mirror of
https://git.yoctoproject.org/meta-ti
synced 2026-07-27 06:18:13 +00:00
linux-ti33x-psp 3.2: update to 3.2.5
Runtime tested on a beaglebone A3 Signed-off-by: Koen Kooi <koen@dominion.thruhere.net> Signed-off-by: Denys Dmytriyenko <denys@ti.com>
This commit is contained in:
committed by
Denys Dmytriyenko
parent
14f31c3c5a
commit
c4eefd7530
+39
@@ -0,0 +1,39 @@
|
||||
From 9589d3910b50c6e66f1a050e365c22271936b6b0 Mon Sep 17 00:00:00 2001
|
||||
From: Roman Tereshonkov <roman.tereshonkov@nokia.com>
|
||||
Date: Tue, 29 Nov 2011 12:49:18 +0200
|
||||
Subject: [PATCH 001/130] mtdoops: fix the oops_page_used array size
|
||||
|
||||
commit 556f063580db2953a7e53cd46b47724246320f60 upstream.
|
||||
|
||||
The array of unsigned long pointed by oops_page_used is allocated
|
||||
by vmalloc which requires the size to be in bytes.
|
||||
|
||||
BITS_PER_LONG is equal to 32.
|
||||
If we want to allocate memory for 32 pages with one bit per page then
|
||||
32 / BITS_PER_LONG is equal to 1 byte that is 8 bits.
|
||||
To fix it we need to multiply the result by sizeof(unsigned long) equal to 4.
|
||||
|
||||
Signed-off-by: Roman Tereshonkov <roman.tereshonkov@nokia.com>
|
||||
Signed-off-by: Artem Bityutskiy <Artem.Bityutskiy@linux.intel.com>
|
||||
Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/mtd/mtdoops.c | 2 +-
|
||||
1 files changed, 1 insertions(+), 1 deletions(-)
|
||||
|
||||
diff --git a/drivers/mtd/mtdoops.c b/drivers/mtd/mtdoops.c
|
||||
index 1e2fa62..0782b31 100644
|
||||
--- a/drivers/mtd/mtdoops.c
|
||||
+++ b/drivers/mtd/mtdoops.c
|
||||
@@ -369,7 +369,7 @@ static void mtdoops_notify_add(struct mtd_info *mtd)
|
||||
|
||||
/* oops_page_used is a bit field */
|
||||
cxt->oops_page_used = vmalloc(DIV_ROUND_UP(mtdoops_pages,
|
||||
- BITS_PER_LONG));
|
||||
+ BITS_PER_LONG) * sizeof(unsigned long));
|
||||
if (!cxt->oops_page_used) {
|
||||
printk(KERN_ERR "mtdoops: could not allocate page array\n");
|
||||
return;
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+36
@@ -0,0 +1,36 @@
|
||||
From e8f072aad40b7d45c605e27f1337b5eb7b6fbc11 Mon Sep 17 00:00:00 2001
|
||||
From: Roman Tereshonkov <roman.tereshonkov@nokia.com>
|
||||
Date: Fri, 2 Dec 2011 15:07:17 +0200
|
||||
Subject: [PATCH 002/130] mtd: mtdoops: skip reading initially bad blocks
|
||||
|
||||
commit 3538c56329936c78f7d356889908790006d0124c upstream.
|
||||
|
||||
Use block_isbad to check and skip the bad blocks reading.
|
||||
This will allow to get rid of the read errors if bad blocks
|
||||
are present initially.
|
||||
|
||||
Signed-off-by: Roman Tereshonkov <roman.tereshonkov@nokia.com>
|
||||
Signed-off-by: Artem Bityutskiy <artem.bityutskiy@linux.intel.com>
|
||||
Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/mtd/mtdoops.c | 3 +++
|
||||
1 files changed, 3 insertions(+), 0 deletions(-)
|
||||
|
||||
diff --git a/drivers/mtd/mtdoops.c b/drivers/mtd/mtdoops.c
|
||||
index 0782b31..f3cdce9 100644
|
||||
--- a/drivers/mtd/mtdoops.c
|
||||
+++ b/drivers/mtd/mtdoops.c
|
||||
@@ -253,6 +253,9 @@ static void find_next_position(struct mtdoops_context *cxt)
|
||||
size_t retlen;
|
||||
|
||||
for (page = 0; page < cxt->oops_pages; page++) {
|
||||
+ if (mtd->block_isbad &&
|
||||
+ mtd->block_isbad(mtd, page * record_size))
|
||||
+ continue;
|
||||
/* Assume the page is used */
|
||||
mark_page_used(cxt, page);
|
||||
ret = mtd->read(mtd, page * record_size, MTDOOPS_HEADER_SIZE,
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+85
@@ -0,0 +1,85 @@
|
||||
From 7e1c31ad0d3116ac301e5d6ef6df036eec548229 Mon Sep 17 00:00:00 2001
|
||||
From: Brian Norris <computersforpeace@gmail.com>
|
||||
Date: Mon, 7 Nov 2011 15:51:05 -0800
|
||||
Subject: [PATCH 003/130] mtd: mtd_blkdevs: don't increase 'open' count on
|
||||
error path
|
||||
|
||||
commit 342ff28f5a2e5aa3236617bd2bddf6c749677ef2 upstream.
|
||||
|
||||
Some error paths in mtd_blkdevs were fixed in the following commit:
|
||||
|
||||
commit 94735ec4044a6d318b83ad3c5794e931ed168d10
|
||||
mtd: mtd_blkdevs: fix error path in blktrans_open
|
||||
|
||||
But on these error paths, the block device's `dev->open' count is
|
||||
already incremented before we check for errors. This meant that, while
|
||||
the error path was handled correctly on the first time through
|
||||
blktrans_open(), the device is erroneously considered already open on
|
||||
the second time through.
|
||||
|
||||
This problem can be seen, for instance, when a UBI volume is
|
||||
simultaneously mounted as a UBIFS partition and read through its
|
||||
corresponding gluebi mtdblockX device. This results in blktrans_open()
|
||||
passing its error checks (with `dev->open > 0') without actually having
|
||||
a handle on the device. Here's a summarized log of the actions and
|
||||
results with nandsim:
|
||||
|
||||
# modprobe nandsim
|
||||
# modprobe mtdblock
|
||||
# modprobe gluebi
|
||||
# modprobe ubifs
|
||||
# ubiattach /dev/ubi_ctrl -m 0
|
||||
...
|
||||
# ubimkvol /dev/ubi0 -N test -s 16MiB
|
||||
...
|
||||
# mount -t ubifs ubi0:test /mnt
|
||||
# ls /dev/mtdblock*
|
||||
/dev/mtdblock0 /dev/mtdblock1
|
||||
# cat /dev/mtdblock1 > /dev/null
|
||||
cat: can't open '/dev/mtdblock4': Device or resource busy
|
||||
# cat /dev/mtdblock1 > /dev/null
|
||||
|
||||
CPU 0 Unable to handle kernel paging request at virtual address
|
||||
fffffff0, epc == 8031536c, ra == 8031f280
|
||||
Oops[#1]:
|
||||
...
|
||||
Call Trace:
|
||||
[<8031536c>] ubi_leb_read+0x14/0x164
|
||||
[<8031f280>] gluebi_read+0xf0/0x148
|
||||
[<802edba8>] mtdblock_readsect+0x64/0x198
|
||||
[<802ecfe4>] mtd_blktrans_thread+0x330/0x3f4
|
||||
[<8005be98>] kthread+0x88/0x90
|
||||
[<8000bc04>] kernel_thread_helper+0x10/0x18
|
||||
|
||||
Signed-off-by: Brian Norris <computersforpeace@gmail.com>
|
||||
Signed-off-by: Artem Bityutskiy <Artem.Bityutskiy@linux.intel.com>
|
||||
Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/mtd/mtd_blkdevs.c | 3 ++-
|
||||
1 files changed, 2 insertions(+), 1 deletions(-)
|
||||
|
||||
diff --git a/drivers/mtd/mtd_blkdevs.c b/drivers/mtd/mtd_blkdevs.c
|
||||
index ed8b5e7..424ca5f 100644
|
||||
--- a/drivers/mtd/mtd_blkdevs.c
|
||||
+++ b/drivers/mtd/mtd_blkdevs.c
|
||||
@@ -215,7 +215,7 @@ static int blktrans_open(struct block_device *bdev, fmode_t mode)
|
||||
|
||||
mutex_lock(&dev->lock);
|
||||
|
||||
- if (dev->open++)
|
||||
+ if (dev->open)
|
||||
goto unlock;
|
||||
|
||||
kref_get(&dev->ref);
|
||||
@@ -235,6 +235,7 @@ static int blktrans_open(struct block_device *bdev, fmode_t mode)
|
||||
goto error_release;
|
||||
|
||||
unlock:
|
||||
+ dev->open++;
|
||||
mutex_unlock(&dev->lock);
|
||||
blktrans_dev_put(dev);
|
||||
return ret;
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+60
@@ -0,0 +1,60 @@
|
||||
From 24935db264c015f91046c597ead8f42a3de24858 Mon Sep 17 00:00:00 2001
|
||||
From: Wolfram Sang <w.sang@pengutronix.de>
|
||||
Date: Tue, 29 Nov 2011 15:34:08 +0100
|
||||
Subject: [PATCH 004/130] mtd: tests: stresstest: bail out if device has not
|
||||
enough eraseblocks
|
||||
|
||||
commit 2f4478ccff7df845dc9c0f8996a96373122c4417 upstream.
|
||||
|
||||
stresstest needs at least two eraseblocks. Bail out gracefully if that
|
||||
condition is not met. Fixes the following 'division by zero' OOPS:
|
||||
|
||||
[ 619.100000] mtd_stresstest: MTD device size 131072, eraseblock size 131072, page size 2048, count of eraseblocks 1, pages per eraseblock 64, OOB size 64
|
||||
[ 619.120000] mtd_stresstest: scanning for bad eraseblocks
|
||||
[ 619.120000] mtd_stresstest: scanned 1 eraseblocks, 0 are bad
|
||||
[ 619.130000] mtd_stresstest: doing operations
|
||||
[ 619.130000] mtd_stresstest: 0 operations done
|
||||
[ 619.140000] Division by zero in kernel.
|
||||
...
|
||||
|
||||
caused by
|
||||
|
||||
/* Read or write up 2 eraseblocks at a time - hence 'ebcnt - 1' */
|
||||
eb %= (ebcnt - 1);
|
||||
|
||||
Signed-off-by: Wolfram Sang <w.sang@pengutronix.de>
|
||||
Signed-off-by: Artem Bityutskiy <artem.bityutskiy@linux.intel.com>
|
||||
Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/mtd/tests/mtd_stresstest.c | 7 +++++++
|
||||
1 files changed, 7 insertions(+), 0 deletions(-)
|
||||
|
||||
diff --git a/drivers/mtd/tests/mtd_stresstest.c b/drivers/mtd/tests/mtd_stresstest.c
|
||||
index 52ffd91..811642f 100644
|
||||
--- a/drivers/mtd/tests/mtd_stresstest.c
|
||||
+++ b/drivers/mtd/tests/mtd_stresstest.c
|
||||
@@ -284,6 +284,12 @@ static int __init mtd_stresstest_init(void)
|
||||
(unsigned long long)mtd->size, mtd->erasesize,
|
||||
pgsize, ebcnt, pgcnt, mtd->oobsize);
|
||||
|
||||
+ if (ebcnt < 2) {
|
||||
+ printk(PRINT_PREF "error: need at least 2 eraseblocks\n");
|
||||
+ err = -ENOSPC;
|
||||
+ goto out_put_mtd;
|
||||
+ }
|
||||
+
|
||||
/* Read or write up 2 eraseblocks at a time */
|
||||
bufsize = mtd->erasesize * 2;
|
||||
|
||||
@@ -322,6 +328,7 @@ out:
|
||||
kfree(bbt);
|
||||
vfree(writebuf);
|
||||
vfree(readbuf);
|
||||
+out_put_mtd:
|
||||
put_mtd_device(mtd);
|
||||
if (err)
|
||||
printk(PRINT_PREF "error %d occurred\n", err);
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+53
@@ -0,0 +1,53 @@
|
||||
From 0ff595b93bc982c60777d727c282cf76050802bf Mon Sep 17 00:00:00 2001
|
||||
From: Ben Hutchings <ben@decadent.org.uk>
|
||||
Date: Tue, 10 Jan 2012 15:11:02 -0800
|
||||
Subject: [PATCH 005/130] drivers/rtc/interface.c: fix alarm rollover when day
|
||||
or month is out-of-range
|
||||
|
||||
commit e74a8f2edb92cb690b467cea0ab652c509e9f624 upstream.
|
||||
|
||||
Commit f44f7f96a20a ("RTC: Initialize kernel state from RTC") introduced a
|
||||
potential infinite loop. If an alarm time contains a wildcard month and
|
||||
an invalid day (> 31), or a wildcard year and an invalid month (>= 12),
|
||||
the loop searching for the next matching date will never terminate. Treat
|
||||
the invalid values as wildcards.
|
||||
|
||||
Fixes <http://bugs.debian.org/646429>, <http://bugs.debian.org/653331>
|
||||
|
||||
Reported-by: leo weppelman <leoweppelman@googlemail.com>
|
||||
Reported-by: "P. van Gaans" <mailme667@yahoo.co.uk>
|
||||
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
|
||||
Signed-off-by: Jonathan Nieder <jrnieder@gmail.com>
|
||||
Cc: Mark Brown <broonie@opensource.wolfsonmicro.com>
|
||||
Cc: Marcelo Roberto Jimenez <mroberto@cpti.cetuc.puc-rio.br>
|
||||
Cc: Thomas Gleixner <tglx@linutronix.de>
|
||||
Cc: John Stultz <john.stultz@linaro.org>
|
||||
Acked-by: Alessandro Zummo <a.zummo@towertech.it>
|
||||
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
|
||||
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/rtc/interface.c | 4 ++--
|
||||
1 files changed, 2 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/drivers/rtc/interface.c b/drivers/rtc/interface.c
|
||||
index 8e28625..8a1c031 100644
|
||||
--- a/drivers/rtc/interface.c
|
||||
+++ b/drivers/rtc/interface.c
|
||||
@@ -228,11 +228,11 @@ int __rtc_read_alarm(struct rtc_device *rtc, struct rtc_wkalrm *alarm)
|
||||
alarm->time.tm_hour = now.tm_hour;
|
||||
|
||||
/* For simplicity, only support date rollover for now */
|
||||
- if (alarm->time.tm_mday == -1) {
|
||||
+ if (alarm->time.tm_mday < 1 || alarm->time.tm_mday > 31) {
|
||||
alarm->time.tm_mday = now.tm_mday;
|
||||
missing = day;
|
||||
}
|
||||
- if (alarm->time.tm_mon == -1) {
|
||||
+ if ((unsigned)alarm->time.tm_mon >= 12) {
|
||||
alarm->time.tm_mon = now.tm_mon;
|
||||
if (missing == none)
|
||||
missing = month;
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+109
@@ -0,0 +1,109 @@
|
||||
From 90d3fbe7c2f63a83921d15a9bb1f451d03040f9b Mon Sep 17 00:00:00 2001
|
||||
From: Djalal Harouni <tixxdz@opendz.org>
|
||||
Date: Wed, 4 Jan 2012 17:09:52 -0500
|
||||
Subject: [PATCH 006/130] ext4: add missing ext4_resize_end on error paths
|
||||
|
||||
commit 014a1770371a028d22f364718c805f4216911ecd upstream.
|
||||
|
||||
Online resize ioctls 'EXT4_IOC_GROUP_EXTEND' and 'EXT4_IOC_GROUP_ADD'
|
||||
call ext4_resize_begin() to check permissions and to set the
|
||||
EXT4_RESIZING bit lock, they do their work and they must finish with
|
||||
ext4_resize_end() which calls clear_bit_unlock() to unlock and to
|
||||
avoid -EBUSY errors for the next resize operations.
|
||||
|
||||
This patch adds the missing ext4_resize_end() calls on error paths.
|
||||
|
||||
Patch tested.
|
||||
|
||||
Signed-off-by: Djalal Harouni <tixxdz@opendz.org>
|
||||
Signed-off-by: "Theodore Ts'o" <tytso@mit.edu>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
fs/ext4/ioctl.c | 28 ++++++++++++++++++----------
|
||||
1 files changed, 18 insertions(+), 10 deletions(-)
|
||||
|
||||
diff --git a/fs/ext4/ioctl.c b/fs/ext4/ioctl.c
|
||||
index a567968..ab25f57 100644
|
||||
--- a/fs/ext4/ioctl.c
|
||||
+++ b/fs/ext4/ioctl.c
|
||||
@@ -182,19 +182,22 @@ setversion_out:
|
||||
if (err)
|
||||
return err;
|
||||
|
||||
- if (get_user(n_blocks_count, (__u32 __user *)arg))
|
||||
- return -EFAULT;
|
||||
+ if (get_user(n_blocks_count, (__u32 __user *)arg)) {
|
||||
+ err = -EFAULT;
|
||||
+ goto group_extend_out;
|
||||
+ }
|
||||
|
||||
if (EXT4_HAS_RO_COMPAT_FEATURE(sb,
|
||||
EXT4_FEATURE_RO_COMPAT_BIGALLOC)) {
|
||||
ext4_msg(sb, KERN_ERR,
|
||||
"Online resizing not supported with bigalloc");
|
||||
- return -EOPNOTSUPP;
|
||||
+ err = -EOPNOTSUPP;
|
||||
+ goto group_extend_out;
|
||||
}
|
||||
|
||||
err = mnt_want_write(filp->f_path.mnt);
|
||||
if (err)
|
||||
- return err;
|
||||
+ goto group_extend_out;
|
||||
|
||||
err = ext4_group_extend(sb, EXT4_SB(sb)->s_es, n_blocks_count);
|
||||
if (EXT4_SB(sb)->s_journal) {
|
||||
@@ -204,9 +207,10 @@ setversion_out:
|
||||
}
|
||||
if (err == 0)
|
||||
err = err2;
|
||||
+
|
||||
mnt_drop_write(filp->f_path.mnt);
|
||||
+group_extend_out:
|
||||
ext4_resize_end(sb);
|
||||
-
|
||||
return err;
|
||||
}
|
||||
|
||||
@@ -267,19 +271,22 @@ mext_out:
|
||||
return err;
|
||||
|
||||
if (copy_from_user(&input, (struct ext4_new_group_input __user *)arg,
|
||||
- sizeof(input)))
|
||||
- return -EFAULT;
|
||||
+ sizeof(input))) {
|
||||
+ err = -EFAULT;
|
||||
+ goto group_add_out;
|
||||
+ }
|
||||
|
||||
if (EXT4_HAS_RO_COMPAT_FEATURE(sb,
|
||||
EXT4_FEATURE_RO_COMPAT_BIGALLOC)) {
|
||||
ext4_msg(sb, KERN_ERR,
|
||||
"Online resizing not supported with bigalloc");
|
||||
- return -EOPNOTSUPP;
|
||||
+ err = -EOPNOTSUPP;
|
||||
+ goto group_add_out;
|
||||
}
|
||||
|
||||
err = mnt_want_write(filp->f_path.mnt);
|
||||
if (err)
|
||||
- return err;
|
||||
+ goto group_add_out;
|
||||
|
||||
err = ext4_group_add(sb, &input);
|
||||
if (EXT4_SB(sb)->s_journal) {
|
||||
@@ -289,9 +296,10 @@ mext_out:
|
||||
}
|
||||
if (err == 0)
|
||||
err = err2;
|
||||
+
|
||||
mnt_drop_write(filp->f_path.mnt);
|
||||
+group_add_out:
|
||||
ext4_resize_end(sb);
|
||||
-
|
||||
return err;
|
||||
}
|
||||
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+74
@@ -0,0 +1,74 @@
|
||||
From 149672e502af36fdb60960faaf2ca3bdde96bd5e Mon Sep 17 00:00:00 2001
|
||||
From: Xi Wang <xi.wang@gmail.com>
|
||||
Date: Tue, 10 Jan 2012 11:51:10 -0500
|
||||
Subject: [PATCH 007/130] ext4: fix undefined behavior in
|
||||
ext4_fill_flex_info()
|
||||
|
||||
commit d50f2ab6f050311dbf7b8f5501b25f0bf64a439b upstream.
|
||||
|
||||
Commit 503358ae01b70ce6909d19dd01287093f6b6271c ("ext4: avoid divide by
|
||||
zero when trying to mount a corrupted file system") fixes CVE-2009-4307
|
||||
by performing a sanity check on s_log_groups_per_flex, since it can be
|
||||
set to a bogus value by an attacker.
|
||||
|
||||
sbi->s_log_groups_per_flex = sbi->s_es->s_log_groups_per_flex;
|
||||
groups_per_flex = 1 << sbi->s_log_groups_per_flex;
|
||||
|
||||
if (groups_per_flex < 2) { ... }
|
||||
|
||||
This patch fixes two potential issues in the previous commit.
|
||||
|
||||
1) The sanity check might only work on architectures like PowerPC.
|
||||
On x86, 5 bits are used for the shifting amount. That means, given a
|
||||
large s_log_groups_per_flex value like 36, groups_per_flex = 1 << 36
|
||||
is essentially 1 << 4 = 16, rather than 0. This will bypass the check,
|
||||
leaving s_log_groups_per_flex and groups_per_flex inconsistent.
|
||||
|
||||
2) The sanity check relies on undefined behavior, i.e., oversized shift.
|
||||
A standard-confirming C compiler could rewrite the check in unexpected
|
||||
ways. Consider the following equivalent form, assuming groups_per_flex
|
||||
is unsigned for simplicity.
|
||||
|
||||
groups_per_flex = 1 << sbi->s_log_groups_per_flex;
|
||||
if (groups_per_flex == 0 || groups_per_flex == 1) {
|
||||
|
||||
We compile the code snippet using Clang 3.0 and GCC 4.6. Clang will
|
||||
completely optimize away the check groups_per_flex == 0, leaving the
|
||||
patched code as vulnerable as the original. GCC keeps the check, but
|
||||
there is no guarantee that future versions will do the same.
|
||||
|
||||
Signed-off-by: Xi Wang <xi.wang@gmail.com>
|
||||
Signed-off-by: "Theodore Ts'o" <tytso@mit.edu>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
fs/ext4/super.c | 7 +++----
|
||||
1 files changed, 3 insertions(+), 4 deletions(-)
|
||||
|
||||
diff --git a/fs/ext4/super.c b/fs/ext4/super.c
|
||||
index 3e1329e..9281dbe 100644
|
||||
--- a/fs/ext4/super.c
|
||||
+++ b/fs/ext4/super.c
|
||||
@@ -2006,17 +2006,16 @@ static int ext4_fill_flex_info(struct super_block *sb)
|
||||
struct ext4_group_desc *gdp = NULL;
|
||||
ext4_group_t flex_group_count;
|
||||
ext4_group_t flex_group;
|
||||
- int groups_per_flex = 0;
|
||||
+ unsigned int groups_per_flex = 0;
|
||||
size_t size;
|
||||
int i;
|
||||
|
||||
sbi->s_log_groups_per_flex = sbi->s_es->s_log_groups_per_flex;
|
||||
- groups_per_flex = 1 << sbi->s_log_groups_per_flex;
|
||||
-
|
||||
- if (groups_per_flex < 2) {
|
||||
+ if (sbi->s_log_groups_per_flex < 1 || sbi->s_log_groups_per_flex > 31) {
|
||||
sbi->s_log_groups_per_flex = 0;
|
||||
return 1;
|
||||
}
|
||||
+ groups_per_flex = 1 << sbi->s_log_groups_per_flex;
|
||||
|
||||
/* We allocate both existing and potentially added groups */
|
||||
flex_group_count = ((sbi->s_groups_count + groups_per_flex - 1) +
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+54
@@ -0,0 +1,54 @@
|
||||
From 77b0511fab25f495a30242f4b2fd940e71ce11ad Mon Sep 17 00:00:00 2001
|
||||
From: Karsten Wiese <fzu@wemgehoertderstaat.de>
|
||||
Date: Fri, 30 Dec 2011 01:42:01 +0100
|
||||
Subject: [PATCH 008/130] ALSA: snd-usb-us122l: Delete calls to
|
||||
preempt_disable
|
||||
|
||||
commit d0f3a2eb9062560bebca8b923424f3ca02a331ba upstream.
|
||||
|
||||
They are not needed here.
|
||||
|
||||
Signed-off-by: Karsten Wiese <fzu@wemgehoertderstaat.de>
|
||||
Signed-off-by: Takashi Iwai <tiwai@suse.de>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
sound/usb/usx2y/usb_stream.c | 6 ++----
|
||||
1 files changed, 2 insertions(+), 4 deletions(-)
|
||||
|
||||
diff --git a/sound/usb/usx2y/usb_stream.c b/sound/usb/usx2y/usb_stream.c
|
||||
index c400ade..1e7a47a 100644
|
||||
--- a/sound/usb/usx2y/usb_stream.c
|
||||
+++ b/sound/usb/usx2y/usb_stream.c
|
||||
@@ -674,7 +674,7 @@ dotry:
|
||||
inurb->transfer_buffer_length =
|
||||
inurb->number_of_packets *
|
||||
inurb->iso_frame_desc[0].length;
|
||||
- preempt_disable();
|
||||
+
|
||||
if (u == 0) {
|
||||
int now;
|
||||
struct usb_device *dev = inurb->dev;
|
||||
@@ -686,19 +686,17 @@ dotry:
|
||||
}
|
||||
err = usb_submit_urb(inurb, GFP_ATOMIC);
|
||||
if (err < 0) {
|
||||
- preempt_enable();
|
||||
snd_printk(KERN_ERR"usb_submit_urb(sk->inurb[%i])"
|
||||
" returned %i\n", u, err);
|
||||
return err;
|
||||
}
|
||||
err = usb_submit_urb(outurb, GFP_ATOMIC);
|
||||
if (err < 0) {
|
||||
- preempt_enable();
|
||||
snd_printk(KERN_ERR"usb_submit_urb(sk->outurb[%i])"
|
||||
" returned %i\n", u, err);
|
||||
return err;
|
||||
}
|
||||
- preempt_enable();
|
||||
+
|
||||
if (inurb->start_frame != outurb->start_frame) {
|
||||
snd_printd(KERN_DEBUG
|
||||
"u[%i] start_frames differ in:%u out:%u\n",
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+57
@@ -0,0 +1,57 @@
|
||||
From c237e8b240ea09139d387e89f7474fbcd2b4bd0c Mon Sep 17 00:00:00 2001
|
||||
From: David Henningsson <david.henningsson@canonical.com>
|
||||
Date: Mon, 2 Jan 2012 12:40:15 +0100
|
||||
Subject: [PATCH 009/130] ALSA: HDA: Fix master control for Cirrus Logic 421X
|
||||
|
||||
commit 40d03e63e91af8ddccdfd5a536cc2a6e51433e1d upstream.
|
||||
|
||||
The control name "HP/Speakers" is non-standard, and since there is
|
||||
only one DAC on this chip there is no need for a virtual master
|
||||
anyway.
|
||||
|
||||
Signed-off-by: David Henningsson <david.henningsson@canonical.com>
|
||||
Signed-off-by: Takashi Iwai <tiwai@suse.de>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
sound/pci/hda/patch_cirrus.c | 13 +------------
|
||||
1 files changed, 1 insertions(+), 12 deletions(-)
|
||||
|
||||
diff --git a/sound/pci/hda/patch_cirrus.c b/sound/pci/hda/patch_cirrus.c
|
||||
index 70a7abd..f55ceb6 100644
|
||||
--- a/sound/pci/hda/patch_cirrus.c
|
||||
+++ b/sound/pci/hda/patch_cirrus.c
|
||||
@@ -1771,30 +1771,19 @@ static int build_cs421x_output(struct hda_codec *codec)
|
||||
struct auto_pin_cfg *cfg = &spec->autocfg;
|
||||
struct snd_kcontrol *kctl;
|
||||
int err;
|
||||
- char *name = "HP/Speakers";
|
||||
+ char *name = "Master";
|
||||
|
||||
fix_volume_caps(codec, dac);
|
||||
- if (!spec->vmaster_sw) {
|
||||
- err = add_vmaster(codec, dac);
|
||||
- if (err < 0)
|
||||
- return err;
|
||||
- }
|
||||
|
||||
err = add_mute(codec, name, 0,
|
||||
HDA_COMPOSE_AMP_VAL(dac, 3, 0, HDA_OUTPUT), 0, &kctl);
|
||||
if (err < 0)
|
||||
return err;
|
||||
- err = snd_ctl_add_slave(spec->vmaster_sw, kctl);
|
||||
- if (err < 0)
|
||||
- return err;
|
||||
|
||||
err = add_volume(codec, name, 0,
|
||||
HDA_COMPOSE_AMP_VAL(dac, 3, 0, HDA_OUTPUT), 0, &kctl);
|
||||
if (err < 0)
|
||||
return err;
|
||||
- err = snd_ctl_add_slave(spec->vmaster_vol, kctl);
|
||||
- if (err < 0)
|
||||
- return err;
|
||||
|
||||
if (cfg->speaker_outs) {
|
||||
err = snd_hda_ctl_add(codec, 0,
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+48
@@ -0,0 +1,48 @@
|
||||
From d08570c3c46be8ea5797897e7ae4df418d404c2d Mon Sep 17 00:00:00 2001
|
||||
From: David Henningsson <david.henningsson@canonical.com>
|
||||
Date: Mon, 2 Jan 2012 12:40:16 +0100
|
||||
Subject: [PATCH 010/130] ALSA: HDA: Fix automute for Cirrus Logic 421x
|
||||
|
||||
commit 78e2a928e377d5124932d4399c6c581908b027a0 upstream.
|
||||
|
||||
There was a bug in the automute logic causing speakers not to
|
||||
mute when headphones were plugged in.
|
||||
|
||||
Tested-by: Hsin-Yi Chen <hychen@canonical.com>
|
||||
Signed-off-by: David Henningsson <david.henningsson@canonical.com>
|
||||
Signed-off-by: Takashi Iwai <tiwai@suse.de>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
sound/pci/hda/patch_cirrus.c | 14 ++++++--------
|
||||
1 files changed, 6 insertions(+), 8 deletions(-)
|
||||
|
||||
diff --git a/sound/pci/hda/patch_cirrus.c b/sound/pci/hda/patch_cirrus.c
|
||||
index f55ceb6..5b0a9bb 100644
|
||||
--- a/sound/pci/hda/patch_cirrus.c
|
||||
+++ b/sound/pci/hda/patch_cirrus.c
|
||||
@@ -920,16 +920,14 @@ static void cs_automute(struct hda_codec *codec)
|
||||
|
||||
/* mute speakers if spdif or hp jack is plugged in */
|
||||
for (i = 0; i < cfg->speaker_outs; i++) {
|
||||
+ int pin_ctl = hp_present ? 0 : PIN_OUT;
|
||||
+ /* detect on spdif is specific to CS421x */
|
||||
+ if (spdif_present && (spec->vendor_nid == CS421X_VENDOR_NID))
|
||||
+ pin_ctl = 0;
|
||||
+
|
||||
nid = cfg->speaker_pins[i];
|
||||
snd_hda_codec_write(codec, nid, 0,
|
||||
- AC_VERB_SET_PIN_WIDGET_CONTROL,
|
||||
- hp_present ? 0 : PIN_OUT);
|
||||
- /* detect on spdif is specific to CS421x */
|
||||
- if (spec->vendor_nid == CS421X_VENDOR_NID) {
|
||||
- snd_hda_codec_write(codec, nid, 0,
|
||||
- AC_VERB_SET_PIN_WIDGET_CONTROL,
|
||||
- spdif_present ? 0 : PIN_OUT);
|
||||
- }
|
||||
+ AC_VERB_SET_PIN_WIDGET_CONTROL, pin_ctl);
|
||||
}
|
||||
if (spec->gpio_eapd_hp) {
|
||||
unsigned int gpio = hp_present ?
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+38
@@ -0,0 +1,38 @@
|
||||
From 37a4221e9e94eb1841d5367baba68e31b0c29d4b Mon Sep 17 00:00:00 2001
|
||||
From: Pavel Hofman <pavel.hofman@ivitera.com>
|
||||
Date: Thu, 5 Jan 2012 23:05:18 +0100
|
||||
Subject: [PATCH 011/130] ALSA: ice1724 - Check for ac97 to avoid kernel oops
|
||||
|
||||
commit e7848163aa2a649d9065f230fadff80dc3519775 upstream.
|
||||
|
||||
Cards with identical PCI ids but no AC97 config in EEPROM do not have
|
||||
the ac97 field initialized. We must check for this case to avoid kernel oops.
|
||||
|
||||
Signed-off-by: Pavel Hofman <pavel.hofman@ivitera.com>
|
||||
Signed-off-by: Takashi Iwai <tiwai@suse.de>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
sound/pci/ice1712/amp.c | 7 +++++--
|
||||
1 files changed, 5 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/sound/pci/ice1712/amp.c b/sound/pci/ice1712/amp.c
|
||||
index e328cfb..e525da2 100644
|
||||
--- a/sound/pci/ice1712/amp.c
|
||||
+++ b/sound/pci/ice1712/amp.c
|
||||
@@ -68,8 +68,11 @@ static int __devinit snd_vt1724_amp_init(struct snd_ice1712 *ice)
|
||||
|
||||
static int __devinit snd_vt1724_amp_add_controls(struct snd_ice1712 *ice)
|
||||
{
|
||||
- /* we use pins 39 and 41 of the VT1616 for left and right read outputs */
|
||||
- snd_ac97_write_cache(ice->ac97, 0x5a, snd_ac97_read(ice->ac97, 0x5a) & ~0x8000);
|
||||
+ if (ice->ac97)
|
||||
+ /* we use pins 39 and 41 of the VT1616 for left and right
|
||||
+ read outputs */
|
||||
+ snd_ac97_write_cache(ice->ac97, 0x5a,
|
||||
+ snd_ac97_read(ice->ac97, 0x5a) & ~0x8000);
|
||||
return 0;
|
||||
}
|
||||
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+46
@@ -0,0 +1,46 @@
|
||||
From 3997412715c72bd24b2433c841b63590ec175755 Mon Sep 17 00:00:00 2001
|
||||
From: Takashi Iwai <tiwai@suse.de>
|
||||
Date: Mon, 9 Jan 2012 11:37:20 +0100
|
||||
Subject: [PATCH 012/130] ALSA: usb-audio - Avoid flood of frame-active debug
|
||||
messages
|
||||
|
||||
commit 80c8a2a372599e604b04a9c568952fe39cd1851d upstream.
|
||||
|
||||
With some buggy devices, the usb-audio driver may give "frame xxx active"
|
||||
kernel messages too often. Better to keep it as debug-only using
|
||||
snd_printdd(), and also add the rate-limit for avoiding floods.
|
||||
|
||||
Bugzilla: https://bugzilla.novell.com/show_bug.cgi?id=738681
|
||||
|
||||
Signed-off-by: Takashi Iwai <tiwai@suse.de>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
sound/usb/endpoint.c | 5 +++--
|
||||
1 files changed, 3 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/sound/usb/endpoint.c b/sound/usb/endpoint.c
|
||||
index 81c6ede..08dcce5 100644
|
||||
--- a/sound/usb/endpoint.c
|
||||
+++ b/sound/usb/endpoint.c
|
||||
@@ -17,6 +17,7 @@
|
||||
|
||||
#include <linux/gfp.h>
|
||||
#include <linux/init.h>
|
||||
+#include <linux/ratelimit.h>
|
||||
#include <linux/usb.h>
|
||||
#include <linux/usb/audio.h>
|
||||
|
||||
@@ -458,8 +459,8 @@ static int retire_capture_urb(struct snd_usb_substream *subs,
|
||||
|
||||
for (i = 0; i < urb->number_of_packets; i++) {
|
||||
cp = (unsigned char *)urb->transfer_buffer + urb->iso_frame_desc[i].offset;
|
||||
- if (urb->iso_frame_desc[i].status) {
|
||||
- snd_printd(KERN_ERR "frame %d active: %d\n", i, urb->iso_frame_desc[i].status);
|
||||
+ if (urb->iso_frame_desc[i].status && printk_ratelimit()) {
|
||||
+ snd_printdd("frame %d active: %d\n", i, urb->iso_frame_desc[i].status);
|
||||
// continue;
|
||||
}
|
||||
bytes = urb->iso_frame_desc[i].actual_length;
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+37
@@ -0,0 +1,37 @@
|
||||
From 82b777e29dcdaa78de5834c88eec7d6733f7aaff Mon Sep 17 00:00:00 2001
|
||||
From: Takashi Iwai <tiwai@suse.de>
|
||||
Date: Tue, 10 Jan 2012 08:59:56 +0100
|
||||
Subject: [PATCH 013/130] ALSA: hda - Use auto-parser for HP laptops with
|
||||
cx20459 codec
|
||||
|
||||
commit de4da59e480cdf1075b33dbaf8078fc87bc52241 upstream.
|
||||
|
||||
These laptops can work well with the auto-parser and their BIOS setups,
|
||||
and in addition, the auto-parser fixes the problem with S3/S4 where
|
||||
the unsol event handling is killed after resume due to fallback to the
|
||||
single-cmd mode.
|
||||
|
||||
Bugzilla: https://bugzilla.novell.com/show_bug.cgi?id=740115
|
||||
|
||||
Signed-off-by: Takashi Iwai <tiwai@suse.de>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
sound/pci/hda/patch_conexant.c | 2 --
|
||||
1 files changed, 0 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/sound/pci/hda/patch_conexant.c b/sound/pci/hda/patch_conexant.c
|
||||
index 0de2119..7072251 100644
|
||||
--- a/sound/pci/hda/patch_conexant.c
|
||||
+++ b/sound/pci/hda/patch_conexant.c
|
||||
@@ -1120,8 +1120,6 @@ static const char * const cxt5045_models[CXT5045_MODELS] = {
|
||||
|
||||
static const struct snd_pci_quirk cxt5045_cfg_tbl[] = {
|
||||
SND_PCI_QUIRK(0x103c, 0x30d5, "HP 530", CXT5045_LAPTOP_HP530),
|
||||
- SND_PCI_QUIRK_MASK(0x103c, 0xff00, 0x3000, "HP DV Series",
|
||||
- CXT5045_LAPTOP_HPSENSE),
|
||||
SND_PCI_QUIRK(0x1179, 0xff31, "Toshiba P105", CXT5045_LAPTOP_MICSENSE),
|
||||
SND_PCI_QUIRK(0x152d, 0x0753, "Benq R55E", CXT5045_BENQ),
|
||||
SND_PCI_QUIRK(0x1734, 0x10ad, "Fujitsu Si1520", CXT5045_LAPTOP_MICSENSE),
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+58
@@ -0,0 +1,58 @@
|
||||
From b347c4f831da8a0e1498b0947e7a334e9113cd83 Mon Sep 17 00:00:00 2001
|
||||
From: Takashi Iwai <tiwai@suse.de>
|
||||
Date: Tue, 10 Jan 2012 12:41:22 +0100
|
||||
Subject: [PATCH 014/130] ALSA: hda - Return the error from get_wcaps_type()
|
||||
for invalid NIDs
|
||||
|
||||
commit 3a90274de3548ebb2aabfbf488cea8e275a73dc6 upstream.
|
||||
|
||||
When an invalid NID is given, get_wcaps() returns zero as the error,
|
||||
but get_wcaps_type() takes it as the normal value and returns a bogus
|
||||
AC_WID_AUD_OUT value. This confuses the parser.
|
||||
|
||||
With this patch, get_wcaps_type() returns -1 when value 0 is given,
|
||||
i.e. an invalid NID is passed to get_wcaps().
|
||||
|
||||
Bugzilla: https://bugzilla.novell.com/show_bug.cgi?id=740118
|
||||
|
||||
Signed-off-by: Takashi Iwai <tiwai@suse.de>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
sound/pci/hda/hda_local.h | 7 ++++++-
|
||||
sound/pci/hda/hda_proc.c | 2 ++
|
||||
2 files changed, 8 insertions(+), 1 deletions(-)
|
||||
|
||||
diff --git a/sound/pci/hda/hda_local.h b/sound/pci/hda/hda_local.h
|
||||
index 618ddad..368f0c5 100644
|
||||
--- a/sound/pci/hda/hda_local.h
|
||||
+++ b/sound/pci/hda/hda_local.h
|
||||
@@ -487,7 +487,12 @@ static inline u32 get_wcaps(struct hda_codec *codec, hda_nid_t nid)
|
||||
}
|
||||
|
||||
/* get the widget type from widget capability bits */
|
||||
-#define get_wcaps_type(wcaps) (((wcaps) & AC_WCAP_TYPE) >> AC_WCAP_TYPE_SHIFT)
|
||||
+static inline int get_wcaps_type(unsigned int wcaps)
|
||||
+{
|
||||
+ if (!wcaps)
|
||||
+ return -1; /* invalid type */
|
||||
+ return (wcaps & AC_WCAP_TYPE) >> AC_WCAP_TYPE_SHIFT;
|
||||
+}
|
||||
|
||||
static inline unsigned int get_wcaps_channels(u32 wcaps)
|
||||
{
|
||||
diff --git a/sound/pci/hda/hda_proc.c b/sound/pci/hda/hda_proc.c
|
||||
index 2c981b5..254ab52 100644
|
||||
--- a/sound/pci/hda/hda_proc.c
|
||||
+++ b/sound/pci/hda/hda_proc.c
|
||||
@@ -54,6 +54,8 @@ static const char *get_wid_type_name(unsigned int wid_value)
|
||||
[AC_WID_BEEP] = "Beep Generator Widget",
|
||||
[AC_WID_VENDOR] = "Vendor Defined Widget",
|
||||
};
|
||||
+ if (wid_value == -1)
|
||||
+ return "UNKNOWN Widget";
|
||||
wid_value &= 0xf;
|
||||
if (names[wid_value])
|
||||
return names[wid_value];
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+42
@@ -0,0 +1,42 @@
|
||||
From ea14c41fb5a54a4f2089c97f85c399965415871a Mon Sep 17 00:00:00 2001
|
||||
From: Takashi Iwai <tiwai@suse.de>
|
||||
Date: Tue, 10 Jan 2012 15:16:02 +0100
|
||||
Subject: [PATCH 015/130] ALSA: hda - Fix the detection of "Loopback Mixing"
|
||||
control for VIA codecs
|
||||
|
||||
commit 4808d12d1dddb046ec86425e5f6766f02e950292 upstream.
|
||||
|
||||
Currently the driver checks only the out_mix_path[] for the primary
|
||||
output route for judging whether to create the loopback-mixing control
|
||||
or not. But, there are cases where aamix-routing is available only on
|
||||
headphone or speaker paths but not on the primary output path. So, the
|
||||
driver ignores such cases inappropriately.
|
||||
|
||||
This patch fixes the check of the loopback-mixing control by testing
|
||||
all mix-routing paths.
|
||||
|
||||
Signed-off-by: Takashi Iwai <tiwai@suse.de>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
sound/pci/hda/patch_via.c | 5 ++++-
|
||||
1 files changed, 4 insertions(+), 1 deletions(-)
|
||||
|
||||
diff --git a/sound/pci/hda/patch_via.c b/sound/pci/hda/patch_via.c
|
||||
index b513762..8d69e59 100644
|
||||
--- a/sound/pci/hda/patch_via.c
|
||||
+++ b/sound/pci/hda/patch_via.c
|
||||
@@ -2200,7 +2200,10 @@ static int via_auto_create_loopback_switch(struct hda_codec *codec)
|
||||
{
|
||||
struct via_spec *spec = codec->spec;
|
||||
|
||||
- if (!spec->aa_mix_nid || !spec->out_mix_path.depth)
|
||||
+ if (!spec->aa_mix_nid)
|
||||
+ return 0; /* no loopback switching available */
|
||||
+ if (!(spec->out_mix_path.depth || spec->hp_mix_path.depth ||
|
||||
+ spec->speaker_path.depth))
|
||||
return 0; /* no loopback switching available */
|
||||
if (!via_clone_control(spec, &via_aamix_ctl_enum))
|
||||
return -ENOMEM;
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+92
@@ -0,0 +1,92 @@
|
||||
From 53eb674241d25d1496c966cd5f140b0bb213dbdc Mon Sep 17 00:00:00 2001
|
||||
From: Takashi Iwai <tiwai@suse.de>
|
||||
Date: Wed, 11 Jan 2012 12:34:11 +0100
|
||||
Subject: [PATCH 016/130] ALSA: hda - Fix the lost power-setup of seconary
|
||||
pins after PM resume
|
||||
|
||||
commit f2cbba7602383cd9cdd21f0a5d0b8bd1aad47b33 upstream.
|
||||
|
||||
When multiple headphone or other detectable output pins are present,
|
||||
the power-map has to be updated after resume appropriately, but the
|
||||
current driver doesn't check all pins but only the first pin (since
|
||||
it's enough to check it for the mute-behavior). This resulted in the
|
||||
silent output from the secondary outputs after PM resume.
|
||||
|
||||
This patch fixes the problem by checking all pins at (re-)init time.
|
||||
|
||||
Bugzilla: https://bugzilla.novell.com/show_bug.cgi?id=740347
|
||||
|
||||
Signed-off-by: Takashi Iwai <tiwai@suse.de>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
sound/pci/hda/patch_sigmatel.c | 36 +++++++++++++++++++++++-------------
|
||||
1 files changed, 23 insertions(+), 13 deletions(-)
|
||||
|
||||
diff --git a/sound/pci/hda/patch_sigmatel.c b/sound/pci/hda/patch_sigmatel.c
|
||||
index 616678f..a87b260 100644
|
||||
--- a/sound/pci/hda/patch_sigmatel.c
|
||||
+++ b/sound/pci/hda/patch_sigmatel.c
|
||||
@@ -4326,6 +4326,27 @@ static void stac_store_hints(struct hda_codec *codec)
|
||||
}
|
||||
}
|
||||
|
||||
+static void stac_issue_unsol_events(struct hda_codec *codec, int num_pins,
|
||||
+ const hda_nid_t *pins)
|
||||
+{
|
||||
+ while (num_pins--)
|
||||
+ stac_issue_unsol_event(codec, *pins++);
|
||||
+}
|
||||
+
|
||||
+/* fake event to set up pins */
|
||||
+static void stac_fake_hp_events(struct hda_codec *codec)
|
||||
+{
|
||||
+ struct sigmatel_spec *spec = codec->spec;
|
||||
+
|
||||
+ if (spec->autocfg.hp_outs)
|
||||
+ stac_issue_unsol_events(codec, spec->autocfg.hp_outs,
|
||||
+ spec->autocfg.hp_pins);
|
||||
+ if (spec->autocfg.line_outs &&
|
||||
+ spec->autocfg.line_out_pins[0] != spec->autocfg.hp_pins[0])
|
||||
+ stac_issue_unsol_events(codec, spec->autocfg.line_outs,
|
||||
+ spec->autocfg.line_out_pins);
|
||||
+}
|
||||
+
|
||||
static int stac92xx_init(struct hda_codec *codec)
|
||||
{
|
||||
struct sigmatel_spec *spec = codec->spec;
|
||||
@@ -4376,10 +4397,7 @@ static int stac92xx_init(struct hda_codec *codec)
|
||||
stac92xx_auto_set_pinctl(codec, spec->autocfg.line_out_pins[0],
|
||||
AC_PINCTL_OUT_EN);
|
||||
/* fake event to set up pins */
|
||||
- if (cfg->hp_pins[0])
|
||||
- stac_issue_unsol_event(codec, cfg->hp_pins[0]);
|
||||
- else if (cfg->line_out_pins[0])
|
||||
- stac_issue_unsol_event(codec, cfg->line_out_pins[0]);
|
||||
+ stac_fake_hp_events(codec);
|
||||
} else {
|
||||
stac92xx_auto_init_multi_out(codec);
|
||||
stac92xx_auto_init_hp_out(codec);
|
||||
@@ -5028,19 +5046,11 @@ static void stac927x_proc_hook(struct snd_info_buffer *buffer,
|
||||
#ifdef CONFIG_PM
|
||||
static int stac92xx_resume(struct hda_codec *codec)
|
||||
{
|
||||
- struct sigmatel_spec *spec = codec->spec;
|
||||
-
|
||||
stac92xx_init(codec);
|
||||
snd_hda_codec_resume_amp(codec);
|
||||
snd_hda_codec_resume_cache(codec);
|
||||
/* fake event to set up pins again to override cached values */
|
||||
- if (spec->hp_detect) {
|
||||
- if (spec->autocfg.hp_pins[0])
|
||||
- stac_issue_unsol_event(codec, spec->autocfg.hp_pins[0]);
|
||||
- else if (spec->autocfg.line_out_pins[0])
|
||||
- stac_issue_unsol_event(codec,
|
||||
- spec->autocfg.line_out_pins[0]);
|
||||
- }
|
||||
+ stac_fake_hp_events(codec);
|
||||
return 0;
|
||||
}
|
||||
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+43
@@ -0,0 +1,43 @@
|
||||
From d69882b450293b61af0820e75dc1bfb8823c58bd Mon Sep 17 00:00:00 2001
|
||||
From: =?UTF-8?q?Rafa=C5=82=20Mi=C5=82ecki?= <zajec5@gmail.com>
|
||||
Date: Fri, 23 Dec 2011 20:32:18 +0100
|
||||
Subject: [PATCH 017/130] drm/radeon/kms: workaround invalid AVI infoframe
|
||||
checksum issue
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
commit 92db7f6c860b8190571a9dc1fcbc16d003422fe8 upstream.
|
||||
|
||||
This change was verified to fix both issues with no video I've
|
||||
investigated. I've also checked checksum calculation with fglrx on:
|
||||
RV620, HD54xx, HD5450, HD6310, HD6320.
|
||||
|
||||
Signed-off-by: Rafał Miłecki <zajec5@gmail.com>
|
||||
Signed-off-by: Dave Airlie <airlied@redhat.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/gpu/drm/radeon/r600_hdmi.c | 7 +++++++
|
||||
1 files changed, 7 insertions(+), 0 deletions(-)
|
||||
|
||||
diff --git a/drivers/gpu/drm/radeon/r600_hdmi.c b/drivers/gpu/drm/radeon/r600_hdmi.c
|
||||
index f5ac7e7..c45d921 100644
|
||||
--- a/drivers/gpu/drm/radeon/r600_hdmi.c
|
||||
+++ b/drivers/gpu/drm/radeon/r600_hdmi.c
|
||||
@@ -196,6 +196,13 @@ static void r600_hdmi_videoinfoframe(
|
||||
frame[0xD] = (right_bar >> 8);
|
||||
|
||||
r600_hdmi_infoframe_checksum(0x82, 0x02, 0x0D, frame);
|
||||
+ /* Our header values (type, version, length) should be alright, Intel
|
||||
+ * is using the same. Checksum function also seems to be OK, it works
|
||||
+ * fine for audio infoframe. However calculated value is always lower
|
||||
+ * by 2 in comparison to fglrx. It breaks displaying anything in case
|
||||
+ * of TVs that strictly check the checksum. Hack it manually here to
|
||||
+ * workaround this issue. */
|
||||
+ frame[0x0] += 2;
|
||||
|
||||
WREG32(offset+R600_HDMI_VIDEOINFOFRAME_0,
|
||||
frame[0x0] | (frame[0x1] << 8) | (frame[0x2] << 16) | (frame[0x3] << 24));
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+40
@@ -0,0 +1,40 @@
|
||||
From 056276f2509223f4f07a0778f1f1b398fdc8ae87 Mon Sep 17 00:00:00 2001
|
||||
From: Alex Deucher <alexander.deucher@amd.com>
|
||||
Date: Tue, 3 Jan 2012 09:48:38 -0500
|
||||
Subject: [PATCH 018/130] drm/radeon/kms: disable writeback on pre-R300 asics
|
||||
|
||||
commit 28eebb703e28bc455ba704adb1026f76649b768c upstream.
|
||||
|
||||
We often end up missing fences on older asics with
|
||||
writeback enabled which leads to delays in the userspace
|
||||
accel code, so just disable it by default on those asics.
|
||||
|
||||
Reported-by: Helge Deller <deller@gmx.de>
|
||||
Reported-by: Dave Airlie <airlied@redhat.com>
|
||||
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
|
||||
Signed-off-by: Dave Airlie <airlied@redhat.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/gpu/drm/radeon/radeon_device.c | 5 ++++-
|
||||
1 files changed, 4 insertions(+), 1 deletions(-)
|
||||
|
||||
diff --git a/drivers/gpu/drm/radeon/radeon_device.c b/drivers/gpu/drm/radeon/radeon_device.c
|
||||
index c4d00a1..9b39145 100644
|
||||
--- a/drivers/gpu/drm/radeon/radeon_device.c
|
||||
+++ b/drivers/gpu/drm/radeon/radeon_device.c
|
||||
@@ -224,8 +224,11 @@ int radeon_wb_init(struct radeon_device *rdev)
|
||||
if (radeon_no_wb == 1)
|
||||
rdev->wb.enabled = false;
|
||||
else {
|
||||
- /* often unreliable on AGP */
|
||||
if (rdev->flags & RADEON_IS_AGP) {
|
||||
+ /* often unreliable on AGP */
|
||||
+ rdev->wb.enabled = false;
|
||||
+ } else if (rdev->family < CHIP_R300) {
|
||||
+ /* often unreliable on pre-r300 */
|
||||
rdev->wb.enabled = false;
|
||||
} else {
|
||||
rdev->wb.enabled = true;
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+70
@@ -0,0 +1,70 @@
|
||||
From a4064a0d9fab7c0a6aa4b6bf170d6ffaed93601a Mon Sep 17 00:00:00 2001
|
||||
From: =?UTF-8?q?Michel=20D=C3=A4nzer?= <michel.daenzer@amd.com>
|
||||
Date: Thu, 5 Jan 2012 18:42:17 +0100
|
||||
Subject: [PATCH 019/130] radeon: Fix disabling PCI bus mastering on big
|
||||
endian hosts.
