| summaryrefslogtreecommitdiff |
Side-by-side diff
| -rw-r--r-- | patches.kernel.org/patch-3.9.1-2 | 3029 | ||||
| -rw-r--r-- | patches.kernel.org/patch-3.9.2-3 | 3862 |
2 files changed, 0 insertions, 6891 deletions
diff --git a/patches.kernel.org/patch-3.9.1-2 b/patches.kernel.org/patch-3.9.1-2 deleted file mode 100644 index 1ff9901..0000000 --- a/patches.kernel.org/patch-3.9.1-2 +++ b/dev/null @@ -1,3029 +0,0 @@ -From: Jiri Slaby <jslaby@suse.cz> -Subject: Linux 3.9.2 -Patch-mainline: 3.9.2 -Git-commit: 12b2f117f3bf738c1a00a6f64393f1953a740bd4 -Git-commit: c5a2a15f8146fdfe45078df7873a6dc1006b3869 -Git-commit: 7fdb7846c9ca6fc06e380de0976a1228703b498a -Git-commit: e253aaf0af51c1e4dc7dd3b26ea8e666bf9a2d8d -Git-commit: c8c64d165ccfd2274058ac84e0c680f9b48c4ec1 -Git-commit: eb384b55ae9c2055ea00c5cc87971e182d47aefa -Git-commit: 41b0fc42800569f63e029549b75c4c9cb63f2dfd -Git-commit: 7fe70b579c9e3daba71635e31b6189394e7b79d3 -Git-commit: 9e48854c58ca9a0f39e716dcb18247bfc21e2022 -Git-commit: 441e76ca83ac604eaf0f046def96d8e3a27eea28 -Git-commit: 62d1f92e06aef9665d71ca7e986b3047ecf0b3c7 -Git-commit: f8e6bfc2ce162855fa4f9822a45659f4b542c960 -Git-commit: beb71fc61c2cad64e347f164991b8ef476529e64 -Git-commit: e884fc640ccbdb6f94b9bdb57cfb8464b6688f4c -Git-commit: 466476dfdcafbb4286ffa232a3a792731b9dc852 -Git-commit: 79b52d6a7085a3e430c6de450a5847fdbe04159b -Git-commit: dcb852905772416e322536ced5cb3c796d176af5 -Git-commit: 0cd9cb76ae26a19df21abc6f94f5fff141e689c7 -Git-commit: 2e97be73e5f74a317232740ae82eb8f95326a660 -Git-commit: 18932a28419596bc9403770f5d8a108c5433fe59 -Git-commit: abf1457bbbe4c62066bd03c6d31837dea28644dc -Git-commit: 2b48b968c0d00aa5ab520b65a15a4f374cda7dda -Git-commit: 2f86e2ede39a98650c2d465857405ef1c51372b1 -Git-commit: 968c01664ccbe0e46c19a1af662c4c266a904203 -Git-commit: 10257a6d8359c41407eb26b7ad7bf710a7e00155 -Git-commit: bea5497bfc1067620c8c8e9d37a42e0bb6d7d7fa -Git-commit: 7c1c7c18fc752b2a1d07597286467ef186312463 -Git-commit: 367cbe2fec9b57b72605e2ac4cfd4f2fa823a256 -Git-commit: 411678288d61ba17afe1f8afed92200be6bbc65d -Git-commit: bf05d9985111f85ed6922c134567b96eb789283b -Git-commit: 43b27290dd42b40f3f23f49677a7faa5a4eb1eff -Git-commit: e4bfff54ed3f5de88f5358504c78c2cb037813aa -Git-commit: b6c5164d7bf624f3e1b750787ddb983150c5117c -Git-commit: c40c0f5bd5b0f09e4386d2cf26c96c89c45ee539 -Git-commit: dc652f90e088798bfa31f496ba994ddadd5d5680 -Git-commit: f30da187cdcd0939288038e11fb3bfbd1b655564 -Git-commit: 3f704fa2778d3fe45e6529825a5c7a8bcbc686f4 -Git-commit: 4615d4c9e27eda42c3e965f208a4b4065841498c -Git-commit: 25ff1195f8a0b3724541ae7bbe331b4296de9c06 -Git-commit: 7a7d1fb79fb581553f4830498045de774a9659f8 -Git-commit: 9e9dd0e889c76c786e8f2e164c825c3c06dea30c -Git-commit: bd6946e87a98fea11907b2a47368e13044458a35 -Git-commit: 306373b645d80625335b8e684fa09b14ba460cec -Git-commit: 219b47339ced80ca580bb6ce7d1636166984afa7 -Git-commit: 011c2282c74db120f01a8414edc66c3f217f5511 -Git-commit: e127dc28cc3057575da0216cde85687153ca180f -Git-commit: 641719599528d806e00de8ae8c8453361266a312 -Git-commit: f3b2bbdc8a87a080ccd23d27fca4b87d61340dd4 -Git-commit: 871dd9286e25330c8a581e5dacfa8b1dfe1dd641 -Git-commit: e5072664f8237cf53b0bd68a51aa1a7bc69061c5 -Git-commit: 0e7f7bcc3fc87489cda5aa6aff8ce40eed912279 -Git-commit: 5b0c275926b8149c555da874bb4ec258ea3292aa -Git-commit: e5195c1f31f399289347e043d6abf3ffa80f0005 -Git-commit: 07c449bbc6aa514098c4f12c7b04180cec2417c6 -Git-commit: 3f8a6411fbada1fa482276591e037f3b1adcf55b -Git-commit: f7a1dd6e3ad59f0cfd51da29dfdbfd54122c5916 -Git-commit: 7cc23cd6c0c7d7f4bee057607e7ce01568925717 -Git-commit: 6e15eb3ba6c0249c9e8c783517d131b47db995ca -Git-commit: 741a698f420c34c458294a6accecfbad702a7c52 -Git-commit: 1b0dac2ac6debdbf1541e15f2cede03613cf4465 -Git-commit: 9a6bc14350b130427725f33e371e86212fa56c85 -Git-commit: 13f85203e1060da83d9ec1c1c5a63343eaab8de4 -Git-commit: edb749f4390b3c1604233dc7c4fb0361f472e712 -Git-commit: 197887f03daecdb3ae21bafeb4155412abad3497 -Git-commit: af73e4d9506d3b797509f3c030e7dcd554f7d9c4 -Git-commit: b9777859ec015a78dae1476e317d04f851bfdd0d -Git-commit: 397944df3290ddc46dcc6a08cd71fb560700431b -Git-commit: ce8a5dbdf9e709bdaf4618d7ef8cceb91e8adc69 -Git-commit: 563861cd633ae52932843477bb6ca3f1c9e2f78b -Git-commit: 7122beeee7bc1757682049780179d7c216dd1c83 -Git-commit: c2fd22df89365df9451d5b91da3b7bfd48122ecd -Git-commit: 73d2fb758e678c93bc76d40876c2359f0729b0ef -Git-commit: 2798ba7d19aed645663398a21ec4006bfdbb1ef3 - -Signed-off-by: Jiri Slaby <jslaby@suse.cz> ---- -diff --git a/Makefile b/Makefile -index 5fcb591..3e71511 100644 ---- a/Makefile -+++ b/Makefile -@@ -1,6 +1,6 @@ - VERSION = 3 - PATCHLEVEL = 9 --SUBLEVEL = 1 -+SUBLEVEL = 2 - EXTRAVERSION = - NAME = Unicycling Gorilla - -diff --git a/arch/arm/xen/enlighten.c b/arch/arm/xen/enlighten.c -index 8dc0605..99ce189 100644 ---- a/arch/arm/xen/enlighten.c -+++ b/arch/arm/xen/enlighten.c -@@ -239,7 +239,7 @@ static int __init xen_init_events(void) - xen_init_IRQ(); - - if (request_percpu_irq(xen_events_irq, xen_arm_callback, -- "events", xen_vcpu)) { -+ "events", &xen_vcpu)) { - pr_err("Error requesting IRQ %d\n", xen_events_irq); - return -EINVAL; - } -diff --git a/arch/arm64/mm/fault.c b/arch/arm64/mm/fault.c -index afadae6..0782eaf 100644 ---- a/arch/arm64/mm/fault.c -+++ b/arch/arm64/mm/fault.c -@@ -148,6 +148,7 @@ void do_bad_area(unsigned long addr, unsigned int esr, struct pt_regs *regs) - #define VM_FAULT_BADACCESS 0x020000 - - #define ESR_WRITE (1 << 6) -+#define ESR_CM (1 << 8) - #define ESR_LNX_EXEC (1 << 24) - - /* -@@ -206,7 +207,7 @@ static int __kprobes do_page_fault(unsigned long addr, unsigned int esr, - struct task_struct *tsk; - struct mm_struct *mm; - int fault, sig, code; -- int write = esr & ESR_WRITE; -+ bool write = (esr & ESR_WRITE) && !(esr & ESR_CM); - unsigned int flags = FAULT_FLAG_ALLOW_RETRY | FAULT_FLAG_KILLABLE | - (write ? FAULT_FLAG_WRITE : 0); - -diff --git a/arch/powerpc/include/asm/ppc-opcode.h b/arch/powerpc/include/asm/ppc-opcode.h -index 8752bc8..8cbc6e5 100644 ---- a/arch/powerpc/include/asm/ppc-opcode.h -+++ b/arch/powerpc/include/asm/ppc-opcode.h -@@ -113,6 +113,10 @@ - #define PPC_INST_MFSPR_DSCR_MASK 0xfc1fffff - #define PPC_INST_MTSPR_DSCR 0x7c1103a6 - #define PPC_INST_MTSPR_DSCR_MASK 0xfc1fffff -+#define PPC_INST_MFSPR_DSCR_USER 0x7c0302a6 -+#define PPC_INST_MFSPR_DSCR_USER_MASK 0xfc1fffff -+#define PPC_INST_MTSPR_DSCR_USER 0x7c0303a6 -+#define PPC_INST_MTSPR_DSCR_USER_MASK 0xfc1fffff - #define PPC_INST_SLBFEE 0x7c0007a7 - - #define PPC_INST_STRING 0x7c00042a -diff --git a/arch/powerpc/kernel/traps.c b/arch/powerpc/kernel/traps.c -index 37cc40e..83efa2f 100644 ---- a/arch/powerpc/kernel/traps.c -+++ b/arch/powerpc/kernel/traps.c -@@ -970,7 +970,10 @@ static int emulate_instruction(struct pt_regs *regs) - - #ifdef CONFIG_PPC64 - /* Emulate the mfspr rD, DSCR. */ -- if (((instword & PPC_INST_MFSPR_DSCR_MASK) == PPC_INST_MFSPR_DSCR) && -+ if ((((instword & PPC_INST_MFSPR_DSCR_USER_MASK) == -+ PPC_INST_MFSPR_DSCR_USER) || -+ ((instword & PPC_INST_MFSPR_DSCR_MASK) == -+ PPC_INST_MFSPR_DSCR)) && - cpu_has_feature(CPU_FTR_DSCR)) { - PPC_WARN_EMULATED(mfdscr, regs); - rd = (instword >> 21) & 0x1f; -@@ -978,7 +981,10 @@ static int emulate_instruction(struct pt_regs *regs) - return 0; - } - /* Emulate the mtspr DSCR, rD. */ -- if (((instword & PPC_INST_MTSPR_DSCR_MASK) == PPC_INST_MTSPR_DSCR) && -+ if ((((instword & PPC_INST_MTSPR_DSCR_USER_MASK) == -+ PPC_INST_MTSPR_DSCR_USER) || -+ ((instword & PPC_INST_MTSPR_DSCR_MASK) == -+ PPC_INST_MTSPR_DSCR)) && - cpu_has_feature(CPU_FTR_DSCR)) { - PPC_WARN_EMULATED(mtdscr, regs); - rd = (instword >> 21) & 0x1f; -diff --git a/arch/powerpc/mm/hash_utils_64.c b/arch/powerpc/mm/hash_utils_64.c -index f410c3e..b75c52f 100644 ---- a/arch/powerpc/mm/hash_utils_64.c -+++ b/arch/powerpc/mm/hash_utils_64.c -@@ -1191,6 +1191,7 @@ void flush_hash_page(unsigned long vpn, real_pte_t pte, int psize, int ssize, - * unmapping it first, it may see the speculated version. - */ - if (local && cpu_has_feature(CPU_FTR_TM) && -+ current->thread.regs && - MSR_TM_ACTIVE(current->thread.regs->msr)) { - tm_enable(); - tm_abort(TM_CAUSE_TLBI); -diff --git a/arch/powerpc/mm/numa.c b/arch/powerpc/mm/numa.c -index bba87ca..6a252c4 100644 ---- a/arch/powerpc/mm/numa.c -+++ b/arch/powerpc/mm/numa.c -@@ -201,7 +201,7 @@ int __node_distance(int a, int b) - int distance = LOCAL_DISTANCE; - - if (!form1_affinity) -- return distance; -+ return ((a == b) ? LOCAL_DISTANCE : REMOTE_DISTANCE); - - for (i = 0; i < distance_ref_points_depth; i++) { - if (distance_lookup_table[a][i] == distance_lookup_table[b][i]) -diff --git a/arch/x86/kernel/cpu/perf_event_intel.c b/arch/x86/kernel/cpu/perf_event_intel.c -index cc45deb..4a0a462 100644 ---- a/arch/x86/kernel/cpu/perf_event_intel.c -+++ b/arch/x86/kernel/cpu/perf_event_intel.c -@@ -125,10 +125,15 @@ static struct event_constraint intel_ivb_event_constraints[] __read_mostly = - INTEL_UEVENT_CONSTRAINT(0x08a3, 0x4), /* CYCLE_ACTIVITY.CYCLES_L1D_PENDING */ - INTEL_UEVENT_CONSTRAINT(0x0ca3, 0x4), /* CYCLE_ACTIVITY.STALLS_L1D_PENDING */ - INTEL_UEVENT_CONSTRAINT(0x01c0, 0x2), /* INST_RETIRED.PREC_DIST */ -- INTEL_EVENT_CONSTRAINT(0xd0, 0xf), /* MEM_UOPS_RETIRED.* */ -- INTEL_EVENT_CONSTRAINT(0xd1, 0xf), /* MEM_LOAD_UOPS_RETIRED.* */ -- INTEL_EVENT_CONSTRAINT(0xd2, 0xf), /* MEM_LOAD_UOPS_LLC_HIT_RETIRED.* */ -- INTEL_EVENT_CONSTRAINT(0xd3, 0xf), /* MEM_LOAD_UOPS_LLC_MISS_RETIRED.* */ -+ /* -+ * Errata BV98 -- MEM_*_RETIRED events can leak between counters of SMT -+ * siblings; disable these events because they can corrupt unrelated -+ * counters. -+ */ -+ INTEL_EVENT_CONSTRAINT(0xd0, 0x0), /* MEM_UOPS_RETIRED.* */ -+ INTEL_EVENT_CONSTRAINT(0xd1, 0x0), /* MEM_LOAD_UOPS_RETIRED.* */ -+ INTEL_EVENT_CONSTRAINT(0xd2, 0x0), /* MEM_LOAD_UOPS_LLC_HIT_RETIRED.* */ -+ INTEL_EVENT_CONSTRAINT(0xd3, 0x0), /* MEM_LOAD_UOPS_LLC_MISS_RETIRED.* */ - EVENT_CONSTRAINT_END - }; - -diff --git a/arch/x86/kernel/cpu/perf_event_intel_lbr.c b/arch/x86/kernel/cpu/perf_event_intel_lbr.c -index da02e9c..d978353 100644 ---- a/arch/x86/kernel/cpu/perf_event_intel_lbr.c -+++ b/arch/x86/kernel/cpu/perf_event_intel_lbr.c -@@ -310,7 +310,7 @@ void intel_pmu_lbr_read(void) - * - in case there is no HW filter - * - in case the HW filter has errata or limitations - */ --static void intel_pmu_setup_sw_lbr_filter(struct perf_event *event) -+static int intel_pmu_setup_sw_lbr_filter(struct perf_event *event) - { - u64 br_type = event->attr.branch_sample_type; - int mask = 0; -@@ -318,8 +318,11 @@ static void intel_pmu_setup_sw_lbr_filter(struct perf_event *event) - if (br_type & PERF_SAMPLE_BRANCH_USER) - mask |= X86_BR_USER; - -- if (br_type & PERF_SAMPLE_BRANCH_KERNEL) -+ if (br_type & PERF_SAMPLE_BRANCH_KERNEL) { -+ if (perf_paranoid_kernel() && !capable(CAP_SYS_ADMIN)) -+ return -EACCES; - mask |= X86_BR_KERNEL; -+ } - - /* we ignore BRANCH_HV here */ - -@@ -339,6 +342,8 @@ static void intel_pmu_setup_sw_lbr_filter(struct perf_event *event) - * be used by fixup code for some CPU - */ - event->hw.branch_reg.reg = mask; -+ -+ return 0; - } - - /* -@@ -386,7 +391,9 @@ int intel_pmu_setup_lbr_filter(struct perf_event *event) - /* - * setup SW LBR filter - */ -- intel_pmu_setup_sw_lbr_filter(event); -+ ret = intel_pmu_setup_sw_lbr_filter(event); -+ if (ret) -+ return ret; - - /* - * setup HW LBR filter, if any -@@ -442,8 +449,18 @@ static int branch_type(unsigned long from, unsigned long to) - return X86_BR_NONE; - - addr = buf; -- } else -- addr = (void *)from; -+ } else { -+ /* -+ * The LBR logs any address in the IP, even if the IP just -+ * faulted. This means userspace can control the from address. -+ * Ensure we don't blindy read any address by validating it is -+ * a known text address. -+ */ -+ if (kernel_text_address(from)) -+ addr = (void *)from; -+ else -+ return X86_BR_NONE; -+ } - - /* - * decoder needs to know the ABI especially -diff --git a/arch/x86/kernel/cpu/perf_event_intel_uncore.c b/arch/x86/kernel/cpu/perf_event_intel_uncore.c -index b43200d..3e091f0 100644 ---- a/arch/x86/kernel/cpu/perf_event_intel_uncore.c -+++ b/arch/x86/kernel/cpu/perf_event_intel_uncore.c -@@ -2428,7 +2428,7 @@ static void __init uncore_types_exit(struct intel_uncore_type **types) - static int __init uncore_type_init(struct intel_uncore_type *type) - { - struct intel_uncore_pmu *pmus; -- struct attribute_group *events_group; -+ struct attribute_group *attr_group; - struct attribute **attrs; - int i, j; - -@@ -2455,19 +2455,19 @@ static int __init uncore_type_init(struct intel_uncore_type *type) - while (type->event_descs[i].attr.attr.name) - i++; - -- events_group = kzalloc(sizeof(struct attribute *) * (i + 1) + -- sizeof(*events_group), GFP_KERNEL); -- if (!events_group) -+ attr_group = kzalloc(sizeof(struct attribute *) * (i + 1) + -+ sizeof(*attr_group), GFP_KERNEL); -+ if (!attr_group) - goto fail; - -- attrs = (struct attribute **)(events_group + 1); -- events_group->name = "events"; -- events_group->attrs = attrs; -+ attrs = (struct attribute **)(attr_group + 1); -+ attr_group->name = "events"; -+ attr_group->attrs = attrs; - - for (j = 0; j < i; j++) - attrs[j] = &type->event_descs[j].attr.attr; - -- type->events_group = events_group; -+ type->events_group = attr_group; - } - - type->pmu_group = &uncore_pmu_attr_group; -@@ -2853,6 +2853,7 @@ static int __init uncore_cpu_init(void) - msr_uncores = nhm_msr_uncores; - break; - case 42: /* Sandy Bridge */ -+ case 58: /* Ivy Bridge */ - if (snb_uncore_cbox.num_boxes > max_cores) - snb_uncore_cbox.num_boxes = max_cores; - msr_uncores = snb_msr_uncores; -diff --git a/block/blk-cgroup.c b/block/blk-cgroup.c -index b2b9837..e8918ff 100644 ---- a/block/blk-cgroup.c -+++ b/block/blk-cgroup.c -@@ -972,10 +972,10 @@ int blkcg_activate_policy(struct request_queue *q, - if (!new_blkg) - return -ENOMEM; - -- preloaded = !radix_tree_preload(GFP_KERNEL); -- - blk_queue_bypass_start(q); - -+ preloaded = !radix_tree_preload(GFP_KERNEL); -+ - /* - * Make sure the root blkg exists and count the existing blkgs. As - * @q is bypassing at this point, blkg_lookup_create() can't be -diff --git a/drivers/edac/edac_mc_sysfs.c b/drivers/edac/edac_mc_sysfs.c -index 5899a76..769d92e 100644 ---- a/drivers/edac/edac_mc_sysfs.c -+++ b/drivers/edac/edac_mc_sysfs.c -@@ -327,17 +327,17 @@ static struct device_attribute *dynamic_csrow_dimm_attr[] = { - }; - - /* possible dynamic channel ce_count attribute files */ --DEVICE_CHANNEL(ch0_ce_count, S_IRUGO | S_IWUSR, -+DEVICE_CHANNEL(ch0_ce_count, S_IRUGO, - channel_ce_count_show, NULL, 0); --DEVICE_CHANNEL(ch1_ce_count, S_IRUGO | S_IWUSR, -+DEVICE_CHANNEL(ch1_ce_count, S_IRUGO, - channel_ce_count_show, NULL, 1); --DEVICE_CHANNEL(ch2_ce_count, S_IRUGO | S_IWUSR, -+DEVICE_CHANNEL(ch2_ce_count, S_IRUGO, - channel_ce_count_show, NULL, 2); --DEVICE_CHANNEL(ch3_ce_count, S_IRUGO | S_IWUSR, -+DEVICE_CHANNEL(ch3_ce_count, S_IRUGO, - channel_ce_count_show, NULL, 3); --DEVICE_CHANNEL(ch4_ce_count, S_IRUGO | S_IWUSR, -+DEVICE_CHANNEL(ch4_ce_count, S_IRUGO, - channel_ce_count_show, NULL, 4); --DEVICE_CHANNEL(ch5_ce_count, S_IRUGO | S_IWUSR, -+DEVICE_CHANNEL(ch5_ce_count, S_IRUGO, - channel_ce_count_show, NULL, 5); - - /* Total possible dynamic ce_count attribute file table */ -diff --git a/drivers/gpu/drm/ast/ast_drv.h b/drivers/gpu/drm/ast/ast_drv.h -index 5284292..02e52d5 100644 ---- a/drivers/gpu/drm/ast/ast_drv.h -+++ b/drivers/gpu/drm/ast/ast_drv.h -@@ -241,6 +241,8 @@ struct ast_fbdev { - void *sysram; - int size; - struct ttm_bo_kmap_obj mapping; -+ int x1, y1, x2, y2; /* dirty rect */ -+ spinlock_t dirty_lock; - }; - - #define to_ast_crtc(x) container_of(x, struct ast_crtc, base) -diff --git a/drivers/gpu/drm/ast/ast_fb.c b/drivers/gpu/drm/ast/ast_fb.c -index 34931fe..fbc0823 100644 ---- a/drivers/gpu/drm/ast/ast_fb.c -+++ b/drivers/gpu/drm/ast/ast_fb.c -@@ -53,16 +53,52 @@ static void ast_dirty_update(struct ast_fbdev *afbdev, - int bpp = (afbdev->afb.base.bits_per_pixel + 7)/8; - int ret; - bool unmap = false; -+ bool store_for_later = false; -+ int x2, y2; -+ unsigned long flags; - - obj = afbdev->afb.obj; - bo = gem_to_ast_bo(obj); - -+ /* -+ * try and reserve the BO, if we fail with busy -+ * then the BO is being moved and we should -+ * store up the damage until later. -+ */ - ret = ast_bo_reserve(bo, true); - if (ret) { -- DRM_ERROR("failed to reserve fb bo\n"); -+ if (ret != -EBUSY) -+ return; -+ -+ store_for_later = true; -+ } -+ -+ x2 = x + width - 1; -+ y2 = y + height - 1; -+ spin_lock_irqsave(&afbdev->dirty_lock, flags); -+ -+ if (afbdev->y1 < y) -+ y = afbdev->y1; -+ if (afbdev->y2 > y2) -+ y2 = afbdev->y2; -+ if (afbdev->x1 < x) -+ x = afbdev->x1; -+ if (afbdev->x2 > x2) -+ x2 = afbdev->x2; -+ -+ if (store_for_later) { -+ afbdev->x1 = x; -+ afbdev->x2 = x2; -+ afbdev->y1 = y; -+ afbdev->y2 = y2; -+ spin_unlock_irqrestore(&afbdev->dirty_lock, flags); - return; - } - -+ afbdev->x1 = afbdev->y1 = INT_MAX; -+ afbdev->x2 = afbdev->y2 = 0; -+ spin_unlock_irqrestore(&afbdev->dirty_lock, flags); -+ - if (!bo->kmap.virtual) { - ret = ttm_bo_kmap(&bo->bo, 0, bo->bo.num_pages, &bo->kmap); - if (ret) { -@@ -72,10 +108,10 @@ static void ast_dirty_update(struct ast_fbdev *afbdev, - } - unmap = true; - } -- for (i = y; i < y + height; i++) { -+ for (i = y; i <= y2; i++) { - /* assume equal stride for now */ - src_offset = dst_offset = i * afbdev->afb.base.pitches[0] + (x * bpp); -- memcpy_toio(bo->kmap.virtual + src_offset, afbdev->sysram + src_offset, width * bpp); -+ memcpy_toio(bo->kmap.virtual + src_offset, afbdev->sysram + src_offset, (x2 - x + 1) * bpp); - - } - if (unmap) -@@ -292,6 +328,7 @@ int ast_fbdev_init(struct drm_device *dev) - - ast->fbdev = afbdev; - afbdev->helper.funcs = &ast_fb_helper_funcs; -+ spin_lock_init(&afbdev->dirty_lock); - ret = drm_fb_helper_init(dev, &afbdev->helper, - 1, 1); - if (ret) { -diff --git a/drivers/gpu/drm/ast/ast_ttm.c b/drivers/gpu/drm/ast/ast_ttm.c -index 3602731..09da339 100644 ---- a/drivers/gpu/drm/ast/ast_ttm.c -+++ b/drivers/gpu/drm/ast/ast_ttm.c -@@ -316,7 +316,7 @@ int ast_bo_reserve(struct ast_bo *bo, bool no_wait) - - ret = ttm_bo_reserve(&bo->bo, true, no_wait, false, 0); - if (ret) { -- if (ret != -ERESTARTSYS) -+ if (ret != -ERESTARTSYS && ret != -EBUSY) - DRM_ERROR("reserve failed %p\n", bo); - return ret; - } -diff --git a/drivers/gpu/drm/cirrus/cirrus_drv.h b/drivers/gpu/drm/cirrus/cirrus_drv.h -index 6e0cc72..7ca0595 100644 ---- a/drivers/gpu/drm/cirrus/cirrus_drv.h -+++ b/drivers/gpu/drm/cirrus/cirrus_drv.h -@@ -154,6 +154,8 @@ struct cirrus_fbdev { - struct list_head fbdev_list; - void *sysram; - int size; -+ int x1, y1, x2, y2; /* dirty rect */ -+ spinlock_t dirty_lock; - }; - - struct cirrus_bo { -diff --git a/drivers/gpu/drm/cirrus/cirrus_fbdev.c b/drivers/gpu/drm/cirrus/cirrus_fbdev.c -index e25afcc..3541b56 100644 ---- a/drivers/gpu/drm/cirrus/cirrus_fbdev.c -+++ b/drivers/gpu/drm/cirrus/cirrus_fbdev.c -@@ -27,16 +27,51 @@ static void cirrus_dirty_update(struct cirrus_fbdev *afbdev, - int bpp = (afbdev->gfb.base.bits_per_pixel + 7)/8; - int ret; - bool unmap = false; -+ bool store_for_later = false; -+ int x2, y2; -+ unsigned long flags; - - obj = afbdev->gfb.obj; - bo = gem_to_cirrus_bo(obj); - -+ /* -+ * try and reserve the BO, if we fail with busy -+ * then the BO is being moved and we should -+ * store up the damage until later. -+ */ - ret = cirrus_bo_reserve(bo, true); - if (ret) { -- DRM_ERROR("failed to reserve fb bo\n"); -+ if (ret != -EBUSY) -+ return; -+ store_for_later = true; -+ } -+ -+ x2 = x + width - 1; -+ y2 = y + height - 1; -+ spin_lock_irqsave(&afbdev->dirty_lock, flags); -+ -+ if (afbdev->y1 < y) -+ y = afbdev->y1; -+ if (afbdev->y2 > y2) -+ y2 = afbdev->y2; -+ if (afbdev->x1 < x) -+ x = afbdev->x1; -+ if (afbdev->x2 > x2) -+ x2 = afbdev->x2; -+ -+ if (store_for_later) { -+ afbdev->x1 = x; -+ afbdev->x2 = x2; -+ afbdev->y1 = y; -+ afbdev->y2 = y2; -+ spin_unlock_irqrestore(&afbdev->dirty_lock, flags); - return; - } - -+ afbdev->x1 = afbdev->y1 = INT_MAX; -+ afbdev->x2 = afbdev->y2 = 0; -+ spin_unlock_irqrestore(&afbdev->dirty_lock, flags); -+ - if (!bo->kmap.virtual) { - ret = ttm_bo_kmap(&bo->bo, 0, bo->bo.num_pages, &bo->kmap); - if (ret) { -@@ -268,6 +303,7 @@ int cirrus_fbdev_init(struct cirrus_device *cdev) - - cdev->mode_info.gfbdev = gfbdev; - gfbdev->helper.funcs = &cirrus_fb_helper_funcs; -+ spin_lock_init(&gfbdev->dirty_lock); - - ret = drm_fb_helper_init(cdev->dev, &gfbdev->helper, - cdev->num_crtc, CIRRUSFB_CONN_LIMIT); -diff --git a/drivers/gpu/drm/cirrus/cirrus_ttm.c b/drivers/gpu/drm/cirrus/cirrus_ttm.c -index 1413a26..2ed8cfc 100644 ---- a/drivers/gpu/drm/cirrus/cirrus_ttm.c -+++ b/drivers/gpu/drm/cirrus/cirrus_ttm.c -@@ -321,7 +321,7 @@ int cirrus_bo_reserve(struct cirrus_bo *bo, bool no_wait) - - ret = ttm_bo_reserve(&bo->bo, true, no_wait, false, 0); - if (ret) { -- if (ret != -ERESTARTSYS) -+ if (ret != -ERESTARTSYS && ret != -EBUSY) - DRM_ERROR("reserve failed %p\n", bo); - return ret; - } -diff --git a/drivers/gpu/drm/drm_gem.c b/drivers/gpu/drm/drm_gem.c -index af779ae..cf919e3 100644 ---- a/drivers/gpu/drm/drm_gem.c -+++ b/drivers/gpu/drm/drm_gem.c -@@ -205,11 +205,11 @@ static void - drm_gem_remove_prime_handles(struct drm_gem_object *obj, struct drm_file *filp) - { - if (obj->import_attach) { -- drm_prime_remove_imported_buf_handle(&filp->prime, -+ drm_prime_remove_buf_handle(&filp->prime, - obj->import_attach->dmabuf); - } - if (obj->export_dma_buf) { -- drm_prime_remove_imported_buf_handle(&filp->prime, -+ drm_prime_remove_buf_handle(&filp->prime, - obj->export_dma_buf); - } - } -diff --git a/drivers/gpu/drm/drm_prime.c b/drivers/gpu/drm/drm_prime.c -index 366910d..db767ca 100644 ---- a/drivers/gpu/drm/drm_prime.c -+++ b/drivers/gpu/drm/drm_prime.c -@@ -62,6 +62,7 @@ struct drm_prime_member { - struct dma_buf *dma_buf; - uint32_t handle; - }; -+static int drm_prime_add_buf_handle(struct drm_prime_file_private *prime_fpriv, struct dma_buf *dma_buf, uint32_t handle); - - static struct sg_table *drm_gem_map_dma_buf(struct dma_buf_attachment *attach, - enum dma_data_direction dir) -@@ -200,7 +201,8 @@ int drm_gem_prime_handle_to_fd(struct drm_device *dev, - { - struct drm_gem_object *obj; - void *buf; -- int ret; -+ int ret = 0; -+ struct dma_buf *dmabuf; - - obj = drm_gem_object_lookup(dev, file_priv, handle); - if (!obj) -@@ -209,43 +211,44 @@ int drm_gem_prime_handle_to_fd(struct drm_device *dev, - mutex_lock(&file_priv->prime.lock); - /* re-export the original imported object */ - if (obj->import_attach) { -- get_dma_buf(obj->import_attach->dmabuf); -- *prime_fd = dma_buf_fd(obj->import_attach->dmabuf, flags); -- drm_gem_object_unreference_unlocked(obj); -- mutex_unlock(&file_priv->prime.lock); -- return 0; -+ dmabuf = obj->import_attach->dmabuf; -+ goto out_have_obj; - } - - if (obj->export_dma_buf) { -- get_dma_buf(obj->export_dma_buf); -- *prime_fd = dma_buf_fd(obj->export_dma_buf, flags); -- drm_gem_object_unreference_unlocked(obj); -- } else { -- buf = dev->driver->gem_prime_export(dev, obj, flags); -- if (IS_ERR(buf)) { -- /* normally the created dma-buf takes ownership of the ref, -- * but if that fails then drop the ref -- */ -- drm_gem_object_unreference_unlocked(obj); -- mutex_unlock(&file_priv->prime.lock); -- return PTR_ERR(buf); -- } -- obj->export_dma_buf = buf; -- *prime_fd = dma_buf_fd(buf, flags); -+ dmabuf = obj->export_dma_buf; -+ goto out_have_obj; - } -+ -+ buf = dev->driver->gem_prime_export(dev, obj, flags); -+ if (IS_ERR(buf)) { -+ /* normally the created dma-buf takes ownership of the ref, -+ * but if that fails then drop the ref -+ */ -+ ret = PTR_ERR(buf); -+ goto out; -+ } -+ obj->export_dma_buf = buf; -+ - /* if we've exported this buffer the cheat and add it to the import list - * so we get the correct handle back - */ -- ret = drm_prime_add_imported_buf_handle(&file_priv->prime, -- obj->export_dma_buf, handle); -- if (ret) { -- drm_gem_object_unreference_unlocked(obj); -- mutex_unlock(&file_priv->prime.lock); -- return ret; -- } -+ ret = drm_prime_add_buf_handle(&file_priv->prime, -+ obj->export_dma_buf, handle); -+ if (ret) -+ goto out; - -+ *prime_fd = dma_buf_fd(buf, flags); - mutex_unlock(&file_priv->prime.lock); - return 0; -+ -+out_have_obj: -+ get_dma_buf(dmabuf); -+ *prime_fd = dma_buf_fd(dmabuf, flags); -+out: -+ drm_gem_object_unreference_unlocked(obj); -+ mutex_unlock(&file_priv->prime.lock); -+ return ret; - } - EXPORT_SYMBOL(drm_gem_prime_handle_to_fd); - -@@ -268,7 +271,6 @@ struct drm_gem_object *drm_gem_prime_import(struct drm_device *dev, - * refcount on gem itself instead of f_count of dmabuf. - */ - drm_gem_object_reference(obj); -- dma_buf_put(dma_buf); - return obj; - } - } -@@ -277,6 +279,8 @@ struct drm_gem_object *drm_gem_prime_import(struct drm_device *dev, - if (IS_ERR(attach)) - return ERR_PTR(PTR_ERR(attach)); - -+ get_dma_buf(dma_buf); -+ - sgt = dma_buf_map_attachment(attach, DMA_BIDIRECTIONAL); - if (IS_ERR_OR_NULL(sgt)) { - ret = PTR_ERR(sgt); -@@ -297,6 +301,8 @@ fail_unmap: - dma_buf_unmap_attachment(attach, sgt, DMA_BIDIRECTIONAL); - fail_detach: - dma_buf_detach(dma_buf, attach); -+ dma_buf_put(dma_buf); -+ - return ERR_PTR(ret); - } - EXPORT_SYMBOL(drm_gem_prime_import); -@@ -314,7 +320,7 @@ int drm_gem_prime_fd_to_handle(struct drm_device *dev, - - mutex_lock(&file_priv->prime.lock); - -- ret = drm_prime_lookup_imported_buf_handle(&file_priv->prime, -+ ret = drm_prime_lookup_buf_handle(&file_priv->prime, - dma_buf, handle); - if (!ret) { - ret = 0; -@@ -333,12 +339,15 @@ int drm_gem_prime_fd_to_handle(struct drm_device *dev, - if (ret) - goto out_put; - -- ret = drm_prime_add_imported_buf_handle(&file_priv->prime, -+ ret = drm_prime_add_buf_handle(&file_priv->prime, - dma_buf, *handle); - if (ret) - goto fail; - - mutex_unlock(&file_priv->prime.lock); -+ -+ dma_buf_put(dma_buf); -+ - return 0; - - fail: -@@ -491,7 +500,7 @@ void drm_prime_destroy_file_private(struct drm_prime_file_private *prime_fpriv) - } - EXPORT_SYMBOL(drm_prime_destroy_file_private); - --int drm_prime_add_imported_buf_handle(struct drm_prime_file_private *prime_fpriv, struct dma_buf *dma_buf, uint32_t handle) -+static int drm_prime_add_buf_handle(struct drm_prime_file_private *prime_fpriv, struct dma_buf *dma_buf, uint32_t handle) - { - struct drm_prime_member *member; - -@@ -499,14 +508,14 @@ int drm_prime_add_imported_buf_handle(struct drm_prime_file_private *prime_fpriv - if (!member) - return -ENOMEM; - -+ get_dma_buf(dma_buf); - member->dma_buf = dma_buf; - member->handle = handle; - list_add(&member->entry, &prime_fpriv->head); - return 0; - } --EXPORT_SYMBOL(drm_prime_add_imported_buf_handle); - --int drm_prime_lookup_imported_buf_handle(struct drm_prime_file_private *prime_fpriv, struct dma_buf *dma_buf, uint32_t *handle) -+int drm_prime_lookup_buf_handle(struct drm_prime_file_private *prime_fpriv, struct dma_buf *dma_buf, uint32_t *handle) - { - struct drm_prime_member *member; - -@@ -518,19 +527,20 @@ int drm_prime_lookup_imported_buf_handle(struct drm_prime_file_private *prime_fp - } - return -ENOENT; - } --EXPORT_SYMBOL(drm_prime_lookup_imported_buf_handle); -+EXPORT_SYMBOL(drm_prime_lookup_buf_handle); - --void drm_prime_remove_imported_buf_handle(struct drm_prime_file_private *prime_fpriv, struct dma_buf *dma_buf) -+void drm_prime_remove_buf_handle(struct drm_prime_file_private *prime_fpriv, struct dma_buf *dma_buf) - { - struct drm_prime_member *member, *safe; - - mutex_lock(&prime_fpriv->lock); - list_for_each_entry_safe(member, safe, &prime_fpriv->head, entry) { - if (member->dma_buf == dma_buf) { -+ dma_buf_put(dma_buf); - list_del(&member->entry); - kfree(member); - } - } - mutex_unlock(&prime_fpriv->lock); - } --EXPORT_SYMBOL(drm_prime_remove_imported_buf_handle); -+EXPORT_SYMBOL(drm_prime_remove_buf_handle); -diff --git a/drivers/gpu/drm/exynos/exynos_drm_dmabuf.c b/drivers/gpu/drm/exynos/exynos_drm_dmabuf.c -index ba0a3aa..ff7f2a8 100644 ---- a/drivers/gpu/drm/exynos/exynos_drm_dmabuf.c -+++ b/drivers/gpu/drm/exynos/exynos_drm_dmabuf.c -@@ -235,7 +235,6 @@ struct drm_gem_object *exynos_dmabuf_prime_import(struct drm_device *drm_dev, - * refcount on gem itself instead of f_count of dmabuf. - */ - drm_gem_object_reference(obj); -- dma_buf_put(dma_buf); - return obj; - } - } -@@ -244,6 +243,7 @@ struct drm_gem_object *exynos_dmabuf_prime_import(struct drm_device *drm_dev, - if (IS_ERR(attach)) - return ERR_PTR(-EINVAL); - -+ get_dma_buf(dma_buf); - - sgt = dma_buf_map_attachment(attach, DMA_BIDIRECTIONAL); - if (IS_ERR_OR_NULL(sgt)) { -@@ -298,6 +298,8 @@ err_unmap_attach: - dma_buf_unmap_attachment(attach, sgt, DMA_BIDIRECTIONAL); - err_buf_detach: - dma_buf_detach(dma_buf, attach); -+ dma_buf_put(dma_buf); -+ - return ERR_PTR(ret); - } - -diff --git a/drivers/gpu/drm/gma500/psb_irq.c b/drivers/gpu/drm/gma500/psb_irq.c -index 8652cdf..029eccf 100644 ---- a/drivers/gpu/drm/gma500/psb_irq.c -+++ b/drivers/gpu/drm/gma500/psb_irq.c -@@ -211,7 +211,7 @@ irqreturn_t