Commit graph

916,475 commits

Author SHA1 Message Date
Pablo Neira Ayuso
f896aebc91 UPSTREAM: netfilter: nft_set_rbtree: Switch to node list walk for overlap detection
commit c9e6978e2725a7d4b6cd23b2facd3f11422c0643 upstream.

...instead of a tree descent, which became overly complicated in an
attempt to cover cases where expired or inactive elements would affect
comparisons with the new element being inserted.

Further, it turned out that it's probably impossible to cover all those
cases, as inactive nodes might entirely hide subtrees consisting of a
complete interval plus a node that makes the current insertion not
overlap.

To speed up the overlap check, descent the tree to find a greater
element that is closer to the key value to insert. Then walk down the
node list for overlap detection. Starting the overlap check from
rb_first() unconditionally is slow, it takes 10 times longer due to the
full linear traversal of the list.

Moreover, perform garbage collection of expired elements when walking
down the node list to avoid bogus overlap reports.

For the insertion operation itself, this essentially reverts back to the
implementation before commit 7c84d41416d8 ("netfilter: nft_set_rbtree:
Detect partial overlaps on insertion"), except that cases of complete
overlap are already handled in the overlap detection phase itself, which
slightly simplifies the loop to find the insertion point.

Based on initial patch from Stefano Brivio, including text from the
original patch description too.

Bug: 299922216
Fixes: 7c84d41416d8 ("netfilter: nft_set_rbtree: Detect partial overlaps on insertion")
Reviewed-by: Stefano Brivio <sbrivio@redhat.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit 181859bdfb)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: Id8979dd639294bfae9a8c8440b4f19a54b33cb0c
2023-12-06 12:31:05 +00:00
Pablo Neira Ayuso
3a298023c9 UPSTREAM: netfilter: nf_tables: drop map element references from preparation phase
commit 628bd3e49cba1c066228e23d71a852c23e26da73 upstream.

set .destroy callback releases the references to other objects in maps.
This is very late and it results in spurious EBUSY errors. Drop refcount
from the preparation phase instead, update set backend not to drop
reference counter from set .destroy path.

Exceptions: NFT_TRANS_PREPARE_ERROR does not require to drop the
reference counter because the transaction abort path releases the map
references for each element since the set is unbound. The abort path
also deals with releasing reference counter for new elements added to
unbound sets.

Bug: 299922216
Fixes: 591054469b ("netfilter: nf_tables: revisit chain/object refcounting from elements")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit 3c7ec098e3)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I3fa17ba11bc3dcdb05d4f50eee79357e806581ad
2023-12-06 12:31:05 +00:00
Pablo Neira Ayuso
28ca053314 UPSTREAM: netfilter: nftables: rename set element data activation/deactivation functions
commit f8bb7889af58d8e74d2d61c76b1418230f1610fa upstream.

Rename:

- nft_set_elem_activate() to nft_set_elem_data_activate().
- nft_set_elem_deactivate() to nft_set_elem_data_deactivate().

To prepare for updates in the set element infrastructure to add support
for the special catch-all element.

Bug: 299922216
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit 6b880f3b2c)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I6411a3604194564f35dd7d59b7b6da1e40a9bbe4
2023-12-06 12:31:05 +00:00
Srinivasarao Pathipati
e85a3e2c8e ANDROID: ABI: Update allowed list for QCOM
Leaf changes summary: 1 artifact changed
Changed leaf types summary: 0 leaf type changed
Removed/Changed/Added functions summary: 0 Removed, 0 Changed, 1 Added function
Removed/Changed/Added variables summary: 0 Removed, 0 Changed, 0 Added variable

1 Added function:

  [A] 'function void snd_compr_use_pause_in_draining(snd_compr_stream*)'

Bug: 307192739
Change-Id: I695b5c361725e99e78eb63859607c86486e63141
Signed-off-by: Srinivasarao Pathipati <quic_c_spathi@quicinc.com>
2023-12-06 01:50:50 +00:00
Soumya Managoli
42ae17e6f4 BACKPORT: ALSA: compress: Allow pause and resume during draining
With a stream with low bitrate, user can't pause or resume the stream
near the end of the stream because current ALSA doesn't allow it.
If the stream has very low bitrate enough to store whole stream into
the buffer, user can't do anything except stop the stream and then
restart it from the first because most of applications call draining
after sending last frame to the kernel.
If pause, resume are allowed during draining, user experience can be
enhanced.
To prevent malfunction in HW drivers which don't support pause
during draining, pause during draining will only work if HW driver
enable this feature explicitly by calling
snd_compr_use_pause_in_draining().

Bug: 307192739
Change-Id: Ie40e6131746f8ee780e38f7f876622b407b84a75
Signed-off-by: Gyeongtaek Lee <gt82.lee@samsung.com>
Acked-by: Vinod Koul <vkoul@kernel.org>
Link: https://lore.kernel.org/r/000101d6c3f0$89b312b0$9d193810$@samsung.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
(cherry picked from commit 9be9f2d3d073ef42127475f4fb6a392ab133f629)
[quic_c_smanag@quicinc.com: ported patch in abi safe way]
Signed-off-by: Soumya Managoli <quic_c_smanag@quicinc.com>
2023-12-06 01:50:50 +00:00
qctecmdr
6c5f5fe18a Merge "clk: qcom: gpucc: Add support for LIMITER reset" 2023-12-05 12:36:04 -08:00
Pablo Neira Ayuso
a8427caea3 UPSTREAM: netfilter: nf_tables: pass context to nft_set_destroy()
commit 0c2a85edd143162b3a698f31e94bf8cdc041da87 upstream.

The patch that adds support for stateful expressions in set definitions
require this.

Bug: 299922216
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit e1eed9e0b5)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: Icd0339beda7c78b58caa7f77e5303ff3add7e4e6
2023-12-05 11:17:02 +00:00
Florian Westphal
1ab45006d5 UPSTREAM: netfilter: nf_tables: don't skip expired elements during walk
commit 24138933b97b055d486e8064b4a1721702442a9b upstream.

There is an asymmetry between commit/abort and preparation phase if the
following conditions are met:

1. set is a verdict map ("1.2.3.4 : jump foo")
2. timeouts are enabled

In this case, following sequence is problematic:

1. element E in set S refers to chain C
2. userspace requests removal of set S
3. kernel does a set walk to decrement chain->use count for all elements
   from preparation phase
4. kernel does another set walk to remove elements from the commit phase
   (or another walk to do a chain->use increment for all elements from
    abort phase)

If E has already expired in 1), it will be ignored during list walk, so its use count
won't have been changed.

Then, when set is culled, ->destroy callback will zap the element via
nf_tables_set_elem_destroy(), but this function is only safe for
elements that have been deactivated earlier from the preparation phase:
lack of earlier deactivate removes the element but leaks the chain use
count, which results in a WARN splat when the chain gets removed later,
plus a leak of the nft_chain structure.

Update pipapo_get() not to skip expired elements, otherwise flush
command reports bogus ENOENT errors.

Bug: 299922216
Fixes: 3c4287f62044 ("nf_tables: Add set type for arbitrary concatenation of ranges")
Fixes: 8d8540c4f5 ("netfilter: nft_set_rbtree: add timeout support")
Fixes: 9d0982927e ("netfilter: nft_hash: add support for timeouts")
Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit 1da4874d05)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I644f3fe0e4e565014ff1fa1a0851bd2cc4d0e707
2023-12-05 11:16:36 +00:00
Taniya Das
f8831e2d34 clk: qcom: gpucc: Add support for LIMITER reset
Add support for the consumer to be able to set/reset the
GPU_CC_FREQUENCY_LIMITER_IRQ_CLEAR register as an when required
on BLAIR and HOLI platforms.

Change-Id: I4706352102159f0465c50e53b759a2600f909de0
Signed-off-by: Taniya Das <quic_tdas@quicinc.com>
2023-12-04 22:19:17 -08:00
Taniya Das
c5ebf4ce1a bindings: clk: gpucc: Add support for LIMITER reset
Add support for the consumer to be able to set/reset the
GPU_CC_FREQUENCY_LIMITER_IRQ_CLEAR register as an when required
on BLAIR and HOLI platforms.

Change-Id: I0d041066e36c0152fdcc8e306367aebdc5fd6283
Signed-off-by: Taniya Das <quic_tdas@quicinc.com>
2023-12-04 22:19:13 -08:00
Yongqin Liu
30cf530fbc ANDROID: GKI: db845c: Update symbols list and ABI on rpmsg_register_device_override
android11-5.4-lts is broken on Dragonboard 845c because of
recently added symbol, rpmsg_register_device_override.

So updated the symbols list by running:
  "BUILD_CONFIG=common/build.config.db845c \
    KMI_SYMBOL_LIST_ADD_ONLY=1 build/build_abi.sh -s"

And the abi_gki_aarch64 ABI by running:
  "BUILD_CONFIG=common/build.config.gki.aarch64 \
    ABI_DEFINITION=abi_gki_aarch64.xml KMI_SYMBOL_LIST_ADD_ONLY=1 \
     build/build_abi.sh --update --print-report"

========================================================
Leaf changes summary: 1 artifact changed
Changed leaf types summary: 0 leaf type changed
Removed/Changed/Added functions summary: 0 Removed, 0 Changed, 1 Added function
Removed/Changed/Added variables summary: 0 Removed, 0 Changed, 0 Added variable

1 Added function:

  [A] 'function int rpmsg_register_device_override(rpmsg_device*, const char*)'
========================================================

Bug: 313495196

Change-Id: I3a3504b6d2061bfce0abe9801e2ecb210c337b9f
Signed-off-by: Yongqin Liu <yongqin.liu@linaro.org>
Signed-off-by: Isaac J. Manjarres <isaacmanjarres@google.com>
2023-12-04 17:05:37 +00:00
Lynus Vaz
cb33e1bdb7 msm: kgsl: Do not free sharedmem if it cannot be unmapped
If sharedmem cannot be unmapped from the mmu, it can still be accessed
by the GPU. Therefore it is not safe to free the backing memory. In the
case that unmap fails, do not free it or return it to the system.

Change-Id: Iad3e86d043f129a4d71cf862865d9033d4a315e3
Signed-off-by: Lynus Vaz <quic_lvaz@quicinc.com>
(cherry picked from commit 330843f544)
2023-12-04 05:29:20 -08:00
Lee Jones
eb1843e8af ANDROID: Use GKI Dr. No OWNERS file
The v5.4 branches seem to have been left behind in this regard.

Let's unify the way we implement OWNERS semantics on all branches.

Bug: 314749503
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I54562c23a38ebe2d0059b6134f758cd8d7ec6bc0
2023-12-04 13:28:17 +00:00
Lee Jones
bbbaa68181 ANDROID: Remove android/OWNERs file
An OWNERS file does now exist in the root directory and the fear that it
would be excessively permissive has not become a reality.  Simplify the
situation by inheriting directly from it instead of proving an override.

Bug: 314749503
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I795eee3d7b44aa0f91a2ac4d9a27d0c7cbdc1cc6
(cherry picked from commit a1bbeb516a5aa4ad86f0d260784ea9b9be454244)
Signed-off-by: Lee Jones <joneslee@google.com>
2023-12-04 13:25:14 +00:00
qctecmdr
c162308952 Merge "Merge android11-5.4.254+ (d43ac48) into msm-5.4" 2023-12-03 21:45:35 -08:00
Lynus Vaz
330843f544 msm: kgsl: Do not free sharedmem if it cannot be unmapped
If sharedmem cannot be unmapped from the mmu, it can still be accessed
by the GPU. Therefore it is not safe to free the backing memory. In the
case that unmap fails, do not free it or return it to the system.

Change-Id: Iad3e86d043f129a4d71cf862865d9033d4a315e3
Signed-off-by: Lynus Vaz <quic_lvaz@quicinc.com>
2023-11-30 06:54:17 -08:00
qctecmdr
8da91b648e Merge "soc: qcom: qmi_encdec: out of bound check for input buffer" 2023-11-30 01:44:05 -08:00
Biswarup Pal
b7ba0d931e FROMGIT: Input: uinput - allow injecting event times
Currently, uinput doesn't use the input_set_timestamp API, so any
event injected using uinput is not accurately timestamped in terms of
measuring when the actual event happened. Hence, call the
input_set_timestamp API from uinput in order to provide a more
accurate sense of time for the event. Propagate only the timestamps
which are a) positive, b) within a pre-defined offset (10 secs) from
the current time, and c) not in the future.

Bug: 271946580
Bug: 277040837
Change-Id: I928be61d0114b78e2098995ee49eeb0376bef2a3
(cherry picked from commit 3a2df60200a03f78173f1fd831aa54c08464dcde
https://git.kernel.org/pub/scm/linux/kernel/git/dtor/input.git master)
Signed-off-by: Biswarup Pal <biswarupp@google.com>
Reviewed-by: Peter Hutterer <peter.hutterer@who-t.net>
Reviewed-by: Siarhei Vishniakou <svv@google.com>
Link: https://lore.kernel.org/r/20230427000152.1407471-1-biswarupp@google.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
(cherry picked from commit ee1f5fc55cc7bf1bca78edbb8a1f9d989d4ea03e)
2023-11-29 18:06:49 +00:00
Treehugger Robot
0acbae5b32 Merge "Merge tag 'android11-5.4.259_r00' into android11-5.4" into android11-5.4 2023-11-29 12:41:51 +00:00
Deepak Kumar Singh
ff6fb61c78 soc: qcom: qmi_encdec: out of bound check for input buffer
Data shared by remote processors can not be trusted.
QMI message could be malformed which can result in decoded
bytes greater than length of input buffer supplied causing
buffer overflow.

Check decoded bytes against buffer length to avoid buffer
overflow.