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
commit 3df96909b75835d487a9178761622b0cbd7310d4 upstream.
|
||||
|
||||
It would previously write basically random bits to PCI configuration space...
|
||||
Not very surprising that the GPU tended to stop responding completely. The
|
||||
resulting MCE even froze the whole machine sometimes.
|
||||
|
||||
Now resetting the GPU after a lockup has at least a fighting chance of
|
||||
succeeding.
|
||||
|
||||
Signed-off-by: Michel Dänzer <michel.daenzer@amd.com>
|
||||
Reviewed-by: Alex Deucher <alexander.deucher@amd.com>
|
||||
Signed-off-by: Dave Airlie <airlied@redhat.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/gpu/drm/radeon/r100.c | 5 +++--
|
||||
drivers/gpu/drm/radeon/rs600.c | 4 ++--
|
||||
2 files changed, 5 insertions(+), 4 deletions(-)
|
||||
|
||||
diff --git a/drivers/gpu/drm/radeon/r100.c b/drivers/gpu/drm/radeon/r100.c
|
||||
index bfc08f6..31b0d1a 100644
|
||||
--- a/drivers/gpu/drm/radeon/r100.c
|
||||
+++ b/drivers/gpu/drm/radeon/r100.c
|
||||
@@ -2177,6 +2177,7 @@ bool r100_gpu_is_lockup(struct radeon_device *rdev)
|
||||
void r100_bm_disable(struct radeon_device *rdev)
|
||||
{
|
||||
u32 tmp;
|
||||
+ u16 tmp16;
|
||||
|
||||
/* disable bus mastering */
|
||||
tmp = RREG32(R_000030_BUS_CNTL);
|
||||
@@ -2187,8 +2188,8 @@ void r100_bm_disable(struct radeon_device *rdev)
|
||||
WREG32(R_000030_BUS_CNTL, (tmp & 0xFFFFFFFF) | 0x00000040);
|
||||
tmp = RREG32(RADEON_BUS_CNTL);
|
||||
mdelay(1);
|
||||
- pci_read_config_word(rdev->pdev, 0x4, (u16*)&tmp);
|
||||
- pci_write_config_word(rdev->pdev, 0x4, tmp & 0xFFFB);
|
||||
+ pci_read_config_word(rdev->pdev, 0x4, &tmp16);
|
||||
+ pci_write_config_word(rdev->pdev, 0x4, tmp16 & 0xFFFB);
|
||||
mdelay(1);
|
||||
}
|
||||
|
||||
diff --git a/drivers/gpu/drm/radeon/rs600.c b/drivers/gpu/drm/radeon/rs600.c
|
||||
index b1053d6..c259e21 100644
|
||||
--- a/drivers/gpu/drm/radeon/rs600.c
|
||||
+++ b/drivers/gpu/drm/radeon/rs600.c
|
||||
@@ -324,10 +324,10 @@ void rs600_hpd_fini(struct radeon_device *rdev)
|
||||
|
||||
void rs600_bm_disable(struct radeon_device *rdev)
|
||||
{
|
||||
- u32 tmp;
|
||||
+ u16 tmp;
|
||||
|
||||
/* disable bus mastering */
|
||||
- pci_read_config_word(rdev->pdev, 0x4, (u16*)&tmp);
|
||||
+ pci_read_config_word(rdev->pdev, 0x4, &tmp);
|
||||
pci_write_config_word(rdev->pdev, 0x4, tmp & 0xFFFB);
|
||||
mdelay(1);
|
||||
}
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+50
@@ -0,0 +1,50 @@
|
||||
From df673b323fa5ef227649ad218343f244261c0611 Mon Sep 17 00:00:00 2001
|
||||
From: Boaz Harrosh <bharrosh@panasas.com>
|
||||
Date: Fri, 6 Jan 2012 09:28:12 +0200
|
||||
Subject: [PATCH 020/130] pnfs-obj: pNFS errors are communicated on
|
||||
iodata->pnfs_error
|
||||
|
||||
commit 5c0b4129c07b902b27d3f3ebc087757f534a3abd upstream.
|
||||
|
||||
Some time along the way pNFS IO errors were switched to
|
||||
communicate with a special iodata->pnfs_error member instead
|
||||
of the regular RPC members. But objlayout was not switched
|
||||
over.
|
||||
|
||||
Fix that!
|
||||
Without this fix any IO error is hanged, because IO is not
|
||||
switched to MDS and pages are never cleared or read.
|
||||
|
||||
[Applies to 3.2.0. Same bug different patch for 3.1/0 Kernels]
|
||||
Signed-off-by: Boaz Harrosh <bharrosh@panasas.com>
|
||||
Signed-off-by: Trond Myklebust <Trond.Myklebust@netapp.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
fs/nfs/objlayout/objlayout.c | 4 ++++
|
||||
1 files changed, 4 insertions(+), 0 deletions(-)
|
||||
|
||||
diff --git a/fs/nfs/objlayout/objlayout.c b/fs/nfs/objlayout/objlayout.c
|
||||
index 72074e3..b3c2903 100644
|
||||
--- a/fs/nfs/objlayout/objlayout.c
|
||||
+++ b/fs/nfs/objlayout/objlayout.c
|
||||
@@ -254,6 +254,8 @@ objlayout_read_done(struct objlayout_io_res *oir, ssize_t status, bool sync)
|
||||
oir->status = rdata->task.tk_status = status;
|
||||
if (status >= 0)
|
||||
rdata->res.count = status;
|
||||
+ else
|
||||
+ rdata->pnfs_error = status;
|
||||
objlayout_iodone(oir);
|
||||
/* must not use oir after this point */
|
||||
|
||||
@@ -334,6 +336,8 @@ objlayout_write_done(struct objlayout_io_res *oir, ssize_t status, bool sync)
|
||||
if (status >= 0) {
|
||||
wdata->res.count = status;
|
||||
wdata->verf.committed = oir->committed;
|
||||
+ } else {
|
||||
+ wdata->pnfs_error = status;
|
||||
}
|
||||
objlayout_iodone(oir);
|
||||
/* must not use oir after this point */
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+92
@@ -0,0 +1,92 @@
|
||||
From 9c85d688c42a6feb8f72204730514ae658854828 Mon Sep 17 00:00:00 2001
|
||||
From: Boaz Harrosh <bharrosh@panasas.com>
|
||||
Date: Fri, 6 Jan 2012 09:31:20 +0200
|
||||
Subject: [PATCH 021/130] pnfs-obj: Must return layout on IO error
|
||||
|
||||
commit fe0fe83585f88346557868a803a479dfaaa0688a upstream.
|
||||
|
||||
As mandated by the standard. In case of an IO error, a pNFS
|
||||
objects layout driver must return it's layout. This is because
|
||||
all device errors are reported to the server as part of the
|
||||
layout return buffer.
|
||||
|
||||
This is implemented the same way PNFS_LAYOUTRET_ON_SETATTR
|
||||
is done, through a bit flag on the pnfs_layoutdriver_type->flags
|
||||
member. The flag is set by the layout driver that wants a
|
||||
layout_return preformed at pnfs_ld_{write,read}_done in case
|
||||
of an error.
|
||||
(Though I have not defined a wrapper like pnfs_ld_layoutret_on_setattr
|
||||
because this code is never called outside of pnfs.c and pnfs IO
|
||||
paths)
|
||||
|
||||
Without this patch 3.[0-2] Kernels leak memory and have an annoying
|
||||
WARN_ON after every IO error utilizing the pnfs-obj driver.
|
||||
|
||||
Signed-off-by: Boaz Harrosh <bharrosh@panasas.com>
|
||||
Signed-off-by: Trond Myklebust <Trond.Myklebust@netapp.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
fs/nfs/objlayout/objio_osd.c | 3 ++-
|
||||
fs/nfs/pnfs.c | 12 ++++++++++++
|
||||
fs/nfs/pnfs.h | 1 +
|
||||
3 files changed, 15 insertions(+), 1 deletions(-)
|
||||
|
||||
diff --git a/fs/nfs/objlayout/objio_osd.c b/fs/nfs/objlayout/objio_osd.c
|
||||
index c807ab9..55d0128 100644
|
||||
--- a/fs/nfs/objlayout/objio_osd.c
|
||||
+++ b/fs/nfs/objlayout/objio_osd.c
|
||||
@@ -551,7 +551,8 @@ static const struct nfs_pageio_ops objio_pg_write_ops = {
|
||||
static struct pnfs_layoutdriver_type objlayout_type = {
|
||||
.id = LAYOUT_OSD2_OBJECTS,
|
||||
.name = "LAYOUT_OSD2_OBJECTS",
|
||||
- .flags = PNFS_LAYOUTRET_ON_SETATTR,
|
||||
+ .flags = PNFS_LAYOUTRET_ON_SETATTR |
|
||||
+ PNFS_LAYOUTRET_ON_ERROR,
|
||||
|
||||
.alloc_layout_hdr = objlayout_alloc_layout_hdr,
|
||||
.free_layout_hdr = objlayout_free_layout_hdr,
|
||||
diff --git a/fs/nfs/pnfs.c b/fs/nfs/pnfs.c
|
||||
index 8e672a2..f881a63 100644
|
||||
--- a/fs/nfs/pnfs.c
|
||||
+++ b/fs/nfs/pnfs.c
|
||||
@@ -1178,6 +1178,15 @@ void pnfs_ld_write_done(struct nfs_write_data *data)
|
||||
put_lseg(data->lseg);
|
||||
data->lseg = NULL;
|
||||
dprintk("pnfs write error = %d\n", data->pnfs_error);
|
||||
+ if (NFS_SERVER(data->inode)->pnfs_curr_ld->flags &
|
||||
+ PNFS_LAYOUTRET_ON_ERROR) {
|
||||
+ /* Don't lo_commit on error, Server will needs to
|
||||
+ * preform a file recovery.
|
||||
+ */
|
||||
+ clear_bit(NFS_INO_LAYOUTCOMMIT,
|
||||
+ &NFS_I(data->inode)->flags);
|
||||
+ pnfs_return_layout(data->inode);
|
||||
+ }
|
||||
}
|
||||
data->mds_ops->rpc_release(data);
|
||||
}
|
||||
@@ -1267,6 +1276,9 @@ static void pnfs_ld_handle_read_error(struct nfs_read_data *data)
|
||||
put_lseg(data->lseg);
|
||||
data->lseg = NULL;
|
||||
dprintk("pnfs write error = %d\n", data->pnfs_error);
|
||||
+ if (NFS_SERVER(data->inode)->pnfs_curr_ld->flags &
|
||||
+ PNFS_LAYOUTRET_ON_ERROR)
|
||||
+ pnfs_return_layout(data->inode);
|
||||
|
||||
nfs_pageio_init_read_mds(&pgio, data->inode);
|
||||
|
||||
diff --git a/fs/nfs/pnfs.h b/fs/nfs/pnfs.h
|
||||
index 1509530..53d593a 100644
|
||||
--- a/fs/nfs/pnfs.h
|
||||
+++ b/fs/nfs/pnfs.h
|
||||
@@ -68,6 +68,7 @@ enum {
|
||||
enum layoutdriver_policy_flags {
|
||||
/* Should the pNFS client commit and return the layout upon a setattr */
|
||||
PNFS_LAYOUTRET_ON_SETATTR = 1 << 0,
|
||||
+ PNFS_LAYOUTRET_ON_ERROR = 1 << 1,
|
||||
};
|
||||
|
||||
struct nfs4_deviceid_node;
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
@@ -0,0 +1,94 @@
|
||||
From 1ef216baa398a27c95a9de67f36805cbeea81fe6 Mon Sep 17 00:00:00 2001
|
||||
From: Chuck Lever <chuck.lever@oracle.com>
|
||||
Date: Mon, 5 Dec 2011 15:40:30 -0500
|
||||
Subject: [PATCH 022/130] NFS: Retry mounting NFSROOT
|
||||
|
||||
commit 43717c7daebf10b43f12e68512484b3095bb1ba5 upstream.
|
||||
|
||||
Lukas Razik <linux@razik.name> reports that on his SPARC system,
|
||||
booting with an NFS root file system stopped working after commit
|
||||
56463e50 "NFS: Use super.c for NFSROOT mount option parsing."
|
||||
|
||||
We found that the network switch to which Lukas' client was attached
|
||||
was delaying access to the LAN after the client's NIC driver reported
|
||||
that its link was up. The delay was longer than the timeouts used in
|
||||
the NFS client during mounting.
|
||||
|
||||
NFSROOT worked for Lukas before commit 56463e50 because in those
|
||||
kernels, the client's first operation was an rpcbind request to
|
||||
determine which port the NFS server was listening on. When that
|
||||
request failed after a long timeout, the client simply selected the
|
||||
default NFS port (2049). By that time the switch was allowing access
|
||||
to the LAN, and the mount succeeded.
|
||||
|
||||
Neither of these client behaviors is desirable, so reverting 56463e50
|
||||
is really not a choice. Instead, introduce a mechanism that retries
|
||||
the NFSROOT mount request several times. This is the same tactic that
|
||||
normal user space NFS mounts employ to overcome server and network
|
||||
delays.
|
||||
|
||||
Signed-off-by: Lukas Razik <linux@razik.name>
|
||||
[ cel: match kernel coding style, add proper patch description ]
|
||||
[ cel: add exponential back-off ]
|
||||
Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
|
||||
Tested-by: Lukas Razik <linux@razik.name>
|
||||
Signed-off-by: Trond Myklebust <Trond.Myklebust@netapp.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
init/do_mounts.c | 35 +++++++++++++++++++++++++++++++----
|
||||
1 files changed, 31 insertions(+), 4 deletions(-)
|
||||
|
||||
diff --git a/init/do_mounts.c b/init/do_mounts.c
|
||||
index 0f6e1d9..db6e5ee 100644
|
||||
--- a/init/do_mounts.c
|
||||
+++ b/init/do_mounts.c
|
||||
@@ -398,15 +398,42 @@ out:
|
||||
}
|
||||
|
||||
#ifdef CONFIG_ROOT_NFS
|
||||
+
|
||||
+#define NFSROOT_TIMEOUT_MIN 5
|
||||
+#define NFSROOT_TIMEOUT_MAX 30
|
||||
+#define NFSROOT_RETRY_MAX 5
|
||||
+
|
||||
static int __init mount_nfs_root(void)
|
||||
{
|
||||
char *root_dev, *root_data;
|
||||
+ unsigned int timeout;
|
||||
+ int try, err;
|
||||
|
||||
- if (nfs_root_data(&root_dev, &root_data) != 0)
|
||||
- return 0;
|
||||
- if (do_mount_root(root_dev, "nfs", root_mountflags, root_data) != 0)
|
||||
+ err = nfs_root_data(&root_dev, &root_data);
|
||||
+ if (err != 0)
|
||||
return 0;
|
||||
- return 1;
|
||||
+
|
||||
+ /*
|
||||
+ * The server or network may not be ready, so try several
|
||||
+ * times. Stop after a few tries in case the client wants
|
||||
+ * to fall back to other boot methods.
|
||||
+ */
|
||||
+ timeout = NFSROOT_TIMEOUT_MIN;
|
||||
+ for (try = 1; ; try++) {
|
||||
+ err = do_mount_root(root_dev, "nfs",
|
||||
+ root_mountflags, root_data);
|
||||
+ if (err == 0)
|
||||
+ return 1;
|
||||
+ if (try > NFSROOT_RETRY_MAX)
|
||||
+ break;
|
||||
+
|
||||
+ /* Wait, in case the server refused us immediately */
|
||||
+ ssleep(timeout);
|
||||
+ timeout <<= 1;
|
||||
+ if (timeout > NFSROOT_TIMEOUT_MAX)
|
||||
+ timeout = NFSROOT_TIMEOUT_MAX;
|
||||
+ }
|
||||
+ return 0;
|
||||
}
|
||||
#endif
|
||||
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+30
@@ -0,0 +1,30 @@
|
||||
From a4d5a638ff204626f6244b3a316cf8f01ef3e2fa Mon Sep 17 00:00:00 2001
|
||||
From: Andy Adamson <andros@netapp.com>
|
||||
Date: Wed, 9 Nov 2011 13:58:20 -0500
|
||||
Subject: [PATCH 023/130] NFSv4.1: fix backchannel slotid off-by-one bug
|
||||
|
||||
commit 61f2e5106582d02f30b6807e3f9c07463c572ccb upstream.
|
||||
|
||||
Signed-off-by: Andy Adamson <andros@netapp.com>
|
||||
Signed-off-by: Trond Myklebust <Trond.Myklebust@netapp.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
fs/nfs/callback_proc.c | 2 +-
|
||||
1 files changed, 1 insertions(+), 1 deletions(-)
|
||||
|
||||
diff --git a/fs/nfs/callback_proc.c b/fs/nfs/callback_proc.c
|
||||
index 43926ad..54cea8a 100644
|
||||
--- a/fs/nfs/callback_proc.c
|
||||
+++ b/fs/nfs/callback_proc.c
|
||||
@@ -339,7 +339,7 @@ validate_seqid(struct nfs4_slot_table *tbl, struct cb_sequenceargs * args)
|
||||
dprintk("%s enter. slotid %d seqid %d\n",
|
||||
__func__, args->csa_slotid, args->csa_sequenceid);
|
||||
|
||||
- if (args->csa_slotid > NFS41_BC_MAX_CALLBACKS)
|
||||
+ if (args->csa_slotid >= NFS41_BC_MAX_CALLBACKS)
|
||||
return htonl(NFS4ERR_BADSLOT);
|
||||
|
||||
slot = tbl->slots + args->csa_slotid;
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+60
@@ -0,0 +1,60 @@
|
||||
From 876118d108ac910a4b4b4384b6d827ef9eb599bb Mon Sep 17 00:00:00 2001
|
||||
From: NeilBrown <neilb@suse.de>
|
||||
Date: Wed, 16 Nov 2011 11:46:31 +1100
|
||||
Subject: [PATCH 024/130] NFS - fix recent breakage to NFS error handling.
|
||||
|
||||
commit 2edb6bc3852c681c0d948245bd55108dc6407604 upstream.
|
||||
|
||||
From c6d615d2b97fe305cbf123a8751ced859dca1d5e Mon Sep 17 00:00:00 2001
|
||||
From: NeilBrown <neilb@suse.de>
|
||||
Date: Wed, 16 Nov 2011 09:39:05 +1100
|
||||
Subject: NFS - fix recent breakage to NFS error handling.
|
||||
|
||||
commit 02c24a82187d5a628c68edfe71ae60dc135cd178 made a small and
|
||||
presumably unintended change to write error handling in NFS.
|
||||
|
||||
Previously an error from filemap_write_and_wait_range would only be of
|
||||
interest if nfs_file_fsync did not return an error. After this commit,
|
||||
an error from filemap_write_and_wait_range would mean that (the rest of)
|
||||
nfs_file_fsync would not even be called.
|
||||
|
||||
This means that:
|
||||
1/ you are more likely to see EIO than e.g. EDQUOT or ENOSPC.
|
||||
2/ NFS_CONTEXT_ERROR_WRITE remains set for longer so more writes are
|
||||
synchronous.
|
||||
|
||||
This patch restores previous behaviour.
|
||||
|
||||
Cc: Josef Bacik <josef@redhat.com>
|
||||
Cc: Jan Kara <jack@suse.cz>
|
||||
Cc: Al Viro <viro@zeniv.linux.org.uk>
|
||||
Signed-off-by: NeilBrown <neilb@suse.de>
|
||||
Signed-off-by: Trond Myklebust <Trond.Myklebust@netapp.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
fs/nfs/file.c | 4 ++--
|
||||
1 files changed, 2 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/fs/nfs/file.c b/fs/nfs/file.c
|
||||
index 606ef0f..c43a452 100644
|
||||
--- a/fs/nfs/file.c
|
||||
+++ b/fs/nfs/file.c
|
||||
@@ -272,13 +272,13 @@ nfs_file_fsync(struct file *file, loff_t start, loff_t end, int datasync)
|
||||
datasync);
|
||||
|
||||
ret = filemap_write_and_wait_range(inode->i_mapping, start, end);
|
||||
- if (ret)
|
||||
- return ret;
|
||||
mutex_lock(&inode->i_mutex);
|
||||
|
||||
nfs_inc_stats(inode, NFSIOS_VFSFSYNC);
|
||||
have_error = test_and_clear_bit(NFS_CONTEXT_ERROR_WRITE, &ctx->flags);
|
||||
status = nfs_commit_inode(inode, FLUSH_SYNC);
|
||||
+ if (status >= 0 && ret < 0)
|
||||
+ status = ret;
|
||||
have_error |= test_bit(NFS_CONTEXT_ERROR_WRITE, &ctx->flags);
|
||||
if (have_error)
|
||||
ret = xchg(&ctx->error, 0);
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+313
@@ -0,0 +1,313 @@
|
||||
From ea3a3ed18130c4a0fe0dbdd3f7dabc59a67c5064 Mon Sep 17 00:00:00 2001
|
||||
From: Andy Adamson <andros@netapp.com>
|
||||
Date: Wed, 7 Dec 2011 11:55:27 -0500
|
||||
Subject: [PATCH 025/130] NFSv4: include bitmap in nfsv4 get acl data
|
||||
|
||||
commit bf118a342f10dafe44b14451a1392c3254629a1f upstream.
|
||||
|
||||
The NFSv4 bitmap size is unbounded: a server can return an arbitrary
|
||||
sized bitmap in an FATTR4_WORD0_ACL request. Replace using the
|
||||
nfs4_fattr_bitmap_maxsz as a guess to the maximum bitmask returned by a server
|
||||
with the inclusion of the bitmap (xdr length plus bitmasks) and the acl data
|
||||
xdr length to the (cached) acl page data.
|
||||
|
||||
This is a general solution to commit e5012d1f "NFSv4.1: update
|
||||
nfs4_fattr_bitmap_maxsz" and fixes hitting a BUG_ON in xdr_shrink_bufhead
|
||||
when getting ACLs.
|
||||
|
||||
Fix a bug in decode_getacl that returned -EINVAL on ACLs > page when getxattr
|
||||
was called with a NULL buffer, preventing ACL > PAGE_SIZE from being retrieved.
|
||||
|
||||
Signed-off-by: Andy Adamson <andros@netapp.com>
|
||||
Signed-off-by: Trond Myklebust <Trond.Myklebust@netapp.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
fs/nfs/nfs4proc.c | 96 ++++++++++++++++++++++++++------------------
|
||||
fs/nfs/nfs4xdr.c | 31 ++++++++++----
|
||||
include/linux/nfs_xdr.h | 5 ++
|
||||
include/linux/sunrpc/xdr.h | 2 +
|
||||
net/sunrpc/xdr.c | 3 +-
|
||||
5 files changed, 89 insertions(+), 48 deletions(-)
|
||||
|
||||
diff --git a/fs/nfs/nfs4proc.c b/fs/nfs/nfs4proc.c
|
||||
index d9f4d78..055d702 100644
|
||||
--- a/fs/nfs/nfs4proc.c
|
||||
+++ b/fs/nfs/nfs4proc.c
|
||||
@@ -3430,19 +3430,6 @@ static inline int nfs4_server_supports_acls(struct nfs_server *server)
|
||||
*/
|
||||
#define NFS4ACL_MAXPAGES (XATTR_SIZE_MAX >> PAGE_CACHE_SHIFT)
|
||||
|
||||
-static void buf_to_pages(const void *buf, size_t buflen,
|
||||
- struct page **pages, unsigned int *pgbase)
|
||||
-{
|
||||
- const void *p = buf;
|
||||
-
|
||||
- *pgbase = offset_in_page(buf);
|
||||
- p -= *pgbase;
|
||||
- while (p < buf + buflen) {
|
||||
- *(pages++) = virt_to_page(p);
|
||||
- p += PAGE_CACHE_SIZE;
|
||||
- }
|
||||
-}
|
||||
-
|
||||
static int buf_to_pages_noslab(const void *buf, size_t buflen,
|
||||
struct page **pages, unsigned int *pgbase)
|
||||
{
|
||||
@@ -3539,9 +3526,19 @@ out:
|
||||
nfs4_set_cached_acl(inode, acl);
|
||||
}
|
||||
|
||||
+/*
|
||||
+ * The getxattr API returns the required buffer length when called with a
|
||||
+ * NULL buf. The NFSv4 acl tool then calls getxattr again after allocating
|
||||
+ * the required buf. On a NULL buf, we send a page of data to the server
|
||||
+ * guessing that the ACL request can be serviced by a page. If so, we cache
|
||||
+ * up to the page of ACL data, and the 2nd call to getxattr is serviced by
|
||||
+ * the cache. If not so, we throw away the page, and cache the required
|
||||
+ * length. The next getxattr call will then produce another round trip to
|
||||
+ * the server, this time with the input buf of the required size.
|
||||
+ */
|
||||
static ssize_t __nfs4_get_acl_uncached(struct inode *inode, void *buf, size_t buflen)
|
||||
{
|
||||
- struct page *pages[NFS4ACL_MAXPAGES];
|
||||
+ struct page *pages[NFS4ACL_MAXPAGES] = {NULL, };
|
||||
struct nfs_getaclargs args = {
|
||||
.fh = NFS_FH(inode),
|
||||
.acl_pages = pages,
|
||||
@@ -3556,41 +3553,60 @@ static ssize_t __nfs4_get_acl_uncached(struct inode *inode, void *buf, size_t bu
|
||||
.rpc_argp = &args,
|
||||
.rpc_resp = &res,
|
||||
};
|
||||
- struct page *localpage = NULL;
|
||||
- int ret;
|
||||
+ int ret = -ENOMEM, npages, i, acl_len = 0;
|
||||
|
||||
- if (buflen < PAGE_SIZE) {
|
||||
- /* As long as we're doing a round trip to the server anyway,
|
||||
- * let's be prepared for a page of acl data. */
|
||||
- localpage = alloc_page(GFP_KERNEL);
|
||||
- resp_buf = page_address(localpage);
|
||||
- if (localpage == NULL)
|
||||
- return -ENOMEM;
|
||||
- args.acl_pages[0] = localpage;
|
||||
- args.acl_pgbase = 0;
|
||||
- args.acl_len = PAGE_SIZE;
|
||||
- } else {
|
||||
- resp_buf = buf;
|
||||
- buf_to_pages(buf, buflen, args.acl_pages, &args.acl_pgbase);
|
||||
+ npages = (buflen + PAGE_SIZE - 1) >> PAGE_SHIFT;
|
||||
+ /* As long as we're doing a round trip to the server anyway,
|
||||
+ * let's be prepared for a page of acl data. */
|
||||
+ if (npages == 0)
|
||||
+ npages = 1;
|
||||
+
|
||||
+ for (i = 0; i < npages; i++) {
|
||||
+ pages[i] = alloc_page(GFP_KERNEL);
|
||||
+ if (!pages[i])
|
||||
+ goto out_free;
|
||||
+ }
|
||||
+ if (npages > 1) {
|
||||
+ /* for decoding across pages */
|
||||
+ args.acl_scratch = alloc_page(GFP_KERNEL);
|
||||
+ if (!args.acl_scratch)
|
||||
+ goto out_free;
|
||||
}
|
||||
- ret = nfs4_call_sync(NFS_SERVER(inode)->client, NFS_SERVER(inode), &msg, &args.seq_args, &res.seq_res, 0);
|
||||
+ args.acl_len = npages * PAGE_SIZE;
|
||||
+ args.acl_pgbase = 0;
|
||||
+ /* Let decode_getfacl know not to fail if the ACL data is larger than
|
||||
+ * the page we send as a guess */
|
||||
+ if (buf == NULL)
|
||||
+ res.acl_flags |= NFS4_ACL_LEN_REQUEST;
|
||||
+ resp_buf = page_address(pages[0]);
|
||||
+
|
||||
+ dprintk("%s buf %p buflen %ld npages %d args.acl_len %ld\n",
|
||||
+ __func__, buf, buflen, npages, args.acl_len);
|
||||
+ ret = nfs4_call_sync(NFS_SERVER(inode)->client, NFS_SERVER(inode),
|
||||
+ &msg, &args.seq_args, &res.seq_res, 0);
|
||||
if (ret)
|
||||
goto out_free;
|
||||
- if (res.acl_len > args.acl_len)
|
||||
- nfs4_write_cached_acl(inode, NULL, res.acl_len);
|
||||
+
|
||||
+ acl_len = res.acl_len - res.acl_data_offset;
|
||||
+ if (acl_len > args.acl_len)
|
||||
+ nfs4_write_cached_acl(inode, NULL, acl_len);
|
||||
else
|
||||
- nfs4_write_cached_acl(inode, resp_buf, res.acl_len);
|
||||
+ nfs4_write_cached_acl(inode, resp_buf + res.acl_data_offset,
|
||||
+ acl_len);
|
||||
if (buf) {
|
||||
ret = -ERANGE;
|
||||
- if (res.acl_len > buflen)
|
||||
+ if (acl_len > buflen)
|
||||
goto out_free;
|
||||
- if (localpage)
|
||||
- memcpy(buf, resp_buf, res.acl_len);
|
||||
+ _copy_from_pages(buf, pages, res.acl_data_offset,
|
||||
+ res.acl_len);
|
||||
}
|
||||
- ret = res.acl_len;
|
||||
+ ret = acl_len;
|
||||
out_free:
|
||||
- if (localpage)
|
||||
- __free_page(localpage);
|
||||
+ for (i = 0; i < npages; i++)
|
||||
+ if (pages[i])
|
||||
+ __free_page(pages[i]);
|
||||
+ if (args.acl_scratch)
|
||||
+ __free_page(args.acl_scratch);
|
||||
return ret;
|
||||
}
|
||||
|
||||
@@ -3621,6 +3637,8 @@ static ssize_t nfs4_proc_get_acl(struct inode *inode, void *buf, size_t buflen)
|
||||
nfs_zap_acl_cache(inode);
|
||||
ret = nfs4_read_cached_acl(inode, buf, buflen);
|
||||
if (ret != -ENOENT)
|
||||
+ /* -ENOENT is returned if there is no ACL or if there is an ACL
|
||||
+ * but no cached acl data, just the acl length */
|
||||
return ret;
|
||||
return nfs4_get_acl_uncached(inode, buf, buflen);
|
||||
}
|
||||
diff --git a/fs/nfs/nfs4xdr.c b/fs/nfs/nfs4xdr.c
|
||||
index e6161b2..dcaf693 100644
|
||||
--- a/fs/nfs/nfs4xdr.c
|
||||
+++ b/fs/nfs/nfs4xdr.c
|
||||
@@ -2517,11 +2517,13 @@ static void nfs4_xdr_enc_getacl(struct rpc_rqst *req, struct xdr_stream *xdr,
|
||||
encode_compound_hdr(xdr, req, &hdr);
|
||||
encode_sequence(xdr, &args->seq_args, &hdr);
|
||||
encode_putfh(xdr, args->fh, &hdr);
|
||||
- replen = hdr.replen + op_decode_hdr_maxsz + nfs4_fattr_bitmap_maxsz + 1;
|
||||
+ replen = hdr.replen + op_decode_hdr_maxsz + 1;
|
||||
encode_getattr_two(xdr, FATTR4_WORD0_ACL, 0, &hdr);
|
||||
|
||||
xdr_inline_pages(&req->rq_rcv_buf, replen << 2,
|
||||
args->acl_pages, args->acl_pgbase, args->acl_len);
|
||||
+ xdr_set_scratch_buffer(xdr, page_address(args->acl_scratch), PAGE_SIZE);
|
||||
+
|
||||
encode_nops(&hdr);
|
||||
}
|
||||
|
||||
@@ -4957,17 +4959,18 @@ decode_restorefh(struct xdr_stream *xdr)
|
||||
}
|
||||
|
||||
static int decode_getacl(struct xdr_stream *xdr, struct rpc_rqst *req,
|
||||
- size_t *acl_len)
|
||||
+ struct nfs_getaclres *res)
|
||||
{
|
||||
- __be32 *savep;
|
||||
+ __be32 *savep, *bm_p;
|
||||
uint32_t attrlen,
|
||||
bitmap[3] = {0};
|
||||
struct kvec *iov = req->rq_rcv_buf.head;
|
||||
int status;
|
||||
|
||||
- *acl_len = 0;
|
||||
+ res->acl_len = 0;
|
||||
if ((status = decode_op_hdr(xdr, OP_GETATTR)) != 0)
|
||||
goto out;
|
||||
+ bm_p = xdr->p;
|
||||
if ((status = decode_attr_bitmap(xdr, bitmap)) != 0)
|
||||
goto out;
|
||||
if ((status = decode_attr_length(xdr, &attrlen, &savep)) != 0)
|
||||
@@ -4979,18 +4982,30 @@ static int decode_getacl(struct xdr_stream *xdr, struct rpc_rqst *req,
|
||||
size_t hdrlen;
|
||||
u32 recvd;
|
||||
|
||||
+ /* The bitmap (xdr len + bitmaps) and the attr xdr len words
|
||||
+ * are stored with the acl data to handle the problem of
|
||||
+ * variable length bitmaps.*/
|
||||
+ xdr->p = bm_p;
|
||||
+ res->acl_data_offset = be32_to_cpup(bm_p) + 2;
|
||||
+ res->acl_data_offset <<= 2;
|
||||
+
|
||||
/* We ignore &savep and don't do consistency checks on
|
||||
* the attr length. Let userspace figure it out.... */
|
||||
hdrlen = (u8 *)xdr->p - (u8 *)iov->iov_base;
|
||||
+ attrlen += res->acl_data_offset;
|
||||
recvd = req->rq_rcv_buf.len - hdrlen;
|
||||
if (attrlen > recvd) {
|
||||
- dprintk("NFS: server cheating in getattr"
|
||||
- " acl reply: attrlen %u > recvd %u\n",
|
||||
+ if (res->acl_flags & NFS4_ACL_LEN_REQUEST) {
|
||||
+ /* getxattr interface called with a NULL buf */
|
||||
+ res->acl_len = attrlen;
|
||||
+ goto out;
|
||||
+ }
|
||||
+ dprintk("NFS: acl reply: attrlen %u > recvd %u\n",
|
||||
attrlen, recvd);
|
||||
return -EINVAL;
|
||||
}
|
||||
xdr_read_pages(xdr, attrlen);
|
||||
- *acl_len = attrlen;
|
||||
+ res->acl_len = attrlen;
|
||||
} else
|
||||
status = -EOPNOTSUPP;
|
||||
|
||||
@@ -6028,7 +6043,7 @@ nfs4_xdr_dec_getacl(struct rpc_rqst *rqstp, struct xdr_stream *xdr,
|
||||
status = decode_putfh(xdr);
|
||||
if (status)
|
||||
goto out;
|
||||
- status = decode_getacl(xdr, rqstp, &res->acl_len);
|
||||
+ status = decode_getacl(xdr, rqstp, res);
|
||||
|
||||
out:
|
||||
return status;
|
||||
diff --git a/include/linux/nfs_xdr.h b/include/linux/nfs_xdr.h
|
||||
index 2a7c533..6c898af 100644
|
||||
--- a/include/linux/nfs_xdr.h
|
||||
+++ b/include/linux/nfs_xdr.h
|
||||
@@ -602,11 +602,16 @@ struct nfs_getaclargs {
|
||||
size_t acl_len;
|
||||
unsigned int acl_pgbase;
|
||||
struct page ** acl_pages;
|
||||
+ struct page * acl_scratch;
|
||||
struct nfs4_sequence_args seq_args;
|
||||
};
|
||||
|
||||
+/* getxattr ACL interface flags */
|
||||
+#define NFS4_ACL_LEN_REQUEST 0x0001 /* zero length getxattr buffer */
|
||||
struct nfs_getaclres {
|
||||
size_t acl_len;
|
||||
+ size_t acl_data_offset;
|
||||
+ int acl_flags;
|
||||
struct nfs4_sequence_res seq_res;
|
||||
};
|
||||
|
||||
diff --git a/include/linux/sunrpc/xdr.h b/include/linux/sunrpc/xdr.h
|
||||
index a20970e..af70af3 100644
|
||||
--- a/include/linux/sunrpc/xdr.h
|
||||
+++ b/include/linux/sunrpc/xdr.h
|
||||
@@ -191,6 +191,8 @@ extern int xdr_decode_array2(struct xdr_buf *buf, unsigned int base,
|
||||
struct xdr_array2_desc *desc);
|
||||
extern int xdr_encode_array2(struct xdr_buf *buf, unsigned int base,
|
||||
struct xdr_array2_desc *desc);
|
||||
+extern void _copy_from_pages(char *p, struct page **pages, size_t pgbase,
|
||||
+ size_t len);
|
||||
|
||||
/*
|
||||
* Provide some simple tools for XDR buffer overflow-checking etc.
|
||||
diff --git a/net/sunrpc/xdr.c b/net/sunrpc/xdr.c
|
||||
index 277ebd4..593f4c6 100644
|
||||
--- a/net/sunrpc/xdr.c
|
||||
+++ b/net/sunrpc/xdr.c
|
||||
@@ -296,7 +296,7 @@ _copy_to_pages(struct page **pages, size_t pgbase, const char *p, size_t len)
|
||||
* Copies data into an arbitrary memory location from an array of pages
|
||||
* The copy is assumed to be non-overlapping.
|
||||
*/
|
||||
-static void
|
||||
+void
|
||||
_copy_from_pages(char *p, struct page **pages, size_t pgbase, size_t len)
|
||||
{
|
||||
struct page **pgfrom;
|
||||
@@ -324,6 +324,7 @@ _copy_from_pages(char *p, struct page **pages, size_t pgbase, size_t len)
|
||||
|
||||
} while ((len -= copy) != 0);
|
||||
}
|
||||
+EXPORT_SYMBOL_GPL(_copy_from_pages);
|
||||
|
||||
/*
|
||||
* xdr_shrink_bufhead
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+147
@@ -0,0 +1,147 @@
|
||||
From e7d23a1c02013b27699c8d993ef0ceb6e3110955 Mon Sep 17 00:00:00 2001
|
||||
From: Jeff Layton <jlayton@redhat.com>
|
||||
Date: Tue, 20 Dec 2011 06:57:45 -0500
|
||||
Subject: [PATCH 026/130] nfs: fix regression in handling of context= option
|
||||
in NFSv4
|
||||
|
||||
commit 8a0d551a59ac92d8ff048d6cb29d3a02073e81e8 upstream.
|
||||
|
||||
Setting the security context of a NFSv4 mount via the context= mount
|
||||
option is currently broken. The NFSv4 codepath allocates a parsed
|
||||
options struct, and then parses the mount options to fill it. It
|
||||
eventually calls nfs4_remote_mount which calls security_init_mnt_opts.
|
||||
That clobbers the lsm_opts struct that was populated earlier. This bug
|
||||
also looks like it causes a small memory leak on each v4 mount where
|
||||
context= is used.
|
||||
|
||||
Fix this by moving the initialization of the lsm_opts into
|
||||
nfs_alloc_parsed_mount_data. Also, add a destructor for
|
||||
nfs_parsed_mount_data to make it easier to free all of the allocations
|
||||
hanging off of it, and to ensure that the security_free_mnt_opts is
|
||||
called whenever security_init_mnt_opts is.
|
||||
|
||||
I believe this regression was introduced quite some time ago, probably
|
||||
by commit c02d7adf.
|
||||
|
||||
Signed-off-by: Jeff Layton <jlayton@redhat.com>
|
||||
Signed-off-by: Trond Myklebust <Trond.Myklebust@netapp.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
fs/nfs/super.c | 43 +++++++++++++++++++------------------------
|
||||
1 files changed, 19 insertions(+), 24 deletions(-)
|
||||
|
||||
diff --git a/fs/nfs/super.c b/fs/nfs/super.c
|
||||
index 1347774..3ada13c 100644
|
||||
--- a/fs/nfs/super.c
|
||||
+++ b/fs/nfs/super.c
|
||||
@@ -909,10 +909,24 @@ static struct nfs_parsed_mount_data *nfs_alloc_parsed_mount_data(unsigned int ve
|
||||
data->auth_flavor_len = 1;
|
||||
data->version = version;
|
||||
data->minorversion = 0;
|
||||
+ security_init_mnt_opts(&data->lsm_opts);
|
||||
}
|
||||
return data;
|
||||
}
|
||||
|
||||
+static void nfs_free_parsed_mount_data(struct nfs_parsed_mount_data *data)
|
||||
+{
|
||||
+ if (data) {
|
||||
+ kfree(data->client_address);
|
||||
+ kfree(data->mount_server.hostname);
|
||||
+ kfree(data->nfs_server.export_path);
|
||||
+ kfree(data->nfs_server.hostname);
|
||||
+ kfree(data->fscache_uniq);
|
||||
+ security_free_mnt_opts(&data->lsm_opts);
|
||||
+ kfree(data);
|
||||
+ }
|
||||
+}
|
||||
+
|
||||
/*
|
||||
* Sanity-check a server address provided by the mount command.
|
||||
*
|
||||
@@ -2220,9 +2234,7 @@ static struct dentry *nfs_fs_mount(struct file_system_type *fs_type,
|
||||
data = nfs_alloc_parsed_mount_data(NFS_DEFAULT_VERSION);
|
||||
mntfh = nfs_alloc_fhandle();
|
||||
if (data == NULL || mntfh == NULL)
|
||||
- goto out_free_fh;
|
||||
-
|
||||
- security_init_mnt_opts(&data->lsm_opts);
|
||||
+ goto out;
|
||||
|
||||
/* Validate the mount data */
|
||||
error = nfs_validate_mount_data(raw_data, data, mntfh, dev_name);
|
||||
@@ -2234,8 +2246,6 @@ static struct dentry *nfs_fs_mount(struct file_system_type *fs_type,
|
||||
#ifdef CONFIG_NFS_V4
|
||||
if (data->version == 4) {
|
||||
mntroot = nfs4_try_mount(flags, dev_name, data);
|
||||
- kfree(data->client_address);
|
||||
- kfree(data->nfs_server.export_path);
|
||||
goto out;
|
||||
}
|
||||
#endif /* CONFIG_NFS_V4 */
|
||||
@@ -2290,13 +2300,8 @@ static struct dentry *nfs_fs_mount(struct file_system_type *fs_type,
|
||||
s->s_flags |= MS_ACTIVE;
|
||||
|
||||
out:
|
||||
- kfree(data->nfs_server.hostname);
|
||||
- kfree(data->mount_server.hostname);
|
||||
- kfree(data->fscache_uniq);
|
||||
- security_free_mnt_opts(&data->lsm_opts);
|
||||
-out_free_fh:
|
||||
+ nfs_free_parsed_mount_data(data);
|
||||
nfs_free_fhandle(mntfh);
|
||||
- kfree(data);
|
||||
return mntroot;
|
||||
|
||||
out_err_nosb:
|
||||
@@ -2623,9 +2628,7 @@ nfs4_remote_mount(struct file_system_type *fs_type, int flags,
|
||||
|
||||
mntfh = nfs_alloc_fhandle();
|
||||
if (data == NULL || mntfh == NULL)
|
||||
- goto out_free_fh;
|
||||
-
|
||||
- security_init_mnt_opts(&data->lsm_opts);
|
||||
+ goto out;
|
||||
|
||||
/* Get a volume representation */
|
||||
server = nfs4_create_server(data, mntfh);
|
||||
@@ -2677,13 +2680,10 @@ nfs4_remote_mount(struct file_system_type *fs_type, int flags,
|
||||
|
||||
s->s_flags |= MS_ACTIVE;
|
||||
|
||||
- security_free_mnt_opts(&data->lsm_opts);
|
||||
nfs_free_fhandle(mntfh);
|
||||
return mntroot;
|
||||
|
||||
out:
|
||||
- security_free_mnt_opts(&data->lsm_opts);
|
||||
-out_free_fh:
|
||||
nfs_free_fhandle(mntfh);
|
||||
return ERR_PTR(error);
|
||||
|
||||
@@ -2838,7 +2838,7 @@ static struct dentry *nfs4_mount(struct file_system_type *fs_type,
|
||||
|
||||
data = nfs_alloc_parsed_mount_data(4);
|
||||
if (data == NULL)
|
||||
- goto out_free_data;
|
||||
+ goto out;
|
||||
|
||||
/* Validate the mount data */
|
||||
error = nfs4_validate_mount_data(raw_data, data, dev_name);
|
||||
@@ -2852,12 +2852,7 @@ static struct dentry *nfs4_mount(struct file_system_type *fs_type,
|
||||
error = PTR_ERR(res);
|
||||
|
||||
out:
|
||||
- kfree(data->client_address);
|
||||
- kfree(data->nfs_server.export_path);
|
||||
- kfree(data->nfs_server.hostname);
|
||||
- kfree(data->fscache_uniq);
|
||||
-out_free_data:
|
||||
- kfree(data);
|
||||
+ nfs_free_parsed_mount_data(data);
|
||||
dprintk("<-- nfs4_mount() = %d%s\n", error,
|
||||
error != 0 ? " [error]" : "");
|
||||
return res;
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+35
@@ -0,0 +1,35 @@
|
||||
From 1d30ef7aee8f11c3f90038ba7d57a82e0acbadb5 Mon Sep 17 00:00:00 2001
|
||||
From: Chase Douglas <chase.douglas@canonical.com>
|
||||
Date: Mon, 7 Nov 2011 11:08:05 -0800
|
||||
Subject: [PATCH 027/130] HID: bump maximum global item tag report size to 96
|
||||
bytes
|
||||
|
||||
commit e46e927b9b7e8d95526e69322855243882b7e1a3 upstream.
|
||||
|
||||
This allows the latest N-Trig devices to function properly.
|
||||
|
||||
BugLink: https://bugs.launchpad.net/bugs/724831
|
||||
|
||||
Signed-off-by: Chase Douglas <chase.douglas@canonical.com>
|
||||
Signed-off-by: Jiri Kosina <jkosina@suse.cz>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/hid/hid-core.c | 2 +-
|
||||
1 files changed, 1 insertions(+), 1 deletions(-)
|
||||
|
||||
diff --git a/drivers/hid/hid-core.c b/drivers/hid/hid-core.c
|
||||
index af35384..1473067 100644
|
||||
--- a/drivers/hid/hid-core.c
|
||||
+++ b/drivers/hid/hid-core.c
|
||||
@@ -362,7 +362,7 @@ static int hid_parser_global(struct hid_parser *parser, struct hid_item *item)
|
||||
|
||||
case HID_GLOBAL_ITEM_TAG_REPORT_SIZE:
|
||||
parser->global.report_size = item_udata(item);
|
||||
- if (parser->global.report_size > 32) {
|
||||
+ if (parser->global.report_size > 96) {
|
||||
dbg_hid("invalid report_size %d\n",
|
||||
parser->global.report_size);
|
||||
return -1;
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+33
@@ -0,0 +1,33 @@
|
||||
From f60dd210e7edd913a760ca4c4f9df2c6341f5ef8 Mon Sep 17 00:00:00 2001
|
||||
From: David Herrmann <dh.herrmann@googlemail.com>
|
||||
Date: Wed, 7 Dec 2011 21:33:59 +0100
|
||||
Subject: [PATCH 028/130] HID: wiimote: Select INPUT_FF_MEMLESS
|
||||
|
||||
commit ef6f41157f3864d9bf42671b2ed66062dcafb72e upstream.
|
||||
|
||||
We depend on memless force-feedback support, therefore correctly select the
|
||||
related config options.
|
||||
|
||||
Reported-by: Randy Dunlap <rdunlap@xenotime.net>
|
||||
Signed-off-by: David Herrmann <dh.herrmann@googlemail.com>
|
||||
Signed-off-by: Jiri Kosina <jkosina@suse.cz>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/hid/Kconfig | 1 +
|
||||
1 files changed, 1 insertions(+), 0 deletions(-)
|
||||
|
||||
diff --git a/drivers/hid/Kconfig b/drivers/hid/Kconfig
|
||||
index 22a4a05..332c22a 100644
|
||||
--- a/drivers/hid/Kconfig
|
||||
+++ b/drivers/hid/Kconfig
|
||||
@@ -620,6 +620,7 @@ config HID_WIIMOTE
|
||||
depends on BT_HIDP
|
||||
depends on LEDS_CLASS
|
||||
select POWER_SUPPLY
|
||||
+ select INPUT_FF_MEMLESS
|
||||
---help---
|
||||
Support for the Nintendo Wii Remote bluetooth device.
|
||||
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+81
@@ -0,0 +1,81 @@
|
||||
From e20542f497522671fa121d7612442a2557bfa2ff Mon Sep 17 00:00:00 2001
|
||||
From: Bhavesh Parekh <bparekh@nvidia.com>
|
||||
Date: Wed, 30 Nov 2011 17:43:42 +0530
|
||||
Subject: [PATCH 029/130] UBI: fix missing scrub when there is a bit-flip
|
||||
|
||||
commit e801e128b2200c40a0ec236cf2330b2586b6e05a upstream.
|
||||
|
||||
Under some cases, when scrubbing the PEB if we did not get the lock on
|
||||
the PEB it fails to scrub. Add that PEB again to the scrub list
|
||||
|
||||
Artem: minor amendments.
|
||||
|
||||
Signed-off-by: Bhavesh Parekh <bparekh@nvidia.com>
|
||||
Signed-off-by: Artem Bityutskiy <artem.bityutskiy@linux.intel.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/mtd/ubi/eba.c | 6 ++++--
|
||||
drivers/mtd/ubi/ubi.h | 2 ++
|
||||
drivers/mtd/ubi/wl.c | 5 ++++-
|
||||
3 files changed, 10 insertions(+), 3 deletions(-)
|
||||
|
||||
diff --git a/drivers/mtd/ubi/eba.c b/drivers/mtd/ubi/eba.c
|
||||
index fb7f19b..cd26da8 100644
|
||||
--- a/drivers/mtd/ubi/eba.c
|
||||
+++ b/drivers/mtd/ubi/eba.c
|
||||
@@ -1028,12 +1028,14 @@ int ubi_eba_copy_leb(struct ubi_device *ubi, int from, int to,
|
||||
* 'ubi_wl_put_peb()' function on the @ubi->move_mutex. In turn, we are
|
||||
* holding @ubi->move_mutex and go sleep on the LEB lock. So, if the
|
||||
* LEB is already locked, we just do not move it and return
|
||||
- * %MOVE_CANCEL_RACE, which means that UBI will re-try, but later.
|
||||
+ * %MOVE_RETRY. Note, we do not return %MOVE_CANCEL_RACE here because
|
||||
+ * we do not know the reasons of the contention - it may be just a
|
||||
+ * normal I/O on this LEB, so we want to re-try.
|
||||
*/
|
||||
err = leb_write_trylock(ubi, vol_id, lnum);
|
||||
if (err) {
|
||||
dbg_wl("contention on LEB %d:%d, cancel", vol_id, lnum);
|
||||
- return MOVE_CANCEL_RACE;
|
||||
+ return MOVE_RETRY;
|
||||
}
|
||||
|
||||
/*
|
||||
diff --git a/drivers/mtd/ubi/ubi.h b/drivers/mtd/ubi/ubi.h
|
||||
index dc64c76..d51d75d 100644
|
||||
--- a/drivers/mtd/ubi/ubi.h
|
||||
+++ b/drivers/mtd/ubi/ubi.h
|
||||
@@ -120,6 +120,7 @@ enum {
|
||||
* PEB
|
||||
* MOVE_CANCEL_BITFLIPS: canceled because a bit-flip was detected in the
|
||||
* target PEB
|
||||
+ * MOVE_RETRY: retry scrubbing the PEB
|
||||
*/
|
||||
enum {
|
||||
MOVE_CANCEL_RACE = 1,
|
||||
@@ -127,6 +128,7 @@ enum {
|
||||
MOVE_TARGET_RD_ERR,
|
||||
MOVE_TARGET_WR_ERR,
|
||||
MOVE_CANCEL_BITFLIPS,
|
||||
+ MOVE_RETRY,
|
||||
};
|
||||
|
||||
/**
|
||||
diff --git a/drivers/mtd/ubi/wl.c b/drivers/mtd/ubi/wl.c
|
||||
index 42c684c..277c429 100644
|
||||
--- a/drivers/mtd/ubi/wl.c
|
||||
+++ b/drivers/mtd/ubi/wl.c
|
||||
@@ -795,7 +795,10 @@ static int wear_leveling_worker(struct ubi_device *ubi, struct ubi_work *wrk,
|
||||
protect = 1;
|
||||
goto out_not_moved;
|
||||
}
|
||||
-
|
||||
+ if (err == MOVE_RETRY) {
|
||||
+ scrubbing = 1;
|
||||
+ goto out_not_moved;
|
||||
+ }
|
||||
if (err == MOVE_CANCEL_BITFLIPS || err == MOVE_TARGET_WR_ERR ||
|
||||
err == MOVE_TARGET_RD_ERR) {
|
||||
/*
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+52
@@ -0,0 +1,52 @@
|
||||
From e9089302a9d795113e8efe652fe30331d75d1fd8 Mon Sep 17 00:00:00 2001
|
||||
From: Artem Bityutskiy <artem.bityutskiy@linux.intel.com>
|
||||
Date: Thu, 5 Jan 2012 10:47:18 +0200
|
||||
Subject: [PATCH 030/130] UBI: fix use-after-free on error path
|
||||
|
||||
commit e57e0d8e818512047fe379157c3f77f1b9fabffb upstream.
|
||||
|
||||
When we fail to erase a PEB, we free the corresponding erase entry object,
|
||||
but then re-schedule this object if the error code was something like -EAGAIN.
|
||||
Obviously, it is a bug to use the object after we have freed it.
|
||||
|
||||
Reported-by: Emese Revfy <re.emese@gmail.com>
|
||||
Signed-off-by: Artem Bityutskiy <artem.bityutskiy@linux.intel.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/mtd/ubi/wl.c | 7 ++++---
|
||||
1 files changed, 4 insertions(+), 3 deletions(-)
|
||||
|
||||
diff --git a/drivers/mtd/ubi/wl.c b/drivers/mtd/ubi/wl.c
|
||||
index 277c429..0696e36 100644
|
||||
--- a/drivers/mtd/ubi/wl.c
|
||||
+++ b/drivers/mtd/ubi/wl.c
|
||||
@@ -1052,7 +1052,6 @@ static int erase_worker(struct ubi_device *ubi, struct ubi_work *wl_wrk,
|
||||
|
||||
ubi_err("failed to erase PEB %d, error %d", pnum, err);
|
||||
kfree(wl_wrk);
|
||||
- kmem_cache_free(ubi_wl_entry_slab, e);
|
||||
|
||||
if (err == -EINTR || err == -ENOMEM || err == -EAGAIN ||
|
||||
err == -EBUSY) {
|
||||
@@ -1065,14 +1064,16 @@ static int erase_worker(struct ubi_device *ubi, struct ubi_work *wl_wrk,
|
||||
goto out_ro;
|
||||
}
|
||||
return err;
|
||||
- } else if (err != -EIO) {
|
||||
+ }
|
||||
+
|
||||
+ kmem_cache_free(ubi_wl_entry_slab, e);
|
||||
+ if (err != -EIO)
|
||||
/*
|
||||
* If this is not %-EIO, we have no idea what to do. Scheduling
|
||||
* this physical eraseblock for erasure again would cause
|
||||
* errors again and again. Well, lets switch to R/O mode.
