This bug was fixed in the package linux - 3.19.0-22.22 --------------- linux (3.19.0-22.22) vivid; urgency=low
[ Brad Figg ] * Release Tracking Bug - LP: #1465755 [ Tai Nguyen ] * SAUCE: power: reset: Add syscon reboot device node for APM X-Gene platform - LP: #1463211 [ Upstream Kernel Changes ] * Revert "dm crypt: fix deadlock when async crypto algorithm returns -EBUSY" - LP: #1465696 * Bluetooth: ath3k: Add a new ID 0cf3:e006 to ath3k list - LP: #1459934 * cdc-acm: prevent infinite loop when parsing CDC headers. - LP: #1460657 * (upstream) libata: Blacklist queued TRIM on all Samsung 800-series - LP: #1338706, #1449005 * powerpc/powernv: Check image loaded or not before calling flash - LP: #1461553 * ahci: avoton port-disable reset-quirk - LP: #1458617 * Bluetooth: btusb: support public address configuration for ath3012 - LP: #1459937 * Bluetooth: btusb: Add setup callback for chip init on USB - LP: #1459937 * Bluetooth: btusb: Add support for QCA ROME chipset family - LP: #1459937 * Bluetooth: btusb: Fix incorrect type in qca_device_info - LP: #1459937 * Bluetooth: btusb: Fix minor whitespace issue in QCA ROME device entries - LP: #1459937 * Bluetooth: btusb: Add support for 0cf3:e007 - LP: #1459937 * storvsc: Set the SRB flags correctly when no data transfer is needed - LP: #1439780 * vfs: read file_handle only once in handle_to_path - LP: #1416503 - CVE-2015-1420 * ozwpan: Use unsigned ints to prevent heap overflow - LP: #1463442 - CVE-2015-4001 * ozwpan: divide-by-zero leading to panic - LP: #1463445 - CVE-2015-4003 * ozwpan: Use proper check to prevent heap overflow - LP: #1463444 - CVE-2015-4002 * ozwpan: unchecked signed subtraction leads to DoS - LP: #1463444 - CVE-2015-4002 * enclosure: fix WARN_ON removing an adapter in multi-path devices - LP: #1415178 * ASoC: tfa9879: Fix return value check in tfa9879_i2c_probe() - LP: #1465696 * ASoC: samsung: s3c24xx-i2s: Fix return value check in s3c24xx_iis_dev_probe() - LP: #1465696 * ASoC: dapm: Enable autodisable on SOC_DAPM_SINGLE_TLV_AUTODISABLE - LP: #1465696 * ASoC: rt5677: add register patch for PLL - LP: #1465696 * btrfs: unlock i_mutex after attempting to delete subvolume during send - LP: #1465696 * ALSA: hda - Fix mute-LED fixed mode - LP: #1465696 * ALSA: hda - Add mute-LED mode control to Thinkpad - LP: #1465696 * arm64: dma-mapping: always clear allocated buffers - LP: #1465696 * ALSA: emu10k1: Fix card shortname string buffer overflow - LP: #1465696 * ALSA: emux: Fix mutex deadlock at unloading - LP: #1465696 * drm/radeon: Use drm_calloc_ab for CS relocs - LP: #1465696 * drm/radeon: adjust pll when audio is not enabled - LP: #1465696 * drm/radeon: add SI DPM quirk for Sapphire R9 270 Dual-X 2G GDDR5 - LP: #1465696 * drm/radeon: fix lockup when BOs aren't part of the VM on release - LP: #1465696 * drm/radeon: reset BOs address after clearing it. - LP: #1465696 * drm/radeon: check new address before removing old one - LP: #1465696 * SCSI: add 1024 max sectors black list flag - LP: #1465696 * 3w-sas: fix command completion race - LP: #1465696 * 3w-xxxx: fix command completion race - LP: #1465696 * 3w-9xxx: fix command completion race - LP: #1465696 * uas: Allow uas_use_uas_driver to return usb-storage flags - LP: #1465696 * uas: Add