diff options
author | Anthony G. Basile <blueness@gentoo.org> | 2016-11-16 06:33:25 -0500 |
---|---|---|
committer | Anthony G. Basile <blueness@gentoo.org> | 2016-11-16 06:33:25 -0500 |
commit | fae64feb1320d6a5a606518663f9112458a95e90 (patch) | |
tree | efffef16e3b2ce6a29d46ad69580c0b80d95dbb3 | |
parent | grsecurity-3.1-4.8.7-201611102210 (diff) | |
download | hardened-patchset-fae64feb1320d6a5a606518663f9112458a95e90.tar.gz hardened-patchset-fae64feb1320d6a5a606518663f9112458a95e90.tar.bz2 hardened-patchset-fae64feb1320d6a5a606518663f9112458a95e90.zip |
grsecurity-3.1-4.8.8-20161115075620161115
-rw-r--r-- | 4.8.7/1001_linux-4.8.2.patch | 1841 | ||||
-rw-r--r-- | 4.8.7/1002_linux-4.8.3.patch | 125 | ||||
-rw-r--r-- | 4.8.7/1003_linux-4.8.4.patch | 2264 | ||||
-rw-r--r-- | 4.8.7/1004_linux-4.8.5.patch | 5397 | ||||
-rw-r--r-- | 4.8.7/1005_linux-4.8.6.patch | 5137 | ||||
-rw-r--r-- | 4.8.7/1006_linux-4.8.7.patch | 4331 | ||||
-rw-r--r-- | 4.8.8/0000_README (renamed from 4.8.7/0000_README) | 26 | ||||
-rw-r--r-- | 4.8.8/1007_linux-4.8.8.patch | 1846 | ||||
-rw-r--r-- | 4.8.8/4420_grsecurity-3.1-4.8.8-201611150756.patch (renamed from 4.8.7/4420_grsecurity-3.1-4.8.7-201611102210.patch) | 197 | ||||
-rw-r--r-- | 4.8.8/4425_grsec_remove_EI_PAX.patch (renamed from 4.8.7/4425_grsec_remove_EI_PAX.patch) | 0 | ||||
-rw-r--r-- | 4.8.8/4427_force_XATTR_PAX_tmpfs.patch (renamed from 4.8.7/4427_force_XATTR_PAX_tmpfs.patch) | 0 | ||||
-rw-r--r-- | 4.8.8/4430_grsec-remove-localversion-grsec.patch (renamed from 4.8.7/4430_grsec-remove-localversion-grsec.patch) | 0 | ||||
-rw-r--r-- | 4.8.8/4435_grsec-mute-warnings.patch (renamed from 4.8.7/4435_grsec-mute-warnings.patch) | 0 | ||||
-rw-r--r-- | 4.8.8/4440_grsec-remove-protected-paths.patch (renamed from 4.8.7/4440_grsec-remove-protected-paths.patch) | 0 | ||||
-rw-r--r-- | 4.8.8/4450_grsec-kconfig-default-gids.patch (renamed from 4.8.7/4450_grsec-kconfig-default-gids.patch) | 0 | ||||
-rw-r--r-- | 4.8.8/4465_selinux-avc_audit-log-curr_ip.patch (renamed from 4.8.7/4465_selinux-avc_audit-log-curr_ip.patch) | 0 | ||||
-rw-r--r-- | 4.8.8/4470_disable-compat_vdso.patch (renamed from 4.8.7/4470_disable-compat_vdso.patch) | 0 | ||||
-rw-r--r-- | 4.8.8/4475_emutramp_default_on.patch (renamed from 4.8.7/4475_emutramp_default_on.patch) | 0 |
18 files changed, 1942 insertions, 19222 deletions
diff --git a/4.8.7/1001_linux-4.8.2.patch b/4.8.7/1001_linux-4.8.2.patch deleted file mode 100644 index 5e354b2..0000000 --- a/4.8.7/1001_linux-4.8.2.patch +++ /dev/null @@ -1,1841 +0,0 @@ -diff --git a/Documentation/virtual/kvm/devices/vcpu.txt b/Documentation/virtual/kvm/devices/vcpu.txt -index c041658..02f5068 100644 ---- a/Documentation/virtual/kvm/devices/vcpu.txt -+++ b/Documentation/virtual/kvm/devices/vcpu.txt -@@ -30,4 +30,6 @@ Returns: -ENODEV: PMUv3 not supported - attribute - -EBUSY: PMUv3 already initialized - --Request the initialization of the PMUv3. -+Request the initialization of the PMUv3. This must be done after creating the -+in-kernel irqchip. Creating a PMU with a userspace irqchip is currently not -+supported. -diff --git a/Makefile b/Makefile -index 75db9f3..bf6e44a 100644 ---- a/Makefile -+++ b/Makefile -@@ -1,6 +1,6 @@ - VERSION = 4 - PATCHLEVEL = 8 --SUBLEVEL = 1 -+SUBLEVEL = 2 - EXTRAVERSION = - NAME = Psychotic Stoned Sheep - -diff --git a/arch/arm/boot/dts/armada-390.dtsi b/arch/arm/boot/dts/armada-390.dtsi -index 094e39c..6cd18d8 100644 ---- a/arch/arm/boot/dts/armada-390.dtsi -+++ b/arch/arm/boot/dts/armada-390.dtsi -@@ -47,6 +47,8 @@ - #include "armada-39x.dtsi" - - / { -+ compatible = "marvell,armada390"; -+ - soc { - internal-regs { - pinctrl@18000 { -@@ -54,4 +56,5 @@ - reg = <0x18000 0x20>; - }; - }; -+ }; - }; -diff --git a/arch/arm/boot/dts/qcom-apq8064.dtsi b/arch/arm/boot/dts/qcom-apq8064.dtsi -index 74a9b6c..9dc83b0 100644 ---- a/arch/arm/boot/dts/qcom-apq8064.dtsi -+++ b/arch/arm/boot/dts/qcom-apq8064.dtsi -@@ -5,6 +5,7 @@ - #include <dt-bindings/reset/qcom,gcc-msm8960.h> - #include <dt-bindings/clock/qcom,mmcc-msm8960.h> - #include <dt-bindings/soc/qcom,gsbi.h> -+#include <dt-bindings/interrupt-controller/irq.h> - #include <dt-bindings/interrupt-controller/arm-gic.h> - / { - model = "Qualcomm APQ8064"; -@@ -559,22 +560,50 @@ - compatible = "qcom,pm8921-gpio", - "qcom,ssbi-gpio"; - reg = <0x150>; -- interrupts = <192 1>, <193 1>, <194 1>, -- <195 1>, <196 1>, <197 1>, -- <198 1>, <199 1>, <200 1>, -- <201 1>, <202 1>, <203 1>, -- <204 1>, <205 1>, <206 1>, -- <207 1>, <208 1>, <209 1>, -- <210 1>, <211 1>, <212 1>, -- <213 1>, <214 1>, <215 1>, -- <216 1>, <217 1>, <218 1>, -- <219 1>, <220 1>, <221 1>, -- <222 1>, <223 1>, <224 1>, -- <225 1>, <226 1>, <227 1>, -- <228 1>, <229 1>, <230 1>, -- <231 1>, <232 1>, <233 1>, -- <234 1>, <235 1>; -- -+ interrupts = <192 IRQ_TYPE_NONE>, -+ <193 IRQ_TYPE_NONE>, -+ <194 IRQ_TYPE_NONE>, -+ <195 IRQ_TYPE_NONE>, -+ <196 IRQ_TYPE_NONE>, -+ <197 IRQ_TYPE_NONE>, -+ <198 IRQ_TYPE_NONE>, -+ <199 IRQ_TYPE_NONE>, -+ <200 IRQ_TYPE_NONE>, -+ <201 IRQ_TYPE_NONE>, -+ <202 IRQ_TYPE_NONE>, -+ <203 IRQ_TYPE_NONE>, -+ <204 IRQ_TYPE_NONE>, -+ <205 IRQ_TYPE_NONE>, -+ <206 IRQ_TYPE_NONE>, -+ <207 IRQ_TYPE_NONE>, -+ <208 IRQ_TYPE_NONE>, -+ <209 IRQ_TYPE_NONE>, -+ <210 IRQ_TYPE_NONE>, -+ <211 IRQ_TYPE_NONE>, -+ <212 IRQ_TYPE_NONE>, -+ <213 IRQ_TYPE_NONE>, -+ <214 IRQ_TYPE_NONE>, -+ <215 IRQ_TYPE_NONE>, -+ <216 IRQ_TYPE_NONE>, -+ <217 IRQ_TYPE_NONE>, -+ <218 IRQ_TYPE_NONE>, -+ <219 IRQ_TYPE_NONE>, -+ <220 IRQ_TYPE_NONE>, -+ <221 IRQ_TYPE_NONE>, -+ <222 IRQ_TYPE_NONE>, -+ <223 IRQ_TYPE_NONE>, -+ <224 IRQ_TYPE_NONE>, -+ <225 IRQ_TYPE_NONE>, -+ <226 IRQ_TYPE_NONE>, -+ <227 IRQ_TYPE_NONE>, -+ <228 IRQ_TYPE_NONE>, -+ <229 IRQ_TYPE_NONE>, -+ <230 IRQ_TYPE_NONE>, -+ <231 IRQ_TYPE_NONE>, -+ <232 IRQ_TYPE_NONE>, -+ <233 IRQ_TYPE_NONE>, -+ <234 IRQ_TYPE_NONE>, -+ <235 IRQ_TYPE_NONE>; - gpio-controller; - #gpio-cells = <2>; - -@@ -587,9 +616,18 @@ - gpio-controller; - #gpio-cells = <2>; - interrupts = -- <128 1>, <129 1>, <130 1>, <131 1>, -- <132 1>, <133 1>, <134 1>, <135 1>, -- <136 1>, <137 1>, <138 1>, <139 1>; -+ <128 IRQ_TYPE_NONE>, -+ <129 IRQ_TYPE_NONE>, -+ <130 IRQ_TYPE_NONE>, -+ <131 IRQ_TYPE_NONE>, -+ <132 IRQ_TYPE_NONE>, -+ <133 IRQ_TYPE_NONE>, -+ <134 IRQ_TYPE_NONE>, -+ <135 IRQ_TYPE_NONE>, -+ <136 IRQ_TYPE_NONE>, -+ <137 IRQ_TYPE_NONE>, -+ <138 IRQ_TYPE_NONE>, -+ <139 IRQ_TYPE_NONE>; - }; - - rtc@11d { -diff --git a/arch/arm/boot/dts/qcom-msm8660.dtsi b/arch/arm/boot/dts/qcom-msm8660.dtsi -index acbe71f..8c65e0d 100644 ---- a/arch/arm/boot/dts/qcom-msm8660.dtsi -+++ b/arch/arm/boot/dts/qcom-msm8660.dtsi -@@ -2,6 +2,7 @@ - - /include/ "skeleton.dtsi" - -+#include <dt-bindings/interrupt-controller/irq.h> - #include <dt-bindings/interrupt-controller/arm-gic.h> - #include <dt-bindings/clock/qcom,gcc-msm8660.h> - #include <dt-bindings/soc/qcom,gsbi.h> -@@ -159,21 +160,50 @@ - "qcom,ssbi-gpio"; - reg = <0x150>; - interrupt-parent = <&pmicintc>; -- interrupts = <192 1>, <193 1>, <194 1>, -- <195 1>, <196 1>, <197 1>, -- <198 1>, <199 1>, <200 1>, -- <201 1>, <202 1>, <203 1>, -- <204 1>, <205 1>, <206 1>, -- <207 1>, <208 1>, <209 1>, -- <210 1>, <211 1>, <212 1>, -- <213 1>, <214 1>, <215 1>, -- <216 1>, <217 1>, <218 1>, -- <219 1>, <220 1>, <221 1>, -- <222 1>, <223 1>, <224 1>, -- <225 1>, <226 1>, <227 1>, -- <228 1>, <229 1>, <230 1>, -- <231 1>, <232 1>, <233 1>, -- <234 1>, <235 1>; -+ interrupts = <192 IRQ_TYPE_NONE>, -+ <193 IRQ_TYPE_NONE>, -+ <194 IRQ_TYPE_NONE>, -+ <195 IRQ_TYPE_NONE>, -+ <196 IRQ_TYPE_NONE>, -+ <197 IRQ_TYPE_NONE>, -+ <198 IRQ_TYPE_NONE>, -+ <199 IRQ_TYPE_NONE>, -+ <200 IRQ_TYPE_NONE>, -+ <201 IRQ_TYPE_NONE>, -+ <202 IRQ_TYPE_NONE>, -+ <203 IRQ_TYPE_NONE>, -+ <204 IRQ_TYPE_NONE>, -+ <205 IRQ_TYPE_NONE>, -+ <206 IRQ_TYPE_NONE>, -+ <207 IRQ_TYPE_NONE>, -+ <208 IRQ_TYPE_NONE>, -+ <209 IRQ_TYPE_NONE>, -+ <210 IRQ_TYPE_NONE>, -+ <211 IRQ_TYPE_NONE>, -+ <212 IRQ_TYPE_NONE>, -+ <213 IRQ_TYPE_NONE>, -+ <214 IRQ_TYPE_NONE>, -+ <215 IRQ_TYPE_NONE>, -+ <216 IRQ_TYPE_NONE>, -+ <217 IRQ_TYPE_NONE>, -+ <218 IRQ_TYPE_NONE>, -+ <219 IRQ_TYPE_NONE>, -+ <220 IRQ_TYPE_NONE>, -+ <221 IRQ_TYPE_NONE>, -+ <222 IRQ_TYPE_NONE>, -+ <223 IRQ_TYPE_NONE>, -+ <224 IRQ_TYPE_NONE>, -+ <225 IRQ_TYPE_NONE>, -+ <226 IRQ_TYPE_NONE>, -+ <227 IRQ_TYPE_NONE>, -+ <228 IRQ_TYPE_NONE>, -+ <229 IRQ_TYPE_NONE>, -+ <230 IRQ_TYPE_NONE>, -+ <231 IRQ_TYPE_NONE>, -+ <232 IRQ_TYPE_NONE>, -+ <233 IRQ_TYPE_NONE>, -+ <234 IRQ_TYPE_NONE>, -+ <235 IRQ_TYPE_NONE>; - gpio-controller; - #gpio-cells = <2>; - -@@ -187,9 +217,18 @@ - #gpio-cells = <2>; - interrupt-parent = <&pmicintc>; - interrupts = -- <128 1>, <129 1>, <130 1>, <131 1>, -- <132 1>, <133 1>, <134 1>, <135 1>, -- <136 1>, <137 1>, <138 1>, <139 1>; -+ <128 IRQ_TYPE_NONE>, -+ <129 IRQ_TYPE_NONE>, -+ <130 IRQ_TYPE_NONE>, -+ <131 IRQ_TYPE_NONE>, -+ <132 IRQ_TYPE_NONE>, -+ <133 IRQ_TYPE_NONE>, -+ <134 IRQ_TYPE_NONE>, -+ <135 IRQ_TYPE_NONE>, -+ <136 IRQ_TYPE_NONE>, -+ <137 IRQ_TYPE_NONE>, -+ <138 IRQ_TYPE_NONE>, -+ <139 IRQ_TYPE_NONE>; - }; - - pwrkey@1c { -diff --git a/arch/arm/include/asm/delay.h b/arch/arm/include/asm/delay.h -index b7a4281..b1ce037 100644 ---- a/arch/arm/include/asm/delay.h -+++ b/arch/arm/include/asm/delay.h -@@ -10,7 +10,7 @@ - #include <asm/param.h> /* HZ */ - - #define MAX_UDELAY_MS 2 --#define UDELAY_MULT UL(2047 * HZ + 483648 * HZ / 1000000) -+#define UDELAY_MULT UL(2147 * HZ + 483648 * HZ / 1000000) - #define UDELAY_SHIFT 31 - - #ifndef __ASSEMBLY__ -diff --git a/arch/arm64/kernel/stacktrace.c b/arch/arm64/kernel/stacktrace.c -index d9751a4..d34fd72 100644 ---- a/arch/arm64/kernel/stacktrace.c -+++ b/arch/arm64/kernel/stacktrace.c -@@ -43,6 +43,9 @@ int notrace unwind_frame(struct task_struct *tsk, struct stackframe *frame) - unsigned long fp = frame->fp; - unsigned long irq_stack_ptr; - -+ if (!tsk) -+ tsk = current; -+ - /* - * Switching between stacks is valid when tracing current and in - * non-preemptible context. -@@ -67,7 +70,7 @@ int notrace unwind_frame(struct task_struct *tsk, struct stackframe *frame) - frame->pc = READ_ONCE_NOCHECK(*(unsigned long *)(fp + 8)); - - #ifdef CONFIG_FUNCTION_GRAPH_TRACER -- if (tsk && tsk->ret_stack && -+ if (tsk->ret_stack && - (frame->pc == (unsigned long)return_to_handler)) { - /* - * This is a case where function graph tracer has -diff --git a/arch/arm64/kernel/traps.c b/arch/arm64/kernel/traps.c -index e04f838..df06750 100644 ---- a/arch/arm64/kernel/traps.c -+++ b/arch/arm64/kernel/traps.c -@@ -142,6 +142,11 @@ static void dump_backtrace(struct pt_regs *regs, struct task_struct *tsk) - unsigned long irq_stack_ptr; - int skip; - -+ pr_debug("%s(regs = %p tsk = %p)\n", __func__, regs, tsk); -+ -+ if (!tsk) -+ tsk = current; -+ - /* - * Switching between stacks is valid when tracing current and in - * non-preemptible context. -@@ -151,11 +156,6 @@ static void dump_backtrace(struct pt_regs *regs, struct task_struct *tsk) - else - irq_stack_ptr = 0; - -- pr_debug("%s(regs = %p tsk = %p)\n", __func__, regs, tsk); -- -- if (!tsk) -- tsk = current; -- - if (tsk == current) { - frame.fp = (unsigned long)__builtin_frame_address(0); - frame.sp = current_stack_pointer; -diff --git a/arch/mips/kvm/emulate.c b/arch/mips/kvm/emulate.c -index e788515..43853ec 100644 ---- a/arch/mips/kvm/emulate.c -+++ b/arch/mips/kvm/emulate.c -@@ -846,6 +846,47 @@ enum emulation_result kvm_mips_emul_tlbr(struct kvm_vcpu *vcpu) - return EMULATE_FAIL; - } - -+/** -+ * kvm_mips_invalidate_guest_tlb() - Indicates a change in guest MMU map. -+ * @vcpu: VCPU with changed mappings. -+ * @tlb: TLB entry being removed. -+ * -+ * This is called to indicate a single change in guest MMU mappings, so that we -+ * can arrange TLB flushes on this and other CPUs. -+ */ -+static void kvm_mips_invalidate_guest_tlb(struct kvm_vcpu *vcpu, -+ struct kvm_mips_tlb *tlb) -+{ -+ int cpu, i; -+ bool user; -+ -+ /* No need to flush for entries which are already invalid */ -+ if (!((tlb->tlb_lo[0] | tlb->tlb_lo[1]) & ENTRYLO_V)) -+ return; -+ /* User address space doesn't need flushing for KSeg2/3 changes */ -+ user = tlb->tlb_hi < KVM_GUEST_KSEG0; -+ -+ preempt_disable(); -+ -+ /* -+ * Probe the shadow host TLB for the entry being overwritten, if one -+ * matches, invalidate it -+ */ -+ kvm_mips_host_tlb_inv(vcpu, tlb->tlb_hi); -+ -+ /* Invalidate the whole ASID on other CPUs */ -+ cpu = smp_processor_id(); -+ for_each_possible_cpu(i) { -+ if (i == cpu) -+ continue; -+ if (user) -+ vcpu->arch.guest_user_asid[i] = 0; -+ vcpu->arch.guest_kernel_asid[i] = 0; -+ } -+ -+ preempt_enable(); -+} -+ - /* Write Guest TLB Entry @ Index */ - enum emulation_result kvm_mips_emul_tlbwi(struct kvm_vcpu *vcpu) - { -@@ -865,11 +906,8 @@ enum emulation_result kvm_mips_emul_tlbwi(struct kvm_vcpu *vcpu) - } - - tlb = &vcpu->arch.guest_tlb[index]; -- /* -- * Probe the shadow host TLB for the entry being overwritten, if one -- * matches, invalidate it -- */ -- kvm_mips_host_tlb_inv(vcpu, tlb->tlb_hi); -+ -+ kvm_mips_invalidate_guest_tlb(vcpu, tlb); - - tlb->tlb_mask = kvm_read_c0_guest_pagemask(cop0); - tlb->tlb_hi = kvm_read_c0_guest_entryhi(cop0); -@@ -898,11 +936,7 @@ enum emulation_result kvm_mips_emul_tlbwr(struct kvm_vcpu *vcpu) - - tlb = &vcpu->arch.guest_tlb[index]; - -- /* -- * Probe the shadow host TLB for the entry being overwritten, if one -- * matches, invalidate it -- */ -- kvm_mips_host_tlb_inv(vcpu, tlb->tlb_hi); -+ kvm_mips_invalidate_guest_tlb(vcpu, tlb); - - tlb->tlb_mask = kvm_read_c0_guest_pagemask(cop0); - tlb->tlb_hi = kvm_read_c0_guest_entryhi(cop0); -@@ -1026,6 +1060,7 @@ enum emulation_result kvm_mips_emulate_CP0(union mips_instruction inst, - enum emulation_result er = EMULATE_DONE; - u32 rt, rd, sel; - unsigned long curr_pc; -+ int cpu, i; - - /* - * Update PC and hold onto current PC in case there is -@@ -1135,8 +1170,16 @@ enum emulation_result kvm_mips_emulate_CP0(union mips_instruction inst, - & KVM_ENTRYHI_ASID, - nasid); - -+ preempt_disable(); - /* Blow away the shadow host TLBs */ - kvm_mips_flush_host_tlb(1); -+ cpu = smp_processor_id(); -+ for_each_possible_cpu(i) -+ if (i != cpu) { -+ vcpu->arch.guest_user_asid[i] = 0; -+ vcpu->arch.guest_kernel_asid[i] = 0; -+ } -+ preempt_enable(); - } - kvm_write_c0_guest_entryhi(cop0, - vcpu->arch.gprs[rt]); -diff --git a/arch/powerpc/include/asm/reg.h b/arch/powerpc/include/asm/reg.h -index f69f40f..978dada 100644 ---- a/arch/powerpc/include/asm/reg.h -+++ b/arch/powerpc/include/asm/reg.h -@@ -737,6 +737,7 @@ - #define MMCR0_FCHV 0x00000001UL /* freeze conditions in hypervisor mode */ - #define SPRN_MMCR1 798 - #define SPRN_MMCR2 785 -+#define SPRN_UMMCR2 769 - #define SPRN_MMCRA 0x312 - #define MMCRA_SDSYNC 0x80000000UL /* SDAR synced with SIAR */ - #define MMCRA_SDAR_DCACHE_MISS 0x40000000UL -diff --git a/arch/powerpc/kvm/book3s_emulate.c b/arch/powerpc/kvm/book3s_emulate.c -index 2afdb9c..729f8fa 100644 ---- a/arch/powerpc/kvm/book3s_emulate.c -+++ b/arch/powerpc/kvm/book3s_emulate.c -@@ -498,6 +498,7 @@ int kvmppc_core_emulate_mtspr_pr(struct kvm_vcpu *vcpu, int sprn, ulong spr_val) - case SPRN_MMCR0: - case SPRN_MMCR1: - case SPRN_MMCR2: -+ case SPRN_UMMCR2: - #endif - break; - unprivileged: -@@ -640,6 +641,7 @@ int kvmppc_core_emulate_mfspr_pr(struct kvm_vcpu *vcpu, int sprn, ulong *spr_val - case SPRN_MMCR0: - case SPRN_MMCR1: - case SPRN_MMCR2: -+ case SPRN_UMMCR2: - case SPRN_TIR: - #endif - *spr_val = 0; -diff --git a/arch/powerpc/kvm/booke.c b/arch/powerpc/kvm/booke.c -index 02b4672..df3f270 100644 ---- a/arch/powerpc/kvm/booke.c -+++ b/arch/powerpc/kvm/booke.c -@@ -2038,7 +2038,7 @@ int kvm_arch_vcpu_ioctl_set_guest_debug(struct kvm_vcpu *vcpu, - if (type == KVMPPC_DEBUG_NONE) - continue; - -- if (type & !(KVMPPC_DEBUG_WATCH_READ | -+ if (type & ~(KVMPPC_DEBUG_WATCH_READ | - KVMPPC_DEBUG_WATCH_WRITE | - KVMPPC_DEBUG_BREAKPOINT)) - return -EINVAL; -diff --git a/arch/x86/include/asm/fpu/xstate.h b/arch/x86/include/asm/fpu/xstate.h -index ae55a43..19f30a8 100644 ---- a/arch/x86/include/asm/fpu/xstate.h -+++ b/arch/x86/include/asm/fpu/xstate.h -@@ -27,11 +27,12 @@ - XFEATURE_MASK_YMM | \ - XFEATURE_MASK_OPMASK | \ - XFEATURE_MASK_ZMM_Hi256 | \ -- XFEATURE_MASK_Hi16_ZMM | \ -- XFEATURE_MASK_PKRU) -+ XFEATURE_MASK_Hi16_ZMM) - - /* Supported features which require eager state saving */ --#define XFEATURE_MASK_EAGER (XFEATURE_MASK_BNDREGS | XFEATURE_MASK_BNDCSR) -+#define XFEATURE_MASK_EAGER (XFEATURE_MASK_BNDREGS | \ -+ XFEATURE_MASK_BNDCSR | \ -+ XFEATURE_MASK_PKRU) - - /* All currently supported features */ - #define XCNTXT_MASK (XFEATURE_MASK_LAZY | XFEATURE_MASK_EAGER) -diff --git a/arch/x86/include/asm/intel-family.h b/arch/x86/include/asm/intel-family.h -index 6277194..9ae5ab8 100644 ---- a/arch/x86/include/asm/intel-family.h -+++ b/arch/x86/include/asm/intel-family.h -@@ -56,8 +56,8 @@ - #define INTEL_FAM6_ATOM_SILVERMONT1 0x37 /* BayTrail/BYT / Valleyview */ - #define INTEL_FAM6_ATOM_SILVERMONT2 0x4D /* Avaton/Rangely */ - #define INTEL_FAM6_ATOM_AIRMONT 0x4C /* CherryTrail / Braswell */ --#define INTEL_FAM6_ATOM_MERRIFIELD1 0x4A /* Tangier */ --#define INTEL_FAM6_ATOM_MERRIFIELD2 0x5A /* Annidale */ -+#define INTEL_FAM6_ATOM_MERRIFIELD 0x4A /* Tangier */ -+#define INTEL_FAM6_ATOM_MOOREFIELD 0x5A /* Annidale */ - #define INTEL_FAM6_ATOM_GOLDMONT 0x5C - #define INTEL_FAM6_ATOM_DENVERTON 0x5F /* Goldmont Microserver */ - -diff --git a/arch/x86/include/asm/mpspec.h b/arch/x86/include/asm/mpspec.h -index b07233b..c2f94dc 100644 ---- a/arch/x86/include/asm/mpspec.h -+++ b/arch/x86/include/asm/mpspec.h -@@ -6,7 +6,6 @@ - #include <asm/x86_init.h> - #include <asm/apicdef.h> - --extern int apic_version[]; - extern int pic_mode; - - #ifdef CONFIG_X86_32 -@@ -40,6 +39,7 @@ extern int mp_bus_id_to_type[MAX_MP_BUSSES]; - extern DECLARE_BITMAP(mp_bus_not_pci, MAX_MP_BUSSES); - - extern unsigned int boot_cpu_physical_apicid; -+extern u8 boot_cpu_apic_version; - extern unsigned long mp_lapic_addr; - - #ifdef CONFIG_X86_LOCAL_APIC -diff --git a/arch/x86/kernel/acpi/boot.c b/arch/x86/kernel/acpi/boot.c -index 90d84c3..fbd1944 100644 ---- a/arch/x86/kernel/acpi/boot.c -+++ b/arch/x86/kernel/acpi/boot.c -@@ -182,7 +182,7 @@ static int acpi_register_lapic(int id, u32 acpiid, u8 enabled) - } - - if (boot_cpu_physical_apicid != -1U) -- ver = apic_version[boot_cpu_physical_apicid]; -+ ver = boot_cpu_apic_version; - - cpu = generic_processor_info(id, ver); - if (cpu >= 0) -diff --git a/arch/x86/kernel/apic/apic.c b/arch/x86/kernel/apic/apic.c -index f3e9b2d..076c315 100644 ---- a/arch/x86/kernel/apic/apic.c -+++ b/arch/x86/kernel/apic/apic.c -@@ -64,6 +64,8 @@ unsigned disabled_cpus; - unsigned int boot_cpu_physical_apicid = -1U; - EXPORT_SYMBOL_GPL(boot_cpu_physical_apicid); - -+u8 boot_cpu_apic_version; -+ - /* - * The highest APIC ID seen during enumeration. - */ -@@ -1816,8 +1818,7 @@ void __init init_apic_mappings(void) - * since smp_sanity_check is prepared for such a case - * and disable smp mode - */ -- apic_version[new_apicid] = -- GET_APIC_VERSION(apic_read(APIC_LVR)); -+ boot_cpu_apic_version = GET_APIC_VERSION(apic_read(APIC_LVR)); - } - } - -@@ -1832,13 +1833,10 @@ void __init register_lapic_address(unsigned long address) - } - if (boot_cpu_physical_apicid == -1U) { - boot_cpu_physical_apicid = read_apic_id(); -- apic_version[boot_cpu_physical_apicid] = -- GET_APIC_VERSION(apic_read(APIC_LVR)); -+ boot_cpu_apic_version = GET_APIC_VERSION(apic_read(APIC_LVR)); - } - } - --int apic_version[MAX_LOCAL_APIC]; -- - /* - * Local APIC interrupts - */ -@@ -2130,11 +2128,10 @@ int generic_processor_info(int apicid, int version) - cpu, apicid); - version = 0x10; - } -- apic_version[apicid] = version; - -- if (version != apic_version[boot_cpu_physical_apicid]) { -+ if (version != boot_cpu_apic_version) { - pr_warning("BIOS bug: APIC version mismatch, boot CPU: %x, CPU %d: version %x\n", -- apic_version[boot_cpu_physical_apicid], cpu, version); -+ boot_cpu_apic_version, cpu, version); - } - - physid_set(apicid, phys_cpu_present_map); -@@ -2277,7 +2274,7 @@ int __init APIC_init_uniprocessor(void) - * Complain if the BIOS pretends there is one. - */ - if (!boot_cpu_has(X86_FEATURE_APIC) && -- APIC_INTEGRATED(apic_version[boot_cpu_physical_apicid])) { -+ APIC_INTEGRATED(boot_cpu_apic_version)) { - pr_err("BIOS bug, local APIC 0x%x not detected!...\n", - boot_cpu_physical_apicid); - return -1; -diff --git a/arch/x86/kernel/apic/io_apic.c b/arch/x86/kernel/apic/io_apic.c -index 7491f41..48e6d84 100644 ---- a/arch/x86/kernel/apic/io_apic.c -+++ b/arch/x86/kernel/apic/io_apic.c -@@ -1593,7 +1593,7 @@ void __init setup_ioapic_ids_from_mpc(void) - * no meaning without the serial APIC bus. - */ - if (!(boot_cpu_data.x86_vendor == X86_VENDOR_INTEL) -- || APIC_XAPIC(apic_version[boot_cpu_physical_apicid])) -+ || APIC_XAPIC(boot_cpu_apic_version)) - return; - setup_ioapic_ids_from_mpc_nocheck(); - } -@@ -2423,7 +2423,7 @@ static int io_apic_get_unique_id(int ioapic, int apic_id) - static u8 io_apic_unique_id(int idx, u8 id) - { - if ((boot_cpu_data.x86_vendor == X86_VENDOR_INTEL) && -- !APIC_XAPIC(apic_version[boot_cpu_physical_apicid])) -+ !APIC_XAPIC(boot_cpu_apic_version)) - return io_apic_get_unique_id(idx, id); - else - return id; -diff --git a/arch/x86/kernel/apic/probe_32.c b/arch/x86/kernel/apic/probe_32.c -index 7c43e71..5630962 100644 ---- a/arch/x86/kernel/apic/probe_32.c -+++ b/arch/x86/kernel/apic/probe_32.c -@@ -152,7 +152,7 @@ early_param("apic", parse_apic); - - void __init default_setup_apic_routing(void) - { -- int version = apic_version[boot_cpu_physical_apicid]; -+ int version = boot_cpu_apic_version; - - if (num_possible_cpus() > 8) { - switch (boot_cpu_data.x86_vendor) { -diff --git a/arch/x86/kernel/apic/vector.c b/arch/x86/kernel/apic/vector.c -index 6066d94..5d30c5e 100644 ---- a/arch/x86/kernel/apic/vector.c -+++ b/arch/x86/kernel/apic/vector.c -@@ -661,11 +661,28 @@ void irq_complete_move(struct irq_cfg *cfg) - */ - void irq_force_complete_move(struct irq_desc *desc) - { -- struct irq_data *irqdata = irq_desc_get_irq_data(desc); -- struct apic_chip_data *data = apic_chip_data(irqdata); -- struct irq_cfg *cfg = data ? &data->cfg : NULL; -+ struct irq_data *irqdata; -+ struct apic_chip_data *data; -+ struct irq_cfg *cfg; - unsigned int cpu; - -+ /* -+ * The function is called for all descriptors regardless of which -+ * irqdomain they belong to. For example if an IRQ is provided by -+ * an irq_chip as part of a GPIO driver, the chip data for that -+ * descriptor is specific to the irq_chip in question. -+ * -+ * Check first that the chip_data is what we expect -+ * (apic_chip_data) before touching it any further. -+ */ -+ irqdata = irq_domain_get_irq_data(x86_vector_domain, -+ irq_desc_get_irq(desc)); -+ if (!irqdata) -+ return; -+ -+ data = apic_chip_data(irqdata); -+ cfg = data ? &data->cfg : NULL; -+ - if (!cfg) - return; - -diff --git a/arch/x86/kernel/e820.c b/arch/x86/kernel/e820.c -index 621b501..8a90f15 100644 ---- a/arch/x86/kernel/e820.c -+++ b/arch/x86/kernel/e820.c -@@ -348,7 +348,7 @@ int __init sanitize_e820_map(struct e820entry *biosmap, int max_nr_map, - * continue building up new bios map based on this - * information - */ -- if (current_type != last_type || current_type == E820_PRAM) { -+ if (current_type != last_type) { - if (last_type != 0) { - new_bios[new_bios_entry].size = - change_point[chgidx]->addr - last_addr; -@@ -754,7 +754,7 @@ u64 __init early_reserve_e820(u64 size, u64 align) - /* - * Find the highest page frame number we have available - */ --static unsigned long __init e820_end_pfn(unsigned long limit_pfn) -+static unsigned long __init e820_end_pfn(unsigned long limit_pfn, unsigned type) - { - int i; - unsigned long last_pfn = 0; -@@ -765,11 +765,7 @@ static unsigned long __init e820_end_pfn(unsigned long limit_pfn) - unsigned long start_pfn; - unsigned long end_pfn; - -- /* -- * Persistent memory is accounted as ram for purposes of -- * establishing max_pfn and mem_map. -- */ -- if (ei->type != E820_RAM && ei->type != E820_PRAM) -+ if (ei->type != type) - continue; - - start_pfn = ei->addr >> PAGE_SHIFT; -@@ -794,12 +790,12 @@ static unsigned long __init e820_end_pfn(unsigned long limit_pfn) - } - unsigned long __init e820_end_of_ram_pfn(void) - { -- return e820_end_pfn(MAX_ARCH_PFN); -+ return e820_end_pfn(MAX_ARCH_PFN, E820_RAM); - } - - unsigned long __init e820_end_of_low_ram_pfn(void) - { -- return e820_end_pfn(1UL << (32-PAGE_SHIFT)); -+ return e820_end_pfn(1UL << (32 - PAGE_SHIFT), E820_RAM); - } - - static void early_panic(char *msg) -diff --git a/arch/x86/kernel/process_64.c b/arch/x86/kernel/process_64.c -index 63236d8..a21068e 100644 ---- a/arch/x86/kernel/process_64.c -+++ b/arch/x86/kernel/process_64.c -@@ -110,12 +110,13 @@ void __show_regs(struct pt_regs *regs, int all) - get_debugreg(d7, 7); - - /* Only print out debug registers if they are in their non-default state. */ -- if ((d0 == 0) && (d1 == 0) && (d2 == 0) && (d3 == 0) && -- (d6 == DR6_RESERVED) && (d7 == 0x400)) -- return; -- -- printk(KERN_DEFAULT "DR0: %016lx DR1: %016lx DR2: %016lx\n", d0, d1, d2); -- printk(KERN_DEFAULT "DR3: %016lx DR6: %016lx DR7: %016lx\n", d3, d6, d7); -+ if (!((d0 == 0) && (d1 == 0) && (d2 == 0) && (d3 == 0) && -+ (d6 == DR6_RESERVED) && (d7 == 0x400))) { -+ printk(KERN_DEFAULT "DR0: %016lx DR1: %016lx DR2: %016lx\n", -+ d0, d1, d2); -+ printk(KERN_DEFAULT "DR3: %016lx DR6: %016lx DR7: %016lx\n", -+ d3, d6, d7); -+ } - - if (boot_cpu_has(X86_FEATURE_OSPKE)) - printk(KERN_DEFAULT "PKRU: %08x\n", read_pkru()); -diff --git a/arch/x86/kernel/ptrace.c b/arch/x86/kernel/ptrace.c -index f79576a..a1606ea 100644 ---- a/arch/x86/kernel/ptrace.c -+++ b/arch/x86/kernel/ptrace.c -@@ -173,8 +173,8 @@ unsigned long kernel_stack_pointer(struct pt_regs *regs) - return sp; - - prev_esp = (u32 *)(context); -- if (prev_esp) -- return (unsigned long)prev_esp; -+ if (*prev_esp) -+ return (unsigned long)*prev_esp; - - return (unsigned long)regs; - } -diff --git a/arch/x86/kernel/smpboot.c b/arch/x86/kernel/smpboot.c -index 4296beb..82b1737 100644 ---- a/arch/x86/kernel/smpboot.c -+++ b/arch/x86/kernel/smpboot.c -@@ -690,7 +690,7 @@ wakeup_secondary_cpu_via_nmi(int apicid, unsigned long start_eip) - * Give the other CPU some time to accept the IPI. - */ - udelay(200); -- if (APIC_INTEGRATED(apic_version[boot_cpu_physical_apicid])) { -+ if (APIC_INTEGRATED(boot_cpu_apic_version)) { - maxlvt = lapic_get_maxlvt(); - if (maxlvt > 3) /* Due to the Pentium erratum 3AP. */ - apic_write(APIC_ESR, 0); -@@ -717,7 +717,7 @@ wakeup_secondary_cpu_via_init(int phys_apicid, unsigned long start_eip) - /* - * Be paranoid about clearing APIC errors. - */ -- if (APIC_INTEGRATED(apic_version[phys_apicid])) { -+ if (APIC_INTEGRATED(boot_cpu_apic_version)) { - if (maxlvt > 3) /* Due to the Pentium erratum 3AP. */ - apic_write(APIC_ESR, 0); - apic_read(APIC_ESR); -@@ -756,7 +756,7 @@ wakeup_secondary_cpu_via_init(int phys_apicid, unsigned long start_eip) - * Determine this based on the APIC version. - * If we don't have an integrated APIC, don't send the STARTUP IPIs. - */ -- if (APIC_INTEGRATED(apic_version[phys_apicid])) -+ if (APIC_INTEGRATED(boot_cpu_apic_version)) - num_starts = 2; - else - num_starts = 0; -@@ -994,7 +994,7 @@ static int do_boot_cpu(int apicid, int cpu, struct task_struct *idle) - /* - * Be paranoid about clearing APIC errors. - */ -- if (APIC_INTEGRATED(apic_version[boot_cpu_physical_apicid])) { -+ if (APIC_INTEGRATED(boot_cpu_apic_version)) { - apic_write(APIC_ESR, 0); - apic_read(APIC_ESR); - } -@@ -1249,7 +1249,7 @@ static int __init smp_sanity_check(unsigned max_cpus) - /* - * If we couldn't find a local APIC, then get out of here now! - */ -- if (APIC_INTEGRATED(apic_version[boot_cpu_physical_apicid]) && -+ if (APIC_INTEGRATED(boot_cpu_apic_version) && - !boot_cpu_has(X86_FEATURE_APIC)) { - if (!disable_apic) { - pr_err("BIOS bug, local APIC #%d not detected!...\n", -@@ -1406,9 +1406,21 @@ __init void prefill_possible_map(void) - { - int i, possible; - -- /* no processor from mptable or madt */ -- if (!num_processors) -- num_processors = 1; -+ /* No boot processor was found in mptable or ACPI MADT */ -+ if (!num_processors) { -+ int apicid = boot_cpu_physical_apicid; -+ int cpu = hard_smp_processor_id(); -+ -+ pr_warn("Boot CPU (id %d) not listed by BIOS\n", cpu); -+ -+ /* Make sure boot cpu is enumerated */ -+ if (apic->cpu_present_to_apicid(0) == BAD_APICID && -+ apic->apic_id_valid(apicid)) -+ generic_processor_info(apicid, boot_cpu_apic_version); -+ -+ if (!num_processors) -+ num_processors = 1; -+ } - - i = setup_max_cpus ?: 1; - if (setup_possible_cpus == -1) { -diff --git a/arch/x86/platform/atom/punit_atom_debug.c b/arch/x86/platform/atom/punit_atom_debug.c -index 8ff7b93..d49d3be 100644 ---- a/arch/x86/platform/atom/punit_atom_debug.c -+++ b/arch/x86/platform/atom/punit_atom_debug.c -@@ -155,7 +155,7 @@ static void punit_dbgfs_unregister(void) - - static const struct x86_cpu_id intel_punit_cpu_ids[] = { - ICPU(INTEL_FAM6_ATOM_SILVERMONT1, punit_device_byt), -- ICPU(INTEL_FAM6_ATOM_MERRIFIELD1, punit_device_tng), -+ ICPU(INTEL_FAM6_ATOM_MERRIFIELD, punit_device_tng), - ICPU(INTEL_FAM6_ATOM_AIRMONT, punit_device_cht), - {} - }; -diff --git a/arch/x86/platform/intel-mid/pwr.c b/arch/x86/platform/intel-mid/pwr.c -index c901a34..6eca0f6 100644 ---- a/arch/x86/platform/intel-mid/pwr.c -+++ b/arch/x86/platform/intel-mid/pwr.c -@@ -354,7 +354,7 @@ static int mid_pwr_probe(struct pci_dev *pdev, const struct pci_device_id *id) - return 0; - } - --static int mid_set_initial_state(struct mid_pwr *pwr) -+static int mid_set_initial_state(struct mid_pwr *pwr, const u32 *states) - { - unsigned int i, j; - int ret; -@@ -379,10 +379,10 @@ static int mid_set_initial_state(struct mid_pwr *pwr) - * NOTE: The actual device mapping is provided by a platform at run - * time using vendor capability of PCI configuration space. - */ -- mid_pwr_set_state(pwr, 0, 0xffffffff); -- mid_pwr_set_state(pwr, 1, 0xffffffff); -- mid_pwr_set_state(pwr, 2, 0xffffffff); -- mid_pwr_set_state(pwr, 3, 0xffffffff); -+ mid_pwr_set_state(pwr, 0, states[0]); -+ mid_pwr_set_state(pwr, 1, states[1]); -+ mid_pwr_set_state(pwr, 2, states[2]); -+ mid_pwr_set_state(pwr, 3, states[3]); - - /* Send command to SCU */ - ret = mid_pwr_wait_for_cmd(pwr, CMD_SET_CFG); -@@ -397,13 +397,41 @@ static int mid_set_initial_state(struct mid_pwr *pwr) - return 0; - } - --static const struct mid_pwr_device_info mid_info = { -- .set_initial_state = mid_set_initial_state, -+static int pnw_set_initial_state(struct mid_pwr *pwr) -+{ -+ /* On Penwell SRAM must stay powered on */ -+ const u32 states[] = { -+ 0xf00fffff, /* PM_SSC(0) */ -+ 0xffffffff, /* PM_SSC(1) */ -+ 0xffffffff, /* PM_SSC(2) */ -+ 0xffffffff, /* PM_SSC(3) */ -+ }; -+ return mid_set_initial_state(pwr, states); -+} -+ -+static int tng_set_initial_state(struct mid_pwr *pwr) -+{ -+ const u32 states[] = { -+ 0xffffffff, /* PM_SSC(0) */ -+ 0xffffffff, /* PM_SSC(1) */ -+ 0xffffffff, /* PM_SSC(2) */ -+ 0xffffffff, /* PM_SSC(3) */ -+ }; -+ return mid_set_initial_state(pwr, states); -+} -+ -+static const struct mid_pwr_device_info pnw_info = { -+ .set_initial_state = pnw_set_initial_state, -+}; -+ -+static const struct mid_pwr_device_info tng_info = { -+ .set_initial_state = tng_set_initial_state, - }; - -+/* This table should be in sync with the one in drivers/pci/pci-mid.c */ - static const struct pci_device_id mid_pwr_pci_ids[] = { -- { PCI_VDEVICE(INTEL, PCI_DEVICE_ID_PENWELL), (kernel_ulong_t)&mid_info }, -- { PCI_VDEVICE(INTEL, PCI_DEVICE_ID_TANGIER), (kernel_ulong_t)&mid_info }, -+ { PCI_VDEVICE(INTEL, PCI_DEVICE_ID_PENWELL), (kernel_ulong_t)&pnw_info }, -+ { PCI_VDEVICE(INTEL, PCI_DEVICE_ID_TANGIER), (kernel_ulong_t)&tng_info }, - {} - }; - -diff --git a/arch/x86/xen/smp.c b/arch/x86/xen/smp.c -index 0b4d04c..6228403 100644 ---- a/arch/x86/xen/smp.c -+++ b/arch/x86/xen/smp.c -@@ -87,6 +87,12 @@ static void cpu_bringup(void) - cpu_data(cpu).x86_max_cores = 1; - set_cpu_sibling_map(cpu); - -+ /* -+ * identify_cpu() may have set logical_pkg_id to -1 due -+ * to incorrect phys_proc_id. Let's re-comupte it. -+ */ -+ topology_update_package_map(apic->cpu_present_to_apicid(cpu), cpu); -+ - xen_setup_cpu_clockevents(); - - notify_cpu_starting(cpu); -diff --git a/drivers/bluetooth/btusb.c b/drivers/bluetooth/btusb.c -index 811f9b9..d4d55f6 100644 ---- a/drivers/bluetooth/btusb.c -+++ b/drivers/bluetooth/btusb.c -@@ -251,6 +251,7 @@ static const struct usb_device_id blacklist_table[] = { - { USB_DEVICE(0x0cf3, 0xe300), .driver_info = BTUSB_QCA_ROME }, - { USB_DEVICE(0x0cf3, 0xe360), .driver_info = BTUSB_QCA_ROME }, - { USB_DEVICE(0x0489, 0xe092), .driver_info = BTUSB_QCA_ROME }, -+ { USB_DEVICE(0x04ca, 0x3011), .driver_info = BTUSB_QCA_ROME }, - - /* Broadcom BCM2035 */ - { USB_DEVICE(0x0a5c, 0x2009), .driver_info = BTUSB_BCM92035 }, -diff --git a/drivers/char/tpm/tpm-dev.c b/drivers/char/tpm/tpm-dev.c -index f5d4521..912ad30 100644 ---- a/drivers/char/tpm/tpm-dev.c -+++ b/drivers/char/tpm/tpm-dev.c -@@ -145,7 +145,7 @@ static ssize_t tpm_write(struct file *file, const char __user *buf, - return -EPIPE; - } - out_size = tpm_transmit(priv->chip, priv->data_buffer, -- sizeof(priv->data_buffer)); -+ sizeof(priv->data_buffer), 0); - - tpm_put_ops(priv->chip); - if (out_size < 0) { -diff --git a/drivers/char/tpm/tpm-interface.c b/drivers/char/tpm/tpm-interface.c -index 1abe2d7..aef20ee 100644 ---- a/drivers/char/tpm/tpm-interface.c -+++ b/drivers/char/tpm/tpm-interface.c -@@ -330,8 +330,8 @@ EXPORT_SYMBOL_GPL(tpm_calc_ordinal_duration); - /* - * Internal kernel interface to transmit TPM commands - */ --ssize_t tpm_transmit(struct tpm_chip *chip, const char *buf, -- size_t bufsiz) -+ssize_t tpm_transmit(struct tpm_chip *chip, const u8 *buf, size_t bufsiz, -+ unsigned int flags) - { - ssize_t rc; - u32 count, ordinal; -@@ -350,7 +350,8 @@ ssize_t tpm_transmit(struct tpm_chip *chip, const char *buf, - return -E2BIG; - } - -- mutex_lock(&chip->tpm_mutex); -+ if (!(flags & TPM_TRANSMIT_UNLOCKED)) -+ mutex_lock(&chip->tpm_mutex); - - rc = chip->ops->send(chip, (u8 *) buf, count); - if (rc < 0) { -@@ -393,20 +394,21 @@ ssize_t tpm_transmit(struct tpm_chip *chip, const char *buf, - dev_err(&chip->dev, - "tpm_transmit: tpm_recv: error %zd\n", rc); - out: -- mutex_unlock(&chip->tpm_mutex); -+ if (!(flags & TPM_TRANSMIT_UNLOCKED)) -+ mutex_unlock(&chip->tpm_mutex); - return rc; - } - - #define TPM_DIGEST_SIZE 20 - #define TPM_RET_CODE_IDX 6 - --ssize_t tpm_transmit_cmd(struct tpm_chip *chip, void *cmd, -- int len, const char *desc) -+ssize_t tpm_transmit_cmd(struct tpm_chip *chip, const void *cmd, -+ int len, unsigned int flags, const char *desc) - { -- struct tpm_output_header *header; -+ const struct tpm_output_header *header; - int err; - -- len = tpm_transmit(chip, (u8 *) cmd, len); -+ len = tpm_transmit(chip, (const u8 *)cmd, len, flags); - if (len < 0) - return len; - else if (len < TPM_HEADER_SIZE) -@@ -453,7 +455,8 @@ ssize_t tpm_getcap(struct tpm_chip *chip, __be32 subcap_id, cap_t *cap, - tpm_cmd.params.getcap_in.subcap_size = cpu_to_be32(4); - tpm_cmd.params.getcap_in.subcap = subcap_id; - } -- rc = tpm_transmit_cmd(chip, &tpm_cmd, TPM_INTERNAL_RESULT_SIZE, desc); -+ rc = tpm_transmit_cmd(chip, &tpm_cmd, TPM_INTERNAL_RESULT_SIZE, 0, -+ desc); - if (!rc) - *cap = tpm_cmd.params.getcap_out.cap; - return rc; -@@ -469,7 +472,7 @@ void tpm_gen_interrupt(struct tpm_chip *chip) - tpm_cmd.params.getcap_in.subcap_size = cpu_to_be32(4); - tpm_cmd.params.getcap_in.subcap = TPM_CAP_PROP_TIS_TIMEOUT; - -- rc = tpm_transmit_cmd(chip, &tpm_cmd, TPM_INTERNAL_RESULT_SIZE, -+ rc = tpm_transmit_cmd(chip, &tpm_cmd, TPM_INTERNAL_RESULT_SIZE, 0, - "attempting to determine the timeouts"); - } - EXPORT_SYMBOL_GPL(tpm_gen_interrupt); -@@ -490,7 +493,7 @@ static int tpm_startup(struct tpm_chip *chip, __be16 startup_type) - start_cmd.header.in = tpm_startup_header; - - start_cmd.params.startup_in.startup_type = startup_type; -- return tpm_transmit_cmd(chip, &start_cmd, TPM_INTERNAL_RESULT_SIZE, -+ return tpm_transmit_cmd(chip, &start_cmd, TPM_INTERNAL_RESULT_SIZE, 0, - "attempting to start the TPM"); - } - -@@ -521,7 +524,8 @@ int tpm_get_timeouts(struct tpm_chip *chip) - tpm_cmd.params.getcap_in.cap = TPM_CAP_PROP; - tpm_cmd.params.getcap_in.subcap_size = cpu_to_be32(4); - tpm_cmd.params.getcap_in.subcap = TPM_CAP_PROP_TIS_TIMEOUT; -- rc = tpm_transmit_cmd(chip, &tpm_cmd, TPM_INTERNAL_RESULT_SIZE, NULL); -+ rc = tpm_transmit_cmd(chip, &tpm_cmd, TPM_INTERNAL_RESULT_SIZE, 0, -+ NULL); - - if (rc == TPM_ERR_INVALID_POSTINIT) { - /* The TPM is not started, we are the first to talk to it. -@@ -535,7 +539,7 @@ int tpm_get_timeouts(struct tpm_chip *chip) - tpm_cmd.params.getcap_in.subcap_size = cpu_to_be32(4); - tpm_cmd.params.getcap_in.subcap = TPM_CAP_PROP_TIS_TIMEOUT; - rc = tpm_transmit_cmd(chip, &tpm_cmd, TPM_INTERNAL_RESULT_SIZE, -- NULL); -+ 0, NULL); - } - if (rc) { - dev_err(&chip->dev, -@@ -596,7 +600,7 @@ int tpm_get_timeouts(struct tpm_chip *chip) - tpm_cmd.params.getcap_in.subcap_size = cpu_to_be32(4); - tpm_cmd.params.getcap_in.subcap = TPM_CAP_PROP_TIS_DURATION; - -- rc = tpm_transmit_cmd(chip, &tpm_cmd, TPM_INTERNAL_RESULT_SIZE, -+ rc = tpm_transmit_cmd(chip, &tpm_cmd, TPM_INTERNAL_RESULT_SIZE, 0, - "attempting to determine the durations"); - if (rc) - return rc; -@@ -652,7 +656,7 @@ static int tpm_continue_selftest(struct tpm_chip *chip) - struct tpm_cmd_t cmd; - - cmd.header.in = continue_selftest_header; -- rc = tpm_transmit_cmd(chip, &cmd, CONTINUE_SELFTEST_RESULT_SIZE, -+ rc = tpm_transmit_cmd(chip, &cmd, CONTINUE_SELFTEST_RESULT_SIZE, 0, - "continue selftest"); - return rc; - } -@@ -672,7 +676,7 @@ int tpm_pcr_read_dev(struct tpm_chip *chip, int pcr_idx, u8 *res_buf) - - cmd.header.in = pcrread_header; - cmd.params.pcrread_in.pcr_idx = cpu_to_be32(pcr_idx); -- rc = tpm_transmit_cmd(chip, &cmd, READ_PCR_RESULT_SIZE, -+ rc = tpm_transmit_cmd(chip, &cmd, READ_PCR_RESULT_SIZE, 0, - "attempting to read a pcr value"); - - if (rc == 0) -@@ -770,7 +774,7 @@ int tpm_pcr_extend(u32 chip_num, int pcr_idx, const u8 *hash) - cmd.header.in = pcrextend_header; - cmd.params.pcrextend_in.pcr_idx = cpu_to_be32(pcr_idx); - memcpy(cmd.params.pcrextend_in.hash, hash, TPM_DIGEST_SIZE); -- rc = tpm_transmit_cmd(chip, &cmd, EXTEND_PCR_RESULT_SIZE, -+ rc = tpm_transmit_cmd(chip, &cmd, EXTEND_PCR_RESULT_SIZE, 0, - "attempting extend a PCR value"); - - tpm_put_ops(chip); -@@ -809,7 +813,7 @@ int tpm_do_selftest(struct tpm_chip *chip) - /* Attempt to read a PCR value */ - cmd.header.in = pcrread_header; - cmd.params.pcrread_in.pcr_idx = cpu_to_be32(0); -- rc = tpm_transmit(chip, (u8 *) &cmd, READ_PCR_RESULT_SIZE); -+ rc = tpm_transmit(chip, (u8 *) &cmd, READ_PCR_RESULT_SIZE, 0); - /* Some buggy TPMs will not respond to tpm_tis_ready() for - * around 300ms while the self test is ongoing, keep trying - * until the self test duration expires. */ -@@ -879,7 +883,7 @@ int tpm_send(u32 chip_num, void *cmd, size_t buflen) - if (chip == NULL) - return -ENODEV; - -- rc = tpm_transmit_cmd(chip, cmd, buflen, "attempting tpm_cmd"); -+ rc = tpm_transmit_cmd(chip, cmd, buflen, 0, "attempting tpm_cmd"); - - tpm_put_ops(chip); - return rc; -@@ -981,14 +985,15 @@ int tpm_pm_suspend(struct device *dev) - cmd.params.pcrextend_in.pcr_idx = cpu_to_be32(tpm_suspend_pcr); - memcpy(cmd.params.pcrextend_in.hash, dummy_hash, - TPM_DIGEST_SIZE); -- rc = tpm_transmit_cmd(chip, &cmd, EXTEND_PCR_RESULT_SIZE, -+ rc = tpm_transmit_cmd(chip, &cmd, EXTEND_PCR_RESULT_SIZE, 0, - "extending dummy pcr before suspend"); - } - - /* now do the actual savestate */ - for (try = 0; try < TPM_RETRY; try++) { - cmd.header.in = savestate_header; -- rc = tpm_transmit_cmd(chip, &cmd, SAVESTATE_RESULT_SIZE, NULL); -+ rc = tpm_transmit_cmd(chip, &cmd, SAVESTATE_RESULT_SIZE, 0, -+ NULL); - - /* - * If the TPM indicates that it is too busy to respond to -@@ -1072,8 +1077,8 @@ int tpm_get_random(u32 chip_num, u8 *out, size_t max) - tpm_cmd.params.getrandom_in.num_bytes = cpu_to_be32(num_bytes); - - err = tpm_transmit_cmd(chip, &tpm_cmd, -- TPM_GETRANDOM_RESULT_SIZE + num_bytes, -- "attempting get random"); -+ TPM_GETRANDOM_RESULT_SIZE + num_bytes, -+ 0, "attempting get random"); - if (err) - break; - -diff --git a/drivers/char/tpm/tpm-sysfs.c b/drivers/char/tpm/tpm-sysfs.c -index b46cf70..e1f7236 100644 ---- a/drivers/char/tpm/tpm-sysfs.c -+++ b/drivers/char/tpm/tpm-sysfs.c -@@ -39,7 +39,7 @@ static ssize_t pubek_show(struct device *dev, struct device_attribute *attr, - struct tpm_chip *chip = to_tpm_chip(dev); - - tpm_cmd.header.in = tpm_readpubek_header; -- err = tpm_transmit_cmd(chip, &tpm_cmd, READ_PUBEK_RESULT_SIZE, -+ err = tpm_transmit_cmd(chip, &tpm_cmd, READ_PUBEK_RESULT_SIZE, 0, - "attempting to read the PUBEK"); - if (err) - goto out; -diff --git a/drivers/char/tpm/tpm.h b/drivers/char/tpm/tpm.h -index 3e32d5b..b0585e9 100644 ---- a/drivers/char/tpm/tpm.h -+++ b/drivers/char/tpm/tpm.h -@@ -476,12 +476,16 @@ extern dev_t tpm_devt; - extern const struct file_operations tpm_fops; - extern struct idr dev_nums_idr; - -+enum tpm_transmit_flags { -+ TPM_TRANSMIT_UNLOCKED = BIT(0), -+}; -+ -+ssize_t tpm_transmit(struct tpm_chip *chip, const u8 *buf, size_t bufsiz, -+ unsigned int flags); -+ssize_t tpm_transmit_cmd(struct tpm_chip *chip, const void *cmd, int len, -+ unsigned int flags, const char *desc); - ssize_t tpm_getcap(struct tpm_chip *chip, __be32 subcap_id, cap_t *cap, - const char *desc); --ssize_t tpm_transmit(struct tpm_chip *chip, const char *buf, -- size_t bufsiz); --ssize_t tpm_transmit_cmd(struct tpm_chip *chip, void *cmd, int len, -- const char *desc); - extern int tpm_get_timeouts(struct tpm_chip *); - extern void tpm_gen_interrupt(struct tpm_chip *); - int tpm1_auto_startup(struct tpm_chip *chip); -diff --git a/drivers/char/tpm/tpm2-cmd.c b/drivers/char/tpm/tpm2-cmd.c -index 0c75c3f..ef5a58b 100644 ---- a/drivers/char/tpm/tpm2-cmd.c -+++ b/drivers/char/tpm/tpm2-cmd.c -@@ -282,7 +282,7 @@ int tpm2_pcr_read(struct tpm_chip *chip, int pcr_idx, u8 *res_buf) - sizeof(cmd.params.pcrread_in.pcr_select)); - cmd.params.pcrread_in.pcr_select[pcr_idx >> 3] = 1 << (pcr_idx & 0x7); - -- rc = tpm_transmit_cmd(chip, &cmd, sizeof(cmd), -+ rc = tpm_transmit_cmd(chip, &cmd, sizeof(cmd), 0, - "attempting to read a pcr value"); - if (rc == 0) { - buf = cmd.params.pcrread_out.digest; -@@ -330,7 +330,7 @@ int tpm2_pcr_extend(struct tpm_chip *chip, int pcr_idx, const u8 *hash) - cmd.params.pcrextend_in.hash_alg = cpu_to_be16(TPM2_ALG_SHA1); - memcpy(cmd.params.pcrextend_in.digest, hash, TPM_DIGEST_SIZE); - -- rc = tpm_transmit_cmd(chip, &cmd, sizeof(cmd), -+ rc = tpm_transmit_cmd(chip, &cmd, sizeof(cmd), 0, - "attempting extend a PCR value"); - - return rc; -@@ -376,7 +376,7 @@ int tpm2_get_random(struct tpm_chip *chip, u8 *out, size_t max) - cmd.header.in = tpm2_getrandom_header; - cmd.params.getrandom_in.size = cpu_to_be16(num_bytes); - -- err = tpm_transmit_cmd(chip, &cmd, sizeof(cmd), -+ err = tpm_transmit_cmd(chip, &cmd, sizeof(cmd), 0, - "attempting get random"); - if (err) - break; -@@ -434,12 +434,12 @@ static void tpm2_buf_append_auth(struct tpm_buf *buf, u32 session_handle, - } - - /** -- * tpm2_seal_trusted() - seal a trusted key -- * @chip_num: A specific chip number for the request or TPM_ANY_NUM -- * @options: authentication values and other options -+ * tpm2_seal_trusted() - seal the payload of a trusted key -+ * @chip_num: TPM chip to use - * @payload: the key data in clear and encrypted form -+ * @options: authentication values and other options - * -- * Returns < 0 on error and 0 on success. -+ * Return: < 0 on error and 0 on success. - */ - int tpm2_seal_trusted(struct tpm_chip *chip, - struct trusted_key_payload *payload, -@@ -512,7 +512,7 @@ int tpm2_seal_trusted(struct tpm_chip *chip, - goto out; - } - -- rc = tpm_transmit_cmd(chip, buf.data, PAGE_SIZE, "sealing data"); -+ rc = tpm_transmit_cmd(chip, buf.data, PAGE_SIZE, 0, "sealing data"); - if (rc) - goto out; - -@@ -538,10 +538,18 @@ int tpm2_seal_trusted(struct tpm_chip *chip, - return rc; - } - --static int tpm2_load(struct tpm_chip *chip, -- struct trusted_key_payload *payload, -- struct trusted_key_options *options, -- u32 *blob_handle) -+/** -+ * tpm2_load_cmd() - execute a TPM2_Load command -+ * @chip_num: TPM chip to use -+ * @payload: the key data in clear and encrypted form -+ * @options: authentication values and other options -+ * -+ * Return: same as with tpm_transmit_cmd -+ */ -+static int tpm2_load_cmd(struct tpm_chip *chip, -+ struct trusted_key_payload *payload, -+ struct trusted_key_options *options, -+ u32 *blob_handle, unsigned int flags) - { - struct tpm_buf buf; - unsigned int private_len; -@@ -576,7 +584,7 @@ static int tpm2_load(struct tpm_chip *chip, - goto out; - } - -- rc = tpm_transmit_cmd(chip, buf.data, PAGE_SIZE, "loading blob"); -+ rc = tpm_transmit_cmd(chip, buf.data, PAGE_SIZE, flags, "loading blob"); - if (!rc) - *blob_handle = be32_to_cpup( - (__be32 *) &buf.data[TPM_HEADER_SIZE]); -@@ -590,7 +598,16 @@ static int tpm2_load(struct tpm_chip *chip, - return rc; - } - --static void tpm2_flush_context(struct tpm_chip *chip, u32 handle) -+/** -+ * tpm2_flush_context_cmd() - execute a TPM2_FlushContext command -+ * @chip_num: TPM chip to use -+ * @payload: the key data in clear and encrypted form -+ * @options: authentication values and other options -+ * -+ * Return: same as with tpm_transmit_cmd -+ */ -+static void tpm2_flush_context_cmd(struct tpm_chip *chip, u32 handle, -+ unsigned int flags) - { - struct tpm_buf buf; - int rc; -@@ -604,7 +621,8 @@ static void tpm2_flush_context(struct tpm_chip *chip, u32 handle) - - tpm_buf_append_u32(&buf, handle); - -- rc = tpm_transmit_cmd(chip, buf.data, PAGE_SIZE, "flushing context"); -+ rc = tpm_transmit_cmd(chip, buf.data, PAGE_SIZE, flags, -+ "flushing context"); - if (rc) - dev_warn(&chip->dev, "0x%08x was not flushed, rc=%d\n", handle, - rc); -@@ -612,10 +630,18 @@ static void tpm2_flush_context(struct tpm_chip *chip, u32 handle) - tpm_buf_destroy(&buf); - } - --static int tpm2_unseal(struct tpm_chip *chip, -- struct trusted_key_payload *payload, -- struct trusted_key_options *options, -- u32 blob_handle) -+/** -+ * tpm2_unseal_cmd() - execute a TPM2_Unload command -+ * @chip_num: TPM chip to use -+ * @payload: the key data in clear and encrypted form -+ * @options: authentication values and other options -+ * -+ * Return: same as with tpm_transmit_cmd -+ */ -+static int tpm2_unseal_cmd(struct tpm_chip *chip, -+ struct trusted_key_payload *payload, -+ struct trusted_key_options *options, -+ u32 blob_handle, unsigned int flags) - { - struct tpm_buf buf; - u16 data_len; -@@ -635,7 +661,7 @@ static int tpm2_unseal(struct tpm_chip *chip, - options->blobauth /* hmac */, - TPM_DIGEST_SIZE); - -- rc = tpm_transmit_cmd(chip, buf.data, PAGE_SIZE, "unsealing"); -+ rc = tpm_transmit_cmd(chip, buf.data, PAGE_SIZE, flags, "unsealing"); - if (rc > 0) - rc = -EPERM; - -@@ -654,12 +680,12 @@ static int tpm2_unseal(struct tpm_chip *chip, - } - - /** -- * tpm_unseal_trusted() - unseal a trusted key -- * @chip_num: A specific chip number for the request or TPM_ANY_NUM -- * @options: authentication values and other options -+ * tpm_unseal_trusted() - unseal the payload of a trusted key -+ * @chip_num: TPM chip to use - * @payload: the key data in clear and encrypted form -+ * @options: authentication values and other options - * -- * Returns < 0 on error and 0 on success. -+ * Return: < 0 on error and 0 on success. - */ - int tpm2_unseal_trusted(struct tpm_chip *chip, - struct trusted_key_payload *payload, -@@ -668,14 +694,17 @@ int tpm2_unseal_trusted(struct tpm_chip *chip, - u32 blob_handle; - int rc; - -- rc = tpm2_load(chip, payload, options, &blob_handle); -+ mutex_lock(&chip->tpm_mutex); -+ rc = tpm2_load_cmd(chip, payload, options, &blob_handle, -+ TPM_TRANSMIT_UNLOCKED); - if (rc) -- return rc; -- -- rc = tpm2_unseal(chip, payload, options, blob_handle); -- -- tpm2_flush_context(chip, blob_handle); -+ goto out; - -+ rc = tpm2_unseal_cmd(chip, payload, options, blob_handle, -+ TPM_TRANSMIT_UNLOCKED); -+ tpm2_flush_context_cmd(chip, blob_handle, TPM_TRANSMIT_UNLOCKED); -+out: -+ mutex_unlock(&chip->tpm_mutex); - return rc; - } - -@@ -701,7 +730,7 @@ ssize_t tpm2_get_tpm_pt(struct tpm_chip *chip, u32 property_id, u32 *value, - cmd.params.get_tpm_pt_in.property_id = cpu_to_be32(property_id); - cmd.params.get_tpm_pt_in.property_cnt = cpu_to_be32(1); - -- rc = tpm_transmit_cmd(chip, &cmd, sizeof(cmd), desc); -+ rc = tpm_transmit_cmd(chip, &cmd, sizeof(cmd), 0, desc); - if (!rc) - *value = be32_to_cpu(cmd.params.get_tpm_pt_out.value); - -@@ -735,7 +764,7 @@ static int tpm2_startup(struct tpm_chip *chip, u16 startup_type) - cmd.header.in = tpm2_startup_header; - - cmd.params.startup_in.startup_type = cpu_to_be16(startup_type); -- return tpm_transmit_cmd(chip, &cmd, sizeof(cmd), -+ return tpm_transmit_cmd(chip, &cmd, sizeof(cmd), 0, - "attempting to start the TPM"); - } - -@@ -763,7 +792,7 @@ void tpm2_shutdown(struct tpm_chip *chip, u16 shutdown_type) - cmd.header.in = tpm2_shutdown_header; - cmd.params.startup_in.startup_type = cpu_to_be16(shutdown_type); - -- rc = tpm_transmit_cmd(chip, &cmd, sizeof(cmd), "stopping the TPM"); -+ rc = tpm_transmit_cmd(chip, &cmd, sizeof(cmd), 0, "stopping the TPM"); - - /* In places where shutdown command is sent there's no much we can do - * except print the error code on a system failure. -@@ -828,7 +857,7 @@ static int tpm2_start_selftest(struct tpm_chip *chip, bool full) - cmd.header.in = tpm2_selftest_header; - cmd.params.selftest_in.full_test = full; - -- rc = tpm_transmit_cmd(chip, &cmd, TPM2_SELF_TEST_IN_SIZE, -+ rc = tpm_transmit_cmd(chip, &cmd, TPM2_SELF_TEST_IN_SIZE, 0, - "continue selftest"); - - /* At least some prototype chips seem to give RC_TESTING error -@@ -880,7 +909,7 @@ static int tpm2_do_selftest(struct tpm_chip *chip) - cmd.params.pcrread_in.pcr_select[1] = 0x00; - cmd.params.pcrread_in.pcr_select[2] = 0x00; - -- rc = tpm_transmit_cmd(chip, (u8 *) &cmd, sizeof(cmd), NULL); -+ rc = tpm_transmit_cmd(chip, &cmd, sizeof(cmd), 0, NULL); - if (rc < 0) - break; - -@@ -928,7 +957,7 @@ int tpm2_probe(struct tpm_chip *chip) - cmd.params.get_tpm_pt_in.property_id = cpu_to_be32(0x100); - cmd.params.get_tpm_pt_in.property_cnt = cpu_to_be32(1); - -- rc = tpm_transmit(chip, (const char *) &cmd, sizeof(cmd)); -+ rc = tpm_transmit(chip, (const u8 *)&cmd, sizeof(cmd), 0); - if (rc < 0) - return rc; - else if (rc < TPM_HEADER_SIZE) -diff --git a/drivers/char/tpm/tpm_crb.c b/drivers/char/tpm/tpm_crb.c -index 018c3825..1801f38 100644 ---- a/drivers/char/tpm/tpm_crb.c -+++ b/drivers/char/tpm/tpm_crb.c -@@ -142,6 +142,11 @@ static int crb_send(struct tpm_chip *chip, u8 *buf, size_t len) - struct crb_priv *priv = dev_get_drvdata(&chip->dev); - int rc = 0; - -+ /* Zero the cancel register so that the next command will not get -+ * canceled. -+ */ -+ iowrite32(0, &priv->cca->cancel); -+ - if (len > ioread32(&priv->cca->cmd_size)) { - dev_err(&chip->dev, - "invalid command count value %x %zx\n", -@@ -175,8 +180,6 @@ static void crb_cancel(struct tpm_chip *chip) - - if ((priv->flags & CRB_FL_ACPI_START) && crb_do_acpi_start(chip)) - dev_err(&chip->dev, "ACPI Start failed\n"); -- -- iowrite32(0, &priv->cca->cancel); - } - - static bool crb_req_canceled(struct tpm_chip *chip, u8 status) -diff --git a/drivers/cpuidle/cpuidle-arm.c b/drivers/cpuidle/cpuidle-arm.c -index 4ba3d3f..f440d38 100644 ---- a/drivers/cpuidle/cpuidle-arm.c -+++ b/drivers/cpuidle/cpuidle-arm.c -@@ -121,6 +121,7 @@ static int __init arm_idle_init(void) - dev = kzalloc(sizeof(*dev), GFP_KERNEL); - if (!dev) { - pr_err("Failed to allocate cpuidle device\n"); -+ ret = -ENOMEM; - goto out_fail; - } - dev->cpu = cpu; -diff --git a/drivers/mfd/Kconfig b/drivers/mfd/Kconfig -index 2d1fb64..580f4f2 100644 ---- a/drivers/mfd/Kconfig -+++ b/drivers/mfd/Kconfig -@@ -1549,6 +1549,7 @@ config MFD_WM8350 - config MFD_WM8350_I2C - bool "Wolfson Microelectronics WM8350 with I2C" - select MFD_WM8350 -+ select REGMAP_I2C - depends on I2C=y - help - The WM8350 is an integrated audio and power management -diff --git a/drivers/mfd/atmel-hlcdc.c b/drivers/mfd/atmel-hlcdc.c -index eca7ea6..4b15b08 100644 ---- a/drivers/mfd/atmel-hlcdc.c -+++ b/drivers/mfd/atmel-hlcdc.c -@@ -50,8 +50,9 @@ static int regmap_atmel_hlcdc_reg_write(void *context, unsigned int reg, - if (reg <= ATMEL_HLCDC_DIS) { - u32 status; - -- readl_poll_timeout(hregmap->regs + ATMEL_HLCDC_SR, status, -- !(status & ATMEL_HLCDC_SIP), 1, 100); -+ readl_poll_timeout_atomic(hregmap->regs + ATMEL_HLCDC_SR, -+ status, !(status & ATMEL_HLCDC_SIP), -+ 1, 100); - } - - writel(val, hregmap->regs + reg); -diff --git a/drivers/mfd/rtsx_usb.c b/drivers/mfd/rtsx_usb.c -index dbd907d..691dab7 100644 ---- a/drivers/mfd/rtsx_usb.c -+++ b/drivers/mfd/rtsx_usb.c -@@ -46,9 +46,6 @@ static void rtsx_usb_sg_timed_out(unsigned long data) - - dev_dbg(&ucr->pusb_intf->dev, "%s: sg transfer timed out", __func__); - usb_sg_cancel(&ucr->current_sg); -- -- /* we know the cancellation is caused by time-out */ -- ucr->current_sg.status = -ETIMEDOUT; - } - - static int rtsx_usb_bulk_transfer_sglist(struct rtsx_ucr *ucr, -@@ -67,12 +64,15 @@ static int rtsx_usb_bulk_transfer_sglist(struct rtsx_ucr *ucr, - ucr->sg_timer.expires = jiffies + msecs_to_jiffies(timeout); - add_timer(&ucr->sg_timer); - usb_sg_wait(&ucr->current_sg); -- del_timer_sync(&ucr->sg_timer); -+ if (!del_timer_sync(&ucr->sg_timer)) -+ ret = -ETIMEDOUT; -+ else -+ ret = ucr->current_sg.status; - - if (act_len) - *act_len = ucr->current_sg.bytes; - -- return ucr->current_sg.status; -+ return ret; - } - - int rtsx_usb_transfer_data(struct rtsx_ucr *ucr, unsigned int pipe, -diff --git a/drivers/pci/pci-mid.c b/drivers/pci/pci-mid.c -index c878aa7..55f453d 100644 ---- a/drivers/pci/pci-mid.c -+++ b/drivers/pci/pci-mid.c -@@ -60,8 +60,13 @@ static struct pci_platform_pm_ops mid_pci_platform_pm = { - - #define ICPU(model) { X86_VENDOR_INTEL, 6, model, X86_FEATURE_ANY, } - -+/* -+ * This table should be in sync with the one in -+ * arch/x86/platform/intel-mid/pwr.c. -+ */ - static const struct x86_cpu_id lpss_cpu_ids[] = { -- ICPU(INTEL_FAM6_ATOM_MERRIFIELD1), -+ ICPU(INTEL_FAM6_ATOM_PENWELL), -+ ICPU(INTEL_FAM6_ATOM_MERRIFIELD), - {} - }; - -diff --git a/drivers/phy/phy-sun4i-usb.c b/drivers/phy/phy-sun4i-usb.c -index 8c7eb33..4d74ca9 100644 ---- a/drivers/phy/phy-sun4i-usb.c -+++ b/drivers/phy/phy-sun4i-usb.c -@@ -40,6 +40,7 @@ - #include <linux/power_supply.h> - #include <linux/regulator/consumer.h> - #include <linux/reset.h> -+#include <linux/spinlock.h> - #include <linux/usb/of.h> - #include <linux/workqueue.h> - -@@ -112,7 +113,7 @@ struct sun4i_usb_phy_data { - void __iomem *base; - const struct sun4i_usb_phy_cfg *cfg; - enum usb_dr_mode dr_mode; -- struct mutex mutex; -+ spinlock_t reg_lock; /* guard access to phyctl reg */ - struct sun4i_usb_phy { - struct phy *phy; - void __iomem *pmu; -@@ -179,9 +180,10 @@ static void sun4i_usb_phy_write(struct sun4i_usb_phy *phy, u32 addr, u32 data, - struct sun4i_usb_phy_data *phy_data = to_sun4i_usb_phy_data(phy); - u32 temp, usbc_bit = BIT(phy->index * 2); - void __iomem *phyctl = phy_data->base + phy_data->cfg->phyctl_offset; -+ unsigned long flags; - int i; - -- mutex_lock(&phy_data->mutex); -+ spin_lock_irqsave(&phy_data->reg_lock, flags); - - if (phy_data->cfg->type == sun8i_a33_phy) { - /* A33 needs us to set phyctl to 0 explicitly */ -@@ -218,7 +220,8 @@ static void sun4i_usb_phy_write(struct sun4i_usb_phy *phy, u32 addr, u32 data, - - data >>= 1; - } -- mutex_unlock(&phy_data->mutex); -+ -+ spin_unlock_irqrestore(&phy_data->reg_lock, flags); - } - - static void sun4i_usb_phy_passby(struct sun4i_usb_phy *phy, int enable) -@@ -577,7 +580,7 @@ static int sun4i_usb_phy_probe(struct platform_device *pdev) - if (!data) - return -ENOMEM; - -- mutex_init(&data->mutex); -+ spin_lock_init(&data->reg_lock); - INIT_DELAYED_WORK(&data->detect, sun4i_usb_phy0_id_vbus_det_scan); - dev_set_drvdata(dev, data); - data->cfg = of_device_get_match_data(dev); -diff --git a/drivers/powercap/intel_rapl.c b/drivers/powercap/intel_rapl.c -index fbab29d..243b233 100644 ---- a/drivers/powercap/intel_rapl.c -+++ b/drivers/powercap/intel_rapl.c -@@ -1154,8 +1154,8 @@ static const struct x86_cpu_id rapl_ids[] __initconst = { - - RAPL_CPU(INTEL_FAM6_ATOM_SILVERMONT1, rapl_defaults_byt), - RAPL_CPU(INTEL_FAM6_ATOM_AIRMONT, rapl_defaults_cht), -- RAPL_CPU(INTEL_FAM6_ATOM_MERRIFIELD1, rapl_defaults_tng), -- RAPL_CPU(INTEL_FAM6_ATOM_MERRIFIELD2, rapl_defaults_ann), -+ RAPL_CPU(INTEL_FAM6_ATOM_MERRIFIELD, rapl_defaults_tng), -+ RAPL_CPU(INTEL_FAM6_ATOM_MOOREFIELD, rapl_defaults_ann), - RAPL_CPU(INTEL_FAM6_ATOM_GOLDMONT, rapl_defaults_core), - RAPL_CPU(INTEL_FAM6_ATOM_DENVERTON, rapl_defaults_core), - -diff --git a/drivers/usb/dwc3/gadget.c b/drivers/usb/dwc3/gadget.c -index 122e64d..6854461 100644 ---- a/drivers/usb/dwc3/gadget.c -+++ b/drivers/usb/dwc3/gadget.c -@@ -348,7 +348,8 @@ static int dwc3_send_clear_stall_ep_cmd(struct dwc3_ep *dep) - * IN transfers due to a mishandled error condition. Synopsys - * STAR 9000614252. - */ -- if (dep->direction && (dwc->revision >= DWC3_REVISION_260A)) -+ if (dep->direction && (dwc->revision >= DWC3_REVISION_260A) && -+ (dwc->gadget.speed >= USB_SPEED_SUPER)) - cmd |= DWC3_DEPCMD_CLEARPENDIN; - - memset(¶ms, 0, sizeof(params)); -diff --git a/drivers/usb/storage/usb.c b/drivers/usb/storage/usb.c -index ef2d8cd..8c5f011 100644 ---- a/drivers/usb/storage/usb.c -+++ b/drivers/usb/storage/usb.c -@@ -1070,17 +1070,17 @@ int usb_stor_probe2(struct us_data *us) - result = usb_stor_acquire_resources(us); - if (result) - goto BadDevice; -+ usb_autopm_get_interface_no_resume(us->pusb_intf); - snprintf(us->scsi_name, sizeof(us->scsi_name), "usb-storage %s", - dev_name(&us->pusb_intf->dev)); - result = scsi_add_host(us_to_host(us), dev); - if (result) { - dev_warn(dev, - "Unable to add the scsi host\n"); -- goto BadDevice; -+ goto HostAddErr; - } - - /* Submit the delayed_work for SCSI-device scanning */ -- usb_autopm_get_interface_no_resume(us->pusb_intf); - set_bit(US_FLIDX_SCAN_PENDING, &us->dflags); - - if (delay_use > 0) -@@ -1090,6 +1090,8 @@ int usb_stor_probe2(struct us_data *us) - return 0; - - /* We come here if there are any problems */ -+HostAddErr: -+ usb_autopm_put_interface_no_suspend(us->pusb_intf); - BadDevice: - usb_stor_dbg(us, "storage_probe() failed\n"); - release_everything(us); -diff --git a/include/linux/mfd/88pm80x.h b/include/linux/mfd/88pm80x.h -index d409ceb..c118a7e 100644 ---- a/include/linux/mfd/88pm80x.h -+++ b/include/linux/mfd/88pm80x.h -@@ -350,7 +350,7 @@ static inline int pm80x_dev_suspend(struct device *dev) - int irq = platform_get_irq(pdev, 0); - - if (device_may_wakeup(dev)) -- set_bit((1 << irq), &chip->wu_flag); -+ set_bit(irq, &chip->wu_flag); - - return 0; - } -@@ -362,7 +362,7 @@ static inline int pm80x_dev_resume(struct device *dev) - int irq = platform_get_irq(pdev, 0); - - if (device_may_wakeup(dev)) -- clear_bit((1 << irq), &chip->wu_flag); -+ clear_bit(irq, &chip->wu_flag); - - return 0; - } -diff --git a/kernel/time/timekeeping.c b/kernel/time/timekeeping.c -index e07fb09..37dec7e 100644 ---- a/kernel/time/timekeeping.c -+++ b/kernel/time/timekeeping.c -@@ -403,8 +403,11 @@ static __always_inline u64 __ktime_get_fast_ns(struct tk_fast *tkf) - tkr = tkf->base + (seq & 0x01); - now = ktime_to_ns(tkr->base); - -- now += clocksource_delta(tkr->read(tkr->clock), -- tkr->cycle_last, tkr->mask); -+ now += timekeeping_delta_to_ns(tkr, -+ clocksource_delta( -+ tkr->read(tkr->clock), -+ tkr->cycle_last, -+ tkr->mask)); - } while (read_seqcount_retry(&tkf->seq, seq)); - - return now; -diff --git a/security/integrity/ima/ima_appraise.c b/security/integrity/ima/ima_appraise.c -index 4b9b4a4..ef1e4e7 100644 ---- a/security/integrity/ima/ima_appraise.c -+++ b/security/integrity/ima/ima_appraise.c -@@ -190,7 +190,7 @@ int ima_appraise_measurement(enum ima_hooks func, - { - static const char op[] = "appraise_data"; - char *cause = "unknown"; -- struct dentry *dentry = file->f_path.dentry; -+ struct dentry *dentry = file_dentry(file); - struct inode *inode = d_backing_inode(dentry); - enum integrity_status status = INTEGRITY_UNKNOWN; - int rc = xattr_len, hash_start = 0; -@@ -295,7 +295,7 @@ int ima_appraise_measurement(enum ima_hooks func, - */ - void ima_update_xattr(struct integrity_iint_cache *iint, struct file *file) - { -- struct dentry *dentry = file->f_path.dentry; -+ struct dentry *dentry = file_dentry(file); - int rc = 0; - - /* do not collect and update hash for digital signatures */ -diff --git a/security/integrity/ima/ima_main.c b/security/integrity/ima/ima_main.c -index 596ef61..423d111 100644 ---- a/security/integrity/ima/ima_main.c -+++ b/security/integrity/ima/ima_main.c -@@ -228,7 +228,7 @@ static int process_measurement(struct file *file, char *buf, loff_t size, - if ((action & IMA_APPRAISE_SUBMASK) || - strcmp(template_desc->name, IMA_TEMPLATE_IMA_NAME) != 0) - /* read 'security.ima' */ -- xattr_len = ima_read_xattr(file->f_path.dentry, &xattr_value); -+ xattr_len = ima_read_xattr(file_dentry(file), &xattr_value); - - hash_algo = ima_get_hash_algo(xattr_value, xattr_len); - -diff --git a/sound/pci/ali5451/ali5451.c b/sound/pci/ali5451/ali5451.c -index 36470af..92b819e 100644 ---- a/sound/pci/ali5451/ali5451.c -+++ b/sound/pci/ali5451/ali5451.c -@@ -1408,6 +1408,7 @@ snd_ali_playback_pointer(struct snd_pcm_substream *substream) - spin_unlock(&codec->reg_lock); - dev_dbg(codec->card->dev, "playback pointer returned cso=%xh.\n", cso); - -+ cso %= runtime->buffer_size; - return cso; - } - -@@ -1428,6 +1429,7 @@ static snd_pcm_uframes_t snd_ali_pointer(struct snd_pcm_substream *substream) - cso = inw(ALI_REG(codec, ALI_CSO_ALPHA_FMS + 2)); - spin_unlock(&codec->reg_lock); - -+ cso %= runtime->buffer_size; - return cso; - } - -diff --git a/sound/usb/line6/driver.c b/sound/usb/line6/driver.c -index 81b7da8..183311c 100644 ---- a/sound/usb/line6/driver.c -+++ b/sound/usb/line6/driver.c -@@ -29,7 +29,7 @@ - /* - This is Line 6's MIDI manufacturer ID. - */ --const unsigned char line6_midi_id[] = { -+const unsigned char line6_midi_id[3] = { - 0x00, 0x01, 0x0c - }; - EXPORT_SYMBOL_GPL(line6_midi_id); -diff --git a/sound/usb/mixer_quirks.c b/sound/usb/mixer_quirks.c -index f6c3bf7..04991b0 100644 ---- a/sound/usb/mixer_quirks.c -+++ b/sound/usb/mixer_quirks.c -@@ -1831,6 +1831,7 @@ void snd_usb_mixer_rc_memory_change(struct usb_mixer_interface *mixer, - } - - static void snd_dragonfly_quirk_db_scale(struct usb_mixer_interface *mixer, -+ struct usb_mixer_elem_info *cval, - struct snd_kcontrol *kctl) - { - /* Approximation using 10 ranges based on output measurement on hw v1.2. -@@ -1848,10 +1849,19 @@ static void snd_dragonfly_quirk_db_scale(struct usb_mixer_interface *mixer, - 41, 50, TLV_DB_MINMAX_ITEM(-441, 0), - ); - -- usb_audio_info(mixer->chip, "applying DragonFly dB scale quirk\n"); -- kctl->tlv.p = scale; -- kctl->vd[0].access |= SNDRV_CTL_ELEM_ACCESS_TLV_READ; -- kctl->vd[0].access &= ~SNDRV_CTL_ELEM_ACCESS_TLV_CALLBACK; -+ if (cval->min == 0 && cval->max == 50) { -+ usb_audio_info(mixer->chip, "applying DragonFly dB scale quirk (0-50 variant)\n"); -+ kctl->tlv.p = scale; -+ kctl->vd[0].access |= SNDRV_CTL_ELEM_ACCESS_TLV_READ; -+ kctl->vd[0].access &= ~SNDRV_CTL_ELEM_ACCESS_TLV_CALLBACK; -+ -+ } else if (cval->min == 0 && cval->max <= 1000) { -+ /* Some other clearly broken DragonFly variant. -+ * At least a 0..53 variant (hw v1.0) exists. -+ */ -+ usb_audio_info(mixer->chip, "ignoring too narrow dB range on a DragonFly device"); -+ kctl->vd[0].access &= ~SNDRV_CTL_ELEM_ACCESS_TLV_CALLBACK; -+ } - } - - void snd_usb_mixer_fu_apply_quirk(struct usb_mixer_interface *mixer, -@@ -1860,8 +1870,8 @@ void snd_usb_mixer_fu_apply_quirk(struct usb_mixer_interface *mixer, - { - switch (mixer->chip->usb_id) { - case USB_ID(0x21b4, 0x0081): /* AudioQuest DragonFly */ -- if (unitid == 7 && cval->min == 0 && cval->max == 50) -- snd_dragonfly_quirk_db_scale(mixer, kctl); -+ if (unitid == 7 && cval->control == UAC_FU_VOLUME) -+ snd_dragonfly_quirk_db_scale(mixer, cval, kctl); - break; - } - } -diff --git a/virt/kvm/arm/pmu.c b/virt/kvm/arm/pmu.c -index a027569..6e9c40e 100644 ---- a/virt/kvm/arm/pmu.c -+++ b/virt/kvm/arm/pmu.c -@@ -423,6 +423,14 @@ static int kvm_arm_pmu_v3_init(struct kvm_vcpu *vcpu) - if (!kvm_arm_support_pmu_v3()) - return -ENODEV; - -+ /* -+ * We currently require an in-kernel VGIC to use the PMU emulation, -+ * because we do not support forwarding PMU overflow interrupts to -+ * userspace yet. -+ */ -+ if (!irqchip_in_kernel(vcpu->kvm) || !vgic_initialized(vcpu->kvm)) -+ return -ENODEV; -+ - if (!test_bit(KVM_ARM_VCPU_PMU_V3, vcpu->arch.features) || - !kvm_arm_pmu_irq_initialized(vcpu)) - return -ENXIO; -diff --git a/virt/kvm/arm/vgic/vgic.c b/virt/kvm/arm/vgic/vgic.c -index e83b7fe..b465ac6 100644 ---- a/virt/kvm/arm/vgic/vgic.c -+++ b/virt/kvm/arm/vgic/vgic.c -@@ -645,6 +645,9 @@ static void vgic_flush_lr_state(struct kvm_vcpu *vcpu) - /* Sync back the hardware VGIC state into our emulation after a guest's run. */ - void kvm_vgic_sync_hwstate(struct kvm_vcpu *vcpu) - { -+ if (unlikely(!vgic_initialized(vcpu->kvm))) -+ return; -+ - vgic_process_maintenance_interrupt(vcpu); - vgic_fold_lr_state(vcpu); - vgic_prune_ap_list(vcpu); -@@ -653,6 +656,9 @@ void kvm_vgic_sync_hwstate(struct kvm_vcpu *vcpu) - /* Flush our emulation state into the GIC hardware before entering the guest. */ - void kvm_vgic_flush_hwstate(struct kvm_vcpu *vcpu) - { -+ if (unlikely(!vgic_initialized(vcpu->kvm))) -+ return; -+ - spin_lock(&vcpu->arch.vgic_cpu.ap_list_lock); - vgic_flush_lr_state(vcpu); - spin_unlock(&vcpu->arch.vgic_cpu.ap_list_lock); diff --git a/4.8.7/1002_linux-4.8.3.patch b/4.8.7/1002_linux-4.8.3.patch deleted file mode 100644 index 4b4c68a..0000000 --- a/4.8.7/1002_linux-4.8.3.patch +++ /dev/null @@ -1,125 +0,0 @@ -diff --git a/Makefile b/Makefile -index bf6e44a..42eb45c 100644 ---- a/Makefile -+++ b/Makefile -@@ -1,6 +1,6 @@ - VERSION = 4 - PATCHLEVEL = 8 --SUBLEVEL = 2 -+SUBLEVEL = 3 - EXTRAVERSION = - NAME = Psychotic Stoned Sheep - -diff --git a/drivers/scsi/hosts.c b/drivers/scsi/hosts.c -index ec6381e..258a3f9 100644 ---- a/drivers/scsi/hosts.c -+++ b/drivers/scsi/hosts.c -@@ -246,10 +246,6 @@ int scsi_add_host_with_dma(struct Scsi_Host *shost, struct device *dev, - - shost->dma_dev = dma_dev; - -- error = device_add(&shost->shost_gendev); -- if (error) -- goto out_destroy_freelist; -- - /* - * Increase usage count temporarily here so that calling - * scsi_autopm_put_host() will trigger runtime idle if there is -@@ -260,6 +256,10 @@ int scsi_add_host_with_dma(struct Scsi_Host *shost, struct device *dev, - pm_runtime_enable(&shost->shost_gendev); - device_enable_async_suspend(&shost->shost_gendev); - -+ error = device_add(&shost->shost_gendev); -+ if (error) -+ goto out_destroy_freelist; -+ - scsi_host_set_state(shost, SHOST_RUNNING); - get_device(shost->shost_gendev.parent); - -@@ -309,6 +309,10 @@ int scsi_add_host_with_dma(struct Scsi_Host *shost, struct device *dev, - out_del_gendev: - device_del(&shost->shost_gendev); - out_destroy_freelist: -+ device_disable_async_suspend(&shost->shost_gendev); -+ pm_runtime_disable(&shost->shost_gendev); -+ pm_runtime_set_suspended(&shost->shost_gendev); -+ pm_runtime_put_noidle(&shost->shost_gendev); - scsi_destroy_command_freelist(shost); - out_destroy_tags: - if (shost_use_blk_mq(shost)) -diff --git a/fs/xfs/xfs_xattr.c b/fs/xfs/xfs_xattr.c -index ea62245..6290093 100644 ---- a/fs/xfs/xfs_xattr.c -+++ b/fs/xfs/xfs_xattr.c -@@ -147,6 +147,7 @@ __xfs_xattr_put_listent( - arraytop = context->count + prefix_len + namelen + 1; - if (arraytop > context->firstu) { - context->count = -1; /* insufficient space */ -+ context->seen_enough = 1; - return 0; - } - offset = (char *)context->alist + context->count; -diff --git a/include/linux/mm.h b/include/linux/mm.h -index ef815b9..277cd39 100644 ---- a/include/linux/mm.h -+++ b/include/linux/mm.h -@@ -2234,6 +2234,7 @@ static inline struct page *follow_page(struct vm_area_struct *vma, - #define FOLL_TRIED 0x800 /* a retry, previous pass started an IO */ - #define FOLL_MLOCK 0x1000 /* lock present pages */ - #define FOLL_REMOTE 0x2000 /* we are working on non-current tsk/mm */ -+#define FOLL_COW 0x4000 /* internal GUP flag */ - - typedef int (*pte_fn_t)(pte_t *pte, pgtable_t token, unsigned long addr, - void *data); -diff --git a/include/media/rcar-fcp.h b/include/media/rcar-fcp.h -index 4c7fc77..8723f05 100644 ---- a/include/media/rcar-fcp.h -+++ b/include/media/rcar-fcp.h -@@ -29,7 +29,7 @@ static inline struct rcar_fcp_device *rcar_fcp_get(const struct device_node *np) - static inline void rcar_fcp_put(struct rcar_fcp_device *fcp) { } - static inline int rcar_fcp_enable(struct rcar_fcp_device *fcp) - { -- return -ENOSYS; -+ return 0; - } - static inline void rcar_fcp_disable(struct rcar_fcp_device *fcp) { } - #endif -diff --git a/mm/gup.c b/mm/gup.c -index 96b2b2f..22cc22e 100644 ---- a/mm/gup.c -+++ b/mm/gup.c -@@ -60,6 +60,16 @@ static int follow_pfn_pte(struct vm_area_struct *vma, unsigned long address, - return -EEXIST; - } - -+/* -+ * FOLL_FORCE can write to even unwritable pte's, but only -+ * after we've gone through a COW cycle and they are dirty. -+ */ -+static inline bool can_follow_write_pte(pte_t pte, unsigned int flags) -+{ -+ return pte_write(pte) || -+ ((flags & FOLL_FORCE) && (flags & FOLL_COW) && pte_dirty(pte)); -+} -+ - static struct page *follow_page_pte(struct vm_area_struct *vma, - unsigned long address, pmd_t *pmd, unsigned int flags) - { -@@ -95,7 +105,7 @@ static struct page *follow_page_pte(struct vm_area_struct *vma, - } - if ((flags & FOLL_NUMA) && pte_protnone(pte)) - goto no_page; -- if ((flags & FOLL_WRITE) && !pte_write(pte)) { -+ if ((flags & FOLL_WRITE) && !can_follow_write_pte(pte, flags)) { - pte_unmap_unlock(ptep, ptl); - return NULL; - } -@@ -412,7 +422,7 @@ static int faultin_page(struct task_struct *tsk, struct vm_area_struct *vma, - * reCOWed by userspace write). - */ - if ((ret & VM_FAULT_WRITE) && !(vma->vm_flags & VM_WRITE)) -- *flags &= ~FOLL_WRITE; -+ *flags |= FOLL_COW; - return 0; - } - diff --git a/4.8.7/1003_linux-4.8.4.patch b/4.8.7/1003_linux-4.8.4.patch deleted file mode 100644 index b326925..0000000 --- a/4.8.7/1003_linux-4.8.4.patch +++ /dev/null @@ -1,2264 +0,0 @@ -diff --git a/MAINTAINERS b/MAINTAINERS -index f593300..babaf82 100644 ---- a/MAINTAINERS -+++ b/MAINTAINERS -@@ -12951,11 +12951,10 @@ F: arch/x86/xen/*swiotlb* - F: drivers/xen/*swiotlb* - - XFS FILESYSTEM --P: Silicon Graphics Inc - M: Dave Chinner <david@fromorbit.com> --M: xfs@oss.sgi.com --L: xfs@oss.sgi.com --W: http://oss.sgi.com/projects/xfs -+M: linux-xfs@vger.kernel.org -+L: linux-xfs@vger.kernel.org -+W: http://xfs.org/ - T: git git://git.kernel.org/pub/scm/linux/kernel/git/dgc/linux-xfs.git - S: Supported - F: Documentation/filesystems/xfs.txt -diff --git a/Makefile b/Makefile -index 42eb45c..82a36ab 100644 ---- a/Makefile -+++ b/Makefile -@@ -1,6 +1,6 @@ - VERSION = 4 - PATCHLEVEL = 8 --SUBLEVEL = 3 -+SUBLEVEL = 4 - EXTRAVERSION = - NAME = Psychotic Stoned Sheep - -diff --git a/arch/arc/include/asm/irqflags-arcv2.h b/arch/arc/include/asm/irqflags-arcv2.h -index d1ec7f6..e880dfa 100644 ---- a/arch/arc/include/asm/irqflags-arcv2.h -+++ b/arch/arc/include/asm/irqflags-arcv2.h -@@ -112,7 +112,7 @@ static inline long arch_local_save_flags(void) - */ - temp = (1 << 5) | - ((!!(temp & STATUS_IE_MASK)) << CLRI_STATUS_IE_BIT) | -- (temp & CLRI_STATUS_E_MASK); -+ ((temp >> 1) & CLRI_STATUS_E_MASK); - return temp; - } - -diff --git a/arch/arc/kernel/intc-arcv2.c b/arch/arc/kernel/intc-arcv2.c -index 6c24faf..62b59409 100644 ---- a/arch/arc/kernel/intc-arcv2.c -+++ b/arch/arc/kernel/intc-arcv2.c -@@ -74,7 +74,7 @@ void arc_init_IRQ(void) - tmp = read_aux_reg(0xa); - tmp |= STATUS_AD_MASK | (irq_prio << 1); - tmp &= ~STATUS_IE_MASK; -- asm volatile("flag %0 \n"::"r"(tmp)); -+ asm volatile("kflag %0 \n"::"r"(tmp)); - } - - static void arcv2_irq_mask(struct irq_data *data) -diff --git a/block/cfq-iosched.c b/block/cfq-iosched.c -index cc2f6db..5e24d88 100644 ---- a/block/cfq-iosched.c -+++ b/block/cfq-iosched.c -@@ -3042,7 +3042,6 @@ static struct request *cfq_check_fifo(struct cfq_queue *cfqq) - if (ktime_get_ns() < rq->fifo_time) - rq = NULL; - -- cfq_log_cfqq(cfqq->cfqd, cfqq, "fifo=%p", rq); - return rq; - } - -@@ -3420,6 +3419,9 @@ static bool cfq_may_dispatch(struct cfq_data *cfqd, struct cfq_queue *cfqq) - { - unsigned int max_dispatch; - -+ if (cfq_cfqq_must_dispatch(cfqq)) -+ return true; -+ - /* - * Drain async requests before we start sync IO - */ -@@ -3511,15 +3513,20 @@ static bool cfq_dispatch_request(struct cfq_data *cfqd, struct cfq_queue *cfqq) - - BUG_ON(RB_EMPTY_ROOT(&cfqq->sort_list)); - -+ rq = cfq_check_fifo(cfqq); -+ if (rq) -+ cfq_mark_cfqq_must_dispatch(cfqq); -+ - if (!cfq_may_dispatch(cfqd, cfqq)) - return false; - - /* - * follow expired path, else get first next available - */ -- rq = cfq_check_fifo(cfqq); - if (!rq) - rq = cfqq->next_rq; -+ else -+ cfq_log_cfqq(cfqq->cfqd, cfqq, "fifo=%p", rq); - - /* - * insert request into driver dispatch list -@@ -3989,7 +3996,7 @@ cfq_should_preempt(struct cfq_data *cfqd, struct cfq_queue *new_cfqq, - * if the new request is sync, but the currently running queue is - * not, let the sync request have priority. - */ -- if (rq_is_sync(rq) && !cfq_cfqq_sync(cfqq)) -+ if (rq_is_sync(rq) && !cfq_cfqq_sync(cfqq) && !cfq_cfqq_must_dispatch(cfqq)) - return true; - - /* -diff --git a/crypto/async_tx/async_pq.c b/crypto/async_tx/async_pq.c -index 08b3ac6..f83de99 100644 ---- a/crypto/async_tx/async_pq.c -+++ b/crypto/async_tx/async_pq.c -@@ -368,8 +368,6 @@ async_syndrome_val(struct page **blocks, unsigned int offset, int disks, - - dma_set_unmap(tx, unmap); - async_tx_submit(chan, tx, submit); -- -- return tx; - } else { - struct page *p_src = P(blocks, disks); - struct page *q_src = Q(blocks, disks); -@@ -424,9 +422,11 @@ async_syndrome_val(struct page **blocks, unsigned int offset, int disks, - submit->cb_param = cb_param_orig; - submit->flags = flags_orig; - async_tx_sync_epilog(submit); -- -- return NULL; -+ tx = NULL; - } -+ dmaengine_unmap_put(unmap); -+ -+ return tx; - } - EXPORT_SYMBOL_GPL(async_syndrome_val); - -diff --git a/crypto/ghash-generic.c b/crypto/ghash-generic.c -index bac7099..12ad3e3 100644 ---- a/crypto/ghash-generic.c -+++ b/crypto/ghash-generic.c -@@ -14,24 +14,13 @@ - - #include <crypto/algapi.h> - #include <crypto/gf128mul.h> -+#include <crypto/ghash.h> - #include <crypto/internal/hash.h> - #include <linux/crypto.h> - #include <linux/init.h> - #include <linux/kernel.h> - #include <linux/module.h> - --#define GHASH_BLOCK_SIZE 16 --#define GHASH_DIGEST_SIZE 16 -- --struct ghash_ctx { -- struct gf128mul_4k *gf128; --}; -- --struct ghash_desc_ctx { -- u8 buffer[GHASH_BLOCK_SIZE]; -- u32 bytes; --}; -- - static int ghash_init(struct shash_desc *desc) - { - struct ghash_desc_ctx *dctx = shash_desc_ctx(desc); -diff --git a/drivers/acpi/nfit/core.c b/drivers/acpi/nfit/core.c -index e1d5ea6..2accf78 100644 ---- a/drivers/acpi/nfit/core.c -+++ b/drivers/acpi/nfit/core.c -@@ -2689,6 +2689,9 @@ static void acpi_nfit_notify(struct acpi_device *adev, u32 event) - - dev_dbg(dev, "%s: event: %d\n", __func__, event); - -+ if (event != NFIT_NOTIFY_UPDATE) -+ return; -+ - device_lock(dev); - if (!dev->driver) { - /* dev->driver may be null if we're being removed */ -diff --git a/drivers/acpi/nfit/nfit.h b/drivers/acpi/nfit/nfit.h -index e894ded..51d23f1 100644 ---- a/drivers/acpi/nfit/nfit.h -+++ b/drivers/acpi/nfit/nfit.h -@@ -78,6 +78,10 @@ enum { - NFIT_ARS_TIMEOUT = 90, - }; - -+enum nfit_root_notifiers { -+ NFIT_NOTIFY_UPDATE = 0x80, -+}; -+ - struct nfit_spa { - struct list_head list; - struct nd_region *nd_region; -diff --git a/drivers/base/dma-mapping.c b/drivers/base/dma-mapping.c -index d799662..261420d 100644 ---- a/drivers/base/dma-mapping.c -+++ b/drivers/base/dma-mapping.c -@@ -334,7 +334,7 @@ void dma_common_free_remap(void *cpu_addr, size_t size, unsigned long vm_flags) - return; - } - -- unmap_kernel_range((unsigned long)cpu_addr, size); -+ unmap_kernel_range((unsigned long)cpu_addr, PAGE_ALIGN(size)); - vunmap(cpu_addr); - } - #endif -diff --git a/drivers/clk/mvebu/cp110-system-controller.c b/drivers/clk/mvebu/cp110-system-controller.c -index 7fa42d6..f2303da 100644 ---- a/drivers/clk/mvebu/cp110-system-controller.c -+++ b/drivers/clk/mvebu/cp110-system-controller.c -@@ -81,13 +81,6 @@ enum { - #define CP110_GATE_EIP150 25 - #define CP110_GATE_EIP197 26 - --static struct clk *cp110_clks[CP110_CLK_NUM]; -- --static struct clk_onecell_data cp110_clk_data = { -- .clks = cp110_clks, -- .clk_num = CP110_CLK_NUM, --}; -- - struct cp110_gate_clk { - struct clk_hw hw; - struct regmap *regmap; -@@ -142,6 +135,8 @@ static struct clk *cp110_register_gate(const char *name, - if (!gate) - return ERR_PTR(-ENOMEM); - -+ memset(&init, 0, sizeof(init)); -+ - init.name = name; - init.ops = &cp110_gate_ops; - init.parent_names = &parent_name; -@@ -194,7 +189,8 @@ static int cp110_syscon_clk_probe(struct platform_device *pdev) - struct regmap *regmap; - struct device_node *np = pdev->dev.of_node; - const char *ppv2_name, *apll_name, *core_name, *eip_name, *nand_name; -- struct clk *clk; -+ struct clk_onecell_data *cp110_clk_data; -+ struct clk *clk, **cp110_clks; - u32 nand_clk_ctrl; - int i, ret; - -@@ -207,6 +203,20 @@ static int cp110_syscon_clk_probe(struct platform_device *pdev) - if (ret) - return ret; - -+ cp110_clks = devm_kcalloc(&pdev->dev, sizeof(struct clk *), -+ CP110_CLK_NUM, GFP_KERNEL); -+ if (!cp110_clks) -+ return -ENOMEM; -+ -+ cp110_clk_data = devm_kzalloc(&pdev->dev, -+ sizeof(*cp110_clk_data), -+ GFP_KERNEL); -+ if (!cp110_clk_data) -+ return -ENOMEM; -+ -+ cp110_clk_data->clks = cp110_clks; -+ cp110_clk_data->clk_num = CP110_CLK_NUM; -+ - /* Register the APLL which is the root of the clk tree */ - of_property_read_string_index(np, "core-clock-output-names", - CP110_CORE_APLL, &apll_name); -@@ -334,10 +344,12 @@ static int cp110_syscon_clk_probe(struct platform_device *pdev) - cp110_clks[CP110_MAX_CORE_CLOCKS + i] = clk; - } - -- ret = of_clk_add_provider(np, cp110_of_clk_get, &cp110_clk_data); -+ ret = of_clk_add_provider(np, cp110_of_clk_get, cp110_clk_data); - if (ret) - goto fail_clk_add; - -+ platform_set_drvdata(pdev, cp110_clks); -+ - return 0; - - fail_clk_add: -@@ -364,6 +376,7 @@ static int cp110_syscon_clk_probe(struct platform_device *pdev) - - static int cp110_syscon_clk_remove(struct platform_device *pdev) - { -+ struct clk **cp110_clks = platform_get_drvdata(pdev); - int i; - - of_clk_del_provider(pdev->dev.of_node); -diff --git a/drivers/crypto/vmx/ghash.c b/drivers/crypto/vmx/ghash.c -index 6c999cb0..27a94a1 100644 ---- a/drivers/crypto/vmx/ghash.c -+++ b/drivers/crypto/vmx/ghash.c -@@ -26,16 +26,13 @@ - #include <linux/hardirq.h> - #include <asm/switch_to.h> - #include <crypto/aes.h> -+#include <crypto/ghash.h> - #include <crypto/scatterwalk.h> - #include <crypto/internal/hash.h> - #include <crypto/b128ops.h> - - #define IN_INTERRUPT in_interrupt() - --#define GHASH_BLOCK_SIZE (16) --#define GHASH_DIGEST_SIZE (16) --#define GHASH_KEY_LEN (16) -- - void gcm_init_p8(u128 htable[16], const u64 Xi[2]); - void gcm_gmult_p8(u64 Xi[2], const u128 htable[16]); - void gcm_ghash_p8(u64 Xi[2], const u128 htable[16], -@@ -55,16 +52,11 @@ struct p8_ghash_desc_ctx { - - static int p8_ghash_init_tfm(struct crypto_tfm *tfm) - { -- const char *alg; -+ const char *alg = "ghash-generic"; - struct crypto_shash *fallback; - struct crypto_shash *shash_tfm = __crypto_shash_cast(tfm); - struct p8_ghash_ctx *ctx = crypto_tfm_ctx(tfm); - -- if (!(alg = crypto_tfm_alg_name(tfm))) { -- printk(KERN_ERR "Failed to get algorithm name.\n"); -- return -ENOENT; -- } -- - fallback = crypto_alloc_shash(alg, 0, CRYPTO_ALG_NEED_FALLBACK); - if (IS_ERR(fallback)) { - printk(KERN_ERR -@@ -78,10 +70,18 @@ static int p8_ghash_init_tfm(struct crypto_tfm *tfm) - crypto_shash_set_flags(fallback, - crypto_shash_get_flags((struct crypto_shash - *) tfm)); -- ctx->fallback = fallback; - -- shash_tfm->descsize = sizeof(struct p8_ghash_desc_ctx) -- + crypto_shash_descsize(fallback); -+ /* Check if the descsize defined in the algorithm is still enough. */ -+ if (shash_tfm->descsize < sizeof(struct p8_ghash_desc_ctx) -+ + crypto_shash_descsize(fallback)) { -+ printk(KERN_ERR -+ "Desc size of the fallback implementation (%s) does not match the expected value: %lu vs %u\n", -+ alg, -+ shash_tfm->descsize - sizeof(struct p8_ghash_desc_ctx), -+ crypto_shash_descsize(fallback)); -+ return -EINVAL; -+ } -+ ctx->fallback = fallback; - - return 0; - } -@@ -113,7 +113,7 @@ static int p8_ghash_setkey(struct crypto_shash *tfm, const u8 *key, - { - struct p8_ghash_ctx *ctx = crypto_tfm_ctx(crypto_shash_tfm(tfm)); - -- if (keylen != GHASH_KEY_LEN) -+ if (keylen != GHASH_BLOCK_SIZE) - return -EINVAL; - - preempt_disable(); -@@ -211,7 +211,8 @@ struct shash_alg p8_ghash_alg = { - .update = p8_ghash_update, - .final = p8_ghash_final, - .setkey = p8_ghash_setkey, -- .descsize = sizeof(struct p8_ghash_desc_ctx), -+ .descsize = sizeof(struct p8_ghash_desc_ctx) -+ + sizeof(struct ghash_desc_ctx), - .base = { - .cra_name = "ghash", - .cra_driver_name = "p8_ghash", -diff --git a/drivers/gpu/drm/virtio/virtgpu_drm_bus.c b/drivers/gpu/drm/virtio/virtgpu_drm_bus.c -index 7f0e93f87..88a3916 100644 ---- a/drivers/gpu/drm/virtio/virtgpu_drm_bus.c -+++ b/drivers/gpu/drm/virtio/virtgpu_drm_bus.c -@@ -27,6 +27,16 @@ - - #include "virtgpu_drv.h" - -+int drm_virtio_set_busid(struct drm_device *dev, struct drm_master *master) -+{ -+ struct pci_dev *pdev = dev->pdev; -+ -+ if (pdev) { -+ return drm_pci_set_busid(dev, master); -+ } -+ return 0; -+} -+ - static void virtio_pci_kick_out_firmware_fb(struct pci_dev *pci_dev) - { - struct apertures_struct *ap; -diff --git a/drivers/gpu/drm/virtio/virtgpu_drv.c b/drivers/gpu/drm/virtio/virtgpu_drv.c -index c13f70c..5820b702 100644 ---- a/drivers/gpu/drm/virtio/virtgpu_drv.c -+++ b/drivers/gpu/drm/virtio/virtgpu_drv.c -@@ -117,6 +117,7 @@ static const struct file_operations virtio_gpu_driver_fops = { - - static struct drm_driver driver = { - .driver_features = DRIVER_MODESET | DRIVER_GEM | DRIVER_PRIME | DRIVER_RENDER | DRIVER_ATOMIC, -+ .set_busid = drm_virtio_set_busid, - .load = virtio_gpu_driver_load, - .unload = virtio_gpu_driver_unload, - .open = virtio_gpu_driver_open, -diff --git a/drivers/gpu/drm/virtio/virtgpu_drv.h b/drivers/gpu/drm/virtio/virtgpu_drv.h -index b18ef31..acf556a 100644 ---- a/drivers/gpu/drm/virtio/virtgpu_drv.h -+++ b/drivers/gpu/drm/virtio/virtgpu_drv.h -@@ -49,6 +49,7 @@ - #define DRIVER_PATCHLEVEL 1 - - /* virtgpu_drm_bus.c */ -+int drm_virtio_set_busid(struct drm_device *dev, struct drm_master *master); - int drm_virtio_init(struct drm_driver *driver, struct virtio_device *vdev); - - struct virtio_gpu_object { -diff --git a/drivers/infiniband/hw/hfi1/rc.c b/drivers/infiniband/hw/hfi1/rc.c -index 5da190e..bcf76c3 100644 ---- a/drivers/infiniband/hw/hfi1/rc.c -+++ b/drivers/infiniband/hw/hfi1/rc.c -@@ -932,8 +932,10 @@ void hfi1_send_rc_ack(struct hfi1_ctxtdata *rcd, struct rvt_qp *qp, - return; - - queue_ack: -- this_cpu_inc(*ibp->rvp.rc_qacks); - spin_lock_irqsave(&qp->s_lock, flags); -+ if (!(ib_rvt_state_ops[qp->state] & RVT_PROCESS_RECV_OK)) -+ goto unlock; -+ this_cpu_inc(*ibp->rvp.rc_qacks); - qp->s_flags |= RVT_S_ACK_PENDING | RVT_S_RESP_PENDING; - qp->s_nak_state = qp->r_nak_state; - qp->s_ack_psn = qp->r_ack_psn; -@@ -942,6 +944,7 @@ void hfi1_send_rc_ack(struct hfi1_ctxtdata *rcd, struct rvt_qp *qp, - - /* Schedule the send tasklet. */ - hfi1_schedule_send(qp); -+unlock: - spin_unlock_irqrestore(&qp->s_lock, flags); - } - -diff --git a/drivers/misc/mei/amthif.c b/drivers/misc/mei/amthif.c -index a039a5d..fd9271b 100644 ---- a/drivers/misc/mei/amthif.c -+++ b/drivers/misc/mei/amthif.c -@@ -67,8 +67,12 @@ int mei_amthif_host_init(struct mei_device *dev, struct mei_me_client *me_cl) - struct mei_cl *cl = &dev->iamthif_cl; - int ret; - -- if (mei_cl_is_connected(cl)) -- return 0; -+ mutex_lock(&dev->device_lock); -+ -+ if (mei_cl_is_connected(cl)) { -+ ret = 0; -+ goto out; -+ } - - dev->iamthif_state = MEI_IAMTHIF_IDLE; - -@@ -77,11 +81,13 @@ int mei_amthif_host_init(struct mei_device *dev, struct mei_me_client *me_cl) - ret = mei_cl_link(cl); - if (ret < 0) { - dev_err(dev->dev, "amthif: failed cl_link %d\n", ret); -- return ret; -+ goto out; - } - - ret = mei_cl_connect(cl, me_cl, NULL); - -+out: -+ mutex_unlock(&dev->device_lock); - return ret; - } - -diff --git a/drivers/misc/mei/bus.c b/drivers/misc/mei/bus.c -index 1f33fea..e094df3 100644 ---- a/drivers/misc/mei/bus.c -+++ b/drivers/misc/mei/bus.c -@@ -983,12 +983,10 @@ void mei_cl_bus_rescan_work(struct work_struct *work) - container_of(work, struct mei_device, bus_rescan_work); - struct mei_me_client *me_cl; - -- mutex_lock(&bus->device_lock); - me_cl = mei_me_cl_by_uuid(bus, &mei_amthif_guid); - if (me_cl) - mei_amthif_host_init(bus, me_cl); - mei_me_cl_put(me_cl); -- mutex_unlock(&bus->device_lock); - - mei_cl_bus_rescan(bus); - } -diff --git a/drivers/net/ethernet/intel/i40e/i40e_main.c b/drivers/net/ethernet/intel/i40e/i40e_main.c -index d0b3a1b..dad15b6 100644 ---- a/drivers/net/ethernet/intel/i40e/i40e_main.c -+++ b/drivers/net/ethernet/intel/i40e/i40e_main.c -@@ -11360,6 +11360,12 @@ static pci_ers_result_t i40e_pci_error_detected(struct pci_dev *pdev, - - dev_info(&pdev->dev, "%s: error %d\n", __func__, error); - -+ if (!pf) { -+ dev_info(&pdev->dev, -+ "Cannot recover - error happened during device probe\n"); -+ return PCI_ERS_RESULT_DISCONNECT; -+ } -+ - /* shutdown all operations */ - if (!test_bit(__I40E_SUSPENDED, &pf->state)) { - rtnl_lock(); -diff --git a/drivers/net/wireless/ath/carl9170/debug.c b/drivers/net/wireless/ath/carl9170/debug.c -index 6808db4..ec3a64e 100644 ---- a/drivers/net/wireless/ath/carl9170/debug.c -+++ b/drivers/net/wireless/ath/carl9170/debug.c -@@ -75,7 +75,8 @@ static ssize_t carl9170_debugfs_read(struct file *file, char __user *userbuf, - - if (!ar) - return -ENODEV; -- dfops = container_of(file->f_op, struct carl9170_debugfs_fops, fops); -+ dfops = container_of(debugfs_real_fops(file), -+ struct carl9170_debugfs_fops, fops); - - if (!dfops->read) - return -ENOSYS; -@@ -127,7 +128,8 @@ static ssize_t carl9170_debugfs_write(struct file *file, - - if (!ar) - return -ENODEV; -- dfops = container_of(file->f_op, struct carl9170_debugfs_fops, fops); -+ dfops = container_of(debugfs_real_fops(file), -+ struct carl9170_debugfs_fops, fops); - - if (!dfops->write) - return -ENOSYS; -diff --git a/drivers/net/wireless/broadcom/b43/debugfs.c b/drivers/net/wireless/broadcom/b43/debugfs.c -index b4bcd94..7704638 100644 ---- a/drivers/net/wireless/broadcom/b43/debugfs.c -+++ b/drivers/net/wireless/broadcom/b43/debugfs.c -@@ -524,7 +524,8 @@ static ssize_t b43_debugfs_read(struct file *file, char __user *userbuf, - goto out_unlock; - } - -- dfops = container_of(file->f_op, struct b43_debugfs_fops, fops); -+ dfops = container_of(debugfs_real_fops(file), -+ struct b43_debugfs_fops, fops); - if (!dfops->read) { - err = -ENOSYS; - goto out_unlock; -@@ -585,7 +586,8 @@ static ssize_t b43_debugfs_write(struct file *file, - goto out_unlock; - } - -- dfops = container_of(file->f_op, struct b43_debugfs_fops, fops); -+ dfops = container_of(debugfs_real_fops(file), -+ struct b43_debugfs_fops, fops); - if (!dfops->write) { - err = -ENOSYS; - goto out_unlock; -diff --git a/drivers/net/wireless/broadcom/b43legacy/debugfs.c b/drivers/net/wireless/broadcom/b43legacy/debugfs.c -index 090910e..82ef56e 100644 ---- a/drivers/net/wireless/broadcom/b43legacy/debugfs.c -+++ b/drivers/net/wireless/broadcom/b43legacy/debugfs.c -@@ -221,7 +221,8 @@ static ssize_t b43legacy_debugfs_read(struct file *file, char __user *userbuf, - goto out_unlock; - } - -- dfops = container_of(file->f_op, struct b43legacy_debugfs_fops, fops); -+ dfops = container_of(debugfs_real_fops(file), -+ struct b43legacy_debugfs_fops, fops); - if (!dfops->read) { - err = -ENOSYS; - goto out_unlock; -@@ -287,7 +288,8 @@ static ssize_t b43legacy_debugfs_write(struct file *file, - goto out_unlock; - } - -- dfops = container_of(file->f_op, struct b43legacy_debugfs_fops, fops); -+ dfops = container_of(debugfs_real_fops(file), -+ struct b43legacy_debugfs_fops, fops); - if (!dfops->write) { - err = -ENOSYS; - goto out_unlock; -diff --git a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c -index b8aec5e5..abaf003 100644 ---- a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c -+++ b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c -@@ -2533,7 +2533,7 @@ static void brcmf_fill_bss_param(struct brcmf_if *ifp, struct station_info *si) - WL_BSS_INFO_MAX); - if (err) { - brcmf_err("Failed to get bss info (%d)\n", err); -- return; -+ goto out_kfree; - } - si->filled |= BIT(NL80211_STA_INFO_BSS_PARAM); - si->bss_param.beacon_interval = le16_to_cpu(buf->bss_le.beacon_period); -@@ -2545,6 +2545,9 @@ static void brcmf_fill_bss_param(struct brcmf_if *ifp, struct station_info *si) - si->bss_param.flags |= BSS_PARAM_FLAGS_SHORT_PREAMBLE; - if (capability & WLAN_CAPABILITY_SHORT_SLOT_TIME) - si->bss_param.flags |= BSS_PARAM_FLAGS_SHORT_SLOT_TIME; -+ -+out_kfree: -+ kfree(buf); - } - - static s32 -@@ -3884,11 +3887,11 @@ brcmf_cfg80211_del_pmksa(struct wiphy *wiphy, struct net_device *ndev, - if (!check_vif_up(ifp->vif)) - return -EIO; - -- brcmf_dbg(CONN, "del_pmksa - PMK bssid = %pM\n", &pmksa->bssid); -+ brcmf_dbg(CONN, "del_pmksa - PMK bssid = %pM\n", pmksa->bssid); - - npmk = le32_to_cpu(cfg->pmk_list.npmk); - for (i = 0; i < npmk; i++) -- if (!memcmp(&pmksa->bssid, &pmk[i].bssid, ETH_ALEN)) -+ if (!memcmp(pmksa->bssid, pmk[i].bssid, ETH_ALEN)) - break; - - if ((npmk > 0) && (i < npmk)) { -diff --git a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/flowring.c b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/flowring.c -index 7e269f9..6366444 100644 ---- a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/flowring.c -+++ b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/flowring.c -@@ -234,13 +234,20 @@ static void brcmf_flowring_block(struct brcmf_flowring *flow, u16 flowid, - - void brcmf_flowring_delete(struct brcmf_flowring *flow, u16 flowid) - { -+ struct brcmf_bus *bus_if = dev_get_drvdata(flow->dev); - struct brcmf_flowring_ring *ring; -+ struct brcmf_if *ifp; - u16 hash_idx; -+ u8 ifidx; - struct sk_buff *skb; - - ring = flow->rings[flowid]; - if (!ring) - return; -+ -+ ifidx = brcmf_flowring_ifidx_get(flow, flowid); -+ ifp = brcmf_get_ifp(bus_if->drvr, ifidx); -+ - brcmf_flowring_block(flow, flowid, false); - hash_idx = ring->hash_id; - flow->hash[hash_idx].ifidx = BRCMF_FLOWRING_INVALID_IFIDX; -@@ -249,7 +256,7 @@ void brcmf_flowring_delete(struct brcmf_flowring *flow, u16 flowid) - - skb = skb_dequeue(&ring->skblist); - while (skb) { -- brcmu_pkt_buf_free_skb(skb); -+ brcmf_txfinalize(ifp, skb, false); - skb = skb_dequeue(&ring->skblist); - } - -diff --git a/drivers/scsi/arcmsr/arcmsr_hba.c b/drivers/scsi/arcmsr/arcmsr_hba.c -index 7640498..3d53d63 100644 ---- a/drivers/scsi/arcmsr/arcmsr_hba.c -+++ b/drivers/scsi/arcmsr/arcmsr_hba.c -@@ -2388,15 +2388,23 @@ static int arcmsr_iop_message_xfer(struct AdapterControlBlock *acb, - } - case ARCMSR_MESSAGE_WRITE_WQBUFFER: { - unsigned char *ver_addr; -- int32_t user_len, cnt2end; -+ uint32_t user_len; -+ int32_t cnt2end; - uint8_t *pQbuffer, *ptmpuserbuffer; -+ -+ user_len = pcmdmessagefld->cmdmessage.Length; -+ if (user_len > ARCMSR_API_DATA_BUFLEN) { -+ retvalue = ARCMSR_MESSAGE_FAIL; -+ goto message_out; -+ } -+ - ver_addr = kmalloc(ARCMSR_API_DATA_BUFLEN, GFP_ATOMIC); - if (!ver_addr) { - retvalue = ARCMSR_MESSAGE_FAIL; - goto message_out; - } - ptmpuserbuffer = ver_addr; -- user_len = pcmdmessagefld->cmdmessage.Length; -+ - memcpy(ptmpuserbuffer, - pcmdmessagefld->messagedatabuffer, user_len); - spin_lock_irqsave(&acb->wqbuffer_lock, flags); -diff --git a/drivers/scsi/ibmvscsi/ibmvfc.c b/drivers/scsi/ibmvscsi/ibmvfc.c -index ab67ec4..79c9860 100644 ---- a/drivers/scsi/ibmvscsi/ibmvfc.c -+++ b/drivers/scsi/ibmvscsi/ibmvfc.c -@@ -717,7 +717,6 @@ static int ibmvfc_reset_crq(struct ibmvfc_host *vhost) - spin_lock_irqsave(vhost->host->host_lock, flags); - vhost->state = IBMVFC_NO_CRQ; - vhost->logged_in = 0; -- ibmvfc_set_host_action(vhost, IBMVFC_HOST_ACTION_NONE); - - /* Clean out the queue */ - memset(crq->msgs, 0, PAGE_SIZE); -diff --git a/drivers/tty/serial/8250/8250_dw.c b/drivers/tty/serial/8250/8250_dw.c -index e199696..b022f5a 100644 ---- a/drivers/tty/serial/8250/8250_dw.c -+++ b/drivers/tty/serial/8250/8250_dw.c -@@ -462,7 +462,7 @@ static int dw8250_probe(struct platform_device *pdev) - } - - data->pclk = devm_clk_get(&pdev->dev, "apb_pclk"); -- if (IS_ERR(data->clk) && PTR_ERR(data->clk) == -EPROBE_DEFER) { -+ if (IS_ERR(data->pclk) && PTR_ERR(data->pclk) == -EPROBE_DEFER) { - err = -EPROBE_DEFER; - goto err_clk; - } -diff --git a/drivers/tty/serial/8250/8250_port.c b/drivers/tty/serial/8250/8250_port.c -index bdfa659..858a546 100644 ---- a/drivers/tty/serial/8250/8250_port.c -+++ b/drivers/tty/serial/8250/8250_port.c -@@ -1414,12 +1414,8 @@ static void __do_stop_tx_rs485(struct uart_8250_port *p) - if (!