|
||||
*/
|
||||
goto out_ro;
|
||||
- }
|
||||
|
||||
/* It is %-EIO, the PEB went bad */
|
||||
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+32
@@ -0,0 +1,32 @@
|
||||
From 9d9e1e743ab7ca6f40a0f6f60f5ebda2a6b8b07b Mon Sep 17 00:00:00 2001
|
||||
From: Alex Williamson <alex.williamson@redhat.com>
|
||||
Date: Wed, 16 Nov 2011 09:24:16 -0700
|
||||
Subject: [PATCH 031/130] PCI: Fix PCI_EXP_TYPE_RC_EC value
|
||||
|
||||
commit 1830ea91c20b06608f7cdb2455ce05ba834b3214 upstream.
|
||||
|
||||
Spec shows this as 1010b = 0xa
|
||||
|
||||
Signed-off-by: Alex Williamson <alex.williamson@redhat.com>
|
||||
Signed-off-by: Jesse Barnes <jbarnes@virtuousgeek.org>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
include/linux/pci_regs.h | 2 +-
|
||||
1 files changed, 1 insertions(+), 1 deletions(-)
|
||||
|
||||
diff --git a/include/linux/pci_regs.h b/include/linux/pci_regs.h
|
||||
index b5d9657..411c412 100644
|
||||
--- a/include/linux/pci_regs.h
|
||||
+++ b/include/linux/pci_regs.h
|
||||
@@ -392,7 +392,7 @@
|
||||
#define PCI_EXP_TYPE_DOWNSTREAM 0x6 /* Downstream Port */
|
||||
#define PCI_EXP_TYPE_PCI_BRIDGE 0x7 /* PCI/PCI-X Bridge */
|
||||
#define PCI_EXP_TYPE_RC_END 0x9 /* Root Complex Integrated Endpoint */
|
||||
-#define PCI_EXP_TYPE_RC_EC 0x10 /* Root Complex Event Collector */
|
||||
+#define PCI_EXP_TYPE_RC_EC 0xa /* Root Complex Event Collector */
|
||||
#define PCI_EXP_FLAGS_SLOT 0x0100 /* Slot implemented */
|
||||
#define PCI_EXP_FLAGS_IRQ 0x3e00 /* Interrupt message number */
|
||||
#define PCI_EXP_DEVCAP 4 /* Device capabilities */
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+53
@@ -0,0 +1,53 @@
|
||||
From 63365de9ebb1b944d0306668f726ad62a08a0371 Mon Sep 17 00:00:00 2001
|
||||
From: "Eric W. Biederman" <ebiederm@xmission.com>
|
||||
Date: Mon, 17 Oct 2011 11:46:06 -0700
|
||||
Subject: [PATCH 032/130] PCI: msi: Disable msi interrupts when we initialize
|
||||
a pci device
|
||||
|
||||
commit a776c491ca5e38c26d9f66923ff574d041e747f4 upstream.
|
||||
|
||||
I traced a nasty kexec on panic boot failure to the fact that we had
|
||||
screaming msi interrupts and we were not disabling the msi messages at
|
||||
kernel startup. The booting kernel had not enabled those interupts so
|
||||
was not prepared to handle them.
|
||||
|
||||
I can see no reason why we would ever want to leave the msi interrupts
|
||||
enabled at boot if something else has enabled those interrupts. The pci
|
||||
spec specifies that msi interrupts should be off by default. Drivers
|
||||
are expected to enable the msi interrupts if they want to use them. Our
|
||||
interrupt handling code reprograms the interrupt handlers at boot and
|
||||
will not be be able to do anything useful with an unexpected interrupt.
|
||||
|
||||
This patch applies cleanly all of the way back to 2.6.32 where I noticed
|
||||
the problem.
|
||||
|
||||
Signed-off-by: Eric W. Biederman <ebiederm@xmission.com>
|
||||
Signed-off-by: Jesse Barnes <jbarnes@virtuousgeek.org>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/pci/msi.c | 10 ++++++++++
|
||||
1 files changed, 10 insertions(+), 0 deletions(-)
|
||||
|
||||
diff --git a/drivers/pci/msi.c b/drivers/pci/msi.c
|
||||
index 0e6d04d..e3efb43 100644
|
||||
--- a/drivers/pci/msi.c
|
||||
+++ b/drivers/pci/msi.c
|
||||
@@ -870,5 +870,15 @@ EXPORT_SYMBOL(pci_msi_enabled);
|
||||
|
||||
void pci_msi_init_pci_dev(struct pci_dev *dev)
|
||||
{
|
||||
+ int pos;
|
||||
INIT_LIST_HEAD(&dev->msi_list);
|
||||
+
|
||||
+ /* Disable the msi hardware to avoid screaming interrupts
|
||||
+ * during boot. This is the power on reset default so
|
||||
+ * usually this should be a noop.
|
||||
+ */
|
||||
+ pos = pci_find_capability(dev, PCI_CAP_ID_MSI);
|
||||
+ if (pos)
|
||||
+ msi_set_enable(dev, pos, 0);
|
||||
+ msix_set_enable(dev, 0);
|
||||
}
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+65
@@ -0,0 +1,65 @@
|
||||
From 5040b50e89f45f17231e6d2ad101596bedc5e431 Mon Sep 17 00:00:00 2001
|
||||
From: Gary Hade <garyhade@us.ibm.com>
|
||||
Date: Mon, 14 Nov 2011 15:42:16 -0800
|
||||
Subject: [PATCH 033/130] x86/PCI: Ignore CPU non-addressable _CRS reserved
|
||||
memory resources
|
||||
|
||||
commit ae5cd86455381282ece162966183d3f208c6fad7 upstream.
|
||||
|
||||
This assures that a _CRS reserved host bridge window or window region is
|
||||
not used if it is not addressable by the CPU. The new code either trims
|
||||
the window to exclude the non-addressable portion or totally ignores the
|
||||
window if the entire window is non-addressable.
|
||||
|
||||
The current code has been shown to be problematic with 32-bit non-PAE
|
||||
kernels on systems where _CRS reserves resources above 4GB.
|
||||
|
||||
Signed-off-by: Gary Hade <garyhade@us.ibm.com>
|
||||
Reviewed-by: Bjorn Helgaas <bhelgaas@google.com>
|
||||
Cc: Thomas Renninger <trenn@novell.com>
|
||||
Cc: linux-kernel@vger.kernel.org
|
||||
Signed-off-by: Jesse Barnes <jbarnes@virtuousgeek.org>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
arch/x86/pci/acpi.c | 18 ++++++++++++++++--
|
||||
1 files changed, 16 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/arch/x86/pci/acpi.c b/arch/x86/pci/acpi.c
|
||||
index 404f21a..f8348ab 100644
|
||||
--- a/arch/x86/pci/acpi.c
|
||||
+++ b/arch/x86/pci/acpi.c
|
||||
@@ -149,7 +149,7 @@ setup_resource(struct acpi_resource *acpi_res, void *data)
|
||||
struct acpi_resource_address64 addr;
|
||||
acpi_status status;
|
||||
unsigned long flags;
|
||||
- u64 start, end;
|
||||
+ u64 start, orig_end, end;
|
||||
|
||||
status = resource_to_addr(acpi_res, &addr);
|
||||
if (!ACPI_SUCCESS(status))
|
||||
@@ -165,7 +165,21 @@ setup_resource(struct acpi_resource *acpi_res, void *data)
|
||||
return AE_OK;
|
||||
|
||||
start = addr.minimum + addr.translation_offset;
|
||||
- end = addr.maximum + addr.translation_offset;
|
||||
+ orig_end = end = addr.maximum + addr.translation_offset;
|
||||
+
|
||||
+ /* Exclude non-addressable range or non-addressable portion of range */
|
||||
+ end = min(end, (u64)iomem_resource.end);
|
||||
+ if (end <= start) {
|
||||
+ dev_info(&info->bridge->dev,
|
||||
+ "host bridge window [%#llx-%#llx] "
|
||||
+ "(ignored, not CPU addressable)\n", start, orig_end);
|
||||
+ return AE_OK;
|
||||
+ } else if (orig_end != end) {
|
||||
+ dev_info(&info->bridge->dev,
|
||||
+ "host bridge window [%#llx-%#llx] "
|
||||
+ "([%#llx-%#llx] ignored, not CPU addressable)\n",
|
||||
+ start, orig_end, end + 1, orig_end);
|
||||
+ }
|
||||
|
||||
res = &info->res[info->res_num];
|
||||
res->name = info->name;
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+160
@@ -0,0 +1,160 @@
|
||||
From c6f611b87ae8cf8a5bd1fc916b4b63e0fd48d6f3 Mon Sep 17 00:00:00 2001
|
||||
From: Bjorn Helgaas <bhelgaas@google.com>
|
||||
Date: Thu, 5 Jan 2012 14:27:19 -0700
|
||||
Subject: [PATCH 034/130] x86/PCI: amd: factor out MMCONFIG discovery
|
||||
|
||||
commit 24d25dbfa63c376323096660bfa9ad45a08870ce upstream.
|
||||
|
||||
This factors out the AMD native MMCONFIG discovery so we can use it
|
||||
outside amd_bus.c.
|
||||
|
||||
amd_bus.c reads AMD MSRs so it can remove the MMCONFIG area from the
|
||||
PCI resources. We may also need the MMCONFIG information to work
|
||||
around BIOS defects in the ACPI MCFG table.
|
||||
|
||||
Cc: Borislav Petkov <borislav.petkov@amd.com>
|
||||
Cc: Yinghai Lu <yinghai@kernel.org>
|
||||
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
|
||||
Signed-off-by: Jesse Barnes <jbarnes@virtuousgeek.org>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
arch/x86/include/asm/amd_nb.h | 2 +
|
||||
arch/x86/kernel/amd_nb.c | 31 ++++++++++++++++++++++++++++++
|
||||
arch/x86/pci/amd_bus.c | 42 ++++++++++------------------------------
|
||||
3 files changed, 44 insertions(+), 31 deletions(-)
|
||||
|
||||
diff --git a/arch/x86/include/asm/amd_nb.h b/arch/x86/include/asm/amd_nb.h
|
||||
index 8e41071..49ad773 100644
|
||||
--- a/arch/x86/include/asm/amd_nb.h
|
||||
+++ b/arch/x86/include/asm/amd_nb.h
|
||||
@@ -1,6 +1,7 @@
|
||||
#ifndef _ASM_X86_AMD_NB_H
|
||||
#define _ASM_X86_AMD_NB_H
|
||||
|
||||
+#include <linux/ioport.h>
|
||||
#include <linux/pci.h>
|
||||
|
||||
struct amd_nb_bus_dev_range {
|
||||
@@ -13,6 +14,7 @@ extern const struct pci_device_id amd_nb_misc_ids[];
|
||||
extern const struct amd_nb_bus_dev_range amd_nb_bus_dev_ranges[];
|
||||
|
||||
extern bool early_is_amd_nb(u32 value);
|
||||
+extern struct resource *amd_get_mmconfig_range(struct resource *res);
|
||||
extern int amd_cache_northbridges(void);
|
||||
extern void amd_flush_garts(void);
|
||||
extern int amd_numa_init(void);
|
||||
diff --git a/arch/x86/kernel/amd_nb.c b/arch/x86/kernel/amd_nb.c
|
||||
index 4c39baa..bae1efe 100644
|
||||
--- a/arch/x86/kernel/amd_nb.c
|
||||
+++ b/arch/x86/kernel/amd_nb.c
|
||||
@@ -119,6 +119,37 @@ bool __init early_is_amd_nb(u32 device)
|
||||
return false;
|
||||
}
|
||||
|
||||
+struct resource *amd_get_mmconfig_range(struct resource *res)
|
||||
+{
|
||||
+ u32 address;
|
||||
+ u64 base, msr;
|
||||
+ unsigned segn_busn_bits;
|
||||
+
|
||||
+ if (boot_cpu_data.x86_vendor != X86_VENDOR_AMD)
|
||||
+ return NULL;
|
||||
+
|
||||
+ /* assume all cpus from fam10h have mmconfig */
|
||||
+ if (boot_cpu_data.x86 < 0x10)
|
||||
+ return NULL;
|
||||
+
|
||||
+ address = MSR_FAM10H_MMIO_CONF_BASE;
|
||||
+ rdmsrl(address, msr);
|
||||
+
|
||||
+ /* mmconfig is not enabled */
|
||||
+ if (!(msr & FAM10H_MMIO_CONF_ENABLE))
|
||||
+ return NULL;
|
||||
+
|
||||
+ base = msr & (FAM10H_MMIO_CONF_BASE_MASK<<FAM10H_MMIO_CONF_BASE_SHIFT);
|
||||
+
|
||||
+ segn_busn_bits = (msr >> FAM10H_MMIO_CONF_BUSRANGE_SHIFT) &
|
||||
+ FAM10H_MMIO_CONF_BUSRANGE_MASK;
|
||||
+
|
||||
+ res->flags = IORESOURCE_MEM;
|
||||
+ res->start = base;
|
||||
+ res->end = base + (1ULL<<(segn_busn_bits + 20)) - 1;
|
||||
+ return res;
|
||||
+}
|
||||
+
|
||||
int amd_get_subcaches(int cpu)
|
||||
{
|
||||
struct pci_dev *link = node_to_amd_nb(amd_get_nb_id(cpu))->link;
|
||||
diff --git a/arch/x86/pci/amd_bus.c b/arch/x86/pci/amd_bus.c
|
||||
index 026e493..385a940 100644
|
||||
--- a/arch/x86/pci/amd_bus.c
|
||||
+++ b/arch/x86/pci/amd_bus.c
|
||||
@@ -30,34 +30,6 @@ static struct pci_hostbridge_probe pci_probes[] __initdata = {
|
||||
{ 0, 0x18, PCI_VENDOR_ID_AMD, 0x1300 },
|
||||
};
|
||||
|
||||
-static u64 __initdata fam10h_mmconf_start;
|
||||
-static u64 __initdata fam10h_mmconf_end;
|
||||
-static void __init get_pci_mmcfg_amd_fam10h_range(void)
|
||||
-{
|
||||
- u32 address;
|
||||
- u64 base, msr;
|
||||
- unsigned segn_busn_bits;
|
||||
-
|
||||
- /* assume all cpus from fam10h have mmconf */
|
||||
- if (boot_cpu_data.x86 < 0x10)
|
||||
- return;
|
||||
-
|
||||
- address = MSR_FAM10H_MMIO_CONF_BASE;
|
||||
- rdmsrl(address, msr);
|
||||
-
|
||||
- /* mmconfig is not enable */
|
||||
- if (!(msr & FAM10H_MMIO_CONF_ENABLE))
|
||||
- return;
|
||||
-
|
||||
- base = msr & (FAM10H_MMIO_CONF_BASE_MASK<<FAM10H_MMIO_CONF_BASE_SHIFT);
|
||||
-
|
||||
- segn_busn_bits = (msr >> FAM10H_MMIO_CONF_BUSRANGE_SHIFT) &
|
||||
- FAM10H_MMIO_CONF_BUSRANGE_MASK;
|
||||
-
|
||||
- fam10h_mmconf_start = base;
|
||||
- fam10h_mmconf_end = base + (1ULL<<(segn_busn_bits + 20)) - 1;
|
||||
-}
|
||||
-
|
||||
#define RANGE_NUM 16
|
||||
|
||||
/**
|
||||
@@ -85,6 +57,9 @@ static int __init early_fill_mp_bus_info(void)
|
||||
u64 val;
|
||||
u32 address;
|
||||
bool found;
|
||||
+ struct resource fam10h_mmconf_res, *fam10h_mmconf;
|
||||
+ u64 fam10h_mmconf_start;
|
||||
+ u64 fam10h_mmconf_end;
|
||||
|
||||
if (!early_pci_allowed())
|
||||
return -1;
|
||||
@@ -211,12 +186,17 @@ static int __init early_fill_mp_bus_info(void)
|
||||
subtract_range(range, RANGE_NUM, 0, end);
|
||||
|
||||
/* get mmconfig */
|
||||
- get_pci_mmcfg_amd_fam10h_range();
|
||||
+ fam10h_mmconf = amd_get_mmconfig_range(&fam10h_mmconf_res);
|
||||
/* need to take out mmconf range */
|
||||
- if (fam10h_mmconf_end) {
|
||||
- printk(KERN_DEBUG "Fam 10h mmconf [%llx, %llx]\n", fam10h_mmconf_start, fam10h_mmconf_end);
|
||||
+ if (fam10h_mmconf) {
|
||||
+ printk(KERN_DEBUG "Fam 10h mmconf %pR\n", fam10h_mmconf);
|
||||
+ fam10h_mmconf_start = fam10h_mmconf->start;
|
||||
+ fam10h_mmconf_end = fam10h_mmconf->end;
|
||||
subtract_range(range, RANGE_NUM, fam10h_mmconf_start,
|
||||
fam10h_mmconf_end + 1);
|
||||
+ } else {
|
||||
+ fam10h_mmconf_start = 0;
|
||||
+ fam10h_mmconf_end = 0;
|
||||
}
|
||||
|
||||
/* mmio resource */
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+37
@@ -0,0 +1,37 @@
|
||||
From a67bd4738894215f045d9d1aed024277cb5ae99e Mon Sep 17 00:00:00 2001
|
||||
From: Bjorn Helgaas <bhelgaas@google.com>
|
||||
Date: Thu, 12 Jan 2012 08:01:40 -0700
|
||||
Subject: [PATCH 035/130] x86/PCI: build amd_bus.o only when CONFIG_AMD_NB=y
|
||||
|
||||
commit 5cf9a4e69c1ff0ccdd1d2b7404f95c0531355274 upstream.
|
||||
|
||||
We only need amd_bus.o for AMD systems with PCI. arch/x86/pci/Makefile
|
||||
already depends on CONFIG_PCI=y, so this patch just adds the dependency
|
||||
on CONFIG_AMD_NB.
|
||||
|
||||
Cc: Yinghai Lu <yinghai@kernel.org>
|
||||
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
|
||||
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
arch/x86/pci/Makefile | 3 ++-
|
||||
1 files changed, 2 insertions(+), 1 deletions(-)
|
||||
|
||||
diff --git a/arch/x86/pci/Makefile b/arch/x86/pci/Makefile
|
||||
index 6b8759f..d24d3da 100644
|
||||
--- a/arch/x86/pci/Makefile
|
||||
+++ b/arch/x86/pci/Makefile
|
||||
@@ -18,8 +18,9 @@ obj-$(CONFIG_X86_NUMAQ) += numaq_32.o
|
||||
obj-$(CONFIG_X86_MRST) += mrst.o
|
||||
|
||||
obj-y += common.o early.o
|
||||
-obj-y += amd_bus.o bus_numa.o
|
||||
+obj-y += bus_numa.o
|
||||
|
||||
+obj-$(CONFIG_AMD_NB) += amd_bus.o
|
||||
obj-$(CONFIG_PCI_CNB20LE_QUIRK) += broadcom_bus.o
|
||||
|
||||
ifeq ($(CONFIG_PCI_DEBUG),y)
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+56
@@ -0,0 +1,56 @@
|
||||
From c96f90776325ceb9fcda278cba8bc85e287d8d15 Mon Sep 17 00:00:00 2001
|
||||
From: "nagalakshmi.nandigama@lsi.com" <nagalakshmi.nandigama@lsi.com>
|
||||
Date: Thu, 1 Dec 2011 07:52:56 +0530
|
||||
Subject: [PATCH 036/130] SCSI: mpt2sas: Release spinlock for the raid device
|
||||
list before blocking it
|
||||
|
||||
commit 30c43282f3d347f47f9e05199d2b14f56f3f2837 upstream.
|
||||
|
||||
Added code to release the spinlock that is used to protect the
|
||||
raid device list before calling a function that can block. The
|
||||
blocking was causing a reschedule, and subsequently it is tried
|
||||
to acquire the same lock, resulting in a panic (NMI Watchdog
|
||||
detecting a CPU lockup).
|
||||
|
||||
Signed-off-by: Nagalakshmi Nandigama <nagalakshmi.nandigama@lsi.com>
|
||||
Signed-off-by: James Bottomley <JBottomley@Parallels.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/scsi/mpt2sas/mpt2sas_scsih.c | 7 ++++---
|
||||
1 files changed, 4 insertions(+), 3 deletions(-)
|
||||
|
||||
diff --git a/drivers/scsi/mpt2sas/mpt2sas_scsih.c b/drivers/scsi/mpt2sas/mpt2sas_scsih.c
|
||||
index d570573..3a4f666 100644
|
||||
--- a/drivers/scsi/mpt2sas/mpt2sas_scsih.c
|
||||
+++ b/drivers/scsi/mpt2sas/mpt2sas_scsih.c
|
||||
@@ -6714,6 +6714,7 @@ _scsih_mark_responding_raid_device(struct MPT2SAS_ADAPTER *ioc, u64 wwid,
|
||||
} else
|
||||
sas_target_priv_data = NULL;
|
||||
raid_device->responding = 1;
|
||||
+ spin_unlock_irqrestore(&ioc->raid_device_lock, flags);
|
||||
starget_printk(KERN_INFO, raid_device->starget,
|
||||
"handle(0x%04x), wwid(0x%016llx)\n", handle,
|
||||
(unsigned long long)raid_device->wwid);
|
||||
@@ -6724,16 +6725,16 @@ _scsih_mark_responding_raid_device(struct MPT2SAS_ADAPTER *ioc, u64 wwid,
|
||||
*/
|
||||
_scsih_init_warpdrive_properties(ioc, raid_device);
|
||||
if (raid_device->handle == handle)
|
||||
- goto out;
|
||||
+ return;
|
||||
printk(KERN_INFO "\thandle changed from(0x%04x)!!!\n",
|
||||
raid_device->handle);
|
||||
raid_device->handle = handle;
|
||||
if (sas_target_priv_data)
|
||||
sas_target_priv_data->handle = handle;
|
||||
- goto out;
|
||||
+ return;
|
||||
}
|
||||
}
|
||||
- out:
|
||||
+
|
||||
spin_unlock_irqrestore(&ioc->raid_device_lock, flags);
|
||||
}
|
||||
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+177
@@ -0,0 +1,177 @@
|
||||
From fe5907648567469336c06cf215932adac76a8e11 Mon Sep 17 00:00:00 2001
|
||||
From: "nagalakshmi.nandigama@lsi.com" <nagalakshmi.nandigama@lsi.com>
|
||||
Date: Thu, 1 Dec 2011 07:53:08 +0530
|
||||
Subject: [PATCH 037/130] SCSI: mpt2sas : Fix for memory allocation error for
|
||||
large host credits
|
||||
|
||||
commit aff132d95ffe14eca96cab90597cdd010b457af7 upstream.
|
||||
|
||||
The amount of memory required for tracking chain buffers is rather
|
||||
large, and when the host credit count is big, memory allocation
|
||||
failure occurs inside __get_free_pages.
|
||||
|
||||
The fix is to limit the number of chains to 100,000. In addition,
|
||||
the number of host credits is limited to 30,000 IOs. However this
|
||||
limitation can be overridden this using the command line option
|
||||
max_queue_depth. The algorithm for calculating the
|
||||
reply_post_queue_depth is changed so that it is equal to
|
||||
(reply_free_queue_depth + 16), previously it was (reply_free_queue_depth * 2).
|
||||
|
||||
Signed-off-by: Nagalakshmi Nandigama <nagalakshmi.nandigama@lsi.com>
|
||||
Signed-off-by: James Bottomley <JBottomley@Parallels.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/scsi/mpt2sas/mpt2sas_base.c | 83 +++++++++++-----------------------
|
||||
drivers/scsi/mpt2sas/mpt2sas_scsih.c | 4 +-
|
||||
2 files changed, 29 insertions(+), 58 deletions(-)
|
||||
|
||||
diff --git a/drivers/scsi/mpt2sas/mpt2sas_base.c b/drivers/scsi/mpt2sas/mpt2sas_base.c
|
||||
index beda04a..0794c72 100644
|
||||
--- a/drivers/scsi/mpt2sas/mpt2sas_base.c
|
||||
+++ b/drivers/scsi/mpt2sas/mpt2sas_base.c
|
||||
@@ -65,6 +65,8 @@ static MPT_CALLBACK mpt_callbacks[MPT_MAX_CALLBACKS];
|
||||
|
||||
#define FAULT_POLLING_INTERVAL 1000 /* in milliseconds */
|
||||
|
||||
+#define MAX_HBA_QUEUE_DEPTH 30000
|
||||
+#define MAX_CHAIN_DEPTH 100000
|
||||
static int max_queue_depth = -1;
|
||||
module_param(max_queue_depth, int, 0);
|
||||
MODULE_PARM_DESC(max_queue_depth, " max controller queue depth ");
|
||||
@@ -2311,8 +2313,6 @@ _base_release_memory_pools(struct MPT2SAS_ADAPTER *ioc)
|
||||
}
|
||||
if (ioc->chain_dma_pool)
|
||||
pci_pool_destroy(ioc->chain_dma_pool);
|
||||
- }
|
||||
- if (ioc->chain_lookup) {
|
||||
free_pages((ulong)ioc->chain_lookup, ioc->chain_pages);
|
||||
ioc->chain_lookup = NULL;
|
||||
}
|
||||
@@ -2330,9 +2330,7 @@ static int
|
||||
_base_allocate_memory_pools(struct MPT2SAS_ADAPTER *ioc, int sleep_flag)
|
||||
{
|
||||
struct mpt2sas_facts *facts;
|
||||
- u32 queue_size, queue_diff;
|
||||
u16 max_sge_elements;
|
||||
- u16 num_of_reply_frames;
|
||||
u16 chains_needed_per_io;
|
||||
u32 sz, total_sz, reply_post_free_sz;
|
||||
u32 retry_sz;
|
||||
@@ -2359,7 +2357,8 @@ _base_allocate_memory_pools(struct MPT2SAS_ADAPTER *ioc, int sleep_flag)
|
||||
max_request_credit = (max_queue_depth < facts->RequestCredit)
|
||||
? max_queue_depth : facts->RequestCredit;
|
||||
else
|
||||
- max_request_credit = facts->RequestCredit;
|
||||
+ max_request_credit = min_t(u16, facts->RequestCredit,
|
||||
+ MAX_HBA_QUEUE_DEPTH);
|
||||
|
||||
ioc->hba_queue_depth = max_request_credit;
|
||||
ioc->hi_priority_depth = facts->HighPriorityCredit;
|
||||
@@ -2400,50 +2399,25 @@ _base_allocate_memory_pools(struct MPT2SAS_ADAPTER *ioc, int sleep_flag)
|
||||
}
|
||||
ioc->chains_needed_per_io = chains_needed_per_io;
|
||||
|
||||
- /* reply free queue sizing - taking into account for events */
|
||||
- num_of_reply_frames = ioc->hba_queue_depth + 32;
|
||||
-
|
||||
- /* number of replies frames can't be a multiple of 16 */
|
||||
- /* decrease number of reply frames by 1 */
|
||||
- if (!(num_of_reply_frames % 16))
|
||||
- num_of_reply_frames--;
|
||||
-
|
||||
- /* calculate number of reply free queue entries
|
||||
- * (must be multiple of 16)
|
||||
- */
|
||||
-
|
||||
- /* (we know reply_free_queue_depth is not a multiple of 16) */
|
||||
- queue_size = num_of_reply_frames;
|
||||
- queue_size += 16 - (queue_size % 16);
|
||||
- ioc->reply_free_queue_depth = queue_size;
|
||||
-
|
||||
- /* reply descriptor post queue sizing */
|
||||
- /* this size should be the number of request frames + number of reply
|
||||
- * frames
|
||||
- */
|
||||
-
|
||||
- queue_size = ioc->hba_queue_depth + num_of_reply_frames + 1;
|
||||
- /* round up to 16 byte boundary */
|
||||
- if (queue_size % 16)
|
||||
- queue_size += 16 - (queue_size % 16);
|
||||
-
|
||||
- /* check against IOC maximum reply post queue depth */
|
||||
- if (queue_size > facts->MaxReplyDescriptorPostQueueDepth) {
|
||||
- queue_diff = queue_size -
|
||||
- facts->MaxReplyDescriptorPostQueueDepth;
|
||||
+ /* reply free queue sizing - taking into account for 64 FW events */
|
||||
+ ioc->reply_free_queue_depth = ioc->hba_queue_depth + 64;
|
||||
|
||||
- /* round queue_diff up to multiple of 16 */
|
||||
- if (queue_diff % 16)
|
||||
- queue_diff += 16 - (queue_diff % 16);
|
||||
-
|
||||
- /* adjust hba_queue_depth, reply_free_queue_depth,
|
||||
- * and queue_size
|
||||
- */
|
||||
- ioc->hba_queue_depth -= (queue_diff / 2);
|
||||
- ioc->reply_free_queue_depth -= (queue_diff / 2);
|
||||
- queue_size = facts->MaxReplyDescriptorPostQueueDepth;
|
||||
+ /* align the reply post queue on the next 16 count boundary */
|
||||
+ if (!ioc->reply_free_queue_depth % 16)
|
||||
+ ioc->reply_post_queue_depth = ioc->reply_free_queue_depth + 16;
|
||||
+ else
|
||||
+ ioc->reply_post_queue_depth = ioc->reply_free_queue_depth +
|
||||
+ 32 - (ioc->reply_free_queue_depth % 16);
|
||||
+ if (ioc->reply_post_queue_depth >
|
||||
+ facts->MaxReplyDescriptorPostQueueDepth) {
|
||||
+ ioc->reply_post_queue_depth = min_t(u16,
|
||||
+ (facts->MaxReplyDescriptorPostQueueDepth -
|
||||
+ (facts->MaxReplyDescriptorPostQueueDepth % 16)),
|
||||
+ (ioc->hba_queue_depth - (ioc->hba_queue_depth % 16)));
|
||||
+ ioc->reply_free_queue_depth = ioc->reply_post_queue_depth - 16;
|
||||
+ ioc->hba_queue_depth = ioc->reply_free_queue_depth - 64;
|
||||
}
|
||||
- ioc->reply_post_queue_depth = queue_size;
|
||||
+
|
||||
|
||||
dinitprintk(ioc, printk(MPT2SAS_INFO_FMT "scatter gather: "
|
||||
"sge_in_main_msg(%d), sge_per_chain(%d), sge_per_io(%d), "
|
||||
@@ -2529,15 +2503,12 @@ _base_allocate_memory_pools(struct MPT2SAS_ADAPTER *ioc, int sleep_flag)
|
||||
"depth(%d)\n", ioc->name, ioc->request,
|
||||
ioc->scsiio_depth));
|
||||
|
||||
- /* loop till the allocation succeeds */
|
||||
- do {
|
||||
- sz = ioc->chain_depth * sizeof(struct chain_tracker);
|
||||
- ioc->chain_pages = get_order(sz);
|
||||
- ioc->chain_lookup = (struct chain_tracker *)__get_free_pages(
|
||||
- GFP_KERNEL, ioc->chain_pages);
|
||||
- if (ioc->chain_lookup == NULL)
|
||||
- ioc->chain_depth -= 100;
|
||||
- } while (ioc->chain_lookup == NULL);
|
||||
+ ioc->chain_depth = min_t(u32, ioc->chain_depth, MAX_CHAIN_DEPTH);
|
||||
+ sz = ioc->chain_depth * sizeof(struct chain_tracker);
|
||||
+ ioc->chain_pages = get_order(sz);
|
||||
+
|
||||
+ ioc->chain_lookup = (struct chain_tracker *)__get_free_pages(
|
||||
+ GFP_KERNEL, ioc->chain_pages);
|
||||
ioc->chain_dma_pool = pci_pool_create("chain pool", ioc->pdev,
|
||||
ioc->request_sz, 16, 0);
|
||||
if (!ioc->chain_dma_pool) {
|
||||
diff --git a/drivers/scsi/mpt2sas/mpt2sas_scsih.c b/drivers/scsi/mpt2sas/mpt2sas_scsih.c
|
||||
index 3a4f666..9bc6fb2 100644
|
||||
--- a/drivers/scsi/mpt2sas/mpt2sas_scsih.c
|
||||
+++ b/drivers/scsi/mpt2sas/mpt2sas_scsih.c
|
||||
@@ -1007,8 +1007,8 @@ _scsih_get_chain_buffer_tracker(struct MPT2SAS_ADAPTER *ioc, u16 smid)
|
||||
spin_lock_irqsave(&ioc->scsi_lookup_lock, flags);
|
||||
if (list_empty(&ioc->free_chain_list)) {
|
||||
spin_unlock_irqrestore(&ioc->scsi_lookup_lock, flags);
|
||||
- printk(MPT2SAS_WARN_FMT "chain buffers not available\n",
|
||||
- ioc->name);
|
||||
+ dfailprintk(ioc, printk(MPT2SAS_WARN_FMT "chain buffers not "
|
||||
+ "available\n", ioc->name));
|
||||
return NULL;
|
||||
}
|
||||
chain_req = list_entry(ioc->free_chain_list.next,
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+78
@@ -0,0 +1,78 @@
|
||||
From fbefcde91f27d0a80ebe70c0b3359b2e6c463cc0 Mon Sep 17 00:00:00 2001
|
||||
From: Ian Campbell <Ian.Campbell@citrix.com>
|
||||
Date: Wed, 4 Jan 2012 09:34:49 +0000
|
||||
Subject: [PATCH 038/130] xen/xenbus: Reject replies with payload >
|
||||
XENSTORE_PAYLOAD_MAX.
|
||||
|
||||
commit 9e7860cee18241633eddb36a4c34c7b61d8cecbc upstream.
|
||||
|
||||
Haogang Chen found out that:
|
||||
|
||||
There is a potential integer overflow in process_msg() that could result
|
||||
in cross-domain attack.
|
||||
|
||||
body = kmalloc(msg->hdr.len + 1, GFP_NOIO | __GFP_HIGH);
|
||||
|
||||
When a malicious guest passes 0xffffffff in msg->hdr.len, the subsequent
|
||||
call to xb_read() would write to a zero-length buffer.
|
||||
|
||||
The other end of this connection is always the xenstore backend daemon
|
||||
so there is no guest (malicious or otherwise) which can do this. The
|
||||
xenstore daemon is a trusted component in the system.
|
||||
|
||||
However this seem like a reasonable robustness improvement so we should
|
||||
have it.
|
||||
|
||||
And Ian when read the API docs found that:
|
||||
The payload length (len field of the header) is limited to 4096
|
||||
(XENSTORE_PAYLOAD_MAX) in both directions. If a client exceeds the
|
||||
limit, its xenstored connection will be immediately killed by
|
||||
xenstored, which is usually catastrophic from the client's point of
|
||||
view. Clients (particularly domains, which cannot just reconnect)
|
||||
should avoid this.
|
||||
|
||||
so this patch checks against that instead.
|
||||
|
||||
This also avoids a potential integer overflow pointed out by Haogang Chen.
|
||||
|
||||
Signed-off-by: Ian Campbell <ian.campbell@citrix.com>
|
||||
Cc: Haogang Chen <haogangchen@gmail.com>
|
||||
Signed-off-by: Konrad Rzeszutek Wilk <konrad.wilk@oracle.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/xen/xenbus/xenbus_xs.c | 6 ++++++
|
||||
include/xen/interface/io/xs_wire.h | 3 +++
|
||||
2 files changed, 9 insertions(+), 0 deletions(-)
|
||||
|
||||
diff --git a/drivers/xen/xenbus/xenbus_xs.c b/drivers/xen/xenbus/xenbus_xs.c
|
||||
index ede860f..a580b17 100644
|
||||
--- a/drivers/xen/xenbus/xenbus_xs.c
|
||||
+++ b/drivers/xen/xenbus/xenbus_xs.c
|
||||
@@ -801,6 +801,12 @@ static int process_msg(void)
|
||||
goto out;
|
||||
}
|
||||
|
||||
+ if (msg->hdr.len > XENSTORE_PAYLOAD_MAX) {
|
||||
+ kfree(msg);
|
||||
+ err = -EINVAL;
|
||||
+ goto out;
|
||||
+ }
|
||||
+
|
||||
body = kmalloc(msg->hdr.len + 1, GFP_NOIO | __GFP_HIGH);
|
||||
if (body == NULL) {
|
||||
kfree(msg);
|
||||
diff --git a/include/xen/interface/io/xs_wire.h b/include/xen/interface/io/xs_wire.h
|
||||
index f6f07aa..7cdfca2 100644
|
||||
--- a/include/xen/interface/io/xs_wire.h
|
||||
+++ b/include/xen/interface/io/xs_wire.h
|
||||
@@ -87,4 +87,7 @@ struct xenstore_domain_interface {
|
||||
XENSTORE_RING_IDX rsp_cons, rsp_prod;
|
||||
};
|
||||
|
||||
+/* Violating this is very bad. See docs/misc/xenstore.txt. */
|
||||
+#define XENSTORE_PAYLOAD_MAX 4096
|
||||
+
|
||||
#endif /* _XS_WIRE_H */
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+56
@@ -0,0 +1,56 @@
|
||||
From b08c639fb415855bbca91bff089b8bada0f4b044 Mon Sep 17 00:00:00 2001
|
||||
From: NeilBrown <neilb@suse.de>
|
||||
Date: Mon, 9 Jan 2012 01:41:51 +1100
|
||||
Subject: [PATCH 039/130] md/raid1: perform bad-block tests for WriteMostly
|
||||
devices too.
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
commit 307729c8bc5b5a41361af8af95906eee7552acb1 upstream.
|
||||
|
||||
We normally try to avoid reading from write-mostly devices, but when
|
||||
we do we really have to check for bad blocks and be sure not to
|
||||
try reading them.
|
||||
|
||||
With the current code, best_good_sectors might not get set and that
|
||||
causes zero-length read requests to be send down which is very
|
||||
confusing.
|
||||
|
||||
This bug was introduced in commit d2eb35acfdccbe2 and so the patch
|
||||
is suitable for 3.1.x and 3.2.x
|
||||
|
||||
Reported-and-tested-by: Michał Mirosław <mirq-linux@rere.qmqm.pl>
|
||||
Reported-and-tested-by: Art -kwaak- van Breemen <ard@telegraafnet.nl>
|
||||
Signed-off-by: NeilBrown <neilb@suse.de>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/md/raid1.c | 11 ++++++++++-
|
||||
1 files changed, 10 insertions(+), 1 deletions(-)
|
||||
|
||||
diff --git a/drivers/md/raid1.c b/drivers/md/raid1.c
|
||||
index ede2461..7d9e071 100644
|
||||
--- a/drivers/md/raid1.c
|
||||
+++ b/drivers/md/raid1.c
|
||||
@@ -525,8 +525,17 @@ static int read_balance(struct r1conf *conf, struct r1bio *r1_bio, int *max_sect
|
||||
if (test_bit(WriteMostly, &rdev->flags)) {
|
||||
/* Don't balance among write-mostly, just
|
||||
* use the first as a last resort */
|
||||
- if (best_disk < 0)
|
||||
+ if (best_disk < 0) {
|
||||
+ if (is_badblock(rdev, this_sector, sectors,
|
||||
+ &first_bad, &bad_sectors)) {
|
||||
+ if (first_bad < this_sector)
|
||||
+ /* Cannot use this */
|
||||
+ continue;
|
||||
+ best_good_sectors = first_bad - this_sector;
|
||||
+ } else
|
||||
+ best_good_sectors = sectors;
|
||||
best_disk = disk;
|
||||
+ }
|
||||
continue;
|
||||
}
|
||||
/* This is a reasonable device to use. It might
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+52
@@ -0,0 +1,52 @@
|
||||
From 52e6ae83dbb962de0a33d2cd1b610cdfd0a09b0d Mon Sep 17 00:00:00 2001
|
||||
From: Roberto Sassu <roberto.sassu@polito.it>
|
||||
Date: Mon, 19 Dec 2011 15:57:27 +0100
|
||||
Subject: [PATCH 040/130] ima: free duplicate measurement memory
|
||||
|
||||
commit 45fae7493970d7c45626ccd96d4a74f5f1eea5a9 upstream.
|
||||
|
||||
Info about new measurements are cached in the iint for performance. When
|
||||
the inode is flushed from cache, the associated iint is flushed as well.
|
||||
Subsequent access to the inode will cause the inode to be re-measured and
|
||||
will attempt to add a duplicate entry to the measurement list.
|
||||
|
||||
This patch frees the duplicate measurement memory, fixing a memory leak.
|
||||
|
||||
Signed-off-by: Roberto Sassu <roberto.sassu@polito.it>
|
||||
Signed-off-by: Mimi Zohar <zohar@us.ibm.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
security/integrity/ima/ima_api.c | 4 ++--
|
||||
security/integrity/ima/ima_queue.c | 1 +
|
||||
2 files changed, 3 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/security/integrity/ima/ima_api.c b/security/integrity/ima/ima_api.c
|
||||
index 0d50df0..88a2788 100644
|
||||
--- a/security/integrity/ima/ima_api.c
|
||||
+++ b/security/integrity/ima/ima_api.c
|
||||
@@ -178,8 +178,8 @@ void ima_store_measurement(struct integrity_iint_cache *iint,
|
||||
strncpy(entry->template.file_name, filename, IMA_EVENT_NAME_LEN_MAX);
|
||||
|
||||
result = ima_store_template(entry, violation, inode);
|
||||
- if (!result)
|
||||
+ if (!result || result == -EEXIST)
|
||||
iint->flags |= IMA_MEASURED;
|
||||
- else
|
||||
+ if (result < 0)
|
||||
kfree(entry);
|
||||
}
|
||||
diff --git a/security/integrity/ima/ima_queue.c b/security/integrity/ima/ima_queue.c
|
||||
index 8e28f04..e1a5062 100644
|
||||
--- a/security/integrity/ima/ima_queue.c
|
||||
+++ b/security/integrity/ima/ima_queue.c
|
||||
@@ -114,6 +114,7 @@ int ima_add_template_entry(struct ima_template_entry *entry, int violation,
|
||||
memcpy(digest, entry->digest, sizeof digest);
|
||||
if (ima_lookup_digest_entry(digest)) {
|
||||
audit_cause = "hash_exists";
|
||||
+ result = -EEXIST;
|
||||
goto out;
|
||||
}
|
||||
}
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+68
@@ -0,0 +1,68 @@
|
||||
From b5be4dc54cfe7c5bb0ce387519c2019d9915435e Mon Sep 17 00:00:00 2001
|
||||
From: Roberto Sassu <roberto.sassu@polito.it>
|
||||
Date: Mon, 19 Dec 2011 15:57:28 +0100
|
||||
Subject: [PATCH 041/130] ima: fix invalid memory reference
|
||||
|
||||
commit 7b7e5916aa2f46e57f8bd8cb89c34620ebfda5da upstream.
|
||||
|
||||
Don't free a valid measurement entry on TPM PCR extend failure.
|
||||
|
||||
Signed-off-by: Roberto Sassu <roberto.sassu@polito.it>
|
||||
Signed-off-by: Mimi Zohar <zohar@us.ibm.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
security/integrity/ima/ima_queue.c | 16 +++++++++++-----
|
||||
1 files changed, 11 insertions(+), 5 deletions(-)
|
||||
|
||||
diff --git a/security/integrity/ima/ima_queue.c b/security/integrity/ima/ima_queue.c
|
||||
index e1a5062..55a6271 100644
|
||||
--- a/security/integrity/ima/ima_queue.c
|
||||
+++ b/security/integrity/ima/ima_queue.c
|
||||
@@ -23,6 +23,8 @@
|
||||
#include <linux/slab.h>
|
||||
#include "ima.h"
|
||||
|
||||
+#define AUDIT_CAUSE_LEN_MAX 32
|
||||
+
|
||||
LIST_HEAD(ima_measurements); /* list of all measurements */
|
||||
|
||||
/* key: inode (before secure-hashing a file) */
|
||||
@@ -94,7 +96,8 @@ static int ima_pcr_extend(const u8 *hash)
|
||||
|
||||
result = tpm_pcr_extend(TPM_ANY_NUM, CONFIG_IMA_MEASURE_PCR_IDX, hash);
|
||||
if (result != 0)
|
||||
- pr_err("IMA: Error Communicating to TPM chip\n");
|
||||
+ pr_err("IMA: Error Communicating to TPM chip, result: %d\n",
|
||||
+ result);
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -106,8 +109,9 @@ int ima_add_template_entry(struct ima_template_entry *entry, int violation,
|
||||
{
|
||||
u8 digest[IMA_DIGEST_SIZE];
|
||||
const char *audit_cause = "hash_added";
|
||||
+ char tpm_audit_cause[AUDIT_CAUSE_LEN_MAX];
|
||||
int audit_info = 1;
|
||||
- int result = 0;
|
||||
+ int result = 0, tpmresult = 0;
|
||||
|
||||
mutex_lock(&ima_extend_list_mutex);
|
||||
if (!violation) {
|
||||
@@ -129,9 +133,11 @@ int ima_add_template_entry(struct ima_template_entry *entry, int violation,
|
||||
if (violation) /* invalidate pcr */
|
||||
memset(digest, 0xff, sizeof digest);
|
||||
|
||||
- result = ima_pcr_extend(digest);
|
||||
- if (result != 0) {
|
||||
- audit_cause = "TPM error";
|
||||
+ tpmresult = ima_pcr_extend(digest);
|
||||
+ if (tpmresult != 0) {
|
||||
+ snprintf(tpm_audit_cause, AUDIT_CAUSE_LEN_MAX, "TPM_error(%d)",
|
||||
+ tpmresult);
|
||||
+ audit_cause = tpm_audit_cause;
|
||||
audit_info = 0;
|
||||
}
|
||||
out:
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+47
@@ -0,0 +1,47 @@
|
||||
From c25b1c3dffca9191001f97e64c9be8e1ff861c0a Mon Sep 17 00:00:00 2001
|
||||
From: Eric Dumazet <eric.dumazet@gmail.com>
|
||||
Date: Tue, 13 Dec 2011 04:57:06 +0100
|
||||
Subject: [PATCH 042/130] slub: fix a possible memleak in __slab_alloc()
|
||||
|
||||
commit 73736e0387ba0e6d2b703407b4d26168d31516a7 upstream.
|
||||
|
||||
Zhihua Che reported a possible memleak in slub allocator on
|
||||
CONFIG_PREEMPT=y builds.
|
||||
|
||||
It is possible current thread migrates right before disabling irqs in
|
||||
__slab_alloc(). We must check again c->freelist, and perform a normal
|
||||
allocation instead of scratching c->freelist.
|
||||
|
||||
Many thanks to Zhihua Che for spotting this bug, introduced in 2.6.39
|
||||
|
||||
V2: Its also possible an IRQ freed one (or several) object(s) and
|
||||
populated c->freelist, so its not a CONFIG_PREEMPT only problem.
|
||||
|
||||
Reported-by: Zhihua Che <zhihua.che@gmail.com>
|
||||
Signed-off-by: Eric Dumazet <eric.dumazet@gmail.com>
|
||||
Acked-by: Christoph Lameter <cl@linux.com>
|
||||
Signed-off-by: Pekka Enberg <penberg@kernel.org>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
mm/slub.c | 5 +++++
|
||||
1 files changed, 5 insertions(+), 0 deletions(-)
|
||||
|
||||
diff --git a/mm/slub.c b/mm/slub.c
|
||||
index ed3334d..1a919f0 100644
|
||||
--- a/mm/slub.c
|
||||
+++ b/mm/slub.c
|
||||
@@ -2166,6 +2166,11 @@ redo:
|
||||
goto new_slab;
|
||||
}
|
||||
|
||||
+ /* must check again c->freelist in case of cpu migration or IRQ */
|
||||
+ object = c->freelist;
|
||||
+ if (object)
|
||||
+ goto load_freelist;
|
||||
+
|
||||
stat(s, ALLOC_SLOWPATH);
|
||||
|
||||
do {
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+101
@@ -0,0 +1,101 @@
|
||||
From c450bfbe6e0d5b7feb3c7570c2f22c4a8da7ca44 Mon Sep 17 00:00:00 2001
|
||||
From: Bjorn Helgaas <bhelgaas@google.com>
|
||||
Date: Thu, 5 Jan 2012 14:27:24 -0700
|
||||
Subject: [PATCH 043/130] PNP: work around Dell 1536/1546 BIOS MMCONFIG bug
|
||||
that breaks USB
|
||||
|
||||
commit eb31aae8cb5eb54e234ed2d857ddac868195d911 upstream.
|
||||
|
||||
Some Dell BIOSes have MCFG tables that don't report the entire
|
||||
MMCONFIG area claimed by the chipset. If we move PCI devices into
|
||||
that claimed-but-unreported area, they don't work.
|
||||
|
||||
This quirk reads the AMD MMCONFIG MSRs and adds PNP0C01 resources as
|
||||
needed to cover the entire area.
|
||||
|
||||
Example problem scenario:
|
||||
|
||||
BIOS-e820: 00000000cfec5400 - 00000000d4000000 (reserved)
|
||||
Fam 10h mmconf [d0000000, dfffffff]
|
||||
PCI: MMCONFIG for domain 0000 [bus 00-3f] at [mem 0xd0000000-0xd3ffffff] (base 0xd0000000)
|
||||
pnp 00:0c: [mem 0xd0000000-0xd3ffffff]
|
||||
pci 0000:00:12.0: reg 10: [mem 0xffb00000-0xffb00fff]
|
||||
pci 0000:00:12.0: no compatible bridge window for [mem 0xffb00000-0xffb00fff]
|
||||
pci 0000:00:12.0: BAR 0: assigned [mem 0xd4000000-0xd40000ff]
|
||||
|
||||
Reported-by: Lisa Salimbas <lisa.salimbas@canonical.com>
|
||||
Reported-by: <thuban@singularity.fr>
|
||||
Tested-by: dann frazier <dann.frazier@canonical.com>
|
||||
References: https://bugzilla.kernel.org/show_bug.cgi?id=31602
|
||||
References: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/647043
|
||||
References: https://bugzilla.redhat.com/show_bug.cgi?id=770308
|
||||
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
|
||||
Signed-off-by: Jesse Barnes <jbarnes@virtuousgeek.org>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/pnp/quirks.c | 42 ++++++++++++++++++++++++++++++++++++++++++
|
||||
1 files changed, 42 insertions(+), 0 deletions(-)
|
||||
|
||||
diff --git a/drivers/pnp/quirks.c b/drivers/pnp/quirks.c
|
||||
index dfbd5a6..258fef2 100644
|
||||
--- a/drivers/pnp/quirks.c
|
||||
+++ b/drivers/pnp/quirks.c
|
||||
@@ -295,6 +295,45 @@ static void quirk_system_pci_resources(struct pnp_dev *dev)
|
||||
}
|
||||
}
|
||||
|
||||
+#ifdef CONFIG_AMD_NB
|
||||
+
|
||||
+#include <asm/amd_nb.h>
|
||||
+
|
||||
+static void quirk_amd_mmconfig_area(struct pnp_dev *dev)
|
||||
+{
|
||||
+ resource_size_t start, end;
|
||||
+ struct pnp_resource *pnp_res;
|
||||
+ struct resource *res;
|
||||
+ struct resource mmconfig_res, *mmconfig;
|
||||
+
|
||||
+ mmconfig = amd_get_mmconfig_range(&mmconfig_res);
|
||||
+ if (!mmconfig)
|
||||
+ return;
|
||||
+
|
||||
+ list_for_each_entry(pnp_res, &dev->resources, list) {
|
||||
+ res = &pnp_res->res;
|
||||
+ if (res->end < mmconfig->start || res->start > mmconfig->end ||
|
||||
+ (res->start == mmconfig->start && res->end == mmconfig->end))
|
||||
+ continue;
|
||||
+
|
||||
+ dev_info(&dev->dev, FW_BUG
|
||||
+ "%pR covers only part of AMD MMCONFIG area %pR; adding more reservations\n",
|
||||
+ res, mmconfig);
|
||||
+ if (mmconfig->start < res->start) {
|
||||
+ start = mmconfig->start;
|
||||
+ end = res->start - 1;
|
||||
+ pnp_add_mem_resource(dev, start, end, 0);
|
||||
+ }
|
||||
+ if (mmconfig->end > res->end) {
|
||||
+ start = res->end + 1;
|
||||
+ end = mmconfig->end;
|
||||
+ pnp_add_mem_resource(dev, start, end, 0);
|
||||
+ }
|
||||
+ break;
|
||||
+ }
|
||||
+}
|
||||
+#endif
|
||||
+
|
||||
/*
|
||||
* PnP Quirks
|
||||
* Cards or devices that need some tweaking due to incomplete resource info
|
||||
@@ -322,6 +361,9 @@ static struct pnp_fixup pnp_fixups[] = {
|
||||
/* PnP resources that might overlap PCI BARs */
|
||||
{"PNP0c01", quirk_system_pci_resources},
|
||||
{"PNP0c02", quirk_system_pci_resources},
|
||||
+#ifdef CONFIG_AMD_NB
|
||||
+ {"PNP0c01", quirk_amd_mmconfig_area},
|
||||
+#endif
|
||||
{""}
|
||||
};
|
||||
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+45
@@ -0,0 +1,45 @@
|
||||
From 95bb58957d5f4db07339eb5c6c87345ec877a3b6 Mon Sep 17 00:00:00 2001
|
||||
From: Jussi Kivilinna <jussi.kivilinna@mbnet.fi>
|
||||
Date: Tue, 10 Jan 2012 06:40:23 +0000
|
||||
Subject: [PATCH 044/130] asix: fix setting custom MAC address on Asix 88178
|
||||
devices
|
||||
|
||||
commit 71bc5d94061516c4e70303570128797bcf768b10 upstream.