Change-Id: I1d2d3aadd297718b8ecc023a20475b60f4bce022
Signed-off-by: Deepak Kumar Singh <quic_deesin@quicinc.com>
2023-11-29 11:47:36 +05:30
Kasin Li
80f8ee28db soc: hgsl: fix race of isync timeline when creating
In isync timeline create, after timeline object is attached into idr and
unlock the isync_timeline_lock, timeline object still is accessed. if
there is a release thread which try to release the same timeline object,
then maybe cause UAF issue.
Move the access operation into lock to avoid.

Change-Id: Ie2ff412b90924acb8f40e182f26c770b1f110a56
Signed-off-by: Kasin Li <quic_donglil@quicinc.com>
2023-11-29 11:33:53 +08:00
Greg Kroah-Hartman
e8f8c3db8c ANDROID: fix up rpmsg_device ABI break
In commit e70898ae1a ("rpmsg: Fix kfree() of static memory on setting
driver_override") a pointer was changed to const, which messes with the
CRC and ABI checks.  As the code is fine if this is left as not-const,
just put it back to preserve the abi.

Bug: 161946584
Fixes: e70898ae1a ("rpmsg: Fix kfree() of static memory on setting driver_override")
Change-Id: I9a87b9cf412191d9872b48f1f876a81df6701de0
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
(cherry picked from commit 0443350950)
Signed-off-by: Lee Jones <joneslee@google.com>
2023-11-28 10:16:08 +00:00
Greg Kroah-Hartman
a1f6648aa3 ANDROID: fix up platform_device ABI break
In commit 063444d66f ("driver: platform: Add helper for safer setting
of driver_override"), a pointer was changed to const, which messes with
the CRC and ABI checks.  As the code is fine if this is left as
not-const, just put it back to preserve the abi.

Bug: 161946584
Fixes: 063444d66f ("driver: platform: Add helper for safer setting of driver_override")
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: Ieb4a730a6a5767d31fbec2f1ba683617f5cda7a9
(cherry picked from commit 398b357f13)
Signed-off-by: Lee Jones <joneslee@google.com>
2023-11-28 10:15:58 +00:00
kamasali Satyanarayan
1445b6d63a Merge android11-5.4.254+ (d43ac48) into msm-5.4
* remotes/origin/tmp-d43ac48:
BACKPORT: firmware_loader: Abort all upcoming firmware load request once reboot triggered
UPSTREAM: firmware_loader: Refactor kill_pending_fw_fallback_reqs()
UPSTREAM: netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet.c
BACKPORT: ravb: Fix use-after-free issue in ravb_tx_timeout_work()
UPSTREAM: ravb: Fix up dma_free_coherent() call in ravb_remove()
UPSTREAM: netfilter: ipset: Fix race between IPSET_CMD_CREATE and IPSET_CMD_SWAP
UPSTREAM: net: xfrm: Fix xfrm_address_filter OOB read
UPSTREAM: igb: set max size RX buffer when store bad packet is enabled
UPSTREAM: netfilter: xt_sctp: validate the flag_info count
UPSTREAM: netfilter: xt_u32: validate user space input
UPSTREAM: netfilter: nfnetlink_osf: avoid OOB read
UPSTREAM: net/sched: Retire rsvp classifier
UPSTREAM: ipv4: fix null-deref in ipv4_link_failure.

Change-Id: I21ca4b4f9681c29854917bd0b717e1f1c1d5071d
Signed-off-by: kamasali Satyanarayan <quic_kamasali@quicinc.com>
2023-11-26 20:04:54 -08:00
Linux Build Service Account
0fafcd89ef Merge e602774fc1 on remote branch
Change-Id: I7420975c3939e68db30c15b06a905e9d8919fb16
2023-11-21 19:03:18 -08:00
Hangyu Hua
b05d8acf42 UPSTREAM: rpmsg: Fix possible refcount leak in rpmsg_register_device_override()
commit d7bd416d35121c95fe47330e09a5c04adbc5f928 upstream.

rpmsg_register_device_override need to call put_device to free vch when
driver_set_override fails.

Fix this by adding a put_device() to the error path.

Bug: 295334746
Fixes: bb17d110cbf2 ("rpmsg: Fix calling device_lock() on non-initialized device")
Reviewed-by: Krzysztof Kozlowski <krzysztof.kozlowski@linaro.org>
Signed-off-by: Hangyu Hua <hbh25y@gmail.com>
Link: https://lore.kernel.org/r/20220624024120.11576-1-hbh25y@gmail.com
Signed-off-by: Mathieu Poirier <mathieu.poirier@linaro.org>
Signed-off-by: Lee Jones <lee@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit d4c8bf5635c4bedaf2470761ced1f502b2d5434e)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I10440a18479d5d207bafb706311c0467b853cf6c
2023-11-21 14:16:55 +00:00
Bjorn Andersson
9e43c50d47 UPSTREAM: rpmsg: glink: Release driver_override
commit fb80ef67e8ff6a00d3faad4cb348dafdb8eccfd8 upstream.

Upon termination of the rpmsg_device, driver_override needs to be freed
to avoid leaking the potentially assigned string.

Bug: 295334746
Fixes: 42cd402b8fd4 ("rpmsg: Fix kfree() of static memory on setting driver_override")
Fixes: 39e47767ec ("rpmsg: Add driver_override device attribute for rpmsg_device")
Reviewed-by: Chris Lew <quic_clew@quicinc.com>
Signed-off-by: Bjorn Andersson <quic_bjorande@quicinc.com>
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Link: https://lore.kernel.org/r/20230109223931.1706429-1-quic_bjorande@quicinc.com
Signed-off-by: Lee Jones <lee@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit a82e0fda8a2f8561a6a6681e8b3557e60cad17da)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I08b147ad640a8e2d71699a09815bbf048425a1fd
2023-11-21 14:16:47 +00:00
Krzysztof Kozlowski
e172d704c7 BACKPORT: rpmsg: Fix calling device_lock() on non-initialized device
commit bb17d110cbf270d5247a6e261c5ad50e362d1675 upstream.

driver_set_override() helper uses device_lock() so it should not be
called before rpmsg_register_device() (which calls device_register()).
Effect can be seen with CONFIG_DEBUG_MUTEXES:

  DEBUG_LOCKS_WARN_ON(lock->magic != lock)
  WARNING: CPU: 3 PID: 57 at kernel/locking/mutex.c:582 __mutex_lock+0x1ec/0x430
  ...
  Call trace:
   __mutex_lock+0x1ec/0x430
   mutex_lock_nested+0x44/0x50
   driver_set_override+0x124/0x150
   qcom_glink_native_probe+0x30c/0x3b0
   glink_rpm_probe+0x274/0x350
   platform_probe+0x6c/0xe0
   really_probe+0x17c/0x3d0
   __driver_probe_device+0x114/0x190
   driver_probe_device+0x3c/0xf0
   ...

Refactor the rpmsg_register_device() function to use two-step device
registering (initialization + add) and call driver_set_override() in
proper moment.

This moves the code around, so while at it also NULL-ify the
rpdev->driver_override in error path to be sure it won't be kfree()
second time.

Bug: 295334746
Fixes: 42cd402b8fd4 ("rpmsg: Fix kfree() of static memory on setting driver_override")
Reported-by: Marek Szyprowski <m.szyprowski@samsung.com>
Signed-off-by: Krzysztof Kozlowski <krzysztof.kozlowski@linaro.org>
Tested-by: Marek Szyprowski <m.szyprowski@samsung.com>
Link: https://lore.kernel.org/r/20220429195946.1061725-2-krzysztof.kozlowski@linaro.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Lee Jones <lee@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit bfd4a664ddfbe12f008efb0b0ab6bf25a8ab2538)
[Lee: Git was confused that the hunk being removed had changed]
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: Ic07d9ff669e88a50354ad8e978ae8e93316a2a5e
2023-11-21 14:16:40 +00:00
Krzysztof Kozlowski
f497d3c5e8 BACKPORT: rpmsg: Fix kfree() of static memory on setting driver_override
commit 42cd402b8fd4672b692400fe5f9eecd55d2794ac upstream.

The driver_override field from platform driver should not be initialized
from static memory (string literal) because the core later kfree() it,
for example when driver_override is set via sysfs.

Use dedicated helper to set driver_override properly.

Bug: 295334746
Fixes: 950a7388f02b ("rpmsg: Turn name service into a stand alone driver")
Fixes: c0cdc19f84 ("rpmsg: Driver for user space endpoint interface")
Reviewed-by: Bjorn Andersson <bjorn.andersson@linaro.org>
Signed-off-by: Krzysztof Kozlowski <krzysztof.kozlowski@linaro.org>
Link: https://lore.kernel.org/r/20220419113435.246203-13-krzysztof.kozlowski@linaro.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Lee Jones <lee@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit 2e76b4f6218c4db3ff00eb15d94d72f371736de4)
[Lee: Cater for name change s/rpmsg_chrdev/rpmsg_ctrl/ due to previous backport]
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: Ib900ad13efcfdf7e50fb92bb45dff2b8aa8ff443
2023-11-21 14:16:32 +00:00
Krzysztof Kozlowski
d0dadc2667 UPSTREAM: rpmsg: Constify local variable in field store macro
commit e5f89131a06142e91073b6959d91cea73861d40e upstream.

Memory pointed by variable 'old' in field store macro is not modified,
so it can be made a pointer to const.

Bug: 295334746
Signed-off-by: Krzysztof Kozlowski <krzysztof.kozlowski@linaro.org>
Link: https://lore.kernel.org/r/20220419113435.246203-12-krzysztof.kozlowski@linaro.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Lee Jones <lee@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit 5c0da71871d3ac3f96d37067bf1a0ba9c25c2c72)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: If5610892601368e855ec1be57e01dbbe06ae046a
2023-11-21 14:01:01 +00:00
Krzysztof Kozlowski
2069521c81 UPSTREAM: driver: platform: Add helper for safer setting of driver_override
commit 6c2f421174273de8f83cde4286d1c076d43a2d35 upstream.

Several core drivers and buses expect that driver_override is a
dynamically allocated memory thus later they can kfree() it.

However such assumption is not documented, there were in the past and
there are already users setting it to a string literal. This leads to
kfree() of static memory during device release (e.g. in error paths or
during unbind):

    kernel BUG at ../mm/slub.c:3960!
    Internal error: Oops - BUG: 0 [#1] PREEMPT SMP ARM
    ...
    (kfree) from [<c058da50>] (platform_device_release+0x88/0xb4)
    (platform_device_release) from [<c0585be0>] (device_release+0x2c/0x90)
    (device_release) from [<c0a69050>] (kobject_put+0xec/0x20c)
    (kobject_put) from [<c0f2f120>] (exynos5_clk_probe+0x154/0x18c)
    (exynos5_clk_probe) from [<c058de70>] (platform_drv_probe+0x6c/0xa4)
    (platform_drv_probe) from [<c058b7ac>] (really_probe+0x280/0x414)
    (really_probe) from [<c058baf4>] (driver_probe_device+0x78/0x1c4)
    (driver_probe_device) from [<c0589854>] (bus_for_each_drv+0x74/0xb8)
    (bus_for_each_drv) from [<c058b48c>] (__device_attach+0xd4/0x16c)
    (__device_attach) from [<c058a638>] (bus_probe_device+0x88/0x90)
    (bus_probe_device) from [<c05871fc>] (device_add+0x3dc/0x62c)
    (device_add) from [<c075ff10>] (of_platform_device_create_pdata+0x94/0xbc)
    (of_platform_device_create_pdata) from [<c07600ec>] (of_platform_bus_create+0x1a8/0x4fc)
    (of_platform_bus_create) from [<c0760150>] (of_platform_bus_create+0x20c/0x4fc)
    (of_platform_bus_create) from [<c07605f0>] (of_platform_populate+0x84/0x118)
    (of_platform_populate) from [<c0f3c964>] (of_platform_default_populate_init+0xa0/0xb8)
    (of_platform_default_populate_init) from [<c01031f8>] (do_one_initcall+0x8c/0x404)

Provide a helper which clearly documents the usage of driver_override.
This will allow later to reuse the helper and reduce the amount of
duplicated code.

Convert the platform driver to use a new helper and make the
driver_override field const char (it is not modified by the core).

Bug: 295334746
Reviewed-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Acked-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Krzysztof Kozlowski <krzysztof.kozlowski@linaro.org>
Link: https://lore.kernel.org/r/20220419113435.246203-2-krzysztof.kozlowski@linaro.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Lee Jones <lee@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit 063444d66f)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I221cb27e2dda0382f0a2f8466a95d046940ffe9c
2023-11-21 14:00:46 +00:00
Dheeraj Kumar
253ff03050 MobileAP: CVE-2022-2663 fix revert kernel change
Added CVE-2022-2663 fix revert kernel change

Change-Id: I0230a6bc4fd3903c918bce86a5e5728c044b3e3b
Signed-off-by: Dheeraj Kumar <quic_dhekum@quicinc.com>
2023-11-14 17:04:08 +05:30
qctecmdr
e602774fc1 Merge "mtd: msm_qpic_nand: Add mutex lock in system suspend/resume functions" 2023-11-09 02:43:01 -08:00
Mukesh Ojha
d43ac48de2 BACKPORT: firmware_loader: Abort all upcoming firmware load request once reboot triggered
There could be following scenario where there is a ongoing reboot
is going from processA which tries to call all the reboot notifier
callback and one of them is firmware reboot call which tries to
abort all the ongoing firmware userspace request under fw_lock but
there could be another processB which tries to do request firmware,
which came just after abort done from ProcessA and ask for userspace
to load the firmware and this can stop the ongoing reboot ProcessA
to stall for next 60s(default timeout) which may not be expected
behaviour everyone like to see, instead we should abort any firmware
load request which came once firmware knows about the reboot through
notification.

