Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1368599 > unrolled thread

[4.2.y-ckt stable] Linux 4.2.8-ckt7 stable review

Started byKamal Mostafa <kamal@canonical.com>
First post2016-03-31 22:20 +0200
Last post2016-03-31 23:30 +0200
Articles 20 on this page of 209 — 2 participants

Back to article view | Back to linux.kernel


Contents

  [4.2.y-ckt stable] Linux 4.2.8-ckt7 stable review Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:20 +0200
    [PATCH 4.2.y-ckt 084/218] bcache: fix cache_set_flush() NULL pointer dereference on OOM Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:20 +0200
    [PATCH 4.2.y-ckt 009/218] Input: powermate - fix oops with malicious USB descriptors Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:20 +0200
    [PATCH 4.2.y-ckt 039/218] [media] adv7511: TX_EDID_PRESENT is still 1 after a disconnect Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:20 +0200
    [PATCH 4.2.y-ckt 199/218] bpf: avoid copying junk bytes in bpf_get_current_comm() Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:30 +0200
    [PATCH 4.2.y-ckt 202/218] mac80211: fix ibss scan parameters Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:30 +0200
    [PATCH 4.2.y-ckt 191/218] sched/preempt, sh: kmap_coherent relies on disabled preemption Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:30 +0200
    [PATCH 4.2.y-ckt 200/218] mac80211: fix unnecessary frame drops in mesh fwding Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:30 +0200
    [PATCH 4.2.y-ckt 198/218] kbuild/mkspec: fix grub2 installkernel issue Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:30 +0200
    [PATCH 4.2.y-ckt 197/218] [media] coda: fix error path in case of missing pdata on non-DT platform Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:30 +0200
    [PATCH 4.2.y-ckt 196/218] clk: meson: Fix meson_clk_register_clks() signature type mismatch Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:30 +0200
    [PATCH 4.2.y-ckt 213/218] ARM: prima2: always enable reset controller Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:30 +0200
    [PATCH 4.2.y-ckt 193/218] spi/rockchip: Make sure spi clk is on in rockchip_spi_set_cs Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:30 +0200
    [PATCH 4.2.y-ckt 188/218] sunrpc/cache: drop reference when sunrpc_cache_pipe_upcall() detects a race Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:30 +0200
    [PATCH 4.2.y-ckt 207/218] paride: make 'verbose' parameter an 'int' again Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:30 +0200
    [PATCH 4.2.y-ckt 211/218] net: add description for len argument of dev_get_phys_port_name Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:30 +0200
    [PATCH 4.2.y-ckt 214/218] drivers/misc/ad525x_dpot: AD5274 fix RDAC read back errors Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:30 +0200
    [PATCH 4.2.y-ckt 186/218] efi: Expose non-blocking set_variable() wrapper to efivars Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:30 +0200
    [PATCH 4.2.y-ckt 189/218] ipv4: fix broadcast packets reception Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:30 +0200
    [PATCH 4.2.y-ckt 159/218] mdio-sun4i: oops in error handling in probe Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:30 +0200
    [PATCH 4.2.y-ckt 205/218] perf pmu: Fix misleadingly indented assignment (whitespace) Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:30 +0200
    [PATCH 4.2.y-ckt 204/218] rtc: hym8563: fix invalid year calculation Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:30 +0200
    [PATCH 4.2.y-ckt 190/218] lpfc: fix misleading indentation Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:30 +0200
    [PATCH 4.2.y-ckt 203/218] at803x: fix reset handling Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:30 +0200
    [PATCH 4.2.y-ckt 210/218] clk: versatile: sp810: support reentrance Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:30 +0200
    [PATCH 4.2.y-ckt 217/218] ipvs: drop first packet to redirect conntrack Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:30 +0200
    [PATCH 4.2.y-ckt 209/218] ppp: ensure file->private_data can't be overridden Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:30 +0200
    [PATCH 4.2.y-ckt 218/218] rtc: max77686: Properly handle regmap_irq_get_virq() error code Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:30 +0200
    [PATCH 4.2.y-ckt 141/218] target: Fix target_release_cmd_kref shutdown comp leak Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:30 +0200
    [PATCH 4.2.y-ckt 208/218] regulator: s5m8767: fix get_register() error handling Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:30 +0200
    [PATCH 4.2.y-ckt 215/218] perf stat: Document --detailed option Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:30 +0200
    [PATCH 4.2.y-ckt 201/218] mtd: brcmnand: Fix v7.1 register offsets Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:30 +0200
    [PATCH 4.2.y-ckt 206/218] nbd: ratelimit error msgs after socket close Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:30 +0200
    [PATCH 4.2.y-ckt 185/218] ARM: OMAP3: Add cpuidle parameters table for omap3430 Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:30 +0200
    RE: [PATCH 4.2.y-ckt 092/218] EDAC/sb_edac: Fix computation of  channel address "Luck, Tony" <tony.luck@intel.com> - 2016-03-31 22:30 +0200
    [PATCH 4.2.y-ckt 216/218] [media] v4l: vsp1: Set the SRU CTRL0 register when starting the stream Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:30 +0200
    [PATCH 4.2.y-ckt 133/218] tracing: Have preempt(irqs)off trace preempt disabled functions Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:30 +0200
    [PATCH 4.2.y-ckt 212/218] net: bcmgenet: fix dma api length mismatch Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:30 +0200
    [PATCH 4.2.y-ckt 154/218] mac80211: avoid excessive stack usage in sta_info Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:40 +0200
    [PATCH 4.2.y-ckt 177/218] spi: rockchip: modify DMA max burst to 1 Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:40 +0200
    [PATCH 4.2.y-ckt 167/218] megaraid_sas: add missing curly braces in ioctl handler Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:40 +0200
    [PATCH 4.2.y-ckt 161/218] ARC: bitops: Remove non relevant comments Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:40 +0200
    [PATCH 4.2.y-ckt 170/218] HID: logitech: fix Dual Action gamepad support Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:40 +0200
    [PATCH 4.2.y-ckt 187/218] rtc: vr41xx: Wire up alarm_irq_enable Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:40 +0200
    [PATCH 4.2.y-ckt 180/218] perf tools: handle spaces in file names obtained from /proc/pid/maps Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:40 +0200
    [PATCH 4.2.y-ckt 176/218] drm/i915: Cleanup phys status page too Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:40 +0200
    [PATCH 4.2.y-ckt 183/218] drm/amdkfd: uninitialized variable in dbgdev_wave_control_set_registers() Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:40 +0200
    [PATCH 4.2.y-ckt 181/218] rtc: ds1685: passing bogus values to irq_restore Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:40 +0200
    [PATCH 4.2.y-ckt 162/218] mac80211: fix txq queue related crashes Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:40 +0200
    [PATCH 4.2.y-ckt 179/218] ath9k: fix buffer overrun for ar9287 Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:40 +0200
    [PATCH 4.2.y-ckt 192/218] ipip: Properly mark ipip GRO packets as encapsulated. Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:40 +0200
    [PATCH 4.2.y-ckt 171/218] net/mlx5: Make command timeout way shorter Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:40 +0200
    [PATCH 4.2.y-ckt 163/218] net: Fix use after free in the recvmmsg exit path Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:40 +0200
    [PATCH 4.2.y-ckt 175/218] ipvs: correct initial offset of Call-ID header search in SIP persistence engine Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:40 +0200
    [PATCH 4.2.y-ckt 174/218] clk: qcom: msm8960: fix ce3_core clk enable register Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:40 +0200
    [PATCH 4.2.y-ckt 165/218] sctp: fix the transports round robin issue when init is retransmitted Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:40 +0200
    [PATCH 4.2.y-ckt 169/218] misc/bmp085: Enable building as a module Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:40 +0200
    [PATCH 4.2.y-ckt 172/218] ASoC: ssm4567: Reset device before regcache_sync() Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:40 +0200
    [PATCH 4.2.y-ckt 140/218] bitops: Do not default to __clear_bit() for __clear_bit_unlock() Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:40 +0200
    [PATCH 4.2.y-ckt 164/218] ath9k: fix misleading indentation Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:40 +0200
    [PATCH 4.2.y-ckt 153/218] mm/page_alloc: prevent merging between isolated and other pageblocks Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:40 +0200
    [PATCH 4.2.y-ckt 195/218] mlx4: add missing braces in verify_qp_parameters Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:40 +0200
    [PATCH 4.2.y-ckt 121/218] x86/iopl: Fix iopl capability check on Xen PV Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:40 +0200
    [PATCH 4.2.y-ckt 166/218] ethernet: micrel: fix some error codes Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:40 +0200
    [PATCH 4.2.y-ckt 145/218] fs/coredump: prevent fsuid=0 dumps into user-controlled directories Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:40 +0200
    [PATCH 4.2.y-ckt 173/218] fbdev: da8xx-fb: fix videomodes of lcd panels Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:40 +0200
    [PATCH 4.2.y-ckt 182/218] ARM: davinci: make I2C support optional Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:40 +0200
    [PATCH 4.2.y-ckt 184/218] mtd: map: fix .set_vpp() documentation Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:40 +0200
    [PATCH 4.2.y-ckt 151/218] ocfs2/dlm: fix race between convert and recovery Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:40 +0200
    [PATCH 4.2.y-ckt 168/218] clk-divider: make sure read-only dividers do not write to their register Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:40 +0200
    [PATCH 4.2.y-ckt 194/218] ASoC: s3c24xx: use const snd_soc_component_driver pointer Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:40 +0200
    [PATCH 4.2.y-ckt 178/218] ata: ahci_xgene: dereferencing uninitialized pointer in probe Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:40 +0200
    [PATCH 4.2.y-ckt 124/218] drm/amdgpu: include the right version of gmc header files for iceland Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:50 +0200
    [PATCH 4.2.y-ckt 137/218] writeback, cgroup: fix premature wb_put() in locked_inode_to_wb_and_lock_list() Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:50 +0200
    [PATCH 4.2.y-ckt 138/218] fs-writeback: unplug before cond_resched in writeback_sb_inodes Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:50 +0200
    [PATCH 4.2.y-ckt 150/218] MAINTAINERS: Update mailing list and web page for hwmon subsystem Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:50 +0200
    [PATCH 4.2.y-ckt 132/218] USB: uas: Reduce can_queue to MAX_CMNDS Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:50 +0200
    [PATCH 4.2.y-ckt 134/218] tracing: Fix crash from reading trace_pipe with sendfile Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:50 +0200
    [PATCH 4.2.y-ckt 143/218] KVM: fix spin_lock_init order on x86 Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:50 +0200
    [PATCH 4.2.y-ckt 149/218] ideapad-laptop: Add ideapad Y700 (15) to the no_hw_rfkill DMI list Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:50 +0200
    [PATCH 4.2.y-ckt 155/218] clk: xgene: Add missing parenthesis when clearing divider value Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:50 +0200
    [PATCH 4.2.y-ckt 139/218] writeback, cgroup: fix use of the wrong bdi_writeback which mismatches the inode Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:50 +0200
    [PATCH 4.2.y-ckt 144/218] tracing: Fix trace_printk() to print when not using bprintk() Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:50 +0200
    [PATCH 4.2.y-ckt 146/218] rapidio/rionet: fix deadlock on SMP Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:50 +0200
    [PATCH 4.2.y-ckt 158/218] ppp: take reference on channels netns Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:50 +0200
    [PATCH 4.2.y-ckt 130/218] x86/apic: Fix suspicious RCU usage in smp_trace_call_function_interrupt() Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:50 +0200
    [PATCH 4.2.y-ckt 136/218] ALSA: usb-audio: add Microsoft HD-5001 to quirks Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:50 +0200
    [PATCH 4.2.y-ckt 131/218] USB: usb_driver_claim_interface: add sanity checking Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:50 +0200
    [PATCH 4.2.y-ckt 148/218] staging: android: ion_test: fix check of platform_device_register_simple() error code Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:50 +0200
    [PATCH 4.2.y-ckt 157/218] xen kconfig: don't "select INPUT_XEN_KBDDEV_FRONTEND" Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:50 +0200
    [PATCH 4.2.y-ckt 147/218] staging: comedi: ni_mio_common: fix the ni_write[blw]() functions Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:50 +0200
    [PATCH 4.2.y-ckt 142/218] KVM: VMX: avoid guest hang on invalid invept instruction Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:50 +0200
    [PATCH 4.2.y-ckt 126/218] watchdog: don't run proc_watchdog_update if new value is same as old Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:50 +0200
    [PATCH 4.2.y-ckt 135/218] splice: handle zero nr_pages in splice_to_pipe() Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:50 +0200
    [PATCH 4.2.y-ckt 129/218] Input: synaptics - handle spurious release of trackstick buttons, again Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:50 +0200
    [PATCH 4.2.y-ckt 120/218] vfs: show_vfsstat: do not ignore errors from show_devname method Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:50 +0200
    [PATCH 4.2.y-ckt 160/218] clk: rockchip: free memory in error cases when registering clock branches Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:50 +0200
    [PATCH 4.2.y-ckt 127/218] mm: memcontrol: reclaim when shrinking memory.high below usage Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:50 +0200
    [PATCH 4.2.y-ckt 156/218] clk: qcom: msm8960: Fix ce3_src register offset Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:50 +0200
    [PATCH 4.2.y-ckt 152/218] ocfs2/dlm: fix BUG in dlm_move_lockres_to_recovery_list Kamal Mostafa <kamal@canonical.com> - 2016-03-31 22:50 +0200
    [PATCH 4.2.y-ckt 114/218] net: mvneta: enable change MAC address when interface is up Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:00 +0200
    [PATCH 4.2.y-ckt 105/218] Bluetooth: Fix potential buffer overflow with Add Advertising Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:00 +0200
    [PATCH 4.2.y-ckt 104/218] xtensa: clear all DBREAKC registers on start Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:00 +0200
    [PATCH 4.2.y-ckt 119/218] nfsd: fix deadlock secinfo+readdir compound Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:00 +0200
