d9\nSigned-off-by: Lorenzo Colitti \u003clorenzo@google.com\u003e\nAcked-by: Eric Dumazet \u003cedumazet@google.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\n"
    },
    {
      "commit": "af706acbb5dbf492ad19fb448c2f05db8595f78e",
      "tree": "4bc5b6abd82e79329c1d5af431f2df5d71b8b077",
      "parents": [
        "a4ea6252cc4b05d002ea465ef17bd8dcdd83b6bf"
      ],
      "author": {
        "name": "Nicolas Dichtel",
        "email": "nicolas.dichtel@6wind.com",
        "time": "Wed Sep 05 02:12:42 2012 +0000"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Wed Oct 26 23:15:43 2016 +0800"
      },
      "message": "ipv6: fix handling of blackhole and prohibit routes\n\ncommit ef2c7d7b59708d54213c7556a82d14de9a7e4475 upstream.\n\nWhen adding a blackhole or a prohibit route, they were handling like classic\nroutes. Moreover, it was only possible to add this kind of routes by specifying\nan interface.\n\nBug already reported here:\n  http://bugs.debian.org/cgi-bin/bugreport.cgi?bug\u003d498498\n\nBefore the patch:\n  $ ip route add blackhole 2001::1/128\n  RTNETLINK answers: No such device\n  $ ip route add blackhole 2001::1/128 dev eth0\n  $ ip -6 route | grep 2001\n  2001::1 dev eth0  metric 1024\n\nAfter:\n  $ ip route add blackhole 2001::1/128\n  $ ip -6 route | grep 2001\n  blackhole 2001::1 dev lo  metric 1024  error -22\n\nv2: wrong patch\nv3: add a field fc_type in struct fib6_config to store RTN_* type\n\nSigned-off-by: Nicolas Dichtel \u003cnicolas.dichtel@6wind.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "a4ea6252cc4b05d002ea465ef17bd8dcdd83b6bf",
      "tree": "f463d59ca2a976954c304276b98cea18437af699",
      "parents": [
        "3b02ae3d45ca3b0128317f38ce5e56828c67e53b"
      ],
      "author": {
        "name": "Michal Kubeček",
        "email": "mkubecek@suse.cz",
        "time": "Mon Sep 09 21:45:04 2013 +0200"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Wed Oct 26 23:15:43 2016 +0800"
      },
      "message": "ipv6: don\u0027t call fib6_run_gc() until routing is ready\n\ncommit 2c861cc65ef4604011a0082e4dcdba2819aa191a upstream.\n\nWhen loading the ipv6 module, ndisc_init() is called before\nip6_route_init(). As the former registers a handler calling\nfib6_run_gc(), this opens a window to run the garbage collector\nbefore necessary data structures are initialized. If a network\ndevice is initialized in this window, adding MAC address to it\ntriggers a NETDEV_CHANGEADDR event, leading to a crash in\nfib6_clean_all().\n\nTake the event handler registration out of ndisc_init() into a\nseparate function ndisc_late_init() and move it after\nip6_route_init().\n\nSigned-off-by: Michal Kubecek \u003cmkubecek@suse.cz\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "5781d89c5468dd7a9a17df7995541b284599e00a",
      "tree": "139ed197f24150f383414c9bf37be1fa9cf725ce",
      "parents": [
        "edd32246ed08de91f2270e7c4b0b65bbec6aba09"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "eric.dumazet@gmail.com",
        "time": "Wed May 01 05:24:03 2013 +0000"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Wed Oct 26 23:15:42 2016 +0800"
      },
      "message": "af_unix: fix a fatal race with bit fields\n\ncommit 60bc851ae59bfe99be6ee89d6bc50008c85ec75d upstream.\n\nUsing bit fields is dangerous on ppc64/sparc64, as the compiler [1]\nuses 64bit instructions to manipulate them.\nIf the 64bit word includes any atomic_t or spinlock_t, we can lose\ncritical concurrent changes.\n\nThis is happening in af_unix, where unix_sk(sk)-\u003egc_candidate/\ngc_maybe_cycle/lock share the same 64bit word.\n\nThis leads to fatal deadlock, as one/several cpus spin forever\non a spinlock that will never be available again.\n\nA safer way would be to use a long to store flags.\nThis way we are sure compiler/arch wont do bad things.\n\nAs we own unix_gc_lock spinlock when clearing or setting bits,\nwe can use the non atomic __set_bit()/__clear_bit().\n\nrecursion_level can share the same 64bit location with the spinlock,\nas it is set only with this spinlock held.\n\n[1] bug fixed in gcc-4.8.0 :\nhttp://gcc.gnu.org/bugzilla/show_bug.cgi?id\u003d52080\n\nReported-by: Ambrose Feinstein \u003cambrose@google.com\u003e\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nCc: Benjamin Herrenschmidt \u003cbenh@kernel.crashing.org\u003e\nCc: Paul Mackerras \u003cpaulus@samba.org\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nCc: hejianet \u003chejianet@gmail.com\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "8a26248a33600fa61516fd190ec13279d1cdedf5",
      "tree": "ca3c7fa3b80a21b3a24e7464fbcfb56779ad63b4",
      "parents": [
        "5a8fea111f5199a7c1923874ff50c76ddbcfe548"
      ],
      "author": {
        "name": "lucien",
        "email": "lucien.xin@gmail.com",
        "time": "Sat Dec 05 15:35:36 2015 +0800"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Wed Oct 26 23:15:35 2016 +0800"
      },
      "message": "sctp: start t5 timer only when peer rwnd is 0 and local state is SHUTDOWN_PENDING\n\ncommit 8a0d19c5ed417c78d03f4e0fa7215e58c40896d8 upstream.\n\nwhen A sends a data to B, then A close() and enter into SHUTDOWN_PENDING\nstate, if B neither claim his rwnd is 0 nor send SACK for this data, A\nwill keep retransmitting this data until t5 timeout, Max.Retrans times\ncan\u0027t work anymore, which is bad.\n\nif B\u0027s rwnd is not 0, it should send abort after Max.Retrans times, only\nwhen B\u0027s rwnd \u003d\u003d 0 and A\u0027s retransmitting beyonds Max.Retrans times, A\nwill start t5 timer, which is also commit f8d960524328 (\"sctp: Enforce\nretransmission limit during shutdown\") means, but it lacks the condition\npeer rwnd \u003d\u003d 0.\n\nso fix it by adding a bit (zero_window_announced) in peer to record if\nthe last rwnd is 0. If it was, zero_window_announced will be set. and use\nthis bit to decide if start t5 timer when local.state is SHUTDOWN_PENDING.\n\nFixes: commit f8d960524328 (\"sctp: Enforce retransmission limit during shutdown\")\nSigned-off-by: Xin Long \u003clucien.xin@gmail.com\u003e\nSigned-off-by: Marcelo Ricardo Leitner \u003cmarcelo.leitner@gmail.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\n[bwh: Backported to 3.2: change sack_needed to bitfield as done earlier upstream]\nSigned-off-by: Ben Hutchings \u003cben@decadent.org.uk\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "4447dfca8d1f6cdafceea49b61fc4f5f8533231f",
      "tree": "845b50f3f9ae37cb6a40a9b1642fe898128b1c1b",
      "parents": [
        "4b97aa11bdea56a873def5228ea1e336f922678d"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "edumazet@google.com",
        "time": "Wed Aug 17 05:56:26 2016 -0700"
      },
      "committer": {
        "name": "Matt Mower",
        "email": "mowerm@gmail.com",
        "time": "Tue Oct 25 13:48:19 2016 -0500"
      },
      "message": "tcp: fix use after free in tcp_xmit_retransmit_queue()\n\nWhen tcp_sendmsg() allocates a fresh and empty skb, it puts it at the\ntail of the write queue using tcp_add_write_queue_tail()\n\nThen it attempts to copy user data into this fresh skb.\n\nIf the copy fails, we undo the work and remove the fresh skb.\n\nUnfortunately, this undo lacks the change done to tp-\u003ehighest_sack and\nwe can leave a dangling pointer (to a freed skb)\n\nLater, tcp_xmit_retransmit_queue() can dereference this pointer and\naccess freed memory. For regular kernels where memory is not unmapped,\nthis might cause SACK bugs because tcp_highest_sack_seq() is buggy,\nreturning garbage instead of tp-\u003esnd_nxt, but with various debug\nfeatures like CONFIG_DEBUG_PAGEALLOC, this can crash the kernel.\n\nThis bug was found by Marco Grassi thanks to syzkaller.\n\nChange-Id: I264f97d30d0a623011d9ee811c63fa0e0c2149a2\nFixes: 6859d49475d4 (\"[TCP]: Abstract tp-\u003ehighest_sack accessing \u0026 point to next skb\")\nReported-by: Marco Grassi \u003cmarco.gra@gmail.com\u003e\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nCc: Ilpo Järvinen \u003cilpo.jarvinen@helsinki.fi\u003e\nCc: Yuchung Cheng \u003cycheng@google.com\u003e\nCc: Neal Cardwell \u003cncardwell@google.com\u003e\nAcked-by: Neal Cardwell \u003cncardwell@google.com\u003e\nReviewed-by: Cong Wang \u003cxiyou.wangcong@gmail.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\n"
    },
    {
      "commit": "18e9860b522d2b45c3ff98887d99f30e70a715e6",
      "tree": "97eee1c8183d26fc02debec483119bd008e3a74a",
      "parents": [
        "963cd9ae820d4b66e2f2cd5867b933315ccb2d19"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "edumazet@google.com",
        "time": "Sun Nov 29 19:37:57 2015 -0800"
      },
      "committer": {
        "name": "Nick Reuter",
        "email": "nreuter85@gmail.com",
        "time": "Wed Aug 10 16:28:31 2016 -0500"
      },
      "message": "UPSTREAM: ipv6: add complete rcu protection around np-\u003eopt\n\n[ Upstream commit 45f6fad84cc305103b28d73482b344d7f5b76f39 ]\n\nThis patch addresses multiple problems :\n\nUDP/RAW sendmsg() need to get a stable struct ipv6_txoptions\nwhile socket is not locked : Other threads can change np-\u003eopt\nconcurrently. Dmitry posted a syzkaller\n(http://github.com/google/syzkaller) program desmonstrating\nuse-after-free.\n\nStarting with TCP/DCCP lockless listeners, tcp_v6_syn_recv_sock()\nand dccp_v6_request_recv_sock() also need to use RCU protection\nto dereference np-\u003eopt once (before calling ipv6_dup_options())\n\nThis patch adds full RCU protection to np-\u003eopt\n\nReported-by: Dmitry Vyukov \u003cdvyukov@google.com\u003e\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nAcked-by: Hannes Frederic Sowa \u003channes@stressinduktion.org\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Jiri Slaby \u003cjslaby@suse.cz\u003e\nChange-Id: I81775b2269a8263c4e4760b94b9fdd0d5916b31e\nBug: 28746669\n"
    },
    {
      "commit": "1f1f52073160a2b1856b3904df80d84dc829ecdf",
      "tree": "f6f78c669b2914d5ee325b72613c17eed16bd166",
      "parents": [
        "5cfac143dbcc96119300c5b1793f41d121eda857"
      ],
      "author": {
        "name": "Lorenzo Colitti",
        "email": "lorenzo@google.com",
        "time": "Wed Dec 16 12:30:05 2015 +0900"
      },
      "committer": {
        "name": "Nick Reuter",
        "email": "nreuter85@gmail.com",
        "time": "Wed Aug 10 16:26:33 2016 -0500"
      },
      "message": "net: diag: Support destroying TCP sockets.\n\nThis implements SOCK_DESTROY for TCP sockets. It causes all\nblocking calls on the socket to fail fast with ECONNABORTED and\ncauses a protocol close of the socket. It informs the other end\nof the connection by sending a RST, i.e., initiating a TCP ABORT\nas per RFC 793. ECONNABORTED was chosen for consistency with\nFreeBSD.\n\n[Backport of net-next c1e64e298b8cad309091b95d8436a0255c84f54a]\n\nChange-Id: Ic5410d3a2f39db28a322c30f4b3b2bffd35ec2de\nSigned-off-by: Lorenzo Colitti \u003clorenzo@google.com\u003e\nAcked-by: Eric Dumazet \u003cedumazet@google.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\n"
    },
    {
      "commit": "33a38ccbbdf78696bdcd5be644fddf0fdd5bd81d",
      "tree": "0fe522ed6c7a7776bfa69113f3d3fe28aafd4f4b",
      "parents": [
        "707ab355d2e29f90e2b2f5ec1f593127291dbee7"
      ],
      "author": {
        "name": "Lorenzo Colitti",
        "email": "lorenzo@google.com",
        "time": "Wed Dec 16 12:30:03 2015 +0900"
      },
      "committer": {
        "name": "Nick Reuter",
        "email": "nreuter85@gmail.com",
        "time": "Wed Aug 10 16:26:21 2016 -0500"
      },
      "message": "net: diag: Add the ability to destroy a socket.\n\nThis patch adds a SOCK_DESTROY operation, a destroy function\npointer to sock_diag_handler, and a diag_destroy function\npointer.  It does not include any implementation code.\n\n[Backport of net-next 64be0aed59ad519d6f2160868734f7e278290ac1]\n\nChange-Id: I1d998e1c5f836b2f5638c0f79244c372c8d2d9d9\nSigned-off-by: Lorenzo Colitti \u003clorenzo@google.com\u003e\nAcked-by: Eric Dumazet \u003cedumazet@google.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\n"
    },
    {
      "commit": "0cf007169665bc6c8eeca0e9089ef0e805c2ac42",
      "tree": "82a470f9ef259808f9d063d24c860bfab5da3809",
      "parents": [
        "25bec49c55f487637b2f9550b6e04ffb51c5863f"
      ],
      "author": {
        "name": "Ivan Grinko",
        "email": "iivanich@gmail.com",
        "time": "Thu Mar 24 09:39:37 2016 +0200"
      },
      "committer": {
        "name": "William Bellavance",
        "email": "flintman@flintmancomputers.com",
        "time": "Tue May 17 07:52:15 2016 -0400"
      },
      "message": "Linux 3.4.111\n"
    },
    {
      "commit": "abd7a6fdf5c96e661e4520ec1cf718b9378f1342",
      "tree": "196b1c60ccc0499fe92e3a531576e6c6c18198c0",
      "parents": [
        "86f24e99598f298b78759616dfa9e8fcca0d3688",
        "3389604d77540abf738b486d650c1745b2d663ca"
      ],
      "author": {
        "name": "David Hays",
        "email": "dhays90@gmail.com",
        "time": "Mon Apr 11 13:09:16 2016 -0700"
      },
      "committer": {
        "name": "Ethan Chen",
        "email": "intervigil@gmail.com",
        "time": "Mon Apr 11 13:39:17 2016 -0700"
      },
      "message": "Merge tag \u0027v3.4.111\u0027 into cm-13.0\n\nThis is the 3.4.111 stable release\n\nConflicts:\n    fs/file_table.c\n    include/net/sock.h\n\nChange-Id: Ic65a8a4450b508018d5c092b420ebb23df0daef6\n"
    },
    {
      "commit": "ca7d623e1e0a028bd7931d153c15c99d11a12211",
      "tree": "4b33f480871a6a6e16586b82827b209be198b048",
      "parents": [
        "40570888be8087838c543f165e0d309b9869f526"
      ],
      "author": {
        "name": "Hannes Frederic Sowa",
        "email": "hannes@stressinduktion.org",
        "time": "Mon Dec 14 23:30:43 2015 +0100"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Mon Mar 21 09:17:57 2016 +0800"
      },
      "message": "net: fix warnings in \u0027make htmldocs\u0027 by moving macro definition out of field declaration\n\ncommit 7bbadd2d1009575dad675afc16650ebb5aa10612 upstream.\n\nDocbook does not like the definition of macros inside a field declaration\nand adds a warning. Move the definition out.\n\nFixes: 79462ad02e86180 (\"net: add validation for the socket syscall protocol argument\")\nReported-by: kbuild test robot \u003clkp@intel.com\u003e\nSigned-off-by: Hannes Frederic Sowa \u003channes@stressinduktion.org\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\n[lizf: Backported to 3.4: adjust context]\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "5317d9af12a59e83a6f173eac3808cc21f6e9d2b",
      "tree": "381f3d110c4dbc457a07ca99252496b5600f673f",
      "parents": [
        "31469735a1e6618754230266fb842c3f7510cd28"
      ],
      "author": {
        "name": "Michal Kubeček",
        "email": "mkubecek@suse.cz",
        "time": "Thu Aug 01 10:04:14 2013 +0200"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Mon Mar 21 09:17:57 2016 +0800"
      },
      "message": "ipv6: prevent fib6_run_gc() contention\n\ncommit 2ac3ac8f86f2fe065d746d9a9abaca867adec577 upstream.\n\nOn a high-traffic router with many processors and many IPv6 dst\nentries, soft lockup in fib6_run_gc() can occur when number of\nentries reaches gc_thresh.\n\nThis happens because fib6_run_gc() uses fib6_gc_lock to allow\nonly one thread to run the garbage collector but ip6_dst_gc()\ndoesn\u0027t update net-\u003eipv6.ip6_rt_last_gc until fib6_run_gc()\nreturns. On a system with many entries, this can take some time\nso that in the meantime, other threads pass the tests in\nip6_dst_gc() (ip6_rt_last_gc is still not updated) and wait for\nthe lock. They then have to run the garbage collector one after\nanother which blocks them for quite long.\n\nResolve this by replacing special value ~0UL of expire parameter\nto fib6_run_gc() by explicit \"force\" parameter to choose between\nspin_lock_bh() and spin_trylock_bh() and call fib6_run_gc() with\nforce\u003dfalse if gc_thresh is reached but not max_size.\n\nSigned-off-by: Michal Kubecek \u003cmkubecek@suse.cz\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\n[lizf: Backported to 3.4: adjust context]\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "39f79797d2c47256f1cac458766748af3d968c60",