      ProcessA                             ProcessB

kernel_restart_prepare
  blocking_notifier_call_chain
   fw_shutdown_notify
     kill_pending_fw_fallback_reqs
      __fw_load_abort
       fw_state_aborted                request_firmware
         __fw_state_set                 firmware_fallback_sysfs
...                                       fw_load_from_user_helper
..                                         ...
.                                          ..
                                            usermodehelper_read_trylock
                                             fw_load_sysfs_fallback
                                              fw_sysfs_wait_timeout
usermodehelper_disable
 __usermodehelper_disable
  down_write()

Bug: 309378049
Change-Id: I61eb91f21a01460f340f890b25c60de7597a87ff
Signed-off-by: Mukesh Ojha <quic_mojha@quicinc.com>
Acked-by: Luis Chamberlain <mcgrof@kernel.org>
Link: https://lore.kernel.org/r/1698330459-31776-2-git-send-email-quic_mojha@quicinc.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit effd7c70eaa0440688b60b9d419243695ede3c45)
Signed-off-by: Srinivasarao Pathipati <quic_c_spathi@quicinc.com>
2023-11-07 10:13:14 +05:30
Mukesh Ojha
93e172c43e UPSTREAM: firmware_loader: Refactor kill_pending_fw_fallback_reqs()
Rename 'only_kill_custom' and refactor logic related to it
to be more meaningful.

Bug: 309378049
Change-Id: I119d2f8c29b9b624e6c1d8546c1533d76a2cc51d
Signed-off-by: Mukesh Ojha <quic_mojha@quicinc.com>
Acked-by: Luis Chamberlain <mcgrof@kernel.org>
Link: https://lore.kernel.org/r/1698330459-31776-1-git-send-email-quic_mojha@quicinc.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit 87ffa98eeee8d62a56afdad80ea697e7a6e5c354)
Signed-off-by: Srinivasarao Pathipati <quic_c_spathi@quicinc.com>
2023-11-07 10:12:56 +05:30
qctecmdr
63ba6ae867 Merge "nl80211: fix beacon tx rate mask validation" 2023-11-02 19:28:18 -07:00
qctecmdr
4acaec04ab Merge "coresight: Fix duplicate and abnormal stop issues of PCIE sw path" 2023-11-02 15:56:08 -07:00
Mao Jinlong
d4bb64720d coresight: Fix duplicate and abnormal stop issues of PCIE sw path
Compare with sysfs buffer size instead of drvdata size to avoid the
duplicate data issue. Need to compare with the actual data size as
the data size could be smaller than the PCIE block size.

Change-Id: I45175b57a9154cbfb96946d424b8474a6a69213f
Signed-off-by: Mao Jinlong <quic_jinlmao@quicinc.com>
2023-11-02 06:44:17 -07:00
Linux Build Service Account
839ace5f36 Merge "Revert "ALSA: compress: Allow pause and resume during draining"" into kernel.lnx.5.4.r3-rel 2023-11-01 22:49:48 -07:00
Xin Deng
bf0f28818c nl80211: fix beacon tx rate mask validation
While adding HE MCS beacon tx rate support, it is observed that legacy
beacon tx rate in VHT hwsim test suite is failed. Whenever the
application doesn't explicitly set VHT/MCS rate attribute in fixed rate
command, by default all HE MCS masks are enabled in cfg80211. In beacon
fixed rate, more than one rate mask is not allowed. Fix that by not
setting all rate mask by default in case of beacon tx rate.

Signed-off-by: Rajkumar Manoharan <rmanohar@codeaurora.org>
Link: https://lore.kernel.org/r/1602879327-29488-1-git-send-email-rmanohar@codeaurora.org
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Git-repo: https://git.kernel.org/pub/scm/linux/kernel/git/wireless/wireless-next.git
Git-commit: 857b34c4fb104cecc95cd5c5fea5052628758a0f
[quic_deng@quicinc.com: Make appropriate modifications to adapt kernel-5.4.]
Change-Id: I85c5bd502b88ca2157fdc74e4c39de6e75580652
Signed-off-by: Xin Deng <quic_deng@quicinc.com>
2023-11-02 10:05:41 +08:00
Kyle Zeng
49de253fb4 UPSTREAM: netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet.c
commit 050d91c03b28ca479df13dfb02bcd2c60dd6a878 upstream.

The missing IP_SET_HASH_WITH_NET0 macro in ip_set_hash_netportnet can
lead to the use of wrong `CIDR_POS(c)` for calculating array offsets,
which can lead to integer underflow. As a result, it leads to slab
out-of-bound access.
This patch adds back the IP_SET_HASH_WITH_NET0 macro to
ip_set_hash_netportnet to address the issue.