(p->port.rs485.flags & SER_RS485_RX_DURING_TX)) { - serial8250_clear_fifos(p); - -- serial8250_rpm_get(p); -- - p->ier |= UART_IER_RLSI | UART_IER_RDI; - serial_port_out(&p->port, UART_IER, p->ier); -- -- serial8250_rpm_put(p); - } - } - -@@ -1429,6 +1425,7 @@ static void serial8250_em485_handle_stop_tx(unsigned long arg) - struct uart_8250_em485 *em485 = p->em485; - unsigned long flags; - -+ serial8250_rpm_get(p); - spin_lock_irqsave(&p->port.lock, flags); - if (em485 && - em485->active_timer == &em485->stop_tx_timer) { -@@ -1436,6 +1433,7 @@ static void serial8250_em485_handle_stop_tx(unsigned long arg) - em485->active_timer = NULL; - } - spin_unlock_irqrestore(&p->port.lock, flags); -+ serial8250_rpm_put(p); - } - - static void __stop_tx_rs485(struct uart_8250_port *p) -@@ -1475,7 +1473,7 @@ static inline void __stop_tx(struct uart_8250_port *p) - unsigned char lsr = serial_in(p, UART_LSR); - /* - * To provide required timeing and allow FIFO transfer, -- * __stop_tx_rs485 must be called only when both FIFO and -+ * __stop_tx_rs485() must be called only when both FIFO and - * shift register are empty. It is for device driver to enable - * interrupt on TEMT. - */ -@@ -1484,9 +1482,10 @@ static inline void __stop_tx(struct uart_8250_port *p) - - del_timer(&em485->start_tx_timer); - em485->active_timer = NULL; -+ -+ __stop_tx_rs485(p); - } - __do_stop_tx(p); -- __stop_tx_rs485(p); - } - - static void serial8250_stop_tx(struct uart_port *port) -diff --git a/drivers/tty/serial/atmel_serial.c b/drivers/tty/serial/atmel_serial.c -index 2eaa18d..8bbde52 100644 ---- a/drivers/tty/serial/atmel_serial.c -+++ b/drivers/tty/serial/atmel_serial.c -@@ -1929,6 +1929,9 @@ static void atmel_shutdown(struct uart_port *port) - { - struct atmel_uart_port *atmel_port = to_atmel_uart_port(port); - -+ /* Disable modem control lines interrupts */ -+ atmel_disable_ms(port); -+ - /* Disable interrupts at device level */ - atmel_uart_writel(port, ATMEL_US_IDR, -1); - -@@ -1979,8 +1982,6 @@ static void atmel_shutdown(struct uart_port *port) - */ - free_irq(port->irq, port); - -- atmel_port->ms_irq_enabled = false; -- - atmel_flush_buffer(port); - } - -diff --git a/drivers/tty/serial/imx.c b/drivers/tty/serial/imx.c -index 0df2b1c..615c027 100644 ---- a/drivers/tty/serial/imx.c -+++ b/drivers/tty/serial/imx.c -@@ -740,12 +740,13 @@ static unsigned int imx_get_hwmctrl(struct imx_port *sport) - { - unsigned int tmp = TIOCM_DSR; - unsigned usr1 = readl(sport->port.membase + USR1); -+ unsigned usr2 = readl(sport->port.membase + USR2); - - if (usr1 & USR1_RTSS) - tmp |= TIOCM_CTS; - - /* in DCE mode DCDIN is always 0 */ -- if (!(usr1 & USR2_DCDIN)) -+ if (!(usr2 & USR2_DCDIN)) - tmp |= TIOCM_CAR; - - if (sport->dte_mode) -diff --git a/fs/attr.c b/fs/attr.c -index 42bb42b..3c42cab 100644 ---- a/fs/attr.c -+++ b/fs/attr.c -@@ -202,6 +202,21 @@ int notify_change(struct dentry * dentry, struct iattr * attr, struct inode **de - return -EPERM; - } - -+ /* -+ * If utimes(2) and friends are called with times == NULL (or both -+ * times are UTIME_NOW), then we need to check for write permission -+ */ -+ if (ia_valid & ATTR_TOUCH) { -+ if (IS_IMMUTABLE(inode)) -+ return -EPERM; -+ -+ if (!inode_owner_or_capable(inode)) { -+ error = inode_permission(inode, MAY_WRITE); -+ if (error) -+ return error; -+ } -+ } -+ - if ((ia_valid & ATTR_MODE)) { - umode_t amode = attr->ia_mode; - /* Flag setting protected by i_mutex */ -diff --git a/fs/autofs4/waitq.c b/fs/autofs4/waitq.c -index 431fd7e..e44271d 100644 ---- a/fs/autofs4/waitq.c -+++ b/fs/autofs4/waitq.c -@@ -431,8 +431,8 @@ int autofs4_wait(struct autofs_sb_info *sbi, - memcpy(&wq->name, &qstr, sizeof(struct qstr)); - wq->dev = autofs4_get_dev(sbi); - wq->ino = autofs4_get_ino(sbi); -- wq->uid = current_uid(); -- wq->gid = current_gid(); -+ wq->uid = current_real_cred()->uid; -+ wq->gid = current_real_cred()->gid; - wq->pid = pid; - wq->tgid = tgid; - wq->status = -EINTR; /* Status return if interrupted */ -diff --git a/fs/btrfs/compression.c b/fs/btrfs/compression.c -index 029db6e..60a850e 100644 ---- a/fs/btrfs/compression.c -+++ b/fs/btrfs/compression.c -@@ -698,7 +698,7 @@ int btrfs_submit_compressed_read(struct inode *inode, struct bio *bio, - - ret = btrfs_map_bio(root, comp_bio, mirror_num, 0); - if (ret) { -- bio->bi_error = ret; -+ comp_bio->bi_error = ret; - bio_endio(comp_bio); - } - -@@ -728,7 +728,7 @@ int btrfs_submit_compressed_read(struct inode *inode, struct bio *bio, - - ret = btrfs_map_bio(root, comp_bio, mirror_num, 0); - if (ret) { -- bio->bi_error = ret; -+ comp_bio->bi_error = ret; - bio_endio(comp_bio); - } - -diff --git a/fs/btrfs/ctree.h b/fs/btrfs/ctree.h -index 33fe035..791e47c 100644 ---- a/fs/btrfs/ctree.h -+++ b/fs/btrfs/ctree.h -@@ -251,7 +251,8 @@ struct btrfs_super_block { - #define BTRFS_FEATURE_COMPAT_SAFE_CLEAR 0ULL - - #define BTRFS_FEATURE_COMPAT_RO_SUPP \ -- (BTRFS_FEATURE_COMPAT_RO_FREE_SPACE_TREE) -+ (BTRFS_FEATURE_COMPAT_RO_FREE_SPACE_TREE | \ -+ BTRFS_FEATURE_COMPAT_RO_FREE_SPACE_TREE_VALID) - - #define BTRFS_FEATURE_COMPAT_RO_SAFE_SET 0ULL - #define BTRFS_FEATURE_COMPAT_RO_SAFE_CLEAR 0ULL -diff --git a/fs/btrfs/disk-io.c b/fs/btrfs/disk-io.c -index 54bc8c7..3dede6d 100644 ---- a/fs/btrfs/disk-io.c -+++ b/fs/btrfs/disk-io.c -@@ -2566,6 +2566,7 @@ int open_ctree(struct super_block *sb, - int num_backups_tried = 0; - int backup_index = 0; - int max_active; -+ int clear_free_space_tree = 0; - - tree_root = fs_info->tree_root = btrfs_alloc_root(fs_info, GFP_KERNEL); - chunk_root = fs_info->chunk_root = btrfs_alloc_root(fs_info, GFP_KERNEL); -@@ -3129,6 +3130,26 @@ int open_ctree(struct super_block *sb, - if (sb->s_flags & MS_RDONLY) - return 0; - -+ if (btrfs_test_opt(fs_info, CLEAR_CACHE) && -+ btrfs_fs_compat_ro(fs_info, FREE_SPACE_TREE)) { -+ clear_free_space_tree = 1; -+ } else if (btrfs_fs_compat_ro(fs_info, FREE_SPACE_TREE) && -+ !btrfs_fs_compat_ro(fs_info, FREE_SPACE_TREE_VALID)) { -+ btrfs_warn(fs_info, "free space tree is invalid"); -+ clear_free_space_tree = 1; -+ } -+ -+ if (clear_free_space_tree) { -+ btrfs_info(fs_info, "clearing free space tree"); -+ ret = btrfs_clear_free_space_tree(fs_info); -+ if (ret) { -+ btrfs_warn(fs_info, -+ "failed to clear free space tree: %d", ret); -+ close_ctree(tree_root); -+ return ret; -+ } -+ } -+ - if (btrfs_test_opt(tree_root->fs_info, FREE_SPACE_TREE) && - !btrfs_fs_compat_ro(fs_info, FREE_SPACE_TREE)) { - btrfs_info(fs_info, "creating free space tree"); -@@ -3166,18 +3187,6 @@ int open_ctree(struct super_block *sb, - - btrfs_qgroup_rescan_resume(fs_info); - -- if (btrfs_test_opt(tree_root->fs_info, CLEAR_CACHE) && -- btrfs_fs_compat_ro(fs_info, FREE_SPACE_TREE)) { -- btrfs_info(fs_info, "clearing free space tree"); -- ret = btrfs_clear_free_space_tree(fs_info); -- if (ret) { -- btrfs_warn(fs_info, -- "failed to clear free space tree: %d", ret); -- close_ctree(tree_root); -- return ret; -- } -- } -- - if (!fs_info->uuid_root) { - btrfs_info(fs_info, "creating UUID tree"); - ret = btrfs_create_uuid_tree(fs_info); -diff --git a/fs/btrfs/extent_io.c b/fs/btrfs/extent_io.c -index 44fe66b..c3ec30d 100644 ---- a/fs/btrfs/extent_io.c -+++ b/fs/btrfs/extent_io.c -@@ -5524,17 +5524,45 @@ void copy_extent_buffer(struct extent_buffer *dst, struct extent_buffer *src, - } - } - --/* -- * The extent buffer bitmap operations are done with byte granularity because -- * bitmap items are not guaranteed to be aligned to a word and therefore a -- * single word in a bitmap may straddle two pages in the extent buffer. -- */ --#define BIT_BYTE(nr) ((nr) / BITS_PER_BYTE) --#define BYTE_MASK ((1 << BITS_PER_BYTE) - 1) --#define BITMAP_FIRST_BYTE_MASK(start) \ -- ((BYTE_MASK << ((start) & (BITS_PER_BYTE - 1))) & BYTE_MASK) --#define BITMAP_LAST_BYTE_MASK(nbits) \ -- (BYTE_MASK >> (-(nbits) & (BITS_PER_BYTE - 1))) -+void le_bitmap_set(u8 *map, unsigned int start, int len) -+{ -+ u8 *p = map + BIT_BYTE(start); -+ const unsigned int size = start + len; -+ int bits_to_set = BITS_PER_BYTE - (start % BITS_PER_BYTE); -+ u8 mask_to_set = BITMAP_FIRST_BYTE_MASK(start); -+ -+ while (len - bits_to_set >= 0) { -+ *p |= mask_to_set; -+ len -= bits_to_set; -+ bits_to_set = BITS_PER_BYTE; -+ mask_to_set = ~(u8)0; -+ p++; -+ } -+ if (len) { -+ mask_to_set &= BITMAP_LAST_BYTE_MASK(size); -+ *p |= mask_to_set; -+ } -+} -+ -+void le_bitmap_clear(u8 *map, unsigned int start, int len) -+{ -+ u8 *p = map + BIT_BYTE(start); -+ const unsigned int size = start + len; -+ int bits_to_clear = BITS_PER_BYTE - (start % BITS_PER_BYTE); -+ u8 mask_to_clear = BITMAP_FIRST_BYTE_MASK(start); -+ -+ while (len - bits_to_clear >= 0) { -+ *p &= ~mask_to_clear; -+ len -= bits_to_clear; -+ bits_to_clear = BITS_PER_BYTE; -+ mask_to_clear = ~(u8)0; -+ p++; -+ } -+ if (len) { -+ mask_to_clear &= BITMAP_LAST_BYTE_MASK(size); -+ *p &= ~mask_to_clear; -+ } -+} - - /* - * eb_bitmap_offset() - calculate the page and offset of the byte containing the -@@ -5578,7 +5606,7 @@ static inline void eb_bitmap_offset(struct extent_buffer *eb, - int extent_buffer_test_bit(struct extent_buffer *eb, unsigned long start, - unsigned long nr) - { -- char *kaddr; -+ u8 *kaddr; - struct page *page; - unsigned long i; - size_t offset; -@@ -5600,13 +5628,13 @@ int extent_buffer_test_bit(struct extent_buffer *eb, unsigned long start, - void extent_buffer_bitmap_set(struct extent_buffer *eb, unsigned long start, - unsigned long pos, unsigned long len) - { -- char *kaddr; -+ u8 *kaddr; - struct page *page; - unsigned long i; - size_t offset; - const unsigned int size = pos + len; - int bits_to_set = BITS_PER_BYTE - (pos % BITS_PER_BYTE); -- unsigned int mask_to_set = BITMAP_FIRST_BYTE_MASK(pos); -+ u8 mask_to_set = BITMAP_FIRST_BYTE_MASK(pos); - - eb_bitmap_offset(eb, start, pos, &i, &offset); - page = eb->pages[i]; -@@ -5617,7 +5645,7 @@ void extent_buffer_bitmap_set(struct extent_buffer *eb, unsigned long start, - kaddr[offset] |= mask_to_set; - len -= bits_to_set; - bits_to_set = BITS_PER_BYTE; -- mask_to_set = ~0U; -+ mask_to_set = ~(u8)0; - if (++offset >= PAGE_SIZE && len > 0) { - offset = 0; - page = eb->pages[++i]; -@@ -5642,13 +5670,13 @@ void extent_buffer_bitmap_set(struct extent_buffer *eb, unsigned long start, - void extent_buffer_bitmap_clear(struct extent_buffer *eb, unsigned long start, - unsigned long pos, unsigned long len) - { -- char *kaddr; -+ u8 *kaddr; - struct page *page; - unsigned long i; - size_t offset; - const unsigned int size = pos + len; - int bits_to_clear = BITS_PER_BYTE - (pos % BITS_PER_BYTE); -- unsigned int mask_to_clear = BITMAP_FIRST_BYTE_MASK(pos); -+ u8 mask_to_clear = BITMAP_FIRST_BYTE_MASK(pos); - - eb_bitmap_offset(eb, start, pos, &i, &offset); - page = eb->pages[i]; -@@ -5659,7 +5687,7 @@ void extent_buffer_bitmap_clear(struct extent_buffer *eb, unsigned long start, - kaddr[offset] &= ~mask_to_clear; - len -= bits_to_clear; - bits_to_clear = BITS_PER_BYTE; -- mask_to_clear = ~0U; -+ mask_to_clear = ~(u8)0; - if (++offset >= PAGE_SIZE && len > 0) { - offset = 0; - page = eb->pages[++i]; -diff --git a/fs/btrfs/extent_io.h b/fs/btrfs/extent_io.h -index 28cd88f..1cf4e42 100644 ---- a/fs/btrfs/extent_io.h -+++ b/fs/btrfs/extent_io.h -@@ -59,6 +59,28 @@ - */ - #define EXTENT_PAGE_PRIVATE 1 - -+/* -+ * The extent buffer bitmap operations are done with byte granularity instead of -+ * word granularity for two reasons: -+ * 1. The bitmaps must be little-endian on disk. -+ * 2. Bitmap items are not guaranteed to be aligned to a word and therefore a -+ * single word in a bitmap may straddle two pages in the extent buffer. -+ */ -+#define BIT_BYTE(nr) ((nr) / BITS_PER_BYTE) -+#define BYTE_MASK ((1 << BITS_PER_BYTE) - 1) -+#define BITMAP_FIRST_BYTE_MASK(start) \ -+ ((BYTE_MASK << ((start) & (BITS_PER_BYTE - 1))) & BYTE_MASK) -+#define BITMAP_LAST_BYTE_MASK(nbits) \ -+ (BYTE_MASK >> (-(nbits) & (BITS_PER_BYTE - 1))) -+ -+static inline int le_test_bit(int nr, const u8 *addr) -+{ -+ return 1U & (addr[BIT_BYTE(nr)] >> (nr & (BITS_PER_BYTE-1))); -+} -+ -+extern void le_bitmap_set(u8 *map, unsigned int start, int len); -+extern void le_bitmap_clear(u8 *map, unsigned int start, int len); -+ - struct extent_state; - struct btrfs_root; - struct btrfs_io_bio; -diff --git a/fs/btrfs/free-space-tree.c b/fs/btrfs/free-space-tree.c -index 87e7e3d..ea605ff 100644 ---- a/fs/btrfs/free-space-tree.c -+++ b/fs/btrfs/free-space-tree.c -@@ -151,7 +151,7 @@ static inline u32 free_space_bitmap_size(u64 size, u32 sectorsize) - return DIV_ROUND_UP((u32)div_u64(size, sectorsize), BITS_PER_BYTE); - } - --static unsigned long *alloc_bitmap(u32 bitmap_size) -+static u8 *alloc_bitmap(u32 bitmap_size) - { - void *mem; - -@@ -180,8 +180,7 @@ int convert_free_space_to_bitmaps(struct btrfs_trans_handle *trans, - struct btrfs_free_space_info *info; - struct btrfs_key key, found_key; - struct extent_buffer *leaf; -- unsigned long *bitmap; -- char *bitmap_cursor; -+ u8 *bitmap, *bitmap_cursor; - u64 start, end; - u64 bitmap_range, i; - u32 bitmap_size, flags, expected_extent_count; -@@ -231,7 +230,7 @@ int convert_free_space_to_bitmaps(struct btrfs_trans_handle *trans, - block_group->sectorsize); - last = div_u64(found_key.objectid + found_key.offset - start, - block_group->sectorsize); -- bitmap_set(bitmap, first, last - first); -+ le_bitmap_set(bitmap, first, last - first); - - extent_count++; - nr++; -@@ -269,7 +268,7 @@ int convert_free_space_to_bitmaps(struct btrfs_trans_handle *trans, - goto out; - } - -- bitmap_cursor = (char *)bitmap; -+ bitmap_cursor = bitmap; - bitmap_range = block_group->sectorsize * BTRFS_FREE_SPACE_BITMAP_BITS; - i = start; - while (i < end) { -@@ -318,7 +317,7 @@ int convert_free_space_to_extents(struct btrfs_trans_handle *trans, - struct btrfs_free_space_info *info; - struct btrfs_key key, found_key; - struct extent_buffer *leaf; -- unsigned long *bitmap; -+ u8 *bitmap; - u64 start, end; - /* Initialize to silence GCC. */ - u64 extent_start = 0; -@@ -362,7 +361,7 @@ int convert_free_space_to_extents(struct btrfs_trans_handle *trans, - break; - } else if (found_key.type == BTRFS_FREE_SPACE_BITMAP_KEY) { - unsigned long ptr; -- char *bitmap_cursor; -+ u8 *bitmap_cursor; - u32 bitmap_pos, data_size; - - ASSERT(found_key.objectid >= start); -@@ -372,7 +371,7 @@ int convert_free_space_to_extents(struct btrfs_trans_handle *trans, - bitmap_pos = div_u64(found_key.objectid - start, - block_group->sectorsize * - BITS_PER_BYTE); -- bitmap_cursor = ((char *)bitmap) + bitmap_pos; -+ bitmap_cursor = bitmap + bitmap_pos; - data_size = free_space_bitmap_size(found_key.offset, - block_group->sectorsize); - -@@ -409,7 +408,7 @@ int convert_free_space_to_extents(struct btrfs_trans_handle *trans, - offset = start; - bitnr = 0; - while (offset < end) { -- bit = !!test_bit(bitnr, bitmap); -+ bit = !!le_test_bit(bitnr, bitmap); - if (prev_bit == 0 && bit == 1) { - extent_start = offset; - } else if (prev_bit == 1 && bit == 0) { -@@ -1183,6 +1182,7 @@ int btrfs_create_free_space_tree(struct btrfs_fs_info *fs_info) - } - - btrfs_set_fs_compat_ro(fs_info, FREE_SPACE_TREE); -+ btrfs_set_fs_compat_ro(fs_info, FREE_SPACE_TREE_VALID); - fs_info->creating_free_space_tree = 0; - - ret = btrfs_commit_transaction(trans, tree_root); -@@ -1251,6 +1251,7 @@ int btrfs_clear_free_space_tree(struct btrfs_fs_info *fs_info) - return PTR_ERR(trans); - - btrfs_clear_fs_compat_ro(fs_info, FREE_SPACE_TREE); -+ btrfs_clear_fs_compat_ro(fs_info, FREE_SPACE_TREE_VALID); - fs_info->free_space_root = NULL; - - ret = clear_free_space_tree(trans, free_space_root); -diff --git a/fs/cachefiles/interface.c b/fs/cachefiles/interface.c -index ce5f345..e7f16a7 100644 ---- a/fs/cachefiles/interface.c -+++ b/fs/cachefiles/interface.c -@@ -253,6 +253,8 @@ static void cachefiles_drop_object(struct fscache_object *_object) - struct cachefiles_object *object; - struct cachefiles_cache *cache; - const struct cred *saved_cred; -+ struct inode *inode; -+ blkcnt_t i_blocks = 0; - - ASSERT(_object); - -@@ -279,6 +281,10 @@ static void cachefiles_drop_object(struct fscache_object *_object) - _object != cache->cache.fsdef - ) { - _debug("- retire object OBJ%x", object->fscache.debug_id); -+ inode = d_backing_inode(object->dentry); -+ if (inode) -+ i_blocks = inode->i_blocks; -+ - cachefiles_begin_secure(cache, &saved_cred); - cachefiles_delete_object(cache, object); - cachefiles_end_secure(cache, saved_cred); -@@ -292,7 +298,7 @@ static void cachefiles_drop_object(struct fscache_object *_object) - - /* note that the object is now inactive */ - if (test_bit(CACHEFILES_OBJECT_ACTIVE, &object->flags)) -- cachefiles_mark_object_inactive(cache, object); -+ cachefiles_mark_object_inactive(cache, object, i_blocks); - - dput(object->dentry); - object->dentry = NULL; -diff --git a/fs/cachefiles/internal.h b/fs/cachefiles/internal.h -index 2fcde1a..cd1effe 100644 ---- a/fs/cachefiles/internal.h -+++ b/fs/cachefiles/internal.h -@@ -160,7 +160,8 @@ extern char *cachefiles_cook_key(const u8 *raw, int keylen, uint8_t type); - * namei.c - */ - extern void cachefiles_mark_object_inactive(struct cachefiles_cache *cache, -- struct cachefiles_object *object); -+ struct cachefiles_object *object, -+ blkcnt_t i_blocks); - extern int cachefiles_delete_object(struct cachefiles_cache *cache, - struct cachefiles_object *object); - extern int cachefiles_walk_to_object(struct cachefiles_object *parent, -diff --git a/fs/cachefiles/namei.c b/fs/cachefiles/namei.c -index 3f7c2cd..c6ee4b5 100644 ---- a/fs/cachefiles/namei.c -+++ b/fs/cachefiles/namei.c -@@ -261,10 +261,9 @@ static int cachefiles_mark_object_active(struct cachefiles_cache *cache, - * Mark an object as being inactive. - */ - void cachefiles_mark_object_inactive(struct cachefiles_cache *cache, -- struct cachefiles_object *object) -+ struct cachefiles_object *object, -+ blkcnt_t i_blocks) - { -- blkcnt_t i_blocks = d_backing_inode(object->dentry)->i_blocks; -- - write_lock(&cache->active_lock); - rb_erase(&object->active_node, &cache->active_nodes); - clear_bit(CACHEFILES_OBJECT_ACTIVE, &object->flags); -@@ -707,7 +706,8 @@ int cachefiles_walk_to_object(struct cachefiles_object *parent, - - check_error: - _debug("check error %d", ret); -- cachefiles_mark_object_inactive(cache, object); -+ cachefiles_mark_object_inactive( -+ cache, object, d_backing_inode(object->dentry)->i_blocks); - release_dentry: - dput(object->dentry); - object->dentry = NULL; -diff --git a/fs/debugfs/file.c b/fs/debugfs/file.c -index 592059f..309f4e9 100644 ---- a/fs/debugfs/file.c -+++ b/fs/debugfs/file.c -@@ -97,9 +97,6 @@ EXPORT_SYMBOL_GPL(debugfs_use_file_finish); - - #define F_DENTRY(filp) ((filp)->f_path.dentry) - --#define REAL_FOPS_DEREF(dentry) \ -- ((const struct file_operations *)(dentry)->d_fsdata) -- - static int open_proxy_open(struct inode *inode, struct file *filp) - { - const struct dentry *dentry = F_DENTRY(filp); -@@ -112,7 +109,7 @@ static int open_proxy_open(struct inode *inode, struct file *filp) - goto out; - } - -- real_fops = REAL_FOPS_DEREF(dentry); -+ real_fops = debugfs_real_fops(filp); - real_fops = fops_get(real_fops); - if (!real_fops) { - /* Huh? Module did not clean up after itself at exit? */ -@@ -143,7 +140,7 @@ static ret_type full_proxy_ ## name(proto) \ - { \ - const struct dentry *dentry = F_DENTRY(filp); \ - const struct file_operations *real_fops = \ -- REAL_FOPS_DEREF(dentry); \ -+ debugfs_real_fops(filp); \ - int srcu_idx; \ - ret_type r; \ - \ -@@ -176,7 +173,7 @@ static unsigned int full_proxy_poll(struct file *filp, - struct poll_table_struct *wait) - { - const struct dentry *dentry = F_DENTRY(filp); -- const struct file_operations *real_fops = REAL_FOPS_DEREF(dentry); -+ const struct file_operations *real_fops = debugfs_real_fops(filp); - int srcu_idx; - unsigned int r = 0; - -@@ -193,7 +190,7 @@ static unsigned int full_proxy_poll(struct file *filp, - static int full_proxy_release(struct inode *inode, struct file *filp) - { - const struct dentry *dentry = F_DENTRY(filp); -- const struct file_operations *real_fops = REAL_FOPS_DEREF(dentry); -+ const struct file_operations *real_fops = debugfs_real_fops(filp); - const struct file_operations *proxy_fops = filp->f_op; - int r = 0; - -@@ -241,7 +238,7 @@ static int full_proxy_open(struct inode *inode, struct file *filp) - goto out; - } - -- real_fops = REAL_FOPS_DEREF(dentry); -+ real_fops = debugfs_real_fops(filp); - real_fops = fops_get(real_fops); - if (!real_fops) { - /* Huh? Module did not cleanup after itself at exit? */ -diff --git a/fs/dlm/lowcomms.c b/fs/dlm/lowcomms.c -index 963016c..609998d 100644 ---- a/fs/dlm/lowcomms.c -+++ b/fs/dlm/lowcomms.c -@@ -1656,16 +1656,12 @@ void dlm_lowcomms_stop(void) - mutex_lock(&connections_lock); - dlm_allow_conn = 0; - foreach_conn(stop_conn); -+ clean_writequeues(); -+ foreach_conn(free_conn); - mutex_unlock(&connections_lock); - - work_stop(); - -- mutex_lock(&connections_lock); -- clean_writequeues(); -- -- foreach_conn(free_conn); -- -- mutex_unlock(&connections_lock); - kmem_cache_destroy(con_cache); - } - -diff --git a/fs/ext4/extents.c b/fs/ext4/extents.c -index d7ccb7f..7f69347 100644 ---- a/fs/ext4/extents.c -+++ b/fs/ext4/extents.c -@@ -5734,6 +5734,9 @@ int ext4_insert_range(struct inode *inode, loff_t offset, loff_t len) - up_write(&EXT4_I(inode)->i_data_sem); - goto out_stop; - } -+ } else { -+ ext4_ext_drop_refs(path); -+ kfree(path); - } - - ret = ext4_es_remove_extent(inode, offset_lblk, -diff --git a/fs/ext4/inode.c b/fs/ext4/inode.c -index c6ea25a..f4cdc64 100644 ---- a/fs/ext4/inode.c -+++ b/fs/ext4/inode.c -@@ -647,11 +647,19 @@ int ext4_map_blocks(handle_t *handle, struct inode *inode, - /* - * We have to zeroout blocks before inserting them into extent - * status tree. Otherwise someone could look them up there and -- * use them before they are really zeroed. -+ * use them before they are really zeroed. We also have to -+ * unmap metadata before zeroing as otherwise writeback can -+ * overwrite zeros with stale data from block device. - */ - if (flags & EXT4_GET_BLOCKS_ZERO && - map->m_flags & EXT4_MAP_MAPPED && - map->m_flags & EXT4_MAP_NEW) { -+ ext4_lblk_t i; -+ -+ for (i = 0; i < map->m_len; i++) { -+ unmap_underlying_metadata(inode->i_sb->s_bdev, -+ map->m_pblk + i); -+ } - ret = ext4_issue_zeroout(inode, map->m_lblk, - map->m_pblk, map->m_len); - if (ret) { -@@ -1649,6 +1657,8 @@ static void mpage_release_unused_pages(struct mpage_da_data *mpd, - BUG_ON(!PageLocked(page)); - BUG_ON(PageWriteback(page)); - if (invalidate) { -+ if (page_mapped(page)) -+ clear_page_dirty_for_io(page); - block_invalidatepage(page, 0, PAGE_SIZE); - ClearPageUptodate(page); - } -@@ -3890,7 +3900,7 @@ int ext4_update_disksize_before_punch(struct inode *inode, loff_t offset, - } - - /* -- * ext4_punch_hole: punches a hole in a file by releaseing the blocks -+ * ext4_punch_hole: punches a hole in a file by releasing the blocks - * associated with the given offset and length - * - * @inode: File inode -@@ -3919,7 +3929,7 @@ int ext4_punch_hole(struct inode *inode, loff_t offset, loff_t length) - * Write out all dirty pages to avoid race conditions - * Then release them. - */ -- if (mapping->nrpages && mapping_tagged(mapping, PAGECACHE_TAG_DIRTY)) { -+ if (mapping_tagged(mapping, PAGECACHE_TAG_DIRTY)) { - ret = filemap_write_and_wait_range(mapping, offset, - offset + length - 1); - if (ret) -@@ -4814,14 +4824,14 @@ static int ext4_do_update_inode(handle_t *handle, - * Fix up interoperability with old kernels. Otherwise, old inodes get - * re-used with the upper 16 bits of the uid/gid intact - */ -- if (!ei->i_dtime) { -+ if (ei->i_dtime && list_empty(&ei->i_orphan)) { -+ raw_inode->i_uid_high = 0; -+ raw_inode->i_gid_high = 0; -+ } else { - raw_inode->i_uid_high = - cpu_to_le16(high_16_bits(i_uid)); - raw_inode->i_gid_high = - cpu_to_le16(high_16_bits(i_gid)); -- } else { -- raw_inode->i_uid_high = 0; -- raw_inode->i_gid_high = 0; - } - } else { - raw_inode->i_uid_low = cpu_to_le16(fs_high2lowuid(i_uid)); -diff --git a/fs/ext4/move_extent.c b/fs/ext4/move_extent.c -index a920c5d..6fc14de 100644 ---- a/fs/ext4/move_extent.c -+++ b/fs/ext4/move_extent.c -@@ -598,6 +598,13 @@ ext4_move_extents(struct file *o_filp, struct file *d_filp, __u64 orig_blk, - return -EOPNOTSUPP; - } - -+ if (ext4_encrypted_inode(orig_inode) || -+ ext4_encrypted_inode(donor_inode)) { -+ ext4_msg(orig_inode->i_sb, KERN_ERR, -+ "Online defrag not supported for encrypted files"); -+ return -EOPNOTSUPP; -+ } -+ - /* Protect orig and donor inodes against a truncate */ - lock_two_nondirectories(orig_inode, donor_inode); - -diff --git a/fs/ext4/namei.c b/fs/ext4/namei.c -index 34c0142..7e2f8c3 100644 ---- a/fs/ext4/namei.c -+++ b/fs/ext4/namei.c -@@ -2044,33 +2044,31 @@ static int make_indexed_dir(handle_t *handle, struct ext4_filename *fname, - frame->entries = entries; - frame->at = entries; - frame->bh = bh; -- bh = bh2; - - retval = ext4_handle_dirty_dx_node(handle, dir, frame->bh); - if (retval) - goto out_frames; -- retval = ext4_handle_dirty_dirent_node(handle, dir, bh); -+ retval = ext4_handle_dirty_dirent_node(handle, dir, bh2); - if (retval) - goto out_frames; - -- de = do_split(handle,dir, &bh, frame, &fname->hinfo); -+ de = do_split(handle,dir, &bh2, frame, &fname->hinfo); - if (IS_ERR(de)) { - retval = PTR_ERR(de); - goto out_frames; - } -- dx_release(frames); - -- retval = add_dirent_to_buf(handle, fname, dir, inode, de, bh); -- brelse(bh); -- return retval; -+ retval = add_dirent_to_buf(handle, fname, dir, inode, de, bh2); - out_frames: - /* - * Even if the block split failed, we have to properly write - * out all the changes we did so far. Otherwise we can end up - * with corrupted filesystem. - */ -- ext4_mark_inode_dirty(handle, dir); -+ if (retval) -+ ext4_mark_inode_dirty(handle, dir); - dx_release(frames); -+ brelse(bh2); - return retval; - } - -diff --git a/fs/ext4/symlink.c b/fs/ext4/symlink.c -index 4d83d9e..04a7850 100644 ---- a/fs/ext4/symlink.c -+++ b/fs/ext4/symlink.c -@@ -65,13 +65,12 @@ static const char *ext4_encrypted_get_link(struct dentry *dentry, - res = fscrypt_fname_alloc_buffer(inode, cstr.len, &pstr); - if (res) - goto errout; -+ paddr = pstr.name; - - res = fscrypt_fname_disk_to_usr(inode, 0, 0, &cstr, &pstr); - if (res < 0) - goto errout; - -- paddr = pstr.name; -- - /* Null-terminate the name */ - if (res <= pstr.len) - paddr[res] = '\0'; -diff --git a/fs/fuse/dir.c b/fs/fuse/dir.c -index c47b778..4ff9251 100644 ---- a/fs/fuse/dir.c -+++ b/fs/fuse/dir.c -@@ -1702,14 +1702,46 @@ int fuse_do_setattr(struct inode *inode, struct iattr *attr, - static int fuse_setattr(struct dentry *entry, struct iattr *attr) - { - struct inode *inode = d_inode(entry); -+ struct file *file = (attr->ia_valid & ATTR_FILE) ? attr->ia_file : NULL; -+ int ret; - - if (!fuse_allow_current_process(get_fuse_conn(inode))) - return -EACCES; - -- if (attr->ia_valid & ATTR_FILE) -- return fuse_do_setattr(inode, attr, attr->ia_file); -- else -- return fuse_do_setattr(inode, attr, NULL); -+ if (attr->ia_valid & (ATTR_KILL_SUID | ATTR_KILL_SGID)) { -+ int kill; -+ -+ attr->ia_valid &= ~(ATTR_KILL_SUID | ATTR_KILL_SGID | -+ ATTR_MODE); -+ /* -+ * ia_mode calculation may have used stale i_mode. Refresh and -+ * recalculate. -+ */ -+ ret = fuse_do_getattr(inode, NULL, file); -+ if (ret) -+ return ret; -+ -+ attr->ia_mode = inode->i_mode; -+ kill = should_remove_suid(entry); -+ if (kill & ATTR_KILL_SUID) { -+ attr->ia_valid |= ATTR_MODE; -+ attr->ia_mode &= ~S_ISUID; -+ } -+ if (kill & ATTR_KILL_SGID) { -+ attr->ia_valid |= ATTR_MODE; -+ attr->ia_mode &= ~S_ISGID; -+ } -+ } -+ if (!attr->ia_valid) -+ return 0; -+ -+ ret = fuse_do_setattr(inode, attr, file); -+ if (!ret) { -+ /* Directory mode changed, may need to revalidate access */ -+ if (d_is_dir(entry) && (attr->ia_valid & ATTR_MODE)) -+ fuse_invalidate_entry_cache(entry); -+ } -+ return ret; - } - - static int fuse_getattr(struct vfsmount *mnt, struct dentry *entry, -@@ -1801,6 +1833,23 @@ static ssize_t fuse_getxattr(struct dentry *entry, struct inode *inode, - return ret; - } - -+static int fuse_verify_xattr_list(char *list, size_t size) -+{ -+ size_t origsize = size; -+ -+ while (size) { -+ size_t thislen = strnlen(list, size); -+ -+ if (!thislen || thislen == size) -+ return -EIO; -+ -+ size -= thislen + 1; -+ list += thislen + 1; -+ } -+ -+ return origsize; -+} -+ - static ssize_t fuse_listxattr(struct dentry *entry, char *list, size_t size) - { - struct inode *inode = d_inode(entry); -@@ -1836,6 +1885,8 @@ static ssize_t fuse_listxattr(struct dentry *entry, char *list, size_t size) - ret = fuse_simple_request(fc, &args); - if (!ret && !size) - ret = outarg.size; -+ if (ret > 0 && size) -+ ret = fuse_verify_xattr_list(list, ret); - if (ret == -ENOSYS) { - fc->no_listxattr = 1; - ret = -EOPNOTSUPP; -diff --git a/fs/jbd2/transaction.c b/fs/jbd2/transaction.c -index b5bc3e2..3d8246a 100644 ---- a/fs/jbd2/transaction.c -+++ b/fs/jbd2/transaction.c -@@ -159,6 +159,7 @@ static void wait_transaction_locked(journal_t *journal) - read_unlock(&journal->j_state_lock); - if (need_to_start) - jbd2_log_start_commit(journal, tid); -+ jbd2_might_wait_for_commit(journal); - schedule(); - finish_wait(&journal->j_wait_transaction_locked, &wait); - } -@@ -182,8 +183,6 @@ static int add_transaction_credits(journal_t *journal, int blocks, - int needed; - int total = blocks + rsv_blocks; - -- jbd2_might_wait_for_commit(journal); -- - /* - * If the current transaction is locked down for commit, wait - * for the lock to be released. -@@ -214,6 +213,7 @@ static int add_transaction_credits(journal_t *journal, int blocks, - if (atomic_read(&journal->j_reserved_credits) + total > - journal->j_max_transaction_buffers) { - read_unlock(&journal->j_state_lock); -+ jbd2_might_wait_for_commit(journal); - wait_event(journal->j_wait_reserved, - atomic_read(&journal->j_reserved_credits) + total <= - journal->j_max_transaction_buffers); -@@ -238,6 +238,7 @@ static int add_transaction_credits(journal_t *journal, int blocks, - if (jbd2_log_space_left(journal) < jbd2_space_needed(journal)) { - atomic_sub(total, &t->t_outstanding_credits); - read_unlock(&journal->j_state_lock); -+ jbd2_might_wait_for_commit(journal); - write_lock(&journal->j_state_lock); - if (jbd2_log_space_left(journal) < jbd2_space_needed(journal)) - __jbd2_log_wait_for_space(journal); -@@ -255,6 +256,7 @@ static int add_transaction_credits(journal_t *journal, int blocks, - sub_reserved_credits(journal, rsv_blocks); - atomic_sub(total, &t->t_outstanding_credits); - read_unlock(&journal->j_state_lock); -+ jbd2_might_wait_for_commit(journal); - wait_event(journal->j_wait_reserved, - atomic_read(&journal->j_reserved_credits) + rsv_blocks - <= journal->j_max_transaction_buffers / 2); -diff --git a/fs/reiserfs/super.c b/fs/reiserfs/super.c -index 7a4a85a..74d5ddd 100644 ---- a/fs/reiserfs/super.c -+++ b/fs/reiserfs/super.c -@@ -190,7 +190,15 @@ static int remove_save_link_only(struct super_block *s, - static int reiserfs_quota_on_mount(struct super_block *, int); - #endif - --/* look for uncompleted unlinks and truncates and complete them */ -+/* -+ * Look for uncompleted unlinks and truncates and complete them -+ * -+ * Called with superblock write locked. If quotas are enabled, we have to -+ * release/retake lest we call dquot_quota_on_mount(), proceed to -+ * schedule_on_each_cpu() in invalidate_bdev() and deadlock waiting for the per -+ * cpu worklets to complete flush_async_commits() that in turn wait for the -+ * superblock write lock. -+ */ - static int finish_unfinished(struct super_block *s) - { - INITIALIZE_PATH(path); -@@ -237,7 +245,9 @@ static int finish_unfinished(struct super_block *s) - quota_enabled[i] = 0; - continue; - } -+ reiserfs_write_unlock(s); - ret = reiserfs_quota_on_mount(s, i); -+ reiserfs_write_lock(s); - if (ret < 0) - reiserfs_warning(s, "reiserfs-2500", - "cannot turn on journaled " -diff --git a/fs/utimes.c b/fs/utimes.c -index 794f5f5..ba54b9e 100644 ---- a/fs/utimes.c -+++ b/fs/utimes.c -@@ -87,21 +87,7 @@ static int utimes_common(struct path *path, struct timespec *times) - */ - newattrs.ia_valid |= ATTR_TIMES_SET; - } else { -- /* -- * If times is NULL (or both times are UTIME_NOW), -- * then we need to check permissions, because -- * inode_change_ok() won't do it. -- */ -- error = -EPERM; -- if (IS_IMMUTABLE(inode)) -- goto mnt_drop_write_and_out; -- -- error = -EACCES; -- if (!inode_owner_or_capable(inode)) { -- error = inode_permission(inode, MAY_WRITE); -- if (error) -- goto mnt_drop_write_and_out; -- } -+ newattrs.ia_valid |= ATTR_TOUCH; - } - retry_deleg: - inode_lock(inode); -@@ -113,7 +99,6 @@ static int utimes_common(struct path *path, struct timespec *times) - goto retry_deleg; - } - --mnt_drop_write_and_out: - mnt_drop_write(path->mnt); - out: - return error; -diff --git a/include/crypto/ghash.h b/include/crypto/ghash.h -new file mode 100644 -index 0000000..2a61c9b ---- /dev/null -+++ b/include/crypto/ghash.h -@@ -0,0 +1,23 @@ -+/* -+ * Common values for GHASH algorithms -+ */ -+ -+#ifndef __CRYPTO_GHASH_H__ -+#define __CRYPTO_GHASH_H__ -+ -+#include <linux/types.h> -+#include <crypto/gf128mul.h> -+ -+#define GHASH_BLOCK_SIZE 16 -+#define GHASH_DIGEST_SIZE 16 -+ -+struct ghash_ctx { -+ struct gf128mul_4k *gf128; -+}; -+ -+struct ghash_desc_ctx { -+ u8 buffer[GHASH_BLOCK_SIZE]; -+ u32 bytes; -+}; -+ -+#endif -diff --git a/include/linux/debugfs.h b/include/linux/debugfs.h -index 1438e23..4d3f0d1 100644 ---- a/include/linux/debugfs.h -+++ b/include/linux/debugfs.h -@@ -45,6 +45,23 @@ extern struct dentry *arch_debugfs_dir; - - extern struct srcu_struct debugfs_srcu; - -+/** -+ * debugfs_real_fops - getter for the real file operation -+ * @filp: a pointer to a struct file -+ * -+ * Must only be called under the protection established by -+ * debugfs_use_file_start(). -+ */ -+static inline const struct file_operations *debugfs_real_fops(struct file *filp) -+ __must_hold(&debugfs_srcu) -+{ -+ /* -+ * Neither the pointer to the struct file_operations, nor its -+ * contents ever change -- srcu_dereference() is not needed here. -+ */ -+ return filp->f_path.dentry->d_fsdata; -+} -+ - #if defined(CONFIG_DEBUG_FS) - - struct dentry *debugfs_create_file(const char *name, umode_t mode, -diff --git a/include/linux/fs.h b/include/linux/fs.h -index 901e25d..7c39136 100644 ---- a/include/linux/fs.h -+++ b/include/linux/fs.h -@@ -224,6 +224,7 @@ typedef int (dio_iodone_t)(struct kiocb *iocb, loff_t offset, - #define ATTR_KILL_PRIV (1 << 14) - #define ATTR_OPEN (1 << 15) /* Truncating from open(O_TRUNC) */ - #define ATTR_TIMES_SET (1 << 16) -+#define ATTR_TOUCH (1 << 17) - - /* - * Whiteout is represented by a char device. The following constants define the -diff --git a/include/linux/radix-tree.h b/include/linux/radix-tree.h -index 4c45105..52b97db 100644 ---- a/include/linux/radix-tree.h -+++ b/include/linux/radix-tree.h -@@ -280,9 +280,9 @@ bool __radix_tree_delete_node(struct radix_tree_root *root, - struct radix_tree_node *node); - void *radix_tree_delete_item(struct radix_tree_root *, unsigned long, void *); - void *radix_tree_delete(struct radix_tree_root *, unsigned long); --struct radix_tree_node *radix_tree_replace_clear_tags( -- struct radix_tree_root *root, -- unsigned long index, void *entry); -+void radix_tree_clear_tags(struct radix_tree_root *root, -+ struct radix_tree_node *node, -+ void **slot); - unsigned int radix_tree_gang_lookup(struct radix_tree_root *root, - void **results, unsigned long first_index, - unsigned int max_items); -diff --git a/include/linux/sem.h b/include/linux/sem.h -index 976ce3a..d0efd6e 100644 ---- a/include/linux/sem.h -+++ b/include/linux/sem.h -@@ -21,6 +21,7 @@ struct sem_array { - struct list_head list_id; /* undo requests on this array */ - int sem_nsems; /* no. of semaphores in array */ - int complex_count; /* pending complex operations */ -+ bool complex_mode; /* no parallel simple ops */ - }; - - #ifdef CONFIG_SYSVIPC -diff --git a/include/uapi/linux/btrfs.h b/include/uapi/linux/btrfs.h -index ac5eacd..db4c253 100644 ---- a/include/uapi/linux/btrfs.h -+++ b/include/uapi/linux/btrfs.h -@@ -239,7 +239,17 @@ struct btrfs_ioctl_fs_info_args { - * Used by: - * struct btrfs_ioctl_feature_flags - */ --#define BTRFS_FEATURE_COMPAT_RO_FREE_SPACE_TREE (1ULL << 0) -+#define BTRFS_FEATURE_COMPAT_RO_FREE_SPACE_TREE (1ULL << 0) -+/* -+ * Older kernels (< 4.9) on big-endian systems produced broken free space tree -+ * bitmaps, and btrfs-progs also used to corrupt the free space tree (versions -+ * < 4.7.3). If this bit is clear, then the free space tree cannot be trusted. -+ * btrfs-progs can also intentionally clear this bit to ask the kernel to -+ * rebuild the free space tree, however this might not work on older kernels -+ * that do not know about this bit. If not sure, clear the cache manually on -+ * first mount when booting older kernel versions. -+ */ -+#define BTRFS_FEATURE_COMPAT_RO_FREE_SPACE_TREE_VALID (1ULL << 1) - - #define BTRFS_FEATURE_INCOMPAT_MIXED_BACKREF (1ULL << 0) - #define BTRFS_FEATURE_INCOMPAT_DEFAULT_SUBVOL (1ULL << 1) -diff --git a/ipc/sem.c b/ipc/sem.c -index 7c9d4f7..5e318c5 100644 ---- a/ipc/sem.c -+++ b/ipc/sem.c -@@ -162,14 +162,21 @@ static int sysvipc_sem_proc_show(struct seq_file *s, void *it); - - /* - * Locking: -+ * a) global sem_lock() for read/write - * sem_undo.id_next, - * sem_array.complex_count, -- * sem_array.pending{_alter,_cont}, -- * sem_array.sem_undo: global sem_lock() for read/write -- * sem_undo.proc_next: only "current" is allowed to read/write that field. -+ * sem_array.complex_mode -+ * sem_array.pending{_alter,_const}, -+ * sem_array.sem_undo - * -+ * b) global or semaphore sem_lock() for read/write: - * sem_array.sem_base[i].pending_{const,alter}: -- * global or semaphore sem_lock() for read/write -+ * sem_array.complex_mode (for read) -+ * -+ * c) special: -+ * sem_undo_list.list_proc: -+ * * undo_list->lock for write -+ * * rcu for read - */ - - #define sc_semmsl sem_ctls[0] -@@ -260,30 +267,61 @@ static void sem_rcu_free(struct rcu_head *head) - } - - /* -- * Wait until all currently ongoing simple ops have completed. -+ * Enter the mode suitable for non-simple operations: - * Caller must own sem_perm.lock. -- * New simple ops cannot start, because simple ops first check -- * that sem_perm.lock is free. -- * that a) sem_perm.lock is free and b) complex_count is 0. - */ --static void sem_wait_array(struct sem_array *sma) -+static void complexmode_enter(struct sem_array *sma) - { - int i; - struct sem *sem; - -- if (sma->complex_count) { -- /* The thread that increased sma->complex_count waited on -- * all sem->lock locks. Thus we don't need to wait again. -- */ -+ if (sma->complex_mode) { -+ /* We are already in complex_mode. Nothing to do */ - return; - } - -+ /* We need a full barrier after seting complex_mode: -+ * The write to complex_mode must be visible -+ * before we read the first sem->lock spinlock state. -+ */ -+ smp_store_mb(sma->complex_mode, true); -+ - for (i = 0; i < sma->sem_nsems; i++) { - sem = sma->sem_base + i; - spin_unlock_wait(&sem->lock); - } -+ /* -+ * spin_unlock_wait() is not a memory barriers, it is only a -+ * control barrier. The code must pair with spin_unlock(&sem->lock), -+ * thus just the control barrier is insufficient. -+ * -+ * smp_rmb() is sufficient, as writes cannot pass the control barrier. -+ */ -+ smp_rmb(); -+} -+ -+/* -+ * Try to leave the mode that disallows simple operations: -+ * Caller must own sem_perm.lock. -+ */ -+static void complexmode_tryleave(struct sem_array *sma) -+{ -+ if (sma->complex_count) { -+ /* Complex ops are sleeping. -+ * We must stay in complex mode -+ */ -+ return; -+ } -+ /* -+ * Immediately after setting complex_mode to false, -+ * a simple op can start. Thus: all memory writes -+ * performed by the current operation must be visible -+ * before we set complex_mode to false. -+ */ -+ smp_store_release(&sma->complex_mode, false); - } - -+#define SEM_GLOBAL_LOCK (-1) - /* - * If the request contains only one semaphore operation, and there are - * no complex transactions pending, lock only the semaphore involved. -@@ -300,56 +338,42 @@ static inline int sem_lock(struct sem_array *sma, struct sembuf *sops, - /* Complex operation - acquire a full lock */ - ipc_lock_object(&sma->sem_perm); - -- /* And wait until all simple ops that are processed -- * right now have dropped their locks. -- */ -- sem_wait_array(sma); -- return -1; -+ /* Prevent parallel simple ops */ -+ complexmode_enter(sma); -+ return SEM_GLOBAL_LOCK; - } - - /* - * Only one semaphore affected - try to optimize locking. -- * The rules are: -- * - optimized locking is possible if no complex operation -- * is either enqueued or processed right now. -- * - The test for enqueued complex ops is simple: -- * sma->complex_count != 0 -- * - Testing for complex ops that are processed right now is -- * a bit more difficult. Complex ops acquire the full lock -- * and first wait that the running simple ops have completed. -- * (see above) -- * Thus: If we own a simple lock and the global lock is free -- * and complex_count is now 0, then it will stay 0 and -- * thus just locking sem->lock is sufficient. -+ * Optimized locking is possible if no complex operation -+ * is either enqueued or processed right now. -+ * -+ * Both facts are tracked by complex_mode. - */ - sem = sma->sem_base + sops->sem_num; - -- if (sma->complex_count == 0) { -+ /* -+ * Initial check for complex_mode. Just an optimization, -+ * no locking, no memory barrier. -+ */ -+ if (!sma->complex_mode) { - /* - * It appears that no complex operation is around. - * Acquire the per-semaphore lock. - */ - spin_lock(&sem->lock); - -- /* Then check that the global lock is free */ -- if (!spin_is_locked(&sma->sem_perm.lock)) { -- /* -- * We need a memory barrier with acquire semantics, -- * otherwise we can race with another thread that does: -- * complex_count++; -- * spin_unlock(sem_perm.lock); -- */ -- smp_acquire__after_ctrl_dep(); -+ /* -+ * See 51d7d5205d33 -+ * ("powerpc: Add smp_mb() to arch_spin_is_locked()"): -+ * A full barrier is required: the write of sem->lock -+ * must be visible before the read is executed -+ */ -+ smp_mb(); - -- /* -- * Now repeat the test of complex_count: -- * It can't change anymore until we drop sem->lock. -- * Thus: if is now 0, then it will stay 0. -- */ -- if (sma->complex_count == 0) { -- /* fast path successful! */ -- return sops->sem_num; -- } -+ if (!smp_load_acquire(&sma->complex_mode)) { -+ /* fast path successful! */ -+ return sops->sem_num; - } - spin_unlock(&sem->lock); - } -@@ -369,15 +393,16 @@ static inline int sem_lock(struct sem_array *sma, struct sembuf *sops, - /* Not a false alarm, thus complete the sequence for a - * full lock. - */ -- sem_wait_array(sma); -- return -1; -+ complexmode_enter(sma); -+ return SEM_GLOBAL_LOCK; - } - } - - static inline void sem_unlock(struct sem_array *sma, int locknum) - { -- if (locknum == -1) { -+ if (locknum == SEM_GLOBAL_LOCK) { - unmerge_queues(sma); -+ complexmode_tryleave(sma); - ipc_unlock_object(&sma->sem_perm); - } else { - struct sem *sem = sma->sem_base + locknum; -@@ -529,6 +554,7 @@ static int newary(struct ipc_namespace *ns, struct ipc_params *params) - } - - sma->complex_count = 0; -+ sma->complex_mode = true; /* dropped by sem_unlock below */ - INIT_LIST_HEAD(&sma->pending_alter); - INIT_LIST_HEAD(&sma->pending_const); - INIT_LIST_HEAD(&sma->list_id); -@@ -2184,10 +2210,10 @@ static int sysvipc_sem_proc_show(struct seq_file *s, void *it) - /* - * The proc interface isn't aware of sem_lock(), it calls - * ipc_lock_object() directly (in sysvipc_find_ipc). -- * In order to stay compatible with sem_lock(), we must wait until -- * all simple semop() calls have left their critical regions. -+ * In order to stay compatible with sem_lock(), we must -+ * enter / leave complex_mode. - */ -- sem_wait_array(sma); -+ complexmode_enter(sma); - - sem_otime = get_semotime(sma); - -@@ -2204,6 +2230,8 @@ static int sysvipc_sem_proc_show(struct seq_file *s, void *it) - sem_otime, - sma->sem_ctime); - -+ complexmode_tryleave(sma); -+ - return 0; - } - #endif -diff --git a/lib/radix-tree.c b/lib/radix-tree.c -index 91f0727..8e6d552 100644 ---- a/lib/radix-tree.c -+++ b/lib/radix-tree.c -@@ -1583,15 +1583,10 @@ void *radix_tree_delete(struct radix_tree_root *root, unsigned long index) - } - EXPORT_SYMBOL(radix_tree_delete); - --struct radix_tree_node *radix_tree_replace_clear_tags( -- struct radix_tree_root *root, -- unsigned long index, void *entry) -+void radix_tree_clear_tags(struct radix_tree_root *root, -+ struct radix_tree_node *node, -+ void **slot) - { -- struct radix_tree_node *node; -- void **slot; -- -- __radix_tree_lookup(root, index, &node, &slot); -- - if (node) { - unsigned int tag, offset = get_slot_offset(node, slot); - for (tag = 0; tag < RADIX_TREE_MAX_TAGS; tag++) -@@ -1600,9 +1595,6 @@ struct radix_tree_node *radix_tree_replace_clear_tags( - /* Clear root node tags */ - root->gfp_mask &= __GFP_BITS_MASK; - } -- -- radix_tree_replace_slot(slot, entry); -- return node; - } - - /** -diff --git a/mm/filemap.c b/mm/filemap.c -index 2d0986a..ced9ef6 100644 ---- a/mm/filemap.c -+++ b/mm/filemap.c -@@ -169,33 +169,35 @@ static int page_cache_tree_insert(struct address_space *mapping, - static void page_cache_tree_delete(struct address_space *mapping, - struct page *page, void *shadow) - { -- struct radix_tree_node *node; - int i, nr = PageHuge(page) ? 1 : hpage_nr_pages(page); - - VM_BUG_ON_PAGE(!PageLocked(page), page); - VM_BUG_ON_PAGE(PageTail(page), page); - VM_BUG_ON_PAGE(nr != 1 && shadow, page); - -- if (shadow) { -- mapping->nrexceptional += nr; -- /* -- * Make sure the nrexceptional update is committed before -- * the nrpages update so that final truncate racing -- * with reclaim does not see both counters 0 at the -- * same time and miss a shadow entry. -- */ -- smp_wmb(); -- } -- mapping->nrpages -= nr; -- - for (i = 0; i < nr; i++) { -- node = radix_tree_replace_clear_tags(&mapping->page_tree, -- page->index + i, shadow); -+ struct radix_tree_node *node; -+ void **slot; -+ -+ __radix_tree_lookup(&mapping->page_tree, page->index + i, -+ &node, &slot); -+ -+ radix_tree_clear_tags(&mapping->page_tree, node, slot); -+ - if (!node) { - VM_BUG_ON_PAGE(nr != 1, page); -- return; -+ /* -+ * We need a node to properly account shadow -+ * entries. Don't plant any without. XXX -+ */ -+ shadow = NULL; - } - -+ radix_tree_replace_slot(slot, shadow); -+ -+ if (!node) -+ break; -+ - workingset_node_pages_dec(node); - if (shadow) - workingset_node_shadows_inc(node); -@@ -219,6 +221,18 @@ static void page_cache_tree_delete(struct address_space *mapping, - &node->private_list); - } - } -+ -+ if (shadow) { -+ mapping->nrexceptional += nr; -+ /* -+ * Make sure the nrexceptional update is committed before -+ * the nrpages update so that final truncate racing -+ * with reclaim does not see both counters 0 at the -+ * same time and miss a shadow entry. -+ */ -+ smp_wmb(); -+ } -+ mapping->nrpages -= nr; - } - - /* -@@ -619,7 +633,6 @@ int replace_page_cache_page(struct page *old, struct page *new, gfp_t gfp_mask) - __delete_from_page_cache(old, NULL); - error = page_cache_tree_insert(mapping, new, NULL); - BUG_ON(error); -- mapping->nrpages++; - - /* - * hugetlb pages do not participate in page cache accounting. -@@ -1674,6 +1687,10 @@ static ssize_t do_generic_file_read(struct file *filp, loff_t *ppos, - unsigned int prev_offset; - int error = 0; - -+ if (unlikely(*ppos >= inode->i_sb->s_maxbytes)) -+ return -EINVAL; -+ iov_iter_truncate(iter, inode->i_sb->s_maxbytes); -+ - index = *ppos >> PAGE_SHIFT; - prev_index = ra->prev_pos >> PAGE_SHIFT; - prev_offset = ra->prev_pos & (PAGE_SIZE-1); -diff --git a/mm/hugetlb.c b/mm/hugetlb.c -index 87e11d8..603bdd0 100644 ---- a/mm/hugetlb.c -+++ b/mm/hugetlb.c -@@ -1443,13 +1443,14 @@ static void dissolve_free_huge_page(struct page *page) - { - spin_lock(&hugetlb_lock); - if (PageHuge(page) && !page_count(page)) { -- struct hstate *h = page_hstate(page); -- int nid = page_to_nid(page); -- list_del(&page->lru); -+ struct page *head = compound_head(page); -+ struct hstate *h = page_hstate(head); -+ int nid = page_to_nid(head); -+ list_del(&head->lru); - h->free_huge_pages--; - h->free_huge_pages_node[nid]--; - h->max_huge_pages--; -- update_and_free_page(h, page); -+ update_and_free_page(h, head); - } - spin_unlock(&hugetlb_lock); - } -@@ -1457,7 +1458,8 @@ static void dissolve_free_huge_page(struct page *page) - /* - * Dissolve free hugepages in a given pfn range. Used by memory hotplug to - * make specified memory blocks removable from the system. -- * Note that start_pfn should aligned with (minimum) hugepage size. -+ * Note that this will dissolve a free gigantic hugepage completely, if any -+ * part of it lies within the given range. - */ - void dissolve_free_huge_pages(unsigned long start_pfn, unsigned long end_pfn) - { -@@ -1466,7 +1468,6 @@ void dissolve_free_huge_pages(unsigned long start_pfn, unsigned long end_pfn) - if (!hugepages_supported()) - return; - -- VM_BUG_ON(!IS_ALIGNED(start_pfn, 1 << minimum_order)); - for (pfn = start_pfn; pfn < end_pfn; pfn += 1 << minimum_order) - dissolve_free_huge_page(pfn_to_page(pfn)); - } -diff --git a/sound/soc/codecs/nau8825.c b/sound/soc/codecs/nau8825.c -index 2e59a85..ff56637 100644 ---- a/sound/soc/codecs/nau8825.c -+++ b/sound/soc/codecs/nau8825.c -@@ -1907,7 +1907,7 @@ static int nau8825_calc_fll_param(unsigned int fll_in, unsigned int fs, - /* Calculate the FLL 10-bit integer input and the FLL 16-bit fractional - * input based on FDCO, FREF and FLL ratio. - */ -- fvco = div_u64(fvco << 16, fref * fll_param->ratio); -+ fvco = div_u64(fvco_max << 16, fref * fll_param->ratio); - fll_param->fll_int = (fvco >> 16) & 0x3FF; - fll_param->fll_frac = fvco & 0xFFFF; - return 0; -diff --git a/sound/soc/intel/atom/sst/sst_pvt.c b/sound/soc/intel/atom/sst/sst_pvt.c -index adb32fe..b1e6b8f 100644 ---- a/sound/soc/intel/atom/sst/sst_pvt.c -+++ b/sound/soc/intel/atom/sst/sst_pvt.c -@@ -279,17 +279,15 @@ int sst_prepare_and_post_msg(struct intel_sst_drv *sst, - - if (response) { - ret = sst_wait_timeout(sst, block); -- if (ret < 0) { -+ if (ret < 0) - goto out; -- } else if(block->data) { -- if (!data) -- goto out; -- *data = kzalloc(block->size, GFP_KERNEL); -- if (!(*data)) { -+ -+ if (data && block->data) { -+ *data = kmemdup(block->data, block->size, GFP_KERNEL); -+ if (!*data) { - ret = -ENOMEM; - goto out; -- } else -- memcpy(data, (void *) block->data, block->size); -+ } - } - } - out: diff --git a/4.8.7/1004_linux-4.8.5.patch b/4.8.7/1004_linux-4.8.5.patch deleted file mode 100644 index b4a1ae0..0000000 --- a/4.8.7/1004_linux-4.8.5.patch +++ /dev/null @@ -1,5397 +0,0 @@ -diff --git a/Documentation/ABI/testing/sysfs-class-cxl b/Documentation/ABI/testing/sysfs-class-cxl -index 4ba0a2a..640f65e 100644 ---- a/Documentation/ABI/testing/sysfs-class-cxl -+++ b/Documentation/ABI/testing/sysfs-class-cxl -@@ -220,8 +220,11 @@ What: /sys/class/cxl/<card>/reset - Date: October 2014 - Contact: linuxppc-dev@lists.ozlabs.org - Description: write only -- Writing 1 will issue a PERST to card which may cause the card -- to reload the FPGA depending on load_image_on_perst. -+ Writing 1 will issue a PERST to card provided there are no -+ contexts active on any one of the card AFUs. This may cause -+ the card to reload the FPGA depending on load_image_on_perst. -+ Writing -1 will do a force PERST irrespective of any active -+ contexts on the card AFUs. - Users: https://github.com/ibm-capi/libcxl - - What: /sys/class/cxl/<card>/perst_reloads_same_image (not in a guest) -diff --git a/Documentation/kernel-parameters.txt b/Documentation/kernel-parameters.txt -index a4f4d69..46726d4 100644 ---- a/Documentation/kernel-parameters.txt -+++ b/Documentation/kernel-parameters.txt -@@ -1457,7 +1457,14 @@ bytes respectively. Such letter suffixes can also be entirely omitted. - i8042.nopnp [HW] Don't use ACPIPnP / PnPBIOS to discover KBD/AUX - controllers - i8042.notimeout [HW] Ignore timeout condition signalled by controller -- i8042.reset [HW] Reset the controller during init and cleanup -+ i8042.reset [HW] Reset the controller during init, cleanup and -+ suspend-to-ram transitions, only during s2r -+ transitions, or never reset -+ Format: { 1 | Y | y | 0 | N | n } -+ 1, Y, y: always reset controller -+ 0, N, n: don't ever reset controller -+ Default: only on s2r transitions on x86; most other -+ architectures force reset to be always executed - i8042.unlock [HW] Unlock (ignore) the keylock - i8042.kbdreset [HW] Reset device connected to KBD port - -diff --git a/Makefile b/Makefile -index 82a36ab..daa3a01 100644 ---- a/Makefile -+++ b/Makefile -@@ -1,6 +1,6 @@ - VERSION = 4 - PATCHLEVEL = 8 --SUBLEVEL = 4 -+SUBLEVEL = 5 - EXTRAVERSION = - NAME = Psychotic Stoned Sheep - -diff --git a/arch/arc/kernel/signal.c b/arch/arc/kernel/signal.c -index 6cb3736..d347bbc 100644 ---- a/arch/arc/kernel/signal.c -+++ b/arch/arc/kernel/signal.c -@@ -107,13 +107,13 @@ static int restore_usr_regs(struct pt_regs *regs, struct rt_sigframe __user *sf) - struct user_regs_struct uregs; - - err = __copy_from_user(&set, &sf->uc.uc_sigmask, sizeof(set)); -- if (!err) -- set_current_blocked(&set); -- - err |= __copy_from_user(&uregs.scratch, - &(sf->uc.uc_mcontext.regs.scratch), - sizeof(sf->uc.uc_mcontext.regs.scratch)); -+ if (err) -+ return err; - -+ set_current_blocked(&set); - regs->bta = uregs.scratch.bta; - regs->lp_start = uregs.scratch.lp_start; - regs->lp_end = uregs.scratch.lp_end; -@@ -138,7 +138,7 @@ static int restore_usr_regs(struct pt_regs *regs, struct rt_sigframe __user *sf) - regs->r0 = uregs.scratch.r0; - regs->sp = uregs.scratch.sp; - -- return err; -+ return 0; - } - - static inline int is_do_ss_needed(unsigned int magic) -diff --git a/arch/arm64/include/asm/kvm_emulate.h b/arch/arm64/include/asm/kvm_emulate.h -index 4cdeae3..948a9a8 100644 ---- a/arch/arm64/include/asm/kvm_emulate.h -+++ b/arch/arm64/include/asm/kvm_emulate.h -@@ -167,11 +167,6 @@ static inline bool kvm_vcpu_dabt_isvalid(const struct kvm_vcpu *vcpu) - return !!(kvm_vcpu_get_hsr(vcpu) & ESR_ELx_ISV); - } - --static inline bool kvm_vcpu_dabt_iswrite(const struct kvm_vcpu *vcpu) --{ -- return !!(kvm_vcpu_get_hsr(vcpu) & ESR_ELx_WNR); --} -- - static inline bool kvm_vcpu_dabt_issext(const struct kvm_vcpu *vcpu) - { - return !!(kvm_vcpu_get_hsr(vcpu) & ESR_ELx_SSE); -@@ -192,6 +187,12 @@ static inline bool kvm_vcpu_dabt_iss1tw(const struct kvm_vcpu *vcpu) - return !!(kvm_vcpu_get_hsr(vcpu) & ESR_ELx_S1PTW); - } - -+static inline bool kvm_vcpu_dabt_iswrite(const struct kvm_vcpu *vcpu) -+{ -+ return !!(kvm_vcpu_get_hsr(vcpu) & ESR_ELx_WNR) || -+ kvm_vcpu_dabt_iss1tw(vcpu); /* AF/DBM update */ -+} -+ - static inline bool kvm_vcpu_dabt_is_cm(const struct kvm_vcpu *vcpu) - { - return !!(kvm_vcpu_get_hsr(vcpu) & ESR_ELx_CM); -diff --git a/arch/arm64/include/asm/module.h b/arch/arm64/include/asm/module.h -index e12af67..06ff7fd 100644 ---- a/arch/arm64/include/asm/module.h -+++ b/arch/arm64/include/asm/module.h -@@ -17,6 +17,7 @@ - #define __ASM_MODULE_H - - #include <asm-generic/module.h> -+#include <asm/memory.h> - - #define MODULE_ARCH_VERMAGIC "aarch64" - -@@ -32,6 +33,10 @@ u64 module_emit_plt_entry(struct module *mod, const Elf64_Rela *rela, - Elf64_Sym *sym); - - #ifdef CONFIG_RANDOMIZE_BASE -+#ifdef CONFIG_MODVERSIONS -+#define ARCH_RELOCATES_KCRCTAB -+#define reloc_start (kimage_vaddr - KIMAGE_VADDR) -+#endif - extern u64 module_alloc_base; - #else - #define module_alloc_base ((u64)_etext - MODULES_VSIZE) -diff --git a/arch/arm64/include/asm/percpu.h b/arch/arm64/include/asm/percpu.h -index 2fee2f5..5394c84 100644 ---- a/arch/arm64/include/asm/percpu.h -+++ b/arch/arm64/include/asm/percpu.h -@@ -44,48 +44,44 @@ static inline unsigned long __percpu_##op(void *ptr, \ - \ - switch (size) { \ - case 1: \ -- do { \ -- asm ("//__per_cpu_" #op "_1\n" \ -- "ldxrb %w[ret], %[ptr]\n" \ -+ asm ("//__per_cpu_" #op "_1\n" \ -+ "1: ldxrb %w[ret], %[ptr]\n" \ - #asm_op " %w[ret], %w[ret], %w[val]\n" \ -- "stxrb %w[loop], %w[ret], %[ptr]\n" \ -- : [loop] "=&r" (loop), [ret] "=&r" (ret), \ -- [ptr] "+Q"(*(u8 *)ptr) \ -- : [val] "Ir" (val)); \ -- } while (loop); \ -+ " stxrb %w[loop], %w[ret], %[ptr]\n" \ -+ " cbnz %w[loop], 1b" \ -+ : [loop] "=&r" (loop), [ret] "=&r" (ret), \ -+ [ptr] "+Q"(*(u8 *)ptr) \ -+ : [val] "Ir" (val)); \ - break; \ - case 2: \ -- do { \ -- asm ("//__per_cpu_" #op "_2\n" \ -- "ldxrh %w[ret], %[ptr]\n" \ -+ asm ("//__per_cpu_" #op "_2\n" \ -+ "1: ldxrh %w[ret], %[ptr]\n" \ - #asm_op " %w[ret], %w[ret], %w[val]\n" \ -- "stxrh %w[loop], %w[ret], %[ptr]\n" \ -- : [loop] "=&r" (loop), [ret] "=&r" (ret), \ -- [ptr] "+Q"(*(u16 *)ptr) \ -- : [val] "Ir" (val)); \ -- } while (loop); \ -+ " stxrh %w[loop], %w[ret], %[ptr]\n" \ -+ " cbnz %w[loop], 1b" \ -+ : [loop] "=&r" (loop), [ret] "=&r" (ret), \ -+ [ptr] "+Q"(*(u16 *)ptr) \ -+ : [val] "Ir" (val)); \ - break; \ - case 4: \ -- do { \ -- asm ("//__per_cpu_" #op "_4\n" \ -- "ldxr %w[ret], %[ptr]\n" \ -+ asm ("//__per_cpu_" #op "_4\n" \ -+ "1: ldxr %w[ret], %[ptr]\n" \ - #asm_op " %w[ret], %w[ret], %w[val]\n" \ -- "stxr %w[loop], %w[ret], %[ptr]\n" \ -- : [loop] "=&r" (loop), [ret] "=&r" (ret), \ -- [ptr] "+Q"(*(u32 *)ptr) \ -- : [val] "Ir" (val)); \ -- } while (loop); \ -+ " stxr %w[loop], %w[ret], %[ptr]\n" \ -+ " cbnz %w[loop], 1b" \ -+ : [loop] "=&r" (loop), [ret] "=&r" (ret), \ -+ [ptr] "+Q"(*(u32 *)ptr) \ -+ : [val] "Ir" (val)); \ - break; \ - case 8: \ -- do { \ -- asm ("//__per_cpu_" #op "_8\n" \ -- "ldxr %[ret], %[ptr]\n" \ -+ asm ("//__per_cpu_" #op "_8\n" \ -+ "1: ldxr %[ret], %[ptr]\n" \ - #asm_op " %[ret], %[ret], %[val]\n" \ -- "stxr %w[loop], %[ret], %[ptr]\n" \ -- : [loop] "=&r" (loop), [ret] "=&r" (ret), \ -- [ptr] "+Q"(*(u64 *)ptr) \ -- : [val] "Ir" (val)); \ -- } while (loop); \ -+ " stxr %w[loop], %[ret], %[ptr]\n" \ -+ " cbnz %w[loop], 1b" \ -+ : [loop] "=&r" (loop), [ret] "=&r" (ret), \ -+ [ptr] "+Q"(*(u64 *)ptr) \ -+ : [val] "Ir" (val)); \ - break; \ - default: \ - BUILD_BUG(); \ -@@ -150,44 +146,40 @@ static inline unsigned long __percpu_xchg(void *ptr, unsigned long val, - - switch (size) { - case 1: -- do { -- asm ("//__percpu_xchg_1\n" -- "ldxrb %w[ret], %[ptr]\n" -- "stxrb %w[loop], %w[val], %[ptr]\n" -- : [loop] "=&r"(loop), [ret] "=&r"(ret), -- [ptr] "+Q"(*(u8 *)ptr) -- : [val] "r" (val)); -- } while (loop); -+ asm ("//__percpu_xchg_1\n" -+ "1: ldxrb %w[ret], %[ptr]\n" -+ " stxrb %w[loop], %w[val], %[ptr]\n" -+ " cbnz %w[loop], 1b" -+ : [loop] "=&r"(loop), [ret] "=&r"(ret), -+ [ptr] "+Q"(*(u8 *)ptr) -+ : [val] "r" (val)); - break; - case 2: -- do { -- asm ("//__percpu_xchg_2\n" -- "ldxrh %w[ret], %[ptr]\n" -- "stxrh %w[loop], %w[val], %[ptr]\n" -- : [loop] "=&r"(loop), [ret] "=&r"(ret), -- [ptr] "+Q"(*(u16 *)ptr) -- : [val] "r" (val)); -- } while (loop); -+ asm ("//__percpu_xchg_2\n" -+ "1: ldxrh %w[ret], %[ptr]\n" -+ " stxrh %w[loop], %w[val], %[ptr]\n" -+ " cbnz %w[loop], 1b" -+ : [loop] "=&r"(loop), [ret] "=&r"(ret), -+ [ptr] "+Q"(*(u16 *)ptr) -+ : [val] "r" (val)); - break; - case 4: -- do { -- asm ("//__percpu_xchg_4\n" -- "ldxr %w[ret], %[ptr]\n" -- "stxr %w[loop], %w[val], %[ptr]\n" -- : [loop] "=&r"(loop), [ret] "=&r"(ret), -- [ptr] "+Q"(*(u32 *)ptr) -- : [val] "r" (val)); -- } while (loop); -+ asm ("//__percpu_xchg_4\n" -+ "1: ldxr %w[ret], %[ptr]\n" -+ " stxr %w[loop], %w[val], %[ptr]\n" -+ " cbnz %w[loop], 1b" -+ : [loop] "=&r"(loop), [ret] "=&r"(ret), -+ [ptr] "+Q"(*(u32 *)ptr) -+ : [val] "r" (val)); - break; - case 8: -- do { -- asm ("//__percpu_xchg_8\n" -- "ldxr %[ret], %[ptr]\n" -- "stxr %w[loop], %[val], %[ptr]\n" -- : [loop] "=&r"(loop), [ret] "=&r"(ret), -- [ptr] "+Q"(*(u64 *)ptr) -- : [val] "r" (val)); -- } while (loop); -+ asm ("//__percpu_xchg_8\n" -+ "1: ldxr %[ret], %[ptr]\n" -+ " stxr %w[loop], %[val], %[ptr]\n" -+ " cbnz %w[loop], 1b" -+ : [loop] "=&r"(loop), [ret] "=&r"(ret), -+ [ptr] "+Q"(*(u64 *)ptr) -+ : [val] "r" (val)); - break; - default: - BUILD_BUG(); -diff --git a/arch/arm64/include/asm/uaccess.h b/arch/arm64/include/asm/uaccess.h -index c47257c..db84983 100644 ---- a/arch/arm64/include/asm/uaccess.h -+++ b/arch/arm64/include/asm/uaccess.h -@@ -21,6 +21,7 @@ - /* - * User space memory access functions - */ -+#include <linux/bitops.h> - #include <linux/kasan-checks.h> - #include <linux/string.h> - #include <linux/thread_info.h> -@@ -102,6 +103,13 @@ static inline void set_fs(mm_segment_t fs) - flag; \ - }) - -+/* -+ * When dealing with data aborts or instruction traps we may end up with -+ * a tagged userland pointer. Clear the tag to get a sane pointer to pass -+ * on to access_ok(), for instance. -+ */ -+#define untagged_addr(addr) sign_extend64(addr, 55) -+ - #define access_ok(type, addr, size) __range_ok(addr, size) - #define user_addr_max get_fs - -diff --git a/arch/arm64/kernel/armv8_deprecated.c b/arch/arm64/kernel/armv8_deprecated.c -index 42ffdb5..b0988bb 100644 ---- a/arch/arm64/kernel/armv8_deprecated.c -+++ b/arch/arm64/kernel/armv8_deprecated.c -@@ -280,35 +280,43 @@ static void __init register_insn_emulation_sysctl(struct ctl_table *table) - /* - * Error-checking SWP macros implemented using ldxr{b}/stxr{b} - */ --#define __user_swpX_asm(data, addr, res, temp, B) \ -+ -+/* Arbitrary constant to ensure forward-progress of the LL/SC loop */ -+#define __SWP_LL_SC_LOOPS 4 -+ -+#define __user_swpX_asm(data, addr, res, temp, temp2, B) \ - __asm__ __volatile__( \ -+ " mov %w3, %w7\n" \ - ALTERNATIVE("nop", SET_PSTATE_PAN(0), ARM64_HAS_PAN, \ - CONFIG_ARM64_PAN) \ -- "0: ldxr"B" %w2, [%3]\n" \ -- "1: stxr"B" %w0, %w1, [%3]\n" \ -+ "0: ldxr"B" %w2, [%4]\n" \ -+ "1: stxr"B" %w0, %w1, [%4]\n" \ - " cbz %w0, 2f\n" \ -- " mov %w0, %w4\n" \ -+ " sub %w3, %w3, #1\n" \ -+ " cbnz %w3, 0b\n" \ -+ " mov %w0, %w5\n" \ - " b 3f\n" \ - "2:\n" \ - " mov %w1, %w2\n" \ - "3:\n" \ - " .pushsection .fixup,\"ax\"\n" \ - " .align 2\n" \ -- "4: mov %w0, %w5\n" \ -+ "4: mov %w0, %w6\n" \ - " b 3b\n" \ - " .popsection" \ - _ASM_EXTABLE(0b, 4b) \ - _ASM_EXTABLE(1b, 4b) \ - ALTERNATIVE("nop", SET_PSTATE_PAN(1), ARM64_HAS_PAN, \ - CONFIG_ARM64_PAN) \ -- : "=&r" (res), "+r" (data), "=&r" (temp) \ -- : "r" (addr), "i" (-EAGAIN), "i" (-EFAULT) \ -+ : "=&r" (res), "+r" (data), "=&r" (temp), "=&r" (temp2) \ -+ : "r" (addr), "i" (-EAGAIN), "i" (-EFAULT), \ -+ "i" (__SWP_LL_SC_LOOPS) \ - : "memory") - --#define __user_swp_asm(data, addr, res, temp) \ -- __user_swpX_asm(data, addr, res, temp, "") --#define __user_swpb_asm(data, addr, res, temp) \ -- __user_swpX_asm(data, addr, res, temp, "b") -+#define __user_swp_asm(data, addr, res, temp, temp2) \ -+ __user_swpX_asm(data, addr, res, temp, temp2, "") -+#define __user_swpb_asm(data, addr, res, temp, temp2) \ -+ __user_swpX_asm(data, addr, res, temp, temp2, "b") - - /* - * Bit 22 of the instruction encoding distinguishes between -@@ -328,12 +336,12 @@ static int emulate_swpX(unsigned int address, unsigned int *data, - } - - while (1) { -- unsigned long temp; -+ unsigned long temp, temp2; - - if (type == TYPE_SWPB) -- __user_swpb_asm(*data, address, res, temp); -+ __user_swpb_asm(*data, address, res, temp, temp2); - else -- __user_swp_asm(*data, address, res, temp); -+ __user_swp_asm(*data, address, res, temp, temp2); - - if (likely(res != -EAGAIN) || signal_pending(current)) - break; -diff --git a/arch/arm64/kernel/head.S b/arch/arm64/kernel/head.S -index 3e7b050..4d19508 100644 ---- a/arch/arm64/kernel/head.S -+++ b/arch/arm64/kernel/head.S -@@ -578,8 +578,9 @@ CPU_LE( movk x0, #0x30d0, lsl #16 ) // Clear EE and E0E on LE systems - b.lt 4f // Skip if no PMU present - mrs x0, pmcr_el0 // Disable debug access traps - ubfx x0, x0, #11, #5 // to EL2 and allow access to -- msr mdcr_el2, x0 // all PMU counters from EL1 - 4: -+ csel x0, xzr, x0, lt // all PMU counters from EL1 -+ msr mdcr_el2, x0 // (if they exist) - - /* Stage-2 translation */ - msr vttbr_el2, xzr -diff --git a/arch/arm64/kernel/traps.c b/arch/arm64/kernel/traps.c -index df06750..771a01a7f 100644 ---- a/arch/arm64/kernel/traps.c -+++ b/arch/arm64/kernel/traps.c -@@ -434,18 +434,21 @@ void cpu_enable_cache_maint_trap(void *__unused) - } - - #define __user_cache_maint(insn, address, res) \ -- asm volatile ( \ -- "1: " insn ", %1\n" \ -- " mov %w0, #0\n" \ -- "2:\n" \ -- " .pushsection .fixup,\"ax\"\n" \ -- " .align 2\n" \ -- "3: mov %w0, %w2\n" \ -- " b 2b\n" \ -- " .popsection\n" \ -- _ASM_EXTABLE(1b, 3b) \ -- : "=r" (res) \ -- : "r" (address), "i" (-EFAULT) ) -+ if (untagged_addr(address) >= user_addr_max()) \ -+ res = -EFAULT; \ -+ else \ -+ asm volatile ( \ -+ "1: " insn ", %1\n" \ -+ " mov %w0, #0\n" \ -+ "2:\n" \ -+ " .pushsection .fixup,\"ax\"\n" \ -+ " .align 2\n" \ -+ "3: mov %w0, %w2\n" \ -+ " b 2b\n" \ -+ " .popsection\n" \ -+ _ASM_EXTABLE(1b, 3b) \ -+ : "=r" (res) \ -+ : "r" (address), "i" (-EFAULT) ) - - asmlinkage void __exception do_sysinstr(unsigned int esr, struct pt_regs *regs) - { -diff --git a/arch/arm64/kvm/hyp/entry.S b/arch/arm64/kvm/hyp/entry.S -index ce9e5e5..eaf08d3 100644 ---- a/arch/arm64/kvm/hyp/entry.S -+++ b/arch/arm64/kvm/hyp/entry.S -@@ -98,6 +98,8 @@ ENTRY(__guest_exit) - // x4-x29,lr: vcpu regs - // vcpu x0-x3 on the stack - -+ ALTERNATIVE(nop, SET_PSTATE_PAN(1), ARM64_HAS_PAN, CONFIG_ARM64_PAN) -+ - add x2, x0, #VCPU_CONTEXT - - stp x4, x5, [x2, #CPU_XREG_OFFSET(4)] -diff --git a/arch/metag/include/asm/atomic.h b/arch/metag/include/asm/atomic.h -index 470e365..8ff0a70 100644 ---- a/arch/metag/include/asm/atomic.h -+++ b/arch/metag/include/asm/atomic.h -@@ -39,11 +39,10 @@ - #define atomic_dec(v) atomic_sub(1, (v)) - - #define atomic_inc_not_zero(v) atomic_add_unless((v), 1, 0) -+#define atomic_dec_if_positive(v) atomic_sub_if_positive(1, v) - - #endif - --#define atomic_dec_if_positive(v) atomic_sub_if_positive(1, v) -- - #include <asm-generic/atomic64.h> - - #endif /* __ASM_METAG_ATOMIC_H */ -diff --git a/arch/mips/include/asm/ptrace.h b/arch/mips/include/asm/ptrace.h -index f6fc6aa..b657861 100644 ---- a/arch/mips/include/asm/ptrace.h -+++ b/arch/mips/include/asm/ptrace.h -@@ -152,7 +152,7 @@ static inline int is_syscall_success(struct pt_regs *regs) - - static inline long regs_return_value(struct pt_regs *regs) - { -- if (is_syscall_success(regs)) -+ if (is_syscall_success(regs) || !user_mode(regs)) - return regs->regs[2]; - else - return -regs->regs[2]; -diff --git a/arch/mips/vdso/Makefile b/arch/mips/vdso/Makefile -index 3b4538e..de9e8836 100644 ---- a/arch/mips/vdso/Makefile -+++ b/arch/mips/vdso/Makefile -@@ -82,7 +82,7 @@ obj-vdso := $(obj-vdso-y:%.o=$(obj)/%.o) - $(obj-vdso): KBUILD_CFLAGS := $(cflags-vdso) $(native-abi) - $(obj-vdso): KBUILD_AFLAGS := $(aflags-vdso) $(native-abi) - --$(obj)/vdso.lds: KBUILD_CPPFLAGS := $(native-abi) -+$(obj)/vdso.lds: KBUILD_CPPFLAGS := $(ccflags-vdso) $(native-abi) - - $(obj)/vdso.so.dbg.raw: $(obj)/vdso.lds $(obj-vdso) FORCE - $(call if_changed,vdsold) -diff --git a/arch/parisc/include/asm/pgtable.h b/arch/parisc/include/asm/pgtable.h -index 291cee2..c2c43f7 100644 ---- a/arch/parisc/include/asm/pgtable.h -+++ b/arch/parisc/include/asm/pgtable.h -@@ -83,10 +83,10 @@ static inline void purge_tlb_entries(struct mm_struct *mm, unsigned long addr) - printk("%s:%d: bad pgd %08lx.\n", __FILE__, __LINE__, (unsigned long)pgd_val(e)) - - /* This is the size of the initially mapped kernel memory */ --#ifdef CONFIG_64BIT --#define KERNEL_INITIAL_ORDER 25 /* 1<<25 = 32MB */ -+#if defined(CONFIG_64BIT) -+#define KERNEL_INITIAL_ORDER 26 /* 1<<26 = 64MB */ - #else --#define KERNEL_INITIAL_ORDER 24 /* 1<<24 = 16MB */ -+#define KERNEL_INITIAL_ORDER 25 /* 1<<25 = 32MB */ - #endif - #define KERNEL_INITIAL_SIZE (1 << KERNEL_INITIAL_ORDER) - -diff --git a/arch/parisc/kernel/setup.c b/arch/parisc/kernel/setup.c -index f7ea626..81d6f63 100644 ---- a/arch/parisc/kernel/setup.c -+++ b/arch/parisc/kernel/setup.c -@@ -38,6 +38,7 @@ - #include <linux/export.h> - - #include <asm/processor.h> -+#include <asm/sections.h> - #include <asm/pdc.h> - #include <asm/led.h> - #include <asm/machdep.h> /* for pa7300lc_init() proto */ -@@ -140,6 +141,13 @@ void __init setup_arch(char **cmdline_p) - #endif - printk(KERN_CONT ".\n"); - -+ /* -+ * Check if initial kernel page mappings are sufficient. -+ * panic early if not, else we may access kernel functions -+ * and variables which can't be reached. -+ */ -+ if (__pa((unsigned long) &_end) >= KERNEL_INITIAL_SIZE) -+ panic("KERNEL_INITIAL_ORDER too small!"); - - pdc_console_init(); - -diff --git a/arch/parisc/kernel/time.c b/arch/parisc/kernel/time.c -index 4b0b963..9b63b87 100644 ---- a/arch/parisc/kernel/time.c -+++ b/arch/parisc/kernel/time.c -@@ -226,12 +226,6 @@ void __init start_cpu_itimer(void) - unsigned int cpu = smp_processor_id(); - unsigned long next_tick = mfctl(16) + clocktick; - --#if defined(CONFIG_HAVE_UNSTABLE_SCHED_CLOCK) && defined(CONFIG_64BIT) -- /* With multiple 64bit CPUs online, the cr16's are not syncronized. */ -- if (cpu != 0) -- clear_sched_clock_stable(); --#endif -- - mtctl(next_tick, 16); /* kick off Interval Timer (CR16) */ - - per_cpu(cpu_data, cpu).it_value = next_tick; -diff --git a/arch/parisc/kernel/vmlinux.lds.S b/arch/parisc/kernel/vmlinux.lds.S -index f3ead0b..75304af 100644 ---- a/arch/parisc/kernel/vmlinux.lds.S -+++ b/arch/parisc/kernel/vmlinux.lds.S -@@ -89,8 +89,9 @@ SECTIONS - /* Start of data section */ - _sdata = .; - -- RO_DATA_SECTION(8) -- -+ /* Architecturally we need to keep __gp below 0x1000000 and thus -+ * in front of RO_DATA_SECTION() which stores lots of tracepoint -+ * and ftrace symbols. */ - #ifdef CONFIG_64BIT - . = ALIGN(16); - /* Linkage tables */ -@@ -105,6 +106,8 @@ SECTIONS - } - #endif - -+ RO_DATA_SECTION(8) -+ - /* unwind info */ - .PARISC.unwind : { - __start___unwind = .; -diff --git a/arch/powerpc/Kconfig b/arch/powerpc/Kconfig -index 927d2ab..792cb17 100644 ---- a/arch/powerpc/Kconfig -+++ b/arch/powerpc/Kconfig -@@ -637,7 +637,7 @@ config FORCE_MAX_ZONEORDER - int "Maximum zone order" - range 8 9 if PPC64 && PPC_64K_PAGES - default "9" if PPC64 && PPC_64K_PAGES -- range 9 13 if PPC64 && !PPC_64K_PAGES -+ range 13 13 if PPC64 && !PPC_64K_PAGES - default "13" if PPC64 && !PPC_64K_PAGES - range 9 64 if PPC32 && PPC_16K_PAGES - default "9" if PPC32 && PPC_16K_PAGES -diff --git a/arch/powerpc/kernel/eeh_driver.c b/arch/powerpc/kernel/eeh_driver.c -index 5f36e8a..29aa8d1 100644 ---- a/arch/powerpc/kernel/eeh_driver.c -+++ b/arch/powerpc/kernel/eeh_driver.c -@@ -994,6 +994,14 @@ static void eeh_handle_special_event(void) - /* Notify all devices to be down */ - eeh_pe_state_clear(pe, EEH_PE_PRI_BUS); - bus = eeh_pe_bus_get(phb_pe); -+ if (!bus) { -+ pr_err("%s: Cannot find PCI bus for " -+ "PHB#%d-PE#%x\n", -+ __func__, -+ pe->phb->global_number, -+ pe->addr); -+ break; -+ } - eeh_pe_dev_traverse(pe, - eeh_report_failure, NULL); - pci_hp_remove_devices(bus); -diff --git a/arch/powerpc/kernel/vdso64/datapage.S b/arch/powerpc/kernel/vdso64/datapage.S -index 184a6ba..abf17fe 100644 ---- a/arch/powerpc/kernel/vdso64/datapage.S -+++ b/arch/powerpc/kernel/vdso64/datapage.S -@@ -59,7 +59,7 @@ V_FUNCTION_BEGIN(__kernel_get_syscall_map) - bl V_LOCAL_FUNC(__get_datapage) - mtlr r12 - addi r3,r3,CFG_SYSCALL_MAP64 -- cmpli cr0,r4,0 -+ cmpldi cr0,r4,0 - crclr cr0*4+so - beqlr - li r0,NR_syscalls -diff --git a/arch/powerpc/kernel/vdso64/gettimeofday.S b/arch/powerpc/kernel/vdso64/gettimeofday.S -index a76b4af..3820213 100644 ---- a/arch/powerpc/kernel/vdso64/gettimeofday.S -+++ b/arch/powerpc/kernel/vdso64/gettimeofday.S -@@ -145,7 +145,7 @@ V_FUNCTION_BEGIN(__kernel_clock_getres) - bne cr0,99f - - li r3,0 -- cmpli cr0,r4,0 -+ cmpldi cr0,r4,0 - crclr cr0*4+so - beqlr - lis r5,CLOCK_REALTIME_RES@h -diff --git a/arch/powerpc/lib/copyuser_64.S b/arch/powerpc/lib/copyuser_64.S -index f09899e..7b22624 100644 ---- a/arch/powerpc/lib/copyuser_64.S -+++ b/arch/powerpc/lib/copyuser_64.S -@@ -359,6 +359,7 @@ END_FTR_SECTION_IFCLR(CPU_FTR_UNALIGNED_LD_STD) - addi r3,r3,8 - 171: - 177: -+179: - addi r3,r3,8 - 370: - 372: -@@ -373,7 +374,6 @@ END_FTR_SECTION_IFCLR(CPU_FTR_UNALIGNED_LD_STD) - 173: - 174: - 175: --179: - 181: - 184: - 186: -diff --git a/arch/powerpc/mm/copro_fault.c b/arch/powerpc/mm/copro_fault.c -index bb03542..362954f 100644 ---- a/arch/powerpc/mm/copro_fault.c -+++ b/arch/powerpc/mm/copro_fault.c -@@ -106,6 +106,8 @@ int copro_calculate_slb(struct mm_struct *mm, u64 ea, struct copro_slb *slb) - switch (REGION_ID(ea)) { - case USER_REGION_ID: - pr_devel("%s: 0x%llx -- USER_REGION_ID\n", __func__, ea); -+ if (mm == NULL) -+ return 1; - psize = get_slice_psize(mm, ea); - ssize = user_segment_size(ea); - vsid = get_vsid(mm->context.id, ea, ssize); -diff --git a/arch/powerpc/mm/hash_utils_64.c b/arch/powerpc/mm/hash_utils_64.c -index 0821556..28923b2 100644 ---- a/arch/powerpc/mm/hash_utils_64.c -+++ b/arch/powerpc/mm/hash_utils_64.c -@@ -526,7 +526,7 @@ static bool might_have_hea(void) - */ - #ifdef CONFIG_IBMEBUS - return !cpu_has_feature(CPU_FTR_ARCH_207S) && -- !firmware_has_feature(FW_FEATURE_SPLPAR); -+ firmware_has_feature(FW_FEATURE_SPLPAR); - #else - return false; - #endif -diff --git a/arch/powerpc/platforms/powernv/eeh-powernv.c b/arch/powerpc/platforms/powernv/eeh-powernv.c -index 86544ea..ba17fdd 100644 ---- a/arch/powerpc/platforms/powernv/eeh-powernv.c -+++ b/arch/powerpc/platforms/powernv/eeh-powernv.c -@@ -1091,6 +1091,11 @@ static int pnv_eeh_reset(struct eeh_pe *pe, int option) - } - - bus = eeh_pe_bus_get(pe); -+ if (!bus) { -+ pr_err("%s: Cannot find PCI bus for PHB#%d-PE#%x\n", -+ __func__, pe->phb->global_number, pe->addr); -+ return -EIO; -+ } - if (pe->type & EEH_PE_VF) - return pnv_eeh_reset_vf_pe(pe, option); - -@@ -1306,7 +1311,7 @@ static void pnv_eeh_get_and_dump_hub_diag(struct pci_controller *hose) - return; - } - -- switch (data->type) { -+ switch (be16_to_cpu(data->type)) { - case OPAL_P7IOC_DIAG_TYPE_RGC: - pr_info("P7IOC diag-data for RGC\n\n"); - pnv_eeh_dump_hub_diag_common(data); -@@ -1538,7 +1543,7 @@ static int pnv_eeh_next_error(struct eeh_pe **pe) - - /* Try best to clear it */ - opal_pci_eeh_freeze_clear(phb->opal_id, -- frozen_pe_no, -+ be64_to_cpu(frozen_pe_no), - OPAL_EEH_ACTION_CLEAR_FREEZE_ALL); - ret = EEH_NEXT_ERR_NONE; - } else if ((*pe)->state & EEH_PE_ISOLATED || -diff --git a/arch/powerpc/platforms/powernv/pci.c b/arch/powerpc/platforms/powernv/pci.c -index a21d831..0fe3520 100644 ---- a/arch/powerpc/platforms/powernv/pci.c -+++ b/arch/powerpc/platforms/powernv/pci.c -@@ -309,8 +309,8 @@ static void pnv_pci_dump_p7ioc_diag_data(struct pci_controller *hose, - be64_to_cpu(data->dma1ErrorLog1)); - - for (i = 0; i < OPAL_P7IOC_NUM_PEST_REGS; i++) { -- if ((data->pestA[i] >> 63) == 0 && -- (data->pestB[i] >> 63) == 0) -+ if ((be64_to_cpu(data->pestA[i]) >> 63) == 0 && -+ (be64_to_cpu(data->pestB[i]) >> 63) == 0) - continue; - - pr_info("PE[%3d] A/B: %016llx %016llx\n", -diff --git a/arch/powerpc/platforms/pseries/lpar.c b/arch/powerpc/platforms/pseries/lpar.c -index 86707e6..aa35245 100644 ---- a/arch/powerpc/platforms/pseries/lpar.c -+++ b/arch/powerpc/platforms/pseries/lpar.c -@@ -393,7 +393,7 @@ static void __pSeries_lpar_hugepage_invalidate(unsigned long *slot, - unsigned long *vpn, int count, - int psize, int ssize) - { -- unsigned long param[8]; -+ unsigned long param[PLPAR_HCALL9_BUFSIZE]; - int i = 0, pix = 0, rc; - unsigned long flags = 0; - int lock_tlbie = !mmu_has_feature(MMU_FTR_LOCKLESS_TLBIE); -@@ -522,7 +522,7 @@ static void pSeries_lpar_flush_hash_range(unsigned long number, int local) - unsigned long flags = 0; - struct ppc64_tlb_batch *batch = this_cpu_ptr(&ppc64_tlb_batch); - int lock_tlbie = !mmu_has_feature(MMU_FTR_LOCKLESS_TLBIE); -- unsigned long param[9]; -+ unsigned long param[PLPAR_HCALL9_BUFSIZE]; - unsigned long hash, index, shift, hidx, slot; - real_pte_t pte; - int psize, ssize; -diff --git a/arch/powerpc/sysdev/cpm1.c b/arch/powerpc/sysdev/cpm1.c -index 81d4947..82e8e2b 100644 ---- a/arch/powerpc/sysdev/cpm1.c -+++ b/arch/powerpc/sysdev/cpm1.c -@@ -233,8 +233,6 @@ void __init cpm_reset(void) - else - out_be32(&siu_conf->sc_sdcr, 1); - immr_unmap(siu_conf); -- -- cpm_muram_init(); - } - - static DEFINE_SPINLOCK(cmd_lock); -diff --git a/arch/powerpc/sysdev/cpm2.c b/arch/powerpc/sysdev/cpm2.c -index 8dc1e24..f78ff84 100644 ---- a/arch/powerpc/sysdev/cpm2.c -+++ b/arch/powerpc/sysdev/cpm2.c -@@ -66,10 +66,6 @@ void __init cpm2_reset(void) - cpm2_immr = ioremap(get_immrbase(), CPM_MAP_SIZE); - #endif - -- /* Reclaim the DP memory for our use. -- */ -- cpm_muram_init(); -- - /* Tell everyone where the comm processor resides. - */ - cpmp = &cpm2_immr->im_cpm; -diff --git a/arch/powerpc/sysdev/cpm_common.c b/arch/powerpc/sysdev/cpm_common.c -index 947f420..51bf749 100644 ---- a/arch/powerpc/sysdev/cpm_common.c -+++ b/arch/powerpc/sysdev/cpm_common.c -@@ -37,6 +37,21 @@ - #include <linux/of_gpio.h> - #endif - -+static int __init cpm_init(void) -+{ -+ struct device_node *np; -+ -+ np = of_find_compatible_node(NULL, NULL, "fsl,cpm1"); -+ if (!np) -+ np = of_find_compatible_node(NULL, NULL, "fsl,cpm2"); -+ if (!np) -+ return -ENODEV; -+ cpm_muram_init(); -+ of_node_put(np); -+ return 0; -+} -+subsys_initcall(cpm_init); -+ - #ifdef CONFIG_PPC_EARLY_DEBUG_CPM - static u32 __iomem *cpm_udbg_txdesc; - static u8 __iomem *cpm_udbg_txbuf; -diff --git a/arch/powerpc/xmon/spr_access.S b/arch/powerpc/xmon/spr_access.S -index 84ad742..7d8b0e8 100644 ---- a/arch/powerpc/xmon/spr_access.S -+++ b/arch/powerpc/xmon/spr_access.S -@@ -2,12 +2,12 @@ - - /* unsigned long xmon_mfspr(sprn, default_value) */ - _GLOBAL(xmon_mfspr) -- ld r5, .Lmfspr_table@got(r2) -+ PPC_LL r5, .Lmfspr_table@got(r2) - b xmon_mxspr - - /* void xmon_mtspr(sprn, new_value) */ - _GLOBAL(xmon_mtspr) -- ld r5, .Lmtspr_table@got(r2) -+ PPC_LL r5, .Lmtspr_table@got(r2) - b xmon_mxspr - - /* -diff --git a/arch/s390/kvm/intercept.c b/arch/s390/kvm/intercept.c -index dfd0ca2..9746b78 100644 ---- a/arch/s390/kvm/intercept.c -+++ b/arch/s390/kvm/intercept.c -@@ -118,8 +118,13 @@ static int handle_validity(struct kvm_vcpu *vcpu) - - vcpu->stat.exit_validity++; - trace_kvm_s390_intercept_validity(vcpu, viwhy); -- WARN_ONCE(true, "kvm: unhandled validity intercept 0x%x\n", viwhy); -- return -EOPNOTSUPP; -+ KVM_EVENT(3, "validity intercept 0x%x for pid %u (kvm 0x%pK)", viwhy, -+ current->pid, vcpu->kvm); -+ -+ /* do not warn on invalid runtime instrumentation mode */ -+ WARN_ONCE(viwhy != 0x44, "kvm: unhandled validity intercept 0x%x\n", -+ viwhy); -+ return -EINVAL; - } - - static int handle_instruction(struct kvm_vcpu *vcpu) -diff --git a/arch/x86/kernel/e820.c b/arch/x86/kernel/e820.c -index 8a90f15..625eb69 100644 ---- a/arch/x86/kernel/e820.c -+++ b/arch/x86/kernel/e820.c -@@ -348,7 +348,7 @@ int __init sanitize_e820_map(struct e820entry *biosmap, int max_nr_map, - * continue building up new bios map based on this - * information - */ -- if (current_type != last_type) { -+ if (current_type != last_type || current_type == E820_PRAM) { - if (last_type != 0) { - new_bios[new_bios_entry].size = - change_point[chgidx]->addr - last_addr; -diff --git a/arch/x86/kernel/smpboot.c b/arch/x86/kernel/smpboot.c -index 82b1737..9e152cd 100644 ---- a/arch/x86/kernel/smpboot.c -+++ b/arch/x86/kernel/smpboot.c -@@ -1408,15 +1408,17 @@ __init void prefill_possible_map(void) - - /* No boot processor was found in mptable or ACPI MADT */ - if (!num_processors) { -- int apicid = boot_cpu_physical_apicid; -- int cpu = hard_smp_processor_id(); -+ if (boot_cpu_has(X86_FEATURE_APIC)) { -+ int apicid = boot_cpu_physical_apicid; -+ int cpu = hard_smp_processor_id(); - -- pr_warn("Boot CPU (id %d) not listed by BIOS\n", cpu); -+ pr_warn("Boot CPU (id %d) not listed by BIOS\n", cpu); - -- /* Make sure boot cpu is enumerated */ -- if (apic->cpu_present_to_apicid(0) == BAD_APICID && -- apic->apic_id_valid(apicid)) -- generic_processor_info(apicid, boot_cpu_apic_version); -+ /* Make sure boot cpu is enumerated */ -+ if (apic->cpu_present_to_apicid(0) == BAD_APICID && -+ apic->apic_id_valid(apicid)) -+ generic_processor_info(apicid, boot_cpu_apic_version); -+ } - - if (!num_processors) - num_processors = 1; -diff --git a/arch/x86/kvm/ioapic.c b/arch/x86/kvm/ioapic.c -index c7220ba..1a22de7 100644 ---- a/arch/x86/kvm/ioapic.c -+++ b/arch/x86/kvm/ioapic.c -@@ -594,7 +594,7 @@ static void kvm_ioapic_reset(struct kvm_ioapic *ioapic) - ioapic->irr = 0; - ioapic->irr_delivered = 0; - ioapic->id = 0; -- memset(ioapic->irq_eoi, 0x00, IOAPIC_NUM_PINS); -+ memset(ioapic->irq_eoi, 0x00, sizeof(ioapic->irq_eoi)); - rtc_irq_eoi_tracking_reset(ioapic); - } - -diff --git a/arch/x86/platform/uv/bios_uv.c b/arch/x86/platform/uv/bios_uv.c -index 23f2f3e..58e152b 100644 ---- a/arch/x86/platform/uv/bios_uv.c -+++ b/arch/x86/platform/uv/bios_uv.c -@@ -40,7 +40,15 @@ s64 uv_bios_call(enum uv_bios_cmd which, u64 a1, u64 a2, u64 a3, u64 a4, u64 a5) - */ - return BIOS_STATUS_UNIMPLEMENTED; - -- ret = efi_call_virt_pointer(tab, function, (u64)which, a1, a2, a3, a4, a5); -+ /* -+ * If EFI_OLD_MEMMAP is set, we need to fall back to using our old EFI -+ * callback method, which uses efi_call() directly, with the kernel page tables: -+ */ -+ if (unlikely(test_bit(EFI_OLD_MEMMAP, &efi.flags))) -+ ret = efi_call((void *)__va(tab->function), (u64)which, a1, a2, a3, a4, a5); -+ else -+ ret = efi_call_virt_pointer(tab, function, (u64)which, a1, a2, a3, a4, a5); -+ - return ret; - } - EXPORT_SYMBOL_GPL(uv_bios_call); -diff --git a/block/blk-cgroup.c b/block/blk-cgroup.c -index dd38e5c..b08ccbb 100644 ---- a/block/blk-cgroup.c -+++ b/block/blk-cgroup.c -@@ -1340,10 +1340,8 @@ int blkcg_policy_register(struct blkcg_policy *pol) - struct blkcg_policy_data *cpd; - - cpd = pol->cpd_alloc_fn(GFP_KERNEL); -- if (!cpd) { -- mutex_unlock(&blkcg_pol_mutex); -+ if (!cpd) - goto err_free_cpds; -- } - - blkcg->cpd[pol->plid] = cpd; - cpd->blkcg = blkcg; -diff --git a/drivers/base/platform.c b/drivers/base/platform.c -index 6482d47..d557229 100644 ---- a/drivers/base/platform.c -+++ b/drivers/base/platform.c -@@ -97,7 +97,7 @@ int platform_get_irq(struct platform_device *dev, unsigned int num) - int ret; - - ret = of_irq_get(dev->dev.of_node, num); -- if (ret >= 0 || ret == -EPROBE_DEFER) -+ if (ret > 0 || ret == -EPROBE_DEFER) - return ret; - } - -@@ -175,7 +175,7 @@ int platform_get_irq_byname(struct platform_device *dev, const char *name) - int ret; - - ret = of_irq_get_byname(dev->dev.of_node, name); -- if (ret >= 0 || ret == -EPROBE_DEFER) -+ if (ret > 0 || ret == -EPROBE_DEFER) - return ret; - } - -diff --git a/drivers/clk/imx/clk-imx6q.c b/drivers/clk/imx/clk-imx6q.c -index ba1c1ae..ce8ea10 100644 ---- a/drivers/clk/imx/clk-imx6q.c -+++ b/drivers/clk/imx/clk-imx6q.c -@@ -318,11 +318,16 @@ static void __init imx6q_clocks_init(struct device_node *ccm_node) - clk[IMX6QDL_CLK_IPG_PER_SEL] = imx_clk_mux("ipg_per_sel", base + 0x1c, 6, 1, ipg_per_sels, ARRAY_SIZE(ipg_per_sels)); - clk[IMX6QDL_CLK_UART_SEL] = imx_clk_mux("uart_sel", base + 0x24, 6, 1, uart_sels, ARRAY_SIZE(uart_sels)); - clk[IMX6QDL_CLK_GPU2D_CORE_SEL] = imx_clk_mux("gpu2d_core_sel", base + 0x18, 16, 2, gpu2d_core_sels_2, ARRAY_SIZE(gpu2d_core_sels_2)); -+ } else if (clk_on_imx6dl()) { -+ clk[IMX6QDL_CLK_MLB_SEL] = imx_clk_mux("mlb_sel", base + 0x18, 16, 2, gpu2d_core_sels, ARRAY_SIZE(gpu2d_core_sels)); - } else { - clk[IMX6QDL_CLK_GPU2D_CORE_SEL] = imx_clk_mux("gpu2d_core_sel", base + 0x18, 16, 2, gpu2d_core_sels, ARRAY_SIZE(gpu2d_core_sels)); - } - clk[IMX6QDL_CLK_GPU3D_CORE_SEL] = imx_clk_mux("gpu3d_core_sel", base + 0x18, 4, 2, gpu3d_core_sels, ARRAY_SIZE(gpu3d_core_sels)); -- clk[IMX6QDL_CLK_GPU3D_SHADER_SEL] = imx_clk_mux("gpu3d_shader_sel", base + 0x18, 8, 2, gpu3d_shader_sels, ARRAY_SIZE(gpu3d_shader_sels)); -+ if (clk_on_imx6dl()) -+ clk[IMX6QDL_CLK_GPU2D_CORE_SEL] = imx_clk_mux("gpu2d_core_sel", base + 0x18, 8, 2, gpu3d_shader_sels, ARRAY_SIZE(gpu3d_shader_sels)); -+ else -+ clk[IMX6QDL_CLK_GPU3D_SHADER_SEL] = imx_clk_mux("gpu3d_shader_sel", base + 0x18, 8, 2, gpu3d_shader_sels, ARRAY_SIZE(gpu3d_shader_sels)); - clk[IMX6QDL_CLK_IPU1_SEL] = imx_clk_mux("ipu1_sel", base + 0x3c, 9, 2, ipu_sels, ARRAY_SIZE(ipu_sels)); - clk[IMX6QDL_CLK_IPU2_SEL] = imx_clk_mux("ipu2_sel", base + 0x3c, 14, 2, ipu_sels, ARRAY_SIZE(ipu_sels)); - clk[IMX6QDL_CLK_LDB_DI0_SEL] = imx_clk_mux_flags("ldb_di0_sel", base + 0x2c, 9, 3, ldb_di_sels, ARRAY_SIZE(ldb_di_sels), CLK_SET_RATE_PARENT); -@@ -400,9 +405,15 @@ static void __init imx6q_clocks_init(struct device_node *ccm_node) - clk[IMX6QDL_CLK_LDB_DI0_DIV_3_5] = imx_clk_fixed_factor("ldb_di0_div_3_5", "ldb_di0_sel", 2, 7); - clk[IMX6QDL_CLK_LDB_DI1_DIV_3_5] = imx_clk_fixed_factor("ldb_di1_div_3_5", "ldb_di1_sel", 2, 7); - } -- clk[IMX6QDL_CLK_GPU2D_CORE_PODF] = imx_clk_divider("gpu2d_core_podf", "gpu2d_core_sel", base + 0x18, 23, 3); -+ if (clk_on_imx6dl()) -+ clk[IMX6QDL_CLK_MLB_PODF] = imx_clk_divider("mlb_podf", "mlb_sel", base + 0x18, 23, 3); -+ else -+ clk[IMX6QDL_CLK_GPU2D_CORE_PODF] = imx_clk_divider("gpu2d_core_podf", "gpu2d_core_sel", base + 0x18, 23, 3); - clk[IMX6QDL_CLK_GPU3D_CORE_PODF] = imx_clk_divider("gpu3d_core_podf", "gpu3d_core_sel", base + 0x18, 26, 3); -- clk[IMX6QDL_CLK_GPU3D_SHADER] = imx_clk_divider("gpu3d_shader", "gpu3d_shader_sel", base + 0x18, 29, 3); -+ if (clk_on_imx6dl()) -+ clk[IMX6QDL_CLK_GPU2D_CORE_PODF] = imx_clk_divider("gpu2d_core_podf", "gpu2d_core_sel", base + 0x18, 29, 3); -+ else -+ clk[IMX6QDL_CLK_GPU3D_SHADER] = imx_clk_divider("gpu3d_shader", "gpu3d_shader_sel", base + 0x18, 29, 3); - clk[IMX6QDL_CLK_IPU1_PODF] = imx_clk_divider("ipu1_podf", "ipu1_sel", base + 0x3c, 11, 3); - clk[IMX6QDL_CLK_IPU2_PODF] = imx_clk_divider("ipu2_podf", "ipu2_sel", base + 0x3c, 16, 3); - clk[IMX6QDL_CLK_LDB_DI0_PODF] = imx_clk_divider_flags("ldb_di0_podf", "ldb_di0_div_3_5", base + 0x20, 10, 1, 0); -@@ -473,14 +484,7 @@ static void __init imx6q_clocks_init(struct device_node *ccm_node) - clk[IMX6QDL_CLK_ESAI_MEM] = imx_clk_gate2_shared("esai_mem", "ahb", base + 0x6c, 16, &share_count_esai); - clk[IMX6QDL_CLK_GPT_IPG] = imx_clk_gate2("gpt_ipg", "ipg", base + 0x6c, 20); - clk[IMX6QDL_CLK_GPT_IPG_PER] = imx_clk_gate2("gpt_ipg_per", "ipg_per", base + 0x6c, 22); -- if (clk_on_imx6dl()) -- /* -- * The multiplexer and divider of imx6q clock gpu3d_shader get -- * redefined/reused as gpu2d_core_sel and gpu2d_core_podf on imx6dl. -- */ -- clk[IMX6QDL_CLK_GPU2D_CORE] = imx_clk_gate2("gpu2d_core", "gpu3d_shader", base + 0x6c, 24); -- else -- clk[IMX6QDL_CLK_GPU2D_CORE] = imx_clk_gate2("gpu2d_core", "gpu2d_core_podf", base + 0x6c, 24); -+ clk[IMX6QDL_CLK_GPU2D_CORE] = imx_clk_gate2("gpu2d_core", "gpu2d_core_podf", base + 0x6c, 24); - clk[IMX6QDL_CLK_GPU3D_CORE] = imx_clk_gate2("gpu3d_core", "gpu3d_core_podf", base + 0x6c, 26); - clk[IMX6QDL_CLK_HDMI_IAHB] = imx_clk_gate2("hdmi_iahb", "ahb", base + 0x70, 0); - clk[IMX6QDL_CLK_HDMI_ISFR] = imx_clk_gate2("hdmi_isfr", "video_27m", base + 0x70, 4); -@@ -511,7 +515,7 @@ static void __init imx6q_clocks_init(struct device_node *ccm_node) - * The multiplexer and divider of the imx6q clock gpu2d get - * redefined/reused as mlb_sys_sel and mlb_sys_clk_podf on imx6dl. - */ -- clk[IMX6QDL_CLK_MLB] = imx_clk_gate2("mlb", "gpu2d_core_podf", base + 0x74, 18); -+ clk[IMX6QDL_CLK_MLB] = imx_clk_gate2("mlb", "mlb_podf", base + 0x74, 18); - else - clk[IMX6QDL_CLK_MLB] = imx_clk_gate2("mlb", "axi", base + 0x74, 18); - clk[IMX6QDL_CLK_MMDC_CH0_AXI] = imx_clk_gate2("mmdc_ch0_axi", "mmdc_ch0_axi_podf", base + 0x74, 20); -@@ -629,6 +633,24 @@ static void __init imx6q_clocks_init(struct device_node *ccm_node) - if (IS_ENABLED(CONFIG_PCI_IMX6)) - clk_set_parent(clk[IMX6QDL_CLK_LVDS1_SEL], clk[IMX6QDL_CLK_SATA_REF_100M]); - -+ /* -+ * Initialize the GPU clock muxes, so that the maximum specified clock -+ * rates for the respective SoC are not exceeded. -+ */ -+ if (clk_on_imx6dl()) { -+ clk_set_parent(clk[IMX6QDL_CLK_GPU3D_CORE_SEL], -+ clk[IMX6QDL_CLK_PLL2_PFD1_594M]); -+ clk_set_parent(clk[IMX6QDL_CLK_GPU2D_CORE_SEL], -+ clk[IMX6QDL_CLK_PLL2_PFD1_594M]); -+ } else if (clk_on_imx6q()) { -+ clk_set_parent(clk[IMX6QDL_CLK_GPU3D_CORE_SEL], -+ clk[IMX6QDL_CLK_MMDC_CH0_AXI]); -+ clk_set_parent(clk[IMX6QDL_CLK_GPU3D_SHADER_SEL], -+ clk[IMX6QDL_CLK_PLL2_PFD1_594M]); -+ clk_set_parent(clk[IMX6QDL_CLK_GPU2D_CORE_SEL], -+ clk[IMX6QDL_CLK_PLL3_USB_OTG]); -+ } -+ - imx_register_uart_clocks(uart_clks); - } - CLK_OF_DECLARE(imx6q, "fsl,imx6q-ccm", imx6q_clocks_init); -diff --git a/drivers/cpufreq/cpufreq-dt-platdev.c b/drivers/cpufreq/cpufreq-dt-platdev.c -index 2ee40fd..e1aa531 100644 ---- a/drivers/cpufreq/cpufreq-dt-platdev.c -+++ b/drivers/cpufreq/cpufreq-dt-platdev.c -@@ -68,6 +68,8 @@ static const struct of_device_id machines[] __initconst = { - - { .compatible = "sigma,tango4" }, - -+ { .compatible = "ti,am33xx", }, -+ { .compatible = "ti,dra7", }, - { .compatible = "ti,omap2", }, - { .compatible = "ti,omap3", }, - { .compatible = "ti,omap4", }, -diff --git a/drivers/cpufreq/cpufreq_conservative.c b/drivers/cpufreq/cpufreq_conservative.c -index 18da4f8..1347589 100644 ---- a/drivers/cpufreq/cpufreq_conservative.c -+++ b/drivers/cpufreq/cpufreq_conservative.c -@@ -17,6 +17,7 @@ - struct cs_policy_dbs_info { - struct policy_dbs_info policy_dbs; - unsigned int down_skip; -+ unsigned int requested_freq; - }; - - static inline struct cs_policy_dbs_info *to_dbs_info(struct policy_dbs_info *policy_dbs) -@@ -61,6 +62,7 @@ static unsigned int cs_dbs_timer(struct cpufreq_policy *policy) - { - struct policy_dbs_info *policy_dbs = policy->governor_data; - struct cs_policy_dbs_info *dbs_info = to_dbs_info(policy_dbs); -+ unsigned int requested_freq = dbs_info->requested_freq; - struct dbs_data *dbs_data = policy_dbs->dbs_data; - struct cs_dbs_tuners *cs_tuners = dbs_data->tuners; - unsigned int load = dbs_update(policy); -@@ -72,10 +74,16 @@ static unsigned int cs_dbs_timer(struct cpufreq_policy *policy) - if (cs_tuners->freq_step == 0) - goto out; - -+ /* -+ * If requested_freq is out of range, it is likely