      "tree": "b42cc0cdfcb7489a66e1a47903d23dd21110db66",
      "parents": [
        "0cf0ae366ff94870075cbe0a8f3a16a2107ae853"
      ],
      "author": {
        "name": "Hannes Frederic Sowa",
        "email": "hannes@stressinduktion.org",
        "time": "Mon Dec 14 22:03:39 2015 +0100"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Mon Mar 21 09:17:53 2016 +0800"
      },
      "message": "net: add validation for the socket syscall protocol argument\n\ncommit 79462ad02e861803b3840cc782248c7359451cd9 upstream.\n\n郭永刚 reported that one could simply crash the kernel as root by\nusing a simple program:\n\n\tint socket_fd;\n\tstruct sockaddr_in addr;\n\taddr.sin_port \u003d 0;\n\taddr.sin_addr.s_addr \u003d INADDR_ANY;\n\taddr.sin_family \u003d 10;\n\n\tsocket_fd \u003d socket(10,3,0x40000000);\n\tconnect(socket_fd , \u0026addr,16);\n\nAF_INET, AF_INET6 sockets actually only support 8-bit protocol\nidentifiers. inet_sock\u0027s skc_protocol field thus is sized accordingly,\nthus larger protocol identifiers simply cut off the higher bits and\nstore a zero in the protocol fields.\n\nThis could lead to e.g. NULL function pointer because as a result of\nthe cut off inet_num is zero and we call down to inet_autobind, which\nis NULL for raw sockets.\n\nkernel: Call Trace:\nkernel:  [\u003cffffffff816db90e\u003e] ? inet_autobind+0x2e/0x70\nkernel:  [\u003cffffffff816db9a4\u003e] inet_dgram_connect+0x54/0x80\nkernel:  [\u003cffffffff81645069\u003e] SYSC_connect+0xd9/0x110\nkernel:  [\u003cffffffff810ac51b\u003e] ? ptrace_notify+0x5b/0x80\nkernel:  [\u003cffffffff810236d8\u003e] ? syscall_trace_enter_phase2+0x108/0x200\nkernel:  [\u003cffffffff81645e0e\u003e] SyS_connect+0xe/0x10\nkernel:  [\u003cffffffff81779515\u003e] tracesys_phase2+0x84/0x89\n\nI found no particular commit which introduced this problem.\n\nCVE: CVE-2015-8543\nCc: Cong Wang \u003ccwang@twopensource.com\u003e\nReported-by: 郭永刚 \u003cguoyonggang@360.cn\u003e\nSigned-off-by: Hannes Frederic Sowa \u003channes@stressinduktion.org\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\n[lizf: Backported to 3.4: open-code U8_MAX]\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "ec54d5ae9d298abf01c273233de9f2bc25d80475",
      "tree": "4293b9f7b2a8ab47f1fc7c667e84e2544a3c8969",
      "parents": [
        "44b2ffc5ed1e7c6b96f103bdbbfda23fed07b18d"
      ],
      "author": {
        "name": "Rainer Weikusat",
        "email": "rweikusat@mobileactivedefense.com",
        "time": "Fri Nov 20 22:07:23 2015 +0000"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Mon Mar 21 09:17:53 2016 +0800"
      },
      "message": "unix: avoid use-after-free in ep_remove_wait_queue\n\ncommit 7d267278a9ece963d77eefec61630223fce08c6c upstream.\n\nRainer Weikusat \u003crweikusat@mobileactivedefense.com\u003e writes:\nAn AF_UNIX datagram socket being the client in an n:1 association with\nsome server socket is only allowed to send messages to the server if the\nreceive queue of this socket contains at most sk_max_ack_backlog\ndatagrams. This implies that prospective writers might be forced to go\nto sleep despite none of the message presently enqueued on the server\nreceive queue were sent by them. In order to ensure that these will be\nwoken up once space becomes again available, the present unix_dgram_poll\nroutine does a second sock_poll_wait call with the peer_wait wait queue\nof the server socket as queue argument (unix_dgram_recvmsg does a wake\nup on this queue after a datagram was received). This is inherently\nproblematic because the server socket is only guaranteed to remain alive\nfor as long as the client still holds a reference to it. In case the\nconnection is dissolved via connect or by the dead peer detection logic\nin unix_dgram_sendmsg, the server socket may be freed despite \"the\npolling mechanism\" (in particular, epoll) still has a pointer to the\ncorresponding peer_wait queue. There\u0027s no way to forcibly deregister a\nwait queue with epoll.\n\nBased on an idea by Jason Baron, the patch below changes the code such\nthat a wait_queue_t belonging to the client socket is enqueued on the\npeer_wait queue of the server whenever the peer receive queue full\ncondition is detected by either a sendmsg or a poll. A wake up on the\npeer queue is then relayed to the ordinary wait queue of the client\nsocket via wake function. The connection to the peer wait queue is again\ndissolved if either a wake up is about to be relayed or the client\nsocket reconnects or a dead peer is detected or the client socket is\nitself closed. This enables removing the second sock_poll_wait from\nunix_dgram_poll, thus avoiding the use-after-free, while still ensuring\nthat no blocked writer sleeps forever.\n\nSigned-off-by: Rainer Weikusat \u003crweikusat@mobileactivedefense.com\u003e\nFixes: ec0d215f9420 (\"af_unix: fix \u0027poll for write\u0027/connected DGRAM sockets\")\nReviewed-by: Jason Baron \u003cjbaron@akamai.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "ad31516703a7c1210078f690ea94a8efe4d01e91",
      "tree": "ab4494f3a60980909ac339ea58ec920c363dbf18",
      "parents": [
        "e8a835b9a482c3ab97c08847361900f7ed8ab1a6",
        "3edd6224c2a677bb59efe0b083a51fc2b3b5c64d"
      ],
      "author": {
        "name": "David Hays",
        "email": "dhays90@gmail.com",
        "time": "Mon Feb 22 00:00:29 2016 -0500"
      },
      "committer": {
        "name": "David Hays",
        "email": "dhays90@gmail.com",
        "time": "Mon Feb 22 17:33:37 2016 -0500"
      },
      "message": "Merge tag v3.4.110 into cm-13.0\n\nConflicts:\n\tdrivers/bluetooth/btusb.c\n\tdrivers/cpufreq/cpufreq.c\n\tdrivers/md/dm-crypt.c\n\tdrivers/mmc/core/core.c\n\tfs/namespace.c\n\tinclude/linux/usb/quirks.h\n\tnet/bluetooth/l2cap_core.c\n\tnet/bluetooth/smp.c\n\tnet/netfilter/xt_socket.c\n\tsecurity/keys/gc.c\n\tsecurity/selinux/nlmsgtab.c\n\nChange-Id: I336fc28268bf70846a49e8f1db4899a10a4e5edb\n"
    },
    {
      "commit": "9cc712efc708bf2d25b6a6c013c66c42f2cfccd0",
      "tree": "f4b7b9d2354b77f6a63eacded1c5b32282c18abc",
      "parents": [
        "64c363146fe8b4b26285d36fad0fc01b9c8c1285"
      ],
      "author": {
        "name": "José Adolfo Galdámez",
        "email": "josegalre@pac-rom.com",
        "time": "Wed Oct 21 21:52:13 2015 -0600"
      },
      "committer": {
        "name": "William Bellavance",
        "email": "flintman@flintmancomputers.com",
        "time": "Wed Feb 10 20:04:59 2016 -0500"
      },
      "message": "Merge tag \u0027v3.4.110\u0027 into mm-6.0\n\nChange-Id: I0afc69bce474139d1b70e062d72c0b8054529833\nSigned-off-by: José Adolfo Galdámez \u003cjosegalre@pac-rom.com\u003e\n"
    },
    {
      "commit": "7a1d4bacdd49739a31d87410e21a712bf70b5e3e",
      "tree": "6c386dcd4dcdb53ccb4e1119a73ac468f60809ce",
      "parents": [
        "594c5e6bd48af952f339a8e10873a1079074c4d3"
      ],
      "author": {
        "name": "Daniel Borkmann",
        "email": "dborkman@redhat.com",
        "time": "Thu Oct 09 22:55:31 2014 +0200"
      },
      "committer": {
        "name": "William Bellavance",
        "email": "flintman@flintmancomputers.com",
        "time": "Wed Feb 10 20:01:42 2016 -0500"
      },
      "message": "net: sctp: fix skb_over_panic when receiving malformed ASCONF chunks\n\ncommit 9de7922bc709eee2f609cd01d98aaedc4cf5ea74 upstream.\n\nCommit 6f4c618ddb0 (\"SCTP : Add paramters validity check for\nASCONF chunk\") added basic verification of ASCONF chunks, however,\nit is still possible to remotely crash a server by sending a\nspecial crafted ASCONF chunk, even up to pre 2.6.12 kernels:\n\nskb_over_panic: text:ffffffffa01ea1c3 len:31056 put:30768\n head:ffff88011bd81800 data:ffff88011bd81800 tail:0x7950\n end:0x440 dev:\u003cNULL\u003e\n ------------[ cut here ]------------\nkernel BUG at net/core/skbuff.c:129!\n[...]\nCall Trace:\n \u003cIRQ\u003e\n [\u003cffffffff8144fb1c\u003e] skb_put+0x5c/0x70\n [\u003cffffffffa01ea1c3\u003e] sctp_addto_chunk+0x63/0xd0 [sctp]\n [\u003cffffffffa01eadaf\u003e] sctp_process_asconf+0x1af/0x540 [sctp]\n [\u003cffffffff8152d025\u003e] ? _read_unlock_bh+0x15/0x20\n [\u003cffffffffa01e0038\u003e] sctp_sf_do_asconf+0x168/0x240 [sctp]\n [\u003cffffffffa01e3751\u003e] sctp_do_sm+0x71/0x1210 [sctp]\n [\u003cffffffff8147645d\u003e] ? fib_rules_lookup+0xad/0xf0\n [\u003cffffffffa01e6b22\u003e] ? sctp_cmp_addr_exact+0x32/0x40 [sctp]\n [\u003cffffffffa01e8393\u003e] sctp_assoc_bh_rcv+0xd3/0x180 [sctp]\n [\u003cffffffffa01ee986\u003e] sctp_inq_push+0x56/0x80 [sctp]\n [\u003cffffffffa01fcc42\u003e] sctp_rcv+0x982/0xa10 [sctp]\n [\u003cffffffffa01d5123\u003e] ? ipt_local_in_hook+0x23/0x28 [iptable_filter]\n [\u003cffffffff8148bdc9\u003e] ? nf_iterate+0x69/0xb0\n [\u003cffffffff81496d10\u003e] ? ip_local_deliver_finish+0x0/0x2d0\n [\u003cffffffff8148bf86\u003e] ? nf_hook_slow+0x76/0x120\n [\u003cffffffff81496d10\u003e] ? ip_local_deliver_finish+0x0/0x2d0\n [\u003cffffffff81496ded\u003e] ip_local_deliver_finish+0xdd/0x2d0\n [\u003cffffffff81497078\u003e] ip_local_deliver+0x98/0xa0\n [\u003cffffffff8149653d\u003e] ip_rcv_finish+0x12d/0x440\n [\u003cffffffff81496ac5\u003e] ip_rcv+0x275/0x350\n [\u003cffffffff8145c88b\u003e] __netif_receive_skb+0x4ab/0x750\n [\u003cffffffff81460588\u003e] netif_receive_skb+0x58/0x60\n\nThis can be triggered e.g., through a simple scripted nmap\nconnection scan injecting the chunk after the handshake, for\nexample, ...\n\n  -------------- INIT[ASCONF; ASCONF_ACK] -------------\u003e\n  \u003c----------- INIT-ACK[ASCONF; ASCONF_ACK] ------------\n  -------------------- COOKIE-ECHO --------------------\u003e\n  \u003c-------------------- COOKIE-ACK ---------------------\n  ------------------ ASCONF; UNKNOWN ------------------\u003e\n\n... where ASCONF chunk of length 280 contains 2 parameters ...\n\n  1) Add IP address parameter (param length: 16)\n  2) Add/del IP address parameter (param length: 255)\n\n... followed by an UNKNOWN chunk of e.g. 4 bytes. Here, the\nAddress Parameter in the ASCONF chunk is even missing, too.\nThis is just an example and similarly-crafted ASCONF chunks\ncould be used just as well.\n\nThe ASCONF chunk passes through sctp_verify_asconf() as all\nparameters passed sanity checks, and after walking, we ended\nup successfully at the chunk end boundary, and thus may invoke\nsctp_process_asconf(). Parameter walking is done with\nWORD_ROUND() to take padding into account.\n\nIn sctp_process_asconf()\u0027s TLV processing, we may fail in\nsctp_process_asconf_param() e.g., due to removal of the IP\naddress that is also the source address of the packet containing\nthe ASCONF chunk, and thus we need to add all TLVs after the\nfailure to our ASCONF response to remote via helper function\nsctp_add_asconf_response(), which basically invokes a\nsctp_addto_chunk() adding the error parameters to the given\nskb.\n\nWhen walking to the next parameter this time, we proceed\nwith ...\n\n  length \u003d ntohs(asconf_param-\u003eparam_hdr.length);\n  asconf_param \u003d (void *)asconf_param + length;\n\n... instead of the WORD_ROUND()\u0027ed length, thus resulting here\nin an off-by-one that leads to reading the follow-up garbage\nparameter length of 12336, and thus throwing an skb_over_panic\nfor the reply when trying to sctp_addto_chunk() next time,\nwhich implicitly calls the skb_put() with that length.\n\nFix it by using sctp_walk_params() [ which is also used in\nINIT parameter processing ] macro in the verification *and*\nin ASCONF processing: it will make sure we don\u0027t spill over,\nthat we walk parameters WORD_ROUND()\u0027ed. Moreover, we\u0027re being\nmore defensive and guard against unknown parameter types and\nmissized addresses.\n\nJoint work with Vlad Yasevich.\n\nFixes: b896b82be4ae (\"[SCTP] ADDIP: Support for processing incoming ASCONF_ACK chunks.\")\nSigned-off-by: Daniel Borkmann \u003cdborkman@redhat.com\u003e\nSigned-off-by: Vlad Yasevich \u003cvyasevich@gmail.com\u003e\nAcked-by: Neil Horman \u003cnhorman@tuxdriver.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\n[lizf: Backported to 3.4: adjust context]\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "594c5e6bd48af952f339a8e10873a1079074c4d3",
      "tree": "64323d1948f7cf93b0c301375043a4c1b8b11260",
      "parents": [
        "618280557800ea300c61e7b705f182aef3323352"
      ],
      "author": {
        "name": "Daniel Borkmann",
        "email": "dborkman@redhat.com",
        "time": "Thu Oct 09 22:55:32 2014 +0200"
      },
      "committer": {
        "name": "William Bellavance",
        "email": "flintman@flintmancomputers.com",
        "time": "Wed Feb 10 20:01:41 2016 -0500"
      },
      "message": "net: sctp: fix panic on duplicate ASCONF chunks\n\ncommit b69040d8e39f20d5215a03502a8e8b4c6ab78395 upstream.\n\nWhen receiving a e.g. semi-good formed connection scan in the\nform of ...\n\n  -------------- INIT[ASCONF; ASCONF_ACK] -------------\u003e\n  \u003c----------- INIT-ACK[ASCONF; ASCONF_ACK] ------------\n  -------------------- COOKIE-ECHO --------------------\u003e\n  \u003c-------------------- COOKIE-ACK ---------------------\n  ---------------- ASCONF_a; ASCONF_b -----------------\u003e\n\n... where ASCONF_a equals ASCONF_b chunk (at least both serials\nneed to be equal), we panic an SCTP server!\n\nThe problem is that good-formed ASCONF chunks that we reply with\nASCONF_ACK chunks are cached per serial. Thus, when we receive a\nsame ASCONF chunk twice (e.g. through a lost ASCONF_ACK), we do\nnot need to process them again on the server side (that was the\nidea, also proposed in the RFC). Instead, we know it was cached\nand we just resend the cached chunk instead. So far, so good.\n\nWhere things get nasty is in SCTP\u0027s side effect interpreter, that\nis, sctp_cmd_interpreter():\n\nWhile incoming ASCONF_a (chunk \u003d event_arg) is being marked\n!end_of_packet and !singleton, and we have an association context,\nwe do not flush the outqueue the first time after processing the\nASCONF_ACK singleton chunk via SCTP_CMD_REPLY. Instead, we keep it\nqueued up, although we set local_cork to 1. Commit 2e3216cd54b1\nchanged the precedence, so that as long as we get bundled, incoming\nchunks we try possible bundling on outgoing queue as well. Before\nthis commit, we would just flush the output queue.\n\nNow, while ASCONF_a\u0027s ASCONF_ACK sits in the corked outq, we\ncontinue to process the same ASCONF_b chunk from the packet. As\nwe have cached the previous ASCONF_ACK, we find it, grab it and\ndo another SCTP_CMD_REPLY command on it. So, effectively, we rip\nthe chunk-\u003elist pointers and requeue the same ASCONF_ACK chunk\nanother time. Since we process ASCONF_b, it\u0027s correctly marked\nwith end_of_packet and we enforce an uncork, and thus flush, thus\ncrashing the kernel.\n\nFix it by testing if the ASCONF_ACK is currently pending and if\nthat is the case, do not requeue it. When flushing the output\nqueue we may relink the chunk for preparing an outgoing packet,\nbut eventually unlink it when it\u0027s copied into the skb right\nbefore transmission.\n\nJoint work with Vlad Yasevich.\n\nFixes: 2e3216cd54b1 (\"sctp: Follow security requirement of responding with 1 packet\")\nSigned-off-by: Daniel Borkmann \u003cdborkman@redhat.com\u003e\nSigned-off-by: Vlad Yasevich \u003cvyasevich@gmail.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "551e1913a7e32d24639bd3457cac6b61aec9761a",