Bug: 302199939
Fixes: 886503f34d ("netfilter: ipset: actually allow allowable CIDR 0 in hash:net,port,net")
Suggested-by: Jozsef Kadlecsik <kadlec@netfilter.org>
Signed-off-by: Kyle Zeng <zengyhkyle@gmail.com>
Acked-by: Jozsef Kadlecsik <kadlec@netfilter.org>
Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit a9e6142e5f8f6ac7d1bca45c1b2b13b084ea9e14)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I11cc1650e7df9d54041164b6bdb01f3a0de46de4
2023-10-31 15:57:14 +00:00
kamasali Satyanarayan
36579e50d8 Merge android11-5.4.254+ (91f7025) into msm-5.4
* remotes/origin/tmp-91f7025:
  UPSTREAM: arm64: efi: Make efi_rt_lock a raw_spinlock
  UPSTREAM: net: sched: sch_qfq: Fix UAF in qfq_dequeue()
  UPSTREAM: net/sched: sch_hfsc: Ensure inner classes have fsc curve
  UPSTREAM: net/sched: sch_qfq: account for stab overhead in qfq_enqueue
  UPSTREAM: netfilter: nf_tables: prevent OOB access in nft_byteorder_eval
  UPSTREAM: af_unix: Fix null-ptr-deref in unix_stream_sendpage().
  BACKPORT: net: nfc: Fix use-after-free caused by nfc_llcp_find_local
  Linux 5.4.254
  sch_netem: fix issues in netem_change() vs get_dist_table()
  alpha: remove __init annotation from exported page_is_ram()
  scsi: core: Fix possible memory leak if device_add() fails
  scsi: snic: Fix possible memory leak if device_add() fails
  scsi: 53c700: Check that command slot is not NULL
  scsi: storvsc: Fix handling of virtual Fibre Channel timeouts
  scsi: core: Fix legacy /proc parsing buffer overflow
  netfilter: nf_tables: report use refcount overflow
  nvme-rdma: fix potential unbalanced freeze & unfreeze
  nvme-tcp: fix potential unbalanced freeze & unfreeze
  btrfs: set cache_block_group_error if we find an error
  btrfs: don't stop integrity writeback too early
  ibmvnic: Handle DMA unmapping of login buffs in release functions
  net/mlx5: Allow 0 for total host VFs
  dmaengine: mcf-edma: Fix a potential un-allocated memory access
  wifi: cfg80211: fix sband iftype data lookup for AP_VLAN
  IB/hfi1: Fix possible panic during hotplug remove
  drivers: net: prevent tun_build_skb() to exceed the packet size limit
  dccp: fix data-race around dp->dccps_mss_cache
  bonding: Fix incorrect deletion of ETH_P_8021AD protocol vid from slaves
  net/packet: annotate data-races around tp->status
  mISDN: Update parameter type of dsp_cmx_send()
  selftests/rseq: Fix build with undefined __weak
  drm/nouveau/disp: Revert a NULL check inside nouveau_connector_get_modes
  x86: Move gds_ucode_mitigated() declaration to header
  x86/mm: Fix VDSO and VVAR placement on 5-level paging machines
  x86/cpu/amd: Enable Zenbleed fix for AMD Custom APU 0405
  usb: common: usb-conn-gpio: Prevent bailing out if initial role is none
  usb: dwc3: Properly handle processing of pending events
  usb-storage: alauda: Fix uninit-value in alauda_check_media()
  binder: fix memory leak in binder_init()
  iio: cros_ec: Fix the allocation size for cros_ec_command
  nilfs2: fix use-after-free of nilfs_root in dirtying inodes via iput
  x86/pkeys: Revert a5eff72597 ("x86/pkeys: Add PKRU value to init_fpstate")
  radix tree test suite: fix incorrect allocation size for pthreads
  drm/nouveau/gr: enable memory loads on helper invocation on all channels
  dmaengine: pl330: Return DMA_PAUSED when transaction is paused
  ipv6: adjust ndisc_is_useropt() to also return true for PIO
  mmc: moxart: read scr register without changing byte order
  Linux 5.4.253
  Revert "driver core: Annotate dev_err_probe() with __must_check"
  drivers: core: fix kernel-doc markup for dev_err_probe()
  driver code: print symbolic error code
  driver core: Annotate dev_err_probe() with __must_check
  ARM: dts: nxp/imx6sll: fix wrong property name in usbphy node
  ARM: dts: imx6sll: fixup of operating points
  ARM: dts: imx: add usb alias
  ARM: dts: imx: Align L2 cache-controller nodename with dtschema
  ARM: dts: imx6sll: Make ssi node name same as other platforms
  arm64: dts: stratix10: fix incorrect I2C property for SCL signal
  ceph: defer stopping mdsc delayed_work
  ceph: use kill_anon_super helper
  ceph: show tasks waiting on caps in debugfs caps file
  PM: sleep: wakeirq: fix wake irq arming
  PM / wakeirq: support enabling wake-up irq after runtime_suspend called
  selftests/rseq: Play nice with binaries statically linked against glibc 2.35+
  selftests/rseq: check if libc rseq support is registered
  powerpc/mm/altmap: Fix altmap boundary check
  mtd: rawnand: omap_elm: Fix incorrect type in assignment
  test_firmware: return ENOMEM instead of ENOSPC on failed memory allocation
  test_firmware: prevent race conditions by a correct implementation of locking
  ext2: Drop fragment support
  fs: Protect reconfiguration of sb read-write from racing writes
  net: usbnet: Fix WARNING in usbnet_start_xmit/usb_submit_urb
  Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_ready_cb
  fs/sysv: Null check to prevent null-ptr-deref bug
  net: tap_open(): set sk_uid from current_fsuid()
  net: tun_chr_open(): set sk_uid from current_fsuid()
  mtd: rawnand: meson: fix OOB available bytes for ECC
  mtd: spinand: toshiba: Fix ecc_get_status
  USB: zaurus: Add ID for A-300/B-500/C-700
  libceph: fix potential hang in ceph_osdc_notify()
  scsi: zfcp: Defer fc_rport blocking until after ADISC response
  tcp_metrics: fix data-race in tcpm_suck_dst() vs fastopen
  tcp_metrics: annotate data-races around tm->tcpm_net
  tcp_metrics: annotate data-races around tm->tcpm_vals[]
  tcp_metrics: annotate data-races around tm->tcpm_lock
  tcp_metrics: annotate data-races around tm->tcpm_stamp
  tcp_metrics: fix addr_same() helper
  ip6mr: Fix skb_under_panic in ip6mr_cache_report()
  net: dcb: choose correct policy to parse DCB_ATTR_BCN
  net: ll_temac: fix error checking of irq_of_parse_and_map()
  net: ll_temac: Switch to use dev_err_probe() helper
  driver core: add device probe log helper
  bpf: sockmap: Remove preempt_disable in sock_map_sk_acquire
  net/sched: cls_route: No longer copy tcf_result on update to avoid use-after-free
  net/sched: cls_fw: No longer copy tcf_result on update to avoid use-after-free
  net/sched: cls_u32: No longer copy tcf_result on update to avoid use-after-free
  net: add missing data-race annotation for sk_ll_usec
  net: add missing data-race annotations around sk->sk_peek_off
  net: add missing READ_ONCE(sk->sk_rcvbuf) annotation
  net: add missing READ_ONCE(sk->sk_sndbuf) annotation
  net: add missing READ_ONCE(sk->sk_rcvlowat) annotation
  net: annotate data-races around sk->sk_max_pacing_rate
  mISDN: hfcpci: Fix potential deadlock on &hc->lock
  net: sched: cls_u32: Fix match key mis-addressing
  perf test uprobe_from_different_cu: Skip if there is no gcc
  rtnetlink: let rtnl_bridge_setlink checks IFLA_BRIDGE_MODE length
  net/mlx5e: fix return value check in mlx5e_ipsec_remove_trailer()
  net/mlx5: DR, fix memory leak in mlx5dr_cmd_create_reformat_ctx
  KVM: s390: fix sthyi error handling
  word-at-a-time: use the same return type for has_zero regardless of endianness
  loop: Select I/O scheduler 'none' from inside add_disk()
  perf: Fix function pointer case
  arm64: Fix bit-shifting UB in the MIDR_CPU_MODEL() macro
  arm64: Add AMPERE1 to the Spectre-BHB affected list
  ASoC: cs42l51: fix driver to properly autoload with automatic module loading
  net/sched: sch_qfq: account for stab overhead in qfq_enqueue
  btrfs: fix race between quota disable and quota assign ioctls
  btrfs: qgroup: return ENOTCONN instead of EINVAL when quotas are not enabled
  btrfs: qgroup: remove one-time use variables for quota_root checks
  cpufreq: intel_pstate: Drop ACPI _PSS states table patching
  ACPI: processor: perflib: Avoid updating frequency QoS unnecessarily
  ACPI: processor: perflib: Use the "no limit" frequency QoS
  dm cache policy smq: ensure IO doesn't prevent cleaner policy progress
  ASoC: wm8904: Fill the cache for WM8904_ADC_TEST_0 register
  s390/dasd: fix hanging device after quiesce/resume
  virtio-net: fix race between set queues and probe
  btrfs: check if the transaction was aborted at btrfs_wait_for_commit()
  irq-bcm6345-l1: Do not assume a fixed block to cpu mapping
  tpm_tis: Explicitly check for error code
  btrfs: check for commit error at btrfs_attach_transaction_barrier()
  hwmon: (nct7802) Fix for temp6 (PECI1) processed even if PECI1 disabled
  staging: ks7010: potential buffer overflow in ks_wlan_set_encode_ext()
  Documentation: security-bugs.rst: clarify CVE handling
  Documentation: security-bugs.rst: update preferences when dealing with the linux-distros group
  Revert "usb: xhci: tegra: Fix error check"
  usb: xhci-mtk: set the dma max_seg_size
  USB: quirks: add quirk for Focusrite Scarlett
  usb: ohci-at91: Fix the unhandle interrupt when resume
  usb: dwc3: don't reset device side if dwc3 was configured as host-only
  usb: dwc3: pci: skip BYT GPIO lookup table for hardwired phy
  Revert "usb: dwc3: core: Enable AutoRetry feature in the controller"
  can: gs_usb: gs_can_close(): add missing set of CAN state to CAN_STATE_STOPPED
  USB: serial: simple: sort driver entries
  USB: serial: simple: add Kaufmann RKS+CAN VCP
  USB: serial: option: add Quectel EC200A module support
  USB: serial: option: support Quectel EM060K_128
  serial: sifive: Fix sifive_serial_console_setup() section
  serial: 8250_dw: Preserve original value of DLF register
  tracing: Fix warning in trace_buffered_event_disable()
  ring-buffer: Fix wrong stat of cpu_buffer->read
  ata: pata_ns87415: mark ns87560_tf_read static
  dm raid: fix missing reconfig_mutex unlock in raid_ctr() error paths
  block: Fix a source code comment in include/uapi/linux/blkzoned.h
  ASoC: fsl_spdif: Silence output on stop
  drm/msm: Fix IS_ERR_OR_NULL() vs NULL check in a5xx_submit_in_rb()
  drm/msm/adreno: Fix snapshot BINDLESS_DATA size
  drm/msm/dpu: drop enum dpu_core_perf_data_bus_id
  RDMA/mlx4: Make check for invalid flags stricter
  benet: fix return value check in be_lancer_xmit_workarounds()
  net/sched: mqprio: Add length check for TCA_MQPRIO_{MAX/MIN}_RATE64
  net/sched: mqprio: add extack to mqprio_parse_nlattr()
  net/sched: mqprio: refactor nlattr parsing to a separate function
  platform/x86: msi-laptop: Fix rfkill out-of-sync on MSI Wind U100
  team: reset team's flags when down link is P2P device
  bonding: reset bond's flags when down link is P2P device
  tcp: Reduce chance of collisions in inet6_hashfn().
  ipv6 addrconf: fix bug where deleting a mngtmpaddr can create a new temporary address
  ethernet: atheros: fix return value check in atl1e_tso_csum()
  phy: hisilicon: Fix an out of bounds check in hisi_inno_phy_probe()
  vxlan: calculate correct header length for GPE
  i40e: Fix an NULL vs IS_ERR() bug for debugfs_create_dir()
  ext4: fix to check return value of freeze_bdev() in ext4_shutdown()
  keys: Fix linking a duplicate key to a keyring's assoc_array
  uapi: General notification queue definitions
  scsi: qla2xxx: Array index may go out of bound
  scsi: qla2xxx: Fix inconsistent format argument type in qla_os.c
  pwm: meson: fix handling of period/duty if greater than UINT_MAX
  pwm: meson: Simplify duplicated per-channel tracking
  pwm: meson: Remove redundant assignment to variable fin_freq
  ftrace: Fix possible warning on checking all pages used in ftrace_process_locs()
  ftrace: Store the order of pages allocated in ftrace_page
  ftrace: Check if pages were allocated before calling free_pages()
  ftrace: Add information on number of page groups allocated
  fs: dlm: interrupt posix locks only when process is killed
  dlm: rearrange async condition return
  dlm: cleanup plock_op vs plock_xop
  PCI/ASPM: Avoid link retraining race
  PCI/ASPM: Factor out pcie_wait_for_retrain()
  PCI/ASPM: Return 0 or -ETIMEDOUT from pcie_retrain_link()
  ext4: Fix reusing stale buffer heads from last failed mounting
  ext4: rename journal_dev to s_journal_dev inside ext4_sb_info
  btrfs: fix extent buffer leak after tree mod log failure at split_node()
  btrfs: fix race between quota disable and relocation
  btrfs: qgroup: catch reserved space leaks at unmount time
  bcache: Fix __bch_btree_node_alloc to make the failure behavior consistent
  bcache: remove 'int n' from parameter list of bch_bucket_alloc_set()
  gpio: tps68470: Make tps68470_gpio_output() always set the initial value
  jbd2: Fix wrongly judgement for buffer head removing while doing checkpoint
  jbd2: recheck chechpointing non-dirty buffer
  jbd2: remove redundant buffer io error checks
  jbd2: fix kernel-doc markups
  jbd2: fix incorrect code style
  Linux 5.4.252
  x86: fix backwards merge of GDS/SRSO bit
  xen/netback: Fix buffer overrun triggered by unusual packet
  x86/cpu, kvm: Add support for CPUID_80000021_EAX
  x86/bugs: Increase the x86 bugs vector size to two u32s
  tools headers cpufeatures: Sync with the kernel sources
  x86/cpufeatures: Assign dedicated feature word for CPUID_0x8000001F[EAX]
  x86/cpu: Add VM page flush MSR availablility as a CPUID feature
  x86/cpufeatures: Add SEV-ES CPU feature
  Documentation/x86: Fix backwards on/off logic about YMM support
  x86/mm: Initialize text poking earlier
  mm: Move mm_cachep initialization to mm_init()
  x86/mm: Use mm_alloc() in poking_init()
  x86/mm: fix poking_init() for Xen PV guests
  x86/xen: Fix secondary processors' FPU initialization
  KVM: Add GDS_NO support to KVM
  x86/speculation: Add Kconfig option for GDS
  x86/speculation: Add force option to GDS mitigation
  x86/speculation: Add Gather Data Sampling mitigation
  x86/fpu: Move FPU initialization into arch_cpu_finalize_init()
  x86/fpu: Mark init functions __init
  x86/fpu: Remove cpuinfo argument from init functions
  init, x86: Move mem_encrypt_init() into arch_cpu_finalize_init()
  init: Invoke arch_cpu_finalize_init() earlier
  init: Remove check_bugs() leftovers
  um/cpu: Switch to arch_cpu_finalize_init()
  sparc/cpu: Switch to arch_cpu_finalize_init()
  sh/cpu: Switch to arch_cpu_finalize_init()
  mips/cpu: Switch to arch_cpu_finalize_init()
  m68k/cpu: Switch to arch_cpu_finalize_init()
  ia64/cpu: Switch to arch_cpu_finalize_init()
  ARM: cpu: Switch to arch_cpu_finalize_init()
  x86/cpu: Switch to arch_cpu_finalize_init()
  init: Provide arch_cpu_finalize_init()
  Revert "posix-timers: Ensure timer ID search-loop limit is valid"
  Revert "drm/panel: Initialise panel dev and funcs through drm_panel_init()"
  Revert "drm/panel: Add and fill drm_panel type field"
  Revert "drm/panel: simple: Add connector_type for innolux_at043tn24"
  Revert "Revert "8250: add support for ASIX devices with a FIFO bug""
  Linux 5.4.251
  tracing/histograms: Return an error if we fail to add histogram to hist_vars list
  tcp: annotate data-races around fastopenq.max_qlen
  tcp: annotate data-races around tp->notsent_lowat
  tcp: annotate data-races around rskq_defer_accept
  tcp: annotate data-races around tp->linger2
  net: Replace the limit of TCP_LINGER2 with TCP_FIN_TIMEOUT_MAX
  tcp: annotate data-races around tp->tcp_tx_delay
  netfilter: nf_tables: can't schedule in nft_chain_validate
  netfilter: nf_tables: fix spurious set element insertion failure
  llc: Don't drop packet from non-root netns.
  fbdev: au1200fb: Fix missing IRQ check in au1200fb_drv_probe
  Revert "tcp: avoid the lookup process failing to get sk in ehash table"
  net:ipv6: check return value of pskb_trim()
  iavf: Fix use-after-free in free_netdev
  net: ethernet: ti: cpsw_ale: Fix cpsw_ale_get_field()/cpsw_ale_set_field()
  pinctrl: amd: Use amd_pinconf_set() for all config options
  fbdev: imxfb: warn about invalid left/right margin
  spi: bcm63xx: fix max prepend length
  igb: Fix igb_down hung on surprise removal
  wifi: iwlwifi: mvm: avoid baid size integer overflow
  wifi: wext-core: Fix -Wstringop-overflow warning in ioctl_standard_iw_point()
  devlink: report devlink_port_type_warn source device
  bpf: Address KCSAN report on bpf_lru_list
  sched/fair: Don't balance task to its current running CPU
  arm64: mm: fix VA-range sanity check
  posix-timers: Ensure timer ID search-loop limit is valid
  md/raid10: prevent soft lockup while flush writes
  md: fix data corruption for raid456 when reshape restart while grow up
  nbd: Add the maximum limit of allocated index in nbd_dev_add
  debugobjects: Recheck debug_objects_enabled before reporting
  ext4: correct inline offset when handling xattrs in inode body
  drm/client: Fix memory leak in drm_client_modeset_probe
  drm/client: Fix memory leak in drm_client_target_cloned
  can: bcm: Fix UAF in bcm_proc_show()
