Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1392807 > unrolled thread

[PATCH 4.5 000/200] 4.5.3-stable review

Started byGreg Kroah-Hartman <gregkh@linuxfoundation.org>
First post2016-05-03 03:20 +0200
Last post2016-05-03 20:20 +0200
Articles 20 on this page of 60 — 4 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH 4.5 000/200] 4.5.3-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:20 +0200
    [PATCH 4.5 064/200] powerpc: scan_features() updates incorrect bits for REAL_LE Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:20 +0200
    [PATCH 4.5 048/200] drm/nouveau/core: use vzalloc for allocating ramht Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:20 +0200
    [PATCH 4.5 073/200] pinctrl: single: Fix pcs_parse_bits_in_pinctrl_entry to use __ffs than ffs Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:20 +0200
    [PATCH 4.5 006/200] kvm: x86: do not leak guest xcr0 into host interrupt handlers Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:20 +0200
    [PATCH 4.5 117/200] [media] videobuf2-core: Check user space planes array in dqbuf Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:20 +0200
    [PATCH 4.5 067/200] nl80211: check netlink protocol in socket release notification Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:20 +0200
    [PATCH 4.5 114/200] ASoC: rt5640: Correct the digital interface data select Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:20 +0200
    [PATCH 4.5 120/200] cxl: Keep IRQ mappings on context teardown Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:20 +0200
    [PATCH 4.5 066/200] powerpc: Update TM user feature bits in scan_features() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:20 +0200
    [PATCH 4.5 116/200] [media] media: vb2: Fix regression on poll() for RW mode Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:20 +0200
    [PATCH 4.5 062/200] crypto: talitos - fix crash in talitos_cra_init() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:20 +0200
    [PATCH 4.5 096/200] drm/amdkfd: uninitialized variable in dbgdev_wave_control_set_registers() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:20 +0200
    [PATCH 4.5 070/200] Input: pmic8xxx-pwrkey - fix algorithm for converting trigger delay Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:20 +0200
    [PATCH 4.5 118/200] [media] videobuf2-v4l2: Verify planes array in buffer dequeueing Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:20 +0200
      Re: [PATCH 4.5 118/200] [media] videobuf2-v4l2: Verify planes array  in buffer dequeueing Mauro Carvalho Chehab <mchehab@osg.samsung.com> - 2016-05-11 18:40 +0200
    [PATCH 4.5 119/200] [media] v4l2-dv-timings.h: fix polarity for 4k formats Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:20 +0200
    [PATCH 4.5 107/200] ACPICA / Interpreter: Fix a regression triggered because of wrong Linux ECDT support Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:20 +0200
    [PATCH 4.5 112/200] ASoC: ssm4567: Reset device before regcache_sync() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:20 +0200
    [PATCH 4.5 061/200] crypto: sha1-mb - use corrcet pointer while completing jobs Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:20 +0200
    [PATCH 4.5 106/200] i2c: exynos5: Fix possible ABBA deadlock by keeping I2C clock prepared Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:20 +0200
    [PATCH 4.5 047/200] futex: Acknowledge a new waiter in counter before plist Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:20 +0200
    [PATCH 4.5 056/200] s390/pci: add extra padding to function measurement block Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:20 +0200
    [PATCH 4.5 057/200] iwlwifi: pcie: lower the debug level for RSA semaphore access Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:20 +0200
    [PATCH 4.5 105/200] i2c: cpm: Fix build break due to incompatible pointer types Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:20 +0200
    [PATCH 4.5 063/200] crypto: talitos - fix AEAD tcrypt tests Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:20 +0200
    [PATCH 4.5 009/200] ARM: dts: am43xx: fix edma memcpy channel allocation Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:20 +0200
    [PATCH 4.5 115/200] [media] vb2-memops: Fix over allocation of frame vectors Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:20 +0200
    [PATCH 4.5 075/200] iommu/dma: Restore scatterlist offsets correctly Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:20 +0200
    [PATCH 4.5 042/200] ALSA: pcxhr: Fix missing mutex unlock Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:30 +0200
    [PATCH 4.5 022/200] usb: gadget: f_fs: Fix use-after-free Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:30 +0200
    [PATCH 4.5 025/200] lib: lz4: fixed zram with lz4 on big endian machines Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:30 +0200
    [PATCH 4.5 004/200] efi/arm64: Dont apply MEMBLOCK_NOMAP to UEFI memory map mapping Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:30 +0200
    [PATCH 4.5 024/200] dm cache metadata: fix cmd_read_lock() acquiring write lock Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:30 +0200
    [PATCH 4.5 029/200] dmaengine: hsu: correct residue calculation of active descriptor Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:30 +0200
    [PATCH 4.5 032/200] dmaengine: pxa_dma: fix the maximum requestor line Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:30 +0200
    [PATCH 4.5 015/200] xhci: resume USB 3 roothub first Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:30 +0200
    [PATCH 4.5 028/200] dmaengine: hsu: correct use of channel status register Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:30 +0200
    [PATCH 4.5 016/200] usb: host: xhci: add a new quirk XHCI_NO_64BIT_SUPPORT Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:30 +0200
    [PATCH 4.5 014/200] usb: xhci: applying XHCI_PME_STUCK_QUIRK to Intel BXT B0 host Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:30 +0200
    [PATCH 4.5 005/200] x86/mce: Avoid using object after free in genpool Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:30 +0200
    [PATCH 4.5 002/200] block: partition: initialize percpuref before sending out KOBJ_ADD Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:30 +0200
    [PATCH 4.5 031/200] dmaengine: edma: Remove dynamic TPTC power management feature Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:30 +0200
    [PATCH 4.5 040/200] ALSA: hda - Keep powering up ADCs on Cirrus codecs Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:30 +0200
    [PATCH 4.5 033/200] mtd: nand: pxa3xx_nand: fix dmaengine initialization Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:30 +0200
    [PATCH 4.5 026/200] debugfs: Make automount point inodes permanently empty Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:30 +0200
    [PATCH 4.5 044/200] ALSA: hda - Update BCLK also at hotplug for i915 HSW/BDW Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:30 +0200
    [PATCH 4.5 011/200] ARM: OMAP2: Fix up interconnect barrier initialization for DRA7 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:30 +0200
    [PATCH 4.5 018/200] usb: xhci: fix wild pointers in xhci_mem_cleanup Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:30 +0200
    [PATCH 4.5 030/200] dmaengine: omap-dma: Fix polled channel completion detection and handling Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:30 +0200
    [PATCH 4.5 023/200] dm cache metadata: fix READ_LOCK macros and cleanup WRITE_LOCK macros Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:30 +0200
    [PATCH 4.5 043/200] ALSA: hda - Add dock support for ThinkPad X260 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:30 +0200
    [PATCH 4.5 027/200] dmaengine: dw: fix master selection Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:30 +0200
    [PATCH 4.5 001/200] mmc: block: Use the mmc host device index as the mmcblk device index Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:30 +0200
    [PATCH 4.5 010/200] ARM: mvebu: Correct unit address for linksys Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 03:40 +0200
    Re: [PATCH 4.5 000/200] 4.5.3-stable review Guenter Roeck <linux@roeck-us.net> - 2016-05-03 09:50 +0200
      Re: [PATCH 4.5 000/200] 4.5.3-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 20:30 +0200
        Re: [PATCH 4.5 000/200] 4.5.3-stable review Guenter Roeck <linux@roeck-us.net> - 2016-05-04 04:30 +0200
    Re: [PATCH 4.5 000/200] 4.5.3-stable review Shuah Khan <shuahkh@osg.samsung.com> - 2016-05-03 17:00 +0200
      Re: [PATCH 4.5 000/200] 4.5.3-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-05-03 20:20 +0200

Page 1 of 3  [1] 2 3  Next page →


#1392807 — [PATCH 4.5 000/200] 4.5.3-stable review

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-05-03 03:20 +0200
Subject[PATCH 4.5 000/200] 4.5.3-stable review
Message-ID<ruwxz-5Wx-3@gated-at.bofh.it>
This is the start of the stable review cycle for the 4.5.3 release.
There are 200 patches in this series, all will be posted as a response
to this one.  If anyone has any issues with these being applied, please
let me know.

Responses should be made by Thu May  5 00:05:29 UTC 2016.
Anything received after that time might be too late.

The whole patch series can be found in one patch at:
	kernel.org/pub/linux/kernel/v4.x/stable-review/patch-4.5.3-rc1.gz
and the diffstat can be found below.

thanks,

greg k-h

-------------
Pseudo-Shortlog of commits:

Greg Kroah-Hartman <gregkh@linuxfoundation.org>
    Linux 4.5.3-rc1

Dan Carpenter <dan.carpenter@oracle.com>
    extcon: max77843: Use correct size for reading the interrupt register

Arnd Bergmann <arnd@arndb.de>
    stm class: Select CONFIG_SRCU

Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com>
    tpm: fix: set continueSession attribute for the unseal operation

Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com>
    tpm: fix checks for policy digest existence in tpm2_seal_trusted()

Arnd Bergmann <arnd@arndb.de>
    megaraid_sas: add missing curly braces in ioctl handler

NeilBrown <neilb@suse.com>
    sunrpc/cache: drop reference when sunrpc_cache_pipe_upcall() detects a race

Caesar Wang <wxt@rock-chips.com>
    thermal: rockchip: fix a impossible condition caused by the warning

Al Viro <viro@ZenIV.linux.org.uk>
    unbreak allmodconfig KCONFIG_ALLCONFIG=...

Jiri Kosina <jkosina@suse.cz>
    btrfs: cleaner_kthread() doesn't need explicit freeze

Kinglong Mee <kinglongmee@gmail.com>
    btrfs: fix memory leak of fs_info in block group cache

Fabio Estevam <fabio.estevam@nxp.com>
    bus: imx-weim: Take the 'status' property value into account

Franklin S Cooper Jr <fcooper@ti.com>
    ARM: dts: am437x: Fix GPMC dma properties

Franklin S Cooper Jr <fcooper@ti.com>
    ARM: dts: am33xx: Fix GPMC dma properties

Robert Jarzmik <robert.jarzmik@free.fr>
    ARM: dts: pxa: fix dma engine node to pxa3xx-nand

Lior Amsalem <alior@marvell.com>
    ARM: dts: armada-375: use armada-370-sata for SATA

Arnd Bergmann <arnd@arndb.de>
    ARM: EXYNOS: select THERMAL_OF

Arnd Bergmann <arnd@arndb.de>
    ARM: prima2: always enable reset controller

Pali Rohár <pali.rohar@gmail.com>
    ARM: OMAP3: Add cpuidle parameters table for omap3430

Andres Freund <andres@anarazel.de>
    perf hists: Fix determination of a callchain node's childlessness

Peter Zijlstra <peterz@infradead.org>
    perf/core: Fix time tracking bug with multiplexing

Alexander Shishkin <alexander.shishkin@linux.intel.com>
    perf/core: Don't leak event in the syscall error path

Allen Hubbe <Allen.Hubbe@emc.com>
    NTB: Remove _addr functions from ntb_hw_amd

Arnd Bergmann <arnd@arndb.de>
    ntb: perf test: fix address space confusion

Borislav Petkov <bp@suse.de>
    perf stat: Document --detailed option

Marcin Ślusarz <marcin.slusarz@gmail.com>
    perf tools: handle spaces in file names obtained from /proc/pid/maps

Namhyung Kim <namhyung@kernel.org>
    perf hists browser: Fix dump to show correct callchain style

Namhyung Kim <namhyung@kernel.org>
    perf hists browser: Only offer symbol scripting when a symbol is under the cursor

Ezequiel García <ezequiel@vanguardiasur.com.ar>
    mtd: nand: Drop mtd.owner requirement in nand_scan

Florian Fainelli <f.fainelli@gmail.com>
    mtd: brcmnand: Fix v7.1 register offsets

Cyrille Pitchen <cyrille.pitchen@atmel.com>
    mtd: spi-nor: remove micron_quad_enable()

Kunihiko Hayashi <hayashi.kunihiko@socionext.com>
    bus: uniphier-system-bus: fix condition of overlap check

Chao Yu <chao2.yu@samsung.com>
    f2fs crypto: make sure the encryption info is initialized on opendir(2)

Chao Yu <chao2.yu@samsung.com>
    f2fs crypto: handle unexpected lack of encryption keys

Jaegeuk Kim <jaegeuk@kernel.org>
    f2fs: don't need to call set_page_dirty for io error

Jaegeuk Kim <jaegeuk@kernel.org>
    f2fs: do f2fs_balance_fs when block is allocated

Jaegeuk Kim <jaegeuk@kernel.org>
    ext4/fscrypto: avoid RCU lookup in d_revalidate

Jaegeuk Kim <jaegeuk@kernel.org>
    f2fs: cover large section in sanity check of super

Shawn Lin <shawn.lin@rock-chips.com>
    f2fs: slightly reorganize read_raw_super_block

Jaegeuk Kim <jaegeuk@kernel.org>
    f2fs crypto: fix corrupted symlink in encrypted case

Eryu Guan <guaneryu@gmail.com>
    ext4: fix NULL pointer dereference in ext4_mark_inode_dirty()

Karol Herbst <nouveau@karolherbst.de>
    x86/mm/kmmio: Fix mmiotrace for hugepages

Addy Ke <addy.ke@rock-chips.com>
    spi: rockchip: modify DMA max burst to 1

Chris Phlipot <cphlipot0@gmail.com>
    perf tools: Fix perf script python database export crash

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf evlist: Reference count the cpu and thread maps at set_maps()

Michael Hennerich <michael.hennerich@analog.com>
    drivers/misc/ad525x_dpot: AD5274 fix RDAC read back errors

Krzysztof Kozlowski <k.kozlowski@samsung.com>
    rtc: max77686: Properly handle regmap_irq_get_virq() error code

Alexandre Belloni <alexandre.belloni@free-electrons.com>
    rtc: rx8025: remove rv8803 id

Dan Carpenter <dan.carpenter@oracle.com>
    rtc: ds1685: passing bogus values to irq_restore

Geert Uytterhoeven <geert@linux-m68k.org>
    rtc: vr41xx: Wire up alarm_irq_enable

Alexander Kochetkov <al.kochet@gmail.com>
    rtc: hym8563: fix invalid year calculation

Jon Hunter <jonathanh@nvidia.com>
    PM / Domains: Fix removal of a subdomain

Viresh Kumar <viresh.kumar@linaro.org>
    PM / OPP: Initialize u_volt_min/max to a valid value

Dan Carpenter <dan.carpenter@oracle.com>
    misc: mic/scif: fix wrap around tests

Ben Hutchings <ben@decadent.org.uk>
    misc/bmp085: Enable building as a module

Michal Marek <mmarek@suse.com>
    lib/mpi: Endianness fix

Sushaanth Srirangapathi <sushaanth.s@ti.com>
    fbdev: da8xx-fb: fix videomodes of lcd panels