|
||||
|
||||
In kernel v3.2 initialization sequence for Asix 88178 devices was changed so
|
||||
that hardware is reseted on every time interface is brought up (ifconfig up),
|
||||
instead just at USB probe time. This causes problem with setting custom MAC
|
||||
address to device as ax88178_reset causes reload of MAC address from EEPROM.
|
||||
|
||||
This patch fixes the issue by rewriting MAC address at end of ax88178_reset.
|
||||
|
||||
Signed-off-by: Jussi Kivilinna <jussi.kivilinna@mbnet.fi>
|
||||
Acked-by: Grant Grundler <grundler@chromium.org>
|
||||
Cc: Allan Chou <allan@asix.com.tw>
|
||||
Signed-off-by: David S. Miller <davem@davemloft.net>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/net/usb/asix.c | 7 +++++++
|
||||
1 files changed, 7 insertions(+), 0 deletions(-)
|
||||
|
||||
diff --git a/drivers/net/usb/asix.c b/drivers/net/usb/asix.c
|
||||
index dd2625a..b495821 100644
|
||||
--- a/drivers/net/usb/asix.c
|
||||
+++ b/drivers/net/usb/asix.c
|
||||
@@ -1316,6 +1316,13 @@ static int ax88178_reset(struct usbnet *dev)
|
||||
if (ret < 0)
|
||||
return ret;
|
||||
|
||||
+ /* Rewrite MAC address */
|
||||
+ memcpy(data->mac_addr, dev->net->dev_addr, ETH_ALEN);
|
||||
+ ret = asix_write_cmd(dev, AX_CMD_WRITE_NODE_ID, 0, 0, ETH_ALEN,
|
||||
+ data->mac_addr);
|
||||
+ if (ret < 0)
|
||||
+ return ret;
|
||||
+
|
||||
ret = asix_write_rx_ctl(dev, AX_DEFAULT_RX_CTL);
|
||||
if (ret < 0)
|
||||
return ret;
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+53
@@ -0,0 +1,53 @@
|
||||
From 25a43c8a8f51501928b5d209ab3880ecd5b180fe Mon Sep 17 00:00:00 2001
|
||||
From: Jussi Kivilinna <jussi.kivilinna@mbnet.fi>
|
||||
Date: Tue, 10 Jan 2012 06:40:17 +0000
|
||||
Subject: [PATCH 045/130] asix: fix setting custom MAC address on Asix 88772
|
||||
devices
|
||||
|
||||
commit 8ef66bdc4bda6aac2dae73b84d79dc8c2db33637 upstream.
|
||||
|
||||
In kernel v3.2 initialization sequence for Asix 88772 devices was changed so
|
||||
that hardware is reseted on every time interface is brought up (ifconfig up),
|
||||
instead just at USB probe time. This causes problem with setting custom MAC
|
||||
address to device as ax88772_reset causes reload of MAC address from EEPROM.
|
||||
|
||||
This patch fixes the issue by rewriting MAC address at end of ax88772_reset.
|
||||
|
||||
Signed-off-by: Jussi Kivilinna <jussi.kivilinna@mbnet.fi>
|
||||
Acked-by: Grant Grundler <grundler@chromium.org>
|
||||
Cc: Allan Chou <allan@asix.com.tw>
|
||||
Signed-off-by: David S. Miller <davem@davemloft.net>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/net/usb/asix.c | 8 ++++++++
|
||||
1 files changed, 8 insertions(+), 0 deletions(-)
|
||||
|
||||
diff --git a/drivers/net/usb/asix.c b/drivers/net/usb/asix.c
|
||||
index b495821..f5e063a 100644
|
||||
--- a/drivers/net/usb/asix.c
|
||||
+++ b/drivers/net/usb/asix.c
|
||||
@@ -974,6 +974,7 @@ static int ax88772_link_reset(struct usbnet *dev)
|
||||
|
||||
static int ax88772_reset(struct usbnet *dev)
|
||||
{
|
||||
+ struct asix_data *data = (struct asix_data *)&dev->data;
|
||||
int ret, embd_phy;
|
||||
u16 rx_ctl;
|
||||
|
||||
@@ -1051,6 +1052,13 @@ static int ax88772_reset(struct usbnet *dev)
|
||||
goto out;
|
||||
}
|
||||
|
||||
+ /* Rewrite MAC address */
|
||||
+ memcpy(data->mac_addr, dev->net->dev_addr, ETH_ALEN);
|
||||
+ ret = asix_write_cmd(dev, AX_CMD_WRITE_NODE_ID, 0, 0, ETH_ALEN,
|
||||
+ data->mac_addr);
|
||||
+ if (ret < 0)
|
||||
+ goto out;
|
||||
+
|
||||
/* Set RX_CTL to default values with 2k buffer, and enable cactus */
|
||||
ret = asix_write_rx_ctl(dev, AX_DEFAULT_RX_CTL);
|
||||
if (ret < 0)
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+54
@@ -0,0 +1,54 @@
|
||||
From 56d30a3ff947d9e4be88a6083eb257bffb7d059e Mon Sep 17 00:00:00 2001
|
||||
From: Fabio Estevam <festevam@gmail.com>
|
||||
Date: Thu, 12 Jan 2012 17:20:20 -0800
|
||||
Subject: [PATCH 046/130] include/linux/crash_dump.h needs elf.h
|
||||
|
||||
commit 1f536b9e9f85456df93614b3c2f6a1a2b7d7cb9b upstream.
|
||||
|
||||
Building an ARM target we get the following warnings:
|
||||
|
||||
CC arch/arm/kernel/setup.o
|
||||
In file included from arch/arm/kernel/setup.c:39:
|
||||
arch/arm/include/asm/elf.h:102:1: warning: "vmcore_elf64_check_arch" redefined
|
||||
In file included from arch/arm/kernel/setup.c:24:
|
||||
include/linux/crash_dump.h:30:1: warning: this is the location of the previous definition
|
||||
|
||||
Quoting Russell King:
|
||||
|
||||
"linux/crash_dump.h makes no attempt to include asm/elf.h, but it depends
|
||||
on stuff in asm/elf.h to determine how stuff inside this file is defined
|
||||
at parse time.
|
||||
|
||||
So, if asm/elf.h is included after linux/crash_dump.h or not at all, you
|
||||
get a different result from the situation where asm/elf.h is included
|
||||
before."
|
||||
|
||||
So add elf.h header to crash_dump.h to avoid this problem.
|
||||
|
||||
The original discussion about this can be found at:
|
||||
http://www.spinics.net/lists/arm-kernel/msg154113.html
|
||||
|
||||
Signed-off-by: Fabio Estevam <fabio.estevam@freescale.com>
|
||||
Cc: Russell King <rmk@arm.linux.org.uk>
|
||||
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
|
||||
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
include/linux/crash_dump.h | 1 +
|
||||
1 files changed, 1 insertions(+), 0 deletions(-)
|
||||
|
||||
diff --git a/include/linux/crash_dump.h b/include/linux/crash_dump.h
|
||||
index 5c4abce..b936763 100644
|
||||
--- a/include/linux/crash_dump.h
|
||||
+++ b/include/linux/crash_dump.h
|
||||
@@ -5,6 +5,7 @@
|
||||
#include <linux/kexec.h>
|
||||
#include <linux/device.h>
|
||||
#include <linux/proc_fs.h>
|
||||
+#include <linux/elf.h>
|
||||
|
||||
#define ELFCORE_ADDR_MAX (-1ULL)
|
||||
#define ELFCORE_ADDR_ERR (-2ULL)
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+44
@@ -0,0 +1,44 @@
|
||||
From 5b48b119d0d1a2331b6368b4be7e3c1406cbda40 Mon Sep 17 00:00:00 2001
|
||||
From: Larry Finger <Larry.Finger@lwfinger.net>
|
||||
Date: Wed, 4 Jan 2012 20:50:47 -0600
|
||||
Subject: [PATCH 047/130] rtl8192se: Fix BUG caused by failure to check skb
|
||||
allocation
|
||||
|
||||
commit d90db4b12bc1b9b8a787ef28550fdb767ee25a49 upstream.
|
||||
|
||||
When downloading firmware into the device, the driver fails to check the
|
||||
return when allocating an skb. When the allocation fails, a BUG can be
|
||||
generated, as seen in https://bugzilla.redhat.com/show_bug.cgi?id=771656.
|
||||
|
||||
Signed-off-by: Larry Finger <Larry.Finger@lwfinger.net>
|
||||
Signed-off-by: John W. Linville <linville@tuxdriver.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/net/wireless/rtlwifi/rtl8192se/fw.c | 4 ++++
|
||||
1 files changed, 4 insertions(+), 0 deletions(-)
|
||||
|
||||
diff --git a/drivers/net/wireless/rtlwifi/rtl8192se/fw.c b/drivers/net/wireless/rtlwifi/rtl8192se/fw.c
|
||||
index 6f91a14..3fda6b1 100644
|
||||
--- a/drivers/net/wireless/rtlwifi/rtl8192se/fw.c
|
||||
+++ b/drivers/net/wireless/rtlwifi/rtl8192se/fw.c
|
||||
@@ -196,6 +196,8 @@ static bool _rtl92s_firmware_downloadcode(struct ieee80211_hw *hw,
|
||||
/* Allocate skb buffer to contain firmware */
|
||||
/* info and tx descriptor info. */
|
||||
skb = dev_alloc_skb(frag_length);
|
||||
+ if (!skb)
|
||||
+ return false;
|
||||
skb_reserve(skb, extra_descoffset);
|
||||
seg_ptr = (u8 *)skb_put(skb, (u32)(frag_length -
|
||||
extra_descoffset));
|
||||
@@ -573,6 +575,8 @@ static bool _rtl92s_firmware_set_h2c_cmd(struct ieee80211_hw *hw, u8 h2c_cmd,
|
||||
|
||||
len = _rtl92s_get_h2c_cmdlen(MAX_TRANSMIT_BUFFER_SIZE, 1, &cmd_len);
|
||||
skb = dev_alloc_skb(len);
|
||||
+ if (!skb)
|
||||
+ return false;
|
||||
cb_desc = (struct rtl_tcb_desc *)(skb->cb);
|
||||
cb_desc->queue_index = TXCMD_QUEUE;
|
||||
cb_desc->cmd_or_init = DESC_PACKET_TYPE_NORMAL;
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+52
@@ -0,0 +1,52 @@
|
||||
From 70f755e08b2df34528ff568bcbe2b856ddd769e1 Mon Sep 17 00:00:00 2001
|
||||
From: Stanislaw Gruszka <sgruszka@redhat.com>
|
||||
Date: Wed, 11 Jan 2012 09:26:54 +0100
|
||||
Subject: [PATCH 048/130] mac80211: fix rx->key NULL pointer dereference in
|
||||
promiscuous mode
|
||||
|
||||
commit 1140afa862842ac3e56678693050760edc4ecde9 upstream.
|
||||
|
||||
Since:
|
||||
|
||||
commit 816c04fe7ef01dd9649f5ccfe796474db8708be5
|
||||
Author: Christian Lamparter <chunkeey@googlemail.com>
|
||||
Date: Sat Apr 30 15:24:30 2011 +0200
|
||||
|
||||
mac80211: consolidate MIC failure report handling
|
||||
|
||||
is possible to that we dereference rx->key == NULL when driver set
|
||||
RX_FLAG_MMIC_STRIPPED and not RX_FLAG_IV_STRIPPED and we are in
|
||||
promiscuous mode. This happen with rt73usb and rt61pci at least.
|
||||
|
||||
Before the commit we always check rx->key against NULL, so I assume
|
||||
fix should be done in mac80211 (also mic_fail path has similar check).
|
||||
|
||||
References:
|
||||
https://bugzilla.redhat.com/show_bug.cgi?id=769766
|
||||
http://rt2x00.serialmonkey.com/pipermail/users_rt2x00.serialmonkey.com/2012-January/004395.html
|
||||
|
||||
Reported-by: Stuart D Gathman <stuart@gathman.org>
|
||||
Reported-by: Kai Wohlfahrt <kai.scorpio@gmail.com>
|
||||
Signed-off-by: Stanislaw Gruszka <sgruszka@redhat.com>
|
||||
Signed-off-by: John W. Linville <linville@tuxdriver.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
net/mac80211/wpa.c | 2 +-
|
||||
1 files changed, 1 insertions(+), 1 deletions(-)
|
||||
|
||||
diff --git a/net/mac80211/wpa.c b/net/mac80211/wpa.c
|
||||
index f614ce7..28a39bb 100644
|
||||
--- a/net/mac80211/wpa.c
|
||||
+++ b/net/mac80211/wpa.c
|
||||
@@ -106,7 +106,7 @@ ieee80211_rx_h_michael_mic_verify(struct ieee80211_rx_data *rx)
|
||||
if (status->flag & RX_FLAG_MMIC_ERROR)
|
||||
goto mic_fail;
|
||||
|
||||
- if (!(status->flag & RX_FLAG_IV_STRIPPED))
|
||||
+ if (!(status->flag & RX_FLAG_IV_STRIPPED) && rx->key)
|
||||
goto update_iv;
|
||||
|
||||
return RX_CONTINUE;
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+68
@@ -0,0 +1,68 @@
|
||||
From 11da5d38bc749c576b8def78827c2ca82d6d6bb6 Mon Sep 17 00:00:00 2001
|
||||
From: Rajkumar Manoharan <rmanohar@qca.qualcomm.com>
|
||||
Date: Mon, 9 Jan 2012 15:37:53 +0530
|
||||
Subject: [PATCH 049/130] ath9k: Fix regression in channelwidth switch at the
|
||||
same channel
|
||||
|
||||
commit 1a19f77f3642b8194ad9cf55548cc5d92e841766 upstream.
|
||||
|
||||
The commit "ath9k: Fix invalid noisefloor reading due to channel update"
|
||||
preserves the current channel noisefloor readings before updating
|
||||
channel type at the same channel index. It is also updating the curchan
|
||||
pointer. As survey updation is also referring curchan pointer to fetch
|
||||
the appropriate index, which might leads to invalid memory access. This
|
||||
patch partially reverts the change and stores the noise floor history
|
||||
buffer before updating channel type w/o updating curchan.
|
||||
|
||||
Cc: Gary Morain <gmorain@google.com>
|
||||
Cc: Paul Stewart <pstew@google.com>
|
||||
Reported-by: Mohammed Shafi Shajakhan <mohammed@qca.qualcomm.com>
|
||||
Signed-off-by: Rajkumar Manoharan <rmanohar@qca.qualcomm.com>
|
||||
Signed-off-by: John W. Linville <linville@tuxdriver.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/net/wireless/ath/ath9k/calib.c | 1 +
|
||||
drivers/net/wireless/ath/ath9k/main.c | 8 ++------
|
||||
2 files changed, 3 insertions(+), 6 deletions(-)
|
||||
|
||||
diff --git a/drivers/net/wireless/ath/ath9k/calib.c b/drivers/net/wireless/ath/ath9k/calib.c
|
||||
index 9953881..8ddef3e 100644
|
||||
--- a/drivers/net/wireless/ath/ath9k/calib.c
|
||||
+++ b/drivers/net/wireless/ath/ath9k/calib.c
|
||||
@@ -402,6 +402,7 @@ bool ath9k_hw_getnf(struct ath_hw *ah, struct ath9k_channel *chan)
|
||||
ah->noise = ath9k_hw_getchan_noise(ah, chan);
|
||||
return true;
|
||||
}
|
||||
+EXPORT_SYMBOL(ath9k_hw_getnf);
|
||||
|
||||
void ath9k_init_nfcal_hist_buffer(struct ath_hw *ah,
|
||||
struct ath9k_channel *chan)
|
||||
diff --git a/drivers/net/wireless/ath/ath9k/main.c b/drivers/net/wireless/ath/ath9k/main.c
|
||||
index a9c5ae7..f76a814 100644
|
||||
--- a/drivers/net/wireless/ath/ath9k/main.c
|
||||
+++ b/drivers/net/wireless/ath/ath9k/main.c
|
||||
@@ -1667,7 +1667,6 @@ static int ath9k_config(struct ieee80211_hw *hw, u32 changed)
|
||||
|
||||
if (changed & IEEE80211_CONF_CHANGE_CHANNEL) {
|
||||
struct ieee80211_channel *curchan = hw->conf.channel;
|
||||
- struct ath9k_channel old_chan;
|
||||
int pos = curchan->hw_value;
|
||||
int old_pos = -1;
|
||||
unsigned long flags;
|
||||
@@ -1693,11 +1692,8 @@ static int ath9k_config(struct ieee80211_hw *hw, u32 changed)
|
||||
* Preserve the current channel values, before updating
|
||||
* the same channel
|
||||
*/
|
||||
- if (old_pos == pos) {
|
||||
- memcpy(&old_chan, &sc->sc_ah->channels[pos],
|
||||
- sizeof(struct ath9k_channel));
|
||||
- ah->curchan = &old_chan;
|
||||
- }
|
||||
+ if (ah->curchan && (old_pos == pos))
|
||||
+ ath9k_hw_getnf(ah, ah->curchan);
|
||||
|
||||
ath9k_cmn_update_ichannel(&sc->sc_ah->channels[pos],
|
||||
curchan, conf->channel_type);
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+179
@@ -0,0 +1,179 @@
|
||||
From 256d142444317960a68e5c5e7a8b41a520b62bd9 Mon Sep 17 00:00:00 2001
|
||||
From: KAMEZAWA Hiroyuki <kamezawa.hiroyu@jp.fujitsu.com>
|
||||
Date: Thu, 12 Jan 2012 17:17:44 -0800
|
||||
Subject: [PATCH 050/130] memcg: add mem_cgroup_replace_page_cache() to fix
|
||||
LRU issue
|
||||
|
||||
commit ab936cbcd02072a34b60d268f94440fd5cf1970b upstream.
|
||||
|
||||
Commit ef6a3c6311 ("mm: add replace_page_cache_page() function") added a
|
||||
function replace_page_cache_page(). This function replaces a page in the
|
||||
radix-tree with a new page. WHen doing this, memory cgroup needs to fix
|
||||
up the accounting information. memcg need to check PCG_USED bit etc.
|
||||
|
||||
In some(many?) cases, 'newpage' is on LRU before calling
|
||||
replace_page_cache(). So, memcg's LRU accounting information should be
|
||||
fixed, too.
|
||||
|
||||
This patch adds mem_cgroup_replace_page_cache() and removes the old hooks.
|
||||
In that function, old pages will be unaccounted without touching
|
||||
res_counter and new page will be accounted to the memcg (of old page).
|
||||
WHen overwriting pc->mem_cgroup of newpage, take zone->lru_lock and avoid
|
||||
races with LRU handling.
|
||||
|
||||
Background:
|
||||
replace_page_cache_page() is called by FUSE code in its splice() handling.
|
||||
Here, 'newpage' is replacing oldpage but this newpage is not a newly allocated
|
||||
page and may be on LRU. LRU mis-accounting will be critical for memory cgroup
|
||||
because rmdir() checks the whole LRU is empty and there is no account leak.
|
||||
If a page is on the other LRU than it should be, rmdir() will fail.
|
||||
|
||||
This bug was added in March 2011, but no bug report yet. I guess there
|
||||
are not many people who use memcg and FUSE at the same time with upstream
|
||||
kernels.
|
||||
|
||||
The result of this bug is that admin cannot destroy a memcg because of
|
||||
account leak. So, no panic, no deadlock. And, even if an active cgroup
|
||||
exist, umount can succseed. So no problem at shutdown.
|
||||
|
||||
Signed-off-by: KAMEZAWA Hiroyuki <kamezawa.hiroyu@jp.fujitsu.com>
|
||||
Acked-by: Johannes Weiner <hannes@cmpxchg.org>
|
||||
Acked-by: Michal Hocko <mhocko@suse.cz>
|
||||
Cc: Miklos Szeredi <mszeredi@suse.cz>
|
||||
Cc: Hugh Dickins <hughd@google.com>
|
||||
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
|
||||
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
include/linux/memcontrol.h | 6 ++++++
|
||||
mm/filemap.c | 18 ++----------------
|
||||
mm/memcontrol.c | 44 ++++++++++++++++++++++++++++++++++++++++++++
|
||||
3 files changed, 52 insertions(+), 16 deletions(-)
|
||||
|
||||
diff --git a/include/linux/memcontrol.h b/include/linux/memcontrol.h
|
||||
index b87068a..81572af 100644
|
||||
--- a/include/linux/memcontrol.h
|
||||
+++ b/include/linux/memcontrol.h
|
||||
@@ -119,6 +119,8 @@ struct zone_reclaim_stat*
|
||||
mem_cgroup_get_reclaim_stat_from_page(struct page *page);
|
||||
extern void mem_cgroup_print_oom_info(struct mem_cgroup *memcg,
|
||||
struct task_struct *p);
|
||||
+extern void mem_cgroup_replace_page_cache(struct page *oldpage,
|
||||
+ struct page *newpage);
|
||||
|
||||
#ifdef CONFIG_CGROUP_MEM_RES_CTLR_SWAP
|
||||
extern int do_swap_account;
|
||||
@@ -366,6 +368,10 @@ static inline
|
||||
void mem_cgroup_count_vm_event(struct mm_struct *mm, enum vm_event_item idx)
|
||||
{
|
||||
}
|
||||
+static inline void mem_cgroup_replace_page_cache(struct page *oldpage,
|
||||
+ struct page *newpage)
|
||||
+{
|
||||
+}
|
||||
#endif /* CONFIG_CGROUP_MEM_CONT */
|
||||
|
||||
#if !defined(CONFIG_CGROUP_MEM_RES_CTLR) || !defined(CONFIG_DEBUG_VM)
|
||||
diff --git a/mm/filemap.c b/mm/filemap.c
|
||||
index 5f0a3c9..90286a4 100644
|
||||
--- a/mm/filemap.c
|
||||
+++ b/mm/filemap.c
|
||||
@@ -393,24 +393,11 @@ EXPORT_SYMBOL(filemap_write_and_wait_range);
|
||||
int replace_page_cache_page(struct page *old, struct page *new, gfp_t gfp_mask)
|
||||
{
|
||||
int error;
|
||||
- struct mem_cgroup *memcg = NULL;
|
||||
|
||||
VM_BUG_ON(!PageLocked(old));
|
||||
VM_BUG_ON(!PageLocked(new));
|
||||
VM_BUG_ON(new->mapping);
|
||||
|
||||
- /*
|
||||
- * This is not page migration, but prepare_migration and
|
||||
- * end_migration does enough work for charge replacement.
|
||||
- *
|
||||
- * In the longer term we probably want a specialized function
|
||||
- * for moving the charge from old to new in a more efficient
|
||||
- * manner.
|
||||
- */
|
||||
- error = mem_cgroup_prepare_migration(old, new, &memcg, gfp_mask);
|
||||
- if (error)
|
||||
- return error;
|
||||
-
|
||||
error = radix_tree_preload(gfp_mask & ~__GFP_HIGHMEM);
|
||||
if (!error) {
|
||||
struct address_space *mapping = old->mapping;
|
||||
@@ -432,13 +419,12 @@ int replace_page_cache_page(struct page *old, struct page *new, gfp_t gfp_mask)
|
||||
if (PageSwapBacked(new))
|
||||
__inc_zone_page_state(new, NR_SHMEM);
|
||||
spin_unlock_irq(&mapping->tree_lock);
|
||||
+ /* mem_cgroup codes must not be called under tree_lock */
|
||||
+ mem_cgroup_replace_page_cache(old, new);
|
||||
radix_tree_preload_end();
|
||||
if (freepage)
|
||||
freepage(old);
|
||||
page_cache_release(old);
|
||||
- mem_cgroup_end_migration(memcg, old, new, true);
|
||||
- } else {
|
||||
- mem_cgroup_end_migration(memcg, old, new, false);
|
||||
}
|
||||
|
||||
return error;
|
||||
diff --git a/mm/memcontrol.c b/mm/memcontrol.c
|
||||
index b63f5f7..f538e9b 100644
|
||||
--- a/mm/memcontrol.c
|
||||
+++ b/mm/memcontrol.c
|
||||
@@ -3366,6 +3366,50 @@ void mem_cgroup_end_migration(struct mem_cgroup *memcg,
|
||||
cgroup_release_and_wakeup_rmdir(&memcg->css);
|
||||
}
|
||||
|
||||
+/*
|
||||
+ * At replace page cache, newpage is not under any memcg but it's on
|
||||
+ * LRU. So, this function doesn't touch res_counter but handles LRU
|
||||
+ * in correct way. Both pages are locked so we cannot race with uncharge.
|
||||
+ */
|
||||
+void mem_cgroup_replace_page_cache(struct page *oldpage,
|
||||
+ struct page *newpage)
|
||||
+{
|
||||
+ struct mem_cgroup *memcg;
|
||||
+ struct page_cgroup *pc;
|
||||
+ struct zone *zone;
|
||||
+ enum charge_type type = MEM_CGROUP_CHARGE_TYPE_CACHE;
|
||||
+ unsigned long flags;
|
||||
+
|
||||
+ if (mem_cgroup_disabled())
|
||||
+ return;
|
||||
+
|
||||
+ pc = lookup_page_cgroup(oldpage);
|
||||
+ /* fix accounting on old pages */
|
||||
+ lock_page_cgroup(pc);
|
||||
+ memcg = pc->mem_cgroup;
|
||||
+ mem_cgroup_charge_statistics(memcg, PageCgroupCache(pc), -1);
|
||||
+ ClearPageCgroupUsed(pc);
|
||||
+ unlock_page_cgroup(pc);
|
||||
+
|
||||
+ if (PageSwapBacked(oldpage))
|
||||
+ type = MEM_CGROUP_CHARGE_TYPE_SHMEM;
|
||||
+
|
||||
+ zone = page_zone(newpage);
|
||||
+ pc = lookup_page_cgroup(newpage);
|
||||
+ /*
|
||||
+ * Even if newpage->mapping was NULL before starting replacement,
|
||||
+ * the newpage may be on LRU(or pagevec for LRU) already. We lock
|
||||
+ * LRU while we overwrite pc->mem_cgroup.
|
||||
+ */
|
||||
+ spin_lock_irqsave(&zone->lru_lock, flags);
|
||||
+ if (PageLRU(newpage))
|
||||
+ del_page_from_lru_list(zone, newpage, page_lru(newpage));
|
||||
+ __mem_cgroup_commit_charge(memcg, newpage, 1, pc, type);
|
||||
+ if (PageLRU(newpage))
|
||||
+ add_page_to_lru_list(zone, newpage, page_lru(newpage));
|
||||
+ spin_unlock_irqrestore(&zone->lru_lock, flags);
|
||||
+}
|
||||
+
|
||||
#ifdef CONFIG_DEBUG_VM
|
||||
static struct page_cgroup *lookup_page_cgroup_used(struct page *page)
|
||||
{
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+47
@@ -0,0 +1,47 @@
|
||||
From 706ade85b9f24b43d5e2b456b2eaf5acf4708fa7 Mon Sep 17 00:00:00 2001
|
||||
From: Ludwig Nussel <ludwig.nussel@suse.de>
|
||||
Date: Tue, 15 Nov 2011 14:46:46 -0800
|
||||
Subject: [PATCH 051/130] x86: Fix mmap random address range
|
||||
|
||||
commit 9af0c7a6fa860698d080481f24a342ba74b68982 upstream.
|
||||
|
||||
On x86_32 casting the unsigned int result of get_random_int() to
|
||||
long may result in a negative value. On x86_32 the range of
|
||||
mmap_rnd() therefore was -255 to 255. The 32bit mode on x86_64
|
||||
used 0 to 255 as intended.
|
||||
|
||||
The bug was introduced by 675a081 ("x86: unify mmap_{32|64}.c")
|
||||
in January 2008.
|
||||
|
||||
Signed-off-by: Ludwig Nussel <ludwig.nussel@suse.de>
|
||||
Cc: Linus Torvalds <torvalds@linux-foundation.org>
|
||||
Cc: harvey.harrison@gmail.com
|
||||
Cc: "H. Peter Anvin" <hpa@zytor.com>
|
||||
Cc: Harvey Harrison <harvey.harrison@gmail.com>
|
||||
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
|
||||
Link: http://lkml.kernel.org/r/201111152246.pAFMklOB028527@wpaz5.hot.corp.google.com
|
||||
Signed-off-by: Ingo Molnar <mingo@elte.hu>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
arch/x86/mm/mmap.c | 4 ++--
|
||||
1 files changed, 2 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/arch/x86/mm/mmap.c b/arch/x86/mm/mmap.c
|
||||
index 4b5ba85..845df68 100644
|
||||
--- a/arch/x86/mm/mmap.c
|
||||
+++ b/arch/x86/mm/mmap.c
|
||||
@@ -75,9 +75,9 @@ static unsigned long mmap_rnd(void)
|
||||
*/
|
||||
if (current->flags & PF_RANDOMIZE) {
|
||||
if (mmap_is_ia32())
|
||||
- rnd = (long)get_random_int() % (1<<8);
|
||||
+ rnd = get_random_int() % (1<<8);
|
||||
else
|
||||
- rnd = (long)(get_random_int() % (1<<28));
|
||||
+ rnd = get_random_int() % (1<<28);
|
||||
}
|
||||
return rnd << PAGE_SHIFT;
|
||||
}
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+37
@@ -0,0 +1,37 @@
|
||||
From fb25b1761ccc5ff102d6d4a8b2997437a9f1f999 Mon Sep 17 00:00:00 2001
|
||||
From: Richard Weinberger <richard@nod.at>
|
||||
Date: Fri, 13 Jan 2012 15:07:40 +0100
|
||||
Subject: [PATCH 052/130] UBI: fix nameless volumes handling
|
||||
|
||||
commit 4a59c797a18917a5cf3ff7ade296b46134d91e6a upstream.
|
||||
|
||||
Currently it's possible to create a volume without a name. E.g:
|
||||
ubimkvol -n 32 -s 2MiB -t static /dev/ubi0 -N ""
|
||||
|
||||
After that vtbl_check() will always fail because it does not permit
|
||||
empty strings.
|
||||
|
||||
Signed-off-by: Richard Weinberger <richard@nod.at>
|
||||
Signed-off-by: Artem Bityutskiy <Artem.Bityutskiy@linux.intel.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/mtd/ubi/cdev.c | 3 +++
|
||||
1 files changed, 3 insertions(+), 0 deletions(-)
|
||||
|
||||
diff --git a/drivers/mtd/ubi/cdev.c b/drivers/mtd/ubi/cdev.c
|
||||
index 3320a50..ad76592 100644
|
||||
--- a/drivers/mtd/ubi/cdev.c
|
||||
+++ b/drivers/mtd/ubi/cdev.c
|
||||
@@ -632,6 +632,9 @@ static int verify_mkvol_req(const struct ubi_device *ubi,
|
||||
if (req->alignment != 1 && n)
|
||||
goto bad;
|
||||
|
||||
+ if (!req->name[0] || !req->name_len)
|
||||
+ goto bad;
|
||||
+
|
||||
if (req->name_len > UBI_VOL_NAME_MAX) {
|
||||
err = -ENAMETOOLONG;
|
||||
goto bad;
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
@@ -0,0 +1,42 @@
|
||||
From 5aefc74158a4193f8e1f0ee3b9af21fd76ace6ca Mon Sep 17 00:00:00 2001
|
||||
From: Artem Bityutskiy <artem.bityutskiy@linux.intel.com>
|
||||
Date: Tue, 10 Jan 2012 19:32:30 +0200
|
||||
Subject: [PATCH 053/130] UBI: fix debugging messages
|
||||
|
||||
commit 72f0d453d81d35087b1d3ad7c8285628c2be6e1d upstream.
|
||||
|
||||
Patch ab50ff684707031ed4bad2fdd313208ae392e5bb broke UBI debugging messages:
|
||||
before that commit when UBI debugging was enabled, users saw few useful
|
||||
debugging messages after attaching an MTD device. However, that patch turned
|
||||
'dbg_msg()' into 'pr_debug()', so to enable the debugging messages users have
|
||||
to enable them first via /sys/kernel/debug/dynamic_debug/control, which is
|
||||
very impractical.
|
||||
|
||||
This commit makes 'dbg_msg()' to use 'printk()' instead of 'pr_debug()', just
|
||||
as it was before the breakage.
|
||||
|
||||
Signed-off-by: Artem Bityutskiy <artem.bityutskiy@linux.intel.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/mtd/ubi/debug.h | 5 ++++-
|
||||
1 files changed, 4 insertions(+), 1 deletions(-)
|
||||
|
||||
diff --git a/drivers/mtd/ubi/debug.h b/drivers/mtd/ubi/debug.h
|
||||
index 64fbb00..ead2cd1 100644
|
||||
--- a/drivers/mtd/ubi/debug.h
|
||||
+++ b/drivers/mtd/ubi/debug.h
|
||||
@@ -43,7 +43,10 @@
|
||||
pr_debug("UBI DBG " type ": " fmt "\n", ##__VA_ARGS__)
|
||||
|
||||
/* Just a debugging messages not related to any specific UBI subsystem */
|
||||
-#define dbg_msg(fmt, ...) ubi_dbg_msg("msg", fmt, ##__VA_ARGS__)
|
||||
+#define dbg_msg(fmt, ...) \
|
||||
+ printk(KERN_DEBUG "UBI DBG (pid %d): %s: " fmt "\n", \
|
||||
+ current->pid, __func__, ##__VA_ARGS__)
|
||||
+
|
||||
/* General debugging messages */
|
||||
#define dbg_gen(fmt, ...) ubi_dbg_msg("gen", fmt, ##__VA_ARGS__)
|
||||
/* Messages from the eraseblock association sub-system */
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
@@ -0,0 +1,36 @@
|
||||
From 7435d88f019f5550cf2d481b582e17ad65b061c0 Mon Sep 17 00:00:00 2001
|
||||
From: Richard Weinberger <rw@linutronix.de>
|
||||
Date: Thu, 22 Dec 2011 16:12:57 +0100
|
||||
Subject: [PATCH 054/130] UBI: make vid_hdr non-static
|
||||
|
||||
commit 6bdccffe8c4268d02f71873102131fb6ed37ed9a upstream.
|
||||
|
||||
Remove 'static' modifier from the 'vid_hdr' local variable. I do not know
|
||||
how it slipped in, but this is a bug and will break UBI if someone attaches
|
||||
2 UBI volumes at the same time.
|
||||
|
||||
Artem: amended teh commit message, added -stable.
|
||||
|
||||
Signed-off-by: Richard Weinberger <rw@linutronix.de>
|
||||
Signed-off-by: Artem Bityutskiy <artem.bityutskiy@linux.intel.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/mtd/ubi/vtbl.c | 2 +-
|
||||
1 files changed, 1 insertions(+), 1 deletions(-)
|
||||
|
||||
diff --git a/drivers/mtd/ubi/vtbl.c b/drivers/mtd/ubi/vtbl.c
|
||||
index 9ad18da..890754c 100644
|
||||
--- a/drivers/mtd/ubi/vtbl.c
|
||||
+++ b/drivers/mtd/ubi/vtbl.c
|
||||
@@ -306,7 +306,7 @@ static int create_vtbl(struct ubi_device *ubi, struct ubi_scan_info *si,
|
||||
int copy, void *vtbl)
|
||||
{
|
||||
int err, tries = 0;
|
||||
- static struct ubi_vid_hdr *vid_hdr;
|
||||
+ struct ubi_vid_hdr *vid_hdr;
|
||||
struct ubi_scan_leb *new_seb;
|
||||
|
||||
ubi_msg("create volume table (copy #%d)", copy + 1);
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+41
@@ -0,0 +1,41 @@
|
||||
From 1b3cf92e4f993769ceaf78263ccebc8eaf67a804 Mon Sep 17 00:00:00 2001
|
||||
From: Artem Bityutskiy <artem.bityutskiy@linux.intel.com>
|
||||
Date: Tue, 10 Jan 2012 19:32:30 +0200
|
||||
Subject: [PATCH 055/130] UBIFS: fix debugging messages
|
||||
|
||||
commit d34315da9146253351146140ea4b277193ee5e5f upstream.
|
||||
|
||||
Patch 56e46742e846e4de167dde0e1e1071ace1c882a5 broke UBIFS debugging messages:
|
||||
before that commit when UBIFS debugging was enabled, users saw few useful
|
||||
debugging messages after mount. However, that patch turned 'dbg_msg()' into
|
||||
'pr_debug()', so to enable the debugging messages users have to enable them
|
||||
first via /sys/kernel/debug/dynamic_debug/control, which is very impractical.
|
||||
|
||||
This commit makes 'dbg_msg()' to use 'printk()' instead of 'pr_debug()', just
|
||||
as it was before the breakage.
|
||||
|
||||
Signed-off-by: Artem Bityutskiy <artem.bityutskiy@linux.intel.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
fs/ubifs/debug.h | 5 ++++-
|
||||
1 files changed, 4 insertions(+), 1 deletions(-)
|
||||
|
||||
diff --git a/fs/ubifs/debug.h b/fs/ubifs/debug.h
|
||||
index 8d9c468..3f65829 100644
|
||||
--- a/fs/ubifs/debug.h
|
||||
+++ b/fs/ubifs/debug.h
|
||||
@@ -190,7 +190,10 @@ extern spinlock_t dbg_lock;
|
||||
} while (0)
|
||||
|
||||
/* Just a debugging messages not related to any specific UBIFS subsystem */
|
||||
-#define dbg_msg(fmt, ...) ubifs_dbg_msg("msg", fmt, ##__VA_ARGS__)
|
||||
+#define dbg_msg(fmt, ...) \
|
||||
+ printk(KERN_DEBUG "UBIFS DBG (pid %d): %s: " fmt "\n", current->pid, \
|
||||
+ __func__, ##__VA_ARGS__)
|
||||
+
|
||||
/* General messages */
|
||||
#define dbg_gen(fmt, ...) ubifs_dbg_msg("gen", fmt, ##__VA_ARGS__)
|
||||
/* Additional journal messages */
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+57
@@ -0,0 +1,57 @@
|
||||
From fd7fabbc63907ebe083460603caa1ba54bef0e80 Mon Sep 17 00:00:00 2001
|
||||
From: Artem Bityutskiy <artem.bityutskiy@linux.intel.com>
|
||||
Date: Wed, 11 Jan 2012 15:13:27 +0200
|
||||
Subject: [PATCH 056/130] UBIFS: make debugging messages light again
|
||||
|
||||
commit 1f5d78dc4823a85f112aaa2d0f17624f8c2a6c52 upstream.
|
||||
|
||||
We switch to dynamic debugging in commit
|
||||
56e46742e846e4de167dde0e1e1071ace1c882a5 but did not take into account that
|
||||
now we do not control anymore whether a specific message is enabled or not.
|
||||
So now we lock the "dbg_lock" and release it in every debugging macro, which
|
||||
make them not so light-weight.
|
||||
|
||||
This commit removes the "dbg_lock" protection from the debugging macros to
|
||||
fix the issue.
|
||||
|
||||
The downside is that now our DBGKEY() stuff is broken, but this is not
|
||||
critical at all and will be fixed later.
|
||||
|
||||
Signed-off-by: Artem Bityutskiy <artem.bityutskiy@linux.intel.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
fs/ubifs/debug.h | 12 +++++-------
|
||||
1 files changed, 5 insertions(+), 7 deletions(-)
|
||||
|
||||
diff --git a/fs/ubifs/debug.h b/fs/ubifs/debug.h
|
||||
index 3f65829..c9d2941 100644
|
||||
--- a/fs/ubifs/debug.h
|
||||
+++ b/fs/ubifs/debug.h
|
||||
@@ -175,19 +175,17 @@ const char *dbg_key_str1(const struct ubifs_info *c,
|
||||
const union ubifs_key *key);
|
||||
|
||||
/*
|
||||
- * DBGKEY macros require @dbg_lock to be held, which it is in the dbg message
|
||||
- * macros.
|
||||
+ * TODO: these macros are now broken because there is no locking around them
|
||||
+ * and we use a global buffer for the key string. This means that in case of
|
||||
+ * concurrent execution we will end up with incorrect and messy key strings.
|
||||
*/
|
||||
#define DBGKEY(key) dbg_key_str0(c, (key))
|
||||
#define DBGKEY1(key) dbg_key_str1(c, (key))
|
||||
|
||||
extern spinlock_t dbg_lock;
|
||||
|
||||
-#define ubifs_dbg_msg(type, fmt, ...) do { \
|
||||
- spin_lock(&dbg_lock); \
|
||||
- pr_debug("UBIFS DBG " type ": " fmt "\n", ##__VA_ARGS__); \
|
||||
- spin_unlock(&dbg_lock); \
|
||||
-} while (0)
|
||||
+#define ubifs_dbg_msg(type, fmt, ...) \
|
||||
+ pr_debug("UBIFS DBG " type ": " fmt "\n", ##__VA_ARGS__)
|
||||
|
||||
/* Just a debugging messages not related to any specific UBIFS subsystem */
|
||||
#define dbg_msg(fmt, ...) \
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+197
@@ -0,0 +1,197 @@
|
||||
From 2c28d6c10fef2ab34270bd90ce2b75207cb951ee Mon Sep 17 00:00:00 2001
|
||||
From: Jean Delvare <khali@linux-fr.org>
|
||||
Date: Thu, 12 Jan 2012 20:32:03 +0100
|
||||
Subject: [PATCH 057/130] i2c: Fix error value returned by several bus drivers
|
||||
|
||||
commit 7c1f59c9d5caf3a84f35549b5d58f3c055a68da5 upstream.
|
||||
|
||||
When adding checks for ACPI resource conflicts to many bus drivers,
|
||||
not enough attention was paid to the error paths, and for several
|
||||
drivers this causes 0 to be returned on error in some cases. Fix this
|
||||
by properly returning a non-zero value on every error.
|
||||
|
||||
Signed-off-by: Jean Delvare <khali@linux-fr.org>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/i2c/busses/i2c-ali1535.c | 11 +++++++----
|
||||
drivers/i2c/busses/i2c-nforce2.c | 2 +-
|
||||
drivers/i2c/busses/i2c-sis5595.c | 4 ++--
|
||||
drivers/i2c/busses/i2c-sis630.c | 6 +++++-
|
||||
drivers/i2c/busses/i2c-viapro.c | 7 +++++--
|
||||
5 files changed, 20 insertions(+), 10 deletions(-)
|
||||
|
||||
diff --git a/drivers/i2c/busses/i2c-ali1535.c b/drivers/i2c/busses/i2c-ali1535.c
|
||||
index b6807db..5b667e5 100644
|
||||
--- a/drivers/i2c/busses/i2c-ali1535.c
|
||||
+++ b/drivers/i2c/busses/i2c-ali1535.c
|
||||
@@ -140,7 +140,7 @@ static unsigned short ali1535_smba;
|
||||
defined to make the transition easier. */
|
||||
static int __devinit ali1535_setup(struct pci_dev *dev)
|
||||
{
|
||||
- int retval = -ENODEV;
|
||||
+ int retval;
|
||||
unsigned char temp;
|
||||
|
||||
/* Check the following things:
|
||||
@@ -155,6 +155,7 @@ static int __devinit ali1535_setup(struct pci_dev *dev)
|
||||
if (ali1535_smba == 0) {
|
||||
dev_warn(&dev->dev,
|
||||
"ALI1535_smb region uninitialized - upgrade BIOS?\n");
|
||||
+ retval = -ENODEV;
|
||||
goto exit;
|
||||
}
|
||||
|
||||
@@ -167,6 +168,7 @@ static int __devinit ali1535_setup(struct pci_dev *dev)
|
||||
ali1535_driver.name)) {
|
||||
dev_err(&dev->dev, "ALI1535_smb region 0x%x already in use!\n",
|
||||
ali1535_smba);
|
||||
+ retval = -EBUSY;
|
||||
goto exit;
|
||||
}
|
||||
|
||||
@@ -174,6 +176,7 @@ static int __devinit ali1535_setup(struct pci_dev *dev)
|
||||
pci_read_config_byte(dev, SMBCFG, &temp);
|
||||
if ((temp & ALI1535_SMBIO_EN) == 0) {
|
||||
dev_err(&dev->dev, "SMB device not enabled - upgrade BIOS?\n");
|
||||
+ retval = -ENODEV;
|
||||
goto exit_free;
|
||||
}
|
||||
|
||||
@@ -181,6 +184,7 @@ static int __devinit ali1535_setup(struct pci_dev *dev)
|
||||
pci_read_config_byte(dev, SMBHSTCFG, &temp);
|
||||
if ((temp & 1) == 0) {
|
||||
dev_err(&dev->dev, "SMBus controller not enabled - upgrade BIOS?\n");
|
||||
+ retval = -ENODEV;
|
||||
goto exit_free;
|
||||
}
|
||||
|
||||
@@ -198,12 +202,11 @@ static int __devinit ali1535_setup(struct pci_dev *dev)
|
||||
dev_dbg(&dev->dev, "SMBREV = 0x%X\n", temp);
|
||||
dev_dbg(&dev->dev, "ALI1535_smba = 0x%X\n", ali1535_smba);
|
||||
|
||||
- retval = 0;
|
||||
-exit:
|
||||
- return retval;
|
||||
+ return 0;
|
||||
|
||||
exit_free:
|
||||
release_region(ali1535_smba, ALI1535_SMB_IOSIZE);
|
||||
+exit:
|
||||
return retval;
|
||||
}
|
||||
|
||||
diff --git a/drivers/i2c/busses/i2c-nforce2.c b/drivers/i2c/busses/i2c-nforce2.c
|
||||
index ff1e127..4853b52 100644
|
||||
--- a/drivers/i2c/busses/i2c-nforce2.c
|
||||
+++ b/drivers/i2c/busses/i2c-nforce2.c
|
||||
@@ -356,7 +356,7 @@ static int __devinit nforce2_probe_smb (struct pci_dev *dev, int bar,
|
||||
error = acpi_check_region(smbus->base, smbus->size,
|
||||
nforce2_driver.name);
|
||||
if (error)
|
||||
- return -1;
|
||||
+ return error;
|
||||
|
||||
if (!request_region(smbus->base, smbus->size, nforce2_driver.name)) {
|
||||
dev_err(&smbus->adapter.dev, "Error requesting region %02x .. %02X for %s\n",
|
||||
diff --git a/drivers/i2c/busses/i2c-sis5595.c b/drivers/i2c/busses/i2c-sis5595.c
|
||||
index 4375866..6d60284 100644
|
||||
--- a/drivers/i2c/busses/i2c-sis5595.c
|
||||
+++ b/drivers/i2c/busses/i2c-sis5595.c
|
||||
@@ -147,7 +147,7 @@ static int __devinit sis5595_setup(struct pci_dev *SIS5595_dev)
|
||||
u16 a;
|
||||
u8 val;
|
||||
int *i;
|
||||
- int retval = -ENODEV;
|
||||
+ int retval;
|
||||
|
||||
/* Look for imposters */
|
||||
for (i = blacklist; *i != 0; i++) {
|
||||
@@ -223,7 +223,7 @@ static int __devinit sis5595_setup(struct pci_dev *SIS5595_dev)
|
||||
|
||||
error:
|
||||
release_region(sis5595_base + SMB_INDEX, 2);
|
||||
- return retval;
|
||||
+ return -ENODEV;
|
||||
}
|
||||
|
||||
static int sis5595_transaction(struct i2c_adapter *adap)
|
||||
diff --git a/drivers/i2c/busses/i2c-sis630.c b/drivers/i2c/busses/i2c-sis630.c
|
||||
index e6f539e..b617fd0 100644
|
||||
--- a/drivers/i2c/busses/i2c-sis630.c
|
||||
+++ b/drivers/i2c/busses/i2c-sis630.c
|
||||
@@ -393,7 +393,7 @@ static int __devinit sis630_setup(struct pci_dev *sis630_dev)
|
||||
{
|
||||
unsigned char b;
|
||||
struct pci_dev *dummy = NULL;
|
||||
- int retval = -ENODEV, i;
|
||||
+ int retval, i;
|
||||
|
||||
/* check for supported SiS devices */
|
||||
for (i=0; supported[i] > 0 ; i++) {
|
||||
@@ -418,18 +418,21 @@ static int __devinit sis630_setup(struct pci_dev *sis630_dev)
|
||||
*/
|
||||
if (pci_read_config_byte(sis630_dev, SIS630_BIOS_CTL_REG,&b)) {
|
||||
dev_err(&sis630_dev->dev, "Error: Can't read bios ctl reg\n");
|
||||
+ retval = -ENODEV;
|
||||
goto exit;
|
||||
}
|
||||
/* if ACPI already enabled , do nothing */
|
||||
if (!(b & 0x80) &&
|
||||
pci_write_config_byte(sis630_dev, SIS630_BIOS_CTL_REG, b | 0x80)) {
|
||||
dev_err(&sis630_dev->dev, "Error: Can't enable ACPI\n");
|
||||
+ retval = -ENODEV;
|
||||
goto exit;
|
||||
}
|
||||
|
||||
/* Determine the ACPI base address */
|
||||
if (pci_read_config_word(sis630_dev,SIS630_ACPI_BASE_REG,&acpi_base)) {
|
||||
dev_err(&sis630_dev->dev, "Error: Can't determine ACPI base address\n");
|
||||
+ retval = -ENODEV;
|
||||
goto exit;
|
||||
}
|
||||
|
||||
@@ -445,6 +448,7 @@ static int __devinit sis630_setup(struct pci_dev *sis630_dev)
|
||||
sis630_driver.name)) {
|
||||
dev_err(&sis630_dev->dev, "SMBus registers 0x%04x-0x%04x already "
|
||||
"in use!\n", acpi_base + SMB_STS, acpi_base + SMB_SAA);
|
||||
+ retval = -EBUSY;
|
||||
goto exit;
|
||||
}
|
||||
|
||||
diff --git a/drivers/i2c/busses/i2c-viapro.c b/drivers/i2c/busses/i2c-viapro.c
|
||||
index 0b012f1..58261d4 100644
|
||||
--- a/drivers/i2c/busses/i2c-viapro.c
|
||||
+++ b/drivers/i2c/busses/i2c-viapro.c
|
||||
@@ -324,7 +324,7 @@ static int __devinit vt596_probe(struct pci_dev *pdev,
|
||||
const struct pci_device_id *id)
|
||||
{
|
||||
unsigned char temp;
|
||||
- int error = -ENODEV;
|
||||
+ int error;
|
||||
|
||||
/* Determine the address of the SMBus areas */
|
||||
if (force_addr) {
|
||||
@@ -390,6 +390,7 @@ found:
|
||||
dev_err(&pdev->dev, "SMBUS: Error: Host SMBus "
|
||||
"controller not enabled! - upgrade BIOS or "
|
||||
"use force=1\n");
|
||||
+ error = -ENODEV;
|
||||
goto release_region;
|
||||
}
|
||||
}
|
||||
@@ -422,9 +423,11 @@ found:
|
||||
"SMBus Via Pro adapter at %04x", vt596_smba);
|
||||
|
||||
vt596_pdev = pci_dev_get(pdev);
|
||||
- if (i2c_add_adapter(&vt596_adapter)) {
|
||||
+ error = i2c_add_adapter(&vt596_adapter);
|
||||
+ if (error) {
|
||||
pci_dev_put(vt596_pdev);
|
||||
vt596_pdev = NULL;
|
||||
+ goto release_region;
|
||||
}
|
||||
|
||||
/* Always return failure here. This is to allow other drivers to bind
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+39
@@ -0,0 +1,39 @@
|
||||
From ac64016ec74f6fbe586ba55f75a87e6459ba0760 Mon Sep 17 00:00:00 2001
|
||||
From: Girish K S <girish.shivananjappa@linaro.org>
|
||||
Date: Thu, 15 Dec 2011 17:27:42 +0530
|
||||
Subject: [PATCH 058/130] mmc: core: Fix voltage select in DDR mode
|
||||
|
||||
commit 913047e9e5787a90696533a9f109552b7694ecc9 upstream.
|
||||
|
||||
This patch fixes the wrong comparison before setting the interface
|
||||
voltage in DDR mode.
|
||||
|
||||
The assignment to the variable ddr before comaprison is either
|
||||
ddr = MMC_1_2V_DDR_MODE; or ddr == MMC_1_8V_DDR_MODE. But the comparison
|
||||
is done with the extended csd value if ddr == EXT_CSD_CARD_TYPE_DDR_1_2V.
|
||||
|
||||
Signed-off-by: Girish K S <girish.shivananjappa@linaro.org>
|
||||
Acked-by: Subhash Jadavani <subhashj@codeaurora.org>
|
||||
Acked-by: Philip Rakity <prakity@marvell.com>
|
||||
Signed-off-by: Chris Ball <cjb@laptop.org>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/mmc/core/mmc.c | 2 +-
|
||||
1 files changed, 1 insertions(+), 1 deletions(-)
|
||||
|
||||
diff --git a/drivers/mmc/core/mmc.c b/drivers/mmc/core/mmc.c
|
||||
index d240427..fb7c27f 100644
|
||||
--- a/drivers/mmc/core/mmc.c
|
||||
+++ b/drivers/mmc/core/mmc.c
|
||||
@@ -1048,7 +1048,7 @@ static int mmc_init_card(struct mmc_host *host, u32 ocr,
|
||||
*
|
||||
* WARNING: eMMC rules are NOT the same as SD DDR
|
||||
*/
|
||||
- if (ddr == EXT_CSD_CARD_TYPE_DDR_1_2V) {
|
||||
+ if (ddr == MMC_1_2V_DDR_MODE) {
|
||||
err = mmc_set_signal_voltage(host,
|
||||
MMC_SIGNAL_VOLTAGE_120, 0);
|
||||
if (err)
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+39
@@ -0,0 +1,39 @@
|
||||
From c1e5c579b2911ebddcdd5cbebc91edbe3a82af4d Mon Sep 17 00:00:00 2001
|
||||
From: Aaron Lu <aaron.lu@amd.com>
|
||||
Date: Wed, 28 Dec 2011 11:11:12 +0800
|
||||
Subject: [PATCH 059/130] mmc: sdhci: Fix tuning timer incorrect setting when
|
||||
suspending host
|
||||
|
||||
commit c6ced0db08010ed75df221a2946c5228454b38d5 upstream.