    [PATCH 4.2.y-ckt 079/218] perf/x86/intel: Use PAGE_SIZE for PEBS buffer size on Core2 Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:00 +0200
    [PATCH 4.2.y-ckt 089/218] sg: fix dxferp in from_to case Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:00 +0200
    [PATCH 4.2.y-ckt 110/218] fuse: Add reference counting for fuse_io_priv Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:00 +0200
    [PATCH 4.2.y-ckt 106/218] ARC: [BE] readl()/writel() to work in Big Endian CPU configuration Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:00 +0200
    [PATCH 4.2.y-ckt 118/218] mmc: mmc_spi: Add Card Detect comments and fix CD GPIO case Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:00 +0200
    [PATCH 4.2.y-ckt 091/218] ALSA: hda - Apply reboot D3 fix for CX20724 codec, too Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:00 +0200
    [PATCH 4.2.y-ckt 102/218] xtensa: ISS: don't hang if stdin EOF is reached Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:00 +0200
    [PATCH 4.2.y-ckt 092/218] EDAC/sb_edac: Fix computation of channel address Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:00 +0200
    [PATCH 4.2.y-ckt 108/218] ALSA: intel8x0: Add clock quirk entry for AD1981B on IBM ThinkPad X41. Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:00 +0200
    [PATCH 4.2.y-ckt 080/218] perf/x86/intel: Fix PEBS warning by only restoring active PMU in pmi Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:00 +0200
    [PATCH 4.2.y-ckt 123/218] mmc: sdhci: Fix override of timeout clk wrt max_busy_timeout Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:00 +0200
    [PATCH 4.2.y-ckt 117/218] ALSA: hda - Fix unconditional GPIO toggle via automute Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:00 +0200
    [PATCH 4.2.y-ckt 128/218] mm: memcontrol: reclaim and OOM kill when shrinking memory.max below usage Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:00 +0200
    [PATCH 4.2.y-ckt 109/218] fuse: do not use iocb after it may have been freed Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:00 +0200
    [PATCH 4.2.y-ckt 101/218] ALSA: hda - fix the mic mute button and led problem for a Lenovo AIO Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:00 +0200
    [PATCH 4.2.y-ckt 115/218] dm: fix rq_end_stats() NULL pointer in dm_requeue_original_request() Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:00 +0200
    [PATCH 4.2.y-ckt 107/218] bus: imx-weim: Take the 'status' property value into account Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:00 +0200
    [PATCH 4.2.y-ckt 103/218] xtensa: fix preemption in {clear,copy}_user_highpage Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:00 +0200
    [PATCH 4.2.y-ckt 097/218] dm cache: make sure every metadata function checks fail_io Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:00 +0200
    [PATCH 4.2.y-ckt 112/218] drm/radeon: rework fbdev handling on chips with no connectors Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:00 +0200
    [PATCH 4.2.y-ckt 111/218] s390/pci: enforce fmb page boundary rule Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:00 +0200
    [PATCH 4.2.y-ckt 116/218] HID: i2c-hid: fix OOB write in i2c_hid_set_or_send_report() Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:00 +0200
    [PATCH 4.2.y-ckt 083/218] bcache: cleaned up error handling around register_cache() Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:10 +0200
    [PATCH 4.2.y-ckt 072/218] usb: hub: fix a typo in hub_port_init() leading to wrong logic Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:10 +0200
    [PATCH 4.2.y-ckt 088/218] drm/radeon: Don't drop DP 2.7 Ghz link setup on some cards. Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:10 +0200
    [PATCH 4.2.y-ckt 087/218] md/raid5: preserve STRIPE_PREREAD_ACTIVE in break_stripe_batch_list Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:10 +0200
    [PATCH 4.2.y-ckt 093/218] Bluetooth: btusb: Add a new AR3012 ID 13d3:3472 Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:10 +0200
    [PATCH 4.2.y-ckt 099/218] iser-target: Add new state ISER_CONN_BOUND to isert_conn Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:10 +0200
    [PATCH 4.2.y-ckt 100/218] iser-target: Separate flows for np listeners and connections cma events Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:10 +0200
    [PATCH 4.2.y-ckt 065/218] mtip32xx: Remove unwanted code from taskfile error handler Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:10 +0200
    [PATCH 4.2.y-ckt 090/218] jbd2: fix FS corruption possibility in jbd2_journal_destroy() on umount path Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:10 +0200
    [PATCH 4.2.y-ckt 071/218] of: alloc anywhere from memblock if range not specified Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:10 +0200
    [PATCH 4.2.y-ckt 067/218] mtip32xx: Avoid issuing standby immediate cmd during FTL rebuild Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:10 +0200
    [PATCH 4.2.y-ckt 096/218] dm thin metadata: don't issue prefetches if a transaction abort has failed Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:10 +0200
    [PATCH 4.2.y-ckt 077/218] pinctrl-bcm2835: Fix cut-and-paste error in "pull" parsing Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:10 +0200
    [PATCH 4.2.y-ckt 066/218] mtip32xx: Print exact time when an internal command is interrupted Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:10 +0200
    [PATCH 4.2.y-ckt 094/218] ALSA: pcm: Avoid "BUG:" string for warnings again Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:10 +0200
    [PATCH 4.2.y-ckt 085/218] x86/PCI: Mark Broadwell-EP Home Agent & PCU as having non-compliant BARs Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:10 +0200
    [PATCH 4.2.y-ckt 070/218] mtip32xx: Handle FTL rebuild failure state during device initialization Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:10 +0200
    [PATCH 4.2.y-ckt 073/218] KVM: i8254: change PIT discard tick policy Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:10 +0200
    [PATCH 4.2.y-ckt 098/218] iser-target: Fix identification of login rx descriptor type Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:10 +0200
    [PATCH 4.2.y-ckt 078/218] perf/core: Fix perf_sched_count derailment Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:10 +0200
    [PATCH 4.2.y-ckt 064/218] mtip32xx: Fix broken service thread handling Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:10 +0200
    [PATCH 4.2.y-ckt 074/218] sched/cputime: Fix steal time accounting vs. CPU hotplug Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:10 +0200
    [PATCH 4.2.y-ckt 069/218] mtip32xx: Handle safe removal during IO Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:10 +0200
    [PATCH 4.2.y-ckt 082/218] bcache: fix race of writeback thread starting before complete initialization Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:10 +0200
    [PATCH 4.2.y-ckt 095/218] dm snapshot: disallow the COW and origin devices from being identical Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:10 +0200
    [PATCH 4.2.y-ckt 081/218] sched/cputime: Fix steal_account_process_tick() to always return jiffies Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:10 +0200
    [PATCH 4.2.y-ckt 050/218] md/raid5: Compare apples to apples (or sectors to sectors) Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:20 +0200
    [PATCH 4.2.y-ckt 042/218] perf tools: Dont stop PMU parsing on alias parse error Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:20 +0200
    [PATCH 4.2.y-ckt 036/218] usb: retry reset if a device times out Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:20 +0200
    [PATCH 4.2.y-ckt 049/218] PCI: Disable IO/MEM decoding for devices with non-compliant BARs Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:20 +0200
    [PATCH 4.2.y-ckt 034/218] tpm: fix the cleanup of struct tpm_chip Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:20 +0200
    [PATCH 4.2.y-ckt 028/218] net: irda: Fix use-after-free in irtty_open() Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:20 +0200
    [PATCH 4.2.y-ckt 061/218] nfsd4: fix bad bounds checking Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:20 +0200
    [PATCH 4.2.y-ckt 053/218] crypto: ccp - memset request context to zero during import Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:20 +0200
    [PATCH 4.2.y-ckt 041/218] tpm_crb: tpm2_shutdown() must be called before tpm_chip_unregister() Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:20 +0200
    [PATCH 4.2.y-ckt 051/218] RAID5: check_reshape() shouldn't call mddev_suspend Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:20 +0200
    [PATCH 4.2.y-ckt 060/218] watchdog: rc32434_wdt: fix ioctl error handling Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:20 +0200
    [PATCH 4.2.y-ckt 026/218] crypto: ccp - Don't assume export/import areas are aligned Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:20 +0200
    [PATCH 4.2.y-ckt 035/218] ARM: dts: armada-375: use armada-370-sata for SATA Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:20 +0200
    [PATCH 4.2.y-ckt 057/218] perf tools: Fix python extension build Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:20 +0200
    [PATCH 4.2.y-ckt 063/218] quota: Fix possible GPF due to uninitialised pointers Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:20 +0200
    [PATCH 4.2.y-ckt 062/218] xfs: fix two memory leaks in xfs_attr_list.c error paths Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:20 +0200
    [PATCH 4.2.y-ckt 054/218] Bluetooth: btusb: Add a new AR3012 ID 04ca:3014 Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:20 +0200
    [PATCH 4.2.y-ckt 068/218] mtip32xx: Fix for rmmod crash when drive is in FTL rebuild Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:20 +0200
    [PATCH 4.2.y-ckt 058/218] IB/srpt: Simplify srpt_handle_tsk_mgmt() Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:20 +0200
    [PATCH 4.2.y-ckt 043/218] Bluetooth: btusb: Add new AR3012 ID 13d3:3395 Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:20 +0200
    [PATCH 4.2.y-ckt 052/218] RAID5: revert e9e4c377e2f563 to fix a livelock Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:20 +0200
    [PATCH 4.2.y-ckt 038/218] scripts/coccinelle: modernize & Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:20 +0200
    [PATCH 4.2.y-ckt 047/218] aic7xxx: Fix queue depth handling Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:20 +0200
    [PATCH 4.2.y-ckt 055/218] mmc: sdhci: fix data timeout (part 1) Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:20 +0200
    [PATCH 4.2.y-ckt 048/218] mtd: onenand: fix deadlock in onenand_block_markbad Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:20 +0200
    [PATCH 4.2.y-ckt 056/218] mmc: sdhci: fix data timeout (part 2) Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:20 +0200
    [PATCH 4.2.y-ckt 040/218] [media] saa7134: Fix bytesperline not being set correctly for planar formats Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:20 +0200
    [PATCH 4.2.y-ckt 037/218] HID: fix hid_ignore_special_drivers module parameter Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:20 +0200
    [PATCH 4.2.y-ckt 044/218] Bluetooth: Add new AR3012 ID 0489:e095 Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:20 +0200
    [PATCH 4.2.y-ckt 045/218] aacraid: Fix RRQ overload Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:20 +0200
    [PATCH 4.2.y-ckt 032/218] tools/hv: Use include/uapi with __EXPORTED_HEADERS__ Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:20 +0200
    [PATCH 4.2.y-ckt 019/218] clk: rockchip: add pclk_cpu to the list of rk3188 critical clocks Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:30 +0200
    [PATCH 4.2.y-ckt 011/218] ALSA: usb-audio: Fix NULL dereference in create_fixed_stream_quirk() Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:30 +0200
    [PATCH 4.2.y-ckt 031/218] staging: comedi: ni_tiocmd: change mistaken use of start_src for start_arg Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:30 +0200
    [PATCH 4.2.y-ckt 024/218] [media] pwc: Add USB id for Philips Spc880nc webcam Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:30 +0200
    [PATCH 4.2.y-ckt 012/218] ALSA: usb-audio: Add sanity checks for endpoint accesses Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:30 +0200
    [PATCH 4.2.y-ckt 015/218] USB: cdc-acm: more sanity checking Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:30 +0200
    [PATCH 4.2.y-ckt 029/218] mei: bus: fix drivers and devices names confusion Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:30 +0200
    [PATCH 4.2.y-ckt 004/218] crypto: algif_skcipher - Do not dereference ctx without socket lock Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:30 +0200
    [PATCH 4.2.y-ckt 027/218] 8250: use callbacks to access UART_DLL/UART_DLM Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:30 +0200
    [PATCH 4.2.y-ckt 001/218] crypto: skcipher - Add crypto_skcipher_has_setkey Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:30 +0200
    [PATCH 4.2.y-ckt 018/218] crypto: ccp - Add hash state import and export support Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:30 +0200
    [PATCH 4.2.y-ckt 030/218] mei: bus: check if the device is enabled before data transfer Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:30 +0200
    [PATCH 4.2.y-ckt 016/218] drm/i915: Workaround CHV pipe C cursor fail Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:30 +0200
    [PATCH 4.2.y-ckt 022/218] tty: Fix GPF in flush_to_ldisc(), part 2 Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:30 +0200
    [PATCH 4.2.y-ckt 008/218] ipv4: Don't do expensive useless work during inetdev destroy. Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:30 +0200
    [PATCH 4.2.y-ckt 014/218] Input: ati_remote2 - fix crashes on detecting device with invalid descriptor Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:30 +0200
    [PATCH 4.2.y-ckt 033/218] tpm: fix the rollback in tpm_chip_register() Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:30 +0200
    [PATCH 4.2.y-ckt 006/218] gpio: add a data pointer to gpio_chip Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:30 +0200
    [PATCH 4.2.y-ckt 020/218] clk: rockchip: Add pclk_peri to critical clocks on RK3066/RK3188 Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:30 +0200
    [PATCH 4.2.y-ckt 010/218] USB: iowarrior: fix oops with malicious USB descriptors Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:30 +0200
    [PATCH 4.2.y-ckt 021/218] clk: rockchip: add hclk_cpubus to the list of rk3188 critical clocks Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:30 +0200
    [PATCH 4.2.y-ckt 005/218] gpiolib: do not allow to insert an empty gpiochip Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:30 +0200
    [PATCH 4.2.y-ckt 007/218] gpio: rcar: Add Runtime PM handling for interrupts Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:30 +0200
    [PATCH 4.2.y-ckt 023/218] [media] media: v4l2-compat-ioctl32: fix missing length copy in put_v4l2_buffer32 Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:30 +0200
    [PATCH 4.2.y-ckt 002/218] crypto: algif_skcipher - Add key check exception for cipher_null Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:30 +0200
    [PATCH 4.2.y-ckt 025/218] crypto: ccp - Limit the amount of information exported Kamal Mostafa <kamal@canonical.com> - 2016-03-31 23:30 +0200