Arnd Bergmann <arnd@arndb.de>
    scsi_dh: force modular build if SCSI is a module

Arnd Bergmann <arnd@arndb.de>
    paride: make 'verbose' parameter an 'int' again

Arnd Bergmann <arnd@arndb.de>
    regulator: s5m8767: fix get_register() error handling

Vladimir Zapolskiy <vz@mleia.com>
    irqchip/mxs: Fix error check of of_io_request_and_map()

Vladimir Zapolskiy <vz@mleia.com>
    irqchip/sunxi-nmi: Fix error check of of_io_request_and_map()

Huibin Hong <huibin.hong@rock-chips.com>
    spi/rockchip: Make sure spi clk is on in rockchip_spi_set_cs

Peter Zijlstra <peterz@infradead.org>
    locking/mcs: Fix mcs_spin_lock() ordering

Ignat Korchagin <ignat.korchagin@gmail.com>
    USB: usbip: fix potential out-of-bounds write

Minchan Kim <minchan@kernel.org>
    mm/hwpoison: fix wrong num_poisoned_pages accounting

Minchan Kim <minchan@kernel.org>
    mm: vmscan: reclaim highmem zone if buffer_heads is over limit

Gerald Schaefer <gerald.schaefer@de.ibm.com>
    numa: fix /proc/<pid>/numa_maps for THP

Konstantin Khlebnikov <koct9i@gmail.com>
    mm/huge_memory: replace VM_NO_THP VM_BUG_ON with actual VMA check

Steve Capper <steve.capper@arm.com>
    mm: exclude HugeTLB pages from THP page_mapped() logic

Tejun Heo <tj@kernel.org>
    memcg: relocate charge moving from ->attach to ->post_attach

Tejun Heo <tj@kernel.org>
    cgroup, cpuset: replace cpuset_post_attach_flush() with cgroup_subsys->post_attach callback

Jesper Dangaard Brouer <brouer@redhat.com>
    slub: clean up code for kmem cgroup support to kmem_cache_free_bulk

Roman Pen <roman.penyaev@profitbricks.com>
    workqueue: fix ghost PENDING flag while doing MQ IO

Keith Busch <keith.busch@intel.com>
    x86/apic: Handle zero vector gracefully in clear_vector_irq()

Ard Biesheuvel <ard.biesheuvel@linaro.org>
    efi: Expose non-blocking set_variable() wrapper to efivars

Laszlo Ersek <lersek@redhat.com>
    efi: Fix out-of-bounds read in variable_matches()

Jason Gunthorpe <jgunthorpe@obsidianresearch.com>
    IB/security: Restrict use of the write() interface

Sagi Grimberg <sagi@grimberg.me>
    IB/mlx5: Expose correct max_sge_rd limit

chunfan chen <jeffc@marvell.com>
    mwifiex: fix IBSS data path issue.

Doug Ledford <dledford@redhat.com>
    IB/core: Fix oops in ib_cache_gid_set_default_gid

Michael Neuling <mikey@neuling.org>
    cxl: Keep IRQ mappings on context teardown

Hans Verkuil <hverkuil@xs4all.nl>
    v4l2-dv-timings.h: fix polarity for 4k formats

Sakari Ailus <sakari.ailus@linux.intel.com>
    videobuf2-v4l2: Verify planes array in buffer dequeueing

Sakari Ailus <sakari.ailus@linux.intel.com>
    videobuf2-core: Check user space planes array in dqbuf

Ricardo Ribalda Delgado <ricardo.ribalda@gmail.com>
    media: vb2: Fix regression on poll() for RW mode

Ricardo Ribalda Delgado <ricardo.ribalda@gmail.com>
    vb2-memops: Fix over allocation of frame vectors

Sugar Zhang <sugar.zhang@rock-chips.com>
    ASoC: rt5640: Correct the digital interface data select

Mark Brown <broonie@kernel.org>
    ASoC: dapm: Make sure we have a card when displaying component widgets

Lars-Peter Clausen <lars@metafoo.de>
    ASoC: ssm4567: Reset device before regcache_sync()

Arnd Bergmann <arnd@arndb.de>
    ASoC: s3c24xx: use const snd_soc_component_driver pointer

Tony Luck <tony.luck@intel.com>
    EDAC: i7core, sb_edac: Don't return NOTIFY_BAD from mce_decoder callback

Azael Avalos <coproscefalo@gmail.com>
    toshiba_acpi: Fix regression caused by hotkey enabling value

Adrian Hunter <adrian.hunter@intel.com>
    mmc: sdhci-acpi: Reduce Baytrail eMMC/SD/SDIO hangs

Lv Zheng <lv.zheng@intel.com>
    ACPICA / Interpreter: Fix a regression triggered because of wrong Linux ECDT support

Javier Martinez Canillas <javier@osg.samsung.com>
    i2c: exynos5: Fix possible ABBA deadlock by keeping I2C clock prepared

Michael Ellerman <mpe@ellerman.id.au>
    i2c: cpm: Fix build break due to incompatible pointer types

Adrian Hunter <adrian.hunter@intel.com>
    perf intel-pt: Fix segfault tracing transactions

Linus Walleij <linus.walleij@linaro.org>
    video: ARM CLCD: runtime check for Versatile

Flora Cui <Flora.Cui@amd.com>
    drm/ttm: fix kref count mess in ttm_bo_move_to_lru_tail

Ville Syrjälä <ville.syrjala@linux.intel.com>
    drm/i915: Use fw_domains_put_with_fifo() on HSW

Chris Wilson <chris@chris-wilson.co.uk>
    drm/i915: Force ringbuffers to not be at offset 0

Akash Goel <akash.goel@intel.com>
    drm/i915: Fixup the free space logic in ring_prepare

Mika Kuoppala <mika.kuoppala@linux.intel.com>
    drm/i915/skl: Fix spurious gpu hang with gt3/gt4 revs

Mat Martineau <mathew.j.martineau@linux.intel.com>
    drm/i915/skl: Fix DMC load on Skylake J0 and K0

Dan Carpenter <dan.carpenter@oracle.com>
    drm/amdkfd: uninitialized variable in dbgdev_wave_control_set_registers()

Ville Syrjälä <ville.syrjala@linux.intel.com>
    drm/i915: skl_update_scaler() wants a rotation bitmask instead of bit number

Ville Syrjälä <ville.syrjala@linux.intel.com>
    drm/i915: Start WM computation from scratch on ILK-BDW

Ville Syrjälä <ville.syrjala@linux.intel.com>
    drm/i915: Use the active wm config for merging on ILK-BDW

Ville Syrjälä <ville.syrjala@linux.intel.com>
    drm/i915: Cleanup phys status page too

Ville Syrjälä <ville.syrjala@linux.intel.com>
    drm/i915: Pass the correct encoder to intel_ddi_clk_select() with MST

Vladimir Zapolskiy <vz@mleia.com>
    pwm: brcmstb: Fix check of devm_ioremap_resource() return code

cpaul@redhat.com <cpaul@redhat.com>
    drm/dp/mst: Get validated port ref in drm_dp_update_payload_part1()

Lyude <cpaul@redhat.com>
    drm/dp/mst: Restore primary hub guid on resume

cpaul@redhat.com <cpaul@redhat.com>
    drm/dp/mst: Validate port in drm_dp_payload_send_msg()

Ben Skeggs <bskeggs@redhat.com>
    drm/nouveau/gr/gf100: select a stream master to fixup tfb offset queries

Huacai Chen <chenhc@lemote.com>
    drm: Loongson-3 doesn't fully support wc memory

Vitaly Prosyak <vitaly.prosyak@amd.com>
    drm/radeon: fix vertical bars appear on monitor (v2)

Jérôme Glisse <jglisse@redhat.com>
    drm/radeon: forbid mapping of userptr bo through radeon device file

Alex Deucher <alexander.deucher@amd.com>
    drm/radeon: fix initial connector audio value

Alex Deucher <alexander.deucher@amd.com>
    drm/radeon: add a quirk for a XFX R9 270X

Grigori Goronzy <greg@chown.ath.cx>
    drm/amdgpu: fix regression on CIK (v2)

Sonny Jiang <sonny.jiang@amd.com>
    amdgpu/uvd: add uvd fw version for amdgpu

Alex Deucher <alexander.deucher@amd.com>
    drm/amdgpu: bump the afmt limit for CZ, ST, Polaris

Alex Deucher <alexander.deucher@amd.com>
    drm/amdgpu: use defines for CRTCs and AMFT blocks

Rex Zhu <Rex.Zhu@amd.com>
    drm/amdgpu: when suspending, if uvd/vce was running. need to cancel delay work.

Robin Murphy <robin.murphy@arm.com>
    iommu/dma: Restore scatterlist offsets correctly

Joerg Roedel <jroedel@suse.de>
    iommu/amd: Fix checking of pci dma aliases

Keerthy <j-keerthy@ti.com>
    pinctrl: single: Fix pcs_parse_bits_in_pinctrl_entry to use __ffs than ffs

Yingjoe Chen <yingjoe.chen@mediatek.com>
    pinctrl: mediatek: correct debounce time unit in mtk_gpio_set_debounce

Arnd Bergmann <arnd@arndb.de>
    xen kconfig: don't "select INPUT_XEN_KBDDEV_FRONTEND"

Stephen Boyd <sboyd@codeaurora.org>
    Input: pmic8xxx-pwrkey - fix algorithm for converting trigger delay

Vladis Dronov <vdronov@redhat.com>
    Input: gtco - fix crash on detecting device without endpoints

Dmitry Ivanov <dmitrijs.ivanovs@ubnt.com>
    netlink: don't send NETLINK_URELEASE for unbound sockets

Dmitry Ivanov <dmitrijs.ivanovs@ubnt.com>
    nl80211: check netlink protocol in socket release notification

Anton Blanchard <anton@samba.org>
    powerpc: Update TM user feature bits in scan_features()

Anton Blanchard <anton@samba.org>
    powerpc: Update cpu_user_features2 in scan_features()

Anton Blanchard <anton@samba.org>
    powerpc: scan_features() updates incorrect bits for REAL_LE

Horia Geant? <horia.geanta@nxp.com>
    crypto: talitos - fix AEAD tcrypt tests

Jonas Eymann <J.Eymann@gmx.net>
    crypto: talitos - fix crash in talitos_cra_init()

Xiaodong Liu <xiaodong.liu@intel.com>
    crypto: sha1-mb - use corrcet pointer while completing jobs

Tom Lendacky <thomas.lendacky@amd.com>
    crypto: ccp - Prevent information leakage on export

Tadeusz Struk <tadeusz.struk@intel.com>
    crypto: rsa-pkcs1pad - fix dst len

Matti Gottlieb <matti.gottlieb@intel.com>
    iwlwifi: mvm: fix memory leak in paging

Emmanuel Grumbach <emmanuel.grumbach@intel.com>
    iwlwifi: pcie: lower the debug level for RSA semaphore access

Sebastian Ott <sebott@linux.vnet.ibm.com>
    s390/pci: add extra padding to function measurement block

Srinivas Pandruvada <srinivas.pandruvada@linux.intel.com>
    cpufreq: intel_pstate: Fix processing for turbo activation ratio

Alex Deucher <alexander.deucher@amd.com>
    Revert "drm/amdgpu: disable runtime pm on PX laptops without dGPU power control"

Vladis Dronov <vdronov@redhat.com>
    usbvision: revert commit 588afcc1

Fabio Estevam <fabio.estevam@nxp.com>
    Revert "PCI: imx6: Add support for active-low reset GPIO"

Alex Deucher <alexander.deucher@amd.com>
    Revert "drm/radeon: disable runtime pm on PX laptops without dGPU power control"

Lyude <cpaul@redhat.com>
    drm/i915: Fix race condition in intel_dp_destroy_mst_connector()

John Keeping <john@metanate.com>
    drm/qxl: fix cursor position with non-zero hotspot

Ilia Mirkin <imirkin@alum.mit.edu>
    drm/nouveau/core: use vzalloc for allocating ramht

Davidlohr Bueso <dave@stgolabs.net>
    futex: Acknowledge a new waiter in counter before plist

Sebastian Andrzej Siewior <bigeasy@linutronix.de>
    futex: Handle unlock_pi race gracefully

Romain Perier <romain.perier@free-electrons.com>
    asm-generic/futex: Re-enable preemption in futex_atomic_cmpxchg_inatomic()

Takashi Iwai <tiwai@suse.de>
    ALSA: hda - Update BCLK also at hotplug for i915 HSW/BDW

Conrad Kostecki <ck+linuxkernel@bl4ckb0x.de>
    ALSA: hda - Add dock support for ThinkPad X260

Takashi Iwai <tiwai@suse.de>
    ALSA: pcxhr: Fix missing mutex unlock

Lu, Han <han.lu@intel.com>
    ALSA: hda - add PCI ID for Intel Broxton-T

Takashi Iwai <tiwai@suse.de>
    ALSA: hda - Keep powering up ADCs on Cirrus codecs

Bastien Nocera <hadess@hadess.net>
    ALSA: hda/realtek - Add ALC3234 headset mode for Optiplex 9020m

Takashi Iwai <tiwai@suse.de>
    ALSA: hda - Don't trust the reported actual power state

Tony Luck <tony.luck@intel.com>
    x86 EDAC, sb_edac.c: Take account of channel hashing when needed

Tony Luck <tony.luck@intel.com>
    x86 EDAC, sb_edac.c: Repair damage introduced when "fixing" channel address

Jan Beulich <JBeulich@suse.com>
    x86/mm/xen: Suppress hugetlbfs in PV guests

Peter Zijlstra <peterz@infradead.org>
    sched/cgroup: Fix/cleanup cgroup teardown/init

Robert Jarzmik <robert.jarzmik@free.fr>
    mtd: nand: pxa3xx_nand: fix dmaengine initialization

Robert Jarzmik <robert.jarzmik@free.fr>
    dmaengine: pxa_dma: fix the maximum requestor line

Peter Ujfalusi <peter.ujfalusi@ti.com>
    dmaengine: edma: Remove dynamic TPTC power management feature

Peter Ujfalusi <peter.ujfalusi@ti.com>
    dmaengine: omap-dma: Fix polled channel completion detection and handling

Andy Shevchenko <andriy.shevchenko@linux.intel.com>
    dmaengine: hsu: correct residue calculation of active descriptor

Andy Shevchenko <andriy.shevchenko@linux.intel.com>
    dmaengine: hsu: correct use of channel status register

Andy Shevchenko <andriy.shevchenko@linux.intel.com>
    dmaengine: dw: fix master selection