that the limits -+ * changed in the meantime, so fall back to current frequency in that -+ * case. -+ */ -+ if (requested_freq > policy->max || requested_freq < policy->min) -+ requested_freq = policy->cur; -+ - /* Check for frequency increase */ - if (load > dbs_data->up_threshold) { -- unsigned int requested_freq = policy->cur; -- - dbs_info->down_skip = 0; - - /* if we are already at full speed then break out early */ -@@ -83,8 +91,11 @@ static unsigned int cs_dbs_timer(struct cpufreq_policy *policy) - goto out; - - requested_freq += get_freq_target(cs_tuners, policy); -+ if (requested_freq > policy->max) -+ requested_freq = policy->max; - - __cpufreq_driver_target(policy, requested_freq, CPUFREQ_RELATION_H); -+ dbs_info->requested_freq = requested_freq; - goto out; - } - -@@ -95,7 +106,7 @@ static unsigned int cs_dbs_timer(struct cpufreq_policy *policy) - - /* Check for frequency decrease */ - if (load < cs_tuners->down_threshold) { -- unsigned int freq_target, requested_freq = policy->cur; -+ unsigned int freq_target; - /* - * if we cannot reduce the frequency anymore, break out early - */ -@@ -109,6 +120,7 @@ static unsigned int cs_dbs_timer(struct cpufreq_policy *policy) - requested_freq = policy->min; - - __cpufreq_driver_target(policy, requested_freq, CPUFREQ_RELATION_L); -+ dbs_info->requested_freq = requested_freq; - } - - out: -@@ -287,6 +299,7 @@ static void cs_start(struct cpufreq_policy *policy) - struct cs_policy_dbs_info *dbs_info = to_dbs_info(policy->governor_data); - - dbs_info->down_skip = 0; -+ dbs_info->requested_freq = policy->cur; - } - - static struct dbs_governor cs_governor = { -diff --git a/drivers/cpufreq/intel_pstate.c b/drivers/cpufreq/intel_pstate.c -index be9eade..b46547e 100644 ---- a/drivers/cpufreq/intel_pstate.c -+++ b/drivers/cpufreq/intel_pstate.c -@@ -556,12 +556,12 @@ static void intel_pstate_hwp_set(const struct cpumask *cpumask) - int min, hw_min, max, hw_max, cpu, range, adj_range; - u64 value, cap; - -- rdmsrl(MSR_HWP_CAPABILITIES, cap); -- hw_min = HWP_LOWEST_PERF(cap); -- hw_max = HWP_HIGHEST_PERF(cap); -- range = hw_max - hw_min; -- - for_each_cpu(cpu, cpumask) { -+ rdmsrl_on_cpu(cpu, MSR_HWP_CAPABILITIES, &cap); -+ hw_min = HWP_LOWEST_PERF(cap); -+ hw_max = HWP_HIGHEST_PERF(cap); -+ range = hw_max - hw_min; -+ - rdmsrl_on_cpu(cpu, MSR_HWP_REQUEST, &value); - adj_range = limits->min_perf_pct * range / 100; - min = hw_min + adj_range; -diff --git a/drivers/gpio/gpio-mpc8xxx.c b/drivers/gpio/gpio-mpc8xxx.c -index 425501c..793518a 100644 ---- a/drivers/gpio/gpio-mpc8xxx.c -+++ b/drivers/gpio/gpio-mpc8xxx.c -@@ -239,7 +239,7 @@ static int mpc8xxx_gpio_irq_map(struct irq_domain *h, unsigned int irq, - irq_hw_number_t hwirq) - { - irq_set_chip_data(irq, h->host_data); -- irq_set_chip_and_handler(irq, &mpc8xxx_irq_chip, handle_level_irq); -+ irq_set_chip_and_handler(irq, &mpc8xxx_irq_chip, handle_edge_irq); - - return 0; - } -diff --git a/drivers/infiniband/core/verbs.c b/drivers/infiniband/core/verbs.c -index f2b776e..5f88ccd 100644 ---- a/drivers/infiniband/core/verbs.c -+++ b/drivers/infiniband/core/verbs.c -@@ -821,7 +821,7 @@ struct ib_qp *ib_create_qp(struct ib_pd *pd, - if (ret) { - pr_err("failed to init MR pool ret= %d\n", ret); - ib_destroy_qp(qp); -- qp = ERR_PTR(ret); -+ return ERR_PTR(ret); - } - } - -diff --git a/drivers/infiniband/ulp/srp/ib_srp.c b/drivers/infiniband/ulp/srp/ib_srp.c -index 3322ed7..6b07d4b 100644 ---- a/drivers/infiniband/ulp/srp/ib_srp.c -+++ b/drivers/infiniband/ulp/srp/ib_srp.c -@@ -1400,7 +1400,9 @@ static int srp_map_sg_entry(struct srp_map_state *state, - - while (dma_len) { - unsigned offset = dma_addr & ~dev->mr_page_mask; -- if (state->npages == dev->max_pages_per_mr || offset != 0) { -+ -+ if (state->npages == dev->max_pages_per_mr || -+ (state->npages > 0 && offset != 0)) { - ret = srp_map_finish_fmr(state, ch); - if (ret) - return ret; -@@ -1417,12 +1419,12 @@ static int srp_map_sg_entry(struct srp_map_state *state, - } - - /* -- * If the last entry of the MR wasn't a full page, then we need to -+ * If the end of the MR is not on a page boundary then we need to - * close it out and start a new one -- we can only merge at page - * boundaries. - */ - ret = 0; -- if (len != dev->mr_page_size) -+ if ((dma_addr & ~dev->mr_page_mask) != 0) - ret = srp_map_finish_fmr(state, ch); - return ret; - } -diff --git a/drivers/input/mouse/elantech.c b/drivers/input/mouse/elantech.c -index 08e252a..ff8c107 100644 ---- a/drivers/input/mouse/elantech.c -+++ b/drivers/input/mouse/elantech.c -@@ -1159,6 +1159,13 @@ static const struct dmi_system_id elantech_dmi_has_middle_button[] = { - DMI_MATCH(DMI_PRODUCT_NAME, "CELSIUS H730"), - }, - }, -+ { -+ /* Fujitsu H760 also has a middle button */ -+ .matches = { -+ DMI_MATCH(DMI_SYS_VENDOR, "FUJITSU"), -+ DMI_MATCH(DMI_PRODUCT_NAME, "CELSIUS H760"), -+ }, -+ }, - #endif - { } - }; -@@ -1503,10 +1510,10 @@ static const struct dmi_system_id elantech_dmi_force_crc_enabled[] = { - }, - }, - { -- /* Fujitsu LIFEBOOK E554 does not work with crc_enabled == 0 */ -+ /* Fujitsu H760 does not work with crc_enabled == 0 */ - .matches = { - DMI_MATCH(DMI_SYS_VENDOR, "FUJITSU"), -- DMI_MATCH(DMI_PRODUCT_NAME, "LIFEBOOK E554"), -+ DMI_MATCH(DMI_PRODUCT_NAME, "CELSIUS H760"), - }, - }, - { -@@ -1517,6 +1524,20 @@ static const struct dmi_system_id elantech_dmi_force_crc_enabled[] = { - }, - }, - { -+ /* Fujitsu LIFEBOOK E554 does not work with crc_enabled == 0 */ -+ .matches = { -+ DMI_MATCH(DMI_SYS_VENDOR, "FUJITSU"), -+ DMI_MATCH(DMI_PRODUCT_NAME, "LIFEBOOK E554"), -+ }, -+ }, -+ { -+ /* Fujitsu LIFEBOOK E556 does not work with crc_enabled == 0 */ -+ .matches = { -+ DMI_MATCH(DMI_SYS_VENDOR, "FUJITSU"), -+ DMI_MATCH(DMI_PRODUCT_NAME, "LIFEBOOK E556"), -+ }, -+ }, -+ { - /* Fujitsu LIFEBOOK U745 does not work with crc_enabled == 0 */ - .matches = { - DMI_MATCH(DMI_SYS_VENDOR, "FUJITSU"), -diff --git a/drivers/input/serio/i8042-io.h b/drivers/input/serio/i8042-io.h -index a5eed2a..34da81c 100644 ---- a/drivers/input/serio/i8042-io.h -+++ b/drivers/input/serio/i8042-io.h -@@ -81,7 +81,7 @@ static inline int i8042_platform_init(void) - return -EBUSY; - #endif - -- i8042_reset = 1; -+ i8042_reset = I8042_RESET_ALWAYS; - return 0; - } - -diff --git a/drivers/input/serio/i8042-ip22io.h b/drivers/input/serio/i8042-ip22io.h -index ee1ad27..08a1c10 100644 ---- a/drivers/input/serio/i8042-ip22io.h -+++ b/drivers/input/serio/i8042-ip22io.h -@@ -61,7 +61,7 @@ static inline int i8042_platform_init(void) - return -EBUSY; - #endif - -- i8042_reset = 1; -+ i8042_reset = I8042_RESET_ALWAYS; - - return 0; - } -diff --git a/drivers/input/serio/i8042-ppcio.h b/drivers/input/serio/i8042-ppcio.h -index f708c75..1aabea4 100644 ---- a/drivers/input/serio/i8042-ppcio.h -+++ b/drivers/input/serio/i8042-ppcio.h -@@ -44,7 +44,7 @@ static inline void i8042_write_command(int val) - - static inline int i8042_platform_init(void) - { -- i8042_reset = 1; -+ i8042_reset = I8042_RESET_ALWAYS; - return 0; - } - -diff --git a/drivers/input/serio/i8042-sparcio.h b/drivers/input/serio/i8042-sparcio.h -index afcd1c1..6231d63 100644 ---- a/drivers/input/serio/i8042-sparcio.h -+++ b/drivers/input/serio/i8042-sparcio.h -@@ -130,7 +130,7 @@ static int __init i8042_platform_init(void) - } - } - -- i8042_reset = 1; -+ i8042_reset = I8042_RESET_ALWAYS; - - return 0; - } -diff --git a/drivers/input/serio/i8042-unicore32io.h b/drivers/input/serio/i8042-unicore32io.h -index 73f5cc1..4557475 100644 ---- a/drivers/input/serio/i8042-unicore32io.h -+++ b/drivers/input/serio/i8042-unicore32io.h -@@ -61,7 +61,7 @@ static inline int i8042_platform_init(void) - if (!request_mem_region(I8042_REGION_START, I8042_REGION_SIZE, "i8042")) - return -EBUSY; - -- i8042_reset = 1; -+ i8042_reset = I8042_RESET_ALWAYS; - return 0; - } - -diff --git a/drivers/input/serio/i8042-x86ia64io.h b/drivers/input/serio/i8042-x86ia64io.h -index 68f5f4a..f4bfb4b 100644 ---- a/drivers/input/serio/i8042-x86ia64io.h -+++ b/drivers/input/serio/i8042-x86ia64io.h -@@ -510,6 +510,90 @@ static const struct dmi_system_id __initconst i8042_dmi_nomux_table[] = { - { } - }; - -+/* -+ * On some Asus laptops, just running self tests cause problems. -+ */ -+static const struct dmi_system_id i8042_dmi_noselftest_table[] = { -+ { -+ .matches = { -+ DMI_MATCH(DMI_SYS_VENDOR, "ASUSTeK COMPUTER INC."), -+ DMI_MATCH(DMI_PRODUCT_NAME, "A455LD"), -+ }, -+ }, -+ { -+ .matches = { -+ DMI_MATCH(DMI_SYS_VENDOR, "ASUSTeK COMPUTER INC."), -+ DMI_MATCH(DMI_PRODUCT_NAME, "K401LB"), -+ }, -+ }, -+ { -+ .matches = { -+ DMI_MATCH(DMI_SYS_VENDOR, "ASUSTeK COMPUTER INC."), -+ DMI_MATCH(DMI_PRODUCT_NAME, "K501LB"), -+ }, -+ }, -+ { -+ .matches = { -+ DMI_MATCH(DMI_SYS_VENDOR, "ASUSTeK COMPUTER INC."), -+ DMI_MATCH(DMI_PRODUCT_NAME, "K501LX"), -+ }, -+ }, -+ { -+ .matches = { -+ DMI_MATCH(DMI_SYS_VENDOR, "ASUSTeK COMPUTER INC."), -+ DMI_MATCH(DMI_PRODUCT_NAME, "R409L"), -+ }, -+ }, -+ { -+ .matches = { -+ DMI_MATCH(DMI_SYS_VENDOR, "ASUSTeK COMPUTER INC."), -+ DMI_MATCH(DMI_PRODUCT_NAME, "V502LX"), -+ }, -+ }, -+ { -+ .matches = { -+ DMI_MATCH(DMI_SYS_VENDOR, "ASUSTeK COMPUTER INC."), -+ DMI_MATCH(DMI_PRODUCT_NAME, "X302LA"), -+ }, -+ }, -+ { -+ .matches = { -+ DMI_MATCH(DMI_SYS_VENDOR, "ASUSTeK COMPUTER INC."), -+ DMI_MATCH(DMI_PRODUCT_NAME, "X450LCP"), -+ }, -+ }, -+ { -+ .matches = { -+ DMI_MATCH(DMI_SYS_VENDOR, "ASUSTeK COMPUTER INC."), -+ DMI_MATCH(DMI_PRODUCT_NAME, "X450LD"), -+ }, -+ }, -+ { -+ .matches = { -+ DMI_MATCH(DMI_SYS_VENDOR, "ASUSTeK COMPUTER INC."), -+ DMI_MATCH(DMI_PRODUCT_NAME, "X455LAB"), -+ }, -+ }, -+ { -+ .matches = { -+ DMI_MATCH(DMI_SYS_VENDOR, "ASUSTeK COMPUTER INC."), -+ DMI_MATCH(DMI_PRODUCT_NAME, "X455LDB"), -+ }, -+ }, -+ { -+ .matches = { -+ DMI_MATCH(DMI_SYS_VENDOR, "ASUSTeK COMPUTER INC."), -+ DMI_MATCH(DMI_PRODUCT_NAME, "X455LF"), -+ }, -+ }, -+ { -+ .matches = { -+ DMI_MATCH(DMI_SYS_VENDOR, "ASUSTeK COMPUTER INC."), -+ DMI_MATCH(DMI_PRODUCT_NAME, "Z450LA"), -+ }, -+ }, -+ { } -+}; - static const struct dmi_system_id __initconst i8042_dmi_reset_table[] = { - { - /* MSI Wind U-100 */ -@@ -1072,12 +1156,18 @@ static int __init i8042_platform_init(void) - return retval; - - #if defined(__ia64__) -- i8042_reset = true; -+ i8042_reset = I8042_RESET_ALWAYS; - #endif - - #ifdef CONFIG_X86 -- if (dmi_check_system(i8042_dmi_reset_table)) -- i8042_reset = true; -+ /* Honor module parameter when value is not default */ -+ if (i8042_reset == I8042_RESET_DEFAULT) { -+ if (dmi_check_system(i8042_dmi_reset_table)) -+ i8042_reset = I8042_RESET_ALWAYS; -+ -+ if (dmi_check_system(i8042_dmi_noselftest_table)) -+ i8042_reset = I8042_RESET_NEVER; -+ } - - if (dmi_check_system(i8042_dmi_noloop_table)) - i8042_noloop = true; -diff --git a/drivers/input/serio/i8042.c b/drivers/input/serio/i8042.c -index 405252a..89abfdb 100644 ---- a/drivers/input/serio/i8042.c -+++ b/drivers/input/serio/i8042.c -@@ -48,9 +48,39 @@ static bool i8042_unlock; - module_param_named(unlock, i8042_unlock, bool, 0); - MODULE_PARM_DESC(unlock, "Ignore keyboard lock."); - --static bool i8042_reset; --module_param_named(reset, i8042_reset, bool, 0); --MODULE_PARM_DESC(reset, "Reset controller during init and cleanup."); -+enum i8042_controller_reset_mode { -+ I8042_RESET_NEVER, -+ I8042_RESET_ALWAYS, -+ I8042_RESET_ON_S2RAM, -+#define I8042_RESET_DEFAULT I8042_RESET_ON_S2RAM -+}; -+static enum i8042_controller_reset_mode i8042_reset = I8042_RESET_DEFAULT; -+static int i8042_set_reset(const char *val, const struct kernel_param *kp) -+{ -+ enum i8042_controller_reset_mode *arg = kp->arg; -+ int error; -+ bool reset; -+ -+ if (val) { -+ error = kstrtobool(val, &reset); -+ if (error) -+ return error; -+ } else { -+ reset = true; -+ } -+ -+ *arg = reset ? I8042_RESET_ALWAYS : I8042_RESET_NEVER; -+ return 0; -+} -+ -+static const struct kernel_param_ops param_ops_reset_param = { -+ .flags = KERNEL_PARAM_OPS_FL_NOARG, -+ .set = i8042_set_reset, -+}; -+#define param_check_reset_param(name, p) \ -+ __param_check(name, p, enum i8042_controller_reset_mode) -+module_param_named(reset, i8042_reset, reset_param, 0); -+MODULE_PARM_DESC(reset, "Reset controller on resume, cleanup or both"); - - static bool i8042_direct; - module_param_named(direct, i8042_direct, bool, 0); -@@ -1019,7 +1049,7 @@ static int i8042_controller_init(void) - * Reset the controller and reset CRT to the original value set by BIOS. - */ - --static void i8042_controller_reset(bool force_reset) -+static void i8042_controller_reset(bool s2r_wants_reset) - { - i8042_flush(); - -@@ -1044,8 +1074,10 @@ static void i8042_controller_reset(bool force_reset) - * Reset the controller if requested. - */ - -- if (i8042_reset || force_reset) -+ if (i8042_reset == I8042_RESET_ALWAYS || -+ (i8042_reset == I8042_RESET_ON_S2RAM && s2r_wants_reset)) { - i8042_controller_selftest(); -+ } - - /* - * Restore the original control register setting. -@@ -1110,7 +1142,7 @@ static void i8042_dritek_enable(void) - * before suspending. - */ - --static int i8042_controller_resume(bool force_reset) -+static int i8042_controller_resume(bool s2r_wants_reset) - { - int error; - -@@ -1118,7 +1150,8 @@ static int i8042_controller_resume(bool force_reset) - if (error) - return error; - -- if (i8042_reset || force_reset) { -+ if (i8042_reset == I8042_RESET_ALWAYS || -+ (i8042_reset == I8042_RESET_ON_S2RAM && s2r_wants_reset)) { - error = i8042_controller_selftest(); - if (error) - return error; -@@ -1195,7 +1228,7 @@ static int i8042_pm_resume_noirq(struct device *dev) - - static int i8042_pm_resume(struct device *dev) - { -- bool force_reset; -+ bool want_reset; - int i; - - for (i = 0; i < I8042_NUM_PORTS; i++) { -@@ -1218,9 +1251,9 @@ static int i8042_pm_resume(struct device *dev) - * off control to the platform firmware, otherwise we can simply restore - * the mode. - */ -- force_reset = pm_resume_via_firmware(); -+ want_reset = pm_resume_via_firmware(); - -- return i8042_controller_resume(force_reset); -+ return i8042_controller_resume(want_reset); - } - - static int i8042_pm_thaw(struct device *dev) -@@ -1482,7 +1515,7 @@ static int __init i8042_probe(struct platform_device *dev) - - i8042_platform_device = dev; - -- if (i8042_reset) { -+ if (i8042_reset == I8042_RESET_ALWAYS) { - error = i8042_controller_selftest(); - if (error) - return error; -diff --git a/drivers/irqchip/irq-eznps.c b/drivers/irqchip/irq-eznps.c -index efbf0e4..ebc2b0b 100644 ---- a/drivers/irqchip/irq-eznps.c -+++ b/drivers/irqchip/irq-eznps.c -@@ -85,7 +85,7 @@ static void nps400_irq_eoi_global(struct irq_data *irqd) - nps_ack_gic(); - } - --static void nps400_irq_eoi(struct irq_data *irqd) -+static void nps400_irq_ack(struct irq_data *irqd) - { - unsigned int __maybe_unused irq = irqd_to_hwirq(irqd); - -@@ -103,7 +103,7 @@ static struct irq_chip nps400_irq_chip_percpu = { - .name = "NPS400 IC", - .irq_mask = nps400_irq_mask, - .irq_unmask = nps400_irq_unmask, -- .irq_eoi = nps400_irq_eoi, -+ .irq_ack = nps400_irq_ack, - }; - - static int nps400_irq_map(struct irq_domain *d, unsigned int virq, -diff --git a/drivers/irqchip/irq-gic-v3.c b/drivers/irqchip/irq-gic-v3.c -index da6c0ba..708a260 100644 ---- a/drivers/irqchip/irq-gic-v3.c -+++ b/drivers/irqchip/irq-gic-v3.c -@@ -153,7 +153,7 @@ static void gic_enable_redist(bool enable) - return; /* No PM support in this redistributor */ - } - -- while (count--) { -+ while (--count) { - val = readl_relaxed(rbase + GICR_WAKER); - if (enable ^ (bool)(val & GICR_WAKER_ChildrenAsleep)) - break; -diff --git a/drivers/md/dm-crypt.c b/drivers/md/dm-crypt.c -index 8742957..6fc8923 100644 ---- a/drivers/md/dm-crypt.c -+++ b/drivers/md/dm-crypt.c -@@ -113,8 +113,7 @@ struct iv_tcw_private { - * and encrypts / decrypts at the same time. - */ - enum flags { DM_CRYPT_SUSPENDED, DM_CRYPT_KEY_VALID, -- DM_CRYPT_SAME_CPU, DM_CRYPT_NO_OFFLOAD, -- DM_CRYPT_EXIT_THREAD}; -+ DM_CRYPT_SAME_CPU, DM_CRYPT_NO_OFFLOAD }; - - /* - * The fields in here must be read only after initialization. -@@ -1207,18 +1206,20 @@ static int dmcrypt_write(void *data) - if (!RB_EMPTY_ROOT(&cc->write_tree)) - goto pop_from_list; - -- if (unlikely(test_bit(DM_CRYPT_EXIT_THREAD, &cc->flags))) { -- spin_unlock_irq(&cc->write_thread_wait.lock); -- break; -- } -- -- __set_current_state(TASK_INTERRUPTIBLE); -+ set_current_state(TASK_INTERRUPTIBLE); - __add_wait_queue(&cc->write_thread_wait, &wait); - - spin_unlock_irq(&cc->write_thread_wait.lock); - -+ if (unlikely(kthread_should_stop())) { -+ set_task_state(current, TASK_RUNNING); -+ remove_wait_queue(&cc->write_thread_wait, &wait); -+ break; -+ } -+ - schedule(); - -+ set_task_state(current, TASK_RUNNING); - spin_lock_irq(&cc->write_thread_wait.lock); - __remove_wait_queue(&cc->write_thread_wait, &wait); - goto continue_locked; -@@ -1533,13 +1534,8 @@ static void crypt_dtr(struct dm_target *ti) - if (!cc) - return; - -- if (cc->write_thread) { -- spin_lock_irq(&cc->write_thread_wait.lock); -- set_bit(DM_CRYPT_EXIT_THREAD, &cc->flags); -- wake_up_locked(&cc->write_thread_wait); -- spin_unlock_irq(&cc->write_thread_wait.lock); -+ if (cc->write_thread) - kthread_stop(cc->write_thread); -- } - - if (cc->io_queue) - destroy_workqueue(cc->io_queue); -diff --git a/drivers/md/dm-mpath.c b/drivers/md/dm-mpath.c -index ac734e5..15db5e9 100644 ---- a/drivers/md/dm-mpath.c -+++ b/drivers/md/dm-mpath.c -@@ -1521,10 +1521,10 @@ static void activate_path(struct work_struct *work) - { - struct pgpath *pgpath = - container_of(work, struct pgpath, activate_path.work); -+ struct request_queue *q = bdev_get_queue(pgpath->path.dev->bdev); - -- if (pgpath->is_active) -- scsi_dh_activate(bdev_get_queue(pgpath->path.dev->bdev), -- pg_init_done, pgpath); -+ if (pgpath->is_active && !blk_queue_dying(q)) -+ scsi_dh_activate(q, pg_init_done, pgpath); - else - pg_init_done(pgpath, SCSI_DH_DEV_OFFLINED); - } -diff --git a/drivers/md/dm-rq.c b/drivers/md/dm-rq.c -index 1ca7463..5da86c8 100644 ---- a/drivers/md/dm-rq.c -+++ b/drivers/md/dm-rq.c -@@ -73,15 +73,24 @@ static void dm_old_start_queue(struct request_queue *q) - spin_unlock_irqrestore(q->queue_lock, flags); - } - -+static void dm_mq_start_queue(struct request_queue *q) -+{ -+ unsigned long flags; -+ -+ spin_lock_irqsave(q->queue_lock, flags); -+ queue_flag_clear(QUEUE_FLAG_STOPPED, q); -+ spin_unlock_irqrestore(q->queue_lock, flags); -+ -+ blk_mq_start_stopped_hw_queues(q, true); -+ blk_mq_kick_requeue_list(q); -+} -+ - void dm_start_queue(struct request_queue *q) - { - if (!q->mq_ops) - dm_old_start_queue(q); -- else { -- queue_flag_clear_unlocked(QUEUE_FLAG_STOPPED, q); -- blk_mq_start_stopped_hw_queues(q, true); -- blk_mq_kick_requeue_list(q); -- } -+ else -+ dm_mq_start_queue(q); - } - - static void dm_old_stop_queue(struct request_queue *q) -diff --git a/drivers/md/dm.c b/drivers/md/dm.c -index fa9b1cb..0f2928b 100644 ---- a/drivers/md/dm.c -+++ b/drivers/md/dm.c -@@ -1873,6 +1873,7 @@ EXPORT_SYMBOL_GPL(dm_device_name); - - static void __dm_destroy(struct mapped_device *md, bool wait) - { -+ struct request_queue *q = dm_get_md_queue(md); - struct dm_table *map; - int srcu_idx; - -@@ -1883,6 +1884,10 @@ static void __dm_destroy(struct mapped_device *md, bool wait) - set_bit(DMF_FREEING, &md->flags); - spin_unlock(&_minor_lock); - -+ spin_lock_irq(q->queue_lock); -+ queue_flag_set(QUEUE_FLAG_DYING, q); -+ spin_unlock_irq(q->queue_lock); -+ - if (dm_request_based(md) && md->kworker_task) - flush_kthread_worker(&md->kworker); - -@@ -2249,10 +2254,11 @@ static int __dm_resume(struct mapped_device *md, struct dm_table *map) - - int dm_resume(struct mapped_device *md) - { -- int r = -EINVAL; -+ int r; - struct dm_table *map = NULL; - - retry: -+ r = -EINVAL; - mutex_lock_nested(&md->suspend_lock, SINGLE_DEPTH_NESTING); - - if (!dm_suspended_md(md)) -@@ -2276,8 +2282,6 @@ int dm_resume(struct mapped_device *md) - goto out; - - clear_bit(DMF_SUSPENDED, &md->flags); -- -- r = 0; - out: - mutex_unlock(&md->suspend_lock); - -diff --git a/drivers/media/dvb-frontends/mb86a20s.c b/drivers/media/dvb-frontends/mb86a20s.c -index 4132532..fe79358 100644 ---- a/drivers/media/dvb-frontends/mb86a20s.c -+++ b/drivers/media/dvb-frontends/mb86a20s.c -@@ -71,25 +71,27 @@ static struct regdata mb86a20s_init1[] = { - }; - - static struct regdata mb86a20s_init2[] = { -- { 0x28, 0x22 }, { 0x29, 0x00 }, { 0x2a, 0x1f }, { 0x2b, 0xf0 }, -+ { 0x50, 0xd1 }, { 0x51, 0x22 }, -+ { 0x39, 0x01 }, -+ { 0x71, 0x00 }, - { 0x3b, 0x21 }, -- { 0x3c, 0x38 }, -+ { 0x3c, 0x3a }, - { 0x01, 0x0d }, -- { 0x04, 0x08 }, { 0x05, 0x03 }, -+ { 0x04, 0x08 }, { 0x05, 0x05 }, - { 0x04, 0x0e }, { 0x05, 0x00 }, -- { 0x04, 0x0f }, { 0x05, 0x37 }, -- { 0x04, 0x0b }, { 0x05, 0x78 }, -+ { 0x04, 0x0f }, { 0x05, 0x14 }, -+ { 0x04, 0x0b }, { 0x05, 0x8c }, - { 0x04, 0x00 }, { 0x05, 0x00 }, -- { 0x04, 0x01 }, { 0x05, 0x1e }, -- { 0x04, 0x02 }, { 0x05, 0x07 }, -- { 0x04, 0x03 }, { 0x05, 0xd0 }, -+ { 0x04, 0x01 }, { 0x05, 0x07 }, -+ { 0x04, 0x02 }, { 0x05, 0x0f }, -+ { 0x04, 0x03 }, { 0x05, 0xa0 }, - { 0x04, 0x09 }, { 0x05, 0x00 }, - { 0x04, 0x0a }, { 0x05, 0xff }, -- { 0x04, 0x27 }, { 0x05, 0x00 }, -+ { 0x04, 0x27 }, { 0x05, 0x64 }, - { 0x04, 0x28 }, { 0x05, 0x00 }, -- { 0x04, 0x1e }, { 0x05, 0x00 }, -- { 0x04, 0x29 }, { 0x05, 0x64 }, -- { 0x04, 0x32 }, { 0x05, 0x02 }, -+ { 0x04, 0x1e }, { 0x05, 0xff }, -+ { 0x04, 0x29 }, { 0x05, 0x0a }, -+ { 0x04, 0x32 }, { 0x05, 0x0a }, - { 0x04, 0x14 }, { 0x05, 0x02 }, - { 0x04, 0x04 }, { 0x05, 0x00 }, - { 0x04, 0x05 }, { 0x05, 0x22 }, -@@ -97,8 +99,6 @@ static struct regdata mb86a20s_init2[] = { - { 0x04, 0x07 }, { 0x05, 0xd8 }, - { 0x04, 0x12 }, { 0x05, 0x00 }, - { 0x04, 0x13 }, { 0x05, 0xff }, -- { 0x04, 0x15 }, { 0x05, 0x4e }, -- { 0x04, 0x16 }, { 0x05, 0x20 }, - - /* - * On this demod, when the bit count reaches the count below, -@@ -152,42 +152,36 @@ static struct regdata mb86a20s_init2[] = { - { 0x50, 0x51 }, { 0x51, 0x04 }, /* MER symbol 4 */ - { 0x45, 0x04 }, /* CN symbol 4 */ - { 0x48, 0x04 }, /* CN manual mode */ -- -+ { 0x50, 0xd5 }, { 0x51, 0x01 }, - { 0x50, 0xd6 }, { 0x51, 0x1f }, - { 0x50, 0xd2 }, { 0x51, 0x03 }, -- { 0x50, 0xd7 }, { 0x51, 0xbf }, -- { 0x28, 0x74 }, { 0x29, 0x00 }, { 0x2a, 0x00 }, { 0x2b, 0xff }, -- { 0x28, 0x46 }, { 0x29, 0x00 }, { 0x2a, 0x1a }, { 0x2b, 0x0c }, -- -- { 0x04, 0x40 }, { 0x05, 0x00 }, -- { 0x28, 0x00 }, { 0x2b, 0x08 }, -- { 0x28, 0x05 }, { 0x2b, 0x00 }, -+ { 0x50, 0xd7 }, { 0x51, 0x3f }, - { 0x1c, 0x01 }, -- { 0x28, 0x06 }, { 0x29, 0x00 }, { 0x2a, 0x00 }, { 0x2b, 0x1f }, -- { 0x28, 0x07 }, { 0x29, 0x00 }, { 0x2a, 0x00 }, { 0x2b, 0x18 }, -- { 0x28, 0x08 }, { 0x29, 0x00 }, { 0x2a, 0x00 }, { 0x2b, 0x12 }, -- { 0x28, 0x09 }, { 0x29, 0x00 }, { 0x2a, 0x00 }, { 0x2b, 0x30 }, -- { 0x28, 0x0a }, { 0x29, 0x00 }, { 0x2a, 0x00 }, { 0x2b, 0x37 }, -- { 0x28, 0x0b }, { 0x29, 0x00 }, { 0x2a, 0x00 }, { 0x2b, 0x02 }, -- { 0x28, 0x0c }, { 0x29, 0x00 }, { 0x2a, 0x00 }, { 0x2b, 0x09 }, -- { 0x28, 0x0d }, { 0x29, 0x00 }, { 0x2a, 0x00 }, { 0x2b, 0x06 }, -- { 0x28, 0x0e }, { 0x29, 0x00 }, { 0x2a, 0x00 }, { 0x2b, 0x7b }, -- { 0x28, 0x0f }, { 0x29, 0x00 }, { 0x2a, 0x00 }, { 0x2b, 0x76 }, -- { 0x28, 0x10 }, { 0x29, 0x00 }, { 0x2a, 0x00 }, { 0x2b, 0x7d }, -- { 0x28, 0x11 }, { 0x29, 0x00 }, { 0x2a, 0x00 }, { 0x2b, 0x08 }, -- { 0x28, 0x12 }, { 0x29, 0x00 }, { 0x2a, 0x00 }, { 0x2b, 0x0b }, -- { 0x28, 0x13 }, { 0x29, 0x00 }, { 0x2a, 0x00 }, { 0x2b, 0x00 }, -- { 0x28, 0x14 }, { 0x29, 0x00 }, { 0x2a, 0x01 }, { 0x2b, 0xf2 }, -- { 0x28, 0x15 }, { 0x29, 0x00 }, { 0x2a, 0x01 }, { 0x2b, 0xf3 }, -- { 0x28, 0x16 }, { 0x29, 0x00 }, { 0x2a, 0x00 }, { 0x2b, 0x05 }, -- { 0x28, 0x17 }, { 0x29, 0x00 }, { 0x2a, 0x00 }, { 0x2b, 0x16 }, -- { 0x28, 0x18 }, { 0x29, 0x00 }, { 0x2a, 0x00 }, { 0x2b, 0x0f }, -- { 0x28, 0x19 }, { 0x29, 0x00 }, { 0x2a, 0x07 }, { 0x2b, 0xef }, -- { 0x28, 0x1a }, { 0x29, 0x00 }, { 0x2a, 0x07 }, { 0x2b, 0xd8 }, -- { 0x28, 0x1b }, { 0x29, 0x00 }, { 0x2a, 0x07 }, { 0x2b, 0xf1 }, -- { 0x28, 0x1c }, { 0x29, 0x00 }, { 0x2a, 0x00 }, { 0x2b, 0x3d }, -- { 0x28, 0x1d }, { 0x29, 0x00 }, { 0x2a, 0x00 }, { 0x2b, 0x94 }, -- { 0x28, 0x1e }, { 0x29, 0x00 }, { 0x2a, 0x00 }, { 0x2b, 0xba }, -+ { 0x28, 0x06 }, { 0x29, 0x00 }, { 0x2a, 0x00 }, { 0x2b, 0x03 }, -+ { 0x28, 0x07 }, { 0x29, 0x00 }, { 0x2a, 0x00 }, { 0x2b, 0x0d }, -+ { 0x28, 0x08 }, { 0x29, 0x00 }, { 0x2a, 0x00 }, { 0x2b, 0x02 }, -+ { 0x28, 0x09 }, { 0x29, 0x00 }, { 0x2a, 0x00 }, { 0x2b, 0x01 }, -+ { 0x28, 0x0a }, { 0x29, 0x00 }, { 0x2a, 0x00 }, { 0x2b, 0x21 }, -+ { 0x28, 0x0b }, { 0x29, 0x00 }, { 0x2a, 0x00 }, { 0x2b, 0x29 }, -+ { 0x28, 0x0c }, { 0x29, 0x00 }, { 0x2a, 0x00 }, { 0x2b, 0x16 }, -+ { 0x28, 0x0d }, { 0x29, 0x00 }, { 0x2a, 0x00 }, { 0x2b, 0x31 }, -+ { 0x28, 0x0e }, { 0x29, 0x00 }, { 0x2a, 0x00 }, { 0x2b, 0x0e }, -+ { 0x28, 0x0f }, { 0x29, 0x00 }, { 0x2a, 0x00 }, { 0x2b, 0x4e }, -+ { 0x28, 0x10 }, { 0x29, 0x00 }, { 0x2a, 0x00 }, { 0x2b, 0x46 }, -+ { 0x28, 0x11 }, { 0x29, 0x00 }, { 0x2a, 0x00 }, { 0x2b, 0x0f }, -+ { 0x28, 0x12 }, { 0x29, 0x00 }, { 0x2a, 0x00 }, { 0x2b, 0x56 }, -+ { 0x28, 0x13 }, { 0x29, 0x00 }, { 0x2a, 0x00 }, { 0x2b, 0x35 }, -+ { 0x28, 0x14 }, { 0x29, 0x00 }, { 0x2a, 0x01 }, { 0x2b, 0xbe }, -+ { 0x28, 0x15 }, { 0x29, 0x00 }, { 0x2a, 0x01 }, { 0x2b, 0x84 }, -+ { 0x28, 0x16 }, { 0x29, 0x00 }, { 0x2a, 0x03 }, { 0x2b, 0xee }, -+ { 0x28, 0x17 }, { 0x29, 0x00 }, { 0x2a, 0x00 }, { 0x2b, 0x98 }, -+ { 0x28, 0x18 }, { 0x29, 0x00 }, { 0x2a, 0x00 }, { 0x2b, 0x9f }, -+ { 0x28, 0x19 }, { 0x29, 0x00 }, { 0x2a, 0x07 }, { 0x2b, 0xb2 }, -+ { 0x28, 0x1a }, { 0x29, 0x00 }, { 0x2a, 0x06 }, { 0x2b, 0xc2 }, -+ { 0x28, 0x1b }, { 0x29, 0x00 }, { 0x2a, 0x07 }, { 0x2b, 0x4a }, -+ { 0x28, 0x1c }, { 0x29, 0x00 }, { 0x2a, 0x01 }, { 0x2b, 0xbc }, -+ { 0x28, 0x1d }, { 0x29, 0x00 }, { 0x2a, 0x04 }, { 0x2b, 0xba }, -+ { 0x28, 0x1e }, { 0x29, 0x00 }, { 0x2a, 0x06 }, { 0x2b, 0x14 }, - { 0x50, 0x1e }, { 0x51, 0x5d }, - { 0x50, 0x22 }, { 0x51, 0x00 }, - { 0x50, 0x23 }, { 0x51, 0xc8 }, -@@ -196,9 +190,7 @@ static struct regdata mb86a20s_init2[] = { - { 0x50, 0x26 }, { 0x51, 0x00 }, - { 0x50, 0x27 }, { 0x51, 0xc3 }, - { 0x50, 0x39 }, { 0x51, 0x02 }, -- { 0xec, 0x0f }, -- { 0xeb, 0x1f }, -- { 0x28, 0x6a }, { 0x29, 0x00 }, { 0x2a, 0x00 }, { 0x2b, 0x00 }, -+ { 0x50, 0xd5 }, { 0x51, 0x01 }, - { 0xd0, 0x00 }, - }; - -@@ -318,7 +310,11 @@ static int mb86a20s_read_status(struct dvb_frontend *fe, enum fe_status *status) - if (val >= 7) - *status |= FE_HAS_SYNC; - -- if (val >= 8) /* Maybe 9? */ -+ /* -+ * Actually, on state S8, it starts receiving TS, but the TS -+ * output is only on normal state after the transition to S9. -+ */ -+ if (val >= 9) - *status |= FE_HAS_LOCK; - - dev_dbg(&state->i2c->dev, "%s: Status = 0x%02x (state = %d)\n", -@@ -2058,6 +2054,11 @@ static void mb86a20s_release(struct dvb_frontend *fe) - kfree(state); - } - -+static int mb86a20s_get_frontend_algo(struct dvb_frontend *fe) -+{ -+ return DVBFE_ALGO_HW; -+} -+ - static struct dvb_frontend_ops mb86a20s_ops; - - struct dvb_frontend *mb86a20s_attach(const struct mb86a20s_config *config, -@@ -2130,6 +2131,7 @@ static struct dvb_frontend_ops mb86a20s_ops = { - .read_status = mb86a20s_read_status_and_stats, - .read_signal_strength = mb86a20s_read_signal_strength_from_cache, - .tune = mb86a20s_tune, -+ .get_frontend_algo = mb86a20s_get_frontend_algo, - }; - - MODULE_DESCRIPTION("DVB Frontend module for Fujitsu mb86A20s hardware"); -diff --git a/drivers/media/usb/cx231xx/cx231xx-avcore.c b/drivers/media/usb/cx231xx/cx231xx-avcore.c -index 4919137..2f52d66 100644 ---- a/drivers/media/usb/cx231xx/cx231xx-avcore.c -+++ b/drivers/media/usb/cx231xx/cx231xx-avcore.c -@@ -1264,7 +1264,10 @@ int cx231xx_set_agc_analog_digital_mux_select(struct cx231xx *dev, - dev->board.agc_analog_digital_select_gpio, - analog_or_digital); - -- return status; -+ if (status < 0) -+ return status; -+ -+ return 0; - } - - int cx231xx_enable_i2c_port_3(struct cx231xx *dev, bool is_port_3) -diff --git a/drivers/media/usb/cx231xx/cx231xx-cards.c b/drivers/media/usb/cx231xx/cx231xx-cards.c -index c63248a..72c246b 100644 ---- a/drivers/media/usb/cx231xx/cx231xx-cards.c -+++ b/drivers/media/usb/cx231xx/cx231xx-cards.c -@@ -486,7 +486,7 @@ struct cx231xx_board cx231xx_boards[] = { - .output_mode = OUT_MODE_VIP11, - .demod_xfer_mode = 0, - .ctl_pin_status_mask = 0xFFFFFFC4, -- .agc_analog_digital_select_gpio = 0x00, /* According with PV cxPolaris.inf file */ -+ .agc_analog_digital_select_gpio = 0x1c, - .tuner_sif_gpio = -1, - .tuner_scl_gpio = -1, - .tuner_sda_gpio = -1, -diff --git a/drivers/media/usb/cx231xx/cx231xx-core.c b/drivers/media/usb/cx231xx/cx231xx-core.c -index 630f4fc..ea9a99e 100644 ---- a/drivers/media/usb/cx231xx/cx231xx-core.c -+++ b/drivers/media/usb/cx231xx/cx231xx-core.c -@@ -712,6 +712,7 @@ int cx231xx_set_mode(struct cx231xx *dev, enum cx231xx_mode set_mode) - break; - case CX231XX_BOARD_CNXT_RDE_253S: - case CX231XX_BOARD_CNXT_RDU_253S: -+ case CX231XX_BOARD_PV_PLAYTV_USB_HYBRID: - errCode = cx231xx_set_agc_analog_digital_mux_select(dev, 1); - break; - case CX231XX_BOARD_HAUPPAUGE_EXETER: -@@ -738,7 +739,7 @@ int cx231xx_set_mode(struct cx231xx *dev, enum cx231xx_mode set_mode) - case CX231XX_BOARD_PV_PLAYTV_USB_HYBRID: - case CX231XX_BOARD_HAUPPAUGE_USB2_FM_PAL: - case CX231XX_BOARD_HAUPPAUGE_USB2_FM_NTSC: -- errCode = cx231xx_set_agc_analog_digital_mux_select(dev, 0); -+ errCode = cx231xx_set_agc_analog_digital_mux_select(dev, 0); - break; - default: - break; -@@ -1301,15 +1302,29 @@ int cx231xx_dev_init(struct cx231xx *dev) - dev->i2c_bus[2].i2c_reserve = 0; - - /* register I2C buses */ -- cx231xx_i2c_register(&dev->i2c_bus[0]); -- cx231xx_i2c_register(&dev->i2c_bus[1]); -- cx231xx_i2c_register(&dev->i2c_bus[2]); -+ errCode = cx231xx_i2c_register(&dev->i2c_bus[0]); -+ if (errCode < 0) -+ return errCode; -+ errCode = cx231xx_i2c_register(&dev->i2c_bus[1]); -+ if (errCode < 0) -+ return errCode; -+ errCode = cx231xx_i2c_register(&dev->i2c_bus[2]); -+ if (errCode < 0) -+ return errCode; - - errCode = cx231xx_i2c_mux_create(dev); -+ if (errCode < 0) { -+ dev_err(dev->dev, -+ "%s: Failed to create I2C mux\n", __func__); -+ return errCode; -+ } -+ errCode = cx231xx_i2c_mux_register(dev, 0); -+ if (errCode < 0) -+ return errCode; -+ -+ errCode = cx231xx_i2c_mux_register(dev, 1); - if (errCode < 0) - return errCode; -- cx231xx_i2c_mux_register(dev, 0); -- cx231xx_i2c_mux_register(dev, 1); - - /* scan the real bus segments in the order of physical port numbers */ - cx231xx_do_i2c_scan(dev, I2C_0); -diff --git a/drivers/memstick/host/rtsx_usb_ms.c b/drivers/memstick/host/rtsx_usb_ms.c -index d34bc35..2e3cf01 100644 ---- a/drivers/memstick/host/rtsx_usb_ms.c -+++ b/drivers/memstick/host/rtsx_usb_ms.c -@@ -524,6 +524,7 @@ static void rtsx_usb_ms_handle_req(struct work_struct *work) - int rc; - - if (!host->req) { -+ pm_runtime_get_sync(ms_dev(host)); - do { - rc = memstick_next_req(msh, &host->req); - dev_dbg(ms_dev(host), "next req %d\n", rc); -@@ -544,6 +545,7 @@ static void rtsx_usb_ms_handle_req(struct work_struct *work) - host->req->error); - } - } while (!rc); -+ pm_runtime_put(ms_dev(host)); - } - - } -@@ -570,6 +572,7 @@ static int rtsx_usb_ms_set_param(struct memstick_host *msh, - dev_dbg(ms_dev(host), "%s: param = %d, value = %d\n", - __func__, param, value); - -+ pm_runtime_get_sync(ms_dev(host)); - mutex_lock(&ucr->dev_mutex); - - err = rtsx_usb_card_exclusive_check(ucr, RTSX_USB_MS_CARD); -@@ -635,6 +638,7 @@ static int rtsx_usb_ms_set_param(struct memstick_host *msh, - } - out: - mutex_unlock(&ucr->dev_mutex); -+ pm_runtime_put(ms_dev(host)); - - /* power-on delay */ - if (param == MEMSTICK_POWER && value == MEMSTICK_POWER_ON) -@@ -681,6 +685,7 @@ static int rtsx_usb_detect_ms_card(void *__host) - int err; - - for (;;) { -+ pm_runtime_get_sync(ms_dev(host)); - mutex_lock(&ucr->dev_mutex); - - /* Check pending MS card changes */ -@@ -703,6 +708,7 @@ static int rtsx_usb_detect_ms_card(void *__host) - } - - poll_again: -+ pm_runtime_put(ms_dev(host)); - if (host->eject) - break; - -diff --git a/drivers/misc/cxl/api.c b/drivers/misc/cxl/api.c -index f3d34b9..af23d7d 100644 ---- a/drivers/misc/cxl/api.c -+++ b/drivers/misc/cxl/api.c -@@ -229,6 +229,14 @@ int cxl_start_context(struct cxl_context *ctx, u64 wed, - if (ctx->status == STARTED) - goto out; /* already started */ - -+ /* -+ * Increment the mapped context count for adapter. This also checks -+ * if adapter_context_lock is taken. -+ */ -+ rc = cxl_adapter_context_get(ctx->afu->adapter); -+ if (rc) -+ goto out; -+ - if (task) { - ctx->pid = get_task_pid(task, PIDTYPE_PID); - ctx->glpid = get_task_pid(task->group_leader, PIDTYPE_PID); -@@ -240,6 +248,7 @@ int cxl_start_context(struct cxl_context *ctx, u64 wed, - - if ((rc = cxl_ops->attach_process(ctx, kernel, wed, 0))) { - put_pid(ctx->pid); -+ cxl_adapter_context_put(ctx->afu->adapter); - cxl_ctx_put(); - goto out; - } -diff --git a/drivers/misc/cxl/context.c b/drivers/misc/cxl/context.c -index c466ee2..5e506c1 100644 ---- a/drivers/misc/cxl/context.c -+++ b/drivers/misc/cxl/context.c -@@ -238,6 +238,9 @@ int __detach_context(struct cxl_context *ctx) - put_pid(ctx->glpid); - - cxl_ctx_put(); -+ -+ /* Decrease the attached context count on the adapter */ -+ cxl_adapter_context_put(ctx->afu->adapter); - return 0; - } - -diff --git a/drivers/misc/cxl/cxl.h b/drivers/misc/cxl/cxl.h -index 344a0ff..19aa2ac 100644 ---- a/drivers/misc/cxl/cxl.h -+++ b/drivers/misc/cxl/cxl.h -@@ -615,6 +615,14 @@ struct cxl { - bool perst_select_user; - bool perst_same_image; - bool psl_timebase_synced; -+ -+ /* -+ * number of contexts mapped on to this card. Possible values are: -+ * >0: Number of contexts mapped and new one can be mapped. -+ * 0: No active contexts and new ones can be mapped. -+ * -1: No contexts mapped and new ones cannot be mapped. -+ */ -+ atomic_t contexts_num; - }; - - int cxl_pci_alloc_one_irq(struct cxl *adapter); -@@ -940,4 +948,20 @@ bool cxl_pci_is_vphb_device(struct pci_dev *dev); - - /* decode AFU error bits in the PSL register PSL_SERR_An */ - void cxl_afu_decode_psl_serr(struct cxl_afu *afu, u64 serr); -+ -+/* -+ * Increments the number of attached contexts on an adapter. -+ * In case an adapter_context_lock is taken the return -EBUSY. -+ */ -+int cxl_adapter_context_get(struct cxl *adapter); -+ -+/* Decrements the number of attached contexts on an adapter */ -+void cxl_adapter_context_put(struct cxl *adapter); -+ -+/* If no active contexts then prevents contexts from being attached */ -+int cxl_adapter_context_lock(struct cxl *adapter); -+ -+/* Unlock the contexts-lock if taken. Warn and force unlock otherwise */ -+void cxl_adapter_context_unlock(struct cxl *adapter); -+ - #endif -diff --git a/drivers/misc/cxl/file.c b/drivers/misc/cxl/file.c -index 5fb9894..d0b421f 100644 ---- a/drivers/misc/cxl/file.c -+++ b/drivers/misc/cxl/file.c -@@ -205,11 +205,22 @@ static long afu_ioctl_start_work(struct cxl_context *ctx, - ctx->pid = get_task_pid(current, PIDTYPE_PID); - ctx->glpid = get_task_pid(current->group_leader, PIDTYPE_PID); - -+ /* -+ * Increment the mapped context count for adapter. This also checks -+ * if adapter_context_lock is taken. -+ */ -+ rc = cxl_adapter_context_get(ctx->afu->adapter); -+ if (rc) { -+ afu_release_irqs(ctx, ctx); -+ goto out; -+ } -+ - trace_cxl_attach(ctx, work.work_element_descriptor, work.num_interrupts, amr); - - if ((rc = cxl_ops->attach_process(ctx, false, work.work_element_descriptor, - amr))) { - afu_release_irqs(ctx, ctx); -+ cxl_adapter_context_put(ctx->afu->adapter); - goto out; - } - -diff --git a/drivers/misc/cxl/guest.c b/drivers/misc/cxl/guest.c -index 9aa58a7..3e102cd 100644 ---- a/drivers/misc/cxl/guest.c -+++ b/drivers/misc/cxl/guest.c -@@ -1152,6 +1152,9 @@ struct cxl *cxl_guest_init_adapter(struct device_node *np, struct platform_devic - if ((rc = cxl_sysfs_adapter_add(adapter))) - goto err_put1; - -+ /* release the context lock as the adapter is configured */ -+ cxl_adapter_context_unlock(adapter); -+ - return adapter; - - err_put1: -diff --git a/drivers/misc/cxl/main.c b/drivers/misc/cxl/main.c -index d9be23b2..62e0dfb 100644 ---- a/drivers/misc/cxl/main.c -+++ b/drivers/misc/cxl/main.c -@@ -243,8 +243,10 @@ struct cxl *cxl_alloc_adapter(void) - if (dev_set_name(&adapter->dev, "card%i", adapter->adapter_num)) - goto err2; - -- return adapter; -+ /* start with context lock taken */ -+ atomic_set(&adapter->contexts_num, -1); - -+ return adapter; - err2: - cxl_remove_adapter_nr(adapter); - err1: -@@ -286,6 +288,44 @@ int cxl_afu_select_best_mode(struct cxl_afu *afu) - return 0; - } - -+int cxl_adapter_context_get(struct cxl *adapter) -+{ -+ int rc; -+ -+ rc = atomic_inc_unless_negative(&adapter->contexts_num); -+ return rc >= 0 ? 0 : -EBUSY; -+} -+ -+void cxl_adapter_context_put(struct cxl *adapter) -+{ -+ atomic_dec_if_positive(&adapter->contexts_num); -+} -+ -+int cxl_adapter_context_lock(struct cxl *adapter) -+{ -+ int rc; -+ /* no active contexts -> contexts_num == 0 */ -+ rc = atomic_cmpxchg(&adapter->contexts_num, 0, -1); -+ return rc ? -EBUSY : 0; -+} -+ -+void cxl_adapter_context_unlock(struct cxl *adapter) -+{ -+ int val = atomic_cmpxchg(&adapter->contexts_num, -1, 0); -+ -+ /* -+ * contexts lock taken -> contexts_num == -1 -+ * If not true then show a warning and force reset the lock. -+ * This will happen when context_unlock was requested without -+ * doing a context_lock. -+ */ -+ if (val != -1) { -+ atomic_set(&adapter->contexts_num, 0); -+ WARN(1, "Adapter context unlocked with %d active contexts", -+ val); -+ } -+} -+ - static int __init init_cxl(void) - { - int rc = 0; -diff --git a/drivers/misc/cxl/pci.c b/drivers/misc/cxl/pci.c -index 6f0c4ac..8ad4e4f 100644 ---- a/drivers/misc/cxl/pci.c -+++ b/drivers/misc/cxl/pci.c -@@ -1484,6 +1484,8 @@ static int cxl_configure_adapter(struct cxl *adapter, struct pci_dev *dev) - if ((rc = cxl_native_register_psl_err_irq(adapter))) - goto err; - -+ /* Release the context lock as adapter is configured */ -+ cxl_adapter_context_unlock(adapter); - return 0; - - err: -diff --git a/drivers/misc/cxl/sysfs.c b/drivers/misc/cxl/sysfs.c -index b043c20..a8b6d6a 100644 ---- a/drivers/misc/cxl/sysfs.c -+++ b/drivers/misc/cxl/sysfs.c -@@ -75,12 +75,31 @@ static ssize_t reset_adapter_store(struct device *device, - int val; - - rc = sscanf(buf, "%i", &val); -- if ((rc != 1) || (val != 1)) -+ if ((rc != 1) || (val != 1 && val != -1)) - return -EINVAL; - -- if ((rc = cxl_ops->adapter_reset(adapter))) -- return rc; -- return count; -+ /* -+ * See if we can lock the context mapping that's only allowed -+ * when there are no contexts attached to the adapter. Once -+ * taken this will also prevent any context from getting activated. -+ */ -+ if (val == 1) { -+ rc = cxl_adapter_context_lock(adapter); -+ if (rc) -+ goto out; -+ -+ rc = cxl_ops->adapter_reset(adapter); -+ /* In case reset failed release context lock */ -+ if (rc) -+ cxl_adapter_context_unlock(adapter); -+ -+ } else if (val == -1) { -+ /* Perform a forced adapter reset */ -+ rc = cxl_ops->adapter_reset(adapter); -+ } -+ -+out: -+ return rc ? rc : count; - } - - static ssize_t load_image_on_perst_show(struct device *device, -diff --git a/drivers/misc/mei/amthif.c b/drivers/misc/mei/amthif.c -index fd9271b..cd01e34 100644 ---- a/drivers/misc/mei/amthif.c -+++ b/drivers/misc/mei/amthif.c -@@ -139,7 +139,7 @@ int mei_amthif_read(struct mei_device *dev, struct file *file, - return -ERESTARTSYS; - - if (!mei_cl_is_connected(cl)) { -- rets = -EBUSY; -+ rets = -ENODEV; - goto out; - } - -diff --git a/drivers/misc/mei/bus.c b/drivers/misc/mei/bus.c -index e094df3..5b5b2e0 100644 ---- a/drivers/misc/mei/bus.c -+++ b/drivers/misc/mei/bus.c -@@ -142,7 +142,7 @@ ssize_t __mei_cl_recv(struct mei_cl *cl, u8 *buf, size_t length) - mutex_lock(&bus->device_lock); - - if (!mei_cl_is_connected(cl)) { -- rets = -EBUSY; -+ rets = -ENODEV; - goto out; - } - } -diff --git a/drivers/misc/mei/hw-me-regs.h b/drivers/misc/mei/hw-me-regs.h -index 0dcb854..7ad15d6 100644 ---- a/drivers/misc/mei/hw-me-regs.h -+++ b/drivers/misc/mei/hw-me-regs.h -@@ -125,6 +125,9 @@ - #define MEI_DEV_ID_BXT_M 0x1A9A /* Broxton M */ - #define MEI_DEV_ID_APL_I 0x5A9A /* Apollo Lake I */ - -+#define MEI_DEV_ID_KBP 0xA2BA /* Kaby Point */ -+#define MEI_DEV_ID_KBP_2 0xA2BB /* Kaby Point 2 */ -+ - /* - * MEI HW Section - */ -diff --git a/drivers/misc/mei/main.c b/drivers/misc/mei/main.c -index 52635b0..080208d 100644 ---- a/drivers/misc/mei/main.c -+++ b/drivers/misc/mei/main.c -@@ -202,7 +202,7 @@ static ssize_t mei_read(struct file *file, char __user *ubuf, - - mutex_lock(&dev->device_lock); - if (!mei_cl_is_connected(cl)) { -- rets = -EBUSY; -+ rets = -ENODEV; - goto out; - } - } -diff --git a/drivers/misc/mei/pci-me.c b/drivers/misc/mei/pci-me.c -index 71cea9b..5eb9b75 100644 ---- a/drivers/misc/mei/pci-me.c -+++ b/drivers/misc/mei/pci-me.c -@@ -91,6 +91,9 @@ static const struct pci_device_id mei_me_pci_tbl[] = { - {MEI_PCI_DEVICE(MEI_DEV_ID_BXT_M, mei_me_pch8_cfg)}, - {MEI_PCI_DEVICE(MEI_DEV_ID_APL_I, mei_me_pch8_cfg)}, - -+ {MEI_PCI_DEVICE(MEI_DEV_ID_KBP, mei_me_pch8_cfg)}, -+ {MEI_PCI_DEVICE(MEI_DEV_ID_KBP_2, mei_me_pch8_cfg)}, -+ - /* required last entry */ - {0, } - }; -diff --git a/drivers/mmc/card/block.c b/drivers/mmc/card/block.c -index 2206d44..17891f1 100644 ---- a/drivers/mmc/card/block.c -+++ b/drivers/mmc/card/block.c -@@ -1778,7 +1778,7 @@ static void mmc_blk_packed_hdr_wrq_prep(struct mmc_queue_req *mqrq, - struct mmc_blk_data *md = mq->data; - struct mmc_packed *packed = mqrq->packed; - bool do_rel_wr, do_data_tag; -- u32 *packed_cmd_hdr; -+ __le32 *packed_cmd_hdr; - u8 hdr_blocks; - u8 i = 1; - -@@ -2303,7 +2303,8 @@ static struct mmc_blk_data *mmc_blk_alloc_req(struct mmc_card *card, - set_capacity(md->disk, size); - - if (mmc_host_cmd23(card->host)) { -- if (mmc_card_mmc(card) || -+ if ((mmc_card_mmc(card) && -+ card->csd.mmca_vsn >= CSD_SPEC_VER_3) || - (mmc_card_sd(card) && - card->scr.cmds & SD_SCR_CMD23_SUPPORT)) - md->flags |= MMC_BLK_CMD23; -diff --git a/drivers/mmc/card/queue.h b/drivers/mmc/card/queue.h -index fee5e12..7f16709 100644 ---- a/drivers/mmc/card/queue.h -+++ b/drivers/mmc/card/queue.h -@@ -31,7 +31,7 @@ enum mmc_packed_type { - - struct mmc_packed { - struct list_head list; -- u32 cmd_hdr[1024]; -+ __le32 cmd_hdr[1024]; - unsigned int blocks; - u8 nr_entries; - u8 retries; -diff --git a/drivers/mmc/core/mmc.c b/drivers/mmc/core/mmc.c -index f2d185c..c57eb32 100644 ---- a/drivers/mmc/core/mmc.c -+++ b/drivers/mmc/core/mmc.c -@@ -1259,6 +1259,16 @@ static int mmc_select_hs400es(struct mmc_card *card) - goto out_err; - } - -+ if (card->mmc_avail_type & EXT_CSD_CARD_TYPE_HS400_1_2V) -+ err = __mmc_set_signal_voltage(host, MMC_SIGNAL_VOLTAGE_120); -+ -+ if (err && card->mmc_avail_type & EXT_CSD_CARD_TYPE_HS400_1_8V) -+ err = __mmc_set_signal_voltage(host, MMC_SIGNAL_VOLTAGE_180); -+ -+ /* If fails try again during next card power cycle */ -+ if (err) -+ goto out_err; -+ - err = mmc_select_bus_width(card); - if (err < 0) - goto out_err; -diff --git a/drivers/mmc/host/rtsx_usb_sdmmc.c b/drivers/mmc/host/rtsx_usb_sdmmc.c -index 6c71fc9..da9f71b 100644 ---- a/drivers/mmc/host/rtsx_usb_sdmmc.c -+++ b/drivers/mmc/host/rtsx_usb_sdmmc.c -@@ -1138,11 +1138,6 @@ static void sdmmc_set_ios(struct mmc_host *mmc, struct mmc_ios *ios) - dev_dbg(sdmmc_dev(host), "%s\n", __func__); - mutex_lock(&ucr->dev_mutex); - -- if (rtsx_usb_card_exclusive_check(ucr, RTSX_USB_SD_CARD)) { -- mutex_unlock(&ucr->dev_mutex); -- return; -- } -- - sd_set_power_mode(host, ios->power_mode); - sd_set_bus_width(host, ios->bus_width); - sd_set_timing(host, ios->timing, &host->ddr_mode); -@@ -1314,6 +1309,7 @@ static void rtsx_usb_update_led(struct work_struct *work) - container_of(work, struct rtsx_usb_sdmmc, led_work); - struct rtsx_ucr *ucr = host->ucr; - -+ pm_runtime_get_sync(sdmmc_dev(host)); - mutex_lock(&ucr->dev_mutex); - - if (host->led.brightness == LED_OFF) -@@ -1322,6 +1318,7 @@ static void rtsx_usb_update_led(struct work_struct *work) - rtsx_usb_turn_on_led(ucr); - - mutex_unlock(&ucr->dev_mutex); -+ pm_runtime_put(sdmmc_dev(host)); - } - #endif - -diff --git a/drivers/mmc/host/sdhci.c b/drivers/mmc/host/sdhci.c -index cd65d47..a8a022a 100644 ---- a/drivers/mmc/host/sdhci.c -+++ b/drivers/mmc/host/sdhci.c -@@ -687,7 +687,7 @@ static u8 sdhci_calc_timeout(struct sdhci_host *host, struct mmc_command *cmd) - * host->clock is in Hz. target_timeout is in us. - * Hence, us = 1000000 * cycles / Hz. Round up. - */ -- val = 1000000 * data->timeout_clks; -+ val = 1000000ULL * data->timeout_clks; - if (do_div(val, host->clock)) - target_timeout++; - target_timeout += val; -diff --git a/drivers/mtd/ubi/wl.c b/drivers/mtd/ubi/wl.c -index f453326..b419c7c 100644 ---- a/drivers/mtd/ubi/wl.c -+++ b/drivers/mtd/ubi/wl.c -@@ -644,7 +644,7 @@ static int wear_leveling_worker(struct ubi_device *ubi, struct ubi_work *wrk, - int shutdown) - { - int err, scrubbing = 0, torture = 0, protect = 0, erroneous = 0; -- int vol_id = -1, lnum = -1; -+ int erase = 0, keep = 0, vol_id = -1, lnum = -1; - #ifdef CONFIG_MTD_UBI_FASTMAP - int anchor = wrk->anchor; - #endif -@@ -780,6 +780,16 @@ static int wear_leveling_worker(struct ubi_device *ubi, struct ubi_work *wrk, - e1->pnum); - scrubbing = 1; - goto out_not_moved; -+ } else if (ubi->fast_attach && err == UBI_IO_BAD_HDR_EBADMSG) { -+ /* -+ * While a full scan would detect interrupted erasures -+ * at attach time we can face them here when attached from -+ * Fastmap. -+ */ -+ dbg_wl("PEB %d has ECC errors, maybe from an interrupted erasure", -+ e1->pnum); -+ erase = 1; -+ goto out_not_moved; - } - - ubi_err(ubi, "error %d while reading VID header from PEB %d", -@@ -815,6 +825,7 @@ static int wear_leveling_worker(struct ubi_device *ubi, struct ubi_work *wrk, - * Target PEB had bit-flips or write error - torture it. - */ - torture = 1; -+ keep = 1; - goto out_not_moved; - } - -@@ -901,7 +912,7 @@ static int wear_leveling_worker(struct ubi_device *ubi, struct ubi_work *wrk, - ubi->erroneous_peb_count += 1; - } else if (scrubbing) - wl_tree_add(e1, &ubi->scrub); -- else -+ else if (keep) - wl_tree_add(e1, &ubi->used); - if (dst_leb_clean) { - wl_tree_add(e2, &ubi->free); -@@ -922,6 +933,12 @@ static int wear_leveling_worker(struct ubi_device *ubi, struct ubi_work *wrk, - goto out_ro; - } - -+ if (erase) { -+ err = do_sync_erase(ubi, e1, vol_id, lnum, 1); -+ if (err) -+ goto out_ro; -+ } -+ - mutex_unlock(&ubi->move_mutex); - return 0; - -diff --git a/drivers/net/wireless/ath/ath10k/ce.c b/drivers/net/wireless/ath/ath10k/ce.c -index 9fb8d74..da9998e 100644 ---- a/drivers/net/wireless/ath/ath10k/ce.c -+++ b/drivers/net/wireless/ath/ath10k/ce.c -@@ -433,6 +433,13 @@ void ath10k_ce_rx_update_write_idx(struct ath10k_ce_pipe *pipe, u32 nentries) - unsigned int nentries_mask = dest_ring->nentries_mask; - unsigned int write_index = dest_ring->write_index; - u32 ctrl_addr = pipe->ctrl_addr; -+ u32 cur_write_idx = ath10k_ce_dest_ring_write_index_get(ar, ctrl_addr); -+ -+ /* Prevent CE ring stuck issue that will occur when ring is full. -+ * Make sure that write index is 1 less than read index. -+ */ -+ if ((cur_write_idx + nentries) == dest_ring->sw_index) -+ nentries -= 1; - - write_index = CE_RING_IDX_ADD(nentries_mask, write_index, nentries); - ath10k_ce_dest_ring_write_index_set(ar, ctrl_addr, write_index); -diff --git a/drivers/net/wireless/realtek/rtlwifi/regd.c b/drivers/net/wireless/realtek/rtlwifi/regd.c -index 3524441..6ee6bf8 100644 ---- a/drivers/net/wireless/realtek/rtlwifi/regd.c -+++ b/drivers/net/wireless/realtek/rtlwifi/regd.c -@@ -345,9 +345,9 @@ static const struct ieee80211_regdomain *_rtl_regdomain_select( - return &rtl_regdom_no_midband; - case COUNTRY_CODE_IC: - return &rtl_regdom_11; -- case COUNTRY_CODE_ETSI: - case COUNTRY_CODE_TELEC_NETGEAR: - return &rtl_regdom_60_64; -+ case COUNTRY_CODE_ETSI: - case COUNTRY_CODE_SPAIN: - case COUNTRY_CODE_FRANCE: - case COUNTRY_CODE_ISRAEL: -@@ -406,6 +406,8 @@ static u8 channel_plan_to_country_code(u8 channelplan) - return COUNTRY_CODE_WORLD_WIDE_13; - case 0x22: - return COUNTRY_CODE_IC; -+ case 0x25: -+ return COUNTRY_CODE_ETSI; - case 0x32: - return COUNTRY_CODE_TELEC_NETGEAR; - case 0x41: -diff --git a/drivers/pci/host/pci-tegra.c b/drivers/pci/host/pci-tegra.c -index 6de0757..84d650d 100644 ---- a/drivers/pci/host/pci-tegra.c -+++ b/drivers/pci/host/pci-tegra.c -@@ -856,7 +856,7 @@ static int tegra_pcie_phy_disable(struct tegra_pcie *pcie) - /* override IDDQ */ - value = pads_readl(pcie, PADS_CTL); - value |= PADS_CTL_IDDQ_1L; -- pads_writel(pcie, PADS_CTL, value); -+ pads_writel(pcie, value, PADS_CTL); - - /* reset PLL */ - value = pads_readl(pcie, soc->pads_pll_ctl); -diff --git a/drivers/pci/quirks.c b/drivers/pci/quirks.c -index 44e0ff3..4bf1a88 100644 ---- a/drivers/pci/quirks.c -+++ b/drivers/pci/quirks.c -@@ -3198,6 +3198,7 @@ static void quirk_no_bus_reset(struct pci_dev *dev) - DECLARE_PCI_FIXUP_HEADER(PCI_VENDOR_ID_ATHEROS, 0x0030, quirk_no_bus_reset); - DECLARE_PCI_FIXUP_HEADER(PCI_VENDOR_ID_ATHEROS, 0x0032, quirk_no_bus_reset); - DECLARE_PCI_FIXUP_HEADER(PCI_VENDOR_ID_ATHEROS, 0x003c, quirk_no_bus_reset); -+DECLARE_PCI_FIXUP_HEADER(PCI_VENDOR_ID_ATHEROS, 0x0033, quirk_no_bus_reset); - - static void quirk_no_pm_reset(struct pci_dev *dev) - { -diff --git a/drivers/pinctrl/intel/pinctrl-baytrail.c b/drivers/pinctrl/intel/pinctrl-baytrail.c -index d22a9fe..71bbeb9 100644 ---- a/drivers/pinctrl/intel/pinctrl-baytrail.c -+++ b/drivers/pinctrl/intel/pinctrl-baytrail.c -@@ -1808,6 +1808,8 @@ static int byt_pinctrl_probe(struct platform_device *pdev) - return PTR_ERR(vg->pctl_dev); - } - -+ raw_spin_lock_init(&vg->lock); -+ - ret = byt_gpio_probe(vg); - if (ret) { - pinctrl_unregister(vg->pctl_dev); -@@ -1815,7 +1817,6 @@ static int byt_pinctrl_probe(struct platform_device *pdev) - } - - platform_set_drvdata(pdev, vg); -- raw_spin_lock_init(&vg->lock); - pm_runtime_enable(&pdev->dev); - - return 0; -diff --git a/drivers/pinctrl/intel/pinctrl-intel.c b/drivers/pinctrl/intel/pinctrl-intel.c -index 257cab1..2b5b20bf 100644 ---- a/drivers/pinctrl/intel/pinctrl-intel.c -+++ b/drivers/pinctrl/intel/pinctrl-intel.c -@@ -19,6 +19,7 @@ - #include <linux/pinctrl/pinconf.h> - #include <linux/pinctrl/pinconf-generic.h> - -+#include "../core.h" - #include "pinctrl-intel.h" - - /* Offset from regs */ -@@ -1079,6 +1080,26 @@ int intel_pinctrl_remove(struct platform_device *pdev) - EXPORT_SYMBOL_GPL(intel_pinctrl_remove); - - #ifdef CONFIG_PM_SLEEP -+static bool intel_pinctrl_should_save(struct intel_pinctrl *pctrl, unsigned pin) -+{ -+ const struct pin_desc *pd = pin_desc_get(pctrl->pctldev, pin); -+ -+ if (!pd || !intel_pad_usable(pctrl, pin)) -+ return false; -+ -+ /* -+ * Only restore the pin if it is actually in use by the kernel (or -+ * by userspace). It is possible that some pins are used by the -+ * BIOS during resume and those are not always locked down so leave -+ * them alone. -+ */ -+ if (pd->mux_owner || pd->gpio_owner || -+ gpiochip_line_is_irq(&pctrl->chip, pin)) -+ return true; -+ -+ return false; -+} -+ - int intel_pinctrl_suspend(struct device *dev) - { - struct platform_device *pdev = to_platform_device(dev); -@@ -1092,7 +1113,7 @@ int intel_pinctrl_suspend(struct device *dev) - const struct pinctrl_pin_desc *desc = &pctrl->soc->pins[i]; - u32 val; - -- if (!intel_pad_usable(pctrl, desc->number)) -+ if (!intel_pinctrl_should_save(pctrl, desc->number)) - continue; - - val = readl(intel_get_padcfg(pctrl, desc->number, PADCFG0)); -@@ -1153,7 +1174,7 @@ int intel_pinctrl_resume(struct device *dev) - void __iomem *padcfg; - u32 val; - -- if (!intel_pad_usable(pctrl, desc->number)) -+ if (!intel_pinctrl_should_save(pctrl, desc->number)) - continue; - - padcfg = intel_get_padcfg(pctrl, desc->number, PADCFG0); -diff --git a/drivers/regulator/tps65910-regulator.c b/drivers/regulator/tps65910-regulator.c -index fb991ec..696116e 100644 ---- a/drivers/regulator/tps65910-regulator.c -+++ b/drivers/regulator/tps65910-regulator.c -@@ -1111,6 +1111,12 @@ static int tps65910_probe(struct platform_device *pdev) - pmic->num_regulators = ARRAY_SIZE(tps65910_regs); - pmic->ext_sleep_control = tps65910_ext_sleep_control; - info = tps65910_regs; -+ /* Work around silicon erratum SWCZ010: output programmed -+ * voltage level can go higher than expected or crash -+ * Workaround: use no synchronization of DCDC clocks -+ */ -+ tps65910_reg_clear_bits(pmic->mfd, TPS65910_DCDCCTRL, -+ DCDCCTRL_DCDCCKSYNC_MASK); - break; - case TPS65911: - pmic->get_ctrl_reg = &tps65911_get_ctrl_register; -diff --git a/drivers/s390/scsi/zfcp_dbf.c b/drivers/s390/scsi/zfcp_dbf.c -index 5d7fbe4..5810019 100644 ---- a/drivers/s390/scsi/zfcp_dbf.c -+++ b/drivers/s390/scsi/zfcp_dbf.c -@@ -3,7 +3,7 @@ - * - * Debug traces for zfcp. - * -- * Copyright IBM Corp. 2002, 2013 -+ * Copyright IBM Corp. 2002, 2016 - */ - - #define KMSG_COMPONENT "zfcp" -@@ -65,7 +65,7 @@ void zfcp_dbf_pl_write(struct zfcp_dbf *dbf, void *data, u16 length, char *area, - * @tag: tag indicating which kind of unsolicited status has been received - * @req: request for which a response was received - */ --void zfcp_dbf_hba_fsf_res(char *tag, struct zfcp_fsf_req *req) -+void zfcp_dbf_hba_fsf_res(char *tag, int level, struct zfcp_fsf_req *req) - { - struct zfcp_dbf *dbf = req->adapter->dbf; - struct fsf_qtcb_prefix *q_pref = &req->qtcb->prefix; -@@ -85,6 +85,8 @@ void zfcp_dbf_hba_fsf_res(char *tag, struct zfcp_fsf_req *req) - rec->u.res.req_issued = req->issued; - rec->u.res.prot_status = q_pref->prot_status; - rec->u.res.fsf_status = q_head->fsf_status; -+ rec->u.res.port_handle = q_head->port_handle; -+ rec->u.res.lun_handle = q_head->lun_handle; - - memcpy(rec->u.res.prot_status_qual, &q_pref->prot_status_qual, - FSF_PROT_STATUS_QUAL_SIZE); -@@ -97,7 +99,7 @@ void zfcp_dbf_hba_fsf_res(char *tag, struct zfcp_fsf_req *req) - rec->pl_len, "fsf_res", req->req_id); - } - -- debug_event(dbf->hba, 1, rec, sizeof(*rec)); -+ debug_event(dbf->hba, level, rec, sizeof(*rec)); - spin_unlock_irqrestore(&dbf->hba_lock, flags); - } - -@@ -241,7 +243,8 @@ static void zfcp_dbf_set_common(struct zfcp_dbf_rec *rec, - if (sdev) { - rec->lun_status = atomic_read(&sdev_to_zfcp(sdev)->status); - rec->lun = zfcp_scsi_dev_lun(sdev); -- } -+ } else -+ rec->lun = ZFCP_DBF_INVALID_LUN; - } - - /** -@@ -320,13 +323,48 @@ void zfcp_dbf_rec_run(char *tag, struct zfcp_erp_action *erp) - spin_unlock_irqrestore(&dbf->rec_lock, flags); - } - -+/** -+ * zfcp_dbf_rec_run_wka - trace wka port event with info like running recovery -+ * @tag: identifier for event -+ * @wka_port: well known address port -+ * @req_id: request ID to correlate with potential HBA trace record -+ */ -+void zfcp_dbf_rec_run_wka(char *tag, struct zfcp_fc_wka_port *wka_port, -+ u64 req_id) -+{ -+ struct zfcp_dbf *dbf = wka_port->adapter->dbf; -+ struct zfcp_dbf_rec *rec = &dbf->rec_buf; -+ unsigned long flags; -+ -+ spin_lock_irqsave(&dbf->rec_lock, flags); -+ memset(rec, 0, sizeof(*rec)); -+ -+ rec->id = ZFCP_DBF_REC_RUN; -+ memcpy(rec->tag, tag, ZFCP_DBF_TAG_LEN); -+ rec->port_status = wka_port->status; -+ rec->d_id = wka_port->d_id; -+ rec->lun = ZFCP_DBF_INVALID_LUN; -+ -+ rec->u.run.fsf_req_id = req_id; -+ rec->u.run.rec_status = ~0; -+ rec->u.run.rec_step = ~0; -+ rec->u.run.rec_action = ~0; -+ rec->u.run.rec_count = ~0; -+ -+ debug_event(dbf->rec, 1, rec, sizeof(*rec)); -+ spin_unlock_irqrestore(&dbf->rec_lock, flags); -+} -+ - static inline --void zfcp_dbf_san(char *tag, struct zfcp_dbf *dbf, void *data, u8 id, u16 len, -- u64 req_id, u32 d_id) -+void zfcp_dbf_san(char *tag, struct zfcp_dbf *dbf, -+ char *paytag, struct scatterlist *sg, u8 id, u16 len, -+ u64 req_id, u32 d_id, u16 cap_len) - { - struct zfcp_dbf_san *rec = &dbf->san_buf; - u16 rec_len; - unsigned long flags; -+ struct zfcp_dbf_pay *payload = &dbf->pay_buf; -+ u16 pay_sum = 0; - - spin_lock_irqsave(&dbf->san_lock, flags); - memset(rec, 0, sizeof(*rec)); -@@ -334,10 +372,41 @@ void zfcp_dbf_san(char *tag, struct zfcp_dbf *dbf, void *data, u8 id, u16 len, - rec->id = id; - rec->fsf_req_id = req_id; - rec->d_id = d_id; -- rec_len = min(len, (u16)ZFCP_DBF_SAN_MAX_PAYLOAD); -- memcpy(rec->payload, data, rec_len); - memcpy(rec->tag, tag, ZFCP_DBF_TAG_LEN); -+ rec->pl_len = len; /* full length even if we cap pay below */ -+ if (!sg) -+ goto out; -+ rec_len = min_t(unsigned int, sg->length, ZFCP_DBF_SAN_MAX_PAYLOAD); -+ memcpy(rec->payload, sg_virt(sg), rec_len); /* part of 1st sg entry */ -+ if (len <= rec_len) -+ goto out; /* skip pay record if full content in rec->payload */ -+ -+ /* if (len > rec_len): -+ * dump data up to cap_len ignoring small duplicate in rec->payload -+ */ -+ spin_lock(&dbf->pay_lock); -+ memset(payload, 0, sizeof(*payload)); -+ memcpy(payload->area, paytag, ZFCP_DBF_TAG_LEN); -+ payload->fsf_req_id = req_id; -+ payload->counter = 0; -+ for (; sg && pay_sum < cap_len; sg = sg_next(sg)) { -+ u16 pay_len, offset = 0; -+ -+ while (offset < sg->length && pay_sum < cap_len) { -+ pay_len = min((u16)ZFCP_DBF_PAY_MAX_REC, -+ (u16)(sg->length - offset)); -+ /* cap_len <= pay_sum < cap_len+ZFCP_DBF_PAY_MAX_REC */ -+ memcpy(payload->data, sg_virt(sg) + offset, pay_len); -+ debug_event(dbf->pay, 1, payload, -+ zfcp_dbf_plen(pay_len)); -+ payload->counter++; -+ offset += pay_len; -+ pay_sum += pay_len; -+ } -+ } -+ spin_unlock(&dbf->pay_lock); - -+out: - debug_event(dbf->san, 1, rec, sizeof(*rec)); - spin_unlock_irqrestore(&dbf->san_lock, flags); - } -@@ -354,9 +423,62 @@ void zfcp_dbf_san_req(char *tag, struct zfcp_fsf_req *fsf, u32 d_id) - struct zfcp_fsf_ct_els *ct_els = fsf->data; - u16 length; - -- length = (u16)(ct_els->req->length + FC_CT_HDR_LEN); -- zfcp_dbf_san(tag, dbf, sg_virt(ct_els->req), ZFCP_DBF_SAN_REQ, length, -- fsf->req_id, d_id); -+ length = (u16)zfcp_qdio_real_bytes(ct_els->req); -+ zfcp_dbf_san(tag, dbf, "san_req", ct_els->req, ZFCP_DBF_SAN_REQ, -+ length, fsf->req_id, d_id, length); -+} -+ -+static u16 zfcp_dbf_san_res_cap_len_if_gpn_ft(char *tag, -+ struct zfcp_fsf_req *fsf, -+ u16 len) -+{ -+ struct zfcp_fsf_ct_els *ct_els = fsf->data; -+ struct fc_ct_hdr *reqh = sg_virt(ct_els->req); -+ struct fc_ns_gid_ft *reqn = (struct fc_ns_gid_ft *)(reqh + 1); -+ struct scatterlist *resp_entry = ct_els->resp; -+ struct fc_gpn_ft_resp *acc; -+ int max_entries, x, last = 0; -+ -+ if (!(memcmp(tag, "fsscth2", 7) == 0 -+ && ct_els->d_id == FC_FID_DIR_SERV -+ && reqh->ct_rev == FC_CT_REV -+ && reqh->ct_in_id[0] == 0 -+ && reqh->ct_in_id[1] == 0 -+ && reqh->ct_in_id[2] == 0 -+ && reqh->ct_fs_type == FC_FST_DIR -+ && reqh->ct_fs_subtype == FC_NS_SUBTYPE -+ && reqh->ct_options == 0 -+ && reqh->_ct_resvd1 == 0 -+ && reqh->ct_cmd == FC_NS_GPN_FT -+ /* reqh->ct_mr_size can vary so do not match but read below */ -+ && reqh->_ct_resvd2 == 0 -+ && reqh->ct_reason == 0 -+ && reqh->ct_explan == 0 -+ && reqh->ct_vendor == 0 -+ && reqn->fn_resvd == 0 -+ && reqn->fn_domain_id_scope == 0 -+ && reqn->fn_area_id_scope == 0 -+ && reqn->fn_fc4_type == FC_TYPE_FCP)) -+ return len; /* not GPN_FT response so do not cap */ -+ -+ acc = sg_virt(resp_entry); -+ max_entries = (reqh->ct_mr_size * 4 / sizeof(struct fc_gpn_ft_resp)) -+ + 1 /* zfcp_fc_scan_ports: bytes correct, entries off-by-one -+ * to account for header as 1st pseudo "entry" */; -+ -+ /* the basic CT_IU preamble is the same size as one entry in the GPN_FT -+ * response, allowing us to skip special handling for it - just skip it -+ */ -+ for (x = 1; x < max_entries && !last; x++) { -+ if (x % (ZFCP_FC_GPN_FT_ENT_PAGE + 1)) -+ acc++; -+ else -+ acc = sg_virt(++resp_entry); -+ -+ last = acc->fp_flags & FC_NS_FID_LAST; -+ } -+ len = min(len, (u16)(x * sizeof(struct fc_gpn_ft_resp))); -+ return len; /* cap after last entry */ - } - - /** -@@ -370,9 +492,10 @@ void zfcp_dbf_san_res(char *tag, struct zfcp_fsf_req *fsf) - struct zfcp_fsf_ct_els *ct_els = fsf->data; - u16 length; - -- length = (u16)(ct_els->resp->length + FC_CT_HDR_LEN); -- zfcp_dbf_san(tag, dbf, sg_virt(ct_els->resp), ZFCP_DBF_SAN_RES, length, -- fsf->req_id, 0); -+ length = (u16)zfcp_qdio_real_bytes(ct_els->resp); -+ zfcp_dbf_san(tag, dbf, "san_res", ct_els->resp, ZFCP_DBF_SAN_RES, -+ length, fsf->req_id, ct_els->d_id, -+ zfcp_dbf_san_res_cap_len_if_gpn_ft(tag, fsf, length)); - } - - /** -@@ -386,11 +509,13 @@ void zfcp_dbf_san_in_els(char *tag, struct zfcp_fsf_req *fsf) - struct fsf_status_read_buffer *srb = - (struct fsf_status_read_buffer *) fsf->data; - u16 length; -+ struct scatterlist sg; - - length = (u16)(srb->length - - offsetof(struct fsf_status_read_buffer, payload)); -- zfcp_dbf_san(tag, dbf, srb->payload.data, ZFCP_DBF_SAN_ELS, length, -- fsf->req_id, ntoh24(srb->d_id)); -+ sg_init_one(&sg, srb->payload.data, length); -+ zfcp_dbf_san(tag, dbf, "san_els", &sg, ZFCP_DBF_SAN_ELS, length, -+ fsf->req_id, ntoh24(srb->d_id), length); - } - - /** -@@ -399,7 +524,8 @@ void zfcp_dbf_san_in_els(char *tag, struct zfcp_fsf_req *fsf) - * @sc: pointer to struct scsi_cmnd - * @fsf: pointer to struct zfcp_fsf_req - */ --void zfcp_dbf_scsi(char *tag, struct scsi_cmnd *sc, struct zfcp_fsf_req *fsf) -+void zfcp_dbf_scsi(char *tag, int level, struct scsi_cmnd *sc, -+ struct zfcp_fsf_req *fsf) - { - struct zfcp_adapter *adapter = - (struct zfcp_adapter *) sc->device->host->hostdata[0]; -@@ -442,7 +568,7 @@ void zfcp_dbf_scsi(char *tag, struct scsi_cmnd *sc, struct zfcp_fsf_req *fsf) - } - } - -- debug_event(dbf->scsi, 1, rec, sizeof(*rec)); -+ debug_event(dbf->scsi, level, rec, sizeof(*rec)); - spin_unlock_irqrestore(&dbf->scsi_lock, flags); - } - -diff --git a/drivers/s390/scsi/zfcp_dbf.h b/drivers/s390/scsi/zfcp_dbf.h -index 0be3d48..36d0758 100644 ---- a/drivers/s390/scsi/zfcp_dbf.h -+++ b/drivers/s390/scsi/zfcp_dbf.h -@@ -2,7 +2,7 @@ - * zfcp device driver - * debug feature declarations - * -- * Copyright IBM Corp. 2008, 2010 -+ * Copyright IBM Corp. 2008, 2015 - */ - - #ifndef ZFCP_DBF_H -@@ -17,6 +17,11 @@ - - #define ZFCP_DBF_INVALID_LUN 0xFFFFFFFFFFFFFFFFull - -+enum zfcp_dbf_pseudo_erp_act_type { -+ ZFCP_PSEUDO_ERP_ACTION_RPORT_ADD = 0xff, -+ ZFCP_PSEUDO_ERP_ACTION_RPORT_DEL = 0xfe, -+}; -+ - /** - * struct zfcp_dbf_rec_trigger - trace record for triggered recovery action - * @ready: number of ready recovery actions -@@ -110,6 +115,7 @@ struct zfcp_dbf_san { - u32 d_id; - #define ZFCP_DBF_SAN_MAX_PAYLOAD (FC_CT_HDR_LEN + 32) - char payload[ZFCP_DBF_SAN_MAX_PAYLOAD]; -+ u16 pl_len; - } __packed; - - /** -@@ -126,6 +132,8 @@ struct zfcp_dbf_hba_res { - u8 prot_status_qual[FSF_PROT_STATUS_QUAL_SIZE]; - u32 fsf_status; - u8 fsf_status_qual[FSF_STATUS_QUALIFIER_SIZE]; -+ u32 port_handle; -+ u32 lun_handle; - } __packed; - - /** -@@ -279,7 +287,7 @@ static inline - void zfcp_dbf_hba_fsf_resp(char *tag, int level, struct zfcp_fsf_req *req) - { - if (debug_level_enabled(req->adapter->dbf->hba, level)) -- zfcp_dbf_hba_fsf_res(tag, req); -+ zfcp_dbf_hba_fsf_res(tag, level, req); - } - - /** -@@ -318,7 +326,7 @@ void _zfcp_dbf_scsi(char *tag, int level, struct scsi_cmnd *scmd, - scmd->device->host->hostdata[0]; - - if (debug_level_enabled(adapter->dbf->scsi, level)) -- zfcp_dbf_scsi(tag, scmd, req); -+ zfcp_dbf_scsi(tag, level, scmd, req); - } - - /** -diff --git a/drivers/s390/scsi/zfcp_erp.c b/drivers/s390/scsi/zfcp_erp.c -index 3fb4109..a59d678 100644 ---- a/drivers/s390/scsi/zfcp_erp.c -+++ b/drivers/s390/scsi/zfcp_erp.c -@@ -3,7 +3,7 @@ - * - * Error Recovery Procedures (ERP). - * -- * Copyright IBM Corp. 2002, 2010 -+ * Copyright IBM Corp. 2002, 2015 - */ - - #define KMSG_COMPONENT "zfcp" -@@ -1217,8 +1217,14 @@ static void zfcp_erp_action_cleanup(struct zfcp_erp_action *act, int result) - break; - - case ZFCP_ERP_ACTION_REOPEN_PORT: -- if (result == ZFCP_ERP_SUCCEEDED) -- zfcp_scsi_schedule_rport_register(port); -+ /* This switch case might also happen after a forced reopen -+ * was successfully done and thus overwritten with a new -+ * non-forced reopen at `ersfs_2'. In this case, we must not -+ * do the clean-up of the non-forced version. -+ */ -+ if (act->step != ZFCP_ERP_STEP_UNINITIALIZED) -+ if (result == ZFCP_ERP_SUCCEEDED) -+ zfcp_scsi_schedule_rport_register(port); - /* fall through */ - case ZFCP_ERP_ACTION_REOPEN_PORT_FORCED: - put_device(&port->dev); -diff --git a/drivers/s390/scsi/zfcp_ext.h b/drivers/s390/scsi/zfcp_ext.h -index 5b50065..c8fed9f 100644 ---- a/drivers/s390/scsi/zfcp_ext.h -+++ b/drivers/s390/scsi/zfcp_ext.h -@@ -3,7 +3,7 @@ - * - * External function declarations. - * -- * Copyright IBM Corp. 2002, 2010 -+ * Copyright IBM Corp. 2002, 2015 - */ - - #ifndef ZFCP_EXT_H -@@ -35,8 +35,9 @@ extern void zfcp_dbf_adapter_unregister(struct zfcp_adapter *); - extern void zfcp_dbf_rec_trig(char *, struct zfcp_adapter *, - struct zfcp_port *, struct scsi_device *, u8, u8); - extern void zfcp_dbf_rec_run(char *, struct zfcp_erp_action *); -+extern void zfcp_dbf_rec_run_wka(char *, struct zfcp_fc_wka_port *, u64); - extern void zfcp_dbf_hba_fsf_uss(char *, struct zfcp_fsf_req *); --extern void zfcp_dbf_hba_fsf_res(char *, struct zfcp_fsf_req *); -+extern void zfcp_dbf_hba_fsf_res(char *, int, struct zfcp_fsf_req *); - extern void zfcp_dbf_hba_bit_err(char *, struct zfcp_fsf_req *); - extern void zfcp_dbf_hba_berr(struct zfcp_dbf *, struct zfcp_fsf_req *); - extern void zfcp_dbf_hba_def_err(struct zfcp_adapter *, u64, u16, void **); -@@ -44,7 +45,8 @@ extern void zfcp_dbf_hba_basic(char *, struct zfcp_adapter *); - extern void zfcp_dbf_san_req(char *, struct zfcp_fsf_req *, u32); - extern void zfcp_dbf_san_res(char *, struct zfcp_fsf_req *); - extern void zfcp_dbf_san_in_els(char *, struct zfcp_fsf_req *); --extern void zfcp_dbf_scsi(char *, struct scsi_cmnd *, struct zfcp_fsf_req *); -+extern void zfcp_dbf_scsi(char *, int, struct scsi_cmnd *, -+ struct zfcp_fsf_req *); - - /* zfcp_erp.c */ - extern void zfcp_erp_set_adapter_status(struct zfcp_adapter *, u32); -diff --git a/drivers/s390/scsi/zfcp_fsf.c b/drivers/s390/scsi/zfcp_fsf.c -index 522a633..75f820ca 100644 ---- a/drivers/s390/scsi/zfcp_fsf.c -+++ b/drivers/s390/scsi/zfcp_fsf.c -@@ -3,7 +3,7 @@ - * - * Implementation of FSF commands. - * -- * Copyright IBM Corp. 2002, 2013 -+ * Copyright IBM Corp. 2002, 2015 - */ - - #define KMSG_COMPONENT "zfcp" -@@ -508,7 +508,10 @@ static int zfcp_fsf_exchange_config_evaluate(struct zfcp_fsf_req *req) - fc_host_port_type(shost) = FC_PORTTYPE_PTP; - break; - case FSF_TOPO_FABRIC: -- fc_host_port_type(shost) = FC_PORTTYPE_NPORT; -+ if (bottom->connection_features & FSF_FEATURE_NPIV_MODE) -+ fc_host_port_type(shost) = FC_PORTTYPE_NPIV; -+ else -+ fc_host_port_type(shost) = FC_PORTTYPE_NPORT; - break; - case FSF_TOPO_AL: - fc_host_port_type(shost) = FC_PORTTYPE_NLPORT; -@@ -613,7 +616,6 @@ static void zfcp_fsf_exchange_port_evaluate(struct zfcp_fsf_req *req) - - if (adapter->connection_features & FSF_FEATURE_NPIV_MODE) { - fc_host_permanent_port_name(shost) = bottom->wwpn; -- fc_host_port_type(shost) = FC_PORTTYPE_NPIV; - } else - fc_host_permanent_port_name(shost) = fc_host_port_name(shost); - fc_host_maxframe_size(shost) = bottom->maximum_frame_size; -@@ -982,8 +984,12 @@ static int zfcp_fsf_setup_ct_els_sbals(struct zfcp_fsf_req *req, - if (zfcp_adapter_multi_buffer_active(adapter)) { - if (zfcp_qdio_sbals_from_sg(qdio, &req->qdio_req, sg_req)) - return -EIO; -+ qtcb->bottom.support.req_buf_length = -+ zfcp_qdio_real_bytes(sg_req); - if (zfcp_qdio_sbals_from_sg(qdio, &req->qdio_req, sg_resp)) - return -EIO; -+ qtcb->bottom.support.resp_buf_length = -+ zfcp_qdio_real_bytes(sg_resp); - - zfcp_qdio_set_data_div(qdio, &req->qdio_req, - zfcp_qdio_sbale_count(sg_req)); -@@ -1073,6 +1079,7 @@ int zfcp_fsf_send_ct(struct zfcp_fc_wka_port *wka_port, - - req->handler = zfcp_fsf_send_ct_handler; - req->qtcb->header.port_handle = wka_port->handle; -+ ct->d_id = wka_port->d_id; - req->data = ct; - - zfcp_dbf_san_req("fssct_1", req, wka_port->d_id); -@@ -1169,6 +1176,7 @@ int zfcp_fsf_send_els(struct zfcp_adapter *adapter, u32 d_id, - - hton24(req->qtcb->bottom.support.d_id, d_id); - req->handler = zfcp_fsf_send_els_handler; -+ els->d_id = d_id; - req->data = els; - - zfcp_dbf_san_req("fssels1", req, d_id); -@@ -1575,7 +1583,7 @@ static void zfcp_fsf_open_wka_port_handler(struct zfcp_fsf_req *req) - int zfcp_fsf_open_wka_port(struct zfcp_fc_wka_port *wka_port) - { - struct zfcp_qdio *qdio = wka_port->adapter->qdio; -- struct zfcp_fsf_req *req; -+ struct zfcp_fsf_req *req = NULL; - int retval = -EIO; - - spin_lock_irq(&qdio->req_q_lock); -@@ -1604,6 +1612,8 @@ int zfcp_fsf_open_wka_port(struct zfcp_fc_wka_port *wka_port) - zfcp_fsf_req_free(req); - out: - spin_unlock_irq(&qdio->req_q_lock); -+ if (req && !IS_ERR(req)) -+ zfcp_dbf_rec_run_wka("fsowp_1", wka_port, req->req_id); - return retval; - } - -@@ -1628,7 +1638,7 @@ static void zfcp_fsf_close_wka_port_handler(struct zfcp_fsf_req *req) - int zfcp_fsf_close_wka_port(struct zfcp_fc_wka_port *wka_port) - { - struct zfcp_qdio *qdio = wka_port->adapter->qdio; -- struct zfcp_fsf_req *req; -+ struct zfcp_fsf_req *req = NULL; - int retval = -EIO; - - spin_lock_irq(&qdio->req_q_lock); -@@ -1657,6 +1667,8 @@ int zfcp_fsf_close_wka_port(struct zfcp_fc_wka_port *wka_port) - zfcp_fsf_req_free(req); - out: - spin_unlock_irq(&qdio->req_q_lock); -+ if (req && !IS_ERR(req)) -+ zfcp_dbf_rec_run_wka("fscwp_1", wka_port, req->req_id); - return retval; - } - -diff --git a/drivers/s390/scsi/zfcp_fsf.h b/drivers/s390/scsi/zfcp_fsf.h -index 57ae3ae..be1c04b 100644 ---- a/drivers/s390/scsi/zfcp_fsf.h -+++ b/drivers/s390/scsi/zfcp_fsf.h -@@ -3,7 +3,7 @@ - * - * Interface to the FSF support functions. - * -- * Copyright IBM Corp. 2002, 2010 -+ * Copyright IBM Corp. 2002, 2015 - */ - - #ifndef FSF_H -@@ -436,6 +436,7 @@ struct zfcp_blk_drv_data { - * @handler_data: data passed to handler function - * @port: Optional pointer to port for zfcp internal ELS (only test link ADISC) - * @status: used to pass error status to calling function -+ * @d_id: Destination ID of either open WKA port for CT or of D_ID for ELS - */ - struct zfcp_fsf_ct_els { - struct scatterlist *req; -@@ -444,6 +445,7 @@ struct zfcp_fsf_ct_els { - void *handler_data; - struct zfcp_port *port; - int status; -+ u32 d_id; - }; - - #endif /* FSF_H */ -diff --git a/drivers/s390/scsi/zfcp_scsi.c b/drivers/s390/scsi/zfcp_scsi.c -index b3c6ff4..9069f98 100644 ---- a/drivers/s390/scsi/zfcp_scsi.c -+++ b/drivers/s390/scsi/zfcp_scsi.c -@@ -3,7 +3,7 @@ - * - * Interface to Linux SCSI midlayer. - * -- * Copyright IBM Corp. 2002, 2013 -+ * Copyright IBM Corp. 2002, 2015 - */ - - #define KMSG_COMPONENT "zfcp" -@@ -556,6 +556,9 @@ static void zfcp_scsi_rport_register(struct zfcp_port *port) - ids.port_id = port->d_id; - ids.roles = FC_RPORT_ROLE_FCP_TARGET; - -+ zfcp_dbf_rec_trig("scpaddy", port->adapter, port, NULL, -+ ZFCP_PSEUDO_ERP_ACTION_RPORT_ADD, -+ ZFCP_PSEUDO_ERP_ACTION_RPORT_ADD); - rport = fc_remote_port_add(port->adapter->scsi_host, 0, &ids); - if (!rport) { - dev_err(&port->adapter->ccw_device->dev, -@@ -577,6 +580,9 @@ static void zfcp_scsi_rport_block(struct zfcp_port *port) - struct fc_rport *rport = port->rport; - - if (rport) { -+ zfcp_dbf_rec_trig("scpdely", port->adapter, port, NULL, -+ ZFCP_PSEUDO_ERP_ACTION_RPORT_DEL, -+ ZFCP_PSEUDO_ERP_ACTION_RPORT_DEL); - fc_remote_port_delete(rport); - port->rport = NULL; - } -diff --git a/drivers/scsi/scsi_scan.c b/drivers/scsi/scsi_scan.c -index e0a78f5..bac8cdf 100644 ---- a/drivers/scsi/scsi_scan.c -+++ b/drivers/scsi/scsi_scan.c -@@ -1472,12 +1472,12 @@ static int scsi_report_lun_scan(struct scsi_target *starget, int bflags, - out_err: - kfree(lun_data); - out: -- scsi_device_put(sdev); - if (scsi_device_created(sdev)) - /* - * the sdev we used didn't appear in the report luns scan - */ - __scsi_remove_device(sdev); -+ scsi_device_put(sdev); - return ret; - } - -diff --git a/drivers/soc/fsl/qe/gpio.c b/drivers/soc/fsl/qe/gpio.c -index 333eb22..0aaf429 100644 ---- a/drivers/soc/fsl/qe/gpio.c -+++ b/drivers/soc/fsl/qe/gpio.c -@@ -41,7 +41,8 @@ struct qe_gpio_chip { - - static void qe_gpio_save_regs(struct of_mm_gpio_chip *mm_gc) - { -- struct qe_gpio_chip *qe_gc = gpiochip_get_data(&mm_gc->gc); -+ struct qe_gpio_chip *qe_gc = -+ container_of(mm_gc, struct qe_gpio_chip, mm_gc); - struct qe_pio_regs __iomem *regs = mm_gc->regs; - - qe_gc->cpdata = in_be32(®s->cpdata); -diff --git a/drivers/soc/fsl/qe/qe_common.c b/drivers/soc/fsl/qe/qe_common.c -index 41eff80..104e68d 100644 ---- a/drivers/soc/fsl/qe/qe_common.c -+++ b/drivers/soc/fsl/qe/qe_common.c -@@ -70,6 +70,11 @@ int cpm_muram_init(void) - } - - muram_pool = gen_pool_create(0, -1); -+ if (!muram_pool) { -+ pr_err("Cannot allocate memory pool for CPM/QE muram"); -+ ret = -ENOMEM; -+ goto out_muram; -+ } - muram_pbase = of_translate_address(np, zero); - if (muram_pbase == (phys_addr_t)OF_BAD_ADDR) { - pr_err("Cannot translate zero through CPM muram node"); -@@ -116,6 +121,9 @@ static unsigned long cpm_muram_alloc_common(unsigned long size, - struct muram_block *entry; - unsigned long start; - -+ if (!muram_pool && cpm_muram_init()) -+ goto out2; -+ - start = gen_pool_alloc_algo(muram_pool, size, algo, data); - if (!start) - goto out2; -diff --git a/drivers/target/target_core_transport.c b/drivers/target/target_core_transport.c -index 6094a6b..e825d58 100644 ---- a/drivers/target/target_core_transport.c -+++ b/drivers/target/target_core_transport.c -@@ -754,15 +754,7 @@ EXPORT_SYMBOL(target_complete_cmd); - - void target_complete_cmd_with_length(struct se_cmd *cmd, u8 scsi_status, int length) - { -- if (scsi_status != SAM_STAT_GOOD) { -- return; -- } -- -- /* -- * Calculate new residual count based upon length of SCSI data -- * transferred. -- */ -- if (length < cmd->data_length) { -+ if (scsi_status == SAM_STAT_GOOD && length < cmd->data_length) { - if (cmd->se_cmd_flags & SCF_UNDERFLOW_BIT) { - cmd->residual_count += cmd->data_length - length; - } else { -@@ -771,12 +763,6 @@ void target_complete_cmd_with_length(struct se_cmd *cmd, u8 scsi_status, int len - } - - cmd->data_length = length; -- } else if (length > cmd->data_length) { -- cmd->se_cmd_flags |= SCF_OVERFLOW_BIT; -- cmd->residual_count = length - cmd->data_length; -- } else { -- cmd->se_cmd_flags &= ~(SCF_OVERFLOW_BIT | SCF_UNDERFLOW_BIT); -- cmd->residual_count = 0; - } - - target_complete_cmd(cmd, scsi_status); -@@ -1706,6 +1692,7 @@ void transport_generic_request_failure(struct se_cmd *cmd, - case TCM_LOGICAL_BLOCK_GUARD_CHECK_FAILED: - case TCM_LOGICAL_BLOCK_APP_TAG_CHECK_FAILED: - case TCM_LOGICAL_BLOCK_REF_TAG_CHECK_FAILED: -+ case TCM_COPY_TARGET_DEVICE_NOT_REACHABLE: - break; - case TCM_OUT_OF_RESOURCES: - sense_reason = TCM_LOGICAL_UNIT_COMMUNICATION_FAILURE; -@@ -2547,8 +2534,10 @@ int target_get_sess_cmd(struct se_cmd *se_cmd, bool ack_kref) - * fabric acknowledgement that requires two target_put_sess_cmd() - * invocations before se_cmd descriptor release. - */ -- if (ack_kref) -+ if (ack_kref) { - kref_get(&se_cmd->cmd_kref); -+ se_cmd->se_cmd_flags |= SCF_ACK_KREF; -+ } - - spin_lock_irqsave(&se_sess->sess_cmd_lock, flags); - if (se_sess->sess_tearing_down) { -@@ -2871,6 +2860,12 @@ static const struct sense_info sense_info_table[] = { - .ascq = 0x03, /* LOGICAL BLOCK REFERENCE TAG CHECK FAILED */ - .add_sector_info = true, - }, -+ [TCM_COPY_TARGET_DEVICE_NOT_REACHABLE] = { -+ .key = COPY_ABORTED, -+ .asc = 0x0d, -+ .ascq = 0x02, /* COPY TARGET DEVICE NOT REACHABLE */ -+ -+ }, - [TCM_LOGICAL_UNIT_COMMUNICATION_FAILURE] = { - /* - * Returning ILLEGAL REQUEST would cause immediate IO errors on -diff --git a/drivers/target/target_core_xcopy.c b/drivers/target/target_core_xcopy.c -index 75cd854..094a144 100644 ---- a/drivers/target/target_core_xcopy.c -+++ b/drivers/target/target_core_xcopy.c -@@ -104,7 +104,7 @@ static int target_xcopy_locate_se_dev_e4(struct se_cmd *se_cmd, struct xcopy_op - } - mutex_unlock(&g_device_mutex); - -- pr_err("Unable to locate 0xe4 descriptor for EXTENDED_COPY\n"); -+ pr_debug_ratelimited("Unable to locate 0xe4 descriptor for EXTENDED_COPY\n"); - return -EINVAL; - } - -@@ -185,7 +185,7 @@ static int target_xcopy_parse_tiddesc_e4(struct se_cmd *se_cmd, struct xcopy_op - - static int target_xcopy_parse_target_descriptors(struct se_cmd *se_cmd, - struct xcopy_op *xop, unsigned char *p, -- unsigned short tdll) -+ unsigned short tdll, sense_reason_t *sense_ret) - { - struct se_device *local_dev = se_cmd->se_dev; - unsigned char *desc = p; -@@ -193,6 +193,8 @@ static int target_xcopy_parse_target_descriptors(struct se_cmd *se_cmd, - unsigned short start = 0; - bool src = true; - -+ *sense_ret = TCM_INVALID_PARAMETER_LIST; -+ - if (offset != 0) { - pr_err("XCOPY target descriptor list length is not" - " multiple of %d\n", XCOPY_TARGET_DESC_LEN); -@@ -243,9 +245,16 @@ static int target_xcopy_parse_target_descriptors(struct se_cmd *se_cmd, - rc = target_xcopy_locate_se_dev_e4(se_cmd, xop, true); - else - rc = target_xcopy_locate_se_dev_e4(se_cmd, xop, false); -- -- if (rc < 0) -+ /* -+ * If a matching IEEE NAA 0x83 descriptor for the requested device -+ * is not located on this node, return COPY_ABORTED with ASQ/ASQC -+ * 0x0d/0x02 - COPY_TARGET_DEVICE_NOT_REACHABLE to request the -+ * initiator to fall back to normal copy method. -+ */ -+ if (rc < 0) { -+ *sense_ret = TCM_COPY_TARGET_DEVICE_NOT_REACHABLE; - goto out; -+ } - - pr_debug("XCOPY TGT desc: Source dev: %p NAA IEEE WWN: 0x%16phN\n", - xop->src_dev, &xop->src_tid_wwn[0]); -@@ -653,6 +662,7 @@ static int target_xcopy_read_source( - rc = target_xcopy_setup_pt_cmd(xpt_cmd, xop, src_dev, &cdb[0], - remote_port, true); - if (rc < 0) { -+ ec_cmd->scsi_status = xpt_cmd->se_cmd.scsi_status; - transport_generic_free_cmd(se_cmd, 0); - return rc; - } -@@ -664,6 +674,7 @@ static int target_xcopy_read_source( - - rc = target_xcopy_issue_pt_cmd(xpt_cmd); - if (rc < 0) { -+ ec_cmd->scsi_status = xpt_cmd->se_cmd.scsi_status; - transport_generic_free_cmd(se_cmd, 0); - return rc; - } -@@ -714,6 +725,7 @@ static int target_xcopy_write_destination( - remote_port, false); - if (rc < 0) { - struct se_cmd *src_cmd = &xop->src_pt_cmd->se_cmd; -+ ec_cmd->scsi_status = xpt_cmd->se_cmd.scsi_status; - /* - * If the failure happened before the t_mem_list hand-off in - * target_xcopy_setup_pt_cmd(), Reset memory + clear flag so that -@@ -729,6 +741,7 @@ static int target_xcopy_write_destination( - - rc = target_xcopy_issue_pt_cmd(xpt_cmd); - if (rc < 0) { -+ ec_cmd->scsi_status = xpt_cmd->se_cmd.scsi_status; - se_cmd->se_cmd_flags &= ~SCF_PASSTHROUGH_SG_TO_MEM_NOALLOC; - transport_generic_free_cmd(se_cmd, 0); - return rc; -@@ -815,9 +828,14 @@ static void target_xcopy_do_work(struct work_struct *work) - out: - xcopy_pt_undepend_remotedev(xop); - kfree(xop); -- -- pr_warn("target_xcopy_do_work: Setting X-COPY CHECK_CONDITION -> sending response\n"); -- ec_cmd->scsi_status = SAM_STAT_CHECK_CONDITION; -+ /* -+ * Don't override an error scsi status if it has already been set -+ */ -+ if (ec_cmd->scsi_status == SAM_STAT_GOOD) { -+ pr_warn_ratelimited("target_xcopy_do_work: rc: %d, Setting X-COPY" -+ " CHECK_CONDITION -> sending response\n", rc); -+ ec_cmd->scsi_status = SAM_STAT_CHECK_CONDITION; -+ } - target_complete_cmd(ec_cmd, SAM_STAT_CHECK_CONDITION); - } - -@@ -875,7 +893,7 @@ sense_reason_t target_do_xcopy(struct se_cmd *se_cmd) - " tdll: %hu sdll: %u inline_dl: %u\n", list_id, list_id_usage, - tdll, sdll, inline_dl); - -- rc = target_xcopy_parse_target_descriptors(se_cmd, xop, &p[16], tdll); -+ rc = target_xcopy_parse_target_descriptors(se_cmd, xop, &p[16], tdll, &ret); - if (rc <= 0) - goto out; - -diff --git a/drivers/target/tcm_fc/tfc_cmd.c b/drivers/target/tcm_fc/tfc_cmd.c -index 216e18c..9a874a8 100644 ---- a/drivers/target/tcm_fc/tfc_cmd.c -+++ b/drivers/target/tcm_fc/tfc_cmd.c -@@ -572,7 +572,7 @@ static void ft_send_work(struct work_struct *work) - if (target_submit_cmd(&cmd->se_cmd, cmd->sess->se_sess, fcp->fc_cdb, - &cmd->ft_sense_buffer[0], scsilun_to_int(&fcp->fc_lun), - ntohl(fcp->fc_dl), task_attr, data_dir, -- TARGET_SCF_ACK_KREF)) -+ TARGET_SCF_ACK_KREF | TARGET_SCF_USE_CPUID)) - goto err; - - pr_debug("r_ctl %x alloc target_submit_cmd\n", fh->fh_r_ctl); -diff --git a/drivers/video/fbdev/efifb.c b/drivers/video/fbdev/efifb.c -index 924bad4..37a37c4 100644 ---- a/drivers/video/fbdev/efifb.c -+++ b/drivers/video/fbdev/efifb.c -@@ -50,9 +50,9 @@ static int efifb_setcolreg(unsigned regno, unsigned red, unsigned green, - return 1; - - if (regno < 16) { -- red >>= 8; -- green >>= 8; -- blue >>= 8; -+ red >>= 16 - info->var.red.length; -+ green >>= 16 - info->var.green.length; -+ blue >>= 16 - info->var.blue.length; - ((u32 *)(info->pseudo_palette))[regno] = - (red << info->var.red.offset) | - (green << info->var.green.offset) | -diff --git a/drivers/watchdog/mt7621_wdt.c b/drivers/watchdog/mt7621_wdt.c -index 4a2290f..d5735c1 100644 ---- a/drivers/watchdog/mt7621_wdt.c -+++ b/drivers/watchdog/mt7621_wdt.c -@@ -139,7 +139,6 @@ static int mt7621_wdt_probe(struct platform_device *pdev) - if (!IS_ERR(mt7621_wdt_reset)) - reset_control_deassert(mt7621_wdt_reset); - -- mt7621_wdt_dev.dev = &pdev->dev; - mt7621_wdt_dev.bootstatus = mt7621_wdt_bootcause(); - - watchdog_init_timeout(&mt7621_wdt_dev, mt7621_wdt_dev.max_timeout, -diff --git a/drivers/watchdog/rt2880_wdt.c b/drivers/watchdog/rt2880_wdt.c -index 1967919..14b4fd4 100644 ---- a/drivers/watchdog/rt2880_wdt.c -+++ b/drivers/watchdog/rt2880_wdt.c -@@ -158,7 +158,6 @@ static int rt288x_wdt_probe(struct platform_device *pdev) - - rt288x_wdt_freq = clk_get_rate(rt288x_wdt_clk) / RALINK_WDT_PRESCALE; - -- rt288x_wdt_dev.dev = &pdev->dev; - rt288x_wdt_dev.bootstatus = rt288x_wdt_bootcause(); - rt288x_wdt_dev.max_timeout = (0xfffful / rt288x_wdt_freq); - rt288x_wdt_dev.parent = &pdev->dev; -diff --git a/fs/ceph/file.c b/fs/ceph/file.c -index 0f5375d..eede975 100644 ---- a/fs/ceph/file.c -+++ b/fs/ceph/file.c -@@ -1272,7 +1272,8 @@ static ssize_t ceph_read_iter(struct kiocb *iocb, struct iov_iter *to) - statret = __ceph_do_getattr(inode, page, - CEPH_STAT_CAP_INLINE_DATA, !!page); - if (statret < 0) { -- __free_page(page); -+ if (page) -+ __free_page(page); - if (statret == -ENODATA) { - BUG_ON(retry_op != READ_INLINE); - goto again; -diff --git a/fs/cifs/cifs_debug.c b/fs/cifs/cifs_debug.c -index 6c58e13..3d03e48 100644 ---- a/fs/cifs/cifs_debug.c -+++ b/fs/cifs/cifs_debug.c -@@ -152,6 +152,7 @@ static int cifs_debug_data_proc_show(struct seq_file *m, void *v) - list_for_each(tmp1, &cifs_tcp_ses_list) { - server = list_entry(tmp1, struct TCP_Server_Info, - tcp_ses_list); -+ seq_printf(m, "\nNumber of credits: %d", server->credits); - i++; - list_for_each(tmp2, &server->smb_ses_list) { - ses = list_entry(tmp2, struct cifs_ses, -diff --git a/fs/cifs/cifsfs.c b/fs/cifs/cifsfs.c -index 14ae4b8..8c68d03 100644 ---- a/fs/cifs/cifsfs.c -+++ b/fs/cifs/cifsfs.c -@@ -271,7 +271,7 @@ cifs_alloc_inode(struct super_block *sb) - cifs_inode->createtime = 0; - cifs_inode->epoch = 0; - #ifdef CONFIG_CIFS_SMB2 -- get_random_bytes(cifs_inode->lease_key, SMB2_LEASE_KEY_SIZE); -+ generate_random_uuid(cifs_inode->lease_key); - #endif - /* - * Can not set i_flags here - they get immediately overwritten to zero -@@ -1271,7 +1271,6 @@ init_cifs(void) - GlobalTotalActiveXid = 0; - GlobalMaxActiveXid = 0; - spin_lock_init(&cifs_tcp_ses_lock); -- spin_lock_init(&cifs_file_list_lock); - spin_lock_init(&GlobalMid_Lock); - - get_random_bytes(&cifs_lock_secret, sizeof(cifs_lock_secret)); -diff --git a/fs/cifs/cifsglob.h b/fs/cifs/cifsglob.h -index 8f1d8c1..65f78b7 100644 ---- a/fs/cifs/cifsglob.h -+++ b/fs/cifs/cifsglob.h -@@ -833,6 +833,7 @@ struct cifs_tcon { - struct list_head tcon_list; - int tc_count; - struct list_head openFileList; -+ spinlock_t open_file_lock; /* protects list above */ - struct cifs_ses *ses; /* pointer to session associated with */ - char treeName[MAX_TREE_SIZE + 1]; /* UNC name of resource in ASCII */ - char *nativeFileSystem; -@@ -889,7 +890,7 @@ struct cifs_tcon { - #endif /* CONFIG_CIFS_STATS2 */ - __u64 bytes_read; - __u64 bytes_written; -- spinlock_t stat_lock; -+ spinlock_t stat_lock; /* protects the two fields above */ - #endif /* CONFIG_CIFS_STATS */ - FILE_SYSTEM_DEVICE_INFO fsDevInfo; - FILE_SYSTEM_ATTRIBUTE_INFO fsAttrInfo; /* ok if fs name truncated */ -@@ -1040,8 +1041,10 @@ struct cifs_fid_locks { - }; - - struct cifsFileInfo { -+ /* following two lists are protected by tcon->open_file_lock */ - struct list_head tlist; /* pointer to next fid owned by tcon */ - struct list_head flist; /* next fid (file instance) for this inode */ -+ /* lock list below protected by cifsi->lock_sem */ - struct cifs_fid_locks *llist; /* brlocks held by this fid */ - kuid_t uid; /* allows finding which FileInfo structure */ - __u32 pid; /* process id who opened file */ -@@ -1049,11 +1052,12 @@ struct cifsFileInfo { - /* BB add lock scope info here if needed */ ; - /* lock scope id (0 if none) */ - struct dentry *dentry; -- unsigned int f_flags; - struct tcon_link *tlink; -+ unsigned int f_flags; - bool invalidHandle:1; /* file closed via session abend */ - bool oplock_break_cancelled:1; -- int count; /* refcount protected by cifs_file_list_lock */ -+ int count; -+ spinlock_t file_info_lock; /* protects four flag/count fields above */ - struct mutex fh_mutex; /* prevents reopen race after dead ses*/ - struct cifs_search_info srch_inf; - struct work_struct oplock_break; /* work for oplock breaks */ -@@ -1120,7 +1124,7 @@ struct cifs_writedata { - - /* - * Take a reference on the file private data. Must be called with -- * cifs_file_list_lock held. -+ * cfile->file_info_lock held. - */ - static inline void - cifsFileInfo_get_locked(struct cifsFileInfo *cifs_file) -@@ -1514,8 +1518,10 @@ require use of the stronger protocol */ - * GlobalMid_Lock protects: - * list operations on pending_mid_q and oplockQ - * updates to XID counters, multiplex id and SMB sequence numbers -- * cifs_file_list_lock protects: -- * list operations on tcp and SMB session lists and tCon lists -+ * tcp_ses_lock protects: -+ * list operations on tcp and SMB session lists -+ * tcon->open_file_lock protects the list of open files hanging off the tcon -+ * cfile->file_info_lock protects counters and fields in cifs file struct - * f_owner.lock protects certain per file struct operations - * mapping->page_lock protects certain per page operations - * -@@ -1547,18 +1553,12 @@ GLOBAL_EXTERN struct list_head cifs_tcp_ses_list; - * tcp session, and the list of tcon's per smb session. It also protects - * the reference counters for the server, smb session, and tcon. Finally, - * changes to the tcon->tidStatus should be done while holding this lock. -+ * generally the locks should be taken in order tcp_ses_lock before -+ * tcon->open_file_lock and that before file->file_info_lock since the -+ * structure order is cifs_socket-->cifs_ses-->cifs_tcon-->cifs_file - */ - GLOBAL_EXTERN spinlock_t cifs_tcp_ses_lock; - --/* -- * This lock protects the cifs_file->llist and cifs_file->flist -- * list operations, and updates to some flags (cifs_file->invalidHandle) -- * It will be moved to either use the tcon->stat_lock or equivalent later. -- * If cifs_tcp_ses_lock and the lock below are both needed to be held, then -- * the cifs_tcp_ses_lock must be grabbed first and released last. -- */ --GLOBAL_EXTERN spinlock_t cifs_file_list_lock; -- - #ifdef CONFIG_CIFS_DNOTIFY_EXPERIMENTAL /* unused temporarily */ - /* Outstanding dir notify requests */ - GLOBAL_EXTERN struct list_head GlobalDnotifyReqList; -diff --git a/fs/cifs/cifssmb.c b/fs/cifs/cifssmb.c -index d47197e..7804605 100644 ---- a/fs/cifs/cifssmb.c -+++ b/fs/cifs/cifssmb.c -@@ -98,13 +98,13 @@ cifs_mark_open_files_invalid(struct cifs_tcon *tcon) - struct list_head *tmp1; - - /* list all files open on tree connection and mark them invalid */ -- spin_lock(&cifs_file_list_lock); -+ spin_lock(&tcon->open_file_lock); - list_for_each_safe(tmp, tmp1, &tcon->openFileList) { - open_file = list_entry(tmp, struct cifsFileInfo, tlist); - open_file->invalidHandle = true; - open_file->oplock_break_cancelled = true; - } -- spin_unlock(&cifs_file_list_lock); -+ spin_unlock(&tcon->open_file_lock); - /* - * BB Add call to invalidate_inodes(sb) for all superblocks mounted - * to this tcon. -diff --git a/fs/cifs/connect.c b/fs/cifs/connect.c -index 2e4f4ba..7b67179 100644 ---- a/fs/cifs/connect.c -+++ b/fs/cifs/connect.c -@@ -2163,7 +2163,7 @@ cifs_get_tcp_session(struct smb_vol *volume_info) - memcpy(&tcp_ses->dstaddr, &volume_info->dstaddr, - sizeof(tcp_ses->dstaddr)); - #ifdef CONFIG_CIFS_SMB2 -- get_random_bytes(tcp_ses->client_guid, SMB2_CLIENT_GUID_SIZE); -+ generate_random_uuid(tcp_ses->client_guid); - #endif - /* - * at this point we are the only ones with the pointer -@@ -3688,14 +3688,16 @@ cifs_mount(struct cifs_sb_info *cifs_sb, struct smb_vol *volume_info) - goto mount_fail_check; - } - -- rc = cifs_are_all_path_components_accessible(server, -+ if (rc != -EREMOTE) { -+ rc = cifs_are_all_path_components_accessible(server, - xid, tcon, cifs_sb, - full_path); -- if (rc != 0) { -- cifs_dbg(VFS, "cannot query dirs between root and final path, " -- "enabling CIFS_MOUNT_USE_PREFIX_PATH\n"); -- cifs_sb->mnt_cifs_flags |= CIFS_MOUNT_USE_PREFIX_PATH; -- rc = 0; -+ if (rc != 0) { -+ cifs_dbg(VFS, "cannot query dirs between root and final path, " -+ "enabling CIFS_MOUNT_USE_PREFIX_PATH\n"); -+ cifs_sb->mnt_cifs_flags |= CIFS_MOUNT_USE_PREFIX_PATH; -+ rc = 0; -+ } - } - kfree(full_path); - } -diff --git a/fs/cifs/file.c b/fs/cifs/file.c -index 579e41b..605438a 100644 ---- a/fs/cifs/file.c -+++ b/fs/cifs/file.c -@@ -305,6 +305,7 @@ cifs_new_fileinfo(struct cifs_fid *fid, struct file *file, - cfile->tlink = cifs_get_tlink(tlink); - INIT_WORK(&cfile->oplock_break, cifs_oplock_break); - mutex_init(&cfile->fh_mutex); -+ spin_lock_init(&cfile->file_info_lock); - - cifs_sb_active(inode->i_sb); - -@@ -317,7 +318,7 @@ cifs_new_fileinfo(struct cifs_fid *fid, struct file *file, - oplock = 0; - } - -- spin_lock(&cifs_file_list_lock); -+ spin_lock(&tcon->open_file_lock); - if (fid->pending_open->oplock != CIFS_OPLOCK_NO_CHANGE && oplock) - oplock = fid->pending_open->oplock; - list_del(&fid->pending_open->olist); -@@ -326,12 +327,13 @@ cifs_new_fileinfo(struct cifs_fid *fid, struct file *file, - server->ops->set_fid(cfile, fid, oplock); - - list_add(&cfile->tlist, &tcon->openFileList); -+ - /* if readable file instance put first in list*/ - if (file->f_mode & FMODE_READ) - list_add(&cfile->flist, &cinode->openFileList); - else - list_add_tail(&cfile->flist, &cinode->openFileList); -- spin_unlock(&cifs_file_list_lock); -+ spin_unlock(&tcon->open_file_lock); - - if (fid->purge_cache) - cifs_zap_mapping(inode); -@@ -343,16 +345,16 @@ cifs_new_fileinfo(struct cifs_fid *fid, struct file *file, - struct cifsFileInfo * - cifsFileInfo_get(struct cifsFileInfo *cifs_file) - { -- spin_lock(&cifs_file_list_lock); -+ spin_lock(&cifs_file->file_info_lock); - cifsFileInfo_get_locked(cifs_file); -- spin_unlock(&cifs_file_list_lock); -+ spin_unlock(&cifs_file->file_info_lock); - return cifs_file; - } - - /* - * Release a reference on the file private data. This may involve closing - * the filehandle out on the server. Must be called without holding -- * cifs_file_list_lock. -+ * tcon->open_file_lock and cifs_file->file_info_lock. - */ - void cifsFileInfo_put(struct cifsFileInfo *cifs_file) - { -@@ -367,11 +369,15 @@ void cifsFileInfo_put(struct cifsFileInfo *cifs_file) - struct cifs_pending_open open; - bool oplock_break_cancelled; - -- spin_lock(&cifs_file_list_lock); -+ spin_lock(&tcon->open_file_lock); -+ -+ spin_lock(&cifs_file->file_info_lock); - if (--cifs_file->count > 0) { -- spin_unlock(&cifs_file_list_lock); -+ spin_unlock(&cifs_file->file_info_lock); -+ spin_unlock(&tcon->open_file_lock); - return; - } -+ spin_unlock(&cifs_file->file_info_lock); - - if (server->ops->get_lease_key) - server->ops->get_lease_key(inode, &fid); -@@ -395,7 +401,8 @@ void cifsFileInfo_put(struct cifsFileInfo *cifs_file) - set_bit(CIFS_INO_INVALID_MAPPING, &cifsi->flags); - cifs_set_oplock_level(cifsi, 0); - } -- spin_unlock(&cifs_file_list_lock); -+ -+ spin_unlock(&tcon->open_file_lock); - - oplock_break_cancelled = cancel_work_sync(&cifs_file->oplock_break); - -@@ -772,10 +779,10 @@ int cifs_closedir(struct inode *inode, struct file *file) - server = tcon->ses->server; - - cifs_dbg(FYI, "Freeing private data in close dir\n"); -- spin_lock(&cifs_file_list_lock); -+ spin_lock(&cfile->file_info_lock); - if (server->ops->dir_needs_close(cfile)) { - cfile->invalidHandle = true; -- spin_unlock(&cifs_file_list_lock); -+ spin_unlock(&cfile->file_info_lock); - if (server->ops->close_dir) - rc = server->ops->close_dir(xid, tcon, &cfile->fid); - else -@@ -784,7 +791,7 @@ int cifs_closedir(struct inode *inode, struct file *file) - /* not much we can do if it fails anyway, ignore rc */ - rc = 0; - } else -- spin_unlock(&cifs_file_list_lock); -+ spin_unlock(&cfile->file_info_lock); - - buf = cfile->srch_inf.ntwrk_buf_start; - if (buf) { -@@ -1728,12 +1735,13 @@ struct cifsFileInfo *find_readable_file(struct cifsInodeInfo *cifs_inode, - { - struct cifsFileInfo *open_file = NULL; - struct cifs_sb_info *cifs_sb = CIFS_SB(cifs_inode->vfs_inode.i_sb); -+ struct cifs_tcon *tcon = cifs_sb_master_tcon(cifs_sb); - - /* only filter by fsuid on multiuser mounts */ - if (!