US_FL_MAX_SECTORS_240 flag - LP: #1465696 * uas: Set max_sectors_240 quirk for ASM1053 devices - LP: #1465696 * usb: chipidea: otg: remove mutex unlock and lock while stop and start role - LP: #1465696 * serial: xilinx: Use platform_get_irq to get irq description structure - LP: #1465696 * serial: of-serial: Remove device_type = "serial" registration - LP: #1465696 * tty/serial: at91: maxburst was missing for dma transfers - LP: #1465696 * ALSA: emux: Fix mutex deadlock in OSS emulation - LP: #1465696 * ACPI / SBS: Enable battery manager when present - LP: #1465696 * ALSA: emu10k1: Emu10k2 32 bit DMA mode - LP: #1465696 * ASoC: rt5677: fixed wrong DMIC ref clock - LP: #1465696 * rbd: end I/O the entire obj_request on error - LP: #1465696 * ext4: fix data corruption caused by unwritten and delayed extents - LP: #1465696 * ext4: move check under lock scope to close a race. - LP: #1465696 * powerpc/pseries: Correct cpu affinity for dlpar added cpus - LP: #1465696 * powerpc/powernv: Restore non-volatile CRs after nap - LP: #1465696 * efivarfs: Ensure VariableName is NUL-terminated - LP: #1465696 * x86/efi: Store upper bits of command line buffer address in ext_cmd_line_ptr - LP: #1465696 * blk-mq: fix race between timeout and CPU hotplug - LP: #1465696 * blk-mq: fix CPU hotplug handling - LP: #1465696 * writeback: use |1 instead of +1 to protect against div by zero - LP: #1465696 * ARM: mvebu: armada-xp-openblocks-ax3-4: Disable internal RTC - LP: #1465696 * ARM: dts: imx23-olinuxino: Fix polarity of LED GPIO - LP: #1465696 * ARM: dts: imx23-olinuxino: Fix dr_mode of usb0 - LP: #1465696 * ARM: dts: imx6: phyFLEX: USB VBUS control is active-high - LP: #1465696 * ARM: dts: imx25: Add #pwm-cells to pwm4 - LP: #1465696 * ARM: dts: imx28: Fix AUART4 TX-DMA interrupt name - LP: #1465696 * marvell-ccic: fix Y'CbCr ordering - LP: #1465696 * gpio: sysfs: fix memory leaks and device hotplug - LP: #1465696 * ACPI / SBS: Add 5 us delay to fix SBS hangs on MacBook - LP: #1465696 * ACPI / PNP: add two IDs to list for PNPACPI device enumeration - LP: #1465696 * ARM: OMAP2+: Fix omap off idle power consumption creeping up - LP: #1465696 * ARM: dts: OMAP3-N900: Add microphone bias voltages - LP: #1465696 * drm/radeon: disable semaphores for UVD V1 (v2) - LP: #1465696 * x86/spinlocks: Fix regression in spinlock contention detection - LP: #1465696 * RDMA/CMA: Canonize IPv4 on IPV6 sockets properly - LP: #1465696 * drm/i915: Assume dual channel LVDS if pixel clock necessitates it - LP: #1465696 * drm/i915: Add missing MacBook Pro models with dual channel LVDS - LP: #1465696 * efi: Fix error handling in add_sysfs_runtime_map_entry() - LP: #1465696 * xen/events: Clear cpu_evtchn_mask before resuming - LP: #1465696 * xen/xenbus: Update xenbus event channel on resume - LP: #1465696 * xen/console: Update console event channel on resume - LP: #1465696 * xen/events: Set irq_info->evtchn before binding the channel to CPU in __startup_pirq() - LP: #1465696 * mm/memory-failure: call shake_page() when error hits thp tail page - LP: #1465696 * mm: soft-offline: fix num_poisoned_pages counting on concurrent events - LP: #1465696 * nilfs2: fix sanity check of btree level in nilfs_btree_root_broken() - LP: #1465696 * ocfs2: dlm: fix race between purge and