Seth Forshee <seth.forshee@canonical.com>
    debugfs: Make automount point inodes permanently empty

Rui Salvaterra <rsalvaterra@gmail.com>
    lib: lz4: fixed zram with lz4 on big endian machines

Ahmed Samy <f.fallen45@gmail.com>
    dm cache metadata: fix cmd_read_lock() acquiring write lock

Mike Snitzer <snitzer@redhat.com>
    dm cache metadata: fix READ_LOCK macros and cleanup WRITE_LOCK macros

Lars-Peter Clausen <lars@metafoo.de>
    usb: gadget: f_fs: Fix use-after-free

Robert Dobrowolski <robert.dobrowolski@linux.intel.com>
    usb: hcd: out of bounds access in for_each_companion

Peter Griffin <peter.griffin@linaro.org>
    usb: host: xhci-plat: Make enum xhci_plat_type start at a non zero value

Mathias Nyman <mathias.nyman@linux.intel.com>
    xhci: fix 10 second timeout on removal of PCI hotpluggable xhci controllers

Lu Baolu <baolu.lu@linux.intel.com>
    usb: xhci: fix wild pointers in xhci_mem_cleanup

Yoshihiro Shimoda <yoshihiro.shimoda.uh@renesas.com>
    usb: host: xhci-plat: fix cannot work if R-Car Gen2/3 run on above 4GB phys

Yoshihiro Shimoda <yoshihiro.shimoda.uh@renesas.com>
    usb: host: xhci: add a new quirk XHCI_NO_64BIT_SUPPORT

Mathias Nyman <mathias.nyman@linux.intel.com>
    xhci: resume USB 3 roothub first

Rafal Redzimski <rafal.f.redzimski@intel.com>
    usb: xhci: applying XHCI_PME_STUCK_QUIRK to Intel BXT B0 host

Jerome Marchand <jmarchan@redhat.com>
    assoc_array: don't call compare_object() on a node

Lokesh Vutla <lokeshvutla@ti.com>
    ARM: OMAP2+: hwmod: Fix updating of sysconfig register

Nishanth Menon <nm@ti.com>
    ARM: OMAP2: Fix up interconnect barrier initialization for DRA7

Patrick Uiterwijk <patrick@puiterwijk.org>
    ARM: mvebu: Correct unit address for linksys

Tero Kristo <t-kristo@ti.com>
    ARM: dts: am43xx: fix edma memcpy channel allocation

Lokesh Vutla <lokeshvutla@ti.com>
    ARM: dts: AM43x-epos: Fix clk parent for synctimer

Marc Zyngier <marc.zyngier@arm.com>
    KVM: arm/arm64: Handle forward time correction gracefully

David Matlack <dmatlack@google.com>
    kvm: x86: do not leak guest xcr0 into host interrupt handlers

Tony Luck <tony.luck@intel.com>
    x86/mce: Avoid using object after free in genpool

Ard Biesheuvel <ard.biesheuvel@linaro.org>
    efi/arm64: Don't apply MEMBLOCK_NOMAP to UEFI memory map mapping

Ming Lei <ming.lei@canonical.com>
    block: loop: fix filesystem corruption in case of aio/dio

Ming Lei <ming.lei@canonical.com>
    block: partition: initialize percpuref before sending out KOBJ_ADD

Ulf Hansson <ulf.hansson@linaro.org>
    mmc: block: Use the mmc host device index as the mmcblk device index


-------------

Diffstat:

 Makefile                                          |   4 +-
 arch/arm/boot/dts/am33xx.dtsi                     |   2 +-
 arch/arm/boot/dts/am4372.dtsi                     |   4 +-
 arch/arm/boot/dts/am43x-epos-evm.dts              |   5 +
 arch/arm/boot/dts/armada-375.dtsi                 |   2 +-
 arch/arm/boot/dts/armada-385-linksys.dtsi         |   2 +-
 arch/arm/boot/dts/pxa3xx.dtsi                     |   2 +-
 arch/arm/mach-exynos/Kconfig                      |   1 +
 arch/arm/mach-omap2/cpuidle34xx.c                 |  69 ++++++++-
 arch/arm/mach-omap2/io.c                          |   1 +
 arch/arm/mach-omap2/omap_hwmod.c                  |   8 +-
 arch/arm/mach-prima2/Kconfig                      |   1 +
 arch/powerpc/include/uapi/asm/cputable.h          |   1 +
 arch/powerpc/kernel/prom.c                        |  26 ++--
 arch/s390/include/asm/pci.h                       |   3 +-
 arch/x86/crypto/sha-mb/sha1_mb.c                  |   4 +-
 arch/x86/include/asm/hugetlb.h                    |   1 +
 arch/x86/kernel/apic/vector.c                     |   3 +-
 arch/x86/kernel/cpu/mcheck/mce-genpool.c          |   4 +-
 arch/x86/kvm/x86.c                                |  10 +-
 arch/x86/mm/kmmio.c                               |  88 ++++++++----
 block/partition-generic.c                         |  13 +-
 crypto/rsa-pkcs1pad.c                             |  12 +-
 drivers/acpi/acpica/nsinit.c                      |   2 +
 drivers/acpi/acpica/tbxfload.c                    |  14 ++
 drivers/acpi/acpica/utxfinit.c                    |  25 ++--
 drivers/base/power/domain.c                       |   2 +-
 drivers/base/power/opp/core.c                     |  10 +-
 drivers/block/loop.c                              |   6 +
 drivers/block/paride/pd.c                         |   4 +-
 drivers/block/paride/pt.c                         |   4 +-
 drivers/bus/imx-weim.c                            |   2 +-
 drivers/bus/uniphier-system-bus.c                 |   2 +-
 drivers/char/tpm/tpm2-cmd.c                       |  22 +--
 drivers/cpufreq/intel_pstate.c                    |   5 +
 drivers/crypto/ccp/ccp-crypto-aes-cmac.c          |   3 +
 drivers/crypto/ccp/ccp-crypto-sha.c               |   3 +
 drivers/crypto/talitos.c                          |  87 ++++++++----
 drivers/dma/dw/core.c                             |  34 +++--
 drivers/dma/edma.c                                |  38 +----
 drivers/dma/hsu/hsu.c                             |   9 +-
 drivers/dma/hsu/hsu.h                             |   3 +
 drivers/dma/omap-dma.c                            |  22 ++-
 drivers/dma/pxa_dma.c                             |  39 +++--
 drivers/edac/i7core_edac.c                        |   2 +-
 drivers/edac/sb_edac.c                            |  32 ++++-
 drivers/extcon/extcon-max77843.c                  |   2 +-
 drivers/firmware/efi/arm-init.c                   |  18 ++-
 drivers/firmware/efi/efi.c                        |   1 +
 drivers/firmware/efi/vars.c                       |  37 +++--
 drivers/gpu/drm/amd/amdgpu/amdgpu.h               |   1 +
 drivers/gpu/drm/amd/amdgpu/amdgpu_atpx_handler.c  |   8 +-
 drivers/gpu/drm/amd/amdgpu/amdgpu_device.c        |   8 +-
 drivers/gpu/drm/amd/amdgpu/amdgpu_kms.c           |   2 +-
 drivers/gpu/drm/amd/amdgpu/amdgpu_mode.h          |   6 +-
 drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c           |   5 +
 drivers/gpu/drm/amd/amdgpu/amdgpu_vce.c           |   1 +
 drivers/gpu/drm/amd/amdgpu/gfx_v7_0.c             |   2 +-
 drivers/gpu/drm/amd/amdkfd/kfd_dbgdev.c           |   2 +-
 drivers/gpu/drm/drm_dp_mst_topology.c             |  29 +++-
 drivers/gpu/drm/i915/intel_csr.c                  |   3 +-
 drivers/gpu/drm/i915/intel_display.c              |   2 +-
 drivers/gpu/drm/i915/intel_dp_mst.c               |   8 +-
 drivers/gpu/drm/i915/intel_lrc.c                  |   6 +-
 drivers/gpu/drm/i915/intel_pm.c                   |  33 ++++-
 drivers/gpu/drm/i915/intel_ringbuffer.c           |  42 ++++--
 drivers/gpu/drm/i915/intel_uncore.c               |   6 +-
 drivers/gpu/drm/nouveau/nvkm/core/ramht.c         |   6 +-
 drivers/gpu/drm/nouveau/nvkm/engine/gr/gf100.c    |   2 +
 drivers/gpu/drm/qxl/qxl_display.c                 |  13 +-
 drivers/gpu/drm/qxl/qxl_drv.h                     |   2 +
 drivers/gpu/drm/radeon/evergreen.c                | 154 +++++++++++++++++++-
 drivers/gpu/drm/radeon/evergreen_reg.h            |  46 ++++++
 drivers/gpu/drm/radeon/radeon_atpx_handler.c      |   8 +-
 drivers/gpu/drm/radeon/radeon_connectors.c        |   7 +-
 drivers/gpu/drm/radeon/radeon_device.c            |   8 +-
 drivers/gpu/drm/radeon/radeon_ttm.c               |   2 +
 drivers/gpu/drm/radeon/si_dpm.c                   |   1 +
 drivers/gpu/drm/ttm/ttm_bo.c                      |  17 +--
 drivers/hwtracing/stm/Kconfig                     |   1 +
 drivers/i2c/busses/i2c-cpm.c                      |   4 +-
 drivers/i2c/busses/i2c-exynos5.c                  |  24 +++-
 drivers/infiniband/core/cache.c                   |   3 +-
 drivers/infiniband/core/ucm.c                     |   4 +
 drivers/infiniband/core/ucma.c                    |   3 +
 drivers/infiniband/core/uverbs_main.c             |   5 +
 drivers/infiniband/hw/mlx5/main.c                 |   2 +-
 drivers/infiniband/hw/qib/qib_file_ops.c          |   5 +
 drivers/input/misc/pmic8xxx-pwrkey.c              |   7 +-
 drivers/input/tablet/gtco.c                       |  10 +-
 drivers/iommu/amd_iommu.c                         |  87 ++++++++++--
 drivers/iommu/dma-iommu.c                         |   4 +-
 drivers/irqchip/irq-mxs.c                         |   2 +-
 drivers/irqchip/irq-sunxi-nmi.c                   |   4 +-
 drivers/md/dm-cache-metadata.c                    |  64 +++++----
 drivers/media/usb/usbvision/usbvision-video.c     |   7 -
 drivers/media/v4l2-core/videobuf2-core.c          |  20 ++-
 drivers/media/v4l2-core/videobuf2-memops.c        |   2 +-
 drivers/media/v4l2-core/videobuf2-v4l2.c          |  20 +--
 drivers/misc/Kconfig                              |   2 +-
 drivers/misc/ad525x_dpot.c                        |   2 +-
 drivers/misc/cxl/irq.c                            |   1 -
 drivers/misc/mic/scif/scif_rma.c                  |   7 +-
 drivers/mmc/card/block.c                          |  18 +--
 drivers/mmc/host/Kconfig                          |   1 +
 drivers/mmc/host/sdhci-acpi.c                     |  81 +++++++++++
 drivers/mtd/nand/brcmnand/brcmnand.c              |  34 ++++-
 drivers/mtd/nand/nand_base.c                      |  10 +-
 drivers/mtd/nand/pxa3xx_nand.c                    |   2 +-
 drivers/mtd/spi-nor/spi-nor.c                     |  46 +-----
 drivers/net/wireless/intel/iwlwifi/mvm/mac80211.c |   2 +
 drivers/net/wireless/intel/iwlwifi/mvm/ops.c      |   2 -
 drivers/net/wireless/intel/iwlwifi/pcie/trans.c   |   4 +-
 drivers/net/wireless/marvell/mwifiex/sta_event.c  |  10 +-
 drivers/net/wireless/marvell/mwifiex/wmm.c        |   6 +-
 drivers/ntb/hw/amd/ntb_hw_amd.c                   |  30 ----
 drivers/ntb/test/ntb_perf.c                       |  21 +--
 drivers/pci/host/pci-imx6.c                       |  20 ++-
 drivers/pinctrl/mediatek/pinctrl-mtk-common.c     |   9 +-
 drivers/pinctrl/pinctrl-single.c                  |   6 +-
 drivers/platform/x86/toshiba_acpi.c               |   2 +-
 drivers/pwm/pwm-brcmstb.c                         |   4 +-
 drivers/regulator/s5m8767.c                       |  13 +-
 drivers/rtc/rtc-ds1685.c                          |   8 +-
 drivers/rtc/rtc-hym8563.c                         |   2 +-
 drivers/rtc/rtc-max77686.c                        |   2 +-
 drivers/rtc/rtc-rx8025.c                          |   1 -
 drivers/rtc/rtc-vr41xx.c                          |  13 +-
 drivers/scsi/device_handler/Kconfig               |   8 +-
 drivers/scsi/megaraid/megaraid_sas_base.c         |   3 +-
 drivers/spi/spi-rockchip.c                        |  19 ++-
 drivers/staging/rdma/hfi1/TODO                    |   2 +-
 drivers/staging/rdma/hfi1/file_ops.c              |   6 +
 drivers/thermal/rockchip_thermal.c                |  11 +-
 drivers/usb/core/hcd-pci.c                        |   9 ++
 drivers/usb/gadget/function/f_fs.c                |   5 +-
 drivers/usb/host/xhci-mem.c                       |   6 +
 drivers/usb/host/xhci-pci.c                       |   5 +-
 drivers/usb/host/xhci-plat.c                      |  13 ++
 drivers/usb/host/xhci-plat.h                      |   2 +-
 drivers/usb/host/xhci-ring.c                      |   3 +-
 drivers/usb/host/xhci.c                           |  24 +++-
 drivers/usb/host/xhci.h                           |   2 +
 drivers/usb/usbip/usbip_common.c                  |  11 ++
 drivers/video/fbdev/Kconfig                       |   1 -
 drivers/video/fbdev/amba-clcd.c                   |  15 +-
 drivers/video/fbdev/da8xx-fb.c                    |   7 +-
 fs/btrfs/disk-io.c                                |   2 +-
 fs/btrfs/tests/btrfs-tests.c                      |   6 -
 fs/btrfs/tests/free-space-tree-tests.c            |   1 +
 fs/debugfs/inode.c                                |   2 +-
 fs/ext4/crypto.c                                  |   4 +
 fs/ext4/inode.c                                   |   6 +-
 fs/f2fs/crypto_policy.c                           |   3 +-
 fs/f2fs/data.c                                    |  13 +-
 fs/f2fs/dir.c                                     |   8 ++
 fs/f2fs/file.c                                    |   6 +-
 fs/f2fs/namei.c                                   |  12 +-
 fs/f2fs/super.c                                   | 165 +++++++++++++---------
 fs/proc/task_mmu.c                                |  33 ++++-
 include/asm-generic/futex.h                       |   8 +-
 include/drm/drm_cache.h                           |   2 +
 include/keys/trusted-type.h                       |   2 +-
 include/linux/cgroup-defs.h                       |   1 +
 include/linux/cpuset.h                            |   6 -
 include/linux/mlx5/device.h                       |  11 ++
 include/linux/mm.h                                |   4 +
 include/media/videobuf2-core.h                    |   8 ++
 include/rdma/ib.h                                 |  16 +++
 include/sound/hda_i915.h                          |   5 +-
 include/uapi/linux/v4l2-dv-timings.h              |  30 ++--
 kernel/cgroup.c                                   |   7 +-
 kernel/cpuset.c                                   |   4 +-
 kernel/events/core.c                              |  15 +-
 kernel/futex.c                                    |  27 +++-
 kernel/locking/mcs_spinlock.h                     |   8 +-
 kernel/sched/core.c                               |  35 ++---
 kernel/workqueue.c                                |  29 ++++
 lib/assoc_array.c                                 |   4 +-
 lib/lz4/lz4defs.h                                 |  21 +--
 lib/mpi/mpicoder.c                                |  39 ++---
 mm/huge_memory.c                                  |   6 +-
 mm/memcontrol.c                                   |  37 ++---
 mm/memory.c                                       |  40 ++++++
 mm/migrate.c                                      |   8 +-
 mm/slub.c                                         |  22 +--
 mm/vmscan.c                                       |   2 +-
 net/netlink/af_netlink.c                          |   2 +-
 net/sunrpc/cache.c                                |   6 +-
 net/wireless/nl80211.c                            |   2 +-
 scripts/kconfig/confdata.c                        |  12 +-
 security/keys/trusted.c                           |  11 +-
 sound/hda/hdac_i915.c                             |  62 ++++++--
 sound/pci/hda/hda_generic.c                       |   6 +-
 sound/pci/hda/hda_intel.c                         |  59 +-------
 sound/pci/hda/patch_cirrus.c                      |  14 ++
 sound/pci/hda/patch_hdmi.c                        |   1 +
 sound/pci/hda/patch_realtek.c                     |   2 +
 sound/pci/pcxhr/pcxhr_core.c                      |   1 +
 sound/soc/codecs/rt5640.c                         |   2 +-
 sound/soc/codecs/rt5640.h                         |  36 ++---
 sound/soc/codecs/ssm4567.c                        |   5 +
 sound/soc/samsung/s3c-i2s-v2.c                    |   2 +-
 sound/soc/samsung/s3c-i2s-v2.h                    |   2 +-
 sound/soc/soc-dapm.c                              |   7 +
 tools/perf/Documentation/perf-stat.txt            |   8 ++
 tools/perf/ui/browsers/hists.c                    |  85 ++++++-----
 tools/perf/util/event.c                           |   2 +-
 tools/perf/util/evlist.c                          |   4 +-
 tools/perf/util/evsel.h                           |   6 +-
 tools/perf/util/intel-pt.c                        |   2 +-
 virt/kvm/arm/arch_timer.c                         |  49 +++++--
 212 files changed, 2004 insertions(+), 955 deletions(-)

