Home Home > GIT Browse
summaryrefslogtreecommitdiff
Side-by-side diff
Diffstat (more/less context) (ignore whitespace changes)
-rw-r--r--patches.kernel.org/patch-3.9.1-23029
-rw-r--r--patches.kernel.org/patch-3.9.2-33862
2 files changed, 0 insertions, 6891 deletions
diff --git a/patches.kernel.org/patch-3.9.1-2 b/patches.kernel.org/patch-3.9.1-2
deleted file mode 100644
index 1ff9901..0000000
--- a/patches.kernel.org/patch-3.9.1-2
+++ b/dev/null
@@ -1,3029 +0,0 @@
-From: Jiri Slaby <jslaby@suse.cz>
-Subject: Linux 3.9.2
-Patch-mainline: 3.9.2
-Git-commit: 12b2f117f3bf738c1a00a6f64393f1953a740bd4
-Git-commit: c5a2a15f8146fdfe45078df7873a6dc1006b3869
-Git-commit: 7fdb7846c9ca6fc06e380de0976a1228703b498a
-Git-commit: e253aaf0af51c1e4dc7dd3b26ea8e666bf9a2d8d
-Git-commit: c8c64d165ccfd2274058ac84e0c680f9b48c4ec1
-Git-commit: eb384b55ae9c2055ea00c5cc87971e182d47aefa
-Git-commit: 41b0fc42800569f63e029549b75c4c9cb63f2dfd
-Git-commit: 7fe70b579c9e3daba71635e31b6189394e7b79d3
-Git-commit: 9e48854c58ca9a0f39e716dcb18247bfc21e2022
-Git-commit: 441e76ca83ac604eaf0f046def96d8e3a27eea28
-Git-commit: 62d1f92e06aef9665d71ca7e986b3047ecf0b3c7
-Git-commit: f8e6bfc2ce162855fa4f9822a45659f4b542c960
-Git-commit: beb71fc61c2cad64e347f164991b8ef476529e64
-Git-commit: e884fc640ccbdb6f94b9bdb57cfb8464b6688f4c
-Git-commit: 466476dfdcafbb4286ffa232a3a792731b9dc852
-Git-commit: 79b52d6a7085a3e430c6de450a5847fdbe04159b
-Git-commit: dcb852905772416e322536ced5cb3c796d176af5
-Git-commit: 0cd9cb76ae26a19df21abc6f94f5fff141e689c7
-Git-commit: 2e97be73e5f74a317232740ae82eb8f95326a660
-Git-commit: 18932a28419596bc9403770f5d8a108c5433fe59
-Git-commit: abf1457bbbe4c62066bd03c6d31837dea28644dc
-Git-commit: 2b48b968c0d00aa5ab520b65a15a4f374cda7dda
-Git-commit: 2f86e2ede39a98650c2d465857405ef1c51372b1
-Git-commit: 968c01664ccbe0e46c19a1af662c4c266a904203
-Git-commit: 10257a6d8359c41407eb26b7ad7bf710a7e00155
-Git-commit: bea5497bfc1067620c8c8e9d37a42e0bb6d7d7fa
-Git-commit: 7c1c7c18fc752b2a1d07597286467ef186312463
-Git-commit: 367cbe2fec9b57b72605e2ac4cfd4f2fa823a256
-Git-commit: 411678288d61ba17afe1f8afed92200be6bbc65d
-Git-commit: bf05d9985111f85ed6922c134567b96eb789283b
-Git-commit: 43b27290dd42b40f3f23f49677a7faa5a4eb1eff
-Git-commit: e4bfff54ed3f5de88f5358504c78c2cb037813aa
-Git-commit: b6c5164d7bf624f3e1b750787ddb983150c5117c
-Git-commit: c40c0f5bd5b0f09e4386d2cf26c96c89c45ee539
-Git-commit: dc652f90e088798bfa31f496ba994ddadd5d5680
-Git-commit: f30da187cdcd0939288038e11fb3bfbd1b655564
-Git-commit: 3f704fa2778d3fe45e6529825a5c7a8bcbc686f4
-Git-commit: 4615d4c9e27eda42c3e965f208a4b4065841498c
-Git-commit: 25ff1195f8a0b3724541ae7bbe331b4296de9c06
-Git-commit: 7a7d1fb79fb581553f4830498045de774a9659f8
-Git-commit: 9e9dd0e889c76c786e8f2e164c825c3c06dea30c
-Git-commit: bd6946e87a98fea11907b2a47368e13044458a35
-Git-commit: 306373b645d80625335b8e684fa09b14ba460cec
-Git-commit: 219b47339ced80ca580bb6ce7d1636166984afa7
-Git-commit: 011c2282c74db120f01a8414edc66c3f217f5511
-Git-commit: e127dc28cc3057575da0216cde85687153ca180f
-Git-commit: 641719599528d806e00de8ae8c8453361266a312
-Git-commit: f3b2bbdc8a87a080ccd23d27fca4b87d61340dd4
-Git-commit: 871dd9286e25330c8a581e5dacfa8b1dfe1dd641
-Git-commit: e5072664f8237cf53b0bd68a51aa1a7bc69061c5
-Git-commit: 0e7f7bcc3fc87489cda5aa6aff8ce40eed912279
-Git-commit: 5b0c275926b8149c555da874bb4ec258ea3292aa
-Git-commit: e5195c1f31f399289347e043d6abf3ffa80f0005
-Git-commit: 07c449bbc6aa514098c4f12c7b04180cec2417c6
-Git-commit: 3f8a6411fbada1fa482276591e037f3b1adcf55b
-Git-commit: f7a1dd6e3ad59f0cfd51da29dfdbfd54122c5916
-Git-commit: 7cc23cd6c0c7d7f4bee057607e7ce01568925717
-Git-commit: 6e15eb3ba6c0249c9e8c783517d131b47db995ca
-Git-commit: 741a698f420c34c458294a6accecfbad702a7c52
-Git-commit: 1b0dac2ac6debdbf1541e15f2cede03613cf4465
-Git-commit: 9a6bc14350b130427725f33e371e86212fa56c85
-Git-commit: 13f85203e1060da83d9ec1c1c5a63343eaab8de4
-Git-commit: edb749f4390b3c1604233dc7c4fb0361f472e712
-Git-commit: 197887f03daecdb3ae21bafeb4155412abad3497
-Git-commit: af73e4d9506d3b797509f3c030e7dcd554f7d9c4
-Git-commit: b9777859ec015a78dae1476e317d04f851bfdd0d
-Git-commit: 397944df3290ddc46dcc6a08cd71fb560700431b
-Git-commit: ce8a5dbdf9e709bdaf4618d7ef8cceb91e8adc69
-Git-commit: 563861cd633ae52932843477bb6ca3f1c9e2f78b
-Git-commit: 7122beeee7bc1757682049780179d7c216dd1c83
-Git-commit: c2fd22df89365df9451d5b91da3b7bfd48122ecd
-Git-commit: 73d2fb758e678c93bc76d40876c2359f0729b0ef
-Git-commit: 2798ba7d19aed645663398a21ec4006bfdbb1ef3
-
-Signed-off-by: Jiri Slaby <jslaby@suse.cz>
----
-diff --git a/Makefile b/Makefile
-index 5fcb591..3e71511 100644
---- a/Makefile
-+++ b/Makefile
-@@ -1,6 +1,6 @@
- VERSION = 3
- PATCHLEVEL = 9
--SUBLEVEL = 1
-+SUBLEVEL = 2
- EXTRAVERSION =
- NAME = Unicycling Gorilla
-
-diff --git a/arch/arm/xen/enlighten.c b/arch/arm/xen/enlighten.c
-index 8dc0605..99ce189 100644
---- a/arch/arm/xen/enlighten.c
-+++ b/arch/arm/xen/enlighten.c
-@@ -239,7 +239,7 @@ static int __init xen_init_events(void)
- xen_init_IRQ();
-
- if (request_percpu_irq(xen_events_irq, xen_arm_callback,
-- "events", xen_vcpu)) {
-+ "events", &xen_vcpu)) {
- pr_err("Error requesting IRQ %d\n", xen_events_irq);
- return -EINVAL;
- }
-diff --git a/arch/arm64/mm/fault.c b/arch/arm64/mm/fault.c
-index afadae6..0782eaf 100644
---- a/arch/arm64/mm/fault.c
-+++ b/arch/arm64/mm/fault.c
-@@ -148,6 +148,7 @@ void do_bad_area(unsigned long addr, unsigned int esr, struct pt_regs *regs)
- #define VM_FAULT_BADACCESS 0x020000
-
- #define ESR_WRITE (1 << 6)
-+#define ESR_CM (1 << 8)
- #define ESR_LNX_EXEC (1 << 24)
-
- /*
-@@ -206,7 +207,7 @@ static int __kprobes do_page_fault(unsigned long addr, unsigned int esr,
- struct task_struct *tsk;
- struct mm_struct *mm;
- int fault, sig, code;
-- int write = esr & ESR_WRITE;
-+ bool write = (esr & ESR_WRITE) && !(esr & ESR_CM);
- unsigned int flags = FAULT_FLAG_ALLOW_RETRY | FAULT_FLAG_KILLABLE |
- (write ? FAULT_FLAG_WRITE : 0);
-
-diff --git a/arch/powerpc/include/asm/ppc-opcode.h b/arch/powerpc/include/asm/ppc-opcode.h
-index 8752bc8..8cbc6e5 100644
---- a/arch/powerpc/include/asm/ppc-opcode.h
-+++ b/arch/powerpc/include/asm/ppc-opcode.h
-@@ -113,6 +113,10 @@
- #define PPC_INST_MFSPR_DSCR_MASK 0xfc1fffff
- #define PPC_INST_MTSPR_DSCR 0x7c1103a6
- #define PPC_INST_MTSPR_DSCR_MASK 0xfc1fffff
-+#define PPC_INST_MFSPR_DSCR_USER 0x7c0302a6
-+#define PPC_INST_MFSPR_DSCR_USER_MASK 0xfc1fffff
-+#define PPC_INST_MTSPR_DSCR_USER 0x7c0303a6
-+#define PPC_INST_MTSPR_DSCR_USER_MASK 0xfc1fffff
- #define PPC_INST_SLBFEE 0x7c0007a7
-
- #define PPC_INST_STRING 0x7c00042a
-diff --git a/arch/powerpc/kernel/traps.c b/arch/powerpc/kernel/traps.c
-index 37cc40e..83efa2f 100644
---- a/arch/powerpc/kernel/traps.c
-+++ b/arch/powerpc/kernel/traps.c
-@@ -970,7 +970,10 @@ static int emulate_instruction(struct pt_regs *regs)
-
- #ifdef CONFIG_PPC64
- /* Emulate the mfspr rD, DSCR. */
-- if (((instword & PPC_INST_MFSPR_DSCR_MASK) == PPC_INST_MFSPR_DSCR) &&
-+ if ((((instword & PPC_INST_MFSPR_DSCR_USER_MASK) ==
-+ PPC_INST_MFSPR_DSCR_USER) ||
-+ ((instword & PPC_INST_MFSPR_DSCR_MASK) ==
-+ PPC_INST_MFSPR_DSCR)) &&
- cpu_has_feature(CPU_FTR_DSCR)) {
- PPC_WARN_EMULATED(mfdscr, regs);
- rd = (instword >> 21) & 0x1f;
-@@ -978,7 +981,10 @@ static int emulate_instruction(struct pt_regs *regs)
- return 0;
- }
- /* Emulate the mtspr DSCR, rD. */
-- if (((instword & PPC_INST_MTSPR_DSCR_MASK) == PPC_INST_MTSPR_DSCR) &&
-+ if ((((instword & PPC_INST_MTSPR_DSCR_USER_MASK) ==
-+ PPC_INST_MTSPR_DSCR_USER) ||
-+ ((instword & PPC_INST_MTSPR_DSCR_MASK) ==
-+ PPC_INST_MTSPR_DSCR)) &&
- cpu_has_feature(CPU_FTR_DSCR)) {
- PPC_WARN_EMULATED(mtdscr, regs);
- rd = (instword >> 21) & 0x1f;
-diff --git a/arch/powerpc/mm/hash_utils_64.c b/arch/powerpc/mm/hash_utils_64.c
-index f410c3e..b75c52f 100644
---- a/arch/powerpc/mm/hash_utils_64.c
-+++ b/arch/powerpc/mm/hash_utils_64.c
-@@ -1191,6 +1191,7 @@ void flush_hash_page(unsigned long vpn, real_pte_t pte, int psize, int ssize,
- * unmapping it first, it may see the speculated version.
- */
- if (local && cpu_has_feature(CPU_FTR_TM) &&
-+ current->thread.regs &&
- MSR_TM_ACTIVE(current->thread.regs->msr)) {
- tm_enable();
- tm_abort(TM_CAUSE_TLBI);
-diff --git a/arch/powerpc/mm/numa.c b/arch/powerpc/mm/numa.c
-index bba87ca..6a252c4 100644
---- a/arch/powerpc/mm/numa.c
-+++ b/arch/powerpc/mm/numa.c
-@@ -201,7 +201,7 @@ int __node_distance(int a, int b)
- int distance = LOCAL_DISTANCE;
-
- if (!form1_affinity)
-- return distance;
-+ return ((a == b) ? LOCAL_DISTANCE : REMOTE_DISTANCE);
-
- for (i = 0; i < distance_ref_points_depth; i++) {
- if (distance_lookup_table[a][i] == distance_lookup_table[b][i])
-diff --git a/arch/x86/kernel/cpu/perf_event_intel.c b/arch/x86/kernel/cpu/perf_event_intel.c
-index cc45deb..4a0a462 100644
---- a/arch/x86/kernel/cpu/perf_event_intel.c
-+++ b/arch/x86/kernel/cpu/perf_event_intel.c
-@@ -125,10 +125,15 @@ static struct event_constraint intel_ivb_event_constraints[] __read_mostly =
- INTEL_UEVENT_CONSTRAINT(0x08a3, 0x4), /* CYCLE_ACTIVITY.CYCLES_L1D_PENDING */
- INTEL_UEVENT_CONSTRAINT(0x0ca3, 0x4), /* CYCLE_ACTIVITY.STALLS_L1D_PENDING */
- INTEL_UEVENT_CONSTRAINT(0x01c0, 0x2), /* INST_RETIRED.PREC_DIST */
-- INTEL_EVENT_CONSTRAINT(0xd0, 0xf), /* MEM_UOPS_RETIRED.* */
-- INTEL_EVENT_CONSTRAINT(0xd1, 0xf), /* MEM_LOAD_UOPS_RETIRED.* */
-- INTEL_EVENT_CONSTRAINT(0xd2, 0xf), /* MEM_LOAD_UOPS_LLC_HIT_RETIRED.* */
-- INTEL_EVENT_CONSTRAINT(0xd3, 0xf), /* MEM_LOAD_UOPS_LLC_MISS_RETIRED.* */
-+ /*
-+ * Errata BV98 -- MEM_*_RETIRED events can leak between counters of SMT
-+ * siblings; disable these events because they can corrupt unrelated
-+ * counters.
-+ */
-+ INTEL_EVENT_CONSTRAINT(0xd0, 0x0), /* MEM_UOPS_RETIRED.* */
-+ INTEL_EVENT_CONSTRAINT(0xd1, 0x0), /* MEM_LOAD_UOPS_RETIRED.* */
-+ INTEL_EVENT_CONSTRAINT(0xd2, 0x0), /* MEM_LOAD_UOPS_LLC_HIT_RETIRED.* */
-+ INTEL_EVENT_CONSTRAINT(0xd3, 0x0), /* MEM_LOAD_UOPS_LLC_MISS_RETIRED.* */
- EVENT_CONSTRAINT_END
- };
-
-diff --git a/arch/x86/kernel/cpu/perf_event_intel_lbr.c b/arch/x86/kernel/cpu/perf_event_intel_lbr.c
-index da02e9c..d978353 100644
---- a/arch/x86/kernel/cpu/perf_event_intel_lbr.c
-+++ b/arch/x86/kernel/cpu/perf_event_intel_lbr.c
-@@ -310,7 +310,7 @@ void intel_pmu_lbr_read(void)
- * - in case there is no HW filter
- * - in case the HW filter has errata or limitations
- */
--static void intel_pmu_setup_sw_lbr_filter(struct perf_event *event)
-+static int intel_pmu_setup_sw_lbr_filter(struct perf_event *event)
- {
- u64 br_type = event->attr.branch_sample_type;
- int mask = 0;
-@@ -318,8 +318,11 @@ static void intel_pmu_setup_sw_lbr_filter(struct perf_event *event)
- if (br_type & PERF_SAMPLE_BRANCH_USER)
- mask |= X86_BR_USER;
-
-- if (br_type & PERF_SAMPLE_BRANCH_KERNEL)
-+ if (br_type & PERF_SAMPLE_BRANCH_KERNEL) {
-+ if (perf_paranoid_kernel() && !capable(CAP_SYS_ADMIN))
-+ return -EACCES;
- mask |= X86_BR_KERNEL;
-+ }
-
- /* we ignore BRANCH_HV here */
-
-@@ -339,6 +342,8 @@ static void intel_pmu_setup_sw_lbr_filter(struct perf_event *event)
- * be used by fixup code for some CPU
- */
- event->hw.branch_reg.reg = mask;
-+
-+ return 0;
- }
-
- /*
-@@ -386,7 +391,9 @@ int intel_pmu_setup_lbr_filter(struct perf_event *event)
- /*
- * setup SW LBR filter
- */
-- intel_pmu_setup_sw_lbr_filter(event);
-+ ret = intel_pmu_setup_sw_lbr_filter(event);
-+ if (ret)
-+ return ret;
-
- /*
- * setup HW LBR filter, if any
-@@ -442,8 +449,18 @@ static int branch_type(unsigned long from, unsigned long to)
- return X86_BR_NONE;
-
- addr = buf;
-- } else
-- addr = (void *)from;
-+ } else {
-+ /*
-+ * The LBR logs any address in the IP, even if the IP just
-+ * faulted. This means userspace can control the from address.
-+ * Ensure we don't blindy read any address by validating it is
-+ * a known text address.
-+ */
-+ if (kernel_text_address(from))
-+ addr = (void *)from;
-+ else
-+ return X86_BR_NONE;
-+ }
-
- /*
- * decoder needs to know the ABI especially
-diff --git a/arch/x86/kernel/cpu/perf_event_intel_uncore.c b/arch/x86/kernel/cpu/perf_event_intel_uncore.c
-index b43200d..3e091f0 100644
---- a/arch/x86/kernel/cpu/perf_event_intel_uncore.c
-+++ b/arch/x86/kernel/cpu/perf_event_intel_uncore.c
-@@ -2428,7 +2428,7 @@ static void __init uncore_types_exit(struct intel_uncore_type **types)
- static int __init uncore_type_init(struct intel_uncore_type *type)
- {
- struct intel_uncore_pmu *pmus;
-- struct attribute_group *events_group;
-+ struct attribute_group *attr_group;
- struct attribute **attrs;
- int i, j;
-
-@@ -2455,19 +2455,19 @@ static int __init uncore_type_init(struct intel_uncore_type *type)
- while (type->event_descs[i].attr.attr.name)
- i++;
-
-- events_group = kzalloc(sizeof(struct attribute *) * (i + 1) +
-- sizeof(*events_group), GFP_KERNEL);
-- if (!events_group)
-+ attr_group = kzalloc(sizeof(struct attribute *) * (i + 1) +
-+ sizeof(*attr_group), GFP_KERNEL);
-+ if (!attr_group)
- goto fail;
-
-- attrs = (struct attribute **)(events_group + 1);
-- events_group->name = "events";
-- events_group->attrs = attrs;
-+ attrs = (struct attribute **)(attr_group + 1);
-+ attr_group->name = "events";
-+ attr_group->attrs = attrs;
-
- for (j = 0; j < i; j++)
- attrs[j] = &type->event_descs[j].attr.attr;
-
-- type->events_group = events_group;
-+ type->events_group = attr_group;
- }
-
- type->pmu_group = &uncore_pmu_attr_group;
-@@ -2853,6 +2853,7 @@ static int __init uncore_cpu_init(void)
- msr_uncores = nhm_msr_uncores;
- break;
- case 42: /* Sandy Bridge */
-+ case 58: /* Ivy Bridge */
- if (snb_uncore_cbox.num_boxes > max_cores)
- snb_uncore_cbox.num_boxes = max_cores;
- msr_uncores = snb_msr_uncores;
-diff --git a/block/blk-cgroup.c b/block/blk-cgroup.c
-index b2b9837..e8918ff 100644
---- a/block/blk-cgroup.c
-+++ b/block/blk-cgroup.c
-@@ -972,10 +972,10 @@ int blkcg_activate_policy(struct request_queue *q,
- if (!new_blkg)
- return -ENOMEM;
-
-- preloaded = !radix_tree_preload(GFP_KERNEL);
--
- blk_queue_bypass_start(q);
-
-+ preloaded = !radix_tree_preload(GFP_KERNEL);
-+
- /*
- * Make sure the root blkg exists and count the existing blkgs. As
- * @q is bypassing at this point, blkg_lookup_create() can't be
-diff --git a/drivers/edac/edac_mc_sysfs.c b/drivers/edac/edac_mc_sysfs.c
-index 5899a76..769d92e 100644
---- a/drivers/edac/edac_mc_sysfs.c
-+++ b/drivers/edac/edac_mc_sysfs.c
-@@ -327,17 +327,17 @@ static struct device_attribute *dynamic_csrow_dimm_attr[] = {
- };
-
- /* possible dynamic channel ce_count attribute files */
--DEVICE_CHANNEL(ch0_ce_count, S_IRUGO | S_IWUSR,
-+DEVICE_CHANNEL(ch0_ce_count, S_IRUGO,
- channel_ce_count_show, NULL, 0);
--DEVICE_CHANNEL(ch1_ce_count, S_IRUGO | S_IWUSR,
-+DEVICE_CHANNEL(ch1_ce_count, S_IRUGO,
- channel_ce_count_show, NULL, 1);
--DEVICE_CHANNEL(ch2_ce_count, S_IRUGO | S_IWUSR,
-+DEVICE_CHANNEL(ch2_ce_count, S_IRUGO,
- channel_ce_count_show, NULL, 2);
--DEVICE_CHANNEL(ch3_ce_count, S_IRUGO | S_IWUSR,
-+DEVICE_CHANNEL(ch3_ce_count, S_IRUGO,
- channel_ce_count_show, NULL, 3);
--DEVICE_CHANNEL(ch4_ce_count, S_IRUGO | S_IWUSR,
-+DEVICE_CHANNEL(ch4_ce_count, S_IRUGO,
- channel_ce_count_show, NULL, 4);
--DEVICE_CHANNEL(ch5_ce_count, S_IRUGO | S_IWUSR,
-+DEVICE_CHANNEL(ch5_ce_count, S_IRUGO,
- channel_ce_count_show, NULL, 5);
-
- /* Total possible dynamic ce_count attribute file table */
-diff --git a/drivers/gpu/drm/ast/ast_drv.h b/drivers/gpu/drm/ast/ast_drv.h
-index 5284292..02e52d5 100644
---- a/drivers/gpu/drm/ast/ast_drv.h
-+++ b/drivers/gpu/drm/ast/ast_drv.h
-@@ -241,6 +241,8 @@ struct ast_fbdev {
- void *sysram;
- int size;
- struct ttm_bo_kmap_obj mapping;
-+ int x1, y1, x2, y2; /* dirty rect */
-+ spinlock_t dirty_lock;
- };
-
- #define to_ast_crtc(x) container_of(x, struct ast_crtc, base)
-diff --git a/drivers/gpu/drm/ast/ast_fb.c b/drivers/gpu/drm/ast/ast_fb.c
-index 34931fe..fbc0823 100644
---- a/drivers/gpu/drm/ast/ast_fb.c
-+++ b/drivers/gpu/drm/ast/ast_fb.c
-@@ -53,16 +53,52 @@ static void ast_dirty_update(struct ast_fbdev *afbdev,
- int bpp = (afbdev->afb.base.bits_per_pixel + 7)/8;
- int ret;
- bool unmap = false;
-+ bool store_for_later = false;
-+ int x2, y2;
-+ unsigned long flags;
-
- obj = afbdev->afb.obj;
- bo = gem_to_ast_bo(obj);
-
-+ /*
-+ * try and reserve the BO, if we fail with busy
-+ * then the BO is being moved and we should
-+ * store up the damage until later.
-+ */
- ret = ast_bo_reserve(bo, true);
- if (ret) {
-- DRM_ERROR("failed to reserve fb bo\n");
-+ if (ret != -EBUSY)
-+ return;
-+
-+ store_for_later = true;
-+ }
-+
-+ x2 = x + width - 1;
-+ y2 = y + height - 1;
-+ spin_lock_irqsave(&afbdev->dirty_lock, flags);
-+
-+ if (afbdev->y1 < y)
-+ y = afbdev->y1;
-+ if (afbdev->y2 > y2)
-+ y2 = afbdev->y2;
-+ if (afbdev->x1 < x)
-+ x = afbdev->x1;
-+ if (afbdev->x2 > x2)
-+ x2 = afbdev->x2;
-+
-+ if (store_for_later) {
-+ afbdev->x1 = x;
-+ afbdev->x2 = x2;
-+ afbdev->y1 = y;
-+ afbdev->y2 = y2;
-+ spin_unlock_irqrestore(&afbdev->dirty_lock, flags);
- return;
- }
-
-+ afbdev->x1 = afbdev->y1 = INT_MAX;
-+ afbdev->x2 = afbdev->y2 = 0;
-+ spin_unlock_irqrestore(&afbdev->dirty_lock, flags);
-+
- if (!bo->kmap.virtual) {
- ret = ttm_bo_kmap(&bo->bo, 0, bo->bo.num_pages, &bo->kmap);
- if (ret) {
-@@ -72,10 +108,10 @@ static void ast_dirty_update(struct ast_fbdev *afbdev,
- }
- unmap = true;
- }
-- for (i = y; i < y + height; i++) {
-+ for (i = y; i <= y2; i++) {
- /* assume equal stride for now */
- src_offset = dst_offset = i * afbdev->afb.base.pitches[0] + (x * bpp);
-- memcpy_toio(bo->kmap.virtual + src_offset, afbdev->sysram + src_offset, width * bpp);
-+ memcpy_toio(bo->kmap.virtual + src_offset, afbdev->sysram + src_offset, (x2 - x + 1) * bpp);
-
- }
- if (unmap)
-@@ -292,6 +328,7 @@ int ast_fbdev_init(struct drm_device *dev)
-
- ast->fbdev = afbdev;
- afbdev->helper.funcs = &ast_fb_helper_funcs;
-+ spin_lock_init(&afbdev->dirty_lock);
- ret = drm_fb_helper_init(dev, &afbdev->helper,
- 1, 1);
- if (ret) {
-diff --git a/drivers/gpu/drm/ast/ast_ttm.c b/drivers/gpu/drm/ast/ast_ttm.c
-index 3602731..09da339 100644
---- a/drivers/gpu/drm/ast/ast_ttm.c
-+++ b/drivers/gpu/drm/ast/ast_ttm.c
-@@ -316,7 +316,7 @@ int ast_bo_reserve(struct ast_bo *bo, bool no_wait)
-
- ret = ttm_bo_reserve(&bo->bo, true, no_wait, false, 0);
- if (ret) {
-- if (ret != -ERESTARTSYS)
-+ if (ret != -ERESTARTSYS && ret != -EBUSY)
- DRM_ERROR("reserve failed %p\n", bo);
- return ret;
- }
-diff --git a/drivers/gpu/drm/cirrus/cirrus_drv.h b/drivers/gpu/drm/cirrus/cirrus_drv.h
-index 6e0cc72..7ca0595 100644
---- a/drivers/gpu/drm/cirrus/cirrus_drv.h
-+++ b/drivers/gpu/drm/cirrus/cirrus_drv.h
-@@ -154,6 +154,8 @@ struct cirrus_fbdev {
- struct list_head fbdev_list;
- void *sysram;
- int size;
-+ int x1, y1, x2, y2; /* dirty rect */
-+ spinlock_t dirty_lock;
- };
-
- struct cirrus_bo {
-diff --git a/drivers/gpu/drm/cirrus/cirrus_fbdev.c b/drivers/gpu/drm/cirrus/cirrus_fbdev.c
-index e25afcc..3541b56 100644
---- a/drivers/gpu/drm/cirrus/cirrus_fbdev.c
-+++ b/drivers/gpu/drm/cirrus/cirrus_fbdev.c
-@@ -27,16 +27,51 @@ static void cirrus_dirty_update(struct cirrus_fbdev *afbdev,
- int bpp = (afbdev->gfb.base.bits_per_pixel + 7)/8;
- int ret;
- bool unmap = false;
-+ bool store_for_later = false;
-+ int x2, y2;
-+ unsigned long flags;
-
- obj = afbdev->gfb.obj;
- bo = gem_to_cirrus_bo(obj);
-
-+ /*
-+ * try and reserve the BO, if we fail with busy
-+ * then the BO is being moved and we should
-+ * store up the damage until later.
-+ */
- ret = cirrus_bo_reserve(bo, true);
- if (ret) {
-- DRM_ERROR("failed to reserve fb bo\n");
-+ if (ret != -EBUSY)
-+ return;
-+ store_for_later = true;
-+ }
-+
-+ x2 = x + width - 1;
-+ y2 = y + height - 1;
-+ spin_lock_irqsave(&afbdev->dirty_lock, flags);
-+
-+ if (afbdev->y1 < y)
-+ y = afbdev->y1;
-+ if (afbdev->y2 > y2)
-+ y2 = afbdev->y2;
-+ if (afbdev->x1 < x)
-+ x = afbdev->x1;
-+ if (afbdev->x2 > x2)
-+ x2 = afbdev->x2;
-+
-+ if (store_for_later) {
-+ afbdev->x1 = x;
-+ afbdev->x2 = x2;
-+ afbdev->y1 = y;
-+ afbdev->y2 = y2;
-+ spin_unlock_irqrestore(&afbdev->dirty_lock, flags);
- return;
- }
-
-+ afbdev->x1 = afbdev->y1 = INT_MAX;
-+ afbdev->x2 = afbdev->y2 = 0;
-+ spin_unlock_irqrestore(&afbdev->dirty_lock, flags);
-+
- if (!bo->kmap.virtual) {
- ret = ttm_bo_kmap(&bo->bo, 0, bo->bo.num_pages, &bo->kmap);
- if (ret) {
-@@ -268,6 +303,7 @@ int cirrus_fbdev_init(struct cirrus_device *cdev)
-
- cdev->mode_info.gfbdev = gfbdev;
- gfbdev->helper.funcs = &cirrus_fb_helper_funcs;
-+ spin_lock_init(&gfbdev->dirty_lock);
-
- ret = drm_fb_helper_init(cdev->dev, &gfbdev->helper,
- cdev->num_crtc, CIRRUSFB_CONN_LIMIT);
-diff --git a/drivers/gpu/drm/cirrus/cirrus_ttm.c b/drivers/gpu/drm/cirrus/cirrus_ttm.c
-index 1413a26..2ed8cfc 100644
---- a/drivers/gpu/drm/cirrus/cirrus_ttm.c
-+++ b/drivers/gpu/drm/cirrus/cirrus_ttm.c
-@@ -321,7 +321,7 @@ int cirrus_bo_reserve(struct cirrus_bo *bo, bool no_wait)
-
- ret = ttm_bo_reserve(&bo->bo, true, no_wait, false, 0);
- if (ret) {
-- if (ret != -ERESTARTSYS)
-+ if (ret != -ERESTARTSYS && ret != -EBUSY)
- DRM_ERROR("reserve failed %p\n", bo);
- return ret;
- }
-diff --git a/drivers/gpu/drm/drm_gem.c b/drivers/gpu/drm/drm_gem.c
-index af779ae..cf919e3 100644
---- a/drivers/gpu/drm/drm_gem.c
-+++ b/drivers/gpu/drm/drm_gem.c
-@@ -205,11 +205,11 @@ static void
- drm_gem_remove_prime_handles(struct drm_gem_object *obj, struct drm_file *filp)
- {
- if (obj->import_attach) {
-- drm_prime_remove_imported_buf_handle(&filp->prime,
-+ drm_prime_remove_buf_handle(&filp->prime,
- obj->import_attach->dmabuf);
- }
- if (obj->export_dma_buf) {
-- drm_prime_remove_imported_buf_handle(&filp->prime,
-+ drm_prime_remove_buf_handle(&filp->prime,
- obj->export_dma_buf);
- }
- }
-diff --git a/drivers/gpu/drm/drm_prime.c b/drivers/gpu/drm/drm_prime.c
-index 366910d..db767ca 100644
---- a/drivers/gpu/drm/drm_prime.c
-+++ b/drivers/gpu/drm/drm_prime.c
-@@ -62,6 +62,7 @@ struct drm_prime_member {
- struct dma_buf *dma_buf;
- uint32_t handle;
- };
-+static int drm_prime_add_buf_handle(struct drm_prime_file_private *prime_fpriv, struct dma_buf *dma_buf, uint32_t handle);
-
- static struct sg_table *drm_gem_map_dma_buf(struct dma_buf_attachment *attach,
- enum dma_data_direction dir)
-@@ -200,7 +201,8 @@ int drm_gem_prime_handle_to_fd(struct drm_device *dev,
- {
- struct drm_gem_object *obj;
- void *buf;
-- int ret;
-+ int ret = 0;
-+ struct dma_buf *dmabuf;
-
- obj = drm_gem_object_lookup(dev, file_priv, handle);
- if (!obj)
-@@ -209,43 +211,44 @@ int drm_gem_prime_handle_to_fd(struct drm_device *dev,
- mutex_lock(&file_priv->prime.lock);
- /* re-export the original imported object */
- if (obj->import_attach) {
-- get_dma_buf(obj->import_attach->dmabuf);
-- *prime_fd = dma_buf_fd(obj->import_attach->dmabuf, flags);
-- drm_gem_object_unreference_unlocked(obj);
-- mutex_unlock(&file_priv->prime.lock);
-- return 0;
-+ dmabuf = obj->import_attach->dmabuf;
-+ goto out_have_obj;
- }
-
- if (obj->export_dma_buf) {
-- get_dma_buf(obj->export_dma_buf);
-- *prime_fd = dma_buf_fd(obj->export_dma_buf, flags);
-- drm_gem_object_unreference_unlocked(obj);
-- } else {
-- buf = dev->driver->gem_prime_export(dev, obj, flags);
-- if (IS_ERR(buf)) {
-- /* normally the created dma-buf takes ownership of the ref,
-- * but if that fails then drop the ref
-- */
-- drm_gem_object_unreference_unlocked(obj);
-- mutex_unlock(&file_priv->prime.lock);
-- return PTR_ERR(buf);
-- }
-- obj->export_dma_buf = buf;
-- *prime_fd = dma_buf_fd(buf, flags);
-+ dmabuf = obj->export_dma_buf;
-+ goto out_have_obj;
- }
-+
-+ buf = dev->driver->gem_prime_export(dev, obj, flags);
-+ if (IS_ERR(buf)) {
-+ /* normally the created dma-buf takes ownership of the ref,
-+ * but if that fails then drop the ref
-+ */
-+ ret = PTR_ERR(buf);
-+ goto out;
-+ }
-+ obj->export_dma_buf = buf;
-+
- /* if we've exported this buffer the cheat and add it to the import list
- * so we get the correct handle back
- */
-- ret = drm_prime_add_imported_buf_handle(&file_priv->prime,
-- obj->export_dma_buf, handle);
-- if (ret) {
-- drm_gem_object_unreference_unlocked(obj);
-- mutex_unlock(&file_priv->prime.lock);
-- return ret;
-- }
-+ ret = drm_prime_add_buf_handle(&file_priv->prime,
-+ obj->export_dma_buf, handle);
-+ if (ret)
-+ goto out;
-
-+ *prime_fd = dma_buf_fd(buf, flags);
- mutex_unlock(&file_priv->prime.lock);
- return 0;
-+
-+out_have_obj:
-+ get_dma_buf(dmabuf);
-+ *prime_fd = dma_buf_fd(dmabuf, flags);
-+out:
-+ drm_gem_object_unreference_unlocked(obj);
-+ mutex_unlock(&file_priv->prime.lock);
-+ return ret;
- }
- EXPORT_SYMBOL(drm_gem_prime_handle_to_fd);
-
-@@ -268,7 +271,6 @@ struct drm_gem_object *drm_gem_prime_import(struct drm_device *dev,
- * refcount on gem itself instead of f_count of dmabuf.
- */
- drm_gem_object_reference(obj);
-- dma_buf_put(dma_buf);
- return obj;
- }
- }
-@@ -277,6 +279,8 @@ struct drm_gem_object *drm_gem_prime_import(struct drm_device *dev,
- if (IS_ERR(attach))
- return ERR_PTR(PTR_ERR(attach));
-
-+ get_dma_buf(dma_buf);
-+
- sgt = dma_buf_map_attachment(attach, DMA_BIDIRECTIONAL);
- if (IS_ERR_OR_NULL(sgt)) {
- ret = PTR_ERR(sgt);
-@@ -297,6 +301,8 @@ fail_unmap:
- dma_buf_unmap_attachment(attach, sgt, DMA_BIDIRECTIONAL);
- fail_detach:
- dma_buf_detach(dma_buf, attach);
-+ dma_buf_put(dma_buf);
-+
- return ERR_PTR(ret);
- }
- EXPORT_SYMBOL(drm_gem_prime_import);
-@@ -314,7 +320,7 @@ int drm_gem_prime_fd_to_handle(struct drm_device *dev,
-
- mutex_lock(&file_priv->prime.lock);
-
-- ret = drm_prime_lookup_imported_buf_handle(&file_priv->prime,
-+ ret = drm_prime_lookup_buf_handle(&file_priv->prime,
- dma_buf, handle);
- if (!ret) {
- ret = 0;
-@@ -333,12 +339,15 @@ int drm_gem_prime_fd_to_handle(struct drm_device *dev,
- if (ret)
- goto out_put;
-
-- ret = drm_prime_add_imported_buf_handle(&file_priv->prime,
-+ ret = drm_prime_add_buf_handle(&file_priv->prime,
- dma_buf, *handle);
- if (ret)
- goto fail;
-
- mutex_unlock(&file_priv->prime.lock);
-+
-+ dma_buf_put(dma_buf);
-+
- return 0;
-
- fail:
-@@ -491,7 +500,7 @@ void drm_prime_destroy_file_private(struct drm_prime_file_private *prime_fpriv)
- }
- EXPORT_SYMBOL(drm_prime_destroy_file_private);
-
--int drm_prime_add_imported_buf_handle(struct drm_prime_file_private *prime_fpriv, struct dma_buf *dma_buf, uint32_t handle)
-+static int drm_prime_add_buf_handle(struct drm_prime_file_private *prime_fpriv, struct dma_buf *dma_buf, uint32_t handle)
- {
- struct drm_prime_member *member;
-
-@@ -499,14 +508,14 @@ int drm_prime_add_imported_buf_handle(struct drm_prime_file_private *prime_fpriv
- if (!member)
- return -ENOMEM;
-
-+ get_dma_buf(dma_buf);
- member->dma_buf = dma_buf;
- member->handle = handle;
- list_add(&member->entry, &prime_fpriv->head);
- return 0;
- }
--EXPORT_SYMBOL(drm_prime_add_imported_buf_handle);
-
--int drm_prime_lookup_imported_buf_handle(struct drm_prime_file_private *prime_fpriv, struct dma_buf *dma_buf, uint32_t *handle)
-+int drm_prime_lookup_buf_handle(struct drm_prime_file_private *prime_fpriv, struct dma_buf *dma_buf, uint32_t *handle)
- {
- struct drm_prime_member *member;
-
-@@ -518,19 +527,20 @@ int drm_prime_lookup_imported_buf_handle(struct drm_prime_file_private *prime_fp
- }
- return -ENOENT;
- }
--EXPORT_SYMBOL(drm_prime_lookup_imported_buf_handle);
-+EXPORT_SYMBOL(drm_prime_lookup_buf_handle);
-
--void drm_prime_remove_imported_buf_handle(struct drm_prime_file_private *prime_fpriv, struct dma_buf *dma_buf)
-+void drm_prime_remove_buf_handle(struct drm_prime_file_private *prime_fpriv, struct dma_buf *dma_buf)
- {
- struct drm_prime_member *member, *safe;
-
- mutex_lock(&prime_fpriv->lock);
- list_for_each_entry_safe(member, safe, &prime_fpriv->head, entry) {
- if (member->dma_buf == dma_buf) {
-+ dma_buf_put(dma_buf);
- list_del(&member->entry);
- kfree(member);
- }
- }
- mutex_unlock(&prime_fpriv->lock);
- }
--EXPORT_SYMBOL(drm_prime_remove_imported_buf_handle);
-+EXPORT_SYMBOL(drm_prime_remove_buf_handle);
-diff --git a/drivers/gpu/drm/exynos/exynos_drm_dmabuf.c b/drivers/gpu/drm/exynos/exynos_drm_dmabuf.c
-index ba0a3aa..ff7f2a8 100644
---- a/drivers/gpu/drm/exynos/exynos_drm_dmabuf.c
-+++ b/drivers/gpu/drm/exynos/exynos_drm_dmabuf.c
-@@ -235,7 +235,6 @@ struct drm_gem_object *exynos_dmabuf_prime_import(struct drm_device *drm_dev,
- * refcount on gem itself instead of f_count of dmabuf.