(cifs_sb->mnt_cifs_flags & CIFS_MOUNT_MULTIUSER)) - fsuid_only = false; - -- spin_lock(&cifs_file_list_lock); -+ spin_lock(&tcon->open_file_lock); - /* we could simply get the first_list_entry since write-only entries - are always at the end of the list but since the first entry might - have a close pending, we go through the whole list */ -@@ -1744,8 +1752,8 @@ struct cifsFileInfo *find_readable_file(struct cifsInodeInfo *cifs_inode, - if (!open_file->invalidHandle) { - /* found a good file */ - /* lock it so it will not be closed on us */ -- cifsFileInfo_get_locked(open_file); -- spin_unlock(&cifs_file_list_lock); -+ cifsFileInfo_get(open_file); -+ spin_unlock(&tcon->open_file_lock); - return open_file; - } /* else might as well continue, and look for - another, or simply have the caller reopen it -@@ -1753,7 +1761,7 @@ struct cifsFileInfo *find_readable_file(struct cifsInodeInfo *cifs_inode, - } else /* write only file */ - break; /* write only files are last so must be done */ - } -- spin_unlock(&cifs_file_list_lock); -+ spin_unlock(&tcon->open_file_lock); - return NULL; - } - -@@ -1762,6 +1770,7 @@ struct cifsFileInfo *find_writable_file(struct cifsInodeInfo *cifs_inode, - { - struct cifsFileInfo *open_file, *inv_file = NULL; - struct cifs_sb_info *cifs_sb; -+ struct cifs_tcon *tcon; - bool any_available = false; - int rc; - unsigned int refind = 0; -@@ -1777,15 +1786,16 @@ struct cifsFileInfo *find_writable_file(struct cifsInodeInfo *cifs_inode, - } - - cifs_sb = CIFS_SB(cifs_inode->vfs_inode.i_sb); -+ tcon = cifs_sb_master_tcon(cifs_sb); - - /* only filter by fsuid on multiuser mounts */ - if (!(cifs_sb->mnt_cifs_flags & CIFS_MOUNT_MULTIUSER)) - fsuid_only = false; - -- spin_lock(&cifs_file_list_lock); -+ spin_lock(&tcon->open_file_lock); - refind_writable: - if (refind > MAX_REOPEN_ATT) { -- spin_unlock(&cifs_file_list_lock); -+ spin_unlock(&tcon->open_file_lock); - return NULL; - } - list_for_each_entry(open_file, &cifs_inode->openFileList, flist) { -@@ -1796,8 +1806,8 @@ struct cifsFileInfo *find_writable_file(struct cifsInodeInfo *cifs_inode, - if (OPEN_FMODE(open_file->f_flags) & FMODE_WRITE) { - if (!open_file->invalidHandle) { - /* found a good writable file */ -- cifsFileInfo_get_locked(open_file); -- spin_unlock(&cifs_file_list_lock); -+ cifsFileInfo_get(open_file); -+ spin_unlock(&tcon->open_file_lock); - return open_file; - } else { - if (!inv_file) -@@ -1813,24 +1823,24 @@ struct cifsFileInfo *find_writable_file(struct cifsInodeInfo *cifs_inode, - - if (inv_file) { - any_available = false; -- cifsFileInfo_get_locked(inv_file); -+ cifsFileInfo_get(inv_file); - } - -- spin_unlock(&cifs_file_list_lock); -+ spin_unlock(&tcon->open_file_lock); - - if (inv_file) { - rc = cifs_reopen_file(inv_file, false); - if (!rc) - return inv_file; - else { -- spin_lock(&cifs_file_list_lock); -+ spin_lock(&tcon->open_file_lock); - list_move_tail(&inv_file->flist, - &cifs_inode->openFileList); -- spin_unlock(&cifs_file_list_lock); -+ spin_unlock(&tcon->open_file_lock); - cifsFileInfo_put(inv_file); -- spin_lock(&cifs_file_list_lock); - ++refind; - inv_file = NULL; -+ spin_lock(&tcon->open_file_lock); - goto refind_writable; - } - } -@@ -3618,15 +3628,17 @@ static int cifs_readpage(struct file *file, struct page *page) - static int is_inode_writable(struct cifsInodeInfo *cifs_inode) - { - struct cifsFileInfo *open_file; -+ struct cifs_tcon *tcon = -+ cifs_sb_master_tcon(CIFS_SB(cifs_inode->vfs_inode.i_sb)); - -- spin_lock(&cifs_file_list_lock); -+ spin_lock(&tcon->open_file_lock); - list_for_each_entry(open_file, &cifs_inode->openFileList, flist) { - if (OPEN_FMODE(open_file->f_flags) & FMODE_WRITE) { -- spin_unlock(&cifs_file_list_lock); -+ spin_unlock(&tcon->open_file_lock); - return 1; - } - } -- spin_unlock(&cifs_file_list_lock); -+ spin_unlock(&tcon->open_file_lock); - return 0; - } - -diff --git a/fs/cifs/misc.c b/fs/cifs/misc.c -index 813fe13..c672915 100644 ---- a/fs/cifs/misc.c -+++ b/fs/cifs/misc.c -@@ -120,6 +120,7 @@ tconInfoAlloc(void) - ++ret_buf->tc_count; - INIT_LIST_HEAD(&ret_buf->openFileList); - INIT_LIST_HEAD(&ret_buf->tcon_list); -+ spin_lock_init(&ret_buf->open_file_lock); - #ifdef CONFIG_CIFS_STATS - spin_lock_init(&ret_buf->stat_lock); - #endif -@@ -465,7 +466,7 @@ is_valid_oplock_break(char *buffer, struct TCP_Server_Info *srv) - continue; - - cifs_stats_inc(&tcon->stats.cifs_stats.num_oplock_brks); -- spin_lock(&cifs_file_list_lock); -+ spin_lock(&tcon->open_file_lock); - list_for_each(tmp2, &tcon->openFileList) { - netfile = list_entry(tmp2, struct cifsFileInfo, - tlist); -@@ -495,11 +496,11 @@ is_valid_oplock_break(char *buffer, struct TCP_Server_Info *srv) - &netfile->oplock_break); - netfile->oplock_break_cancelled = false; - -- spin_unlock(&cifs_file_list_lock); -+ spin_unlock(&tcon->open_file_lock); - spin_unlock(&cifs_tcp_ses_lock); - return true; - } -- spin_unlock(&cifs_file_list_lock); -+ spin_unlock(&tcon->open_file_lock); - spin_unlock(&cifs_tcp_ses_lock); - cifs_dbg(FYI, "No matching file for oplock break\n"); - return true; -@@ -613,9 +614,9 @@ backup_cred(struct cifs_sb_info *cifs_sb) - void - cifs_del_pending_open(struct cifs_pending_open *open) - { -- spin_lock(&cifs_file_list_lock); -+ spin_lock(&tlink_tcon(open->tlink)->open_file_lock); - list_del(&open->olist); -- spin_unlock(&cifs_file_list_lock); -+ spin_unlock(&tlink_tcon(open->tlink)->open_file_lock); - } - - void -@@ -635,7 +636,7 @@ void - cifs_add_pending_open(struct cifs_fid *fid, struct tcon_link *tlink, - struct cifs_pending_open *open) - { -- spin_lock(&cifs_file_list_lock); -+ spin_lock(&tlink_tcon(tlink)->open_file_lock); - cifs_add_pending_open_locked(fid, tlink, open); -- spin_unlock(&cifs_file_list_lock); -+ spin_unlock(&tlink_tcon(open->tlink)->open_file_lock); - } -diff --git a/fs/cifs/readdir.c b/fs/cifs/readdir.c -index 65cf85d..8f6a2a5 100644 ---- a/fs/cifs/readdir.c -+++ b/fs/cifs/readdir.c -@@ -597,14 +597,14 @@ find_cifs_entry(const unsigned int xid, struct cifs_tcon *tcon, loff_t pos, - is_dir_changed(file)) || (index_to_find < first_entry_in_buffer)) { - /* close and restart search */ - cifs_dbg(FYI, "search backing up - close and restart search\n"); -- spin_lock(&cifs_file_list_lock); -+ spin_lock(&cfile->file_info_lock); - if (server->ops->dir_needs_close(cfile)) { - cfile->invalidHandle = true; -- spin_unlock(&cifs_file_list_lock); -+ spin_unlock(&cfile->file_info_lock); - if (server->ops->close_dir) - server->ops->close_dir(xid, tcon, &cfile->fid); - } else -- spin_unlock(&cifs_file_list_lock); -+ spin_unlock(&cfile->file_info_lock); - if (cfile->srch_inf.ntwrk_buf_start) { - cifs_dbg(FYI, "freeing SMB ff cache buf on search rewind\n"); - if (cfile->srch_inf.smallBuf) -diff --git a/fs/cifs/smb2glob.h b/fs/cifs/smb2glob.h -index 0ffa180..238759c 100644 ---- a/fs/cifs/smb2glob.h -+++ b/fs/cifs/smb2glob.h -@@ -61,4 +61,14 @@ - /* Maximum buffer size value we can send with 1 credit */ - #define SMB2_MAX_BUFFER_SIZE 65536 - -+/* -+ * Maximum number of credits to keep available. -+ * This value is chosen somewhat arbitrarily. The Windows client -+ * defaults to 128 credits, the Windows server allows clients up to -+ * 512 credits, and the NetApp server does not limit clients at all. -+ * Choose a high enough value such that the client shouldn't limit -+ * performance. -+ */ -+#define SMB2_MAX_CREDITS_AVAILABLE 32000 -+ - #endif /* _SMB2_GLOB_H */ -diff --git a/fs/cifs/smb2inode.c b/fs/cifs/smb2inode.c -index 4f0231e..1238cd3 100644 ---- a/fs/cifs/smb2inode.c -+++ b/fs/cifs/smb2inode.c -@@ -266,9 +266,15 @@ smb2_set_file_info(struct inode *inode, const char *full_path, - struct tcon_link *tlink; - int rc; - -+ if ((buf->CreationTime == 0) && (buf->LastAccessTime == 0) && -+ (buf->LastWriteTime == 0) && (buf->ChangeTime) && -+ (buf->Attributes == 0)) -+ return 0; /* would be a no op, no sense sending this */ -+ - tlink = cifs_sb_tlink(cifs_sb); - if (IS_ERR(tlink)) - return PTR_ERR(tlink); -+ - rc = smb2_open_op_close(xid, tlink_tcon(tlink), cifs_sb, full_path, - FILE_WRITE_ATTRIBUTES, FILE_OPEN, 0, buf, - SMB2_OP_SET_INFO); -diff --git a/fs/cifs/smb2misc.c b/fs/cifs/smb2misc.c -index 389fb9f..3d38348 100644 ---- a/fs/cifs/smb2misc.c -+++ b/fs/cifs/smb2misc.c -@@ -549,19 +549,19 @@ smb2_is_valid_lease_break(char *buffer) - list_for_each(tmp1, &server->smb_ses_list) { - ses = list_entry(tmp1, struct cifs_ses, smb_ses_list); - -- spin_lock(&cifs_file_list_lock); - list_for_each(tmp2, &ses->tcon_list) { - tcon = list_entry(tmp2, struct cifs_tcon, - tcon_list); -+ spin_lock(&tcon->open_file_lock); - cifs_stats_inc( - &tcon->stats.cifs_stats.num_oplock_brks); - if (smb2_tcon_has_lease(tcon, rsp, lw)) { -- spin_unlock(&cifs_file_list_lock); -+ spin_unlock(&tcon->open_file_lock); - spin_unlock(&cifs_tcp_ses_lock); - return true; - } -+ spin_unlock(&tcon->open_file_lock); - } -- spin_unlock(&cifs_file_list_lock); - } - } - spin_unlock(&cifs_tcp_ses_lock); -@@ -603,7 +603,7 @@ smb2_is_valid_oplock_break(char *buffer, struct TCP_Server_Info *server) - tcon = list_entry(tmp1, struct cifs_tcon, tcon_list); - - cifs_stats_inc(&tcon->stats.cifs_stats.num_oplock_brks); -- spin_lock(&cifs_file_list_lock); -+ spin_lock(&tcon->open_file_lock); - list_for_each(tmp2, &tcon->openFileList) { - cfile = list_entry(tmp2, struct cifsFileInfo, - tlist); -@@ -615,7 +615,7 @@ smb2_is_valid_oplock_break(char *buffer, struct TCP_Server_Info *server) - - cifs_dbg(FYI, "file id match, oplock break\n"); - cinode = CIFS_I(d_inode(cfile->dentry)); -- -+ spin_lock(&cfile->file_info_lock); - if (!CIFS_CACHE_WRITE(cinode) && - rsp->OplockLevel == SMB2_OPLOCK_LEVEL_NONE) - cfile->oplock_break_cancelled = true; -@@ -637,14 +637,14 @@ smb2_is_valid_oplock_break(char *buffer, struct TCP_Server_Info *server) - clear_bit( - CIFS_INODE_DOWNGRADE_OPLOCK_TO_L2, - &cinode->flags); -- -+ spin_unlock(&cfile->file_info_lock); - queue_work(cifsiod_wq, &cfile->oplock_break); - -- spin_unlock(&cifs_file_list_lock); -+ spin_unlock(&tcon->open_file_lock); - spin_unlock(&cifs_tcp_ses_lock); - return true; - } -- spin_unlock(&cifs_file_list_lock); -+ spin_unlock(&tcon->open_file_lock); - spin_unlock(&cifs_tcp_ses_lock); - cifs_dbg(FYI, "No matching file for oplock break\n"); - return true; -diff --git a/fs/cifs/smb2ops.c b/fs/cifs/smb2ops.c -index d203c03..0e73cef 100644 ---- a/fs/cifs/smb2ops.c -+++ b/fs/cifs/smb2ops.c -@@ -287,7 +287,7 @@ SMB3_request_interfaces(const unsigned int xid, struct cifs_tcon *tcon) - cifs_dbg(FYI, "Link Speed %lld\n", - le64_to_cpu(out_buf->LinkSpeed)); - } -- -+ kfree(out_buf); - return rc; - } - #endif /* STATS2 */ -@@ -541,6 +541,7 @@ smb2_set_fid(struct cifsFileInfo *cfile, struct cifs_fid *fid, __u32 oplock) - server->ops->set_oplock_level(cinode, oplock, fid->epoch, - &fid->purge_cache); - cinode->can_cache_brlcks = CIFS_CACHE_WRITE(cinode); -+ memcpy(cfile->fid.create_guid, fid->create_guid, 16); - } - - static void -@@ -699,6 +700,7 @@ smb2_clone_range(const unsigned int xid, - - cchunk_out: - kfree(pcchunk); -+ kfree(retbuf); - return rc; - } - -@@ -823,7 +825,6 @@ smb2_duplicate_extents(const unsigned int xid, - { - int rc; - unsigned int ret_data_len; -- char *retbuf = NULL; - struct duplicate_extents_to_file dup_ext_buf; - struct cifs_tcon *tcon = tlink_tcon(trgtfile->tlink); - -@@ -849,7 +850,7 @@ smb2_duplicate_extents(const unsigned int xid, - FSCTL_DUPLICATE_EXTENTS_TO_FILE, - true /* is_fsctl */, (char *)&dup_ext_buf, - sizeof(struct duplicate_extents_to_file), -- (char **)&retbuf, -+ NULL, - &ret_data_len); - - if (ret_data_len > 0) -@@ -872,7 +873,6 @@ smb3_set_integrity(const unsigned int xid, struct cifs_tcon *tcon, - struct cifsFileInfo *cfile) - { - struct fsctl_set_integrity_information_req integr_info; -- char *retbuf = NULL; - unsigned int ret_data_len; - - integr_info.ChecksumAlgorithm = cpu_to_le16(CHECKSUM_TYPE_UNCHANGED); -@@ -884,7 +884,7 @@ smb3_set_integrity(const unsigned int xid, struct cifs_tcon *tcon, - FSCTL_SET_INTEGRITY_INFORMATION, - true /* is_fsctl */, (char *)&integr_info, - sizeof(struct fsctl_set_integrity_information_req), -- (char **)&retbuf, -+ NULL, - &ret_data_len); - - } -@@ -1041,7 +1041,7 @@ smb2_set_lease_key(struct inode *inode, struct cifs_fid *fid) - static void - smb2_new_lease_key(struct cifs_fid *fid) - { -- get_random_bytes(fid->lease_key, SMB2_LEASE_KEY_SIZE); -+ generate_random_uuid(fid->lease_key); - } - - #define SMB2_SYMLINK_STRUCT_SIZE \ -diff --git a/fs/cifs/smb2pdu.c b/fs/cifs/smb2pdu.c -index 29e06db..3eec96c 100644 ---- a/fs/cifs/smb2pdu.c -+++ b/fs/cifs/smb2pdu.c -@@ -100,7 +100,21 @@ smb2_hdr_assemble(struct smb2_hdr *hdr, __le16 smb2_cmd /* command */ , - hdr->ProtocolId = SMB2_PROTO_NUMBER; - hdr->StructureSize = cpu_to_le16(64); - hdr->Command = smb2_cmd; -- hdr->CreditRequest = cpu_to_le16(2); /* BB make this dynamic */ -+ if (tcon && tcon->ses && tcon->ses->server) { -+ struct TCP_Server_Info *server = tcon->ses->server; -+ -+ spin_lock(&server->req_lock); -+ /* Request up to 2 credits but don't go over the limit. */ -+ if (server->credits >= SMB2_MAX_CREDITS_AVAILABLE) -+ hdr->CreditRequest = cpu_to_le16(0); -+ else -+ hdr->CreditRequest = cpu_to_le16( -+ min_t(int, SMB2_MAX_CREDITS_AVAILABLE - -+ server->credits, 2)); -+ spin_unlock(&server->req_lock); -+ } else { -+ hdr->CreditRequest = cpu_to_le16(2); -+ } - hdr->ProcessId = cpu_to_le32((__u16)current->tgid); - - if (!tcon) -@@ -590,6 +604,7 @@ SMB2_sess_setup(const unsigned int xid, struct cifs_ses *ses, - char *security_blob = NULL; - unsigned char *ntlmssp_blob = NULL; - bool use_spnego = false; /* else use raw ntlmssp */ -+ u64 previous_session = ses->Suid; - - cifs_dbg(FYI, "Session Setup\n"); - -@@ -627,6 +642,10 @@ SMB2_sess_setup(const unsigned int xid, struct cifs_ses *ses, - return rc; - - req->hdr.SessionId = 0; /* First session, not a reauthenticate */ -+ -+ /* if reconnect, we need to send previous sess id, otherwise it is 0 */ -+ req->PreviousSessionId = previous_session; -+ - req->Flags = 0; /* MBZ */ - /* to enable echos and oplocks */ - req->hdr.CreditRequest = cpu_to_le16(3); -@@ -1164,7 +1183,7 @@ create_durable_v2_buf(struct cifs_fid *pfid) - - buf->dcontext.Timeout = 0; /* Should this be configurable by workload */ - buf->dcontext.Flags = cpu_to_le32(SMB2_DHANDLE_FLAG_PERSISTENT); -- get_random_bytes(buf->dcontext.CreateGuid, 16); -+ generate_random_uuid(buf->dcontext.CreateGuid); - memcpy(pfid->create_guid, buf->dcontext.CreateGuid, 16); - - /* SMB2_CREATE_DURABLE_HANDLE_REQUEST is "DH2Q" */ -@@ -2057,6 +2076,7 @@ smb2_async_readv(struct cifs_readdata *rdata) - if (rdata->credits) { - buf->CreditCharge = cpu_to_le16(DIV_ROUND_UP(rdata->bytes, - SMB2_MAX_BUFFER_SIZE)); -+ buf->CreditRequest = buf->CreditCharge; - spin_lock(&server->req_lock); - server->credits += rdata->credits - - le16_to_cpu(buf->CreditCharge); -@@ -2243,6 +2263,7 @@ smb2_async_writev(struct cifs_writedata *wdata, - if (wdata->credits) { - req->hdr.CreditCharge = cpu_to_le16(DIV_ROUND_UP(wdata->bytes, - SMB2_MAX_BUFFER_SIZE)); -+ req->hdr.CreditRequest = req->hdr.CreditCharge; - spin_lock(&server->req_lock); - server->credits += wdata->credits - - le16_to_cpu(req->hdr.CreditCharge); -diff --git a/fs/cifs/smb2pdu.h b/fs/cifs/smb2pdu.h -index ff88d9f..fd3709e 100644 ---- a/fs/cifs/smb2pdu.h -+++ b/fs/cifs/smb2pdu.h -@@ -276,7 +276,7 @@ struct smb2_sess_setup_req { - __le32 Channel; - __le16 SecurityBufferOffset; - __le16 SecurityBufferLength; -- __le64 PreviousSessionId; -+ __u64 PreviousSessionId; - __u8 Buffer[1]; /* variable length GSS security buffer */ - } __packed; - -diff --git a/fs/crypto/crypto.c b/fs/crypto/crypto.c -index c502c11..55d64fb 100644 ---- a/fs/crypto/crypto.c -+++ b/fs/crypto/crypto.c -@@ -152,7 +152,10 @@ static int do_page_crypto(struct inode *inode, - struct page *src_page, struct page *dest_page, - gfp_t gfp_flags) - { -- u8 xts_tweak[FS_XTS_TWEAK_SIZE]; -+ struct { -+ __le64 index; -+ u8 padding[FS_XTS_TWEAK_SIZE - sizeof(__le64)]; -+ } xts_tweak; - struct skcipher_request *req = NULL; - DECLARE_FS_COMPLETION_RESULT(ecr); - struct scatterlist dst, src; -@@ -172,17 +175,15 @@ static int do_page_crypto(struct inode *inode, - req, CRYPTO_TFM_REQ_MAY_BACKLOG | CRYPTO_TFM_REQ_MAY_SLEEP, - fscrypt_complete, &ecr); - -- BUILD_BUG_ON(FS_XTS_TWEAK_SIZE < sizeof(index)); -- memcpy(xts_tweak, &index, sizeof(index)); -- memset(&xts_tweak[sizeof(index)], 0, -- FS_XTS_TWEAK_SIZE - sizeof(index)); -+ BUILD_BUG_ON(sizeof(xts_tweak) != FS_XTS_TWEAK_SIZE); -+ xts_tweak.index = cpu_to_le64(index); -+ memset(xts_tweak.padding, 0, sizeof(xts_tweak.padding)); - - sg_init_table(&dst, 1); - sg_set_page(&dst, dest_page, PAGE_SIZE, 0); - sg_init_table(&src, 1); - sg_set_page(&src, src_page, PAGE_SIZE, 0); -- skcipher_request_set_crypt(req, &src, &dst, PAGE_SIZE, -- xts_tweak); -+ skcipher_request_set_crypt(req, &src, &dst, PAGE_SIZE, &xts_tweak); - if (rw == FS_DECRYPT) - res = crypto_skcipher_decrypt(req); - else -diff --git a/fs/crypto/policy.c b/fs/crypto/policy.c -index ed115ac..6865663 100644 ---- a/fs/crypto/policy.c -+++ b/fs/crypto/policy.c -@@ -109,6 +109,8 @@ int fscrypt_process_policy(struct file *filp, - if (ret) - return ret; - -+ inode_lock(inode); -+ - if (!inode_has_encryption_context(inode)) { - if (!S_ISDIR(inode->i_mode)) - ret = -EINVAL; -@@ -127,6 +129,8 @@ int fscrypt_process_policy(struct file *filp, - ret = -EINVAL; - } - -+ inode_unlock(inode); -+ - mnt_drop_write_file(filp); - return ret; - } -diff --git a/fs/ext4/sysfs.c b/fs/ext4/sysfs.c -index 73bcfd4..42145be 100644 ---- a/fs/ext4/sysfs.c -+++ b/fs/ext4/sysfs.c -@@ -223,14 +223,18 @@ static struct attribute *ext4_attrs[] = { - EXT4_ATTR_FEATURE(lazy_itable_init); - EXT4_ATTR_FEATURE(batched_discard); - EXT4_ATTR_FEATURE(meta_bg_resize); -+#ifdef CONFIG_EXT4_FS_ENCRYPTION - EXT4_ATTR_FEATURE(encryption); -+#endif - EXT4_ATTR_FEATURE(metadata_csum_seed); - - static struct attribute *ext4_feat_attrs[] = { - ATTR_LIST(lazy_itable_init), - ATTR_LIST(batched_discard), - ATTR_LIST(meta_bg_resize), -+#ifdef CONFIG_EXT4_FS_ENCRYPTION - ATTR_LIST(encryption), -+#endif - ATTR_LIST(metadata_csum_seed), - NULL, - }; -diff --git a/fs/isofs/inode.c b/fs/isofs/inode.c -index ad0c745..871c8b3 100644 ---- a/fs/isofs/inode.c -+++ b/fs/isofs/inode.c -@@ -687,6 +687,11 @@ static int isofs_fill_super(struct super_block *s, void *data, int silent) - pri_bh = NULL; - - root_found: -+ /* We don't support read-write mounts */ -+ if (!(s->s_flags & MS_RDONLY)) { -+ error = -EACCES; -+ goto out_freebh; -+ } - - if (joliet_level && (pri == NULL || !opt.rock)) { - /* This is the case of Joliet with the norock mount flag. -@@ -1501,9 +1506,6 @@ struct inode *__isofs_iget(struct super_block *sb, - static struct dentry *isofs_mount(struct file_system_type *fs_type, - int flags, const char *dev_name, void *data) - { -- /* We don't support read-write mounts */ -- if (!(flags & MS_RDONLY)) -- return ERR_PTR(-EACCES); - return mount_bdev(fs_type, flags, dev_name, data, isofs_fill_super); - } - -diff --git a/fs/jbd2/transaction.c b/fs/jbd2/transaction.c -index 3d8246a..e165266 100644 ---- a/fs/jbd2/transaction.c -+++ b/fs/jbd2/transaction.c -@@ -1149,6 +1149,7 @@ int jbd2_journal_get_create_access(handle_t *handle, struct buffer_head *bh) - JBUFFER_TRACE(jh, "file as BJ_Reserved"); - spin_lock(&journal->j_list_lock); - __jbd2_journal_file_buffer(jh, transaction, BJ_Reserved); -+ spin_unlock(&journal->j_list_lock); - } else if (jh->b_transaction == journal->j_committing_transaction) { - /* first access by this transaction */ - jh->b_modified = 0; -@@ -1156,8 +1157,8 @@ int jbd2_journal_get_create_access(handle_t *handle, struct buffer_head *bh) - JBUFFER_TRACE(jh, "set next transaction"); - spin_lock(&journal->j_list_lock); - jh->b_next_transaction = transaction; -+ spin_unlock(&journal->j_list_lock); - } -- spin_unlock(&journal->j_list_lock); - jbd_unlock_bh_state(bh); - - /* -diff --git a/fs/nfs/blocklayout/blocklayout.c b/fs/nfs/blocklayout/blocklayout.c -index 2178476..2905479 100644 ---- a/fs/nfs/blocklayout/blocklayout.c -+++ b/fs/nfs/blocklayout/blocklayout.c -@@ -344,9 +344,10 @@ static void bl_write_cleanup(struct work_struct *work) - u64 start = hdr->args.offset & (loff_t)PAGE_MASK; - u64 end = (hdr->args.offset + hdr->args.count + - PAGE_SIZE - 1) & (loff_t)PAGE_MASK; -+ u64 lwb = hdr->args.offset + hdr->args.count; - - ext_tree_mark_written(bl, start >> SECTOR_SHIFT, -- (end - start) >> SECTOR_SHIFT, end); -+ (end - start) >> SECTOR_SHIFT, lwb); - } - - pnfs_ld_write_done(hdr); -diff --git a/fs/nfs/delegation.c b/fs/nfs/delegation.c -index 322c258..b9c6542 100644 ---- a/fs/nfs/delegation.c -+++ b/fs/nfs/delegation.c -@@ -41,6 +41,17 @@ void nfs_mark_delegation_referenced(struct nfs_delegation *delegation) - set_bit(NFS_DELEGATION_REFERENCED, &delegation->flags); - } - -+static bool -+nfs4_is_valid_delegation(const struct nfs_delegation *delegation, -+ fmode_t flags) -+{ -+ if (delegation != NULL && (delegation->type & flags) == flags && -+ !test_bit(NFS_DELEGATION_REVOKED, &delegation->flags) && -+ !test_bit(NFS_DELEGATION_RETURNING, &delegation->flags)) -+ return true; -+ return false; -+} -+ - static int - nfs4_do_check_delegation(struct inode *inode, fmode_t flags, bool mark) - { -@@ -50,8 +61,7 @@ nfs4_do_check_delegation(struct inode *inode, fmode_t flags, bool mark) - flags &= FMODE_READ|FMODE_WRITE; - rcu_read_lock(); - delegation = rcu_dereference(NFS_I(inode)->delegation); -- if (delegation != NULL && (delegation->type & flags) == flags && -- !test_bit(NFS_DELEGATION_RETURNING, &delegation->flags)) { -+ if (nfs4_is_valid_delegation(delegation, flags)) { - if (mark) - nfs_mark_delegation_referenced(delegation); - ret = 1; -@@ -893,7 +903,7 @@ bool nfs4_copy_delegation_stateid(struct inode *inode, fmode_t flags, - flags &= FMODE_READ|FMODE_WRITE; - rcu_read_lock(); - delegation = rcu_dereference(nfsi->delegation); -- ret = (delegation != NULL && (delegation->type & flags) == flags); -+ ret = nfs4_is_valid_delegation(delegation, flags); - if (ret) { - nfs4_stateid_copy(dst, &delegation->stateid); - nfs_mark_delegation_referenced(delegation); -diff --git a/fs/nfs/dir.c b/fs/nfs/dir.c -index 177fefb..6bc5a68 100644 ---- a/fs/nfs/dir.c -+++ b/fs/nfs/dir.c -@@ -435,11 +435,11 @@ int nfs_same_file(struct dentry *dentry, struct nfs_entry *entry) - return 0; - - nfsi = NFS_I(inode); -- if (entry->fattr->fileid == nfsi->fileid) -- return 1; -- if (nfs_compare_fh(entry->fh, &nfsi->fh) == 0) -- return 1; -- return 0; -+ if (entry->fattr->fileid != nfsi->fileid) -+ return 0; -+ if (entry->fh->size && nfs_compare_fh(entry->fh, &nfsi->fh) != 0) -+ return 0; -+ return 1; - } - - static -@@ -517,6 +517,8 @@ void nfs_prime_dcache(struct dentry *parent, struct nfs_entry *entry) - &entry->fattr->fsid)) - goto out; - if (nfs_same_file(dentry, entry)) { -+ if (!entry->fh->size) -+ goto out; - nfs_set_verifier(dentry, nfs_save_change_attribute(dir)); - status = nfs_refresh_inode(d_inode(dentry), entry->fattr); - if (!status) -@@ -529,6 +531,10 @@ void nfs_prime_dcache(struct dentry *parent, struct nfs_entry *entry) - goto again; - } - } -+ if (!entry->fh->size) { -+ d_lookup_done(dentry); -+ goto out; -+ } - - inode = nfs_fhget(dentry->d_sb, entry->fh, entry->fattr, entry->label); - alias = d_splice_alias(inode, dentry); -diff --git a/fs/nfs/nfs42proc.c b/fs/nfs/nfs42proc.c -index 64b43b4..6085019 100644 ---- a/fs/nfs/nfs42proc.c -+++ b/fs/nfs/nfs42proc.c -@@ -443,6 +443,7 @@ int nfs42_proc_layoutstats_generic(struct nfs_server *server, - task = rpc_run_task(&task_setup); - if (IS_ERR(task)) - return PTR_ERR(task); -+ rpc_put_task(task); - return 0; - } - -diff --git a/fs/nfs/nfs4state.c b/fs/nfs/nfs4state.c -index cada00a..8353f33f 100644 ---- a/fs/nfs/nfs4state.c -+++ b/fs/nfs/nfs4state.c -@@ -1498,6 +1498,9 @@ static int nfs4_reclaim_open_state(struct nfs4_state_owner *sp, const struct nfs - __func__, status); - case -ENOENT: - case -ENOMEM: -+ case -EACCES: -+ case -EROFS: -+ case -EIO: - case -ESTALE: - /* Open state on this file cannot be recovered */ - nfs4_state_mark_recovery_failed(state, status); -diff --git a/fs/nfsd/nfssvc.c b/fs/nfsd/nfssvc.c -index 45007ac..a2b65fc 100644 ---- a/fs/nfsd/nfssvc.c -+++ b/fs/nfsd/nfssvc.c -@@ -366,14 +366,21 @@ static struct notifier_block nfsd_inet6addr_notifier = { - }; - #endif - -+/* Only used under nfsd_mutex, so this atomic may be overkill: */ -+static atomic_t nfsd_notifier_refcount = ATOMIC_INIT(0); -+ - static void nfsd_last_thread(struct svc_serv *serv, struct net *net) - { - struct nfsd_net *nn = net_generic(net, nfsd_net_id); - -- unregister_inetaddr_notifier(&nfsd_inetaddr_notifier); -+ /* check if the notifier still has clients */ -+ if (atomic_dec_return(&nfsd_notifier_refcount) == 0) { -+ unregister_inetaddr_notifier(&nfsd_inetaddr_notifier); - #if IS_ENABLED(CONFIG_IPV6) -- unregister_inet6addr_notifier(&nfsd_inet6addr_notifier); -+ unregister_inet6addr_notifier(&nfsd_inet6addr_notifier); - #endif -+ } -+ - /* - * write_ports can create the server without actually starting - * any threads--if we get shut down before any threads are -@@ -488,10 +495,13 @@ int nfsd_create_serv(struct net *net) - } - - set_max_drc(); -- register_inetaddr_notifier(&nfsd_inetaddr_notifier); -+ /* check if the notifier is already set */ -+ if (atomic_inc_return(&nfsd_notifier_refcount) == 1) { -+ register_inetaddr_notifier(&nfsd_inetaddr_notifier); - #if IS_ENABLED(CONFIG_IPV6) -- register_inet6addr_notifier(&nfsd_inet6addr_notifier); -+ register_inet6addr_notifier(&nfsd_inet6addr_notifier); - #endif -+ } - do_gettimeofday(&nn->nfssvc_boot); /* record boot time */ - return 0; - } -diff --git a/fs/overlayfs/copy_up.c b/fs/overlayfs/copy_up.c -index 43fdc27..abadbc3 100644 ---- a/fs/overlayfs/copy_up.c -+++ b/fs/overlayfs/copy_up.c -@@ -57,6 +57,7 @@ int ovl_copy_xattr(struct dentry *old, struct dentry *new) - ssize_t list_size, size, value_size = 0; - char *buf, *name, *value = NULL; - int uninitialized_var(error); -+ size_t slen; - - if (!old->d_inode->i_op->getxattr || - !new->d_inode->i_op->getxattr) -@@ -79,7 +80,16 @@ int ovl_copy_xattr(struct dentry *old, struct dentry *new) - goto out; - } - -- for (name = buf; name < (buf + list_size); name += strlen(name) + 1) { -+ for (name = buf; list_size; name += slen) { -+ slen = strnlen(name, list_size) + 1; -+ -+ /* underlying fs providing us with an broken xattr list? */ -+ if (WARN_ON(slen > list_size)) { -+ error = -EIO; -+ break; -+ } -+ list_size -= slen; -+ - if (ovl_is_private_xattr(name)) - continue; - retry: -diff --git a/fs/overlayfs/dir.c b/fs/overlayfs/dir.c -index 1560fdc..74e6964 100644 ---- a/fs/overlayfs/dir.c -+++ b/fs/overlayfs/dir.c -@@ -14,6 +14,7 @@ - #include <linux/cred.h> - #include <linux/posix_acl.h> - #include <linux/posix_acl_xattr.h> -+#include <linux/atomic.h> - #include "overlayfs.h" - - void ovl_cleanup(struct inode *wdir, struct dentry *wdentry) -@@ -37,8 +38,10 @@ struct dentry *ovl_lookup_temp(struct dentry *workdir, struct dentry *dentry) - { - struct dentry *temp; - char name[20]; -+ static atomic_t temp_id = ATOMIC_INIT(0); - -- snprintf(name, sizeof(name), "#%lx", (unsigned long) dentry); -+ /* counter is allowed to wrap, since temp dentries are ephemeral */ -+ snprintf(name, sizeof(name), "#%x", atomic_inc_return(&temp_id)); - - temp = lookup_one_len(name, workdir, strlen(name)); - if (!IS_ERR(temp) && temp->d_inode) { -diff --git a/fs/pstore/ram.c b/fs/pstore/ram.c -index 7a034d6..2340262 100644 ---- a/fs/pstore/ram.c -+++ b/fs/pstore/ram.c -@@ -377,13 +377,14 @@ static void ramoops_free_przs(struct ramoops_context *cxt) - { - int i; - -- cxt->max_dump_cnt = 0; - if (!cxt->przs) - return; - -- for (i = 0; !IS_ERR_OR_NULL(cxt->przs[i]); i++) -+ for (i = 0; i < cxt->max_dump_cnt; i++) - persistent_ram_free(cxt->przs[i]); -+ - kfree(cxt->przs); -+ cxt->max_dump_cnt = 0; - } - - static int ramoops_init_przs(struct device *dev, struct ramoops_context *cxt, -@@ -408,7 +409,7 @@ static int ramoops_init_przs(struct device *dev, struct ramoops_context *cxt, - GFP_KERNEL); - if (!cxt->przs) { - dev_err(dev, "failed to initialize a prz array for dumps\n"); -- goto fail_prz; -+ goto fail_mem; - } - - for (i = 0; i < cxt->max_dump_cnt; i++) { -@@ -419,6 +420,11 @@ static int ramoops_init_przs(struct device *dev, struct ramoops_context *cxt, - err = PTR_ERR(cxt->przs[i]); - dev_err(dev, "failed to request mem region (0x%zx@0x%llx): %d\n", - cxt->record_size, (unsigned long long)*paddr, err); -+ -+ while (i > 0) { -+ i--; -+ persistent_ram_free(cxt->przs[i]); -+ } - goto fail_prz; - } - *paddr += cxt->record_size; -@@ -426,7 +432,9 @@ static int ramoops_init_przs(struct device *dev, struct ramoops_context *cxt, - - return 0; - fail_prz: -- ramoops_free_przs(cxt); -+ kfree(cxt->przs); -+fail_mem: -+ cxt->max_dump_cnt = 0; - return err; - } - -@@ -659,7 +667,6 @@ static int ramoops_remove(struct platform_device *pdev) - struct ramoops_context *cxt = &oops_cxt; - - pstore_unregister(&cxt->pstore); -- cxt->max_dump_cnt = 0; - - kfree(cxt->pstore.buf); - cxt->pstore.bufsize = 0; -diff --git a/fs/pstore/ram_core.c b/fs/pstore/ram_core.c -index 76c3f80..364d2df 100644 ---- a/fs/pstore/ram_core.c -+++ b/fs/pstore/ram_core.c -@@ -47,43 +47,10 @@ static inline size_t buffer_start(struct persistent_ram_zone *prz) - return atomic_read(&prz->buffer->start); - } - --/* increase and wrap the start pointer, returning the old value */ --static size_t buffer_start_add_atomic(struct persistent_ram_zone *prz, size_t a) --{ -- int old; -- int new; -- -- do { -- old = atomic_read(&prz->buffer->start); -- new = old + a; -- while (unlikely(new >= prz->buffer_size)) -- new -= prz->buffer_size; -- } while (atomic_cmpxchg(&prz->buffer->start, old, new) != old); -- -- return old; --} -- --/* increase the size counter until it hits the max size */ --static void buffer_size_add_atomic(struct persistent_ram_zone *prz, size_t a) --{ -- size_t old; -- size_t new; -- -- if (atomic_read(&prz->buffer->size) == prz->buffer_size) -- return; -- -- do { -- old = atomic_read(&prz->buffer->size); -- new = old + a; -- if (new > prz->buffer_size) -- new = prz->buffer_size; -- } while (atomic_cmpxchg(&prz->buffer->size, old, new) != old); --} -- - static DEFINE_RAW_SPINLOCK(buffer_lock); - - /* increase and wrap the start pointer, returning the old value */ --static size_t buffer_start_add_locked(struct persistent_ram_zone *prz, size_t a) -+static size_t buffer_start_add(struct persistent_ram_zone *prz, size_t a) - { - int old; - int new; -@@ -103,7 +70,7 @@ static size_t buffer_start_add_locked(struct persistent_ram_zone *prz, size_t a) - } - - /* increase the size counter until it hits the max size */ --static void buffer_size_add_locked(struct persistent_ram_zone *prz, size_t a) -+static void buffer_size_add(struct persistent_ram_zone *prz, size_t a) - { - size_t old; - size_t new; -@@ -124,9 +91,6 @@ static void buffer_size_add_locked(struct persistent_ram_zone *prz, size_t a) - raw_spin_unlock_irqrestore(&buffer_lock, flags); - } - --static size_t (*buffer_start_add)(struct persistent_ram_zone *, size_t) = buffer_start_add_atomic; --static void (*buffer_size_add)(struct persistent_ram_zone *, size_t) = buffer_size_add_atomic; -- - static void notrace persistent_ram_encode_rs8(struct persistent_ram_zone *prz, - uint8_t *data, size_t len, uint8_t *ecc) - { -@@ -299,7 +263,7 @@ static void notrace persistent_ram_update(struct persistent_ram_zone *prz, - const void *s, unsigned int start, unsigned int count) - { - struct persistent_ram_buffer *buffer = prz->buffer; -- memcpy(buffer->data + start, s, count); -+ memcpy_toio(buffer->data + start, s, count); - persistent_ram_update_ecc(prz, start, count); - } - -@@ -322,8 +286,8 @@ void persistent_ram_save_old(struct persistent_ram_zone *prz) - } - - prz->old_log_size = size; -- memcpy(prz->old_log, &buffer->data[start], size - start); -- memcpy(prz->old_log + size - start, &buffer->data[0], start); -+ memcpy_fromio(prz->old_log, &buffer->data[start], size - start); -+ memcpy_fromio(prz->old_log + size - start, &buffer->data[0], start); - } - - int notrace persistent_ram_write(struct persistent_ram_zone *prz, -@@ -426,9 +390,6 @@ static void *persistent_ram_iomap(phys_addr_t start, size_t size, - return NULL; - } - -- buffer_start_add = buffer_start_add_locked; -- buffer_size_add = buffer_size_add_locked; -- - if (memtype) - va = ioremap(start, size); - else -diff --git a/fs/super.c b/fs/super.c -index c2ff475..47d11e0 100644 ---- a/fs/super.c -+++ b/fs/super.c -@@ -1379,8 +1379,8 @@ int freeze_super(struct super_block *sb) - } - } - /* -- * This is just for debugging purposes so that fs can warn if it -- * sees write activity when frozen is set to SB_FREEZE_COMPLETE. -+ * For debugging purposes so that fs can warn if it sees write activity -+ * when frozen is set to SB_FREEZE_COMPLETE, and for thaw_super(). - */ - sb->s_writers.frozen = SB_FREEZE_COMPLETE; - up_write(&sb->s_umount); -@@ -1399,7 +1399,7 @@ int thaw_super(struct super_block *sb) - int error; - - down_write(&sb->s_umount); -- if (sb->s_writers.frozen == SB_UNFROZEN) { -+ if (sb->s_writers.frozen != SB_FREEZE_COMPLETE) { - up_write(&sb->s_umount); - return -EINVAL; - } -diff --git a/fs/ubifs/xattr.c b/fs/ubifs/xattr.c -index 11a0041..c9ee6f6 100644 ---- a/fs/ubifs/xattr.c -+++ b/fs/ubifs/xattr.c -@@ -172,6 +172,7 @@ static int create_xattr(struct ubifs_info *c, struct inode *host, - host_ui->xattr_cnt -= 1; - host_ui->xattr_size -= CALC_DENT_SIZE(nm->len); - host_ui->xattr_size -= CALC_XATTR_BYTES(size); -+ host_ui->xattr_names -= nm->len; - mutex_unlock(&host_ui->ui_mutex); - out_free: - make_bad_inode(inode); -@@ -476,6 +477,7 @@ static int remove_xattr(struct ubifs_info *c, struct inode *host, - host_ui->xattr_cnt += 1; - host_ui->xattr_size += CALC_DENT_SIZE(nm->len); - host_ui->xattr_size += CALC_XATTR_BYTES(ui->data_len); -+ host_ui->xattr_names += nm->len; - mutex_unlock(&host_ui->ui_mutex); - ubifs_release_budget(c, &req); - make_bad_inode(inode); -diff --git a/include/dt-bindings/clock/imx6qdl-clock.h b/include/dt-bindings/clock/imx6qdl-clock.h -index 2905033..da59fd9 100644 ---- a/include/dt-bindings/clock/imx6qdl-clock.h -+++ b/include/dt-bindings/clock/imx6qdl-clock.h -@@ -269,6 +269,8 @@ - #define IMX6QDL_CLK_PRG0_APB 256 - #define IMX6QDL_CLK_PRG1_APB 257 - #define IMX6QDL_CLK_PRE_AXI 258 --#define IMX6QDL_CLK_END 259 -+#define IMX6QDL_CLK_MLB_SEL 259 -+#define IMX6QDL_CLK_MLB_PODF 260 -+#define IMX6QDL_CLK_END 261 - - #endif /* __DT_BINDINGS_CLOCK_IMX6QDL_H */ -diff --git a/include/linux/cpufreq.h b/include/linux/cpufreq.h -index 631ba33b..32dc0cbd 100644 ---- a/include/linux/cpufreq.h -+++ b/include/linux/cpufreq.h -@@ -639,19 +639,19 @@ static inline int cpufreq_table_find_index_al(struct cpufreq_policy *policy, - unsigned int target_freq) - { - struct cpufreq_frequency_table *table = policy->freq_table; -+ struct cpufreq_frequency_table *pos, *best = table - 1; - unsigned int freq; -- int i, best = -1; - -- for (i = 0; table[i].frequency != CPUFREQ_TABLE_END; i++) { -- freq = table[i].frequency; -+ cpufreq_for_each_valid_entry(pos, table) { -+ freq = pos->frequency; - - if (freq >= target_freq) -- return i; -+ return pos - table; - -- best = i; -+ best = pos; - } - -- return best; -+ return best - table; - } - - /* Find lowest freq at or above target in a table in descending order */ -@@ -659,28 +659,28 @@ static inline int cpufreq_table_find_index_dl(struct cpufreq_policy *policy, - unsigned int target_freq) - { - struct cpufreq_frequency_table *table = policy->freq_table; -+ struct cpufreq_frequency_table *pos, *best = table - 1; - unsigned int freq; -- int i, best = -1; - -- for (i = 0; table[i].frequency != CPUFREQ_TABLE_END; i++) { -- freq = table[i].frequency; -+ cpufreq_for_each_valid_entry(pos, table) { -+ freq = pos->frequency; - - if (freq == target_freq) -- return i; -+ return pos - table; - - if (freq > target_freq) { -- best = i; -+ best = pos; - continue; - } - - /* No freq found above target_freq */ -- if (best == -1) -- return i; -+ if (best == table - 1) -+ return pos - table; - -- return best; -+ return best - table; - } - -- return best; -+ return best - table; - } - - /* Works only on sorted freq-tables */ -@@ -700,28 +700,28 @@ static inline int cpufreq_table_find_index_ah(struct cpufreq_policy *policy, - unsigned int target_freq) - { - struct cpufreq_frequency_table *table = policy->freq_table; -+ struct cpufreq_frequency_table *pos, *best = table - 1; - unsigned int freq; -- int i, best = -1; - -- for (i = 0; table[i].frequency != CPUFREQ_TABLE_END; i++) { -- freq = table[i].frequency; -+ cpufreq_for_each_valid_entry(pos, table) { -+ freq = pos->frequency; - - if (freq == target_freq) -- return i; -+ return pos - table; - - if (freq < target_freq) { -- best = i; -+ best = pos; - continue; - } - - /* No freq found below target_freq */ -- if (best == -1) -- return i; -+ if (best == table - 1) -+ return pos - table; - -- return best; -+ return best - table; - } - -- return best; -+ return best - table; - } - - /* Find highest freq at or below target in a table in descending order */ -@@ -729,19 +729,19 @@ static inline int cpufreq_table_find_index_dh(struct cpufreq_policy *policy, - unsigned int target_freq) - { - struct cpufreq_frequency_table *table = policy->freq_table; -+ struct cpufreq_frequency_table *pos, *best = table - 1; - unsigned int freq; -- int i, best = -1; - -- for (i = 0; table[i].frequency != CPUFREQ_TABLE_END; i++) { -- freq = table[i].frequency; -+ cpufreq_for_each_valid_entry(pos, table) { -+ freq = pos->frequency; - - if (freq <= target_freq) -- return i; -+ return pos - table; - -- best = i; -+ best = pos; - } - -- return best; -+ return best - table; - } - - /* Works only on sorted freq-tables */ -@@ -761,32 +761,32 @@ static inline int cpufreq_table_find_index_ac(struct cpufreq_policy *policy, - unsigned int target_freq) - { - struct cpufreq_frequency_table *table = policy->freq_table; -+ struct cpufreq_frequency_table *pos, *best = table - 1; - unsigned int freq; -- int i, best = -1; - -- for (i = 0; table[i].frequency != CPUFREQ_TABLE_END; i++) { -- freq = table[i].frequency; -+ cpufreq_for_each_valid_entry(pos, table) { -+ freq = pos->frequency; - - if (freq == target_freq) -- return i; -+ return pos - table; - - if (freq < target_freq) { -- best = i; -+ best = pos; - continue; - } - - /* No freq found below target_freq */ -- if (best == -1) -- return i; -+ if (best == table - 1) -+ return pos - table; - - /* Choose the closest freq */ -- if (target_freq - table[best].frequency > freq - target_freq) -- return i; -+ if (target_freq - best->frequency > freq - target_freq) -+ return pos - table; - -- return best; -+ return best - table; - } - -- return best; -+ return best - table; - } - - /* Find closest freq to target in a table in descending order */ -@@ -794,32 +794,32 @@ static inline int cpufreq_table_find_index_dc(struct cpufreq_policy *policy, - unsigned int target_freq) - { - struct cpufreq_frequency_table *table = policy->freq_table; -+ struct cpufreq_frequency_table *pos, *best = table - 1; - unsigned int freq; -- int i, best = -1; - -- for (i = 0; table[i].frequency != CPUFREQ_TABLE_END; i++) { -- freq = table[i].frequency; -+ cpufreq_for_each_valid_entry(pos, table) { -+ freq = pos->frequency; - - if (freq == target_freq) -- return i; -+ return pos - table; - - if (freq > target_freq) { -- best = i; -+ best = pos; - continue; - } - - /* No freq found above target_freq */ -- if (best == -1) -- return i; -+ if (best == table - 1) -+ return pos - table; - - /* Choose the closest freq */ -- if (table[best].frequency - target_freq > target_freq - freq) -- return i; -+ if (best->frequency - target_freq > target_freq - freq) -+ return pos - table; - -- return best; -+ return best - table; - } - -- return best; -+ return best - table; - } - - /* Works only on sorted freq-tables */ -diff --git a/include/linux/devfreq-event.h b/include/linux/devfreq-event.h -index 0a83a1e..4db00b0 100644 ---- a/include/linux/devfreq-event.h -+++ b/include/linux/devfreq-event.h -@@ -148,11 +148,6 @@ static inline int devfreq_event_reset_event(struct devfreq_event_dev *edev) - return -EINVAL; - } - --static inline void *devfreq_event_get_drvdata(struct devfreq_event_dev *edev) --{ -- return ERR_PTR(-EINVAL); --} -- - static inline struct devfreq_event_dev *devfreq_event_get_edev_by_phandle( - struct device *dev, int index) - { -diff --git a/include/linux/irqchip/arm-gic-v3.h b/include/linux/irqchip/arm-gic-v3.h -index 99ac022..3a8610e 100644 ---- a/include/linux/irqchip/arm-gic-v3.h -+++ b/include/linux/irqchip/arm-gic-v3.h -@@ -290,7 +290,7 @@ - #define GITS_BASER_TYPE_SHIFT (56) - #define GITS_BASER_TYPE(r) (((r) >> GITS_BASER_TYPE_SHIFT) & 7) - #define GITS_BASER_ENTRY_SIZE_SHIFT (48) --#define GITS_BASER_ENTRY_SIZE(r) ((((r) >> GITS_BASER_ENTRY_SIZE_SHIFT) & 0xff) + 1) -+#define GITS_BASER_ENTRY_SIZE(r) ((((r) >> GITS_BASER_ENTRY_SIZE_SHIFT) & 0x1f) + 1) - #define GITS_BASER_SHAREABILITY_SHIFT (10) - #define GITS_BASER_InnerShareable \ - GIC_BASER_SHAREABILITY(GITS_BASER, InnerShareable) -diff --git a/include/target/target_core_base.h b/include/target/target_core_base.h -index fb8e3b6..c211900 100644 ---- a/include/target/target_core_base.h -+++ b/include/target/target_core_base.h -@@ -177,6 +177,7 @@ enum tcm_sense_reason_table { - TCM_LOGICAL_BLOCK_GUARD_CHECK_FAILED = R(0x15), - TCM_LOGICAL_BLOCK_APP_TAG_CHECK_FAILED = R(0x16), - TCM_LOGICAL_BLOCK_REF_TAG_CHECK_FAILED = R(0x17), -+ TCM_COPY_TARGET_DEVICE_NOT_REACHABLE = R(0x18), - #undef R - }; - -diff --git a/kernel/sched/fair.c b/kernel/sched/fair.c -index 039de34..8b3610c 100644 ---- a/kernel/sched/fair.c -+++ b/kernel/sched/fair.c -@@ -456,17 +456,23 @@ static inline int entity_before(struct sched_entity *a, - - static void update_min_vruntime(struct cfs_rq *cfs_rq) - { -+ struct sched_entity *curr = cfs_rq->curr; -+ - u64 vruntime = cfs_rq->min_vruntime; - -- if (cfs_rq->curr) -- vruntime = cfs_rq->curr->vruntime; -+ if (curr) { -+ if (curr->on_rq) -+ vruntime = curr->vruntime; -+ else -+ curr = NULL; -+ } - - if (cfs_rq->rb_leftmost) { - struct sched_entity *se = rb_entry(cfs_rq->rb_leftmost, - struct sched_entity, - run_node); - -- if (!cfs_rq->curr) -+ if (!curr) - vruntime = se->vruntime; - else - vruntime = min_vruntime(vruntime, se->vruntime); -@@ -680,7 +686,14 @@ void init_entity_runnable_average(struct sched_entity *se) - * will definitely be update (after enqueue). - */ - sa->period_contrib = 1023; -- sa->load_avg = scale_load_down(se->load.weight); -+ /* -+ * Tasks are intialized with full load to be seen as heavy tasks until -+ * they get a chance to stabilize to their real load level. -+ * Group entities are intialized with zero load to reflect the fact that -+ * nothing has been attached to the task group yet. -+ */ -+ if (entity_is_task(se)) -+ sa->load_avg = scale_load_down(se->load.weight); - sa->load_sum = sa->load_avg * LOAD_AVG_MAX; - /* - * At this point, util_avg won't be used in select_task_rq_fair anyway -@@ -3459,9 +3472,10 @@ dequeue_entity(struct cfs_rq *cfs_rq, struct sched_entity *se, int flags) - account_entity_dequeue(cfs_rq, se); - - /* -- * Normalize the entity after updating the min_vruntime because the -- * update can refer to the ->curr item and we need to reflect this -- * movement in our normalized position. -+ * Normalize after update_curr(); which will also have moved -+ * min_vruntime if @se is the one holding it back. But before doing -+ * update_min_vruntime() again, which will discount @se's position and -+ * can move min_vruntime forward still more. - */ - if (!(flags & DEQUEUE_SLEEP)) - se->vruntime -= cfs_rq->min_vruntime; -@@ -3469,8 +3483,16 @@ dequeue_entity(struct cfs_rq *cfs_rq, struct sched_entity *se, int flags) - /* return excess runtime on last dequeue */ - return_cfs_rq_runtime(cfs_rq); - -- update_min_vruntime(cfs_rq); - update_cfs_shares(cfs_rq); -+ -+ /* -+ * Now advance min_vruntime if @se was the entity holding it back, -+ * except when: DEQUEUE_SAVE && !DEQUEUE_MOVE, in this case we'll be -+ * put back on, and if we advance min_vruntime, we'll be placed back -+ * further than we started -- ie. we'll be penalized. -+ */ -+ if ((flags & (DEQUEUE_SAVE | DEQUEUE_MOVE)) == DEQUEUE_SAVE) -+ update_min_vruntime(cfs_rq); - } - - /* -diff --git a/net/sunrpc/xprtsock.c b/net/sunrpc/xprtsock.c -index bf16883..e72581d 100644 ---- a/net/sunrpc/xprtsock.c -+++ b/net/sunrpc/xprtsock.c -@@ -473,7 +473,16 @@ static int xs_nospace(struct rpc_task *task) - spin_unlock_bh(&xprt->transport_lock); - - /* Race breaker in case memory is freed before above code is called */ -- sk->sk_write_space(sk); -+ if (ret == -EAGAIN) { -+ struct socket_wq *wq; -+ -+ rcu_read_lock(); -+ wq = rcu_dereference(sk->sk_wq); -+ set_bit(SOCKWQ_ASYNC_NOSPACE, &wq->flags); -+ rcu_read_unlock(); -+ -+ sk->sk_write_space(sk); -+ } - return ret; - } - -diff --git a/sound/pci/hda/dell_wmi_helper.c b/sound/pci/hda/dell_wmi_helper.c -index 9c22f95..19d41da 100644 ---- a/sound/pci/hda/dell_wmi_helper.c -+++ b/sound/pci/hda/dell_wmi_helper.c -@@ -49,7 +49,7 @@ static void alc_fixup_dell_wmi(struct hda_codec *codec, - removefunc = true; - if (dell_led_set_func(DELL_LED_MICMUTE, false) >= 0) { - dell_led_value = 0; -- if (spec->gen.num_adc_nids > 1) -+ if (spec->gen.num_adc_nids > 1 && !spec->gen.dyn_adc_switch) - codec_dbg(codec, "Skipping micmute LED control due to several ADCs"); - else { - dell_old_cap_hook = spec->gen.cap_sync_hook; -diff --git a/sound/pci/hda/thinkpad_helper.c b/sound/pci/hda/thinkpad_helper.c -index f0955fd..6a23302 100644 ---- a/sound/pci/hda/thinkpad_helper.c -+++ b/sound/pci/hda/thinkpad_helper.c -@@ -62,7 +62,7 @@ static void hda_fixup_thinkpad_acpi(struct hda_codec *codec, - removefunc = false; - } - if (led_set_func(TPACPI_LED_MICMUTE, false) >= 0) { -- if (spec->num_adc_nids > 1) -+ if (spec->num_adc_nids > 1 && !spec->dyn_adc_switch) - codec_dbg(codec, - "Skipping micmute LED control due to several ADCs"); - else { -diff --git a/tools/perf/util/intel-pt-decoder/intel-pt-decoder.c b/tools/perf/util/intel-pt-decoder/intel-pt-decoder.c -index 8ff6c6a..c9c8dc3 100644 ---- a/tools/perf/util/intel-pt-decoder/intel-pt-decoder.c -+++ b/tools/perf/util/intel-pt-decoder/intel-pt-decoder.c -@@ -89,6 +89,7 @@ struct intel_pt_decoder { - bool pge; - bool have_tma; - bool have_cyc; -+ bool fixup_last_mtc; - uint64_t pos; - uint64_t last_ip; - uint64_t ip; -@@ -584,10 +585,31 @@ struct intel_pt_calc_cyc_to_tsc_info { - uint64_t tsc_timestamp; - uint64_t timestamp; - bool have_tma; -+ bool fixup_last_mtc; - bool from_mtc; - double cbr_cyc_to_tsc; - }; - -+/* -+ * MTC provides a 8-bit slice of CTC but the TMA packet only provides the lower -+ * 16 bits of CTC. If mtc_shift > 8 then some of the MTC bits are not in the CTC -+ * provided by the TMA packet. Fix-up the last_mtc calculated from the TMA -+ * packet by copying the missing bits from the current MTC assuming the least -+ * difference between the two, and that the current MTC comes after last_mtc. -+ */ -+static void intel_pt_fixup_last_mtc(uint32_t mtc, int mtc_shift, -+ uint32_t *last_mtc) -+{ -+ uint32_t first_missing_bit = 1U << (16 - mtc_shift); -+ uint32_t mask = ~(first_missing_bit - 1); -+ -+ *last_mtc |= mtc & mask; -+ if (*last_mtc >= mtc) { -+ *last_mtc -= first_missing_bit; -+ *last_mtc &= 0xff; -+ } -+} -+ - static int intel_pt_calc_cyc_cb(struct intel_pt_pkt_info *pkt_info) - { - struct intel_pt_decoder *decoder = pkt_info->decoder; -@@ -617,6 +639,11 @@ static int intel_pt_calc_cyc_cb(struct intel_pt_pkt_info *pkt_info) - return 0; - - mtc = pkt_info->packet.payload; -+ if (decoder->mtc_shift > 8 && data->fixup_last_mtc) { -+ data->fixup_last_mtc = false; -+ intel_pt_fixup_last_mtc(mtc, decoder->mtc_shift, -+ &data->last_mtc); -+ } - if (mtc > data->last_mtc) - mtc_delta = mtc - data->last_mtc; - else -@@ -685,6 +712,7 @@ static int intel_pt_calc_cyc_cb(struct intel_pt_pkt_info *pkt_info) - - data->ctc_delta = 0; - data->have_tma = true; -+ data->fixup_last_mtc = true; - - return 0; - -@@ -751,6 +779,7 @@ static void intel_pt_calc_cyc_to_tsc(struct intel_pt_decoder *decoder, - .tsc_timestamp = decoder->tsc_timestamp, - .timestamp = decoder->timestamp, - .have_tma = decoder->have_tma, -+ .fixup_last_mtc = decoder->fixup_last_mtc, - .from_mtc = from_mtc, - .cbr_cyc_to_tsc = 0, - }; -@@ -1241,6 +1270,7 @@ static void intel_pt_calc_tma(struct intel_pt_decoder *decoder) - } - decoder->ctc_delta = 0; - decoder->have_tma = true; -+ decoder->fixup_last_mtc = true; - intel_pt_log("CTC timestamp " x64_fmt " last MTC %#x CTC rem %#x\n", - decoder->ctc_timestamp, decoder->last_mtc, ctc_rem); - } -@@ -1255,6 +1285,12 @@ static void intel_pt_calc_mtc_timestamp(struct intel_pt_decoder *decoder) - - mtc = decoder->packet.payload; - -+ if (decoder->mtc_shift > 8 && decoder->fixup_last_mtc) { -+ decoder->fixup_last_mtc = false; -+ intel_pt_fixup_last_mtc(mtc, decoder->mtc_shift, -+ &decoder->last_mtc); -+ } -+ - if (mtc > decoder->last_mtc) - mtc_delta = mtc - decoder->last_mtc; - else -@@ -1323,6 +1359,8 @@ static void intel_pt_calc_cyc_timestamp(struct intel_pt_decoder *decoder) - timestamp, decoder->timestamp); - else - decoder->timestamp = timestamp; -+ -+ decoder->timestamp_insn_cnt = 0; - } - - /* Walk PSB+ packets when already in sync. */ -diff --git a/tools/perf/util/intel-pt.c b/tools/perf/util/intel-pt.c -index 551ff6f..b2878d2 100644 ---- a/tools/perf/util/intel-pt.c -+++ b/tools/perf/util/intel-pt.c -@@ -241,7 +241,7 @@ static int intel_pt_get_trace(struct intel_pt_buffer *b, void *data) - } - - queue = &ptq->pt->queues.queue_array[ptq->queue_nr]; -- -+next: - buffer = auxtrace_buffer__next(queue, buffer); - if (!buffer) { - if (old_buffer) -@@ -264,9 +264,6 @@ static int intel_pt_get_trace(struct intel_pt_buffer *b, void *data) - intel_pt_do_fix_overlap(ptq->pt, old_buffer, buffer)) - return -ENOMEM; - -- if (old_buffer) -- auxtrace_buffer__drop_data(old_buffer); -- - if (buffer->use_data) { - b->len = buffer->use_size; - b->buf = buffer->use_data; -@@ -276,6 +273,16 @@ static int intel_pt_get_trace(struct intel_pt_buffer *b, void *data) - } - b->ref_timestamp = buffer->reference; - -+ /* -+ * If in snapshot mode and the buffer has no usable data, get next -+ * buffer and again check overlap against old_buffer. -+ */ -+ if (ptq->pt->snapshot_mode && !b->len) -+ goto next; -+ -+ if (old_buffer) -+ auxtrace_buffer__drop_data(old_buffer); -+ - if (!old_buffer || ptq->pt->sampling_mode || (ptq->pt->snapshot_mode && - !buffer->consecutive)) { - b->consecutive = false; -diff --git a/tools/spi/spidev_test.c b/tools/spi/spidev_test.c -index 8a73d81..f3825b6 100644 ---- a/tools/spi/spidev_test.c -+++ b/tools/spi/spidev_test.c -@@ -284,7 +284,7 @@ static void parse_opts(int argc, char *argv[]) - - static void transfer_escaped_string(int fd, char *str) - { -- size_t size = strlen(str + 1); -+ size_t size = strlen(str); - uint8_t *tx; - uint8_t *rx; - diff --git a/4.8.7/1005_linux-4.8.6.patch b/4.8.7/1005_linux-4.8.6.patch deleted file mode 100644 index 641ba27..0000000 --- a/4.8.7/1005_linux-4.8.6.patch +++ /dev/null @@ -1,5137 +0,0 @@ -diff --git a/Makefile b/Makefile -index daa3a01..b249529 100644 ---- a/Makefile -+++ b/Makefile -@@ -1,6 +1,6 @@ - VERSION = 4 - PATCHLEVEL = 8 --SUBLEVEL = 5 -+SUBLEVEL = 6 - EXTRAVERSION = - NAME = Psychotic Stoned Sheep - -diff --git a/arch/arm/boot/dts/arm-realview-eb.dtsi b/arch/arm/boot/dts/arm-realview-eb.dtsi -index 1c6a040..e2e9599 100644 ---- a/arch/arm/boot/dts/arm-realview-eb.dtsi -+++ b/arch/arm/boot/dts/arm-realview-eb.dtsi -@@ -51,14 +51,6 @@ - regulator-boot-on; - }; - -- veth: fixedregulator@0 { -- compatible = "regulator-fixed"; -- regulator-name = "veth"; -- regulator-min-microvolt = <3300000>; -- regulator-max-microvolt = <3300000>; -- regulator-boot-on; -- }; -- - xtal24mhz: xtal24mhz@24M { - #clock-cells = <0>; - compatible = "fixed-clock"; -@@ -134,16 +126,15 @@ - bank-width = <4>; - }; - -- /* SMSC 9118 ethernet with PHY and EEPROM */ -+ /* SMSC LAN91C111 ethernet with PHY and EEPROM */ - ethernet: ethernet@4e000000 { -- compatible = "smsc,lan9118", "smsc,lan9115"; -+ compatible = "smsc,lan91c111"; - reg = <0x4e000000 0x10000>; -- phy-mode = "mii"; -- reg-io-width = <4>; -- smsc,irq-active-high; -- smsc,irq-push-pull; -- vdd33a-supply = <&veth>; -- vddvario-supply = <&veth>; -+ /* -+ * This means the adapter can be accessed with 8, 16 or -+ * 32 bit reads/writes. -+ */ -+ reg-io-width = <7>; - }; - - usb: usb@4f000000 { -diff --git a/arch/arm/boot/dts/bcm958625hr.dts b/arch/arm/boot/dts/bcm958625hr.dts -index 03b8bbe..652418a 100644 ---- a/arch/arm/boot/dts/bcm958625hr.dts -+++ b/arch/arm/boot/dts/bcm958625hr.dts -@@ -47,7 +47,8 @@ - }; - - memory { -- reg = <0x60000000 0x20000000>; -+ device_type = "memory"; -+ reg = <0x60000000 0x80000000>; - }; - }; - -diff --git a/arch/arm/boot/dts/omap3-overo-common-lcd35.dtsi b/arch/arm/boot/dts/omap3-overo-common-lcd35.dtsi -index ca86da6..854117d 100644 ---- a/arch/arm/boot/dts/omap3-overo-common-lcd35.dtsi -+++ b/arch/arm/boot/dts/omap3-overo-common-lcd35.dtsi -@@ -119,7 +119,7 @@ - pinctrl-names = "default"; - pinctrl-0 = <&mcspi1_pins>; - -- lcd0: display { -+ lcd0: display@1 { - compatible = "lgphilips,lb035q02"; - label = "lcd35"; - -diff --git a/arch/arm/boot/dts/sun9i-a80.dtsi b/arch/arm/boot/dts/sun9i-a80.dtsi -index f68b324..3f528a3 100644 ---- a/arch/arm/boot/dts/sun9i-a80.dtsi -+++ b/arch/arm/boot/dts/sun9i-a80.dtsi -@@ -899,8 +899,7 @@ - resets = <&apbs_rst 0>; - gpio-controller; - interrupt-controller; -- #address-cells = <1>; -- #size-cells = <0>; -+ #interrupt-cells = <3>; - #gpio-cells = <3>; - - r_ir_pins: r_ir { -diff --git a/arch/arm/crypto/ghash-ce-glue.c b/arch/arm/crypto/ghash-ce-glue.c -index 1568cb5..b88364a 100644 ---- a/arch/arm/crypto/ghash-ce-glue.c -+++ b/arch/arm/crypto/ghash-ce-glue.c -@@ -220,6 +220,27 @@ static int ghash_async_digest(struct ahash_request *req) - } - } - -+static int ghash_async_import(struct ahash_request *req, const void *in) -+{ -+ struct ahash_request *cryptd_req = ahash_request_ctx(req); -+ struct crypto_ahash *tfm = crypto_ahash_reqtfm(req); -+ struct ghash_async_ctx *ctx = crypto_ahash_ctx(tfm); -+ struct shash_desc *desc = cryptd_shash_desc(cryptd_req); -+ -+ desc->tfm = cryptd_ahash_child(ctx->cryptd_tfm); -+ desc->flags = req->base.flags; -+ -+ return crypto_shash_import(desc, in); -+} -+ -+static int ghash_async_export(struct ahash_request *req, void *out) -+{ -+ struct ahash_request *cryptd_req = ahash_request_ctx(req); -+ struct shash_desc *desc = cryptd_shash_desc(cryptd_req); -+ -+ return crypto_shash_export(desc, out); -+} -+ - static int ghash_async_setkey(struct crypto_ahash *tfm, const u8 *key, - unsigned int keylen) - { -@@ -268,7 +289,10 @@ static struct ahash_alg ghash_async_alg = { - .final = ghash_async_final, - .setkey = ghash_async_setkey, - .digest = ghash_async_digest, -+ .import = ghash_async_import, -+ .export = ghash_async_export, - .halg.digestsize = GHASH_DIGEST_SIZE, -+ .halg.statesize = sizeof(struct ghash_desc_ctx), - .halg.base = { - .cra_name = "ghash", - .cra_driver_name = "ghash-ce", -diff --git a/arch/arm/mach-pxa/corgi_pm.c b/arch/arm/mach-pxa/corgi_pm.c -index d920681..c71c483 100644 ---- a/arch/arm/mach-pxa/corgi_pm.c -+++ b/arch/arm/mach-pxa/corgi_pm.c -@@ -131,16 +131,11 @@ static int corgi_should_wakeup(unsigned int resume_on_alarm) - return is_resume; - } - --static unsigned long corgi_charger_wakeup(void) -+static bool corgi_charger_wakeup(void) - { -- unsigned long ret; -- -- ret = (!gpio_get_value(CORGI_GPIO_AC_IN) << GPIO_bit(CORGI_GPIO_AC_IN)) -- | (!gpio_get_value(CORGI_GPIO_KEY_INT) -- << GPIO_bit(CORGI_GPIO_KEY_INT)) -- | (!gpio_get_value(CORGI_GPIO_WAKEUP) -- << GPIO_bit(CORGI_GPIO_WAKEUP)); -- return ret; -+ return !gpio_get_value(CORGI_GPIO_AC_IN) || -+ !gpio_get_value(CORGI_GPIO_KEY_INT) || -+ !gpio_get_value(CORGI_GPIO_WAKEUP); - } - - unsigned long corgipm_read_devdata(int type) -diff --git a/arch/arm/mach-pxa/pxa_cplds_irqs.c b/arch/arm/mach-pxa/pxa_cplds_irqs.c -index 2385052..e362f86 100644 ---- a/arch/arm/mach-pxa/pxa_cplds_irqs.c -+++ b/arch/arm/mach-pxa/pxa_cplds_irqs.c -@@ -41,30 +41,35 @@ static irqreturn_t cplds_irq_handler(int in_irq, void *d) - unsigned long pending; - unsigned int bit; - -- pending = readl(fpga->base + FPGA_IRQ_SET_CLR) & fpga->irq_mask; -- for_each_set_bit(bit, &pending, CPLDS_NB_IRQ) -- generic_handle_irq(irq_find_mapping(fpga->irqdomain, bit)); -+ do { -+ pending = readl(fpga->base + FPGA_IRQ_SET_CLR) & fpga->irq_mask; -+ for_each_set_bit(bit, &pending, CPLDS_NB_IRQ) { -+ generic_handle_irq(irq_find_mapping(fpga->irqdomain, -+ bit)); -+ } -+ } while (pending); - - return IRQ_HANDLED; - } - --static void cplds_irq_mask_ack(struct irq_data *d) -+static void cplds_irq_mask(struct irq_data *d) - { - struct cplds *fpga = irq_data_get_irq_chip_data(d); - unsigned int cplds_irq = irqd_to_hwirq(d); -- unsigned int set, bit = BIT(cplds_irq); -+ unsigned int bit = BIT(cplds_irq); - - fpga->irq_mask &= ~bit; - writel(fpga->irq_mask, fpga->base + FPGA_IRQ_MASK_EN); -- set = readl(fpga->base + FPGA_IRQ_SET_CLR); -- writel(set & ~bit, fpga->base + FPGA_IRQ_SET_CLR); - } - - static void cplds_irq_unmask(struct irq_data *d) - { - struct cplds *fpga = irq_data_get_irq_chip_data(d); - unsigned int cplds_irq = irqd_to_hwirq(d); -- unsigned int bit = BIT(cplds_irq); -+ unsigned int set, bit = BIT(cplds_irq); -+ -+ set = readl(fpga->base + FPGA_IRQ_SET_CLR); -+ writel(set & ~bit, fpga->base + FPGA_IRQ_SET_CLR); - - fpga->irq_mask |= bit; - writel(fpga->irq_mask, fpga->base + FPGA_IRQ_MASK_EN); -@@ -72,7 +77,8 @@ static void cplds_irq_unmask(struct irq_data *d) - - static struct irq_chip cplds_irq_chip = { - .name = "pxa_cplds", -- .irq_mask_ack = cplds_irq_mask_ack, -+ .irq_ack = cplds_irq_mask, -+ .irq_mask = cplds_irq_mask, - .irq_unmask = cplds_irq_unmask, - .flags = IRQCHIP_MASK_ON_SUSPEND | IRQCHIP_SKIP_SET_WAKE, - }; -diff --git a/arch/arm/mach-pxa/sharpsl_pm.c b/arch/arm/mach-pxa/sharpsl_pm.c -index b80eab9..249b7bd 100644 ---- a/arch/arm/mach-pxa/sharpsl_pm.c -+++ b/arch/arm/mach-pxa/sharpsl_pm.c -@@ -744,7 +744,7 @@ static int sharpsl_off_charge_battery(void) - time = RCNR; - while (1) { - /* Check if any wakeup event had occurred */ -- if (sharpsl_pm.machinfo->charger_wakeup() != 0) -+ if (sharpsl_pm.machinfo->charger_wakeup()) - return 0; - /* Check for timeout */ - if ((RCNR - time) > SHARPSL_WAIT_CO_TIME) -diff --git a/arch/arm/mach-pxa/sharpsl_pm.h b/arch/arm/mach-pxa/sharpsl_pm.h -index 905be67..fa75b6d 100644 ---- a/arch/arm/mach-pxa/sharpsl_pm.h -+++ b/arch/arm/mach-pxa/sharpsl_pm.h -@@ -34,7 +34,7 @@ struct sharpsl_charger_machinfo { - #define SHARPSL_STATUS_LOCK 5 - #define SHARPSL_STATUS_CHRGFULL 6 - #define SHARPSL_STATUS_FATAL 7 -- unsigned long (*charger_wakeup)(void); -+ bool (*charger_wakeup)(void); - int (*should_wakeup)(unsigned int resume_on_alarm); - void (*backlight_limit)(int); - int (*backlight_get_status) (void); -diff --git a/arch/arm/mach-pxa/spitz_pm.c b/arch/arm/mach-pxa/spitz_pm.c -index ea9f903..4e64a14 100644 ---- a/arch/arm/mach-pxa/spitz_pm.c -+++ b/arch/arm/mach-pxa/spitz_pm.c -@@ -165,13 +165,10 @@ static int spitz_should_wakeup(unsigned int resume_on_alarm) - return is_resume; - } - --static unsigned long spitz_charger_wakeup(void) -+static bool spitz_charger_wakeup(void) - { -- unsigned long ret; -- ret = ((!gpio_get_value(SPITZ_GPIO_KEY_INT) -- << GPIO_bit(SPITZ_GPIO_KEY_INT)) -- | gpio_get_value(SPITZ_GPIO_SYNC)); -- return ret; -+ return !gpio_get_value(SPITZ_GPIO_KEY_INT) || -+ gpio_get_value(SPITZ_GPIO_SYNC); - } - - unsigned long spitzpm_read_devdata(int type) -diff --git a/arch/powerpc/include/asm/book3s/64/pgtable.h b/arch/powerpc/include/asm/book3s/64/pgtable.h -index 263bf39..9bd84ba 100644 ---- a/arch/powerpc/include/asm/book3s/64/pgtable.h -+++ b/arch/powerpc/include/asm/book3s/64/pgtable.h -@@ -6,6 +6,8 @@ - */ - #define _PAGE_BIT_SWAP_TYPE 0 - -+#define _PAGE_RO 0 -+ - #define _PAGE_EXEC 0x00001 /* execute permission */ - #define _PAGE_WRITE 0x00002 /* write access allowed */ - #define _PAGE_READ 0x00004 /* read access allowed */ -diff --git a/arch/powerpc/kernel/nvram_64.c b/arch/powerpc/kernel/nvram_64.c -index 64174bf..05a0a91 100644 ---- a/arch/powerpc/kernel/nvram_64.c -+++ b/arch/powerpc/kernel/nvram_64.c -@@ -956,7 +956,7 @@ int __init nvram_remove_partition(const char *name, int sig, - - /* Make partition a free partition */ - part->header.signature = NVRAM_SIG_FREE; -- strncpy(part->header.name, "wwwwwwwwwwww", 12); -+ memset(part->header.name, 'w', 12); - part->header.checksum = nvram_checksum(&part->header); - rc = nvram_write_header(part); - if (rc <= 0) { -@@ -974,8 +974,8 @@ int __init nvram_remove_partition(const char *name, int sig, - } - if (prev) { - prev->header.length += part->header.length; -- prev->header.checksum = nvram_checksum(&part->header); -- rc = nvram_write_header(part); -+ prev->header.checksum = nvram_checksum(&prev->header); -+ rc = nvram_write_header(prev); - if (rc <= 0) { - printk(KERN_ERR "nvram_remove_partition: nvram_write failed (%d)\n", rc); - return rc; -diff --git a/arch/powerpc/kernel/process.c b/arch/powerpc/kernel/process.c -index 9ee2623..ad37aa1 100644 ---- a/arch/powerpc/kernel/process.c -+++ b/arch/powerpc/kernel/process.c -@@ -88,7 +88,13 @@ static void check_if_tm_restore_required(struct task_struct *tsk) - set_thread_flag(TIF_RESTORE_TM); - } - } -+ -+static inline bool msr_tm_active(unsigned long msr) -+{ -+ return MSR_TM_ACTIVE(msr); -+} - #else -+static inline bool msr_tm_active(unsigned long msr) { return false; } - static inline void check_if_tm_restore_required(struct task_struct *tsk) { } - #endif /* CONFIG_PPC_TRANSACTIONAL_MEM */ - -@@ -208,7 +214,7 @@ void enable_kernel_fp(void) - EXPORT_SYMBOL(enable_kernel_fp); - - static int restore_fp(struct task_struct *tsk) { -- if (tsk->thread.load_fp) { -+ if (tsk->thread.load_fp || msr_tm_active(tsk->thread.regs->msr)) { - load_fp_state(¤t->thread.fp_state); - current->thread.load_fp++; - return 1; -@@ -278,7 +284,8 @@ EXPORT_SYMBOL_GPL(flush_altivec_to_thread); - - static int restore_altivec(struct task_struct *tsk) - { -- if (cpu_has_feature(CPU_FTR_ALTIVEC) && tsk->thread.load_vec) { -+ if (cpu_has_feature(CPU_FTR_ALTIVEC) && -+ (tsk->thread.load_vec || msr_tm_active(tsk->thread.regs->msr))) { - load_vr_state(&tsk->thread.vr_state); - tsk->thread.used_vr = 1; - tsk->thread.load_vec++; -@@ -438,6 +445,7 @@ void giveup_all(struct task_struct *tsk) - return; - - msr_check_and_set(msr_all_available); -+ check_if_tm_restore_required(tsk); - - #ifdef CONFIG_PPC_FPU - if (usermsr & MSR_FP) -@@ -464,7 +472,8 @@ void restore_math(struct pt_regs *regs) - { - unsigned long msr; - -- if (!current->thread.load_fp && !loadvec(current->thread)) -+ if (!msr_tm_active(regs->msr) && -+ !current->thread.load_fp && !loadvec(current->thread)) - return; - - msr = regs->msr; -@@ -983,6 +992,13 @@ void restore_tm_state(struct pt_regs *regs) - msr_diff = current->thread.ckpt_regs.msr & ~regs->msr; - msr_diff &= MSR_FP | MSR_VEC | MSR_VSX; - -+ /* Ensure that restore_math() will restore */ -+ if (msr_diff & MSR_FP) -+ current->thread.load_fp = 1; -+#ifdef CONFIG_ALIVEC -+ if (cpu_has_feature(CPU_FTR_ALTIVEC) && msr_diff & MSR_VEC) -+ current->thread.load_vec = 1; -+#endif - restore_math(regs); - - regs->msr |= msr_diff; -diff --git a/arch/powerpc/mm/hugetlbpage.c b/arch/powerpc/mm/hugetlbpage.c -index 7372ee1..a5d3ecd 100644 ---- a/arch/powerpc/mm/hugetlbpage.c -+++ b/arch/powerpc/mm/hugetlbpage.c -@@ -1019,8 +1019,15 @@ int gup_hugepte(pte_t *ptep, unsigned long sz, unsigned long addr, - - pte = READ_ONCE(*ptep); - mask = _PAGE_PRESENT | _PAGE_READ; -+ -+ /* -+ * On some CPUs like the 8xx, _PAGE_RW hence _PAGE_WRITE is defined -+ * as 0 and _PAGE_RO has to be set when a page is not writable -+ */ - if (write) - mask |= _PAGE_WRITE; -+ else -+ mask |= _PAGE_RO; - - if ((pte_val(pte) & mask) != mask) - return 0; -diff --git a/arch/x86/kernel/early-quirks.c b/arch/x86/kernel/early-quirks.c -index de7501e..8b8852b 100644 ---- a/arch/x86/kernel/early-quirks.c -+++ b/arch/x86/kernel/early-quirks.c -@@ -317,16 +317,11 @@ static phys_addr_t __init i85x_stolen_base(int num, int slot, int func, - static phys_addr_t __init i865_stolen_base(int num, int slot, int func, - size_t stolen_size) - { -- u16 toud; -+ u16 toud = 0; - -- /* -- * FIXME is the graphics stolen memory region -- * always at TOUD? Ie. is it always the last -- * one to be allocated by the BIOS? -- */ - toud = read_pci_config_16(0, 0, 0, I865_TOUD); - -- return (phys_addr_t)toud << 16; -+ return (phys_addr_t)(toud << 16) + i845_tseg_size(); - } - - static phys_addr_t __init gen3_stolen_base(int num, int slot, int func, -diff --git a/crypto/gcm.c b/crypto/gcm.c -index 70a892e8..f624ac9 100644 ---- a/crypto/gcm.c -+++ b/crypto/gcm.c -@@ -117,7 +117,7 @@ static int crypto_gcm_setkey(struct crypto_aead *aead, const u8 *key, - struct crypto_skcipher *ctr = ctx->ctr; - struct { - be128 hash; -- u8 iv[8]; -+ u8 iv[16]; - - struct crypto_gcm_setkey_result result; - -diff --git a/drivers/char/hw_random/omap-rng.c b/drivers/char/hw_random/omap-rng.c -index 01d4be2..f5c26a5 100644 ---- a/drivers/char/hw_random/omap-rng.c -+++ b/drivers/char/hw_random/omap-rng.c -@@ -385,7 +385,7 @@ static int omap_rng_probe(struct platform_device *pdev) - - pm_runtime_enable(&pdev->dev); - ret = pm_runtime_get_sync(&pdev->dev); -- if (ret) { -+ if (ret < 0) { - dev_err(&pdev->dev, "Failed to runtime_get device: %d\n", ret); - pm_runtime_put_noidle(&pdev->dev); - goto err_ioremap; -@@ -443,7 +443,7 @@ static int __maybe_unused omap_rng_resume(struct device *dev) - int ret; - - ret = pm_runtime_get_sync(dev); -- if (ret) { -+ if (ret < 0) { - dev_err(dev, "Failed to runtime_get device: %d\n", ret); - pm_runtime_put_noidle(dev); - return ret; -diff --git a/drivers/clk/bcm/clk-bcm2835.c b/drivers/clk/bcm/clk-bcm2835.c -index 7a79708..0fc71cb 100644 ---- a/drivers/clk/bcm/clk-bcm2835.c -+++ b/drivers/clk/bcm/clk-bcm2835.c -@@ -1006,16 +1006,28 @@ static int bcm2835_clock_set_rate(struct clk_hw *hw, - return 0; - } - -+static bool -+bcm2835_clk_is_pllc(struct clk_hw *hw) -+{ -+ if (!hw) -+ return false; -+ -+ return strncmp(clk_hw_get_name(hw), "pllc", 4) == 0; -+} -+ - static int bcm2835_clock_determine_rate(struct clk_hw *hw, - struct clk_rate_request *req) - { - struct bcm2835_clock *clock = bcm2835_clock_from_hw(hw); - struct clk_hw *parent, *best_parent = NULL; -+ bool current_parent_is_pllc; - unsigned long rate, best_rate = 0; - unsigned long prate, best_prate = 0; - size_t i; - u32 div; - -+ current_parent_is_pllc = bcm2835_clk_is_pllc(clk_hw_get_parent(hw)); -+ - /* - * Select parent clock that results in the closest but lower rate - */ -@@ -1023,6 +1035,17 @@ static int bcm2835_clock_determine_rate(struct clk_hw *hw, - parent = clk_hw_get_parent_by_index(hw, i); - if (!parent) - continue; -+ -+ /* -+ * Don't choose a PLLC-derived clock as our parent -+ * unless it had been manually set that way. PLLC's -+ * frequency gets adjusted by the firmware due to -+ * over-temp or under-voltage conditions, without -+ * prior notification to our clock consumer. -+ */ -+ if (bcm2835_clk_is_pllc(parent) && !current_parent_is_pllc) -+ continue; -+ - prate = clk_hw_get_rate(parent); - div = bcm2835_clock_choose_div(hw, req->rate, prate, true); - rate = bcm2835_clock_rate_from_divisor(clock, prate, div); -diff --git a/drivers/clk/clk-divider.c b/drivers/clk/clk-divider.c -index a0f55bc..96386ff 100644 ---- a/drivers/clk/clk-divider.c -+++ b/drivers/clk/clk-divider.c -@@ -352,7 +352,7 @@ static long clk_divider_round_rate(struct clk_hw *hw, unsigned long rate, - - /* if read only, just return current value */ - if (divider->flags & CLK_DIVIDER_READ_ONLY) { -- bestdiv = readl(divider->reg) >> divider->shift; -+ bestdiv = clk_readl(divider->reg) >> divider->shift; - bestdiv &= div_mask(divider->width); - bestdiv = _get_div(divider->table, bestdiv, divider->flags, - divider->width); -diff --git a/drivers/clk/clk-qoriq.c b/drivers/clk/clk-qoriq.c -index 58566a17..20b1055 100644 ---- a/drivers/clk/clk-qoriq.c -+++ b/drivers/clk/clk-qoriq.c -@@ -766,7 +766,11 @@ static struct clk * __init create_one_cmux(struct clockgen *cg, int idx) - if (!hwc) - return NULL; - -- hwc->reg = cg->regs + 0x20 * idx; -+ if (cg->info.flags & CG_VER3) -+ hwc->reg = cg->regs + 0x70000 + 0x20 * idx; -+ else -+ hwc->reg = cg->regs + 0x20 * idx; -+ - hwc->info = cg->info.cmux_groups[cg->info.cmux_to_group[idx]]; - - /* -diff --git a/drivers/clk/clk.c b/drivers/clk/clk.c -index 820a939..2877a4d 100644 ---- a/drivers/clk/clk.c -+++ b/drivers/clk/clk.c -@@ -1908,10 +1908,6 @@ int clk_set_phase(struct clk *clk, int degrees) - - clk_prepare_lock(); - -- /* bail early if nothing to do */ -- if (degrees == clk->core->phase) -- goto out; -- - trace_clk_set_phase(clk->core, degrees); - - if (clk->core->ops->set_phase) -@@ -1922,7 +1918,6 @@ int clk_set_phase(struct clk *clk, int degrees) - if (!ret) - clk->core->phase = degrees; - --out: - clk_prepare_unlock(); - - return ret; -@@ -3186,7 +3181,7 @@ struct clk *__of_clk_get_from_provider(struct of_phandle_args *clkspec, - { - struct of_clk_provider *provider; - struct clk *clk = ERR_PTR(-EPROBE_DEFER); -- struct clk_hw *hw = ERR_PTR(-EPROBE_DEFER); -+ struct clk_hw *hw; - - if (!clkspec) - return ERR_PTR(-EINVAL); -@@ -3194,12 +3189,13 @@ struct clk *__of_clk_get_from_provider(struct of_phandle_args *clkspec, - /* Check if we have such a provider in our array */ - mutex_lock(&of_clk_mutex); - list_for_each_entry(provider, &of_clk_providers, link) { -- if (provider->node == clkspec->np) -+ if (provider->node == clkspec->np) { - hw = __of_clk_get_hw_from_provider(provider, clkspec); -- if (!IS_ERR(hw)) { - clk = __clk_create_clk(hw, dev_id, con_id); -+ } - -- if (!IS_ERR(clk) && !__clk_get(clk)) { -+ if (!IS_ERR(clk)) { -+ if (!__clk_get(clk)) { - __clk_free_clk(clk); - clk = ERR_PTR(-ENOENT); - } -diff --git a/drivers/clk/imx/clk-imx35.c b/drivers/clk/imx/clk-imx35.c -index b0978d3..d302ed3 100644 ---- a/drivers/clk/imx/clk-imx35.c -+++ b/drivers/clk/imx/clk-imx35.c -@@ -115,7 +115,7 @@ static void __init _mx35_clocks_init(void) - } - - clk[ckih] = imx_clk_fixed("ckih", 24000000); -- clk[ckil] = imx_clk_fixed("ckih", 32768); -+ clk[ckil] = imx_clk_fixed("ckil", 32768); - clk[mpll] = imx_clk_pllv1(IMX_PLLV1_IMX35, "mpll", "ckih", base + MX35_CCM_MPCTL); - clk[ppll] = imx_clk_pllv1(IMX_PLLV1_IMX35, "ppll", "ckih", base + MX35_CCM_PPCTL); - -diff --git a/drivers/clk/qcom/Kconfig b/drivers/clk/qcom/Kconfig -index 95e3b3e..98909b1 100644 ---- a/drivers/clk/qcom/Kconfig -+++ b/drivers/clk/qcom/Kconfig -@@ -117,6 +117,7 @@ config MSM_MMCC_8974 - - config MSM_GCC_8996 - tristate "MSM8996 Global Clock Controller" -+ select QCOM_GDSC - depends on COMMON_CLK_QCOM - help - Support for the global clock controller on msm8996 devices. -@@ -126,6 +127,7 @@ config MSM_GCC_8996 - config MSM_MMCC_8996 - tristate "MSM8996 Multimedia Clock Controller" - select MSM_GCC_8996 -+ select QCOM_GDSC - depends on COMMON_CLK_QCOM - help - Support for the multimedia clock controller on msm8996 devices. -diff --git a/drivers/clk/qcom/gcc-msm8996.c b/drivers/clk/qcom/gcc-msm8996.c -index bbf732b..9f643cc 100644 ---- a/drivers/clk/qcom/gcc-msm8996.c -+++ b/drivers/clk/qcom/gcc-msm8996.c -@@ -2592,9 +2592,9 @@ static struct clk_branch gcc_pcie_2_aux_clk = { - }; - - static struct clk_branch gcc_pcie_2_pipe_clk = { -- .halt_reg = 0x6e108, -+ .halt_reg = 0x6e018, - .clkr = { -- .enable_reg = 0x6e108, -+ .enable_reg = 0x6e018, - .enable_mask = BIT(0), - .hw.init = &(struct clk_init_data){ - .name = "gcc_pcie_2_pipe_clk", -diff --git a/drivers/crypto/ccp/ccp-dmaengine.c b/drivers/crypto/ccp/ccp-dmaengine.c -index 94f77b0..32f645e 100644 ---- a/drivers/crypto/ccp/ccp-dmaengine.c -+++ b/drivers/crypto/ccp/ccp-dmaengine.c -@@ -650,7 +650,7 @@ int ccp_dmaengine_register(struct ccp_device *ccp) - dma_desc_cache_name = devm_kasprintf(ccp->dev, GFP_KERNEL, - "%s-dmaengine-desc-cache", - ccp->name); -- if (!dma_cmd_cache_name) -+ if (!dma_desc_cache_name) - return -ENOMEM; - ccp->dma_desc_cache = kmem_cache_create(dma_desc_cache_name, - sizeof(struct ccp_dma_desc), -diff --git a/drivers/crypto/marvell/cesa.c b/drivers/crypto/marvell/cesa.c -index d64af86..37dadb2 100644 ---- a/drivers/crypto/marvell/cesa.c -+++ b/drivers/crypto/marvell/cesa.c -@@ -166,6 +166,7 @@ static irqreturn_t mv_cesa_int(int irq, void *priv) - if (!req) - break; - -+ ctx = crypto_tfm_ctx(req->tfm); - mv_cesa_complete_req(ctx, req, 0); - } - } -diff --git a/drivers/crypto/marvell/hash.c b/drivers/crypto/marvell/hash.c -index 82e0f4e6..b111e14 100644 ---- a/drivers/crypto/marvell/hash.c -+++ b/drivers/crypto/marvell/hash.c -@@ -805,13 +805,14 @@ static int mv_cesa_md5_init(struct ahash_request *req) - struct mv_cesa_op_ctx tmpl = { }; - - mv_cesa_set_op_cfg(&tmpl, CESA_SA_DESC_CFG_MACM_MD5); -+ -+ mv_cesa_ahash_init(req, &tmpl, true); -+ - creq->state[0] = MD5_H0; - creq->state[1] = MD5_H1; - creq->state[2] = MD5_H2; - creq->state[3] = MD5_H3; - -- mv_cesa_ahash_init(req, &tmpl, true); -- - return 0; - } - -@@ -873,14 +874,15 @@ static int mv_cesa_sha1_init(struct ahash_request *req) - struct mv_cesa_op_ctx tmpl = { }; - - mv_cesa_set_op_cfg(&tmpl, CESA_SA_DESC_CFG_MACM_SHA1); -+ -+ mv_cesa_ahash_init(req, &tmpl, false); -+ - creq->state[0] = SHA1_H0; - creq->state[1] = SHA1_H1; - creq->state[2] = SHA1_H2; - creq->state[3] = SHA1_H3; - creq->state[4] = SHA1_H4; - -- mv_cesa_ahash_init(req, &tmpl, false); -- - return 0; - } - -@@ -942,6 +944,9 @@ static int mv_cesa_sha256_init(struct ahash_request *req) - struct mv_cesa_op_ctx tmpl = { }; - - mv_cesa_set_op_cfg(&tmpl, CESA_SA_DESC_CFG_MACM_SHA256); -+ -+ mv_cesa_ahash_init(req, &tmpl, false); -+ - creq->state[0] = SHA256_H0; - creq->state[1] = SHA256_H1; - creq->state[2] = SHA256_H2; -@@ -951,8 +956,6 @@ static int mv_cesa_sha256_init(struct ahash_request *req) - creq->state[6] = SHA256_H6; - creq->state[7] = SHA256_H7; - -- mv_cesa_ahash_init(req, &tmpl, false); -- - return 0; - } - -diff --git a/drivers/dma/ipu/ipu_irq.c b/drivers/dma/ipu/ipu_irq.c -index 2bf37e6..dd184b5 100644 ---- a/drivers/dma/ipu/ipu_irq.c -+++ b/drivers/dma/ipu/ipu_irq.c -@@ -286,22 +286,21 @@ static void ipu_irq_handler(struct irq_desc *desc) - raw_spin_unlock(&bank_lock); - while ((line = ffs(status))) { - struct ipu_irq_map *map; -- unsigned int irq = NO_IRQ; -+ unsigned int irq; - - line--; - status &= ~(1UL << line); - - raw_spin_lock(&bank_lock); - map = src2map(32 * i + line); -- if (map) -- irq = map->irq; -- raw_spin_unlock(&bank_lock); -- - if (!map) { -+ raw_spin_unlock(&bank_lock); - pr_err("IPU: Interrupt on unmapped source %u bank %d\n", - line, i); - continue; - } -+ irq = map->irq; -+ raw_spin_unlock(&bank_lock); - generic_handle_irq(irq); - } - } -diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_ctx.c b/drivers/gpu/drm/amd/amdgpu/amdgpu_ctx.c -index 17e1362..4e71a68 100644 ---- a/drivers/gpu/drm/amd/amdgpu/amdgpu_ctx.c -+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_ctx.c -@@ -43,6 +43,9 @@ static int amdgpu_ctx_init(struct amdgpu_device *adev, struct amdgpu_ctx *ctx) - ctx->rings[i].sequence = 1; - ctx->rings[i].fences = &ctx->fences[amdgpu_sched_jobs * i]; - } -+ -+ ctx->reset_counter = atomic_read(&adev->gpu_reset_counter); -+ - /* create context entity for each ring */ - for (i = 0; i < adev->num_rings; i++) { - struct amdgpu_ring *ring = adev->rings[i]; -diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_dpm.c b/drivers/gpu/drm/amd/amdgpu/amdgpu_dpm.c -index fe36caf..14f57d9 100644 ---- a/drivers/gpu/drm/amd/amdgpu/amdgpu_dpm.c -+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_dpm.c -@@ -113,24 +113,26 @@ void amdgpu_dpm_print_ps_status(struct amdgpu_device *adev, - printk("\n"); - } - -+ - u32 amdgpu_dpm_get_vblank_time(struct amdgpu_device *adev) - { - struct drm_device *dev = adev->ddev; - struct drm_crtc *crtc; - struct amdgpu_crtc *amdgpu_crtc; -- u32 line_time_us, vblank_lines; -+ u32 vblank_in_pixels; - u32 vblank_time_us = 0xffffffff; /* if the displays are off, vblank time is max */ - - if (adev->mode_info.num_crtc && adev->mode_info.mode_config_initialized) { - list_for_each_entry(crtc, &dev->mode_config.crtc_list, head) { - amdgpu_crtc = to_amdgpu_crtc(crtc); - if (crtc->enabled && amdgpu_crtc->enabled && amdgpu_crtc->hw_mode.clock) { -- line_time_us = (amdgpu_crtc->hw_mode.crtc_htotal * 1000) / -- amdgpu_crtc->hw_mode.clock; -- vblank_lines = amdgpu_crtc->hw_mode.crtc_vblank_end - -+ vblank_in_pixels = -+ amdgpu_crtc->hw_mode.crtc_htotal * -+ (amdgpu_crtc->hw_mode.crtc_vblank_end - - amdgpu_crtc->hw_mode.crtc_vdisplay + -- (amdgpu_crtc->v_border * 2); -- vblank_time_us = vblank_lines * line_time_us; -+ (amdgpu_crtc->v_border * 2)); -+ -+ vblank_time_us = vblank_in_pixels * 1000 / amdgpu_crtc->hw_mode.clock; - break; - } - } -diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_kms.c b/drivers/gpu/drm/amd/amdgpu/amdgpu_kms.c -index d942654..e24a8af 100644 ---- a/drivers/gpu/drm/amd/amdgpu/amdgpu_kms.c -+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_kms.c -@@ -292,7 +292,7 @@ static int amdgpu_info_ioctl(struct drm_device *dev, void *data, struct drm_file - type = AMD_IP_BLOCK_TYPE_UVD; - ring_mask = adev->uvd.ring.ready ? 