      "tree": "8eeb8f4bcf5ee97b6365ec89c812fa330b3eedd5",
      "parents": [
        "1e3d5cf82112a0a78820b603c6a86a38c5ac300f"
      ],
      "author": {
        "name": "Hannes Frederic Sowa",
        "email": "hannes@stressinduktion.org",
        "time": "Mon Dec 14 21:03:39 2015 +0000"
      },
      "committer": {
        "name": "William Bellavance",
        "email": "flintman@flintmancomputers.com",
        "time": "Sat Dec 19 08:41:03 2015 -0500"
      },
      "message": "net: add validation for the socket syscall protocol argument\n\n郭永刚 reported that one could simply crash the kernel as root by\nusing a simple program:\n\n\tint socket_fd;\n\tstruct sockaddr_in addr;\n\taddr.sin_port \u003d 0;\n\taddr.sin_addr.s_addr \u003d INADDR_ANY;\n\taddr.sin_family \u003d 10;\n\n\tsocket_fd \u003d socket(10,3,0x40000000);\n\tconnect(socket_fd , \u0026addr,16);\n\nAF_INET, AF_INET6 sockets actually only support 8-bit protocol\nidentifiers. inet_sock\u0027s skc_protocol field thus is sized accordingly,\nthus larger protocol identifiers simply cut off the higher bits and\nstore a zero in the protocol fields.\n\nThis could lead to e.g. NULL function pointer because as a result of\nthe cut off inet_num is zero and we call down to inet_autobind, which\nis NULL for raw sockets.\n\nkernel: Call Trace:\nkernel:  [\u003cffffffff816db90e\u003e] ? inet_autobind+0x2e/0x70\nkernel:  [\u003cffffffff816db9a4\u003e] inet_dgram_connect+0x54/0x80\nkernel:  [\u003cffffffff81645069\u003e] SYSC_connect+0xd9/0x110\nkernel:  [\u003cffffffff810ac51b\u003e] ? ptrace_notify+0x5b/0x80\nkernel:  [\u003cffffffff810236d8\u003e] ? syscall_trace_enter_phase2+0x108/0x200\nkernel:  [\u003cffffffff81645e0e\u003e] SyS_connect+0xe/0x10\nkernel:  [\u003cffffffff81779515\u003e] tracesys_phase2+0x84/0x89\n\nI found no particular commit which introduced this problem.\n\nChange-Id: I653fad90da54908144cc8916c2dccb1fa6f14eed\nCVE: CVE-2015-8543\nCc: Cong Wang \u003ccwang@twopensource.com\u003e\nReported-by: 郭永刚 \u003cguoyonggang@360.cn\u003e\nSigned-off-by: Hannes Frederic Sowa \u003channes@stressinduktion.org\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\n"
    },
    {
      "commit": "e72ace45e4a755b8b05fa714f7bea1ed4b79a9a8",
      "tree": "9b49ac46e092ee3a9c5061d0d9c78a9326dde402",
      "parents": [
        "c742cd3a567c2d713b48f4cfed1b519dde1f321a"
      ],
      "author": {
        "name": "Hannes Frederic Sowa",
        "email": "hannes@stressinduktion.org",
        "time": "Mon Dec 14 21:03:39 2015 +0000"
      },
      "committer": {
        "name": "David Hays",
        "email": "dhays90@gmail.com",
        "time": "Wed Dec 16 09:29:49 2015 -0800"
      },
      "message": "net: add validation for the socket syscall protocol argument\n\n郭永刚 reported that one could simply crash the kernel as root by\nusing a simple program:\n\n\tint socket_fd;\n\tstruct sockaddr_in addr;\n\taddr.sin_port \u003d 0;\n\taddr.sin_addr.s_addr \u003d INADDR_ANY;\n\taddr.sin_family \u003d 10;\n\n\tsocket_fd \u003d socket(10,3,0x40000000);\n\tconnect(socket_fd , \u0026addr,16);\n\nAF_INET, AF_INET6 sockets actually only support 8-bit protocol\nidentifiers. inet_sock\u0027s skc_protocol field thus is sized accordingly,\nthus larger protocol identifiers simply cut off the higher bits and\nstore a zero in the protocol fields.\n\nThis could lead to e.g. NULL function pointer because as a result of\nthe cut off inet_num is zero and we call down to inet_autobind, which\nis NULL for raw sockets.\n\nkernel: Call Trace:\nkernel:  [\u003cffffffff816db90e\u003e] ? inet_autobind+0x2e/0x70\nkernel:  [\u003cffffffff816db9a4\u003e] inet_dgram_connect+0x54/0x80\nkernel:  [\u003cffffffff81645069\u003e] SYSC_connect+0xd9/0x110\nkernel:  [\u003cffffffff810ac51b\u003e] ? ptrace_notify+0x5b/0x80\nkernel:  [\u003cffffffff810236d8\u003e] ? syscall_trace_enter_phase2+0x108/0x200\nkernel:  [\u003cffffffff81645e0e\u003e] SyS_connect+0xe/0x10\nkernel:  [\u003cffffffff81779515\u003e] tracesys_phase2+0x84/0x89\n\nI found no particular commit which introduced this problem.\n\nChange-Id: I653fad90da54908144cc8916c2dccb1fa6f14eed\nCVE: CVE-2015-8543\nCc: Cong Wang \u003ccwang@twopensource.com\u003e\nReported-by: 郭永刚 \u003cguoyonggang@360.cn\u003e\nSigned-off-by: Hannes Frederic Sowa \u003channes@stressinduktion.org\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\n(cherry picked from commit c56b239c819bc0476b0a0059d7a92a9dd12915e3)\n"
    },
    {
      "commit": "493d6a2da3b5206d5da2f458a5d896a6ee7ad2c5",
      "tree": "753621083e3dd8cc7f9e643fadf1e4b3a8735de9",
      "parents": [
        "c33fd0601490793b937dd27209d0ec37150e1c79"
      ],
      "author": {
        "name": "Marcelo Ricardo Leitner",
        "email": "marcelo.leitner@gmail.com",
        "time": "Fri Jun 12 10:16:41 2015 -0300"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Oct 22 09:20:04 2015 +0800"
      },
      "message": "sctp: fix ASCONF list handling\n\ncommit 2d45a02d0166caf2627fe91897c6ffc3b19514c4 upstream.\n\n-\u003eauto_asconf_splist is per namespace and mangled by functions like\nsctp_setsockopt_auto_asconf() which doesn\u0027t guarantee any serialization.\n\nAlso, the call to inet_sk_copy_descendant() was backuping\n-\u003eauto_asconf_list through the copy but was not honoring\n-\u003edo_auto_asconf, which could lead to list corruption if it was\ndifferent between both sockets.\n\nThis commit thus fixes the list handling by using -\u003eaddr_wq_lock\nspinlock to protect the list. A special handling is done upon socket\ncreation and destruction for that. Error handlig on sctp_init_sock()\nwill never return an error after having initialized asconf, so\nsctp_destroy_sock() can be called without addrq_wq_lock. The lock now\nwill be take on sctp_close_sock(), before locking the socket, so we\ndon\u0027t do it in inverse order compared to sctp_addr_wq_timeout_handler().\n\nInstead of taking the lock on sctp_sock_migrate() for copying and\nrestoring the list values, it\u0027s preferred to avoid rewritting it by\nimplementing sctp_copy_descendant().\n\nIssue was found with a test application that kept flipping sysctl\ndefault_auto_asconf on and off, but one could trigger it by issuing\nsimultaneous setsockopt() calls on multiple sockets or by\ncreating/destroying sockets fast enough. This is only triggerable\nlocally.\n\nFixes: 9f7d653b67ae (\"sctp: Add Auto-ASCONF support (core).\")\nReported-by: Ji Jianwen \u003cjiji@redhat.com\u003e\nSuggested-by: Neil Horman \u003cnhorman@tuxdriver.com\u003e\nSuggested-by: Hannes Frederic Sowa \u003channes@stressinduktion.org\u003e\nAcked-by: Hannes Frederic Sowa \u003channes@stressinduktion.org\u003e\nSigned-off-by: Marcelo Ricardo Leitner \u003cmarcelo.leitner@gmail.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\n[lizf: Backported to 3.4:\n - use global spinlock instead of per-namespace lock]\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "aa18f6fcc491d131e2b67135622e3c089bd5d0b4",
      "tree": "40086c66ca378f8d1334fa8f2ad84243eafedc31",
      "parents": [
        "6ff9603dec2399dbe2fe9e5fe87c11fda054c668"
      ],
      "author": {
        "name": "Eric W. Biederman",
        "email": "ebiederm@xmission.com",
        "time": "Wed Jun 15 10:21:48 2011 -0700"
      },
      "committer": {
        "name": "Ethan Chen",
        "email": "intervigil@gmail.com",
        "time": "Sat Oct 17 16:13:18 2015 -0700"
      },
      "message": "proc: Usable inode numbers for the namespace file descriptors.\n\nAssign a unique proc inode to each namespace, and use that\ninode number to ensure we only allocate at most one proc\ninode for every namespace in proc.\n\nA single proc inode per namespace allows userspace to test\nto see if two processes are in the same namespace.\n\nThis has been a long requested feature and only blocked because\na naive implementation would put the id in a global space and\nwould ultimately require having a namespace for the names of\nnamespaces, making migration and certain virtualization tricks\nimpossible.\n\nWe still don\u0027t have per superblock inode numbers for proc, which\nappears necessary for application unaware checkpoint/restart and\nmigrations (if the application is using namespace file descriptors)\nbut that is now allowd by the design if it becomes important.\n\nI have preallocated the ipc and uts initial proc inode numbers so\ntheir structures can be statically initialized.\n\nSigned-off-by: Eric W. Biederman \u003cebiederm@xmission.com\u003e\n(cherry picked from commit 98f842e675f96ffac96e6c50315790912b2812be)\n"
    },
    {
      "commit": "75d9a22306c18844879cddcbf940e22a03918561",
      "tree": "f1cb1be07f5deee75c1f515b60caac68080b1b68",
      "parents": [
        "ba12817ba1b77ce1d8141b7f0f68419aa1ac42eb"
      ],
      "author": {
        "name": "Eric W. Biederman",
        "email": "ebiederm@xmission.com",
        "time": "Wed Jun 15 10:21:48 2011 -0700"
      },
      "committer": {
        "name": "flintman",
        "email": "flintman@flintmancomputers.com",
        "time": "Wed Oct 14 06:40:30 2015 -0400"
      },
      "message": "proc: Usable inode numbers for the namespace file descriptors.\n\nAssign a unique proc inode to each namespace, and use that\ninode number to ensure we only allocate at most one proc\ninode for every namespace in proc.\n\nA single proc inode per namespace allows userspace to test\nto see if two processes are in the same namespace.\n\nThis has been a long requested feature and only blocked because\na naive implementation would put the id in a global space and\nwould ultimately require having a namespace for the names of\nnamespaces, making migration and certain virtualization tricks\nimpossible.\n\nWe still don\u0027t have per superblock inode numbers for proc, which\nappears necessary for application unaware checkpoint/restart and\nmigrations (if the application is using namespace file descriptors)\nbut that is now allowd by the design if it becomes important.\n\nI have preallocated the ipc and uts initial proc inode numbers so\ntheir structures can be statically initialized.\n\nSigned-off-by: Eric W. Biederman \u003cebiederm@xmission.com\u003e\n(cherry picked from commit 98f842e675f96ffac96e6c50315790912b2812be)\n"
    },
    {
      "commit": "9892c405641b5e2be1054f4964dc31a56678a038",
      "tree": "a639fa6939753e6afd04d3b4eb7231efa885245b",
      "parents": [
        "e0c1cadbab0d0dbfcb776453abdbbb9d9c072548"
      ],
      "author": {
        "name": "flintman",
        "email": "flintman@flintmancomputers.com",
        "time": "Wed Sep 23 06:14:10 2015 -0400"
      },
      "committer": {
        "name": "flintman",
        "email": "flintman@flintmancomputers.com",
        "time": "Fri Oct 02 19:50:07 2015 -0400"
      },
      "message": "Bluetooth:   Backport BT manager 1.3\n\nBackported from msm 3.10 kernel\n\nChange-Id: I0c4ba93e9d590388efd562c3dbb3a2d1ac5f3c6a\n"
    },
    {
      "commit": "57f91e3057ee92e0bc207725fed0f919d522c9a1",
      "tree": "9df4ea864f270cf4215ade2cd4d4f665cb8f063d",
      "parents": [
        "3987222cedbd86ff1b3e4bb8e5ee171a7b560028"
      ],
      "author": {
        "name": "Sabrina Dubroca",
        "email": "sd@queasysnail.net",
        "time": "Wed Sep 10 23:23:02 2014 +0200"
      },
      "committer": {
        "name": "Matt Mower",
        "email": "mowerm@gmail.com",
        "time": "Thu Aug 06 19:24:11 2015 -0500"
      },
      "message": "ipv6: clean up anycast when an interface is destroyed\n\nIf we try to rmmod the driver for an interface while sockets with\nsetsockopt(JOIN_ANYCAST) are alive, some refcounts aren\u0027t cleaned up\nand we get stuck on:\n\n  unregister_netdevice: waiting for ens3 to become free. Usage count \u003d 1\n\nIf we LEAVE_ANYCAST/close everything before rmmod\u0027ing, there is no\nproblem.\n\nWe need to perform a cleanup similar to the one for multicast in\naddrconf_ifdown(how \u003d\u003d 1).\n\nBUG: 18902601\nBug: 19100303\n\nChange-Id: I6d51aed5755eb5738fcba91950e7773a1c985d2e\nSigned-off-by: Sabrina Dubroca \u003csd@queasysnail.net\u003e\nAcked-by: Hannes Frederic Sowa \u003channes@stressinduktion.org\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Patrick Tjin \u003cpattjin@google.com\u003e\n"
    },
    {
      "commit": "cd5ade278d49db238f6fa1eb50a2c68ce7962a05",
      "tree": "f4fa0ad139828c19e81babdbc0baf876502d7ea8",
      "parents": [
        "c54ef265bae7cf5f36a81a324615f9554b8b7b98"
      ],
      "author": {
        "name": "Ben Hutchings",
        "email": "ben@decadent.org.uk",
        "time": "Thu Oct 30 18:27:17 2014 +0000"
      },
      "committer": {
        "name": "flintman",
        "email": "flintman@flintmancomputers.com",
        "time": "Mon Apr 27 08:03:27 2015 -0400"
      },
      "message": "drivers/net, ipv6: Select IPv6 fragment idents for virtio UFO packets\n\ncommit 5188cd44c55db3e92cd9e77a40b5baa7ed4340f7 upstream.\n\nUFO is now disabled on all drivers that work with virtio net headers,\nbut userland may try to send UFO/IPv6 packets anyway.  Instead of\nsending with ID\u003d0, we should select identifiers on their behalf (as we\nused to).\n\nSigned-off-by: Ben Hutchings \u003cben@decadent.org.uk\u003e\nFixes: 916e4cf46d02 (\"ipv6: reuse ip6_frag_id from ip6_ufo_append_data\")\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\n[bwh: For 3.2, net/ipv6/output_core.c is a completely new file]\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "b0f741c5d11b1b2bafd8392f0cb4d8ac25be9164",
      "tree": "b90bcdc903e1ea997e6a684e58bd3f4c7ac86ee8",
      "parents": [
        "d3fdf67442c2c1c97390176ce3451a6ae48450fe"
      ],
      "author": {
        "name": "Daniel Borkmann",
        "email": "dborkman@redhat.com",
        "time": "Thu Oct 09 22:55:31 2014 +0200"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Tue Apr 14 17:33:57 2015 +0800"
      },
