drivers rebuild
This commit is contained in:
Binary file not shown.
-57
@@ -1,57 +0,0 @@
|
||||
From 12d868964f7352e8b18e755488f7265a93431de1 Mon Sep 17 00:00:00 2001
|
||||
From: Dmitry Tunin <hanipouspilot@gmail.com>
|
||||
Date: Tue, 12 Jul 2016 01:35:18 +0300
|
||||
Subject: [PATCH] Bluetooth: Add support of 13d3:3490 AR3012 device
|
||||
|
||||
T: Bus=01 Lev=01 Prnt=01 Port=07 Cnt=05 Dev#= 5 Spd=12 MxCh= 0
|
||||
D: Ver= 1.10 Cls=e0(wlcon) Sub=01 Prot=01 MxPS=64 #Cfgs= 1
|
||||
P: Vendor=13d3 ProdID=3490 Rev=00.01
|
||||
C: #Ifs= 2 Cfg#= 1 Atr=e0 MxPwr=100mA
|
||||
I: If#= 0 Alt= 0 #EPs= 3 Cls=e0(wlcon) Sub=01 Prot=01 Driver=btusb
|
||||
I: If#= 1 Alt= 0 #EPs= 2 Cls=e0(wlcon) Sub=01 Prot=01 Driver=btusb
|
||||
|
||||
BugLink: https://bugs.launchpad.net/bugs/1600623
|
||||
|
||||
Signed-off-by: Dmitry Tunin <hanipouspilot@gmail.com>
|
||||
Signed-off-by: Marcel Holtmann <marcel@holtmann.org>
|
||||
Cc: stable@vger.kernel.org
|
||||
---
|
||||
drivers/bluetooth/ath3k.c | 2 ++
|
||||
drivers/bluetooth/btusb.c | 1 +
|
||||
2 files changed, 3 insertions(+)
|
||||
|
||||
diff --git a/drivers/bluetooth/ath3k.c b/drivers/bluetooth/ath3k.c
|
||||
index 2589468..fadba88 100644
|
||||
--- a/drivers/bluetooth/ath3k.c
|
||||
+++ b/drivers/bluetooth/ath3k.c
|
||||
@@ -123,6 +123,7 @@ static const struct usb_device_id ath3k_table[] = {
|
||||
{ USB_DEVICE(0x13d3, 0x3472) },
|
||||
{ USB_DEVICE(0x13d3, 0x3474) },
|
||||
{ USB_DEVICE(0x13d3, 0x3487) },
|
||||
+ { USB_DEVICE(0x13d3, 0x3490) },
|
||||
|
||||
/* Atheros AR5BBU12 with sflash firmware */
|
||||
{ USB_DEVICE(0x0489, 0xE02C) },
|
||||
@@ -190,6 +191,7 @@ static const struct usb_device_id ath3k_blist_tbl[] = {
|
||||
{ USB_DEVICE(0x13d3, 0x3472), .driver_info = BTUSB_ATH3012 },
|
||||
{ USB_DEVICE(0x13d3, 0x3474), .driver_info = BTUSB_ATH3012 },
|
||||
{ USB_DEVICE(0x13d3, 0x3487), .driver_info = BTUSB_ATH3012 },
|
||||
+ { USB_DEVICE(0x13d3, 0x3490), .driver_info = BTUSB_ATH3012 },
|
||||
|
||||
/* Atheros AR5BBU22 with sflash firmware */
|
||||
{ USB_DEVICE(0x0489, 0xE036), .driver_info = BTUSB_ATH3012 },
|
||||
diff --git a/drivers/bluetooth/btusb.c b/drivers/bluetooth/btusb.c
|
||||
index f2e8fd7..811f9b9 100644
|
||||
--- a/drivers/bluetooth/btusb.c
|
||||
+++ b/drivers/bluetooth/btusb.c
|
||||
@@ -237,6 +237,7 @@ static const struct usb_device_id blacklist_table[] = {
|
||||
{ USB_DEVICE(0x13d3, 0x3472), .driver_info = BTUSB_ATH3012 },
|
||||
{ USB_DEVICE(0x13d3, 0x3474), .driver_info = BTUSB_ATH3012 },
|
||||
{ USB_DEVICE(0x13d3, 0x3487), .driver_info = BTUSB_ATH3012 },
|
||||
+ { USB_DEVICE(0x13d3, 0x3490), .driver_info = BTUSB_ATH3012 },
|
||||
|
||||
/* Atheros AR5BBU12 with sflash firmware */
|
||||
{ USB_DEVICE(0x0489, 0xe02c), .driver_info = BTUSB_IGNORE },
|
||||
--
|
||||
2.9.2
|
||||
|
||||
-116
@@ -1,116 +0,0 @@
|
||||
From 67f8ecc550b5bda03335f845dc869b8501d25fd0 Mon Sep 17 00:00:00 2001
|
||||
From: Roderick Colenbrander <roderick.colenbrander@sony.com>
|
||||
Date: Wed, 18 May 2016 13:11:09 -0700
|
||||
Subject: [PATCH] HID: uhid: fix timeout when probe races with IO
|
||||
|
||||
Many devices use userspace bluetooth stacks like BlueZ or Bluedroid in combination
|
||||
with uhid. If any of these stacks is used with a HID device for which the driver
|
||||
performs a HID request as part .probe (or technically another HID operation),
|
||||
this results in a deadlock situation. The deadlock results in a 5 second timeout
|
||||
for I/O operations in HID drivers, so isn't fatal, but none of the I/O operations
|
||||
have a chance of succeeding.
|
||||
|
||||
The root cause for the problem is that uhid only allows for one request to be
|
||||
processed at a time per uhid instance and locks out other operations. This means
|
||||
that if a user space is creating a new HID device through 'UHID_CREATE', which
|
||||
ultimately triggers '.probe' through the HID layer. Then any HID request e.g. a
|
||||
read for calibration data would trigger a HID operation on uhid again, but it
|
||||
won't go out to userspace, because it is still stuck in UHID_CREATE.
|
||||
In addition bluetooth stacks are typically single threaded, so they wouldn't be
|
||||
able to handle any requests while waiting on uhid.
|
||||
|
||||
Lucikly the UHID spec is somewhat flexible and allows for fixing the issue,
|
||||
without breaking user space. The idea which the patch implements as discussed
|
||||
with David Herrmann is to decouple adding of a hid device (which triggers .probe)
|
||||
from UHID_CREATE. The work will kick off roughly once UHID_CREATE completed (or
|
||||
else will wait a tiny bit of time in .probe for a lock). A HID driver has to call
|
||||
HID to call 'hid_hw_start()' as part of .probe once it is ready for I/O, which
|
||||
triggers UHID_START to user space. Any HID operations should function now within
|
||||
.probe and won't deadlock because userspace is stuck on UHID_CREATE.
|
||||
|
||||
We verified this patch on Bluedroid with Android 6.0 and on desktop Linux with
|
||||
BlueZ stacks. Prior to the patch they had the deadlock issue.
|
||||
|
||||
[jkosina@suse.cz: reword subject]
|
||||
Signed-off-by: Roderick Colenbrander <roderick.colenbrander@sony.com>
|
||||
Cc: stable@vger.kernel.org
|
||||
Signed-off-by: Jiri Kosina <jkosina@suse.cz>
|
||||
---
|
||||
drivers/hid/uhid.c | 33 ++++++++++++++++++++++++---------
|
||||
1 file changed, 24 insertions(+), 9 deletions(-)
|
||||
|
||||
diff --git a/drivers/hid/uhid.c b/drivers/hid/uhid.c
|
||||
index 16b6f11..99ec3ff 100644
|
||||
--- a/drivers/hid/uhid.c
|
||||
+++ b/drivers/hid/uhid.c
|
||||
@@ -51,10 +51,26 @@ struct uhid_device {
|
||||
u32 report_id;
|
||||
u32 report_type;
|
||||
struct uhid_event report_buf;
|
||||
+ struct work_struct worker;
|
||||
};
|
||||
|
||||
static struct miscdevice uhid_misc;
|
||||
|
||||
+static void uhid_device_add_worker(struct work_struct *work)
|
||||
+{
|
||||
+ struct uhid_device *uhid = container_of(work, struct uhid_device, worker);
|
||||
+ int ret;
|
||||
+
|
||||
+ ret = hid_add_device(uhid->hid);
|
||||
+ if (ret) {
|
||||
+ hid_err(uhid->hid, "Cannot register HID device: error %d\n", ret);
|
||||
+
|
||||
+ hid_destroy_device(uhid->hid);
|
||||
+ uhid->hid = NULL;
|
||||
+ uhid->running = false;
|
||||
+ }
|
||||
+}
|
||||
+
|
||||
static void uhid_queue(struct uhid_device *uhid, struct uhid_event *ev)
|
||||
{
|
||||
__u8 newhead;
|
||||
@@ -498,18 +514,14 @@ static int uhid_dev_create2(struct uhid_device *uhid,
|
||||
uhid->hid = hid;
|
||||
uhid->running = true;
|
||||
|
||||
- ret = hid_add_device(hid);
|
||||
- if (ret) {
|
||||
- hid_err(hid, "Cannot register HID device\n");
|
||||
- goto err_hid;
|
||||
- }
|
||||
+ /* Adding of a HID device is done through a worker, to allow HID drivers
|
||||
+ * which use feature requests during .probe to work, without they would
|
||||
+ * be blocked on devlock, which is held by uhid_char_write.
|
||||
+ */
|
||||
+ schedule_work(&uhid->worker);
|
||||
|
||||
return 0;
|
||||
|
||||
-err_hid:
|
||||
- hid_destroy_device(hid);
|
||||
- uhid->hid = NULL;
|
||||
- uhid->running = false;
|
||||
err_free:
|
||||
kfree(uhid->rd_data);
|
||||
uhid->rd_data = NULL;
|
||||
@@ -550,6 +562,8 @@ static int uhid_dev_destroy(struct uhid_device *uhid)
|
||||
uhid->running = false;
|
||||
wake_up_interruptible(&uhid->report_wait);
|
||||
|
||||
+ cancel_work_sync(&uhid->worker);
|
||||
+
|
||||
hid_destroy_device(uhid->hid);
|
||||
kfree(uhid->rd_data);
|
||||
|
||||
@@ -612,6 +626,7 @@ static int uhid_char_open(struct inode *inode, struct file *file)
|
||||
init_waitqueue_head(&uhid->waitq);
|
||||
init_waitqueue_head(&uhid->report_wait);
|
||||
uhid->running = false;
|
||||
+ INIT_WORK(&uhid->worker, uhid_device_add_worker);
|
||||
|
||||
file->private_data = uhid;
|
||||
nonseekable_open(inode, file);
|
||||
--
|
||||
2.9.2
|
||||
|
||||
-75
@@ -1,75 +0,0 @@
|
||||
From da7d3abe1c9e5ebac2cf86f97e9e89888a5e2094 Mon Sep 17 00:00:00 2001
|
||||
From: Andreas Herrmann <aherrmann@suse.com>
|
||||
Date: Fri, 22 Jul 2016 17:14:11 +0200
|
||||
Subject: [PATCH] Revert "cpufreq: pcc-cpufreq: update default value of
|
||||
cpuinfo_transition_latency"
|
||||
|
||||
This reverts commit 790d849bf811a8ab5d4cd2cce0f6fda92f6aebf2.
|
||||
|
||||
Using a v4.7-rc7 kernel on a HP ProLiant triggered following messages
|
||||
|
||||
pcc-cpufreq: (v1.10.00) driver loaded with frequency limits: 1200 MHz, 2800 MHz
|
||||
cpufreq: ondemand governor failed, too long transition latency of HW, fallback to performance governor
|
||||
|
||||
The last line was shown for each CPU in the system.
|
||||
Testing v4.5 (where commit 790d849b was integrated) triggered
|
||||
similar messages. Same behaviour on a 2nd HP Proliant system.
|
||||
|
||||
So commit 790d849bf (cpufreq: pcc-cpufreq: update default value of
|
||||
cpuinfo_transition_latency) causes the system to use performance
|
||||
governor which, I guess, was not the intention of the patch.
|
||||
|
||||
Enabling debug output in pcc-cpufreq provides following verbose output:
|
||||
|
||||
pcc-cpufreq: (v1.10.00) driver loaded with frequency limits: 1200 MHz, 2800 MHz
|
||||
pcc_get_offset: for CPU 0: pcc_cpu_data input_offset: 0x44, pcc_cpu_data output_offset: 0x48
|
||||
init: policy->max is 2800000, policy->min is 1200000
|
||||
get: get_freq for CPU 0
|
||||
get: SUCCESS: (virtual) output_offset for cpu 0 is 0xffffc9000d7c0048, contains a value of: 0xff06. Speed is: 168000 MHz
|
||||
cpufreq: ondemand governor failed, too long transition latency of HW, fallback to performance governor
|
||||
target: CPU 0 should go to target freq: 2800000 (virtual) input_offset is 0xffffc9000d7c0044
|
||||
target: was SUCCESSFUL for cpu 0
|
||||
|
||||
I am asking to revert 790d849bf to re-enable usage of ondemand
|
||||
governor with pcc-cpufreq.
|
||||
|
||||
Fixes: 790d849bf (cpufreq: pcc-cpufreq: update default value of cpuinfo_transition_latency)
|
||||
CC: <stable@vger.kernel.org> # 4.5+
|
||||
Signed-off-by: Andreas Herrmann <aherrmann@suse.com>
|
||||
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
|
||||
---
|
||||
Documentation/cpu-freq/pcc-cpufreq.txt | 4 ++--
|
||||
drivers/cpufreq/pcc-cpufreq.c | 2 --
|
||||
2 files changed, 2 insertions(+), 4 deletions(-)
|
||||
|
||||
diff --git a/Documentation/cpu-freq/pcc-cpufreq.txt b/Documentation/cpu-freq/pcc-cpufreq.txt
|
||||
index 0a94224..9e3c3b3 100644
|
||||
--- a/Documentation/cpu-freq/pcc-cpufreq.txt
|
||||
+++ b/Documentation/cpu-freq/pcc-cpufreq.txt
|
||||
@@ -159,8 +159,8 @@ to be strictly associated with a P-state.
|
||||
|
||||
2.2 cpuinfo_transition_latency:
|
||||
-------------------------------
|
||||
-The cpuinfo_transition_latency field is CPUFREQ_ETERNAL. The PCC specification
|
||||
-does not include a field to expose this value currently.
