diff --git a/android/abi_gki_aarch64.xml b/android/abi_gki_aarch64.xml
index 97726ce2476b..eec475e88335 100644
--- a/android/abi_gki_aarch64.xml
+++ b/android/abi_gki_aarch64.xml
@@ -2365,6 +2365,7 @@
+
@@ -6789,12 +6790,12 @@
-
+
-
+
-
+
@@ -17102,63 +17103,63 @@
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
@@ -21451,18 +21452,18 @@
-
+
-
+
-
+
-
+
-
+
@@ -36333,63 +36334,63 @@
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
@@ -42195,18 +42196,18 @@
-
+
-
+
-
+
-
+
-
+
@@ -44549,8 +44550,8 @@
-
-
+
+
@@ -44559,34 +44560,34 @@
-
-
-
-
-
+
+
+
+
+
-
-
+
+
-
-
+
+
-
-
-
-
-
+
+
+
+
+
-
-
+
+
-
-
+
+
@@ -44595,9 +44596,9 @@
-
-
-
+
+
+
@@ -44608,34 +44609,34 @@
-
-
+
+
-
-
+
+
-
-
-
-
+
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
@@ -44653,34 +44654,34 @@
-
-
+
+
-
-
+
+
-
-
-
-
+
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
@@ -44702,10 +44703,10 @@
-
-
-
-
+
+
+
+
@@ -44816,7 +44817,7 @@
-
+
@@ -44830,7 +44831,7 @@
-
+
@@ -50090,61 +50091,61 @@
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
-
-
-
-
+
+
+
+
+
+
-
-
-
+
+
+
@@ -50154,168 +50155,168 @@
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
@@ -50358,8 +50359,8 @@
-
-
+
+
@@ -55481,17 +55482,17 @@
-
-
-
+
+
+
-
+
-
-
-
+
+
+
@@ -56113,92 +56114,92 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
+
+
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
@@ -56221,19 +56222,19 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
@@ -56241,8 +56242,8 @@
-
-
+
+
@@ -56256,9 +56257,9 @@
-
-
-
+
+
+
@@ -58010,18 +58011,18 @@
-
-
-
-
+
+
+
+
-
-
-
-
-
-
+
+
+
+
+
+
@@ -77093,422 +77094,422 @@
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
@@ -77528,58 +77529,58 @@
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
@@ -80159,12 +80160,12 @@
-
-
+
+
-
-
+
+
@@ -80179,12 +80180,12 @@
-
-
+
+
-
-
+
+
@@ -93281,10 +93282,10 @@
-
-
-
-
+
+
+
+
@@ -96495,46 +96496,46 @@
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
@@ -98939,51 +98940,51 @@
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
@@ -101675,10 +101676,10 @@
-
-
-
-
+
+
+
+
@@ -101696,9 +101697,9 @@
-
-
-
+
+
+
@@ -101719,8 +101720,8 @@
-
-
+
+
@@ -101733,30 +101734,30 @@
-
-
-
-
+
+
+
+
-
-
-
-
-
-
+
+
+
+
+
+
-
-
-
-
-
-
+
+
+
+
+
+
@@ -103872,22 +103873,22 @@
-
-
-
-
+
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
@@ -103898,40 +103899,40 @@
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
-
-
-
+
+
+
+
+
-
-
+
+
-
-
-
-
-
-
+
+
+
+
+
+
@@ -106376,18 +106377,18 @@
-
-
-
-
+
+
+
+
-
-
+
+
-
-
+
+
@@ -106396,20 +106397,20 @@
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
+
+
@@ -106421,9 +106422,9 @@
-
-
-
+
+
+
@@ -106432,14 +106433,14 @@
-
-
-
-
+
+
+
+
-
-
+
+
@@ -108656,13 +108657,13 @@
-
-
+
+
-
-
-
+
+
+