- */
- drm_gem_object_reference(obj);
-- dma_buf_put(dma_buf);
- return obj;
- }
- }
-@@ -244,6 +243,7 @@ struct drm_gem_object *exynos_dmabuf_prime_import(struct drm_device *drm_dev,
- if (IS_ERR(attach))
- return ERR_PTR(-EINVAL);
-
-+ get_dma_buf(dma_buf);
-
- sgt = dma_buf_map_attachment(attach, DMA_BIDIRECTIONAL);
- if (IS_ERR_OR_NULL(sgt)) {
-@@ -298,6 +298,8 @@ err_unmap_attach:
- dma_buf_unmap_attachment(attach, sgt, DMA_BIDIRECTIONAL);
- err_buf_detach:
- dma_buf_detach(dma_buf, attach);
-+ dma_buf_put(dma_buf);
-+
- return ERR_PTR(ret);
- }
-
-diff --git a/drivers/gpu/drm/gma500/psb_irq.c b/drivers/gpu/drm/gma500/psb_irq.c
-index 8652cdf..029eccf 100644
---- a/drivers/gpu/drm/gma500/psb_irq.c
-+++ b/drivers/gpu/drm/gma500/psb_irq.c
-@@ -211,7 +211,7 @@ irqreturn_t psb_irq_handler(DRM_IRQ_ARGS)
-
- vdc_stat = PSB_RVDC32(PSB_INT_IDENTITY_R);
-
-- if (vdc_stat & _PSB_PIPE_EVENT_FLAG)
-+ if (vdc_stat & (_PSB_PIPE_EVENT_FLAG|_PSB_IRQ_ASLE))
- dsp_int = 1;
-
- /* FIXME: Handle Medfield
-diff --git a/drivers/gpu/drm/i915/i915_drv.h b/drivers/gpu/drm/i915/i915_drv.h
-index 01769e2..ef99b1c 100644
---- a/drivers/gpu/drm/i915/i915_drv.h
-+++ b/drivers/gpu/drm/i915/i915_drv.h
-@@ -941,6 +941,7 @@ typedef struct drm_i915_private {
- unsigned int int_crt_support:1;
- unsigned int lvds_use_ssc:1;
- unsigned int display_clock_mode:1;
-+ unsigned int fdi_rx_polarity_inverted:1;
- int lvds_ssc_freq;
- unsigned int bios_lvds_val; /* initial [PCH_]LVDS reg val in VBIOS */
- struct {
-diff --git a/drivers/gpu/drm/i915/i915_gem.c b/drivers/gpu/drm/i915/i915_gem.c
-index 0e207e6..73cb479 100644
---- a/drivers/gpu/drm/i915/i915_gem.c
-+++ b/drivers/gpu/drm/i915/i915_gem.c
-@@ -2678,17 +2678,35 @@ static inline int fence_number(struct drm_i915_private *dev_priv,
- return fence - dev_priv->fence_regs;
- }
-
-+static void i915_gem_write_fence__ipi(void *data)
-+{
-+ wbinvd();
-+}
-+
- static void i915_gem_object_update_fence(struct drm_i915_gem_object *obj,
- struct drm_i915_fence_reg *fence,
- bool enable)
- {
-- struct drm_i915_private *dev_priv = obj->base.dev->dev_private;
-- int reg = fence_number(dev_priv, fence);
--
-- i915_gem_write_fence(obj->base.dev, reg, enable ? obj : NULL);
-+ struct drm_device *dev = obj->base.dev;
-+ struct drm_i915_private *dev_priv = dev->dev_private;
-+ int fence_reg = fence_number(dev_priv, fence);
-+
-+ /* In order to fully serialize access to the fenced region and
-+ * the update to the fence register we need to take extreme
-+ * measures on SNB+. In theory, the write to the fence register
-+ * flushes all memory transactions before, and coupled with the
-+ * mb() placed around the register write we serialise all memory
-+ * operations with respect to the changes in the tiler. Yet, on
-+ * SNB+ we need to take a step further and emit an explicit wbinvd()
-+ * on each processor in order to manually flush all memory
-+ * transactions before updating the fence register.
-+ */
-+ if (HAS_LLC(obj->base.dev))
-+ on_each_cpu(i915_gem_write_fence__ipi, NULL, 1);
-+ i915_gem_write_fence(dev, fence_reg, enable ? obj : NULL);
-
- if (enable) {
-- obj->fence_reg = reg;
-+ obj->fence_reg = fence_reg;
- fence->obj = obj;
- list_move_tail(&fence->lru_list, &dev_priv->mm.fence_list);
- } else {
-diff --git a/drivers/gpu/drm/i915/i915_gem_context.c b/drivers/gpu/drm/i915/i915_gem_context.c
-index 94d873a..a1e8ecb 100644
---- a/drivers/gpu/drm/i915/i915_gem_context.c
-+++ b/drivers/gpu/drm/i915/i915_gem_context.c
-@@ -152,6 +152,13 @@ create_hw_context(struct drm_device *dev,
- return ERR_PTR(-ENOMEM);
- }
-
-+ if (INTEL_INFO(dev)->gen >= 7) {
-+ ret = i915_gem_object_set_cache_level(ctx->obj,
-+ I915_CACHE_LLC_MLC);
-+ if (ret)
-+ goto err_out;
-+ }
-+
- /* The ring associated with the context object is handled by the normal
- * object tracking code. We give an initial ring value simple to pass an
- * assertion in the context switch code.
-diff --git a/drivers/gpu/drm/i915/i915_gem_dmabuf.c b/drivers/gpu/drm/i915/i915_gem_dmabuf.c
-index 6a5af68..c303de1 100644
---- a/drivers/gpu/drm/i915/i915_gem_dmabuf.c
-+++ b/drivers/gpu/drm/i915/i915_gem_dmabuf.c
-@@ -271,7 +271,6 @@ struct drm_gem_object *i915_gem_prime_import(struct drm_device *dev,
- * refcount on gem itself instead of f_count of dmabuf.
- */
- drm_gem_object_reference(&obj->base);
-- dma_buf_put(dma_buf);
- return &obj->base;
- }
- }
-@@ -281,6 +280,8 @@ struct drm_gem_object *i915_gem_prime_import(struct drm_device *dev,
- if (IS_ERR(attach))
- return ERR_CAST(attach);
-
-+ get_dma_buf(dma_buf);
-+
- obj = i915_gem_object_alloc(dev);
- if (obj == NULL) {
- ret = -ENOMEM;
-@@ -300,5 +301,7 @@ struct drm_gem_object *i915_gem_prime_import(struct drm_device *dev,
-
- fail_detach:
- dma_buf_detach(dma_buf, attach);
-+ dma_buf_put(dma_buf);
-+
- return ERR_PTR(ret);
- }
-diff --git a/drivers/gpu/drm/i915/i915_gem_gtt.c b/drivers/gpu/drm/i915/i915_gem_gtt.c
-index 926a1e2..193c8d1 100644
---- a/drivers/gpu/drm/i915/i915_gem_gtt.c
-+++ b/drivers/gpu/drm/i915/i915_gem_gtt.c
-@@ -182,8 +182,7 @@ static int gen6_ppgtt_init(struct i915_hw_ppgtt *ppgtt)
- /* ppgtt PDEs reside in the global gtt pagetable, which has 512*1024
- * entries. For aliasing ppgtt support we just steal them at the end for
- * now. */
-- first_pd_entry_in_global_pt =
-- gtt_total_entries(dev_priv->gtt) - I915_PPGTT_PD_ENTRIES;
-+ first_pd_entry_in_global_pt = gtt_total_entries(dev_priv->gtt);
-
- ppgtt->num_pd_entries = I915_PPGTT_PD_ENTRIES;
- ppgtt->clear_range = gen6_ppgtt_clear_range;
-diff --git a/drivers/gpu/drm/i915/i915_reg.h b/drivers/gpu/drm/i915/i915_reg.h
-index 848992f..c91124f 100644
---- a/drivers/gpu/drm/i915/i915_reg.h
-+++ b/drivers/gpu/drm/i915/i915_reg.h
-@@ -3827,7 +3827,7 @@
- #define _TRANSB_CHICKEN2 0xf1064
- #define TRANS_CHICKEN2(pipe) _PIPE(pipe, _TRANSA_CHICKEN2, _TRANSB_CHICKEN2)
- #define TRANS_CHICKEN2_TIMING_OVERRIDE (1<<31)
--
-+#define TRANS_CHICKEN2_FDI_POLARITY_REVERSED (1<<29)
-
- #define SOUTH_CHICKEN1 0xc2000
- #define FDIA_PHASE_SYNC_SHIFT_OVR 19
-diff --git a/drivers/gpu/drm/i915/intel_bios.c b/drivers/gpu/drm/i915/intel_bios.c
-index 55ffba1..bd83391 100644
---- a/drivers/gpu/drm/i915/intel_bios.c
-+++ b/drivers/gpu/drm/i915/intel_bios.c
-@@ -351,12 +351,14 @@ parse_general_features(struct drm_i915_private *dev_priv,
- dev_priv->lvds_ssc_freq =
- intel_bios_ssc_frequency(dev, general->ssc_freq);
- dev_priv->display_clock_mode = general->display_clock_mode;
-- DRM_DEBUG_KMS("BDB_GENERAL_FEATURES int_tv_support %d int_crt_support %d lvds_use_ssc %d lvds_ssc_freq %d display_clock_mode %d\n",
-+ dev_priv->fdi_rx_polarity_inverted = general->fdi_rx_polarity_inverted;
-+ DRM_DEBUG_KMS("BDB_GENERAL_FEATURES int_tv_support %d int_crt_support %d lvds_use_ssc %d lvds_ssc_freq %d display_clock_mode %d fdi_rx_polarity_inverted %d\n",
- dev_priv->int_tv_support,
- dev_priv->int_crt_support,
- dev_priv->lvds_use_ssc,
- dev_priv->lvds_ssc_freq,
-- dev_priv->display_clock_mode);
-+ dev_priv->display_clock_mode,
-+ dev_priv->fdi_rx_polarity_inverted);
- }
- }
-
-diff --git a/drivers/gpu/drm/i915/intel_bios.h b/drivers/gpu/drm/i915/intel_bios.h
-index 36e57f9..e088d6f 100644
---- a/drivers/gpu/drm/i915/intel_bios.h
-+++ b/drivers/gpu/drm/i915/intel_bios.h
-@@ -127,7 +127,9 @@ struct bdb_general_features {
- /* bits 3 */
- u8 disable_smooth_vision:1;
- u8 single_dvi:1;
-- u8 rsvd9:6; /* finish byte */
-+ u8 rsvd9:1;
-+ u8 fdi_rx_polarity_inverted:1;
-+ u8 rsvd10:4; /* finish byte */
-
- /* bits 4 */
- u8 legacy_monitor_detect;
-diff --git a/drivers/gpu/drm/i915/intel_display.c b/drivers/gpu/drm/i915/intel_display.c
-index b20d501..c2d173a 100644
---- a/drivers/gpu/drm/i915/intel_display.c
-+++ b/drivers/gpu/drm/i915/intel_display.c
-@@ -7589,22 +7589,25 @@ intel_modeset_affected_pipes(struct drm_crtc *crtc, unsigned *modeset_pipes,
- if (crtc->enabled)
- *prepare_pipes |= 1 << intel_crtc->pipe;
-
-- /* We only support modeset on one single crtc, hence we need to do that
-- * only for the passed in crtc iff we change anything else than just
-- * disable crtcs.
-- *
-- * This is actually not true, to be fully compatible with the old crtc
-- * helper we automatically disable _any_ output (i.e. doesn't need to be
-- * connected to the crtc we're modesetting on) if it's disconnected.
-- * Which is a rather nutty api (since changed the output configuration
-- * without userspace's explicit request can lead to confusion), but
-- * alas. Hence we currently need to modeset on all pipes we prepare. */
-+ /*
-+ * For simplicity do a full modeset on any pipe where the output routing
-+ * changed. We could be more clever, but that would require us to be
-+ * more careful with calling the relevant encoder->mode_set functions.
-+ */
- if (*prepare_pipes)
- *modeset_pipes = *prepare_pipes;
-
- /* ... and mask these out. */
- *modeset_pipes &= ~(*disable_pipes);
- *prepare_pipes &= ~(*disable_pipes);
-+
-+ /*
-+ * HACK: We don't (yet) fully support global modesets. intel_set_config
-+ * obies this rule, but the modeset restore mode of
-+ * intel_modeset_setup_hw_state does not.
-+ */
-+ *modeset_pipes &= 1 << intel_crtc->pipe;
-+ *prepare_pipes &= 1 << intel_crtc->pipe;
- }
-
- static bool intel_crtc_in_use(struct drm_crtc *crtc)
-@@ -7771,9 +7774,9 @@ intel_modeset_check_state(struct drm_device *dev)
- }
- }
-
--int intel_set_mode(struct drm_crtc *crtc,
-- struct drm_display_mode *mode,
-- int x, int y, struct drm_framebuffer *fb)
-+static int __intel_set_mode(struct drm_crtc *crtc,
-+ struct drm_display_mode *mode,
-+ int x, int y, struct drm_framebuffer *fb)
- {
- struct drm_device *dev = crtc->dev;
- drm_i915_private_t *dev_priv = dev->dev_private;
-@@ -7863,8 +7866,6 @@ done:
- if (ret && crtc->enabled) {
- crtc->hwmode = *saved_hwmode;
- crtc->mode = *saved_mode;
-- } else {
-- intel_modeset_check_state(dev);
- }
-
- out:
-@@ -7872,6 +7873,20 @@ out:
- return ret;
- }
-
-+int intel_set_mode(struct drm_crtc *crtc,
-+ struct drm_display_mode *mode,
-+ int x, int y, struct drm_framebuffer *fb)
-+{
-+ int ret;
-+
-+ ret = __intel_set_mode(crtc, mode, x, y, fb);
-+
-+ if (ret == 0)
-+ intel_modeset_check_state(crtc->dev);
-+
-+ return ret;
-+}
-+
- void intel_crtc_restore_mode(struct drm_crtc *crtc)
- {
- intel_set_mode(crtc, &crtc->mode, crtc->x, crtc->y, crtc->fb);
-@@ -8314,7 +8329,7 @@ static void intel_setup_outputs(struct drm_device *dev)
- I915_WRITE(PFIT_CONTROL, 0);
- }
-
-- if (!(HAS_DDI(dev) && (I915_READ(DDI_BUF_CTL(PORT_A)) & DDI_A_4_LANES)))
-+ if (!IS_ULT(dev))
- intel_crt_init(dev);
-
- if (HAS_DDI(dev)) {
-@@ -9172,8 +9187,16 @@ void intel_modeset_setup_hw_state(struct drm_device *dev,
- }
-
- if (force_restore) {
-+ /*
-+ * We need to use raw interfaces for restoring state to avoid
-+ * checking (bogus) intermediate states.
-+ */
- for_each_pipe(pipe) {
-- intel_crtc_restore_mode(dev_priv->pipe_to_crtc_mapping[pipe]);
-+ struct drm_crtc *crtc =
-+ dev_priv->pipe_to_crtc_mapping[pipe];
-+
-+ __intel_set_mode(crtc, &crtc->mode, crtc->x, crtc->y,
-+ crtc->fb);
- }
-
- i915_redisable_vga(dev);
-@@ -9236,6 +9259,9 @@ void intel_modeset_cleanup(struct drm_device *dev)
- /* flush any delayed tasks or pending work */
- flush_scheduled_work();
-
-+ /* destroy backlight, if any, before the connectors */
-+ intel_panel_destroy_backlight(dev);
-+
- drm_mode_config_cleanup(dev);
-
- intel_cleanup_overlay(dev);
-diff --git a/drivers/gpu/drm/i915/intel_dp.c b/drivers/gpu/drm/i915/intel_dp.c
-index 8fc93f9..b8e17e5 100644
---- a/drivers/gpu/drm/i915/intel_dp.c
-+++ b/drivers/gpu/drm/i915/intel_dp.c
-@@ -2538,17 +2538,14 @@ done:
- static void
- intel_dp_destroy(struct drm_connector *connector)
- {
-- struct drm_device *dev = connector->dev;
- struct intel_dp *intel_dp = intel_attached_dp(connector);
- struct intel_connector *intel_connector = to_intel_connector(connector);
-
- if (!IS_ERR_OR_NULL(intel_connector->edid))
- kfree(intel_connector->edid);
-
-- if (is_edp(intel_dp)) {
-- intel_panel_destroy_backlight(dev);
-+ if (is_edp(intel_dp))
- intel_panel_fini(&intel_connector->panel);
-- }
-
- drm_sysfs_connector_remove(connector);
- drm_connector_cleanup(connector);
-diff --git a/drivers/gpu/drm/i915/intel_dvo.c b/drivers/gpu/drm/i915/intel_dvo.c
-index 00e70db..cc70b16 100644
---- a/drivers/gpu/drm/i915/intel_dvo.c
-+++ b/drivers/gpu/drm/i915/intel_dvo.c
-@@ -448,6 +448,7 @@ void intel_dvo_init(struct drm_device *dev)
- const struct intel_dvo_device *dvo = &intel_dvo_devices[i];
- struct i2c_adapter *i2c;
- int gpio;
-+ bool dvoinit;
-
- /* Allow the I2C driver info to specify the GPIO to be used in
- * special cases, but otherwise default to what's defined
-@@ -467,7 +468,17 @@ void intel_dvo_init(struct drm_device *dev)
- i2c = intel_gmbus_get_adapter(dev_priv, gpio);
-
- intel_dvo->dev = *dvo;
-- if (!dvo->dev_ops->init(&intel_dvo->dev, i2c))
-+
-+ /* GMBUS NAK handling seems to be unstable, hence let the
-+ * transmitter detection run in bit banging mode for now.
-+ */
-+ intel_gmbus_force_bit(i2c, true);
-+
-+ dvoinit = dvo->dev_ops->init(&intel_dvo->dev, i2c);
-+
-+ intel_gmbus_force_bit(i2c, false);
-+
-+ if (!dvoinit)
- continue;
-
- intel_encoder->type = INTEL_OUTPUT_DVO;
-diff --git a/drivers/gpu/drm/i915/intel_lvds.c b/drivers/gpu/drm/i915/intel_lvds.c
-index 3d1d974..e0d6985 100644
---- a/drivers/gpu/drm/i915/intel_lvds.c
-+++ b/drivers/gpu/drm/i915/intel_lvds.c
-@@ -618,7 +618,6 @@ static void intel_lvds_destroy(struct drm_connector *connector)
- if (!IS_ERR_OR_NULL(lvds_connector->base.edid))
- kfree(lvds_connector->base.edid);
-
-- intel_panel_destroy_backlight(connector->dev);
- intel_panel_fini(&lvds_connector->base.panel);
-
- drm_sysfs_connector_remove(connector);
-@@ -850,6 +849,14 @@ static const struct dmi_system_id intel_no_lvds[] = {
- DMI_MATCH(DMI_PRODUCT_NAME, "X7SPA-H"),
- },
- },
-+ {
-+ .callback = intel_no_lvds_dmi_callback,
-+ .ident = "Fujitsu Esprimo Q900",
-+ .matches = {
-+ DMI_MATCH(DMI_SYS_VENDOR, "FUJITSU"),
-+ DMI_MATCH(DMI_PRODUCT_NAME, "ESPRIMO Q900"),
-+ },
-+ },
-
- { } /* terminating entry */
- };
-diff --git a/drivers/gpu/drm/i915/intel_panel.c b/drivers/gpu/drm/i915/intel_panel.c
-index bee8cb6..94d895b 100644
---- a/drivers/gpu/drm/i915/intel_panel.c
-+++ b/drivers/gpu/drm/i915/intel_panel.c
-@@ -422,6 +422,9 @@ int intel_panel_setup_backlight(struct drm_connector *connector)
-
- intel_panel_init_backlight(dev);
-
-+ if (WARN_ON(dev_priv->backlight))
-+ return -ENODEV;
-+
- memset(&props, 0, sizeof(props));
- props.type = BACKLIGHT_RAW;
- props.max_brightness = _intel_panel_get_max_backlight(dev);
-@@ -447,8 +450,10 @@ int intel_panel_setup_backlight(struct drm_connector *connector)
- void intel_panel_destroy_backlight(struct drm_device *dev)
- {
- struct drm_i915_private *dev_priv = dev->dev_private;
-- if (dev_priv->backlight)
-+ if (dev_priv->backlight) {
- backlight_device_unregister(dev_priv->backlight);
-+ dev_priv->backlight = NULL;
-+ }
- }
- #else
- int intel_panel_setup_backlight(struct drm_connector *connector)
-diff --git a/drivers/gpu/drm/i915/intel_pm.c b/drivers/gpu/drm/i915/intel_pm.c
-index adca007..332b29e 100644
---- a/drivers/gpu/drm/i915/intel_pm.c
-+++ b/drivers/gpu/drm/i915/intel_pm.c
-@@ -3562,6 +3562,7 @@ static void cpt_init_clock_gating(struct drm_device *dev)
- {
- struct drm_i915_private *dev_priv = dev->dev_private;
- int pipe;
-+ uint32_t val;
-
- /*
- * On Ibex Peak and Cougar Point, we need to disable clock
-@@ -3574,8 +3575,12 @@ static void cpt_init_clock_gating(struct drm_device *dev)
- /* The below fixes the weird display corruption, a few pixels shifted
- * downward, on (only) LVDS of some HP laptops with IVY.
- */
-- for_each_pipe(pipe)
-- I915_WRITE(TRANS_CHICKEN2(pipe), TRANS_CHICKEN2_TIMING_OVERRIDE);
-+ for_each_pipe(pipe) {
-+ val = TRANS_CHICKEN2_TIMING_OVERRIDE;
-+ if (dev_priv->fdi_rx_polarity_inverted)
-+ val |= TRANS_CHICKEN2_FDI_POLARITY_REVERSED;
-+ I915_WRITE(TRANS_CHICKEN2(pipe), val);
-+ }
- /* WADP0ClockGatingDisable */
- for_each_pipe(pipe) {
- I915_WRITE(TRANS_CHICKEN1(pipe),
-diff --git a/drivers/gpu/drm/i915/intel_sdvo.c b/drivers/gpu/drm/i915/intel_sdvo.c
-index d07a8cd..d6df786 100644
---- a/drivers/gpu/drm/i915/intel_sdvo.c
-+++ b/drivers/gpu/drm/i915/intel_sdvo.c
-@@ -1235,11 +1235,13 @@ static bool intel_sdvo_get_hw_state(struct intel_encoder *encoder,
- struct drm_device *dev = encoder->base.dev;
- struct drm_i915_private *dev_priv = dev->dev_private;
- struct intel_sdvo *intel_sdvo = to_intel_sdvo(&encoder->base);
-+ u16 active_outputs;
- u32 tmp;
-
- tmp = I915_READ(intel_sdvo->sdvo_reg);
-+ intel_sdvo_get_active_outputs(intel_sdvo, &active_outputs);
-
-- if (!(tmp & SDVO_ENABLE))
-+ if (!(tmp & SDVO_ENABLE) && (active_outputs == 0))
- return false;
-
- if (HAS_PCH_CPT(dev))
-@@ -2739,7 +2741,6 @@ bool intel_sdvo_init(struct drm_device *dev, uint32_t sdvo_reg, bool is_sdvob)
- struct intel_sdvo *intel_sdvo;
- u32 hotplug_mask;
- int i;
--
- intel_sdvo = kzalloc(sizeof(struct intel_sdvo), GFP_KERNEL);
- if (!intel_sdvo)
- return false;
-diff --git a/drivers/gpu/drm/mgag200/mgag200_drv.h b/drivers/gpu/drm/mgag200/mgag200_drv.h
-index 4d932c4..8065919 100644
---- a/drivers/gpu/drm/mgag200/mgag200_drv.h
-+++ b/drivers/gpu/drm/mgag200/mgag200_drv.h
-@@ -115,6 +115,8 @@ struct mga_fbdev {
- void *sysram;
- int size;
- struct ttm_bo_kmap_obj mapping;
-+ int x1, y1, x2, y2; /* dirty rect */
-+ spinlock_t dirty_lock;
- };
-
- struct mga_crtc {
-diff --git a/drivers/gpu/drm/mgag200/mgag200_fb.c b/drivers/gpu/drm/mgag200/mgag200_fb.c
-index d2253f6..b0dad27 100644
---- a/drivers/gpu/drm/mgag200/mgag200_fb.c
-+++ b/drivers/gpu/drm/mgag200/mgag200_fb.c
-@@ -29,16 +29,52 @@ static void mga_dirty_update(struct mga_fbdev *mfbdev,
- int bpp = (mfbdev->mfb.base.bits_per_pixel + 7)/8;
- int ret;
- bool unmap = false;
-+ bool store_for_later = false;
-+ int x2, y2;
-+ unsigned long flags;
-
- obj = mfbdev->mfb.obj;
- bo = gem_to_mga_bo(obj);
-
-+ /*
-+ * try and reserve the BO, if we fail with busy
-+ * then the BO is being moved and we should
-+ * store up the damage until later.
-+ */
- ret = mgag200_bo_reserve(bo, true);
- if (ret) {
-- DRM_ERROR("failed to reserve fb bo\n");
-+ if (ret != -EBUSY)
-+ return;
-+
-+ store_for_later = true;
-+ }
-+
-+ x2 = x + width - 1;
-+ y2 = y + height - 1;
-+ spin_lock_irqsave(&mfbdev->dirty_lock, flags);
-+
-+ if (mfbdev->y1 < y)
-+ y = mfbdev->y1;
-+ if (mfbdev->y2 > y2)
-+ y2 = mfbdev->y2;
-+ if (mfbdev->x1 < x)
-+ x = mfbdev->x1;
-+ if (mfbdev->x2 > x2)
-+ x2 = mfbdev->x2;
-+
-+ if (store_for_later) {
-+ mfbdev->x1 = x;
-+ mfbdev->x2 = x2;
-+ mfbdev->y1 = y;
-+ mfbdev->y2 = y2;
-+ spin_unlock_irqrestore(&mfbdev->dirty_lock, flags);
- return;
- }
-
-+ mfbdev->x1 = mfbdev->y1 = INT_MAX;
-+ mfbdev->x2 = mfbdev->y2 = 0;
-+ spin_unlock_irqrestore(&mfbdev->dirty_lock, flags);
-+
- if (!bo->kmap.virtual) {
- ret = ttm_bo_kmap(&bo->bo, 0, bo->bo.num_pages, &bo->kmap);
- if (ret) {
-@@ -48,10 +84,10 @@ static void mga_dirty_update(struct mga_fbdev *mfbdev,
- }
- unmap = true;
- }
-- for (i = y; i < y + height; i++) {
-+ for (i = y; i <= y2; i++) {
- /* assume equal stride for now */
- src_offset = dst_offset = i * mfbdev->mfb.base.pitches[0] + (x * bpp);
-- memcpy_toio(bo->kmap.virtual + src_offset, mfbdev->sysram + src_offset, width * bpp);
-+ memcpy_toio(bo->kmap.virtual + src_offset, mfbdev->sysram + src_offset, (x2 - x + 1) * bpp);
-
- }
- if (unmap)
-@@ -255,6 +291,7 @@ int mgag200_fbdev_init(struct mga_device *mdev)
-
- mdev->mfbdev = mfbdev;
- mfbdev->helper.funcs = &mga_fb_helper_funcs;
-+ spin_lock_init(&mfbdev->dirty_lock);
-
- ret = drm_fb_helper_init(mdev->dev, &mfbdev->helper,
- mdev->num_crtc, MGAG200FB_CONN_LIMIT);
-diff --git a/drivers/gpu/drm/mgag200/mgag200_ttm.c b/drivers/gpu/drm/mgag200/mgag200_ttm.c
-index 8fc9d92..401c989 100644
---- a/drivers/gpu/drm/mgag200/mgag200_ttm.c
-+++ b/drivers/gpu/drm/mgag200/mgag200_ttm.c
-@@ -315,8 +315,8 @@ int mgag200_bo_reserve(struct mgag200_bo *bo, bool no_wait)
-
- ret = ttm_bo_reserve(&bo->bo, true, no_wait, false, 0);
- if (ret) {
-- if (ret != -ERESTARTSYS)
-- DRM_ERROR("reserve failed %p\n", bo);
-+ if (ret != -ERESTARTSYS && ret != -EBUSY)
-+ DRM_ERROR("reserve failed %p %d\n", bo, ret);
- return ret;
- }
- return 0;
-diff --git a/drivers/gpu/drm/omapdrm/omap_gem_dmabuf.c b/drivers/gpu/drm/omapdrm/omap_gem_dmabuf.c
-index ac74d1b..1bdf7e1 100644
---- a/drivers/gpu/drm/omapdrm/omap_gem_dmabuf.c
-+++ b/drivers/gpu/drm/omapdrm/omap_gem_dmabuf.c
-@@ -212,7 +212,6 @@ struct drm_gem_object *omap_gem_prime_import(struct drm_device *dev,
- * refcount on gem itself instead of f_count of dmabuf.
- */
- drm_gem_object_reference(obj);
-- dma_buf_put(buffer);
- return obj;
- }
- }
-diff --git a/drivers/gpu/drm/radeon/atom.c b/drivers/gpu/drm/radeon/atom.c
-index 46a9c37..fb441a7 100644
---- a/drivers/gpu/drm/radeon/atom.c
-+++ b/drivers/gpu/drm/radeon/atom.c
-@@ -1394,10 +1394,10 @@ int atom_allocate_fb_scratch(struct atom_context *ctx)
- firmware_usage = (struct _ATOM_VRAM_USAGE_BY_FIRMWARE *)(ctx->bios + data_offset);
-
- DRM_DEBUG("atom firmware requested %08x %dkb\n",
-- firmware_usage->asFirmwareVramReserveInfo[0].ulStartAddrUsedByFirmware,
-- firmware_usage->asFirmwareVramReserveInfo[0].usFirmwareUseInKb);
-+ le32_to_cpu(firmware_usage->asFirmwareVramReserveInfo[0].ulStartAddrUsedByFirmware),
-+ le16_to_cpu(firmware_usage->asFirmwareVramReserveInfo[0].usFirmwareUseInKb));
-
-- usage_bytes = firmware_usage->asFirmwareVramReserveInfo[0].usFirmwareUseInKb * 1024;
-+ usage_bytes = le16_to_cpu(firmware_usage->asFirmwareVramReserveInfo[0].usFirmwareUseInKb) * 1024;
- }
- ctx->scratch_size_bytes = 0;
- if (usage_bytes == 0)
-diff --git a/drivers/gpu/drm/radeon/atombios_crtc.c b/drivers/gpu/drm/radeon/atombios_crtc.c
-index 21a892c..6d6fdb3 100644
---- a/drivers/gpu/drm/radeon/atombios_crtc.c
-+++ b/drivers/gpu/drm/radeon/atombios_crtc.c
-@@ -557,6 +557,9 @@ static u32 atombios_adjust_pll(struct drm_crtc *crtc,
- /* use frac fb div on APUs */
- if (ASIC_IS_DCE41(rdev) || ASIC_IS_DCE61(rdev))
- radeon_crtc->pll_flags |= RADEON_PLL_USE_FRAC_FB_DIV;
-+ /* use frac fb div on RS780/RS880 */
-+ if ((rdev->family == CHIP_RS780) || (rdev->family == CHIP_RS880))
-+ radeon_crtc->pll_flags |= RADEON_PLL_USE_FRAC_FB_DIV;
- if (ASIC_IS_DCE32(rdev) && mode->clock > 165000)
- radeon_crtc->pll_flags |= RADEON_PLL_USE_FRAC_FB_DIV;
- } else {
-diff --git a/drivers/gpu/drm/radeon/evergreen.c b/drivers/gpu/drm/radeon/evergreen.c
-index 305a657..aeaa386 100644
---- a/drivers/gpu/drm/radeon/evergreen.c
-+++ b/drivers/gpu/drm/radeon/evergreen.c
-@@ -105,6 +105,27 @@ void evergreen_fix_pci_max_read_req_size(struct radeon_device *rdev)
- }
- }
-
-+static bool dce4_is_in_vblank(struct radeon_device *rdev, int crtc)
-+{
-+ if (RREG32(EVERGREEN_CRTC_STATUS + crtc_offsets[crtc]) & EVERGREEN_CRTC_V_BLANK)
-+ return true;
-+ else
-+ return false;
-+}
-+
-+static bool dce4_is_counter_moving(struct radeon_device *rdev, int crtc)
-+{
-+ u32 pos1, pos2;
-+
-+ pos1 = RREG32(EVERGREEN_CRTC_STATUS_POSITION + crtc_offsets[crtc]);
-+ pos2 = RREG32(EVERGREEN_CRTC_STATUS_POSITION + crtc_offsets[crtc]);
-+
-+ if (pos1 != pos2)
-+ return true;
-+ else
-+ return false;
-+}
-+
- /**
- * dce4_wait_for_vblank - vblank wait asic callback.
- *
-@@ -115,21 +136,28 @@ void evergreen_fix_pci_max_read_req_size(struct radeon_device *rdev)
- */
- void dce4_wait_for_vblank(struct radeon_device *rdev, int crtc)
- {
-- int i;
-+ unsigned i = 0;
-
- if (crtc >= rdev->num_crtc)
- return;
-
-- if (RREG32(EVERGREEN_CRTC_CONTROL + crtc_offsets[crtc]) & EVERGREEN_CRTC_MASTER_EN) {
-- for (i = 0; i < rdev->usec_timeout; i++) {
-- if (!(RREG32(EVERGREEN_CRTC_STATUS + crtc_offsets[crtc]) & EVERGREEN_CRTC_V_BLANK))
-+ if (!(RREG32(EVERGREEN_CRTC_CONTROL + crtc_offsets[crtc]) & EVERGREEN_CRTC_MASTER_EN))
-+ return;
-+
-+ /* depending on when we hit vblank, we may be close to active; if so,
-+ * wait for another frame.
-+ */
-+ while (dce4_is_in_vblank(rdev, crtc)) {
-+ if (i++ % 100 == 0) {
-+ if (!dce4_is_counter_moving(rdev, crtc))
- break;
-- udelay(1);
- }
-- for (i = 0; i < rdev->usec_timeout; i++) {
-- if (RREG32(EVERGREEN_CRTC_STATUS + crtc_offsets[crtc]) & EVERGREEN_CRTC_V_BLANK)
-+ }
-+
-+ while (!dce4_is_in_vblank(rdev, crtc)) {
-+ if (i++ % 100 == 0) {
-+ if (!dce4_is_counter_moving(rdev, crtc))
- break;
-- udelay(1);
- }
- }
- }
-@@ -608,6 +636,16 @@ void evergreen_hpd_init(struct radeon_device *rdev)
-
- list_for_each_entry(connector, &dev->mode_config.connector_list, head) {
- struct radeon_connector *radeon_connector = to_radeon_connector(connector);
-+
-+ if (connector->connector_type == DRM_MODE_CONNECTOR_eDP ||
-+ connector->connector_type == DRM_MODE_CONNECTOR_LVDS) {
-+ /* don't try to enable hpd on eDP or LVDS avoid breaking the
-+ * aux dp channel on imac and help (but not completely fix)
-+ * https://bugzilla.redhat.com/show_bug.cgi?id=726143
-+ * also avoid interrupt storms during dpms.
-+ */
-+ continue;
-+ }
- switch (radeon_connector->hpd.hpd) {
- case RADEON_HPD_1:
- WREG32(DC_HPD1_CONTROL, tmp);
-@@ -1325,17 +1363,16 @@ void evergreen_mc_stop(struct radeon_device *rdev, struct evergreen_mc_save *sav
- tmp = RREG32(EVERGREEN_CRTC_BLANK_CONTROL + crtc_offsets[i]);
- if (!(tmp & EVERGREEN_CRTC_BLANK_DATA_EN)) {
- radeon_wait_for_vblank(rdev, i);
-- tmp |= EVERGREEN_CRTC_BLANK_DATA_EN;
- WREG32(EVERGREEN_CRTC_UPDATE_LOCK + crtc_offsets[i], 1);
-+ tmp |= EVERGREEN_CRTC_BLANK_DATA_EN;
- WREG32(EVERGREEN_CRTC_BLANK_CONTROL + crtc_offsets[i], tmp);
-- WREG32(EVERGREEN_CRTC_UPDATE_LOCK + crtc_offsets[i], 0);
- }
- } else {
- tmp = RREG32(EVERGREEN_CRTC_CONTROL + crtc_offsets[i]);
- if (!(tmp & EVERGREEN_CRTC_DISP_READ_REQUEST_DISABLE)) {
- radeon_wait_for_vblank(rdev, i);
-- tmp |= EVERGREEN_CRTC_DISP_READ_REQUEST_DISABLE;
- WREG32(EVERGREEN_CRTC_UPDATE_LOCK + crtc_offsets[i], 1);
-+ tmp |= EVERGREEN_CRTC_DISP_READ_REQUEST_DISABLE;
- WREG32(EVERGREEN_CRTC_CONTROL + crtc_offsets[i], tmp);
- WREG32(EVERGREEN_CRTC_UPDATE_LOCK + crtc_offsets[i], 0);
- }
-@@ -1347,6 +1384,15 @@ void evergreen_mc_stop(struct radeon_device *rdev, struct evergreen_mc_save *sav
- break;
- udelay(1);
- }
-+
-+ /* XXX this is a hack to avoid strange behavior with EFI on certain systems */
-+ WREG32(EVERGREEN_CRTC_UPDATE_LOCK + crtc_offsets[i], 1);
-+ tmp = RREG32(EVERGREEN_CRTC_CONTROL + crtc_offsets[i]);
-+ tmp &= ~EVERGREEN_CRTC_MASTER_EN;
-+ WREG32(EVERGREEN_CRTC_CONTROL + crtc_offsets[i], tmp);
-+ WREG32(EVERGREEN_CRTC_UPDATE_LOCK + crtc_offsets[i], 0);
-+ save->crtc_enabled[i] = false;
-+ /* ***** */
- } else {
- save->crtc_enabled[i] = false;
- }
-@@ -1364,6 +1410,22 @@ void evergreen_mc_stop(struct radeon_device *rdev, struct evergreen_mc_save *sav
- }
- /* wait for the MC to settle */
- udelay(100);
-+
-+ /* lock double buffered regs */
-+ for (i = 0; i < rdev->num_crtc; i++) {
-+ if (save->crtc_enabled[i]) {
-+ tmp = RREG32(EVERGREEN_GRPH_UPDATE + crtc_offsets[i]);
-+ if (!(tmp & EVERGREEN_GRPH_UPDATE_LOCK)) {
-+ tmp |= EVERGREEN_GRPH_UPDATE_LOCK;
-+ WREG32(EVERGREEN_GRPH_UPDATE + crtc_offsets[i], tmp);
-+ }
-+ tmp = RREG32(EVERGREEN_MASTER_UPDATE_LOCK + crtc_offsets[i]);
-+ if (!(tmp & 1)) {
-+ tmp |= 1;
-+ WREG32(EVERGREEN_MASTER_UPDATE_LOCK + crtc_offsets[i], tmp);
-+ }
-+ }
-+ }
- }
-
- void evergreen_mc_resume(struct radeon_device *rdev, struct evergreen_mc_save *save)
-@@ -1385,6 +1447,33 @@ void evergreen_mc_resume(struct radeon_device *rdev, struct evergreen_mc_save *s
- WREG32(EVERGREEN_VGA_MEMORY_BASE_ADDRESS_HIGH, upper_32_bits(rdev->mc.vram_start));
- WREG32(EVERGREEN_VGA_MEMORY_BASE_ADDRESS, (u32)rdev->mc.vram_start);
-
-+ /* unlock regs and wait for update */
-+ for (i = 0; i < rdev->num_crtc; i++) {
-+ if (save->crtc_enabled[i]) {
-+ tmp = RREG32(EVERGREEN_MASTER_UPDATE_MODE + crtc_offsets[i]);
-+ if ((tmp & 0x3) != 0) {
-+ tmp &= ~0x3;
-+ WREG32(EVERGREEN_MASTER_UPDATE_MODE + crtc_offsets[i], tmp);
-+ }
-+ tmp = RREG32(EVERGREEN_GRPH_UPDATE + crtc_offsets[i]);
-+ if (tmp & EVERGREEN_GRPH_UPDATE_LOCK) {
-+ tmp &= ~EVERGREEN_GRPH_UPDATE_LOCK;
-+ WREG32(EVERGREEN_GRPH_UPDATE + crtc_offsets[i], tmp);
-+ }
-+ tmp = RREG32(EVERGREEN_MASTER_UPDATE_LOCK + crtc_offsets[i]);
-+ if (tmp & 1) {
-+ tmp &= ~1;
-+ WREG32(EVERGREEN_MASTER_UPDATE_LOCK + crtc_offsets[i], tmp);
-+ }
-+ for (j = 0; j < rdev->usec_timeout; j++) {
-+ tmp = RREG32(EVERGREEN_GRPH_UPDATE + crtc_offsets[i]);
-+ if ((tmp & EVERGREEN_GRPH_SURFACE_UPDATE_PENDING) == 0)
-+ break;
-+ udelay(1);
-+ }
-+ }
-+ }
-+
- /* unblackout the MC */
- tmp = RREG32(MC_SHARED_BLACKOUT_CNTL);
- tmp &= ~BLACKOUT_MODE_MASK;
-diff --git a/drivers/gpu/drm/radeon/evergreen_reg.h b/drivers/gpu/drm/radeon/evergreen_reg.h
-index f585be1..881aba2 100644
---- a/drivers/gpu/drm/radeon/evergreen_reg.h
-+++ b/drivers/gpu/drm/radeon/evergreen_reg.h
-@@ -226,6 +226,8 @@
- #define EVERGREEN_CRTC_STATUS_HV_COUNT 0x6ea0
- #define EVERGREEN_MASTER_UPDATE_MODE 0x6ef8
- #define EVERGREEN_CRTC_UPDATE_LOCK 0x6ed4
-+#define EVERGREEN_MASTER_UPDATE_LOCK 0x6ef4
-+#define EVERGREEN_MASTER_UPDATE_MODE 0x6ef8
-
- #define EVERGREEN_DC_GPIO_HPD_MASK 0x64b0
- #define EVERGREEN_DC_GPIO_HPD_A 0x64b4
-diff --git a/drivers/gpu/drm/radeon/ni.c b/drivers/gpu/drm/radeon/ni.c
-index 27769e7..0a32d89 100644
---- a/drivers/gpu/drm/radeon/ni.c
-+++ b/drivers/gpu/drm/radeon/ni.c
-@@ -473,7 +473,8 @@ static void cayman_gpu_init(struct radeon_device *rdev)
- (rdev->pdev->device == 0x990F) ||
- (rdev->pdev->device == 0x9910) ||
- (rdev->pdev->device == 0x9917) ||
-- (rdev->pdev->device == 0x9999)) {
-+ (rdev->pdev->device == 0x9999) ||
-+ (rdev->pdev->device == 0x999C)) {
- rdev->config.cayman.max_simds_per_se = 6;
- rdev->config.cayman.max_backends_per_se = 2;
- } else if ((rdev->pdev->device == 0x9903) ||
-@@ -482,7 +483,8 @@ static void cayman_gpu_init(struct radeon_device *rdev)
- (rdev->pdev->device == 0x990D) ||
- (rdev->pdev->device == 0x990E) ||
- (rdev->pdev->device == 0x9913) ||
-- (rdev->pdev->device == 0x9918)) {
-+ (rdev->pdev->device == 0x9918) ||
-+ (rdev->pdev->device == 0x999D)) {
- rdev->config.cayman.max_simds_per_se = 4;
- rdev->config.cayman.max_backends_per_se = 2;
- } else if ((rdev->pdev->device == 0x9919) ||
-@@ -621,6 +623,8 @@ static void cayman_gpu_init(struct radeon_device *rdev)
-
- WREG32(GB_ADDR_CONFIG, gb_addr_config);
- WREG32(DMIF_ADDR_CONFIG, gb_addr_config);
-+ if (ASIC_IS_DCE6(rdev))
-+ WREG32(DMIF_ADDR_CALC, gb_addr_config);
- WREG32(HDP_ADDR_CONFIG, gb_addr_config);
- WREG32(DMA_TILING_CONFIG + DMA0_REGISTER_OFFSET, gb_addr_config);
- WREG32(DMA_TILING_CONFIG + DMA1_REGISTER_OFFSET, gb_addr_config);
-diff --git a/drivers/gpu/drm/radeon/nid.h b/drivers/gpu/drm/radeon/nid.h
-index 079dee2..445b235 100644
---- a/drivers/gpu/drm/radeon/nid.h
-+++ b/drivers/gpu/drm/radeon/nid.h
-@@ -45,6 +45,10 @@
- #define ARUBA_GB_ADDR_CONFIG_GOLDEN 0x12010001
-
- #define DMIF_ADDR_CONFIG 0xBD4
-+
-+/* DCE6 only */
-+#define DMIF_ADDR_CALC 0xC00
-+
- #define SRBM_GFX_CNTL 0x0E44
- #define RINGID(x) (((x) & 0x3) << 0)
- #define VMID(x) (((x) & 0x7) << 0)
-diff --git a/drivers/gpu/drm/radeon/r100.c b/drivers/gpu/drm/radeon/r100.c
-index 9db5853..4973bff 100644
---- a/drivers/gpu/drm/radeon/r100.c
-+++ b/drivers/gpu/drm/radeon/r100.c
-@@ -69,6 +69,38 @@ MODULE_FIRMWARE(FIRMWARE_R520);
- * and others in some cases.