|
||||
+The cpuinfo_transition_latency field is 0. The PCC specification does
|
||||
+not include a field to expose this value currently.
|
||||
|
||||
2.3 cpuinfo_cur_freq:
|
||||
---------------------
|
||||
diff --git a/drivers/cpufreq/pcc-cpufreq.c b/drivers/cpufreq/pcc-cpufreq.c
|
||||
index a7ecb9a..3f0ce2a 100644
|
||||
--- a/drivers/cpufreq/pcc-cpufreq.c
|
||||
+++ b/drivers/cpufreq/pcc-cpufreq.c
|
||||
@@ -555,8 +555,6 @@ static int pcc_cpufreq_cpu_init(struct cpufreq_policy *policy)
|
||||
policy->min = policy->cpuinfo.min_freq =
|
||||
ioread32(&pcch_hdr->minimum_frequency) * 1000;
|
||||
|
||||
- policy->cpuinfo.transition_latency = CPUFREQ_ETERNAL;
|
||||
-
|
||||
pr_debug("init: policy->max is %d, policy->min is %d\n",
|
||||
policy->max, policy->min);
|
||||
out:
|
||||
--
|
||||
2.9.2
|
||||
|
||||
-45
@@ -1,45 +0,0 @@
|
||||
From 6a7fd522a7c94cdef0a3b08acf8e6702056e635c Mon Sep 17 00:00:00 2001
|
||||
From: Vegard Nossum <vegard.nossum@oracle.com>
|
||||
Date: Mon, 4 Jul 2016 11:03:00 -0400
|
||||
Subject: [PATCH] ext4: don't call ext4_should_journal_data() on the journal
|
||||
inode
|
||||
|
||||
If ext4_fill_super() fails early, it's possible for ext4_evict_inode()
|
||||
to call ext4_should_journal_data() before superblock options and flags
|
||||
are fully set up. In that case, the iput() on the journal inode can
|
||||
end up causing a BUG().
|
||||
|
||||
Work around this problem by reordering the tests so we only call
|
||||
ext4_should_journal_data() after we know it's not the journal inode.
|
||||
|
||||
Fixes: 2d859db3e4 ("ext4: fix data corruption in inodes with journalled data")
|
||||
Fixes: 2b405bfa84 ("ext4: fix data=journal fast mount/umount hang")
|
||||
Cc: Jan Kara <jack@suse.cz>
|
||||
Cc: stable@vger.kernel.org
|
||||
Signed-off-by: Vegard Nossum <vegard.nossum@oracle.com>
|
||||
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
|
||||
Reviewed-by: Jan Kara <jack@suse.cz>
|
||||
---
|
||||
fs/ext4/inode.c | 6 +++---
|
||||
1 file changed, 3 insertions(+), 3 deletions(-)
|
||||
|
||||
diff --git a/fs/ext4/inode.c b/fs/ext4/inode.c
|
||||
index 321a31c..ea39d19 100644
|
||||
--- a/fs/ext4/inode.c
|
||||
+++ b/fs/ext4/inode.c
|
||||
@@ -211,9 +211,9 @@ void ext4_evict_inode(struct inode *inode)
|
||||
* Note that directories do not have this problem because they
|
||||
* don't use page cache.
|
||||
*/
|
||||
- if (ext4_should_journal_data(inode) &&
|
||||
- (S_ISLNK(inode->i_mode) || S_ISREG(inode->i_mode)) &&
|
||||
- inode->i_ino != EXT4_JOURNAL_INO) {
|
||||
+ if (inode->i_ino != EXT4_JOURNAL_INO &&
|
||||
+ ext4_should_journal_data(inode) &&
|
||||
+ (S_ISLNK(inode->i_mode) || S_ISREG(inode->i_mode))) {
|
||||
journal_t *journal = EXT4_SB(inode->i_sb)->s_journal;
|
||||
tid_t commit_tid = EXT4_I(inode)->i_datasync_tid;
|
||||
|
||||
--
|
||||
2.9.2
|
||||
|
||||
-78
@@ -1,78 +0,0 @@
|
||||
From 646caa9c8e196880b41cd3e3d33a2ebc752bdb85 Mon Sep 17 00:00:00 2001
|
||||
From: Jan Kara <jack@suse.cz>
|
||||
Date: Mon, 4 Jul 2016 10:14:01 -0400
|
||||
Subject: [PATCH] ext4: fix deadlock during page writeback
|
||||
|
||||
Commit 06bd3c36a733 (ext4: fix data exposure after a crash) uncovered a
|
||||
deadlock in ext4_writepages() which was previously much harder to hit.
|
||||
After this commit xfstest generic/130 reproduces the deadlock on small
|
||||
filesystems.
|
||||
|
||||
The problem happens when ext4_do_update_inode() sets LARGE_FILE feature
|
||||
and marks current inode handle as synchronous. That subsequently results
|
||||
in ext4_journal_stop() called from ext4_writepages() to block waiting for
|
||||
transaction commit while still holding page locks, reference to io_end,
|
||||
and some prepared bio in mpd structure each of which can possibly block
|
||||
transaction commit from completing and thus results in deadlock.
|
||||
|
||||
Fix the problem by releasing page locks, io_end reference, and
|
||||
submitting prepared bio before calling ext4_journal_stop().
|
||||
|
||||
[ Changed to defer the call to ext4_journal_stop() only if the handle
|
||||
is synchronous. --tytso ]
|
||||
|
||||
Reported-and-tested-by: Eryu Guan <eguan@redhat.com>
|
||||
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
|
||||
CC: stable@vger.kernel.org
|
||||
Signed-off-by: Jan Kara <jack@suse.cz>
|
||||
---
|
||||
fs/ext4/inode.c | 29 ++++++++++++++++++++++++++---
|
||||
1 file changed, 26 insertions(+), 3 deletions(-)
|
||||
|
||||
diff --git a/fs/ext4/inode.c b/fs/ext4/inode.c
|
||||
index 44ee5d9..321a31c 100644
|
||||
--- a/fs/ext4/inode.c
|
||||
+++ b/fs/ext4/inode.c
|
||||
@@ -2754,13 +2754,36 @@ retry:
|
||||
done = true;
|
||||
}
|
||||
}
|
||||
- ext4_journal_stop(handle);
|
||||
+ /*
|
||||
+ * Caution: If the handle is synchronous,
|
||||
+ * ext4_journal_stop() can wait for transaction commit
|
||||
+ * to finish which may depend on writeback of pages to
|
||||
+ * complete or on page lock to be released. In that
|
||||
+ * case, we have to wait until after after we have
|
||||
+ * submitted all the IO, released page locks we hold,
|
||||
+ * and dropped io_end reference (for extent conversion
|
||||
+ * to be able to complete) before stopping the handle.
|
||||
+ */
|
||||
+ if (!ext4_handle_valid(handle) || handle->h_sync == 0) {
|
||||
+ ext4_journal_stop(handle);
|
||||
+ handle = NULL;
|
||||
+ }
|
||||
/* Submit prepared bio */
|
||||
ext4_io_submit(&mpd.io_submit);
|
||||
/* Unlock pages we didn't use */
|
||||
mpage_release_unused_pages(&mpd, give_up_on_write);
|
||||
- /* Drop our io_end reference we got from init */
|
||||
- ext4_put_io_end(mpd.io_submit.io_end);
|
||||
+ /*
|
||||
+ * Drop our io_end reference we got from init. We have
|
||||
+ * to be careful and use deferred io_end finishing if
|
||||
+ * we are still holding the transaction as we can
|
||||
+ * release the last reference to io_end which may end
|
||||
+ * up doing unwritten extent conversion.
|
||||
+ */
|
||||
+ if (handle) {
|
||||
+ ext4_put_io_end_defer(mpd.io_submit.io_end);
|
||||
+ ext4_journal_stop(handle);
|
||||
+ } else
|
||||
+ ext4_put_io_end(mpd.io_submit.io_end);
|
||||
|
||||
if (ret == -ENOSPC && sbi->s_journal) {
|
||||
/*
|
||||
--
|
||||
2.9.2
|
||||
|
||||
-47
@@ -1,47 +0,0 @@
|
||||
From fc8a601e1175ae351f662506030f9939cb7fdbfe Mon Sep 17 00:00:00 2001
|
||||
From: Alex Hung <alex.hung@canonical.com>
|
||||
Date: Mon, 13 Jun 2016 19:44:00 +0800
|
||||
Subject: [PATCH] hp-wmi: Fix wifi cannot be hard-unblocked
|
||||
|
||||
Several users reported wifi cannot be unblocked as discussed in [1].
|
||||
This patch removes the use of the 2009 flag by BIOS but uses the actual
|
||||
WMI function calls - it will be skipped if WMI reports unsupported.
|
||||
|
||||
[1] https://bugzilla.kernel.org/show_bug.cgi?id=69131
|
||||
|
||||
Signed-off-by: Alex Hung <alex.hung@canonical.com>
|
||||
Tested-by: Evgenii Shatokhin <eugene.shatokhin@yandex.ru>
|
||||
Cc: stable@vger.kernel.org
|
||||
Signed-off-by: Darren Hart <dvhart@linux.intel.com>
|
||||
---
|
||||
drivers/platform/x86/hp-wmi.c | 7 ++++++-
|
||||
1 file changed, 6 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/drivers/platform/x86/hp-wmi.c b/drivers/platform/x86/hp-wmi.c
|
||||
index 6f145f2..96ffda4 100644
|
||||
--- a/drivers/platform/x86/hp-wmi.c
|
||||
+++ b/drivers/platform/x86/hp-wmi.c
|
||||
@@ -718,6 +718,11 @@ static int __init hp_wmi_rfkill_setup(struct platform_device *device)
|
||||
if (err)
|
||||
return err;
|
||||
|
||||
+ err = hp_wmi_perform_query(HPWMI_WIRELESS_QUERY, 1, &wireless,
|
||||
+ sizeof(wireless), 0);
|
||||
+ if (err)
|
||||
+ return err;
|
||||
+
|
||||
if (wireless & 0x1) {
|
||||
wifi_rfkill = rfkill_alloc("hp-wifi", &device->dev,
|
||||
RFKILL_TYPE_WLAN,
|
||||
@@ -882,7 +887,7 @@ static int __init hp_wmi_bios_setup(struct platform_device *device)
|
||||
wwan_rfkill = NULL;
|
||||
rfkill2_count = 0;
|
||||
|
||||
- if (hp_wmi_bios_2009_later() || hp_wmi_rfkill_setup(device))
|
||||
+ if (hp_wmi_rfkill_setup(device))
|
||||
hp_wmi_rfkill2_setup(device);
|
||||
|
||||
err = device_create_file(&device->dev, &dev_attr_display);
|
||||
--
|
||||
2.9.2
|
||||
|
||||
-64
@@ -1,64 +0,0 @@
|
||||
From 2a00932f082aff93c3a55426e0c7af6d0ec03997 Mon Sep 17 00:00:00 2001
|
||||
From: Matthew Leach <matthew@mattleach.net>
|
||||
Date: Fri, 8 Jul 2016 09:04:27 -0300
|
||||
Subject: [PATCH] [media] media: usbtv: prevent access to free'd resources
|
||||
|
||||
When disconnecting the usbtv device, the sound card is unregistered
|
||||
from ALSA and the snd member of the usbtv struct is set to NULL. If
|
||||
the usbtv snd_trigger work is running, this can cause a race condition
|
||||
where the kernel will attempt to access free'd resources, shown in
|
||||
[1].
|
||||
|
||||
This patch fixes the disconnection code by cancelling any snd_trigger
|
||||
work before unregistering the sound card from ALSA and checking that
|
||||
the snd member still exists in the work function.
|
||||
|
||||
[1]:
|
||||
usb 3-1.2: USB disconnect, device number 6
|
||||
BUG: unable to handle kernel NULL pointer dereference at 0000000000000008
|
||||
IP: [<ffffffff81093850>] process_one_work+0x30/0x480
|
||||
PGD 405bbf067 PUD 405bbe067 PMD 0
|
||||
Call Trace:
|
||||
[<ffffffff81093ce8>] worker_thread+0x48/0x4e0
|
||||
[<ffffffff81093ca0>] ? process_one_work+0x480/0x480
|
||||
[<ffffffff81093ca0>] ? process_one_work+0x480/0x480
|
||||
[<ffffffff81099998>] kthread+0xd8/0xf0
|
||||
[<ffffffff815c73c2>] ret_from_fork+0x22/0x40
|
||||
[<ffffffff810998c0>] ? kthread_worker_fn+0x170/0x170
|
||||
---[ end trace 0f3dac5c1a38e610 ]---
|
||||
|
||||
Signed-off-by: Matthew Leach <matthew@mattleach.net>
|
||||
Tested-by: Peter Sutton <foxxy@foxdogstudios.com>
|
||||
Cc: stable@vger.kernel.org
|
||||
Signed-off-by: Hans Verkuil <hans.verkuil@cisco.com>
|
||||
Signed-off-by: Mauro Carvalho Chehab <mchehab@s-opensource.com>
|
||||
---
|
||||
drivers/media/usb/usbtv/usbtv-audio.c | 5 +++++
|
||||
1 file changed, 5 insertions(+)
|
||||
|
||||
diff --git a/drivers/media/usb/usbtv/usbtv-audio.c b/drivers/media/usb/usbtv/usbtv-audio.c
|
||||
index d4b4db3..1965ff1 100644
|
||||
--- a/drivers/media/usb/usbtv/usbtv-audio.c
|
||||
+++ b/drivers/media/usb/usbtv/usbtv-audio.c
|
||||
@@ -292,6 +292,9 @@ static void snd_usbtv_trigger(struct work_struct *work)
|
||||
{
|
||||
struct usbtv *chip = container_of(work, struct usbtv, snd_trigger);
|
||||
|
||||
+ if (!chip->snd)
|
||||
+ return;
|
||||
+
|
||||
if (atomic_read(&chip->snd_stream))
|
||||
usbtv_audio_start(chip);
|
||||
else
|
||||
@@ -392,6 +395,8 @@ err:
|
||||
|
||||
void usbtv_audio_free(struct usbtv *usbtv)
|
||||
{
|
||||
+ cancel_work_sync(&usbtv->snd_trigger);
|
||||
+
|
||||
if (usbtv->snd && usbtv->udev) {
|
||||
snd_card_free(usbtv->snd);
|
||||
usbtv->snd = NULL;
|
||||
--
|
||||
2.9.2
|
||||
|
||||
-54
@@ -1,54 +0,0 @@
|
||||
From 126f40298446a82116e1f92a1aaf72b8c8228fae Mon Sep 17 00:00:00 2001
|
||||
From: Sakari Ailus <sakari.ailus@linux.intel.com>
|
||||
Date: Wed, 11 May 2016 18:44:32 -0300
|
||||
Subject: [PATCH] [media] vb2: core: Skip planes array verification if pb is
|
||||
NULL
|
||||
|
||||
An earlier patch fixing an input validation issue introduced another
|
||||
issue: vb2_core_dqbuf() is called with pb argument value NULL in some
|
||||
cases, causing a NULL pointer dereference. Fix this by skipping the
|
||||
verification as there's nothing to verify.