      "message": "net: sctp: fix skb_over_panic when receiving malformed ASCONF chunks\n\ncommit 9de7922bc709eee2f609cd01d98aaedc4cf5ea74 upstream.\n\nCommit 6f4c618ddb0 (\"SCTP : Add paramters validity check for\nASCONF chunk\") added basic verification of ASCONF chunks, however,\nit is still possible to remotely crash a server by sending a\nspecial crafted ASCONF chunk, even up to pre 2.6.12 kernels:\n\nskb_over_panic: text:ffffffffa01ea1c3 len:31056 put:30768\n head:ffff88011bd81800 data:ffff88011bd81800 tail:0x7950\n end:0x440 dev:\u003cNULL\u003e\n ------------[ cut here ]------------\nkernel BUG at net/core/skbuff.c:129!\n[...]\nCall Trace:\n \u003cIRQ\u003e\n [\u003cffffffff8144fb1c\u003e] skb_put+0x5c/0x70\n [\u003cffffffffa01ea1c3\u003e] sctp_addto_chunk+0x63/0xd0 [sctp]\n [\u003cffffffffa01eadaf\u003e] sctp_process_asconf+0x1af/0x540 [sctp]\n [\u003cffffffff8152d025\u003e] ? _read_unlock_bh+0x15/0x20\n [\u003cffffffffa01e0038\u003e] sctp_sf_do_asconf+0x168/0x240 [sctp]\n [\u003cffffffffa01e3751\u003e] sctp_do_sm+0x71/0x1210 [sctp]\n [\u003cffffffff8147645d\u003e] ? fib_rules_lookup+0xad/0xf0\n [\u003cffffffffa01e6b22\u003e] ? sctp_cmp_addr_exact+0x32/0x40 [sctp]\n [\u003cffffffffa01e8393\u003e] sctp_assoc_bh_rcv+0xd3/0x180 [sctp]\n [\u003cffffffffa01ee986\u003e] sctp_inq_push+0x56/0x80 [sctp]\n [\u003cffffffffa01fcc42\u003e] sctp_rcv+0x982/0xa10 [sctp]\n [\u003cffffffffa01d5123\u003e] ? ipt_local_in_hook+0x23/0x28 [iptable_filter]\n [\u003cffffffff8148bdc9\u003e] ? nf_iterate+0x69/0xb0\n [\u003cffffffff81496d10\u003e] ? ip_local_deliver_finish+0x0/0x2d0\n [\u003cffffffff8148bf86\u003e] ? nf_hook_slow+0x76/0x120\n [\u003cffffffff81496d10\u003e] ? ip_local_deliver_finish+0x0/0x2d0\n [\u003cffffffff81496ded\u003e] ip_local_deliver_finish+0xdd/0x2d0\n [\u003cffffffff81497078\u003e] ip_local_deliver+0x98/0xa0\n [\u003cffffffff8149653d\u003e] ip_rcv_finish+0x12d/0x440\n [\u003cffffffff81496ac5\u003e] ip_rcv+0x275/0x350\n [\u003cffffffff8145c88b\u003e] __netif_receive_skb+0x4ab/0x750\n [\u003cffffffff81460588\u003e] netif_receive_skb+0x58/0x60\n\nThis can be triggered e.g., through a simple scripted nmap\nconnection scan injecting the chunk after the handshake, for\nexample, ...\n\n  -------------- INIT[ASCONF; ASCONF_ACK] -------------\u003e\n  \u003c----------- INIT-ACK[ASCONF; ASCONF_ACK] ------------\n  -------------------- COOKIE-ECHO --------------------\u003e\n  \u003c-------------------- COOKIE-ACK ---------------------\n  ------------------ ASCONF; UNKNOWN ------------------\u003e\n\n... where ASCONF chunk of length 280 contains 2 parameters ...\n\n  1) Add IP address parameter (param length: 16)\n  2) Add/del IP address parameter (param length: 255)\n\n... followed by an UNKNOWN chunk of e.g. 4 bytes. Here, the\nAddress Parameter in the ASCONF chunk is even missing, too.\nThis is just an example and similarly-crafted ASCONF chunks\ncould be used just as well.\n\nThe ASCONF chunk passes through sctp_verify_asconf() as all\nparameters passed sanity checks, and after walking, we ended\nup successfully at the chunk end boundary, and thus may invoke\nsctp_process_asconf(). Parameter walking is done with\nWORD_ROUND() to take padding into account.\n\nIn sctp_process_asconf()\u0027s TLV processing, we may fail in\nsctp_process_asconf_param() e.g., due to removal of the IP\naddress that is also the source address of the packet containing\nthe ASCONF chunk, and thus we need to add all TLVs after the\nfailure to our ASCONF response to remote via helper function\nsctp_add_asconf_response(), which basically invokes a\nsctp_addto_chunk() adding the error parameters to the given\nskb.\n\nWhen walking to the next parameter this time, we proceed\nwith ...\n\n  length \u003d ntohs(asconf_param-\u003eparam_hdr.length);\n  asconf_param \u003d (void *)asconf_param + length;\n\n... instead of the WORD_ROUND()\u0027ed length, thus resulting here\nin an off-by-one that leads to reading the follow-up garbage\nparameter length of 12336, and thus throwing an skb_over_panic\nfor the reply when trying to sctp_addto_chunk() next time,\nwhich implicitly calls the skb_put() with that length.\n\nFix it by using sctp_walk_params() [ which is also used in\nINIT parameter processing ] macro in the verification *and*\nin ASCONF processing: it will make sure we don\u0027t spill over,\nthat we walk parameters WORD_ROUND()\u0027ed. Moreover, we\u0027re being\nmore defensive and guard against unknown parameter types and\nmissized addresses.\n\nJoint work with Vlad Yasevich.\n\nFixes: b896b82be4ae (\"[SCTP] ADDIP: Support for processing incoming ASCONF_ACK chunks.\")\nSigned-off-by: Daniel Borkmann \u003cdborkman@redhat.com\u003e\nSigned-off-by: Vlad Yasevich \u003cvyasevich@gmail.com\u003e\nAcked-by: Neil Horman \u003cnhorman@tuxdriver.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\n[lizf: Backported to 3.4: adjust context]\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "d3fdf67442c2c1c97390176ce3451a6ae48450fe",
      "tree": "552e89166881eb139ded32dd20c6fdf297b40d5b",
      "parents": [
        "203ce0b2fb0cd248adfe49aa757527583aeab327"
      ],
      "author": {
        "name": "Daniel Borkmann",
        "email": "dborkman@redhat.com",
        "time": "Thu Oct 09 22:55:32 2014 +0200"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Tue Apr 14 17:33:57 2015 +0800"
      },
      "message": "net: sctp: fix panic on duplicate ASCONF chunks\n\ncommit b69040d8e39f20d5215a03502a8e8b4c6ab78395 upstream.\n\nWhen receiving a e.g. semi-good formed connection scan in the\nform of ...\n\n  -------------- INIT[ASCONF; ASCONF_ACK] -------------\u003e\n  \u003c----------- INIT-ACK[ASCONF; ASCONF_ACK] ------------\n  -------------------- COOKIE-ECHO --------------------\u003e\n  \u003c-------------------- COOKIE-ACK ---------------------\n  ---------------- ASCONF_a; ASCONF_b -----------------\u003e\n\n... where ASCONF_a equals ASCONF_b chunk (at least both serials\nneed to be equal), we panic an SCTP server!\n\nThe problem is that good-formed ASCONF chunks that we reply with\nASCONF_ACK chunks are cached per serial. Thus, when we receive a\nsame ASCONF chunk twice (e.g. through a lost ASCONF_ACK), we do\nnot need to process them again on the server side (that was the\nidea, also proposed in the RFC). Instead, we know it was cached\nand we just resend the cached chunk instead. So far, so good.\n\nWhere things get nasty is in SCTP\u0027s side effect interpreter, that\nis, sctp_cmd_interpreter():\n\nWhile incoming ASCONF_a (chunk \u003d event_arg) is being marked\n!end_of_packet and !singleton, and we have an association context,\nwe do not flush the outqueue the first time after processing the\nASCONF_ACK singleton chunk via SCTP_CMD_REPLY. Instead, we keep it\nqueued up, although we set local_cork to 1. Commit 2e3216cd54b1\nchanged the precedence, so that as long as we get bundled, incoming\nchunks we try possible bundling on outgoing queue as well. Before\nthis commit, we would just flush the output queue.\n\nNow, while ASCONF_a\u0027s ASCONF_ACK sits in the corked outq, we\ncontinue to process the same ASCONF_b chunk from the packet. As\nwe have cached the previous ASCONF_ACK, we find it, grab it and\ndo another SCTP_CMD_REPLY command on it. So, effectively, we rip\nthe chunk-\u003elist pointers and requeue the same ASCONF_ACK chunk\nanother time. Since we process ASCONF_b, it\u0027s correctly marked\nwith end_of_packet and we enforce an uncork, and thus flush, thus\ncrashing the kernel.\n\nFix it by testing if the ASCONF_ACK is currently pending and if\nthat is the case, do not requeue it. When flushing the output\nqueue we may relink the chunk for preparing an outgoing packet,\nbut eventually unlink it when it\u0027s copied into the skb right\nbefore transmission.\n\nJoint work with Vlad Yasevich.\n\nFixes: 2e3216cd54b1 (\"sctp: Follow security requirement of responding with 1 packet\")\nSigned-off-by: Daniel Borkmann \u003cdborkman@redhat.com\u003e\nSigned-off-by: Vlad Yasevich \u003cvyasevich@gmail.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "ae436e93e3c0f5f90e0cb32a78e684964eabe420",
      "tree": "703dd8f400bd239ead2fe3d3074339e9694e813f",
      "parents": [
        "db13521323cf9f3d03240a031a07c9687269d2cf"
      ],
      "author": {
        "name": "Hannes Frederic Sowa",
        "email": "hannes@stressinduktion.org",
        "time": "Fri Jan 23 12:01:26 2015 +0100"
      },
      "committer": {
        "name": "Brinly Taylor",
        "email": "uberlaggydarwin@gmail.com",
        "time": "Thu Feb 05 08:46:17 2015 +1030"
      },
      "message": "ipv4: try to cache dst_entries which would cause a redirect\n\nNot caching dst_entries which cause redirects could be exploited by hosts\non the same subnet, causing a severe DoS attack. This effect aggravated\nsince commit f88649721268999 (\"ipv4: fix dst race in sk_dst_get()\").\n\nLookups causing redirects will be allocated with DST_NOCACHE set which\nwill force dst_release to free them via RCU.  Unfortunately waiting for\nRCU grace period just takes too long, we can end up with \u003e1M dst_entries\nwaiting to be released and the system will run OOM. rcuos threads cannot\ncatch up under high softirq load.\n\nAttaching the flag to emit a redirect later on to the specific skb allows\nus to cache those dst_entries thus reducing the pressure on allocation\nand deallocation.\n\nThis issue was discovered by Marcelo Leitner.\n\nCc: Julian Anastasov \u003cja@ssi.bg\u003e\nSigned-off-by: Marcelo Leitner \u003cmleitner@redhat.com\u003e\nSigned-off-by: Florian Westphal \u003cfw@strlen.de\u003e\nSigned-off-by: Hannes Frederic Sowa \u003channes@stressinduktion.org\u003e\nSigned-off-by: Julian Anastasov \u003cja@ssi.bg\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\n\nConflicts:\n\tinclude/net/ip.h\n\tnet/ipv4/route.c\n\nChange-Id: I53e4b500a4db2f5fece937a42a3bd810b2640c44\n"
    },
    {
      "commit": "e02ae9ddc8130c8a83c3439d24ac831608384fc9",
      "tree": "9b60f0eb4ace52ca08fb8228af0642db94b5342d",
      "parents": [
        "fd873bf1ce5477514515e82aa8acdc7ec06a9b97"
      ],
      "author": {
        "name": "Ben Hutchings",
        "email": "ben@decadent.org.uk",
        "time": "Thu Oct 30 18:27:17 2014 +0000"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Mon Feb 02 17:05:26 2015 +0800"
      },
      "message": "drivers/net, ipv6: Select IPv6 fragment idents for virtio UFO packets\n\ncommit 5188cd44c55db3e92cd9e77a40b5baa7ed4340f7 upstream.\n\nUFO is now disabled on all drivers that work with virtio net headers,\nbut userland may try to send UFO/IPv6 packets anyway.  Instead of\nsending with ID\u003d0, we should select identifiers on their behalf (as we\nused to).\n\nSigned-off-by: Ben Hutchings \u003cben@decadent.org.uk\u003e\nFixes: 916e4cf46d02 (\"ipv6: reuse ip6_frag_id from ip6_ufo_append_data\")\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\n[bwh: For 3.2, net/ipv6/output_core.c is a completely new file]\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "1097d78180e1a2916c2bcdb15cb90ba131af9cd8",
      "tree": "5910f8fc0dcb85c71011ccccee18895769699390",
      "parents": [
        "3ded4adc97887ddde3c1855f29f062e015d19425",
        "7fd7a446b1c2b96252e4389746e5419eae04faef"
      ],
      "author": {
        "name": "Paul",
        "email": "javelinanddart@gmail.com",
        "time": "Sun Jan 11 17:15:40 2015 -0800"
      },
      "committer": {
        "name": "Ethan Chen",
        "email": "intervigil@gmail.com",
        "time": "Sun Jan 11 17:20:45 2015 -0800"
      },
      "message": "Merge tag \u0027v3.4.105\u0027 into cm-12.0\n\nThis is the 3.4.105 stable release\n\nConflicts:\n\tarch/arm/mm/proc-v7.S\n\tdrivers/bluetooth/hci_ldisc.c\n\tdrivers/media/dvb/dvb-core/dmxdev.c\n\tdrivers/usb/core/driver.c\n\tdrivers/usb/dwc3/core.c\n\tdrivers/usb/host/xhci-hub.c\n\tdrivers/usb/host/xhci.c\n\tdrivers/usb/serial/qcserial.c\n\tdrivers/usb/serial/usb_wwan.c\n\tkernel/events/core.c\n\tkernel/time/tick-sched.ck\n\tkernel/futex.c\n\tmm/memory_hotplug.c\n\tmm/vmscan.c\n\tnet/bluetooth/hci_conn.c\n\tnet/bluetooth/hci_event.c\n\tnet/bluetooth/l2cap_core.c\n\tnet/ipv4/ping.c\n\tnet/wireless/nl80211.c\n\tsound/soc/soc-core.c\n\nChange-Id: Id09da84afb427ba1a32ff26e74f2bb86458d4a2e\n"
    },
    {
      "commit": "74cfe2dcc0f4b17f9abbabf349e33c39a260987e",
      "tree": "206493082f5edc72fdac6c958877090d7d17fb37",
      "parents": [
        "a580da13cb3f1f4984e71befc4f78c5a1f3181d0",
        "6cf93503105dc0cf63fc1384088db92bb71cbe4c"
      ],
      "author": {
        "name": "Ethan Chen",
        "email": "intervigil@gmail.com",
        "time": "Tue Dec 16 00:35:23 2014 -0800"
      },
      "committer": {
        "name": "Ethan Chen",
        "email": "intervigil@gmail.com",
        "time": "Tue Dec 16 00:35:23 2014 -0800"
      },
      "message": "Merge remote-tracking branch \u0027caf/LA.AF.1.1_rb1.7\u0027 into cm-12.0\n\nConflicts:\n\tdrivers/misc/qseecom.c\n\tfs/proc/task_mmu.c\n\tinclude/net/tcp.h\n\tnet/ipv4/syncookies.c\n\tnet/ipv6/route.c\n\tnet/ipv6/tcp_ipv6.c\n\nChange-Id: I8a953e9f483a24ee45f5e1c570b6a4f92e87c6e9\n"
    },
    {
      "commit": "be93eea739598a5bf2562110323d79d80d0e6a33",
      "tree": "58479ef6306aea7696730678edfe87d6523ed4e5",
      "parents": [
        "a51b4d7710d1a3593c3bdc4592fdecbbb8df4f16"
      ],
      "author": {
        "name": "Eliad Peller",
        "email": "eliad@wizery.com",
        "time": "Wed Jun 11 10:23:35 2014 +0300"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Mon Dec 01 18:02:22 2014 +0800"
      },
      "message": "regulatory: add NUL to alpha2\n\ncommit a5fe8e7695dc3f547e955ad2b662e3e72969e506 upstream.\n\nalpha2 is defined as 2-chars array, but is used in multiple\nplaces as string (e.g. with nla_put_string calls), which\nmight leak kernel data.\n\nSolve it by simply adding an extra char for the NULL\nterminator, making such operations safe.\n\nSigned-off-by: Eliad Peller \u003celiadx.peller@intel.com\u003e\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\n[lizf: Backported to 3.4: adjust context]\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "50db8c0110dbff94dfacc1f4752a927dbe339e9c",
      "tree": "fc604545ec971ab0e224c305f0b948edc08295aa",
      "parents": [
        "25b02b6d180efeec13851162c3319962977c1fb0",
        "2f64c5e6faa76368cd2c70c1d48fc4c2d44acbbf"
      ],
      "author": {
        "name": "Ethan Chen",
        "email": "intervigil@gmail.com",
        "time": "Fri Nov 14 01:04:45 2014 -0800"
      },
      "committer": {
        "name": "Ethan Chen",
        "email": "intervigil@gmail.com",
        "time": "Fri Nov 14 01:04:45 2014 -0800"
      },
      "message": "Merge remote-tracking branch \u0027caf/caf/LA.AF.1.1_rb1.5\u0027 into cm-12.0\n"
    },
    {
      "commit": "bc2be064bd7394f417326404d641cf9eabb4ac4e",
      "tree": "a03a6f166cf26ed0bc49a84dd754d2e1160e18a3",
      "parents": [
        "52cb8fc12e41c36111d5531c6c8e70d406a85207",
        "8cb56e3467fd98e6f9396553402cf22b08f1e5a5"
      ],
      "author": {
        "name": "Linux Build Service Account",
        "email": "lnxbuild@localhost",
        "time": "Thu Nov 13 13:03:28 2014 -0800"
      },
      "committer": {
        "name": "Gerrit - the friendly Code Review server",
        "email": "code-review@localhost",
        "time": "Thu Nov 13 13:03:27 2014 -0800"
      },
      "message": "Merge \"net: support marking accepting TCP sockets\""
    },
    {
      "commit": "52cb8fc12e41c36111d5531c6c8e70d406a85207",
      "tree": "5b91171e550f77916bd148961615c7ba5be56a1c",
      "parents": [
        "8c1d434b2e49df7a7cefac06e62ab5faa7eb4776",
        "2887dec4438f37edfd8dbf355af23d61cfdd4c27"
      ],
      "author": {
        "name": "Linux Build Service Account",
        "email": "lnxbuild@localhost",
        "time": "Thu Nov 13 13:03:27 2014 -0800"
      },
      "committer": {
        "name": "Gerrit - the friendly Code Review server",
        "email": "code-review@localhost",
        "time": "Thu Nov 13 13:03:27 2014 -0800"
      },
      "message": "Merge \"net: add a sysctl to reflect the fwmark on replies\""
    },
    {
      "commit": "8c1d434b2e49df7a7cefac06e62ab5faa7eb4776",
      "tree": "97f3aa4b233011a156128517bd85fb3e09f8cc38",
      "parents": [
        "bc4bcee71617461ed19a852f9d873f5979820ef1",
        "653be181eef3589b47119cd68c985975119fa61f"
      ],
      "author": {
        "name": "Linux Build Service Account",
        "email": "lnxbuild@localhost",
        "time": "Thu Nov 13 13:03:26 2014 -0800"
      },
      "committer": {
        "name": "Gerrit - the friendly Code Review server",
        "email": "code-review@localhost",
        "time": "Thu Nov 13 13:03:26 2014 -0800"
      },
      "message": "Merge \"net: ipv6: autoconf routes into per-device tables\""
    },
    {
      "commit": "6891c8f90220dfb5d71d83263f0a41b30f9732e2",