get lock resource - LP: #1465696 * drm/i915/dp: there is no audio on port A - LP: #1465696 * drm/amdkfd: allow unregister process with queues - LP: #1465696 * drm/radeon: fix userptr BO unpin bug v3 - LP: #1465696 * drm/radeon: make VCE handle check more strict - LP: #1465696 * drm/radeon: make UVD handle checking more strict - LP: #1465696 * drm/radeon: more strictly validate the UVD codec - LP: #1465696 * path_openat(): fix double fput() - LP: #1465696 * mnt: Fix fs_fully_visible to verify the root directory is visible - LP: #1465696 * drm: Zero out invalid vblank timestamp in drm_update_vblank_count. - LP: #1465696 * ARM: ux500: Move GPIO regulator for SD-card into board DTSs - LP: #1465696 * ARM: ux500: Enable GPIO regulator for SD-card for HREF boards - LP: #1465696 * ARM: ux500: Enable GPIO regulator for SD-card for snowball - LP: #1465696 * xen-pciback: Add name prefix to global 'permissive' variable - LP: #1465696 * mmc: core: add missing pm event in mmc_pm_notify to fix hib restore - LP: #1465696 * ARM: dts: am57xx-beagle-x15: Fix IRQ type for mcp7941x - LP: #1465696 * mmc: sh_mmcif: Fix timeout value for command request - LP: #1465696 * pinctrl: Don't just pretend to protect pinctrl_maps, do it for real - LP: #1465696 * arm64: add missing PAGE_ALIGN() to __dma_free() - LP: #1465696 * Linux 3.19.8-ckt1 - LP: #1465696 -- Brad Figg <brad.f...@canonical.com> Tue, 16 Jun 2015 09:21:59 -0700 ** Changed in: linux (Ubuntu) Status: In Progress => Fix Released ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2015-1420 ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2015-4001 ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2015-4002 ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2015-4003 -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1415178 Title: Kernel trace message when the ipr driver is rmmod from Ubuntu 14.10 guest (GTO - PCI Passthrough) Status in linux package in Ubuntu: Fix Released Status in linux source package in Vivid: Fix Committed Bug description: SRU Justification: [Impact] Removing the ipr driver causes kernel warnings. [Fix] commit 11e52a699afff576606ceb6cf697270459f1a4aa upstream $ git describe --contains 11e52a699afff576606ceb6cf697270459f1a4aa v4.0~8^2~2 [Test Case] See Steps to Reproduce below. -- pKVM version: [root@yangtze-lp1 ~]# cat /etc/issue IBM_PowerKVM release 2.1.1 build 10 alpha (pkvm2_1_1) Kernel \r on a \m (\l) Ubuntu version: root@ubuntushinner:~# uname -a Linux ubuntushinner 3.16.0-14-generic #20-Ubuntu SMP Sat Sep 6 23:45:12 UTC 2014 ppc64le ppc64le ppc64le GNU/Linux steps to reproduce: 1. rmmod the ipr driver and kernel traces are seen on the syslog. root@ubuntushinner:~# lsmod Module Size Used by pseries_rng 2849 0 ses 9046 0 enclosure 11198 1 ses rtc_generic 2249 0 ipr 140038 0 ohci_pci 6794 0 root@ubuntushinner:~# uname -a Linux ubuntushinner 3.16.0-14-generic #20-Ubuntu SMP Sat Sep 6 23:45:12 UTC 2014 ppc64le ppc64le ppc64le GNU/Linux root@ubuntushinner:~# rmmod ipr root@ubuntushinner:~# lsscsi [0:0:0:0] disk QEMU QEMU HARDDISK 2.0. /dev/sda [0:0:0:1] cd/dvd QEMU QEMU CD-ROM 2.0. /dev/sr0 syslog: Sep 9 02:57:57 ubuntushinner kernel: [ 576.546878] kernfs: can not remove 'device', no directory Sep 9 02:57:57 ubuntushinner kernel: [ 