@@ -108690,8 +108691,8 @@
-
-
+
+
@@ -108720,9 +108721,9 @@
-
-
-
+
+
+
@@ -117099,9 +117100,9 @@
-
-
-
+
+
+
@@ -117114,8 +117115,8 @@
-
-
+
+
@@ -117128,13 +117129,13 @@
-
-
-
+
+
+
-
-
+
+
@@ -117145,27 +117146,27 @@
-
-
-
-
-
-
+
+
+
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
@@ -117188,9 +117189,9 @@
-
-
-
+
+
+
@@ -118822,130 +118823,130 @@
-
-
-
-
+
+
+
+
-
-
-
-
-
-
+
+
+
+
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
-
-
+
+
+
+
-
-
+
+
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
-
+
+
+
+
-
-
+
+
-
-
-
-
-
+
+
+
+
+
-
-
-
-
-
+
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
-
+
+
+
+
+
-
-
-
-
-
-
+
+
+
+
+
+
-
-
-
-
+
+
+
+
@@ -119428,8 +119429,8 @@
-
-
+
+
@@ -119437,18 +119438,18 @@
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
@@ -119913,41 +119914,41 @@
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
@@ -120161,8 +120162,8 @@
-
-
+
+
@@ -121715,73 +121716,73 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
@@ -124047,21 +124048,21 @@
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
@@ -124074,12 +124075,12 @@
-
-
+
+
-
-
+
+
@@ -126147,9 +126148,9 @@
-
-
-
+
+
+
@@ -127801,10 +127802,10 @@
-
-
-
-
+
+
+
+
@@ -128507,6 +128508,10 @@
+
+
+
+
@@ -128612,24 +128617,24 @@
-
+
-
+
-
+
-
+
-
+
-
+
-
+
@@ -144823,22 +144828,22 @@
-
-
-
-
+
+
+
+
-
-
-
-
-
-
+
+
+
+
+
+
@@ -144849,25 +144854,25 @@
-
-
-
-
-
-
-
-
-
+
+
+
+
+
+
+
+
+
-
-
+
+
-
-
-
-
+
+
+
+
@@ -150272,23 +150277,23 @@
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
@@ -151594,13 +151599,6 @@
-
-
-
-
-
-
-
@@ -151611,51 +151609,58 @@
-
-
-
-
+
+
+
+
+
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
+
+
+
+
+
-
-
-
-
-
+
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
-
-
-
-
+
+
+
+
+
-
-
-
+
+
+
@@ -153056,8 +153061,8 @@
-
-
+
+
@@ -153070,12 +153075,12 @@
-
-
+
+
-
-
+
+
@@ -153084,8 +153089,8 @@
-
-
+
+
@@ -153561,12 +153566,12 @@
-
-
+
+
-
-
+
+
@@ -153992,12 +153997,12 @@
-
+
-
+
-
+
@@ -154007,10 +154012,10 @@
-
-
-
-
+
+
+
+
@@ -154021,67 +154026,67 @@
-
-
+
+
-
-
-
-
+
+
+
+
-
-
-
-
-
+
+
+
+
+
-
-
-
-
-
+
+
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
+
-
-
+
+
-
-
+
+
-
-
+
+
@@ -159020,9 +159025,9 @@
-
-
-
+
+
+
@@ -159290,31 +159295,31 @@
-
-
-
-
-
+
+
+
+
+
-
-
-
-
-
+
+
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
@@ -159322,32 +159327,32 @@
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
@@ -159483,24 +159488,24 @@
-
+
-
+
-
+
-
+
-
+
-
+
-
+
@@ -159576,22 +159581,22 @@
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
@@ -160261,34 +160266,34 @@
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
-
-
-
+
+
+
+
+
+
@@ -161180,8 +161185,8 @@
-
-
+
+
@@ -161240,6 +161245,26 @@
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