|
||||
|
||||
Fixes: e7e0c3e26587 ("[media] videobuf2-core: Check user space planes array in dqbuf")
|
||||
|
||||
Signed-off-by: David R <david@unsolicited.net>
|
||||
Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
|
||||
Reviewed-by: Hans Verkuil <hans.verkuil@cisco.com>
|
||||
Cc: stable@vger.kernel.org # for v4.4 and later
|
||||
Signed-off-by: Mauro Carvalho Chehab <mchehab@s-opensource.com>
|
||||
---
|
||||
drivers/media/v4l2-core/videobuf2-core.c | 10 ++++++----
|
||||
1 file changed, 6 insertions(+), 4 deletions(-)
|
||||
|
||||
diff --git a/drivers/media/v4l2-core/videobuf2-core.c b/drivers/media/v4l2-core/videobuf2-core.c
|
||||
index 9fbcb67..633fc1a 100644
|
||||
--- a/drivers/media/v4l2-core/videobuf2-core.c
|
||||
+++ b/drivers/media/v4l2-core/videobuf2-core.c
|
||||
@@ -1648,7 +1648,7 @@ static int __vb2_get_done_vb(struct vb2_queue *q, struct vb2_buffer **vb,
|
||||
void *pb, int nonblocking)
|
||||
{
|
||||
unsigned long flags;
|
||||
- int ret;
|
||||
+ int ret = 0;
|
||||
|
||||
/*
|
||||
* Wait for at least one buffer to become available on the done_list.
|
||||
@@ -1664,10 +1664,12 @@ static int __vb2_get_done_vb(struct vb2_queue *q, struct vb2_buffer **vb,
|
||||
spin_lock_irqsave(&q->done_lock, flags);
|
||||
*vb = list_first_entry(&q->done_list, struct vb2_buffer, done_entry);
|
||||
/*
|
||||
- * Only remove the buffer from done_list if v4l2_buffer can handle all
|
||||
- * the planes.
|
||||
+ * Only remove the buffer from done_list if all planes can be
|
||||
+ * handled. Some cases such as V4L2 file I/O and DVB have pb
|
||||
+ * == NULL; skip the check then as there's nothing to verify.
|
||||
*/
|
||||
- ret = call_bufop(q, verify_planes_array, *vb, pb);
|
||||
+ if (pb)
|
||||
+ ret = call_bufop(q, verify_planes_array, *vb, pb);
|
||||
if (!ret)
|
||||
list_del(&(*vb)->done_entry);
|
||||
spin_unlock_irqrestore(&q->done_lock, flags);
|
||||
--
|
||||
2.9.2
|
||||
|
||||
-57
@@ -1,57 +0,0 @@
|
||||
From 83934b75c368f529d084815c463a7ef781dc9751 Mon Sep 17 00:00:00 2001
|
||||
From: Sakari Ailus <sakari.ailus@linux.intel.com>
|
||||
Date: Sun, 3 Apr 2016 16:31:03 -0300
|
||||
Subject: [PATCH] [media] videobuf2-v4l2: Verify planes array in buffer
|
||||
dequeueing
|
||||
|
||||
When a buffer is being dequeued using VIDIOC_DQBUF IOCTL, the exact buffer
|
||||
which will be dequeued is not known until the buffer has been removed from
|
||||
the queue. The number of planes is specific to a buffer, not to the queue.
|
||||
|
||||
This does lead to the situation where multi-plane buffers may be requested
|
||||
and queued with n planes, but VIDIOC_DQBUF IOCTL may be passed an argument
|
||||
struct with fewer planes.
|
||||
|
||||
__fill_v4l2_buffer() however uses the number of planes from the dequeued
|
||||
videobuf2 buffer, overwriting kernel memory (the m.planes array allocated
|
||||
in video_usercopy() in v4l2-ioctl.c) if the user provided fewer
|
||||
planes than the dequeued buffer had. Oops!
|
||||
|
||||
Fixes: b0e0e1f83de3 ("[media] media: videobuf2: Prepare to divide videobuf2")
|
||||
|
||||
Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
|
||||
Acked-by: Hans Verkuil <hans.verkuil@cisco.com>
|
||||
Cc: stable@vger.kernel.org # for v4.4 and later
|
||||
Signed-off-by: Mauro Carvalho Chehab <mchehab@osg.samsung.com>
|
||||
Signed-off-by: Mauro Carvalho Chehab <mchehab@s-opensource.com>
|
||||
---
|
||||
drivers/media/v4l2-core/videobuf2-v4l2.c | 6 ++++++
|
||||
1 file changed, 6 insertions(+)
|
||||
|
||||
diff --git a/drivers/media/v4l2-core/videobuf2-v4l2.c b/drivers/media/v4l2-core/videobuf2-v4l2.c
|
||||
index 0b1b8c7..7f366f1 100644
|
||||
--- a/drivers/media/v4l2-core/videobuf2-v4l2.c
|
||||
+++ b/drivers/media/v4l2-core/videobuf2-v4l2.c
|
||||
@@ -74,6 +74,11 @@ static int __verify_planes_array(struct vb2_buffer *vb, const struct v4l2_buffer
|
||||
return 0;
|
||||
}
|
||||
|
||||
+static int __verify_planes_array_core(struct vb2_buffer *vb, const void *pb)
|
||||
+{
|
||||
+ return __verify_planes_array(vb, pb);
|
||||
+}
|
||||
+
|
||||
/**
|
||||
* __verify_length() - Verify that the bytesused value for each plane fits in
|
||||
* the plane length and that the data offset doesn't exceed the bytesused value.
|
||||
@@ -437,6 +442,7 @@ static int __fill_vb2_buffer(struct vb2_buffer *vb,
|
||||
}
|
||||
|
||||
static const struct vb2_buf_ops v4l2_buf_ops = {
|
||||
+ .verify_planes_array = __verify_planes_array_core,
|
||||
.fill_user_buffer = __fill_v4l2_buffer,
|
||||
.fill_vb2_buffer = __fill_vb2_buffer,
|
||||
.copy_timestamp = __copy_timestamp,
|
||||
--
|
||||
2.9.2
|
||||
|
||||
-59
@@ -1,59 +0,0 @@
|
||||
From d9083160c2f6ee456ea867ea2279c1fc6124e56f Mon Sep 17 00:00:00 2001
|
||||
From: Sumit Saxena <sumit.saxena@broadcom.com>
|
||||
Date: Fri, 8 Jul 2016 03:30:16 -0700
|
||||
Subject: [PATCH] megaraid_sas: Do not fire MR_DCMD_PD_LIST_QUERY to
|
||||
controllers which do not support it
|
||||
|
||||
There was an issue reported by Lucz Geza on Dell Perc 6i. As per issue
|
||||
reported, megaraid_sas driver goes into an infinite error reporting loop
|
||||
as soon as there is a change in the status of one of the
|
||||
arrays (degrade, resync online etc ). Below are the error logs reported
|
||||
continuously-
|
||||
|
||||
Jun 25 08:49:30 ns8 kernel: [ 757.757017] megaraid_sas 0000:02:00.0: DCMD failed/not supported by firmware: megasas_get_pd_list 4115
|
||||
Jun 25 08:49:30 ns8 kernel: [ 757.778017] megaraid_sas 0000:02:00.0: DCMD failed/not supported by firmware: megasas_get_pd_list 4115
|
||||
Jun 25 08:49:30 ns8 kernel: [ 757.799017] megaraid_sas 0000:02:00.0: DCMD failed/not supported by firmware: megasas_get_pd_list 4115
|
||||
Jun 25 08:49:30 ns8 kernel: [ 757.820018] megaraid_sas 0000:02:00.0: DCMD failed/not supported by firmware: megasas_get_pd_list 4115
|
||||
Jun 25 08:49:30 ns8 kernel: [ 757.841018] megaraid_sas 0000:02:00.0: DCMD failed/not supported by firmware: megasas_get_pd_list 4115
|
||||
|
||||
This issue is very much specific to controllers which do not support
|
||||
DCMD- MR_DCMD_PD_LIST_QUERY. In case of any hotplugging/rescanning of
|
||||
drives, AEN thread will be scheduled by driver and fire DCMD-
|
||||
MR_DCMD_PD_LIST_QUERY and if this DCMD is failed then driver will fail
|
||||
this event processing and will not go ahead for further events. This
|
||||
will cause infinite loop of same event getting retried infinitely and
|
||||
causing above mentioned logs.
|
||||
|
||||
Fix for this problem is: not to fire DCMD MR_DCMD_PD_LIST_QUERY for
|
||||
controllers which do not support it and send DCMD SUCCESS status to AEN
|
||||
function so that it can go ahead with other event processing.
|
||||
|
||||
Reported-by: Lucz Geza <geza@lucz.com>
|
||||
Cc: <stable@vger.kernel.org>
|
||||
Signed-off-by: Sumit Saxena <sumit.saxena@broadcom.com>
|
||||
Reviewed-by: Tomas Henzl <thenzl@redhat.com>
|
||||
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
|
||||
---
|
||||
drivers/scsi/megaraid/megaraid_sas_base.c | 6 ++++++
|
||||
1 file changed, 6 insertions(+)
|
||||
|
||||
diff --git a/drivers/scsi/megaraid/megaraid_sas_base.c b/drivers/scsi/megaraid/megaraid_sas_base.c
|
||||
index f4b0690..2dab3dc 100644
|
||||
--- a/drivers/scsi/megaraid/megaraid_sas_base.c
|
||||
+++ b/drivers/scsi/megaraid/megaraid_sas_base.c
|
||||
@@ -4079,6 +4079,12 @@ megasas_get_pd_list(struct megasas_instance *instance)
|
||||
struct MR_PD_ADDRESS *pd_addr;
|
||||
dma_addr_t ci_h = 0;
|
||||
|
||||
+ if (instance->pd_list_not_supported) {
|
||||
+ dev_info(&instance->pdev->dev, "MR_DCMD_PD_LIST_QUERY "
|
||||
+ "not supported by firmware\n");
|
||||
+ return ret;
|
||||
+ }
|
||||
+
|
||||
cmd = megasas_get_cmd(instance);
|
||||
|
||||
if (!cmd) {
|
||||
--
|
||||
2.9.2
|
||||
|
||||
-43
@@ -1,43 +0,0 @@
|
||||
From 1bea0512c3394965de28a152149b90afd686fae5 Mon Sep 17 00:00:00 2001
|
||||
From: =?UTF-8?q?Rafa=C5=82=20Mi=C5=82ecki?= <zajec5@gmail.com>
|
||||
Date: Mon, 11 Jul 2016 23:01:36 +0200
|
||||
Subject: [PATCH] bcma: add PCI ID for Foxconn's BCM43142 device
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
After discovering there are 2 very different 14e4:4365 PCI devices we
|
||||
made ID tables less generic. Back then we believed there are only 2 such
|
||||
devices:
|
||||
1) 14e4:4365 1028:0016 with SoftMAC BCM43142 chipset
|
||||
2) 14e4:4365 14e4:4365 with FullMAC BCM4366 chipset
|
||||
|
||||
>From the recent report it appears there is also 14e4:4365 105b:e092
|
||||
which should be claimed by bcma. Add back support for it.
|
||||
|
||||
Bugzilla: https://bugzilla.kernel.org/show_bug.cgi?id=121881
|
||||
Fixes: 515b399c9a20 ("bcma: claim only 14e4:4365 PCI Dell card with SoftMAC BCM43142")
|
||||
Reported-by: Igor Mammedov <imammedo@redhat.com>
|
||||
Signed-off-by: Rafał Miłecki <zajec5@gmail.com>
|
||||
Cc: Stable <stable@vger.kernel.org> [4.6+]
|
||||
Tested-by: Igor Mammedov <imammedo@redhat.com>
|
||||
Signed-off-by: Kalle Valo <kvalo@codeaurora.org>
|
||||
---
|
||||
drivers/bcma/host_pci.c | 1 +
|
||||
1 file changed, 1 insertion(+)
|
||||
|
||||
diff --git a/drivers/bcma/host_pci.c b/drivers/bcma/host_pci.c
|
||||
index cae5385..bd46569 100644
|
||||
--- a/drivers/bcma/host_pci.c
|
||||
+++ b/drivers/bcma/host_pci.c
|
||||
@@ -295,6 +295,7 @@ static const struct pci_device_id bcma_pci_bridge_tbl[] = {
|
||||
{ PCI_DEVICE(PCI_VENDOR_ID_BROADCOM, 0x4359) },
|
||||
{ PCI_DEVICE(PCI_VENDOR_ID_BROADCOM, 0x4360) },
|
||||
{ PCI_DEVICE_SUB(PCI_VENDOR_ID_BROADCOM, 0x4365, PCI_VENDOR_ID_DELL, 0x0016) },
|
||||
+ { PCI_DEVICE_SUB(PCI_VENDOR_ID_BROADCOM, 0x4365, PCI_VENDOR_ID_FOXCONN, 0xe092) },
|
||||
{ PCI_DEVICE(PCI_VENDOR_ID_BROADCOM, 0x43a0) },
|
||||
{ PCI_DEVICE(PCI_VENDOR_ID_BROADCOM, 0x43a9) },
|
||||
{ PCI_DEVICE(PCI_VENDOR_ID_BROADCOM, 0x43aa) },
|
||||
--
|
||||
2.9.2
|
||||
|
||||
-61
@@ -1,61 +0,0 @@
|
||||
From 82bc9ab6a8f577d2174a736c33f3d4ecf7d9ef47 Mon Sep 17 00:00:00 2001
|
||||
From: Arend Van Spriel <arend.vanspriel@broadcom.com>
|
||||
Date: Fri, 15 Jul 2016 12:16:12 +0200
|
||||
Subject: [PATCH] brcmfmac: restore stopping netdev queue when bus clogs up
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
When the host-interface bus has hard time handling transmit packets
|
||||
it informs higher layer about this and it would stop the netdev
|
||||
queue when needed. However, since commit 9cd18359d31e ("brcmfmac:
|
||||
Make FWS queueing configurable.") this was broken. With this patch
|
||||
the behaviour is restored.