576.546903] ------------[ cut here ]------------ Sep 9 02:57:57 ubuntushinner kernel: [ 576.546906] WARNING: at /build/buildd/linux-3.16.0/fs/kernfs/dir.c:1220 Sep 9 02:57:57 ubuntushinner kernel: [ 576.546908] Modules linked in: pseries_rng ses enclosure rtc_generic ipr(-) ohci_pci Sep 9 02:57:57 ubuntushinner kernel: [ 576.546922] CPU: 1 PID: 3537 Comm: rmmod Not tainted 3.16.0-14-generic #20-Ubuntu Sep 9 02:57:57 ubuntushinner kernel: [ 576.546926] task: c0000003ebad6830 ti: c0000003e5da8000 task.ti: c0000003e5da8000 Sep 9 02:57:57 ubuntushinner kernel: [ 576.546928] NIP: c000000000350c34 LR: c000000000350c30 CTR: c000000000517a60 Sep 9 02:57:57 ubuntushinner kernel: [ 576.546931] REGS: c0000003e5dab380 TRAP: 0700 Not tainted (3.16.0-14-generic) Sep 9 02:57:57 ubuntushinner kernel: [ 576.546932] MSR: 8000000100029033 <SF,EE,ME,IR,DR,RI,LE> CR: 28088844 XER: 20000000 Sep 9 02:57:57 ubuntushinner kernel: [ 576.546942] CFAR: c0000000009fd270 SOFTE: 1 Sep 9 02:57:57 ubuntushinner kernel: [ 576.546942] GPR00: c000000000350c30 c0000003e5dab600 c0000000013d49e0 000000000000002d Sep 9 02:57:57 ubuntushinner kernel: [ 576.546942] GPR04: c000000001845db0 c000000001856618 0000000000000175 0000000000000175 Sep 9 02:57:57 ubuntushinner kernel: [ 576.546942] GPR08: c000000000e449e0 0000000000000000 0000000000000000 c000000000c41b80 Sep 9 02:57:57 ubuntushinner kernel: [ 576.546942] GPR12: 0000000000008800 c00000000fb80900 0000000000000000 00000100311e01f0 Sep 9 02:57:57 ubuntushinner kernel: [ 576.546942] GPR16: 0000000000000000 000000004c7133a0 000000004c713358 0000000000000000 Sep 9 02:57:57 ubuntushinner kernel: [ 576.546942] GPR20: 000000004c713380 000000004c7133b8 0000000000000000 000000004c713398 Sep 9 02:57:57 ubuntushinner kernel: [ 576.546942] GPR24: 0000000000000000 0000000000000001 00003fffe6f71750 c0000003e4e01d28 Sep 9 02:57:57 ubuntushinner kernel: [ 576.546942] GPR28: 0000000000000000 d000000005fe18e0 c0000003e4e01d18 0000000000000000 Sep 9 02:57:57 ubuntushinner kernel: [ 576.546980] NIP [c000000000350c34] kernfs_remove_by_name_ns+0xe4/0xf0 Sep 9 02:57:57 ubuntushinner kernel: [ 576.546984] LR [c000000000350c30] kernfs_remove_by_name_ns+0xe0/0xf0 Sep 9 02:57:57 ubuntushinner kernel: [ 576.546987] Call Trace: Sep 9 02:57:57 ubuntushinner kernel: [ 576.546990] [c0000003e5dab600] [c000000000350c30] kernfs_remove_by_name_ns+0xe0/0xf0 (unreliable) Sep 9 02:57:57 ubuntushinner kernel: [ 576.546995] [c0000003e5dab680] [c0000000003542c0] sysfs_remove_link+0x40/0x90 Sep 9 02:57:57 ubuntushinner kernel: [ 576.547001] [c0000003e5dab6c0] [d000000005fe0de0] enclosure_remove_links.part.2+0x80/0xb0 [enclosure] Sep 9 02:57:57 ubuntushinner kernel: [ 576.547005] [c0000003e5dab730] [d000000005fe0e54] enclosure_component_release+0x44/0x70 [enclosure] Sep 9 02:57:57 ubuntushinner kernel: [ 576.547012] [c0000003e5dab760] [c000000000639360] device_release+0x60/0xf0 Sep 9 02:57:57 ubuntushinner kernel: [ 576.547018] [c0000003e5dab7e0] [c00000000050b73c] kobject_release+0xdc/0x250 Sep 9 02:57:57 ubuntushinner kernel: [ 576.547022] [c0000003e5dab870] [c000000000639f3c] device_unregister+0x4c/0xb0 Sep 9 02:57:57 ubuntushinner kernel: [ 576.547025] [c0000003e5dab8e0] [d000000005fe0810] enclosure_unregister+0xb0/0x100 [enclosure] Sep 9 