psb_irq_handler(DRM_IRQ_ARGS) - - vdc_stat = PSB_RVDC32(PSB_INT_IDENTITY_R); - -- if (vdc_stat & _PSB_PIPE_EVENT_FLAG) -+ if (vdc_stat & (_PSB_PIPE_EVENT_FLAG|_PSB_IRQ_ASLE)) - dsp_int = 1; - - /* FIXME: Handle Medfield -diff --git a/drivers/gpu/drm/i915/i915_drv.h b/drivers/gpu/drm/i915/i915_drv.h -index 01769e2..ef99b1c 100644 ---- a/drivers/gpu/drm/i915/i915_drv.h -+++ b/drivers/gpu/drm/i915/i915_drv.h -@@ -941,6 +941,7 @@ typedef struct drm_i915_private { - unsigned int int_crt_support:1; - unsigned int lvds_use_ssc:1; - unsigned int display_clock_mode:1; -+ unsigned int fdi_rx_polarity_inverted:1; - int lvds_ssc_freq; - unsigned int bios_lvds_val; /* initial [PCH_]LVDS reg val in VBIOS */ - struct { -diff --git a/drivers/gpu/drm/i915/i915_gem.c b/drivers/gpu/drm/i915/i915_gem.c -index 0e207e6..73cb479 100644 ---- a/drivers/gpu/drm/i915/i915_gem.c -+++ b/drivers/gpu/drm/i915/i915_gem.c -@@ -2678,17 +2678,35 @@ static inline int fence_number(struct drm_i915_private *dev_priv, - return fence - dev_priv->fence_regs; - } - -+static void i915_gem_write_fence__ipi(void *data) -+{ -+ wbinvd(); -+} -+ - static void i915_gem_object_update_fence(struct drm_i915_gem_object *obj, - struct drm_i915_fence_reg *fence, - bool enable) - { -- struct drm_i915_private *dev_priv = obj->base.dev->dev_private; -- int reg = fence_number(dev_priv, fence); -- -- i915_gem_write_fence(obj->base.dev, reg, enable ? obj : NULL); -+ struct drm_device *dev = obj->base.dev; -+ struct drm_i915_private *dev_priv = dev->dev_private; -+ int fence_reg = fence_number(dev_priv, fence); -+ -+ /* In order to fully serialize access to the fenced region and -+ * the update to the fence register we need to take extreme -+ * measures on SNB+. In theory, the write to the fence register -+ * flushes all memory transactions before, and coupled with the -+ * mb() placed around the register write we serialise all memory -+ * operations with respect to the changes in the tiler. Yet, on -+ * SNB+ we need to take a step further and emit an explicit wbinvd() -+ * on each processor in order to manually flush all memory -+ * transactions before updating the fence register. -+ */ -+ if (HAS_LLC(obj->base.dev)) -+ on_each_cpu(i915_gem_write_fence__ipi, NULL, 1); -+ i915_gem_write_fence(dev, fence_reg, enable ? obj : NULL); - - if (enable) { -- obj->fence_reg = reg; -+ obj->fence_reg = fence_reg; - fence->obj = obj; - list_move_tail(&fence->lru_list, &dev_priv->mm.fence_list); - } else { -diff --git a/drivers/gpu/drm/i915/i915_gem_context.c b/drivers/gpu/drm/i915/i915_gem_context.c -index 94d873a..a1e8ecb 100644 ---- a/drivers/gpu/drm/i915/i915_gem_context.c -+++ b/drivers/gpu/drm/i915/i915_gem_context.c -@@ -152,6 +152,13 @@ create_hw_context(struct drm_device *dev, - return ERR_PTR(-ENOMEM); - } - -+ if (INTEL_INFO(dev)->gen >= 7) { -+ ret = i915_gem_object_set_cache_level(ctx->obj, -+ I915_CACHE_LLC_MLC); -+ if (ret) -+ goto err_out; -+ } -+ - /* The ring associated with the context object is handled by the normal - * object tracking code. We give an initial ring value simple to pass an - * assertion in the context switch code. -diff --git a/drivers/gpu/drm/i915/i915_gem_dmabuf.c b/drivers/gpu/drm/i915/i915_gem_dmabuf.c -index 6a5af68..c303de1 100644 ---- a/drivers/gpu/drm/i915/i915_gem_dmabuf.c -+++ b/drivers/gpu/drm/i915/i915_gem_dmabuf.c -@@ -271,7 +271,6 @@ struct drm_gem_object *i915_gem_prime_import(struct drm_device *dev, - * refcount on gem itself instead of f_count of dmabuf. - */ - drm_gem_object_reference(&obj->base); -- dma_buf_put(dma_buf); - return &obj->base; - } - } -@@ -281,6 +280,8 @@ struct drm_gem_object *i915_gem_prime_import(struct drm_device *dev, - if (IS_ERR(attach)) - return ERR_CAST(attach); - -+ get_dma_buf(dma_buf); -+ - obj = i915_gem_object_alloc(dev); - if (obj == NULL) { - ret = -ENOMEM; -@@ -300,5 +301,7 @@ struct drm_gem_object *i915_gem_prime_import(struct drm_device *dev, - - fail_detach: - dma_buf_detach(dma_buf, attach); -+ dma_buf_put(dma_buf); -+ - return ERR_PTR(ret); - } -diff --git a/drivers/gpu/drm/i915/i915_gem_gtt.c b/drivers/gpu/drm/i915/i915_gem_gtt.c -index 926a1e2..193c8d1 100644 ---- a/drivers/gpu/drm/i915/i915_gem_gtt.c -+++ b/drivers/gpu/drm/i915/i915_gem_gtt.c -@@ -182,8 +182,7 @@ static int gen6_ppgtt_init(struct i915_hw_ppgtt *ppgtt) - /* ppgtt PDEs reside in the global gtt pagetable, which has 512*1024 - * entries. For aliasing ppgtt support we just steal them at the end for - * now. */ -- first_pd_entry_in_global_pt = -- gtt_total_entries(dev_priv->gtt) - I915_PPGTT_PD_ENTRIES; -+ first_pd_entry_in_global_pt = gtt_total_entries(dev_priv->gtt); - - ppgtt->num_pd_entries = I915_PPGTT_PD_ENTRIES; - ppgtt->clear_range = gen6_ppgtt_clear_range; -diff --git a/drivers/gpu/drm/i915/i915_reg.h b/drivers/gpu/drm/i915/i915_reg.h -index 848992f..c91124f 100644 ---- a/drivers/gpu/drm/i915/i915_reg.h -+++ b/drivers/gpu/drm/i915/i915_reg.h -@@ -3827,7 +3827,7 @@ - #define _TRANSB_CHICKEN2 0xf1064 - #define TRANS_CHICKEN2(pipe) _PIPE(pipe, _TRANSA_CHICKEN2, _TRANSB_CHICKEN2) - #define TRANS_CHICKEN2_TIMING_OVERRIDE (1<<31) -- -+#define TRANS_CHICKEN2_FDI_POLARITY_REVERSED (1<<29) - - #define SOUTH_CHICKEN1 0xc2000 - #define FDIA_PHASE_SYNC_SHIFT_OVR 19 -diff --git a/drivers/gpu/drm/i915/intel_bios.c b/drivers/gpu/drm/i915/intel_bios.c -index 55ffba1..bd83391 100644 ---- a/drivers/gpu/drm/i915/intel_bios.c -+++ b/drivers/gpu/drm/i915/intel_bios.c -@@ -351,12 +351,14 @@ parse_general_features(struct drm_i915_private *dev_priv, - dev_priv->lvds_ssc_freq = - intel_bios_ssc_frequency(dev, general->ssc_freq); - dev_priv->display_clock_mode = general->display_clock_mode; -- DRM_DEBUG_KMS("BDB_GENERAL_FEATURES int_tv_support %d int_crt_support %d lvds_use_ssc %d lvds_ssc_freq %d display_clock_mode %d\n", -+ dev_priv->fdi_rx_polarity_inverted = general->fdi_rx_polarity_inverted; -+ DRM_DEBUG_KMS("BDB_GENERAL_FEATURES int_tv_support %d int_crt_support %d lvds_use_ssc %d lvds_ssc_freq %d display_clock_mode %d fdi_rx_polarity_inverted %d\n", - dev_priv->int_tv_support, - dev_priv->int_crt_support, - dev_priv->lvds_use_ssc, - dev_priv->lvds_ssc_freq, -- dev_priv->display_clock_mode); -+ dev_priv->display_clock_mode, -+ dev_priv->fdi_rx_polarity_inverted); - } - } - -diff --git a/drivers/gpu/drm/i915/intel_bios.h b/drivers/gpu/drm/i915/intel_bios.h -index 36e57f9..e088d6f 100644 ---- a/drivers/gpu/drm/i915/intel_bios.h -+++ b/drivers/gpu/drm/i915/intel_bios.h -@@ -127,7 +127,9 @@ struct bdb_general_features { - /* bits 3 */ - u8 disable_smooth_vision:1; - u8 single_dvi:1; -- u8 rsvd9:6; /* finish byte */ -+ u8 rsvd9:1; -+ u8 fdi_rx_polarity_inverted:1; -+ u8 rsvd10:4; /* finish byte */ - - /* bits 4 */ - u8 legacy_monitor_detect; -diff --git a/drivers/gpu/drm/i915/intel_display.c b/drivers/gpu/drm/i915/intel_display.c -index b20d501..c2d173a 100644 ---- a/drivers/gpu/drm/i915/intel_display.c -+++ b/drivers/gpu/drm/i915/intel_display.c -@@ -7589,22 +7589,25 @@ intel_modeset_affected_pipes(struct drm_crtc *crtc, unsigned *modeset_pipes, - if (crtc->enabled) - *prepare_pipes |= 1 << intel_crtc->pipe; - -- /* We only support modeset on one single crtc, hence we need to do that -- * only for the passed in crtc iff we change anything else than just -- * disable crtcs. -- * -- * This is actually not true, to be fully compatible with the old crtc -- * helper we automatically disable _any_ output (i.e. doesn't need to be -- * connected to the crtc we're modesetting on) if it's disconnected. -- * Which is a rather nutty api (since changed the output configuration -- * without userspace's explicit request can lead to confusion), but -- * alas. Hence we currently need to modeset on all pipes we prepare. */ -+ /* -+ * For simplicity do a full modeset on any pipe where the output routing -+ * changed. We could be more clever, but that would require us to be -+ * more careful with calling the relevant encoder->mode_set functions. -+ */ - if (*prepare_pipes) - *modeset_pipes = *prepare_pipes; - - /* ... and mask these out. */ - *modeset_pipes &= ~(*disable_pipes); - *prepare_pipes &= ~(*disable_pipes); -+ -+ /* -+ * HACK: We don't (yet) fully support global modesets. intel_set_config -+ * obies this rule, but the modeset restore mode of -+ * intel_modeset_setup_hw_state does not. -+ */ -+ *modeset_pipes &= 1 << intel_crtc->pipe; -+ *prepare_pipes &= 1 << intel_crtc->pipe; - } - - static bool intel_crtc_in_use(struct drm_crtc *crtc) -@@ -7771,9 +7774,9 @@ intel_modeset_check_state(struct drm_device *dev) - } - } - --int intel_set_mode(struct drm_crtc *crtc, -- struct drm_display_mode *mode, -- int x, int y, struct drm_framebuffer *fb) -+static int __intel_set_mode(struct drm_crtc *crtc, -+ struct drm_display_mode *mode, -+ int x, int y, struct drm_framebuffer *fb) - { - struct drm_device *dev = crtc->dev; - drm_i915_private_t *dev_priv = dev->dev_private; -@@ -7863,8 +7866,6 @@ done: - if (ret && crtc->enabled) { - crtc->hwmode = *saved_hwmode; - crtc->mode = *saved_mode; -- } else { -- intel_modeset_check_state(dev); - } - - out: -@@ -7872,6 +7873,20 @@ out: - return ret; - } - -+int intel_set_mode(struct drm_crtc *crtc, -+ struct drm_display_mode *mode, -+ int x, int y, struct drm_framebuffer *fb) -+{ -+ int ret; -+ -+ ret = __intel_set_mode(crtc, mode, x, y, fb); -+ -+ if (ret == 0) -+ intel_modeset_check_state(crtc->dev); -+ -+ return ret; -+} -+ - void intel_crtc_restore_mode(struct drm_crtc *crtc) - { - intel_set_mode(crtc, &crtc->mode, crtc->x, crtc->y, crtc->fb); -@@ -8314,7 +8329,7 @@ static void intel_setup_outputs(struct drm_device *dev) - I915_WRITE(PFIT_CONTROL, 0); - } - -- if (!(HAS_DDI(dev) && (I915_READ(DDI_BUF_CTL(PORT_A)) & DDI_A_4_LANES))) -+ if (!IS_ULT(dev)) - intel_crt_init(dev); - - if (HAS_DDI(dev)) { -@@ -9172,8 +9187,16 @@ void intel_modeset_setup_hw_state(struct drm_device *dev, - } - - if (force_restore) { -+ /* -+ * We need to use raw interfaces for restoring state to avoid -+ * checking (bogus) intermediate states. -+ */ - for_each_pipe(pipe) { -- intel_crtc_restore_mode(dev_priv->pipe_to_crtc_mapping[pipe]); -+ struct drm_crtc *crtc = -+ dev_priv->pipe_to_crtc_mapping[pipe]; -+ -+ __intel_set_mode(crtc, &crtc->mode, crtc->x, crtc->y, -+ crtc->fb); - } - - i915_redisable_vga(dev); -@@ -9236,6 +9259,9 @@ void intel_modeset_cleanup(struct drm_device *dev) - /* flush any delayed tasks or pending work */ - flush_scheduled_work(); - -+ /* destroy backlight, if any, before the connectors */ -+ intel_panel_destroy_backlight(dev); -+ - drm_mode_config_cleanup(dev); - - intel_cleanup_overlay(dev); -diff --git a/drivers/gpu/drm/i915/intel_dp.c b/drivers/gpu/drm/i915/intel_dp.c -index 8fc93f9..b8e17e5 100644 ---- a/drivers/gpu/drm/i915/intel_dp.c -+++ b/drivers/gpu/drm/i915/intel_dp.c -@@ -2538,17 +2538,14 @@ done: - static void - intel_dp_destroy(struct drm_connector *connector) - { -- struct drm_device *dev = connector->dev; - struct intel_dp *intel_dp = intel_attached_dp(connector); - struct intel_connector *intel_connector = to_intel_connector(connector); - - if (!IS_ERR_OR_NULL(intel_connector->edid)) - kfree(intel_connector->edid); - -- if (is_edp(intel_dp)) { -- intel_panel_destroy_backlight(dev); -+ if (is_edp(intel_dp)) - intel_panel_fini(&intel_connector->panel); -- } - - drm_sysfs_connector_remove(connector); - drm_connector_cleanup(connector); -diff --git a/drivers/gpu/drm/i915/intel_dvo.c b/drivers/gpu/drm/i915/intel_dvo.c -index 00e70db..cc70b16 100644 ---- a/drivers/gpu/drm/i915/intel_dvo.c -+++ b/drivers/gpu/drm/i915/intel_dvo.c -@@ -448,6 +448,7 @@ void intel_dvo_init(struct drm_device *dev) - const struct intel_dvo_device *dvo = &intel_dvo_devices[i]; - struct i2c_adapter *i2c; - int gpio; -+ bool dvoinit; - - /* Allow the I2C driver info to specify the GPIO to be used in - * special cases, but otherwise default to what's defined -@@ -467,7 +468,17 @@ void intel_dvo_init(struct drm_device *dev) - i2c = intel_gmbus_get_adapter(dev_priv, gpio); - - intel_dvo->dev = *dvo; -- if (!dvo->dev_ops->init(&intel_dvo->dev, i2c)) -+ -+ /* GMBUS NAK handling seems to be unstable, hence let the -+ * transmitter detection run in bit banging mode for now. -+ */ -+ intel_gmbus_force_bit(i2c, true); -+ -+ dvoinit = dvo->dev_ops->init(&intel_dvo->dev, i2c); -+ -+ intel_gmbus_force_bit(i2c, false); -+ -+ if (!dvoinit) - continue; - - intel_encoder->type = INTEL_OUTPUT_DVO; -diff --git a/drivers/gpu/drm/i915/intel_lvds.c b/drivers/gpu/drm/i915/intel_lvds.c -index 3d1d974..e0d6985 100644 ---- a/drivers/gpu/drm/i915/intel_lvds.c -+++ b/drivers/gpu/drm/i915/intel_lvds.c -@@ -618,7 +618,6 @@ static void intel_lvds_destroy(struct drm_connector *connector) - if (!IS_ERR_OR_NULL(lvds_connector->base.edid)) - kfree(lvds_connector->base.edid); - -- intel_panel_destroy_backlight(connector->dev); - intel_panel_fini(&lvds_connector->base.panel); - - drm_sysfs_connector_remove(connector); -@@ -850,6 +849,14 @@ static const struct dmi_system_id intel_no_lvds[] = { - DMI_MATCH(DMI_PRODUCT_NAME, "X7SPA-H"), - }, - }, -+ { -+ .callback = intel_no_lvds_dmi_callback, -+ .ident = "Fujitsu Esprimo Q900", -+ .matches = { -+ DMI_MATCH(DMI_SYS_VENDOR, "FUJITSU"), -+ DMI_MATCH(DMI_PRODUCT_NAME, "ESPRIMO Q900"), -+ }, -+ }, - - { } /* terminating entry */ - }; -diff --git a/drivers/gpu/drm/i915/intel_panel.c b/drivers/gpu/drm/i915/intel_panel.c -index bee8cb6..94d895b 100644 ---- a/drivers/gpu/drm/i915/intel_panel.c -+++ b/drivers/gpu/drm/i915/intel_panel.c -@@ -422,6 +422,9 @@ int intel_panel_setup_backlight(struct drm_connector *connector) - - intel_panel_init_backlight(dev); - -+ if (WARN_ON(dev_priv->backlight)) -+ return -ENODEV; -+ - memset(&props, 0, sizeof(props)); - props.type = BACKLIGHT_RAW; - props.max_brightness = _intel_panel_get_max_backlight(dev); -@@ -447,8 +450,10 @@ int intel_panel_setup_backlight(struct drm_connector *connector) - void intel_panel_destroy_backlight(struct drm_device *dev) - { - struct drm_i915_private *dev_priv = dev->dev_private; -- if (dev_priv->backlight) -+ if (dev_priv->backlight) { - backlight_device_unregister(dev_priv->backlight); -+ dev_priv->backlight = NULL; -+ } - } - #else - int intel_panel_setup_backlight(struct drm_connector *connector) -diff --git a/drivers/gpu/drm/i915/intel_pm.c b/drivers/gpu/drm/i915/intel_pm.c -index adca007..332b29e 100644 ---- a/drivers/gpu/drm/i915/intel_pm.c -+++ b/drivers/gpu/drm/i915/intel_pm.c -@@ -3562,6 +3562,7 @@ static void cpt_init_clock_gating(struct drm_device *dev) - { - struct drm_i915_private *dev_priv = dev->dev_private; - int pipe; -+ uint32_t val; - - /* - * On Ibex Peak and Cougar Point, we need to disable clock -@@ -3574,8 +3575,12 @@ static void cpt_init_clock_gating(struct drm_device *dev) - /* The below fixes the weird display corruption, a few pixels shifted - * downward, on (only) LVDS of some HP laptops with IVY. - */ -- for_each_pipe(pipe) -- I915_WRITE(TRANS_CHICKEN2(pipe), TRANS_CHICKEN2_TIMING_OVERRIDE); -+ for_each_pipe(pipe) { -+ val = TRANS_CHICKEN2_TIMING_OVERRIDE; -+ if (dev_priv->fdi_rx_polarity_inverted) -+ val |= TRANS_CHICKEN2_FDI_POLARITY_REVERSED; -+ I915_WRITE(TRANS_CHICKEN2(pipe), val); -+ } - /* WADP0ClockGatingDisable */ - for_each_pipe(pipe) { - I915_WRITE(TRANS_CHICKEN1(pipe), -diff --git a/drivers/gpu/drm/i915/intel_sdvo.c b/drivers/gpu/drm/i915/intel_sdvo.c -index d07a8cd..d6df786 100644 ---- a/drivers/gpu/drm/i915/intel_sdvo.c -+++ b/drivers/gpu/drm/i915/intel_sdvo.c -@@ -1235,11 +1235,13 @@ static bool intel_sdvo_get_hw_state(struct intel_encoder *encoder, - struct drm_device *dev = encoder->base.dev; - struct drm_i915_private *dev_priv = dev->dev_private; - struct intel_sdvo *intel_sdvo = to_intel_sdvo(&encoder->base); -+ u16 active_outputs; - u32 tmp; - - tmp = I915_READ(intel_sdvo->sdvo_reg); -+ intel_sdvo_get_active_outputs(intel_sdvo, &active_outputs); - -- if (!(tmp & SDVO_ENABLE)) -+ if (!(tmp & SDVO_ENABLE) && (active_outputs == 0)) - return false; - - if (HAS_PCH_CPT(dev)) -@@ -2739,7 +2741,6 @@ bool intel_sdvo_init(struct drm_device *dev, uint32_t sdvo_reg, bool is_sdvob) - struct intel_sdvo *intel_sdvo; - u32 hotplug_mask; - int i; -- - intel_sdvo = kzalloc(sizeof(struct intel_sdvo), GFP_KERNEL); - if (!intel_sdvo) - return false; -diff --git a/drivers/gpu/drm/mgag200/mgag200_drv.h b/drivers/gpu/drm/mgag200/mgag200_drv.h -index 4d932c4..8065919 100644 ---- a/drivers/gpu/drm/mgag200/mgag200_drv.h -+++ b/drivers/gpu/drm/mgag200/mgag200_drv.h -@@ -115,6 +115,8 @@ struct mga_fbdev { - void *sysram; - int size; - struct ttm_bo_kmap_obj mapping; -+ int x1, y1, x2, y2; /* dirty rect */ -+ spinlock_t dirty_lock; - }; - - struct mga_crtc { -diff --git a/drivers/gpu/drm/mgag200/mgag200_fb.c b/drivers/gpu/drm/mgag200/mgag200_fb.c -index d2253f6..b0dad27 100644 ---- a/drivers/gpu/drm/mgag200/mgag200_fb.c -+++ b/drivers/gpu/drm/mgag200/mgag200_fb.c -@@ -29,16 +29,52 @@ static void mga_dirty_update(struct mga_fbdev *mfbdev, - int bpp = (mfbdev->mfb.base.bits_per_pixel + 7)/8; - int ret; - bool unmap = false; -+ bool store_for_later = false; -+ int x2, y2; -+ unsigned long flags; - - obj = mfbdev->mfb.obj; - bo = gem_to_mga_bo(obj); - -+ /* -+ * try and reserve the BO, if we fail with busy -+ * then the BO is being moved and we should -+ * store up the damage until later. -+ */ - ret = mgag200_bo_reserve(bo, true); - if (ret) { -- DRM_ERROR("failed to reserve fb bo\n"); -+ if (ret != -EBUSY) -+ return; -+ -+ store_for_later = true; -+ } -+ -+ x2 = x + width - 1; -+ y2 = y + height - 1; -+ spin_lock_irqsave(&mfbdev->dirty_lock, flags); -+ -+ if (mfbdev->y1 < y) -+ y = mfbdev->y1; -+ if (mfbdev->y2 > y2) -+ y2 = mfbdev->y2; -+ if (mfbdev->x1 < x) -+ x = mfbdev->x1; -+ if (mfbdev->x2 > x2) -+ x2 = mfbdev->x2; -+ -+ if (store_for_later) { -+ mfbdev->x1 = x; -+ mfbdev->x2 = x2; -+ mfbdev->y1 = y; -+ mfbdev->y2 = y2; -+ spin_unlock_irqrestore(&mfbdev->dirty_lock, flags); - return; - } - -+ mfbdev->x1 = mfbdev->y1 = INT_MAX; -+ mfbdev->x2 = mfbdev->y2 = 0; -+ spin_unlock_irqrestore(&mfbdev->dirty_lock, flags); -+ - if (!bo->kmap.virtual) { - ret = ttm_bo_kmap(&bo->bo, 0, bo->bo.num_pages, &bo->kmap); - if (ret) { -@@ -48,10 +84,10 @@ static void mga_dirty_update(struct mga_fbdev *mfbdev, - } - unmap = true; - } -- for (i = y; i < y + height; i++) { -+ for (i = y; i <= y2; i++) { - /* assume equal stride for now */ - src_offset = dst_offset = i * mfbdev->mfb.base.pitches[0] + (x * bpp); -- memcpy_toio(bo->kmap.virtual + src_offset, mfbdev->sysram + src_offset, width * bpp); -+ memcpy_toio(bo->kmap.virtual + src_offset, mfbdev->sysram + src_offset, (x2 - x + 1) * bpp); - - } - if (unmap) -@@ -255,6 +291,7 @@ int mgag200_fbdev_init(struct mga_device *mdev) - - mdev->mfbdev = mfbdev; - mfbdev->helper.funcs = &mga_fb_helper_funcs; -+ spin_lock_init(&mfbdev->dirty_lock); - - ret = drm_fb_helper_init(mdev->dev, &mfbdev->helper, - mdev->num_crtc, MGAG200FB_CONN_LIMIT); -diff --git a/drivers/gpu/drm/mgag200/mgag200_ttm.c b/drivers/gpu/drm/mgag200/mgag200_ttm.c -index 8fc9d92..401c989 100644 ---- a/drivers/gpu/drm/mgag200/mgag200_ttm.c -+++ b/drivers/gpu/drm/mgag200/mgag200_ttm.c -@@ -315,8 +315,8 @@ int mgag200_bo_reserve(struct mgag200_bo *bo, bool no_wait) - - ret = ttm_bo_reserve(&bo->bo, true, no_wait, false, 0); - if (ret) { -- if (ret != -ERESTARTSYS) -- DRM_ERROR("reserve failed %p\n", bo); -+ if (ret != -ERESTARTSYS && ret != -EBUSY) -+ DRM_ERROR("reserve failed %p %d\n", bo, ret); - return ret; - } - return 0; -diff --git a/drivers/gpu/drm/omapdrm/omap_gem_dmabuf.c b/drivers/gpu/drm/omapdrm/omap_gem_dmabuf.c -index ac74d1b..1bdf7e1 100644 ---- a/drivers/gpu/drm/omapdrm/omap_gem_dmabuf.c -+++ b/drivers/gpu/drm/omapdrm/omap_gem_dmabuf.c -@@ -212,7 +212,6 @@ struct drm_gem_object *omap_gem_prime_import(struct drm_device *dev, - * refcount on gem itself instead of f_count of dmabuf. - */ - drm_gem_object_reference(obj); -- dma_buf_put(buffer); - return obj; - } - } -diff --git a/drivers/gpu/drm/radeon/atom.c b/drivers/gpu/drm/radeon/atom.c -index 46a9c37..fb441a7 100644 ---- a/drivers/gpu/drm/radeon/atom.c -+++ b/drivers/gpu/drm/radeon/atom.c -@@ -1394,10 +1394,10 @@ int atom_allocate_fb_scratch(struct atom_context *ctx) - firmware_usage = (struct _ATOM_VRAM_USAGE_BY_FIRMWARE *)(ctx->bios + data_offset); - - DRM_DEBUG("atom firmware requested %08x %dkb\n", -- firmware_usage->asFirmwareVramReserveInfo[0].ulStartAddrUsedByFirmware, -- firmware_usage->asFirmwareVramReserveInfo[0].usFirmwareUseInKb); -+ le32_to_cpu(firmware_usage->asFirmwareVramReserveInfo[0].ulStartAddrUsedByFirmware), -+ le16_to_cpu(firmware_usage->asFirmwareVramReserveInfo[0].usFirmwareUseInKb)); - -- usage_bytes = firmware_usage->asFirmwareVramReserveInfo[0].usFirmwareUseInKb * 1024; -+ usage_bytes = le16_to_cpu(firmware_usage->asFirmwareVramReserveInfo[0].usFirmwareUseInKb) * 1024; - } - ctx->scratch_size_bytes = 0; - if (usage_bytes == 0) -diff --git a/drivers/gpu/drm/radeon/atombios_crtc.c b/drivers/gpu/drm/radeon/atombios_crtc.c -index 21a892c..6d6fdb3 100644 ---- a/drivers/gpu/drm/radeon/atombios_crtc.c -+++ b/drivers/gpu/drm/radeon/atombios_crtc.c -@@ -557,6 +557,9 @@ static u32 atombios_adjust_pll(struct drm_crtc *crtc, - /* use frac fb div on APUs */ - if (ASIC_IS_DCE41(rdev) || ASIC_IS_DCE61(rdev)) - radeon_crtc->pll_flags |= RADEON_PLL_USE_FRAC_FB_DIV; -+ /* use frac fb div on RS780/RS880 */ -+ if ((rdev->family == CHIP_RS780) || (rdev->family == CHIP_RS880)) -+ radeon_crtc->pll_flags |= RADEON_PLL_USE_FRAC_FB_DIV; - if (ASIC_IS_DCE32(rdev) && mode->clock > 165000) - radeon_crtc->pll_flags |= RADEON_PLL_USE_FRAC_FB_DIV; - } else { -diff --git a/drivers/gpu/drm/radeon/evergreen.c b/drivers/gpu/drm/radeon/evergreen.c -index 305a657..aeaa386 100644 ---- a/drivers/gpu/drm/radeon/evergreen.c -+++ b/drivers/gpu/drm/radeon/evergreen.c -@@ -105,6 +105,27 @@ void evergreen_fix_pci_max_read_req_size(struct radeon_device *rdev) - } - } - -+static bool dce4_is_in_vblank(struct radeon_device *rdev, int crtc) -+{ -+ if (RREG32(EVERGREEN_CRTC_STATUS + crtc_offsets[crtc]) & EVERGREEN_CRTC_V_BLANK) -+ return true; -+ else -+ return false; -+} -+ -+static bool dce4_is_counter_moving(struct radeon_device *rdev, int crtc) -+{ -+ u32 pos1, pos2; -+ -+ pos1 = RREG32(EVERGREEN_CRTC_STATUS_POSITION + crtc_offsets[crtc]); -+ pos2 = RREG32(EVERGREEN_CRTC_STATUS_POSITION + crtc_offsets[crtc]); -+ -+ if (pos1 != pos2) -+ return true; -+ else -+ return false; -+} -+ - /** - * dce4_wait_for_vblank - vblank wait asic callback. - * -@@ -115,21 +136,28 @@ void evergreen_fix_pci_max_read_req_size(struct radeon_device *rdev) - */ - void dce4_wait_for_vblank(struct radeon_device *rdev, int crtc) - { -- int i; -+ unsigned i = 0; - - if (crtc >= rdev->num_crtc) - return; - -- if (RREG32(EVERGREEN_CRTC_CONTROL + crtc_offsets[crtc]) & EVERGREEN_CRTC_MASTER_EN) { -- for (i = 0; i < rdev->usec_timeout; i++) { -- if (!(RREG32(EVERGREEN_CRTC_STATUS + crtc_offsets[crtc]) & EVERGREEN_CRTC_V_BLANK)) -+ if (!(RREG32(EVERGREEN_CRTC_CONTROL + crtc_offsets[crtc]) & EVERGREEN_CRTC_MASTER_EN)) -+ return; -+ -+ /* depending on when we hit vblank, we may be close to active; if so, -+ * wait for another frame. -+ */ -+ while (dce4_is_in_vblank(rdev, crtc)) { -+ if (i++ % 100 == 0) { -+ if (!dce4_is_counter_moving(rdev, crtc)) - break; -- udelay(1); - } -- for (i = 0; i < rdev->usec_timeout; i++) { -- if (RREG32(EVERGREEN_CRTC_STATUS + crtc_offsets[crtc]) & EVERGREEN_CRTC_V_BLANK) -+ } -+ -+ while (!dce4_is_in_vblank(rdev, crtc)) { -+ if (i++ % 100 == 0) { -+ if (!dce4_is_counter_moving(rdev, crtc)) - break; -- udelay(1); - } - } - } -@@ -608,6 +636,16 @@ void evergreen_hpd_init(struct radeon_device *rdev) - - list_for_each_entry(connector, &dev->mode_config.connector_list, head) { - struct radeon_connector *radeon_connector = to_radeon_connector(connector); -+ -+ if (connector->connector_type == DRM_MODE_CONNECTOR_eDP || -+ connector->connector_type == DRM_MODE_CONNECTOR_LVDS) { -+ /* don't try to enable hpd on eDP or LVDS avoid breaking the -+ * aux dp channel on imac and help (but not completely fix) -+ * https://bugzilla.redhat.com/show_bug.cgi?id=726143 -+ * also avoid interrupt storms during dpms. -+ */ -+ continue; -+ } - switch (radeon_connector->hpd.hpd) { - case RADEON_HPD_1: - WREG32(DC_HPD1_CONTROL, tmp); -@@ -1325,17 +1363,16 @@ void evergreen_mc_stop(struct radeon_device *rdev, struct evergreen_mc_save *sav - tmp = RREG32(EVERGREEN_CRTC_BLANK_CONTROL + crtc_offsets[i]); - if (!(tmp & EVERGREEN_CRTC_BLANK_DATA_EN)) { - radeon_wait_for_vblank(rdev, i); -- tmp |= EVERGREEN_CRTC_BLANK_DATA_EN; - WREG32(EVERGREEN_CRTC_UPDATE_LOCK + crtc_offsets[i], 1); -+ tmp |= EVERGREEN_CRTC_BLANK_DATA_EN; - WREG32(EVERGREEN_CRTC_BLANK_CONTROL + crtc_offsets[i], tmp); -- WREG32(EVERGREEN_CRTC_UPDATE_LOCK + crtc_offsets[i], 0); - } - } else { - tmp = RREG32(EVERGREEN_CRTC_CONTROL + crtc_offsets[i]); - if (!(tmp & EVERGREEN_CRTC_DISP_READ_REQUEST_DISABLE)) { - radeon_wait_for_vblank(rdev, i); -- tmp |= EVERGREEN_CRTC_DISP_READ_REQUEST_DISABLE; - WREG32(EVERGREEN_CRTC_UPDATE_LOCK + crtc_offsets[i], 1); -+ tmp |= EVERGREEN_CRTC_DISP_READ_REQUEST_DISABLE; - WREG32(EVERGREEN_CRTC_CONTROL + crtc_offsets[i], tmp); - WREG32(EVERGREEN_CRTC_UPDATE_LOCK + crtc_offsets[i], 0); - } -@@ -1347,6 +1384,15 @@ void evergreen_mc_stop(struct radeon_device *rdev, struct evergreen_mc_save *sav - break; - udelay(1); - } -+ -+ /* XXX this is a hack to avoid strange behavior with EFI on certain systems */ -+ WREG32(EVERGREEN_CRTC_UPDATE_LOCK + crtc_offsets[i], 1); -+ tmp = RREG32(EVERGREEN_CRTC_CONTROL + crtc_offsets[i]); -+ tmp &= ~EVERGREEN_CRTC_MASTER_EN; -+ WREG32(EVERGREEN_CRTC_CONTROL + crtc_offsets[i], tmp); -+ WREG32(EVERGREEN_CRTC_UPDATE_LOCK + crtc_offsets[i], 0); -+ save->crtc_enabled[i] = false; -+ /* ***** */ - } else { - save->crtc_enabled[i] = false; - } -@@ -1364,6 +1410,22 @@ void evergreen_mc_stop(struct radeon_device *rdev, struct evergreen_mc_save *sav - } - /* wait for the MC to settle */ - udelay(100); -+ -+ /* lock double buffered regs */ -+ for (i = 0; i < rdev->num_crtc; i++) { -+ if (save->crtc_enabled[i]) { -+ tmp = RREG32(EVERGREEN_GRPH_UPDATE + crtc_offsets[i]); -+ if (!(tmp & EVERGREEN_GRPH_UPDATE_LOCK)) { -+ tmp |= EVERGREEN_GRPH_UPDATE_LOCK; -+ WREG32(EVERGREEN_GRPH_UPDATE + crtc_offsets[i], tmp); -+ } -+ tmp = RREG32(EVERGREEN_MASTER_UPDATE_LOCK + crtc_offsets[i]); -+ if (!