- */
-
-+static bool r100_is_in_vblank(struct radeon_device *rdev, int crtc)
-+{
-+ if (crtc == 0) {
-+ if (RREG32(RADEON_CRTC_STATUS) & RADEON_CRTC_VBLANK_CUR)
-+ return true;
-+ else
-+ return false;
-+ } else {
-+ if (RREG32(RADEON_CRTC2_STATUS) & RADEON_CRTC2_VBLANK_CUR)
-+ return true;
-+ else
-+ return false;
-+ }
-+}
-+
-+static bool r100_is_counter_moving(struct radeon_device *rdev, int crtc)
-+{
-+ u32 vline1, vline2;
-+
-+ if (crtc == 0) {
-+ vline1 = (RREG32(RADEON_CRTC_VLINE_CRNT_VLINE) >> 16) & RADEON_CRTC_V_TOTAL;
-+ vline2 = (RREG32(RADEON_CRTC_VLINE_CRNT_VLINE) >> 16) & RADEON_CRTC_V_TOTAL;
-+ } else {
-+ vline1 = (RREG32(RADEON_CRTC2_VLINE_CRNT_VLINE) >> 16) & RADEON_CRTC_V_TOTAL;
-+ vline2 = (RREG32(RADEON_CRTC2_VLINE_CRNT_VLINE) >> 16) & RADEON_CRTC_V_TOTAL;
-+ }
-+ if (vline1 != vline2)
-+ return true;
-+ else
-+ return false;
-+}
-+
- /**
- * r100_wait_for_vblank - vblank wait asic callback.
- *
-@@ -79,36 +111,33 @@ MODULE_FIRMWARE(FIRMWARE_R520);
- */
- void r100_wait_for_vblank(struct radeon_device *rdev, int crtc)
- {
-- int i;
-+ unsigned i = 0;
-
- if (crtc >= rdev->num_crtc)
- return;
-
- if (crtc == 0) {
-- if (RREG32(RADEON_CRTC_GEN_CNTL) & RADEON_CRTC_EN) {
-- for (i = 0; i < rdev->usec_timeout; i++) {
-- if (!(RREG32(RADEON_CRTC_STATUS) & RADEON_CRTC_VBLANK_CUR))
-- break;
-- udelay(1);
-- }
-- for (i = 0; i < rdev->usec_timeout; i++) {
-- if (RREG32(RADEON_CRTC_STATUS) & RADEON_CRTC_VBLANK_CUR)
-- break;
-- udelay(1);
-- }
-- }
-+ if (!(RREG32(RADEON_CRTC_GEN_CNTL) & RADEON_CRTC_EN))
-+ return;
- } else {
-- if (RREG32(RADEON_CRTC2_GEN_CNTL) & RADEON_CRTC2_EN) {
-- for (i = 0; i < rdev->usec_timeout; i++) {
-- if (!(RREG32(RADEON_CRTC2_STATUS) & RADEON_CRTC2_VBLANK_CUR))
-- break;
-- udelay(1);
-- }
-- for (i = 0; i < rdev->usec_timeout; i++) {
-- if (RREG32(RADEON_CRTC2_STATUS) & RADEON_CRTC2_VBLANK_CUR)
-- break;
-- udelay(1);
-- }
-+ if (!(RREG32(RADEON_CRTC2_GEN_CNTL) & RADEON_CRTC2_EN))
-+ return;
-+ }
-+
-+ /* depending on when we hit vblank, we may be close to active; if so,
-+ * wait for another frame.
-+ */
-+ while (r100_is_in_vblank(rdev, crtc)) {
-+ if (i++ % 100 == 0) {
-+ if (!r100_is_counter_moving(rdev, crtc))
-+ break;
-+ }
-+ }
-+
-+ while (!r100_is_in_vblank(rdev, crtc)) {
-+ if (i++ % 100 == 0) {
-+ if (!r100_is_counter_moving(rdev, crtc))
-+ break;
- }
- }
- }
-diff --git a/drivers/gpu/drm/radeon/r500_reg.h b/drivers/gpu/drm/radeon/r500_reg.h
-index c0dc8d3..1dd0d32 100644
---- a/drivers/gpu/drm/radeon/r500_reg.h
-+++ b/drivers/gpu/drm/radeon/r500_reg.h
-@@ -358,7 +358,9 @@
- #define AVIVO_D1CRTC_STATUS_HV_COUNT 0x60ac
- #define AVIVO_D1CRTC_STEREO_CONTROL 0x60c4
-
-+#define AVIVO_D1MODE_MASTER_UPDATE_LOCK 0x60e0
- #define AVIVO_D1MODE_MASTER_UPDATE_MODE 0x60e4
-+#define AVIVO_D1CRTC_UPDATE_LOCK 0x60e8
-
- /* master controls */
- #define AVIVO_DC_CRTC_MASTER_EN 0x60f8
-diff --git a/drivers/gpu/drm/radeon/r600_hdmi.c b/drivers/gpu/drm/radeon/r600_hdmi.c
-index 21ecc0e..8520833 100644
---- a/drivers/gpu/drm/radeon/r600_hdmi.c
-+++ b/drivers/gpu/drm/radeon/r600_hdmi.c
-@@ -433,7 +433,7 @@ void r600_hdmi_enable(struct drm_encoder *encoder)
- offset = dig->afmt->offset;
-
- /* Older chipsets require setting HDMI and routing manually */
-- if (rdev->family >= CHIP_R600 && !ASIC_IS_DCE3(rdev)) {
-+ if (ASIC_IS_DCE2(rdev) && !ASIC_IS_DCE3(rdev)) {
- hdmi = HDMI0_ERROR_ACK | HDMI0_ENABLE;
- switch (radeon_encoder->encoder_id) {
- case ENCODER_OBJECT_ID_INTERNAL_KLDSCP_TMDS1:
-@@ -501,7 +501,7 @@ void r600_hdmi_disable(struct drm_encoder *encoder)
- radeon_irq_kms_disable_afmt(rdev, dig->afmt->id);
-
- /* Older chipsets not handled by AtomBIOS */
-- if (rdev->family >= CHIP_R600 && !ASIC_IS_DCE3(rdev)) {
-+ if (ASIC_IS_DCE2(rdev) && !ASIC_IS_DCE3(rdev)) {
- switch (radeon_encoder->encoder_id) {
- case ENCODER_OBJECT_ID_INTERNAL_KLDSCP_TMDS1:
- WREG32_P(AVIVO_TMDSA_CNTL, 0,
-diff --git a/drivers/gpu/drm/radeon/radeon_atombios.c b/drivers/gpu/drm/radeon/radeon_atombios.c
-index f22eb57..96168ef 100644
---- a/drivers/gpu/drm/radeon/radeon_atombios.c
-+++ b/drivers/gpu/drm/radeon/radeon_atombios.c
-@@ -2028,6 +2028,8 @@ static int radeon_atombios_parse_power_table_1_3(struct radeon_device *rdev)
- num_modes = power_info->info.ucNumOfPowerModeEntries;
- if (num_modes > ATOM_MAX_NUMBEROF_POWER_BLOCK)
- num_modes = ATOM_MAX_NUMBEROF_POWER_BLOCK;
-+ if (num_modes == 0)
-+ return state_index;
- rdev->pm.power_state = kzalloc(sizeof(struct radeon_power_state) * num_modes, GFP_KERNEL);
- if (!rdev->pm.power_state)
- return state_index;
-@@ -2432,6 +2434,8 @@ static int radeon_atombios_parse_power_table_4_5(struct radeon_device *rdev)
- power_info = (union power_info *)(mode_info->atom_context->bios + data_offset);
-
- radeon_atombios_add_pplib_thermal_controller(rdev, &power_info->pplib.sThermalController);
-+ if (power_info->pplib.ucNumStates == 0)
-+ return state_index;
- rdev->pm.power_state = kzalloc(sizeof(struct radeon_power_state) *
- power_info->pplib.ucNumStates, GFP_KERNEL);
- if (!rdev->pm.power_state)
-@@ -2514,6 +2518,7 @@ static int radeon_atombios_parse_power_table_6(struct radeon_device *rdev)
- int index = GetIndexIntoMasterTable(DATA, PowerPlayInfo);
- u16 data_offset;
- u8 frev, crev;
-+ u8 *power_state_offset;
-
- if (!atom_parse_data_header(mode_info->atom_context, index, NULL,
- &frev, &crev, &data_offset))
-@@ -2530,15 +2535,17 @@ static int radeon_atombios_parse_power_table_6(struct radeon_device *rdev)
- non_clock_info_array = (struct _NonClockInfoArray *)
- (mode_info->atom_context->bios + data_offset +
- le16_to_cpu(power_info->pplib.usNonClockInfoArrayOffset));
-+ if (state_array->ucNumEntries == 0)
-+ return state_index;
- rdev->pm.power_state = kzalloc(sizeof(struct radeon_power_state) *
- state_array->ucNumEntries, GFP_KERNEL);
- if (!rdev->pm.power_state)
- return state_index;
-+ power_state_offset = (u8 *)state_array->states;
- for (i = 0; i < state_array->ucNumEntries; i++) {
- mode_index = 0;
-- power_state = (union pplib_power_state *)&state_array->states[i];
-- /* XXX this might be an inagua bug... */
-- non_clock_array_index = i; /* power_state->v2.nonClockInfoIndex */
-+ power_state = (union pplib_power_state *)power_state_offset;
-+ non_clock_array_index = power_state->v2.nonClockInfoIndex;
- non_clock_info = (struct _ATOM_PPLIB_NONCLOCK_INFO *)
- &non_clock_info_array->nonClockInfo[non_clock_array_index];
- rdev->pm.power_state[i].clock_info = kzalloc(sizeof(struct radeon_pm_clock_info) *
-@@ -2550,9 +2557,6 @@ static int radeon_atombios_parse_power_table_6(struct radeon_device *rdev)
- if (power_state->v2.ucNumDPMLevels) {
- for (j = 0; j < power_state->v2.ucNumDPMLevels; j++) {
- clock_array_index = power_state->v2.clockInfoIndex[j];
-- /* XXX this might be an inagua bug... */
-- if (clock_array_index >= clock_info_array->ucNumEntries)
-- continue;
- clock_info = (union pplib_clock_info *)
- &clock_info_array->clockInfo[clock_array_index * clock_info_array->ucEntrySize];
- valid = radeon_atombios_parse_pplib_clock_info(rdev,
-@@ -2574,6 +2578,7 @@ static int radeon_atombios_parse_power_table_6(struct radeon_device *rdev)
- non_clock_info);
- state_index++;
- }
-+ power_state_offset += 2 + power_state->v2.ucNumDPMLevels;
- }
- /* if multiple clock modes, mark the lowest as no display */
- for (i = 0; i < state_index; i++) {
-@@ -2620,7 +2625,9 @@ void radeon_atombios_get_power_modes(struct radeon_device *rdev)
- default:
- break;
- }
-- } else {
-+ }
-+
-+ if (state_index == 0) {
- rdev->pm.power_state = kzalloc(sizeof(struct radeon_power_state), GFP_KERNEL);
- if (rdev->pm.power_state) {
- rdev->pm.power_state[0].clock_info =
-diff --git a/drivers/gpu/drm/radeon/radeon_kms.c b/drivers/gpu/drm/radeon/radeon_kms.c
-index c75cb2c..c5b2765 100644
---- a/drivers/gpu/drm/radeon/radeon_kms.c
-+++ b/drivers/gpu/drm/radeon/radeon_kms.c
-@@ -50,9 +50,13 @@ int radeon_driver_unload_kms(struct drm_device *dev)
-
- if (rdev == NULL)
- return 0;
-+ if (rdev->rmmio == NULL)
-+ goto done_free;
- radeon_acpi_fini(rdev);
- radeon_modeset_fini(rdev);
- radeon_device_fini(rdev);
-+
-+done_free:
- kfree(rdev);
- dev->dev_private = NULL;
- return 0;
-diff --git a/drivers/gpu/drm/radeon/radeon_pm.c b/drivers/gpu/drm/radeon/radeon_pm.c
-index 338fd6a..788c64c 100644
---- a/drivers/gpu/drm/radeon/radeon_pm.c
-+++ b/drivers/gpu/drm/radeon/radeon_pm.c
-@@ -843,7 +843,11 @@ static int radeon_debugfs_pm_info(struct seq_file *m, void *data)
- struct radeon_device *rdev = dev->dev_private;
-
- seq_printf(m, "default engine clock: %u0 kHz\n", rdev->pm.default_sclk);
-- seq_printf(m, "current engine clock: %u0 kHz\n", radeon_get_engine_clock(rdev));
-+ /* radeon_get_engine_clock is not reliable on APUs so just print the current clock */
-+ if ((rdev->family >= CHIP_PALM) && (rdev->flags & RADEON_IS_IGP))
-+ seq_printf(m, "current engine clock: %u0 kHz\n", rdev->pm.current_sclk);
-+ else
-+ seq_printf(m, "current engine clock: %u0 kHz\n", radeon_get_engine_clock(rdev));
- seq_printf(m, "default memory clock: %u0 kHz\n", rdev->pm.default_mclk);
- if (rdev->asic->pm.get_memory_clock)
- seq_printf(m, "current memory clock: %u0 kHz\n", radeon_get_memory_clock(rdev));
-diff --git a/drivers/gpu/drm/radeon/radeon_ring.c b/drivers/gpu/drm/radeon/radeon_ring.c
-index 8d58e26..1ef5eaa 100644
---- a/drivers/gpu/drm/radeon/radeon_ring.c
-+++ b/drivers/gpu/drm/radeon/radeon_ring.c
-@@ -180,7 +180,8 @@ int radeon_ib_schedule(struct radeon_device *rdev, struct radeon_ib *ib,
- radeon_semaphore_free(rdev, &ib->semaphore, NULL);
- }
- /* if we can't remember our last VM flush then flush now! */
-- if (ib->vm && !ib->vm->last_flush) {
-+ /* XXX figure out why we have to flush for every IB */
-+ if (ib->vm /*&& !ib->vm->last_flush*/) {
- radeon_ring_vm_flush(rdev, ib->ring, ib->vm);
- }
- if (const_ib) {
-diff --git a/drivers/gpu/drm/radeon/rs600.c b/drivers/gpu/drm/radeon/rs600.c
-index 5a0fc74..46fa1b0 100644
---- a/drivers/gpu/drm/radeon/rs600.c
-+++ b/drivers/gpu/drm/radeon/rs600.c
-@@ -52,23 +52,59 @@ static const u32 crtc_offsets[2] =
- AVIVO_D2CRTC_H_TOTAL - AVIVO_D1CRTC_H_TOTAL
- };
-
-+static bool avivo_is_in_vblank(struct radeon_device *rdev, int crtc)
-+{
-+ if (RREG32(AVIVO_D1CRTC_STATUS + crtc_offsets[crtc]) & AVIVO_D1CRTC_V_BLANK)
-+ return true;
-+ else
-+ return false;
-+}
-+
-+static bool avivo_is_counter_moving(struct radeon_device *rdev, int crtc)
-+{
-+ u32 pos1, pos2;
-+
-+ pos1 = RREG32(AVIVO_D1CRTC_STATUS_POSITION + crtc_offsets[crtc]);
-+ pos2 = RREG32(AVIVO_D1CRTC_STATUS_POSITION + crtc_offsets[crtc]);
-+
-+ if (pos1 != pos2)
-+ return true;
-+ else
-+ return false;
-+}
-+
-+/**
-+ * avivo_wait_for_vblank - vblank wait asic callback.
-+ *
-+ * @rdev: radeon_device pointer
-+ * @crtc: crtc to wait for vblank on
-+ *
-+ * Wait for vblank on the requested crtc (r5xx-r7xx).
-+ */
- void avivo_wait_for_vblank(struct radeon_device *rdev, int crtc)
- {
-- int i;
-+ unsigned i = 0;
-
- if (crtc >= rdev->num_crtc)
- return;
-
-- if (RREG32(AVIVO_D1CRTC_CONTROL + crtc_offsets[crtc]) & AVIVO_CRTC_EN) {
-- for (i = 0; i < rdev->usec_timeout; i++) {
-- if (!(RREG32(AVIVO_D1CRTC_STATUS + crtc_offsets[crtc]) & AVIVO_D1CRTC_V_BLANK))
-+ if (!(RREG32(AVIVO_D1CRTC_CONTROL + crtc_offsets[crtc]) & AVIVO_CRTC_EN))
-+ return;
-+
-+ /* depending on when we hit vblank, we may be close to active; if so,
-+ * wait for another frame.
-+ */
-+ while (avivo_is_in_vblank(rdev, crtc)) {
-+ if (i++ % 100 == 0) {
-+ if (!avivo_is_counter_moving(rdev, crtc))
- break;
-- udelay(1);
- }
-- for (i = 0; i < rdev->usec_timeout; i++) {
-- if (RREG32(AVIVO_D1CRTC_STATUS + crtc_offsets[crtc]) & AVIVO_D1CRTC_V_BLANK)
-+ }
-+
-+ while (!avivo_is_in_vblank(rdev, crtc)) {
-+ if (i++ % 100 == 0) {
-+ if (!avivo_is_counter_moving(rdev, crtc))
- break;
-- udelay(1);
- }
- }
- }
-diff --git a/drivers/gpu/drm/radeon/rv515.c b/drivers/gpu/drm/radeon/rv515.c
-index 435ed35..ffcba73 100644
---- a/drivers/gpu/drm/radeon/rv515.c
-+++ b/drivers/gpu/drm/radeon/rv515.c
-@@ -303,8 +303,10 @@ void rv515_mc_stop(struct radeon_device *rdev, struct rv515_mc_save *save)
- tmp = RREG32(AVIVO_D1CRTC_CONTROL + crtc_offsets[i]);
- if (!(tmp & AVIVO_CRTC_DISP_READ_REQUEST_DISABLE)) {
- radeon_wait_for_vblank(rdev, i);
-+ WREG32(AVIVO_D1CRTC_UPDATE_LOCK + crtc_offsets[i], 1);
- tmp |= AVIVO_CRTC_DISP_READ_REQUEST_DISABLE;
- WREG32(AVIVO_D1CRTC_CONTROL + crtc_offsets[i], tmp);
-+ WREG32(AVIVO_D1CRTC_UPDATE_LOCK + crtc_offsets[i], 0);
- }
- /* wait for the next frame */
- frame_count = radeon_get_vblank_counter(rdev, i);
-@@ -313,6 +315,15 @@ void rv515_mc_stop(struct radeon_device *rdev, struct rv515_mc_save *save)
- break;
- udelay(1);
- }
-+
-+ /* XXX this is a hack to avoid strange behavior with EFI on certain systems */
-+ WREG32(AVIVO_D1CRTC_UPDATE_LOCK + crtc_offsets[i], 1);
-+ tmp = RREG32(AVIVO_D1CRTC_CONTROL + crtc_offsets[i]);
-+ tmp &= ~AVIVO_CRTC_EN;
-+ WREG32(AVIVO_D1CRTC_CONTROL + crtc_offsets[i], tmp);
-+ WREG32(AVIVO_D1CRTC_UPDATE_LOCK + crtc_offsets[i], 0);
-+ save->crtc_enabled[i] = false;
-+ /* ***** */
- } else {
- save->crtc_enabled[i] = false;
- }
-@@ -338,6 +349,22 @@ void rv515_mc_stop(struct radeon_device *rdev, struct rv515_mc_save *save)
- }
- /* wait for the MC to settle */
- udelay(100);
-+
-+ /* lock double buffered regs */
-+ for (i = 0; i < rdev->num_crtc; i++) {
-+ if (save->crtc_enabled[i]) {
-+ tmp = RREG32(AVIVO_D1GRPH_UPDATE + crtc_offsets[i]);
-+ if (!(tmp & AVIVO_D1GRPH_UPDATE_LOCK)) {
-+ tmp |= AVIVO_D1GRPH_UPDATE_LOCK;
-+ WREG32(AVIVO_D1GRPH_UPDATE + crtc_offsets[i], tmp);
-+ }
-+ tmp = RREG32(AVIVO_D1MODE_MASTER_UPDATE_LOCK + crtc_offsets[i]);
-+ if (!(tmp & 1)) {
-+ tmp |= 1;
-+ WREG32(AVIVO_D1MODE_MASTER_UPDATE_LOCK + crtc_offsets[i], tmp);
-+ }
-+ }
-+ }
- }
-
- void rv515_mc_resume(struct radeon_device *rdev, struct rv515_mc_save *save)
-@@ -348,7 +375,7 @@ void rv515_mc_resume(struct radeon_device *rdev, struct rv515_mc_save *save)
- /* update crtc base addresses */
- for (i = 0; i < rdev->num_crtc; i++) {
- if (rdev->family >= CHIP_RV770) {
-- if (i == 1) {
-+ if (i == 0) {
- WREG32(R700_D1GRPH_PRIMARY_SURFACE_ADDRESS_HIGH,
- upper_32_bits(rdev->mc.vram_start));
- WREG32(R700_D1GRPH_SECONDARY_SURFACE_ADDRESS_HIGH,
-@@ -367,6 +394,33 @@ void rv515_mc_resume(struct radeon_device *rdev, struct rv515_mc_save *save)
- }
- WREG32(R_000310_VGA_MEMORY_BASE_ADDRESS, (u32)rdev->mc.vram_start);
-
-+ /* unlock regs and wait for update */
-+ for (i = 0; i < rdev->num_crtc; i++) {
-+ if (save->crtc_enabled[i]) {
-+ tmp = RREG32(AVIVO_D1MODE_MASTER_UPDATE_MODE + crtc_offsets[i]);
-+ if ((tmp & 0x3) != 0) {
-+ tmp &= ~0x3;
-+ WREG32(AVIVO_D1MODE_MASTER_UPDATE_MODE + crtc_offsets[i], tmp);
-+ }
-+ tmp = RREG32(AVIVO_D1GRPH_UPDATE + crtc_offsets[i]);
-+ if (tmp & AVIVO_D1GRPH_UPDATE_LOCK) {
-+ tmp &= ~AVIVO_D1GRPH_UPDATE_LOCK;
-+ WREG32(AVIVO_D1GRPH_UPDATE + crtc_offsets[i], tmp);
-+ }
-+ tmp = RREG32(AVIVO_D1MODE_MASTER_UPDATE_LOCK + crtc_offsets[i]);
-+ if (tmp & 1) {
-+ tmp &= ~1;
-+ WREG32(AVIVO_D1MODE_MASTER_UPDATE_LOCK + crtc_offsets[i], tmp);
-+ }
-+ for (j = 0; j < rdev->usec_timeout; j++) {
-+ tmp = RREG32(AVIVO_D1GRPH_UPDATE + crtc_offsets[i]);
-+ if ((tmp & AVIVO_D1GRPH_SURFACE_UPDATE_PENDING) == 0)
-+ break;
-+ udelay(1);
-+ }
-+ }
-+ }
-+
- if (rdev->family >= CHIP_R600) {
- /* unblackout the MC */
- if (rdev->family >= CHIP_RV770)
-diff --git a/drivers/gpu/drm/radeon/si.c b/drivers/gpu/drm/radeon/si.c
-index bafbe32..3dd7ecc 100644
---- a/drivers/gpu/drm/radeon/si.c
-+++ b/drivers/gpu/drm/radeon/si.c
-@@ -1463,7 +1463,7 @@ static void si_select_se_sh(struct radeon_device *rdev,
- u32 data = INSTANCE_BROADCAST_WRITES;
-
- if ((se_num == 0xffffffff) && (sh_num == 0xffffffff))
-- data = SH_BROADCAST_WRITES | SE_BROADCAST_WRITES;
-+ data |= SH_BROADCAST_WRITES | SE_BROADCAST_WRITES;
- else if (se_num == 0xffffffff)
- data |= SE_BROADCAST_WRITES | SH_INDEX(sh_num);
- else if (sh_num == 0xffffffff)
-@@ -1765,6 +1765,7 @@ static void si_gpu_init(struct radeon_device *rdev)
-
- WREG32(GB_ADDR_CONFIG, gb_addr_config);
- WREG32(DMIF_ADDR_CONFIG, gb_addr_config);
-+ WREG32(DMIF_ADDR_CALC, gb_addr_config);
- WREG32(HDP_ADDR_CONFIG, gb_addr_config);
- WREG32(DMA_TILING_CONFIG + DMA0_REGISTER_OFFSET, gb_addr_config);
- WREG32(DMA_TILING_CONFIG + DMA1_REGISTER_OFFSET, gb_addr_config);
-diff --git a/drivers/gpu/drm/radeon/sid.h b/drivers/gpu/drm/radeon/sid.h
-index 23fc08f..f84cff0 100644
---- a/drivers/gpu/drm/radeon/sid.h
-+++ b/drivers/gpu/drm/radeon/sid.h
-@@ -65,6 +65,8 @@
-
- #define DMIF_ADDR_CONFIG 0xBD4
-
-+#define DMIF_ADDR_CALC 0xC00
-+
- #define SRBM_STATUS 0xE50
- #define GRBM_RQ_PENDING (1 << 5)
- #define VMC_BUSY (1 << 8)
-diff --git a/drivers/gpu/drm/tilcdc/tilcdc_drv.c b/drivers/gpu/drm/tilcdc/tilcdc_drv.c
-index c5b592d..bfac582 100644
---- a/drivers/gpu/drm/tilcdc/tilcdc_drv.c
-+++ b/drivers/gpu/drm/tilcdc/tilcdc_drv.c
-@@ -75,7 +75,7 @@ static int modeset_init(struct drm_device *dev)
- mod->funcs->modeset_init(mod, dev);
- }
-
-- if ((priv->num_encoders = 0) || (priv->num_connectors == 0)) {
-+ if ((priv->num_encoders == 0) || (priv->num_connectors == 0)) {
- /* oh nos! */
- dev_err(dev->dev, "no encoders/connectors found\n");
- return -ENXIO;
-diff --git a/drivers/gpu/drm/udl/udl_gem.c b/drivers/gpu/drm/udl/udl_gem.c
-index 3816270..ef034fa 100644
---- a/drivers/gpu/drm/udl/udl_gem.c
-+++ b/drivers/gpu/drm/udl/udl_gem.c
-@@ -303,6 +303,8 @@ struct drm_gem_object *udl_gem_prime_import(struct drm_device *dev,
- if (IS_ERR(attach))
- return ERR_CAST(attach);
-
-+ get_dma_buf(dma_buf);
-+
- sg = dma_buf_map_attachment(attach, DMA_BIDIRECTIONAL);
- if (IS_ERR(sg)) {
- ret = PTR_ERR(sg);
-@@ -322,5 +324,7 @@ fail_unmap:
- dma_buf_unmap_attachment(attach, sg, DMA_BIDIRECTIONAL);
- fail_detach:
- dma_buf_detach(dma_buf, attach);
-+ dma_buf_put(dma_buf);
-+
- return ERR_PTR(ret);
- }
-diff --git a/drivers/infiniband/hw/cxgb4/qp.c b/drivers/infiniband/hw/cxgb4/qp.c
-index 70b1808..ed49ab3 100644
---- a/drivers/infiniband/hw/cxgb4/qp.c
-+++ b/drivers/infiniband/hw/cxgb4/qp.c
-@@ -100,6 +100,16 @@ static int alloc_host_sq(struct c4iw_rdev *rdev, struct t4_sq *sq)
- return 0;
- }
-
-+static int alloc_sq(struct c4iw_rdev *rdev, struct t4_sq *sq, int user)
-+{
-+ int ret = -ENOSYS;
-+ if (user)
-+ ret = alloc_oc_sq(rdev, sq);
-+ if (ret)
-+ ret = alloc_host_sq(rdev, sq);
-+ return ret;
-+}
-+
- static int destroy_qp(struct c4iw_rdev *rdev, struct t4_wq *wq,
- struct c4iw_dev_ucontext *uctx)
- {
-@@ -168,18 +178,9 @@ static int create_qp(struct c4iw_rdev *rdev, struct t4_wq *wq,
- goto free_sw_rq;
- }
-
-- if (user) {
-- ret = alloc_oc_sq(rdev, &wq->sq);
-- if (ret)
-- goto free_hwaddr;
--
-- ret = alloc_host_sq(rdev, &wq->sq);
-- if (ret)
-- goto free_sq;
-- } else
-- ret = alloc_host_sq(rdev, &wq->sq);
-- if (ret)
-- goto free_hwaddr;
-+ ret = alloc_sq(rdev, &wq->sq, user);
-+ if (ret)
-+ goto free_hwaddr;
- memset(wq->sq.queue, 0, wq->sq.memsize);
- dma_unmap_addr_set(&wq->sq, mapping, wq->sq.dma_addr);
-
-diff --git a/drivers/iommu/amd_iommu.c b/drivers/iommu/amd_iommu.c
-index b287ca3..cbb1645 100644
---- a/drivers/iommu/amd_iommu.c
-+++ b/drivers/iommu/amd_iommu.c
-@@ -3947,6 +3947,9 @@ static struct irq_remap_table *get_irq_table(u16 devid, bool ioapic)
- if (!table)
- goto out;
-
-+ /* Initialize table spin-lock */
-+ spin_lock_init(&table->lock);
-+
- if (ioapic)
- /* Keep the first 32 indexes free for IOAPIC interrupts */
- table->min_index = 32;
-diff --git a/drivers/net/ethernet/ibm/ibmveth.c b/drivers/net/ethernet/ibm/ibmveth.c
-index c859771..f46dbef 100644
---- a/drivers/net/ethernet/ibm/ibmveth.c
-+++ b/drivers/net/ethernet/ibm/ibmveth.c
-@@ -1324,7 +1324,7 @@ static const struct net_device_ops ibmveth_netdev_ops = {
-
- static int ibmveth_probe(struct vio_dev *dev, const struct vio_device_id *id)
- {
-- int rc, i;
-+ int rc, i, mac_len;
- struct net_device *netdev;
- struct ibmveth_adapter *adapter;
- unsigned char *mac_addr_p;
-@@ -1334,11 +1334,19 @@ static int ibmveth_probe(struct vio_dev *dev, const struct vio_device_id *id)
- dev->unit_address);
-
- mac_addr_p = (unsigned char *)vio_get_attribute(dev, VETH_MAC_ADDR,
-- NULL);
-+ &mac_len);
- if (!mac_addr_p) {
- dev_err(&dev->dev, "Can't find VETH_MAC_ADDR attribute\n");
- return -EINVAL;
- }
-+ /* Workaround for old/broken pHyp */
-+ if (mac_len == 8)
-+ mac_addr_p += 2;
-+ else if (mac_len != 6) {
-+ dev_err(&dev->dev, "VETH_MAC_ADDR attribute wrong len %d\n",
-+ mac_len);
-+ return -EINVAL;
-+ }
-
- mcastFilterSize_p = (unsigned int *)vio_get_attribute(dev,
- VETH_MCAST_FILTER_SIZE, NULL);
-@@ -1363,17 +1371,6 @@ static int ibmveth_probe(struct vio_dev *dev, const struct vio_device_id *id)
-
- netif_napi_add(netdev, &adapter->napi, ibmveth_poll, 16);
-
-- /*
-- * Some older boxes running PHYP non-natively have an OF that returns
-- * a 8-byte local-mac-address field (and the first 2 bytes have to be
-- * ignored) while newer boxes' OF return a 6-byte field. Note that
-- * IEEE 1275 specifies that local-mac-address must be a 6-byte field.
-- * The RPA doc specifies that the first byte must be 10b, so we'll
-- * just look for it to solve this 8 vs. 6 byte field issue
-- */
-- if ((*mac_addr_p & 0x3) != 0x02)
-- mac_addr_p += 2;
--
- adapter->mac_addr = 0;
- memcpy(&adapter->mac_addr, mac_addr_p, 6);
-
-diff --git a/drivers/net/ethernet/realtek/r8169.c b/drivers/net/ethernet/realtek/r8169.c
-index 4ecbe64..15ba8c4 100644
---- a/drivers/net/ethernet/realtek/r8169.c
-+++ b/drivers/net/ethernet/realtek/r8169.c
-@@ -5787,6 +5787,14 @@ static netdev_tx_t rtl8169_start_xmit(struct sk_buff *skb,
- goto err_stop_0;
- }
-
-+ /* 8168evl does not automatically pad to minimum length. */
-+ if (unlikely(tp->mac_version == RTL_GIGA_MAC_VER_34 &&
-+ skb->len < ETH_ZLEN)) {
-+ if (skb_padto(skb, ETH_ZLEN))
-+ goto err_update_stats;
-+ skb_put(skb, ETH_ZLEN - skb->len);
-+ }
-+
- if (unlikely(le32_to_cpu(txd->opts1) & DescOwn))
- goto err_stop_0;
-
-@@ -5858,6 +5866,7 @@ err_dma_1:
- rtl8169_unmap_tx_skb(d, tp->tx_skb + entry, txd);
- err_dma_0:
- dev_kfree_skb(skb);
-+err_update_stats:
- dev->stats.tx_dropped++;
- return NETDEV_TX_OK;
-
-diff --git a/drivers/net/usb/cdc_ether.c b/drivers/net/usb/cdc_ether.c
-index 57136dc..299c53b 100644
---- a/drivers/net/usb/cdc_ether.c
-+++ b/drivers/net/usb/cdc_ether.c
-@@ -615,6 +615,13 @@ static const struct usb_device_id products [] = {
- .driver_info = 0,
- },
-
-+/* Dell Wireless 5804 (Novatel E371) - handled by qmi_wwan */
-+{
-+ USB_DEVICE_AND_INTERFACE_INFO(DELL_VENDOR_ID, 0x819b, USB_CLASS_COMM,
-+ USB_CDC_SUBCLASS_ETHERNET, USB_CDC_PROTO_NONE),
-+ .driver_info = 0,
-+},
-+
- /* AnyDATA ADU960S - handled by qmi_wwan */
- {
- USB_DEVICE_AND_INTERFACE_INFO(0x16d5, 0x650a, USB_CLASS_COMM,
-diff --git a/drivers/net/usb/qmi_wwan.c b/drivers/net/usb/qmi_wwan.c
-index 2a3579f..a7cafe4 100644
---- a/drivers/net/usb/qmi_wwan.c
-+++ b/drivers/net/usb/qmi_wwan.c
-@@ -496,6 +496,13 @@ static const struct usb_device_id products[] = {
- USB_CDC_PROTO_NONE),
- .driver_info = (unsigned long)&qmi_wwan_info,
- },
-+ { /* Dell Wireless 5804 (Novatel E371) */
-+ USB_DEVICE_AND_INTERFACE_INFO(0x413C, 0x819b,
-+ USB_CLASS_COMM,
-+ USB_CDC_SUBCLASS_ETHERNET,
-+ USB_CDC_PROTO_NONE),
-+ .driver_info = (unsigned long)&qmi_wwan_info,
-+ },
- { /* ADU960S */
- USB_DEVICE_AND_INTERFACE_INFO(0x16d5, 0x650a,
- USB_CLASS_COMM,
-diff --git a/drivers/pci/bus.c b/drivers/pci/bus.c
-index 8647dc6..f9c61fb 100644
---- a/drivers/pci/bus.c
-+++ b/drivers/pci/bus.c
-@@ -174,6 +174,7 @@ int pci_bus_add_device(struct pci_dev *dev)
- * Can not put in pci_device_add yet because resources
- * are not assigned yet for some devices.
- */
-+ pci_fixup_device(pci_fixup_final, dev);
- pci_create_sysfs_dev_files(dev);
-
- dev->match_driver = true;
-diff --git a/drivers/pci/probe.c b/drivers/pci/probe.c
-index b494066..5427787 100644
---- a/drivers/pci/probe.c
-+++ b/drivers/pci/probe.c
-@@ -1339,7 +1339,6 @@ void pci_device_add(struct pci_dev *dev, struct pci_bus *bus)
- list_add_tail(&dev->bus_list, &bus->devices);
- up_write(&pci_bus_sem);
-
-- pci_fixup_device(pci_fixup_final, dev);
- ret = pcibios_add_device(dev);
- WARN_ON(ret < 0);
-
-diff --git a/drivers/pwm/pwm-spear.c b/drivers/pwm/pwm-spear.c
-index 69a2d9e..3223b57 100644
---- a/drivers/pwm/pwm-spear.c
-+++ b/drivers/pwm/pwm-spear.c
-@@ -143,7 +143,7 @@ static int spear_pwm_enable(struct pwm_chip *chip, struct pwm_device *pwm)
- u32 val;
-
- rc = clk_enable(pc->clk);
-- if (!rc)
-+ if (rc)
- return rc;
-
- val = spear_pwm_readl(pc, pwm->hwpwm, PWMCR);
-@@ -209,12 +209,12 @@ static int spear_pwm_probe(struct platform_device *pdev)
- pc->chip.npwm = NUM_PWM;
-
- ret = clk_prepare(pc->clk);
-- if (!ret)
-+ if (ret)
- return ret;
-
- if (of_device_is_compatible(np, "st,spear1340-pwm")) {
- ret = clk_enable(pc->clk);
-- if (!ret) {
-+ if (ret) {
- clk_unprepare(pc->clk);
- return ret;
- }
-diff --git a/drivers/remoteproc/Kconfig b/drivers/remoteproc/Kconfig
-index c6d77e2..be6e121 100644
---- a/drivers/remoteproc/Kconfig
-+++ b/drivers/remoteproc/Kconfig
-@@ -6,6 +6,7 @@ config REMOTEPROC
- depends on HAS_DMA
- select FW_LOADER
- select VIRTIO
-+ select VIRTUALIZATION
-
- config OMAP_REMOTEPROC
- tristate "OMAP remoteproc support"
-diff --git a/drivers/rpmsg/Kconfig b/drivers/rpmsg/Kconfig
-index f6e0ea6..69a2193 100644
---- a/drivers/rpmsg/Kconfig
-+++ b/drivers/rpmsg/Kconfig
-@@ -4,5 +4,6 @@ menu "Rpmsg drivers"
- config RPMSG
- tristate
- select VIRTIO
-+ select VIRTUALIZATION
-
- endmenu
-diff --git a/fs/autofs4/expire.c b/fs/autofs4/expire.c
-index 01443ce..13ddec9 100644
---- a/fs/autofs4/expire.c
-+++ b/fs/autofs4/expire.c
-@@ -61,15 +61,6 @@ static int autofs4_mount_busy(struct vfsmount *mnt, struct dentry *dentry)
- /* This is an autofs submount, we can't expire it */
- if (autofs_type_indirect(sbi->type))
- goto done;
--
-- /*
-- * Otherwise it's an offset mount and we need to check
-- * if we can umount its mount, if there is one.