02:57:57 ubuntushinner kernel: [ 576.547029] [c0000003e5dab920] [d0000000060a0178] ses_intf_remove+0xb8/0x160 [ses] Sep 9 02:57:57 ubuntushinner kernel: [ 576.547032] [c0000003e5dab950] [c000000000639d84] device_del+0x104/0x270 Sep 9 02:57:57 ubuntushinner kernel: [ 576.547036] [c0000003e5dab990] [c000000000639f2c] device_unregister+0x3c/0xb0 Sep 9 02:57:57 ubuntushinner kernel: [ 576.547041] [c0000003e5daba00] [c0000000006bb8b4] __scsi_remove_device+0x124/0x150 Sep 9 02:57:57 ubuntushinner kernel: [ 576.547044] [c0000003e5daba30] [c0000000006b8834] scsi_forget_host+0xa4/0xb0 Sep 9 02:57:57 ubuntushinner kernel: [ 576.547048] [c0000003e5daba60] [c0000000006a88e4] scsi_remove_host+0xa4/0x1b0 Sep 9 02:57:57 ubuntushinner kernel: [ 576.547054] [c0000003e5dabaa0] [d000000003b74bd0] ipr_remove+0x80/0x100 [ipr] Sep 9 02:57:57 ubuntushinner kernel: [ 576.547058] [c0000003e5dabb20] [c000000000567bb0] pci_device_remove+0x70/0x110 Sep 9 02:57:57 ubuntushinner kernel: [ 576.547061] [c0000003e5dabb60] [c00000000063ff9c] __device_release_driver+0xac/0x130 Sep 9 02:57:57 ubuntushinner kernel: [ 576.547064] [c0000003e5dabb90] [c000000000640e08] driver_detach+0x148/0x190 Sep 9 02:57:57 ubuntushinner kernel: [ 576.547067] [c0000003e5dabbe0] [c00000000063fa28] bus_remove_driver+0x98/0x150 Sep 9 02:57:57 ubuntushinner kernel: [ 576.547070] [c0000003e5dabc50] [c000000000641aac] driver_unregister+0x4c/0x80 Sep 9 02:57:57 ubuntushinner kernel: [ 576.547074] [c0000003e5dabcc0] [c00000000056613c] pci_unregister_driver+0x4c/0x120 Sep 9 02:57:57 ubuntushinner kernel: [ 576.547078] [c0000003e5dabd10] [d000000003b7573c] ipr_exit+0x34/0x1f18 [ipr] Sep 9 02:57:57 ubuntushinner kernel: [ 576.547083] [c0000003e5dabd40] [c00000000015ddc8] SyS_delete_module+0x228/0x280 Sep 9 02:57:57 ubuntushinner kernel: [ 576.547087] [c0000003e5dabe30] [c00000000000a17c] syscall_exit+0x0/0x7c Sep 9 02:57:57 ubuntushinner kernel: [ 576.547089] Instruction dump: Sep 9 02:57:57 ubuntushinner kernel: [ 576.547090] e8010010 eb81ffe0 eba1ffe8 ebc1fff0 7c0803a6 ebe1fff8 4e800020 3c62ff89 Sep 9 02:57:57 ubuntushinner kernel: [ 576.547095] 7fa4eb78 38638f40 486ac5b9 60000000 <0fe00000> 3860fffe 4bffff94 3c4c0108 Sep 9 02:57:57 ubuntushinner kernel: [ 576.547101] ---[ end trace 4a44cd6dfffd2bb9 ]--- Guest xml: [root@yangtze-lp1 ~]# virsh dumpxml GManu_Ubuntu_14_10_GTO <domain type='kvm' id='11'> <name>GManu_Ubuntu_14_10_GTO</name> <uuid>22a274f5-e9bc-4189-b4bb-5cf7f848889e</uuid> <memory unit='KiB'>17532928</memory> <currentMemory unit='KiB'>17532672</currentMemory> <vcpu placement='static'>16</vcpu> <resource> <partition>/machine</partition> </resource> <os> <type arch='ppc64' machine='pseries'>hvm</type> <boot dev='hd'/> <boot dev='cdrom'/> <boot dev='network'/> <bootmenu enable='yes'/> </os> <features> <acpi/> <apic/> <pae/> </features> <clock offset='utc'/> <on_poweroff>destroy</on_poweroff> <on_reboot>restart</on_reboot> <on_crash>restart</on_crash> <devices> <emulator>/usr/bin/qemu-kvm</emulator> <disk type='file' device='disk'> <driver name='qemu' type='qcow2'/> <source file='/var/lib/libvirt/images/manu/Ubunut_14_10_shinner.qcow2'/> <backingStore/> <target dev='sda' bus='scsi'/> <alias name='scsi0-0-0-0'/> <address type='drive' controller='0' bus='0' target='0' unit='0'/> </disk> <disk