  selftests: tc: set timeout to 15 minutes
  fuse: revalidate: don't invalidate if interrupted
  btrfs: fix warning when putting transaction with qgroups enabled after abort
  perf probe: Add test for regression introduced by switch to die_get_decl_file()
  drm/atomic: Fix potential use-after-free in nonblocking commits
  scsi: qla2xxx: Remove unused nvme_ls_waitq wait queue
  scsi: qla2xxx: Pointer may be dereferenced
  scsi: qla2xxx: Correct the index of array
  scsi: qla2xxx: Check valid rport returned by fc_bsg_to_rport()
  scsi: qla2xxx: Fix potential NULL pointer dereference
  scsi: qla2xxx: Wait for io return on terminate rport
  tracing/probes: Fix not to count error code to total length
  tracing: Fix null pointer dereference in tracing_err_log_open()
  xtensa: ISS: fix call to split_if_spec
  ring-buffer: Fix deadloop issue on reading trace_pipe
  tracing/histograms: Add histograms to hist_vars if they have referenced variables
  tty: serial: samsung_tty: Fix a memory leak in s3c24xx_serial_getclk() when iterating clk
  tty: serial: samsung_tty: Fix a memory leak in s3c24xx_serial_getclk() in case of error
  Revert "8250: add support for ASIX devices with a FIFO bug"
  meson saradc: fix clock divider mask length
  ceph: don't let check_caps skip sending responses for revoke msgs
  hwrng: imx-rngc - fix the timeout for init and self check
  firmware: stratix10-svc: Fix a potential resource leak in svc_create_memory_pool()
  serial: atmel: don't enable IRQs prematurely
  drm/rockchip: vop: Leave vblank enabled in self-refresh
  drm/atomic: Allow vblank-enabled + self-refresh "disable"
  fs: dlm: return positive pid value for F_GETLK
  md/raid0: add discard support for the 'original' layout
  misc: pci_endpoint_test: Re-init completion for every test
  misc: pci_endpoint_test: Free IRQs before removing the device
  PCI: rockchip: Set address alignment for endpoint mode
  PCI: rockchip: Use u32 variable to access 32-bit registers
  PCI: rockchip: Fix legacy IRQ generation for RK3399 PCIe endpoint core
  PCI: rockchip: Add poll and timeout to wait for PHY PLLs to be locked
  PCI: rockchip: Write PCI Device ID to correct register
  PCI: rockchip: Assert PCI Configuration Enable bit after probe
  PCI: qcom: Disable write access to read only registers for IP v2.3.3
  PCI: Add function 1 DMA alias quirk for Marvell 88SE9235
  PCI/PM: Avoid putting EloPOS E2/S2/H2 PCIe Ports in D3cold
  jfs: jfs_dmap: Validate db_l2nbperpage while mounting
  ext4: only update i_reserved_data_blocks on successful block allocation
  ext4: fix wrong unit use in ext4_mb_clear_bb
  erofs: fix compact 4B support for 16k block size
  SUNRPC: Fix UAF in svc_tcp_listen_data_ready()
  misc: fastrpc: Create fastrpc scalar with correct buffer count
  powerpc: Fail build if using recordmcount with binutils v2.37
  net: bcmgenet: Ensure MDIO unregistration has clocks enabled
  mtd: rawnand: meson: fix unaligned DMA buffers handling
  tpm: tpm_vtpm_proxy: fix a race condition in /dev/vtpmx creation
  pinctrl: amd: Only use special debounce behavior for GPIO 0
  pinctrl: amd: Detect internal GPIO0 debounce handling
  pinctrl: amd: Fix mistake in handling clearing pins at startup
  net/sched: make psched_mtu() RTNL-less safe
  net/sched: flower: Ensure both minimum and maximum ports are specified
  cls_flower: Add extack support for src and dst port range options
  wifi: airo: avoid uninitialized warning in airo_get_rate()
  erofs: avoid infinite loop in z_erofs_do_read_page() when reading beyond EOF
  platform/x86: wmi: Break possible infinite loop when parsing GUID
  platform/x86: wmi: move variables
  platform/x86: wmi: use guid_t and guid_equal()
  platform/x86: wmi: remove unnecessary argument
  platform/x86: wmi: Fix indentation in some cases
  platform/x86: wmi: Replace UUID redefinitions by their originals
  ipv6/addrconf: fix a potential refcount underflow for idev
  NTB: ntb_tool: Add check for devm_kcalloc
  NTB: ntb_transport: fix possible memory leak while device_register() fails
  ntb: intel: Fix error handling in intel_ntb_pci_driver_init()
  NTB: amd: Fix error handling in amd_ntb_pci_driver_init()
  ntb: idt: Fix error handling in idt_pci_driver_init()
  udp6: fix udp6_ehashfn() typo
  icmp6: Fix null-ptr-deref of ip6_null_entry->rt6i_idev in icmp6_dev().
  ionic: remove WARN_ON to prevent panic_on_warn
  ionic: ionic_intr_free parameter change
  ionic: move irq request to qcq alloc
  ionic: clean irq affinity on queue deinit
  ionic: improve irq numa locality
  net/sched: cls_fw: Fix improper refcount update leads to use-after-free
  net: mvneta: fix txq_map in case of txq_number==1
  scsi: qla2xxx: Fix error code in qla2x00_start_sp()
  igc: set TP bit in 'supported' and 'advertising' fields of ethtool_link_ksettings
  igc: Remove delay during TX ring configuration
  drm/panel: simple: Add connector_type for innolux_at043tn24
  drm/panel: Add and fill drm_panel type field
  drm/panel: Initialise panel dev and funcs through drm_panel_init()
  workqueue: clean up WORK_* constant types, clarify masking
  net: lan743x: Don't sleep in atomic context
  block/partition: fix signedness issue for Amiga partitions
  tty: serial: fsl_lpuart: add earlycon for imx8ulp platform
  netfilter: nf_tables: prevent OOB access in nft_byteorder_eval
  netfilter: conntrack: Avoid nf_ct_helper_hash uses after free
  netfilter: nf_tables: fix scheduling-while-atomic splat
  netfilter: nf_tables: unbind non-anonymous set if rule construction fails
  netfilter: nf_tables: reject unbound anonymous set before commit phase
  netfilter: nf_tables: add NFT_TRANS_PREPARE_ERROR to deal with bound set/chain
  netfilter: nf_tables: incorrect error path handling with NFT_MSG_NEWRULE
  netfilter: nf_tables: add rescheduling points during loop detection walks
  netfilter: nf_tables: use net_generic infra for transaction data
  netfilter: add helper function to set up the nfnetlink header and use it
  netfilter: nftables: add helper function to set the base sequence number
  netfilter: nf_tables: fix nat hook table deletion
  block: add overflow checks for Amiga partition support
  fanotify: disallow mount/sb marks on kernel internal pseudo fs
  fs: no need to check source
  ARM: orion5x: fix d2net gpio initialization
  btrfs: fix race when deleting quota root from the dirty cow roots list
  fs: Lock moved directories
  fs: Establish locking order for unrelated directories
  Revert "f2fs: fix potential corruption when moving a directory"
  ext4: Remove ext4 locking of moved directory
  fs: avoid empty option when generating legacy mount string
  jffs2: reduce stack usage in jffs2_build_xattr_subsystem()
  integrity: Fix possible multiple allocation in integrity_inode_get()
  bcache: Remove unnecessary NULL point check in node allocations
  mmc: sdhci: fix DMA configure compatibility issue when 64bit DMA mode is used.
  mmc: core: disable TRIM on Micron MTFC4GACAJCN-1M
  mmc: core: disable TRIM on Kingston EMMC04G-M627
  NFSD: add encoding of op_recall flag for write delegation
  ALSA: jack: Fix mutex call in snd_jack_report()
  i2c: xiic: Don't try to handle more interrupt events after error
  i2c: xiic: Defer xiic_wakeup() and __xiic_start_xfer() in xiic_process()
  sh: dma: Fix DMA channel offset calculation
  net: dsa: tag_sja1105: fix MAC DA patching from meta frames
  net/sched: act_pedit: Add size check for TCA_PEDIT_PARMS_EX
  xsk: Honor SO_BINDTODEVICE on bind
  xsk: Improve documentation for AF_XDP
  tcp: annotate data races in __tcp_oow_rate_limited()
  net: bridge: keep ports without IFF_UNICAST_FLT in BR_PROMISC mode
  powerpc: allow PPC_EARLY_DEBUG_CPM only when SERIAL_CPM=y
  f2fs: fix error path handling in truncate_dnode()
  mailbox: ti-msgmgr: Fill non-message tx data fields with 0x0
  spi: bcm-qspi: return error if neither hif_mspi nor mspi is available
  Add MODULE_FIRMWARE() for FIRMWARE_TG357766.
  sctp: fix potential deadlock on &net->sctp.addr_wq_lock
  rtc: st-lpc: Release some resources in st_rtc_probe() in case of error
  pwm: sysfs: Do not apply state to already disabled PWMs
  pwm: imx-tpm: force 'real_period' to be zero in suspend
  mfd: stmpe: Only disable the regulators if they are enabled
  KVM: s390: vsie: fix the length of APCB bitmap
  mfd: stmfx: Fix error path in stmfx_chip_init
  serial: 8250_omap: Use force_suspend and resume for system suspend
  mfd: intel-lpss: Add missing check for platform_get_resource
  usb: dwc3: qcom: Release the correct resources in dwc3_qcom_remove()
  KVM: s390: fix KVM_S390_GET_CMMA_BITS for GFNs in memslot holes
  mfd: rt5033: Drop rt5033-battery sub-device
  usb: hide unused usbfs_notify_suspend/resume functions
  usb: phy: phy-tahvo: fix memory leak in tahvo_usb_probe()
  extcon: Fix kernel doc of property capability fields to avoid warnings
  extcon: Fix kernel doc of property fields to avoid warnings
  usb: dwc3: qcom: Fix potential memory leak
  media: usb: siano: Fix warning due to null work_func_t function pointer
  media: videodev2.h: Fix struct v4l2_input tuner index comment
  media: usb: Check az6007_read() return value
  sh: j2: Use ioremap() to translate device tree address into kernel memory
  w1: fix loop in w1_fini()
  block: change all __u32 annotations to __be32 in affs_hardblocks.h
  block: fix signed int overflow in Amiga partition support
  usb: dwc3: gadget: Propagate core init errors to UDC during pullup
  USB: serial: option: add LARA-R6 01B PIDs
  hwrng: st - keep clock enabled while hwrng is registered
  hwrng: st - Fix W=1 unused variable warning
  NFSv4.1: freeze the session table upon receiving NFS4ERR_BADSESSION
  ARC: define ASM_NL and __ALIGN(_STR) outside #ifdef __ASSEMBLY__ guard
  modpost: fix off by one in is_executable_section()
  crypto: marvell/cesa - Fix type mismatch warning
  modpost: fix section mismatch message for R_ARM_{PC24,CALL,JUMP24}
  modpost: fix section mismatch message for R_ARM_ABS32
  crypto: nx - fix build warnings when DEBUG_FS is not enabled
  hwrng: virtio - Fix race on data_avail and actual data
  hwrng: virtio - always add a pending request
  hwrng: virtio - don't waste entropy
  hwrng: virtio - don't wait on cleanup
  hwrng: virtio - add an internal buffer
  powerpc/mm/dax: Fix the condition when checking if altmap vmemap can cross-boundary
  pinctrl: at91-pio4: check return value of devm_kasprintf()
  perf dwarf-aux: Fix off-by-one in die_get_varname()
  pinctrl: cherryview: Return correct value if pin in push-pull mode
  PCI: Add pci_clear_master() stub for non-CONFIG_PCI
  PCI: ftpci100: Release the clock resources
  PCI: pciehp: Cancel bringup sequence if card is not present
  scsi: 3w-xxxx: Add error handling for initialization failure in tw_probe()
  PCI/ASPM: Disable ASPM on MFD function removal to avoid use-after-free
  scsi: qedf: Fix NULL dereference in error handling
  ASoC: imx-audmix: check return value of devm_kasprintf()
  clk: keystone: sci-clk: check return value of kasprintf()
  clk: cdce925: check return value of kasprintf()
  ALSA: ac97: Fix possible NULL dereference in snd_ac97_mixer
  clk: tegra: tegra124-emc: Fix potential memory leak
  drm/radeon: fix possible division-by-zero errors
  drm/amdkfd: Fix potential deallocation of previously deallocated memory.
  fbdev: omapfb: lcd_mipid: Fix an error handling path in mipid_spi_probe()
  arm64: dts: renesas: ulcb-kf: Remove flow control for SCIF1
  IB/hfi1: Fix sdma.h tx->num_descs off-by-one errors
  soc/fsl/qe: fix usb.c build errors
  ASoC: es8316: Do not set rate constraints for unsupported MCLKs
  ASoC: es8316: Increment max value for ALC Capture Target Volume control
  memory: brcmstb_dpfe: fix testing array offset after use
  ARM: ep93xx: fix missing-prototype warnings
  drm/panel: simple: fix active size for Ampire AM-480272H3TMQW-T01H
  arm64: dts: qcom: msm8916: correct camss unit address
  ARM: dts: gta04: Move model property out of pinctrl node
  RDMA/bnxt_re: Fix to remove an unnecessary log
  drm: sun4i_tcon: use devm_clk_get_enabled in `sun4i_tcon_init_clocks`
  Input: adxl34x - do not hardcode interrupt trigger type
  ARM: dts: BCM5301X: Drop "clock-names" from the SPI node
  Input: drv260x - sleep between polling GO bit
  radeon: avoid double free in ci_dpm_init()
  netlink: Add __sock_i_ino() for __netlink_diag_dump().
  ipvlan: Fix return value of ipvlan_queue_xmit()
  netfilter: nf_conntrack_sip: fix the ct_sip_parse_numerical_param() return value.
  netfilter: conntrack: dccp: copy entire header to stack buffer, not just basic one
  lib/ts_bm: reset initial match offset for every block of text
  net: nfc: Fix use-after-free caused by nfc_llcp_find_local
  nfc: llcp: simplify llcp_sock_connect() error paths
  gtp: Fix use-after-free in __gtp_encap_destroy().
  selftests: rtnetlink: remove netdevsim device after ipsec offload test
  netlink: do not hard code device address lenth in fdb dumps
  netlink: fix potential deadlock in netlink_set_err()
  wifi: ath9k: convert msecs to jiffies where needed
  wifi: cfg80211: rewrite merging of inherited elements
  wifi: iwlwifi: pull from TXQs with softirqs disabled
  rtnetlink: extend RTEXT_FILTER_SKIP_STATS to IFLA_VF_INFO
  wifi: ath9k: Fix possible stall on ath9k_txq_list_has_key()
  memstick r592: make memstick_debug_get_tpc_name() static
  kexec: fix a memory leak in crash_shrink_memory()
  watchdog/perf: more properly prevent false positives with turbo modes
  watchdog/perf: define dummy watchdog_update_hrtimer_threshold() on correct config
  wifi: rsi: Do not set MMC_PM_KEEP_POWER in shutdown
  wifi: ath9k: don't allow to overwrite ENDPOINT0 attributes
  wifi: ray_cs: Fix an error handling path in ray_probe()
  wifi: ray_cs: Drop useless status variable in parse_addr()
  wifi: ray_cs: Utilize strnlen() in parse_addr()
  wifi: wl3501_cs: Fix an error handling path in wl3501_probe()
  wl3501_cs: use eth_hw_addr_set()
  net: create netdev->dev_addr assignment helpers
  wl3501_cs: Fix misspelling and provide missing documentation
  wl3501_cs: Remove unnecessary NULL check
  wl3501_cs: Fix a bunch of formatting issues related to function docs
  wifi: atmel: Fix an error handling path in atmel_probe()
  wifi: orinoco: Fix an error handling path in orinoco_cs_probe()
  wifi: orinoco: Fix an error handling path in spectrum_cs_probe()
  regulator: core: Streamline debugfs operations
  regulator: core: Fix more error checking for debugfs_create_dir()
  nfc: llcp: fix possible use of uninitialized variable in nfc_llcp_send_connect()
  nfc: constify several pointers to u8, char and sk_buff
  wifi: mwifiex: Fix the size of a memory allocation in mwifiex_ret_802_11_scan()
  spi: spi-geni-qcom: Correct CS_TOGGLE bit in SPI_TRANS_CFG
  samples/bpf: Fix buffer overflow in tcp_basertt
  wifi: ath9k: avoid referencing uninit memory in ath9k_wmi_ctrl_rx
  wifi: ath9k: fix AR9003 mac hardware hang check register offset calculation
  ima: Fix build warnings
  pstore/ram: Add check for kstrdup
  evm: Complete description of evm_inode_setattr()
  ARM: 9303/1: kprobes: avoid missing-declaration warnings
  powercap: RAPL: Fix CONFIG_IOSF_MBI dependency
  PM: domains: fix integer overflow issues in genpd_parse_state()
  clocksource/drivers/cadence-ttc: Fix memory leak in ttc_timer_probe
  clocksource/drivers/cadence-ttc: Use ttc driver as platform driver
  tracing/timer: Add missing hrtimer modes to decode_hrtimer_mode().
  irqchip/jcore-aic: Fix missing allocation of IRQ descriptors
  irqchip/jcore-aic: Kill use of irq_create_strict_mappings()
  md/raid10: fix io loss while replacement replace rdev
  md/raid10: fix null-ptr-deref of mreplace in raid10_sync_request
  md/raid10: fix wrong setting of max_corr_read_errors
  md/raid10: fix overflow of md/safe_mode_delay
  md/raid10: check slab-out-of-bounds in md_bitmap_get_counter
  x86/resctrl: Only show tasks' pid in current pid namespace
  x86/resctrl: Use is_closid_match() in more places
  bgmac: fix *initial* chip reset to support BCM5358
  drm/amdgpu: Validate VM ioctl flags.
  scripts/tags.sh: Resolve gtags empty index generation
  drm/i915: Initialise outparam for error return from wait_for_register
  HID: wacom: Use ktime_t rather than int when dealing with timestamps
  fbdev: imsttfb: Fix use after free bug in imsttfb_probe
  video: imsttfb: check for ioremap() failures
  x86/smp: Use dedicated cache-line for mwait_play_dead()
  gfs2: Don't deref jdesc in evict
  Linux 5.4.250
  x86/cpu/amd: Add a Zenbleed fix
  x86/cpu/amd: Move the errata checking functionality up
  x86/microcode/AMD: Load late on both threads too