-- */
-- if (!d_mountpoint(path.dentry)) {
-- status = 0;
-- goto done;
-- }
- }
-
- /* Update the expiry counter if fs is busy */
-diff --git a/fs/btrfs/delayed-ref.c b/fs/btrfs/delayed-ref.c
-index b7a0641..116abec 100644
---- a/fs/btrfs/delayed-ref.c
-+++ b/fs/btrfs/delayed-ref.c
-@@ -40,16 +40,19 @@ struct kmem_cache *btrfs_delayed_extent_op_cachep;
- * compare two delayed tree backrefs with same bytenr and type
- */
- static int comp_tree_refs(struct btrfs_delayed_tree_ref *ref2,
-- struct btrfs_delayed_tree_ref *ref1)
-+ struct btrfs_delayed_tree_ref *ref1, int type)
- {
-- if (ref1->root < ref2->root)
-- return -1;
-- if (ref1->root > ref2->root)
-- return 1;
-- if (ref1->parent < ref2->parent)
-- return -1;
-- if (ref1->parent > ref2->parent)
-- return 1;
-+ if (type == BTRFS_TREE_BLOCK_REF_KEY) {
-+ if (ref1->root < ref2->root)
-+ return -1;
-+ if (ref1->root > ref2->root)
-+ return 1;
-+ } else {
-+ if (ref1->parent < ref2->parent)
-+ return -1;
-+ if (ref1->parent > ref2->parent)
-+ return 1;
-+ }
- return 0;
- }
-
-@@ -113,7 +116,8 @@ static int comp_entry(struct btrfs_delayed_ref_node *ref2,
- if (ref1->type == BTRFS_TREE_BLOCK_REF_KEY ||
- ref1->type == BTRFS_SHARED_BLOCK_REF_KEY) {
- return comp_tree_refs(btrfs_delayed_node_to_tree_ref(ref2),
-- btrfs_delayed_node_to_tree_ref(ref1));
-+ btrfs_delayed_node_to_tree_ref(ref1),
-+ ref1->type);
- } else if (ref1->type == BTRFS_EXTENT_DATA_REF_KEY ||
- ref1->type == BTRFS_SHARED_DATA_REF_KEY) {
- return comp_data_refs(btrfs_delayed_node_to_data_ref(ref2),
-diff --git a/fs/btrfs/inode.c b/fs/btrfs/inode.c
-index 09c58a3..cc6ce3e 100644
---- a/fs/btrfs/inode.c
-+++ b/fs/btrfs/inode.c
-@@ -6502,7 +6502,9 @@ out:
- * block must be cow'd
- */
- static noinline int can_nocow_odirect(struct btrfs_trans_handle *trans,
-- struct inode *inode, u64 offset, u64 len)
-+ struct inode *inode, u64 offset, u64 *len,
-+ u64 *orig_start, u64 *orig_block_len,
-+ u64 *ram_bytes)
- {
- struct btrfs_path *path;
- int ret;
-@@ -6559,8 +6561,12 @@ static noinline int can_nocow_odirect(struct btrfs_trans_handle *trans,
- disk_bytenr = btrfs_file_extent_disk_bytenr(leaf, fi);
- backref_offset = btrfs_file_extent_offset(leaf, fi);
-
-+ *orig_start = key.offset - backref_offset;
-+ *orig_block_len = btrfs_file_extent_disk_num_bytes(leaf, fi);
-+ *ram_bytes = btrfs_file_extent_ram_bytes(leaf, fi);
-+
- extent_end = key.offset + btrfs_file_extent_num_bytes(leaf, fi);
-- if (extent_end < offset + len) {
-+ if (extent_end < offset + *len) {
- /* extent doesn't include our full range, must cow */
- goto out;
- }
-@@ -6584,13 +6590,14 @@ static noinline int can_nocow_odirect(struct btrfs_trans_handle *trans,
- */
- disk_bytenr += backref_offset;
- disk_bytenr += offset - key.offset;
-- num_bytes = min(offset + len, extent_end) - offset;
-+ num_bytes = min(offset + *len, extent_end) - offset;
- if (csum_exist_in_range(root, disk_bytenr, num_bytes))
- goto out;
- /*
- * all of the above have passed, it is safe to overwrite this extent
- * without cow
- */
-+ *len = num_bytes;
- ret = 1;
- out:
- btrfs_free_path(path);
-@@ -6789,7 +6796,7 @@ static int btrfs_get_blocks_direct(struct inode *inode, sector_t iblock,
- em->block_start != EXTENT_MAP_HOLE)) {
- int type;
- int ret;
-- u64 block_start;
-+ u64 block_start, orig_start, orig_block_len, ram_bytes;
-
- if (test_bit(EXTENT_FLAG_PREALLOC, &em->flags))
- type = BTRFS_ORDERED_PREALLOC;
-@@ -6807,10 +6814,8 @@ static int btrfs_get_blocks_direct(struct inode *inode, sector_t iblock,
- if (IS_ERR(trans))
- goto must_cow;
-
-- if (can_nocow_odirect(trans, inode, start, len) == 1) {
-- u64 orig_start = em->orig_start;
-- u64 orig_block_len = em->orig_block_len;
--
-+ if (can_nocow_odirect(trans, inode, start, &len, &orig_start,
-+ &orig_block_len, &ram_bytes) == 1) {
- if (type == BTRFS_ORDERED_PREALLOC) {
- free_extent_map(em);
- em = create_pinned_em(inode, start, len,
-diff --git a/fs/ext4/resize.c b/fs/ext4/resize.c
-index 1357260..3beae6a 100644
---- a/fs/ext4/resize.c
-+++ b/fs/ext4/resize.c
-@@ -1882,6 +1882,10 @@ retry:
- return 0;
-
- ext4_get_group_no_and_offset(sb, n_blocks_count - 1, &n_group, &offset);
-+ if (n_group > (0xFFFFFFFFUL / EXT4_INODES_PER_GROUP(sb))) {
-+ ext4_warning(sb, "resize would cause inodes_count overflow");
-+ return -EINVAL;
-+ }
- ext4_get_group_no_and_offset(sb, o_blocks_count - 1, &o_group, &offset);
-
- n_desc_blocks = num_desc_blocks(sb, n_group + 1);
-diff --git a/fs/hugetlbfs/inode.c b/fs/hugetlbfs/inode.c
-index 523464e..a3f868a 100644
---- a/fs/hugetlbfs/inode.c
-+++ b/fs/hugetlbfs/inode.c
-@@ -909,11 +909,8 @@ static int can_do_hugetlb_shm(void)
-
- static int get_hstate_idx(int page_size_log)
- {
-- struct hstate *h;
-+ struct hstate *h = hstate_sizelog(page_size_log);
-
-- if (!page_size_log)
-- return default_hstate_idx;
-- h = size_to_hstate(1 << page_size_log);
- if (!h)
- return -1;
- return h - hstates;
-@@ -929,9 +926,12 @@ static struct dentry_operations anon_ops = {
- .d_dname = hugetlb_dname
- };
-
--struct file *hugetlb_file_setup(const char *name, unsigned long addr,
-- size_t size, vm_flags_t acctflag,
-- struct user_struct **user,
-+/*
-+ * Note that size should be aligned to proper hugepage size in caller side,
-+ * otherwise hugetlb_reserve_pages reserves one less hugepages than intended.
-+ */
-+struct file *hugetlb_file_setup(const char *name, size_t size,
-+ vm_flags_t acctflag, struct user_struct **user,
- int creat_flags, int page_size_log)
- {
- struct file *file = ERR_PTR(-ENOMEM);
-@@ -939,8 +939,6 @@ struct file *hugetlb_file_setup(const char *name, unsigned long addr,
- struct path path;
- struct super_block *sb;
- struct qstr quick_string;
-- struct hstate *hstate;
-- unsigned long num_pages;
- int hstate_idx;
-
- hstate_idx = get_hstate_idx(page_size_log);
-@@ -980,12 +978,10 @@ struct file *hugetlb_file_setup(const char *name, unsigned long addr,
- if (!inode)
- goto out_dentry;
-
-- hstate = hstate_inode(inode);
-- size += addr & ~huge_page_mask(hstate);
-- num_pages = ALIGN(size, huge_page_size(hstate)) >>
-- huge_page_shift(hstate);
- file = ERR_PTR(-ENOMEM);
-- if (hugetlb_reserve_pages(inode, 0, num_pages, NULL, acctflag))
-+ if (hugetlb_reserve_pages(inode, 0,
-+ size >> huge_page_shift(hstate_inode(inode)), NULL,
-+ acctflag))
- goto out_inode;
-
- d_instantiate(path.dentry, inode);
-diff --git a/fs/nfs/nfs4proc.c b/fs/nfs/nfs4proc.c
-index c7856a1..0086401 100644
---- a/fs/nfs/nfs4proc.c
-+++ b/fs/nfs/nfs4proc.c
-@@ -4553,9 +4553,9 @@ static int nfs4_proc_unlck(struct nfs4_state *state, int cmd, struct file_lock *
- if (status != 0)
- goto out;
- /* Is this a delegated lock? */
-- if (test_bit(NFS_DELEGATED_STATE, &state->flags))
-- goto out;
- lsp = request->fl_u.nfs4_fl.owner;
-+ if (test_bit(NFS_LOCK_INITIALIZED, &lsp->ls_flags) == 0)
-+ goto out;
- seqid = nfs_alloc_seqid(&lsp->ls_seqid, GFP_KERNEL);
- status = -ENOMEM;
- if (seqid == NULL)
-diff --git a/include/drm/drmP.h b/include/drm/drmP.h
-index 2d94d74..f1ce786 100644
---- a/include/drm/drmP.h
-+++ b/include/drm/drmP.h
-@@ -1593,9 +1593,8 @@ extern void drm_prime_gem_destroy(struct drm_gem_object *obj, struct sg_table *s
-
- void drm_prime_init_file_private(struct drm_prime_file_private *prime_fpriv);
- void drm_prime_destroy_file_private(struct drm_prime_file_private *prime_fpriv);
--int drm_prime_add_imported_buf_handle(struct drm_prime_file_private *prime_fpriv, struct dma_buf *dma_buf, uint32_t handle);
--int drm_prime_lookup_imported_buf_handle(struct drm_prime_file_private *prime_fpriv, struct dma_buf *dma_buf, uint32_t *handle);
--void drm_prime_remove_imported_buf_handle(struct drm_prime_file_private *prime_fpriv, struct dma_buf *dma_buf);
-+int drm_prime_lookup_buf_handle(struct drm_prime_file_private *prime_fpriv, struct dma_buf *dma_buf, uint32_t *handle);
-+void drm_prime_remove_buf_handle(struct drm_prime_file_private *prime_fpriv, struct dma_buf *dma_buf);
-
- int drm_prime_add_dma_buf(struct drm_device *dev, struct drm_gem_object *obj);
- int drm_prime_lookup_obj(struct drm_device *dev, struct dma_buf *buf,
-diff --git a/include/drm/drm_pciids.h b/include/drm/drm_pciids.h
-index 918e8fe..c2af598 100644
---- a/include/drm/drm_pciids.h
-+++ b/include/drm/drm_pciids.h
-@@ -240,6 +240,7 @@
- {0x1002, 0x6819, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_PITCAIRN|RADEON_NEW_MEMMAP}, \
- {0x1002, 0x6820, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_VERDE|RADEON_IS_MOBILITY|RADEON_NEW_MEMMAP}, \
- {0x1002, 0x6821, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_VERDE|RADEON_IS_MOBILITY|RADEON_NEW_MEMMAP}, \
-+ {0x1002, 0x6822, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_VERDE|RADEON_IS_MOBILITY|RADEON_NEW_MEMMAP}, \
- {0x1002, 0x6823, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_VERDE|RADEON_IS_MOBILITY|RADEON_NEW_MEMMAP}, \
- {0x1002, 0x6824, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_VERDE|RADEON_IS_MOBILITY|RADEON_NEW_MEMMAP}, \
- {0x1002, 0x6825, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_VERDE|RADEON_IS_MOBILITY|RADEON_NEW_MEMMAP}, \
-@@ -247,11 +248,13 @@
- {0x1002, 0x6827, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_VERDE|RADEON_IS_MOBILITY|RADEON_NEW_MEMMAP}, \
- {0x1002, 0x6828, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_VERDE|RADEON_NEW_MEMMAP}, \
- {0x1002, 0x6829, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_VERDE|RADEON_NEW_MEMMAP}, \
-+ {0x1002, 0x682A, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_VERDE|RADEON_IS_MOBILITY|RADEON_NEW_MEMMAP}, \
- {0x1002, 0x682B, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_VERDE|RADEON_IS_MOBILITY|RADEON_NEW_MEMMAP}, \
- {0x1002, 0x682D, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_VERDE|RADEON_IS_MOBILITY|RADEON_NEW_MEMMAP}, \
- {0x1002, 0x682F, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_VERDE|RADEON_IS_MOBILITY|RADEON_NEW_MEMMAP}, \
- {0x1002, 0x6830, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_VERDE|RADEON_IS_MOBILITY|RADEON_NEW_MEMMAP}, \
- {0x1002, 0x6831, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_VERDE|RADEON_IS_MOBILITY|RADEON_NEW_MEMMAP}, \
-+ {0x1002, 0x6835, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_VERDE|RADEON_NEW_MEMMAP}, \
- {0x1002, 0x6837, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_VERDE|RADEON_NEW_MEMMAP}, \
- {0x1002, 0x6838, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_VERDE|RADEON_NEW_MEMMAP}, \
- {0x1002, 0x6839, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_VERDE|RADEON_NEW_MEMMAP}, \
-@@ -603,6 +606,8 @@
- {0x1002, 0x9999, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_ARUBA|RADEON_IS_MOBILITY|RADEON_NEW_MEMMAP|RADEON_IS_IGP}, \
- {0x1002, 0x999A, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_ARUBA|RADEON_IS_MOBILITY|RADEON_NEW_MEMMAP|RADEON_IS_IGP}, \
- {0x1002, 0x999B, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_ARUBA|RADEON_IS_MOBILITY|RADEON_NEW_MEMMAP|RADEON_IS_IGP}, \
-+ {0x1002, 0x999C, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_ARUBA|RADEON_NEW_MEMMAP|RADEON_IS_IGP}, \
-+ {0x1002, 0x999D, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_ARUBA|RADEON_NEW_MEMMAP|RADEON_IS_IGP}, \
- {0x1002, 0x99A0, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_ARUBA|RADEON_IS_MOBILITY|RADEON_NEW_MEMMAP|RADEON_IS_IGP}, \
- {0x1002, 0x99A2, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_ARUBA|RADEON_IS_MOBILITY|RADEON_NEW_MEMMAP|RADEON_IS_IGP}, \
- {0x1002, 0x99A4, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_ARUBA|RADEON_NEW_MEMMAP|RADEON_IS_IGP}, \
-diff --git a/include/linux/blkdev.h b/include/linux/blkdev.h
-index 78feda9..33f358f 100644
---- a/include/linux/blkdev.h
-+++ b/include/linux/blkdev.h
-@@ -838,7 +838,7 @@ static inline unsigned int blk_queue_get_max_sectors(struct request_queue *q,
- unsigned int cmd_flags)
- {
- if (unlikely(cmd_flags & REQ_DISCARD))
-- return q->limits.max_discard_sectors;
-+ return min(q->limits.max_discard_sectors, UINT_MAX >> 9);
-
- if (unlikely(cmd_flags & REQ_WRITE_SAME))
- return q->limits.max_write_same_sectors;
-diff --git a/include/linux/hugetlb.h b/include/linux/hugetlb.h
-index 16e4e9a..df1ff7c 100644
---- a/include/linux/hugetlb.h
-+++ b/include/linux/hugetlb.h
-@@ -185,8 +185,7 @@ static inline struct hugetlbfs_sb_info *HUGETLBFS_SB(struct super_block *sb)
-
- extern const struct file_operations hugetlbfs_file_operations;
- extern const struct vm_operations_struct hugetlb_vm_ops;
--struct file *hugetlb_file_setup(const char *name, unsigned long addr,
-- size_t size, vm_flags_t acct,
-+struct file *hugetlb_file_setup(const char *name, size_t size, vm_flags_t acct,
- struct user_struct **user, int creat_flags,
- int page_size_log);
-
-@@ -205,8 +204,8 @@ static inline int is_file_hugepages(struct file *file)
-
- #define is_file_hugepages(file) 0
- static inline struct file *
--hugetlb_file_setup(const char *name, unsigned long addr, size_t size,
-- vm_flags_t acctflag, struct user_struct **user, int creat_flags,
-+hugetlb_file_setup(const char *name, size_t size, vm_flags_t acctflag,
-+ struct user_struct **user, int creat_flags,
- int page_size_log)
- {
- return ERR_PTR(-ENOSYS);
-@@ -284,6 +283,13 @@ static inline struct hstate *hstate_file(struct file *f)
- return hstate_inode(file_inode(f));
- }
-
-+static inline struct hstate *hstate_sizelog(int page_size_log)
-+{
-+ if (!page_size_log)
-+ return &default_hstate;
-+ return size_to_hstate(1 << page_size_log);
-+}
-+
- static inline struct hstate *hstate_vma(struct vm_area_struct *vma)
- {
- return hstate_file(vma->vm_file);
-@@ -348,11 +354,12 @@ static inline int hstate_index(struct hstate *h)
- return h - hstates;
- }
-
--#else
-+#else /* CONFIG_HUGETLB_PAGE */
- struct hstate {};
- #define alloc_huge_page_node(h, nid) NULL
- #define alloc_bootmem_huge_page(h) NULL
- #define hstate_file(f) NULL
-+#define hstate_sizelog(s) NULL
- #define hstate_vma(v) NULL
- #define hstate_inode(i) NULL
- #define huge_page_size(h) PAGE_SIZE
-@@ -367,6 +374,6 @@ static inline unsigned int pages_per_huge_page(struct hstate *h)
- }
- #define hstate_index_to_shift(index) 0
- #define hstate_index(h) 0
--#endif
-+#endif /* CONFIG_HUGETLB_PAGE */
-
- #endif /* _LINUX_HUGETLB_H */
-diff --git a/ipc/shm.c b/ipc/shm.c
-index 8247c49..34af1fe 100644
---- a/ipc/shm.c
-+++ b/ipc/shm.c
-@@ -491,10 +491,14 @@ static int newseg(struct ipc_namespace *ns, struct ipc_params *params)
-
- sprintf (name, "SYSV%08x", key);
- if (shmflg & SHM_HUGETLB) {
-+ struct hstate *hs = hstate_sizelog((shmflg >> SHM_HUGE_SHIFT)
-+ & SHM_HUGE_MASK);
-+ size_t hugesize = ALIGN(size, huge_page_size(hs));
-+
- /* hugetlb_file_setup applies strict accounting */
- if (shmflg & SHM_NORESERVE)
- acctflag = VM_NORESERVE;
-- file = hugetlb_file_setup(name, 0, size, acctflag,
-+ file = hugetlb_file_setup(name, hugesize, acctflag,
- &shp->mlock_user, HUGETLB_SHMFS_INODE,
- (shmflg >> SHM_HUGE_SHIFT) & SHM_HUGE_MASK);
- } else {
-diff --git a/kernel/Makefile b/kernel/Makefile
-index bbde5f1..5a51e6c 100644
---- a/kernel/Makefile
-+++ b/kernel/Makefile
-@@ -175,7 +175,7 @@ signing_key.priv signing_key.x509: x509.genkey
- openssl req -new -nodes -utf8 -$(CONFIG_MODULE_SIG_HASH) -days 36500 \
- -batch -x509 -config x509.genkey \
- -outform DER -out signing_key.x509 \
-- -keyout signing_key.priv
-+ -keyout signing_key.priv 2>&1
- @echo "###"
- @echo "### Key pair generated."
- @echo "###"
-diff --git a/kernel/audit_tree.c b/kernel/audit_tree.c
-index 642a89c..a291aa2 100644
---- a/kernel/audit_tree.c
-+++ b/kernel/audit_tree.c
-@@ -617,9 +617,9 @@ void audit_trim_trees(void)
- }
- spin_unlock(&hash_lock);
- trim_marked(tree);
-- put_tree(tree);
- drop_collected_mounts(root_mnt);
- skip_it:
-+ put_tree(tree);
- mutex_lock(&audit_filter_mutex);
- }
- list_del(&cursor);
-diff --git a/kernel/trace/trace.c b/kernel/trace/trace.c
-index 7713d1b..3f28192 100644
---- a/kernel/trace/trace.c
-+++ b/kernel/trace/trace.c
-@@ -5168,36 +5168,32 @@ void trace_init_global_iter(struct trace_iterator *iter)
- iter->cpu_file = TRACE_PIPE_ALL_CPU;
- }
-
--static void
--__ftrace_dump(bool disable_tracing, enum ftrace_dump_mode oops_dump_mode)
-+void ftrace_dump(enum ftrace_dump_mode oops_dump_mode)
- {
-- static arch_spinlock_t ftrace_dump_lock =
-- (arch_spinlock_t)__ARCH_SPIN_LOCK_UNLOCKED;
- /* use static because iter can be a bit big for the stack */
- static struct trace_iterator iter;
-+ static atomic_t dump_running;
- unsigned int old_userobj;
-- static int dump_ran;
- unsigned long flags;
- int cnt = 0, cpu;
-
-- /* only one dump */
-- local_irq_save(flags);
-- arch_spin_lock(&ftrace_dump_lock);
-- if (dump_ran)
-- goto out;
--
-- dump_ran = 1;
-+ /* Only allow one dump user at a time. */
-+ if (atomic_inc_return(&dump_running) != 1) {
-+ atomic_dec(&dump_running);
-+ return;
-+ }
-
-+ /*
-+ * Always turn off tracing when we dump.
-+ * We don't need to show trace output of what happens
-+ * between multiple crashes.
-+ *
-+ * If the user does a sysrq-z, then they can re-enable
-+ * tracing with echo 1 > tracing_on.
-+ */
- tracing_off();
-
-- /* Did function tracer already get disabled? */
-- if (ftrace_is_dead()) {
-- printk("# WARNING: FUNCTION TRACING IS CORRUPTED\n");
-- printk("# MAY BE MISSING FUNCTION EVENTS\n");
-- }
--
-- if (disable_tracing)
-- ftrace_kill();
-+ local_irq_save(flags);
-
- /* Simulate the iterator */
- trace_init_global_iter(&iter);
-@@ -5227,6 +5223,12 @@ __ftrace_dump(bool disable_tracing, enum ftrace_dump_mode oops_dump_mode)
-
- printk(KERN_TRACE "Dumping ftrace buffer:\n");
-
-+ /* Did function tracer already get disabled? */
-+ if (ftrace_is_dead()) {
-+ printk("# WARNING: FUNCTION TRACING IS CORRUPTED\n");
-+ printk("# MAY BE MISSING FUNCTION EVENTS\n");
-+ }
-+
- /*
- * We need to stop all tracing on all CPUS to read the
- * the next buffer. This is a bit expensive, but is
-@@ -5266,26 +5268,14 @@ __ftrace_dump(bool disable_tracing, enum ftrace_dump_mode oops_dump_mode)
- printk(KERN_TRACE "---------------------------------\n");
-
- out_enable:
-- /* Re-enable tracing if requested */
-- if (!disable_tracing) {
-- trace_flags |= old_userobj;
-+ trace_flags |= old_userobj;
-
-- for_each_tracing_cpu(cpu) {
-- atomic_dec(&iter.tr->data[cpu]->disabled);
-- }
-- tracing_on();
-+ for_each_tracing_cpu(cpu) {
-+ atomic_dec(&iter.tr->data[cpu]->disabled);
- }
--
-- out:
-- arch_spin_unlock(&ftrace_dump_lock);
-+ atomic_dec(&dump_running);
- local_irq_restore(flags);
- }
--
--/* By default: disable tracing after the dump */
--void ftrace_dump(enum ftrace_dump_mode oops_dump_mode)
--{
-- __ftrace_dump(true, oops_dump_mode);
--}
- EXPORT_SYMBOL_GPL(ftrace_dump);
-
- __init static int tracer_alloc_buffers(void)
-diff --git a/kernel/trace/trace_selftest.c b/kernel/trace/trace_selftest.c
-index 51c819c..eedc297 100644
---- a/kernel/trace/trace_selftest.c
-+++ b/kernel/trace/trace_selftest.c
-@@ -703,8 +703,6 @@ trace_selftest_startup_function(struct tracer *trace, struct trace_array *tr)
- /* Maximum number of functions to trace before diagnosing a hang */
- #define GRAPH_MAX_FUNC_TEST 100000000
-
--static void
--__ftrace_dump(bool disable_tracing, enum ftrace_dump_mode oops_dump_mode);
- static unsigned int graph_hang_thresh;
-
- /* Wrap the real function entry probe to avoid possible hanging */
-@@ -714,8 +712,11 @@ static int trace_graph_entry_watchdog(struct ftrace_graph_ent *trace)
- if (unlikely(++graph_hang_thresh > GRAPH_MAX_FUNC_TEST)) {
- ftrace_graph_stop();
- printk(KERN_WARNING "BUG: Function graph tracer hang!\n");
-- if (ftrace_dump_on_oops)
-- __ftrace_dump(false, DUMP_ALL);
-+ if (ftrace_dump_on_oops) {
-+ ftrace_dump(DUMP_ALL);
-+ /* ftrace_dump() disables tracing */
-+ tracing_on();
-+ }
- return 0;
- }
-
-diff --git a/mm/mmap.c b/mm/mmap.c
-index 033094b..e17fc06 100644
---- a/mm/mmap.c
-+++ b/mm/mmap.c
-@@ -1327,15 +1327,20 @@ SYSCALL_DEFINE6(mmap_pgoff, unsigned long, addr, unsigned long, len,
- file = fget(fd);
- if (!file)
- goto out;
-+ if (is_file_hugepages(file))
-+ len = ALIGN(len, huge_page_size(hstate_file(file)));
- } else if (flags & MAP_HUGETLB) {
- struct user_struct *user = NULL;
-+
-+ len = ALIGN(len, huge_page_size(hstate_sizelog(
-+ (flags >> MAP_HUGE_SHIFT) & MAP_HUGE_MASK)));
- /*
- * VM_NORESERVE is used because the reservations will be
- * taken when vm_ops->mmap() is called
- * A dummy user value is used because we are not locking
- * memory so no accounting is necessary
- */
-- file = hugetlb_file_setup(HUGETLB_ANON_FILE, addr, len,
-+ file = hugetlb_file_setup(HUGETLB_ANON_FILE, len,
- VM_NORESERVE,
- &user, HUGETLB_ANONHUGE_INODE,
- (flags >> MAP_HUGE_SHIFT) & MAP_HUGE_MASK);
-diff --git a/net/netfilter/ipvs/ip_vs_pe_sip.c b/net/netfilter/ipvs/ip_vs_pe_sip.c
-index 12475ef..e5920fb 100644
---- a/net/netfilter/ipvs/ip_vs_pe_sip.c
-+++ b/net/netfilter/ipvs/ip_vs_pe_sip.c
-@@ -37,14 +37,10 @@ static int get_callid(const char *dptr, unsigned int dataoff,
- if (ret > 0)
- break;
- if (!ret)
-- return 0;
-+ return -EINVAL;
- dataoff += *matchoff;
- }
-
-- /* Empty callid is useless */
-- if (!*matchlen)
-- return -EINVAL;
--
- /* Too large is useless */
- if (*matchlen > IP_VS_PEDATA_MAXLEN)
- return -EINVAL;
-diff --git a/scripts/kconfig/list.h b/scripts/kconfig/list.h
-index 0ae730b..b87206c 100644
---- a/scripts/kconfig/list.h
-+++ b/scripts/kconfig/list.h
-@@ -51,6 +51,19 @@ struct list_head {
- pos = list_entry(pos->member.next, typeof(*pos), member))
-
- /**
-+ * list_for_each_entry_safe - iterate over list of given type safe against removal of list entry
-+ * @pos: the type * to use as a loop cursor.
-+ * @n: another type * to use as temporary storage
-+ * @head: the head for your list.
-+ * @member: the name of the list_struct within the struct.
-+ */
-+#define list_for_each_entry_safe(pos, n, head, member) \
-+ for (pos = list_entry((head)->next, typeof(*pos), member), \
-+ n = list_entry(pos->member.next, typeof(*pos), member); \
-+ &pos->member != (head); \
-+ pos = n, n = list_entry(n->member.next, typeof(*n), member))
-+
-+/**
- * list_empty - tests whether a list is empty
- * @head: the list to test.
- */
-diff --git a/scripts/kconfig/mconf.c b/scripts/kconfig/mconf.c
-index 566288a..c5418d6 100644
---- a/scripts/kconfig/mconf.c
-+++ b/scripts/kconfig/mconf.c
-@@ -389,6 +389,7 @@ again:
- .targets = targets,
- .keys = keys,
- };
-+ struct jump_key *pos, *tmp;
-
- res = get_relations_str(sym_arr, &head);
- dres = show_textbox_ext(_("Search Results"), (char *)
-@@ -402,6 +403,8 @@ again:
- again = true;
- }
- str_free(&res);
-+ list_for_each_entry_safe(pos, tmp, &head, entries)
-+ free(pos);
- } while (again);
- free(sym_arr);
- str_free(&title);
diff --git a/patches.kernel.org/patch-3.9.2-3 b/patches.kernel.org/patch-3.9.2-3
deleted file mode 100644
index 8ab11c2..0000000
--- a/patches.kernel.org/patch-3.9.2-3
+++ b/dev/null
@@ -1,3862 +0,0 @@
-From: Jiri Slaby <jslaby@suse.cz>
-Subject: Linux 3.9.3
-Patch-mainline: 3.9.3
-Git-commit: e3e84cda321703b123f36488f50700f371bc7230
-Git-commit: 780a7654cee8d61819512385e778e4827db4bfbc
-Git-commit: 6880b0150a7c25fd75c5ece80abc49ebf53c38c1
-Git-commit: 93782eba49e23c3f311a6b05a19ba15927ec4e8b
-Git-commit: bbbfde782084b4f0d85ddffb88f1cf4650ff40e4
-Git-commit: f0a18819e261afc5fdbd8c5c6f9943123c5461ba
-Git-commit: c207a76bf155cb5cf24cf849c08f6555e9180594
-Git-commit: 264b83c07a84223f0efd0d1db9ccc66d6f88288f
-Git-commit: e9ced8e040ebe40e9953db90acbe7d0b58702ebb
-Git-commit: fefaedcfb82d2e57c2320acf60604ab03b750cc0
-Git-commit: 61559af111e41761f5f4f20ce0897345eb59076e
-Git-commit: 6368087e851e697679af059b4247aca33a69cef3
-Git-commit: a5f2b3d6a738e7d4180012fe7b541172f8c8dcea
-Git-commit: 28fe5c825f8e15744d04c7c1b8df197950923ecd
-Git-commit: d2bdbee0d91a5d3ba2e439ce889e20bfe6fd4f1b
-Git-commit: ccf5ae83a6cf3d9cfe9a7038bfe7cd38ab03d5e1
-Git-commit: 3eccfdb01da58fbd0f789ae6ca61cee3769e26de
-Git-commit: ca182aee389f8026401510f4c63841cb02c820e8
-Git-commit: d8f469e9cff3bc4a6317d923e9506be046aa7bdc
-Git-commit: 1abc4b20b85b42e8573957e54b193385cf48b0d6
-Git-commit: 35623715818dfa720cccf99cd280dcbb4b78da23
-Git-commit: 088584618836b159947bc4ab5011a5cf1f081a62
-Git-commit: 22ee3b57c3ff71772b0c4178404b04f5df78d501
-Git-commit: 7c689e63a847316c1b2500f86891b0a574ce7e69
-Git-commit: 94ad0a101415978be04945b2787be1e8e8a874db
-Git-commit: ef57f9e6bb9278720c8a5278728f252ab85d7ac6
-Git-commit: 60403f7a4d9368d187f79cba5e4672d01df37574
-Git-commit: 5c1ef59168c485318e40ba485c1eba57d81d0faa
-Git-commit: 84c4a9dfbf430861e7588d95ae3ff61535dca351
-Git-commit: 5dbd5068430b8bd1c19387d46d6c1a88b261257f
-Git-commit: f77d602124d865c38705df7fa25c03de9c284ad2
-Git-commit: 233c7df0821c4190e2d3f4be0f2ca0ab40a5ed8c
-Git-commit: 4f924b2aa4d3cb30f07e57d6b608838edcbc0d88
-Git-commit: 4b264a1676e70dc656ba53a8cac690f2d4b65f4e
-Git-commit: c81400be716aa4c76f6ebf339ba94358dbbf6da6
-Git-commit: b56141ab34e2c3e2d7960cea12c20c99530c0c76
-Git-commit: 77d21f23a1e4db8639e3916547c903a3b3c7a07c
-Git-commit: 8da3056c04bfc5f69f840ab038a38389e2de8189
-Git-commit: c5060cec6ba27ad3f0e7facfdf05d2f18e3e3010
-Git-commit: 83401eb4990ff6af55aeed8f49681558544192e6
-Git-commit: b29d3145183da4e07d4b570fa8acdd3ac4a5c572
-Git-commit: 6708c9e5cc9bfc7c9a00ce9c0fdd0b1d4952b3d1
-Git-commit: 0dcffd09641f3abb21ac5cabc61542ab289d1a3c
-Git-commit: 3b54912f9cd167641b91d4a697bd742f70e534fe
-Git-commit: cd75eff64dae8856afbf6ef0f0ca3c145465d8e0
-Git-commit: 2c1bbbffa0b644fab4f91878cde0c2e8f52e2dcc
-Git-commit: 3811ae76bc84e5dc1a670ae10695f046b310bee1
-Git-commit: 89cc80a44b7c320e08599cb86f6aef0ead8986a1
-Git-commit: 093162553c33e9479283e107b4431378271c735d
-Git-commit: 1ffc5289bfcf7f4c4e4213240bb4be68c48ce603
-Git-commit: a9b054e8ab06504c2afa0e307ee78d3778993a1d
-Git-commit: 3a359f0b21ab218c1bf7a6a1b638b6fd143d0b99
-Git-commit: 9f1d036648c1c5ed81b0e98d7a06d55df972701e
-Git-commit: fb70a6690875315a3a1454e52fa339441ee7612b
-Git-commit: dd9c46408fdc07098333655ff27edf8cac8d9fcf
-Git-commit: 73b82bf0bfbf58e6ff328d3726934370585f6e78
-Git-commit: c539914dcd9a68c63305e055b14115a6a19578a8
-Git-commit: ccd384b10420ac81ba3fb9b0a7d18272c7173552
-Git-commit: f16fdc9d2dc1e5b270e9a08377587e831e0d36ac
-Git-commit: 48795424acff7215d5eac0b52793a2c1eb3a6283
-Git-commit: 4ef69d0394cba8caa9f75d3f2e53429bfb8b3045
-Git-commit: 79c66ce8f6448a3295a32efeac88c9debd7f7094
-Git-commit: 120496ac2d2d60aee68d3123a68169502a85f4b5
-Git-commit: 6eabb3301b1facee669d9938f7c5a0295c21d71d
-Git-commit: 074d72ff57f65de779e2f70d5906964c0ba1c123
-Git-commit: e6155736ad76b2070652745f9e54cdea3f0d8567
-Git-commit: 60705c89460fdc7227f2d153b68b3f34814738a4
-Git-commit: 4b0c0f294f60abcdd20994a8341a95c8ac5eeb96
-Git-commit: 42a5cf46cd56f46267d2a9fcf2655f4078cd3042
-Git-commit: b4f711ee03d28f776fd2324fd0bd999cc428e4d2
-Git-commit: 33e2208acfc15ce00d3dd13e839bf6434faa2b04
-Git-commit: cdee3904b4ce7c03d1013ed6dd704b43ae7fc2e9
-Git-commit: 39c60a0948cc06139e2fbfe084f83cb7e7deae3b
-Git-commit: 7f1fc268c47491fd5e63548f6415fc8604e13003
-Git-commit: 091d0d55b286c9340201b4ed4470be87fc568228
-Git-commit: 7783819920ca52fc582a2782f654fe6ed373f465
-Git-commit: 7255e716b1757dc10fa5e3a4d2eaab303ff9f7b6
-Git-commit: 9f415eb25574db4b73a9a712a4438e41dc284922
-Git-commit: 68aa8efcd1ab961e4684ef5af32f72a6ec1911de
-Git-commit: f3002134158092178be81339ec5a22ff80e6c308
-Git-commit: 772c808a252594692972773f6ee41c289b8e0b2a
-Git-commit: 55eaa7c1f511af5fb6ef808b5328804f4d4e5243
-Git-commit: d9a3c9823a2e6a543eb7807fb3d15d8233817ec5
-Git-commit: f792685006274a850e6cc0ea9ade275ccdfc90bc
-Git-commit: fa4d683af3693863bec761e2761a07e4c1351f86
-Git-commit: 09e8b813897a0f85bb401435d009228644c81214
-Git-commit: 502624bdad3dba45dfaacaf36b7d83e39e74b2d2
-Git-commit: d793e684277124d55c5d2444007e224635821346
-Git-commit: dc019b21fb92d620a3b52ccecc135ac968a7c7ec
-Git-commit: 9a188eb126aa7bf27077ee46fcb914898d6fc281
-Git-commit: ff359b14919c379a365233aa2e1dd469efac8ce8
-Git-commit: 2195b063f6609e4c6268f291683902f25eaf9aa6
-Git-commit: 6c35ae3c327ef4b5f51d3428d2ba47ac2153e882
-Git-commit: 61388f9e5d93053cf399a356414f31f9b4814c6d
-Git-commit: 4495e46fe18f198366961bb2b324a694ef8a9b44
-Git-commit: e65f131a14726e5f1b880a528271a52428e5b3a5
-Git-commit: c1e0ac192b48b37f31801c17534ab3d2a9282d84
-Git-commit: 326f578f7e1443bac2333712dd130a261ec15288
-Git-commit: 7fa57952d70f5737513d8319395e471d107e4e0d
-Git-commit: a035d5c64d08a8ac12d81b596e7fa6d95a73c347
-Git-commit: 8d76c49e9ffeee839bc0b7a3278a23f99101263e
-
-Signed-off-by: Jiri Slaby <jslaby@suse.cz>
----
-diff --git a/Makefile b/Makefile
-index 3e71511..01003d4 100644
---- a/Makefile
-+++ b/Makefile
-@@ -1,6 +1,6 @@
- VERSION = 3
- PATCHLEVEL = 9
--SUBLEVEL = 2
-+SUBLEVEL = 3
- EXTRAVERSION =
- NAME = Unicycling Gorilla
-
-diff --git a/arch/arm/include/asm/cmpxchg.h b/arch/arm/include/asm/cmpxchg.h
-index 7eb18c1..4f009c1 100644
---- a/arch/arm/include/asm/cmpxchg.h
-+++ b/arch/arm/include/asm/cmpxchg.h
