diff --git a/kernel/kernel/files/configs/kernel-x86_64-config b/kernel/kernel/files/configs/kernel-x86_64-config index 7273edf1..8d2a836f 100644 --- a/kernel/kernel/files/configs/kernel-x86_64-config +++ b/kernel/kernel/files/configs/kernel-x86_64-config @@ -1,6 +1,6 @@ # # Automatically generated file; DO NOT EDIT. -# Linux/x86_64 4.14.23 Kernel Configuration +# Linux/x86_64 4.14.24 Kernel Configuration # CONFIG_64BIT=y CONFIG_X86_64=y @@ -75,7 +75,7 @@ CONFIG_POSIX_MQUEUE=y CONFIG_POSIX_MQUEUE_SYSCTL=y CONFIG_CROSS_MEMORY_ATTACH=y CONFIG_FHANDLE=y -CONFIG_USELIB=y +# CONFIG_USELIB is not set CONFIG_AUDIT=y CONFIG_HAVE_ARCH_AUDITSYSCALL=y CONFIG_AUDITSYSCALL=y @@ -146,8 +146,8 @@ CONFIG_RCU_NEED_SEGCBLIST=y CONFIG_BUILD_BIN2C=y CONFIG_IKCONFIG=y CONFIG_IKCONFIG_PROC=y -CONFIG_LOG_BUF_SHIFT=17 -CONFIG_LOG_CPU_MAX_BUF_SHIFT=13 +CONFIG_LOG_BUF_SHIFT=18 +CONFIG_LOG_CPU_MAX_BUF_SHIFT=12 CONFIG_PRINTK_SAFE_LOG_BUF_SHIFT=13 CONFIG_HAVE_UNSTABLE_SCHED_CLOCK=y CONFIG_ARCH_SUPPORTS_NUMA_BALANCING=y @@ -175,7 +175,6 @@ CONFIG_PROC_PID_CPUSET=y CONFIG_CGROUP_DEVICE=y CONFIG_CGROUP_CPUACCT=y CONFIG_CGROUP_PERF=y -# CONFIG_CGROUP_BPF is not set CONFIG_SOCK_CGROUP_DATA=y # CONFIG_CHECKPOINT_RESTORE is not set CONFIG_NAMESPACES=y @@ -193,8 +192,8 @@ CONFIG_RD_GZIP=y CONFIG_RD_BZIP2=y CONFIG_RD_LZMA=y CONFIG_RD_XZ=y -# CONFIG_RD_LZO is not set -# CONFIG_RD_LZ4 is not set +CONFIG_RD_LZO=y +CONFIG_RD_LZ4=y CONFIG_CC_OPTIMIZE_FOR_PERFORMANCE=y # CONFIG_CC_OPTIMIZE_FOR_SIZE is not set CONFIG_SYSCTL=y @@ -225,12 +224,11 @@ CONFIG_EPOLL=y CONFIG_SIGNALFD=y CONFIG_TIMERFD=y CONFIG_EVENTFD=y -CONFIG_BPF_SYSCALL=y -# CONFIG_BPF_JIT_ALWAYS_ON is not set +# CONFIG_BPF_SYSCALL is not set CONFIG_SHMEM=y CONFIG_AIO=y CONFIG_ADVISE_SYSCALLS=y -CONFIG_USERFAULTFD=y +# CONFIG_USERFAULTFD is not set CONFIG_PCI_QUIRKS=y CONFIG_MEMBARRIER=y # CONFIG_EMBEDDED is not set @@ -253,7 +251,7 @@ CONFIG_TRACEPOINTS=y CONFIG_CRASH_CORE=y CONFIG_KEXEC_CORE=y CONFIG_OPROFILE=m -# CONFIG_OPROFILE_EVENT_MULTIPLEX is not set +CONFIG_OPROFILE_EVENT_MULTIPLEX=y CONFIG_HAVE_OPROFILE=y CONFIG_OPROFILE_NMI_TIMER=y CONFIG_KPROBES=y @@ -301,9 +299,9 @@ CONFIG_SECCOMP_FILTER=y CONFIG_HAVE_GCC_PLUGINS=y # CONFIG_GCC_PLUGINS is not set CONFIG_HAVE_CC_STACKPROTECTOR=y -CONFIG_CC_STACKPROTECTOR=y -# CONFIG_CC_STACKPROTECTOR_NONE is not set -CONFIG_CC_STACKPROTECTOR_REGULAR=y +# CONFIG_CC_STACKPROTECTOR is not set +CONFIG_CC_STACKPROTECTOR_NONE=y +# CONFIG_CC_STACKPROTECTOR_REGULAR is not set # CONFIG_CC_STACKPROTECTOR_STRONG is not set CONFIG_THIN_ARCHIVES=y CONFIG_HAVE_ARCH_WITHIN_STACK_FRAMES=y @@ -1540,7 +1538,6 @@ CONFIG_CGROUP_NET_CLASSID=y CONFIG_NET_RX_BUSY_POLL=y CONFIG_BQL=y CONFIG_BPF_JIT=y -# CONFIG_BPF_STREAM_PARSER is not set CONFIG_NET_FLOW_LIMIT=y # @@ -2095,6 +2092,7 @@ CONFIG_SCSI_INITIO=m CONFIG_SCSI_INIA100=m # CONFIG_SCSI_PPA is not set # CONFIG_SCSI_IMM is not set +# CONFIG_PPSCSI is not set CONFIG_SCSI_STEX=m CONFIG_SCSI_SYM53C8XX_2=m CONFIG_SCSI_SYM53C8XX_DMA_ADDRESSING_MODE=1 @@ -6335,7 +6333,7 @@ CONFIG_GOOGLE_SMI=m # # EFI (Extensible Firmware Interface) Support # -CONFIG_EFI_VARS=y +CONFIG_EFI_VARS=m CONFIG_EFI_ESRT=y CONFIG_EFI_VARS_PSTORE=m # CONFIG_EFI_VARS_PSTORE_DEFAULT_DISABLE is not set @@ -6359,11 +6357,11 @@ CONFIG_EFI_DEV_PATH_PARSER=y # CONFIG_DCACHE_WORD_ACCESS=y CONFIG_FS_IOMAP=y -CONFIG_EXT2_FS=y +CONFIG_EXT2_FS=m CONFIG_EXT2_FS_XATTR=y # CONFIG_EXT2_FS_POSIX_ACL is not set CONFIG_EXT2_FS_SECURITY=y -CONFIG_EXT3_FS=y +CONFIG_EXT3_FS=m CONFIG_EXT3_FS_POSIX_ACL=y CONFIG_EXT3_FS_SECURITY=y CONFIG_EXT4_FS=y @@ -6375,18 +6373,18 @@ CONFIG_EXT4_FS_ENCRYPTION=y CONFIG_JBD2=y # CONFIG_JBD2_DEBUG is not set CONFIG_FS_MBCACHE=y -CONFIG_REISERFS_FS=y +CONFIG_REISERFS_FS=m # CONFIG_REISERFS_CHECK is not set CONFIG_REISERFS_PROC_INFO=y CONFIG_REISERFS_FS_XATTR=y CONFIG_REISERFS_FS_POSIX_ACL=y CONFIG_REISERFS_FS_SECURITY=y -CONFIG_JFS_FS=y +CONFIG_JFS_FS=m CONFIG_JFS_POSIX_ACL=y CONFIG_JFS_SECURITY=y # CONFIG_JFS_DEBUG is not set # CONFIG_JFS_STATISTICS is not set -CONFIG_XFS_FS=y +CONFIG_XFS_FS=m CONFIG_XFS_QUOTA=y CONFIG_XFS_POSIX_ACL=y # CONFIG_XFS_RT is not set @@ -6475,9 +6473,7 @@ CONFIG_VFAT_FS=m CONFIG_FAT_DEFAULT_CODEPAGE=437 CONFIG_FAT_DEFAULT_IOCHARSET="ascii" # CONFIG_FAT_DEFAULT_UTF8 is not set -CONFIG_NTFS_FS=m -# CONFIG_NTFS_DEBUG is not set -# CONFIG_NTFS_RW is not set +# CONFIG_NTFS_FS is not set # # Pseudo filesystems @@ -6809,7 +6805,6 @@ CONFIG_STACK_TRACER=y CONFIG_BLK_DEV_IO_TRACE=y CONFIG_KPROBE_EVENTS=y CONFIG_UPROBE_EVENTS=y -CONFIG_BPF_EVENTS=y CONFIG_PROBE_EVENTS=y CONFIG_DYNAMIC_FTRACE=y CONFIG_DYNAMIC_FTRACE_WITH_REGS=y @@ -6968,7 +6963,7 @@ CONFIG_CRYPTO_NULL=y CONFIG_CRYPTO_NULL2=y CONFIG_CRYPTO_PCRYPT=m CONFIG_CRYPTO_WORKQUEUE=y -CONFIG_CRYPTO_CRYPTD=m +CONFIG_CRYPTO_CRYPTD=y CONFIG_CRYPTO_MCRYPTD=m CONFIG_CRYPTO_AUTHENC=m CONFIG_CRYPTO_TEST=m @@ -6982,7 +6977,7 @@ CONFIG_CRYPTO_ENGINE=m # CONFIG_CRYPTO_CCM=m CONFIG_CRYPTO_GCM=m -CONFIG_CRYPTO_CHACHA20POLY1305=m +# CONFIG_CRYPTO_CHACHA20POLY1305 is not set CONFIG_CRYPTO_SEQIV=y CONFIG_CRYPTO_ECHAINIV=m @@ -7043,7 +7038,7 @@ CONFIG_CRYPTO_GHASH_CLMUL_NI_INTEL=m # Ciphers # CONFIG_CRYPTO_AES=y -CONFIG_CRYPTO_AES_TI=m +# CONFIG_CRYPTO_AES_TI is not set CONFIG_CRYPTO_AES_X86_64=m CONFIG_CRYPTO_AES_NI_INTEL=m CONFIG_CRYPTO_ANUBIS=m @@ -7099,11 +7094,11 @@ CONFIG_CRYPTO_DRBG_HMAC=y # CONFIG_CRYPTO_DRBG_CTR is not set CONFIG_CRYPTO_DRBG=y CONFIG_CRYPTO_JITTERENTROPY=y -CONFIG_CRYPTO_USER_API=m -CONFIG_CRYPTO_USER_API_HASH=m -CONFIG_CRYPTO_USER_API_SKCIPHER=m +CONFIG_CRYPTO_USER_API=y +CONFIG_CRYPTO_USER_API_HASH=y +CONFIG_CRYPTO_USER_API_SKCIPHER=y CONFIG_CRYPTO_USER_API_RNG=m -CONFIG_CRYPTO_USER_API_AEAD=m +# CONFIG_CRYPTO_USER_API_AEAD is not set CONFIG_CRYPTO_HASH_INFO=y CONFIG_CRYPTO_HW=y CONFIG_CRYPTO_DEV_PADLOCK=m @@ -7183,7 +7178,7 @@ CONFIG_CRC32_SLICEBY8=y # CONFIG_CRC32_BIT is not set # CONFIG_CRC4 is not set # CONFIG_CRC7 is not set -CONFIG_LIBCRC32C=y +CONFIG_LIBCRC32C=m CONFIG_CRC8=m CONFIG_XXHASH=m # CONFIG_AUDIT_ARCH_COMPAT_GENERIC is not set @@ -7194,7 +7189,7 @@ CONFIG_LZO_COMPRESS=y CONFIG_LZO_DECOMPRESS=y CONFIG_LZ4_COMPRESS=m CONFIG_LZ4HC_COMPRESS=m -CONFIG_LZ4_DECOMPRESS=m +CONFIG_LZ4_DECOMPRESS=y CONFIG_ZSTD_COMPRESS=m CONFIG_ZSTD_DECOMPRESS=m CONFIG_XZ_DEC=y @@ -7210,6 +7205,8 @@ CONFIG_DECOMPRESS_GZIP=y CONFIG_DECOMPRESS_BZIP2=y CONFIG_DECOMPRESS_LZMA=y CONFIG_DECOMPRESS_XZ=y +CONFIG_DECOMPRESS_LZO=y +CONFIG_DECOMPRESS_LZ4=y CONFIG_GENERIC_ALLOCATOR=y CONFIG_REED_SOLOMON=m CONFIG_REED_SOLOMON_ENC8=y @@ -7253,11 +7250,3 @@ CONFIG_ARCH_HAS_UACCESS_FLUSHCACHE=y CONFIG_SBITMAP=y CONFIG_PARMAN=m # CONFIG_STRING_SELFTEST is not set - -# -# Unofficial 3rd party kernel additions -# -CONFIG_VIAHSS=m -CONFIG_NDISWRAPPER=m -CONFIG_RTL8723DE=m -CONFIG_RTL8812AU=m diff --git a/kernel/kernel/files/patches/linux/patch-4.14.24.xz b/kernel/kernel/files/patches/linux/patch-4.14.24.xz new file mode 100644 index 00000000..08aba43d Binary files /dev/null and b/kernel/kernel/files/patches/linux/patch-4.14.24.xz differ diff --git a/kernel/kernel/files/patches/mageia/PCI-Add-function-1-DMA-alias-quirk-for-Highpoint-RocketRAID-644L.patch b/kernel/kernel/files/patches/mageia/PCI-Add-function-1-DMA-alias-quirk-for-Highpoint-RocketRAID-644L.patch new file mode 100644 index 00000000..b3c56fe0 --- /dev/null +++ b/kernel/kernel/files/patches/mageia/PCI-Add-function-1-DMA-alias-quirk-for-Highpoint-RocketRAID-644L.patch @@ -0,0 +1,34 @@ +From: Hans de Goede +Subject: [PATCH 2/2] PCI: Add function 1 DMA alias quirk for Highpoint RocketRAID 644L +Date: Fri, 2 Mar 2018 11:36:33 +0100 + +The Highpoint RocketRAID 644L uses a Marvel 88SE9235 controller, as with +other Marvel controllers this needs a function 1 DMA alias quirk. + +Note the RocketRAID 642L uses the same Marvel 88SE9235 controller and +already is listed with a function 1 DMA alias quirk. + +Cc: stable@vger.kernel.org +BugLink: https://bugzilla.redhat.com/show_bug.cgi?id=1534106 +Signed-off-by: Hans de Goede +--- + drivers/pci/quirks.c | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/drivers/pci/quirks.c b/drivers/pci/quirks.c +index 8b14bd326d4a..46d47bd6ca1f 100644 +--- a/drivers/pci/quirks.c ++++ b/drivers/pci/quirks.c +@@ -3908,6 +3908,8 @@ DECLARE_PCI_FIXUP_HEADER(PCI_VENDOR_ID_MARVELL_EXT, 0x9230, + quirk_dma_func1_alias); + DECLARE_PCI_FIXUP_HEADER(PCI_VENDOR_ID_TTI, 0x0642, + quirk_dma_func1_alias); ++DECLARE_PCI_FIXUP_HEADER(PCI_VENDOR_ID_TTI, 0x0645, ++ quirk_dma_func1_alias); + /* https://bugs.gentoo.org/show_bug.cgi?id=497630 */ + DECLARE_PCI_FIXUP_HEADER(PCI_VENDOR_ID_JMICRON, + PCI_DEVICE_ID_JMICRON_JMB388_ESD, +-- +2.14.3 + + diff --git a/kernel/kernel/files/patches/mageia/arch-ARM-omap2-hide-omap3_save_secure_ram-on-non-OMAP3-bu.patch b/kernel/kernel/files/patches/mageia/arch-ARM-omap2-hide-omap3_save_secure_ram-on-non-OMAP3-bu.patch new file mode 100644 index 00000000..e2783603 --- /dev/null +++ b/kernel/kernel/files/patches/mageia/arch-ARM-omap2-hide-omap3_save_secure_ram-on-non-OMAP3-bu.patch @@ -0,0 +1,46 @@ +From 863204cfdae98626a92535ac928ad79f4d6b74ff Mon Sep 17 00:00:00 2001 +From: Arnd Bergmann +Date: Wed, 6 Dec 2017 14:17:17 +0100 +Subject: [PATCH] ARM: omap2: hide omap3_save_secure_ram on non-OMAP3 builds + +In configurations without CONFIG_OMAP3 but with secure RAM support, +we now run into a link failure: + +arch/arm/mach-omap2/omap-secure.o: In function `omap3_save_secure_ram': +omap-secure.c:(.text+0x130): undefined reference to `save_secure_ram_context' + +The omap3_save_secure_ram() function is only called from the OMAP34xx +power management code, so we can simply hide that function in the +appropriate #ifdef. + +Fixes: d09220a887f7 ("ARM: OMAP2+: Fix SRAM virt to phys translation for save_secure_ram_context") +Acked-by: Tony Lindgren +Tested-by: Dan Murphy +Signed-off-by: Arnd Bergmann +--- + arch/arm/mach-omap2/omap-secure.c | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/arch/arm/mach-omap2/omap-secure.c b/arch/arm/mach-omap2/omap-secure.c +index 9ff92050053c..fa7f308c9027 100644 +--- a/arch/arm/mach-omap2/omap-secure.c ++++ b/arch/arm/mach-omap2/omap-secure.c +@@ -73,6 +73,7 @@ phys_addr_t omap_secure_ram_mempool_base(void) + return omap_secure_memblock_base; + } + ++#if defined(CONFIG_ARCH_OMAP3) && defined(CONFIG_PM) + u32 omap3_save_secure_ram(void __iomem *addr, int size) + { + u32 ret; +@@ -91,6 +92,7 @@ u32 omap3_save_secure_ram(void __iomem *addr, int size) + + return ret; + } ++#endif + + /** + * rx51_secure_dispatcher: Routine to dispatch secure PPA API calls +-- +2.16.2 + diff --git a/kernel/kernel/files/patches/mageia/ata-ahci-Add-PCI-id-for-the-Highpoint-Rocketraid-644L-card.patch b/kernel/kernel/files/patches/mageia/ata-ahci-Add-PCI-id-for-the-Highpoint-Rocketraid-644L-card.patch new file mode 100644 index 00000000..cf6a1a2c --- /dev/null +++ b/kernel/kernel/files/patches/mageia/ata-ahci-Add-PCI-id-for-the-Highpoint-Rocketraid-644L-card.patch @@ -0,0 +1,37 @@ +From: Hans de Goede +Subject: [PATCH 1/2] ahci: Add PCI-id for the Highpoint Rocketraid 644L card +Date: Fri, 2 Mar 2018 11:36:32 +0100 + +Like the Highpoint Rocketraid 642L and cards using a Marvel 88SE9235 +controller in general, this RAID card also supports AHCI mode and short +of a custom driver, this is the only way to make it work under Linux. + +Note that even though the card is called to 644L, it has a product-id +of 0x0645. + +Cc: stable@vger.kernel.org +BugLink: https://bugzilla.redhat.com/show_bug.cgi?id=1534106 +Signed-off-by: Hans de Goede +--- + drivers/ata/ahci.c | 4 +++- + 1 file changed, 3 insertions(+), 1 deletion(-) + +diff --git a/drivers/ata/ahci.c b/drivers/ata/ahci.c +index 355a95a83a34..1ff17799769d 100644 +--- a/drivers/ata/ahci.c ++++ b/drivers/ata/ahci.c +@@ -550,7 +550,9 @@ static const struct pci_device_id ahci_pci_tbl[] = { + .driver_data = board_ahci_yes_fbs }, + { PCI_DEVICE(PCI_VENDOR_ID_MARVELL_EXT, 0x9230), + .driver_data = board_ahci_yes_fbs }, +- { PCI_DEVICE(PCI_VENDOR_ID_TTI, 0x0642), ++ { PCI_DEVICE(PCI_VENDOR_ID_TTI, 0x0642), /* highpoint rocketraid 642L */ ++ .driver_data = board_ahci_yes_fbs }, ++ { PCI_DEVICE(PCI_VENDOR_ID_TTI, 0x0645), /* highpoint rocketraid 644L */ + .driver_data = board_ahci_yes_fbs }, + + /* Promise */ +-- +2.14.3 + + diff --git a/kernel/kernel/files/patches/mageia/fs-aufs-4.14.patch b/kernel/kernel/files/patches/mageia/fs-aufs-4.14.patch index b558c0aa..8672929f 100644 --- a/kernel/kernel/files/patches/mageia/fs-aufs-4.14.patch +++ b/kernel/kernel/files/patches/mageia/fs-aufs-4.14.patch @@ -90,7 +90,7 @@ fs/aufs/wkq.c | 378 ++++ fs/aufs/wkq.h | 81 + fs/aufs/xattr.c | 343 ++++ - fs/aufs/xino.c | 1406 +++++++++++++++ + fs/aufs/xino.c | 1457 +++++++++++++++ fs/dcache.c | 2 +- fs/fcntl.c | 4 +- fs/inode.c | 2 +- @@ -117,7 +117,7 @@ mm/mmap.c | 33 +- mm/nommu.c | 10 +- mm/prfile.c | 86 + - 119 files changed, 35967 insertions(+), 31 deletions(-) + 119 files changed, 36018 insertions(+), 31 deletions(-) diff --git a/Documentation/ABI/testing/debugfs-aufs b/Documentation/ABI/testing/debugfs-aufs new file mode 100644 @@ -34595,10 +34595,10 @@ index 000000000000..dbe452868cd5 +} diff --git a/fs/aufs/xino.c b/fs/aufs/xino.c new file mode 100644 -index 000000000000..74aecb7193ab +index 000000000000..eea2c34cabf4 --- /dev/null +++ b/fs/aufs/xino.c -@@ -0,0 +1,1406 @@ +@@ -0,0 +1,1457 @@ +/* + * SPDX-License-Identifier: GPL-2.0 + * Copyright (C) 2005-2017 Junjiro R. Okajima @@ -34612,6 +34612,9 @@ index 000000000000..74aecb7193ab +#include +#include "aufs.h" + ++static ssize_t xino_fread_wkq(vfs_readf_t func, struct file *file, void *buf, ++ size_t size, loff_t *pos); ++ +/* todo: unnecessary to support mmap_sem since kernel-space? */ +ssize_t xino_fread(vfs_readf_t func, struct file *file, void *kbuf, size_t size, + loff_t *pos) @@ -34622,14 +34625,26 @@ index 000000000000..74aecb7193ab + void *k; + char __user *u; + } buf; ++ int i; ++ const int prevent_endless = 10; + ++ i = 0; + buf.k = kbuf; + oldfs = get_fs(); + set_fs(KERNEL_DS); + do { -+ /* todo: signal_pending? */ + err = func(file, buf.u, size, pos); -+ } while (err == -EAGAIN || err == -EINTR); ++ if (err == -EINTR ++ && !au_wkq_test() ++ && fatal_signal_pending(current)) { ++ set_fs(oldfs); ++ err = xino_fread_wkq(func, file, kbuf, size, pos); ++ BUG_ON(err == -EINTR); ++ oldfs = get_fs(); ++ set_fs(KERNEL_DS); ++ } ++ } while (i++ < prevent_endless ++ && (err == -EAGAIN || err == -EINTR)); + set_fs(oldfs); + +#if 0 /* reserved for future use */ @@ -34640,6 +34655,42 @@ index 000000000000..74aecb7193ab + return err; +} + ++struct xino_fread_args { ++ ssize_t *errp; ++ vfs_readf_t func; ++ struct file *file; ++ void *buf; ++ size_t size; ++ loff_t *pos; ++}; ++ ++static void call_xino_fread(void *args) ++{ ++ struct xino_fread_args *a = args; ++ *a->errp = xino_fread(a->func, a->file, a->buf, a->size, a->pos); ++} ++ ++static ssize_t xino_fread_wkq(vfs_readf_t func, struct file *file, void *buf, ++ size_t size, loff_t *pos) ++{ ++ ssize_t err; ++ int wkq_err; ++ struct xino_fread_args args = { ++ .errp = &err, ++ .func = func, ++ .file = file, ++ .buf = buf, ++ .size = size, ++ .pos = pos ++ }; ++ ++ wkq_err = au_wkq_wait(call_xino_fread, &args); ++ if (unlikely(wkq_err)) ++ err = wkq_err; ++ ++ return err; ++} ++ +/* ---------------------------------------------------------------------- */ + +static ssize_t xino_fwrite_wkq(vfs_writef_t func, struct file *file, void *buf, diff --git a/kernel/kernel/files/patches/mageia/input-goodix-add-support-for-GDIX1002.patch b/kernel/kernel/files/patches/mageia/input-goodix-add-support-for-GDIX1002.patch new file mode 100644 index 00000000..8f263bee --- /dev/null +++ b/kernel/kernel/files/patches/mageia/input-goodix-add-support-for-GDIX1002.patch @@ -0,0 +1,18 @@ +--- a/drivers/input/touchscreen/goodix.c ++++ a/drivers/input/touchscreen/goodix.c +@@ -947,6 +954,7 @@ static SIMPLE_DEV_PM_OPS(goodix_pm_ops, goodix_suspend, goodix_resume); + + static const struct i2c_device_id goodix_ts_id[] = { + { "GDIX1001:00", 0 }, ++ { "GDIX1002:00", 0 }, + { } + }; + MODULE_DEVICE_TABLE(i2c, goodix_ts_id); +@@ -954,6 +962,7 @@ MODULE_DEVICE_TABLE(i2c, goodix_ts_id); + #ifdef CONFIG_ACPI + static const struct acpi_device_id goodix_acpi_match[] = { + { "GDIX1001", 0 }, ++ { "GDIX1002", 0 }, + { } + }; + MODULE_DEVICE_TABLE(acpi, goodix_acpi_match); diff --git a/kernel/kernel/files/patches/mageia/input-goodix-disable-IRQs-while-suspended.patch b/kernel/kernel/files/patches/mageia/input-goodix-disable-IRQs-while-suspended.patch new file mode 100644 index 00000000..e946f0d3 --- /dev/null +++ b/kernel/kernel/files/patches/mageia/input-goodix-disable-IRQs-while-suspended.patch @@ -0,0 +1,60 @@ +From faec44b6838312484d63e82286087cf2d5ebb891 Mon Sep 17 00:00:00 2001 +From: Hans de Goede +Date: Fri, 12 Jan 2018 00:36:48 -0800 +Subject: [PATCH] Input: goodix - disable IRQs while suspended + +We should not try to do any i2c transfers before the controller is +resumed (which happens before our resume method gets called). + +So we need to disable our IRQ while suspended to enforce this. The +code paths for devices with GPIOs for the int and reset pins already +disable the IRQ the through goodix_free_irq(). + +This commit also disables the IRQ while suspended for devices without +GPIOs for the int and reset pins. + +This fixes the i2c bus sometimes getting stuck after a suspend/resume +causing the touchscreen to sometimes not work after a suspend/resume. +This has been tested on a GPD pocked device. + +BugLink: https://github.com/nexus511/gpd-ubuntu-packages/issues/10 +BugLink: https://www.reddit.com/r/GPDPocket/comments/7niut2/fix_for_broken_touch_after_resume_all_linux/ +Tested-by: Hans de Goede +Signed-off-by: Hans de Goede +Reviewed-by: Bastien Nocera +Signed-off-by: Dmitry Torokhov +--- + drivers/input/touchscreen/goodix.c | 8 ++++++-- + 1 file changed, 6 insertions(+), 2 deletions(-) + +diff --git a/drivers/input/touchscreen/goodix.c b/drivers/input/touchscreen/goodix.c +index 69d0b8cbc71f..ecec8eb17f28 100644 +--- a/drivers/input/touchscreen/goodix.c ++++ b/drivers/input/touchscreen/goodix.c +@@ -878,8 +878,10 @@ static int __maybe_unused goodix_suspend(struct device *dev) + int error; + + /* We need gpio pins to suspend/resume */ +- if (!ts->gpiod_int || !ts->gpiod_rst) ++ if (!ts->gpiod_int || !ts->gpiod_rst) { ++ disable_irq(client->irq); + return 0; ++ } + + wait_for_completion(&ts->firmware_loading_complete); + +@@ -919,8 +921,10 @@ static int __maybe_unused goodix_resume(struct device *dev) + struct goodix_ts_data *ts = i2c_get_clientdata(client); + int error; + +- if (!ts->gpiod_int || !ts->gpiod_rst) ++ if (!ts->gpiod_int || !ts->gpiod_rst) { ++ enable_irq(client->irq); + return 0; ++ } + + /* + * Exit sleep mode by outputting HIGH level to INT pin +-- +2.16.2 + diff --git a/kernel/kernel/files/patches/mageia/net-WireGuard.patch b/kernel/kernel/files/patches/mageia/net-WireGuard.patch index e42e438c..fce4fe44 100644 --- a/kernel/kernel/files/patches/mageia/net-WireGuard.patch +++ b/kernel/kernel/files/patches/mageia/net-WireGuard.patch @@ -1,6 +1,6 @@ ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/allowedips.c 2018-02-18 22:22:31.000000000 +0200 -@@ -0,0 +1,327 @@ +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/allowedips.c 2018-03-04 19:51:33.000000000 +0200 +@@ -0,0 +1,328 @@ +/* SPDX-License-Identifier: GPL-2.0 + * + * Copyright (C) 2015-2018 Jason A. Donenfeld . All Rights Reserved. @@ -142,7 +142,8 @@ +/* This could be much faster if it actually just compared the common bits properly, + * by precomputing a mask bswap(~0 << (32 - cidr)), and the rest, but it turns out that + * common_bits is already super fast on modern processors, even taking into account -+ * the unfortunate bswap. So, we just inline it like this instead. */ ++ * the unfortunate bswap. So, we just inline it like this instead. ++ */ +#define prefix_matches(node, key, bits) (common_bits(node, key, bits) >= node->cidr) + +static __always_inline struct allowedips_node *find_node(struct allowedips_node *trie, u8 bits, const u8 *key) @@ -328,8 +329,8 @@ +} + +#include "selftest/allowedips.h" ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/cookie.c 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/cookie.c 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,195 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -526,8 +527,8 @@ +out: + peer_put(entry->peer); +} ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/device.c 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/device.c 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,421 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -950,8 +951,8 @@ +#endif + rcu_barrier_bh(); +} ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/hashtables.c 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/hashtables.c 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,168 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -1121,8 +1122,8 @@ + rcu_read_unlock_bh(); + return entry; +} ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/main.c 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/main.c 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,69 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -1193,8 +1194,8 @@ +MODULE_VERSION(WIREGUARD_VERSION); +MODULE_ALIAS_RTNL_LINK(KBUILD_MODNAME); +MODULE_ALIAS_GENL_FAMILY(WG_GENL_NAME); ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/netlink.c 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/netlink.c 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,517 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -1713,8 +1714,8 @@ +{ + genl_unregister_family(&genl_family); +} ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/noise.c 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/noise.c 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,635 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -2351,8 +2352,8 @@ + up_write(&handshake->lock); + return false; +} ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/peer.c 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/peer.c 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,136 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -2490,8 +2491,8 @@ + list_for_each_entry_safe(peer, temp, &wg->peer_list, peer_list) + peer_remove(peer); +} ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/queueing.c 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/queueing.c 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,46 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -2539,8 +2540,8 @@ + WARN_ON(!ptr_ring_empty_bh(&queue->ring)); + ptr_ring_cleanup(&queue->ring, NULL); +} ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/ratelimiter.c 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/ratelimiter.c 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,199 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -2741,8 +2742,8 @@ +} + +#include "selftest/ratelimiter.h" ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/receive.c 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/receive.c 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,490 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -3234,8 +3235,8 @@ +err: + dev_kfree_skb(skb); +} ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/send.c 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/send.c 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,348 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -3585,8 +3586,8 @@ + */ + packet_send_queued_handshake_initiation(peer, false); +} ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/socket.c 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/socket.c 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,393 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -3981,8 +3982,8 @@ + sock_free(old4); + sock_free(old6); +} ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/timers.c 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/timers.c 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,199 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -4183,8 +4184,8 @@ + del_timer_sync(&peer->timer_persistent_keepalive); + flush_work(&peer->clear_peer_work); +} ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/allowedips.h 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/allowedips.h 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,44 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -4230,8 +4231,8 @@ +#endif + +#endif /* _WG_ALLOWEDIPS_H */ ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/cookie.h 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/cookie.h 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,52 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -4285,8 +4286,8 @@ +void cookie_message_consume(struct message_handshake_cookie *src, struct wireguard_device *wg); + +#endif /* _WG_COOKIE_H */ ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/device.h 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/device.h 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,64 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -4352,8 +4353,8 @@ +void device_uninit(void); + +#endif /* _WG_DEVICE_H */ ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/hashtables.h 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/hashtables.h 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,52 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -4407,9 +4408,9 @@ +struct index_hashtable_entry *index_hashtable_lookup(struct index_hashtable *table, const enum index_hashtable_type type_mask, const __le32 index); + +#endif /* _WG_HASHTABLES_H */ ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/messages.h 2018-02-18 22:22:31.000000000 +0200 -@@ -0,0 +1,129 @@ +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/messages.h 2018-03-04 19:51:33.000000000 +0200 +@@ -0,0 +1,128 @@ +/* SPDX-License-Identifier: GPL-2.0 */ +/* + * Copyright (C) 2015-2018 Jason A. Donenfeld . All Rights Reserved. @@ -4472,8 +4473,7 @@ + MESSAGE_HANDSHAKE_INITIATION = 1, + MESSAGE_HANDSHAKE_RESPONSE = 2, + MESSAGE_HANDSHAKE_COOKIE = 3, -+ MESSAGE_DATA = 4, -+ MESSAGE_TOTAL = 5 ++ MESSAGE_DATA = 4 +}; + +struct message_header { @@ -4539,8 +4539,8 @@ +}; + +#endif /* _WG_MESSAGES_H */ ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/netlink.h 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/netlink.h 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,12 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -4554,8 +4554,8 @@ +void genetlink_uninit(void); + +#endif /* _WG_NETLINK_H */ ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/noise.h 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/noise.h 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,117 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -4613,10 +4613,10 @@ +}; + +struct noise_static_identity { -+ bool has_identity; + u8 static_public[NOISE_PUBLIC_KEY_LEN]; + u8 static_private[NOISE_PUBLIC_KEY_LEN]; + struct rw_semaphore lock; ++ bool has_identity; +}; + +enum noise_handshake_state { @@ -4668,14 +4668,14 @@ +bool noise_handshake_create_initiation(struct message_handshake_initiation *dst, struct noise_handshake *handshake); +struct wireguard_peer *noise_handshake_consume_initiation(struct message_handshake_initiation *src, struct wireguard_device *wg); + -+bool noise_handshake_create_response(struct message_handshake_response *dst, struct noise_handshake *peer); ++bool noise_handshake_create_response(struct message_handshake_response *dst, struct noise_handshake *handshake); +struct wireguard_peer *noise_handshake_consume_response(struct message_handshake_response *src, struct wireguard_device *wg); + +bool noise_handshake_begin_session(struct noise_handshake *handshake, struct noise_keypairs *keypairs); + +#endif /* _WG_NOISE_H */ ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/peer.h 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/peer.h 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,73 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -4750,8 +4750,8 @@ +struct wireguard_peer *peer_lookup_by_index(struct wireguard_device *wg, u32 index); + +#endif /* _WG_PEER_H */ ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/queueing.h 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/queueing.h 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,142 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -4818,7 +4818,7 @@ + +static inline void skb_reset(struct sk_buff *skb) +{ -+ skb_scrub_packet(skb, false); ++ skb_scrub_packet(skb, true); + memset(&skb->headers_start, 0, offsetof(struct sk_buff, headers_end) - offsetof(struct sk_buff, headers_start)); + skb->queue_mapping = 0; + skb->nohdr = 0; @@ -4895,8 +4895,8 @@ +#endif + +#endif /* _WG_QUEUEING_H */ ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/ratelimiter.h 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/ratelimiter.h 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,19 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -4917,8 +4917,8 @@ +#endif + +#endif /* _WG_RATELIMITER_H */ ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/socket.h 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/socket.h 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,35 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -4955,8 +4955,8 @@ +#endif + +#endif /* _WG_SOCKET_H */ ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/timers.h 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/timers.h 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,21 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -4979,12 +4979,12 @@ +void timers_any_authenticated_packet_traversal(struct wireguard_peer *peer); + +#endif /* _WG_TIMERS_H */ ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/version.h 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/version.h 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1 @@ -+#define WIREGUARD_VERSION "0.0.20180218" ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/uapi/wireguard.h 2018-02-18 22:22:31.000000000 +0200 ++#define WIREGUARD_VERSION "0.0.20180304" +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/uapi/wireguard.h 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,182 @@ +/* SPDX-License-Identifier: ((GPL-2.0 WITH Linux-syscall-note) OR MIT) + * @@ -5168,8 +5168,8 @@ +#define WGALLOWEDIP_A_MAX (__WGALLOWEDIP_A_LAST - 1) + +#endif /* _WG_UAPI_WIREGUARD_H */ ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/selftest/allowedips.h 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/selftest/allowedips.h 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,514 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -5685,8 +5685,8 @@ +#undef init_peer + +#endif ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/selftest/blake2s.h 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/selftest/blake2s.h 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,559 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -6247,8 +6247,8 @@ + return success; +} +#endif ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/selftest/chacha20poly1305.h 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/selftest/chacha20poly1305.h 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,333 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -6583,8 +6583,8 @@ + return success; +} +#endif ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/selftest/counter.h 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/selftest/counter.h 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,92 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -6678,8 +6678,8 @@ + return success; +} +#endif ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/selftest/curve25519.h 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/selftest/curve25519.h 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,103 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -6784,8 +6784,8 @@ + return success; +} +#endif ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/selftest/poly1305.h 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/selftest/poly1305.h 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,1566 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -8353,8 +8353,8 @@ + return success; +} +#endif ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/selftest/ratelimiter.h 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/selftest/ratelimiter.h 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,157 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -8513,8 +8513,8 @@ + return ret; +} +#endif ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/crypto/blake2s.c 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/crypto/blake2s.c 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,294 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -8631,8 +8631,8 @@ +#include +#include +#include -+static bool blake2s_use_avx __read_mostly; -+static bool blake2s_use_avx512 __read_mostly; ++static bool blake2s_use_avx __ro_after_init; ++static bool blake2s_use_avx512 __ro_after_init; +void __init blake2s_fpu_init(void) +{ +#ifndef CONFIG_UML @@ -8810,8 +8810,8 @@ +} + +#include "../selftest/blake2s.h" ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/crypto/chacha20poly1305.c 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/crypto/chacha20poly1305.c 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,852 @@ +/* SPDX-License-Identifier: OpenSSL OR (BSD-3-Clause OR GPL-2.0) + * @@ -8853,11 +8853,11 @@ +asmlinkage void poly1305_blocks_avx512(void *ctx, const u8 *inp, size_t len, u32 padbit); +#endif + -+static bool chacha20poly1305_use_ssse3 __read_mostly; -+static bool chacha20poly1305_use_avx __read_mostly; -+static bool chacha20poly1305_use_avx2 __read_mostly; -+static bool chacha20poly1305_use_avx512 __read_mostly; -+static bool chacha20poly1305_use_avx512vl __read_mostly; ++static bool chacha20poly1305_use_ssse3 __ro_after_init; ++static bool chacha20poly1305_use_avx __ro_after_init; ++static bool chacha20poly1305_use_avx2 __ro_after_init; ++static bool chacha20poly1305_use_avx512 __ro_after_init; ++static bool chacha20poly1305_use_avx512vl __ro_after_init; + +void __init chacha20poly1305_fpu_init(void) +{ @@ -8889,7 +8889,7 @@ +asmlinkage void poly1305_emit_neon(void *ctx, u8 mac[16], const u32 nonce[4]); +asmlinkage void chacha20_neon(u8 *out, const u8 *in, size_t len, const u32 key[8], const u32 counter[4]); +#endif -+static bool chacha20poly1305_use_neon __read_mostly; ++static bool chacha20poly1305_use_neon __ro_after_init; +void __init chacha20poly1305_fpu_init(void) +{ +#if defined(CONFIG_ARM64) @@ -9665,8 +9665,8 @@ + +#include "../selftest/chacha20poly1305.h" +#include "../selftest/poly1305.h" ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/crypto/curve25519.c 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/crypto/curve25519.c 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,81 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -9749,8 +9749,8 @@ +} + +#include "../selftest/curve25519.h" ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/crypto/blake2s.h 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/crypto/blake2s.h 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,94 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -9846,8 +9846,8 @@ +#endif + +#endif /* _WG_BLAKE2S_H */ ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/crypto/chacha20poly1305.h 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/crypto/chacha20poly1305.h 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,93 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -9942,8 +9942,8 @@ +#endif + +#endif /* _WG_CHACHA20POLY1305_H */ ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/crypto/curve25519-arm.h 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/crypto/curve25519-arm.h 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,14 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -9954,13 +9954,13 @@ +#include +#include +asmlinkage void curve25519_neon(u8 mypublic[CURVE25519_POINT_SIZE], const u8 secret[CURVE25519_POINT_SIZE], const u8 basepoint[CURVE25519_POINT_SIZE]); -+static bool curve25519_use_neon __read_mostly; ++static bool curve25519_use_neon __ro_after_init; +void __init curve25519_fpu_init(void) +{ + curve25519_use_neon = elf_hwcap & HWCAP_NEON; +} ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/crypto/curve25519-fiat32.h 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/crypto/curve25519-fiat32.h 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,838 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -10800,8 +10800,8 @@ + memzero_explicit(&tmp1l, sizeof(tmp1l)); + memzero_explicit(&e, sizeof(e)); +} ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/crypto/curve25519.h 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/crypto/curve25519.h 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,25 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -10828,8 +10828,8 @@ +#endif + +#endif /* _WG_CURVE25519_H */ ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/crypto/curve25519-hacl64.h 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/crypto/curve25519-hacl64.h 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,751 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -11582,9 +11582,9 @@ + } + memzero_explicit(buf0, sizeof(buf0)); +} ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/crypto/curve25519-x86_64.h 2018-02-18 22:22:31.000000000 +0200 -@@ -0,0 +1,175 @@ +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/crypto/curve25519-x86_64.h 2018-03-04 19:51:33.000000000 +0200 +@@ -0,0 +1,176 @@ +/* SPDX-License-Identifier: GPL-2.0 + * + * Copyright (C) 2015-2018 Jason A. Donenfeld . All Rights Reserved. @@ -11596,7 +11596,8 @@ +#include +#include +#include -+static bool curve25519_use_avx __read_mostly; ++ ++static bool curve25519_use_avx __ro_after_init; +void __init curve25519_fpu_init(void) +{ +#ifndef CONFIG_UML @@ -11760,8 +11761,8 @@ + memzero_explicit(x_51, sizeof(x_51)); + memzero_explicit(z_51, sizeof(z_51)); +} ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/crypto/blake2s-x86_64.S 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/crypto/blake2s-x86_64.S 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,685 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -12448,8 +12449,8 @@ + retq +ENDPROC(blake2s_compress_avx512) +#endif /* CONFIG_AS_AVX512 */ ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/crypto/chacha20-arm64.S 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/crypto/chacha20-arm64.S 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,1940 @@ +/* SPDX-License-Identifier: OpenSSL OR (BSD-3-Clause OR GPL-2.0) + * @@ -14391,8 +14392,8 @@ +.Labort_neon: + ret +ENDPROC(chacha20_neon) ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/crypto/chacha20-arm.S 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/crypto/chacha20-arm.S 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,1471 @@ +/* SPDX-License-Identifier: OpenSSL OR (BSD-3-Clause OR GPL-2.0) + * @@ -15865,8 +15866,8 @@ +.Lno_data_arm: + ldmia sp!,{r4-r11,pc} +ENDPROC(chacha20_arm) ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/crypto/chacha20-x86_64.S 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/crypto/chacha20-x86_64.S 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,2630 @@ +/* SPDX-License-Identifier: OpenSSL OR (BSD-3-Clause OR GPL-2.0) + * @@ -18498,8 +18499,8 @@ +ENDPROC(chacha20_avx512vl) + +#endif /* CONFIG_AS_AVX512 */ ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/crypto/curve25519-arm.S 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/crypto/curve25519-arm.S 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,2110 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -20611,8 +20612,8 @@ + bx lr +ENDPROC(curve25519_neon) +#endif ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/crypto/curve25519-x86_64.S 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/crypto/curve25519-x86_64.S 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,3261 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -23875,8 +23876,8 @@ + ret +ENDPROC(curve25519_sandy2x_ladder_base) +#endif /* CONFIG_AS_AVX */ ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/crypto/poly1305-arm64.S 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/crypto/poly1305-arm64.S 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,820 @@ +/* SPDX-License-Identifier: OpenSSL OR (BSD-3-Clause OR GPL-2.0) + * @@ -24698,8 +24699,8 @@ +.align 5 +.Lzeros: +.long 0,0,0,0,0,0,0,0 ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/crypto/poly1305-arm.S 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/crypto/poly1305-arm.S 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,1115 @@ +/* SPDX-License-Identifier: OpenSSL OR (BSD-3-Clause OR GPL-2.0) + * @@ -25816,8 +25817,8 @@ +.Lzeros: +.long 0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0 +#endif ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/crypto/poly1305-mips64.S 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/crypto/poly1305-mips64.S 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,357 @@ +/* SPDX-License-Identifier: OpenSSL OR (BSD-3-Clause OR GPL-2.0) + * @@ -26176,8 +26177,8 @@ + + jr $31 +.end poly1305_emit_mips ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/crypto/poly1305-x86_64.S 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/crypto/poly1305-x86_64.S 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,2803 @@ +/* SPDX-License-Identifier: OpenSSL OR (BSD-3-Clause OR GPL-2.0) + * @@ -28982,8 +28983,8 @@ + +ENDPROC(poly1305_blocks_avx512) +#endif /* CONFIG_AS_AVX512 */ ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/Makefile 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/Makefile 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,19 @@ +# SPDX-License-Identifier: GPL-2.0 +# @@ -29004,13 +29005,14 @@ +include $(src)/compat/Makefile.include + +obj-$(if $(KBUILD_EXTMOD),m,$(CONFIG_WIREGUARD)) := wireguard.o ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/Kconfig 2018-02-18 22:22:31.000000000 +0200 -@@ -0,0 +1,30 @@ +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/Kconfig 2018-03-04 19:51:33.000000000 +0200 +@@ -0,0 +1,31 @@ +config WIREGUARD + tristate "IP: WireGuard secure network tunnel" + depends on NET && INET + select NET_UDP_TUNNEL ++ select DST_CACHE + select CRYPTO_BLKCIPHER + select VFP + select VFPv3 @@ -29037,12 +29039,12 @@ + only useful for debugging. + + Say N here unless you know what you're doing. ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/compat/simd/include/asm/simd.h 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/compat/simd/include/asm/simd.h 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1 @@ +#include ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/compat/udp_tunnel/udp_tunnel_partial_compat.h 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/compat/udp_tunnel/udp_tunnel_partial_compat.h 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,226 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -29270,8 +29272,8 @@ +#define udp_port_cfg udp_port_cfg_new +#define udp_sock_create(a, b, c) udp_sock_create_new(a, b, c) +#endif ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/compat/udp_tunnel/include/net/udp_tunnel.h 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/compat/udp_tunnel/include/net/udp_tunnel.h 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,94 @@ +#ifndef _WG_NET_UDP_TUNNEL_H +#define _WG_NET_UDP_TUNNEL_H @@ -29367,8 +29369,8 @@ +void udp_tunnel_sock_release(struct socket *sock); + +#endif /* _WG_NET_UDP_TUNNEL_H */ ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/compat/udp_tunnel/udp_tunnel.c 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/compat/udp_tunnel/udp_tunnel.c 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,385 @@ +#include +#include @@ -29755,12 +29757,12 @@ + return 0; +} +#endif ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/compat/fpu/include/asm/fpu/api.h 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/compat/fpu/include/asm/fpu/api.h 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1 @@ +#include ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/compat/checksum/checksum_partial_compat.h 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/compat/checksum/checksum_partial_compat.h 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,208 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -29970,21 +29972,22 @@ + } + return err; +} ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/compat/Makefile.include 2018-02-18 22:22:31.000000000 +0200 -@@ -0,0 +1,70 @@ +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/compat/Makefile.include 2018-03-04 19:51:33.000000000 +0200 +@@ -0,0 +1,71 @@ +# SPDX-License-Identifier: GPL-2.0 +# +# Copyright (C) 2015-2018 Jason A. Donenfeld . All Rights Reserved. + +ifeq ($(wildcard $(src)/compat/compat.h),) -+ccflags-y += -include $(srctree)/$(src)/compat/compat.h -+asflags-y += -include $(srctree)/$(src)/compat/compat-asm.h ++cmd_include_path_prefix := $(srctree)/$(src) +else -+ccflags-y += -include $(src)/compat/compat.h -+asflags-y += -include $(src)/compat/compat-asm.h ++cmd_include_path_prefix := $(src) +endif + ++ccflags-y += -include $(cmd_include_path_prefix)/compat/compat.h ++asflags-y += -include $(cmd_include_path_prefix)/compat/compat-asm.h ++ +ifeq ($(wildcard $(srctree)/include/linux/ptr_ring.h),) +ccflags-y += -I$(src)/compat/ptr_ring/include +endif @@ -30017,7 +30020,7 @@ +endif + +ifeq ($(shell grep -F "int crypto_memneq" "$(srctree)/include/crypto/algapi.h"),) -+ccflags-y += -include $(src)/compat/memneq/include.h ++ccflags-y += -include $(cmd_include_path_prefix)/compat/memneq/include.h +wireguard-y += compat/memneq/memneq.o +endif + @@ -30043,8 +30046,8 @@ + asflags-y += $(avx512_instr) + endif +endif ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/compat/siphash/siphash.c 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/compat/siphash/siphash.c 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,539 @@ +/* Copyright (C) 2015-2018 Jason A. Donenfeld . All Rights Reserved. + * @@ -30585,8 +30588,8 @@ + HPOSTAMBLE +} +#endif ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/compat/siphash/include/linux/siphash.h 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/compat/siphash/include/linux/siphash.h 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,140 @@ +/* Copyright (C) 2015-2018 Jason A. Donenfeld . All Rights Reserved. + * @@ -30728,8 +30731,8 @@ +} + +#endif /* _WG_LINUX_SIPHASH_H */ ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/compat/intel-family/include/asm/intel-family.h 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/compat/intel-family/include/asm/intel-family.h 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,73 @@ +/* SPDX-License-Identifier: GPL-2.0 */ +#ifndef _ASM_X86_INTEL_FAMILY_H @@ -30804,8 +30807,8 @@ +#define INTEL_FAM6_XEON_PHI_KNM 0x85 /* Knights Mill */ + +#endif /* _ASM_X86_INTEL_FAMILY_H */ ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/compat/compat.h 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/compat/compat.h 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,632 @@ +/* SPDX-License-Identifier: GPL-2.0 + * @@ -31291,7 +31294,7 @@ +#else +#define ___COMPAT_NETLINK_DUMP_BLOCK return get_device_dump_real(skb, cb); +#endif -+#if (LINUX_VERSION_CODE < KERNEL_VERSION(4, 13, 14) && LINUX_VERSION_CODE >= KERNEL_VERSION(4, 10, 0)) || LINUX_VERSION_CODE < KERNEL_VERSION(4, 9, 63) ++#if LINUX_VERSION_CODE < KERNEL_VERSION(4, 16, 0) +#define get_device_dump(a, b) get_device_dump_real(a, b); \ +static int get_device_dump(a, b) { \ + struct wireguard_device *wg = (struct wireguard_device *)cb->args[0]; \ @@ -31439,8 +31442,8 @@ +#endif + +#endif /* _WG_COMPAT_H */ ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/compat/ptr_ring/include/linux/ptr_ring.h 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/compat/ptr_ring/include/linux/ptr_ring.h 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,640 @@ +/* + * Definitions for the 'struct ptr_ring' datastructure. @@ -32082,16 +32085,16 @@ +} + +#endif /* _LINUX_PTR_RING_H */ ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/compat/memneq/include.h 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/compat/memneq/include.h 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,5 @@ +extern noinline unsigned long __crypto_memneq(const void *a, const void *b, size_t size); +static inline int crypto_memneq(const void *a, const void *b, size_t size) +{ + return __crypto_memneq(a, b, size) != 0UL ? 1 : 0; +} ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/compat/memneq/memneq.c 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/compat/memneq/memneq.c 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,170 @@ +/* + * Constant-time equality testing of memory regions. @@ -32157,7 +32160,7 @@ +#include + +/* Make the optimizer believe the variable can be manipulated arbitrarily. */ -+#define COMPILER_OPTIMIZER_HIDE_VAR(var) __asm__ ("" : "=r" (var) : "0" (var)) ++#define COMPILER_OPTIMIZER_HIDE_VAR(var) asm("" : "=r" (var) : "0" (var)) + +#ifndef __HAVE_ARCH_CRYPTO_MEMNEQ + @@ -32263,8 +32266,8 @@ +} + +#endif /* __HAVE_ARCH_CRYPTO_MEMNEQ */ ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/compat/dst_cache/dst_cache.c 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/compat/dst_cache/dst_cache.c 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,175 @@ +/* + * net/core/dst_cache.c - dst entry cache @@ -32441,8 +32444,8 @@ + + free_percpu(dst_cache->cache); +} ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/compat/dst_cache/include/net/dst_cache.h 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/compat/dst_cache/include/net/dst_cache.h 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,97 @@ +#ifndef _WG_NET_DST_CACHE_H +#define _WG_NET_DST_CACHE_H @@ -32541,8 +32544,8 @@ +void dst_cache_destroy(struct dst_cache *dst_cache); + +#endif /* _WG_NET_DST_CACHE_H */ ---- /dev/null 2018-02-18 13:06:28.903837808 +0200 -+++ b/net/wireguard/compat/compat-asm.h 2018-02-18 22:22:31.000000000 +0200 +--- /dev/null 2018-03-04 21:55:12.891724619 +0200 ++++ b/net/wireguard/compat/compat-asm.h 2018-03-04 19:51:33.000000000 +0200 @@ -0,0 +1,18 @@ +/* SPDX-License-Identifier: GPL-2.0 + * diff --git a/kernel/kernel/files/patches/mageia/net-netfilter-add-back-stackpointer-size-checks.patch b/kernel/kernel/files/patches/mageia/net-netfilter-add-back-stackpointer-size-checks.patch new file mode 100644 index 00000000..56c0f51b --- /dev/null +++ b/kernel/kernel/files/patches/mageia/net-netfilter-add-back-stackpointer-size-checks.patch @@ -0,0 +1,84 @@ +From 57ebd808a97d7c5b1e1afb937c2db22beba3c1f8 Mon Sep 17 00:00:00 2001 +From: Florian Westphal +Date: Wed, 7 Feb 2018 13:46:25 +0100 +Subject: [PATCH] netfilter: add back stackpointer size checks + +The rationale for removing the check is only correct for rulesets +generated by ip(6)tables. + +In iptables, a jump can only occur to a user-defined chain, i.e. +because we size the stack based on number of user-defined chains we +cannot exceed stack size. + +However, the underlying binary format has no such restriction, +and the validation step only ensures that the jump target is a +valid rule start point. + +IOW, its possible to build a rule blob that has no user-defined +chains but does contain a jump. + +If this happens, no jump stack gets allocated and crash occurs +because no jumpstack was allocated. + +Fixes: 7814b6ec6d0d6 ("netfilter: xtables: don't save/restore jumpstack offset") +Reported-by: syzbot+e783f671527912cd9403@syzkaller.appspotmail.com +Signed-off-by: Florian Westphal +Signed-off-by: Pablo Neira Ayuso +--- + net/ipv4/netfilter/arp_tables.c | 4 ++++ + net/ipv4/netfilter/ip_tables.c | 7 ++++++- + net/ipv6/netfilter/ip6_tables.c | 4 ++++ + 3 files changed, 14 insertions(+), 1 deletion(-) + +diff --git a/net/ipv4/netfilter/arp_tables.c b/net/ipv4/netfilter/arp_tables.c +index 4ffe302f9b82..e3e420f3ba7b 100644 +--- a/net/ipv4/netfilter/arp_tables.c ++++ b/net/ipv4/netfilter/arp_tables.c +@@ -252,6 +252,10 @@ unsigned int arpt_do_table(struct sk_buff *skb, + } + if (table_base + v + != arpt_next_entry(e)) { ++ if (unlikely(stackidx >= private->stacksize)) { ++ verdict = NF_DROP; ++ break; ++ } + jumpstack[stackidx++] = e; + } + +diff --git a/net/ipv4/netfilter/ip_tables.c b/net/ipv4/netfilter/ip_tables.c +index 9a71f3149507..e38395a8dcf2 100644 +--- a/net/ipv4/netfilter/ip_tables.c ++++ b/net/ipv4/netfilter/ip_tables.c +@@ -330,8 +330,13 @@ ipt_do_table(struct sk_buff *skb, + continue; + } + if (table_base + v != ipt_next_entry(e) && +- !(e->ip.flags & IPT_F_GOTO)) ++ !(e->ip.flags & IPT_F_GOTO)) { ++ if (unlikely(stackidx >= private->stacksize)) { ++ verdict = NF_DROP; ++ break; ++ } + jumpstack[stackidx++] = e; ++ } + + e = get_entry(table_base, v); + continue; +diff --git a/net/ipv6/netfilter/ip6_tables.c b/net/ipv6/netfilter/ip6_tables.c +index af4c917e0836..62358b93bbac 100644 +--- a/net/ipv6/netfilter/ip6_tables.c ++++ b/net/ipv6/netfilter/ip6_tables.c +@@ -352,6 +352,10 @@ ip6t_do_table(struct sk_buff *skb, + } + if (table_base + v != ip6t_next_entry(e) && + !(e->ipv6.flags & IP6T_F_GOTO)) { ++ if (unlikely(stackidx >= private->stacksize)) { ++ verdict = NF_DROP; ++ break; ++ } + jumpstack[stackidx++] = e; + } + +-- +2.16.2 + diff --git a/kernel/kernel/files/patches/mageia/patch-4.14.25-rc1.patch b/kernel/kernel/files/patches/mageia/patch-4.14.25-rc1.patch new file mode 100644 index 00000000..3246762b --- /dev/null +++ b/kernel/kernel/files/patches/mageia/patch-4.14.25-rc1.patch @@ -0,0 +1,4181 @@ +diff --git a/Documentation/networking/ip-sysctl.txt b/Documentation/networking/ip-sysctl.txt +index 77f4de59dc9c..d499676890d8 100644 +--- a/Documentation/networking/ip-sysctl.txt ++++ b/Documentation/networking/ip-sysctl.txt +@@ -508,7 +508,7 @@ tcp_rmem - vector of 3 INTEGERs: min, default, max + min: Minimal size of receive buffer used by TCP sockets. + It is guaranteed to each TCP socket, even under moderate memory + pressure. +- Default: 1 page ++ Default: 4K + + default: initial size of receive buffer used by TCP sockets. + This value overrides net.core.rmem_default used by other protocols. +@@ -666,7 +666,7 @@ tcp_window_scaling - BOOLEAN + tcp_wmem - vector of 3 INTEGERs: min, default, max + min: Amount of memory reserved for send buffers for TCP sockets. + Each TCP socket has rights to use it due to fact of its birth. +- Default: 1 page ++ Default: 4K + + default: initial size of send buffer used by TCP sockets. This + value overrides net.core.wmem_default used by other protocols. +diff --git a/arch/arm/boot/dts/logicpd-som-lv.dtsi b/arch/arm/boot/dts/logicpd-som-lv.dtsi +index 4f2c5ec75714..e262fa9ef334 100644 +--- a/arch/arm/boot/dts/logicpd-som-lv.dtsi ++++ b/arch/arm/boot/dts/logicpd-som-lv.dtsi +@@ -97,6 +97,8 @@ + }; + + &i2c1 { ++ pinctrl-names = "default"; ++ pinctrl-0 = <&i2c1_pins>; + clock-frequency = <2600000>; + + twl: twl@48 { +@@ -215,7 +217,12 @@ + >; + }; + +- ++ i2c1_pins: pinmux_i2c1_pins { ++ pinctrl-single,pins = < ++ OMAP3_CORE1_IOPAD(0x21ba, PIN_INPUT | MUX_MODE0) /* i2c1_scl.i2c1_scl */ ++ OMAP3_CORE1_IOPAD(0x21bc, PIN_INPUT | MUX_MODE0) /* i2c1_sda.i2c1_sda */ ++ >; ++ }; + }; + + &omap3_pmx_wkup { +diff --git a/arch/arm/boot/dts/logicpd-torpedo-som.dtsi b/arch/arm/boot/dts/logicpd-torpedo-som.dtsi +index 6d89736c7b44..cf22b35f0a28 100644 +--- a/arch/arm/boot/dts/logicpd-torpedo-som.dtsi ++++ b/arch/arm/boot/dts/logicpd-torpedo-som.dtsi +@@ -104,6 +104,8 @@ + }; + + &i2c1 { ++ pinctrl-names = "default"; ++ pinctrl-0 = <&i2c1_pins>; + clock-frequency = <2600000>; + + twl: twl@48 { +@@ -211,6 +213,12 @@ + OMAP3_CORE1_IOPAD(0x21b8, PIN_INPUT | MUX_MODE0) /* hsusb0_data7.hsusb0_data7 */ + >; + }; ++ i2c1_pins: pinmux_i2c1_pins { ++ pinctrl-single,pins = < ++ OMAP3_CORE1_IOPAD(0x21ba, PIN_INPUT | MUX_MODE0) /* i2c1_scl.i2c1_scl */ ++ OMAP3_CORE1_IOPAD(0x21bc, PIN_INPUT | MUX_MODE0) /* i2c1_sda.i2c1_sda */ ++ >; ++ }; + }; + + &uart2 { +diff --git a/arch/arm/boot/dts/rk3288-phycore-som.dtsi b/arch/arm/boot/dts/rk3288-phycore-som.dtsi +index 99cfae875e12..5eae4776ffde 100644 +--- a/arch/arm/boot/dts/rk3288-phycore-som.dtsi ++++ b/arch/arm/boot/dts/rk3288-phycore-som.dtsi +@@ -110,26 +110,6 @@ + }; + }; + +-&cpu0 { +- cpu0-supply = <&vdd_cpu>; +- operating-points = < +- /* KHz uV */ +- 1800000 1400000 +- 1608000 1350000 +- 1512000 1300000 +- 1416000 1200000 +- 1200000 1100000 +- 1008000 1050000 +- 816000 1000000 +- 696000 950000 +- 600000 900000 +- 408000 900000 +- 312000 900000 +- 216000 900000 +- 126000 900000 +- >; +-}; +- + &emmc { + status = "okay"; + bus-width = <8>; +diff --git a/arch/arm/kvm/hyp/Makefile b/arch/arm/kvm/hyp/Makefile +index 5638ce0c9524..63d6b404d88e 100644 +--- a/arch/arm/kvm/hyp/Makefile ++++ b/arch/arm/kvm/hyp/Makefile +@@ -7,6 +7,8 @@ ccflags-y += -fno-stack-protector -DDISABLE_BRANCH_PROFILING + + KVM=../../../../virt/kvm + ++CFLAGS_ARMV7VE :=$(call cc-option, -march=armv7ve) ++ + obj-$(CONFIG_KVM_ARM_HOST) += $(KVM)/arm/hyp/vgic-v2-sr.o + obj-$(CONFIG_KVM_ARM_HOST) += $(KVM)/arm/hyp/vgic-v3-sr.o + obj-$(CONFIG_KVM_ARM_HOST) += $(KVM)/arm/hyp/timer-sr.o +@@ -15,7 +17,10 @@ obj-$(CONFIG_KVM_ARM_HOST) += tlb.o + obj-$(CONFIG_KVM_ARM_HOST) += cp15-sr.o + obj-$(CONFIG_KVM_ARM_HOST) += vfp.o + obj-$(CONFIG_KVM_ARM_HOST) += banked-sr.o ++CFLAGS_banked-sr.o += $(CFLAGS_ARMV7VE) ++ + obj-$(CONFIG_KVM_ARM_HOST) += entry.o + obj-$(CONFIG_KVM_ARM_HOST) += hyp-entry.o + obj-$(CONFIG_KVM_ARM_HOST) += switch.o ++CFLAGS_switch.o += $(CFLAGS_ARMV7VE) + obj-$(CONFIG_KVM_ARM_HOST) += s2-setup.o +diff --git a/arch/arm/kvm/hyp/banked-sr.c b/arch/arm/kvm/hyp/banked-sr.c +index 111bda8cdebd..be4b8b0a40ad 100644 +--- a/arch/arm/kvm/hyp/banked-sr.c ++++ b/arch/arm/kvm/hyp/banked-sr.c +@@ -20,6 +20,10 @@ + + #include + ++/* ++ * gcc before 4.9 doesn't understand -march=armv7ve, so we have to ++ * trick the assembler. ++ */ + __asm__(".arch_extension virt"); + + void __hyp_text __banked_save_state(struct kvm_cpu_context *ctxt) +diff --git a/arch/arm/mach-mvebu/Kconfig b/arch/arm/mach-mvebu/Kconfig +index 9b49867154bf..63fa79f9f121 100644 +--- a/arch/arm/mach-mvebu/Kconfig ++++ b/arch/arm/mach-mvebu/Kconfig +@@ -42,7 +42,7 @@ config MACH_ARMADA_375 + depends on ARCH_MULTI_V7 + select ARMADA_370_XP_IRQ + select ARM_ERRATA_720789 +- select ARM_ERRATA_753970 ++ select PL310_ERRATA_753970 + select ARM_GIC + select ARMADA_375_CLK + select HAVE_ARM_SCU +@@ -58,7 +58,7 @@ config MACH_ARMADA_38X + bool "Marvell Armada 380/385 boards" + depends on ARCH_MULTI_V7 + select ARM_ERRATA_720789 +- select ARM_ERRATA_753970 ++ select PL310_ERRATA_753970 + select ARM_GIC + select ARM_GLOBAL_TIMER + select CLKSRC_ARM_GLOBAL_TIMER_SCHED_CLOCK +diff --git a/arch/arm/plat-orion/common.c b/arch/arm/plat-orion/common.c +index aff6994950ba..a2399fd66e97 100644 +--- a/arch/arm/plat-orion/common.c ++++ b/arch/arm/plat-orion/common.c +@@ -472,28 +472,27 @@ void __init orion_ge11_init(struct mv643xx_eth_platform_data *eth_data, + /***************************************************************************** + * Ethernet switch + ****************************************************************************/ +-static __initconst const char *orion_ge00_mvmdio_bus_name = "orion-mii"; +-static __initdata struct mdio_board_info +- orion_ge00_switch_board_info; ++static __initdata struct mdio_board_info orion_ge00_switch_board_info = { ++ .bus_id = "orion-mii", ++ .modalias = "mv88e6085", ++}; + + void __init orion_ge00_switch_init(struct dsa_chip_data *d) + { +- struct mdio_board_info *bd; + unsigned int i; + + if (!IS_BUILTIN(CONFIG_PHYLIB)) + return; + +- for (i = 0; i < ARRAY_SIZE(d->port_names); i++) +- if (!strcmp(d->port_names[i], "cpu")) ++ for (i = 0; i < ARRAY_SIZE(d->port_names); i++) { ++ if (!strcmp(d->port_names[i], "cpu")) { ++ d->netdev[i] = &orion_ge00.dev; + break; ++ } ++ } + +- bd = &orion_ge00_switch_board_info; +- bd->bus_id = orion_ge00_mvmdio_bus_name; +- bd->mdio_addr = d->sw_addr; +- d->netdev[i] = &orion_ge00.dev; +- strcpy(bd->modalias, "mv88e6085"); +- bd->platform_data = d; ++ orion_ge00_switch_board_info.mdio_addr = d->sw_addr; ++ orion_ge00_switch_board_info.platform_data = d; + + mdiobus_register_board_info(&orion_ge00_switch_board_info, 1); + } +diff --git a/arch/parisc/include/asm/cacheflush.h b/arch/parisc/include/asm/cacheflush.h +index 3742508cc534..bd5ce31936f5 100644 +--- a/arch/parisc/include/asm/cacheflush.h ++++ b/arch/parisc/include/asm/cacheflush.h +@@ -26,6 +26,7 @@ void flush_user_icache_range_asm(unsigned long, unsigned long); + void flush_kernel_icache_range_asm(unsigned long, unsigned long); + void flush_user_dcache_range_asm(unsigned long, unsigned long); + void flush_kernel_dcache_range_asm(unsigned long, unsigned long); ++void purge_kernel_dcache_range_asm(unsigned long, unsigned long); + void flush_kernel_dcache_page_asm(void *); + void flush_kernel_icache_page(void *); + +diff --git a/arch/parisc/include/asm/processor.h b/arch/parisc/include/asm/processor.h +index 0e6ab6e4a4e9..2dbe5580a1a4 100644 +--- a/arch/parisc/include/asm/processor.h ++++ b/arch/parisc/include/asm/processor.h +@@ -316,6 +316,8 @@ extern int _parisc_requires_coherency; + #define parisc_requires_coherency() (0) + #endif + ++extern int running_on_qemu; ++ + #endif /* __ASSEMBLY__ */ + + #endif /* __ASM_PARISC_PROCESSOR_H */ +diff --git a/arch/parisc/kernel/cache.c b/arch/parisc/kernel/cache.c +index 19c0c141bc3f..79089778725b 100644 +--- a/arch/parisc/kernel/cache.c ++++ b/arch/parisc/kernel/cache.c +@@ -465,10 +465,10 @@ EXPORT_SYMBOL(copy_user_page); + int __flush_tlb_range(unsigned long sid, unsigned long start, + unsigned long end) + { +- unsigned long flags, size; ++ unsigned long flags; + +- size = (end - start); +- if (size >= parisc_tlb_flush_threshold) { ++ if ((!IS_ENABLED(CONFIG_SMP) || !arch_irqs_disabled()) && ++ end - start >= parisc_tlb_flush_threshold) { + flush_tlb_all(); + return 1; + } +@@ -539,13 +539,11 @@ void flush_cache_mm(struct mm_struct *mm) + struct vm_area_struct *vma; + pgd_t *pgd; + +- /* Flush the TLB to avoid speculation if coherency is required. */ +- if (parisc_requires_coherency()) +- flush_tlb_all(); +- + /* Flushing the whole cache on each cpu takes forever on + rp3440, etc. So, avoid it if the mm isn't too big. */ +- if (mm_total_size(mm) >= parisc_cache_flush_threshold) { ++ if ((!IS_ENABLED(CONFIG_SMP) || !arch_irqs_disabled()) && ++ mm_total_size(mm) >= parisc_cache_flush_threshold) { ++ flush_tlb_all(); + flush_cache_all(); + return; + } +@@ -553,9 +551,9 @@ void flush_cache_mm(struct mm_struct *mm) + if (mm->context == mfsp(3)) { + for (vma = mm->mmap; vma; vma = vma->vm_next) { + flush_user_dcache_range_asm(vma->vm_start, vma->vm_end); +- if ((vma->vm_flags & VM_EXEC) == 0) +- continue; +- flush_user_icache_range_asm(vma->vm_start, vma->vm_end); ++ if (vma->vm_flags & VM_EXEC) ++ flush_user_icache_range_asm(vma->vm_start, vma->vm_end); ++ flush_tlb_range(vma, vma->vm_start, vma->vm_end); + } + return; + } +@@ -581,14 +579,9 @@ void flush_cache_mm(struct mm_struct *mm) + void flush_cache_range(struct vm_area_struct *vma, + unsigned long start, unsigned long end) + { +- BUG_ON(!vma->vm_mm->context); +- +- /* Flush the TLB to avoid speculation if coherency is required. */ +- if (parisc_requires_coherency()) ++ if ((!IS_ENABLED(CONFIG_SMP) || !arch_irqs_disabled()) && ++ end - start >= parisc_cache_flush_threshold) { + flush_tlb_range(vma, start, end); +- +- if ((end - start) >= parisc_cache_flush_threshold +- || vma->vm_mm->context != mfsp(3)) { + flush_cache_all(); + return; + } +@@ -596,6 +589,7 @@ void flush_cache_range(struct vm_area_struct *vma, + flush_user_dcache_range_asm(start, end); + if (vma->vm_flags & VM_EXEC) + flush_user_icache_range_asm(start, end); ++ flush_tlb_range(vma, start, end); + } + + void +@@ -604,8 +598,7 @@ flush_cache_page(struct vm_area_struct *vma, unsigned long vmaddr, unsigned long + BUG_ON(!vma->vm_mm->context); + + if (pfn_valid(pfn)) { +- if (parisc_requires_coherency()) +- flush_tlb_page(vma, vmaddr); ++ flush_tlb_page(vma, vmaddr); + __flush_cache_page(vma, vmaddr, PFN_PHYS(pfn)); + } + } +@@ -613,21 +606,33 @@ flush_cache_page(struct vm_area_struct *vma, unsigned long vmaddr, unsigned long + void flush_kernel_vmap_range(void *vaddr, int size) + { + unsigned long start = (unsigned long)vaddr; ++ unsigned long end = start + size; + +- if ((unsigned long)size > parisc_cache_flush_threshold) ++ if ((!IS_ENABLED(CONFIG_SMP) || !arch_irqs_disabled()) && ++ (unsigned long)size >= parisc_cache_flush_threshold) { ++ flush_tlb_kernel_range(start, end); + flush_data_cache(); +- else +- flush_kernel_dcache_range_asm(start, start + size); ++ return; ++ } ++ ++ flush_kernel_dcache_range_asm(start, end); ++ flush_tlb_kernel_range(start, end); + } + EXPORT_SYMBOL(flush_kernel_vmap_range); + + void invalidate_kernel_vmap_range(void *vaddr, int size) + { + unsigned long start = (unsigned long)vaddr; ++ unsigned long end = start + size; + +- if ((unsigned long)size > parisc_cache_flush_threshold) ++ if ((!IS_ENABLED(CONFIG_SMP) || !arch_irqs_disabled()) && ++ (unsigned long)size >= parisc_cache_flush_threshold) { ++ flush_tlb_kernel_range(start, end); + flush_data_cache(); +- else +- flush_kernel_dcache_range_asm(start, start + size); ++ return; ++ } ++ ++ purge_kernel_dcache_range_asm(start, end); ++ flush_tlb_kernel_range(start, end); + } + EXPORT_SYMBOL(invalidate_kernel_vmap_range); +diff --git a/arch/parisc/kernel/pacache.S b/arch/parisc/kernel/pacache.S +index 2d40c4ff3f69..67b0f7532e83 100644 +--- a/arch/parisc/kernel/pacache.S ++++ b/arch/parisc/kernel/pacache.S +@@ -1110,6 +1110,28 @@ ENTRY_CFI(flush_kernel_dcache_range_asm) + .procend + ENDPROC_CFI(flush_kernel_dcache_range_asm) + ++ENTRY_CFI(purge_kernel_dcache_range_asm) ++ .proc ++ .callinfo NO_CALLS ++ .entry ++ ++ ldil L%dcache_stride, %r1 ++ ldw R%dcache_stride(%r1), %r23 ++ ldo -1(%r23), %r21 ++ ANDCM %r26, %r21, %r26 ++ ++1: cmpb,COND(<<),n %r26, %r25,1b ++ pdc,m %r23(%r26) ++ ++ sync ++ syncdma ++ bv %r0(%r2) ++ nop ++ .exit ++ ++ .procend ++ENDPROC_CFI(purge_kernel_dcache_range_asm) ++ + ENTRY_CFI(flush_user_icache_range_asm) + .proc + .callinfo NO_CALLS +diff --git a/arch/parisc/kernel/time.c b/arch/parisc/kernel/time.c +index 4b8fd6dc22da..f7e684560186 100644 +--- a/arch/parisc/kernel/time.c ++++ b/arch/parisc/kernel/time.c +@@ -76,10 +76,10 @@ irqreturn_t __irq_entry timer_interrupt(int irq, void *dev_id) + next_tick = cpuinfo->it_value; + + /* Calculate how many ticks have elapsed. */ ++ now = mfctl(16); + do { + ++ticks_elapsed; + next_tick += cpt; +- now = mfctl(16); + } while (next_tick - now > cpt); + + /* Store (in CR16 cycles) up to when we are accounting right now. */ +@@ -103,16 +103,17 @@ irqreturn_t __irq_entry timer_interrupt(int irq, void *dev_id) + * if one or the other wrapped. If "now" is "bigger" we'll end up + * with a very large unsigned number. + */ +- while (next_tick - mfctl(16) > cpt) ++ now = mfctl(16); ++ while (next_tick - now > cpt) + next_tick += cpt; + + /* Program the IT when to deliver the next interrupt. + * Only bottom 32-bits of next_tick are writable in CR16! + * Timer interrupt will be delivered at least a few hundred cycles +- * after the IT fires, so if we are too close (<= 500 cycles) to the ++ * after the IT fires, so if we are too close (<= 8000 cycles) to the + * next cycle, simply skip it. + */ +- if (next_tick - mfctl(16) <= 500) ++ if (next_tick - now <= 8000) + next_tick += cpt; + mtctl(next_tick, 16); + +@@ -248,7 +249,7 @@ static int __init init_cr16_clocksource(void) + * different sockets, so mark them unstable and lower rating on + * multi-socket SMP systems. + */ +- if (num_online_cpus() > 1) { ++ if (num_online_cpus() > 1 && !running_on_qemu) { + int cpu; + unsigned long cpu0_loc; + cpu0_loc = per_cpu(cpu_data, 0).cpu_loc; +diff --git a/arch/s390/kvm/interrupt.c b/arch/s390/kvm/interrupt.c +index a832ad031cee..5185be314661 100644 +--- a/arch/s390/kvm/interrupt.c ++++ b/arch/s390/kvm/interrupt.c +@@ -173,8 +173,15 @@ static int ckc_interrupts_enabled(struct kvm_vcpu *vcpu) + + static int ckc_irq_pending(struct kvm_vcpu *vcpu) + { +- if (vcpu->arch.sie_block->ckc >= kvm_s390_get_tod_clock_fast(vcpu->kvm)) ++ const u64 now = kvm_s390_get_tod_clock_fast(vcpu->kvm); ++ const u64 ckc = vcpu->arch.sie_block->ckc; ++ ++ if (vcpu->arch.sie_block->gcr[0] & 0x0020000000000000ul) { ++ if ((s64)ckc >= (s64)now) ++ return 0; ++ } else if (ckc >= now) { + return 0; ++ } + return ckc_interrupts_enabled(vcpu); + } + +@@ -1004,13 +1011,19 @@ int kvm_cpu_has_pending_timer(struct kvm_vcpu *vcpu) + + static u64 __calculate_sltime(struct kvm_vcpu *vcpu) + { +- u64 now, cputm, sltime = 0; ++ const u64 now = kvm_s390_get_tod_clock_fast(vcpu->kvm); ++ const u64 ckc = vcpu->arch.sie_block->ckc; ++ u64 cputm, sltime = 0; + + if (ckc_interrupts_enabled(vcpu)) { +- now = kvm_s390_get_tod_clock_fast(vcpu->kvm); +- sltime = tod_to_ns(vcpu->arch.sie_block->ckc - now); +- /* already expired or overflow? */ +- if (!sltime || vcpu->arch.sie_block->ckc <= now) ++ if (vcpu->arch.sie_block->gcr[0] & 0x0020000000000000ul) { ++ if ((s64)now < (s64)ckc) ++ sltime = tod_to_ns((s64)ckc - (s64)now); ++ } else if (now < ckc) { ++ sltime = tod_to_ns(ckc - now); ++ } ++ /* already expired */ ++ if (!sltime) + return 0; + if (cpu_timer_interrupts_enabled(vcpu)) { + cputm = kvm_s390_get_cpu_timer(vcpu); +diff --git a/arch/s390/kvm/kvm-s390.c b/arch/s390/kvm/kvm-s390.c +index 6e3d80b2048e..f4f12ecd0cec 100644 +--- a/arch/s390/kvm/kvm-s390.c ++++ b/arch/s390/kvm/kvm-s390.c +@@ -169,6 +169,28 @@ int kvm_arch_hardware_enable(void) + static void kvm_gmap_notifier(struct gmap *gmap, unsigned long start, + unsigned long end); + ++static void kvm_clock_sync_scb(struct kvm_s390_sie_block *scb, u64 delta) ++{ ++ u8 delta_idx = 0; ++ ++ /* ++ * The TOD jumps by delta, we have to compensate this by adding ++ * -delta to the epoch. ++ */ ++ delta = -delta; ++ ++ /* sign-extension - we're adding to signed values below */ ++ if ((s64)delta < 0) ++ delta_idx = -1; ++ ++ scb->epoch += delta; ++ if (scb->ecd & ECD_MEF) { ++ scb->epdx += delta_idx; ++ if (scb->epoch < delta) ++ scb->epdx += 1; ++ } ++} ++ + /* + * This callback is executed during stop_machine(). All CPUs are therefore + * temporarily stopped. In order not to change guest behavior, we have to +@@ -184,13 +206,17 @@ static int kvm_clock_sync(struct notifier_block *notifier, unsigned long val, + unsigned long long *delta = v; + + list_for_each_entry(kvm, &vm_list, vm_list) { +- kvm->arch.epoch -= *delta; + kvm_for_each_vcpu(i, vcpu, kvm) { +- vcpu->arch.sie_block->epoch -= *delta; ++ kvm_clock_sync_scb(vcpu->arch.sie_block, *delta); ++ if (i == 0) { ++ kvm->arch.epoch = vcpu->arch.sie_block->epoch; ++ kvm->arch.epdx = vcpu->arch.sie_block->epdx; ++ } + if (vcpu->arch.cputm_enabled) + vcpu->arch.cputm_start += *delta; + if (vcpu->arch.vsie_block) +- vcpu->arch.vsie_block->epoch -= *delta; ++ kvm_clock_sync_scb(vcpu->arch.vsie_block, ++ *delta); + } + } + return NOTIFY_OK; +@@ -888,12 +914,9 @@ static int kvm_s390_set_tod_ext(struct kvm *kvm, struct kvm_device_attr *attr) + if (copy_from_user(>od, (void __user *)attr->addr, sizeof(gtod))) + return -EFAULT; + +- if (test_kvm_facility(kvm, 139)) +- kvm_s390_set_tod_clock_ext(kvm, >od); +- else if (gtod.epoch_idx == 0) +- kvm_s390_set_tod_clock(kvm, gtod.tod); +- else ++ if (!test_kvm_facility(kvm, 139) && gtod.epoch_idx) + return -EINVAL; ++ kvm_s390_set_tod_clock(kvm, >od); + + VM_EVENT(kvm, 3, "SET: TOD extension: 0x%x, TOD base: 0x%llx", + gtod.epoch_idx, gtod.tod); +@@ -918,13 +941,14 @@ static int kvm_s390_set_tod_high(struct kvm *kvm, struct kvm_device_attr *attr) + + static int kvm_s390_set_tod_low(struct kvm *kvm, struct kvm_device_attr *attr) + { +- u64 gtod; ++ struct kvm_s390_vm_tod_clock gtod = { 0 }; + +- if (copy_from_user(>od, (void __user *)attr->addr, sizeof(gtod))) ++ if (copy_from_user(>od.tod, (void __user *)attr->addr, ++ sizeof(gtod.tod))) + return -EFAULT; + +- kvm_s390_set_tod_clock(kvm, gtod); +- VM_EVENT(kvm, 3, "SET: TOD base: 0x%llx", gtod); ++ kvm_s390_set_tod_clock(kvm, >od); ++ VM_EVENT(kvm, 3, "SET: TOD base: 0x%llx", gtod.tod); + return 0; + } + +@@ -2359,6 +2383,7 @@ void kvm_arch_vcpu_postcreate(struct kvm_vcpu *vcpu) + mutex_lock(&vcpu->kvm->lock); + preempt_disable(); + vcpu->arch.sie_block->epoch = vcpu->kvm->arch.epoch; ++ vcpu->arch.sie_block->epdx = vcpu->kvm->arch.epdx; + preempt_enable(); + mutex_unlock(&vcpu->kvm->lock); + if (!kvm_is_ucontrol(vcpu->kvm)) { +@@ -2945,8 +2970,8 @@ static int kvm_s390_handle_requests(struct kvm_vcpu *vcpu) + return 0; + } + +-void kvm_s390_set_tod_clock_ext(struct kvm *kvm, +- const struct kvm_s390_vm_tod_clock *gtod) ++void kvm_s390_set_tod_clock(struct kvm *kvm, ++ const struct kvm_s390_vm_tod_clock *gtod) + { + struct kvm_vcpu *vcpu; + struct kvm_s390_tod_clock_ext htod; +@@ -2958,10 +2983,12 @@ void kvm_s390_set_tod_clock_ext(struct kvm *kvm, + get_tod_clock_ext((char *)&htod); + + kvm->arch.epoch = gtod->tod - htod.tod; +- kvm->arch.epdx = gtod->epoch_idx - htod.epoch_idx; +- +- if (kvm->arch.epoch > gtod->tod) +- kvm->arch.epdx -= 1; ++ kvm->arch.epdx = 0; ++ if (test_kvm_facility(kvm, 139)) { ++ kvm->arch.epdx = gtod->epoch_idx - htod.epoch_idx; ++ if (kvm->arch.epoch > gtod->tod) ++ kvm->arch.epdx -= 1; ++ } + + kvm_s390_vcpu_block_all(kvm); + kvm_for_each_vcpu(i, vcpu, kvm) { +@@ -2974,22 +3001,6 @@ void kvm_s390_set_tod_clock_ext(struct kvm *kvm, + mutex_unlock(&kvm->lock); + } + +-void kvm_s390_set_tod_clock(struct kvm *kvm, u64 tod) +-{ +- struct kvm_vcpu *vcpu; +- int i; +- +- mutex_lock(&kvm->lock); +- preempt_disable(); +- kvm->arch.epoch = tod - get_tod_clock(); +- kvm_s390_vcpu_block_all(kvm); +- kvm_for_each_vcpu(i, vcpu, kvm) +- vcpu->arch.sie_block->epoch = kvm->arch.epoch; +- kvm_s390_vcpu_unblock_all(kvm); +- preempt_enable(); +- mutex_unlock(&kvm->lock); +-} +- + /** + * kvm_arch_fault_in_page - fault-in guest page if necessary + * @vcpu: The corresponding virtual cpu +diff --git a/arch/s390/kvm/kvm-s390.h b/arch/s390/kvm/kvm-s390.h +index 9f8fdd7b2311..e22d94f494a7 100644 +--- a/arch/s390/kvm/kvm-s390.h ++++ b/arch/s390/kvm/kvm-s390.h +@@ -272,9 +272,8 @@ int kvm_s390_handle_sigp_pei(struct kvm_vcpu *vcpu); + int handle_sthyi(struct kvm_vcpu *vcpu); + + /* implemented in kvm-s390.c */ +-void kvm_s390_set_tod_clock_ext(struct kvm *kvm, +- const struct kvm_s390_vm_tod_clock *gtod); +-void kvm_s390_set_tod_clock(struct kvm *kvm, u64 tod); ++void kvm_s390_set_tod_clock(struct kvm *kvm, ++ const struct kvm_s390_vm_tod_clock *gtod); + long kvm_arch_fault_in_page(struct kvm_vcpu *vcpu, gpa_t gpa, int writable); + int kvm_s390_store_status_unloaded(struct kvm_vcpu *vcpu, unsigned long addr); + int kvm_s390_vcpu_store_status(struct kvm_vcpu *vcpu, unsigned long addr); +diff --git a/arch/s390/kvm/priv.c b/arch/s390/kvm/priv.c +index 7bd3a59232f0..734283a21677 100644 +--- a/arch/s390/kvm/priv.c ++++ b/arch/s390/kvm/priv.c +@@ -84,9 +84,10 @@ int kvm_s390_handle_e3(struct kvm_vcpu *vcpu) + /* Handle SCK (SET CLOCK) interception */ + static int handle_set_clock(struct kvm_vcpu *vcpu) + { ++ struct kvm_s390_vm_tod_clock gtod = { 0 }; + int rc; + u8 ar; +- u64 op2, val; ++ u64 op2; + + if (vcpu->arch.sie_block->gpsw.mask & PSW_MASK_PSTATE) + return kvm_s390_inject_program_int(vcpu, PGM_PRIVILEGED_OP); +@@ -94,12 +95,12 @@ static int handle_set_clock(struct kvm_vcpu *vcpu) + op2 = kvm_s390_get_base_disp_s(vcpu, &ar); + if (op2 & 7) /* Operand must be on a doubleword boundary */ + return kvm_s390_inject_program_int(vcpu, PGM_SPECIFICATION); +- rc = read_guest(vcpu, op2, ar, &val, sizeof(val)); ++ rc = read_guest(vcpu, op2, ar, >od.tod, sizeof(gtod.tod)); + if (rc) + return kvm_s390_inject_prog_cond(vcpu, rc); + +- VCPU_EVENT(vcpu, 3, "SCK: setting guest TOD to 0x%llx", val); +- kvm_s390_set_tod_clock(vcpu->kvm, val); ++ VCPU_EVENT(vcpu, 3, "SCK: setting guest TOD to 0x%llx", gtod.tod); ++ kvm_s390_set_tod_clock(vcpu->kvm, >od); + + kvm_s390_set_psw_cc(vcpu, 0); + return 0; +diff --git a/arch/x86/include/asm/pgtable.h b/arch/x86/include/asm/pgtable.h +index 8b8f1f14a0bf..5c790e93657d 100644 +--- a/arch/x86/include/asm/pgtable.h ++++ b/arch/x86/include/asm/pgtable.h +@@ -350,14 +350,14 @@ static inline pmd_t pmd_set_flags(pmd_t pmd, pmdval_t set) + { + pmdval_t v = native_pmd_val(pmd); + +- return __pmd(v | set); ++ return native_make_pmd(v | set); + } + + static inline pmd_t pmd_clear_flags(pmd_t pmd, pmdval_t clear) + { + pmdval_t v = native_pmd_val(pmd); + +- return __pmd(v & ~clear); ++ return native_make_pmd(v & ~clear); + } + + static inline pmd_t pmd_mkold(pmd_t pmd) +@@ -409,14 +409,14 @@ static inline pud_t pud_set_flags(pud_t pud, pudval_t set) + { + pudval_t v = native_pud_val(pud); + +- return __pud(v | set); ++ return native_make_pud(v | set); + } + + static inline pud_t pud_clear_flags(pud_t pud, pudval_t clear) + { + pudval_t v = native_pud_val(pud); + +- return __pud(v & ~clear); ++ return native_make_pud(v & ~clear); + } + + static inline pud_t pud_mkold(pud_t pud) +diff --git a/arch/x86/include/asm/pgtable_32.h b/arch/x86/include/asm/pgtable_32.h +index e55466760ff8..b3ec519e3982 100644 +--- a/arch/x86/include/asm/pgtable_32.h ++++ b/arch/x86/include/asm/pgtable_32.h +@@ -32,6 +32,7 @@ extern pmd_t initial_pg_pmd[]; + static inline void pgtable_cache_init(void) { } + static inline void check_pgt_cache(void) { } + void paging_init(void); ++void sync_initial_page_table(void); + + /* + * Define this if things work differently on an i386 and an i486: +diff --git a/arch/x86/include/asm/pgtable_64.h b/arch/x86/include/asm/pgtable_64.h +index 81462e9a34f6..1149d2112b2e 100644 +--- a/arch/x86/include/asm/pgtable_64.h ++++ b/arch/x86/include/asm/pgtable_64.h +@@ -28,6 +28,7 @@ extern pgd_t init_top_pgt[]; + #define swapper_pg_dir init_top_pgt + + extern void paging_init(void); ++static inline void sync_initial_page_table(void) { } + + #define pte_ERROR(e) \ + pr_err("%s:%d: bad pte %p(%016lx)\n", \ +diff --git a/arch/x86/include/asm/pgtable_types.h b/arch/x86/include/asm/pgtable_types.h +index 3696398a9475..246f15b4e64c 100644 +--- a/arch/x86/include/asm/pgtable_types.h ++++ b/arch/x86/include/asm/pgtable_types.h +@@ -323,6 +323,11 @@ static inline pudval_t native_pud_val(pud_t pud) + #else + #include + ++static inline pud_t native_make_pud(pudval_t val) ++{ ++ return (pud_t) { .p4d.pgd = native_make_pgd(val) }; ++} ++ + static inline pudval_t native_pud_val(pud_t pud) + { + return native_pgd_val(pud.p4d.pgd); +@@ -344,6 +349,11 @@ static inline pmdval_t native_pmd_val(pmd_t pmd) + #else + #include + ++static inline pmd_t native_make_pmd(pmdval_t val) ++{ ++ return (pmd_t) { .pud.p4d.pgd = native_make_pgd(val) }; ++} ++ + static inline pmdval_t native_pmd_val(pmd_t pmd) + { + return native_pgd_val(pmd.pud.p4d.pgd); +diff --git a/arch/x86/kernel/setup.c b/arch/x86/kernel/setup.c +index c54361a22f59..efbcf5283520 100644 +--- a/arch/x86/kernel/setup.c ++++ b/arch/x86/kernel/setup.c +@@ -1238,20 +1238,13 @@ void __init setup_arch(char **cmdline_p) + + kasan_init(); + +-#ifdef CONFIG_X86_32 +- /* sync back kernel address range */ +- clone_pgd_range(initial_page_table + KERNEL_PGD_BOUNDARY, +- swapper_pg_dir + KERNEL_PGD_BOUNDARY, +- KERNEL_PGD_PTRS); +- + /* +- * sync back low identity map too. It is used for example +- * in the 32-bit EFI stub. ++ * Sync back kernel address range. ++ * ++ * FIXME: Can the later sync in setup_cpu_entry_areas() replace ++ * this call? + */ +- clone_pgd_range(initial_page_table, +- swapper_pg_dir + KERNEL_PGD_BOUNDARY, +- min(KERNEL_PGD_PTRS, KERNEL_PGD_BOUNDARY)); +-#endif ++ sync_initial_page_table(); + + tboot_probe(); + +diff --git a/arch/x86/kernel/setup_percpu.c b/arch/x86/kernel/setup_percpu.c +index 497aa766fab3..ea554f812ee1 100644 +--- a/arch/x86/kernel/setup_percpu.c ++++ b/arch/x86/kernel/setup_percpu.c +@@ -287,24 +287,15 @@ void __init setup_per_cpu_areas(void) + /* Setup cpu initialized, callin, callout masks */ + setup_cpu_local_masks(); + +-#ifdef CONFIG_X86_32 + /* + * Sync back kernel address range again. We already did this in + * setup_arch(), but percpu data also needs to be available in + * the smpboot asm. We can't reliably pick up percpu mappings + * using vmalloc_fault(), because exception dispatch needs + * percpu data. ++ * ++ * FIXME: Can the later sync in setup_cpu_entry_areas() replace ++ * this call? + */ +- clone_pgd_range(initial_page_table + KERNEL_PGD_BOUNDARY, +- swapper_pg_dir + KERNEL_PGD_BOUNDARY, +- KERNEL_PGD_PTRS); +- +- /* +- * sync back low identity map too. It is used for example +- * in the 32-bit EFI stub. +- */ +- clone_pgd_range(initial_page_table, +- swapper_pg_dir + KERNEL_PGD_BOUNDARY, +- min(KERNEL_PGD_PTRS, KERNEL_PGD_BOUNDARY)); +-#endif ++ sync_initial_page_table(); + } +diff --git a/arch/x86/kvm/lapic.c b/arch/x86/kvm/lapic.c +index ef03efba1c23..8cfdb6484fd0 100644 +--- a/arch/x86/kvm/lapic.c ++++ b/arch/x86/kvm/lapic.c +@@ -1944,14 +1944,13 @@ void kvm_lapic_set_base(struct kvm_vcpu *vcpu, u64 value) + + void kvm_lapic_reset(struct kvm_vcpu *vcpu, bool init_event) + { +- struct kvm_lapic *apic; ++ struct kvm_lapic *apic = vcpu->arch.apic; + int i; + +- apic_debug("%s\n", __func__); ++ if (!apic) ++ return; + +- ASSERT(vcpu); +- apic = vcpu->arch.apic; +- ASSERT(apic != NULL); ++ apic_debug("%s\n", __func__); + + /* Stop the timer in case it's a reset to an active apic */ + hrtimer_cancel(&apic->lapic_timer.timer); +@@ -2107,7 +2106,6 @@ int kvm_create_lapic(struct kvm_vcpu *vcpu) + */ + vcpu->arch.apic_base = MSR_IA32_APICBASE_ENABLE; + static_key_slow_inc(&apic_sw_disabled.key); /* sw disabled at reset */ +- kvm_lapic_reset(vcpu, false); + kvm_iodevice_init(&apic->dev, &apic_mmio_ops); + + return 0; +@@ -2511,7 +2509,6 @@ void kvm_apic_accept_events(struct kvm_vcpu *vcpu) + + pe = xchg(&apic->pending_events, 0); + if (test_bit(KVM_APIC_INIT, &pe)) { +- kvm_lapic_reset(vcpu, true); + kvm_vcpu_reset(vcpu, true); + if (kvm_vcpu_is_bsp(apic->vcpu)) + vcpu->arch.mp_state = KVM_MP_STATE_RUNNABLE; +diff --git a/arch/x86/kvm/mmu.c b/arch/x86/kvm/mmu.c +index ca000fc644bc..2b6f8a4f2731 100644 +--- a/arch/x86/kvm/mmu.c ++++ b/arch/x86/kvm/mmu.c +@@ -150,6 +150,20 @@ module_param(dbg, bool, 0644); + /* make pte_list_desc fit well in cache line */ + #define PTE_LIST_EXT 3 + ++/* ++ * Return values of handle_mmio_page_fault and mmu.page_fault: ++ * RET_PF_RETRY: let CPU fault again on the address. ++ * RET_PF_EMULATE: mmio page fault, emulate the instruction directly. ++ * ++ * For handle_mmio_page_fault only: ++ * RET_PF_INVALID: the spte is invalid, let the real page fault path update it. ++ */ ++enum { ++ RET_PF_RETRY = 0, ++ RET_PF_EMULATE = 1, ++ RET_PF_INVALID = 2, ++}; ++ + struct pte_list_desc { + u64 *sptes[PTE_LIST_EXT]; + struct pte_list_desc *more; +@@ -2794,13 +2808,13 @@ static int set_spte(struct kvm_vcpu *vcpu, u64 *sptep, + return ret; + } + +-static bool mmu_set_spte(struct kvm_vcpu *vcpu, u64 *sptep, unsigned pte_access, +- int write_fault, int level, gfn_t gfn, kvm_pfn_t pfn, +- bool speculative, bool host_writable) ++static int mmu_set_spte(struct kvm_vcpu *vcpu, u64 *sptep, unsigned pte_access, ++ int write_fault, int level, gfn_t gfn, kvm_pfn_t pfn, ++ bool speculative, bool host_writable) + { + int was_rmapped = 0; + int rmap_count; +- bool emulate = false; ++ int ret = RET_PF_RETRY; + + pgprintk("%s: spte %llx write_fault %d gfn %llx\n", __func__, + *sptep, write_fault, gfn); +@@ -2830,12 +2844,12 @@ static bool mmu_set_spte(struct kvm_vcpu *vcpu, u64 *sptep, unsigned pte_access, + if (set_spte(vcpu, sptep, pte_access, level, gfn, pfn, speculative, + true, host_writable)) { + if (write_fault) +- emulate = true; ++ ret = RET_PF_EMULATE; + kvm_make_request(KVM_REQ_TLB_FLUSH, vcpu); + } + + if (unlikely(is_mmio_spte(*sptep))) +- emulate = true; ++ ret = RET_PF_EMULATE; + + pgprintk("%s: setting spte %llx\n", __func__, *sptep); + pgprintk("instantiating %s PTE (%s) at %llx (%llx) addr %p\n", +@@ -2855,7 +2869,7 @@ static bool mmu_set_spte(struct kvm_vcpu *vcpu, u64 *sptep, unsigned pte_access, + + kvm_release_pfn_clean(pfn); + +- return emulate; ++ return ret; + } + + static kvm_pfn_t pte_prefetch_gfn_to_pfn(struct kvm_vcpu *vcpu, gfn_t gfn, +@@ -2994,17 +3008,16 @@ static int kvm_handle_bad_page(struct kvm_vcpu *vcpu, gfn_t gfn, kvm_pfn_t pfn) + * Do not cache the mmio info caused by writing the readonly gfn + * into the spte otherwise read access on readonly gfn also can + * caused mmio page fault and treat it as mmio access. +- * Return 1 to tell kvm to emulate it. + */ + if (pfn == KVM_PFN_ERR_RO_FAULT) +- return 1; ++ return RET_PF_EMULATE; + + if (pfn == KVM_PFN_ERR_HWPOISON) { + kvm_send_hwpoison_signal(kvm_vcpu_gfn_to_hva(vcpu, gfn), current); +- return 0; ++ return RET_PF_RETRY; + } + +- return -EFAULT; ++ return RET_PF_EMULATE; + } + + static void transparent_hugepage_adjust(struct kvm_vcpu *vcpu, +@@ -3286,13 +3299,13 @@ static int nonpaging_map(struct kvm_vcpu *vcpu, gva_t v, u32 error_code, + } + + if (fast_page_fault(vcpu, v, level, error_code)) +- return 0; ++ return RET_PF_RETRY; + + mmu_seq = vcpu->kvm->mmu_notifier_seq; + smp_rmb(); + + if (try_async_pf(vcpu, prefault, gfn, v, &pfn, write, &map_writable)) +- return 0; ++ return RET_PF_RETRY; + + if (handle_abnormal_pfn(vcpu, v, gfn, pfn, ACC_ALL, &r)) + return r; +@@ -3312,7 +3325,7 @@ static int nonpaging_map(struct kvm_vcpu *vcpu, gva_t v, u32 error_code, + out_unlock: + spin_unlock(&vcpu->kvm->mmu_lock); + kvm_release_pfn_clean(pfn); +- return 0; ++ return RET_PF_RETRY; + } + + +@@ -3659,54 +3672,38 @@ walk_shadow_page_get_mmio_spte(struct kvm_vcpu *vcpu, u64 addr, u64 *sptep) + return reserved; + } + +-/* +- * Return values of handle_mmio_page_fault: +- * RET_MMIO_PF_EMULATE: it is a real mmio page fault, emulate the instruction +- * directly. +- * RET_MMIO_PF_INVALID: invalid spte is detected then let the real page +- * fault path update the mmio spte. +- * RET_MMIO_PF_RETRY: let CPU fault again on the address. +- * RET_MMIO_PF_BUG: a bug was detected (and a WARN was printed). +- */ +-enum { +- RET_MMIO_PF_EMULATE = 1, +- RET_MMIO_PF_INVALID = 2, +- RET_MMIO_PF_RETRY = 0, +- RET_MMIO_PF_BUG = -1 +-}; +- + static int handle_mmio_page_fault(struct kvm_vcpu *vcpu, u64 addr, bool direct) + { + u64 spte; + bool reserved; + + if (mmio_info_in_cache(vcpu, addr, direct)) +- return RET_MMIO_PF_EMULATE; ++ return RET_PF_EMULATE; + + reserved = walk_shadow_page_get_mmio_spte(vcpu, addr, &spte); + if (WARN_ON(reserved)) +- return RET_MMIO_PF_BUG; ++ return -EINVAL; + + if (is_mmio_spte(spte)) { + gfn_t gfn = get_mmio_spte_gfn(spte); + unsigned access = get_mmio_spte_access(spte); + + if (!check_mmio_spte(vcpu, spte)) +- return RET_MMIO_PF_INVALID; ++ return RET_PF_INVALID; + + if (direct) + addr = 0; + + trace_handle_mmio_page_fault(addr, gfn, access); + vcpu_cache_mmio_info(vcpu, addr, gfn, access); +- return RET_MMIO_PF_EMULATE; ++ return RET_PF_EMULATE; + } + + /* + * If the page table is zapped by other cpus, let CPU fault again on + * the address. + */ +- return RET_MMIO_PF_RETRY; ++ return RET_PF_RETRY; + } + EXPORT_SYMBOL_GPL(handle_mmio_page_fault); + +@@ -3756,7 +3753,7 @@ static int nonpaging_page_fault(struct kvm_vcpu *vcpu, gva_t gva, + pgprintk("%s: gva %lx error %x\n", __func__, gva, error_code); + + if (page_fault_handle_page_track(vcpu, error_code, gfn)) +- return 1; ++ return RET_PF_EMULATE; + + r = mmu_topup_memory_caches(vcpu); + if (r) +@@ -3877,7 +3874,7 @@ static int tdp_page_fault(struct kvm_vcpu *vcpu, gva_t gpa, u32 error_code, + MMU_WARN_ON(!VALID_PAGE(vcpu->arch.mmu.root_hpa)); + + if (page_fault_handle_page_track(vcpu, error_code, gfn)) +- return 1; ++ return RET_PF_EMULATE; + + r = mmu_topup_memory_caches(vcpu); + if (r) +@@ -3894,13 +3891,13 @@ static int tdp_page_fault(struct kvm_vcpu *vcpu, gva_t gpa, u32 error_code, + } + + if (fast_page_fault(vcpu, gpa, level, error_code)) +- return 0; ++ return RET_PF_RETRY; + + mmu_seq = vcpu->kvm->mmu_notifier_seq; + smp_rmb(); + + if (try_async_pf(vcpu, prefault, gfn, gpa, &pfn, write, &map_writable)) +- return 0; ++ return RET_PF_RETRY; + + if (handle_abnormal_pfn(vcpu, 0, gfn, pfn, ACC_ALL, &r)) + return r; +@@ -3920,7 +3917,7 @@ static int tdp_page_fault(struct kvm_vcpu *vcpu, gva_t gpa, u32 error_code, + out_unlock: + spin_unlock(&vcpu->kvm->mmu_lock); + kvm_release_pfn_clean(pfn); +- return 0; ++ return RET_PF_RETRY; + } + + static void nonpaging_init_context(struct kvm_vcpu *vcpu, +@@ -4919,25 +4916,25 @@ int kvm_mmu_page_fault(struct kvm_vcpu *vcpu, gva_t cr2, u64 error_code, + vcpu->arch.gpa_val = cr2; + } + ++ r = RET_PF_INVALID; + if (unlikely(error_code & PFERR_RSVD_MASK)) { + r = handle_mmio_page_fault(vcpu, cr2, direct); +- if (r == RET_MMIO_PF_EMULATE) { ++ if (r == RET_PF_EMULATE) { + emulation_type = 0; + goto emulate; + } +- if (r == RET_MMIO_PF_RETRY) +- return 1; +- if (r < 0) +- return r; +- /* Must be RET_MMIO_PF_INVALID. */ + } + +- r = vcpu->arch.mmu.page_fault(vcpu, cr2, lower_32_bits(error_code), +- false); ++ if (r == RET_PF_INVALID) { ++ r = vcpu->arch.mmu.page_fault(vcpu, cr2, lower_32_bits(error_code), ++ false); ++ WARN_ON(r == RET_PF_INVALID); ++ } ++ ++ if (r == RET_PF_RETRY) ++ return 1; + if (r < 0) + return r; +- if (!r) +- return 1; + + /* + * Before emulating the instruction, check if the error code +diff --git a/arch/x86/kvm/paging_tmpl.h b/arch/x86/kvm/paging_tmpl.h +index f18d1f8d332b..5abae72266b7 100644 +--- a/arch/x86/kvm/paging_tmpl.h ++++ b/arch/x86/kvm/paging_tmpl.h +@@ -593,7 +593,7 @@ static int FNAME(fetch)(struct kvm_vcpu *vcpu, gva_t addr, + struct kvm_mmu_page *sp = NULL; + struct kvm_shadow_walk_iterator it; + unsigned direct_access, access = gw->pt_access; +- int top_level, emulate; ++ int top_level, ret; + + direct_access = gw->pte_access; + +@@ -659,15 +659,15 @@ static int FNAME(fetch)(struct kvm_vcpu *vcpu, gva_t addr, + } + + clear_sp_write_flooding_count(it.sptep); +- emulate = mmu_set_spte(vcpu, it.sptep, gw->pte_access, write_fault, +- it.level, gw->gfn, pfn, prefault, map_writable); ++ ret = mmu_set_spte(vcpu, it.sptep, gw->pte_access, write_fault, ++ it.level, gw->gfn, pfn, prefault, map_writable); + FNAME(pte_prefetch)(vcpu, gw, it.sptep); + +- return emulate; ++ return ret; + + out_gpte_changed: + kvm_release_pfn_clean(pfn); +- return 0; ++ return RET_PF_RETRY; + } + + /* +@@ -762,12 +762,12 @@ static int FNAME(page_fault)(struct kvm_vcpu *vcpu, gva_t addr, u32 error_code, + if (!prefault) + inject_page_fault(vcpu, &walker.fault); + +- return 0; ++ return RET_PF_RETRY; + } + + if (page_fault_handle_page_track(vcpu, error_code, walker.gfn)) { + shadow_page_table_clear_flood(vcpu, addr); +- return 1; ++ return RET_PF_EMULATE; + } + + vcpu->arch.write_fault_to_shadow_pgtable = false; +@@ -789,7 +789,7 @@ static int FNAME(page_fault)(struct kvm_vcpu *vcpu, gva_t addr, u32 error_code, + + if (try_async_pf(vcpu, prefault, walker.gfn, addr, &pfn, write_fault, + &map_writable)) +- return 0; ++ return RET_PF_RETRY; + + if (handle_abnormal_pfn(vcpu, addr, walker.gfn, pfn, walker.pte_access, &r)) + return r; +@@ -834,7 +834,7 @@ static int FNAME(page_fault)(struct kvm_vcpu *vcpu, gva_t addr, u32 error_code, + out_unlock: + spin_unlock(&vcpu->kvm->mmu_lock); + kvm_release_pfn_clean(pfn); +- return 0; ++ return RET_PF_RETRY; + } + + static gpa_t FNAME(get_level1_sp_gpa)(struct kvm_mmu_page *sp) +diff --git a/arch/x86/kvm/svm.c b/arch/x86/kvm/svm.c +index e0bc3ad0f6cd..9fb0daf628cb 100644 +--- a/arch/x86/kvm/svm.c ++++ b/arch/x86/kvm/svm.c +@@ -45,6 +45,7 @@ + #include + #include + #include ++#include + #include + + #include +@@ -5015,7 +5016,7 @@ static void svm_vcpu_run(struct kvm_vcpu *vcpu) + * being speculatively taken. + */ + if (svm->spec_ctrl) +- wrmsrl(MSR_IA32_SPEC_CTRL, svm->spec_ctrl); ++ native_wrmsrl(MSR_IA32_SPEC_CTRL, svm->spec_ctrl); + + asm volatile ( + "push %%" _ASM_BP "; \n\t" +@@ -5124,11 +5125,11 @@ static void svm_vcpu_run(struct kvm_vcpu *vcpu) + * If the L02 MSR bitmap does not intercept the MSR, then we need to + * save it. + */ +- if (!msr_write_intercepted(vcpu, MSR_IA32_SPEC_CTRL)) +- rdmsrl(MSR_IA32_SPEC_CTRL, svm->spec_ctrl); ++ if (unlikely(!msr_write_intercepted(vcpu, MSR_IA32_SPEC_CTRL))) ++ svm->spec_ctrl = native_read_msr(MSR_IA32_SPEC_CTRL); + + if (svm->spec_ctrl) +- wrmsrl(MSR_IA32_SPEC_CTRL, 0); ++ native_wrmsrl(MSR_IA32_SPEC_CTRL, 0); + + /* Eliminate branch target predictions from guest mode */ + vmexit_fill_RSB(); +diff --git a/arch/x86/kvm/vmx.c b/arch/x86/kvm/vmx.c +index 5ffde16253cb..315fccb2684b 100644 +--- a/arch/x86/kvm/vmx.c ++++ b/arch/x86/kvm/vmx.c +@@ -51,6 +51,7 @@ + #include + #include + #include ++#include + #include + + #include "trace.h" +@@ -9431,7 +9432,7 @@ static void __noclone vmx_vcpu_run(struct kvm_vcpu *vcpu) + * being speculatively taken. + */ + if (vmx->spec_ctrl) +- wrmsrl(MSR_IA32_SPEC_CTRL, vmx->spec_ctrl); ++ native_wrmsrl(MSR_IA32_SPEC_CTRL, vmx->spec_ctrl); + + vmx->__launched = vmx->loaded_vmcs->launched; + asm( +@@ -9566,11 +9567,11 @@ static void __noclone vmx_vcpu_run(struct kvm_vcpu *vcpu) + * If the L02 MSR bitmap does not intercept the MSR, then we need to + * save it. + */ +- if (!msr_write_intercepted(vcpu, MSR_IA32_SPEC_CTRL)) +- rdmsrl(MSR_IA32_SPEC_CTRL, vmx->spec_ctrl); ++ if (unlikely(!msr_write_intercepted(vcpu, MSR_IA32_SPEC_CTRL))) ++ vmx->spec_ctrl = native_read_msr(MSR_IA32_SPEC_CTRL); + + if (vmx->spec_ctrl) +- wrmsrl(MSR_IA32_SPEC_CTRL, 0); ++ native_wrmsrl(MSR_IA32_SPEC_CTRL, 0); + + /* Eliminate branch target predictions from guest mode */ + vmexit_fill_RSB(); +diff --git a/arch/x86/kvm/x86.c b/arch/x86/kvm/x86.c +index 0dcd7bf45dc1..b9afb4784d12 100644 +--- a/arch/x86/kvm/x86.c ++++ b/arch/x86/kvm/x86.c +@@ -7482,13 +7482,13 @@ EXPORT_SYMBOL_GPL(kvm_task_switch); + + int kvm_valid_sregs(struct kvm_vcpu *vcpu, struct kvm_sregs *sregs) + { +- if ((sregs->efer & EFER_LME) && (sregs->cr0 & X86_CR0_PG_BIT)) { ++ if ((sregs->efer & EFER_LME) && (sregs->cr0 & X86_CR0_PG)) { + /* + * When EFER.LME and CR0.PG are set, the processor is in + * 64-bit mode (though maybe in a 32-bit code segment). + * CR4.PAE and EFER.LMA must be set. + */ +- if (!(sregs->cr4 & X86_CR4_PAE_BIT) ++ if (!(sregs->cr4 & X86_CR4_PAE) + || !(sregs->efer & EFER_LMA)) + return -EINVAL; + } else { +@@ -7821,6 +7821,8 @@ void kvm_arch_vcpu_destroy(struct kvm_vcpu *vcpu) + + void kvm_vcpu_reset(struct kvm_vcpu *vcpu, bool init_event) + { ++ kvm_lapic_reset(vcpu, init_event); ++ + vcpu->arch.hflags = 0; + + vcpu->arch.smi_pending = 0; +@@ -8249,10 +8251,8 @@ int __x86_set_memory_region(struct kvm *kvm, int id, gpa_t gpa, u32 size) + return r; + } + +- if (!size) { +- r = vm_munmap(old.userspace_addr, old.npages * PAGE_SIZE); +- WARN_ON(r < 0); +- } ++ if (!size) ++ vm_munmap(old.userspace_addr, old.npages * PAGE_SIZE); + + return 0; + } +diff --git a/arch/x86/mm/cpu_entry_area.c b/arch/x86/mm/cpu_entry_area.c +index b9283cc27622..476d810639a8 100644 +--- a/arch/x86/mm/cpu_entry_area.c ++++ b/arch/x86/mm/cpu_entry_area.c +@@ -163,4 +163,10 @@ void __init setup_cpu_entry_areas(void) + + for_each_possible_cpu(cpu) + setup_cpu_entry_area(cpu); ++ ++ /* ++ * This is the last essential update to swapper_pgdir which needs ++ * to be synchronized to initial_page_table on 32bit. ++ */ ++ sync_initial_page_table(); + } +diff --git a/arch/x86/mm/init_32.c b/arch/x86/mm/init_32.c +index 135c9a7898c7..3141e67ec24c 100644 +--- a/arch/x86/mm/init_32.c ++++ b/arch/x86/mm/init_32.c +@@ -453,6 +453,21 @@ static inline void permanent_kmaps_init(pgd_t *pgd_base) + } + #endif /* CONFIG_HIGHMEM */ + ++void __init sync_initial_page_table(void) ++{ ++ clone_pgd_range(initial_page_table + KERNEL_PGD_BOUNDARY, ++ swapper_pg_dir + KERNEL_PGD_BOUNDARY, ++ KERNEL_PGD_PTRS); ++ ++ /* ++ * sync back low identity map too. It is used for example ++ * in the 32-bit EFI stub. ++ */ ++ clone_pgd_range(initial_page_table, ++ swapper_pg_dir + KERNEL_PGD_BOUNDARY, ++ min(KERNEL_PGD_PTRS, KERNEL_PGD_BOUNDARY)); ++} ++ + void __init native_pagetable_init(void) + { + unsigned long pfn, va; +diff --git a/arch/x86/platform/intel-mid/intel-mid.c b/arch/x86/platform/intel-mid/intel-mid.c +index 86676cec99a1..09dd7f3cf621 100644 +--- a/arch/x86/platform/intel-mid/intel-mid.c ++++ b/arch/x86/platform/intel-mid/intel-mid.c +@@ -79,7 +79,7 @@ static void intel_mid_power_off(void) + + static void intel_mid_reboot(void) + { +- intel_scu_ipc_simple_command(IPCMSG_COLD_BOOT, 0); ++ intel_scu_ipc_simple_command(IPCMSG_COLD_RESET, 0); + } + + static unsigned long __init intel_mid_calibrate_tsc(void) +diff --git a/arch/x86/xen/suspend.c b/arch/x86/xen/suspend.c +index 92bf5ecb6baf..3e3a58ea669e 100644 +--- a/arch/x86/xen/suspend.c ++++ b/arch/x86/xen/suspend.c +@@ -1,12 +1,15 @@ + // SPDX-License-Identifier: GPL-2.0 + #include + #include ++#include + + #include + #include + #include + #include + ++#include ++#include + #include + #include + #include +@@ -15,6 +18,8 @@ + #include "mmu.h" + #include "pmu.h" + ++static DEFINE_PER_CPU(u64, spec_ctrl); ++ + void xen_arch_pre_suspend(void) + { + if (xen_pv_domain()) +@@ -31,6 +36,9 @@ void xen_arch_post_suspend(int cancelled) + + static void xen_vcpu_notify_restore(void *data) + { ++ if (xen_pv_domain() && boot_cpu_has(X86_FEATURE_SPEC_CTRL)) ++ wrmsrl(MSR_IA32_SPEC_CTRL, this_cpu_read(spec_ctrl)); ++ + /* Boot processor notified via generic timekeeping_resume() */ + if (smp_processor_id() == 0) + return; +@@ -40,7 +48,15 @@ static void xen_vcpu_notify_restore(void *data) + + static void xen_vcpu_notify_suspend(void *data) + { ++ u64 tmp; ++ + tick_suspend_local(); ++ ++ if (xen_pv_domain() && boot_cpu_has(X86_FEATURE_SPEC_CTRL)) { ++ rdmsrl(MSR_IA32_SPEC_CTRL, tmp); ++ this_cpu_write(spec_ctrl, tmp); ++ wrmsrl(MSR_IA32_SPEC_CTRL, 0); ++ } + } + + void xen_arch_resume(void) +diff --git a/block/blk-core.c b/block/blk-core.c +index 95b7ea996ac2..c01f4907dbbc 100644 +--- a/block/blk-core.c ++++ b/block/blk-core.c +@@ -2277,7 +2277,7 @@ blk_qc_t submit_bio(struct bio *bio) + unsigned int count; + + if (unlikely(bio_op(bio) == REQ_OP_WRITE_SAME)) +- count = queue_logical_block_size(bio->bi_disk->queue); ++ count = queue_logical_block_size(bio->bi_disk->queue) >> 9; + else + count = bio_sectors(bio); + +diff --git a/block/blk-mq.c b/block/blk-mq.c +index b60798a30ea2..f1fb126a3be5 100644 +--- a/block/blk-mq.c ++++ b/block/blk-mq.c +@@ -638,7 +638,6 @@ static void __blk_mq_requeue_request(struct request *rq) + + trace_block_rq_requeue(q, rq); + wbt_requeue(q->rq_wb, &rq->issue_stat); +- blk_mq_sched_requeue_request(rq); + + if (test_and_clear_bit(REQ_ATOM_STARTED, &rq->atomic_flags)) { + if (q->dma_drain_size && blk_rq_bytes(rq)) +@@ -650,6 +649,9 @@ void blk_mq_requeue_request(struct request *rq, bool kick_requeue_list) + { + __blk_mq_requeue_request(rq); + ++ /* this request will be re-inserted to io scheduler queue */ ++ blk_mq_sched_requeue_request(rq); ++ + BUG_ON(blk_queued_rq(rq)); + blk_mq_add_to_requeue_list(rq, true, kick_requeue_list); + } +diff --git a/block/kyber-iosched.c b/block/kyber-iosched.c +index f58cab82105b..09cd5cf2e459 100644 +--- a/block/kyber-iosched.c ++++ b/block/kyber-iosched.c +@@ -814,6 +814,7 @@ static struct elevator_type kyber_sched = { + .limit_depth = kyber_limit_depth, + .prepare_request = kyber_prepare_request, + .finish_request = kyber_finish_request, ++ .requeue_request = kyber_finish_request, + .completed_request = kyber_completed_request, + .dispatch_request = kyber_dispatch_request, + .has_work = kyber_has_work, +diff --git a/drivers/acpi/bus.c b/drivers/acpi/bus.c +index 4d0979e02a28..b6d58cc58f5f 100644 +--- a/drivers/acpi/bus.c ++++ b/drivers/acpi/bus.c +@@ -66,10 +66,37 @@ static int set_copy_dsdt(const struct dmi_system_id *id) + return 0; + } + #endif ++static int set_gbl_term_list(const struct dmi_system_id *id) ++{ ++ acpi_gbl_parse_table_as_term_list = 1; ++ return 0; ++} + +-static const struct dmi_system_id dsdt_dmi_table[] __initconst = { ++static const struct dmi_system_id acpi_quirks_dmi_table[] __initconst = { ++ /* ++ * Touchpad on Dell XPS 9570/Precision M5530 doesn't work under I2C ++ * mode. ++ * https://bugzilla.kernel.org/show_bug.cgi?id=198515 ++ */ ++ { ++ .callback = set_gbl_term_list, ++ .ident = "Dell Precision M5530", ++ .matches = { ++ DMI_MATCH(DMI_SYS_VENDOR, "Dell Inc."), ++ DMI_MATCH(DMI_PRODUCT_NAME, "Precision M5530"), ++ }, ++ }, ++ { ++ .callback = set_gbl_term_list, ++ .ident = "Dell XPS 15 9570", ++ .matches = { ++ DMI_MATCH(DMI_SYS_VENDOR, "Dell Inc."), ++ DMI_MATCH(DMI_PRODUCT_NAME, "XPS 15 9570"), ++ }, ++ }, + /* + * Invoke DSDT corruption work-around on all Toshiba Satellite. ++ * DSDT will be copied to memory. + * https://bugzilla.kernel.org/show_bug.cgi?id=14679 + */ + { +@@ -83,7 +110,7 @@ static const struct dmi_system_id dsdt_dmi_table[] __initconst = { + {} + }; + #else +-static const struct dmi_system_id dsdt_dmi_table[] __initconst = { ++static const struct dmi_system_id acpi_quirks_dmi_table[] __initconst = { + {} + }; + #endif +@@ -1001,11 +1028,8 @@ void __init acpi_early_init(void) + + acpi_permanent_mmap = true; + +- /* +- * If the machine falls into the DMI check table, +- * DSDT will be copied to memory +- */ +- dmi_check_system(dsdt_dmi_table); ++ /* Check machine-specific quirks */ ++ dmi_check_system(acpi_quirks_dmi_table); + + status = acpi_reallocate_root_table(); + if (ACPI_FAILURE(status)) { +diff --git a/drivers/bluetooth/btusb.c b/drivers/bluetooth/btusb.c +index d54c3f6f728c..673698c7b143 100644 +--- a/drivers/bluetooth/btusb.c ++++ b/drivers/bluetooth/btusb.c +@@ -21,6 +21,7 @@ + * + */ + ++#include + #include + #include + #include +@@ -381,6 +382,21 @@ static const struct usb_device_id blacklist_table[] = { + { } /* Terminating entry */ + }; + ++/* The Bluetooth USB module build into some devices needs to be reset on resume, ++ * this is a problem with the platform (likely shutting off all power) not with ++ * the module itself. So we use a DMI list to match known broken platforms. ++ */ ++static const struct dmi_system_id btusb_needs_reset_resume_table[] = { ++ { ++ /* Lenovo Yoga 920 (QCA Rome device 0cf3:e300) */ ++ .matches = { ++ DMI_MATCH(DMI_SYS_VENDOR, "LENOVO"), ++ DMI_MATCH(DMI_PRODUCT_VERSION, "Lenovo YOGA 920"), ++ }, ++ }, ++ {} ++}; ++ + #define BTUSB_MAX_ISOC_FRAMES 10 + + #define BTUSB_INTR_RUNNING 0 +@@ -3013,6 +3029,9 @@ static int btusb_probe(struct usb_interface *intf, + hdev->send = btusb_send_frame; + hdev->notify = btusb_notify; + ++ if (dmi_check_system(btusb_needs_reset_resume_table)) ++ interface_to_usbdev(intf)->quirks |= USB_QUIRK_RESET_RESUME; ++ + #ifdef CONFIG_PM + err = btusb_config_oob_wake(hdev); + if (err) +@@ -3099,12 +3118,6 @@ static int btusb_probe(struct usb_interface *intf, + if (id->driver_info & BTUSB_QCA_ROME) { + data->setup_on_usb = btusb_setup_qca; + hdev->set_bdaddr = btusb_set_bdaddr_ath3012; +- +- /* QCA Rome devices lose their updated firmware over suspend, +- * but the USB hub doesn't notice any status change. +- * explicitly request a device reset on resume. +- */ +- interface_to_usbdev(intf)->quirks |= USB_QUIRK_RESET_RESUME; + } + + #ifdef CONFIG_BT_HCIBTUSB_RTL +diff --git a/drivers/char/tpm/st33zp24/st33zp24.c b/drivers/char/tpm/st33zp24/st33zp24.c +index 4d1dc8b46877..f95b9c75175b 100644 +--- a/drivers/char/tpm/st33zp24/st33zp24.c ++++ b/drivers/char/tpm/st33zp24/st33zp24.c +@@ -457,7 +457,7 @@ static int st33zp24_recv(struct tpm_chip *chip, unsigned char *buf, + size_t count) + { + int size = 0; +- int expected; ++ u32 expected; + + if (!chip) + return -EBUSY; +@@ -474,7 +474,7 @@ static int st33zp24_recv(struct tpm_chip *chip, unsigned char *buf, + } + + expected = be32_to_cpu(*(__be32 *)(buf + 2)); +- if (expected > count) { ++ if (expected > count || expected < TPM_HEADER_SIZE) { + size = -EIO; + goto out; + } +diff --git a/drivers/char/tpm/tpm-interface.c b/drivers/char/tpm/tpm-interface.c +index 1d6729be4cd6..3cec403a80b3 100644 +--- a/drivers/char/tpm/tpm-interface.c ++++ b/drivers/char/tpm/tpm-interface.c +@@ -1228,6 +1228,10 @@ int tpm_get_random(u32 chip_num, u8 *out, size_t max) + break; + + recd = be32_to_cpu(tpm_cmd.params.getrandom_out.rng_data_len); ++ if (recd > num_bytes) { ++ total = -EFAULT; ++ break; ++ } + + rlength = be32_to_cpu(tpm_cmd.header.out.length); + if (rlength < offsetof(struct tpm_getrandom_out, rng_data) + +diff --git a/drivers/char/tpm/tpm2-cmd.c b/drivers/char/tpm/tpm2-cmd.c +index e1a41b788f08..44a3d16231f6 100644 +--- a/drivers/char/tpm/tpm2-cmd.c ++++ b/drivers/char/tpm/tpm2-cmd.c +@@ -683,6 +683,10 @@ static int tpm2_unseal_cmd(struct tpm_chip *chip, + if (!rc) { + data_len = be16_to_cpup( + (__be16 *) &buf.data[TPM_HEADER_SIZE + 4]); ++ if (data_len < MIN_KEY_SIZE || data_len > MAX_KEY_SIZE + 1) { ++ rc = -EFAULT; ++ goto out; ++ } + + rlength = be32_to_cpu(((struct tpm2_cmd *)&buf) + ->header.out.length); +diff --git a/drivers/char/tpm/tpm_i2c_infineon.c b/drivers/char/tpm/tpm_i2c_infineon.c +index 79d6bbb58e39..d5b44cadac56 100644 +--- a/drivers/char/tpm/tpm_i2c_infineon.c ++++ b/drivers/char/tpm/tpm_i2c_infineon.c +@@ -473,7 +473,8 @@ static int recv_data(struct tpm_chip *chip, u8 *buf, size_t count) + static int tpm_tis_i2c_recv(struct tpm_chip *chip, u8 *buf, size_t count) + { + int size = 0; +- int expected, status; ++ int status; ++ u32 expected; + + if (count < TPM_HEADER_SIZE) { + size = -EIO; +@@ -488,7 +489,7 @@ static int tpm_tis_i2c_recv(struct tpm_chip *chip, u8 *buf, size_t count) + } + + expected = be32_to_cpu(*(__be32 *)(buf + 2)); +- if ((size_t) expected > count) { ++ if (((size_t) expected > count) || (expected < TPM_HEADER_SIZE)) { + size = -EIO; + goto out; + } +diff --git a/drivers/char/tpm/tpm_i2c_nuvoton.c b/drivers/char/tpm/tpm_i2c_nuvoton.c +index c6428771841f..caa86b19c76d 100644 +--- a/drivers/char/tpm/tpm_i2c_nuvoton.c ++++ b/drivers/char/tpm/tpm_i2c_nuvoton.c +@@ -281,7 +281,11 @@ static int i2c_nuvoton_recv(struct tpm_chip *chip, u8 *buf, size_t count) + struct device *dev = chip->dev.parent; + struct i2c_client *client = to_i2c_client(dev); + s32 rc; +- int expected, status, burst_count, retries, size = 0; ++ int status; ++ int burst_count; ++ int retries; ++ int size = 0; ++ u32 expected; + + if (count < TPM_HEADER_SIZE) { + i2c_nuvoton_ready(chip); /* return to idle */ +@@ -323,7 +327,7 @@ static int i2c_nuvoton_recv(struct tpm_chip *chip, u8 *buf, size_t count) + * to machine native + */ + expected = be32_to_cpu(*(__be32 *) (buf + 2)); +- if (expected > count) { ++ if (expected > count || expected < size) { + dev_err(dev, "%s() expected > count\n", __func__); + size = -EIO; + continue; +diff --git a/drivers/char/tpm/tpm_tis.c b/drivers/char/tpm/tpm_tis.c +index 7e55aa9ce680..ebd0e75a3e4d 100644 +--- a/drivers/char/tpm/tpm_tis.c ++++ b/drivers/char/tpm/tpm_tis.c +@@ -223,7 +223,7 @@ static int tpm_tcg_read_bytes(struct tpm_tis_data *data, u32 addr, u16 len, + } + + static int tpm_tcg_write_bytes(struct tpm_tis_data *data, u32 addr, u16 len, +- u8 *value) ++ const u8 *value) + { + struct tpm_tis_tcg_phy *phy = to_tpm_tis_tcg_phy(data); + +diff --git a/drivers/char/tpm/tpm_tis_core.c b/drivers/char/tpm/tpm_tis_core.c +index 63bc6c3b949e..083578b2517e 100644 +--- a/drivers/char/tpm/tpm_tis_core.c ++++ b/drivers/char/tpm/tpm_tis_core.c +@@ -202,7 +202,8 @@ static int tpm_tis_recv(struct tpm_chip *chip, u8 *buf, size_t count) + { + struct tpm_tis_data *priv = dev_get_drvdata(&chip->dev); + int size = 0; +- int expected, status; ++ int status; ++ u32 expected; + + if (count < TPM_HEADER_SIZE) { + size = -EIO; +@@ -217,7 +218,7 @@ static int tpm_tis_recv(struct tpm_chip *chip, u8 *buf, size_t count) + } + + expected = be32_to_cpu(*(__be32 *) (buf + 2)); +- if (expected > count) { ++ if (expected > count || expected < TPM_HEADER_SIZE) { + size = -EIO; + goto out; + } +@@ -252,7 +253,7 @@ static int tpm_tis_recv(struct tpm_chip *chip, u8 *buf, size_t count) + * tpm.c can skip polling for the data to be available as the interrupt is + * waited for here + */ +-static int tpm_tis_send_data(struct tpm_chip *chip, u8 *buf, size_t len) ++static int tpm_tis_send_data(struct tpm_chip *chip, const u8 *buf, size_t len) + { + struct tpm_tis_data *priv = dev_get_drvdata(&chip->dev); + int rc, status, burstcnt; +@@ -343,7 +344,7 @@ static void disable_interrupts(struct tpm_chip *chip) + * tpm.c can skip polling for the data to be available as the interrupt is + * waited for here + */ +-static int tpm_tis_send_main(struct tpm_chip *chip, u8 *buf, size_t len) ++static int tpm_tis_send_main(struct tpm_chip *chip, const u8 *buf, size_t len) + { + struct tpm_tis_data *priv = dev_get_drvdata(&chip->dev); + int rc; +diff --git a/drivers/char/tpm/tpm_tis_core.h b/drivers/char/tpm/tpm_tis_core.h +index e2212f021a02..6bbac319ff3b 100644 +--- a/drivers/char/tpm/tpm_tis_core.h ++++ b/drivers/char/tpm/tpm_tis_core.h +@@ -98,7 +98,7 @@ struct tpm_tis_phy_ops { + int (*read_bytes)(struct tpm_tis_data *data, u32 addr, u16 len, + u8 *result); + int (*write_bytes)(struct tpm_tis_data *data, u32 addr, u16 len, +- u8 *value); ++ const u8 *value); + int (*read16)(struct tpm_tis_data *data, u32 addr, u16 *result); + int (*read32)(struct tpm_tis_data *data, u32 addr, u32 *result); + int (*write32)(struct tpm_tis_data *data, u32 addr, u32 src); +@@ -128,7 +128,7 @@ static inline int tpm_tis_read32(struct tpm_tis_data *data, u32 addr, + } + + static inline int tpm_tis_write_bytes(struct tpm_tis_data *data, u32 addr, +- u16 len, u8 *value) ++ u16 len, const u8 *value) + { + return data->phy_ops->write_bytes(data, addr, len, value); + } +diff --git a/drivers/char/tpm/tpm_tis_spi.c b/drivers/char/tpm/tpm_tis_spi.c +index 88fe72ae967f..8ab0bd8445f6 100644 +--- a/drivers/char/tpm/tpm_tis_spi.c ++++ b/drivers/char/tpm/tpm_tis_spi.c +@@ -46,9 +46,7 @@ + struct tpm_tis_spi_phy { + struct tpm_tis_data priv; + struct spi_device *spi_device; +- +- u8 tx_buf[4]; +- u8 rx_buf[4]; ++ u8 *iobuf; + }; + + static inline struct tpm_tis_spi_phy *to_tpm_tis_spi_phy(struct tpm_tis_data *data) +@@ -57,7 +55,7 @@ static inline struct tpm_tis_spi_phy *to_tpm_tis_spi_phy(struct tpm_tis_data *da + } + + static int tpm_tis_spi_transfer(struct tpm_tis_data *data, u32 addr, u16 len, +- u8 *buffer, u8 direction) ++ u8 *in, const u8 *out) + { + struct tpm_tis_spi_phy *phy = to_tpm_tis_spi_phy(data); + int ret = 0; +@@ -71,14 +69,14 @@ static int tpm_tis_spi_transfer(struct tpm_tis_data *data, u32 addr, u16 len, + while (len) { + transfer_len = min_t(u16, len, MAX_SPI_FRAMESIZE); + +- phy->tx_buf[0] = direction | (transfer_len - 1); +- phy->tx_buf[1] = 0xd4; +- phy->tx_buf[2] = addr >> 8; +- phy->tx_buf[3] = addr; ++ phy->iobuf[0] = (in ? 