Salvatore Bonaccorso
7b2acecada
macsec: avoid heap overflow in skb_to_sgvec (CVE-2017-7477)
2017-04-27 06:43:38 +02:00
Ben Hutchings
e7b761c5fd
[arm64] Add bug closure for raising NR_CPUS
2017-04-25 23:40:09 +01:00
Ben Hutchings
4e57833523
watchdog: Enable WATCHDOG_SYSFS
2017-04-25 23:16:40 +01:00
Ben Hutchings
2b2a89c35f
thermal: Explicitly disable GENERIC_ADC_THERMAL per default
2017-04-25 23:15:47 +01:00
Ben Hutchings
a1a96efe46
[x86] thermal: Enable INT3406_THERMAL as module
2017-04-25 23:13:32 +01:00
Ben Hutchings
cc56cd8593
gpio: Explicitly set various symbols to their defaults
2017-04-25 22:58:43 +01:00
Ben Hutchings
8ab44aa518
[x86] gpio: Enable GPIO_AMDPT as module
2017-04-25 22:57:34 +01:00
Ben Hutchings
f3a2da345c
spi: Explicitly set various symbols to their defaults
2017-04-25 22:56:53 +01:00
Ben Hutchings
9ad676b26c
char: Explicitly enable DEVPORT per default
2017-04-25 22:53:32 +01:00
Ben Hutchings
fd23df3a24
serial/8250: Enable SERIAL_8250_MOXA as module
2017-04-25 22:50:51 +01:00
Ben Hutchings
25cf1aa652
[x86] input/touchscreen: Enable TOUCHSCREEN_SURFACE3_SPI as module
2017-04-25 22:49:04 +01:00
Ben Hutchings
79226c42bf
input: Enable TABLET_USB_PEGASUS as module
2017-04-25 22:48:26 +01:00
Ben Hutchings
c9034d73b4
drivers/input: Explicitly set various symbols to their defaults
2017-04-25 22:46:57 +01:00
Ben Hutchings
e4f8eedb77
net/phy: Enable MICROSEMI_PHY as module
2017-04-25 22:42:23 +01:00
Ben Hutchings
9ee3fb1151
ethernet: Enable NFP_NETVF as module
2017-04-25 22:41:37 +01:00
Ben Hutchings
6a09142123
drivers/net: Explicitly set various symbols to their defaults
2017-04-25 22:37:52 +01:00
Ben Hutchings
94b8328125
net/sched: Enable NET_ACT_SKBMOD as module
2017-04-25 22:23:51 +01:00
Ben Hutchings
45a93062df
6lowpan: Enable Generic Header Compression modules
2017-04-25 22:22:50 +01:00
Ben Hutchings
f6ab826219
PCI: Enable PCIE_PTM (except on armel/marvell)
2017-04-25 22:20:09 +01:00
Salvatore Bonaccorso
fe7d4b95a0
Add changelog entry for CVE-2017-8061
...
Gbp-Dch: Ignore
2017-04-23 12:15:25 +02:00
Salvatore Bonaccorso
1beb630d78
Add changelog entry to record CVE-2017-8063
...
Gbp-Dch: Ignore
2017-04-23 12:09:00 +02:00
Salvatore Bonaccorso
dff836d7ec
Add CVE-2017-8064 reference
...
Gbp-Dch: Ignore
2017-04-23 12:02:37 +02:00
Salvatore Bonaccorso
1ad0a79c0a
Add changelog entry for CVE-2017-8067
...
Gbp-Dch: Ignore
2017-04-23 11:46:28 +02:00
Ben Hutchings
7bf90ad750
KEYS: fix keyctl_set_reqkey_keyring() to not leak thread keyrings (CVE-2017-7472)
2017-04-22 02:26:48 +01:00
Ben Hutchings
89402402c8
KEYS: Disallow keyrings beginning with '.' to be joined as session keyrings (CVE-2016-9604)
2017-04-22 02:25:04 +01:00
Ben Hutchings
74fdfed494
Drop ABI maintenance patches
...
We're bumping ABI in the next upload so don't need these.
2017-04-22 02:22:38 +01:00
Ben Hutchings
9c5f88b1f6
Update to 4.9.24
...
Drop most of our bug fix patches, which were included in it.
Adjust context in a couple of rt patches that have textual conflicts.
2017-04-22 00:59:32 +01:00
Aurelien Jarno
d518bcf5f3
[mips*el/loongson-3] Disable PAGE_EXTENSION and PAGE_POISONING.
...
This workaround a kernel crash, until the real issue is found. It is
currently being investigated.
2017-04-22 01:16:49 +02:00
Aurelien Jarno
f2b1e81469
[mips*/octeon] Drop obsolete patch adding support for the UBNT E200 board.