-@@ -233,15 +233,15 @@ static inline unsigned long __cmpxchg_local(volatile void *ptr,
- ((__typeof__(*(ptr)))atomic64_cmpxchg(container_of((ptr), \
- atomic64_t, \
- counter), \
-- (unsigned long)(o), \
-- (unsigned long)(n)))
-+ (unsigned long long)(o), \
-+ (unsigned long long)(n)))
-
- #define cmpxchg64_local(ptr, o, n) \
- ((__typeof__(*(ptr)))local64_cmpxchg(container_of((ptr), \
- local64_t, \
- a), \
-- (unsigned long)(o), \
-- (unsigned long)(n)))
-+ (unsigned long long)(o), \
-+ (unsigned long long)(n)))
-
- #endif /* __LINUX_ARM_ARCH__ >= 6 */
-
-diff --git a/arch/arm/mach-exynos/include/mach/regs-pmu.h b/arch/arm/mach-exynos/include/mach/regs-pmu.h
-index 3f30aa1..57344b7 100644
---- a/arch/arm/mach-exynos/include/mach/regs-pmu.h
-+++ b/arch/arm/mach-exynos/include/mach/regs-pmu.h
-@@ -344,6 +344,7 @@
- #define EXYNOS5_FSYS_ARM_OPTION S5P_PMUREG(0x2208)
- #define EXYNOS5_ISP_ARM_OPTION S5P_PMUREG(0x2288)
- #define EXYNOS5_ARM_COMMON_OPTION S5P_PMUREG(0x2408)
-+#define EXYNOS5_ARM_L2_OPTION S5P_PMUREG(0x2608)
- #define EXYNOS5_TOP_PWR_OPTION S5P_PMUREG(0x2C48)
- #define EXYNOS5_TOP_PWR_SYSMEM_OPTION S5P_PMUREG(0x2CC8)
- #define EXYNOS5_JPEG_MEM_OPTION S5P_PMUREG(0x2F48)
-diff --git a/arch/arm/mach-exynos/pmu.c b/arch/arm/mach-exynos/pmu.c
-index daebc1a..97d6885 100644
---- a/arch/arm/mach-exynos/pmu.c
-+++ b/arch/arm/mach-exynos/pmu.c
-@@ -228,6 +228,7 @@ static struct exynos_pmu_conf exynos5250_pmu_config[] = {
- { EXYNOS5_DIS_IRQ_ISP_ARM_CENTRAL_SYS_PWR_REG, { 0x0, 0x0, 0x0} },
- { EXYNOS5_ARM_COMMON_SYS_PWR_REG, { 0x0, 0x0, 0x2} },
- { EXYNOS5_ARM_L2_SYS_PWR_REG, { 0x3, 0x3, 0x3} },
-+ { EXYNOS5_ARM_L2_OPTION, { 0x10, 0x10, 0x0 } },
- { EXYNOS5_CMU_ACLKSTOP_SYS_PWR_REG, { 0x1, 0x0, 0x1} },
- { EXYNOS5_CMU_SCLKSTOP_SYS_PWR_REG, { 0x1, 0x0, 0x1} },
- { EXYNOS5_CMU_RESET_SYS_PWR_REG, { 0x1, 0x1, 0x0} },
-@@ -353,11 +354,9 @@ static void exynos5_init_pmu(void)
-
- /*
- * SKIP_DEACTIVATE_ACEACP_IN_PWDN_BITFIELD Enable
-- * MANUAL_L2RSTDISABLE_CONTROL_BITFIELD Enable
- */
- tmp = __raw_readl(EXYNOS5_ARM_COMMON_OPTION);
-- tmp |= (EXYNOS5_MANUAL_L2RSTDISABLE_CONTROL |
-- EXYNOS5_SKIP_DEACTIVATE_ACEACP_IN_PWDN);
-+ tmp |= EXYNOS5_SKIP_DEACTIVATE_ACEACP_IN_PWDN;
- __raw_writel(tmp, EXYNOS5_ARM_COMMON_OPTION);
-
- /*
-diff --git a/arch/arm/mach-omap2/board-rx51-peripherals.c b/arch/arm/mach-omap2/board-rx51-peripherals.c
-index 3a077df..9bc9f19 100644
---- a/arch/arm/mach-omap2/board-rx51-peripherals.c
-+++ b/arch/arm/mach-omap2/board-rx51-peripherals.c
-@@ -73,11 +73,11 @@
- #define LIS302_IRQ1_GPIO 181
- #define LIS302_IRQ2_GPIO 180 /* Not yet in use */
-
--/* list all spi devices here */
-+/* List all SPI devices here. Note that the list/probe order seems to matter! */
- enum {
- RX51_SPI_WL1251,
-- RX51_SPI_MIPID, /* LCD panel */
- RX51_SPI_TSC2005, /* Touch Controller */
-+ RX51_SPI_MIPID, /* LCD panel */
- };
-
- static struct wl12xx_platform_data wl1251_pdata;
-diff --git a/arch/parisc/Makefile b/arch/parisc/Makefile
-index 113e282..1976900 100644
---- a/arch/parisc/Makefile
-+++ b/arch/parisc/Makefile
-@@ -23,26 +23,21 @@ NM = sh $(srctree)/arch/parisc/nm
- CHECKFLAGS += -D__hppa__=1
- LIBGCC = $(shell $(CC) $(KBUILD_CFLAGS) -print-libgcc-file-name)
-
--MACHINE := $(shell uname -m)
--ifeq ($(MACHINE),parisc*)
--NATIVE := 1
--endif
--
- ifdef CONFIG_64BIT
- UTS_MACHINE := parisc64
- CHECKFLAGS += -D__LP64__=1 -m64
--WIDTH := 64
-+CC_ARCHES = hppa64
- else # 32-bit
--WIDTH :=
-+CC_ARCHES = hppa hppa2.0 hppa1.1
- endif
-
--# attempt to help out folks who are cross-compiling
--ifeq ($(NATIVE),1)
--CROSS_COMPILE := hppa$(WIDTH)-linux-
--else
-- ifeq ($(CROSS_COMPILE),)
-- CROSS_COMPILE := hppa$(WIDTH)-linux-gnu-
-- endif
-+ifneq ($(SUBARCH),$(UTS_MACHINE))
-+ ifeq ($(CROSS_COMPILE),)
-+ CC_SUFFIXES = linux linux-gnu unknown-linux-gnu
-+ CROSS_COMPILE := $(call cc-cross-prefix, \
-+ $(foreach a,$(CC_ARCHES), \
-+ $(foreach s,$(CC_SUFFIXES),$(a)-$(s)-)))
-+ endif
- endif
-
- OBJCOPY_FLAGS =-O binary -R .note -R .comment -S
-diff --git a/arch/parisc/kernel/entry.S b/arch/parisc/kernel/entry.S
-index f33201b..897bce4 100644
---- a/arch/parisc/kernel/entry.S
-+++ b/arch/parisc/kernel/entry.S
-@@ -444,9 +444,41 @@
- L2_ptep \pgd,\pte,\index,\va,\fault
- .endm
-
-+ /* Acquire pa_dbit_lock lock. */
-+ .macro dbit_lock spc,tmp,tmp1
-+#ifdef CONFIG_SMP
-+ cmpib,COND(=),n 0,\spc,2f
-+ load32 PA(pa_dbit_lock),\tmp
-+1: LDCW 0(\tmp),\tmp1
-+ cmpib,COND(=) 0,\tmp1,1b
-+ nop
-+2:
-+#endif
-+ .endm
-+
-+ /* Release pa_dbit_lock lock without reloading lock address. */
-+ .macro dbit_unlock0 spc,tmp
-+#ifdef CONFIG_SMP
-+ or,COND(=) %r0,\spc,%r0
-+ stw \spc,0(\tmp)
-+#endif
-+ .endm
-+
-+ /* Release pa_dbit_lock lock. */
-+ .macro dbit_unlock1 spc,tmp
-+#ifdef CONFIG_SMP
-+ load32 PA(pa_dbit_lock),\tmp
-+ dbit_unlock0 \spc,\tmp
-+#endif
-+ .endm
-+
- /* Set the _PAGE_ACCESSED bit of the PTE. Be clever and
- * don't needlessly dirty the cache line if it was already set */
-- .macro update_ptep ptep,pte,tmp,tmp1
-+ .macro update_ptep spc,ptep,pte,tmp,tmp1
-+#ifdef CONFIG_SMP
-+ or,COND(=) %r0,\spc,%r0
-+ LDREG 0(\ptep),\pte
-+#endif
- ldi _PAGE_ACCESSED,\tmp1
- or \tmp1,\pte,\tmp
- and,COND(<>) \tmp1,\pte,%r0
-@@ -455,7 +487,11 @@
-
- /* Set the dirty bit (and accessed bit). No need to be
- * clever, this is only used from the dirty fault */
-- .macro update_dirty ptep,pte,tmp
-+ .macro update_dirty spc,ptep,pte,tmp
-+#ifdef CONFIG_SMP
-+ or,COND(=) %r0,\spc,%r0
-+ LDREG 0(\ptep),\pte
-+#endif
- ldi _PAGE_ACCESSED|_PAGE_DIRTY,\tmp
- or \tmp,\pte,\pte
- STREG \pte,0(\ptep)
-@@ -825,11 +861,6 @@ ENTRY(syscall_exit_rfi)
- STREG %r19,PT_SR7(%r16)
-
- intr_return:
-- /* NOTE: Need to enable interrupts incase we schedule. */
-- ssm PSW_SM_I, %r0
--
--intr_check_resched:
--
- /* check for reschedule */
- mfctl %cr30,%r1
- LDREG TI_FLAGS(%r1),%r19 /* sched.h: TIF_NEED_RESCHED */
-@@ -856,6 +887,11 @@ intr_check_sig:
- LDREG PT_IASQ1(%r16), %r20
- cmpib,COND(=),n 0,%r20,intr_restore /* backward */
-
-+ /* NOTE: We need to enable interrupts if we have to deliver
-+ * signals. We used to do this earlier but it caused kernel
-+ * stack overflows. */
-+ ssm PSW_SM_I, %r0
-+
- copy %r0, %r25 /* long in_syscall = 0 */
- #ifdef CONFIG_64BIT
- ldo -16(%r30),%r29 /* Reference param save area */
-@@ -907,6 +943,10 @@ intr_do_resched:
- cmpib,COND(=) 0, %r20, intr_do_preempt
- nop
-
-+ /* NOTE: We need to enable interrupts if we schedule. We used
-+ * to do this earlier but it caused kernel stack overflows. */
-+ ssm PSW_SM_I, %r0
-+
- #ifdef CONFIG_64BIT
- ldo -16(%r30),%r29 /* Reference param save area */
- #endif
-@@ -1099,11 +1139,13 @@ dtlb_miss_20w:
-
- L3_ptep ptp,pte,t0,va,dtlb_check_alias_20w
-
-- update_ptep ptp,pte,t0,t1
-+ dbit_lock spc,t0,t1
-+ update_ptep spc,ptp,pte,t0,t1
-
- make_insert_tlb spc,pte,prot
-
- idtlbt pte,prot
-+ dbit_unlock1 spc,t0
-
- rfir
- nop
-@@ -1123,11 +1165,13 @@ nadtlb_miss_20w:
-
- L3_ptep ptp,pte,t0,va,nadtlb_check_alias_20w
-
-- update_ptep ptp,pte,t0,t1
-+ dbit_lock spc,t0,t1
-+ update_ptep spc,ptp,pte,t0,t1
-
- make_insert_tlb spc,pte,prot
-
- idtlbt pte,prot
-+ dbit_unlock1 spc,t0
-
- rfir
- nop
-@@ -1149,7 +1193,8 @@ dtlb_miss_11:
-
- L2_ptep ptp,pte,t0,va,dtlb_check_alias_11
-
-- update_ptep ptp,pte,t0,t1
-+ dbit_lock spc,t0,t1
-+ update_ptep spc,ptp,pte,t0,t1
-
- make_insert_tlb_11 spc,pte,prot
-
-@@ -1160,6 +1205,7 @@ dtlb_miss_11:
- idtlbp prot,(%sr1,va)
-
- mtsp t0, %sr1 /* Restore sr1 */
-+ dbit_unlock1 spc,t0
-
- rfir
- nop
-@@ -1180,7 +1226,8 @@ nadtlb_miss_11:
-
- L2_ptep ptp,pte,t0,va,nadtlb_check_alias_11
-
-- update_ptep ptp,pte,t0,t1
-+ dbit_lock spc,t0,t1
-+ update_ptep spc,ptp,pte,t0,t1
-
- make_insert_tlb_11 spc,pte,prot
-
-@@ -1192,6 +1239,7 @@ nadtlb_miss_11:
- idtlbp prot,(%sr1,va)
-
- mtsp t0, %sr1 /* Restore sr1 */
-+ dbit_unlock1 spc,t0
-
- rfir
- nop
-@@ -1212,13 +1260,15 @@ dtlb_miss_20:
-
- L2_ptep ptp,pte,t0,va,dtlb_check_alias_20
-
-- update_ptep ptp,pte,t0,t1
-+ dbit_lock spc,t0,t1
-+ update_ptep spc,ptp,pte,t0,t1
-
- make_insert_tlb spc,pte,prot
-
- f_extend pte,t0
-
- idtlbt pte,prot
-+ dbit_unlock1 spc,t0
-
- rfir
- nop
-@@ -1238,13 +1288,15 @@ nadtlb_miss_20:
-
- L2_ptep ptp,pte,t0,va,nadtlb_check_alias_20
-
-- update_ptep ptp,pte,t0,t1
-+ dbit_lock spc,t0,t1
-+ update_ptep spc,ptp,pte,t0,t1
-
- make_insert_tlb spc,pte,prot
-
- f_extend pte,t0
-
- idtlbt pte,prot
-+ dbit_unlock1 spc,t0
-
- rfir
- nop
-@@ -1345,11 +1397,13 @@ itlb_miss_20w:
-
- L3_ptep ptp,pte,t0,va,itlb_fault
-
-- update_ptep ptp,pte,t0,t1
-+ dbit_lock spc,t0,t1
-+ update_ptep spc,ptp,pte,t0,t1
-
- make_insert_tlb spc,pte,prot
-
- iitlbt pte,prot
-+ dbit_unlock1 spc,t0
-
- rfir
- nop
-@@ -1367,11 +1421,13 @@ naitlb_miss_20w:
-
- L3_ptep ptp,pte,t0,va,naitlb_check_alias_20w
-
-- update_ptep ptp,pte,t0,t1
-+ dbit_lock spc,t0,t1
-+ update_ptep spc,ptp,pte,t0,t1
-
- make_insert_tlb spc,pte,prot
-
- iitlbt pte,prot
-+ dbit_unlock1 spc,t0
-
- rfir
- nop
-@@ -1393,7 +1449,8 @@ itlb_miss_11:
-
- L2_ptep ptp,pte,t0,va,itlb_fault
-
-- update_ptep ptp,pte,t0,t1
-+ dbit_lock spc,t0,t1
-+ update_ptep spc,ptp,pte,t0,t1
-
- make_insert_tlb_11 spc,pte,prot
-
-@@ -1404,6 +1461,7 @@ itlb_miss_11:
- iitlbp prot,(%sr1,va)
-
- mtsp t0, %sr1 /* Restore sr1 */
-+ dbit_unlock1 spc,t0
-
- rfir
- nop
-@@ -1415,7 +1473,8 @@ naitlb_miss_11:
-
- L2_ptep ptp,pte,t0,va,naitlb_check_alias_11
-
-- update_ptep ptp,pte,t0,t1
-+ dbit_lock spc,t0,t1
-+ update_ptep spc,ptp,pte,t0,t1
-
- make_insert_tlb_11 spc,pte,prot
-
-@@ -1426,6 +1485,7 @@ naitlb_miss_11:
- iitlbp prot,(%sr1,va)
-
- mtsp t0, %sr1 /* Restore sr1 */
-+ dbit_unlock1 spc,t0
-
- rfir
- nop
-@@ -1447,13 +1507,15 @@ itlb_miss_20:
-
- L2_ptep ptp,pte,t0,va,itlb_fault
-
-- update_ptep ptp,pte,t0,t1
-+ dbit_lock spc,t0,t1
-+ update_ptep spc,ptp,pte,t0,t1
-
- make_insert_tlb spc,pte,prot
-
- f_extend pte,t0
-
- iitlbt pte,prot
-+ dbit_unlock1 spc,t0
-
- rfir
- nop
-@@ -1465,13 +1527,15 @@ naitlb_miss_20:
-
- L2_ptep ptp,pte,t0,va,naitlb_check_alias_20
-
-- update_ptep ptp,pte,t0,t1
-+ dbit_lock spc,t0,t1
-+ update_ptep spc,ptp,pte,t0,t1
-
- make_insert_tlb spc,pte,prot
-
- f_extend pte,t0
-
- iitlbt pte,prot
-+ dbit_unlock1 spc,t0
-
- rfir
- nop
-@@ -1495,29 +1559,13 @@ dbit_trap_20w:
-
- L3_ptep ptp,pte,t0,va,dbit_fault
-
--#ifdef CONFIG_SMP
-- cmpib,COND(=),n 0,spc,dbit_nolock_20w
-- load32 PA(pa_dbit_lock),t0
--
--dbit_spin_20w:
-- LDCW 0(t0),t1
-- cmpib,COND(=) 0,t1,dbit_spin_20w
-- nop
--
--dbit_nolock_20w:
--#endif
-- update_dirty ptp,pte,t1
-+ dbit_lock spc,t0,t1
-+ update_dirty spc,ptp,pte,t1
-
- make_insert_tlb spc,pte,prot
-
- idtlbt pte,prot
--#ifdef CONFIG_SMP
-- cmpib,COND(=),n 0,spc,dbit_nounlock_20w
-- ldi 1,t1
-- stw t1,0(t0)
--
--dbit_nounlock_20w:
--#endif
-+ dbit_unlock0 spc,t0
-
- rfir
- nop
-@@ -1531,18 +1579,8 @@ dbit_trap_11:
-
- L2_ptep ptp,pte,t0,va,dbit_fault
-
--#ifdef CONFIG_SMP
-- cmpib,COND(=),n 0,spc,dbit_nolock_11
-- load32 PA(pa_dbit_lock),t0
--
--dbit_spin_11:
-- LDCW 0(t0),t1
-- cmpib,= 0,t1,dbit_spin_11
-- nop
--
--dbit_nolock_11:
--#endif
-- update_dirty ptp,pte,t1
-+ dbit_lock spc,t0,t1
-+ update_dirty spc,ptp,pte,t1
-
- make_insert_tlb_11 spc,pte,prot
-
-@@ -1553,13 +1591,7 @@ dbit_nolock_11:
- idtlbp prot,(%sr1,va)
-
- mtsp t1, %sr1 /* Restore sr1 */
--#ifdef CONFIG_SMP
-- cmpib,COND(=),n 0,spc,dbit_nounlock_11
-- ldi 1,t1
-- stw t1,0(t0)
--
--dbit_nounlock_11:
--#endif
-+ dbit_unlock0 spc,t0
-
- rfir
- nop
-@@ -1571,32 +1603,15 @@ dbit_trap_20:
-
- L2_ptep ptp,pte,t0,va,dbit_fault
-
--#ifdef CONFIG_SMP
-- cmpib,COND(=),n 0,spc,dbit_nolock_20
-- load32 PA(pa_dbit_lock),t0
--
--dbit_spin_20:
-- LDCW 0(t0),t1
-- cmpib,= 0,t1,dbit_spin_20
-- nop
--
--dbit_nolock_20:
--#endif
-- update_dirty ptp,pte,t1
-+ dbit_lock spc,t0,t1
-+ update_dirty spc,ptp,pte,t1
-
- make_insert_tlb spc,pte,prot
-
- f_extend pte,t1
-
- idtlbt pte,prot
--
--#ifdef CONFIG_SMP
-- cmpib,COND(=),n 0,spc,dbit_nounlock_20
-- ldi 1,t1
-- stw t1,0(t0)
--
--dbit_nounlock_20:
--#endif
-+ dbit_unlock0 spc,t0
-
- rfir
- nop
-@@ -1694,7 +1709,8 @@ ENTRY(sys_\name\()_wrapper)
- ldo TASK_REGS(%r1),%r1
- reg_save %r1
- mfctl %cr27, %r28
-- b sys_\name
-+ ldil L%sys_\name, %r31
-+ be R%sys_\name(%sr4,%r31)
- STREG %r28, PT_CR27(%r1)
- ENDPROC(sys_\name\()_wrapper)
- .endm
-diff --git a/arch/powerpc/include/asm/rtas.h b/arch/powerpc/include/asm/rtas.h
-index aef00c6..ee38f29 100644
---- a/arch/powerpc/include/asm/rtas.h
-+++ b/arch/powerpc/include/asm/rtas.h
-@@ -262,6 +262,8 @@ extern void rtas_progress(char *s, unsigned short hex);
- extern void rtas_initialize(void);
- extern int rtas_suspend_cpu(struct rtas_suspend_me_data *data);
- extern int rtas_suspend_last_cpu(struct rtas_suspend_me_data *data);
-+extern int rtas_online_cpus_mask(cpumask_var_t cpus);
-+extern int rtas_offline_cpus_mask(cpumask_var_t cpus);
- extern int rtas_ibm_suspend_me(struct rtas_args *);
-
- struct rtc_time;
-diff --git a/arch/powerpc/kernel/machine_kexec_64.c b/arch/powerpc/kernel/machine_kexec_64.c
-index 466a290..611acdf 100644
---- a/arch/powerpc/kernel/machine_kexec_64.c
-+++ b/arch/powerpc/kernel/machine_kexec_64.c
-@@ -17,6 +17,7 @@
- #include <linux/errno.h>
- #include <linux/kernel.h>
- #include <linux/cpu.h>
-+#include <linux/hardirq.h>
-
- #include <asm/page.h>
- #include <asm/current.h>
-@@ -335,10 +336,13 @@ void default_machine_kexec(struct kimage *image)
- pr_debug("kexec: Starting switchover sequence.\n");
-
- /* switch to a staticly allocated stack. Based on irq stack code.
-+ * We setup preempt_count to avoid using VMX in memcpy.
- * XXX: the task struct will likely be invalid once we do the copy!
- */
- kexec_stack.thread_info.task = current_thread_info()->task;
- kexec_stack.thread_info.flags = 0;
-+ kexec_stack.thread_info.preempt_count = HARDIRQ_OFFSET;
-+ kexec_stack.thread_info.cpu = current_thread_info()->cpu;
-
- /* We need a static PACA, too; copy this CPU's PACA over and switch to
- * it. Also poison per_cpu_offset to catch anyone using non-static
-diff --git a/arch/powerpc/kernel/rtas.c b/arch/powerpc/kernel/rtas.c
-index 1fd6e7b..52add6f 100644
---- a/arch/powerpc/kernel/rtas.c
-+++ b/arch/powerpc/kernel/rtas.c
-@@ -19,6 +19,7 @@
- #include <linux/init.h>
- #include <linux/capability.h>
- #include <linux/delay.h>
-+#include <linux/cpu.h>
- #include <linux/smp.h>
- #include <linux/completion.h>
- #include <linux/cpumask.h>
-@@ -807,6 +808,95 @@ static void rtas_percpu_suspend_me(void *info)
- __rtas_suspend_cpu((struct rtas_suspend_me_data *)info, 1);
- }
-
-+enum rtas_cpu_state {
-+ DOWN,
-+ UP,
-+};
-+
-+#ifndef CONFIG_SMP
-+static int rtas_cpu_state_change_mask(enum rtas_cpu_state state,
-+ cpumask_var_t cpus)
-+{
-+ if (!cpumask_empty(cpus)) {
-+ cpumask_clear(cpus);
-+ return -EINVAL;
-+ } else
-+ return 0;
-+}
-+#else
-+/* On return cpumask will be altered to indicate CPUs changed.
-+ * CPUs with states changed will be set in the mask,
-+ * CPUs with status unchanged will be unset in the mask. */
-+static int rtas_cpu_state_change_mask(enum rtas_cpu_state state,
-+ cpumask_var_t cpus)
-+{
-+ int cpu;
-+ int cpuret = 0;
-+ int ret = 0;
-+
-+ if (cpumask_empty(cpus))
-+ return 0;
-+
-+ for_each_cpu(cpu, cpus) {
-+ switch (state) {
-+ case DOWN:
-+ cpuret = cpu_down(cpu);
-+ break;
-+ case UP:
-+ cpuret = cpu_up(cpu);
-+ break;
-+ }
-+ if (cpuret) {
-+ pr_debug("%s: cpu_%s for cpu#%d returned %d.\n",
-+ __func__,
-+ ((state == UP) ? "up" : "down"),
-+ cpu, cpuret);
-+ if (!ret)
-+ ret = cpuret;
-+ if (state == UP) {
-+ /* clear bits for unchanged cpus, return */
-+ cpumask_shift_right(cpus, cpus, cpu);
-+ cpumask_shift_left(cpus, cpus, cpu);
-+ break;
-+ } else {
-+ /* clear bit for unchanged cpu, continue */
-+ cpumask_clear_cpu(cpu, cpus);
-+ }
-+ }
-+ }
-+
-+ return ret;
-+}
-+#endif
-+
-+int rtas_online_cpus_mask(cpumask_var_t cpus)
-+{
-+ int ret;
-+
-+ ret = rtas_cpu_state_change_mask(UP, cpus);
-+
-+ if (ret) {
-+ cpumask_var_t tmp_mask;
-+
-+ if (!alloc_cpumask_var(&tmp_mask, GFP_TEMPORARY))
-+ return ret;
-+
-+ /* Use tmp_mask to preserve cpus mask from first failure */
-+ cpumask_copy(tmp_mask, cpus);
-+ rtas_offline_cpus_mask(tmp_mask);
-+ free_cpumask_var(tmp_mask);
-+ }
-+
-+ return ret;
-+}
-+EXPORT_SYMBOL(rtas_online_cpus_mask);
-+
-+int rtas_offline_cpus_mask(cpumask_var_t cpus)
-+{
-+ return rtas_cpu_state_change_mask(DOWN, cpus);
-+}
-+EXPORT_SYMBOL(rtas_offline_cpus_mask);
-+
- int rtas_ibm_suspend_me(struct rtas_args *args)
- {
- long state;
-@@ -814,6 +904,8 @@ int rtas_ibm_suspend_me(struct rtas_args *args)
- unsigned long retbuf[PLPAR_HCALL_BUFSIZE];
- struct rtas_suspend_me_data data;
- DECLARE_COMPLETION_ONSTACK(done);
-+ cpumask_var_t offline_mask;
-+ int cpuret;
-
- if (!rtas_service_present("ibm,suspend-me"))
- return -ENOSYS;
-@@ -837,11 +929,24 @@ int rtas_ibm_suspend_me(struct rtas_args *args)
- return 0;
- }
-
-+ if (!alloc_cpumask_var(&offline_mask, GFP_TEMPORARY))
-+ return -ENOMEM;
-+
- atomic_set(&data.working, 0);
- atomic_set(&data.done, 0);
- atomic_set(&data.error, 0);
- data.token = rtas_token("ibm,suspend-me");
- data.complete = &done;
-+
-+ /* All present CPUs must be online */
-+ cpumask_andnot(offline_mask, cpu_present_mask, cpu_online_mask);
-+ cpuret = rtas_online_cpus_mask(offline_mask);
-+ if (cpuret) {
-+ pr_err("%s: Could not bring present CPUs online.\n", __func__);
-+ atomic_set(&data.error, cpuret);
-+ goto out;
-+ }
-+
- stop_topology_update();
-
- /* Call function on all CPUs. One of us will make the
-@@ -857,6 +962,14 @@ int rtas_ibm_suspend_me(struct rtas_args *args)
-
- start_topology_update();
-
-+ /* Take down CPUs not online prior to suspend */
-+ cpuret = rtas_offline_cpus_mask(offline_mask);
-+ if (cpuret)
-+ pr_warn("%s: Could not restore CPUs to offline state.\n",
-+ __func__);
-+
-+out:
-+ free_cpumask_var(offline_mask);
- return atomic_read(&data.error);
- }
- #else /* CONFIG_PPC_PSERIES */
-diff --git a/arch/powerpc/platforms/pseries/suspend.c b/arch/powerpc/platforms/pseries/suspend.c
-index 47226e0..5f997e7 100644
---- a/arch/powerpc/platforms/pseries/suspend.c
-+++ b/arch/powerpc/platforms/pseries/suspend.c
-@@ -16,6 +16,7 @@
- * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
- */
-
-+#include <linux/cpu.h>
- #include <linux/delay.h>
- #include <linux/suspend.h>
- #include <linux/stat.h>
-@@ -126,11 +127,15 @@ static ssize_t store_hibernate(struct device *dev,
- struct device_attribute *attr,
- const char *buf, size_t count)
- {
-+ cpumask_var_t offline_mask;
- int rc;
-
- if (!capable(CAP_SYS_ADMIN))
- return -EPERM;
-
-+ if (!alloc_cpumask_var(&offline_mask, GFP_TEMPORARY))
-+ return -ENOMEM;
-+
- stream_id = simple_strtoul(buf, NULL, 16);
-
- do {
-@@ -140,15 +145,32 @@ static ssize_t store_hibernate(struct device *dev,
- } while (rc == -EAGAIN);
-
- if (!rc) {
-+ /* All present CPUs must be online */
-+ cpumask_andnot(offline_mask, cpu_present_mask,
-+ cpu_online_mask);
-+ rc = rtas_online_cpus_mask(offline_mask);
-+ if (rc) {
-+ pr_err("%s: Could not bring present CPUs online.\n",
-+ __func__);
-+ goto out;
-+ }
-+
- stop_topology_update();
- rc = pm_suspend(PM_SUSPEND_MEM);
- start_topology_update();
-+
-+ /* Take down CPUs not online prior to suspend */
-+ if (!rtas_offline_cpus_mask(offline_mask))
-+ pr_warn("%s: Could not restore CPUs to offline "
-+ "state.\n", __func__);
- }
-
- stream_id = 0;
-
- if (!rc)
- rc = count;
-+out:
-+ free_cpumask_var(offline_mask);
- return rc;
- }
-
-diff --git a/arch/tile/Kconfig b/arch/tile/Kconfig
-index 25877ae..41a2a0b 100644
---- a/arch/tile/Kconfig
-+++ b/arch/tile/Kconfig
-@@ -368,11 +368,17 @@ config HARDWALL
- config KERNEL_PL
- int "Processor protection level for kernel"
- range 1 2
-- default "1"
-+ default 2 if TILEGX
-+ default 1 if !TILEGX
- ---help---
-- This setting determines the processor protection level the
-- kernel will be built to run at. Generally you should use
-- the default value here.
-+ Since MDE 4.2, the Tilera hypervisor runs the kernel
-+ at PL2 by default. If running under an older hypervisor,
-+ or as a KVM guest, you must run at PL1. (The current
-+ hypervisor may also be recompiled with "make HV_PL=2" to
-+ allow it to run a kernel at PL1, but clients running at PL1
-+ are not expected to be supported indefinitely.)
-+
-+ If you're not sure, don't change the default.
-
- source "arch/tile/gxio/Kconfig"
-
-diff --git a/arch/tile/include/hv/hypervisor.h b/arch/tile/include/hv/hypervisor.h
-index ccd847e..837dca5 100644
---- a/arch/tile/include/hv/hypervisor.h
-+++ b/arch/tile/include/hv/hypervisor.h
-@@ -107,7 +107,22 @@
- #define HV_DISPATCH_ENTRY_SIZE 32
-
- /** Version of the hypervisor interface defined by this file */
--#define _HV_VERSION 11
-+#define _HV_VERSION 13
-+
-+/** Last version of the hypervisor interface with old hv_init() ABI.
-+ *
-+ * The change from version 12 to version 13 corresponds to launching
-+ * the client by default at PL2 instead of PL1 (corresponding to the
-+ * hv itself running at PL3 instead of PL2). To make this explicit,
-+ * the hv_init() API was also extended so the client can report its
-+ * desired PL, resulting in a more helpful failure diagnostic. If you
-+ * call hv_init() with _HV_VERSION_OLD_HV_INIT and omit the client_pl
-+ * argument, the hypervisor will assume client_pl = 1.
-+ *
-+ * Note that this is a deprecated solution and we do not expect to
-+ * support clients of the Tilera hypervisor running at PL1 indefinitely.
-+ */
-+#define _HV_VERSION_OLD_HV_INIT 12
-
- /* Index into hypervisor interface dispatch code blocks.
- *
-@@ -377,7 +392,11 @@ typedef int HV_Errno;
- #ifndef __ASSEMBLER__
-
- /** Pass HV_VERSION to hv_init to request this version of the interface. */
--typedef enum { HV_VERSION = _HV_VERSION } HV_VersionNumber;
-+typedef enum {
-+ HV_VERSION = _HV_VERSION,
-+ HV_VERSION_OLD_HV_INIT = _HV_VERSION_OLD_HV_INIT,
-+
-+} HV_VersionNumber;
-
- /** Initializes the hypervisor.
- *
-@@ -385,9 +404,11 @@ typedef enum { HV_VERSION = _HV_VERSION } HV_VersionNumber;
- * that this program expects, typically HV_VERSION.
- * @param chip_num Architecture number of the chip the client was built for.
- * @param chip_rev_num Revision number of the chip the client was built for.
-+ * @param client_pl Privilege level the client is built for
-+ * (not required if interface_version_number == HV_VERSION_OLD_HV_INIT).
- */
- void hv_init(HV_VersionNumber interface_version_number,
-- int chip_num, int chip_rev_num);
-+ int chip_num, int chip_rev_num, int client_pl);
-
-
- /** Queries we can make for hv_sysconf().
-diff --git a/arch/tile/kernel/head_32.S b/arch/tile/kernel/head_32.S
-index f71bfee..ac11530 100644
---- a/arch/tile/kernel/head_32.S
-+++ b/arch/tile/kernel/head_32.S
-@@ -38,7 +38,7 @@ ENTRY(_start)
- movei r2, TILE_CHIP_REV
- }
- {
-- moveli r0, _HV_VERSION
-+ moveli r0, _HV_VERSION_OLD_HV_INIT
- jal hv_init
- }
- /* Get a reasonable default ASID in r0 */
-diff --git a/arch/tile/kernel/head_64.S b/arch/tile/kernel/head_64.S
-index f9a2734..6093964 100644
---- a/arch/tile/kernel/head_64.S
-+++ b/arch/tile/kernel/head_64.S
-@@ -34,13 +34,19 @@
- ENTRY(_start)
- /* Notify the hypervisor of what version of the API we want */
- {
-+#if KERNEL_PL == 1 && _HV_VERSION == 13
-+ /* Support older hypervisors by asking for API version 12. */
-+ movei r0, _HV_VERSION_OLD_HV_INIT
-+#else
-+ movei r0, _HV_VERSION
-+#endif
- movei r1, TILE_CHIP
-- movei r2, TILE_CHIP_REV
- }
- {
-- moveli r0, _HV_VERSION
-- jal hv_init
-+ movei r2, TILE_CHIP_REV
-+ movei r3, KERNEL_PL
- }
-+ jal hv_init
- /* Get a reasonable default ASID in r0 */
- {
- move r0, zero
-diff --git a/arch/x86/Kconfig b/arch/x86/Kconfig
-index 15b5cef..6ef2a37 100644
---- a/arch/x86/Kconfig
-+++ b/arch/x86/Kconfig
-@@ -107,7 +107,6 @@ config X86
- select GENERIC_CLOCKEVENTS_BROADCAST if X86_64 || (X86_32 && X86_LOCAL_APIC)
- select GENERIC_TIME_VSYSCALL if X86_64
- select KTIME_SCALAR if X86_32
-- select ALWAYS_USE_PERSISTENT_CLOCK
- select GENERIC_STRNCPY_FROM_USER
- select GENERIC_STRNLEN_USER
- select HAVE_CONTEXT_TRACKING if X86_64
-diff --git a/arch/x86/kernel/microcode_intel_early.c b/arch/x86/kernel/microcode_intel_early.c
-index d893e8e..2e9e128 100644
---- a/arch/x86/kernel/microcode_intel_early.c
-+++ b/arch/x86/kernel/microcode_intel_early.c
-@@ -487,6 +487,7 @@ static inline void show_saved_mc(void)
- #endif
-
- #if defined(CONFIG_MICROCODE_INTEL_EARLY) && defined(CONFIG_HOTPLUG_CPU)
-+static DEFINE_MUTEX(x86_cpu_microcode_mutex);
- /*
- * Save this mc into mc_saved_data. So it will be loaded early when a CPU is
- * hot added or resumes.
-@@ -507,7 +508,7 @@ int save_mc_for_early(u8 *mc)
- * Hold hotplug lock so mc_saved_data is not accessed by a CPU in
- * hotplug.
- */
-- cpu_hotplug_driver_lock();
-+ mutex_lock(&x86_cpu_microcode_mutex);
-
- mc_saved_count_init = mc_saved_data.mc_saved_count;
- mc_saved_count = mc_saved_data.mc_saved_count;
-@@ -544,7 +545,7 @@ int save_mc_for_early(u8 *mc)
- }
-
- out:
-- cpu_hotplug_driver_unlock();
-+ mutex_unlock(&x86_cpu_microcode_mutex);
-
- return ret;
- }
-diff --git a/arch/x86/kvm/emulate.c b/arch/x86/kvm/emulate.c
-index a9c9d3e..59622c9 100644
---- a/arch/x86/kvm/emulate.c
-+++ b/arch/x86/kvm/emulate.c
-@@ -60,6 +60,7 @@
- #define OpGS 25ull /* GS */
- #define OpMem8 26ull /* 8-bit zero extended memory operand */
- #define OpImm64 27ull /* Sign extended 16/32/64-bit immediate */
-+#define OpXLat 28ull /* memory at BX/EBX/RBX + zero-extended AL */
-
- #define OpBits 5 /* Width of operand field */
- #define OpMask ((1ull << OpBits) - 1)
-@@ -99,6 +100,7 @@
- #define SrcImmUByte (OpImmUByte << SrcShift)
- #define SrcImmU (OpImmU << SrcShift)
- #define SrcSI (OpSI << SrcShift)
-+#define SrcXLat (OpXLat << SrcShift)
- #define SrcImmFAddr (OpImmFAddr << SrcShift)
- #define SrcMemFAddr (OpMemFAddr << SrcShift)
- #define SrcAcc (OpAcc << SrcShift)
-@@ -532,6 +534,9 @@ FOP_SETCC(setle)
- FOP_SETCC(setnle)
- FOP_END;
-
-+FOP_START(salc) "pushf; sbb %al, %al; popf \n\t" FOP_RET
-+FOP_END;
-+
- #define __emulate_1op_rax_rdx(ctxt, _op, _suffix, _ex) \
- do { \
- unsigned long _tmp; \
-@@ -2986,6 +2991,28 @@ static int em_das(struct x86_emulate_ctxt *ctxt)
- return X86EMUL_CONTINUE;
- }
-
-+static int em_aam(struct x86_emulate_ctxt *ctxt)
-+{
-+ u8 al, ah;
-+
-+ if (ctxt->src.val == 0)
-+ return emulate_de(ctxt);
-+
-+ al = ctxt->dst.val & 0xff;
-+ ah = al / ctxt->src.val;
-+ al %= ctxt->src.val;
-+
-+ ctxt->dst.val = (ctxt->dst.val & 0xffff0000) | al | (ah << 8);
-+
-+ /* Set PF, ZF, SF */
-+ ctxt->src.type = OP_IMM;
-+ ctxt->src.val = 0;
-+ ctxt->src.bytes = 1;
-+ fastop(ctxt, em_or);
-+
-+ return X86EMUL_CONTINUE;
-+}
-+
- static int em_aad(struct x86_emulate_ctxt *ctxt)
- {
- u8 al = ctxt->dst.val & 0xff;
-@@ -3926,7 +3953,10 @@ static const struct opcode opcode_table[256] = {
- /* 0xD0 - 0xD7 */
- G(Src2One | ByteOp, group2), G(Src2One, group2),
- G(Src2CL | ByteOp, group2), G(Src2CL, group2),
-- N, I(DstAcc | SrcImmByte | No64, em_aad), N, N,
-+ I(DstAcc | SrcImmUByte | No64, em_aam),
-+ I(DstAcc | SrcImmUByte | No64, em_aad),
-+ F(DstAcc | ByteOp | No64, em_salc),
-+ I(DstAcc | SrcXLat | ByteOp, em_mov),
- /* 0xD8 - 0xDF */
- N, E(0, &escape_d9), N, E(0, &escape_db), N, E(0, &escape_dd), N, N,
- /* 0xE0 - 0xE7 */
-@@ -4188,6 +4218,16 @@ static int decode_operand(struct x86_emulate_ctxt *ctxt, struct operand *op,
- op->val = 0;
- op->count = 1;
- break;
-+ case OpXLat:
-+ op->type = OP_MEM;
-+ op->bytes = (ctxt->d & ByteOp) ? 1 : ctxt->op_bytes;
-+ op->addr.mem.ea =
-+ register_address(ctxt,
-+ reg_read(ctxt, VCPU_REGS_RBX) +
-+ (reg_read(ctxt, VCPU_REGS_RAX) & 0xff));
-+ op->addr.mem.seg = seg_override(ctxt);
-+ op->val = 0;
-+ break;
- case OpImmFAddr:
- op->type = OP_IMM;
- op->addr.mem.ea = ctxt->_eip;
-diff --git a/arch/x86/kvm/vmx.c b/arch/x86/kvm/vmx.c
-index 6667042..0af1807 100644
---- a/arch/x86/kvm/vmx.c
-+++ b/arch/x86/kvm/vmx.c
-@@ -5197,6 +5197,12 @@ static int handle_invalid_guest_state(struct kvm_vcpu *vcpu)
- return 0;
- }
-
-+ if (vcpu->arch.halt_request) {
-+ vcpu->arch.halt_request = 0;
-+ ret = kvm_emulate_halt(vcpu);
-+ goto out;
-+ }
-+
- if (signal_pending(current))
- goto out;
- if (need_resched())
-diff --git a/arch/x86/xen/enlighten.c b/arch/x86/xen/enlighten.c
-index 2363127..cf95e19 100644
---- a/arch/x86/xen/enlighten.c
-+++ b/arch/x86/xen/enlighten.c
-@@ -156,6 +156,21 @@ static void xen_vcpu_setup(int cpu)
-
- BUG_ON(HYPERVISOR_shared_info == &xen_dummy_shared_info);
-
-+ /*
-+ * This path is called twice on PVHVM - first during bootup via
-+ * smp_init -> xen_hvm_cpu_notify, and then if the VCPU is being
-+ * hotplugged: cpu_up -> xen_hvm_cpu_notify.
-+ * As we can only do the VCPUOP_register_vcpu_info once lets
-+ * not over-write its result.
-+ *
-+ * For PV it is called during restore (xen_vcpu_restore) and bootup
-+ * (xen_setup_vcpu_info_placement). The hotplug mechanism does not
-+ * use this function.