0x80 : 0) | (transfer_len - 1); ++ phy->iobuf[1] = 0xd4; ++ phy->iobuf[2] = addr >> 8; ++ phy->iobuf[3] = addr; + + memset(&spi_xfer, 0, sizeof(spi_xfer)); +- spi_xfer.tx_buf = phy->tx_buf; +- spi_xfer.rx_buf = phy->rx_buf; ++ spi_xfer.tx_buf = phy->iobuf; ++ spi_xfer.rx_buf = phy->iobuf; + spi_xfer.len = 4; + spi_xfer.cs_change = 1; + +@@ -88,9 +86,9 @@ static int tpm_tis_spi_transfer(struct tpm_tis_data *data, u32 addr, u16 len, + if (ret < 0) + goto exit; + +- if ((phy->rx_buf[3] & 0x01) == 0) { ++ if ((phy->iobuf[3] & 0x01) == 0) { + // handle SPI wait states +- phy->tx_buf[0] = 0; ++ phy->iobuf[0] = 0; + + for (i = 0; i < TPM_RETRY; i++) { + spi_xfer.len = 1; +@@ -99,7 +97,7 @@ static int tpm_tis_spi_transfer(struct tpm_tis_data *data, u32 addr, u16 len, + ret = spi_sync_locked(phy->spi_device, &m); + if (ret < 0) + goto exit; +- if (phy->rx_buf[0] & 0x01) ++ if (phy->iobuf[0] & 0x01) + break; + } + +@@ -113,12 +111,12 @@ static int tpm_tis_spi_transfer(struct tpm_tis_data *data, u32 addr, u16 len, + spi_xfer.len = transfer_len; + spi_xfer.delay_usecs = 5; + +- if (direction) { ++ if (in) { + spi_xfer.tx_buf = NULL; +- spi_xfer.rx_buf = buffer; +- } else { +- spi_xfer.tx_buf = buffer; ++ } else if (out) { + spi_xfer.rx_buf = NULL; ++ memcpy(phy->iobuf, out, transfer_len); ++ out += transfer_len; + } + + spi_message_init(&m); +@@ -127,8 +125,12 @@ static int tpm_tis_spi_transfer(struct tpm_tis_data *data, u32 addr, u16 len, + if (ret < 0) + goto exit; + ++ if (in) { ++ memcpy(in, phy->iobuf, transfer_len); ++ in += transfer_len; ++ } ++ + len -= transfer_len; +- buffer += transfer_len; + } + + exit: +@@ -139,13 +141,13 @@ static int tpm_tis_spi_transfer(struct tpm_tis_data *data, u32 addr, u16 len, + static int tpm_tis_spi_read_bytes(struct tpm_tis_data *data, u32 addr, + u16 len, u8 *result) + { +- return tpm_tis_spi_transfer(data, addr, len, result, 0x80); ++ return tpm_tis_spi_transfer(data, addr, len, result, NULL); + } + + static int tpm_tis_spi_write_bytes(struct tpm_tis_data *data, u32 addr, +- u16 len, u8 *value) ++ u16 len, const u8 *value) + { +- return tpm_tis_spi_transfer(data, addr, len, value, 0); ++ return tpm_tis_spi_transfer(data, addr, len, NULL, value); + } + + static int tpm_tis_spi_read16(struct tpm_tis_data *data, u32 addr, u16 *result) +@@ -194,6 +196,10 @@ static int tpm_tis_spi_probe(struct spi_device *dev) + + phy->spi_device = dev; + ++ phy->iobuf = devm_kmalloc(&dev->dev, MAX_SPI_FRAMESIZE, GFP_KERNEL); ++ if (!phy->iobuf) ++ return -ENOMEM; ++ + return tpm_tis_core_init(&dev->dev, &phy->priv, -1, &tpm_spi_phy_ops, + NULL); + } +diff --git a/drivers/cpufreq/s3c24xx-cpufreq.c b/drivers/cpufreq/s3c24xx-cpufreq.c +index 7b596fa38ad2..6bebc1f9f55a 100644 +--- a/drivers/cpufreq/s3c24xx-cpufreq.c ++++ b/drivers/cpufreq/s3c24xx-cpufreq.c +@@ -351,7 +351,13 @@ struct clk *s3c_cpufreq_clk_get(struct device *dev, const char *name) + static int s3c_cpufreq_init(struct cpufreq_policy *policy) + { + policy->clk = clk_arm; +- return cpufreq_generic_init(policy, ftab, cpu_cur.info->latency); ++ ++ policy->cpuinfo.transition_latency = cpu_cur.info->latency; ++ ++ if (ftab) ++ return cpufreq_table_validate_and_show(policy, ftab); ++ ++ return 0; + } + + static int __init s3c_cpufreq_initclks(void) +diff --git a/drivers/edac/sb_edac.c b/drivers/edac/sb_edac.c +index cd9d6ba03579..0dc0d595c47c 100644 +--- a/drivers/edac/sb_edac.c ++++ b/drivers/edac/sb_edac.c +@@ -279,7 +279,7 @@ static const u32 correrrthrsld[] = { + * sbridge structs + */ + +-#define NUM_CHANNELS 4 /* Max channels per MC */ ++#define NUM_CHANNELS 6 /* Max channels per MC */ + #define MAX_DIMMS 3 /* Max DIMMS per channel */ + #define KNL_MAX_CHAS 38 /* KNL max num. of Cache Home Agents */ + #define KNL_MAX_CHANNELS 6 /* KNL max num. of PCI channels */ +diff --git a/drivers/md/md.c b/drivers/md/md.c +index 6bf093cef958..e058c209bbcf 100644 +--- a/drivers/md/md.c ++++ b/drivers/md/md.c +@@ -8522,6 +8522,10 @@ static int remove_and_add_spares(struct mddev *mddev, + int removed = 0; + bool remove_some = false; + ++ if (this && test_bit(MD_RECOVERY_RUNNING, &mddev->recovery)) ++ /* Mustn't remove devices when resync thread is running */ ++ return 0; ++ + rdev_for_each(rdev, mddev) { + if ((this == NULL || rdev == this) && + rdev->raid_disk >= 0 && +diff --git a/drivers/media/dvb-frontends/m88ds3103.c b/drivers/media/dvb-frontends/m88ds3103.c +index 50bce68ffd66..65d157fe76d1 100644 +--- a/drivers/media/dvb-frontends/m88ds3103.c ++++ b/drivers/media/dvb-frontends/m88ds3103.c +@@ -1262,11 +1262,12 @@ static int m88ds3103_select(struct i2c_mux_core *muxc, u32 chan) + * New users must use I2C client binding directly! + */ + struct dvb_frontend *m88ds3103_attach(const struct m88ds3103_config *cfg, +- struct i2c_adapter *i2c, struct i2c_adapter **tuner_i2c_adapter) ++ struct i2c_adapter *i2c, ++ struct i2c_adapter **tuner_i2c_adapter) + { + struct i2c_client *client; + struct i2c_board_info board_info; +- struct m88ds3103_platform_data pdata; ++ struct m88ds3103_platform_data pdata = {}; + + pdata.clk = cfg->clock; + pdata.i2c_wr_max = cfg->i2c_wr_max; +@@ -1409,6 +1410,8 @@ static int m88ds3103_probe(struct i2c_client *client, + case M88DS3103_CHIP_ID: + break; + default: ++ ret = -ENODEV; ++ dev_err(&client->dev, "Unknown device. Chip_id=%02x\n", dev->chip_id); + goto err_kfree; + } + +diff --git a/drivers/mmc/host/dw_mmc-exynos.c b/drivers/mmc/host/dw_mmc-exynos.c +index 35026795be28..fa41d9422d57 100644 +--- a/drivers/mmc/host/dw_mmc-exynos.c ++++ b/drivers/mmc/host/dw_mmc-exynos.c +@@ -487,6 +487,7 @@ static unsigned long exynos_dwmmc_caps[4] = { + + static const struct dw_mci_drv_data exynos_drv_data = { + .caps = exynos_dwmmc_caps, ++ .num_caps = ARRAY_SIZE(exynos_dwmmc_caps), + .init = dw_mci_exynos_priv_init, + .set_ios = dw_mci_exynos_set_ios, + .parse_dt = dw_mci_exynos_parse_dt, +diff --git a/drivers/mmc/host/dw_mmc-k3.c b/drivers/mmc/host/dw_mmc-k3.c +index 64cda84b2302..864e7fcaffaf 100644 +--- a/drivers/mmc/host/dw_mmc-k3.c ++++ b/drivers/mmc/host/dw_mmc-k3.c +@@ -135,6 +135,9 @@ static int dw_mci_hi6220_parse_dt(struct dw_mci *host) + if (priv->ctrl_id < 0) + priv->ctrl_id = 0; + ++ if (priv->ctrl_id >= TIMING_MODE) ++ return -EINVAL; ++ + host->priv = priv; + return 0; + } +@@ -207,6 +210,7 @@ static int dw_mci_hi6220_execute_tuning(struct dw_mci_slot *slot, u32 opcode) + + static const struct dw_mci_drv_data hi6220_data = { + .caps = dw_mci_hi6220_caps, ++ .num_caps = ARRAY_SIZE(dw_mci_hi6220_caps), + .switch_voltage = dw_mci_hi6220_switch_voltage, + .set_ios = dw_mci_hi6220_set_ios, + .parse_dt = dw_mci_hi6220_parse_dt, +diff --git a/drivers/mmc/host/dw_mmc-rockchip.c b/drivers/mmc/host/dw_mmc-rockchip.c +index a3f1c2b30145..339295212935 100644 +--- a/drivers/mmc/host/dw_mmc-rockchip.c ++++ b/drivers/mmc/host/dw_mmc-rockchip.c +@@ -319,6 +319,7 @@ static const struct dw_mci_drv_data rk2928_drv_data = { + + static const struct dw_mci_drv_data rk3288_drv_data = { + .caps = dw_mci_rk3288_dwmmc_caps, ++ .num_caps = ARRAY_SIZE(dw_mci_rk3288_dwmmc_caps), + .set_ios = dw_mci_rk3288_set_ios, + .execute_tuning = dw_mci_rk3288_execute_tuning, + .parse_dt = dw_mci_rk3288_parse_dt, +diff --git a/drivers/mmc/host/dw_mmc-zx.c b/drivers/mmc/host/dw_mmc-zx.c +index d38e94ae2b85..c06b5393312f 100644 +--- a/drivers/mmc/host/dw_mmc-zx.c ++++ b/drivers/mmc/host/dw_mmc-zx.c +@@ -195,6 +195,7 @@ static unsigned long zx_dwmmc_caps[3] = { + + static const struct dw_mci_drv_data zx_drv_data = { + .caps = zx_dwmmc_caps, ++ .num_caps = ARRAY_SIZE(zx_dwmmc_caps), + .execute_tuning = dw_mci_zx_execute_tuning, + .prepare_hs400_tuning = dw_mci_zx_prepare_hs400_tuning, + .parse_dt = dw_mci_zx_parse_dt, +diff --git a/drivers/mmc/host/dw_mmc.c b/drivers/mmc/host/dw_mmc.c +index 4f2806720c5c..60341a814055 100644 +--- a/drivers/mmc/host/dw_mmc.c ++++ b/drivers/mmc/host/dw_mmc.c +@@ -165,6 +165,8 @@ static int dw_mci_regs_show(struct seq_file *s, void *v) + { + struct dw_mci *host = s->private; + ++ pm_runtime_get_sync(host->dev); ++ + seq_printf(s, "STATUS:\t0x%08x\n", mci_readl(host, STATUS)); + seq_printf(s, "RINTSTS:\t0x%08x\n", mci_readl(host, RINTSTS)); + seq_printf(s, "CMD:\t0x%08x\n", mci_readl(host, CMD)); +@@ -172,6 +174,8 @@ static int dw_mci_regs_show(struct seq_file *s, void *v) + seq_printf(s, "INTMASK:\t0x%08x\n", mci_readl(host, INTMASK)); + seq_printf(s, "CLKENA:\t0x%08x\n", mci_readl(host, CLKENA)); + ++ pm_runtime_put_autosuspend(host->dev); ++ + return 0; + } + +@@ -2758,12 +2762,57 @@ static irqreturn_t dw_mci_interrupt(int irq, void *dev_id) + return IRQ_HANDLED; + } + ++static int dw_mci_init_slot_caps(struct dw_mci_slot *slot) ++{ ++ struct dw_mci *host = slot->host; ++ const struct dw_mci_drv_data *drv_data = host->drv_data; ++ struct mmc_host *mmc = slot->mmc; ++ int ctrl_id; ++ ++ if (host->pdata->caps) ++ mmc->caps = host->pdata->caps; ++ ++ /* ++ * Support MMC_CAP_ERASE by default. ++ * It needs to use trim/discard/erase commands. ++ */ ++ mmc->caps |= MMC_CAP_ERASE; ++ ++ if (host->pdata->pm_caps) ++ mmc->pm_caps = host->pdata->pm_caps; ++ ++ if (host->dev->of_node) { ++ ctrl_id = of_alias_get_id(host->dev->of_node, "mshc"); ++ if (ctrl_id < 0) ++ ctrl_id = 0; ++ } else { ++ ctrl_id = to_platform_device(host->dev)->id; ++ } ++ ++ if (drv_data && drv_data->caps) { ++ if (ctrl_id >= drv_data->num_caps) { ++ dev_err(host->dev, "invalid controller id %d\n", ++ ctrl_id); ++ return -EINVAL; ++ } ++ mmc->caps |= drv_data->caps[ctrl_id]; ++ } ++ ++ if (host->pdata->caps2) ++ mmc->caps2 = host->pdata->caps2; ++ ++ /* Process SDIO IRQs through the sdio_irq_work. */ ++ if (mmc->caps & MMC_CAP_SDIO_IRQ) ++ mmc->caps2 |= MMC_CAP2_SDIO_IRQ_NOTHREAD; ++ ++ return 0; ++} ++ + static int dw_mci_init_slot(struct dw_mci *host) + { + struct mmc_host *mmc; + struct dw_mci_slot *slot; +- const struct dw_mci_drv_data *drv_data = host->drv_data; +- int ctrl_id, ret; ++ int ret; + u32 freq[2]; + + mmc = mmc_alloc_host(sizeof(struct dw_mci_slot), host->dev); +@@ -2797,38 +2846,13 @@ static int dw_mci_init_slot(struct dw_mci *host) + if (!mmc->ocr_avail) + mmc->ocr_avail = MMC_VDD_32_33 | MMC_VDD_33_34; + +- if (host->pdata->caps) +- mmc->caps = host->pdata->caps; +- +- /* +- * Support MMC_CAP_ERASE by default. +- * It needs to use trim/discard/erase commands. +- */ +- mmc->caps |= MMC_CAP_ERASE; +- +- if (host->pdata->pm_caps) +- mmc->pm_caps = host->pdata->pm_caps; +- +- if (host->dev->of_node) { +- ctrl_id = of_alias_get_id(host->dev->of_node, "mshc"); +- if (ctrl_id < 0) +- ctrl_id = 0; +- } else { +- ctrl_id = to_platform_device(host->dev)->id; +- } +- if (drv_data && drv_data->caps) +- mmc->caps |= drv_data->caps[ctrl_id]; +- +- if (host->pdata->caps2) +- mmc->caps2 = host->pdata->caps2; +- + ret = mmc_of_parse(mmc); + if (ret) + goto err_host_allocated; + +- /* Process SDIO IRQs through the sdio_irq_work. */ +- if (mmc->caps & MMC_CAP_SDIO_IRQ) +- mmc->caps2 |= MMC_CAP2_SDIO_IRQ_NOTHREAD; ++ ret = dw_mci_init_slot_caps(slot); ++ if (ret) ++ goto err_host_allocated; + + /* Useful defaults if platform data is unset. */ + if (host->use_dma == TRANS_MODE_IDMAC) { +diff --git a/drivers/mmc/host/dw_mmc.h b/drivers/mmc/host/dw_mmc.h +index 34474ad731aa..044c87ce6725 100644 +--- a/drivers/mmc/host/dw_mmc.h ++++ b/drivers/mmc/host/dw_mmc.h +@@ -542,6 +542,7 @@ struct dw_mci_slot { + /** + * dw_mci driver data - dw-mshc implementation specific driver data. + * @caps: mmc subsystem specified capabilities of the controller(s). ++ * @num_caps: number of capabilities specified by @caps. + * @init: early implementation specific initialization. + * @set_ios: handle bus specific extensions. + * @parse_dt: parse implementation specific device tree properties. +@@ -553,6 +554,7 @@ struct dw_mci_slot { + */ + struct dw_mci_drv_data { + unsigned long *caps; ++ u32 num_caps; + int (*init)(struct dw_mci *host); + void (*set_ios)(struct dw_mci *host, struct mmc_ios *ios); + int (*parse_dt)(struct dw_mci *host); +diff --git a/drivers/mmc/host/sdhci-pci-core.c b/drivers/mmc/host/sdhci-pci-core.c +index 67d787fa3306..070f5da06fd2 100644 +--- a/drivers/mmc/host/sdhci-pci-core.c ++++ b/drivers/mmc/host/sdhci-pci-core.c +@@ -594,9 +594,36 @@ static void byt_read_dsm(struct sdhci_pci_slot *slot) + slot->chip->rpm_retune = intel_host->d3_retune; + } + +-static int byt_emmc_probe_slot(struct sdhci_pci_slot *slot) ++static int intel_execute_tuning(struct mmc_host *mmc, u32 opcode) ++{ ++ int err = sdhci_execute_tuning(mmc, opcode); ++ struct sdhci_host *host = mmc_priv(mmc); ++ ++ if (err) ++ return err; ++ ++ /* ++ * Tuning can leave the IP in an active state (Buffer Read Enable bit ++ * set) which prevents the entry to low power states (i.e. S0i3). Data ++ * reset will clear it. ++ */ ++ sdhci_reset(host, SDHCI_RESET_DATA); ++ ++ return 0; ++} ++ ++static void byt_probe_slot(struct sdhci_pci_slot *slot) + { ++ struct mmc_host_ops *ops = &slot->host->mmc_host_ops; ++ + byt_read_dsm(slot); ++ ++ ops->execute_tuning = intel_execute_tuning; ++} ++ ++static int byt_emmc_probe_slot(struct sdhci_pci_slot *slot) ++{ ++ byt_probe_slot(slot); + slot->host->mmc->caps |= MMC_CAP_8_BIT_DATA | MMC_CAP_NONREMOVABLE | + MMC_CAP_HW_RESET | MMC_CAP_1_8V_DDR | + MMC_CAP_CMD_DURING_TFR | +@@ -651,7 +678,7 @@ static int ni_byt_sdio_probe_slot(struct sdhci_pci_slot *slot) + { + int err; + +- byt_read_dsm(slot); ++ byt_probe_slot(slot); + + err = ni_set_max_freq(slot); + if (err) +@@ -664,7 +691,7 @@ static int ni_byt_sdio_probe_slot(struct sdhci_pci_slot *slot) + + static int byt_sdio_probe_slot(struct sdhci_pci_slot *slot) + { +- byt_read_dsm(slot); ++ byt_probe_slot(slot); + slot->host->mmc->caps |= MMC_CAP_POWER_OFF_CARD | MMC_CAP_NONREMOVABLE | + MMC_CAP_WAIT_WHILE_BUSY; + return 0; +@@ -672,7 +699,7 @@ static int byt_sdio_probe_slot(struct sdhci_pci_slot *slot) + + static int byt_sd_probe_slot(struct sdhci_pci_slot *slot) + { +- byt_read_dsm(slot); ++ byt_probe_slot(slot); + slot->host->mmc->caps |= MMC_CAP_WAIT_WHILE_BUSY | + MMC_CAP_AGGRESSIVE_PM | MMC_CAP_CD_WAKE; + slot->cd_idx = 0; +diff --git a/drivers/net/ethernet/amd/xgbe/xgbe-drv.c b/drivers/net/ethernet/amd/xgbe/xgbe-drv.c +index 608693d11bd7..75c4455e2271 100644 +--- a/drivers/net/ethernet/amd/xgbe/xgbe-drv.c ++++ b/drivers/net/ethernet/amd/xgbe/xgbe-drv.c +@@ -595,7 +595,7 @@ static void xgbe_isr_task(unsigned long data) + + reissue_mask = 1 << 0; + if (!pdata->per_channel_irq) +- reissue_mask |= 0xffff < 4; ++ reissue_mask |= 0xffff << 4; + + XP_IOWRITE(pdata, XP_INT_REISSUE_EN, reissue_mask); + } +diff --git a/drivers/net/ethernet/amd/xgbe/xgbe-pci.c b/drivers/net/ethernet/amd/xgbe/xgbe-pci.c +index 3e5833cf1fab..eb23f9ba1a9a 100644 +--- a/drivers/net/ethernet/amd/xgbe/xgbe-pci.c ++++ b/drivers/net/ethernet/amd/xgbe/xgbe-pci.c +@@ -426,6 +426,8 @@ static int xgbe_pci_resume(struct pci_dev *pdev) + struct net_device *netdev = pdata->netdev; + int ret = 0; + ++ XP_IOWRITE(pdata, XP_INT_EN, 0x1fffff); ++ + pdata->lpm_ctrl &= ~MDIO_CTRL1_LPOWER; + XMDIO_WRITE(pdata, MDIO_MMD_PCS, MDIO_CTRL1, pdata->lpm_ctrl); + +diff --git a/drivers/net/ethernet/intel/ixgbe/ixgbe_main.c b/drivers/net/ethernet/intel/ixgbe/ixgbe_main.c +index 879a9c4cef59..29f600fd6977 100644 +--- a/drivers/net/ethernet/intel/ixgbe/ixgbe_main.c ++++ b/drivers/net/ethernet/intel/ixgbe/ixgbe_main.c +@@ -1877,6 +1877,14 @@ static void ixgbe_dma_sync_frag(struct ixgbe_ring *rx_ring, + ixgbe_rx_pg_size(rx_ring), + DMA_FROM_DEVICE, + IXGBE_RX_DMA_ATTR); ++ } else if (ring_uses_build_skb(rx_ring)) { ++ unsigned long offset = (unsigned long)(skb->data) & ~PAGE_MASK; ++ ++ dma_sync_single_range_for_cpu(rx_ring->dev, ++ IXGBE_CB(skb)->dma, ++ offset, ++ skb_headlen(skb), ++ DMA_FROM_DEVICE); + } else { + struct skb_frag_struct *frag = &skb_shinfo(skb)->frags[0]; + +diff --git a/drivers/net/ethernet/mellanox/mlx5/core/en_main.c b/drivers/net/ethernet/mellanox/mlx5/core/en_main.c +index 3cdb932cae76..a863572882b2 100644 +--- a/drivers/net/ethernet/mellanox/mlx5/core/en_main.c ++++ b/drivers/net/ethernet/mellanox/mlx5/core/en_main.c +@@ -1918,13 +1918,16 @@ static void mlx5e_build_rq_param(struct mlx5e_priv *priv, + param->wq.linear = 1; + } + +-static void mlx5e_build_drop_rq_param(struct mlx5e_rq_param *param) ++static void mlx5e_build_drop_rq_param(struct mlx5_core_dev *mdev, ++ struct mlx5e_rq_param *param) + { + void *rqc = param->rqc; + void *wq = MLX5_ADDR_OF(rqc, rqc, wq); + + MLX5_SET(wq, wq, wq_type, MLX5_WQ_TYPE_LINKED_LIST); + MLX5_SET(wq, wq, log_wq_stride, ilog2(sizeof(struct mlx5e_rx_wqe))); ++ ++ param->wq.buf_numa_node = dev_to_node(&mdev->pdev->dev); + } + + static void mlx5e_build_sq_param_common(struct mlx5e_priv *priv, +@@ -2778,6 +2781,9 @@ static int mlx5e_alloc_drop_cq(struct mlx5_core_dev *mdev, + struct mlx5e_cq *cq, + struct mlx5e_cq_param *param) + { ++ param->wq.buf_numa_node = dev_to_node(&mdev->pdev->dev); ++ param->wq.db_numa_node = dev_to_node(&mdev->pdev->dev); ++ + return mlx5e_alloc_cq_common(mdev, param, cq); + } + +@@ -2789,7 +2795,7 @@ static int mlx5e_open_drop_rq(struct mlx5_core_dev *mdev, + struct mlx5e_cq *cq = &drop_rq->cq; + int err; + +- mlx5e_build_drop_rq_param(&rq_param); ++ mlx5e_build_drop_rq_param(mdev, &rq_param); + + err = mlx5e_alloc_drop_cq(mdev, cq, &cq_param); + if (err) +diff --git a/drivers/net/ethernet/mellanox/mlx5/core/en_rx.c b/drivers/net/ethernet/mellanox/mlx5/core/en_rx.c +index 91b1b0938931..3476f594c195 100644 +--- a/drivers/net/ethernet/mellanox/mlx5/core/en_rx.c ++++ b/drivers/net/ethernet/mellanox/mlx5/core/en_rx.c +@@ -36,6 +36,7 @@ + #include + #include + #include ++#include + #include "en.h" + #include "en_tc.h" + #include "eswitch.h" +@@ -546,20 +547,33 @@ bool mlx5e_post_rx_mpwqes(struct mlx5e_rq *rq) + return true; + } + ++static void mlx5e_lro_update_tcp_hdr(struct mlx5_cqe64 *cqe, struct tcphdr *tcp) ++{ ++ u8 l4_hdr_type = get_cqe_l4_hdr_type(cqe); ++ u8 tcp_ack = (l4_hdr_type == CQE_L4_HDR_TYPE_TCP_ACK_NO_DATA) || ++ (l4_hdr_type == CQE_L4_HDR_TYPE_TCP_ACK_AND_DATA); ++ ++ tcp->check = 0; ++ tcp->psh = get_cqe_lro_tcppsh(cqe); ++ ++ if (tcp_ack) { ++ tcp->ack = 1; ++ tcp->ack_seq = cqe->lro_ack_seq_num; ++ tcp->window = cqe->lro_tcp_win; ++ } ++} ++ + static void mlx5e_lro_update_hdr(struct sk_buff *skb, struct mlx5_cqe64 *cqe, + u32 cqe_bcnt) + { + struct ethhdr *eth = (struct ethhdr *)(skb->data); + struct tcphdr *tcp; + int network_depth = 0; ++ __wsum check; + __be16 proto; + u16 tot_len; + void *ip_p; + +- u8 l4_hdr_type = get_cqe_l4_hdr_type(cqe); +- u8 tcp_ack = (l4_hdr_type == CQE_L4_HDR_TYPE_TCP_ACK_NO_DATA) || +- (l4_hdr_type == CQE_L4_HDR_TYPE_TCP_ACK_AND_DATA); +- + skb->mac_len = ETH_HLEN; + proto = __vlan_get_protocol(skb, eth->h_proto, &network_depth); + +@@ -577,23 +591,30 @@ static void mlx5e_lro_update_hdr(struct sk_buff *skb, struct mlx5_cqe64 *cqe, + ipv4->check = 0; + ipv4->check = ip_fast_csum((unsigned char *)ipv4, + ipv4->ihl); ++ ++ mlx5e_lro_update_tcp_hdr(cqe, tcp); ++ check = csum_partial(tcp, tcp->doff * 4, ++ csum_unfold((__force __sum16)cqe->check_sum)); ++ /* Almost done, don't forget the pseudo header */ ++ tcp->check = csum_tcpudp_magic(ipv4->saddr, ipv4->daddr, ++ tot_len - sizeof(struct iphdr), ++ IPPROTO_TCP, check); + } else { ++ u16 payload_len = tot_len - sizeof(struct ipv6hdr); + struct ipv6hdr *ipv6 = ip_p; + + tcp = ip_p + sizeof(struct ipv6hdr); + skb_shinfo(skb)->gso_type = SKB_GSO_TCPV6; + + ipv6->hop_limit = cqe->lro_min_ttl; +- ipv6->payload_len = cpu_to_be16(tot_len - +- sizeof(struct ipv6hdr)); +- } +- +- tcp->psh = get_cqe_lro_tcppsh(cqe); +- +- if (tcp_ack) { +- tcp->ack = 1; +- tcp->ack_seq = cqe->lro_ack_seq_num; +- tcp->window = cqe->lro_tcp_win; ++ ipv6->payload_len = cpu_to_be16(payload_len); ++ ++ mlx5e_lro_update_tcp_hdr(cqe, tcp); ++ check = csum_partial(tcp, tcp->doff * 4, ++ csum_unfold((__force __sum16)cqe->check_sum)); ++ /* Almost done, don't forget the pseudo header */ ++ tcp->check = csum_ipv6_magic(&ipv6->saddr, &ipv6->daddr, payload_len, ++ IPPROTO_TCP, check); + } + } + +diff --git a/drivers/net/ethernet/mellanox/mlx5/core/en_selftest.c b/drivers/net/ethernet/mellanox/mlx5/core/en_selftest.c +index 5a4608281f38..707976482c09 100644 +--- a/drivers/net/ethernet/mellanox/mlx5/core/en_selftest.c ++++ b/drivers/net/ethernet/mellanox/mlx5/core/en_selftest.c +@@ -216,7 +216,8 @@ mlx5e_test_loopback_validate(struct sk_buff *skb, + if (iph->protocol != IPPROTO_UDP) + goto out; + +- udph = udp_hdr(skb); ++ /* Don't assume skb_transport_header() was set */ ++ udph = (struct udphdr *)((u8 *)iph + 4 * iph->ihl); + if (udph->dest != htons(9)) + goto out; + +diff --git a/drivers/net/ethernet/mellanox/mlx5/core/en_tx.c b/drivers/net/ethernet/mellanox/mlx5/core/en_tx.c +index 1d6925d4369a..eea7f931cad3 100644 +--- a/drivers/net/ethernet/mellanox/mlx5/core/en_tx.c ++++ b/drivers/net/ethernet/mellanox/mlx5/core/en_tx.c +@@ -155,7 +155,7 @@ static inline u16 mlx5e_calc_min_inline(enum mlx5_inline_modes mode, + default: + hlen = mlx5e_skb_l2_header_offset(skb); + } +- return min_t(u16, hlen, skb->len); ++ return min_t(u16, hlen, skb_headlen(skb)); + } + + static inline void mlx5e_tx_skb_pull_inline(unsigned char **skb_data, +diff --git a/drivers/net/ethernet/mellanox/mlxsw/spectrum_router.c b/drivers/net/ethernet/mellanox/mlxsw/spectrum_router.c +index 7bef80676464..516e63244606 100644 +--- a/drivers/net/ethernet/mellanox/mlxsw/spectrum_router.c ++++ b/drivers/net/ethernet/mellanox/mlxsw/spectrum_router.c +@@ -729,26 +729,29 @@ static struct mlxsw_sp_fib *mlxsw_sp_vr_fib(const struct mlxsw_sp_vr *vr, + static struct mlxsw_sp_vr *mlxsw_sp_vr_create(struct mlxsw_sp *mlxsw_sp, + u32 tb_id) + { ++ struct mlxsw_sp_fib *fib4; ++ struct mlxsw_sp_fib *fib6; + struct mlxsw_sp_vr *vr; + int err; + + vr = mlxsw_sp_vr_find_unused(mlxsw_sp); + if (!vr) + return ERR_PTR(-EBUSY); +- vr->fib4 = mlxsw_sp_fib_create(vr, MLXSW_SP_L3_PROTO_IPV4); +- if (IS_ERR(vr->fib4)) +- return ERR_CAST(vr->fib4); +- vr->fib6 = mlxsw_sp_fib_create(vr, MLXSW_SP_L3_PROTO_IPV6); +- if (IS_ERR(vr->fib6)) { +- err = PTR_ERR(vr->fib6); ++ fib4 = mlxsw_sp_fib_create(vr, MLXSW_SP_L3_PROTO_IPV4); ++ if (IS_ERR(fib4)) ++ return ERR_CAST(fib4); ++ fib6 = mlxsw_sp_fib_create(vr, MLXSW_SP_L3_PROTO_IPV6); ++ if (IS_ERR(fib6)) { ++ err = PTR_ERR(fib6); + goto err_fib6_create; + } ++ vr->fib4 = fib4; ++ vr->fib6 = fib6; + vr->tb_id = tb_id; + return vr; + + err_fib6_create: +- mlxsw_sp_fib_destroy(vr->fib4); +- vr->fib4 = NULL; ++ mlxsw_sp_fib_destroy(fib4); + return ERR_PTR(err); + } + +@@ -3029,6 +3032,9 @@ mlxsw_sp_fib4_entry_offload_unset(struct mlxsw_sp_fib_entry *fib_entry) + struct mlxsw_sp_nexthop_group *nh_grp = fib_entry->nh_group; + int i; + ++ if (!list_is_singular(&nh_grp->fib_list)) ++ return; ++ + for (i = 0; i < nh_grp->count; i++) { + struct mlxsw_sp_nexthop *nh = &nh_grp->nexthops[i]; + +diff --git a/drivers/net/ethernet/mellanox/mlxsw/spectrum_switchdev.c b/drivers/net/ethernet/mellanox/mlxsw/spectrum_switchdev.c +index f5863e5bec81..42a6afcaae03 100644 +--- a/drivers/net/ethernet/mellanox/mlxsw/spectrum_switchdev.c ++++ b/drivers/net/ethernet/mellanox/mlxsw/spectrum_switchdev.c +@@ -1098,6 +1098,7 @@ static int __mlxsw_sp_port_fdb_uc_op(struct mlxsw_sp *mlxsw_sp, u8 local_port, + bool dynamic) + { + char *sfd_pl; ++ u8 num_rec; + int err; + + sfd_pl = kmalloc(MLXSW_REG_SFD_LEN, GFP_KERNEL); +@@ -1107,9 +1108,16 @@ static int __mlxsw_sp_port_fdb_uc_op(struct mlxsw_sp *mlxsw_sp, u8 local_port, + mlxsw_reg_sfd_pack(sfd_pl, mlxsw_sp_sfd_op(adding), 0); + mlxsw_reg_sfd_uc_pack(sfd_pl, 0, mlxsw_sp_sfd_rec_policy(dynamic), + mac, fid, action, local_port); ++ num_rec = mlxsw_reg_sfd_num_rec_get(sfd_pl); + err = mlxsw_reg_write(mlxsw_sp->core, MLXSW_REG(sfd), sfd_pl); +- kfree(sfd_pl); ++ if (err) ++ goto out; ++ ++ if (num_rec != mlxsw_reg_sfd_num_rec_get(sfd_pl)) ++ err = -EBUSY; + ++out: ++ kfree(sfd_pl); + return err; + } + +@@ -1134,6 +1142,7 @@ static int mlxsw_sp_port_fdb_uc_lag_op(struct mlxsw_sp *mlxsw_sp, u16 lag_id, + bool adding, bool dynamic) + { + char *sfd_pl; ++ u8 num_rec; + int err; + + sfd_pl = kmalloc(MLXSW_REG_SFD_LEN, GFP_KERNEL); +@@ -1144,9 +1153,16 @@ static int mlxsw_sp_port_fdb_uc_lag_op(struct mlxsw_sp *mlxsw_sp, u16 lag_id, + mlxsw_reg_sfd_uc_lag_pack(sfd_pl, 0, mlxsw_sp_sfd_rec_policy(dynamic), + mac, fid, MLXSW_REG_SFD_REC_ACTION_NOP, + lag_vid, lag_id); ++ num_rec = mlxsw_reg_sfd_num_rec_get(sfd_pl); + err = mlxsw_reg_write(mlxsw_sp->core, MLXSW_REG(sfd), sfd_pl); +- kfree(sfd_pl); ++ if (err) ++ goto out; ++ ++ if (num_rec != mlxsw_reg_sfd_num_rec_get(sfd_pl)) ++ err = -EBUSY; + ++out: ++ kfree(sfd_pl); + return err; + } + +@@ -1191,6 +1207,7 @@ static int mlxsw_sp_port_mdb_op(struct mlxsw_sp *mlxsw_sp, const char *addr, + u16 fid, u16 mid, bool adding) + { + char *sfd_pl; ++ u8 num_rec; + int err; + + sfd_pl = kmalloc(MLXSW_REG_SFD_LEN, GFP_KERNEL); +@@ -1200,7 +1217,15 @@ static int mlxsw_sp_port_mdb_op(struct mlxsw_sp *mlxsw_sp, const char *addr, + mlxsw_reg_sfd_pack(sfd_pl, mlxsw_sp_sfd_op(adding), 0); + mlxsw_reg_sfd_mc_pack(sfd_pl, 0, addr, fid, + MLXSW_REG_SFD_REC_ACTION_NOP, mid); ++ num_rec = mlxsw_reg_sfd_num_rec_get(sfd_pl); + err = mlxsw_reg_write(mlxsw_sp->core, MLXSW_REG(sfd), sfd_pl); ++ if (err) ++ goto out; ++ ++ if (num_rec != mlxsw_reg_sfd_num_rec_get(sfd_pl)) ++ err = -EBUSY; ++ ++out: + kfree(sfd_pl); + return err; + } +diff --git a/drivers/net/ethernet/ti/cpsw.c b/drivers/net/ethernet/ti/cpsw.c +index db8a4bcfc6c7..14b646b3b084 100644 +--- a/drivers/net/ethernet/ti/cpsw.c ++++ b/drivers/net/ethernet/ti/cpsw.c +@@ -1618,6 +1618,7 @@ static netdev_tx_t cpsw_ndo_start_xmit(struct sk_buff *skb, + q_idx = q_idx % cpsw->tx_ch_num; + + txch = cpsw->txv[q_idx].ch; ++ txq = netdev_get_tx_queue(ndev, q_idx); + ret = cpsw_tx_packet_submit(priv, skb, txch); + if (unlikely(ret != 0)) { + cpsw_err(priv, tx_err, "desc submit failed\n"); +@@ -1628,15 +1629,26 @@ static netdev_tx_t cpsw_ndo_start_xmit(struct sk_buff *skb, + * tell the kernel to stop sending us tx frames. + */ + if (unlikely(!cpdma_check_free_tx_desc(txch))) { +- txq = netdev_get_tx_queue(ndev, q_idx); + netif_tx_stop_queue(txq); ++ ++ /* Barrier, so that stop_queue visible to other cpus */ ++ smp_mb__after_atomic(); ++ ++ if (cpdma_check_free_tx_desc(txch)) ++ netif_tx_wake_queue(txq); + } + + return NETDEV_TX_OK; + fail: + ndev->stats.tx_dropped++; +- txq = netdev_get_tx_queue(ndev, skb_get_queue_mapping(skb)); + netif_tx_stop_queue(txq); ++ ++ /* Barrier, so that stop_queue visible to other cpus */ ++ smp_mb__after_atomic(); ++ ++ if (cpdma_check_free_tx_desc(txch)) ++ netif_tx_wake_queue(txq); ++ + return NETDEV_TX_BUSY; + } + +diff --git a/drivers/net/phy/phy.c b/drivers/net/phy/phy.c +index 2b1e67bc1e73..3d860de5e342 100644 +--- a/drivers/net/phy/phy.c ++++ b/drivers/net/phy/phy.c +@@ -842,7 +842,7 @@ void phy_start(struct phy_device *phydev) + break; + case PHY_HALTED: + /* make sure interrupts are re-enabled for the PHY */ +- if (phydev->irq != PHY_POLL) { ++ if (phy_interrupt_is_valid(phydev)) { + err = phy_enable_interrupts(phydev); + if (err < 0) + break; +diff --git a/drivers/net/ppp/ppp_generic.c b/drivers/net/ppp/ppp_generic.c +index 8c6b8918ec31..38cd2e8fae23 100644 +--- a/drivers/net/ppp/ppp_generic.c ++++ b/drivers/net/ppp/ppp_generic.c +@@ -3158,6 +3158,15 @@ ppp_connect_channel(struct channel *pch, int unit) + goto outl; + + ppp_lock(ppp); ++ spin_lock_bh(&pch->downl); ++ if (!pch->chan) { ++ /* Don't connect unregistered channels */ ++ spin_unlock_bh(&pch->downl); ++ ppp_unlock(ppp); ++ ret = -ENOTCONN; ++ goto outl; ++ } ++ spin_unlock_bh(&pch->downl); + if (pch->file.hdrlen > ppp->file.hdrlen) + ppp->file.hdrlen = pch->file.hdrlen; + hdrlen = pch->file.hdrlen + 2; /* for protocol bytes */ +diff --git a/drivers/net/tun.c b/drivers/net/tun.c +index fa51b7b0e9ea..bc38d54e37b9 100644 +--- a/drivers/net/tun.c ++++ b/drivers/net/tun.c +@@ -1315,6 +1315,7 @@ static struct sk_buff *tun_build_skb(struct tun_struct *tun, + else + *skb_xdp = 0; + ++ preempt_disable(); + rcu_read_lock(); + xdp_prog = rcu_dereference(tun->xdp_prog); + if (xdp_prog && !*skb_xdp) { +@@ -1333,9 +1334,11 @@ static struct sk_buff *tun_build_skb(struct tun_struct *tun, + get_page(alloc_frag->page); + alloc_frag->offset += buflen; + err = xdp_do_redirect(tun->dev, &xdp, xdp_prog); ++ xdp_do_flush_map(); + if (err) + goto err_redirect; + rcu_read_unlock(); ++ preempt_enable(); + return NULL; + case XDP_TX: + xdp_xmit = true; +@@ -1357,6 +1360,7 @@ static struct sk_buff *tun_build_skb(struct tun_struct *tun, + skb = build_skb(buf, buflen); + if (!skb) { + rcu_read_unlock(); ++ preempt_enable(); + return ERR_PTR(-ENOMEM); + } + +@@ -1369,10 +1373,12 @@ static struct sk_buff *tun_build_skb(struct tun_struct *tun, + skb->dev = tun->dev; + generic_xdp_tx(skb, xdp_prog); + rcu_read_unlock(); ++ preempt_enable(); + return NULL; + } + + rcu_read_unlock(); ++ preempt_enable(); + + return skb; + +@@ -1380,6 +1386,7 @@ static struct sk_buff *tun_build_skb(struct tun_struct *tun, + put_page(alloc_frag->page); + err_xdp: + rcu_read_unlock(); ++ preempt_enable(); + this_cpu_inc(tun->pcpu_stats->rx_dropped); + return NULL; + } +diff --git a/drivers/net/virtio_net.c b/drivers/net/virtio_net.c +index 7927e28f5336..6a785595b9b8 100644 +--- a/drivers/net/virtio_net.c ++++ b/drivers/net/virtio_net.c +@@ -1995,8 +1995,9 @@ static int virtnet_xdp_set(struct net_device *dev, struct bpf_prog *prog, + } + + /* Make sure NAPI is not using any XDP TX queues for RX. */ +- for (i = 0; i < vi->max_queue_pairs; i++) +- napi_disable(&vi->rq[i].napi); ++ if (netif_running(dev)) ++ for (i = 0; i < vi->max_queue_pairs; i++) ++ napi_disable(&vi->rq[i].napi); + + netif_set_real_num_rx_queues(dev, curr_qp + xdp_qp); + err = _virtnet_set_queues(vi, curr_qp + xdp_qp); +@@ -2015,7 +2016,8 @@ static int virtnet_xdp_set(struct net_device *dev, struct bpf_prog *prog, + } + if (old_prog) + bpf_prog_put(old_prog); +- virtnet_napi_enable(vi->rq[i].vq, &vi->rq[i].napi); ++ if (netif_running(dev)) ++ virtnet_napi_enable(vi->rq[i].vq, &vi->rq[i].napi); + } + + return 0; +diff --git a/drivers/net/wan/hdlc_ppp.c b/drivers/net/wan/hdlc_ppp.c +index 0d2e00ece804..f3c1d5245978 100644 +--- a/drivers/net/wan/hdlc_ppp.c ++++ b/drivers/net/wan/hdlc_ppp.c +@@ -574,7 +574,10 @@ static void ppp_timer(unsigned long arg) + ppp_cp_event(proto->dev, proto->pid, TO_GOOD, 0, 0, + 0, NULL); + proto->restart_counter--; +- } else ++ } else if (netif_carrier_ok(proto->dev)) ++ ppp_cp_event(proto->dev, proto->pid, TO_GOOD, 0, 0, ++ 0, NULL); ++ else + ppp_cp_event(proto->dev, proto->pid, TO_BAD, 0, 0, + 0, NULL); + break; +diff --git a/drivers/nvme/host/rdma.c b/drivers/nvme/host/rdma.c +index 33d4431c2b4b..93a082e0bdd4 100644 +--- a/drivers/nvme/host/rdma.c ++++ b/drivers/nvme/host/rdma.c +@@ -88,7 +88,6 @@ enum nvme_rdma_queue_flags { + + struct nvme_rdma_queue { + struct nvme_rdma_qe *rsp_ring; +- atomic_t sig_count; + int queue_size; + size_t cmnd_capsule_len; + struct nvme_rdma_ctrl *ctrl; +@@ -521,7 +520,6 @@ static int nvme_rdma_alloc_queue(struct nvme_rdma_ctrl *ctrl, + queue->cmnd_capsule_len = sizeof(struct nvme_command); + + queue->queue_size = queue_size; +- atomic_set(&queue->sig_count, 0); + + queue->cm_id = rdma_create_id(&init_net, nvme_rdma_cm_handler, queue, + RDMA_PS_TCP, IB_QPT_RC); +@@ -1232,21 +1230,9 @@ static void nvme_rdma_send_done(struct ib_cq *cq, struct ib_wc *wc) + nvme_end_request(rq, req->status, req->result); + } + +-/* +- * We want to signal completion at least every queue depth/2. This returns the +- * largest power of two that is not above half of (queue size + 1) to optimize +- * (avoid divisions). +- */ +-static inline bool nvme_rdma_queue_sig_limit(struct nvme_rdma_queue *queue) +-{ +- int limit = 1 << ilog2((queue->queue_size + 1) / 2); +- +- return (atomic_inc_return(&queue->sig_count) & (limit - 1)) == 0; +-} +- + static int nvme_rdma_post_send(struct nvme_rdma_queue *queue, + struct nvme_rdma_qe *qe, struct ib_sge *sge, u32 num_sge, +- struct ib_send_wr *first, bool flush) ++ struct ib_send_wr *first) + { + struct ib_send_wr wr, *bad_wr; + int ret; +@@ -1255,31 +1241,12 @@ static int nvme_rdma_post_send(struct nvme_rdma_queue *queue, + sge->length = sizeof(struct nvme_command), + sge->lkey = queue->device->pd->local_dma_lkey; + +- qe->cqe.done = nvme_rdma_send_done; +- + wr.next = NULL; + wr.wr_cqe = &qe->cqe; + wr.sg_list = sge; + wr.num_sge = num_sge; + wr.opcode = IB_WR_SEND; +- wr.send_flags = 0; +- +- /* +- * Unsignalled send completions are another giant desaster in the +- * IB Verbs spec: If we don't regularly post signalled sends +- * the send queue will fill up and only a QP reset will rescue us. +- * Would have been way to obvious to handle this in hardware or +- * at least the RDMA stack.. +- * +- * Always signal the flushes. The magic request used for the flush +- * sequencer is not allocated in our driver's tagset and it's +- * triggered to be freed by blk_cleanup_queue(). So we need to +- * always mark it as signaled to ensure that the "wr_cqe", which is +- * embedded in request's payload, is not freed when __ib_process_cq() +- * calls wr_cqe->done(). +- */ +- if (nvme_rdma_queue_sig_limit(queue) || flush) +- wr.send_flags |= IB_SEND_SIGNALED; ++ wr.send_flags = IB_SEND_SIGNALED; + + if (first) + first->next = ≀ +@@ -1329,6 +1296,12 @@ static struct blk_mq_tags *nvme_rdma_tagset(struct nvme_rdma_queue *queue) + return queue->ctrl->tag_set.tags[queue_idx - 1]; + } + ++static void nvme_rdma_async_done(struct ib_cq *cq, struct ib_wc *wc) ++{ ++ if (unlikely(wc->status != IB_WC_SUCCESS)) ++ nvme_rdma_wr_error(cq, wc, "ASYNC"); ++} ++ + static void nvme_rdma_submit_async_event(struct nvme_ctrl *arg, int aer_idx) + { + struct nvme_rdma_ctrl *ctrl = to_rdma_ctrl(arg); +@@ -1350,10 +1323,12 @@ static void nvme_rdma_submit_async_event(struct nvme_ctrl *arg, int aer_idx) + cmd->common.flags |= NVME_CMD_SGL_METABUF; + nvme_rdma_set_sg_null(cmd); + ++ sqe->cqe.done = nvme_rdma_async_done; ++ + ib_dma_sync_single_for_device(dev, sqe->dma, sizeof(*cmd), + DMA_TO_DEVICE); + +- ret = nvme_rdma_post_send(queue, sqe, &sge, 1, NULL, false); ++ ret = nvme_rdma_post_send(queue, sqe, &sge, 1, NULL); + WARN_ON_ONCE(ret); + } + +@@ -1639,7 +1614,6 @@ static blk_status_t nvme_rdma_queue_rq(struct blk_mq_hw_ctx *hctx, + struct nvme_rdma_request *req = blk_mq_rq_to_pdu(rq); + struct nvme_rdma_qe *sqe = &req->sqe; + struct nvme_command *c = sqe->data; +- bool flush = false; + struct ib_device *dev; + blk_status_t ret; + int err; +@@ -1668,13 +1642,13 @@ static blk_status_t nvme_rdma_queue_rq(struct blk_mq_hw_ctx *hctx, + goto err; + } + ++ sqe->cqe.done = nvme_rdma_send_done; ++ + ib_dma_sync_single_for_device(dev, sqe->dma, + sizeof(struct nvme_command), DMA_TO_DEVICE); + +- if (req_op(rq) == REQ_OP_FLUSH) +- flush = true; + err = nvme_rdma_post_send(queue, sqe, req->sge, req->num_sge, +- req->mr->need_inval ? &req->reg_wr.wr : NULL, flush); ++ req->mr->need_inval ? &req->reg_wr.wr : NULL); + if (unlikely(err)) { + nvme_rdma_unmap_data(queue, rq); + goto err; +diff --git a/drivers/pci/pcie/aspm.c b/drivers/pci/pcie/aspm.c +index cae54f8320be..633e55c57b13 100644 +--- a/drivers/pci/pcie/aspm.c ++++ b/drivers/pci/pcie/aspm.c +@@ -803,10 +803,14 @@ static struct pcie_link_state *alloc_pcie_link_state(struct pci_dev *pdev) + + /* + * Root Ports and PCI/PCI-X to PCIe Bridges are roots of PCIe +- * hierarchies. ++ * hierarchies. Note that some PCIe host implementations omit ++ * the root ports entirely, in which case a downstream port on ++ * a switch may become the root of the link state chain for all ++ * its subordinate endpoints. + */ + if (pci_pcie_type(pdev) == PCI_EXP_TYPE_ROOT_PORT || +- pci_pcie_type(pdev) == PCI_EXP_TYPE_PCIE_BRIDGE) { ++ pci_pcie_type(pdev) == PCI_EXP_TYPE_PCIE_BRIDGE || ++ !pdev->bus->parent->self) { + link->root = link; + } else { + struct pcie_link_state *parent; +diff --git a/drivers/s390/net/qeth_core.h b/drivers/s390/net/qeth_core.h +index 92dd4aef21a3..6b1e83539a9d 100644 +--- a/drivers/s390/net/qeth_core.h ++++ b/drivers/s390/net/qeth_core.h +@@ -580,6 +580,11 @@ struct qeth_cmd_buffer { + void (*callback) (struct qeth_channel *, struct qeth_cmd_buffer *); + }; + ++static inline struct qeth_ipa_cmd *__ipa_cmd(struct qeth_cmd_buffer *iob) ++{ ++ return (struct qeth_ipa_cmd *)(iob->data + IPA_PDU_HEADER_SIZE); ++} ++ + /** + * definition of a qeth channel, used for read and write + */ +@@ -834,7 +839,7 @@ struct qeth_trap_id { + */ + static inline int qeth_get_elements_for_range(addr_t start, addr_t end) + { +- return PFN_UP(end - 1) - PFN_DOWN(start); ++ return PFN_UP(end) - PFN_DOWN(start); + } + + static inline int qeth_get_micros(void) +diff --git a/drivers/s390/net/qeth_core_main.c b/drivers/s390/net/qeth_core_main.c +index 7c7a244b6684..145b57762d8f 100644 +--- a/drivers/s390/net/qeth_core_main.c ++++ b/drivers/s390/net/qeth_core_main.c +@@ -2073,7 +2073,7 @@ int qeth_send_control_data(struct qeth_card *card, int len, + unsigned long flags; + struct qeth_reply *reply = NULL; + unsigned long timeout, event_timeout; +- struct qeth_ipa_cmd *cmd; ++ struct qeth_ipa_cmd *cmd = NULL; + + QETH_CARD_TEXT(card, 2, "sendctl"); + +@@ -2087,23 +2087,27 @@ int qeth_send_control_data(struct qeth_card *card, int len, + } + reply->callback = reply_cb; + reply->param = reply_param; +- if (card->state == CARD_STATE_DOWN) +- reply->seqno = QETH_IDX_COMMAND_SEQNO; +- else +- reply->seqno = card->seqno.ipa++; ++ + init_waitqueue_head(&reply->wait_q); +- spin_lock_irqsave(&card->lock, flags); +- list_add_tail(&reply->list, &card->cmd_waiter_list); +- spin_unlock_irqrestore(&card->lock, flags); + QETH_DBF_HEX(CTRL, 2, iob->data, QETH_DBF_CTRL_LEN); + + while (atomic_cmpxchg(&card->write.irq_pending, 0, 1)) ; +- qeth_prepare_control_data(card, len, iob); + +- if (IS_IPA(iob->data)) ++ if (IS_IPA(iob->data)) { ++ cmd = __ipa_cmd(iob); ++ cmd->hdr.seqno = card->seqno.ipa++; ++ reply->seqno = cmd->hdr.seqno; + event_timeout = QETH_IPA_TIMEOUT; +- else ++ } else { ++ reply->seqno = QETH_IDX_COMMAND_SEQNO; + event_timeout = QETH_TIMEOUT; ++ } ++ qeth_prepare_control_data(card, len, iob); ++ ++ spin_lock_irqsave(&card->lock, flags); ++ list_add_tail(&reply->list, &card->cmd_waiter_list); ++ spin_unlock_irqrestore(&card->lock, flags); ++ + timeout = jiffies + event_timeout; + + QETH_CARD_TEXT(card, 6, "noirqpnd"); +@@ -2128,9 +2132,8 @@ int qeth_send_control_data(struct qeth_card *card, int len, + + /* we have only one long running ipassist, since we can ensure + process context of this command we can sleep */ +- cmd = (struct qeth_ipa_cmd *)(iob->data+IPA_PDU_HEADER_SIZE); +- if ((cmd->hdr.command == IPA_CMD_SETIP) && +- (cmd->hdr.prot_version == QETH_PROT_IPV4)) { ++ if (cmd && cmd->hdr.command == IPA_CMD_SETIP && ++ cmd->hdr.prot_version == QETH_PROT_IPV4) { + if (!wait_event_timeout(reply->wait_q, + atomic_read(&reply->received), event_timeout)) + goto time_err; +@@ -2894,7 +2897,7 @@ static void qeth_fill_ipacmd_header(struct qeth_card *card, + memset(cmd, 0, sizeof(struct qeth_ipa_cmd)); + cmd->hdr.command = command; + cmd->hdr.initiator = IPA_CMD_INITIATOR_HOST; +- cmd->hdr.seqno = card->seqno.ipa; ++ /* cmd->hdr.seqno is set by qeth_send_control_data() */ + cmd->hdr.adapter_type = qeth_get_ipa_adp_type(card->info.link_type); + cmd->hdr.rel_adapter_no = (__u8) card->info.portno; + if (card->options.layer2) +@@ -3859,10 +3862,12 @@ EXPORT_SYMBOL_GPL(qeth_get_elements_for_frags); + int qeth_get_elements_no(struct qeth_card *card, + struct sk_buff *skb, int extra_elems, int data_offset) + { +- int elements = qeth_get_elements_for_range( +- (addr_t)skb->data + data_offset, +- (addr_t)skb->data + skb_headlen(skb)) + +- qeth_get_elements_for_frags(skb); ++ addr_t end = (addr_t)skb->data + skb_headlen(skb); ++ int elements = qeth_get_elements_for_frags(skb); ++ addr_t start = (addr_t)skb->data + data_offset; ++ ++ if (start != end) ++ elements += qeth_get_elements_for_range(start, end); + + if ((elements + extra_elems) > QETH_MAX_BUFFER_ELEMENTS(card)) { + QETH_DBF_MESSAGE(2, "Invalid size of IP packet " +diff --git a/drivers/s390/net/qeth_l3.h b/drivers/s390/net/qeth_l3.h +index e5833837b799..8727b9517de8 100644 +--- a/drivers/s390/net/qeth_l3.h ++++ b/drivers/s390/net/qeth_l3.h +@@ -40,8 +40,40 @@ struct qeth_ipaddr { + unsigned int pfxlen; + } a6; + } u; +- + }; ++ ++static inline bool qeth_l3_addr_match_ip(struct qeth_ipaddr *a1, ++ struct qeth_ipaddr *a2) ++{ ++ if (a1->proto != a2->proto) ++ return false; ++ if (a1->proto == QETH_PROT_IPV6) ++ return ipv6_addr_equal(&a1->u.a6.addr, &a2->u.a6.addr); ++ return a1->u.a4.addr == a2->u.a4.addr; ++} ++ ++static inline bool qeth_l3_addr_match_all(struct qeth_ipaddr *a1, ++ struct qeth_ipaddr *a2) ++{ ++ /* Assumes that the pair was obtained via qeth_l3_addr_find_by_ip(), ++ * so 'proto' and 'addr' match for sure. ++ * ++ * For ucast: ++ * - 'mac' is always 0. ++ * - 'mask'/'pfxlen' for RXIP/VIPA is always 0. For NORMAL, matching ++ * values are required to avoid mixups in takeover eligibility. ++ * ++ * For mcast, ++ * - 'mac' is mapped from the IP, and thus always matches. ++ * - 'mask'/'pfxlen' is always 0. ++ */ ++ if (a1->type != a2->type) ++ return false; ++ if (a1->proto == QETH_PROT_IPV6) ++ return a1->u.a6.pfxlen == a2->u.a6.pfxlen; ++ return a1->u.a4.mask == a2->u.a4.mask; ++} ++ + static inline u64 qeth_l3_ipaddr_hash(struct qeth_ipaddr *addr) + { + u64 ret = 0; +diff --git a/drivers/s390/net/qeth_l3_main.c b/drivers/s390/net/qeth_l3_main.c +index 36dee176f8e2..96576e729222 100644 +--- a/drivers/s390/net/qeth_l3_main.c ++++ b/drivers/s390/net/qeth_l3_main.c +@@ -149,6 +149,24 @@ int qeth_l3_string_to_ipaddr(const char *buf, enum qeth_prot_versions proto, + return -EINVAL; + } + ++static struct qeth_ipaddr *qeth_l3_find_addr_by_ip(struct qeth_card *card, ++ struct qeth_ipaddr *query) ++{ ++ u64 key = qeth_l3_ipaddr_hash(query); ++ struct qeth_ipaddr *addr; ++ ++ if (query->is_multicast) { ++ hash_for_each_possible(card->ip_mc_htable, addr, hnode, key) ++ if (qeth_l3_addr_match_ip(addr, query)) ++ return addr; ++ } else { ++ hash_for_each_possible(card->ip_htable, addr, hnode, key) ++ if (qeth_l3_addr_match_ip(addr, query)) ++ return addr; ++ } ++ return NULL; ++} ++ + static void qeth_l3_convert_addr_to_bits(u8 *addr, u8 *bits, int len) + { + int i, j; +@@ -202,34 +220,6 @@ static bool qeth_l3_is_addr_covered_by_ipato(struct qeth_card *card, + return rc; + } + +-inline int +-qeth_l3_ipaddrs_is_equal(struct qeth_ipaddr *addr1, struct qeth_ipaddr *addr2) +-{ +- return addr1->proto == addr2->proto && +- !memcmp(&addr1->u, &addr2->u, sizeof(addr1->u)) && +- !memcmp(&addr1->mac, &addr2->mac, sizeof(addr1->mac)); +-} +- +-static struct qeth_ipaddr * +-qeth_l3_ip_from_hash(struct qeth_card *card, struct qeth_ipaddr *tmp_addr) +-{ +- struct qeth_ipaddr *addr; +- +- if (tmp_addr->is_multicast) { +- hash_for_each_possible(card->ip_mc_htable, addr, +- hnode, qeth_l3_ipaddr_hash(tmp_addr)) +- if (qeth_l3_ipaddrs_is_equal(tmp_addr, addr)) +- return addr; +- } else { +- hash_for_each_possible(card->ip_htable, addr, +- hnode, qeth_l3_ipaddr_hash(tmp_addr)) +- if (qeth_l3_ipaddrs_is_equal(tmp_addr, addr)) +- return addr; +- } +- +- return NULL; +-} +- + int qeth_l3_delete_ip(struct qeth_card *card, struct qeth_ipaddr *tmp_addr) + { + int rc = 0; +@@ -244,23 +234,18 @@ int qeth_l3_delete_ip(struct qeth_card *card, struct qeth_ipaddr *tmp_addr) + QETH_CARD_HEX(card, 4, ((char *)&tmp_addr->u.a6.addr) + 8, 8); + } + +- addr = qeth_l3_ip_from_hash(card, tmp_addr); +- if (!addr) ++ addr = qeth_l3_find_addr_by_ip(card, tmp_addr); ++ if (!addr || !qeth_l3_addr_match_all(addr, tmp_addr)) + return -ENOENT; + + addr->ref_counter--; +- if (addr->ref_counter > 0 && (addr->type == QETH_IP_TYPE_NORMAL || +- addr->type == QETH_IP_TYPE_RXIP)) ++ if (addr->type == QETH_IP_TYPE_NORMAL && addr->ref_counter > 0) + return rc; + if (addr->in_progress) + return -EINPROGRESS; + +- if (!qeth_card_hw_is_reachable(card)) { +- addr->disp_flag = QETH_DISP_ADDR_DELETE; +- return 0; +- } +- +- rc = qeth_l3_deregister_addr_entry(card, addr); ++ if (qeth_card_hw_is_reachable(card)) ++ rc = qeth_l3_deregister_addr_entry(card, addr); + + hash_del(&addr->hnode); + kfree(addr); +@@ -272,6 +257,7 @@ int qeth_l3_add_ip(struct qeth_card *card, struct qeth_ipaddr *tmp_addr) + { + int rc = 0; + struct qeth_ipaddr *addr; ++ char buf[40]; + + QETH_CARD_TEXT(card, 4, "addip"); + +@@ -282,8 +268,20 @@ int qeth_l3_add_ip(struct qeth_card *card, struct qeth_ipaddr *tmp_addr) + QETH_CARD_HEX(card, 4, ((char *)&tmp_addr->u.a6.addr) + 8, 8); + } + +- addr = qeth_l3_ip_from_hash(card, tmp_addr); +- if (!addr) { ++ addr = qeth_l3_find_addr_by_ip(card, tmp_addr); ++ if (addr) { ++ if (tmp_addr->type != QETH_IP_TYPE_NORMAL) ++ return -EADDRINUSE; ++ if (qeth_l3_addr_match_all(addr, tmp_addr)) { ++ addr->ref_counter++; ++ return 0; ++ } ++ qeth_l3_ipaddr_to_string(tmp_addr->proto, (u8 *)&tmp_addr->u, ++ buf); ++ dev_warn(&card->gdev->dev, ++ "Registering IP address %s failed\n", buf); ++ return -EADDRINUSE; ++ } else { + addr = qeth_l3_get_addr_buffer(tmp_addr->proto); + if (!addr) + return -ENOMEM; +@@ -323,19 +321,15 @@ int qeth_l3_add_ip(struct qeth_card *card, struct qeth_ipaddr *tmp_addr) + (rc == IPA_RC_LAN_OFFLINE)) { + addr->disp_flag = QETH_DISP_ADDR_DO_NOTHING; + if (addr->ref_counter < 1) { +- qeth_l3_delete_ip(card, addr); ++ qeth_l3_deregister_addr_entry(card, addr); ++ hash_del(&addr->hnode); + kfree(addr); + } + } else { + hash_del(&addr->hnode); + kfree(addr); + } +- } else { +- if (addr->type == QETH_IP_TYPE_NORMAL || +- addr->type == QETH_IP_TYPE_RXIP) +- addr->ref_counter++; + } +- + return rc; + } + +@@ -403,11 +397,7 @@ static void qeth_l3_recover_ip(struct qeth_card *card) + spin_lock_bh(&card->ip_lock); + + hash_for_each_safe(card->ip_htable, i, tmp, addr, hnode) { +- if (addr->disp_flag == QETH_DISP_ADDR_DELETE) { +- qeth_l3_deregister_addr_entry(card, addr); +- hash_del(&addr->hnode); +- kfree(addr); +- } else if (addr->disp_flag == QETH_DISP_ADDR_ADD) { ++ if (addr->disp_flag == QETH_DISP_ADDR_ADD) { + if (addr->proto == QETH_PROT_IPV4) { + addr->in_progress = 1; + spin_unlock_bh(&card->ip_lock); +@@ -723,12 +713,7 @@ int qeth_l3_add_vipa(struct qeth_card *card, enum qeth_prot_versions proto, + return -ENOMEM; + + spin_lock_bh(&card->ip_lock); +- +- if (qeth_l3_ip_from_hash(card, ipaddr)) +- rc = -EEXIST; +- else +- qeth_l3_add_ip(card, ipaddr); +- ++ rc = qeth_l3_add_ip(card, ipaddr); + spin_unlock_bh(&card->ip_lock); + + kfree(ipaddr); +@@ -791,12 +776,7 @@ int qeth_l3_add_rxip(struct qeth_card *card, enum qeth_prot_versions proto, + return -ENOMEM; + + spin_lock_bh(&card->ip_lock); +- +- if (qeth_l3_ip_from_hash(card, ipaddr)) +- rc = -EEXIST; +- else +- qeth_l3_add_ip(card, ipaddr); +- ++ rc = qeth_l3_add_ip(card, ipaddr); + spin_unlock_bh(&card->ip_lock); + + kfree(ipaddr); +@@ -1404,8 +1384,9 @@ qeth_l3_add_mc_to_hash(struct qeth_card *card, struct in_device *in4_dev) + memcpy(tmp->mac, buf, sizeof(tmp->mac)); + tmp->is_multicast = 1; + +- ipm = qeth_l3_ip_from_hash(card, tmp); ++ ipm = qeth_l3_find_addr_by_ip(card, tmp); + if (ipm) { ++ /* for mcast, by-IP match means full match */ + ipm->disp_flag = QETH_DISP_ADDR_DO_NOTHING; + } else { + ipm = qeth_l3_get_addr_buffer(QETH_PROT_IPV4); +@@ -1488,8 +1469,9 @@ qeth_l3_add_mc6_to_hash(struct qeth_card *card, struct inet6_dev *in6_dev) + sizeof(struct in6_addr)); + tmp->is_multicast = 1; + +- ipm = qeth_l3_ip_from_hash(card, tmp); ++ ipm = qeth_l3_find_addr_by_ip(card, tmp); + if (ipm) { ++ /* for mcast, by-IP match means full match */ + ipm->disp_flag = QETH_DISP_ADDR_DO_NOTHING; + continue; + } +@@ -2633,11 +2615,12 @@ static void qeth_tso_fill_header(struct qeth_card *card, + static int qeth_l3_get_elements_no_tso(struct qeth_card *card, + struct sk_buff *skb, int extra_elems) + { +- addr_t tcpdptr = (addr_t)tcp_hdr(skb) + tcp_hdrlen(skb); +- int elements = qeth_get_elements_for_range( +- tcpdptr, +- (addr_t)skb->data + skb_headlen(skb)) + +- qeth_get_elements_for_frags(skb); ++ addr_t start = (addr_t)tcp_hdr(skb) + tcp_hdrlen(skb); ++ addr_t end = (addr_t)skb->data + skb_headlen(skb); ++ int elements = qeth_get_elements_for_frags(skb); ++ ++ if (start != end) ++ elements += qeth_get_elements_for_range(start, end); + + if ((elements + extra_elems) > QETH_MAX_BUFFER_ELEMENTS(card)) { + QETH_DBF_MESSAGE(2, +diff --git a/drivers/vfio/vfio_iommu_type1.c b/drivers/vfio/vfio_iommu_type1.c +index 92155cce926d..fb4e6a7ee521 100644 +--- a/drivers/vfio/vfio_iommu_type1.c ++++ b/drivers/vfio/vfio_iommu_type1.c +@@ -338,11 +338,12 @@ static int vaddr_get_pfn(struct mm_struct *mm, unsigned long vaddr, + { + struct page *page[1]; + struct vm_area_struct *vma; ++ struct vm_area_struct *vmas[1]; + int ret; + + if (mm == current->mm) { +- ret = get_user_pages_fast(vaddr, 1, !!(prot & IOMMU_WRITE), +- page); ++ ret = get_user_pages_longterm(vaddr, 1, !!(prot & IOMMU_WRITE), ++ page, vmas); + } else { + unsigned int flags = 0; + +@@ -351,7 +352,18 @@ static int vaddr_get_pfn(struct mm_struct *mm, unsigned long vaddr, + + down_read(&mm->mmap_sem); + ret = get_user_pages_remote(NULL, mm, vaddr, 1, flags, page, +- NULL, NULL); ++ vmas, NULL); ++ /* ++ * The lifetime of a vaddr_get_pfn() page pin is ++ * userspace-controlled. In the fs-dax case this could ++ * lead to indefinite stalls in filesystem operations. ++ * Disallow attempts to pin fs-dax pages via this ++ * interface. ++ */ ++ if (ret > 0 && vma_is_fsdax(vmas[0])) { ++ ret = -EOPNOTSUPP; ++ put_page(page[0]); ++ } + up_read(&mm->mmap_sem); + } + +diff --git a/fs/btrfs/sysfs.c b/fs/btrfs/sysfs.c +index 883881b16c86..4447e0fe9b55 100644 +--- a/fs/btrfs/sysfs.c ++++ b/fs/btrfs/sysfs.c +@@ -422,7 +422,7 @@ static ssize_t btrfs_nodesize_show(struct kobject *kobj, + { + struct btrfs_fs_info *fs_info = to_fs_info(kobj); + +- return snprintf(buf, PAGE_SIZE, "%u\n", fs_info->super_copy->nodesize); ++ return snprintf(buf, PAGE_SIZE, "%u\n", fs_info->nodesize); + } + + BTRFS_ATTR(nodesize, btrfs_nodesize_show); +@@ -432,8 +432,7 @@ static ssize_t btrfs_sectorsize_show(struct kobject *kobj, + { + struct btrfs_fs_info *fs_info = to_fs_info(kobj); + +- return snprintf(buf, PAGE_SIZE, "%u\n", +- fs_info->super_copy->sectorsize); ++ return snprintf(buf, PAGE_SIZE, "%u\n", fs_info->sectorsize); + } + + BTRFS_ATTR(sectorsize, btrfs_sectorsize_show); +@@ -443,8 +442,7 @@ static ssize_t btrfs_clone_alignment_show(struct kobject *kobj, + { + struct btrfs_fs_info *fs_info = to_fs_info(kobj); + +- return snprintf(buf, PAGE_SIZE, "%u\n", +- fs_info->super_copy->sectorsize); ++ return snprintf(buf, PAGE_SIZE, "%u\n", fs_info->sectorsize); + } + + BTRFS_ATTR(clone_alignment, btrfs_clone_alignment_show); +diff --git a/fs/btrfs/transaction.c b/fs/btrfs/transaction.c +index f615d59b0489..46bda13e5727 100644 +--- a/fs/btrfs/transaction.c ++++ b/fs/btrfs/transaction.c +@@ -1722,19 +1722,23 @@ static void update_super_roots(struct btrfs_fs_info *fs_info) + + super = fs_info->super_copy; + ++ /* update latest btrfs_super_block::chunk_root refs */ + root_item = &fs_info->chunk_root->root_item; +- super->chunk_root = root_item->bytenr; +- super->chunk_root_generation = root_item->generation; +- super->chunk_root_level = root_item->level; ++ btrfs_set_super_chunk_root(super, root_item->bytenr); ++ btrfs_set_super_chunk_root_generation(super, root_item->generation); ++ btrfs_set_super_chunk_root_level(super, root_item->level); + ++ /* update latest btrfs_super_block::root refs */ + root_item = &fs_info->tree_root->root_item; +- super->root = root_item->bytenr; +- super->generation = root_item->generation; +- super->root_level = root_item->level; ++ btrfs_set_super_root(super, root_item->bytenr); ++ btrfs_set_super_generation(super, root_item->generation); ++ btrfs_set_super_root_level(super, root_item->level); ++ + if (btrfs_test_opt(fs_info, SPACE_CACHE)) +- super->cache_generation = root_item->generation; ++ btrfs_set_super_cache_generation(super, root_item->generation); + if (test_bit(BTRFS_FS_UPDATE_UUID_TREE_GEN, &fs_info->flags)) +- super->uuid_tree_generation = root_item->generation; ++ btrfs_set_super_uuid_tree_generation(super, ++ root_item->generation); + } + + int btrfs_transaction_in_commit(struct btrfs_fs_info *info) +diff --git a/fs/direct-io.c b/fs/direct-io.c +index b53e66d9abd7..625a84aa6484 100644 +--- a/fs/direct-io.c ++++ b/fs/direct-io.c +@@ -1252,8 +1252,7 @@ do_blockdev_direct_IO(struct kiocb *iocb, struct inode *inode, + */ + if (dio->is_async && iov_iter_rw(iter) == WRITE) { + retval = 0; +- if ((iocb->ki_filp->f_flags & O_DSYNC) || +- IS_SYNC(iocb->ki_filp->f_mapping->host)) ++ if (iocb->ki_flags & IOCB_DSYNC) + retval = dio_set_defer_completion(dio); + else if (!dio->inode->i_sb->s_dio_done_wq) { + /* +diff --git a/include/linux/fs.h b/include/linux/fs.h +index 440281f8564d..d54f41a63dbf 100644 +--- a/include/linux/fs.h ++++ b/include/linux/fs.h +@@ -3185,7 +3185,7 @@ static inline bool vma_is_fsdax(struct vm_area_struct *vma) + if (!vma_is_dax(vma)) + return false; + inode = file_inode(vma->vm_file); +- if (inode->i_mode == S_IFCHR) ++ if (S_ISCHR(inode->i_mode)) + return false; /* device-dax */ + return true; + } +diff --git a/include/linux/nospec.h b/include/linux/nospec.h +index fbc98e2c8228..132e3f5a2e0d 100644 +--- a/include/linux/nospec.h ++++ b/include/linux/nospec.h +@@ -72,7 +72,6 @@ static inline unsigned long array_index_mask_nospec(unsigned long index, + BUILD_BUG_ON(sizeof(_i) > sizeof(long)); \ + BUILD_BUG_ON(sizeof(_s) > sizeof(long)); \ + \ +- _i &= _mask; \ +- _i; \ ++ (typeof(_i)) (_i & _mask); \ + }) + #endif /* _LINUX_NOSPEC_H */ +diff --git a/include/net/udplite.h b/include/net/udplite.h +index 81bdbf97319b..9185e45b997f 100644 +--- a/include/net/udplite.h ++++ b/include/net/udplite.h +@@ -64,6 +64,7 @@ static inline int udplite_checksum_init(struct sk_buff *skb, struct udphdr *uh) + UDP_SKB_CB(skb)->cscov = cscov; + if (skb->ip_summed == CHECKSUM_COMPLETE) + skb->ip_summed = CHECKSUM_NONE; ++ skb->csum_valid = 0; + } + + return 0; +diff --git a/kernel/time/timer.c b/kernel/time/timer.c +index db5e6daadd94..9fe525f410bf 100644 +--- a/kernel/time/timer.c ++++ b/kernel/time/timer.c +@@ -1834,6 +1834,12 @@ int timers_dead_cpu(unsigned int cpu) + raw_spin_lock_irq(&new_base->lock); + raw_spin_lock_nested(&old_base->lock, SINGLE_DEPTH_NESTING); + ++ /* ++ * The current CPUs base clock might be stale. Update it ++ * before moving the timers over. ++ */ ++ forward_timer_base(new_base); ++ + BUG_ON(old_base->running_timer); + + for (i = 0; i < WHEEL_SIZE; i++) +diff --git a/net/bridge/br_sysfs_if.c b/net/bridge/br_sysfs_if.c +index 5d5d413a6cf8..a097a8613a02 100644 +--- a/net/bridge/br_sysfs_if.c ++++ b/net/bridge/br_sysfs_if.c +@@ -235,6 +235,9 @@ static ssize_t brport_show(struct kobject *kobj, + struct brport_attribute *brport_attr = to_brport_attr(attr); + struct net_bridge_port *p = to_brport(kobj); + ++ if (!brport_attr->show) ++ return -EINVAL; ++ + return brport_attr->show(p, buf); + } + +diff --git a/net/bridge/br_vlan.c b/net/bridge/br_vlan.c +index 233a30040c91..9b8a53568b0f 100644 +--- a/net/bridge/br_vlan.c ++++ b/net/bridge/br_vlan.c +@@ -157,6 +157,8 @@ static struct net_bridge_vlan *br_vlan_get_master(struct net_bridge *br, u16 vid + masterv = br_vlan_find(vg, vid); + if (WARN_ON(!masterv)) + return NULL; ++ refcount_set(&masterv->refcnt, 1); ++ return masterv; + } + refcount_inc(&masterv->refcnt); + +diff --git a/net/core/dev.c b/net/core/dev.c +index d33bbed640b1..c75ef9d8105a 100644 +--- a/net/core/dev.c ++++ b/net/core/dev.c +@@ -2343,8 +2343,11 @@ EXPORT_SYMBOL(netdev_set_num_tc); + */ + int netif_set_real_num_tx_queues(struct net_device *dev, unsigned int txq) + { ++ bool disabling; + int rc; + ++ disabling = txq < dev->real_num_tx_queues; ++ + if (txq < 1 || txq > dev->num_tx_queues) + return -EINVAL; + +@@ -2360,15 +2363,19 @@ int netif_set_real_num_tx_queues(struct net_device *dev, unsigned int txq) + if (dev->num_tc) + netif_setup_tc(dev, txq); + +- if (txq < dev->real_num_tx_queues) { ++ dev->real_num_tx_queues = txq; ++ ++ if (disabling) { ++ synchronize_net(); + qdisc_reset_all_tx_gt(dev, txq); + #ifdef CONFIG_XPS + netif_reset_xps_queues_gt(dev, txq); + #endif + } ++ } else { ++ dev->real_num_tx_queues = txq; + } + +- dev->real_num_tx_queues = txq; + return 0; + } + EXPORT_SYMBOL(netif_set_real_num_tx_queues); +diff --git a/net/core/gen_estimator.c b/net/core/gen_estimator.c +index 00ecec4891f3..7f980bd7426e 100644 +--- a/net/core/gen_estimator.c ++++ b/net/core/gen_estimator.c +@@ -66,6 +66,7 @@ struct net_rate_estimator { + static void est_fetch_counters(struct net_rate_estimator *e, + struct gnet_stats_basic_packed *b) + { ++ memset(b, 0, sizeof(*b)); + if (e->stats_lock) + spin_lock(e->stats_lock); + +diff --git a/net/ipv4/fib_semantics.c b/net/ipv4/fib_semantics.c +index aff3751df950..1ee6c0d8dde4 100644 +--- a/net/ipv4/fib_semantics.c ++++ b/net/ipv4/fib_semantics.c +@@ -654,6 +654,11 @@ int fib_nh_match(struct fib_config *cfg, struct fib_info *fi, + fi->fib_nh, cfg, extack)) + return 1; + } ++#ifdef CONFIG_IP_ROUTE_CLASSID ++ if (cfg->fc_flow && ++ cfg->fc_flow != fi->fib_nh->nh_tclassid) ++ return 1; ++#endif + if ((!cfg->fc_oif || cfg->fc_oif == fi->fib_nh->nh_oif) && + (!cfg->fc_gw || cfg->fc_gw == fi->fib_nh->nh_gw)) + return 0; +diff --git a/net/ipv4/route.c b/net/ipv4/route.c +index 0ba88efca7ad..9ff06c5051ae 100644 +--- a/net/ipv4/route.c ++++ b/net/ipv4/route.c +@@ -128,10 +128,13 @@ static int ip_rt_redirect_silence __read_mostly = ((HZ / 50) << (9 + 1)); + static int ip_rt_error_cost __read_mostly = HZ; + static int ip_rt_error_burst __read_mostly = 5 * HZ; + static int ip_rt_mtu_expires __read_mostly = 10 * 60 * HZ; +-static int ip_rt_min_pmtu __read_mostly = 512 + 20 + 20; ++static u32 ip_rt_min_pmtu __read_mostly = 512 + 20 + 20; + static int ip_rt_min_advmss __read_mostly = 256; + + static int ip_rt_gc_timeout __read_mostly = RT_GC_TIMEOUT; ++ ++static int ip_min_valid_pmtu __read_mostly = IPV4_MIN_MTU; ++ + /* + * Interface to generic destination cache. + */ +@@ -1829,6 +1832,8 @@ int fib_multipath_hash(const struct fib_info *fi, const struct flowi4 *fl4, + return skb_get_hash_raw(skb) >> 1; + memset(&hash_keys, 0, sizeof(hash_keys)); + skb_flow_dissect_flow_keys(skb, &keys, flag); ++ ++ hash_keys.control.addr_type = FLOW_DISSECTOR_KEY_IPV4_ADDRS; + hash_keys.addrs.v4addrs.src = keys.addrs.v4addrs.src; + hash_keys.addrs.v4addrs.dst = keys.addrs.v4addrs.dst; + hash_keys.ports.src = keys.ports.src; +@@ -2934,7 +2939,8 @@ static struct ctl_table ipv4_route_table[] = { + .data = &ip_rt_min_pmtu, + .maxlen = sizeof(int), + .mode = 0644, +- .proc_handler = proc_dointvec, ++ .proc_handler = proc_dointvec_minmax, ++ .extra1 = &ip_min_valid_pmtu, + }, + { + .procname = "min_adv_mss", +diff --git a/net/ipv4/tcp_input.c b/net/ipv4/tcp_input.c +index d9d215e27b8a..14474acea0bb 100644 +--- a/net/ipv4/tcp_input.c ++++ b/net/ipv4/tcp_input.c +@@ -2013,11 +2013,6 @@ void tcp_enter_loss(struct sock *sk) + /* F-RTO RFC5682 sec 3.1 step 1: retransmit SND.UNA if no previous + * loss recovery is underway except recurring timeout(s) on + * the same SND.UNA (sec 3.2). Disable F-RTO on path MTU probing +- * +- * In theory F-RTO can be used repeatedly during loss recovery. +- * In practice this interacts badly with broken middle-boxes that +- * falsely raise the receive window, which results in repeated +- * timeouts and stop-and-go behavior. + */ + tp->frto = sysctl_tcp_frto && + (new_recovery || icsk->icsk_retransmits) && +@@ -2699,18 +2694,14 @@ static void tcp_process_loss(struct sock *sk, int flag, bool is_dupack, + tcp_try_undo_loss(sk, false)) + return; + +- /* The ACK (s)acks some never-retransmitted data meaning not all +- * the data packets before the timeout were lost. Therefore we +- * undo the congestion window and state. This is essentially +- * the operation in F-RTO (RFC5682 section 3.1 step 3.b). Since +- * a retransmitted skb is permantly marked, we can apply such an +- * operation even if F-RTO was not used. +- */ +- if ((flag & FLAG_ORIG_SACK_ACKED) && +- tcp_try_undo_loss(sk, tp->undo_marker)) +- return; +- + if (tp->frto) { /* F-RTO RFC5682 sec 3.1 (sack enhanced version). */ ++ /* Step 3.b. A timeout is spurious if not all data are ++ * lost, i.e., never-retransmitted data are (s)acked. ++ */ ++ if ((flag & FLAG_ORIG_SACK_ACKED) && ++ tcp_try_undo_loss(sk, true)) ++ return; ++ + if (after(tp->snd_nxt, tp->high_seq)) { + if (flag & FLAG_DATA_SACKED || is_dupack) + tp->frto = 0; /* Step 3.a. loss was real */ +@@ -4020,6 +4011,7 @@ void tcp_reset(struct sock *sk) + /* This barrier is coupled with smp_rmb() in tcp_poll() */ + smp_wmb(); + ++ tcp_write_queue_purge(sk); + tcp_done(sk); + + if (!sock_flag(sk, SOCK_DEAD)) +diff --git a/net/ipv4/tcp_output.c b/net/ipv4/tcp_output.c +index cd3d60bb7cc8..83d11cd2eb65 100644 +--- a/net/ipv4/tcp_output.c ++++ b/net/ipv4/tcp_output.c +@@ -1681,7 +1681,7 @@ u32 tcp_tso_autosize(const struct sock *sk, unsigned int mss_now, + */ + segs = max_t(u32, bytes / mss_now, min_tso_segs); + +- return min_t(u32, segs, sk->sk_gso_max_segs); ++ return segs; + } + EXPORT_SYMBOL(tcp_tso_autosize); + +@@ -1693,8 +1693,10 @@ static u32 tcp_tso_segs(struct sock *sk, unsigned int mss_now) + const struct tcp_congestion_ops *ca_ops = inet_csk(sk)->icsk_ca_ops; + u32 tso_segs = ca_ops->tso_segs_goal ? ca_ops->tso_segs_goal(sk) : 0; + +- return tso_segs ? : +- tcp_tso_autosize(sk, mss_now, sysctl_tcp_min_tso_segs); ++ if (!tso_segs) ++ tso_segs = tcp_tso_autosize(sk, mss_now, ++ sysctl_tcp_min_tso_segs); ++ return min_t(u32, tso_segs, sk->sk_gso_max_segs); + } + + /* Returns the portion of skb which can be sent right away */ +@@ -1973,6 +1975,24 @@ static inline void tcp_mtu_check_reprobe(struct sock *sk) + } + } + ++static bool tcp_can_coalesce_send_queue_head(struct sock *sk, int len) ++{ ++ struct sk_buff *skb, *next; ++ ++ skb = tcp_send_head(sk); ++ tcp_for_write_queue_from_safe(skb, next, sk) { ++ if (len <= skb->len) ++ break; ++ ++ if (unlikely(TCP_SKB_CB(skb)->eor)) ++ return false; ++ ++ len -= skb->len; ++ } ++ ++ return true; ++} ++ + /* Create a new MTU probe if we are ready. + * MTU probe is regularly attempting to increase the path MTU by + * deliberately sending larger packets. This discovers routing +@@ -2045,6 +2065,9 @@ static int tcp_mtu_probe(struct sock *sk) + return 0; + } + ++ if (!tcp_can_coalesce_send_queue_head(sk, probe_size)) ++ return -1; ++ + /* We're allowed to probe. Build it now. */ + nskb = sk_stream_alloc_skb(sk, probe_size, GFP_ATOMIC, false); + if (!nskb) +@@ -2080,6 +2103,10 @@ static int tcp_mtu_probe(struct sock *sk) + /* We've eaten all the data from this skb. + * Throw it away. */ + TCP_SKB_CB(nskb)->tcp_flags |= TCP_SKB_CB(skb)->tcp_flags; ++ /* If this is the last SKB we copy and eor is set ++ * we need to propagate it to the new skb. ++ */ ++ TCP_SKB_CB(nskb)->eor = TCP_SKB_CB(skb)->eor; + tcp_unlink_write_queue(skb, sk); + sk_wmem_free_skb(sk, skb); + } else { +diff --git a/net/ipv4/udp.c b/net/ipv4/udp.c +index ebfbccae62fd..c79fa6f6b758 100644 +--- a/net/ipv4/udp.c ++++ b/net/ipv4/udp.c +@@ -2032,6 +2032,11 @@ static inline int udp4_csum_init(struct sk_buff *skb, struct udphdr *uh, + err = udplite_checksum_init(skb, uh); + if (err) + return err; ++ ++ if (UDP_SKB_CB(skb)->partial_cov) { ++ skb->csum = inet_compute_pseudo(skb, proto); ++ return 0; ++ } + } + + /* Note, we are only interested in != 0 or == 0, thus the +diff --git a/net/ipv6/ip6_checksum.c b/net/ipv6/ip6_checksum.c +index ec43d18b5ff9..547515e8450a 100644 +--- a/net/ipv6/ip6_checksum.c ++++ b/net/ipv6/ip6_checksum.c +@@ -73,6 +73,11 @@ int udp6_csum_init(struct sk_buff *skb, struct udphdr *uh, int proto) + err = udplite_checksum_init(skb, uh); + if (err) + return err; ++ ++ if (UDP_SKB_CB(skb)->partial_cov) { ++ skb->csum = ip6_compute_pseudo(skb, proto); ++ return 0; ++ } + } + + /* To support RFC 6936 (allow zero checksum in UDP/IPV6 for tunnels) +diff --git a/net/ipv6/sit.c b/net/ipv6/sit.c +index e79854cc5790..cac815cc8600 100644 +--- a/net/ipv6/sit.c ++++ b/net/ipv6/sit.c +@@ -176,7 +176,7 @@ static void ipip6_tunnel_clone_6rd(struct net_device *dev, struct sit_net *sitn) + #ifdef CONFIG_IPV6_SIT_6RD + struct ip_tunnel *t = netdev_priv(dev); + +- if (t->dev == sitn->fb_tunnel_dev) { ++ if (dev == sitn->fb_tunnel_dev) { + ipv6_addr_set(&t->ip6rd.prefix, htonl(0x20020000), 0, 0, 0); + t->ip6rd.relay_prefix = 0; + t->ip6rd.prefixlen = 16; +diff --git a/net/netlink/af_netlink.c b/net/netlink/af_netlink.c +index 533fd0503ba0..9219bc134109 100644 +--- a/net/netlink/af_netlink.c ++++ b/net/netlink/af_netlink.c +@@ -2276,7 +2276,7 @@ int __netlink_dump_start(struct sock *ssk, struct sk_buff *skb, + if (cb->start) { + ret = cb->start(cb); + if (ret) +- goto error_unlock; ++ goto error_put; + } + + nlk->cb_running = true; +@@ -2296,6 +2296,8 @@ int __netlink_dump_start(struct sock *ssk, struct sk_buff *skb, + */ + return -EINTR; + ++error_put: ++ module_put(control->module); + error_unlock: + sock_put(sk); + mutex_unlock(nlk->cb_mutex); +diff --git a/net/netlink/genetlink.c b/net/netlink/genetlink.c +index d444daf1ac04..6f02499ef007 100644 +--- a/net/netlink/genetlink.c ++++ b/net/netlink/genetlink.c +@@ -1081,6 +1081,7 @@ static int genlmsg_mcast(struct sk_buff *skb, u32 portid, unsigned long group, + { + struct sk_buff *tmp; + struct net *net, *prev = NULL; ++ bool delivered = false; + int err; + + for_each_net_rcu(net) { +@@ -1092,14 +1093,21 @@ static int genlmsg_mcast(struct sk_buff *skb, u32 portid, unsigned long group, + } + err = nlmsg_multicast(prev->genl_sock, tmp, + portid, group, flags); +- if (err) ++ if (!err) ++ delivered = true; ++ else if (err != -ESRCH) + goto error; + } + + prev = net; + } + +- return nlmsg_multicast(prev->genl_sock, skb, portid, group, flags); ++ err = nlmsg_multicast(prev->genl_sock, skb, portid, group, flags); ++ if (!err) ++ delivered = true; ++ else if (err != -ESRCH) ++ goto error; ++ return delivered ? 0 : -ESRCH; + error: + kfree_skb(skb); + return err; +diff --git a/net/rxrpc/output.c b/net/rxrpc/output.c +index 71e6f713fbe7..5b67cb5d47f0 100644 +--- a/net/rxrpc/output.c ++++ b/net/rxrpc/output.c +@@ -395,7 +395,7 @@ int rxrpc_send_data_packet(struct rxrpc_call *call, struct sk_buff *skb, + (char *)&opt, sizeof(opt)); + if (ret == 0) { + ret = kernel_sendmsg(conn->params.local->socket, &msg, +- iov, 1, iov[0].iov_len); ++ iov, 2, len); + + opt = IPV6_PMTUDISC_DO; + kernel_setsockopt(conn->params.local->socket, +diff --git a/net/sched/cls_api.c b/net/sched/cls_api.c +index 934c239cf98d..c2fab4bcb8be 100644 +--- a/net/sched/cls_api.c ++++ b/net/sched/cls_api.c +@@ -871,13 +871,18 @@ static int tc_dump_tfilter(struct sk_buff *skb, struct netlink_callback *cb) + if (tca[TCA_CHAIN] && + nla_get_u32(tca[TCA_CHAIN]) != chain->index) + continue; +- if (!tcf_chain_dump(chain, skb, cb, index_start, &index)) ++ if (!tcf_chain_dump(chain, skb, cb, index_start, &index)) { ++ err = -EMSGSIZE; + break; ++ } + } + + cb->args[0] = index; + + out: ++ /* If we did no progress, the error (EMSGSIZE) is real */ ++ if (skb->len == 0 && err) ++ return err; + return skb->len; + } + +diff --git a/net/sched/cls_u32.c b/net/sched/cls_u32.c +index b58eccb21f03..ba37d8f57e68 100644 +--- a/net/sched/cls_u32.c ++++ b/net/sched/cls_u32.c +@@ -398,10 +398,12 @@ static int u32_init(struct tcf_proto *tp) + static int u32_destroy_key(struct tcf_proto *tp, struct tc_u_knode *n, + bool free_pf) + { ++ struct tc_u_hnode *ht = rtnl_dereference(n->ht_down); ++ + tcf_exts_destroy(&n->exts); + tcf_exts_put_net(&n->exts); +- if (n->ht_down) +- n->ht_down->refcnt--; ++ if (ht && --ht->refcnt == 0) ++ kfree(ht); + #ifdef CONFIG_CLS_U32_PERF + if (free_pf) + free_percpu(n->pf); +@@ -649,16 +651,15 @@ static void u32_destroy(struct tcf_proto *tp) + + hlist_del(&tp_c->hnode); + +- for (ht = rtnl_dereference(tp_c->hlist); +- ht; +- ht = rtnl_dereference(ht->next)) { +- ht->refcnt--; +- u32_clear_hnode(tp, ht); +- } +- + while ((ht = rtnl_dereference(tp_c->hlist)) != NULL) { ++ u32_clear_hnode(tp, ht); + RCU_INIT_POINTER(tp_c->hlist, ht->next); +- kfree_rcu(ht, rcu); ++ ++ /* u32_destroy_key() will later free ht for us, if it's ++ * still referenced by some knode ++ */ ++ if (--ht->refcnt == 0) ++ kfree_rcu(ht, rcu); + } + + kfree(tp_c); +@@ -927,7 +928,8 @@ static int u32_change(struct net *net, struct sk_buff *in_skb, + if (TC_U32_KEY(n->handle) == 0) + return -EINVAL; + +- if (n->flags != flags) ++ if ((n->flags ^ flags) & ++ ~(TCA_CLS_FLAGS_IN_HW | TCA_CLS_FLAGS_NOT_IN_HW)) + return -EINVAL; + + new = u32_init_knode(tp, n); +diff --git a/net/sctp/input.c b/net/sctp/input.c +index 141c9c466ec1..0247cc432e02 100644 +--- a/net/sctp/input.c ++++ b/net/sctp/input.c +@@ -897,15 +897,12 @@ int sctp_hash_transport(struct sctp_transport *t) + rhl_for_each_entry_rcu(transport, tmp, list, node) + if (transport->asoc->ep == t->asoc->ep) { + rcu_read_unlock(); +- err = -EEXIST; +- goto out; ++ return -EEXIST; + } + rcu_read_unlock(); + + err = rhltable_insert_key(&sctp_transport_hashtable, &arg, + &t->node, sctp_hash_params); +- +-out: + if (err) + pr_err_once("insert transport fail, errno %d\n", err); + +diff --git a/net/sctp/ipv6.c b/net/sctp/ipv6.c +index 3b18085e3b10..f27a9718554c 100644 +--- a/net/sctp/ipv6.c ++++ b/net/sctp/ipv6.c +@@ -326,8 +326,10 @@ static void sctp_v6_get_dst(struct sctp_transport *t, union sctp_addr *saddr, + final_p = fl6_update_dst(fl6, rcu_dereference(np->opt), &final); + bdst = ip6_dst_lookup_flow(sk, fl6, final_p); + +- if (!IS_ERR(bdst) && +- ipv6_chk_addr(dev_net(bdst->dev), ++ if (IS_ERR(bdst)) ++ continue; ++ ++ if (ipv6_chk_addr(dev_net(bdst->dev), + &laddr->a.v6.sin6_addr, bdst->dev, 1)) { + if (!IS_ERR_OR_NULL(dst)) + dst_release(dst); +@@ -336,8 +338,10 @@ static void sctp_v6_get_dst(struct sctp_transport *t, union sctp_addr *saddr, + } + + bmatchlen = sctp_v6_addr_match_len(daddr, &laddr->a); +- if (matchlen > bmatchlen) ++ if (matchlen > bmatchlen) { ++ dst_release(bdst); + continue; ++ } + + if (!IS_ERR_OR_NULL(dst)) + dst_release(dst); +diff --git a/net/sctp/protocol.c b/net/sctp/protocol.c +index fcd80feb293f..df22a9c352ad 100644 +--- a/net/sctp/protocol.c ++++ b/net/sctp/protocol.c +@@ -514,22 +514,20 @@ static void sctp_v4_get_dst(struct sctp_transport *t, union sctp_addr *saddr, + if (IS_ERR(rt)) + continue; + +- if (!dst) +- dst = &rt->dst; +- + /* Ensure the src address belongs to the output + * interface. + */ + odev = __ip_dev_find(sock_net(sk), laddr->a.v4.sin_addr.s_addr, + false); + if (!odev || odev->ifindex != fl4->flowi4_oif) { +- if (&rt->dst != dst) ++ if (!dst) ++ dst = &rt->dst; ++ else + dst_release(&rt->dst); + continue; + } + +- if (dst != &rt->dst) +- dst_release(dst); ++ dst_release(dst); + dst = &rt->dst; + break; + } +diff --git a/net/sctp/sm_make_chunk.c b/net/sctp/sm_make_chunk.c +index 514465b03829..e4a400f88168 100644 +--- a/net/sctp/sm_make_chunk.c ++++ b/net/sctp/sm_make_chunk.c +@@ -1378,9 +1378,14 @@ static struct sctp_chunk *_sctp_make_chunk(const struct sctp_association *asoc, + struct sctp_chunk *retval; + struct sk_buff *skb; + struct sock *sk; ++ int chunklen; ++ ++ chunklen = SCTP_PAD4(sizeof(*chunk_hdr) + paylen); ++ if (chunklen > SCTP_MAX_CHUNK_LEN) ++ goto nodata; + + /* No need to allocate LL here, as this is only a chunk. */ +- skb = alloc_skb(SCTP_PAD4(sizeof(*chunk_hdr) + paylen), gfp); ++ skb = alloc_skb(chunklen, gfp); + if (!skb) + goto nodata; + +diff --git a/sound/core/control.c b/sound/core/control.c +index 56b3e2d49c82..af7e6165e21e 100644 +--- a/sound/core/control.c ++++ b/sound/core/control.c +@@ -888,7 +888,7 @@ static int snd_ctl_elem_read(struct snd_card *card, + + index_offset = snd_ctl_get_ioff(kctl, &control->id); + vd = &kctl->vd[index_offset]; +- if (!(vd->access & SNDRV_CTL_ELEM_ACCESS_READ) && kctl->get == NULL) ++ if (!(vd->access & SNDRV_CTL_ELEM_ACCESS_READ) || kctl->get == NULL) + return -EPERM; + + snd_ctl_build_ioff(&control->id, kctl, index_offset); +diff --git a/sound/pci/hda/hda_intel.c b/sound/pci/hda/hda_intel.c +index c71dcacea807..96143df19b21 100644 +--- a/sound/pci/hda/hda_intel.c ++++ b/sound/pci/hda/hda_intel.c +@@ -181,7 +181,7 @@ static const struct kernel_param_ops param_ops_xint = { + }; + #define param_check_xint param_check_int + +-static int power_save = CONFIG_SND_HDA_POWER_SAVE_DEFAULT; ++static int power_save = -1; + module_param(power_save, xint, 0644); + MODULE_PARM_DESC(power_save, "Automatic power-saving timeout " + "(in second, 0 = disable)."); +@@ -2186,6 +2186,24 @@ static int azx_probe(struct pci_dev *pci, + return err; + } + ++#ifdef CONFIG_PM ++/* On some boards setting power_save to a non 0 value leads to clicking / ++ * popping sounds when ever we enter/leave powersaving mode. Ideally we would ++ * figure out how to avoid these sounds, but that is not always feasible. ++ * So we keep a list of devices where we disable powersaving as its known ++ * to causes problems on these devices. ++ */ ++static struct snd_pci_quirk power_save_blacklist[] = { ++ /* https://bugzilla.redhat.com/show_bug.cgi?id=1525104 */ ++ SND_PCI_QUIRK(0x1849, 0x0c0c, "Asrock B85M-ITX", 0), ++ /* https://bugzilla.redhat.com/show_bug.cgi?id=1525104 */ ++ SND_PCI_QUIRK(0x1043, 0x8733, "Asus Prime X370-Pro", 0), ++ /* https://bugzilla.kernel.org/show_bug.cgi?id=198611 */ ++ SND_PCI_QUIRK(0x17aa, 0x2227, "Lenovo X1 Carbon 3rd Gen", 0), ++ {} ++}; ++#endif /* CONFIG_PM */ ++ + /* number of codec slots for each chipset: 0 = default slots (i.e. 4) */ + static unsigned int azx_max_codecs[AZX_NUM_DRIVERS] = { + [AZX_DRIVER_NVIDIA] = 8, +@@ -2198,6 +2216,7 @@ static int azx_probe_continue(struct azx *chip) + struct hdac_bus *bus = azx_bus(chip); + struct pci_dev *pci = chip->pci; + int dev = chip->dev_index; ++ int val; + int err; + + hda->probe_continued = 1; +@@ -2278,7 +2297,22 @@ static int azx_probe_continue(struct azx *chip) + + chip->running = 1; + azx_add_card_list(chip); +- snd_hda_set_power_save(&chip->bus, power_save * 1000); ++ ++ val = power_save; ++#ifdef CONFIG_PM ++ if (val == -1) { ++ const struct snd_pci_quirk *q; ++ ++ val = CONFIG_SND_HDA_POWER_SAVE_DEFAULT; ++ q = snd_pci_quirk_lookup(chip->pci, power_save_blacklist); ++ if (q && val) { ++ dev_info(chip->card->dev, "device %04x:%04x is on the power_save blacklist, forcing power_save to 0\n", ++ q->subvendor, q->subdevice); ++ val = 0; ++ } ++ } ++#endif /* CONFIG_PM */ ++ snd_hda_set_power_save(&chip->bus, val * 1000); + if (azx_has_pm_runtime(chip) || hda->use_vga_switcheroo) + pm_runtime_put_autosuspend(&pci->dev); + +diff --git a/sound/pci/hda/patch_realtek.c b/sound/pci/hda/patch_realtek.c +index b7acffdf16a4..454476b47b79 100644 +--- a/sound/pci/hda/patch_realtek.c ++++ b/sound/pci/hda/patch_realtek.c +@@ -4852,13 +4852,14 @@ static void alc_fixup_tpt470_dock(struct hda_codec *codec, + + if (action == HDA_FIXUP_ACT_PRE_PROBE) { + spec->parse_flags = HDA_PINCFG_NO_HP_FIXUP; ++ snd_hda_apply_pincfgs(codec, pincfgs); ++ } else if (action == HDA_FIXUP_ACT_INIT) { + /* Enable DOCK device */ + snd_hda_codec_write(codec, 0x17, 0, + AC_VERB_SET_CONFIG_DEFAULT_BYTES_3, 0); + /* Enable DOCK device */ + snd_hda_codec_write(codec, 0x19, 0, + AC_VERB_SET_CONFIG_DEFAULT_BYTES_3, 0); +- snd_hda_apply_pincfgs(codec, pincfgs); + } + } + +diff --git a/sound/usb/quirks-table.h b/sound/usb/quirks-table.h +index 8a59d4782a0f..69bf5cf1e91e 100644 +--- a/sound/usb/quirks-table.h ++++ b/sound/usb/quirks-table.h +@@ -3277,4 +3277,51 @@ AU0828_DEVICE(0x2040, 0x7270, "Hauppauge", "HVR-950Q"), + } + }, + ++{ ++ /* ++ * Bower's & Wilkins PX headphones only support the 48 kHz sample rate ++ * even though it advertises more. The capture interface doesn't work ++ * even on windows. ++ */ ++ USB_DEVICE(0x19b5, 0x0021), ++ .driver_info = (unsigned long) &(const struct snd_usb_audio_quirk) { ++ .ifnum = QUIRK_ANY_INTERFACE, ++ .type = QUIRK_COMPOSITE, ++ .data = (const struct snd_usb_audio_quirk[]) { ++ { ++ .ifnum = 0, ++ .type = QUIRK_AUDIO_STANDARD_MIXER, ++ }, ++ /* Capture */ ++ { ++ .ifnum = 1, ++ .type = QUIRK_IGNORE_INTERFACE, ++ }, ++ /* Playback */ ++ { ++ .ifnum = 2, ++ .type = QUIRK_AUDIO_FIXED_ENDPOINT, ++ .data = &(const struct audioformat) { ++ .formats = SNDRV_PCM_FMTBIT_S16_LE, ++ .channels = 2, ++ .iface = 2, ++ .altsetting = 1, ++ .altset_idx = 1, ++ .attributes = UAC_EP_CS_ATTR_FILL_MAX | ++ UAC_EP_CS_ATTR_SAMPLE_RATE, ++ .endpoint = 0x03, ++ .ep_attr = USB_ENDPOINT_XFER_ISOC, ++ .rates = SNDRV_PCM_RATE_48000, ++ .rate_min = 48000, ++ .rate_max = 48000, ++ .nr_rates = 1, ++ .rate_table = (unsigned int[]) { ++ 48000 ++ } ++ } ++ }, ++ } ++ } ++}, ++ + #undef USB_DEVICE_VENDOR_SPEC +diff --git a/sound/x86/intel_hdmi_audio.c b/sound/x86/intel_hdmi_audio.c +index a0951505c7f5..697872d8308e 100644 +--- a/sound/x86/intel_hdmi_audio.c ++++ b/sound/x86/intel_hdmi_audio.c +@@ -1827,6 +1827,8 @@ static int hdmi_lpe_audio_probe(struct platform_device *pdev) + ctx->port = port; + ctx->pipe = -1; + ++ spin_lock_init(&ctx->had_spinlock); ++ mutex_init(&ctx->mutex); + INIT_WORK(&ctx->hdmi_audio_wq, had_audio_wq); + + ret = snd_pcm_new(card, INTEL_HAD, port, MAX_PB_STREAMS, +diff --git a/virt/kvm/kvm_main.c b/virt/kvm/kvm_main.c +index 8401774f5aeb..d81af263f50b 100644 +--- a/virt/kvm/kvm_main.c ++++ b/virt/kvm/kvm_main.c +@@ -975,8 +975,7 @@ int __kvm_set_memory_region(struct kvm *kvm, + /* Check for overlaps */ + r = -EEXIST; + kvm_for_each_memslot(slot, __kvm_memslots(kvm, as_id)) { +- if ((slot->id >= KVM_USER_MEM_SLOTS) || +- (slot->id == id)) ++ if (slot->id == id) + continue; + if (!