Conflict:
	drivers/usb/dwc3/gadget.c

Change-Id: Ibfc470316e278f29831f47d6c76bade3f8514073
Signed-off-by: kamasali Satyanarayan <quic_kamasali@quicinc.com>
2023-10-30 22:46:41 -07:00
Greg Kroah-Hartman
b40f1a5d2f Merge tag 'android11-5.4.259_r00' into android11-5.4
This merges the upstream 5.4.259 LTS release into the android11-5.4
branch.  It contains the following commits:

* 4934e8f7a8 Revert "perf: Disallow mis-matched inherited group reads"
* 231c81bbc8 Revert "xfrm: fix a data-race in xfrm_gen_index()"
* 0ca22be029 Revert "Bluetooth: hci_core: Fix build warnings"
* cf5d98b23e Revert "xfrm: interface: use DEV_STATS_INC()"
*   6b5f21afc2 Merge 5.4.259 into android11-5.4-lts
|\
| * 86ea40e6ad Linux 5.4.259
| * c01ac092d9 xfrm6: fix inet6_dev refcount underflow problem
| * b849a38e18 Bluetooth: hci_sock: Correctly bounds check and pad HCI_MON_NEW_INDEX name
| * 4d161e18b1 Bluetooth: hci_sock: fix slab oob read in create_monitor_event
| * a0f0e43128 phy: mapphone-mdm6600: Fix pinctrl_pm handling for sleep pins
| * d1618b9223 phy: mapphone-mdm6600: Fix runtime PM for remove
| * 4db06513a0 phy: mapphone-mdm6600: Fix runtime disable on probe
| * 083ff5b50c ASoC: pxa: fix a memory leak in probe()
| * 27a17a2590 gpio: vf610: set value before the direction to avoid a glitch
| * 664aad86e5 s390/pci: fix iommu bitmap allocation
| * 7252c8b981 perf: Disallow mis-matched inherited group reads
| * 32279bbbd8 USB: serial: option: add Fibocom to DELL custom modem FM101R-GL
| * 1ff2a7fa0c USB: serial: option: add entry for Sierra EM9191 with new firmware
| * eb8f5e40cb USB: serial: option: add Telit LE910C4-WWX 0x1035 composition
| * b43a412aa1 ACPI: irq: Fix incorrect return value in acpi_register_gsi()
| * 3189d2d587 Revert "pinctrl: avoid unsafe code pattern in find_pinctrl()"
| * 690eb3772f mmc: core: Capture correct oemid-bits for eMMC cards
| * 894b678d86 mmc: core: sdio: hold retuning if sdio in 1-bit mode
| * 37ae7c493a mtd: physmap-core: Restore map_rom fallback
| * de28fa5331 mtd: spinand: micron: correct bitmask for ecc status
| * bd68f50684 mtd: rawnand: qcom: Unmap the right resource upon probe failure
| * a787e07755 Bluetooth: hci_event: Fix using memcmp when comparing keys
| * 897d6aee8f HID: multitouch: Add required quirk for Synaptics 0xcd7e device
| * 9cae05233b btrfs: fix some -Wmaybe-uninitialized warnings in ioctl.c
| * 693ecef543 drm: panel-orientation-quirks: Add quirk for One Mix 2S
| * 4030effab8 sky2: Make sure there is at least one frag_addr available
| * 340bb4b716 regulator/core: Revert "fix kobject release warning and memory leak in regulator_register()"
| * d7604e819a wifi: cfg80211: avoid leaking stack data into trace
| * 139234011f wifi: mac80211: allow transmitting EAPOL frames with tainted key
| * b48595f5b1 Bluetooth: hci_core: Fix build warnings
| * 16e36cde27 Bluetooth: Avoid redundant authentication
| * fa83d852e9 HID: holtek: fix slab-out-of-bounds Write in holtek_kbd_input_event
| * 981dfec995 tracing: relax trace_event_eval_update() execution with cond_resched()
| * b5d9f34f38 ata: libata-eh: Fix compilation warning in ata_eh_link_report()
| * 392f597ead gpio: timberdale: Fix potential deadlock on &tgpio->lock
| * 91ae08dc30 overlayfs: set ctime when setting mtime and atime
| * 01a4e9bc63 i2c: mux: Avoid potential false error message in i2c_mux_add_adapter
| * 97cb55f41e btrfs: initialize start_slot in btrfs_log_prealloc_extents
| * a055d9d4dd btrfs: return -EUCLEAN for delayed tree ref with a ref count not equals to 1
| * d65dbb2aa4 ARM: dts: ti: omap: Fix noisy serial with overrun-throttle-ms for mapphone
| * 611c991b9e ACPI: resource: Skip IRQ override on ASUS ExpertBook B1402CBA
| * b2d0649c8e ACPI: resource: Skip IRQ override on ASUS ExpertBook B1502CBA
| * 8c0982fc4b ACPI: resource: Skip IRQ override on Asus Expertbook B2402CBA
| * 0818716a90 ACPI: resource: Add Asus ExpertBook B2502 to Asus quirks
| * c6f7b33586 ACPI: resource: Skip IRQ override on Asus Vivobook S5602ZA
| * b1f5f4720f ACPI: resource: Add ASUS model S5402ZA to quirks
| * fdcd669371 ACPI: resource: Skip IRQ override on Asus Vivobook K3402ZA/K3502ZA
| * cd202a9f88 ACPI: resources: Add DMI-based legacy IRQ override quirk
| * 26b2bc9bdc ACPI: Drop acpi_dev_irqresource_disabled()
| * 583913b1a6 resource: Add irqresource_disabled()
| * d6878d39b6 net: pktgen: Fix interface flags printing
| * cee9ea14c8 netfilter: nft_set_rbtree: .deactivate fails if element has expired
| * 863acae0b8 neighbor: tracing: Move pin6 inside CONFIG_IPV6=y section
| * f34916502d net/sched: sch_hfsc: upgrade 'rt' to 'sc' when it becomes a inner curve
| * b1ad377bba i40e: prevent crash on probe if hw registers have invalid values
| * c813d17660 net: usb: smsc95xx: Fix an error code in smsc95xx_reset()
| * 47419f2aef ipv4: fib: annotate races around nh->nh_saddr_genid and nh->nh_saddr
| * 00a251ea45 tun: prevent negative ifindex
| * 8710dbe09e tcp: tsq: relax tcp_small_queue_check() when rtx queue contains a single skb
| * 1ae2c7d44e tcp: fix excessive TLP and RACK timeouts from HZ rounding
| * eb1a33195a net: rfkill: gpio: prevent value glitch during probe
| * cd44e14573 net: ipv6: fix return value check in esp_remove_trailer
| * 03b88b7d2a net: ipv4: fix return value check in esp_remove_trailer
| * 0cb7b894e4 xfrm: interface: use DEV_STATS_INC()
| * bcacdf4deb xfrm: fix a data-race in xfrm_gen_index()
| * 639e979a7d qed: fix LL2 RX buffer allocation
| * 1cb76fec3e netfilter: nft_payload: fix wrong mac header matching
| * 6b2875b527 KVM: x86: Mask LVTPC when handling a PMI
| * 1d434d8313 regmap: fix NULL deref on lookup
| * 76050b0cc5 nfc: nci: fix possible NULL pointer dereference in send_acknowledge()
| * 80ce32ab9b ice: fix over-shifted variable
| * ec8f0d0fe6 Bluetooth: avoid memcmp() out of bounds warning
| * 1a00e3544b Bluetooth: hci_event: Fix coding style
| * 84598a339b Bluetooth: vhci: Fix race when opening vhci device
| * 1769ac55db Bluetooth: Fix a refcnt underflow problem for hci_conn
| * 97ce8eca07 Bluetooth: Reject connection with the device which has same BD_ADDR
| * 6ce3478336 Bluetooth: hci_event: Ignore NULL link key
| * 6ad3e9fd36 usb: hub: Guard against accesses to uninitialized BOS descriptors
| * 57e83c2445 Documentation: sysctl: align cells in second content column
| * 947cd2fba1 dev_forward_skb: do not scrub skb mark within the same name space
| * 65d34cfd4e ravb: Fix use-after-free issue in ravb_tx_timeout_work()
| * de6e271338 powerpc/64e: Fix wrong test in __ptep_test_and_clear_young()
| * 85ae11da85 powerpc/8xx: Fix pte_access_permitted() for PAGE_NONE
| * 077fdae908 dmaengine: mediatek: Fix deadlock caused by synchronize_irq()
| * 6ea15d9f7a x86/cpu: Fix AMD erratum #1485 on Zen4-based CPUs
| * e7ca00f35d usb: gadget: ncm: Handle decoding of multiple NTB's in unwrap call
| * 1e4414c387 usb: gadget: udc-xilinx: replace memcpy with memcpy_toio
| * 2a433d3255 pinctrl: avoid unsafe code pattern in find_pinctrl()
| * d5b11bd893 cgroup: Remove duplicates in cgroup v1 tasks file
| * 1e59ebed9c Input: xpad - add PXN V900 support
| * 8664fa7fbb Input: psmouse - fix fast_reconnect function for PS/2 mode
| * 5aa514100a Input: powermate - fix use-after-free in powermate_config_complete
| * 3cdce751b0 ceph: fix incorrect revoked caps assert in ceph_fill_file_size()
| * 92cd1635c6 libceph: use kernel_connect()
| * 5704225cdd mcb: remove is_added flag from mcb_device struct
| * 2bf6c93e17 iio: pressure: ms5611: ms5611_prom_is_valid false negative bug
| * 84af249e48 iio: pressure: dps310: Adjust Timeout Settings
| * 00cd9d9c12 iio: pressure: bmp280: Fix NULL pointer exception
| * f4c11b2ea0 usb: musb: Modify the "HWVers" register address
| * fc1ecea726 usb: musb: Get the musb_qh poniter after musb_giveback
| * c0fb0419c1 usb: dwc3: Soft reset phy on probe for host
| * 7efac5b4c2 net: usb: dm9601: fix uninitialized variable use in dm9601_mdio_read
| * 57942b0763 usb: xhci: xhci-ring: Use sysdev for mapping bounce buffer
| * e397100846 dmaengine: stm32-mdma: abort resume if no ongoing transfer
| * 3345799c4f workqueue: Override implicit ordered attribute in workqueue_apply_unbound_cpumask()
| * 95733ea130 nfc: nci: assert requested protocol is valid
| * 7adcf014bd net: nfc: fix races in nfc_llcp_sock_get() and nfc_llcp_sock_get_sn()
| * 22ca282ea0 ixgbe: fix crash with empty VF macvlan list
| * 0cc6c070d9 drm/vmwgfx: fix typo of sizeof argument
| * 80a3c00684 xen-netback: use default TX queue size for vifs
| * 332587dc7f mlxsw: fix mlxsw_sp2_nve_vxlan_learning_set() return type
| * 85c2857ef9 ieee802154: ca8210: Fix a potential UAF in ca8210_probe
| * daff72af3f ravb: Fix up dma_free_coherent() call in ravb_remove()
| * d3d2aecc1f drm/msm/dsi: skip the wait for video mode done if not applicable
| * a0c24f802d drm: etvnaviv: fix bad backport leading to warning
| * 907a380eb3 net: prevent address rewrite in kernel_bind()
| * 061a18239c quota: Fix slow quotaoff
| * cd0e2bf7fb HID: logitech-hidpp: Fix kernel crash on receiver USB disconnect
| * 8e39b5fb83 pwm: hibvt: Explicitly set .polarity in .get_state()
| * c4eff809d6 lib/test_meminit: fix off-by-one error in test_pages()
| * ffdd8f56a4 RDMA/cxgb4: Check skb value for failure to allocate
* |   bbe33b72cc Merge changes I407c2796,If3f36646,Ia03ea493,I5f0e742b,Ibe09c3b1, ... into android11-5.4-lts
|\ \
| * | 6eb76db1fc Revert "netfilter: conntrack: allow sctp hearbeat after connection re-use"
| * | 62bde05901 Revert "netfilter: conntrack: don't refresh sctp entries in closed state"
| * | e6f57200f5 Revert "netfilter: handle the connecting collision properly in nf_conntrack_proto_sctp"
| * | e18c011afe Merge 5.4.258 into android11-5.4-lts
| |\|
| | * 02f78c59a0 Linux 5.4.258
| | * f70c285cf0 xen/events: replace evtchn_rwlock with RCU
| | * e2614ab16a ima: rework CONFIG_IMA dependency block
| | * b5c3bc4b81 NFS: Fix a race in __nfs_list_for_each_server()
| | * f0ea421fa2 parisc: Restore __ldcw_align for PA-RISC 2.0 processors
| | * 14e5d94d5c RDMA/mlx5: Fix NULL string error
| | * 6e26812e28 RDMA/siw: Fix connection failure handling
| | * 8ab1fb16dc RDMA/uverbs: Fix typo of sizeof argument
| | * 26d48f7090 RDMA/cma: Fix truncation compilation warning in make_cma_ports
| | * f102dd8a17 gpio: pxa: disable pinctrl calls for MMP_GPIO
| | * e38aceeadb gpio: aspeed: fix the GPIO number passed to pinctrl_gpio_set_config()
| | * 8584ee20a5 IB/mlx4: Fix the size of a buffer in add_port_entries()
| | * 35b689ee4b RDMA/core: Require admin capabilities to set system parameters
| | * 1047ca5bae cpupower: add Makefile dependencies for install targets
| | * 3c2f536c3d sctp: update hb timer immediately after users change hb_interval