-+ */
-+ if (xen_hvm_domain()) {
-+ if (per_cpu(xen_vcpu, cpu) == &per_cpu(xen_vcpu_info, cpu))
-+ return;
-+ }
- if (cpu < MAX_VIRT_CPUS)
- per_cpu(xen_vcpu,cpu) = &HYPERVISOR_shared_info->vcpu_info[cpu];
-
-diff --git a/drivers/acpi/acpica/exfldio.c b/drivers/acpi/acpica/exfldio.c
-index ec7f569..c84ee95 100644
---- a/drivers/acpi/acpica/exfldio.c
-+++ b/drivers/acpi/acpica/exfldio.c
-@@ -720,7 +720,19 @@ acpi_ex_extract_from_field(union acpi_operand_object *obj_desc,
-
- if ((obj_desc->common_field.start_field_bit_offset == 0) &&
- (obj_desc->common_field.bit_length == access_bit_width)) {
-- status = acpi_ex_field_datum_io(obj_desc, 0, buffer, ACPI_READ);
-+ if (buffer_length >= sizeof(u64)) {
-+ status =
-+ acpi_ex_field_datum_io(obj_desc, 0, buffer,
-+ ACPI_READ);
-+ } else {
-+ /* Use raw_datum (u64) to handle buffers < 64 bits */
-+
-+ status =
-+ acpi_ex_field_datum_io(obj_desc, 0, &raw_datum,
-+ ACPI_READ);
-+ ACPI_MEMCPY(buffer, &raw_datum, buffer_length);
-+ }
-+
- return_ACPI_STATUS(status);
- }
-
-diff --git a/drivers/acpi/ec.c b/drivers/acpi/ec.c
-index d45b287..edc0081 100644
---- a/drivers/acpi/ec.c
-+++ b/drivers/acpi/ec.c
-@@ -223,7 +223,7 @@ static int ec_check_sci_sync(struct acpi_ec *ec, u8 state)
- static int ec_poll(struct acpi_ec *ec)
- {
- unsigned long flags;
-- int repeat = 2; /* number of command restarts */
-+ int repeat = 5; /* number of command restarts */
- while (repeat--) {
- unsigned long delay = jiffies +
- msecs_to_jiffies(ec_delay);
-@@ -241,8 +241,6 @@ static int ec_poll(struct acpi_ec *ec)
- }
- advance_transaction(ec, acpi_ec_read_status(ec));
- } while (time_before(jiffies, delay));
-- if (acpi_ec_read_status(ec) & ACPI_EC_FLAG_IBF)
-- break;
- pr_debug(PREFIX "controller reset, restart transaction\n");
- spin_lock_irqsave(&ec->lock, flags);
- start_transaction(ec);
-diff --git a/drivers/block/drbd/drbd_main.c b/drivers/block/drbd/drbd_main.c
-index e98da67..54d03d4 100644
---- a/drivers/block/drbd/drbd_main.c
-+++ b/drivers/block/drbd/drbd_main.c
-@@ -2795,6 +2795,7 @@ void drbd_free_bc(struct drbd_backing_dev *ldev)
- blkdev_put(ldev->backing_bdev, FMODE_READ | FMODE_WRITE | FMODE_EXCL);
- blkdev_put(ldev->md_bdev, FMODE_READ | FMODE_WRITE | FMODE_EXCL);
-
-+ kfree(ldev->disk_conf);
- kfree(ldev);
- }
-
-diff --git a/drivers/block/drbd/drbd_receiver.c b/drivers/block/drbd/drbd_receiver.c
-index a9eccfc..2f5fffd 100644
---- a/drivers/block/drbd/drbd_receiver.c
-+++ b/drivers/block/drbd/drbd_receiver.c
-@@ -2661,7 +2661,6 @@ static int drbd_asb_recover_1p(struct drbd_conf *mdev) __must_hold(local)
- if (hg == -1 && mdev->state.role == R_PRIMARY) {
- enum drbd_state_rv rv2;
-
-- drbd_set_role(mdev, R_SECONDARY, 0);
- /* drbd_change_state() does not sleep while in SS_IN_TRANSIENT_STATE,
- * we might be here in C_WF_REPORT_PARAMS which is transient.
- * we do not need to wait for the after state change work either. */
-@@ -4659,8 +4658,8 @@ static int drbd_do_features(struct drbd_tconn *tconn)
- #if !defined(CONFIG_CRYPTO_HMAC) && !defined(CONFIG_CRYPTO_HMAC_MODULE)
- static int drbd_do_auth(struct drbd_tconn *tconn)
- {
-- dev_err(DEV, "This kernel was build without CONFIG_CRYPTO_HMAC.\n");
-- dev_err(DEV, "You need to disable 'cram-hmac-alg' in drbd.conf.\n");
-+ conn_err(tconn, "This kernel was build without CONFIG_CRYPTO_HMAC.\n");
-+ conn_err(tconn, "You need to disable 'cram-hmac-alg' in drbd.conf.\n");
- return -1;
- }
- #else
-diff --git a/drivers/char/ipmi/ipmi_bt_sm.c b/drivers/char/ipmi/ipmi_bt_sm.c
-index cdd4c09f..a22a7a5 100644
---- a/drivers/char/ipmi/ipmi_bt_sm.c
-+++ b/drivers/char/ipmi/ipmi_bt_sm.c
-@@ -95,9 +95,9 @@ struct si_sm_data {
- enum bt_states state;
- unsigned char seq; /* BT sequence number */
- struct si_sm_io *io;
-- unsigned char write_data[IPMI_MAX_MSG_LENGTH];
-+ unsigned char write_data[IPMI_MAX_MSG_LENGTH + 2]; /* +2 for memcpy */
- int write_count;
-- unsigned char read_data[IPMI_MAX_MSG_LENGTH];
-+ unsigned char read_data[IPMI_MAX_MSG_LENGTH + 2]; /* +2 for memcpy */
- int read_count;
- int truncated;
- long timeout; /* microseconds countdown */
-diff --git a/drivers/char/ipmi/ipmi_devintf.c b/drivers/char/ipmi/ipmi_devintf.c
-index 9eb360f..d5a5f02 100644
---- a/drivers/char/ipmi/ipmi_devintf.c
-+++ b/drivers/char/ipmi/ipmi_devintf.c
-@@ -837,13 +837,25 @@ static long compat_ipmi_ioctl(struct file *filep, unsigned int cmd,
- return ipmi_ioctl(filep, cmd, arg);
- }
- }
-+
-+static long unlocked_compat_ipmi_ioctl(struct file *filep, unsigned int cmd,
-+ unsigned long arg)
-+{
-+ int ret;
-+
-+ mutex_lock(&ipmi_mutex);
-+ ret = compat_ipmi_ioctl(filep, cmd, arg);
-+ mutex_unlock(&ipmi_mutex);
-+
-+ return ret;
-+}
- #endif
-
- static const struct file_operations ipmi_fops = {
- .owner = THIS_MODULE,
- .unlocked_ioctl = ipmi_unlocked_ioctl,
- #ifdef CONFIG_COMPAT
-- .compat_ioctl = compat_ipmi_ioctl,
-+ .compat_ioctl = unlocked_compat_ipmi_ioctl,
- #endif
- .open = ipmi_open,
- .release = ipmi_release,
-diff --git a/drivers/cpufreq/intel_pstate.c b/drivers/cpufreq/intel_pstate.c
-index 6133ef5..d8a8c9b 100644
---- a/drivers/cpufreq/intel_pstate.c
-+++ b/drivers/cpufreq/intel_pstate.c
-@@ -48,12 +48,7 @@ static inline int32_t div_fp(int32_t x, int32_t y)
- }
-
- struct sample {
-- ktime_t start_time;
-- ktime_t end_time;
- int core_pct_busy;
-- int pstate_pct_busy;
-- u64 duration_us;
-- u64 idletime_us;
- u64 aperf;
- u64 mperf;
- int freq;
-@@ -91,8 +86,6 @@ struct cpudata {
- int min_pstate_count;
- int idle_mode;
-
-- ktime_t prev_sample;
-- u64 prev_idle_time_us;
- u64 prev_aperf;
- u64 prev_mperf;
- int sample_ptr;
-@@ -124,6 +117,8 @@ struct perf_limits {
- int min_perf_pct;
- int32_t max_perf;
- int32_t min_perf;
-+ int max_policy_pct;
-+ int max_sysfs_pct;
- };
-
- static struct perf_limits limits = {
-@@ -132,6 +127,8 @@ static struct perf_limits limits = {
- .max_perf = int_tofp(1),
- .min_perf_pct = 0,
- .min_perf = 0,
-+ .max_policy_pct = 100,
-+ .max_sysfs_pct = 100,
- };
-
- static inline void pid_reset(struct _pid *pid, int setpoint, int busy,
-@@ -302,7 +299,8 @@ static ssize_t store_max_perf_pct(struct kobject *a, struct attribute *b,
- if (ret != 1)
- return -EINVAL;
-
-- limits.max_perf_pct = clamp_t(int, input, 0 , 100);
-+ limits.max_sysfs_pct = clamp_t(int, input, 0 , 100);
-+ limits.max_perf_pct = min(limits.max_policy_pct, limits.max_sysfs_pct);
- limits.max_perf = div_fp(int_tofp(limits.max_perf_pct), int_tofp(100));
- return count;
- }
-@@ -450,48 +448,26 @@ static inline void intel_pstate_calc_busy(struct cpudata *cpu,
- struct sample *sample)
- {
- u64 core_pct;
-- sample->pstate_pct_busy = 100 - div64_u64(
-- sample->idletime_us * 100,
-- sample->duration_us);
- core_pct = div64_u64(sample->aperf * 100, sample->mperf);
- sample->freq = cpu->pstate.max_pstate * core_pct * 1000;
-
-- sample->core_pct_busy = div_s64((sample->pstate_pct_busy * core_pct),
-- 100);
-+ sample->core_pct_busy = core_pct;
- }
-
- static inline void intel_pstate_sample(struct cpudata *cpu)
- {
-- ktime_t now;
-- u64 idle_time_us;
- u64 aperf, mperf;
-
-- now = ktime_get();
-- idle_time_us = get_cpu_idle_time_us(cpu->cpu, NULL);
--
- rdmsrl(MSR_IA32_APERF, aperf);
- rdmsrl(MSR_IA32_MPERF, mperf);
-- /* for the first sample, don't actually record a sample, just
-- * set the baseline */
-- if (cpu->prev_idle_time_us > 0) {
-- cpu->sample_ptr = (cpu->sample_ptr + 1) % SAMPLE_COUNT;
-- cpu->samples[cpu->sample_ptr].start_time = cpu->prev_sample;
-- cpu->samples[cpu->sample_ptr].end_time = now;
-- cpu->samples[cpu->sample_ptr].duration_us =
-- ktime_us_delta(now, cpu->prev_sample);
-- cpu->samples[cpu->sample_ptr].idletime_us =
-- idle_time_us - cpu->prev_idle_time_us;
--
-- cpu->samples[cpu->sample_ptr].aperf = aperf;
-- cpu->samples[cpu->sample_ptr].mperf = mperf;
-- cpu->samples[cpu->sample_ptr].aperf -= cpu->prev_aperf;
-- cpu->samples[cpu->sample_ptr].mperf -= cpu->prev_mperf;
--
-- intel_pstate_calc_busy(cpu, &cpu->samples[cpu->sample_ptr]);
-- }
-+ cpu->sample_ptr = (cpu->sample_ptr + 1) % SAMPLE_COUNT;
-+ cpu->samples[cpu->sample_ptr].aperf = aperf;
-+ cpu->samples[cpu->sample_ptr].mperf = mperf;
-+ cpu->samples[cpu->sample_ptr].aperf -= cpu->prev_aperf;
-+ cpu->samples[cpu->sample_ptr].mperf -= cpu->prev_mperf;
-+
-+ intel_pstate_calc_busy(cpu, &cpu->samples[cpu->sample_ptr]);
-
-- cpu->prev_sample = now;
-- cpu->prev_idle_time_us = idle_time_us;
- cpu->prev_aperf = aperf;
- cpu->prev_mperf = mperf;
- }
-@@ -575,22 +551,16 @@ static void intel_pstate_timer_func(unsigned long __data)
- struct cpudata *cpu = (struct cpudata *) __data;
-
- intel_pstate_sample(cpu);
-+ intel_pstate_adjust_busy_pstate(cpu);
-
-- if (!cpu->idle_mode)
-- intel_pstate_adjust_busy_pstate(cpu);
-- else
-- intel_pstate_adjust_idle_pstate(cpu);
--
--#if defined(XPERF_FIX)
- if (cpu->pstate.current_pstate == cpu->pstate.min_pstate) {
- cpu->min_pstate_count++;
- if (!(cpu->min_pstate_count % 5)) {
- intel_pstate_set_pstate(cpu, cpu->pstate.max_pstate);
-- intel_pstate_idle_mode(cpu);
- }
- } else
- cpu->min_pstate_count = 0;
--#endif
-+
- intel_pstate_set_sample_time(cpu);
- }
-
-@@ -670,8 +640,9 @@ static int intel_pstate_set_policy(struct cpufreq_policy *policy)
- limits.min_perf_pct = clamp_t(int, limits.min_perf_pct, 0 , 100);
- limits.min_perf = div_fp(int_tofp(limits.min_perf_pct), int_tofp(100));
-
-- limits.max_perf_pct = policy->max * 100 / policy->cpuinfo.max_freq;
-- limits.max_perf_pct = clamp_t(int, limits.max_perf_pct, 0 , 100);
-+ limits.max_policy_pct = policy->max * 100 / policy->cpuinfo.max_freq;
-+ limits.max_policy_pct = clamp_t(int, limits.max_policy_pct, 0 , 100);
-+ limits.max_perf_pct = min(limits.max_policy_pct, limits.max_sysfs_pct);
- limits.max_perf = div_fp(int_tofp(limits.max_perf_pct), int_tofp(100));
-
- if (policy->policy == CPUFREQ_POLICY_PERFORMANCE) {
-diff --git a/drivers/dma/of-dma.c b/drivers/dma/of-dma.c
-index 69d04d2..09c7ad1 100644
---- a/drivers/dma/of-dma.c
-+++ b/drivers/dma/of-dma.c
-@@ -93,6 +93,7 @@ int of_dma_controller_register(struct device_node *np,
- {
- struct of_dma *ofdma;
- int nbcells;
-+ const __be32 *prop;
-
- if (!np || !of_dma_xlate) {
- pr_err("%s: not enough information provided\n", __func__);
-@@ -103,8 +104,11 @@ int of_dma_controller_register(struct device_node *np,
- if (!ofdma)
- return -ENOMEM;
-
-- nbcells = be32_to_cpup(of_get_property(np, "#dma-cells", NULL));
-- if (!nbcells) {
-+ prop = of_get_property(np, "#dma-cells", NULL);
-+ if (prop)
-+ nbcells = be32_to_cpup(prop);
-+
-+ if (!prop || !nbcells) {
- pr_err("%s: #dma-cells property is missing or invalid\n",
- __func__);
- kfree(ofdma);
-diff --git a/drivers/dma/pch_dma.c b/drivers/dma/pch_dma.c
-index d01faeb..ce3dc3e 100644
---- a/drivers/dma/pch_dma.c
-+++ b/drivers/dma/pch_dma.c
-@@ -476,7 +476,7 @@ static struct pch_dma_desc *pdc_desc_get(struct pch_dma_chan *pd_chan)
- dev_dbg(chan2dev(&pd_chan->chan), "scanned %d descriptors\n", i);
-
- if (!ret) {
-- ret = pdc_alloc_desc(&pd_chan->chan, GFP_NOIO);
-+ ret = pdc_alloc_desc(&pd_chan->chan, GFP_ATOMIC);
- if (ret) {
- spin_lock(&pd_chan->lock);
- pd_chan->descs_allocated++;
-diff --git a/drivers/gpu/drm/drm_crtc.c b/drivers/gpu/drm/drm_crtc.c
-index dd64a06..016c5d8 100644
---- a/drivers/gpu/drm/drm_crtc.c
-+++ b/drivers/gpu/drm/drm_crtc.c
-@@ -78,6 +78,10 @@ void drm_warn_on_modeset_not_all_locked(struct drm_device *dev)
- {
- struct drm_crtc *crtc;
-
-+ /* Locking is currently fubar in the panic handler. */
-+ if (oops_in_progress)
-+ return;
-+
- list_for_each_entry(crtc, &dev->mode_config.crtc_list, head)
- WARN_ON(!mutex_is_locked(&crtc->mutex));
-
-diff --git a/drivers/gpu/drm/drm_mm.c b/drivers/gpu/drm/drm_mm.c
-index db1e2d6..07cf99c 100644
---- a/drivers/gpu/drm/drm_mm.c
-+++ b/drivers/gpu/drm/drm_mm.c
-@@ -755,33 +755,35 @@ void drm_mm_debug_table(struct drm_mm *mm, const char *prefix)
- EXPORT_SYMBOL(drm_mm_debug_table);
-
- #if defined(CONFIG_DEBUG_FS)
--int drm_mm_dump_table(struct seq_file *m, struct drm_mm *mm)
-+static unsigned long drm_mm_dump_hole(struct seq_file *m, struct drm_mm_node *entry)
- {
-- struct drm_mm_node *entry;
-- unsigned long total_used = 0, total_free = 0, total = 0;
- unsigned long hole_start, hole_end, hole_size;
-
-- hole_start = drm_mm_hole_node_start(&mm->head_node);
-- hole_end = drm_mm_hole_node_end(&mm->head_node);
-- hole_size = hole_end - hole_start;
-- if (hole_size)
-+ if (entry->hole_follows) {
-+ hole_start = drm_mm_hole_node_start(entry);
-+ hole_end = drm_mm_hole_node_end(entry);
-+ hole_size = hole_end - hole_start;
- seq_printf(m, "0x%08lx-0x%08lx: 0x%08lx: free\n",
- hole_start, hole_end, hole_size);
-- total_free += hole_size;
-+ return hole_size;
-+ }
-+
-+ return 0;
-+}
-+
-+int drm_mm_dump_table(struct seq_file *m, struct drm_mm *mm)
-+{
-+ struct drm_mm_node *entry;
-+ unsigned long total_used = 0, total_free = 0, total = 0;
-+
-+ total_free += drm_mm_dump_hole(m, &mm->head_node);
-
- drm_mm_for_each_node(entry, mm) {
- seq_printf(m, "0x%08lx-0x%08lx: 0x%08lx: used\n",
- entry->start, entry->start + entry->size,
- entry->size);
- total_used += entry->size;
-- if (entry->hole_follows) {
-- hole_start = drm_mm_hole_node_start(entry);
-- hole_end = drm_mm_hole_node_end(entry);
-- hole_size = hole_end - hole_start;
-- seq_printf(m, "0x%08lx-0x%08lx: 0x%08lx: free\n",
-- hole_start, hole_end, hole_size);
-- total_free += hole_size;
-- }
-+ total_free += drm_mm_dump_hole(m, entry);
- }
- total = total_free + total_used;
-
-diff --git a/drivers/gpu/drm/i915/intel_fb.c b/drivers/gpu/drm/i915/intel_fb.c
-index 981bdce..898832b 100644
---- a/drivers/gpu/drm/i915/intel_fb.c
-+++ b/drivers/gpu/drm/i915/intel_fb.c
-@@ -261,10 +261,22 @@ void intel_fbdev_fini(struct drm_device *dev)
- void intel_fbdev_set_suspend(struct drm_device *dev, int state)
- {
- drm_i915_private_t *dev_priv = dev->dev_private;
-- if (!dev_priv->fbdev)
-+ struct intel_fbdev *ifbdev = dev_priv->fbdev;
-+ struct fb_info *info;
-+
-+ if (!ifbdev)
- return;
-
-- fb_set_suspend(dev_priv->fbdev->helper.fbdev, state);
-+ info = ifbdev->helper.fbdev;
-+
-+ /* On resume from hibernation: If the object is shmemfs backed, it has
-+ * been restored from swap. If the object is stolen however, it will be
-+ * full of whatever garbage was left in there.
-+ */
-+ if (!state && ifbdev->ifb.obj->stolen)
-+ memset_io(info->screen_base, 0, info->screen_size);
-+
-+ fb_set_suspend(info, state);
- }
-
- MODULE_LICENSE("GPL and additional rights");
-diff --git a/drivers/gpu/drm/mgag200/mgag200_mode.c b/drivers/gpu/drm/mgag200/mgag200_mode.c
-index 78d8e919..713dd70 100644
---- a/drivers/gpu/drm/mgag200/mgag200_mode.c
-+++ b/drivers/gpu/drm/mgag200/mgag200_mode.c
-@@ -189,12 +189,12 @@ static int mga_g200wb_set_plls(struct mga_device *mdev, long clock)
- WREG8(DAC_INDEX, MGA1064_PIX_CLK_CTL);
- tmp = RREG8(DAC_DATA);
- tmp |= MGA1064_PIX_CLK_CTL_CLK_DIS;
-- WREG_DAC(MGA1064_PIX_CLK_CTL_CLK_DIS, tmp);
-+ WREG8(DAC_DATA, tmp);
-
- WREG8(DAC_INDEX, MGA1064_REMHEADCTL);
- tmp = RREG8(DAC_DATA);
- tmp |= MGA1064_REMHEADCTL_CLKDIS;
-- WREG_DAC(MGA1064_REMHEADCTL, tmp);
-+ WREG8(DAC_DATA, tmp);
-
- /* select PLL Set C */
- tmp = RREG8(MGAREG_MEM_MISC_READ);
-@@ -204,7 +204,7 @@ static int mga_g200wb_set_plls(struct mga_device *mdev, long clock)
- WREG8(DAC_INDEX, MGA1064_PIX_CLK_CTL);
- tmp = RREG8(DAC_DATA);
- tmp |= MGA1064_PIX_CLK_CTL_CLK_POW_DOWN | 0x80;
-- WREG_DAC(MGA1064_PIX_CLK_CTL, tmp);
-+ WREG8(DAC_DATA, tmp);
-
- udelay(500);
-
-@@ -212,7 +212,7 @@ static int mga_g200wb_set_plls(struct mga_device *mdev, long clock)
- WREG8(DAC_INDEX, MGA1064_VREF_CTL);
- tmp = RREG8(DAC_DATA);
- tmp &= ~0x04;
-- WREG_DAC(MGA1064_VREF_CTL, tmp);
-+ WREG8(DAC_DATA, tmp);
-
- udelay(50);
-
-@@ -236,13 +236,13 @@ static int mga_g200wb_set_plls(struct mga_device *mdev, long clock)
- tmp = RREG8(DAC_DATA);
- tmp &= ~MGA1064_PIX_CLK_CTL_SEL_MSK;
- tmp |= MGA1064_PIX_CLK_CTL_SEL_PLL;
-- WREG_DAC(MGA1064_PIX_CLK_CTL, tmp);
-+ WREG8(DAC_DATA, tmp);
-
- WREG8(DAC_INDEX, MGA1064_REMHEADCTL);
- tmp = RREG8(DAC_DATA);
- tmp &= ~MGA1064_REMHEADCTL_CLKSL_MSK;
- tmp |= MGA1064_REMHEADCTL_CLKSL_PLL;
-- WREG_DAC(MGA1064_REMHEADCTL, tmp);
-+ WREG8(DAC_DATA, tmp);
-
- /* reset dotclock rate bit */
- WREG8(MGAREG_SEQ_INDEX, 1);
-@@ -253,7 +253,7 @@ static int mga_g200wb_set_plls(struct mga_device *mdev, long clock)
- WREG8(DAC_INDEX, MGA1064_PIX_CLK_CTL);
- tmp = RREG8(DAC_DATA);
- tmp &= ~MGA1064_PIX_CLK_CTL_CLK_DIS;
-- WREG_DAC(MGA1064_PIX_CLK_CTL, tmp);
-+ WREG8(DAC_DATA, tmp);
-
- vcount = RREG8(MGAREG_VCOUNT);
-
-@@ -318,7 +318,7 @@ static int mga_g200ev_set_plls(struct mga_device *mdev, long clock)
- WREG8(DAC_INDEX, MGA1064_PIX_CLK_CTL);
- tmp = RREG8(DAC_DATA);
- tmp |= MGA1064_PIX_CLK_CTL_CLK_DIS;
-- WREG_DAC(MGA1064_PIX_CLK_CTL_CLK_DIS, tmp);
-+ WREG8(DAC_DATA, tmp);
-
- tmp = RREG8(MGAREG_MEM_MISC_READ);
- tmp |= 0x3 << 2;
-@@ -326,12 +326,12 @@ static int mga_g200ev_set_plls(struct mga_device *mdev, long clock)
-
- WREG8(DAC_INDEX, MGA1064_PIX_PLL_STAT);
- tmp = RREG8(DAC_DATA);
-- WREG_DAC(MGA1064_PIX_PLL_STAT, tmp & ~0x40);
-+ WREG8(DAC_DATA, tmp & ~0x40);
-
- WREG8(DAC_INDEX, MGA1064_PIX_CLK_CTL);
- tmp = RREG8(DAC_DATA);
- tmp |= MGA1064_PIX_CLK_CTL_CLK_POW_DOWN;
-- WREG_DAC(MGA1064_PIX_CLK_CTL, tmp);
-+ WREG8(DAC_DATA, tmp);
-
- WREG_DAC(MGA1064_EV_PIX_PLLC_M, m);
- WREG_DAC(MGA1064_EV_PIX_PLLC_N, n);
-@@ -342,7 +342,7 @@ static int mga_g200ev_set_plls(struct mga_device *mdev, long clock)
- WREG8(DAC_INDEX, MGA1064_PIX_CLK_CTL);
- tmp = RREG8(DAC_DATA);
- tmp &= ~MGA1064_PIX_CLK_CTL_CLK_POW_DOWN;
-- WREG_DAC(MGA1064_PIX_CLK_CTL, tmp);
-+ WREG8(DAC_DATA, tmp);
-
- udelay(500);
-
-@@ -350,11 +350,11 @@ static int mga_g200ev_set_plls(struct mga_device *mdev, long clock)
- tmp = RREG8(DAC_DATA);
- tmp &= ~MGA1064_PIX_CLK_CTL_SEL_MSK;
- tmp |= MGA1064_PIX_CLK_CTL_SEL_PLL;
-- WREG_DAC(MGA1064_PIX_CLK_CTL, tmp);
-+ WREG8(DAC_DATA, tmp);
-
- WREG8(DAC_INDEX, MGA1064_PIX_PLL_STAT);
- tmp = RREG8(DAC_DATA);
-- WREG_DAC(MGA1064_PIX_PLL_STAT, tmp | 0x40);
-+ WREG8(DAC_DATA, tmp | 0x40);
-
- tmp = RREG8(MGAREG_MEM_MISC_READ);
- tmp |= (0x3 << 2);
-@@ -363,7 +363,7 @@ static int mga_g200ev_set_plls(struct mga_device *mdev, long clock)
- WREG8(DAC_INDEX, MGA1064_PIX_CLK_CTL);
- tmp = RREG8(DAC_DATA);
- tmp &= ~MGA1064_PIX_CLK_CTL_CLK_DIS;
-- WREG_DAC(MGA1064_PIX_CLK_CTL, tmp);
-+ WREG8(DAC_DATA, tmp);
-
- return 0;
- }
-@@ -416,7 +416,7 @@ static int mga_g200eh_set_plls(struct mga_device *mdev, long clock)
- WREG8(DAC_INDEX, MGA1064_PIX_CLK_CTL);
- tmp = RREG8(DAC_DATA);
- tmp |= MGA1064_PIX_CLK_CTL_CLK_DIS;
-- WREG_DAC(MGA1064_PIX_CLK_CTL_CLK_DIS, tmp);
-+ WREG8(DAC_DATA, tmp);
-
- tmp = RREG8(MGAREG_MEM_MISC_READ);
- tmp |= 0x3 << 2;
-@@ -425,7 +425,7 @@ static int mga_g200eh_set_plls(struct mga_device *mdev, long clock)
- WREG8(DAC_INDEX, MGA1064_PIX_CLK_CTL);
- tmp = RREG8(DAC_DATA);
- tmp |= MGA1064_PIX_CLK_CTL_CLK_POW_DOWN;
-- WREG_DAC(MGA1064_PIX_CLK_CTL, tmp);
-+ WREG8(DAC_DATA, tmp);
-
- udelay(500);
-
-@@ -439,13 +439,13 @@ static int mga_g200eh_set_plls(struct mga_device *mdev, long clock)
- tmp = RREG8(DAC_DATA);
- tmp &= ~MGA1064_PIX_CLK_CTL_SEL_MSK;
- tmp |= MGA1064_PIX_CLK_CTL_SEL_PLL;
-- WREG_DAC(MGA1064_PIX_CLK_CTL, tmp);
-+ WREG8(DAC_DATA, tmp);
-
- WREG8(DAC_INDEX, MGA1064_PIX_CLK_CTL);
- tmp = RREG8(DAC_DATA);
- tmp &= ~MGA1064_PIX_CLK_CTL_CLK_DIS;
- tmp &= ~MGA1064_PIX_CLK_CTL_CLK_POW_DOWN;
-- WREG_DAC(MGA1064_PIX_CLK_CTL, tmp);
-+ WREG8(DAC_DATA, tmp);
-
- vcount = RREG8(MGAREG_VCOUNT);
-
-@@ -515,12 +515,12 @@ static int mga_g200er_set_plls(struct mga_device *mdev, long clock)
- WREG8(DAC_INDEX, MGA1064_PIX_CLK_CTL);
- tmp = RREG8(DAC_DATA);
- tmp |= MGA1064_PIX_CLK_CTL_CLK_DIS;
-- WREG_DAC(MGA1064_PIX_CLK_CTL_CLK_DIS, tmp);
-+ WREG8(DAC_DATA, tmp);
-
- WREG8(DAC_INDEX, MGA1064_REMHEADCTL);
- tmp = RREG8(DAC_DATA);
- tmp |= MGA1064_REMHEADCTL_CLKDIS;
-- WREG_DAC(MGA1064_REMHEADCTL, tmp);
-+ WREG8(DAC_DATA, tmp);
-
- tmp = RREG8(MGAREG_MEM_MISC_READ);
- tmp |= (0x3<<2) | 0xc0;
-@@ -530,7 +530,7 @@ static int mga_g200er_set_plls(struct mga_device *mdev, long clock)
- tmp = RREG8(DAC_DATA);
- tmp &= ~MGA1064_PIX_CLK_CTL_CLK_DIS;
- tmp |= MGA1064_PIX_CLK_CTL_CLK_POW_DOWN;
-- WREG_DAC(MGA1064_PIX_CLK_CTL, tmp);
-+ WREG8(DAC_DATA, tmp);
-
- udelay(500);
-
-@@ -657,12 +657,26 @@ static void mga_g200wb_commit(struct drm_crtc *crtc)
- WREG_DAC(MGA1064_GEN_IO_DATA, tmp);
- }
-
--
-+/*
-+ This is how the framebuffer base address is stored in g200 cards:
-+ * Assume @offset is the gpu_addr variable of the framebuffer object
-+ * Then addr is the number of _pixels_ (not bytes) from the start of
-+ VRAM to the first pixel we want to display. (divided by 2 for 32bit
-+ framebuffers)
-+ * addr is stored in the CRTCEXT0, CRTCC and CRTCD registers
-+ addr<20> -> CRTCEXT0<6>
-+ addr<19-16> -> CRTCEXT0<3-0>
-+ addr<15-8> -> CRTCC<7-0>
-+ addr<7-0> -> CRTCD<7-0>
-+ CRTCEXT0 has to be programmed last to trigger an update and make the
-+ new addr variable take effect.
-+ */
- void mga_set_start_address(struct drm_crtc *crtc, unsigned offset)
- {
- struct mga_device *mdev = crtc->dev->dev_private;
- u32 addr;
- int count;
-+ u8 crtcext0;
-
- while (RREG8(0x1fda) & 0x08);
- while (!(RREG8(0x1fda) & 0x08));
-@@ -670,10 +684,17 @@ void mga_set_start_address(struct drm_crtc *crtc, unsigned offset)
- count = RREG8(MGAREG_VCOUNT) + 2;
- while (RREG8(MGAREG_VCOUNT) < count);
-
-- addr = offset >> 2;
-+ WREG8(MGAREG_CRTCEXT_INDEX, 0);
-+ crtcext0 = RREG8(MGAREG_CRTCEXT_DATA);
-+ crtcext0 &= 0xB0;
-+ addr = offset / 8;
-+ /* Can't store addresses any higher than that...
-+ but we also don't have more than 16MB of memory, so it should be fine. */
-+ WARN_ON(addr > 0x1fffff);
-+ crtcext0 |= (!!(addr & (1<<20)))<<6;
- WREG_CRT(0x0d, (u8)(addr & 0xff));
- WREG_CRT(0x0c, (u8)(addr >> 8) & 0xff);
-- WREG_CRT(0xaf, (u8)(addr >> 16) & 0xf);
-+ WREG_ECRT(0x0, ((u8)(addr >> 16) & 0xf) | crtcext0);
- }
-
-
-diff --git a/drivers/gpu/drm/radeon/r300_cmdbuf.c b/drivers/gpu/drm/radeon/r300_cmdbuf.c
-index 865e2c9..60170ea 100644
---- a/drivers/gpu/drm/radeon/r300_cmdbuf.c
-+++ b/drivers/gpu/drm/radeon/r300_cmdbuf.c
-@@ -75,7 +75,7 @@ static int r300_emit_cliprects(drm_radeon_private_t *dev_priv,
- OUT_RING(CP_PACKET0(R300_RE_CLIPRECT_TL_0, nr * 2 - 1));
-
- for (i = 0; i < nr; ++i) {
-- if (DRM_COPY_FROM_USER_UNCHECKED
-+ if (DRM_COPY_FROM_USER
- (&box, &cmdbuf->boxes[n + i], sizeof(box))) {
- DRM_ERROR("copy cliprect faulted\n");
- return -EFAULT;
-diff --git a/drivers/gpu/drm/radeon/radeon_drv.c b/drivers/gpu/drm/radeon/radeon_drv.c
-index 66a7f0f..96cf439 100644
---- a/drivers/gpu/drm/radeon/radeon_drv.c
-+++ b/drivers/gpu/drm/radeon/radeon_drv.c
-@@ -144,7 +144,7 @@ static inline void radeon_unregister_atpx_handler(void) {}
- #endif
-
- int radeon_no_wb;
--int radeon_modeset = 1;
-+int radeon_modeset = -1;
- int radeon_dynclks = -1;
- int radeon_r4xx_atom = 0;
- int radeon_agpmode = 0;
-@@ -449,6 +449,16 @@ static struct pci_driver radeon_kms_pci_driver = {
-
- static int __init radeon_init(void)
- {
-+#ifdef CONFIG_VGA_CONSOLE
-+ if (vgacon_text_force() && radeon_modeset == -1) {
-+ DRM_INFO("VGACON disable radeon kernel modesetting.\n");
-+ radeon_modeset = 0;
-+ }
-+#endif
-+ /* set to modesetting by default if not nomodeset */
-+ if (radeon_modeset == -1)
-+ radeon_modeset = 1;
-+
- if (radeon_modeset == 1) {
- DRM_INFO("radeon kernel modesetting enabled.\n");
- driver = &kms_driver;
-diff --git a/drivers/hid/hid-core.c b/drivers/hid/hid-core.c
-index aa341d1..e6dbf09 100644
---- a/drivers/hid/hid-core.c
-+++ b/drivers/hid/hid-core.c
-@@ -1702,6 +1702,7 @@ static const struct hid_device_id hid_have_special_driver[] = {
- { HID_USB_DEVICE(USB_VENDOR_ID_SONY, USB_DEVICE_ID_SONY_NAVIGATION_CONTROLLER) },
- { HID_BLUETOOTH_DEVICE(USB_VENDOR_ID_SONY, USB_DEVICE_ID_SONY_PS3_CONTROLLER) },
- { HID_USB_DEVICE(USB_VENDOR_ID_SONY, USB_DEVICE_ID_SONY_VAIO_VGX_MOUSE) },
-+ { HID_USB_DEVICE(USB_VENDOR_ID_SONY, USB_DEVICE_ID_SONY_VAIO_VGP_MOUSE) },
- { HID_USB_DEVICE(USB_VENDOR_ID_STEELSERIES, USB_DEVICE_ID_STEELSERIES_SRWS1) },
- { HID_USB_DEVICE(USB_VENDOR_ID_SUNPLUS, USB_DEVICE_ID_SUNPLUS_WDESKTOP) },
- { HID_USB_DEVICE(USB_VENDOR_ID_THINGM, USB_DEVICE_ID_BLINK1) },
-diff --git a/drivers/md/dm-bufio.c b/drivers/md/dm-bufio.c
-index c608313..0387e05 100644
---- a/drivers/md/dm-bufio.c
-+++ b/drivers/md/dm-bufio.c
-@@ -319,6 +319,9 @@ static void __cache_size_refresh(void)
- static void *alloc_buffer_data(struct dm_bufio_client *c, gfp_t gfp_mask,
- enum data_mode *data_mode)
- {
-+ unsigned noio_flag;
-+ void *ptr;
-+
- if (c->block_size <= DM_BUFIO_BLOCK_SIZE_SLAB_LIMIT) {
- *data_mode = DATA_MODE_SLAB;
- return kmem_cache_alloc(DM_BUFIO_CACHE(c), gfp_mask);
-@@ -332,7 +335,26 @@ static void *alloc_buffer_data(struct dm_bufio_client *c, gfp_t gfp_mask,
- }
-
- *data_mode = DATA_MODE_VMALLOC;
-- return __vmalloc(c->block_size, gfp_mask, PAGE_KERNEL);
-+
-+ /*
-+ * __vmalloc allocates the data pages and auxiliary structures with
-+ * gfp_flags that were specified, but pagetables are always allocated
-+ * with GFP_KERNEL, no matter what was specified as gfp_mask.
-+ *
-+ * Consequently, we must set per-process flag PF_MEMALLOC_NOIO so that
-+ * all allocations done by this process (including pagetables) are done
-+ * as if GFP_NOIO was specified.
-+ */
-+
-+ if (gfp_mask & __GFP_NORETRY)
-+ noio_flag = memalloc_noio_save();
-+
-+ ptr = __vmalloc(c->block_size, gfp_mask, PAGE_KERNEL);
-+
-+ if (gfp_mask & __GFP_NORETRY)
-+ memalloc_noio_restore(noio_flag);
-+
-+ return ptr;
- }
-
- /*
-diff --git a/drivers/md/dm-cache-target.c b/drivers/md/dm-cache-target.c
-index 1074409..6feaba2 100644
---- a/drivers/md/dm-cache-target.c
-+++ b/drivers/md/dm-cache-target.c
-@@ -1971,6 +1971,7 @@ static int cache_create(struct cache_args *ca, struct cache **result)
- atomic_set(&cache->nr_migrations, 0);
- init_waitqueue_head(&cache->migration_wait);
-
-+ r = -ENOMEM;
- cache->nr_dirty = 0;
- cache->dirty_bitset = alloc_bitset(from_cblock(cache->cache_size));
- if (!cache->dirty_bitset) {
-diff --git a/drivers/md/dm-snap.c b/drivers/md/dm-snap.c
-index c0e0702..c434e5a 100644
---- a/drivers/md/dm-snap.c
-+++ b/drivers/md/dm-snap.c
-@@ -1121,6 +1121,7 @@ static int snapshot_ctr(struct dm_target *ti, unsigned int argc, char **argv)
- s->pending_pool = mempool_create_slab_pool(MIN_IOS, pending_cache);
- if (!s->pending_pool) {
- ti->error = "Could not allocate mempool for pending exceptions";
-+ r = -ENOMEM;
- goto bad_pending_pool;
- }
-
-diff --git a/drivers/md/dm-stripe.c b/drivers/md/dm-stripe.c
-index d8837d3..7b8b2b9 100644
---- a/drivers/md/dm-stripe.c
-+++ b/drivers/md/dm-stripe.c
-@@ -94,7 +94,7 @@ static int get_stripe(struct dm_target *ti, struct stripe_c *sc,
- static int stripe_ctr(struct dm_target *ti, unsigned int argc, char **argv)
- {
- struct stripe_c *sc;
-- sector_t width;
-+ sector_t width, tmp_len;
- uint32_t stripes;
- uint32_t chunk_size;
- int r;
-@@ -116,15 +116,16 @@ static int stripe_ctr(struct dm_target *ti, unsigned int argc, char **argv)
- }
-
- width = ti->len;
-- if (sector_div(width, chunk_size)) {
-+ if (sector_div(width, stripes)) {
- ti->error = "Target length not divisible by "
-- "chunk size";
-+ "number of stripes";
- return -EINVAL;
- }
-
-- if (sector_div(width, stripes)) {
-+ tmp_len = width;
-+ if (sector_div(tmp_len, chunk_size)) {
- ti->error = "Target length not divisible by "
-- "number of stripes";
-+ "chunk size";
- return -EINVAL;
- }
-
-diff --git a/drivers/md/dm-table.c b/drivers/md/dm-table.c
-index e50dad0..1ff252a 100644
---- a/drivers/md/dm-table.c
-+++ b/drivers/md/dm-table.c
-@@ -1442,7 +1442,7 @@ static bool dm_table_supports_write_same(struct dm_table *t)
- return false;
-
- if (!ti->type->iterate_devices ||
-- !ti->type->iterate_devices(ti, device_not_write_same_capable, NULL))
-+ ti->type->iterate_devices(ti, device_not_write_same_capable, NULL))
- return false;
- }
-
-diff --git a/drivers/net/ethernet/3com/3c509.c b/drivers/net/ethernet/3com/3c509.c
-index f36ff99..adb4bf5 100644
---- a/drivers/net/ethernet/3com/3c509.c
-+++ b/drivers/net/ethernet/3com/3c509.c
-@@ -306,6 +306,7 @@ static int el3_isa_match(struct device *pdev, unsigned int ndev)
- if (!dev)
- return -ENOMEM;
-
-+ SET_NETDEV_DEV(dev, pdev);
- netdev_boot_setup_check(dev);
-
- if (!request_region(ioaddr, EL3_IO_EXTENT, "3c509-isa")) {
-@@ -595,6 +596,7 @@ static int __init el3_eisa_probe (struct device *device)
- return -ENOMEM;
- }
-
-+ SET_NETDEV_DEV(dev, device);
- netdev_boot_setup_check(dev);
-
- el3_dev_fill(dev, phys_addr, ioaddr, irq, if_port, EL3_EISA);
-diff --git a/drivers/net/ethernet/3com/3c59x.c b/drivers/net/ethernet/3com/3c59x.c
-index 1928e20..072c6f1 100644
---- a/drivers/net/ethernet/3com/3c59x.c
-+++ b/drivers/net/ethernet/3com/3c59x.c
-@@ -632,7 +632,6 @@ struct vortex_private {
- pm_state_valid:1, /* pci_dev->saved_config_space has sane contents */
- open:1,
- medialock:1,
-- must_free_region:1, /* Flag: if zero, Cardbus owns the I/O region */
- large_frames:1, /* accept large frames */
- handling_irq:1; /* private in_irq indicator */
- /* {get|set}_wol operations are already serialized by rtnl.