|
||||
|
||||
When suspending host, the tuning timer shoule be deactivated.
|
||||
And the HOST_NEEDS_TUNING flag should be set after tuning timer is
|
||||
deactivated.
|
||||
|
||||
Signed-off-by: Philip Rakity <prakity@marvell.com>
|
||||
Signed-off-by: Aaron Lu <aaron.lu@amd.com>
|
||||
Acked-by: Adrian Hunter <adrian.hunter@intel.com>
|
||||
Signed-off-by: Chris Ball <cjb@laptop.org>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/mmc/host/sdhci.c | 3 +--
|
||||
1 files changed, 1 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/drivers/mmc/host/sdhci.c b/drivers/mmc/host/sdhci.c
|
||||
index 19ed580..9279c1b 100644
|
||||
--- a/drivers/mmc/host/sdhci.c
|
||||
+++ b/drivers/mmc/host/sdhci.c
|
||||
@@ -2336,9 +2336,8 @@ int sdhci_suspend_host(struct sdhci_host *host)
|
||||
/* Disable tuning since we are suspending */
|
||||
if (host->version >= SDHCI_SPEC_300 && host->tuning_count &&
|
||||
host->tuning_mode == SDHCI_TUNING_MODE_1) {
|
||||
+ del_timer_sync(&host->tuning_timer);
|
||||
host->flags &= ~SDHCI_NEEDS_RETUNING;
|
||||
- mod_timer(&host->tuning_timer, jiffies +
|
||||
- host->tuning_count * HZ);
|
||||
}
|
||||
|
||||
ret = mmc_suspend_host(host->mmc);
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+38
@@ -0,0 +1,38 @@
|
||||
From 2bcbb8b0e7cecfd753f470dfa9f0780f7c07e28d Mon Sep 17 00:00:00 2001
|
||||
From: Alexander Elbs <alex@segv.de>
|
||||
Date: Tue, 3 Jan 2012 23:26:53 -0500
|
||||
Subject: [PATCH 060/130] mmc: sd: Fix SDR12 timing regression
|
||||
|
||||
commit dd8df17fe83483d7ea06ff229895e35a42071599 upstream.
|
||||
|
||||
This patch fixes a failure to recognize SD cards reported on a Dell
|
||||
Vostro with O2 Micro SD card reader. Patch 49c468f ("mmc: sd: add
|
||||
support for uhs bus speed mode selection") caused the problem, by
|
||||
setting the SDHCI_CTRL_HISPD flag even for legacy timings.
|
||||
|
||||
Signed-off-by: Alexander Elbs <alex@segv.de>
|
||||
Acked-by: Philip Rakity <prakity@marvell.com>
|
||||
Acked-by: Arindam Nath <arindam.nath@amd.com>
|
||||
Signed-off-by: Chris Ball <cjb@laptop.org>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/mmc/host/sdhci.c | 3 +--
|
||||
1 files changed, 1 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/drivers/mmc/host/sdhci.c b/drivers/mmc/host/sdhci.c
|
||||
index 9279c1b..6ce32a7 100644
|
||||
--- a/drivers/mmc/host/sdhci.c
|
||||
+++ b/drivers/mmc/host/sdhci.c
|
||||
@@ -1364,8 +1364,7 @@ static void sdhci_do_set_ios(struct sdhci_host *host, struct mmc_ios *ios)
|
||||
if ((ios->timing == MMC_TIMING_UHS_SDR50) ||
|
||||
(ios->timing == MMC_TIMING_UHS_SDR104) ||
|
||||
(ios->timing == MMC_TIMING_UHS_DDR50) ||
|
||||
- (ios->timing == MMC_TIMING_UHS_SDR25) ||
|
||||
- (ios->timing == MMC_TIMING_UHS_SDR12))
|
||||
+ (ios->timing == MMC_TIMING_UHS_SDR25))
|
||||
ctrl |= SDHCI_CTRL_HISPD;
|
||||
|
||||
ctrl_2 = sdhci_readw(host, SDHCI_HOST_CONTROL2);
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+54
@@ -0,0 +1,54 @@
|
||||
From 367f7884638cda94299eb0e38e200031a5d3130d Mon Sep 17 00:00:00 2001
|
||||
From: Dan Carpenter <dan.carpenter@oracle.com>
|
||||
Date: Thu, 5 Jan 2012 02:27:57 -0300
|
||||
Subject: [PATCH 061/130] V4L/DVB: v4l2-ioctl: integer overflow in
|
||||
video_usercopy()
|
||||
|
||||
commit 6c06108be53ca5e94d8b0e93883d534dd9079646 upstream.
|
||||
|
||||
If ctrls->count is too high the multiplication could overflow and
|
||||
array_size would be lower than expected. Mauro and Hans Verkuil
|
||||
suggested that we cap it at 1024. That comes from the maximum
|
||||
number of controls with lots of room for expantion.
|
||||
|
||||
$ grep V4L2_CID include/linux/videodev2.h | wc -l
|
||||
211
|
||||
|
||||
Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
|
||||
Signed-off-by: Mauro Carvalho Chehab <mchehab@redhat.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/media/video/v4l2-ioctl.c | 4 ++++
|
||||
include/linux/videodev2.h | 1 +
|
||||
2 files changed, 5 insertions(+), 0 deletions(-)
|
||||
|
||||
diff --git a/drivers/media/video/v4l2-ioctl.c b/drivers/media/video/v4l2-ioctl.c
|
||||
index e1da8fc..639abee 100644
|
||||
--- a/drivers/media/video/v4l2-ioctl.c
|
||||
+++ b/drivers/media/video/v4l2-ioctl.c
|
||||
@@ -2226,6 +2226,10 @@ static int check_array_args(unsigned int cmd, void *parg, size_t *array_size,
|
||||
struct v4l2_ext_controls *ctrls = parg;
|
||||
|
||||
if (ctrls->count != 0) {
|
||||
+ if (ctrls->count > V4L2_CID_MAX_CTRLS) {
|
||||
+ ret = -EINVAL;
|
||||
+ break;
|
||||
+ }
|
||||
*user_ptr = (void __user *)ctrls->controls;
|
||||
*kernel_ptr = (void *)&ctrls->controls;
|
||||
*array_size = sizeof(struct v4l2_ext_control)
|
||||
diff --git a/include/linux/videodev2.h b/include/linux/videodev2.h
|
||||
index 4b752d5..45a7698 100644
|
||||
--- a/include/linux/videodev2.h
|
||||
+++ b/include/linux/videodev2.h
|
||||
@@ -1131,6 +1131,7 @@ struct v4l2_querymenu {
|
||||
#define V4L2_CTRL_FLAG_NEXT_CTRL 0x80000000
|
||||
|
||||
/* User-class control IDs defined by V4L2 */
|
||||
+#define V4L2_CID_MAX_CTRLS 1024
|
||||
#define V4L2_CID_BASE (V4L2_CTRL_CLASS_USER | 0x900)
|
||||
#define V4L2_CID_USER_BASE V4L2_CID_BASE
|
||||
/* IDs reserved for driver specific controls */
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+71
@@ -0,0 +1,71 @@
|
||||
From b8292304bc243db5cc68c27e19c7c14c15e19263 Mon Sep 17 00:00:00 2001
|
||||
From: Gleb Natapov <gleb@redhat.com>
|
||||
Date: Sun, 8 Jan 2012 17:07:28 +0200
|
||||
Subject: [PATCH 062/130] Unused iocbs in a batch should not be accounted as
|
||||
active.
|
||||
|
||||
commit 69e4747ee9727d660b88d7e1efe0f4afcb35db1b upstream.
|
||||
|
||||
Since commit 080d676de095 ("aio: allocate kiocbs in batches") iocbs are
|
||||
allocated in a batch during processing of first iocbs. All iocbs in a
|
||||
batch are automatically added to ctx->active_reqs list and accounted in
|
||||
ctx->reqs_active.
|
||||
|
||||
If one (not the last one) of iocbs submitted by an user fails, further
|
||||
iocbs are not processed, but they are still present in ctx->active_reqs
|
||||
and accounted in ctx->reqs_active. This causes process to stuck in a D
|
||||
state in wait_for_all_aios() on exit since ctx->reqs_active will never
|
||||
go down to zero. Furthermore since kiocb_batch_free() frees iocb
|
||||
without removing it from active_reqs list the list become corrupted
|
||||
which may cause oops.
|
||||
|
||||
Fix this by removing iocb from ctx->active_reqs and updating
|
||||
ctx->reqs_active in kiocb_batch_free().
|
||||
|
||||
Signed-off-by: Gleb Natapov <gleb@redhat.com>
|
||||
Reviewed-by: Jeff Moyer <jmoyer@redhat.com>
|
||||
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
fs/aio.c | 11 +++++++++--
|
||||
1 files changed, 9 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/fs/aio.c b/fs/aio.c
|
||||
index 78c514c..969beb0 100644
|
||||
--- a/fs/aio.c
|
||||
+++ b/fs/aio.c
|
||||
@@ -476,14 +476,21 @@ static void kiocb_batch_init(struct kiocb_batch *batch, long total)
|
||||
batch->count = total;
|
||||
}
|
||||
|
||||
-static void kiocb_batch_free(struct kiocb_batch *batch)
|
||||
+static void kiocb_batch_free(struct kioctx *ctx, struct kiocb_batch *batch)
|
||||
{
|
||||
struct kiocb *req, *n;
|
||||
|
||||
+ if (list_empty(&batch->head))
|
||||
+ return;
|
||||
+
|
||||
+ spin_lock_irq(&ctx->ctx_lock);
|
||||
list_for_each_entry_safe(req, n, &batch->head, ki_batch) {
|
||||
list_del(&req->ki_batch);
|
||||
+ list_del(&req->ki_list);
|
||||
kmem_cache_free(kiocb_cachep, req);
|
||||
+ ctx->reqs_active--;
|
||||
}
|
||||
+ spin_unlock_irq(&ctx->ctx_lock);
|
||||
}
|
||||
|
||||
/*
|
||||
@@ -1742,7 +1749,7 @@ long do_io_submit(aio_context_t ctx_id, long nr,
|
||||
}
|
||||
blk_finish_plug(&plug);
|
||||
|
||||
- kiocb_batch_free(&batch);
|
||||
+ kiocb_batch_free(ctx, &batch);
|
||||
put_ioctx(ctx);
|
||||
return i ? i : ret;
|
||||
}
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+227
@@ -0,0 +1,227 @@
|
||||
From dedf47c7159cb4b5d1744557aa744145f161eac5 Mon Sep 17 00:00:00 2001
|
||||
From: Jiri Olsa <jolsa@redhat.com>
|
||||
Date: Mon, 5 Dec 2011 18:22:48 +0100
|
||||
Subject: [PATCH 063/130] ftrace: Fix unregister ftrace_ops accounting
|
||||
|
||||
commit 30fb6aa74011dcf595f306ca2727254d708b786e upstream.
|
||||
|
||||
Multiple users of the function tracer can register their functions
|
||||
with the ftrace_ops structure. The accounting within ftrace will
|
||||
update the counter on each function record that is being traced.
|
||||
When the ftrace_ops filtering adds or removes functions, the
|
||||
function records will be updated accordingly if the ftrace_ops is
|
||||
still registered.
|
||||
|
||||
When a ftrace_ops is removed, the counter of the function records,
|
||||
that the ftrace_ops traces, are decremented. When they reach zero
|
||||
the functions that they represent are modified to stop calling the
|
||||
mcount code.
|
||||
|
||||
When changes are made, the code is updated via stop_machine() with
|
||||
a command passed to the function to tell it what to do. There is an
|
||||
ENABLE and DISABLE command that tells the called function to enable
|
||||
or disable the functions. But the ENABLE is really a misnomer as it
|
||||
should just update the records, as records that have been enabled
|
||||
and now have a count of zero should be disabled.
|
||||
|
||||
The DISABLE command is used to disable all functions regardless of
|
||||
their counter values. This is the big off switch and is not the
|
||||
complement of the ENABLE command.
|
||||
|
||||
To make matters worse, when a ftrace_ops is unregistered and there
|
||||
is another ftrace_ops registered, neither the DISABLE nor the
|
||||
ENABLE command are set when calling into the stop_machine() function
|
||||
and the records will not be updated to match their counter. A command
|
||||
is passed to that function that will update the mcount code to call
|
||||
the registered callback directly if it is the only one left. This
|
||||
means that the ftrace_ops that is still registered will have its callback
|
||||
called by all functions that have been set for it as well as the ftrace_ops
|
||||
that was just unregistered.
|
||||
|
||||
Here's a way to trigger this bug. Compile the kernel with
|
||||
CONFIG_FUNCTION_PROFILER set and with CONFIG_FUNCTION_GRAPH not set:
|
||||
|
||||
CONFIG_FUNCTION_PROFILER=y
|
||||
# CONFIG_FUNCTION_GRAPH is not set
|
||||
|
||||
This will force the function profiler to use the function tracer instead
|
||||
of the function graph tracer.
|
||||
|
||||
# cd /sys/kernel/debug/tracing
|
||||
# echo schedule > set_ftrace_filter
|
||||
# echo function > current_tracer
|
||||
# cat set_ftrace_filter
|
||||
schedule
|
||||
# cat trace
|
||||
# tracer: nop
|
||||
#
|
||||
# entries-in-buffer/entries-written: 692/68108025 #P:4
|
||||
#
|
||||
# _-----=> irqs-off
|
||||
# / _----=> need-resched
|
||||
# | / _---=> hardirq/softirq
|
||||
# || / _--=> preempt-depth
|
||||
# ||| / delay
|
||||
# TASK-PID CPU# |||| TIMESTAMP FUNCTION
|
||||
# | | | |||| | |
|
||||
kworker/0:2-909 [000] .... 531.235574: schedule <-worker_thread
|
||||
<idle>-0 [001] .N.. 531.235575: schedule <-cpu_idle
|
||||
kworker/0:2-909 [000] .... 531.235597: schedule <-worker_thread
|
||||
sshd-2563 [001] .... 531.235647: schedule <-schedule_hrtimeout_range_clock
|
||||
|
||||
# echo 1 > function_profile_enabled
|
||||
# echo 0 > function_porfile_enabled
|
||||
# cat set_ftrace_filter
|
||||
schedule
|
||||
# cat trace
|
||||
# tracer: function
|
||||
#
|
||||
# entries-in-buffer/entries-written: 159701/118821262 #P:4
|
||||
#
|
||||
# _-----=> irqs-off
|
||||
# / _----=> need-resched
|
||||
# | / _---=> hardirq/softirq
|
||||
# || / _--=> preempt-depth
|
||||
# ||| / delay
|
||||
# TASK-PID CPU# |||| TIMESTAMP FUNCTION
|
||||
# | | | |||| | |
|
||||
<idle>-0 [002] ...1 604.870655: local_touch_nmi <-cpu_idle
|
||||
<idle>-0 [002] d..1 604.870655: enter_idle <-cpu_idle
|
||||
<idle>-0 [002] d..1 604.870656: atomic_notifier_call_chain <-enter_idle
|
||||
<idle>-0 [002] d..1 604.870656: __atomic_notifier_call_chain <-atomic_notifier_call_chain
|
||||
|
||||
The same problem could have happened with the trace_probe_ops,
|
||||
but they are modified with the set_frace_filter file which does the
|
||||
update at closure of the file.
|
||||
|
||||
The simple solution is to change ENABLE to UPDATE and call it every
|
||||
time an ftrace_ops is unregistered.
|
||||
|
||||
Link: http://lkml.kernel.org/r/1323105776-26961-3-git-send-email-jolsa@redhat.com
|
||||
|
||||
Signed-off-by: Jiri Olsa <jolsa@redhat.com>
|
||||
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
kernel/trace/ftrace.c | 27 +++++++++++++--------------
|
||||
1 files changed, 13 insertions(+), 14 deletions(-)
|
||||
|
||||
diff --git a/kernel/trace/ftrace.c b/kernel/trace/ftrace.c
|
||||
index b1e8943..25b4f4d 100644
|
||||
--- a/kernel/trace/ftrace.c
|
||||
+++ b/kernel/trace/ftrace.c
|
||||
@@ -948,7 +948,7 @@ struct ftrace_func_probe {
|
||||
};
|
||||
|
||||
enum {
|
||||
- FTRACE_ENABLE_CALLS = (1 << 0),
|
||||
+ FTRACE_UPDATE_CALLS = (1 << 0),
|
||||
FTRACE_DISABLE_CALLS = (1 << 1),
|
||||
FTRACE_UPDATE_TRACE_FUNC = (1 << 2),
|
||||
FTRACE_START_FUNC_RET = (1 << 3),
|
||||
@@ -1519,7 +1519,7 @@ int ftrace_text_reserved(void *start, void *end)
|
||||
|
||||
|
||||
static int
|
||||
-__ftrace_replace_code(struct dyn_ftrace *rec, int enable)
|
||||
+__ftrace_replace_code(struct dyn_ftrace *rec, int update)
|
||||
{
|
||||
unsigned long ftrace_addr;
|
||||
unsigned long flag = 0UL;
|
||||
@@ -1527,17 +1527,17 @@ __ftrace_replace_code(struct dyn_ftrace *rec, int enable)
|
||||
ftrace_addr = (unsigned long)FTRACE_ADDR;
|
||||
|
||||
/*
|
||||
- * If we are enabling tracing:
|
||||
+ * If we are updating calls:
|
||||
*
|
||||
* If the record has a ref count, then we need to enable it
|
||||
* because someone is using it.
|
||||
*
|
||||
* Otherwise we make sure its disabled.
|
||||
*
|
||||
- * If we are disabling tracing, then disable all records that
|
||||
+ * If we are disabling calls, then disable all records that
|
||||
* are enabled.
|
||||
*/
|
||||
- if (enable && (rec->flags & ~FTRACE_FL_MASK))
|
||||
+ if (update && (rec->flags & ~FTRACE_FL_MASK))
|
||||
flag = FTRACE_FL_ENABLED;
|
||||
|
||||
/* If the state of this record hasn't changed, then do nothing */
|
||||
@@ -1553,7 +1553,7 @@ __ftrace_replace_code(struct dyn_ftrace *rec, int enable)
|
||||
return ftrace_make_nop(NULL, rec, ftrace_addr);
|
||||
}
|
||||
|
||||
-static void ftrace_replace_code(int enable)
|
||||
+static void ftrace_replace_code(int update)
|
||||
{
|
||||
struct dyn_ftrace *rec;
|
||||
struct ftrace_page *pg;
|
||||
@@ -1567,7 +1567,7 @@ static void ftrace_replace_code(int enable)
|
||||
if (rec->flags & FTRACE_FL_FREE)
|
||||
continue;
|
||||
|
||||
- failed = __ftrace_replace_code(rec, enable);
|
||||
+ failed = __ftrace_replace_code(rec, update);
|
||||
if (failed) {
|
||||
ftrace_bug(failed, rec->ip);
|
||||
/* Stop processing */
|
||||
@@ -1623,7 +1623,7 @@ static int __ftrace_modify_code(void *data)
|
||||
*/
|
||||
function_trace_stop++;
|
||||
|
||||
- if (*command & FTRACE_ENABLE_CALLS)
|
||||
+ if (*command & FTRACE_UPDATE_CALLS)
|
||||
ftrace_replace_code(1);
|
||||
else if (*command & FTRACE_DISABLE_CALLS)
|
||||
ftrace_replace_code(0);
|
||||
@@ -1691,7 +1691,7 @@ static int ftrace_startup(struct ftrace_ops *ops, int command)
|
||||
return -ENODEV;
|
||||
|
||||
ftrace_start_up++;
|
||||
- command |= FTRACE_ENABLE_CALLS;
|
||||
+ command |= FTRACE_UPDATE_CALLS;
|
||||
|
||||
/* ops marked global share the filter hashes */
|
||||
if (ops->flags & FTRACE_OPS_FL_GLOBAL) {
|
||||
@@ -1743,8 +1743,7 @@ static void ftrace_shutdown(struct ftrace_ops *ops, int command)
|
||||
if (ops != &global_ops || !global_start_up)
|
||||
ops->flags &= ~FTRACE_OPS_FL_ENABLED;
|
||||
|
||||
- if (!ftrace_start_up)
|
||||
- command |= FTRACE_DISABLE_CALLS;
|
||||
+ command |= FTRACE_UPDATE_CALLS;
|
||||
|
||||
if (saved_ftrace_func != ftrace_trace_function) {
|
||||
saved_ftrace_func = ftrace_trace_function;
|
||||
@@ -1766,7 +1765,7 @@ static void ftrace_startup_sysctl(void)
|
||||
saved_ftrace_func = NULL;
|
||||
/* ftrace_start_up is true if we want ftrace running */
|
||||
if (ftrace_start_up)
|
||||
- ftrace_run_update_code(FTRACE_ENABLE_CALLS);
|
||||
+ ftrace_run_update_code(FTRACE_UPDATE_CALLS);
|
||||
}
|
||||
|
||||
static void ftrace_shutdown_sysctl(void)
|
||||
@@ -2919,7 +2918,7 @@ ftrace_set_regex(struct ftrace_ops *ops, unsigned char *buf, int len,
|
||||
ret = ftrace_hash_move(ops, enable, orig_hash, hash);
|
||||
if (!ret && ops->flags & FTRACE_OPS_FL_ENABLED
|
||||
&& ftrace_enabled)
|
||||
- ftrace_run_update_code(FTRACE_ENABLE_CALLS);
|
||||
+ ftrace_run_update_code(FTRACE_UPDATE_CALLS);
|
||||
|
||||
mutex_unlock(&ftrace_lock);
|
||||
|
||||
@@ -3107,7 +3106,7 @@ ftrace_regex_release(struct inode *inode, struct file *file)
|
||||
orig_hash, iter->hash);
|
||||
if (!ret && (iter->ops->flags & FTRACE_OPS_FL_ENABLED)
|
||||
&& ftrace_enabled)
|
||||
- ftrace_run_update_code(FTRACE_ENABLE_CALLS);
|
||||
+ ftrace_run_update_code(FTRACE_UPDATE_CALLS);
|
||||
|
||||
mutex_unlock(&ftrace_lock);
|
||||
}
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+68
@@ -0,0 +1,68 @@
|
||||
From 700e5b37d0da1b3688992c53abba2ba9c123c547 Mon Sep 17 00:00:00 2001
|
||||
From: Steven Rostedt <srostedt@redhat.com>
|
||||
Date: Fri, 13 Jan 2012 17:50:39 -0500
|
||||
Subject: [PATCH 064/130] kconfig/streamline-config.pl: Simplify backslash
|
||||
line concatination
|
||||
|
||||
commit d060d963e88f3e990cec2fe5214de49de9a49eca upstream.
|
||||
|
||||
Simplify the way lines ending with backslashes (continuation) in Makefiles
|
||||
is parsed. This is needed to implement a necessary fix.
|
||||
|
||||
Tested-by: Thomas Lange <thomas-lange2@gmx.de>
|
||||
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
scripts/kconfig/streamline_config.pl | 25 ++++++++++++-------------
|
||||
1 files changed, 12 insertions(+), 13 deletions(-)
|
||||
|
||||
diff --git a/scripts/kconfig/streamline_config.pl b/scripts/kconfig/streamline_config.pl
|
||||
index ec7afce..42ef5ea 100644
|
||||
--- a/scripts/kconfig/streamline_config.pl
|
||||
+++ b/scripts/kconfig/streamline_config.pl
|
||||
@@ -253,17 +253,22 @@ if ($kconfig) {
|
||||
# Read all Makefiles to map the configs to the objects
|
||||
foreach my $makefile (@makefiles) {
|
||||
|
||||
- my $cont = 0;
|
||||
+ my $line = "";
|
||||
|
||||
open(MIN,$makefile) || die "Can't open $makefile";
|
||||
while (<MIN>) {
|
||||
- my $objs;
|
||||
-
|
||||
- # is this a line after a line with a backslash?
|
||||
- if ($cont && /(\S.*)$/) {
|
||||
- $objs = $1;
|
||||
+ # if this line ends with a backslash, continue
|
||||
+ chomp;
|
||||
+ if (/^(.*)\\$/) {
|
||||
+ $line .= $1;
|
||||
+ next;
|
||||
}
|
||||
- $cont = 0;
|
||||
+
|
||||
+ $line .= $_;
|
||||
+ $_ = $line;
|
||||
+ $line = "";
|
||||
+
|
||||
+ my $objs;
|
||||
|
||||
# collect objects after obj-$(CONFIG_FOO_BAR)
|
||||
if (/obj-\$\((CONFIG_[^\)]*)\)\s*[+:]?=\s*(.*)/) {
|
||||
@@ -271,12 +276,6 @@ foreach my $makefile (@makefiles) {
|
||||
$objs = $2;
|
||||
}
|
||||
if (defined($objs)) {
|
||||
- # test if the line ends with a backslash
|
||||
- if ($objs =~ m,(.*)\\$,) {
|
||||
- $objs = $1;
|
||||
- $cont = 1;
|
||||
- }
|
||||
-
|
||||
foreach my $obj (split /\s+/,$objs) {
|
||||
$obj =~ s/-/_/g;
|
||||
if ($obj =~ /(.*)\.o$/) {
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+98
@@ -0,0 +1,98 @@
|
||||
From 4f45c91ec4a5953d1a1bf1d88d8bf4fa5b0273a0 Mon Sep 17 00:00:00 2001
|
||||
From: Steven Rostedt <srostedt@redhat.com>
|
||||
Date: Fri, 13 Jan 2012 17:53:40 -0500
|
||||
Subject: [PATCH 065/130] kconfig/streamline-config.pl: Fix parsing Makefile
|
||||
with variables
|
||||
|
||||
commit 364212fddaaa60c5a64f67a0f5624ad996ecc8a0 upstream.
|
||||
|
||||
Thomas Lange reported that when he did a 'make localmodconfig', his
|
||||
config was missing the brcmsmac driver, even though he had the module
|
||||
loaded.
|
||||
|
||||
Looking into this, I found the file:
|
||||
drivers/net/wireless/brcm80211/brcmsmac/Makefile
|
||||
had the following in the Makefile:
|
||||
|
||||
MODULEPFX := brcmsmac
|
||||
|
||||
obj-$(CONFIG_BRCMSMAC) += $(MODULEPFX).o
|
||||
|
||||
The way streamline-config.pl works, is parsing all the
|
||||
obj-$(CONFIG_FOO) += foo.o
|
||||
lines to find that CONFIG_FOO belongs to the module foo.ko.
|
||||
|
||||
But in this case, the brcmsmac.o was not used, but a variable in its place.
|
||||
|
||||
By changing streamline-config.pl to remember defined variables in Makefiles
|
||||
and substituting them when they are used in the obj-X lines, allows
|
||||
Thomas (and others) to have their brcmsmac module stay configured
|
||||
when it is loaded and running "make localmodconfig".
|
||||
|
||||
Reported-by: Thomas Lange <thomas-lange2@gmx.de>
|
||||
Tested-by: Thomas Lange <thomas-lange2@gmx.de>
|
||||
Cc: Arend van Spriel <arend@broadcom.com>
|
||||
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
scripts/kconfig/streamline_config.pl | 29 +++++++++++++++++++++++++++++
|
||||
1 files changed, 29 insertions(+), 0 deletions(-)
|
||||
|
||||
diff --git a/scripts/kconfig/streamline_config.pl b/scripts/kconfig/streamline_config.pl
|
||||
index 42ef5ea..bccf07d 100644
|
||||
--- a/scripts/kconfig/streamline_config.pl
|
||||
+++ b/scripts/kconfig/streamline_config.pl
|
||||
@@ -250,10 +250,33 @@ if ($kconfig) {
|
||||
read_kconfig($kconfig);
|
||||
}
|
||||
|
||||
+sub convert_vars {
|
||||
+ my ($line, %vars) = @_;
|
||||
+
|
||||
+ my $process = "";
|
||||
+
|
||||
+ while ($line =~ s/^(.*?)(\$\((.*?)\))//) {
|
||||
+ my $start = $1;
|
||||
+ my $variable = $2;
|
||||
+ my $var = $3;
|
||||
+
|
||||
+ if (defined($vars{$var})) {
|
||||
+ $process .= $start . $vars{$var};
|
||||
+ } else {
|
||||
+ $process .= $start . $variable;
|
||||
+ }
|
||||
+ }
|
||||
+
|
||||
+ $process .= $line;
|
||||
+
|
||||
+ return $process;
|
||||
+}
|
||||
+
|
||||
# Read all Makefiles to map the configs to the objects
|
||||
foreach my $makefile (@makefiles) {
|
||||
|
||||
my $line = "";
|
||||
+ my %make_vars;
|
||||
|
||||
open(MIN,$makefile) || die "Can't open $makefile";
|
||||
while (<MIN>) {
|
||||
@@ -270,10 +293,16 @@ foreach my $makefile (@makefiles) {
|
||||
|
||||
my $objs;
|
||||
|
||||
+ $_ = convert_vars($_, %make_vars);
|
||||
+
|
||||
# collect objects after obj-$(CONFIG_FOO_BAR)
|
||||
if (/obj-\$\((CONFIG_[^\)]*)\)\s*[+:]?=\s*(.*)/) {
|
||||
$var = $1;
|
||||
$objs = $2;
|
||||
+
|
||||
+ # check if variables are set
|
||||
+ } elsif (/^\s*(\S+)\s*[:]?=\s*(.*\S)/) {
|
||||
+ $make_vars{$1} = $2;
|
||||
}
|
||||
if (defined($objs)) {
|
||||
foreach my $obj (split /\s+/,$objs) {
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+60
@@ -0,0 +1,60 @@
|
||||
From 843e6d14e855cc86d260b1077a3226d3344376af Mon Sep 17 00:00:00 2001
|
||||
From: "J. Bruce Fields" <bfields@redhat.com>
|
||||
Date: Thu, 22 Dec 2011 18:22:49 -0700
|
||||
Subject: [PATCH 066/130] svcrpc: fix double-free on shutdown of nfsd after
|
||||
changing pool mode
|
||||
|
||||
commit 61c8504c428edcebf23b97775a129c5b393a302b upstream.
|
||||
|
||||
The pool_to and to_pool fields of the global svc_pool_map are freed on
|
||||
shutdown, but are initialized in nfsd startup only in the
|
||||
SVC_POOL_PERCPU and SVC_POOL_PERNODE cases.
|
||||
|
||||
They *are* initialized to zero on kernel startup. So as long as you use
|
||||
only SVC_POOL_GLOBAL (the default), this will never be a problem.
|
||||
|
||||
You're also OK if you only ever use SVC_POOL_PERCPU or SVC_POOL_PERNODE.
|
||||
|
||||
However, the following sequence events leads to a double-free:
|
||||
|
||||
1. set SVC_POOL_PERCPU or SVC_POOL_PERNODE
|
||||
2. start nfsd: both fields are initialized.
|
||||
3. shutdown nfsd: both fields are freed.
|
||||
4. set SVC_POOL_GLOBAL
|
||||
5. start nfsd: the fields are left untouched.
|
||||
6. shutdown nfsd: now we try to free them again.
|
||||
|
||||
Step 4 is actually unnecessary, since (for some bizarre reason), nfsd
|
||||
automatically resets the pool mode to SVC_POOL_GLOBAL on shutdown.
|
||||
|
||||
Signed-off-by: J. Bruce Fields <bfields@redhat.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
net/sunrpc/svc.c | 3 +++
|
||||
1 files changed, 3 insertions(+), 0 deletions(-)
|
||||
|
||||
diff --git a/net/sunrpc/svc.c b/net/sunrpc/svc.c
|
||||
index 6e03888..5443ffd 100644
|
||||
--- a/net/sunrpc/svc.c
|
||||
+++ b/net/sunrpc/svc.c
|
||||
@@ -167,6 +167,7 @@ svc_pool_map_alloc_arrays(struct svc_pool_map *m, unsigned int maxpools)
|
||||
|
||||
fail_free:
|
||||
kfree(m->to_pool);
|
||||
+ m->to_pool = NULL;
|
||||
fail:
|
||||
return -ENOMEM;
|
||||
}
|
||||
@@ -287,7 +288,9 @@ svc_pool_map_put(void)
|
||||
if (!--m->count) {
|
||||
m->mode = SVC_POOL_DEFAULT;
|
||||
kfree(m->to_pool);
|
||||
+ m->to_pool = NULL;
|
||||
kfree(m->pool_to);
|
||||
+ m->pool_to = NULL;
|
||||
m->npools = 0;
|
||||
}
|
||||
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+85
@@ -0,0 +1,85 @@
|
||||
From c132bb68434e1dcfc0e148d1e677f4433d6cf075 Mon Sep 17 00:00:00 2001
|
||||
From: "J. Bruce Fields" <bfields@redhat.com>
|
||||
Date: Tue, 29 Nov 2011 11:35:35 -0500
|
||||
Subject: [PATCH 067/130] svcrpc: destroy server sockets all at once
|
||||
|
||||
commit 2fefb8a09e7ed251ae8996e0c69066e74c5aa560 upstream.
|
||||
|
||||
There's no reason I can see that we need to call sv_shutdown between
|
||||
closing the two lists of sockets.
|
||||
|
||||
Signed-off-by: J. Bruce Fields <bfields@redhat.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
include/linux/sunrpc/svcsock.h | 2 +-
|
||||
net/sunrpc/svc.c | 7 +------
|
||||
net/sunrpc/svc_xprt.c | 11 ++++++++++-
|
||||
3 files changed, 12 insertions(+), 8 deletions(-)
|
||||
|
||||
diff --git a/include/linux/sunrpc/svcsock.h b/include/linux/sunrpc/svcsock.h
|
||||
index 85c50b4..c84e974 100644
|
||||
--- a/include/linux/sunrpc/svcsock.h
|
||||
+++ b/include/linux/sunrpc/svcsock.h
|
||||
@@ -34,7 +34,7 @@ struct svc_sock {
|
||||
/*
|
||||
* Function prototypes.
|
||||
*/
|
||||
-void svc_close_all(struct list_head *);
|
||||
+void svc_close_all(struct svc_serv *);
|
||||
int svc_recv(struct svc_rqst *, long);
|
||||
int svc_send(struct svc_rqst *);
|
||||
void svc_drop(struct svc_rqst *);
|
||||
diff --git a/net/sunrpc/svc.c b/net/sunrpc/svc.c
|
||||
index 5443ffd..7ddfb04 100644
|
||||
--- a/net/sunrpc/svc.c
|
||||
+++ b/net/sunrpc/svc.c
|
||||
@@ -531,16 +531,11 @@ svc_destroy(struct svc_serv *serv)
|
||||
|
||||
del_timer_sync(&serv->sv_temptimer);
|
||||
|
||||
- svc_close_all(&serv->sv_tempsocks);
|
||||
+ svc_close_all(serv);
|
||||
|
||||
if (serv->sv_shutdown)
|
||||
serv->sv_shutdown(serv);
|
||||
|
||||
- svc_close_all(&serv->sv_permsocks);
|
||||
-
|
||||
- BUG_ON(!list_empty(&serv->sv_permsocks));
|
||||
- BUG_ON(!list_empty(&serv->sv_tempsocks));
|
||||
-
|
||||
cache_clean_deferred(serv);
|
||||
|
||||
if (svc_serv_is_pooled(serv))
|
||||
diff --git a/net/sunrpc/svc_xprt.c b/net/sunrpc/svc_xprt.c
|
||||
index 447cd0e..dcdc8df 100644
|
||||
--- a/net/sunrpc/svc_xprt.c
|
||||
+++ b/net/sunrpc/svc_xprt.c
|
||||
@@ -928,7 +928,7 @@ void svc_close_xprt(struct svc_xprt *xprt)
|
||||
}
|
||||
EXPORT_SYMBOL_GPL(svc_close_xprt);
|
||||
|
||||
-void svc_close_all(struct list_head *xprt_list)
|
||||
+static void svc_close_list(struct list_head *xprt_list)
|
||||
{
|
||||
struct svc_xprt *xprt;
|
||||
struct svc_xprt *tmp;
|
||||
@@ -946,6 +946,15 @@ void svc_close_all(struct list_head *xprt_list)
|
||||
}
|
||||
}
|
||||
|
||||
+void svc_close_all(struct svc_serv *serv)
|
||||
+{
|
||||
+ svc_close_list(&serv->sv_tempsocks);
|
||||
+ svc_close_list(&serv->sv_permsocks);
|
||||
+ BUG_ON(!list_empty(&serv->sv_permsocks));
|
||||
+ BUG_ON(!list_empty(&serv->sv_tempsocks));
|
||||
+
|
||||
+}
|
||||
+
|
||||
/*
|
||||
* Handle defer and revisit of requests
|
||||
*/
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+156
@@ -0,0 +1,156 @@
|
||||
From fb5e1630fc3566904898da68a99cc8e764cb420f Mon Sep 17 00:00:00 2001
|
||||
From: "J. Bruce Fields" <bfields@redhat.com>
|
||||
Date: Tue, 29 Nov 2011 17:00:26 -0500
|
||||
Subject: [PATCH 068/130] svcrpc: avoid memory-corruption on pool shutdown
|
||||
|
||||
commit b4f36f88b3ee7cf26bf0be84e6c7fc15f84dcb71 upstream.
|
||||
|
||||
Socket callbacks use svc_xprt_enqueue() to add an xprt to a
|
||||
pool->sp_sockets list. In normal operation a server thread will later
|
||||
come along and take the xprt off that list. On shutdown, after all the
|
||||
threads have exited, we instead manually walk the sv_tempsocks and
|
||||
sv_permsocks lists to find all the xprt's and delete them.
|
||||
|
||||
So the sp_sockets lists don't really matter any more. As a result,
|
||||
we've mostly just ignored them and hoped they would go away.
|
||||
|
||||
Which has gotten us into trouble; witness for example ebc63e531cc6
|
||||
"svcrpc: fix list-corrupting race on nfsd shutdown", the result of Ben
|
||||
Greear noticing that a still-running svc_xprt_enqueue() could re-add an
|
||||
xprt to an sp_sockets list just before it was deleted. The fix was to
|
||||
remove it from the list at the end of svc_delete_xprt(). But that only
|
||||
made corruption less likely--I can see nothing that prevents a
|
||||
svc_xprt_enqueue() from adding another xprt to the list at the same
|
||||
moment that we're removing this xprt from the list. In fact, despite
|
||||
the earlier xpo_detach(), I don't even see what guarantees that
|
||||
svc_xprt_enqueue() couldn't still be running on this xprt.
|
||||
|
||||
So, instead, note that svc_xprt_enqueue() essentially does:
|
||||
lock sp_lock
|
||||
if XPT_BUSY unset
|
||||
add to sp_sockets
|
||||
unlock sp_lock
|
||||
|
||||
So, if we do:
|
||||
|
||||
set XPT_BUSY on every xprt.
|
||||
Empty every sp_sockets list, under the sp_socks locks.
|
||||
|
||||
Then we're left knowing that the sp_sockets lists are all empty and will
|
||||
stay that way, since any svc_xprt_enqueue() will check XPT_BUSY under
|
||||
the sp_lock and see it set.
|
||||
|
||||
And *then* we can continue deleting the xprt's.
|
||||
|
||||
(Thanks to Jeff Layton for being correctly suspicious of this code....)
|
||||
|
||||
Cc: Ben Greear <greearb@candelatech.com>
|
||||
Cc: Jeff Layton <jlayton@redhat.com>
|
||||
Signed-off-by: J. Bruce Fields <bfields@redhat.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
net/sunrpc/svc.c | 10 +++++++++-
|
||||
net/sunrpc/svc_xprt.c | 48 +++++++++++++++++++++++++++++-------------------
|
||||
2 files changed, 38 insertions(+), 20 deletions(-)
|
||||
|
||||
diff --git a/net/sunrpc/svc.c b/net/sunrpc/svc.c
|
||||
index 7ddfb04..d4ad50e 100644
|
||||
--- a/net/sunrpc/svc.c
|
||||
+++ b/net/sunrpc/svc.c
|
||||
@@ -530,7 +530,15 @@ svc_destroy(struct svc_serv *serv)
|
||||
printk("svc_destroy: no threads for serv=%p!\n", serv);
|
||||
|
||||
del_timer_sync(&serv->sv_temptimer);
|
||||
-
|
||||
+ /*
|
||||
+ * The set of xprts (contained in the sv_tempsocks and
|
||||
+ * sv_permsocks lists) is now constant, since it is modified
|
||||
+ * only by accepting new sockets (done by service threads in
|
||||
+ * svc_recv) or aging old ones (done by sv_temptimer), or
|
||||
+ * configuration changes (excluded by whatever locking the
|
||||
+ * caller is using--nfsd_mutex in the case of nfsd). So it's
|
||||
+ * safe to traverse those lists and shut everything down:
|
||||
+ */
|
||||
svc_close_all(serv);
|
||||
|
||||
if (serv->sv_shutdown)
|
||||
diff --git a/net/sunrpc/svc_xprt.c b/net/sunrpc/svc_xprt.c
|
||||
index dcdc8df..9ed2cd0 100644
|
||||
--- a/net/sunrpc/svc_xprt.c
|
||||
+++ b/net/sunrpc/svc_xprt.c
|
||||
@@ -893,14 +893,7 @@ void svc_delete_xprt(struct svc_xprt *xprt)
|
||||
spin_lock_bh(&serv->sv_lock);
|
||||
if (!test_and_set_bit(XPT_DETACHED, &xprt->xpt_flags))
|
||||
list_del_init(&xprt->xpt_list);
|
||||
- /*
|
||||
- * The only time we're called while xpt_ready is still on a list
|
||||
- * is while the list itself is about to be destroyed (in
|
||||
- * svc_destroy). BUT svc_xprt_enqueue could still be attempting
|
||||
- * to add new entries to the sp_sockets list, so we can't leave
|
||||
- * a freed xprt on it.
|
||||
- */
|
||||
- list_del_init(&xprt->xpt_ready);
|
||||
+ BUG_ON(!list_empty(&xprt->xpt_ready));
|
||||
if (test_bit(XPT_TEMP, &xprt->xpt_flags))
|
||||
serv->sv_tmpcnt--;
|
||||
spin_unlock_bh(&serv->sv_lock);
|
||||
@@ -931,28 +924,45 @@ EXPORT_SYMBOL_GPL(svc_close_xprt);
|
||||
static void svc_close_list(struct list_head *xprt_list)
|
||||
{
|
||||
struct svc_xprt *xprt;
|
||||
- struct svc_xprt *tmp;
|
||||
|
||||
- /*
|
||||
- * The server is shutting down, and no more threads are running.
|
||||
- * svc_xprt_enqueue() might still be running, but at worst it
|
||||
- * will re-add the xprt to sp_sockets, which will soon get
|
||||
- * freed. So we don't bother with any more locking, and don't
|
||||
- * leave the close to the (nonexistent) server threads:
|
||||
- */
|
||||
- list_for_each_entry_safe(xprt, tmp, xprt_list, xpt_list) {
|
||||
+ list_for_each_entry(xprt, xprt_list, xpt_list) {
|
||||
set_bit(XPT_CLOSE, &xprt->xpt_flags);
|
||||
- svc_delete_xprt(xprt);
|
||||
+ set_bit(XPT_BUSY, &xprt->xpt_flags);
|
||||
}
|
||||
}
|
||||
|
||||
void svc_close_all(struct svc_serv *serv)
|
||||
{
|
||||
+ struct svc_pool *pool;
|
||||
+ struct svc_xprt *xprt;
|
||||
+ struct svc_xprt *tmp;
|
||||
+ int i;
|
||||
+
|
||||
svc_close_list(&serv->sv_tempsocks);
|
||||
svc_close_list(&serv->sv_permsocks);
|
||||
+
|
||||
+ for (i = 0; i < serv->sv_nrpools; i++) {
|
||||
+ pool = &serv->sv_pools[i];
|
||||
+
|
||||
+ spin_lock_bh(&pool->sp_lock);
|
||||
+ while (!list_empty(&pool->sp_sockets)) {
|
||||
+ xprt = list_first_entry(&pool->sp_sockets, struct svc_xprt, xpt_ready);
|
||||
+ list_del_init(&xprt->xpt_ready);
|
||||
+ }
|
||||
+ spin_unlock_bh(&pool->sp_lock);
|
||||
+ }
|
||||
+ /*
|
||||
+ * At this point the sp_sockets lists will stay empty, since
|
||||
+ * svc_enqueue will not add new entries without taking the
|
||||
+ * sp_lock and checking XPT_BUSY.
|
||||
+ */
|
||||
+ list_for_each_entry_safe(xprt, tmp, &serv->sv_tempsocks, xpt_list)
|
||||
+ svc_delete_xprt(xprt);
|
||||
+ list_for_each_entry_safe(xprt, tmp, &serv->sv_permsocks, xpt_list)
|
||||
+ svc_delete_xprt(xprt);
|
||||
+
|
||||
BUG_ON(!list_empty(&serv->sv_permsocks));
|
||||
BUG_ON(!list_empty(&serv->sv_tempsocks));
|
||||
-
|
||||
}
|
||||
|
||||
/*
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+59
@@ -0,0 +1,59 @@
|
||||
From a626caf8192900669acd90726f7e2716a7cb4c8d Mon Sep 17 00:00:00 2001
|
||||
From: "J. Bruce Fields" <bfields@redhat.com>
|
||||
Date: Mon, 7 Nov 2011 16:37:57 -0500
|
||||
Subject: [PATCH 069/130] nfsd4: fix lockowner matching
|
||||
|
||||
commit b93d87c19821ba7d3ee11557403d782e541071ad upstream.
|
||||
|
||||
Lockowners are looked up by file as well as by owner, but we were
|
||||
forgetting to do a comparison on the file. This could cause an
|
||||
incorrect result from lockt.
|
||||
|
||||
(Note looking up the inode from the lockowner is pretty awkward here.
|
||||
The data structures need fixing.)
|
||||
|
||||
Signed-off-by: J. Bruce Fields <bfields@redhat.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
fs/nfsd/nfs4state.c | 17 +++++++++++++++--
|
||||
1 files changed, 15 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/fs/nfsd/nfs4state.c b/fs/nfsd/nfs4state.c
|
||||
index 47e94e3..5abced7 100644
|
||||
--- a/fs/nfsd/nfs4state.c
|
||||
+++ b/fs/nfsd/nfs4state.c
|
||||
@@ -3809,16 +3809,29 @@ nevermind:
|
||||
deny->ld_type = NFS4_WRITE_LT;
|
||||
}
|
||||
|
||||
+static bool same_lockowner_ino(struct nfs4_lockowner *lo, struct inode *inode, clientid_t *clid, struct xdr_netobj *owner)
|
||||
+{
|
||||
+ struct nfs4_ol_stateid *lst;
|
||||
+
|
||||
+ if (!same_owner_str(&lo->lo_owner, owner, clid))
|
||||
+ return false;
|
||||
+ lst = list_first_entry(&lo->lo_owner.so_stateids,
|
||||
+ struct nfs4_ol_stateid, st_perstateowner);
|
||||
+ return lst->st_file->fi_inode == inode;
|
||||
+}
|
||||
+
|
||||
static struct nfs4_lockowner *
|
||||
find_lockowner_str(struct inode *inode, clientid_t *clid,
|
||||
struct xdr_netobj *owner)
|
||||
{
|
||||
unsigned int hashval = lock_ownerstr_hashval(inode, clid->cl_id, owner);
|
||||
+ struct nfs4_lockowner *lo;
|
||||
struct nfs4_stateowner *op;
|
||||
|
||||
list_for_each_entry(op, &lock_ownerstr_hashtbl[hashval], so_strhash) {
|
||||
- if (same_owner_str(op, owner, clid))
|
||||
- return lockowner(op);
|
||||
+ lo = lockowner(op);
|
||||
+ if (same_lockowner_ino(lo, inode, clid, owner))
|
||||
+ return lo;
|
||||
}
|
||||
return NULL;
|
||||
}
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+82
@@ -0,0 +1,82 @@
|
||||
From 721aa63a8836ec85efe320a384b97ba3c3048740 Mon Sep 17 00:00:00 2001
|
||||
From: Sasha Levin <levinsasha928@gmail.com>
|
||||
Date: Fri, 18 Nov 2011 12:14:49 +0200
|
||||
Subject: [PATCH 070/130] nfsd: Fix oops when parsing a 0 length export
|
||||
|
||||
commit b2ea70afade7080360ac55c4e64ff7a5fafdb67b upstream.
|
||||
|
||||
expkey_parse() oopses when handling a 0 length export. This is easily
|
||||
triggerable from usermode by writing 0 bytes into
|
||||
'/proc/[proc id]/net/rpc/nfsd.fh/channel'.
|
||||
|
||||
Below is the log:
|
||||
|
||||
[ 1402.286893] BUG: unable to handle kernel paging request at ffff880077c49fff
|
||||
[ 1402.287632] IP: [<ffffffff812b4b99>] expkey_parse+0x28/0x2e1
|
||||
[ 1402.287632] PGD 2206063 PUD 1fdfd067 PMD 1ffbc067 PTE 8000000077c49160
|
||||
[ 1402.287632] Oops: 0000 [#1] PREEMPT SMP DEBUG_PAGEALLOC
|
||||
[ 1402.287632] CPU 1
|
||||
[ 1402.287632] Pid: 20198, comm: trinity Not tainted 3.2.0-rc2-sasha-00058-gc65cd37 #6
|
||||
[ 1402.287632] RIP: 0010:[<ffffffff812b4b99>] [<ffffffff812b4b99>] expkey_parse+0x28/0x2e1
|
||||
[ 1402.287632] RSP: 0018:ffff880077f0fd68 EFLAGS: 00010292
|
||||
[ 1402.287632] RAX: ffff880077c49fff RBX: 00000000ffffffea RCX: 0000000001043400
|
||||
[ 1402.287632] RDX: 0000000000000000 RSI: ffff880077c4a000 RDI: ffffffff82283de0
|
||||
[ 1402.287632] RBP: ffff880077f0fe18 R08: 0000000000000001 R09: ffff880000000000
|
||||
[ 1402.287632] R10: 0000000000000000 R11: 0000000000000001 R12: ffff880077c4a000
|
||||
[ 1402.287632] R13: ffffffff82283de0 R14: 0000000001043400 R15: ffffffff82283de0
|
||||
[ 1402.287632] FS: 00007f25fec3f700(0000) GS:ffff88007d400000(0000) knlGS:0000000000000000
|
||||
[ 1402.287632] CS: 0010 DS: 0000 ES: 0000 CR0: 000000008005003b
|
||||
[ 1402.287632] CR2: ffff880077c49fff CR3: 0000000077e1d000 CR4: 00000000000406e0
|
||||
[ 1402.287632] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
|
||||
[ 1402.287632] DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400
|
||||
[ 1402.287632] Process trinity (pid: 20198, threadinfo ffff880077f0e000, task ffff880077db17b0)
|
||||
[ 1402.287632] Stack:
|
||||
[ 1402.287632] ffff880077db17b0 ffff880077c4a000 ffff880077f0fdb8 ffffffff810b411e
|
||||
[ 1402.287632] ffff880000000000 ffff880077db17b0 ffff880077c4a000 ffffffff82283de0
|
||||
[ 1402.287632] 0000000001043400 ffffffff82283de0 ffff880077f0fde8 ffffffff81111f63
|
||||
[ 1402.287632] Call Trace:
|
||||
[ 1402.287632] [<ffffffff810b411e>] ? lock_release+0x1af/0x1bc
|
||||
[ 1402.287632] [<ffffffff81111f63>] ? might_fault+0x97/0x9e
|
||||
[ 1402.287632] [<ffffffff81111f1a>] ? might_fault+0x4e/0x9e
|
||||
[ 1402.287632] [<ffffffff81a8bcf2>] cache_do_downcall+0x3e/0x4f
|
||||
[ 1402.287632] [<ffffffff81a8c950>] cache_write.clone.16+0xbb/0x130
|
||||
[ 1402.287632] [<ffffffff81a8c9df>] ? cache_write_pipefs+0x1a/0x1a
|
||||
[ 1402.287632] [<ffffffff81a8c9f8>] cache_write_procfs+0x19/0x1b
|
||||
[ 1402.287632] [<ffffffff8118dc54>] proc_reg_write+0x8e/0xad
|
||||
[ 1402.287632] [<ffffffff8113fe81>] vfs_write+0xaa/0xfd
|
||||
[ 1402.287632] [<ffffffff8114142d>] ? fget_light+0x35/0x9e
|
||||
[ 1402.287632] [<ffffffff8113ff8b>] sys_write+0x48/0x6f
|
||||
[ 1402.287632] [<ffffffff81bbdb92>] system_call_fastpath+0x16/0x1b
|
||||
[ 1402.287632] Code: c0 c9 c3 55 48 63 d2 48 89 e5 48 8d 44 32 ff 41 57 41 56 41 55 41 54 53 bb ea ff ff ff 48 81 ec 88 00 00 00 48 89 b5 58 ff ff ff
|
||||
[ 1402.287632] 38 0a 0f 85 89 02 00 00 c6 00 00 48 8b 3d 44 4a e5 01 48 85
|
||||
[ 1402.287632] RIP [<ffffffff812b4b99>] expkey_parse+0x28/0x2e1
|
||||
[ 1402.287632] RSP <ffff880077f0fd68>
|
||||
[ 1402.287632] CR2: ffff880077c49fff
|
||||
[ 1402.287632] ---[ end trace 368ef53ff773a5e3 ]---
|
||||
|
||||
Cc: "J. Bruce Fields" <bfields@fieldses.org>
|
||||
Cc: Neil Brown <neilb@suse.de>
|
||||
Cc: linux-nfs@vger.kernel.org
|
||||
Signed-off-by: Sasha Levin <levinsasha928@gmail.com>
|
||||
Signed-off-by: J. Bruce Fields <bfields@redhat.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
fs/nfsd/export.c | 2 +-
|
||||
1 files changed, 1 insertions(+), 1 deletions(-)
|
||||
|
||||
diff --git a/fs/nfsd/export.c b/fs/nfsd/export.c
|
||||
index 62f3b90..5f312ab 100644
|
||||
--- a/fs/nfsd/export.c
|
||||
+++ b/fs/nfsd/export.c
|
||||
@@ -87,7 +87,7 @@ static int expkey_parse(struct cache_detail *cd, char *mesg, int mlen)
|
||||
struct svc_expkey key;
|
||||
struct svc_expkey *ek = NULL;
|
||||
|
||||
- if (mesg[mlen-1] != '\n')
|
||||
+ if (mlen < 1 || mesg[mlen-1] != '\n')
|
||||
return -EINVAL;
|
||||
mesg[mlen-1] = 0;
|
||||
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+61
@@ -0,0 +1,61 @@
|
||||
From 4af0dd80de2155ea9bdd1a691d5a902884639359 Mon Sep 17 00:00:00 2001
|
||||
From: Miklos Szeredi <mszeredi@suse.cz>
|
||||
Date: Thu, 12 Jan 2012 17:59:46 +0100
|
||||
Subject: [PATCH 071/130] fsnotify: don't BUG in fsnotify_destroy_mark()
|
||||
|
||||
commit fed474857efbed79cd390d0aee224231ca718f63 upstream.
|
||||
|
||||
Removing the parent of a watched file results in "kernel BUG at
|
||||
fs/notify/mark.c:139".
|
||||
|
||||
To reproduce
|
||||
|
||||
add "-w /tmp/audit/dir/watched_file" to audit.rules
|
||||
rm -rf /tmp/audit/dir
|
||||
|
||||
This is caused by fsnotify_destroy_mark() being called without an
|
||||
extra reference taken by the caller.
|
||||
|
||||
Reported by Francesco Cosoleto here:
|
||||
|
||||
https://bugzilla.novell.com/show_bug.cgi?id=689860
|
||||
|
||||
Fix by removing the BUG_ON and adding a comment about not accessing mark after
|
||||
the iput.
|
||||
|
||||
Signed-off-by: Miklos Szeredi <mszeredi@suse.cz>
|
||||
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
fs/notify/mark.c | 8 +++++---
|
||||
1 files changed, 5 insertions(+), 3 deletions(-)
|
||||
|
||||
diff --git a/fs/notify/mark.c b/fs/notify/mark.c
|
||||
index e14587d..f104d56 100644
|
||||
--- a/fs/notify/mark.c
|
||||
+++ b/fs/notify/mark.c
|
||||
@@ -135,9 +135,6 @@ void fsnotify_destroy_mark(struct fsnotify_mark *mark)
|
||||
|
||||
mark->flags &= ~FSNOTIFY_MARK_FLAG_ALIVE;
|
||||
|
||||
- /* 1 from caller and 1 for being on i_list/g_list */
|
||||
- BUG_ON(atomic_read(&mark->refcnt) < 2);
|
||||
-
|
||||
spin_lock(&group->mark_lock);
|
||||
|
||||
if (mark->flags & FSNOTIFY_MARK_FLAG_INODE) {
|
||||
@@ -182,6 +179,11 @@ void fsnotify_destroy_mark(struct fsnotify_mark *mark)
|
||||
iput(inode);
|
||||
|
||||
/*
|
||||
+ * We don't necessarily have a ref on mark from caller so the above iput
|
||||
+ * may have already destroyed it. Don't touch from now on.
|
||||
+ */
|
||||
+
|
||||
+ /*
|
||||
* it's possible that this group tried to destroy itself, but this
|
||||
* this mark was simultaneously being freed by inode. If that's the
|
||||
* case, we finish freeing the group here.