Page 6 of 11 — ← Prev page 1 … 4 5 [6] 7 8 … 11  Next page →


#1368715 — [PATCH 4.2.y-ckt 114/218] net: mvneta: enable change MAC address when interface is up

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-31 23:00 +0200
Subject[PATCH 4.2.y-ckt 114/218] net: mvneta: enable change MAC address when interface is up
Message-ID<riRR7-291-3@gated-at.bofh.it>
In reply to#1368599
4.2.8-ckt7 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Dmitri Epshtein <dima@marvell.com>

commit 928b6519afeb2a5e2dc61154380b545ed66c476a upstream.

Function eth_prepare_mac_addr_change() is called as part of MAC
address change. This function check if interface is running.
To enable change MAC address when interface is running:
IFF_LIVE_ADDR_CHANGE flag must be set to dev->priv_flags field

Fixes: c5aff18204da ("net: mvneta: driver for Marvell Armada 370/XP
network unit")
Signed-off-by: Dmitri Epshtein <dima@marvell.com>
Signed-off-by: Gregory CLEMENT <gregory.clement@free-electrons.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/net/ethernet/marvell/mvneta.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/net/ethernet/marvell/mvneta.c b/drivers/net/ethernet/marvell/mvneta.c
index 060af9b..37abcde 100644
--- a/drivers/net/ethernet/marvell/mvneta.c
+++ b/drivers/net/ethernet/marvell/mvneta.c
@@ -3163,7 +3163,7 @@ static int mvneta_probe(struct platform_device *pdev)
 	dev->features = NETIF_F_SG | NETIF_F_IP_CSUM | NETIF_F_TSO;
 	dev->hw_features |= dev->features;
 	dev->vlan_features |= dev->features;
-	dev->priv_flags |= IFF_UNICAST_FLT;
+	dev->priv_flags |= IFF_UNICAST_FLT | IFF_LIVE_ADDR_CHANGE;
 	dev->gso_max_segs = MVNETA_MAX_TSO_SEGS;
 
 	err = register_netdev(dev);
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1368716 — [PATCH 4.2.y-ckt 105/218] Bluetooth: Fix potential buffer overflow with Add Advertising

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-31 23:00 +0200
Subject[PATCH 4.2.y-ckt 105/218] Bluetooth: Fix potential buffer overflow with Add Advertising
Message-ID<riRR8-291-7@gated-at.bofh.it>
In reply to#1368599
4.2.8-ckt7 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Johan Hedberg <johan.hedberg@intel.com>

commit 6a0e78072c2ae7b20b14e0249d8108441ea928d2 upstream.

The Add Advertising command handler does the appropriate checks for
the AD and Scan Response data, however fails to take into account the
general length of the mgmt command itself, which could lead to
potential buffer overflows. This patch adds the necessary check that
the mgmt command length is consistent with the given ad and scan_rsp
lengths.

Signed-off-by: Johan Hedberg <johan.hedberg@intel.com>
Signed-off-by: Marcel Holtmann <marcel@holtmann.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 net/bluetooth/mgmt.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/net/bluetooth/mgmt.c b/net/bluetooth/mgmt.c
index e32a9e4..3750b37 100644
--- a/net/bluetooth/mgmt.c
+++ b/net/bluetooth/mgmt.c
@@ -7135,6 +7135,10 @@ static int add_advertising(struct sock *sk, struct hci_dev *hdev,
 		return mgmt_cmd_status(sk, hdev->id, MGMT_OP_ADD_ADVERTISING,
 				       status);
 
+	if (data_len != sizeof(*cp) + cp->adv_data_len + cp->scan_rsp_len)
+		return mgmt_cmd_status(sk, hdev->id, MGMT_OP_ADD_ADVERTISING,
+				       MGMT_STATUS_INVALID_PARAMS);
+
 	flags = __le32_to_cpu(cp->flags);
 	timeout = __le16_to_cpu(cp->timeout);
 	duration = __le16_to_cpu(cp->duration);
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1368717 — [PATCH 4.2.y-ckt 104/218] xtensa: clear all DBREAKC registers on start

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-31 23:00 +0200
Subject[PATCH 4.2.y-ckt 104/218] xtensa: clear all DBREAKC registers on start
Message-ID<riRR8-291-9@gated-at.bofh.it>
In reply to#1368599
4.2.8-ckt7 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Max Filippov <jcmvbkbc@gmail.com>

commit 7de7ac785ae18a2cdc78d7560f48e3213d9ea0ab upstream.

There are XCHAL_NUM_DBREAK registers, clear them all.
This also fixes cryptic assembler error message with binutils 2.25 when
XCHAL_NUM_DBREAK is 0:

  as: out of memory allocating 18446744073709551575 bytes after a total
  of 495616 bytes

Signed-off-by: Max Filippov <jcmvbkbc@gmail.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 arch/xtensa/kernel/head.S | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/xtensa/kernel/head.S b/arch/xtensa/kernel/head.S
index 9ed5564..05e1df9 100644
--- a/arch/xtensa/kernel/head.S
+++ b/arch/xtensa/kernel/head.S
@@ -128,7 +128,7 @@ ENTRY(_startup)
 	wsr	a0, icountlevel
 
 	.set	_index, 0
-	.rept	XCHAL_NUM_DBREAK - 1
+	.rept	XCHAL_NUM_DBREAK
 	wsr	a0, SREG_DBREAKC + _index
 	.set	_index, _index + 1
 	.endr
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1368718 — [PATCH 4.2.y-ckt 119/218] nfsd: fix deadlock secinfo+readdir compound

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-31 23:00 +0200
Subject[PATCH 4.2.y-ckt 119/218] nfsd: fix deadlock secinfo+readdir compound
Message-ID<riRR8-291-13@gated-at.bofh.it>
In reply to#1368599
4.2.8-ckt7 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: "J. Bruce Fields" <bfields@redhat.com>

commit 2f6fc056e899bd0144a08da5cacaecbe8997cd74 upstream.

nfsd_lookup_dentry exits with the parent filehandle locked.  fh_put also
unlocks if necessary (nfsd filehandle locking is probably too lenient),
so it gets unlocked eventually, but if the following op in the compound
needs to lock it again, we can deadlock.

A fuzzer ran into this; normal clients don't send a secinfo followed by
a readdir in the same compound.

Signed-off-by: J. Bruce Fields <bfields@redhat.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 fs/nfsd/nfs4proc.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/fs/nfsd/nfs4proc.c b/fs/nfsd/nfs4proc.c
index 90cfda7..aaa5b8f 100644
--- a/fs/nfsd/nfs4proc.c
+++ b/fs/nfsd/nfs4proc.c
@@ -879,6 +879,7 @@ nfsd4_secinfo(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate,
 				    &exp, &dentry);
 	if (err)
 		return err;
+	fh_unlock(&cstate->current_fh);
 	if (d_really_is_negative(dentry)) {
 		exp_put(exp);
 		err = nfserr_noent;
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1368719 — [PATCH 4.2.y-ckt 079/218] perf/x86/intel: Use PAGE_SIZE for PEBS buffer size on Core2

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-31 23:00 +0200
Subject[PATCH 4.2.y-ckt 079/218] perf/x86/intel: Use PAGE_SIZE for PEBS buffer size on Core2
Message-ID<riRR8-291-11@gated-at.bofh.it>
In reply to#1368599
4.2.8-ckt7 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Jiri Olsa <jolsa@redhat.com>

commit e72daf3f4d764c47fb71c9bdc7f9c54a503825b1 upstream.

Using PAGE_SIZE buffers makes the WRMSR to PERF_GLOBAL_CTRL in
intel_pmu_enable_all() mysteriously hang on Core2. As a workaround, we
don't do this.

The hard lockup is easily triggered by running 'perf test attr'
repeatedly. Most of the time it gets stuck on sample session with
small periods.