((base_gfn + npages <= slot->base_gfn) || + (base_gfn >= slot->base_gfn + slot->npages))) diff --git a/kernel/kernel/files/patches/mageia/pti32bit-0001-x86-asm-offsets-Move-TSS_sp0-and-TSS_sp1-to-asm-offs.patch b/kernel/kernel/files/patches/mageia/pti32bit-0001-x86-asm-offsets-Move-TSS_sp0-and-TSS_sp1-to-asm-offs.patch index 4a7877fe..b4edc558 100644 --- a/kernel/kernel/files/patches/mageia/pti32bit-0001-x86-asm-offsets-Move-TSS_sp0-and-TSS_sp1-to-asm-offs.patch +++ b/kernel/kernel/files/patches/mageia/pti32bit-0001-x86-asm-offsets-Move-TSS_sp0-and-TSS_sp1-to-asm-offs.patch @@ -1,7 +1,7 @@ From 3b7711fd3adb7d6b812a33da4a4639ddce6522b6 Mon Sep 17 00:00:00 2001 From: Joerg Roedel Date: Fri, 19 Jan 2018 13:46:20 +0100 -Subject: [PATCH 01/31] x86/asm-offsets: Move TSS_sp0 and TSS_sp1 to +Subject: [PATCH 01/34] x86/asm-offsets: Move TSS_sp0 and TSS_sp1 to asm-offsets.c These offsets will be used in 32 bit assembly code as well, @@ -40,5 +40,5 @@ index bf51e51d808d..d2eba73a5f8a 100644 #ifdef CONFIG_CC_STACKPROTECTOR -- -2.13.6 +2.16.2 diff --git a/kernel/kernel/files/patches/mageia/pti32bit-0002-x86-entry-32-Rename-TSS_sysenter_sp0-to-TSS_entry_st.patch b/kernel/kernel/files/patches/mageia/pti32bit-0002-x86-entry-32-Rename-TSS_sysenter_sp0-to-TSS_entry_st.patch index d228b31f..1d9b8f47 100644 --- a/kernel/kernel/files/patches/mageia/pti32bit-0002-x86-entry-32-Rename-TSS_sysenter_sp0-to-TSS_entry_st.patch +++ b/kernel/kernel/files/patches/mageia/pti32bit-0002-x86-entry-32-Rename-TSS_sysenter_sp0-to-TSS_entry_st.patch @@ -1,7 +1,7 @@ From 52806123bdb0b558a5b4fbfa132bae32e53b008a Mon Sep 17 00:00:00 2001 From: Joerg Roedel Date: Mon, 15 Jan 2018 18:20:15 +0100 -Subject: [PATCH 02/31] x86/entry/32: Rename TSS_sysenter_sp0 to +Subject: [PATCH 02/34] x86/entry/32: Rename TSS_sysenter_sp0 to TSS_entry_stack The stack address doesn't need to be stored in tss.sp0 if @@ -44,5 +44,5 @@ index fa1261eefa16..f452bfdc485a 100644 #ifdef CONFIG_CC_STACKPROTECTOR -- -2.13.6 +2.16.2 diff --git a/kernel/kernel/files/patches/mageia/pti32bit-0003-x86-entry-32-Load-task-stack-from-x86_tss.sp1-in-SYS.patch b/kernel/kernel/files/patches/mageia/pti32bit-0003-x86-entry-32-Load-task-stack-from-x86_tss.sp1-in-SYS.patch index cf3e210d..6a891571 100644 --- a/kernel/kernel/files/patches/mageia/pti32bit-0003-x86-entry-32-Load-task-stack-from-x86_tss.sp1-in-SYS.patch +++ b/kernel/kernel/files/patches/mageia/pti32bit-0003-x86-entry-32-Load-task-stack-from-x86_tss.sp1-in-SYS.patch @@ -1,7 +1,7 @@ From b696a2c46d9b9937b816b11ff2ec72aa0b65f204 Mon Sep 17 00:00:00 2001 From: Joerg Roedel Date: Fri, 19 Jan 2018 13:33:37 +0100 -Subject: [PATCH 03/31] x86/entry/32: Load task stack from x86_tss.sp1 in +Subject: [PATCH 03/34] x86/entry/32: Load task stack from x86_tss.sp1 in SYSENTER handler We want x86_tss.sp0 point to the entry stack later to use @@ -45,5 +45,5 @@ index 5224c6099184..097d36a64889 100644 /* * Restore %gs if needed (which is common) -- -2.13.6 +2.16.2 diff --git a/kernel/kernel/files/patches/mageia/pti32bit-0004-x86-entry-32-Put-ESPFIX-code-into-a-macro.patch b/kernel/kernel/files/patches/mageia/pti32bit-0004-x86-entry-32-Put-ESPFIX-code-into-a-macro.patch index 488ab4fc..7a6d04ed 100644 --- a/kernel/kernel/files/patches/mageia/pti32bit-0004-x86-entry-32-Put-ESPFIX-code-into-a-macro.patch +++ b/kernel/kernel/files/patches/mageia/pti32bit-0004-x86-entry-32-Put-ESPFIX-code-into-a-macro.patch @@ -1,7 +1,7 @@ From 7c97243c7694dc1c0e0ad73bc17bdc2c553225ac Mon Sep 17 00:00:00 2001 From: Joerg Roedel Date: Wed, 31 Jan 2018 10:50:02 +0100 -Subject: [PATCH 04/31] x86/entry/32: Put ESPFIX code into a macro +Subject: [PATCH 04/34] x86/entry/32: Put ESPFIX code into a macro This makes it easier to split up the shared iret code path. @@ -133,5 +133,5 @@ index e65977615616..0289bde37a08 100644 .macro FIXUP_ESPFIX_STACK -- -2.13.6 +2.16.2 diff --git a/kernel/kernel/files/patches/mageia/pti32bit-0005-x86-entry-32-Unshare-NMI-return-path.patch b/kernel/kernel/files/patches/mageia/pti32bit-0005-x86-entry-32-Unshare-NMI-return-path.patch index c3171963..33a1f95e 100644 --- a/kernel/kernel/files/patches/mageia/pti32bit-0005-x86-entry-32-Unshare-NMI-return-path.patch +++ b/kernel/kernel/files/patches/mageia/pti32bit-0005-x86-entry-32-Unshare-NMI-return-path.patch @@ -1,7 +1,7 @@ From c66ec22d03296d1311197aaef753c1c320eed225 Mon Sep 17 00:00:00 2001 From: Joerg Roedel Date: Wed, 31 Jan 2018 10:58:38 +0100 -Subject: [PATCH 05/31] x86/entry/32: Unshare NMI return path +Subject: [PATCH 05/34] x86/entry/32: Unshare NMI return path NMI will no longer use most of the shared return path, because NMI needs special handling when the CR3 switches for @@ -39,5 +39,5 @@ index 0289bde37a08..00ae759a7c44 100644 #ifdef CONFIG_X86_ESPFIX32 .Lnmi_espfix_stack: -- -2.13.6 +2.16.2 diff --git a/kernel/kernel/files/patches/mageia/pti32bit-0006-x86-entry-32-Split-off-return-to-kernel-path.patch b/kernel/kernel/files/patches/mageia/pti32bit-0006-x86-entry-32-Split-off-return-to-kernel-path.patch index 523e0f90..e47ab3d3 100644 --- a/kernel/kernel/files/patches/mageia/pti32bit-0006-x86-entry-32-Split-off-return-to-kernel-path.patch +++ b/kernel/kernel/files/patches/mageia/pti32bit-0006-x86-entry-32-Split-off-return-to-kernel-path.patch @@ -1,7 +1,7 @@ From 916e5e906873de859d8a87c1ffb0323e167d1a44 Mon Sep 17 00:00:00 2001 From: Joerg Roedel Date: Wed, 31 Jan 2018 11:07:32 +0100 -Subject: [PATCH 06/31] x86/entry/32: Split off return-to-kernel path +Subject: [PATCH 06/34] x86/entry/32: Split off return-to-kernel path Use a separate return path when we know we are returning to the kernel. This allows us to put the PTI cr3-switch and the @@ -51,5 +51,5 @@ index 00ae759a7c44..9bd77183965f 100644 ENTRY(iret_exc ) pushl $0 # no error code -- -2.13.6 +2.16.2 diff --git a/kernel/kernel/files/patches/mageia/pti32bit-0007-x86-entry-32-Restore-segments-before-int-registers.patch b/kernel/kernel/files/patches/mageia/pti32bit-0007-x86-entry-32-Restore-segments-before-int-registers.patch index 52c548e7..2fd4c846 100644 --- a/kernel/kernel/files/patches/mageia/pti32bit-0007-x86-entry-32-Restore-segments-before-int-registers.patch +++ b/kernel/kernel/files/patches/mageia/pti32bit-0007-x86-entry-32-Restore-segments-before-int-registers.patch @@ -1,7 +1,7 @@ From c19ad15b16ec8908794459f28b44eca889a925f7 Mon Sep 17 00:00:00 2001 From: Joerg Roedel Date: Wed, 31 Jan 2018 11:29:59 +0100 -Subject: [PATCH 07/31] x86/entry/32: Restore segments before int registers +Subject: [PATCH 07/34] x86/entry/32: Restore segments before int registers Restoring the segments can cause exceptions that need to be handled. With PTI enabled, we still need to be on kernel cr3 @@ -27,18 +27,18 @@ diff --git a/arch/x86/entry/entry_32.S b/arch/x86/entry/entry_32.S index 9bd77183965f..b39c5e210b43 100644 --- a/arch/x86/entry/entry_32.S +++ b/arch/x86/entry/entry_32.S -@@ -92,11 +92,6 @@ +@@ -91,11 +91,6 @@ + /* unfortunately push/pop can't be no-op */ .macro PUSH_GS pushl $0 - .endm +-.endm -.macro POP_GS pop=0 - addl $(4 + \pop), %esp -.endm -.macro POP_GS_EX --.endm + .endm /* all the rest are no-op */ - .macro PTGS_TO_GS @@ -116,20 +111,6 @@ pushl %gs .endm @@ -107,5 +107,5 @@ index 9bd77183965f..b39c5e210b43 100644 .macro CHECK_AND_APPLY_ESPFIX -- -2.13.6 +2.16.2 diff --git a/kernel/kernel/files/patches/mageia/pti32bit-0008-x86-entry-32-Enter-the-kernel-via-trampoline-stack.patch b/kernel/kernel/files/patches/mageia/pti32bit-0008-x86-entry-32-Enter-the-kernel-via-trampoline-stack.patch index eb3f5103..0fddc074 100644 --- a/kernel/kernel/files/patches/mageia/pti32bit-0008-x86-entry-32-Enter-the-kernel-via-trampoline-stack.patch +++ b/kernel/kernel/files/patches/mageia/pti32bit-0008-x86-entry-32-Enter-the-kernel-via-trampoline-stack.patch @@ -1,7 +1,7 @@ -From d9dc2b83bdfc2a9265302cc90b32739ac579f8cc Mon Sep 17 00:00:00 2001 +From 288a2a6b31018ab9172598a39477404582ae29fa Mon Sep 17 00:00:00 2001 From: Joerg Roedel Date: Tue, 16 Jan 2018 10:55:52 +0100 -Subject: [PATCH 08/31] x86/entry/32: Enter the kernel via trampoline stack +Subject: [PATCH 08/34] x86/entry/32: Enter the kernel via trampoline stack Use the entry-stack as a trampoline to enter the kernel. The entry-stack is already in the cpu_entry_area and will be @@ -9,16 +9,16 @@ mapped to userspace when PTI is enabled. Signed-off-by: Joerg Roedel --- - arch/x86/entry/entry_32.S | 135 +++++++++++++++++++++++++++++++-------- + arch/x86/entry/entry_32.S | 136 +++++++++++++++++++++++++++++++-------- arch/x86/include/asm/switch_to.h | 6 +- arch/x86/kernel/asm-offsets.c | 1 + arch/x86/kernel/cpu/common.c | 5 +- arch/x86/kernel/process.c | 2 - arch/x86/kernel/process_32.c | 10 +-- - 6 files changed, 120 insertions(+), 39 deletions(-) + 6 files changed, 121 insertions(+), 39 deletions(-) diff --git a/arch/x86/entry/entry_32.S b/arch/x86/entry/entry_32.S -index b39c5e210b43..e714b53b1eaa 100644 +index b39c5e210b43..1737da2e4517 100644 --- a/arch/x86/entry/entry_32.S +++ b/arch/x86/entry/entry_32.S @@ -135,25 +135,36 @@ @@ -65,7 +65,7 @@ index b39c5e210b43..e714b53b1eaa 100644 .endm /* -@@ -261,6 +272,71 @@ +@@ -261,6 +272,72 @@ .Lend_\@: #endif /* CONFIG_X86_ESPFIX32 */ .endm @@ -128,8 +128,9 @@ index b39c5e210b43..e714b53b1eaa 100644 + * We are now on the task-stack and can safely copy over the + * stack-frame + */ ++ shrl $2, %ecx + cld -+ rep movsb ++ rep movsl + +.Lend_\@: +.endm @@ -137,7 +138,7 @@ index b39c5e210b43..e714b53b1eaa 100644 /* * %eax: prev task * %edx: next task -@@ -454,6 +530,7 @@ ENTRY(xen_sysenter_target) +@@ -454,6 +531,7 @@ ENTRY(xen_sysenter_target) */ ENTRY(entry_SYSENTER_32) movl TSS_entry_stack(%esp), %esp @@ -145,7 +146,7 @@ index b39c5e210b43..e714b53b1eaa 100644 .Lsysenter_past_esp: pushl $__USER_DS /* pt_regs->ss */ pushl %ebp /* pt_regs->sp (stashed in bp) */ -@@ -462,7 +539,7 @@ ENTRY(entry_SYSENTER_32) +@@ -462,7 +540,7 @@ ENTRY(entry_SYSENTER_32) pushl $__USER_CS /* pt_regs->cs */ pushl $0 /* pt_regs->ip = 0 (placeholder) */ pushl %eax /* pt_regs->orig_ax */ @@ -154,7 +155,7 @@ index b39c5e210b43..e714b53b1eaa 100644 /* * SYSENTER doesn't filter flags, so we need to clear NT, AC -@@ -573,7 +650,8 @@ ENDPROC(entry_SYSENTER_32) +@@ -573,7 +651,8 @@ ENDPROC(entry_SYSENTER_32) ENTRY(entry_INT80_32) ASM_CLAC pushl %eax /* pt_regs->orig_ax */ @@ -164,7 +165,7 @@ index b39c5e210b43..e714b53b1eaa 100644 /* * User mode is traced as though IRQs are on, and the interrupt gate -@@ -665,7 +743,8 @@ END(irq_entries_start) +@@ -665,7 +744,8 @@ END(irq_entries_start) common_interrupt: ASM_CLAC addl $-0x80, (%esp) /* Adjust vector into the [-256, -1] range */ @@ -174,7 +175,7 @@ index b39c5e210b43..e714b53b1eaa 100644 ENCODE_FRAME_POINTER TRACE_IRQS_OFF movl %esp, %eax -@@ -673,16 +752,16 @@ common_interrupt: +@@ -673,16 +753,16 @@ common_interrupt: jmp ret_from_intr ENDPROC(common_interrupt) @@ -201,7 +202,7 @@ index b39c5e210b43..e714b53b1eaa 100644 ENDPROC(name) #define BUILD_INTERRUPT(name, nr) \ -@@ -908,16 +987,20 @@ common_exception: +@@ -908,16 +988,20 @@ common_exception: pushl %es pushl %ds pushl %eax @@ -224,7 +225,7 @@ index b39c5e210b43..e714b53b1eaa 100644 UNWIND_ESPFIX_STACK GS_TO_REG %ecx movl PT_GS(%esp), %edi # get the function address -@@ -925,9 +1008,6 @@ common_exception: +@@ -925,9 +1009,6 @@ common_exception: movl $-1, PT_ORIG_EAX(%esp) # no syscall to restart REG_TO_PTGS %ecx SET_KERNEL_GS %ecx @@ -234,7 +235,7 @@ index b39c5e210b43..e714b53b1eaa 100644 TRACE_IRQS_OFF movl %esp, %eax # pt_regs pointer CALL_NOSPEC %edi -@@ -946,6 +1026,7 @@ ENTRY(debug) +@@ -946,6 +1027,7 @@ ENTRY(debug) */ ASM_CLAC pushl $-1 # mark this as an int @@ -242,7 +243,7 @@ index b39c5e210b43..e714b53b1eaa 100644 SAVE_ALL ENCODE_FRAME_POINTER xorl %edx, %edx # error code 0 -@@ -981,6 +1062,7 @@ END(debug) +@@ -981,6 +1063,7 @@ END(debug) */ ENTRY(nmi) ASM_CLAC @@ -250,7 +251,7 @@ index b39c5e210b43..e714b53b1eaa 100644 #ifdef CONFIG_X86_ESPFIX32 pushl %eax movl %ss, %eax -@@ -1048,7 +1130,8 @@ END(nmi) +@@ -1048,7 +1131,8 @@ END(nmi) ENTRY(int3) ASM_CLAC pushl $-1 # mark this as an int @@ -351,5 +352,5 @@ index 097d36a64889..3f3a8c620c63 100644 /* -- -2.13.6 +2.16.2 diff --git a/kernel/kernel/files/patches/mageia/pti32bit-0009-x86-entry-32-Leave-the-kernel-via-trampoline-stack.patch b/kernel/kernel/files/patches/mageia/pti32bit-0009-x86-entry-32-Leave-the-kernel-via-trampoline-stack.patch index 9abb0d63..d49e9396 100644 --- a/kernel/kernel/files/patches/mageia/pti32bit-0009-x86-entry-32-Leave-the-kernel-via-trampoline-stack.patch +++ b/kernel/kernel/files/patches/mageia/pti32bit-0009-x86-entry-32-Leave-the-kernel-via-trampoline-stack.patch @@ -1,29 +1,30 @@ -From 4a06e416cfe4d173f8ed65799e112f77ecb12be8 Mon Sep 17 00:00:00 2001 +From af8c0db250e710c6ecd19a83bd8b57da44662041 Mon Sep 17 00:00:00 2001 From: Joerg Roedel Date: Tue, 16 Jan 2018 11:28:30 +0100 -Subject: [PATCH 09/31] x86/entry/32: Leave the kernel via trampoline stack +Subject: [PATCH 09/34] x86/entry/32: Leave the kernel via trampoline stack Switch back to the trampoline stack before returning to userspace. Signed-off-by: Joerg Roedel --- - arch/x86/entry/entry_32.S | 55 +++++++++++++++++++++++++++++++++++++++++++++++ - 1 file changed, 55 insertions(+) + arch/x86/entry/entry_32.S | 79 +++++++++++++++++++++++++++++++++++++++++++++-- + 1 file changed, 77 insertions(+), 2 deletions(-) diff --git a/arch/x86/entry/entry_32.S b/arch/x86/entry/entry_32.S -index e714b53b1eaa..ba3d8c2886ed 100644 +index 1737da2e4517..1b5656d7040e 100644 --- a/arch/x86/entry/entry_32.S +++ b/arch/x86/entry/entry_32.S -@@ -338,6 +338,59 @@ +@@ -338,6 +338,60 @@ + .Lend_\@: .endm - /* ++/* + * Switch back from the kernel stack to the entry stack. + * + * The %esp register must point to pt_regs on the task stack. It will + * first calculate the size of the stack-frame to copy, depending on -+ * whether we return to VM86 mode or not. With that it uses 'rep movsb' ++ * whether we return to VM86 mode or not. With that it uses 'rep movsl' + * to copy the contents of the stack over to the entry stack. + * + * We must be very careful here, as we can't trust the contents of the @@ -55,11 +56,12 @@ index e714b53b1eaa..ba3d8c2886ed 100644 + movl %esp, %esi + + /* Save future stack pointer in %ebx */ -+ movl %edi, %ebx ++ movl %edi, %ebx + + /* Copy over the stack-frame */ ++ shrl $2, %ecx + cld -+ rep movsb ++ rep movsl + + /* + * Switch to entry-stack - needs to happen after everything is @@ -71,19 +73,58 @@ index e714b53b1eaa..ba3d8c2886ed 100644 +.Lend_\@: +.endm + -+/* + /* * %eax: prev task * %edx: next task - */ -@@ -578,6 +631,7 @@ ENTRY(entry_SYSENTER_32) +@@ -579,25 +633,45 @@ ENTRY(entry_SYSENTER_32) /* Opportunistic SYSEXIT */ TRACE_IRQS_ON /* User mode traces as IRQs on. */ -+ SWITCH_TO_ENTRY_STACK /* Switch to per-cpu entry stack */ ++ ++ /* ++ * Setup entry stack - we keep the pointer in %eax and do the ++ * switch after almost all user-state is restored. ++ */ ++ ++ /* Load entry stack pointer and allocate frame for eflags/eax */ ++ movl PER_CPU_VAR(cpu_tss_rw + TSS_sp0), %eax ++ subl $(2*4), %eax ++ ++ /* Copy eflags and eax to entry stack */ ++ movl PT_EFLAGS(%esp), %edi ++ movl PT_EAX(%esp), %esi ++ movl %edi, (%eax) ++ movl %esi, 4(%eax) ++ ++ /* Restore user registers and segments */ movl PT_EIP(%esp), %edx /* pt_regs->ip */ movl PT_OLDESP(%esp), %ecx /* pt_regs->sp */ 1: mov PT_FS(%esp), %fs -@@ -665,6 +719,7 @@ ENTRY(entry_INT80_32) + PTGS_TO_GS ++ + popl %ebx /* pt_regs->bx */ + addl $2*4, %esp /* skip pt_regs->cx and pt_regs->dx */ + popl %esi /* pt_regs->si */ + popl %edi /* pt_regs->di */ + popl %ebp /* pt_regs->bp */ +- popl %eax /* pt_regs->ax */ ++ ++ /* Switch to entry stack */ ++ movl %eax, %esp + + /* + * Restore all flags except IF. (We restore IF separately because + * STI gives a one-instruction window in which we won't be interrupted, + * whereas POPF does not.) + */ +- addl $PT_EFLAGS-PT_DS, %esp /* point esp at pt_regs->flags */ + btr $X86_EFLAGS_IF_BIT, (%esp) + popfl ++ popl %eax + + /* + * Return back to the vDSO, which will pop ecx and edx. +@@ -666,6 +740,7 @@ ENTRY(entry_INT80_32) restore_all: TRACE_IRQS_IRET @@ -92,5 +133,5 @@ index e714b53b1eaa..ba3d8c2886ed 100644 CHECK_AND_APPLY_ESPFIX .Lrestore_nocheck: -- -2.13.6 +2.16.2 diff --git a/kernel/kernel/files/patches/mageia/pti32bit-0010-x86-entry-32-Introduce-SAVE_ALL_NMI-and-RESTORE_ALL_.patch b/kernel/kernel/files/patches/mageia/pti32bit-0010-x86-entry-32-Introduce-SAVE_ALL_NMI-and-RESTORE_ALL_.patch index 9d5b730e..b45bb7b1 100644 --- a/kernel/kernel/files/patches/mageia/pti32bit-0010-x86-entry-32-Introduce-SAVE_ALL_NMI-and-RESTORE_ALL_.patch +++ b/kernel/kernel/files/patches/mageia/pti32bit-0010-x86-entry-32-Introduce-SAVE_ALL_NMI-and-RESTORE_ALL_.patch @@ -1,7 +1,7 @@ -From 26b38ec7dd2591f092eb359a5a59752d799ab60d Mon Sep 17 00:00:00 2001 +From 49a15ace3cbe2fba45548538ede04c1599b33fb9 Mon Sep 17 00:00:00 2001 From: Joerg Roedel Date: Wed, 31 Jan 2018 16:35:42 +0100 -Subject: [PATCH 10/31] x86/entry/32: Introduce SAVE_ALL_NMI and +Subject: [PATCH 10/34] x86/entry/32: Introduce SAVE_ALL_NMI and RESTORE_ALL_NMI These macros will be used in the NMI handler code and @@ -14,7 +14,7 @@ Signed-off-by: Joerg Roedel 1 file changed, 19 insertions(+), 4 deletions(-) diff --git a/arch/x86/entry/entry_32.S b/arch/x86/entry/entry_32.S -index ba3d8c2886ed..be1d814bd056 100644 +index 1b5656d7040e..bb0bd896c74b 100644 --- a/arch/x86/entry/entry_32.S +++ b/arch/x86/entry/entry_32.S @@ -167,6 +167,9 @@ @@ -46,7 +46,7 @@ index ba3d8c2886ed..be1d814bd056 100644 .macro CHECK_AND_APPLY_ESPFIX #ifdef CONFIG_X86_ESPFIX32 #define GDT_ESPFIX_SS PER_CPU_VAR(gdt_page) + (GDT_ENTRY_ESPFIX_SS * 8) -@@ -1127,7 +1142,7 @@ ENTRY(nmi) +@@ -1148,7 +1163,7 @@ ENTRY(nmi) #endif pushl %eax # pt_regs->orig_ax @@ -55,7 +55,7 @@ index ba3d8c2886ed..be1d814bd056 100644 ENCODE_FRAME_POINTER xorl %edx, %edx # zero error code movl %esp, %eax # pt_regs pointer -@@ -1155,7 +1170,7 @@ ENTRY(nmi) +@@ -1176,7 +1191,7 @@ ENTRY(nmi) .Lnmi_return: CHECK_AND_APPLY_ESPFIX @@ -64,7 +64,7 @@ index ba3d8c2886ed..be1d814bd056 100644 jmp .Lirq_return #ifdef CONFIG_X86_ESPFIX32 -@@ -1171,12 +1186,12 @@ ENTRY(nmi) +@@ -1192,12 +1207,12 @@ ENTRY(nmi) pushl 16(%esp) .endr pushl %eax @@ -80,5 +80,5 @@ index ba3d8c2886ed..be1d814bd056 100644 jmp .Lirq_return #endif -- -2.13.6 +2.16.2 diff --git a/kernel/kernel/files/patches/mageia/pti32bit-0013-x86-entry-32-Handle-Entry-from-Kernel-Mode-on-Entry-.patch b/kernel/kernel/files/patches/mageia/pti32bit-0011-x86-entry-32-Handle-Entry-from-Kernel-Mode-on-Entry-.patch similarity index 91% rename from kernel/kernel/files/patches/mageia/pti32bit-0013-x86-entry-32-Handle-Entry-from-Kernel-Mode-on-Entry-.patch rename to kernel/kernel/files/patches/mageia/pti32bit-0011-x86-entry-32-Handle-Entry-from-Kernel-Mode-on-Entry-.patch index 5f9f0ae2..c96d7a6e 100644 --- a/kernel/kernel/files/patches/mageia/pti32bit-0013-x86-entry-32-Handle-Entry-from-Kernel-Mode-on-Entry-.patch +++ b/kernel/kernel/files/patches/mageia/pti32bit-0011-x86-entry-32-Handle-Entry-from-Kernel-Mode-on-Entry-.patch @@ -1,7 +1,7 @@ -From a98c3fa3166e37c6f66f5b7e221b9c0cf1455806 Mon Sep 17 00:00:00 2001 +From bbad1145165d4ed4452913df109ee3429a10dd90 Mon Sep 17 00:00:00 2001 From: Joerg Roedel Date: Wed, 31 Jan 2018 20:48:02 +0100 -Subject: [PATCH 13/31] x86/entry/32: Handle Entry from Kernel-Mode on +Subject: [PATCH 11/34] x86/entry/32: Handle Entry from Kernel-Mode on Entry-Stack It can happen that we enter the kernel from kernel-mode and @@ -33,14 +33,14 @@ to it. Signed-off-by: Joerg Roedel --- - arch/x86/entry/entry_32.S | 109 +++++++++++++++++++++++++++++++++++++++++++++- - 1 file changed, 108 insertions(+), 1 deletion(-) + arch/x86/entry/entry_32.S | 110 +++++++++++++++++++++++++++++++++++++++++++++- + 1 file changed, 109 insertions(+), 1 deletion(-) diff --git a/arch/x86/entry/entry_32.S b/arch/x86/entry/entry_32.S -index b5ef00302316..d94dab68b526 100644 +index bb0bd896c74b..3a84945fa3b6 100644 --- a/arch/x86/entry/entry_32.S +++ b/arch/x86/entry/entry_32.S -@@ -358,6 +358,9 @@ +@@ -299,6 +299,9 @@ * copied there. So allocate the stack-frame on the task-stack and * switch to it before we do any copying. */ @@ -50,7 +50,7 @@ index b5ef00302316..d94dab68b526 100644 .macro SWITCH_TO_KERNEL_STACK ALTERNATIVE "", "jmp .Lend_\@", X86_FEATURE_XENPV -@@ -381,6 +384,10 @@ +@@ -320,6 +323,10 @@ /* Load top of task-stack into %edi */ movl TSS_entry_stack(%edi), %edi @@ -61,7 +61,7 @@ index b5ef00302316..d94dab68b526 100644 /* Bytes to copy */ movl $PTREGS_SIZE, %ecx -@@ -394,8 +401,8 @@ +@@ -333,8 +340,8 @@ */ addl $(4 * 4), %ecx @@ -71,9 +71,9 @@ index b5ef00302316..d94dab68b526 100644 /* Allocate frame on task-stack */ subl %ecx, %edi -@@ -410,6 +417,56 @@ +@@ -350,6 +357,56 @@ cld - rep movsb + rep movsl + jmp .Lend_\@ + @@ -128,10 +128,11 @@ index b5ef00302316..d94dab68b526 100644 .Lend_\@: .endm -@@ -467,6 +524,55 @@ +@@ -407,6 +464,56 @@ + .Lend_\@: .endm - /* ++/* + * This macro handles the case when we return to kernel-mode on the iret + * path and have to switch back to the entry stack. + * @@ -172,19 +173,19 @@ index b5ef00302316..d94dab68b526 100644 + movl %edi, %ebx + + /* Do the copy */ ++ shrl $2, %ecx + cld -+ rep movsb ++ rep movsl + + /* Safe to switch to entry-stack now */ + movl %ebx, %esp + +.Lend_\@: +.endm -+/* + /* * %eax: prev task * %edx: next task - */ -@@ -837,6 +943,7 @@ restore_all: +@@ -765,6 +872,7 @@ restore_all: restore_all_kernel: TRACE_IRQS_IRET @@ -193,5 +194,5 @@ index b5ef00302316..d94dab68b526 100644 jmp .Lirq_return -- -2.13.6 +2.16.2 diff --git a/kernel/kernel/files/patches/mageia/pti32bit-0012-x86-entry-32-Add-PTI-cr3-switch-to-non-NMI-entry-exi.patch b/kernel/kernel/files/patches/mageia/pti32bit-0012-x86-entry-32-Add-PTI-cr3-switch-to-non-NMI-entry-exi.patch deleted file mode 100644 index f572180a..00000000 --- a/kernel/kernel/files/patches/mageia/pti32bit-0012-x86-entry-32-Add-PTI-cr3-switch-to-non-NMI-entry-exi.patch +++ /dev/null @@ -1,122 +0,0 @@ -From 883518e6e2b618c2ee49ac822057712090784eda Mon Sep 17 00:00:00 2001 -From: Joerg Roedel -Date: Wed, 31 Jan 2018 17:22:10 +0100 -Subject: [PATCH 12/31] x86/entry/32: Add PTI cr3 switch to non-NMI entry/exit - points - -Add unconditional cr3 switches between user and kernel cr3 -to all non-NMI entry and exit points. - -Signed-off-by: Joerg Roedel ---- - arch/x86/entry/entry_32.S | 59 ++++++++++++++++++++++++++++++++++++++++++++++- - 1 file changed, 58 insertions(+), 1 deletion(-) - -diff --git a/arch/x86/entry/entry_32.S b/arch/x86/entry/entry_32.S -index 9693485c901a..b5ef00302316 100644 ---- a/arch/x86/entry/entry_32.S -+++ b/arch/x86/entry/entry_32.S -@@ -328,6 +328,25 @@ - #endif /* CONFIG_X86_ESPFIX32 */ - .endm - -+/* Unconditionally switch to user cr3 */ -+.macro SWITCH_TO_USER_CR3 scratch_reg:req -+ ALTERNATIVE "jmp .Lend_\@", "", X86_FEATURE_PTI -+ -+ movl %cr3, \scratch_reg -+ orl $PTI_SWITCH_MASK, \scratch_reg -+ movl \scratch_reg, %cr3 -+.Lend_\@: -+.endm -+ -+/* Unconditionally switch to kernel cr3 */ -+.macro SWITCH_TO_KERNEL_CR3 scratch_reg:req -+ ALTERNATIVE "jmp .Lend_\@", "", X86_FEATURE_PTI -+ movl %cr3, \scratch_reg -+ andl $(~PTI_SWITCH_MASK), \scratch_reg -+ movl \scratch_reg, %cr3 -+.Lend_\@: -+.endm -+ - - /* - * Called with pt_regs fully populated and kernel segments loaded, -@@ -343,6 +362,8 @@ - - ALTERNATIVE "", "jmp .Lend_\@", X86_FEATURE_XENPV - -+ SWITCH_TO_KERNEL_CR3 scratch_reg=%eax -+ - /* Are we on the entry stack? Bail out if not! */ - movl PER_CPU_VAR(cpu_entry_area), %edi - addl $CPU_ENTRY_AREA_entry_stack, %edi -@@ -637,6 +658,18 @@ ENTRY(xen_sysenter_target) - * 0(%ebp) arg6 - */ - ENTRY(entry_SYSENTER_32) -+ /* -+ * On entry-stack with all userspace-regs live - save and -+ * restore eflags and %eax to use it as scratch-reg for the cr3 -+ * switch. -+ */ -+ pushfl -+ pushl %eax -+ SWITCH_TO_KERNEL_CR3 scratch_reg=%eax -+ popl %eax -+ popfl -+ -+ /* Stack empty again, switch to task stack */ - movl TSS_entry_stack(%esp), %esp - - .Lsysenter_past_esp: -@@ -691,6 +724,10 @@ ENTRY(entry_SYSENTER_32) - movl PT_OLDESP(%esp), %ecx /* pt_regs->sp */ - 1: mov PT_FS(%esp), %fs - PTGS_TO_GS -+ -+ /* Segments are restored - switch to user cr3 */ -+ SWITCH_TO_USER_CR3 scratch_reg=%eax -+ - popl %ebx /* pt_regs->bx */ - addl $2*4, %esp /* skip pt_regs->cx and pt_regs->dx */ - popl %esi /* pt_regs->si */ -@@ -778,7 +815,23 @@ restore_all: - .Lrestore_all_notrace: - CHECK_AND_APPLY_ESPFIX - .Lrestore_nocheck: -- RESTORE_REGS 4 # skip orig_eax/error_code -+ /* -+ * First restore user segments. This can cause exceptions, so we -+ * run it with kernel cr3. -+ */ -+ RESTORE_SEGMENTS -+ -+ /* -+ * Segments are restored - no more exceptions from here on except on -+ * iret, but that handled safely. -+ */ -+ SWITCH_TO_USER_CR3 scratch_reg=%eax -+ -+ /* Restore rest */ -+ RESTORE_INT_REGS -+ -+ /* Unwind stack to the iret frame */ -+ RESTORE_SKIP_SEGMENTS 4 # skip orig_eax/error_code - .Lirq_return: - INTERRUPT_RETURN - -@@ -1139,6 +1192,10 @@ ENTRY(debug) - - SAVE_ALL - ENCODE_FRAME_POINTER -+ -+ /* Make sure we are running on kernel cr3 */ -+ SWITCH_TO_KERNEL_CR3 scratch_reg=%eax -+ - xorl %edx, %edx # error code 0 - movl %esp, %eax # pt_regs pointer - --- -2.13.6 - diff --git a/kernel/kernel/files/patches/mageia/pti32bit-0012-x86-entry-32-Simplify-debug-entry-point.patch b/kernel/kernel/files/patches/mageia/pti32bit-0012-x86-entry-32-Simplify-debug-entry-point.patch new file mode 100644 index 00000000..803fb485 --- /dev/null +++ b/kernel/kernel/files/patches/mageia/pti32bit-0012-x86-entry-32-Simplify-debug-entry-point.patch @@ -0,0 +1,69 @@ +From 8743506d5153928d0a0fb4106470a6581d03796d Mon Sep 17 00:00:00 2001 +From: Joerg Roedel +Date: Thu, 1 Mar 2018 14:48:16 +0100 +Subject: [PATCH 12/34] x86/entry/32: Simplify debug entry point + +The common exception entry code now handles the +entry-from-sysenter stack situation and makes sure to leave +with the same stack as it entered the kernel. + +So there is no need anymore for the special handling in the +debug entry code. + +Signed-off-by: Joerg Roedel +--- + arch/x86/entry/entry_32.S | 35 +++-------------------------------- + 1 file changed, 3 insertions(+), 32 deletions(-) + +diff --git a/arch/x86/entry/entry_32.S b/arch/x86/entry/entry_32.S +index 3a84945fa3b6..b1a5f34eeb27 100644 +--- a/arch/x86/entry/entry_32.S ++++ b/arch/x86/entry/entry_32.S +@@ -1215,41 +1215,12 @@ END(common_exception) + + ENTRY(debug) + /* +- * #DB can happen at the first instruction of +- * entry_SYSENTER_32 or in Xen's SYSENTER prologue. If this +- * happens, then we will be running on a very small stack. We +- * need to detect this condition and switch to the thread +- * stack before calling any C code at all. +- * +- * If you edit this code, keep in mind that NMIs can happen in here. ++ * Entry from sysenter is now handled in common_exception + */ + ASM_CLAC + pushl $-1 # mark this as an int +- +- SAVE_ALL +- ENCODE_FRAME_POINTER +- xorl %edx, %edx # error code 0 +- movl %esp, %eax # pt_regs pointer +- +- /* Are we currently on the SYSENTER stack? */ +- movl PER_CPU_VAR(cpu_entry_area), %ecx +- addl $CPU_ENTRY_AREA_entry_stack + SIZEOF_entry_stack, %ecx +- subl %eax, %ecx /* ecx = (end of entry_stack) - esp */ +- cmpl $SIZEOF_entry_stack, %ecx +- jb .Ldebug_from_sysenter_stack +- +- TRACE_IRQS_OFF +- call do_debug +- jmp ret_from_exception +- +-.Ldebug_from_sysenter_stack: +- /* We're on the SYSENTER stack. Switch off. */ +- movl %esp, %ebx +- movl PER_CPU_VAR(cpu_current_top_of_stack), %esp +- TRACE_IRQS_OFF +- call do_debug +- movl %ebx, %esp +- jmp ret_from_exception ++ pushl $do_debug ++ jmp common_exception + END(debug) + + /* +-- +2.16.2 + diff --git a/kernel/kernel/files/patches/mageia/pti32bit-0011-x86-entry-32-Add-PTI-cr3-switches-to-NMI-handler-cod.patch b/kernel/kernel/files/patches/mageia/pti32bit-0013-x86-entry-32-Add-PTI-cr3-switches-to-NMI-handler-cod.patch similarity index 91% rename from kernel/kernel/files/patches/mageia/pti32bit-0011-x86-entry-32-Add-PTI-cr3-switches-to-NMI-handler-cod.patch rename to kernel/kernel/files/patches/mageia/pti32bit-0013-x86-entry-32-Add-PTI-cr3-switches-to-NMI-handler-cod.patch index e4a8b057..3ecd0997 100644 --- a/kernel/kernel/files/patches/mageia/pti32bit-0011-x86-entry-32-Add-PTI-cr3-switches-to-NMI-handler-cod.patch +++ b/kernel/kernel/files/patches/mageia/pti32bit-0013-x86-entry-32-Add-PTI-cr3-switches-to-NMI-handler-cod.patch @@ -1,7 +1,7 @@ -From d7f5719fe456d24dd01fdcc281aac44dacfa57b2 Mon Sep 17 00:00:00 2001 +From 41bc2c77864b5464134c3ec722225a9ae4701968 Mon Sep 17 00:00:00 2001 From: Joerg Roedel Date: Wed, 31 Jan 2018 16:58:57 +0100 -Subject: [PATCH 11/31] x86/entry/32: Add PTI cr3 switches to NMI handler code +Subject: [PATCH 13/34] x86/entry/32: Add PTI cr3 switches to NMI handler code The NMI handler is special, as it needs to leave with the same cr3 as it was entered with. We need to do this because @@ -14,7 +14,7 @@ Signed-off-by: Joerg Roedel 1 file changed, 46 insertions(+), 6 deletions(-) diff --git a/arch/x86/entry/entry_32.S b/arch/x86/entry/entry_32.S -index be1d814bd056..9693485c901a 100644 +index b1a5f34eeb27..35379e5f60c6 100644 --- a/arch/x86/entry/entry_32.S +++ b/arch/x86/entry/entry_32.S @@ -77,6 +77,8 @@ @@ -89,7 +89,7 @@ index be1d814bd056..9693485c901a 100644 /* Restore integer registers and unwind stack to iret frame */ RESTORE_INT_REGS RESTORE_SKIP_SEGMENTS \pop -@@ -1142,7 +1182,7 @@ ENTRY(nmi) +@@ -1242,7 +1282,7 @@ ENTRY(nmi) #endif pushl %eax # pt_regs->orig_ax @@ -98,7 +98,7 @@ index be1d814bd056..9693485c901a 100644 ENCODE_FRAME_POINTER xorl %edx, %edx # zero error code movl %esp, %eax # pt_regs pointer -@@ -1170,7 +1210,7 @@ ENTRY(nmi) +@@ -1270,7 +1310,7 @@ ENTRY(nmi) .Lnmi_return: CHECK_AND_APPLY_ESPFIX @@ -107,7 +107,7 @@ index be1d814bd056..9693485c901a 100644 jmp .Lirq_return #ifdef CONFIG_X86_ESPFIX32 -@@ -1186,12 +1226,12 @@ ENTRY(nmi) +@@ -1286,12 +1326,12 @@ ENTRY(nmi) pushl 16(%esp) .endr pushl %eax @@ -123,5 +123,5 @@ index be1d814bd056..9693485c901a 100644 jmp .Lirq_return #endif -- -2.13.6 +2.16.2 diff --git a/kernel/kernel/files/patches/mageia/pti32bit-0014-x86-entry-32-Add-PTI-cr3-switch-to-non-NMI-entry-exi.patch b/kernel/kernel/files/patches/mageia/pti32bit-0014-x86-entry-32-Add-PTI-cr3-switch-to-non-NMI-entry-exi.patch new file mode 100644 index 00000000..7f9db488 --- /dev/null +++ b/kernel/kernel/files/patches/mageia/pti32bit-0014-x86-entry-32-Add-PTI-cr3-switch-to-non-NMI-entry-exi.patch @@ -0,0 +1,187 @@ +From d40791fdb56c15767c7c65a1a2e0c8736f3db0af Mon Sep 17 00:00:00 2001 +From: Joerg Roedel +Date: Wed, 31 Jan 2018 17:22:10 +0100 +Subject: [PATCH 14/34] x86/entry/32: Add PTI cr3 switch to non-NMI entry/exit + points + +Add unconditional cr3 switches between user and kernel cr3 +to all non-NMI entry and exit points. + +Signed-off-by: Joerg Roedel +--- + arch/x86/entry/entry_32.S | 91 +++++++++++++++++++++++++++++++++++++++++++++-- + 1 file changed, 88 insertions(+), 3 deletions(-) + +diff --git a/arch/x86/entry/entry_32.S b/arch/x86/entry/entry_32.S +index 35379e5f60c6..8f78abcf1f9c 100644 +--- a/arch/x86/entry/entry_32.S ++++ b/arch/x86/entry/entry_32.S +@@ -328,6 +328,30 @@ + #endif /* CONFIG_X86_ESPFIX32 */ + .endm + ++/* Unconditionally switch to user cr3 */ ++.macro SWITCH_TO_USER_CR3 scratch_reg:req ++ ALTERNATIVE "jmp .Lend_\@", "", X86_FEATURE_PTI ++ ++ movl %cr3, \scratch_reg ++ orl $PTI_SWITCH_MASK, \scratch_reg ++ movl \scratch_reg, %cr3 ++.Lend_\@: ++.endm ++ ++/* Unconditionally switch to kernel cr3 */ ++.macro SWITCH_TO_KERNEL_CR3 scratch_reg:req ++ ALTERNATIVE "jmp .Lend_\@", "", X86_FEATURE_PTI ++ movl %cr3, \scratch_reg ++ /* Test if we are already on kernel CR3 */ ++ testl $PTI_SWITCH_MASK, \scratch_reg ++ jz .Lend_\@ ++ andl $(~PTI_SWITCH_MASK), \scratch_reg ++ movl \scratch_reg, %cr3 ++ /* Return original CR3 in \scratch_reg */ ++ orl $PTI_SWITCH_MASK, \scratch_reg ++.Lend_\@: ++.endm ++ + + /* + * Called with pt_regs fully populated and kernel segments loaded, +@@ -341,11 +365,19 @@ + */ + + #define CS_FROM_ENTRY_STACK (1 << 31) ++#define CS_FROM_USER_CR3 (1 << 30) + + .macro SWITCH_TO_KERNEL_STACK + + ALTERNATIVE "", "jmp .Lend_\@", X86_FEATURE_XENPV + ++ SWITCH_TO_KERNEL_CR3 scratch_reg=%eax ++ ++ /* ++ * %eax now contains the entry cr3 and we carry it forward in ++ * that register for the time this macro runs ++ */ ++ + /* Are we on the entry stack? Bail out if not! */ + movl PER_CPU_VAR(cpu_entry_area), %edi + addl $CPU_ENTRY_AREA_entry_stack, %edi +@@ -408,7 +440,8 @@ + * but switch back to the entry-stack again when we approach + * iret and return to the interrupted code-path. This usually + * happens when we hit an exception while restoring user-space +- * segment registers on the way back to user-space. ++ * segment registers on the way back to user-space or when the ++ * sysenter handler runs with eflags.tf set. + * + * When we switch to the task-stack here, we can't trust the + * contents of the entry-stack anymore, as the exception handler +@@ -425,6 +458,7 @@ + * + * %esi: Entry-Stack pointer (same as %esp) + * %edi: Top of the task stack ++ * %eax: CR3 on kernel entry + */ + + /* Calculate number of bytes on the entry stack in %ecx */ +@@ -440,6 +474,14 @@ + /* Mark stackframe as coming from entry stack */ + orl $CS_FROM_ENTRY_STACK, PT_CS(%esp) + ++ /* ++ * Test the cr3 used to enter the kernel and add a marker ++ * so that we can switch back to it before iret. ++ */ ++ testl $PTI_SWITCH_MASK, %eax ++ jz .Lcopy_pt_regs_\@ ++ orl $CS_FROM_USER_CR3, PT_CS(%esp) ++ + /* + * %esi and %edi are unchanged, %ecx contains the number of + * bytes to copy. The code at .Lcopy_pt_regs_\@ will allocate +@@ -506,7 +548,7 @@ + + /* + * This macro handles the case when we return to kernel-mode on the iret +- * path and have to switch back to the entry stack. ++ * path and have to switch back to the entry stack and/or user-cr3 + * + * See the comments below the .Lentry_from_kernel_\@ label in the + * SWITCH_TO_KERNEL_STACK macro for more details. +@@ -552,6 +594,18 @@ + /* Safe to switch to entry-stack now */ + movl %ebx, %esp + ++ /* ++ * We came from entry-stack and need to check if we also need to ++ * switch back to user cr3. ++ */ ++ testl $CS_FROM_USER_CR3, PT_CS(%esp) ++ jz .Lend_\@ ++ ++ /* Clear marker from stack-frame */ ++ andl $(~CS_FROM_USER_CR3), PT_CS(%esp) ++ ++ SWITCH_TO_USER_CR3 scratch_reg=%eax ++ + .Lend_\@: + .endm + /* +@@ -746,6 +800,18 @@ ENTRY(xen_sysenter_target) + * 0(%ebp) arg6 + */ + ENTRY(entry_SYSENTER_32) ++ /* ++ * On entry-stack with all userspace-regs live - save and ++ * restore eflags and %eax to use it as scratch-reg for the cr3 ++ * switch. ++ */ ++ pushfl ++ pushl %eax ++ SWITCH_TO_KERNEL_CR3 scratch_reg=%eax ++ popl %eax ++ popfl ++ ++ /* Stack empty again, switch to task stack */ + movl TSS_entry_stack(%esp), %esp + + .Lsysenter_past_esp: +@@ -826,6 +892,9 @@ ENTRY(entry_SYSENTER_32) + /* Switch to entry stack */ + movl %eax, %esp + ++ /* Now ready to switch the cr3 */ ++ SWITCH_TO_USER_CR3 scratch_reg=%eax ++ + /* + * Restore all flags except IF. (We restore IF separately because + * STI gives a one-instruction window in which we won't be interrupted, +@@ -906,7 +975,23 @@ restore_all: + .Lrestore_all_notrace: + CHECK_AND_APPLY_ESPFIX + .Lrestore_nocheck: +- RESTORE_REGS 4 # skip orig_eax/error_code ++ /* ++ * First restore user segments. This can cause exceptions, so we ++ * run it with kernel cr3. ++ */ ++ RESTORE_SEGMENTS ++ ++ /* ++ * Segments are restored - no more exceptions from here on except on ++ * iret, but that handled safely. ++ */ ++ SWITCH_TO_USER_CR3 scratch_reg=%eax ++ ++ /* Restore rest */ ++ RESTORE_INT_REGS ++ ++ /* Unwind stack to the iret frame */ ++ RESTORE_SKIP_SEGMENTS 4 # skip orig_eax/error_code + .Lirq_return: + INTERRUPT_RETURN + +-- +2.16.2 + diff --git a/kernel/kernel/files/patches/mageia/pti32bit-0015-x86-pgtable-Rename-pti_set_user_pgd-to-pti_set_user_.patch b/kernel/kernel/files/patches/mageia/pti32bit-0015-x86-pgtable-Rename-pti_set_user_pgd-to-pti_set_user_.patch new file mode 100644 index 00000000..60452628 --- /dev/null +++ b/kernel/kernel/files/patches/mageia/pti32bit-0015-x86-pgtable-Rename-pti_set_user_pgd-to-pti_set_user_.patch @@ -0,0 +1,81 @@ +From 55797d951b45c9eb709a4e7483eef89d738c2427 Mon Sep 17 00:00:00 2001 +From: Joerg Roedel +Date: Thu, 1 Mar 2018 13:40:39 +0100 +Subject: [PATCH 15/34] x86/pgtable: Rename pti_set_user_pgd to + pti_set_user_pgtbl + +With the way page-table folding is implemented on 32 bit, we +are not only setting PGDs with this functions, but also PUDs +and even PMDs. Give the function a more generic name to +reflect that. + +Signed-off-by: Joerg Roedel +--- + arch/x86/include/asm/pgtable_64.h | 12 ++++++------ + arch/x86/mm/pti.c | 2 +- + 2 files changed, 7 insertions(+), 7 deletions(-) + +diff --git a/arch/x86/include/asm/pgtable_64.h b/arch/x86/include/asm/pgtable_64.h +index 81462e9a34f6..b68bda56db67 100644 +--- a/arch/x86/include/asm/pgtable_64.h ++++ b/arch/x86/include/asm/pgtable_64.h +@@ -195,21 +195,21 @@ static inline bool pgdp_maps_userspace(void *__ptr) + } + + #ifdef CONFIG_PAGE_TABLE_ISOLATION +-pgd_t __pti_set_user_pgd(pgd_t *pgdp, pgd_t pgd); ++pgd_t __pti_set_user_pgtbl(pgd_t *pgdp, pgd_t pgd); + + /* + * Take a PGD location (pgdp) and a pgd value that needs to be set there. + * Populates the user and returns the resulting PGD that must be set in + * the kernel copy of the page tables. + */ +-static inline pgd_t pti_set_user_pgd(pgd_t *pgdp, pgd_t pgd) ++static inline pgd_t pti_set_user_pgtbl(pgd_t *pgdp, pgd_t pgd) + { + if (!static_cpu_has(X86_FEATURE_PTI)) + return pgd; +- return __pti_set_user_pgd(pgdp, pgd); ++ return __pti_set_user_pgtbl(pgdp, pgd); + } + #else +-static inline pgd_t pti_set_user_pgd(pgd_t *pgdp, pgd_t pgd) ++static inline pgd_t pti_set_user_pgtbl(pgd_t *pgdp, pgd_t pgd) + { + return pgd; + } +@@ -218,7 +218,7 @@ static inline pgd_t pti_set_user_pgd(pgd_t *pgdp, pgd_t pgd) + static inline void native_set_p4d(p4d_t *p4dp, p4d_t p4d) + { + #if defined(CONFIG_PAGE_TABLE_ISOLATION) && !defined(CONFIG_X86_5LEVEL) +- p4dp->pgd = pti_set_user_pgd(&p4dp->pgd, p4d.pgd); ++ p4dp->pgd = pti_set_user_pgtbl(&p4dp->pgd, p4d.pgd); + #else + *p4dp = p4d; + #endif +@@ -236,7 +236,7 @@ static inline void native_p4d_clear(p4d_t *p4d) + static inline void native_set_pgd(pgd_t *pgdp, pgd_t pgd) + { + #ifdef CONFIG_PAGE_TABLE_ISOLATION +- *pgdp = pti_set_user_pgd(pgdp, pgd); ++ *pgdp = pti_set_user_pgtbl(pgdp, pgd); + #else + *pgdp = pgd; + #endif +diff --git a/arch/x86/mm/pti.c b/arch/x86/mm/pti.c +index ce38f165489b..8f53d2101f64 100644 +--- a/arch/x86/mm/pti.c ++++ b/arch/x86/mm/pti.c +@@ -102,7 +102,7 @@ void __init pti_check_boottime_disable(void) + setup_force_cpu_cap(X86_FEATURE_PTI); + } + +-pgd_t __pti_set_user_pgd(pgd_t *pgdp, pgd_t pgd) ++pgd_t __pti_set_user_pgtbl(pgd_t *pgdp, pgd_t pgd) + { + /* + * Changes to the high (kernel) portion of the kernelmode page +-- +2.16.2 + diff --git a/kernel/kernel/files/patches/mageia/pti32bit-0014-x86-pgtable-pae-Unshare-kernel-PMDs-when-PTI-is-enab.patch b/kernel/kernel/files/patches/mageia/pti32bit-0016-x86-pgtable-pae-Unshare-kernel-PMDs-when-PTI-is-enab.patch similarity index 88% rename from kernel/kernel/files/patches/mageia/pti32bit-0014-x86-pgtable-pae-Unshare-kernel-PMDs-when-PTI-is-enab.patch rename to kernel/kernel/files/patches/mageia/pti32bit-0016-x86-pgtable-pae-Unshare-kernel-PMDs-when-PTI-is-enab.patch index 2c1818b0..dc9e750d 100644 --- a/kernel/kernel/files/patches/mageia/pti32bit-0014-x86-pgtable-pae-Unshare-kernel-PMDs-when-PTI-is-enab.patch +++ b/kernel/kernel/files/patches/mageia/pti32bit-0016-x86-pgtable-pae-Unshare-kernel-PMDs-when-PTI-is-enab.patch @@ -1,7 +1,7 @@ -From cc4fcd3fae72f6a72d9f275366b7165fa4ac3f71 Mon Sep 17 00:00:00 2001 +From 5439accd9f31dacdfbf67a18440d5805e8a0bfad Mon Sep 17 00:00:00 2001 From: Joerg Roedel Date: Fri, 2 Feb 2018 10:41:36 +0100 -Subject: [PATCH 14/31] x86/pgtable/pae: Unshare kernel PMDs when PTI is +Subject: [PATCH 16/34] x86/pgtable/pae: Unshare kernel PMDs when PTI is enabled With PTI we need to map the per-process LDT into the kernel @@ -31,5 +31,5 @@ index 876b4c77d983..ed8a200ecdaf 100644 /* -- -2.13.6 +2.16.2 diff --git a/kernel/kernel/files/patches/mageia/pti32bit-0015-x86-pgtable-32-Allocate-8k-page-tables-when-PTI-is-e.patch b/kernel/kernel/files/patches/mageia/pti32bit-0017-x86-pgtable-32-Allocate-8k-page-tables-when-PTI-is-e.patch similarity index 95% rename from kernel/kernel/files/patches/mageia/pti32bit-0015-x86-pgtable-32-Allocate-8k-page-tables-when-PTI-is-e.patch rename to kernel/kernel/files/patches/mageia/pti32bit-0017-x86-pgtable-32-Allocate-8k-page-tables-when-PTI-is-e.patch index 76ca7bad..1cf7b9c7 100644 --- a/kernel/kernel/files/patches/mageia/pti32bit-0015-x86-pgtable-32-Allocate-8k-page-tables-when-PTI-is-e.patch +++ b/kernel/kernel/files/patches/mageia/pti32bit-0017-x86-pgtable-32-Allocate-8k-page-tables-when-PTI-is-e.patch @@ -1,7 +1,7 @@ -From 5ea0338f46add135a70678a6eba2e402310e7b26 Mon Sep 17 00:00:00 2001 +From 35cdf0541e9d5c7a47b59530fc8a42ac9ab767f8 Mon Sep 17 00:00:00 2001 From: Joerg Roedel Date: Tue, 16 Jan 2018 13:10:57 +0100 -Subject: [PATCH 15/31] x86/pgtable/32: Allocate 8k page-tables when PTI is +Subject: [PATCH 17/34] x86/pgtable/32: Allocate 8k page-tables when PTI is enabled Allocate a kernel and a user page-table root when PTI is @@ -94,5 +94,5 @@ index 004abf9ebf12..a81d42e48922 100644 kmem_cache_free(pgd_cache, pgd); } -- -2.13.6 +2.16.2 diff --git a/kernel/kernel/files/patches/mageia/pti32bit-0016-x86-pgtable-Move-pgdp-kernel-user-conversion-functio.patch b/kernel/kernel/files/patches/mageia/pti32bit-0018-x86-pgtable-Move-pgdp-kernel-user-conversion-functio.patch similarity index 95% rename from kernel/kernel/files/patches/mageia/pti32bit-0016-x86-pgtable-Move-pgdp-kernel-user-conversion-functio.patch rename to kernel/kernel/files/patches/mageia/pti32bit-0018-x86-pgtable-Move-pgdp-kernel-user-conversion-functio.patch index 31bf11b7..ff12561b 100644 --- a/kernel/kernel/files/patches/mageia/pti32bit-0016-x86-pgtable-Move-pgdp-kernel-user-conversion-functio.patch +++ b/kernel/kernel/files/patches/mageia/pti32bit-0018-x86-pgtable-Move-pgdp-kernel-user-conversion-functio.patch @@ -1,7 +1,7 @@ -From eaacd465ad0f08807b151d2d27b0cad27b9de076 Mon Sep 17 00:00:00 2001 +From 69dfcb6ee23f6841982e059f58cc9be921b669dc Mon Sep 17 00:00:00 2001 From: Joerg Roedel Date: Tue, 16 Jan 2018 11:53:38 +0100 -Subject: [PATCH 16/31] x86/pgtable: Move pgdp kernel/user conversion functions +Subject: [PATCH 18/34] x86/pgtable: Move pgdp kernel/user conversion functions to pgtable.h Make them available on 32 bit and clone_pgd_range() happy. @@ -73,7 +73,7 @@ index e42b8943cb1a..0a9f746cbdc1 100644 * clone_pgd_range(pgd_t *dst, pgd_t *src, int count); * diff --git a/arch/x86/include/asm/pgtable_64.h b/arch/x86/include/asm/pgtable_64.h -index 81462e9a34f6..58d7f10e937d 100644 +index b68bda56db67..5e680838761d 100644 --- a/arch/x86/include/asm/pgtable_64.h +++ b/arch/x86/include/asm/pgtable_64.h @@ -131,55 +131,6 @@ static inline pud_t native_pudp_get_and_clear(pud_t *xp) @@ -133,5 +133,5 @@ index 81462e9a34f6..58d7f10e937d 100644 * Page table pages are page-aligned. The lower half of the top * level is used for userspace and the top half for the kernel. -- -2.13.6 +2.16.2 diff --git a/kernel/kernel/files/patches/mageia/pti32bit-0017-x86-pgtable-Move-pti_set_user_pgd-to-pgtable.h.patch b/kernel/kernel/files/patches/mageia/pti32bit-0019-x86-pgtable-Move-pti_set_user_pgtbl-to-pgtable.h.patch similarity index 74% rename from kernel/kernel/files/patches/mageia/pti32bit-0017-x86-pgtable-Move-pti_set_user_pgd-to-pgtable.h.patch rename to kernel/kernel/files/patches/mageia/pti32bit-0019-x86-pgtable-Move-pti_set_user_pgtbl-to-pgtable.h.patch index 7d8f2eb1..f7ccdc80 100644 --- a/kernel/kernel/files/patches/mageia/pti32bit-0017-x86-pgtable-Move-pti_set_user_pgd-to-pgtable.h.patch +++ b/kernel/kernel/files/patches/mageia/pti32bit-0019-x86-pgtable-Move-pti_set_user_pgtbl-to-pgtable.h.patch @@ -1,7 +1,7 @@ -From 82dd2440260533d518a810905c5492ba4f422a6f Mon Sep 17 00:00:00 2001 +From 88eb961770b7b265bf4725f0d687af8c9cf33467 Mon Sep 17 00:00:00 2001 From: Joerg Roedel Date: Tue, 16 Jan 2018 15:50:39 +0100 -Subject: [PATCH 17/31] x86/pgtable: Move pti_set_user_pgd() to pgtable.h +Subject: [PATCH 19/34] x86/pgtable: Move pti_set_user_pgtbl() to pgtable.h There it is also usable from 32 bit code. @@ -12,7 +12,7 @@ Signed-off-by: Joerg Roedel 2 files changed, 23 insertions(+), 21 deletions(-) diff --git a/arch/x86/include/asm/pgtable.h b/arch/x86/include/asm/pgtable.h -index 0a9f746cbdc1..c9d3cf9ce831 100644 +index 0a9f746cbdc1..1e900c1f8ab1 100644 --- a/arch/x86/include/asm/pgtable.h +++ b/arch/x86/include/asm/pgtable.h @@ -618,8 +618,31 @@ static inline int is_new_memtype_allowed(u64 paddr, unsigned long size, @@ -21,21 +21,21 @@ index 0a9f746cbdc1..c9d3cf9ce831 100644 pte_t *populate_extra_pte(unsigned long vaddr); + +#ifdef CONFIG_PAGE_TABLE_ISOLATION -+pgd_t __pti_set_user_pgd(pgd_t *pgdp, pgd_t pgd); ++pgd_t __pti_set_user_pgtbl(pgd_t *pgdp, pgd_t pgd); + +/* + * Take a PGD location (pgdp) and a pgd value that needs to be set there. + * Populates the user and returns the resulting PGD that must be set in + * the kernel copy of the page tables. + */ -+static inline pgd_t pti_set_user_pgd(pgd_t *pgdp, pgd_t pgd) ++static inline pgd_t pti_set_user_pgtbl(pgd_t *pgdp, pgd_t pgd) +{ + if (!static_cpu_has(X86_FEATURE_PTI)) + return pgd; -+ return __pti_set_user_pgd(pgdp, pgd); ++ return __pti_set_user_pgtbl(pgdp, pgd); +} +#else /* CONFIG_PAGE_TABLE_ISOLATION */ -+static inline pgd_t pti_set_user_pgd(pgd_t *pgdp, pgd_t pgd) ++static inline pgd_t pti_set_user_pgtbl(pgd_t *pgdp, pgd_t pgd) +{ + return pgd; +} @@ -48,7 +48,7 @@ index 0a9f746cbdc1..c9d3cf9ce831 100644 # include #else diff --git a/arch/x86/include/asm/pgtable_64.h b/arch/x86/include/asm/pgtable_64.h -index 58d7f10e937d..396664d95ac9 100644 +index 5e680838761d..4cbf5173dd76 100644 --- a/arch/x86/include/asm/pgtable_64.h +++ b/arch/x86/include/asm/pgtable_64.h @@ -145,27 +145,6 @@ static inline bool pgdp_maps_userspace(void *__ptr) @@ -56,21 +56,21 @@ index 58d7f10e937d..396664d95ac9 100644 } -#ifdef CONFIG_PAGE_TABLE_ISOLATION --pgd_t __pti_set_user_pgd(pgd_t *pgdp, pgd_t pgd); +-pgd_t __pti_set_user_pgtbl(pgd_t *pgdp, pgd_t pgd); - -/* - * Take a PGD location (pgdp) and a pgd value that needs to be set there. - * Populates the user and returns the resulting PGD that must be set in - * the kernel copy of the page tables. - */ --static inline pgd_t pti_set_user_pgd(pgd_t *pgdp, pgd_t pgd) +-static inline pgd_t pti_set_user_pgtbl(pgd_t *pgdp, pgd_t pgd) -{ - if (!static_cpu_has(X86_FEATURE_PTI)) - return pgd; -- return __pti_set_user_pgd(pgdp, pgd); +- return __pti_set_user_pgtbl(pgdp, pgd); -} -#else --static inline pgd_t pti_set_user_pgd(pgd_t *pgdp, pgd_t pgd) +-static inline pgd_t pti_set_user_pgtbl(pgd_t *pgdp, pgd_t pgd) -{ - return pgd; -} @@ -80,5 +80,5 @@ index 58d7f10e937d..396664d95ac9 100644 { #if defined(CONFIG_PAGE_TABLE_ISOLATION) && !defined(CONFIG_X86_5LEVEL) -- -2.13.6 +2.16.2 diff --git a/kernel/kernel/files/patches/mageia/pti32bit-0018-x86-pgtable-Move-two-more-functions-from-pgtable_64..patch b/kernel/kernel/files/patches/mageia/pti32bit-0020-x86-pgtable-Move-two-more-functions-from-pgtable_64..patch similarity index 94% rename from kernel/kernel/files/patches/mageia/pti32bit-0018-x86-pgtable-Move-two-more-functions-from-pgtable_64..patch rename to kernel/kernel/files/patches/mageia/pti32bit-0020-x86-pgtable-Move-two-more-functions-from-pgtable_64..patch index 96040567..419f6fe9 100644 --- a/kernel/kernel/files/patches/mageia/pti32bit-0018-x86-pgtable-Move-two-more-functions-from-pgtable_64..patch +++ b/kernel/kernel/files/patches/mageia/pti32bit-0020-x86-pgtable-Move-two-more-functions-from-pgtable_64..patch @@ -1,7 +1,7 @@ -From 29023f0a7d98a96f2928c80ace36beffe5d28d41 Mon Sep 17 00:00:00 2001 +From 2bcb4034a5d3e49213d4b7e72187b106a50d53f3 Mon Sep 17 00:00:00 2001 From: Joerg Roedel Date: Tue, 16 Jan 2018 12:48:14 +0100 -Subject: [PATCH 18/31] x86/pgtable: Move two more functions from pgtable_64.h +Subject: [PATCH 20/34] x86/pgtable: Move two more functions from pgtable_64.h to pgtable.h These two functions are required for PTI on 32 bit: @@ -45,7 +45,7 @@ index ed8a200ecdaf..925ac1bc45cb 100644 #endif /* _ASM_X86_PGTABLE_3LEVEL_DEFS_H */ diff --git a/arch/x86/include/asm/pgtable.h b/arch/x86/include/asm/pgtable.h -index c9d3cf9ce831..82151f602174 100644 +index 1e900c1f8ab1..981e49a8cdb2 100644 --- a/arch/x86/include/asm/pgtable.h +++ b/arch/x86/include/asm/pgtable.h @@ -1132,6 +1132,22 @@ static inline int pud_write(pud_t pud) @@ -72,7 +72,7 @@ index c9d3cf9ce831..82151f602174 100644 /* * All top-level PAGE_TABLE_ISOLATION page tables are order-1 pages diff --git a/arch/x86/include/asm/pgtable_64.h b/arch/x86/include/asm/pgtable_64.h -index 396664d95ac9..50a02a32a0b3 100644 +index 4cbf5173dd76..e11b92585de4 100644 --- a/arch/x86/include/asm/pgtable_64.h +++ b/arch/x86/include/asm/pgtable_64.h @@ -131,20 +131,6 @@ static inline pud_t native_pudp_get_and_clear(pud_t *xp) @@ -116,5 +116,5 @@ index 6b8f73dcbc2c..e57003a3f58a 100644 + #endif /* _ASM_X86_PGTABLE_64_DEFS_H */ -- -2.13.6 +2.16.2 diff --git a/kernel/kernel/files/patches/mageia/pti32bit-0019-x86-mm-pae-Populate-valid-user-PGD-entries.patch b/kernel/kernel/files/patches/mageia/pti32bit-0021-x86-mm-pae-Populate-valid-user-PGD-entries.patch similarity index 81% rename from kernel/kernel/files/patches/mageia/pti32bit-0019-x86-mm-pae-Populate-valid-user-PGD-entries.patch rename to kernel/kernel/files/patches/mageia/pti32bit-0021-x86-mm-pae-Populate-valid-user-PGD-entries.patch index 4f94c0fe..04281249 100644 --- a/kernel/kernel/files/patches/mageia/pti32bit-0019-x86-mm-pae-Populate-valid-user-PGD-entries.patch +++ b/kernel/kernel/files/patches/mageia/pti32bit-0021-x86-mm-pae-Populate-valid-user-PGD-entries.patch @@ -1,7 +1,7 @@ -From fbd7d587621cdf5c45fc32ae35e8cbec26387ed6 Mon Sep 17 00:00:00 2001 +From 85228cdba0d4634d6a1a162be0d755bd8ed3bdfa Mon Sep 17 00:00:00 2001 From: Joerg Roedel Date: Tue, 16 Jan 2018 15:28:57 +0100 -Subject: [PATCH 19/31] x86/mm/pae: Populate valid user PGD entries +Subject: [PATCH 21/34] x86/mm/pae: Populate valid user PGD entries Generic page-table code populates all non-leaf entries with _KERNPG_TABLE bits set. This is fine for all paging modes @@ -13,11 +13,11 @@ reserved bits. Signed-off-by: Joerg Roedel --- - arch/x86/include/asm/pgtable_types.h | 26 ++++++++++++++++++++++++-- - 1 file changed, 24 insertions(+), 2 deletions(-) + arch/x86/include/asm/pgtable_types.h | 28 ++++++++++++++++++++++++++-- + 1 file changed, 26 insertions(+), 2 deletions(-) diff --git a/arch/x86/include/asm/pgtable_types.h b/arch/x86/include/asm/pgtable_types.h -index 3696398a9475..5027470f4f1c 100644 +index 3696398a9475..48fc70b2d044 100644 --- a/arch/x86/include/asm/pgtable_types.h +++ b/arch/x86/include/asm/pgtable_types.h @@ -50,6 +50,7 @@ @@ -28,7 +28,7 @@ index 3696398a9475..5027470f4f1c 100644 #define _PAGE_PAT (_AT(pteval_t, 1) << _PAGE_BIT_PAT) #define _PAGE_PAT_LARGE (_AT(pteval_t, 1) << _PAGE_BIT_PAT_LARGE) #define _PAGE_SPECIAL (_AT(pteval_t, 1) << _PAGE_BIT_SPECIAL) -@@ -267,14 +268,35 @@ typedef struct pgprot { pgprotval_t pgprot; } pgprot_t; +@@ -267,14 +268,37 @@ typedef struct pgprot { pgprotval_t pgprot; } pgprot_t; typedef struct { pgdval_t pgd; } pgd_t; @@ -38,7 +38,9 @@ index 3696398a9475..5027470f4f1c 100644 + * PHYSICAL_PAGE_MASK might be non-constant when SME is compiled in, so we can't + * use it here. + */ -+#define PGD_PAE_PHYS_MASK (((1ULL << __PHYSICAL_MASK_SHIFT)-1) & PAGE_MASK) ++ ++#define PGD_PAE_PAGE_MASK ((signed long)PAGE_MASK) ++#define PGD_PAE_PHYS_MASK (((1ULL << __PHYSICAL_MASK_SHIFT)-1) & PGD_PAE_PAGE_MASK) + +/* + * PAE allows Base Address, P, PWT, PCD and AVL bits to be set in PGD entries. @@ -67,5 +69,5 @@ index 3696398a9475..5027470f4f1c 100644 static inline pgdval_t pgd_flags(pgd_t pgd) -- -2.13.6 +2.16.2 diff --git a/kernel/kernel/files/patches/mageia/pti32bit-0020-x86-mm-pae-Populate-the-user-page-table-with-user-pg.patch b/kernel/kernel/files/patches/mageia/pti32bit-0022-x86-mm-pae-Populate-the-user-page-table-with-user-pg.patch similarity index 78% rename from kernel/kernel/files/patches/mageia/pti32bit-0020-x86-mm-pae-Populate-the-user-page-table-with-user-pg.patch rename to kernel/kernel/files/patches/mageia/pti32bit-0022-x86-mm-pae-Populate-the-user-page-table-with-user-pg.patch index 138b74f8..02bc60df 100644 --- a/kernel/kernel/files/patches/mageia/pti32bit-0020-x86-mm-pae-Populate-the-user-page-table-with-user-pg.patch +++ b/kernel/kernel/files/patches/mageia/pti32bit-0022-x86-mm-pae-Populate-the-user-page-table-with-user-pg.patch @@ -1,7 +1,7 @@ -From d20f4e476110d1af543b471f317dfc97bec54d7c Mon Sep 17 00:00:00 2001 +From f05eb123abd9d8696ef340e62a37348381ff95fa Mon Sep 17 00:00:00 2001 From: Joerg Roedel Date: Tue, 16 Jan 2018 15:55:17 +0100 -Subject: [PATCH 20/31] x86/mm/pae: Populate the user page-table with user +Subject: [PATCH 22/34] x86/mm/pae: Populate the user page-table with user pgd's When we populate a PGD entry, make sure we populate it in @@ -13,7 +13,7 @@ Signed-off-by: Joerg Roedel 1 file changed, 7 insertions(+) diff --git a/arch/x86/include/asm/pgtable-3level.h b/arch/x86/include/asm/pgtable-3level.h -index bc4af5453802..1a0661be1861 100644 +index bc4af5453802..ab2aa4468293 100644 --- a/arch/x86/include/asm/pgtable-3level.h +++ b/arch/x86/include/asm/pgtable-3level.h @@ -98,6 +98,9 @@ static inline void native_set_pmd(pmd_t *pmdp, pmd_t pmd) @@ -21,7 +21,7 @@ index bc4af5453802..1a0661be1861 100644 static inline void native_set_pud(pud_t *pudp, pud_t pud) { +#ifdef CONFIG_PAGE_TABLE_ISOLATION -+ pud.p4d.pgd = pti_set_user_pgd(&pudp->p4d.pgd, pud.p4d.pgd); ++ pud.p4d.pgd = pti_set_user_pgtbl(&pudp->p4d.pgd, pud.p4d.pgd); +#endif set_64bit((unsigned long long *)(pudp), native_pud_val(pud)); } @@ -31,12 +31,12 @@ index bc4af5453802..1a0661be1861 100644 union split_pud res, *orig = (union split_pud *)pudp; +#ifdef CONFIG_PAGE_TABLE_ISOLATION -+ pti_set_user_pgd(&pudp->p4d.pgd, __pgd(0)); ++ pti_set_user_pgtbl(&pudp->p4d.pgd, __pgd(0)); +#endif + /* xchg acts as a barrier before setting of the high bits */ res.pud_low = xchg(&orig->pud_low, 0); res.pud_high = orig->pud_high; -- -2.13.6 +2.16.2 diff --git a/kernel/kernel/files/patches/mageia/pti32bit-0021-x86-mm-legacy-Populate-the-user-page-table-with-user.patch b/kernel/kernel/files/patches/mageia/pti32bit-0023-x86-mm-legacy-Populate-the-user-page-table-with-user.patch similarity index 77% rename from kernel/kernel/files/patches/mageia/pti32bit-0021-x86-mm-legacy-Populate-the-user-page-table-with-user.patch rename to kernel/kernel/files/patches/mageia/pti32bit-0023-x86-mm-legacy-Populate-the-user-page-table-with-user.patch index ebbafdb4..50bb46d8 100644 --- a/kernel/kernel/files/patches/mageia/pti32bit-0021-x86-mm-legacy-Populate-the-user-page-table-with-user.patch +++ b/kernel/kernel/files/patches/mageia/pti32bit-0023-x86-mm-legacy-Populate-the-user-page-table-with-user.patch @@ -1,7 +1,7 @@ -From c7eb77959596dc4e78ef164f572520767df21fa3 Mon Sep 17 00:00:00 2001 +From 08a22d9c7b62e9c9e08eaf9508f3ef881768a636 Mon Sep 17 00:00:00 2001 From: Joerg Roedel Date: Tue, 16 Jan 2018 16:29:13 +0100 -Subject: [PATCH 21/31] x86/mm/legacy: Populate the user page-table with user +Subject: [PATCH 23/34] x86/mm/legacy: Populate the user page-table with user pgd's Also populate the user-spage pgd's in the user page-table. @@ -12,7 +12,7 @@ Signed-off-by: Joerg Roedel 1 file changed, 9 insertions(+) diff --git a/arch/x86/include/asm/pgtable-2level.h b/arch/x86/include/asm/pgtable-2level.h -index 685ffe8a0eaf..d77255451d7a 100644 +index 685ffe8a0eaf..c399ea5eea41 100644 --- a/arch/x86/include/asm/pgtable-2level.h +++ b/arch/x86/include/asm/pgtable-2level.h @@ -19,6 +19,9 @@ static inline void native_set_pte(pte_t *ptep , pte_t pte) @@ -20,7 +20,7 @@ index 685ffe8a0eaf..d77255451d7a 100644 static inline void native_set_pmd(pmd_t *pmdp, pmd_t pmd) { +#ifdef CONFIG_PAGE_TABLE_ISOLATION -+ pmd.pud.p4d.pgd = pti_set_user_pgd(&pmdp->pud.p4d.pgd, pmd.pud.p4d.pgd); ++ pmd.pud.p4d.pgd = pti_set_user_pgtbl(&pmdp->pud.p4d.pgd, pmd.pud.p4d.pgd); +#endif *pmdp = pmd; } @@ -30,7 +30,7 @@ index 685ffe8a0eaf..d77255451d7a 100644 static inline pmd_t native_pmdp_get_and_clear(pmd_t *xp) { +#ifdef CONFIG_PAGE_TABLE_ISOLATION -+ pti_set_user_pgd(&xp->pud.p4d.pgd, __pgd(0)); ++ pti_set_user_pgtbl(&xp->pud.p4d.pgd, __pgd(0)); +#endif return __pmd(xchg((pmdval_t *)xp, 0)); } @@ -40,11 +40,11 @@ index 685ffe8a0eaf..d77255451d7a 100644 static inline pud_t native_pudp_get_and_clear(pud_t *xp) { +#ifdef CONFIG_PAGE_TABLE_ISOLATION -+ pti_set_user_pgd(&xp->p4d.pgd, __pgd(0)); ++ pti_set_user_pgtbl(&xp->p4d.pgd, __pgd(0)); +#endif return __pud(xchg((pudval_t *)xp, 0)); } #else -- -2.13.6 +2.16.2 diff --git a/kernel/kernel/files/patches/mageia/pti32bit-0022-x86-mm-pti-Add-an-overflow-check-to-pti_clone_pmds.patch b/kernel/kernel/files/patches/mageia/pti32bit-0024-x86-mm-pti-Add-an-overflow-check-to-pti_clone_pmds.patch similarity index 80% rename from kernel/kernel/files/patches/mageia/pti32bit-0022-x86-mm-pti-Add-an-overflow-check-to-pti_clone_pmds.patch rename to kernel/kernel/files/patches/mageia/pti32bit-0024-x86-mm-pti-Add-an-overflow-check-to-pti_clone_pmds.patch index 364a540c..3619c152 100644 --- a/kernel/kernel/files/patches/mageia/pti32bit-0022-x86-mm-pti-Add-an-overflow-check-to-pti_clone_pmds.patch +++ b/kernel/kernel/files/patches/mageia/pti32bit-0024-x86-mm-pti-Add-an-overflow-check-to-pti_clone_pmds.patch @@ -1,7 +1,7 @@ -From 9c0f3c2b70d61e768172c322343b8d049224f8bc Mon Sep 17 00:00:00 2001 +From 9fb9b9305a94eb64cd9bfc007d0457aa16a3429c Mon Sep 17 00:00:00 2001 From: Joerg Roedel Date: Tue, 16 Jan 2018 16:23:52 +0100 -Subject: [PATCH 22/31] x86/mm/pti: Add an overflow check to pti_clone_pmds() +Subject: [PATCH 24/34] x86/mm/pti: Add an overflow check to pti_clone_pmds() The addr counter will overflow if we clone the last PMD of the address space, resulting in an endless loop. @@ -14,7 +14,7 @@ Signed-off-by: Joerg Roedel 1 file changed, 4 insertions(+) diff --git a/arch/x86/mm/pti.c b/arch/x86/mm/pti.c -index ce38f165489b..7f5e698d127c 100644 +index 8f53d2101f64..96a690e6c9b1 100644 --- a/arch/x86/mm/pti.c +++ b/arch/x86/mm/pti.c @@ -282,6 +282,10 @@ pti_clone_pmds(unsigned long start, unsigned long end, pmdval_t clear) @@ -29,5 +29,5 @@ index ce38f165489b..7f5e698d127c 100644 if (WARN_ON(pgd_none(*pgd))) return; -- -2.13.6 +2.16.2 diff --git a/kernel/kernel/files/patches/mageia/pti32bit-0023-x86-mm-pti-Define-X86_CR3_PTI_PCID_USER_BIT-on-x86_3.patch b/kernel/kernel/files/patches/mageia/pti32bit-0025-x86-mm-pti-Define-X86_CR3_PTI_PCID_USER_BIT-on-x86_3.patch similarity index 84% rename from kernel/kernel/files/patches/mageia/pti32bit-0023-x86-mm-pti-Define-X86_CR3_PTI_PCID_USER_BIT-on-x86_3.patch rename to kernel/kernel/files/patches/mageia/pti32bit-0025-x86-mm-pti-Define-X86_CR3_PTI_PCID_USER_BIT-on-x86_3.patch index c6f7d44d..b927eac1 100644 --- a/kernel/kernel/files/patches/mageia/pti32bit-0023-x86-mm-pti-Define-X86_CR3_PTI_PCID_USER_BIT-on-x86_3.patch +++ b/kernel/kernel/files/patches/mageia/pti32bit-0025-x86-mm-pti-Define-X86_CR3_PTI_PCID_USER_BIT-on-x86_3.patch @@ -1,11 +1,12 @@ -From a53c9f48916802bf66a66055537376dbe31716d1 Mon Sep 17 00:00:00 2001 +From b4c87612168011f7e95681027bf1de290da8d668 Mon Sep 17 00:00:00 2001 From: Joerg Roedel Date: Tue, 16 Jan 2018 11:35:19 +0100 -Subject: [PATCH 23/31] x86/mm/pti: Define X86_CR3_PTI_PCID_USER_BIT on x86_32 +Subject: [PATCH 25/34] x86/mm/pti: Define X86_CR3_PTI_PCID_USER_BIT on x86_32 Move it out of the X86_64 specific processor defines so that its visible for 32bit too. +Reviewed-by: Andy Lutomirski Signed-off-by: Joerg Roedel --- arch/x86/include/asm/processor-flags.h | 8 ++++---- @@ -36,5 +37,5 @@ index 625a52a5594f..02c2cbda4a74 100644 + #endif /* _ASM_X86_PROCESSOR_FLAGS_H */ -- -2.13.6 +2.16.2 diff --git a/kernel/kernel/files/patches/mageia/pti32bit-0024-x86-mm-pti-Clone-CPU_ENTRY_AREA-on-PMD-level-on-x86_.patch b/kernel/kernel/files/patches/mageia/pti32bit-0026-x86-mm-pti-Clone-CPU_ENTRY_AREA-on-PMD-level-on-x86_.patch similarity index 89% rename from kernel/kernel/files/patches/mageia/pti32bit-0024-x86-mm-pti-Clone-CPU_ENTRY_AREA-on-PMD-level-on-x86_.patch rename to kernel/kernel/files/patches/mageia/pti32bit-0026-x86-mm-pti-Clone-CPU_ENTRY_AREA-on-PMD-level-on-x86_.patch index f5d73505..26d863cf 100644 --- a/kernel/kernel/files/patches/mageia/pti32bit-0024-x86-mm-pti-Clone-CPU_ENTRY_AREA-on-PMD-level-on-x86_.patch +++ b/kernel/kernel/files/patches/mageia/pti32bit-0026-x86-mm-pti-Clone-CPU_ENTRY_AREA-on-PMD-level-on-x86_.patch @@ -1,7 +1,7 @@ -From 56d5b738711fe0179293e1364d78763edfad55f3 Mon Sep 17 00:00:00 2001 +From c3b8f5b6bbb097409895ea8e00042034408cac54 Mon Sep 17 00:00:00 2001 From: Joerg Roedel Date: Tue, 16 Jan 2018 14:13:04 +0100 -Subject: [PATCH 24/31] x86/mm/pti: Clone CPU_ENTRY_AREA on PMD level on x86_32 +Subject: [PATCH 26/34] x86/mm/pti: Clone CPU_ENTRY_AREA on PMD level on x86_32 Cloning on the P4D level would clone the complete kernel address space into the user-space page-tables for PAE @@ -14,7 +14,7 @@ Signed-off-by: Joerg Roedel 1 file changed, 20 insertions(+) diff --git a/arch/x86/mm/pti.c b/arch/x86/mm/pti.c -index 7f5e698d127c..ec9852abc357 100644 +index 96a690e6c9b1..3ffd92309aca 100644 --- a/arch/x86/mm/pti.c +++ b/arch/x86/mm/pti.c @@ -312,6 +312,7 @@ pti_clone_pmds(unsigned long start, unsigned long end, pmdval_t clear) @@ -52,5 +52,5 @@ index 7f5e698d127c..ec9852abc357 100644 * Clone the ESPFIX P4D into the user space visinble page table */ -- -2.13.6 +2.16.2 diff --git a/kernel/kernel/files/patches/mageia/pti32bit-0025-x86-mm-dump_pagetables-Define-INIT_PGD.patch b/kernel/kernel/files/patches/mageia/pti32bit-0027-x86-mm-dump_pagetables-Define-INIT_PGD.patch similarity index 92% rename from kernel/kernel/files/patches/mageia/pti32bit-0025-x86-mm-dump_pagetables-Define-INIT_PGD.patch rename to kernel/kernel/files/patches/mageia/pti32bit-0027-x86-mm-dump_pagetables-Define-INIT_PGD.patch index be3f674d..bf454270 100644 --- a/kernel/kernel/files/patches/mageia/pti32bit-0025-x86-mm-dump_pagetables-Define-INIT_PGD.patch +++ b/kernel/kernel/files/patches/mageia/pti32bit-0027-x86-mm-dump_pagetables-Define-INIT_PGD.patch @@ -1,7 +1,7 @@ -From 2d0143773e3f3e021b75fcdb886efd7cf2a4e8ce Mon Sep 17 00:00:00 2001 +From 35f7b44b3ce2d5b4c4fe2fabb8905bfff44559d4 Mon Sep 17 00:00:00 2001 From: Joerg Roedel Date: Thu, 8 Feb 2018 09:11:57 +0100 -Subject: [PATCH 25/31] x86/mm/dump_pagetables: Define INIT_PGD +Subject: [PATCH 27/34] x86/mm/dump_pagetables: Define INIT_PGD Define INIT_PGD to point to the correct initial page-table for 32 and 64 bit and use it where needed. This fixes the @@ -57,5 +57,5 @@ index 2a4849e92831..2151ebb6a282 100644 if (!static_cpu_has(X86_FEATURE_PTI)) return; -- -2.13.6 +2.16.2 diff --git a/kernel/kernel/files/patches/mageia/pti32bit-0026-x86-pgtable-pae-Use-separate-kernel-PMDs-for-user-pa.patch b/kernel/kernel/files/patches/mageia/pti32bit-0028-x86-pgtable-pae-Use-separate-kernel-PMDs-for-user-pa.patch similarity index 97% rename from kernel/kernel/files/patches/mageia/pti32bit-0026-x86-pgtable-pae-Use-separate-kernel-PMDs-for-user-pa.patch rename to kernel/kernel/files/patches/mageia/pti32bit-0028-x86-pgtable-pae-Use-separate-kernel-PMDs-for-user-pa.patch index ad8be5ea..48d3ba08 100644 --- a/kernel/kernel/files/patches/mageia/pti32bit-0026-x86-pgtable-pae-Use-separate-kernel-PMDs-for-user-pa.patch +++ b/kernel/kernel/files/patches/mageia/pti32bit-0028-x86-pgtable-pae-Use-separate-kernel-PMDs-for-user-pa.patch @@ -1,7 +1,7 @@ -From eccc6c5333bb7f33f88e7ec9a87f561bc5d63ccd Mon Sep 17 00:00:00 2001 +From c15cbcd9bc3d2e8aaecffc5053dbcf382fe6e56d Mon Sep 17 00:00:00 2001 From: Joerg Roedel Date: Wed, 7 Feb 2018 15:37:52 +0100 -Subject: [PATCH 26/31] x86/pgtable/pae: Use separate kernel PMDs for user +Subject: [PATCH 28/34] x86/pgtable/pae: Use separate kernel PMDs for user page-table We need separate kernel PMDs in the user page-table when PTI @@ -209,5 +209,5 @@ index a81d42e48922..d95bc7b1ffb4 100644 _pgd_free(pgd); out: -- -2.13.6 +2.16.2 diff --git a/kernel/kernel/files/patches/mageia/pti32bit-0027-x86-ldt-Reserve-address-space-range-on-32-bit-for-th.patch b/kernel/kernel/files/patches/mageia/pti32bit-0029-x86-ldt-Reserve-address-space-range-on-32-bit-for-th.patch similarity index 87% rename from kernel/kernel/files/patches/mageia/pti32bit-0027-x86-ldt-Reserve-address-space-range-on-32-bit-for-th.patch rename to kernel/kernel/files/patches/mageia/pti32bit-0029-x86-ldt-Reserve-address-space-range-on-32-bit-for-th.patch index 1ceb7ec0..28f11c02 100644 --- a/kernel/kernel/files/patches/mageia/pti32bit-0027-x86-ldt-Reserve-address-space-range-on-32-bit-for-th.patch +++ b/kernel/kernel/files/patches/mageia/pti32bit-0029-x86-ldt-Reserve-address-space-range-on-32-bit-for-th.patch @@ -1,7 +1,7 @@ -From c07a31bb57363adb6f9d0def1d6b7a16b4a5c72c Mon Sep 17 00:00:00 2001 +From dd247e8ec4d2eeefdcb6ad173f1eef8007f54101 Mon Sep 17 00:00:00 2001 From: Joerg Roedel Date: Tue, 16 Jan 2018 12:40:07 +0100 -Subject: [PATCH 27/31] x86/ldt: Reserve address-space range on 32 bit for the +Subject: [PATCH 29/34] x86/ldt: Reserve address-space range on 32 bit for the LDT Reserve 2MB/4MB of address-space for mapping the LDT to @@ -40,26 +40,26 @@ diff --git a/arch/x86/mm/dump_pagetables.c b/arch/x86/mm/dump_pagetables.c index 2151ebb6a282..fdefdf05739c 100644 --- a/arch/x86/mm/dump_pagetables.c +++ b/arch/x86/mm/dump_pagetables.c -@@ -117,6 +117,9 @@ enum address_markers_idx { +@@ -116,6 +116,9 @@ enum address_markers_idx { + VMALLOC_END_NR, #ifdef CONFIG_HIGHMEM PKMAP_BASE_NR, - #endif ++#endif +#ifdef CONFIG_MODIFY_LDT_SYSCALL + LDT_NR, -+#endif + #endif CPU_ENTRY_AREA_NR, FIXADDR_START_NR, - END_OF_SPACE_NR, -@@ -130,6 +133,9 @@ static struct addr_marker address_markers[] = { +@@ -129,6 +132,9 @@ static struct addr_marker address_markers[] = { + [VMALLOC_END_NR] = { 0UL, "vmalloc() End" }, #ifdef CONFIG_HIGHMEM [PKMAP_BASE_NR] = { 0UL, "Persistent kmap() Area" }, - #endif ++#endif +#ifdef CONFIG_MODIFY_LDT_SYSCALL + [LDT_NR] = { 0UL, "LDT remap" }, -+#endif + #endif [CPU_ENTRY_AREA_NR] = { 0UL, "CPU entry area" }, [FIXADDR_START_NR] = { 0UL, "Fixmap area" }, - [END_OF_SPACE_NR] = { -1, NULL } @@ -579,6 +585,9 @@ static int __init pt_dump_init(void) # endif address_markers[FIXADDR_START_NR].start_address = FIXADDR_START; @@ -71,5 +71,5 @@ index 2151ebb6a282..fdefdf05739c 100644 return 0; } -- -2.13.6 +2.16.2 diff --git a/kernel/kernel/files/patches/mageia/pti32bit-0028-x86-ldt-Define-LDT_END_ADDR.patch b/kernel/kernel/files/patches/mageia/pti32bit-0030-x86-ldt-Define-LDT_END_ADDR.patch similarity index 94% rename from kernel/kernel/files/patches/mageia/pti32bit-0028-x86-ldt-Define-LDT_END_ADDR.patch rename to kernel/kernel/files/patches/mageia/pti32bit-0030-x86-ldt-Define-LDT_END_ADDR.patch index 19f4dfd9..f6aebd55 100644 --- a/kernel/kernel/files/patches/mageia/pti32bit-0028-x86-ldt-Define-LDT_END_ADDR.patch +++ b/kernel/kernel/files/patches/mageia/pti32bit-0030-x86-ldt-Define-LDT_END_ADDR.patch @@ -1,7 +1,7 @@ -From 2b4c93fdb404c6155b1f7098895b93cde7b79550 Mon Sep 17 00:00:00 2001 +From e00857066a9f75a64a00528d451be9899ec7328f Mon Sep 17 00:00:00 2001 From: Joerg Roedel Date: Wed, 7 Feb 2018 17:44:44 +0100 -Subject: [PATCH 28/31] x86/ldt: Define LDT_END_ADDR +Subject: [PATCH 30/34] x86/ldt: Define LDT_END_ADDR It marks the end of the address-space range reserved for the LDT. The LDT-code will use it when unmapping the LDT for @@ -60,5 +60,5 @@ index 26d713ecad34..f3c2fbf3c458 100644 if (!static_cpu_has(X86_FEATURE_PTI)) return; -- -2.13.6 +2.16.2 diff --git a/kernel/kernel/files/patches/mageia/pti32bit-0029-x86-ldt-Split-out-sanity-check-in-map_ldt_struct.patch b/kernel/kernel/files/patches/mageia/pti32bit-0031-x86-ldt-Split-out-sanity-check-in-map_ldt_struct.patch similarity index 96% rename from kernel/kernel/files/patches/mageia/pti32bit-0029-x86-ldt-Split-out-sanity-check-in-map_ldt_struct.patch rename to kernel/kernel/files/patches/mageia/pti32bit-0031-x86-ldt-Split-out-sanity-check-in-map_ldt_struct.patch index aad46d37..14453bad 100644 --- a/kernel/kernel/files/patches/mageia/pti32bit-0029-x86-ldt-Split-out-sanity-check-in-map_ldt_struct.patch +++ b/kernel/kernel/files/patches/mageia/pti32bit-0031-x86-ldt-Split-out-sanity-check-in-map_ldt_struct.patch @@ -1,7 +1,7 @@ -From 9a4c777654ebe02d30461d2a8a05de6fe4b987f0 Mon Sep 17 00:00:00 2001 +From 126ef631acff4fe06d76992f40e04237d7d57344 Mon Sep 17 00:00:00 2001 From: Joerg Roedel Date: Wed, 7 Feb 2018 18:02:18 +0100 -Subject: [PATCH 29/31] x86/ldt: Split out sanity check in map_ldt_struct() +Subject: [PATCH 31/34] x86/ldt: Split out sanity check in map_ldt_struct() This splits out the mapping sanity check and the actual mapping of the LDT to user-space from the map_ldt_struct() @@ -142,5 +142,5 @@ index f3c2fbf3c458..8ab7df99c868 100644 { #ifdef CONFIG_PAGE_TABLE_ISOLATION -- -2.13.6 +2.16.2 diff --git a/kernel/kernel/files/patches/mageia/pti32bit-0030-x86-ldt-Enable-LDT-user-mapping-for-PAE.patch b/kernel/kernel/files/patches/mageia/pti32bit-0032-x86-ldt-Enable-LDT-user-mapping-for-PAE.patch similarity index 95% rename from kernel/kernel/files/patches/mageia/pti32bit-0030-x86-ldt-Enable-LDT-user-mapping-for-PAE.patch rename to kernel/kernel/files/patches/mageia/pti32bit-0032-x86-ldt-Enable-LDT-user-mapping-for-PAE.patch index 2436cc5a..d1d98bfc 100644 --- a/kernel/kernel/files/patches/mageia/pti32bit-0030-x86-ldt-Enable-LDT-user-mapping-for-PAE.patch +++ b/kernel/kernel/files/patches/mageia/pti32bit-0032-x86-ldt-Enable-LDT-user-mapping-for-PAE.patch @@ -1,7 +1,7 @@ -From 94b5cc7e833ec2b9427fa42f8de203f2f4c98bc5 Mon Sep 17 00:00:00 2001 +From 1d4ac3c5063abdada00ad78e0ccf74c7de4b365d Mon Sep 17 00:00:00 2001 From: Joerg Roedel Date: Wed, 7 Feb 2018 18:11:54 +0100 -Subject: [PATCH 30/31] x86/ldt: Enable LDT user-mapping for PAE +Subject: [PATCH 32/34] x86/ldt: Enable LDT user-mapping for PAE This adds the needed special case for PAE to get the LDT mapped into the user page-table when PTI is enabled. The big @@ -103,5 +103,5 @@ index 8ab7df99c868..778745199d96 100644 * If PTI is enabled, this maps the LDT into the kernelmode and * usermode tables for the given mm. -- -2.13.6 +2.16.2 diff --git a/kernel/kernel/files/patches/mageia/pti32bit-0031-x86-pti-Allow-CONFIG_PAGE_TABLE_ISOLATION-for-x86_32.patch b/kernel/kernel/files/patches/mageia/pti32bit-0033-x86-pti-Allow-CONFIG_PAGE_TABLE_ISOLATION-for-x86_32.patch similarity index 83% rename from kernel/kernel/files/patches/mageia/pti32bit-0031-x86-pti-Allow-CONFIG_PAGE_TABLE_ISOLATION-for-x86_32.patch rename to kernel/kernel/files/patches/mageia/pti32bit-0033-x86-pti-Allow-CONFIG_PAGE_TABLE_ISOLATION-for-x86_32.patch index 53ee21fc..d6842089 100644 --- a/kernel/kernel/files/patches/mageia/pti32bit-0031-x86-pti-Allow-CONFIG_PAGE_TABLE_ISOLATION-for-x86_32.patch +++ b/kernel/kernel/files/patches/mageia/pti32bit-0033-x86-pti-Allow-CONFIG_PAGE_TABLE_ISOLATION-for-x86_32.patch @@ -1,7 +1,7 @@ -From dbb0074f778b396a11e0c897fef9d0c4583e7ccb Mon Sep 17 00:00:00 2001 +From c15b3c596de19962f32b8aecb5abe56a9455a342 Mon Sep 17 00:00:00 2001 From: Joerg Roedel Date: Tue, 16 Jan 2018 11:33:01 +0100 -Subject: [PATCH 31/31] x86/pti: Allow CONFIG_PAGE_TABLE_ISOLATION for x86_32 +Subject: [PATCH 33/34] x86/pti: Allow CONFIG_PAGE_TABLE_ISOLATION for x86_32 Allow PTI to be compiled on x86_32. diff --git a/kernel/kernel/files/patches/mageia/pti32bit-0034-x86-mm-pti-Add-Warning-when-booting-on-a-PCID-capabl.patch