      "tree": "48b4c7141a700787180c07ff23e35ffb42d21037",
      "parents": [
        "2eeb25228b825cd3692275f3972c551504cc02ec"
      ],
      "author": {
        "name": "JP Abgrall",
        "email": "jpa@google.com",
        "time": "Fri Feb 07 18:40:10 2014 -0800"
      },
      "committer": {
        "name": "Ian Maund",
        "email": "imaund@codeaurora.org",
        "time": "Fri Nov 07 16:35:05 2014 -0800"
      },
      "message": "tcp: add a sysctl to config the tcp_default_init_rwnd\n\nThe default initial rwnd is hardcoded to 10.\n\nNow we allow it to be controlled via\n  /proc/sys/net/ipv4/tcp_default_init_rwnd\nwhich limits the values from 3 to 100\n\nThis is somewhat needed because ipv6 routes are\nautoconfigured by the kernel.\n\nSee \"An Argument for Increasing TCP\u0027s Initial Congestion Window\"\nin https://developers.google.com/speed/articles/tcp_initcwnd_paper.pdf\n\nChange-Id: I386b2a9d62de0ebe05c1ebe1b4bd91b314af5c54\nSigned-off-by: JP Abgrall \u003cjpa@google.com\u003e\nGit-commit: 969ff3bbb38b6622800a1a4bd38404e3701193de\nGit-Repo: https://android.googlesource.com/kernel/common.git\n[imaund@codeaurora.org: Resolved trivial context conflicts.]\nSigned-off-by: Ian Maund \u003cimaund@codeaurora.org\u003e\n"
    },
    {
      "commit": "414192d0710b30b2dbf5855b684cd0a18a33aebf",
      "tree": "c2a53833018988086d0b94ed58babb08b7ecb443",
      "parents": [
        "462ce7cf70a565d9fd58421bb28a4bdcff9dfa6e"
      ],
      "author": {
        "name": "Sreeram Ramachandran",
        "email": "sreeram@google.com",
        "time": "Tue Jul 08 11:37:03 2014 -0700"
      },
      "committer": {
        "name": "Gerrit - the friendly Code Review server",
        "email": "code-review@localhost",
        "time": "Wed Sep 17 03:33:00 2014 -0700"
      },
      "message": "Handle \u0027sk\u0027 being NULL in UID-based routing.\n\nBug: 15413527\nChange-Id: If33bebb7b52c0ebfa8dac2452607bce0c2b0faa0\nSigned-off-by: Sreeram Ramachandran \u003csreeram@google.com\u003e\nGit-commit: 0836a0c191f580ed69254e0b287cdce58481e978\nGit-repo: https://android.googlesource.com/kernel/common.git\nSigned-off-by: Ian Maund \u003cimaund@codeaurora.org\u003e\n"
    },
    {
      "commit": "462ce7cf70a565d9fd58421bb28a4bdcff9dfa6e",
      "tree": "08073040d1eeaa0b05e95fb9e7a78e162f4aab72",
      "parents": [
        "1af043959e84f3e14fed7c9a965ce649217d2e42"
      ],
      "author": {
        "name": "Lorenzo Colitti",
        "email": "lorenzo@google.com",
        "time": "Mon Mar 31 16:23:51 2014 +0900"
      },
      "committer": {
        "name": "Gerrit - the friendly Code Review server",
        "email": "code-review@localhost",
        "time": "Wed Sep 17 03:26:12 2014 -0700"
      },
      "message": "net: core: Support UID-based routing.\n\nThis contains the following commits:\n\n1. 0149763 net: core: Add a UID range to fib rules.\n2. 1650474 net: core: Use the socket UID in routing lookups.\n3. 0b16771 net: ipv4: Add the UID to the route cache.\n4. ee058f1 net: core: Add a RTA_UID attribute to routes.\n    This is so that userspace can do per-UID route lookups.\n\nBug: 15413527\nChange-Id: I1285474c6734614d3bda6f61d88dfe89a4af7892\nSigned-off-by: Lorenzo Colitti \u003clorenzo@google.com\u003e\nGit-commit: 0b428749ce5969bc06c73855e360141b4e7126e8\nGit-repo: https://android.googlesource.com/kernel/common.git\nSigned-off-by: Ian Maund \u003cimaund@codeaurora.org\u003e\n"
    },
    {
      "commit": "509a15a5d6b0cfd3e4e396844615df6335ff4c62",
      "tree": "a3f92b13246768ed53016216cac459a86ec1f772",
      "parents": [
        "ad52eef552c7896ec6024ee72fc126167fe5c4e2"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "edumazet@google.com",
        "time": "Sat Jul 26 08:58:10 2014 +0200"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Aug 14 08:42:35 2014 +0800"
      },
      "message": "ip: make IP identifiers less predictable\n\n[ Upstream commit 04ca6973f7c1a0d8537f2d9906a0cf8e69886d75 ]\n\nIn \"Counting Packets Sent Between Arbitrary Internet Hosts\", Jeffrey and\nJedidiah describe ways exploiting linux IP identifier generation to\ninfer whether two machines are exchanging packets.\n\nWith commit 73f156a6e8c1 (\"inetpeer: get rid of ip_id_count\"), we\nchanged IP id generation, but this does not really prevent this\nside-channel technique.\n\nThis patch adds a random amount of perturbation so that IP identifiers\nfor a given destination [1] are no longer monotonically increasing after\nan idle period.\n\nNote that prandom_u32_max(1) returns 0, so if generator is used at most\nonce per jiffy, this patch inserts no hole in the ID suite and do not\nincrease collision probability.\n\nThis is jiffies based, so in the worst case (HZ\u003d1000), the id can\nrollover after ~65 seconds of idle time, which should be fine.\n\nWe also change the hash used in __ip_select_ident() to not only hash\non daddr, but also saddr and protocol, so that ICMP probes can not be\nused to infer information for other protocols.\n\nFor IPv6, adds saddr into the hash as well, but not nexthdr.\n\nIf I ping the patched target, we can see ID are now hard to predict.\n\n21:57:11.008086 IP (...)\n    A \u003e target: ICMP echo request, seq 1, length 64\n21:57:11.010752 IP (... id 2081 ...)\n    target \u003e A: ICMP echo reply, seq 1, length 64\n\n21:57:12.013133 IP (...)\n    A \u003e target: ICMP echo request, seq 2, length 64\n21:57:12.015737 IP (... id 3039 ...)\n    target \u003e A: ICMP echo reply, seq 2, length 64\n\n21:57:13.016580 IP (...)\n    A \u003e target: ICMP echo request, seq 3, length 64\n21:57:13.019251 IP (... id 3437 ...)\n    target \u003e A: ICMP echo reply, seq 3, length 64\n\n[1] TCP sessions uses a per flow ID generator not changed by this patch.\n\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nReported-by: Jeffrey Knockel \u003cjeffk@cs.unm.edu\u003e\nReported-by: Jedidiah R. Crandall \u003ccrandall@cs.unm.edu\u003e\nCc: Willy Tarreau \u003cw@1wt.eu\u003e\nCc: Hannes Frederic Sowa \u003channes@redhat.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "ad52eef552c7896ec6024ee72fc126167fe5c4e2",
      "tree": "ad82cf940ab103a6b51260f681b22d21f6ecdb2c",
      "parents": [
        "0a9d91dca3b9f797f2fc615486c12afa59f19a3b"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "edumazet@google.com",
        "time": "Mon Jun 02 05:26:03 2014 -0700"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Aug 14 08:42:35 2014 +0800"
      },
      "message": "inetpeer: get rid of ip_id_count\n\n[ Upstream commit 73f156a6e8c1074ac6327e0abd1169e95eb66463 ]\n\nIdeally, we would need to generate IP ID using a per destination IP\ngenerator.\n\nlinux kernels used inet_peer cache for this purpose, but this had a huge\ncost on servers disabling MTU discovery.\n\n1) each inet_peer struct consumes 192 bytes\n\n2) inetpeer cache uses a binary tree of inet_peer structs,\n   with a nominal size of ~66000 elements under load.\n\n3) lookups in this tree are hitting a lot of cache lines, as tree depth\n   is about 20.\n\n4) If server deals with many tcp flows, we have a high probability of\n   not finding the inet_peer, allocating a fresh one, inserting it in\n   the tree with same initial ip_id_count, (cf secure_ip_id())\n\n5) We garbage collect inet_peer aggressively.\n\nIP ID generation do not have to be \u0027perfect\u0027\n\nGoal is trying to avoid duplicates in a short period of time,\nso that reassembly units have a chance to complete reassembly of\nfragments belonging to one message before receiving other fragments\nwith a recycled ID.\n\nWe simply use an array of generators, and a Jenkin hash using the dst IP\nas a key.\n\nipv6_select_ident() is put back into net/ipv6/ip6_output.c where it\nbelongs (it is only used from this file)\n\nsecure_ip_id() and secure_ipv6_id() no longer are needed.\n\nRename ip_select_ident_more() to ip_select_ident_segs() to avoid\nunnecessary decrement/increment of the number of segments.\n\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "8cb56e3467fd98e6f9396553402cf22b08f1e5a5",
      "tree": "55167cefd4f2d970a4723a35f61d7322d256b0ba",
      "parents": [
        "2887dec4438f37edfd8dbf355af23d61cfdd4c27"
      ],
      "author": {
        "name": "Lorenzo Colitti",
        "email": "lorenzo@google.com",
        "time": "Wed Mar 26 13:03:12 2014 +0900"
      },
      "committer": {
        "name": "Samir Mehta",
        "email": "samirn@codeaurora.org",
        "time": "Tue Aug 05 18:02:48 2014 +0530"
      },
      "message": "net: support marking accepting TCP sockets\n\nWhen using mark-based routing, sockets returned from accept()\nmay need to be marked differently depending on the incoming\nconnection request.\n\nThis is the case, for example, if different socket marks identify\ndifferent networks: a listening socket may want to accept\nconnections from all networks, but each connection should be\nmarked with the network that the request came in on, so that\nsubsequent packets are sent on the correct network.\n\nThis patch adds a sysctl to mark TCP sockets based on the fwmark\nof the incoming SYN packet. If enabled, and an unmarked socket\nreceives a SYN, then the SYN packet\u0027s fwmark is written to the\nconnection\u0027s inet_request_sock, and later written back to the\naccepted socket when the connection is established.  If the\nsocket already has a nonzero mark, then the behaviour is the same\nas it is today, i.e., the listening socket\u0027s fwmark is used.\n\nBlack-box tested using user-mode linux:\n\n- IPv4/IPv6 SYN+ACK, FIN, etc. packets are routed based on the\n  mark of the incoming SYN packet.\n- The socket returned by accept() is marked with the mark of the\n  incoming SYN packet.\n- Tested with syncookies\u003d1 and syncookies\u003d2.\n\nChange-Id: I5e8c9b989762a93f3eb5a0c1b4df44f62d57f3cb\nSigned-off-by: Lorenzo Colitti \u003clorenzo@google.com\u003e\n[imaund@codeaurora.org: Resolve trivial merge conflicts.]\nGit-commit: 4593f09b1f9939ec6ed2f8d7848def26b98c47ac\nGit-repo: https://android.googlesource.com/kernel/common.git\nSigned-off-by: Ian Maund \u003cimaund@codeaurora.org\u003e\nSigned-off-by: Samir Mehta \u003csamirn@codeaurora.org\u003e\n"
    },
    {
      "commit": "2887dec4438f37edfd8dbf355af23d61cfdd4c27",
      "tree": "820f262ff612b449760fbf18a498f74e4f5958eb",
      "parents": [
        "653be181eef3589b47119cd68c985975119fa61f"
      ],
      "author": {
        "name": "Lorenzo Colitti",
        "email": "lorenzo@google.com",
        "time": "Tue Mar 18 20:52:27 2014 +0900"
      },
      "committer": {
        "name": "Samir Mehta",
        "email": "samirn@codeaurora.org",
        "time": "Tue Aug 05 18:01:30 2014 +0530"
      },
      "message": "net: add a sysctl to reflect the fwmark on replies\n\nKernel-originated IP packets that have no user socket associated\nwith them (e.g., ICMP errors and echo replies, TCP RSTs, etc.)\nare emitted with a mark of zero. Add a sysctl to make them have\nthe same mark as the packet they are replying to.\n\nThis allows an administrator that wishes to do so to use\nmark-based routing, firewalling, etc. for these replies by\nmarking the original packets inbound.\n\nTested using user-mode linux:\n - ICMP/ICMPv6 echo replies and errors.\n - TCP RST packets (IPv4 and IPv6).\n\nChange-Id: I95d896647b278d092ef331d1377b959da1deb042\nSigned-off-by: Lorenzo Colitti \u003clorenzo@google.com\u003e\nGit-commit: 3356997e1e1b2aa9959f046203e6d0b193bbd7f7\nGit-repo: https://android.googlesource.com/kernel/common.git\n[imaund@codeaurora.org: Resolve trivial merge conflicts.]\nSigned-off-by: Ian Maund \u003cimaund@codeaurora.org\u003e\nSigned-off-by: Samir Mehta \u003csamirn@codeaurora.org\u003e\n"
    },
    {
      "commit": "653be181eef3589b47119cd68c985975119fa61f",
      "tree": "70622b13f1dd7ec4ce74ada46f489abe582fe2c5",
      "parents": [
        "cfc667e1eac22c3ee27aceaebb18e68102a2c65b"
      ],
      "author": {
        "name": "Lorenzo Colitti",
        "email": "lorenzo@google.com",
        "time": "Wed Mar 26 19:35:41 2014 +0900"
      },
      "committer": {
        "name": "Samir Mehta",
        "email": "samirn@codeaurora.org",
        "time": "Tue Aug 05 17:58:34 2014 +0530"
      },
      "message": "net: ipv6: autoconf routes into per-device tables\n\nCurrently, IPv6 router discovery always puts routes into\nRT6_TABLE_MAIN. This causes problems for connection managers\nthat want to support multiple simultaneous network connections\nand want control over which one is used by default (e.g., wifi\nand wired).\n\nTo work around this connection managers typically take the routes\nthey prefer and copy them to static routes with low metrics in\nthe main table. This puts the burden on the connection manager\nto watch netlink to see if the routes have changed, delete the\nroutes when their lifetime expires, etc.\n\nInstead, this patch adds a per-interface sysctl to have the\nkernel put autoconf routes into different tables. This allows\neach interface to have its own autoconf table, and choosing the\ndefault interface (or using different interfaces at the same\ntime for different types of traffic) can be done using\nappropriate ip rules.\n\nThe sysctl behaves as follows:\n\n- \u003d 0: default. Put routes into RT6_TABLE_MAIN as before.\n- \u003e 0: manual. Put routes into the specified table.\n- \u003c 0: automatic. Add the absolute value of the sysctl to the\n       device\u0027s ifindex, and use that table.\n\nThe automatic mode is most useful in conjunction with\nnet.ipv6.conf.default.accept_ra_rt_table. A connection manager\nor distribution could set it to, say, -100 on boot, and\nthereafter just use IP rules.\n\nChange-Id: I093d39fb06ec413905dc0d0d5792c1bc5d5c73a9\nSigned-off-by: Lorenzo Colitti \u003clorenzo@google.com\u003e\nGit-commit: 5fe5c512af518d0abbbc0d2fafa8e355f518c2a9\nGit-repo: https://android.googlesource.com/kernel/common.git\n[imaund@codeaurora.org: Resolve trivial merge conflicts]\nSigned-off-by: Ian Maund \u003cimaund@codeaurora.org\u003e\n[samirn@codeaurora.org: Resolve trivial merge conflicts]\nSigned-off-by: Samir Mehta \u003csamirn@codeaurora.org\u003e\n"
    },
    {
      "commit": "eb688f6a4b6090dbcdccc935cf074618c0f421c1",
      "tree": "a250da8a12592fdb19ec3cf27e52b8ba6ed11abb",
      "parents": [
        "bc96ff59b2f19e924d9e15e24cee19723d674b92"
      ],
      "author": {
        "name": "Syam Sidhardhan",
        "email": "s.syam@samsung.com",
        "time": "Thu Apr 12 20:33:17 2012 +0530"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Wed Jul 09 10:51:20 2014 -0700"
      },
      "message": "Bluetooth: Remove unused hci_le_ltk_reply()\n\ncommit e10b9969f217c948c5523045f44eba4d3a758ff0 upstream.\n\nIn this API, we were using sizeof operator for an array\ngiven as function argument, which is invalid.\nHowever this API is not used anywhere.\n\nSigned-off-by: Syam Sidhardhan \u003cs.syam@samsung.com\u003e\nSigned-off-by: Gustavo Padovan \u003cgustavo@padovan.org\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "0a4474aaad97472efcd10a3e8d897d5798206f0e",
      "tree": "eedca98333d8d5ec4a09195faadef3fd6e2b52c2",
      "parents": [
        "d0e49724c557974bb109ffee5cd3eb4864b8cc1d"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "edumazet@google.com",
        "time": "Thu May 29 08:45:14 2014 -0700"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Jun 26 15:10:28 2014 -0400"
      },