  # perf test attr -vv
  14: struct perf_event_attr setup                             :
  --- start ---
  ...
    'PERF_TEST_ATTR=/tmp/tmpuEKz3B /usr/bin/perf record -o /tmp/tmpuEKz3B/perf.data -c 123 kill >/dev/null 2>&1' ret 1

Reported-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Jiri Olsa <jolsa@kernel.org>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Reviewed-by: Andi Kleen <ak@linux.intel.com>
Cc: Alexander Shishkin <alexander.shishkin@linux.intel.com>
Cc: Jiri Olsa <jolsa@redhat.com>
Cc: Kan Liang <kan.liang@intel.com>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Stephane Eranian <eranian@google.com>
Cc: Thomas Gleixner <tglx@linutronix.de>
Cc: Vince Weaver <vincent.weaver@maine.edu>
Cc: Wang Nan <wangnan0@huawei.com>
Link: http://lkml.kernel.org/r/20160301190352.GA8355@krava.redhat.com
Signed-off-by: Ingo Molnar <mingo@kernel.org>
[ kamal: backport to 4.2-stable: files renamed ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 arch/x86/kernel/cpu/perf_event.h          |  1 +
 arch/x86/kernel/cpu/perf_event_intel_ds.c | 13 +++++++++++--
 2 files changed, 12 insertions(+), 2 deletions(-)

diff --git a/arch/x86/kernel/cpu/perf_event.h b/arch/x86/kernel/cpu/perf_event.h
index 3e7fd27..04cd687 100644
--- a/arch/x86/kernel/cpu/perf_event.h
+++ b/arch/x86/kernel/cpu/perf_event.h
@@ -590,6 +590,7 @@ struct x86_pmu {
 			pebs_active	:1,
 			pebs_broken	:1;
 	int		pebs_record_size;
+	int		pebs_buffer_size;
 	void		(*drain_pebs)(struct pt_regs *regs);
 	struct event_constraint *pebs_constraints;
 	void		(*pebs_aliases)(struct perf_event *event);
diff --git a/arch/x86/kernel/cpu/perf_event_intel_ds.c b/arch/x86/kernel/cpu/perf_event_intel_ds.c
index dbe8d89..56a9cfd 100644
--- a/arch/x86/kernel/cpu/perf_event_intel_ds.c
+++ b/arch/x86/kernel/cpu/perf_event_intel_ds.c
@@ -256,7 +256,7 @@ static int alloc_pebs_buffer(int cpu)
 	if (!x86_pmu.pebs)
 		return 0;
 
-	buffer = kzalloc_node(PEBS_BUFFER_SIZE, GFP_KERNEL, node);
+	buffer = kzalloc_node(x86_pmu.pebs_buffer_size, GFP_KERNEL, node);
 	if (unlikely(!buffer))
 		return -ENOMEM;
 
@@ -273,7 +273,7 @@ static int alloc_pebs_buffer(int cpu)
 		per_cpu(insn_buffer, cpu) = ibuffer;
 	}
 
-	max = PEBS_BUFFER_SIZE / x86_pmu.pebs_record_size;
+	max = x86_pmu.pebs_buffer_size / x86_pmu.pebs_record_size;
 
 	ds->pebs_buffer_base = (u64)(unsigned long)buffer;
 	ds->pebs_index = ds->pebs_buffer_base;
@@ -1229,6 +1229,7 @@ void __init intel_ds_init(void)
 
 	x86_pmu.bts  = boot_cpu_has(X86_FEATURE_BTS);
 	x86_pmu.pebs = boot_cpu_has(X86_FEATURE_PEBS);
+	x86_pmu.pebs_buffer_size = PEBS_BUFFER_SIZE;
 	if (x86_pmu.pebs) {
 		char pebs_type = x86_pmu.intel_cap.pebs_trap ?  '+' : '-';
 		int format = x86_pmu.intel_cap.pebs_format;
@@ -1237,6 +1238,14 @@ void __init intel_ds_init(void)
 		case 0:
 			printk(KERN_CONT "PEBS fmt0%c, ", pebs_type);
 			x86_pmu.pebs_record_size = sizeof(struct pebs_record_core);
+			/*
+			 * Using >PAGE_SIZE buffers makes the WRMSR to
+			 * PERF_GLOBAL_CTRL in intel_pmu_enable_all()
+			 * mysteriously hang on Core2.
+			 *
+			 * As a workaround, we don't do this.
+			 */
+			x86_pmu.pebs_buffer_size = PAGE_SIZE;
 			x86_pmu.drain_pebs = intel_pmu_drain_pebs_core;
 			break;
 
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1368720 — [PATCH 4.2.y-ckt 089/218] sg: fix dxferp in from_to case

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-31 23:00 +0200
Subject[PATCH 4.2.y-ckt 089/218] sg: fix dxferp in from_to case
Message-ID<riRR8-291-17@gated-at.bofh.it>
In reply to#1368599
4.2.8-ckt7 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Douglas Gilbert <dgilbert@interlog.com>

commit 5ecee0a3ee8d74b6950cb41e8989b0c2174568d4 upstream.

One of the strange things that the original sg driver did was let the
user provide both a data-out buffer (it followed the sg_header+cdb)
_and_ specify a reply length greater than zero. What happened was that
the user data-out buffer was copied into some kernel buffers and then
the mid level was told a read type operation would take place with the
data from the device overwriting the same kernel buffers. The user would
then read those kernel buffers back into the user space.

From what I can tell, the above action was broken by commit fad7f01e61bf
("sg: set dxferp to NULL for READ with the older SG interface") in 2008
and syzkaller found that out recently.

Make sure that a user space pointer is passed through when data follows
the sg_header structure and command.  Fix the abnormal case when a
non-zero reply_len is also given.

Fixes: fad7f01e61bf737fe8a3740d803f000db57ecac6
Signed-off-by: Douglas Gilbert <dgilbert@interlog.com>
Reviewed-by: Ewan Milne <emilne@redhat.com>
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/scsi/sg.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/scsi/sg.c b/drivers/scsi/sg.c
index 3bbf485..ec19293 100644
--- a/drivers/scsi/sg.c
+++ b/drivers/scsi/sg.c
@@ -652,7 +652,8 @@ sg_write(struct file *filp, const char __user *buf, size_t count, loff_t * ppos)
 	else
 		hp->dxfer_direction = (mxsize > 0) ? SG_DXFER_FROM_DEV : SG_DXFER_NONE;
 	hp->dxfer_len = mxsize;
-	if (hp->dxfer_direction == SG_DXFER_TO_DEV)
+	if ((hp->dxfer_direction == SG_DXFER_TO_DEV) ||
+	    (hp->dxfer_direction == SG_DXFER_TO_FROM_DEV))
 		hp->dxferp = (char __user *)buf + cmd_size;
 	else
 		hp->dxferp = NULL;
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1368721 — [PATCH 4.2.y-ckt 110/218] fuse: Add reference counting for fuse_io_priv

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-31 23:00 +0200
Subject[PATCH 4.2.y-ckt 110/218] fuse: Add reference counting for fuse_io_priv
Message-ID<riRR8-291-15@gated-at.bofh.it>
In reply to#1368599
4.2.8-ckt7 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Seth Forshee <seth.forshee@canonical.com>

commit 744742d692e37ad5c20630e57d526c8f2e2fe3c9 upstream.

The 'reqs' member of fuse_io_priv serves two purposes. First is to track
the number of oustanding async requests to the server and to signal that
the io request is completed. The second is to be a reference count on the
structure to know when it can be freed.

For sync io requests these purposes can be at odds.  fuse_direct_IO() wants
to block until the request is done, and since the signal is sent when
'reqs' reaches 0 it cannot keep a reference to the object. Yet it needs to
use the object after the userspace server has completed processing
requests. This leads to some handshaking and special casing that it
needlessly complicated and responsible for at least one race condition.

It's much cleaner and safer to maintain a separate reference count for the
object lifecycle and to let 'reqs' just be a count of outstanding requests
to the userspace server. Then we can know for sure when it is safe to free
the object without any handshaking or special cases.

The catch here is that most of the time these objects are stack allocated
and should not be freed. Initializing these objects with a single reference
that is never released prevents accidental attempts to free the objects.

Fixes: 9d5722b7777e ("fuse: handle synchronous iocbs internally")
Signed-off-by: Seth Forshee <seth.forshee@canonical.com>
Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 fs/fuse/cuse.c   |  4 ++--
 fs/fuse/file.c   | 28 +++++++++++++++++++++-------
 fs/fuse/fuse_i.h |  9 +++++++++
 3 files changed, 32 insertions(+), 9 deletions(-)

diff --git a/fs/fuse/cuse.c b/fs/fuse/cuse.c
index 8e3ee19..c5b6b71 100644
--- a/fs/fuse/cuse.c
+++ b/fs/fuse/cuse.c
@@ -90,7 +90,7 @@ static struct list_head *cuse_conntbl_head(dev_t devt)
 
 static ssize_t cuse_read_iter(struct kiocb *kiocb, struct iov_iter *to)
 {
-	struct fuse_io_priv io = { .async = 0, .file = kiocb->ki_filp };
+	struct fuse_io_priv io = FUSE_IO_PRIV_SYNC(kiocb->ki_filp);
 	loff_t pos = 0;
 
 	return fuse_direct_io(&io, to, &pos, FUSE_DIO_CUSE);
@@ -98,7 +98,7 @@ static ssize_t cuse_read_iter(struct kiocb *kiocb, struct iov_iter *to)
 
 static ssize_t cuse_write_iter(struct kiocb *kiocb, struct iov_iter *from)
 {
-	struct fuse_io_priv io = { .async = 0, .file = kiocb->ki_filp };
+	struct fuse_io_priv io = FUSE_IO_PRIV_SYNC(kiocb->ki_filp);
 	loff_t pos = 0;
 	/*
 	 * No locking or generic_write_checks(), the server is
diff --git a/fs/fuse/file.c b/fs/fuse/file.c
index 9e80d01..b4aae5a 100644
--- a/fs/fuse/file.c
+++ b/fs/fuse/file.c
@@ -528,6 +528,11 @@ static void fuse_release_user_pages(struct fuse_req *req, int write)
 	}
 }
 
+static void fuse_io_release(struct kref *kref)
+{
+	kfree(container_of(kref, struct fuse_io_priv, refcnt));
+}
+
 static ssize_t fuse_get_res_by_io(struct fuse_io_priv *io)
 {
 	if (io->err)
@@ -585,8 +590,9 @@ static void fuse_aio_complete(struct fuse_io_priv *io, int err, ssize_t pos)
 		}
 
 		io->iocb->ki_complete(io->iocb, res, 0);
-		kfree(io);
 	}
+
+	kref_put(&io->refcnt, fuse_io_release);
 }
 
 static void fuse_aio_complete_req(struct fuse_conn *fc, struct fuse_req *req)
@@ -613,6 +619,7 @@ static size_t fuse_async_req_send(struct fuse_conn *fc, struct fuse_req *req,
 		size_t num_bytes, struct fuse_io_priv *io)
 {
 	spin_lock(&io->lock);
+	kref_get(&io->refcnt);
 	io->size += num_bytes;
 	io->reqs++;
 	spin_unlock(&io->lock);
@@ -691,7 +698,7 @@ static void fuse_short_read(struct fuse_req *req, struct inode *inode,
 
 static int fuse_do_readpage(struct file *file, struct page *page)
 {
-	struct fuse_io_priv io = { .async = 0, .file = file };
+	struct fuse_io_priv io = FUSE_IO_PRIV_SYNC(file);
 	struct inode *inode = page->mapping->host;
 	struct fuse_conn *fc = get_fuse_conn(inode);
 	struct fuse_req *req;
@@ -984,7 +991,7 @@ static size_t fuse_send_write_pages(struct fuse_req *req, struct file *file,
 	size_t res;
 	unsigned offset;
 	unsigned i;
-	struct fuse_io_priv io = { .async = 0, .file = file };
+	struct fuse_io_priv io = FUSE_IO_PRIV_SYNC(file);
 
 	for (i = 0; i < req->num_pages; i++)
 		fuse_wait_on_page_writeback(inode, req->pages[i]->index);
@@ -1398,7 +1405,7 @@ static ssize_t __fuse_direct_read(struct fuse_io_priv *io,
 
 static ssize_t fuse_direct_read_iter(struct kiocb *iocb, struct iov_iter *to)
 {
-	struct fuse_io_priv io = { .async = 0, .file = iocb->ki_filp };
+	struct fuse_io_priv io = FUSE_IO_PRIV_SYNC(iocb->ki_filp);
 	return __fuse_direct_read(&io, to, &iocb->ki_pos);
 }
 