[toc] | [next] | [standalone]


#1392808 — [PATCH 4.5 064/200] powerpc: scan_features() updates incorrect bits for REAL_LE

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-05-03 03:20 +0200
Subject[PATCH 4.5 064/200] powerpc: scan_features() updates incorrect bits for REAL_LE
Message-ID<ruxai-6BA-21@gated-at.bofh.it>
In reply to#1392807
4.5-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Anton Blanchard <anton@samba.org>

commit 6997e57d693b07289694239e52a10d2f02c3a46f upstream.

The REAL_LE feature entry in the ibm_pa_feature struct is missing an MMU
feature value, meaning all the remaining elements initialise the wrong
values.

This means instead of checking for byte 5, bit 0, we check for byte 0,
bit 0, and then we incorrectly set the CPU feature bit as well as MMU
feature bit 1 and CPU user feature bits 0 and 2 (5).

Checking byte 0 bit 0 (IBM numbering), means we're looking at the
"Memory Management Unit (MMU)" feature - ie. does the CPU have an MMU.
In practice that bit is set on all platforms which have the property.

This means we set CPU_FTR_REAL_LE always. In practice that seems not to
matter because all the modern cpus which have this property also
implement REAL_LE, and we've never needed to disable it.

We're also incorrectly setting MMU feature bit 1, which is:

  #define MMU_FTR_TYPE_8xx		0x00000002

Luckily the only place that looks for MMU_FTR_TYPE_8xx is in Book3E
code, which can't run on the same cpus as scan_features(). So this also
doesn't matter in practice.

Finally in the CPU user feature mask, we're setting bits 0 and 2. Bit 2
is not currently used, and bit 0 is:

  #define PPC_FEATURE_PPC_LE		0x00000001

Which says the CPU supports the old style "PPC Little Endian" mode.
Again this should be harmless in practice as no 64-bit CPUs implement
that mode.

Fix the code by adding the missing initialisation of the MMU feature.

Also add a comment marking CPU user feature bit 2 (0x4) as reserved. It
would be unsafe to start using it as old kernels incorrectly set it.

Fixes: 44ae3ab3358e ("powerpc: Free up some CPU feature bits by moving out MMU-related features")
Signed-off-by: Anton Blanchard <anton@samba.org>
[mpe: Flesh out changelog, add comment reserving 0x4]
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 arch/powerpc/include/uapi/asm/cputable.h |    1 +
 arch/powerpc/kernel/prom.c               |    2 +-
 2 files changed, 2 insertions(+), 1 deletion(-)

--- a/arch/powerpc/include/uapi/asm/cputable.h
+++ b/arch/powerpc/include/uapi/asm/cputable.h
@@ -31,6 +31,7 @@
 #define PPC_FEATURE_PSERIES_PERFMON_COMPAT \
 					0x00000040
 
+/* Reserved - do not use		0x00000004 */
 #define PPC_FEATURE_TRUE_LE		0x00000002
 #define PPC_FEATURE_PPC_LE		0x00000001
 
--- a/arch/powerpc/kernel/prom.c
+++ b/arch/powerpc/kernel/prom.c
@@ -158,7 +158,7 @@ static struct ibm_pa_feature {
 	{CPU_FTR_NOEXECUTE, 0, 0,	0, 6, 0},
 	{CPU_FTR_NODSISRALIGN, 0, 0,	1, 1, 1},
 	{0, MMU_FTR_CI_LARGE_PAGE, 0,	1, 2, 0},
-	{CPU_FTR_REAL_LE, PPC_FEATURE_TRUE_LE, 5, 0, 0},
+	{CPU_FTR_REAL_LE, 0, PPC_FEATURE_TRUE_LE, 5, 0, 0},
 	/*
 	 * If the kernel doesn't support TM (ie. CONFIG_PPC_TRANSACTIONAL_MEM=n),
 	 * we don't want to turn on CPU_FTR_TM here, so we use CPU_FTR_TM_COMP

[toc] | [prev] | [next] | [standalone]


#1392809 — [PATCH 4.5 048/200] drm/nouveau/core: use vzalloc for allocating ramht

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-05-03 03:20 +0200
Subject[PATCH 4.5 048/200] drm/nouveau/core: use vzalloc for allocating ramht
Message-ID<ruxai-6BA-17@gated-at.bofh.it>
In reply to#1392807
4.5-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ilia Mirkin <imirkin@alum.mit.edu>

commit 78a121d82da8aff3aca2a6a1c40f5061081760f0 upstream.

Most calls to nvkm_ramht_new use 0x8000 as the size. This results in a
fairly sizeable chunk of memory to be allocated, which may not be
available with kzalloc. Since this is done fairly rarely (once per
channel), use vzalloc instead.

Signed-off-by: Ilia Mirkin <imirkin@alum.mit.edu>
Signed-off-by: Ben Skeggs <bskeggs@redhat.com>
Cc: Sven Joachim <svenjoac@gmx.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/gpu/drm/nouveau/nvkm/core/ramht.c |    6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

--- a/drivers/gpu/drm/nouveau/nvkm/core/ramht.c
+++ b/drivers/gpu/drm/nouveau/nvkm/core/ramht.c
@@ -131,7 +131,7 @@ nvkm_ramht_del(struct nvkm_ramht **pramh
 	struct nvkm_ramht *ramht = *pramht;
 	if (ramht) {
 		nvkm_gpuobj_del(&ramht->gpuobj);
-		kfree(*pramht);
+		vfree(*pramht);
 		*pramht = NULL;
 	}
 }
@@ -143,8 +143,8 @@ nvkm_ramht_new(struct nvkm_device *devic
 	struct nvkm_ramht *ramht;
 	int ret, i;
 
-	if (!(ramht = *pramht = kzalloc(sizeof(*ramht) + (size >> 3) *
-					sizeof(*ramht->data), GFP_KERNEL)))
+	if (!(ramht = *pramht = vzalloc(sizeof(*ramht) +
+					(size >> 3) * sizeof(*ramht->data))))
 		return -ENOMEM;
 
 	ramht->device = device;

[toc] | [prev] | [next] | [standalone]


#1392810 — [PATCH 4.5 073/200] pinctrl: single: Fix pcs_parse_bits_in_pinctrl_entry to use __ffs than ffs

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-05-03 03:20 +0200
Subject[PATCH 4.5 073/200] pinctrl: single: Fix pcs_parse_bits_in_pinctrl_entry to use __ffs than ffs
Message-ID<ruxai-6BA-23@gated-at.bofh.it>
In reply to#1392807
4.5-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Keerthy <j-keerthy@ti.com>

commit 56b367c0cd67d4c3006738e7dc9dda9273fd2bfe upstream.

pcs_parse_bits_in_pinctrl_entry uses ffs which gives bit indices
ranging from 1 to MAX. This leads to a corner case where we try to request
the pin number = MAX and fails.

bit_pos value is being calculted using ffs. pin_num_from_lsb uses
bit_pos value. pins array is populated with:

pin + pin_num_from_lsb.

The above is 1 more than usual bit indices as bit_pos uses ffs to compute
first set bit. Hence the last of the pins array is populated with the MAX
value and not MAX - 1 which causes error when we call pin_request.

mask_pos is rightly calculated as ((pcs->fmask) << (bit_pos - 1))
Consequently val_pos and submask are correct.

Hence use __ffs which gives (ffs(x) - 1) as the first bit set.

fixes: 4e7e8017a8 ("pinctrl: pinctrl-single: enhance to configure multiple pins of different modules")
Signed-off-by: Keerthy <j-keerthy@ti.com>
Acked-by: Tony Lindgren <tony@atomide.com>
Signed-off-by: Linus Walleij <linus.walleij@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/pinctrl/pinctrl-single.c |    6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

--- a/drivers/pinctrl/pinctrl-single.c
+++ b/drivers/pinctrl/pinctrl-single.c
@@ -1273,9 +1273,9 @@ static int pcs_parse_bits_in_pinctrl_ent
 
 		/* Parse pins in each row from LSB */
 		while (mask) {
-			bit_pos = ffs(mask);
+			bit_pos = __ffs(mask);
 			pin_num_from_lsb = bit_pos / pcs->bits_per_pin;
-			mask_pos = ((pcs->fmask) << (bit_pos - 1));
+			mask_pos = ((pcs->fmask) << bit_pos);
 			val_pos = val & mask_pos;
 			submask = mask & mask_pos;
 
@@ -1844,7 +1844,7 @@ static int pcs_probe(struct platform_dev
 	ret = of_property_read_u32(np, "pinctrl-single,function-mask",
 				   &pcs->fmask);
 	if (!ret) {
-		pcs->fshift = ffs(pcs->fmask) - 1;
+		pcs->fshift = __ffs(pcs->fmask);
 		pcs->fmax = pcs->fmask >> pcs->fshift;
 	} else {
 		/* If mask property doesn't exist, function mux is invalid. */

[toc] | [prev] | [next] | [standalone]


#1392811 — [PATCH 4.5 006/200] kvm: x86: do not leak guest xcr0 into host interrupt handlers

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-05-03 03:20 +0200
Subject[PATCH 4.5 006/200] kvm: x86: do not leak guest xcr0 into host interrupt handlers
Message-ID<ruxai-6BA-19@gated-at.bofh.it>
In reply to#1392807
4.5-stable review patch.  If anyone has any objections, please let me know.

------------------

From: David Matlack <dmatlack@google.com>

commit fc5b7f3bf1e1414bd4e91db6918c85ace0c873a5 upstream.

An interrupt handler that uses the fpu can kill a KVM VM, if it runs
under the following conditions:
 - the guest's xcr0 register is loaded on the cpu
 - the guest's fpu context is not loaded
 - the host is using eagerfpu

Note that the guest's xcr0 register and fpu context are not loaded as
part of the atomic world switch into "guest mode". They are loaded by
KVM while the cpu is still in "host mode".

Usage of the fpu in interrupt context is gated by irq_fpu_usable(). The
interrupt handler will look something like this:

if (irq_fpu_usable()) {
        kernel_fpu_begin();

        [... code that uses the fpu ...]

        kernel_fpu_end();
}

As long as the guest's fpu is not loaded and the host is using eager
fpu, irq_fpu_usable() returns true (interrupted_kernel_fpu_idle()
returns true). The interrupt handler proceeds to use the fpu with
the guest's xcr0 live.

kernel_fpu_begin() saves the current fpu context. If this uses
XSAVE[OPT], it may leave the xsave area in an undesirable state.
According to the SDM, during XSAVE bit i of XSTATE_BV is not modified
if bit i is 0 in xcr0. So it's possible that XSTATE_BV[i] == 1 and
xcr0[i] == 0 following an XSAVE.

kernel_fpu_end() restores the fpu context. Now if any bit i in
XSTATE_BV == 1 while xcr0[i] == 0, XRSTOR generates a #GP. The
fault is trapped and SIGSEGV is delivered to the current process.

Only pre-4.2 kernels appear to be vulnerable to this sequence of
events. Commit 653f52c ("kvm,x86: load guest FPU context more eagerly")
from 4.2 forces the guest's fpu to always be loaded on eagerfpu hosts.

This patch fixes the bug by keeping the host's xcr0 loaded outside
of the interrupts-disabled region where KVM switches into guest mode.