1 : 0; - ib_start_alignment = AMDGPU_GPU_PAGE_SIZE; -- ib_size_alignment = 8; -+ ib_size_alignment = 16; - break; - case AMDGPU_HW_IP_VCE: - type = AMD_IP_BLOCK_TYPE_VCE; -diff --git a/drivers/gpu/drm/amd/amdgpu/dce_v10_0.c b/drivers/gpu/drm/amd/amdgpu/dce_v10_0.c -index c1b04e9..172bed9 100644 ---- a/drivers/gpu/drm/amd/amdgpu/dce_v10_0.c -+++ b/drivers/gpu/drm/amd/amdgpu/dce_v10_0.c -@@ -425,16 +425,6 @@ static void dce_v10_0_hpd_init(struct amdgpu_device *adev) - list_for_each_entry(connector, &dev->mode_config.connector_list, head) { - struct amdgpu_connector *amdgpu_connector = to_amdgpu_connector(connector); - -- if (connector->connector_type == DRM_MODE_CONNECTOR_eDP || -- connector->connector_type == DRM_MODE_CONNECTOR_LVDS) { -- /* don't try to enable hpd on eDP or LVDS avoid breaking the -- * aux dp channel on imac and help (but not completely fix) -- * https://bugzilla.redhat.com/show_bug.cgi?id=726143 -- * also avoid interrupt storms during dpms. -- */ -- continue; -- } -- - switch (amdgpu_connector->hpd.hpd) { - case AMDGPU_HPD_1: - idx = 0; -@@ -458,6 +448,19 @@ static void dce_v10_0_hpd_init(struct amdgpu_device *adev) - continue; - } - -+ if (connector->connector_type == DRM_MODE_CONNECTOR_eDP || -+ connector->connector_type == DRM_MODE_CONNECTOR_LVDS) { -+ /* don't try to enable hpd on eDP or LVDS avoid breaking the -+ * aux dp channel on imac and help (but not completely fix) -+ * https://bugzilla.redhat.com/show_bug.cgi?id=726143 -+ * also avoid interrupt storms during dpms. -+ */ -+ tmp = RREG32(mmDC_HPD_INT_CONTROL + hpd_offsets[idx]); -+ tmp = REG_SET_FIELD(tmp, DC_HPD_INT_CONTROL, DC_HPD_INT_EN, 0); -+ WREG32(mmDC_HPD_INT_CONTROL + hpd_offsets[idx], tmp); -+ continue; -+ } -+ - tmp = RREG32(mmDC_HPD_CONTROL + hpd_offsets[idx]); - tmp = REG_SET_FIELD(tmp, DC_HPD_CONTROL, DC_HPD_EN, 1); - WREG32(mmDC_HPD_CONTROL + hpd_offsets[idx], tmp); -diff --git a/drivers/gpu/drm/amd/amdgpu/dce_v11_0.c b/drivers/gpu/drm/amd/amdgpu/dce_v11_0.c -index d4bf133..67c7c05 100644 ---- a/drivers/gpu/drm/amd/amdgpu/dce_v11_0.c -+++ b/drivers/gpu/drm/amd/amdgpu/dce_v11_0.c -@@ -443,16 +443,6 @@ static void dce_v11_0_hpd_init(struct amdgpu_device *adev) - list_for_each_entry(connector, &dev->mode_config.connector_list, head) { - struct amdgpu_connector *amdgpu_connector = to_amdgpu_connector(connector); - -- if (connector->connector_type == DRM_MODE_CONNECTOR_eDP || -- connector->connector_type == DRM_MODE_CONNECTOR_LVDS) { -- /* don't try to enable hpd on eDP or LVDS avoid breaking the -- * aux dp channel on imac and help (but not completely fix) -- * https://bugzilla.redhat.com/show_bug.cgi?id=726143 -- * also avoid interrupt storms during dpms. -- */ -- continue; -- } -- - switch (amdgpu_connector->hpd.hpd) { - case AMDGPU_HPD_1: - idx = 0; -@@ -476,6 +466,19 @@ static void dce_v11_0_hpd_init(struct amdgpu_device *adev) - continue; - } - -+ if (connector->connector_type == DRM_MODE_CONNECTOR_eDP || -+ connector->connector_type == DRM_MODE_CONNECTOR_LVDS) { -+ /* don't try to enable hpd on eDP or LVDS avoid breaking the -+ * aux dp channel on imac and help (but not completely fix) -+ * https://bugzilla.redhat.com/show_bug.cgi?id=726143 -+ * also avoid interrupt storms during dpms. -+ */ -+ tmp = RREG32(mmDC_HPD_INT_CONTROL + hpd_offsets[idx]); -+ tmp = REG_SET_FIELD(tmp, DC_HPD_INT_CONTROL, DC_HPD_INT_EN, 0); -+ WREG32(mmDC_HPD_INT_CONTROL + hpd_offsets[idx], tmp); -+ continue; -+ } -+ - tmp = RREG32(mmDC_HPD_CONTROL + hpd_offsets[idx]); - tmp = REG_SET_FIELD(tmp, DC_HPD_CONTROL, DC_HPD_EN, 1); - WREG32(mmDC_HPD_CONTROL + hpd_offsets[idx], tmp); -@@ -3109,6 +3112,7 @@ static int dce_v11_0_sw_fini(void *handle) - - dce_v11_0_afmt_fini(adev); - -+ drm_mode_config_cleanup(adev->ddev); - adev->mode_info.mode_config_initialized = false; - - return 0; -diff --git a/drivers/gpu/drm/amd/amdgpu/dce_v8_0.c b/drivers/gpu/drm/amd/amdgpu/dce_v8_0.c -index 4fdfab1..ea07c50 100644 ---- a/drivers/gpu/drm/amd/amdgpu/dce_v8_0.c -+++ b/drivers/gpu/drm/amd/amdgpu/dce_v8_0.c -@@ -395,15 +395,6 @@ static void dce_v8_0_hpd_init(struct amdgpu_device *adev) - list_for_each_entry(connector, &dev->mode_config.connector_list, head) { - struct amdgpu_connector *amdgpu_connector = to_amdgpu_connector(connector); - -- if (connector->connector_type == DRM_MODE_CONNECTOR_eDP || -- connector->connector_type == DRM_MODE_CONNECTOR_LVDS) { -- /* don't try to enable hpd on eDP or LVDS avoid breaking the -- * aux dp channel on imac and help (but not completely fix) -- * https://bugzilla.redhat.com/show_bug.cgi?id=726143 -- * also avoid interrupt storms during dpms. -- */ -- continue; -- } - switch (amdgpu_connector->hpd.hpd) { - case AMDGPU_HPD_1: - WREG32(mmDC_HPD1_CONTROL, tmp); -@@ -426,6 +417,45 @@ static void dce_v8_0_hpd_init(struct amdgpu_device *adev) - default: - break; - } -+ -+ if (connector->connector_type == DRM_MODE_CONNECTOR_eDP || -+ connector->connector_type == DRM_MODE_CONNECTOR_LVDS) { -+ /* don't try to enable hpd on eDP or LVDS avoid breaking the -+ * aux dp channel on imac and help (but not completely fix) -+ * https://bugzilla.redhat.com/show_bug.cgi?id=726143 -+ * also avoid interrupt storms during dpms. -+ */ -+ u32 dc_hpd_int_cntl_reg, dc_hpd_int_cntl; -+ -+ switch (amdgpu_connector->hpd.hpd) { -+ case AMDGPU_HPD_1: -+ dc_hpd_int_cntl_reg = mmDC_HPD1_INT_CONTROL; -+ break; -+ case AMDGPU_HPD_2: -+ dc_hpd_int_cntl_reg = mmDC_HPD2_INT_CONTROL; -+ break; -+ case AMDGPU_HPD_3: -+ dc_hpd_int_cntl_reg = mmDC_HPD3_INT_CONTROL; -+ break; -+ case AMDGPU_HPD_4: -+ dc_hpd_int_cntl_reg = mmDC_HPD4_INT_CONTROL; -+ break; -+ case AMDGPU_HPD_5: -+ dc_hpd_int_cntl_reg = mmDC_HPD5_INT_CONTROL; -+ break; -+ case AMDGPU_HPD_6: -+ dc_hpd_int_cntl_reg = mmDC_HPD6_INT_CONTROL; -+ break; -+ default: -+ continue; -+ } -+ -+ dc_hpd_int_cntl = RREG32(dc_hpd_int_cntl_reg); -+ dc_hpd_int_cntl &= ~DC_HPD1_INT_CONTROL__DC_HPD1_INT_EN_MASK; -+ WREG32(dc_hpd_int_cntl_reg, dc_hpd_int_cntl); -+ continue; -+ } -+ - dce_v8_0_hpd_set_polarity(adev, amdgpu_connector->hpd.hpd); - amdgpu_irq_get(adev, &adev->hpd_irq, amdgpu_connector->hpd.hpd); - } -diff --git a/drivers/gpu/drm/amd/powerplay/eventmgr/eventactionchains.c b/drivers/gpu/drm/amd/powerplay/eventmgr/eventactionchains.c -index 635fc4b..92b1178 100644 ---- a/drivers/gpu/drm/amd/powerplay/eventmgr/eventactionchains.c -+++ b/drivers/gpu/drm/amd/powerplay/eventmgr/eventactionchains.c -@@ -262,6 +262,8 @@ static const pem_event_action * const display_config_change_event[] = { - unblock_adjust_power_state_tasks, - set_cpu_power_state, - notify_hw_power_source_tasks, -+ get_2d_performance_state_tasks, -+ set_performance_state_tasks, - /* updateDALConfigurationTasks, - variBrightDisplayConfigurationChangeTasks, */ - adjust_power_state_tasks, -diff --git a/drivers/gpu/drm/amd/powerplay/eventmgr/psm.c b/drivers/gpu/drm/amd/powerplay/eventmgr/psm.c -index a46225c..d6bee72 100644 ---- a/drivers/gpu/drm/amd/powerplay/eventmgr/psm.c -+++ b/drivers/gpu/drm/amd/powerplay/eventmgr/psm.c -@@ -100,11 +100,12 @@ int psm_adjust_power_state_dynamic(struct pp_eventmgr *eventmgr, bool skip) - if (requested == NULL) - return 0; - -+ phm_apply_state_adjust_rules(hwmgr, requested, pcurrent); -+ - if (pcurrent == NULL || (0 != phm_check_states_equal(hwmgr, &pcurrent->hardware, &requested->hardware, &equal))) - equal = false; - - if (!equal || phm_check_smc_update_required_for_display_configuration(hwmgr)) { -- phm_apply_state_adjust_rules(hwmgr, requested, pcurrent); - phm_set_power_state(hwmgr, &pcurrent->hardware, &requested->hardware); - hwmgr->current_ps = requested; - } -diff --git a/drivers/gpu/drm/drm_prime.c b/drivers/gpu/drm/drm_prime.c -index 780589b..9c4387d 100644 ---- a/drivers/gpu/drm/drm_prime.c -+++ b/drivers/gpu/drm/drm_prime.c -@@ -335,14 +335,17 @@ static const struct dma_buf_ops drm_gem_prime_dmabuf_ops = { - * using the PRIME helpers. - */ - struct dma_buf *drm_gem_prime_export(struct drm_device *dev, -- struct drm_gem_object *obj, int flags) -+ struct drm_gem_object *obj, -+ int flags) - { -- DEFINE_DMA_BUF_EXPORT_INFO(exp_info); -- -- exp_info.ops = &drm_gem_prime_dmabuf_ops; -- exp_info.size = obj->size; -- exp_info.flags = flags; -- exp_info.priv = obj; -+ struct dma_buf_export_info exp_info = { -+ .exp_name = KBUILD_MODNAME, /* white lie for debug */ -+ .owner = dev->driver->fops->owner, -+ .ops = &drm_gem_prime_dmabuf_ops, -+ .size = obj->size, -+ .flags = flags, -+ .priv = obj, -+ }; - - if (dev->driver->gem_prime_res_obj) - exp_info.resv = dev->driver->gem_prime_res_obj(obj); -diff --git a/drivers/gpu/drm/fsl-dcu/fsl_dcu_drm_drv.c b/drivers/gpu/drm/fsl-dcu/fsl_dcu_drm_drv.c -index 7882387..5fc8ebd 100644 ---- a/drivers/gpu/drm/fsl-dcu/fsl_dcu_drm_drv.c -+++ b/drivers/gpu/drm/fsl-dcu/fsl_dcu_drm_drv.c -@@ -330,6 +330,7 @@ static int fsl_dcu_drm_probe(struct platform_device *pdev) - const char *pix_clk_in_name; - const struct of_device_id *id; - int ret; -+ u8 div_ratio_shift = 0; - - fsl_dev = devm_kzalloc(dev, sizeof(*fsl_dev), GFP_KERNEL); - if (!fsl_dev) -@@ -382,11 +383,14 @@ static int fsl_dcu_drm_probe(struct platform_device *pdev) - pix_clk_in = fsl_dev->clk; - } - -+ if (of_property_read_bool(dev->of_node, "big-endian")) -+ div_ratio_shift = 24; -+ - pix_clk_in_name = __clk_get_name(pix_clk_in); - snprintf(pix_clk_name, sizeof(pix_clk_name), "%s_pix", pix_clk_in_name); - fsl_dev->pix_clk = clk_register_divider(dev, pix_clk_name, - pix_clk_in_name, 0, base + DCU_DIV_RATIO, -- 0, 8, CLK_DIVIDER_ROUND_CLOSEST, NULL); -+ div_ratio_shift, 8, CLK_DIVIDER_ROUND_CLOSEST, NULL); - if (IS_ERR(fsl_dev->pix_clk)) { - dev_err(dev, "failed to register pix clk\n"); - ret = PTR_ERR(fsl_dev->pix_clk); -diff --git a/drivers/gpu/drm/i915/i915_drv.h b/drivers/gpu/drm/i915/i915_drv.h -index f68c789..84a0010 100644 ---- a/drivers/gpu/drm/i915/i915_drv.h -+++ b/drivers/gpu/drm/i915/i915_drv.h -@@ -631,6 +631,8 @@ struct drm_i915_display_funcs { - struct intel_crtc_state *crtc_state); - void (*crtc_enable)(struct drm_crtc *crtc); - void (*crtc_disable)(struct drm_crtc *crtc); -+ void (*update_crtcs)(struct drm_atomic_state *state, -+ unsigned int *crtc_vblank_mask); - void (*audio_codec_enable)(struct drm_connector *connector, - struct intel_encoder *encoder, - const struct drm_display_mode *adjusted_mode); -@@ -1965,11 +1967,11 @@ struct drm_i915_private { - struct vlv_s0ix_state vlv_s0ix_state; - - enum { -- I915_SKL_SAGV_UNKNOWN = 0, -- I915_SKL_SAGV_DISABLED, -- I915_SKL_SAGV_ENABLED, -- I915_SKL_SAGV_NOT_CONTROLLED -- } skl_sagv_status; -+ I915_SAGV_UNKNOWN = 0, -+ I915_SAGV_DISABLED, -+ I915_SAGV_ENABLED, -+ I915_SAGV_NOT_CONTROLLED -+ } sagv_status; - - struct { - /* -@@ -2280,21 +2282,19 @@ struct drm_i915_gem_object { - /** Record of address bit 17 of each page at last unbind. */ - unsigned long *bit_17; - -- union { -- /** for phy allocated objects */ -- struct drm_dma_handle *phys_handle; -- -- struct i915_gem_userptr { -- uintptr_t ptr; -- unsigned read_only :1; -- unsigned workers :4; -+ struct i915_gem_userptr { -+ uintptr_t ptr; -+ unsigned read_only :1; -+ unsigned workers :4; - #define I915_GEM_USERPTR_MAX_WORKERS 15 - -- struct i915_mm_struct *mm; -- struct i915_mmu_object *mmu_object; -- struct work_struct *work; -- } userptr; -- }; -+ struct i915_mm_struct *mm; -+ struct i915_mmu_object *mmu_object; -+ struct work_struct *work; -+ } userptr; -+ -+ /** for phys allocated objects */ -+ struct drm_dma_handle *phys_handle; - }; - #define to_intel_bo(x) container_of(x, struct drm_i915_gem_object, base) - -diff --git a/drivers/gpu/drm/i915/i915_gem_stolen.c b/drivers/gpu/drm/i915/i915_gem_stolen.c -index 66be299a1..2bb69f3 100644 ---- a/drivers/gpu/drm/i915/i915_gem_stolen.c -+++ b/drivers/gpu/drm/i915/i915_gem_stolen.c -@@ -115,17 +115,28 @@ static unsigned long i915_stolen_to_physical(struct drm_device *dev) - - base = bsm & INTEL_BSM_MASK; - } else if (IS_I865G(dev)) { -+ u32 tseg_size = 0; - u16 toud = 0; -+ u8 tmp; -+ -+ pci_bus_read_config_byte(dev->pdev->bus, PCI_DEVFN(0, 0), -+ I845_ESMRAMC, &tmp); -+ -+ if (tmp & TSEG_ENABLE) { -+ switch (tmp & I845_TSEG_SIZE_MASK) { -+ case I845_TSEG_SIZE_512K: -+ tseg_size = KB(512); -+ break; -+ case I845_TSEG_SIZE_1M: -+ tseg_size = MB(1); -+ break; -+ } -+ } - -- /* -- * FIXME is the graphics stolen memory region -- * always at TOUD? Ie. is it always the last -- * one to be allocated by the BIOS? -- */ - pci_bus_read_config_word(dev->pdev->bus, PCI_DEVFN(0, 0), - I865_TOUD, &toud); - -- base = toud << 16; -+ base = (toud << 16) + tseg_size; - } else if (IS_I85X(dev)) { - u32 tseg_size = 0; - u32 tom; -diff --git a/drivers/gpu/drm/i915/intel_display.c b/drivers/gpu/drm/i915/intel_display.c -index 175595f..e9a64fb 100644 ---- a/drivers/gpu/drm/i915/intel_display.c -+++ b/drivers/gpu/drm/i915/intel_display.c -@@ -2980,6 +2980,7 @@ static void skylake_update_primary_plane(struct drm_plane *plane, - struct intel_crtc *intel_crtc = to_intel_crtc(crtc_state->base.crtc); - struct drm_framebuffer *fb = plane_state->base.fb; - struct drm_i915_gem_object *obj = intel_fb_obj(fb); -+ const struct skl_wm_values *wm = &dev_priv->wm.skl_results; - int pipe = intel_crtc->pipe; - u32 plane_ctl, stride_div, stride; - u32 tile_height, plane_offset, plane_size; -@@ -3031,6 +3032,9 @@ static void skylake_update_primary_plane(struct drm_plane *plane, - intel_crtc->adjusted_x = x_offset; - intel_crtc->adjusted_y = y_offset; - -+ if (wm->dirty_pipes & drm_crtc_mask(&intel_crtc->base)) -+ skl_write_plane_wm(intel_crtc, wm, 0); -+ - I915_WRITE(PLANE_CTL(pipe, 0), plane_ctl); - I915_WRITE(PLANE_OFFSET(pipe, 0), plane_offset); - I915_WRITE(PLANE_SIZE(pipe, 0), plane_size); -@@ -3061,7 +3065,15 @@ static void skylake_disable_primary_plane(struct drm_plane *primary, - { - struct drm_device *dev = crtc->dev; - struct drm_i915_private *dev_priv = to_i915(dev); -- int pipe = to_intel_crtc(crtc)->pipe; -+ struct intel_crtc *intel_crtc = to_intel_crtc(crtc); -+ int pipe = intel_crtc->pipe; -+ -+ /* -+ * We only populate skl_results on watermark updates, and if the -+ * plane's visiblity isn't actually changing neither is its watermarks. -+ */ -+ if (!to_intel_plane_state(crtc->primary->state)->visible) -+ skl_write_plane_wm(intel_crtc, &dev_priv->wm.skl_results, 0); - - I915_WRITE(PLANE_CTL(pipe, 0), 0); - I915_WRITE(PLANE_SURF(pipe, 0), 0); -@@ -8995,6 +9007,24 @@ static void ironlake_compute_dpll(struct intel_crtc *intel_crtc, - if (intel_crtc_has_dp_encoder(crtc_state)) - dpll |= DPLL_SDVO_HIGH_SPEED; - -+ /* -+ * The high speed IO clock is only really required for -+ * SDVO/HDMI/DP, but we also enable it for CRT to make it -+ * possible to share the DPLL between CRT and HDMI. Enabling -+ * the clock needlessly does no real harm, except use up a -+ * bit of power potentially. -+ * -+ * We'll limit this to IVB with 3 pipes, since it has only two -+ * DPLLs and so DPLL sharing is the only way to get three pipes -+ * driving PCH ports at the same time. On SNB we could do this, -+ * and potentially avoid enabling the second DPLL, but it's not -+ * clear if it''s a win or loss power wise. No point in doing -+ * this on ILK at all since it has a fixed DPLL<->pipe mapping. -+ */ -+ if (INTEL_INFO(dev_priv)->num_pipes == 3 && -+ intel_crtc_has_type(crtc_state, INTEL_OUTPUT_ANALOG)) -+ dpll |= DPLL_SDVO_HIGH_SPEED; -+ - /* compute bitmask from p1 value */ - dpll |= (1 << (crtc_state->dpll.p1 - 1)) << DPLL_FPA01_P1_POST_DIV_SHIFT; - /* also FPA1 */ -@@ -10306,9 +10336,13 @@ static void i9xx_update_cursor(struct drm_crtc *crtc, u32 base, - struct drm_device *dev = crtc->dev; - struct drm_i915_private *dev_priv = to_i915(dev); - struct intel_crtc *intel_crtc = to_intel_crtc(crtc); -+ const struct skl_wm_values *wm = &dev_priv->wm.skl_results; - int pipe = intel_crtc->pipe; - uint32_t cntl = 0; - -+ if (INTEL_GEN(dev_priv) >= 9 && wm->dirty_pipes & drm_crtc_mask(crtc)) -+ skl_write_cursor_wm(intel_crtc, wm); -+ - if (plane_state && plane_state->visible) { - cntl = MCURSOR_GAMMA_ENABLE; - switch (plane_state->base.crtc_w) { -@@ -12956,16 +12990,23 @@ static void verify_wm_state(struct drm_crtc *crtc, - hw_entry->start, hw_entry->end); - } - -- /* cursor */ -- hw_entry = &hw_ddb.plane[pipe][PLANE_CURSOR]; -- sw_entry = &sw_ddb->plane[pipe][PLANE_CURSOR]; -- -- if (!skl_ddb_entry_equal(hw_entry, sw_entry)) { -- DRM_ERROR("mismatch in DDB state pipe %c cursor " -- "(expected (%u,%u), found (%u,%u))\n", -- pipe_name(pipe), -- sw_entry->start, sw_entry->end, -- hw_entry->start, hw_entry->end); -+ /* -+ * cursor -+ * If the cursor plane isn't active, we may not have updated it's ddb -+ * allocation. In that case since the ddb allocation will be updated -+ * once the plane becomes visible, we can skip this check -+ */ -+ if (intel_crtc->cursor_addr) { -+ hw_entry = &hw_ddb.plane[pipe][PLANE_CURSOR]; -+ sw_entry = &sw_ddb->plane[pipe][PLANE_CURSOR]; -+ -+ if (!skl_ddb_entry_equal(hw_entry, sw_entry)) { -+ DRM_ERROR("mismatch in DDB state pipe %c cursor " -+ "(expected (%u,%u), found (%u,%u))\n", -+ pipe_name(pipe), -+ sw_entry->start, sw_entry->end, -+ hw_entry->start, hw_entry->end); -+ } - } - } - -@@ -13671,6 +13712,111 @@ static bool needs_vblank_wait(struct intel_crtc_state *crtc_state) - return false; - } - -+static void intel_update_crtc(struct drm_crtc *crtc, -+ struct drm_atomic_state *state, -+ struct drm_crtc_state *old_crtc_state, -+ unsigned int *crtc_vblank_mask) -+{ -+ struct drm_device *dev = crtc->dev; -+ struct drm_i915_private *dev_priv = to_i915(dev); -+ struct intel_crtc *intel_crtc = to_intel_crtc(crtc); -+ struct intel_crtc_state *pipe_config = to_intel_crtc_state(crtc->state); -+ bool modeset = needs_modeset(crtc->state); -+ -+ if (modeset) { -+ update_scanline_offset(intel_crtc); -+ dev_priv->display.crtc_enable(crtc); -+ } else { -+ intel_pre_plane_update(to_intel_crtc_state(old_crtc_state)); -+ } -+ -+ if (drm_atomic_get_existing_plane_state(state, crtc->primary)) { -+ intel_fbc_enable( -+ intel_crtc, pipe_config, -+ to_intel_plane_state(crtc->primary->state)); -+ } -+ -+ drm_atomic_helper_commit_planes_on_crtc(old_crtc_state); -+ -+ if (needs_vblank_wait(pipe_config)) -+ *crtc_vblank_mask |= drm_crtc_mask(crtc); -+} -+ -+static void intel_update_crtcs(struct drm_atomic_state *state, -+ unsigned int *crtc_vblank_mask) -+{ -+ struct drm_crtc *crtc; -+ struct drm_crtc_state *old_crtc_state; -+ int i; -+ -+ for_each_crtc_in_state(state, crtc, old_crtc_state, i) { -+ if (!crtc->state->active) -+ continue; -+ -+ intel_update_crtc(crtc, state, old_crtc_state, -+ crtc_vblank_mask); -+ } -+} -+ -+static void skl_update_crtcs(struct drm_atomic_state *state, -+ unsigned int *crtc_vblank_mask) -+{ -+ struct drm_device *dev = state->dev; -+ struct drm_i915_private *dev_priv = to_i915(dev); -+ struct intel_atomic_state *intel_state = to_intel_atomic_state(state); -+ struct drm_crtc *crtc; -+ struct drm_crtc_state *old_crtc_state; -+ struct skl_ddb_allocation *new_ddb = &intel_state->wm_results.ddb; -+ struct skl_ddb_allocation *cur_ddb = &dev_priv->wm.skl_hw.ddb; -+ unsigned int updated = 0; -+ bool progress; -+ enum pipe pipe; -+ -+ /* -+ * Whenever the number of active pipes changes, we need to make sure we -+ * update the pipes in the right order so that their ddb allocations -+ * never overlap with eachother inbetween CRTC updates. Otherwise we'll -+ * cause pipe underruns and other bad stuff. -+ */ -+ do { -+ int i; -+ progress = false; -+ -+ for_each_crtc_in_state(state, crtc, old_crtc_state, i) { -+ bool vbl_wait = false; -+ unsigned int cmask = drm_crtc_mask(crtc); -+ pipe = to_intel_crtc(crtc)->pipe; -+ -+ if (updated & cmask || !crtc->state->active) -+ continue; -+ if (skl_ddb_allocation_overlaps(state, cur_ddb, new_ddb, -+ pipe)) -+ continue; -+ -+ updated |= cmask; -+ -+ /* -+ * If this is an already active pipe, it's DDB changed, -+ * and this isn't the last pipe that needs updating -+ * then we need to wait for a vblank to pass for the -+ * new ddb allocation to take effect. -+ */ -+ if (!skl_ddb_allocation_equals(cur_ddb, new_ddb, pipe) && -+ !crtc->state->active_changed && -+ intel_state->wm_results.dirty_pipes != updated) -+ vbl_wait = true; -+ -+ intel_update_crtc(crtc, state, old_crtc_state, -+ crtc_vblank_mask); -+ -+ if (vbl_wait) -+ intel_wait_for_vblank(dev, pipe); -+ -+ progress = true; -+ } -+ } while (progress); -+} -+ - static void intel_atomic_commit_tail(struct drm_atomic_state *state) - { - struct drm_device *dev = state->dev; -@@ -13763,23 +13909,15 @@ static void intel_atomic_commit_tail(struct drm_atomic_state *state) - * SKL workaround: bspec recommends we disable the SAGV when we - * have more then one pipe enabled - */ -- if (IS_SKYLAKE(dev_priv) && !skl_can_enable_sagv(state)) -- skl_disable_sagv(dev_priv); -+ if (!intel_can_enable_sagv(state)) -+ intel_disable_sagv(dev_priv); - - intel_modeset_verify_disabled(dev); - } - -- /* Now enable the clocks, plane, pipe, and connectors that we set up. */ -+ /* Complete the events for pipes that have now been disabled */ - for_each_crtc_in_state(state, crtc, old_crtc_state, i) { -- struct intel_crtc *intel_crtc = to_intel_crtc(crtc); - bool modeset = needs_modeset(crtc->state); -- struct intel_crtc_state *pipe_config = -- to_intel_crtc_state(crtc->state); -- -- if (modeset && crtc->state->active) { -- update_scanline_offset(to_intel_crtc(crtc)); -- dev_priv->display.crtc_enable(crtc); -- } - - /* Complete events for now disable pipes here. */ - if (modeset && !crtc->state->active && crtc->state->event) { -@@ -13789,21 +13927,11 @@ static void intel_atomic_commit_tail(struct drm_atomic_state *state) - - crtc->state->event = NULL; - } -- -- if (!modeset) -- intel_pre_plane_update(to_intel_crtc_state(old_crtc_state)); -- -- if (crtc->state->active && -- drm_atomic_get_existing_plane_state(state, crtc->primary)) -- intel_fbc_enable(intel_crtc, pipe_config, to_intel_plane_state(crtc->primary->state)); -- -- if (crtc->state->active) -- drm_atomic_helper_commit_planes_on_crtc(old_crtc_state); -- -- if (pipe_config->base.active && needs_vblank_wait(pipe_config)) -- crtc_vblank_mask |= 1 << i; - } - -+ /* Now enable the clocks, plane, pipe, and connectors that we set up. */ -+ dev_priv->display.update_crtcs(state, &crtc_vblank_mask); -+ - /* FIXME: We should call drm_atomic_helper_commit_hw_done() here - * already, but still need the state for the delayed optimization. To - * fix this: -@@ -13839,9 +13967,8 @@ static void intel_atomic_commit_tail(struct drm_atomic_state *state) - intel_modeset_verify_crtc(crtc, old_crtc_state, crtc->state); - } - -- if (IS_SKYLAKE(dev_priv) && intel_state->modeset && -- skl_can_enable_sagv(state)) -- skl_enable_sagv(dev_priv); -+ if (intel_state->modeset && intel_can_enable_sagv(state)) -+ intel_enable_sagv(dev_priv); - - drm_atomic_helper_commit_hw_done(state); - -@@ -14221,10 +14348,12 @@ static void intel_begin_crtc_commit(struct drm_crtc *crtc, - struct drm_crtc_state *old_crtc_state) - { - struct drm_device *dev = crtc->dev; -+ struct drm_i915_private *dev_priv = to_i915(dev); - struct intel_crtc *intel_crtc = to_intel_crtc(crtc); - struct intel_crtc_state *old_intel_state = - to_intel_crtc_state(old_crtc_state); - bool modeset = needs_modeset(crtc->state); -+ enum pipe pipe = intel_crtc->pipe; - - /* Perform vblank evasion around commit operation */ - intel_pipe_update_start(intel_crtc); -@@ -14239,8 +14368,12 @@ static void intel_begin_crtc_commit(struct drm_crtc *crtc, - - if (to_intel_crtc_state(crtc->state)->update_pipe) - intel_update_pipe_config(intel_crtc, old_intel_state); -- else if (INTEL_INFO(dev)->gen >= 9) -+ else if (INTEL_GEN(dev_priv) >= 9) { - skl_detach_scalers(intel_crtc); -+ -+ I915_WRITE(PIPE_WM_LINETIME(pipe), -+ dev_priv->wm.skl_hw.wm_linetime[pipe]); -+ } - } - - static void intel_finish_crtc_commit(struct drm_crtc *crtc, -@@ -15347,6 +15480,11 @@ void intel_init_display_hooks(struct drm_i915_private *dev_priv) - skl_modeset_calc_cdclk; - } - -+ if (dev_priv->info.gen >= 9) -+ dev_priv->display.update_crtcs = skl_update_crtcs; -+ else -+ dev_priv->display.update_crtcs = intel_update_crtcs; -+ - switch (INTEL_INFO(dev_priv)->gen) { - case 2: - dev_priv->display.queue_flip = intel_gen2_queue_flip; -diff --git a/drivers/gpu/drm/i915/intel_dp.c b/drivers/gpu/drm/i915/intel_dp.c -index 21b04c3..1ca155f 100644 ---- a/drivers/gpu/drm/i915/intel_dp.c -+++ b/drivers/gpu/drm/i915/intel_dp.c -@@ -4148,7 +4148,7 @@ static bool bxt_digital_port_connected(struct drm_i915_private *dev_priv, - * - * Return %true if @port is connected, %false otherwise. - */ --bool intel_digital_port_connected(struct drm_i915_private *dev_priv, -+static bool intel_digital_port_connected(struct drm_i915_private *dev_priv, - struct intel_digital_port *port) - { - if (HAS_PCH_IBX(dev_priv)) -@@ -4207,7 +4207,7 @@ intel_dp_unset_edid(struct intel_dp *intel_dp) - intel_dp->has_audio = false; - } - --static void -+static enum drm_connector_status - intel_dp_long_pulse(struct intel_connector *intel_connector) - { - struct drm_connector *connector = &intel_connector->base; -@@ -4232,7 +4232,7 @@ intel_dp_long_pulse(struct intel_connector *intel_connector) - else - status = connector_status_disconnected; - -- if (status != connector_status_connected) { -+ if (status == connector_status_disconnected) { - intel_dp->compliance_test_active = 0; - intel_dp->compliance_test_type = 0; - intel_dp->compliance_test_data = 0; -@@ -4284,8 +4284,8 @@ intel_dp_long_pulse(struct intel_connector *intel_connector) - intel_dp->aux.i2c_defer_count = 0; - - intel_dp_set_edid(intel_dp); -- -- status = connector_status_connected; -+ if (is_edp(intel_dp) || intel_connector->detect_edid) -+ status = connector_status_connected; - intel_dp->detect_done = true; - - /* Try to read the source of the interrupt */ -@@ -4303,12 +4303,11 @@ intel_dp_long_pulse(struct intel_connector *intel_connector) - } - - out: -- if ((status != connector_status_connected) && -- (intel_dp->is_mst == false)) -+ if (status != connector_status_connected && !intel_dp->is_mst) - intel_dp_unset_edid(intel_dp); - - intel_display_power_put(to_i915(dev), power_domain); -- return; -+ return status; - } - - static enum drm_connector_status -@@ -4317,7 +4316,7 @@ intel_dp_detect(struct drm_connector *connector, bool force) - struct intel_dp *intel_dp = intel_attached_dp(connector); - struct intel_digital_port *intel_dig_port = dp_to_dig_port(intel_dp); - struct intel_encoder *intel_encoder = &intel_dig_port->base; -- struct intel_connector *intel_connector = to_intel_connector(connector); -+ enum drm_connector_status status = connector->status; - - DRM_DEBUG_KMS("[CONNECTOR:%d:%s]\n", - connector->base.id, connector->name); -@@ -4332,14 +4331,11 @@ intel_dp_detect(struct drm_connector *connector, bool force) - - /* If full detect is not performed yet, do a full detect */ - if (!intel_dp->detect_done) -- intel_dp_long_pulse(intel_dp->attached_connector); -+ status = intel_dp_long_pulse(intel_dp->attached_connector); - - intel_dp->detect_done = false; - -- if (is_edp(intel_dp) || intel_connector->detect_edid) -- return connector_status_connected; -- else -- return connector_status_disconnected; -+ return status; - } - - static void -@@ -4696,36 +4692,34 @@ intel_dp_hpd_pulse(struct intel_digital_port *intel_dig_port, bool long_hpd) - port_name(intel_dig_port->port), - long_hpd ? "long" : "short"); - -+ if (long_hpd) { -+ intel_dp->detect_done = false; -+ return IRQ_NONE; -+ } -+ - power_domain = intel_display_port_aux_power_domain(intel_encoder); - intel_display_power_get(dev_priv, power_domain); - -- if (long_hpd) { -- intel_dp_long_pulse(intel_dp->attached_connector); -- if (intel_dp->is_mst) -- ret = IRQ_HANDLED; -- goto put_power; -- -- } else { -- if (intel_dp->is_mst) { -- if (intel_dp_check_mst_status(intel_dp) == -EINVAL) { -- /* -- * If we were in MST mode, and device is not -- * there, get out of MST mode -- */ -- DRM_DEBUG_KMS("MST device may have disappeared %d vs %d\n", -- intel_dp->is_mst, intel_dp->mst_mgr.mst_state); -- intel_dp->is_mst = false; -- drm_dp_mst_topology_mgr_set_mst(&intel_dp->mst_mgr, -- intel_dp->is_mst); -- goto put_power; -- } -+ if (intel_dp->is_mst) { -+ if (intel_dp_check_mst_status(intel_dp) == -EINVAL) { -+ /* -+ * If we were in MST mode, and device is not -+ * there, get out of MST mode -+ */ -+ DRM_DEBUG_KMS("MST device may have disappeared %d vs %d\n", -+ intel_dp->is_mst, intel_dp->mst_mgr.mst_state); -+ intel_dp->is_mst = false; -+ drm_dp_mst_topology_mgr_set_mst(&intel_dp->mst_mgr, -+ intel_dp->is_mst); -+ intel_dp->detect_done = false; -+ goto put_power; - } -+ } - -- if (!intel_dp->is_mst) { -- if (!intel_dp_short_pulse(intel_dp)) { -- intel_dp_long_pulse(intel_dp->attached_connector); -- goto put_power; -- } -+ if (!intel_dp->is_mst) { -+ if (!intel_dp_short_pulse(intel_dp)) { -+ intel_dp->detect_done = false; -+ goto put_power; - } - } - -diff --git a/drivers/gpu/drm/i915/intel_drv.h b/drivers/gpu/drm/i915/intel_drv.h -index ff399b9..9a58800 100644 ---- a/drivers/gpu/drm/i915/intel_drv.h -+++ b/drivers/gpu/drm/i915/intel_drv.h -@@ -236,6 +236,7 @@ struct intel_panel { - bool enabled; - bool combination_mode; /* gen 2/4 only */ - bool active_low_pwm; -+ bool alternate_pwm_increment; /* lpt+ */ - - /* PWM chip */ - bool util_pin_active_low; /* bxt+ */ -@@ -1387,8 +1388,6 @@ void intel_edp_drrs_disable(struct intel_dp *intel_dp); - void intel_edp_drrs_invalidate(struct drm_device *dev, - unsigned frontbuffer_bits); - void intel_edp_drrs_flush(struct drm_device *dev, unsigned frontbuffer_bits); --bool intel_digital_port_connected(struct drm_i915_private *dev_priv, -- struct intel_digital_port *port); - - void - intel_dp_program_link_training_pattern(struct intel_dp *intel_dp, -@@ -1716,9 +1715,21 @@ void ilk_wm_get_hw_state(struct drm_device *dev); - void skl_wm_get_hw_state(struct drm_device *dev); - void skl_ddb_get_hw_state(struct drm_i915_private *dev_priv, - struct skl_ddb_allocation *ddb /* out */); --bool skl_can_enable_sagv(struct drm_atomic_state *state); --int skl_enable_sagv(struct drm_i915_private *dev_priv); --int skl_disable_sagv(struct drm_i915_private *dev_priv); -+bool intel_can_enable_sagv(struct drm_atomic_state *state); -+int intel_enable_sagv(struct drm_i915_private *dev_priv); -+int intel_disable_sagv(struct drm_i915_private *dev_priv); -+bool skl_ddb_allocation_equals(const struct skl_ddb_allocation *old, -+ const struct skl_ddb_allocation *new, -+ enum pipe pipe); -+bool skl_ddb_allocation_overlaps(struct drm_atomic_state *state, -+ const struct skl_ddb_allocation *old, -+ const struct skl_ddb_allocation *new, -+ enum pipe pipe); -+void skl_write_cursor_wm(struct intel_crtc *intel_crtc, -+ const struct skl_wm_values *wm); -+void skl_write_plane_wm(struct intel_crtc *intel_crtc, -+ const struct skl_wm_values *wm, -+ int plane); - uint32_t ilk_pipe_pixel_rate(const struct intel_crtc_state *pipe_config); - bool ilk_disable_lp_wm(struct drm_device *dev); - int sanitize_rc6_option(struct drm_i915_private *dev_priv, int enable_rc6); -diff --git a/drivers/gpu/drm/i915/intel_hdmi.c b/drivers/gpu/drm/i915/intel_hdmi.c -index 4df9f38..c3aa9e6 100644 ---- a/drivers/gpu/drm/i915/intel_hdmi.c -+++ b/drivers/gpu/drm/i915/intel_hdmi.c -@@ -1422,24 +1422,22 @@ intel_hdmi_dp_dual_mode_detect(struct drm_connector *connector, bool has_edid) - } - - static bool --intel_hdmi_set_edid(struct drm_connector *connector, bool force) -+intel_hdmi_set_edid(struct drm_connector *connector) - { - struct drm_i915_private *dev_priv = to_i915(connector->dev); - struct intel_hdmi *intel_hdmi = intel_attached_hdmi(connector); -- struct edid *edid = NULL; -+ struct edid *edid; - bool connected = false; - -- if (force) { -- intel_display_power_get(dev_priv, POWER_DOMAIN_GMBUS); -+ intel_display_power_get(dev_priv, POWER_DOMAIN_GMBUS); - -- edid = drm_get_edid(connector, -- intel_gmbus_get_adapter(dev_priv, -- intel_hdmi->ddc_bus)); -+ edid = drm_get_edid(connector, -+ intel_gmbus_get_adapter(dev_priv, -+ intel_hdmi->ddc_bus)); - -- intel_hdmi_dp_dual_mode_detect(connector, edid != NULL); -+ intel_hdmi_dp_dual_mode_detect(connector, edid != NULL); - -- intel_display_power_put(dev_priv, POWER_DOMAIN_GMBUS); -- } -+ intel_display_power_put(dev_priv, POWER_DOMAIN_GMBUS); - - to_intel_connector(connector)->detect_edid = edid; - if (edid && edid->input & DRM_EDID_INPUT_DIGITAL) { -@@ -1465,37 +1463,16 @@ static enum drm_connector_status - intel_hdmi_detect(struct drm_connector *connector, bool force) - { - enum drm_connector_status status; -- struct intel_hdmi *intel_hdmi = intel_attached_hdmi(connector); - struct drm_i915_private *dev_priv = to_i915(connector->dev); -- bool live_status = false; -- unsigned int try; - - DRM_DEBUG_KMS("[CONNECTOR:%d:%s]\n", - connector->base.id, connector->name); - - intel_display_power_get(dev_priv, POWER_DOMAIN_GMBUS); - -- for (try = 0; !live_status && try < 9; try++) { -- if (try) -- msleep(10); -- live_status = intel_digital_port_connected(dev_priv, -- hdmi_to_dig_port(intel_hdmi)); -- } -- -- if (!live_status) { -- DRM_DEBUG_KMS("HDMI live status down\n"); -- /* -- * Live status register is not reliable on all intel platforms. -- * So consider live_status only for certain platforms, for -- * others, read EDID to determine presence of sink. -- */ -- if (INTEL_INFO(dev_priv)->gen < 7 || IS_IVYBRIDGE(dev_priv)) -- live_status = true; -- } -- - intel_hdmi_unset_edid(connector); - -- if (intel_hdmi_set_edid(connector, live_status)) { -+ if (intel_hdmi_set_edid(connector)) { - struct intel_hdmi *intel_hdmi = intel_attached_hdmi(connector); - - hdmi_to_dig_port(intel_hdmi)->base.type = INTEL_OUTPUT_HDMI; -@@ -1521,7 +1498,7 @@ intel_hdmi_force(struct drm_connector *connector) - if (connector->status != connector_status_connected) - return; - -- intel_hdmi_set_edid(connector, true); -+ intel_hdmi_set_edid(connector); - hdmi_to_dig_port(intel_hdmi)->base.type = INTEL_OUTPUT_HDMI; - } - -diff --git a/drivers/gpu/drm/i915/intel_panel.c b/drivers/gpu/drm/i915/intel_panel.c -index 96c65d7..9a2393a 100644 ---- a/drivers/gpu/drm/i915/intel_panel.c -+++ b/drivers/gpu/drm/i915/intel_panel.c -@@ -841,7 +841,7 @@ static void lpt_enable_backlight(struct intel_connector *connector) - { - struct drm_i915_private *dev_priv = to_i915(connector->base.dev); - struct intel_panel *panel = &connector->panel; -- u32 pch_ctl1, pch_ctl2; -+ u32 pch_ctl1, pch_ctl2, schicken; - - pch_ctl1 = I915_READ(BLC_PWM_PCH_CTL1); - if (pch_ctl1 & BLM_PCH_PWM_ENABLE) { -@@ -850,6 +850,22 @@ static void lpt_enable_backlight(struct intel_connector *connector) - I915_WRITE(BLC_PWM_PCH_CTL1, pch_ctl1); - } - -+ if (HAS_PCH_LPT(dev_priv)) { -+ schicken = I915_READ(SOUTH_CHICKEN2); -+ if (panel->backlight.alternate_pwm_increment) -+ schicken |= LPT_PWM_GRANULARITY; -+ else -+ schicken &= ~LPT_PWM_GRANULARITY; -+ I915_WRITE(SOUTH_CHICKEN2, schicken); -+ } else { -+ schicken = I915_READ(SOUTH_CHICKEN1); -+ if (panel->backlight.alternate_pwm_increment) -+ schicken |= SPT_PWM_GRANULARITY; -+ else -+ schicken &= ~SPT_PWM_GRANULARITY; -+ I915_WRITE(SOUTH_CHICKEN1, schicken); -+ } -+ - pch_ctl2 = panel->backlight.max << 16; - I915_WRITE(BLC_PWM_PCH_CTL2, pch_ctl2); - -@@ -1242,10 +1258,10 @@ static u32 bxt_hz_to_pwm(struct intel_connector *connector, u32 pwm_freq_hz) - */ - static u32 spt_hz_to_pwm(struct intel_connector *connector, u32 pwm_freq_hz) - { -- struct drm_i915_private *dev_priv = to_i915(connector->base.dev); -+ struct intel_panel *panel = &connector->panel; - u32 mul; - -- if (I915_READ(SOUTH_CHICKEN1) & SPT_PWM_GRANULARITY) -+ if (panel->backlight.alternate_pwm_increment) - mul = 128; - else - mul = 16; -@@ -1261,9 +1277,10 @@ static u32 spt_hz_to_pwm(struct intel_connector *connector, u32 pwm_freq_hz) - static u32 lpt_hz_to_pwm(struct intel_connector *connector, u32 pwm_freq_hz) - { - struct drm_i915_private *dev_priv = to_i915(connector->base.dev); -+ struct intel_panel *panel = &connector->panel; - u32 mul, clock; - -- if (I915_READ(SOUTH_CHICKEN2) & LPT_PWM_GRANULARITY) -+ if (panel->backlight.alternate_pwm_increment) - mul = 16; - else - mul = 128; -@@ -1414,6 +1431,13 @@ static int lpt_setup_backlight(struct intel_connector *connector, enum pipe unus - struct drm_i915_private *dev_priv = to_i915(connector->base.dev); - struct intel_panel *panel = &connector->panel; - u32 pch_ctl1, pch_ctl2, val; -+ bool alt; -+ -+ if (HAS_PCH_LPT(dev_priv)) -+ alt = I915_READ(SOUTH_CHICKEN2) & LPT_PWM_GRANULARITY; -+ else -+ alt = I915_READ(SOUTH_CHICKEN1) & SPT_PWM_GRANULARITY; -+ panel->backlight.alternate_pwm_increment = alt; - - pch_ctl1 = I915_READ(BLC_PWM_PCH_CTL1); - panel->backlight.active_low_pwm = pch_ctl1 & BLM_PCH_POLARITY; -diff --git a/drivers/gpu/drm/i915/intel_pm.c b/drivers/gpu/drm/i915/intel_pm.c -index 2d24813..e59a28c 100644 ---- a/drivers/gpu/drm/i915/intel_pm.c -+++ b/drivers/gpu/drm/i915/intel_pm.c -@@ -2119,32 +2119,34 @@ static void intel_read_wm_latency(struct drm_device *dev, uint16_t wm[8]) - GEN9_MEM_LATENCY_LEVEL_MASK; - - /* -+ * If a level n (n > 1) has a 0us latency, all levels m (m >= n) -+ * need to be disabled. We make sure to sanitize the values out -+ * of the punit to satisfy this requirement. -+ */ -+ for (level = 1; level <= max_level; level++) { -+ if (wm[level] == 0) { -+ for (i = level + 1; i <= max_level; i++) -+ wm[i] = 0; -+ break; -+ } -+ } -+ -+ /* - * WaWmMemoryReadLatency:skl - * - * punit doesn't take into account the read latency so we need -- * to add 2us to the various latency levels we retrieve from -- * the punit. -- * - W0 is a bit special in that it's the only level that -- * can't be disabled if we want to have display working, so -- * we always add 2us there. -- * - For levels >=1, punit returns 0us latency when they are -- * disabled, so we respect that and don't add 2us then -- * -- * Additionally, if a level n (n > 1) has a 0us latency, all -- * levels m (m >= n) need to be disabled. We make sure to -- * sanitize the values out of the punit to satisfy this -- * requirement. -+ * to add 2us to the various latency levels we retrieve from the -+ * punit when level 0 response data us 0us. - */ -- wm[0] += 2; -- for (level = 1; level <= max_level; level++) -- if (wm[level] != 0) -+ if (wm[0] == 0) { -+ wm[0] += 2; -+ for (level = 1; level <= max_level; level++) { -+ if (wm[level] == 0) -+ break; - wm[level] += 2; -- else { -- for (i = level + 1; i <= max_level; i++) -- wm[i] = 0; -- -- break; - } -+ } -+ - } else if (IS_HASWELL(dev) || IS_BROADWELL(dev)) { - uint64_t sskpd = I915_READ64(MCH_SSKPD); - -@@ -2876,6 +2878,19 @@ skl_wm_plane_id(const struct intel_plane *plane) - } - } - -+static bool -+intel_has_sagv(struct drm_i915_private *dev_priv) -+{ -+ if (IS_KABYLAKE(dev_priv)) -+ return true; -+ -+ if (IS_SKYLAKE(dev_priv) && -+ dev_priv->sagv_status != I915_SAGV_NOT_CONTROLLED) -+ return true; -+ -+ return false; -+} -+ - /* - * SAGV dynamically adjusts the system agent voltage and clock frequencies - * depending on power and performance requirements. The display engine access -@@ -2888,12 +2903,14 @@ skl_wm_plane_id(const struct intel_plane *plane) - * - We're not using an interlaced display configuration - */ - int --skl_enable_sagv(struct drm_i915_private *dev_priv) -+intel_enable_sagv(struct drm_i915_private *dev_priv) - { - int ret; - -- if (dev_priv->skl_sagv_status == I915_SKL_SAGV_NOT_CONTROLLED || -- dev_priv->skl_sagv_status == I915_SKL_SAGV_ENABLED) -+ if (!intel_has_sagv(dev_priv)) -+ return 0; -+ -+ if (dev_priv->sagv_status == I915_SAGV_ENABLED) - return 0; - - DRM_DEBUG_KMS("Enabling the SAGV\n"); -@@ -2909,21 +2926,21 @@ skl_enable_sagv(struct drm_i915_private *dev_priv) - * Some skl systems, pre-release machines in particular, - * don't actually have an SAGV. - */ -- if (ret == -ENXIO) { -+ if (IS_SKYLAKE(dev_priv) && ret == -ENXIO) { - DRM_DEBUG_DRIVER("No SAGV found on system, ignoring\n"); -- dev_priv->skl_sagv_status = I915_SKL_SAGV_NOT_CONTROLLED; -+ dev_priv->sagv_status = I915_SAGV_NOT_CONTROLLED; - return 0; - } else if (ret < 0) { - DRM_ERROR("Failed to enable the SAGV\n"); - return ret; - } - -- dev_priv->skl_sagv_status = I915_SKL_SAGV_ENABLED; -+ dev_priv->sagv_status = I915_SAGV_ENABLED; - return 0; - } - - static int --skl_do_sagv_disable(struct drm_i915_private *dev_priv) -+intel_do_sagv_disable(struct drm_i915_private *dev_priv) - { - int ret; - uint32_t temp = GEN9_SAGV_DISABLE; -@@ -2937,19 +2954,21 @@ skl_do_sagv_disable(struct drm_i915_private *dev_priv) - } - - int --skl_disable_sagv(struct drm_i915_private *dev_priv) -+intel_disable_sagv(struct drm_i915_private *dev_priv) - { - int ret, result; - -- if (dev_priv->skl_sagv_status == I915_SKL_SAGV_NOT_CONTROLLED || -- dev_priv->skl_sagv_status == I915_SKL_SAGV_DISABLED) -+ if (!intel_has_sagv(dev_priv)) -+ return 0; -+ -+ if (dev_priv->sagv_status == I915_SAGV_DISABLED) - return 0; - - DRM_DEBUG_KMS("Disabling the SAGV\n"); - mutex_lock(&dev_priv->rps.hw_lock); - - /* bspec says to keep retrying for at least 1 ms */ -- ret = wait_for(result = skl_do_sagv_disable(dev_priv), 1); -+ ret = wait_for(result = intel_do_sagv_disable(dev_priv), 1); - mutex_unlock(&dev_priv->rps.hw_lock); - - if (ret == -ETIMEDOUT) { -@@ -2961,20 +2980,20 @@ skl_disable_sagv(struct drm_i915_private *dev_priv) - * Some skl systems, pre-release machines in particular, - * don't actually have an SAGV. - */ -- if (result == -ENXIO) { -+ if (IS_SKYLAKE(dev_priv) && result == -ENXIO) { - DRM_DEBUG_DRIVER("No SAGV found on system, ignoring\n"); -- dev_priv->skl_sagv_status = I915_SKL_SAGV_NOT_CONTROLLED; -+ dev_priv->sagv_status = I915_SAGV_NOT_CONTROLLED; - return 0; - } else if (result < 0) { - DRM_ERROR("Failed to disable the SAGV\n"); - return result; - } - -- dev_priv->skl_sagv_status = I915_SKL_SAGV_DISABLED; -+ dev_priv->sagv_status = I915_SAGV_DISABLED; - return 0; - } - --bool skl_can_enable_sagv(struct drm_atomic_state *state) -+bool intel_can_enable_sagv(struct drm_atomic_state *state) - { - struct drm_device *dev = state->dev; - struct drm_i915_private *dev_priv = to_i915(dev); -@@ -2983,6 +3002,9 @@ bool skl_can_enable_sagv(struct drm_atomic_state *state) - enum pipe pipe; - int level, plane; - -+ if (!intel_has_sagv(dev_priv)) -+ return false; -+ - /* - * SKL workaround: bspec recommends we disable the SAGV when we have - * more then one pipe enabled -@@ -3473,29 +3495,14 @@ static uint32_t skl_wm_method1(uint32_t pixel_rate, uint8_t cpp, uint32_t latenc - } - - static uint32_t skl_wm_method2(uint32_t pixel_rate, uint32_t pipe_htotal, -- uint32_t horiz_pixels, uint8_t cpp, -- uint64_t tiling, uint32_t latency) -+ uint32_t latency, uint32_t plane_blocks_per_line) - { - uint32_t ret; -- uint32_t plane_bytes_per_line, plane_blocks_per_line; - uint32_t wm_intermediate_val; - - if (latency == 0) - return UINT_MAX; - -- plane_bytes_per_line = horiz_pixels * cpp; -- -- if (tiling == I915_FORMAT_MOD_Y_TILED || -- tiling == I915_FORMAT_MOD_Yf_TILED) { -- plane_bytes_per_line *= 4; -- plane_blocks_per_line = DIV_ROUND_UP(plane_bytes_per_line, 512); -- plane_blocks_per_line /= 4; -- } else if (tiling == DRM_FORMAT_MOD_NONE) { -- plane_blocks_per_line = DIV_ROUND_UP(plane_bytes_per_line, 512) + 1; -- } else { -- plane_blocks_per_line = DIV_ROUND_UP(plane_bytes_per_line, 512); -- } -- - wm_intermediate_val = latency * pixel_rate; - ret = DIV_ROUND_UP(wm_intermediate_val, pipe_htotal * 1000) * - plane_blocks_per_line; -@@ -3546,6 +3553,7 @@ static int skl_compute_plane_wm(const struct drm_i915_private *dev_priv, - uint8_t cpp; - uint32_t width = 0, height = 0; - uint32_t plane_pixel_rate; -+ uint32_t y_tile_minimum, y_min_scanlines; - - if (latency == 0 || !cstate->base.active || !intel_pstate->visible) { - *enabled = false; -@@ -3561,38 +3569,51 @@ static int skl_compute_plane_wm(const struct drm_i915_private *dev_priv, - cpp = drm_format_plane_cpp(fb->pixel_format, 0); - plane_pixel_rate = skl_adjusted_plane_pixel_rate(cstate, intel_pstate); - -+ if (intel_rotation_90_or_270(pstate->rotation)) { -+ int cpp = (fb->pixel_format == DRM_FORMAT_NV12) ? -+ drm_format_plane_cpp(fb->pixel_format, 1) : -+ drm_format_plane_cpp(fb->pixel_format, 0); -+ -+ switch (cpp) { -+ case 1: -+ y_min_scanlines = 16; -+ break; -+ case 2: -+ y_min_scanlines = 8; -+ break; -+ default: -+ WARN(1, "Unsupported pixel depth for rotation"); -+ case 4: -+ y_min_scanlines = 4; -+ break; -+ } -+ } else { -+ y_min_scanlines = 4; -+ } -+ -+ plane_bytes_per_line = width * cpp; -+ if (fb->modifier[0] == I915_FORMAT_MOD_Y_TILED || -+ fb->modifier[0] == I915_FORMAT_MOD_Yf_TILED) { -+ plane_blocks_per_line = -+ DIV_ROUND_UP(plane_bytes_per_line * y_min_scanlines, 512); -+ plane_blocks_per_line /= y_min_scanlines; -+ } else if (fb->modifier[0] == DRM_FORMAT_MOD_NONE) { -+ plane_blocks_per_line = DIV_ROUND_UP(plane_bytes_per_line, 512) -+ + 1; -+ } else { -+ plane_blocks_per_line = DIV_ROUND_UP(plane_bytes_per_line, 512); -+ } -+ - method1 = skl_wm_method1(plane_pixel_rate, cpp, latency); - method2 = skl_wm_method2(plane_pixel_rate, - cstate->base.adjusted_mode.crtc_htotal, -- width, -- cpp, -- fb->modifier[0], -- latency); -+ latency, -+ plane_blocks_per_line); - -- plane_bytes_per_line = width * cpp; -- plane_blocks_per_line = DIV_ROUND_UP(plane_bytes_per_line, 512); -+ y_tile_minimum = plane_blocks_per_line * y_min_scanlines; - - if (fb->modifier[0] == I915_FORMAT_MOD_Y_TILED || - fb->modifier[0] == I915_FORMAT_MOD_Yf_TILED) { -- uint32_t min_scanlines = 4; -- uint32_t y_tile_minimum; -- if (intel_rotation_90_or_270(pstate->rotation)) { -- int cpp = (fb->pixel_format == DRM_FORMAT_NV12) ? -- drm_format_plane_cpp(fb->pixel_format, 1) : -- drm_format_plane_cpp(fb->pixel_format, 0); -- -- switch (cpp) { -- case 1: -- min_scanlines = 16; -- break; -- case 2: -- min_scanlines = 8; -- break; -- case 8: -- WARN(1, "Unsupported pixel depth for rotation"); -- } -- } -- y_tile_minimum = plane_blocks_per_line * min_scanlines; - selected_result = max(method2, y_tile_minimum); - } else { - if ((ddb_allocation / plane_blocks_per_line) >= 1) -@@ -3606,10 +3627,12 @@ static int skl_compute_plane_wm(const struct drm_i915_private *dev_priv, - - if (level >= 1 && level <= 7) { - if (fb->modifier[0] == I915_FORMAT_MOD_Y_TILED || -- fb->modifier[0] == I915_FORMAT_MOD_Yf_TILED) -- res_lines += 4; -- else -+ fb->modifier[0] == I915_FORMAT_MOD_Yf_TILED) { -+ res_blocks += y_tile_minimum; -+ res_lines += y_min_scanlines; -+ } else { - res_blocks++; -+ } - } - - if (res_blocks >= ddb_allocation || res_lines > 31) { -@@ -3828,183 +3851,82 @@ static void skl_ddb_entry_write(struct drm_i915_private *dev_priv, - I915_WRITE(reg, 0); - } - --static void skl_write_wm_values(struct drm_i915_private *dev_priv, -- const struct skl_wm_values *new) -+void skl_write_plane_wm(struct intel_crtc *intel_crtc, -+ const struct skl_wm_values *wm, -+ int plane) - { -- struct drm_device *dev = &dev_priv->drm; -- struct intel_crtc *crtc; -- -- for_each_intel_crtc(dev, crtc) { -- int i, level, max_level = ilk_wm_max_level(dev); -- enum pipe pipe = crtc->pipe; -- -- if ((new->dirty_pipes & drm_crtc_mask(&crtc->base)) == 0) -- continue; -- if (!crtc->active) -- continue; -- -- I915_WRITE(PIPE_WM_LINETIME(pipe), new->wm_linetime[pipe]); -- -- for (level = 0; level <= max_level; level++) { -- for (i = 0; i < intel_num_planes(crtc); i++) -- I915_WRITE(PLANE_WM(pipe, i, level), -- new->plane[pipe][i][level]); -- I915_WRITE(CUR_WM(pipe, level), -- new->plane[pipe][PLANE_CURSOR][level]); -- } -- for (i = 0; i < intel_num_planes(crtc); i++) -- I915_WRITE(PLANE_WM_TRANS(pipe, i), -- new->plane_trans[pipe][i]); -- I915_WRITE(CUR_WM_TRANS(pipe), -- new->plane_trans[pipe][PLANE_CURSOR]); -- -- for (i = 0; i < intel_num_planes(crtc); i++) { -- skl_ddb_entry_write(dev_priv, -- PLANE_BUF_CFG(pipe, i), -- &new->ddb.plane[pipe][i]); -- skl_ddb_entry_write(dev_priv, -- PLANE_NV12_BUF_CFG(pipe, i), -- &new->ddb.y_plane[pipe][i]); -- } -+ struct drm_crtc *crtc = &intel_crtc->base; -+ struct drm_device *dev = crtc->dev; -+ struct drm_i915_private *dev_priv = to_i915(dev); -+ int level, max_level = ilk_wm_max_level(dev); -+ enum pipe pipe = intel_crtc->pipe; - -- skl_ddb_entry_write(dev_priv, CUR_BUF_CFG(pipe), -- &new->ddb.plane[pipe][PLANE_CURSOR]); -+ for (level = 0; level <= max_level; level++) { -+ I915_WRITE(PLANE_WM(pipe, plane, level), -+ wm->plane[pipe][plane][level]); - } --} -+ I915_WRITE(PLANE_WM_TRANS(pipe, plane), wm->plane_trans[pipe][plane]); - --/* -- * When setting up a new DDB allocation arrangement, we need to correctly -- * sequence the times at which the new allocations for the pipes are taken into -- * account or we'll have pipes fetching from space previously allocated to -- * another pipe. -- * -- * Roughly the sequence looks like: -- * 1. re-allocate the pipe(s) with the allocation being reduced and not -- * overlapping with a previous light-up pipe (another way to put it is: -- * pipes with their new allocation strickly included into their old ones). -- * 2. re-allocate the other pipes that get their allocation reduced -- * 3. allocate the pipes having their allocation increased -- * -- * Steps 1. and 2. are here to take care of the following case: -- * - Initially DDB looks like this: -- * | B | C | -- * - enable pipe A. -- * - pipe B has a reduced DDB allocation that overlaps with the old pipe C -- * allocation -- * | A | B | C | -- * -- * We need to sequence the re-allocation: C, B, A (and not B, C, A). -- */ -+ skl_ddb_entry_write(dev_priv, PLANE_BUF_CFG(pipe, plane), -+ &wm->ddb.plane[pipe][plane]); -+ skl_ddb_entry_write(dev_priv, PLANE_NV12_BUF_CFG(pipe, plane), -+ &wm->ddb.y_plane[pipe][plane]); -+} - --static void --skl_wm_flush_pipe(struct drm_i915_private *dev_priv, enum pipe pipe, int pass) -+void skl_write_cursor_wm(struct intel_crtc *intel_crtc, -+ const struct skl_wm_values *wm) - { -- int plane; -- -- DRM_DEBUG_KMS("flush pipe %c (pass %d)\n", pipe_name(pipe), pass); -+ struct drm_crtc *crtc = &intel_crtc->base; -+ struct drm_device *dev = crtc->dev; -+ struct drm_i915_private *dev_priv = to_i915(dev); -+ int level, max_level = ilk_wm_max_level(dev); -+ enum pipe pipe = intel_crtc->pipe; - -- for_each_plane(dev_priv, pipe, plane) { -- I915_WRITE(PLANE_SURF(pipe, plane), -- I915_READ(PLANE_SURF(pipe, plane))); -+ for (level = 0; level <= max_level; level++) { -+ I915_WRITE(CUR_WM(pipe, level), -+ wm->plane[pipe][PLANE_CURSOR][level]); - } -- I915_WRITE(CURBASE(pipe), I915_READ(CURBASE(pipe))); -+ I915_WRITE(CUR_WM_TRANS(pipe), wm->plane_trans[pipe][PLANE_CURSOR]); -+ -+ skl_ddb_entry_write(dev_priv, CUR_BUF_CFG(pipe), -+ &wm->ddb.plane[pipe][PLANE_CURSOR]); - } - --static bool --skl_ddb_allocation_included(const struct skl_ddb_allocation *old, -- const struct skl_ddb_allocation *new, -- enum pipe pipe) -+bool skl_ddb_allocation_equals(const struct skl_ddb_allocation *old, -+ const struct skl_ddb_allocation *new, -+ enum pipe pipe) - { -- uint16_t old_size, new_size; -- -- old_size = skl_ddb_entry_size(&old->pipe[pipe]); -- new_size = skl_ddb_entry_size(&new->pipe[pipe]); -- -- return old_size != new_size && -- new->pipe[pipe].start >= old->pipe[pipe].start && -- new->pipe[pipe].end <= old->pipe[pipe].end; -+ return new->pipe[pipe].start == old->pipe[pipe].start && -+ new->pipe[pipe].end == old->pipe[pipe].end; - } - --static void skl_flush_wm_values(struct drm_i915_private *dev_priv, -- struct skl_wm_values *new_values) -+static inline bool skl_ddb_entries_overlap(const struct skl_ddb_entry *a, -+ const struct skl_ddb_entry *b) - { -- struct drm_device *dev = &dev_priv->drm; -- struct skl_ddb_allocation *cur_ddb, *new_ddb; -- bool reallocated[I915_MAX_PIPES] = {}; -- struct intel_crtc *crtc; -- enum pipe pipe; -- -- new_ddb = &new_values->ddb; -- cur_ddb = &dev_priv->wm.skl_hw.ddb; -- -- /* -- * First pass: flush the pipes with the new allocation contained into -- * the old space. -- * -- * We'll wait for the vblank on those pipes to ensure we can safely -- * re-allocate the freed space without this pipe fetching from it. -- */ -- for_each_intel_crtc(dev, crtc) { -- if (!crtc->active) -- continue; -- -- pipe = crtc->pipe; -- -- if (!skl_ddb_allocation_included(cur_ddb, new_ddb, pipe)) -- continue; -- -- skl_wm_flush_pipe(dev_priv, pipe, 1); -- intel_wait_for_vblank(dev, pipe); -- -- reallocated[pipe] = true; -- } -- -+ return a->start < b->end && b->start < a->end; -+} - -- /* -- * Second pass: flush the pipes that are having their allocation -- * reduced, but overlapping with a previous allocation. -- * -- * Here as well we need to wait for the vblank to make sure the freed -- * space is not used anymore. -- */ -- for_each_intel_crtc(dev, crtc) { -- if (!crtc->active) -- continue; -+bool skl_ddb_allocation_overlaps(struct drm_atomic_state *state, -+ const struct skl_ddb_allocation *old, -+ const struct skl_ddb_allocation *new, -+ enum pipe pipe) -+{ -+ struct drm_device *dev = state->dev; -+ struct intel_crtc *intel_crtc; -+ enum pipe otherp; - -- pipe = crtc->pipe; -+ for_each_intel_crtc(dev, intel_crtc) { -+ otherp = intel_crtc->pipe; - -- if (reallocated[pipe]) -+ if (otherp == pipe) - continue; - -- if (skl_ddb_entry_size(&new_ddb->pipe[pipe]) < -- skl_ddb_entry_size(&cur_ddb->pipe[pipe])) { -- skl_wm_flush_pipe(dev_priv, pipe, 2); -- intel_wait_for_vblank(dev, pipe); -- reallocated[pipe] = true; -- } -+ if (skl_ddb_entries_overlap(&new->pipe[pipe], -+ &old->pipe[otherp])) -+ return true; - } - -- /* -- * Third pass: flush the pipes that got more space allocated. -- * -- * We don't need to actively wait for the update here, next vblank -- * will just get more DDB space with the correct WM values. -- */ -- for_each_intel_crtc(dev, crtc) { -- if (!crtc->active) -- continue; -- -- pipe = crtc->pipe; -- -- /* -- * At this point, only the pipes more space than before are -- * left to re-allocate. -- */ -- if (reallocated[pipe]) -- continue; -- -- skl_wm_flush_pipe(dev_priv, pipe, 3); -- } -+ return false; - } - - static int skl_update_pipe_wm(struct drm_crtc_state *cstate, -@@ -4041,6 +3963,41 @@ pipes_modified(struct drm_atomic_state *state) - return ret; - } - -+int -+skl_ddb_add_affected_planes(struct intel_crtc_state *cstate) -+{ -+ struct drm_atomic_state *state = cstate->base.state; -+ struct drm_device *dev = state->dev; -+ struct drm_crtc *crtc = cstate->base.crtc; -+ struct intel_crtc *intel_crtc = to_intel_crtc(crtc); -+ struct drm_i915_private *dev_priv = to_i915(dev); -+ struct intel_atomic_state *intel_state = to_intel_atomic_state(state); -+ struct skl_ddb_allocation *new_ddb = &intel_state->wm_results.ddb; -+ struct skl_ddb_allocation *cur_ddb = &dev_priv->wm.skl_hw.ddb; -+ struct drm_plane_state *plane_state; -+ struct drm_plane *plane; -+ enum pipe pipe = intel_crtc->pipe; -+ int id; -+ -+ WARN_ON(!drm_atomic_get_existing_crtc_state(state, crtc)); -+ -+ drm_for_each_plane_mask(plane, dev, crtc->state->plane_mask) { -+ id = skl_wm_plane_id(to_intel_plane(plane)); -+ -+ if (skl_ddb_entry_equal(&cur_ddb->plane[pipe][id], -+ &new_ddb->plane[pipe][id]) && -+ skl_ddb_entry_equal(&cur_ddb->y_plane[pipe][id], -+ &new_ddb->y_plane[pipe][id])) -+ continue; -+ -+ plane_state = drm_atomic_get_plane_state(state, plane); -+ if (IS_ERR(plane_state)) -+ return PTR_ERR(plane_state); -+ } -+ -+ return 0; -+} -+ - static int - skl_compute_ddb(struct drm_atomic_state *state) - { -@@ -4105,6 +4062,10 @@ skl_compute_ddb(struct drm_atomic_state *state) - if (ret) - return ret; - -+ ret = skl_ddb_add_affected_planes(cstate); -+ if (ret) -+ return ret; -+ - ret = drm_atomic_add_affected_planes(state, &intel_crtc->base); - if (ret) - return ret; -@@ -4206,7 +4167,7 @@ static void skl_update_wm(struct drm_crtc *crtc) - struct skl_wm_values *hw_vals = &dev_priv->wm.skl_hw; - struct intel_crtc_state *cstate = to_intel_crtc_state(crtc->state); - struct skl_pipe_wm *pipe_wm = &cstate->wm.skl.optimal; -- int pipe; -+ enum pipe pipe = intel_crtc->pipe; - - if ((results->dirty_pipes & drm_crtc_mask(crtc)) == 0) - return; -@@ -4215,15 +4176,22 @@ static void skl_update_wm(struct drm_crtc *crtc) - - mutex_lock(&dev_priv->wm.wm_mutex); - -- skl_write_wm_values(dev_priv, results); -- skl_flush_wm_values(dev_priv, results); -- - /* -- * Store the new configuration (but only for the pipes that have -- * changed; the other values weren't recomputed). -+ * If this pipe isn't active already, we're going to be enabling it -+ * very soon. Since it's safe to update a pipe's ddb allocation while -+ * the pipe's shut off, just do so here. Already active pipes will have -+ * their watermarks updated once we update their planes. - */ -- for_each_pipe_masked(dev_priv, pipe, results->dirty_pipes) -- skl_copy_wm_for_pipe(hw_vals, results, pipe); -+ if (crtc->state->active_changed) { -+ int plane; -+ -+ for (plane = 0; plane < intel_num_planes(intel_crtc); plane++) -+ skl_write_plane_wm(intel_crtc, results, plane); -+ -+ skl_write_cursor_wm(intel_crtc, results); -+ } -+ -+ skl_copy_wm_for_pipe(hw_vals, results, pipe); - - mutex_unlock(&dev_priv->wm.wm_mutex); - } -diff --git a/drivers/gpu/drm/i915/intel_sprite.c b/drivers/gpu/drm/i915/intel_sprite.c -index 7c08e4f..4178849 100644 ---- a/drivers/gpu/drm/i915/intel_sprite.c -+++ b/drivers/gpu/drm/i915/intel_sprite.c -@@ -203,6 +203,9 @@ skl_update_plane(struct drm_plane *drm_plane, - struct intel_plane *intel_plane = to_intel_plane(drm_plane); - struct drm_framebuffer *fb = plane_state->base.fb; - struct drm_i915_gem_object *obj = intel_fb_obj(fb); -+ const struct skl_wm_values *wm = &dev_priv->wm.skl_results; -+ struct drm_crtc *crtc = crtc_state->base.crtc; -+ struct intel_crtc *intel_crtc = to_intel_crtc(crtc); - const int pipe = intel_plane->pipe; - const int plane = intel_plane->plane + 1; - u32 plane_ctl, stride_div, stride; -@@ -238,6 +241,9 @@ skl_update_plane(struct drm_plane *drm_plane, - crtc_w--; - crtc_h--; - -+ if (wm->dirty_pipes & drm_crtc_mask(crtc)) -+ skl_write_plane_wm(intel_crtc, wm, plane); -+ - if (key->flags) { - I915_WRITE(PLANE_KEYVAL(pipe, plane), key->min_value); - I915_WRITE(PLANE_KEYMAX(pipe, plane), key->max_value); -@@ -308,6 +314,14 @@ skl_disable_plane(struct drm_plane *dplane, struct drm_crtc *crtc) - const int pipe = intel_plane->pipe; - const int plane = intel_plane->plane + 1; - -+ /* -+ * We only populate skl_results on watermark updates, and if the -+ * plane's visiblity isn't actually changing neither is its watermarks. -+ */ -+ if (!to_intel_plane_state(dplane->state)->visible) -+ skl_write_plane_wm(to_intel_crtc(crtc), -+ &dev_priv->wm.skl_results, plane); -+ - I915_WRITE(PLANE_CTL(pipe, plane), 0); - - I915_WRITE(PLANE_SURF(pipe, plane), 0); -diff --git a/drivers/gpu/drm/i915/intel_uncore.c b/drivers/gpu/drm/i915/intel_uncore.c -index ff80a81..ec28b15 100644 ---- a/drivers/gpu/drm/i915/intel_uncore.c -+++ b/drivers/gpu/drm/i915/intel_uncore.c -@@ -796,10 +796,9 @@ __unclaimed_reg_debug(struct drm_i915_private *dev_priv, - const bool read, - const bool before) - { -- if (WARN(check_for_unclaimed_mmio(dev_priv), -- "Unclaimed register detected %s %s register 0x%x\n", -- before ? "before" : "after", -- read ? "reading" : "writing to", -+ if (WARN(check_for_unclaimed_mmio(dev_priv) && !before, -+ "Unclaimed %s register 0x%x\n", -+ read ? "read from" : "write to", - i915_mmio_reg_offset(reg))) - i915.mmio_debug--; /* Only report the first N failures */ - } -diff --git a/drivers/gpu/drm/radeon/r600_dpm.c b/drivers/gpu/drm/radeon/r600_dpm.c -index 6a4b020..5a26eb4 100644 ---- a/drivers/gpu/drm/radeon/r600_dpm.c -+++ b/drivers/gpu/drm/radeon/r600_dpm.c -@@ -156,19 +156,20 @@ u32 r600_dpm_get_vblank_time(struct radeon_device *rdev) - struct drm_device *dev = rdev->ddev; - struct drm_crtc *crtc; - struct radeon_crtc *radeon_crtc; -- u32 line_time_us, vblank_lines; -+ u32 vblank_in_pixels; - u32 vblank_time_us = 0xffffffff; /* if the displays are off, vblank time is max */ - - if (rdev->num_crtc && rdev->mode_info.mode_config_initialized) { - list_for_each_entry(crtc, &dev->mode_config.crtc_list, head) { - radeon_crtc = to_radeon_crtc(crtc); - if (crtc->enabled && radeon_crtc->enabled && radeon_crtc->hw_mode.clock) { -- line_time_us = (radeon_crtc->hw_mode.crtc_htotal * 1000) / -- radeon_crtc->hw_mode.clock; -- vblank_lines = radeon_crtc->hw_mode.crtc_vblank_end - -- radeon_crtc->hw_mode.crtc_vdisplay + -- (radeon_crtc->v_border * 2); -- vblank_time_us = vblank_lines * line_time_us; -+ vblank_in_pixels = -+ radeon_crtc->hw_mode.crtc_htotal * -+ (radeon_crtc->hw_mode.crtc_vblank_end - -+ radeon_crtc->hw_mode.crtc_vdisplay + -+ (radeon_crtc->v_border * 2)); -+ -+ vblank_time_us = vblank_in_pixels * 1000 / radeon_crtc->hw_mode.clock; - break; - } - } -diff --git a/drivers/gpu/drm/radeon/radeon_device.c b/drivers/gpu/drm/radeon/radeon_device.c -index a00dd2f..554ca71 100644 ---- a/drivers/gpu/drm/radeon/radeon_device.c -+++ b/drivers/gpu/drm/radeon/radeon_device.c -@@ -661,8 +661,9 @@ bool radeon_card_posted(struct radeon_device *rdev) - { - uint32_t reg; - -- /* for pass through, always force asic_init */ -- if (radeon_device_is_virtual()) -+ /* for pass through, always force asic_init for CI */ -+ if (rdev->family >= CHIP_BONAIRE && -+ radeon_device_is_virtual()) - return false; - - /* required for EFI mode on macbook2,1 which uses an r5xx asic */ -diff --git a/drivers/gpu/drm/radeon/si_dpm.c b/drivers/gpu/drm/radeon/si_dpm.c -index 1f78ec2..89bdf20 100644 ---- a/drivers/gpu/drm/radeon/si_dpm.c -+++ b/drivers/gpu/drm/radeon/si_dpm.c -@@ -4112,7 +4112,7 @@ static int si_populate_smc_voltage_tables(struct radeon_device *rdev, - &rdev->pm.dpm.dyn_state.phase_shedding_limits_table)) { - si_populate_smc_voltage_table(rdev, &si_pi->vddc_phase_shed_table, table); - -- table->phaseMaskTable.lowMask[SISLANDS_SMC_VOLTAGEMASK_VDDC] = -+ table->phaseMaskTable.lowMask[SISLANDS_SMC_VOLTAGEMASK_VDDC_PHASE_SHEDDING] = - cpu_to_be32(si_pi->vddc_phase_shed_table.mask_low); - - si_write_smc_soft_register(rdev, SI_SMC_SOFT_REGISTER_phase_shedding_delay, -diff --git a/drivers/gpu/drm/radeon/sislands_smc.h b/drivers/gpu/drm/radeon/sislands_smc.h -index 3c77983..966e3a5 100644 ---- a/drivers/gpu/drm/radeon/sislands_smc.h -+++ b/drivers/gpu/drm/radeon/sislands_smc.h -@@ -194,6 +194,7 @@ typedef struct SISLANDS_SMC_SWSTATE SISLANDS_SMC_SWSTATE; - #define SISLANDS_SMC_VOLTAGEMASK_VDDC 0 - #define SISLANDS_SMC_VOLTAGEMASK_MVDD 1 - #define SISLANDS_SMC_VOLTAGEMASK_VDDCI 2 -+#define SISLANDS_SMC_VOLTAGEMASK_VDDC_PHASE_SHEDDING 3 - #define SISLANDS_SMC_VOLTAGEMASK_MAX 4 - - struct SISLANDS_SMC_VOLTAGEMASKTABLE -diff --git a/drivers/gpu/drm/vc4/vc4_drv.h b/drivers/gpu/drm/vc4/vc4_drv.h -index 428e249..f696b75 100644 ---- a/drivers/gpu/drm/vc4/vc4_drv.h -+++ b/drivers/gpu/drm/vc4/vc4_drv.h -@@ -122,9 +122,16 @@ to_vc4_dev(struct drm_device *dev) - struct vc4_bo { - struct drm_gem_cma_object base; - -- /* seqno of the last job to render to this BO. */ -+ /* seqno of the last job to render using this BO. */ - uint64_t seqno; - -+ /* seqno of the last job to use the RCL to write to this BO. -+ * -+ * Note that this doesn't include binner overflow memory -+ * writes. -+ */ -+ uint64_t write_seqno; -+ - /* List entry for the BO's position in either - * vc4_exec_info->unref_list or vc4_dev->bo_cache.time_list - */ -@@ -216,6 +223,9 @@ struct vc4_exec_info { - /* Sequence number for this bin/render job. */ - uint64_t seqno; - -+ /* Latest write_seqno of any BO that binning depends on. */ -+ uint64_t bin_dep_seqno; -+ - /* Last current addresses the hardware was processing when the - * hangcheck timer checked on us. - */ -@@ -230,6 +240,13 @@ struct vc4_exec_info { - struct drm_gem_cma_object **bo; - uint32_t bo_count; - -+ /* List of BOs that are being written by the RCL. Other than -+ * the binner temporary storage, this is all the BOs written -+ * by the job. -+ */ -+ struct drm_gem_cma_object *rcl_write_bo[4]; -+ uint32_t rcl_write_bo_count; -+ - /* Pointers for our position in vc4->job_list */ - struct list_head head; - -diff --git a/drivers/gpu/drm/vc4/vc4_gem.c b/drivers/gpu/drm/vc4/vc4_gem.c -index b262c5c..ae1609e 100644 ---- a/drivers/gpu/drm/vc4/vc4_gem.c -+++ b/drivers/gpu/drm/vc4/vc4_gem.c -@@ -471,6 +471,11 @@ vc4_update_bo_seqnos(struct vc4_exec_info *exec, uint64_t seqno) - list_for_each_entry(bo, &exec->unref_list, unref_head) { - bo->seqno = seqno; - } -+ -+ for (i = 0; i < exec->rcl_write_bo_count; i++) { -+ bo = to_vc4_bo(&exec->rcl_write_bo[i]->base); -+ bo->write_seqno = seqno; -+ } - } - - /* Queues a struct vc4_exec_info for execution. If no job is -@@ -673,6 +678,14 @@ vc4_get_bcl(struct drm_device *dev, struct vc4_exec_info *exec) - goto fail; - - ret = vc4_validate_shader_recs(dev, exec); -+ if (ret) -+ goto fail; -+ -+ /* Block waiting on any previous rendering into the CS's VBO, -+ * IB, or textures, so that pixels are actually written by the -+ * time we try to read them. -+ */ -+ ret = vc4_wait_for_seqno(dev, exec->bin_dep_seqno, ~0ull, true); - - fail: - drm_free_large(temp); -diff --git a/drivers/gpu/drm/vc4/vc4_render_cl.c b/drivers/gpu/drm/vc4/vc4_render_cl.c -index 0f12418..08886a3 100644 ---- a/drivers/gpu/drm/vc4/vc4_render_cl.c -+++ b/drivers/gpu/drm/vc4/vc4_render_cl.c -@@ -45,6 +45,8 @@ struct vc4_rcl_setup { - - struct drm_gem_cma_object *rcl; - u32 next_offset; -+ -+ u32 next_write_bo_index; - }; - - static inline void rcl_u8(struct vc4_rcl_setup *setup, u8 val) -@@ -407,6 +409,8 @@ static int vc4_rcl_msaa_surface_setup(struct vc4_exec_info *exec, - if (!*obj) - return -EINVAL; - -+ exec->rcl_write_bo[exec->rcl_write_bo_count++] = *obj; -+ - if (surf->offset & 0xf) { - DRM_ERROR("MSAA write must be 16b aligned.\n"); - return -EINVAL; -@@ -417,7 +421,8 @@ static int vc4_rcl_msaa_surface_setup(struct vc4_exec_info *exec, - - static int vc4_rcl_surface_setup(struct vc4_exec_info *exec, - struct drm_gem_cma_object **obj, -- struct drm_vc4_submit_rcl_surface *surf) -+ struct drm_vc4_submit_rcl_surface *surf, -+ bool is_write) - { - uint8_t tiling = VC4_GET_FIELD(surf->bits, - VC4_LOADSTORE_TILE_BUFFER_TILING); -@@ -440,6 +445,9 @@ static int vc4_rcl_surface_setup(struct vc4_exec_info *exec, - if (!*obj) - return -EINVAL; - -+ if (is_write) -+ exec->rcl_write_bo[exec->rcl_write_bo_count++] = *obj; -+ - if (surf->flags & VC4_SUBMIT_RCL_SURFACE_READ_IS_FULL_RES) { - if (surf == &exec->args->zs_write) { - DRM_ERROR("general zs write may not be a full-res.\n"); -@@ -542,6 +550,8 @@ vc4_rcl_render_config_surface_setup(struct vc4_exec_info *exec, - if (!*obj) - return -EINVAL; - -+ exec->rcl_write_bo[exec->rcl_write_bo_count++] = *obj; -+ - if (tiling > VC4_TILING_FORMAT_LT) { - DRM_ERROR("Bad tiling format\n"); - return -EINVAL; -@@ -599,15 +609,18 @@ int vc4_get_rcl(struct drm_device *dev, struct vc4_exec_info *exec) - if (ret) - return ret; - -- ret = vc4_rcl_surface_setup(exec, &setup.color_read, &args->color_read); -+ ret = vc4_rcl_surface_setup(exec, &setup.color_read, &args->color_read, -+ false); - if (ret) - return ret; - -- ret = vc4_rcl_surface_setup(exec, &setup.zs_read, &args->zs_read); -+ ret = vc4_rcl_surface_setup(exec, &setup.zs_read, &args->zs_read, -+ false); - if (ret) - return ret; - -- ret = vc4_rcl_surface_setup(exec, &setup.zs_write, &args->zs_write); -+ ret = vc4_rcl_surface_setup(exec, &setup.zs_write, &args->zs_write, -+ true); - if (ret) - return ret; - -diff --git a/drivers/gpu/drm/vc4/vc4_validate.c b/drivers/gpu/drm/vc4/vc4_validate.c -index 9ce1d0a..26503e3 100644 ---- a/drivers/gpu/drm/vc4/vc4_validate.c -+++ b/drivers/gpu/drm/vc4/vc4_validate.c -@@ -267,6 +267,9 @@ validate_indexed_prim_list(VALIDATE_ARGS) - if (!ib) - return -EINVAL; - -+ exec->bin_dep_seqno = max(exec->bin_dep_seqno, -+ to_vc4_bo(&ib->base)->write_seqno); -+ - if (offset > ib->base.size || - (ib->base.size - offset) / index_size < length) { - DRM_ERROR("IB access overflow (%d + %d*%d > %zd)\n", -@@ -555,8 +558,7 @@ static bool - reloc_tex(struct vc4_exec_info *exec, - void *uniform_data_u, - struct vc4_texture_sample_info *sample, -- uint32_t texture_handle_index) -- -+ uint32_t texture_handle_index, bool is_cs) - { - struct drm_gem_cma_object *tex; - uint32_t p0 = *(uint32_t *)(uniform_data_u + sample->p_offset[0]); -@@ -714,6 +716,11 @@ reloc_tex(struct vc4_exec_info *exec, - - *validated_p0 = tex->paddr + p0; - -+ if (is_cs) { -+ exec->bin_dep_seqno = max(exec->bin_dep_seqno, -+ to_vc4_bo(&tex->base)->write_seqno); -+ } -+ - return true; - fail: - DRM_INFO("Texture p0 at %d: 0x%08x\n", sample->p_offset[0], p0); -@@ -835,7 +842,8 @@ validate_gl_shader_rec(struct drm_device *dev, - if (!reloc_tex(exec, - uniform_data_u, - &validated_shader->texture_samples[tex], -- texture_handles_u[tex])) { -+ texture_handles_u[tex], -+ i == 2)) { - return -EINVAL; - } - } -@@ -867,6 +875,9 @@ validate_gl_shader_rec(struct drm_device *dev, - uint32_t stride = *(uint8_t *)(pkt_u + o + 5); - uint32_t max_index; - -+ exec->bin_dep_seqno = max(exec->bin_dep_seqno, -+ to_vc4_bo(&vbo->base)->write_seqno); -+ - if (state->addr & 0x8) - stride |= (*(uint32_t *)(pkt_u + 100 + i * 4)) & ~0xff; - -diff --git a/drivers/gpu/drm/vmwgfx/vmwgfx_execbuf.c b/drivers/gpu/drm/vmwgfx/vmwgfx_execbuf.c -index dc5beff..8a15c4a 100644 ---- a/drivers/gpu/drm/vmwgfx/vmwgfx_execbuf.c -+++ b/drivers/gpu/drm/vmwgfx/vmwgfx_execbuf.c -@@ -34,6 +34,24 @@ - - #define VMW_RES_HT_ORDER 12 - -+ /** -+ * enum vmw_resource_relocation_type - Relocation type for resources -+ * -+ * @vmw_res_rel_normal: Traditional relocation. The resource id in the -+ * command stream is replaced with the actual id after validation. -+ * @vmw_res_rel_nop: NOP relocation. The command is unconditionally replaced -+ * with a NOP. -+ * @vmw_res_rel_cond_nop: Conditional NOP relocation. If the resource id -+ * after validation is -1, the command is replaced with a NOP. Otherwise no -+ * action. -+ */ -+enum vmw_resource_relocation_type { -+ vmw_res_rel_normal, -+ vmw_res_rel_nop, -+ vmw_res_rel_cond_nop, -+ vmw_res_rel_max -+}; -+ - /** - * struct vmw_resource_relocation - Relocation info for resources - * -@@ -41,11 +59,13 @@ - * @res: Non-ref-counted pointer to the resource. - * @offset: Offset of 4 byte entries into the command buffer where the - * id that needs fixup is located. -+ * @rel_type: Type of relocation. - */ - struct vmw_resource_relocation { - struct list_head head; - const struct vmw_resource *res; -- unsigned long offset; -+ u32 offset:29; -+ enum vmw_resource_relocation_type rel_type:3; - }; - - /** -@@ -410,10 +430,13 @@ static int vmw_resource_context_res_add(struct vmw_private *dev_priv, - * @res: The resource. - * @offset: Offset into the command buffer currently being parsed where the - * id that needs fixup is located. Granularity is 4 bytes. -+ * @rel_type: Relocation type. - */ - static int vmw_resource_relocation_add(struct list_head *list, - const struct vmw_resource *res, -- unsigned long offset) -+ unsigned long offset, -+ enum vmw_resource_relocation_type -+ rel_type) - { - struct vmw_resource_relocation *rel; - -@@ -425,6 +448,7 @@ static int vmw_resource_relocation_add(struct list_head *list, - - rel->res = res; - rel->offset = offset; -+ rel->rel_type = rel_type; - list_add_tail(&rel->head, list); - - return 0; -@@ -459,11 +483,23 @@ static void vmw_resource_relocations_apply(uint32_t *cb, - { - struct vmw_resource_relocation *rel; - -+ /* Validate the struct vmw_resource_relocation member size */ -+ BUILD_BUG_ON(SVGA_CB_MAX_SIZE >= (1 << 29)); -+ BUILD_BUG_ON(vmw_res_rel_max >= (1 << 3)); -+ - list_for_each_entry(rel, list, head) { -- if (likely(rel->res != NULL)) -+ switch (rel->rel_type) { -+ case vmw_res_rel_normal: - cb[rel->offset] = rel->res->id; -- else -+ break; -+ case vmw_res_rel_nop: - cb[rel->offset] = SVGA_3D_CMD_NOP; -+ break; -+ default: -+ if (rel->res->id == -1) -+ cb[rel->offset] = SVGA_3D_CMD_NOP; -+ break; -+ } - } - } - -@@ -655,7 +691,8 @@ static int vmw_cmd_res_reloc_add(struct vmw_private *dev_priv, - *p_val = NULL; - ret = vmw_resource_relocation_add(&sw_context->res_relocations, - res, -- id_loc - sw_context->buf_start); -+ id_loc - sw_context->buf_start, -+ vmw_res_rel_normal); - if (unlikely(ret != 0)) - return ret; - -@@ -721,7 +758,8 @@ vmw_cmd_res_check(struct vmw_private *dev_priv, - - return vmw_resource_relocation_add - (&sw_context->res_relocations, res, -- id_loc - sw_context->buf_start); -+ id_loc - sw_context->buf_start, -+ vmw_res_rel_normal); - } - - ret = vmw_user_resource_lookup_handle(dev_priv, -@@ -2144,7 +2182,8 @@ static int vmw_cmd_shader_define(struct vmw_private *dev_priv, - - return vmw_resource_relocation_add(&sw_context->res_relocations, - NULL, &cmd->header.id - -- sw_context->buf_start); -+ sw_context->buf_start, -+ vmw_res_rel_nop); - - return 0; - } -@@ -2189,7 +2228,8 @@ static int vmw_cmd_shader_destroy(struct vmw_private *dev_priv, - - return vmw_resource_relocation_add(&sw_context->res_relocations, - NULL, &cmd->header.id - -- sw_context->buf_start); -+ sw_context->buf_start, -+ vmw_res_rel_nop); - - return 0; - } -@@ -2848,8 +2888,7 @@ static int vmw_cmd_dx_cid_check(struct vmw_private *dev_priv, - * @header: Pointer to the command header in the command stream. - * - * Check that the view exists, and if it was not created using this -- * command batch, make sure it's validated (present in the device) so that -- * the remove command will not confuse the device. -+ * command batch, conditionally make this command a NOP. - */ - static int vmw_cmd_dx_view_remove(struct vmw_private *dev_priv, - struct vmw_sw_context *sw_context, -@@ -2877,10 +2916,15 @@ static int vmw_cmd_dx_view_remove(struct vmw_private *dev_priv, - return ret; - - /* -- * Add view to the validate list iff it was not created using this -- * command batch. -+ * If the view wasn't created during this command batch, it might -+ * have been removed due to a context swapout, so add a -+ * relocation to conditionally make this command a NOP to avoid -+ * device errors. - */ -- return vmw_view_res_val_add(sw_context, view); -+ return vmw_resource_relocation_add(&sw_context->res_relocations, -+ view, -+ &cmd->header.id - sw_context->buf_start, -+ vmw_res_rel_cond_nop); - } - - /** -@@ -3848,14 +3892,14 @@ static void *vmw_execbuf_cmdbuf(struct vmw_private *dev_priv, - int ret; - - *header = NULL; -- if (!dev_priv->cman || kernel_commands) -- return kernel_commands; -- - if (command_size > SVGA_CB_MAX_SIZE) { - DRM_ERROR("Command buffer is too large.\n"); - return ERR_PTR(-EINVAL); - } - -+ if (!dev_priv->cman || kernel_commands) -+ return kernel_commands; -+ - /* If possible, add a little space for fencing. */ - cmdbuf_size = command_size + 512; - cmdbuf_size = min_t(size_t, cmdbuf_size, SVGA_CB_MAX_SIZE); -diff --git a/drivers/hid/hid-ids.h b/drivers/hid/hid-ids.h -index 4ed9a4f..e92b09d 100644 ---- a/drivers/hid/hid-ids.h -+++ b/drivers/hid/hid-ids.h -@@ -64,6 +64,9 @@ - #define USB_VENDOR_ID_AKAI 0x2011 - #define USB_DEVICE_ID_AKAI_MPKMINI2 0x0715 - -+#define USB_VENDOR_ID_AKAI_09E8 0x09E8 -+#define USB_DEVICE_ID_AKAI_09E8_MIDIMIX 0x0031 -+ - #define USB_VENDOR_ID_ALCOR 0x058f - #define USB_DEVICE_ID_ALCOR_USBRS232 0x9720 - -diff --git a/drivers/hid/usbhid/hid-quirks.c b/drivers/hid/usbhid/hid-quirks.c -index b4b8c6a..bb40008 100644 ---- a/drivers/hid/usbhid/hid-quirks.c -+++ b/drivers/hid/usbhid/hid-quirks.c -@@ -56,6 +56,7 @@ static const struct hid_blacklist { - - { USB_VENDOR_ID_AIREN, USB_DEVICE_ID_AIREN_SLIMPLUS, HID_QUIRK_NOGET }, - { USB_VENDOR_ID_AKAI, USB_DEVICE_ID_AKAI_MPKMINI2, HID_QUIRK_NO_INIT_REPORTS }, -+ { USB_VENDOR_ID_AKAI_09E8, USB_DEVICE_ID_AKAI_09E8_MIDIMIX, HID_QUIRK_NO_INIT_REPORTS }, - { USB_VENDOR_ID_ATEN, USB_DEVICE_ID_ATEN_UC100KM, HID_QUIRK_NOGET }, - { USB_VENDOR_ID_ATEN, USB_DEVICE_ID_ATEN_CS124U, HID_QUIRK_NOGET }, - { USB_VENDOR_ID_ATEN, USB_DEVICE_ID_ATEN_2PORTKVM, HID_QUIRK_NOGET }, -diff --git a/drivers/hwtracing/coresight/coresight-tmc.c b/drivers/hwtracing/coresight/coresight-tmc.c -index 9e02ac9..3978cbb 100644 ---- a/drivers/hwtracing/coresight/coresight-tmc.c -+++ b/drivers/hwtracing/coresight/coresight-tmc.c -@@ -388,9 +388,6 @@ static int tmc_probe(struct amba_device *adev, const struct amba_id *id) - err_misc_register: - coresight_unregister(drvdata->csdev); - err_devm_kzalloc: -- if (drvdata->config_type == TMC_CONFIG_TYPE_ETR) -- dma_free_coherent(dev, drvdata->size, -- drvdata->vaddr, drvdata->paddr); - return ret; - } - -diff --git a/drivers/iio/dac/ad5755.c b/drivers/iio/dac/ad5755.c -index 0fde593..5f79682 100644 ---- a/drivers/iio/dac/ad5755.c -+++ b/drivers/iio/dac/ad5755.c -@@ -655,7 +655,7 @@ static struct ad5755_platform_data *ad5755_parse_dt(struct device *dev) - - devnr = 0; - for_each_child_of_node(np, pp) { -- if (devnr > AD5755_NUM_CHANNELS) { -+ if (devnr >= AD5755_NUM_CHANNELS) { - dev_err(dev, - "There is to many channels defined in DT\n"); - goto error_out; -diff --git a/drivers/iio/light/us5182d.c b/drivers/iio/light/us5182d.c -index 20c40f7..18cf2e2 100644 ---- a/drivers/iio/light/us5182d.c -+++ b/drivers/iio/light/us5182d.c -@@ -894,7 +894,7 @@ static int us5182d_probe(struct i2c_client *client, - goto out_err; - - if (data->default_continuous) { -- pm_runtime_set_active(&client->dev); -+ ret = pm_runtime_set_active(&client->dev); - if (ret < 0) - goto out_err; - } -diff --git a/drivers/infiniband/hw/hfi1/qp.c b/drivers/infiniband/hw/hfi1/qp.c -index 4e4d831..c17c9dd 100644 ---- a/drivers/infiniband/hw/hfi1/qp.c -+++ b/drivers/infiniband/hw/hfi1/qp.c -@@ -808,6 +808,13 @@ void *qp_priv_alloc(struct rvt_dev_info *rdi, struct rvt_qp *qp, - kfree(priv); - return ERR_PTR(-ENOMEM); - } -+ iowait_init( -+ &priv->s_iowait, -+ 1, -+ _hfi1_do_send, -+ iowait_sleep, -+ iowait_wakeup, -+ iowait_sdma_drained); - setup_timer(&priv->s_rnr_timer, hfi1_rc_rnr_retry, (unsigned long)qp); - qp->s_timer.function = hfi1_rc_timeout; - return priv; -@@ -873,13 +880,6 @@ void notify_qp_reset(struct rvt_qp *qp) - { - struct hfi1_qp_priv *priv = qp->priv; - -- iowait_init( -- &priv->s_iowait, -- 1, -- _hfi1_do_send, -- iowait_sleep, -- iowait_wakeup, -- iowait_sdma_drained); - priv->r_adefered = 0; - clear_ahg(qp); - } -diff --git a/drivers/infiniband/hw/mlx5/main.c b/drivers/infiniband/hw/mlx5/main.c -index e19537c..bff8707a 100644 ---- a/drivers/infiniband/hw/mlx5/main.c -+++ b/drivers/infiniband/hw/mlx5/main.c -@@ -1843,6 +1843,7 @@ static struct mlx5_ib_flow_handler *create_leftovers_rule(struct mlx5_ib_dev *de - &leftovers_specs[LEFTOVERS_UC].flow_attr, - dst); - if (IS_ERR(handler_ucast)) { -+ mlx5_del_flow_rule(handler->rule); - kfree(handler); - handler = handler_ucast; - } else { -diff --git a/drivers/infiniband/hw/qib/qib.h b/drivers/infiniband/hw/qib/qib.h -index bbf0a16..54bb655f 100644 ---- a/drivers/infiniband/hw/qib/qib.h -+++ b/drivers/infiniband/hw/qib/qib.h -@@ -1131,7 +1131,6 @@ extern spinlock_t qib_devs_lock; - extern struct qib_devdata *qib_lookup(int unit); - extern u32 qib_cpulist_count; - extern unsigned long *qib_cpulist; --extern u16 qpt_mask; - extern unsigned qib_cc_table_size; - - int qib_init(struct qib_devdata *, int); -diff --git a/drivers/infiniband/hw/qib/qib_qp.c b/drivers/infiniband/hw/qib/qib_qp.c -index f9b8cd2..99d31ef 100644 ---- a/drivers/infiniband/hw/qib/qib_qp.c -+++ b/drivers/infiniband/hw/qib/qib_qp.c -@@ -41,14 +41,6 @@ - - #include "qib.h" - --/* -- * mask field which was present in now deleted qib_qpn_table -- * is not present in rvt_qpn_table. Defining the same field -- * as qpt_mask here instead of adding the mask field to -- * rvt_qpn_table. -- */ --u16 qpt_mask; -- - static inline unsigned mk_qpn(struct rvt_qpn_table *qpt, - struct rvt_qpn_map *map, unsigned off) - { -@@ -57,7 +49,7 @@ static inline unsigned mk_qpn(struct rvt_qpn_table *qpt, - - static inline unsigned find_next_offset(struct rvt_qpn_table *qpt, - struct rvt_qpn_map *map, unsigned off, -- unsigned n) -+ unsigned n, u16 qpt_mask) - { - if (qpt_mask) { - off++; -@@ -179,6 +171,7 @@ int qib_alloc_qpn(struct rvt_dev_info *rdi, struct rvt_qpn_table *qpt, - struct qib_ibdev *verbs_dev = container_of(rdi, struct qib_ibdev, rdi); - struct qib_devdata *dd = container_of(verbs_dev, struct qib_devdata, - verbs_dev); -+ u16 qpt_mask = dd->qpn_mask; - - if (type == IB_QPT_SMI || type == IB_QPT_GSI) { - unsigned n; -@@ -215,7 +208,7 @@ int qib_alloc_qpn(struct rvt_dev_info *rdi, struct rvt_qpn_table *qpt, - goto bail; - } - offset = find_next_offset(qpt, map, offset, -- dd->n_krcv_queues); -+ dd->n_krcv_queues, qpt_mask); - qpn = mk_qpn(qpt, map, offset); - /* - * This test differs from alloc_pidmap(). -diff --git a/drivers/infiniband/hw/qib/qib_verbs.c b/drivers/infiniband/hw/qib/qib_verbs.c -index fd1dfbc..b2b845f 100644 ---- a/drivers/infiniband/hw/qib/qib_verbs.c -+++ b/drivers/infiniband/hw/qib/qib_verbs.c -@@ -1606,8 +1606,6 @@ int qib_register_ib_device(struct qib_devdata *dd) - /* Only need to initialize non-zero fields. */ - setup_timer(&dev->mem_timer, mem_timer, (unsigned long)dev); - -- qpt_mask = dd->qpn_mask; -- - INIT_LIST_HEAD(&dev->piowait); - INIT_LIST_HEAD(&dev->dmawait); - INIT_LIST_HEAD(&dev->txwait); -diff --git a/drivers/infiniband/sw/rdmavt/qp.c b/drivers/infiniband/sw/rdmavt/qp.c -index 870b4f2..5911c53 100644 ---- a/drivers/infiniband/sw/rdmavt/qp.c -+++ b/drivers/infiniband/sw/rdmavt/qp.c -@@ -501,12 +501,9 @@ static void rvt_remove_qp(struct rvt_dev_info *rdi, struct rvt_qp *qp) - */ - static void rvt_reset_qp(struct rvt_dev_info *rdi, struct rvt_qp *qp, - enum ib_qp_type type) -- __releases(&qp->s_lock) -- __releases(&qp->s_hlock) -- __releases(&qp->r_lock) -- __acquires(&qp->r_lock) -- __acquires(&qp->s_hlock) -- __acquires(&qp->s_lock) -+ __must_hold(&qp->r_lock) -+ __must_hold(&qp->s_hlock) -+ __must_hold(&qp->s_lock) - { - if (qp->state != IB_QPS_RESET) { - qp->state = IB_QPS_RESET; -diff --git a/drivers/net/ethernet/intel/i40e/i40e_client.c b/drivers/net/ethernet/intel/i40e/i40e_client.c -index 618f184..c65e17f 100644 ---- a/drivers/net/ethernet/intel/i40e/i40e_client.c -+++ b/drivers/net/ethernet/intel/i40e/i40e_client.c -@@ -1009,7 +1009,6 @@ int i40e_unregister_client(struct i40e_client *client) - if (!i40e_client_is_registered(client)) { - pr_info("i40e: Client %s has not been registered\n", - client->name); -- mutex_unlock(&i40e_client_mutex); - ret = -ENODEV; - goto out; - } -diff --git a/drivers/net/ethernet/intel/i40e/i40e_main.c b/drivers/net/ethernet/intel/i40e/i40e_main.c -index dad15b6..c74d164 100644 ---- a/drivers/net/ethernet/intel/i40e/i40e_main.c -+++ b/drivers/net/ethernet/intel/i40e/i40e_main.c -@@ -7990,45 +7990,34 @@ static int i40e_setup_misc_vector(struct i40e_pf *pf) - static int i40e_config_rss_aq(struct i40e_vsi *vsi, const u8 *seed, - u8 *lut, u16 lut_size) - { -- struct i40e_aqc_get_set_rss_key_data rss_key; - struct i40e_pf *pf = vsi->back; - struct i40e_hw *hw = &pf->hw; -- bool pf_lut = false; -- u8 *rss_lut; -- int ret, i; -- -- memcpy(&rss_key, seed, sizeof(rss_key)); -- -- rss_lut = kzalloc(pf->rss_table_size, GFP_KERNEL); -- if (!rss_lut) -- return -ENOMEM; -- -- /* Populate the LUT with max no. of queues in round robin fashion */ -- for (i = 0; i < vsi->rss_table_size; i++) -- rss_lut[i] = i % vsi->rss_size; -+ int ret = 0; - -- ret = i40e_aq_set_rss_key(hw, vsi->id, &rss_key); -- if (ret) { -- dev_info(&pf->pdev->dev, -- "Cannot set RSS key, err %s aq_err %s\n", -- i40e_stat_str(&pf->hw, ret), -- i40e_aq_str(&pf->hw, pf->hw.aq.asq_last_status)); -- goto config_rss_aq_out; -+ if (seed) { -+ struct i40e_aqc_get_set_rss_key_data *seed_dw = -+ (struct i40e_aqc_get_set_rss_key_data *)seed; -+ ret = i40e_aq_set_rss_key(hw, vsi->id, seed_dw); -+ if (ret) { -+ dev_info(&pf->pdev->dev, -+ "Cannot set RSS key, err %s aq_err %s\n", -+ i40e_stat_str(hw, ret), -+ i40e_aq_str(hw, hw->aq.asq_last_status)); -+ return ret; -+ } - } -+ if (lut) { -+ bool pf_lut = vsi->type == I40E_VSI_MAIN ? true : false; - -- if (vsi->type == I40E_VSI_MAIN) -- pf_lut = true; -- -- ret = i40e_aq_set_rss_lut(hw, vsi->id, pf_lut, rss_lut, -- vsi->rss_table_size); -- if (ret) -- dev_info(&pf->pdev->dev, -- "Cannot set RSS lut, err %s aq_err %s\n", -- i40e_stat_str(&pf->hw, ret), -- i40e_aq_str(&pf->hw, pf->hw.aq.asq_last_status)); -- --config_rss_aq_out: -- kfree(rss_lut); -+ ret = i40e_aq_set_rss_lut(hw, vsi->id, pf_lut, lut, lut_size); -+ if (ret) { -+ dev_info(&pf->pdev->dev, -+ "Cannot set RSS lut, err %s aq_err %s\n", -+ i40e_stat_str(hw, ret), -+ i40e_aq_str(hw, hw->aq.asq_last_status)); -+ return ret; -+ } -+ } - return ret; - } - -diff --git a/drivers/net/wireless/ath/ath10k/htt_rx.c b/drivers/net/wireless/ath/ath10k/htt_rx.c -index 24c8d65..09ca634 100644 ---- a/drivers/net/wireless/ath/ath10k/htt_rx.c -+++ b/drivers/net/wireless/ath/ath10k/htt_rx.c -@@ -2394,6 +2394,8 @@ static void ath10k_htt_txrx_compl_task(unsigned long ptr) - skb_queue_splice_init(&htt->rx_in_ord_compl_q, &rx_ind_q); - spin_unlock_irqrestore(&htt->rx_in_ord_compl_q.lock, flags); - -+ ath10k_mac_tx_push_pending(ar); -+ - spin_lock_irqsave(&htt->tx_fetch_ind_q.lock, flags); - skb_queue_splice_init(&htt->tx_fetch_ind_q, &tx_ind_q); - spin_unlock_irqrestore(&htt->tx_fetch_ind_q.lock, flags); -diff --git a/drivers/net/wireless/ath/ath10k/mac.c b/drivers/net/wireless/ath/ath10k/mac.c -index 0bbd0a0..146365b 100644 ---- a/drivers/net/wireless/ath/ath10k/mac.c -+++ b/drivers/net/wireless/ath/ath10k/mac.c -@@ -3777,7 +3777,9 @@ int ath10k_mac_tx_push_txq(struct ieee80211_hw *hw, - enum ath10k_hw_txrx_mode txmode; - enum ath10k_mac_tx_path txpath; - struct sk_buff *skb; -+ struct ieee80211_hdr *hdr; - size_t skb_len; -+ bool is_mgmt, is_presp; - int ret; - - spin_lock_bh(&ar->htt.tx_lock); -@@ -3801,6 +3803,22 @@ int ath10k_mac_tx_push_txq(struct ieee80211_hw *hw, - skb_len = skb->len; - txmode = ath10k_mac_tx_h_get_txmode(ar, vif, sta, skb); - txpath = ath10k_mac_tx_h_get_txpath(ar, skb, txmode); -+ is_mgmt = (txpath == ATH10K_MAC_TX_HTT_MGMT); -+ -+ if (is_mgmt) { -+ hdr = (struct ieee80211_hdr *)skb->data; -+ is_presp = ieee80211_is_probe_resp(hdr->frame_control); -+ -+ spin_lock_bh(&ar->htt.tx_lock); -+ ret = ath10k_htt_tx_mgmt_inc_pending(htt, is_mgmt, is_presp); -+ -+ if (ret) { -+ ath10k_htt_tx_dec_pending(htt); -+ spin_unlock_bh(&ar->htt.tx_lock); -+ return ret; -+ } -+ spin_unlock_bh(&ar->htt.tx_lock); -+ } - - ret = ath10k_mac_tx(ar, vif, sta, txmode, txpath, skb); - if (unlikely(ret)) { -@@ -3808,6 +3826,8 @@ int ath10k_mac_tx_push_txq(struct ieee80211_hw *hw, - - spin_lock_bh(&ar->htt.tx_lock); - ath10k_htt_tx_dec_pending(htt); -+ if (is_mgmt) -+ ath10k_htt_tx_mgmt_dec_pending(htt); - spin_unlock_bh(&ar->htt.tx_lock); - - return ret; -@@ -6538,7 +6558,7 @@ static int ath10k_get_survey(struct ieee80211_hw *hw, int idx, - goto exit; - } - -- ath10k_mac_update_bss_chan_survey(ar, survey->channel); -+ ath10k_mac_update_bss_chan_survey(ar, &sband->channels[idx]); - - spin_lock_bh(&ar->data_lock); - memcpy(survey, ar_survey, sizeof(*survey)); -diff --git a/drivers/net/wireless/ath/ath10k/txrx.c b/drivers/net/wireless/ath/ath10k/txrx.c -index b29a86a..28ff5cb 100644 ---- a/drivers/net/wireless/ath/ath10k/txrx.c -+++ b/drivers/net/wireless/ath/ath10k/txrx.c -@@ -119,8 +119,6 @@ int ath10k_txrx_tx_unref(struct ath10k_htt *htt, - ieee80211_tx_status(htt->ar->hw, msdu); - /* we do not own the msdu anymore */ - -- ath10k_mac_tx_push_pending(ar); -- - return 0; - } - -diff --git a/drivers/net/wireless/ath/ath10k/wmi.h b/drivers/net/wireless/ath/ath10k/wmi.h -index 3ef4688..f67cc19 100644 ---- a/drivers/net/wireless/ath/ath10k/wmi.h -+++ b/drivers/net/wireless/ath/ath10k/wmi.h -@@ -180,6 +180,7 @@ enum wmi_service { - WMI_SERVICE_MESH_NON_11S, - WMI_SERVICE_PEER_STATS, - WMI_SERVICE_RESTRT_CHNL_SUPPORT, -+ WMI_SERVICE_PERIODIC_CHAN_STAT_SUPPORT, - WMI_SERVICE_TX_MODE_PUSH_ONLY, - WMI_SERVICE_TX_MODE_PUSH_PULL, - WMI_SERVICE_TX_MODE_DYNAMIC, -@@ -305,6 +306,7 @@ enum wmi_10_4_service { - WMI_10_4_SERVICE_RESTRT_CHNL_SUPPORT, - WMI_10_4_SERVICE_PEER_STATS, - WMI_10_4_SERVICE_MESH_11S, -+ WMI_10_4_SERVICE_PERIODIC_CHAN_STAT_SUPPORT, - WMI_10_4_SERVICE_TX_MODE_PUSH_ONLY, - WMI_10_4_SERVICE_TX_MODE_PUSH_PULL, - WMI_10_4_SERVICE_TX_MODE_DYNAMIC, -@@ -402,6 +404,7 @@ static inline char *wmi_service_name(int service_id) - SVCSTR(WMI_SERVICE_MESH_NON_11S); - SVCSTR(WMI_SERVICE_PEER_STATS); - SVCSTR(WMI_SERVICE_RESTRT_CHNL_SUPPORT); -+ SVCSTR(WMI_SERVICE_PERIODIC_CHAN_STAT_SUPPORT); - SVCSTR(WMI_SERVICE_TX_MODE_PUSH_ONLY); - SVCSTR(WMI_SERVICE_TX_MODE_PUSH_PULL); - SVCSTR(WMI_SERVICE_TX_MODE_DYNAMIC); -@@ -652,6 +655,8 @@ static inline void wmi_10_4_svc_map(const __le32 *in, unsigned long *out, - WMI_SERVICE_PEER_STATS, len); - SVCMAP(WMI_10_4_SERVICE_MESH_11S, - WMI_SERVICE_MESH_11S, len); -+ SVCMAP(WMI_10_4_SERVICE_PERIODIC_CHAN_STAT_SUPPORT, -+ WMI_SERVICE_PERIODIC_CHAN_STAT_SUPPORT, len); - SVCMAP(WMI_10_4_SERVICE_TX_MODE_PUSH_ONLY, - WMI_SERVICE_TX_MODE_PUSH_ONLY, len); - SVCMAP(WMI_10_4_SERVICE_TX_MODE_PUSH_PULL, -diff --git a/drivers/net/wireless/intel/iwlwifi/iwl-nvm-parse.c b/drivers/net/wireless/intel/iwlwifi/iwl-nvm-parse.c -index 43f8f7d..adba3b0 100644 ---- a/drivers/net/wireless/intel/iwlwifi/iwl-nvm-parse.c -+++ b/drivers/net/wireless/intel/iwlwifi/iwl-nvm-parse.c -@@ -564,11 +564,16 @@ static void iwl_set_hw_address_from_csr(struct iwl_trans *trans, - __le32 mac_addr0 = cpu_to_le32(iwl_read32(trans, CSR_MAC_ADDR0_STRAP)); - __le32 mac_addr1 = cpu_to_le32(iwl_read32(trans, CSR_MAC_ADDR1_STRAP)); - -- /* If OEM did not fuse address - get it from OTP */ -- if (!mac_addr0 && !mac_addr1) { -- mac_addr0 = cpu_to_le32(iwl_read32(trans, CSR_MAC_ADDR0_OTP)); -- mac_addr1 = cpu_to_le32(iwl_read32(trans, CSR_MAC_ADDR1_OTP)); -- } -+ iwl_flip_hw_address(mac_addr0, mac_addr1, data->hw_addr); -+ /* -+ * If the OEM fused a valid address, use it instead of the one in the -+ * OTP -+ */ -+ if (is_valid_ether_addr(data->hw_addr)) -+ return; -+ -+ mac_addr0 = cpu_to_le32(iwl_read32(trans, CSR_MAC_ADDR0_OTP)); -+ mac_addr1 = cpu_to_le32(iwl_read32(trans, CSR_MAC_ADDR1_OTP)); - - iwl_flip_hw_address(mac_addr0, mac_addr1, data->hw_addr); - } -diff --git a/drivers/net/wireless/intel/iwlwifi/mvm/fw.c b/drivers/net/wireless/intel/iwlwifi/mvm/fw.c -index 7e0cdbf..794c574 100644 ---- a/drivers/net/wireless/intel/iwlwifi/mvm/fw.c -+++ b/drivers/net/wireless/intel/iwlwifi/mvm/fw.c -@@ -1214,9 +1214,12 @@ int iwl_mvm_up(struct iwl_mvm *mvm) - } - - /* TODO: read the budget from BIOS / Platform NVM */ -- if (iwl_mvm_is_ctdp_supported(mvm) && mvm->cooling_dev.cur_state > 0) -+ if (iwl_mvm_is_ctdp_supported(mvm) && mvm->cooling_dev.cur_state > 0) { - ret = iwl_mvm_ctdp_command(mvm, CTDP_CMD_OPERATION_START, - mvm->cooling_dev.cur_state); -+ if (ret) -+ goto error; -+ } - #else - /* Initialize tx backoffs to the minimal possible */ - iwl_mvm_tt_tx_backoff(mvm, 0); -diff --git a/drivers/net/wireless/intel/iwlwifi/mvm/mac-ctxt.c b/drivers/net/wireless/intel/iwlwifi/mvm/mac-ctxt.c -index 69c42ce..d742d27 100644 ---- a/drivers/net/wireless/intel/iwlwifi/mvm/mac-ctxt.c -+++ b/drivers/net/wireless/intel/iwlwifi/mvm/mac-ctxt.c -@@ -539,6 +539,11 @@ void iwl_mvm_mac_ctxt_release(struct iwl_mvm *mvm, struct ieee80211_vif *vif) - iwl_mvm_disable_txq(mvm, IWL_MVM_OFFCHANNEL_QUEUE, - IWL_MVM_OFFCHANNEL_QUEUE, - IWL_MAX_TID_COUNT, 0); -+ else -+ iwl_mvm_disable_txq(mvm, -+ IWL_MVM_DQA_P2P_DEVICE_QUEUE, -+ vif->hw_queue[0], IWL_MAX_TID_COUNT, -+ 0); - - break; - case NL80211_IFTYPE_AP: -diff --git a/drivers/net/wireless/intel/iwlwifi/mvm/rxmq.c b/drivers/net/wireless/intel/iwlwifi/mvm/rxmq.c -index df6c32c..afb7eb6 100644 ---- a/drivers/net/wireless/intel/iwlwifi/mvm/rxmq.c -+++ b/drivers/net/wireless/intel/iwlwifi/mvm/rxmq.c -@@ -598,9 +598,10 @@ static bool iwl_mvm_reorder(struct iwl_mvm *mvm, - - mvm_sta = iwl_mvm_sta_from_mac80211(sta); - -- /* not a data packet */ -- if (!ieee80211_is_data_qos(hdr->frame_control) || -- is_multicast_ether_addr(hdr->addr1)) -+ /* not a data packet or a bar */ -+ if (!ieee80211_is_back_req(hdr->frame_control) && -+ (!ieee80211_is_data_qos(hdr->frame_control) || -+ is_multicast_ether_addr(hdr->addr1))) - return false; - - if (unlikely(!ieee80211_is_data_present(hdr->frame_control))) -@@ -624,6 +625,11 @@ static bool iwl_mvm_reorder(struct iwl_mvm *mvm, - - spin_lock_bh(&buffer->lock); - -+ if (ieee80211_is_back_req(hdr->frame_control)) { -+ iwl_mvm_release_frames(mvm, sta, napi, buffer, nssn); -+ goto drop; -+ } -+ - /* - * If there was a significant jump in the nssn - adjust. - * If the SN is smaller than the NSSN it might need to first go into -diff --git a/drivers/net/wireless/intel/iwlwifi/mvm/sta.c b/drivers/net/wireless/intel/iwlwifi/mvm/sta.c -index 3130b9c..e933c12 100644 ---- a/drivers/net/wireless/intel/iwlwifi/mvm/sta.c -+++ b/drivers/net/wireless/intel/iwlwifi/mvm/sta.c -@@ -576,9 +576,7 @@ static int iwl_mvm_scd_queue_redirect(struct iwl_mvm *mvm, int queue, int tid, - ret); - - /* Make sure the SCD wrptr is correctly set before reconfiguring */ -- iwl_trans_txq_enable(mvm->trans, queue, iwl_mvm_ac_to_tx_fifo[ac], -- cmd.sta_id, tid, LINK_QUAL_AGG_FRAME_LIMIT_DEF, -- ssn, wdg_timeout); -+ iwl_trans_txq_enable_cfg(mvm->trans, queue, ssn, NULL, wdg_timeout); - - /* TODO: Work-around SCD bug when moving back by multiples of 0x40 */ - -@@ -1270,9 +1268,31 @@ int iwl_mvm_rm_sta(struct iwl_mvm *mvm, - ret = iwl_mvm_drain_sta(mvm, mvm_sta, false); - - /* If DQA is supported - the queues can be disabled now */ -- if (iwl_mvm_is_dqa_supported(mvm)) -+ if (iwl_mvm_is_dqa_supported(mvm)) { -+ u8 reserved_txq = mvm_sta->reserved_queue; -+ enum iwl_mvm_queue_status *status; -+ - iwl_mvm_disable_sta_queues(mvm, vif, mvm_sta); - -+ /* -+ * If no traffic has gone through the reserved TXQ - it -+ * is still marked as IWL_MVM_QUEUE_RESERVED, and -+ * should be manually marked as free again -+ */ -+ spin_lock_bh(&mvm->queue_info_lock); -+ status = &mvm->queue_info[reserved_txq].status; -+ if (WARN((*status != IWL_MVM_QUEUE_RESERVED) && -+ (*status != IWL_MVM_QUEUE_FREE), -+ "sta_id %d reserved txq %d status %d", -+ mvm_sta->sta_id, reserved_txq, *status)) { -+ spin_unlock_bh(&mvm->queue_info_lock); -+ return -EINVAL; -+ } -+ -+ *status = IWL_MVM_QUEUE_FREE; -+ spin_unlock_bh(&mvm->queue_info_lock); -+ } -+ - if (vif->type == NL80211_IFTYPE_STATION && - mvmvif->ap_sta_id == mvm_sta->sta_id) { - /* if associated - we can't remove the AP STA now */ -diff --git a/drivers/net/wireless/intel/iwlwifi/mvm/tx.c b/drivers/net/wireless/intel/iwlwifi/mvm/tx.c -index b3a87a3..a0c1e3d 100644 ---- a/drivers/net/wireless/intel/iwlwifi/mvm/tx.c -+++ b/drivers/net/wireless/intel/iwlwifi/mvm/tx.c -@@ -903,9 +903,13 @@ static int iwl_mvm_tx_mpdu(struct iwl_mvm *mvm, struct sk_buff *skb, - tid = IWL_MAX_TID_COUNT; - } - -- if (iwl_mvm_is_dqa_supported(mvm)) -+ if (iwl_mvm_is_dqa_supported(mvm)) { - txq_id = mvmsta->tid_data[tid].txq_id; - -+ if (ieee80211_is_mgmt(fc)) -+ tx_cmd->tid_tspec = IWL_TID_NON_QOS; -+ } -+ - /* Copy MAC header from skb into command buffer */ - memcpy(tx_cmd->hdr, hdr, hdrlen); - -diff --git a/drivers/net/wireless/marvell/mwifiex/join.c b/drivers/net/wireless/marvell/mwifiex/join.c -index 1c7b006..b89596c 100644 ---- a/drivers/net/wireless/marvell/mwifiex/join.c -+++ b/drivers/net/wireless/marvell/mwifiex/join.c -@@ -669,9 +669,8 @@ int mwifiex_ret_802_11_associate(struct mwifiex_private *priv, - priv->assoc_rsp_size = min(le16_to_cpu(resp->size) - S_DS_GEN, - sizeof(priv->assoc_rsp_buf)); - -- memcpy(priv->assoc_rsp_buf, &resp->params, priv->assoc_rsp_size); -- - assoc_rsp->a_id = cpu_to_le16(aid); -+ memcpy(priv->assoc_rsp_buf, &resp->params, priv->assoc_rsp_size); - - if (status_code) { - priv->adapter->dbg.num_cmd_assoc_failure++; -diff --git a/drivers/net/wireless/marvell/mwifiex/sta_event.c b/drivers/net/wireless/marvell/mwifiex/sta_event.c -index a422f33..7e394d4 100644 ---- a/drivers/net/wireless/marvell/mwifiex/sta_event.c -+++ b/drivers/net/wireless/marvell/mwifiex/sta_event.c -@@ -708,7 +708,11 @@ int mwifiex_process_sta_event(struct mwifiex_private *priv) - - case EVENT_EXT_SCAN_REPORT: - mwifiex_dbg(adapter, EVENT, "event: EXT_SCAN Report\n"); -- if (adapter->ext_scan && !priv->scan_aborting) -+ /* We intend to skip this event during suspend, but handle -+ * it in interface disabled case -+ */ -+ if (adapter->ext_scan && (!priv->scan_aborting || -+ !netif_running(priv->netdev))) - ret = mwifiex_handle_event_ext_scan_report(priv, - adapter->event_skb->data); - -diff --git a/drivers/net/wireless/ralink/rt2x00/rt2x00usb.c b/drivers/net/wireless/ralink/rt2x00/rt2x00usb.c -index 7cf26c6..6005e14 100644 ---- a/drivers/net/wireless/ralink/rt2x00/rt2x00usb.c -+++ b/drivers/net/wireless/ralink/rt2x00/rt2x00usb.c -@@ -831,8 +831,10 @@ int rt2x00usb_probe(struct usb_interface *usb_intf, - rt2x00dev->anchor = devm_kmalloc(&usb_dev->dev, - sizeof(struct usb_anchor), - GFP_KERNEL); -- if (!rt2x00dev->anchor) -+ if (!rt2x00dev->anchor) { -+ retval = -ENOMEM; - goto exit_free_reg; -+ } - - init_usb_anchor(rt2x00dev->anchor); - return 0; -diff --git a/drivers/nvdimm/bus.c b/drivers/nvdimm/bus.c -index 935866f..a8b6949 100644 ---- a/drivers/nvdimm/bus.c -+++ b/drivers/nvdimm/bus.c -@@ -217,6 +217,8 @@ long nvdimm_clear_poison(struct device *dev, phys_addr_t phys, - return rc; - if (cmd_rc < 0) - return cmd_rc; -+ -+ nvdimm_clear_from_poison_list(nvdimm_bus, phys, len); - return clear_err.cleared; - } - EXPORT_SYMBOL_GPL(nvdimm_clear_poison); -diff --git a/drivers/nvdimm/core.c b/drivers/nvdimm/core.c -index 4d7bbd2..7ceba08 100644 ---- a/drivers/nvdimm/core.c -+++ b/drivers/nvdimm/core.c -@@ -547,11 +547,12 @@ void nvdimm_badblocks_populate(struct nd_region *nd_region, - } - EXPORT_SYMBOL_GPL(nvdimm_badblocks_populate); - --static int add_poison(struct nvdimm_bus *nvdimm_bus, u64 addr, u64 length) -+static int add_poison(struct nvdimm_bus *nvdimm_bus, u64 addr, u64 length, -+ gfp_t flags) - { - struct nd_poison *pl; - -- pl = kzalloc(sizeof(*pl), GFP_KERNEL); -+ pl = kzalloc(sizeof(*pl), flags); - if (!pl) - return -ENOMEM; - -@@ -567,7 +568,7 @@ static int bus_add_poison(struct nvdimm_bus *nvdimm_bus, u64 addr, u64 length) - struct nd_poison *pl; - - if (list_empty(&nvdimm_bus->poison_list)) -- return add_poison(nvdimm_bus, addr, length); -+ return add_poison(nvdimm_bus, addr, length, GFP_KERNEL); - - /* - * There is a chance this is a duplicate, check for those first. -@@ -587,7 +588,7 @@ static int bus_add_poison(struct nvdimm_bus *nvdimm_bus, u64 addr, u64 length) - * as any overlapping ranges will get resolved when the list is consumed - * and converted to badblocks - */ -- return add_poison(nvdimm_bus, addr, length); -+ return add_poison(nvdimm_bus, addr, length, GFP_KERNEL); - } - - int nvdimm_bus_add_poison(struct nvdimm_bus *nvdimm_bus, u64 addr, u64 length) -@@ -602,6 +603,70 @@ int nvdimm_bus_add_poison(struct nvdimm_bus *nvdimm_bus, u64 addr, u64 length) - } - EXPORT_SYMBOL_GPL(nvdimm_bus_add_poison); - -+void nvdimm_clear_from_poison_list(struct nvdimm_bus *nvdimm_bus, -+ phys_addr_t start, unsigned int len) -+{ -+ struct list_head *poison_list = &nvdimm_bus->poison_list; -+ u64 clr_end = start + len - 1; -+ struct nd_poison *pl, *next; -+ -+ nvdimm_bus_lock(&nvdimm_bus->dev); -+ WARN_ON_ONCE(list_empty(poison_list)); -+ -+ /* -+ * [start, clr_end] is the poison interval being cleared. -+ * [pl->start, pl_end] is the poison_list entry we're comparing -+ * the above interval against. The poison list entry may need -+ * to be modified (update either start or length), deleted, or -+ * split into two based on the overlap characteristics -+ */ -+ -+ list_for_each_entry_safe(pl, next, poison_list, list) { -+ u64 pl_end = pl->start + pl->length - 1; -+ -+ /* Skip intervals with no intersection */ -+ if (pl_end < start) -+ continue; -+ if (pl->start > clr_end) -+ continue; -+ /* Delete completely overlapped poison entries */ -+ if ((pl->start >= start) && (pl_end <= clr_end)) { -+ list_del(&pl->list); -+ kfree(pl); -+ continue; -+ } -+ /* Adjust start point of partially cleared entries */ -+ if ((start <= pl->start) && (clr_end > pl->start)) { -+ pl->length -= clr_end - pl->start + 1; -+ pl->start = clr_end + 1; -+ continue; -+ } -+ /* Adjust pl->length for partial clearing at the tail end */ -+ if ((pl->start < start) && (pl_end <= clr_end)) { -+ /* pl->start remains the same */ -+ pl->length = start - pl->start; -+ continue; -+ } -+ /* -+ * If clearing in the middle of an entry, we split it into -+ * two by modifying the current entry to represent one half of -+ * the split, and adding a new entry for the second half. -+ */ -+ if ((pl->start < start) && (pl_end > clr_end)) { -+ u64 new_start = clr_end + 1; -+ u64 new_len = pl_end - new_start + 1; -+ -+ /* Add new entry covering the right half */ -+ add_poison(nvdimm_bus, new_start, new_len, GFP_NOIO); -+ /* Adjust this entry to cover the left half */ -+ pl->length = start - pl->start; -+ continue; -+ } -+ } -+ nvdimm_bus_unlock(&nvdimm_bus->dev); -+} -+EXPORT_SYMBOL_GPL(nvdimm_clear_from_poison_list); -+ - #ifdef CONFIG_BLK_DEV_INTEGRITY - int nd_integrity_init(struct gendisk *disk, unsigned long meta_size) - { -diff --git a/drivers/pci/host/pci-aardvark.c b/drivers/pci/host/pci-aardvark.c -index ef9893f..4f5e567 100644 ---- a/drivers/pci/host/pci-aardvark.c -+++ b/drivers/pci/host/pci-aardvark.c -@@ -848,7 +848,7 @@ static int advk_pcie_parse_request_of_pci_ranges(struct advk_pcie *pcie) - int err, res_valid = 0; - struct device *dev = &pcie->pdev->dev; - struct device_node *np = dev->of_node; -- struct resource_entry *win; -+ struct resource_entry *win, *tmp; - resource_size_t iobase; - - INIT_LIST_HEAD(&pcie->resources); -@@ -862,7 +862,7 @@ static int advk_pcie_parse_request_of_pci_ranges(struct advk_pcie *pcie) - if (err) - goto out_release_res; - -- resource_list_for_each_entry(win, &pcie->resources) { -+ resource_list_for_each_entry_safe(win, tmp, &pcie->resources) { - struct resource *res = win->res; - - switch (resource_type(res)) { -@@ -874,9 +874,11 @@ static int advk_pcie_parse_request_of_pci_ranges(struct advk_pcie *pcie) - lower_32_bits(res->start), - OB_PCIE_IO); - err = pci_remap_iospace(res, iobase); -- if (err) -+ if (err) { - dev_warn(dev, "error %d: failed to map resource %pR\n", - err, res); -+ resource_list_destroy_entry(win); -+ } - break; - case IORESOURCE_MEM: - advk_pcie_set_ob_win(pcie, 0, -diff --git a/drivers/pci/host/pci-host-common.c b/drivers/pci/host/pci-host-common.c -index 9d9d34e..61eb4d4 100644 ---- a/drivers/pci/host/pci-host-common.c -+++ b/drivers/pci/host/pci-host-common.c -@@ -29,7 +29,7 @@ static int gen_pci_parse_request_of_pci_ranges(struct device *dev, - int err, res_valid = 0; - struct device_node *np = dev->of_node; - resource_size_t iobase; -- struct resource_entry *win; -+ struct resource_entry *win, *tmp; - - err = of_pci_get_host_bridge_resources(np, 0, 0xff, resources, &iobase); - if (err) -@@ -39,15 +39,17 @@ static int gen_pci_parse_request_of_pci_ranges(struct device *dev, - if (err) - return err; - -- resource_list_for_each_entry(win, resources) { -+ resource_list_for_each_entry_safe(win, tmp, resources) { - struct resource *res = win->res; - - switch (resource_type(res)) { - case IORESOURCE_IO: - err = pci_remap_iospace(res, iobase); -- if (err) -+ if (err) { - dev_warn(dev, "error %d: failed to map resource %pR\n", - err, res); -+ resource_list_destroy_entry(win); -+ } - break; - case IORESOURCE_MEM: - res_valid |= !(res->flags & IORESOURCE_PREFETCH); -diff --git a/drivers/pci/host/pci-tegra.c b/drivers/pci/host/pci-tegra.c -index 84d650d..7ec1e80 100644 ---- a/drivers/pci/host/pci-tegra.c -+++ b/drivers/pci/host/pci-tegra.c -@@ -621,7 +621,11 @@ static int tegra_pcie_setup(int nr, struct pci_sys_data *sys) - if (err < 0) - return err; - -- pci_add_resource_offset(&sys->resources, &pcie->pio, sys->io_offset); -+ err = pci_remap_iospace(&pcie->pio, pcie->io.start); -+ if (!err) -+ pci_add_resource_offset(&sys->resources, &pcie->pio, -+ sys->io_offset); -+ - pci_add_resource_offset(&sys->resources, &pcie->mem, sys->mem_offset); - pci_add_resource_offset(&sys->resources, &pcie->prefetch, - sys->mem_offset); -@@ -631,7 +635,6 @@ static int tegra_pcie_setup(int nr, struct pci_sys_data *sys) - if (err < 0) - return err; - -- pci_remap_iospace(&pcie->pio, pcie->io.start); - return 1; - } - -diff --git a/drivers/pci/host/pci-versatile.c b/drivers/pci/host/pci-versatile.c -index f2344057..b7dc070 100644 ---- a/drivers/pci/host/pci-versatile.c -+++ b/drivers/pci/host/pci-versatile.c -@@ -74,7 +74,7 @@ static int versatile_pci_parse_request_of_pci_ranges(struct device *dev, - int err, mem = 1, res_valid = 0; - struct device_node *np = dev->of_node; - resource_size_t iobase; -- struct resource_entry *win; -+ struct resource_entry *win, *tmp; - - err = of_pci_get_host_bridge_resources(np, 0, 0xff, res, &iobase); - if (err) -@@ -84,15 +84,17 @@ static int versatile_pci_parse_request_of_pci_ranges(struct device *dev, - if (err) - goto out_release_res; - -- resource_list_for_each_entry(win, res) { -+ resource_list_for_each_entry_safe(win, tmp, res) { - struct resource *res = win->res; - - switch (resource_type(res)) { - case IORESOURCE_IO: - err = pci_remap_iospace(res, iobase); -- if (err) -+ if (err) { - dev_warn(dev, "error %d: failed to map resource %pR\n", - err, res); -+ resource_list_destroy_entry(win); -+ } - break; - case IORESOURCE_MEM: - res_valid |= !