@@ -1406,7 +1413,7 @@ static ssize_t fuse_direct_write_iter(struct kiocb *iocb, struct iov_iter *from)
 {
 	struct file *file = iocb->ki_filp;
 	struct inode *inode = file_inode(file);
-	struct fuse_io_priv io = { .async = 0, .file = file };
+	struct fuse_io_priv io = FUSE_IO_PRIV_SYNC(file);
 	ssize_t res;
 
 	if (is_bad_inode(inode))
@@ -2807,6 +2814,7 @@ fuse_direct_IO(struct kiocb *iocb, struct iov_iter *iter, loff_t offset)
 	if (!io)
 		return -ENOMEM;
 	spin_lock_init(&io->lock);
+	kref_init(&io->refcnt);
 	io->reqs = 1;
 	io->bytes = -1;
 	io->size = 0;
@@ -2830,8 +2838,14 @@ fuse_direct_IO(struct kiocb *iocb, struct iov_iter *iter, loff_t offset)
 	    iov_iter_rw(iter) == WRITE)
 		io->async = false;
 
-	if (io->async && is_sync)
+	if (io->async && is_sync) {
+		/*
+		 * Additional reference to keep io around after
+		 * calling fuse_aio_complete()
+		 */
+		kref_get(&io->refcnt);
 		io->done = &wait;
+	}
 
 	if (iov_iter_rw(iter) == WRITE) {
 		ret = fuse_direct_io(io, iter, &pos, FUSE_DIO_WRITE);
@@ -2851,7 +2865,7 @@ fuse_direct_IO(struct kiocb *iocb, struct iov_iter *iter, loff_t offset)
 		ret = fuse_get_res_by_io(io);
 	}
 
-	kfree(io);
+	kref_put(&io->refcnt, fuse_io_release);
 
 	if (iov_iter_rw(iter) == WRITE) {
 		if (ret > 0)
diff --git a/fs/fuse/fuse_i.h b/fs/fuse/fuse_i.h
index 4051131..604cd42 100644
--- a/fs/fuse/fuse_i.h
+++ b/fs/fuse/fuse_i.h
@@ -22,6 +22,7 @@
 #include <linux/rbtree.h>
 #include <linux/poll.h>
 #include <linux/workqueue.h>
+#include <linux/kref.h>
 
 /** Max number of pages that can be used in a single read request */
 #define FUSE_MAX_PAGES_PER_REQ 32
@@ -243,6 +244,7 @@ struct fuse_args {
 
 /** The request IO state (for asynchronous processing) */
 struct fuse_io_priv {
+	struct kref refcnt;
 	int async;
 	spinlock_t lock;
 	unsigned reqs;
@@ -256,6 +258,13 @@ struct fuse_io_priv {
 	struct completion *done;
 };
 
+#define FUSE_IO_PRIV_SYNC(f) \
+{					\
+	.refcnt = { ATOMIC_INIT(1) },	\
+	.async = 0,			\
+	.file = f,			\
+}
+
 /**
  * Request flags
  *
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1368723 — [PATCH 4.2.y-ckt 106/218] ARC: [BE] readl()/writel() to work in Big Endian CPU configuration

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-31 23:00 +0200
Subject[PATCH 4.2.y-ckt 106/218] ARC: [BE] readl()/writel() to work in Big Endian CPU configuration
Message-ID<riRR9-291-21@gated-at.bofh.it>
In reply to#1368599
4.2.8-ckt7 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Lada Trimasova <ltrimas@synopsys.com>

commit f778cc65717687a3d3f26dd21bef62cd059f1b8b upstream.

read{l,w}() write{l,w}() primitives should use le{16,32}_to_cpu() and
cpu_to_le{16,32}() respectively to ensure device registers are read
correctly in Big Endian CPU configuration.

Per Arnd Bergmann
| Most drivers using readl() or readl_relaxed() expect those to perform byte
| swaps on big-endian architectures, as the registers tend to be fixed endian

This was needed for getting UART to work correctly on a Big Endian ARC.

The ARC accessors originally were fine, and the bug got introduced
inadventently by commit b8a033023994 ("ARCv2: barriers")

Fixes: b8a033023994 ("ARCv2: barriers")
Link: http://lkml.kernel.org/r/201603100845.30602.arnd@arndb.de
Cc: Alexey Brodkin <abrodkin@synopsys.com>
Cc: Arnd Bergmann <arnd@arndb.de>
Signed-off-by: Lada Trimasova <ltrimas@synopsys.com>
[vgupta: beefed up changelog, added Fixes/stable tags]
Signed-off-by: Vineet Gupta <vgupta@synopsys.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 arch/arc/include/asm/io.h | 18 +++++++++++++-----
 1 file changed, 13 insertions(+), 5 deletions(-)

diff --git a/arch/arc/include/asm/io.h b/arch/arc/include/asm/io.h
index 694ece8..27b17ad 100644
--- a/arch/arc/include/asm/io.h
+++ b/arch/arc/include/asm/io.h
@@ -129,15 +129,23 @@ static inline void __raw_writel(u32 w, volatile void __iomem *addr)
 #define writel(v,c)		({ __iowmb(); writel_relaxed(v,c); })
 
 /*
- * Relaxed API for drivers which can handle any ordering themselves
+ * Relaxed API for drivers which can handle barrier ordering themselves
+ *
+ * Also these are defined to perform little endian accesses.
+ * To provide the typical device register semantics of fixed endian,
+ * swap the byte order for Big Endian
+ *
+ * http://lkml.kernel.org/r/201603100845.30602.arnd@arndb.de
  */
 #define readb_relaxed(c)	__raw_readb(c)
-#define readw_relaxed(c)	__raw_readw(c)
-#define readl_relaxed(c)	__raw_readl(c)
+#define readw_relaxed(c) ({ u16 __r = le16_to_cpu((__force __le16) \
+					__raw_readw(c)); __r; })
+#define readl_relaxed(c) ({ u32 __r = le32_to_cpu((__force __le32) \
+					__raw_readl(c)); __r; })
 
 #define writeb_relaxed(v,c)	__raw_writeb(v,c)
-#define writew_relaxed(v,c)	__raw_writew(v,c)
-#define writel_relaxed(v,c)	__raw_writel(v,c)
+#define writew_relaxed(v,c)	__raw_writew((__force u16) cpu_to_le16(v),c)
+#define writel_relaxed(v,c)	__raw_writel((__force u32) cpu_to_le32(v),c)
 
 #include <asm-generic/io.h>
 
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1368724 — [PATCH 4.2.y-ckt 118/218] mmc: mmc_spi: Add Card Detect comments and fix CD GPIO case

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-31 23:00 +0200
Subject[PATCH 4.2.y-ckt 118/218] mmc: mmc_spi: Add Card Detect comments and fix CD GPIO case
Message-ID<riRR9-291-25@gated-at.bofh.it>
In reply to#1368599
4.2.8-ckt7 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Magnus Damm <damm+renesas@opensource.se>

commit bcdc9f260bdce09913db1464be9817170d51044a upstream.

This patch fixes the MMC SPI driver from doing polling card detect when a
CD GPIO that supports interrupts is specified using the gpios DT property.

Without this patch the DT node below results in the following output:

 spi_gpio: spi-gpio { /* SD2 @ CN12 */
         compatible = "spi-gpio";
         #address-cells = <1>;
         #size-cells = <0>;
         gpio-sck = <&gpio6 16 GPIO_ACTIVE_HIGH>;
         gpio-mosi = <&gpio6 17 GPIO_ACTIVE_HIGH>;
         gpio-miso = <&gpio6 18 GPIO_ACTIVE_HIGH>;
         num-chipselects = <1>;
         cs-gpios = <&gpio6 21 GPIO_ACTIVE_LOW>;
         status = "okay";

         spi@0 {
                 compatible = "mmc-spi-slot";
                 reg = <0>;
                 voltage-ranges = <3200 3400>;
                 spi-max-frequency = <25000000>;
                 gpios = <&gpio6 22 GPIO_ACTIVE_LOW>;   /* CD */
         };
 };

 # dmesg | grep mmc
 mmc_spi spi32766.0: SD/MMC host mmc0, no WP, no poweroff, cd polling
 mmc0: host does not support reading read-only switch, assuming write-enable
 mmc0: new SDHC card on SPI
 mmcblk0: mmc0:0000 SU04G 3.69 GiB
 mmcblk0: p1

With this patch applied the "cd polling" portion above disappears.

Signed-off-by: Magnus Damm <damm+renesas@opensource.se>
Signed-off-by: Ulf Hansson <ulf.hansson@linaro.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/mmc/host/mmc_spi.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/drivers/mmc/host/mmc_spi.c b/drivers/mmc/host/mmc_spi.c
index ae19d83..055cad1 100644
--- a/drivers/mmc/host/mmc_spi.c
+++ b/drivers/mmc/host/mmc_spi.c
@@ -1436,6 +1436,12 @@ static int mmc_spi_probe(struct spi_device *spi)
 					     host->pdata->cd_debounce);
 		if (status != 0)
 			goto fail_add_host;
+
+		/* The platform has a CD GPIO signal that may support
+		 * interrupts, so let mmc_gpiod_request_cd_irq() decide
+		 * if polling is needed or not.
+		 */
+		mmc->caps &= ~MMC_CAP_NEEDS_POLL;
 		mmc_gpiod_request_cd_irq(mmc);
 	}
 
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1368727 — [PATCH 4.2.y-ckt 091/218] ALSA: hda - Apply reboot D3 fix for CX20724 codec, too

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-31 23:00 +0200
Subject[PATCH 4.2.y-ckt 091/218] ALSA: hda - Apply reboot D3 fix for CX20724 codec, too
Message-ID<riRR9-291-31@gated-at.bofh.it>
In reply to#1368599
4.2.8-ckt7 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Takashi Iwai <tiwai@suse.de>

commit 56dc66ff1c6d71f9a38c4a7c000b72b921fe4c89 upstream.

Just like CX20722, CX7024 codec also requires the power down at reboot
in order to reduce the noise at reboot/shutdown.

Bugzilla: https://bugzilla.kernel.org/show_bug.cgi?id=113511
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 sound/pci/hda/patch_conexant.c | 7 ++++++-
 1 file changed, 6 insertions(+), 1 deletion(-)

diff --git a/sound/pci/hda/patch_conexant.c b/sound/pci/hda/patch_conexant.c
index 2f0ec7c..ae2a8da 100644
--- a/sound/pci/hda/patch_conexant.c
+++ b/sound/pci/hda/patch_conexant.c
@@ -204,8 +204,13 @@ static void cx_auto_reboot_notify(struct hda_codec *codec)
 {
 	struct conexant_spec *spec = codec->spec;
 
-	if (codec->core.vendor_id != 0x14f150f2)
+	switch (codec->core.vendor_id) {
+	case 0x14f150f2: /* CX20722 */
+	case 0x14f150f4: /* CX20724 */
+		break;
+	default:
 		return;
+	}
 
 	/* Turn the CX20722 codec into D3 to avoid spurious noises
 	   from the internal speaker during (and after) reboot */
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1368728 — [PATCH 4.2.y-ckt 102/218] xtensa: ISS: don't hang if stdin EOF is reached

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-31 23:00 +0200
Subject[PATCH 4.2.y-ckt 102/218] xtensa: ISS: don't hang if stdin EOF is reached
Message-ID<riRR9-291-33@gated-at.bofh.it>
In reply to#1368599
4.2.8-ckt7 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Max Filippov <jcmvbkbc@gmail.com>

commit 362014c8d9d51d504c167c44ac280169457732be upstream.