-@@ -951,7 +950,7 @@ static int vortex_eisa_remove(struct device *device)
-
- unregister_netdev(dev);
- iowrite16(TotalReset|0x14, ioaddr + EL3_CMD);
-- release_region(dev->base_addr, VORTEX_TOTAL_SIZE);
-+ release_region(edev->base_addr, VORTEX_TOTAL_SIZE);
-
- free_netdev(dev);
- return 0;
-@@ -1012,6 +1011,12 @@ static int vortex_init_one(struct pci_dev *pdev,
- if (rc < 0)
- goto out;
-
-+ rc = pci_request_regions(pdev, DRV_NAME);
-+ if (rc < 0) {
-+ pci_disable_device(pdev);
-+ goto out;
-+ }
-+
- unit = vortex_cards_found;
-
- if (global_use_mmio < 0 && (unit >= MAX_UNITS || use_mmio[unit] < 0)) {
-@@ -1027,6 +1032,7 @@ static int vortex_init_one(struct pci_dev *pdev,
- if (!ioaddr) /* If mapping fails, fall-back to BAR 0... */
- ioaddr = pci_iomap(pdev, 0, 0);
- if (!ioaddr) {
-+ pci_release_regions(pdev);
- pci_disable_device(pdev);
- rc = -ENOMEM;
- goto out;
-@@ -1036,6 +1042,7 @@ static int vortex_init_one(struct pci_dev *pdev,
- ent->driver_data, unit);
- if (rc < 0) {
- pci_iounmap(pdev, ioaddr);
-+ pci_release_regions(pdev);
- pci_disable_device(pdev);
- goto out;
- }
-@@ -1178,11 +1185,6 @@ static int vortex_probe1(struct device *gendev, void __iomem *ioaddr, int irq,
-
- /* PCI-only startup logic */
- if (pdev) {
-- /* EISA resources already marked, so only PCI needs to do this here */
-- /* Ignore return value, because Cardbus drivers already allocate for us */
-- if (request_region(dev->base_addr, vci->io_size, print_name) != NULL)
-- vp->must_free_region = 1;
--
- /* enable bus-mastering if necessary */
- if (vci->flags & PCI_USES_MASTER)
- pci_set_master(pdev);
-@@ -1220,7 +1222,7 @@ static int vortex_probe1(struct device *gendev, void __iomem *ioaddr, int irq,
- &vp->rx_ring_dma);
- retval = -ENOMEM;
- if (!vp->rx_ring)
-- goto free_region;
-+ goto free_device;
-
- vp->tx_ring = (struct boom_tx_desc *)(vp->rx_ring + RX_RING_SIZE);
- vp->tx_ring_dma = vp->rx_ring_dma + sizeof(struct boom_rx_desc) * RX_RING_SIZE;
-@@ -1484,9 +1486,7 @@ free_ring:
- + sizeof(struct boom_tx_desc) * TX_RING_SIZE,
- vp->rx_ring,
- vp->rx_ring_dma);
--free_region:
-- if (vp->must_free_region)
-- release_region(dev->base_addr, vci->io_size);
-+free_device:
- free_netdev(dev);
- pr_err(PFX "vortex_probe1 fails. Returns %d\n", retval);
- out:
-@@ -3254,8 +3254,9 @@ static void vortex_remove_one(struct pci_dev *pdev)
- + sizeof(struct boom_tx_desc) * TX_RING_SIZE,
- vp->rx_ring,
- vp->rx_ring_dma);
-- if (vp->must_free_region)
-- release_region(dev->base_addr, vp->io_size);
-+
-+ pci_release_regions(pdev);
-+
- free_netdev(dev);
- }
-
-diff --git a/drivers/net/ethernet/sfc/mcdi.c b/drivers/net/ethernet/sfc/mcdi.c
-index 0095ce9..97dd8f18 100644
---- a/drivers/net/ethernet/sfc/mcdi.c
-+++ b/drivers/net/ethernet/sfc/mcdi.c
-@@ -667,7 +667,7 @@ fail:
- int efx_mcdi_get_board_cfg(struct efx_nic *efx, u8 *mac_address,
- u16 *fw_subtype_list, u32 *capabilities)
- {
-- uint8_t outbuf[MC_CMD_GET_BOARD_CFG_OUT_LENMIN];
-+ uint8_t outbuf[MC_CMD_GET_BOARD_CFG_OUT_LENMAX];
- size_t outlen, offset, i;
- int port_num = efx_port_num(efx);
- int rc;
-diff --git a/drivers/net/ethernet/tile/tilegx.c b/drivers/net/ethernet/tile/tilegx.c
-index 66e025a..f3c2d03 100644
---- a/drivers/net/ethernet/tile/tilegx.c
-+++ b/drivers/net/ethernet/tile/tilegx.c
-@@ -930,7 +930,7 @@ static int tile_net_setup_interrupts(struct net_device *dev)
- if (info->has_iqueue) {
- gxio_mpipe_request_notif_ring_interrupt(
- &context, cpu_x(cpu), cpu_y(cpu),
-- 1, ingress_irq, info->iqueue.ring);
-+ KERNEL_PL, ingress_irq, info->iqueue.ring);
- }
- }
-
-diff --git a/drivers/net/macvlan.c b/drivers/net/macvlan.c
-index 73abbc1..011062e 100644
---- a/drivers/net/macvlan.c
-+++ b/drivers/net/macvlan.c
-@@ -222,7 +222,8 @@ static rx_handler_result_t macvlan_handle_frame(struct sk_buff **pskb)
- }
-
- if (port->passthru)
-- vlan = list_first_entry(&port->vlans, struct macvlan_dev, list);
-+ vlan = list_first_or_null_rcu(&port->vlans,
-+ struct macvlan_dev, list);
- else
- vlan = macvlan_hash_lookup(port, eth->h_dest);
- if (vlan == NULL)
-@@ -807,7 +808,7 @@ int macvlan_common_newlink(struct net *src_net, struct net_device *dev,
- if (err < 0)
- goto upper_dev_unlink;
-
-- list_add_tail(&vlan->list, &port->vlans);
-+ list_add_tail_rcu(&vlan->list, &port->vlans);
- netif_stacked_transfer_operstate(lowerdev, dev);
-
- return 0;
-@@ -835,7 +836,7 @@ void macvlan_dellink(struct net_device *dev, struct list_head *head)
- {
- struct macvlan_dev *vlan = netdev_priv(dev);
-
-- list_del(&vlan->list);
-+ list_del_rcu(&vlan->list);
- unregister_netdevice_queue(dev, head);
- netdev_upper_dev_unlink(vlan->lowerdev, dev);
- }
-diff --git a/drivers/net/tun.c b/drivers/net/tun.c
-index 729ed53..755fa9e 100644
---- a/drivers/net/tun.c
-+++ b/drivers/net/tun.c
-@@ -1471,14 +1471,17 @@ static int tun_recvmsg(struct kiocb *iocb, struct socket *sock,
- if (!tun)
- return -EBADFD;
-
-- if (flags & ~(MSG_DONTWAIT|MSG_TRUNC))
-- return -EINVAL;
-+ if (flags & ~(MSG_DONTWAIT|MSG_TRUNC)) {
-+ ret = -EINVAL;
-+ goto out;
-+ }
- ret = tun_do_read(tun, tfile, iocb, m->msg_iov, total_len,
- flags & MSG_DONTWAIT);
- if (ret > total_len) {
- m->msg_flags |= MSG_TRUNC;
- ret = flags & MSG_TRUNC ? ret : total_len;
- }
-+out:
- tun_put(tun);
- return ret;
- }
-diff --git a/drivers/net/usb/asix_common.c b/drivers/net/usb/asix_common.c
-index f7f623a..577c72d 100644
---- a/drivers/net/usb/asix_common.c
-+++ b/drivers/net/usb/asix_common.c
-@@ -100,6 +100,9 @@ int asix_rx_fixup_internal(struct usbnet *dev, struct sk_buff *skb,
- netdev_err(dev->net, "asix_rx_fixup() Bad RX Length %d\n",
- rx->size);
- kfree_skb(rx->ax_skb);
-+ rx->ax_skb = NULL;
-+ rx->size = 0U;
-+
- return 0;
- }
-
-diff --git a/drivers/net/wireless/ath/ath9k/main.c b/drivers/net/wireless/ath/ath9k/main.c
-index 988372d..e509c37 100644
---- a/drivers/net/wireless/ath/ath9k/main.c
-+++ b/drivers/net/wireless/ath/ath9k/main.c
-@@ -1308,6 +1308,7 @@ static int ath9k_sta_add(struct ieee80211_hw *hw,
- struct ath_common *common = ath9k_hw_common(sc->sc_ah);
- struct ath_node *an = (struct ath_node *) sta->drv_priv;
- struct ieee80211_key_conf ps_key = { };
-+ int key;
-
- ath_node_attach(sc, sta, vif);
-
-@@ -1315,7 +1316,9 @@ static int ath9k_sta_add(struct ieee80211_hw *hw,
- vif->type != NL80211_IFTYPE_AP_VLAN)
- return 0;
-
-- an->ps_key = ath_key_config(common, vif, sta, &ps_key);
-+ key = ath_key_config(common, vif, sta, &ps_key);
-+ if (key > 0)
-+ an->ps_key = key;
-
- return 0;
- }
-@@ -1332,6 +1335,7 @@ static void ath9k_del_ps_key(struct ath_softc *sc,
- return;
-
- ath_key_delete(common, &ps_key);
-+ an->ps_key = 0;
- }
-
- static int ath9k_sta_remove(struct ieee80211_hw *hw,
-diff --git a/drivers/net/wireless/b43/dma.c b/drivers/net/wireless/b43/dma.c
-index 1221469..ee3d640 100644
---- a/drivers/net/wireless/b43/dma.c
-+++ b/drivers/net/wireless/b43/dma.c
-@@ -1733,6 +1733,25 @@ drop_recycle_buffer:
- sync_descbuffer_for_device(ring, dmaaddr, ring->rx_buffersize);
- }
-
-+void b43_dma_handle_rx_overflow(struct b43_dmaring *ring)
-+{
-+ int current_slot, previous_slot;
-+
-+ B43_WARN_ON(ring->tx);
-+
-+ /* Device has filled all buffers, drop all packets and let TCP
-+ * decrease speed.
-+ * Decrement RX index by one will let the device to see all slots
-+ * as free again
-+ */
-+ /*
-+ *TODO: How to increase rx_drop in mac80211?
-+ */
-+ current_slot = ring->ops->get_current_rxslot(ring);
-+ previous_slot = prev_slot(ring, current_slot);
-+ ring->ops->set_current_rxslot(ring, previous_slot);
-+}
-+
- void b43_dma_rx(struct b43_dmaring *ring)
- {
- const struct b43_dma_ops *ops = ring->ops;
-diff --git a/drivers/net/wireless/b43/dma.h b/drivers/net/wireless/b43/dma.h
-index 9fdd198..df8c8cd 100644
---- a/drivers/net/wireless/b43/dma.h
-+++ b/drivers/net/wireless/b43/dma.h
-@@ -9,7 +9,7 @@
- /* DMA-Interrupt reasons. */
- #define B43_DMAIRQ_FATALMASK ((1 << 10) | (1 << 11) | (1 << 12) \
- | (1 << 14) | (1 << 15))
--#define B43_DMAIRQ_NONFATALMASK (1 << 13)
-+#define B43_DMAIRQ_RDESC_UFLOW (1 << 13)
- #define B43_DMAIRQ_RX_DONE (1 << 16)
-
- /*** 32-bit DMA Engine. ***/
-@@ -295,6 +295,8 @@ int b43_dma_tx(struct b43_wldev *dev,
- void b43_dma_handle_txstatus(struct b43_wldev *dev,
- const struct b43_txstatus *status);
-
-+void b43_dma_handle_rx_overflow(struct b43_dmaring *ring);
-+
- void b43_dma_rx(struct b43_dmaring *ring);
-
- void b43_dma_direct_fifo_rx(struct b43_wldev *dev,
-diff --git a/drivers/net/wireless/b43/main.c b/drivers/net/wireless/b43/main.c
-index 0568273..64b637a 100644
---- a/drivers/net/wireless/b43/main.c
-+++ b/drivers/net/wireless/b43/main.c
-@@ -1895,30 +1895,18 @@ static void b43_do_interrupt_thread(struct b43_wldev *dev)
- }
- }
-
-- if (unlikely(merged_dma_reason & (B43_DMAIRQ_FATALMASK |
-- B43_DMAIRQ_NONFATALMASK))) {
-- if (merged_dma_reason & B43_DMAIRQ_FATALMASK) {
-- b43err(dev->wl, "Fatal DMA error: "
-- "0x%08X, 0x%08X, 0x%08X, "
-- "0x%08X, 0x%08X, 0x%08X\n",
-- dma_reason[0], dma_reason[1],
-- dma_reason[2], dma_reason[3],
-- dma_reason[4], dma_reason[5]);
-- b43err(dev->wl, "This device does not support DMA "
-+ if (unlikely(merged_dma_reason & (B43_DMAIRQ_FATALMASK))) {
-+ b43err(dev->wl,
-+ "Fatal DMA error: 0x%08X, 0x%08X, 0x%08X, 0x%08X, 0x%08X, 0x%08X\n",
-+ dma_reason[0], dma_reason[1],
-+ dma_reason[2], dma_reason[3],
-+ dma_reason[4], dma_reason[5]);
-+ b43err(dev->wl, "This device does not support DMA "
- "on your system. It will now be switched to PIO.\n");
-- /* Fall back to PIO transfers if we get fatal DMA errors! */
-- dev->use_pio = true;
-- b43_controller_restart(dev, "DMA error");
-- return;
-- }
-- if (merged_dma_reason & B43_DMAIRQ_NONFATALMASK) {
-- b43err(dev->wl, "DMA error: "
-- "0x%08X, 0x%08X, 0x%08X, "
-- "0x%08X, 0x%08X, 0x%08X\n",
-- dma_reason[0], dma_reason[1],
-- dma_reason[2], dma_reason[3],
-- dma_reason[4], dma_reason[5]);
-- }
-+ /* Fall back to PIO transfers if we get fatal DMA errors! */
-+ dev->use_pio = true;
-+ b43_controller_restart(dev, "DMA error");
-+ return;
- }
-
- if (unlikely(reason & B43_IRQ_UCODE_DEBUG))
-@@ -1937,6 +1925,11 @@ static void b43_do_interrupt_thread(struct b43_wldev *dev)
- handle_irq_noise(dev);
-
- /* Check the DMA reason registers for received data. */
-+ if (dma_reason[0] & B43_DMAIRQ_RDESC_UFLOW) {
-+ if (B43_DEBUG)
-+ b43warn(dev->wl, "RX descriptor underrun\n");
-+ b43_dma_handle_rx_overflow(dev->dma.rx_ring);
-+ }
- if (dma_reason[0] & B43_DMAIRQ_RX_DONE) {
- if (b43_using_pio_transfers(dev))
- b43_pio_rx(dev->pio.rx_queue);
-@@ -1994,7 +1987,7 @@ static irqreturn_t b43_do_interrupt(struct b43_wldev *dev)
- return IRQ_NONE;
-
- dev->dma_reason[0] = b43_read32(dev, B43_MMIO_DMA0_REASON)
-- & 0x0001DC00;
-+ & 0x0001FC00;
- dev->dma_reason[1] = b43_read32(dev, B43_MMIO_DMA1_REASON)
- & 0x0000DC00;
- dev->dma_reason[2] = b43_read32(dev, B43_MMIO_DMA2_REASON)
-@@ -3126,7 +3119,7 @@ static int b43_chip_init(struct b43_wldev *dev)
- b43_write32(dev, 0x018C, 0x02000000);
- }
- b43_write32(dev, B43_MMIO_GEN_IRQ_REASON, 0x00004000);
-- b43_write32(dev, B43_MMIO_DMA0_IRQ_MASK, 0x0001DC00);
-+ b43_write32(dev, B43_MMIO_DMA0_IRQ_MASK, 0x0001FC00);
- b43_write32(dev, B43_MMIO_DMA1_IRQ_MASK, 0x0000DC00);
- b43_write32(dev, B43_MMIO_DMA2_IRQ_MASK, 0x0000DC00);
- b43_write32(dev, B43_MMIO_DMA3_IRQ_MASK, 0x0001DC00);
-diff --git a/drivers/net/wireless/iwlegacy/4965-mac.c b/drivers/net/wireless/iwlegacy/4965-mac.c
-index 7941eb3..cbaa777 100644
---- a/drivers/net/wireless/iwlegacy/4965-mac.c
-+++ b/drivers/net/wireless/iwlegacy/4965-mac.c
-@@ -5740,8 +5740,7 @@ il4965_mac_setup_register(struct il_priv *il, u32 max_probe_length)
- hw->flags =
- IEEE80211_HW_SIGNAL_DBM | IEEE80211_HW_AMPDU_AGGREGATION |
- IEEE80211_HW_NEED_DTIM_BEFORE_ASSOC | IEEE80211_HW_SPECTRUM_MGMT |
-- IEEE80211_HW_REPORTS_TX_ACK_STATUS | IEEE80211_HW_SUPPORTS_PS |
-- IEEE80211_HW_SUPPORTS_DYNAMIC_PS;
-+ IEEE80211_HW_SUPPORTS_PS | IEEE80211_HW_SUPPORTS_DYNAMIC_PS;
- if (il->cfg->sku & IL_SKU_N)
- hw->flags |=
- IEEE80211_HW_SUPPORTS_DYNAMIC_SMPS |
-diff --git a/drivers/net/wireless/mwifiex/cfg80211.c b/drivers/net/wireless/mwifiex/cfg80211.c
-index 8aaf56a..c13f6e9 100644
---- a/drivers/net/wireless/mwifiex/cfg80211.c
-+++ b/drivers/net/wireless/mwifiex/cfg80211.c
-@@ -2280,9 +2280,6 @@ int mwifiex_del_virtual_intf(struct wiphy *wiphy, struct wireless_dev *wdev)
- if (wdev->netdev->reg_state == NETREG_REGISTERED)
- unregister_netdevice(wdev->netdev);
-
-- if (wdev->netdev->reg_state == NETREG_UNREGISTERED)
-- free_netdev(wdev->netdev);
--
- /* Clear the priv in adapter */
- priv->netdev = NULL;
-
-diff --git a/drivers/net/wireless/mwifiex/cmdevt.c b/drivers/net/wireless/mwifiex/cmdevt.c
-index b5c8b96..aeade10 100644
---- a/drivers/net/wireless/mwifiex/cmdevt.c
-+++ b/drivers/net/wireless/mwifiex/cmdevt.c
-@@ -1176,6 +1176,7 @@ mwifiex_process_hs_config(struct mwifiex_adapter *adapter)
- adapter->if_ops.wakeup(adapter);
- adapter->hs_activated = false;
- adapter->is_hs_configured = false;
-+ adapter->is_suspended = false;
- mwifiex_hs_activated_event(mwifiex_get_priv(adapter,
- MWIFIEX_BSS_ROLE_ANY),
- false);
-diff --git a/drivers/net/wireless/mwifiex/main.c b/drivers/net/wireless/mwifiex/main.c
-index 9c802ed..6d9bc63 100644
---- a/drivers/net/wireless/mwifiex/main.c
-+++ b/drivers/net/wireless/mwifiex/main.c
-@@ -646,6 +646,7 @@ void mwifiex_init_priv_params(struct mwifiex_private *priv,
- struct net_device *dev)
- {
- dev->netdev_ops = &mwifiex_netdev_ops;
-+ dev->destructor = free_netdev;
- /* Initialize private structure */
- priv->current_key_index = 0;
- priv->media_connected = false;
-diff --git a/drivers/net/wireless/mwifiex/sta_ioctl.c b/drivers/net/wireless/mwifiex/sta_ioctl.c
-index 13100f8..fb420fe 100644
---- a/drivers/net/wireless/mwifiex/sta_ioctl.c
-+++ b/drivers/net/wireless/mwifiex/sta_ioctl.c
-@@ -99,7 +99,7 @@ int mwifiex_request_set_multicast_list(struct mwifiex_private *priv,
- } else {
- /* Multicast */
- priv->curr_pkt_filter &= ~HostCmd_ACT_MAC_PROMISCUOUS_ENABLE;
-- if (mcast_list->mode == MWIFIEX_MULTICAST_MODE) {
-+ if (mcast_list->mode == MWIFIEX_ALL_MULTI_MODE) {
- dev_dbg(priv->adapter->dev,
- "info: Enabling All Multicast!\n");
- priv->curr_pkt_filter |=
-@@ -111,20 +111,11 @@ int mwifiex_request_set_multicast_list(struct mwifiex_private *priv,
- dev_dbg(priv->adapter->dev,
- "info: Set multicast list=%d\n",
- mcast_list->num_multicast_addr);
-- /* Set multicast addresses to firmware */
-- if (old_pkt_filter == priv->curr_pkt_filter) {
-- /* Send request to firmware */
-- ret = mwifiex_send_cmd_async(priv,
-- HostCmd_CMD_MAC_MULTICAST_ADR,
-- HostCmd_ACT_GEN_SET, 0,
-- mcast_list);
-- } else {
-- /* Send request to firmware */
-- ret = mwifiex_send_cmd_async(priv,
-- HostCmd_CMD_MAC_MULTICAST_ADR,
-- HostCmd_ACT_GEN_SET, 0,
-- mcast_list);
-- }
-+ /* Send multicast addresses to firmware */
-+ ret = mwifiex_send_cmd_async(priv,
-+ HostCmd_CMD_MAC_MULTICAST_ADR,
-+ HostCmd_ACT_GEN_SET, 0,
-+ mcast_list);
- }
- }
- }
-diff --git a/drivers/platform/x86/hp_accel.c b/drivers/platform/x86/hp_accel.c
-index e64a7a8..a8e43cf 100644
---- a/drivers/platform/x86/hp_accel.c
-+++ b/drivers/platform/x86/hp_accel.c
-@@ -362,7 +362,8 @@ static int lis3lv02d_suspend(struct device *dev)
-
- static int lis3lv02d_resume(struct device *dev)
- {
-- return lis3lv02d_poweron(&lis3_dev);
-+ lis3lv02d_poweron(&lis3_dev);
-+ return 0;
- }
-
- static SIMPLE_DEV_PM_OPS(hp_accel_pm, lis3lv02d_suspend, lis3lv02d_resume);
-diff --git a/drivers/rtc/Kconfig b/drivers/rtc/Kconfig
-index 79fbe38..9e95473 100644
---- a/drivers/rtc/Kconfig
-+++ b/drivers/rtc/Kconfig
-@@ -20,7 +20,6 @@ if RTC_CLASS
- config RTC_HCTOSYS
- bool "Set system time from RTC on startup and resume"
- default y
-- depends on !ALWAYS_USE_PERSISTENT_CLOCK
- help
- If you say yes here, the system time (wall clock) will be set using
- the value read from a specified RTC device. This is useful to avoid
-@@ -29,7 +28,6 @@ config RTC_HCTOSYS
- config RTC_SYSTOHC
- bool "Set the RTC time based on NTP synchronization"
- default y
-- depends on !ALWAYS_USE_PERSISTENT_CLOCK
- help
- If you say yes here, the system time (wall clock) will be stored
- in the RTC specified by RTC_HCTOSYS_DEVICE approximately every 11
-diff --git a/drivers/rtc/rtc-pcf2123.c b/drivers/rtc/rtc-pcf2123.c
-index 02b742a..6dd6b38 100644
---- a/drivers/rtc/rtc-pcf2123.c
-+++ b/drivers/rtc/rtc-pcf2123.c
-@@ -265,6 +265,7 @@ static int pcf2123_probe(struct spi_device *spi)
-
- if (!(rxbuf[0] & 0x20)) {
- dev_err(&spi->dev, "chip not found\n");
-+ ret = -ENODEV;
- goto kfree_exit;
- }
-
-diff --git a/drivers/scsi/sd.c b/drivers/scsi/sd.c
-index 7992635..82910cc 100644
---- a/drivers/scsi/sd.c
-+++ b/drivers/scsi/sd.c
-@@ -142,6 +142,7 @@ sd_store_cache_type(struct device *dev, struct device_attribute *attr,
- char *buffer_data;
- struct scsi_mode_data data;
- struct scsi_sense_hdr sshdr;
-+ const char *temp = "temporary ";
- int len;
-
- if (sdp->type != TYPE_DISK)
-@@ -150,6 +151,13 @@ sd_store_cache_type(struct device *dev, struct device_attribute *attr,
- * it's not worth the risk */
- return -EINVAL;
-
-+ if (strncmp(buf, temp, sizeof(temp) - 1) == 0) {
-+ buf += sizeof(temp) - 1;
-+ sdkp->cache_override = 1;
-+ } else {
-+ sdkp->cache_override = 0;
-+ }
-+
- for (i = 0; i < ARRAY_SIZE(sd_cache_types); i++) {
- len = strlen(sd_cache_types[i]);
- if (strncmp(sd_cache_types[i], buf, len) == 0 &&
-@@ -162,6 +170,13 @@ sd_store_cache_type(struct device *dev, struct device_attribute *attr,
- return -EINVAL;
- rcd = ct & 0x01 ? 1 : 0;
- wce = ct & 0x02 ? 1 : 0;
-+
-+ if (sdkp->cache_override) {
-+ sdkp->WCE = wce;
-+ sdkp->RCD = rcd;
-+ return count;
-+ }
-+
- if (scsi_mode_sense(sdp, 0x08, 8, buffer, sizeof(buffer), SD_TIMEOUT,
- SD_MAX_RETRIES, &data, NULL))
- return -EINVAL;
-@@ -2319,6 +2334,10 @@ sd_read_cache_type(struct scsi_disk *sdkp, unsigned char *buffer)
- int old_rcd = sdkp->RCD;
- int old_dpofua = sdkp->DPOFUA;
-
-+
-+ if (sdkp->cache_override)
-+ return;
-+
- first_len = 4;
- if (sdp->skip_ms_page_8) {
- if (sdp->type == TYPE_RBC)
-@@ -2812,6 +2831,7 @@ static void sd_probe_async(void *data, async_cookie_t cookie)
- sdkp->capacity = 0;
- sdkp->media_present = 1;
- sdkp->write_prot = 0;
-+ sdkp->cache_override = 0;
- sdkp->WCE = 0;
- sdkp->RCD = 0;
- sdkp->ATO = 0;
-diff --git a/drivers/scsi/sd.h b/drivers/scsi/sd.h
-index 74a1e4c..2386aeb 100644
---- a/drivers/scsi/sd.h
-+++ b/drivers/scsi/sd.h
-@@ -73,6 +73,7 @@ struct scsi_disk {
- u8 protection_type;/* Data Integrity Field */
- u8 provisioning_mode;
- unsigned ATO : 1; /* state of disk ATO bit */
-+ unsigned cache_override : 1; /* temp override of WCE,RCD */
- unsigned WCE : 1; /* state of disk WCE bit */
- unsigned RCD : 1; /* state of disk RCD bit, unused */
- unsigned DPOFUA : 1; /* state of disk DPOFUA bit */
-diff --git a/drivers/target/iscsi/iscsi_target_erl1.c b/drivers/target/iscsi/iscsi_target_erl1.c
-index 0b52a23..805f3d2 100644
---- a/drivers/target/iscsi/iscsi_target_erl1.c
-+++ b/drivers/target/iscsi/iscsi_target_erl1.c
-@@ -819,7 +819,7 @@ static int iscsit_attach_ooo_cmdsn(
- /*
- * CmdSN is greater than the tail of the list.
- */
-- if (ooo_tail->cmdsn < ooo_cmdsn->cmdsn)
-+ if (iscsi_sna_lt(ooo_tail->cmdsn, ooo_cmdsn->cmdsn))
- list_add_tail(&ooo_cmdsn->ooo_list,
- &sess->sess_ooo_cmdsn_list);
- else {
-@@ -829,11 +829,12 @@ static int iscsit_attach_ooo_cmdsn(
- */
- list_for_each_entry(ooo_tmp, &sess->sess_ooo_cmdsn_list,
- ooo_list) {
-- if (ooo_tmp->cmdsn < ooo_cmdsn->cmdsn)
-+ if (iscsi_sna_lt(ooo_tmp->cmdsn, ooo_cmdsn->cmdsn))
- continue;
-
-+ /* Insert before this entry */
- list_add(&ooo_cmdsn->ooo_list,
-- &ooo_tmp->ooo_list);
-+ ooo_tmp->ooo_list.prev);
- break;
- }
- }
-diff --git a/drivers/target/target_core_file.c b/drivers/target/target_core_file.c
-index 17a6acb..ca4b219 100644
---- a/drivers/target/target_core_file.c
-+++ b/drivers/target/target_core_file.c
-@@ -148,13 +148,8 @@ static int fd_configure_device(struct se_device *dev)
- */
- inode = file->f_mapping->host;
- if (S_ISBLK(inode->i_mode)) {
-- struct request_queue *q = bdev_get_queue(inode->i_bdev);
- unsigned long long dev_size;
-
-- dev->dev_attrib.hw_block_size =
-- bdev_logical_block_size(inode->i_bdev);
-- dev->dev_attrib.hw_max_sectors = queue_max_hw_sectors(q);
--
- /*
- * Determine the number of bytes from i_size_read() minus
- * one (1) logical sector from underlying struct block_device
-@@ -173,13 +168,12 @@ static int fd_configure_device(struct se_device *dev)
- " block_device\n");
- goto fail;
- }
--
-- dev->dev_attrib.hw_block_size = FD_BLOCKSIZE;
-- dev->dev_attrib.hw_max_sectors = FD_MAX_SECTORS;
- }
-
- fd_dev->fd_block_size = dev->dev_attrib.hw_block_size;
-
-+ dev->dev_attrib.hw_block_size = FD_BLOCKSIZE;
-+ dev->dev_attrib.hw_max_sectors = FD_MAX_SECTORS;
- dev->dev_attrib.hw_queue_depth = FD_MAX_DEVICE_QUEUE_DEPTH;
-
- if (fd_dev->fbd_flags & FDBD_HAS_BUFFERED_IO_WCE) {
-diff --git a/drivers/target/target_core_iblock.c b/drivers/target/target_core_iblock.c
-index 8bcc514..e1af9d5 100644
---- a/drivers/target/target_core_iblock.c
-+++ b/drivers/target/target_core_iblock.c
-@@ -679,6 +679,8 @@ iblock_execute_rw(struct se_cmd *cmd)
- rw = WRITE_FUA;
- else if (!(q->flush_flags & REQ_FLUSH))
- rw = WRITE_FUA;
-+ else
-+ rw = WRITE;
- } else {
- rw = WRITE;
- }
-diff --git a/drivers/target/target_core_transport.c b/drivers/target/target_core_transport.c
-index 3243ea7..0d46276 100644
---- a/drivers/target/target_core_transport.c
-+++ b/drivers/target/target_core_transport.c
-@@ -2213,21 +2213,19 @@ static void target_release_cmd_kref(struct kref *kref)
- {
- struct se_cmd *se_cmd = container_of(kref, struct se_cmd, cmd_kref);
- struct se_session *se_sess = se_cmd->se_sess;
-- unsigned long flags;
-
-- spin_lock_irqsave(&se_sess->sess_cmd_lock, flags);
- if (list_empty(&se_cmd->se_cmd_list)) {
-- spin_unlock_irqrestore(&se_sess->sess_cmd_lock, flags);
-+ spin_unlock(&se_sess->sess_cmd_lock);
- se_cmd->se_tfo->release_cmd(se_cmd);
- return;
- }
- if (se_sess->sess_tearing_down && se_cmd->cmd_wait_set) {
-- spin_unlock_irqrestore(&se_sess->sess_cmd_lock, flags);
-+ spin_unlock(&se_sess->sess_cmd_lock);
- complete(&se_cmd->cmd_wait_comp);
- return;
- }
- list_del(&se_cmd->se_cmd_list);
-- spin_unlock_irqrestore(&se_sess->sess_cmd_lock, flags);
-+ spin_unlock(&se_sess->sess_cmd_lock);
-
- se_cmd->se_tfo->release_cmd(se_cmd);
- }
-@@ -2238,7 +2236,8 @@ static void target_release_cmd_kref(struct kref *kref)
- */
- int target_put_sess_cmd(struct se_session *se_sess, struct se_cmd *se_cmd)
- {
-- return kref_put(&se_cmd->cmd_kref, target_release_cmd_kref);
-+ return kref_put_spinlock_irqsave(&se_cmd->cmd_kref, target_release_cmd_kref,
-+ &se_sess->sess_cmd_lock);
- }
- EXPORT_SYMBOL(target_put_sess_cmd);
-
-diff --git a/drivers/watchdog/watchdog_dev.c b/drivers/watchdog/watchdog_dev.c
-index 08b48bb..faf4e18 100644
---- a/drivers/watchdog/watchdog_dev.c
-+++ b/drivers/watchdog/watchdog_dev.c
-@@ -523,6 +523,7 @@ int watchdog_dev_register(struct watchdog_device *watchdog)
- int err, devno;
-
- if (watchdog->id == 0) {
-+ old_wdd = watchdog;
- watchdog_miscdev.parent = watchdog->parent;
- err = misc_register(&watchdog_miscdev);
- if (err != 0) {
-@@ -531,9 +532,9 @@ int watchdog_dev_register(struct watchdog_device *watchdog)
- if (err == -EBUSY)
- pr_err("%s: a legacy watchdog module is probably present.\n",
- watchdog->info->identity);
-+ old_wdd = NULL;
- return err;
- }
-- old_wdd = watchdog;
- }
-
- /* Fill in the data structures */
-diff --git a/fs/ext4/mballoc.c b/fs/ext4/mballoc.c
-index cf3025c..f3190ab 100644
---- a/fs/ext4/mballoc.c
-+++ b/fs/ext4/mballoc.c
-@@ -1994,7 +1994,11 @@ repeat:
- group = ac->ac_g_ex.fe_group;
-
- for (i = 0; i < ngroups; group++, i++) {
-- if (group == ngroups)
-+ /*
-+ * Artificially restricted ngroups for non-extent
-+ * files makes group > ngroups possible on first loop.
-+ */
-+ if (group >= ngroups)
- group = 0;
-
- /* This now checks without needing the buddy page */
-diff --git a/fs/namei.c b/fs/namei.c
-index 57ae9c8..85e40d1 100644
---- a/fs/namei.c
-+++ b/fs/namei.c
-@@ -2740,7 +2740,7 @@ static int do_last(struct nameidata *nd, struct path *path,
- if (error)
- return error;
-
-- audit_inode(name, dir, 0);
-+ audit_inode(name, dir, LOOKUP_PARENT);
- error = -EISDIR;
- /* trailing slashes? */
- if (nd->last.name[nd->last.len])
-diff --git a/fs/nfsd/nfs4proc.c b/fs/nfsd/nfs4proc.c
-index 8288b08..d401d01 100644
---- a/fs/nfsd/nfs4proc.c
-+++ b/fs/nfsd/nfs4proc.c
-@@ -271,6 +271,7 @@ static __be32
- do_open_fhandle(struct svc_rqst *rqstp, struct svc_fh *current_fh, struct nfsd4_open *open)
- {
- __be32 status;
-+ int accmode = 0;
-
- /* We don't know the target directory, and therefore can not
- * set the change info
-@@ -284,9 +285,19 @@ do_open_fhandle(struct svc_rqst *rqstp, struct svc_fh *current_fh, struct nfsd4_
-
- open->op_truncate = (open->op_iattr.ia_valid & ATTR_SIZE) &&
- (open->op_iattr.ia_size == 0);
-+ /*
-+ * In the delegation case, the client is telling us about an
-+ * open that it *already* performed locally, some time ago. We
-+ * should let it succeed now if possible.
-+ *
-+ * In the case of a CLAIM_FH open, on the other hand, the client
-+ * may be counting on us to enforce permissions (the Linux 4.1
-+ * client uses this for normal opens, for example).
-+ */
-+ if (open->op_claim_type == NFS4_OPEN_CLAIM_DELEG_CUR_FH)
-+ accmode = NFSD_MAY_OWNER_OVERRIDE;
-
-- status = do_open_permission(rqstp, current_fh, open,
-- NFSD_MAY_OWNER_OVERRIDE);
-+ status = do_open_permission(rqstp, current_fh, open, accmode);
-
- return status;
- }
-diff --git a/fs/nfsd/nfs4recover.c b/fs/nfsd/nfs4recover.c
-index 899ca26..4e9a21d 100644
---- a/fs/nfsd/nfs4recover.c
-+++ b/fs/nfsd/nfs4recover.c
-@@ -146,7 +146,7 @@ out_no_tfm:
- * then disable recovery tracking.
- */
- static void
--legacy_recdir_name_error(int error)
-+legacy_recdir_name_error(struct nfs4_client *clp, int error)
- {
- printk(KERN_ERR "NFSD: unable to generate recoverydir "
- "name (%d).\n", error);
-@@ -159,9 +159,7 @@ legacy_recdir_name_error(int error)
- if (error == -ENOENT) {
- printk(KERN_ERR "NFSD: disabling legacy clientid tracking. "
- "Reboot recovery will not function correctly!\n");
--
-- /* the argument is ignored by the legacy exit function */
-- nfsd4_client_tracking_exit(NULL);
-+ nfsd4_client_tracking_exit(clp->net);
- }
- }
-
-@@ -184,7 +182,7 @@ nfsd4_create_clid_dir(struct nfs4_client *clp)
-
- status = nfs4_make_rec_clidname(dname, &clp->cl_name);
- if (status)
-- return legacy_recdir_name_error(status);
-+ return legacy_recdir_name_error(clp, status);
-
- status = nfs4_save_creds(&original_cred);
- if (status < 0)
-@@ -341,7 +339,7 @@ nfsd4_remove_clid_dir(struct nfs4_client *clp)
-
- status = nfs4_make_rec_clidname(dname, &clp->cl_name);
- if (status)
-- return legacy_recdir_name_error(status);
-+ return legacy_recdir_name_error(clp, status);
-
- status = mnt_want_write_file(nn->rec_file);
- if (status)
-@@ -601,7 +599,7 @@ nfsd4_check_legacy_client(struct nfs4_client *clp)
-
- status = nfs4_make_rec_clidname(dname, &clp->cl_name);
- if (status) {
-- legacy_recdir_name_error(status);
-+ legacy_recdir_name_error(clp, status);
- return status;
- }
-
-diff --git a/include/linux/audit.h b/include/linux/audit.h
-index 5a6d718..b4086cf 100644
---- a/include/linux/audit.h
-+++ b/include/linux/audit.h
-@@ -120,7 +120,7 @@ static inline void audit_syscall_entry(int arch, int major, unsigned long a0,
- unsigned long a1, unsigned long a2,
- unsigned long a3)
- {
-- if (unlikely(!audit_dummy_context()))
-+ if (unlikely(current->audit_context))
- __audit_syscall_entry(arch, major, a0, a1, a2, a3);
- }
- static inline void audit_syscall_exit(void *pt_regs)
-@@ -390,6 +390,11 @@ static inline void audit_ptrace(struct task_struct *t)
- #define audit_signals 0
- #endif /* CONFIG_AUDITSYSCALL */
-
-+static inline bool audit_loginuid_set(struct task_struct *tsk)
-+{
-+ return uid_valid(audit_get_loginuid(tsk));
-+}
-+
- #ifdef CONFIG_AUDIT
- /* These are defined in audit.c */
- /* Public API */
-diff --git a/include/linux/kref.h b/include/linux/kref.h
-index 4972e6e..7419c02 100644
---- a/include/linux/kref.h
-+++ b/include/linux/kref.h
-@@ -19,6 +19,7 @@
- #include <linux/atomic.h>
- #include <linux/kernel.h>
- #include <linux/mutex.h>
-+#include <linux/spinlock.h>
-
- struct kref {
- atomic_t refcount;
-@@ -95,6 +96,38 @@ static inline int kref_put(struct kref *kref, void (*release)(struct kref *kref)
- return kref_sub(kref, 1, release);
- }
-
-+/**
-+ * kref_put_spinlock_irqsave - decrement refcount for object.
-+ * @kref: object.
-+ * @release: pointer to the function that will clean up the object when the
-+ * last reference to the object is released.
-+ * This pointer is required, and it is not acceptable to pass kfree
-+ * in as this function.
-+ * @lock: lock to take in release case
-+ *
-+ * Behaves identical to kref_put with one exception. If the reference count
-+ * drops to zero, the lock will be taken atomically wrt dropping the reference
-+ * count. The release function has to call spin_unlock() without _irqrestore.