      "message": "net: fix inet_getid() and ipv6_select_ident() bugs\n\n[ Upstream commit 39c36094d78c39e038c1e499b2364e13bce36f54 ]\n\nI noticed we were sending wrong IPv4 ID in TCP flows when MTU discovery\nis disabled.\nNote how GSO/TSO packets do not have monotonically incrementing ID.\n\n06:37:41.575531 IP (id 14227, proto: TCP (6), length: 4396)\n06:37:41.575534 IP (id 14272, proto: TCP (6), length: 65212)\n06:37:41.575544 IP (id 14312, proto: TCP (6), length: 57972)\n06:37:41.575678 IP (id 14317, proto: TCP (6), length: 7292)\n06:37:41.575683 IP (id 14361, proto: TCP (6), length: 63764)\n\nIt appears I introduced this bug in linux-3.1.\n\ninet_getid() must return the old value of peer-\u003eip_id_count,\nnot the new one.\n\nLets revert this part, and remove the prevention of\na null identification field in IPv6 Fragment Extension Header,\nwhich is dubious and not even done properly.\n\nFixes: 87c48fa3b463 (\"ipv6: make fragment identifications less predictable\")\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "3a2c0d4b76454fe93fa4a5042962cfd76a0a31e2",
      "tree": "3e43723bbb5b85824cbdf84a0730ee562965beb9",
      "parents": [
        "d6f6a6494dbe3be2992ae95baa52f94356d98c81"
      ],
      "author": {
        "name": "Stanislaw Gruszka",
        "email": "sgruszka@redhat.com",
        "time": "Mon Dec 03 12:56:33 2012 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Sat Jun 07 16:02:07 2014 -0700"
      },
      "message": "mac80211: introduce IEEE80211_HW_TEARDOWN_AGGR_ON_BAR_FAIL\n\ncommit 5b632fe85ec82e5c43740b52e74c66df50a37db3 upstream.\n\nCommit f0425beda4d404a6e751439b562100b902ba9c98 \"mac80211: retry sending\nfailed BAR frames later instead of tearing down aggr\" caused regression\non rt2x00 hardware (connection hangs). This regression was fixed by\ncommit be03d4a45c09ee5100d3aaaedd087f19bc20d01 \"rt2x00: Don\u0027t let\nmac80211 send a BAR when an AMPDU subframe fails\". But the latter\ncommit caused yet another problem reported in\nhttps://bugzilla.kernel.org/show_bug.cgi?id\u003d42828#c22\n\nAfter long discussion in this thread:\nhttp://mid.gmane.org/20121018075615.GA18212@redhat.com\nand testing various alternative solutions, which failed on one or other\nsetup, we have no other good fix for the issues like just revert both\nmentioned earlier commits.\n\nTo do not affect other hardware which benefit from commit\nf0425beda4d404a6e751439b562100b902ba9c98, instead of reverting it,\nintroduce flag that when used will restore mac80211 behaviour before\nthe commit.\n\nSigned-off-by: Stanislaw Gruszka \u003csgruszka@redhat.com\u003e\n[replaced link with mid.gmane.org that has message-id]\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\n[bwh: Backported to 3.2: adjust context]\nSigned-off-by: Ben Hutchings \u003cben@decadent.org.uk\u003e\n[hq: Backported to 3.4: adjust context]\nSigned-off-by: Qiang Huang \u003ch.huangqiang@huawei.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "6392b2685b864f0ace1eaae43c998dccb856bd30",
      "tree": "bb292ae3b0ac6311e88201c20d74f81241ec4d1c",
      "parents": [
        "cedc89a20df8cb06e3fee2f3f7b9d90430142e22"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "edumazet@google.com",
        "time": "Thu Apr 10 21:23:36 2014 -0700"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Sat Jun 07 16:01:59 2014 -0700"
      },
      "message": "ipv6: Limit mtu to 65575 bytes\n\n[ Upstream commit 30f78d8ebf7f514801e71b88a10c948275168518 ]\n\nFrancois reported that setting big mtu on loopback device could prevent\ntcp sessions making progress.\n\nWe do not support (yet ?) IPv6 Jumbograms and cook corrupted packets.\n\nWe must limit the IPv6 MTU to (65535 + 40) bytes in theory.\n\nTested:\n\nifconfig lo mtu 70000\nnetperf -H ::1\n\nBefore patch : Throughput :   0.05 Mbits\n\nAfter patch : Throughput : 35484 Mbits\n\nReported-by: Francois WELLENREITER \u003cf.wellenreiter@gmail.com\u003e\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nAcked-by: YOSHIFUJI Hideaki \u003cyoshfuji@linux-ipv6.org\u003e\nAcked-by: Hannes Frederic Sowa \u003channes@stressinduktion.org\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "4b87f408045848f42ae574326faf64073f92f2af",
      "tree": "118545ed115af537d5bbb2da8cbc46ff9dd943cb",
      "parents": [
        "14eee5bd065d6aac0acbdc6092a25ba68c55b9c8"
      ],
      "author": {
        "name": "Andrey Vagin",
        "email": "avagin@openvz.org",
        "time": "Fri Mar 28 13:54:32 2014 +0400"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Sun May 18 05:25:55 2014 -0700"
      },
      "message": "netfilter: nf_conntrack: reserve two bytes for nf_ct_ext-\u003elen\n\ncommit 223b02d923ecd7c84cf9780bb3686f455d279279 upstream.\n\n\"len\" contains sizeof(nf_ct_ext) and size of extensions. In a worst\ncase it can contain all extensions. Bellow you can find sizes for all\ntypes of extensions. Their sum is definitely bigger than 256.\n\nnf_ct_ext_types[0]-\u003elen \u003d 24\nnf_ct_ext_types[1]-\u003elen \u003d 32\nnf_ct_ext_types[2]-\u003elen \u003d 24\nnf_ct_ext_types[3]-\u003elen \u003d 32\nnf_ct_ext_types[4]-\u003elen \u003d 152\nnf_ct_ext_types[5]-\u003elen \u003d 2\nnf_ct_ext_types[6]-\u003elen \u003d 16\nnf_ct_ext_types[7]-\u003elen \u003d 8\n\nI have seen \"len\" up to 280 and my host has crashes w/o this patch.\n\nThe right way to fix this problem is reducing the size of the ecache\nextension (4) and Florian is going to do this, but these changes will\nbe quite large to be appropriate for a stable tree.\n\nFixes: 5b423f6a40a0 (netfilter: nf_conntrack: fix racy timer handling with reliable)\nCc: Pablo Neira Ayuso \u003cpablo@netfilter.org\u003e\nCc: Patrick McHardy \u003ckaber@trash.net\u003e\nCc: Jozsef Kadlecsik \u003ckadlec@blackhole.kfki.hu\u003e\nCc: \"David S. Miller\" \u003cdavem@davemloft.net\u003e\nSigned-off-by: Andrey Vagin \u003cavagin@openvz.org\u003e\nSigned-off-by: Pablo Neira Ayuso \u003cpablo@netfilter.org\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "36a093caf736755c3f42cde0abebbf6937f9f3e6",
      "tree": "c4cb589e1abe457ef20e85771acb787a5ddb9b3e",
      "parents": [
        "5cce5d16d13d6bd5f53b2cab181fefa55ae8efad",
        "00fcc691ed4a13522e01cfc1575cb7b984485b0a"
      ],
      "author": {
        "name": "Ethan Chen",
        "email": "intervigil@gmail.com",
        "time": "Fri May 02 22:35:16 2014 -0700"
      },
      "committer": {
        "name": "Ethan Chen",
        "email": "intervigil@gmail.com",
        "time": "Fri May 02 22:35:16 2014 -0700"
      },
      "message": "Merge remote-tracking branch \u0027codeaurora/caf/kk_2.7_rb1.37\u0027 into cm-11.0\n\nConflicts:\n\tarch/arm/mm/dma-mapping.c\n\tdrivers/media/video/msm/vfe/msm_vfe32.c\n\tnet/wireless/nl80211.c\n\nChange-Id: I4228f28bc74631aba13e1da969c91aaefc463195\n"
    },
    {
      "commit": "c523abc466c9b7c693e4a528ca2f54c6e931b6a6",
      "tree": "c82c97f255a7e2411d85472ae0abb991599193da",
      "parents": [
        "7f81e91dcddec69dc0124e0753e2ba6c1ae3b6b9",
        "9f48c5a49a9f69c98c3ead6bf820072df3f14732"
      ],
      "author": {
        "name": "Ethan Chen",
        "email": "intervigil@gmail.com",
        "time": "Fri Mar 07 11:49:08 2014 -0800"
      },
      "committer": {
        "name": "Ethan Chen",
        "email": "intervigil@gmail.com",
        "time": "Fri Mar 07 11:49:08 2014 -0800"
      },
      "message": "Merge remote-tracking branch \u0027codeaurora/kk_2.7_rb1.30\u0027 into cm-11.0\n\nConflicts:\n\tarch/arm/mach-msm/acpuclock-krait.c\n\tdrivers/media/video/msm/actuators/msm_actuator.c\n\tdrivers/media/video/msm/flash.c\n\tdrivers/media/video/msm/msm_camera.c\n\tdrivers/media/video/msm/server/msm_cam_server.c\n\tdrivers/media/video/msm/vfe/msm_vfe32.c\n\tdrivers/uio/uio.c\n\tdrivers/video/au1100fb.c\n\tdrivers/video/au1200fb.c\n\tinclude/media/msm_isp.h\n\tinclude/media/radio-iris.h\n\tnet/ipv4/ping.c\n\nChange-Id: Ic027f55c9667ecccaa35ee4a96ad77dbb1e8708f\n"
    },
    {
      "commit": "f33364e2359ae08121b1981c869e44d4a187f58d",
      "tree": "08a2a2f2bb860ad459d715d9f2a99bf17b30db67",
      "parents": [
        "aa7bdbd9b90a259f8c600cae4fb4f2ef1df6ee45",
        "d950549504d4302846d80b66a000b91a9eae50af"
      ],
      "author": {
        "name": "Linux Build Service Account",
        "email": "lnxbuild@localhost",
        "time": "Fri Mar 07 10:02:54 2014 -0800"
      },
      "committer": {
        "name": "Gerrit - the friendly Code Review server",
        "email": "code-review@localhost",
        "time": "Fri Mar 07 10:02:53 2014 -0800"
      },
      "message": "Merge \"nl80211: support vendor-specific events\""
    },
    {
      "commit": "aa7bdbd9b90a259f8c600cae4fb4f2ef1df6ee45",
      "tree": "dedb789e41cb0b11f26e51405f8a2419a21fc58c",
      "parents": [
        "9ad119819d2c7884c9e1836f08627d0e3280b8df",
        "b784fbe8d030a5204126e56727ee63144e16e50b"
      ],
      "author": {
        "name": "Linux Build Service Account",
        "email": "lnxbuild@localhost",
        "time": "Fri Mar 07 10:02:52 2014 -0800"
      },
      "committer": {
        "name": "Gerrit - the friendly Code Review server",
        "email": "code-review@localhost",
        "time": "Fri Mar 07 10:02:52 2014 -0800"
      },
      "message": "Merge \"nl80211: vendor command support\""
    },
    {
      "commit": "9ad119819d2c7884c9e1836f08627d0e3280b8df",
      "tree": "a77baa15e4248c6ccc2c60b68a82eb2624b93902",
      "parents": [
        "4077fccfa88d3336f7c006bb75bdf8c59bb94ad1",
        "60a48a89ebd20ef285636719a7f0a02dd8175021"
      ],
      "author": {
        "name": "Linux Build Service Account",
        "email": "lnxbuild@localhost",
        "time": "Fri Mar 07 10:02:51 2014 -0800"
      },
      "committer": {
        "name": "Gerrit - the friendly Code Review server",
        "email": "code-review@localhost",
        "time": "Fri Mar 07 10:02:51 2014 -0800"
      },
      "message": "Merge \"cfg80211: pass station supported channel and oper class info\""
    },
    {
      "commit": "d950549504d4302846d80b66a000b91a9eae50af",
      "tree": "cee8c8bff754058965e1951d6d1c620ac89e6094",
      "parents": [
        "b784fbe8d030a5204126e56727ee63144e16e50b"
      ],
      "author": {
        "name": "Leo Chang",
        "email": "leochang@codeaurora.org",
        "time": "Wed Jan 15 19:52:00 2014 -0800"
      },
      "committer": {
        "name": "Mahesh A Saptasagar",
        "email": "msapta@codeaurora.org",
        "time": "Thu Feb 20 21:17:51 2014 +0530"
      },
      "message": "nl80211: support vendor-specific events\n\nIn addition to vendor-specific commands, also support vendor-specific\nevents. These must be registered with cfg80211 before they can be used.\nThey\u0027re also advertised in nl80211 in the wiphy information so that\nuserspace knows can be expected. The events themselves are sent on a\nnew multicast group called \"vendor\".\n\nChange-Id: I184aaa9f9e8461aee572f7d0a35916cd668c2218\nCRs-fixed: 576020\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nGit-commit: 567ffc3509b2d3f965a49a18631d3da7f9a96d4f\nGit-repo: https://git.kernel.org/cgit/linux/kernel/git/linville/wireless-next.git\nSigned-off-by: Leo Chang \u003cleochang@codeaurora.org\u003e\n"
    },
    {
      "commit": "b784fbe8d030a5204126e56727ee63144e16e50b",
      "tree": "bcc9f447b5e1dfb6b220f1c028dd065b4e7ea013",
      "parents": [
        "60a48a89ebd20ef285636719a7f0a02dd8175021"
      ],
      "author": {
        "name": "Leo Chang",
        "email": "leochang@codeaurora.org",
        "time": "Wed Jan 15 19:22:28 2014 -0800"
      },
      "committer": {
        "name": "Mahesh A Saptasagar",
        "email": "msapta@codeaurora.org",
        "time": "Thu Feb 20 20:51:24 2014 +0530"
      },
      "message": "nl80211: vendor command support\n\nAdd support for vendor-specific commands to nl80211. This is\nintended to be used for really vendor-specific functionality\nthat can\u0027t be implemented in a generic fashion for any reason.\nIt\u0027s *NOT* intended to be used for any normal/generic feature\nor any optimisations that could be implemented across drivers.\nCurrently, only vendor commands (with replies) are supported,\nno dump operations or vendor-specific notifications.\nAlso add a function wdev_to_ieee80211_vif() to mac80211 which\nis needed for mac80211-based drivers wanting to implement any\nvendor commands.\n\nChange-Id: If73cf90d152ca0888a563cf4ae685aad9cec6443\nCRs-fixed: 576020\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nGit-commit: ad7e718c9b4f717823fd920a0103f7b0fb06183f\nGit-repo: https://git.kernel.org/cgit/linux/kernel/git/linville/wireless-next.git\nSigned-off-by: Leo Chang \u003cleochang@codeaurora.org\u003e\n"
    },
    {
      "commit": "60a48a89ebd20ef285636719a7f0a02dd8175021",
      "tree": "8fa5e58b0a189001c136ad4a191b11aa2863eae4",
      "parents": [
        "08e79dc6850c649f8d04aa0c039ea2a00ec60297"
      ],
      "author": {
        "name": "Naresh Jayaram",
        "email": "njayar@codeaurora.org",
        "time": "Fri Jan 03 14:46:34 2014 +0530"
      },
      "committer": {
        "name": "Mahesh A Saptasagar",
        "email": "msapta@codeaurora.org",
        "time": "Thu Feb 20 20:42:04 2014 +0530"
      },
      "message": "cfg80211: pass station supported channel and oper class info\n\nThe information of the peer\u0027s supported channels and supported operating\nclasses are required for the driver to perform TDLS off channel\noperations. This commit enhances the function nl80211_(new)set_station\nto pass this information of the peer to the driver.\n\nCRs-fixed: 595620\nChange-Id: I1d630deb4cf435e7f72e3a59276d3771c2b03114\nSigned-off-by: Naresh Jayaram \u003cnjayar@codeaurora.org\u003e\n"
    },
    {
      "commit": "7f285eb6d3ab8aca873632bfc9ff6faf645a246b",
      "tree": "f3d8668126d79b01fb95dc61bbf133a0cfe121db",
      "parents": [
        "63d6049bf5ff893a101bb8c41bd4ba0cd0ee967c"
      ],
      "author": {
        "name": "Mahesh A Saptasagar",
        "email": "msapta@codeaurora.org",
        "time": "Tue Feb 11 13:39:05 2014 +0530"
      },
      "committer": {
        "name": "Mahesh A Saptasagar",
        "email": "msapta@codeaurora.org",
        "time": "Tue Feb 11 13:47:13 2014 +0530"
      },
      "message": "WLAN subsystem: Sysctl support for key TCP/IP parameters\n\nIt has been observed that default values for some of key tcp/ip\nparameters are affecting the tput/performance of the system. Hence\nextending configuration capabilities to TCP/Ip stack through\nsysctl interface.\n\nChange-Id: I0c99d5b50cbe0d6496e40d391eacc12b0c62dbed\nCRs-Fixed: 507581\nSigned-off-by: Mahesh A Saptasagar \u003cmsapta@codeaurora.org\u003e\n"
    },
    {
      "commit": "f704820d27f72bc596d47a1119514a67b91a7b7c",
      "tree": "dca4b1daf6ef90080e637c7956f8871d7ae644cf",
      "parents": [
        "dce956192e60503d992558fea5ea5665fdfc929a"
      ],
      "author": {
        "name": "Lorenzo Colitti",
        "email": "lorenzo@google.com",
        "time": "Wed Jan 16 22:09:49 2013 +0000"
      },
      "committer": {
        "name": "Subash Abhinov Kasiviswanathan",
        "email": "subashab@codeaurora.org",
        "time": "Wed Jan 29 10:02:50 2014 -0700"
      },