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+44
@@ -0,0 +1,44 @@
|
||||
From 9a2eeb78ce5b0f0d7a3a0d0917c10bd128d974d3 Mon Sep 17 00:00:00 2001
|
||||
From: Jack Steiner <steiner@sgi.com>
|
||||
Date: Fri, 6 Jan 2012 13:19:00 -0600
|
||||
Subject: [PATCH 072/130] x86, UV: Update Boot messages for SGI UV2 platform
|
||||
|
||||
commit da517a08ac5913cd80ce3507cddd00f2a091b13c upstream.
|
||||
|
||||
SGI UV systems print a message during boot:
|
||||
|
||||
UV: Found <num> blades
|
||||
|
||||
Due to packaging changes, the blade count is not accurate for
|
||||
on the next generation of the platform. This patch corrects the
|
||||
count.
|
||||
|
||||
Signed-off-by: Jack Steiner <steiner@sgi.com>
|
||||
Link: http://lkml.kernel.org/r/20120106191900.GA19772@sgi.com
|
||||
Signed-off-by: Ingo Molnar <mingo@elte.hu>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
arch/x86/kernel/apic/x2apic_uv_x.c | 7 ++++++-
|
||||
1 files changed, 6 insertions(+), 1 deletions(-)
|
||||
|
||||
diff --git a/arch/x86/kernel/apic/x2apic_uv_x.c b/arch/x86/kernel/apic/x2apic_uv_x.c
|
||||
index 9d59bba..79b05b8 100644
|
||||
--- a/arch/x86/kernel/apic/x2apic_uv_x.c
|
||||
+++ b/arch/x86/kernel/apic/x2apic_uv_x.c
|
||||
@@ -769,7 +769,12 @@ void __init uv_system_init(void)
|
||||
for(i = 0; i < UVH_NODE_PRESENT_TABLE_DEPTH; i++)
|
||||
uv_possible_blades +=
|
||||
hweight64(uv_read_local_mmr( UVH_NODE_PRESENT_TABLE + i * 8));
|
||||
- printk(KERN_DEBUG "UV: Found %d blades\n", uv_num_possible_blades());
|
||||
+
|
||||
+ /* uv_num_possible_blades() is really the hub count */
|
||||
+ printk(KERN_INFO "UV: Found %d blades, %d hubs\n",
|
||||
+ is_uv1_hub() ? uv_num_possible_blades() :
|
||||
+ (uv_num_possible_blades() + 1) / 2,
|
||||
+ uv_num_possible_blades());
|
||||
|
||||
bytes = sizeof(struct uv_blade_info) * uv_num_possible_blades();
|
||||
uv_blade_info = kzalloc(bytes, GFP_KERNEL);
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+46
@@ -0,0 +1,46 @@
|
||||
From e27a416d10935bfd79c8783a3b3ccf27e1d16230 Mon Sep 17 00:00:00 2001
|
||||
From: David Daney <david.daney@cavium.com>
|
||||
Date: Mon, 19 Dec 2011 17:42:42 -0800
|
||||
Subject: [PATCH 073/130] recordmcount: Fix handling of elf64 big-endian
|
||||
objects.
|
||||
|
||||
commit 2e885057b7f75035f0b85e02f737891482815a81 upstream.
|
||||
|
||||
In ELF64, the sh_flags field is 64-bits wide. recordmcount was
|
||||
erroneously treating it as a 32-bit wide field. For little endian
|
||||
objects this works because the flags of interest (SHF_EXECINSTR)
|
||||
reside in the lower 32 bits of the word, and you get the same result
|
||||
with either a 32-bit or 64-bit read. Big endian objects on the
|
||||
other hand do not work at all with this error.
|
||||
|
||||
The fix: Correctly treat sh_flags as 64-bits wide in elf64 objects.
|
||||
|
||||
The symptom I observed was that my
|
||||
__start_mcount_loc..__stop_mcount_loc was empty even though ftrace
|
||||
function tracing was enabled.
|
||||
|
||||
Link: http://lkml.kernel.org/r/1324345362-12230-1-git-send-email-ddaney.cavm@gmail.com
|
||||
|
||||
Signed-off-by: David Daney <david.daney@cavium.com>
|
||||
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
scripts/recordmcount.h | 2 +-
|
||||
1 files changed, 1 insertions(+), 1 deletions(-)
|
||||
|
||||
diff --git a/scripts/recordmcount.h b/scripts/recordmcount.h
|
||||
index f40a6af6..54e35c1 100644
|
||||
--- a/scripts/recordmcount.h
|
||||
+++ b/scripts/recordmcount.h
|
||||
@@ -462,7 +462,7 @@ __has_rel_mcount(Elf_Shdr const *const relhdr, /* is SHT_REL or SHT_RELA */
|
||||
succeed_file();
|
||||
}
|
||||
if (w(txthdr->sh_type) != SHT_PROGBITS ||
|
||||
- !(w(txthdr->sh_flags) & SHF_EXECINSTR))
|
||||
+ !(_w(txthdr->sh_flags) & SHF_EXECINSTR))
|
||||
return NULL;
|
||||
return txtname;
|
||||
}
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+62
@@ -0,0 +1,62 @@
|
||||
From 847db7a6053aff7d165a60f10a8cb585a950e6f9 Mon Sep 17 00:00:00 2001
|
||||
From: Haogang Chen <haogangchen@gmail.com>
|
||||
Date: Tue, 29 Nov 2011 18:32:25 -0300
|
||||
Subject: [PATCH 074/130] uvcvideo: Fix integer overflow in
|
||||
uvc_ioctl_ctrl_map()
|
||||
|
||||
commit 806e23e95f94a27ee445022d724060b9b45cb64a upstream.
|
||||
|
||||
There is a potential integer overflow in uvc_ioctl_ctrl_map(). When a
|
||||
large xmap->menu_count is passed from the userspace, the subsequent call
|
||||
to kmalloc() will allocate a buffer smaller than expected.
|
||||
map->menu_count and map->menu_info would later be used in a loop (e.g.
|
||||
in uvc_query_v4l2_ctrl), which leads to out-of-bound access.
|
||||
|
||||
The patch checks the ioctl argument and returns -EINVAL for zero or too
|
||||
large values in xmap->menu_count.
|
||||
|
||||
Signed-off-by: Haogang Chen <haogangchen@gmail.com>
|
||||
[laurent.pinchart@ideasonboard.com Prevent excessive memory consumption]
|
||||
Signed-off-by: Laurent Pinchart <laurent.pinchart@ideasonboard.com>
|
||||
Signed-off-by: Mauro Carvalho Chehab <mchehab@redhat.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/media/video/uvc/uvc_v4l2.c | 9 +++++++++
|
||||
drivers/media/video/uvc/uvcvideo.h | 1 +
|
||||
2 files changed, 10 insertions(+), 0 deletions(-)
|
||||
|
||||
diff --git a/drivers/media/video/uvc/uvc_v4l2.c b/drivers/media/video/uvc/uvc_v4l2.c
|
||||
index dadf11f..cf7788f 100644
|
||||
--- a/drivers/media/video/uvc/uvc_v4l2.c
|
||||
+++ b/drivers/media/video/uvc/uvc_v4l2.c
|
||||
@@ -58,6 +58,15 @@ static int uvc_ioctl_ctrl_map(struct uvc_video_chain *chain,
|
||||
break;
|
||||
|
||||
case V4L2_CTRL_TYPE_MENU:
|
||||
+ /* Prevent excessive memory consumption, as well as integer
|
||||
+ * overflows.
|
||||
+ */
|
||||
+ if (xmap->menu_count == 0 ||
|
||||
+ xmap->menu_count > UVC_MAX_CONTROL_MENU_ENTRIES) {
|
||||
+ ret = -EINVAL;
|
||||
+ goto done;
|
||||
+ }
|
||||
+
|
||||
size = xmap->menu_count * sizeof(*map->menu_info);
|
||||
map->menu_info = kmalloc(size, GFP_KERNEL);
|
||||
if (map->menu_info == NULL) {
|
||||
diff --git a/drivers/media/video/uvc/uvcvideo.h b/drivers/media/video/uvc/uvcvideo.h
|
||||
index 4c1392e..bc446ba 100644
|
||||
--- a/drivers/media/video/uvc/uvcvideo.h
|
||||
+++ b/drivers/media/video/uvc/uvcvideo.h
|
||||
@@ -113,6 +113,7 @@
|
||||
|
||||
/* Maximum allowed number of control mappings per device */
|
||||
#define UVC_MAX_CONTROL_MAPPINGS 1024
|
||||
+#define UVC_MAX_CONTROL_MENU_ENTRIES 32
|
||||
|
||||
/* Devices quirks */
|
||||
#define UVC_QUIRK_STATUS_INTERVAL 0x00000001
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+172
@@ -0,0 +1,172 @@
|
||||
From 48a7a2bae38f29f5b231f460dd2852e00e50d549 Mon Sep 17 00:00:00 2001
|
||||
From: Dave Chinner <david@fromorbit.com>
|
||||
Date: Tue, 23 Aug 2011 18:56:24 +1000
|
||||
Subject: [PATCH 075/130] dcache: use a dispose list in select_parent
|
||||
|
||||
commit b48f03b319ba78f3abf9a7044d1f436d8d90f4f9 upstream.
|
||||
|
||||
select_parent currently abuses the dentry cache LRU to provide
|
||||
cleanup features for child dentries that need to be freed. It moves
|
||||
them to the tail of the LRU, then tells shrink_dcache_parent() to
|
||||
calls __shrink_dcache_sb to unconditionally move them to a dispose
|
||||
list (as DCACHE_REFERENCED is ignored). __shrink_dcache_sb() has to
|
||||
relock the dentries to move them off the LRU onto the dispose list,
|
||||
but otherwise does not touch the dentries that select_parent() moved
|
||||
to the tail of the LRU. It then passses the dispose list to
|
||||
shrink_dentry_list() which tries to free the dentries.
|
||||
|
||||
IOWs, the use of __shrink_dcache_sb() is superfluous - we can build
|
||||
exactly the same list of dentries for disposal directly in
|
||||
select_parent() and call shrink_dentry_list() instead of calling
|
||||
__shrink_dcache_sb() to do that. This means that we avoid long holds
|
||||
on the lru lock walking the LRU moving dentries to the dispose list
|
||||
We also avoid the need to relock each dentry just to move it off the
|
||||
LRU, reducing the numebr of times we lock each dentry to dispose of
|
||||
them in shrink_dcache_parent() from 3 to 2 times.
|
||||
|
||||
Further, we remove one of the two callers of __shrink_dcache_sb().
|
||||
This also means that __shrink_dcache_sb can be moved into back into
|
||||
prune_dcache_sb() and we no longer have to handle referenced
|
||||
dentries conditionally, simplifying the code.
|
||||
|
||||
Signed-off-by: Dave Chinner <dchinner@redhat.com>
|
||||
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
|
||||
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
fs/dcache.c | 63 +++++++++++++++++++---------------------------------------
|
||||
1 files changed, 21 insertions(+), 42 deletions(-)
|
||||
|
||||
diff --git a/fs/dcache.c b/fs/dcache.c
|
||||
index 89509b5..108116e 100644
|
||||
--- a/fs/dcache.c
|
||||
+++ b/fs/dcache.c
|
||||
@@ -275,15 +275,15 @@ static void dentry_lru_prune(struct dentry *dentry)
|
||||
}
|
||||
}
|
||||
|
||||
-static void dentry_lru_move_tail(struct dentry *dentry)
|
||||
+static void dentry_lru_move_list(struct dentry *dentry, struct list_head *list)
|
||||
{
|
||||
spin_lock(&dcache_lru_lock);
|
||||
if (list_empty(&dentry->d_lru)) {
|
||||
- list_add_tail(&dentry->d_lru, &dentry->d_sb->s_dentry_lru);
|
||||
+ list_add_tail(&dentry->d_lru, list);
|
||||
dentry->d_sb->s_nr_dentry_unused++;
|
||||
dentry_stat.nr_unused++;
|
||||
} else {
|
||||
- list_move_tail(&dentry->d_lru, &dentry->d_sb->s_dentry_lru);
|
||||
+ list_move_tail(&dentry->d_lru, list);
|
||||
}
|
||||
spin_unlock(&dcache_lru_lock);
|
||||
}
|
||||
@@ -769,14 +769,18 @@ static void shrink_dentry_list(struct list_head *list)
|
||||
}
|
||||
|
||||
/**
|
||||
- * __shrink_dcache_sb - shrink the dentry LRU on a given superblock
|
||||
- * @sb: superblock to shrink dentry LRU.
|
||||
- * @count: number of entries to prune
|
||||
- * @flags: flags to control the dentry processing
|
||||
+ * prune_dcache_sb - shrink the dcache
|
||||
+ * @sb: superblock
|
||||
+ * @count: number of entries to try to free
|
||||
+ *
|
||||
+ * Attempt to shrink the superblock dcache LRU by @count entries. This is
|
||||
+ * done when we need more memory an called from the superblock shrinker
|
||||
+ * function.
|
||||
*
|
||||
- * If flags contains DCACHE_REFERENCED reference dentries will not be pruned.
|
||||
+ * This function may fail to free any resources if all the dentries are in
|
||||
+ * use.
|
||||
*/
|
||||
-static void __shrink_dcache_sb(struct super_block *sb, int count, int flags)
|
||||
+void prune_dcache_sb(struct super_block *sb, int count)
|
||||
{
|
||||
struct dentry *dentry;
|
||||
LIST_HEAD(referenced);
|
||||
@@ -795,13 +799,7 @@ relock:
|
||||
goto relock;
|
||||
}
|
||||
|
||||
- /*
|
||||
- * If we are honouring the DCACHE_REFERENCED flag and the
|
||||
- * dentry has this flag set, don't free it. Clear the flag
|
||||
- * and put it back on the LRU.
|
||||
- */
|
||||
- if (flags & DCACHE_REFERENCED &&
|
||||
- dentry->d_flags & DCACHE_REFERENCED) {
|
||||
+ if (dentry->d_flags & DCACHE_REFERENCED) {
|
||||
dentry->d_flags &= ~DCACHE_REFERENCED;
|
||||
list_move(&dentry->d_lru, &referenced);
|
||||
spin_unlock(&dentry->d_lock);
|
||||
@@ -821,23 +819,6 @@ relock:
|
||||
}
|
||||
|
||||
/**
|
||||
- * prune_dcache_sb - shrink the dcache
|
||||
- * @sb: superblock
|
||||
- * @nr_to_scan: number of entries to try to free
|
||||
- *
|
||||
- * Attempt to shrink the superblock dcache LRU by @nr_to_scan entries. This is
|
||||
- * done when we need more memory an called from the superblock shrinker
|
||||
- * function.
|
||||
- *
|
||||
- * This function may fail to free any resources if all the dentries are in
|
||||
- * use.
|
||||
- */
|
||||
-void prune_dcache_sb(struct super_block *sb, int nr_to_scan)
|
||||
-{
|
||||
- __shrink_dcache_sb(sb, nr_to_scan, DCACHE_REFERENCED);
|
||||
-}
|
||||
-
|
||||
-/**
|
||||
* shrink_dcache_sb - shrink dcache for a superblock
|
||||
* @sb: superblock
|
||||
*
|
||||
@@ -1091,7 +1072,7 @@ EXPORT_SYMBOL(have_submounts);
|
||||
* drop the lock and return early due to latency
|
||||
* constraints.
|
||||
*/
|
||||
-static int select_parent(struct dentry * parent)
|
||||
+static int select_parent(struct dentry *parent, struct list_head *dispose)
|
||||
{
|
||||
struct dentry *this_parent;
|
||||
struct list_head *next;
|
||||
@@ -1113,12 +1094,11 @@ resume:
|
||||
|
||||
spin_lock_nested(&dentry->d_lock, DENTRY_D_LOCK_NESTED);
|
||||
|
||||
- /*
|
||||
- * move only zero ref count dentries to the end
|
||||
- * of the unused list for prune_dcache
|
||||
+ /*
|
||||
+ * move only zero ref count dentries to the dispose list.
|
||||
*/
|
||||
if (!dentry->d_count) {
|
||||
- dentry_lru_move_tail(dentry);
|
||||
+ dentry_lru_move_list(dentry, dispose);
|
||||
found++;
|
||||
} else {
|
||||
dentry_lru_del(dentry);
|
||||
@@ -1180,14 +1160,13 @@ rename_retry:
|
||||
*
|
||||
* Prune the dcache to remove unused children of the parent dentry.
|
||||
*/
|
||||
-
|
||||
void shrink_dcache_parent(struct dentry * parent)
|
||||
{
|
||||
- struct super_block *sb = parent->d_sb;
|
||||
+ LIST_HEAD(dispose);
|
||||
int found;
|
||||
|
||||
- while ((found = select_parent(parent)) != 0)
|
||||
- __shrink_dcache_sb(sb, found, 0);
|
||||
+ while ((found = select_parent(parent, &dispose)) != 0)
|
||||
+ shrink_dentry_list(&dispose);
|
||||
}
|
||||
EXPORT_SYMBOL(shrink_dcache_parent);
|
||||
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+130
@@ -0,0 +1,130 @@
|
||||
From 26c9f57c6ada2518c265d0a52b29a26be7bcb746 Mon Sep 17 00:00:00 2001
|
||||
From: Miklos Szeredi <miklos@szeredi.hu>
|
||||
Date: Tue, 10 Jan 2012 18:22:25 +0100
|
||||
Subject: [PATCH 076/130] fix shrink_dcache_parent() livelock
|
||||
|
||||
commit eaf5f9073533cde21c7121c136f1c3f072d9cf59 upstream.
|
||||
|
||||
Two (or more) concurrent calls of shrink_dcache_parent() on the same dentry may
|
||||
cause shrink_dcache_parent() to loop forever.
|
||||
|
||||
Here's what appears to happen:
|
||||
|
||||
1 - CPU0: select_parent(P) finds C and puts it on dispose list, returns 1
|
||||
|
||||
2 - CPU1: select_parent(P) locks P->d_lock
|
||||
|
||||
3 - CPU0: shrink_dentry_list() locks C->d_lock
|
||||
dentry_kill(C) tries to lock P->d_lock but fails, unlocks C->d_lock
|
||||
|
||||
4 - CPU1: select_parent(P) locks C->d_lock,
|
||||
moves C from dispose list being processed on CPU0 to the new
|
||||
dispose list, returns 1
|
||||
|
||||
5 - CPU0: shrink_dentry_list() finds dispose list empty, returns
|
||||
|
||||
6 - Goto 2 with CPU0 and CPU1 switched
|
||||
|
||||
Basically select_parent() steals the dentry from shrink_dentry_list() and thinks
|
||||
it found a new one, causing shrink_dentry_list() to think it's making progress
|
||||
and loop over and over.
|
||||
|
||||
One way to trigger this is to make udev calls stat() on the sysfs file while it
|
||||
is going away.
|
||||
|
||||
Having a file in /lib/udev/rules.d/ with only this one rule seems to the trick:
|
||||
|
||||
ATTR{vendor}=="0x8086", ATTR{device}=="0x10ca", ENV{PCI_SLOT_NAME}="%k", ENV{MATCHADDR}="$attr{address}", RUN+="/bin/true"
|
||||
|
||||
Then execute the following loop:
|
||||
|
||||
while true; do
|
||||
echo -bond0 > /sys/class/net/bonding_masters
|
||||
echo +bond0 > /sys/class/net/bonding_masters
|
||||
echo -bond1 > /sys/class/net/bonding_masters
|
||||
echo +bond1 > /sys/class/net/bonding_masters
|
||||
done
|
||||
|
||||
One fix would be to check all callers and prevent concurrent calls to
|
||||
shrink_dcache_parent(). But I think a better solution is to stop the
|
||||
stealing behavior.
|
||||
|
||||
This patch adds a new dentry flag that is set when the dentry is added to the
|
||||
dispose list. The flag is cleared in dentry_lru_del() in case the dentry gets a
|
||||
new reference just before being pruned.
|
||||
|
||||
If the dentry has this flag, select_parent() will skip it and let
|
||||
shrink_dentry_list() retry pruning it. With select_parent() skipping those
|
||||
dentries there will not be the appearance of progress (new dentries found) when
|
||||
there is none, hence shrink_dcache_parent() will not loop forever.
|
||||
|
||||
Set the flag is also set in prune_dcache_sb() for consistency as suggested by
|
||||
Linus.
|
||||
|
||||
Signed-off-by: Miklos Szeredi <mszeredi@suse.cz>
|
||||
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
fs/dcache.c | 15 +++++++++++----
|
||||
include/linux/dcache.h | 1 +
|
||||
2 files changed, 12 insertions(+), 4 deletions(-)
|
||||
|
||||
diff --git a/fs/dcache.c b/fs/dcache.c
|
||||
index 108116e..f7908ae 100644
|
||||
--- a/fs/dcache.c
|
||||
+++ b/fs/dcache.c
|
||||
@@ -242,6 +242,7 @@ static void dentry_lru_add(struct dentry *dentry)
|
||||
static void __dentry_lru_del(struct dentry *dentry)
|
||||
{
|
||||
list_del_init(&dentry->d_lru);
|
||||
+ dentry->d_flags &= ~DCACHE_SHRINK_LIST;
|
||||
dentry->d_sb->s_nr_dentry_unused--;
|
||||
dentry_stat.nr_unused--;
|
||||
}
|
||||
@@ -805,6 +806,7 @@ relock:
|
||||
spin_unlock(&dentry->d_lock);
|
||||
} else {
|
||||
list_move_tail(&dentry->d_lru, &tmp);
|
||||
+ dentry->d_flags |= DCACHE_SHRINK_LIST;
|
||||
spin_unlock(&dentry->d_lock);
|
||||
if (!--count)
|
||||
break;
|
||||
@@ -1096,14 +1098,19 @@ resume:
|
||||
|
||||
/*
|
||||
* move only zero ref count dentries to the dispose list.
|
||||
+ *
|
||||
+ * Those which are presently on the shrink list, being processed
|
||||
+ * by shrink_dentry_list(), shouldn't be moved. Otherwise the
|
||||
+ * loop in shrink_dcache_parent() might not make any progress
|
||||
+ * and loop forever.
|
||||
*/
|
||||
- if (!dentry->d_count) {
|
||||
+ if (dentry->d_count) {
|
||||
+ dentry_lru_del(dentry);
|
||||
+ } else if (!(dentry->d_flags & DCACHE_SHRINK_LIST)) {
|
||||
dentry_lru_move_list(dentry, dispose);
|
||||
+ dentry->d_flags |= DCACHE_SHRINK_LIST;
|
||||
found++;
|
||||
- } else {
|
||||
- dentry_lru_del(dentry);
|
||||
}
|
||||
-
|
||||
/*
|
||||
* We can return to the caller if we have found some (this
|
||||
* ensures forward progress). We'll be coming back to find
|
||||
diff --git a/include/linux/dcache.h b/include/linux/dcache.h
|
||||
index ed9f74f..4eb8c80 100644
|
||||
--- a/include/linux/dcache.h
|
||||
+++ b/include/linux/dcache.h
|
||||
@@ -203,6 +203,7 @@ struct dentry_operations {
|
||||
|
||||
#define DCACHE_CANT_MOUNT 0x0100
|
||||
#define DCACHE_GENOCIDE 0x0200
|
||||
+#define DCACHE_SHRINK_LIST 0x0400
|
||||
|
||||
#define DCACHE_NFSFS_RENAMED 0x1000
|
||||
/* this dentry has been "silly renamed" and has to be deleted on the last
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+64
@@ -0,0 +1,64 @@
|
||||
From 6feb42647758cf08e5707c9f6a2f0d78d6fb3cc8 Mon Sep 17 00:00:00 2001
|
||||
From: Peng Tao <bergwolf@gmail.com>
|
||||
Date: Thu, 12 Jan 2012 23:18:41 +0800
|
||||
Subject: [PATCH 077/130] pnfsblock: acquire im_lock in _preload_range
|
||||
|
||||
commit 39e567ae36fe03c2b446e1b83ee3d39bea08f90b upstream.
|
||||
|
||||
When calling _add_entry, we should take the im_lock to protect
|
||||
agains other modifiers.
|
||||
|
||||
Signed-off-by: Peng Tao <peng_tao@emc.com>
|
||||
Signed-off-by: Benny Halevy <bhalevy@tonian.com>
|
||||
Signed-off-by: Trond Myklebust <Trond.Myklebust@netapp.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
fs/nfs/blocklayout/extents.c | 11 ++++++-----
|
||||
1 files changed, 6 insertions(+), 5 deletions(-)
|
||||
|
||||
diff --git a/fs/nfs/blocklayout/extents.c b/fs/nfs/blocklayout/extents.c
|
||||
index 19fa7b0..c69682a 100644
|
||||
--- a/fs/nfs/blocklayout/extents.c
|
||||
+++ b/fs/nfs/blocklayout/extents.c
|
||||
@@ -139,11 +139,13 @@ static int _set_range(struct my_tree *tree, int32_t tag, u64 s, u64 length)
|
||||
}
|
||||
|
||||
/* Ensure that future operations on given range of tree will not malloc */
|
||||
-static int _preload_range(struct my_tree *tree, u64 offset, u64 length)
|
||||
+static int _preload_range(struct pnfs_inval_markings *marks,
|
||||
+ u64 offset, u64 length)
|
||||
{
|
||||
u64 start, end, s;
|
||||
int count, i, used = 0, status = -ENOMEM;
|
||||
struct pnfs_inval_tracking **storage;
|
||||
+ struct my_tree *tree = &marks->im_tree;
|
||||
|
||||
dprintk("%s(%llu, %llu) enter\n", __func__, offset, length);
|
||||
start = normalize(offset, tree->mtt_step_size);
|
||||
@@ -161,12 +163,11 @@ static int _preload_range(struct my_tree *tree, u64 offset, u64 length)
|
||||
goto out_cleanup;
|
||||
}
|
||||
|
||||
- /* Now need lock - HOW??? */
|
||||
-
|
||||
+ spin_lock(&marks->im_lock);
|
||||
for (s = start; s < end; s += tree->mtt_step_size)
|
||||
used += _add_entry(tree, s, INTERNAL_EXISTS, storage[used]);
|
||||
+ spin_unlock(&marks->im_lock);
|
||||
|
||||
- /* Unlock - HOW??? */
|
||||
status = 0;
|
||||
|
||||
out_cleanup:
|
||||
@@ -286,7 +287,7 @@ int bl_mark_sectors_init(struct pnfs_inval_markings *marks,
|
||||
|
||||
start = normalize(offset, marks->im_block_size);
|
||||
end = normalize_up(offset + length, marks->im_block_size);
|
||||
- if (_preload_range(&marks->im_tree, start, end - start))
|
||||
+ if (_preload_range(marks, start, end - start))
|
||||
goto outerr;
|
||||
|
||||
spin_lock(&marks->im_lock);
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+46
@@ -0,0 +1,46 @@
|
||||
From b6fd682adf525b6766b8e16b39e39412153d19da Mon Sep 17 00:00:00 2001
|
||||
From: Peng Tao <bergwolf@gmail.com>
|
||||
Date: Thu, 12 Jan 2012 23:18:47 +0800
|
||||
Subject: [PATCH 078/130] pnfsblock: don't spinlock when freeing block_dev
|
||||
|
||||
commit 93a3844ee0f843b05a1df4b52e1a19ff26b98d24 upstream.
|
||||
|
||||
bl_free_block_dev() may sleep. We can not call it with spinlock held.
|
||||
Besides, there is no need to take bm_lock as we are last user freeing bm_devlist.
|
||||
|
||||
Signed-off-by: Peng Tao <peng_tao@emc.com>
|
||||
Signed-off-by: Benny Halevy <bhalevy@tonian.com>
|
||||
Signed-off-by: Trond Myklebust <Trond.Myklebust@netapp.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
fs/nfs/blocklayout/blocklayout.c | 11 ++++-------
|
||||
1 files changed, 4 insertions(+), 7 deletions(-)
|
||||
|
||||
diff --git a/fs/nfs/blocklayout/blocklayout.c b/fs/nfs/blocklayout/blocklayout.c
|
||||
index 281ae95..ce8129d 100644
|
||||
--- a/fs/nfs/blocklayout/blocklayout.c
|
||||
+++ b/fs/nfs/blocklayout/blocklayout.c
|
||||
@@ -779,16 +779,13 @@ bl_cleanup_layoutcommit(struct nfs4_layoutcommit_data *lcdata)
|
||||
static void free_blk_mountid(struct block_mount_id *mid)
|
||||
{
|
||||
if (mid) {
|
||||
- struct pnfs_block_dev *dev;
|
||||
- spin_lock(&mid->bm_lock);
|
||||
- while (!list_empty(&mid->bm_devlist)) {
|
||||
- dev = list_first_entry(&mid->bm_devlist,
|
||||
- struct pnfs_block_dev,
|
||||
- bm_node);
|
||||
+ struct pnfs_block_dev *dev, *tmp;
|
||||
+
|
||||
+ /* No need to take bm_lock as we are last user freeing bm_devlist */
|
||||
+ list_for_each_entry_safe(dev, tmp, &mid->bm_devlist, bm_node) {
|
||||
list_del(&dev->bm_node);
|
||||
bl_free_block_dev(dev);
|
||||
}
|
||||
- spin_unlock(&mid->bm_lock);
|
||||
kfree(mid);
|
||||
}
|
||||
}
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+51
@@ -0,0 +1,51 @@
|
||||
From 4ebc5f6665b0d03c9488fafb7ac6f8bd2f104d70 Mon Sep 17 00:00:00 2001
|
||||
From: Peng Tao <bergwolf@gmail.com>
|
||||
Date: Thu, 12 Jan 2012 23:18:48 +0800
|
||||
Subject: [PATCH 079/130] pnfsblock: limit bio page count
|
||||
|
||||
commit 74a6eeb44ca6174d9cc93b9b8b4d58211c57bc80 upstream.
|
||||
|
||||
One bio can have at most BIO_MAX_PAGES pages. We should limit it bec otherwise
|
||||
bio_alloc will fail when there are many pages in one read/write_pagelist.
|
||||
|
||||
Signed-off-by: Peng Tao <peng_tao@emc.com>
|
||||
Signed-off-by: Benny Halevy <bhalevy@tonian.com>
|
||||
Signed-off-by: Trond Myklebust <Trond.Myklebust@netapp.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
fs/nfs/blocklayout/blocklayout.c | 17 +++++++++++------
|
||||
1 files changed, 11 insertions(+), 6 deletions(-)
|
||||
|
||||
diff --git a/fs/nfs/blocklayout/blocklayout.c b/fs/nfs/blocklayout/blocklayout.c
|
||||
index ce8129d..3db6b82 100644
|
||||
--- a/fs/nfs/blocklayout/blocklayout.c
|
||||
+++ b/fs/nfs/blocklayout/blocklayout.c
|
||||
@@ -146,14 +146,19 @@ static struct bio *bl_alloc_init_bio(int npg, sector_t isect,
|
||||
{
|
||||
struct bio *bio;
|
||||
|
||||
+ npg = min(npg, BIO_MAX_PAGES);
|
||||
bio = bio_alloc(GFP_NOIO, npg);
|
||||
- if (!bio)
|
||||
- return NULL;
|
||||
+ if (!bio && (current->flags & PF_MEMALLOC)) {
|
||||
+ while (!bio && (npg /= 2))
|
||||
+ bio = bio_alloc(GFP_NOIO, npg);
|
||||
+ }
|
||||
|
||||
- bio->bi_sector = isect - be->be_f_offset + be->be_v_offset;
|
||||
- bio->bi_bdev = be->be_mdev;
|
||||
- bio->bi_end_io = end_io;
|
||||
- bio->bi_private = par;
|
||||
+ if (bio) {
|
||||
+ bio->bi_sector = isect - be->be_f_offset + be->be_v_offset;
|
||||
+ bio->bi_bdev = be->be_mdev;
|
||||
+ bio->bi_end_io = end_io;
|
||||
+ bio->bi_private = par;
|
||||
+ }
|
||||
return bio;
|
||||
}
|
||||
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+635
@@ -0,0 +1,635 @@
|
||||
From 5b8206fb91b97732d80ada2e494e060d50ab30bd Mon Sep 17 00:00:00 2001
|
||||
From: Johannes Berg <johannes.berg@intel.com>
|
||||
Date: Tue, 29 Nov 2011 10:20:02 +0100
|
||||
Subject: [PATCH 080/130] mac80211: revert on-channel work optimisations
|
||||
|
||||
commit e76aadc572288a158ae18ae1c10fe395c7bca066 upstream.
|
||||
|
||||
Backport note:
|
||||
This patch it's a full revert of commit b23b025f "mac80211: Optimize
|
||||
scans on current operating channel.". On upstrem revert e76aadc5 we
|
||||
keep some bits from that commit, which are needed for upstream version
|
||||
of mac80211.
|
||||
|
||||
The on-channel work optimisations have caused a
|
||||
number of issues, and the code is unfortunately
|
||||
very complex and almost impossible to follow.
|
||||
Instead of attempting to put in more workarounds
|
||||
let's just remove those optimisations, we can
|
||||
work on them again later, after we change the
|
||||
whole auth/assoc design.
|
||||
|
||||
This should fix rate_control_send_low() warnings,
|
||||
see RH bug 731365.
|
||||
|
||||
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
|
||||
Signed-off-by: John W. Linville <linville@tuxdriver.com>
|
||||
Signed-off-by: Stanislaw Gruszka <sgruszka@redhat.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
net/mac80211/ieee80211_i.h | 13 +++----
|
||||
net/mac80211/main.c | 58 +++-----------------------------
|
||||
net/mac80211/offchannel.c | 68 +++++++++++++++++---------------------
|
||||
net/mac80211/rx.c | 10 ++++-
|
||||
net/mac80211/scan.c | 77 ++++++++++++-------------------------------
|
||||
net/mac80211/tx.c | 3 +-
|
||||
net/mac80211/work.c | 77 ++++++-------------------------------------
|
||||
7 files changed, 85 insertions(+), 221 deletions(-)
|
||||
|
||||
diff --git a/net/mac80211/ieee80211_i.h b/net/mac80211/ieee80211_i.h
|
||||
index ea10a51..73495f1 100644
|
||||
--- a/net/mac80211/ieee80211_i.h
|
||||
+++ b/net/mac80211/ieee80211_i.h
|
||||
@@ -702,6 +702,8 @@ struct tpt_led_trigger {
|
||||
* well be on the operating channel
|
||||
* @SCAN_HW_SCANNING: The hardware is scanning for us, we have no way to
|
||||
* determine if we are on the operating channel or not
|
||||
+ * @SCAN_OFF_CHANNEL: We're off our operating channel for scanning,
|
||||
+ * gets only set in conjunction with SCAN_SW_SCANNING
|
||||
* @SCAN_COMPLETED: Set for our scan work function when the driver reported
|
||||
* that the scan completed.
|
||||
* @SCAN_ABORTED: Set for our scan work function when the driver reported
|
||||
@@ -710,6 +712,7 @@ struct tpt_led_trigger {
|
||||
enum {
|
||||
SCAN_SW_SCANNING,
|
||||
SCAN_HW_SCANNING,
|
||||
+ SCAN_OFF_CHANNEL,
|
||||
SCAN_COMPLETED,
|
||||
SCAN_ABORTED,
|
||||
};
|
||||
@@ -1140,14 +1143,10 @@ int ieee80211_request_sched_scan_stop(struct ieee80211_sub_if_data *sdata);
|
||||
void ieee80211_sched_scan_stopped_work(struct work_struct *work);
|
||||
|
||||
/* off-channel helpers */
|
||||
-bool ieee80211_cfg_on_oper_channel(struct ieee80211_local *local);
|
||||
-void ieee80211_offchannel_enable_all_ps(struct ieee80211_local *local,
|
||||
- bool tell_ap);
|
||||
-void ieee80211_offchannel_stop_vifs(struct ieee80211_local *local,
|
||||
- bool offchannel_ps_enable);
|
||||
+void ieee80211_offchannel_stop_beaconing(struct ieee80211_local *local);
|
||||
+void ieee80211_offchannel_stop_station(struct ieee80211_local *local);
|
||||
void ieee80211_offchannel_return(struct ieee80211_local *local,
|
||||
- bool enable_beaconing,
|
||||
- bool offchannel_ps_disable);
|
||||
+ bool enable_beaconing);
|
||||
void ieee80211_hw_roc_setup(struct ieee80211_local *local);
|
||||
|
||||
/* interface handling */
|
||||
diff --git a/net/mac80211/main.c b/net/mac80211/main.c
|
||||
index cae4435..a7536fd 100644
|
||||
--- a/net/mac80211/main.c
|
||||
+++ b/net/mac80211/main.c
|
||||
@@ -92,47 +92,6 @@ static void ieee80211_reconfig_filter(struct work_struct *work)
|
||||
ieee80211_configure_filter(local);
|
||||
}
|
||||
|
||||
-/*
|
||||
- * Returns true if we are logically configured to be on
|
||||
- * the operating channel AND the hardware-conf is currently
|
||||
- * configured on the operating channel. Compares channel-type
|
||||
- * as well.
|
||||
- */
|
||||
-bool ieee80211_cfg_on_oper_channel(struct ieee80211_local *local)
|
||||
-{
|
||||
- struct ieee80211_channel *chan, *scan_chan;
|
||||
- enum nl80211_channel_type channel_type;
|
||||
-
|
||||
- /* This logic needs to match logic in ieee80211_hw_config */
|
||||
- if (local->scan_channel) {
|
||||
- chan = local->scan_channel;
|
||||
- /* If scanning on oper channel, use whatever channel-type
|
||||
- * is currently in use.
|
||||
- */
|
||||
- if (chan == local->oper_channel)
|
||||
- channel_type = local->_oper_channel_type;
|
||||
- else
|
||||
- channel_type = NL80211_CHAN_NO_HT;
|
||||
- } else if (local->tmp_channel) {
|
||||
- chan = scan_chan = local->tmp_channel;
|
||||
- channel_type = local->tmp_channel_type;
|
||||
- } else {
|
||||
- chan = local->oper_channel;
|
||||
- channel_type = local->_oper_channel_type;
|
||||
- }
|
||||
-
|
||||
- if (chan != local->oper_channel ||
|
||||
- channel_type != local->_oper_channel_type)
|
||||
- return false;
|
||||
-
|
||||
- /* Check current hardware-config against oper_channel. */
|
||||
- if ((local->oper_channel != local->hw.conf.channel) ||
|
||||
- (local->_oper_channel_type != local->hw.conf.channel_type))
|
||||
- return false;
|
||||
-
|
||||
- return true;
|
||||
-}
|
||||
-
|
||||
int ieee80211_hw_config(struct ieee80211_local *local, u32 changed)
|
||||
{
|
||||
struct ieee80211_channel *chan, *scan_chan;
|
||||
@@ -145,9 +104,6 @@ int ieee80211_hw_config(struct ieee80211_local *local, u32 changed)
|
||||
|
||||
scan_chan = local->scan_channel;
|
||||
|
||||
- /* If this off-channel logic ever changes, ieee80211_on_oper_channel
|
||||
- * may need to change as well.
|
||||
- */
|
||||
offchannel_flag = local->hw.conf.flags & IEEE80211_CONF_OFFCHANNEL;
|
||||
if (scan_chan) {
|
||||
chan = scan_chan;
|
||||
@@ -158,19 +114,17 @@ int ieee80211_hw_config(struct ieee80211_local *local, u32 changed)
|
||||
channel_type = local->_oper_channel_type;
|
||||
else
|
||||
channel_type = NL80211_CHAN_NO_HT;
|
||||
- } else if (local->tmp_channel) {
|
||||
+ local->hw.conf.flags |= IEEE80211_CONF_OFFCHANNEL;
|
||||
+ } else if (local->tmp_channel &&
|
||||
+ local->oper_channel != local->tmp_channel) {
|
||||
chan = scan_chan = local->tmp_channel;
|
||||
channel_type = local->tmp_channel_type;
|
||||
+ local->hw.conf.flags |= IEEE80211_CONF_OFFCHANNEL;
|
||||
} else {
|
||||
chan = local->oper_channel;
|
||||
channel_type = local->_oper_channel_type;
|
||||
- }
|
||||
-
|
||||
- if (chan != local->oper_channel ||
|
||||
- channel_type != local->_oper_channel_type)
|
||||
- local->hw.conf.flags |= IEEE80211_CONF_OFFCHANNEL;
|
||||
- else
|
||||
local->hw.conf.flags &= ~IEEE80211_CONF_OFFCHANNEL;
|
||||
+ }
|
||||
|
||||
offchannel_flag ^= local->hw.conf.flags & IEEE80211_CONF_OFFCHANNEL;
|
||||
|
||||
@@ -279,7 +233,7 @@ void ieee80211_bss_info_change_notify(struct ieee80211_sub_if_data *sdata,
|
||||
|
||||
if (changed & BSS_CHANGED_BEACON_ENABLED) {
|
||||
if (local->quiescing || !ieee80211_sdata_running(sdata) ||
|
||||
- test_bit(SDATA_STATE_OFFCHANNEL, &sdata->state)) {
|
||||
+ test_bit(SCAN_SW_SCANNING, &local->scanning)) {
|
||||
sdata->vif.bss_conf.enable_beacon = false;
|
||||
} else {
|
||||
/*
|
||||
diff --git a/net/mac80211/offchannel.c b/net/mac80211/offchannel.c
|
||||
index 3d41441..1b239be 100644
|
||||
--- a/net/mac80211/offchannel.c
|
||||
+++ b/net/mac80211/offchannel.c
|
||||
@@ -18,14 +18,10 @@
|
||||
#include "driver-trace.h"
|
||||
|
||||
/*
|
||||
- * Tell our hardware to disable PS.
|
||||
- * Optionally inform AP that we will go to sleep so that it will buffer
|
||||
- * the frames while we are doing off-channel work. This is optional
|
||||
- * because we *may* be doing work on-operating channel, and want our
|
||||
- * hardware unconditionally awake, but still let the AP send us normal frames.
|
||||
+ * inform AP that we will go to sleep so that it will buffer the frames
|
||||
+ * while we scan
|
||||
*/
|
||||
-static void ieee80211_offchannel_ps_enable(struct ieee80211_sub_if_data *sdata,
|
||||
- bool tell_ap)
|
||||
+static void ieee80211_offchannel_ps_enable(struct ieee80211_sub_if_data *sdata)
|
||||
{
|
||||
struct ieee80211_local *local = sdata->local;
|
||||
struct ieee80211_if_managed *ifmgd = &sdata->u.mgd;
|
||||
@@ -46,8 +42,8 @@ static void ieee80211_offchannel_ps_enable(struct ieee80211_sub_if_data *sdata,
|
||||
ieee80211_hw_config(local, IEEE80211_CONF_CHANGE_PS);
|
||||
}
|
||||
|
||||
- if (tell_ap && (!local->offchannel_ps_enabled ||
|
||||
- !(local->hw.flags & IEEE80211_HW_PS_NULLFUNC_STACK)))
|
||||
+ if (!(local->offchannel_ps_enabled) ||
|
||||
+ !(local->hw.flags & IEEE80211_HW_PS_NULLFUNC_STACK))
|
||||
/*
|
||||
* If power save was enabled, no need to send a nullfunc
|
||||
* frame because AP knows that we are sleeping. But if the
|
||||
@@ -82,9 +78,6 @@ static void ieee80211_offchannel_ps_disable(struct ieee80211_sub_if_data *sdata)
|
||||
* we are sleeping, let's just enable power save mode in
|
||||
* hardware.
|
||||
*/
|
||||
- /* TODO: Only set hardware if CONF_PS changed?
|
||||
- * TODO: Should we set offchannel_ps_enabled to false?
|
||||
- */
|
||||
local->hw.conf.flags |= IEEE80211_CONF_PS;
|
||||
ieee80211_hw_config(local, IEEE80211_CONF_CHANGE_PS);
|
||||
} else if (local->hw.conf.dynamic_ps_timeout > 0) {
|
||||
@@ -103,61 +96,63 @@ static void ieee80211_offchannel_ps_disable(struct ieee80211_sub_if_data *sdata)
|
||||
ieee80211_sta_reset_conn_monitor(sdata);
|
||||
}
|
||||
|
||||
-void ieee80211_offchannel_stop_vifs(struct ieee80211_local *local,
|
||||
- bool offchannel_ps_enable)
|
||||
+void ieee80211_offchannel_stop_beaconing(struct ieee80211_local *local)
|
||||
{
|
||||
struct ieee80211_sub_if_data *sdata;
|
||||
|
||||
- /*
|
||||
- * notify the AP about us leaving the channel and stop all
|
||||
- * STA interfaces.
|
||||
- */
|
||||
mutex_lock(&local->iflist_mtx);
|
||||
list_for_each_entry(sdata, &local->interfaces, list) {
|
||||
if (!ieee80211_sdata_running(sdata))
|
||||
continue;
|
||||
|
||||
- if (sdata->vif.type != NL80211_IFTYPE_MONITOR)
|
||||
- set_bit(SDATA_STATE_OFFCHANNEL, &sdata->state);
|
||||
-
|
||||
- /* Check to see if we should disable beaconing. */
|
||||
+ /* disable beaconing */
|
||||
if (sdata->vif.type == NL80211_IFTYPE_AP ||
|
||||
sdata->vif.type == NL80211_IFTYPE_ADHOC ||
|
||||
sdata->vif.type == NL80211_IFTYPE_MESH_POINT)
|
||||
ieee80211_bss_info_change_notify(
|
||||
sdata, BSS_CHANGED_BEACON_ENABLED);
|
||||
|
||||
- if (sdata->vif.type != NL80211_IFTYPE_MONITOR) {
|
||||
+ /*
|
||||
+ * only handle non-STA interfaces here, STA interfaces
|
||||
+ * are handled in ieee80211_offchannel_stop_station(),
|
||||
+ * e.g., from the background scan state machine.
|
||||
+ *
|
||||
+ * In addition, do not stop monitor interface to allow it to be
|
||||
+ * used from user space controlled off-channel operations.
|
||||
+ */
|
||||
+ if (sdata->vif.type != NL80211_IFTYPE_STATION &&
|
||||
+ sdata->vif.type != NL80211_IFTYPE_MONITOR) {
|
||||
+ set_bit(SDATA_STATE_OFFCHANNEL, &sdata->state);
|
||||
netif_tx_stop_all_queues(sdata->dev);
|
||||
- if (offchannel_ps_enable &&
|
||||
- (sdata->vif.type == NL80211_IFTYPE_STATION) &&
|
||||
- sdata->u.mgd.associated)
|
||||
- ieee80211_offchannel_ps_enable(sdata, true);
|
||||
}
|
||||
}
|
||||
mutex_unlock(&local->iflist_mtx);
|
||||
}
|
||||
|
||||
-void ieee80211_offchannel_enable_all_ps(struct ieee80211_local *local,
|
||||
- bool tell_ap)
|
||||
+void ieee80211_offchannel_stop_station(struct ieee80211_local *local)
|
||||
{
|
||||
struct ieee80211_sub_if_data *sdata;
|
||||
|
||||
+ /*
|
||||
+ * notify the AP about us leaving the channel and stop all STA interfaces
|
||||
+ */
|
||||
mutex_lock(&local->iflist_mtx);
|
||||
list_for_each_entry(sdata, &local->interfaces, list) {
|
||||
if (!ieee80211_sdata_running(sdata))
|
||||
continue;
|
||||
|
||||
- if (sdata->vif.type == NL80211_IFTYPE_STATION &&
|
||||
- sdata->u.mgd.associated)
|
||||
- ieee80211_offchannel_ps_enable(sdata, tell_ap);
|
||||
+ if (sdata->vif.type == NL80211_IFTYPE_STATION) {
|
||||
+ set_bit(SDATA_STATE_OFFCHANNEL, &sdata->state);
|
||||
+ netif_tx_stop_all_queues(sdata->dev);
|
||||
+ if (sdata->u.mgd.associated)
|
||||
+ ieee80211_offchannel_ps_enable(sdata);
|
||||
+ }
|
||||
}
|
||||
mutex_unlock(&local->iflist_mtx);
|
||||
}
|
||||
|
||||
void ieee80211_offchannel_return(struct ieee80211_local *local,
|
||||
- bool enable_beaconing,
|
||||
- bool offchannel_ps_disable)
|
||||
+ bool enable_beaconing)
|
||||
{
|
||||
struct ieee80211_sub_if_data *sdata;
|
||||
|
||||
@@ -167,8 +162,7 @@ void ieee80211_offchannel_return(struct ieee80211_local *local,
|
||||
continue;
|
||||
|
||||
/* Tell AP we're back */
|
||||
- if (offchannel_ps_disable &&
|
||||
- sdata->vif.type == NL80211_IFTYPE_STATION) {
|
||||
+ if (sdata->vif.type == NL80211_IFTYPE_STATION) {
|
||||
if (sdata->u.mgd.associated)
|
||||
ieee80211_offchannel_ps_disable(sdata);
|
||||
}
|
||||
@@ -188,7 +182,7 @@ void ieee80211_offchannel_return(struct ieee80211_local *local,
|
||||
netif_tx_wake_all_queues(sdata->dev);
|
||||
}
|
||||
|
||||
- /* Check to see if we should re-enable beaconing */
|
||||
+ /* re-enable beaconing */
|
||||
if (enable_beaconing &&
|
||||
(sdata->vif.type == NL80211_IFTYPE_AP ||
|
||||
sdata->vif.type == NL80211_IFTYPE_ADHOC ||
|
||||
diff --git a/net/mac80211/rx.c b/net/mac80211/rx.c
|
||||
index fb123e2..5c51607 100644
|
||||
--- a/net/mac80211/rx.c
|
||||
+++ b/net/mac80211/rx.c
|
||||
@@ -421,10 +421,16 @@ ieee80211_rx_h_passive_scan(struct ieee80211_rx_data *rx)
|
||||
return RX_CONTINUE;
|
||||
|
||||
if (test_bit(SCAN_HW_SCANNING, &local->scanning) ||
|
||||
- test_bit(SCAN_SW_SCANNING, &local->scanning) ||
|
||||
local->sched_scanning)
|
||||
return ieee80211_scan_rx(rx->sdata, skb);
|
||||
|
||||
+ if (test_bit(SCAN_SW_SCANNING, &local->scanning)) {
|
||||
+ /* drop all the other packets during a software scan anyway */
|
||||
+ if (ieee80211_scan_rx(rx->sdata, skb) != RX_QUEUED)
|
||||
+ dev_kfree_skb(skb);
|
||||
+ return RX_QUEUED;
|
||||
+ }
|
||||
+
|
||||
/* scanning finished during invoking of handlers */
|
||||
I802_DEBUG_INC(local->rx_handlers_drop_passive_scan);
|
||||
return RX_DROP_UNUSABLE;
|
||||
@@ -2858,7 +2864,7 @@ static void __ieee80211_rx_handle_packet(struct ieee80211_hw *hw,
|
||||
local->dot11ReceivedFragmentCount++;
|
||||
|
||||
if (unlikely(test_bit(SCAN_HW_SCANNING, &local->scanning) ||
|
||||
- test_bit(SCAN_SW_SCANNING, &local->scanning)))
|
||||
+ test_bit(SCAN_OFF_CHANNEL, &local->scanning)))
|
||||
status->rx_flags |= IEEE80211_RX_IN_SCAN;
|
||||
|
||||
if (ieee80211_is_mgmt(fc))
|
||||
diff --git a/net/mac80211/scan.c b/net/mac80211/scan.c
|
||||
index 105436d..5279300 100644
|
||||
--- a/net/mac80211/scan.c
|
||||
+++ b/net/mac80211/scan.c
|
||||
@@ -213,14 +213,6 @@ ieee80211_scan_rx(struct ieee80211_sub_if_data *sdata, struct sk_buff *skb)
|
||||
if (bss)
|
||||
ieee80211_rx_bss_put(sdata->local, bss);
|
||||
|
||||
- /* If we are on-operating-channel, and this packet is for the
|
||||
- * current channel, pass the pkt on up the stack so that
|
||||
- * the rest of the stack can make use of it.