|
||||
|
||||
Cc: stable@vger.kernel.org # v4.5, v4.6, v4.7
|
||||
Fixes: 9cd18359d31e ("brcmfmac: Make FWS queueing configurable.")
|
||||
Tested-by: Per Förlin <per.forlin@gmail.com>
|
||||
Reviewed-by: Hante Meuleman <hante.meuleman@broadcom.com>
|
||||
Reviewed-by: Pieter-Paul Giesberts <pieter-paul.giesberts@broadcom.com>
|
||||
Reviewed-by: Franky Lin <franky.lin@broadcom.com>
|
||||
Signed-off-by: Arend van Spriel <arend.vanspriel@broadcom.com>
|
||||
Signed-off-by: Kalle Valo <kvalo@codeaurora.org>
|
||||
---
|
||||
.../broadcom/brcm80211/brcmfmac/fwsignal.c | 22 +++++++++++++++++-----
|
||||
1 file changed, 17 insertions(+), 5 deletions(-)
|
||||
|
||||
diff --git a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/fwsignal.c b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/fwsignal.c
|
||||
index cd221ab..9f9024a 100644
|
||||
--- a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/fwsignal.c
|
||||
+++ b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/fwsignal.c
|
||||
@@ -2469,10 +2469,22 @@ void brcmf_fws_bustxfail(struct brcmf_fws_info *fws, struct sk_buff *skb)
|
||||
void brcmf_fws_bus_blocked(struct brcmf_pub *drvr, bool flow_blocked)
|
||||
{
|
||||
struct brcmf_fws_info *fws = drvr->fws;
|
||||
+ struct brcmf_if *ifp;
|
||||
+ int i;
|
||||
|
||||
- fws->bus_flow_blocked = flow_blocked;
|
||||
- if (!flow_blocked)
|
||||
- brcmf_fws_schedule_deq(fws);
|
||||
- else
|
||||
- fws->stats.bus_flow_block++;
|
||||
+ if (fws->avoid_queueing) {
|
||||
+ for (i = 0; i < BRCMF_MAX_IFS; i++) {
|
||||
+ ifp = drvr->iflist[i];
|
||||
+ if (!ifp || !ifp->ndev)
|
||||
+ continue;
|
||||
+ brcmf_txflowblock_if(ifp, BRCMF_NETIF_STOP_REASON_FLOW,
|
||||
+ flow_blocked);
|
||||
+ }
|
||||
+ } else {
|
||||
+ fws->bus_flow_blocked = flow_blocked;
|
||||
+ if (!flow_blocked)
|
||||
+ brcmf_fws_schedule_deq(fws);
|
||||
+ else
|
||||
+ fws->stats.bus_flow_block++;
|
||||
+ }
|
||||
}
|
||||
--
|
||||
2.9.2
|
||||
|
||||
-42
@@ -1,42 +0,0 @@
|
||||
From: Luca Coelho <luca-XPOmlcxoEMv1KXRcyAk9cg@public.gmane.org>
|
||||
Subject: [PATCH 13/56] iwlwifi: add new 8260 PCI IDs
|
||||
Date: Wed, 6 Jul 2016 13:40:08 +0300
|
||||
|
||||
From: Oren Givon <oren.givon-ral2JQCrhuEAvxtiuMwx3w@public.gmane.org>
|
||||
|
||||
Add 3 new 8260 series PCI IDs:
|
||||
- (0x24F3, 0x10B0)
|
||||
- (0x24F3, 0xD0B0)
|
||||
- (0x24F3, 0xB0B0)
|
||||
|
||||
CC: <stable-u79uwXL29TY76Z2rM5mHXA@public.gmane.org> [4.1+]
|
||||
Signed-off-by: Oren Givon <oren.givon-ral2JQCrhuEAvxtiuMwx3w@public.gmane.org>
|
||||
Signed-off-by: David Spinadel <david.spinadel-ral2JQCrhuEAvxtiuMwx3w@public.gmane.org>
|
||||
Signed-off-by: Luca Coelho <luciano.coelho-ral2JQCrhuEAvxtiuMwx3w@public.gmane.org>
|
||||
---
|
||||
drivers/net/wireless/intel/iwlwifi/pcie/drv.c | 3 +++
|
||||
1 file changed, 3 insertions(+)
|
||||
|
||||
diff --git a/drivers/net/wireless/intel/iwlwifi/pcie/drv.c b/drivers/net/wireless/intel/iwlwifi/pcie/drv.c
|
||||
index a588b05..1cae19d 100644
|
||||
--- a/drivers/net/wireless/intel/iwlwifi/pcie/drv.c
|
||||
+++ b/drivers/net/wireless/intel/iwlwifi/pcie/drv.c
|
||||
@@ -433,6 +433,7 @@ static const struct pci_device_id iwl_hw_card_ids[] = {
|
||||
/* 8000 Series */
|
||||
{IWL_PCI_DEVICE(0x24F3, 0x0010, iwl8260_2ac_cfg)},
|
||||
{IWL_PCI_DEVICE(0x24F3, 0x1010, iwl8260_2ac_cfg)},
|
||||
+ {IWL_PCI_DEVICE(0x24F3, 0x10B0, iwl8260_2ac_cfg)},
|
||||
{IWL_PCI_DEVICE(0x24F3, 0x0130, iwl8260_2ac_cfg)},
|
||||
{IWL_PCI_DEVICE(0x24F3, 0x1130, iwl8260_2ac_cfg)},
|
||||
{IWL_PCI_DEVICE(0x24F3, 0x0132, iwl8260_2ac_cfg)},
|
||||
@@ -454,6 +455,8 @@ static const struct pci_device_id iwl_hw_card_ids[] = {
|
||||
{IWL_PCI_DEVICE(0x24F3, 0xD010, iwl8260_2ac_cfg)},
|
||||
{IWL_PCI_DEVICE(0x24F3, 0xC050, iwl8260_2ac_cfg)},
|
||||
{IWL_PCI_DEVICE(0x24F3, 0xD050, iwl8260_2ac_cfg)},
|
||||
+ {IWL_PCI_DEVICE(0x24F3, 0xD0B0, iwl8260_2ac_cfg)},
|
||||
+ {IWL_PCI_DEVICE(0x24F3, 0xB0B0, iwl8260_2ac_cfg)},
|
||||
{IWL_PCI_DEVICE(0x24F3, 0x8010, iwl8260_2ac_cfg)},
|
||||
{IWL_PCI_DEVICE(0x24F3, 0x8110, iwl8260_2ac_cfg)},
|
||||
{IWL_PCI_DEVICE(0x24F3, 0x9010, iwl8260_2ac_cfg)},
|
||||
--
|
||||
2.8.1
|
||||
-48
@@ -1,48 +0,0 @@
|
||||
From: Luca Coelho <luca@coelho.fi>
|
||||
Subject: [PATCH 14/56] iwlwifi: add new 8265
|
||||
Date: Wed, 6 Jul 2016 13:40:09 +0300
|
||||
|
||||
From: Oren Givon <oren.givon@intel.com>
|
||||
|
||||
Add 6 new 8265 series PCI IDs:
|
||||
- (0x24FD, 0x1130)
|
||||
- (0x24FD, 0x0130)
|
||||
- (0x24FD, 0x0910)
|
||||
- (0x24FD, 0x0930)
|
||||
- (0x24FD, 0x0950)
|
||||
- (0x24FD, 0x0850)
|
||||
|
||||
CC: <stable@vger.kernel.org> [4.6+]
|
||||
Signed-off-by: Oren Givon <oren.givon@intel.com>
|
||||
Signed-off-by: David Spinadel <david.spinadel@intel.com>
|
||||
Signed-off-by: Luca Coelho <luciano.coelho@intel.com>
|
||||
---
|
||||
drivers/net/wireless/intel/iwlwifi/pcie/drv.c | 6 ++++++
|
||||
1 file changed, 6 insertions(+)
|
||||
|
||||
diff --git a/drivers/net/wireless/intel/iwlwifi/pcie/drv.c b/drivers/net/wireless/intel/iwlwifi/pcie/drv.c
|
||||
index 1cae19d..6f020e4 100644
|
||||
--- a/drivers/net/wireless/intel/iwlwifi/pcie/drv.c
|
||||
+++ b/drivers/net/wireless/intel/iwlwifi/pcie/drv.c
|
||||
@@ -484,6 +484,8 @@ static const struct pci_device_id iwl_hw_card_ids[] = {
|
||||
{IWL_PCI_DEVICE(0x24FD, 0x0010, iwl8265_2ac_cfg)},
|
||||
{IWL_PCI_DEVICE(0x24FD, 0x0110, iwl8265_2ac_cfg)},
|
||||
{IWL_PCI_DEVICE(0x24FD, 0x1110, iwl8265_2ac_cfg)},
|
||||
+ {IWL_PCI_DEVICE(0x24FD, 0x1130, iwl8265_2ac_cfg)},
|
||||
+ {IWL_PCI_DEVICE(0x24FD, 0x0130, iwl8265_2ac_cfg)},
|
||||
{IWL_PCI_DEVICE(0x24FD, 0x1010, iwl8265_2ac_cfg)},
|
||||
{IWL_PCI_DEVICE(0x24FD, 0x0050, iwl8265_2ac_cfg)},
|
||||
{IWL_PCI_DEVICE(0x24FD, 0x0150, iwl8265_2ac_cfg)},
|
||||
@@ -494,6 +496,10 @@ static const struct pci_device_id iwl_hw_card_ids[] = {
|
||||
{IWL_PCI_DEVICE(0x24FD, 0x0810, iwl8265_2ac_cfg)},
|
||||
{IWL_PCI_DEVICE(0x24FD, 0x9110, iwl8265_2ac_cfg)},
|
||||
{IWL_PCI_DEVICE(0x24FD, 0x8130, iwl8265_2ac_cfg)},
|
||||
+ {IWL_PCI_DEVICE(0x24FD, 0x0910, iwl8265_2ac_cfg)},
|
||||
+ {IWL_PCI_DEVICE(0x24FD, 0x0930, iwl8265_2ac_cfg)},
|
||||
+ {IWL_PCI_DEVICE(0x24FD, 0x0950, iwl8265_2ac_cfg)},
|
||||
+ {IWL_PCI_DEVICE(0x24FD, 0x0850, iwl8265_2ac_cfg)},
|
||||
|
||||
/* 9000 Series */
|
||||
{IWL_PCI_DEVICE(0x2526, 0x0000, iwl9260_2ac_cfg)},
|
||||
--
|
||||
2.8.1
|
||||
-58
@@ -1,58 +0,0 @@
|
||||
From: Luca Coelho <luca-XPOmlcxoEMv1KXRcyAk9cg@public.gmane.org>
|
||||
Subject: [PATCH 28/56] iwlwifi: pcie: enable interrupts before releasing the NIC's CPU
|
||||
Date: Wed, 6 Jul 2016 13:40:23 +0300
|
||||
|
||||
From: Emmanuel Grumbach <emmanuel.grumbach-ral2JQCrhuEAvxtiuMwx3w@public.gmane.org>
|
||||
|
||||
The NIC's CPU gets started after the firmware has been
|
||||
written to its memory. The first thing it does is to
|
||||
send an interrupt to let the driver know that it is
|
||||
running. In order to get that interrupt, the driver needs
|
||||
to make sure it is not masked. Of course, the interrupt
|
||||
needs to be enabled in the driver before the CPU starts to
|
||||
run.
|
||||
I mistakenly inversed those two steps leading to races
|
||||
which prevented the driver from getting the alive interrupt
|
||||
from the firmware.
|
||||
Fix that.
|
||||
|
||||
Cc: <stable-u79uwXL29TY76Z2rM5mHXA@public.gmane.org> [4.5+]
|
||||
Fixes: a6bd005fe92 ("iwlwifi: pcie: fix RF-Kill vs. firmware load race")
|
||||
Signed-off-by: Emmanuel Grumbach <emmanuel.grumbach-ral2JQCrhuEAvxtiuMwx3w@public.gmane.org>
|
||||
Signed-off-by: Luca Coelho <luciano.coelho-ral2JQCrhuEAvxtiuMwx3w@public.gmane.org>
|
||||
---
|
||||
drivers/net/wireless/intel/iwlwifi/pcie/trans.c | 5 ++++-
|
||||
1 file changed, 4 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/drivers/net/wireless/intel/iwlwifi/pcie/trans.c b/drivers/net/wireless/intel/iwlwifi/pcie/trans.c
|
||||
index 3badebb..ac623c3 100644
|
||||
--- a/drivers/net/wireless/intel/iwlwifi/pcie/trans.c
|
||||
+++ b/drivers/net/wireless/intel/iwlwifi/pcie/trans.c
|
||||
@@ -801,6 +801,8 @@ static int iwl_pcie_load_cpu_sections_8000(struct iwl_trans *trans,
|
||||
|
||||
*first_ucode_section = last_read_idx;
|
||||
|
||||
+ iwl_enable_interrupts(trans);
|
||||
+
|
||||
if (cpu == 1)
|
||||
iwl_write_direct32(trans, FH_UCODE_LOAD_STATUS, 0xFFFF);
|
||||
else
|
||||
@@ -980,6 +982,8 @@ static int iwl_pcie_load_given_ucode(struct iwl_trans *trans,
|
||||
iwl_pcie_apply_destination(trans);
|
||||
}
|
||||
|
||||
+ iwl_enable_interrupts(trans);
|
||||
+
|
||||
/* release CPU reset */
|
||||
iwl_write32(trans, CSR_RESET, 0);
|
||||
|
||||
@@ -1215,7 +1219,6 @@ static int iwl_trans_pcie_start_fw(struct iwl_trans *trans,
|
||||
ret = iwl_pcie_load_given_ucode_8000(trans, fw);
|
||||
else
|
||||
ret = iwl_pcie_load_given_ucode(trans, fw);
|
||||
- iwl_enable_interrupts(trans);
|
||||
|
||||
/* re-check RF-Kill state since we may have missed the interrupt */
|
||||
hw_rfkill = iwl_is_rfkill_set(trans);
|
||||
--
|
||||
2.8.1
|
||||
-195
@@ -1,195 +0,0 @@
|
||||
From: Luca Coelho <luca@coelho.fi>
|
||||
Subject: [PATCH 48/56] iwlwifi: pcie: fix a race in firmware loading flow
|
||||
Date: Wed, 6 Jul 2016 13:40:43 +0300
|
||||
|
||||
From: Emmanuel Grumbach <emmanuel.grumbach@intel.com>
|
||||
|
||||
Upon firmware load interrupt (FH_TX), the ISR re-enables the
|
||||
firmware load interrupt only to avoid races with other
|
||||
flows as described in the commit below. When the firmware
|
||||
is completely loaded, the thread that is loading the
|
||||
firmware will enable all the interrupts to make sure that
|
||||
the driver gets the ALIVE interrupt.