b/kernel/kernel/files/patches/mageia/pti32bit-0034-x86-mm-pti-Add-Warning-when-booting-on-a-PCID-capabl.patch new file mode 100644 index 00000000..1339d475 --- /dev/null +++ b/kernel/kernel/files/patches/mageia/pti32bit-0034-x86-mm-pti-Add-Warning-when-booting-on-a-PCID-capabl.patch @@ -0,0 +1,45 @@ +From e7591bc0c06694418c773c099f84b79003257069 Mon Sep 17 00:00:00 2001 +From: Joerg Roedel +Date: Mon, 12 Feb 2018 19:47:19 +0100 +Subject: [PATCH 34/34] x86/mm/pti: Add Warning when booting on a PCID capable + CPU + +Warn the user in case the performance can be significantly +improved by switching to a 64-bit kernel. + +Suggested-by: Andy Lutomirski +Signed-off-by: Joerg Roedel +--- + arch/x86/mm/pti.c | 16 ++++++++++++++++ + 1 file changed, 16 insertions(+) + +diff --git a/arch/x86/mm/pti.c b/arch/x86/mm/pti.c +index 3ffd92309aca..8f5aa0dda327 100644 +--- a/arch/x86/mm/pti.c ++++ b/arch/x86/mm/pti.c +@@ -385,6 +385,22 @@ void __init pti_init(void) + + pr_info("enabled\n"); + ++#ifdef CONFIG_X86_32 ++ if (boot_cpu_has(X86_FEATURE_PCID)) { ++ /* Use printk to work around pr_fmt() */ ++ printk(KERN_WARNING "\n"); ++ printk(KERN_WARNING "************************************************************\n"); ++ printk(KERN_WARNING "** WARNING! WARNING! WARNING! WARNING! WARNING! WARNING! **\n"); ++ printk(KERN_WARNING "** **\n"); ++ printk(KERN_WARNING "** You are using 32-bit PTI on a 64-bit PCID-capable CPU. **\n"); ++ printk(KERN_WARNING "** Your performance will increase dramatically if you **\n"); ++ printk(KERN_WARNING "** switch to a 64-bit kernel! **\n"); ++ printk(KERN_WARNING "** **\n"); ++ printk(KERN_WARNING "** WARNING! WARNING! WARNING! WARNING! WARNING! WARNING! **\n"); ++ printk(KERN_WARNING "************************************************************\n"); ++ } ++#endif ++ + pti_clone_user_shared(); + pti_clone_entry_text(); + pti_setup_espfix64(); +-- +2.16.2 + diff --git a/kernel/kernel/files/patches/mageia/pti32bit-0100-tone-down-PCID-on-32bit-message.patch b/kernel/kernel/files/patches/mageia/pti32bit-0100-tone-down-PCID-on-32bit-message.patch new file mode 100644 index 00000000..9e14a8ea --- /dev/null +++ b/kernel/kernel/files/patches/mageia/pti32bit-0100-tone-down-PCID-on-32bit-message.patch @@ -0,0 +1,32 @@ + +Dont scare people with something that should be an informal message. + +Signed-off-by: Thomas Backlund + +--- linux/arch/x86/mm/pti.c.orig ++++ linux/arch/x86/mm/pti.c +@@ -388,16 +388,14 @@ void __init pti_init(void) + #ifdef CONFIG_X86_32 + if (boot_cpu_has(X86_FEATURE_PCID)) { + /* Use printk to work around pr_fmt() */ +- printk(KERN_WARNING "\n"); +- printk(KERN_WARNING "************************************************************\n"); +- printk(KERN_WARNING "** WARNING! WARNING! WARNING! WARNING! WARNING! WARNING! **\n"); +- printk(KERN_WARNING "** **\n"); +- printk(KERN_WARNING "** You are using 32-bit PTI on a 64-bit PCID-capable CPU. **\n"); +- printk(KERN_WARNING "** Your performance will increase dramatically if you **\n"); +- printk(KERN_WARNING "** switch to a 64-bit kernel! **\n"); +- printk(KERN_WARNING "** **\n"); +- printk(KERN_WARNING "** WARNING! WARNING! WARNING! WARNING! WARNING! WARNING! **\n"); +- printk(KERN_WARNING "************************************************************\n"); ++ printk(KERN_INFO "\n"); ++ printk(KERN_INFO "************************************************************\n"); ++ printk(KERN_INFO "** **\n"); ++ printk(KERN_INFO "** You are using 32-bit PTI on a 64-bit PCID-capable CPU. **\n"); ++ printk(KERN_INFO "** Your performance will increase dramatically if you **\n"); ++ printk(KERN_INFO "** switch to a 64-bit install. **\n"); ++ printk(KERN_INFO "** **\n"); ++ printk(KERN_INFO "************************************************************\n"); + } + #endif + diff --git a/kernel/kernel/files/patches/mageia/scsi-core-Avoid-that-ATA-error-handling-can-trigger-a-kernel-hang-or-oops.patch b/kernel/kernel/files/patches/mageia/scsi-core-Avoid-that-ATA-error-handling-can-trigger-a-kernel-hang-or-oops.patch new file mode 100644 index 00000000..c2bdadef --- /dev/null +++ b/kernel/kernel/files/patches/mageia/scsi-core-Avoid-that-ATA-error-handling-can-trigger-a-kernel-hang-or-oops.patch @@ -0,0 +1,126 @@ +From 3be8828fc507cdafe7040a3dcf361a2bcd8e305b Mon Sep 17 00:00:00 2001 +From: Bart Van Assche +Date: Thu, 22 Feb 2018 11:30:20 -0800 +Subject: scsi: core: Avoid that ATA error handling can trigger a kernel hang + or oops + +Avoid that the recently introduced call_rcu() call in the SCSI core +triggers a double call_rcu() call. + +Reported-by: Natanael Copa +Reported-by: Damien Le Moal +References: https://bugzilla.kernel.org/show_bug.cgi?id=198861 +Fixes: 3bd6f43f5cb3 ("scsi: core: Ensure that the SCSI error handler gets woken up") +Signed-off-by: Bart Van Assche +Reviewed-by: Damien Le Moal +Tested-by: Damien Le Moal +Cc: Natanael Copa +Cc: Damien Le Moal +Cc: Alexandre Oliva +Cc: Pavel Tikhomirov +Cc: Hannes Reinecke +Cc: Johannes Thumshirn +Cc: +Signed-off-by: Martin K. Petersen +--- + drivers/scsi/hosts.c | 3 --- + drivers/scsi/scsi_error.c | 5 +++-- + drivers/scsi/scsi_lib.c | 2 ++ + include/scsi/scsi_cmnd.h | 3 +++ + include/scsi/scsi_host.h | 2 -- + 5 files changed, 8 insertions(+), 7 deletions(-) + +diff --git a/drivers/scsi/hosts.c b/drivers/scsi/hosts.c +index 57bf43e..dd94649 100644 +--- a/drivers/scsi/hosts.c ++++ b/drivers/scsi/hosts.c +@@ -328,8 +328,6 @@ static void scsi_host_dev_release(struct device *dev) + if (shost->work_q) + destroy_workqueue(shost->work_q); + +- destroy_rcu_head(&shost->rcu); +- + if (shost->shost_state == SHOST_CREATED) { + /* + * Free the shost_dev device name here if scsi_host_alloc() +@@ -404,7 +402,6 @@ struct Scsi_Host *scsi_host_alloc(struct scsi_host_template *sht, int privsize) + INIT_LIST_HEAD(&shost->starved_list); + init_waitqueue_head(&shost->host_wait); + mutex_init(&shost->scan_mutex); +- init_rcu_head(&shost->rcu); + + index = ida_simple_get(&host_index_ida, 0, 0, GFP_KERNEL); + if (index < 0) +diff --git a/drivers/scsi/scsi_error.c b/drivers/scsi/scsi_error.c +index d042915..ca53a5f 100644 +--- a/drivers/scsi/scsi_error.c ++++ b/drivers/scsi/scsi_error.c +@@ -223,7 +223,8 @@ static void scsi_eh_reset(struct scsi_cmnd *scmd) + + static void scsi_eh_inc_host_failed(struct rcu_head *head) + { +- struct Scsi_Host *shost = container_of(head, typeof(*shost), rcu); ++ struct scsi_cmnd *scmd = container_of(head, typeof(*scmd), rcu); ++ struct Scsi_Host *shost = scmd->device->host; + unsigned long flags; + + spin_lock_irqsave(shost->host_lock, flags); +@@ -259,7 +260,7 @@ void scsi_eh_scmd_add(struct scsi_cmnd *scmd) + * Ensure that all tasks observe the host state change before the + * host_failed change. + */ +- call_rcu(&shost->rcu, scsi_eh_inc_host_failed); ++ call_rcu(&scmd->rcu, scsi_eh_inc_host_failed); + } + + /** +diff --git a/drivers/scsi/scsi_lib.c b/drivers/scsi/scsi_lib.c +index 5cbc69b..4af1682 100644 +--- a/drivers/scsi/scsi_lib.c ++++ b/drivers/scsi/scsi_lib.c +@@ -670,6 +670,7 @@ static bool scsi_end_request(struct request *req, blk_status_t error, + if (!blk_rq_is_scsi(req)) { + WARN_ON_ONCE(!(cmd->flags & SCMD_INITIALIZED)); + cmd->flags &= ~SCMD_INITIALIZED; ++ destroy_rcu_head(&cmd->rcu); + } + + if (req->mq_ctx) { +@@ -1150,6 +1151,7 @@ static void scsi_initialize_rq(struct request *rq) + struct scsi_cmnd *cmd = blk_mq_rq_to_pdu(rq); + + scsi_req_init(&cmd->req); ++ init_rcu_head(&cmd->rcu); + cmd->jiffies_at_alloc = jiffies; + cmd->retries = 0; + } +diff --git a/include/scsi/scsi_cmnd.h b/include/scsi/scsi_cmnd.h +index 949a016..0382cea 100644 +--- a/include/scsi/scsi_cmnd.h ++++ b/include/scsi/scsi_cmnd.h +@@ -69,6 +69,9 @@ struct scsi_cmnd { + struct list_head list; /* scsi_cmnd participates in queue lists */ + struct list_head eh_entry; /* entry for the host eh_cmd_q */ + struct delayed_work abort_work; ++ ++ struct rcu_head rcu; ++ + int eh_eflags; /* Used by error handlr */ + + /* +diff --git a/include/scsi/scsi_host.h b/include/scsi/scsi_host.h +index 1a1df0d..a8b7bf8 100644 +--- a/include/scsi/scsi_host.h ++++ b/include/scsi/scsi_host.h +@@ -571,8 +571,6 @@ struct Scsi_Host { + struct blk_mq_tag_set tag_set; + }; + +- struct rcu_head rcu; +- + atomic_t host_busy; /* commands actually active on low-level */ + atomic_t host_blocked; + +-- +cgit v1.1 + diff --git a/kernel/kernel/files/patches/mageia/scsi-core-return-BLK_STS_OK-for-DID_OK-in-__scsi_error_from_host_byte.patch b/kernel/kernel/files/patches/mageia/scsi-core-return-BLK_STS_OK-for-DID_OK-in-__scsi_error_from_host_byte.patch new file mode 100644 index 00000000..30489291 --- /dev/null +++ b/kernel/kernel/files/patches/mageia/scsi-core-return-BLK_STS_OK-for-DID_OK-in-__scsi_error_from_host_byte.patch @@ -0,0 +1,34 @@ +From e39a97353e5378eb46bf01679799c5704d397f32 Mon Sep 17 00:00:00 2001 +From: Hannes Reinecke +Date: Mon, 26 Feb 2018 08:39:59 +0100 +Subject: scsi: core: return BLK_STS_OK for DID_OK in + __scsi_error_from_host_byte() + +When converting __scsi_error_from_host_byte() to BLK_STS error codes the +case DID_OK was forgotten, resulting in it always returning an error. + +Fixes: 2a842acab109 ("block: introduce new block status code type") +Cc: Doug Gilbert +Signed-off-by: Hannes Reinecke +Reviewed-by: Douglas Gilbert +Signed-off-by: Martin K. Petersen +--- + drivers/scsi/scsi_lib.c | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/drivers/scsi/scsi_lib.c b/drivers/scsi/scsi_lib.c +index 4af1682..c984404 100644 +--- a/drivers/scsi/scsi_lib.c ++++ b/drivers/scsi/scsi_lib.c +@@ -720,6 +720,8 @@ static blk_status_t __scsi_error_from_host_byte(struct scsi_cmnd *cmd, + int result) + { + switch (host_byte(result)) { ++ case DID_OK: ++ return BLK_STS_OK; + case DID_TRANSPORT_FAILFAST: + return BLK_STS_TRANSPORT; + case DID_TARGET_FAILURE: +-- +cgit v1.1 + diff --git a/kernel/kernel/files/patches/mageia/scsi-qla2xxx-Fix-NULL-pointer-crash-due-to-active-timer-for-ABTS.patch b/kernel/kernel/files/patches/mageia/scsi-qla2xxx-Fix-NULL-pointer-crash-due-to-active-timer-for-ABTS.patch new file mode 100644 index 00000000..07d56db5 --- /dev/null +++ b/kernel/kernel/files/patches/mageia/scsi-qla2xxx-Fix-NULL-pointer-crash-due-to-active-timer-for-ABTS.patch @@ -0,0 +1,119 @@ +From 1514839b366417934e2f1328edb50ed1e8a719f5 Mon Sep 17 00:00:00 2001 +From: "himanshu.madhani@cavium.com" +Date: Mon, 12 Feb 2018 10:28:14 -0800 +Subject: scsi: qla2xxx: Fix NULL pointer crash due to active timer for ABTS + +This patch fixes NULL pointer crash due to active timer running for abort +IOCB. + +From crash dump analysis it was discoverd that get_next_timer_interrupt() +encountered a corrupted entry on the timer list. + + #9 [ffff95e1f6f0fd40] page_fault at ffffffff914fe8f8 + [exception RIP: get_next_timer_interrupt+440] + RIP: ffffffff90ea3088 RSP: ffff95e1f6f0fdf0 RFLAGS: 00010013 + RAX: ffff95e1f6451028 RBX: 000218e2389e5f40 RCX: 00000001232ad600 + RDX: 0000000000000001 RSI: ffff95e1f6f0fdf0 RDI: 0000000001232ad6 + RBP: ffff95e1f6f0fe40 R8: ffff95e1f6451188 R9: 0000000000000001 + R10: 0000000000000016 R11: 0000000000000016 R12: 00000001232ad5f6 + R13: ffff95e1f6450000 R14: ffff95e1f6f0fdf8 R15: ffff95e1f6f0fe10 + ORIG_RAX: ffffffffffffffff CS: 0010 SS: 0018 + +Looking at the assembly of get_next_timer_interrupt(), address came +from %r8 (ffff95e1f6451188) which is pointing to list_head with single +entry at ffff95e5ff621178. + + 0xffffffff90ea307a : mov (%r8),%rdx + 0xffffffff90ea307d : cmp %r8,%rdx + 0xffffffff90ea3080 : je 0xffffffff90ea30a7 + 0xffffffff90ea3082 : nopw 0x0(%rax,%rax,1) + 0xffffffff90ea3088 : testb $0x1,0x18(%rdx) + + crash> rd ffff95e1f6451188 10 + ffff95e1f6451188: ffff95e5ff621178 ffff95e5ff621178 x.b.....x.b..... + ffff95e1f6451198: ffff95e1f6451198 ffff95e1f6451198 ..E.......E..... + ffff95e1f64511a8: ffff95e1f64511a8 ffff95e1f64511a8 ..E.......E..... + ffff95e1f64511b8: ffff95e77cf509a0 ffff95e77cf509a0 ...|.......|.... + ffff95e1f64511c8: ffff95e1f64511c8 ffff95e1f64511c8 ..E.......E..... + + crash> rd ffff95e5ff621178 10 + ffff95e5ff621178: 0000000000000001 ffff95e15936aa00 ..........6Y.... + ffff95e5ff621188: 0000000000000000 00000000ffffffff ................ + ffff95e5ff621198: 00000000000000a0 0000000000000010 ................ + ffff95e5ff6211a8: ffff95e5ff621198 000000000000000c ..b............. + ffff95e5ff6211b8: 00000f5800000000 ffff95e751f8d720 ....X... ..Q.... + + ffff95e5ff621178 belongs to freed mempool object at ffff95e5ff621080. + + CACHE NAME OBJSIZE ALLOCATED TOTAL SLABS SSIZE + ffff95dc7fd74d00 mnt_cache 384 19785 24948 594 16k + SLAB MEMORY NODE TOTAL ALLOCATED FREE + ffffdc5dabfd8800 ffff95e5ff620000 1 42 29 13 + FREE / [ALLOCATED] + ffff95e5ff621080 (cpu 6 cache) + +Examining the contents of that memory reveals a pointer to a constant string +in the driver, "abort\0", which is set by qla24xx_async_abort_cmd(). + + crash> rd ffffffffc059277c 20 + ffffffffc059277c: 6e490074726f6261 0074707572726574 abort.Interrupt. + ffffffffc059278c: 00676e696c6c6f50 6920726576697244 Polling.Driver i + ffffffffc059279c: 646f6d207325206e 6974736554000a65 n %s mode..Testi + ffffffffc05927ac: 636976656420676e 786c252074612065 ng device at %lx + ffffffffc05927bc: 6b63656843000a2e 646f727020676e69 ...Checking prod + ffffffffc05927cc: 6f20444920746375 0a2e706968632066 uct ID of chip.. + ffffffffc05927dc: 5120646e756f4600 204130303232414c .Found QLA2200A + ffffffffc05927ec: 43000a2e70696843 20676e696b636568 Chip...Checking + ffffffffc05927fc: 65786f626c69616d 6c636e69000a2e73 mailboxes...incl + ffffffffc059280c: 756e696c2f656475 616d2d616d642f78 ude/linux/dma-ma + + crash> struct -ox srb_iocb + struct srb_iocb { + union { + struct {...} logio; + struct {...} els_logo; + struct {...} tmf; + struct {...} fxiocb; + struct {...} abt; + struct ct_arg ctarg; + struct {...} mbx; + struct {...} nack; + [0x0 ] } u; + [0xb8] struct timer_list timer; + [0x108] void (*timeout)(void *); + } + SIZE: 0x110 + + crash> ! bc + ibase=16 + obase=10 + B8+40 + F8 + +The object is a srb_t, and at offset 0xf8 within that structure +(i.e. ffff95e5ff621080 + f8 -> ffff95e5ff621178) is a struct timer_list. + +Cc: #4.4+ +Fixes: 4440e46d5db7 ("[SCSI] qla2xxx: Add IOCB Abort command asynchronous handling.") +Signed-off-by: Himanshu Madhani +Reviewed-by: Johannes Thumshirn +Signed-off-by: Martin K. Petersen +--- + drivers/scsi/qla2xxx/qla_init.c | 1 + + 1 file changed, 1 insertion(+) + +diff --git a/drivers/scsi/qla2xxx/qla_init.c b/drivers/scsi/qla2xxx/qla_init.c +index 2dea112..0487062 100644 +--- a/drivers/scsi/qla2xxx/qla_init.c ++++ b/drivers/scsi/qla2xxx/qla_init.c +@@ -1527,6 +1527,7 @@ qla24xx_abort_sp_done(void *ptr, int res) + srb_t *sp = ptr; + struct srb_iocb *abt = &sp->u.iocb_cmd; + ++ del_timer(&sp->u.iocb_cmd.timer); + complete(&abt->u.abt.comp); + } + +-- +cgit v1.1 + diff --git a/kernel/kernel/files/patches/mageia/series b/kernel/kernel/files/patches/mageia/series index f2118064..eaf1d51c 100644 --- a/kernel/kernel/files/patches/mageia/series +++ b/kernel/kernel/files/patches/mageia/series @@ -14,6 +14,7 @@ ### ### Stable Queue ### +patch-4.14.25-rc1.patch ### ### Arch x86 @@ -45,35 +46,40 @@ pti32bit-0003-x86-entry-32-Load-task-stack-from-x86_tss.sp1-in-SYS.patch pti32bit-0004-x86-entry-32-Put-ESPFIX-code-into-a-macro.patch pti32bit-0005-x86-entry-32-Unshare-NMI-return-path.patch pti32bit-0006-x86-entry-32-Split-off-return-to-kernel-path.patch +# could be disabled as not needed according to Linus @ LKML pti32bit-0007-x86-entry-32-Restore-segments-before-int-registers.patch pti32bit-0008-x86-entry-32-Enter-the-kernel-via-trampoline-stack.patch pti32bit-0009-x86-entry-32-Leave-the-kernel-via-trampoline-stack.patch pti32bit-0010-x86-entry-32-Introduce-SAVE_ALL_NMI-and-RESTORE_ALL_.patch -pti32bit-0011-x86-entry-32-Add-PTI-cr3-switches-to-NMI-handler-cod.patch -pti32bit-0012-x86-entry-32-Add-PTI-cr3-switch-to-non-NMI-entry-exi.patch -pti32bit-0013-x86-entry-32-Handle-Entry-from-Kernel-Mode-on-Entry-.patch -pti32bit-0014-x86-pgtable-pae-Unshare-kernel-PMDs-when-PTI-is-enab.patch -pti32bit-0015-x86-pgtable-32-Allocate-8k-page-tables-when-PTI-is-e.patch -pti32bit-0016-x86-pgtable-Move-pgdp-kernel-user-conversion-functio.patch -pti32bit-0017-x86-pgtable-Move-pti_set_user_pgd-to-pgtable.h.patch -pti32bit-0018-x86-pgtable-Move-two-more-functions-from-pgtable_64..patch -pti32bit-0019-x86-mm-pae-Populate-valid-user-PGD-entries.patch -pti32bit-0020-x86-mm-pae-Populate-the-user-page-table-with-user-pg.patch -pti32bit-0021-x86-mm-legacy-Populate-the-user-page-table-with-user.patch -pti32bit-0022-x86-mm-pti-Add-an-overflow-check-to-pti_clone_pmds.patch -pti32bit-0023-x86-mm-pti-Define-X86_CR3_PTI_PCID_USER_BIT-on-x86_3.patch -pti32bit-0024-x86-mm-pti-Clone-CPU_ENTRY_AREA-on-PMD-level-on-x86_.patch -pti32bit-0025-x86-mm-dump_pagetables-Define-INIT_PGD.patch -pti32bit-0026-x86-pgtable-pae-Use-separate-kernel-PMDs-for-user-pa.patch -pti32bit-0027-x86-ldt-Reserve-address-space-range-on-32-bit-for-th.patch -pti32bit-0028-x86-ldt-Define-LDT_END_ADDR.patch -pti32bit-0029-x86-ldt-Split-out-sanity-check-in-map_ldt_struct.patch -pti32bit-0030-x86-ldt-Enable-LDT-user-mapping-for-PAE.patch -pti32bit-0031-x86-pti-Allow-CONFIG_PAGE_TABLE_ISOLATION-for-x86_32.patch +pti32bit-0011-x86-entry-32-Handle-Entry-from-Kernel-Mode-on-Entry-.patch +pti32bit-0012-x86-entry-32-Simplify-debug-entry-point.patch +pti32bit-0013-x86-entry-32-Add-PTI-cr3-switches-to-NMI-handler-cod.patch +pti32bit-0014-x86-entry-32-Add-PTI-cr3-switch-to-non-NMI-entry-exi.patch +pti32bit-0015-x86-pgtable-Rename-pti_set_user_pgd-to-pti_set_user_.patch +pti32bit-0016-x86-pgtable-pae-Unshare-kernel-PMDs-when-PTI-is-enab.patch +pti32bit-0017-x86-pgtable-32-Allocate-8k-page-tables-when-PTI-is-e.patch +pti32bit-0018-x86-pgtable-Move-pgdp-kernel-user-conversion-functio.patch +pti32bit-0019-x86-pgtable-Move-pti_set_user_pgtbl-to-pgtable.h.patch +pti32bit-0020-x86-pgtable-Move-two-more-functions-from-pgtable_64..patch +pti32bit-0021-x86-mm-pae-Populate-valid-user-PGD-entries.patch +pti32bit-0022-x86-mm-pae-Populate-the-user-page-table-with-user-pg.patch +pti32bit-0023-x86-mm-legacy-Populate-the-user-page-table-with-user.patch +pti32bit-0024-x86-mm-pti-Add-an-overflow-check-to-pti_clone_pmds.patch +pti32bit-0025-x86-mm-pti-Define-X86_CR3_PTI_PCID_USER_BIT-on-x86_3.patch +pti32bit-0026-x86-mm-pti-Clone-CPU_ENTRY_AREA-on-PMD-level-on-x86_.patch +pti32bit-0027-x86-mm-dump_pagetables-Define-INIT_PGD.patch +pti32bit-0028-x86-pgtable-pae-Use-separate-kernel-PMDs-for-user-pa.patch +pti32bit-0029-x86-ldt-Reserve-address-space-range-on-32-bit-for-th.patch +pti32bit-0030-x86-ldt-Define-LDT_END_ADDR.patch +pti32bit-0031-x86-ldt-Split-out-sanity-check-in-map_ldt_struct.patch +pti32bit-0032-x86-ldt-Enable-LDT-user-mapping-for-PAE.patch +pti32bit-0033-x86-pti-Allow-CONFIG_PAGE_TABLE_ISOLATION-for-x86_32.patch +pti32bit-0034-x86-mm-pti-Add-Warning-when-booting-on-a-PCID-capabl.patch +# tone down warning about PCID on 32bit +pti32bit-0100-tone-down-PCID-on-32bit-message.patch # selected fixes from x86/pti x86-pti-0070-nospec-Kill-array_index_nospec_mask_check.patch -x86-pti-0071-nospec-Allow-index-argument-to-have-const-qualified-.patch x86-pti-0072-nospec-Include-asm-barrier.h-dependency.patch x86-pti-0073-x86-microcode-Propagate-return-value-from-updating-f.patch x86-pti-0074-x86-CPU-Add-a-microcode-loader-callback.patch @@ -186,6 +192,15 @@ block-bfq-limit-sectors-served-with-interactive-weig.patch block-bfq-put-async-queues-for-root-bfq-groups-too.patch block-bfq-add-requeue-request-hook.patch +# HPT RR 644L +ata-ahci-Add-PCI-id-for-the-Highpoint-Rocketraid-644L-card.patch +PCI-Add-function-1-DMA-alias-quirk-for-Highpoint-RocketRAID-644L.patch + +# scsi +scsi-core-Avoid-that-ATA-error-handling-can-trigger-a-kernel-hang-or-oops.patch +scsi-core-return-BLK_STS_OK-for-DID_OK-in-__scsi_error_from_host_byte.patch +scsi-qla2xxx-Fix-NULL-pointer-crash-due-to-active-timer-for-ABTS.patch + ### ### Char ### @@ -251,6 +266,10 @@ hwmon-k10temp-Add-support-for-temperature-offsets.patch input-i8042-quirks-for-Fujitsu-Lifebook-A544-and-Lif.patch +# mga #22703 +input-goodix-disable-IRQs-while-suspended.patch +input-goodix-add-support-for-GDIX1002.patch + ### ### idle ### @@ -309,6 +328,9 @@ net-tls-Correct-length-of-scatterlist-in-tls_sw_sendpage.patch # silence message that gets reported as a bug net-netfilter-xt_addrtype-silence-BROADCAST-message.patch +# CVE-2018-1065 +net-netfilter-add-back-stackpointer-size-checks.patch + ### ### pinctrl ### @@ -340,6 +362,12 @@ platform-x86-ideapad-laptop-Increase-timeout-to-wait-for-ec-answer.patch ### Sound ### +sound-ALSA-hda-Fix-a-wrong-FIXUP-for-alc289-on-Dell-machines.patch + +# skl/kbl fixes +sound-ASoC-Intel-Skylake-Fix-jack-name-format-substitution.patch +sound-ASoC-Intel-kbl-fix-jack-name.patch + ### ### Staging ### @@ -448,6 +476,8 @@ video-mageia-logo.patch ### ARM ### +arch-ARM-omap2-hide-omap3_save_secure_ram-on-non-OMAP3-bu.patch + ### ### IA64 ### diff --git a/kernel/kernel/files/patches/mageia/sound-ALSA-hda-Fix-a-wrong-FIXUP-for-alc289-on-Dell-machines.patch b/kernel/kernel/files/patches/mageia/sound-ALSA-hda-Fix-a-wrong-FIXUP-for-alc289-on-Dell-machines.patch new file mode 100644 index 00000000..449e697a --- /dev/null +++ b/kernel/kernel/files/patches/mageia/sound-ALSA-hda-Fix-a-wrong-FIXUP-for-alc289-on-Dell-machines.patch @@ -0,0 +1,35 @@ +From: Hui Wang +Subject: [PATCH] ALSA: hda - Fix a wrong FIXUP for alc289 on Dell machines +Date: Fri, 2 Mar 2018 13:05:36 +0800 + +With the alc289, the Pin 0x1b is Headphone-Mic, so we should assign +ALC269_FIXUP_DELL4_MIC_NO_PRESENCE rather than +ALC225_FIXUP_DELL1_MIC_NO_PRESENCE to it. And this change is suggested +by Kailang of Realtek and is verified on the machine. + +(This fixes the commit 3f2f7c55) + +Cc: Kailang Yang +Cc: +Signed-off-by: Hui Wang +--- + sound/pci/hda/patch_realtek.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/sound/pci/hda/patch_realtek.c b/sound/pci/hda/patch_realtek.c +index b9c93fa..7a9a867 100644 +--- a/sound/pci/hda/patch_realtek.c ++++ b/sound/pci/hda/patch_realtek.c +@@ -6872,7 +6872,7 @@ static const struct snd_hda_pin_quirk alc269_pin_fixup_tbl[] = { + {0x12, 0x90a60120}, + {0x14, 0x90170110}, + {0x21, 0x0321101f}), +- SND_HDA_PIN_QUIRK(0x10ec0289, 0x1028, "Dell", ALC225_FIXUP_DELL1_MIC_NO_PRESENCE, ++ SND_HDA_PIN_QUIRK(0x10ec0289, 0x1028, "Dell", ALC269_FIXUP_DELL4_MIC_NO_PRESENCE, + {0x12, 0xb7a60130}, + {0x14, 0x90170110}, + {0x21, 0x04211020}), +-- +2.7.4 + + diff --git a/kernel/kernel/files/patches/mageia/sound-ASoC-Intel-Skylake-Fix-jack-name-format-substitution.patch b/kernel/kernel/files/patches/mageia/sound-ASoC-Intel-Skylake-Fix-jack-name-format-substitution.patch new file mode 100644 index 00000000..b3fd6ec2 --- /dev/null +++ b/kernel/kernel/files/patches/mageia/sound-ASoC-Intel-Skylake-Fix-jack-name-format-substitution.patch @@ -0,0 +1,35 @@ +From d1c4cb447a7efcb5608a33cdfed8ab4234378b0a Mon Sep 17 00:00:00 2001 +From: Chintan Patel +Date: Mon, 18 Sep 2017 08:43:18 -0700 +Subject: [PATCH] ASoC: Intel: Skylake: Fix jack name format substitution + +Jack name is not getting formatted correctly hence resulting +in invalid name for HDMI/DP input devices. + +This was recently exposed due changes brought by MST: +commit 3a13347f05fd ("ASoC: Intel: kbl: Add jack port initialize +in kbl machine drivers") + +Signed-off-by: Chintan Patel +Acked-By: Vinod Koul +Signed-off-by: Mark Brown +--- + sound/soc/intel/boards/kbl_rt5663_rt5514_max98927.c | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/sound/soc/intel/boards/kbl_rt5663_rt5514_max98927.c b/sound/soc/intel/boards/kbl_rt5663_rt5514_max98927.c +index 88ff54220007..9cd0769ccd34 100644 +--- a/sound/soc/intel/boards/kbl_rt5663_rt5514_max98927.c ++++ b/sound/soc/intel/boards/kbl_rt5663_rt5514_max98927.c +@@ -604,6 +604,8 @@ static int kabylake_card_late_probe(struct snd_soc_card *card) + + list_for_each_entry(pcm, &ctx->hdmi_pcm_list, head) { + codec = pcm->codec_dai->codec; ++ snprintf(jack_name, sizeof(jack_name), ++ "HDMI/DP, pcm=%d Jack", pcm->device); + err = snd_soc_card_jack_new(card, jack_name, + SND_JACK_AVOUT, &ctx->kabylake_hdmi[i], + NULL, 0); +-- +2.16.2 + diff --git a/kernel/kernel/files/patches/mageia/sound-ASoC-Intel-kbl-fix-jack-name.patch b/kernel/kernel/files/patches/mageia/sound-ASoC-Intel-kbl-fix-jack-name.patch new file mode 100644 index 00000000..75359b31 --- /dev/null +++ b/kernel/kernel/files/patches/mageia/sound-ASoC-Intel-kbl-fix-jack-name.patch @@ -0,0 +1,32 @@ +From cedb6415f9ece6d3368aa0ac8a433caff799792a Mon Sep 17 00:00:00 2001 +From: Vinod Koul +Date: Tue, 31 Oct 2017 16:47:27 +0530 +Subject: [PATCH] ASoC: Intel: kbl: fix jack name + +Commit d1c4cb447a7e ("ASoC: Intel: Skylake: Fix jack name format +substitution") added Jack name but erroneously added a space as well, +so remove the space in Jack name. + +Fixes: d1c4cb447a7e ("ASoC: Intel: Skylake: Fix jack name format substitution") +Signed-off-by: Vinod Koul +Signed-off-by: Mark Brown +--- + sound/soc/intel/boards/kbl_rt5663_rt5514_max98927.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/sound/soc/intel/boards/kbl_rt5663_rt5514_max98927.c b/sound/soc/intel/boards/kbl_rt5663_rt5514_max98927.c +index 9cd0769ccd34..69ab55956492 100644 +--- a/sound/soc/intel/boards/kbl_rt5663_rt5514_max98927.c ++++ b/sound/soc/intel/boards/kbl_rt5663_rt5514_max98927.c +@@ -605,7 +605,7 @@ static int kabylake_card_late_probe(struct snd_soc_card *card) + list_for_each_entry(pcm, &ctx->hdmi_pcm_list, head) { + codec = pcm->codec_dai->codec; + snprintf(jack_name, sizeof(jack_name), +- "HDMI/DP, pcm=%d Jack", pcm->device); ++ "HDMI/DP,pcm=%d Jack", pcm->device); + err = snd_soc_card_jack_new(card, jack_name, + SND_JACK_AVOUT, &ctx->kabylake_hdmi[i], + NULL, 0); +-- +2.16.2 + diff --git a/kernel/kernel/files/patches/mageia/x86-pti-0071-nospec-Allow-index-argument-to-have-const-qualified-.patch b/kernel/kernel/files/patches/mageia/x86-pti-0071-nospec-Allow-index-argument-to-have-const-qualified-.patch deleted file mode 100644 index 4541193c..00000000 --- a/kernel/kernel/files/patches/mageia/x86-pti-0071-nospec-Allow-index-argument-to-have-const-qualified-.patch +++ /dev/null @@ -1,65 +0,0 @@ -From b98c6a160a057d5686a8c54c79cc6c8c94a7d0c8 Mon Sep 17 00:00:00 2001 -From: Rasmus Villemoes -Date: Fri, 16 Feb 2018 13:20:48 -0800 -Subject: [PATCH 71/77] nospec: Allow index argument to have const-qualified - type - -The last expression in a statement expression need not be a bare -variable, quoting gcc docs - - The last thing in the compound statement should be an expression - followed by a semicolon; the value of this subexpression serves as the - value of the entire construct. - -and we already use that in e.g. the min/max macros which end with a -ternary expression. - -This way, we can allow index to have const-qualified type, which will in -some cases avoid the need for introducing a local copy of index of -non-const qualified type. That, in turn, can prevent readers not -familiar with the internals of array_index_nospec from wondering about -the seemingly redundant extra variable, and I think that's worthwhile -considering how confusing the whole _nospec business is. - -The expression _i&_mask has type unsigned long (since that is the type -of _mask, and the BUILD_BUG_ONs guarantee that _i will get promoted to -that), so in order not to change the type of the whole expression, add -a cast back to typeof(_i). - -Signed-off-by: Rasmus Villemoes -Signed-off-by: Dan Williams -Acked-by: Linus Torvalds -Cc: Andy Lutomirski -Cc: Arjan van de Ven -Cc: Borislav Petkov -Cc: Dave Hansen -Cc: David Woodhouse -Cc: Greg Kroah-Hartman -Cc: Josh Poimboeuf -Cc: Peter Zijlstra -Cc: Thomas Gleixner -Cc: Will Deacon -Cc: linux-arch@vger.kernel.org -Cc: stable@vger.kernel.org -Link: http://lkml.kernel.org/r/151881604837.17395.10812767547837568328.stgit@dwillia2-desk3.amr.corp.intel.com -Signed-off-by: Ingo Molnar ---- - include/linux/nospec.h | 3 +-- - 1 file changed, 1 insertion(+), 2 deletions(-) - -diff --git a/include/linux/nospec.h b/include/linux/nospec.h -index d6701e34424f..172a19dc35ab 100644 ---- a/include/linux/nospec.h -+++ b/include/linux/nospec.h -@@ -52,7 +52,6 @@ static inline unsigned long array_index_mask_nospec(unsigned long index, - BUILD_BUG_ON(sizeof(_i) > sizeof(long)); \ - BUILD_BUG_ON(sizeof(_s) > sizeof(long)); \ - \ -- _i &= _mask; \ -- _i; \ -+ (typeof(_i)) (_i & _mask); \ - }) - #endif /* _LINUX_NOSPEC_H */ --- -2.16.1 - diff --git a/kernel/kernel/pspec.xml b/kernel/kernel/pspec.xml index 7e909130..b1f00438 100644 --- a/kernel/kernel/pspec.xml +++ b/kernel/kernel/pspec.xml @@ -28,8 +28,8 @@ - patches/linux/patch-4.14.23.xz - + patches/linux/patch-4.14.24.xz + @@ -48,29 +48,31 @@ patches/mageia/pti32bit-0008-x86-entry-32-Enter-the-kernel-via-trampoline-stack.patch patches/mageia/pti32bit-0009-x86-entry-32-Leave-the-kernel-via-trampoline-stack.patch patches/mageia/pti32bit-0010-x86-entry-32-Introduce-SAVE_ALL_NMI-and-RESTORE_ALL_.patch - patches/mageia/pti32bit-0011-x86-entry-32-Add-PTI-cr3-switches-to-NMI-handler-cod.patch - patches/mageia/pti32bit-0012-x86-entry-32-Add-PTI-cr3-switch-to-non-NMI-entry-exi.patch - patches/mageia/pti32bit-0013-x86-entry-32-Handle-Entry-from-Kernel-Mode-on-Entry-.patch - patches/mageia/pti32bit-0014-x86-pgtable-pae-Unshare-kernel-PMDs-when-PTI-is-enab.patch - patches/mageia/pti32bit-0015-x86-pgtable-32-Allocate-8k-page-tables-when-PTI-is-e.patch - patches/mageia/pti32bit-0016-x86-pgtable-Move-pgdp-kernel-user-conversion-functio.patch - patches/mageia/pti32bit-0017-x86-pgtable-Move-pti_set_user_pgd-to-pgtable.h.patch - patches/mageia/pti32bit-0018-x86-pgtable-Move-two-more-functions-from-pgtable_64..patch - patches/mageia/pti32bit-0019-x86-mm-pae-Populate-valid-user-PGD-entries.patch - patches/mageia/pti32bit-0020-x86-mm-pae-Populate-the-user-page-table-with-user-pg.patch - patches/mageia/pti32bit-0021-x86-mm-legacy-Populate-the-user-page-table-with-user.patch - patches/mageia/pti32bit-0022-x86-mm-pti-Add-an-overflow-check-to-pti_clone_pmds.patch - patches/mageia/pti32bit-0023-x86-mm-pti-Define-X86_CR3_PTI_PCID_USER_BIT-on-x86_3.patch - patches/mageia/pti32bit-0024-x86-mm-pti-Clone-CPU_ENTRY_AREA-on-PMD-level-on-x86_.patch - patches/mageia/pti32bit-0025-x86-mm-dump_pagetables-Define-INIT_PGD.patch - patches/mageia/pti32bit-0026-x86-pgtable-pae-Use-separate-kernel-PMDs-for-user-pa.patch - patches/mageia/pti32bit-0027-x86-ldt-Reserve-address-space-range-on-32-bit-for-th.patch - patches/mageia/pti32bit-0028-x86-ldt-Define-LDT_END_ADDR.patch - patches/mageia/pti32bit-0029-x86-ldt-Split-out-sanity-check-in-map_ldt_struct.patch - patches/mageia/pti32bit-0030-x86-ldt-Enable-LDT-user-mapping-for-PAE.patch - patches/mageia/pti32bit-0031-x86-pti-Allow-CONFIG_PAGE_TABLE_ISOLATION-for-x86_32.patch + patches/mageia/pti32bit-0011-x86-entry-32-Handle-Entry-from-Kernel-Mode-on-Entry-.patch + patches/mageia/pti32bit-0012-x86-entry-32-Simplify-debug-entry-point.patch + patches/mageia/pti32bit-0013-x86-entry-32-Add-PTI-cr3-switches-to-NMI-handler-cod.patch + patches/mageia/pti32bit-0014-x86-entry-32-Add-PTI-cr3-switch-to-non-NMI-entry-exi.patch + patches/mageia/pti32bit-0015-x86-pgtable-Rename-pti_set_user_pgd-to-pti_set_user_.patch + patches/mageia/pti32bit-0016-x86-pgtable-pae-Unshare-kernel-PMDs-when-PTI-is-enab.patch + patches/mageia/pti32bit-0017-x86-pgtable-32-Allocate-8k-page-tables-when-PTI-is-e.patch + patches/mageia/pti32bit-0018-x86-pgtable-Move-pgdp-kernel-user-conversion-functio.patch + patches/mageia/pti32bit-0019-x86-pgtable-Move-pti_set_user_pgtbl-to-pgtable.h.patch + patches/mageia/pti32bit-0020-x86-pgtable-Move-two-more-functions-from-pgtable_64..patch + patches/mageia/pti32bit-0021-x86-mm-pae-Populate-valid-user-PGD-entries.patch + patches/mageia/pti32bit-0022-x86-mm-pae-Populate-the-user-page-table-with-user-pg.patch + patches/mageia/pti32bit-0023-x86-mm-legacy-Populate-the-user-page-table-with-user.patch + patches/mageia/pti32bit-0024-x86-mm-pti-Add-an-overflow-check-to-pti_clone_pmds.patch + patches/mageia/pti32bit-0025-x86-mm-pti-Define-X86_CR3_PTI_PCID_USER_BIT-on-x86_3.patch + patches/mageia/pti32bit-0026-x86-mm-pti-Clone-CPU_ENTRY_AREA-on-PMD-level-on-x86_.patch + patches/mageia/pti32bit-0027-x86-mm-dump_pagetables-Define-INIT_PGD.patch + patches/mageia/pti32bit-0028-x86-pgtable-pae-Use-separate-kernel-PMDs-for-user-pa.patch + patches/mageia/pti32bit-0029-x86-ldt-Reserve-address-space-range-on-32-bit-for-th.patch + patches/mageia/pti32bit-0030-x86-ldt-Define-LDT_END_ADDR.patch + patches/mageia/pti32bit-0031-x86-ldt-Split-out-sanity-check-in-map_ldt_struct.patch + patches/mageia/pti32bit-0032-x86-ldt-Enable-LDT-user-mapping-for-PAE.patch + patches/mageia/pti32bit-0033-x86-pti-Allow-CONFIG_PAGE_TABLE_ISOLATION-for-x86_32.patch + patches/mageia/pti32bit-0034-x86-mm-pti-Add-Warning-when-booting-on-a-PCID-capabl.patch patches/mageia/x86-pti-0070-nospec-Kill-array_index_nospec_mask_check.patch - patches/mageia/x86-pti-0071-nospec-Allow-index-argument-to-have-const-qualified-.patch patches/mageia/x86-pti-0072-nospec-Include-asm-barrier.h-dependency.patch patches/mageia/x86-pti-0073-x86-microcode-Propagate-return-value-from-updating-f.patch patches/mageia/x86-pti-0074-x86-CPU-Add-a-microcode-loader-callback.patch @@ -84,12 +86,12 @@ patches/mageia/acpi-processor-M720SR-limit-to-C2.patch patches/mageia/ACPI-video-Add-a-quirk-to-force-acpi-video-backlight.patch patches/mageia/acpi-ec-restore-polling-during-noirq-suspend_resume-phases.patch - patches/mageia/scsi-ppscsi-2.6.2.patch patches/mageia/scsi-ppscsi_fixes.patch patches/mageia/scsi-ppscsi-sg-helper-update.patch patches/mageia/scsi-ppscsi-update-for-scsi_data_buffer.patch patches/mageia/scsi-ppscsi-mdvbz45393.patch - patches/mageia/scsi-ppscsi-3.0-buildfix.patch + patches/mageia/scsi-ppscsi-3.0-buildfix.patch patches/mageia/scsi-megaraid-new-sysfs-name.patch patches/mageia/ide-pci-sis5513-965.patch patches/mageia/mpt-vmware-fix.patch @@ -119,6 +121,11 @@ patches/mageia/block-bfq-limit-sectors-served-with-interactive-weig.patch patches/mageia/block-bfq-add-requeue-request-hook.patch patches/mageia/block-bfq-put-async-queues-for-root-bfq-groups-too.patch + patches/mageia/ata-ahci-Add-PCI-id-for-the-Highpoint-Rocketraid-644L-card.patch + patches/mageia/PCI-Add-function-1-DMA-alias-quirk-for-Highpoint-RocketRAID-644L.patch + patches/mageia/scsi-core-Avoid-that-ATA-error-handling-can-trigger-a-kernel-hang-or-oops.patch + patches/mageia/scsi-core-return-BLK_STS_OK-for-DID_OK-in-__scsi_error_from_host_byte.patch + patches/mageia/scsi-qla2xxx-Fix-NULL-pointer-crash-due-to-active-timer-for-ABTS.patch patches/mageia/fs-aufs-4.14.patch patches/mageia/fs-aufs-4.14-modular.patch patches/mageia/fs-aufs-include-vmalloc.patch @@ -145,6 +152,8 @@ patches/mageia/hwmon-k10temp-Add-support-for-family-17h.patch patches/mageia/hwmon-k10temp-Add-support-for-temperature-offsets.patch patches/mageia/input-i8042-quirks-for-Fujitsu-Lifebook-A544-and-Lif.patch + patches/mageia/input-goodix-disable-IRQs-while-suspended.patch + patches/mageia/input-goodix-add-support-for-GDIX1002.patch patches/mageia/mm-page_vma_mapped-Introduce-pfn_in_hpage.patch patches/mageia/net-sis190-fix-list-usage.patch patches/mageia/net-netfilter-IFWLOG.patch @@ -162,17 +171,21 @@ patches/mageia/net-WireGuard.patch patches/mageia/net-tls-Correct-length-of-scatterlist-in-tls_sw_sendpage.patch patches/mageia/net-netfilter-xt_addrtype-silence-BROADCAST-message.patch + patches/mageia/net-netfilter-add-back-stackpointer-size-checks.patch patches/mageia/platform-x86-add-shuttle-wmi-driver.patch patches/mageia/platform-x86-shuttle-wmi-drop-devinit-exit.patch patches/mageia/platform-x86-shuttle-wmi-4.2-buildfix.patch patches/mageia/platform-x86-shuttle-wmi-4.13-buildfix.patch patches/mageia/platform-x86-ideapad-Add-IdeaPad-320-15IKB-to-no_hw_rfkill_list.patch - patches/mageia/platform-x86-ideapad-laptop-Increase-timeout-to-wait-for-ec-answer.patch + patches/mageia/platform-x86-ideapad-laptop-Increase-timeout-to-wait-for-ec-answer.patch + patches/mageia/sound-ALSA-hda-Fix-a-wrong-FIXUP-for-alc289-on-Dell-machines.patch + patches/mageia/sound-ASoC-Intel-Skylake-Fix-jack-name-format-substitution.patch + patches/mageia/sound-ASoC-Intel-kbl-fix-jack-name.patch patches/mageia/hid-usbhid-IBM-BladeCenterHS20-quirk.patch patches/mageia/usb-storage-unusual_devs-add-id.patch patches/mageia/usb-storage-unusual_devs-add-id-2.6.37-buildfix.patch patches/mageia/media-usb-pwc-lie-in-proc-usb-devices.patch - patches/mageia/3rd-3rdparty-1.0-tree.patch + + patches/mageia/3rd-aes2501-rmmod-oops-fix.patch patches/mageia/3rd-ndiswrapper-1.61.patch patches/mageia/3rd-ndiswrapper-Kconfig.patch patches/mageia/3rd-ndiswrapper-Makefile-build-fix.patch @@ -198,8 +211,9 @@ patches/mageia/3rd-viahss-2.6.35-buildfix.patch patches/mageia/3rd-viahss-3.0-buildfix.patch patches/mageia/3rd-rtl8812au.patch - patches/mageia/3rd-rtl8723de.patch + patches/mageia/3rd-rtl8723de.patch patches/mageia/tools-testing-selftest-Makefile-remove-powerpc-reference.patch + patches/mageia/arch-ARM-omap2-hide-omap3_save_secure_ram-on-non-OMAP3-bu.patch @@ -255,8 +269,8 @@ - 2018-03-03 - 4.14.23 + 2018-03-09 + 4.14.24 Version Bump. security