      "message": "net: ipv6: Add IPv6 support to the ping socket.\n\n[backport of net-next 6d0bfe22611602f36617bc7aa2ffa1bbb2f54c67]\n\nThis adds the ability to send ICMPv6 echo requests without a\nraw socket. The equivalent ability for ICMPv4 was added in\n2011.\n\nInstead of having separate code paths for IPv4 and IPv6, make\nmost of the code in net/ipv4/ping.c dual-stack and only add a\nfew IPv6-specific bits (like the protocol definition) to a new\nnet/ipv6/ping.c. Hopefully this will reduce divergence and/or\nduplication of bugs in the future.\n\nCaveats:\n\n- Setting options via ancillary data (e.g., using IPV6_PKTINFO\n  to specify the outgoing interface) is not yet supported.\n- There are no separate security settings for IPv4 and IPv6;\n  everything is controlled by /proc/net/ipv4/ping_group_range.\n- The proc interface does not yet display IPv6 ping sockets\n  properly.\n\nTested with a patched copy of ping6 and using raw socket calls.\nCompiles and works with all of CONFIG_IPV6\u003d{n,m,y}.\n\nCRs-Fixed: 573548\nChange-Id: I0081b4654dd54b12c8f233e00e18943582aa2142\nSigned-off-by: Lorenzo Colitti \u003clorenzo@google.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\n[lorenzo@google.com: backported to 3.4]\nSigned-off-by: Lorenzo Colitti \u003clorenzo@google.com\u003e\nGit-commit: 1f0675844e3b63a765e5bd32bc5af051ccd951c0\nGit-repo: https://android.googlesource.com/kernel/common\n[subashab@codeaurora.org : resolve trivial merge conflicts]\nSigned-off-by: Subash Abhinov Kasiviswanathan \u003csubashab@codeaurora.org\u003e\nSigned-off-by: Ian Maund \u003cimaund@codeaurora.org\u003e\n"
    },
    {
      "commit": "dce956192e60503d992558fea5ea5665fdfc929a",
      "tree": "eaa55b05bc7628622dacac5de1b6d9dcfc7dda76",
      "parents": [
        "78617601ecb1f3b0a2c1d7cf4eb97a0ebccc8f03"
      ],
      "author": {
        "name": "Hannes Frederic Sowa",
        "email": "hannes@stressinduktion.org",
        "time": "Tue Jan 21 11:26:33 2014 -0700"
      },
      "committer": {
        "name": "Subash Abhinov Kasiviswanathan",
        "email": "subashab@codeaurora.org",
        "time": "Wed Jan 29 09:50:59 2014 -0700"
      },
      "message": "ipv6: introdcue __ipv6_addr_needs_scope_id and ipv6_iface_scope_id helper functions\n\n[net-next commit b7ef213ef65256168df83ddfbb8131ed9adc10f9]\n\n__ipv6_addr_needs_scope_id checks if an ipv6 address needs to supply\na \u0027sin6_scope_id !\u003d 0\u0027. \u0027sin6_scope_id !\u003d 0\u0027 was enforced in case\nof link-local addresses. To support interface-local multicast these\nchecks had to be enhanced and are now consolidated into these new helper\nfunctions.\n\nv2:\na) migrated to struct ipv6_addr_props\n\nv3:\na) reverted changes for ipv6_addr_props\nb) test for address type instead of comparing scope\n\nv4:\na) unchanged\n\nCRs-Fixed: 573548\nChange-Id: Id6fc54cec61f967928e08a9eba4f857157d973a3\nSuggested-by: YOSHIFUJI Hideaki \u003cyoshfuji@linux-ipv6.org\u003e\nCc: YOSHIFUJI Hideaki \u003cyoshfuji@linux-ipv6.org\u003e\nAcked-by: YOSHIFUJI Hideaki \u003cyoshfuji@linux-ipv6.org\u003e\nSigned-off-by: Hannes Frederic Sowa \u003channes@stressinduktion.org\u003e\nAcked-by: YOSHIFUJI Hideaki \u003cyoshfuji@linux-ipv6.org\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nGit-commit: 6607cf0ded9a5f456295477bb1215351fce38d23\nGit-repo: https://android.googlesource.com/kernel/common/\nSigned-off-by: Subash Abhinov Kasiviswanathan \u003csubashab@codeaurora.org\u003e\n"
    },
    {
      "commit": "58634ac42e736eea0e8b93cec610174879d36d58",
      "tree": "4179bdb042aa497dd2fb3c7d0cddc88e244e5237",
      "parents": [
        "fda73056f62d84376a3d29926708b4a08155da31",
        "a995dd1c29426a074364170359a026f68e8426db"
      ],
      "author": {
        "name": "Ethan Chen",
        "email": "intervigil@gmail.com",
        "time": "Tue Jan 14 21:51:43 2014 -0800"
      },
      "committer": {
        "name": "Ethan Chen",
        "email": "intervigil@gmail.com",
        "time": "Tue Jan 14 21:51:43 2014 -0800"
      },
      "message": "Merge remote-tracking branch \u0027codeaurora/kk_2.7_rb1.21\u0027 into cm-11.0\n\nConflicts:\n\tdrivers/media/video/msm/msm_vfe32.h\n\tdrivers/media/video/msm/vfe/msm_vfe32.c\n\tnet/wireless/reg.c\n\nChange-Id: I073c609cfa1c461249bf728b28249bcaa1eaa211\n"
    },
    {
      "commit": "de0f9a5a9d7932086e623560d66655cc8507cfec",
      "tree": "d9e4678d68da38d7670b79c8b5e8782445c5ad7e",
      "parents": [
        "e1a3c5a3706d580390c02c69cb14dcd679d31d91",
        "84dfcb758ba7cce52ef475ac96861a558e1a20ca"
      ],
      "author": {
        "name": "Ethan Chen",
        "email": "intervigil@gmail.com",
        "time": "Sat Dec 21 14:22:41 2013 -0800"
      },
      "committer": {
        "name": "Ethan Chen",
        "email": "intervigil@gmail.com",
        "time": "Sat Dec 21 14:22:41 2013 -0800"
      },
      "message": "Merge tag \u0027v3.4.75\u0027 into cm-11.0\n\nThis is the 3.4.75 stable release\n\nConflicts:\n\tdrivers/md/dm-crypt.c\n\tdrivers/mmc/card/block.c\n\tdrivers/net/ethernet/smsc/smc91x.h\n\nChange-Id: I39f38ef5530c5fef07583beb9d76b983e71b9ff3\n"
    },
    {
      "commit": "f0c7091c82594bc42bb5af99dae4f18e1dae6d46",
      "tree": "6e20dde649190f77969c15aedf8eb4bc4e40cae2",
      "parents": [
        "09b3d7972025ff9e654b8cce3453b5d9f205cbf8"
      ],
      "author": {
        "name": "Mihir Shete",
        "email": "smihir@codeaurora.org",
        "time": "Mon Oct 14 00:54:40 2013 +0530"
      },
      "committer": {
        "name": "Gerrit - the friendly Code Review server",
        "email": "code-review@localhost",
        "time": "Fri Dec 13 03:57:02 2013 -0800"
      },
      "message": "cfg80211: export regulatory_hint_user() API\n\nThis is to help the hardware configured in world\nroaming mode to save power when not connected to\nany AP.\n\nCRs-Fixed: 542802\nChange-Id: Ia643d0e9848dcd486832973bd6dd186edd7bd4ea\nSigned-off-by: Mihir Shete \u003csmihir@codeaurora.org\u003e\n"
    },
    {
      "commit": "2a38ada0f1ab9f894eea4428731ebc811b51c3f3",
      "tree": "759c765808a23a3a35e4ba10d8306c847c0205b7",
      "parents": [
        "19218e895cefdd389c96af12c93c89e7276bbaad",
        "44d19f5a04ae4e433548ba2f25e4d2ccfcac765e"
      ],
      "author": {
        "name": "Ethan Chen",
        "email": "intervigil@gmail.com",
        "time": "Sun Dec 08 12:50:38 2013 -0800"
      },
      "committer": {
        "name": "Ethan Chen",
        "email": "intervigil@gmail.com",
        "time": "Sun Dec 08 12:50:38 2013 -0800"
      },
      "message": "Merge tag \u0027v3.4.72\u0027 into tmp\n\nThis is the 3.4.72 stable release\n\nConflicts:\n\tarch/arm/Kconfig\n\tarch/arm/include/asm/mutex.h\n\tarch/arm/kernel/perf_event.c\n\tarch/arm/kernel/traps.c\n\tarch/arm/mm/dma-mapping.c\n\tdrivers/base/power/main.c\n\tdrivers/bluetooth/ath3k.c\n\tdrivers/bluetooth/btusb.c\n\tdrivers/gpu/drm/radeon/radeon_mode.h\n\tdrivers/mmc/card/block.c\n\tdrivers/mmc/host/sdhci.c\n\tdrivers/usb/core/message.c\n\tdrivers/usb/host/xhci-plat.c\n\tdrivers/usb/host/xhci.h\n\tdrivers/virtio/virtio_ring.c\n\tfs/ubifs/dir.c\n\tinclude/linux/freezer.h\n\tinclude/linux/virtio.h\n\tinclude/media/v4l2-ctrls.h\n\tinclude/net/bluetooth/hci_core.h\n\tinclude/net/bluetooth/mgmt.h\n\tkernel/cgroup.c\n\tkernel/futex.c\n\tkernel/signal.c\n\tnet/bluetooth/hci_conn.c\n\tnet/bluetooth/hci_core.c\n\tnet/bluetooth/hci_event.c\n\tnet/bluetooth/l2cap_core.c\n\tnet/bluetooth/mgmt.c\n\tnet/bluetooth/rfcomm/sock.c\n\tnet/bluetooth/smp.c\n\nChange-Id: I4fb0d5de74ca76f933d95d98e1a9c2c859402f34\n"
    },
    {
      "commit": "ad25b5df02bacf27efb56fe12bb8da8dd9273546",
      "tree": "46b4c357415225acf77d155d659a729c307fdee0",
      "parents": [
        "ea9d7dc958579b07bf5cc419c4db932689a1224d"
      ],
      "author": {
        "name": "Hannes Frederic Sowa",
        "email": "hannes@stressinduktion.org",
        "time": "Sat Nov 23 00:46:12 2013 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Sun Dec 08 07:29:42 2013 -0800"
      },
      "message": "inet: fix addr_len/msg-\u003emsg_namelen assignment in recv_error and rxpmtu functions\n\n[ Upstream commit 85fbaa75037d0b6b786ff18658ddf0b4014ce2a4 ]\n\nCommit bceaa90240b6019ed73b49965eac7d167610be69 (\"inet: prevent leakage\nof uninitialized memory to user in recv syscalls\") conditionally updated\naddr_len if the msg_name is written to. The recv_error and rxpmtu\nfunctions relied on the recvmsg functions to set up addr_len before.\n\nAs this does not happen any more we have to pass addr_len to those\nfunctions as well and set it to the size of the corresponding sockaddr\nlength.\n\nThis broke traceroute and such.\n\nFixes: bceaa90240b6 (\"inet: prevent leakage of uninitialized memory to user in recv syscalls\")\nReported-by: Brad Spengler \u003cspender@grsecurity.net\u003e\nReported-by: Tom Labanowski\nCc: mpb \u003cmpb.mail@gmail.com\u003e\nCc: David S. Miller \u003cdavem@davemloft.net\u003e\nCc: Eric Dumazet \u003ceric.dumazet@gmail.com\u003e\nSigned-off-by: Hannes Frederic Sowa \u003channes@stressinduktion.org\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "c5812972d6d39b23ceb2a74d89c6a2d1cd140c56",
      "tree": "e4195c36259c17ddc4907dcdf97268a44ae7c770",
      "parents": [
        "ca3763f7ebb644e0e179ee2d84cd9402ad1e5d4f",
        "59a719e8389a77b7788b389af302f143dd74c9c7"
      ],
      "author": {
        "name": "Ethan Chen",
        "email": "intervigil@gmail.com",
        "time": "Thu Nov 21 17:20:24 2013 -0800"
      },
      "committer": {
        "name": "Ethan Chen",
        "email": "intervigil@gmail.com",
        "time": "Thu Nov 21 17:20:24 2013 -0800"
      },
      "message": "Merge remote-tracking branch \u0027codeaurora/kk_2.7_rb1.10\u0027 into HEAD\n\nConflicts:\n\tnet/wireless/reg.c\n\nChange-Id: I7e670492fddabd2218bb65a7e88a870c5e196909\n"
    },
    {
      "commit": "ee5fc1b5789d5bddd8034310d03d3bd1eafdbe3a",
      "tree": "face2e89ec4af36c5a6ba29ce2ac925dc8cd6669",
      "parents": [
        "fa0433af5d71ba85d96f904a173fa3c7e7269bbd"
      ],
      "author": {
        "name": "Mihir Shete",
        "email": "smihir@codeaurora.org",
        "time": "Sun Oct 13 05:25:30 2013 +0530"
      },
      "committer": {
        "name": "Gerrit - the friendly Code Review server",
        "email": "code-review@localhost",
        "time": "Tue Nov 12 07:06:02 2013 -0800"
      },
      "message": "cfg80211: add flags to define country IE processing rules\n\n802.11 cards may have different country IE parsing behavioural\npreferences and vendors may want to support these. These preferences\nwere managed by the WIPHY_FLAG_CUSTOM_REGULATORY and the\nWIPHY_FLAG_STRICT_REGULATORY flags and their combination.\nInstead of using this existing notation, split out the country IE\nbehavioural preferences to a new flag. This will allow us to add more\ncustomizations easily and make the code more maintainable. Also add\na new flag to disable country IE hints issued by the CORE as the\nfirst customization.\n\nChange-Id: I66ba4a92ac0f029a115eea0a274b02db11279787\nCRs-Fixed: 542802\nSigned-off-by: Mihir Shete \u003csmihir@codeaurora.org\u003e\n"
    },
    {
      "commit": "2b5f6d110ee835cba1742c999cabd30a54c10b76",
      "tree": "4e10f90603b71437153e18c38cd356b569fdb98c",
      "parents": [
        "4dde1cb060276e93a2ed22e4a167fc260a9d8c23"
      ],
      "author": {
        "name": "Seif Mazareeb",
        "email": "seif@marvell.com",
        "time": "Thu Oct 17 20:33:21 2013 -0700"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Mon Nov 04 04:23:41 2013 -0800"
      },
      "message": "net: fix cipso packet validation when !NETLABEL\n\n[ Upstream commit f2e5ddcc0d12f9c4c7b254358ad245c9dddce13b ]\n\nWhen CONFIG_NETLABEL is disabled, the cipso_v4_validate() function could loop\nforever in the main loop if opt[opt_iter +1] \u003d\u003d 0, this will causing a kernel\ncrash in an SMP system, since the CPU executing this function will\nstall /not respond to IPIs.\n\nThis problem can be reproduced by running the IP Stack Integrity Checker\n(http://isic.sourceforge.net) using the following command on a Linux machine\nconnected to DUT:\n\n\"icmpsic -s rand -d \u003cDUT IP address\u003e -r 123456\"\nwait (1-2 min)\n\nSigned-off-by: Seif Mazareeb \u003cseif@marvell.com\u003e\nAcked-by: Paul Moore \u003cpaul@paul-moore.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "3e5d72cd013a30bbd3a835243b635f0b85c4dd0a",
      "tree": "79b48fb112d98c9631a7e2a1ff1b5428fb1cf1db",
      "parents": [
        "225be57bbaf2c104f339b1a21efc25ff6b6bd9cb"
      ],
      "author": {
        "name": "Vlad Yasevich",
        "email": "vyasevich@gmail.com",
        "time": "Tue Oct 15 22:01:29 2013 -0400"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Mon Nov 04 04:23:41 2013 -0800"
      },
      "message": "net: dst: provide accessor function to dst-\u003exfrm\n\n[ Upstream commit e87b3998d795123b4139bc3f25490dd236f68212 ]\n\ndst-\u003exfrm is conditionally defined.  Provide accessor funtion that\nis always available.\n\nSigned-off-by: Vlad Yasevich \u003cvyasevich@gmail.com\u003e\nAcked-by: Neil Horman \u003cnhorman@tuxdriver.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "4c481c15615a3ff1cd28d2cfd687817704be63ad",
      "tree": "dc15be09c319156ed362f1c349bc1d052cfb7542",
      "parents": [
        "a8cefcec4999befc00b4be17985644b7a092dff1",
        "0841f631e5cecf7fb08f6ae6c89e47b79dca83cd"
      ],
      "author": {
        "name": "Ethan Chen",
        "email": "intervigil@gmail.com",
        "time": "Tue Oct 22 15:09:42 2013 -0700"
      },
      "committer": {
        "name": "Ethan Chen",
        "email": "intervigil@gmail.com",
        "time": "Tue Oct 22 15:09:42 2013 -0700"
      },
      "message": "Merge tag \u0027AU_LINUX_ANDROID_JB_2.6.04.03.00.109.082\u0027 into revert-linux\n\nAU_LINUX_ANDROID_JB_2.6.04.03.00.109.082 based on quic/aosp/jb_2.6\n\nConflicts:\n\tarch/arm/mach-msm/ipc_router.h\n\tarch/arm/mach-msm/ipc_socket.c\n\tdrivers/media/video/msm/actuators/msm_actuator.c\n\tdrivers/media/video/msm/csi/msm_csid.c\n\tdrivers/media/video/msm/vfe/msm_vfe32.c\n\tdrivers/video/msm/hdmi_msm.c\n\tinclude/media/msm_camera.h\n\nChange-Id: I9285b7519314f034fb8a6a4b7e2d21aa2e3e3739\n"
    },
    {
      "commit": "f72299da3e1a010a3d77fbed0b9ee6abd0a19911",
      "tree": "7ea60bcfbe30a8b48fe9e3a5d2af5c08d2f115a9",
      "parents": [
        "832ae42a43dd7ea2a39d7cc0687363d0039da850"
      ],
      "author": {
        "name": "Ansis Atteka",
        "email": "aatteka@nicira.com",
        "time": "Wed Sep 18 15:29:53 2013 -0700"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Sun Oct 13 15:42:48 2013 -0700"
      },
      "message": "ip: generate unique IP identificator if local fragmentation is allowed\n\n[ Upstream commit 703133de331a7a7df47f31fb9de51dc6f68a9de8 ]\n\nIf local fragmentation is allowed, then ip_select_ident() and\nip_select_ident_more() need to generate unique IDs to ensure\ncorrect defragmentation on the peer.\n\nFor example, if IPsec (tunnel mode) has to encrypt large skbs\nthat have local_df bit set, then all IP fragments that belonged\nto different ESP datagrams would have used the same identificator.\nIf one of these IP fragments would get lost or reordered, then\npeer could possibly stitch together wrong IP fragments that did\nnot belong to the same datagram. This would lead to a packet loss\nor data corruption.\n\nSigned-off-by: Ansis Atteka \u003caatteka@nicira.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "50b5f07287564a13d3ae28cfe243cca566407b53",
      "tree": "8c94e43b5da4ff1ecaa85d92d6b52f0bf1da9847",
      "parents": [
        "3b44f9ff1137befb8a907638d6383cf8b20c7413"
      ],
      "author": {
        "name": "Sameer Thalappil",
        "email": "sameert@codeaurora.org",
        "time": "Fri Jul 05 14:58:32 2013 -0700"
      },
      "committer": {
        "name": "Sameer Thalappil",
        "email": "sameert@codeaurora.org",
        "time": "Mon Sep 16 14:26:14 2013 -0700"
      },