2017-04-21 11:31:33 +02:00
Ben Hutchings
3cd2ed795d
[arm64] Enable REGULATOR_GPIO as module ( Closes : #860222 )
2017-04-21 01:33:01 +01:00
Ben Hutchings
1e2342437a
[arm64] Enable ARC_SUNXI, RTC_DRV_SUN6I as built-in, MMC_SUNXI and PHY_SUN4I_USB as modules
...
Closes : #860855
2017-04-21 01:00:12 +01:00
Ben Hutchings
ce8bf477b0
Restore #include that I mistakenly removed from arm64 securelevel/lockdown patch
2017-04-21 00:54:11 +01:00
Ben Hutchings
0905519af4
Clean up kconfig using kconfigeditor2
...
Rename or delete options that changed in 4.11.
2017-04-20 19:45:06 +01:00
Ben Hutchings
259372e240
[x86] Make hyperv-modules depends on nic-shared-modules
...
hv_utils (not hv_netvsc!) now implements a PTP clock.
2017-04-20 19:24:09 +01:00
Ben Hutchings
0e0b29ad5a
[arm64,x86] Replace securelevel patch set with lockdown patch set
...
Matthew stopped maintaining the securelevel patch set, and David
Howells has taken it up under the new name 'lockdown'. This is
taken from:
https://git.kernel.org/pub/scm/linux/kernel/git/dhowells/linux-fs.git#efi-lock-down
commits ddb99e118e37f324a4be65a411bb60ae62795cf9..0240fa7c7c948b19d57c0163d57e55296277ff3c
Rebase the three patches not included there (cold boot mitigation,
arm64 SB integration, MTD RAM restrictions).
Update our kconfig for the renaming.
2017-04-20 02:38:34 +01:00
Ben Hutchings
be339ddfdd
aufs: Update support patchset to aufs4.x-rcN-20170410
2017-04-20 01:48:49 +01:00
Ben Hutchings
327c328b54
Update to 4.11-rc7 (and credit Lukas for his previous work)
2017-04-20 01:11:22 +01:00
Ben Hutchings
d85c3a332d
Complete forward-porting of "arm64: add kernel config option to set securelevel ..."
...
efi_get_secureboot() now returns one of three enumerated values, not
a boolean. We need to either redefine the DT property the same way
(risky unless we also rename it) or squash them into a boolean.
Do the latter.
2017-04-20 00:51:24 +01:00
Ben Hutchings
85c3a1be4d
Note Lukas Wunner's forward-porting work in patches
2017-04-20 00:48:59 +01:00
Ben Hutchings
40f397ca1a
Drop another patch redundant with upstream changes
2017-04-20 00:16:12 +01:00
Lukas Wunner
f26f2a520d
Update to 4.11-rc6
...
Remove merged patches and rebase remaining patches.
A portion of the secureboot patches have been upstreamed, but were
changed substantially during review, primarily to avoid code
duplication among arches. I've stripped the patches of the merged
bits and rebased the remainder.
Signed-off-by: Lukas Wunner <lukas@wunner.de>
[bwh: Undo some incorrect context changes in
bugfix/all/firmware-remove-redundant-log-messages-from-drivers.patch]
2017-04-20 00:15:17 +01:00
Ben Hutchings
22e8e7af28
Explicitly mark some patches as Forwarded: no or not-needed
2017-04-18 04:19:54 +01:00
Ben Hutchings
cf75a4d22c
Add Origin for a probably-obsolete MIPS patch
2017-04-18 04:19:20 +01:00
Ben Hutchings
aa2adea45f
Update Origin and description for various patches now applied/merged upstream
2017-04-18 04:18:56 +01:00
Ben Hutchings
790885d6d8
Add Forwarded header and update description for several patches
2017-04-18 04:15:47 +01:00
Ben Hutchings
8701ef58ba
Replace "[media] dvb-usb: Don't use stack for reset either" with upstream fix
2017-04-18 01:16:50 +01:00
Ben Hutchings
3f62574711
crypto: ahash - Fix EINPROGRESS notification callback (CVE-2017-7618)
2017-04-16 23:25:12 +01:00
Ben Hutchings
4d042ae0ff
[rt] Update to 4.9.20-rt16
2017-04-16 21:52:57 +01:00
Ben Hutchings
31945f628c
Update to 4.9.22
...
Drop patches applied upstream.
2017-04-16 21:47:05 +01:00
Ben Hutchings
326a2052e2
linux-image: Disable signing until it's supported in dak
...
Only code signing through dak is going to be acceptable for a stable
release, so disable the current arrangement.
2017-04-16 18:53:52 +01:00