|
||||
- */
|
||||
- if (ieee80211_cfg_on_oper_channel(sdata->local)
|
||||
- && (channel == sdata->local->oper_channel))
|
||||
- return RX_CONTINUE;
|
||||
-
|
||||
dev_kfree_skb(skb);
|
||||
return RX_QUEUED;
|
||||
}
|
||||
@@ -264,8 +256,6 @@ static void __ieee80211_scan_completed(struct ieee80211_hw *hw, bool aborted,
|
||||
bool was_hw_scan)
|
||||
{
|
||||
struct ieee80211_local *local = hw_to_local(hw);
|
||||
- bool on_oper_chan;
|
||||
- bool enable_beacons = false;
|
||||
|
||||
lockdep_assert_held(&local->mtx);
|
||||
|
||||
@@ -298,25 +288,11 @@ static void __ieee80211_scan_completed(struct ieee80211_hw *hw, bool aborted,
|
||||
local->scanning = 0;
|
||||
local->scan_channel = NULL;
|
||||
|
||||
- on_oper_chan = ieee80211_cfg_on_oper_channel(local);
|
||||
-
|
||||
- if (was_hw_scan || !on_oper_chan)
|
||||
- ieee80211_hw_config(local, IEEE80211_CONF_CHANGE_CHANNEL);
|
||||
- else
|
||||
- /* Set power back to normal operating levels. */
|
||||
- ieee80211_hw_config(local, 0);
|
||||
-
|
||||
+ ieee80211_hw_config(local, IEEE80211_CONF_CHANGE_CHANNEL);
|
||||
if (!was_hw_scan) {
|
||||
- bool on_oper_chan2;
|
||||
ieee80211_configure_filter(local);
|
||||
drv_sw_scan_complete(local);
|
||||
- on_oper_chan2 = ieee80211_cfg_on_oper_channel(local);
|
||||
- /* We should always be on-channel at this point. */
|
||||
- WARN_ON(!on_oper_chan2);
|
||||
- if (on_oper_chan2 && (on_oper_chan != on_oper_chan2))
|
||||
- enable_beacons = true;
|
||||
-
|
||||
- ieee80211_offchannel_return(local, enable_beacons, true);
|
||||
+ ieee80211_offchannel_return(local, true);
|
||||
}
|
||||
|
||||
ieee80211_recalc_idle(local);
|
||||
@@ -357,15 +333,13 @@ static int ieee80211_start_sw_scan(struct ieee80211_local *local)
|
||||
*/
|
||||
drv_sw_scan_start(local);
|
||||
|
||||
+ ieee80211_offchannel_stop_beaconing(local);
|
||||
+
|
||||
local->leave_oper_channel_time = 0;
|
||||
local->next_scan_state = SCAN_DECISION;
|
||||
local->scan_channel_idx = 0;
|
||||
|
||||
- /* We always want to use off-channel PS, even if we
|
||||
- * are not really leaving oper-channel. Don't
|
||||
- * tell the AP though, as long as we are on-channel.
|
||||
- */
|
||||
- ieee80211_offchannel_enable_all_ps(local, false);
|
||||
+ drv_flush(local, false);
|
||||
|
||||
ieee80211_configure_filter(local);
|
||||
|
||||
@@ -508,20 +482,7 @@ static void ieee80211_scan_state_decision(struct ieee80211_local *local,
|
||||
}
|
||||
mutex_unlock(&local->iflist_mtx);
|
||||
|
||||
- next_chan = local->scan_req->channels[local->scan_channel_idx];
|
||||
-
|
||||
- if (ieee80211_cfg_on_oper_channel(local)) {
|
||||
- /* We're currently on operating channel. */
|
||||
- if (next_chan == local->oper_channel)
|
||||
- /* We don't need to move off of operating channel. */
|
||||
- local->next_scan_state = SCAN_SET_CHANNEL;
|
||||
- else
|
||||
- /*
|
||||
- * We do need to leave operating channel, as next
|
||||
- * scan is somewhere else.
|
||||
- */
|
||||
- local->next_scan_state = SCAN_LEAVE_OPER_CHANNEL;
|
||||
- } else {
|
||||
+ if (local->scan_channel) {
|
||||
/*
|
||||
* we're currently scanning a different channel, let's
|
||||
* see if we can scan another channel without interfering
|
||||
@@ -537,6 +498,7 @@ static void ieee80211_scan_state_decision(struct ieee80211_local *local,
|
||||
*
|
||||
* Otherwise switch back to the operating channel.
|
||||
*/
|
||||
+ next_chan = local->scan_req->channels[local->scan_channel_idx];
|
||||
|
||||
bad_latency = time_after(jiffies +
|
||||
ieee80211_scan_get_channel_time(next_chan),
|
||||
@@ -554,6 +516,12 @@ static void ieee80211_scan_state_decision(struct ieee80211_local *local,
|
||||
local->next_scan_state = SCAN_ENTER_OPER_CHANNEL;
|
||||
else
|
||||
local->next_scan_state = SCAN_SET_CHANNEL;
|
||||
+ } else {
|
||||
+ /*
|
||||
+ * we're on the operating channel currently, let's
|
||||
+ * leave that channel now to scan another one
|
||||
+ */
|
||||
+ local->next_scan_state = SCAN_LEAVE_OPER_CHANNEL;
|
||||
}
|
||||
|
||||
*next_delay = 0;
|
||||
@@ -562,10 +530,9 @@ static void ieee80211_scan_state_decision(struct ieee80211_local *local,
|
||||
static void ieee80211_scan_state_leave_oper_channel(struct ieee80211_local *local,
|
||||
unsigned long *next_delay)
|
||||
{
|
||||
- /* PS will already be in off-channel mode,
|
||||
- * we do that once at the beginning of scanning.
|
||||
- */
|
||||
- ieee80211_offchannel_stop_vifs(local, false);
|
||||
+ ieee80211_offchannel_stop_station(local);
|
||||
+
|
||||
+ __set_bit(SCAN_OFF_CHANNEL, &local->scanning);
|
||||
|
||||
/*
|
||||
* What if the nullfunc frames didn't arrive?
|
||||
@@ -588,15 +555,15 @@ static void ieee80211_scan_state_enter_oper_channel(struct ieee80211_local *loca
|
||||
{
|
||||
/* switch back to the operating channel */
|
||||
local->scan_channel = NULL;
|
||||
- if (!ieee80211_cfg_on_oper_channel(local))
|
||||
- ieee80211_hw_config(local, IEEE80211_CONF_CHANGE_CHANNEL);
|
||||
+ ieee80211_hw_config(local, IEEE80211_CONF_CHANGE_CHANNEL);
|
||||
|
||||
/*
|
||||
- * Re-enable vifs and beaconing. Leave PS
|
||||
- * in off-channel state..will put that back
|
||||
- * on-channel at the end of scanning.
|
||||
+ * Only re-enable station mode interface now; beaconing will be
|
||||
+ * re-enabled once the full scan has been completed.
|
||||
*/
|
||||
- ieee80211_offchannel_return(local, true, false);
|
||||
+ ieee80211_offchannel_return(local, false);
|
||||
+
|
||||
+ __clear_bit(SCAN_OFF_CHANNEL, &local->scanning);
|
||||
|
||||
*next_delay = HZ / 5;
|
||||
local->next_scan_state = SCAN_DECISION;
|
||||
diff --git a/net/mac80211/tx.c b/net/mac80211/tx.c
|
||||
index 1f8b120..eff1f4e 100644
|
||||
--- a/net/mac80211/tx.c
|
||||
+++ b/net/mac80211/tx.c
|
||||
@@ -259,8 +259,7 @@ ieee80211_tx_h_check_assoc(struct ieee80211_tx_data *tx)
|
||||
if (unlikely(info->flags & IEEE80211_TX_CTL_INJECTED))
|
||||
return TX_CONTINUE;
|
||||
|
||||
- if (unlikely(test_bit(SCAN_SW_SCANNING, &tx->local->scanning)) &&
|
||||
- test_bit(SDATA_STATE_OFFCHANNEL, &tx->sdata->state) &&
|
||||
+ if (unlikely(test_bit(SCAN_OFF_CHANNEL, &tx->local->scanning)) &&
|
||||
!ieee80211_is_probe_req(hdr->frame_control) &&
|
||||
!ieee80211_is_nullfunc(hdr->frame_control))
|
||||
/*
|
||||
diff --git a/net/mac80211/work.c b/net/mac80211/work.c
|
||||
index 6c53b6d..99165ef 100644
|
||||
--- a/net/mac80211/work.c
|
||||
+++ b/net/mac80211/work.c
|
||||
@@ -899,26 +899,6 @@ static bool ieee80211_work_ct_coexists(enum nl80211_channel_type wk_ct,
|
||||
return false;
|
||||
}
|
||||
|
||||
-static enum nl80211_channel_type
|
||||
-ieee80211_calc_ct(enum nl80211_channel_type wk_ct,
|
||||
- enum nl80211_channel_type oper_ct)
|
||||
-{
|
||||
- switch (wk_ct) {
|
||||
- case NL80211_CHAN_NO_HT:
|
||||
- return oper_ct;
|
||||
- case NL80211_CHAN_HT20:
|
||||
- if (oper_ct != NL80211_CHAN_NO_HT)
|
||||
- return oper_ct;
|
||||
- return wk_ct;
|
||||
- case NL80211_CHAN_HT40MINUS:
|
||||
- case NL80211_CHAN_HT40PLUS:
|
||||
- return wk_ct;
|
||||
- }
|
||||
- WARN_ON(1); /* shouldn't get here */
|
||||
- return wk_ct;
|
||||
-}
|
||||
-
|
||||
-
|
||||
static void ieee80211_work_timer(unsigned long data)
|
||||
{
|
||||
struct ieee80211_local *local = (void *) data;
|
||||
@@ -969,52 +949,18 @@ static void ieee80211_work_work(struct work_struct *work)
|
||||
}
|
||||
|
||||
if (!started && !local->tmp_channel) {
|
||||
- bool on_oper_chan;
|
||||
- bool tmp_chan_changed = false;
|
||||
- bool on_oper_chan2;
|
||||
- enum nl80211_channel_type wk_ct;
|
||||
- on_oper_chan = ieee80211_cfg_on_oper_channel(local);
|
||||
-
|
||||
- /* Work with existing channel type if possible. */
|
||||
- wk_ct = wk->chan_type;
|
||||
- if (wk->chan == local->hw.conf.channel)
|
||||
- wk_ct = ieee80211_calc_ct(wk->chan_type,
|
||||
- local->hw.conf.channel_type);
|
||||
-
|
||||
- if (local->tmp_channel)
|
||||
- if ((local->tmp_channel != wk->chan) ||
|
||||
- (local->tmp_channel_type != wk_ct))
|
||||
- tmp_chan_changed = true;
|
||||
-
|
||||
- local->tmp_channel = wk->chan;
|
||||
- local->tmp_channel_type = wk_ct;
|
||||
/*
|
||||
- * Leave the station vifs in awake mode if they
|
||||
- * happen to be on the same channel as
|
||||
- * the requested channel.
|
||||
+ * TODO: could optimize this by leaving the
|
||||
+ * station vifs in awake mode if they
|
||||
+ * happen to be on the same channel as
|
||||
+ * the requested channel
|
||||
*/
|
||||
- on_oper_chan2 = ieee80211_cfg_on_oper_channel(local);
|
||||
- if (on_oper_chan != on_oper_chan2) {
|
||||
- if (on_oper_chan2) {
|
||||
- /* going off oper channel, PS too */
|
||||
- ieee80211_offchannel_stop_vifs(local,
|
||||
- true);
|
||||
- ieee80211_hw_config(local, 0);
|
||||
- } else {
|
||||
- /* going on channel, but leave PS
|
||||
- * off-channel. */
|
||||
- ieee80211_hw_config(local, 0);
|
||||
- ieee80211_offchannel_return(local,
|
||||
- true,
|
||||
- false);
|
||||
- }
|
||||
- } else if (tmp_chan_changed)
|
||||
- /* Still off-channel, but on some other
|
||||
- * channel, so update hardware.
|
||||
- * PS should already be off-channel.
|
||||
- */
|
||||
- ieee80211_hw_config(local, 0);
|
||||
+ ieee80211_offchannel_stop_beaconing(local);
|
||||
+ ieee80211_offchannel_stop_station(local);
|
||||
|
||||
+ local->tmp_channel = wk->chan;
|
||||
+ local->tmp_channel_type = wk->chan_type;
|
||||
+ ieee80211_hw_config(local, 0);
|
||||
started = true;
|
||||
wk->timeout = jiffies;
|
||||
}
|
||||
@@ -1100,8 +1046,7 @@ static void ieee80211_work_work(struct work_struct *work)
|
||||
* we still need to do a hardware config. Currently,
|
||||
* we cannot be here while scanning, however.
|
||||
*/
|
||||
- if (!ieee80211_cfg_on_oper_channel(local))
|
||||
- ieee80211_hw_config(local, 0);
|
||||
+ ieee80211_hw_config(local, 0);
|
||||
|
||||
/* At the least, we need to disable offchannel_ps,
|
||||
* so just go ahead and run the entire offchannel
|
||||
@@ -1109,7 +1054,7 @@ static void ieee80211_work_work(struct work_struct *work)
|
||||
* beaconing if we were already on-oper-channel
|
||||
* as a future optimization.
|
||||
*/
|
||||
- ieee80211_offchannel_return(local, true, true);
|
||||
+ ieee80211_offchannel_return(local, true);
|
||||
|
||||
/* give connection some time to breathe */
|
||||
run_again(local, jiffies + HZ/2);
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+60
@@ -0,0 +1,60 @@
|
||||
From 4b66a35b31fdc078582e40ec3cc0ee12abbffd17 Mon Sep 17 00:00:00 2001
|
||||
From: Chris Bagwell <chris@cnpbagwell.com>
|
||||
Date: Wed, 23 Nov 2011 10:54:27 +0100
|
||||
Subject: [PATCH 081/130] HID: hid-multitouch - add another eGalax id
|
||||
|
||||
commit 1fd8f047490dd0ec4e4db710fcbc1bd4798d944c upstream.
|
||||
|
||||
This allows ASUS Eee Slate touchscreens to work.
|
||||
|
||||
Signed-off-by: Chris Bagwell <chris@cnpbagwell.com>
|
||||
Reviewed-by: Benjamin Tissoires <benjamin.tissoires@gmail.com>
|
||||
Signed-off-by: Jiri Kosina <jkosina@suse.cz>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/hid/hid-core.c | 1 +
|
||||
drivers/hid/hid-ids.h | 1 +
|
||||
drivers/hid/hid-multitouch.c | 3 +++
|
||||
3 files changed, 5 insertions(+), 0 deletions(-)
|
||||
|
||||
diff --git a/drivers/hid/hid-core.c b/drivers/hid/hid-core.c
|
||||
index 1473067..b51cbf2 100644
|
||||
--- a/drivers/hid/hid-core.c
|
||||
+++ b/drivers/hid/hid-core.c
|
||||
@@ -1409,6 +1409,7 @@ static const struct hid_device_id hid_have_special_driver[] = {
|
||||
{ HID_USB_DEVICE(USB_VENDOR_ID_DWAV, USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH2) },
|
||||
{ HID_USB_DEVICE(USB_VENDOR_ID_DWAV, USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH3) },
|
||||
{ HID_USB_DEVICE(USB_VENDOR_ID_DWAV, USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH4) },
|
||||
+ { HID_USB_DEVICE(USB_VENDOR_ID_DWAV, USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH5) },
|
||||
{ HID_BLUETOOTH_DEVICE(USB_VENDOR_ID_ELECOM, USB_DEVICE_ID_ELECOM_BM084) },
|
||||
{ HID_USB_DEVICE(USB_VENDOR_ID_ELO, USB_DEVICE_ID_ELO_TS2515) },
|
||||
{ HID_USB_DEVICE(USB_VENDOR_ID_EMS, USB_DEVICE_ID_EMS_TRIO_LINKER_PLUS_II) },
|
||||
diff --git a/drivers/hid/hid-ids.h b/drivers/hid/hid-ids.h
|
||||
index 4a441a6..4c9a342 100644
|
||||
--- a/drivers/hid/hid-ids.h
|
||||
+++ b/drivers/hid/hid-ids.h
|
||||
@@ -235,6 +235,7 @@
|
||||
#define USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH2 0x72a1
|
||||
#define USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH3 0x480e
|
||||
#define USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH4 0x726b
|
||||
+#define USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH5 0xa001
|
||||
|
||||
#define USB_VENDOR_ID_ELECOM 0x056e
|
||||
#define USB_DEVICE_ID_ELECOM_BM084 0x0061
|
||||
diff --git a/drivers/hid/hid-multitouch.c b/drivers/hid/hid-multitouch.c
|
||||
index f1c909f..a59d939 100644
|
||||
--- a/drivers/hid/hid-multitouch.c
|
||||
+++ b/drivers/hid/hid-multitouch.c
|
||||
@@ -662,6 +662,9 @@ static const struct hid_device_id mt_devices[] = {
|
||||
{ .driver_data = MT_CLS_EGALAX,
|
||||
HID_USB_DEVICE(USB_VENDOR_ID_DWAV,
|
||||
USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH4) },
|
||||
+ { .driver_data = MT_CLS_EGALAX,
|
||||
+ HID_USB_DEVICE(USB_VENDOR_ID_DWAV,
|
||||
+ USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH5) },
|
||||
|
||||
/* Elo TouchSystems IntelliTouch Plus panel */
|
||||
{ .driver_data = MT_CLS_DUAL_NSMU_CONTACTID,
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+112
@@ -0,0 +1,112 @@
|
||||
From e5664bb7172d41e38788a503d6e33d14af866fb5 Mon Sep 17 00:00:00 2001
|
||||
From: Benjamin Tissoires <benjamin.tissoires@enac.fr>
|
||||
Date: Wed, 23 Nov 2011 10:54:31 +0100
|
||||
Subject: [PATCH 082/130] HID: multitouch: cleanup with eGalax PID definitions
|
||||
|
||||
commit e36f690b37945e0a9bb1554e1546eeec93f7d1f6 upstream.
|
||||
|
||||
This is just a renaming of USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH{N}
|
||||
to USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_{PID} to handle more eGalax
|
||||
devices.
|
||||
|
||||
Signed-off-by: Benjamin Tissoires <benjamin.tissoires@enac.fr>
|
||||
Signed-off-by: Jiri Kosina <jkosina@suse.cz>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/hid/hid-core.c | 12 ++++++------
|
||||
drivers/hid/hid-ids.h | 12 ++++++------
|
||||
drivers/hid/hid-multitouch.c | 24 ++++++++++++------------
|
||||
3 files changed, 24 insertions(+), 24 deletions(-)
|
||||
|
||||
diff --git a/drivers/hid/hid-core.c b/drivers/hid/hid-core.c
|
||||
index b51cbf2..4434aba 100644
|
||||
--- a/drivers/hid/hid-core.c
|
||||
+++ b/drivers/hid/hid-core.c
|
||||
@@ -1404,12 +1404,12 @@ static const struct hid_device_id hid_have_special_driver[] = {
|
||||
{ HID_USB_DEVICE(USB_VENDOR_ID_CYPRESS, USB_DEVICE_ID_CYPRESS_TRUETOUCH) },
|
||||
{ HID_USB_DEVICE(USB_VENDOR_ID_DRAGONRISE, 0x0006) },
|
||||
{ HID_USB_DEVICE(USB_VENDOR_ID_DRAGONRISE, 0x0011) },
|
||||
- { HID_USB_DEVICE(USB_VENDOR_ID_DWAV, USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH) },
|
||||
- { HID_USB_DEVICE(USB_VENDOR_ID_DWAV, USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH1) },
|
||||
- { HID_USB_DEVICE(USB_VENDOR_ID_DWAV, USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH2) },
|
||||
- { HID_USB_DEVICE(USB_VENDOR_ID_DWAV, USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH3) },
|
||||
- { HID_USB_DEVICE(USB_VENDOR_ID_DWAV, USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH4) },
|
||||
- { HID_USB_DEVICE(USB_VENDOR_ID_DWAV, USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH5) },
|
||||
+ { HID_USB_DEVICE(USB_VENDOR_ID_DWAV, USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_480D) },
|
||||
+ { HID_USB_DEVICE(USB_VENDOR_ID_DWAV, USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_480E) },
|
||||
+ { HID_USB_DEVICE(USB_VENDOR_ID_DWAV, USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_720C) },
|
||||
+ { HID_USB_DEVICE(USB_VENDOR_ID_DWAV, USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_726B) },
|
||||
+ { HID_USB_DEVICE(USB_VENDOR_ID_DWAV, USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_72A1) },
|
||||
+ { HID_USB_DEVICE(USB_VENDOR_ID_DWAV, USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_A001) },
|
||||
{ HID_BLUETOOTH_DEVICE(USB_VENDOR_ID_ELECOM, USB_DEVICE_ID_ELECOM_BM084) },
|
||||
{ HID_USB_DEVICE(USB_VENDOR_ID_ELO, USB_DEVICE_ID_ELO_TS2515) },
|
||||
{ HID_USB_DEVICE(USB_VENDOR_ID_EMS, USB_DEVICE_ID_EMS_TRIO_LINKER_PLUS_II) },
|
||||
diff --git a/drivers/hid/hid-ids.h b/drivers/hid/hid-ids.h
|
||||
index 4c9a342..9db8789 100644
|
||||
--- a/drivers/hid/hid-ids.h
|
||||
+++ b/drivers/hid/hid-ids.h
|
||||
@@ -230,12 +230,12 @@
|
||||
|
||||
#define USB_VENDOR_ID_DWAV 0x0eef
|
||||
#define USB_DEVICE_ID_EGALAX_TOUCHCONTROLLER 0x0001
|
||||
-#define USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH 0x480d
|
||||
-#define USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH1 0x720c
|
||||
-#define USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH2 0x72a1
|
||||
-#define USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH3 0x480e
|
||||
-#define USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH4 0x726b
|
||||
-#define USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH5 0xa001
|
||||
+#define USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_480D 0x480d
|
||||
+#define USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_480E 0x480e
|
||||
+#define USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_720C 0x720c
|
||||
+#define USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_726B 0x726b
|
||||
+#define USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_72A1 0x72a1
|
||||
+#define USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_A001 0xa001
|
||||
|
||||
#define USB_VENDOR_ID_ELECOM 0x056e
|
||||
#define USB_DEVICE_ID_ELECOM_BM084 0x0061
|
||||
diff --git a/drivers/hid/hid-multitouch.c b/drivers/hid/hid-multitouch.c
|
||||
index a59d939..815bd22 100644
|
||||
--- a/drivers/hid/hid-multitouch.c
|
||||
+++ b/drivers/hid/hid-multitouch.c
|
||||
@@ -645,26 +645,26 @@ static const struct hid_device_id mt_devices[] = {
|
||||
USB_DEVICE_ID_CYPRESS_TRUETOUCH) },
|
||||
|
||||
/* eGalax devices (resistive) */
|
||||
- { .driver_data = MT_CLS_EGALAX,
|
||||
+ { .driver_data = MT_CLS_EGALAX,
|
||||
HID_USB_DEVICE(USB_VENDOR_ID_DWAV,
|
||||
- USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH) },
|
||||
- { .driver_data = MT_CLS_EGALAX,
|
||||
+ USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_480D) },
|
||||
+ { .driver_data = MT_CLS_EGALAX,
|
||||
HID_USB_DEVICE(USB_VENDOR_ID_DWAV,
|
||||
- USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH3) },
|
||||
+ USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_480E) },
|
||||
|
||||
/* eGalax devices (capacitive) */
|
||||
- { .driver_data = MT_CLS_EGALAX,
|
||||
+ { .driver_data = MT_CLS_EGALAX,
|
||||
HID_USB_DEVICE(USB_VENDOR_ID_DWAV,
|
||||
- USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH1) },
|
||||
- { .driver_data = MT_CLS_EGALAX,
|
||||
+ USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_720C) },
|
||||
+ { .driver_data = MT_CLS_EGALAX,
|
||||
HID_USB_DEVICE(USB_VENDOR_ID_DWAV,
|
||||
- USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH2) },
|
||||
- { .driver_data = MT_CLS_EGALAX,
|
||||
+ USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_726B) },
|
||||
+ { .driver_data = MT_CLS_EGALAX,
|
||||
HID_USB_DEVICE(USB_VENDOR_ID_DWAV,
|
||||
- USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH4) },
|
||||
- { .driver_data = MT_CLS_EGALAX,
|
||||
+ USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_72A1) },
|
||||
+ { .driver_data = MT_CLS_EGALAX,
|
||||
HID_USB_DEVICE(USB_VENDOR_ID_DWAV,
|
||||
- USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH5) },
|
||||
+ USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_A001) },
|
||||
|
||||
/* Elo TouchSystems IntelliTouch Plus panel */
|
||||
{ .driver_data = MT_CLS_DUAL_NSMU_CONTACTID,
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+62
@@ -0,0 +1,62 @@
|
||||
From f8c7a53e06ce63f80f74db3c6582be6d07ad0318 Mon Sep 17 00:00:00 2001
|
||||
From: Marek Vasut <marek.vasut@gmail.com>
|
||||
Date: Wed, 23 Nov 2011 10:54:32 +0100
|
||||
Subject: [PATCH 083/130] HID: multitouch: Add egalax ID for Acer Iconia W500
|
||||
|
||||
commit bb9ff21072043634f147c05ac65dbf8185d4af6d upstream.
|
||||
|
||||
This patch adds USB ID for the touchpanel in Acer Iconia W500. The panel
|
||||
supports up to five fingers, therefore the need for a new addition of panel
|
||||
types.
|
||||
|
||||
Signed-off-by: Marek Vasut <marek.vasut@gmail.com>
|
||||
Signed-off-by: Benjamin Tissoires <benjamin.tissoires@enac.fr>
|
||||
Signed-off-by: Jiri Kosina <jkosina@suse.cz>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/hid/hid-core.c | 1 +
|
||||
drivers/hid/hid-ids.h | 1 +
|
||||
drivers/hid/hid-multitouch.c | 3 +++
|
||||
3 files changed, 5 insertions(+), 0 deletions(-)
|
||||
|
||||
diff --git a/drivers/hid/hid-core.c b/drivers/hid/hid-core.c
|
||||
index 4434aba..9cee7b2 100644
|
||||
--- a/drivers/hid/hid-core.c
|
||||
+++ b/drivers/hid/hid-core.c
|
||||
@@ -1409,6 +1409,7 @@ static const struct hid_device_id hid_have_special_driver[] = {
|
||||
{ HID_USB_DEVICE(USB_VENDOR_ID_DWAV, USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_720C) },
|
||||
{ HID_USB_DEVICE(USB_VENDOR_ID_DWAV, USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_726B) },
|
||||
{ HID_USB_DEVICE(USB_VENDOR_ID_DWAV, USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_72A1) },
|
||||
+ { HID_USB_DEVICE(USB_VENDOR_ID_DWAV, USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_7302) },
|
||||
{ HID_USB_DEVICE(USB_VENDOR_ID_DWAV, USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_A001) },
|
||||
{ HID_BLUETOOTH_DEVICE(USB_VENDOR_ID_ELECOM, USB_DEVICE_ID_ELECOM_BM084) },
|
||||
{ HID_USB_DEVICE(USB_VENDOR_ID_ELO, USB_DEVICE_ID_ELO_TS2515) },
|
||||
diff --git a/drivers/hid/hid-ids.h b/drivers/hid/hid-ids.h
|
||||
index 9db8789..9eb90b1 100644
|
||||
--- a/drivers/hid/hid-ids.h
|
||||
+++ b/drivers/hid/hid-ids.h
|
||||
@@ -235,6 +235,7 @@
|
||||
#define USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_720C 0x720c
|
||||
#define USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_726B 0x726b
|
||||
#define USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_72A1 0x72a1
|
||||
+#define USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_7302 0x7302
|
||||
#define USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_A001 0xa001
|
||||
|
||||
#define USB_VENDOR_ID_ELECOM 0x056e
|
||||
diff --git a/drivers/hid/hid-multitouch.c b/drivers/hid/hid-multitouch.c
|
||||
index 815bd22..c77d495 100644
|
||||
--- a/drivers/hid/hid-multitouch.c
|
||||
+++ b/drivers/hid/hid-multitouch.c
|
||||
@@ -664,6 +664,9 @@ static const struct hid_device_id mt_devices[] = {
|
||||
USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_72A1) },
|
||||
{ .driver_data = MT_CLS_EGALAX,
|
||||
HID_USB_DEVICE(USB_VENDOR_ID_DWAV,
|
||||
+ USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_7302) },
|
||||
+ { .driver_data = MT_CLS_EGALAX,
|
||||
+ HID_USB_DEVICE(USB_VENDOR_ID_DWAV,
|
||||
USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_A001) },
|
||||
|
||||
/* Elo TouchSystems IntelliTouch Plus panel */
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+49
@@ -0,0 +1,49 @@
|
||||
From 5b2c651d5496aad3c5359e72fc6eb6efcadecc4e Mon Sep 17 00:00:00 2001
|
||||
From: Benjamin Tissoires <benjamin.tissoires@enac.fr>
|
||||
Date: Wed, 23 Nov 2011 10:54:33 +0100
|
||||
Subject: [PATCH 084/130] HID: multitouch: add support for the MSI Windpad
|
||||
110W
|
||||
|
||||
commit 66f06127f34ad6e8a1b24a2c03144b694d19f99f upstream.
|
||||
|
||||
Just another eGalax device.
|
||||
Please note that adding this device to have_special_driver
|
||||
in hid-core.c is not required anymore.
|
||||
|
||||
Signed-off-by: Benjamin Tissoires <benjamin.tissoires@enac.fr>
|
||||
Signed-off-by: Jiri Kosina <jkosina@suse.cz>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/hid/hid-ids.h | 1 +
|
||||
drivers/hid/hid-multitouch.c | 3 +++
|
||||
2 files changed, 4 insertions(+), 0 deletions(-)
|
||||
|
||||
diff --git a/drivers/hid/hid-ids.h b/drivers/hid/hid-ids.h
|
||||
index 9eb90b1..6ccd7df 100644
|
||||
--- a/drivers/hid/hid-ids.h
|
||||
+++ b/drivers/hid/hid-ids.h
|
||||
@@ -235,6 +235,7 @@
|
||||
#define USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_720C 0x720c
|
||||
#define USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_726B 0x726b
|
||||
#define USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_72A1 0x72a1
|
||||
+#define USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_72FA 0x72fa
|
||||
#define USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_7302 0x7302
|
||||
#define USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_A001 0xa001
|
||||
|
||||
diff --git a/drivers/hid/hid-multitouch.c b/drivers/hid/hid-multitouch.c
|
||||
index c77d495..6f6b1d9 100644
|
||||
--- a/drivers/hid/hid-multitouch.c
|
||||
+++ b/drivers/hid/hid-multitouch.c
|
||||
@@ -664,6 +664,9 @@ static const struct hid_device_id mt_devices[] = {
|
||||
USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_72A1) },
|
||||
{ .driver_data = MT_CLS_EGALAX,
|
||||
HID_USB_DEVICE(USB_VENDOR_ID_DWAV,
|
||||
+ USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_72FA) },
|
||||
+ { .driver_data = MT_CLS_EGALAX,
|
||||
+ HID_USB_DEVICE(USB_VENDOR_ID_DWAV,
|
||||
USB_DEVICE_ID_DWAV_EGALAX_MULTITOUCH_7302) },
|
||||
{ .driver_data = MT_CLS_EGALAX,
|
||||
HID_USB_DEVICE(USB_VENDOR_ID_DWAV,
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+63
@@ -0,0 +1,63 @@
|
||||
From 6da88efbdd98ef411f670b51ad6ab0ca5e3a753b Mon Sep 17 00:00:00 2001
|
||||
From: Benjamin Tissoires <benjamin.tissoires@enac.fr>
|
||||
Date: Tue, 29 Nov 2011 13:13:12 +0100
|
||||
Subject: [PATCH 085/130] HID: hid-multitouch: add support for new Hanvon
|
||||
panels
|
||||
|
||||
commit 545803651da8dde248eeb8ce3ed1e547e9e4ac0a upstream.
|
||||
|
||||
Signed-off-by: Benjamin Tissoires <benjamin.tissoires@enac.fr>
|
||||
Acked-by: Henrik Rydberg <rydberg@euromail.se>
|
||||
Signed-off-by: Jiri Kosina <jkosina@suse.cz>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/hid/hid-core.c | 1 +
|
||||
drivers/hid/hid-ids.h | 3 +++
|
||||
drivers/hid/hid-multitouch.c | 5 +++++
|
||||
3 files changed, 9 insertions(+), 0 deletions(-)
|
||||
|
||||
diff --git a/drivers/hid/hid-core.c b/drivers/hid/hid-core.c
|
||||
index 9cee7b2..a1cb906 100644
|
||||
--- a/drivers/hid/hid-core.c
|
||||
+++ b/drivers/hid/hid-core.c
|
||||
@@ -1425,6 +1425,7 @@ static const struct hid_device_id hid_have_special_driver[] = {
|
||||
{ HID_USB_DEVICE(USB_VENDOR_ID_GYRATION, USB_DEVICE_ID_GYRATION_REMOTE_2) },
|
||||
{ HID_USB_DEVICE(USB_VENDOR_ID_GYRATION, USB_DEVICE_ID_GYRATION_REMOTE_3) },
|
||||
{ HID_USB_DEVICE(USB_VENDOR_ID_HANVON, USB_DEVICE_ID_HANVON_MULTITOUCH) },
|
||||
+ { HID_USB_DEVICE(USB_VENDOR_ID_HANVON_ALT, USB_DEVICE_ID_HANVON_ALT_MULTITOUCH) },
|
||||
{ HID_USB_DEVICE(USB_VENDOR_ID_IDEACOM, USB_DEVICE_ID_IDEACOM_IDC6650) },
|
||||
{ HID_USB_DEVICE(USB_VENDOR_ID_HOLTEK, USB_DEVICE_ID_HOLTEK_ON_LINE_GRIP) },
|
||||
{ HID_USB_DEVICE(USB_VENDOR_ID_ILITEK, USB_DEVICE_ID_ILITEK_MULTITOUCH) },
|
||||
diff --git a/drivers/hid/hid-ids.h b/drivers/hid/hid-ids.h
|
||||
index 6ccd7df..56df290 100644
|
||||
--- a/drivers/hid/hid-ids.h
|
||||
+++ b/drivers/hid/hid-ids.h
|
||||
@@ -359,6 +359,9 @@
|
||||
#define USB_VENDOR_ID_HANVON 0x20b3
|
||||
#define USB_DEVICE_ID_HANVON_MULTITOUCH 0x0a18
|
||||
|
||||
+#define USB_VENDOR_ID_HANVON_ALT 0x22ed
|
||||
+#define USB_DEVICE_ID_HANVON_ALT_MULTITOUCH 0x1010
|
||||
+
|
||||
#define USB_VENDOR_ID_HAPP 0x078b
|
||||
#define USB_DEVICE_ID_UGCI_DRIVING 0x0010
|
||||
#define USB_DEVICE_ID_UGCI_FLYING 0x0020
|
||||
diff --git a/drivers/hid/hid-multitouch.c b/drivers/hid/hid-multitouch.c
|
||||
index 6f6b1d9..ea20c8e 100644
|
||||
--- a/drivers/hid/hid-multitouch.c
|
||||
+++ b/drivers/hid/hid-multitouch.c
|
||||
@@ -687,6 +687,11 @@ static const struct hid_device_id mt_devices[] = {
|
||||
HID_USB_DEVICE(USB_VENDOR_ID_GOODTOUCH,
|
||||
USB_DEVICE_ID_GOODTOUCH_000f) },
|
||||
|
||||
+ /* Hanvon panels */
|
||||
+ { .driver_data = MT_CLS_DUAL_INRANGE_CONTACTID,
|
||||
+ HID_USB_DEVICE(USB_VENDOR_ID_HANVON_ALT,
|
||||
+ USB_DEVICE_ID_HANVON_ALT_MULTITOUCH) },
|
||||
+
|
||||
/* Ideacom panel */
|
||||
{ .driver_data = MT_CLS_SERIAL,
|
||||
HID_USB_DEVICE(USB_VENDOR_ID_IDEACOM,
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+63
@@ -0,0 +1,63 @@
|
||||
From ba791aa0bf69b20ba364329edc62dc04ddb86dfc Mon Sep 17 00:00:00 2001
|
||||
From: Benjamin Tissoires <benjamin.tissoires@gmail.com>
|
||||
Date: Fri, 23 Dec 2011 15:40:59 +0100
|
||||
Subject: [PATCH 086/130] HID: multitouch: add support of Atmel multitouch
|
||||
panels
|
||||
|
||||
commit b105712469d957cf1ab223c1ea72b7ba88edb926 upstream.
|
||||
|
||||
Signed-off-by: Benjamin Tissoires <benjamin.tissoires@gmail.com>
|
||||
Acked-by: Henrik Rydberg <rydberg@euromail.se>
|
||||
Signed-off-by: Jiri Kosina <jkosina@suse.cz>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/hid/Kconfig | 1 +
|
||||
drivers/hid/hid-ids.h | 3 +++
|
||||
drivers/hid/hid-multitouch.c | 5 +++++
|
||||
3 files changed, 9 insertions(+), 0 deletions(-)
|
||||
|
||||
diff --git a/drivers/hid/Kconfig b/drivers/hid/Kconfig
|
||||
index 332c22a..36f5df3 100644
|
||||
--- a/drivers/hid/Kconfig
|
||||
+++ b/drivers/hid/Kconfig
|
||||
@@ -335,6 +335,7 @@ config HID_MULTITOUCH
|
||||
Say Y here if you have one of the following devices:
|
||||
- 3M PCT touch screens
|
||||
- ActionStar dual touch panels
|
||||
+ - Atmel panels
|
||||
- Cando dual touch panels
|
||||
- Chunghwa panels
|
||||
- CVTouch panels
|
||||
diff --git a/drivers/hid/hid-ids.h b/drivers/hid/hid-ids.h
|
||||
index 56df290..bf95a50 100644
|
||||
--- a/drivers/hid/hid-ids.h
|
||||
+++ b/drivers/hid/hid-ids.h
|
||||
@@ -145,6 +145,9 @@
|
||||
#define USB_DEVICE_ID_ATEN_4PORTKVM 0x2205
|
||||
#define USB_DEVICE_ID_ATEN_4PORTKVMC 0x2208
|
||||
|
||||
+#define USB_VENDOR_ID_ATMEL 0x03eb
|
||||
+#define USB_DEVICE_ID_ATMEL_MULTITOUCH 0x211c
|
||||
+
|
||||
#define USB_VENDOR_ID_AVERMEDIA 0x07ca
|
||||
#define USB_DEVICE_ID_AVER_FM_MR800 0xb800
|
||||
|
||||
diff --git a/drivers/hid/hid-multitouch.c b/drivers/hid/hid-multitouch.c
|
||||
index ea20c8e..7f83024 100644
|
||||
--- a/drivers/hid/hid-multitouch.c
|
||||
+++ b/drivers/hid/hid-multitouch.c
|
||||
@@ -615,6 +615,11 @@ static const struct hid_device_id mt_devices[] = {
|
||||
HID_USB_DEVICE(USB_VENDOR_ID_ACTIONSTAR,
|
||||
USB_DEVICE_ID_ACTIONSTAR_1011) },
|
||||
|
||||
+ /* Atmel panels */
|
||||
+ { .driver_data = MT_CLS_SERIAL,
|
||||
+ HID_USB_DEVICE(USB_VENDOR_ID_ATMEL,
|
||||
+ USB_DEVICE_ID_ATMEL_MULTITOUCH) },
|
||||
+
|
||||
/* Cando panels */
|
||||
{ .driver_data = MT_CLS_DUAL_INRANGE_CONTACTNUMBER,
|
||||
HID_USB_DEVICE(USB_VENDOR_ID_CANDO,
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+45
@@ -0,0 +1,45 @@
|
||||
From 59e1439e23925a4029af1ba09e54e57d6824d6af Mon Sep 17 00:00:00 2001
|
||||
From: Benjamin Tissoires <benjamin.tissoires@gmail.com>
|
||||
Date: Fri, 23 Dec 2011 15:41:00 +0100
|
||||
Subject: [PATCH 087/130] HID: multitouch: add support for 3M 32"
|
||||
|
||||
commit c4fad877cd0efb51d8180ae2eaa791c99c92051c upstream.
|
||||
|
||||
Signed-off-by: Benjamin Tissoires <benjamin.tissoires@gmail.com>
|
||||
Acked-by: Henrik Rydberg <rydberg@euromail.se>
|
||||
Signed-off-by: Jiri Kosina <jkosina@suse.cz>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/hid/hid-ids.h | 1 +
|
||||
drivers/hid/hid-multitouch.c | 3 +++
|
||||
2 files changed, 4 insertions(+), 0 deletions(-)
|
||||
|
||||
diff --git a/drivers/hid/hid-ids.h b/drivers/hid/hid-ids.h
|
||||
index bf95a50..6e53391a 100644
|
||||
--- a/drivers/hid/hid-ids.h
|
||||
+++ b/drivers/hid/hid-ids.h
|
||||
@@ -21,6 +21,7 @@
|
||||
#define USB_VENDOR_ID_3M 0x0596
|
||||
#define USB_DEVICE_ID_3M1968 0x0500
|
||||
#define USB_DEVICE_ID_3M2256 0x0502
|
||||
+#define USB_DEVICE_ID_3M3266 0x0506
|
||||
|
||||
#define USB_VENDOR_ID_A4TECH 0x09da
|
||||
#define USB_DEVICE_ID_A4TECH_WCP32PU 0x0006
|
||||
diff --git a/drivers/hid/hid-multitouch.c b/drivers/hid/hid-multitouch.c
|
||||
index 7f83024..4a63dee 100644
|
||||
--- a/drivers/hid/hid-multitouch.c
|
||||
+++ b/drivers/hid/hid-multitouch.c
|
||||
@@ -609,6 +609,9 @@ static const struct hid_device_id mt_devices[] = {
|
||||
{ .driver_data = MT_CLS_3M,
|
||||
HID_USB_DEVICE(USB_VENDOR_ID_3M,
|
||||
USB_DEVICE_ID_3M2256) },
|
||||
+ { .driver_data = MT_CLS_3M,
|
||||
+ HID_USB_DEVICE(USB_VENDOR_ID_3M,
|
||||
+ USB_DEVICE_ID_3M3266) },
|
||||
|
||||
/* ActionStar panels */
|
||||
{ .driver_data = MT_CLS_DEFAULT,
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+117
@@ -0,0 +1,117 @@
|
||||
From 9f0708248c8226860e4fbb4492575f7128e593d5 Mon Sep 17 00:00:00 2001
|
||||
From: Masatoshi Hoshikawa <hoshikawa@xiroku.com>
|
||||
Date: Thu, 5 Jan 2012 11:53:46 +0900
|
||||
Subject: [PATCH 088/130] HID: hid-multitouch: add support 9 new Xiroku
|
||||
devices
|
||||
|
||||
commit 11576c6114c3b6505aea2e0c988bedb856a0e20c upstream.
|
||||
|
||||
This patch adds support for the Xiroku Inc. panels (SPX/MPX/CSR/etc.).
|
||||
|
||||
Signed-off-by: Masatoshi Hoshikawa <hoshikawa@xiroku.com>
|
||||
Signed-off-by: Jiri Kosina <jkosina@suse.cz>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/hid/Kconfig | 1 +
|
||||
drivers/hid/hid-core.c | 9 +++++++++
|
||||
drivers/hid/hid-ids.h | 11 +++++++++++
|
||||
drivers/hid/hid-multitouch.c | 29 +++++++++++++++++++++++++++++
|
||||
4 files changed, 50 insertions(+), 0 deletions(-)
|
||||
|
||||
diff --git a/drivers/hid/Kconfig b/drivers/hid/Kconfig
|
||||
index 36f5df3..d21f6d0 100644
|
||||
--- a/drivers/hid/Kconfig
|
||||
+++ b/drivers/hid/Kconfig
|
||||
@@ -356,6 +356,7 @@ config HID_MULTITOUCH
|
||||
- Touch International Panels
|
||||
- Unitec Panels
|
||||
- XAT optical touch panels
|
||||
+ - Xiroku optical touch panels
|
||||
|
||||
If unsure, say N.
|
||||
|
||||
diff --git a/drivers/hid/hid-core.c b/drivers/hid/hid-core.c
|
||||
index a1cb906..bb656d8 100644
|
||||
--- a/drivers/hid/hid-core.c
|
||||
+++ b/drivers/hid/hid-core.c
|
||||
@@ -1552,6 +1552,15 @@ static const struct hid_device_id hid_have_special_driver[] = {
|
||||
{ HID_USB_DEVICE(USB_VENDOR_ID_WALTOP, USB_DEVICE_ID_WALTOP_MEDIA_TABLET_10_6_INCH) },
|
||||
{ HID_USB_DEVICE(USB_VENDOR_ID_WALTOP, USB_DEVICE_ID_WALTOP_MEDIA_TABLET_14_1_INCH) },
|
||||
{ HID_USB_DEVICE(USB_VENDOR_ID_XAT, USB_DEVICE_ID_XAT_CSR) },
|
||||
+ { HID_USB_DEVICE(USB_VENDOR_ID_XIROKU, USB_DEVICE_ID_XIROKU_SPX) },
|
||||
+ { HID_USB_DEVICE(USB_VENDOR_ID_XIROKU, USB_DEVICE_ID_XIROKU_MPX) },
|
||||
+ { HID_USB_DEVICE(USB_VENDOR_ID_XIROKU, USB_DEVICE_ID_XIROKU_CSR) },
|
||||
+ { HID_USB_DEVICE(USB_VENDOR_ID_XIROKU, USB_DEVICE_ID_XIROKU_SPX1) },
|
||||
+ { HID_USB_DEVICE(USB_VENDOR_ID_XIROKU, USB_DEVICE_ID_XIROKU_MPX1) },
|
||||
+ { HID_USB_DEVICE(USB_VENDOR_ID_XIROKU, USB_DEVICE_ID_XIROKU_CSR1) },
|
||||
+ { HID_USB_DEVICE(USB_VENDOR_ID_XIROKU, USB_DEVICE_ID_XIROKU_SPX2) },
|
||||
+ { HID_USB_DEVICE(USB_VENDOR_ID_XIROKU, USB_DEVICE_ID_XIROKU_MPX2) },
|
||||
+ { HID_USB_DEVICE(USB_VENDOR_ID_XIROKU, USB_DEVICE_ID_XIROKU_CSR2) },
|
||||
{ HID_USB_DEVICE(USB_VENDOR_ID_X_TENSIONS, USB_DEVICE_ID_SPEEDLINK_VAD_CEZANNE) },
|
||||
{ HID_USB_DEVICE(USB_VENDOR_ID_ZEROPLUS, 0x0005) },
|
||||
{ HID_USB_DEVICE(USB_VENDOR_ID_ZEROPLUS, 0x0030) },
|
||||
diff --git a/drivers/hid/hid-ids.h b/drivers/hid/hid-ids.h
|
||||
index 6e53391a..00cabb3 100644
|
||||
--- a/drivers/hid/hid-ids.h
|
||||
+++ b/drivers/hid/hid-ids.h
|
||||
@@ -717,6 +717,17 @@
|
||||
#define USB_VENDOR_ID_XAT 0x2505
|
||||
#define USB_DEVICE_ID_XAT_CSR 0x0220
|
||||
|
||||
+#define USB_VENDOR_ID_XIROKU 0x1477
|
||||
+#define USB_DEVICE_ID_XIROKU_SPX 0x1006
|
||||
+#define USB_DEVICE_ID_XIROKU_MPX 0x1007
|
||||
+#define USB_DEVICE_ID_XIROKU_CSR 0x100e
|
||||
+#define USB_DEVICE_ID_XIROKU_SPX1 0x1021
|
||||
+#define USB_DEVICE_ID_XIROKU_CSR1 0x1022
|
||||
+#define USB_DEVICE_ID_XIROKU_MPX1 0x1023
|
||||
+#define USB_DEVICE_ID_XIROKU_SPX2 0x1024
|
||||
+#define USB_DEVICE_ID_XIROKU_CSR2 0x1025
|
||||
+#define USB_DEVICE_ID_XIROKU_MPX2 0x1026
|
||||
+
|
||||
#define USB_VENDOR_ID_YEALINK 0x6993
|
||||
#define USB_DEVICE_ID_YEALINK_P1K_P4K_B2K 0xb001
|
||||
|
||||
diff --git a/drivers/hid/hid-multitouch.c b/drivers/hid/hid-multitouch.c
|
||||
index 4a63dee..995fc4c 100644
|
||||
--- a/drivers/hid/hid-multitouch.c
|
||||
+++ b/drivers/hid/hid-multitouch.c
|
||||
@@ -780,6 +780,35 @@ static const struct hid_device_id mt_devices[] = {
|
||||
HID_USB_DEVICE(USB_VENDOR_ID_XAT,
|
||||
USB_DEVICE_ID_XAT_CSR) },
|
||||
|
||||
+ /* Xiroku */
|
||||
+ { .driver_data = MT_CLS_DEFAULT,
|
||||
+ HID_USB_DEVICE(USB_VENDOR_ID_XIROKU,
|
||||
+ USB_DEVICE_ID_XIROKU_SPX) },
|
||||
+ { .driver_data = MT_CLS_DEFAULT,
|
||||
+ HID_USB_DEVICE(USB_VENDOR_ID_XIROKU,
|
||||
+ USB_DEVICE_ID_XIROKU_MPX) },
|
||||
+ { .driver_data = MT_CLS_DEFAULT,
|
||||
+ HID_USB_DEVICE(USB_VENDOR_ID_XIROKU,
|
||||
+ USB_DEVICE_ID_XIROKU_CSR) },
|
||||
+ { .driver_data = MT_CLS_DEFAULT,
|
||||
+ HID_USB_DEVICE(USB_VENDOR_ID_XIROKU,
|
||||
+ USB_DEVICE_ID_XIROKU_SPX1) },
|
||||
+ { .driver_data = MT_CLS_DEFAULT,
|
||||
+ HID_USB_DEVICE(USB_VENDOR_ID_XIROKU,
|
||||
+ USB_DEVICE_ID_XIROKU_MPX1) },
|
||||
+ { .driver_data = MT_CLS_DEFAULT,
|
||||
+ HID_USB_DEVICE(USB_VENDOR_ID_XIROKU,
|
||||
+ USB_DEVICE_ID_XIROKU_CSR1) },
|
||||
+ { .driver_data = MT_CLS_DEFAULT,
|
||||
+ HID_USB_DEVICE(USB_VENDOR_ID_XIROKU,
|
||||
+ USB_DEVICE_ID_XIROKU_SPX2) },
|
||||
+ { .driver_data = MT_CLS_DEFAULT,
|
||||
+ HID_USB_DEVICE(USB_VENDOR_ID_XIROKU,
|
||||
+ USB_DEVICE_ID_XIROKU_MPX2) },
|
||||
+ { .driver_data = MT_CLS_DEFAULT,
|
||||
+ HID_USB_DEVICE(USB_VENDOR_ID_XIROKU,
|
||||
+ USB_DEVICE_ID_XIROKU_CSR2) },
|
||||
+
|
||||
{ }
|
||||
};
|
||||
MODULE_DEVICE_TABLE(hid, mt_devices);
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+49
@@ -0,0 +1,49 @@
|
||||
From 7d6b552faf6a591c44f680e3e897a1bd6471985a Mon Sep 17 00:00:00 2001
|
||||
From: Martin Schwidefsky <schwidefsky@de.ibm.com>
|
||||
Date: Thu, 15 Dec 2011 14:56:10 +0100
|
||||
Subject: [PATCH 089/130] fix cputime overflow in uptime_proc_show
|
||||
|
||||
commit c3e0ef9a298e028a82ada28101ccd5cf64d209ee upstream.
|
||||
|
||||
For 32-bit architectures using standard jiffies the idletime calculation
|
||||
in uptime_proc_show will quickly overflow. It takes (2^32 / HZ) seconds
|
||||
of idle-time, or e.g. 12.45 days with no load on a quad-core with HZ=1000.
|
||||
Switch to 64-bit calculations.