      "message": "cfg80211: Add AP stopped interface\n\nAP stopped interface can be used to indicate that the AP mode has\nstopped functioning, WLAN driver may have encountered errors that has\nforced the driver to stop the AP mode.\n\nWhen the driver is in P2P-Go mode, and when it goes thru automatic\nrecovery from firmware crashes, it uses this interface to notify the\nuserspace that the group has been deleted.\n\nCRs-Fixed: 453060\nChange-Id: Ifcd8d4f0c0b26f56a56fb8560aa474297b7521d4\nSigned-off-by: Sameer Thalappil \u003csameert@codeaurora.org\u003e\n"
    },
    {
      "commit": "eeddd9177a67b743868e09742d58f574b2b9a497",
      "tree": "6f78ff2f6a6cc08cf59d4ceeece5e9601f4e135e",
      "parents": [
        "589acc586e0f12e0c46bc98e79ff2a008e8c6c11"
      ],
      "author": {
        "name": "Hannes Frederic Sowa",
        "email": "hannes@stressinduktion.org",
        "time": "Mon Jul 01 20:21:30 2013 +0200"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Sun Jul 28 16:26:02 2013 -0700"
      },
      "message": "ipv6: call udp_push_pending_frames when uncorking a socket with AF_INET pending data\n\n[ Upstream commit 8822b64a0fa64a5dd1dfcf837c5b0be83f8c05d1 ]\n\nWe accidentally call down to ip6_push_pending_frames when uncorking\npending AF_INET data on a ipv6 socket. This results in the following\nsplat (from Dave Jones):\n\nskbuff: skb_under_panic: text:ffffffff816765f6 len:48 put:40 head:ffff88013deb6df0 data:ffff88013deb6dec tail:0x2c end:0xc0 dev:\u003cNULL\u003e\n------------[ cut here ]------------\nkernel BUG at net/core/skbuff.c:126!\ninvalid opcode: 0000 [#1] PREEMPT SMP DEBUG_PAGEALLOC\nModules linked in: dccp_ipv4 dccp 8021q garp bridge stp dlci mpoa snd_seq_dummy sctp fuse hidp tun bnep nfnetlink scsi_transport_iscsi rfcomm can_raw can_bcm af_802154 appletalk caif_socket can caif ipt_ULOG x25 rose af_key pppoe pppox ipx phonet irda llc2 ppp_generic slhc p8023 psnap p8022 llc crc_ccitt atm bluetooth\n+netrom ax25 nfc rfkill rds af_rxrpc coretemp hwmon kvm_intel kvm crc32c_intel snd_hda_codec_realtek ghash_clmulni_intel microcode pcspkr snd_hda_codec_hdmi snd_hda_intel snd_hda_codec snd_hwdep usb_debug snd_seq snd_seq_device snd_pcm e1000e snd_page_alloc snd_timer ptp snd pps_core soundcore xfs libcrc32c\nCPU: 2 PID: 8095 Comm: trinity-child2 Not tainted 3.10.0-rc7+ #37\ntask: ffff8801f52c2520 ti: ffff8801e6430000 task.ti: ffff8801e6430000\nRIP: 0010:[\u003cffffffff816e759c\u003e]  [\u003cffffffff816e759c\u003e] skb_panic+0x63/0x65\nRSP: 0018:ffff8801e6431de8  EFLAGS: 00010282\nRAX: 0000000000000086 RBX: ffff8802353d3cc0 RCX: 0000000000000006\nRDX: 0000000000003b90 RSI: ffff8801f52c2ca0 RDI: ffff8801f52c2520\nRBP: ffff8801e6431e08 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000001 R11: 0000000000000001 R12: ffff88022ea0c800\nR13: ffff88022ea0cdf8 R14: ffff8802353ecb40 R15: ffffffff81cc7800\nFS:  00007f5720a10740(0000) GS:ffff880244c00000(0000) knlGS:0000000000000000\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000005862000 CR3: 000000022843c000 CR4: 00000000001407e0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000600\nStack:\n ffff88013deb6dec 000000000000002c 00000000000000c0 ffffffff81a3f6e4\n ffff8801e6431e18 ffffffff8159a9aa ffff8801e6431e90 ffffffff816765f6\n ffffffff810b756b 0000000700000002 ffff8801e6431e40 0000fea9292aa8c0\nCall Trace:\n [\u003cffffffff8159a9aa\u003e] skb_push+0x3a/0x40\n [\u003cffffffff816765f6\u003e] ip6_push_pending_frames+0x1f6/0x4d0\n [\u003cffffffff810b756b\u003e] ? mark_held_locks+0xbb/0x140\n [\u003cffffffff81694919\u003e] udp_v6_push_pending_frames+0x2b9/0x3d0\n [\u003cffffffff81694660\u003e] ? udplite_getfrag+0x20/0x20\n [\u003cffffffff8162092a\u003e] udp_lib_setsockopt+0x1aa/0x1f0\n [\u003cffffffff811cc5e7\u003e] ? fget_light+0x387/0x4f0\n [\u003cffffffff816958a4\u003e] udpv6_setsockopt+0x34/0x40\n [\u003cffffffff815949f4\u003e] sock_common_setsockopt+0x14/0x20\n [\u003cffffffff81593c31\u003e] SyS_setsockopt+0x71/0xd0\n [\u003cffffffff816f5d54\u003e] tracesys+0xdd/0xe2\nCode: 00 00 48 89 44 24 10 8b 87 d8 00 00 00 48 89 44 24 08 48 8b 87 e8 00 00 00 48 c7 c7 c0 04 aa 81 48 89 04 24 31 c0 e8 e1 7e ff ff \u003c0f\u003e 0b 55 48 89 e5 0f 0b 55 48 89 e5 0f 0b 55 48 89 e5 0f 0b 55\nRIP  [\u003cffffffff816e759c\u003e] skb_panic+0x63/0x65\n RSP \u003cffff8801e6431de8\u003e\n\nThis patch adds a check if the pending data is of address family AF_INET\nand directly calls udp_push_ending_frames from udp_v6_push_pending_frames\nif that is the case.\n\nThis bug was found by Dave Jones with trinity.\n\n(Also move the initialization of fl6 below the AF_INET check, even if\nnot strictly necessary.)\n\nSigned-off-by: Hannes Frederic Sowa \u003channes@stressinduktion.org\u003e\nCc: Dave Jones \u003cdavej@redhat.com\u003e\nCc: YOSHIFUJI Hideaki \u003cyoshfuji@linux-ipv6.org\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "3ef208a71f18b128e318294af3f7ee8081fe0ac1",
      "tree": "7c6094a3e8003f9532b6e935121bb36a3dc98a2f",
      "parents": [
        "d11ff32e52d86dfc6d3f100653ad88b83b6ead0e"
      ],
      "author": {
        "name": "Amerigo Wang",
        "email": "amwang@redhat.com",
        "time": "Sat Jun 29 21:30:49 2013 +0800"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Sun Jul 28 16:26:02 2013 -0700"
      },
      "message": "ipv6,mcast: always hold idev-\u003elock before mca_lock\n\n[ Upstream commit 8965779d2c0e6ab246c82a405236b1fb2adae6b2, with\n  some bits from commit b7b1bfce0bb68bd8f6e62a28295922785cc63781\n  (\"ipv6: split duplicate address detection and router solicitation timer\")\n  to get the __ipv6_get_lladdr() used by this patch. ]\n\ndingtianhong reported the following deadlock detected by lockdep:\n\n \u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n [ INFO: possible circular locking dependency detected ]\n 3.4.24.05-0.1-default #1 Not tainted\n -------------------------------------------------------\n ksoftirqd/0/3 is trying to acquire lock:\n  (\u0026ndev-\u003elock){+.+...}, at: [\u003cffffffff8147f804\u003e] ipv6_get_lladdr+0x74/0x120\n\n but task is already holding lock:\n  (\u0026mc-\u003emca_lock){+.+...}, at: [\u003cffffffff8149d130\u003e] mld_send_report+0x40/0x150\n\n which lock already depends on the new lock.\n\n the existing dependency chain (in reverse order) is:\n\n -\u003e #1 (\u0026mc-\u003emca_lock){+.+...}:\n        [\u003cffffffff810a8027\u003e] validate_chain+0x637/0x730\n        [\u003cffffffff810a8417\u003e] __lock_acquire+0x2f7/0x500\n        [\u003cffffffff810a8734\u003e] lock_acquire+0x114/0x150\n        [\u003cffffffff814f691a\u003e] rt_spin_lock+0x4a/0x60\n        [\u003cffffffff8149e4bb\u003e] igmp6_group_added+0x3b/0x120\n        [\u003cffffffff8149e5d8\u003e] ipv6_mc_up+0x38/0x60\n        [\u003cffffffff81480a4d\u003e] ipv6_find_idev+0x3d/0x80\n        [\u003cffffffff81483175\u003e] addrconf_notify+0x3d5/0x4b0\n        [\u003cffffffff814fae3f\u003e] notifier_call_chain+0x3f/0x80\n        [\u003cffffffff81073471\u003e] raw_notifier_call_chain+0x11/0x20\n        [\u003cffffffff813d8722\u003e] call_netdevice_notifiers+0x32/0x60\n        [\u003cffffffff813d92d4\u003e] __dev_notify_flags+0x34/0x80\n        [\u003cffffffff813d9360\u003e] dev_change_flags+0x40/0x70\n        [\u003cffffffff813ea627\u003e] do_setlink+0x237/0x8a0\n        [\u003cffffffff813ebb6c\u003e] rtnl_newlink+0x3ec/0x600\n        [\u003cffffffff813eb4d0\u003e] rtnetlink_rcv_msg+0x160/0x310\n        [\u003cffffffff814040b9\u003e] netlink_rcv_skb+0x89/0xb0\n        [\u003cffffffff813eb357\u003e] rtnetlink_rcv+0x27/0x40\n        [\u003cffffffff81403e20\u003e] netlink_unicast+0x140/0x180\n        [\u003cffffffff81404a9e\u003e] netlink_sendmsg+0x33e/0x380\n        [\u003cffffffff813c4252\u003e] sock_sendmsg+0x112/0x130\n        [\u003cffffffff813c537e\u003e] __sys_sendmsg+0x44e/0x460\n        [\u003cffffffff813c5544\u003e] sys_sendmsg+0x44/0x70\n        [\u003cffffffff814feab9\u003e] system_call_fastpath+0x16/0x1b\n\n -\u003e #0 (\u0026ndev-\u003elock){+.+...}:\n        [\u003cffffffff810a798e\u003e] check_prev_add+0x3de/0x440\n        [\u003cffffffff810a8027\u003e] validate_chain+0x637/0x730\n        [\u003cffffffff810a8417\u003e] __lock_acquire+0x2f7/0x500\n        [\u003cffffffff810a8734\u003e] lock_acquire+0x114/0x150\n        [\u003cffffffff814f6c82\u003e] rt_read_lock+0x42/0x60\n        [\u003cffffffff8147f804\u003e] ipv6_get_lladdr+0x74/0x120\n        [\u003cffffffff8149b036\u003e] mld_newpack+0xb6/0x160\n        [\u003cffffffff8149b18b\u003e] add_grhead+0xab/0xc0\n        [\u003cffffffff8149d03b\u003e] add_grec+0x3ab/0x460\n        [\u003cffffffff8149d14a\u003e] mld_send_report+0x5a/0x150\n        [\u003cffffffff8149f99e\u003e] igmp6_timer_handler+0x4e/0xb0\n        [\u003cffffffff8105705a\u003e] call_timer_fn+0xca/0x1d0\n        [\u003cffffffff81057b9f\u003e] run_timer_softirq+0x1df/0x2e0\n        [\u003cffffffff8104e8c7\u003e] handle_pending_softirqs+0xf7/0x1f0\n        [\u003cffffffff8104ea3b\u003e] __do_softirq_common+0x7b/0xf0\n        [\u003cffffffff8104f07f\u003e] __thread_do_softirq+0x1af/0x210\n        [\u003cffffffff8104f1c1\u003e] run_ksoftirqd+0xe1/0x1f0\n        [\u003cffffffff8106c7de\u003e] kthread+0xae/0xc0\n        [\u003cffffffff814fff74\u003e] kernel_thread_helper+0x4/0x10\n\nactually we can just hold idev-\u003elock before taking pmc-\u003emca_lock,\nand avoid taking idev-\u003elock again when iterating idev-\u003eaddr_list,\nsince the upper callers of mld_newpack() already take\nread_lock_bh(\u0026idev-\u003elock).\n\nReported-by: dingtianhong \u003cdingtianhong@huawei.com\u003e\nCc: dingtianhong \u003cdingtianhong@huawei.com\u003e\nCc: Hideaki YOSHIFUJI \u003cyoshfuji@linux-ipv6.org\u003e\nCc: David S. Miller \u003cdavem@davemloft.net\u003e\nCc: Hannes Frederic Sowa \u003channes@stressinduktion.org\u003e\nTested-by: Ding Tianhong \u003cdingtianhong@huawei.com\u003e\nTested-by: Chen Weilong \u003cchenweilong@huawei.com\u003e\nSigned-off-by: Cong Wang \u003camwang@redhat.com\u003e\nAcked-by: Hannes Frederic Sowa \u003channes@stressinduktion.org\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "d9795bafda02819105f8e91a0fce6c657ae55779",
      "tree": "cfa6c413100ffb2d5570244053ededcd6f3e47bf",
      "parents": [
        "73a5d309beea98f65799b6c1b4f248ff4e723808",
        "e2b6ece3cddd1da43c67aa17f89bd1e436b2e9f0"
      ],
      "author": {
        "name": "Ethan Chen",
        "email": "intervigil@gmail.com",
        "time": "Mon Jul 22 10:56:03 2013 -0700"
      },
      "committer": {
        "name": "Ethan Chen",
        "email": "intervigil@gmail.com",
        "time": "Mon Jul 22 10:56:03 2013 -0700"
      },
      "message": "Merge tag \u0027AU_LINUX_ANDROID_JB_2.5.04.02.02.040.432\u0027 into cm-10.1\n\nAU_LINUX_ANDROID_JB_2.5.04.02.02.040.432 based on quic/aosp/jb_2.5\n\nConflicts:\n\tdrivers/media/video/msm/gemini/msm_gemini_hw.c\n\tdrivers/media/video/msm/gemini/msm_gemini_hw.h\n\tdrivers/media/video/msm/gemini/msm_gemini_sync.c\n\tdrivers/media/video/msm/jpeg_10/msm_jpeg_sync.c\n\tdrivers/media/video/msm/mercury/msm_mercury_sync.c\n\tdrivers/media/video/msm/msm.c\n\tdrivers/media/video/msm/msm.h\n\tdrivers/media/video/msm/msm_mctl.c\n\tdrivers/media/video/msm/msm_mctl_buf.c\n\tdrivers/media/video/msm/msm_vpe.c\n\tdrivers/media/video/msm/vfe/msm_vfe32.c\n\tdrivers/video/msm/hdmi_msm.c\n\nChange-Id: I57b6cff57599d10983cd3bff63a6f20e4d62655e\n"
    },
    {
      "commit": "cb4c2165ff339d67d27092615a5f0b961e735ae0",
      "tree": "1e61e3e907af70ab142f6813f14d0f6c35d37782",
      "parents": [
        "b6a01e111f335ab6cdc67ee63f89162eca2ec355"
      ],
      "author": {
        "name": "Hemant Gupta",
        "email": "hemantg@codeaurora.org",
        "time": "Sat Jun 08 19:07:57 2013 +0530"
      },
      "committer": {
        "name": "Sridhar Gujje",
        "email": "sgujje@codeaurora.org",
        "time": "Sun Jul 07 10:30:53 2013 +0530"
      },
      "message": "Bluetooth: hidp: Remove sysfs entry if hid connection is disconnected\n\nThis patch fixes the issue that sysfs entry for hid was not removed when\ndisconnection was initiated from remote end or if BT was reset. Sysfs\nentry prevented reconnection from HID device.\n\nCRs-Fixed: 468516, 473179\nChange-Id: I40bcd27450cd8f87180d33b66969dde4f08a34f3\nSigned-off-by: Hemant Gupta \u003chemantg@codeaurora.org\u003e\nSigned-off-by: Sridhar Gujje \u003csgujje@codeaurora.org\u003e\n"
    },
    {
      "commit": "aa888f493125b21930ba87ad26f0c1ad5be39a51",
      "tree": "89f9f67f2a1b4bfdc133612c04668c4bff914ca3",
      "parents": [
        "35f33d90b228cf1a1abc4aa96036815c9fbdbf39",
        "50ca37a286e73b7a897226b24978d8742c7728da"
      ],
      "author": {
        "name": "Linux Build Service Account",
        "email": "lnxbuild@localhost",
        "time": "Wed Jul 03 21:44:36 2013 -0700"
      },
      "committer": {
        "name": "Gerrit - the friendly Code Review server",
        "email": "code-review@localhost",
        "time": "Wed Jul 03 21:44:35 2013 -0700"
      },
      "message": "Merge \"cfg80211/nl80211: add API for MAC address ACLs\""
    },
    {
      "commit": "50ca37a286e73b7a897226b24978d8742c7728da",
      "tree": "d2f5c123361d77ada295df397dd7e50933b5e993",
      "parents": [
        "c772e69b7f97e15c5cc5c7cd0a798a44ecb3f6af"
      ],
      "author": {
        "name": "Vasanthakumar Thiagarajan",
        "email": "vthiagar@qca.qualcomm.com",
        "time": "Wed Jul 03 14:16:36 2013 +0530"
      },
      "committer": {
        "name": "Sunil Dutt",
        "email": "duttus@codeaurora.org",
        "time": "Wed Jul 03 16:21:16 2013 +0530"
      },
      "message": "cfg80211/nl80211: add API for MAC address ACLs\n\nAdd API to enable drivers to implement MAC address based\naccess control in AP/P2P GO mode. Capable drivers advertise\ncfg80211/nl80211: add API for MAC address ACLs\n\nAdd API to enable drivers to implement MAC address based\naccess control in AP/P2P GO mode. Capable drivers advertise\nthis capability by setting the maximum number of MAC\naddresses in such a list in wiphy-\u003emax_acl_mac_addrs.\n\nAn initial ACL may be given to the NL80211_CMD_START_AP\ncommand and/or changed later with NL80211_CMD_SET_MAC_ACL.\n\nBlack- and whitelists are supported, but not simultaneously.\n\nSigned-off-by: Vasanthakumar Thiagarajan \u003cvthiagar@qca.qualcomm.com\u003e\n[rewrite commit log, many cleanups]\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nGit-commit: 77765eaf5cfb6b8dd98ec8b54b411d74ff6095f1\nGit-repo: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git\nCRs-fixed: 487410\nChange-Id: Ib739f5c317e1433827370f24ab04ef798eca0d53\n[duttus@codeaurora.org: resolved 3.4 backport issues]\nSigned-off-by: Sunil Dutt \u003cduttus@codeaurora.org\u003e\n"
    },
    {
      "commit": "0b6ad97dbce851f65ae4359392218d867fe39e3f",
      "tree": "b5cc089dc635243322870bf69b7cc0494f0c4c42",
      "parents": [
        "5bd77dd603c814d015538dbfdbbb3c3b97d4fd01"
      ],
      "author": {
        "name": "Hemant Gupta",
        "email": "hemantg@codeaurora.org",
        "time": "Sat Jun 08 19:07:57 2013 +0530"
      },
      "committer": {
        "name": "Hemant Gupta",
        "email": "hemantg@codeaurora.org",
        "time": "Tue Jul 02 12:55:44 2013 +0530"
      },
      "message": "Bluetooth: hidp: Remove sysfs entry if hid connection is disconnected\n\nThis patch fixes the issue that sysfs entry for hid was not removed when\ndisconnection was initiated from remote end or if BT was reset. Sysfs\nentry prevented reconnection from HID device.\n\nCRs-Fixed: 468516, 473179\nChange-Id: I40bcd27450cd8f87180d33b66969dde4f08a34f3\nSigned-off-by: Hemant Gupta \u003chemantg@codeaurora.org\u003e\n"
    }
  ],
  "next": "b3eb72f13a8f9146914ede4bbf36f7f4d0e58a32"
}