-+ */
-+static inline int kref_put_spinlock_irqsave(struct kref *kref,
-+ void (*release)(struct kref *kref),
-+ spinlock_t *lock)
-+{
-+ unsigned long flags;
-+
-+ WARN_ON(release == NULL);
-+ if (atomic_add_unless(&kref->refcount, -1, 1))
-+ return 0;
-+ spin_lock_irqsave(lock, flags);
-+ if (atomic_dec_and_test(&kref->refcount)) {
-+ release(kref);
-+ local_irq_restore(flags);
-+ return 1;
-+ }
-+ spin_unlock_irqrestore(lock, flags);
-+ return 0;
-+}
-+
- static inline int kref_put_mutex(struct kref *kref,
- void (*release)(struct kref *kref),
- struct mutex *lock)
-diff --git a/include/linux/time.h b/include/linux/time.h
-index d4835df..afcdc4b 100644
---- a/include/linux/time.h
-+++ b/include/linux/time.h
-@@ -117,14 +117,10 @@ static inline bool timespec_valid_strict(const struct timespec *ts)
-
- extern bool persistent_clock_exist;
-
--#ifdef ALWAYS_USE_PERSISTENT_CLOCK
--#define has_persistent_clock() true
--#else
- static inline bool has_persistent_clock(void)
- {
- return persistent_clock_exist;
- }
--#endif
-
- extern void read_persistent_clock(struct timespec *ts);
- extern void read_boot_clock(struct timespec *ts);
-diff --git a/include/net/inet_frag.h b/include/net/inet_frag.h
-index 0a1dcc2..ab3d0ac 100644
---- a/include/net/inet_frag.h
-+++ b/include/net/inet_frag.h
-@@ -135,14 +135,15 @@ static inline int sum_frag_mem_limit(struct netns_frags *nf)
- static inline void inet_frag_lru_move(struct inet_frag_queue *q)
- {
- spin_lock(&q->net->lru_lock);
-- list_move_tail(&q->lru_list, &q->net->lru_list);
-+ if (!list_empty(&q->lru_list))
-+ list_move_tail(&q->lru_list, &q->net->lru_list);
- spin_unlock(&q->net->lru_lock);
- }
-
- static inline void inet_frag_lru_del(struct inet_frag_queue *q)
- {
- spin_lock(&q->net->lru_lock);
-- list_del(&q->lru_list);
-+ list_del_init(&q->lru_list);
- spin_unlock(&q->net->lru_lock);
- }
-
-diff --git a/include/net/sock.h b/include/net/sock.h
-index 14f6e9d..0be480a 100644
---- a/include/net/sock.h
-+++ b/include/net/sock.h
-@@ -865,6 +865,18 @@ struct inet_hashinfo;
- struct raw_hashinfo;
- struct module;
-
-+/*
-+ * caches using SLAB_DESTROY_BY_RCU should let .next pointer from nulls nodes
-+ * un-modified. Special care is taken when initializing object to zero.
-+ */
-+static inline void sk_prot_clear_nulls(struct sock *sk, int size)
-+{
-+ if (offsetof(struct sock, sk_node.next) != 0)
-+ memset(sk, 0, offsetof(struct sock, sk_node.next));
-+ memset(&sk->sk_node.pprev, 0,
-+ size - offsetof(struct sock, sk_node.pprev));
-+}
-+
- /* Networking protocol blocks we attach to sockets.
- * socket layer -> transport layer interface
- * transport -> network interface is defined by struct inet_proto
-diff --git a/include/net/tcp.h b/include/net/tcp.h
-index cf0694d..a345480 100644
---- a/include/net/tcp.h
-+++ b/include/net/tcp.h
-@@ -1049,6 +1049,7 @@ static inline bool tcp_prequeue(struct sock *sk, struct sk_buff *skb)
- skb_queue_len(&tp->ucopy.prequeue) == 0)
- return false;
-
-+ skb_dst_force(skb);
- __skb_queue_tail(&tp->ucopy.prequeue, skb);
- tp->ucopy.memory += skb->truesize;
- if (tp->ucopy.memory > sk->sk_rcvbuf) {
-diff --git a/include/uapi/linux/audit.h b/include/uapi/linux/audit.h
-index 9f096f1..9554a19 100644
---- a/include/uapi/linux/audit.h
-+++ b/include/uapi/linux/audit.h
-@@ -246,6 +246,7 @@
- #define AUDIT_OBJ_TYPE 21
- #define AUDIT_OBJ_LEV_LOW 22
- #define AUDIT_OBJ_LEV_HIGH 23
-+#define AUDIT_LOGINUID_SET 24
-
- /* These are ONLY useful when checking
- * at syscall exit time (AUDIT_AT_EXIT). */
-diff --git a/include/uapi/linux/if_cablemodem.h b/include/uapi/linux/if_cablemodem.h
-index 9ca1007..ee6b3c4 100644
---- a/include/uapi/linux/if_cablemodem.h
-+++ b/include/uapi/linux/if_cablemodem.h
-@@ -12,11 +12,11 @@
- */
-
- /* some useful defines for sb1000.c e cmconfig.c - fv */
--#define SIOCGCMSTATS SIOCDEVPRIVATE+0 /* get cable modem stats */
--#define SIOCGCMFIRMWARE SIOCDEVPRIVATE+1 /* get cm firmware version */
--#define SIOCGCMFREQUENCY SIOCDEVPRIVATE+2 /* get cable modem frequency */
--#define SIOCSCMFREQUENCY SIOCDEVPRIVATE+3 /* set cable modem frequency */
--#define SIOCGCMPIDS SIOCDEVPRIVATE+4 /* get cable modem PIDs */
--#define SIOCSCMPIDS SIOCDEVPRIVATE+5 /* set cable modem PIDs */
-+#define SIOCGCMSTATS (SIOCDEVPRIVATE+0) /* get cable modem stats */
-+#define SIOCGCMFIRMWARE (SIOCDEVPRIVATE+1) /* get cm firmware version */
-+#define SIOCGCMFREQUENCY (SIOCDEVPRIVATE+2) /* get cable modem frequency */
-+#define SIOCSCMFREQUENCY (SIOCDEVPRIVATE+3) /* set cable modem frequency */
-+#define SIOCGCMPIDS (SIOCDEVPRIVATE+4) /* get cable modem PIDs */
-+#define SIOCSCMPIDS (SIOCDEVPRIVATE+5) /* set cable modem PIDs */
-
- #endif
-diff --git a/include/uapi/linux/virtio_net.h b/include/uapi/linux/virtio_net.h
-index a5a8c88..c520203 100644
---- a/include/uapi/linux/virtio_net.h
-+++ b/include/uapi/linux/virtio_net.h
-@@ -191,7 +191,7 @@ struct virtio_net_ctrl_mac {
- * specified.
- */
- struct virtio_net_ctrl_mq {
-- u16 virtqueue_pairs;
-+ __u16 virtqueue_pairs;
- };
-
- #define VIRTIO_NET_CTRL_MQ 4
-diff --git a/ipc/shm.c b/ipc/shm.c
-index 34af1fe..7e199fa 100644
---- a/ipc/shm.c
-+++ b/ipc/shm.c
-@@ -493,7 +493,13 @@ static int newseg(struct ipc_namespace *ns, struct ipc_params *params)
- if (shmflg & SHM_HUGETLB) {
- struct hstate *hs = hstate_sizelog((shmflg >> SHM_HUGE_SHIFT)
- & SHM_HUGE_MASK);
-- size_t hugesize = ALIGN(size, huge_page_size(hs));
-+ size_t hugesize;
-+
-+ if (!hs) {
-+ error = -EINVAL;
-+ goto no_file;
-+ }
-+ hugesize = ALIGN(size, huge_page_size(hs));
-
- /* hugetlb_file_setup applies strict accounting */
- if (shmflg & SHM_NORESERVE)
-diff --git a/kernel/auditfilter.c b/kernel/auditfilter.c
-index f9fc54b..2bf508d 100644
---- a/kernel/auditfilter.c
-+++ b/kernel/auditfilter.c
-@@ -345,6 +345,12 @@ static struct audit_entry *audit_rule_to_entry(struct audit_rule *rule)
- f->uid = INVALID_UID;
- f->gid = INVALID_GID;
-
-+ /* Support legacy tests for a valid loginuid */
-+ if ((f->type == AUDIT_LOGINUID) && (f->val == 4294967295U)) {
-+ f->type = AUDIT_LOGINUID_SET;
-+ f->val = 0;
-+ }
-+
- err = -EINVAL;
- if (f->op == Audit_bad)
- goto exit_free;
-@@ -352,6 +358,12 @@ static struct audit_entry *audit_rule_to_entry(struct audit_rule *rule)
- switch(f->type) {
- default:
- goto exit_free;
-+ case AUDIT_LOGINUID_SET:
-+ if ((f->val != 0) && (f->val != 1))
-+ goto exit_free;
-+ if (f->op != Audit_not_equal && f->op != Audit_equal)
-+ goto exit_free;
-+ break;
- case AUDIT_UID:
- case AUDIT_EUID:
- case AUDIT_SUID:
-@@ -459,7 +471,20 @@ static struct audit_entry *audit_data_to_entry(struct audit_rule_data *data,
- f->gid = INVALID_GID;
- f->lsm_str = NULL;
- f->lsm_rule = NULL;
-- switch(f->type) {
-+
-+ /* Support legacy tests for a valid loginuid */
-+ if ((f->type == AUDIT_LOGINUID) && (f->val == 4294967295U)) {
-+ f->type = AUDIT_LOGINUID_SET;
-+ f->val = 0;
-+ }
-+
-+ switch (f->type) {
-+ case AUDIT_LOGINUID_SET:
-+ if ((f->val != 0) && (f->val != 1))
-+ goto exit_free;
-+ if (f->op != Audit_not_equal && f->op != Audit_equal)
-+ goto exit_free;
-+ break;
- case AUDIT_UID:
- case AUDIT_EUID:
- case AUDIT_SUID:
-@@ -1378,6 +1403,10 @@ static int audit_filter_user_rules(struct audit_krule *rule,
- result = audit_uid_comparator(audit_get_loginuid(current),
- f->op, f->uid);
- break;
-+ case AUDIT_LOGINUID_SET:
-+ result = audit_comparator(audit_loginuid_set(current),
-+ f->op, f->val);
-+ break;
- case AUDIT_SUBJ_USER:
- case AUDIT_SUBJ_ROLE:
- case AUDIT_SUBJ_TYPE:
-diff --git a/kernel/auditsc.c b/kernel/auditsc.c
-index a371f85..c4b72b0 100644
---- a/kernel/auditsc.c
-+++ b/kernel/auditsc.c
-@@ -742,6 +742,9 @@ static int audit_filter_rules(struct task_struct *tsk,
- if (ctx)
- result = audit_uid_comparator(tsk->loginuid, f->op, f->uid);
- break;
-+ case AUDIT_LOGINUID_SET:
-+ result = audit_comparator(audit_loginuid_set(tsk), f->op, f->val);
-+ break;
- case AUDIT_SUBJ_USER:
- case AUDIT_SUBJ_ROLE:
- case AUDIT_SUBJ_TYPE:
-@@ -2309,7 +2312,7 @@ int audit_set_loginuid(kuid_t loginuid)
- unsigned int sessionid;
-
- #ifdef CONFIG_AUDIT_LOGINUID_IMMUTABLE
-- if (uid_valid(task->loginuid))
-+ if (audit_loginuid_set(task))
- return -EPERM;
- #else /* CONFIG_AUDIT_LOGINUID_IMMUTABLE */
- if (!capable(CAP_AUDIT_CONTROL))
-diff --git a/kernel/kmod.c b/kernel/kmod.c
-index 56dd349..8985c87 100644
---- a/kernel/kmod.c
-+++ b/kernel/kmod.c
-@@ -570,6 +570,11 @@ int call_usermodehelper_exec(struct subprocess_info *sub_info, int wait)
- int retval = 0;
-
- helper_lock();
-+ if (!sub_info->path) {
-+ retval = -EINVAL;
-+ goto out;
-+ }
-+
- if (sub_info->path[0] == '\0')
- goto out;
-
-diff --git a/kernel/sched/cputime.c b/kernel/sched/cputime.c
-index e93cca9..6af50ad 100644
---- a/kernel/sched/cputime.c
-+++ b/kernel/sched/cputime.c
-@@ -521,18 +521,49 @@ EXPORT_SYMBOL_GPL(vtime_account_irq_enter);
-
- #else /* !CONFIG_VIRT_CPU_ACCOUNTING */
-
--static cputime_t scale_stime(cputime_t stime, cputime_t rtime, cputime_t total)
-+/*
-+ * Perform (stime * rtime) / total, but avoid multiplication overflow by
-+ * loosing precision when the numbers are big.
-+ */
-+static cputime_t scale_stime(u64 stime, u64 rtime, u64 total)
- {
-- u64 temp = (__force u64) rtime;
-+ u64 scaled;
-
-- temp *= (__force u64) stime;
-+ for (;;) {
-+ /* Make sure "rtime" is the bigger of stime/rtime */
-+ if (stime > rtime) {
-+ u64 tmp = rtime; rtime = stime; stime = tmp;
-+ }
-
-- if (sizeof(cputime_t) == 4)
-- temp = div_u64(temp, (__force u32) total);
-- else
-- temp = div64_u64(temp, (__force u64) total);
-+ /* Make sure 'total' fits in 32 bits */
-+ if (total >> 32)
-+ goto drop_precision;
-+
-+ /* Does rtime (and thus stime) fit in 32 bits? */
-+ if (!(rtime >> 32))
-+ break;
-
-- return (__force cputime_t) temp;
-+ /* Can we just balance rtime/stime rather than dropping bits? */
-+ if (stime >> 31)
-+ goto drop_precision;
-+
-+ /* We can grow stime and shrink rtime and try to make them both fit */
-+ stime <<= 1;
-+ rtime >>= 1;
-+ continue;
-+
-+drop_precision:
-+ /* We drop from rtime, it has more bits than stime */
-+ rtime >>= 1;
-+ total >>= 1;
-+ }
-+
-+ /*
-+ * Make sure gcc understands that this is a 32x32->64 multiply,
-+ * followed by a 64/32->64 divide.
-+ */
-+ scaled = div_u64((u64) (u32) stime * (u64) (u32) rtime, (u32)total);
-+ return (__force cputime_t) scaled;
- }
-
- /*
-@@ -543,7 +574,7 @@ static void cputime_adjust(struct task_cputime *curr,
- struct cputime *prev,
- cputime_t *ut, cputime_t *st)
- {
-- cputime_t rtime, stime, total;
-+ cputime_t rtime, stime, utime, total;
-
- stime = curr->stime;
- total = stime + curr->utime;
-@@ -560,10 +591,22 @@ static void cputime_adjust(struct task_cputime *curr,
- */
- rtime = nsecs_to_cputime(curr->sum_exec_runtime);
-
-- if (total)
-- stime = scale_stime(stime, rtime, total);
-- else
-+ /*
-+ * Update userspace visible utime/stime values only if actual execution
-+ * time is bigger than already exported. Note that can happen, that we
-+ * provided bigger values due to scaling inaccuracy on big numbers.
-+ */
-+ if (prev->stime + prev->utime >= rtime)
-+ goto out;
-+
-+ if (total) {
-+ stime = scale_stime((__force u64)stime,
-+ (__force u64)rtime, (__force u64)total);
-+ utime = rtime - stime;
-+ } else {
- stime = rtime;
-+ utime = 0;
-+ }
-
- /*
- * If the tick based count grows faster than the scheduler one,
-@@ -571,8 +614,9 @@ static void cputime_adjust(struct task_cputime *curr,
- * Let's enforce monotonicity.
- */
- prev->stime = max(prev->stime, stime);
-- prev->utime = max(prev->utime, rtime - prev->stime);
-+ prev->utime = max(prev->utime, utime);
-
-+out:
- *ut = prev->utime;
- *st = prev->stime;
- }
-diff --git a/kernel/time/Kconfig b/kernel/time/Kconfig
-index 24510d8..b696922 100644
---- a/kernel/time/Kconfig
-+++ b/kernel/time/Kconfig
-@@ -12,11 +12,6 @@ config CLOCKSOURCE_WATCHDOG
- config ARCH_CLOCKSOURCE_DATA
- bool
-
--# Platforms has a persistent clock
--config ALWAYS_USE_PERSISTENT_CLOCK
-- bool
-- default n
--
- # Timekeeping vsyscall support
- config GENERIC_TIME_VSYSCALL
- bool
-diff --git a/kernel/time/tick-sched.c b/kernel/time/tick-sched.c
-index a19a399..e717ad9 100644
---- a/kernel/time/tick-sched.c
-+++ b/kernel/time/tick-sched.c
-@@ -904,7 +904,7 @@ void tick_cancel_sched_timer(int cpu)
- hrtimer_cancel(&ts->sched_timer);
- # endif
-
-- ts->nohz_mode = NOHZ_MODE_INACTIVE;
-+ memset(ts, 0, sizeof(*ts));
- }
- #endif
-
-diff --git a/kernel/timer.c b/kernel/timer.c
-index dbf7a78..1b399c8 100644
---- a/kernel/timer.c
-+++ b/kernel/timer.c
-@@ -1678,12 +1678,12 @@ static int __cpuinit init_timers_cpu(int cpu)
- boot_done = 1;
- base = &boot_tvec_bases;
- }
-+ spin_lock_init(&base->lock);
- tvec_base_done[cpu] = 1;
- } else {
- base = per_cpu(tvec_bases, cpu);
- }
-
-- spin_lock_init(&base->lock);
-
- for (j = 0; j < TVN_SIZE; j++) {
- INIT_LIST_HEAD(base->tv5.vec + j);
-diff --git a/kernel/trace/trace_events_filter.c b/kernel/trace/trace_events_filter.c
-index e5b0ca8..5a8a53e 100644
---- a/kernel/trace/trace_events_filter.c
-+++ b/kernel/trace/trace_events_filter.c
-@@ -777,7 +777,11 @@ static int filter_set_pred(struct event_filter *filter,
-
- static void __free_preds(struct event_filter *filter)
- {
-+ int i;
-+
- if (filter->preds) {
-+ for (i = 0; i < filter->n_preds; i++)
-+ kfree(filter->preds[i].ops);
- kfree(filter->preds);
- filter->preds = NULL;
- }
-diff --git a/mm/mmap.c b/mm/mmap.c
-index e17fc06..0dceed8 100644
---- a/mm/mmap.c
-+++ b/mm/mmap.c
-@@ -1331,9 +1331,13 @@ SYSCALL_DEFINE6(mmap_pgoff, unsigned long, addr, unsigned long, len,
- len = ALIGN(len, huge_page_size(hstate_file(file)));
- } else if (flags & MAP_HUGETLB) {
- struct user_struct *user = NULL;
-+ struct hstate *hs = hstate_sizelog((flags >> MAP_HUGE_SHIFT) &
-+ SHM_HUGE_MASK);
-
-- len = ALIGN(len, huge_page_size(hstate_sizelog(
-- (flags >> MAP_HUGE_SHIFT) & MAP_HUGE_MASK)));
-+ if (!hs)
-+ return -EINVAL;
-+
-+ len = ALIGN(len, huge_page_size(hs));
- /*
- * VM_NORESERVE is used because the reservations will be
- * taken when vm_ops->mmap() is called
-diff --git a/net/8021q/vlan_dev.c b/net/8021q/vlan_dev.c
-index 19cf81b..63bd98c 100644
---- a/net/8021q/vlan_dev.c
-+++ b/net/8021q/vlan_dev.c
-@@ -627,7 +627,7 @@ static netdev_features_t vlan_dev_fix_features(struct net_device *dev,
- netdev_features_t features)
- {
- struct net_device *real_dev = vlan_dev_priv(dev)->real_dev;
-- u32 old_features = features;
-+ netdev_features_t old_features = features;
-
- features &= real_dev->vlan_features;
- features |= NETIF_F_RXCSUM;
-diff --git a/net/bridge/br_stp_timer.c b/net/bridge/br_stp_timer.c
-index c3530a8..950663d 100644
---- a/net/bridge/br_stp_timer.c
-+++ b/net/bridge/br_stp_timer.c
-@@ -107,7 +107,7 @@ static void br_tcn_timer_expired(unsigned long arg)
-
- br_debug(br, "tcn timer expired\n");
- spin_lock(&br->lock);
-- if (br->dev->flags & IFF_UP) {
-+ if (!br_is_root_bridge(br) && (br->dev->flags & IFF_UP)) {
- br_transmit_tcn(br);
-
- mod_timer(&br->tcn_timer,jiffies + br->bridge_hello_time);
-diff --git a/net/core/dev.c b/net/core/dev.c
-index b24ab0e9..9a278e9 100644
---- a/net/core/dev.c
-+++ b/net/core/dev.c
-@@ -2458,7 +2458,7 @@ EXPORT_SYMBOL(netif_skb_features);
- * 2. skb is fragmented and the device does not support SG.
- */
- static inline int skb_needs_linearize(struct sk_buff *skb,
-- int features)
-+ netdev_features_t features)
- {
- return skb_is_nonlinear(skb) &&
- ((skb_has_frag_list(skb) &&
-diff --git a/net/core/ethtool.c b/net/core/ethtool.c
-index 3e9b2c3..41f4bdf 100644
---- a/net/core/ethtool.c
-+++ b/net/core/ethtool.c
-@@ -1416,7 +1416,7 @@ int dev_ethtool(struct net *net, struct ifreq *ifr)
- void __user *useraddr = ifr->ifr_data;
- u32 ethcmd;
- int rc;
-- u32 old_features;
-+ netdev_features_t old_features;
-
- if (!dev || !netif_device_present(dev))
- return -ENODEV;
-diff --git a/net/core/sock.c b/net/core/sock.c
-index b261a79..1432266 100644
---- a/net/core/sock.c
-+++ b/net/core/sock.c
-@@ -1209,18 +1209,6 @@ static void sock_copy(struct sock *nsk, const struct sock *osk)
- #endif
- }
-
--/*
-- * caches using SLAB_DESTROY_BY_RCU should let .next pointer from nulls nodes
-- * un-modified. Special care is taken when initializing object to zero.
-- */
--static inline void sk_prot_clear_nulls(struct sock *sk, int size)
--{
-- if (offsetof(struct sock, sk_node.next) != 0)
-- memset(sk, 0, offsetof(struct sock, sk_node.next));
-- memset(&sk->sk_node.pprev, 0,
-- size - offsetof(struct sock, sk_node.pprev));
--}
--
- void sk_prot_clear_portaddr_nulls(struct sock *sk, int size)
- {
- unsigned long nulls1, nulls2;
-diff --git a/net/ipv4/inet_fragment.c b/net/ipv4/inet_fragment.c
-index f4fd23d..3211914 100644
---- a/net/ipv4/inet_fragment.c
-+++ b/net/ipv4/inet_fragment.c
-@@ -257,6 +257,7 @@ static struct inet_frag_queue *inet_frag_alloc(struct netns_frags *nf,
- setup_timer(&q->timer, f->frag_expire, (unsigned long)q);
- spin_lock_init(&q->lock);
- atomic_set(&q->refcnt, 1);
-+ INIT_LIST_HEAD(&q->lru_list);
-
- return q;
- }
-diff --git a/net/ipv4/tcp_minisocks.c b/net/ipv4/tcp_minisocks.c
-index b83a49c..2f672e7 100644
---- a/net/ipv4/tcp_minisocks.c
-+++ b/net/ipv4/tcp_minisocks.c
-@@ -583,8 +583,13 @@ struct sock *tcp_check_req(struct sock *sk, struct sk_buff *skb,
- *
- * Note that even if there is new data in the SYN packet
- * they will be thrown away too.
-+ *
-+ * Reset timer after retransmitting SYNACK, similar to
-+ * the idea of fast retransmit in recovery.
- */
-- inet_rtx_syn_ack(sk, req);
-+ if (!inet_rtx_syn_ack(sk, req))
-+ req->expires = min(TCP_TIMEOUT_INIT << req->num_timeout,
-+ TCP_RTO_MAX) + jiffies;
- return NULL;
- }
-
-diff --git a/net/ipv6/ip6_gre.c b/net/ipv6/ip6_gre.c
-index e4efffe..95d13c7 100644
---- a/net/ipv6/ip6_gre.c
-+++ b/net/ipv6/ip6_gre.c
-@@ -1135,6 +1135,7 @@ static int ip6gre_tunnel_ioctl(struct net_device *dev,
- }
- if (t == NULL)
- t = netdev_priv(dev);
-+ memset(&p, 0, sizeof(p));
- ip6gre_tnl_parm_to_user(&p, &t->parms);
- if (copy_to_user(ifr->ifr_ifru.ifru_data, &p, sizeof(p)))
- err = -EFAULT;
-@@ -1182,6 +1183,7 @@ static int ip6gre_tunnel_ioctl(struct net_device *dev,
- if (t) {
- err = 0;
-
-+ memset(&p, 0, sizeof(p));
- ip6gre_tnl_parm_to_user(&p, &t->parms);
- if (copy_to_user(ifr->ifr_ifru.ifru_data, &p, sizeof(p)))
- err = -EFAULT;
-diff --git a/net/ipv6/tcp_ipv6.c b/net/ipv6/tcp_ipv6.c
-index 46a5be8..0fce928 100644
---- a/net/ipv6/tcp_ipv6.c
-+++ b/net/ipv6/tcp_ipv6.c
-@@ -1937,6 +1937,17 @@ void tcp6_proc_exit(struct net *net)
- }
- #endif
-
-+static void tcp_v6_clear_sk(struct sock *sk, int size)
-+{
-+ struct inet_sock *inet = inet_sk(sk);
-+
-+ /* we do not want to clear pinet6 field, because of RCU lookups */
-+ sk_prot_clear_nulls(sk, offsetof(struct inet_sock, pinet6));
-+
-+ size -= offsetof(struct inet_sock, pinet6) + sizeof(inet->pinet6);
-+ memset(&inet->pinet6 + 1, 0, size);
-+}
-+
- struct proto tcpv6_prot = {
- .name = "TCPv6",
- .owner = THIS_MODULE,
-@@ -1980,6 +1991,7 @@ struct proto tcpv6_prot = {
- #ifdef CONFIG_MEMCG_KMEM
- .proto_cgroup = tcp_proto_cgroup,
- #endif
-+ .clear_sk = tcp_v6_clear_sk,
- };
-
- static const struct inet6_protocol tcpv6_protocol = {
-diff --git a/net/ipv6/udp.c b/net/ipv6/udp.c
-index d8e5e85..27f0f8e 100644
---- a/net/ipv6/udp.c
-+++ b/net/ipv6/udp.c
-@@ -1422,6 +1422,17 @@ void udp6_proc_exit(struct net *net) {
- }
- #endif /* CONFIG_PROC_FS */
-
-+void udp_v6_clear_sk(struct sock *sk, int size)
-+{
-+ struct inet_sock *inet = inet_sk(sk);
-+
-+ /* we do not want to clear pinet6 field, because of RCU lookups */
-+ sk_prot_clear_portaddr_nulls(sk, offsetof(struct inet_sock, pinet6));
-+
-+ size -= offsetof(struct inet_sock, pinet6) + sizeof(inet->pinet6);
-+ memset(&inet->pinet6 + 1, 0, size);
-+}
-+
- /* ------------------------------------------------------------------------ */
-
- struct proto udpv6_prot = {
-@@ -1452,7 +1463,7 @@ struct proto udpv6_prot = {
- .compat_setsockopt = compat_udpv6_setsockopt,
- .compat_getsockopt = compat_udpv6_getsockopt,
- #endif
-- .clear_sk = sk_prot_clear_portaddr_nulls,
-+ .clear_sk = udp_v6_clear_sk,
- };
-
- static struct inet_protosw udpv6_protosw = {
-diff --git a/net/ipv6/udp_impl.h b/net/ipv6/udp_impl.h
-index d757104..4691ed5 100644
---- a/net/ipv6/udp_impl.h
-+++ b/net/ipv6/udp_impl.h
-@@ -31,6 +31,8 @@ extern int udpv6_recvmsg(struct kiocb *iocb, struct sock *sk,
- extern int udpv6_queue_rcv_skb(struct sock * sk, struct sk_buff *skb);
- extern void udpv6_destroy_sock(struct sock *sk);
-
-+extern void udp_v6_clear_sk(struct sock *sk, int size);
-+
- #ifdef CONFIG_PROC_FS
- extern int udp6_seq_show(struct seq_file *seq, void *v);
- #endif
-diff --git a/net/ipv6/udplite.c b/net/ipv6/udplite.c
-index 1d08e21..dfcc4be 100644
---- a/net/ipv6/udplite.c
-+++ b/net/ipv6/udplite.c
-@@ -56,7 +56,7 @@ struct proto udplitev6_prot = {
- .compat_setsockopt = compat_udpv6_setsockopt,
- .compat_getsockopt = compat_udpv6_getsockopt,
- #endif
-- .clear_sk = sk_prot_clear_portaddr_nulls,
-+ .clear_sk = udp_v6_clear_sk,
- };
-
- static struct inet_protosw udplite6_protosw = {
-diff --git a/net/ipv6/xfrm6_policy.c b/net/ipv6/xfrm6_policy.c
-index 4ef7bdb..23ed03d 100644
---- a/net/ipv6/xfrm6_policy.c
-+++ b/net/ipv6/xfrm6_policy.c
-@@ -103,8 +103,10 @@ static int xfrm6_fill_dst(struct xfrm_dst *xdst, struct net_device *dev,
- dev_hold(dev);
-
- xdst->u.rt6.rt6i_idev = in6_dev_get(dev);
-- if (!xdst->u.rt6.rt6i_idev)
-+ if (!xdst->u.rt6.rt6i_idev) {
-+ dev_put(dev);
- return -ENODEV;
-+ }
-
- rt6_transfer_peer(&xdst->u.rt6, rt);
-
-diff --git a/net/mac802154/mac802154.h b/net/mac802154/mac802154.h
-index a4dcaf1..703c121 100644
---- a/net/mac802154/mac802154.h
-+++ b/net/mac802154/mac802154.h
-@@ -90,7 +90,7 @@ struct mac802154_sub_if_data {
-
- #define MAC802154_MAX_XMIT_ATTEMPTS 3
-
--#define MAC802154_CHAN_NONE (~(u8)0) /* No channel is assigned */
-+#define MAC802154_CHAN_NONE 0xff /* No channel is assigned */
-
- extern struct ieee802154_reduced_mlme_ops mac802154_mlme_reduced;
- extern struct ieee802154_mlme_ops mac802154_mlme_wpan;
-diff --git a/net/packet/af_packet.c b/net/packet/af_packet.c
-index 1d6793d..f83e172 100644
---- a/net/packet/af_packet.c
-+++ b/net/packet/af_packet.c
-@@ -693,36 +693,33 @@ static void prb_open_block(struct tpacket_kbdq_core *pkc1,
-
- smp_rmb();
-
-- if (likely(TP_STATUS_KERNEL == BLOCK_STATUS(pbd1))) {
-+ /* We could have just memset this but we will lose the
-+ * flexibility of making the priv area sticky
-+ */
-
-- /* We could have just memset this but we will lose the
-- * flexibility of making the priv area sticky
-- */
-- BLOCK_SNUM(pbd1) = pkc1->knxt_seq_num++;
-- BLOCK_NUM_PKTS(pbd1) = 0;
-- BLOCK_LEN(pbd1) = BLK_PLUS_PRIV(pkc1->blk_sizeof_priv);
-- getnstimeofday(&ts);
-- h1->ts_first_pkt.ts_sec = ts.tv_sec;
-- h1->ts_first_pkt.ts_nsec = ts.tv_nsec;
-- pkc1->pkblk_start = (char *)pbd1;
-- pkc1->nxt_offset = pkc1->pkblk_start + BLK_PLUS_PRIV(pkc1->blk_sizeof_priv);
-- BLOCK_O2FP(pbd1) = (__u32)BLK_PLUS_PRIV(pkc1->blk_sizeof_priv);
-- BLOCK_O2PRIV(pbd1) = BLK_HDR_LEN;
-- pbd1->version = pkc1->version;
-- pkc1->prev = pkc1->nxt_offset;
-- pkc1->pkblk_end = pkc1->pkblk_start + pkc1->kblk_size;
-- prb_thaw_queue(pkc1);
-- _prb_refresh_rx_retire_blk_timer(pkc1);
-+ BLOCK_SNUM(pbd1) = pkc1->knxt_seq_num++;
-+ BLOCK_NUM_PKTS(pbd1) = 0;
-+ BLOCK_LEN(pbd1) = BLK_PLUS_PRIV(pkc1->blk_sizeof_priv);
-
-- smp_wmb();
-+ getnstimeofday(&ts);
-
-- return;
-- }
-+ h1->ts_first_pkt.ts_sec = ts.tv_sec;
-+ h1->ts_first_pkt.ts_nsec = ts.tv_nsec;
-
-- WARN(1, "ERROR block:%p is NOT FREE status:%d kactive_blk_num:%d\n",
-- pbd1, BLOCK_STATUS(pbd1), pkc1->kactive_blk_num);
-- dump_stack();
-- BUG();
-+ pkc1->pkblk_start = (char *)pbd1;
-+ pkc1->nxt_offset = pkc1->pkblk_start + BLK_PLUS_PRIV(pkc1->blk_sizeof_priv);
-+
-+ BLOCK_O2FP(pbd1) = (__u32)BLK_PLUS_PRIV(pkc1->blk_sizeof_priv);
-+ BLOCK_O2PRIV(pbd1) = BLK_HDR_LEN;
-+
-+ pbd1->version = pkc1->version;
-+ pkc1->prev = pkc1->nxt_offset;
-+ pkc1->pkblk_end = pkc1->pkblk_start + pkc1->kblk_size;
-+
-+ prb_thaw_queue(pkc1);
-+ _prb_refresh_rx_retire_blk_timer(pkc1);
-+
-+ smp_wmb();
- }
-
- /*
-@@ -813,10 +810,6 @@ static void prb_retire_current_block(struct tpacket_kbdq_core *pkc,
- prb_close_block(pkc, pbd, po, status);
- return;
- }
--
-- WARN(1, "ERROR-pbd[%d]:%p\n", pkc->kactive_blk_num, pbd);
-- dump_stack();
-- BUG();
- }
-
- static int prb_curr_blk_in_use(struct tpacket_kbdq_core *pkc,
-diff --git a/net/sched/act_ipt.c b/net/sched/act_ipt.c
-index e0f6de6..60d88b6 100644
---- a/net/sched/act_ipt.c
-+++ b/net/sched/act_ipt.c
-@@ -8,7 +8,7 @@
- * as published by the Free Software Foundation; either version
- * 2 of the License, or (at your option) any later version.
- *
-- * Copyright: Jamal Hadi Salim (2002-4)
-+ * Copyright: Jamal Hadi Salim (2002-13)
- */
-
- #include <linux/types.h>
-@@ -303,17 +303,44 @@ static struct tc_action_ops act_ipt_ops = {
- .walk = tcf_generic_walker
- };
-
--MODULE_AUTHOR("Jamal Hadi Salim(2002-4)");
-+static struct tc_action_ops act_xt_ops = {
-+ .kind = "xt",
-+ .hinfo = &ipt_hash_info,
-+ .type = TCA_ACT_IPT,
-+ .capab = TCA_CAP_NONE,
-+ .owner = THIS_MODULE,
-+ .act = tcf_ipt,
-+ .dump = tcf_ipt_dump,
-+ .cleanup = tcf_ipt_cleanup,
-+ .lookup = tcf_hash_search,
-+ .init = tcf_ipt_init,
-+ .walk = tcf_generic_walker
-+};
-+
-+MODULE_AUTHOR("Jamal Hadi Salim(2002-13)");
- MODULE_DESCRIPTION("Iptables target actions");
- MODULE_LICENSE("GPL");
-+MODULE_ALIAS("act_xt");
-
- static int __init ipt_init_module(void)
- {
-- return tcf_register_action(&act_ipt_ops);
-+ int ret1, ret2;
-+ ret1 = tcf_register_action(&act_xt_ops);
-+ if (ret1 < 0)
-+ printk("Failed to load xt action\n");
-+ ret2 = tcf_register_action(&act_ipt_ops);
-+ if (ret2 < 0)
-+ printk("Failed to load ipt action\n");
-+
-+ if (ret1 < 0 && ret2 < 0)
-+ return ret1;
-+ else
-+ return 0;
- }
-
- static void __exit ipt_cleanup_module(void)
- {
-+ tcf_unregister_action(&act_xt_ops);
- tcf_unregister_action(&act_ipt_ops);
- }
-
-diff --git a/net/vmw_vsock/af_vsock.c b/net/vmw_vsock/af_vsock.c
-index 7f93e2a..2e330e8 100644
---- a/net/vmw_vsock/af_vsock.c
-+++ b/net/vmw_vsock/af_vsock.c
-@@ -165,7 +165,7 @@ static struct list_head vsock_bind_table[VSOCK_HASH_SIZE + 1];
- static struct list_head vsock_connected_table[VSOCK_HASH_SIZE];
- static DEFINE_SPINLOCK(vsock_table_lock);
-
--static __init void vsock_init_tables(void)
-+static void vsock_init_tables(void)
- {
- int i;
-
-diff --git a/sound/pci/hda/hda_codec.c b/sound/pci/hda/hda_codec.c
-index 4aba764..c414cdd 100644
---- a/sound/pci/hda/hda_codec.c
-+++ b/sound/pci/hda/hda_codec.c
-@@ -681,6 +681,9 @@ int snd_hda_queue_unsol_event(struct hda_bus *bus, u32 res, u32 res_ex)
- struct hda_bus_unsolicited *unsol;
- unsigned int wp;
-
-+ if (!bus || !bus->workq)
-+ return 0;
-+
- trace_hda_unsol_event(bus, res, res_ex);
- unsol = bus->unsol;
- if (!unsol)
-@@ -1577,7 +1580,7 @@ void snd_hda_codec_setup_stream(struct hda_codec *codec, hda_nid_t nid,
- "NID=0x%x, stream=0x%x, channel=%d, format=0x%x\n",
- nid, stream_tag, channel_id, format);
- p = get_hda_cvt_setup(codec, nid);
-- if (!p || p->active)
-+ if (!p)
- return;
-
- if (codec->pcm_format_first)
-@@ -1624,7 +1627,7 @@ void __snd_hda_codec_cleanup_stream(struct hda_codec *codec, hda_nid_t nid,
-
- snd_printdd("hda_codec_cleanup_stream: NID=0x%x\n", nid);
- p = get_hda_cvt_setup(codec, nid);
-- if (p && p->active) {
-+ if (p) {
- /* here we just clear the active flag when do_now isn't set;
- * actual clean-ups will be done later in
- * purify_inactive_streams() called from snd_hda_codec_prpapre()
-diff --git a/sound/pci/hda/patch_conexant.c b/sound/pci/hda/patch_conexant.c
-index 2a89d1ee..1e5a30f 100644
---- a/sound/pci/hda/patch_conexant.c
-+++ b/sound/pci/hda/patch_conexant.c
-@@ -64,6 +64,7 @@ struct conexant_spec {
- /* extra EAPD pins */
- unsigned int num_eapds;
- hda_nid_t eapds[4];
-+ bool dynamic_eapd;
-
- #ifdef ENABLE_CXT_STATIC_QUIRKS
- const struct snd_kcontrol_new *mixers[5];
-@@ -3152,7 +3153,7 @@ static void cx_auto_parse_eapd(struct hda_codec *codec)
- * thus it might control over all pins.
- */
- if (spec->num_eapds > 2)
-- spec->gen.own_eapd_ctl = 1;
-+ spec->dynamic_eapd = 1;
- }
-
- static void cx_auto_turn_eapd(struct hda_codec *codec, int num_pins,
-@@ -3191,6 +3192,15 @@ static int cx_auto_build_controls(struct hda_codec *codec)
- return 0;
- }
-
-+static int cx_auto_init(struct hda_codec *codec)
-+{
-+ struct conexant_spec *spec = codec->spec;
-+ snd_hda_gen_init(codec);
-+ if (!spec->dynamic_eapd)
-+ cx_auto_turn_eapd(codec, spec->num_eapds, spec->eapds, true);
-+ return 0;
-+}
-+
- static void cx_auto_free(struct hda_codec *codec)
- {
- snd_hda_detach_beep_device(codec);
-@@ -3200,7 +3210,7 @@ static void cx_auto_free(struct hda_codec *codec)
- static const struct hda_codec_ops cx_auto_patch_ops = {
- .build_controls = cx_auto_build_controls,
- .build_pcms = snd_hda_gen_build_pcms,
-- .init = snd_hda_gen_init,
-+ .init = cx_auto_init,
- .free = cx_auto_free,
- .unsol_event = snd_hda_jack_unsol_event,
- #ifdef CONFIG_PM
-@@ -3350,7 +3360,8 @@ static int patch_conexant_auto(struct hda_codec *codec)
-
- cx_auto_parse_beep(codec);
- cx_auto_parse_eapd(codec);
-- if (spec->gen.own_eapd_ctl)
-+ spec->gen.own_eapd_ctl = 1;
-+ if (spec->dynamic_eapd)
- spec->gen.vmaster_mute.hook = cx_auto_vmaster_hook;
-
- switch (codec->vendor_id) {
-diff --git a/sound/soc/codecs/da7213.c b/sound/soc/codecs/da7213.c
-index 41230ad..4a6f1da 100644
---- a/sound/soc/codecs/da7213.c
-+++ b/sound/soc/codecs/da7213.c
-@@ -1488,17 +1488,17 @@ static int da7213_probe(struct snd_soc_codec *codec)
- DA7213_DMIC_DATA_SEL_SHIFT);
- break;
- }
-- switch (pdata->dmic_data_sel) {
-+ switch (pdata->dmic_samplephase) {
- case DA7213_DMIC_SAMPLE_ON_CLKEDGE:
- case DA7213_DMIC_SAMPLE_BETWEEN_CLKEDGE:
-- dmic_cfg |= (pdata->dmic_data_sel <<
-+ dmic_cfg |= (pdata->dmic_samplephase <<
- DA7213_DMIC_SAMPLEPHASE_SHIFT);
- break;
- }
-- switch (pdata->dmic_data_sel) {
-+ switch (pdata->dmic_clk_rate) {
- case DA7213_DMIC_CLK_3_0MHZ:
- case DA7213_DMIC_CLK_1_5MHZ:
-- dmic_cfg |= (pdata->dmic_data_sel <<
-+ dmic_cfg |= (pdata->dmic_clk_rate <<
- DA7213_DMIC_CLK_RATE_SHIFT);
- break;
- }
-diff --git a/sound/soc/codecs/wm8994.c b/sound/soc/codecs/wm8994.c
-index c9bd445..e5f96c9 100644
---- a/sound/soc/codecs/wm8994.c
-+++ b/sound/soc/codecs/wm8994.c
-@@ -2841,6 +2841,7 @@ static int wm8994_aif3_hw_params(struct snd_pcm_substream *substream,
- default:
- return 0;
- }
-+ break;
- default:
- return 0;
- }