(tmp & 1)) { -+ tmp |= 1; -+ WREG32(EVERGREEN_MASTER_UPDATE_LOCK + crtc_offsets[i], tmp); -+ } -+ } -+ } - } - - void evergreen_mc_resume(struct radeon_device *rdev, struct evergreen_mc_save *save) -@@ -1385,6 +1447,33 @@ void evergreen_mc_resume(struct radeon_device *rdev, struct evergreen_mc_save *s - WREG32(EVERGREEN_VGA_MEMORY_BASE_ADDRESS_HIGH, upper_32_bits(rdev->mc.vram_start)); - WREG32(EVERGREEN_VGA_MEMORY_BASE_ADDRESS, (u32)rdev->mc.vram_start); - -+ /* unlock regs and wait for update */ -+ for (i = 0; i < rdev->num_crtc; i++) { -+ if (save->crtc_enabled[i]) { -+ tmp = RREG32(EVERGREEN_MASTER_UPDATE_MODE + crtc_offsets[i]); -+ if ((tmp & 0x3) != 0) { -+ tmp &= ~0x3; -+ WREG32(EVERGREEN_MASTER_UPDATE_MODE + crtc_offsets[i], tmp); -+ } -+ tmp = RREG32(EVERGREEN_GRPH_UPDATE + crtc_offsets[i]); -+ if (tmp & EVERGREEN_GRPH_UPDATE_LOCK) { -+ tmp &= ~EVERGREEN_GRPH_UPDATE_LOCK; -+ WREG32(EVERGREEN_GRPH_UPDATE + crtc_offsets[i], tmp); -+ } -+ tmp = RREG32(EVERGREEN_MASTER_UPDATE_LOCK + crtc_offsets[i]); -+ if (tmp & 1) { -+ tmp &= ~1; -+ WREG32(EVERGREEN_MASTER_UPDATE_LOCK + crtc_offsets[i], tmp); -+ } -+ for (j = 0; j < rdev->usec_timeout; j++) { -+ tmp = RREG32(EVERGREEN_GRPH_UPDATE + crtc_offsets[i]); -+ if ((tmp & EVERGREEN_GRPH_SURFACE_UPDATE_PENDING) == 0) -+ break; -+ udelay(1); -+ } -+ } -+ } -+ - /* unblackout the MC */ - tmp = RREG32(MC_SHARED_BLACKOUT_CNTL); - tmp &= ~BLACKOUT_MODE_MASK; -diff --git a/drivers/gpu/drm/radeon/evergreen_reg.h b/drivers/gpu/drm/radeon/evergreen_reg.h -index f585be1..881aba2 100644 ---- a/drivers/gpu/drm/radeon/evergreen_reg.h -+++ b/drivers/gpu/drm/radeon/evergreen_reg.h -@@ -226,6 +226,8 @@ - #define EVERGREEN_CRTC_STATUS_HV_COUNT 0x6ea0 - #define EVERGREEN_MASTER_UPDATE_MODE 0x6ef8 - #define EVERGREEN_CRTC_UPDATE_LOCK 0x6ed4 -+#define EVERGREEN_MASTER_UPDATE_LOCK 0x6ef4 -+#define EVERGREEN_MASTER_UPDATE_MODE 0x6ef8 - - #define EVERGREEN_DC_GPIO_HPD_MASK 0x64b0 - #define EVERGREEN_DC_GPIO_HPD_A 0x64b4 -diff --git a/drivers/gpu/drm/radeon/ni.c b/drivers/gpu/drm/radeon/ni.c -index 27769e7..0a32d89 100644 ---- a/drivers/gpu/drm/radeon/ni.c -+++ b/drivers/gpu/drm/radeon/ni.c -@@ -473,7 +473,8 @@ static void cayman_gpu_init(struct radeon_device *rdev) - (rdev->pdev->device == 0x990F) || - (rdev->pdev->device == 0x9910) || - (rdev->pdev->device == 0x9917) || -- (rdev->pdev->device == 0x9999)) { -+ (rdev->pdev->device == 0x9999) || -+ (rdev->pdev->device == 0x999C)) { - rdev->config.cayman.max_simds_per_se = 6; - rdev->config.cayman.max_backends_per_se = 2; - } else if ((rdev->pdev->device == 0x9903) || -@@ -482,7 +483,8 @@ static void cayman_gpu_init(struct radeon_device *rdev) - (rdev->pdev->device == 0x990D) || - (rdev->pdev->device == 0x990E) || - (rdev->pdev->device == 0x9913) || -- (rdev->pdev->device == 0x9918)) { -+ (rdev->pdev->device == 0x9918) || -+ (rdev->pdev->device == 0x999D)) { - rdev->config.cayman.max_simds_per_se = 4; - rdev->config.cayman.max_backends_per_se = 2; - } else if ((rdev->pdev->device == 0x9919) || -@@ -621,6 +623,8 @@ static void cayman_gpu_init(struct radeon_device *rdev) - - WREG32(GB_ADDR_CONFIG, gb_addr_config); - WREG32(DMIF_ADDR_CONFIG, gb_addr_config); -+ if (ASIC_IS_DCE6(rdev)) -+ WREG32(DMIF_ADDR_CALC, gb_addr_config); - WREG32(HDP_ADDR_CONFIG, gb_addr_config); - WREG32(DMA_TILING_CONFIG + DMA0_REGISTER_OFFSET, gb_addr_config); - WREG32(DMA_TILING_CONFIG + DMA1_REGISTER_OFFSET, gb_addr_config); -diff --git a/drivers/gpu/drm/radeon/nid.h b/drivers/gpu/drm/radeon/nid.h -index 079dee2..445b235 100644 ---- a/drivers/gpu/drm/radeon/nid.h -+++ b/drivers/gpu/drm/radeon/nid.h -@@ -45,6 +45,10 @@ - #define ARUBA_GB_ADDR_CONFIG_GOLDEN 0x12010001 - - #define DMIF_ADDR_CONFIG 0xBD4 -+ -+/* DCE6 only */ -+#define DMIF_ADDR_CALC 0xC00 -+ - #define SRBM_GFX_CNTL 0x0E44 - #define RINGID(x) (((x) & 0x3) << 0) - #define VMID(x) (((x) & 0x7) << 0) -diff --git a/drivers/gpu/drm/radeon/r100.c b/drivers/gpu/drm/radeon/r100.c -index 9db5853..4973bff 100644 ---- a/drivers/gpu/drm/radeon/r100.c -+++ b/drivers/gpu/drm/radeon/r100.c -@@ -69,6 +69,38 @@ MODULE_FIRMWARE(FIRMWARE_R520); - * and others in some cases. - */ - -+static bool r100_is_in_vblank(struct radeon_device *rdev, int crtc) -+{ -+ if (crtc == 0) { -+ if (RREG32(RADEON_CRTC_STATUS) & RADEON_CRTC_VBLANK_CUR) -+ return true; -+ else -+ return false; -+ } else { -+ if (RREG32(RADEON_CRTC2_STATUS) & RADEON_CRTC2_VBLANK_CUR) -+ return true; -+ else -+ return false; -+ } -+} -+ -+static bool r100_is_counter_moving(struct radeon_device *rdev, int crtc) -+{ -+ u32 vline1, vline2; -+ -+ if (crtc == 0) { -+ vline1 = (RREG32(RADEON_CRTC_VLINE_CRNT_VLINE) >> 16) & RADEON_CRTC_V_TOTAL; -+ vline2 = (RREG32(RADEON_CRTC_VLINE_CRNT_VLINE) >> 16) & RADEON_CRTC_V_TOTAL; -+ } else { -+ vline1 = (RREG32(RADEON_CRTC2_VLINE_CRNT_VLINE) >> 16) & RADEON_CRTC_V_TOTAL; -+ vline2 = (RREG32(RADEON_CRTC2_VLINE_CRNT_VLINE) >> 16) & RADEON_CRTC_V_TOTAL; -+ } -+ if (vline1 != vline2) -+ return true; -+ else -+ return false; -+} -+ - /** - * r100_wait_for_vblank - vblank wait asic callback. - * -@@ -79,36 +111,33 @@ MODULE_FIRMWARE(FIRMWARE_R520); - */ - void r100_wait_for_vblank(struct radeon_device *rdev, int crtc) - { -- int i; -+ unsigned i = 0; - - if (crtc >= rdev->num_crtc) - return; - - if (crtc == 0) { -- if (RREG32(RADEON_CRTC_GEN_CNTL) & RADEON_CRTC_EN) { -- for (i = 0; i < rdev->usec_timeout; i++) { -- if (!(RREG32(RADEON_CRTC_STATUS) & RADEON_CRTC_VBLANK_CUR)) -- break; -- udelay(1); -- } -- for (i = 0; i < rdev->usec_timeout; i++) { -- if (RREG32(RADEON_CRTC_STATUS) & RADEON_CRTC_VBLANK_CUR) -- break; -- udelay(1); -- } -- } -+ if (!(RREG32(RADEON_CRTC_GEN_CNTL) & RADEON_CRTC_EN)) -+ return; - } else { -- if (RREG32(RADEON_CRTC2_GEN_CNTL) & RADEON_CRTC2_EN) { -- for (i = 0; i < rdev->usec_timeout; i++) { -- if (!(RREG32(RADEON_CRTC2_STATUS) & RADEON_CRTC2_VBLANK_CUR)) -- break; -- udelay(1); -- } -- for (i = 0; i < rdev->usec_timeout; i++) { -- if (RREG32(RADEON_CRTC2_STATUS) & RADEON_CRTC2_VBLANK_CUR) -- break; -- udelay(1); -- } -+ if (!(RREG32(RADEON_CRTC2_GEN_CNTL) & RADEON_CRTC2_EN)) -+ return; -+ } -+ -+ /* depending on when we hit vblank, we may be close to active; if so, -+ * wait for another frame. -+ */ -+ while (r100_is_in_vblank(rdev, crtc)) { -+ if (i++ % 100 == 0) { -+ if (!r100_is_counter_moving(rdev, crtc)) -+ break; -+ } -+ } -+ -+ while (!r100_is_in_vblank(rdev, crtc)) { -+ if (i++ % 100 == 0) { -+ if (!r100_is_counter_moving(rdev, crtc)) -+ break; - } - } - } -diff --git a/drivers/gpu/drm/radeon/r500_reg.h b/drivers/gpu/drm/radeon/r500_reg.h -index c0dc8d3..1dd0d32 100644 ---- a/drivers/gpu/drm/radeon/r500_reg.h -+++ b/drivers/gpu/drm/radeon/r500_reg.h -@@ -358,7 +358,9 @@ - #define AVIVO_D1CRTC_STATUS_HV_COUNT 0x60ac - #define AVIVO_D1CRTC_STEREO_CONTROL 0x60c4 - -+#define AVIVO_D1MODE_MASTER_UPDATE_LOCK 0x60e0 - #define AVIVO_D1MODE_MASTER_UPDATE_MODE 0x60e4 -+#define AVIVO_D1CRTC_UPDATE_LOCK 0x60e8 - - /* master controls */ - #define AVIVO_DC_CRTC_MASTER_EN 0x60f8 -diff --git a/drivers/gpu/drm/radeon/r600_hdmi.c b/drivers/gpu/drm/radeon/r600_hdmi.c -index 21ecc0e..8520833 100644 ---- a/drivers/gpu/drm/radeon/r600_hdmi.c -+++ b/drivers/gpu/drm/radeon/r600_hdmi.c -@@ -433,7 +433,7 @@ void r600_hdmi_enable(struct drm_encoder *encoder) - offset = dig->afmt->offset; - - /* Older chipsets require setting HDMI and routing manually */ -- if (rdev->family >= CHIP_R600 && !ASIC_IS_DCE3(rdev)) { -+ if (ASIC_IS_DCE2(rdev) && !ASIC_IS_DCE3(rdev)) { - hdmi = HDMI0_ERROR_ACK | HDMI0_ENABLE; - switch (radeon_encoder->encoder_id) { - case ENCODER_OBJECT_ID_INTERNAL_KLDSCP_TMDS1: -@@ -501,7 +501,7 @@ void r600_hdmi_disable(struct drm_encoder *encoder) - radeon_irq_kms_disable_afmt(rdev, dig->afmt->id); - - /* Older chipsets not handled by AtomBIOS */ -- if (rdev->family >= CHIP_R600 && !ASIC_IS_DCE3(rdev)) { -+ if (ASIC_IS_DCE2(rdev) && !ASIC_IS_DCE3(rdev)) { - switch (radeon_encoder->encoder_id) { - case ENCODER_OBJECT_ID_INTERNAL_KLDSCP_TMDS1: - WREG32_P(AVIVO_TMDSA_CNTL, 0, -diff --git a/drivers/gpu/drm/radeon/radeon_atombios.c b/drivers/gpu/drm/radeon/radeon_atombios.c -index f22eb57..96168ef 100644 ---- a/drivers/gpu/drm/radeon/radeon_atombios.c -+++ b/drivers/gpu/drm/radeon/radeon_atombios.c -@@ -2028,6 +2028,8 @@ static int radeon_atombios_parse_power_table_1_3(struct radeon_device *rdev) - num_modes = power_info->info.ucNumOfPowerModeEntries; - if (num_modes > ATOM_MAX_NUMBEROF_POWER_BLOCK) - num_modes = ATOM_MAX_NUMBEROF_POWER_BLOCK; -+ if (num_modes == 0) -+ return state_index; - rdev->pm.power_state = kzalloc(sizeof(struct radeon_power_state) * num_modes, GFP_KERNEL); - if (!rdev->pm.power_state) - return state_index; -@@ -2432,6 +2434,8 @@ static int radeon_atombios_parse_power_table_4_5(struct radeon_device *rdev) - power_info = (union power_info *)(mode_info->atom_context->bios + data_offset); - - radeon_atombios_add_pplib_thermal_controller(rdev, &power_info->pplib.sThermalController); -+ if (power_info->pplib.ucNumStates == 0) -+ return state_index; - rdev->pm.power_state = kzalloc(sizeof(struct radeon_power_state) * - power_info->pplib.ucNumStates, GFP_KERNEL); - if (!rdev->pm.power_state) -@@ -2514,6 +2518,7 @@ static int radeon_atombios_parse_power_table_6(struct radeon_device *rdev) - int index = GetIndexIntoMasterTable(DATA, PowerPlayInfo); - u16 data_offset; - u8 frev, crev; -+ u8 *power_state_offset; - - if (!atom_parse_data_header(mode_info->atom_context, index, NULL, - &frev, &crev, &data_offset)) -@@ -2530,15 +2535,17 @@ static int radeon_atombios_parse_power_table_6(struct radeon_device *rdev) - non_clock_info_array = (struct _NonClockInfoArray *) - (mode_info->atom_context->bios + data_offset + - le16_to_cpu(power_info->pplib.usNonClockInfoArrayOffset)); -+ if (state_array->ucNumEntries == 0) -+ return state_index; - rdev->pm.power_state = kzalloc(sizeof(struct radeon_power_state) * - state_array->ucNumEntries, GFP_KERNEL); - if (!rdev->pm.power_state) - return state_index; -+ power_state_offset = (u8 *)state_array->states; - for (i = 0; i < state_array->ucNumEntries; i++) { - mode_index = 0; -- power_state = (union pplib_power_state *)&state_array->states[i]; -- /* XXX this might be an inagua bug... */ -- non_clock_array_index = i; /* power_state->v2.nonClockInfoIndex */ -+ power_state = (union pplib_power_state *)power_state_offset; -+ non_clock_array_index = power_state->v2.nonClockInfoIndex; - non_clock_info = (struct _ATOM_PPLIB_NONCLOCK_INFO *) - &non_clock_info_array->nonClockInfo[non_clock_array_index]; - rdev->pm.power_state[i].clock_info = kzalloc(sizeof(struct radeon_pm_clock_info) * -@@ -2550,9 +2557,6 @@ static int radeon_atombios_parse_power_table_6(struct radeon_device *rdev) - if (power_state->v2.ucNumDPMLevels) { - for (j = 0; j < power_state->v2.ucNumDPMLevels; j++) { - clock_array_index = power_state->v2.clockInfoIndex[j]; -- /* XXX this might be an inagua bug... */ -- if (clock_array_index >= clock_info_array->ucNumEntries) -- continue; - clock_info = (union pplib_clock_info *) - &clock_info_array->clockInfo[clock_array_index * clock_info_array->ucEntrySize]; - valid = radeon_atombios_parse_pplib_clock_info(rdev, -@@ -2574,6 +2578,7 @@ static int radeon_atombios_parse_power_table_6(struct radeon_device *rdev) - non_clock_info); - state_index++; - } -+ power_state_offset += 2 + power_state->v2.ucNumDPMLevels; - } - /* if multiple clock modes, mark the lowest as no display */ - for (i = 0; i < state_index; i++) { -@@ -2620,7 +2625,9 @@ void radeon_atombios_get_power_modes(struct radeon_device *rdev) - default: - break; - } -- } else { -+ } -+ -+ if (state_index == 0) { - rdev->pm.power_state = kzalloc(sizeof(struct radeon_power_state), GFP_KERNEL); - if (rdev->pm.power_state) { - rdev->pm.power_state[0].clock_info = -diff --git a/drivers/gpu/drm/radeon/radeon_kms.c b/drivers/gpu/drm/radeon/radeon_kms.c -index c75cb2c..c5b2765 100644 ---- a/drivers/gpu/drm/radeon/radeon_kms.c -+++ b/drivers/gpu/drm/radeon/radeon_kms.c -@@ -50,9 +50,13 @@ int radeon_driver_unload_kms(struct drm_device *dev) - - if (rdev == NULL) - return 0; -+ if (rdev->rmmio == NULL) -+ goto done_free; - radeon_acpi_fini(rdev); - radeon_modeset_fini(rdev); - radeon_device_fini(rdev); -+ -+done_free: - kfree(rdev); - dev->dev_private = NULL; - return 0; -diff --git a/drivers/gpu/drm/radeon/radeon_pm.c b/drivers/gpu/drm/radeon/radeon_pm.c -index 338fd6a..788c64c 100644 ---- a/drivers/gpu/drm/radeon/radeon_pm.c -+++ b/drivers/gpu/drm/radeon/radeon_pm.c -@@ -843,7 +843,11 @@ static int radeon_debugfs_pm_info(struct seq_file *m, void *data) - struct radeon_device *rdev = dev->dev_private; - - seq_printf(m, "default engine clock: %u0 kHz\n", rdev->pm.default_sclk); -- seq_printf(m, "current engine clock: %u0 kHz\n", radeon_get_engine_clock(rdev)); -+ /* radeon_get_engine_clock is not reliable on APUs so just print the current clock */ -+ if ((rdev->family >= CHIP_PALM) && (rdev->flags & RADEON_IS_IGP)) -+ seq_printf(m, "current engine clock: %u0 kHz\n", rdev->pm.current_sclk); -+ else -+ seq_printf(m, "current engine clock: %u0 kHz\n", radeon_get_engine_clock(rdev)); - seq_printf(m, "default memory clock: %u0 kHz\n", rdev->pm.default_mclk); - if (rdev->asic->pm.get_memory_clock) - seq_printf(m, "current memory clock: %u0 kHz\n", radeon_get_memory_clock(rdev)); -diff --git a/drivers/gpu/drm/radeon/radeon_ring.c b/drivers/gpu/drm/radeon/radeon_ring.c -index 8d58e26..1ef5eaa 100644 ---- a/drivers/gpu/drm/radeon/radeon_ring.c -+++ b/drivers/gpu/drm/radeon/radeon_ring.c -@@ -180,7 +180,8 @@ int radeon_ib_schedule(struct radeon_device *rdev, struct radeon_ib *ib, - radeon_semaphore_free(rdev, &ib->semaphore, NULL); - } - /* if we can't remember our last VM flush then flush now! */ -- if (ib->vm && !ib->vm->last_flush) { -+ /* XXX figure out why we have to flush for every IB */ -+ if (ib->vm /*&& !ib->vm->last_flush*/) { - radeon_ring_vm_flush(rdev, ib->ring, ib->vm); - } - if (const_ib) { -diff --git a/drivers/gpu/drm/radeon/rs600.c b/drivers/gpu/drm/radeon/rs600.c -index 5a0fc74..46fa1b0 100644 ---- a/drivers/gpu/drm/radeon/rs600.c -+++ b/drivers/gpu/drm/radeon/rs600.c -@@ -52,23 +52,59 @@ static const u32 crtc_offsets[2] = - AVIVO_D2CRTC_H_TOTAL - AVIVO_D1CRTC_H_TOTAL - }; - -+static bool avivo_is_in_vblank(struct radeon_device *rdev, int crtc) -+{ -+ if (RREG32(AVIVO_D1CRTC_STATUS + crtc_offsets[crtc]) & AVIVO_D1CRTC_V_BLANK) -+ return true; -+ else -+ return false; -+} -+ -+static bool avivo_is_counter_moving(struct radeon_device *rdev, int crtc) -+{ -+ u32 pos1, pos2; -+ -+ pos1 = RREG32(AVIVO_D1CRTC_STATUS_POSITION + crtc_offsets[crtc]); -+ pos2 = RREG32(AVIVO_D1CRTC_STATUS_POSITION + crtc_offsets[crtc]); -+ -+ if (pos1 != pos2) -+ return true; -+ else -+ return false; -+} -+ -+/** -+ * avivo_wait_for_vblank - vblank wait asic callback. -+ * -+ * @rdev: radeon_device pointer -+ * @crtc: crtc to wait for vblank on -+ * -+ * Wait for vblank on the requested crtc (r5xx-r7xx). -+ */ - void avivo_wait_for_vblank(struct radeon_device *rdev, int crtc) - { -- int i; -+ unsigned i = 0; - - if (crtc >= rdev->num_crtc) - return; - -- if (RREG32(AVIVO_D1CRTC_CONTROL + crtc_offsets[crtc]) & AVIVO_CRTC_EN) { -- for (i = 0; i < rdev->usec_timeout; i++) { -- if (!(RREG32(AVIVO_D1CRTC_STATUS + crtc_offsets[crtc]) & AVIVO_D1CRTC_V_BLANK)) -+ if (!(RREG32(AVIVO_D1CRTC_CONTROL + crtc_offsets[crtc]) & AVIVO_CRTC_EN)) -+ return; -+ -+ /* depending on when we hit vblank, we may be close to active; if so, -+ * wait for another frame. -+ */ -+ while (avivo_is_in_vblank(rdev, crtc)) { -+ if (i++ % 100 == 0) { -+ if (!avivo_is_counter_moving(rdev, crtc)) - break; -- udelay(1); - } -- for (i = 0; i < rdev->usec_timeout; i++) { -- if (RREG32(AVIVO_D1CRTC_STATUS + crtc_offsets[crtc]) & AVIVO_D1CRTC_V_BLANK) -+ } -+ -+ while (!avivo_is_in_vblank(rdev, crtc)) { -+ if (i++ % 100 == 0) { -+ if (!avivo_is_counter_moving(rdev, crtc)) - break; -- udelay(1); - } - } - } -diff --git a/drivers/gpu/drm/radeon/rv515.c b/drivers/gpu/drm/radeon/rv515.c -index 435ed35..ffcba73 100644 ---- a/drivers/gpu/drm/radeon/rv515.c -+++ b/drivers/gpu/drm/radeon/rv515.c -@@ -303,8 +303,10 @@ void rv515_mc_stop(struct radeon_device *rdev, struct rv515_mc_save *save) - tmp = RREG32(AVIVO_D1CRTC_CONTROL + crtc_offsets[i]); - if (!(tmp & AVIVO_CRTC_DISP_READ_REQUEST_DISABLE)) { - radeon_wait_for_vblank(rdev, i); -+ WREG32(AVIVO_D1CRTC_UPDATE_LOCK + crtc_offsets[i], 1); - tmp |= AVIVO_CRTC_DISP_READ_REQUEST_DISABLE; - WREG32(AVIVO_D1CRTC_CONTROL + crtc_offsets[i], tmp); -+ WREG32(AVIVO_D1CRTC_UPDATE_LOCK + crtc_offsets[i], 0); - } - /* wait for the next frame */ - frame_count = radeon_get_vblank_counter(rdev, i); -@@ -313,6 +315,15 @@ void rv515_mc_stop(struct radeon_device *rdev, struct rv515_mc_save *save) - break; - udelay(1); - } -+ -+ /* XXX this is a hack to avoid strange behavior with EFI on certain systems */ -+ WREG32(AVIVO_D1CRTC_UPDATE_LOCK + crtc_offsets[i], 1); -+ tmp = RREG32(AVIVO_D1CRTC_CONTROL + crtc_offsets[i]); -+ tmp &= ~AVIVO_CRTC_EN; -+ WREG32(AVIVO_D1CRTC_CONTROL + crtc_offsets[i], tmp); -+ WREG32(AVIVO_D1CRTC_UPDATE_LOCK + crtc_offsets[i], 0); -+ save->crtc_enabled[i] = false; -+ /* ***** */ - } else { - save->crtc_enabled[i] = false; - } -@@ -338,6 +349,22 @@ void rv515_mc_stop(struct radeon_device *rdev, struct rv515_mc_save *save) - } - /* wait for the MC to settle */ - udelay(100); -+ -+ /* lock double buffered regs */ -+ for (i = 0; i < rdev->num_crtc; i++) { -+ if (save->crtc_enabled[i]) { -+ tmp = RREG32(AVIVO_D1GRPH_UPDATE + crtc_offsets[i]); -+ if (!(tmp & AVIVO_D1GRPH_UPDATE_LOCK)) { -+ tmp |= AVIVO_D1GRPH_UPDATE_LOCK; -+ WREG32(AVIVO_D1GRPH_UPDATE + crtc_offsets[i], tmp); -+ } -+ tmp = RREG32(AVIVO_D1MODE_MASTER_UPDATE_LOCK + crtc_offsets[i]); -+ if (!(tmp & 1)) { -+ tmp |= 1; -+ WREG32(AVIVO_D1MODE_MASTER_UPDATE_LOCK + crtc_offsets[i], tmp); -+ } -+ } -+ } - } - - void rv515_mc_resume(struct radeon_device *rdev, struct rv515_mc_save *save) -@@ -348,7 +375,7 @@ void rv515_mc_resume(struct radeon_device *rdev, struct rv515_mc_save *save) - /* update crtc base addresses */ - for (i = 0; i < rdev->num_crtc; i++) { - if (rdev->family >= CHIP_RV770) { -- if (i == 1) { -+ if (i == 0) { - WREG32(R700_D1GRPH_PRIMARY_SURFACE_ADDRESS_HIGH, - upper_32_bits(rdev->mc.vram_start)); - WREG32(R700_D1GRPH_SECONDARY_SURFACE_ADDRESS_HIGH, -@@ -367,6 +394,33 @@ void rv515_mc_resume(struct radeon_device *rdev, struct rv515_mc_save *save) - } - WREG32(R_000310_VGA_MEMORY_BASE_ADDRESS, (u32)rdev->mc.vram_start); - -+ /* unlock regs and wait for update */ -+ for (i = 0; i < rdev->num_crtc; i++) { -+ if (save->crtc_enabled[i]) { -+ tmp = RREG32(AVIVO_D1MODE_MASTER_UPDATE_MODE + crtc_offsets[i]); -+ if ((tmp & 0x3) != 0) { -+ tmp &= ~0x3; -+ WREG32(AVIVO_D1MODE_MASTER_UPDATE_MODE + crtc_offsets[i], tmp); -+ } -+ tmp = RREG32(AVIVO_D1GRPH_UPDATE + crtc_offsets[i]); -+ if (tmp & AVIVO_D1GRPH_UPDATE_LOCK) { -+ tmp &= ~AVIVO_D1GRPH_UPDATE_LOCK; -+ WREG32(AVIVO_D1GRPH_UPDATE + crtc_offsets[i], tmp); -+ } -+ tmp = RREG32(AVIVO_D1MODE_MASTER_UPDATE_LOCK + crtc_offsets[i]); -+ if (tmp & 1) { -+ tmp &= ~1; -+ WREG32(AVIVO_D1MODE_MASTER_UPDATE_LOCK + crtc_offsets[i], tmp); -+ } -+ for (j = 0; j < rdev->usec_timeout; j++) { -+ tmp = RREG32(AVIVO_D1GRPH_UPDATE + crtc_offsets[i]); -+ if ((tmp & AVIVO_D1GRPH_SURFACE_UPDATE_PENDING) == 0) -+ break; -+ udelay(1); -+ } -+ } -+ } -+ - if (rdev->family >= CHIP_R600) { - /* unblackout the MC */ - if (rdev->family >= CHIP_RV770) -diff --git a/drivers/gpu/drm/radeon/si.c b/drivers/gpu/drm/radeon/si.c -index bafbe32..3dd7ecc 100644 ---- a/drivers/gpu/drm/radeon/si.c -+++ b/drivers/gpu/drm/radeon/si.c -@@ -1463,7 +1463,7 @@ static void si_select_se_sh(struct radeon_device *rdev, - u32 data = INSTANCE_BROADCAST_WRITES; - - if ((se_num == 0xffffffff) && (sh_num == 0xffffffff)) -- data = SH_BROADCAST_WRITES | SE_BROADCAST_WRITES; -+ data |= SH_BROADCAST_WRITES | SE_BROADCAST_WRITES; - else if (se_num == 0xffffffff) - data |= SE_BROADCAST_WRITES | SH_INDEX(sh_num); - else if (sh_num == 0xffffffff) -@@ -1765,6 +1765,7 @@ static void si_gpu_init(struct radeon_device *rdev) - - WREG32(GB_ADDR_CONFIG, gb_addr_config); - WREG32(DMIF_ADDR_CONFIG, gb_addr_config); -+ WREG32(DMIF_ADDR_CALC, gb_addr_config); - WREG32(HDP_ADDR_CONFIG, gb_addr_config); - WREG32(DMA_TILING_CONFIG + DMA0_REGISTER_OFFSET, gb_addr_config); - WREG32(DMA_TILING_CONFIG + DMA1_REGISTER_OFFSET, gb_addr_config); -diff --git a/drivers/gpu/drm/radeon/sid.h b/drivers/gpu/drm/radeon/sid.h -index 23fc08f..f84cff0 100644 ---- a/drivers/gpu/drm/radeon/sid.h -+++ b/drivers/gpu/drm/radeon/sid.h -@@ -65,6 +65,8 @@ - - #define DMIF_ADDR_CONFIG 0xBD4 - -+#define DMIF_ADDR_CALC 0xC00 -+ - #define SRBM_STATUS 0xE50 - #define GRBM_RQ_PENDING (1 << 5) - #define VMC_BUSY (1 << 8) -diff --git a/drivers/gpu/drm/tilcdc/tilcdc_drv.c b/drivers/gpu/drm/tilcdc/tilcdc_drv.c -index c5b592d..bfac582 100644 ---- a/drivers/gpu/drm/tilcdc/tilcdc_drv.c -+++ b/drivers/gpu/drm/tilcdc/tilcdc_drv.c -@@ -75,7 +75,7 @@ static int modeset_init(struct drm_device *dev) - mod->funcs->modeset_init(mod, dev); - } - -- if ((priv->num_encoders = 0) || (priv->num_connectors == 0)) { -+ if ((priv->num_encoders == 0) || (priv->num_connectors == 0)) { - /* oh nos! */ - dev_err(dev->dev, "no encoders/connectors found\n"); - return -ENXIO; -diff --git a/drivers/gpu/drm/udl/udl_gem.c b/drivers/gpu/drm/udl/udl_gem.c -index 3816270..ef034fa 100644 ---- a/drivers/gpu/drm/udl/udl_gem.c -+++ b/drivers/gpu/drm/udl/udl_gem.c -@@ -303,6 +303,8 @@ struct drm_gem_object *udl_gem_prime_import(struct drm_device *dev, - if (IS_ERR(attach)) - return ERR_CAST(attach); - -+ get_dma_buf(dma_buf); -+ - sg = dma_buf_map_attachment(attach, DMA_BIDIRECTIONAL); - if (IS_ERR(sg)) { - ret = PTR_ERR(sg); -@@ -322,5 +324,7 @@ fail_unmap: - dma_buf_unmap_attachment(attach, sg, DMA_BIDIRECTIONAL); - fail_detach: - dma_buf_detach(dma_buf, attach); -+ dma_buf_put(dma_buf); -+ - return ERR_PTR(ret); - } -diff --git a/drivers/infiniband/hw/cxgb4/qp.c b/drivers/infiniband/hw/cxgb4/qp.c -index 70b1808..ed49ab3 100644 ---- a/drivers/infiniband/hw/cxgb4/qp.c -+++ b/drivers/infiniband/hw/cxgb4/qp.c -@@ -100,6 +100,16 @@ static int alloc_host_sq(struct c4iw_rdev *rdev, struct t4_sq *sq) - return 0; - } - -+static int alloc_sq(struct c4iw_rdev *rdev, struct t4_sq *sq, int user) -+{ -+ int ret = -ENOSYS; -+ if (user) -+ ret = alloc_oc_sq(rdev, sq); -+ if (ret) -+ ret = alloc_host_sq(rdev, sq); -+ return ret; -+} -+ - static int destroy_qp(struct c4iw_rdev *rdev, struct t4_wq *wq, - struct c4iw_dev_ucontext *uctx) - { -@@ -168,18 +178,9 @@ static int create_qp(struct c4iw_rdev *rdev, struct t4_wq *wq, - goto free_sw_rq; - } - -- if (user) { -- ret = alloc_oc_sq(rdev, &wq->sq); -- if (ret) -- goto free_hwaddr; -- -- ret = alloc_host_sq(rdev, &wq->sq); -- if (ret) -- goto free_sq; -- } else -- ret = alloc_host_sq(rdev, &wq->sq); -- if (ret) -- goto free_hwaddr; -+ ret = alloc_sq(rdev, &wq->sq, user); -+ if (ret) -+ goto free_hwaddr; - memset(wq->sq.queue, 0, wq->sq.memsize); - dma_unmap_addr_set(&wq->sq, mapping, wq->sq.dma_addr); - -diff --git a/drivers/iommu/amd_iommu.c b/drivers/iommu/amd_iommu.c -index b287ca3..cbb1645 100644 ---- a/drivers/iommu/amd_iommu.c -+++ b/drivers/iommu/amd_iommu.c -@@ -3947,6 +3947,9 @@ static struct irq_remap_table *get_irq_table(u16 devid, bool ioapic) - if (!table) - goto out; - -+ /* Initialize table spin-lock */ -+ spin_lock_init(&table->lock); -+ - if (ioapic) - /* Keep the first 32 indexes free for IOAPIC interrupts */ - table->min_index = 32; -diff --git a/drivers/net/ethernet/ibm/ibmveth.c b/drivers/net/ethernet/ibm/ibmveth.c -index c859771..f46dbef 100644 ---- a/drivers/net/ethernet/ibm/ibmveth.c -+++ b/drivers/net/ethernet/ibm/ibmveth.c -@@ -1324,7 +1324,7 @@ static const struct net_device_ops ibmveth_netdev_ops = { - - static int ibmveth_probe(struct vio_dev *dev, const struct vio_device_id *id) - { -- int rc, i; -+ int rc, i, mac_len; - struct net_device *netdev; - struct ibmveth_adapter *adapter; - unsigned char *mac_addr_p; -@@ -1334,11 +1334,19 @@ static int ibmveth_probe(struct vio_dev *dev, const struct vio_device_id *id) - dev->unit_address); - - mac_addr_p = (unsigned char *)vio_get_attribute(dev, VETH_MAC_ADDR, -- NULL); -+ &mac_len); - if (!mac_addr_p) { - dev_err(&dev->dev, "Can't find VETH_MAC_ADDR attribute\n"); - return -EINVAL; - } -+ /* Workaround for old/broken pHyp */ -+ if (mac_len == 8) -+ mac_addr_p += 2; -+ else if (mac_len != 6) { -+ dev_err(&dev->dev, "VETH_MAC_ADDR attribute wrong len %d\n", -+ mac_len); -+ return -EINVAL; -+ } - - mcastFilterSize_p = (unsigned int *)vio_get_attribute(dev, - VETH_MCAST_FILTER_SIZE, NULL); -@@ -1363,17 +1371,6 @@ static int ibmveth_probe(struct vio_dev *dev, const struct vio_device_id *id) - - netif_napi_add(netdev, &adapter->napi, ibmveth_poll, 16); - -- /* -- * Some older boxes running PHYP non-natively have an OF that returns -- * a 8-byte local-mac-address field (and the first 2 bytes have to be -- * ignored) while newer boxes' OF return a 6-byte field. Note that -- * IEEE 1275 specifies that local-mac-address must be a 6-byte field. -- * The RPA doc specifies that the first byte must be 10b, so we'll -- * just look for it to solve this 8 vs. 6 byte field issue -- */ -- if ((*mac_addr_p & 0x3) != 0x02) -- mac_addr_p += 2; -- - adapter->mac_addr = 0; - memcpy(&adapter->mac_addr, mac_addr_p, 6); - -diff --git a/drivers/net/ethernet/realtek/r8169.c b/drivers/net/ethernet/realtek/r8169.c -index 4ecbe64..15ba8c4 100644 ---- a/drivers/net/ethernet/realtek/r8169.c -+++ b/drivers/net/ethernet/realtek/r8169.c -@@ -5787,6 +5787,14 @@ static netdev_tx_t rtl8169_start_xmit(struct sk_buff *skb, - goto err_stop_0; - } - -+ /* 8168evl does not automatically pad to minimum length. */ -+ if (unlikely(tp->mac_version == RTL_GIGA_MAC_VER_34 && -+ skb->len < ETH_ZLEN)) { -+ if (skb_padto(skb, ETH_ZLEN)) -+ goto err_update_stats; -+ skb_put(skb, ETH_ZLEN - skb->len); -+ } -+ - if (unlikely(le32_to_cpu(txd->opts1) & DescOwn)) - goto err_stop_0; - -@@ -5858,6 +5866,7 @@ err_dma_1: - rtl8169_unmap_tx_skb(d, tp->tx_skb + entry, txd); - err_dma_0: - dev_kfree_skb(skb); -+err_update_stats: - dev->stats.tx_dropped++; - return NETDEV_TX_OK; - -diff --git a/drivers/net/usb/cdc_ether.c b/drivers/net/usb/cdc_ether.c -index 57136dc..299c53b 100644 ---- a/drivers/net/usb/cdc_ether.c -+++ b/drivers/net/usb/cdc_ether.c -@@ -615,6 +615,13 @@ static const struct usb_device_id products [] = { - .driver_info = 0, - }, - -+/* Dell Wireless 5804 (Novatel E371) - handled by qmi_wwan */ -+{ -+ USB_DEVICE_AND_INTERFACE_INFO(DELL_VENDOR_ID, 0x819b, USB_CLASS_COMM, -+ USB_CDC_SUBCLASS_ETHERNET, USB_CDC_PROTO_NONE), -+ .driver_info = 0, -+}, -+ - /* AnyDATA ADU960S - handled by qmi_wwan */ - { - USB_DEVICE_AND_INTERFACE_INFO(0x16d5, 0x650a, USB_CLASS_COMM, -diff --git a/drivers/net/usb/qmi_wwan.c b/drivers/net/usb/qmi_wwan.c -index 2a3579f..a7cafe4 100644 ---- a/drivers/net/usb/qmi_wwan.c -+++ b/drivers/net/usb/qmi_wwan.c -@@ -496,6 +496,13 @@ static const struct usb_device_id products[] = { - USB_CDC_PROTO_NONE), - .driver_info = (unsigned long)&qmi_wwan_info, - }, -+ { /* Dell Wireless 5804 (Novatel E371) */ -+ USB_DEVICE_AND_INTERFACE_INFO(0x413C, 0x819b, -+ USB_CLASS_COMM, -+ USB_CDC_SUBCLASS_ETHERNET, -+ USB_CDC_PROTO_NONE), -+ .driver_info = (unsigned long)&qmi_wwan_info, -+ }, - { /* ADU960S */ - USB_DEVICE_AND_INTERFACE_INFO(0x16d5, 0x650a, - USB_CLASS_COMM, -diff --git a/drivers/pci/bus.c b/drivers/pci/bus.c -index 8647dc6..f9c61fb 100644 ---- a/drivers/pci/bus.c -+++ b/drivers/pci/bus.c -@@ -174,6 +174,7 @@ int pci_bus_add_device(struct pci_dev *dev) - * Can not put in pci_device_add yet because resources - * are not assigned yet for some devices. - */ -+ pci_fixup_device(pci_fixup_final, dev); - pci_create_sysfs_dev_files(dev); - - dev->match_driver = true; -diff --git a/drivers/pci/probe.c b/drivers/pci/probe.c -index b494066..5427787 100644 ---- a/drivers/pci/probe.c -+++ b/drivers/pci/probe.c -@@ -1339,7 +1339,6 @@ void pci_device_add(struct pci_dev *dev, struct pci_bus *bus) - list_add_tail(&dev->bus_list, &bus->devices); - up_write(&pci_bus_sem); - -- pci_fixup_device(pci_fixup_final, dev); - ret = pcibios_add_device(dev); - WARN_ON(ret < 0); - -diff --git a/drivers/pwm/pwm-spear.c b/drivers/pwm/pwm-spear.c -index 69a2d9e..3223b57 100644 ---- a/drivers/pwm/pwm-spear.c -+++ b/drivers/pwm/pwm-spear.c -@@ -143,7 +143,7 @@ static int spear_pwm_enable(struct pwm_chip *chip, struct pwm_device *pwm) - u32 val; - - rc = clk_enable(pc->clk); -- if (!rc) -+ if (rc) - return rc; - - val = spear_pwm_readl(pc, pwm->hwpwm, PWMCR); -@@ -209,12 +209,12 @@ static int spear_pwm_probe(struct platform_device *pdev) - pc->chip.npwm = NUM_PWM; - - ret = clk_prepare(pc->clk); -- if (!ret) -+ if (ret) - return ret; - - if (of_device_is_compatible(np, "st,spear1340-pwm")) { - ret = clk_enable(pc->clk); -- if (!ret) { -+ if (ret) { - clk_unprepare(pc->clk); - return ret; - } -diff --git a/drivers/remoteproc/Kconfig b/drivers/remoteproc/Kconfig -index c6d77e2..be6e121 100644 ---- a/drivers/remoteproc/Kconfig -+++ b/drivers/remoteproc/Kconfig -@@ -6,6 +6,7 @@ config REMOTEPROC - depends on HAS_DMA - select FW_LOADER - select VIRTIO -+ select VIRTUALIZATION - - config OMAP_REMOTEPROC - tristate "OMAP remoteproc support" -diff --git a/drivers/rpmsg/Kconfig b/drivers/rpmsg/Kconfig -index f6e0ea6..69a2193 100644 ---- a/drivers/rpmsg/Kconfig -+++ b/drivers/rpmsg/Kconfig -@@ -4,5 +4,6 @@ menu "Rpmsg drivers" - config RPMSG - tristate - select VIRTIO -+ select VIRTUALIZATION - - endmenu -diff --git a/fs/autofs4/expire.c b/fs/autofs4/expire.c -index 01443ce..13ddec9 100644 ---- a/fs/autofs4/expire.c -+++ b/fs/autofs4/expire.c -@@ -61,15 +61,6 @@ static int autofs4_mount_busy(struct vfsmount *mnt, struct dentry *dentry) - /* This is an autofs submount, we can't expire it */ - if (autofs_type_indirect(sbi->type)) - goto done; -- -- /* -- * Otherwise it's an offset mount and we need to check -- * if we can umount its mount, if there is one. -- */ -- if (!d_mountpoint(path.dentry)) { -- status = 0; -- goto done; -- } - } - - /* Update the expiry counter if fs is busy */ -diff --git a/fs/btrfs/delayed-ref.c b/fs/btrfs/delayed-ref.c -index b7a0641..116abec 100644 ---- a/fs/btrfs/delayed-ref.c -+++ b/fs/btrfs/delayed-ref.c -@@ -40,16 +40,19 @@ struct kmem_cache *btrfs_delayed_extent_op_cachep; - * compare two delayed tree backrefs with same bytenr and type - */ - static int comp_tree_refs(struct btrfs_delayed_tree_ref *ref2, -- struct btrfs_delayed_tree_ref *ref1) -+ struct btrfs_delayed_tree_ref *ref1, int type) - { -- if (ref1->root < ref2->root) -- return -1; -- if (ref1->root > ref2->root) -- return 1; -- if (ref1->parent < ref2->parent) -- return -1; -- if (ref1->parent > ref2->parent) -- return 1; -+ if (type == BTRFS_TREE_BLOCK_REF_KEY) { -+ if (ref1->root < ref2->root) -+ return -1; -+ if (ref1->root > ref2->root) -+ return 1; -+ } else { -+ if (ref1->parent < ref2->parent) -+ return -1; -+ if (ref1->parent > ref2->parent) -+ return 1; -+ } - return 0; - } - -@@ -113,7 +116,8 @@ static int comp_entry(struct btrfs_delayed_ref_node *ref2, - if (ref1->type == BTRFS_TREE_BLOCK_REF_KEY || - ref1->type == BTRFS_SHARED_BLOCK_REF_KEY) { - return comp_tree_refs(btrfs_delayed_node_to_tree_ref(ref2), -- btrfs_delayed_node_to_tree_ref(ref1)); -+ btrfs_delayed_node_to_tree_ref(ref1), -+ ref1->type); - } else if (ref1->type == BTRFS_EXTENT_DATA_REF_KEY || - ref1->type == BTRFS_SHARED_DATA_REF_KEY) { - return comp_data_refs(btrfs_delayed_node_to_data_ref(ref2), -diff --git a/fs/btrfs/inode.c b/fs/btrfs/inode.c -index 09c58a3..cc6ce3e 100644 ---- a/fs/btrfs/inode.c -+++ b/fs/btrfs/inode.c -@@ -6502,7 +6502,9 @@ out: - * block must be cow'd - */ - static noinline int can_nocow_odirect(struct btrfs_trans_handle *trans, -- struct inode *inode, u64 offset, u64 len) -+ struct inode *inode, u64 offset, u64 *len, -+ u64 *orig_start, u64 *orig_block_len, -+ u64 *ram_bytes) - { - struct btrfs_path *path; - int ret; -@@ -6559,8 +6561,12 @@ static noinline int can_nocow_odirect(struct btrfs_trans_handle *trans, - disk_bytenr = btrfs_file_extent_disk_bytenr(leaf, fi); - backref_offset = btrfs_file_extent_offset(leaf, fi); - -+ *orig_start = key.offset - backref_offset; -+ *orig_block_len = btrfs_file_extent_disk_num_bytes(leaf, fi); -+ *ram_bytes = btrfs_file_extent_ram_bytes(leaf, fi); -+ - extent_end = key.offset + btrfs_file_extent_num_bytes(leaf, fi); -- if (extent_end < offset + len) { -+ if (extent_end < offset + *len) { - /* extent doesn't include our full range, must cow */ - goto out; - } -@@ -6584,13 +6590,14 @@ static noinline int can_nocow_odirect(struct btrfs_trans_handle *trans, - */ - disk_bytenr += backref_offset; - disk_bytenr += offset - key.offset; -- num_bytes = min(offset + len, extent_end) - offset; -+ num_bytes = min(offset + *len, extent_end) - offset; - if (csum_exist_in_range(root, disk_bytenr, num_bytes)) - goto out; - /* - * all of the above have passed, it is safe to overwrite this extent - * without cow - */ -+ *len = num_bytes; - ret = 1; - out: - btrfs_free_path(path); -@@ -6789,7 +6796,7 @@ static int btrfs_get_blocks_direct(struct inode *inode, sector_t iblock, - em->block_start != EXTENT_MAP_HOLE)) { - int type; - int ret; -- u64 block_start; -+ u64 block_start, orig_start, orig_block_len, ram_bytes; - - if (test_bit(EXTENT_FLAG_PREALLOC, &em->flags)) - type = BTRFS_ORDERED_PREALLOC; -@@ -6807,10 +6814,8 @@ static int btrfs_get_blocks_direct(struct inode *inode, sector_t iblock, - if (IS_ERR(trans)) - goto must_cow; - -- if (can_nocow_odirect(trans, inode, start, len) == 1) { -- u64 orig_start = em->orig_start; -- u64 orig_block_len = em->orig_block_len; -- -+ if (can_nocow_odirect(trans, inode, start, &len, &orig_start, -+ &orig_block_len, &ram_bytes) == 1) { - if (type == BTRFS_ORDERED_PREALLOC) { - free_extent_map(em); - em = create_pinned_em(inode, start, len, -diff --git a/fs/ext4/resize.c b/fs/ext4/resize.c -index 1357260..3beae6a 100644 ---- a/fs/ext4/resize.c -+++ b/fs/ext4/resize.c -@@ -1882,6 +1882,10 @@ retry: - return 0; - - ext4_get_group_no_and_offset(sb, n_blocks_count - 1, &n_group, &offset); -+ if (n_group > (0xFFFFFFFFUL / EXT4_INODES_PER_GROUP(sb))) { -+ ext4_warning(sb, "resize would cause inodes_count overflow"); -+ return -EINVAL; -+ } - ext4_get_group_no_and_offset(sb, o_blocks_count - 1, &o_group, &offset); - - n_desc_blocks = num_desc_blocks(sb, n_group + 1); -diff --git a/fs/hugetlbfs/inode.c b/fs/hugetlbfs/inode.c -index 523464e..a3f868a 100644 ---- a/fs/hugetlbfs/inode.c -+++ b/fs/hugetlbfs/inode.c -@@ -909,11 +909,8 @@ static int can_do_hugetlb_shm(void) - - static int get_hstate_idx(int page_size_log) - { -- struct hstate *h; -+ struct hstate *h = hstate_sizelog(page_size_log); - -- if (!page_size_log) -- return default_hstate_idx; -- h = size_to_hstate(1 << page_size_log); - if (!h) - return -1; - return h - hstates; -@@ -929,9 +926,12 @@ static struct dentry_operations anon_ops = { - .d_dname = hugetlb_dname - }; - --struct file *hugetlb_file_setup(const char *name, unsigned long addr, -- size_t size, vm_flags_t acctflag, -- struct user_struct **user, -+/* -+ * Note that size should be aligned to proper hugepage size in caller side, -+ * otherwise hugetlb_reserve_pages reserves one less hugepages than intended. -+ */ -+struct file *hugetlb_file_setup(const char *name, size_t size, -+ vm_flags_t acctflag, struct user_struct **user, - int creat_flags, int page_size_log) - { - struct file *file = ERR_PTR(-ENOMEM); -@@ -939,8 +939,6 @@ struct file *hugetlb_file_setup(const char *name, unsigned long addr, - struct path path; - struct super_block *sb; - struct qstr quick_string; -- struct hstate *hstate; -- unsigned long num_pages; - int hstate_idx; - - hstate_idx = get_hstate_idx(page_size_log); -@@ -980,12 +978,10 @@ struct file *hugetlb_file_setup(const char *name, unsigned long addr, - if (!inode) - goto out_dentry; - -- hstate = hstate_inode(inode); -- size += addr & ~huge_page_mask(hstate); -- num_pages = ALIGN(size, huge_page_size(hstate)) >> -- huge_page_shift(hstate); - file = ERR_PTR(-ENOMEM); -- if (hugetlb_reserve_pages(inode, 0, num_pages, NULL, acctflag)) -+ if (hugetlb_reserve_pages(inode, 0, -+ size >> huge_page_shift(hstate_inode(inode)), NULL, -+ acctflag)) - goto out_inode; - - d_instantiate(path.dentry, inode); -diff --git a/fs/nfs/nfs4proc.c b/fs/nfs/nfs4proc.c -index c7856a1..0086401 100644 ---- a/fs/nfs/nfs4proc.c -+++ b/fs/nfs/nfs4proc.c -@@ -4553,9 +4553,9 @@ static int nfs4_proc_unlck(struct nfs4_state *state, int cmd, struct file_lock * - if (status != 0) - goto out; - /* Is this a delegated lock? */ -- if (test_bit(NFS_DELEGATED_STATE, &state->flags)) -- goto out; - lsp = request->fl_u.nfs4_fl.owner; -+ if (test_bit(NFS_LOCK_INITIALIZED, &lsp->ls_flags) == 0) -+ goto out; - seqid = nfs_alloc_seqid(&lsp->ls_seqid, GFP_KERNEL); - status = -ENOMEM; - if (seqid == NULL) -diff --git a/include/drm/drmP.h b/include/drm/drmP.h -index 2d94d74..f1ce786 100644 ---- a/include/drm/drmP.h -+++ b/include/drm/drmP.h -@@ -1593,9 +1593,8 @@ extern void drm_prime_gem_destroy(struct drm_gem_object *obj, struct sg_table *s - - void drm_prime_init_file_private(struct drm_prime_file_private *prime_fpriv); - void drm_prime_destroy_file_private(struct drm_prime_file_private *prime_fpriv); --int drm_prime_add_imported_buf_handle(struct drm_prime_file_private *prime_fpriv, struct dma_buf *dma_buf, uint32_t handle); --int drm_prime_lookup_imported_buf_handle(struct drm_prime_file_private *prime_fpriv, struct dma_buf *dma_buf, uint32_t *handle); --void drm_prime_remove_imported_buf_handle(struct drm_prime_file_private *prime_fpriv, struct dma_buf *dma_buf); -+int drm_prime_lookup_buf_handle(struct drm_prime_file_private *prime_fpriv, struct dma_buf *dma_buf, uint32_t *handle); -+void drm_prime_remove_buf_handle(struct drm_prime_file_private *prime_fpriv, struct dma_buf *dma_buf); - - int drm_prime_add_dma_buf(struct drm_device *dev, struct drm_gem_object *obj); - int drm_prime_lookup_obj(struct drm_device *dev, struct dma_buf *buf, -diff --git a/include/drm/drm_pciids.h b/include/drm/drm_pciids.h -index 918e8fe..c2af598 100644 ---- a/include/drm/drm_pciids.h -+++ b/include/drm/drm_pciids.h -@@ -240,6 +240,7 @@ - {0x1002, 0x6819, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_PITCAIRN|RADEON_NEW_MEMMAP}, \ - {0x1002, 0x6820, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_VERDE|RADEON_IS_MOBILITY|RADEON_NEW_MEMMAP}, \ - {0x1002, 0x6821, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_VERDE|RADEON_IS_MOBILITY|RADEON_NEW_MEMMAP}, \ -+ {0x1002, 0x6822, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_VERDE|RADEON_IS_MOBILITY|RADEON_NEW_MEMMAP}, \ - {0x1002, 0x6823, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_VERDE|RADEON_IS_MOBILITY|RADEON_NEW_MEMMAP}, \ - {0x1002, 0x6824, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_VERDE|RADEON_IS_MOBILITY|RADEON_NEW_MEMMAP}, \ - {0x1002, 0x6825, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_VERDE|RADEON_IS_MOBILITY|RADEON_NEW_MEMMAP}, \ -@@ -247,11 +248,13 @@ - {0x1002, 0x6827, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_VERDE|RADEON_IS_MOBILITY|RADEON_NEW_MEMMAP}, \ - {0x1002, 0x6828, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_VERDE|RADEON_NEW_MEMMAP}, \ - {0x1002, 0x6829, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_VERDE|RADEON_NEW_MEMMAP}, \ -+ {0x1002, 0x682A, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_VERDE|RADEON_IS_MOBILITY|RADEON_NEW_MEMMAP}, \ - {0x1002, 0x682B, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_VERDE|RADEON_IS_MOBILITY|RADEON_NEW_MEMMAP}, \ - {0x1002, 0x682D, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_VERDE|RADEON_IS_MOBILITY|RADEON_NEW_MEMMAP}, \ - {0x1002, 0x682F, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_VERDE|RADEON_IS_MOBILITY|RADEON_NEW_MEMMAP}, \ - {0x1002, 0x6830, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_VERDE|RADEON_IS_MOBILITY|RADEON_NEW_MEMMAP}, \ - {0x1002, 0x6831, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_VERDE|RADEON_IS_MOBILITY|RADEON_NEW_MEMMAP}, \ -+ {0x1002, 0x6835, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_VERDE|RADEON_NEW_MEMMAP}, \ - {0x1002, 0x6837, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_VERDE|RADEON_NEW_MEMMAP}, \ - {0x1002, 0x6838, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_VERDE|RADEON_NEW_MEMMAP}, \ - {0x1002, 0x6839, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_VERDE|RADEON_NEW_MEMMAP}, \ -@@ -603,6 +606,8 @@ - {0x1002, 0x9999, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_ARUBA|RADEON_IS_MOBILITY|RADEON_NEW_MEMMAP|RADEON_IS_IGP}, \ - {0x1002, 0x999A, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_ARUBA|RADEON_IS_MOBILITY|RADEON_NEW_MEMMAP|RADEON_IS_IGP}, \ - {0x1002, 0x999B, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_ARUBA|RADEON_IS_MOBILITY|RADEON_NEW_MEMMAP|RADEON_IS_IGP}, \ -+ {0x1002, 0x999C, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_ARUBA|RADEON_NEW_MEMMAP|RADEON_IS_IGP}, \ -+ {0x1002, 0x999D, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_ARUBA|RADEON_NEW_MEMMAP|RADEON_IS_IGP}, \ - {0x1002, 0x99A0, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_ARUBA|RADEON_IS_MOBILITY|RADEON_NEW_MEMMAP|RADEON_IS_IGP}, \ - {0x1002, 0x99A2, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_ARUBA|RADEON_IS_MOBILITY|RADEON_NEW_MEMMAP|RADEON_IS_IGP}, \ - {0x1002, 0x99A4, PCI_ANY_ID, PCI_ANY_ID, 0, 0, CHIP_ARUBA|RADEON_NEW_MEMMAP|RADEON_IS_IGP}, \ -diff --git a/include/linux/blkdev.h b/include/linux/blkdev.h -index 78feda9..33f358f 100644 ---- a/include/linux/blkdev.h -+++ b/include/linux/blkdev.h -@@ -838,7 +838,7 @@ static inline unsigned int blk_queue_get_max_sectors(struct request_queue *q, - unsigned int cmd_flags) - { - if (unlikely(cmd_flags & REQ_DISCARD)) -- return q->limits.max_discard_sectors; -+ return min(q->limits.max_discard_sectors, UINT_MAX >> 9); - - if (unlikely(cmd_flags & REQ_WRITE_SAME)) - return q->limits.max_write_same_sectors; -diff --git a/include/linux/hugetlb.h b/include/linux/hugetlb.h -index 16e4e9a..df1ff7c 100644 ---- a/include/linux/hugetlb.h -+++ b/include/linux/hugetlb.h -@@ -185,8 +185,7 @@ static inline struct hugetlbfs_sb_info *HUGETLBFS_SB(struct super_block *sb) - - extern const struct file_operations hugetlbfs_file_operations; - extern const struct vm_operations_struct hugetlb_vm_ops; --struct file *hugetlb_file_setup(const char *name, unsigned long addr, -- size_t size, vm_flags_t acct, -+struct file *hugetlb_file_setup(const char *name, size_t size, vm_flags_t acct, - struct user_struct **user, int creat_flags, - int page_size_log); - -@@ -205,8 +204,8 @@ static inline int is_file_hugepages(struct file *file) - - #define is_file_hugepages(file) 0 - static inline struct file * --hugetlb_file_setup(const char *name, unsigned long addr, size_t size, -- vm_flags_t acctflag, struct user_struct **user, int creat_flags, -+hugetlb_file_setup(const char *name, size_t size, vm_flags_t acctflag, -+ struct user_struct **user, int creat_flags, - int page_size_log) - { - return ERR_PTR(-ENOSYS); -@@ -284,6 +283,13 @@ static inline struct hstate *hstate_file(struct file *f) - return hstate_inode(file_inode(f)); - } - -+static inline struct hstate *hstate_sizelog(int page_size_log) -+{ -+ if (!page_size_log) -+ return &default_hstate; -+ return size_to_hstate(1 << page_size_log); -+} -+ - static inline struct hstate *hstate_vma(struct vm_area_struct *vma) - { - return hstate_file(vma->vm_file); -@@ -348,11 +354,12 @@ static inline int hstate_index(struct hstate *h) - return h - hstates; - } - --#else -+#else /* CONFIG_HUGETLB_PAGE */ - struct hstate {}; - #define alloc_huge_page_node(h, nid) NULL - #define alloc_bootmem_huge_page(h) NULL - #define hstate_file(f) NULL -+#define hstate_sizelog(s) NULL - #define hstate_vma(v) NULL - #define hstate_inode(i) NULL - #define huge_page_size(h) PAGE_SIZE -@@ -367,6 +374,6 @@ static inline unsigned int pages_per_huge_page(struct hstate *h) - } - #define hstate_index_to_shift(index) 0 - #define hstate_index(h) 0 --#endif -+#endif /* CONFIG_HUGETLB_PAGE */ - - #endif /* _LINUX_HUGETLB_H */ -diff --git a/ipc/shm.c b/ipc/shm.c -index 8247c49..34af1fe 100644 ---- a/ipc/shm.c -+++ b/ipc/shm.c -@@ -491,10 +491,14 @@ static int newseg(struct ipc_namespace *ns, struct ipc_params *params) - - sprintf (name, "SYSV%08x", key); - if (shmflg & SHM_HUGETLB) { -+ struct hstate *hs = hstate_sizelog((shmflg >> SHM_HUGE_SHIFT) -+ & SHM_HUGE_MASK); -+ size_t hugesize = ALIGN(size, huge_page_size(hs)); -+ - /* hugetlb_file_setup applies strict accounting */ - if (shmflg & SHM_NORESERVE) - acctflag = VM_NORESERVE; -- file = hugetlb_file_setup(name, 0, size, acctflag, -+ file = hugetlb_file_setup(name, hugesize, acctflag, - &shp->mlock_user, HUGETLB_SHMFS_INODE, - (shmflg >> SHM_HUGE_SHIFT) & SHM_HUGE_MASK); - } else { -diff --git a/kernel/Makefile b/kernel/Makefile -index bbde5f1..5a51e6c 100644 ---- a/kernel/Makefile -+++ b/kernel/Makefile -@@ -175,7 +175,7 @@ signing_key.priv signing_key.x509: x509.genkey - openssl req -new -nodes -utf8 -$(CONFIG_MODULE_SIG_HASH) -days 36500 \ - -batch -x509 -config x509.genkey \ - -outform DER -out signing_key.x509 \ -- -keyout signing_key.priv -+ -keyout signing_key.priv 2>&1 - @echo "###" - @echo "### Key pair generated." - @echo "###" -diff --git a/kernel/audit_tree.c b/kernel/audit_tree.c -index 642a89c..a291aa2 100644 ---- a/kernel/audit_tree.c -+++ b/kernel/audit_tree.c -@@ -617,9 +617,9 @@ void audit_trim_trees(void) - } - spin_unlock(&hash_lock); - trim_marked(tree); -- put_tree(tree); - drop_collected_mounts(root_mnt); - skip_it: -+ put_tree(tree); - mutex_lock(&audit_filter_mutex); - } - list_del(&cursor); -diff --git a/kernel/trace/trace.c b/kernel/trace/trace.c -index 7713d1b..3f28192 100644 ---- a/kernel/trace/trace.c -+++ b/kernel/trace/trace.c -@@ -5168,36 +5168,32 @@ void trace_init_global_iter(struct trace_iterator *iter) - iter->cpu_file = TRACE_PIPE_ALL_CPU; - } - --static void --__ftrace_dump(bool disable_tracing, enum ftrace_dump_mode oops_dump_mode) -+void ftrace_dump(enum ftrace_dump_mode oops_dump_mode) - { -- static arch_spinlock_t ftrace_dump_lock = -- (arch_spinlock_t)__ARCH_SPIN_LOCK_UNLOCKED; - /* use static because iter can be a bit big for the stack */ - static struct trace_iterator iter; -+ static atomic_t dump_running; - unsigned int old_userobj; -- static int dump_ran; - unsigned long flags; - int cnt = 0, cpu; - -- /* only one dump */ -- local_irq_save(flags); -- arch_spin_lock(&ftrace_dump_lock); -- if (dump_ran) -- goto out; -- -- dump_ran = 1; -+ /* Only allow one dump user at a time. */ -+ if (atomic_inc_return(&dump_running) != 1) { -+ atomic_dec(&dump_running); -+ return; -+ } - -+ /* -+ * Always turn off tracing when we dump. -+ * We don't need to show trace output of what happens -+ * between multiple crashes. -+ * -+ * If the user does a sysrq-z, then they can re-enable -+ * tracing with echo 1 > tracing_on. -+ */ - tracing_off(); - -- /* Did function tracer already get disabled? */ -- if (ftrace_is_dead()) { -- printk("# WARNING: FUNCTION TRACING IS CORRUPTED\n"); -- printk("# MAY BE MISSING FUNCTION EVENTS\n"); -- } -- -- if (disable_tracing) -- ftrace_kill(); -+ local_irq_save(flags); - - /* Simulate the iterator */ - trace_init_global_iter(&iter); -@@ -5227,6 +5223,12 @@ __ftrace_dump(bool disable_tracing, enum ftrace_dump_mode oops_dump_mode) - - printk(KERN_TRACE "Dumping ftrace buffer:\n"); - -+ /* Did function tracer already get disabled? */ -+ if (ftrace_is_dead()) { -+ printk("# WARNING: FUNCTION TRACING IS CORRUPTED\n"); -+ printk("# MAY BE MISSING FUNCTION EVENTS\n"); -+ } -+ - /* - * We need to stop all tracing on all CPUS to read the - * the next buffer. This is a bit expensive, but is -@@ -5266,26 +5268,14 @@ __ftrace_dump(bool disable_tracing, enum ftrace_dump_mode oops_dump_mode) - printk(KERN_TRACE "---------------------------------\n"); - - out_enable: -- /* Re-enable tracing if requested */ -- if (!disable_tracing) { -- trace_flags |= old_userobj; -+ trace_flags |= old_userobj; - -- for_each_tracing_cpu(cpu) { -- atomic_dec(&iter.tr->data[cpu]->disabled); -- } -- tracing_on(); -+ for_each_tracing_cpu(cpu) { -+ atomic_dec(&iter.tr->data[cpu]->disabled); - } -- -- out: -- arch_spin_unlock(&ftrace_dump_lock); -+ atomic_dec(&dump_running); - local_irq_restore(flags); - } -- --/* By default: disable tracing after the dump */ --void ftrace_dump(enum ftrace_dump_mode oops_dump_mode) --{ -- __ftrace_dump(true, oops_dump_mode); --} - EXPORT_SYMBOL_GPL(ftrace_dump); - - __init static int tracer_alloc_buffers(void) -diff --git a/kernel/trace/trace_selftest.c b/kernel/trace/trace_selftest.c -index 51c819c..eedc297 100644 ---- a/kernel/trace/trace_selftest.c -+++ b/kernel/trace/trace_selftest.c -@@ -703,8 +703,6 @@ trace_selftest_startup_function(struct tracer *trace, struct trace_array *tr) - /* Maximum number of functions to trace before diagnosing a hang */ - #define GRAPH_MAX_FUNC_TEST 100000000 - --static void --__ftrace_dump(bool disable_tracing, enum ftrace_dump_mode oops_dump_mode); - static unsigned int graph_hang_thresh; - - /* Wrap the real function entry probe to avoid possible hanging */ -@@ -714,8 +712,11 @@ static int trace_graph_entry_watchdog(struct ftrace_graph_ent *trace) - if (unlikely(++graph_hang_thresh > GRAPH_MAX_FUNC_TEST)) { - ftrace_graph_stop(); - printk(KERN_WARNING "BUG: Function graph tracer hang!\n"); -- if (ftrace_dump_on_oops) -- __ftrace_dump(false, DUMP_ALL); -+ if (ftrace_dump_on_oops) { -+ ftrace_dump(DUMP_ALL); -+ /* ftrace_dump() disables tracing */ -+ tracing_on(); -+ } - return 0; - } - -diff --git a/mm/mmap.c b/mm/mmap.c -index 033094b..e17fc06 100644 ---- a/mm/mmap.c -+++ b/mm/mmap.c -@@ -1327,15 +1327,20 @@ SYSCALL_DEFINE6(mmap_pgoff, unsigned long, addr, unsigned long, len, - file = fget(fd); - if (!file) - goto out; -+ if (is_file_hugepages(file)) -+ len = ALIGN(len, huge_page_size(hstate_file(file))); - } else if (flags & MAP_HUGETLB) { - struct user_struct *user = NULL; -+ -+ len = ALIGN(len, huge_page_size(hstate_sizelog( -+ (flags >> MAP_HUGE_SHIFT) & MAP_HUGE_MASK))); - /* - * VM_NORESERVE is used because the reservations will be - * taken when vm_ops->mmap() is called - * A dummy user value is used because we are not locking - * memory so no accounting is necessary - */ -- file = hugetlb_file_setup(HUGETLB_ANON_FILE, addr, len, -+ file = hugetlb_file_setup(HUGETLB_ANON_FILE, len, - VM_NORESERVE, - &user, HUGETLB_ANONHUGE_INODE, - (flags >> MAP_HUGE_SHIFT) & MAP_HUGE_MASK); -diff --git a/net/netfilter/ipvs/ip_vs_pe_sip.c b/net/netfilter/ipvs/ip_vs_pe_sip.c -index 12475ef..e5920fb 100644 ---- a/net/netfilter/ipvs/ip_vs_pe_sip.c -+++ b/net/netfilter/ipvs/ip_vs_pe_sip.c -@@ -37,14 +37,10 @@ static int get_callid(const char *dptr, unsigned int dataoff, - if (ret > 0) - break; - if (!ret) -- return 0; -+ return -EINVAL; - dataoff += *matchoff; - } - -- /* Empty callid is useless */ -- if (!*matchlen) -- return -EINVAL; -- - /* Too large is useless */ - if (*matchlen > IP_VS_PEDATA_MAXLEN) - return -EINVAL; -diff --git a/scripts/kconfig/list.h b/scripts/kconfig/list.h -index 0ae730b..b87206c 100644 ---- a/scripts/kconfig/list.h -+++ b/scripts/kconfig/list.h -@@ -51,6 +51,19 @@ struct list_head { - pos = list_entry(pos->member.next, typeof(*pos), member)) - - /** -+ * list_for_each_entry_safe - iterate over list of given type safe against removal of list entry -+ * @pos: the type * to use as a loop cursor. -+ * @n: another type * to use as temporary storage -+ * @head: the head for your list. -+ * @member: the name of the list_struct within the struct. -+ */ -+#define list_for_each_entry_safe(pos, n, head, member) \ -+ for (pos = list_entry((head)->next, typeof(*pos), member), \ -+ n = list_entry(pos->member.next, typeof(*pos), member); \ -+ &pos->member != (head); \ -+ pos = n, n = list_entry(n->member.next, typeof(*n), member)) -+ -+/** - * list_empty - tests whether a list is empty - * @head: the list to test. - */ -diff --git a/scripts/kconfig/mconf.c b/scripts/kconfig/mconf.c -index 566288a..c5418d6 100644 ---- a/scripts/kconfig/mconf.c -+++ b/scripts/kconfig/mconf.c -@@ -389,6 +389,7 @@ again: - .targets = targets, - .keys = keys, - }; -+ struct jump_key *pos, *tmp; - - res = get_relations_str(sym_arr, &head); - dres = show_textbox_ext(_("Search Results"), (char *) -@@ -402,6 +403,8 @@ again: - again = true; - } - str_free(&res); -+ list_for_each_entry_safe(pos, tmp, &head, entries) -+ free(pos); - } while (again); - free(sym_arr); - str_free(&title); diff --git a/patches.kernel.org/patch-3.9.2-3 b/patches.kernel.org/patch-3.9.2-3 deleted file mode 100644 index 8ab11c2..0000000 --- a/patches.kernel.org/patch-3.9.2-3 +++ b/dev/null @@ -1,3862 +0,0 @@ -From: Jiri Slaby <jslaby@suse.cz> -Subject: Linux 3.9.3 -Patch-mainline: 3.9.3 -Git-commit: e3e84cda321703b123f36488f50700f371bc7230 -Git-commit: 780a7654cee8d61819512385e778e4827db4bfbc -Git-commit: 6880b0150a7c25fd75c5ece80abc49ebf53c38c1 -Git-commit: 93782eba49e23c3f311a6b05a19ba15927ec4e8b -Git-commit: bbbfde782084b4f0d85ddffb88f1cf4650ff40e4 -Git-commit: f0a18819e261afc5fdbd8c5c6f9943123c5461ba -Git-commit: c207a76bf155cb5cf24cf849c08f6555e9180594 -Git-commit: 264b83c07a84223f0efd0d1db9ccc66d6f88288f -Git-commit: e9ced8e040ebe40e9953db90acbe7d0b58702ebb -Git-commit: fefaedcfb82d2e57c2320acf60604ab03b750cc0 -Git-commit: 61559af111e41761f5f4f20ce0897345eb59076e -Git-commit: 6368087e851e697679af059b4247aca33a69cef3 -Git-commit: a5f2b3d6a738e7d4180012fe7b541172f8c8dcea -Git-commit: 28fe5c825f8e15744d04c7c1b8df197950923ecd -Git-commit: d2bdbee0d91a5d3ba2e439ce889e20bfe6fd4f1b -Git-commit: ccf5ae83a6cf3d9cfe9a7038bfe7cd38ab03d5e1 -Git-commit: 3eccfdb01da58fbd0f789ae6ca61cee3769e26de -Git-commit: ca182aee389f8026401510f4c63841cb02c820e8 -Git-commit: d8f469e9cff3bc4a6317d923e9506be046aa7bdc -Git-commit: 1abc4b20b85b42e8573957e54b193385cf48b0d6 -Git-commit: 35623715818dfa720cccf99cd280dcbb4b78da23 -Git-commit: 088584618836b159947bc4ab5011a5cf1f081a62 -Git-commit: 22ee3b57c3ff71772b0c4178404b04f5df78d501 -Git-commit: 7c689e63a847316c1b2500f86891b0a574ce7e69 -Git-commit: 94ad0a101415978be04945b2787be1e8e8a874db -Git-commit: ef57f9e6bb9278720c8a5278728f252ab85d7ac6 -Git-commit: 60403f7a4d9368d187f79cba5e4672d01df37574 -Git-commit: 5c1ef59168c485318e40ba485c1eba57d81d0faa -Git-commit: 84c4a9dfbf430861e7588d95ae3ff61535dca351 -Git-commit: 5dbd5068430b8bd1c19387d46d6c1a88b261257f -Git-commit: f77d602124d865c38705df7fa25c03de9c284ad2 -Git-commit: 233c7df0821c4190e2d3f4be0f2ca0ab40a5ed8c -Git-commit: 4f924b2aa4d3cb30f07e57d6b608838edcbc0d88 -Git-commit: 4b264a1676e70dc656ba53a8cac690f2d4b65f4e -Git-commit: c81400be716aa4c76f6ebf339ba94358dbbf6da6 -Git-commit: b56141ab34e2c3e2d7960cea12c20c99530c0c76 -Git-commit: 77d21f23a1e4db8639e3916547c903a3b3c7a07c -Git-commit: 8da3056c04bfc5f69f840ab038a38389e2de8189 -Git-commit: c5060cec6ba27ad3f0e7facfdf05d2f18e3e3010 -Git-commit: 83401eb4990ff6af55aeed8f49681558544192e6 -Git-commit: b29d3145183da4e07d4b570fa8acdd3ac4a5c572 -Git-commit: 6708c9e5cc9bfc7c9a00ce9c0fdd0b1d4952b3d1 -Git-commit: 0dcffd09641f3abb21ac5cabc61542ab289d1a3c -Git-commit: 3b54912f9cd167641b91d4a697bd742f70e534fe -Git-commit: cd75eff64dae8856afbf6ef0f0ca3c145465d8e0 -Git-commit: 2c1bbbffa0b644fab4f91878cde0c2e8f52e2dcc -Git-commit: 3811ae76bc84e5dc1a670ae10695f046b310bee1 -Git-commit: 89cc80a44b7c320e08599cb86f6aef0ead8986a1 -Git-commit: 093162553c33e9479283e107b4431378271c735d -Git-commit: 1ffc5289bfcf7f4c4e4213240bb4be68c48ce603 -Git-commit: a9b054e8ab06504c2afa0e307ee78d3778993a1d -Git-commit: 3a359f0b21ab218c1bf7a6a1b638b6fd143d0b99 -Git-commit: 9f1d036648c1c5ed81b0e98d7a06d55df972701e -Git-commit: fb70a6690875315a3a1454e52fa339441ee7612b -Git-commit: dd9c46408fdc07098333655ff27edf8cac8d9fcf -Git-commit: 73b82bf0bfbf58e6ff328d3726934370585f6e78 -Git-commit: c539914dcd9a68c63305e055b14115a6a19578a8 -Git-commit: ccd384b10420ac81ba3fb9b0a7d18272c7173552 -Git-commit: f16fdc9d2dc1e5b270e9a08377587e831e0d36ac -Git-commit: 48795424acff7215d5eac0b52793a2c1eb3a6283 -Git-commit: 4ef69d0394cba8caa9f75d3f2e53429bfb8b3045 -Git-commit: 79c66ce8f6448a3295a32efeac88c9debd7f7094 -Git-commit: 120496ac2d2d60aee68d3123a68169502a85f4b5 -Git-commit: 6eabb3301b1facee669d9938f7c5a0295c21d71d -Git-commit: 074d72ff57f65de779e2f70d5906964c0ba1c123 -Git-commit: e6155736ad76b2070652745f9e54cdea3f0d8567 -Git-commit: 60705c89460fdc7227f2d153b68b3f34814738a4 -Git-commit: 4b0c0f294f60abcdd20994a8341a95c8ac5eeb96 -Git-commit: 42a5cf46cd56f46267d2a9fcf2655f4078cd3042 -Git-commit: b4f711ee03d28f776fd2324fd0bd999cc428e4d2 -Git-commit: 33e2208acfc15ce00d3dd13e839bf6434faa2b04 -Git-commit: cdee3904b4ce7c03d1013ed6dd704b43ae7fc2e9 -Git-commit: 39c60a0948cc06139e2fbfe084f83cb7e7deae3b -Git-commit: 7f1fc268c47491fd5e63548f6415fc8604e13003 -Git-commit: 091d0d55b286c9340201b4ed4470be87fc568228 -Git-commit: 7783819920ca52fc582a2782f654fe6ed373f465 -Git-commit: 7255e716b1757dc10fa5e3a4d2eaab303ff9f7b6 -Git-commit: 9f415eb25574db4b73a9a712a4438e41dc284922 -Git-commit: 68aa8efcd1ab961e4684ef5af32f72a6ec1911de -Git-commit: f3002134158092178be81339ec5a22ff80e6c308 -Git-commit: 772c808a252594692972773f6ee41c289b8e0b2a -Git-commit: 55eaa7c1f511af5fb6ef808b5328804f4d4e5243 -Git-commit: d9a3c9823a2e6a543eb7807fb3d15d8233817ec5 -Git-commit: f792685006274a850e6cc0ea9ade275ccdfc90bc -Git-commit: fa4d683af3693863bec761e2761a07e4c1351f86 -Git-commit: 09e8b813897a0f85bb401435d009228644c81214 -Git-commit: 502624bdad3dba45dfaacaf36b7d83e39e74b2d2 -Git-commit: d793e684277124d55c5d2444007e224635821346 -Git-commit: dc019b21fb92d620a3b52ccecc135ac968a7c7ec -Git-commit: 9a188eb126aa7bf27077ee46fcb914898d6fc281 -Git-commit: ff359b14919c379a365233aa2e1dd469efac8ce8 -Git-commit: 2195b063f6609e4c6268f291683902f25eaf9aa6 -Git-commit: 6c35ae3c327ef4b5f51d3428d2ba47ac2153e882 -Git-commit: 61388f9e5d93053cf399a356414f31f9b4814c6d -Git-commit: 4495e46fe18f198366961bb2b324a694ef8a9b44 -Git-commit: e65f131a14726e5f1b880a528271a52428e5b3a5 -Git-commit: c1e0ac192b48b37f31801c17534ab3d2a9282d84 -Git-commit: 326f578f7e1443bac2333712dd130a261ec15288 -Git-commit: 7fa57952d70f5737513d8319395e471d107e4e0d -Git-commit: a035d5c64d08a8ac12d81b596e7fa6d95a73c347 -Git-commit: 8d76c49e9ffeee839bc0b7a3278a23f99101263e - -Signed-off-by: Jiri Slaby <jslaby@suse.cz> ---- -diff --git a/Makefile b/Makefile -index 3e71511..01003d4 100644 ---- a/Makefile -+++ b/Makefile -@@ -1,6 +1,6 @@ - VERSION = 3 - PATCHLEVEL = 9 --SUBLEVEL = 2 -+SUBLEVEL = 3 - EXTRAVERSION = - NAME = Unicycling Gorilla - -diff --git a/arch/arm/include/asm/cmpxchg.h b/arch/arm/include/asm/cmpxchg.h -index 7eb18c1..4f009c1 100644 ---- a/arch/arm/include/asm/cmpxchg.h -+++ b/arch/arm/include/asm/cmpxchg.h -@@ -233,15 +233,15 @@ static inline unsigned long __cmpxchg_local(volatile void *ptr, - ((__typeof__(*(ptr)))atomic64_cmpxchg(container_of((ptr), \ - atomic64_t, \ - counter), \ -- (unsigned long)(o), \ -- (unsigned long)(n))) -+ (unsigned long long)(o), \ -+ (unsigned long long)(n))) - - #define cmpxchg64_local(ptr, o, n) \ - ((__typeof__(*(ptr)))local64_cmpxchg(container_of((ptr), \ - local64_t, \ - a), \ -- (unsigned long)(o), \ -- (unsigned long)(n))) -+ (unsigned long long)(o), \ -+ (unsigned long long)(n))) - - #endif /* __LINUX_ARM_ARCH__ >= 6 */ - -diff --git a/arch/arm/mach-exynos/include/mach/regs-pmu.h b/arch/arm/mach-exynos/include/mach/regs-pmu.h -index 3f30aa1..57344b7 100644 ---- a/arch/arm/mach-exynos/include/mach/regs-pmu.h -+++ b/arch/arm/mach-exynos/include/mach/regs-pmu.h -@@ -344,6 +344,7 @@ - #define EXYNOS5_FSYS_ARM_OPTION S5P_PMUREG(0x2208) - #define EXYNOS5_ISP_ARM_OPTION S5P_PMUREG(0x2288) - #define EXYNOS5_ARM_COMMON_OPTION S5P_PMUREG(0x2408) -+#define EXYNOS5_ARM_L2_OPTION S5P_PMUREG(0x2608) - #define EXYNOS5_TOP_PWR_OPTION S5P_PMUREG(0x2C48) - #define EXYNOS5_TOP_PWR_SYSMEM_OPTION S5P_PMUREG(0x2CC8) - #define EXYNOS5_JPEG_MEM_OPTION S5P_PMUREG(0x2F48) -diff --git a/arch/arm/mach-exynos/pmu.c b/arch/arm/mach-exynos/pmu.c -index daebc1a..97d6885 100644 ---- a/arch/arm/mach-exynos/pmu.c -+++ b/arch/arm/mach-exynos/pmu.c -@@ -228,6 +228,7 @@ static struct exynos_pmu_conf exynos5250_pmu_config[] = { - { EXYNOS5_DIS_IRQ_ISP_ARM_CENTRAL_SYS_PWR_REG, { 0x0, 0x0, 0x0} }, - { EXYNOS5_ARM_COMMON_SYS_PWR_REG, { 0x0, 0x0, 0x2} }, - { EXYNOS5_ARM_L2_SYS_PWR_REG, { 0x3, 0x3, 0x3} }, -+ { EXYNOS5_ARM_L2_OPTION, { 0x10, 0x10, 0x0 } }, - { EXYNOS5_CMU_ACLKSTOP_SYS_PWR_REG, { 0x1, 0x0, 0x1} }, - { EXYNOS5_CMU_SCLKSTOP_SYS_PWR_REG, { 0x1, 0x0, 0x1} }, - { EXYNOS5_CMU_RESET_SYS_PWR_REG, { 0x1, 0x1, 0x0} }, -@@ -353,11 +354,9 @@ static void exynos5_init_pmu(void) - - /* - * SKIP_DEACTIVATE_ACEACP_IN_PWDN_BITFIELD Enable -- * MANUAL_L2RSTDISABLE_CONTROL_BITFIELD Enable - */ - tmp = __raw_readl(EXYNOS5_ARM_COMMON_OPTION); -- tmp |= (EXYNOS5_MANUAL_L2RSTDISABLE_CONTROL | -- EXYNOS5_SKIP_DEACTIVATE_ACEACP_IN_PWDN); -+ tmp |= EXYNOS5_SKIP_DEACTIVATE_ACEACP_IN_PWDN; - __raw_writel(tmp, EXYNOS5_ARM_COMMON_OPTION); - - /* -diff --git a/arch/arm/mach-omap2/board-rx51-peripherals.c b/arch/arm/mach-omap2/board-rx51-peripherals.c -index 3a077df..9bc9f19 100644 ---- a/arch/arm/mach-omap2/board-rx51-peripherals.c -+++ b/arch/arm/mach-omap2/board-rx51-peripherals.c -@@ -73,11 +73,11 @@ - #define LIS302_IRQ1_GPIO 181 - #define LIS302_IRQ2_GPIO 180 /* Not yet in use */ - --/* list all spi devices here */ -+/* List all SPI devices here. Note that the list/probe order seems to matter! */ - enum { - RX51_SPI_WL1251, -- RX51_SPI_MIPID, /* LCD panel */ - RX51_SPI_TSC2005, /* Touch Controller */ -+ RX51_SPI_MIPID, /* LCD panel */ - }; - - static struct wl12xx_platform_data wl1251_pdata; -diff --git a/arch/parisc/Makefile b/arch/parisc/Makefile -index 113e282..1976900 100644 ---- a/arch/parisc/Makefile -+++ b/arch/parisc/Makefile -@@ -23,26 +23,21 @@ NM = sh $(srctree)/arch/parisc/nm - CHECKFLAGS += -D__hppa__=1 - LIBGCC = $(shell $(CC) $(KBUILD_CFLAGS) -print-libgcc-file-name) - --MACHINE := $(shell uname -m) --ifeq ($(MACHINE),parisc*) --NATIVE := 1 --endif -- - ifdef CONFIG_64BIT - UTS_MACHINE := parisc64 - CHECKFLAGS += -D__LP64__=1 -m64 --WIDTH := 64 -+CC_ARCHES = hppa64 - else # 32-bit --WIDTH := -+CC_ARCHES = hppa hppa2.0 hppa1.1 - endif - --# attempt to help out folks who are cross-compiling --ifeq ($(NATIVE),1) --CROSS_COMPILE := hppa$(WIDTH)-linux- --else -- ifeq ($(CROSS_COMPILE),) -- CROSS_COMPILE := hppa$(WIDTH)-linux-gnu- -- endif -+ifneq ($(SUBARCH),$(UTS_MACHINE)) -+ ifeq ($(CROSS_COMPILE),) -+ CC_SUFFIXES = linux linux-gnu unknown-linux-gnu -+ CROSS_COMPILE := $(call cc-cross-prefix, \ -+ $(foreach a,$(CC_ARCHES), \ -+ $(foreach s,$(CC_SUFFIXES),$(a)-$(s)-))) -+ endif - endif - - OBJCOPY_FLAGS =-O binary -R .note -R .comment -S -diff --git a/arch/parisc/kernel/entry.S b/arch/parisc/kernel/entry.S -index f33201b..897bce4 100644 ---- a/arch/parisc/kernel/entry.S -+++ b/arch/parisc/kernel/entry.S -@@ -444,9 +444,41 @@ - L2_ptep \pgd,\pte,\index,\va,\fault - .endm - -+ /* Acquire pa_dbit_lock lock. */ -+ .macro dbit_lock spc,tmp,tmp1 -+#ifdef CONFIG_SMP -+ cmpib,COND(=),n 0,\spc,2f -+ load32 PA(pa_dbit_lock),\tmp -+1: LDCW 0(\tmp),\tmp1 -+ cmpib,COND(=) 0,\tmp1,1b -+ nop -+2: -+#endif -+ .endm -+ -+ /* Release pa_dbit_lock lock without reloading lock address. */ -+ .macro dbit_unlock0 spc,tmp -+#ifdef CONFIG_SMP -+ or,COND(=) %r0,\spc,%r0 -+ stw \spc,0(\tmp) -+#endif -+ .endm -+ -+ /* Release pa_dbit_lock lock. */ -+ .macro dbit_unlock1 spc,tmp -+#ifdef CONFIG_SMP -+ load32 PA(pa_dbit_lock),\tmp -+ dbit_unlock0 \spc,\tmp -+#endif -+ .endm -+ - /* Set the _PAGE_ACCESSED bit of the PTE. Be clever and - * don't needlessly dirty the cache line if it was already set */ -- .macro update_ptep ptep,pte,tmp,tmp1 -+ .macro update_ptep spc,ptep,pte,tmp,tmp1 -+#ifdef CONFIG_SMP -+ or,COND(=) %r0,\spc,%r0 -+ LDREG 0(\ptep),\pte -+#endif - ldi _PAGE_ACCESSED,\tmp1 - or \tmp1,\pte,\tmp - and,COND(<>) \tmp1,\pte,%r0 -@@ -455,7 +487,11 @@ - - /* Set the dirty bit (and accessed bit). No need to be - * clever, this is only used from the dirty fault */ -- .macro update_dirty ptep,pte,tmp -+ .macro update_dirty spc,ptep,pte,tmp -+#ifdef CONFIG_SMP -+ or,COND(=) %r0,\spc,%r0 -+ LDREG 0(\ptep),\pte -+#endif - ldi _PAGE_ACCESSED|_PAGE_DIRTY,\tmp - or \tmp,\pte,\pte - STREG \pte,0(\ptep) -@@ -825,11 +861,6 @@ ENTRY(syscall_exit_rfi) - STREG %r19,PT_SR7(%r16) - - intr_return: -- /* NOTE: Need to enable interrupts incase we schedule. */ -- ssm PSW_SM_I, %r0 -- --intr_check_resched: -- - /* check for reschedule */ - mfctl %cr30,%r1 - LDREG TI_FLAGS(%r1),%r19 /* sched.h: TIF_NEED_RESCHED */ -@@ -856,6 +887,11 @@ intr_check_sig: - LDREG PT_IASQ1(%r16), %r20 - cmpib,COND(=),n 0,%r20,intr_restore /* backward */ - -+ /* NOTE: We need to enable interrupts if we have to deliver -+ * signals. We used to do this earlier but it caused kernel -+ * stack overflows. */ -+ ssm PSW_SM_I, %r0 -+ - copy %r0, %r25 /* long in_syscall = 0 */ - #ifdef CONFIG_64BIT - ldo -16(%r30),%r29 /* Reference param save area */ -@@ -907,6 +943,10 @@ intr_do_resched: - cmpib,COND(=) 0, %r20, intr_do_preempt - nop - -+ /* NOTE: We need to enable interrupts if we schedule. We used -+ * to do this earlier but it caused kernel stack overflows. */ -+ ssm PSW_SM_I, %r0 -+ - #ifdef CONFIG_64BIT - ldo -16(%r30),%r29 /* Reference param save area */ - #endif -@@ -1099,11 +1139,13 @@ dtlb_miss_20w: - - L3_ptep ptp,pte,t0,va,dtlb_check_alias_20w - -- update_ptep ptp,pte,t0,t1 -+ dbit_lock spc,t0,t1 -+ update_ptep spc,ptp,pte,t0,t1 - - make_insert_tlb spc,pte,prot - - idtlbt pte,prot -+ dbit_unlock1 spc,t0 - - rfir - nop -@@ -1123,11 +1165,13 @@ nadtlb_miss_20w: - - L3_ptep ptp,pte,t0,va,nadtlb_check_alias_20w - -- update_ptep ptp,pte,t0,t1 -+ dbit_lock spc,t0,t1 -+ update_ptep spc,ptp,pte,t0,t1 - - make_insert_tlb spc,pte,prot - - idtlbt pte,prot -+ dbit_unlock1 spc,t0 - - rfir - nop -@@ -1149,7 +1193,8 @@ dtlb_miss_11: - - L2_ptep ptp,pte,t0,va,dtlb_check_alias_11 - -- update_ptep ptp,pte,t0,t1 -+ dbit_lock spc,t0,t1 -+ update_ptep spc,ptp,pte,t0,t1 - - make_insert_tlb_11 spc,pte,prot - -@@ -1160,6 +1205,7 @@ dtlb_miss_11: - idtlbp prot,(%sr1,va) - - mtsp t0, %sr1 /* Restore sr1 */ -+ dbit_unlock1 spc,t0 - - rfir - nop -@@ -1180,7 +1226,8 @@ nadtlb_miss_11: - - L2_ptep ptp,pte,t0,va,nadtlb_check_alias_11 - -- update_ptep ptp,pte,t0,t1 -+ dbit_lock spc,t0,t1 -+ update_ptep spc,ptp,pte,t0,t1 - - make_insert_tlb_11 spc,pte,prot - -@@ -1192,6 +1239,7 @@ nadtlb_miss_11: - idtlbp prot,(%sr1,va) - - mtsp t0, %sr1 /* Restore sr1 */ -+ dbit_unlock1 spc,t0 - - rfir - nop -@@ -1212,13 +1260,15 @@ dtlb_miss_20: - - L2_ptep ptp,pte,t0,va,dtlb_check_alias_20 - -- update_ptep ptp,pte,t0,t1 -+ dbit_lock spc,t0,t1 -+ update_ptep spc,ptp,pte,t0,t1 - - make_insert_tlb spc,pte,prot - - f_extend pte,t0 - - idtlbt pte,prot -+ dbit_unlock1 spc,t0 - - rfir - nop -@@ -1238,13 +1288,15 @@ nadtlb_miss_20: - - L2_ptep ptp,pte,t0,va,nadtlb_check_alias_20 - -- update_ptep ptp,pte,t0,t1 -+ dbit_lock spc,t0,t1 -+ update_ptep spc,ptp,pte,t0,t1 - - make_insert_tlb spc,pte,prot - - f_extend pte,t0 - - idtlbt pte,prot -+ dbit_unlock1 spc,t0 - - rfir - nop -@@ -1345,11 +1397,13 @@ itlb_miss_20w: - - L3_ptep ptp,pte,t0,va,itlb_fault - -- update_ptep ptp,pte,t0,t1 -+ dbit_lock spc,t0,t1 -+ update_ptep spc,ptp,pte,t0,t1 - - make_insert_tlb spc,pte,prot - - iitlbt pte,prot -+ dbit_unlock1 spc,t0 - - rfir - nop -@@ -1367,11 +1421,13 @@ naitlb_miss_20w: - - L3_ptep ptp,pte,t0,va,naitlb_check_alias_20w - -- update_ptep ptp,pte,t0,t1 -+ dbit_lock spc,t0,t1 -+ update_ptep spc,ptp,pte,t0,t1 - - make_insert_tlb spc,pte,prot - - iitlbt pte,prot -+ dbit_unlock1 spc,t0 - - rfir - nop -@@ -1393,7 +1449,8 @@ itlb_miss_11: - - L2_ptep ptp,pte,t0,va,itlb_fault - -- update_ptep ptp,pte,t0,t1 -+ dbit_lock spc,t0,t1 -+ update_ptep spc,ptp,pte,t0,t1 - - make_insert_tlb_11 spc,pte,prot - -@@ -1404,6 +1461,7 @@ itlb_miss_11: - iitlbp prot,(%sr1,va) - - mtsp t0, %sr1 /* Restore sr1 */ -+ dbit_unlock1 spc,t0 - - rfir - nop -@@ -1415,7 +1473,8 @@ naitlb_miss_11: - - L2_ptep ptp,pte,t0,va,naitlb_check_alias_11 - -- update_ptep ptp,pte,t0,t1 -+ dbit_lock spc,t0,t1 -+ update_ptep spc,ptp,pte,t0,t1 - - make_insert_tlb_11 spc,pte,prot - -@@ -1426,6 +1485,7 @@ naitlb_miss_11: - iitlbp prot,(%sr1,va) - - mtsp t0, %sr1 /* Restore sr1 */ -+ dbit_unlock1 spc,t0 - - rfir - nop -@@ -1447,13 +1507,15 @@ itlb_miss_20: - - L2_ptep ptp,pte,t0,va,itlb_fault - -- update_ptep ptp,pte,t0,t1 -+ dbit_lock spc,t0,t1 -+ update_ptep spc,ptp,pte,t0,t1 - - make_insert_tlb spc,pte,prot - - f_extend pte,t0 - - iitlbt pte,prot -+ dbit_unlock1 spc,t0 - - rfir - nop -@@ -1465,13 +1527,15 @@ naitlb_miss_20: - - L2_ptep ptp,pte,t0,va,naitlb_check_alias_20 - -- update_ptep ptp,pte,t0,t1 -+ dbit_lock spc,t0,t1 -+ update_ptep spc,ptp,pte,t0,t1 - - make_insert_tlb spc,pte,prot - - f_extend pte,t0 - - iitlbt pte,prot -+ dbit_unlock1 spc,t0 - - rfir - nop -@@ -1495,29 +1559,13 @@ dbit_trap_20w: - - L3_ptep ptp,pte,t0,va,dbit_fault - --#ifdef CONFIG_SMP -- cmpib,COND(=),n 0,spc,dbit_nolock_20w -- load32 PA(pa_dbit_lock),t0 -- --dbit_spin_20w: -- LDCW 0(t0),t1 -- cmpib,COND(=) 0,t1,dbit_spin_20w -- nop -- --dbit_nolock_20w: --#endif -- update_dirty ptp,pte,t1 -+ dbit_lock spc,t0,t1 -+ update_dirty spc,ptp,pte,t1 - - make_insert_tlb spc,pte,prot - - idtlbt pte,prot --#ifdef CONFIG_SMP -- cmpib,COND(=),n 0,spc,dbit_nounlock_20w -- ldi 1,t1 -- stw t1,0(t0) -- --dbit_nounlock_20w: --#endif -+ dbit_unlock0 spc,t0 - - rfir - nop -@@ -1531,18 +1579,8 @@ dbit_trap_11: - - L2_ptep ptp,pte,t0,va,dbit_fault - --#ifdef CONFIG_SMP -- cmpib,COND(=),n 0,spc,dbit_nolock_11 -- load32 PA(pa_dbit_lock),t0 -- --dbit_spin_11: -- LDCW 0(t0),t1 -- cmpib,= 0,t1,dbit_spin_11 -- nop -- --dbit_nolock_11: --#endif -- update_dirty ptp,pte,t1 -+ dbit_lock spc,t0,t1 -+ update_dirty spc,ptp,pte,t1 - - make_insert_tlb_11 spc,pte,prot - -@@ -1553,13 +1591,7 @@ dbit_nolock_11: - idtlbp prot,(%sr1,va) - - mtsp t1, %sr1 /* Restore sr1 */ --#ifdef CONFIG_SMP -- cmpib,COND(=),n 0,spc,dbit_nounlock_11 -- ldi 1,t1 -- stw t1,0(t0) -- --dbit_nounlock_11: --#endif -+ dbit_unlock0 spc,t0 - - rfir - nop -@@ -1571,32 +1603,15 @@ dbit_trap_20: - - L2_ptep ptp,pte,t0,va,dbit_fault - --#ifdef CONFIG_SMP -- cmpib,COND(=),n 0,spc,dbit_nolock_20 -- load32 PA(pa_dbit_lock),t0 -- --dbit_spin_20: -- LDCW 0(t0),t1 -- cmpib,= 0,t1,dbit_spin_20 -- nop -- --dbit_nolock_20: --#endif -- update_dirty ptp,pte,t1 -+ dbit_lock spc,t0,t1 -+ update_dirty spc,ptp,pte,t1 - - make_insert_tlb spc,pte,prot - - f_extend pte,t1 - - idtlbt pte,prot -- --#ifdef CONFIG_SMP -- cmpib,COND(=),n 0,spc,dbit_nounlock_20 -- ldi 1,t1 -- stw t1,0(t0) -- --dbit_nounlock_20: --#endif -+ dbit_unlock0 spc,t0 - - rfir - nop -@@ -1694,7 +1709,8 @@ ENTRY(sys_\name\()_wrapper) - ldo TASK_REGS(%r1),%r1 - reg_save %r1 - mfctl %cr27, %r28 -- b sys_\name -+ ldil L%sys_\name, %r31 -+ be R%sys_\name(%sr4,%r31) - STREG %r28, PT_CR27(%r1) - ENDPROC(sys_\name\()_wrapper) - .endm -diff --git a/arch/powerpc/include/asm/rtas.h b/arch/powerpc/include/asm/rtas.h -index aef00c6..ee38f29 100644 ---- a/arch/powerpc/include/asm/rtas.h -+++ b/arch/powerpc/include/asm/rtas.h -@@ -262,6 +262,8 @@ extern void rtas_progress(char *s, unsigned short hex); - extern void rtas_initialize(void); - extern int rtas_suspend_cpu(struct rtas_suspend_me_data *data); - extern int rtas_suspend_last_cpu(struct rtas_suspend_me_data *data); -+extern int rtas_online_cpus_mask(cpumask_var_t cpus); -+extern int rtas_offline_cpus_mask(cpumask_var_t cpus); - extern int rtas_ibm_suspend_me(struct rtas_args *); - - struct rtc_time; -diff --git a/arch/powerpc/kernel/machine_kexec_64.c b/arch/powerpc/kernel/machine_kexec_64.c -index 466a290..611acdf 100644 ---- a/arch/powerpc/kernel/machine_kexec_64.c -+++ b/arch/powerpc/kernel/machine_kexec_64.c -@@ -17,6 +17,7 @@ - #include <linux/errno.h> - #include <linux/kernel.h> - #include <linux/cpu.h> -+#include <linux/hardirq.h> - - #include <asm/page.h> - #include <asm/current.h> -@@ -335,10 +336,13 @@ void default_machine_kexec(struct kimage *image) - pr_debug("kexec: Starting switchover sequence.\n"); - - /* switch to a staticly allocated stack. Based on irq stack code. -+ * We setup preempt_count to avoid using VMX in memcpy. - * XXX: the task struct will likely be invalid once we do the copy! - */ - kexec_stack.thread_info.task = current_thread_info()->task; - kexec_stack.thread_info.flags = 0; -+ kexec_stack.thread_info.preempt_count = HARDIRQ_OFFSET; -+ kexec_stack.thread_info.cpu = current_thread_info()->cpu; - - /* We need a static PACA, too; copy this CPU's PACA over and switch to - * it. Also poison per_cpu_offset to catch anyone using non-static -diff --git a/arch/powerpc/kernel/rtas.c b/arch/powerpc/kernel/rtas.c -index 1fd6e7b..52add6f 100644 ---- a/arch/powerpc/kernel/rtas.c -+++ b/arch/powerpc/kernel/rtas.c -@@ -19,6 +19,7 @@ - #include <linux/init.h> - #include <linux/capability.h> - #include <linux/delay.h> -+#include <linux/cpu.h> - #include <linux/smp.h> - #include <linux/completion.h> - #include <linux/cpumask.h> -@@ -807,6 +808,95 @@ static void rtas_percpu_suspend_me(void *info) - __rtas_suspend_cpu((struct rtas_suspend_me_data *)info, 1); - } - -+enum rtas_cpu_state { -+ DOWN, -+ UP, -+}; -+ -+#ifndef CONFIG_SMP -+static int rtas_cpu_state_change_mask(enum rtas_cpu_state state, -+ cpumask_var_t cpus) -+{ -+ if (!cpumask_empty(cpus)) { -+ cpumask_clear(cpus); -+ return -EINVAL; -+ } else -+ return 0; -+} -+#else -+/* On return cpumask will be altered to indicate CPUs changed. -+ * CPUs with states changed will be set in the mask, -+ * CPUs with status unchanged will be unset in the mask. */ -+static int rtas_cpu_state_change_mask(enum rtas_cpu_state state, -+ cpumask_var_t cpus) -+{ -+ int cpu; -+ int cpuret = 0; -+ int ret = 0; -+ -+ if (cpumask_empty(cpus)) -+ return 0; -+ -+ for_each_cpu(cpu, cpus) { -+ switch (state) { -+ case DOWN: -+ cpuret = cpu_down(cpu); -+ break; -+ case UP: -+ cpuret = cpu_up(cpu); -+ break; -+ } -+ if (cpuret) { -+ pr_debug("%s: cpu_%s for cpu#%d returned %d.\n", -+ __func__, -+ ((state == UP) ? "up" : "down"), -+ cpu, cpuret); -+ if (!ret) -+ ret = cpuret; -+ if (state == UP) { -+ /* clear bits for unchanged cpus, return */ -+ cpumask_shift_right(cpus, cpus, cpu); -+ cpumask_shift_left(cpus, cpus, cpu); -+ break; -+ } else { -+ /* clear bit for unchanged cpu, continue */ -+ cpumask_clear_cpu(cpu, cpus); -+ } -+ } -+ } -+ -+ return ret; -+} -+#endif -+ -+int rtas_online_cpus_mask(cpumask_var_t cpus) -+{ -+ int ret; -+ -+ ret = rtas_cpu_state_change_mask(UP, cpus); -+ -+ if (ret) { -+ cpumask_var_t tmp_mask; -+ -+ if (!alloc_cpumask_var(&tmp_mask, GFP_TEMPORARY)) -+ return ret; -+ -+ /* Use tmp_mask to preserve cpus mask from first failure */ -+ cpumask_copy(tmp_mask, cpus); -+ rtas_offline_cpus_mask(tmp_mask); -+ free_cpumask_var(tmp_mask); -+ } -+ -+ return ret; -+} -+EXPORT_SYMBOL(rtas_online_cpus_mask); -+ -+int rtas_offline_cpus_mask(cpumask_var_t cpus) -+{ -+ return rtas_cpu_state_change_mask(DOWN, cpus); -+} -+EXPORT_SYMBOL(rtas_offline_cpus_mask); -+ - int rtas_ibm_suspend_me(struct rtas_args *args) - { - long state; -@@ -814,6 +904,8 @@ int rtas_ibm_suspend_me(struct rtas_args *args) - unsigned long retbuf[PLPAR_HCALL_BUFSIZE]; - struct rtas_suspend_me_data data; - DECLARE_COMPLETION_ONSTACK(done); -+ cpumask_var_t offline_mask; -+ int cpuret; - - if (!rtas_service_present("ibm,suspend-me")) - return -ENOSYS; -@@ -837,11 +929,24 @@ int rtas_ibm_suspend_me(struct rtas_args *args) - return 0; - } - -+ if (!alloc_cpumask_var(&offline_mask, GFP_TEMPORARY)) -+ return -ENOMEM; -+ - atomic_set(&data.working, 0); - atomic_set(&data.done, 0); - atomic_set(&data.error, 0); - data.token = rtas_token("ibm,suspend-me"); - data.complete = &done; -+ -+ /* All present CPUs must be online */ -+ cpumask_andnot(offline_mask, cpu_present_mask, cpu_online_mask); -+ cpuret = rtas_online_cpus_mask(offline_mask); -+ if (cpuret) { -+ pr_err("%s: Could not bring present CPUs online.\n", __func__); -+ atomic_set(&data.error, cpuret); -+ goto out; -+ } -+ - stop_topology_update(); - - /* Call function on all CPUs. One of us will make the -@@ -857,6 +962,14 @@ int rtas_ibm_suspend_me(struct rtas_args *args) - - start_topology_update(); - -+ /* Take down CPUs not online prior to suspend */ -+ cpuret = rtas_offline_cpus_mask(offline_mask); -+ if (cpuret) -+ pr_warn("%s: Could not restore CPUs to offline state.\n", -+ __func__); -+ -+out: -+ free_cpumask_var(offline_mask); - return atomic_read(&data.error); - } - #else /* CONFIG_PPC_PSERIES */ -diff --git a/arch/powerpc/platforms/pseries/suspend.c b/arch/powerpc/platforms/pseries/suspend.c -index 47226e0..5f997e7 100644 ---- a/arch/powerpc/platforms/pseries/suspend.c -+++ b/arch/powerpc/platforms/pseries/suspend.c -@@ -16,6 +16,7 @@ - * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA - */ - -+#include <linux/cpu.h> - #include <linux/delay.h> - #include <linux/suspend.h> - #include <linux/stat.h> -@@ -126,11 +127,15 @@ static ssize_t store_hibernate(struct device *dev, - struct device_attribute *attr, - const char *buf, size_t count) - { -+ cpumask_var_t offline_mask; - int rc; - - if (!capable(CAP_SYS_ADMIN)) - return -EPERM; - -+ if (!alloc_cpumask_var(&offline_mask, GFP_TEMPORARY)) -+ return -ENOMEM; -+ - stream_id = simple_strtoul(buf, NULL, 16); - - do { -@@ -140,15 +145,32 @@ static ssize_t store_hibernate(struct device *dev, - } while (rc == -EAGAIN); - - if (!rc) { -+ /* All present CPUs must be online */ -+ cpumask_andnot(offline_mask, cpu_present_mask, -+ cpu_online_mask); -+ rc = rtas_online_cpus_mask(offline_mask); -+ if (rc) { -+ pr_err("%s: Could not bring present CPUs online.\n", -+ __func__); -+ goto out; -+ } -+ - stop_topology_update(); - rc = pm_suspend(PM_SUSPEND_MEM); - start_topology_update(); -+ -+ /* Take down CPUs not online prior to suspend */ -+ if (!rtas_offline_cpus_mask(offline_mask)) -+ pr_warn("%s: Could not restore CPUs to offline " -+ "state.\n", __func__); - } - - stream_id = 0; - - if (!rc) - rc = count; -+out: -+ free_cpumask_var(offline_mask); - return rc; - } - -diff --git a/arch/tile/Kconfig b/arch/tile/Kconfig -index 25877ae..41a2a0b 100644 ---- a/arch/tile/Kconfig -+++ b/arch/tile/Kconfig -@@ -368,11 +368,17 @@ config HARDWALL - config KERNEL_PL - int "Processor protection level for kernel" - range 1 2 -- default "1" -+ default 2 if TILEGX -+ default 1 if !TILEGX - ---help--- -- This setting determines the processor protection level the -- kernel will be built to run at. Generally you should use -- the default value here. -+ Since MDE 4.2, the Tilera hypervisor runs the kernel -+ at PL2 by default. If running under an older hypervisor, -+ or as a KVM guest, you must run at PL1. (The current -+ hypervisor may also be recompiled with "make HV_PL=2" to -+ allow it to run a kernel at PL1, but clients running at PL1 -+ are not expected to be supported indefinitely.) -+ -+ If you're not sure, don't change the default. - - source "arch/tile/gxio/Kconfig" - -diff --git a/arch/tile/include/hv/hypervisor.h b/arch/tile/include/hv/hypervisor.h -index ccd847e..837dca5 100644 ---- a/arch/tile/include/hv/hypervisor.h -+++ b/arch/tile/include/hv/hypervisor.h -@@ -107,7 +107,22 @@ - #define HV_DISPATCH_ENTRY_SIZE 32 - - /** Version of the hypervisor interface defined by this file */ --#define _HV_VERSION 11 -+#define _HV_VERSION 13 -+ -+/** Last version of the hypervisor interface with old hv_init() ABI. -+ * -+ * The change from version 12 to version 13 corresponds to launching -+ * the client by default at PL2 instead of PL1 (corresponding to the -+ * hv itself running at PL3 instead of PL2). To make this explicit, -+ * the hv_init() API was also extended so the client can report its -+ * desired PL, resulting in a more helpful failure diagnostic. If you -+ * call hv_init() with _HV_VERSION_OLD_HV_INIT and omit the client_pl -+ * argument, the hypervisor will assume client_pl = 1. -+ * -+ * Note that this is a deprecated solution and we do not expect to -+ * support clients of the Tilera hypervisor running at PL1 indefinitely. -+ */ -+#define _HV_VERSION_OLD_HV_INIT 12 - - /* Index into hypervisor interface dispatch code blocks. - * -@@ -377,7 +392,11 @@ typedef int HV_Errno; - #ifndef __ASSEMBLER__ - - /** Pass HV_VERSION to hv_init to request this version of the interface. */ --typedef enum { HV_VERSION = _HV_VERSION } HV_VersionNumber; -+typedef enum { -+ HV_VERSION = _HV_VERSION, -+ HV_VERSION_OLD_HV_INIT = _HV_VERSION_OLD_HV_INIT, -+ -+} HV_VersionNumber; - - /** Initializes the hypervisor. - * -@@ -385,9 +404,11 @@ typedef enum { HV_VERSION = _HV_VERSION } HV_VersionNumber; - * that this program expects, typically HV_VERSION. - * @param chip_num Architecture number of the chip the client was built for. - * @param chip_rev_num Revision number of the chip the client was built for. -+ * @param client_pl Privilege level the client is built for -+ * (not required if interface_version_number == HV_VERSION_OLD_HV_INIT). - */ - void hv_init(HV_VersionNumber interface_version_number, -- int chip_num, int chip_rev_num); -+ int chip_num, int chip_rev_num, int client_pl); - - - /** Queries we can make for hv_sysconf(). -diff --git a/arch/tile/kernel/head_32.S b/arch/tile/kernel/head_32.S -index f71bfee..ac11530 100644 ---- a/arch/tile/kernel/head_32.S -+++ b/arch/tile/kernel/head_32.S -@@ -38,7 +38,7 @@ ENTRY(_start) - movei r2, TILE_CHIP_REV - } - { -- moveli r0, _HV_VERSION -+ moveli r0, _HV_VERSION_OLD_HV_INIT - jal hv_init - } - /* Get a reasonable default ASID in r0 */ -diff --git a/arch/tile/kernel/head_64.S b/arch/tile/kernel/head_64.S -index f9a2734..6093964 100644 ---- a/arch/tile/kernel/head_64.S -+++ b/arch/tile/kernel/head_64.S -@@ -34,13 +34,19 @@ - ENTRY(_start) - /* Notify the hypervisor of what version of the API we want */ - { -+#if KERNEL_PL == 1 && _HV_VERSION == 13 -+ /* Support older hypervisors by asking for API version 12. */ -+ movei r0, _HV_VERSION_OLD_HV_INIT -+#else -+ movei r0, _HV_VERSION -+#endif - movei r1, TILE_CHIP -- movei r2, TILE_CHIP_REV - } - { -- moveli r0, _HV_VERSION -- jal hv_init -+ movei r2, TILE_CHIP_REV -+ movei r3, KERNEL_PL - } -+ jal hv_init - /* Get a reasonable default ASID in r0 */ - { - move r0, zero -diff --git a/arch/x86/Kconfig b/arch/x86/Kconfig -index 15b5cef..6ef2a37 100644 ---- a/arch/x86/Kconfig -+++ b/arch/x86/Kconfig -@@ -107,7 +107,6 @@ config X86 - select GENERIC_CLOCKEVENTS_BROADCAST if X86_64 || (X86_32 && X86_LOCAL_APIC) - select GENERIC_TIME_VSYSCALL if X86_64 - select KTIME_SCALAR if X86_32 -- select ALWAYS_USE_PERSISTENT_CLOCK - select GENERIC_STRNCPY_FROM_USER - select GENERIC_STRNLEN_USER - select HAVE_CONTEXT_TRACKING if X86_64 -diff --git a/arch/x86/kernel/microcode_intel_early.c b/arch/x86/kernel/microcode_intel_early.c -index d893e8e..2e9e128 100644 ---- a/arch/x86/kernel/microcode_intel_early.c -+++ b/arch/x86/kernel/microcode_intel_early.c -@@ -487,6 +487,7 @@ static inline void show_saved_mc(void) - #endif - - #if defined(CONFIG_MICROCODE_INTEL_EARLY) && defined(CONFIG_HOTPLUG_CPU) -+static DEFINE_MUTEX(x86_cpu_microcode_mutex); - /* - * Save this mc into mc_saved_data. So it will be loaded early when a CPU is - * hot added or resumes. -@@ -507,7 +508,7 @@ int save_mc_for_early(u8 *mc) - * Hold hotplug lock so mc_saved_data is not accessed by a CPU in - * hotplug. - */ -- cpu_hotplug_driver_lock(); -+ mutex_lock(&x86_cpu_microcode_mutex); - - mc_saved_count_init = mc_saved_data.mc_saved_count; - mc_saved_count = mc_saved_data.mc_saved_count; -@@ -544,7 +545,7 @@ int save_mc_for_early(u8 *mc) - } - - out: -- cpu_hotplug_driver_unlock(); -+ mutex_unlock(&x86_cpu_microcode_mutex); - - return ret; - } -diff --git a/arch/x86/kvm/emulate.c b/arch/x86/kvm/emulate.c -index a9c9d3e..59622c9 100644 ---- a/arch/x86/kvm/emulate.c -+++ b/arch/x86/kvm/emulate.c -@@ -60,6 +60,7 @@ - #define OpGS 25ull /* GS */ - #define OpMem8 26ull /* 8-bit zero extended memory operand */ - #define OpImm64 27ull /* Sign extended 16/32/64-bit immediate */ -+#define OpXLat 28ull /* memory at BX/EBX/RBX + zero-extended AL */ - - #define OpBits 5 /* Width of operand field */ - #define OpMask ((1ull << OpBits) - 1) -@@ -99,6 +100,7 @@ - #define SrcImmUByte (OpImmUByte << SrcShift) - #define SrcImmU (OpImmU << SrcShift) - #define SrcSI (OpSI << SrcShift) -+#define SrcXLat (OpXLat << SrcShift) - #define SrcImmFAddr (OpImmFAddr << SrcShift) - #define SrcMemFAddr (OpMemFAddr << SrcShift) - #define SrcAcc (OpAcc << SrcShift) -@@ -532,6 +534,9 @@ FOP_SETCC(setle) - FOP_SETCC(setnle) - FOP_END; - -+FOP_START(salc) "pushf; sbb %al, %al; popf \n\t" FOP_RET -+FOP_END; -+ - #define __emulate_1op_rax_rdx(ctxt, _op, _suffix, _ex) \ - do { \ - unsigned long _tmp; \ -@@ -2986,6 +2991,28 @@ static int em_das(struct x86_emulate_ctxt *ctxt) - return X86EMUL_CONTINUE; - } - -+static int em_aam(struct x86_emulate_ctxt *ctxt) -+{ -+ u8 al, ah; -+ -+ if (ctxt->src.val == 0) -+ return emulate_de(ctxt); -+ -+ al = ctxt->dst.val & 0xff; -+ ah = al / ctxt->src.val; -+ al %= ctxt->src.val; -+ -+ ctxt->dst.val = (ctxt->dst.val & 0xffff0000) | al | (ah << 8); -+ -+ /* Set PF, ZF, SF */ -+ ctxt->src.type = OP_IMM; -+ ctxt->src.val = 0; -+ ctxt->src.bytes = 1; -+ fastop(ctxt, em_or); -+ -+ return X86EMUL_CONTINUE; -+} -+ - static int em_aad(struct x86_emulate_ctxt *ctxt) - { - u8 al = ctxt->dst.val & 0xff; -@@ -3926,7 +3953,10 @@ static const struct opcode opcode_table[256] = { - /* 0xD0 - 0xD7 */ - G(Src2One | ByteOp, group2), G(Src2One, group2), - G(Src2CL | ByteOp, group2), G(Src2CL, group2), -- N, I(DstAcc | SrcImmByte | No64, em_aad), N, N, -+ I(DstAcc | SrcImmUByte | No64, em_aam), -+ I(DstAcc | SrcImmUByte | No64, em_aad), -+ F(DstAcc | ByteOp | No64, em_salc), -+ I(DstAcc | SrcXLat | ByteOp, em_mov), - /* 0xD8 - 0xDF */ - N, E(0, &escape_d9), N, E(0, &escape_db), N, E(0, &escape_dd), N, N, - /* 0xE0 - 0xE7 */ -@@ -4188,6 +4218,16 @@ static int decode_operand(struct x86_emulate_ctxt *ctxt, struct operand *op, - op->val = 0; - op->count = 1; - break; -+ case OpXLat: -+ op->type = OP_MEM; -+ op->bytes = (ctxt->d & ByteOp) ? 1 : ctxt->op_bytes; -+ op->addr.mem.ea = -+ register_address(ctxt, -+ reg_read(ctxt, VCPU_REGS_RBX) + -+ (reg_read(ctxt, VCPU_REGS_RAX) & 0xff)); -+ op->addr.mem.seg = seg_override(ctxt); -+ op->val = 0; -+ break; - case OpImmFAddr: - op->type = OP_IMM; - op->addr.mem.ea = ctxt->_eip; -diff --git a/arch/x86/kvm/vmx.c b/arch/x86/kvm/vmx.c -index 6667042..0af1807 100644 ---- a/arch/x86/kvm/vmx.c -+++ b/arch/x86/kvm/vmx.c -@@ -5197,6 +5197,12 @@ static int handle_invalid_guest_state(struct kvm_vcpu *vcpu) - return 0; - } - -+ if (vcpu->arch.halt_request) { -+ vcpu->arch.halt_request = 0; -+ ret = kvm_emulate_halt(vcpu); -+ goto out; -+ } -+ - if (signal_pending(current)) - goto out; - if (need_resched()) -diff --git a/arch/x86/xen/enlighten.c b/arch/x86/xen/enlighten.c -index 2363127..cf95e19 100644 ---- a/arch/x86/xen/enlighten.c -+++ b/arch/x86/xen/enlighten.c -@@ -156,6 +156,21 @@ static void xen_vcpu_setup(int cpu) - - BUG_ON(HYPERVISOR_shared_info == &xen_dummy_shared_info); - -+ /* -+ * This path is called twice on PVHVM - first during bootup via -+ * smp_init -> xen_hvm_cpu_notify, and then if the VCPU is being -+ * hotplugged: cpu_up -> xen_hvm_cpu_notify. -+ * As we can only do the VCPUOP_register_vcpu_info once lets -+ * not over-write its result. -+ * -+ * For PV it is called during restore (xen_vcpu_restore) and bootup -+ * (xen_setup_vcpu_info_placement). The hotplug mechanism does not -+ * use this function. -+ */ -+ if (xen_hvm_domain()) { -+ if (per_cpu(xen_vcpu, cpu) == &per_cpu(xen_vcpu_info, cpu)) -+ return; -+ } - if (cpu < MAX_VIRT_CPUS) - per_cpu(xen_vcpu,cpu) = &HYPERVISOR_shared_info->vcpu_info[cpu]; - -diff --git a/drivers/acpi/acpica/exfldio.c b/drivers/acpi/acpica/exfldio.c -index ec7f569..c84ee95 100644 ---- a/drivers/acpi/acpica/exfldio.c -+++ b/drivers/acpi/acpica/exfldio.c -@@ -720,7 +720,19 @@ acpi_ex_extract_from_field(union acpi_operand_object *obj_desc, - - if ((obj_desc->common_field.start_field_bit_offset == 0) && - (obj_desc->common_field.bit_length == access_bit_width)) { -- status = acpi_ex_field_datum_io(obj_desc, 0, buffer, ACPI_READ); -+ if (buffer_length >= sizeof(u64)) { -+ status = -+ acpi_ex_field_datum_io(obj_desc, 0, buffer, -+ ACPI_READ); -+ } else { -+ /* Use raw_datum (u64) to handle buffers < 64 bits */ -+ -+ status = -+ acpi_ex_field_datum_io(obj_desc, 0, &raw_datum, -+ ACPI_READ); -+ ACPI_MEMCPY(buffer, &raw_datum, buffer_length); -+ } -+ - return_ACPI_STATUS(status); - } - -diff --git a/drivers/acpi/ec.c b/drivers/acpi/ec.c -index d45b287..edc0081 100644 ---- a/drivers/acpi/ec.c -+++ b/drivers/acpi/ec.c -@@ -223,7 +223,7 @@ static int ec_check_sci_sync(struct acpi_ec *ec, u8 state) - static int ec_poll(struct acpi_ec *ec) - { - unsigned long flags; -- int repeat = 2; /* number of command restarts */ -+ int repeat = 5; /* number of command restarts */ - while (repeat--) { - unsigned long delay = jiffies + - msecs_to_jiffies(ec_delay); -@@ -241,8 +241,6 @@ static int ec_poll(struct acpi_ec *ec) - } - advance_transaction(ec, acpi_ec_read_status(ec)); - } while (time_before(jiffies, delay)); -- if (acpi_ec_read_status(ec) & ACPI_EC_FLAG_IBF) -- break; - pr_debug(PREFIX "controller reset, restart transaction\n"); - spin_lock_irqsave(&ec->lock, flags); - start_transaction(ec); -diff --git a/drivers/block/drbd/drbd_main.c b/drivers/block/drbd/drbd_main.c -index e98da67..54d03d4 100644 ---- a/drivers/block/drbd/drbd_main.c -+++ b/drivers/block/drbd/drbd_main.c -@@ -2795,6 +2795,7 @@ void drbd_free_bc(struct drbd_backing_dev *ldev) - blkdev_put(ldev->backing_bdev, FMODE_READ | FMODE_WRITE | FMODE_EXCL); - blkdev_put(ldev->md_bdev, FMODE_READ | FMODE_WRITE | FMODE_EXCL); - -+ kfree(ldev->disk_conf); - kfree(ldev); - } - -diff --git a/drivers/block/drbd/drbd_receiver.c b/drivers/block/drbd/drbd_receiver.c -index a9eccfc..2f5fffd 100644 ---- a/drivers/block/drbd/drbd_receiver.c -+++ b/drivers/block/drbd/drbd_receiver.c -@@ -2661,7 +2661,6 @@ static int drbd_asb_recover_1p(struct drbd_conf *mdev) __must_hold(local) - if (hg == -1 && mdev->state.role == R_PRIMARY) { - enum drbd_state_rv rv2; - -- drbd_set_role(mdev, R_SECONDARY, 0); - /* drbd_change_state() does not sleep while in SS_IN_TRANSIENT_STATE, - * we might be here in C_WF_REPORT_PARAMS which is transient. - * we do not need to wait for the after state change work either. */ -@@ -4659,8 +4658,8 @@ static int drbd_do_features(struct drbd_tconn *tconn) - #if !defined(CONFIG_CRYPTO_HMAC) && !defined(CONFIG_CRYPTO_HMAC_MODULE) - static int drbd_do_auth(struct drbd_tconn *tconn) - { -- dev_err(DEV, "This kernel was build without CONFIG_CRYPTO_HMAC.