|
||||
The problem with that is that the thread that is loading
|
||||
the firmware is actually racing against the ISR and we can
|
||||
get to the following situation:
|
||||
|
||||
CPU0 CPU1
|
||||
iwl_pcie_load_given_ucode
|
||||
...
|
||||
iwl_pcie_load_firmware_chunk
|
||||
wait_for_interrupt
|
||||
<interrupt>
|
||||
ISR handles CSR_INT_BIT_FH_TX
|
||||
ISR wakes up the thread on CPU0
|
||||
/* enable all the interrupts
|
||||
* to get the ALIVE interrupt
|
||||
*/
|
||||
iwl_enable_interrupts
|
||||
ISR re-enables CSR_INT_BIT_FH_TX only
|
||||
/* start the firmware */
|
||||
iwl_write32(trans, CSR_RESET, 0);
|
||||
|
||||
BUG! ALIVE interrupt will never arrive since it has been
|
||||
masked by CPU1.
|
||||
|
||||
In order to fix that, change the ISR to first check if
|
||||
STATUS_INT_ENABLED is set. If so, re-enable all the
|
||||
interrupts. If STATUS_INT_ENABLED is clear, then we can
|
||||
check what specific interrupt happened and re-enable only
|
||||
that specific interrupt (RFKILL or FH_TX).
|
||||
|
||||
All the credit for the analysis goes to Kirtika who did the
|
||||
actual debugging work.
|
||||
|
||||
Cc: <stable@vger.kernel.org> [4.5+]
|
||||
Fixes: a6bd005fe92 ("iwlwifi: pcie: fix RF-Kill vs. firmware load race")
|
||||
Signed-off-by: Luca Coelho <luciano.coelho@intel.com>
|
||||
---
|
||||
drivers/net/wireless/intel/iwlwifi/pcie/internal.h | 21 +++++++++++++++++++--
|
||||
drivers/net/wireless/intel/iwlwifi/pcie/rx.c | 16 +++++++++-------
|
||||
drivers/net/wireless/intel/iwlwifi/pcie/trans.c | 8 --------
|
||||
3 files changed, 28 insertions(+), 17 deletions(-)
|
||||
|
||||
diff --git a/drivers/net/wireless/intel/iwlwifi/pcie/internal.h b/drivers/net/wireless/intel/iwlwifi/pcie/internal.h
|
||||
index f684b9d..54af3da 100644
|
||||
--- a/drivers/net/wireless/intel/iwlwifi/pcie/internal.h
|
||||
+++ b/drivers/net/wireless/intel/iwlwifi/pcie/internal.h
|
||||
@@ -500,7 +500,7 @@ void iwl_pcie_dump_csr(struct iwl_trans *trans);
|
||||
/*****************************************************
|
||||
* Helpers
|
||||
******************************************************/
|
||||
-static inline void iwl_disable_interrupts(struct iwl_trans *trans)
|
||||
+static inline void _iwl_disable_interrupts(struct iwl_trans *trans)
|
||||
{
|
||||
struct iwl_trans_pcie *trans_pcie = IWL_TRANS_GET_PCIE_TRANS(trans);
|
||||
|
||||
@@ -523,7 +523,16 @@ static inline void iwl_disable_interrupts(struct iwl_trans *trans)
|
||||
IWL_DEBUG_ISR(trans, "Disabled interrupts\n");
|
||||
}
|
||||
|
||||
-static inline void iwl_enable_interrupts(struct iwl_trans *trans)
|
||||
+static inline void iwl_disable_interrupts(struct iwl_trans *trans)
|
||||
+{
|
||||
+ struct iwl_trans_pcie *trans_pcie = IWL_TRANS_GET_PCIE_TRANS(trans);
|
||||
+
|
||||
+ spin_lock(&trans_pcie->irq_lock);
|
||||
+ _iwl_disable_interrupts(trans);
|
||||
+ spin_unlock(&trans_pcie->irq_lock);
|
||||
+}
|
||||
+
|
||||
+static inline void _iwl_enable_interrupts(struct iwl_trans *trans)
|
||||
{
|
||||
struct iwl_trans_pcie *trans_pcie = IWL_TRANS_GET_PCIE_TRANS(trans);
|
||||
|
||||
@@ -546,6 +555,14 @@ static inline void iwl_enable_interrupts(struct iwl_trans *trans)
|
||||
}
|
||||
}
|
||||
|
||||
+static inline void iwl_enable_interrupts(struct iwl_trans *trans)
|
||||
+{
|
||||
+ struct iwl_trans_pcie *trans_pcie = IWL_TRANS_GET_PCIE_TRANS(trans);
|
||||
+
|
||||
+ spin_lock(&trans_pcie->irq_lock);
|
||||
+ _iwl_enable_interrupts(trans);
|
||||
+ spin_unlock(&trans_pcie->irq_lock);
|
||||
+}
|
||||
static inline void iwl_enable_hw_int_msk_msix(struct iwl_trans *trans, u32 msk)
|
||||
{
|
||||
struct iwl_trans_pcie *trans_pcie = IWL_TRANS_GET_PCIE_TRANS(trans);
|
||||
diff --git a/drivers/net/wireless/intel/iwlwifi/pcie/rx.c b/drivers/net/wireless/intel/iwlwifi/pcie/rx.c
|
||||
index 0296c29..45f1b7e 100644
|
||||
--- a/drivers/net/wireless/intel/iwlwifi/pcie/rx.c
|
||||
+++ b/drivers/net/wireless/intel/iwlwifi/pcie/rx.c
|
||||
@@ -1535,7 +1535,7 @@ irqreturn_t iwl_pcie_irq_handler(int irq, void *dev_id)
|
||||
* have anything to service
|
||||
*/
|
||||
if (test_bit(STATUS_INT_ENABLED, &trans->status))
|
||||
- iwl_enable_interrupts(trans);
|
||||
+ _iwl_enable_interrupts(trans);
|
||||
spin_unlock(&trans_pcie->irq_lock);
|
||||
lock_map_release(&trans->sync_cmd_lockdep_map);
|
||||
return IRQ_NONE;
|
||||
@@ -1727,15 +1727,17 @@ irqreturn_t iwl_pcie_irq_handler(int irq, void *dev_id)
|
||||
inta & ~trans_pcie->inta_mask);
|
||||
}
|
||||
|
||||
+ spin_lock(&trans_pcie->irq_lock);
|
||||
+ /* only Re-enable all interrupt if disabled by irq */
|
||||
+ if (test_bit(STATUS_INT_ENABLED, &trans->status))
|
||||
+ _iwl_enable_interrupts(trans);
|
||||
/* we are loading the firmware, enable FH_TX interrupt only */
|
||||
- if (handled & CSR_INT_BIT_FH_TX)
|
||||
+ else if (handled & CSR_INT_BIT_FH_TX)
|
||||
iwl_enable_fw_load_int(trans);
|
||||
- /* only Re-enable all interrupt if disabled by irq */
|
||||
- else if (test_bit(STATUS_INT_ENABLED, &trans->status))
|
||||
- iwl_enable_interrupts(trans);
|
||||
/* Re-enable RF_KILL if it occurred */
|
||||
else if (handled & CSR_INT_BIT_RF_KILL)
|
||||
iwl_enable_rfkill_int(trans);
|
||||
+ spin_unlock(&trans_pcie->irq_lock);
|
||||
|
||||
out:
|
||||
lock_map_release(&trans->sync_cmd_lockdep_map);
|
||||
@@ -1799,7 +1801,7 @@ void iwl_pcie_reset_ict(struct iwl_trans *trans)
|
||||
return;
|
||||
|
||||
spin_lock(&trans_pcie->irq_lock);
|
||||
- iwl_disable_interrupts(trans);
|
||||
+ _iwl_disable_interrupts(trans);
|
||||
|
||||
memset(trans_pcie->ict_tbl, 0, ICT_SIZE);
|
||||
|
||||
@@ -1815,7 +1817,7 @@ void iwl_pcie_reset_ict(struct iwl_trans *trans)
|
||||
trans_pcie->use_ict = true;
|
||||
trans_pcie->ict_index = 0;
|
||||
iwl_write32(trans, CSR_INT, trans_pcie->inta_mask);
|
||||
- iwl_enable_interrupts(trans);
|
||||
+ _iwl_enable_interrupts(trans);
|
||||
spin_unlock(&trans_pcie->irq_lock);
|
||||
}
|
||||
|
||||
diff --git a/drivers/net/wireless/intel/iwlwifi/pcie/trans.c b/drivers/net/wireless/intel/iwlwifi/pcie/trans.c
|
||||
index 3b7a414..9e953a4 100644
|
||||
--- a/drivers/net/wireless/intel/iwlwifi/pcie/trans.c
|
||||
+++ b/drivers/net/wireless/intel/iwlwifi/pcie/trans.c
|
||||
@@ -1037,9 +1037,7 @@ static void _iwl_trans_pcie_stop_device(struct iwl_trans *trans, bool low_power)
|
||||
was_hw_rfkill = iwl_is_rfkill_set(trans);
|
||||
|
||||
/* tell the device to stop sending interrupts */
|
||||
- spin_lock(&trans_pcie->irq_lock);
|
||||
iwl_disable_interrupts(trans);
|
||||
- spin_unlock(&trans_pcie->irq_lock);
|
||||
|
||||
/* device going down, Stop using ICT table */
|
||||
iwl_pcie_disable_ict(trans);
|
||||
@@ -1083,9 +1081,7 @@ static void _iwl_trans_pcie_stop_device(struct iwl_trans *trans, bool low_power)
|
||||
* the time, unless the interrupt is ACKed even if the interrupt
|
||||
* should be masked. Re-ACK all the interrupts here.
|
||||
*/
|
||||
- spin_lock(&trans_pcie->irq_lock);
|
||||
iwl_disable_interrupts(trans);
|
||||
- spin_unlock(&trans_pcie->irq_lock);
|
||||
|
||||
/* clear all status bits */
|
||||
clear_bit(STATUS_SYNC_HCMD_ACTIVE, &trans->status);
|
||||
@@ -1578,15 +1574,11 @@ static void iwl_trans_pcie_op_mode_leave(struct iwl_trans *trans)
|
||||
mutex_lock(&trans_pcie->mutex);
|
||||
|
||||
/* disable interrupts - don't enable HW RF kill interrupt */
|
||||
- spin_lock(&trans_pcie->irq_lock);
|
||||
iwl_disable_interrupts(trans);
|
||||
- spin_unlock(&trans_pcie->irq_lock);
|
||||
|
||||
iwl_pcie_apm_stop(trans, true);
|
||||
|
||||
- spin_lock(&trans_pcie->irq_lock);
|
||||
iwl_disable_interrupts(trans);
|
||||
- spin_unlock(&trans_pcie->irq_lock);
|
||||
|
||||
iwl_pcie_disable_ict(trans);
|
||||
|
||||
--
|
||||
2.8.1
|
||||
|
||||
-339
@@ -1,339 +0,0 @@
|
||||
From 0bd50d719b004110e791800450ad204399100a86 Mon Sep 17 00:00:00 2001
|
||||
From: Dan O'Donovan <dan@emutex.com>
|
||||
Date: Fri, 10 Jun 2016 13:23:34 +0100
|
||||
Subject: [PATCH] pinctrl: cherryview: prevent concurrent access to GPIO
|
||||
controllers
|
||||
|
||||
Due to a silicon issue on the Atom X5-Z8000 "Cherry Trail" processor
|
||||
series, a common lock must be used to prevent concurrent accesses
|
||||
across the 4 GPIO controllers managed by this driver.
|
||||
|
||||
See Intel Atom Z8000 Processor Series Specification Update
|
||||
(Rev. 005), errata #CHT34, for further information.
|
||||
|
||||
Cc: stable <stable@vger.kernel.org>
|
||||
Signed-off-by: Dan O'Donovan <dan@emutex.com>
|
||||
Acked-by: Mika Westerberg <mika.westerberg@linux.intel.com>
|
||||
Signed-off-by: Linus Walleij <linus.walleij@linaro.org>
|
||||
---
|
||||
drivers/pinctrl/intel/pinctrl-cherryview.c | 80 ++++++++++++++++--------------
|
||||
1 file changed, 44 insertions(+), 36 deletions(-)
|
||||
|
||||
diff --git a/drivers/pinctrl/intel/pinctrl-cherryview.c b/drivers/pinctrl/intel/pinctrl-cherryview.c
|
||||
index ac4f564..bf65c94 100644
|
||||
--- a/drivers/pinctrl/intel/pinctrl-cherryview.c
|
||||
+++ b/drivers/pinctrl/intel/pinctrl-cherryview.c
|
||||
@@ -160,7 +160,6 @@ struct chv_pin_context {
|
||||
* @pctldev: Pointer to the pin controller device
|
||||
* @chip: GPIO chip in this pin controller
|
||||
* @regs: MMIO registers
|
||||
- * @lock: Lock to serialize register accesses
|
||||
* @intr_lines: Stores mapping between 16 HW interrupt wires and GPIO
|
||||
* offset (in GPIO number space)
|
||||
* @community: Community this pinctrl instance represents
|
||||
@@ -174,7 +173,6 @@ struct chv_pinctrl {
|
||||
struct pinctrl_dev *pctldev;
|
||||
struct gpio_chip chip;
|
||||
void __iomem *regs;
|
||||
- raw_spinlock_t lock;
|
||||
unsigned intr_lines[16];
|
||||
const struct chv_community *community;
|
||||
u32 saved_intmask;
|
||||
@@ -657,6 +655,17 @@ static const struct chv_community *chv_communities[] = {
|
||||
&southeast_community,
|
||||
};
|
||||
|
||||
+/*
|
||||
+ * Lock to serialize register accesses
|
||||
+ *
|
||||
+ * Due to a silicon issue, a shared lock must be used to prevent
|
||||
+ * concurrent accesses across the 4 GPIO controllers.