Suggested-by: Andy Lutomirski <luto@amacapital.net>
Signed-off-by: David Matlack <dmatlack@google.com>
[Move load after goto cancel_injection. - Paolo]
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 arch/x86/kvm/x86.c |   10 ++++------
 1 file changed, 4 insertions(+), 6 deletions(-)

--- a/arch/x86/kvm/x86.c
+++ b/arch/x86/kvm/x86.c
@@ -697,7 +697,6 @@ static int __kvm_set_xcr(struct kvm_vcpu
 		if ((xcr0 & XFEATURE_MASK_AVX512) != XFEATURE_MASK_AVX512)
 			return 1;
 	}
-	kvm_put_guest_xcr0(vcpu);
 	vcpu->arch.xcr0 = xcr0;
 
 	if ((xcr0 ^ old_xcr0) & XFEATURE_MASK_EXTEND)
@@ -6569,8 +6568,6 @@ static int vcpu_enter_guest(struct kvm_v
 	kvm_x86_ops->prepare_guest_switch(vcpu);
 	if (vcpu->fpu_active)
 		kvm_load_guest_fpu(vcpu);
-	kvm_load_guest_xcr0(vcpu);
-
 	vcpu->mode = IN_GUEST_MODE;
 
 	srcu_read_unlock(&vcpu->kvm->srcu, vcpu->srcu_idx);
@@ -6593,6 +6590,8 @@ static int vcpu_enter_guest(struct kvm_v
 		goto cancel_injection;
 	}
 
+	kvm_load_guest_xcr0(vcpu);
+
 	if (req_immediate_exit)
 		smp_send_reschedule(vcpu->cpu);
 
@@ -6642,6 +6641,8 @@ static int vcpu_enter_guest(struct kvm_v
 	vcpu->mode = OUTSIDE_GUEST_MODE;
 	smp_wmb();
 
+	kvm_put_guest_xcr0(vcpu);
+
 	/* Interrupt is enabled by handle_external_intr() */
 	kvm_x86_ops->handle_external_intr(vcpu);
 
@@ -7289,7 +7290,6 @@ void kvm_load_guest_fpu(struct kvm_vcpu
 	 * and assume host would use all available bits.
 	 * Guest xcr0 would be loaded later.
 	 */
-	kvm_put_guest_xcr0(vcpu);
 	vcpu->guest_fpu_loaded = 1;
 	__kernel_fpu_begin();
 	__copy_kernel_to_fpregs(&vcpu->arch.guest_fpu.state);
@@ -7298,8 +7298,6 @@ void kvm_load_guest_fpu(struct kvm_vcpu
 
 void kvm_put_guest_fpu(struct kvm_vcpu *vcpu)
 {
-	kvm_put_guest_xcr0(vcpu);
-
 	if (!vcpu->guest_fpu_loaded) {
 		vcpu->fpu_counter = 0;
 		return;

[toc] | [prev] | [next] | [standalone]


#1392812 — [PATCH 4.5 117/200] [media] videobuf2-core: Check user space planes array in dqbuf

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-05-03 03:20 +0200
Subject[PATCH 4.5 117/200] [media] videobuf2-core: Check user space planes array in dqbuf
Message-ID<ruxai-6BA-25@gated-at.bofh.it>
In reply to#1392807
4.5-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sakari Ailus <sakari.ailus@linux.intel.com>

commit e7e0c3e26587749b62d17b9dd0532874186c77f7 upstream.

The number of planes in videobuf2 is specific to a buffer. In order to
verify that the planes array provided by the user is long enough, a new
vb2_buf_op is required.

Call __verify_planes_array() when the dequeued buffer is known. Return an
error to the caller if there was one, otherwise remove the buffer from the
done list.

Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
Acked-by: Hans Verkuil <hans.verkuil@cisco.com>
Signed-off-by: Mauro Carvalho Chehab <mchehab@osg.samsung.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/media/v4l2-core/videobuf2-core.c |   10 +++++-----
 include/media/videobuf2-core.h           |    4 ++++
 2 files changed, 9 insertions(+), 5 deletions(-)

--- a/drivers/media/v4l2-core/videobuf2-core.c
+++ b/drivers/media/v4l2-core/videobuf2-core.c
@@ -1643,7 +1643,7 @@ static int __vb2_wait_for_done_vb(struct
  * Will sleep if required for nonblocking == false.
  */
 static int __vb2_get_done_vb(struct vb2_queue *q, struct vb2_buffer **vb,
-				int nonblocking)
+			     void *pb, int nonblocking)
 {
 	unsigned long flags;
 	int ret;
@@ -1664,10 +1664,10 @@ static int __vb2_get_done_vb(struct vb2_
 	/*
 	 * Only remove the buffer from done_list if v4l2_buffer can handle all
 	 * the planes.
-	 * Verifying planes is NOT necessary since it already has been checked
-	 * before the buffer is queued/prepared. So it can never fail.
 	 */
-	list_del(&(*vb)->done_entry);
+	ret = call_bufop(q, verify_planes_array, *vb, pb);
+	if (!ret)
+		list_del(&(*vb)->done_entry);
 	spin_unlock_irqrestore(&q->done_lock, flags);
 
 	return ret;
@@ -1746,7 +1746,7 @@ int vb2_core_dqbuf(struct vb2_queue *q,
 	struct vb2_buffer *vb = NULL;
 	int ret;
 
-	ret = __vb2_get_done_vb(q, &vb, nonblocking);
+	ret = __vb2_get_done_vb(q, &vb, pb, nonblocking);
 	if (ret < 0)
 		return ret;
 
--- a/include/media/videobuf2-core.h
+++ b/include/media/videobuf2-core.h
@@ -375,6 +375,9 @@ struct vb2_ops {
 /**
  * struct vb2_ops - driver-specific callbacks
  *
+ * @verify_planes_array: Verify that a given user space structure contains
+ *			enough planes for the buffer. This is called
+ *			for each dequeued buffer.
  * @fill_user_buffer:	given a vb2_buffer fill in the userspace structure.
  *			For V4L2 this is a struct v4l2_buffer.
  * @fill_vb2_buffer:	given a userspace structure, fill in the vb2_buffer.
@@ -384,6 +387,7 @@ struct vb2_ops {
  *			the vb2_buffer struct.
  */
 struct vb2_buf_ops {
+	int (*verify_planes_array)(struct vb2_buffer *vb, const void *pb);
 	void (*fill_user_buffer)(struct vb2_buffer *vb, void *pb);
 	int (*fill_vb2_buffer)(struct vb2_buffer *vb, const void *pb,
 				struct vb2_plane *planes);

[toc] | [prev] | [next] | [standalone]


#1392813 — [PATCH 4.5 067/200] nl80211: check netlink protocol in socket release notification

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-05-03 03:20 +0200
Subject[PATCH 4.5 067/200] nl80211: check netlink protocol in socket release notification
Message-ID<ruxaj-6BA-27@gated-at.bofh.it>
In reply to#1392807
4.5-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Dmitry Ivanov <dmitrijs.ivanovs@ubnt.com>

commit 8f815cdde3e550e10c2736990d791f60c2ce43eb upstream.

A non-privileged user can create a netlink socket with the same port_id as
used by an existing open nl80211 netlink socket (e.g. as used by a hostapd
process) with a different protocol number.

Closing this socket will then lead to the notification going to nl80211's
socket release notification handler, and possibly cause an action such as
removing a virtual interface.

Fix this issue by checking that the netlink protocol is NETLINK_GENERIC.
Since generic netlink has no notifier chain of its own, we can't fix the
problem more generically.

Fixes: 026331c4d9b5 ("cfg80211/mac80211: allow registering for and sending action frames")
Signed-off-by: Dmitry Ivanov <dima@ubnt.com>
[rewrite commit message]
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 net/wireless/nl80211.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/net/wireless/nl80211.c
+++ b/net/wireless/nl80211.c
@@ -13201,7 +13201,7 @@ static int nl80211_netlink_notify(struct
 	struct wireless_dev *wdev;
 	struct cfg80211_beacon_registration *reg, *tmp;
 
-	if (state != NETLINK_URELEASE)
+	if (state != NETLINK_URELEASE || notify->protocol != NETLINK_GENERIC)
 		return NOTIFY_DONE;
 
 	rcu_read_lock();

[toc] | [prev] | [next] | [standalone]


#1392814 — [PATCH 4.5 114/200] ASoC: rt5640: Correct the digital interface data select

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-05-03 03:20 +0200
Subject[PATCH 4.5 114/200] ASoC: rt5640: Correct the digital interface data select
Message-ID<ruxaj-6BA-29@gated-at.bofh.it>
In reply to#1392807
4.5-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sugar Zhang <sugar.zhang@rock-chips.com>

commit 653aa4645244042826f105aab1be3d01b3d493ca upstream.

this patch corrects the interface adc/dac control register definition
according to datasheet.

Signed-off-by: Sugar Zhang <sugar.zhang@rock-chips.com>
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 sound/soc/codecs/rt5640.c |    2 +-
 sound/soc/codecs/rt5640.h |   36 ++++++++++++++++++------------------
 2 files changed, 19 insertions(+), 19 deletions(-)

--- a/sound/soc/codecs/rt5640.c
+++ b/sound/soc/codecs/rt5640.c
@@ -359,7 +359,7 @@ static const DECLARE_TLV_DB_RANGE(bst_tl
 
 /* Interface data select */
 static const char * const rt5640_data_select[] = {
-	"Normal", "left copy to right", "right copy to left", "Swap"};
+	"Normal", "Swap", "left copy to right", "right copy to left"};
 
 static SOC_ENUM_SINGLE_DECL(rt5640_if1_dac_enum, RT5640_DIG_INF_DATA,
 			    RT5640_IF1_DAC_SEL_SFT, rt5640_data_select);
--- a/sound/soc/codecs/rt5640.h
+++ b/sound/soc/codecs/rt5640.h
@@ -442,39 +442,39 @@
 #define RT5640_IF1_DAC_SEL_MASK			(0x3 << 14)
 #define RT5640_IF1_DAC_SEL_SFT			14
 #define RT5640_IF1_DAC_SEL_NOR			(0x0 << 14)
-#define RT5640_IF1_DAC_SEL_L2R			(0x1 << 14)
-#define RT5640_IF1_DAC_SEL_R2L			(0x2 << 14)
-#define RT5640_IF1_DAC_SEL_SWAP			(0x3 << 14)
+#define RT5640_IF1_DAC_SEL_SWAP			(0x1 << 14)
+#define RT5640_IF1_DAC_SEL_L2R			(0x2 << 14)
+#define RT5640_IF1_DAC_SEL_R2L			(0x3 << 14)
 #define RT5640_IF1_ADC_SEL_MASK			(0x3 << 12)
 #define RT5640_IF1_ADC_SEL_SFT			12
 #define RT5640_IF1_ADC_SEL_NOR			(0x0 << 12)
-#define RT5640_IF1_ADC_SEL_L2R			(0x1 << 12)
-#define RT5640_IF1_ADC_SEL_R2L			(0x2 << 12)
-#define RT5640_IF1_ADC_SEL_SWAP			(0x3 << 12)
+#define RT5640_IF1_ADC_SEL_SWAP			(0x1 << 12)
+#define RT5640_IF1_ADC_SEL_L2R			(0x2 << 12)
+#define RT5640_IF1_ADC_SEL_R2L			(0x3 << 12)
 #define RT5640_IF2_DAC_SEL_MASK			(0x3 << 10)
 #define RT5640_IF2_DAC_SEL_SFT			10
 #define RT5640_IF2_DAC_SEL_NOR			(0x0 << 10)
-#define RT5640_IF2_DAC_SEL_L2R			(0x1 << 10)
-#define RT5640_IF2_DAC_SEL_R2L			(0x2 << 10)
-#define RT5640_IF2_DAC_SEL_SWAP			(0x3 << 10)
+#define RT5640_IF2_DAC_SEL_SWAP			(0x1 << 10)
+#define RT5640_IF2_DAC_SEL_L2R			(0x2 << 10)
+#define RT5640_IF2_DAC_SEL_R2L			(0x3 << 10)
 #define RT5640_IF2_ADC_SEL_MASK			(0x3 << 8)
 #define RT5640_IF2_ADC_SEL_SFT			8
 #define RT5640_IF2_ADC_SEL_NOR			(0x0 << 8)
-#define RT5640_IF2_ADC_SEL_L2R			(0x1 << 8)
-#define RT5640_IF2_ADC_SEL_R2L			(0x2 << 8)
-#define RT5640_IF2_ADC_SEL_SWAP			(0x3 << 8)
+#define RT5640_IF2_ADC_SEL_SWAP			(0x1 << 8)
+#define RT5640_IF2_ADC_SEL_L2R			(0x2 << 8)
+#define RT5640_IF2_ADC_SEL_R2L			(0x3 << 8)
 #define RT5640_IF3_DAC_SEL_MASK			(0x3 << 6)
 #define RT5640_IF3_DAC_SEL_SFT			6
 #define RT5640_IF3_DAC_SEL_NOR			(0x0 << 6)
-#define RT5640_IF3_DAC_SEL_L2R			(0x1 << 6)
-#define RT5640_IF3_DAC_SEL_R2L			(0x2 << 6)
-#define RT5640_IF3_DAC_SEL_SWAP			(0x3 << 6)
+#define RT5640_IF3_DAC_SEL_SWAP			(0x1 << 6)
+#define RT5640_IF3_DAC_SEL_L2R			(0x2 << 6)
+#define RT5640_IF3_DAC_SEL_R2L			(0x3 << 6)
 #define RT5640_IF3_ADC_SEL_MASK			(0x3 << 4)
 #define RT5640_IF3_ADC_SEL_SFT			4
 #define RT5640_IF3_ADC_SEL_NOR			(0x0 << 4)
-#define RT5640_IF3_ADC_SEL_L2R			(0x1 << 4)
-#define RT5640_IF3_ADC_SEL_R2L			(0x2 << 4)
-#define RT5640_IF3_ADC_SEL_SWAP			(0x3 << 4)
+#define RT5640_IF3_ADC_SEL_SWAP			(0x1 << 4)
+#define RT5640_IF3_ADC_SEL_L2R			(0x2 << 4)
+#define RT5640_IF3_ADC_SEL_R2L			(0x3 << 4)
 
 /* REC Left Mixer Control 1 (0x3b) */
 #define RT5640_G_HP_L_RM_L_MASK			(0x7 << 13)

[toc] | [prev] | [next] | [standalone]


#1392815 — [PATCH 4.5 120/200] cxl: Keep IRQ mappings on context teardown

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-05-03 03:20 +0200
Subject[PATCH 4.5 120/200] cxl: Keep IRQ mappings on context teardown
Message-ID<ruxaj-6BA-31@gated-at.bofh.it>
In reply to#1392807
4.5-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Michael Neuling <mikey@neuling.org>

commit d6776bba44d9752f6cdf640046070e71ee4bba7b upstream.

Keep IRQ mappings on context teardown.  This won't leak IRQs as if we
allocate the mapping again, the generic code will give the same
mapping used last time.