(res->flags & IORESOURCE_PREFETCH); -diff --git a/drivers/pci/host/pcie-designware.c b/drivers/pci/host/pcie-designware.c -index 12afce1..2a500f2 100644 ---- a/drivers/pci/host/pcie-designware.c -+++ b/drivers/pci/host/pcie-designware.c -@@ -436,7 +436,7 @@ int dw_pcie_host_init(struct pcie_port *pp) - struct resource *cfg_res; - int i, ret; - LIST_HEAD(res); -- struct resource_entry *win; -+ struct resource_entry *win, *tmp; - - cfg_res = platform_get_resource_byname(pdev, IORESOURCE_MEM, "config"); - if (cfg_res) { -@@ -457,17 +457,20 @@ int dw_pcie_host_init(struct pcie_port *pp) - goto error; - - /* Get the I/O and memory ranges from DT */ -- resource_list_for_each_entry(win, &res) { -+ resource_list_for_each_entry_safe(win, tmp, &res) { - switch (resource_type(win->res)) { - case IORESOURCE_IO: -- pp->io = win->res; -- pp->io->name = "I/O"; -- pp->io_size = resource_size(pp->io); -- pp->io_bus_addr = pp->io->start - win->offset; -- ret = pci_remap_iospace(pp->io, pp->io_base); -- if (ret) -+ ret = pci_remap_iospace(win->res, pp->io_base); -+ if (ret) { - dev_warn(pp->dev, "error %d: failed to map resource %pR\n", -- ret, pp->io); -+ ret, win->res); -+ resource_list_destroy_entry(win); -+ } else { -+ pp->io = win->res; -+ pp->io->name = "I/O"; -+ pp->io_size = resource_size(pp->io); -+ pp->io_bus_addr = pp->io->start - win->offset; -+ } - break; - case IORESOURCE_MEM: - pp->mem = win->res; -diff --git a/drivers/pci/host/pcie-rcar.c b/drivers/pci/host/pcie-rcar.c -index 65db7a2..5f7fcc9 100644 ---- a/drivers/pci/host/pcie-rcar.c -+++ b/drivers/pci/host/pcie-rcar.c -@@ -945,7 +945,7 @@ static int rcar_pcie_parse_request_of_pci_ranges(struct rcar_pcie *pci) - struct device *dev = pci->dev; - struct device_node *np = dev->of_node; - resource_size_t iobase; -- struct resource_entry *win; -+ struct resource_entry *win, *tmp; - - err = of_pci_get_host_bridge_resources(np, 0, 0xff, &pci->resources, &iobase); - if (err) -@@ -955,14 +955,17 @@ static int rcar_pcie_parse_request_of_pci_ranges(struct rcar_pcie *pci) - if (err) - goto out_release_res; - -- resource_list_for_each_entry(win, &pci->resources) { -+ resource_list_for_each_entry_safe(win, tmp, &pci->resources) { - struct resource *res = win->res; - - if (resource_type(res) == IORESOURCE_IO) { - err = pci_remap_iospace(res, iobase); -- if (err) -+ if (err) { - dev_warn(dev, "error %d: failed to map resource %pR\n", - err, res); -+ -+ resource_list_destroy_entry(win); -+ } - } - } - -diff --git a/drivers/pinctrl/qcom/pinctrl-msm.c b/drivers/pinctrl/qcom/pinctrl-msm.c -index 51c42d7..775c883 100644 ---- a/drivers/pinctrl/qcom/pinctrl-msm.c -+++ b/drivers/pinctrl/qcom/pinctrl-msm.c -@@ -156,7 +156,7 @@ static int msm_pinmux_set_mux(struct pinctrl_dev *pctldev, - spin_lock_irqsave(&pctrl->lock, flags); - - val = readl(pctrl->regs + g->ctl_reg); -- val &= mask; -+ val &= ~mask; - val |= i << g->mux_bit; - writel(val, pctrl->regs + g->ctl_reg); - -diff --git a/drivers/power/bq24257_charger.c b/drivers/power/bq24257_charger.c -index 1fea2c7..6fc31bd 100644 ---- a/drivers/power/bq24257_charger.c -+++ b/drivers/power/bq24257_charger.c -@@ -1068,6 +1068,12 @@ static int bq24257_probe(struct i2c_client *client, - return ret; - } - -+ ret = bq24257_power_supply_init(bq); -+ if (ret < 0) { -+ dev_err(dev, "Failed to register power supply\n"); -+ return ret; -+ } -+ - ret = devm_request_threaded_irq(dev, client->irq, NULL, - bq24257_irq_handler_thread, - IRQF_TRIGGER_FALLING | -@@ -1078,12 +1084,6 @@ static int bq24257_probe(struct i2c_client *client, - return ret; - } - -- ret = bq24257_power_supply_init(bq); -- if (ret < 0) { -- dev_err(dev, "Failed to register power supply\n"); -- return ret; -- } -- - ret = sysfs_create_group(&bq->charger->dev.kobj, &bq24257_attr_group); - if (ret < 0) { - dev_err(dev, "Can't create sysfs entries\n"); -diff --git a/drivers/s390/char/con3270.c b/drivers/s390/char/con3270.c -index 6b1577c..285b400 100644 ---- a/drivers/s390/char/con3270.c -+++ b/drivers/s390/char/con3270.c -@@ -124,7 +124,12 @@ con3270_create_status(struct con3270 *cp) - static void - con3270_update_string(struct con3270 *cp, struct string *s, int nr) - { -- if (s->len >= cp->view.cols - 5) -+ if (s->len < 4) { -+ /* This indicates a bug, but printing a warning would -+ * cause a deadlock. */ -+ return; -+ } -+ if (s->string[s->len - 4] != TO_RA) - return; - raw3270_buffer_address(cp->view.dev, s->string + s->len - 3, - cp->view.cols * (nr + 1)); -@@ -460,11 +465,11 @@ con3270_cline_end(struct con3270 *cp) - cp->cline->len + 4 : cp->view.cols; - s = con3270_alloc_string(cp, size); - memcpy(s->string, cp->cline->string, cp->cline->len); -- if (s->len < cp->view.cols - 5) { -+ if (cp->cline->len < cp->view.cols - 5) { - s->string[s->len - 4] = TO_RA; - s->string[s->len - 1] = 0; - } else { -- while (--size > cp->cline->len) -+ while (--size >= cp->cline->len) - s->string[size] = cp->view.ascebc[' ']; - } - /* Replace cline with allocated line s and reset cline. */ -diff --git a/drivers/s390/cio/chsc.c b/drivers/s390/cio/chsc.c -index 940e725..1167469 100644 ---- a/drivers/s390/cio/chsc.c -+++ b/drivers/s390/cio/chsc.c -@@ -95,12 +95,13 @@ struct chsc_ssd_area { - int chsc_get_ssd_info(struct subchannel_id schid, struct chsc_ssd_info *ssd) - { - struct chsc_ssd_area *ssd_area; -+ unsigned long flags; - int ccode; - int ret; - int i; - int mask; - -- spin_lock_irq(&chsc_page_lock); -+ spin_lock_irqsave(&chsc_page_lock, flags); - memset(chsc_page, 0, PAGE_SIZE); - ssd_area = chsc_page; - ssd_area->request.length = 0x0010; -@@ -144,7 +145,7 @@ int chsc_get_ssd_info(struct subchannel_id schid, struct chsc_ssd_info *ssd) - ssd->fla[i] = ssd_area->fla[i]; - } - out: -- spin_unlock_irq(&chsc_page_lock); -+ spin_unlock_irqrestore(&chsc_page_lock, flags); - return ret; - } - -@@ -832,9 +833,10 @@ int __chsc_do_secm(struct channel_subsystem *css, int enable) - u32 fmt : 4; - u32 : 16; - } __attribute__ ((packed)) *secm_area; -+ unsigned long flags; - int ret, ccode; - -- spin_lock_irq(&chsc_page_lock); -+ spin_lock_irqsave(&chsc_page_lock, flags); - memset(chsc_page, 0, PAGE_SIZE); - secm_area = chsc_page; - secm_area->request.length = 0x0050; -@@ -864,7 +866,7 @@ int __chsc_do_secm(struct channel_subsystem *css, int enable) - CIO_CRW_EVENT(2, "chsc: secm failed (rc=%04x)\n", - secm_area->response.code); - out: -- spin_unlock_irq(&chsc_page_lock); -+ spin_unlock_irqrestore(&chsc_page_lock, flags); - return ret; - } - -@@ -992,6 +994,7 @@ chsc_initialize_cmg_chars(struct channel_path *chp, u8 cmcv, - - int chsc_get_channel_measurement_chars(struct channel_path *chp) - { -+ unsigned long flags; - int ccode, ret; - - struct { -@@ -1021,7 +1024,7 @@ int chsc_get_channel_measurement_chars(struct channel_path *chp) - if (!css_chsc_characteristics.scmc || !css_chsc_characteristics.secm) - return -EINVAL; - -- spin_lock_irq(&chsc_page_lock); -+ spin_lock_irqsave(&chsc_page_lock, flags); - memset(chsc_page, 0, PAGE_SIZE); - scmc_area = chsc_page; - scmc_area->request.length = 0x0010; -@@ -1053,7 +1056,7 @@ int chsc_get_channel_measurement_chars(struct channel_path *chp) - chsc_initialize_cmg_chars(chp, scmc_area->cmcv, - (struct cmg_chars *) &scmc_area->data); - out: -- spin_unlock_irq(&chsc_page_lock); -+ spin_unlock_irqrestore(&chsc_page_lock, flags); - return ret; - } - -@@ -1134,6 +1137,7 @@ struct css_chsc_char css_chsc_characteristics; - int __init - chsc_determine_css_characteristics(void) - { -+ unsigned long flags; - int result; - struct { - struct chsc_header request; -@@ -1146,7 +1150,7 @@ chsc_determine_css_characteristics(void) - u32 chsc_char[508]; - } __attribute__ ((packed)) *scsc_area; - -- spin_lock_irq(&chsc_page_lock); -+ spin_lock_irqsave(&chsc_page_lock, flags); - memset(chsc_page, 0, PAGE_SIZE); - scsc_area = chsc_page; - scsc_area->request.length = 0x0010; -@@ -1168,7 +1172,7 @@ chsc_determine_css_characteristics(void) - CIO_CRW_EVENT(2, "chsc: scsc failed (rc=%04x)\n", - scsc_area->response.code); - exit: -- spin_unlock_irq(&chsc_page_lock); -+ spin_unlock_irqrestore(&chsc_page_lock, flags); - return result; - } - -diff --git a/drivers/scsi/cxlflash/main.c b/drivers/scsi/cxlflash/main.c -index 661bb94..228b99e 100644 ---- a/drivers/scsi/cxlflash/main.c -+++ b/drivers/scsi/cxlflash/main.c -@@ -823,17 +823,6 @@ static void notify_shutdown(struct cxlflash_cfg *cfg, bool wait) - } - - /** -- * cxlflash_shutdown() - shutdown handler -- * @pdev: PCI device associated with the host. -- */ --static void cxlflash_shutdown(struct pci_dev *pdev) --{ -- struct cxlflash_cfg *cfg = pci_get_drvdata(pdev); -- -- notify_shutdown(cfg, false); --} -- --/** - * cxlflash_remove() - PCI entry point to tear down host - * @pdev: PCI device associated with the host. - * -@@ -844,6 +833,11 @@ static void cxlflash_remove(struct pci_dev *pdev) - struct cxlflash_cfg *cfg = pci_get_drvdata(pdev); - ulong lock_flags; - -+ if (!pci_is_enabled(pdev)) { -+ pr_debug("%s: Device is disabled\n", __func__); -+ return; -+ } -+ - /* If a Task Management Function is active, wait for it to complete - * before continuing with remove. - */ -@@ -2685,7 +2679,7 @@ static struct pci_driver cxlflash_driver = { - .id_table = cxlflash_pci_table, - .probe = cxlflash_probe, - .remove = cxlflash_remove, -- .shutdown = cxlflash_shutdown, -+ .shutdown = cxlflash_remove, - .err_handler = &cxlflash_err_handler, - }; - -diff --git a/drivers/scsi/mpt3sas/mpt3sas_scsih.c b/drivers/scsi/mpt3sas/mpt3sas_scsih.c -index cd91a68..4cb7990 100644 ---- a/drivers/scsi/mpt3sas/mpt3sas_scsih.c -+++ b/drivers/scsi/mpt3sas/mpt3sas_scsih.c -@@ -4701,7 +4701,7 @@ _scsih_io_done(struct MPT3SAS_ADAPTER *ioc, u16 smid, u8 msix_index, u32 reply) - le16_to_cpu(mpi_reply->DevHandle)); - mpt3sas_trigger_scsi(ioc, data.skey, data.asc, data.ascq); - -- if (!(ioc->logging_level & MPT_DEBUG_REPLY) && -+ if ((ioc->logging_level & MPT_DEBUG_REPLY) && - ((scmd->sense_buffer[2] == UNIT_ATTENTION) || - (scmd->sense_buffer[2] == MEDIUM_ERROR) || - (scmd->sense_buffer[2] == HARDWARE_ERROR))) -diff --git a/drivers/spi/spi-fsl-dspi.c b/drivers/spi/spi-fsl-dspi.c -index 9e9dadb..eec5e3f 100644 ---- a/drivers/spi/spi-fsl-dspi.c -+++ b/drivers/spi/spi-fsl-dspi.c -@@ -760,7 +760,6 @@ static int dspi_remove(struct platform_device *pdev) - /* Disconnect from the SPI framework */ - clk_disable_unprepare(dspi->clk); - spi_unregister_master(dspi->master); -- spi_master_put(dspi->master); - - return 0; - } -diff --git a/drivers/staging/android/ion/Kconfig b/drivers/staging/android/ion/Kconfig -index 19c1572..800245e 100644 ---- a/drivers/staging/android/ion/Kconfig -+++ b/drivers/staging/android/ion/Kconfig -@@ -36,6 +36,7 @@ config ION_TEGRA - config ION_HISI - tristate "Ion for Hisilicon" - depends on ARCH_HISI && ION -+ select ION_OF - help - Choose this option if you wish to use ion on Hisilicon Platform. - -diff --git a/drivers/staging/ks7010/ks_hostif.c b/drivers/staging/ks7010/ks_hostif.c -index a8822fe..f4cee81 100644 ---- a/drivers/staging/ks7010/ks_hostif.c -+++ b/drivers/staging/ks7010/ks_hostif.c -@@ -69,16 +69,20 @@ inline u32 get_DWORD(struct ks_wlan_private *priv) - return data; - } - --void ks_wlan_hw_wakeup_task(struct work_struct *work) -+static void ks_wlan_hw_wakeup_task(struct work_struct *work) - { - struct ks_wlan_private *priv = - container_of(work, struct ks_wlan_private, ks_wlan_wakeup_task); - int ps_status = atomic_read(&priv->psstatus.status); -+ long time_left; - - if (ps_status == PS_SNOOZE) { - ks_wlan_hw_wakeup_request(priv); -- if (!wait_for_completion_interruptible_timeout(&priv->psstatus.wakeup_wait, HZ / 50)) { /* 20ms timeout */ -- DPRINTK(1, "wake up timeout !!!\n"); -+ time_left = wait_for_completion_interruptible_timeout( -+ &priv->psstatus.wakeup_wait, -+ msecs_to_jiffies(20)); -+ if (time_left <= 0) { -+ DPRINTK(1, "wake up timeout or interrupted !!!\n"); - schedule_work(&priv->ks_wlan_wakeup_task); - return; - } -@@ -1505,7 +1509,7 @@ void hostif_infrastructure_set_request(struct ks_wlan_private *priv) - ks_wlan_hw_tx(priv, pp, hif_align_size(sizeof(*pp)), NULL, NULL, NULL); - } - --void hostif_infrastructure_set2_request(struct ks_wlan_private *priv) -+static void hostif_infrastructure_set2_request(struct ks_wlan_private *priv) - { - struct hostif_infrastructure_set2_request_t *pp; - uint16_t capability; -diff --git a/drivers/staging/rtl8188eu/core/rtw_cmd.c b/drivers/staging/rtl8188eu/core/rtw_cmd.c -index 7748523..32d3a9c 100644 ---- a/drivers/staging/rtl8188eu/core/rtw_cmd.c -+++ b/drivers/staging/rtl8188eu/core/rtw_cmd.c -@@ -670,13 +670,13 @@ u8 rtw_addbareq_cmd(struct adapter *padapter, u8 tid, u8 *addr) - u8 res = _SUCCESS; - - -- ph2c = kzalloc(sizeof(struct cmd_obj), GFP_KERNEL); -+ ph2c = kzalloc(sizeof(struct cmd_obj), GFP_ATOMIC); - if (!ph2c) { - res = _FAIL; - goto exit; - } - -- paddbareq_parm = kzalloc(sizeof(struct addBaReq_parm), GFP_KERNEL); -+ paddbareq_parm = kzalloc(sizeof(struct addBaReq_parm), GFP_ATOMIC); - if (!paddbareq_parm) { - kfree(ph2c); - res = _FAIL; -diff --git a/drivers/staging/sm750fb/ddk750_mode.c b/drivers/staging/sm750fb/ddk750_mode.c -index ccb4e06..e29d4bd 100644 ---- a/drivers/staging/sm750fb/ddk750_mode.c -+++ b/drivers/staging/sm750fb/ddk750_mode.c -@@ -63,7 +63,7 @@ static unsigned long displayControlAdjust_SM750LE(mode_parameter_t *pModeParam, - dispControl |= (CRT_DISPLAY_CTRL_CRTSELECT | CRT_DISPLAY_CTRL_RGBBIT); - - /* Set bit 14 of display controller */ -- dispControl = DISPLAY_CTRL_CLOCK_PHASE; -+ dispControl |= DISPLAY_CTRL_CLOCK_PHASE; - - POKE32(CRT_DISPLAY_CTRL, dispControl); - -diff --git a/drivers/uio/uio_dmem_genirq.c b/drivers/uio/uio_dmem_genirq.c -index 915facb..e1134a4 100644 ---- a/drivers/uio/uio_dmem_genirq.c -+++ b/drivers/uio/uio_dmem_genirq.c -@@ -229,7 +229,7 @@ static int uio_dmem_genirq_probe(struct platform_device *pdev) - ++uiomem; - } - -- priv->dmem_region_start = i; -+ priv->dmem_region_start = uiomem - &uioinfo->mem[0]; - priv->num_dmem_regions = pdata->num_dynamic_regions; - - for (i = 0; i < pdata->num_dynamic_regions; ++i) { -diff --git a/fs/9p/acl.c b/fs/9p/acl.c -index 5b6a174..b3c2cc7 100644 ---- a/fs/9p/acl.c -+++ b/fs/9p/acl.c -@@ -276,32 +276,26 @@ static int v9fs_xattr_set_acl(const struct xattr_handler *handler, - switch (handler->flags) { - case ACL_TYPE_ACCESS: - if (acl) { -- umode_t mode = inode->i_mode; -- retval = posix_acl_equiv_mode(acl, &mode); -- if (retval < 0) -+ struct iattr iattr; -+ -+ retval = posix_acl_update_mode(inode, &iattr.ia_mode, &acl); -+ if (retval) - goto err_out; -- else { -- struct iattr iattr; -- if (retval == 0) { -- /* -- * ACL can be represented -- * by the mode bits. So don't -- * update ACL. -- */ -- acl = NULL; -- value = NULL; -- size = 0; -- } -- /* Updte the mode bits */ -- iattr.ia_mode = ((mode & S_IALLUGO) | -- (inode->i_mode & ~S_IALLUGO)); -- iattr.ia_valid = ATTR_MODE; -- /* FIXME should we update ctime ? -- * What is the following setxattr update the -- * mode ? -+ if (!acl) { -+ /* -+ * ACL can be represented -+ * by the mode bits. So don't -+ * update ACL. - */ -- v9fs_vfs_setattr_dotl(dentry, &iattr); -+ value = NULL; -+ size = 0; - } -+ iattr.ia_valid = ATTR_MODE; -+ /* FIXME should we update ctime ? -+ * What is the following setxattr update the -+ * mode ? -+ */ -+ v9fs_vfs_setattr_dotl(dentry, &iattr); - } - break; - case ACL_TYPE_DEFAULT: -diff --git a/fs/btrfs/acl.c b/fs/btrfs/acl.c -index 53bb7af..247b8df 100644 ---- a/fs/btrfs/acl.c -+++ b/fs/btrfs/acl.c -@@ -79,11 +79,9 @@ static int __btrfs_set_acl(struct btrfs_trans_handle *trans, - case ACL_TYPE_ACCESS: - name = XATTR_NAME_POSIX_ACL_ACCESS; - if (acl) { -- ret = posix_acl_equiv_mode(acl, &inode->i_mode); -- if (ret < 0) -+ ret = posix_acl_update_mode(inode, &inode->i_mode, &acl); -+ if (ret) - return ret; -- if (ret == 0) -- acl = NULL; - } - ret = 0; - break; -diff --git a/fs/ceph/acl.c b/fs/ceph/acl.c -index 4f67227..d0b6b342 100644 ---- a/fs/ceph/acl.c -+++ b/fs/ceph/acl.c -@@ -95,11 +95,9 @@ int ceph_set_acl(struct inode *inode, struct posix_acl *acl, int type) - case ACL_TYPE_ACCESS: - name = XATTR_NAME_POSIX_ACL_ACCESS; - if (acl) { -- ret = posix_acl_equiv_mode(acl, &new_mode); -- if (ret < 0) -+ ret = posix_acl_update_mode(inode, &new_mode, &acl); -+ if (ret) - goto out; -- if (ret == 0) -- acl = NULL; - } - break; - case ACL_TYPE_DEFAULT: -diff --git a/fs/ext2/acl.c b/fs/ext2/acl.c -index 42f1d18..e725aa0 100644 ---- a/fs/ext2/acl.c -+++ b/fs/ext2/acl.c -@@ -190,15 +190,11 @@ ext2_set_acl(struct inode *inode, struct posix_acl *acl, int type) - case ACL_TYPE_ACCESS: - name_index = EXT2_XATTR_INDEX_POSIX_ACL_ACCESS; - if (acl) { -- error = posix_acl_equiv_mode(acl, &inode->i_mode); -- if (error < 0) -+ error = posix_acl_update_mode(inode, &inode->i_mode, &acl); -+ if (error) - return error; -- else { -- inode->i_ctime = CURRENT_TIME_SEC; -- mark_inode_dirty(inode); -- if (error == 0) -- acl = NULL; -- } -+ inode->i_ctime = CURRENT_TIME_SEC; -+ mark_inode_dirty(inode); - } - break; - -diff --git a/fs/ext4/acl.c b/fs/ext4/acl.c -index c6601a4..dfa5199 100644 ---- a/fs/ext4/acl.c -+++ b/fs/ext4/acl.c -@@ -193,15 +193,11 @@ __ext4_set_acl(handle_t *handle, struct inode *inode, int type, - case ACL_TYPE_ACCESS: - name_index = EXT4_XATTR_INDEX_POSIX_ACL_ACCESS; - if (acl) { -- error = posix_acl_equiv_mode(acl, &inode->i_mode); -- if (error < 0) -+ error = posix_acl_update_mode(inode, &inode->i_mode, &acl); -+ if (error) - return error; -- else { -- inode->i_ctime = ext4_current_time(inode); -- ext4_mark_inode_dirty(handle, inode); -- if (error == 0) -- acl = NULL; -- } -+ inode->i_ctime = ext4_current_time(inode); -+ ext4_mark_inode_dirty(handle, inode); - } - break; - -diff --git a/fs/f2fs/acl.c b/fs/f2fs/acl.c -index 4dcc9e2..3134424 100644 ---- a/fs/f2fs/acl.c -+++ b/fs/f2fs/acl.c -@@ -210,12 +210,10 @@ static int __f2fs_set_acl(struct inode *inode, int type, - case ACL_TYPE_ACCESS: - name_index = F2FS_XATTR_INDEX_POSIX_ACL_ACCESS; - if (acl) { -- error = posix_acl_equiv_mode(acl, &inode->i_mode); -- if (error < 0) -+ error = posix_acl_update_mode(inode, &inode->i_mode, &acl); -+ if (error) - return error; - set_acl_inode(inode, inode->i_mode); -- if (error == 0) -- acl = NULL; - } - break; - -diff --git a/fs/gfs2/acl.c b/fs/gfs2/acl.c -index 363ba9e..2524807 100644 ---- a/fs/gfs2/acl.c -+++ b/fs/gfs2/acl.c -@@ -92,17 +92,11 @@ int __gfs2_set_acl(struct inode *inode, struct posix_acl *acl, int type) - if (type == ACL_TYPE_ACCESS) { - umode_t mode = inode->i_mode; - -- error = posix_acl_equiv_mode(acl, &mode); -- if (error < 0) -+ error = posix_acl_update_mode(inode, &inode->i_mode, &acl); -+ if (error) - return error; -- -- if (error == 0) -- acl = NULL; -- -- if (mode != inode->i_mode) { -- inode->i_mode = mode; -+ if (mode != inode->i_mode) - mark_inode_dirty(inode); -- } - } - - if (acl) { -diff --git a/fs/hfsplus/posix_acl.c b/fs/hfsplus/posix_acl.c -index ab7ea25..9b92058 100644 ---- a/fs/hfsplus/posix_acl.c -+++ b/fs/hfsplus/posix_acl.c -@@ -65,8 +65,8 @@ int hfsplus_set_posix_acl(struct inode *inode, struct posix_acl *acl, - case ACL_TYPE_ACCESS: - xattr_name = XATTR_NAME_POSIX_ACL_ACCESS; - if (acl) { -- err = posix_acl_equiv_mode(acl, &inode->i_mode); -- if (err < 0) -+ err = posix_acl_update_mode(inode, &inode->i_mode, &acl); -+ if (err) - return err; - } - err = 0; -diff --git a/fs/jffs2/acl.c b/fs/jffs2/acl.c -index bc2693d..2a0f2a1 100644 ---- a/fs/jffs2/acl.c -+++ b/fs/jffs2/acl.c -@@ -233,9 +233,10 @@ int jffs2_set_acl(struct inode *inode, struct posix_acl *acl, int type) - case ACL_TYPE_ACCESS: - xprefix = JFFS2_XPREFIX_ACL_ACCESS; - if (acl) { -- umode_t mode = inode->i_mode; -- rc = posix_acl_equiv_mode(acl, &mode); -- if (rc < 0) -+ umode_t mode; -+ -+ rc = posix_acl_update_mode(inode, &mode, &acl); -+ if (rc) - return rc; - if (inode->i_mode != mode) { - struct iattr attr; -@@ -247,8 +248,6 @@ int jffs2_set_acl(struct inode *inode, struct posix_acl *acl, int type) - if (rc < 0) - return rc; - } -- if (rc == 0) -- acl = NULL; - } - break; - case ACL_TYPE_DEFAULT: -diff --git a/fs/jfs/acl.c b/fs/jfs/acl.c -index 21fa92b..3a1e155 100644 ---- a/fs/jfs/acl.c -+++ b/fs/jfs/acl.c -@@ -78,13 +78,11 @@ static int __jfs_set_acl(tid_t tid, struct inode *inode, int type, - case ACL_TYPE_ACCESS: - ea_name = XATTR_NAME_POSIX_ACL_ACCESS; - if (acl) { -- rc = posix_acl_equiv_mode(acl, &inode->i_mode); -- if (rc < 0) -+ rc = posix_acl_update_mode(inode, &inode->i_mode, &acl); -+ if (rc) - return rc; - inode->i_ctime = CURRENT_TIME; - mark_inode_dirty(inode); -- if (rc == 0) -- acl = NULL; - } - break; - case ACL_TYPE_DEFAULT: -diff --git a/fs/ocfs2/acl.c b/fs/ocfs2/acl.c -index 2162434..164307b 100644 ---- a/fs/ocfs2/acl.c -+++ b/fs/ocfs2/acl.c -@@ -241,13 +241,11 @@ int ocfs2_set_acl(handle_t *handle, - case ACL_TYPE_ACCESS: - name_index = OCFS2_XATTR_INDEX_POSIX_ACL_ACCESS; - if (acl) { -- umode_t mode = inode->i_mode; -- ret = posix_acl_equiv_mode(acl, &mode); -- if (ret < 0) -- return ret; -+ umode_t mode; - -- if (ret == 0) -- acl = NULL; -+ ret = posix_acl_update_mode(inode, &mode, &acl); -+ if (ret) -+ return ret; - - ret = ocfs2_acl_set_mode(inode, di_bh, - handle, mode); -diff --git a/fs/orangefs/acl.c b/fs/orangefs/acl.c -index 28f2195..7a37544 100644 ---- a/fs/orangefs/acl.c -+++ b/fs/orangefs/acl.c -@@ -73,14 +73,11 @@ int orangefs_set_acl(struct inode *inode, struct posix_acl *acl, int type) - case ACL_TYPE_ACCESS: - name = XATTR_NAME_POSIX_ACL_ACCESS; - if (acl) { -- umode_t mode = inode->i_mode; -- /* -- * can we represent this with the traditional file -- * mode permission bits? -- */ -- error = posix_acl_equiv_mode(acl, &mode); -- if (error < 0) { -- gossip_err("%s: posix_acl_equiv_mode err: %d\n", -+ umode_t mode; -+ -+ error = posix_acl_update_mode(inode, &mode, &acl); -+ if (error) { -+ gossip_err("%s: posix_acl_update_mode err: %d\n", - __func__, - error); - return error; -@@ -90,8 +87,6 @@ int orangefs_set_acl(struct inode *inode, struct posix_acl *acl, int type) - SetModeFlag(orangefs_inode); - inode->i_mode = mode; - mark_inode_dirty_sync(inode); -- if (error == 0) -- acl = NULL; - } - break; - case ACL_TYPE_DEFAULT: -diff --git a/fs/posix_acl.c b/fs/posix_acl.c -index 59d47ab0..bfc3ec3 100644 ---- a/fs/posix_acl.c -+++ b/fs/posix_acl.c -@@ -626,6 +626,37 @@ posix_acl_create(struct inode *dir, umode_t *mode, - } - EXPORT_SYMBOL_GPL(posix_acl_create); - -+/** -+ * posix_acl_update_mode - update mode in set_acl -+ * -+ * Update the file mode when setting an ACL: compute the new file permission -+ * bits based on the ACL. In addition, if the ACL is equivalent to the new -+ * file mode, set *acl to NULL to indicate that no ACL should be set. -+ * -+ * As with chmod, clear the setgit bit if the caller is not in the owning group -+ * or capable of CAP_FSETID (see inode_change_ok). -+ * -+ * Called from set_acl inode operations. -+ */ -+int posix_acl_update_mode(struct inode *inode, umode_t *mode_p, -+ struct posix_acl **acl) -+{ -+ umode_t mode = inode->i_mode; -+ int error; -+ -+ error = posix_acl_equiv_mode(*acl, &mode); -+ if (error < 0) -+ return error; -+ if (error == 0) -+ *acl = NULL; -+ if (!in_group_p(inode->i_gid) && -+ !capable_wrt_inode_uidgid(inode, CAP_FSETID)) -+ mode &= ~S_ISGID; -+ *mode_p = mode; -+ return 0; -+} -+EXPORT_SYMBOL(posix_acl_update_mode); -+ - /* - * Fix up the uids and gids in posix acl extended attributes in place. - */ -diff --git a/fs/reiserfs/xattr_acl.c b/fs/reiserfs/xattr_acl.c -index dbed42f..2737668 100644 ---- a/fs/reiserfs/xattr_acl.c -+++ b/fs/reiserfs/xattr_acl.c -@@ -242,13 +242,9 @@ __reiserfs_set_acl(struct reiserfs_transaction_handle *th, struct inode *inode, - case ACL_TYPE_ACCESS: - name = XATTR_NAME_POSIX_ACL_ACCESS; - if (acl) { -- error = posix_acl_equiv_mode(acl, &inode->i_mode); -- if (error < 0) -+ error = posix_acl_update_mode(inode, &inode->i_mode, &acl); -+ if (error) - return error; -- else { -- if (error == 0) -- acl = NULL; -- } - } - break; - case ACL_TYPE_DEFAULT: -diff --git a/fs/xfs/xfs_acl.c b/fs/xfs/xfs_acl.c -index b6e527b..8a0dec8 100644 ---- a/fs/xfs/xfs_acl.c -+++ b/fs/xfs/xfs_acl.c -@@ -257,16 +257,11 @@ xfs_set_acl(struct inode *inode, struct posix_acl *acl, int type) - return error; - - if (type == ACL_TYPE_ACCESS) { -- umode_t mode = inode->i_mode; -- error = posix_acl_equiv_mode(acl, &mode); -- -- if (error <= 0) { -- acl = NULL; -- -- if (error < 0) -- return error; -- } -+ umode_t mode; - -+ error = posix_acl_update_mode(inode, &mode, &acl); -+ if (error) -+ return error; - error = xfs_set_mode(inode, mode); - if (error) - return error; -diff --git a/include/drm/drmP.h b/include/drm/drmP.h -index d377865..988903a 100644 ---- a/include/drm/drmP.h -+++ b/include/drm/drmP.h -@@ -938,7 +938,8 @@ static inline int drm_debugfs_remove_files(const struct drm_info_list *files, - #endif - - extern struct dma_buf *drm_gem_prime_export(struct drm_device *dev, -- struct drm_gem_object *obj, int flags); -+ struct drm_gem_object *obj, -+ int flags); - extern int drm_gem_prime_handle_to_fd(struct drm_device *dev, - struct drm_file *file_priv, uint32_t handle, uint32_t flags, - int *prime_fd); -diff --git a/include/linux/hugetlb.h b/include/linux/hugetlb.h -index c26d463..fe99e6f 100644 ---- a/include/linux/hugetlb.h -+++ b/include/linux/hugetlb.h -@@ -450,8 +450,8 @@ static inline pgoff_t basepage_index(struct page *page) - return __basepage_index(page); - } - --extern void dissolve_free_huge_pages(unsigned long start_pfn, -- unsigned long end_pfn); -+extern int dissolve_free_huge_pages(unsigned long start_pfn, -+ unsigned long end_pfn); - static inline bool hugepage_migration_supported(struct hstate *h) - { - #ifdef CONFIG_ARCH_ENABLE_HUGEPAGE_MIGRATION -@@ -518,7 +518,7 @@ static inline pgoff_t basepage_index(struct page *page) - { - return page->index; - } --#define dissolve_free_huge_pages(s, e) do {} while (0) -+#define dissolve_free_huge_pages(s, e) 0 - #define hugepage_migration_supported(h) false - - static inline spinlock_t *huge_pte_lockptr(struct hstate *h, -diff --git a/include/linux/libnvdimm.h b/include/linux/libnvdimm.h -index b519e13..bbfce62 100644 ---- a/include/linux/libnvdimm.h -+++ b/include/linux/libnvdimm.h -@@ -129,6 +129,8 @@ static inline struct nd_blk_region_desc *to_blk_region_desc( - } - - int nvdimm_bus_add_poison(struct nvdimm_bus *nvdimm_bus, u64 addr, u64 length); -+void nvdimm_clear_from_poison_list(struct nvdimm_bus *nvdimm_bus, -+ phys_addr_t start, unsigned int len); - struct nvdimm_bus *nvdimm_bus_register(struct device *parent, - struct nvdimm_bus_descriptor *nfit_desc); - void nvdimm_bus_unregister(struct nvdimm_bus *nvdimm_bus); -diff --git a/include/linux/posix_acl.h b/include/linux/posix_acl.h -index d5d3d74..bf1046d 100644 ---- a/include/linux/posix_acl.h -+++ b/include/linux/posix_acl.h -@@ -93,6 +93,7 @@ extern int set_posix_acl(struct inode *, int, struct posix_acl *); - extern int posix_acl_chmod(struct inode *, umode_t); - extern int posix_acl_create(struct inode *, umode_t *, struct posix_acl **, - struct posix_acl **); -+extern int posix_acl_update_mode(struct inode *, umode_t *, struct posix_acl **); - - extern int simple_set_acl(struct inode *, struct posix_acl *, int); - extern int simple_acl_create(struct inode *, struct inode *); -diff --git a/kernel/irq/generic-chip.c b/kernel/irq/generic-chip.c -index abd286a..a4775f3 100644 ---- a/kernel/irq/generic-chip.c -+++ b/kernel/irq/generic-chip.c -@@ -411,8 +411,29 @@ int irq_map_generic_chip(struct irq_domain *d, unsigned int virq, - } - EXPORT_SYMBOL_GPL(irq_map_generic_chip); - -+static void irq_unmap_generic_chip(struct irq_domain *d, unsigned int virq) -+{ -+ struct irq_data *data = irq_domain_get_irq_data(d, virq); -+ struct irq_domain_chip_generic *dgc = d->gc; -+ unsigned int hw_irq = data->hwirq; -+ struct irq_chip_generic *gc; -+ int irq_idx; -+ -+ gc = irq_get_domain_generic_chip(d, hw_irq); -+ if (!gc) -+ return; -+ -+ irq_idx = hw_irq % dgc->irqs_per_chip; -+ -+ clear_bit(irq_idx, &gc->installed); -+ irq_domain_set_info(d, virq, hw_irq, &no_irq_chip, NULL, NULL, NULL, -+ NULL); -+ -+} -+ - struct irq_domain_ops irq_generic_chip_ops = { - .map = irq_map_generic_chip, -+ .unmap = irq_unmap_generic_chip, - .xlate = irq_domain_xlate_onetwocell, - }; - EXPORT_SYMBOL_GPL(irq_generic_chip_ops); -diff --git a/mm/hugetlb.c b/mm/hugetlb.c -index 603bdd0..770d83e 100644 ---- a/mm/hugetlb.c -+++ b/mm/hugetlb.c -@@ -1437,22 +1437,32 @@ static int free_pool_huge_page(struct hstate *h, nodemask_t *nodes_allowed, - - /* - * Dissolve a given free hugepage into free buddy pages. This function does -- * nothing for in-use (including surplus) hugepages. -+ * nothing for in-use (including surplus) hugepages. Returns -EBUSY if the -+ * number of free hugepages would be reduced below the number of reserved -+ * hugepages. - */ --static void dissolve_free_huge_page(struct page *page) -+static int dissolve_free_huge_page(struct page *page) - { -+ int rc = 0; -+ - spin_lock(&hugetlb_lock); - if (PageHuge(page) && !page_count(page)) { - struct page *head = compound_head(page); - struct hstate *h = page_hstate(head); - int nid = page_to_nid(head); -+ if (h->free_huge_pages - h->resv_huge_pages == 0) { -+ rc = -EBUSY; -+ goto out; -+ } - list_del(&head->lru); - h->free_huge_pages--; - h->free_huge_pages_node[nid]--; - h->max_huge_pages--; - update_and_free_page(h, head); - } -+out: - spin_unlock(&hugetlb_lock); -+ return rc; - } - - /* -@@ -1460,16 +1470,28 @@ static void dissolve_free_huge_page(struct page *page) - * make specified memory blocks removable from the system. - * Note that this will dissolve a free gigantic hugepage completely, if any - * part of it lies within the given range. -+ * Also note that if dissolve_free_huge_page() returns with an error, all -+ * free hugepages that were dissolved before that error are lost. - */ --void dissolve_free_huge_pages(unsigned long start_pfn, unsigned long end_pfn) -+int dissolve_free_huge_pages(unsigned long start_pfn, unsigned long end_pfn) - { - unsigned long pfn; -+ struct page *page; -+ int rc = 0; - - if (!hugepages_supported()) -- return; -+ return rc; -+ -+ for (pfn = start_pfn; pfn < end_pfn; pfn += 1 << minimum_order) { -+ page = pfn_to_page(pfn); -+ if (PageHuge(page) && !page_count(page)) { -+ rc = dissolve_free_huge_page(page); -+ if (rc) -+ break; -+ } -+ } - -- for (pfn = start_pfn; pfn < end_pfn; pfn += 1 << minimum_order) -- dissolve_free_huge_page(pfn_to_page(pfn)); -+ return rc; - } - - /* -diff --git a/mm/memory_hotplug.c b/mm/memory_hotplug.c -index 9d29ba0..9629273 100644 ---- a/mm/memory_hotplug.c -+++ b/mm/memory_hotplug.c -@@ -1945,7 +1945,9 @@ static int __ref __offline_pages(unsigned long start_pfn, - * dissolve free hugepages in the memory block before doing offlining - * actually in order to make hugetlbfs's object counting consistent. - */ -- dissolve_free_huge_pages(start_pfn, end_pfn); -+ ret = dissolve_free_huge_pages(start_pfn, end_pfn); -+ if (ret) -+ goto failed_removal; - /* check again */ - offlined_pages = check_pages_isolated(start_pfn, end_pfn); - if (offlined_pages < 0) { -diff --git a/sound/soc/intel/boards/bxt_da7219_max98357a.c b/sound/soc/intel/boards/bxt_da7219_max98357a.c -index 3774b11..49b65d4 100644 ---- a/sound/soc/intel/boards/bxt_da7219_max98357a.c -+++ b/sound/soc/intel/boards/bxt_da7219_max98357a.c -@@ -255,7 +255,7 @@ static struct snd_soc_ops broxton_da7219_ops = { - /* broxton digital audio interface glue - connects codec <--> CPU */ - static struct snd_soc_dai_link broxton_dais[] = { - /* Front End DAI links */ -- [BXT_DPCM_AUDIO_PB] -+ [BXT_DPCM_AUDIO_PB] = - { - .name = "Bxt Audio Port", - .stream_name = "Audio", -@@ -271,7 +271,7 @@ static struct snd_soc_dai_link broxton_dais[] = { - .dpcm_playback = 1, - .ops = &broxton_da7219_fe_ops, - }, -- [BXT_DPCM_AUDIO_CP] -+ [BXT_DPCM_AUDIO_CP] = - { - .name = "Bxt Audio Capture Port", - .stream_name = "Audio Record", -@@ -286,7 +286,7 @@ static struct snd_soc_dai_link broxton_dais[] = { - .dpcm_capture = 1, - .ops = &broxton_da7219_fe_ops, - }, -- [BXT_DPCM_AUDIO_REF_CP] -+ [BXT_DPCM_AUDIO_REF_CP] = - { - .name = "Bxt Audio Reference cap", - .stream_name = "Refcap", -@@ -300,7 +300,7 @@ static struct snd_soc_dai_link broxton_dais[] = { - .nonatomic = 1, - .dynamic = 1, - }, -- [BXT_DPCM_AUDIO_HDMI1_PB] -+ [BXT_DPCM_AUDIO_HDMI1_PB] = - { - .name = "Bxt HDMI Port1", - .stream_name = "Hdmi1", -@@ -313,7 +313,7 @@ static struct snd_soc_dai_link broxton_dais[] = { - .nonatomic = 1, - .dynamic = 1, - }, -- [BXT_DPCM_AUDIO_HDMI2_PB] -+ [BXT_DPCM_AUDIO_HDMI2_PB] = - { - .name = "Bxt HDMI Port2", - .stream_name = "Hdmi2", -@@ -326,7 +326,7 @@ static struct snd_soc_dai_link broxton_dais[] = { - .nonatomic = 1, - .dynamic = 1, - }, -- [BXT_DPCM_AUDIO_HDMI3_PB] -+ [BXT_DPCM_AUDIO_HDMI3_PB] = - { - .name = "Bxt HDMI Port3", - .stream_name = "Hdmi3", -diff --git a/sound/soc/intel/boards/bxt_rt298.c b/sound/soc/intel/boards/bxt_rt298.c -index 253d7bf..d610bdca 100644 ---- a/sound/soc/intel/boards/bxt_rt298.c -+++ b/sound/soc/intel/boards/bxt_rt298.c -@@ -271,7 +271,7 @@ static const struct snd_soc_ops broxton_rt286_fe_ops = { - /* broxton digital audio interface glue - connects codec <--> CPU */ - static struct snd_soc_dai_link broxton_rt298_dais[] = { - /* Front End DAI links */ -- [BXT_DPCM_AUDIO_PB] -+ [BXT_DPCM_AUDIO_PB] = - { - .name = "Bxt Audio Port", - .stream_name = "Audio", -@@ -286,7 +286,7 @@ static struct snd_soc_dai_link broxton_rt298_dais[] = { - .dpcm_playback = 1, - .ops = &broxton_rt286_fe_ops, - }, -- [BXT_DPCM_AUDIO_CP] -+ [BXT_DPCM_AUDIO_CP] = - { - .name = "Bxt Audio Capture Port", - .stream_name = "Audio Record", -@@ -300,7 +300,7 @@ static struct snd_soc_dai_link broxton_rt298_dais[] = { - .dpcm_capture = 1, - .ops = &broxton_rt286_fe_ops, - }, -- [BXT_DPCM_AUDIO_REF_CP] -+ [BXT_DPCM_AUDIO_REF_CP] = - { - .name = "Bxt Audio Reference cap", - .stream_name = "refcap", -@@ -313,7 +313,7 @@ static struct snd_soc_dai_link broxton_rt298_dais[] = { - .nonatomic = 1, - .dynamic = 1, - }, -- [BXT_DPCM_AUDIO_DMIC_CP] -+ [BXT_DPCM_AUDIO_DMIC_CP] = - { - .name = "Bxt Audio DMIC cap", - .stream_name = "dmiccap", -@@ -327,7 +327,7 @@ static struct snd_soc_dai_link broxton_rt298_dais[] = { - .dynamic = 1, - .ops = &broxton_dmic_ops, - }, -- [BXT_DPCM_AUDIO_HDMI1_PB] -+ [BXT_DPCM_AUDIO_HDMI1_PB] = - { - .name = "Bxt HDMI Port1", - .stream_name = "Hdmi1", -@@ -340,7 +340,7 @@ static struct snd_soc_dai_link broxton_rt298_dais[] = { - .nonatomic = 1, - .dynamic = 1, - }, -- [BXT_DPCM_AUDIO_HDMI2_PB] -+ [BXT_DPCM_AUDIO_HDMI2_PB] = - { - .name = "Bxt HDMI Port2", - .stream_name = "Hdmi2", -@@ -353,7 +353,7 @@ static struct snd_soc_dai_link broxton_rt298_dais[] = { - .nonatomic = 1, - .dynamic = 1, - }, -- [BXT_DPCM_AUDIO_HDMI3_PB] -+ [BXT_DPCM_AUDIO_HDMI3_PB] = - { - .name = "Bxt HDMI Port3", - .stream_name = "Hdmi3", -diff --git a/sound/soc/soc-dapm.c b/sound/soc/soc-dapm.c -index d908ff8..801082f 100644 ---- a/sound/soc/soc-dapm.c -+++ b/sound/soc/soc-dapm.c -@@ -823,6 +823,7 @@ static int dapm_create_or_share_kcontrol(struct snd_soc_dapm_widget *w, - case snd_soc_dapm_switch: - case snd_soc_dapm_mixer: - case snd_soc_dapm_pga: -+ case snd_soc_dapm_out_drv: - wname_in_long_name = true; - kcname_in_long_name = true; - break; -@@ -3049,6 +3050,9 @@ int snd_soc_dapm_get_volsw(struct snd_kcontrol *kcontrol, - } - mutex_unlock(&card->dapm_mutex); - -+ if (ret) -+ return ret; -+ - if (invert) - ucontrol->value.integer.value[0] = max - val; - else -@@ -3200,7 +3204,7 @@ int snd_soc_dapm_put_enum_double(struct snd_kcontrol *kcontrol, - if (e->shift_l != e->shift_r) { - if (item[1] > e->items) - return -EINVAL; -- val |= snd_soc_enum_item_to_val(e, item[1]) << e->shift_l; -+ val |= snd_soc_enum_item_to_val(e, item[1]) << e->shift_r; - mask |= e->mask << e->shift_r; - } - -diff --git a/sound/soc/soc-topology.c b/sound/soc/soc-topology.c -index ee7f15a..3406907 100644 ---- a/sound/soc/soc-topology.c -+++ b/sound/soc/soc-topology.c -@@ -1475,6 +1475,7 @@ static int soc_tplg_dapm_widget_create(struct soc_tplg *tplg, - if (widget == NULL) { - dev_err(tplg->dev, "ASoC: failed to create widget %s controls\n", - w->name); -+ ret = -ENOMEM; - goto hdr_err; - } - -diff --git a/tools/perf/perf-sys.h b/tools/perf/perf-sys.h -index 7ed72a4..e4b717e 100644 ---- a/tools/perf/perf-sys.h -+++ b/tools/perf/perf-sys.h -@@ -20,7 +20,6 @@ - #endif - - #ifdef __powerpc__ --#include "../../arch/powerpc/include/uapi/asm/unistd.h" - #define CPUINFO_PROC {"cpu"} - #endif - -diff --git a/tools/perf/ui/browsers/hists.c b/tools/perf/ui/browsers/hists.c -index 13d4143..7aee954 100644 ---- a/tools/perf/ui/browsers/hists.c -+++ b/tools/perf/ui/browsers/hists.c -@@ -1091,7 +1091,6 @@ static int __hpp__slsmg_color_printf(struct perf_hpp *hpp, const char *fmt, ...) - ret = scnprintf(hpp->buf, hpp->size, fmt, len, percent); - ui_browser__printf(arg->b, "%s", hpp->buf); - -- advance_hpp(hpp, ret); - return ret; - } - -@@ -2046,6 +2045,7 @@ void hist_browser__init(struct hist_browser *browser, - struct hists *hists) - { - struct perf_hpp_fmt *fmt; -+ struct perf_hpp_list_node *node; - - browser->hists = hists; - browser->b.refresh = hist_browser__refresh; -@@ -2058,6 +2058,11 @@ void hist_browser__init(struct hist_browser *browser, - perf_hpp__reset_width(fmt, hists); - ++browser->b.columns; - } -+ /* hierarchy entries have their own hpp list */ -+ list_for_each_entry(node, &hists->hpp_formats, list) { -+ perf_hpp_list__for_each_format(&node->hpp, fmt) -+ perf_hpp__reset_width(fmt, hists); -+ } - } - - struct hist_browser *hist_browser__new(struct hists *hists) -diff --git a/tools/perf/ui/stdio/hist.c b/tools/perf/ui/stdio/hist.c -index f04a631..d0cae75 100644 ---- a/tools/perf/ui/stdio/hist.c -+++ b/tools/perf/ui/stdio/hist.c -@@ -628,14 +628,6 @@ hists__fprintf_hierarchy_headers(struct hists *hists, - struct perf_hpp *hpp, - FILE *fp) - { -- struct perf_hpp_list_node *fmt_node; -- struct perf_hpp_fmt *fmt; -- -- list_for_each_entry(fmt_node, &hists->hpp_formats, list) { -- perf_hpp_list__for_each_format(&fmt_node->hpp, fmt) -- perf_hpp__reset_width(fmt, hists); -- } -- - return print_hierarchy_header(hists, hpp, symbol_conf.field_sep, fp); - } - -@@ -714,6 +706,7 @@ size_t hists__fprintf(struct hists *hists, bool show_header, int max_rows, - bool use_callchain) - { - struct perf_hpp_fmt *fmt; -+ struct perf_hpp_list_node *node; - struct rb_node *nd; - size_t ret = 0; - const char *sep = symbol_conf.field_sep; -@@ -726,6 +719,11 @@ size_t hists__fprintf(struct hists *hists, bool show_header, int max_rows, - - hists__for_each_format(hists, fmt) - perf_hpp__reset_width(fmt, hists); -+ /* hierarchy entries have their own hpp list */ -+ list_for_each_entry(node, &hists->hpp_formats, list) { -+ perf_hpp_list__for_each_format(&node->hpp, fmt) -+ perf_hpp__reset_width(fmt, hists); -+ } - - if (symbol_conf.col_width_list_str) - perf_hpp__set_user_width(symbol_conf.col_width_list_str); -diff --git a/tools/perf/util/data-convert-bt.c b/tools/perf/util/data-convert-bt.c -index 4f979bb..7123f4d 100644 ---- a/tools/perf/util/data-convert-bt.c -+++ b/tools/perf/util/data-convert-bt.c -@@ -437,7 +437,7 @@ add_bpf_output_values(struct bt_ctf_event_class *event_class, - int ret; - - if (nr_elements * sizeof(u32) != raw_size) -- pr_warning("Incorrect raw_size (%u) in bpf output event, skip %lu bytes\n", -+ pr_warning("Incorrect raw_size (%u) in bpf output event, skip %zu bytes\n", - raw_size, nr_elements * sizeof(u32) - raw_size); - - len_type = bt_ctf_event_class_get_field_by_name(event_class, "raw_len"); -diff --git a/tools/perf/util/symbol-elf.c b/tools/perf/util/symbol-elf.c -index a811c13..f77b316 100644 ---- a/tools/perf/util/symbol-elf.c -+++ b/tools/perf/util/symbol-elf.c -@@ -1113,9 +1113,8 @@ int dso__load_sym(struct dso *dso, struct map *map, - * For misannotated, zeroed, ASM function sizes. - */ - if (nr > 0) { -- if (!symbol_conf.allow_aliases) -- symbols__fixup_duplicate(&dso->symbols[map->type]); - symbols__fixup_end(&dso->symbols[map->type]); -+ symbols__fixup_duplicate(&dso->symbols[map->type]); - if (kmap) { - /* - * We need to fixup this here too because we create new -diff --git a/tools/perf/util/symbol.c b/tools/perf/util/symbol.c -index 37e8d20..f29f336 100644 ---- a/tools/perf/util/symbol.c -+++ b/tools/perf/util/symbol.c -@@ -152,6 +152,9 @@ void symbols__fixup_duplicate(struct rb_root *symbols) - struct rb_node *nd; - struct symbol *curr, *next; - -+ if (symbol_conf.allow_aliases) -+ return; -+ - nd = rb_first(symbols); - - while (nd) { -@@ -1234,8 +1237,8 @@ int __dso__load_kallsyms(struct dso *dso, const char *filename, - if (kallsyms__delta(map, filename, &delta)) - return -1; - -- symbols__fixup_duplicate(&dso->symbols[map->type]); - symbols__fixup_end(&dso->symbols[map->type]); -+ symbols__fixup_duplicate(&dso->symbols[map->type]); - - if (dso->kernel == DSO_TYPE_GUEST_KERNEL) - dso->symtab_type = DSO_BINARY_TYPE__GUEST_KALLSYMS; diff --git a/4.8.7/1006_linux-4.8.7.patch b/4.8.7/1006_linux-4.8.7.patch deleted file mode 100644 index d96f1e2..0000000 --- a/4.8.7/1006_linux-4.8.7.patch +++ /dev/null @@ -1,4331 +0,0 @@ -diff --git a/Documentation/device-mapper/dm-raid.txt b/Documentation/device-mapper/dm-raid.txt -index e5b6497..c75b64a 100644 ---- a/Documentation/device-mapper/dm-raid.txt -+++ b/Documentation/device-mapper/dm-raid.txt -@@ -309,3 +309,4 @@ Version History - with a reshape in progress. - 1.9.0 Add support for RAID level takeover/reshape/region size - and set size reduction. -+1.9.1 Fix activation of existing RAID 4/10 mapped devices -diff --git a/Makefile b/Makefile -index b249529..4d0f28c 100644 ---- a/Makefile -+++ b/Makefile -@@ -1,6 +1,6 @@ - VERSION = 4 - PATCHLEVEL = 8 --SUBLEVEL = 6 -+SUBLEVEL = 7 - EXTRAVERSION = - NAME = Psychotic Stoned Sheep - -diff --git a/arch/arm/boot/dts/ste-snowball.dts b/arch/arm/boot/dts/ste-snowball.dts -index b3df1c6..386eee6 100644 ---- a/arch/arm/boot/dts/ste-snowball.dts -+++ b/arch/arm/boot/dts/ste-snowball.dts -@@ -239,14 +239,25 @@ - arm,primecell-periphid = <0x10480180>; - max-frequency = <100000000>; - bus-width = <4>; -+ cap-sd-highspeed; - cap-mmc-highspeed; -+ sd-uhs-sdr12; -+ sd-uhs-sdr25; -+ /* All direction control is used */ -+ st,sig-dir-cmd; -+ st,sig-dir-dat0; -+ st,sig-dir-dat2; -+ st,sig-dir-dat31; -+ st,sig-pin-fbclk; -+ full-pwr-cycle; - vmmc-supply = <&ab8500_ldo_aux3_reg>; - vqmmc-supply = <&vmmci>; - pinctrl-names = "default", "sleep"; - pinctrl-0 = <&sdi0_default_mode>; - pinctrl-1 = <&sdi0_sleep_mode>; - -- cd-gpios = <&gpio6 26 GPIO_ACTIVE_LOW>; // 218 -+ /* GPIO218 MMC_CD */ -+ cd-gpios = <&gpio6 26 GPIO_ACTIVE_LOW>; - - status = "okay"; - }; -@@ -549,7 +560,7 @@ - /* VMMCI level-shifter enable */ - snowball_cfg3 { - pins = "GPIO217_AH12"; -- ste,config = <&gpio_out_lo>; -+ ste,config = <&gpio_out_hi>; - }; - /* VMMCI level-shifter voltage select */ - snowball_cfg4 { -diff --git a/arch/arm/mach-mvebu/Kconfig b/arch/arm/mach-mvebu/Kconfig -index f9b6bd3..541647f 100644 ---- a/arch/arm/mach-mvebu/Kconfig -+++ b/arch/arm/mach-mvebu/Kconfig -@@ -23,6 +23,7 @@ config MACH_MVEBU_V7 - select CACHE_L2X0 - select ARM_CPU_SUSPEND - select MACH_MVEBU_ANY -+ select MVEBU_CLK_COREDIV - - config MACH_ARMADA_370 - bool "Marvell Armada 370 boards" -@@ -32,7 +33,6 @@ config MACH_ARMADA_370 - select CPU_PJ4B - select MACH_MVEBU_V7 - select PINCTRL_ARMADA_370 -- select MVEBU_CLK_COREDIV - help - Say 'Y' here if you want your kernel to support boards based - on the Marvell Armada 370 SoC with device tree. -@@ -50,7 +50,6 @@ config MACH_ARMADA_375 - select HAVE_SMP - select MACH_MVEBU_V7 - select PINCTRL_ARMADA_375 -- select MVEBU_CLK_COREDIV - help - Say 'Y' here if you want your kernel to support boards based - on the Marvell Armada 375 SoC with device tree. -@@ -68,7 +67,6 @@ config MACH_ARMADA_38X - select HAVE_SMP - select MACH_MVEBU_V7 - select PINCTRL_ARMADA_38X -- select MVEBU_CLK_COREDIV - help - Say 'Y' here if you want your kernel to support boards based - on the Marvell Armada 380/385 SoC with device tree. -diff --git a/arch/arm/mm/abort-lv4t.S b/arch/arm/mm/abort-lv4t.S -index 6d8e8e3..4cdfab3 100644 ---- a/arch/arm/mm/abort-lv4t.S -+++ b/arch/arm/mm/abort-lv4t.S -@@ -7,7 +7,7 @@ - * : r4 = aborted context pc - * : r5 = aborted context psr - * -- * Returns : r4-r5, r10-r11, r13 preserved -+ * Returns : r4-r5, r9-r11, r13 preserved - * - * Purpose : obtain information about current aborted instruction. - * Note: we read user space. This means we might cause a data -@@ -48,7 +48,10 @@ ENTRY(v4t_late_abort) - /* c */ b do_DataAbort @ ldc rd, [rn], #m @ Same as ldr rd, [rn], #m - /* d */ b do_DataAbort @ ldc rd, [rn, #m] - /* e */ b .data_unknown --/* f */ -+/* f */ b .data_unknown -+ -+.data_unknown_r9: -+ ldr r9, [sp], #4 - .data_unknown: @ Part of jumptable - mov r0, r4 - mov r1, r8 -@@ -57,6 +60,7 @@ ENTRY(v4t_late_abort) - .data_arm_ldmstm: - tst r8, #1 << 21 @ check writeback bit - beq do_DataAbort @ no writeback -> no fixup -+ str r9, [sp, #-4]! - mov r7, #0x11 - orr r7, r7, #0x1100 - and r6, r8, r7 -@@ -75,12 +79,14 @@ ENTRY(v4t_late_abort) - subne r7, r7, r6, lsl #2 @ Undo increment - addeq r7, r7, r6, lsl #2 @ Undo decrement - str r7, [r2, r9, lsr #14] @ Put register 'Rn' -+ ldr r9, [sp], #4 - b do_DataAbort - - .data_arm_lateldrhpre: - tst r8, #1 << 21 @ Check writeback bit - beq do_DataAbort @ No writeback -> no fixup - .data_arm_lateldrhpost: -+ str r9, [sp, #-4]! - and r9, r8, #0x00f @ get Rm / low nibble of immediate value - tst r8, #1 << 22 @ if (immediate offset) - andne r6, r8, #0xf00 @ { immediate high nibble -@@ -93,6 +99,7 @@ ENTRY(v4t_late_abort) - subne r7, r7, r6 @ Undo incrmenet - addeq r7, r7, r6 @ Undo decrement - str r7, [r2, r9, lsr #14] @ Put register 'Rn' -+ ldr r9, [sp], #4 - b do_DataAbort - - .data_arm_lateldrpreconst: -@@ -101,12 +108,14 @@ ENTRY(v4t_late_abort) - .data_arm_lateldrpostconst: - movs r6, r8, lsl #20 @ Get offset - beq do_DataAbort @ zero -> no fixup -+ str r9, [sp, #-4]! - and r9, r8, #15 << 16 @ Extract 'n' from instruction - ldr r7, [r2, r9, lsr #14] @ Get register 'Rn' - tst r8, #1 << 23 @ Check U bit - subne r7, r7, r6, lsr #20 @ Undo increment - addeq r7, r7, r6, lsr #20 @ Undo decrement - str r7, [r2, r9, lsr #14] @ Put register 'Rn' -+ ldr r9, [sp], #4 - b do_DataAbort - - .data_arm_lateldrprereg: -@@ -115,6 +124,7 @@ ENTRY(v4t_late_abort) - .data_arm_lateldrpostreg: - and r7, r8, #15 @ Extract 'm' from instruction - ldr r6, [r2, r7, lsl #2] @ Get register 'Rm' -+ str r9, [sp, #-4]! - mov r9, r8, lsr #7 @ get shift count - ands r9, r9, #31 - and r7, r8, #0x70 @ get shift type -@@ -126,33 +136,33 @@ ENTRY(v4t_late_abort) - b .data_arm_apply_r6_and_rn - b .data_arm_apply_r6_and_rn @ 1: LSL #0 - nop -- b .data_unknown @ 2: MUL? -+ b .data_unknown_r9 @ 2: MUL? - nop -- b .data_unknown @ 3: MUL? -+ b .data_unknown_r9 @ 3: MUL? - nop - mov r6, r6, lsr r9 @ 4: LSR #!0 - b .data_arm_apply_r6_and_rn - mov r6, r6, lsr #32 @ 5: LSR #32 - b .data_arm_apply_r6_and_rn -- b .data_unknown @ 6: MUL? -+ b .data_unknown_r9 @ 6: MUL? - nop -- b .data_unknown @ 7: MUL? -+ b .data_unknown_r9 @ 7: MUL? - nop - mov r6, r6, asr r9 @ 8: ASR #!0 - b .data_arm_apply_r6_and_rn - mov r6, r6, asr #32 @ 9: ASR #32 - b .data_arm_apply_r6_and_rn -- b .data_unknown @ A: MUL? -+ b .data_unknown_r9 @ A: MUL? - nop -- b .data_unknown @ B: MUL? -+ b .data_unknown_r9 @ B: MUL? - nop - mov r6, r6, ror r9 @ C: ROR #!0 - b .data_arm_apply_r6_and_rn - mov r6, r6, rrx @ D: RRX - b .data_arm_apply_r6_and_rn -- b .data_unknown @ E: MUL? -+ b .data_unknown_r9 @ E: MUL? - nop -- b .data_unknown @ F: MUL? -+ b .data_unknown_r9 @ F: MUL? - - .data_thumb_abort: - ldrh r8, [r4] @ read instruction -@@ -190,6 +200,7 @@ ENTRY(v4t_late_abort) - .data_thumb_pushpop: - tst r8, #1 << 10 - beq .data_unknown -+ str r9, [sp, #-4]! - and r6, r8, #0x55 @ hweight8(r8) + R bit - and r9, r8, #0xaa - add r6, r6, r9, lsr #1 -@@ -204,9 +215,11 @@ ENTRY(v4t_late_abort) - addeq r7, r7, r6, lsl #2 @ increment SP if PUSH - subne r7, r7, r6, lsl #2 @ decrement SP if POP - str r7, [r2, #13 << 2] -+ ldr r9, [sp], #4 - b do_DataAbort - - .data_thumb_ldmstm: -+ str r9, [sp, #-4]! - and r6, r8, #0x55 @ hweight8(r8) - and r9, r8, #0xaa - add r6, r6, r9, lsr #1 -@@ -219,4 +232,5 @@ ENTRY(v4t_late_abort) - and r6, r6, #15 @ number of regs to transfer - sub r7, r7, r6, lsl #2 @ always decrement - str r7, [r2, r9, lsr #6] -+ ldr r9, [sp], #4 - b do_DataAbort -diff --git a/arch/arm64/boot/dts/marvell/armada-cp110-master.dtsi b/arch/arm64/boot/dts/marvell/armada-cp110-master.dtsi -index da31bbb..3992718 100644 ---- a/arch/arm64/boot/dts/marvell/armada-cp110-master.dtsi -+++ b/arch/arm64/boot/dts/marvell/armada-cp110-master.dtsi -@@ -131,7 +131,7 @@ - #address-cells = <0x1>; - #size-cells = <0x0>; - cell-index = <1>; -- clocks = <&cpm_syscon0 0 3>; -+ clocks = <&cpm_syscon0 1 21>; - status = "disabled"; - }; - -diff --git a/arch/h8300/include/asm/thread_info.h b/arch/h8300/include/asm/thread_info.h -index b408fe6..3cef068 100644 ---- a/arch/h8300/include/asm/thread_info.h -+++ b/arch/h8300/include/asm/thread_info.h -@@ -31,7 +31,6 @@ struct thread_info { - int cpu; /* cpu we're on */ - int preempt_count; /* 0 => preemptable, <0 => BUG */ - mm_segment_t addr_limit; -- struct restart_block restart_block; - }; - - /* -@@ -44,9 +43,6 @@ struct thread_info { - .cpu = 0, \ - .preempt_count = INIT_PREEMPT_COUNT, \ - .addr_limit = KERNEL_DS, \ -- .restart_block = { \ -- .fn = do_no_restart_syscall, \ -- }, \ - } - - #define init_thread_info (init_thread_union.thread_info) -diff --git a/arch/h8300/kernel/signal.c b/arch/h8300/kernel/signal.c -index ad1f81f..7138303 100644 ---- a/arch/h8300/kernel/signal.c -+++ b/arch/h8300/kernel/signal.c -@@ -79,7 +79,7 @@ restore_sigcontext(struct sigcontext *usc, int *pd0) - unsigned int er0; - - /* Always make any pending restarted system calls return -EINTR */ -- current_thread_info()->restart_block.fn = do_no_restart_syscall; -+ current->restart_block.fn = do_no_restart_syscall; - - /* restore passed registers */ - #define COPY(r) do { err |= get_user(regs->r, &usc->sc_##r); } while (0) -diff --git a/arch/mips/include/asm/kvm_host.h b/arch/mips/include/asm/kvm_host.h -index b54bcad..45799ef 100644 ---- a/arch/mips/include/asm/kvm_host.h -+++ b/arch/mips/include/asm/kvm_host.h -@@ -279,7 +279,10 @@ struct kvm_vcpu_arch { - /* Host KSEG0 address of the EI/DI offset */ - void *kseg0_commpage; - -- u32 io_gpr; /* GPR used as IO source/target */ -+ /* Resume PC after MMIO completion */ -+ unsigned long io_pc; -+ /* GPR used as IO source/target */ -+ u32 io_gpr; - - struct hrtimer comparecount_timer; - /* Count timer control KVM register */ -@@ -301,8 +304,6 @@ struct kvm_vcpu_arch { - /* Bitmask of pending exceptions to be cleared */ - unsigned long pending_exceptions_clr; - -- u32 pending_load_cause; -- - /* Save/Restore the entryhi register when are are preempted/scheduled back in */ - unsigned long preempt_entryhi; - -diff --git a/arch/mips/kernel/relocate.c b/arch/mips/kernel/relocate.c -index ca1cc30..1958910 100644 ---- a/arch/mips/kernel/relocate.c -+++ b/arch/mips/kernel/relocate.c -@@ -200,7 +200,7 @@ static inline __init unsigned long get_random_boot(void) - - #if defined(CONFIG_USE_OF) - /* Get any additional entropy passed in device tree */ -- { -+ if (initial_boot_params) { - int node, len; - u64 *prop; - -diff --git a/arch/mips/kvm/emulate.c b/arch/mips/kvm/emulate.c -index 43853ec..4d65285 100644 ---- a/arch/mips/kvm/emulate.c -+++ b/arch/mips/kvm/emulate.c -@@ -791,15 +791,15 @@ enum emulation_result kvm_mips_emul_eret(struct kvm_vcpu *vcpu) - struct mips_coproc *cop0 = vcpu->arch.cop0; - enum emulation_result er = EMULATE_DONE; - -- if (kvm_read_c0_guest_status(cop0) & ST0_EXL) { -+ if (kvm_read_c0_guest_status(cop0) & ST0_ERL) { -+ kvm_clear_c0_guest_status(cop0, ST0_ERL); -+ vcpu->arch.pc = kvm_read_c0_guest_errorepc(cop0); -+ } else if (kvm_read_c0_guest_status(cop0) & ST0_EXL) { - kvm_debug("[%#lx] ERET to %#lx\n", vcpu->arch.pc, - kvm_read_c0_guest_epc(cop0)); - kvm_clear_c0_guest_status(cop0, ST0_EXL); - vcpu->arch.pc = kvm_read_c0_guest_epc(cop0); - -- } else if (kvm_read_c0_guest_status(cop0) & ST0_ERL) { -- kvm_clear_c0_guest_status(cop0, ST0_ERL); -- vcpu->arch.pc = kvm_read_c0_guest_errorepc(cop0); - } else { - kvm_err("[%#lx] ERET when MIPS_SR_EXL|MIPS_SR_ERL == 0\n", - vcpu->arch.pc); -@@ -1522,13 +1522,25 @@ enum emulation_result kvm_mips_emulate_load(union mips_instruction inst, - struct kvm_vcpu *vcpu) - { - enum emulation_result er = EMULATE_DO_MMIO; -+ unsigned long curr_pc; - u32 op, rt; - u32 bytes; - - rt = inst.i_format.rt; - op = inst.i_format.opcode; - -- vcpu->arch.pending_load_cause = cause; -+ /* -+ * Find the resume PC now while we have safe and easy access to the -+ * prior branch instruction, and save it for -+ * kvm_mips_complete_mmio_load() to restore later. -+ */ -+ curr_pc = vcpu->arch.pc; -+ er = update_pc(vcpu, cause); -+ if (er == EMULATE_FAIL) -+ return er; -+ vcpu->arch.io_pc = vcpu->arch.pc; -+ vcpu->arch.pc = curr_pc; -+ - vcpu->arch.io_gpr = rt; - - switch (op) { -@@ -2488,9 +2500,8 @@ enum emulation_result kvm_mips_complete_mmio_load(struct kvm_vcpu *vcpu, - goto done; - } - -- er = update_pc(vcpu, vcpu->arch.pending_load_cause); -- if (er == EMULATE_FAIL) -- return er; -+ /* Restore saved resume PC */ -+ vcpu->arch.pc = vcpu->arch.io_pc; - - switch (run->mmio.len) { - case 4: -@@ -2512,11 +2523,6 @@ enum emulation_result kvm_mips_complete_mmio_load(struct kvm_vcpu *vcpu, - break; - } - -- if (vcpu->arch.pending_load_cause & CAUSEF_BD) -- kvm_debug("[%#lx] Completing %d byte BD Load to gpr %d (0x%08lx) type %d\n", -- vcpu->arch.pc, run->mmio.len, vcpu->arch.io_gpr, *gpr, -- vcpu->mmio_needed); -- - done: - return er; - } -diff --git a/arch/parisc/kernel/syscall.S b/arch/parisc/kernel/syscall.S -index d03422e..7ed036c 100644 ---- a/arch/parisc/kernel/syscall.S -+++ b/arch/parisc/kernel/syscall.S -@@ -106,8 +106,6 @@ linux_gateway_entry: - mtsp %r0,%sr4 /* get kernel space into sr4 */ - mtsp %r0,%sr5 /* get kernel space into sr5 */ - mtsp %r0,%sr6 /* get kernel space into sr6 */ -- mfsp %sr7,%r1 /* save user sr7 */ -- mtsp %r1,%sr3 /* and store it in sr3 */ - - #ifdef CONFIG_64BIT - /* for now we can *always* set the W bit on entry to the syscall -@@ -133,6 +131,14 @@ linux_gateway_entry: - depdi 0, 31, 32, %r21 - 1: - #endif -+ -+ /* We use a rsm/ssm pair to prevent sr3 from being clobbered -+ * by external interrupts. -+ */ -+ mfsp %sr7,%r1 /* save user sr7 */ -+ rsm PSW_SM_I, %r0 /* disable interrupts */ -+ mtsp %r1,%sr3 /* and store it in sr3 */ -+ - mfctl %cr30,%r1 - xor %r1,%r30,%r30 /* ye olde xor trick */ - xor %r1,%r30,%r1 -@@ -147,6 +153,7 @@ linux_gateway_entry: - */ - - mtsp %r0,%sr7 /* get kernel space into sr7 */ -+ ssm PSW_SM_I, %r0 /* enable interrupts */ - STREGM %r1,FRAME_SIZE(%r30) /* save r1 (usp) here for now */ - mfctl %cr30,%r1 /* get task ptr in %r1 */ - LDREG TI_TASK(%r1),%r1 -diff --git a/arch/powerpc/include/asm/cpuidle.h b/arch/powerpc/include/asm/cpuidle.h -index 01b8a13..3919332 100644 ---- a/arch/powerpc/include/asm/cpuidle.h -+++ b/arch/powerpc/include/asm/cpuidle.h -@@ -26,7 +26,7 @@ extern u64 pnv_first_deep_stop_state; - std r0,0(r1); \ - ptesync; \ - ld r0,0(r1); \ --1: cmp cr0,r0,r0; \ -+1: cmpd cr0,r0,r0; \ - bne 1b; \ - IDLE_INST; \ - b . -diff --git a/arch/powerpc/include/asm/tlb.h b/arch/powerpc/include/asm/tlb.h -index f6f68f7..99e1397 100644 ---- a/arch/powerpc/include/asm/tlb.h -+++ b/arch/powerpc/include/asm/tlb.h -@@ -52,11 +52,23 @@ static inline int mm_is_core_local(struct mm_struct *mm) - return cpumask_subset(mm_cpumask(mm), - topology_sibling_cpumask(smp_processor_id())); - } -+ -+static inline int mm_is_thread_local(struct mm_struct *mm) -+{ -+ return cpumask_equal(mm_cpumask(mm), -+ cpumask_of(smp_processor_id())); -+} -+ - #else - static inline int mm_is_core_local(struct mm_struct *mm) - { - return 1; - } -+ -+static inline int mm_is_thread_local(struct mm_struct *mm) -+{ -+ return 1; -+} - #endif - - #endif /* __KERNEL__ */ -diff --git a/arch/powerpc/kernel/idle_book3s.S b/arch/powerpc/kernel/idle_book3s.S -index bd739fe..72dac0b 100644 ---- a/arch/powerpc/kernel/idle_book3s.S -+++ b/arch/powerpc/kernel/idle_book3s.S -@@ -90,6 +90,7 @@ ALT_FTR_SECTION_END_IFSET(CPU_FTR_ARCH_300) - * Threads will spin in HMT_LOW until the lock bit is cleared. - * r14 - pointer to core_idle_state - * r15 - used to load contents of core_idle_state -+ * r9 - used as a temporary variable - */ - - core_idle_lock_held: -@@ -99,6 +100,8 @@ core_idle_lock_held: - bne 3b - HMT_MEDIUM - lwarx r15,0,r14 -+ andi. r9,r15,PNV_CORE_IDLE_LOCK_BIT -+ bne core_idle_lock_held - blr - - /* -@@ -163,12 +166,6 @@ _GLOBAL(pnv_powersave_common) - std r9,_MSR(r1) - std r1,PACAR1(r13) - --#ifdef CONFIG_KVM_BOOK3S_HV_POSSIBLE -- /* Tell KVM we're entering idle */ -- li r4,KVM_HWTHREAD_IN_IDLE -- stb r4,HSTATE_HWTHREAD_STATE(r13) --#endif -- - /* - * Go to real mode to do the nap, as required by the architecture. - * Also, we need to be in real mode before setting hwthread_state, -@@ -185,6 +182,26 @@ _GLOBAL(pnv_powersave_common) - - .globl pnv_enter_arch207_idle_mode - pnv_enter_arch207_idle_mode: -+#ifdef CONFIG_KVM_BOOK3S_HV_POSSIBLE -+ /* Tell KVM we're entering idle */ -+ li r4,KVM_HWTHREAD_IN_IDLE -+ /******************************************************/ -+ /* N O T E W E L L ! ! ! N O T E W E L L */ -+ /* The following store to HSTATE_HWTHREAD_STATE(r13) */ -+ /* MUST occur in real mode, i.e. with the MMU off, */ -+ /* and the MMU must stay off until we clear this flag */ -+ /* and test HSTATE_HWTHREAD_REQ(r13) in the system */ -+ /* reset interrupt vector in exceptions-64s.S. */ -+ /* The reason is that another thread can switch the */ -+ /* MMU to a guest context whenever this flag is set */ -+ /* to KVM_HWTHREAD_IN_IDLE, and if the MMU was on, */ -+ /* that would potentially cause this thread to start */ -+ /* executing instructions from guest memory in */ -+ /* hypervisor mode, leading to a host crash or data */ -+ /* corruption, or worse. */ -+ /******************************************************/ -+ stb r4,HSTATE_HWTHREAD_STATE(r13) -+#endif - stb r3,PACA_THREAD_IDLE_STATE(r13) - cmpwi cr3,r3,PNV_THREAD_SLEEP - bge cr3,2f -@@ -250,6 +267,12 @@ enter_winkle: - * r3 - requested stop state - */ - power_enter_stop: -+#ifdef CONFIG_KVM_BOOK3S_HV_POSSIBLE -+ /* Tell KVM we're entering idle */ -+ li r4,KVM_HWTHREAD_IN_IDLE -+ /* DO THIS IN REAL MODE! See comment above. */ -+ stb r4,HSTATE_HWTHREAD_STATE(r13) -+#endif - /* - * Check if the requested state is a deep idle state. - */ -diff --git a/arch/powerpc/mm/tlb-radix.c b/arch/powerpc/mm/tlb-radix.c -index 48df05e..d696068 100644 ---- a/arch/powerpc/mm/tlb-radix.c -+++ b/arch/powerpc/mm/tlb-radix.c -@@ -175,7 +175,7 @@ void radix__flush_tlb_mm(struct mm_struct *mm) - if (unlikely(pid == MMU_NO_CONTEXT)) - goto no_context; - -- if (!mm_is_core_local(mm)) { -+ if (!mm_is_thread_local(mm)) { - int lock_tlbie = !mmu_has_feature(MMU_FTR_LOCKLESS_TLBIE); - - if (lock_tlbie) -@@ -201,7 +201,7 @@ void radix__flush_tlb_pwc(struct mmu_gather *tlb, unsigned long addr) - if (unlikely(pid == MMU_NO_CONTEXT)) - goto no_context; - -- if (!mm_is_core_local(mm)) { -+ if (!mm_is_thread_local(mm)) { - int lock_tlbie = !mmu_has_feature(MMU_FTR_LOCKLESS_TLBIE); - - if (lock_tlbie) -@@ -226,7 +226,7 @@ void radix__flush_tlb_page_psize(struct mm_struct *mm, unsigned long vmaddr, - pid = mm ? mm->context.id : 0; - if (unlikely(pid == MMU_NO_CONTEXT)) - goto bail; -- if (!mm_is_core_local(mm)) { -+ if (!mm_is_thread_local(mm)) { - int lock_tlbie = !mmu_has_feature(MMU_FTR_LOCKLESS_TLBIE); - - if (lock_tlbie) -@@ -321,7 +321,7 @@ void radix__flush_tlb_range_psize(struct mm_struct *mm, unsigned long start, - { - unsigned long pid; - unsigned long addr; -- int local = mm_is_core_local(mm); -+ int local = mm_is_thread_local(mm); - unsigned long ap = mmu_get_ap(psize); - int lock_tlbie = !mmu_has_feature(MMU_FTR_LOCKLESS_TLBIE); - unsigned long page_size = 1UL << mmu_psize_defs[psize].shift; -diff --git a/arch/s390/kvm/sthyi.c b/arch/s390/kvm/sthyi.c -index bd98b7d..05c98bb 100644 ---- a/arch/s390/kvm/sthyi.c -+++ b/arch/s390/kvm/sthyi.c -@@ -315,7 +315,7 @@ static void fill_diag(struct sthyi_sctns *sctns) - if (r < 0) - goto out; - -- diag224_buf = kmalloc(PAGE_SIZE, GFP_KERNEL | GFP_DMA); -+ diag224_buf = (void *)__get_free_page(GFP_KERNEL | GFP_DMA); - if (!diag224_buf || diag224(diag224_buf)) - goto out; - -@@ -378,7 +378,7 @@ static void fill_diag(struct sthyi_sctns *sctns) - sctns->par.infpval1 |= PAR_WGHT_VLD; - - out: -- kfree(diag224_buf); -+ free_page((unsigned long)diag224_buf); - vfree(diag204_buf); - } - -diff --git a/arch/x86/kernel/cpu/microcode/amd.c b/arch/x86/kernel/cpu/microcode/amd.c -index 620ab06..017bda1 100644 ---- a/arch/x86/kernel/cpu/microcode/amd.c -+++ b/arch/x86/kernel/cpu/microcode/amd.c -@@ -429,7 +429,7 @@ int __init save_microcode_in_initrd_amd(void) - * We need the physical address of the container for both bitness since - * boot_params.hdr.ramdisk_image is a physical address. - */ -- cont = __pa(container); -+ cont = __pa_nodebug(container); - cont_va = container; - #endif - -diff --git a/arch/x86/kernel/setup.c b/arch/x86/kernel/setup.c -index 98c9cd6..d5219b1 100644 ---- a/arch/x86/kernel/setup.c -+++ b/arch/x86/kernel/setup.c -@@ -1222,11 +1222,16 @@ void __init setup_arch(char **cmdline_p) - if (smp_found_config) - get_smp_config(); - -+ /* -+ * Systems w/o ACPI and mptables might not have it mapped the local -+ * APIC yet, but prefill_possible_map() might need to access it. -+ */ -+ init_apic_mappings(); -+ - prefill_possible_map(); - - init_cpu_to_node(); - -- init_apic_mappings(); - io_apic_init_mappings(); - - kvm_guest_init(); -diff --git a/arch/x86/kvm/emulate.c b/arch/x86/kvm/emulate.c -index 4e95d3e..cbd7b92 100644 ---- a/arch/x86/kvm/emulate.c -+++ b/arch/x86/kvm/emulate.c -@@ -5045,7 +5045,7 @@ int x86_decode_insn(struct x86_emulate_ctxt *ctxt, void *insn, int insn_len) - /* Decode and fetch the destination operand: register or memory. */ - rc = decode_operand(ctxt, &ctxt->dst, (ctxt->d >> DstShift) & OpMask); - -- if (ctxt->rip_relative) -+ if (ctxt->rip_relative && likely(ctxt->memopp)) - ctxt->memopp->addr.mem.ea = address_mask(ctxt, - ctxt->memopp->addr.mem.ea + ctxt->_eip); - -diff --git a/arch/x86/kvm/x86.c b/arch/x86/kvm/x86.c -index 699f872..46f74d4 100644 ---- a/arch/x86/kvm/x86.c -+++ b/arch/x86/kvm/x86.c -@@ -7372,10 +7372,12 @@ void kvm_put_guest_fpu(struct kvm_vcpu *vcpu) - - void kvm_arch_vcpu_free(struct kvm_vcpu *vcpu) - { -+ void *wbinvd_dirty_mask = vcpu->arch.wbinvd_dirty_mask; -+ - kvmclock_reset(vcpu); - -- free_cpumask_var(vcpu->arch.wbinvd_dirty_mask); - kvm_x86_ops->vcpu_free(vcpu); -+ free_cpumask_var(wbinvd_dirty_mask); - } - - struct kvm_vcpu *kvm_arch_vcpu_create(struct kvm *kvm, -diff --git a/drivers/android/binder.c b/drivers/android/binder.c -index 16288e7..4b1e4ea 100644 ---- a/drivers/android/binder.c -+++ b/drivers/android/binder.c -@@ -1003,7 +1003,7 @@ static int binder_dec_node(struct binder_node *node, int strong, int internal) - - - static struct binder_ref *binder_get_ref(struct binder_proc *proc, -- uint32_t desc) -+ u32 desc, bool need_strong_ref) - { - struct rb_node *n = proc->refs_by_desc.rb_node; - struct binder_ref *ref; -@@ -1011,12 +1011,16 @@ static struct binder_ref *binder_get_ref(struct binder_proc *proc, - while (n) { - ref = rb_entry(n, struct binder_ref, rb_node_desc); - -- if (desc < ref->desc) -+ if (desc < ref->desc) { - n = n->rb_left; -- else if (desc > ref->desc) -+ } else if (desc > ref->desc) { - n = n->rb_right; -- else -+ } else if (need_strong_ref && !ref->strong) { -+ binder_user_error("tried to use weak ref as strong ref\n"); -+ return NULL; -+ } else { - return ref; -+ } - } - return NULL; - } -@@ -1286,7 +1290,10 @@ static void binder_transaction_buffer_release(struct binder_proc *proc, - } break; - case BINDER_TYPE_HANDLE: - case BINDER_TYPE_WEAK_HANDLE: { -- struct binder_ref *ref = binder_get_ref(proc, fp->handle); -+ struct binder_ref *ref; -+ -+ ref = binder_get_ref(proc, fp->handle, -+ fp->type == BINDER_TYPE_HANDLE); - - if (ref == NULL) { - pr_err("transaction release %d bad handle %d\n", -@@ -1381,7 +1388,7 @@ static void binder_transaction(struct binder_proc *proc, - if (tr->target.handle) { - struct binder_ref *ref; - -- ref = binder_get_ref(proc, tr->target.handle); -+ ref = binder_get_ref(proc, tr->target.handle, true); - if (ref == NULL) { - binder_user_error("%d:%d got transaction to invalid handle\n", - proc->pid, thread->pid); -@@ -1578,7 +1585,9 @@ static void binder_transaction(struct binder_proc *proc, - fp->type = BINDER_TYPE_HANDLE; - else - fp->type = BINDER_TYPE_WEAK_HANDLE; -+ fp->binder = 0; - fp->handle = ref->desc; -+ fp->cookie = 0; - binder_inc_ref(ref, fp->type == BINDER_TYPE_HANDLE, - &thread->todo); - -@@ -1590,7 +1599,10 @@ static void binder_transaction(struct binder_proc *proc, - } break; - case BINDER_TYPE_HANDLE: - case BINDER_TYPE_WEAK_HANDLE: { -- struct binder_ref *ref = binder_get_ref(proc, fp->handle); -+ struct binder_ref *ref; -+ -+ ref = binder_get_ref(proc, fp->handle, -+ fp->type == BINDER_TYPE_HANDLE); - - if (ref == NULL) { - binder_user_error("%d:%d got transaction with invalid handle, %d\n", -@@ -1625,7 +1637,9 @@ static void binder_transaction(struct binder_proc *proc, - return_error = BR_FAILED_REPLY; - goto err_binder_get_ref_for_node_failed; - } -+ fp->binder = 0; - fp->handle = new_ref->desc; -+ fp->cookie = 0; - binder_inc_ref(new_ref, fp->type == BINDER_TYPE_HANDLE, NULL); - trace_binder_transaction_ref_to_ref(t, ref, - new_ref); -@@ -1679,6 +1693,7 @@ static void binder_transaction(struct binder_proc *proc, - binder_debug(BINDER_DEBUG_TRANSACTION, - " fd %d -> %d\n", fp->handle, target_fd); - /* TODO: fput? */ -+ fp->binder = 0; - fp->handle = target_fd; - } break; - -@@ -1801,7 +1816,9 @@ static int binder_thread_write(struct binder_proc *proc, - ref->desc); - } - } else -- ref = binder_get_ref(proc, target); -+ ref = binder_get_ref(proc, target, -+ cmd == BC_ACQUIRE || -+ cmd == BC_RELEASE); - if (ref == NULL) { - binder_user_error("%d:%d refcount change on invalid ref %d\n", - proc->pid, thread->pid, target); -@@ -1997,7 +2014,7 @@ static int binder_thread_write(struct binder_proc *proc, - if (get_user(cookie, (binder_uintptr_t __user *)ptr)) - return -EFAULT; - ptr += sizeof(binder_uintptr_t); -- ref = binder_get_ref(proc, target); -+ ref = binder_get_ref(proc, target, false); - if (ref == NULL) { - binder_user_error("%d:%d %s invalid ref %d\n", - proc->pid, thread->pid, -diff --git a/drivers/char/virtio_console.c b/drivers/char/virtio_console.c -index 5da47e26..4aae0d2 100644 ---- a/drivers/char/virtio_console.c -+++ b/drivers/char/virtio_console.c -@@ -1540,19 +1540,29 @@ static void remove_port_data(struct port *port) - spin_lock_irq(&port->inbuf_lock); - /* Remove unused data this port might have received. */ - discard_port_data(port); -+ spin_unlock_irq(&port->inbuf_lock); - - /* Remove buffers we queued up for the Host to send us data in. */ -- while ((buf = virtqueue_detach_unused_buf(port->in_vq))) -- free_buf(buf, true); -- spin_unlock_irq(&port->inbuf_lock); -+ do { -+ spin_lock_irq(&port->inbuf_lock); -+ buf = virtqueue_detach_unused_buf(port->in_vq); -+ spin_unlock_irq(&port->inbuf_lock); -+ if (buf) -+ free_buf(buf, true); -+ } while (buf); - - spin_lock_irq(&port->outvq_lock); - reclaim_consumed_buffers(port); -+ spin_unlock_irq(&port->outvq_lock); - - /* Free pending buffers from the out-queue. */ -- while ((buf = virtqueue_detach_unused_buf(port->out_vq))) -- free_buf(buf, true); -- spin_unlock_irq(&port->outvq_lock); -+ do { -+ spin_lock_irq(&port->outvq_lock); -+ buf = virtqueue_detach_unused_buf(port->out_vq); -+ spin_unlock_irq(&port->outvq_lock); -+ if (buf) -+ free_buf(buf, true); -+ } while (buf); - } - - /* -diff --git a/drivers/cpufreq/intel_pstate.c b/drivers/cpufreq/intel_pstate.c -index b46547e..8c347f5 100644 ---- a/drivers/cpufreq/intel_pstate.c -+++ b/drivers/cpufreq/intel_pstate.c -@@ -1133,10 +1133,8 @@ static void intel_pstate_get_min_max(struct cpudata *cpu, int *min, int *max) - *min = clamp_t(int, min_perf, cpu->pstate.min_pstate, max_perf); - } - --static void intel_pstate_set_min_pstate(struct cpudata *cpu) -+static void intel_pstate_set_pstate(struct cpudata *cpu, int pstate) - { -- int pstate = cpu->pstate.min_pstate; -- - trace_cpu_frequency(pstate * cpu->pstate.scaling, cpu->cpu); - cpu->pstate.current_pstate = pstate; - /* -@@ -1148,6 +1146,20 @@ static void intel_pstate_set_min_pstate(struct cpudata *cpu) - pstate_funcs.get_val(cpu, pstate)); - } - -+static void intel_pstate_set_min_pstate(struct cpudata *cpu) -+{ -+ intel_pstate_set_pstate(cpu, cpu->pstate.min_pstate); -+} -+ -+static void intel_pstate_max_within_limits(struct cpudata *cpu) -+{ -+ int min_pstate, max_pstate; -+ -+ update_turbo_state(); -+ intel_pstate_get_min_max(cpu, &min_pstate, &max_pstate); -+ intel_pstate_set_pstate(cpu, max_pstate); -+} -+ - static void intel_pstate_get_cpu_pstates(struct cpudata *cpu) - { - cpu->pstate.min_pstate = pstate_funcs.get_min(); -@@ -1465,7 +1477,7 @@ static int intel_pstate_set_policy(struct cpufreq_policy *policy) - pr_debug("set_policy cpuinfo.max %u policy->max %u\n", - policy->cpuinfo.max_freq, policy->max); - -- cpu = all_cpu_data[0]; -+ cpu = all_cpu_data[policy->cpu]; - if (cpu->pstate.max_pstate_physical > cpu->pstate.max_pstate && - policy->max < policy->cpuinfo.max_freq && - policy->max > cpu->pstate.max_pstate * cpu->pstate.scaling) { -@@ -1509,6 +1521,15 @@ static int intel_pstate_set_policy(struct cpufreq_policy *policy) - limits->max_perf = round_up(limits->max_perf, FRAC_BITS); - - out: -+ if (policy->policy == CPUFREQ_POLICY_PERFORMANCE) { -+ /* -+ * NOHZ_FULL CPUs need this as the governor callback may not -+ * be invoked on them. -+ */ -+ intel_pstate_clear_update_util_hook(policy->cpu); -+ intel_pstate_max_within_limits(cpu); -+ } -+ - intel_pstate_set_update_util_hook(policy->cpu); - - intel_pstate_hwp_set_policy(policy); -diff --git a/drivers/dax/pmem.c b/drivers/dax/pmem.c -index 1f01e98..73ae849 100644 ---- a/drivers/dax/pmem.c -+++ b/drivers/dax/pmem.c -@@ -44,7 +44,6 @@ static void dax_pmem_percpu_exit(void *data) - - dev_dbg(dax_pmem->dev, "%s\n", __func__); - percpu_ref_exit(ref); -- wait_for_completion(&dax_pmem->cmp); - } - - static void dax_pmem_percpu_kill(void *data) -@@ -54,6 +53,7 @@ static void dax_pmem_percpu_kill(void *data) - - dev_dbg(dax_pmem->dev, "%s\n", __func__); - percpu_ref_kill(ref); -+ wait_for_completion(&dax_pmem->cmp); - } - - static int dax_pmem_probe(struct device *dev) -diff --git a/drivers/firewire/net.c b/drivers/firewire/net.c -index 309311b..1547589 100644 ---- a/drivers/firewire/net.c -+++ b/drivers/firewire/net.c -@@ -73,13 +73,13 @@ struct rfc2734_header { - - #define fwnet_get_hdr_lf(h) (((h)->w0 & 0xc0000000) >> 30) - #define fwnet_get_hdr_ether_type(h) (((h)->w0 & 0x0000ffff)) --#define fwnet_get_hdr_dg_size(h) (((h)->w0 & 0x0fff0000) >> 16) -+#define fwnet_get_hdr_dg_size(h) ((((h)->w0 & 0x0fff0000) >> 16) + 1) - #define fwnet_get_hdr_fg_off(h) (((h)->w0 & 0x00000fff)) - #define fwnet_get_hdr_dgl(h) (((h)->w1 & 0xffff0000) >> 16) - --#define fwnet_set_hdr_lf(lf) ((lf) << 30) -+#define fwnet_set_hdr_lf(lf) ((lf) << 30) - #define fwnet_set_hdr_ether_type(et) (et) --#define fwnet_set_hdr_dg_size(dgs) ((dgs) << 16) -+#define fwnet_set_hdr_dg_size(dgs) (((dgs) - 1) << 16) - #define fwnet_set_hdr_fg_off(fgo) (fgo) - - #define fwnet_set_hdr_dgl(dgl) ((dgl) << 16) -@@ -578,6 +578,9 @@ static int fwnet_incoming_packet(struct fwnet_device *dev, __be32 *buf, int len, - int retval; - u16 ether_type; - -+ if (len <= RFC2374_UNFRAG_HDR_SIZE) -+ return 0; -+ - hdr.w0 = be32_to_cpu(buf[0]); - lf = fwnet_get_hdr_lf(&hdr); - if (lf == RFC2374_HDR_UNFRAG) { -@@ -602,7 +605,12 @@ static int fwnet_incoming_packet(struct fwnet_device *dev, __be32 *buf, int len, - return fwnet_finish_incoming_packet(net, skb, source_node_id, - is_broadcast, ether_type); - } -+ - /* A datagram fragment has been received, now the fun begins. */ -+ -+ if (len <= RFC2374_FRAG_HDR_SIZE) -+ return 0; -+ - hdr.w1 = ntohl(buf[1]); - buf += 2; - len -= RFC2374_FRAG_HDR_SIZE; -@@ -614,7 +622,10 @@ static int fwnet_incoming_packet(struct fwnet_device *dev, __be32 *buf, int len, - fg_off = fwnet_get_hdr_fg_off(&hdr); - } - datagram_label = fwnet_get_hdr_dgl(&hdr); -- dg_size = fwnet_get_hdr_dg_size(&hdr); /* ??? + 1 */ -+ dg_size = fwnet_get_hdr_dg_size(&hdr); -+ -+ if (fg_off + len > dg_size) -+ return 0; - - spin_lock_irqsave(&dev->lock, flags); - -@@ -722,6 +733,22 @@ static void fwnet_receive_packet(struct fw_card *card, struct fw_request *r, - fw_send_response(card, r, rcode); - } - -+static int gasp_source_id(__be32 *p) -+{ -+ return be32_to_cpu(p[0]) >> 16; -+} -+ -+static u32 gasp_specifier_id(__be32 *p) -+{ -+ return (be32_to_cpu(p[0]) & 0xffff) << 8 | -+ (be32_to_cpu(p[1]) & 0xff000000) >> 24; -+} -+ -+static u32 gasp_version(__be32 *p) -+{ -+ return be32_to_cpu(p[1]) & 0xffffff; -+} -+ - static void fwnet_receive_broadcast(struct fw_iso_context *context, - u32 cycle, size_t header_length, void *header, void *data) - { -@@ -731,9 +758,6 @@ static void fwnet_receive_broadcast(struct fw_iso_context *context, - __be32 *buf_ptr; - int retval; - u32 length; -- u16 source_node_id; -- u32 specifier_id; -- u32 ver; - unsigned long offset; - unsigned long flags; - -@@ -750,22 +774,17 @@ static void fwnet_receive_broadcast(struct fw_iso_context *context, - - spin_unlock_irqrestore(&dev->lock, flags); - -- specifier_id = (be32_to_cpu(buf_ptr[0]) & 0xffff) << 8 -- | (be32_to_cpu(buf_ptr[1]) & 0xff000000) >> 24; -- ver = be32_to_cpu(buf_ptr[1]) & 0xffffff; -- source_node_id = be32_to_cpu(buf_ptr[0]) >> 16; -- -- if (specifier_id == IANA_SPECIFIER_ID && -- (ver == RFC2734_SW_VERSION -+ if (length > IEEE1394_GASP_HDR_SIZE && -+ gasp_specifier_id(buf_ptr) == IANA_SPECIFIER_ID && -+ (gasp_version(buf_ptr) == RFC2734_SW_VERSION - #if IS_ENABLED(CONFIG_IPV6) -- || ver == RFC3146_SW_VERSION -+ || gasp_version(buf_ptr) == RFC3146_SW_VERSION - #endif -- )) { -- buf_ptr += 2; -- length -= IEEE1394_GASP_HDR_SIZE; -- fwnet_incoming_packet(dev, buf_ptr, length, source_node_id, -+ )) -+ fwnet_incoming_packet(dev, buf_ptr + 2, -+ length - IEEE1394_GASP_HDR_SIZE, -+ gasp_source_id(buf_ptr), - context->card->generation, true); -- } - - packet.payload_length = dev->rcv_buffer_size; - packet.interrupt = 1; -diff --git a/drivers/gpio/gpiolib-acpi.c b/drivers/gpio/gpiolib-acpi.c -index af51461..14f2d98 100644 ---- a/drivers/gpio/gpiolib-acpi.c -+++ b/drivers/gpio/gpiolib-acpi.c -@@ -602,14 +602,17 @@ int acpi_dev_gpio_irq_get(struct acpi_device *adev, int index) - { - int idx, i; - unsigned int irq_flags; -+ int ret = -ENOENT; - - for (i = 0, idx = 0; idx <= index; i++) { - struct acpi_gpio_info info; - struct gpio_desc *desc; - - desc = acpi_get_gpiod_by_index(adev, NULL, i, &info); -- if (IS_ERR(desc)) -+ if (IS_ERR(desc)) { -+ ret = PTR_ERR(desc); - break; -+ } - if (info.gpioint && idx++ == index) { - int irq = gpiod_to_irq(desc); - -@@ -628,7 +631,7 @@ int acpi_dev_gpio_irq_get(struct acpi_device *adev, int index) - } - - } -- return -ENOENT; -+ return ret; - } - EXPORT_SYMBOL_GPL(acpi_dev_gpio_irq_get); - -diff --git a/drivers/gpio/gpiolib.c b/drivers/gpio/gpiolib.c -index 53ff25a..b2dee10 100644 ---- a/drivers/gpio/gpiolib.c -+++ b/drivers/gpio/gpiolib.c -@@ -21,6 +21,7 @@ - #include <linux/uaccess.h> - #include <linux/compat.h> - #include <linux/anon_inodes.h> -+#include <linux/file.h> - #include <linux/kfifo.h> - #include <linux/poll.h> - #include <linux/timekeeping.h> -@@ -331,6 +332,13 @@ struct linehandle_state { - u32 numdescs; - }; - -+#define GPIOHANDLE_REQUEST_VALID_FLAGS \ -+ (GPIOHANDLE_REQUEST_INPUT | \ -+ GPIOHANDLE_REQUEST_OUTPUT | \ -+ GPIOHANDLE_REQUEST_ACTIVE_LOW | \ -+ GPIOHANDLE_REQUEST_OPEN_DRAIN | \ -+ GPIOHANDLE_REQUEST_OPEN_SOURCE) -+ - static long linehandle_ioctl(struct file *filep, unsigned int cmd, - unsigned long arg) - { -@@ -342,6 +350,8 @@ static long linehandle_ioctl(struct file *filep, unsigned int cmd, - if (cmd == GPIOHANDLE_GET_LINE_VALUES_IOCTL) { - int val; - -+ memset(&ghd, 0, sizeof(ghd)); -+ - /* TODO: check if descriptors are really input */ - for (i = 0; i < lh->numdescs; i++) { - val = gpiod_get_value_cansleep(lh->descs[i]); -@@ -412,6 +422,7 @@ static int linehandle_create(struct gpio_device *gdev, void __user *ip) - { - struct gpiohandle_request handlereq; - struct linehandle_state *lh; -+ struct file *file; - int fd, i, ret; - - if (copy_from_user(&handlereq, ip, sizeof(handlereq))) -@@ -442,6 +453,17 @@ static int linehandle_create(struct gpio_device *gdev, void __user *ip) - u32 lflags = handlereq.flags; - struct gpio_desc *desc; - -+ if (offset >= gdev->ngpio) { -+ ret = -EINVAL; -+ goto out_free_descs; -+ } -+ -+ /* Return an error if a unknown flag is set */ -+ if (lflags & ~GPIOHANDLE_REQUEST_VALID_FLAGS) { -+ ret = -EINVAL; -+ goto out_free_descs; -+ } -+ - desc = &gdev->descs[offset]; - ret = gpiod_request(desc, lh->label); - if (ret) -@@ -477,26 +499,41 @@ static int linehandle_create(struct gpio_device *gdev, void __user *ip) - i--; - lh->numdescs = handlereq.lines; - -- fd = anon_inode_getfd("gpio-linehandle", -- &linehandle_fileops, -- lh, -- O_RDONLY | O_CLOEXEC); -+ fd = get_unused_fd_flags(O_RDONLY | O_CLOEXEC); - if (fd < 0) { - ret = fd; - goto out_free_descs; - } - -+ file = anon_inode_getfile("gpio-linehandle", -+ &linehandle_fileops, -+ lh, -+ O_RDONLY | O_CLOEXEC); -+ if (IS_ERR(file)) { -+ ret = PTR_ERR(file); -+ goto out_put_unused_fd; -+ } -+ - handlereq.fd = fd; - if (copy_to_user(ip, &handlereq, sizeof(handlereq))) { -- ret = -EFAULT; -- goto out_free_descs; -+ /* -+ * fput() will trigger the release() callback, so do not go onto -+ * the regular error cleanup path here. -+ */ -+ fput(file); -+ put_unused_fd(fd); -+ return -EFAULT; - } - -+ fd_install(fd, file); -+ - dev_dbg(&gdev->dev, "registered chardev handle for %d lines\n", - lh->numdescs); - - return 0; - -+out_put_unused_fd: -+ put_unused_fd(fd); - out_free_descs: - for (; i >= 0; i--) - gpiod_free(lh->descs[i]); -@@ -534,6 +571,10 @@ struct lineevent_state { - struct mutex read_lock; - }; - -+#define GPIOEVENT_REQUEST_VALID_FLAGS \ -+ (GPIOEVENT_REQUEST_RISING_EDGE | \ -+ GPIOEVENT_REQUEST_FALLING_EDGE) -+ - static unsigned int lineevent_poll(struct file *filep, - struct poll_table_struct *wait) - { -@@ -621,6 +662,8 @@ static long lineevent_ioctl(struct file *filep, unsigned int cmd, - if (cmd == GPIOHANDLE_GET_LINE_VALUES_IOCTL) { - int val; - -+ memset(&ghd, 0, sizeof(ghd)); -+ - val = gpiod_get_value_cansleep(le->desc); - if (val < 0) - return val; -@@ -693,6 +736,7 @@ static int lineevent_create(struct gpio_device *gdev, void __user *ip) - struct gpioevent_request eventreq; - struct lineevent_state *le; - struct gpio_desc *desc; -+ struct file *file; - u32 offset; - u32 lflags; - u32 eflags; -@@ -724,6 +768,18 @@ static int lineevent_create(struct gpio_device *gdev, void __user *ip) - lflags = eventreq.handleflags; - eflags = eventreq.eventflags; - -+ if (offset >= gdev->ngpio) { -+ ret = -EINVAL; -+ goto out_free_label; -+ } -+ -+ /* Return an error if a unknown flag is set */ -+ if ((lflags & ~GPIOHANDLE_REQUEST_VALID_FLAGS) || -+ (eflags & ~GPIOEVENT_REQUEST_VALID_FLAGS)) { -+ ret = -EINVAL; -+ goto out_free_label; -+ } -+ - /* This is just wrong: we don't look for events on output lines */ - if (lflags & GPIOHANDLE_REQUEST_OUTPUT) { - ret = -EINVAL; -@@ -775,23 +831,38 @@ static int lineevent_create(struct gpio_device *gdev, void __user *ip) - if (ret) - goto out_free_desc; - -- fd = anon_inode_getfd("gpio-event", -- &lineevent_fileops, -- le, -- O_RDONLY | O_CLOEXEC); -+ fd = get_unused_fd_flags(O_RDONLY | O_CLOEXEC); - if (fd < 0) { - ret = fd; - goto out_free_irq; - } - -+ file = anon_inode_getfile("gpio-event", -+ &lineevent_fileops, -+ le, -+ O_RDONLY | O_CLOEXEC); -+ if (IS_ERR(file)) { -+ ret = PTR_ERR(file); -+ goto out_put_unused_fd; -+ } -+ - eventreq.fd = fd; - if (copy_to_user(ip, &eventreq, sizeof(eventreq))) { -- ret = -EFAULT; -- goto out_free_irq; -+ /* -+ * fput() will trigger the release() callback, so do not go onto -+ * the regular error cleanup path here. -+ */ -+ fput(file); -+ put_unused_fd(fd); -+ return -EFAULT; - } - -+ fd_install(fd, file); -+ - return 0; - -+out_put_unused_fd: -+ put_unused_fd(fd); - out_free_irq: - free_irq(le->irq, le); - out_free_desc: -@@ -821,6 +892,8 @@ static long gpio_ioctl(struct file *filp, unsigned int cmd, unsigned long arg) - if (cmd == GPIO_GET_CHIPINFO_IOCTL) { - struct gpiochip_info chipinfo; - -+ memset(&chipinfo, 0, sizeof(chipinfo)); -+ - strncpy(chipinfo.name, dev_name(&gdev->dev), - sizeof(chipinfo.name)); - chipinfo.name[sizeof(chipinfo.name)-1] = '\0'; -@@ -837,7 +910,7 @@ static long gpio_ioctl(struct file *filp, unsigned int cmd, unsigned long arg) - - if (copy_from_user(&lineinfo, ip, sizeof(lineinfo))) - return -EFAULT; -- if (lineinfo.line_offset > gdev->ngpio) -+ if (lineinfo.line_offset >= gdev->ngpio) - return -EINVAL; - - desc = &gdev->descs[lineinfo.line_offset]; -diff --git a/drivers/gpu/drm/drm_atomic.c b/drivers/gpu/drm/drm_atomic.c -index 2a3ded4..7c8c185 100644 ---- a/drivers/gpu/drm/drm_atomic.c -+++ b/drivers/gpu/drm/drm_atomic.c -@@ -420,18 +420,21 @@ drm_atomic_replace_property_blob_from_id(struct drm_crtc *crtc, - ssize_t expected_size, - bool *replaced) - { -- struct drm_device *dev = crtc->dev; - struct drm_property_blob *new_blob = NULL; - - if (blob_id != 0) { -- new_blob = drm_property_lookup_blob(dev, blob_id); -+ new_blob = drm_property_lookup_blob(crtc->dev, blob_id); - if (new_blob == NULL) - return -EINVAL; -- if (expected_size > 0 && expected_size != new_blob->length) -+ -+ if (expected_size > 0 && expected_size != new_blob->length) { -+ drm_property_unreference_blob(new_blob); - return -EINVAL; -+ } - } - - drm_atomic_replace_property_blob(blob, new_blob, replaced); -+ drm_property_unreference_blob(new_blob); - - return 0; - } -diff --git a/drivers/gpu/drm/drm_dp_mst_topology.c b/drivers/gpu/drm/drm_dp_mst_topology.c -index 04e4571..aa64448 100644 ---- a/drivers/gpu/drm/drm_dp_mst_topology.c -+++ b/drivers/gpu/drm/drm_dp_mst_topology.c -@@ -914,6 +914,7 @@ static void drm_dp_destroy_port(struct kref *kref) - /* no need to clean up vcpi - * as if we have no connector we never setup a vcpi */ - drm_dp_port_teardown_pdt(port, port->pdt); -+ port->pdt = DP_PEER_DEVICE_NONE; - } - kfree(port); - } -@@ -1159,7 +1160,9 @@ static void drm_dp_add_port(struct drm_dp_mst_branch *mstb, - drm_dp_put_port(port); - goto out; - } -- if (port->port_num >= DP_MST_LOGICAL_PORT_0) { -+ if ((port->pdt == DP_PEER_DEVICE_DP_LEGACY_CONV || -+ port->pdt == DP_PEER_DEVICE_SST_SINK) && -+ port->port_num >= DP_MST_LOGICAL_PORT_0) { - port->cached_edid = drm_get_edid(port->connector, &port->aux.ddc); - drm_mode_connector_set_tile_property(port->connector); - } -@@ -2919,6 +2922,7 @@ static void drm_dp_destroy_connector_work(struct work_struct *work) - mgr->cbs->destroy_connector(mgr, port->connector); - - drm_dp_port_teardown_pdt(port, port->pdt); -+ port->pdt = DP_PEER_DEVICE_NONE; - - if (!port->input && port->vcpi.vcpi > 0) { - drm_dp_mst_reset_vcpi_slots(mgr, port); -diff --git a/drivers/gpu/drm/drm_fb_helper.c b/drivers/gpu/drm/drm_fb_helper.c -index 0a06f91..337c555 100644 ---- a/drivers/gpu/drm/drm_fb_helper.c -+++ b/drivers/gpu/drm/drm_fb_helper.c -@@ -129,7 +129,12 @@ int drm_fb_helper_single_add_all_connectors(struct drm_fb_helper *fb_helper) - return 0; - fail: - for (i = 0; i < fb_helper->connector_count; i++) { -- kfree(fb_helper->connector_info[i]); -+ struct drm_fb_helper_connector *fb_helper_connector = -+ fb_helper->connector_info[i]; -+ -+ drm_connector_unreference(fb_helper_connector->connector); -+ -+ kfree(fb_helper_connector); - fb_helper->connector_info[i] = NULL; - } - fb_helper->connector_count = 0; -@@ -601,6 +606,24 @@ int drm_fb_helper_blank(int blank, struct fb_info *info) - } - EXPORT_SYMBOL(drm_fb_helper_blank); - -+static void drm_fb_helper_modeset_release(struct drm_fb_helper *helper, -+ struct drm_mode_set *modeset) -+{ -+ int i; -+ -+ for (i = 0; i < modeset->num_connectors; i++) { -+ drm_connector_unreference(modeset->connectors[i]); -+ modeset->connectors[i] = NULL; -+ } -+ modeset->num_connectors = 0; -+ -+ drm_mode_destroy(helper->dev, modeset->mode); -+ modeset->mode = NULL; -+ -+ /* FIXME should hold a ref? */ -+ modeset->fb = NULL; -+} -+ - static void drm_fb_helper_crtc_free(struct drm_fb_helper *helper) - { - int i; -@@ -610,10 +633,12 @@ static void drm_fb_helper_crtc_free(struct drm_fb_helper *helper) - kfree(helper->connector_info[i]); - } - kfree(helper->connector_info); -+ - for (i = 0; i < helper->crtc_count; i++) { -- kfree(helper->crtc_info[i].mode_set.connectors); -- if (helper->crtc_info[i].mode_set.mode) -- drm_mode_destroy(helper->dev, helper->crtc_info[i].mode_set.mode); -+ struct drm_mode_set *modeset = &helper->crtc_info[i].mode_set; -+ -+ drm_fb_helper_modeset_release(helper, modeset); -+ kfree(modeset->connectors); - } - kfree(helper->crtc_info); - } -@@ -632,7 +657,9 @@ static void drm_fb_helper_dirty_work(struct work_struct *work) - clip->x2 = clip->y2 = 0; - spin_unlock_irqrestore(&helper->dirty_lock, flags); - -- helper->fb->funcs->dirty(helper->fb, NULL, 0, 0, &clip_copy, 1); -+ /* call dirty callback only when it has been really touched */ -+ if (clip_copy.x1 < clip_copy.x2 && clip_copy.y1 < clip_copy.y2) -+ helper->fb->funcs->dirty(helper->fb, NULL, 0, 0, &clip_copy, 1); - } - - /** -@@ -2027,7 +2054,6 @@ static void drm_setup_crtcs(struct drm_fb_helper *fb_helper) - struct drm_fb_helper_crtc **crtcs; - struct drm_display_mode **modes; - struct drm_fb_offset *offsets; -- struct drm_mode_set *modeset; - bool *enabled; - int width, height; - int i; -@@ -2075,45 +2101,35 @@ static void drm_setup_crtcs(struct drm_fb_helper *fb_helper) - - /* need to set the modesets up here for use later */ - /* fill out the connector<->crtc mappings into the modesets */ -- for (i = 0; i < fb_helper->crtc_count; i++) { -- modeset = &fb_helper->crtc_info[i].mode_set; -- modeset->num_connectors = 0; -- modeset->fb = NULL; -- } -+ for (i = 0; i < fb_helper->crtc_count; i++) -+ drm_fb_helper_modeset_release(fb_helper, -+ &fb_helper->crtc_info[i].mode_set); - - for (i = 0; i < fb_helper->connector_count; i++) { - struct drm_display_mode *mode = modes[i]; - struct drm_fb_helper_crtc *fb_crtc = crtcs[i]; - struct drm_fb_offset *offset = &offsets[i]; -- modeset = &fb_crtc->mode_set; -+ struct drm_mode_set *modeset = &fb_crtc->mode_set; - - if (mode && fb_crtc) { -+ struct drm_connector *connector = -+ fb_helper->connector_info[i]->connector; -+ - DRM_DEBUG_KMS("desired mode %s set on crtc %d (%d,%d)\n", - mode->name, fb_crtc->mode_set.crtc->base.id, offset->x, offset->y); -+ - fb_crtc->desired_mode = mode; - fb_crtc->x = offset->x; - fb_crtc->y = offset->y; -- if (modeset->mode) -- drm_mode_destroy(dev, modeset->mode); - modeset->mode = drm_mode_duplicate(dev, - fb_crtc->desired_mode); -- modeset->connectors[modeset->num_connectors++] = fb_helper->connector_info[i]->connector; -+ drm_connector_reference(connector); -+ modeset->connectors[modeset->num_connectors++] = connector; - modeset->fb = fb_helper->fb; - modeset->x = offset->x; - modeset->y = offset->y; - } - } -- -- /* Clear out any old modes if there are no more connected outputs. */ -- for (i = 0; i < fb_helper->crtc_count; i++) { -- modeset = &fb_helper->crtc_info[i].mode_set; -- if (modeset->num_connectors == 0) { -- BUG_ON(modeset->fb); -- if (modeset->mode) -- drm_mode_destroy(dev, modeset->mode); -- modeset->mode = NULL; -- } -- } - out: - kfree(crtcs); - kfree(modes); -diff --git a/drivers/gpu/drm/i915/intel_bios.c b/drivers/gpu/drm/i915/intel_bios.c -index c6e69e4..1f8af87 100644 ---- a/drivers/gpu/drm/i915/intel_bios.c -+++ b/drivers/gpu/drm/i915/intel_bios.c -@@ -1031,6 +1031,77 @@ static u8 translate_iboost(u8 val) - return mapping[val]; - } - -+static void sanitize_ddc_pin(struct drm_i915_private *dev_priv, -+ enum port port) -+{ -+ const struct ddi_vbt_port_info *info = -+ &dev_priv->vbt.ddi_port_info[port]; -+ enum port p; -+ -+ if (!info->alternate_ddc_pin) -+ return; -+ -+ for_each_port_masked(p, (1 << port) - 1) { -+ struct ddi_vbt_port_info *i = &dev_priv->vbt.ddi_port_info[p]; -+ -+ if (info->alternate_ddc_pin != i->alternate_ddc_pin) -+ continue; -+ -+ DRM_DEBUG_KMS("port %c trying to use the same DDC pin (0x%x) as port %c, " -+ "disabling port %c DVI/HDMI support\n", -+ port_name(p), i->alternate_ddc_pin, -+ port_name(port), port_name(p)); -+ -+ /* -+ * If we have multiple ports supposedly sharing the -+ * pin, then dvi/hdmi couldn't exist on the shared -+ * port. Otherwise they share the same ddc bin and -+ * system couldn't communicate with them separately. -+ * -+ * Due to parsing the ports in alphabetical order, -+ * a higher port will always clobber a lower one. -+ */ -+ i->supports_dvi = false; -+ i->supports_hdmi = false; -+ i->alternate_ddc_pin = 0; -+ } -+} -+ -+static void sanitize_aux_ch(struct drm_i915_private *dev_priv, -+ enum port port) -+{ -+ const struct ddi_vbt_port_info *info = -+ &dev_priv->vbt.ddi_port_info[port]; -+ enum port p; -+ -+ if (!info->alternate_aux_channel) -+ return; -+ -+ for_each_port_masked(p, (1 << port) - 1) { -+ struct ddi_vbt_port_info *i = &dev_priv->vbt.ddi_port_info[p]; -+ -+ if (info->alternate_aux_channel != i->alternate_aux_channel) -+ continue; -+ -+ DRM_DEBUG_KMS("port %c trying to use the same AUX CH (0x%x) as port %c, " -+ "disabling port %c DP support\n", -+ port_name(p), i->alternate_aux_channel, -+ port_name(port), port_name(p)); -+ -+ /* -+ * If we have multiple ports supposedlt sharing the -+ * aux channel, then DP couldn't exist on the shared -+ * port. Otherwise they share the same aux channel -+ * and system couldn't communicate with them separately. -+ * -+ * Due to parsing the ports in alphabetical order, -+ * a higher port will always clobber a lower one. -+ */ -+ i->supports_dp = false; -+ i->alternate_aux_channel = 0; -+ } -+} -+ - static void parse_ddi_port(struct drm_i915_private *dev_priv, enum port port, - const struct bdb_header *bdb) - { -@@ -1105,54 +1176,15 @@ static void parse_ddi_port(struct drm_i915_private *dev_priv, enum port port, - DRM_DEBUG_KMS("Port %c is internal DP\n", port_name(port)); - - if (is_dvi) { -- if (port == PORT_E) { -- info->alternate_ddc_pin = ddc_pin; -- /* if DDIE share ddc pin with other port, then -- * dvi/hdmi couldn't exist on the shared port. -- * Otherwise they share the same ddc bin and system -- * couldn't communicate with them seperately. */ -- if (ddc_pin == DDC_PIN_B) { -- dev_priv->vbt.ddi_port_info[PORT_B].supports_dvi = 0; -- dev_priv->vbt.ddi_port_info[PORT_B].supports_hdmi = 0; -- } else if (ddc_pin == DDC_PIN_C) { -- dev_priv->vbt.ddi_port_info[PORT_C].supports_dvi = 0; -- dev_priv->vbt.ddi_port_info[PORT_C].supports_hdmi = 0; -- } else if (ddc_pin == DDC_PIN_D) { -- dev_priv->vbt.ddi_port_info[PORT_D].supports_dvi = 0; -- dev_priv->vbt.ddi_port_info[PORT_D].supports_hdmi = 0; -- } -- } else if (ddc_pin == DDC_PIN_B && port != PORT_B) -- DRM_DEBUG_KMS("Unexpected DDC pin for port B\n"); -- else if (ddc_pin == DDC_PIN_C && port != PORT_C) -- DRM_DEBUG_KMS("Unexpected DDC pin for port C\n"); -- else if (ddc_pin == DDC_PIN_D && port != PORT_D) -- DRM_DEBUG_KMS("Unexpected DDC pin for port D\n"); -+ info->alternate_ddc_pin = ddc_pin; -+ -+ sanitize_ddc_pin(dev_priv, port); - } - - if (is_dp) { -- if (port == PORT_E) { -- info->alternate_aux_channel = aux_channel; -- /* if DDIE share aux channel with other port, then -- * DP couldn't exist on the shared port. Otherwise -- * they share the same aux channel and system -- * couldn't communicate with them seperately. */ -- if (aux_channel == DP_AUX_A) -- dev_priv->vbt.ddi_port_info[PORT_A].supports_dp = 0; -- else if (aux_channel == DP_AUX_B) -- dev_priv->vbt.ddi_port_info[PORT_B].supports_dp = 0; -- else if (aux_channel == DP_AUX_C) -- dev_priv->vbt.ddi_port_info[PORT_C].supports_dp = 0; -- else if (aux_channel == DP_AUX_D) -- dev_priv->vbt.ddi_port_info[PORT_D].supports_dp = 0; -- } -- else if (aux_channel == DP_AUX_A && port != PORT_A) -- DRM_DEBUG_KMS("Unexpected AUX channel for port A\n"); -- else if (aux_channel == DP_AUX_B && port != PORT_B) -- DRM_DEBUG_KMS("Unexpected AUX channel for port B\n"); -- else if (aux_channel == DP_AUX_C && port != PORT_C) -- DRM_DEBUG_KMS("Unexpected AUX channel for port C\n"); -- else if (aux_channel == DP_AUX_D && port != PORT_D) -- DRM_DEBUG_KMS("Unexpected AUX channel for port D\n"); -+ info->alternate_aux_channel = aux_channel; -+ -+ sanitize_aux_ch(dev_priv, port); - } - - if (bdb->version >= 158) { -diff --git a/drivers/gpu/drm/i915/intel_display.c b/drivers/gpu/drm/i915/intel_display.c -index e9a64fb..63462f2 100644 ---- a/drivers/gpu/drm/i915/intel_display.c -+++ b/drivers/gpu/drm/i915/intel_display.c -@@ -13834,7 +13834,7 @@ static void intel_atomic_commit_tail(struct drm_atomic_state *state) - - for_each_plane_in_state(state, plane, plane_state, i) { - struct intel_plane_state *intel_plane_state = -- to_intel_plane_state(plane_state); -+ to_intel_plane_state(plane->state); - - if (!intel_plane_state->wait_req) - continue; -diff --git a/drivers/gpu/drm/i915/intel_dp.c b/drivers/gpu/drm/i915/intel_dp.c -index 1ca155f..3051182 100644 ---- a/drivers/gpu/drm/i915/intel_dp.c -+++ b/drivers/gpu/drm/i915/intel_dp.c -@@ -1090,6 +1090,44 @@ intel_dp_aux_transfer(struct drm_dp_aux *aux, struct drm_dp_aux_msg *msg) - return ret; - } - -+static enum port intel_aux_port(struct drm_i915_private *dev_priv, -+ enum port port) -+{ -+ const struct ddi_vbt_port_info *info = -+ &dev_priv->vbt.ddi_port_info[port]; -+ enum port aux_port; -+ -+ if (!info->alternate_aux_channel) { -+ DRM_DEBUG_KMS("using AUX %c for port %c (platform default)\n", -+ port_name(port), port_name(port)); -+ return port; -+ } -+ -+ switch (info->alternate_aux_channel) { -+ case DP_AUX_A: -+ aux_port = PORT_A; -+ break; -+ case DP_AUX_B: -+ aux_port = PORT_B; -+ break; -+ case DP_AUX_C: -+ aux_port = PORT_C; -+ break; -+ case DP_AUX_D: -+ aux_port = PORT_D; -+ break; -+ default: -+ MISSING_CASE(info->alternate_aux_channel); -+ aux_port = PORT_A; -+ break; -+ } -+ -+ DRM_DEBUG_KMS("using AUX %c for port %c (VBT)\n", -+ port_name(aux_port), port_name(port)); -+ -+ return aux_port; -+} -+ - static i915_reg_t g4x_aux_ctl_reg(struct drm_i915_private *dev_priv, - enum port port) - { -@@ -1150,36 +1188,9 @@ static i915_reg_t ilk_aux_data_reg(struct drm_i915_private *dev_priv, - } - } - --/* -- * On SKL we don't have Aux for port E so we rely -- * on VBT to set a proper alternate aux channel. -- */ --static enum port skl_porte_aux_port(struct drm_i915_private *dev_priv) --{ -- const struct ddi_vbt_port_info *info = -- &dev_priv->vbt.ddi_port_info[PORT_E]; -- -- switch (info->alternate_aux_channel) { -- case DP_AUX_A: -- return PORT_A; -- case DP_AUX_B: -- return PORT_B; -- case DP_AUX_C: -- return PORT_C; -- case DP_AUX_D: -- return PORT_D; -- default: -- MISSING_CASE(info->alternate_aux_channel); -- return PORT_A; -- } --} -- - static i915_reg_t skl_aux_ctl_reg(struct drm_i915_private *dev_priv, - enum port port) - { -- if (port == PORT_E) -- port = skl_porte_aux_port(dev_priv); -- - switch (port) { - case PORT_A: - case PORT_B: -@@ -1195,9 +1206,6 @@ static i915_reg_t skl_aux_ctl_reg(struct drm_i915_private *dev_priv, - static i915_reg_t skl_aux_data_reg(struct drm_i915_private *dev_priv, - enum port port, int index) - { -- if (port == PORT_E) -- port = skl_porte_aux_port(dev_priv); -- - switch (port) { - case PORT_A: - case PORT_B: -@@ -1235,7 +1243,8 @@ static i915_reg_t intel_aux_data_reg(struct drm_i915_private *dev_priv, - static void intel_aux_reg_init(struct intel_dp *intel_dp) - { - struct drm_i915_private *dev_priv = to_i915(intel_dp_to_dev(intel_dp)); -- enum port port = dp_to_dig_port(intel_dp)->port; -+ enum port port = intel_aux_port(dev_priv, -+ dp_to_dig_port(intel_dp)->port); - int i; - - intel_dp->aux_ch_ctl_reg = intel_aux_ctl_reg(dev_priv, port); -diff --git a/drivers/gpu/drm/i915/intel_fbc.c b/drivers/gpu/drm/i915/intel_fbc.c -index 3836a1c..ad483376 100644 ---- a/drivers/gpu/drm/i915/intel_fbc.c -+++ b/drivers/gpu/drm/i915/intel_fbc.c -@@ -104,8 +104,10 @@ static int intel_fbc_calculate_cfb_size(struct drm_i915_private *dev_priv, - int lines; - - intel_fbc_get_plane_source_size(cache, NULL, &lines); -- if (INTEL_INFO(dev_priv)->gen >= 7) -+ if (INTEL_GEN(dev_priv) == 7) - lines = min(lines, 2048); -+ else if (INTEL_GEN(dev_priv) >= 8) -+ lines = min(lines, 2560); - - /* Hardware needs the full buffer stride, not just the active area. */ - return lines * cache->fb.stride; -diff --git a/drivers/gpu/drm/i915/intel_pm.c b/drivers/gpu/drm/i915/intel_pm.c -index e59a28c..a691605 100644 ---- a/drivers/gpu/drm/i915/intel_pm.c -+++ b/drivers/gpu/drm/i915/intel_pm.c -@@ -3363,13 +3363,15 @@ skl_allocate_pipe_ddb(struct intel_crtc_state *cstate, - int num_active; - int id, i; - -+ /* Clear the partitioning for disabled planes. */ -+ memset(ddb->plane[pipe], 0, sizeof(ddb->plane[pipe])); -+ memset(ddb->y_plane[pipe], 0, sizeof(ddb->y_plane[pipe])); -+ - if (WARN_ON(!state)) - return 0; - - if (!cstate->base.active) { - ddb->pipe[pipe].start = ddb->pipe[pipe].end = 0; -- memset(ddb->plane[pipe], 0, sizeof(ddb->plane[pipe])); -- memset(ddb->y_plane[pipe], 0, sizeof(ddb->y_plane[pipe])); - return 0; - } - -@@ -3469,12 +3471,6 @@ skl_allocate_pipe_ddb(struct intel_crtc_state *cstate, - return 0; - } - --static uint32_t skl_pipe_pixel_rate(const struct intel_crtc_state *config) --{ -- /* TODO: Take into account the scalers once we support them */ -- return config->base.adjusted_mode.crtc_clock; --} -- - /* - * The max latency should be 257 (max the punit can code is 255 and we add 2us - * for the read latency) and cpp should always be <= 8, so that -@@ -3525,7 +3521,7 @@ static uint32_t skl_adjusted_plane_pixel_rate(const struct intel_crtc_state *cst - * Adjusted plane pixel rate is just the pipe's adjusted pixel rate - * with additional adjustments for plane-specific scaling. - */ -- adjusted_pixel_rate = skl_pipe_pixel_rate(cstate); -+ adjusted_pixel_rate = ilk_pipe_pixel_rate(cstate); - downscale_amount = skl_plane_downscale_amount(pstate); - - pixel_rate = adjusted_pixel_rate * downscale_amount >> 16; -@@ -3737,11 +3733,11 @@ skl_compute_linetime_wm(struct intel_crtc_state *cstate) - if (!cstate->base.active) - return 0; - -- if (WARN_ON(skl_pipe_pixel_rate(cstate) == 0)) -+ if (WARN_ON(ilk_pipe_pixel_rate(cstate) == 0)) - return 0; - - return DIV_ROUND_UP(8 * cstate->base.adjusted_mode.crtc_htotal * 1000, -- skl_pipe_pixel_rate(cstate)); -+ ilk_pipe_pixel_rate(cstate)); - } - - static void skl_compute_transition_wm(struct intel_crtc_state *cstate, -@@ -4051,6 +4047,12 @@ skl_compute_ddb(struct drm_atomic_state *state) - intel_state->wm_results.dirty_pipes = ~0; - } - -+ /* -+ * We're not recomputing for the pipes not included in the commit, so -+ * make sure we start with the current state. -+ */ -+ memcpy(ddb, &dev_priv->wm.skl_hw.ddb, sizeof(*ddb)); -+ - for_each_intel_crtc_mask(dev, intel_crtc, realloc_pipes) { - struct intel_crtc_state *cstate; - -diff --git a/drivers/gpu/drm/imx/ipuv3-plane.c b/drivers/gpu/drm/imx/ipuv3-plane.c -index 29423e75..927c51e 100644 ---- a/drivers/gpu/drm/imx/ipuv3-plane.c -+++ b/drivers/gpu/drm/imx/ipuv3-plane.c -@@ -108,6 +108,7 @@ static void ipu_plane_atomic_set_base(struct ipu_plane *ipu_plane, - { - struct drm_plane *plane = &ipu_plane->base; - struct drm_plane_state *state = plane->state; -+ struct drm_crtc_state *crtc_state = state->crtc->state; - struct drm_framebuffer *fb = state->fb; - unsigned long eba, ubo, vbo; - int active; -@@ -149,7 +150,7 @@ static void ipu_plane_atomic_set_base(struct ipu_plane *ipu_plane, - break; - } - -- if (old_state->fb) { -+ if (!drm_atomic_crtc_needs_modeset(crtc_state)) { - active = ipu_idmac_get_current_buffer(ipu_plane->ipu_ch); - ipu_cpmem_set_buffer(ipu_plane->ipu_ch, !active, eba); - ipu_idmac_select_buffer(ipu_plane->ipu_ch, !active); -@@ -359,7 +360,9 @@ static int ipu_plane_atomic_check(struct drm_plane *plane, - if ((ubo > 0xfffff8) || (vbo > 0xfffff8)) - return -EINVAL; - -- if (old_fb) { -+ if (old_fb && -+ (old_fb->pixel_format == DRM_FORMAT_YUV420 || -+ old_fb->pixel_format == DRM_FORMAT_YVU420)) { - old_ubo = drm_plane_state_to_ubo(old_state); - old_vbo = drm_plane_state_to_vbo(old_state); - if (ubo != old_ubo || vbo != old_vbo) -diff --git a/drivers/gpu/drm/nouveau/nouveau_acpi.c b/drivers/gpu/drm/nouveau/nouveau_acpi.c -index dc57b62..193573d 100644 ---- a/drivers/gpu/drm/nouveau/nouveau_acpi.c -+++ b/drivers/gpu/drm/nouveau/nouveau_acpi.c -@@ -240,7 +240,8 @@ static bool nouveau_pr3_present(struct pci_dev *pdev) - if (!parent_adev) - return false; - -- return acpi_has_method(parent_adev->handle, "_PR3"); -+ return parent_adev->power.flags.power_resources && -+ acpi_has_method(parent_adev->handle, "_PR3"); - } - - static void nouveau_dsm_pci_probe(struct pci_dev *pdev, acpi_handle *dhandle_out, -diff --git a/drivers/gpu/drm/radeon/ni.c b/drivers/gpu/drm/radeon/ni.c -index 4a3d7ca..4b9c2d5 100644 ---- a/drivers/gpu/drm/radeon/ni.c -+++ b/drivers/gpu/drm/radeon/ni.c -@@ -1396,9 +1396,7 @@ static void cayman_pcie_gart_fini(struct radeon_device *rdev) - void cayman_cp_int_cntl_setup(struct radeon_device *rdev, - int ring, u32 cp_int_cntl) - { -- u32 srbm_gfx_cntl = RREG32(SRBM_GFX_CNTL) & ~3; -- -- WREG32(SRBM_GFX_CNTL, srbm_gfx_cntl | (ring & 3)); -+ WREG32(SRBM_GFX_CNTL, RINGID(ring)); - WREG32(CP_INT_CNTL, cp_int_cntl); - } - -diff --git a/drivers/gpu/drm/radeon/radeon_dp_auxch.c b/drivers/gpu/drm/radeon/radeon_dp_auxch.c -index db64e00..3b0c229 100644 ---- a/drivers/gpu/drm/radeon/radeon_dp_auxch.c -+++ b/drivers/gpu/drm/radeon/radeon_dp_auxch.c -@@ -105,7 +105,7 @@ radeon_dp_aux_transfer_native(struct drm_dp_aux *aux, struct drm_dp_aux_msg *msg - - tmp &= AUX_HPD_SEL(0x7); - tmp |= AUX_HPD_SEL(chan->rec.hpd); -- tmp |= AUX_EN | AUX_LS_READ_EN | AUX_HPD_DISCON(0x1); -+ tmp |= AUX_EN | AUX_LS_READ_EN; - - WREG32(AUX_CONTROL + aux_offset[instance], tmp); - -diff --git a/drivers/gpu/drm/radeon/si_dpm.c b/drivers/gpu/drm/radeon/si_dpm.c -index 89bdf20..c4993452 100644 ---- a/drivers/gpu/drm/radeon/si_dpm.c -+++ b/drivers/gpu/drm/radeon/si_dpm.c -@@ -2999,6 +2999,49 @@ static void si_apply_state_adjust_rules(struct radeon_device *rdev, - int i; - struct si_dpm_quirk *p = si_dpm_quirk_list; - -+ /* limit all SI kickers */ -+ if (rdev->family == CHIP_PITCAIRN) { -+ if ((rdev->pdev->revision == 0x81) || -+ (rdev->pdev->device == 0x6810) || -+ (rdev->pdev->device == 0x6811) || -+ (rdev->pdev->device == 0x6816) || -+ (rdev->pdev->device == 0x6817) || -+ (rdev->pdev->device == 0x6806)) -+ max_mclk = 120000; -+ } else if (rdev->family == CHIP_VERDE) { -+ if ((rdev->pdev->revision == 0x81) || -+ (rdev->pdev->revision == 0x83) || -+ (rdev->pdev->revision == 0x87) || -+ (rdev->pdev->device == 0x6820) || -+ (rdev->pdev->device == 0x6821) || -+ (rdev->pdev->device == 0x6822) || -+ (rdev->pdev->device == 0x6823) || -+ (rdev->pdev->device == 0x682A) || -+ (rdev->pdev->device == 0x682B)) { -+ max_sclk = 75000; -+ max_mclk = 80000; -+ } -+ } else if (rdev->family == CHIP_OLAND) { -+ if ((rdev->pdev->revision == 0xC7) || -+ (rdev->pdev->revision == 0x80) || -+ (rdev->pdev->revision == 0x81) || -+ (rdev->pdev->revision == 0x83) || -+ (rdev->pdev->device == 0x6604) || -+ (rdev->pdev->device == 0x6605)) { -+ max_sclk = 75000; -+ max_mclk = 80000; -+ } -+ } else if (rdev->family == CHIP_HAINAN) { -+ if ((rdev->pdev->revision == 0x81) || -+ (rdev->pdev->revision == 0x83) || -+ (rdev->pdev->revision == 0xC3) || -+ (rdev->pdev->device == 0x6664) || -+ (rdev->pdev->device == 0x6665) || -+ (rdev->pdev->device == 0x6667)) { -+ max_sclk = 75000; -+ max_mclk = 80000; -+ } -+ } - /* Apply dpm quirks */ - while (p && p->chip_device != 0) { - if (rdev->pdev->vendor == p->chip_vendor && -@@ -3011,16 +3054,6 @@ static void si_apply_state_adjust_rules(struct radeon_device *rdev, - } - ++p; - } -- /* limit mclk on all R7 370 parts for stability */ -- if (rdev->pdev->device == 0x6811 && -- rdev->pdev->revision == 0x81) -- max_mclk = 120000; -- /* limit sclk/mclk on Jet parts for stability */ -- if (rdev->pdev->device == 0x6665 && -- rdev->pdev->revision == 0xc3) { -- max_sclk = 75000; -- max_mclk = 80000; -- } - - if (rps->vce_active) { - rps->evclk = rdev->pm.dpm.vce_states[rdev->pm.dpm.vce_level].evclk; -diff --git a/drivers/hid/hid-ids.h b/drivers/hid/hid-ids.h -index e92b09d..9ab703c 100644 ---- a/drivers/hid/hid-ids.h -+++ b/drivers/hid/hid-ids.h -@@ -179,6 +179,7 @@ - #define USB_DEVICE_ID_ATEN_4PORTKVM 0x2205 - #define USB_DEVICE_ID_ATEN_4PORTKVMC 0x2208 - #define USB_DEVICE_ID_ATEN_CS682 0x2213 -+#define USB_DEVICE_ID_ATEN_CS692 0x8021 - - #define USB_VENDOR_ID_ATMEL 0x03eb - #define USB_DEVICE_ID_ATMEL_MULTITOUCH 0x211c -diff --git a/drivers/hid/usbhid/hid-quirks.c b/drivers/hid/usbhid/hid-quirks.c -index bb40008..85fcf60 100644 ---- a/drivers/hid/usbhid/hid-quirks.c -+++ b/drivers/hid/usbhid/hid-quirks.c -@@ -63,6 +63,7 @@ static const struct hid_blacklist { - { USB_VENDOR_ID_ATEN, USB_DEVICE_ID_ATEN_4PORTKVM, HID_QUIRK_NOGET }, - { USB_VENDOR_ID_ATEN, USB_DEVICE_ID_ATEN_4PORTKVMC, HID_QUIRK_NOGET }, - { USB_VENDOR_ID_ATEN, USB_DEVICE_ID_ATEN_CS682, HID_QUIRK_NOGET }, -+ { USB_VENDOR_ID_ATEN, USB_DEVICE_ID_ATEN_CS692, HID_QUIRK_NOGET }, - { USB_VENDOR_ID_CH, USB_DEVICE_ID_CH_FIGHTERSTICK, HID_QUIRK_NOGET }, - { USB_VENDOR_ID_CH, USB_DEVICE_ID_CH_COMBATSTICK, HID_QUIRK_NOGET }, - { USB_VENDOR_ID_CH, USB_DEVICE_ID_CH_FLIGHT_SIM_ECLIPSE_YOKE, HID_QUIRK_NOGET }, -diff --git a/drivers/hv/hv_util.c b/drivers/hv/hv_util.c -index d5acaa2..9dc6372 100644 ---- a/drivers/hv/hv_util.c -+++ b/drivers/hv/hv_util.c -@@ -283,10 +283,14 @@ static void heartbeat_onchannelcallback(void *context) - u8 *hbeat_txf_buf = util_heartbeat.recv_buffer; - struct icmsg_negotiate *negop = NULL; - -- vmbus_recvpacket(channel, hbeat_txf_buf, -- PAGE_SIZE, &recvlen, &requestid); -+ while (1) { -+ -+ vmbus_recvpacket(channel, hbeat_txf_buf, -+ PAGE_SIZE, &recvlen, &requestid); -+ -+ if (!recvlen) -+ break; - -- if (recvlen > 0) { - icmsghdrp = (struct icmsg_hdr *)&hbeat_txf_buf[ - sizeof(struct vmbuspipe_hdr)]; - -diff --git a/drivers/i2c/busses/i2c-rk3x.c b/drivers/i2c/busses/i2c-rk3x.c -index 5c5b7ca..dfae435 100644 ---- a/drivers/i2c/busses/i2c-rk3x.c -+++ b/drivers/i2c/busses/i2c-rk3x.c -@@ -694,6 +694,8 @@ static int rk3x_i2c_v0_calc_timings(unsigned long clk_rate, - t_calc->div_low--; - t_calc->div_high--; - -+ /* Give the tuning value 0, that would not update con register */ -+ t_calc->tuning = 0; - /* Maximum divider supported by hw is 0xffff */ - if (t_calc->div_low > 0xffff) { - t_calc->div_low = 0xffff; -diff --git a/drivers/i2c/busses/i2c-xgene-slimpro.c b/drivers/i2c/busses/i2c-xgene-slimpro.c -index 4233f56..3c38029 100644 ---- a/drivers/i2c/busses/i2c-xgene-slimpro.c -+++ b/drivers/i2c/busses/i2c-xgene-slimpro.c -@@ -105,7 +105,7 @@ struct slimpro_i2c_dev { - struct mbox_chan *mbox_chan; - struct mbox_client mbox_client; - struct completion rd_complete; -- u8 dma_buffer[I2C_SMBUS_BLOCK_MAX]; -+ u8 dma_buffer[I2C_SMBUS_BLOCK_MAX + 1]; /* dma_buffer[0] is used for length */ - u32 *resp_msg; - }; - -diff --git a/drivers/i2c/i2c-core.c b/drivers/i2c/i2c-core.c -index da3a02e..a9a9f66 100644 ---- a/drivers/i2c/i2c-core.c -+++ b/drivers/i2c/i2c-core.c -@@ -1592,6 +1592,7 @@ static struct i2c_client *of_i2c_register_device(struct i2c_adapter *adap, - static void of_i2c_register_devices(struct i2c_adapter *adap) - { - struct device_node *node; -+ struct i2c_client *client; - - /* Only register child devices if the adapter has a node pointer set */ - if (!adap->dev.of_node) -@@ -1602,7 +1603,14 @@ static void of_i2c_register_devices(struct i2c_adapter *adap) - for_each_available_child_of_node(adap->dev.of_node, node) { - if (of_node_test_and_set_flag(node, OF_POPULATED)) - continue; -- of_i2c_register_device(adap, node); -+ -+ client = of_i2c_register_device(adap, node); -+ if (IS_ERR(client)) { -+ dev_warn(&adap->dev, -+ "Failed to create I2C device for %s\n", -+ node->full_name); -+ of_node_clear_flag(node, OF_POPULATED); -+ } - } - } - -@@ -2073,6 +2081,7 @@ int i2c_register_driver(struct module *owner, struct i2c_driver *driver) - /* add the driver to the list of i2c drivers in the driver core */ - driver->driver.owner = owner; - driver->driver.bus = &i2c_bus_type; -+ INIT_LIST_HEAD(&driver->clients); - - /* When registration returns, the driver core - * will have called probe() for all matching-but-unbound devices. -@@ -2083,7 +2092,6 @@ int i2c_register_driver(struct module *owner, struct i2c_driver *driver) - - pr_debug("driver [%s] registered\n", driver->driver.name); - -- INIT_LIST_HEAD(&driver->clients); - /* Walk the adapters that are already present */ - i2c_for_each_dev(driver, __process_new_driver); - -@@ -2201,6 +2209,7 @@ static int of_i2c_notify(struct notifier_block *nb, unsigned long action, - if (IS_ERR(client)) { - dev_err(&adap->dev, "failed to create client for '%s'\n", - rd->dn->full_name); -+ of_node_clear_flag(rd->dn, OF_POPULATED); - return notifier_from_errno(PTR_ERR(client)); - } - break; -diff --git a/drivers/iio/chemical/atlas-ph-sensor.c b/drivers/iio/chemical/atlas-ph-sensor.c -index 407f141..a3fbdb7 100644 ---- a/drivers/iio/chemical/atlas-ph-sensor.c -+++ b/drivers/iio/chemical/atlas-ph-sensor.c -@@ -207,13 +207,14 @@ static int atlas_check_ec_calibration(struct atlas_data *data) - struct device *dev = &data->client->dev; - int ret; - unsigned int val; -+ __be16 rval; - -- ret = regmap_bulk_read(data->regmap, ATLAS_REG_EC_PROBE, &val, 2); -+ ret = regmap_bulk_read(data->regmap, ATLAS_REG_EC_PROBE, &rval, 2); - if (ret) - return ret; - -- dev_info(dev, "probe set to K = %d.%.2d", be16_to_cpu(val) / 100, -- be16_to_cpu(val) % 100); -+ val = be16_to_cpu(rval); -+ dev_info(dev, "probe set to K = %d.%.2d", val / 100, val % 100); - - ret = regmap_read(data->regmap, ATLAS_REG_EC_CALIB_STATUS, &val); - if (ret) -diff --git a/drivers/input/serio/i8042-x86ia64io.h b/drivers/input/serio/i8042-x86ia64io.h -index f4bfb4b..073246c 100644 ---- a/drivers/input/serio/i8042-x86ia64io.h -+++ b/drivers/input/serio/i8042-x86ia64io.h -@@ -877,6 +877,13 @@ static const struct dmi_system_id __initconst i8042_dmi_kbdreset_table[] = { - DMI_MATCH(DMI_PRODUCT_NAME, "P34"), - }, - }, -+ { -+ /* Schenker XMG C504 - Elantech touchpad */ -+ .matches = { -+ DMI_MATCH(DMI_SYS_VENDOR, "XMG"), -+ DMI_MATCH(DMI_PRODUCT_NAME, "C504"), -+ }, -+ }, - { } - }; - -diff --git a/drivers/md/dm-raid.c b/drivers/md/dm-raid.c -index 8abde6b..6d53810 100644 ---- a/drivers/md/dm-raid.c -+++ b/drivers/md/dm-raid.c -@@ -266,7 +266,7 @@ static struct raid_type { - {"raid10_offset", "raid10 offset (striped mirrors)", 0, 2, 10, ALGORITHM_RAID10_OFFSET}, - {"raid10_near", "raid10 near (striped mirrors)", 0, 2, 10, ALGORITHM_RAID10_NEAR}, - {"raid10", "raid10 (striped mirrors)", 0, 2, 10, ALGORITHM_RAID10_DEFAULT}, -- {"raid4", "raid4 (dedicated last parity disk)", 1, 2, 4, ALGORITHM_PARITY_N}, /* raid4 layout = raid5_n */ -+ {"raid4", "raid4 (dedicated first parity disk)", 1, 2, 5, ALGORITHM_PARITY_0}, /* raid4 layout = raid5_0 */ - {"raid5_n", "raid5 (dedicated last parity disk)", 1, 2, 5, ALGORITHM_PARITY_N}, - {"raid5_ls", "raid5 (left symmetric)", 1, 2, 5, ALGORITHM_LEFT_SYMMETRIC}, - {"raid5_rs", "raid5 (right symmetric)", 1, 2, 5, ALGORITHM_RIGHT_SYMMETRIC}, -@@ -2087,11 +2087,11 @@ static int super_init_validation(struct raid_set *rs, struct md_rdev *rdev) - /* - * No takeover/reshaping, because we don't have the extended v1.9.0 metadata - */ -- if (le32_to_cpu(sb->level) != mddev->level) { -+ if (le32_to_cpu(sb->level) != mddev->new_level) { - DMERR("Reshaping/takeover raid sets not yet supported. (raid level/stripes/size change)"); - return -EINVAL; - } -- if (le32_to_cpu(sb->layout) != mddev->layout) { -+ if (le32_to_cpu(sb->layout) != mddev->new_layout) { - DMERR("Reshaping raid sets not yet supported. (raid layout change)"); - DMERR(" 0x%X vs 0x%X", le32_to_cpu(sb->layout), mddev->layout); - DMERR(" Old layout: %s w/ %d copies", -@@ -2102,7 +2102,7 @@ static int super_init_validation(struct raid_set *rs, struct md_rdev *rdev) - raid10_md_layout_to_copies(mddev->layout)); - return -EINVAL; - } -- if (le32_to_cpu(sb->stripe_sectors) != mddev->chunk_sectors) { -+ if (le32_to_cpu(sb->stripe_sectors) != mddev->new_chunk_sectors) { - DMERR("Reshaping raid sets not yet supported. (stripe sectors change)"); - return -EINVAL; - } -@@ -2115,6 +2115,8 @@ static int super_init_validation(struct raid_set *rs, struct md_rdev *rdev) - return -EINVAL; - } - -+ DMINFO("Discovered old metadata format; upgrading to extended metadata format"); -+ - /* Table line is checked vs. authoritative superblock */ - rs_set_new(rs); - } -@@ -2258,7 +2260,8 @@ static int super_validate(struct raid_set *rs, struct md_rdev *rdev) - if (!mddev->events && super_init_validation(rs, rdev)) - return -EINVAL; - -- if (le32_to_cpu(sb->compat_features) != FEATURE_FLAG_SUPPORTS_V190) { -+ if (le32_to_cpu(sb->compat_features) && -+ le32_to_cpu(sb->compat_features) != FEATURE_FLAG_SUPPORTS_V190) { - rs->ti->error = "Unable to assemble array: Unknown flag(s) in compatible feature flags"; - return -EINVAL; - } -@@ -3646,7 +3649,7 @@ static void raid_resume(struct dm_target *ti) - - static struct target_type raid_target = { - .name = "raid", -- .version = {1, 9, 0}, -+ .version = {1, 9, 1}, - .module = THIS_MODULE, - .ctr = raid_ctr, - .dtr = raid_dtr, -diff --git a/drivers/md/dm-raid1.c b/drivers/md/dm-raid1.c -index bdf1606..7a6254d 100644 ---- a/drivers/md/dm-raid1.c -+++ b/drivers/md/dm-raid1.c -@@ -1292,6 +1292,7 @@ static int mirror_end_io(struct dm_target *ti, struct bio *bio, int error) - - dm_bio_restore(bd, bio); - bio_record->details.bi_bdev = NULL; -+ bio->bi_error = 0; - - queue_bio(ms, bio, rw); - return DM_ENDIO_INCOMPLETE; -diff --git a/drivers/md/dm-rq.c b/drivers/md/dm-rq.c -index 5da86c8..2154596 100644 ---- a/drivers/md/dm-rq.c -+++ b/drivers/md/dm-rq.c -@@ -835,8 +835,11 @@ int dm_old_init_request_queue(struct mapped_device *md) - init_kthread_worker(&md->kworker); - md->kworker_task = kthread_run(kthread_worker_fn, &md->kworker, - "kdmwork-%s", dm_device_name(md)); -- if (IS_ERR(md->kworker_task)) -- return PTR_ERR(md->kworker_task); -+ if (IS_ERR(md->kworker_task)) { -+ int error = PTR_ERR(md->kworker_task); -+ md->kworker_task = NULL; -+ return error; -+ } - - elv_register_queue(md->queue); - -diff --git a/drivers/md/dm-table.c b/drivers/md/dm-table.c -index 3e407a9..c4b53b3 100644 ---- a/drivers/md/dm-table.c -+++ b/drivers/md/dm-table.c -@@ -695,37 +695,32 @@ int dm_table_add_target(struct dm_table *t, const char *type, - - tgt->type = dm_get_target_type(type); - if (!tgt->type) { -- DMERR("%s: %s: unknown target type", dm_device_name(t->md), -- type); -+ DMERR("%s: %s: unknown target type", dm_device_name(t->md), type); - return -EINVAL; - } - - if (dm_target_needs_singleton(tgt->type)) { - if (t->num_targets) { -- DMERR("%s: target type %s must appear alone in table", -- dm_device_name(t->md), type); -- return -EINVAL; -+ tgt->error = "singleton target type must appear alone in table"; -+ goto bad; - } - t->singleton = true; - } - - if (dm_target_always_writeable(tgt->type) && !(t->mode & FMODE_WRITE)) { -- DMERR("%s: target type %s may not be included in read-only tables", -- dm_device_name(t->md), type); -- return -EINVAL; -+ tgt->error = "target type may not be included in a read-only table"; -+ goto bad; - } - - if (t->immutable_target_type) { - if (t->immutable_target_type != tgt->type) { -- DMERR("%s: immutable target type %s cannot be mixed with other target types", -- dm_device_name(t->md), t->immutable_target_type->name); -- return -EINVAL; -+ tgt->error = "immutable target type cannot be mixed with other target types"; -+ goto bad; - } - } else if (dm_target_is_immutable(tgt->type)) { - if (t->num_targets) { -- DMERR("%s: immutable target type %s cannot be mixed with other target types", -- dm_device_name(t->md), tgt->type->name); -- return -EINVAL; -+ tgt->error = "immutable target type cannot be mixed with other target types"; -+ goto bad; - } - t->immutable_target_type = tgt->type; - } -@@ -740,7 +735,6 @@ int dm_table_add_target(struct dm_table *t, const char *type, - */ - if (!adjoin(t, tgt)) { - tgt->error = "Gap in table"; -- r = -EINVAL; - goto bad; - } - -diff --git a/drivers/md/dm.c b/drivers/md/dm.c -index 0f2928b..eeef575 100644 ---- a/drivers/md/dm.c -+++ b/drivers/md/dm.c -@@ -1423,8 +1423,6 @@ static void cleanup_mapped_device(struct mapped_device *md) - if (md->bs) - bioset_free(md->bs); - -- cleanup_srcu_struct(&md->io_barrier); -- - if (md->disk) { - spin_lock(&_minor_lock); - md->disk->private_data = NULL; -@@ -1436,6 +1434,8 @@ static void cleanup_mapped_device(struct mapped_device *md) - if (md->queue) - blk_cleanup_queue(md->queue); - -+ cleanup_srcu_struct(&md->io_barrier); -+ - if (md->bdev) { - bdput(md->bdev); - md->bdev = NULL; -diff --git a/drivers/md/md.c b/drivers/md/md.c -index 915e84d..db0aa6c 100644 ---- a/drivers/md/md.c -+++ b/drivers/md/md.c -@@ -8120,14 +8120,14 @@ void md_do_sync(struct md_thread *thread) - - if (!test_bit(MD_RECOVERY_RESHAPE, &mddev->recovery) && - !test_bit(MD_RECOVERY_INTR, &mddev->recovery) && -- mddev->curr_resync > 2) { -+ mddev->curr_resync > 3) { - mddev->curr_resync_completed = mddev->curr_resync; - sysfs_notify(&mddev->kobj, NULL, "sync_completed"); - } - mddev->pers->sync_request(mddev, max_sectors, &skipped); - - if (!test_bit(MD_RECOVERY_CHECK, &mddev->recovery) && -- mddev->curr_resync > 2) { -+ mddev->curr_resync > 3) { - if (test_bit(MD_RECOVERY_SYNC, &mddev->recovery)) { - if (test_bit(MD_RECOVERY_INTR, &mddev->recovery)) { - if (mddev->curr_resync >= mddev->recovery_cp) { -diff --git a/drivers/md/raid1.c b/drivers/md/raid1.c -index 21dc00e..95bf4cd 100644 ---- a/drivers/md/raid1.c -+++ b/drivers/md/raid1.c -@@ -407,11 +407,14 @@ static void raid1_end_write_request(struct bio *bio) - struct bio *to_put = NULL; - int mirror = find_bio_disk(r1_bio, bio); - struct md_rdev *rdev = conf->mirrors[mirror].rdev; -+ bool discard_error; -+ -+ discard_error = bio->bi_error && bio_op(bio) == REQ_OP_DISCARD; - - /* - * 'one mirror IO has finished' event handler: - */ -- if (bio->bi_error) { -+ if (bio->bi_error && !discard_error) { - set_bit(WriteErrorSeen, &rdev->flags); - if (!test_and_set_bit(WantReplacement, &rdev->flags)) - set_bit(MD_RECOVERY_NEEDED, & -@@ -448,7 +451,7 @@ static void raid1_end_write_request(struct bio *bio) - - /* Maybe we can clear some bad blocks. */ - if (is_badblock(rdev, r1_bio->sector, r1_bio->sectors, -- &first_bad, &bad_sectors)) { -+ &first_bad, &bad_sectors) && !discard_error) { - r1_bio->bios[mirror] = IO_MADE_GOOD; - set_bit(R1BIO_MadeGood, &r1_bio->state); - } -diff --git a/drivers/md/raid10.c b/drivers/md/raid10.c -index be1a9fc..39fddda 100644 ---- a/drivers/md/raid10.c -+++ b/drivers/md/raid10.c -@@ -447,6 +447,9 @@ static void raid10_end_write_request(struct bio *bio) - struct r10conf *conf = r10_bio->mddev->private; - int slot, repl; - struct md_rdev *rdev = NULL; -+ bool discard_error; -+ -+ discard_error = bio->bi_error && bio_op(bio) == REQ_OP_DISCARD; - - dev = find_bio_disk(conf, r10_bio, bio, &slot, &repl); - -@@ -460,7 +463,7 @@ static void raid10_end_write_request(struct bio *bio) - /* - * this branch is our 'one mirror IO has finished' event handler: - */ -- if (bio->bi_error) { -+ if (bio->bi_error && !discard_error) { - if (repl) - /* Never record new bad blocks to replacement, - * just fail it. -@@ -503,7 +506,7 @@ static void raid10_end_write_request(struct bio *bio) - if (is_badblock(rdev, - r10_bio->devs[slot].addr, - r10_bio->sectors, -- &first_bad, &bad_sectors)) { -+ &first_bad, &bad_sectors) && !discard_error) { - bio_put(bio); - if (repl) - r10_bio->devs[slot].repl_bio = IO_MADE_GOOD; -diff --git a/drivers/media/platform/vsp1/vsp1_video.c b/drivers/media/platform/vsp1/vsp1_video.c -index 9fb4fc2..ed9759e 100644 ---- a/drivers/media/platform/vsp1/vsp1_video.c -+++ b/drivers/media/platform/vsp1/vsp1_video.c -@@ -675,6 +675,13 @@ static void vsp1_video_stop_streaming(struct vb2_queue *vq) - unsigned long flags; - int ret; - -+ /* Clear the buffers ready flag to make sure the device won't be started -+ * by a QBUF on the video node on the other side of the pipeline. -+ */ -+ spin_lock_irqsave(&video->irqlock, flags); -+ pipe->buffers_ready &= ~(1 << video->pipe_index); -+ spin_unlock_irqrestore(&video->irqlock, flags); -+ - mutex_lock(&pipe->lock); - if (--pipe->stream_count == pipe->num_inputs) { - /* Stop the pipeline. */ -diff --git a/drivers/misc/cxl/api.c b/drivers/misc/cxl/api.c -index af23d7d..2e5233b 100644 ---- a/drivers/misc/cxl/api.c -+++ b/drivers/misc/cxl/api.c -@@ -247,7 +247,9 @@ int cxl_start_context(struct cxl_context *ctx, u64 wed, - cxl_ctx_get(); - - if ((rc = cxl_ops->attach_process(ctx, kernel, wed, 0))) { -+ put_pid(ctx->glpid); - put_pid(ctx->pid); -+ ctx->glpid = ctx->pid = NULL; - cxl_adapter_context_put(ctx->afu->adapter); - cxl_ctx_put(); - goto out; -diff --git a/drivers/misc/cxl/file.c b/drivers/misc/cxl/file.c -index d0b421f..77080cc 100644 ---- a/drivers/misc/cxl/file.c -+++ b/drivers/misc/cxl/file.c -@@ -194,6 +194,16 @@ static long afu_ioctl_start_work(struct cxl_context *ctx, - ctx->mmio_err_ff = !!(work.flags & CXL_START_WORK_ERR_FF); - - /* -+ * Increment the mapped context count for adapter. This also checks -+ * if adapter_context_lock is taken. -+ */ -+ rc = cxl_adapter_context_get(ctx->afu->adapter); -+ if (rc) { -+ afu_release_irqs(ctx, ctx); -+ goto out; -+ } -+ -+ /* - * We grab the PID here and not in the file open to allow for the case - * where a process (master, some daemon, etc) has opened the chardev on - * behalf of another process, so the AFU's mm gets bound to the process -@@ -205,15 +215,6 @@ static long afu_ioctl_start_work(struct cxl_context *ctx, - ctx->pid = get_task_pid(current, PIDTYPE_PID); - ctx->glpid = get_task_pid(current->group_leader, PIDTYPE_PID); - -- /* -- * Increment the mapped context count for adapter. This also checks -- * if adapter_context_lock is taken. -- */ -- rc = cxl_adapter_context_get(ctx->afu->adapter); -- if (rc) { -- afu_release_irqs(ctx, ctx); -- goto out; -- } - - trace_cxl_attach(ctx, work.work_element_descriptor, work.num_interrupts, amr); - -@@ -221,6 +222,9 @@ static long afu_ioctl_start_work(struct cxl_context *ctx, - amr))) { - afu_release_irqs(ctx, ctx); - cxl_adapter_context_put(ctx->afu->adapter); -+ put_pid(ctx->glpid); -+ put_pid(ctx->pid); -+ ctx->glpid = ctx->pid = NULL; - goto out; - } - -diff --git a/drivers/misc/genwqe/card_utils.c b/drivers/misc/genwqe/card_utils.c -index 222367c..524660510 100644 ---- a/drivers/misc/genwqe/card_utils.c -+++ b/drivers/misc/genwqe/card_utils.c -@@ -352,17 +352,27 @@ int genwqe_alloc_sync_sgl(struct genwqe_dev *cd, struct genwqe_sgl *sgl, - if (copy_from_user(sgl->lpage, user_addr + user_size - - sgl->lpage_size, sgl->lpage_size)) { - rc = -EFAULT; -- goto err_out1; -+ goto err_out2; - } - } - return 0; - -+ err_out2: -+ __genwqe_free_consistent(cd, PAGE_SIZE, sgl->lpage, -+ sgl->lpage_dma_addr); -+ sgl->lpage = NULL; -+ sgl->lpage_dma_addr = 0; - err_out1: - __genwqe_free_consistent(cd, PAGE_SIZE, sgl->fpage, - sgl->fpage_dma_addr); -+ sgl->fpage = NULL; -+ sgl->fpage_dma_addr = 0; - err_out: - __genwqe_free_consistent(cd, sgl->sgl_size, sgl->sgl, - sgl->sgl_dma_addr); -+ sgl->sgl = NULL; -+ sgl->sgl_dma_addr = 0; -+ sgl->sgl_size = 0; - return -ENOMEM; - } - -diff --git a/drivers/misc/mei/hw-txe.c b/drivers/misc/mei/hw-txe.c -index 4a6c1b8..2d23cdf 100644 ---- a/drivers/misc/mei/hw-txe.c -+++ b/drivers/misc/mei/hw-txe.c -@@ -978,11 +978,13 @@ static bool mei_txe_check_and_ack_intrs(struct mei_device *dev, bool do_ack) - hisr = mei_txe_br_reg_read(hw, HISR_REG); - - aliveness = mei_txe_aliveness_get(dev); -- if (hhisr & IPC_HHIER_SEC && aliveness) -+ if (hhisr & IPC_HHIER_SEC && aliveness) { - ipc_isr = mei_txe_sec_reg_read_silent(hw, - SEC_IPC_HOST_INT_STATUS_REG); -- else -+ } else { - ipc_isr = 0; -+ hhisr &= ~IPC_HHIER_SEC; -+ } - - generated = generated || - (hisr & HISR_INT_STS_MSK) || -diff --git a/drivers/mmc/host/dw_mmc-pltfm.c b/drivers/mmc/host/dw_mmc-pltfm.c -index c0bb0c7..dbbc430 100644 ---- a/drivers/mmc/host/dw_mmc-pltfm.c -+++ b/drivers/mmc/host/dw_mmc-pltfm.c -@@ -46,12 +46,13 @@ int dw_mci_pltfm_register(struct platform_device *pdev, - host->pdata = pdev->dev.platform_data; - - regs = platform_get_resource(pdev, IORESOURCE_MEM, 0); -- /* Get registers' physical base address */ -- host->phy_regs = regs->start; - host->regs = devm_ioremap_resource(&pdev->dev, regs); - if (IS_ERR(host->regs)) - return PTR_ERR(host->regs); - -+ /* Get registers' physical base address */ -+ host->phy_regs = regs->start; -+ - platform_set_drvdata(pdev, host); - return dw_mci_probe(host); - } -diff --git a/drivers/mtd/ubi/fastmap.c b/drivers/mtd/ubi/fastmap.c -index 48eb55f..a01a70a 100644 ---- a/drivers/mtd/ubi/fastmap.c -+++ b/drivers/mtd/ubi/fastmap.c -@@ -515,10 +515,11 @@ static int scan_pool(struct ubi_device *ubi, struct ubi_attach_info *ai, - unsigned long long ec = be64_to_cpu(ech->ec); - unmap_peb(ai, pnum); - dbg_bld("Adding PEB to free: %i", pnum); -+ - if (err == UBI_IO_FF_BITFLIPS) -- add_aeb(ai, free, pnum, ec, 1); -- else -- add_aeb(ai, free, pnum, ec, 0); -+ scrub = 1; -+ -+ add_aeb(ai, free, pnum, ec, scrub); - continue; - } else if (err == 0 || err == UBI_IO_BITFLIPS) { - dbg_bld("Found non empty PEB:%i in pool", pnum); -@@ -750,11 +751,11 @@ static int ubi_attach_fastmap(struct ubi_device *ubi, - fmvhdr->vol_type, - be32_to_cpu(fmvhdr->last_eb_bytes)); - -- if (!av) -- goto fail_bad; -- if (PTR_ERR(av) == -EINVAL) { -- ubi_err(ubi, "volume (ID %i) already exists", -- fmvhdr->vol_id); -+ if (IS_ERR(av)) { -+ if (PTR_ERR(av) == -EEXIST) -+ ubi_err(ubi, "volume (ID %i) already exists", -+ fmvhdr->vol_id); -+ - goto fail_bad; - } - -diff --git a/drivers/net/wireless/ath/ath10k/core.h b/drivers/net/wireless/ath/ath10k/core.h -index 30ae5bf..76ad825 100644 ---- a/drivers/net/wireless/ath/ath10k/core.h -+++ b/drivers/net/wireless/ath/ath10k/core.h -@@ -445,6 +445,7 @@ struct ath10k_debug { - u32 pktlog_filter; - u32 reg_addr; - u32 nf_cal_period; -+ void *cal_data; - - struct ath10k_fw_crash_data *fw_crash_data; - }; -diff --git a/drivers/net/wireless/ath/ath10k/debug.c b/drivers/net/wireless/ath/ath10k/debug.c -index 8f0fd41..8c6a5dd 100644 ---- a/drivers/net/wireless/ath/ath10k/debug.c -+++ b/drivers/net/wireless/ath/ath10k/debug.c -@@ -30,6 +30,8 @@ - /* ms */ - #define ATH10K_DEBUG_HTT_STATS_INTERVAL 1000 - -+#define ATH10K_DEBUG_CAL_DATA_LEN 12064 -+ - #define ATH10K_FW_CRASH_DUMP_VERSION 1 - - /** -@@ -1450,56 +1452,51 @@ static const struct file_operations fops_fw_dbglog = { - .llseek = default_llseek, - }; - --static int ath10k_debug_cal_data_open(struct inode *inode, struct file *file) -+static int ath10k_debug_cal_data_fetch(struct ath10k *ar) - { -- struct ath10k *ar = inode->i_private; -- void *buf; - u32 hi_addr; - __le32 addr; - int ret; - -- mutex_lock(&ar->conf_mutex); -- -- if (ar->state != ATH10K_STATE_ON && -- ar->state != ATH10K_STATE_UTF) { -- ret = -ENETDOWN; -- goto err; -- } -+ lockdep_assert_held(&ar->conf_mutex); - -- buf = vmalloc(ar->hw_params.cal_data_len); -- if (!buf) { -- ret = -ENOMEM; -- goto err; -- } -+ if (WARN_ON(ar->hw_params.cal_data_len > ATH10K_DEBUG_CAL_DATA_LEN)) -+ return -EINVAL; - - hi_addr = host_interest_item_address(HI_ITEM(hi_board_data)); - - ret = ath10k_hif_diag_read(ar, hi_addr, &addr, sizeof(addr)); - if (ret) { -- ath10k_warn(ar, "failed to read hi_board_data address: %d\n", ret); -- goto err_vfree; -+ ath10k_warn(ar, "failed to read hi_board_data address: %d\n", -+ ret); -+ return ret; - } - -- ret = ath10k_hif_diag_read(ar, le32_to_cpu(addr), buf, -+ ret = ath10k_hif_diag_read(ar, le32_to_cpu(addr), ar->debug.cal_data, - ar->hw_params.cal_data_len); - if (ret) { - ath10k_warn(ar, "failed to read calibration data: %d\n", ret); -- goto err_vfree; -+ return ret; - } - -- file->private_data = buf; -+ return 0; -+} - -- mutex_unlock(&ar->conf_mutex); -+static int ath10k_debug_cal_data_open(struct inode *inode, struct file *file) -+{ -+ struct ath10k *ar = inode->i_private; - -- return 0; -+ mutex_lock(&ar->conf_mutex); - --err_vfree: -- vfree(buf); -+ if (ar->state == ATH10K_STATE_ON || -+ ar->state == ATH10K_STATE_UTF) { -+ ath10k_debug_cal_data_fetch(ar); -+ } - --err: -+ file->private_data = ar; - mutex_unlock(&ar->conf_mutex); - -- return ret; -+ return 0; - } - - static ssize_t ath10k_debug_cal_data_read(struct file *file, -@@ -1507,18 +1504,16 @@ static ssize_t ath10k_debug_cal_data_read(struct file *file, - size_t count, loff_t *ppos) - { - struct ath10k *ar = file->private_data; -- void *buf = file->private_data; - -- return simple_read_from_buffer(user_buf, count, ppos, -- buf, ar->hw_params.cal_data_len); --} -+ mutex_lock(&ar->conf_mutex); - --static int ath10k_debug_cal_data_release(struct inode *inode, -- struct file *file) --{ -- vfree(file->private_data); -+ count = simple_read_from_buffer(user_buf, count, ppos, -+ ar->debug.cal_data, -+ ar->hw_params.cal_data_len); - -- return 0; -+ mutex_unlock(&ar->conf_mutex); -+ -+ return count; - } - - static ssize_t ath10k_write_ani_enable(struct file *file, -@@ -1579,7 +1574,6 @@ static const struct file_operations fops_ani_enable = { - static const struct file_operations fops_cal_data = { - .open = ath10k_debug_cal_data_open, - .read = ath10k_debug_cal_data_read, -- .release = ath10k_debug_cal_data_release, - .owner = THIS_MODULE, - .llseek = default_llseek, - }; -@@ -1931,6 +1925,8 @@ void ath10k_debug_stop(struct ath10k *ar) - { - lockdep_assert_held(&ar->conf_mutex); - -+ ath10k_debug_cal_data_fetch(ar); -+ - /* Must not use _sync to avoid deadlock, we do that in - * ath10k_debug_destroy(). The check for htt_stats_mask is to avoid - * warning from del_timer(). */ -@@ -2343,6 +2339,10 @@ int ath10k_debug_create(struct ath10k *ar) - if (!ar->debug.fw_crash_data) - return -ENOMEM; - -+ ar->debug.cal_data = vzalloc(ATH10K_DEBUG_CAL_DATA_LEN); -+ if (!ar->debug.cal_data) -+ return -ENOMEM; -+ - INIT_LIST_HEAD(&ar->debug.fw_stats.pdevs); - INIT_LIST_HEAD(&ar->debug.fw_stats.vdevs); - INIT_LIST_HEAD(&ar->debug.fw_stats.peers); -@@ -2356,6 +2356,9 @@ void ath10k_debug_destroy(struct ath10k *ar) - vfree(ar->debug.fw_crash_data); - ar->debug.fw_crash_data = NULL; - -+ vfree(ar->debug.cal_data); -+ ar->debug.cal_data = NULL; -+ - ath10k_debug_fw_stats_reset(ar); - - kfree(ar->debug.tpc_stats); -diff --git a/drivers/net/wireless/ath/ath9k/ar9003_calib.c b/drivers/net/wireless/ath/ath9k/ar9003_calib.c -index b6f064a..7e27a06 100644 ---- a/drivers/net/wireless/ath/ath9k/ar9003_calib.c -+++ b/drivers/net/wireless/ath/ath9k/ar9003_calib.c -@@ -33,7 +33,6 @@ struct coeff { - - enum ar9003_cal_types { - IQ_MISMATCH_CAL = BIT(0), -- TEMP_COMP_CAL = BIT(1), - }; - - static void ar9003_hw_setup_calibration(struct ath_hw *ah, -@@ -59,12 +58,6 @@ static void ar9003_hw_setup_calibration(struct ath_hw *ah, - /* Kick-off cal */ - REG_SET_BIT(ah, AR_PHY_TIMING4, AR_PHY_TIMING4_DO_CAL); - break; -- case TEMP_COMP_CAL: -- ath_dbg(common, CALIBRATE, -- "starting Temperature Compensation Calibration\n"); -- REG_SET_BIT(ah, AR_CH0_THERM, AR_CH0_THERM_LOCAL); -- REG_SET_BIT(ah, AR_CH0_THERM, AR_CH0_THERM_START); -- break; - default: - ath_err(common, "Invalid calibration type\n"); - break; -@@ -93,8 +86,7 @@ static bool ar9003_hw_per_calibration(struct ath_hw *ah, - /* - * Accumulate cal measures for active chains - */ -- if (cur_caldata->calCollect) -- cur_caldata->calCollect(ah); -+ cur_caldata->calCollect(ah); - ah->cal_samples++; - - if (ah->cal_samples >= cur_caldata->calNumSamples) { -@@ -107,8 +99,7 @@ static bool ar9003_hw_per_calibration(struct ath_hw *ah, - /* - * Process accumulated data - */ -- if (cur_caldata->calPostProc) -- cur_caldata->calPostProc(ah, numChains); -+ cur_caldata->calPostProc(ah, numChains); - - /* Calibration has finished. */ - caldata->CalValid |= cur_caldata->calType; -@@ -323,16 +314,9 @@ static const struct ath9k_percal_data iq_cal_single_sample = { - ar9003_hw_iqcalibrate - }; - --static const struct ath9k_percal_data temp_cal_single_sample = { -- TEMP_COMP_CAL, -- MIN_CAL_SAMPLES, -- PER_MAX_LOG_COUNT, --}; -- - static void ar9003_hw_init_cal_settings(struct ath_hw *ah) - { - ah->iq_caldata.calData = &iq_cal_single_sample; -- ah->temp_caldata.calData = &temp_cal_single_sample; - - if (AR_SREV_9300_20_OR_LATER(ah)) { - ah->enabled_cals |= TX_IQ_CAL; -@@ -340,7 +324,7 @@ static void ar9003_hw_init_cal_settings(struct ath_hw *ah) - ah->enabled_cals |= TX_IQ_ON_AGC_CAL; - } - -- ah->supp_cals = IQ_MISMATCH_CAL | TEMP_COMP_CAL; -+ ah->supp_cals = IQ_MISMATCH_CAL; - } - - #define OFF_UPPER_LT 24 -@@ -1399,9 +1383,6 @@ static void ar9003_hw_init_cal_common(struct ath_hw *ah) - INIT_CAL(&ah->iq_caldata); - INSERT_CAL(ah, &ah->iq_caldata); - -- INIT_CAL(&ah->temp_caldata); -- INSERT_CAL(ah, &ah->temp_caldata); -- - /* Initialize current pointer to first element in list */ - ah->cal_list_curr = ah->cal_list; - -diff --git a/drivers/net/wireless/ath/ath9k/hw.h b/drivers/net/wireless/ath/ath9k/hw.h -index 2a5d3ad..9cbca12 100644 ---- a/drivers/net/wireless/ath/ath9k/hw.h -+++ b/drivers/net/wireless/ath/ath9k/hw.h -@@ -830,7 +830,6 @@ struct ath_hw { - /* Calibration */ - u32 supp_cals; - struct ath9k_cal_list iq_caldata; -- struct ath9k_cal_list temp_caldata; - struct ath9k_cal_list adcgain_caldata; - struct ath9k_cal_list adcdc_caldata; - struct ath9k_cal_list *cal_list; -diff --git a/drivers/net/wireless/realtek/rtl8xxxu/rtl8xxxu.h b/drivers/net/wireless/realtek/rtl8xxxu/rtl8xxxu.h -index 4341d56..a280932 100644 ---- a/drivers/net/wireless/realtek/rtl8xxxu/rtl8xxxu.h -+++ b/drivers/net/wireless/realtek/rtl8xxxu/rtl8xxxu.h -@@ -231,7 +231,7 @@ struct rtl8xxxu_rxdesc16 { - u32 pattern1match:1; - u32 pattern0match:1; - #endif -- __le32 tsfl; -+ u32 tsfl; - #if 0 - u32 bassn:12; - u32 bavld:1; -@@ -361,7 +361,7 @@ struct rtl8xxxu_rxdesc24 { - u32 ldcp:1; - u32 splcp:1; - #endif -- __le32 tsfl; -+ u32 tsfl; - }; - - struct rtl8xxxu_txdesc32 { -diff --git a/drivers/net/wireless/realtek/rtl8xxxu/rtl8xxxu_8723b.c b/drivers/net/wireless/realtek/rtl8xxxu/rtl8xxxu_8723b.c -index 9d45afb..c831a586 100644 ---- a/drivers/net/wireless/realtek/rtl8xxxu/rtl8xxxu_8723b.c -+++ b/drivers/net/wireless/realtek/rtl8xxxu/rtl8xxxu_8723b.c -@@ -1498,6 +1498,10 @@ static void rtl8723b_enable_rf(struct rtl8xxxu_priv *priv) - u32 val32; - u8 val8; - -+ val32 = rtl8xxxu_read32(priv, REG_RX_WAIT_CCA); -+ val32 |= (BIT(22) | BIT(23)); -+ rtl8xxxu_write32(priv, REG_RX_WAIT_CCA, val32); -+ - /* - * No indication anywhere as to what 0x0790 does. The 2 antenna - * vendor code preserves bits 6-7 here. -diff --git a/drivers/net/wireless/realtek/rtl8xxxu/rtl8xxxu_core.c b/drivers/net/wireless/realtek/rtl8xxxu/rtl8xxxu_core.c -index 77048db..c6b246a 100644 ---- a/drivers/net/wireless/realtek/rtl8xxxu/rtl8xxxu_core.c -+++ b/drivers/net/wireless/realtek/rtl8xxxu/rtl8xxxu_core.c -@@ -5201,7 +5201,12 @@ int rtl8xxxu_parse_rxdesc16(struct rtl8xxxu_priv *priv, struct sk_buff *skb) - pkt_offset = roundup(pkt_len + drvinfo_sz + desc_shift + - sizeof(struct rtl8xxxu_rxdesc16), 128); - -- if (pkt_cnt > 1) -+ /* -+ * Only clone the skb if there's enough data at the end to -+ * at least cover the rx descriptor -+ */ -+ if (pkt_cnt > 1 && -+ urb_len > (pkt_offset + sizeof(struct rtl8xxxu_rxdesc16))) - next_skb = skb_clone(skb, GFP_ATOMIC); - - rx_status = IEEE80211_SKB_RXCB(skb); -@@ -5219,7 +5224,7 @@ int rtl8xxxu_parse_rxdesc16(struct rtl8xxxu_priv *priv, struct sk_buff *skb) - rtl8xxxu_rx_parse_phystats(priv, rx_status, phy_stats, - rx_desc->rxmcs); - -- rx_status->mactime = le32_to_cpu(rx_desc->tsfl); -+ rx_status->mactime = rx_desc->tsfl; - rx_status->flag |= RX_FLAG_MACTIME_START; - - if (!rx_desc->swdec) -@@ -5289,7 +5294,7 @@ int rtl8xxxu_parse_rxdesc24(struct rtl8xxxu_priv *priv, struct sk_buff *skb) - rtl8xxxu_rx_parse_phystats(priv, rx_status, phy_stats, - rx_desc->rxmcs); - -- rx_status->mactime = le32_to_cpu(rx_desc->tsfl); -+ rx_status->mactime = rx_desc->tsfl; - rx_status->flag |= RX_FLAG_MACTIME_START; - - if (!rx_desc->swdec) -diff --git a/drivers/pwm/core.c b/drivers/pwm/core.c -index 0dbd29e..172ef82 100644 ---- a/drivers/pwm/core.c -+++ b/drivers/pwm/core.c -@@ -339,6 +339,8 @@ int pwmchip_remove(struct pwm_chip *chip) - unsigned int i; - int ret = 0; - -+ pwmchip_sysfs_unexport_children(chip); -+ - mutex_lock(&pwm_lock); - - for (i = 0; i < chip->npwm; i++) { -diff --git a/drivers/pwm/sysfs.c b/drivers/pwm/sysfs.c -index 18ed725..0296d81 100644 ---- a/drivers/pwm/sysfs.c -+++ b/drivers/pwm/sysfs.c -@@ -409,6 +409,24 @@ void pwmchip_sysfs_unexport(struct pwm_chip *chip) - } - } - -+void pwmchip_sysfs_unexport_children(struct pwm_chip *chip) -+{ -+ struct device *parent; -+ unsigned int i; -+ -+ parent = class_find_device(&pwm_class, NULL, chip, -+ pwmchip_sysfs_match); -+ if (!parent) -+ return; -+ -+ for (i = 0; i < chip->npwm; i++) { -+ struct pwm_device *pwm = &chip->pwms[i]; -+ -+ if (test_bit(PWMF_EXPORTED, &pwm->flags)) -+ pwm_unexport_child(parent, pwm); -+ } -+} -+ - static int __init pwm_sysfs_init(void) - { - return class_register(&pwm_class); -diff --git a/drivers/scsi/arcmsr/arcmsr_hba.c b/drivers/scsi/arcmsr/arcmsr_hba.c -index 3d53d63..f0cfb04 100644 ---- a/drivers/scsi/arcmsr/arcmsr_hba.c -+++ b/drivers/scsi/arcmsr/arcmsr_hba.c -@@ -2636,18 +2636,9 @@ static int arcmsr_queue_command_lck(struct scsi_cmnd *cmd, - struct AdapterControlBlock *acb = (struct AdapterControlBlock *) host->hostdata; - struct CommandControlBlock *ccb; - int target = cmd->device->id; -- int lun = cmd->device->lun; -- uint8_t scsicmd = cmd->cmnd[0]; - cmd->scsi_done = done; - cmd->host_scribble = NULL; - cmd->result = 0; -- if ((scsicmd == SYNCHRONIZE_CACHE) ||(scsicmd == SEND_DIAGNOSTIC)){ -- if(acb->devstate[target][lun] == ARECA_RAID_GONE) { -- cmd->result = (DID_NO_CONNECT << 16); -- } -- cmd->scsi_done(cmd); -- return 0; -- } - if (target == 16) { - /* virtual device for iop message transfer */ - arcmsr_handle_virtual_command(acb, cmd); -diff --git a/drivers/scsi/scsi_debug.c b/drivers/scsi/scsi_debug.c -index 6a219a0..05e892a 100644 ---- a/drivers/scsi/scsi_debug.c -+++ b/drivers/scsi/scsi_debug.c -@@ -5134,6 +5134,7 @@ static void __exit scsi_debug_exit(void) - bus_unregister(&pseudo_lld_bus); - root_device_unregister(pseudo_primary); - -+ vfree(map_storep); - vfree(dif_storep); - vfree(fake_storep); - kfree(sdebug_q_arr); -diff --git a/drivers/spi/spi-fsl-espi.c b/drivers/spi/spi-fsl-espi.c -index 8d85a3c..3f35613 100644 ---- a/drivers/spi/spi-fsl-espi.c -+++ b/drivers/spi/spi-fsl-espi.c -@@ -581,7 +581,7 @@ void fsl_espi_cpu_irq(struct mpc8xxx_spi *mspi, u32 events) - - mspi->len -= rx_nr_bytes; - -- if (mspi->rx) -+ if (rx_nr_bytes && mspi->rx) - mspi->get_rx(rx_data, mspi); - } - -diff --git a/drivers/spi/spi.c b/drivers/spi/spi.c -index 200ca22..935f1a5 100644 ---- a/drivers/spi/spi.c -+++ b/drivers/spi/spi.c -@@ -1607,9 +1607,11 @@ static void of_register_spi_devices(struct spi_master *master) - if (of_node_test_and_set_flag(nc, OF_POPULATED)) - continue; - spi = of_register_spi_device(master, nc); -- if (IS_ERR(spi)) -+ if (IS_ERR(spi)) { - dev_warn(&master->dev, "Failed to create SPI device for %s\n", - nc->full_name); -+ of_node_clear_flag(nc, OF_POPULATED); -+ } - } - } - #else -@@ -3120,6 +3122,7 @@ static int of_spi_notify(struct notifier_block *nb, unsigned long action, - if (IS_ERR(spi)) { - pr_err("%s: failed to create for '%s'\n", - __func__, rd->dn->full_name); -+ of_node_clear_flag(rd->dn, OF_POPULATED); - return notifier_from_errno(PTR_ERR(spi)); - } - break; -diff --git a/drivers/staging/wilc1000/host_interface.c b/drivers/staging/wilc1000/host_interface.c -index 78f524f..f4dbcb1 100644 ---- a/drivers/staging/wilc1000/host_interface.c -+++ b/drivers/staging/wilc1000/host_interface.c -@@ -3391,7 +3391,6 @@ int wilc_init(struct net_device *dev, struct host_if_drv **hif_drv_handler) - - clients_count++; - -- destroy_workqueue(hif_workqueue); - _fail_: - return result; - } -diff --git a/drivers/thermal/intel_powerclamp.c b/drivers/thermal/intel_powerclamp.c -index 0e4dc0a..7a22307 100644 ---- a/drivers/thermal/intel_powerclamp.c -+++ b/drivers/thermal/intel_powerclamp.c -@@ -669,20 +669,10 @@ static struct thermal_cooling_device_ops powerclamp_cooling_ops = { - .set_cur_state = powerclamp_set_cur_state, - }; - --static const struct x86_cpu_id intel_powerclamp_ids[] __initconst = { -- { X86_VENDOR_INTEL, X86_FAMILY_ANY, X86_MODEL_ANY, X86_FEATURE_MWAIT }, -- { X86_VENDOR_INTEL, X86_FAMILY_ANY, X86_MODEL_ANY, X86_FEATURE_ARAT }, -- { X86_VENDOR_INTEL, X86_FAMILY_ANY, X86_MODEL_ANY, X86_FEATURE_NONSTOP_TSC }, -- { X86_VENDOR_INTEL, X86_FAMILY_ANY, X86_MODEL_ANY, X86_FEATURE_CONSTANT_TSC}, -- {} --}; --MODULE_DEVICE_TABLE(x86cpu, intel_powerclamp_ids); -- - static int __init powerclamp_probe(void) - { -- if (!x86_match_cpu(intel_powerclamp_ids)) { -- pr_err("Intel powerclamp does not run on family %d model %d\n", -- boot_cpu_data.x86, boot_cpu_data.x86_model); -+ if (!boot_cpu_has(X86_FEATURE_MWAIT)) { -+ pr_err("CPU does not support MWAIT"); - return -ENODEV; - } - -diff --git a/drivers/tty/vt/vt.c b/drivers/tty/vt/vt.c -index 2705ca9..fd375f1 100644 ---- a/drivers/tty/vt/vt.c -+++ b/drivers/tty/vt/vt.c -@@ -870,10 +870,15 @@ static int vc_do_resize(struct tty_struct *tty, struct vc_data *vc, - if (new_cols == vc->vc_cols && new_rows == vc->vc_rows) - return 0; - -+ if (new_screen_size > (4 << 20)) -+ return -EINVAL; - newscreen = kmalloc(new_screen_size, GFP_USER); - if (!newscreen) - return -ENOMEM; - -+ if (vc == sel_cons) -+ clear_selection(); -+ - old_rows = vc->vc_rows; - old_row_size = vc->vc_size_row; - -@@ -1176,7 +1181,7 @@ static void csi_J(struct vc_data *vc, int vpar) - break; - case 3: /* erase scroll-back buffer (and whole display) */ - scr_memsetw(vc->vc_screenbuf, vc->vc_video_erase_char, -- vc->vc_screenbuf_size >> 1); -+ vc->vc_screenbuf_size); - set_origin(vc); - if (con_is_visible(vc)) - update_screen(vc); -diff --git a/drivers/usb/chipidea/host.c b/drivers/usb/chipidea/host.c -index 053bac9..887be34 100644 ---- a/drivers/usb/chipidea/host.c -+++ b/drivers/usb/chipidea/host.c -@@ -185,6 +185,8 @@ static void host_stop(struct ci_hdrc *ci) - - if (hcd) { - usb_remove_hcd(hcd); -+ ci->role = CI_ROLE_END; -+ synchronize_irq(ci->irq); - usb_put_hcd(hcd); - if (ci->platdata->reg_vbus && !ci_otg_is_fsm_mode(ci) && - (ci->platdata->flags & CI_HDRC_TURN_VBUS_EARLY_ON)) -diff --git a/drivers/usb/dwc3/gadget.c b/drivers/usb/dwc3/gadget.c -index 6854461..6443cfb 100644 ---- a/drivers/usb/dwc3/gadget.c -+++ b/drivers/usb/dwc3/gadget.c -@@ -3055,7 +3055,7 @@ int dwc3_gadget_init(struct dwc3 *dwc) - kfree(dwc->setup_buf); - - err2: -- dma_free_coherent(dwc->dev, sizeof(*dwc->ep0_trb), -+ dma_free_coherent(dwc->dev, sizeof(*dwc->ep0_trb) * 2, - dwc->ep0_trb, dwc->ep0_trb_addr); - - err1: -@@ -3080,7 +3080,7 @@ void dwc3_gadget_exit(struct dwc3 *dwc) - kfree(dwc->setup_buf); - kfree(dwc->zlp_buf); - -- dma_free_coherent(dwc->dev, sizeof(*dwc->ep0_trb), -+ dma_free_coherent(dwc->dev, sizeof(*dwc->ep0_trb) * 2, - dwc->ep0_trb, dwc->ep0_trb_addr); - - dma_free_coherent(dwc->dev, sizeof(*dwc->ctrl_req), -diff --git a/drivers/usb/gadget/function/u_ether.c b/drivers/usb/gadget/function/u_ether.c -index 5f562c1..9b9e71f 100644 ---- a/drivers/usb/gadget/function/u_ether.c -+++ b/drivers/usb/gadget/function/u_ether.c -@@ -587,8 +587,9 @@ static netdev_tx_t eth_start_xmit(struct sk_buff *skb, - - /* throttle high/super speed IRQ rate back slightly */ - if (gadget_is_dualspeed(dev->gadget)) -- req->no_interrupt = (dev->gadget->speed == USB_SPEED_HIGH || -- dev->gadget->speed == USB_SPEED_SUPER) -+ req->no_interrupt = (((dev->gadget->speed == USB_SPEED_HIGH || -+ dev->gadget->speed == USB_SPEED_SUPER)) && -+ !list_empty(&dev->tx_reqs)) - ? ((atomic_read(&dev->tx_qlen) % dev->qmult) != 0) - : 0; - -diff --git a/drivers/usb/gadget/udc/atmel_usba_udc.c b/drivers/usb/gadget/udc/atmel_usba_udc.c -index bb1f6c8..45bc997 100644 ---- a/drivers/usb/gadget/udc/atmel_usba_udc.c -+++ b/drivers/usb/gadget/udc/atmel_usba_udc.c -@@ -1978,7 +1978,7 @@ static struct usba_ep * atmel_udc_of_init(struct platform_device *pdev, - dev_err(&pdev->dev, "of_probe: name error(%d)\n", ret); - goto err; - } -- ep->ep.name = name; -+ ep->ep.name = kasprintf(GFP_KERNEL, "ep%d", ep->index); - - ep->ep_regs = udc->regs + USBA_EPT_BASE(i); - ep->dma_regs = udc->regs + USBA_DMA_BASE(i); -diff --git a/drivers/usb/host/ohci-hcd.c b/drivers/usb/host/ohci-hcd.c -index 1700908..86612ac 100644 ---- a/drivers/usb/host/ohci-hcd.c -+++ b/drivers/usb/host/ohci-hcd.c -@@ -72,7 +72,7 @@ - static const char hcd_name [] = "ohci_hcd"; - - #define STATECHANGE_DELAY msecs_to_jiffies(300) --#define IO_WATCHDOG_DELAY msecs_to_jiffies(250) -+#define IO_WATCHDOG_DELAY msecs_to_jiffies(275) - - #include "ohci.h" - #include "pci-quirks.h" -diff --git a/drivers/usb/host/xhci-hub.c b/drivers/usb/host/xhci-hub.c -index 730b9fd..0ef1690 100644 ---- a/drivers/usb/host/xhci-hub.c -+++ b/drivers/usb/host/xhci-hub.c -@@ -1166,7 +1166,7 @@ int xhci_hub_control(struct usb_hcd *hcd, u16 typeReq, u16 wValue, - xhci_set_link_state(xhci, port_array, wIndex, - XDEV_RESUME); - spin_unlock_irqrestore(&xhci->lock, flags); -- msleep(20); -+ msleep(USB_RESUME_TIMEOUT); - spin_lock_irqsave(&xhci->lock, flags); - xhci_set_link_state(xhci, port_array, wIndex, - XDEV_U0); -@@ -1355,6 +1355,35 @@ int xhci_bus_suspend(struct usb_hcd *hcd) - return 0; - } - -+/* -+ * Workaround for missing Cold Attach Status (CAS) if device re-plugged in S3. -+ * warm reset a USB3 device stuck in polling or compliance mode after resume. -+ * See Intel 100/c230 series PCH specification update Doc #332692-006 Errata #8 -+ */ -+static bool xhci_port_missing_cas_quirk(int port_index, -+ __le32 __iomem **port_array) -+{ -+ u32 portsc; -+ -+ portsc = readl(port_array[port_index]); -+ -+ /* if any of these are set we are not stuck */ -+ if (portsc & (PORT_CONNECT | PORT_CAS)) -+ return false; -+ -+ if (((portsc & PORT_PLS_MASK) != XDEV_POLLING) && -+ ((portsc & PORT_PLS_MASK) != XDEV_COMP_MODE)) -+ return false; -+ -+ /* clear wakeup/change bits, and do a warm port reset */ -+ portsc &= ~(PORT_RWC_BITS | PORT_CEC | PORT_WAKE_BITS); -+ portsc |= PORT_WR; -+ writel(portsc, port_array[port_index]); -+ /* flush write */ -+ readl(port_array[port_index]); -+ return true; -+} -+ - int xhci_bus_resume(struct usb_hcd *hcd) - { - struct xhci_hcd *xhci = hcd_to_xhci(hcd); -@@ -1392,6 +1421,14 @@ int xhci_bus_resume(struct usb_hcd *hcd) - u32 temp; - - temp = readl(port_array[port_index]); -+ -+ /* warm reset CAS limited ports stuck in polling/compliance */ -+ if ((xhci->quirks & XHCI_MISSING_CAS) && -+ (hcd->speed >= HCD_USB3) && -+ xhci_port_missing_cas_quirk(port_index, port_array)) { -+ xhci_dbg(xhci, "reset stuck port %d\n", port_index); -+ continue; -+ } - if (DEV_SUPERSPEED_ANY(temp)) - temp &= ~(PORT_RWC_BITS | PORT_CEC | PORT_WAKE_BITS); - else -@@ -1410,7 +1447,7 @@ int xhci_bus_resume(struct usb_hcd *hcd) - - if (need_usb2_u3_exit) { - spin_unlock_irqrestore(&xhci->lock, flags); -- msleep(20); -+ msleep(USB_RESUME_TIMEOUT); - spin_lock_irqsave(&xhci->lock, flags); - } - -diff --git a/drivers/usb/host/xhci-pci.c b/drivers/usb/host/xhci-pci.c -index d7b0f97..e96ae80 100644 ---- a/drivers/usb/host/xhci-pci.c -+++ b/drivers/usb/host/xhci-pci.c -@@ -45,11 +45,13 @@ - - #define PCI_DEVICE_ID_INTEL_LYNXPOINT_XHCI 0x8c31 - #define PCI_DEVICE_ID_INTEL_LYNXPOINT_LP_XHCI 0x9c31 -+#define PCI_DEVICE_ID_INTEL_WILDCATPOINT_LP_XHCI 0x9cb1 - #define PCI_DEVICE_ID_INTEL_CHERRYVIEW_XHCI 0x22b5 - #define PCI_DEVICE_ID_INTEL_SUNRISEPOINT_H_XHCI 0xa12f - #define PCI_DEVICE_ID_INTEL_SUNRISEPOINT_LP_XHCI 0x9d2f - #define PCI_DEVICE_ID_INTEL_BROXTON_M_XHCI 0x0aa8 - #define PCI_DEVICE_ID_INTEL_BROXTON_B_XHCI 0x1aa8 -+#define PCI_DEVICE_ID_INTEL_APL_XHCI 0x5aa8 - - static const char hcd_name[] = "xhci_hcd"; - -@@ -153,7 +155,8 @@ static void xhci_pci_quirks(struct device *dev, struct xhci_hcd *xhci) - xhci->quirks |= XHCI_SPURIOUS_REBOOT; - } - if (pdev->vendor == PCI_VENDOR_ID_INTEL && -- pdev->device == PCI_DEVICE_ID_INTEL_LYNXPOINT_LP_XHCI) { -+ (pdev->device == PCI_DEVICE_ID_INTEL_LYNXPOINT_LP_XHCI || -+ pdev->device == PCI_DEVICE_ID_INTEL_WILDCATPOINT_LP_XHCI)) { - xhci->quirks |= XHCI_SPURIOUS_REBOOT; - xhci->quirks |= XHCI_SPURIOUS_WAKEUP; - } -@@ -169,6 +172,11 @@ static void xhci_pci_quirks(struct device *dev, struct xhci_hcd *xhci) - pdev->device == PCI_DEVICE_ID_INTEL_CHERRYVIEW_XHCI) { - xhci->quirks |= XHCI_SSIC_PORT_UNUSED; - } -+ if (pdev->vendor == PCI_VENDOR_ID_INTEL && -+ (pdev->device == PCI_DEVICE_ID_INTEL_CHERRYVIEW_XHCI || -+ pdev->device == PCI_DEVICE_ID_INTEL_APL_XHCI)) -+ xhci->quirks |= XHCI_MISSING_CAS; -+ - if (pdev->vendor == PCI_VENDOR_ID_ETRON && - pdev->device == PCI_DEVICE_ID_EJ168) { - xhci->quirks |= XHCI_RESET_ON_RESUME; -diff --git a/drivers/usb/host/xhci.h b/drivers/usb/host/xhci.h -index b2c1dc5..f945380 100644 ---- a/drivers/usb/host/xhci.h -+++ b/drivers/usb/host/xhci.h -@@ -314,6 +314,8 @@ struct xhci_op_regs { - #define XDEV_U2 (0x2 << 5) - #define XDEV_U3 (0x3 << 5) - #define XDEV_INACTIVE (0x6 << 5) -+#define XDEV_POLLING (0x7 << 5) -+#define XDEV_COMP_MODE (0xa << 5) - #define XDEV_RESUME (0xf << 5) - /* true: port has power (see HCC_PPC) */ - #define PORT_POWER (1 << 9) -@@ -1653,6 +1655,7 @@ struct xhci_hcd { - #define XHCI_MTK_HOST (1 << 21) - #define XHCI_SSIC_PORT_UNUSED (1 << 22) - #define XHCI_NO_64BIT_SUPPORT (1 << 23) -+#define XHCI_MISSING_CAS (1 << 24) - unsigned int num_active_eps; - unsigned int limit_active_eps; - /* There are two roothubs to keep track of bus suspend info for */ -diff --git a/drivers/usb/musb/omap2430.c b/drivers/usb/musb/omap2430.c -index 0b4cec9..dae92de 100644 ---- a/drivers/usb/musb/omap2430.c -+++ b/drivers/usb/musb/omap2430.c -@@ -337,6 +337,7 @@ static int omap2430_musb_init(struct musb *musb) - } - musb->isr = omap2430_musb_interrupt; - phy_init(musb->phy); -+ phy_power_on(musb->phy); - - l = musb_readl(musb->mregs, OTG_INTERFSEL); - -@@ -373,8 +374,6 @@ static void omap2430_musb_enable(struct musb *musb) - struct musb_hdrc_platform_data *pdata = dev_get_platdata(dev); - struct omap_musb_board_data *data = pdata->board_data; - -- if (!WARN_ON(!musb->phy)) -- phy_power_on(musb->phy); - - omap2430_set_power(musb, true, glue->cable_connected); - -@@ -413,9 +412,6 @@ static void omap2430_musb_disable(struct musb *musb) - struct device *dev = musb->controller; - struct omap2430_glue *glue = dev_get_drvdata(dev->parent); - -- if (!WARN_ON(!musb->phy)) -- phy_power_off(musb->phy); -- - if (glue->status != MUSB_UNKNOWN) - omap_control_usb_set_mode(glue->control_otghs, - USB_MODE_DISCONNECT); -@@ -429,6 +425,7 @@ static int omap2430_musb_exit(struct musb *musb) - struct omap2430_glue *glue = dev_get_drvdata(dev->parent); - - omap2430_low_level_exit(musb); -+ phy_power_off(musb->phy); - phy_exit(musb->phy); - musb->phy = NULL; - cancel_work_sync(&glue->omap_musb_mailbox_work); -diff --git a/drivers/usb/renesas_usbhs/rcar3.c b/drivers/usb/renesas_usbhs/rcar3.c -index 1d70add..d544b33 100644 ---- a/drivers/usb/renesas_usbhs/rcar3.c -+++ b/drivers/usb/renesas_usbhs/rcar3.c -@@ -9,6 +9,7 @@ - * - */ - -+#include <linux/delay.h> - #include <linux/io.h> - #include "common.h" - #include "rcar3.h" -@@ -35,10 +36,13 @@ static int usbhs_rcar3_power_ctrl(struct platform_device *pdev, - - usbhs_write32(priv, UGCTRL2, UGCTRL2_RESERVED_3 | UGCTRL2_USB0SEL_OTG); - -- if (enable) -+ if (enable) { - usbhs_bset(priv, LPSTS, LPSTS_SUSPM, LPSTS_SUSPM); -- else -+ /* The controller on R-Car Gen3 needs to wait up to 45 usec */ -+ udelay(45); -+ } else { - usbhs_bset(priv, LPSTS, LPSTS_SUSPM, 0); -+ } - - return 0; - } -diff --git a/drivers/usb/serial/cp210x.c b/drivers/usb/serial/cp210x.c -index 54a4de0..f61477b 100644 ---- a/drivers/usb/serial/cp210x.c -+++ b/drivers/usb/serial/cp210x.c -@@ -1077,7 +1077,9 @@ static int cp210x_tiocmget(struct tty_struct *tty) - u8 control; - int result; - -- cp210x_read_u8_reg(port, CP210X_GET_MDMSTS, &control); -+ result = cp210x_read_u8_reg(port, CP210X_GET_MDMSTS, &control); -+ if (result) -+ return result; - - result = ((control & CONTROL_DTR) ? TIOCM_DTR : 0) - |((control & CONTROL_RTS) ? TIOCM_RTS : 0) -diff --git a/drivers/usb/serial/ftdi_sio.c b/drivers/usb/serial/ftdi_sio.c -index b2d767e..0ff7f38 100644 ---- a/drivers/usb/serial/ftdi_sio.c -+++ b/drivers/usb/serial/ftdi_sio.c -@@ -986,7 +986,8 @@ static const struct usb_device_id id_table_combined[] = { - /* ekey Devices */ - { USB_DEVICE(FTDI_VID, FTDI_EKEY_CONV_USB_PID) }, - /* Infineon Devices */ -- { USB_DEVICE_INTERFACE_NUMBER(INFINEON_VID, INFINEON_TRIBOARD_PID, 1) }, -+ { USB_DEVICE_INTERFACE_NUMBER(INFINEON_VID, INFINEON_TRIBOARD_TC1798_PID, 1) }, -+ { USB_DEVICE_INTERFACE_NUMBER(INFINEON_VID, INFINEON_TRIBOARD_TC2X7_PID, 1) }, - /* GE Healthcare devices */ - { USB_DEVICE(GE_HEALTHCARE_VID, GE_HEALTHCARE_NEMO_TRACKER_PID) }, - /* Active Research (Actisense) devices */ -diff --git a/drivers/usb/serial/ftdi_sio_ids.h b/drivers/usb/serial/ftdi_sio_ids.h -index f87a938..21011c0 100644 ---- a/drivers/usb/serial/ftdi_sio_ids.h -+++ b/drivers/usb/serial/ftdi_sio_ids.h -@@ -626,8 +626,9 @@ - /* - * Infineon Technologies - */ --#define INFINEON_VID 0x058b --#define INFINEON_TRIBOARD_PID 0x0028 /* DAS JTAG TriBoard TC1798 V1.0 */ -+#define INFINEON_VID 0x058b -+#define INFINEON_TRIBOARD_TC1798_PID 0x0028 /* DAS JTAG TriBoard TC1798 V1.0 */ -+#define INFINEON_TRIBOARD_TC2X7_PID 0x0043 /* DAS JTAG TriBoard TC2X7 V1.0 */ - - /* - * Acton Research Corp. -diff --git a/drivers/usb/serial/usb-serial.c b/drivers/usb/serial/usb-serial.c -index d213cf4..4a037b4 100644 ---- a/drivers/usb/serial/usb-serial.c -+++ b/drivers/usb/serial/usb-serial.c -@@ -1078,7 +1078,8 @@ static int usb_serial_probe(struct usb_interface *interface, - - serial->disconnected = 0; - -- usb_serial_console_init(serial->port[0]->minor); -+ if (num_ports > 0) -+ usb_serial_console_init(serial->port[0]->minor); - exit: - module_put(type->driver.owner); - return 0; -diff --git a/drivers/video/fbdev/omap2/omapfb/dss/dsi.c b/drivers/video/fbdev/omap2/omapfb/dss/dsi.c -index 9e4800a..951dd93 100644 ---- a/drivers/video/fbdev/omap2/omapfb/dss/dsi.c -+++ b/drivers/video/fbdev/omap2/omapfb/dss/dsi.c -@@ -5348,7 +5348,7 @@ static int dsi_bind(struct device *dev, struct device *master, void *data) - - dsi->phy_base = devm_ioremap(&dsidev->dev, res->start, - resource_size(res)); -- if (!dsi->proto_base) { -+ if (!dsi->phy_base) { - DSSERR("can't ioremap DSI PHY\n"); - return -ENOMEM; - } -@@ -5368,7 +5368,7 @@ static int dsi_bind(struct device *dev, struct device *master, void *data) - - dsi->pll_base = devm_ioremap(&dsidev->dev, res->start, - resource_size(res)); -- if (!dsi->proto_base) { -+ if (!dsi->pll_base) { - DSSERR("can't ioremap DSI PLL\n"); - return -ENOMEM; - } -diff --git a/drivers/video/fbdev/pxafb.c b/drivers/video/fbdev/pxafb.c -index 2c0487f..ed41fdb 100644 ---- a/drivers/video/fbdev/pxafb.c -+++ b/drivers/video/fbdev/pxafb.c -@@ -2125,7 +2125,7 @@ static int of_get_pxafb_display(struct device *dev, struct device_node *disp, - - timings = of_get_display_timings(disp); - if (!timings) -- goto out; -+ return -EINVAL; - - ret = -ENOMEM; - info->modes = kmalloc_array(timings->num_timings, -diff --git a/drivers/virtio/virtio_pci_legacy.c b/drivers/virtio/virtio_pci_legacy.c -index 8c4e617..6d9e517 100644 ---- a/drivers/virtio/virtio_pci_legacy.c -+++ b/drivers/virtio/virtio_pci_legacy.c -@@ -212,10 +212,18 @@ int virtio_pci_legacy_probe(struct virtio_pci_device *vp_dev) - return -ENODEV; - } - -- rc = dma_set_mask_and_coherent(&pci_dev->dev, DMA_BIT_MASK(64)); -- if (rc) -- rc = dma_set_mask_and_coherent(&pci_dev->dev, -- DMA_BIT_MASK(32)); -+ rc = dma_set_mask(&pci_dev->dev, DMA_BIT_MASK(64)); -+ if (rc) { -+ rc = dma_set_mask_and_coherent(&pci_dev->dev, DMA_BIT_MASK(32)); -+ } else { -+ /* -+ * The virtio ring base address is expressed as a 32-bit PFN, -+ * with a page size of 1 << VIRTIO_PCI_QUEUE_ADDR_SHIFT. -+ */ -+ dma_set_coherent_mask(&pci_dev->dev, -+ DMA_BIT_MASK(32 + VIRTIO_PCI_QUEUE_ADDR_SHIFT)); -+ } -+ - if (rc) - dev_warn(&pci_dev->dev, "Failed to enable 64-bit or 32-bit DMA. Trying to continue, but this might not work.\n"); - -diff --git a/drivers/virtio/virtio_ring.c b/drivers/virtio/virtio_ring.c -index ed9c9ee..6b2cd92 100644 ---- a/drivers/virtio/virtio_ring.c -+++ b/drivers/virtio/virtio_ring.c -@@ -732,7 +732,8 @@ void virtqueue_disable_cb(struct virtqueue *_vq) - - if (!(vq->avail_flags_shadow & VRING_AVAIL_F_NO_INTERRUPT)) { - vq->avail_flags_shadow |= VRING_AVAIL_F_NO_INTERRUPT; -- vq->vring.avail->flags = cpu_to_virtio16(_vq->vdev, vq->avail_flags_shadow); -+ if (!vq->event) -+ vq->vring.avail->flags = cpu_to_virtio16(_vq->vdev, vq->avail_flags_shadow); - } - - } -@@ -764,7 +765,8 @@ unsigned virtqueue_enable_cb_prepare(struct virtqueue *_vq) - * entry. Always do both to keep code simple. */ - if (vq->avail_flags_shadow & VRING_AVAIL_F_NO_INTERRUPT) { - vq->avail_flags_shadow &= ~VRING_AVAIL_F_NO_INTERRUPT; -- vq->vring.avail->flags = cpu_to_virtio16(_vq->vdev, vq->avail_flags_shadow); -+ if (!vq->event) -+ vq->vring.avail->flags = cpu_to_virtio16(_vq->vdev, vq->avail_flags_shadow); - } - vring_used_event(&vq->vring) = cpu_to_virtio16(_vq->vdev, last_used_idx = vq->last_used_idx); - END_USE(vq); -@@ -832,10 +834,11 @@ bool virtqueue_enable_cb_delayed(struct virtqueue *_vq) - * more to do. */ - /* Depending on the VIRTIO_RING_F_USED_EVENT_IDX feature, we need to - * either clear the flags bit or point the event index at the next -- * entry. Always do both to keep code simple. */ -+ * entry. Always update the event index to keep code simple. */ - if (vq->avail_flags_shadow & VRING_AVAIL_F_NO_INTERRUPT) { - vq->avail_flags_shadow &= ~VRING_AVAIL_F_NO_INTERRUPT; -- vq->vring.avail->flags = cpu_to_virtio16(_vq->vdev, vq->avail_flags_shadow); -+ if (!vq->event) -+ vq->vring.avail->flags = cpu_to_virtio16(_vq->vdev, vq->avail_flags_shadow); - } - /* TODO: tune this threshold */ - bufs = (u16)(vq->avail_idx_shadow - vq->last_used_idx) * 3 / 4; -@@ -953,7 +956,8 @@ struct virtqueue *__vring_new_virtqueue(unsigned int index, - /* No callback? Tell other side not to bother us. */ - if (!callback) { - vq->avail_flags_shadow |= VRING_AVAIL_F_NO_INTERRUPT; -- vq->vring.avail->flags = cpu_to_virtio16(vdev, vq->avail_flags_shadow); -+ if (!vq->event) -+ vq->vring.avail->flags = cpu_to_virtio16(vdev, vq->avail_flags_shadow); - } - - /* Put everything in free lists. */ -diff --git a/fs/btrfs/inode.c b/fs/btrfs/inode.c -index e6811c4..bc1a004 100644 ---- a/fs/btrfs/inode.c -+++ b/fs/btrfs/inode.c -@@ -8915,9 +8915,14 @@ static void btrfs_invalidatepage(struct page *page, unsigned int offset, - * So even we call qgroup_free_data(), it won't decrease reserved - * space. - * 2) Not written to disk -- * This means the reserved space should be freed here. -+ * This means the reserved space should be freed here. However, -+ * if a truncate invalidates the page (by clearing PageDirty) -+ * and the page is accounted for while allocating extent -+ * in btrfs_check_data_free_space() we let delayed_ref to -+ * free the entire extent. - */ -- btrfs_qgroup_free_data(inode, page_start, PAGE_SIZE); -+ if (PageDirty(page)) -+ btrfs_qgroup_free_data(inode, page_start, PAGE_SIZE); - if (!inode_evicting) { - clear_extent_bit(tree, page_start, page_end, - EXTENT_LOCKED | EXTENT_DIRTY | -diff --git a/fs/btrfs/tree-log.c b/fs/btrfs/tree-log.c -index ef9c55b..90e1198 100644 ---- a/fs/btrfs/tree-log.c -+++ b/fs/btrfs/tree-log.c -@@ -2713,14 +2713,12 @@ static inline void btrfs_remove_all_log_ctxs(struct btrfs_root *root, - int index, int error) - { - struct btrfs_log_ctx *ctx; -+ struct btrfs_log_ctx *safe; - -- if (!error) { -- INIT_LIST_HEAD(&root->log_ctxs[index]); -- return; -- } -- -- list_for_each_entry(ctx, &root->log_ctxs[index], list) -+ list_for_each_entry_safe(ctx, safe, &root->log_ctxs[index], list) { -+ list_del_init(&ctx->list); - ctx->log_ret = error; -+ } - - INIT_LIST_HEAD(&root->log_ctxs[index]); - } -@@ -2961,13 +2959,9 @@ int btrfs_sync_log(struct btrfs_trans_handle *trans, - mutex_unlock(&root->log_mutex); - - out_wake_log_root: -- /* -- * We needn't get log_mutex here because we are sure all -- * the other tasks are blocked. -- */ -+ mutex_lock(&log_root_tree->log_mutex); - btrfs_remove_all_log_ctxs(log_root_tree, index2, ret); - -- mutex_lock(&log_root_tree->log_mutex); - log_root_tree->log_transid_committed++; - atomic_set(&log_root_tree->log_commit[index2], 0); - mutex_unlock(&log_root_tree->log_mutex); -@@ -2978,10 +2972,8 @@ int btrfs_sync_log(struct btrfs_trans_handle *trans, - if (waitqueue_active(&log_root_tree->log_commit_wait[index2])) - wake_up(&log_root_tree->log_commit_wait[index2]); - out: -- /* See above. */ -- btrfs_remove_all_log_ctxs(root, index1, ret); -- - mutex_lock(&root->log_mutex); -+ btrfs_remove_all_log_ctxs(root, index1, ret); - root->log_transid_committed++; - atomic_set(&root->log_commit[index1], 0); - mutex_unlock(&root->log_mutex); -diff --git a/fs/nfsd/nfs4state.c b/fs/nfsd/nfs4state.c -index a204d7e..0fe31b4 100644 ---- a/fs/nfsd/nfs4state.c -+++ b/fs/nfsd/nfs4state.c -@@ -1147,9 +1147,7 @@ static void put_ol_stateid_locked(struct nfs4_ol_stateid *stp, - - static bool unhash_lock_stateid(struct nfs4_ol_stateid *stp) - { -- struct nfs4_openowner *oo = openowner(stp->st_openstp->st_stateowner); -- -- lockdep_assert_held(&oo->oo_owner.so_client->cl_lock); -+ lockdep_assert_held(&stp->st_stid.sc_client->cl_lock); - - list_del_init(&stp->st_locks); - nfs4_unhash_stid(&stp->st_stid); -@@ -1158,12 +1156,12 @@ static bool unhash_lock_stateid(struct nfs4_ol_stateid *stp) - - static void release_lock_stateid(struct nfs4_ol_stateid *stp) - { -- struct nfs4_openowner *oo = openowner(stp->st_openstp->st_stateowner); -+ struct nfs4_client *clp = stp->st_stid.sc_client; - bool unhashed; - -- spin_lock(&oo->oo_owner.so_client->cl_lock); -+ spin_lock(&clp->cl_lock); - unhashed = unhash_lock_stateid(stp); -- spin_unlock(&oo->oo_owner.so_client->cl_lock); -+ spin_unlock(&clp->cl_lock); - if (unhashed) - nfs4_put_stid(&stp->st_stid); - } -diff --git a/fs/overlayfs/copy_up.c b/fs/overlayfs/copy_up.c -index abadbc3..767377e 100644 ---- a/fs/overlayfs/copy_up.c -+++ b/fs/overlayfs/copy_up.c -@@ -171,6 +171,8 @@ static int ovl_copy_up_data(struct path *old, struct path *new, loff_t len) - len -= bytes; - } - -+ if (!error) -+ error = vfs_fsync(new_file, 0); - fput(new_file); - out_fput: - fput(old_file); -diff --git a/fs/overlayfs/inode.c b/fs/overlayfs/inode.c -index c75625c..cf2bfeb 100644 ---- a/fs/overlayfs/inode.c -+++ b/fs/overlayfs/inode.c -@@ -294,9 +294,6 @@ struct posix_acl *ovl_get_acl(struct inode *inode, int type) - if (!IS_ENABLED(CONFIG_FS_POSIX_ACL) || !IS_POSIXACL(realinode)) - return NULL; - -- if (!realinode->i_op->get_acl) -- return NULL; -- - old_cred = ovl_override_creds(inode->i_sb); - acl = get_acl(realinode, type); - revert_creds(old_cred); -diff --git a/fs/overlayfs/super.c b/fs/overlayfs/super.c -index e2a94a2..a78415d 100644 ---- a/fs/overlayfs/super.c -+++ b/fs/overlayfs/super.c -@@ -1026,6 +1026,21 @@ ovl_posix_acl_xattr_set(const struct xattr_handler *handler, - - posix_acl_release(acl); - -+ /* -+ * Check if sgid bit needs to be cleared (actual setacl operation will -+ * be done with mounter's capabilities and so that won't do it for us). -+ */ -+ if (unlikely(inode->i_mode & S_ISGID) && -+ handler->flags == ACL_TYPE_ACCESS && -+ !in_group_p(inode->i_gid) && -+ !capable_wrt_inode_uidgid(inode, CAP_FSETID)) { -+ struct iattr iattr = { .ia_valid = ATTR_KILL_SGID }; -+ -+ err = ovl_setattr(dentry, &iattr); -+ if (err) -+ return err; -+ } -+ - err = ovl_xattr_set(dentry, handler->name, value, size, flags); - if (!err) - ovl_copyattr(ovl_inode_real(inode, NULL), inode); -diff --git a/fs/ubifs/dir.c b/fs/ubifs/dir.c -index 4b86d3a..3b27145 100644 ---- a/fs/ubifs/dir.c -+++ b/fs/ubifs/dir.c -@@ -350,7 +350,7 @@ static unsigned int vfs_dent_type(uint8_t type) - */ - static int ubifs_readdir(struct file *file, struct dir_context *ctx) - { -- int err; -+ int err = 0; - struct qstr nm; - union ubifs_key key; - struct ubifs_dent_node *dent; -@@ -452,14 +452,20 @@ static int ubifs_readdir(struct file *file, struct dir_context *ctx) - kfree(file->private_data); - file->private_data = NULL; - -- if (err != -ENOENT) { -+ if (err != -ENOENT) - ubifs_err(c, "cannot find next direntry, error %d", err); -- return err; -- } -+ else -+ /* -+ * -ENOENT is a non-fatal error in this context, the TNC uses -+ * it to indicate that the cursor moved past the current directory -+ * and readdir() has to stop. -+ */ -+ err = 0; -+ - - /* 2 is a special value indicating that there are no more direntries */ - ctx->pos = 2; -- return 0; -+ return err; - } - - /* Free saved readdir() state when the directory is closed */ -diff --git a/fs/xfs/libxfs/xfs_dquot_buf.c b/fs/xfs/libxfs/xfs_dquot_buf.c -index 3cc3cf7..ac9a003 100644 ---- a/fs/xfs/libxfs/xfs_dquot_buf.c -+++ b/fs/xfs/libxfs/xfs_dquot_buf.c -@@ -191,8 +191,7 @@ xfs_dquot_buf_verify_crc( - if (mp->m_quotainfo) - ndquots = mp->m_quotainfo->qi_dqperchunk; - else -- ndquots = xfs_calc_dquots_per_chunk( -- XFS_BB_TO_FSB(mp, bp->b_length)); -+ ndquots = xfs_calc_dquots_per_chunk(bp->b_length); - - for (i = 0; i < ndquots; i++, d++) { - if (!xfs_verify_cksum((char *)d, sizeof(struct xfs_dqblk), -diff --git a/include/linux/pwm.h b/include/linux/pwm.h -index f1bbae0..2c6c511 100644 ---- a/include/linux/pwm.h -+++ b/include/linux/pwm.h -@@ -641,6 +641,7 @@ static inline void pwm_remove_table(struct pwm_lookup *table, size_t num) - #ifdef CONFIG_PWM_SYSFS - void pwmchip_sysfs_export(struct pwm_chip *chip); - void pwmchip_sysfs_unexport(struct pwm_chip *chip); -+void pwmchip_sysfs_unexport_children(struct pwm_chip *chip); - #else - static inline void pwmchip_sysfs_export(struct pwm_chip *chip) - { -@@ -649,6 +650,10 @@ static inline void pwmchip_sysfs_export(struct pwm_chip *chip) - static inline void pwmchip_sysfs_unexport(struct pwm_chip *chip) - { - } -+ -+static inline void pwmchip_sysfs_unexport_children(struct pwm_chip *chip) -+{ -+} - #endif /* CONFIG_PWM_SYSFS */ - - #endif /* __LINUX_PWM_H */ -diff --git a/include/uapi/linux/Kbuild b/include/uapi/linux/Kbuild -index 185f8ea..407ca0d 100644 ---- a/include/uapi/linux/Kbuild -+++ b/include/uapi/linux/Kbuild -@@ -396,6 +396,7 @@ header-y += string.h - header-y += suspend_ioctls.h - header-y += swab.h - header-y += synclink.h -+header-y += sync_file.h - header-y += sysctl.h - header-y += sysinfo.h - header-y += target_core_user.h -diff --git a/kernel/time/timer.c b/kernel/time/timer.c -index 32bf6f7..96db64b 100644 ---- a/kernel/time/timer.c -+++ b/kernel/time/timer.c -@@ -878,7 +878,7 @@ static inline struct timer_base *get_timer_base(u32 tflags) - - #ifdef CONFIG_NO_HZ_COMMON - static inline struct timer_base * --__get_target_base(struct timer_base *base, unsigned tflags) -+get_target_base(struct timer_base *base, unsigned tflags) - { - #ifdef CONFIG_SMP - if ((tflags & TIMER_PINNED) || !base->migration_enabled) -@@ -891,25 +891,27 @@ __get_target_base(struct timer_base *base, unsigned tflags) - - static inline void forward_timer_base(struct timer_base *base) - { -+ unsigned long jnow = READ_ONCE(jiffies); -+ - /* - * We only forward the base when it's idle and we have a delta between - * base clock and jiffies. - */ -- if (!base->is_idle || (long) (jiffies - base->clk) < 2) -+ if (!base->is_idle || (long) (jnow - base->clk) < 2) - return; - - /* - * If the next expiry value is > jiffies, then we fast forward to - * jiffies otherwise we forward to the next expiry value. - */ -- if (time_after(base->next_expiry, jiffies)) -- base->clk = jiffies; -+ if (time_after(base->next_expiry, jnow)) -+ base->clk = jnow; - else - base->clk = base->next_expiry; - } - #else - static inline struct timer_base * --__get_target_base(struct timer_base *base, unsigned tflags) -+get_target_base(struct timer_base *base, unsigned tflags) - { - return get_timer_this_cpu_base(tflags); - } -@@ -917,14 +919,6 @@ __get_target_base(struct timer_base *base, unsigned tflags) - static inline void forward_timer_base(struct timer_base *base) { } - #endif - --static inline struct timer_base * --get_target_base(struct timer_base *base, unsigned tflags) --{ -- struct timer_base *target = __get_target_base(base, tflags); -- -- forward_timer_base(target); -- return target; --} - - /* - * We are using hashed locking: Holding per_cpu(timer_bases[x]).lock means -@@ -943,7 +937,14 @@ static struct timer_base *lock_timer_base(struct timer_list *timer, - { - for (;;) { - struct timer_base *base; -- u32 tf = timer->flags; -+ u32 tf; -+ -+ /* -+ * We need to use READ_ONCE() here, otherwise the compiler -+ * might re-read @tf between the check for TIMER_MIGRATING -+ * and spin_lock(). -+ */ -+ tf = READ_ONCE(timer->flags); - - if (!(tf & TIMER_MIGRATING)) { - base = get_timer_base(tf); -@@ -964,6 +965,8 @@ __mod_timer(struct timer_list *timer, unsigned long expires, bool pending_only) - unsigned long clk = 0, flags; - int ret = 0; - -+ BUG_ON(!timer->function); -+ - /* - * This is a common optimization triggered by the networking code - if - * the timer is re-modified to have the same timeout or ends up in the -@@ -972,13 +975,16 @@ __mod_timer(struct timer_list *timer, unsigned long expires, bool pending_only) - if (timer_pending(timer)) { - if (timer->expires == expires) - return 1; -+ - /* -- * Take the current timer_jiffies of base, but without holding -- * the lock! -+ * We lock timer base and calculate the bucket index right -+ * here. If the timer ends up in the same bucket, then we -+ * just update the expiry time and avoid the whole -+ * dequeue/enqueue dance. - */ -- base = get_timer_base(timer->flags); -- clk = base->clk; -+ base = lock_timer_base(timer, &flags); - -+ clk = base->clk; - idx = calc_wheel_index(expires, clk); - - /* -@@ -988,14 +994,14 @@ __mod_timer(struct timer_list *timer, unsigned long expires, bool pending_only) - */ - if (idx == timer_get_idx(timer)) { - timer->expires = expires; -- return 1; -+ ret = 1; -+ goto out_unlock; - } -+ } else { -+ base = lock_timer_base(timer, &flags); - } - - timer_stats_timer_set_start_info(timer); -- BUG_ON(!timer->function); -- -- base = lock_timer_base(timer, &flags); - - ret = detach_if_pending(timer, base, false); - if (!ret && pending_only) -@@ -1025,12 +1031,16 @@ __mod_timer(struct timer_list *timer, unsigned long expires, bool pending_only) - } - } - -+ /* Try to forward a stale timer base clock */ -+ forward_timer_base(base); -+ - timer->expires = expires; - /* - * If 'idx' was calculated above and the base time did not advance -- * between calculating 'idx' and taking the lock, only enqueue_timer() -- * and trigger_dyntick_cpu() is required. Otherwise we need to -- * (re)calculate the wheel index via internal_add_timer(). -+ * between calculating 'idx' and possibly switching the base, only -+ * enqueue_timer() and trigger_dyntick_cpu() is required. Otherwise -+ * we need to (re)calculate the wheel index via -+ * internal_add_timer(). - */ - if (idx != UINT_MAX && clk == base->clk) { - enqueue_timer(base, timer, idx); -@@ -1510,12 +1520,16 @@ u64 get_next_timer_interrupt(unsigned long basej, u64 basem) - is_max_delta = (nextevt == base->clk + NEXT_TIMER_MAX_DELTA); - base->next_expiry = nextevt; - /* -- * We have a fresh next event. Check whether we can forward the base: -+ * We have a fresh next event. Check whether we can forward the -+ * base. We can only do that when @basej is past base->clk -+ * otherwise we might rewind base->clk. - */ -- if (time_after(nextevt, jiffies)) -- base->clk = jiffies; -- else if (time_after(nextevt, base->clk)) -- base->clk = nextevt; -+ if (time_after(basej, base->clk)) { -+ if (time_after(nextevt, basej)) -+ base->clk = basej; -+ else if (time_after(nextevt, base->clk)) -+ base->clk = nextevt; -+ } - - if (time_before_eq(nextevt, basej)) { - expires = basem; -diff --git a/mm/list_lru.c b/mm/list_lru.c -index 1d05cb9..234676e 100644 ---- a/mm/list_lru.c -+++ b/mm/list_lru.c -@@ -554,6 +554,8 @@ int __list_lru_init(struct list_lru *lru, bool memcg_aware, - err = memcg_init_list_lru(lru, memcg_aware); - if (err) { - kfree(lru->node); -+ /* Do this so a list_lru_destroy() doesn't crash: */ -+ lru->node = NULL; - goto out; - } - -diff --git a/mm/memcontrol.c b/mm/memcontrol.c -index 4be518d..dddead1 100644 ---- a/mm/memcontrol.c -+++ b/mm/memcontrol.c -@@ -1947,6 +1947,15 @@ static int try_charge(struct mem_cgroup *memcg, gfp_t gfp_mask, - current->flags & PF_EXITING)) - goto force; - -+ /* -+ * Prevent unbounded recursion when reclaim operations need to -+ * allocate memory. This might exceed the limits temporarily, -+ * but we prefer facilitating memory reclaim and getting back -+ * under the limit over triggering OOM kills in these cases. -+ */ -+ if (unlikely(current->flags & PF_MEMALLOC)) -+ goto force; -+ - if (unlikely(task_in_memcg_oom(current))) - goto nomem; - -diff --git a/mm/slab.c b/mm/slab.c -index b672710..525a911 100644 ---- a/mm/slab.c -+++ b/mm/slab.c -@@ -964,7 +964,7 @@ static int setup_kmem_cache_node(struct kmem_cache *cachep, - * guaranteed to be valid until irq is re-enabled, because it will be - * freed after synchronize_sched(). - */ -- if (force_change) -+ if (old_shared && force_change) - synchronize_sched(); - - fail: -diff --git a/mm/vmscan.c b/mm/vmscan.c -index 0fe8b71..ba0fad7 100644 ---- a/mm/vmscan.c -+++ b/mm/vmscan.c -@@ -3048,7 +3048,9 @@ unsigned long try_to_free_mem_cgroup_pages(struct mem_cgroup *memcg, - sc.gfp_mask, - sc.reclaim_idx); - -+ current->flags |= PF_MEMALLOC; - nr_reclaimed = do_try_to_free_pages(zonelist, &sc); -+ current->flags &= ~PF_MEMALLOC; - - trace_mm_vmscan_memcg_reclaim_end(nr_reclaimed); - -diff --git a/net/mac80211/rx.c b/net/mac80211/rx.c -index 9dce3b1..59a9603 100644 ---- a/net/mac80211/rx.c -+++ b/net/mac80211/rx.c -@@ -2253,16 +2253,22 @@ ieee80211_rx_h_amsdu(struct ieee80211_rx_data *rx) - if (!