|
||||
+ *
|
||||
+ * See Intel Atom Z8000 Processor Series Specification Update (Rev. 005),
|
||||
+ * errata #CHT34, for further information.
|
||||
+ */
|
||||
+static DEFINE_RAW_SPINLOCK(chv_lock);
|
||||
+
|
||||
static void __iomem *chv_padreg(struct chv_pinctrl *pctrl, unsigned offset,
|
||||
unsigned reg)
|
||||
{
|
||||
@@ -718,13 +727,13 @@ static void chv_pin_dbg_show(struct pinctrl_dev *pctldev, struct seq_file *s,
|
||||
u32 ctrl0, ctrl1;
|
||||
bool locked;
|
||||
|
||||
- raw_spin_lock_irqsave(&pctrl->lock, flags);
|
||||
+ raw_spin_lock_irqsave(&chv_lock, flags);
|
||||
|
||||
ctrl0 = readl(chv_padreg(pctrl, offset, CHV_PADCTRL0));
|
||||
ctrl1 = readl(chv_padreg(pctrl, offset, CHV_PADCTRL1));
|
||||
locked = chv_pad_locked(pctrl, offset);
|
||||
|
||||
- raw_spin_unlock_irqrestore(&pctrl->lock, flags);
|
||||
+ raw_spin_unlock_irqrestore(&chv_lock, flags);
|
||||
|
||||
if (ctrl0 & CHV_PADCTRL0_GPIOEN) {
|
||||
seq_puts(s, "GPIO ");
|
||||
@@ -787,14 +796,14 @@ static int chv_pinmux_set_mux(struct pinctrl_dev *pctldev, unsigned function,
|
||||
|
||||
grp = &pctrl->community->groups[group];
|
||||
|
||||
- raw_spin_lock_irqsave(&pctrl->lock, flags);
|
||||
+ raw_spin_lock_irqsave(&chv_lock, flags);
|
||||
|
||||
/* Check first that the pad is not locked */
|
||||
for (i = 0; i < grp->npins; i++) {
|
||||
if (chv_pad_locked(pctrl, grp->pins[i])) {
|
||||
dev_warn(pctrl->dev, "unable to set mode for locked pin %u\n",
|
||||
grp->pins[i]);
|
||||
- raw_spin_unlock_irqrestore(&pctrl->lock, flags);
|
||||
+ raw_spin_unlock_irqrestore(&chv_lock, flags);
|
||||
return -EBUSY;
|
||||
}
|
||||
}
|
||||
@@ -837,7 +846,7 @@ static int chv_pinmux_set_mux(struct pinctrl_dev *pctldev, unsigned function,
|
||||
pin, altfunc->mode, altfunc->invert_oe ? "" : "not ");
|
||||
}
|
||||
|
||||
- raw_spin_unlock_irqrestore(&pctrl->lock, flags);
|
||||
+ raw_spin_unlock_irqrestore(&chv_lock, flags);
|
||||
|
||||
return 0;
|
||||
}
|
||||
@@ -851,13 +860,13 @@ static int chv_gpio_request_enable(struct pinctrl_dev *pctldev,
|
||||
void __iomem *reg;
|
||||
u32 value;
|
||||
|
||||
- raw_spin_lock_irqsave(&pctrl->lock, flags);
|
||||
+ raw_spin_lock_irqsave(&chv_lock, flags);
|
||||
|
||||
if (chv_pad_locked(pctrl, offset)) {
|
||||
value = readl(chv_padreg(pctrl, offset, CHV_PADCTRL0));
|
||||
if (!(value & CHV_PADCTRL0_GPIOEN)) {
|
||||
/* Locked so cannot enable */
|
||||
- raw_spin_unlock_irqrestore(&pctrl->lock, flags);
|
||||
+ raw_spin_unlock_irqrestore(&chv_lock, flags);
|
||||
return -EBUSY;
|
||||
}
|
||||
} else {
|
||||
@@ -897,7 +906,7 @@ static int chv_gpio_request_enable(struct pinctrl_dev *pctldev,
|
||||
chv_writel(value, reg);
|
||||
}
|
||||
|
||||
- raw_spin_unlock_irqrestore(&pctrl->lock, flags);
|
||||
+ raw_spin_unlock_irqrestore(&chv_lock, flags);
|
||||
|
||||
return 0;
|
||||
}
|
||||
@@ -911,13 +920,13 @@ static void chv_gpio_disable_free(struct pinctrl_dev *pctldev,
|
||||
void __iomem *reg;
|
||||
u32 value;
|
||||
|
||||
- raw_spin_lock_irqsave(&pctrl->lock, flags);
|
||||
+ raw_spin_lock_irqsave(&chv_lock, flags);
|
||||
|
||||
reg = chv_padreg(pctrl, offset, CHV_PADCTRL0);
|
||||
value = readl(reg) & ~CHV_PADCTRL0_GPIOEN;
|
||||
chv_writel(value, reg);
|
||||
|
||||
- raw_spin_unlock_irqrestore(&pctrl->lock, flags);
|
||||
+ raw_spin_unlock_irqrestore(&chv_lock, flags);
|
||||
}
|
||||
|
||||
static int chv_gpio_set_direction(struct pinctrl_dev *pctldev,
|
||||
@@ -929,7 +938,7 @@ static int chv_gpio_set_direction(struct pinctrl_dev *pctldev,
|
||||
unsigned long flags;
|
||||
u32 ctrl0;
|
||||
|
||||
- raw_spin_lock_irqsave(&pctrl->lock, flags);
|
||||
+ raw_spin_lock_irqsave(&chv_lock, flags);
|
||||
|
||||
ctrl0 = readl(reg) & ~CHV_PADCTRL0_GPIOCFG_MASK;
|
||||
if (input)
|
||||
@@ -938,7 +947,7 @@ static int chv_gpio_set_direction(struct pinctrl_dev *pctldev,
|
||||
ctrl0 |= CHV_PADCTRL0_GPIOCFG_GPO << CHV_PADCTRL0_GPIOCFG_SHIFT;
|
||||
chv_writel(ctrl0, reg);
|
||||
|
||||
- raw_spin_unlock_irqrestore(&pctrl->lock, flags);
|
||||
+ raw_spin_unlock_irqrestore(&chv_lock, flags);
|
||||
|
||||
return 0;
|
||||
}
|
||||
@@ -963,10 +972,10 @@ static int chv_config_get(struct pinctrl_dev *pctldev, unsigned pin,
|
||||
u16 arg = 0;
|
||||
u32 term;
|
||||
|
||||
- raw_spin_lock_irqsave(&pctrl->lock, flags);
|
||||
+ raw_spin_lock_irqsave(&chv_lock, flags);
|
||||
ctrl0 = readl(chv_padreg(pctrl, pin, CHV_PADCTRL0));
|
||||
ctrl1 = readl(chv_padreg(pctrl, pin, CHV_PADCTRL1));
|
||||
- raw_spin_unlock_irqrestore(&pctrl->lock, flags);
|
||||
+ raw_spin_unlock_irqrestore(&chv_lock, flags);
|
||||
|
||||
term = (ctrl0 & CHV_PADCTRL0_TERM_MASK) >> CHV_PADCTRL0_TERM_SHIFT;
|
||||
|
||||
@@ -1040,7 +1049,7 @@ static int chv_config_set_pull(struct chv_pinctrl *pctrl, unsigned pin,
|
||||
unsigned long flags;
|
||||
u32 ctrl0, pull;
|
||||
|
||||
- raw_spin_lock_irqsave(&pctrl->lock, flags);
|
||||
+ raw_spin_lock_irqsave(&chv_lock, flags);
|
||||
ctrl0 = readl(reg);
|
||||
|
||||
switch (param) {
|
||||
@@ -1063,7 +1072,7 @@ static int chv_config_set_pull(struct chv_pinctrl *pctrl, unsigned pin,
|
||||
pull = CHV_PADCTRL0_TERM_20K << CHV_PADCTRL0_TERM_SHIFT;
|
||||
break;
|
||||
default:
|
||||
- raw_spin_unlock_irqrestore(&pctrl->lock, flags);
|
||||
+ raw_spin_unlock_irqrestore(&chv_lock, flags);
|
||||
return -EINVAL;
|
||||
}
|
||||
|
||||
@@ -1081,7 +1090,7 @@ static int chv_config_set_pull(struct chv_pinctrl *pctrl, unsigned pin,
|
||||
pull = CHV_PADCTRL0_TERM_20K << CHV_PADCTRL0_TERM_SHIFT;
|
||||
break;
|
||||
default:
|
||||
- raw_spin_unlock_irqrestore(&pctrl->lock, flags);
|
||||
+ raw_spin_unlock_irqrestore(&chv_lock, flags);
|
||||
return -EINVAL;
|
||||
}
|
||||
|
||||
@@ -1089,12 +1098,12 @@ static int chv_config_set_pull(struct chv_pinctrl *pctrl, unsigned pin,
|
||||
break;
|
||||
|
||||
default:
|
||||
- raw_spin_unlock_irqrestore(&pctrl->lock, flags);
|
||||
+ raw_spin_unlock_irqrestore(&chv_lock, flags);
|
||||
return -EINVAL;
|
||||
}
|
||||
|
||||
chv_writel(ctrl0, reg);
|
||||
- raw_spin_unlock_irqrestore(&pctrl->lock, flags);
|
||||
+ raw_spin_unlock_irqrestore(&chv_lock, flags);
|
||||
|
||||
return 0;
|
||||
}
|
||||
@@ -1160,9 +1169,9 @@ static int chv_gpio_get(struct gpio_chip *chip, unsigned offset)
|
||||
unsigned long flags;
|
||||
u32 ctrl0, cfg;
|
||||
|
||||
- raw_spin_lock_irqsave(&pctrl->lock, flags);
|
||||
+ raw_spin_lock_irqsave(&chv_lock, flags);
|
||||
ctrl0 = readl(chv_padreg(pctrl, pin, CHV_PADCTRL0));
|
||||
- raw_spin_unlock_irqrestore(&pctrl->lock, flags);
|
||||
+ raw_spin_unlock_irqrestore(&chv_lock, flags);
|
||||
|
||||
cfg = ctrl0 & CHV_PADCTRL0_GPIOCFG_MASK;
|
||||
cfg >>= CHV_PADCTRL0_GPIOCFG_SHIFT;
|
||||
@@ -1180,7 +1189,7 @@ static void chv_gpio_set(struct gpio_chip *chip, unsigned offset, int value)
|
||||
void __iomem *reg;
|
||||
u32 ctrl0;
|
||||
|
||||
- raw_spin_lock_irqsave(&pctrl->lock, flags);
|
||||
+ raw_spin_lock_irqsave(&chv_lock, flags);
|
||||
|
||||
reg = chv_padreg(pctrl, pin, CHV_PADCTRL0);
|
||||
ctrl0 = readl(reg);
|
||||
@@ -1192,7 +1201,7 @@ static void chv_gpio_set(struct gpio_chip *chip, unsigned offset, int value)
|
||||
|
||||
chv_writel(ctrl0, reg);
|
||||
|
||||
- raw_spin_unlock_irqrestore(&pctrl->lock, flags);
|
||||
+ raw_spin_unlock_irqrestore(&chv_lock, flags);
|
||||
}
|
||||
|
||||
static int chv_gpio_get_direction(struct gpio_chip *chip, unsigned offset)
|
||||
@@ -1202,9 +1211,9 @@ static int chv_gpio_get_direction(struct gpio_chip *chip, unsigned offset)
|
||||
u32 ctrl0, direction;
|
||||
unsigned long flags;
|
||||
|
||||
- raw_spin_lock_irqsave(&pctrl->lock, flags);
|
||||
+ raw_spin_lock_irqsave(&chv_lock, flags);
|
||||
ctrl0 = readl(chv_padreg(pctrl, pin, CHV_PADCTRL0));
|
||||
- raw_spin_unlock_irqrestore(&pctrl->lock, flags);
|
||||
+ raw_spin_unlock_irqrestore(&chv_lock, flags);
|
||||
|
||||
direction = ctrl0 & CHV_PADCTRL0_GPIOCFG_MASK;
|
||||
direction >>= CHV_PADCTRL0_GPIOCFG_SHIFT;
|
||||
@@ -1242,14 +1251,14 @@ static void chv_gpio_irq_ack(struct irq_data *d)
|
||||
int pin = chv_gpio_offset_to_pin(pctrl, irqd_to_hwirq(d));
|
||||
u32 intr_line;
|
||||
|
||||
- raw_spin_lock(&pctrl->lock);
|
||||
+ raw_spin_lock(&chv_lock);
|
||||
|
||||
intr_line = readl(chv_padreg(pctrl, pin, CHV_PADCTRL0));
|
||||
intr_line &= CHV_PADCTRL0_INTSEL_MASK;
|
||||
intr_line >>= CHV_PADCTRL0_INTSEL_SHIFT;
|
||||
chv_writel(BIT(intr_line), pctrl->regs + CHV_INTSTAT);
|
||||
|
||||
- raw_spin_unlock(&pctrl->lock);
|
||||
+ raw_spin_unlock(&chv_lock);
|
||||
}
|
||||
|
||||
static void chv_gpio_irq_mask_unmask(struct irq_data *d, bool mask)
|
||||
@@ -1260,7 +1269,7 @@ static void chv_gpio_irq_mask_unmask(struct irq_data *d, bool mask)
|
||||
u32 value, intr_line;
|
||||
unsigned long flags;
|
||||
|
||||
- raw_spin_lock_irqsave(&pctrl->lock, flags);
|
||||
+ raw_spin_lock_irqsave(&chv_lock, flags);
|
||||
|
||||
intr_line = readl(chv_padreg(pctrl, pin, CHV_PADCTRL0));
|
||||
intr_line &= CHV_PADCTRL0_INTSEL_MASK;
|
||||
@@ -1273,7 +1282,7 @@ static void chv_gpio_irq_mask_unmask(struct irq_data *d, bool mask)
|
||||
value |= BIT(intr_line);
|
||||
chv_writel(value, pctrl->regs + CHV_INTMASK);
|
||||
|
||||
- raw_spin_unlock_irqrestore(&pctrl->lock, flags);
|
||||
+ raw_spin_unlock_irqrestore(&chv_lock, flags);
|
||||
}
|
||||
|
||||
static void chv_gpio_irq_mask(struct irq_data *d)
|
||||
@@ -1307,7 +1316,7 @@ static unsigned chv_gpio_irq_startup(struct irq_data *d)
|
||||
unsigned long flags;
|
||||
u32 intsel, value;
|
||||
|
||||
- raw_spin_lock_irqsave(&pctrl->lock, flags);
|
||||
+ raw_spin_lock_irqsave(&chv_lock, flags);
|
||||
intsel = readl(chv_padreg(pctrl, pin, CHV_PADCTRL0));
|
||||
intsel &= CHV_PADCTRL0_INTSEL_MASK;
|
||||
intsel >>= CHV_PADCTRL0_INTSEL_SHIFT;
|
||||
@@ -1322,7 +1331,7 @@ static unsigned chv_gpio_irq_startup(struct irq_data *d)
|
||||
irq_set_handler_locked(d, handler);