Doing this works around a race in the generic code. Masking the
interrupt introduces a race which can crash the kernel or result in
IRQ that is never EOIed. The lost of EOI results in all subsequent
mappings to the same HW IRQ never receiving an interrupt.

We've seen this race with cxl test cases which are doing heavy context
startup and teardown at the same time as heavy interrupt load.

A fix to the generic code is being investigated also.

Signed-off-by: Michael Neuling <mikey@neuling.org>
Tested-by: Andrew Donnellan <andrew.donnellan@au1.ibm.com>
Acked-by: Ian Munsie <imunsie@au1.ibm.com>
Tested-by: Vaibhav Jain <vaibhav@linux.vnet.ibm.com>
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/misc/cxl/irq.c |    1 -
 1 file changed, 1 deletion(-)

--- a/drivers/misc/cxl/irq.c
+++ b/drivers/misc/cxl/irq.c
@@ -288,7 +288,6 @@ unsigned int cxl_map_irq(struct cxl *ada
 void cxl_unmap_irq(unsigned int virq, void *cookie)
 {
 	free_irq(virq, cookie);
-	irq_dispose_mapping(virq);
 }
 
 static int cxl_register_one_irq(struct cxl *adapter,

[toc] | [prev] | [next] | [standalone]


#1392816 — [PATCH 4.5 066/200] powerpc: Update TM user feature bits in scan_features()

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-05-03 03:20 +0200
Subject[PATCH 4.5 066/200] powerpc: Update TM user feature bits in scan_features()
Message-ID<ruxaj-6BA-33@gated-at.bofh.it>
In reply to#1392807
4.5-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Anton Blanchard <anton@samba.org>

commit 4705e02498d6d5a7ab98dfee9595cd5e91db2017 upstream.

We need to update the user TM feature bits (PPC_FEATURE2_HTM and
PPC_FEATURE2_HTM) to mirror what we do with the kernel TM feature
bit.

At the moment, if firmware reports TM is not available we turn off
the kernel TM feature bit but leave the userspace ones on. Userspace
thinks it can execute TM instructions and it dies trying.

This (together with a QEMU patch) fixes PR KVM, which doesn't currently
support TM.

Signed-off-by: Anton Blanchard <anton@samba.org>
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 arch/powerpc/kernel/prom.c |    9 +++++----
 1 file changed, 5 insertions(+), 4 deletions(-)

--- a/arch/powerpc/kernel/prom.c
+++ b/arch/powerpc/kernel/prom.c
@@ -161,11 +161,12 @@ static struct ibm_pa_feature {
 	{0, MMU_FTR_CI_LARGE_PAGE, 0, 0,		1, 2, 0},
 	{CPU_FTR_REAL_LE, 0, PPC_FEATURE_TRUE_LE, 0, 5, 0, 0},
 	/*
-	 * If the kernel doesn't support TM (ie. CONFIG_PPC_TRANSACTIONAL_MEM=n),
-	 * we don't want to turn on CPU_FTR_TM here, so we use CPU_FTR_TM_COMP
-	 * which is 0 if the kernel doesn't support TM.
+	 * If the kernel doesn't support TM (ie CONFIG_PPC_TRANSACTIONAL_MEM=n),
+	 * we don't want to turn on TM here, so we use the *_COMP versions
+	 * which are 0 if the kernel doesn't support TM.
 	 */
-	{CPU_FTR_TM_COMP, 0, 0, 0,		22, 0, 0},
+	{CPU_FTR_TM_COMP, 0, 0,
+	 PPC_FEATURE2_HTM_COMP|PPC_FEATURE2_HTM_NOSC_COMP, 22, 0, 0},
 };
 
 static void __init scan_features(unsigned long node, const unsigned char *ftrs,

[toc] | [prev] | [next] | [standalone]


#1392817 — [PATCH 4.5 116/200] [media] media: vb2: Fix regression on poll() for RW mode

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-05-03 03:20 +0200
Subject[PATCH 4.5 116/200] [media] media: vb2: Fix regression on poll() for RW mode
Message-ID<ruxaj-6BA-35@gated-at.bofh.it>
In reply to#1392807
4.5-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ricardo Ribalda Delgado <ricardo.ribalda@gmail.com>

commit b93876845c5e30a92964eeb088d9d2e024118022 upstream.

When using a device is read/write mode, vb2 does not handle properly the
first select/poll operation.

The reason for this, is that when this code has been refactored, some of
the operations have changed their order, and now fileio emulator is not
started.

The reintroduced check to the core is enabled by a quirk flag, that
avoids this check by other subsystems like DVB.

Fixes: 49d8ab9feaf2 ("media] media: videobuf2: Separate vb2_poll()")

Reported-by: Dimitrios Katsaros <patcherwork@gmail.com>
Cc: Junghak Sung <jh1009.sung@samsung.com>
Signed-off-by: Ricardo Ribalda Delgado <ricardo.ribalda@gmail.com>
Signed-off-by: Hans Verkuil <hans.verkuil@cisco.com>
Signed-off-by: Mauro Carvalho Chehab <mchehab@osg.samsung.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/media/v4l2-core/videobuf2-core.c |   10 ++++++++++
 drivers/media/v4l2-core/videobuf2-v4l2.c |   14 ++++++--------
 include/media/videobuf2-core.h           |    4 ++++
 3 files changed, 20 insertions(+), 8 deletions(-)

--- a/drivers/media/v4l2-core/videobuf2-core.c
+++ b/drivers/media/v4l2-core/videobuf2-core.c
@@ -2293,6 +2293,16 @@ unsigned int vb2_core_poll(struct vb2_qu
 		return POLLERR;
 
 	/*
+	 * If this quirk is set and QBUF hasn't been called yet then
+	 * return POLLERR as well. This only affects capture queues, output
+	 * queues will always initialize waiting_for_buffers to false.
+	 * This quirk is set by V4L2 for backwards compatibility reasons.
+	 */
+	if (q->quirk_poll_must_check_waiting_for_buffers &&
+	    q->waiting_for_buffers && (req_events & (POLLIN | POLLRDNORM)))
+		return POLLERR;
+
+	/*
 	 * For output streams you can call write() as long as there are fewer
 	 * buffers queued than there are buffers available.
 	 */
--- a/drivers/media/v4l2-core/videobuf2-v4l2.c
+++ b/drivers/media/v4l2-core/videobuf2-v4l2.c
@@ -765,6 +765,12 @@ int vb2_queue_init(struct vb2_queue *q)
 	q->is_output = V4L2_TYPE_IS_OUTPUT(q->type);
 	q->copy_timestamp = (q->timestamp_flags & V4L2_BUF_FLAG_TIMESTAMP_MASK)
 			== V4L2_BUF_FLAG_TIMESTAMP_COPY;
+	/*
+	 * For compatibility with vb1: if QBUF hasn't been called yet, then
+	 * return POLLERR as well. This only affects capture queues, output
+	 * queues will always initialize waiting_for_buffers to false.
+	 */
+	q->quirk_poll_must_check_waiting_for_buffers = true;
 
 	return vb2_core_queue_init(q);
 }
@@ -818,14 +824,6 @@ unsigned int vb2_poll(struct vb2_queue *
 			poll_wait(file, &fh->wait, wait);
 	}
 
-	/*
-	 * For compatibility with vb1: if QBUF hasn't been called yet, then
-	 * return POLLERR as well. This only affects capture queues, output
-	 * queues will always initialize waiting_for_buffers to false.
-	 */
-	if (q->waiting_for_buffers && (req_events & (POLLIN | POLLRDNORM)))
-		return POLLERR;
-
 	return res | vb2_core_poll(q, file, wait);
 }
 EXPORT_SYMBOL_GPL(vb2_poll);
--- a/include/media/videobuf2-core.h
+++ b/include/media/videobuf2-core.h
@@ -400,6 +400,9 @@ struct vb2_buf_ops {
  * @fileio_read_once:		report EOF after reading the first buffer
  * @fileio_write_immediately:	queue buffer after each write() call
  * @allow_zero_bytesused:	allow bytesused == 0 to be passed to the driver
+ * @quirk_poll_must_check_waiting_for_buffers: Return POLLERR at poll when QBUF
+ *              has not been called. This is a vb1 idiom that has been adopted
+ *              also by vb2.
  * @lock:	pointer to a mutex that protects the vb2_queue struct. The
  *		driver can set this to a mutex to let the v4l2 core serialize
  *		the queuing ioctls. If the driver wants to handle locking
@@ -463,6 +466,7 @@ struct vb2_queue {
 	unsigned			fileio_read_once:1;
 	unsigned			fileio_write_immediately:1;
 	unsigned			allow_zero_bytesused:1;
+	unsigned		   quirk_poll_must_check_waiting_for_buffers:1;
 
 	struct mutex			*lock;
 	void				*owner;

[toc] | [prev] | [next] | [standalone]


#1392818 — [PATCH 4.5 062/200] crypto: talitos - fix crash in talitos_cra_init()

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-05-03 03:20 +0200
Subject[PATCH 4.5 062/200] crypto: talitos - fix crash in talitos_cra_init()
Message-ID<ruxaj-6BA-37@gated-at.bofh.it>
In reply to#1392807
4.5-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jonas Eymann <J.Eymann@gmx.net>

commit 89d124cb61b39900959e2839ac06b6339b6a54cb upstream.

Conversion of talitos driver to the new AEAD interface
hasn't been properly tested.

AEAD algorithms crash in talitos_cra_init as follows:

[...]
[    1.141095] talitos ffe30000.crypto: hwrng
[    1.145381] Unable to handle kernel paging request for data at address 0x00000058
[    1.152913] Faulting instruction address: 0xc02accc0
[    1.157910] Oops: Kernel access of bad area, sig: 11 [#1]
[    1.163315] SMP NR_CPUS=2 P1020 RDB
[    1.166810] Modules linked in:
[    1.169875] CPU: 0 PID: 1007 Comm: cryptomgr_test Not tainted 4.4.6 #1
[    1.176415] task: db5ec200 ti: db4d6000 task.ti: db4d6000
[    1.181821] NIP: c02accc0 LR: c02acd18 CTR: c02acd04
[    1.186793] REGS: db4d7d30 TRAP: 0300   Not tainted  (4.4.6)
[    1.192457] MSR: 00029000 <CE,EE,ME>  CR: 95009359  XER: e0000000
[    1.198585] DEAR: 00000058 ESR: 00000000
GPR00: c017bdc0 db4d7de0 db5ec200 df424b48 00000000 00000000 df424bfc db75a600
GPR08: df424b48 00000000 db75a628 db4d6000 00000149 00000000 c0044cac db5acda0
GPR16: 00000000 00000000 00000000 00000000 00000000 00000000 00000400 df424940
GPR24: df424900 00003083 00000400 c0180000 db75a640 c03e9f84 df424b40 df424b48
[    1.230978] NIP [c02accc0] talitos_cra_init+0x28/0x6c
[    1.236039] LR [c02acd18] talitos_cra_init_aead+0x14/0x28
[    1.241443] Call Trace:
[    1.243894] [db4d7de0] [c03e9f84] 0xc03e9f84 (unreliable)
[    1.249322] [db4d7df0] [c017bdc0] crypto_create_tfm+0x5c/0xf0
[    1.255083] [db4d7e10] [c017beec] crypto_alloc_tfm+0x98/0xf8
[    1.260769] [db4d7e40] [c0186a20] alg_test_aead+0x28/0xc8
[    1.266181] [db4d7e60] [c0186718] alg_test+0x260/0x2e0
[    1.271333] [db4d7ee0] [c0183860] cryptomgr_test+0x30/0x54
[    1.276843] [db4d7ef0] [c0044d80] kthread+0xd4/0xd8
[    1.281741] [db4d7f40] [c000e4a4] ret_from_kernel_thread+0x5c/0x64
[    1.287930] Instruction dump:
[    1.290902] 38600000 4e800020 81230028 7c681b78 81490010 38e9ffc0 3929ffe8 554a073e
[    1.298691] 2b8a000a 7d474f9e 812a0008 91230030 <80e90058> 39270060 7c0004ac 7cc04828

Fixes: aeb4c132f33d ("crypto: talitos - Convert to new AEAD interface")
Signed-off-by: Jonas Eymann <J.Eymann@gmx.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

Fix typo - replaced parameter of __crypto_ahash_alg(): s/tfm/alg
Remove checkpatch warnings.
Add commit message.

Signed-off-by: Horia Geant? <horia.geanta@nxp.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>

---
 drivers/crypto/talitos.c |   41 +++++++++++++++++++++++++++--------------
 1 file changed, 27 insertions(+), 14 deletions(-)

--- a/drivers/crypto/talitos.c
+++ b/drivers/crypto/talitos.c
@@ -2629,21 +2629,11 @@ struct talitos_crypto_alg {
 	struct talitos_alg_template algt;
 };
 
-static int talitos_cra_init(struct crypto_tfm *tfm)
+static int talitos_init_common(struct talitos_ctx *ctx,
+			       struct talitos_crypto_alg *talitos_alg)
 {
-	struct crypto_alg *alg = tfm->__crt_alg;
-	struct talitos_crypto_alg *talitos_alg;
-	struct talitos_ctx *ctx = crypto_tfm_ctx(tfm);
 	struct talitos_private *priv;
 
-	if ((alg->cra_flags & CRYPTO_ALG_TYPE_MASK) == CRYPTO_ALG_TYPE_AHASH)
-		talitos_alg = container_of(__crypto_ahash_alg(alg),
-					   struct talitos_crypto_alg,
-					   algt.alg.hash);
-	else
-		talitos_alg = container_of(alg, struct talitos_crypto_alg,
-					   algt.alg.crypto);
-
 	/* update context with ptr to dev */
 	ctx->dev = talitos_alg->dev;
 
@@ -2661,10 +2651,33 @@ static int talitos_cra_init(struct crypt
 	return 0;
 }
 
+static int talitos_cra_init(struct crypto_tfm *tfm)
+{
+	struct crypto_alg *alg = tfm->__crt_alg;
+	struct talitos_crypto_alg *talitos_alg;
+	struct talitos_ctx *ctx = crypto_tfm_ctx(tfm);
+
+	if ((alg->cra_flags & CRYPTO_ALG_TYPE_MASK) == CRYPTO_ALG_TYPE_AHASH)
+		talitos_alg = container_of(__crypto_ahash_alg(alg),
+					   struct talitos_crypto_alg,
+					   algt.alg.hash);
+	else
+		talitos_alg = container_of(alg, struct talitos_crypto_alg,
+					   algt.alg.crypto);
+
+	return talitos_init_common(ctx, talitos_alg);
+}
+
 static int talitos_cra_init_aead(struct crypto_aead *tfm)
 {
-	talitos_cra_init(crypto_aead_tfm(tfm));
-	return 0;
+	struct aead_alg *alg = crypto_aead_alg(tfm);
+	struct talitos_crypto_alg *talitos_alg;
+	struct talitos_ctx *ctx = crypto_aead_ctx(tfm);
+
+	talitos_alg = container_of(alg, struct talitos_crypto_alg,
+				   algt.alg.aead);
+
+	return talitos_init_common(ctx, talitos_alg);
 }
 
 static int talitos_cra_init_ahash(struct crypto_tfm *tfm)

[toc] | [prev] | [next] | [standalone]


#1392819 — [PATCH 4.5 096/200] drm/amdkfd: uninitialized variable in dbgdev_wave_control_set_registers()

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-05-03 03:20 +0200
Subject[PATCH 4.5 096/200] drm/amdkfd: uninitialized variable in dbgdev_wave_control_set_registers()
Message-ID<ruxaj-6BA-39@gated-at.bofh.it>
In reply to#1392807
4.5-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Dan Carpenter <dan.carpenter@oracle.com>

commit 93fce954427effee89e44a976299b15dd75b4bbc upstream.