type='file' device='cdrom'> <driver name='qemu' type='raw'/> <source file='/var/lib/libvirt/images/manu/utopic-server-ppc64el.iso'/> <backingStore/> <target dev='sdb' bus='scsi'/> <readonly/> <alias name='scsi0-0-0-1'/> <address type='drive' controller='0' bus='0' target='0' unit='1'/> </disk> <controller type='usb' index='0'> <alias name='usb0'/> <address type='pci' domain='0x0000' bus='0x00' slot='0x02' function='0x0'/> </controller> <controller type='pci' index='0' model='pci-root'> <alias name='pci.0'/> </controller> <controller type='scsi' index='0'> <alias name='scsi0'/> <address type='spapr-vio' reg='0x2000'/> </controller> <controller type='scsi' index='1'> <alias name='scsi1'/> <address type='spapr-vio' reg='0x3000'/> </controller> <interface type='bridge'> <mac address='52:54:00:d7:00:34'/> <source bridge='virbr0'/> <target dev='vnet1'/> <model type='virtio'/> <alias name='net0'/> <address type='pci' domain='0x0000' bus='0x00' slot='0x01' function='0x0'/> </interface> <serial type='pty'> <source path='/dev/pts/0'/> <target port='0'/> <alias name='serial0'/> <address type='spapr-vio' reg='0x30000000'/> </serial> <console type='pty' tty='/dev/pts/0'> <source path='/dev/pts/0'/> <target type='serial' port='0'/> <alias name='serial0'/> <address type='spapr-vio' reg='0x30000000'/> </console> <hostdev mode='subsystem' type='pci' managed='yes'> <driver name='vfio'/> <source> <address domain='0x0000' bus='0x01' slot='0x00' function='0x0'/> </source> <alias name='hostdev0'/> </hostdev> <memballoon model='virtio'> <alias name='balloon0'/> <address type='pci' domain='0x0000' bus='0x00' slot='0x05' function='0x0'/> </memballoon> </devices> <seclabel type='dynamic' model='selinux' relabel='yes'> <label>system_u:system_r:svirt_t:s0:c16,c940</label> <imagelabel>system_u:object_r:svirt_image_t:s0:c16,c940</imagelabel> </seclabel> </domain> We saw the similar issue when we tried to "rmmod ipr" with daul controllers configuration. Looks his guest only has one GTO adapter. Also I checked the latest kernel source code for drivers/misc/enclosure.c, it included the fix patch for dual controller case. static void enclosure_remove_links(struct enclosure_component *cdev) { char name[ENCLOSURE_NAME_SIZE]; /* * In odd circumstances, like multipath devices, something else may * already have removed the links, so check for this condition first. */ if (!cdev->dev->kobj.sd) -------------> fix patch for dual controllers return; enclosure_link_name(cdev, name); sysfs_remove_link(&cdev->dev->kobj, name); sysfs_remove_link(&cdev->cdev.kobj, "device"); } Thanks, Wendy I re-created the issue on another guest. Looks the following patch caused the issue. I need to re-build the kernel and do more debug. http://git.kernel.org/cgit/linux/kernel/git/jejb/scsi.git/commit/fs/sysfs/symlink.c?h =for-next&id=879f40d193bb3c6c13930e88e3e9d5d7baf84d19 Thanks, Wendy Here is the upstream link for the patch: http://marc.info/?l=linux-scsi&m=142145523316373&w=2 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1415178/+subscriptions -- Mailing list: https://launchpad.net/~kernel-packages Post to : kernel-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~kernel-packages More help : https://help.launchpad.net/ListHelp