|
||||
pctrl->intr_lines[intsel] = offset;
|
||||
}
|
||||
- raw_spin_unlock_irqrestore(&pctrl->lock, flags);
|
||||
+ raw_spin_unlock_irqrestore(&chv_lock, flags);
|
||||
}
|
||||
|
||||
chv_gpio_irq_unmask(d);
|
||||
@@ -1338,7 +1347,7 @@ static int chv_gpio_irq_type(struct irq_data *d, unsigned type)
|
||||
unsigned long flags;
|
||||
u32 value;
|
||||
|
||||
- raw_spin_lock_irqsave(&pctrl->lock, flags);
|
||||
+ raw_spin_lock_irqsave(&chv_lock, flags);
|
||||
|
||||
/*
|
||||
* Pins which can be used as shared interrupt are configured in
|
||||
@@ -1387,7 +1396,7 @@ static int chv_gpio_irq_type(struct irq_data *d, unsigned type)
|
||||
else if (type & IRQ_TYPE_LEVEL_MASK)
|
||||
irq_set_handler_locked(d, handle_level_irq);
|
||||
|
||||
- raw_spin_unlock_irqrestore(&pctrl->lock, flags);
|
||||
+ raw_spin_unlock_irqrestore(&chv_lock, flags);
|
||||
|
||||
return 0;
|
||||
}
|
||||
@@ -1499,7 +1508,6 @@ static int chv_pinctrl_probe(struct platform_device *pdev)
|
||||
if (i == ARRAY_SIZE(chv_communities))
|
||||
return -ENODEV;
|
||||
|
||||
- raw_spin_lock_init(&pctrl->lock);
|
||||
pctrl->dev = &pdev->dev;
|
||||
|
||||
#ifdef CONFIG_PM_SLEEP
|
||||
--
|
||||
2.9.2
|
||||
|
||||
@@ -38,15 +38,9 @@ x86-increase-default-minimum-vmalloc-area-by-64MB-to-192MB.patch
|
||||
# slows down boot
|
||||
Revert-cpufreq-pcc-Enable-autoload-of-pcc-cpufreq-fo.patch
|
||||
|
||||
#
|
||||
Revert-cpufreq-pcc-cpufreq-update-default-value-of-c.patch
|
||||
|
||||
# breaks nvidia304
|
||||
Revert-x86-mm-mtrr-Remove-kernel-internal-MTRR-inter.patch
|
||||
|
||||
#
|
||||
x86-power-64-Fix-hibernation-return-address-corrupti.patch
|
||||
|
||||
###
|
||||
### Core
|
||||
###
|
||||
@@ -128,9 +122,6 @@ block-Make-CFQ-default-to-IOPS-mode-on-SSDs.patch
|
||||
# ahci ids
|
||||
ahci-add-new-Intel-device-IDs.patch
|
||||
|
||||
#
|
||||
megaraid_sas-Do-not-fire-MR_DCMD_PD_LIST_QUERY-to-co.patch
|
||||
|
||||
###
|
||||
### Char
|
||||
###
|
||||
@@ -147,10 +138,6 @@ fs-aufs-4.7.patch
|
||||
fs-aufs-4.7-modular.patch
|
||||
fs-aufs-4.7-ver-fix.patch
|
||||
|
||||
# ext4
|
||||
fs-ext4-don-t-call-ext4_should_journal_data-on-the-jour.patch
|
||||
fs-ext4-fix-deadlock-during-page-writeback.patch
|
||||
|
||||
###
|
||||
### FireWire
|
||||
###
|
||||
@@ -235,16 +222,6 @@ net-netfilter-psd.patch
|
||||
net-netfilter-psd-mdv.patch
|
||||
net-netfilter-psd-2.6.35-buildfix.patch
|
||||
|
||||
# iwlwifi fixes
|
||||
net-wireless-iwlwifi-add-new-8260-PCI-IDs.patch
|
||||
net-wireless-iwlwifi-add-new-8265.patch
|
||||
net-wireless-iwlwifi-pcie-enable-interrupts-before-releasing-the-NICs-CPU.patch
|
||||
net-wireless-iwlwifi-pcie-fix-a-race-in-firmware-loading-flow.patch
|
||||
|
||||
#
|
||||
net-bcma-add-PCI-ID-for-Foxconn-s-BCM43142-device.patch
|
||||
net-brcmfmac-restore-stopping-netdev-queue-when-bus-clog.patch
|
||||
|
||||
###
|
||||
### Platform drivers
|
||||
###
|
||||
@@ -256,12 +233,8 @@ platform-x86-shuttle-wmi-drop-devinit-exit.patch
|
||||
platform-x86-shuttle-wmi-4.2-buildfix.patch
|
||||
|
||||
#
|
||||
hp-wmi-Fix-wifi-cannot-be-hard-unblocked.patch
|
||||
|
||||
Bluetooth-Add-support-of-13d3-3490-AR3012-device.patch
|
||||
intel_th-Fix-a-deadlock-in-modprobing.patch
|
||||
intel_th-pci-Add-Kaby-Lake-PCH-H-support.patch
|
||||
pinctrl-cherryview-prevent-concurrent-access-to-GPIO.patch
|
||||
|
||||
###
|
||||
### RTC
|
||||
@@ -300,13 +273,6 @@ hid-usbhid-IBM-BladeCenterHS20-quirk.patch
|
||||
usb-storage-unusual_devs-add-id.patch
|
||||
usb-storage-unusual_devs-add-id-2.6.37-buildfix.patch
|
||||
|
||||
#
|
||||
usb-dwc3-fix-for-the-isoc-transfer-EP_BUSY-flag.patch
|
||||
usb-renesas_usbhs-fix-NULL-pointer-dereference-in-xf.patch
|
||||
|
||||
#
|
||||
HID-uhid-fix-timeout-when-probe-races-with-IO.patch
|
||||
|
||||
###
|
||||
### V4L
|
||||
###
|
||||
@@ -314,11 +280,6 @@ HID-uhid-fix-timeout-when-probe-races-with-IO.patch
|
||||
# pwc driver name in /proc/bus/devices, /sys fix and "advertisement" removal
|
||||
media-usb-pwc-lie-in-proc-usb-devices.patch
|
||||
|
||||
#
|
||||
media-media-usbtv-prevent-access-to-free-d-resources.patch
|
||||
media-vb2-core-Skip-planes-array-verification-if-pb-.patch
|
||||
media-videobuf2-v4l2-Verify-planes-array-in-buffer-d.patch
|
||||
|
||||
###
|
||||
### Video
|
||||
###
|
||||
|
||||
-42
@@ -1,42 +0,0 @@
|
||||
From 9cad39fe4e4a4fe95d8ea5a7b0692b0a6e89e38b Mon Sep 17 00:00:00 2001
|
||||
From: Konrad Leszczynski <konrad.leszczynski@intel.com>
|
||||
Date: Mon, 8 Feb 2016 16:13:12 +0100
|
||||
Subject: [PATCH] usb: dwc3: fix for the isoc transfer EP_BUSY flag
|
||||
|
||||
commit f3af36511e60 ("usb: dwc3: gadget: always
|
||||
enable IOC on bulk/interrupt transfers") ended up
|
||||
regressing Isochronous endpoints by clearing
|
||||
DWC3_EP_BUSY flag too early, which resulted in
|
||||
choppy audio playback over USB.
|
||||
|
||||
Fix that by partially reverting original commit and
|
||||
making sure that we check for isochronous endpoints.
|
||||
|
||||
Fixes: f3af36511e60 ("usb: dwc3: gadget: always enable IOC
|
||||
on bulk/interrupt transfers")
|
||||
Cc: <stable@vger.kernel.org>
|
||||
Signed-off-by: Konrad Leszczynski <konrad.leszczynski@intel.com>
|
||||
Signed-off-by: Rafal Redzimski <rafal.f.redzimski@intel.com>
|
||||
Signed-off-by: Felipe Balbi <felipe.balbi@linux.intel.com>
|
||||
---
|
||||
drivers/usb/dwc3/gadget.c | 4 ++++
|
||||
1 file changed, 4 insertions(+)
|
||||
|
||||
diff --git a/drivers/usb/dwc3/gadget.c b/drivers/usb/dwc3/gadget.c
|
||||
index 5e7b2ba..867adc9 100644
|
||||
--- a/drivers/usb/dwc3/gadget.c
|
||||
+++ b/drivers/usb/dwc3/gadget.c
|
||||
@@ -2058,6 +2058,10 @@ static int dwc3_cleanup_done_reqs(struct dwc3 *dwc, struct dwc3_ep *dep,
|
||||
return 1;
|
||||
}
|
||||
|
||||
+ if (usb_endpoint_xfer_isoc(dep->endpoint.desc))
|
||||
+ if ((event->status & DEPEVT_STATUS_IOC) &&
|
||||
+ (trb->ctrl & DWC3_TRB_CTRL_IOC))
|
||||
+ return 0;
|
||||
return 1;
|
||||
}
|
||||
|
||||
--
|
||||
2.9.2
|
||||
|
||||
-80
@@ -1,80 +0,0 @@
|
||||
From 4fdef698383db07d829da567e0e405fc41ff3a89 Mon Sep 17 00:00:00 2001
|
||||
From: Yoshihiro Shimoda <yoshihiro.shimoda.uh@renesas.com>
|
||||
Date: Wed, 8 Jun 2016 16:32:49 +0900
|
||||
Subject: [PATCH] usb: renesas_usbhs: fix NULL pointer dereference in
|
||||
xfer_work()
|
||||
|
||||
This patch fixes an issue that the xfer_work() is possible to cause
|
||||
NULL pointer dereference if the usb cable is disconnected while data
|
||||
transfer is running.
|
||||
|
||||
In such case, a gadget driver may call usb_ep_disable()) before
|
||||
xfer_work() is actually called. In this case, the usbhs_pkt_pop()
|
||||
will call usbhsf_fifo_unselect(), and then usbhs_pipe_to_fifo()
|
||||
in xfer_work() will return NULL.
|
||||
|
||||
Fixes: e73a989 ("usb: renesas_usbhs: add DMAEngine support")
|
||||
Cc: <stable@vger.kernel.org> # v3.1+
|
||||
Signed-off-by: Yoshihiro Shimoda <yoshihiro.shimoda.uh@renesas.com>
|
||||
Signed-off-by: Felipe Balbi <felipe.balbi@linux.intel.com>
|
||||
---
|
||||
drivers/usb/renesas_usbhs/fifo.c | 18 ++++++++++++++----
|
||||
1 file changed, 14 insertions(+), 4 deletions(-)
|
||||
|
||||
diff --git a/drivers/usb/renesas_usbhs/fifo.c b/drivers/usb/renesas_usbhs/fifo.c
|
||||
index 7be4e7d..280ed5f 100644
|
||||
--- a/drivers/usb/renesas_usbhs/fifo.c
|
||||
+++ b/drivers/usb/renesas_usbhs/fifo.c
|
||||
@@ -810,20 +810,27 @@ static void xfer_work(struct work_struct *work)
|
||||
{
|
||||
struct usbhs_pkt *pkt = container_of(work, struct usbhs_pkt, work);
|
||||
struct usbhs_pipe *pipe = pkt->pipe;
|
||||
- struct usbhs_fifo *fifo = usbhs_pipe_to_fifo(pipe);
|
||||
+ struct usbhs_fifo *fifo;
|
||||
struct usbhs_priv *priv = usbhs_pipe_to_priv(pipe);
|
||||
struct dma_async_tx_descriptor *desc;
|
||||
- struct dma_chan *chan = usbhsf_dma_chan_get(fifo, pkt);
|
||||
+ struct dma_chan *chan;
|
||||
struct device *dev = usbhs_priv_to_dev(priv);
|
||||
enum dma_transfer_direction dir;
|
||||
+ unsigned long flags;
|
||||
|
||||
+ usbhs_lock(priv, flags);
|
||||
+ fifo = usbhs_pipe_to_fifo(pipe);
|
||||
+ if (!fifo)
|
||||
+ goto xfer_work_end;
|
||||
+
|
||||
+ chan = usbhsf_dma_chan_get(fifo, pkt);
|
||||
dir = usbhs_pipe_is_dir_in(pipe) ? DMA_DEV_TO_MEM : DMA_MEM_TO_DEV;
|
||||
|
||||
desc = dmaengine_prep_slave_single(chan, pkt->dma + pkt->actual,
|
||||
pkt->trans, dir,
|
||||
DMA_PREP_INTERRUPT | DMA_CTRL_ACK);
|
||||
if (!desc)
|
||||
- return;
|
||||
+ goto xfer_work_end;
|
||||
|
||||
desc->callback = usbhsf_dma_complete;
|
||||
desc->callback_param = pipe;
|
||||
@@ -831,7 +838,7 @@ static void xfer_work(struct work_struct *work)
|
||||
pkt->cookie = dmaengine_submit(desc);
|
||||
if (pkt->cookie < 0) {
|
||||
dev_err(dev, "Failed to submit dma descriptor\n");
|
||||
- return;
|
||||
+ goto xfer_work_end;
|
||||
}
|
||||
|
||||
dev_dbg(dev, " %s %d (%d/ %d)\n",
|
||||
@@ -842,6 +849,9 @@ static void xfer_work(struct work_struct *work)
|
||||
usbhs_pipe_set_trans_count_if_bulk(pipe, pkt->trans);
|
||||
dma_async_issue_pending(chan);
|
||||
usbhs_pipe_enable(pipe);
|
||||
+
|
||||
+xfer_work_end:
|
||||
+ usbhs_unlock(priv, flags);
|
||||
}
|
||||
|
||||
/*
|
||||
--
|
||||
2.9.2
|
||||
|
||||
-101
@@ -1,101 +0,0 @@
|
||||
From 4ce827b4cc58bec7952591b96cce2b28553e4d5b Mon Sep 17 00:00:00 2001
|
||||
From: Josh Poimboeuf <jpoimboe@redhat.com>
|
||||
Date: Thu, 28 Jul 2016 23:15:21 +0200
|
||||
Subject: [PATCH] x86/power/64: Fix hibernation return address corruption
|
||||
|
||||
In kernel bug 150021, a kernel panic was reported when restoring a
|
||||
hibernate image. Only a picture of the oops was reported, so I can't
|
||||
paste the whole thing here. But here are the most interesting parts:
|
||||
|
||||
kernel tried to execute NX-protected page - exploit attempt? (uid: 0)
|
||||
BUG: unable to handle kernel paging request at ffff8804615cfd78
|
||||
...