At the end of the function we expect "status" to be zero, but it's
either -EINVAL or uninitialized.

Fixes: 788bf83db301 ('drm/amdkfd: Add wave control operation to debugger')
Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: Oded Gabbay <oded.gabbay@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/gpu/drm/amd/amdkfd/kfd_dbgdev.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/gpu/drm/amd/amdkfd/kfd_dbgdev.c
+++ b/drivers/gpu/drm/amd/amdkfd/kfd_dbgdev.c
@@ -513,7 +513,7 @@ static int dbgdev_wave_control_set_regis
 				union SQ_CMD_BITS *in_reg_sq_cmd,
 				union GRBM_GFX_INDEX_BITS *in_reg_gfx_index)
 {
-	int status;
+	int status = 0;
 	union SQ_CMD_BITS reg_sq_cmd;
 	union GRBM_GFX_INDEX_BITS reg_gfx_index;
 	struct HsaDbgWaveMsgAMDGen2 *pMsg;

[toc] | [prev] | [next] | [standalone]


#1392820 — [PATCH 4.5 070/200] Input: pmic8xxx-pwrkey - fix algorithm for converting trigger delay

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-05-03 03:20 +0200
Subject[PATCH 4.5 070/200] Input: pmic8xxx-pwrkey - fix algorithm for converting trigger delay
Message-ID<ruxaj-6BA-41@gated-at.bofh.it>
In reply to#1392807
4.5-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Stephen Boyd <sboyd@codeaurora.org>

commit eda5ecc0a6b865561997e177c393f0b0136fe3b7 upstream.

The trigger delay algorithm that converts from microseconds to
the register value looks incorrect. According to most of the PMIC
documentation, the equation is

	delay (Seconds) = (1 / 1024) * 2 ^ (x + 4)

except for one case where the documentation looks to have a
formatting issue and the equation looks like

	delay (Seconds) = (1 / 1024) * 2 x + 4

Most likely this driver was written with the improper
documentation to begin with. According to the downstream sources
the valid delays are from 2 seconds to 1/64 second, and the
latter equation just doesn't make sense for that. Let's fix the
algorithm and the range check to match the documentation and the
downstream sources.

Reported-by: Bjorn Andersson <bjorn.andersson@linaro.org>
Fixes: 92d57a73e410 ("input: Add support for Qualcomm PMIC8XXX power key")
Signed-off-by: Stephen Boyd <sboyd@codeaurora.org>
Tested-by: John Stultz <john.stultz@linaro.org>
Acked-by: Bjorn Andersson <bjorn.andersson@linaro.org>
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/input/misc/pmic8xxx-pwrkey.c |    7 ++++---
 1 file changed, 4 insertions(+), 3 deletions(-)

--- a/drivers/input/misc/pmic8xxx-pwrkey.c
+++ b/drivers/input/misc/pmic8xxx-pwrkey.c
@@ -353,7 +353,8 @@ static int pmic8xxx_pwrkey_probe(struct
 	if (of_property_read_u32(pdev->dev.of_node, "debounce", &kpd_delay))
 		kpd_delay = 15625;
 
-	if (kpd_delay > 62500 || kpd_delay == 0) {
+	/* Valid range of pwr key trigger delay is 1/64 sec to 2 seconds. */
+	if (kpd_delay > USEC_PER_SEC * 2 || kpd_delay < USEC_PER_SEC / 64) {
 		dev_err(&pdev->dev, "invalid power key trigger delay\n");
 		return -EINVAL;
 	}
@@ -385,8 +386,8 @@ static int pmic8xxx_pwrkey_probe(struct
 	pwr->name = "pmic8xxx_pwrkey";
 	pwr->phys = "pmic8xxx_pwrkey/input0";
 
-	delay = (kpd_delay << 10) / USEC_PER_SEC;
-	delay = 1 + ilog2(delay);
+	delay = (kpd_delay << 6) / USEC_PER_SEC;
+	delay = ilog2(delay);
 
 	err = regmap_read(regmap, PON_CNTL_1, &pon_cntl);
 	if (err < 0) {

[toc] | [prev] | [next] | [standalone]


#1392821 — [PATCH 4.5 118/200] [media] videobuf2-v4l2: Verify planes array in buffer dequeueing

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-05-03 03:20 +0200
Subject[PATCH 4.5 118/200] [media] videobuf2-v4l2: Verify planes array in buffer dequeueing
Message-ID<ruxaj-6BA-43@gated-at.bofh.it>
In reply to#1392807
4.5-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sakari Ailus <sakari.ailus@linux.intel.com>

commit 2c1f6951a8a82e6de0d82b1158b5e493fc6c54ab upstream.

When a buffer is being dequeued using VIDIOC_DQBUF IOCTL, the exact buffer
which will be dequeued is not known until the buffer has been removed from
the queue. The number of planes is specific to a buffer, not to the queue.

This does lead to the situation where multi-plane buffers may be requested
and queued with n planes, but VIDIOC_DQBUF IOCTL may be passed an argument
struct with fewer planes.

__fill_v4l2_buffer() however uses the number of planes from the dequeued
videobuf2 buffer, overwriting kernel memory (the m.planes array allocated
in video_usercopy() in v4l2-ioctl.c)  if the user provided fewer
planes than the dequeued buffer had. Oops!

Fixes: b0e0e1f83de3 ("[media] media: videobuf2: Prepare to divide videobuf2")

Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
Acked-by: Hans Verkuil <hans.verkuil@cisco.com>
Signed-off-by: Mauro Carvalho Chehab <mchehab@osg.samsung.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/media/v4l2-core/videobuf2-v4l2.c |    6 ++++++
 1 file changed, 6 insertions(+)

--- a/drivers/media/v4l2-core/videobuf2-v4l2.c
+++ b/drivers/media/v4l2-core/videobuf2-v4l2.c
@@ -74,6 +74,11 @@ static int __verify_planes_array(struct
 	return 0;
 }
 
+static int __verify_planes_array_core(struct vb2_buffer *vb, const void *pb)
+{
+	return __verify_planes_array(vb, pb);
+}
+
 /**
  * __verify_length() - Verify that the bytesused value for each plane fits in
  * the plane length and that the data offset doesn't exceed the bytesused value.
@@ -437,6 +442,7 @@ static int __fill_vb2_buffer(struct vb2_
 }
 
 static const struct vb2_buf_ops v4l2_buf_ops = {
+	.verify_planes_array	= __verify_planes_array_core,
 	.fill_user_buffer	= __fill_v4l2_buffer,
 	.fill_vb2_buffer	= __fill_vb2_buffer,
 	.copy_timestamp		= __copy_timestamp,

[toc] | [prev] | [next] | [standalone]


#1399339 — Re: [PATCH 4.5 118/200] [media] videobuf2-v4l2: Verify planes array in buffer dequeueing

FromMauro Carvalho Chehab <mchehab@osg.samsung.com>
Date2016-05-11 18:40 +0200
SubjectRe: [PATCH 4.5 118/200] [media] videobuf2-v4l2: Verify planes array in buffer dequeueing
Message-ID<rxFl1-3u1-33@gated-at.bofh.it>
In reply to#1392821
Hi Greg,

This patch seems to be causing trobles with DVB drivers that uses
videobuf2-dvb.

Just sent a patch reverting it.

Regards,
Mauro

Em Mon, 2 May 2016 17:11:57 -0700
Greg Kroah-Hartman <gregkh@linuxfoundation.org> escreveu:

> 4.5-stable review patch.  If anyone has any objections, please let me know.
> 
> ------------------
> 
> From: Sakari Ailus <sakari.ailus@linux.intel.com>
> 
> commit 2c1f6951a8a82e6de0d82b1158b5e493fc6c54ab upstream.
> 
> When a buffer is being dequeued using VIDIOC_DQBUF IOCTL, the exact buffer
> which will be dequeued is not known until the buffer has been removed from
> the queue. The number of planes is specific to a buffer, not to the queue.
> 
> This does lead to the situation where multi-plane buffers may be requested
> and queued with n planes, but VIDIOC_DQBUF IOCTL may be passed an argument
> struct with fewer planes.
> 
> __fill_v4l2_buffer() however uses the number of planes from the dequeued
> videobuf2 buffer, overwriting kernel memory (the m.planes array allocated
> in video_usercopy() in v4l2-ioctl.c)  if the user provided fewer
> planes than the dequeued buffer had. Oops!
> 
> Fixes: b0e0e1f83de3 ("[media] media: videobuf2: Prepare to divide videobuf2")
> 
> Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
> Acked-by: Hans Verkuil <hans.verkuil@cisco.com>
> Signed-off-by: Mauro Carvalho Chehab <mchehab@osg.samsung.com>
> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
> 
> ---
>  drivers/media/v4l2-core/videobuf2-v4l2.c |    6 ++++++
>  1 file changed, 6 insertions(+)
> 
> --- a/drivers/media/v4l2-core/videobuf2-v4l2.c
> +++ b/drivers/media/v4l2-core/videobuf2-v4l2.c
> @@ -74,6 +74,11 @@ static int __verify_planes_array(struct
>  	return 0;
>  }
>  
> +static int __verify_planes_array_core(struct vb2_buffer *vb, const void *pb)
> +{
> +	return __verify_planes_array(vb, pb);
> +}
> +
>  /**
>   * __verify_length() - Verify that the bytesused value for each plane fits in
>   * the plane length and that the data offset doesn't exceed the bytesused value.
> @@ -437,6 +442,7 @@ static int __fill_vb2_buffer(struct vb2_
>  }
>  
>  static const struct vb2_buf_ops v4l2_buf_ops = {
> +	.verify_planes_array	= __verify_planes_array_core,
>  	.fill_user_buffer	= __fill_v4l2_buffer,
>  	.fill_vb2_buffer	= __fill_vb2_buffer,
>  	.copy_timestamp		= __copy_timestamp,
> 
> 


-- 
Thanks,
Mauro

[toc] | [prev] | [next] | [standalone]


#1392822 — [PATCH 4.5 119/200] [media] v4l2-dv-timings.h: fix polarity for 4k formats

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-05-03 03:20 +0200
Subject[PATCH 4.5 119/200] [media] v4l2-dv-timings.h: fix polarity for 4k formats
Message-ID<ruxaj-6BA-47@gated-at.bofh.it>
In reply to#1392807
4.5-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Hans Verkuil <hverkuil@xs4all.nl>

commit 3020ca711871fdaf0c15c8bab677a6bc302e28fe upstream.

The VSync polarity was negative instead of positive for the 4k CEA formats.
I probably copy-and-pasted these from the DMT 4k format, which does have a
negative VSync polarity.

Signed-off-by: Hans Verkuil <hans.verkuil@cisco.com>
Reported-by: Martin Bugge <marbugge@cisco.com>
Signed-off-by: Mauro Carvalho Chehab <mchehab@osg.samsung.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 include/uapi/linux/v4l2-dv-timings.h |   30 ++++++++++++++++++++----------
 1 file changed, 20 insertions(+), 10 deletions(-)

--- a/include/uapi/linux/v4l2-dv-timings.h
+++ b/include/uapi/linux/v4l2-dv-timings.h
@@ -183,7 +183,8 @@
 
 #define V4L2_DV_BT_CEA_3840X2160P24 { \
 	.type = V4L2_DV_BT_656_1120, \
-	V4L2_INIT_BT_TIMINGS(3840, 2160, 0, V4L2_DV_HSYNC_POS_POL, \
+	V4L2_INIT_BT_TIMINGS(3840, 2160, 0, \
+		V4L2_DV_HSYNC_POS_POL | V4L2_DV_VSYNC_POS_POL, \
 		297000000, 1276, 88, 296, 8, 10, 72, 0, 0, 0, \
 		V4L2_DV_BT_STD_CEA861, \
 		V4L2_DV_FL_CAN_REDUCE_FPS | V4L2_DV_FL_IS_CE_VIDEO) \
@@ -191,14 +192,16 @@
 
 #define V4L2_DV_BT_CEA_3840X2160P25 { \
 	.type = V4L2_DV_BT_656_1120, \
-	V4L2_INIT_BT_TIMINGS(3840, 2160, 0, V4L2_DV_HSYNC_POS_POL, \
+	V4L2_INIT_BT_TIMINGS(3840, 2160, 0, \
+		V4L2_DV_HSYNC_POS_POL | V4L2_DV_VSYNC_POS_POL, \
 		297000000, 1056, 88, 296, 8, 10, 72, 0, 0, 0, \
 		V4L2_DV_BT_STD_CEA861, V4L2_DV_FL_IS_CE_VIDEO) \
 }
 
 #define V4L2_DV_BT_CEA_3840X2160P30 { \
 	.type = V4L2_DV_BT_656_1120, \
-	V4L2_INIT_BT_TIMINGS(3840, 2160, 0, V4L2_DV_HSYNC_POS_POL, \
+	V4L2_INIT_BT_TIMINGS(3840, 2160, 0, \
+		V4L2_DV_HSYNC_POS_POL | V4L2_DV_VSYNC_POS_POL, \
 		297000000, 176, 88, 296, 8, 10, 72, 0, 0, 0, \
 		V4L2_DV_BT_STD_CEA861, \
 		V4L2_DV_FL_CAN_REDUCE_FPS | V4L2_DV_FL_IS_CE_VIDEO) \
@@ -206,14 +209,16 @@
 