| | * caf0c61f14 sctp: update transport state when processing a dupcook packet
| | * 14fc22c929 tcp: fix delayed ACKs for MSS boundary condition
| | * 2791d64e66 tcp: fix quick-ack counting to count actual ACKs of new data
| | * 7fbce1e46b net: stmmac: dwmac-stm32: fix resume on STM32 MCU
| | * f110aa377d netfilter: handle the connecting collision properly in nf_conntrack_proto_sctp
| | * 191d87a19c net: nfc: llcp: Add lock when modifying device list
| | * 310f1c92f6 net: usb: smsc75xx: Fix uninit-value access in __smsc75xx_read_reg
| | * 8992055210 net: dsa: mv88e6xxx: Avoid EEPROM timeout when EEPROM is absent
| | * 1fc793d68d ipv4, ipv6: Fix handling of transhdrlen in __ip{,6}_append_data()
| | * 95eabb075a net: fix possible store tearing in neigh_periodic_work()
| | * 10a301c83a modpost: add missing else to the "of" check
| | * 5e1c1bf53e NFSv4: Fix a nfs4_state_manager() race
| | * f90821f667 NFS: Add a helper nfs_client_for_each_server()
| | * e2d4fc53e9 NFS4: Trace state recovery operation
| | * c87f66c43c scsi: target: core: Fix deadlock due to recursive locking
| | * 8a1fa738b4 ima: Finish deprecation of IMA_TRUSTED_KEYRING Kconfig
| | * 442e50393a regmap: rbtree: Fix wrong register marked as in-cache when creating new node
| * | 4542148a7e Reapply "netfilter: conntrack: don't refresh sctp entries in closed state"
| * | 7fe1de446b Reapply "netfilter: conntrack: allow sctp hearbeat after connection re-use"
* | |   1891143414 Merge 52008a5e22 ("wifi: mt76: mt76x02: fix MT76x0 external LNA gain handling") into android11-5.4-lts
|\ \ \
| | |/
| |/|
| * | 52008a5e22 wifi: mt76: mt76x02: fix MT76x0 external LNA gain handling
| * | 31b2777690 drivers/net: process the result of hdlc_open() and add call of hdlc_close() in uhdlc_close()
| * | b8e260654a wifi: mwifiex: Fix oob check condition in mwifiex_process_rx_packet
| * | 1b67be400a wifi: iwlwifi: dbg_ini: fix structure packing
| * | c6d3583876 ubi: Refuse attaching if mtd's erasesize is 0
| * | b4ec10b962 net: prevent rewrite of msg_name in sock_sendmsg()
| * | 53b700b41a net: replace calls to sock->ops->connect() with kernel_connect()
* | | 993e3b2df8 Merge 3c4bfa7a56 ("wifi: mwifiex: Fix tlv_buf_left calculation") into android11-5.4-lts
|\| |
| * | 3c4bfa7a56 wifi: mwifiex: Fix tlv_buf_left calculation
| * | 2e608cede0 qed/red_ll2: Fix undefined behavior bug in struct qed_ll2_info
| * | 810248a129 scsi: zfcp: Fix a double put in zfcp_port_enqueue()
| * | e60272ab02 Revert "PCI: qcom: Disable write access to read only registers for IP v2.3.3"
| * | 6e37de4a14 rbd: take header_rwsem in rbd_dev_refresh() only when updating
| * | bc2a304401 rbd: decouple parent info read-in from updating rbd_dev
| * | 2e0114edeb rbd: decouple header read-in from updating rbd_dev->header
| * | 32a59639c5 rbd: move rbd_dev_refresh() definition
* | | 8fb5605ba2 Merge ff10b1fad5 ("fs: binfmt_elf_efpic: fix personality for ELF-FDPIC") into android11-5.4-lts
|\| |
| |/
|/|
| * ff10b1fad5 fs: binfmt_elf_efpic: fix personality for ELF-FDPIC
| * 43e5dc1ee2 ata: libata-sata: increase PMP SRST timeout to 10s
| * ac1aebd4e3 ata: libata-core: Do not register PM operations for SAS ports
| * 9313aab5f6 ata: libata-core: Fix port and device removal
| * 9207666f16 ata: libata-core: Fix ata_port_request_pm() locking
| * d9483f5aec net: thunderbolt: Fix TCPv6 GSO checksum calculation
| * 47062af859 btrfs: properly report 0 avail for very full file systems
* | 8a59cb3011 Reapply "ANDROID: Revert "tracing/ring-buffer: Have polling block on watermark""
* | 574430d8ef Revert "ring-buffer: Update "shortest_full" in polling"
* | 5ca567aeaa Merge cf221a7880 ("ring-buffer: Update "shortest_full" in polling") into android11-5.4-lts
|\|
| * cf221a7880 ring-buffer: Update "shortest_full" in polling
* | fc8b7e30fd Revert "ANDROID: Revert "tracing/ring-buffer: Have polling block on watermark""
* | 74e7ad6a22 Merge ec7b2e7b36 ("i2c: i801: unregister tco_pdev in i801_probe() error path") into android11-5.4-lts
|\|
| * ec7b2e7b36 i2c: i801: unregister tco_pdev in i801_probe() error path
| * a4ecd8562c ata: libata-scsi: ignore reserved bits for REPORT SUPPORTED OPERATION CODES
| * ec1df5d37d ALSA: hda: Disable power save for solving pop issue on Lenovo ThinkCentre M70q
| * 193b5a1c6c nilfs2: fix potential use after free in nilfs_gccache_submit_read_data()
| * bf3c728e36 serial: 8250_port: Check IRQ data before use
| * 76ffbd900b Smack:- Use overlay inode label in smack_inode_copy_up()
| * 957a9916db smack: Retrieve transmuting information in smack_inode_getsecurity()
| * c9ce9bab23 smack: Record transmuting in smk_transmuted
| * d037d8964f i40e: fix return of uninitialized aq_ret in i40e_set_vsi_promisc
| * 2d78e2d3e3 i40e: always propagate error value in i40e_set_vsi_promisc()
| * 8ed4b5d710 i40e: improve locking of mac_filter_hash
| * 30055e020a watchdog: iTCO_wdt: Set NO_REBOOT if the watchdog is not already running
| * c54a392fc7 watchdog: iTCO_wdt: No need to stop the timer in probe
| * d68c61092c nvme-pci: do not set the NUMA node of device if it has none
| * 283f24df83 fbdev/sh7760fb: Depend on FB=y
| * ee1f5c63e9 ncsi: Propagate carrier gain/loss events to the NCSI controller
| * b42eac1462 powerpc/watchpoints: Annotate atomic context in more places
| * 723904ce85 bpf: Clarify error expectations from bpf_clone_redirect
| * db4afbc6c1 spi: nxp-fspi: reset the FLSHxCR1 registers
| * 3502dd8031 ata: libata-eh: do not clear ATA_PFLAG_EH_PENDING in ata_eh_reset()
* | 09125ac12e Merge 05264d6551 ("ring-buffer: Avoid softlockup in ring_buffer_resize()") into android11-5.4-lts
|\|
| * 05264d6551 ring-buffer: Avoid softlockup in ring_buffer_resize()
* | 82d0266c8c Merge 1d28224d49 ("selftests/ftrace: Correctly enable event in instance-event.tc") into android11-5.4-lts
|\|
| * 1d28224d49 selftests/ftrace: Correctly enable event in instance-event.tc
| * ded3551163 parisc: irq: Make irq_stack_union static to avoid sparse warning
| * a721e5788a parisc: drivers: Fix sparse warning
| * 2569e0ceff parisc: iosapic.c: Fix sparse warnings
| * f1a0dd9243 parisc: sba: Fix compile warning wrt list of SBA devices
| * 6db9cdfdc3 gpio: pmic-eic-sprd: Add can_sleep flag for PMIC EIC chip
| * 4a62d23eba xtensa: boot/lib: fix function prototypes
| * e11fa78a37 xtensa: boot: don't add include-dirs
| * 5ed83a0a39 xtensa: iss/network: make functions static
| * b821e6a8b2 xtensa: add default definition for XCHAL_HAVE_DIV32
| * 49dc6fcd4b bus: ti-sysc: Fix SYSC_QUIRK_SWSUP_SIDLE_ACT handling for uart wake-up
| * 841733189b ARM: dts: ti: omap: motorola-mapphone: Fix abe_clkctrl warning on boot
| * 3468fa39d8 clk: tegra: fix error return case for recalc_rate
| * 6938a6cbe6 MIPS: Alchemy: only build mmc support helpers if au1xmmc is enabled
| * 5b0d13e2d9 ata: libata: disallow dev-initiated LPM transitions to unsupported states
| * 617a89ff55 drm/amd/display: prevent potential division by zero errors
| * 07b63a3dcf drm/amd/display: Fix LFC multiplier changing erratically
| * 11e3f781f6 drm/amd/display: Reinstate LFC optimization
* | c5c964fd2f Revert "net: bridge: use DEV_STATS_INC()"
* | f69adcec03 Merge a4628a5b98 ("scsi: qla2xxx: Fix deletion race condition") into android11-5.4-lts
|\|
| * a4628a5b98 scsi: qla2xxx: Fix deletion race condition
| * 0a51c838c5 scsi: qla2xxx: Fix update_fcport for current_topology
| * ecdf4c658b Input: i8042 - add quirk for TUXEDO Gemini 17 Gen1/Clevo PD70PN
| * 0926a2b7cb i2c: mux: demux-pinctrl: check the return value of devm_kstrdup()
| * e09db461f2 gpio: tb10x: Fix an error handling path in tb10x_gpio_probe()
| * 02a233986c netfilter: ipset: Fix race between IPSET_CMD_CREATE and IPSET_CMD_SWAP
| * 812da2a08d net: rds: Fix possible NULL-pointer dereference
| * c5f6478686 team: fix null-ptr-deref when team device type is changed
| * ad8d39c7b4 net: bridge: use DEV_STATS_INC()
| * 121a7c474c net: hns3: add 5ms delay before clear firmware reset irq source
| * a6f4d582e2 dccp: fix dccp_v4_err()/dccp_v6_err() again
| * 16b88d7a14 powerpc/perf/hv-24x7: Update domain value check
| * 810fd23d97 ipv4: fix null-deref in ipv4_link_failure
| * 8f228c326d i40e: Fix VF VLAN offloading when port VLAN is configured
| * 8b835db279 i40e: Fix warning message and call stack during rmmod i40e driver
| * 9cbec71a57 i40e: Remove scheduling while atomic possibility
| * 0988fc499f i40e: Fix for persistent lldp support
| * 09475d6476 ASoC: imx-audmix: Fix return error with devm_clk_get()
| * ca1d4e3c4d selftests: tls: swap the TX and RX sockets in some tests
| * b9eb384fd4 selftests/tls: Add {} to avoid static checker warning
| * 40e34ea017 bpf: Avoid deadlock when using queue and stack maps from NMI
| * eec981349b netfilter: nf_tables: disallow element removal on anonymous sets
* | d8ca210978 Merge d2a6844be5 ("ASoC: meson: spdifin: start hw on dai probe") into android11-5.4-lts
|\|
| * d2a6844be5 ASoC: meson: spdifin: start hw on dai probe
| * 0c908e1595 ext4: do not let fstrim block system suspend
| * 4db34feaf2 ext4: move setting of trimmed bit into ext4_try_to_trim_range()
| * 767a50bef2 ext4: replace the traditional ternary conditional operator with with max()/min()
| * 2fd502f53b ext4: mark group as trimmed only if it was fully scanned
| * 635901bdbd ext4: change s_last_trim_minblks type to unsigned long
| * 2d87415158 ext4: scope ret locally in ext4_try_to_trim_range()
| * c71cb46aff ext4: add new helper interface ext4_try_to_trim_range()
| * b0dcbd4bb9 ext4: remove the 'group' parameter of ext4_trim_extent
| * bf06607565 ata: libahci: clear pending interrupt status
| * e6807c873d tracing: Increase trace array ref count on enable and filter files
| * 7d3f6612e9 SUNRPC: Mark the cred for revalidation if the server rejects it
| * 321c75b01c NFS/pNFS: Report EINVAL errors from connect() to the server
* | 432ea675f2 Merge android11-5.4 branch into android11-5.4-lts branch
* | 8a932792da FROMLIST: lib/test_meminit: fix off-by-one error in test_pages()
* | 5000f4d84d Revert "drm/panel: simple: Add missing connector type and pixel format for AUO T215HVN01"
* | 50de6be756 Revert "usb: typec: bus: verify partner exists in typec_altmode_attention"
* | 13c2fe5c0a Revert "fs/nls: make load_nls() take a const parameter"
* | 4d59a2c9b9 Revert "ip_tunnels: use DEV_STATS_INC()"
* | 2b44f56202 Merge 5.4.257 into android11-5.4-lts
|\|
| * a140610d8a Linux 5.4.257
| * 42900fd140 net/sched: Retire rsvp classifier
| * b3637835ac drm/amdgpu: fix amdgpu_cs_p1_user_fence
| * 650ebbba5c mtd: rawnand: brcmnand: Fix ECC level field setting for v7.2 controller
| * b1ef1f2f37 ext4: fix rec_len verify error
| * e4efb0aaf2 scsi: megaraid_sas: Fix deadlock on firmware crashdump