|
||||
RIP: ffff8804615cfd78
|
||||
RSP: ffff8804615f0000
|
||||
RBP: ffff8804615cfdc0
|
||||
...
|
||||
Call Trace:
|
||||
do_signal+0x23
|
||||
exit_to_usermode_loop+0x64
|
||||
...
|
||||
|
||||
The RIP is on the same page as RBP, so it apparently started executing
|
||||
on the stack.
|
||||
|
||||
The bug was bisected to commit ef0f3ed5a4ac (x86/asm/power: Create
|
||||
stack frames in hibernate_asm_64.S), which in retrospect seems quite
|
||||
dangerous, since that code saves and restores the stack pointer from a
|
||||
global variable ('saved_context').
|
||||
|
||||
There are a lot of moving parts in the hibernate save and restore paths,
|
||||
so I don't know exactly what caused the panic. Presumably, a FRAME_END
|
||||
was executed without the corresponding FRAME_BEGIN, or vice versa. That
|
||||
would corrupt the return address on the stack and would be consistent
|
||||
with the details of the above panic.
|
||||
|
||||
[ rjw: One major problem is that by the time the FRAME_BEGIN in
|
||||
restore_registers() is executed, the stack pointer value may not
|
||||
be valid any more. Namely, the stack area pointed to by it
|
||||
previously may have been overwritten by some image memory contents
|
||||
and that page frame may now be used for whatever different purpose
|
||||
it had been allocated for before hibernation. In that case, the
|
||||
FRAME_BEGIN will corrupt that memory. ]
|
||||
|
||||
Instead of doing the frame pointer save/restore around the bounds of the
|
||||
affected functions, just do it around the call to swsusp_save().
|
||||
|
||||
That has the same effect of ensuring that if swsusp_save() sleeps, the
|
||||
frame pointers will be correct. It's also a much more obviously safe
|
||||
way to do it than the original patch. And objtool still doesn't report
|
||||
any warnings.
|
||||
|
||||
Fixes: ef0f3ed5a4ac (x86/asm/power: Create stack frames in hibernate_asm_64.S)
|
||||
Link: https://bugzilla.kernel.org/show_bug.cgi?id=150021
|
||||
Cc: 4.6+ <stable@vger.kernel.org> # 4.6+
|
||||
Reported-by: Andre Reinke <andre.reinke@mailbox.org>
|
||||
Tested-by: Andre Reinke <andre.reinke@mailbox.org>
|
||||
Signed-off-by: Josh Poimboeuf <jpoimboe@redhat.com>
|
||||
Acked-by: Ingo Molnar <mingo@kernel.org>
|
||||
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
|
||||
---
|
||||
arch/x86/power/hibernate_asm_64.S | 4 +---
|
||||
1 file changed, 1 insertion(+), 3 deletions(-)
|
||||
|
||||
diff --git a/arch/x86/power/hibernate_asm_64.S b/arch/x86/power/hibernate_asm_64.S
|
||||
index 3177c2b..8eee0e9 100644
|
||||
--- a/arch/x86/power/hibernate_asm_64.S
|
||||
+++ b/arch/x86/power/hibernate_asm_64.S
|
||||
@@ -24,7 +24,6 @@
|
||||
#include <asm/frame.h>
|
||||
|
||||
ENTRY(swsusp_arch_suspend)
|
||||
- FRAME_BEGIN
|
||||
movq $saved_context, %rax
|
||||
movq %rsp, pt_regs_sp(%rax)
|
||||
movq %rbp, pt_regs_bp(%rax)
|
||||
@@ -48,6 +47,7 @@ ENTRY(swsusp_arch_suspend)
|
||||
movq %cr3, %rax
|
||||
movq %rax, restore_cr3(%rip)
|
||||
|
||||
+ FRAME_BEGIN
|
||||
call swsusp_save
|
||||
FRAME_END
|
||||
ret
|
||||
@@ -104,7 +104,6 @@ ENTRY(core_restore_code)
|
||||
/* code below belongs to the image kernel */
|
||||
.align PAGE_SIZE
|
||||
ENTRY(restore_registers)
|
||||
- FRAME_BEGIN
|
||||
/* go back to the original page tables */
|
||||
movq %r9, %cr3
|
||||
|
||||
@@ -145,6 +144,5 @@ ENTRY(restore_registers)
|
||||
/* tell the hibernation core that we've just restored the memory */
|
||||
movq %rax, in_suspend(%rip)
|
||||
|
||||
- FRAME_END
|
||||
ret
|
||||
ENDPROC(restore_registers)
|
||||
--
|
||||
2.9.2
|
||||
|
||||
@@ -18,8 +18,8 @@
|
||||
</BuildDependencies>
|
||||
<Patches>
|
||||
<!-- Linux patches -->
|
||||
<!--Patch level="1" compressionType="xz">patches/linux/patch-4.6.3.xz</Patch-->
|
||||
<!-- Mageia Linux patches // compatible with http://svnweb.mageia.org/packages/cauldron/kernel/releases/4.7.0/2.mga6/PATCHES/patches/series-->
|
||||
<Patch level="1" compressionType="xz">patches/linux/patch-4.7.2.xz</Patch>
|
||||
<!-- Mageia Linux patches // compatible with http://svnweb.mageia.org/packages/cauldron/kernel/releases/4.7.2/2.mga6/PATCHES/patches/series-->
|
||||
<!--stable patches-->
|
||||
<!--other patches-->
|
||||
<Patch level="1">patches/mageia/Revert-ipmi-Start-the-timer-and-thread-on-internal-m.patch</Patch>
|
||||
@@ -27,10 +27,8 @@
|
||||
<Patch level="1">patches/mageia/x86-boot-video-80x25-if-break.patch</Patch>
|
||||
<Patch level="1">patches/mageia/x86-default_poweroff_up_machines.patch</Patch>
|
||||
<Patch level="1">patches/mageia/x86-increase-default-minimum-vmalloc-area-by-64MB-to-192MB.patch</Patch>
|
||||
<Patch level="1">patches/mageia/Revert-cpufreq-pcc-Enable-autoload-of-pcc-cpufreq-fo.patch</Patch>
|
||||
<Patch level="1">patches/mageia/Revert-cpufreq-pcc-cpufreq-update-default-value-of-c.patch</Patch>
|
||||
<Patch level="1">patches/mageia/Revert-cpufreq-pcc-Enable-autoload-of-pcc-cpufreq-fo.patch</Patch>
|
||||
<Patch level="1">patches/mageia/Revert-x86-mm-mtrr-Remove-kernel-internal-MTRR-inter.patch</Patch>
|
||||
<Patch level="1">patches/mageia/x86-power-64-Fix-hibernation-return-address-corrupti.patch</Patch>
|
||||
<Patch level="1">patches/mageia/base-cacheinfo-silence-DT-warnings.patch</Patch>
|
||||
<Patch level="1">patches/mageia/pci-add-ALI-M5229-ide-compatibility-mode-quirk.patch</Patch>
|
||||
<Patch level="1">patches/mageia/pci-quirks-drop-devinit-exit.patch</Patch>
|
||||
@@ -53,8 +51,6 @@
|
||||
<Patch level="1">patches/mageia/fs-aufs-4.7.patch</Patch>
|
||||
<Patch level="1">patches/mageia/fs-aufs-4.7-modular.patch</Patch>
|
||||
<Patch level="1">patches/mageia/fs-aufs-4.7-ver-fix.patch</Patch>
|
||||
<Patch level="1">patches/mageia/fs-ext4-don-t-call-ext4_should_journal_data-on-the-jour.patch</Patch>
|
||||
<Patch level="1">patches/mageia/fs-ext4-fix-deadlock-during-page-writeback.patch</Patch>
|
||||
<Patch level="1">patches/mageia/firewire-ieee1394-module-aliases.patch</Patch>
|
||||
<Patch level="1">patches/mageia/char-agp-intel-new-Q57-id.patch</Patch>
|
||||
<!--remove external mach64 support for buildfix-->
|
||||
@@ -87,31 +83,16 @@
|
||||
<Patch level="1">patches/mageia/net-netfilter-psd.patch</Patch>
|
||||
<Patch level="1">patches/mageia/net-netfilter-psd-mdv.patch</Patch>
|
||||
<Patch level="1">patches/mageia/net-netfilter-psd-2.6.35-buildfix.patch</Patch>
|
||||
<Patch level="1">patches/mageia/net-wireless-iwlwifi-add-new-8260-PCI-IDs.patch</Patch>
|
||||
<Patch level="1">patches/mageia/net-wireless-iwlwifi-add-new-8265.patch</Patch>
|
||||
<Patch level="1">patches/mageia/net-wireless-iwlwifi-pcie-enable-interrupts-before-releasing-the-NICs-CPU.patch</Patch>
|
||||
<Patch level="1">patches/mageia/net-wireless-iwlwifi-pcie-fix-a-race-in-firmware-loading-flow.patch</Patch>
|
||||
<Patch level="1">patches/mageia/net-bcma-add-PCI-ID-for-Foxconn-s-BCM43142-device.patch</Patch>
|
||||
<Patch level="1">patches/mageia/net-brcmfmac-restore-stopping-netdev-queue-when-bus-clog.patch</Patch>
|
||||
<Patch level="1">patches/mageia/platform-x86-add-shuttle-wmi-driver.patch</Patch>
|
||||
<Patch level="1">patches/mageia/platform-x86-shuttle-wmi-drop-devinit-exit.patch</Patch>
|
||||
<Patch level="1">patches/mageia/platform-x86-shuttle-wmi-4.2-buildfix.patch</Patch>
|
||||
<Patch level="1">patches/mageia/hp-wmi-Fix-wifi-cannot-be-hard-unblocked.patch</Patch>
|
||||
<Patch level="1">patches/mageia/Bluetooth-Add-support-of-13d3-3490-AR3012-device.patch</Patch>
|
||||
<Patch level="1">patches/mageia/intel_th-Fix-a-deadlock-in-modprobing.patch</Patch>
|
||||
<Patch level="1">patches/mageia/intel_th-pci-Add-Kaby-Lake-PCH-H-support.patch</Patch>
|
||||
<Patch level="1">patches/mageia/pinctrl-cherryview-prevent-concurrent-access-to-GPIO.patch</Patch>
|
||||
<Patch level="1">patches/mageia/intel_th-pci-Add-Kaby-Lake-PCH-H-support.patch</Patch>
|
||||
<Patch level="1">patches/mageia/include-kbuild-export-pci_ids.patch</Patch>
|
||||
<Patch level="1">patches/mageia/hid-usbhid-IBM-BladeCenterHS20-quirk.patch</Patch>
|
||||
<Patch level="1">patches/mageia/usb-storage-unusual_devs-add-id.patch</Patch>
|
||||
<Patch level="1">patches/mageia/usb-storage-unusual_devs-add-id-2.6.37-buildfix.patch</Patch>
|
||||
<Patch level="1">patches/mageia/usb-dwc3-fix-for-the-isoc-transfer-EP_BUSY-flag.patch</Patch>
|
||||
<Patch level="1">patches/mageia/usb-renesas_usbhs-fix-NULL-pointer-dereference-in-xf.patch</Patch>
|
||||
<Patch level="1">patches/mageia/HID-uhid-fix-timeout-when-probe-races-with-IO.patch</Patch>
|
||||
<Patch level="1">patches/mageia/media-usb-pwc-lie-in-proc-usb-devices.patch</Patch>
|
||||
<Patch level="1">patches/mageia/media-media-usbtv-prevent-access-to-free-d-resources.patch</Patch>
|
||||
<Patch level="1">patches/mageia/media-vb2-core-Skip-planes-array-verification-if-pb-.patch</Patch>
|
||||
<Patch level="1">patches/mageia/media-videobuf2-v4l2-Verify-planes-array-in-buffer-d.patch</Patch>
|
||||
<Patch level="1">patches/mageia/3rd-3rdparty-1.0-tree.patch</Patch>
|
||||
<Patch level="1">patches/mageia/3rd-3rdparty-merge.patch</Patch>
|
||||
<Patch level="1">patches/mageia/3rd-acerhk-0.5.35.patch</Patch>
|
||||
@@ -140,7 +121,6 @@
|
||||
<Patch level="1">patches/mageia/3rd-rtl8723bs.patch</Patch>
|
||||
<Patch level="1">patches/mageia/3rd-rtl8723bs-4.7-buildfix.patch</Patch>
|
||||
<Patch level="1">patches/mageia/ahci-add-new-Intel-device-IDs.patch</Patch>
|
||||
<Patch level="1">patches/mageia/megaraid_sas-Do-not-fire-MR_DCMD_PD_LIST_QUERY-to-co.patch</Patch>
|
||||
<Patch level="1">patches/mageia/arm-0001-ARM-bcm2835-dt-Add-the-ethernet-to-the-device-trees.patch</Patch>
|
||||
</Patches>
|
||||
</Source>
|
||||
@@ -167,6 +147,13 @@
|
||||
</Provides>-->
|
||||
</Package>
|
||||
<History>
|
||||
<Update release="6">
|
||||
<Date>2016-08-24</Date>
|
||||
<Version>4.7.2</Version>
|
||||
<Comment>Release bump</Comment>
|
||||
<Name>PisiLinux Community</Name>
|
||||
<Email>admin@pisilinux.org</Email>
|
||||
</Update>
|
||||
<Update release="5">
|
||||
<Date>2016-08-06</Date>
|
||||
<Version>4.7.0</Version>
|
||||
|
||||
Reference in New Issue
Block a user