\n"); -- dev_err(DEV, "You need to disable 'cram-hmac-alg' in drbd.conf.\n"); -+ conn_err(tconn, "This kernel was build without CONFIG_CRYPTO_HMAC.\n"); -+ conn_err(tconn, "You need to disable 'cram-hmac-alg' in drbd.conf.\n"); - return -1; - } - #else -diff --git a/drivers/char/ipmi/ipmi_bt_sm.c b/drivers/char/ipmi/ipmi_bt_sm.c -index cdd4c09f..a22a7a5 100644 ---- a/drivers/char/ipmi/ipmi_bt_sm.c -+++ b/drivers/char/ipmi/ipmi_bt_sm.c -@@ -95,9 +95,9 @@ struct si_sm_data { - enum bt_states state; - unsigned char seq; /* BT sequence number */ - struct si_sm_io *io; -- unsigned char write_data[IPMI_MAX_MSG_LENGTH]; -+ unsigned char write_data[IPMI_MAX_MSG_LENGTH + 2]; /* +2 for memcpy */ - int write_count; -- unsigned char read_data[IPMI_MAX_MSG_LENGTH]; -+ unsigned char read_data[IPMI_MAX_MSG_LENGTH + 2]; /* +2 for memcpy */ - int read_count; - int truncated; - long timeout; /* microseconds countdown */ -diff --git a/drivers/char/ipmi/ipmi_devintf.c b/drivers/char/ipmi/ipmi_devintf.c -index 9eb360f..d5a5f02 100644 ---- a/drivers/char/ipmi/ipmi_devintf.c -+++ b/drivers/char/ipmi/ipmi_devintf.c -@@ -837,13 +837,25 @@ static long compat_ipmi_ioctl(struct file *filep, unsigned int cmd, - return ipmi_ioctl(filep, cmd, arg); - } - } -+ -+static long unlocked_compat_ipmi_ioctl(struct file *filep, unsigned int cmd, -+ unsigned long arg) -+{ -+ int ret; -+ -+ mutex_lock(&ipmi_mutex); -+ ret = compat_ipmi_ioctl(filep, cmd, arg); -+ mutex_unlock(&ipmi_mutex); -+ -+ return ret; -+} - #endif - - static const struct file_operations ipmi_fops = { - .owner = THIS_MODULE, - .unlocked_ioctl = ipmi_unlocked_ioctl, - #ifdef CONFIG_COMPAT -- .compat_ioctl = compat_ipmi_ioctl, -+ .compat_ioctl = unlocked_compat_ipmi_ioctl, - #endif - .open = ipmi_open, - .release = ipmi_release, -diff --git a/drivers/cpufreq/intel_pstate.c b/drivers/cpufreq/intel_pstate.c -index 6133ef5..d8a8c9b 100644 ---- a/drivers/cpufreq/intel_pstate.c -+++ b/drivers/cpufreq/intel_pstate.c -@@ -48,12 +48,7 @@ static inline int32_t div_fp(int32_t x, int32_t y) - } - - struct sample { -- ktime_t start_time; -- ktime_t end_time; - int core_pct_busy; -- int pstate_pct_busy; -- u64 duration_us; -- u64 idletime_us; - u64 aperf; - u64 mperf; - int freq; -@@ -91,8 +86,6 @@ struct cpudata { - int min_pstate_count; - int idle_mode; - -- ktime_t prev_sample; -- u64 prev_idle_time_us; - u64 prev_aperf; - u64 prev_mperf; - int sample_ptr; -@@ -124,6 +117,8 @@ struct perf_limits { - int min_perf_pct; - int32_t max_perf; - int32_t min_perf; -+ int max_policy_pct; -+ int max_sysfs_pct; - }; - - static struct perf_limits limits = { -@@ -132,6 +127,8 @@ static struct perf_limits limits = { - .max_perf = int_tofp(1), - .min_perf_pct = 0, - .min_perf = 0, -+ .max_policy_pct = 100, -+ .max_sysfs_pct = 100, - }; - - static inline void pid_reset(struct _pid *pid, int setpoint, int busy, -@@ -302,7 +299,8 @@ static ssize_t store_max_perf_pct(struct kobject *a, struct attribute *b, - if (ret != 1) - return -EINVAL; - -- limits.max_perf_pct = clamp_t(int, input, 0 , 100); -+ limits.max_sysfs_pct = clamp_t(int, input, 0 , 100); -+ limits.max_perf_pct = min(limits.max_policy_pct, limits.max_sysfs_pct); - limits.max_perf = div_fp(int_tofp(limits.max_perf_pct), int_tofp(100)); - return count; - } -@@ -450,48 +448,26 @@ static inline void intel_pstate_calc_busy(struct cpudata *cpu, - struct sample *sample) - { - u64 core_pct; -- sample->pstate_pct_busy = 100 - div64_u64( -- sample->idletime_us * 100, -- sample->duration_us); - core_pct = div64_u64(sample->aperf * 100, sample->mperf); - sample->freq = cpu->pstate.max_pstate * core_pct * 1000; - -- sample->core_pct_busy = div_s64((sample->pstate_pct_busy * core_pct), -- 100); -+ sample->core_pct_busy = core_pct; - } - - static inline void intel_pstate_sample(struct cpudata *cpu) - { -- ktime_t now; -- u64 idle_time_us; - u64 aperf, mperf; - -- now = ktime_get(); -- idle_time_us = get_cpu_idle_time_us(cpu->cpu, NULL); -- - rdmsrl(MSR_IA32_APERF, aperf); - rdmsrl(MSR_IA32_MPERF, mperf); -- /* for the first sample, don't actually record a sample, just -- * set the baseline */ -- if (cpu->prev_idle_time_us > 0) { -- cpu->sample_ptr = (cpu->sample_ptr + 1) % SAMPLE_COUNT; -- cpu->samples[cpu->sample_ptr].start_time = cpu->prev_sample; -- cpu->samples[cpu->sample_ptr].end_time = now; -- cpu->samples[cpu->sample_ptr].duration_us = -- ktime_us_delta(now, cpu->prev_sample); -- cpu->samples[cpu->sample_ptr].idletime_us = -- idle_time_us - cpu->prev_idle_time_us; -- -- cpu->samples[cpu->sample_ptr].aperf = aperf; -- cpu->samples[cpu->sample_ptr].mperf = mperf; -- cpu->samples[cpu->sample_ptr].aperf -= cpu->prev_aperf; -- cpu->samples[cpu->sample_ptr].mperf -= cpu->prev_mperf; -- -- intel_pstate_calc_busy(cpu, &cpu->samples[cpu->sample_ptr]); -- } -+ cpu->sample_ptr = (cpu->sample_ptr + 1) % SAMPLE_COUNT; -+ cpu->samples[cpu->sample_ptr].aperf = aperf; -+ cpu->samples[cpu->sample_ptr].mperf = mperf; -+ cpu->samples[cpu->sample_ptr].aperf -= cpu->prev_aperf; -+ cpu->samples[cpu->sample_ptr].mperf -= cpu->prev_mperf; -+ -+ intel_pstate_calc_busy(cpu, &cpu->samples[cpu->sample_ptr]); - -- cpu->prev_sample = now; -- cpu->prev_idle_time_us = idle_time_us; - cpu->prev_aperf = aperf; - cpu->prev_mperf = mperf; - } -@@ -575,22 +551,16 @@ static void intel_pstate_timer_func(unsigned long __data) - struct cpudata *cpu = (struct cpudata *) __data; - - intel_pstate_sample(cpu); -+ intel_pstate_adjust_busy_pstate(cpu); - -- if (!cpu->idle_mode) -- intel_pstate_adjust_busy_pstate(cpu); -- else -- intel_pstate_adjust_idle_pstate(cpu); -- --#if defined(XPERF_FIX) - if (cpu->pstate.current_pstate == cpu->pstate.min_pstate) { - cpu->min_pstate_count++; - if (!(cpu->min_pstate_count % 5)) { - intel_pstate_set_pstate(cpu, cpu->pstate.max_pstate); -- intel_pstate_idle_mode(cpu); - } - } else - cpu->min_pstate_count = 0; --#endif -+ - intel_pstate_set_sample_time(cpu); - } - -@@ -670,8 +640,9 @@ static int intel_pstate_set_policy(struct cpufreq_policy *policy) - limits.min_perf_pct = clamp_t(int, limits.min_perf_pct, 0 , 100); - limits.min_perf = div_fp(int_tofp(limits.min_perf_pct), int_tofp(100)); - -- limits.max_perf_pct = policy->max * 100 / policy->cpuinfo.max_freq; -- limits.max_perf_pct = clamp_t(int, limits.max_perf_pct, 0 , 100); -+ limits.max_policy_pct = policy->max * 100 / policy->cpuinfo.max_freq; -+ limits.max_policy_pct = clamp_t(int, limits.max_policy_pct, 0 , 100); -+ limits.max_perf_pct = min(limits.max_policy_pct, limits.max_sysfs_pct); - limits.max_perf = div_fp(int_tofp(limits.max_perf_pct), int_tofp(100)); - - if (policy->policy == CPUFREQ_POLICY_PERFORMANCE) { -diff --git a/drivers/dma/of-dma.c b/drivers/dma/of-dma.c -index 69d04d2..09c7ad1 100644 ---- a/drivers/dma/of-dma.c -+++ b/drivers/dma/of-dma.c -@@ -93,6 +93,7 @@ int of_dma_controller_register(struct device_node *np, - { - struct of_dma *ofdma; - int nbcells; -+ const __be32 *prop; - - if (!np || !of_dma_xlate) { - pr_err("%s: not enough information provided\n", __func__); -@@ -103,8 +104,11 @@ int of_dma_controller_register(struct device_node *np, - if (!ofdma) - return -ENOMEM; - -- nbcells = be32_to_cpup(of_get_property(np, "#dma-cells", NULL)); -- if (!nbcells) { -+ prop = of_get_property(np, "#dma-cells", NULL); -+ if (prop) -+ nbcells = be32_to_cpup(prop); -+ -+ if (!prop || !nbcells) { - pr_err("%s: #dma-cells property is missing or invalid\n", - __func__); - kfree(ofdma); -diff --git a/drivers/dma/pch_dma.c b/drivers/dma/pch_dma.c -index d01faeb..ce3dc3e 100644 ---- a/drivers/dma/pch_dma.c -+++ b/drivers/dma/pch_dma.c -@@ -476,7 +476,7 @@ static struct pch_dma_desc *pdc_desc_get(struct pch_dma_chan *pd_chan) - dev_dbg(chan2dev(&pd_chan->chan), "scanned %d descriptors\n", i); - - if (!ret) { -- ret = pdc_alloc_desc(&pd_chan->chan, GFP_NOIO); -+ ret = pdc_alloc_desc(&pd_chan->chan, GFP_ATOMIC); - if (ret) { - spin_lock(&pd_chan->lock); - pd_chan->descs_allocated++; -diff --git a/drivers/gpu/drm/drm_crtc.c b/drivers/gpu/drm/drm_crtc.c -index dd64a06..016c5d8 100644 ---- a/drivers/gpu/drm/drm_crtc.c -+++ b/drivers/gpu/drm/drm_crtc.c -@@ -78,6 +78,10 @@ void drm_warn_on_modeset_not_all_locked(struct drm_device *dev) - { - struct drm_crtc *crtc; - -+ /* Locking is currently fubar in the panic handler. */ -+ if (oops_in_progress) -+ return; -+ - list_for_each_entry(crtc, &dev->mode_config.crtc_list, head) - WARN_ON(!mutex_is_locked(&crtc->mutex)); - -diff --git a/drivers/gpu/drm/drm_mm.c b/drivers/gpu/drm/drm_mm.c -index db1e2d6..07cf99c 100644 ---- a/drivers/gpu/drm/drm_mm.c -+++ b/drivers/gpu/drm/drm_mm.c -@@ -755,33 +755,35 @@ void drm_mm_debug_table(struct drm_mm *mm, const char *prefix) - EXPORT_SYMBOL(drm_mm_debug_table); - - #if defined(CONFIG_DEBUG_FS) --int drm_mm_dump_table(struct seq_file *m, struct drm_mm *mm) -+static unsigned long drm_mm_dump_hole(struct seq_file *m, struct drm_mm_node *entry) - { -- struct drm_mm_node *entry; -- unsigned long total_used = 0, total_free = 0, total = 0; - unsigned long hole_start, hole_end, hole_size; - -- hole_start = drm_mm_hole_node_start(&mm->head_node); -- hole_end = drm_mm_hole_node_end(&mm->head_node); -- hole_size = hole_end - hole_start; -- if (hole_size) -+ if (entry->hole_follows) { -+ hole_start = drm_mm_hole_node_start(entry); -+ hole_end = drm_mm_hole_node_end(entry); -+ hole_size = hole_end - hole_start; - seq_printf(m, "0x%08lx-0x%08lx: 0x%08lx: free\n", - hole_start, hole_end, hole_size); -- total_free += hole_size; -+ return hole_size; -+ } -+ -+ return 0; -+} -+ -+int drm_mm_dump_table(struct seq_file *m, struct drm_mm *mm) -+{ -+ struct drm_mm_node *entry; -+ unsigned long total_used = 0, total_free = 0, total = 0; -+ -+ total_free += drm_mm_dump_hole(m, &mm->head_node); - - drm_mm_for_each_node(entry, mm) { - seq_printf(m, "0x%08lx-0x%08lx: 0x%08lx: used\n", - entry->start, entry->start + entry->size, - entry->size); - total_used += entry->size; -- if (entry->hole_follows) { -- hole_start = drm_mm_hole_node_start(entry); -- hole_end = drm_mm_hole_node_end(entry); -- hole_size = hole_end - hole_start; -- seq_printf(m, "0x%08lx-0x%08lx: 0x%08lx: free\n", -- hole_start, hole_end, hole_size); -- total_free += hole_size; -- } -+ total_free += drm_mm_dump_hole(m, entry); - } - total = total_free + total_used; - -diff --git a/drivers/gpu/drm/i915/intel_fb.c b/drivers/gpu/drm/i915/intel_fb.c -index 981bdce..898832b 100644 ---- a/drivers/gpu/drm/i915/intel_fb.c -+++ b/drivers/gpu/drm/i915/intel_fb.c -@@ -261,10 +261,22 @@ void intel_fbdev_fini(struct drm_device *dev) - void intel_fbdev_set_suspend(struct drm_device *dev, int state) - { - drm_i915_private_t *dev_priv = dev->dev_private; -- if (!dev_priv->fbdev) -+ struct intel_fbdev *ifbdev = dev_priv->fbdev; -+ struct fb_info *info; -+ -+ if (!ifbdev) - return; - -- fb_set_suspend(dev_priv->fbdev->helper.fbdev, state); -+ info = ifbdev->helper.fbdev; -+ -+ /* On resume from hibernation: If the object is shmemfs backed, it has -+ * been restored from swap. If the object is stolen however, it will be -+ * full of whatever garbage was left in there. -+ */ -+ if (!state && ifbdev->ifb.obj->stolen) -+ memset_io(info->screen_base, 0, info->screen_size); -+ -+ fb_set_suspend(info, state); - } - - MODULE_LICENSE("GPL and additional rights"); -diff --git a/drivers/gpu/drm/mgag200/mgag200_mode.c b/drivers/gpu/drm/mgag200/mgag200_mode.c -index 78d8e919..713dd70 100644 ---- a/drivers/gpu/drm/mgag200/mgag200_mode.c -+++ b/drivers/gpu/drm/mgag200/mgag200_mode.c -@@ -189,12 +189,12 @@ static int mga_g200wb_set_plls(struct mga_device *mdev, long clock) - WREG8(DAC_INDEX, MGA1064_PIX_CLK_CTL); - tmp = RREG8(DAC_DATA); - tmp |= MGA1064_PIX_CLK_CTL_CLK_DIS; -- WREG_DAC(MGA1064_PIX_CLK_CTL_CLK_DIS, tmp); -+ WREG8(DAC_DATA, tmp); - - WREG8(DAC_INDEX, MGA1064_REMHEADCTL); - tmp = RREG8(DAC_DATA); - tmp |= MGA1064_REMHEADCTL_CLKDIS; -- WREG_DAC(MGA1064_REMHEADCTL, tmp); -+ WREG8(DAC_DATA, tmp); - - /* select PLL Set C */ - tmp = RREG8(MGAREG_MEM_MISC_READ); -@@ -204,7 +204,7 @@ static int mga_g200wb_set_plls(struct mga_device *mdev, long clock) - WREG8(DAC_INDEX, MGA1064_PIX_CLK_CTL); - tmp = RREG8(DAC_DATA); - tmp |= MGA1064_PIX_CLK_CTL_CLK_POW_DOWN | 0x80; -- WREG_DAC(MGA1064_PIX_CLK_CTL, tmp); -+ WREG8(DAC_DATA, tmp); - - udelay(500); - -@@ -212,7 +212,7 @@ static int mga_g200wb_set_plls(struct mga_device *mdev, long clock) - WREG8(DAC_INDEX, MGA1064_VREF_CTL); - tmp = RREG8(DAC_DATA); - tmp &= ~0x04; -- WREG_DAC(MGA1064_VREF_CTL, tmp); -+ WREG8(DAC_DATA, tmp); - - udelay(50); - -@@ -236,13 +236,13 @@ static int mga_g200wb_set_plls(struct mga_device *mdev, long clock) - tmp = RREG8(DAC_DATA); - tmp &= ~MGA1064_PIX_CLK_CTL_SEL_MSK; - tmp |= MGA1064_PIX_CLK_CTL_SEL_PLL; -- WREG_DAC(MGA1064_PIX_CLK_CTL, tmp); -+ WREG8(DAC_DATA, tmp); - - WREG8(DAC_INDEX, MGA1064_REMHEADCTL); - tmp = RREG8(DAC_DATA); - tmp &= ~MGA1064_REMHEADCTL_CLKSL_MSK; - tmp |= MGA1064_REMHEADCTL_CLKSL_PLL; -- WREG_DAC(MGA1064_REMHEADCTL, tmp); -+ WREG8(DAC_DATA, tmp); - - /* reset dotclock rate bit */ - WREG8(MGAREG_SEQ_INDEX, 1); -@@ -253,7 +253,7 @@ static int mga_g200wb_set_plls(struct mga_device *mdev, long clock) - WREG8(DAC_INDEX, MGA1064_PIX_CLK_CTL); - tmp = RREG8(DAC_DATA); - tmp &= ~MGA1064_PIX_CLK_CTL_CLK_DIS; -- WREG_DAC(MGA1064_PIX_CLK_CTL, tmp); -+ WREG8(DAC_DATA, tmp); - - vcount = RREG8(MGAREG_VCOUNT); - -@@ -318,7 +318,7 @@ static int mga_g200ev_set_plls(struct mga_device *mdev, long clock) - WREG8(DAC_INDEX, MGA1064_PIX_CLK_CTL); - tmp = RREG8(DAC_DATA); - tmp |= MGA1064_PIX_CLK_CTL_CLK_DIS; -- WREG_DAC(MGA1064_PIX_CLK_CTL_CLK_DIS, tmp); -+ WREG8(DAC_DATA, tmp); - - tmp = RREG8(MGAREG_MEM_MISC_READ); - tmp |= 0x3 << 2; -@@ -326,12 +326,12 @@ static int mga_g200ev_set_plls(struct mga_device *mdev, long clock) - - WREG8(DAC_INDEX, MGA1064_PIX_PLL_STAT); - tmp = RREG8(DAC_DATA); -- WREG_DAC(MGA1064_PIX_PLL_STAT, tmp & ~0x40); -+ WREG8(DAC_DATA, tmp & ~0x40); - - WREG8(DAC_INDEX, MGA1064_PIX_CLK_CTL); - tmp = RREG8(DAC_DATA); - tmp |= MGA1064_PIX_CLK_CTL_CLK_POW_DOWN; -- WREG_DAC(MGA1064_PIX_CLK_CTL, tmp); -+ WREG8(DAC_DATA, tmp); - - WREG_DAC(MGA1064_EV_PIX_PLLC_M, m); - WREG_DAC(MGA1064_EV_PIX_PLLC_N, n); -@@ -342,7 +342,7 @@ static int mga_g200ev_set_plls(struct mga_device *mdev, long clock) - WREG8(DAC_INDEX, MGA1064_PIX_CLK_CTL); - tmp = RREG8(DAC_DATA); - tmp &= ~MGA1064_PIX_CLK_CTL_CLK_POW_DOWN; -- WREG_DAC(MGA1064_PIX_CLK_CTL, tmp); -+ WREG8(DAC_DATA, tmp); - - udelay(500); - -@@ -350,11 +350,11 @@ static int mga_g200ev_set_plls(struct mga_device *mdev, long clock) - tmp = RREG8(DAC_DATA); - tmp &= ~MGA1064_PIX_CLK_CTL_SEL_MSK; - tmp |= MGA1064_PIX_CLK_CTL_SEL_PLL; -- WREG_DAC(MGA1064_PIX_CLK_CTL, tmp); -+ WREG8(DAC_DATA, tmp); - - WREG8(DAC_INDEX, MGA1064_PIX_PLL_STAT); - tmp = RREG8(DAC_DATA); -- WREG_DAC(MGA1064_PIX_PLL_STAT, tmp | 0x40); -+ WREG8(DAC_DATA, tmp | 0x40); - - tmp = RREG8(MGAREG_MEM_MISC_READ); - tmp |= (0x3 << 2); -@@ -363,7 +363,7 @@ static int mga_g200ev_set_plls(struct mga_device *mdev, long clock) - WREG8(DAC_INDEX, MGA1064_PIX_CLK_CTL); - tmp = RREG8(DAC_DATA); - tmp &= ~MGA1064_PIX_CLK_CTL_CLK_DIS; -- WREG_DAC(MGA1064_PIX_CLK_CTL, tmp); -+ WREG8(DAC_DATA, tmp); - - return 0; - } -@@ -416,7 +416,7 @@ static int mga_g200eh_set_plls(struct mga_device *mdev, long clock) - WREG8(DAC_INDEX, MGA1064_PIX_CLK_CTL); - tmp = RREG8(DAC_DATA); - tmp |= MGA1064_PIX_CLK_CTL_CLK_DIS; -- WREG_DAC(MGA1064_PIX_CLK_CTL_CLK_DIS, tmp); -+ WREG8(DAC_DATA, tmp); - - tmp = RREG8(MGAREG_MEM_MISC_READ); - tmp |= 0x3 << 2; -@@ -425,7 +425,7 @@ static int mga_g200eh_set_plls(struct mga_device *mdev, long clock) - WREG8(DAC_INDEX, MGA1064_PIX_CLK_CTL); - tmp = RREG8(DAC_DATA); - tmp |= MGA1064_PIX_CLK_CTL_CLK_POW_DOWN; -- WREG_DAC(MGA1064_PIX_CLK_CTL, tmp); -+ WREG8(DAC_DATA, tmp); - - udelay(500); - -@@ -439,13 +439,13 @@ static int mga_g200eh_set_plls(struct mga_device *mdev, long clock) - tmp = RREG8(DAC_DATA); - tmp &= ~MGA1064_PIX_CLK_CTL_SEL_MSK; - tmp |= MGA1064_PIX_CLK_CTL_SEL_PLL; -- WREG_DAC(MGA1064_PIX_CLK_CTL, tmp); -+ WREG8(DAC_DATA, tmp); - - WREG8(DAC_INDEX, MGA1064_PIX_CLK_CTL); - tmp = RREG8(DAC_DATA); - tmp &= ~MGA1064_PIX_CLK_CTL_CLK_DIS; - tmp &= ~MGA1064_PIX_CLK_CTL_CLK_POW_DOWN; -- WREG_DAC(MGA1064_PIX_CLK_CTL, tmp); -+ WREG8(DAC_DATA, tmp); - - vcount = RREG8(MGAREG_VCOUNT); - -@@ -515,12 +515,12 @@ static int mga_g200er_set_plls(struct mga_device *mdev, long clock) - WREG8(DAC_INDEX, MGA1064_PIX_CLK_CTL); - tmp = RREG8(DAC_DATA); - tmp |= MGA1064_PIX_CLK_CTL_CLK_DIS; -- WREG_DAC(MGA1064_PIX_CLK_CTL_CLK_DIS, tmp); -+ WREG8(DAC_DATA, tmp); - - WREG8(DAC_INDEX, MGA1064_REMHEADCTL); - tmp = RREG8(DAC_DATA); - tmp |= MGA1064_REMHEADCTL_CLKDIS; -- WREG_DAC(MGA1064_REMHEADCTL, tmp); -+ WREG8(DAC_DATA, tmp); - - tmp = RREG8(MGAREG_MEM_MISC_READ); - tmp |= (0x3<<2) | 0xc0; -@@ -530,7 +530,7 @@ static int mga_g200er_set_plls(struct mga_device *mdev, long clock) - tmp = RREG8(DAC_DATA); - tmp &= ~MGA1064_PIX_CLK_CTL_CLK_DIS; - tmp |= MGA1064_PIX_CLK_CTL_CLK_POW_DOWN; -- WREG_DAC(MGA1064_PIX_CLK_CTL, tmp); -+ WREG8(DAC_DATA, tmp); - - udelay(500); - -@@ -657,12 +657,26 @@ static void mga_g200wb_commit(struct drm_crtc *crtc) - WREG_DAC(MGA1064_GEN_IO_DATA, tmp); - } - -- -+/* -+ This is how the framebuffer base address is stored in g200 cards: -+ * Assume @offset is the gpu_addr variable of the framebuffer object -+ * Then addr is the number of _pixels_ (not bytes) from the start of -+ VRAM to the first pixel we want to display. (divided by 2 for 32bit -+ framebuffers) -+ * addr is stored in the CRTCEXT0, CRTCC and CRTCD registers -+ addr<20> -> CRTCEXT0<6> -+ addr<19-16> -> CRTCEXT0<3-0> -+ addr<15-8> -> CRTCC<7-0> -+ addr<7-0> -> CRTCD<7-0> -+ CRTCEXT0 has to be programmed last to trigger an update and make the -+ new addr variable take effect. -+ */ - void mga_set_start_address(struct drm_crtc *crtc, unsigned offset) - { - struct mga_device *mdev = crtc->dev->dev_private; - u32 addr; - int count; -+ u8 crtcext0; - - while (RREG8(0x1fda) & 0x08); - while (!(RREG8(0x1fda) & 0x08)); -@@ -670,10 +684,17 @@ void mga_set_start_address(struct drm_crtc *crtc, unsigned offset) - count = RREG8(MGAREG_VCOUNT) + 2; - while (RREG8(MGAREG_VCOUNT) < count); - -- addr = offset >> 2; -+ WREG8(MGAREG_CRTCEXT_INDEX, 0); -+ crtcext0 = RREG8(MGAREG_CRTCEXT_DATA); -+ crtcext0 &= 0xB0; -+ addr = offset / 8; -+ /* Can't store addresses any higher than that... -+ but we also don't have more than 16MB of memory, so it should be fine. */ -+ WARN_ON(addr > 0x1fffff); -+ crtcext0 |= (!!(addr & (1<<20)))<<6; - WREG_CRT(0x0d, (u8)(addr & 0xff)); - WREG_CRT(0x0c, (u8)(addr >> 8) & 0xff); -- WREG_CRT(0xaf, (u8)(addr >> 16) & 0xf); -+ WREG_ECRT(0x0, ((u8)(addr >> 16) & 0xf) | crtcext0); - } - - -diff --git a/drivers/gpu/drm/radeon/r300_cmdbuf.c b/drivers/gpu/drm/radeon/r300_cmdbuf.c -index 865e2c9..60170ea 100644 ---- a/drivers/gpu/drm/radeon/r300_cmdbuf.c -+++ b/drivers/gpu/drm/radeon/r300_cmdbuf.c -@@ -75,7 +75,7 @@ static int r300_emit_cliprects(drm_radeon_private_t *dev_priv, - OUT_RING(CP_PACKET0(R300_RE_CLIPRECT_TL_0, nr * 2 - 1)); - - for (i = 0; i < nr; ++i) { -- if (DRM_COPY_FROM_USER_UNCHECKED -+ if (DRM_COPY_FROM_USER - (&box, &cmdbuf->boxes[n + i], sizeof(box))) { - DRM_ERROR("copy cliprect faulted\n"); - return -EFAULT; -diff --git a/drivers/gpu/drm/radeon/radeon_drv.c b/drivers/gpu/drm/radeon/radeon_drv.c -index 66a7f0f..96cf439 100644 ---- a/drivers/gpu/drm/radeon/radeon_drv.c -+++ b/drivers/gpu/drm/radeon/radeon_drv.c -@@ -144,7 +144,7 @@ static inline void radeon_unregister_atpx_handler(void) {} - #endif - - int radeon_no_wb; --int radeon_modeset = 1; -+int radeon_modeset = -1; - int radeon_dynclks = -1; - int radeon_r4xx_atom = 0; - int radeon_agpmode = 0; -@@ -449,6 +449,16 @@ static struct pci_driver radeon_kms_pci_driver = { - - static int __init radeon_init(void) - { -+#ifdef CONFIG_VGA_CONSOLE -+ if (vgacon_text_force() && radeon_modeset == -1) { -+ DRM_INFO("VGACON disable radeon kernel modesetting.\n"); -+ radeon_modeset = 0; -+ } -+#endif -+ /* set to modesetting by default if not nomodeset */ -+ if (radeon_modeset == -1) -+ radeon_modeset = 1; -+ - if (radeon_modeset == 1) { - DRM_INFO("radeon kernel modesetting enabled.\n"); - driver = &kms_driver; -diff --git a/drivers/hid/hid-core.c b/drivers/hid/hid-core.c -index aa341d1..e6dbf09 100644 ---- a/drivers/hid/hid-core.c -+++ b/drivers/hid/hid-core.c -@@ -1702,6 +1702,7 @@ static const struct hid_device_id hid_have_special_driver[] = { - { HID_USB_DEVICE(USB_VENDOR_ID_SONY, USB_DEVICE_ID_SONY_NAVIGATION_CONTROLLER) }, - { HID_BLUETOOTH_DEVICE(USB_VENDOR_ID_SONY, USB_DEVICE_ID_SONY_PS3_CONTROLLER) }, - { HID_USB_DEVICE(USB_VENDOR_ID_SONY, USB_DEVICE_ID_SONY_VAIO_VGX_MOUSE) }, -+ { HID_USB_DEVICE(USB_VENDOR_ID_SONY, USB_DEVICE_ID_SONY_VAIO_VGP_MOUSE) }, - { HID_USB_DEVICE(USB_VENDOR_ID_STEELSERIES, USB_DEVICE_ID_STEELSERIES_SRWS1) }, - { HID_USB_DEVICE(USB_VENDOR_ID_SUNPLUS, USB_DEVICE_ID_SUNPLUS_WDESKTOP) }, - { HID_USB_DEVICE(USB_VENDOR_ID_THINGM, USB_DEVICE_ID_BLINK1) }, -diff --git a/drivers/md/dm-bufio.c b/drivers/md/dm-bufio.c -index c608313..0387e05 100644 ---- a/drivers/md/dm-bufio.c -+++ b/drivers/md/dm-bufio.c -@@ -319,6 +319,9 @@ static void __cache_size_refresh(void) - static void *alloc_buffer_data(struct dm_bufio_client *c, gfp_t gfp_mask, - enum data_mode *data_mode) - { -+ unsigned noio_flag; -+ void *ptr; -+ - if (c->block_size <= DM_BUFIO_BLOCK_SIZE_SLAB_LIMIT) { - *data_mode = DATA_MODE_SLAB; - return kmem_cache_alloc(DM_BUFIO_CACHE(c), gfp_mask); -@@ -332,7 +335,26 @@ static void *alloc_buffer_data(struct dm_bufio_client *c, gfp_t gfp_mask, - } - - *data_mode = DATA_MODE_VMALLOC; -- return __vmalloc(c->block_size, gfp_mask, PAGE_KERNEL); -+ -+ /* -+ * __vmalloc allocates the data pages and auxiliary structures with -+ * gfp_flags that were specified, but pagetables are always allocated -+ * with GFP_KERNEL, no matter what was specified as gfp_mask. -+ * -+ * Consequently, we must set per-process flag PF_MEMALLOC_NOIO so that -+ * all allocations done by this process (including pagetables) are done -+ * as if GFP_NOIO was specified. -+ */ -+ -+ if (gfp_mask & __GFP_NORETRY) -+ noio_flag = memalloc_noio_save(); -+ -+ ptr = __vmalloc(c->block_size, gfp_mask, PAGE_KERNEL); -+ -+ if (gfp_mask & __GFP_NORETRY) -+ memalloc_noio_restore(noio_flag); -+ -+ return ptr; - } - - /* -diff --git a/drivers/md/dm-cache-target.c b/drivers/md/dm-cache-target.c -index 1074409..6feaba2 100644 ---- a/drivers/md/dm-cache-target.c -+++ b/drivers/md/dm-cache-target.c -@@ -1971,6 +1971,7 @@ static int cache_create(struct cache_args *ca, struct cache **result) - atomic_set(&cache->nr_migrations, 0); - init_waitqueue_head(&cache->migration_wait); - -+ r = -ENOMEM; - cache->nr_dirty = 0; - cache->dirty_bitset = alloc_bitset(from_cblock(cache->cache_size)); - if (!cache->dirty_bitset) { -diff --git a/drivers/md/dm-snap.c b/drivers/md/dm-snap.c -index c0e0702..c434e5a 100644 ---- a/drivers/md/dm-snap.c -+++ b/drivers/md/dm-snap.c -@@ -1121,6 +1121,7 @@ static int snapshot_ctr(struct dm_target *ti, unsigned int argc, char **argv) - s->pending_pool = mempool_create_slab_pool(MIN_IOS, pending_cache); - if (!s->pending_pool) { - ti->error = "Could not allocate mempool for pending exceptions"; -+ r = -ENOMEM; - goto bad_pending_pool; - } - -diff --git a/drivers/md/dm-stripe.c b/drivers/md/dm-stripe.c -index d8837d3..7b8b2b9 100644 ---- a/drivers/md/dm-stripe.c -+++ b/drivers/md/dm-stripe.c -@@ -94,7 +94,7 @@ static int get_stripe(struct dm_target *ti, struct stripe_c *sc, - static int stripe_ctr(struct dm_target *ti, unsigned int argc, char **argv) - { - struct stripe_c *sc; -- sector_t width; -+ sector_t width, tmp_len; - uint32_t stripes; - uint32_t chunk_size; - int r; -@@ -116,15 +116,16 @@ static int stripe_ctr(struct dm_target *ti, unsigned int argc, char **argv) - } - - width = ti->len; -- if (sector_div(width, chunk_size)) { -+ if (sector_div(width, stripes)) { - ti->error = "Target length not divisible by " -- "chunk size"; -+ "number of stripes"; - return -EINVAL; - } - -- if (sector_div(width, stripes)) { -+ tmp_len = width; -+ if (sector_div(tmp_len, chunk_size)) { - ti->error = "Target length not divisible by " -- "number of stripes"; -+ "chunk size"; - return -EINVAL; - } - -diff --git a/drivers/md/dm-table.c b/drivers/md/dm-table.c -index e50dad0..1ff252a 100644 ---- a/drivers/md/dm-table.c -+++ b/drivers/md/dm-table.c -@@ -1442,7 +1442,7 @@ static bool dm_table_supports_write_same(struct dm_table *t) - return false; - - if (!ti->type->iterate_devices || -- !ti->type->iterate_devices(ti, device_not_write_same_capable, NULL)) -+ ti->type->iterate_devices(ti, device_not_write_same_capable, NULL)) - return false; - } - -diff --git a/drivers/net/ethernet/3com/3c509.c b/drivers/net/ethernet/3com/3c509.c -index f36ff99..adb4bf5 100644 ---- a/drivers/net/ethernet/3com/3c509.c -+++ b/drivers/net/ethernet/3com/3c509.c -@@ -306,6 +306,7 @@ static int el3_isa_match(struct device *pdev, unsigned int ndev) - if (!dev) - return -ENOMEM; - -+ SET_NETDEV_DEV(dev, pdev); - netdev_boot_setup_check(dev); - - if (!request_region(ioaddr, EL3_IO_EXTENT, "3c509-isa")) { -@@ -595,6 +596,7 @@ static int __init el3_eisa_probe (struct device *device) - return -ENOMEM; - } - -+ SET_NETDEV_DEV(dev, device); - netdev_boot_setup_check(dev); - - el3_dev_fill(dev, phys_addr, ioaddr, irq, if_port, EL3_EISA); -diff --git a/drivers/net/ethernet/3com/3c59x.c b/drivers/net/ethernet/3com/3c59x.c -index 1928e20..072c6f1 100644 ---- a/drivers/net/ethernet/3com/3c59x.c -+++ b/drivers/net/ethernet/3com/3c59x.c -@@ -632,7 +632,6 @@ struct vortex_private { - pm_state_valid:1, /* pci_dev->saved_config_space has sane contents */ - open:1, - medialock:1, -- must_free_region:1, /* Flag: if zero, Cardbus owns the I/O region */ - large_frames:1, /* accept large frames */ - handling_irq:1; /* private in_irq indicator */ - /* {get|set}_wol operations are already serialized by rtnl. -@@ -951,7 +950,7 @@ static int vortex_eisa_remove(struct device *device) - - unregister_netdev(dev); - iowrite16(TotalReset|0x14, ioaddr + EL3_CMD); -- release_region(dev->base_addr, VORTEX_TOTAL_SIZE); -+ release_region(edev->base_addr, VORTEX_TOTAL_SIZE); - - free_netdev(dev); - return 0; -@@ -1012,6 +1011,12 @@ static int vortex_init_one(struct pci_dev *pdev, - if (rc < 0) - goto out; - -+ rc = pci_request_regions(pdev, DRV_NAME); -+ if (rc < 0) { -+ pci_disable_device(pdev); -+ goto out; -+ } -+ - unit = vortex_cards_found; - - if (global_use_mmio < 0 && (unit >= MAX_UNITS || use_mmio[unit] < 0)) { -@@ -1027,6 +1032,7 @@ static int vortex_init_one(struct pci_dev *pdev, - if (!ioaddr) /* If mapping fails, fall-back to BAR 0... */ - ioaddr = pci_iomap(pdev, 0, 0); - if (!ioaddr) { -+ pci_release_regions(pdev); - pci_disable_device(pdev); - rc = -ENOMEM; - goto out; -@@ -1036,6 +1042,7 @@ static int vortex_init_one(struct pci_dev *pdev, - ent->driver_data, unit); - if (rc < 0) { - pci_iounmap(pdev, ioaddr); -+ pci_release_regions(pdev); - pci_disable_device(pdev); - goto out; - } -@@ -1178,11 +1185,6 @@ static int vortex_probe1(struct device *gendev, void __iomem *ioaddr, int irq, - - /* PCI-only startup logic */ - if (pdev) { -- /* EISA resources already marked, so only PCI needs to do this here */ -- /* Ignore return value, because Cardbus drivers already allocate for us */ -- if (request_region(dev->base_addr, vci->io_size, print_name) != NULL) -- vp->must_free_region = 1; -- - /* enable bus-mastering if necessary */ - if (vci->flags & PCI_USES_MASTER) - pci_set_master(pdev); -@@ -1220,7 +1222,7 @@ static int vortex_probe1(struct device *gendev, void __iomem *ioaddr, int irq, - &vp->rx_ring_dma); - retval = -ENOMEM; - if (!vp->rx_ring) -- goto free_region; -+ goto free_device; - - vp->tx_ring = (struct boom_tx_desc *)(vp->rx_ring + RX_RING_SIZE); - vp->tx_ring_dma = vp->rx_ring_dma + sizeof(struct boom_rx_desc) * RX_RING_SIZE; -@@ -1484,9 +1486,7 @@ free_ring: - + sizeof(struct boom_tx_desc) * TX_RING_SIZE, - vp->rx_ring, - vp->rx_ring_dma); --free_region: -- if (vp->must_free_region) -- release_region(dev->base_addr, vci->io_size); -+free_device: - free_netdev(dev); - pr_err(PFX "vortex_probe1 fails. Returns %d\n", retval); - out: -@@ -3254,8 +3254,9 @@ static void vortex_remove_one(struct pci_dev *pdev) - + sizeof(struct boom_tx_desc) * TX_RING_SIZE, - vp->rx_ring, - vp->rx_ring_dma); -- if (vp->must_free_region) -- release_region(dev->base_addr, vp->io_size); -+ -+ pci_release_regions(pdev); -+ - free_netdev(dev); - } - -diff --git a/drivers/net/ethernet/sfc/mcdi.c b/drivers/net/ethernet/sfc/mcdi.c -index 0095ce9..97dd8f18 100644 ---- a/drivers/net/ethernet/sfc/mcdi.c -+++ b/drivers/net/ethernet/sfc/mcdi.c -@@ -667,7 +667,7 @@ fail: - int efx_mcdi_get_board_cfg(struct efx_nic *efx, u8 *mac_address, - u16 *fw_subtype_list, u32 *capabilities) - { -- uint8_t outbuf[MC_CMD_GET_BOARD_CFG_OUT_LENMIN]; -+ uint8_t outbuf[MC_CMD_GET_BOARD_CFG_OUT_LENMAX]; - size_t outlen, offset, i; - int port_num = efx_port_num(efx); - int rc; -diff --git a/drivers/net/ethernet/tile/tilegx.c b/drivers/net/ethernet/tile/tilegx.c -index 66e025a..f3c2d03 100644 ---- a/drivers/net/ethernet/tile/tilegx.c -+++ b/drivers/net/ethernet/tile/tilegx.c -@@ -930,7 +930,7 @@ static int tile_net_setup_interrupts(struct net_device *dev) - if (info->has_iqueue) { - gxio_mpipe_request_notif_ring_interrupt( - &context, cpu_x(cpu), cpu_y(cpu), -- 1, ingress_irq, info->iqueue.ring); -+ KERNEL_PL, ingress_irq, info->iqueue.ring); - } - } - -diff --git a/drivers/net/macvlan.c b/drivers/net/macvlan.c -index 73abbc1..011062e 100644 ---- a/drivers/net/macvlan.c -+++ b/drivers/net/macvlan.c -@@ -222,7 +222,8 @@ static rx_handler_result_t macvlan_handle_frame(struct sk_buff **pskb) - } - - if (port->passthru) -- vlan = list_first_entry(&port->vlans, struct macvlan_dev, list); -+ vlan = list_first_or_null_rcu(&port->vlans, -+ struct macvlan_dev, list); - else - vlan = macvlan_hash_lookup(port, eth->h_dest); - if (vlan == NULL) -@@ -807,7 +808,7 @@ int macvlan_common_newlink(struct net *src_net, struct net_device *dev, - if (err < 0) - goto upper_dev_unlink; - -- list_add_tail(&vlan->list, &port->vlans); -+ list_add_tail_rcu(&vlan->list, &port->vlans); - netif_stacked_transfer_operstate(lowerdev, dev); - - return 0; -@@ -835,7 +836,7 @@ void macvlan_dellink(struct net_device *dev, struct list_head *head) - { - struct macvlan_dev *vlan = netdev_priv(dev); - -- list_del(&vlan->list); -+ list_del_rcu(&vlan->list); - unregister_netdevice_queue(dev, head); - netdev_upper_dev_unlink(vlan->lowerdev, dev); - } -diff --git a/drivers/net/tun.c b/drivers/net/tun.c -index 729ed53..755fa9e 100644 ---- a/drivers/net/tun.c -+++ b/drivers/net/tun.c -@@ -1471,14 +1471,17 @@ static int tun_recvmsg(struct kiocb *iocb, struct socket *sock, - if (!tun) - return -EBADFD; - -- if (flags & ~(MSG_DONTWAIT|MSG_TRUNC)) -- return -EINVAL; -+ if (flags & ~(MSG_DONTWAIT|MSG_TRUNC)) { -+ ret = -EINVAL; -+ goto out; -+ } - ret = tun_do_read(tun, tfile, iocb, m->msg_iov, total_len, - flags & MSG_DONTWAIT); - if (ret > total_len) { - m->msg_flags |= MSG_TRUNC; - ret = flags & MSG_TRUNC ? ret : total_len; - } -+out: - tun_put(tun); - return ret; - } -diff --git a/drivers/net/usb/asix_common.c b/drivers/net/usb/asix_common.c -index f7f623a..577c72d 100644 ---- a/drivers/net/usb/asix_common.c -+++ b/drivers/net/usb/asix_common.c -@@ -100,6 +100,9 @@ int asix_rx_fixup_internal(struct usbnet *dev, struct sk_buff *skb, - netdev_err(dev->net, "asix_rx_fixup() Bad RX Length %d\n", - rx->size); - kfree_skb(rx->ax_skb); -+ rx->ax_skb = NULL; -+ rx->size = 0U; -+ - return 0; - } - -diff --git a/drivers/net/wireless/ath/ath9k/main.c b/drivers/net/wireless/ath/ath9k/main.c -index 988372d..e509c37 100644 ---- a/drivers/net/wireless/ath/ath9k/main.c -+++ b/drivers/net/wireless/ath/ath9k/main.c -@@ -1308,6 +1308,7 @@ static int ath9k_sta_add(struct ieee80211_hw *hw, - struct ath_common *common = ath9k_hw_common(sc->sc_ah); - struct ath_node *an = (struct ath_node *) sta->drv_priv; - struct ieee80211_key_conf ps_key = { }; -+ int key; - - ath_node_attach(sc, sta, vif); - -@@ -1315,7 +1316,9 @@ static int ath9k_sta_add(struct ieee80211_hw *hw, - vif->type != NL80211_IFTYPE_AP_VLAN) - return 0; - -- an->ps_key = ath_key_config(common, vif, sta, &ps_key); -+ key = ath_key_config(common, vif, sta, &ps_key); -+ if (key > 0) -+ an->ps_key = key; - - return 0; - } -@@ -1332,6 +1335,7 @@ static void ath9k_del_ps_key(struct ath_softc *sc, - return; - - ath_key_delete(common, &ps_key); -+ an->ps_key = 0; - } - - static int ath9k_sta_remove(struct ieee80211_hw *hw, -diff --git a/drivers/net/wireless/b43/dma.c b/drivers/net/wireless/b43/dma.c -index 1221469..ee3d640 100644 ---- a/drivers/net/wireless/b43/dma.c -+++ b/drivers/net/wireless/b43/dma.c -@@ -1733,6 +1733,25 @@ drop_recycle_buffer: - sync_descbuffer_for_device(ring, dmaaddr, ring->rx_buffersize); - } - -+void b43_dma_handle_rx_overflow(struct b43_dmaring *ring) -+{ -+ int current_slot, previous_slot; -+ -+ B43_WARN_ON(ring->tx); -+ -+ /* Device has filled all buffers, drop all packets and let TCP -+ * decrease speed. -+ * Decrement RX index by one will let the device to see all slots -+ * as free again -+ */ -+ /* -+ *TODO: How to increase rx_drop in mac80211? -+ */ -+ current_slot = ring->ops->get_current_rxslot(ring); -+ previous_slot = prev_slot(ring, current_slot); -+ ring->ops->set_current_rxslot(ring, previous_slot); -+} -+ - void b43_dma_rx(struct b43_dmaring *ring) - { - const struct b43_dma_ops *ops = ring->ops; -diff --git a/drivers/net/wireless/b43/dma.h b/drivers/net/wireless/b43/dma.h -index 9fdd198..df8c8cd 100644 ---- a/drivers/net/wireless/b43/dma.h -+++ b/drivers/net/wireless/b43/dma.h -@@ -9,7 +9,7 @@ - /* DMA-Interrupt reasons. */ - #define B43_DMAIRQ_FATALMASK ((1 << 10) | (1 << 11) | (1 << 12) \ - | (1 << 14) | (1 << 15)) --#define B43_DMAIRQ_NONFATALMASK (1 << 13) -+#define B43_DMAIRQ_RDESC_UFLOW (1 << 13) - #define B43_DMAIRQ_RX_DONE (1 << 16) - - /*** 32-bit DMA Engine. ***/ -@@ -295,6 +295,8 @@ int b43_dma_tx(struct b43_wldev *dev, - void b43_dma_handle_txstatus(struct b43_wldev *dev, - const struct b43_txstatus *status); - -+void b43_dma_handle_rx_overflow(struct b43_dmaring *ring); -+ - void b43_dma_rx(struct b43_dmaring *ring); - - void b43_dma_direct_fifo_rx(struct b43_wldev *dev, -diff --git a/drivers/net/wireless/b43/main.c b/drivers/net/wireless/b43/main.c -index 0568273..64b637a 100644 ---- a/drivers/net/wireless/b43/main.c -+++ b/drivers/net/wireless/b43/main.c -@@ -1895,30 +1895,18 @@ static void b43_do_interrupt_thread(struct b43_wldev *dev) - } - } - -- if (unlikely(merged_dma_reason & (B43_DMAIRQ_FATALMASK | -- B43_DMAIRQ_NONFATALMASK))) { -- if (merged_dma_reason & B43_DMAIRQ_FATALMASK) { -- b43err(dev->wl, "Fatal DMA error: " -- "0x%08X, 0x%08X, 0x%08X, " -- "0x%08X, 0x%08X, 0x%08X\n", -- dma_reason[0], dma_reason[1], -- dma_reason[2], dma_reason[3], -- dma_reason[4], dma_reason[5]); -- b43err(dev->wl, "This device does not support DMA " -+ if (unlikely(merged_dma_reason & (B43_DMAIRQ_FATALMASK))) { -+ b43err(dev->wl, -+ "Fatal DMA error: 0x%08X, 0x%08X, 0x%08X, 0x%08X, 0x%08X, 0x%08X\n", -+ dma_reason[0], dma_reason[1], -+ dma_reason[2], dma_reason[3], -+ dma_reason[4], dma_reason[5]); -+ b43err(dev->wl, "This device does not support DMA " - "on your system. It will now be switched to PIO.\n"); -- /* Fall back to PIO transfers if we get fatal DMA errors! */ -- dev->use_pio = true; -- b43_controller_restart(dev, "DMA error"); -- return; -- } -- if (merged_dma_reason & B43_DMAIRQ_NONFATALMASK) { -- b43err(dev->wl, "DMA error: " -- "0x%08X, 0x%08X, 0x%08X, " -- "0x%08X, 0x%08X, 0x%08X\n", -- dma_reason[0], dma_reason[1], -- dma_reason[2], dma_reason[3], -- dma_reason[4], dma_reason[5]); -- } -+ /* Fall back to PIO transfers if we get fatal DMA errors! */ -+ dev->use_pio = true; -+ b43_controller_restart(dev, "DMA error"); -+ return; - } - - if (unlikely(reason & B43_IRQ_UCODE_DEBUG)) -@@ -1937,6 +1925,11 @@ static void b43_do_interrupt_thread(struct b43_wldev *dev) - handle_irq_noise(dev); - - /* Check the DMA reason registers for received data. */ -+ if (dma_reason[0] & B43_DMAIRQ_RDESC_UFLOW) { -+ if (B43_DEBUG) -+ b43warn(dev->wl, "RX descriptor underrun\n"); -+ b43_dma_handle_rx_overflow(dev->dma.rx_ring); -+ } - if (dma_reason[0] & B43_DMAIRQ_RX_DONE) { - if (b43_using_pio_transfers(dev)) - b43_pio_rx(dev->pio.rx_queue); -@@ -1994,7 +1987,7 @@ static irqreturn_t b43_do_interrupt(struct b43_wldev *dev) - return IRQ_NONE; - - dev->dma_reason[0] = b43_read32(dev, B43_MMIO_DMA0_REASON) -- & 0x0001DC00; -+ & 0x0001FC00; - dev->dma_reason[1] = b43_read32(dev, B43_MMIO_DMA1_REASON) - & 0x0000DC00; - dev->dma_reason[2] = b43_read32(dev, B43_MMIO_DMA2_REASON) -@@ -3126,7 +3119,7 @@ static int b43_chip_init(struct b43_wldev *dev) - b43_write32(dev, 0x018C, 0x02000000); - } - b43_write32(dev, B43_MMIO_GEN_IRQ_REASON, 0x00004000); -- b43_write32(dev, B43_MMIO_DMA0_IRQ_MASK, 0x0001DC00); -+ b43_write32(dev, B43_MMIO_DMA0_IRQ_MASK, 0x0001FC00); - b43_write32(dev, B43_MMIO_DMA1_IRQ_MASK, 0x0000DC00); - b43_write32(dev, B43_MMIO_DMA2_IRQ_MASK, 0x0000DC00); - b43_write32(dev, B43_MMIO_DMA3_IRQ_MASK, 0x0001DC00); -diff --git a/drivers/net/wireless/iwlegacy/4965-mac.c b/drivers/net/wireless/iwlegacy/4965-mac.c -index 7941eb3..cbaa777 100644 ---- a/drivers/net/wireless/iwlegacy/4965-mac.c -+++ b/drivers/net/wireless/iwlegacy/4965-mac.c -@@ -5740,8 +5740,7 @@ il4965_mac_setup_register(struct il_priv *il, u32 max_probe_length) - hw->flags = - IEEE80211_HW_SIGNAL_DBM | IEEE80211_HW_AMPDU_AGGREGATION | - IEEE80211_HW_NEED_DTIM_BEFORE_ASSOC | IEEE80211_HW_SPECTRUM_MGMT | -- IEEE80211_HW_REPORTS_TX_ACK_STATUS | IEEE80211_HW_SUPPORTS_PS | -- IEEE80211_HW_SUPPORTS_DYNAMIC_PS; -+ IEEE80211_HW_SUPPORTS_PS | IEEE80211_HW_SUPPORTS_DYNAMIC_PS; - if (il->cfg->sku & IL_SKU_N) - hw->flags |= - IEEE80211_HW_SUPPORTS_DYNAMIC_SMPS | -diff --git a/drivers/net/wireless/mwifiex/cfg80211.c b/drivers/net/wireless/mwifiex/cfg80211.c -index 8aaf56a..c13f6e9 100644 ---- a/drivers/net/wireless/mwifiex/cfg80211.c -+++ b/drivers/net/wireless/mwifiex/cfg80211.c -@@ -2280,9 +2280,6 @@ int mwifiex_del_virtual_intf(struct wiphy *wiphy, struct wireless_dev *wdev) - if (wdev->netdev->reg_state == NETREG_REGISTERED) - unregister_netdevice(wdev->netdev); - -- if (wdev->netdev->reg_state == NETREG_UNREGISTERED) -- free_netdev(wdev->netdev); -- - /* Clear the priv in adapter */ - priv->netdev = NULL; - -diff --git a/drivers/net/wireless/mwifiex/cmdevt.c b/drivers/net/wireless/mwifiex/cmdevt.c -index b5c8b96..aeade10 100644 ---- a/drivers/net/wireless/mwifiex/cmdevt.c -+++ b/drivers/net/wireless/mwifiex/cmdevt.c -@@ -1176,6 +1176,7 @@ mwifiex_process_hs_config(struct mwifiex_adapter *adapter) - adapter->if_ops.wakeup(adapter); - adapter->hs_activated = false; - adapter->is_hs_configured = false; -+ adapter->is_suspended = false; - mwifiex_hs_activated_event(mwifiex_get_priv(adapter, - MWIFIEX_BSS_ROLE_ANY), - false); -diff --git a/drivers/net/wireless/mwifiex/main.c b/drivers/net/wireless/mwifiex/main.c -index 9c802ed..6d9bc63 100644 ---- a/drivers/net/wireless/mwifiex/main.c -+++ b/drivers/net/wireless/mwifiex/main.c -@@ -646,6 +646,7 @@ void mwifiex_init_priv_params(struct mwifiex_private *priv, - struct net_device *dev) - { - dev->netdev_ops = &mwifiex_netdev_ops; -+ dev->destructor = free_netdev; - /* Initialize private structure */ - priv->current_key_index = 0; - priv->media_connected = false; -diff --git a/drivers/net/wireless/mwifiex/sta_ioctl.c b/drivers/net/wireless/mwifiex/sta_ioctl.c -index 13100f8..fb420fe 100644 ---- a/drivers/net/wireless/mwifiex/sta_ioctl.c -+++ b/drivers/net/wireless/mwifiex/sta_ioctl.c -@@ -99,7 +99,7 @@ int mwifiex_request_set_multicast_list(struct mwifiex_private *priv, - } else { - /* Multicast */ - priv->curr_pkt_filter &= ~HostCmd_ACT_MAC_PROMISCUOUS_ENABLE; -- if (mcast_list->mode == MWIFIEX_MULTICAST_MODE) { -+ if (mcast_list->mode == MWIFIEX_ALL_MULTI_MODE) { - dev_dbg(priv->adapter->dev, - "info: Enabling All Multicast!\n"); - priv->curr_pkt_filter |= -@@ -111,20 +111,11 @@ int mwifiex_request_set_multicast_list(struct mwifiex_private *priv, - dev_dbg(priv->adapter->dev, - "info: Set multicast list=%d\n", - mcast_list->num_multicast_addr); -- /* Set multicast addresses to firmware */ -- if (old_pkt_filter == priv->curr_pkt_filter) { -- /* Send request to firmware */ -- ret = mwifiex_send_cmd_async(priv, -- HostCmd_CMD_MAC_MULTICAST_ADR, -- HostCmd_ACT_GEN_SET, 0, -- mcast_list); -- } else { -- /* Send request to firmware */ -- ret = mwifiex_send_cmd_async(priv, -- HostCmd_CMD_MAC_MULTICAST_ADR, -- HostCmd_ACT_GEN_SET, 0, -- mcast_list); -- } -+ /* Send multicast addresses to firmware */ -+ ret = mwifiex_send_cmd_async(priv, -+ HostCmd_CMD_MAC_MULTICAST_ADR, -+ HostCmd_ACT_GEN_SET, 0, -+ mcast_list); - } - } - } -diff --git a/drivers/platform/x86/hp_accel.c b/drivers/platform/x86/hp_accel.c -index e64a7a8..a8e43cf 100644 ---- a/drivers/platform/x86/hp_accel.c -+++ b/drivers/platform/x86/hp_accel.c -@@ -362,7 +362,8 @@ static int lis3lv02d_suspend(struct device *dev) - - static int lis3lv02d_resume(struct device *dev) - { -- return lis3lv02d_poweron(&lis3_dev); -+ lis3lv02d_poweron(&lis3_dev); -+ return 0; - } - - static SIMPLE_DEV_PM_OPS(hp_accel_pm, lis3lv02d_suspend, lis3lv02d_resume); -diff --git a/drivers/rtc/Kconfig b/drivers/rtc/Kconfig -index 79fbe38..9e95473 100644 ---- a/drivers/rtc/Kconfig -+++ b/drivers/rtc/Kconfig -@@ -20,7 +20,6 @@ if RTC_CLASS - config RTC_HCTOSYS - bool "Set system time from RTC on startup and resume" - default y -- depends on !ALWAYS_USE_PERSISTENT_CLOCK - help - If you say yes here, the system time (wall clock) will be set using - the value read from a specified RTC device. This is useful to avoid -@@ -29,7 +28,6 @@ config RTC_HCTOSYS - config RTC_SYSTOHC - bool "Set the RTC time based on NTP synchronization" - default y -- depends on !ALWAYS_USE_PERSISTENT_CLOCK - help - If you say yes here, the system time (wall clock) will be stored - in the RTC specified by RTC_HCTOSYS_DEVICE approximately every 11 -diff --git a/drivers/rtc/rtc-pcf2123.c b/drivers/rtc/rtc-pcf2123.c -index 02b742a..6dd6b38 100644 ---- a/drivers/rtc/rtc-pcf2123.c -+++ b/drivers/rtc/rtc-pcf2123.c -@@ -265,6 +265,7 @@ static int pcf2123_probe(struct spi_device *spi) - - if (!(rxbuf[0] & 0x20)) { - dev_err(&spi->dev, "chip not found\n"); -+ ret = -ENODEV; - goto kfree_exit; - } - -diff --git a/drivers/scsi/sd.c b/drivers/scsi/sd.c -index 7992635..82910cc 100644 ---- a/drivers/scsi/sd.c -+++ b/drivers/scsi/sd.c -@@ -142,6 +142,7 @@ sd_store_cache_type(struct device *dev, struct device_attribute *attr, - char *buffer_data; - struct scsi_mode_data data; - struct scsi_sense_hdr sshdr; -+ const char *temp = "temporary "; - int len; - - if (sdp->type != TYPE_DISK) -@@ -150,6 +151,13 @@ sd_store_cache_type(struct device *dev, struct device_attribute *attr, - * it's not worth the risk */ - return -EINVAL; - -+ if (strncmp(buf, temp, sizeof(temp) - 1) == 0) { -+ buf += sizeof(temp) - 1; -+ sdkp->cache_override = 1; -+ } else { -+ sdkp->cache_override = 0; -+ } -+ - for (i = 0; i < ARRAY_SIZE(sd_cache_types); i++) { - len = strlen(sd_cache_types[i]); - if (strncmp(sd_cache_types[i], buf, len) == 0 && -@@ -162,6 +170,13 @@ sd_store_cache_type(struct device *dev, struct device_attribute *attr, - return -EINVAL; - rcd = ct & 0x01 ? 1 : 0; - wce = ct & 0x02 ? 1 : 0; -+ -+ if (sdkp->cache_override) { -+ sdkp->WCE = wce; -+ sdkp->RCD = rcd; -+ return count; -+ } -+ - if (scsi_mode_sense(sdp, 0x08, 8, buffer, sizeof(buffer), SD_TIMEOUT, - SD_MAX_RETRIES, &data, NULL)) - return -EINVAL; -@@ -2319,6 +2334,10 @@ sd_read_cache_type(struct scsi_disk *sdkp, unsigned char *buffer) - int old_rcd = sdkp->RCD; - int old_dpofua = sdkp->DPOFUA; - -+ -+ if (sdkp->cache_override) -+ return; -+ - first_len = 4; - if (sdp->skip_ms_page_8) { - if (sdp->type == TYPE_RBC) -@@ -2812,6 +2831,7 @@ static void sd_probe_async(void *data, async_cookie_t cookie) - sdkp->capacity = 0; - sdkp->media_present = 1; - sdkp->write_prot = 0; -+ sdkp->cache_override = 0; - sdkp->WCE = 0; - sdkp->RCD = 0; - sdkp->ATO = 0; -diff --git a/drivers/scsi/sd.h b/drivers/scsi/sd.h -index 74a1e4c..2386aeb 100644 ---- a/drivers/scsi/sd.h -+++ b/drivers/scsi/sd.h -@@ -73,6 +73,7 @@ struct scsi_disk { - u8 protection_type;/* Data Integrity Field */ - u8 provisioning_mode; - unsigned ATO : 1; /* state of disk ATO bit */ -+ unsigned cache_override : 1; /* temp override of WCE,RCD */ - unsigned WCE : 1; /* state of disk WCE bit */ - unsigned RCD : 1; /* state of disk RCD bit, unused */ - unsigned DPOFUA : 1; /* state of disk DPOFUA bit */ -diff --git a/drivers/target/iscsi/iscsi_target_erl1.c b/drivers/target/iscsi/iscsi_target_erl1.c -index 0b52a23..805f3d2 100644 ---- a/drivers/target/iscsi/iscsi_target_erl1.c -+++ b/drivers/target/iscsi/iscsi_target_erl1.c -@@ -819,7 +819,7 @@ static int iscsit_attach_ooo_cmdsn( - /* - * CmdSN is greater than the tail of the list. - */ -- if (ooo_tail->cmdsn < ooo_cmdsn->cmdsn) -+ if (iscsi_sna_lt(ooo_tail->cmdsn, ooo_cmdsn->cmdsn)) - list_add_tail(&ooo_cmdsn->ooo_list, - &sess->sess_ooo_cmdsn_list); - else { -@@ -829,11 +829,12 @@ static int iscsit_attach_ooo_cmdsn( - */ - list_for_each_entry(ooo_tmp, &sess->sess_ooo_cmdsn_list, - ooo_list) { -- if (ooo_tmp->cmdsn < ooo_cmdsn->cmdsn) -+ if (iscsi_sna_lt(ooo_tmp->cmdsn, ooo_cmdsn->cmdsn)) - continue; - -+ /* Insert before this entry */ - list_add(&ooo_cmdsn->ooo_list, -- &ooo_tmp->ooo_list); -+ ooo_tmp->ooo_list.prev); - break; - } - } -diff --git a/drivers/target/target_core_file.c b/drivers/target/target_core_file.c -index 17a6acb..ca4b219 100644 ---- a/drivers/target/target_core_file.c -+++ b/drivers/target/target_core_file.c -@@ -148,13 +148,8 @@ static int fd_configure_device(struct se_device *dev) - */ - inode = file->f_mapping->host; - if (S_ISBLK(inode->i_mode)) { -- struct request_queue *q = bdev_get_queue(inode->i_bdev); - unsigned long long dev_size; - -- dev->dev_attrib.hw_block_size = -- bdev_logical_block_size(inode->i_bdev); -- dev->dev_attrib.hw_max_sectors = queue_max_hw_sectors(q); -- - /* - * Determine the number of bytes from i_size_read() minus - * one (1) logical sector from underlying struct block_device -@@ -173,13 +168,12 @@ static int fd_configure_device(struct se_device *dev) - " block_device\n"); - goto fail; - } -- -- dev->dev_attrib.hw_block_size = FD_BLOCKSIZE; -- dev->dev_attrib.hw_max_sectors = FD_MAX_SECTORS; - } - - fd_dev->fd_block_size = dev->dev_attrib.hw_block_size; - -+ dev->dev_attrib.hw_block_size = FD_BLOCKSIZE; -+ dev->dev_attrib.hw_max_sectors = FD_MAX_SECTORS; - dev->dev_attrib.hw_queue_depth = FD_MAX_DEVICE_QUEUE_DEPTH; - - if (fd_dev->fbd_flags & FDBD_HAS_BUFFERED_IO_WCE) { -diff --git a/drivers/target/target_core_iblock.c b/drivers/target/target_core_iblock.c -index 8bcc514..e1af9d5 100644 ---- a/drivers/target/target_core_iblock.c -+++ b/drivers/target/target_core_iblock.c -@@ -679,6 +679,8 @@ iblock_execute_rw(struct se_cmd *cmd) - rw = WRITE_FUA; - else if (!(q->flush_flags & REQ_FLUSH)) - rw = WRITE_FUA; -+ else -+ rw = WRITE; - } else { - rw = WRITE; - } -diff --git a/drivers/target/target_core_transport.c b/drivers/target/target_core_transport.c -index 3243ea7..0d46276 100644 ---- a/drivers/target/target_core_transport.c -+++ b/drivers/target/target_core_transport.c -@@ -2213,21 +2213,19 @@ static void target_release_cmd_kref(struct kref *kref) - { - struct se_cmd *se_cmd = container_of(kref, struct se_cmd, cmd_kref); - struct se_session *se_sess = se_cmd->se_sess; -- unsigned long flags; - -- spin_lock_irqsave(&se_sess->sess_cmd_lock, flags); - if (list_empty(&se_cmd->se_cmd_list)) { -- spin_unlock_irqrestore(&se_sess->sess_cmd_lock, flags); -+ spin_unlock(&se_sess->sess_cmd_lock); - se_cmd->se_tfo->release_cmd(se_cmd); - return; - } - if (se_sess->sess_tearing_down && se_cmd->cmd_wait_set) { -- spin_unlock_irqrestore(&se_sess->sess_cmd_lock, flags); -+ spin_unlock(&se_sess->sess_cmd_lock); - complete(&se_cmd->cmd_wait_comp); - return; - } - list_del(&se_cmd->se_cmd_list); -- spin_unlock_irqrestore(&se_sess->sess_cmd_lock, flags); -+ spin_unlock(&se_sess->sess_cmd_lock); - - se_cmd->se_tfo->release_cmd(se_cmd); - } -@@ -2238,7 +2236,8 @@ static void target_release_cmd_kref(struct kref *kref) - */ - int target_put_sess_cmd(struct se_session *se_sess, struct se_cmd *se_cmd) - { -- return kref_put(&se_cmd->cmd_kref, target_release_cmd_kref); -+ return kref_put_spinlock_irqsave(&se_cmd->cmd_kref, target_release_cmd_kref, -+ &se_sess->sess_cmd_lock); - } - EXPORT_SYMBOL(target_put_sess_cmd); - -diff --git a/drivers/watchdog/watchdog_dev.c b/drivers/watchdog/watchdog_dev.c -index 08b48bb..faf4e18 100644 ---- a/drivers/watchdog/watchdog_dev.c -+++ b/drivers/watchdog/watchdog_dev.c -@@ -523,6 +523,7 @@ int watchdog_dev_register(struct watchdog_device *watchdog) - int err, devno; - - if (watchdog->id == 0) { -+ old_wdd = watchdog; - watchdog_miscdev.parent = watchdog->parent; - err = misc_register(&watchdog_miscdev); - if (err != 0) { -@@ -531,9 +532,9 @@ int watchdog_dev_register(struct watchdog_device *watchdog) - if (err == -EBUSY) - pr_err("%s: a legacy watchdog module is probably present.\n", - watchdog->info->identity); -+ old_wdd = NULL; - return err; - } -- old_wdd = watchdog; - } - - /* Fill in the data structures */ -diff --git a/fs/ext4/mballoc.c b/fs/ext4/mballoc.c -index cf3025c..f3190ab 100644 ---- a/fs/ext4/mballoc.c -+++ b/fs/ext4/mballoc.c -@@ -1994,7 +1994,11 @@ repeat: - group = ac->ac_g_ex.fe_group; - - for (i = 0; i < ngroups; group++, i++) { -- if (group == ngroups) -+ /* -+ * Artificially restricted ngroups for non-extent -+ * files makes group > ngroups possible on first loop. -+ */ -+ if (group >= ngroups) - group = 0; - - /* This now checks without needing the buddy page */ -diff --git a/fs/namei.c b/fs/namei.c -index 57ae9c8..85e40d1 100644 ---- a/fs/namei.c -+++ b/fs/namei.c -@@ -2740,7 +2740,7 @@ static int do_last(struct nameidata *nd, struct path *path, - if (error) - return error; - -- audit_inode(name, dir, 0); -+ audit_inode(name, dir, LOOKUP_PARENT); - error = -EISDIR; - /* trailing slashes? */ - if (nd->last.name[nd->last.len]) -diff --git a/fs/nfsd/nfs4proc.c b/fs/nfsd/nfs4proc.c -index 8288b08..d401d01 100644 ---- a/fs/nfsd/nfs4proc.c -+++ b/fs/nfsd/nfs4proc.c -@@ -271,6 +271,7 @@ static __be32 - do_open_fhandle(struct svc_rqst *rqstp, struct svc_fh *current_fh, struct nfsd4_open *open) - { - __be32 status; -+ int accmode = 0; - - /* We don't know the target directory, and therefore can not - * set the change info -@@ -284,9 +285,19 @@ do_open_fhandle(struct svc_rqst *rqstp, struct svc_fh *current_fh, struct nfsd4_ - - open->op_truncate = (open->op_iattr.ia_valid & ATTR_SIZE) && - (open->op_iattr.ia_size == 0); -+ /* -+ * In the delegation case, the client is telling us about an -+ * open that it *already* performed locally, some time ago. We -+ * should let it succeed now if possible. -+ * -+ * In the case of a CLAIM_FH open, on the other hand, the client -+ * may be counting on us to enforce permissions (the Linux 4.1 -+ * client uses this for normal opens, for example). -+ */ -+ if (open->op_claim_type == NFS4_OPEN_CLAIM_DELEG_CUR_FH) -+ accmode = NFSD_MAY_OWNER_OVERRIDE; - -- status = do_open_permission(rqstp, current_fh, open, -- NFSD_MAY_OWNER_OVERRIDE); -+ status = do_open_permission(rqstp, current_fh, open, accmode); - - return status; - } -diff --git a/fs/nfsd/nfs4recover.c b/fs/nfsd/nfs4recover.c -index 899ca26..4e9a21d 100644 ---- a/fs/nfsd/nfs4recover.c -+++ b/fs/nfsd/nfs4recover.c -@@ -146,7 +146,7 @@ out_no_tfm: - * then disable recovery tracking. - */ - static void --legacy_recdir_name_error(int error) -+legacy_recdir_name_error(struct nfs4_client *clp, int error) - { - printk(KERN_ERR "NFSD: unable to generate recoverydir " - "name (%d).\n", error); -@@ -159,9 +159,7 @@ legacy_recdir_name_error(int error) - if (error == -ENOENT) { - printk(KERN_ERR "NFSD: disabling legacy clientid tracking. " - "Reboot recovery will not function correctly!\n"); -- -- /* the argument is ignored by the legacy exit function */ -- nfsd4_client_tracking_exit(NULL); -+ nfsd4_client_tracking_exit(clp->net); - } - } - -@@ -184,7 +182,7 @@ nfsd4_create_clid_dir(struct nfs4_client *clp) - - status = nfs4_make_rec_clidname(dname, &clp->cl_name); - if (status) -- return legacy_recdir_name_error(status); -+ return legacy_recdir_name_error(clp, status); - - status = nfs4_save_creds(&original_cred); - if (status < 0) -@@ -341,7 +339,7 @@ nfsd4_remove_clid_dir(struct nfs4_client *clp) - - status = nfs4_make_rec_clidname(dname, &clp->cl_name); - if (status) -- return legacy_recdir_name_error(status); -+ return legacy_recdir_name_error(clp, status); - - status = mnt_want_write_file(nn->rec_file); - if (status) -@@ -601,7 +599,7 @@ nfsd4_check_legacy_client(struct nfs4_client *clp) - - status = nfs4_make_rec_clidname(dname, &clp->cl_name); - if (status) { -- legacy_recdir_name_error(status); -+ legacy_recdir_name_error(clp, status); - return status; - } - -diff --git a/include/linux/audit.h b/include/linux/audit.h -index 5a6d718..b4086cf 100644 ---- a/include/linux/audit.h -+++ b/include/linux/audit.h -@@ -120,7 +120,7 @@ static inline void audit_syscall_entry(int arch, int major, unsigned long a0, - unsigned long a1, unsigned long a2, - unsigned long a3) - { -- if (unlikely(!audit_dummy_context())) -+ if (unlikely(current->audit_context)) - __audit_syscall_entry(arch, major, a0, a1, a2, a3); - } - static inline void audit_syscall_exit(void *pt_regs) -@@ -390,6 +390,11 @@ static inline void audit_ptrace(struct task_struct *t) - #define audit_signals 0 - #endif /* CONFIG_AUDITSYSCALL */ - -+static inline bool audit_loginuid_set(struct task_struct *tsk) -+{ -+ return uid_valid(audit_get_loginuid(tsk)); -+} -+ - #ifdef CONFIG_AUDIT - /* These are defined in audit.c */ - /* Public API */ -diff --git a/include/linux/kref.h b/include/linux/kref.h -index 4972e6e..7419c02 100644 ---- a/include/linux/kref.h -+++ b/include/linux/kref.h -@@ -19,6 +19,7 @@ - #include <linux/atomic.h> - #include <linux/kernel.h> - #include <linux/mutex.h> -+#include <linux/spinlock.h> - - struct kref { - atomic_t refcount; -@@ -95,6 +96,38 @@ static inline int kref_put(struct kref *kref, void (*release)(struct kref *kref) - return kref_sub(kref, 1, release); - } - -+/** -+ * kref_put_spinlock_irqsave - decrement refcount for object. -+ * @kref: object. -+ * @release: pointer to the function that will clean up the object when the -+ * last reference to the object is released. -+ * This pointer is required, and it is not acceptable to pass kfree -+ * in as this function. -+ * @lock: lock to take in release case -+ * -+ * Behaves identical to kref_put with one exception. If the reference count -+ * drops to zero, the lock will be taken atomically wrt dropping the reference -+ * count. The release function has to call spin_unlock() without _irqrestore. -+ */ -+static inline int kref_put_spinlock_irqsave(struct kref *kref, -+ void (*release)(struct kref *kref), -+ spinlock_t *lock) -+{ -+ unsigned long flags; -+ -+ WARN_ON(release == NULL); -+ if (atomic_add_unless(&kref->refcount, -1, 1)) -+ return 0; -+ spin_lock_irqsave(lock, flags); -+ if (atomic_dec_and_test(&kref->refcount)) { -+ release(kref); -+ local_irq_restore(flags); -+ return 1; -+ } -+ spin_unlock_irqrestore(lock, flags); -+ return 0; -+} -+ - static inline int kref_put_mutex(struct kref *kref, - void (*release)(struct kref *kref), - struct mutex *lock) -diff --git a/include/linux/time.h b/include/linux/time.h -index d4835df..afcdc4b 100644 ---- a/include/linux/time.h -+++ b/include/linux/time.h -@@ -117,14 +117,10 @@ static inline bool timespec_valid_strict(const struct timespec *ts) - - extern bool persistent_clock_exist; - --#ifdef ALWAYS_USE_PERSISTENT_CLOCK --#define has_persistent_clock() true --#else - static inline bool has_persistent_clock(void) - { - return persistent_clock_exist; - } --#endif - - extern void read_persistent_clock(struct timespec *ts); - extern void read_boot_clock(struct timespec *ts); -diff --git a/include/net/inet_frag.h b/include/net/inet_frag.h -index 0a1dcc2..ab3d0ac 100644 ---- a/include/net/inet_frag.h -+++ b/include/net/inet_frag.h -@@ -135,14 +135,15 @@ static inline int sum_frag_mem_limit(struct netns_frags *nf) - static inline void inet_frag_lru_move(struct inet_frag_queue *q) - { - spin_lock(&q->net->lru_lock); -- list_move_tail(&q->lru_list, &q->net->lru_list); -+ if (!list_empty(&q->lru_list)) -+ list_move_tail(&q->lru_list, &q->net->lru_list); - spin_unlock(&q->net->lru_lock); - } - - static inline void inet_frag_lru_del(struct inet_frag_queue *q) - { - spin_lock(&q->net->lru_lock); -- list_del(&q->lru_list); -+ list_del_init(&q->lru_list); - spin_unlock(&q->net->lru_lock); - } - -diff --git a/include/net/sock.h b/include/net/sock.h -index 14f6e9d..0be480a 100644 ---- a/include/net/sock.h -+++ b/include/net/sock.h -@@ -865,6 +865,18 @@ struct inet_hashinfo; - struct raw_hashinfo; - struct module; - -+/* -+ * caches using SLAB_DESTROY_BY_RCU should let .next pointer from nulls nodes -+ * un-modified. Special care is taken when initializing object to zero. -+ */ -+static inline void sk_prot_clear_nulls(struct sock *sk, int size) -+{ -+ if (offsetof(struct sock, sk_node.next) != 0) -+ memset(sk, 0, offsetof(struct sock, sk_node.next)); -+ memset(&sk->sk_node.pprev, 0, -+ size - offsetof(struct sock, sk_node.pprev)); -+} -+ - /* Networking protocol blocks we attach to sockets. - * socket layer -> transport layer interface - * transport -> network interface is defined by struct inet_proto -diff --git a/include/net/tcp.h b/include/net/tcp.h -index cf0694d..a345480 100644 ---- a/include/net/tcp.h -+++ b/include/net/tcp.h -@@ -1049,6 +1049,7 @@ static inline bool tcp_prequeue(struct sock *sk, struct sk_buff *skb) - skb_queue_len(&tp->ucopy.prequeue) == 0) - return false; - -+ skb_dst_force(skb); - __skb_queue_tail(&tp->ucopy.prequeue, skb); - tp->ucopy.memory += skb->truesize; - if (tp->ucopy.memory > sk->sk_rcvbuf) { -diff --git a/include/uapi/linux/audit.h b/include/uapi/linux/audit.h -index 9f096f1..9554a19 100644 ---- a/include/uapi/linux/audit.h -+++ b/include/uapi/linux/audit.h -@@ -246,6 +246,7 @@ - #define AUDIT_OBJ_TYPE 21 - #define AUDIT_OBJ_LEV_LOW 22 - #define AUDIT_OBJ_LEV_HIGH 23 -+#define AUDIT_LOGINUID_SET 24 - - /* These are ONLY useful when checking - * at syscall exit time (AUDIT_AT_EXIT). */ -diff --git a/include/uapi/linux/if_cablemodem.h b/include/uapi/linux/if_cablemodem.h -index 9ca1007..ee6b3c4 100644 ---- a/include/uapi/linux/if_cablemodem.h -+++ b/include/uapi/linux/if_cablemodem.h -@@ -12,11 +12,11 @@ - */ - - /* some useful defines for sb1000.c e cmconfig.c - fv */ --#define SIOCGCMSTATS SIOCDEVPRIVATE+0 /* get cable modem stats */ --#define SIOCGCMFIRMWARE SIOCDEVPRIVATE+1 /* get cm firmware version */ --#define SIOCGCMFREQUENCY SIOCDEVPRIVATE+2 /* get cable modem frequency */ --#define SIOCSCMFREQUENCY SIOCDEVPRIVATE+3 /* set cable modem frequency */ --#define SIOCGCMPIDS SIOCDEVPRIVATE+4 /* get cable modem PIDs */ --#define SIOCSCMPIDS SIOCDEVPRIVATE+5 /* set cable modem PIDs */ -+#define SIOCGCMSTATS (SIOCDEVPRIVATE+0) /* get cable modem stats */ -+#define SIOCGCMFIRMWARE (SIOCDEVPRIVATE+1) /* get cm firmware version */ -+#define SIOCGCMFREQUENCY (SIOCDEVPRIVATE+2) /* get cable modem frequency */ -+#define SIOCSCMFREQUENCY (SIOCDEVPRIVATE+3) /* set cable modem frequency */ -+#define SIOCGCMPIDS (SIOCDEVPRIVATE+4) /* get cable modem PIDs */ -+#define SIOCSCMPIDS (SIOCDEVPRIVATE+5) /* set cable modem PIDs */ - - #endif -diff --git a/include/uapi/linux/virtio_net.h b/include/uapi/linux/virtio_net.h -index a5a8c88..c520203 100644 ---- a/include/uapi/linux/virtio_net.h -+++ b/include/uapi/linux/virtio_net.h -@@ -191,7 +191,7 @@ struct virtio_net_ctrl_mac { - * specified. - */ - struct virtio_net_ctrl_mq { -- u16 virtqueue_pairs; -+ __u16 virtqueue_pairs; - }; - - #define VIRTIO_NET_CTRL_MQ 4 -diff --git a/ipc/shm.c b/ipc/shm.c -index 34af1fe..7e199fa 100644 ---- a/ipc/shm.c -+++ b/ipc/shm.c -@@ -493,7 +493,13 @@ static int newseg(struct ipc_namespace *ns, struct ipc_params *params) - if (shmflg & SHM_HUGETLB) { - struct hstate *hs = hstate_sizelog((shmflg >> SHM_HUGE_SHIFT) - & SHM_HUGE_MASK); -- size_t hugesize = ALIGN(size, huge_page_size(hs)); -+ size_t hugesize; -+ -+ if (!hs) { -+ error = -EINVAL; -+ goto no_file; -+ } -+ hugesize = ALIGN(size, huge_page_size(hs)); - - /* hugetlb_file_setup applies strict accounting */ - if (shmflg & SHM_NORESERVE) -diff --git a/kernel/auditfilter.c b/kernel/auditfilter.c -index f9fc54b..2bf508d 100644 ---- a/kernel/auditfilter.c -+++ b/kernel/auditfilter.c -@@ -345,6 +345,12 @@ static struct audit_entry *audit_rule_to_entry(struct audit_rule *rule) - f->uid = INVALID_UID; - f->gid = INVALID_GID; - -+ /* Support legacy tests for a valid loginuid */ -+ if ((f->type == AUDIT_LOGINUID) && (f->val == 4294967295U)) { -+ f->type = AUDIT_LOGINUID_SET; -+ f->val = 0; -+ } -+ - err = -EINVAL; - if (f->op == Audit_bad) - goto exit_free; -@@ -352,6 +358,12 @@ static struct audit_entry *audit_rule_to_entry(struct audit_rule *rule) - switch(f->type) { - default: - goto exit_free; -+ case AUDIT_LOGINUID_SET: -+ if ((f->val != 0) && (f->val != 1)) -+ goto exit_free; -+ if (f->op != Audit_not_equal && f->op != Audit_equal) -+ goto exit_free; -+ break; - case AUDIT_UID: - case AUDIT_EUID: - case AUDIT_SUID: -@@ -459,7 +471,20 @@ static struct audit_entry *audit_data_to_entry(struct audit_rule_data *data, - f->gid = INVALID_GID; - f->lsm_str = NULL; - f->lsm_rule = NULL; -- switch(f->type) { -+ -+ /* Support legacy tests for a valid loginuid */ -+ if ((f->type == AUDIT_LOGINUID) && (f->val == 4294967295U)) { -+ f->type = AUDIT_LOGINUID_SET; -+ f->val = 0; -+ } -+ -+ switch (f->type) { -+ case AUDIT_LOGINUID_SET: -+ if ((f->val != 0) && (f->val != 1)) -+ goto exit_free; -+ if (f->op != Audit_not_equal && f->op != Audit_equal) -+ goto exit_free; -+ break; - case AUDIT_UID: - case AUDIT_EUID: - case AUDIT_SUID: -@@ -1378,6 +1403,10 @@ static int audit_filter_user_rules(struct audit_krule *rule, - result = audit_uid_comparator(audit_get_loginuid(current), - f->op, f->uid); - break; -+ case AUDIT_LOGINUID_SET: -+ result = audit_comparator(audit_loginuid_set(current), -+ f->op, f->val); -+ break; - case AUDIT_SUBJ_USER: - case AUDIT_SUBJ_ROLE: - case AUDIT_SUBJ_TYPE: -diff --git a/kernel/auditsc.c b/kernel/auditsc.c -index a371f85..c4b72b0 100644 ---- a/kernel/auditsc.c -+++ b/kernel/auditsc.c -@@ -742,6 +742,9 @@ static int audit_filter_rules(struct task_struct *tsk, - if (ctx) - result = audit_uid_comparator(tsk->loginuid, f->op, f->uid); - break; -+ case AUDIT_LOGINUID_SET: -+ result = audit_comparator(audit_loginuid_set(tsk), f->op, f->val); -+ break; - case AUDIT_SUBJ_USER: - case AUDIT_SUBJ_ROLE: - case AUDIT_SUBJ_TYPE: -@@ -2309,7 +2312,7 @@ int audit_set_loginuid(kuid_t loginuid) - unsigned int sessionid; - - #ifdef CONFIG_AUDIT_LOGINUID_IMMUTABLE -- if (uid_valid(task->loginuid)) -+ if (audit_loginuid_set(task)) - return -EPERM; - #else /* CONFIG_AUDIT_LOGINUID_IMMUTABLE */ - if (!capable(CAP_AUDIT_CONTROL)) -diff --git a/kernel/kmod.c b/kernel/kmod.c -index 56dd349..8985c87 100644 ---- a/kernel/kmod.c -+++ b/kernel/kmod.c -@@ -570,6 +570,11 @@ int call_usermodehelper_exec(struct subprocess_info *sub_info, int wait) - int retval = 0; - - helper_lock(); -+ if (!sub_info->path) { -+ retval = -EINVAL; -+ goto out; -+ } -+ - if (sub_info->path[0] == '\0') - goto out; - -diff --git a/kernel/sched/cputime.c b/kernel/sched/cputime.c -index e93cca9..6af50ad 100644 ---- a/kernel/sched/cputime.c -+++ b/kernel/sched/cputime.c -@@ -521,18 +521,49 @@ EXPORT_SYMBOL_GPL(vtime_account_irq_enter); - - #else /* !CONFIG_VIRT_CPU_ACCOUNTING */ - --static cputime_t scale_stime(cputime_t stime, cputime_t rtime, cputime_t total) -+/* -+ * Perform (stime * rtime) / total, but avoid multiplication overflow by -+ * loosing precision when the numbers are big. -+ */ -+static cputime_t scale_stime(u64 stime, u64 rtime, u64 total) - { -- u64 temp = (__force u64) rtime; -+ u64 scaled; - -- temp *= (__force u64) stime; -+ for (;;) { -+ /* Make sure "rtime" is the bigger of stime/rtime */ -+ if (stime > rtime) { -+ u64 tmp = rtime; rtime = stime; stime = tmp; -+ } - -- if (sizeof(cputime_t) == 4) -- temp = div_u64(temp, (__force u32) total); -- else -- temp = div64_u64(temp, (__force u64) total); -+ /* Make sure 'total' fits in 32 bits */ -+ if (total >> 32) -+ goto drop_precision; -+ -+ /* Does rtime (and thus stime) fit in 32 bits? */ -+ if (!(rtime >> 32)) -+ break; - -- return (__force cputime_t) temp; -+ /* Can we just balance rtime/stime rather than dropping bits? */ -+ if (stime >> 31) -+ goto drop_precision; -+ -+ /* We can grow stime and shrink rtime and try to make them both fit */ -+ stime <<= 1; -+ rtime >>= 1; -+ continue; -+ -+drop_precision: -+ /* We drop from rtime, it has more bits than stime */ -+ rtime >>= 1; -+ total >>= 1; -+ } -+ -+ /* -+ * Make sure gcc understands that this is a 32x32->64 multiply, -+ * followed by a 64/32->64 divide. -+ */ -+ scaled = div_u64((u64) (u32) stime * (u64) (u32) rtime, (u32)total); -+ return (__force cputime_t) scaled; - } - - /* -@@ -543,7 +574,7 @@ static void cputime_adjust(struct task_cputime *curr, - struct cputime *prev, - cputime_t *ut, cputime_t *st) - { -- cputime_t rtime, stime, total; -+ cputime_t rtime, stime, utime, total; - - stime = curr->stime; - total = stime + curr->utime; -@@ -560,10 +591,22 @@ static void cputime_adjust(struct task_cputime *curr, - */ - rtime = nsecs_to_cputime(curr->sum_exec_runtime); - -- if (total) -- stime = scale_stime(stime, rtime, total); -- else -+ /* -+ * Update userspace visible utime/stime values only if actual execution -+ * time is bigger than already exported. Note that can happen, that we -+ * provided bigger values due to scaling inaccuracy on big numbers. -+ */ -+ if (prev->stime + prev->utime >= rtime) -+ goto out; -+ -+ if (total) { -+ stime = scale_stime((__force u64)stime, -+ (__force u64)rtime, (__force u64)total); -+ utime = rtime - stime; -+ } else { - stime = rtime; -+ utime = 0; -+ } - - /* - * If the tick based count grows faster than the scheduler one, -@@ -571,8 +614,9 @@ static void cputime_adjust(struct task_cputime *curr, - * Let's enforce monotonicity. - */ - prev->stime = max(prev->stime, stime); -- prev->utime = max(prev->utime, rtime - prev->stime); -+ prev->utime = max(prev->utime, utime); - -+out: - *ut = prev->utime; - *st = prev->stime; - } -diff --git a/kernel/time/Kconfig b/kernel/time/Kconfig -index 24510d8..b696922 100644 ---- a/kernel/time/Kconfig -+++ b/kernel/time/Kconfig -@@ -12,11 +12,6 @@ config CLOCKSOURCE_WATCHDOG - config ARCH_CLOCKSOURCE_DATA - bool - --# Platforms has a persistent clock --config ALWAYS_USE_PERSISTENT_CLOCK -- bool -- default n -- - # Timekeeping vsyscall support - config GENERIC_TIME_VSYSCALL - bool -diff --git a/kernel/time/tick-sched.c b/kernel/time/tick-sched.c -index a19a399..e717ad9 100644 ---- a/kernel/time/tick-sched.c -+++ b/kernel/time/tick-sched.c -@@ -904,7 +904,7 @@ void tick_cancel_sched_timer(int cpu) - hrtimer_cancel(&ts->sched_timer); - # endif - -- ts->nohz_mode = NOHZ_MODE_INACTIVE; -+ memset(ts, 0, sizeof(*ts)); - } - #endif - -diff --git a/kernel/timer.c b/kernel/timer.c -index dbf7a78..1b399c8 100644 ---- a/kernel/timer.c -+++ b/kernel/timer.c -@@ -1678,12 +1678,12 @@ static int __cpuinit init_timers_cpu(int cpu) - boot_done = 1; - base = &boot_tvec_bases; - } -+ spin_lock_init(&base->lock); - tvec_base_done[cpu] = 1; - } else { - base = per_cpu(tvec_bases, cpu); - } - -- spin_lock_init(&base->lock); - - for (j = 0; j < TVN_SIZE; j++) { - INIT_LIST_HEAD(base->tv5.vec + j); -diff --git a/kernel/trace/trace_events_filter.c b/kernel/trace/trace_events_filter.c -index e5b0ca8..5a8a53e 100644 ---- a/kernel/trace/trace_events_filter.c -+++ b/kernel/trace/trace_events_filter.c -@@ -777,7 +777,11 @@ static int filter_set_pred(struct event_filter *filter, - - static void __free_preds(struct event_filter *filter) - { -+ int i; -+ - if (filter->preds) { -+ for (i = 0; i < filter->n_preds; i++) -+ kfree(filter->preds[i].ops); - kfree(filter->preds); - filter->preds = NULL; - } -diff --git a/mm/mmap.c b/mm/mmap.c -index e17fc06..0dceed8 100644 ---- a/mm/mmap.c -+++ b/mm/mmap.c -@@ -1331,9 +1331,13 @@ SYSCALL_DEFINE6(mmap_pgoff, unsigned long, addr, unsigned long, len, - len = ALIGN(len, huge_page_size(hstate_file(file))); - } else if (flags & MAP_HUGETLB) { - struct user_struct *user = NULL; -+ struct hstate *hs = hstate_sizelog((flags >> MAP_HUGE_SHIFT) & -+ SHM_HUGE_MASK); - -- len = ALIGN(len, huge_page_size(hstate_sizelog( -- (flags >> MAP_HUGE_SHIFT) & MAP_HUGE_MASK))); -+ if (!hs) -+ return -EINVAL; -+ -+ len = ALIGN(len, huge_page_size(hs)); - /* - * VM_NORESERVE is used because the reservations will be - * taken when vm_ops->mmap() is called -diff --git a/net/8021q/vlan_dev.c b/net/8021q/vlan_dev.c -index 19cf81b..63bd98c 100644 ---- a/net/8021q/vlan_dev.c -+++ b/net/8021q/vlan_dev.c -@@ -627,7 +627,7 @@ static netdev_features_t vlan_dev_fix_features(struct net_device *dev, - netdev_features_t features) - { - struct net_device *real_dev = vlan_dev_priv(dev)->real_dev; -- u32 old_features = features; -+ netdev_features_t old_features = features; - - features &= real_dev->vlan_features; - features |= NETIF_F_RXCSUM; -diff --git a/net/bridge/br_stp_timer.c b/net/bridge/br_stp_timer.c -index c3530a8..950663d 100644 ---- a/net/bridge/br_stp_timer.c -+++ b/net/bridge/br_stp_timer.c -@@ -107,7 +107,7 @@ static void br_tcn_timer_expired(unsigned long arg) - - br_debug(br, "tcn timer expired\n"); - spin_lock(&br->lock); -- if (br->dev->flags & IFF_UP) { -+ if (!br_is_root_bridge(br) && (br->dev->flags & IFF_UP)) { - br_transmit_tcn(br); - - mod_timer(&br->tcn_timer,jiffies + br->bridge_hello_time); -diff --git a/net/core/dev.c b/net/core/dev.c -index b24ab0e9..9a278e9 100644 ---- a/net/core/dev.c -+++ b/net/core/dev.c -@@ -2458,7 +2458,7 @@ EXPORT_SYMBOL(netif_skb_features); - * 2. skb is fragmented and the device does not support SG. - */ - static inline int skb_needs_linearize(struct sk_buff *skb, -- int features) -+ netdev_features_t features) - { - return skb_is_nonlinear(skb) && - ((skb_has_frag_list(skb) && -diff --git a/net/core/ethtool.c b/net/core/ethtool.c -index 3e9b2c3..41f4bdf 100644 ---- a/net/core/ethtool.c -+++ b/net/core/ethtool.c -@@ -1416,7 +1416,7 @@ int dev_ethtool(struct net *net, struct ifreq *ifr) - void __user *useraddr = ifr->ifr_data; - u32 ethcmd; - int rc; -- u32 old_features; -+ netdev_features_t old_features; - - if (!dev || !netif_device_present(dev)) - return -ENODEV; -diff --git a/net/core/sock.c b/net/core/sock.c -index b261a79..1432266 100644 ---- a/net/core/sock.c -+++ b/net/core/sock.c -@@ -1209,18 +1209,6 @@ static void sock_copy(struct sock *nsk, const struct sock *osk) - #endif - } - --/* -- * caches using SLAB_DESTROY_BY_RCU should let .next pointer from nulls nodes -- * un-modified. Special care is taken when initializing object to zero. -- */ --static inline void sk_prot_clear_nulls(struct sock *sk, int size) --{ -- if (offsetof(struct sock, sk_node.next) != 0) -- memset(sk, 0, offsetof(struct sock, sk_node.next)); -- memset(&sk->sk_node.pprev, 0, -- size - offsetof(struct sock, sk_node.pprev)); --} -- - void sk_prot_clear_portaddr_nulls(struct sock *sk, int size) - { - unsigned long nulls1, nulls2; -diff --git a/net/ipv4/inet_fragment.c b/net/ipv4/inet_fragment.c -index f4fd23d..3211914 100644 ---- a/net/ipv4/inet_fragment.c -+++ b/net/ipv4/inet_fragment.c -@@ -257,6 +257,7 @@ static struct inet_frag_queue *inet_frag_alloc(struct netns_frags *nf, - setup_timer(&q->timer, f->frag_expire, (unsigned long)q); - spin_lock_init(&q->lock); - atomic_set(&q->refcnt, 1); -+ INIT_LIST_HEAD(&q->lru_list); - - return q; - } -diff --git a/net/ipv4/tcp_minisocks.c b/net/ipv4/tcp_minisocks.c -index b83a49c..2f672e7 100644 ---- a/net/ipv4/tcp_minisocks.c -+++ b/net/ipv4/tcp_minisocks.c -@@ -583,8 +583,13 @@ struct sock *tcp_check_req(struct sock *sk, struct sk_buff *skb, - * - * Note that even if there is new data in the SYN packet - * they will be thrown away too. -+ * -+ * Reset timer after retransmitting SYNACK, similar to -+ * the idea of fast retransmit in recovery. - */ -- inet_rtx_syn_ack(sk, req); -+ if (!inet_rtx_syn_ack(sk, req)) -+ req->expires = min(TCP_TIMEOUT_INIT << req->num_timeout, -+ TCP_RTO_MAX) + jiffies; - return NULL; - } - -diff --git a/net/ipv6/ip6_gre.c b/net/ipv6/ip6_gre.c -index e4efffe..95d13c7 100644 ---- a/net/ipv6/ip6_gre.c -+++ b/net/ipv6/ip6_gre.c -@@ -1135,6 +1135,7 @@ static int ip6gre_tunnel_ioctl(struct net_device *dev, - } - if (t == NULL) - t = netdev_priv(dev); -+ memset(&p, 0, sizeof(p)); - ip6gre_tnl_parm_to_user(&p, &t->parms); - if (copy_to_user(ifr->ifr_ifru.ifru_data, &p, sizeof(p))) - err = -EFAULT; -@@ -1182,6 +1183,7 @@ static int ip6gre_tunnel_ioctl(struct net_device *dev, - if (t) { - err = 0; - -+ memset(&p, 0, sizeof(p)); - ip6gre_tnl_parm_to_user(&p, &t->parms); - if (copy_to_user(ifr->ifr_ifru.ifru_data, &p, sizeof(p))) - err = -EFAULT; -diff --git a/net/ipv6/tcp_ipv6.c b/net/ipv6/tcp_ipv6.c -index 46a5be8..0fce928 100644 ---- a/net/ipv6/tcp_ipv6.c -+++ b/net/ipv6/tcp_ipv6.c -@@ -1937,6 +1937,17 @@ void tcp6_proc_exit(struct net *net) - } - #endif - -+static void tcp_v6_clear_sk(struct sock *sk, int size) -+{ -+ struct inet_sock *inet = inet_sk(sk); -+ -+ /* we do not want to clear pinet6 field, because of RCU lookups */ -+ sk_prot_clear_nulls(sk, offsetof(struct inet_sock, pinet6)); -+ -+ size -= offsetof(struct inet_sock, pinet6) + sizeof(inet->pinet6); -+ memset(&inet->pinet6 + 1, 0, size); -+} -+ - struct proto tcpv6_prot = { - .name = "TCPv6", - .owner = THIS_MODULE, -@@ -1980,6 +1991,7 @@ struct proto tcpv6_prot = { - #ifdef CONFIG_MEMCG_KMEM - .proto_cgroup = tcp_proto_cgroup, - #endif -+ .clear_sk = tcp_v6_clear_sk, - }; - - static const struct inet6_protocol tcpv6_protocol = { -diff --git a/net/ipv6/udp.c b/net/ipv6/udp.c -index d8e5e85..27f0f8e 100644 ---- a/net/ipv6/udp.c -+++ b/net/ipv6/udp.c -@@ -1422,6 +1422,17 @@ void udp6_proc_exit(struct net *net) { - } - #endif /* CONFIG_PROC_FS */ - -+void udp_v6_clear_sk(struct sock *sk, int size) -+{ -+ struct inet_sock *inet = inet_sk(sk); -+ -+ /* we do not want to clear pinet6 field, because of RCU lookups */ -+ sk_prot_clear_portaddr_nulls(sk, offsetof(struct inet_sock, pinet6)); -+ -+ size -= offsetof(struct inet_sock, pinet6) + sizeof(inet->pinet6); -+ memset(&inet->pinet6 + 1, 0, size); -+} -+ - /* ------------------------------------------------------------------------ */ - - struct proto udpv6_prot = { -@@ -1452,7 +1463,7 @@ struct proto udpv6_prot = { - .compat_setsockopt = compat_udpv6_setsockopt, - .compat_getsockopt = compat_udpv6_getsockopt, - #endif -- .clear_sk = sk_prot_clear_portaddr_nulls, -+ .clear_sk = udp_v6_clear_sk, - }; - - static struct inet_protosw udpv6_protosw = { -diff --git a/net/ipv6/udp_impl.h b/net/ipv6/udp_impl.h -index d757104..4691ed5 100644 ---- a/net/ipv6/udp_impl.h -+++ b/net/ipv6/udp_impl.h -@@ -31,6 +31,8 @@ extern int udpv6_recvmsg(struct kiocb *iocb, struct sock *sk, - extern int udpv6_queue_rcv_skb(struct sock * sk, struct sk_buff *skb); - extern void udpv6_destroy_sock(struct sock *sk); - -+extern void udp_v6_clear_sk(struct sock *sk, int size); -+ - #ifdef CONFIG_PROC_FS - extern int udp6_seq_show(struct seq_file *seq, void *v); - #endif -diff --git a/net/ipv6/udplite.c b/net/ipv6/udplite.c -index 1d08e21..dfcc4be 100644 ---- a/net/ipv6/udplite.c -+++ b/net/ipv6/udplite.c -@@ -56,7 +56,7 @@ struct proto udplitev6_prot = { - .compat_setsockopt = compat_udpv6_setsockopt, - .compat_getsockopt = compat_udpv6_getsockopt, - #endif -- .clear_sk = sk_prot_clear_portaddr_nulls, -+ .clear_sk = udp_v6_clear_sk, - }; - - static struct inet_protosw udplite6_protosw = { -diff --git a/net/ipv6/xfrm6_policy.c b/net/ipv6/xfrm6_policy.c -index 4ef7bdb..23ed03d 100644 ---- a/net/ipv6/xfrm6_policy.c -+++ b/net/ipv6/xfrm6_policy.c -@@ -103,8 +103,10 @@ static int xfrm6_fill_dst(struct xfrm_dst *xdst, struct net_device *dev, - dev_hold(dev); - - xdst->u.rt6.rt6i_idev = in6_dev_get(dev); -- if (!xdst->u.rt6.rt6i_idev) -+ if (!xdst->u.rt6.rt6i_idev) { -+ dev_put(dev); - return -ENODEV; -+ } - - rt6_transfer_peer(&xdst->u.rt6, rt); - -diff --git a/net/mac802154/mac802154.h b/net/mac802154/mac802154.h -index a4dcaf1..703c121 100644 ---- a/net/mac802154/mac802154.h -+++ b/net/mac802154/mac802154.h -@@ -90,7 +90,7 @@ struct mac802154_sub_if_data { - - #define MAC802154_MAX_XMIT_ATTEMPTS 3 - --#define MAC802154_CHAN_NONE (~(u8)0) /* No channel is assigned */ -+#define MAC802154_CHAN_NONE 0xff /* No channel is assigned */ - - extern struct ieee802154_reduced_mlme_ops mac802154_mlme_reduced; - extern struct ieee802154_mlme_ops mac802154_mlme_wpan; -diff --git a/net/packet/af_packet.c b/net/packet/af_packet.c -index 1d6793d..f83e172 100644 ---- a/net/packet/af_packet.c -+++ b/net/packet/af_packet.c -@@ -693,36 +693,33 @@ static void prb_open_block(struct tpacket_kbdq_core *pkc1, - - smp_rmb(); - -- if (likely(TP_STATUS_KERNEL == BLOCK_STATUS(pbd1))) { -+ /* We could have just memset this but we will lose the -+ * flexibility of making the priv area sticky -+ */ - -- /* We could have just memset this but we will lose the -- * flexibility of making the priv area sticky -- */ -- BLOCK_SNUM(pbd1) = pkc1->knxt_seq_num++; -- BLOCK_NUM_PKTS(pbd1) = 0; -- BLOCK_LEN(pbd1) = BLK_PLUS_PRIV(pkc1->blk_sizeof_priv); -- getnstimeofday(&ts); -- h1->ts_first_pkt.ts_sec = ts.tv_sec; -- h1->ts_first_pkt.ts_nsec = ts.tv_nsec; -- pkc1->pkblk_start = (char *)pbd1; -- pkc1->nxt_offset = pkc1->pkblk_start + BLK_PLUS_PRIV(pkc1->blk_sizeof_priv); -- BLOCK_O2FP(pbd1) = (__u32)BLK_PLUS_PRIV(pkc1->blk_sizeof_priv); -- BLOCK_O2PRIV(pbd1) = BLK_HDR_LEN; -- pbd1->version = pkc1->version; -- pkc1->prev = pkc1->nxt_offset; -- pkc1->pkblk_end = pkc1->pkblk_start + pkc1->kblk_size; -- prb_thaw_queue(pkc1); -- _prb_refresh_rx_retire_blk_timer(pkc1); -+ BLOCK_SNUM(pbd1) = pkc1->knxt_seq_num++; -+ BLOCK_NUM_PKTS(pbd1) = 0; -+ BLOCK_LEN(pbd1) = BLK_PLUS_PRIV(pkc1->blk_sizeof_priv); - -- smp_wmb(); -+ getnstimeofday(&ts); - -- return; -- } -+ h1->ts_first_pkt.ts_sec = ts.tv_sec; -+ h1->ts_first_pkt.ts_nsec = ts.tv_nsec; - -- WARN(1, "ERROR block:%p is NOT FREE status:%d kactive_blk_num:%d\n", -- pbd1, BLOCK_STATUS(pbd1), pkc1->kactive_blk_num); -- dump_stack(); -- BUG(); -+ pkc1->pkblk_start = (char *)pbd1; -+ pkc1->nxt_offset = pkc1->pkblk_start + BLK_PLUS_PRIV(pkc1->blk_sizeof_priv); -+ -+ BLOCK_O2FP(pbd1) = (__u32)BLK_PLUS_PRIV(pkc1->blk_sizeof_priv); -+ BLOCK_O2PRIV(pbd1) = BLK_HDR_LEN; -+ -+ pbd1->version = pkc1->version; -+ pkc1->prev = pkc1->nxt_offset; -+ pkc1->pkblk_end = pkc1->pkblk_start + pkc1->kblk_size; -+ -+ prb_thaw_queue(pkc1); -+ _prb_refresh_rx_retire_blk_timer(pkc1); -+ -+ smp_wmb(); - } - - /* -@@ -813,10 +810,6 @@ static void prb_retire_current_block(struct tpacket_kbdq_core *pkc, - prb_close_block(pkc, pbd, po, status); - return; - } -- -- WARN(1, "ERROR-pbd[%d]:%p\n", pkc->kactive_blk_num, pbd); -- dump_stack(); -- BUG(); - } - - static int prb_curr_blk_in_use(struct tpacket_kbdq_core *pkc, -diff --git a/net/sched/act_ipt.c b/net/sched/act_ipt.c -index e0f6de6..60d88b6 100644 ---- a/net/sched/act_ipt.c -+++ b/net/sched/act_ipt.c -@@ -8,7 +8,7 @@ - * as published by the Free Software Foundation; either version - * 2 of the License, or (at your option) any later version. - * -- * Copyright: Jamal Hadi Salim (2002-4) -+ * Copyright: Jamal Hadi Salim (2002-13) - */ - - #include <linux/types.h> -@@ -303,17 +303,44 @@ static struct tc_action_ops act_ipt_ops = { - .walk = tcf_generic_walker - }; - --MODULE_AUTHOR("Jamal Hadi Salim(2002-4)"); -+static struct tc_action_ops act_xt_ops = { -+ .kind = "xt", -+ .hinfo = &ipt_hash_info, -+ .type = TCA_ACT_IPT, -+ .capab = TCA_CAP_NONE, -+ .owner = THIS_MODULE, -+ .act = tcf_ipt, -+ .dump = tcf_ipt_dump, -+ .cleanup = tcf_ipt_cleanup, -+ .lookup = tcf_hash_search, -+ .init = tcf_ipt_init, -+ .walk = tcf_generic_walker -+}; -+ -+MODULE_AUTHOR("Jamal Hadi Salim(2002-13)"); - MODULE_DESCRIPTION("Iptables target actions"); - MODULE_LICENSE("GPL"); -+MODULE_ALIAS("act_xt"); - - static int __init ipt_init_module(void) - { -- return tcf_register_action(&act_ipt_ops); -+ int ret1, ret2; -+ ret1 = tcf_register_action(&act_xt_ops); -+ if (ret1 < 0) -+ printk("Failed to load xt action\n"); -+ ret2 = tcf_register_action(&act_ipt_ops); -+ if (ret2 < 0) -+ printk("Failed to load ipt action\n"); -+ -+ if (ret1 < 0 && ret2 < 0) -+ return ret1; -+ else -+ return 0; - } - - static void __exit ipt_cleanup_module(void) - { -+ tcf_unregister_action(&act_xt_ops); - tcf_unregister_action(&act_ipt_ops); - } - -diff --git a/net/vmw_vsock/af_vsock.c b/net/vmw_vsock/af_vsock.c -index 7f93e2a..2e330e8 100644 ---- a/net/vmw_vsock/af_vsock.c -+++ b/net/vmw_vsock/af_vsock.c -@@ -165,7 +165,7 @@ static struct list_head vsock_bind_table[VSOCK_HASH_SIZE + 1]; - static struct list_head vsock_connected_table[VSOCK_HASH_SIZE]; - static DEFINE_SPINLOCK(vsock_table_lock); - --static __init void vsock_init_tables(void) -+static void vsock_init_tables(void) - { - int i; - -diff --git a/sound/pci/hda/hda_codec.c b/sound/pci/hda/hda_codec.c -index 4aba764..c414cdd 100644 ---- a/sound/pci/hda/hda_codec.c -+++ b/sound/pci/hda/hda_codec.c -@@ -681,6 +681,9 @@ int snd_hda_queue_unsol_event(struct hda_bus *bus, u32 res, u32 res_ex) - struct hda_bus_unsolicited *unsol; - unsigned int wp; - -+ if (!bus || !bus->workq) -+ return 0; -+ - trace_hda_unsol_event(bus, res, res_ex); - unsol = bus->unsol; - if (!unsol) -@@ -1577,7 +1580,7 @@ void snd_hda_codec_setup_stream(struct hda_codec *codec, hda_nid_t nid, - "NID=0x%x, stream=0x%x, channel=%d, format=0x%x\n", - nid, stream_tag, channel_id, format); - p = get_hda_cvt_setup(codec, nid); -- if (!p || p->active) -+ if (!p) - return; - - if (codec->pcm_format_first) -@@ -1624,7 +1627,7 @@ void __snd_hda_codec_cleanup_stream(struct hda_codec *codec, hda_nid_t nid, - - snd_printdd("hda_codec_cleanup_stream: NID=0x%x\n", nid); - p = get_hda_cvt_setup(codec, nid); -- if (p && p->active) { -+ if (p) { - /* here we just clear the active flag when do_now isn't set; - * actual clean-ups will be done later in - * purify_inactive_streams() called from snd_hda_codec_prpapre() -diff --git a/sound/pci/hda/patch_conexant.c b/sound/pci/hda/patch_conexant.c -index 2a89d1ee..1e5a30f 100644 ---- a/sound/pci/hda/patch_conexant.c -+++ b/sound/pci/hda/patch_conexant.c -@@ -64,6 +64,7 @@ struct conexant_spec { - /* extra EAPD pins */ - unsigned int num_eapds; - hda_nid_t eapds[4]; -+ bool dynamic_eapd; - - #ifdef ENABLE_CXT_STATIC_QUIRKS - const struct snd_kcontrol_new *mixers[5]; -@@ -3152,7 +3153,7 @@ static void cx_auto_parse_eapd(struct hda_codec *codec) - * thus it might control over all pins. - */ - if (spec->num_eapds > 2) -- spec->gen.own_eapd_ctl = 1; -+ spec->dynamic_eapd = 1; - } - - static void cx_auto_turn_eapd(struct hda_codec *codec, int num_pins, -@@ -3191,6 +3192,15 @@ static int cx_auto_build_controls(struct hda_codec *codec) - return 0; - } - -+static int cx_auto_init(struct hda_codec *codec) -+{ -+ struct conexant_spec *spec = codec->spec; -+ snd_hda_gen_init(codec); -+ if (!spec->dynamic_eapd) -+ cx_auto_turn_eapd(codec, spec->num_eapds, spec->eapds, true); -+ return 0; -+} -+ - static void cx_auto_free(struct hda_codec *codec) - { - snd_hda_detach_beep_device(codec); -@@ -3200,7 +3210,7 @@ static void cx_auto_free(struct hda_codec *codec) - static const struct hda_codec_ops cx_auto_patch_ops = { - .build_controls = cx_auto_build_controls, - .build_pcms = snd_hda_gen_build_pcms, -- .init = snd_hda_gen_init, -+ .init = cx_auto_init, - .free = cx_auto_free, - .unsol_event = snd_hda_jack_unsol_event, - #ifdef CONFIG_PM -@@ -3350,7 +3360,8 @@ static int patch_conexant_auto(struct hda_codec *codec) - - cx_auto_parse_beep(codec); - cx_auto_parse_eapd(codec); -- if (spec->gen.own_eapd_ctl) -+ spec->gen.own_eapd_ctl = 1; -+ if (spec->dynamic_eapd) - spec->gen.vmaster_mute.hook = cx_auto_vmaster_hook; - - switch (codec->vendor_id) { -diff --git a/sound/soc/codecs/da7213.c b/sound/soc/codecs/da7213.c -index 41230ad..4a6f1da 100644 ---- a/sound/soc/codecs/da7213.c -+++ b/sound/soc/codecs/da7213.c -@@ -1488,17 +1488,17 @@ static int da7213_probe(struct snd_soc_codec *codec) - DA7213_DMIC_DATA_SEL_SHIFT); - break; - } -- switch (pdata->dmic_data_sel) { -+ switch (pdata->dmic_samplephase) { - case DA7213_DMIC_SAMPLE_ON_CLKEDGE: - case DA7213_DMIC_SAMPLE_BETWEEN_CLKEDGE: -- dmic_cfg |= (pdata->dmic_data_sel << -+ dmic_cfg |= (pdata->dmic_samplephase << - DA7213_DMIC_SAMPLEPHASE_SHIFT); - break; - } -- switch (pdata->dmic_data_sel) { -+ switch (pdata->dmic_clk_rate) { - case DA7213_DMIC_CLK_3_0MHZ: - case DA7213_DMIC_CLK_1_5MHZ: -- dmic_cfg |= (pdata->dmic_data_sel << -+ dmic_cfg |= (pdata->dmic_clk_rate << - DA7213_DMIC_CLK_RATE_SHIFT); - break; - } -diff --git a/sound/soc/codecs/wm8994.c b/sound/soc/codecs/wm8994.c -index c9bd445..e5f96c9 100644 ---- a/sound/soc/codecs/wm8994.c -+++ b/sound/soc/codecs/wm8994.c -@@ -2841,6 +2841,7 @@ static int wm8994_aif3_hw_params(struct snd_pcm_substream *substream, - default: - return 0; - } -+ break; - default: - return 0; - } |