Simulator stdin may be connected to a file, when its end is reached
kernel hangs in infinite loop inside rs_poll, because simc_poll always
signals that descriptor 0 is readable and simc_read always returns 0.
Check simc_read return value and exit loop if it's not positive. Also
don't rewind polling timer if it's zero.

Signed-off-by: Max Filippov <jcmvbkbc@gmail.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 arch/xtensa/platforms/iss/console.c | 10 ++++++----
 1 file changed, 6 insertions(+), 4 deletions(-)

diff --git a/arch/xtensa/platforms/iss/console.c b/arch/xtensa/platforms/iss/console.c
index 70cb408..92d785f 100644
--- a/arch/xtensa/platforms/iss/console.c
+++ b/arch/xtensa/platforms/iss/console.c
@@ -100,21 +100,23 @@ static void rs_poll(unsigned long priv)
 {
 	struct tty_port *port = (struct tty_port *)priv;
 	int i = 0;
+	int rd = 1;
 	unsigned char c;
 
 	spin_lock(&timer_lock);
 
 	while (simc_poll(0)) {
-		simc_read(0, &c, 1);
+		rd = simc_read(0, &c, 1);
+		if (rd <= 0)
+			break;
 		tty_insert_flip_char(port, c, TTY_NORMAL);
 		i++;
 	}
 
 	if (i)
 		tty_flip_buffer_push(port);
-
-
-	mod_timer(&serial_timer, jiffies + SERIAL_TIMER_VALUE);
+	if (rd)
+		mod_timer(&serial_timer, jiffies + SERIAL_TIMER_VALUE);
 	spin_unlock(&timer_lock);
 }
 
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1368729 — [PATCH 4.2.y-ckt 092/218] EDAC/sb_edac: Fix computation of channel address

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-31 23:00 +0200
Subject[PATCH 4.2.y-ckt 092/218] EDAC/sb_edac: Fix computation of channel address
Message-ID<riRo8-1UF-77@gated-at.bofh.it>
In reply to#1368599
4.2.8-ckt7 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: "Luck, Tony" <tony.luck@intel.com>

commit eb1af3b71f9d83e45f2fd2fd649356e98e1c582c upstream.

Large memory Haswell-EX systems with multiple DIMMs per channel were
sometimes reporting the wrong DIMM.

Found three problems:

 1) Debug printouts for socket and channel interleave were not interpreting
    the register fields correctly. The socket interleave field is a 2^X
    value (0=1, 1=2, 2=4, 3=8). The channel interleave is X+1 (0=1, 1=2,
    2=3. 3=4).

 2) Actual use of the socket interleave value didn't interpret as 2^X

 3) Conversion of address to channel address was complicated, and wrong.

Signed-off-by: Tony Luck <tony.luck@intel.com>
Acked-by: Aristeu Rozanski <arozansk@redhat.com>
Cc: Borislav Petkov <bp@alien8.de>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Mauro Carvalho Chehab <mchehab@osg.samsung.com>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Thomas Gleixner <tglx@linutronix.de>
Cc: linux-edac@vger.kernel.org
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/edac/sb_edac.c | 26 ++++++++++----------------
 1 file changed, 10 insertions(+), 16 deletions(-)

diff --git a/drivers/edac/sb_edac.c b/drivers/edac/sb_edac.c
index 91cf710..9c61607 100644
--- a/drivers/edac/sb_edac.c
+++ b/drivers/edac/sb_edac.c
@@ -1077,8 +1077,8 @@ static void get_memory_layout(const struct mem_ctl_info *mci)
 		edac_dbg(0, "TAD#%d: up to %u.%03u GB (0x%016Lx), socket interleave %d, memory interleave %d, TGT: %d, %d, %d, %d, reg=0x%08x\n",
 			 n_tads, gb, (mb*1000)/1024,
 			 ((u64)tmp_mb) << 20L,
-			 (u32)TAD_SOCK(reg),
-			 (u32)TAD_CH(reg),
+			 (u32)(1 << TAD_SOCK(reg)),
+			 (u32)TAD_CH(reg) + 1,
 			 (u32)TAD_TGT0(reg),
 			 (u32)TAD_TGT1(reg),
 			 (u32)TAD_TGT2(reg),
@@ -1356,7 +1356,7 @@ static int get_memory_error_data(struct mem_ctl_info *mci,
 	}
 
 	ch_way = TAD_CH(reg) + 1;
-	sck_way = TAD_SOCK(reg) + 1;
+	sck_way = 1 << TAD_SOCK(reg);
 
 	if (ch_way == 3)
 		idx = addr >> 6;
@@ -1413,7 +1413,7 @@ static int get_memory_error_data(struct mem_ctl_info *mci,
 		 n_tads,
 		 addr,
 		 limit,
-		 (u32)TAD_SOCK(reg),
+		 sck_way,
 		 ch_way,
 		 offset,
 		 idx,
@@ -1428,18 +1428,12 @@ static int get_memory_error_data(struct mem_ctl_info *mci,
 			offset, addr);
 		return -EINVAL;
 	}
-	addr -= offset;
-	/* Store the low bits [0:6] of the addr */
-	ch_addr = addr & 0x7f;
-	/* Remove socket wayness and remove 6 bits */
-	addr >>= 6;
-	addr = div_u64(addr, sck_xch);
-#if 0
-	/* Divide by channel way */
-	addr = addr / ch_way;
-#endif
-	/* Recover the last 6 bits */
-	ch_addr |= addr << 6;
+
+	ch_addr = addr - offset;
+	ch_addr >>= (6 + shiftup);
+	ch_addr /= ch_way * sck_way;
+	ch_addr <<= (6 + shiftup);
+	ch_addr |= addr & ((1 << (6 + shiftup)) - 1);
 
 	/*
 	 * Step 3) Decode rank
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1368730 — [PATCH 4.2.y-ckt 108/218] ALSA: intel8x0: Add clock quirk entry for AD1981B on IBM ThinkPad X41.

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-31 23:00 +0200
Subject[PATCH 4.2.y-ckt 108/218] ALSA: intel8x0: Add clock quirk entry for AD1981B on IBM ThinkPad X41.
Message-ID<riRR9-291-37@gated-at.bofh.it>
In reply to#1368599
4.2.8-ckt7 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: "Vittorio Gambaletta (VittGam)" <linuxbugs@vittgam.net>

commit 4061db03dd71d195b9973ee466f6ed32f6a3fc16 upstream.

The clock measurement on the AC'97 audio card found in the IBM ThinkPad X41
will often fail, so add a quirk entry to fix it.

Bugzilla: https://bugzilla.redhat.com/show_bug.cgi?id=441087
Signed-off-by: Vittorio Gambaletta <linuxbugs@vittgam.net>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 sound/pci/intel8x0.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/sound/pci/intel8x0.c b/sound/pci/intel8x0.c
index 42bcbac..ccdab29 100644
--- a/sound/pci/intel8x0.c
+++ b/sound/pci/intel8x0.c
@@ -2879,6 +2879,7 @@ static void intel8x0_measure_ac97_clock(struct intel8x0 *chip)
 
 static struct snd_pci_quirk intel8x0_clock_list[] = {
 	SND_PCI_QUIRK(0x0e11, 0x008a, "AD1885", 41000),
+	SND_PCI_QUIRK(0x1014, 0x0581, "AD1981B", 48000),
 	SND_PCI_QUIRK(0x1028, 0x00be, "AD1885", 44100),
 	SND_PCI_QUIRK(0x1028, 0x0177, "AD1980", 48000),
 	SND_PCI_QUIRK(0x1028, 0x01ad, "AD1981B", 48000),
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1368731 — [PATCH 4.2.y-ckt 080/218] perf/x86/intel: Fix PEBS warning by only restoring active PMU in pmi

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-31 23:00 +0200
Subject[PATCH 4.2.y-ckt 080/218] perf/x86/intel: Fix PEBS warning by only restoring active PMU in pmi
Message-ID<riRR9-291-35@gated-at.bofh.it>
In reply to#1368599
4.2.8-ckt7 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Kan Liang <kan.liang@intel.com>

commit c3d266c8a9838cc141b69548bc3b1b18808ae8c4 upstream.

This patch tries to fix a PEBS warning found in my stress test. The
following perf command can easily trigger the pebs warning or spurious
NMI error on Skylake/Broadwell/Haswell platforms:

  sudo perf record -e 'cpu/umask=0x04,event=0xc4/pp,cycles,branches,ref-cycles,cache-misses,cache-references' --call-graph fp -b -c1000 -a

Also the NMI watchdog must be enabled.

For this case, the events number is larger than counter number. So
perf has to do multiplexing.

In perf_mux_hrtimer_handler, it does perf_pmu_disable(), schedule out
old events, rotate_ctx, schedule in new events and finally
perf_pmu_enable().

If the old events include precise event, the MSR_IA32_PEBS_ENABLE
should be cleared when perf_pmu_disable().  The MSR_IA32_PEBS_ENABLE
should keep 0 until the perf_pmu_enable() is called and the new event is
precise event.

However, there is a corner case which could restore PEBS_ENABLE to
stale value during the above period. In perf_pmu_disable(), GLOBAL_CTRL
will be set to 0 to stop overflow and followed PMI. But there may be
pending PMI from an earlier overflow, which cannot be stopped. So even
GLOBAL_CTRL is cleared, the kernel still be possible to get PMI. At
the end of the PMI handler, __intel_pmu_enable_all() will be called,
which will restore the stale values if old events haven't scheduled
out.

Once the stale pebs value is set, it's impossible to be corrected if
the new events are non-precise. Because the pebs_enabled will be set
to 0. x86_pmu.enable_all() will ignore the MSR_IA32_PEBS_ENABLE
setting. As a result, the following NMI with stale PEBS_ENABLE
trigger pebs warning.

The pending PMI after enabled=0 will become harmless if the NMI handler
does not change the state. This patch checks cpuc->enabled in pmi and
only restore the state when PMU is active.