@@ -161636,26 +161661,6 @@
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
@@ -161923,8 +161928,8 @@
-
-
+
+
@@ -161958,24 +161963,24 @@
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
@@ -162154,11 +162159,6 @@
-
-
-
-
-
@@ -162177,6 +162177,11 @@
+
+
+
+
+
@@ -163953,17 +163958,17 @@
-
-
+
+
-
-
+
+
-
-
-
+
+
+
@@ -167764,10 +167769,10 @@
-
-
-
-
+
+
+
+
@@ -168250,16 +168255,16 @@
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
@@ -170937,25 +170942,25 @@
-
-
-
+
+
+
-
-
-
-
-
+
+
+
+
+
-
-
-
+
+
+
-
-
+
+
@@ -170963,8 +170968,8 @@
-
-
+
+
@@ -171380,10 +171385,10 @@
-
-
-
-
+
+
+
+
@@ -171395,8 +171400,8 @@
-
-
+
+
@@ -172033,15 +172038,15 @@
-
-
-
-
-
+
+
+
+
+
-
-
+
+
@@ -172054,19 +172059,19 @@
-
-
-
-
-
+
+
+
+
+
-
-
+
+
-
-
+
+
@@ -172077,13 +172082,13 @@
-
-
-
-
-
-
-
+
+
+
+
+
+
+
@@ -172812,29 +172817,29 @@
-
-
-
-
-
-
-
-
-
+
+
+
+
+
+
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
@@ -179682,12 +179687,12 @@
-
-
-
-
-
-
+
+
+
+
+
+
@@ -182049,24 +182054,24 @@
-
-
-
-
-
-
-
+
+
+
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
+
+
+
@@ -187764,19 +187769,19 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
@@ -187789,15 +187794,15 @@
-
-
-
-
+
+
+
+
-
-
-
+
+
+
@@ -187805,9 +187810,9 @@
-
-
-
+
+
+
@@ -187820,19 +187825,19 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
@@ -187845,16 +187850,16 @@
-
-
-
-
-
+
+
+
+
+
-
-
-
+
+
+
diff --git a/android/abi_gki_aarch64_db845c b/android/abi_gki_aarch64_db845c
index d9bc40995f5b..898684f65cfe 100644
--- a/android/abi_gki_aarch64_db845c
+++ b/android/abi_gki_aarch64_db845c
@@ -583,6 +583,7 @@
__kfifo_alloc
__kfifo_free
kmalloc_order_trace
+ ktime_get_with_offset
__local_bh_enable_ip
memmove
param_ops_ulong
@@ -590,6 +591,7 @@
__rcu_read_lock
__rcu_read_unlock
regulatory_hint
+ rfc1042_header
skb_copy
skb_realloc_headroom
strlcat
@@ -660,6 +662,7 @@
phy_pm_runtime_get_sync
phy_pm_runtime_put_sync
platform_get_irq_byname_optional
+ pm_runtime_barrier
system_freezable_wq
usb_add_gadget_udc
usb_decode_ctrl
@@ -733,7 +736,6 @@
generic_file_read_iter
generic_file_splice_read
generic_read_dir
- generic_shutdown_super
__get_free_pages
get_zeroed_page
iget5_locked
@@ -745,6 +747,7 @@
kernel_read
kernel_write
kern_path
+ kill_anon_super
kobject_create_and_add
kobject_put
lockref_get
diff --git a/arch/arm64/configs/gki_defconfig b/arch/arm64/configs/gki_defconfig
index e0a67b0c52f4..67418fc50830 100644
--- a/arch/arm64/configs/gki_defconfig
+++ b/arch/arm64/configs/gki_defconfig
@@ -317,6 +317,7 @@ CONFIG_SERIAL_8250=y
# CONFIG_SERIAL_8250_DEPRECATED_OPTIONS is not set
CONFIG_SERIAL_8250_CONSOLE=y
# CONFIG_SERIAL_8250_EXAR is not set
+CONFIG_SERIAL_8250_RUNTIME_UARTS=0
CONFIG_SERIAL_OF_PLATFORM=y
CONFIG_SERIAL_AMBA_PL011=y