 #define V4L2_DV_BT_CEA_3840X2160P50 { \
 	.type = V4L2_DV_BT_656_1120, \
-	V4L2_INIT_BT_TIMINGS(3840, 2160, 0, V4L2_DV_HSYNC_POS_POL, \
+	V4L2_INIT_BT_TIMINGS(3840, 2160, 0, \
+		V4L2_DV_HSYNC_POS_POL | V4L2_DV_VSYNC_POS_POL, \
 		594000000, 1056, 88, 296, 8, 10, 72, 0, 0, 0, \
 		V4L2_DV_BT_STD_CEA861, V4L2_DV_FL_IS_CE_VIDEO) \
 }
 
 #define V4L2_DV_BT_CEA_3840X2160P60 { \
 	.type = V4L2_DV_BT_656_1120, \
-	V4L2_INIT_BT_TIMINGS(3840, 2160, 0, V4L2_DV_HSYNC_POS_POL, \
+	V4L2_INIT_BT_TIMINGS(3840, 2160, 0, \
+		V4L2_DV_HSYNC_POS_POL | V4L2_DV_VSYNC_POS_POL, \
 		594000000, 176, 88, 296, 8, 10, 72, 0, 0, 0, \
 		V4L2_DV_BT_STD_CEA861, \
 		V4L2_DV_FL_CAN_REDUCE_FPS | V4L2_DV_FL_IS_CE_VIDEO) \
@@ -221,7 +226,8 @@
 
 #define V4L2_DV_BT_CEA_4096X2160P24 { \
 	.type = V4L2_DV_BT_656_1120, \
-	V4L2_INIT_BT_TIMINGS(4096, 2160, 0, V4L2_DV_HSYNC_POS_POL, \
+	V4L2_INIT_BT_TIMINGS(4096, 2160, 0, \
+		V4L2_DV_HSYNC_POS_POL | V4L2_DV_VSYNC_POS_POL, \
 		297000000, 1020, 88, 296, 8, 10, 72, 0, 0, 0, \
 		V4L2_DV_BT_STD_CEA861, \
 		V4L2_DV_FL_CAN_REDUCE_FPS | V4L2_DV_FL_IS_CE_VIDEO) \
@@ -229,14 +235,16 @@
 
 #define V4L2_DV_BT_CEA_4096X2160P25 { \
 	.type = V4L2_DV_BT_656_1120, \
-	V4L2_INIT_BT_TIMINGS(4096, 2160, 0, V4L2_DV_HSYNC_POS_POL, \
+	V4L2_INIT_BT_TIMINGS(4096, 2160, 0, \
+		V4L2_DV_HSYNC_POS_POL | V4L2_DV_VSYNC_POS_POL, \
 		297000000, 968, 88, 128, 8, 10, 72, 0, 0, 0, \
 		V4L2_DV_BT_STD_CEA861, V4L2_DV_FL_IS_CE_VIDEO) \
 }
 
 #define V4L2_DV_BT_CEA_4096X2160P30 { \
 	.type = V4L2_DV_BT_656_1120, \
-	V4L2_INIT_BT_TIMINGS(4096, 2160, 0, V4L2_DV_HSYNC_POS_POL, \
+	V4L2_INIT_BT_TIMINGS(4096, 2160, 0, \
+		V4L2_DV_HSYNC_POS_POL | V4L2_DV_VSYNC_POS_POL, \
 		297000000, 88, 88, 128, 8, 10, 72, 0, 0, 0, \
 		V4L2_DV_BT_STD_CEA861, \
 		V4L2_DV_FL_CAN_REDUCE_FPS | V4L2_DV_FL_IS_CE_VIDEO) \
@@ -244,14 +252,16 @@
 
 #define V4L2_DV_BT_CEA_4096X2160P50 { \
 	.type = V4L2_DV_BT_656_1120, \
-	V4L2_INIT_BT_TIMINGS(4096, 2160, 0, V4L2_DV_HSYNC_POS_POL, \
+	V4L2_INIT_BT_TIMINGS(4096, 2160, 0, \
+		V4L2_DV_HSYNC_POS_POL | V4L2_DV_VSYNC_POS_POL, \
 		594000000, 968, 88, 128, 8, 10, 72, 0, 0, 0, \
 		V4L2_DV_BT_STD_CEA861, V4L2_DV_FL_IS_CE_VIDEO) \
 }
 
 #define V4L2_DV_BT_CEA_4096X2160P60 { \
 	.type = V4L2_DV_BT_656_1120, \
-	V4L2_INIT_BT_TIMINGS(4096, 2160, 0, V4L2_DV_HSYNC_POS_POL, \
+	V4L2_INIT_BT_TIMINGS(4096, 2160, 0, \
+		V4L2_DV_HSYNC_POS_POL | V4L2_DV_VSYNC_POS_POL, \
 		594000000, 88, 88, 128, 8, 10, 72, 0, 0, 0, \
 		V4L2_DV_BT_STD_CEA861, \
 		V4L2_DV_FL_CAN_REDUCE_FPS | V4L2_DV_FL_IS_CE_VIDEO) \

[toc] | [prev] | [next] | [standalone]


#1392823 — [PATCH 4.5 107/200] ACPICA / Interpreter: Fix a regression triggered because of wrong Linux ECDT support

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-05-03 03:20 +0200
Subject[PATCH 4.5 107/200] ACPICA / Interpreter: Fix a regression triggered because of wrong Linux ECDT support
Message-ID<ruxaj-6BA-49@gated-at.bofh.it>
In reply to#1392807
4.5-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Lv Zheng <lv.zheng@intel.com>

commit 5508df89756f8378024828e185724a9bd2348985 upstream.

It is reported that the following commit triggers regressions:
 Linux commit: efaed9be998b5ae0afb7458e057e5f4402b43fa0
 ACPICA commit: 31178590dde82368fdb0f6b0e466b6c0add96c57
 Subject: ACPICA: Events: Enhance acpi_ev_execute_reg_method() to
          ensure no _REG evaluations can happen during OS early boot
          stages

This is because that the ECDT support is not corrected in Linux, and Linux
requires to execute _REG for ECDT (though this sounds so wrong), we need to
ensure acpi_gbl_namespace_initialized is set before ECDT probing in order
for _REG to be executed. Since we have to move
"acpi_gbl_namespace_initialized = TRUE" to the initialization step
happening before ECDT probing, acpi_load_tables() is the best candidate for
now. Thus this patch fixes the regression by doing so.

But if the ECDT support is fixed, Linux will not execute _REG for ECDT, and
ECDT probing will happen before acpi_load_tables(). At that time, we still
want to ensure acpi_gbl_namespace_initialized is set after executing
acpi_ns_initialize_objects() (under the condition of
acpi_gbl_group_module_level_code = FALSE), this patch also moves
acpi_ns_initialize_objects() to acpi_load_tables() accordingly.

Since acpi_ns_initialize_objects() doesn't seem to be skippable, this
patch also removes ACPI_NO_OBJECT_INIT for the one invoked in
acpi_load_tables(). And since the default region handlers should always be
installed before loading the tables, this patch also removes useless
acpi_gbl_group_module_level_code check accordingly. Reported by Chris
Bainbridge, Fixed by Lv Zheng.

Fixes: efaed9be998b (ACPICA: Events: Enhance acpi_ev_execute_reg_method() to ensure no _REG evaluations can happen during OS early boot stages)
Reported-and-tested-by: Chris Bainbridge <chris.bainbridge@gmail.com>
Signed-off-by: Lv Zheng <lv.zheng@intel.com>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/acpi/acpica/nsinit.c   |    2 ++
 drivers/acpi/acpica/tbxfload.c |   14 ++++++++++++++
 drivers/acpi/acpica/utxfinit.c |   25 +++++++++++--------------
 3 files changed, 27 insertions(+), 14 deletions(-)

--- a/drivers/acpi/acpica/nsinit.c
+++ b/drivers/acpi/acpica/nsinit.c
@@ -83,6 +83,8 @@ acpi_status acpi_ns_initialize_objects(v
 
 	ACPI_FUNCTION_TRACE(ns_initialize_objects);
 
+	ACPI_DEBUG_PRINT((ACPI_DB_EXEC,
+			  "[Init] Completing Initialization of ACPI Objects\n"));
 	ACPI_DEBUG_PRINT((ACPI_DB_DISPATCH,
 			  "**** Starting initialization of namespace objects ****\n"));
 	ACPI_DEBUG_PRINT_RAW((ACPI_DB_INIT,
--- a/drivers/acpi/acpica/tbxfload.c
+++ b/drivers/acpi/acpica/tbxfload.c
@@ -83,6 +83,20 @@ acpi_status __init acpi_load_tables(void
 				"While loading namespace from ACPI tables"));
 	}
 
+	if (!acpi_gbl_group_module_level_code) {
+		/*
+		 * Initialize the objects that remain uninitialized. This
+		 * runs the executable AML that may be part of the
+		 * declaration of these objects:
+		 * operation_regions, buffer_fields, Buffers, and Packages.
+		 */
+		status = acpi_ns_initialize_objects();
+		if (ACPI_FAILURE(status)) {
+			return_ACPI_STATUS(status);
+		}
+	}
+
+	acpi_gbl_reg_methods_enabled = TRUE;
 	return_ACPI_STATUS(status);
 }
 
--- a/drivers/acpi/acpica/utxfinit.c
+++ b/drivers/acpi/acpica/utxfinit.c
@@ -267,7 +267,6 @@ acpi_status __init acpi_initialize_objec
 	 * initialized, even if they contain executable AML (see the call to
 	 * acpi_ns_initialize_objects below).
 	 */
-	acpi_gbl_reg_methods_enabled = TRUE;
 	if (!(flags & ACPI_NO_ADDRESS_SPACE_INIT)) {
 		ACPI_DEBUG_PRINT((ACPI_DB_EXEC,
 				  "[Init] Executing _REG OpRegion methods\n"));
@@ -299,20 +298,18 @@ acpi_status __init acpi_initialize_objec
 	 */
 	if (acpi_gbl_group_module_level_code) {
 		acpi_ns_exec_module_code_list();
-	}
 
-	/*
-	 * Initialize the objects that remain uninitialized. This runs the
-	 * executable AML that may be part of the declaration of these objects:
-	 * operation_regions, buffer_fields, Buffers, and Packages.
-	 */
-	if (!(flags & ACPI_NO_OBJECT_INIT)) {
-		ACPI_DEBUG_PRINT((ACPI_DB_EXEC,
-				  "[Init] Completing Initialization of ACPI Objects\n"));
-
-		status = acpi_ns_initialize_objects();
-		if (ACPI_FAILURE(status)) {
-			return_ACPI_STATUS(status);
+		/*
+		 * Initialize the objects that remain uninitialized. This
+		 * runs the executable AML that may be part of the
+		 * declaration of these objects:
+		 * operation_regions, buffer_fields, Buffers, and Packages.
+		 */
+		if (!(flags & ACPI_NO_OBJECT_INIT)) {
+			status = acpi_ns_initialize_objects();
+			if (ACPI_FAILURE(status)) {
+				return_ACPI_STATUS(status);
+			}
 		}
 	}
 

[toc] | [prev] | [next] | [standalone]


#1392824 — [PATCH 4.5 112/200] ASoC: ssm4567: Reset device before regcache_sync()

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-05-03 03:20 +0200
Subject[PATCH 4.5 112/200] ASoC: ssm4567: Reset device before regcache_sync()
Message-ID<ruxak-6BA-55@gated-at.bofh.it>
In reply to#1392807
4.5-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Lars-Peter Clausen <lars@metafoo.de>

commit 712a8038cc24dba668afe82f0413714ca87184e0 upstream.

When the ssm4567 is powered up the driver calles regcache_sync() to restore
the register map content. regcache_sync() assumes that the device is in its
power-on reset state. Make sure that this is the case by explicitly
resetting the ssm4567 register map before calling regcache_sync() otherwise
we might end up with a incorrect register map which leads to undefined
behaviour.

One such undefined behaviour was observed when returning from system
suspend while a playback stream is active, in that case the ssm4567 was
kept muted after resume.

Fixes: 1ee44ce03011 ("ASoC: ssm4567: Add driver for Analog Devices SSM4567 amplifier")
Reported-by: Harsha Priya <harshapriya.n@intel.com>
Tested-by: Fang, Yang A <yang.a.fang@intel.com>
Signed-off-by: Lars-Peter Clausen <lars@metafoo.de>
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 sound/soc/codecs/ssm4567.c |    5 +++++
 1 file changed, 5 insertions(+)

--- a/sound/soc/codecs/ssm4567.c
+++ b/sound/soc/codecs/ssm4567.c
@@ -352,6 +352,11 @@ static int ssm4567_set_power(struct ssm4
 	regcache_cache_only(ssm4567->regmap, !enable);
 
 	if (enable) {
+		ret = regmap_write(ssm4567->regmap, SSM4567_REG_SOFT_RESET,
+			0x00);
+		if (ret)
+			return ret;
+
 		ret = regmap_update_bits(ssm4567->regmap,
 			SSM4567_REG_POWER_CTRL,
 			SSM4567_POWER_SPWDN, 0x00);

[toc] | [prev] | [next] | [standalone]


#1392825 — [PATCH 4.5 061/200] crypto: sha1-mb - use corrcet pointer while completing jobs

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-05-03 03:20 +0200
Subject[PATCH 4.5 061/200] crypto: sha1-mb - use corrcet pointer while completing jobs
Message-ID<ruxak-6BA-53@gated-at.bofh.it>
In reply to#1392807
4.5-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Xiaodong Liu <xiaodong.liu@intel.com>

commit 0851561d9c965df086ef8a53f981f5f95a57c2c8 upstream.

In sha_complete_job, incorrect mcryptd_hash_request_ctx pointer is used
when check and complete other jobs. If the memory of first completed req
is freed, while still completing other jobs in the func, kernel will
crash since NULL pointer is assigned to RIP.

Signed-off-by: Xiaodong Liu <xiaodong.liu@intel.com>
Acked-by: Tim Chen <tim.c.chen@linux.intel.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 arch/x86/crypto/sha-mb/sha1_mb.c |    4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

--- a/arch/x86/crypto/sha-mb/sha1_mb.c
+++ b/arch/x86/crypto/sha-mb/sha1_mb.c
@@ -453,10 +453,10 @@ static int sha_complete_job(struct mcryp
 
 			req = cast_mcryptd_ctx_to_req(req_ctx);
 			if (irqs_disabled())
-				rctx->complete(&req->base, ret);
+				req_ctx->complete(&req->base, ret);
 			else {
 				local_bh_disable();
-				rctx->complete(&req->base, ret);
+				req_ctx->complete(&req->base, ret);
 				local_bh_enable();
 			}
 		}

[toc] | [prev] | [next] | [standalone]


Page 1 of 3  [1] 2 3  Next page →

Back to top | Article view | linux.kernel


csiph-web