Here is the dump:

  Call Trace:
   <NMI>  [<ffffffff813c3a2e>] dump_stack+0x63/0x85
   [<ffffffff810a46f2>] warn_slowpath_common+0x82/0xc0
   [<ffffffff810a483a>] warn_slowpath_null+0x1a/0x20
   [<ffffffff8100fe2e>] intel_pmu_drain_pebs_nhm+0x2be/0x320
   [<ffffffff8100caa9>] intel_pmu_handle_irq+0x279/0x460
   [<ffffffff810639b6>] ? native_write_msr_safe+0x6/0x40
   [<ffffffff811f290d>] ? vunmap_page_range+0x20d/0x330
   [<ffffffff811f2f11>] ?  unmap_kernel_range_noflush+0x11/0x20
   [<ffffffff8148379f>] ? ghes_copy_tofrom_phys+0x10f/0x2a0
   [<ffffffff814839c8>] ? ghes_read_estatus+0x98/0x170
   [<ffffffff81005a7d>] perf_event_nmi_handler+0x2d/0x50
   [<ffffffff810310b9>] nmi_handle+0x69/0x120
   [<ffffffff810316f6>] default_do_nmi+0xe6/0x100
   [<ffffffff810317f2>] do_nmi+0xe2/0x130
   [<ffffffff817aea71>] end_repeat_nmi+0x1a/0x1e
   [<ffffffff810639b6>] ? native_write_msr_safe+0x6/0x40
   [<ffffffff810639b6>] ? native_write_msr_safe+0x6/0x40
   [<ffffffff810639b6>] ? native_write_msr_safe+0x6/0x40
   <<EOE>>  <IRQ>  [<ffffffff81006df8>] ?  x86_perf_event_set_period+0xd8/0x180
   [<ffffffff81006eec>] x86_pmu_start+0x4c/0x100
   [<ffffffff8100722d>] x86_pmu_enable+0x28d/0x300
   [<ffffffff811994d7>] perf_pmu_enable.part.81+0x7/0x10
   [<ffffffff8119cb70>] perf_mux_hrtimer_handler+0x200/0x280
   [<ffffffff8119c970>] ?  __perf_install_in_context+0xc0/0xc0
   [<ffffffff8110f92d>] __hrtimer_run_queues+0xfd/0x280
   [<ffffffff811100d8>] hrtimer_interrupt+0xa8/0x190
   [<ffffffff81199080>] ?  __perf_read_group_add.part.61+0x1a0/0x1a0
   [<ffffffff81051bd8>] local_apic_timer_interrupt+0x38/0x60
   [<ffffffff817af01d>] smp_apic_timer_interrupt+0x3d/0x50
   [<ffffffff817ad15c>] apic_timer_interrupt+0x8c/0xa0
   <EOI>  [<ffffffff81199080>] ?  __perf_read_group_add.part.61+0x1a0/0x1a0
   [<ffffffff81123de5>] ?  smp_call_function_single+0xd5/0x130
   [<ffffffff81123ddb>] ?  smp_call_function_single+0xcb/0x130
   [<ffffffff81199080>] ?  __perf_read_group_add.part.61+0x1a0/0x1a0
   [<ffffffff8119765a>] event_function_call+0x10a/0x120
   [<ffffffff8119c660>] ? ctx_resched+0x90/0x90
   [<ffffffff811971e0>] ? cpu_clock_event_read+0x30/0x30
   [<ffffffff811976d0>] ? _perf_event_disable+0x60/0x60
   [<ffffffff8119772b>] _perf_event_enable+0x5b/0x70
   [<ffffffff81197388>] perf_event_for_each_child+0x38/0xa0
   [<ffffffff811976d0>] ? _perf_event_disable+0x60/0x60
   [<ffffffff811a0ffd>] perf_ioctl+0x12d/0x3c0
   [<ffffffff8134d855>] ? selinux_file_ioctl+0x95/0x1e0
   [<ffffffff8124a3a1>] do_vfs_ioctl+0xa1/0x5a0
   [<ffffffff81036d29>] ? sched_clock+0x9/0x10
   [<ffffffff8124a919>] SyS_ioctl+0x79/0x90
   [<ffffffff817ac4b2>] entry_SYSCALL_64_fastpath+0x1a/0xa4
  ---[ end trace aef202839fe9a71d ]---
  Uhhuh. NMI received for unknown reason 2d on CPU 2.
  Do you have a strange power saving mode enabled?

Signed-off-by: Kan Liang <kan.liang@intel.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Cc: Alexander Shishkin <alexander.shishkin@linux.intel.com>
Cc: Arnaldo Carvalho de Melo <acme@redhat.com>
Cc: Jiri Olsa <jolsa@redhat.com>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Stephane Eranian <eranian@google.com>
Cc: Thomas Gleixner <tglx@linutronix.de>
Cc: Vince Weaver <vincent.weaver@maine.edu>
Link: http://lkml.kernel.org/r/1457046448-6184-1-git-send-email-kan.liang@intel.com
[ Fixed various typos and other small details. ]
Signed-off-by: Ingo Molnar <mingo@kernel.org>
[ kamal: backport to 4.2-stable: files renamed ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 arch/x86/kernel/cpu/perf_event.c       | 13 +++++++++++++
 arch/x86/kernel/cpu/perf_event_intel.c | 15 +++++++++++++--
 arch/x86/kernel/cpu/perf_event_knc.c   |  4 +++-
 3 files changed, 29 insertions(+), 3 deletions(-)

diff --git a/arch/x86/kernel/cpu/perf_event.c b/arch/x86/kernel/cpu/perf_event.c
index a27d738..d93690c 100644
--- a/arch/x86/kernel/cpu/perf_event.c
+++ b/arch/x86/kernel/cpu/perf_event.c
@@ -593,6 +593,19 @@ void x86_pmu_disable_all(void)
 	}
 }
 
+/*
+ * There may be PMI landing after enabled=0. The PMI hitting could be before or
+ * after disable_all.
+ *
+ * If PMI hits before disable_all, the PMU will be disabled in the NMI handler.
+ * It will not be re-enabled in the NMI handler again, because enabled=0. After
+ * handling the NMI, disable_all will be called, which will not change the
+ * state either. If PMI hits after disable_all, the PMU is already disabled
+ * before entering NMI handler. The NMI handler will not change the state
+ * either.
+ *
+ * So either situation is harmless.
+ */
 static void x86_pmu_disable(struct pmu *pmu)
 {
 	struct cpu_hw_events *cpuc = this_cpu_ptr(&cpu_hw_events);
diff --git a/arch/x86/kernel/cpu/perf_event_intel.c b/arch/x86/kernel/cpu/perf_event_intel.c
index 1b09c42..9af4ba8 100644
--- a/arch/x86/kernel/cpu/perf_event_intel.c
+++ b/arch/x86/kernel/cpu/perf_event_intel.c
@@ -1244,7 +1244,15 @@ static __initconst const u64 slm_hw_cache_event_ids
 };
 
 /*
- * Use from PMIs where the LBRs are already disabled.
+ * Used from PMIs where the LBRs are already disabled.
+ *
+ * This function could be called consecutively. It is required to remain in
+ * disabled state if called consecutively.
+ *
+ * During consecutive calls, the same disable value will be written to related
+ * registers, so the PMU state remains unchanged. hw.state in
+ * intel_bts_disable_local will remain PERF_HES_STOPPED too in consecutive
+ * calls.
  */
 static void __intel_pmu_disable_all(void)
 {
@@ -1670,7 +1678,10 @@ again:
 		goto again;
 
 done:
-	__intel_pmu_enable_all(0, true);
+	/* Only restore PMU state when it's active. See x86_pmu_disable(). */
+	if (cpuc->enabled)
+		__intel_pmu_enable_all(0, true);
+
 	/*
 	 * Only unmask the NMI after the overflow counters
 	 * have been reset. This avoids spurious NMIs on
diff --git a/arch/x86/kernel/cpu/perf_event_knc.c b/arch/x86/kernel/cpu/perf_event_knc.c
index 5b0c232..b931095 100644
--- a/arch/x86/kernel/cpu/perf_event_knc.c
+++ b/arch/x86/kernel/cpu/perf_event_knc.c
@@ -263,7 +263,9 @@ again:
 		goto again;
 
 done:
-	knc_pmu_enable_all(0);
+	/* Only restore PMU state when it's active. See x86_pmu_disable(). */
+	if (cpuc->enabled)
+		knc_pmu_enable_all(0);
 
 	return handled;
 }
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1368732 — [PATCH 4.2.y-ckt 123/218] mmc: sdhci: Fix override of timeout clk wrt max_busy_timeout

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-31 23:00 +0200
Subject[PATCH 4.2.y-ckt 123/218] mmc: sdhci: Fix override of timeout clk wrt max_busy_timeout
Message-ID<riRR9-291-39@gated-at.bofh.it>
In reply to#1368599
4.2.8-ckt7 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Adrian Hunter <adrian.hunter@intel.com>

commit 995136247915c5cee633d55ba23f6eebf67aa567 upstream.

Normally the timeout clock frequency is read from the capabilities
register.  It is also possible to set the value prior to calling
sdhci_add_host() in which case that value will override the
capabilities register value.  However that was being done after
calculating max_busy_timeout so that max_busy_timeout was being
calculated using the wrong value of timeout_clk.

Fix that by moving the override before max_busy_timeout is
calculated.

The result is that the max_busy_timeout and max_discard
increase for BSW devices so that, for example, the time for
mkfs.ext4 on a 64GB eMMC drops from about 1 minute 40 seconds
to about 20 seconds.

Note, in the future, the capabilities setting will be tidied up
and this override won't be used anymore.  However this fix is
needed for stable.

Signed-off-by: Adrian Hunter <adrian.hunter@intel.com>
Signed-off-by: Ulf Hansson <ulf.hansson@linaro.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/mmc/host/sdhci.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/drivers/mmc/host/sdhci.c b/drivers/mmc/host/sdhci.c
index 57dd499..c27800d 100644
--- a/drivers/mmc/host/sdhci.c
+++ b/drivers/mmc/host/sdhci.c
@@ -3076,14 +3076,14 @@ int sdhci_add_host(struct sdhci_host *host)
 		if (caps[0] & SDHCI_TIMEOUT_CLK_UNIT)
 			host->timeout_clk *= 1000;
 
+		if (override_timeout_clk)
+			host->timeout_clk = override_timeout_clk;
+
 		mmc->max_busy_timeout = host->ops->get_max_timeout_count ?
 			host->ops->get_max_timeout_count(host) : 1 << 27;
 		mmc->max_busy_timeout /= host->timeout_clk;
 	}
 
-	if (override_timeout_clk)
-		host->timeout_clk = override_timeout_clk;
-
 	mmc->caps |= MMC_CAP_SDIO_IRQ | MMC_CAP_ERASE | MMC_CAP_CMD23;
 	mmc->caps2 |= MMC_CAP2_SDIO_IRQ_NOTHREAD;
 
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1368733 — [PATCH 4.2.y-ckt 117/218] ALSA: hda - Fix unconditional GPIO toggle via automute

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-31 23:00 +0200
Subject[PATCH 4.2.y-ckt 117/218] ALSA: hda - Fix unconditional GPIO toggle via automute
Message-ID<riRR9-291-41@gated-at.bofh.it>
In reply to#1368599
4.2.8-ckt7 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Takashi Iwai <tiwai@suse.de>

commit 1f7c6658962fa1260c1658d681bd6bb0c746b99a upstream.

Cirrus HD-audio driver may adjust GPIO pins for EAPD dynamically
depending on the jack plug state.  This works fine for the auto-mute
mode where the speaker gets muted upon the HP jack plug.   OTOH, when
the auto-mute mode is off, this turns off the EAPD unexpectedly
depending on the jack state, which results in the silent speaker
output.

This patch fixes the silent speaker output issue by setting GPIO bits
constantly when the auto-mute mode is off.

Reported-and-tested-by: moosotc@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 sound/pci/hda/patch_cirrus.c | 8 ++++++--
 1 file changed, 6 insertions(+), 2 deletions(-)

diff --git a/sound/pci/hda/patch_cirrus.c b/sound/pci/hda/patch_cirrus.c
index ac38222..43fc6e8 100644
--- a/sound/pci/hda/patch_cirrus.c
+++ b/sound/pci/hda/patch_cirrus.c
@@ -174,8 +174,12 @@ static void cs_automute(struct hda_codec *codec)
 	snd_hda_gen_update_outputs(codec);
 
 	if (spec->gpio_eapd_hp || spec->gpio_eapd_speaker) {
-		spec->gpio_data = spec->gen.hp_jack_present ?
-			spec->gpio_eapd_hp : spec->gpio_eapd_speaker;
+		if (spec->gen.automute_speaker)
+			spec->gpio_data = spec->gen.hp_jack_present ?
+				spec->gpio_eapd_hp : spec->gpio_eapd_speaker;
+		else
+			spec->gpio_data =
+				spec->gpio_eapd_hp | spec->gpio_eapd_speaker;
 		snd_hda_codec_write(codec, 0x01, 0,
 				    AC_VERB_SET_GPIO_DATA, spec->gpio_data);
 	}
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1368735 — [PATCH 4.2.y-ckt 128/218] mm: memcontrol: reclaim and OOM kill when shrinking memory.max below usage

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-31 23:00 +0200
Subject[PATCH 4.2.y-ckt 128/218] mm: memcontrol: reclaim and OOM kill when shrinking memory.max below usage
Message-ID<riRRa-291-47@gated-at.bofh.it>
In reply to#1368599
4.2.8-ckt7 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Johannes Weiner <hannes@cmpxchg.org>

commit b6e6edcfa40561e9c8abe5eecf1c96f8e5fd9c6f upstream.