CONFIG_SERIAL_AMBA_PL011_CONSOLE=y
diff --git a/arch/x86/configs/gki_defconfig b/arch/x86/configs/gki_defconfig
index 1da7f7fb4291..f3d46d70e639 100644
--- a/arch/x86/configs/gki_defconfig
+++ b/arch/x86/configs/gki_defconfig
@@ -289,6 +289,7 @@ CONFIG_INPUT_UINPUT=y
CONFIG_SERIAL_8250=y
# CONFIG_SERIAL_8250_DEPRECATED_OPTIONS is not set
CONFIG_SERIAL_8250_CONSOLE=y
+CONFIG_SERIAL_8250_RUNTIME_UARTS=0
CONFIG_SERIAL_OF_PLATFORM=y
CONFIG_SERIAL_DEV_BUS=y
CONFIG_HW_RANDOM=y
diff --git a/arch/x86/include/asm/setup.h b/arch/x86/include/asm/setup.h
index ed8ec011a9fd..42f3e42a10ee 100644
--- a/arch/x86/include/asm/setup.h
+++ b/arch/x86/include/asm/setup.h
@@ -4,7 +4,7 @@
#include
-#define COMMAND_LINE_SIZE 2048
+#define COMMAND_LINE_SIZE 4096
#include
#include
diff --git a/block/blk-core.c b/block/blk-core.c
index 08966d8574e6..eeb6b0245e18 100644
--- a/block/blk-core.c
+++ b/block/blk-core.c
@@ -120,7 +120,6 @@ void blk_rq_init(struct request_queue *q, struct request *rq)
rq->internal_tag = -1;
rq->start_time_ns = ktime_get_ns();
rq->part = NULL;
- refcount_set(&rq->ref, 1);
}
EXPORT_SYMBOL(blk_rq_init);
diff --git a/block/blk-flush.c b/block/blk-flush.c
index e5735a213db7..04bcb6feb1d1 100644
--- a/block/blk-flush.c
+++ b/block/blk-flush.c
@@ -325,6 +325,14 @@ static void blk_kick_flush(struct request_queue *q, struct blk_flush_queue *fq,
flush_rq->rq_flags |= RQF_FLUSH_SEQ;
flush_rq->rq_disk = first_rq->rq_disk;
flush_rq->end_io = flush_end_io;
+ /*
+ * Order WRITE ->end_io and WRITE rq->ref, and its pair is the one
+ * implied in refcount_inc_not_zero() called from
+ * blk_mq_find_and_get_req(), which orders WRITE/READ flush_rq->ref
+ * and READ flush_rq->end_io
+ */
+ smp_wmb();
+ refcount_set(&flush_rq->ref, 1);
blk_flush_queue_rq(flush_rq, false);
}
diff --git a/drivers/android/binder.c b/drivers/android/binder.c
index 441b2aabc30c..d42c1c13e0a1 100644
--- a/drivers/android/binder.c
+++ b/drivers/android/binder.c
@@ -5743,7 +5743,8 @@ static const char * const binder_return_strings[] = {
"BR_FINISHED",
"BR_DEAD_BINDER",
"BR_CLEAR_DEATH_NOTIFICATION_DONE",
- "BR_FAILED_REPLY"
+ "BR_FAILED_REPLY",
+ "BR_FROZEN_REPLY",
};
static const char * const binder_command_strings[] = {
diff --git a/drivers/android/binder_internal.h b/drivers/android/binder_internal.h
index 7c5993bcfc10..e32807fbb732 100644
--- a/drivers/android/binder_internal.h
+++ b/drivers/android/binder_internal.h
@@ -155,7 +155,7 @@ enum binder_stat_types {
};
struct binder_stats {
- atomic_t br[_IOC_NR(BR_FAILED_REPLY) + 1];
+ atomic_t br[_IOC_NR(BR_FROZEN_REPLY) + 1];
atomic_t bc[_IOC_NR(BC_REPLY_SG) + 1];
atomic_t obj_created[BINDER_STAT_COUNT];
atomic_t obj_deleted[BINDER_STAT_COUNT];
diff --git a/drivers/base/core.c b/drivers/base/core.c