|
||||
|
||||
Cc: Michael Abbott <michael.abbott@diamond.ac.uk>
|
||||
Signed-off-by: Martin Schwidefsky <schwidefsky@de.ibm.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
fs/proc/uptime.c | 9 +++++++--
|
||||
1 files changed, 7 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/fs/proc/uptime.c b/fs/proc/uptime.c
|
||||
index 766b1d4..29166ec 100644
|
||||
--- a/fs/proc/uptime.c
|
||||
+++ b/fs/proc/uptime.c
|
||||
@@ -11,15 +11,20 @@ static int uptime_proc_show(struct seq_file *m, void *v)
|
||||
{
|
||||
struct timespec uptime;
|
||||
struct timespec idle;
|
||||
+ cputime64_t idletime;
|
||||
+ u64 nsec;
|
||||
+ u32 rem;
|
||||
int i;
|
||||
- cputime_t idletime = cputime_zero;
|
||||
|
||||
+ idletime = 0;
|
||||
for_each_possible_cpu(i)
|
||||
idletime = cputime64_add(idletime, kstat_cpu(i).cpustat.idle);
|
||||
|
||||
do_posix_clock_monotonic_gettime(&uptime);
|
||||
monotonic_to_bootbased(&uptime);
|
||||
- cputime_to_timespec(idletime, &idle);
|
||||
+ nsec = cputime64_to_jiffies64(idletime) * TICK_NSEC;
|
||||
+ idle.tv_sec = div_u64_rem(nsec, NSEC_PER_SEC, &rem);
|
||||
+ idle.tv_nsec = rem;
|
||||
seq_printf(m, "%lu.%02lu %lu.%02lu\n",
|
||||
(unsigned long) uptime.tv_sec,
|
||||
(uptime.tv_nsec / (NSEC_PER_SEC / 100)),
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+166
@@ -0,0 +1,166 @@
|
||||
From 4adb778fc31d3c9c7707167165b07138f31c78c4 Mon Sep 17 00:00:00 2001
|
||||
From: Paolo Bonzini <pbonzini@redhat.com>
|
||||
Date: Thu, 12 Jan 2012 16:01:27 +0100
|
||||
Subject: [PATCH 090/130] block: add and use scsi_blk_cmd_ioctl
|
||||
|
||||
commit 577ebb374c78314ac4617242f509e2f5e7156649 upstream.
|
||||
|
||||
Introduce a wrapper around scsi_cmd_ioctl that takes a block device.
|
||||
|
||||
The function will then be enhanced to detect partition block devices
|
||||
and, in that case, subject the ioctls to whitelisting.
|
||||
|
||||
Cc: linux-scsi@vger.kernel.org
|
||||
Cc: Jens Axboe <axboe@kernel.dk>
|
||||
Cc: James Bottomley <JBottomley@parallels.com>
|
||||
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
|
||||
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
block/scsi_ioctl.c | 7 +++++++
|
||||
drivers/block/cciss.c | 6 +++---
|
||||
drivers/block/ub.c | 3 +--
|
||||
drivers/block/virtio_blk.c | 4 ++--
|
||||
drivers/cdrom/cdrom.c | 3 +--
|
||||
drivers/ide/ide-floppy_ioctl.c | 3 +--
|
||||
drivers/scsi/sd.c | 2 +-
|
||||
include/linux/blkdev.h | 2 ++
|
||||
8 files changed, 18 insertions(+), 12 deletions(-)
|
||||
|
||||
diff --git a/block/scsi_ioctl.c b/block/scsi_ioctl.c
|
||||
index fbdf0d8..a2c11f3 100644
|
||||
--- a/block/scsi_ioctl.c
|
||||
+++ b/block/scsi_ioctl.c
|
||||
@@ -690,6 +690,13 @@ int scsi_cmd_ioctl(struct request_queue *q, struct gendisk *bd_disk, fmode_t mod
|
||||
}
|
||||
EXPORT_SYMBOL(scsi_cmd_ioctl);
|
||||
|
||||
+int scsi_cmd_blk_ioctl(struct block_device *bd, fmode_t mode,
|
||||
+ unsigned int cmd, void __user *arg)
|
||||
+{
|
||||
+ return scsi_cmd_ioctl(bd->bd_disk->queue, bd->bd_disk, mode, cmd, arg);
|
||||
+}
|
||||
+EXPORT_SYMBOL(scsi_cmd_blk_ioctl);
|
||||
+
|
||||
static int __init blk_scsi_ioctl_init(void)
|
||||
{
|
||||
blk_set_cmd_filter_defaults(&blk_default_cmd_filter);
|
||||
diff --git a/drivers/block/cciss.c b/drivers/block/cciss.c
|
||||
index 587cce5..b0f553b 100644
|
||||
--- a/drivers/block/cciss.c
|
||||
+++ b/drivers/block/cciss.c
|
||||
@@ -1735,7 +1735,7 @@ static int cciss_ioctl(struct block_device *bdev, fmode_t mode,
|
||||
case CCISS_BIG_PASSTHRU:
|
||||
return cciss_bigpassthru(h, argp);
|
||||
|
||||
- /* scsi_cmd_ioctl handles these, below, though some are not */
|
||||
+ /* scsi_cmd_blk_ioctl handles these, below, though some are not */
|
||||
/* very meaningful for cciss. SG_IO is the main one people want. */
|
||||
|
||||
case SG_GET_VERSION_NUM:
|
||||
@@ -1746,9 +1746,9 @@ static int cciss_ioctl(struct block_device *bdev, fmode_t mode,
|
||||
case SG_EMULATED_HOST:
|
||||
case SG_IO:
|
||||
case SCSI_IOCTL_SEND_COMMAND:
|
||||
- return scsi_cmd_ioctl(disk->queue, disk, mode, cmd, argp);
|
||||
+ return scsi_cmd_blk_ioctl(bdev, mode, cmd, argp);
|
||||
|
||||
- /* scsi_cmd_ioctl would normally handle these, below, but */
|
||||
+ /* scsi_cmd_blk_ioctl would normally handle these, below, but */
|
||||
/* they aren't a good fit for cciss, as CD-ROMs are */
|
||||
/* not supported, and we don't have any bus/target/lun */
|
||||
/* which we present to the kernel. */
|
||||
diff --git a/drivers/block/ub.c b/drivers/block/ub.c
|
||||
index 0e376d4..7333b9e 100644
|
||||
--- a/drivers/block/ub.c
|
||||
+++ b/drivers/block/ub.c
|
||||
@@ -1744,12 +1744,11 @@ static int ub_bd_release(struct gendisk *disk, fmode_t mode)
|
||||
static int ub_bd_ioctl(struct block_device *bdev, fmode_t mode,
|
||||
unsigned int cmd, unsigned long arg)
|
||||
{
|
||||
- struct gendisk *disk = bdev->bd_disk;
|
||||
void __user *usermem = (void __user *) arg;
|
||||
int ret;
|
||||
|
||||
mutex_lock(&ub_mutex);
|
||||
- ret = scsi_cmd_ioctl(disk->queue, disk, mode, cmd, usermem);
|
||||
+ ret = scsi_cmd_blk_ioctl(bdev, mode, cmd, usermem);
|
||||
mutex_unlock(&ub_mutex);
|
||||
|
||||
return ret;
|
||||
diff --git a/drivers/block/virtio_blk.c b/drivers/block/virtio_blk.c
|
||||
index 4d0b70a..e46f2f7 100644
|
||||
--- a/drivers/block/virtio_blk.c
|
||||
+++ b/drivers/block/virtio_blk.c
|
||||
@@ -243,8 +243,8 @@ static int virtblk_ioctl(struct block_device *bdev, fmode_t mode,
|
||||
if (!virtio_has_feature(vblk->vdev, VIRTIO_BLK_F_SCSI))
|
||||
return -ENOTTY;
|
||||
|
||||
- return scsi_cmd_ioctl(disk->queue, disk, mode, cmd,
|
||||
- (void __user *)data);
|
||||
+ return scsi_cmd_blk_ioctl(bdev, mode, cmd,
|
||||
+ (void __user *)data);
|
||||
}
|
||||
|
||||
/* We provide getgeo only to please some old bootloader/partitioning tools */
|
||||
diff --git a/drivers/cdrom/cdrom.c b/drivers/cdrom/cdrom.c
|
||||
index f997c27..cedb231 100644
|
||||
--- a/drivers/cdrom/cdrom.c
|
||||
+++ b/drivers/cdrom/cdrom.c
|
||||
@@ -2747,12 +2747,11 @@ int cdrom_ioctl(struct cdrom_device_info *cdi, struct block_device *bdev,
|
||||
{
|
||||
void __user *argp = (void __user *)arg;
|
||||
int ret;
|
||||
- struct gendisk *disk = bdev->bd_disk;
|
||||
|
||||
/*
|
||||
* Try the generic SCSI command ioctl's first.
|
||||
*/
|
||||
- ret = scsi_cmd_ioctl(disk->queue, disk, mode, cmd, argp);
|
||||
+ ret = scsi_cmd_blk_ioctl(bdev, mode, cmd, argp);
|
||||
if (ret != -ENOTTY)
|
||||
return ret;
|
||||
|
||||
diff --git a/drivers/ide/ide-floppy_ioctl.c b/drivers/ide/ide-floppy_ioctl.c
|
||||
index d267b7a..a22ca84 100644
|
||||
--- a/drivers/ide/ide-floppy_ioctl.c
|
||||
+++ b/drivers/ide/ide-floppy_ioctl.c
|
||||
@@ -292,8 +292,7 @@ int ide_floppy_ioctl(ide_drive_t *drive, struct block_device *bdev,
|
||||
* and CDROM_SEND_PACKET (legacy) ioctls
|
||||
*/
|
||||
if (cmd != CDROM_SEND_PACKET && cmd != SCSI_IOCTL_SEND_COMMAND)
|
||||
- err = scsi_cmd_ioctl(bdev->bd_disk->queue, bdev->bd_disk,
|
||||
- mode, cmd, argp);
|
||||
+ err = scsi_cmd_blk_ioctl(bdev, mode, cmd, argp);
|
||||
|
||||
if (err == -ENOTTY)
|
||||
err = generic_ide_ioctl(drive, bdev, cmd, arg);
|
||||
diff --git a/drivers/scsi/sd.c b/drivers/scsi/sd.c
|
||||
index fa3a591..ffa1c79 100644
|
||||
--- a/drivers/scsi/sd.c
|
||||
+++ b/drivers/scsi/sd.c
|
||||
@@ -1096,7 +1096,7 @@ static int sd_ioctl(struct block_device *bdev, fmode_t mode,
|
||||
error = scsi_ioctl(sdp, cmd, p);
|
||||
break;
|
||||
default:
|
||||
- error = scsi_cmd_ioctl(disk->queue, disk, mode, cmd, p);
|
||||
+ error = scsi_cmd_blk_ioctl(bdev, mode, cmd, p);
|
||||
if (error != -ENOTTY)
|
||||
break;
|
||||
error = scsi_ioctl(sdp, cmd, p);
|
||||
diff --git a/include/linux/blkdev.h b/include/linux/blkdev.h
|
||||
index 94acd81..ca7b869 100644
|
||||
--- a/include/linux/blkdev.h
|
||||
+++ b/include/linux/blkdev.h
|
||||
@@ -675,6 +675,8 @@ extern int blk_insert_cloned_request(struct request_queue *q,
|
||||
struct request *rq);
|
||||
extern void blk_delay_queue(struct request_queue *, unsigned long);
|
||||
extern void blk_recount_segments(struct request_queue *, struct bio *);
|
||||
+extern int scsi_cmd_blk_ioctl(struct block_device *, fmode_t,
|
||||
+ unsigned int, void __user *);
|
||||
extern int scsi_cmd_ioctl(struct request_queue *, struct gendisk *, fmode_t,
|
||||
unsigned int, void __user *);
|
||||
extern int sg_scsi_ioctl(struct request_queue *, struct gendisk *, fmode_t,
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+166
@@ -0,0 +1,166 @@
|
||||
From b4bc30558b98e2eba6f6d86239d49bf3d60015cb Mon Sep 17 00:00:00 2001
|
||||
From: Paolo Bonzini <pbonzini@redhat.com>
|
||||
Date: Thu, 12 Jan 2012 16:01:28 +0100
|
||||
Subject: [PATCH 091/130] block: fail SCSI passthrough ioctls on partition
|
||||
devices
|
||||
|
||||
commit 0bfc96cb77224736dfa35c3c555d37b3646ef35e upstream.
|
||||
|
||||
[ Changes with respect to 3.3: return -ENOTTY from scsi_verify_blk_ioctl
|
||||
and -ENOIOCTLCMD from sd_compat_ioctl. ]
|
||||
|
||||
Linux allows executing the SG_IO ioctl on a partition or LVM volume, and
|
||||
will pass the command to the underlying block device. This is
|
||||
well-known, but it is also a large security problem when (via Unix
|
||||
permissions, ACLs, SELinux or a combination thereof) a program or user
|
||||
needs to be granted access only to part of the disk.
|
||||
|
||||
This patch lets partitions forward a small set of harmless ioctls;
|
||||
others are logged with printk so that we can see which ioctls are
|
||||
actually sent. In my tests only CDROM_GET_CAPABILITY actually occurred.
|
||||
Of course it was being sent to a (partition on a) hard disk, so it would
|
||||
have failed with ENOTTY and the patch isn't changing anything in
|
||||
practice. Still, I'm treating it specially to avoid spamming the logs.
|
||||
|
||||
In principle, this restriction should include programs running with
|
||||
CAP_SYS_RAWIO. If for example I let a program access /dev/sda2 and
|
||||
/dev/sdb, it still should not be able to read/write outside the
|
||||
boundaries of /dev/sda2 independent of the capabilities. However, for
|
||||
now programs with CAP_SYS_RAWIO will still be allowed to send the
|
||||
ioctls. Their actions will still be logged.
|
||||
|
||||
This patch does not affect the non-libata IDE driver. That driver
|
||||
however already tests for bd != bd->bd_contains before issuing some
|
||||
ioctl; it could be restricted further to forbid these ioctls even for
|
||||
programs running with CAP_SYS_ADMIN/CAP_SYS_RAWIO.
|
||||
|
||||
Cc: linux-scsi@vger.kernel.org
|
||||
Cc: Jens Axboe <axboe@kernel.dk>
|
||||
Cc: James Bottomley <JBottomley@parallels.com>
|
||||
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
|
||||
[ Make it also print the command name when warning - Linus ]
|
||||
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
block/scsi_ioctl.c | 45 +++++++++++++++++++++++++++++++++++++++++++++
|
||||
drivers/scsi/sd.c | 11 +++++++++--
|
||||
include/linux/blkdev.h | 1 +
|
||||
3 files changed, 55 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/block/scsi_ioctl.c b/block/scsi_ioctl.c
|
||||
index a2c11f3..688be8a 100644
|
||||
--- a/block/scsi_ioctl.c
|
||||
+++ b/block/scsi_ioctl.c
|
||||
@@ -24,6 +24,7 @@
|
||||
#include <linux/capability.h>
|
||||
#include <linux/completion.h>
|
||||
#include <linux/cdrom.h>
|
||||
+#include <linux/ratelimit.h>
|
||||
#include <linux/slab.h>
|
||||
#include <linux/times.h>
|
||||
#include <asm/uaccess.h>
|
||||
@@ -690,9 +691,53 @@ int scsi_cmd_ioctl(struct request_queue *q, struct gendisk *bd_disk, fmode_t mod
|
||||
}
|
||||
EXPORT_SYMBOL(scsi_cmd_ioctl);
|
||||
|
||||
+int scsi_verify_blk_ioctl(struct block_device *bd, unsigned int cmd)
|
||||
+{
|
||||
+ if (bd && bd == bd->bd_contains)
|
||||
+ return 0;
|
||||
+
|
||||
+ /* Actually none of these is particularly useful on a partition,
|
||||
+ * but they are safe.
|
||||
+ */
|
||||
+ switch (cmd) {
|
||||
+ case SCSI_IOCTL_GET_IDLUN:
|
||||
+ case SCSI_IOCTL_GET_BUS_NUMBER:
|
||||
+ case SCSI_IOCTL_GET_PCI:
|
||||
+ case SCSI_IOCTL_PROBE_HOST:
|
||||
+ case SG_GET_VERSION_NUM:
|
||||
+ case SG_SET_TIMEOUT:
|
||||
+ case SG_GET_TIMEOUT:
|
||||
+ case SG_GET_RESERVED_SIZE:
|
||||
+ case SG_SET_RESERVED_SIZE:
|
||||
+ case SG_EMULATED_HOST:
|
||||
+ return 0;
|
||||
+ case CDROM_GET_CAPABILITY:
|
||||
+ /* Keep this until we remove the printk below. udev sends it
|
||||
+ * and we do not want to spam dmesg about it. CD-ROMs do
|
||||
+ * not have partitions, so we get here only for disks.
|
||||
+ */
|
||||
+ return -ENOTTY;
|
||||
+ default:
|
||||
+ break;
|
||||
+ }
|
||||
+
|
||||
+ /* In particular, rule out all resets and host-specific ioctls. */
|
||||
+ printk_ratelimited(KERN_WARNING
|
||||
+ "%s: sending ioctl %x to a partition!\n", current->comm, cmd);
|
||||
+
|
||||
+ return capable(CAP_SYS_RAWIO) ? 0 : -ENOTTY;
|
||||
+}
|
||||
+EXPORT_SYMBOL(scsi_verify_blk_ioctl);
|
||||
+
|
||||
int scsi_cmd_blk_ioctl(struct block_device *bd, fmode_t mode,
|
||||
unsigned int cmd, void __user *arg)
|
||||
{
|
||||
+ int ret;
|
||||
+
|
||||
+ ret = scsi_verify_blk_ioctl(bd, cmd);
|
||||
+ if (ret < 0)
|
||||
+ return ret;
|
||||
+
|
||||
return scsi_cmd_ioctl(bd->bd_disk->queue, bd->bd_disk, mode, cmd, arg);
|
||||
}
|
||||
EXPORT_SYMBOL(scsi_cmd_blk_ioctl);
|
||||
diff --git a/drivers/scsi/sd.c b/drivers/scsi/sd.c
|
||||
index ffa1c79..4b63c73 100644
|
||||
--- a/drivers/scsi/sd.c
|
||||
+++ b/drivers/scsi/sd.c
|
||||
@@ -1074,6 +1074,10 @@ static int sd_ioctl(struct block_device *bdev, fmode_t mode,
|
||||
SCSI_LOG_IOCTL(1, sd_printk(KERN_INFO, sdkp, "sd_ioctl: disk=%s, "
|
||||
"cmd=0x%x\n", disk->disk_name, cmd));
|
||||
|
||||
+ error = scsi_verify_blk_ioctl(bdev, cmd);
|
||||
+ if (error < 0)
|
||||
+ return error;
|
||||
+
|
||||
/*
|
||||
* If we are in the middle of error recovery, don't let anyone
|
||||
* else try and use this device. Also, if error recovery fails, it
|
||||
@@ -1266,6 +1270,11 @@ static int sd_compat_ioctl(struct block_device *bdev, fmode_t mode,
|
||||
unsigned int cmd, unsigned long arg)
|
||||
{
|
||||
struct scsi_device *sdev = scsi_disk(bdev->bd_disk)->device;
|
||||
+ int ret;
|
||||
+
|
||||
+ ret = scsi_verify_blk_ioctl(bdev, cmd);
|
||||
+ if (ret < 0)
|
||||
+ return -ENOIOCTLCMD;
|
||||
|
||||
/*
|
||||
* If we are in the middle of error recovery, don't let anyone
|
||||
@@ -1277,8 +1286,6 @@ static int sd_compat_ioctl(struct block_device *bdev, fmode_t mode,
|
||||
return -ENODEV;
|
||||
|
||||
if (sdev->host->hostt->compat_ioctl) {
|
||||
- int ret;
|
||||
-
|
||||
ret = sdev->host->hostt->compat_ioctl(sdev, cmd, (void __user *)arg);
|
||||
|
||||
return ret;
|
||||
diff --git a/include/linux/blkdev.h b/include/linux/blkdev.h
|
||||
index ca7b869..0ed1eb0 100644
|
||||
--- a/include/linux/blkdev.h
|
||||
+++ b/include/linux/blkdev.h
|
||||
@@ -675,6 +675,7 @@ extern int blk_insert_cloned_request(struct request_queue *q,
|
||||
struct request *rq);
|
||||
extern void blk_delay_queue(struct request_queue *, unsigned long);
|
||||
extern void blk_recount_segments(struct request_queue *, struct bio *);
|
||||
+extern int scsi_verify_blk_ioctl(struct block_device *, unsigned int);
|
||||
extern int scsi_cmd_blk_ioctl(struct block_device *, fmode_t,
|
||||
unsigned int, void __user *);
|
||||
extern int scsi_cmd_ioctl(struct request_queue *, struct gendisk *, fmode_t,
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+90
@@ -0,0 +1,90 @@
|
||||
From eb8de39f8d8116261b98f971f3e3e2230fa3abcf Mon Sep 17 00:00:00 2001
|
||||
From: Paolo Bonzini <pbonzini@redhat.com>
|
||||
Date: Thu, 12 Jan 2012 16:01:29 +0100
|
||||
Subject: [PATCH 092/130] dm: do not forward ioctls from logical volumes to
|
||||
the underlying device
|
||||
|
||||
commit ec8013beddd717d1740cfefb1a9b900deef85462 upstream.
|
||||
|
||||
A logical volume can map to just part of underlying physical volume.
|
||||
In this case, it must be treated like a partition.
|
||||
|
||||
Based on a patch from Alasdair G Kergon.
|
||||
|
||||
Cc: Alasdair G Kergon <agk@redhat.com>
|
||||
Cc: dm-devel@redhat.com
|
||||
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
|
||||
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/md/dm-flakey.c | 11 ++++++++++-
|
||||
drivers/md/dm-linear.c | 12 +++++++++++-
|
||||
drivers/md/dm-mpath.c | 6 ++++++
|
||||
3 files changed, 27 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/drivers/md/dm-flakey.c b/drivers/md/dm-flakey.c
|
||||
index f84c080..9fb18c1 100644
|
||||
--- a/drivers/md/dm-flakey.c
|
||||
+++ b/drivers/md/dm-flakey.c
|
||||
@@ -368,8 +368,17 @@ static int flakey_status(struct dm_target *ti, status_type_t type,
|
||||
static int flakey_ioctl(struct dm_target *ti, unsigned int cmd, unsigned long arg)
|
||||
{
|
||||
struct flakey_c *fc = ti->private;
|
||||
+ struct dm_dev *dev = fc->dev;
|
||||
+ int r = 0;
|
||||
|
||||
- return __blkdev_driver_ioctl(fc->dev->bdev, fc->dev->mode, cmd, arg);
|
||||
+ /*
|
||||
+ * Only pass ioctls through if the device sizes match exactly.
|
||||
+ */
|
||||
+ if (fc->start ||
|
||||
+ ti->len != i_size_read(dev->bdev->bd_inode) >> SECTOR_SHIFT)
|
||||
+ r = scsi_verify_blk_ioctl(NULL, cmd);
|
||||
+
|
||||
+ return r ? : __blkdev_driver_ioctl(dev->bdev, dev->mode, cmd, arg);
|
||||
}
|
||||
|
||||
static int flakey_merge(struct dm_target *ti, struct bvec_merge_data *bvm,
|
||||
diff --git a/drivers/md/dm-linear.c b/drivers/md/dm-linear.c
|
||||
index 3921e3b..9728839 100644
|
||||
--- a/drivers/md/dm-linear.c
|
||||
+++ b/drivers/md/dm-linear.c
|
||||
@@ -116,7 +116,17 @@ static int linear_ioctl(struct dm_target *ti, unsigned int cmd,
|
||||
unsigned long arg)
|
||||
{
|
||||
struct linear_c *lc = (struct linear_c *) ti->private;
|
||||
- return __blkdev_driver_ioctl(lc->dev->bdev, lc->dev->mode, cmd, arg);
|
||||
+ struct dm_dev *dev = lc->dev;
|
||||
+ int r = 0;
|
||||
+
|
||||
+ /*
|
||||
+ * Only pass ioctls through if the device sizes match exactly.
|
||||
+ */
|
||||
+ if (lc->start ||
|
||||
+ ti->len != i_size_read(dev->bdev->bd_inode) >> SECTOR_SHIFT)
|
||||
+ r = scsi_verify_blk_ioctl(NULL, cmd);
|
||||
+
|
||||
+ return r ? : __blkdev_driver_ioctl(dev->bdev, dev->mode, cmd, arg);
|
||||
}
|
||||
|
||||
static int linear_merge(struct dm_target *ti, struct bvec_merge_data *bvm,
|
||||
diff --git a/drivers/md/dm-mpath.c b/drivers/md/dm-mpath.c
|
||||
index 5e0090e..801d92d 100644
|
||||
--- a/drivers/md/dm-mpath.c
|
||||
+++ b/drivers/md/dm-mpath.c
|
||||
@@ -1520,6 +1520,12 @@ static int multipath_ioctl(struct dm_target *ti, unsigned int cmd,
|
||||
|
||||
spin_unlock_irqrestore(&m->lock, flags);
|
||||
|
||||
+ /*
|
||||
+ * Only pass ioctls through if the device sizes match exactly.
|
||||
+ */
|
||||
+ if (!r && ti->len != i_size_read(bdev->bd_inode) >> SECTOR_SHIFT)
|
||||
+ r = scsi_verify_blk_ioctl(NULL, cmd);
|
||||
+
|
||||
return r ? : __blkdev_driver_ioctl(bdev, mode, cmd, arg);
|
||||
}
|
||||
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+271
@@ -0,0 +1,271 @@
|
||||
From 483f23031ea337d0abf4392186bdfd2b8ae5dce3 Mon Sep 17 00:00:00 2001
|
||||
From: Linus Torvalds <torvalds@linux-foundation.org>
|
||||
Date: Tue, 17 Jan 2012 15:21:19 -0800
|
||||
Subject: [PATCH 093/130] proc: clean up and fix /proc/<pid>/mem handling
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
commit e268337dfe26dfc7efd422a804dbb27977a3cccc upstream.
|
||||
|
||||
Jüri Aedla reported that the /proc/<pid>/mem handling really isn't very
|
||||
robust, and it also doesn't match the permission checking of any of the
|
||||
other related files.
|
||||
|
||||
This changes it to do the permission checks at open time, and instead of
|
||||
tracking the process, it tracks the VM at the time of the open. That
|
||||
simplifies the code a lot, but does mean that if you hold the file
|
||||
descriptor open over an execve(), you'll continue to read from the _old_
|
||||
VM.
|
||||
|
||||
That is different from our previous behavior, but much simpler. If
|
||||
somebody actually finds a load where this matters, we'll need to revert
|
||||
this commit.
|
||||
|
||||
I suspect that nobody will ever notice - because the process mapping
|
||||
addresses will also have changed as part of the execve. So you cannot
|
||||
actually usefully access the fd across a VM change simply because all
|
||||
the offsets for IO would have changed too.
|
||||
|
||||
Reported-by: Jüri Aedla <asd@ut.ee>
|
||||
Cc: Al Viro <viro@zeniv.linux.org.uk>
|
||||
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
fs/proc/base.c | 145 +++++++++++++++-----------------------------------------
|
||||
1 files changed, 39 insertions(+), 106 deletions(-)
|
||||
|
||||
diff --git a/fs/proc/base.c b/fs/proc/base.c
|
||||
index 851ba3d..1fc1dca 100644
|
||||
--- a/fs/proc/base.c
|
||||
+++ b/fs/proc/base.c
|
||||
@@ -194,65 +194,7 @@ static int proc_root_link(struct inode *inode, struct path *path)
|
||||
return result;
|
||||
}
|
||||
|
||||
-static struct mm_struct *__check_mem_permission(struct task_struct *task)
|
||||
-{
|
||||
- struct mm_struct *mm;
|
||||
-
|
||||
- mm = get_task_mm(task);
|
||||
- if (!mm)
|
||||
- return ERR_PTR(-EINVAL);
|
||||
-
|
||||
- /*
|
||||
- * A task can always look at itself, in case it chooses
|
||||
- * to use system calls instead of load instructions.
|
||||
- */
|
||||
- if (task == current)
|
||||
- return mm;
|
||||
-
|
||||
- /*
|
||||
- * If current is actively ptrace'ing, and would also be
|
||||
- * permitted to freshly attach with ptrace now, permit it.
|
||||
- */
|
||||
- if (task_is_stopped_or_traced(task)) {
|
||||
- int match;
|
||||
- rcu_read_lock();
|
||||
- match = (ptrace_parent(task) == current);
|
||||
- rcu_read_unlock();
|
||||
- if (match && ptrace_may_access(task, PTRACE_MODE_ATTACH))
|
||||
- return mm;
|
||||
- }
|
||||
-
|
||||
- /*
|
||||
- * No one else is allowed.
|
||||
- */
|
||||
- mmput(mm);
|
||||
- return ERR_PTR(-EPERM);
|
||||
-}
|
||||
-
|
||||
-/*
|
||||
- * If current may access user memory in @task return a reference to the
|
||||
- * corresponding mm, otherwise ERR_PTR.
|
||||
- */
|
||||
-static struct mm_struct *check_mem_permission(struct task_struct *task)
|
||||
-{
|
||||
- struct mm_struct *mm;
|
||||
- int err;
|
||||
-
|
||||
- /*
|
||||
- * Avoid racing if task exec's as we might get a new mm but validate
|
||||
- * against old credentials.
|
||||
- */
|
||||
- err = mutex_lock_killable(&task->signal->cred_guard_mutex);
|
||||
- if (err)
|
||||
- return ERR_PTR(err);
|
||||
-
|
||||
- mm = __check_mem_permission(task);
|
||||
- mutex_unlock(&task->signal->cred_guard_mutex);
|
||||
-
|
||||
- return mm;
|
||||
-}
|
||||
-
|
||||
-struct mm_struct *mm_for_maps(struct task_struct *task)
|
||||
+static struct mm_struct *mm_access(struct task_struct *task, unsigned int mode)
|
||||
{
|
||||
struct mm_struct *mm;
|
||||
int err;
|
||||
@@ -263,7 +205,7 @@ struct mm_struct *mm_for_maps(struct task_struct *task)
|
||||
|
||||
mm = get_task_mm(task);
|
||||
if (mm && mm != current->mm &&
|
||||
- !ptrace_may_access(task, PTRACE_MODE_READ)) {
|
||||
+ !ptrace_may_access(task, mode)) {
|
||||
mmput(mm);
|
||||
mm = ERR_PTR(-EACCES);
|
||||
}
|
||||
@@ -272,6 +214,11 @@ struct mm_struct *mm_for_maps(struct task_struct *task)
|
||||
return mm;
|
||||
}
|
||||
|
||||
+struct mm_struct *mm_for_maps(struct task_struct *task)
|
||||
+{
|
||||
+ return mm_access(task, PTRACE_MODE_READ);
|
||||
+}
|
||||
+
|
||||
static int proc_pid_cmdline(struct task_struct *task, char * buffer)
|
||||
{
|
||||
int res = 0;
|
||||
@@ -816,38 +763,39 @@ static const struct file_operations proc_single_file_operations = {
|
||||
|
||||
static int mem_open(struct inode* inode, struct file* file)
|
||||
{
|
||||
- file->private_data = (void*)((long)current->self_exec_id);
|
||||
+ struct task_struct *task = get_proc_task(file->f_path.dentry->d_inode);
|
||||
+ struct mm_struct *mm;
|
||||
+
|
||||
+ if (!task)
|
||||
+ return -ESRCH;
|
||||
+
|
||||
+ mm = mm_access(task, PTRACE_MODE_ATTACH);
|
||||
+ put_task_struct(task);
|
||||
+
|
||||
+ if (IS_ERR(mm))
|
||||
+ return PTR_ERR(mm);
|
||||
+
|
||||
/* OK to pass negative loff_t, we can catch out-of-range */
|
||||
file->f_mode |= FMODE_UNSIGNED_OFFSET;
|
||||
+ file->private_data = mm;
|
||||
+
|
||||
return 0;
|
||||
}
|
||||
|
||||
static ssize_t mem_read(struct file * file, char __user * buf,
|
||||
size_t count, loff_t *ppos)
|
||||
{
|
||||
- struct task_struct *task = get_proc_task(file->f_path.dentry->d_inode);
|
||||
+ int ret;
|
||||
char *page;
|
||||
unsigned long src = *ppos;
|
||||
- int ret = -ESRCH;
|
||||
- struct mm_struct *mm;
|
||||
+ struct mm_struct *mm = file->private_data;
|
||||
|
||||
- if (!task)
|
||||
- goto out_no_task;
|
||||
+ if (!mm)
|
||||
+ return 0;
|
||||
|
||||
- ret = -ENOMEM;
|
||||
page = (char *)__get_free_page(GFP_TEMPORARY);
|
||||
if (!page)
|
||||
- goto out;
|
||||
-
|
||||
- mm = check_mem_permission(task);
|
||||
- ret = PTR_ERR(mm);
|
||||
- if (IS_ERR(mm))
|
||||
- goto out_free;
|
||||
-
|
||||
- ret = -EIO;
|
||||
-
|
||||
- if (file->private_data != (void*)((long)current->self_exec_id))
|
||||
- goto out_put;
|
||||
+ return -ENOMEM;
|
||||
|
||||
ret = 0;
|
||||
|
||||
@@ -874,13 +822,7 @@ static ssize_t mem_read(struct file * file, char __user * buf,
|
||||
}
|
||||
*ppos = src;
|
||||
|
||||
-out_put:
|
||||
- mmput(mm);
|
||||
-out_free:
|
||||
free_page((unsigned long) page);
|
||||
-out:
|
||||
- put_task_struct(task);
|
||||
-out_no_task:
|
||||
return ret;
|
||||
}
|
||||
|
||||
@@ -889,27 +831,15 @@ static ssize_t mem_write(struct file * file, const char __user *buf,
|
||||
{
|
||||
int copied;
|
||||
char *page;
|
||||
- struct task_struct *task = get_proc_task(file->f_path.dentry->d_inode);
|
||||
unsigned long dst = *ppos;
|
||||
- struct mm_struct *mm;
|
||||
+ struct mm_struct *mm = file->private_data;
|
||||
|
||||
- copied = -ESRCH;
|
||||
- if (!task)
|
||||
- goto out_no_task;
|
||||
+ if (!mm)
|
||||
+ return 0;
|
||||
|
||||
- copied = -ENOMEM;
|
||||
page = (char *)__get_free_page(GFP_TEMPORARY);
|
||||
if (!page)
|
||||
- goto out_task;
|
||||
-
|
||||
- mm = check_mem_permission(task);
|
||||
- copied = PTR_ERR(mm);
|
||||
- if (IS_ERR(mm))
|
||||
- goto out_free;
|
||||
-
|
||||
- copied = -EIO;
|
||||
- if (file->private_data != (void *)((long)current->self_exec_id))
|
||||
- goto out_mm;
|
||||
+ return -ENOMEM;
|
||||
|
||||
copied = 0;
|
||||
while (count > 0) {
|
||||
@@ -933,13 +863,7 @@ static ssize_t mem_write(struct file * file, const char __user *buf,
|
||||
}
|
||||
*ppos = dst;
|
||||
|
||||
-out_mm:
|
||||
- mmput(mm);
|
||||
-out_free:
|
||||
free_page((unsigned long) page);
|
||||
-out_task:
|
||||
- put_task_struct(task);
|
||||
-out_no_task:
|
||||
return copied;
|
||||
}
|
||||
|
||||
@@ -959,11 +883,20 @@ loff_t mem_lseek(struct file *file, loff_t offset, int orig)
|
||||
return file->f_pos;
|
||||
}
|
||||
|
||||
+static int mem_release(struct inode *inode, struct file *file)
|
||||
+{
|
||||
+ struct mm_struct *mm = file->private_data;
|
||||
+
|
||||
+ mmput(mm);
|
||||
+ return 0;
|
||||
+}
|
||||
+
|
||||
static const struct file_operations proc_mem_operations = {
|
||||
.llseek = mem_lseek,
|
||||
.read = mem_read,
|
||||
.write = mem_write,
|
||||
.open = mem_open,
|
||||
+ .release = mem_release,
|
||||
};
|
||||
|
||||
static ssize_t environ_read(struct file *file, char __user *buf,
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+35
@@ -0,0 +1,35 @@
|
||||
From 19c9fdb5e8d481a2a13b437ef124486808a35726 Mon Sep 17 00:00:00 2001
|
||||
From: David Henningsson <david.henningsson@canonical.com>
|
||||
Date: Thu, 12 Jan 2012 16:31:14 +0100
|
||||
Subject: [PATCH 094/130] ALSA: HDA: Use LPIB position fix for Macbook Pro 7,1
|
||||
|
||||
commit b01de4fb40137fbda7530550ff0cd37171dafb0c upstream.
|
||||
|
||||
Several users have reported "choppy" audio under the 3.2 kernel,
|
||||
and that changing position_fix to 1 has resolved their problem.
|
||||
The chip is an nVidia Corporation MCP89 High Definition Audio,
|
||||
[10de:0d94] (rev a2).
|
||||
|
||||
BugLink: https://bugs.launchpad.net/bugs/909419
|
||||
Signed-off-by: David Henningsson <david.henningsson@canonical.com>
|
||||
Signed-off-by: Takashi Iwai <tiwai@suse.de>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
sound/pci/hda/hda_intel.c | 1 +
|
||||
1 files changed, 1 insertions(+), 0 deletions(-)
|
||||
|
||||
diff --git a/sound/pci/hda/hda_intel.c b/sound/pci/hda/hda_intel.c
|
||||
index c2f79e6..5b2b75b 100644
|
||||
--- a/sound/pci/hda/hda_intel.c
|
||||
+++ b/sound/pci/hda/hda_intel.c
|
||||
@@ -2509,6 +2509,7 @@ static struct snd_pci_quirk position_fix_list[] __devinitdata = {
|
||||
SND_PCI_QUIRK(0x1043, 0x81e7, "ASUS M2V", POS_FIX_LPIB),
|
||||
SND_PCI_QUIRK(0x1043, 0x83ce, "ASUS 1101HA", POS_FIX_LPIB),
|
||||
SND_PCI_QUIRK(0x104d, 0x9069, "Sony VPCS11V9E", POS_FIX_LPIB),
|
||||
+ SND_PCI_QUIRK(0x10de, 0xcb89, "Macbook Pro 7,1", POS_FIX_LPIB),
|
||||
SND_PCI_QUIRK(0x1297, 0x3166, "Shuttle", POS_FIX_LPIB),
|
||||
SND_PCI_QUIRK(0x1458, 0xa022, "ga-ma770-ud3", POS_FIX_LPIB),
|
||||
SND_PCI_QUIRK(0x1462, 0x1002, "MSI Wind U115", POS_FIX_LPIB),
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+37
@@ -0,0 +1,37 @@
|
||||
From a199c605727cb1fd45800b12ede56637c027e0a2 Mon Sep 17 00:00:00 2001
|
||||
From: Clemens Ladisch <clemens@ladisch.de>
|
||||
Date: Sat, 14 Jan 2012 16:42:24 +0100
|
||||
Subject: [PATCH 095/130] ALSA: virtuoso: Xonar DS: fix polarity of front
|
||||
output
|
||||
|
||||
commit f0e48b6bd4e407459715240cd241ddb6b89bdf81 upstream.
|
||||
|
||||
The two DACs for the front output and the surround/center/LFE/back
|
||||
outputs are wired up out of phase, so when channels are duplicated,
|
||||
their sound can cancel out each other and result in a weaker bass
|
||||
response. To fix this, reverse the polarity of the neutron flow to
|
||||
the front output.
|
||||
|
||||
Reported-any-tested-by: Daniel Hill <daniel@enemyplanet.geek.nz>
|
||||
Signed-off-by: Clemens Ladisch <clemens@ladisch.de>
|
||||
Signed-off-by: Takashi Iwai <tiwai@suse.de>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
sound/pci/oxygen/xonar_wm87x6.c | 1 +
|
||||
1 files changed, 1 insertions(+), 0 deletions(-)
|
||||
|
||||
diff --git a/sound/pci/oxygen/xonar_wm87x6.c b/sound/pci/oxygen/xonar_wm87x6.c
|
||||
index 42d1ab1..915546a 100644
|
||||
--- a/sound/pci/oxygen/xonar_wm87x6.c
|
||||
+++ b/sound/pci/oxygen/xonar_wm87x6.c
|
||||
@@ -177,6 +177,7 @@ static void wm8776_registers_init(struct oxygen *chip)
|
||||
struct xonar_wm87x6 *data = chip->model_data;
|
||||
|
||||
wm8776_write(chip, WM8776_RESET, 0);
|
||||
+ wm8776_write(chip, WM8776_PHASESWAP, WM8776_PH_MASK);
|
||||
wm8776_write(chip, WM8776_DACCTRL1, WM8776_DZCEN |
|
||||
WM8776_PL_LEFT_LEFT | WM8776_PL_RIGHT_RIGHT);
|
||||
wm8776_write(chip, WM8776_DACMUTE, chip->dac_mute ? WM8776_DMUTE : 0);
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+36
@@ -0,0 +1,36 @@
|
||||
From 6ddbb15e9a2b460a42697a83ab2b4119978af8c8 Mon Sep 17 00:00:00 2001
|
||||
From: David Henningsson <david.henningsson@canonical.com>
|
||||
Date: Mon, 16 Jan 2012 10:52:20 +0100
|
||||
Subject: [PATCH 096/130] ALSA: HDA: Fix internal microphone on Dell Studio 16
|
||||
XPS 1645
|
||||
|
||||
commit ffe535edb9a9c5b4d5fe03dfa3d89a1495580f1b upstream.
|
||||
|
||||
More than one user reports that changing the model from "both" to
|
||||
"dmic" makes their Internal Mic work.
|
||||
|
||||
Tested-by: Martin Ling <martin-launchpad@earth.li>
|
||||
BugLink: https://bugs.launchpad.net/bugs/795823
|
||||
Signed-off-by: David Henningsson <david.henningsson@canonical.com>
|
||||
Signed-off-by: Takashi Iwai <tiwai@suse.de>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
sound/pci/hda/patch_sigmatel.c | 2 +-
|
||||
1 files changed, 1 insertions(+), 1 deletions(-)
|
||||
|
||||
diff --git a/sound/pci/hda/patch_sigmatel.c b/sound/pci/hda/patch_sigmatel.c
|
||||
index a87b260..f3c73a9 100644
|
||||
--- a/sound/pci/hda/patch_sigmatel.c
|
||||
+++ b/sound/pci/hda/patch_sigmatel.c
|
||||
@@ -1631,7 +1631,7 @@ static const struct snd_pci_quirk stac92hd73xx_cfg_tbl[] = {
|
||||
SND_PCI_QUIRK(PCI_VENDOR_ID_DELL, 0x02bd,
|
||||
"Dell Studio 1557", STAC_DELL_M6_DMIC),
|
||||
SND_PCI_QUIRK(PCI_VENDOR_ID_DELL, 0x02fe,
|
||||
- "Dell Studio XPS 1645", STAC_DELL_M6_BOTH),
|
||||
+ "Dell Studio XPS 1645", STAC_DELL_M6_DMIC),
|
||||
SND_PCI_QUIRK(PCI_VENDOR_ID_DELL, 0x0413,
|
||||
"Dell Studio 1558", STAC_DELL_M6_DMIC),
|
||||
{} /* terminator */
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+43
@@ -0,0 +1,43 @@
|
||||
From 4e99d3453e09872ef6979dfe1518b80377fa5134 Mon Sep 17 00:00:00 2001
|
||||
From: Tetsuo Handa <from-tomoyo-users-en@I-love.SAKURA.ne.jp>
|
||||
Date: Sun, 15 Jan 2012 11:05:59 +0900
|
||||
Subject: [PATCH 097/130] TOMOYO: Accept \000 as a valid character.
|
||||
|
||||
commit 25add8cf99c9ec8b8dc0acd8b9241e963fc0d29c upstream.
|
||||
|
||||
TOMOYO 2.5 in Linux 3.2 and later handles Unix domain socket's address.
|
||||
Thus, tomoyo_correct_word2() needs to accept \000 as a valid character, or
|
||||
TOMOYO 2.5 cannot handle Unix domain's abstract socket address.
|
||||
|
||||
Reported-by: Steven Allen <steven@stebalien.com>
|
||||
Signed-off-by: Tetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp>
|
||||
Signed-off-by: James Morris <jmorris@namei.org>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
security/tomoyo/util.c | 6 +++---
|
||||
1 files changed, 3 insertions(+), 3 deletions(-)
|
||||
|
||||
diff --git a/security/tomoyo/util.c b/security/tomoyo/util.c
|
||||
index 4a9b4b2..867558c 100644
|
||||
--- a/security/tomoyo/util.c
|
||||
+++ b/security/tomoyo/util.c
|
||||
@@ -492,13 +492,13 @@ static bool tomoyo_correct_word2(const char *string, size_t len)
|
||||
if (d < '0' || d > '7' || e < '0' || e > '7')
|
||||
break;
|
||||
c = tomoyo_make_byte(c, d, e);
|
||||
- if (tomoyo_invalid(c))
|
||||
- continue; /* pattern is not \000 */
|
||||
+ if (c <= ' ' || c >= 127)
|
||||
+ continue;
|
||||
}
|
||||
goto out;
|
||||
} else if (in_repetition && c == '/') {
|
||||
goto out;
|
||||
- } else if (tomoyo_invalid(c)) {
|
||||
+ } else if (c <= ' ' || c >= 127) {
|
||||
goto out;
|
||||
}
|
||||
}
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+53
@@ -0,0 +1,53 @@
|
||||
From 1ca189655bf3edf14c4837eba5873fc9c50f7e15 Mon Sep 17 00:00:00 2001
|
||||
From: Thomas Renninger <trenn@suse.de>
|
||||
Date: Sun, 4 Dec 2011 22:17:29 +0100
|
||||
Subject: [PATCH 098/130] intel idle: Make idle driver more robust
|
||||
|
||||
commit 5c2a9f06a9cd7194f884cdc88144866235dec07d upstream.
|
||||
|
||||
kvm -cpu host passes the original cpuid info to the guest.
|
||||
|
||||
Latest kvm version seem to return true for mwait_leaf cpuid
|
||||
function on recent Intel CPUs. But it does not return mwait
|
||||
C-states (mwait_substates), instead zero is returned.
|
||||
|
||||
While real CPUs seem to always return non-zero values, the intel
|
||||
idle driver should not get active in kvm (mwait_substates == 0)
|
||||
case and bail out.
|
||||
Otherwise a Null pointer exception will happen later when the
|
||||
cpuidle subsystem tries to get active:
|
||||
[0.984807] BUG: unable to handle kernel NULL pointer dereference at (null)
|
||||
[0.984807] IP: [<(null)>] (null)
|
||||
...
|
||||
[0.984807][<ffffffff8143cf34>] ? cpuidle_idle_call+0xb4/0x340
|
||||
[0.984807][<ffffffff8159e7bc>] ? __atomic_notifier_call_chain+0x4c/0x70
|
||||
[0.984807][<ffffffff81001198>] ? cpu_idle+0x78/0xd0
|
||||
|
||||
Reference:
|
||||
https://bugzilla.novell.com/show_bug.cgi?id=726296
|
||||
|
||||
Signed-off-by: Thomas Renninger <trenn@suse.de>
|
||||
CC: Bruno Friedmann <bruno@ioda-net.ch>
|
||||
Signed-off-by: Len Brown <len.brown@intel.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/idle/intel_idle.c | 3 ++-
|
||||
1 files changed, 2 insertions(+), 1 deletions(-)
|
||||
|
||||
diff --git a/drivers/idle/intel_idle.c b/drivers/idle/intel_idle.c
|
||||
index 5d2f8e1..1dafcc3 100644
|
||||
--- a/drivers/idle/intel_idle.c
|
||||
+++ b/drivers/idle/intel_idle.c
|
||||
@@ -348,7 +348,8 @@ static int intel_idle_probe(void)
|
||||
cpuid(CPUID_MWAIT_LEAF, &eax, &ebx, &ecx, &mwait_substates);
|
||||
|
||||
if (!(ecx & CPUID5_ECX_EXTENSIONS_SUPPORTED) ||
|
||||
- !(ecx & CPUID5_ECX_INTERRUPT_BREAK))
|
||||
+ !(ecx & CPUID5_ECX_INTERRUPT_BREAK) ||
|
||||
+ !mwait_substates)
|
||||
return -ENODEV;
|
||||
|
||||
pr_debug(PREFIX "MWAIT substates: 0x%x\n", mwait_substates);
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
@@ -0,0 +1,56 @@
|
||||
From aaeec055d714b03aededdf7bd4eb75415e16f1ce Mon Sep 17 00:00:00 2001
|
||||
From: Shaohua Li <shaohua.li@intel.com>
|
||||
Date: Tue, 10 Jan 2012 15:48:19 -0800
|
||||
Subject: [PATCH 099/130] intel_idle: fix API misuse
|
||||
|
||||
commit 39a74fdedd1c1461d6fb6d330b5266886513c98f upstream.
|
||||
|
||||
smp_call_function() only lets all other CPUs execute a specific function,
|
||||
while we expect all CPUs do in intel_idle. Without the fix, we could have
|
||||
one cpu which has auto_demotion enabled or has no broadcast timer setup.
|
||||
Usually we don't see impact because auto demotion just harms power and the
|
||||
intel_idle init is called in CPU 0, where boradcast timer delivers
|
||||
interrupt, but this still could be a problem.
|
||||
|
||||
Signed-off-by: Shaohua Li <shaohua.li@intel.com>
|
||||
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
|
||||
Signed-off-by: Len Brown <len.brown@intel.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/idle/intel_idle.c | 6 +++---
|
||||
1 files changed, 3 insertions(+), 3 deletions(-)
|
||||
|
||||
diff --git a/drivers/idle/intel_idle.c b/drivers/idle/intel_idle.c
|
||||
index 1dafcc3..5b39216 100644
|
||||
--- a/drivers/idle/intel_idle.c
|
||||
+++ b/drivers/idle/intel_idle.c
|
||||
@@ -395,7 +395,7 @@ static int intel_idle_probe(void)
|
||||
if (boot_cpu_has(X86_FEATURE_ARAT)) /* Always Reliable APIC Timer */
|
||||
lapic_timer_reliable_states = LAPIC_TIMER_ALWAYS_RELIABLE;
|
||||
else {
|
||||
- smp_call_function(__setup_broadcast_timer, (void *)true, 1);
|
||||
+ on_each_cpu(__setup_broadcast_timer, (void *)true, 1);
|
||||
register_cpu_notifier(&setup_broadcast_notifier);
|
||||
}
|
||||
|
||||
@@ -472,7 +472,7 @@ static int intel_idle_cpuidle_driver_init(void)
|
||||
}
|
||||
|
||||
if (auto_demotion_disable_flags)
|
||||
- smp_call_function(auto_demotion_disable, NULL, 1);
|
||||
+ on_each_cpu(auto_demotion_disable, NULL, 1);
|
||||
|
||||
return 0;
|
||||
}
|
||||
@@ -569,7 +569,7 @@ static void __exit intel_idle_exit(void)
|
||||
cpuidle_unregister_driver(&intel_idle_driver);
|
||||
|
||||
if (lapic_timer_reliable_states != LAPIC_TIMER_ALWAYS_RELIABLE) {
|
||||
- smp_call_function(__setup_broadcast_timer, (void *)false, 1);
|
||||
+ on_each_cpu(__setup_broadcast_timer, (void *)false, 1);
|
||||
unregister_cpu_notifier(&setup_broadcast_notifier);
|
||||
}
|
||||
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
+66
@@ -0,0 +1,66 @@
|
||||
From 30301eff41ac5268c71f2790e22d600785cd2664 Mon Sep 17 00:00:00 2001
|
||||
From: Kurt Garloff <kurt@garloff.de>
|
||||
Date: Tue, 17 Jan 2012 04:18:02 -0500
|
||||
Subject: [PATCH 100/130] ACPI: Store SRAT table revision
|
||||
|
||||
commit 8df0eb7c9d96f9e82f233ee8b74e0f0c8471f868 upstream.
|
||||
|
||||
In SRAT v1, we had 8bit proximity domain (PXM) fields; SRAT v2 provides
|
||||
32bits for these. The new fields were reserved before.
|
||||
According to the ACPI spec, the OS must disregrard reserved fields.
|
||||
In order to know whether or not, we must know what version the SRAT
|
||||
table has.
|
||||
|
||||
This patch stores the SRAT table revision for later consumption
|
||||
by arch specific __init functions.
|
||||
|
||||
Signed-off-by: Kurt Garloff <kurt@garloff.de>
|
||||
Signed-off-by: Len Brown <len.brown@intel.com>
|
||||
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
|
||||
---
|
||||
drivers/acpi/numa.c | 6 ++++++
|
||||
include/acpi/acpi_numa.h | 1 +
|
||||
2 files changed, 7 insertions(+), 0 deletions(-)
|
||||
|
||||
diff --git a/drivers/acpi/numa.c b/drivers/acpi/numa.c
|
||||
index 3b5c318..e56f3be 100644
|
||||
--- a/drivers/acpi/numa.c
|
||||
+++ b/drivers/acpi/numa.c
|
||||
@@ -45,6 +45,8 @@ static int pxm_to_node_map[MAX_PXM_DOMAINS]
|
||||
static int node_to_pxm_map[MAX_NUMNODES]
|
||||
= { [0 ... MAX_NUMNODES - 1] = PXM_INVAL };
|
||||
|
||||
+unsigned char acpi_srat_revision __initdata;
|
||||
+
|
||||
int pxm_to_node(int pxm)
|
||||
{
|
||||
if (pxm < 0)
|
||||
@@ -255,9 +257,13 @@ acpi_parse_memory_affinity(struct acpi_subtable_header * header,
|
||||
|
||||
static int __init acpi_parse_srat(struct acpi_table_header *table)
|
||||
{
|
||||
+ struct acpi_table_srat *srat;
|
||||
if (!table)
|
||||
return -EINVAL;
|
||||
|
||||
+ srat = (struct acpi_table_srat *)table;
|
||||
+ acpi_srat_revision = srat->header.revision;
|
||||
+
|
||||
/* Real work done in acpi_table_parse_srat below. */
|
||||
|
||||
return 0;
|
||||
diff --git a/include/acpi/acpi_numa.h b/include/acpi/acpi_numa.h
|
||||
index 1739726..451823c 100644
|
||||
--- a/include/acpi/acpi_numa.h
|
||||
+++ b/include/acpi/acpi_numa.h
|
||||
@@ -15,6 +15,7 @@ extern int pxm_to_node(int);
|
||||
extern int node_to_pxm(int);
|
||||
extern void __acpi_map_pxm_to_node(int, int);
|
||||
extern int acpi_map_pxm_to_node(int);
|
||||
+extern unsigned char acpi_srat_revision;
|
||||
|
||||
#endif /* CONFIG_ACPI_NUMA */
|
||||
#endif /* __ACP_NUMA_H */
|
||||
--
|
||||
1.7.7.4
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user