(status->rx_flags & IEEE80211_RX_AMSDU)) - return RX_CONTINUE; - -- if (ieee80211_has_a4(hdr->frame_control) && -- rx->sdata->vif.type == NL80211_IFTYPE_AP_VLAN && -- !rx->sdata->u.vlan.sta) -- return RX_DROP_UNUSABLE; -+ if (unlikely(ieee80211_has_a4(hdr->frame_control))) { -+ switch (rx->sdata->vif.type) { -+ case NL80211_IFTYPE_AP_VLAN: -+ if (!rx->sdata->u.vlan.sta) -+ return RX_DROP_UNUSABLE; -+ break; -+ case NL80211_IFTYPE_STATION: -+ if (!rx->sdata->u.mgd.use_4addr) -+ return RX_DROP_UNUSABLE; -+ break; -+ default: -+ return RX_DROP_UNUSABLE; -+ } -+ } - -- if (is_multicast_ether_addr(hdr->addr1) && -- ((rx->sdata->vif.type == NL80211_IFTYPE_AP_VLAN && -- rx->sdata->u.vlan.sta) || -- (rx->sdata->vif.type == NL80211_IFTYPE_STATION && -- rx->sdata->u.mgd.use_4addr))) -+ if (is_multicast_ether_addr(hdr->addr1)) - return RX_DROP_UNUSABLE; - - skb->dev = dev; -diff --git a/net/netfilter/xt_NFLOG.c b/net/netfilter/xt_NFLOG.c -index 018eed7..8668a5c 100644 ---- a/net/netfilter/xt_NFLOG.c -+++ b/net/netfilter/xt_NFLOG.c -@@ -32,6 +32,7 @@ nflog_tg(struct sk_buff *skb, const struct xt_action_param *par) - li.u.ulog.copy_len = info->len; - li.u.ulog.group = info->group; - li.u.ulog.qthreshold = info->threshold; -+ li.u.ulog.flags = 0; - - if (info->flags & XT_NFLOG_F_COPY_LEN) - li.u.ulog.flags |= NF_LOG_F_COPY_LEN; -diff --git a/security/keys/Kconfig b/security/keys/Kconfig -index f826e87..d942c7c 100644 ---- a/security/keys/Kconfig -+++ b/security/keys/Kconfig -@@ -41,7 +41,7 @@ config BIG_KEYS - bool "Large payload keys" - depends on KEYS - depends on TMPFS -- select CRYPTO -+ depends on (CRYPTO_ANSI_CPRNG = y || CRYPTO_DRBG = y) - select CRYPTO_AES - select CRYPTO_ECB - select CRYPTO_RNG -diff --git a/security/keys/big_key.c b/security/keys/big_key.c -index c0b3030..835c1ab 100644 ---- a/security/keys/big_key.c -+++ b/security/keys/big_key.c -@@ -9,6 +9,7 @@ - * 2 of the Licence, or (at your option) any later version. - */ - -+#define pr_fmt(fmt) "big_key: "fmt - #include <linux/init.h> - #include <linux/seq_file.h> - #include <linux/file.h> -@@ -341,44 +342,48 @@ long big_key_read(const struct key *key, char __user *buffer, size_t buflen) - */ - static int __init big_key_init(void) - { -- return register_key_type(&key_type_big_key); --} -- --/* -- * Initialize big_key crypto and RNG algorithms -- */ --static int __init big_key_crypto_init(void) --{ -- int ret = -EINVAL; -+ struct crypto_skcipher *cipher; -+ struct crypto_rng *rng; -+ int ret; - -- /* init RNG */ -- big_key_rng = crypto_alloc_rng(big_key_rng_name, 0, 0); -- if (IS_ERR(big_key_rng)) { -- big_key_rng = NULL; -- return -EFAULT; -+ rng = crypto_alloc_rng(big_key_rng_name, 0, 0); -+ if (IS_ERR(rng)) { -+ pr_err("Can't alloc rng: %ld\n", PTR_ERR(rng)); -+ return PTR_ERR(rng); - } - -+ big_key_rng = rng; -+ - /* seed RNG */ -- ret = crypto_rng_reset(big_key_rng, NULL, crypto_rng_seedsize(big_key_rng)); -- if (ret) -- goto error; -+ ret = crypto_rng_reset(rng, NULL, crypto_rng_seedsize(rng)); -+ if (ret) { -+ pr_err("Can't reset rng: %d\n", ret); -+ goto error_rng; -+ } - - /* init block cipher */ -- big_key_skcipher = crypto_alloc_skcipher(big_key_alg_name, -- 0, CRYPTO_ALG_ASYNC); -- if (IS_ERR(big_key_skcipher)) { -- big_key_skcipher = NULL; -- ret = -EFAULT; -- goto error; -+ cipher = crypto_alloc_skcipher(big_key_alg_name, 0, CRYPTO_ALG_ASYNC); -+ if (IS_ERR(cipher)) { -+ ret = PTR_ERR(cipher); -+ pr_err("Can't alloc crypto: %d\n", ret); -+ goto error_rng; -+ } -+ -+ big_key_skcipher = cipher; -+ -+ ret = register_key_type(&key_type_big_key); -+ if (ret < 0) { -+ pr_err("Can't register type: %d\n", ret); -+ goto error_cipher; - } - - return 0; - --error: -+error_cipher: -+ crypto_free_skcipher(big_key_skcipher); -+error_rng: - crypto_free_rng(big_key_rng); -- big_key_rng = NULL; - return ret; - } - --device_initcall(big_key_init); --late_initcall(big_key_crypto_init); -+late_initcall(big_key_init); -diff --git a/security/keys/proc.c b/security/keys/proc.c -index f0611a6..b9f531c 100644 ---- a/security/keys/proc.c -+++ b/security/keys/proc.c -@@ -181,7 +181,7 @@ static int proc_keys_show(struct seq_file *m, void *v) - struct timespec now; - unsigned long timo; - key_ref_t key_ref, skey_ref; -- char xbuf[12]; -+ char xbuf[16]; - int rc; - - struct keyring_search_context ctx = { -diff --git a/sound/core/seq/seq_timer.c b/sound/core/seq/seq_timer.c -index dcc1028..37d9cfb 100644 ---- a/sound/core/seq/seq_timer.c -+++ b/sound/core/seq/seq_timer.c -@@ -448,8 +448,8 @@ snd_seq_real_time_t snd_seq_timer_get_cur_time(struct snd_seq_timer *tmr) - - ktime_get_ts64(&tm); - tm = timespec64_sub(tm, tmr->last_update); -- cur_time.tv_nsec = tm.tv_nsec; -- cur_time.tv_sec = tm.tv_sec; -+ cur_time.tv_nsec += tm.tv_nsec; -+ cur_time.tv_sec += tm.tv_sec; - snd_seq_sanity_real_time(&cur_time); - } - spin_unlock_irqrestore(&tmr->lock, flags); -diff --git a/sound/pci/hda/hda_intel.c b/sound/pci/hda/hda_intel.c -index 160c7f7..487fcbf 100644 ---- a/sound/pci/hda/hda_intel.c -+++ b/sound/pci/hda/hda_intel.c -@@ -340,8 +340,7 @@ enum { - - /* quirks for Nvidia */ - #define AZX_DCAPS_PRESET_NVIDIA \ -- (AZX_DCAPS_NO_MSI | /*AZX_DCAPS_ALIGN_BUFSIZE |*/ \ -- AZX_DCAPS_NO_64BIT | AZX_DCAPS_CORBRP_SELF_CLEAR |\ -+ (AZX_DCAPS_NO_MSI | AZX_DCAPS_CORBRP_SELF_CLEAR |\ - AZX_DCAPS_SNOOP_TYPE(NVIDIA)) - - #define AZX_DCAPS_PRESET_CTHDA \ -@@ -1699,6 +1698,10 @@ static int azx_first_init(struct azx *chip) - } - } - -+ /* NVidia hardware normally only supports up to 40 bits of DMA */ -+ if (chip->pci->vendor == PCI_VENDOR_ID_NVIDIA) -+ dma_bits = 40; -+ - /* disable 64bit DMA address on some devices */ - if (chip->driver_caps & AZX_DCAPS_NO_64BIT) { - dev_dbg(card->dev, "Disabling 64bit DMA\n"); -diff --git a/sound/pci/hda/patch_realtek.c b/sound/pci/hda/patch_realtek.c -index bd481ac..26e866f 100644 ---- a/sound/pci/hda/patch_realtek.c -+++ b/sound/pci/hda/patch_realtek.c -@@ -5809,8 +5809,6 @@ static const struct hda_model_fixup alc269_fixup_models[] = { - #define ALC295_STANDARD_PINS \ - {0x12, 0xb7a60130}, \ - {0x14, 0x90170110}, \ -- {0x17, 0x21014020}, \ -- {0x18, 0x21a19030}, \ - {0x21, 0x04211020} - - #define ALC298_STANDARD_PINS \ -@@ -5857,11 +5855,19 @@ static const struct snd_hda_pin_quirk alc269_pin_fixup_tbl[] = { - {0x1b, 0x02011020}, - {0x21, 0x0221101f}), - SND_HDA_PIN_QUIRK(0x10ec0255, 0x1028, "Dell", ALC255_FIXUP_DELL1_MIC_NO_PRESENCE, -+ {0x14, 0x90170110}, -+ {0x1b, 0x01011020}, -+ {0x21, 0x0221101f}), -+ SND_HDA_PIN_QUIRK(0x10ec0255, 0x1028, "Dell", ALC255_FIXUP_DELL1_MIC_NO_PRESENCE, - {0x14, 0x90170130}, - {0x1b, 0x01014020}, - {0x21, 0x0221103f}), - SND_HDA_PIN_QUIRK(0x10ec0255, 0x1028, "Dell", ALC255_FIXUP_DELL1_MIC_NO_PRESENCE, - {0x14, 0x90170130}, -+ {0x1b, 0x01011020}, -+ {0x21, 0x0221103f}), -+ SND_HDA_PIN_QUIRK(0x10ec0255, 0x1028, "Dell", ALC255_FIXUP_DELL1_MIC_NO_PRESENCE, -+ {0x14, 0x90170130}, - {0x1b, 0x02011020}, - {0x21, 0x0221103f}), - SND_HDA_PIN_QUIRK(0x10ec0255, 0x1028, "Dell", ALC255_FIXUP_DELL1_MIC_NO_PRESENCE, -@@ -6037,7 +6043,13 @@ static const struct snd_hda_pin_quirk alc269_pin_fixup_tbl[] = { - ALC292_STANDARD_PINS, - {0x13, 0x90a60140}), - SND_HDA_PIN_QUIRK(0x10ec0295, 0x1028, "Dell", ALC269_FIXUP_DELL1_MIC_NO_PRESENCE, -- ALC295_STANDARD_PINS), -+ ALC295_STANDARD_PINS, -+ {0x17, 0x21014020}, -+ {0x18, 0x21a19030}), -+ SND_HDA_PIN_QUIRK(0x10ec0295, 0x1028, "Dell", ALC269_FIXUP_DELL1_MIC_NO_PRESENCE, -+ ALC295_STANDARD_PINS, -+ {0x17, 0x21014040}, -+ {0x18, 0x21a19050}), - SND_HDA_PIN_QUIRK(0x10ec0298, 0x1028, "Dell", ALC298_FIXUP_DELL1_MIC_NO_PRESENCE, - ALC298_STANDARD_PINS, - {0x17, 0x90170110}), -@@ -6611,6 +6623,7 @@ enum { - ALC891_FIXUP_HEADSET_MODE, - ALC891_FIXUP_DELL_MIC_NO_PRESENCE, - ALC662_FIXUP_ACER_VERITON, -+ ALC892_FIXUP_ASROCK_MOBO, - }; - - static const struct hda_fixup alc662_fixups[] = { -@@ -6887,6 +6900,16 @@ static const struct hda_fixup alc662_fixups[] = { - { } - } - }, -+ [ALC892_FIXUP_ASROCK_MOBO] = { -+ .type = HDA_FIXUP_PINS, -+ .v.pins = (const struct hda_pintbl[]) { -+ { 0x15, 0x40f000f0 }, /* disabled */ -+ { 0x16, 0x40f000f0 }, /* disabled */ -+ { 0x18, 0x01014011 }, /* LO */ -+ { 0x1a, 0x01014012 }, /* LO */ -+ { } -+ } -+ }, - }; - - static const struct snd_pci_quirk alc662_fixup_tbl[] = { -@@ -6924,6 +6947,7 @@ static const struct snd_pci_quirk alc662_fixup_tbl[] = { - SND_PCI_QUIRK(0x144d, 0xc051, "Samsung R720", ALC662_FIXUP_IDEAPAD), - SND_PCI_QUIRK(0x17aa, 0x38af, "Lenovo Ideapad Y550P", ALC662_FIXUP_IDEAPAD), - SND_PCI_QUIRK(0x17aa, 0x3a0d, "Lenovo Ideapad Y550", ALC662_FIXUP_IDEAPAD), -+ SND_PCI_QUIRK(0x1849, 0x5892, "ASRock B150M", ALC892_FIXUP_ASROCK_MOBO), - SND_PCI_QUIRK(0x19da, 0xa130, "Zotac Z68", ALC662_FIXUP_ZOTAC_Z68), - SND_PCI_QUIRK(0x1b0a, 0x01b8, "ACER Veriton", ALC662_FIXUP_ACER_VERITON), - SND_PCI_QUIRK(0x1b35, 0x2206, "CZC P10T", ALC662_FIXUP_CZC_P10T), -diff --git a/sound/usb/quirks-table.h b/sound/usb/quirks-table.h -index c60a776..8a59d47 100644 ---- a/sound/usb/quirks-table.h -+++ b/sound/usb/quirks-table.h -@@ -2907,6 +2907,23 @@ AU0828_DEVICE(0x2040, 0x7260, "Hauppauge", "HVR-950Q"), - AU0828_DEVICE(0x2040, 0x7213, "Hauppauge", "HVR-950Q"), - AU0828_DEVICE(0x2040, 0x7270, "Hauppauge", "HVR-950Q"), - -+/* Syntek STK1160 */ -+{ -+ .match_flags = USB_DEVICE_ID_MATCH_DEVICE | -+ USB_DEVICE_ID_MATCH_INT_CLASS | -+ USB_DEVICE_ID_MATCH_INT_SUBCLASS, -+ .idVendor = 0x05e1, -+ .idProduct = 0x0408, -+ .bInterfaceClass = USB_CLASS_AUDIO, -+ .bInterfaceSubClass = USB_SUBCLASS_AUDIOCONTROL, -+ .driver_info = (unsigned long) &(const struct snd_usb_audio_quirk) { -+ .vendor_name = "Syntek", -+ .product_name = "STK1160", -+ .ifnum = QUIRK_ANY_INTERFACE, -+ .type = QUIRK_AUDIO_ALIGN_TRANSFER -+ } -+}, -+ - /* Digidesign Mbox */ - { - /* Thanks to Clemens Ladisch <clemens@ladisch.de> */ diff --git a/4.8.7/0000_README b/4.8.8/0000_README index 81b2200..59f6fd4 100644 --- a/4.8.7/0000_README +++ b/4.8.8/0000_README @@ -2,31 +2,11 @@ README ----------------------------------------------------------------------------- Individual Patch Descriptions: ----------------------------------------------------------------------------- -Patch: 1001_linux-4.8.2.patch +Patch: 1007_linux-4.8.8.patch From: http://www.kernel.org -Desc: Linux 4.8.2 +Desc: Linux 4.8.8 -Patch: 1002_linux-4.8.3.patch -From: http://www.kernel.org -Desc: Linux 4.8.3 - -Patch: 1003_linux-4.8.4.patch -From: http://www.kernel.org -Desc: Linux 4.8.4 - -Patch: 1004_linux-4.8.5.patch -From: http://www.kernel.org -Desc: Linux 4.8.5 - -Patch: 1005_linux-4.8.6.patch -From: http://www.kernel.org -Desc: Linux 4.8.6 - -Patch: 1006_linux-4.8.7.patch -From: http://www.kernel.org -Desc: Linux 4.8.7 - -Patch: 4420_grsecurity-3.1-4.8.7-201611102210.patch +Patch: 4420_grsecurity-3.1-4.8.8-201611150756.patch From: http://www.grsecurity.net Desc: hardened-sources base patch from upstream grsecurity diff --git a/4.8.8/1007_linux-4.8.8.patch b/4.8.8/1007_linux-4.8.8.patch new file mode 100644 index 0000000..35fb91c --- /dev/null +++ b/4.8.8/1007_linux-4.8.8.patch @@ -0,0 +1,1846 @@ +diff --git a/Makefile b/Makefile +index 4d0f28c..8f18daa 100644 +--- a/Makefile ++++ b/Makefile +@@ -1,6 +1,6 @@ + VERSION = 4 + PATCHLEVEL = 8 +-SUBLEVEL = 7 ++SUBLEVEL = 8 + EXTRAVERSION = + NAME = Psychotic Stoned Sheep + +diff --git a/arch/powerpc/include/asm/checksum.h b/arch/powerpc/include/asm/checksum.h +index ee655ed..1e8fceb 100644 +--- a/arch/powerpc/include/asm/checksum.h ++++ b/arch/powerpc/include/asm/checksum.h +@@ -53,10 +53,8 @@ static inline __sum16 csum_fold(__wsum sum) + return (__force __sum16)(~((__force u32)sum + tmp) >> 16); + } + +-static inline __wsum csum_tcpudp_nofold(__be32 saddr, __be32 daddr, +- unsigned short len, +- unsigned short proto, +- __wsum sum) ++static inline __wsum csum_tcpudp_nofold(__be32 saddr, __be32 daddr, __u32 len, ++ __u8 proto, __wsum sum) + { + #ifdef __powerpc64__ + unsigned long s = (__force u32)sum; +@@ -83,10 +81,8 @@ static inline __wsum csum_tcpudp_nofold(__be32 saddr, __be32 daddr, + * computes the checksum of the TCP/UDP pseudo-header + * returns a 16-bit checksum, already complemented + */ +-static inline __sum16 csum_tcpudp_magic(__be32 saddr, __be32 daddr, +- unsigned short len, +- unsigned short proto, +- __wsum sum) ++static inline __sum16 csum_tcpudp_magic(__be32 saddr, __be32 daddr, __u32 len, ++ __u8 proto, __wsum sum) + { + return csum_fold(csum_tcpudp_nofold(saddr, daddr, len, proto, sum)); + } +diff --git a/drivers/infiniband/ulp/ipoib/ipoib.h b/drivers/infiniband/ulp/ipoib/ipoib.h +index 9dbfcc0..5ff64af 100644 +--- a/drivers/infiniband/ulp/ipoib/ipoib.h ++++ b/drivers/infiniband/ulp/ipoib/ipoib.h +@@ -63,6 +63,8 @@ enum ipoib_flush_level { + + enum { + IPOIB_ENCAP_LEN = 4, ++ IPOIB_PSEUDO_LEN = 20, ++ IPOIB_HARD_LEN = IPOIB_ENCAP_LEN + IPOIB_PSEUDO_LEN, + + IPOIB_UD_HEAD_SIZE = IB_GRH_BYTES + IPOIB_ENCAP_LEN, + IPOIB_UD_RX_SG = 2, /* max buffer needed for 4K mtu */ +@@ -134,15 +136,21 @@ struct ipoib_header { + u16 reserved; + }; + +-struct ipoib_cb { +- struct qdisc_skb_cb qdisc_cb; +- u8 hwaddr[INFINIBAND_ALEN]; ++struct ipoib_pseudo_header { ++ u8 hwaddr[INFINIBAND_ALEN]; + }; + +-static inline struct ipoib_cb *ipoib_skb_cb(const struct sk_buff *skb) ++static inline void skb_add_pseudo_hdr(struct sk_buff *skb) + { +- BUILD_BUG_ON(sizeof(skb->cb) < sizeof(struct ipoib_cb)); +- return (struct ipoib_cb *)skb->cb; ++ char *data = skb_push(skb, IPOIB_PSEUDO_LEN); ++ ++ /* ++ * only the ipoib header is present now, make room for a dummy ++ * pseudo header and set skb field accordingly ++ */ ++ memset(data, 0, IPOIB_PSEUDO_LEN); ++ skb_reset_mac_header(skb); ++ skb_pull(skb, IPOIB_HARD_LEN); + } + + /* Used for all multicast joins (broadcast, IPv4 mcast and IPv6 mcast) */ +diff --git a/drivers/infiniband/ulp/ipoib/ipoib_cm.c b/drivers/infiniband/ulp/ipoib/ipoib_cm.c +index 4ad297d..339a1ee 100644 +--- a/drivers/infiniband/ulp/ipoib/ipoib_cm.c ++++ b/drivers/infiniband/ulp/ipoib/ipoib_cm.c +@@ -63,6 +63,8 @@ MODULE_PARM_DESC(cm_data_debug_level, + #define IPOIB_CM_RX_DELAY (3 * 256 * HZ) + #define IPOIB_CM_RX_UPDATE_MASK (0x3) + ++#define IPOIB_CM_RX_RESERVE (ALIGN(IPOIB_HARD_LEN, 16) - IPOIB_ENCAP_LEN) ++ + static struct ib_qp_attr ipoib_cm_err_attr = { + .qp_state = IB_QPS_ERR + }; +@@ -146,15 +148,15 @@ static struct sk_buff *ipoib_cm_alloc_rx_skb(struct net_device *dev, + struct sk_buff *skb; + int i; + +- skb = dev_alloc_skb(IPOIB_CM_HEAD_SIZE + 12); ++ skb = dev_alloc_skb(ALIGN(IPOIB_CM_HEAD_SIZE + IPOIB_PSEUDO_LEN, 16)); + if (unlikely(!skb)) + return NULL; + + /* +- * IPoIB adds a 4 byte header. So we need 12 more bytes to align the ++ * IPoIB adds a IPOIB_ENCAP_LEN byte header, this will align the + * IP header to a multiple of 16. + */ +- skb_reserve(skb, 12); ++ skb_reserve(skb, IPOIB_CM_RX_RESERVE); + + mapping[0] = ib_dma_map_single(priv->ca, skb->data, IPOIB_CM_HEAD_SIZE, + DMA_FROM_DEVICE); +@@ -624,9 +626,9 @@ void ipoib_cm_handle_rx_wc(struct net_device *dev, struct ib_wc *wc) + if (wc->byte_len < IPOIB_CM_COPYBREAK) { + int dlen = wc->byte_len; + +- small_skb = dev_alloc_skb(dlen + 12); ++ small_skb = dev_alloc_skb(dlen + IPOIB_CM_RX_RESERVE); + if (small_skb) { +- skb_reserve(small_skb, 12); ++ skb_reserve(small_skb, IPOIB_CM_RX_RESERVE); + ib_dma_sync_single_for_cpu(priv->ca, rx_ring[wr_id].mapping[0], + dlen, DMA_FROM_DEVICE); + skb_copy_from_linear_data(skb, small_skb->data, dlen); +@@ -663,8 +665,7 @@ void ipoib_cm_handle_rx_wc(struct net_device *dev, struct ib_wc *wc) + + copied: + skb->protocol = ((struct ipoib_header *) skb->data)->proto; +- skb_reset_mac_header(skb); +- skb_pull(skb, IPOIB_ENCAP_LEN); ++ skb_add_pseudo_hdr(skb); + + ++dev->stats.rx_packets; + dev->stats.rx_bytes += skb->len; +diff --git a/drivers/infiniband/ulp/ipoib/ipoib_ib.c b/drivers/infiniband/ulp/ipoib/ipoib_ib.c +index be11d5d..830fecb 100644 +--- a/drivers/infiniband/ulp/ipoib/ipoib_ib.c ++++ b/drivers/infiniband/ulp/ipoib/ipoib_ib.c +@@ -128,16 +128,15 @@ static struct sk_buff *ipoib_alloc_rx_skb(struct net_device *dev, int id) + + buf_size = IPOIB_UD_BUF_SIZE(priv->max_ib_mtu); + +- skb = dev_alloc_skb(buf_size + IPOIB_ENCAP_LEN); ++ skb = dev_alloc_skb(buf_size + IPOIB_HARD_LEN); + if (unlikely(!skb)) + return NULL; + + /* +- * IB will leave a 40 byte gap for a GRH and IPoIB adds a 4 byte +- * header. So we need 4 more bytes to get to 48 and align the +- * IP header to a multiple of 16. ++ * the IP header will be at IPOIP_HARD_LEN + IB_GRH_BYTES, that is ++ * 64 bytes aligned + */ +- skb_reserve(skb, 4); ++ skb_reserve(skb, sizeof(struct ipoib_pseudo_header)); + + mapping = priv->rx_ring[id].mapping; + mapping[0] = ib_dma_map_single(priv->ca, skb->data, buf_size, +@@ -253,8 +252,7 @@ static void ipoib_ib_handle_rx_wc(struct net_device *dev, struct ib_wc *wc) + skb_pull(skb, IB_GRH_BYTES); + + skb->protocol = ((struct ipoib_header *) skb->data)->proto; +- skb_reset_mac_header(skb); +- skb_pull(skb, IPOIB_ENCAP_LEN); ++ skb_add_pseudo_hdr(skb); + + ++dev->stats.rx_packets; + dev->stats.rx_bytes += skb->len; +diff --git a/drivers/infiniband/ulp/ipoib/ipoib_main.c b/drivers/infiniband/ulp/ipoib/ipoib_main.c +index cc1c1b0..823a528 100644 +--- a/drivers/infiniband/ulp/ipoib/ipoib_main.c ++++ b/drivers/infiniband/ulp/ipoib/ipoib_main.c +@@ -925,9 +925,12 @@ static void neigh_add_path(struct sk_buff *skb, u8 *daddr, + ipoib_neigh_free(neigh); + goto err_drop; + } +- if (skb_queue_len(&neigh->queue) < IPOIB_MAX_PATH_REC_QUEUE) ++ if (skb_queue_len(&neigh->queue) < ++ IPOIB_MAX_PATH_REC_QUEUE) { ++ /* put pseudoheader back on for next time */ ++ skb_push(skb, IPOIB_PSEUDO_LEN); + __skb_queue_tail(&neigh->queue, skb); +- else { ++ } else { + ipoib_warn(priv, "queue length limit %d. Packet drop.\n", + skb_queue_len(&neigh->queue)); + goto err_drop; +@@ -964,7 +967,7 @@ static void neigh_add_path(struct sk_buff *skb, u8 *daddr, + } + + static void unicast_arp_send(struct sk_buff *skb, struct net_device *dev, +- struct ipoib_cb *cb) ++ struct ipoib_pseudo_header *phdr) + { + struct ipoib_dev_priv *priv = netdev_priv(dev); + struct ipoib_path *path; +@@ -972,16 +975,18 @@ static void unicast_arp_send(struct sk_buff *skb, struct net_device *dev, + + spin_lock_irqsave(&priv->lock, flags); + +- path = __path_find(dev, cb->hwaddr + 4); ++ path = __path_find(dev, phdr->hwaddr + 4); + if (!path || !path->valid) { + int new_path = 0; + + if (!path) { +- path = path_rec_create(dev, cb->hwaddr + 4); ++ path = path_rec_create(dev, phdr->hwaddr + 4); + new_path = 1; + } + if (path) { + if (skb_queue_len(&path->queue) < IPOIB_MAX_PATH_REC_QUEUE) { ++ /* put pseudoheader back on for next time */ ++ skb_push(skb, IPOIB_PSEUDO_LEN); + __skb_queue_tail(&path->queue, skb); + } else { + ++dev->stats.tx_dropped; +@@ -1009,10 +1014,12 @@ static void unicast_arp_send(struct sk_buff *skb, struct net_device *dev, + be16_to_cpu(path->pathrec.dlid)); + + spin_unlock_irqrestore(&priv->lock, flags); +- ipoib_send(dev, skb, path->ah, IPOIB_QPN(cb->hwaddr)); ++ ipoib_send(dev, skb, path->ah, IPOIB_QPN(phdr->hwaddr)); + return; + } else if ((path->query || !path_rec_start(dev, path)) && + skb_queue_len(&path->queue) < IPOIB_MAX_PATH_REC_QUEUE) { ++ /* put pseudoheader back on for next time */ ++ skb_push(skb, IPOIB_PSEUDO_LEN); + __skb_queue_tail(&path->queue, skb); + } else { + ++dev->stats.tx_dropped; +@@ -1026,13 +1033,15 @@ static int ipoib_start_xmit(struct sk_buff *skb, struct net_device *dev) + { + struct ipoib_dev_priv *priv = netdev_priv(dev); + struct ipoib_neigh *neigh; +- struct ipoib_cb *cb = ipoib_skb_cb(skb); ++ struct ipoib_pseudo_header *phdr; + struct ipoib_header *header; + unsigned long flags; + ++ phdr = (struct ipoib_pseudo_header *) skb->data; ++ skb_pull(skb, sizeof(*phdr)); + header = (struct ipoib_header *) skb->data; + +- if (unlikely(cb->hwaddr[4] == 0xff)) { ++ if (unlikely(phdr->hwaddr[4] == 0xff)) { + /* multicast, arrange "if" according to probability */ + if ((header->proto != htons(ETH_P_IP)) && + (header->proto != htons(ETH_P_IPV6)) && +@@ -1045,13 +1054,13 @@ static int ipoib_start_xmit(struct sk_buff *skb, struct net_device *dev) + return NETDEV_TX_OK; + } + /* Add in the P_Key for multicast*/ +- cb->hwaddr[8] = (priv->pkey >> 8) & 0xff; +- cb->hwaddr[9] = priv->pkey & 0xff; ++ phdr->hwaddr[8] = (priv->pkey >> 8) & 0xff; ++ phdr->hwaddr[9] = priv->pkey & 0xff; + +- neigh = ipoib_neigh_get(dev, cb->hwaddr); ++ neigh = ipoib_neigh_get(dev, phdr->hwaddr); + if (likely(neigh)) + goto send_using_neigh; +- ipoib_mcast_send(dev, cb->hwaddr, skb); ++ ipoib_mcast_send(dev, phdr->hwaddr, skb); + return NETDEV_TX_OK; + } + +@@ -1060,16 +1069,16 @@ static int ipoib_start_xmit(struct sk_buff *skb, struct net_device *dev) + case htons(ETH_P_IP): + case htons(ETH_P_IPV6): + case htons(ETH_P_TIPC): +- neigh = ipoib_neigh_get(dev, cb->hwaddr); ++ neigh = ipoib_neigh_get(dev, phdr->hwaddr); + if (unlikely(!neigh)) { +- neigh_add_path(skb, cb->hwaddr, dev); ++ neigh_add_path(skb, phdr->hwaddr, dev); + return NETDEV_TX_OK; + } + break; + case htons(ETH_P_ARP): + case htons(ETH_P_RARP): + /* for unicast ARP and RARP should always perform path find */ +- unicast_arp_send(skb, dev, cb); ++ unicast_arp_send(skb, dev, phdr); + return NETDEV_TX_OK; + default: + /* ethertype not supported by IPoIB */ +@@ -1086,11 +1095,13 @@ static int ipoib_start_xmit(struct sk_buff *skb, struct net_device *dev) + goto unref; + } + } else if (neigh->ah) { +- ipoib_send(dev, skb, neigh->ah, IPOIB_QPN(cb->hwaddr)); ++ ipoib_send(dev, skb, neigh->ah, IPOIB_QPN(phdr->hwaddr)); + goto unref; + } + + if (skb_queue_len(&neigh->queue) < IPOIB_MAX_PATH_REC_QUEUE) { ++ /* put pseudoheader back on for next time */ ++ skb_push(skb, sizeof(*phdr)); + spin_lock_irqsave(&priv->lock, flags); + __skb_queue_tail(&neigh->queue, skb); + spin_unlock_irqrestore(&priv->lock, flags); +@@ -1122,8 +1133,8 @@ static int ipoib_hard_header(struct sk_buff *skb, + unsigned short type, + const void *daddr, const void *saddr, unsigned len) + { ++ struct ipoib_pseudo_header *phdr; + struct ipoib_header *header; +- struct ipoib_cb *cb = ipoib_skb_cb(skb); + + header = (struct ipoib_header *) skb_push(skb, sizeof *header); + +@@ -1132,12 +1143,13 @@ static int ipoib_hard_header(struct sk_buff *skb, + + /* + * we don't rely on dst_entry structure, always stuff the +- * destination address into skb->cb so we can figure out where ++ * destination address into skb hard header so we can figure out where + * to send the packet later. + */ +- memcpy(cb->hwaddr, daddr, INFINIBAND_ALEN); ++ phdr = (struct ipoib_pseudo_header *) skb_push(skb, sizeof(*phdr)); ++ memcpy(phdr->hwaddr, daddr, INFINIBAND_ALEN); + +- return sizeof *header; ++ return IPOIB_HARD_LEN; + } + + static void ipoib_set_mcast_list(struct net_device *dev) +@@ -1759,7 +1771,7 @@ void ipoib_setup(struct net_device *dev) + + dev->flags |= IFF_BROADCAST | IFF_MULTICAST; + +- dev->hard_header_len = IPOIB_ENCAP_LEN; ++ dev->hard_header_len = IPOIB_HARD_LEN; + dev->addr_len = INFINIBAND_ALEN; + dev->type = ARPHRD_INFINIBAND; + dev->tx_queue_len = ipoib_sendq_size * 2; +diff --git a/drivers/infiniband/ulp/ipoib/ipoib_multicast.c b/drivers/infiniband/ulp/ipoib/ipoib_multicast.c +index d3394b6..1909dd2 100644 +--- a/drivers/infiniband/ulp/ipoib/ipoib_multicast.c ++++ b/drivers/infiniband/ulp/ipoib/ipoib_multicast.c +@@ -796,9 +796,11 @@ void ipoib_mcast_send(struct net_device *dev, u8 *daddr, struct sk_buff *skb) + __ipoib_mcast_add(dev, mcast); + list_add_tail(&mcast->list, &priv->multicast_list); + } +- if (skb_queue_len(&mcast->pkt_queue) < IPOIB_MAX_MCAST_QUEUE) ++ if (skb_queue_len(&mcast->pkt_queue) < IPOIB_MAX_MCAST_QUEUE) { ++ /* put pseudoheader back on for next time */ ++ skb_push(skb, sizeof(struct ipoib_pseudo_header)); + skb_queue_tail(&mcast->pkt_queue, skb); +- else { ++ } else { + ++dev->stats.tx_dropped; + dev_kfree_skb_any(skb); + } +diff --git a/drivers/net/ethernet/freescale/fec_main.c b/drivers/net/ethernet/freescale/fec_main.c +index 692ee24..3474de5 100644 +--- a/drivers/net/ethernet/freescale/fec_main.c ++++ b/drivers/net/ethernet/freescale/fec_main.c +@@ -913,13 +913,11 @@ fec_restart(struct net_device *ndev) + * enet-mac reset will reset mac address registers too, + * so need to reconfigure it. + */ +- if (fep->quirks & FEC_QUIRK_ENET_MAC) { +- memcpy(&temp_mac, ndev->dev_addr, ETH_ALEN); +- writel((__force u32)cpu_to_be32(temp_mac[0]), +- fep->hwp + FEC_ADDR_LOW); +- writel((__force u32)cpu_to_be32(temp_mac[1]), +- fep->hwp + FEC_ADDR_HIGH); +- } ++ memcpy(&temp_mac, ndev->dev_addr, ETH_ALEN); ++ writel((__force u32)cpu_to_be32(temp_mac[0]), ++ fep->hwp + FEC_ADDR_LOW); ++ writel((__force u32)cpu_to_be32(temp_mac[1]), ++ fep->hwp + FEC_ADDR_HIGH); + + /* Clear any outstanding interrupt. */ + writel(0xffffffff, fep->hwp + FEC_IEVENT); +@@ -1432,14 +1430,14 @@ fec_enet_rx_queue(struct net_device *ndev, int budget, u16 queue_id) + skb_put(skb, pkt_len - 4); + data = skb->data; + ++ if (!is_copybreak && need_swap) ++ swap_buffer(data, pkt_len); ++ + #if !defined(CONFIG_M5272) + if (fep->quirks & FEC_QUIRK_HAS_RACC) + data = skb_pull_inline(skb, 2); + #endif + +- if (!is_copybreak && need_swap) +- swap_buffer(data, pkt_len); +- + /* Extract the enhanced buffer descriptor */ + ebdp = NULL; + if (fep->bufdesc_ex) +diff --git a/drivers/net/ethernet/mellanox/mlx4/en_cq.c b/drivers/net/ethernet/mellanox/mlx4/en_cq.c +index 132cea6..e3be7e4 100644 +--- a/drivers/net/ethernet/mellanox/mlx4/en_cq.c ++++ b/drivers/net/ethernet/mellanox/mlx4/en_cq.c +@@ -127,7 +127,15 @@ int mlx4_en_activate_cq(struct mlx4_en_priv *priv, struct mlx4_en_cq *cq, + /* For TX we use the same irq per + ring we assigned for the RX */ + struct mlx4_en_cq *rx_cq; +- ++ int xdp_index; ++ ++ /* The xdp tx irq must align with the rx ring that forwards to ++ * it, so reindex these from 0. This should only happen when ++ * tx_ring_num is not a multiple of rx_ring_num. ++ */ ++ xdp_index = (priv->xdp_ring_num - priv->tx_ring_num) + cq_idx; ++ if (xdp_index >= 0) ++ cq_idx = xdp_index; + cq_idx = cq_idx % priv->rx_ring_num; + rx_cq = priv->rx_cq[cq_idx]; + cq->vector = rx_cq->vector; +diff --git a/drivers/net/geneve.c b/drivers/net/geneve.c +index 3c20e87..16af1ce 100644 +--- a/drivers/net/geneve.c ++++ b/drivers/net/geneve.c +@@ -453,7 +453,7 @@ static struct sk_buff **geneve_gro_receive(struct sock *sk, + + skb_gro_pull(skb, gh_len); + skb_gro_postpull_rcsum(skb, gh, gh_len); +- pp = ptype->callbacks.gro_receive(head, skb); ++ pp = call_gro_receive(ptype->callbacks.gro_receive, head, skb); + flush = 0; + + out_unlock: +diff --git a/drivers/net/hyperv/netvsc_drv.c b/drivers/net/hyperv/netvsc_drv.c +index 3ba29fc..c4d9653 100644 +--- a/drivers/net/hyperv/netvsc_drv.c ++++ b/drivers/net/hyperv/netvsc_drv.c +@@ -624,15 +624,18 @@ static struct sk_buff *netvsc_alloc_recv_skb(struct net_device *net, + packet->total_data_buflen); + + skb->protocol = eth_type_trans(skb, net); +- if (csum_info) { +- /* We only look at the IP checksum here. +- * Should we be dropping the packet if checksum +- * failed? How do we deal with other checksums - TCP/UDP? +- */ +- if (csum_info->receive.ip_checksum_succeeded) ++ ++ /* skb is already created with CHECKSUM_NONE */ ++ skb_checksum_none_assert(skb); ++ ++ /* ++ * In Linux, the IP checksum is always checked. ++ * Do L4 checksum offload if enabled and present. ++ */ ++ if (csum_info && (net->features & NETIF_F_RXCSUM)) { ++ if (csum_info->receive.tcp_checksum_succeeded || ++ csum_info->receive.udp_checksum_succeeded) + skb->ip_summed = CHECKSUM_UNNECESSARY; +- else +- skb->ip_summed = CHECKSUM_NONE; + } + + if (vlan_tci & VLAN_TAG_PRESENT) +diff --git a/drivers/net/macsec.c b/drivers/net/macsec.c +index 351e701..b72ddc6 100644 +--- a/drivers/net/macsec.c ++++ b/drivers/net/macsec.c +@@ -397,6 +397,14 @@ static struct macsec_cb *macsec_skb_cb(struct sk_buff *skb) + #define DEFAULT_ENCRYPT false + #define DEFAULT_ENCODING_SA 0 + ++static bool send_sci(const struct macsec_secy *secy) ++{ ++ const struct macsec_tx_sc *tx_sc = &secy->tx_sc; ++ ++ return tx_sc->send_sci || ++ (secy->n_rx_sc > 1 && !tx_sc->end_station && !tx_sc->scb); ++} ++ + static sci_t make_sci(u8 *addr, __be16 port) + { + sci_t sci; +@@ -437,15 +445,15 @@ static unsigned int macsec_extra_len(bool sci_present) + + /* Fill SecTAG according to IEEE 802.1AE-2006 10.5.3 */ + static void macsec_fill_sectag(struct macsec_eth_header *h, +- const struct macsec_secy *secy, u32 pn) ++ const struct macsec_secy *secy, u32 pn, ++ bool sci_present) + { + const struct macsec_tx_sc *tx_sc = &secy->tx_sc; + +- memset(&h->tci_an, 0, macsec_sectag_len(tx_sc->send_sci)); ++ memset(&h->tci_an, 0, macsec_sectag_len(sci_present)); + h->eth.h_proto = htons(ETH_P_MACSEC); + +- if (tx_sc->send_sci || +- (secy->n_rx_sc > 1 && !tx_sc->end_station && !tx_sc->scb)) { ++ if (sci_present) { + h->tci_an |= MACSEC_TCI_SC; + memcpy(&h->secure_channel_id, &secy->sci, + sizeof(h->secure_channel_id)); +@@ -650,6 +658,7 @@ static struct sk_buff *macsec_encrypt(struct sk_buff *skb, + struct macsec_tx_sc *tx_sc; + struct macsec_tx_sa *tx_sa; + struct macsec_dev *macsec = macsec_priv(dev); ++ bool sci_present; + u32 pn; + + secy = &macsec->secy; +@@ -687,7 +696,8 @@ static struct sk_buff *macsec_encrypt(struct sk_buff *skb, + + unprotected_len = skb->len; + eth = eth_hdr(skb); +- hh = (struct macsec_eth_header *)skb_push(skb, macsec_extra_len(tx_sc->send_sci)); ++ sci_present = send_sci(secy); ++ hh = (struct macsec_eth_header *)skb_push(skb, macsec_extra_len(sci_present)); + memmove(hh, eth, 2 * ETH_ALEN); + + pn = tx_sa_update_pn(tx_sa, secy); +@@ -696,7 +706,7 @@ static struct sk_buff *macsec_encrypt(struct sk_buff *skb, + kfree_skb(skb); + return ERR_PTR(-ENOLINK); + } +- macsec_fill_sectag(hh, secy, pn); ++ macsec_fill_sectag(hh, secy, pn, sci_present); + macsec_set_shortlen(hh, unprotected_len - 2 * ETH_ALEN); + + skb_put(skb, secy->icv_len); +@@ -726,10 +736,10 @@ static struct sk_buff *macsec_encrypt(struct sk_buff *skb, + skb_to_sgvec(skb, sg, 0, skb->len); + + if (tx_sc->encrypt) { +- int len = skb->len - macsec_hdr_len(tx_sc->send_sci) - ++ int len = skb->len - macsec_hdr_len(sci_present) - + secy->icv_len; + aead_request_set_crypt(req, sg, sg, len, iv); +- aead_request_set_ad(req, macsec_hdr_len(tx_sc->send_sci)); ++ aead_request_set_ad(req, macsec_hdr_len(sci_present)); + } else { + aead_request_set_crypt(req, sg, sg, 0, iv); + aead_request_set_ad(req, skb->len - secy->icv_len); +diff --git a/drivers/net/phy/phy.c b/drivers/net/phy/phy.c +index c6f6683..f424b86 100644 +--- a/drivers/net/phy/phy.c ++++ b/drivers/net/phy/phy.c +@@ -608,6 +608,21 @@ void phy_start_machine(struct phy_device *phydev) + } + + /** ++ * phy_trigger_machine - trigger the state machine to run ++ * ++ * @phydev: the phy_device struct ++ * ++ * Description: There has been a change in state which requires that the ++ * state machine runs. ++ */ ++ ++static void phy_trigger_machine(struct phy_device *phydev) ++{ ++ cancel_delayed_work_sync(&phydev->state_queue); ++ queue_delayed_work(system_power_efficient_wq, &phydev->state_queue, 0); ++} ++ ++/** + * phy_stop_machine - stop the PHY state machine tracking + * @phydev: target phy_device struct + * +@@ -639,6 +654,8 @@ static void phy_error(struct phy_device *phydev) + mutex_lock(&phydev->lock); + phydev->state = PHY_HALTED; + mutex_unlock(&phydev->lock); ++ ++ phy_trigger_machine(phydev); + } + + /** +@@ -800,8 +817,7 @@ void phy_change(struct work_struct *work) + } + + /* reschedule state queue work to run as soon as possible */ +- cancel_delayed_work_sync(&phydev->state_queue); +- queue_delayed_work(system_power_efficient_wq, &phydev->state_queue, 0); ++ phy_trigger_machine(phydev); + return; + + ignore: +@@ -890,6 +906,8 @@ void phy_start(struct phy_device *phydev) + /* if phy was suspended, bring the physical link up again */ + if (do_resume) + phy_resume(phydev); ++ ++ phy_trigger_machine(phydev); + } + EXPORT_SYMBOL(phy_start); + +diff --git a/drivers/net/vxlan.c b/drivers/net/vxlan.c +index 6e65832..5ae664c 100644 +--- a/drivers/net/vxlan.c ++++ b/drivers/net/vxlan.c +@@ -584,7 +584,7 @@ static struct sk_buff **vxlan_gro_receive(struct sock *sk, + } + } + +- pp = eth_gro_receive(head, skb); ++ pp = call_gro_receive(eth_gro_receive, head, skb); + flush = 0; + + out: +diff --git a/drivers/ptp/ptp_chardev.c b/drivers/ptp/ptp_chardev.c +index d637c93..58a97d4 100644 +--- a/drivers/ptp/ptp_chardev.c ++++ b/drivers/ptp/ptp_chardev.c +@@ -193,6 +193,7 @@ long ptp_ioctl(struct posix_clock *pc, unsigned int cmd, unsigned long arg) + if (err) + break; + ++ memset(&precise_offset, 0, sizeof(precise_offset)); + ts = ktime_to_timespec64(xtstamp.device); + precise_offset.device.sec = ts.tv_sec; + precise_offset.device.nsec = ts.tv_nsec; +diff --git a/drivers/scsi/megaraid/megaraid_sas.h b/drivers/scsi/megaraid/megaraid_sas.h +index ca86c88..3aaea71 100644 +--- a/drivers/scsi/megaraid/megaraid_sas.h ++++ b/drivers/scsi/megaraid/megaraid_sas.h +@@ -2233,7 +2233,7 @@ struct megasas_instance_template { + }; + + #define MEGASAS_IS_LOGICAL(scp) \ +- (scp->device->channel < MEGASAS_MAX_PD_CHANNELS) ? 0 : 1 ++ ((scp->device->channel < MEGASAS_MAX_PD_CHANNELS) ? 0 : 1) + + #define MEGASAS_DEV_INDEX(scp) \ + (((scp->device->channel % 2) * MEGASAS_MAX_DEV_PER_CHANNEL) + \ +diff --git a/drivers/scsi/megaraid/megaraid_sas_base.c b/drivers/scsi/megaraid/megaraid_sas_base.c +index c1ed25a..71e4899 100644 +--- a/drivers/scsi/megaraid/megaraid_sas_base.c ++++ b/drivers/scsi/megaraid/megaraid_sas_base.c +@@ -1713,16 +1713,13 @@ megasas_queue_command(struct Scsi_Host *shost, struct scsi_cmnd *scmd) + goto out_done; + } + +- switch (scmd->cmnd[0]) { +- case SYNCHRONIZE_CACHE: +- /* +- * FW takes care of flush cache on its own +- * No need to send it down +- */ ++ /* ++ * FW takes care of flush cache on its own for Virtual Disk. ++ * No need to send it down for VD. For JBOD send SYNCHRONIZE_CACHE to FW. ++ */ ++ if ((scmd->cmnd[0] == SYNCHRONIZE_CACHE) && MEGASAS_IS_LOGICAL(scmd)) { + scmd->result = DID_OK << 16; + goto out_done; +- default: +- break; + } + + return instance->instancet->build_and_issue_cmd(instance, scmd); +diff --git a/drivers/usb/dwc3/gadget.c b/drivers/usb/dwc3/gadget.c +index 6443cfb..dc3b596 100644 +--- a/drivers/usb/dwc3/gadget.c ++++ b/drivers/usb/dwc3/gadget.c +@@ -789,6 +789,7 @@ static void dwc3_prepare_one_trb(struct dwc3_ep *dep, + req->trb = trb; + req->trb_dma = dwc3_trb_dma_offset(dep, trb); + req->first_trb_index = dep->trb_enqueue; ++ dep->queued_requests++; + } + + dwc3_ep_inc_enq(dep); +@@ -841,8 +842,6 @@ static void dwc3_prepare_one_trb(struct dwc3_ep *dep, + + trb->ctrl |= DWC3_TRB_CTRL_HWO; + +- dep->queued_requests++; +- + trace_dwc3_prepare_trb(dep, trb); + } + +@@ -1963,7 +1962,9 @@ static int __dwc3_cleanup_done_trbs(struct dwc3 *dwc, struct dwc3_ep *dep, + unsigned int s_pkt = 0; + unsigned int trb_status; + +- dep->queued_requests--; ++ if (req->trb == trb) ++ dep->queued_requests--; ++ + trace_dwc3_complete_trb(dep, trb); + + /* +diff --git a/include/linux/netdevice.h b/include/linux/netdevice.h +index e8d79d4..e942c67 100644 +--- a/include/linux/netdevice.h ++++ b/include/linux/netdevice.h +@@ -2154,7 +2154,10 @@ struct napi_gro_cb { + /* Used to determine if flush_id can be ignored */ + u8 is_atomic:1; + +- /* 5 bit hole */ ++ /* Number of gro_receive callbacks this packet already went through */ ++ u8 recursion_counter:4; ++ ++ /* 1 bit hole */ + + /* used to support CHECKSUM_COMPLETE for tunneling protocols */ + __wsum csum; +@@ -2165,6 +2168,40 @@ struct napi_gro_cb { + + #define NAPI_GRO_CB(skb) ((struct napi_gro_cb *)(skb)->cb) + ++#define GRO_RECURSION_LIMIT 15 ++static inline int gro_recursion_inc_test(struct sk_buff *skb) ++{ ++ return ++NAPI_GRO_CB(skb)->recursion_counter == GRO_RECURSION_LIMIT; ++} ++ ++typedef struct sk_buff **(*gro_receive_t)(struct sk_buff **, struct sk_buff *); ++static inline struct sk_buff **call_gro_receive(gro_receive_t cb, ++ struct sk_buff **head, ++ struct sk_buff *skb) ++{ ++ if (unlikely(gro_recursion_inc_test(skb))) { ++ NAPI_GRO_CB(skb)->flush |= 1; ++ return NULL; ++ } ++ ++ return cb(head, skb); ++} ++ ++typedef struct sk_buff **(*gro_receive_sk_t)(struct sock *, struct sk_buff **, ++ struct sk_buff *); ++static inline struct sk_buff **call_gro_receive_sk(gro_receive_sk_t cb, ++ struct sock *sk, ++ struct sk_buff **head, ++ struct sk_buff *skb) ++{ ++ if (unlikely(gro_recursion_inc_test(skb))) { ++ NAPI_GRO_CB(skb)->flush |= 1; ++ return NULL; ++ } ++ ++ return cb(sk, head, skb); ++} ++ + struct packet_type { + __be16 type; /* This is really htons(ether_type). */ + struct net_device *dev; /* NULL is wildcarded here */ +@@ -3862,7 +3899,7 @@ struct net_device *netdev_all_lower_get_next_rcu(struct net_device *dev, + ldev = netdev_all_lower_get_next(dev, &(iter))) + + #define netdev_for_each_all_lower_dev_rcu(dev, ldev, iter) \ +- for (iter = (dev)->all_adj_list.lower.next, \ ++ for (iter = &(dev)->all_adj_list.lower, \ + ldev = netdev_all_lower_get_next_rcu(dev, &(iter)); \ + ldev; \ + ldev = netdev_all_lower_get_next_rcu(dev, &(iter))) +diff --git a/include/net/ip.h b/include/net/ip.h +index 9742b92..156b0c1 100644 +--- a/include/net/ip.h ++++ b/include/net/ip.h +@@ -549,7 +549,7 @@ int ip_options_rcv_srr(struct sk_buff *skb); + */ + + void ipv4_pktinfo_prepare(const struct sock *sk, struct sk_buff *skb); +-void ip_cmsg_recv_offset(struct msghdr *msg, struct sk_buff *skb, int offset); ++void ip_cmsg_recv_offset(struct msghdr *msg, struct sk_buff *skb, int tlen, int offset); + int ip_cmsg_send(struct sock *sk, struct msghdr *msg, + struct ipcm_cookie *ipc, bool allow_ipv6); + int ip_setsockopt(struct sock *sk, int level, int optname, char __user *optval, +@@ -571,7 +571,7 @@ void ip_local_error(struct sock *sk, int err, __be32 daddr, __be16 dport, + + static inline void ip_cmsg_recv(struct msghdr *msg, struct sk_buff *skb) + { +- ip_cmsg_recv_offset(msg, skb, 0); ++ ip_cmsg_recv_offset(msg, skb, 0, 0); + } + + bool icmp_global_allow(void); +diff --git a/include/net/ip6_route.h b/include/net/ip6_route.h +index d97305d..0a2d270 100644 +--- a/include/net/ip6_route.h ++++ b/include/net/ip6_route.h +@@ -32,6 +32,7 @@ struct route_info { + #define RT6_LOOKUP_F_SRCPREF_TMP 0x00000008 + #define RT6_LOOKUP_F_SRCPREF_PUBLIC 0x00000010 + #define RT6_LOOKUP_F_SRCPREF_COA 0x00000020 ++#define RT6_LOOKUP_F_IGNORE_LINKSTATE 0x00000040 + + /* We do not (yet ?) support IPv6 jumbograms (RFC 2675) + * Unlike IPv4, hdr->seg_len doesn't include the IPv6 header +diff --git a/include/uapi/linux/rtnetlink.h b/include/uapi/linux/rtnetlink.h +index 262f037..5a78be5 100644 +--- a/include/uapi/linux/rtnetlink.h ++++ b/include/uapi/linux/rtnetlink.h +@@ -350,7 +350,7 @@ struct rtnexthop { + #define RTNH_F_OFFLOAD 8 /* offloaded route */ + #define RTNH_F_LINKDOWN 16 /* carrier-down on nexthop */ + +-#define RTNH_COMPARE_MASK (RTNH_F_DEAD | RTNH_F_LINKDOWN) ++#define RTNH_COMPARE_MASK (RTNH_F_DEAD | RTNH_F_LINKDOWN | RTNH_F_OFFLOAD) + + /* Macros to handle hexthops */ + +diff --git a/net/8021q/vlan.c b/net/8021q/vlan.c +index 8de138d..f2531ad 100644 +--- a/net/8021q/vlan.c ++++ b/net/8021q/vlan.c +@@ -664,7 +664,7 @@ static struct sk_buff **vlan_gro_receive(struct sk_buff **head, + + skb_gro_pull(skb, sizeof(*vhdr)); + skb_gro_postpull_rcsum(skb, vhdr, sizeof(*vhdr)); +- pp = ptype->callbacks.gro_receive(head, skb); ++ pp = call_gro_receive(ptype->callbacks.gro_receive, head, skb); + + out_unlock: + rcu_read_unlock(); +diff --git a/net/bridge/br_multicast.c b/net/bridge/br_multicast.c +index c5fea93..2136e45 100644 +--- a/net/bridge/br_multicast.c ++++ b/net/bridge/br_multicast.c +@@ -972,13 +972,12 @@ static void br_multicast_enable(struct bridge_mcast_own_query *query) + mod_timer(&query->timer, jiffies); + } + +-void br_multicast_enable_port(struct net_bridge_port *port) ++static void __br_multicast_enable_port(struct net_bridge_port *port) + { + struct net_bridge *br = port->br; + +- spin_lock(&br->multicast_lock); + if (br->multicast_disabled || !netif_running(br->dev)) +- goto out; ++ return; + + br_multicast_enable(&port->ip4_own_query); + #if IS_ENABLED(CONFIG_IPV6) +@@ -987,8 +986,14 @@ void br_multicast_enable_port(struct net_bridge_port *port) + if (port->multicast_router == MDB_RTR_TYPE_PERM && + hlist_unhashed(&port->rlist)) + br_multicast_add_router(br, port); ++} + +-out: ++void br_multicast_enable_port(struct net_bridge_port *port) ++{ ++ struct net_bridge *br = port->br; ++ ++ spin_lock(&br->multicast_lock); ++ __br_multicast_enable_port(port); + spin_unlock(&br->multicast_lock); + } + +@@ -1994,8 +1999,9 @@ static void br_multicast_start_querier(struct net_bridge *br, + + int br_multicast_toggle(struct net_bridge *br, unsigned long val) + { +- int err = 0; + struct net_bridge_mdb_htable *mdb; ++ struct net_bridge_port *port; ++ int err = 0; + + spin_lock_bh(&br->multicast_lock); + if (br->multicast_disabled == !val) +@@ -2023,10 +2029,9 @@ int br_multicast_toggle(struct net_bridge *br, unsigned long val) + goto rollback; + } + +- br_multicast_start_querier(br, &br->ip4_own_query); +-#if IS_ENABLED(CONFIG_IPV6) +- br_multicast_start_querier(br, &br->ip6_own_query); +-#endif ++ br_multicast_open(br); ++ list_for_each_entry(port, &br->port_list, list) ++ __br_multicast_enable_port(port); + + unlock: + spin_unlock_bh(&br->multicast_lock); +diff --git a/net/core/dev.c b/net/core/dev.c +index ea63120..44b3ba4 100644 +--- a/net/core/dev.c ++++ b/net/core/dev.c +@@ -3035,6 +3035,7 @@ struct sk_buff *validate_xmit_skb_list(struct sk_buff *skb, struct net_device *d + } + return head; + } ++EXPORT_SYMBOL_GPL(validate_xmit_skb_list); + + static void qdisc_pkt_len_init(struct sk_buff *skb) + { +@@ -4496,6 +4497,7 @@ static enum gro_result dev_gro_receive(struct napi_struct *napi, struct sk_buff + NAPI_GRO_CB(skb)->flush = 0; + NAPI_GRO_CB(skb)->free = 0; + NAPI_GRO_CB(skb)->encap_mark = 0; ++ NAPI_GRO_CB(skb)->recursion_counter = 0; + NAPI_GRO_CB(skb)->is_fou = 0; + NAPI_GRO_CB(skb)->is_atomic = 1; + NAPI_GRO_CB(skb)->gro_remcsum_start = 0; +@@ -5500,10 +5502,14 @@ struct net_device *netdev_all_lower_get_next_rcu(struct net_device *dev, + { + struct netdev_adjacent *lower; + +- lower = list_first_or_null_rcu(&dev->all_adj_list.lower, +- struct netdev_adjacent, list); ++ lower = list_entry_rcu((*iter)->next, struct netdev_adjacent, list); ++ ++ if (&lower->list == &dev->all_adj_list.lower) ++ return NULL; ++ ++ *iter = &lower->list; + +- return lower ? lower->dev : NULL; ++ return lower->dev; + } + EXPORT_SYMBOL(netdev_all_lower_get_next_rcu); + +@@ -5578,6 +5584,7 @@ static inline bool netdev_adjacent_is_neigh_list(struct net_device *dev, + + static int __netdev_adjacent_dev_insert(struct net_device *dev, + struct net_device *adj_dev, ++ u16 ref_nr, + struct list_head *dev_list, + void *private, bool master) + { +@@ -5587,7 +5594,7 @@ static int __netdev_adjacent_dev_insert(struct net_device *dev, + adj = __netdev_find_adj(adj_dev, dev_list); + + if (adj) { +- adj->ref_nr++; ++ adj->ref_nr += ref_nr; + return 0; + } + +@@ -5597,7 +5604,7 @@ static int __netdev_adjacent_dev_insert(struct net_device *dev, + + adj->dev = adj_dev; + adj->master = master; +- adj->ref_nr = 1; ++ adj->ref_nr = ref_nr; + adj->private = private; + dev_hold(adj_dev); + +@@ -5636,6 +5643,7 @@ static int __netdev_adjacent_dev_insert(struct net_device *dev, + + static void __netdev_adjacent_dev_remove(struct net_device *dev, + struct net_device *adj_dev, ++ u16 ref_nr, + struct list_head *dev_list) + { + struct netdev_adjacent *adj; +@@ -5648,10 +5656,10 @@ static void __netdev_adjacent_dev_remove(struct net_device *dev, + BUG(); + } + +- if (adj->ref_nr > 1) { +- pr_debug("%s to %s ref_nr-- = %d\n", dev->name, adj_dev->name, +- adj->ref_nr-1); +- adj->ref_nr--; ++ if (adj->ref_nr > ref_nr) { ++ pr_debug("%s to %s ref_nr-%d = %d\n", dev->name, adj_dev->name, ++ ref_nr, adj->ref_nr-ref_nr); ++ adj->ref_nr -= ref_nr; + return; + } + +@@ -5670,21 +5678,22 @@ static void __netdev_adjacent_dev_remove(struct net_device *dev, + + static int __netdev_adjacent_dev_link_lists(struct net_device *dev, + struct net_device *upper_dev, ++ u16 ref_nr, + struct list_head *up_list, + struct list_head *down_list, + void *private, bool master) + { + int ret; + +- ret = __netdev_adjacent_dev_insert(dev, upper_dev, up_list, private, +- master); ++ ret = __netdev_adjacent_dev_insert(dev, upper_dev, ref_nr, up_list, ++ private, master); + if (ret) + return ret; + +- ret = __netdev_adjacent_dev_insert(upper_dev, dev, down_list, private, +- false); ++ ret = __netdev_adjacent_dev_insert(upper_dev, dev, ref_nr, down_list, ++ private, false); + if (ret) { +- __netdev_adjacent_dev_remove(dev, upper_dev, up_list); ++ __netdev_adjacent_dev_remove(dev, upper_dev, ref_nr, up_list); + return ret; + } + +@@ -5692,9 +5701,10 @@ static int __netdev_adjacent_dev_link_lists(struct net_device *dev, + } + + static int __netdev_adjacent_dev_link(struct net_device *dev, +- struct net_device *upper_dev) ++ struct net_device *upper_dev, ++ u16 ref_nr) + { +- return __netdev_adjacent_dev_link_lists(dev, upper_dev, ++ return __netdev_adjacent_dev_link_lists(dev, upper_dev, ref_nr, + &dev->all_adj_list.upper, + &upper_dev->all_adj_list.lower, + NULL, false); +@@ -5702,17 +5712,19 @@ static int __netdev_adjacent_dev_link(struct net_device *dev, + + static void __netdev_adjacent_dev_unlink_lists(struct net_device *dev, + struct net_device *upper_dev, ++ u16 ref_nr, + struct list_head *up_list, + struct list_head *down_list) + { +- __netdev_adjacent_dev_remove(dev, upper_dev, up_list); +- __netdev_adjacent_dev_remove(upper_dev, dev, down_list); ++ __netdev_adjacent_dev_remove(dev, upper_dev, ref_nr, up_list); ++ __netdev_adjacent_dev_remove(upper_dev, dev, ref_nr, down_list); + } + + static void __netdev_adjacent_dev_unlink(struct net_device *dev, +- struct net_device *upper_dev) ++ struct net_device *upper_dev, ++ u16 ref_nr) + { +- __netdev_adjacent_dev_unlink_lists(dev, upper_dev, ++ __netdev_adjacent_dev_unlink_lists(dev, upper_dev, ref_nr, + &dev->all_adj_list.upper, + &upper_dev->all_adj_list.lower); + } +@@ -5721,17 +5733,17 @@ static int __netdev_adjacent_dev_link_neighbour(struct net_device *dev, + struct net_device *upper_dev, + void *private, bool master) + { +- int ret = __netdev_adjacent_dev_link(dev, upper_dev); ++ int ret = __netdev_adjacent_dev_link(dev, upper_dev, 1); + + if (ret) + return ret; + +- ret = __netdev_adjacent_dev_link_lists(dev, upper_dev, ++ ret = __netdev_adjacent_dev_link_lists(dev, upper_dev, 1, + &dev->adj_list.upper, + &upper_dev->adj_list.lower, + private, master); + if (ret) { +- __netdev_adjacent_dev_unlink(dev, upper_dev); ++ __netdev_adjacent_dev_unlink(dev, upper_dev, 1); + return ret; + } + +@@ -5741,8 +5753,8 @@ static int __netdev_adjacent_dev_link_neighbour(struct net_device *dev, + static void __netdev_adjacent_dev_unlink_neighbour(struct net_device *dev, + struct net_device *upper_dev) + { +- __netdev_adjacent_dev_unlink(dev, upper_dev); +- __netdev_adjacent_dev_unlink_lists(dev, upper_dev, ++ __netdev_adjacent_dev_unlink(dev, upper_dev, 1); ++ __netdev_adjacent_dev_unlink_lists(dev, upper_dev, 1, + &dev->adj_list.upper, + &upper_dev->adj_list.lower); + } +@@ -5795,7 +5807,7 @@ static int __netdev_upper_dev_link(struct net_device *dev, + list_for_each_entry(j, &upper_dev->all_adj_list.upper, list) { + pr_debug("Interlinking %s with %s, non-neighbour\n", + i->dev->name, j->dev->name); +- ret = __netdev_adjacent_dev_link(i->dev, j->dev); ++ ret = __netdev_adjacent_dev_link(i->dev, j->dev, i->ref_nr); + if (ret) + goto rollback_mesh; + } +@@ -5805,7 +5817,7 @@ static int __netdev_upper_dev_link(struct net_device *dev, + list_for_each_entry(i, &upper_dev->all_adj_list.upper, list) { + pr_debug("linking %s's upper device %s with %s\n", + upper_dev->name, i->dev->name, dev->name); +- ret = __netdev_adjacent_dev_link(dev, i->dev); ++ ret = __netdev_adjacent_dev_link(dev, i->dev, i->ref_nr); + if (ret) + goto rollback_upper_mesh; + } +@@ -5814,7 +5826,7 @@ static int __netdev_upper_dev_link(struct net_device *dev, + list_for_each_entry(i, &dev->all_adj_list.lower, list) { + pr_debug("linking %s's lower device %s with %s\n", dev->name, + i->dev->name, upper_dev->name); +- ret = __netdev_adjacent_dev_link(i->dev, upper_dev); ++ ret = __netdev_adjacent_dev_link(i->dev, upper_dev, i->ref_nr); + if (ret) + goto rollback_lower_mesh; + } +@@ -5832,7 +5844,7 @@ static int __netdev_upper_dev_link(struct net_device *dev, + list_for_each_entry(i, &dev->all_adj_list.lower, list) { + if (i == to_i) + break; +- __netdev_adjacent_dev_unlink(i->dev, upper_dev); ++ __netdev_adjacent_dev_unlink(i->dev, upper_dev, i->ref_nr); + } + + i = NULL; +@@ -5842,7 +5854,7 @@ static int __netdev_upper_dev_link(struct net_device *dev, + list_for_each_entry(i, &upper_dev->all_adj_list.upper, list) { + if (i == to_i) + break; +- __netdev_adjacent_dev_unlink(dev, i->dev); ++ __netdev_adjacent_dev_unlink(dev, i->dev, i->ref_nr); + } + + i = j = NULL; +@@ -5854,7 +5866,7 @@ static int __netdev_upper_dev_link(struct net_device *dev, + list_for_each_entry(j, &upper_dev->all_adj_list.upper, list) { + if (i == to_i && j == to_j) + break; +- __netdev_adjacent_dev_unlink(i->dev, j->dev); ++ __netdev_adjacent_dev_unlink(i->dev, j->dev, i->ref_nr); + } + if (i == to_i) + break; +@@ -5934,16 +5946,16 @@ void netdev_upper_dev_unlink(struct net_device *dev, + */ + list_for_each_entry(i, &dev->all_adj_list.lower, list) + list_for_each_entry(j, &upper_dev->all_adj_list.upper, list) +- __netdev_adjacent_dev_unlink(i->dev, j->dev); ++ __netdev_adjacent_dev_unlink(i->dev, j->dev, i->ref_nr); + + /* remove also the devices itself from lower/upper device + * list + */ + list_for_each_entry(i, &dev->all_adj_list.lower, list) +- __netdev_adjacent_dev_unlink(i->dev, upper_dev); ++ __netdev_adjacent_dev_unlink(i->dev, upper_dev, i->ref_nr); + + list_for_each_entry(i, &upper_dev->all_adj_list.upper, list) +- __netdev_adjacent_dev_unlink(dev, i->dev); ++ __netdev_adjacent_dev_unlink(dev, i->dev, i->ref_nr); + + call_netdevice_notifiers_info(NETDEV_CHANGEUPPER, dev, + &changeupper_info.info); +diff --git a/net/core/pktgen.c b/net/core/pktgen.c +index bbd118b..306b8f0 100644 +--- a/net/core/pktgen.c ++++ b/net/core/pktgen.c +@@ -216,8 +216,8 @@ + #define M_QUEUE_XMIT 2 /* Inject packet into qdisc */ + + /* If lock -- protects updating of if_list */ +-#define if_lock(t) spin_lock(&(t->if_lock)); +-#define if_unlock(t) spin_unlock(&(t->if_lock)); ++#define if_lock(t) mutex_lock(&(t->if_lock)); ++#define if_unlock(t) mutex_unlock(&(t->if_lock)); + + /* Used to help with determining the pkts on receive */ + #define PKTGEN_MAGIC 0xbe9be955 +@@ -423,7 +423,7 @@ struct pktgen_net { + }; + + struct pktgen_thread { +- spinlock_t if_lock; /* for list of devices */ ++ struct mutex if_lock; /* for list of devices */ + struct list_head if_list; /* All device here */ + struct list_head th_list; + struct task_struct *tsk; +@@ -2010,11 +2010,13 @@ static void pktgen_change_name(const struct pktgen_net *pn, struct net_device *d + { + struct pktgen_thread *t; + ++ mutex_lock(&pktgen_thread_lock); ++ + list_for_each_entry(t, &pn->pktgen_threads, th_list) { + struct pktgen_dev *pkt_dev; + +- rcu_read_lock(); +- list_for_each_entry_rcu(pkt_dev, &t->if_list, list) { ++ if_lock(t); ++ list_for_each_entry(pkt_dev, &t->if_list, list) { + if (pkt_dev->odev != dev) + continue; + +@@ -2029,8 +2031,9 @@ static void pktgen_change_name(const struct pktgen_net *pn, struct net_device *d + dev->name); + break; + } +- rcu_read_unlock(); ++ if_unlock(t); + } ++ mutex_unlock(&pktgen_thread_lock); + } + + static int pktgen_device_event(struct notifier_block *unused, +@@ -2286,7 +2289,7 @@ static void spin(struct pktgen_dev *pkt_dev, ktime_t spin_until) + + static inline void set_pkt_overhead(struct pktgen_dev *pkt_dev) + { +- pkt_dev->pkt_overhead = LL_RESERVED_SPACE(pkt_dev->odev); ++ pkt_dev->pkt_overhead = 0; + pkt_dev->pkt_overhead += pkt_dev->nr_labels*sizeof(u32); + pkt_dev->pkt_overhead += VLAN_TAG_SIZE(pkt_dev); + pkt_dev->pkt_overhead += SVLAN_TAG_SIZE(pkt_dev); +@@ -2777,13 +2780,13 @@ static void pktgen_finalize_skb(struct pktgen_dev *pkt_dev, struct sk_buff *skb, + } + + static struct sk_buff *pktgen_alloc_skb(struct net_device *dev, +- struct pktgen_dev *pkt_dev, +- unsigned int extralen) ++ struct pktgen_dev *pkt_dev) + { ++ unsigned int extralen = LL_RESERVED_SPACE(dev); + struct sk_buff *skb = NULL; +- unsigned int size = pkt_dev->cur_pkt_size + 64 + extralen + +- pkt_dev->pkt_overhead; ++ unsigned int size; + ++ size = pkt_dev->cur_pkt_size + 64 + extralen + pkt_dev->pkt_overhead; + if (pkt_dev->flags & F_NODE) { + int node = pkt_dev->node >= 0 ? pkt_dev->node : numa_node_id(); + +@@ -2796,8 +2799,9 @@ static struct sk_buff *pktgen_alloc_skb(struct net_device *dev, + skb = __netdev_alloc_skb(dev, size, GFP_NOWAIT); + } + ++ /* the caller pre-fetches from skb->data and reserves for the mac hdr */ + if (likely(skb)) +- skb_reserve(skb, LL_RESERVED_SPACE(dev)); ++ skb_reserve(skb, extralen - 16); + + return skb; + } +@@ -2830,16 +2834,14 @@ static struct sk_buff *fill_packet_ipv4(struct net_device *odev, + mod_cur_headers(pkt_dev); + queue_map = pkt_dev->cur_queue_map; + +- datalen = (odev->hard_header_len + 16) & ~0xf; +- +- skb = pktgen_alloc_skb(odev, pkt_dev, datalen); ++ skb = pktgen_alloc_skb(odev, pkt_dev); + if (!skb) { + sprintf(pkt_dev->result, "No memory"); + return NULL; + } + + prefetchw(skb->data); +- skb_reserve(skb, datalen); ++ skb_reserve(skb, 16); + + /* Reserve for ethernet and IP header */ + eth = (__u8 *) skb_push(skb, 14); +@@ -2959,7 +2961,7 @@ static struct sk_buff *fill_packet_ipv6(struct net_device *odev, + mod_cur_headers(pkt_dev); + queue_map = pkt_dev->cur_queue_map; + +- skb = pktgen_alloc_skb(odev, pkt_dev, 16); ++ skb = pktgen_alloc_skb(odev, pkt_dev); + if (!skb) { + sprintf(pkt_dev->result, "No memory"); + return NULL; +@@ -3763,7 +3765,7 @@ static int __net_init pktgen_create_thread(int cpu, struct pktgen_net *pn) + return -ENOMEM; + } + +- spin_lock_init(&t->if_lock); ++ mutex_init(&t->if_lock); + t->cpu = cpu; + + INIT_LIST_HEAD(&t->if_list); +diff --git a/net/ethernet/eth.c b/net/ethernet/eth.c +index 66dff5e..02acfff 100644 +--- a/net/ethernet/eth.c ++++ b/net/ethernet/eth.c +@@ -439,7 +439,7 @@ struct sk_buff **eth_gro_receive(struct sk_buff **head, + + skb_gro_pull(skb, sizeof(*eh)); + skb_gro_postpull_rcsum(skb, eh, sizeof(*eh)); +- pp = ptype->callbacks.gro_receive(head, skb); ++ pp = call_gro_receive(ptype->callbacks.gro_receive, head, skb); + + out_unlock: + rcu_read_unlock(); +diff --git a/net/ipv4/af_inet.c b/net/ipv4/af_inet.c +index 55513e6..eebbc0f 100644 +--- a/net/ipv4/af_inet.c ++++ b/net/ipv4/af_inet.c +@@ -1388,7 +1388,7 @@ struct sk_buff **inet_gro_receive(struct sk_buff **head, struct sk_buff *skb) + skb_gro_pull(skb, sizeof(*iph)); + skb_set_transport_header(skb, skb_gro_offset(skb)); + +- pp = ops->callbacks.gro_receive(head, skb); ++ pp = call_gro_receive(ops->callbacks.gro_receive, head, skb); + + out_unlock: + rcu_read_unlock(); +diff --git a/net/ipv4/fou.c b/net/ipv4/fou.c +index 321d57f..5351b61 100644 +--- a/net/ipv4/fou.c ++++ b/net/ipv4/fou.c +@@ -249,7 +249,7 @@ static struct sk_buff **fou_gro_receive(struct sock *sk, + if (!ops || !ops->callbacks.gro_receive) + goto out_unlock; + +- pp = ops->callbacks.gro_receive(head, skb); ++ pp = call_gro_receive(ops->callbacks.gro_receive, head, skb); + + out_unlock: + rcu_read_unlock(); +@@ -441,7 +441,7 @@ static struct sk_buff **gue_gro_receive(struct sock *sk, + if (WARN_ON_ONCE(!ops || !ops->callbacks.gro_receive)) + goto out_unlock; + +- pp = ops->callbacks.gro_receive(head, skb); ++ pp = call_gro_receive(ops->callbacks.gro_receive, head, skb); + flush = 0; + + out_unlock: +diff --git a/net/ipv4/gre_offload.c b/net/ipv4/gre_offload.c +index ecd1e09..6871f59 100644 +--- a/net/ipv4/gre_offload.c ++++ b/net/ipv4/gre_offload.c +@@ -227,7 +227,7 @@ static struct sk_buff **gre_gro_receive(struct sk_buff **head, + /* Adjusted NAPI_GRO_CB(skb)->csum after skb_gro_pull()*/ + skb_gro_postpull_rcsum(skb, greh, grehlen); + +- pp = ptype->callbacks.gro_receive(head, skb); ++ pp = call_gro_receive(ptype->callbacks.gro_receive, head, skb); + flush = 0; + + out_unlock: +diff --git a/net/ipv4/ip_sockglue.c b/net/ipv4/ip_sockglue.c +index 71a52f4d..11ef96e 100644 +--- a/net/ipv4/ip_sockglue.c ++++ b/net/ipv4/ip_sockglue.c +@@ -98,7 +98,7 @@ static void ip_cmsg_recv_retopts(struct msghdr *msg, struct sk_buff *skb) + } + + static void ip_cmsg_recv_checksum(struct msghdr *msg, struct sk_buff *skb, +- int offset) ++ int tlen, int offset) + { + __wsum csum = skb->csum; + +@@ -106,8 +106,9 @@ static void ip_cmsg_recv_checksum(struct msghdr *msg, struct sk_buff *skb, + return; + + if (offset != 0) +- csum = csum_sub(csum, csum_partial(skb_transport_header(skb), +- offset, 0)); ++ csum = csum_sub(csum, ++ csum_partial(skb_transport_header(skb) + tlen, ++ offset, 0)); + + put_cmsg(msg, SOL_IP, IP_CHECKSUM, sizeof(__wsum), &csum); + } +@@ -153,7 +154,7 @@ static void ip_cmsg_recv_dstaddr(struct msghdr *msg, struct sk_buff *skb) + } + + void ip_cmsg_recv_offset(struct msghdr *msg, struct sk_buff *skb, +- int offset) ++ int tlen, int offset) + { + struct inet_sock *inet = inet_sk(skb->sk); + unsigned int flags = inet->cmsg_flags; +@@ -216,7 +217,7 @@ void ip_cmsg_recv_offset(struct msghdr *msg, struct sk_buff *skb, + } + + if (flags & IP_CMSG_CHECKSUM) +- ip_cmsg_recv_checksum(msg, skb, offset); ++ ip_cmsg_recv_checksum(msg, skb, tlen, offset); + } + EXPORT_SYMBOL(ip_cmsg_recv_offset); + +diff --git a/net/ipv4/sysctl_net_ipv4.c b/net/ipv4/sysctl_net_ipv4.c +index 1cb67de..80bc36b 100644 +--- a/net/ipv4/sysctl_net_ipv4.c ++++ b/net/ipv4/sysctl_net_ipv4.c +@@ -96,11 +96,11 @@ static void inet_get_ping_group_range_table(struct ctl_table *table, kgid_t *low + container_of(table->data, struct net, ipv4.ping_group_range.range); + unsigned int seq; + do { +- seq = read_seqbegin(&net->ipv4.ip_local_ports.lock); ++ seq = read_seqbegin(&net->ipv4.ping_group_range.lock); + + *low = data[0]; + *high = data[1]; +- } while (read_seqretry(&net->ipv4.ip_local_ports.lock, seq)); ++ } while (read_seqretry(&net->ipv4.ping_group_range.lock, seq)); + } + + /* Update system visible IP port range */ +@@ -109,10 +109,10 @@ static void set_ping_group_range(struct ctl_table *table, kgid_t low, kgid_t hig + kgid_t *data = table->data; + struct net *net = + container_of(table->data, struct net, ipv4.ping_group_range.range); +- write_seqlock(&net->ipv4.ip_local_ports.lock); ++ write_seqlock(&net->ipv4.ping_group_range.lock); + data[0] = low; + data[1] = high; +- write_sequnlock(&net->ipv4.ip_local_ports.lock); ++ write_sequnlock(&net->ipv4.ping_group_range.lock); + } + + /* Validate changes from /proc interface. */ +diff --git a/net/ipv4/udp.c b/net/ipv4/udp.c +index 5fdcb8d..c0d71e7 100644 +--- a/net/ipv4/udp.c ++++ b/net/ipv4/udp.c +@@ -1327,7 +1327,7 @@ int udp_recvmsg(struct sock *sk, struct msghdr *msg, size_t len, int noblock, + *addr_len = sizeof(*sin); + } + if (inet->cmsg_flags) +- ip_cmsg_recv_offset(msg, skb, sizeof(struct udphdr) + off); ++ ip_cmsg_recv_offset(msg, skb, sizeof(struct udphdr), off); + + err = copied; + if (flags & MSG_TRUNC) +diff --git a/net/ipv4/udp_offload.c b/net/ipv4/udp_offload.c +index 81f253b..6de9f97 100644 +--- a/net/ipv4/udp_offload.c ++++ b/net/ipv4/udp_offload.c +@@ -293,7 +293,7 @@ struct sk_buff **udp_gro_receive(struct sk_buff **head, struct sk_buff *skb, + + skb_gro_pull(skb, sizeof(struct udphdr)); /* pull encapsulating udp header */ + skb_gro_postpull_rcsum(skb, uh, sizeof(struct udphdr)); +- pp = udp_sk(sk)->gro_receive(sk, head, skb); ++ pp = call_gro_receive_sk(udp_sk(sk)->gro_receive, sk, head, skb); + + out_unlock: + rcu_read_unlock(); +diff --git a/net/ipv6/addrconf.c b/net/ipv6/addrconf.c +index 2f1f5d4..f5432d6 100644 +--- a/net/ipv6/addrconf.c ++++ b/net/ipv6/addrconf.c +@@ -2995,7 +2995,7 @@ static void init_loopback(struct net_device *dev) + * lo device down, release this obsolete dst and + * reallocate a new router for ifa. + */ +- if (sp_ifa->rt->dst.obsolete > 0) { ++ if (!atomic_read(&sp_ifa->rt->rt6i_ref)) { + ip6_rt_put(sp_ifa->rt); + sp_ifa->rt = NULL; + } else { +diff --git a/net/ipv6/ip6_offload.c b/net/ipv6/ip6_offload.c +index 22e90e5..a09418b 100644 +--- a/net/ipv6/ip6_offload.c ++++ b/net/ipv6/ip6_offload.c +@@ -243,7 +243,7 @@ static struct sk_buff **ipv6_gro_receive(struct sk_buff **head, + + skb_gro_postpull_rcsum(skb, iph, nlen); + +- pp = ops->callbacks.gro_receive(head, skb); ++ pp = call_gro_receive(ops->callbacks.gro_receive, head, skb); + + out_unlock: + rcu_read_unlock(); +diff --git a/net/ipv6/ip6_tunnel.c b/net/ipv6/ip6_tunnel.c +index 888543d..41489f3 100644 +--- a/net/ipv6/ip6_tunnel.c ++++ b/net/ipv6/ip6_tunnel.c +@@ -155,6 +155,7 @@ ip6_tnl_lookup(struct net *net, const struct in6_addr *remote, const struct in6_ + hash = HASH(&any, local); + for_each_ip6_tunnel_rcu(ip6n->tnls_r_l[hash]) { + if (ipv6_addr_equal(local, &t->parms.laddr) && ++ ipv6_addr_any(&t->parms.raddr) && + (t->dev->flags & IFF_UP)) + return t; + } +@@ -162,6 +163,7 @@ ip6_tnl_lookup(struct net *net, const struct in6_addr *remote, const struct in6_ + hash = HASH(remote, &any); + for_each_ip6_tunnel_rcu(ip6n->tnls_r_l[hash]) { + if (ipv6_addr_equal(remote, &t->parms.raddr) && ++ ipv6_addr_any(&t->parms.laddr) && + (t->dev->flags & IFF_UP)) + return t; + } +@@ -1132,6 +1134,7 @@ int ip6_tnl_xmit(struct sk_buff *skb, struct net_device *dev, __u8 dsfield, + if (err) + return err; + ++ skb->protocol = htons(ETH_P_IPV6); + skb_push(skb, sizeof(struct ipv6hdr)); + skb_reset_network_header(skb); + ipv6h = ipv6_hdr(skb); +diff --git a/net/ipv6/route.c b/net/ipv6/route.c +index 269218a..23153ac 100644 +--- a/net/ipv6/route.c ++++ b/net/ipv6/route.c +@@ -656,7 +656,8 @@ static struct rt6_info *find_match(struct rt6_info *rt, int oif, int strict, + struct net_device *dev = rt->dst.dev; + + if (dev && !netif_carrier_ok(dev) && +- idev->cnf.ignore_routes_with_linkdown) ++ idev->cnf.ignore_routes_with_linkdown && ++ !(strict & RT6_LOOKUP_F_IGNORE_LINKSTATE)) + goto out; + + if (rt6_check_expired(rt)) +@@ -1050,6 +1051,7 @@ struct rt6_info *ip6_pol_route(struct net *net, struct fib6_table *table, + int strict = 0; + + strict |= flags & RT6_LOOKUP_F_IFACE; ++ strict |= flags & RT6_LOOKUP_F_IGNORE_LINKSTATE; + if (net->ipv6.devconf_all->forwarding == 0) + strict |= RT6_LOOKUP_F_REACHABLE; + +@@ -1783,7 +1785,7 @@ static struct rt6_info *ip6_nh_lookup_table(struct net *net, + }; + struct fib6_table *table; + struct rt6_info *rt; +- int flags = RT6_LOOKUP_F_IFACE; ++ int flags = RT6_LOOKUP_F_IFACE | RT6_LOOKUP_F_IGNORE_LINKSTATE; + + table = fib6_get_table(net, cfg->fc_table); + if (!table) +diff --git a/net/ipv6/tcp_ipv6.c b/net/ipv6/tcp_ipv6.c +index 94f4f89..fc67822 100644 +--- a/net/ipv6/tcp_ipv6.c ++++ b/net/ipv6/tcp_ipv6.c +@@ -1193,6 +1193,16 @@ static struct sock *tcp_v6_syn_recv_sock(const struct sock *sk, struct sk_buff * + return NULL; + } + ++static void tcp_v6_restore_cb(struct sk_buff *skb) ++{ ++ /* We need to move header back to the beginning if xfrm6_policy_check() ++ * and tcp_v6_fill_cb() are going to be called again. ++ * ip6_datagram_recv_specific_ctl() also expects IP6CB to be there. ++ */ ++ memmove(IP6CB(skb), &TCP_SKB_CB(skb)->header.h6, ++ sizeof(struct inet6_skb_parm)); ++} ++ + /* The socket must have it's spinlock held when we get + * here, unless it is a TCP_LISTEN socket. + * +@@ -1322,6 +1332,7 @@ static int tcp_v6_do_rcv(struct sock *sk, struct sk_buff *skb) + np->flow_label = ip6_flowlabel(ipv6_hdr(opt_skb)); + if (ipv6_opt_accepted(sk, opt_skb, &TCP_SKB_CB(opt_skb)->header.h6)) { + skb_set_owner_r(opt_skb, sk); ++ tcp_v6_restore_cb(opt_skb); + opt_skb = xchg(&np->pktoptions, opt_skb); + } else { + __kfree_skb(opt_skb); +@@ -1355,15 +1366,6 @@ static void tcp_v6_fill_cb(struct sk_buff *skb, const struct ipv6hdr *hdr, + TCP_SKB_CB(skb)->sacked = 0; + } + +-static void tcp_v6_restore_cb(struct sk_buff *skb) +-{ +- /* We need to move header back to the beginning if xfrm6_policy_check() +- * and tcp_v6_fill_cb() are going to be called again. +- */ +- memmove(IP6CB(skb), &TCP_SKB_CB(skb)->header.h6, +- sizeof(struct inet6_skb_parm)); +-} +- + static int tcp_v6_rcv(struct sk_buff *skb) + { + const struct tcphdr *th; +diff --git a/net/ipv6/udp.c b/net/ipv6/udp.c +index 19ac3a1..c2a8656 100644 +--- a/net/ipv6/udp.c ++++ b/net/ipv6/udp.c +@@ -427,7 +427,8 @@ int udpv6_recvmsg(struct sock *sk, struct msghdr *msg, size_t len, + + if (is_udp4) { + if (inet->cmsg_flags) +- ip_cmsg_recv(msg, skb); ++ ip_cmsg_recv_offset(msg, skb, ++ sizeof(struct udphdr), off); + } else { + if (np->rxopt.all) + ip6_datagram_recv_specific_ctl(sk, msg, skb); +diff --git a/net/netlink/af_netlink.c b/net/netlink/af_netlink.c +index 627f898..62bea45 100644 +--- a/net/netlink/af_netlink.c ++++ b/net/netlink/af_netlink.c +@@ -1832,7 +1832,7 @@ static int netlink_recvmsg(struct socket *sock, struct msghdr *msg, size_t len, + /* Record the max length of recvmsg() calls for future allocations */ + nlk->max_recvmsg_len = max(nlk->max_recvmsg_len, len); + nlk->max_recvmsg_len = min_t(size_t, nlk->max_recvmsg_len, +- 16384); ++ SKB_WITH_OVERHEAD(32768)); + + copied = data_skb->len; + if (len < copied) { +@@ -2083,8 +2083,9 @@ static int netlink_dump(struct sock *sk) + + if (alloc_min_size < nlk->max_recvmsg_len) { + alloc_size = nlk->max_recvmsg_len; +- skb = alloc_skb(alloc_size, GFP_KERNEL | +- __GFP_NOWARN | __GFP_NORETRY); ++ skb = alloc_skb(alloc_size, ++ (GFP_KERNEL & ~__GFP_DIRECT_RECLAIM) | ++ __GFP_NOWARN | __GFP_NORETRY); + } + if (!skb) { + alloc_size = alloc_min_size; +diff --git a/net/packet/af_packet.c b/net/packet/af_packet.c +index 33a4697..d2238b2 100644 +--- a/net/packet/af_packet.c ++++ b/net/packet/af_packet.c +@@ -250,7 +250,7 @@ static void __fanout_link(struct sock *sk, struct packet_sock *po); + static int packet_direct_xmit(struct sk_buff *skb) + { + struct net_device *dev = skb->dev; +- netdev_features_t features; ++ struct sk_buff *orig_skb = skb; + struct netdev_queue *txq; + int ret = NETDEV_TX_BUSY; + +@@ -258,9 +258,8 @@ static int packet_direct_xmit(struct sk_buff *skb) + !netif_carrier_ok(dev))) + goto drop; + +- features = netif_skb_features(skb); +- if (skb_needs_linearize(skb, features) && +- __skb_linearize(skb)) ++ skb = validate_xmit_skb_list(skb, dev); ++ if (skb != orig_skb) + goto drop; + + txq = skb_get_tx_queue(dev, skb); +@@ -280,7 +279,7 @@ static int packet_direct_xmit(struct sk_buff *skb) + return ret; + drop: + atomic_long_inc(&dev->tx_dropped); +- kfree_skb(skb); ++ kfree_skb_list(skb); + return NET_XMIT_DROP; + } + +@@ -3952,6 +3951,7 @@ static int packet_notifier(struct notifier_block *this, + } + if (msg == NETDEV_UNREGISTER) { + packet_cached_dev_reset(po); ++ fanout_release(sk); + po->ifindex = -1; + if (po->prot_hook.dev) + dev_put(po->prot_hook.dev); +diff --git a/net/sched/act_api.c b/net/sched/act_api.c +index d09d068..027ddf4 100644 +--- a/net/sched/act_api.c ++++ b/net/sched/act_api.c +@@ -341,22 +341,25 @@ int tcf_register_action(struct tc_action_ops *act, + if (!act->act || !act->dump || !act->init || !act->walk || !act->lookup) + return -EINVAL; + ++ /* We have to register pernet ops before making the action ops visible, ++ * otherwise tcf_action_init_1() could get a partially initialized ++ * netns. ++ */ ++ ret = register_pernet_subsys(ops); ++ if (ret) ++ return ret; ++ + write_lock(&act_mod_lock); + list_for_each_entry(a, &act_base, head) { + if (act->type == a->type || (strcmp(act->kind, a->kind) == 0)) { + write_unlock(&act_mod_lock); ++ unregister_pernet_subsys(ops); + return -EEXIST; + } + } + list_add_tail(&act->head, &act_base); + write_unlock(&act_mod_lock); + +- ret = register_pernet_subsys(ops); +- if (ret) { +- tcf_unregister_action(act, ops); +- return ret; +- } +- + return 0; + } + EXPORT_SYMBOL(tcf_register_action); +@@ -367,8 +370,6 @@ int tcf_unregister_action(struct tc_action_ops *act, + struct tc_action_ops *a; + int err = -ENOENT; + +- unregister_pernet_subsys(ops); +- + write_lock(&act_mod_lock); + list_for_each_entry(a, &act_base, head) { + if (a == act) { +@@ -378,6 +379,8 @@ int tcf_unregister_action(struct tc_action_ops *act, + } + } + write_unlock(&act_mod_lock); ++ if (!err) ++ unregister_pernet_subsys(ops); + return err; + } + EXPORT_SYMBOL(tcf_unregister_action); +diff --git a/net/sched/act_vlan.c b/net/sched/act_vlan.c +index 691409d..4ffc6c1 100644 +--- a/net/sched/act_vlan.c ++++ b/net/sched/act_vlan.c +@@ -36,6 +36,12 @@ static int tcf_vlan(struct sk_buff *skb, const struct tc_action *a, + bstats_update(&v->tcf_bstats, skb); + action = v->tcf_action; + ++ /* Ensure 'data' points at mac_header prior calling vlan manipulating ++ * functions. ++ */ ++ if (skb_at_tc_ingress(skb)) ++ skb_push_rcsum(skb, skb->mac_len); ++ + switch (v->tcfv_action) { + case TCA_VLAN_ACT_POP: + err = skb_vlan_pop(skb); +@@ -57,6 +63,9 @@ static int tcf_vlan(struct sk_buff *skb, const struct tc_action *a, + action = TC_ACT_SHOT; + v->tcf_qstats.drops++; + unlock: ++ if (skb_at_tc_ingress(skb)) ++ skb_pull_rcsum(skb, skb->mac_len); ++ + spin_unlock(&v->tcf_lock); + return action; + } +diff --git a/net/sched/cls_api.c b/net/sched/cls_api.c +index a7c5645..74bed5e 100644 +--- a/net/sched/cls_api.c ++++ b/net/sched/cls_api.c +@@ -344,7 +344,8 @@ static int tc_ctl_tfilter(struct sk_buff *skb, struct nlmsghdr *n) + if (err == 0) { + struct tcf_proto *next = rtnl_dereference(tp->next); + +- tfilter_notify(net, skb, n, tp, fh, RTM_DELTFILTER); ++ tfilter_notify(net, skb, n, tp, ++ t->tcm_handle, RTM_DELTFILTER); + if (tcf_destroy(tp, false)) + RCU_INIT_POINTER(*back, next); + } +diff --git a/net/sctp/output.c b/net/sctp/output.c +index 31b7bc3..8192990 100644 +--- a/net/sctp/output.c ++++ b/net/sctp/output.c +@@ -417,6 +417,7 @@ int sctp_packet_transmit(struct sctp_packet *packet, gfp_t gfp) + __u8 has_data = 0; + int gso = 0; + int pktcount = 0; ++ int auth_len = 0; + struct dst_entry *dst; + unsigned char *auth = NULL; /* pointer to auth in skb data */ + +@@ -505,7 +506,12 @@ int sctp_packet_transmit(struct sctp_packet *packet, gfp_t gfp) + list_for_each_entry(chunk, &packet->chunk_list, list) { + int padded = WORD_ROUND(chunk->skb->len); + +- if (pkt_size + padded > tp->pathmtu) ++ if (chunk == packet->auth) ++ auth_len = padded; ++ else if (auth_len + padded + packet->overhead > ++ tp->pathmtu) ++ goto nomem; ++ else if (pkt_size + padded > tp->pathmtu) + break; + pkt_size += padded; + } +diff --git a/net/sctp/sm_statefuns.c b/net/sctp/sm_statefuns.c +index d88bb2b..920469e 100644 +--- a/net/sctp/sm_statefuns.c ++++ b/net/sctp/sm_statefuns.c +@@ -3422,6 +3422,12 @@ sctp_disposition_t sctp_sf_ootb(struct net *net, + return sctp_sf_violation_chunklen(net, ep, asoc, type, arg, + commands); + ++ /* Report violation if chunk len overflows */ ++ ch_end = ((__u8 *)ch) + WORD_ROUND(ntohs(ch->length)); ++ if (ch_end > skb_tail_pointer(skb)) ++ return sctp_sf_violation_chunklen(net, ep, asoc, type, arg, ++ commands); ++ + /* Now that we know we at least have a chunk header, + * do things that are type appropriate. + */ +@@ -3453,12 +3459,6 @@ sctp_disposition_t sctp_sf_ootb(struct net *net, + } + } + +- /* Report violation if chunk len overflows */ +- ch_end = ((__u8 *)ch) + WORD_ROUND(ntohs(ch->length)); +- if (ch_end > skb_tail_pointer(skb)) +- return sctp_sf_violation_chunklen(net, ep, asoc, type, arg, +- commands); +- + ch = (sctp_chunkhdr_t *) ch_end; + } while (ch_end < skb_tail_pointer(skb)); + +diff --git a/net/sctp/socket.c b/net/sctp/socket.c +index 8ed2d99..baccbf3 100644 +--- a/net/sctp/socket.c ++++ b/net/sctp/socket.c +@@ -4683,7 +4683,7 @@ static int sctp_getsockopt_disable_fragments(struct sock *sk, int len, + static int sctp_getsockopt_events(struct sock *sk, int len, char __user *optval, + int __user *optlen) + { +- if (len <= 0) ++ if (len == 0) + return -EINVAL; + if (len > sizeof(struct sctp_event_subscribe)) + len = sizeof(struct sctp_event_subscribe); +@@ -6426,6 +6426,9 @@ static int sctp_getsockopt(struct sock *sk, int level, int optname, + if (get_user(len, optlen)) + return -EFAULT; + ++ if (len < 0) ++ return -EINVAL; ++ + lock_sock(sk); + + switch (optname) { +diff --git a/net/switchdev/switchdev.c b/net/switchdev/switchdev.c +index a5fc9dd..a56c5e6 100644 +--- a/net/switchdev/switchdev.c ++++ b/net/switchdev/switchdev.c +@@ -774,6 +774,9 @@ int switchdev_port_bridge_getlink(struct sk_buff *skb, u32 pid, u32 seq, + u32 mask = BR_LEARNING | BR_LEARNING_SYNC | BR_FLOOD; + int err; + ++ if (!netif_is_bridge_port(dev)) ++ return -EOPNOTSUPP; ++ + err = switchdev_port_attr_get(dev, &attr); + if (err && err != -EOPNOTSUPP) + return err; +@@ -929,6 +932,9 @@ int switchdev_port_bridge_setlink(struct net_device *dev, + struct nlattr *afspec; + int err = 0; + ++ if (!netif_is_bridge_port(dev)) ++ return -EOPNOTSUPP; ++ + protinfo = nlmsg_find_attr(nlh, sizeof(struct ifinfomsg), + IFLA_PROTINFO); + if (protinfo) { +@@ -962,6 +968,9 @@ int switchdev_port_bridge_dellink(struct net_device *dev, + { + struct nlattr *afspec; + ++ if (!netif_is_bridge_port(dev)) ++ return -EOPNOTSUPP; ++ + afspec = nlmsg_find_attr(nlh, sizeof(struct ifinfomsg), + IFLA_AF_SPEC); + if (afspec) diff --git a/4.8.7/4420_grsecurity-3.1-4.8.7-201611102210.patch b/4.8.8/4420_grsecurity-3.1-4.8.8-201611150756.patch index 76a16d1..e0579c2 100644 --- a/4.8.7/4420_grsecurity-3.1-4.8.7-201611102210.patch +++ b/4.8.8/4420_grsecurity-3.1-4.8.8-201611150756.patch @@ -407,7 +407,7 @@ index ffab8b5..b8fcd61 100644 A toggle value indicating if modules are allowed to be loaded diff --git a/Makefile b/Makefile -index 4d0f28c..1fee46b 100644 +index 8f18daa..a2e9eda 100644 --- a/Makefile +++ b/Makefile @@ -302,7 +302,9 @@ CONFIG_SHELL := $(shell if [ -x "$$BASH" ]; then echo $$BASH; \ @@ -52853,10 +52853,10 @@ index cac1d52..29bb903 100644 int need_req_skb; diff --git a/drivers/infiniband/ulp/ipoib/ipoib_main.c b/drivers/infiniband/ulp/ipoib/ipoib_main.c -index cc1c1b0..fa712b0 100644 +index 823a528..c8171f7 100644 --- a/drivers/infiniband/ulp/ipoib/ipoib_main.c +++ b/drivers/infiniband/ulp/ipoib/ipoib_main.c -@@ -1022,7 +1022,7 @@ static void unicast_arp_send(struct sk_buff *skb, struct net_device *dev, +@@ -1029,7 +1029,7 @@ static void unicast_arp_send(struct sk_buff *skb, struct net_device *dev, spin_unlock_irqrestore(&priv->lock, flags); } @@ -65237,7 +65237,7 @@ index 93dc10b..6598671 100644 struct net_local *lp = netdev_priv(dev); struct sk_buff *new_skb; diff --git a/drivers/net/geneve.c b/drivers/net/geneve.c -index 3c20e87..5696f6f 100644 +index 16af1ce..deabcc5 100644 --- a/drivers/net/geneve.c +++ b/drivers/net/geneve.c @@ -1450,7 +1450,7 @@ nla_put_failure: @@ -65325,7 +65325,7 @@ index 591af71..a5bbc7a 100644 spinlock_t request_lock; struct list_head req_list; diff --git a/drivers/net/hyperv/netvsc_drv.c b/drivers/net/hyperv/netvsc_drv.c -index 3ba29fc..793bdcf 100644 +index c4d9653..a4c9101 100644 --- a/drivers/net/hyperv/netvsc_drv.c +++ b/drivers/net/hyperv/netvsc_drv.c @@ -349,7 +349,7 @@ not_ip: @@ -65528,10 +65528,10 @@ index 6255973..7ae59f5 100644 .init = loopback_net_init, }; diff --git a/drivers/net/macsec.c b/drivers/net/macsec.c -index 351e701..8b7039d 100644 +index b72ddc6..7f75c10 100644 --- a/drivers/net/macsec.c +++ b/drivers/net/macsec.c -@@ -3378,7 +3378,7 @@ nla_put_failure: +@@ -3388,7 +3388,7 @@ nla_put_failure: return -EMSGSIZE; } @@ -66015,7 +66015,7 @@ index 1ce7420..8bef471 100644 }; diff --git a/drivers/net/vxlan.c b/drivers/net/vxlan.c -index 6e65832..def968c 100644 +index 5ae664c..65d0be53 100644 --- a/drivers/net/vxlan.c +++ b/drivers/net/vxlan.c @@ -3169,7 +3169,7 @@ static struct net *vxlan_get_link_net(const struct net_device *dev) @@ -75028,7 +75028,7 @@ index d197aa1..c1178a6 100644 /** diff --git a/drivers/scsi/megaraid/megaraid_sas.h b/drivers/scsi/megaraid/megaraid_sas.h -index ca86c88..175be62 100644 +index 3aaea71..6cd098b 100644 --- a/drivers/scsi/megaraid/megaraid_sas.h +++ b/drivers/scsi/megaraid/megaraid_sas.h @@ -2048,7 +2048,7 @@ struct megasas_instance { @@ -137208,7 +137208,7 @@ index b9f0ff4..fd3f501 100644 struct iovec; struct kvec; diff --git a/include/linux/netdevice.h b/include/linux/netdevice.h -index e8d79d4..d9519a7 100644 +index e942c67..6133147 100644 --- a/include/linux/netdevice.h +++ b/include/linux/netdevice.h @@ -1307,6 +1307,7 @@ struct net_device_ops { @@ -137241,7 +137241,7 @@ index e8d79d4..d9519a7 100644 #ifdef CONFIG_WIRELESS_EXT const struct iw_handler_def *wireless_handlers; -@@ -4218,7 +4219,7 @@ static inline bool netif_reduces_vlan_mtu(struct net_device *dev) +@@ -4255,7 +4256,7 @@ static inline bool netif_reduces_vlan_mtu(struct net_device *dev) return dev->priv_flags & IFF_MACSEC; } @@ -140765,7 +140765,7 @@ index 235c781..160d4a3 100644 struct rcu_head rcu; struct inet_peer *gc_next; diff --git a/include/net/ip.h b/include/net/ip.h -index 9742b92..f47d922 100644 +index 156b0c1..f921618 100644 --- a/include/net/ip.h +++ b/include/net/ip.h @@ -326,7 +326,7 @@ static inline unsigned int ip_skb_dst_mtu(struct sock *sk, @@ -146876,16 +146876,15 @@ index 8f27d5a..e7389a0 100644 if (pm_wakeup_pending()) { diff --git a/kernel/power/snapshot.c b/kernel/power/snapshot.c -index b022284..b48c449 100644 +index b022284..48d5ea6 100644 --- a/kernel/power/snapshot.c +++ b/kernel/power/snapshot.c -@@ -1020,6 +1020,28 @@ static void swsusp_unset_page_forbidden(struct page *page) +@@ -1020,6 +1020,26 @@ static void swsusp_unset_page_forbidden(struct page *page) memory_bm_clear_bit(forbidden_pages_map, page_to_pfn(page)); } +void clear_free_pages(void) +{ -+#if defined(CONFIG_PAX_MEMORY_SANITIZE) || defined(CONFIG_PAGE_POISONING_ZERO) + struct memory_bitmap *bm = free_pages_map; + unsigned long pfn; + @@ -146902,39 +146901,11 @@ index b022284..b48c449 100644 + } + memory_bm_position_reset(bm); + pr_info("PM: free pages cleared after restore\n"); -+#endif /* CONFIG_PAX_MEMORY_SANITIZE || PAGE_POISONING_ZERO */ +} + /** * mark_nosave_pages - Mark pages that should not be saved. * @bm: Memory bitmap. -@@ -1132,6 +1154,26 @@ void free_basic_memory_bitmaps(void) - pr_debug("PM: Basic memory bitmaps freed\n"); - } - -+void clear_free_pages(void) -+{ -+ struct memory_bitmap *bm = free_pages_map; -+ unsigned long pfn; -+ -+ if (WARN_ON(!(free_pages_map))) -+ return; -+ -+ memory_bm_position_reset(bm); -+ pfn = memory_bm_next_pfn(bm); -+ while (pfn != BM_END_OF_MAP) { -+ if (pfn_valid(pfn)) -+ clear_highpage(pfn_to_page(pfn)); -+ -+ pfn = memory_bm_next_pfn(bm); -+ } -+ memory_bm_position_reset(bm); -+ pr_info("PM: free pages cleared after restore\n"); -+} -+ - /** - * snapshot_additional_pages - Estimate the number of extra pages needed. - * @zone: Memory zone to carry out the computation for. diff --git a/kernel/printk/printk.c b/kernel/printk/printk.c index eea6dbc..075ab5e 100644 --- a/kernel/printk/printk.c @@ -150712,6 +150683,18 @@ index cab7405..c65d473 100644 help If you want to debug problems which hang or crash the kernel early on boot and the crashing machine has a FireWire port, you can use +diff --git a/lib/Kconfig.kmemcheck b/lib/Kconfig.kmemcheck +index 846e039..63ef284 100644 +--- a/lib/Kconfig.kmemcheck ++++ b/lib/Kconfig.kmemcheck +@@ -10,6 +10,7 @@ menuconfig KMEMCHECK + depends on SLUB || SLAB + depends on !CC_OPTIMIZE_FOR_SIZE + depends on !FUNCTION_TRACER ++ depends on !PAX_INITIFY + select FRAME_POINTER + select STACKTRACE + default n diff --git a/lib/Makefile b/lib/Makefile index 5dc77a8..8c18345 100644 --- a/lib/Makefile @@ -157663,7 +157646,7 @@ index 89cec42..673413a 100644 return 0; } diff --git a/net/8021q/vlan.c b/net/8021q/vlan.c -index 8de138d..df7e387 100644 +index f2531ad..5792672 100644 --- a/net/8021q/vlan.c +++ b/net/8021q/vlan.c @@ -496,7 +496,7 @@ out: @@ -158872,7 +158855,7 @@ index b7de71f..808387d 100644 return err; diff --git a/net/core/dev.c b/net/core/dev.c -index ea63120..7fbab94 100644 +index 44b3ba4..34822e6 100644 --- a/net/core/dev.c +++ b/net/core/dev.c @@ -1768,7 +1768,7 @@ int __dev_forward_skb(struct net_device *dev, struct sk_buff *skb) @@ -158893,7 +158876,7 @@ index ea63120..7fbab94 100644 return NULL; } -@@ -3425,7 +3425,7 @@ recursion_alert: +@@ -3426,7 +3426,7 @@ recursion_alert: rc = -ENETDOWN; rcu_read_unlock_bh(); @@ -158902,7 +158885,7 @@ index ea63120..7fbab94 100644 kfree_skb_list(skb); return rc; out: -@@ -3778,7 +3778,7 @@ drop: +@@ -3779,7 +3779,7 @@ drop: local_irq_restore(flags); @@ -158911,7 +158894,7 @@ index ea63120..7fbab94 100644 kfree_skb(skb); return NET_RX_DROP; } -@@ -3855,7 +3855,7 @@ int netif_rx_ni(struct sk_buff *skb) +@@ -3856,7 +3856,7 @@ int netif_rx_ni(struct sk_buff *skb) } EXPORT_SYMBOL(netif_rx_ni); @@ -158920,7 +158903,7 @@ index ea63120..7fbab94 100644 { struct softnet_data *sd = this_cpu_ptr(&softnet_data); -@@ -4218,9 +4218,9 @@ ncls: +@@ -4219,9 +4219,9 @@ ncls: } else { drop: if (!deliver_exact) @@ -158932,7 +158915,7 @@ index ea63120..7fbab94 100644 kfree_skb(skb); /* Jamal, now you will not able to escape explaining * me how you were going to use this. :-) -@@ -5187,7 +5187,7 @@ out_unlock: +@@ -5189,7 +5189,7 @@ out_unlock: return work; } @@ -158941,7 +158924,7 @@ index ea63120..7fbab94 100644 { struct softnet_data *sd = this_cpu_ptr(&softnet_data); unsigned long time_limit = jiffies + 2; -@@ -7520,9 +7520,9 @@ struct rtnl_link_stats64 *dev_get_stats(struct net_device *dev, +@@ -7532,9 +7532,9 @@ struct rtnl_link_stats64 *dev_get_stats(struct net_device *dev, } else { netdev_stats_to_stats64(storage, &dev->stats); } @@ -158954,7 +158937,7 @@ index ea63120..7fbab94 100644 return storage; } EXPORT_SYMBOL(dev_get_stats); -@@ -8144,7 +8144,7 @@ static void __net_exit netdev_exit(struct net *net) +@@ -8156,7 +8156,7 @@ static void __net_exit netdev_exit(struct net *net) kfree(net->dev_index_head); } @@ -158963,7 +158946,7 @@ index ea63120..7fbab94 100644 .init = netdev_init, .exit = netdev_exit, }; -@@ -8244,7 +8244,7 @@ static void __net_exit default_device_exit_batch(struct list_head *net_list) +@@ -8256,7 +8256,7 @@ static void __net_exit default_device_exit_batch(struct list_head *net_list) rtnl_unlock(); } @@ -159305,10 +159288,10 @@ index 53599bd..cbd0b29 100644 iph->ttl = 64; iph->protocol = IPPROTO_UDP; diff --git a/net/core/pktgen.c b/net/core/pktgen.c -index bbd118b..c1c33449 100644 +index 306b8f0..0214187 100644 --- a/net/core/pktgen.c +++ b/net/core/pktgen.c -@@ -3865,7 +3865,7 @@ static int __net_init pg_net_init(struct net *net) +@@ -3867,7 +3867,7 @@ static int __net_init pg_net_init(struct net *net) pn->net = net; INIT_LIST_HEAD(&pn->pktgen_threads); pn->pktgen_exiting = false; @@ -160069,7 +160052,7 @@ index cb7176c..afd2c62 100644 return NULL; } diff --git a/net/ipv4/af_inet.c b/net/ipv4/af_inet.c -index 55513e6..87546f8 100644 +index eebbc0f..59069ff 100644 --- a/net/ipv4/af_inet.c +++ b/net/ipv4/af_inet.c @@ -1445,7 +1445,7 @@ int inet_recv_error(struct sock *sk, struct msghdr *msg, int len, int *addr_len) @@ -160469,10 +160452,10 @@ index d6feabb..9cb3988 100644 ICMP_PROT_UNREACH, 0); } diff --git a/net/ipv4/ip_sockglue.c b/net/ipv4/ip_sockglue.c -index 71a52f4d..2bab905 100644 +index 11ef96e..6901706 100644 --- a/net/ipv4/ip_sockglue.c +++ b/net/ipv4/ip_sockglue.c -@@ -1325,7 +1325,8 @@ static int do_ip_getsockopt(struct sock *sk, int level, int optname, +@@ -1326,7 +1326,8 @@ static int do_ip_getsockopt(struct sock *sk, int level, int optname, len = min_t(unsigned int, len, opt->optlen); if (put_user(len, optlen)) return -EFAULT; @@ -160482,7 +160465,7 @@ index 71a52f4d..2bab905 100644 return -EFAULT; return 0; } -@@ -1461,7 +1462,7 @@ static int do_ip_getsockopt(struct sock *sk, int level, int optname, +@@ -1462,7 +1463,7 @@ static int do_ip_getsockopt(struct sock *sk, int level, int optname, if (sk->sk_type != SOCK_STREAM) return -ENOPROTOOPT; @@ -160997,7 +160980,7 @@ index 62c3ed0..a3694bf 100644 ip_tstamps = kcalloc(IP_IDENTS_SZ, sizeof(*ip_tstamps), GFP_KERNEL); if (!ip_tstamps) diff --git a/net/ipv4/sysctl_net_ipv4.c b/net/ipv4/sysctl_net_ipv4.c -index 1cb67de..2acf1f0 100644 +index 80bc36b..d70d622 100644 --- a/net/ipv4/sysctl_net_ipv4.c +++ b/net/ipv4/sysctl_net_ipv4.c @@ -66,7 +66,7 @@ static int ipv4_local_port_range(struct ctl_table *table, int write, @@ -161312,7 +161295,7 @@ index f712b41..b651403 100644 syn_set ? 0 : icsk->icsk_user_timeout, syn_set)) { /* Has it gone just too far? */ diff --git a/net/ipv4/udp.c b/net/ipv4/udp.c -index 5fdcb8d..e9d917f 100644 +index c0d71e7..f4b404a3 100644 --- a/net/ipv4/udp.c +++ b/net/ipv4/udp.c @@ -87,6 +87,7 @@ @@ -161535,7 +161518,7 @@ index 542074c..648df74 100644 sizeof(XFRM_MODE_SKB_CB(skb)->flow_lbl)); diff --git a/net/ipv6/addrconf.c b/net/ipv6/addrconf.c -index 2f1f5d4..b8eadc4 100644 +index f5432d6..42b4ef0 100644 --- a/net/ipv6/addrconf.c +++ b/net/ipv6/addrconf.c @@ -179,7 +179,7 @@ static struct ipv6_devconf ipv6_devconf __read_mostly = { @@ -161807,7 +161790,7 @@ index edc3daa..c951634 100644 .maxtype = IFLA_GRE_MAX, .policy = ip6gre_policy, diff --git a/net/ipv6/ip6_tunnel.c b/net/ipv6/ip6_tunnel.c -index 888543d..bcc126c 100644 +index 41489f3..62a4ed4 100644 --- a/net/ipv6/ip6_tunnel.c +++ b/net/ipv6/ip6_tunnel.c @@ -80,7 +80,7 @@ static u32 HASH(const struct in6_addr *addr1, const struct in6_addr *addr2) @@ -161819,7 +161802,7 @@ index 888543d..bcc126c 100644 static int ip6_tnl_net_id __read_mostly; struct ip6_tnl_net { -@@ -1994,7 +1994,7 @@ static const struct nla_policy ip6_tnl_policy[IFLA_IPTUN_MAX + 1] = { +@@ -1997,7 +1997,7 @@ static const struct nla_policy ip6_tnl_policy[IFLA_IPTUN_MAX + 1] = { [IFLA_IPTUN_ENCAP_DPORT] = { .type = NLA_U16 }, }; @@ -162200,10 +162183,10 @@ index 2160d5d..6816c42 100644 return -ENOMEM; } diff --git a/net/ipv6/route.c b/net/ipv6/route.c -index 269218a..3b9358f 100644 +index 23153ac..08b47f9 100644 --- a/net/ipv6/route.c +++ b/net/ipv6/route.c -@@ -3571,7 +3571,7 @@ struct ctl_table ipv6_route_table_template[] = { +@@ -3573,7 +3573,7 @@ struct ctl_table ipv6_route_table_template[] = { struct ctl_table * __net_init ipv6_route_sysctl_init(struct net *net) { @@ -162248,7 +162231,7 @@ index 69c50e7..ec875fa 100644 struct ctl_table *ipv6_icmp_table; int err; diff --git a/net/ipv6/tcp_ipv6.c b/net/ipv6/tcp_ipv6.c -index 94f4f89..74404a9 100644 +index fc67822..e20c9c3 100644 --- a/net/ipv6/tcp_ipv6.c +++ b/net/ipv6/tcp_ipv6.c @@ -101,6 +101,10 @@ static void inet6_sk_rx_dst_set(struct sock *sk, const struct sk_buff *skb) @@ -162262,7 +162245,7 @@ index 94f4f89..74404a9 100644 static __u32 tcp_v6_init_sequence(const struct sk_buff *skb) { return secure_tcpv6_sequence_number(ipv6_hdr(skb)->daddr.s6_addr32, -@@ -1289,6 +1293,9 @@ static int tcp_v6_do_rcv(struct sock *sk, struct sk_buff *skb) +@@ -1299,6 +1303,9 @@ static int tcp_v6_do_rcv(struct sock *sk, struct sk_buff *skb) return 0; reset: @@ -162272,7 +162255,7 @@ index 94f4f89..74404a9 100644 tcp_v6_send_reset(sk, skb); discard: if (opt_skb) -@@ -1401,12 +1408,20 @@ lookup: +@@ -1403,12 +1410,20 @@ lookup: sk = __inet6_lookup_skb(&tcp_hashinfo, skb, __tcp_hdrlen(th), th->source, th->dest, inet6_iif(skb), &refcounted); @@ -162295,7 +162278,7 @@ index 94f4f89..74404a9 100644 if (sk->sk_state == TCP_NEW_SYN_RECV) { struct request_sock *req = inet_reqsk(sk); -@@ -1496,6 +1511,10 @@ csum_error: +@@ -1498,6 +1513,10 @@ csum_error: bad_packet: __TCP_INC_STATS(net, TCP_MIB_INERRS); } else { @@ -162307,7 +162290,7 @@ index 94f4f89..74404a9 100644 } diff --git a/net/ipv6/udp.c b/net/ipv6/udp.c -index 19ac3a1..6b586db 100644 +index c2a8656..cef76e9 100644 --- a/net/ipv6/udp.c +++ b/net/ipv6/udp.c @@ -78,6 +78,10 @@ static u32 udp6_ehashfn(const struct net *net, @@ -162330,7 +162313,7 @@ index 19ac3a1..6b586db 100644 if (is_udp4) UDP_INC_STATS(sock_net(sk), UDP_MIB_INERRORS, is_udplite); -@@ -646,7 +650,7 @@ csum_error: +@@ -647,7 +651,7 @@ csum_error: __UDP6_INC_STATS(sock_net(sk), UDP_MIB_CSUMERRORS, is_udplite); drop: __UDP6_INC_STATS(sock_net(sk), UDP_MIB_INERRORS, is_udplite); @@ -162339,7 +162322,7 @@ index 19ac3a1..6b586db 100644 kfree_skb(skb); return -1; } -@@ -727,7 +731,7 @@ start_lookup: +@@ -728,7 +732,7 @@ start_lookup: } nskb = skb_clone(skb, GFP_ATOMIC); if (unlikely(!nskb)) { @@ -162348,7 +162331,7 @@ index 19ac3a1..6b586db 100644 __UDP6_INC_STATS(net, UDP_MIB_RCVBUFERRORS, IS_UDPLITE(sk)); __UDP6_INC_STATS(net, UDP_MIB_INERRORS, -@@ -845,6 +849,9 @@ int __udp6_lib_rcv(struct sk_buff *skb, struct udp_table *udptable, +@@ -846,6 +850,9 @@ int __udp6_lib_rcv(struct sk_buff *skb, struct udp_table *udptable, goto csum_error; __UDP6_INC_STATS(net, UDP_MIB_NOPORTS, proto == IPPROTO_UDPLITE); @@ -164708,7 +164691,7 @@ index 11de55e..f25e448 100644 return 0; } diff --git a/net/netlink/af_netlink.c b/net/netlink/af_netlink.c -index 627f898c..32d06cc 100644 +index 62bea45..94c8501 100644 --- a/net/netlink/af_netlink.c +++ b/net/netlink/af_netlink.c @@ -287,7 +287,7 @@ static void netlink_overrun(struct sock *sk) @@ -164735,7 +164718,7 @@ index 627f898c..32d06cc 100644 } static int netlink_sendmsg(struct socket *sock, struct msghdr *msg, size_t len) -@@ -2150,7 +2151,9 @@ errout_skb: +@@ -2151,7 +2152,9 @@ errout_skb: int __netlink_dump_start(struct sock *ssk, struct sk_buff *skb, const struct nlmsghdr *nlh, @@ -164746,7 +164729,7 @@ index 627f898c..32d06cc 100644 { struct netlink_callback *cb; struct sock *sk; -@@ -2173,7 +2176,7 @@ int __netlink_dump_start(struct sock *ssk, struct sk_buff *skb, +@@ -2174,7 +2177,7 @@ int __netlink_dump_start(struct sock *ssk, struct sk_buff *skb, goto error_unlock; } /* add reference of module which cb->dump belongs to */ @@ -164755,7 +164738,7 @@ index 627f898c..32d06cc 100644 ret = -EPROTONOSUPPORT; goto error_unlock; } -@@ -2184,8 +2187,8 @@ int __netlink_dump_start(struct sock *ssk, struct sk_buff *skb, +@@ -2185,8 +2188,8 @@ int __netlink_dump_start(struct sock *ssk, struct sk_buff *skb, cb->dump = control->dump; cb->done = control->done; cb->nlh = nlh; @@ -164766,7 +164749,7 @@ index 627f898c..32d06cc 100644 cb->min_dump_alloc = control->min_dump_alloc; cb->skb = skb; -@@ -2452,7 +2455,7 @@ static int netlink_seq_show(struct seq_file *seq, void *v) +@@ -2453,7 +2456,7 @@ static int netlink_seq_show(struct seq_file *seq, void *v) sk_wmem_alloc_get(s), nlk->cb_running, atomic_read(&s->sk_refcnt), @@ -164775,7 +164758,7 @@ index 627f898c..32d06cc 100644 sock_i_ino(s) ); -@@ -2559,7 +2562,7 @@ static void __init netlink_add_usersock_entry(void) +@@ -2560,7 +2563,7 @@ static void __init netlink_add_usersock_entry(void) netlink_table_ungrab(); } @@ -164948,19 +164931,19 @@ index 7eb955e..479c9a6 100644 static int __init ovs_vxlan_tnl_init(void) diff --git a/net/packet/af_packet.c b/net/packet/af_packet.c -index 33a4697..c3f149fb 100644 +index d2238b2..7123b3f 100644 --- a/net/packet/af_packet.c +++ b/net/packet/af_packet.c -@@ -279,7 +279,7 @@ static int packet_direct_xmit(struct sk_buff *skb) +@@ -278,7 +278,7 @@ static int packet_direct_xmit(struct sk_buff *skb) return ret; drop: - atomic_long_inc(&dev->tx_dropped); + atomic_long_inc_unchecked(&dev->tx_dropped); - kfree_skb(skb); + kfree_skb_list(skb); return NET_XMIT_DROP; } -@@ -1392,9 +1392,9 @@ static unsigned int fanout_demux_rollover(struct packet_fanout *f, +@@ -1391,9 +1391,9 @@ static unsigned int fanout_demux_rollover(struct packet_fanout *f, packet_rcv_has_room(po_next, skb) == ROOM_NORMAL) { if (i != j) po->rollover->sock = i; @@ -164972,7 +164955,7 @@ index 33a4697..c3f149fb 100644 return i; } -@@ -1402,7 +1402,7 @@ static unsigned int fanout_demux_rollover(struct packet_fanout *f, +@@ -1401,7 +1401,7 @@ static unsigned int fanout_demux_rollover(struct packet_fanout *f, i = 0; } while (i != j); @@ -164981,7 +164964,7 @@ index 33a4697..c3f149fb 100644 return idx; } -@@ -1653,9 +1653,9 @@ static int fanout_add(struct sock *sk, u16 id, u16 type_flags) +@@ -1652,9 +1652,9 @@ static int fanout_add(struct sock *sk, u16 id, u16 type_flags) po->rollover = kzalloc(sizeof(*po->rollover), GFP_KERNEL); if (!po->rollover) return -ENOMEM; @@ -164994,7 +164977,7 @@ index 33a4697..c3f149fb 100644 } mutex_lock(&fanout_mutex); -@@ -2107,7 +2107,7 @@ drop_n_acct: +@@ -2106,7 +2106,7 @@ drop_n_acct: is_drop_n_account = true; spin_lock(&sk->sk_receive_queue.lock); po->stats.stats1.tp_drops++; @@ -165003,7 +164986,7 @@ index 33a4697..c3f149fb 100644 spin_unlock(&sk->sk_receive_queue.lock); drop_n_restore: -@@ -3842,7 +3842,7 @@ static int packet_getsockopt(struct socket *sock, int level, int optname, +@@ -3841,7 +3841,7 @@ static int packet_getsockopt(struct socket *sock, int level, int optname, case PACKET_HDRLEN: if (len > sizeof(int)) len = sizeof(int); @@ -165012,7 +164995,7 @@ index 33a4697..c3f149fb 100644 return -EFAULT; switch (val) { case TPACKET_V1: -@@ -3877,9 +3877,9 @@ static int packet_getsockopt(struct socket *sock, int level, int optname, +@@ -3876,9 +3876,9 @@ static int packet_getsockopt(struct socket *sock, int level, int optname, case PACKET_ROLLOVER_STATS: if (!po->rollover) return -EINVAL; @@ -165025,7 +165008,7 @@ index 33a4697..c3f149fb 100644 data = &rstats; lv = sizeof(rstats); break; -@@ -3897,7 +3897,7 @@ static int packet_getsockopt(struct socket *sock, int level, int optname, +@@ -3896,7 +3896,7 @@ static int packet_getsockopt(struct socket *sock, int level, int optname, len = lv; if (put_user(len, optlen)) return -EFAULT; @@ -165675,7 +165658,7 @@ index 12d4519..367dae4 100644 NULL, sctp_cname, sctp_tname, sctp_oname, sctp_pname, }; diff --git a/net/sctp/socket.c b/net/sctp/socket.c -index 8ed2d99..ac059f5 100644 +index baccbf3..aed4ec2 100644 --- a/net/sctp/socket.c +++ b/net/sctp/socket.c @@ -2199,11 +2199,13 @@ static int sctp_setsockopt_events(struct sock *sk, char __user *optval, @@ -165699,7 +165682,7 @@ index 8ed2d99..ac059f5 100644 { + struct sctp_event_subscribe subscribe; + - if (len <= 0) + if (len == 0) return -EINVAL; if (len > sizeof(struct sctp_event_subscribe)) len = sizeof(struct sctp_event_subscribe); @@ -169524,10 +169507,10 @@ index 0000000..7514850 +fi diff --git a/scripts/gcc-plugins/initify_plugin.c b/scripts/gcc-plugins/initify_plugin.c new file mode 100644 -index 0000000..0c0cf81 +index 0000000..bdd5d64 --- /dev/null +++ b/scripts/gcc-plugins/initify_plugin.c -@@ -0,0 +1,1804 @@ +@@ -0,0 +1,1811 @@ +/* + * Copyright 2015-2016 by Emese Revfy <re.emese@gmail.com> + * Licensed under the GPL v2 @@ -169577,7 +169560,7 @@ index 0000000..0c0cf81 +__visible int plugin_is_GPL_compatible; + +static struct plugin_info initify_plugin_info = { -+ .version = "20160929", ++ .version = "20161115", + .help = "disable\tturn off the initify plugin\n" + "verbose\tprint all initified strings and all" + " functions which should be __init/__exit\n" @@ -170474,7 +170457,7 @@ index 0000000..0c0cf81 + if (is_gimple_debug(use_stmt)) + continue; + -+ if (pointer_set_contains(visited_defs, use_stmt)) ++ if (pointer_set_insert(visited_defs, use_stmt)) + continue; + + switch (gimple_code(use_stmt)) { @@ -170499,9 +170482,12 @@ index 0000000..0c0cf81 + gassign *assign = as_a_gassign(use_stmt); + const_tree rhs = gimple_assign_rhs1(assign); + ++ if (TREE_CODE(rhs) == INDIRECT_REF) ++ return; ++#if BUILDING_GCC_VERSION >= 4006 + if (TREE_CODE(rhs) == MEM_REF) + return; -+ ++#endif + if (is_cast_to_integer_type(assign)) + return; + @@ -170586,8 +170572,12 @@ index 0000000..0c0cf81 + tree lhs; + const_tree rhs = gimple_assign_rhs1(stmt); + ++ if (TREE_CODE(rhs) == INDIRECT_REF) ++ break; ++#if BUILDING_GCC_VERSION >= 4006 + if (TREE_CODE(rhs) == MEM_REF) + break; ++#endif + + lhs = gimple_assign_lhs(stmt); + if (lhs_is_a_nocapture_parm_decl(lhs)) @@ -217288,10 +217278,10 @@ index b3775a9..be6b9f9 100755 # Find all available archs find_all_archs() diff --git a/security/Kconfig b/security/Kconfig -index 118f454..d1818a1 100644 +index 118f454..5c61f40 100644 --- a/security/Kconfig +++ b/security/Kconfig -@@ -4,6 +4,1066 @@ +@@ -4,6 +4,1065 @@ menu "Security options" @@ -218273,7 +218263,6 @@ index 118f454..d1818a1 100644 +config PAX_INITIFY + bool "Free more kernel memory after init" + depends on GCC_PLUGINS -+ depends on BROKEN + help + The kernel has a mechanism to free up code and data memory that is + only used during kernel or module initialization. Enabling this @@ -218358,7 +218347,7 @@ index 118f454..d1818a1 100644 source security/keys/Kconfig config SECURITY_DMESG_RESTRICT -@@ -104,7 +1164,7 @@ config INTEL_TXT +@@ -104,7 +1163,7 @@ config INTEL_TXT config LSM_MMAP_MIN_ADDR int "Low address space for LSM to protect from user allocation" depends on SECURITY && SECURITY_SELINUX @@ -218367,7 +218356,7 @@ index 118f454..d1818a1 100644 default 65536 help This is the portion of low virtual memory which should be protected -@@ -118,13 +1178,6 @@ config LSM_MMAP_MIN_ADDR +@@ -118,13 +1177,6 @@ config LSM_MMAP_MIN_ADDR this low address space will need the permission specific to the systems running LSM. @@ -218381,7 +218370,7 @@ index 118f454..d1818a1 100644 config HAVE_ARCH_HARDENED_USERCOPY bool help -@@ -134,23 +1187,14 @@ config HAVE_ARCH_HARDENED_USERCOPY +@@ -134,23 +1186,14 @@ config HAVE_ARCH_HARDENED_USERCOPY copy_to_user() and copy_from_user(). config HARDENED_USERCOPY @@ -218408,7 +218397,7 @@ index 118f454..d1818a1 100644 help When a multi-page allocation is done without __GFP_COMP, hardened usercopy will reject attempts to copy it. There are, -@@ -205,4 +1249,3 @@ config DEFAULT_SECURITY +@@ -205,4 +1248,3 @@ config DEFAULT_SECURITY default "" if DEFAULT_SECURITY_DAC endmenu diff --git a/4.8.7/4425_grsec_remove_EI_PAX.patch b/4.8.8/4425_grsec_remove_EI_PAX.patch index 594598a..594598a 100644 --- a/4.8.7/4425_grsec_remove_EI_PAX.patch +++ b/4.8.8/4425_grsec_remove_EI_PAX.patch diff --git a/4.8.7/4427_force_XATTR_PAX_tmpfs.patch b/4.8.8/4427_force_XATTR_PAX_tmpfs.patch index 2562d2f..2562d2f 100644 --- a/4.8.7/4427_force_XATTR_PAX_tmpfs.patch +++ b/4.8.8/4427_force_XATTR_PAX_tmpfs.patch diff --git a/4.8.7/4430_grsec-remove-localversion-grsec.patch b/4.8.8/4430_grsec-remove-localversion-grsec.patch index 31cf878..31cf878 100644 --- a/4.8.7/4430_grsec-remove-localversion-grsec.patch +++ b/4.8.8/4430_grsec-remove-localversion-grsec.patch diff --git a/4.8.7/4435_grsec-mute-warnings.patch b/4.8.8/4435_grsec-mute-warnings.patch index 8929222..8929222 100644 --- a/4.8.7/4435_grsec-mute-warnings.patch +++ b/4.8.8/4435_grsec-mute-warnings.patch diff --git a/4.8.7/4440_grsec-remove-protected-paths.patch b/4.8.8/4440_grsec-remove-protected-paths.patch index 741546d..741546d 100644 --- a/4.8.7/4440_grsec-remove-protected-paths.patch +++ b/4.8.8/4440_grsec-remove-protected-paths.patch diff --git a/4.8.7/4450_grsec-kconfig-default-gids.patch b/4.8.8/4450_grsec-kconfig-default-gids.patch index 6fd0511..6fd0511 100644 --- a/4.8.7/4450_grsec-kconfig-default-gids.patch +++ b/4.8.8/4450_grsec-kconfig-default-gids.patch diff --git a/4.8.7/4465_selinux-avc_audit-log-curr_ip.patch b/4.8.8/4465_selinux-avc_audit-log-curr_ip.patch index 7248385..7248385 100644 --- a/4.8.7/4465_selinux-avc_audit-log-curr_ip.patch +++ b/4.8.8/4465_selinux-avc_audit-log-curr_ip.patch diff --git a/4.8.7/4470_disable-compat_vdso.patch b/4.8.8/4470_disable-compat_vdso.patch index 1e4b84a..1e4b84a 100644 --- a/4.8.7/4470_disable-compat_vdso.patch +++ b/4.8.8/4470_disable-compat_vdso.patch diff --git a/4.8.7/4475_emutramp_default_on.patch b/4.8.8/4475_emutramp_default_on.patch index 7b468ee..7b468ee 100644 --- a/4.8.7/4475_emutramp_default_on.patch +++ b/4.8.8/4475_emutramp_default_on.patch |