index 73f559bcd613..358785c50995 100644
--- a/drivers/base/core.c
+++ b/drivers/base/core.c
@@ -642,9 +642,7 @@ struct device_link *device_link_add(struct device *consumer,
dev_set_name(&link->link_dev, "%s--%s",
dev_name(supplier), dev_name(consumer));
if (device_register(&link->link_dev)) {
- put_device(consumer);
- put_device(supplier);
- kfree(link);
+ put_device(&link->link_dev);
link = NULL;
goto out;
}
diff --git a/fs/incfs/vfs.c b/fs/incfs/vfs.c
index b972716f0c25..ceb0c2e41402 100644
--- a/fs/incfs/vfs.c
+++ b/fs/incfs/vfs.c
@@ -319,7 +319,6 @@ static struct mount_info *get_mount_info(struct super_block *sb)
{
struct mount_info *result = sb->s_fs_info;
- WARN_ON(!result);
return result;
}
@@ -678,7 +677,7 @@ static int iterate_incfs_dir(struct file *file, struct dir_context *ctx)
struct mount_info *mi = get_mount_info(file_superblock(file));
bool root;
- if (!dir) {
+ if (!dir || !mi) {
error = -EBADF;
goto out;
}
@@ -1842,6 +1841,9 @@ static int dir_rename(struct inode *old_dir, struct dentry *old_dentry,
struct dentry *trap;
int error = 0;
+ if (!mi)
+ return -EBADF;
+
error = mutex_lock_interruptible(&mi->mi_dir_struct_mutex);
if (error)
return error;
@@ -2089,6 +2091,9 @@ static ssize_t incfs_getxattr(struct dentry *d, const char *name,
char *stored_value;
size_t stored_size;
+ if (!mi)
+ return -EBADF;
+
if (di && di->backing_path.dentry)
return vfs_getxattr(di->backing_path.dentry, name, value, size);
@@ -2125,6 +2130,9 @@ static ssize_t incfs_setxattr(struct dentry *d, const char *name,
void **stored_value;
size_t *stored_size;
+ if (!mi)
+ return -EBADF;
+
if (di && di->backing_path.dentry)
return vfs_setxattr(di->backing_path.dentry, name, value, size,
flags);
@@ -2165,6 +2173,11 @@ static ssize_t incfs_listxattr(struct dentry *d, char *list, size_t size)
return vfs_listxattr(di->backing_path.dentry, list, size);
}
+static int incfs_test_super(struct super_block *s, void *p)
+{
+ return s->s_fs_info != NULL;
+}
+
struct dentry *incfs_mount_fs(struct file_system_type *type, int flags,
const char *dev_name, void *data)
{
@@ -2174,7 +2187,8 @@ struct dentry *incfs_mount_fs(struct file_system_type *type, int flags,
struct dentry *index_dir;
struct super_block *src_fs_sb = NULL;
struct inode *root_inode = NULL;
- struct super_block *sb = sget(type, NULL, set_anon_super, flags, NULL);
+ struct super_block *sb = sget(type, incfs_test_super, set_anon_super,
+ flags, NULL);
int error = 0;
if (IS_ERR(sb))
@@ -2215,13 +2229,18 @@ struct dentry *incfs_mount_fs(struct file_system_type *type, int flags,
src_fs_sb = backing_dir_path.dentry->d_sb;
sb->s_maxbytes = src_fs_sb->s_maxbytes;
- mi = incfs_alloc_mount_info(sb, &options, &backing_dir_path);
+ if (!sb->s_fs_info) {
+ mi = incfs_alloc_mount_info(sb, &options, &backing_dir_path);