Setting the original memory.limit_in_bytes hardlimit is subject to a
race condition when the desired value is below the current usage.  The
code tries a few times to first reclaim and then see if the usage has
dropped to where we would like it to be, but there is no locking, and
the workload is free to continue making new charges up to the old limit.
Thus, attempting to shrink a workload relies on pure luck and hope that
the workload happens to cooperate.

To fix this in the cgroup2 memory.max knob, do it the other way round:
set the limit first, then try enforcement.  And if reclaim is not able
to succeed, trigger OOM kills in the group.  Keep going until the new
limit is met, we run out of OOM victims and there's only unreclaimable
memory left, or the task writing to memory.max is killed.  This allows
users to shrink groups reliably, and the behavior is consistent with
what happens when new charges are attempted in excess of memory.max.

Signed-off-by: Johannes Weiner <hannes@cmpxchg.org>
Acked-by: Michal Hocko <mhocko@suse.com>
Cc: Vladimir Davydov <vdavydov@virtuozzo.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
[ kamal: backport to 4.2-stable: no Documentation/cgroup-v2.txt ]
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 mm/memcontrol.c | 38 ++++++++++++++++++++++++++++++++++----
 1 file changed, 34 insertions(+), 4 deletions(-)

diff --git a/mm/memcontrol.c b/mm/memcontrol.c
index 1021069..d5ff354 100644
--- a/mm/memcontrol.c
+++ b/mm/memcontrol.c
@@ -1551,7 +1551,7 @@ static unsigned long mem_cgroup_get_limit(struct mem_cgroup *memcg)
 	return limit;
 }
 
-static void mem_cgroup_out_of_memory(struct mem_cgroup *memcg, gfp_t gfp_mask,
+static bool mem_cgroup_out_of_memory(struct mem_cgroup *memcg, gfp_t gfp_mask,
 				     int order)
 {
 	struct mem_cgroup *iter;
@@ -1624,6 +1624,7 @@ static void mem_cgroup_out_of_memory(struct mem_cgroup *memcg, gfp_t gfp_mask,
 	}
 unlock:
 	mutex_unlock(&oom_lock);
+	return chosen;
 }
 
 #if MAX_NUMNODES > 1
@@ -5459,6 +5460,8 @@ static ssize_t memory_max_write(struct kernfs_open_file *of,
 				char *buf, size_t nbytes, loff_t off)
 {
 	struct mem_cgroup *memcg = mem_cgroup_from_css(of_css(of));
+	unsigned int nr_reclaims = MEM_CGROUP_RECLAIM_RETRIES;
+	bool drained = false;
 	unsigned long max;
 	int err;
 
@@ -5467,9 +5470,36 @@ static ssize_t memory_max_write(struct kernfs_open_file *of,
 	if (err)
 		return err;
 
-	err = mem_cgroup_resize_limit(memcg, max);
-	if (err)
-		return err;
+	xchg(&memcg->memory.limit, max);
+
+	for (;;) {
+		unsigned long nr_pages = page_counter_read(&memcg->memory);
+
+		if (nr_pages <= max)
+			break;
+
+		if (signal_pending(current)) {
+			err = -EINTR;
+			break;
+		}
+
+		if (!drained) {
+			drain_all_stock(memcg);
+			drained = true;
+			continue;
+		}
+
+		if (nr_reclaims) {
+			if (!try_to_free_mem_cgroup_pages(memcg, nr_pages - max,
+							  GFP_KERNEL, true))
+				nr_reclaims--;
+			continue;
+		}
+
+		mem_cgroup_events(memcg, MEMCG_OOM, 1);
+		if (!mem_cgroup_out_of_memory(memcg, GFP_KERNEL, 0))
+			break;
+	}
 
 	memcg_wb_domain_size_changed(memcg);
 	return nbytes;
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1368736 — [PATCH 4.2.y-ckt 109/218] fuse: do not use iocb after it may have been freed

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-31 23:00 +0200
Subject[PATCH 4.2.y-ckt 109/218] fuse: do not use iocb after it may have been freed
Message-ID<riRRa-291-49@gated-at.bofh.it>
In reply to#1368599
4.2.8-ckt7 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Robert Doebbelin <robert@quobyte.com>

commit 7cabc61e01a0a8b663bd2b4c982aa53048218734 upstream.

There's a race in fuse_direct_IO(), whereby is_sync_kiocb() is called on an
iocb that could have been freed if async io has already completed.  The fix
in this case is simple and obvious: cache the result before starting io.

It was discovered by KASan:

kernel: ==================================================================
kernel: BUG: KASan: use after free in fuse_direct_IO+0xb1a/0xcc0 at addr ffff88036c414390

Signed-off-by: Robert Doebbelin <robert@quobyte.com>
Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
Fixes: bcba24ccdc82 ("fuse: enable asynchronous processing direct IO")
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 fs/fuse/file.c | 7 ++++---
 1 file changed, 4 insertions(+), 3 deletions(-)

diff --git a/fs/fuse/file.c b/fs/fuse/file.c
index 195476a..9e80d01 100644
--- a/fs/fuse/file.c
+++ b/fs/fuse/file.c
@@ -2786,6 +2786,7 @@ fuse_direct_IO(struct kiocb *iocb, struct iov_iter *iter, loff_t offset)
 	loff_t i_size;
 	size_t count = iov_iter_count(iter);
 	struct fuse_io_priv *io;
+	bool is_sync = is_sync_kiocb(iocb);
 
 	pos = offset;
 	inode = file->f_mapping->host;
@@ -2825,11 +2826,11 @@ fuse_direct_IO(struct kiocb *iocb, struct iov_iter *iter, loff_t offset)
 	 * to wait on real async I/O requests, so we must submit this request
 	 * synchronously.
 	 */
-	if (!is_sync_kiocb(iocb) && (offset + count > i_size) &&
+	if (!is_sync && (offset + count > i_size) &&
 	    iov_iter_rw(iter) == WRITE)
 		io->async = false;
 
-	if (io->async && is_sync_kiocb(iocb))
+	if (io->async && is_sync)
 		io->done = &wait;
 
 	if (iov_iter_rw(iter) == WRITE) {
@@ -2843,7 +2844,7 @@ fuse_direct_IO(struct kiocb *iocb, struct iov_iter *iter, loff_t offset)
 		fuse_aio_complete(io, ret < 0 ? ret : 0, -1);
 
 		/* we have a non-extending, async request, so return */
-		if (!is_sync_kiocb(iocb))
+		if (!is_sync)
 			return -EIOCBQUEUED;
 
 		wait_for_completion(&wait);
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1368737 — [PATCH 4.2.y-ckt 101/218] ALSA: hda - fix the mic mute button and led problem for a Lenovo AIO

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-31 23:00 +0200
Subject[PATCH 4.2.y-ckt 101/218] ALSA: hda - fix the mic mute button and led problem for a Lenovo AIO
Message-ID<riRRa-291-51@gated-at.bofh.it>
In reply to#1368599
4.2.8-ckt7 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Hui Wang <hui.wang@canonical.com>

commit 6ef2f68fa38bf415830f67903d87180d933e0f47 upstream.

This Lenovo ThinkCentre AIO also uses Line2 as mic mute button and
uses GPIO2 to control the mic mute led, so applying this quirk can
make both the button and led work.

BugLink: https://bugs.launchpad.net/bugs/1555912
Signed-off-by: Hui Wang <hui.wang@canonical.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 sound/pci/hda/patch_realtek.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/sound/pci/hda/patch_realtek.c b/sound/pci/hda/patch_realtek.c
index 73d135c..6c143e3 100644
--- a/sound/pci/hda/patch_realtek.c
+++ b/sound/pci/hda/patch_realtek.c
@@ -5505,6 +5505,7 @@ static const struct snd_pci_quirk alc269_fixup_tbl[] = {
 	SND_PCI_QUIRK(0x17aa, 0x2226, "ThinkPad X250", ALC292_FIXUP_TPT440_DOCK),
 	SND_PCI_QUIRK(0x17aa, 0x2233, "Thinkpad", ALC293_FIXUP_LENOVO_SPK_NOISE),
 	SND_PCI_QUIRK(0x17aa, 0x30bb, "ThinkCentre AIO", ALC233_FIXUP_LENOVO_LINE2_MIC_HOTKEY),
+	SND_PCI_QUIRK(0x17aa, 0x30e2, "ThinkCentre AIO", ALC233_FIXUP_LENOVO_LINE2_MIC_HOTKEY),
 	SND_PCI_QUIRK(0x17aa, 0x3902, "Lenovo E50-80", ALC269_FIXUP_DMIC_THINKPAD_ACPI),
 	SND_PCI_QUIRK(0x17aa, 0x3977, "IdeaPad S210", ALC283_FIXUP_INT_MIC),
 	SND_PCI_QUIRK(0x17aa, 0x3978, "IdeaPad Y410P", ALC269_FIXUP_NO_SHUTUP),
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1368738 — [PATCH 4.2.y-ckt 115/218] dm: fix rq_end_stats() NULL pointer in dm_requeue_original_request()

FromKamal Mostafa <kamal@canonical.com>
Date2016-03-31 23:00 +0200
Subject[PATCH 4.2.y-ckt 115/218] dm: fix rq_end_stats() NULL pointer in dm_requeue_original_request()
Message-ID<riRRa-291-55@gated-at.bofh.it>
In reply to#1368599
4.2.8-ckt7 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: "Bryn M. Reeves" <bmr@redhat.com>

commit 98dbc9c6c61698792e3a66f32f3bf066201d42d7 upstream.

An "old" (.request_fn) DM 'struct request' stores a pointer to the
associated 'struct dm_rq_target_io' in rq->special.

dm_requeue_original_request(), previously named
dm_requeue_unmapped_original_request(), called dm_unprep_request() to
reset rq->special to NULL.  But rq_end_stats() would go on to hit a NULL
pointer deference because its call to tio_from_request() returned NULL.

Fix this by calling rq_end_stats() _before_ dm_unprep_request()

Signed-off-by: Bryn M. Reeves <bmr@redhat.com>
Signed-off-by: Mike Snitzer <snitzer@redhat.com>
Fixes: e262f34741 ("dm stats: add support for request-based DM devices")
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/md/dm.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/md/dm.c b/drivers/md/dm.c
index 3f82998..e066983 100644
--- a/drivers/md/dm.c
+++ b/drivers/md/dm.c
@@ -1184,9 +1184,9 @@ static void dm_requeue_original_request(struct mapped_device *md,
 {
 	int rw = rq_data_dir(rq);
 
+	rq_end_stats(md, rq);
 	dm_unprep_request(rq);
 
-	rq_end_stats(md, rq);
 	if (!rq->q->mq_ops)
 		old_requeue_request(rq);
 	else {
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


Page 6 of 11 — ← Prev page 1 … 4 5 [6] 7 8 … 11  Next page →

Back to top | Article view | linux.kernel


csiph-web