- if (IS_ERR_OR_NULL(mi)) {
- error = PTR_ERR(mi);
- pr_err("incfs: Error allocating mount info. %d\n", error);
- mi = NULL;
- goto err;
+ if (IS_ERR_OR_NULL(mi)) {
+ error = PTR_ERR(mi);
+ pr_err("incfs: Error allocating mount info. %d\n", error);
+ mi = NULL;
+ goto err;
+ }
+ sb->s_fs_info = mi;
+ } else {
+ mi = sb->s_fs_info;
}
index_dir = open_or_create_index_dir(backing_dir_path.dentry);
@@ -2233,23 +2252,24 @@ struct dentry *incfs_mount_fs(struct file_system_type *type, int flags,
}
mi->mi_index_dir = index_dir;
- sb->s_fs_info = mi;
root_inode = fetch_regular_inode(sb, backing_dir_path.dentry);
if (IS_ERR(root_inode)) {
error = PTR_ERR(root_inode);
goto err;
}
- sb->s_root = d_make_root(root_inode);
if (!sb->s_root) {
- error = -ENOMEM;
- goto err;
+ sb->s_root = d_make_root(root_inode);
+ if (!sb->s_root) {
+ error = -ENOMEM;
+ goto err;
+ }
+ error = incfs_init_dentry(sb->s_root, &backing_dir_path);
+ if (error)
+ goto err;
}
- error = incfs_init_dentry(sb->s_root, &backing_dir_path);
- if (error)
- goto err;
- path_put(&backing_dir_path);
+ mi->mi_backing_dir_path = backing_dir_path;
sb->s_flags |= SB_ACTIVE;
pr_debug("incfs: mount\n");
@@ -2268,6 +2288,9 @@ static int incfs_remount_fs(struct super_block *sb, int *flags, char *data)
struct mount_info *mi = get_mount_info(sb);
int err = 0;
+ if (!mi)
+ return err;
+
sync_filesystem(sb);
err = parse_options(&options, (char *)data);
if (err)
@@ -2286,14 +2309,19 @@ void incfs_kill_sb(struct super_block *sb)
struct mount_info *mi = sb->s_fs_info;
pr_debug("incfs: unmount\n");
+ vfs_rmdir(d_inode(mi->mi_backing_dir_path.dentry), mi->mi_index_dir);
+ kill_anon_super(sb);
incfs_free_mount_info(mi);
- generic_shutdown_super(sb);
+ sb->s_fs_info = NULL;
}
static int show_options(struct seq_file *m, struct dentry *root)
{
struct mount_info *mi = get_mount_info(root->d_sb);
+ if (!mi)
+ return -EBADF;
+
seq_printf(m, ",read_timeout_ms=%u", mi->mi_options.read_timeout_ms);
seq_printf(m, ",readahead=%u", mi->mi_options.readahead_pages);
if (mi->mi_options.read_log_pages != 0) {
diff --git a/net/xfrm/xfrm_user.c b/net/xfrm/xfrm_user.c
index 98213258638e..d1b6beeb1399 100644
--- a/net/xfrm/xfrm_user.c
+++ b/net/xfrm/xfrm_user.c
@@ -2769,6 +2769,16 @@ static int xfrm_user_rcv_msg(struct sk_buff *skb, struct nlmsghdr *nlh,
err = link->doit(skb, nlh, attrs);
+ /* We need to free skb allocated in xfrm_alloc_compat() before
+ * returning from this function, because consume_skb() won't take
+ * care of frag_list since netlink destructor sets
+ * sbk->head to NULL. (see netlink_skb_destructor())
+ */
+ if (skb_has_frag_list(skb)) {
+ kfree_skb(skb_shinfo(skb)->frag_list);
+ skb_shinfo(skb)->frag_list = NULL;
+ }
+
err:
kvfree(nlh64);
return err;