| * 44654114fb i2c: aspeed: Reset the i2c controller when timeout occurs
| * ce47fe53f7 tracefs: Add missing lockdown check to tracefs_create_dir()
| * b6c042d4ac nfsd: fix change_info in NFSv4 RENAME replies
| * 952e477f90 tracing: Have option files inc the trace array ref count
| * ff8cf370d3 tracing: Have current_trace inc the trace array ref count
| * a70c6e5731 btrfs: fix lockdep splat and potential deadlock after failure running delayed items
| * 8e8dcc0f15 attr: block mode changes of symlinks
| * a8403f9fd4 md/raid1: fix error: ISO C90 forbids mixed declarations
| * 349640248b selftests: tracing: Fix to unmount tracefs for recovering environment
| * 5b50c95cf8 btrfs: compare the correct fsid/metadata_uuid in btrfs_validate_super
| * b61aad18b3 btrfs: add a helper to read the superblock metadata_uuid
| * bd0fe54891 btrfs: move btrfs_pinned_by_swapfile prototype into volumes.h
| * a04cce3e79 perf tools: Add an option to build without libbfd
| * f3701ef61f perf jevents: Make build dependency on test JSONs
| * a12e9ba7f3 tools features: Add feature test to check if libbfd has buildid support
| * 964e025cee kobject: Add sanity check for kset->kobj.ktype in kset_register()
| * 545d1070ed media: pci: ipu3-cio2: Initialise timing struct to avoid a compiler warning
| * 44d72e9edd serial: cpm_uart: Avoid suspicious locking
| * 2cbe6a88fb scsi: target: iscsi: Fix buffer overflow in lio_target_nacl_info_show()
| * 9cd6b3802d usb: gadget: fsl_qe_udc: validate endpoint index for ch9 udc
| * abe0cd279a media: pci: cx23885: replace BUG with error return
| * 641e602239 media: tuners: qt1010: replace BUG_ON with a regular error
| * 991c77fe18 media: az6007: Fix null-ptr-deref in az6007_i2c_xfer()
| * 8dc5b37025 media: anysee: fix null-ptr-deref in anysee_master_xfer
| * 0c02eb70b1 media: af9005: Fix null-ptr-deref in af9005_i2c_xfer
| * beb9550494 media: dw2102: Fix null-ptr-deref in dw2102_i2c_transfer()
| * b49c6e5dd2 media: dvb-usb-v2: af9035: Fix null-ptr-deref in af9035_i2c_master_xfer
| * 7ffe14fce7 powerpc/pseries: fix possible memory leak in ibmebus_bus_init()
| * 5873df0195 jfs: fix invalid free of JFS_IP(ipimap)->i_imap in diUnmount
| * b12ccbfdf6 fs/jfs: prevent double-free in dbUnmount() after failed jfs_remount()
| * a7fde3d46a ext2: fix datatype of block number in ext2_xattr_set2()
| * 25a68f2286 md: raid1: fix potential OOB in raid1_remove_disk()
| * 77918680ab bus: ti-sysc: Configure uart quirks for k3 SoC
| * 279e32b79d drm/exynos: fix a possible null-pointer dereference due to data race in exynos_drm_crtc_atomic_disable()
| * 3beb97bed8 wifi: mac80211_hwsim: drop short frames
| * 6773ea9982 alx: fix OOB-read compiler warning
| * fd1a177d2c mmc: sdhci-esdhc-imx: improve ESDHC_FLAG_ERR010450
| * ff75c853b7 tpm_tis: Resend command to recover from data transfer errors
| * 61f5453e97 crypto: lib/mpi - avoid null pointer deref in mpi_cmp_ui()
| * d1473fc030 wifi: mwifiex: fix fortify warning
| * 38eb4ef67f wifi: ath9k: fix printk specifier
| * 93f4a0b744 devlink: remove reload failed checks in params get/set callbacks
| * aadb178c51 hw_breakpoint: fix single-stepping when using bpf_overflow_handler
| * cb37e7fa23 perf/smmuv3: Enable HiSilicon Erratum 162001900 quirk for HIP08/09
| * 4de282f491 ACPI: video: Add backlight=native DMI quirk for Lenovo Ideapad Z470
| * d0a13c395e kernel/fork: beware of __put_task_struct() calling context
| * 3bf4463e40 ACPICA: Add AML_NO_OPERAND_RESOLVE flag to Timer
| * 117fb80cd1 locks: fix KASAN: use-after-free in trace_event_raw_event_filelock_lock
| * 7afbfde45d btrfs: output extra debug info if we failed to find an inline backref
| * 6079dc77c6 autofs: fix memory leak of waitqueues in autofs_catatonic_mode
| * 8c027a5798 parisc: Drop loops_per_jiffy from per_cpu struct
| * 4316b82945 drm/amd/display: Fix a bug when searching for insert_above_mpcc
| * 1ce8362b4a kcm: Fix error handling for SOCK_DGRAM in kcm_sendmsg().
| * b5fc6fd660 ixgbe: fix timestamp configuration code
| * f9f3ce7719 net/tls: do not free tls_rec on async operation in bpf_exec_tx_verdict()
| * 08d36f317c platform/mellanox: mlxbf-tmfifo: Drop jumbo frames
| * 0507815ae9 mlxbf-tmfifo: sparse tags for config access
| * 7efc9e97f6 platform/mellanox: mlxbf-tmfifo: Drop the Rx packet if no more descriptors
| * 479c71cda1 kcm: Fix memory leak in error path of kcm_sendmsg()
| * c565533407 r8152: check budget for r8152_poll()
| * 653fbddbdf net: ethernet: mtk_eth_soc: fix possible NULL pointer dereference in mtk_hwlro_get_fdir_all()
| * ba6673824e net: ethernet: mvpp2_main: fix possible OOB write in mvpp2_ethtool_get_rxnfc()
| * 5624f26a35 net: ipv4: fix one memleak in __inet_del_ifa()
| * e757ca9c1c clk: imx8mm: Move 1443X/1416X PLL clock structure to common place
| * 75e0bd9761 ARM: dts: BCM5301X: Extend RAM to full 256MB for Linksys EA6500 V2
| * 5f71716772 usb: typec: bus: verify partner exists in typec_altmode_attention
| * 14fe0f8627 usb: typec: tcpm: Refactor tcpm_handle_vdm_request
| * 979f8743f3 usb: typec: tcpm: Refactor tcpm_handle_vdm_request payload handling
| * 6ca8e31480 perf tools: Handle old data in PERF_RECORD_ATTR
| * dffa46d0ca perf hists browser: Fix hierarchy mode header
| * 6095dd2821 mtd: rawnand: brcmnand: Fix potential false time out warning
| * aae45746f4 mtd: rawnand: brcmnand: Fix potential out-of-bounds access in oob write
| * 09417fbf12 mtd: rawnand: brcmnand: Fix crash during the panic_write
| * aa64f6f0ce btrfs: use the correct superblock to compare fsid in btrfs_validate_super
| * 6eb1fc314c btrfs: don't start transaction when joining with TRANS_JOIN_NOSTART
| * b0d236e3af fuse: nlookup missing decrement in fuse_direntplus_link
| * 0e918d7c00 ata: pata_ftide010: Add missing MODULE_DESCRIPTION
| * e03ac17734 ata: sata_gemini: Add missing MODULE_DESCRIPTION
| * 118db787ba sh: boards: Fix CEU buffer size passed to dma_declare_coherent_memory()
| * 89099d73b2 net: hns3: fix the port information display when sfp is absent
| * a44602888b netfilter: nfnetlink_osf: avoid OOB read
| * 62c363e604 ip_tunnels: use DEV_STATS_INC()
| * a5dffc1203 idr: fix param name in idr_alloc_cyclic() doc
| * 6b0cb9c055 s390/zcrypt: don't leak memory if dev_set_name() fails
| * c149b61301 igb: Change IGB_MIN to allow set rx/tx value between 64 and 80
| * 4a5defbfe8 igbvf: Change IGBVF_MIN to allow set rx/tx value between 64 and 80
| * c805b87414 igc: Change IGC_MIN to allow set rx/tx value between 64 and 80
| * 8047a48984 kcm: Destroy mutex in kcm_exit_net()
| * a6d11571b9 net: sched: sch_qfq: Fix UAF in qfq_dequeue()
| * f1ba9a03b1 af_unix: Fix data race around sk->sk_err.
| * 1ffed3ea87 af_unix: Fix data-races around sk->sk_shutdown.
| * 5d91b7891f af_unix: Fix data-race around unix_tot_inflight.
| * adcf4e0693 af_unix: Fix data-races around user->unix_inflight.
| * e13db62db9 net: ipv6/addrconf: avoid integer underflow in ipv6_create_tempaddr
| * 23b4b1a069 veth: Fixing transmit return status for dropped packets
| * 0133bc2897 igb: disable virtualization features on 82580
| * 41f10a4d78 net: read sk->sk_family once in sk_mc_loop()
| * cd12efc54f ipv4: annotate data-races around fi->fib_dead
| * 01585fa326 sctp: annotate data-races around sk->sk_wmem_queued
| * 04301da4d8 pwm: lpc32xx: Remove handling of PWM channels
| * 565f7bb0b3 watchdog: intel-mid_wdt: add MODULE_ALIAS() to allow auto-load
| * 7a0e41223e perf top: Don't pass an ERR_PTR() directly to perf_session__delete()
| * c5be10f1bf x86/virt: Drop unnecessary check on extended CPUID level in cpu_has_svm()
| * 1d0cc1a9c4 perf annotate bpf: Don't enclose non-debug code with an assert()
| * c7cc4dc247 kconfig: fix possible buffer overflow
| * 0158dab8e8 NFSv4/pnfs: minor fix for cleanup path in nfs4_get_device_info
| * 64c5e916fa soc: qcom: qmi_encdec: Restrict string length in decode
| * 5c7608d976 clk: qcom: gcc-mdm9615: use proper parent for pll0_vote clock
| * b88626c472 parisc: led: Reduce CPU overhead for disk & lan LED computation
| * 536f309225 parisc: led: Fix LAN receive and transmit LEDs
| * cbfffe5122 lib/test_meminit: allocate pages up to order MAX_ORDER
| * 9b7f6e5009 drm/ast: Fix DRAM init on AST2200
| * 8ffa40ff64 fbdev/ep93xx-fb: Do not assign to struct fb_info.dev
| * 6d5eb57a02 scsi: qla2xxx: Remove unsupported ql2xenabledif option
| * e24bc58113 scsi: qla2xxx: Turn off noisy message log
| * 05935f9106 scsi: qla2xxx: Fix erroneous link up failure
| * 61641000ad scsi: qla2xxx: fix inconsistent TMF timeout
| * f966dc8c2d net/ipv6: SKB symmetric hash should incorporate transport ports
| * d31331e2df drm: fix double free for gbo in drm_gem_vram_init and drm_gem_vram_create
| * 34eb4bd915 udf: initialize newblock to 0
| * 206d2b7baf usb: typec: tcpci: clear the fault status bit
| * 8244218681 serial: sc16is7xx: fix broken port 0 uart init
| * 159bc8c6b5 sc16is7xx: Set iobase to device index
| * 355ac79584 cpufreq: brcmstb-avs-cpufreq: Fix -Warray-bounds bug
| * 5e7d0acc69 crypto: stm32 - fix loop iterating through scatterlist for DMA
| * 306e356d58 s390/ipl: add missing secure/has_secure file to ipl type 'unknown'
| * e972231db2 pstore/ram: Check start of empty przs during init
| * b6c9d04019 fsverity: skip PKCS#7 parser when keyring is empty
| * 712491c9ab net: handle ARPHRD_PPP in dev_is_mac_header_xmit()
| * 15b3727108 X.509: if signature is unsupported skip validation
| * 7a7dd70cb9 dccp: Fix out of bounds access in DCCP error handler
| * 1c675c937c dlm: fix plock lookup when using multiple lockspaces
| * 8cd1c5cec6 parisc: Fix /proc/cpuinfo output for lscpu
| * 0337bb53cb procfs: block chmod on /proc/thread-self/comm
| * 2e1f12ce0d Revert "PCI: Mark NVIDIA T4 GPUs to avoid bus reset"
| * eb1fa4819d ntb: Fix calculation ntb_transport_tx_free_entry()
| * b2a6a169c2 ntb: Clean up tx tail index on link down
| * 94491412a2 ntb: Drop packets when qp link is down
| * ff3bb51e21 media: dvb: symbol fixup for dvb_attach()
| * b047ac1528 xtensa: PMU: fix base address for the newer hardware
| * 2791a2a69a backlight/lv5207lp: Compare against struct fb_info.device
| * bc86f29e12 backlight/bd6107: Compare against struct fb_info.device
| * 3dd8ff5695 backlight/gpio_backlight: Compare against struct fb_info.device
| * c2e1ce4fa4 ARM: OMAP2+: Fix -Warray-bounds warning in _pwrdm_state_switch()
| * f53ab5a2bf ipmi_si: fix a memleak in try_smi_init()
| * e7f97980f7 ALSA: pcm: Fix missing fixup call in compat hw_refine ioctl
| * 29811f4b82 PM / devfreq: Fix leak in devfreq_dev_release()
| * c2ad60ed38 igb: set max size RX buffer when store bad packet is enabled
| * d44403ec06 skbuff: skb_segment, Call zero copy functions before using skbuff frags
| * 64831fb6a2 netfilter: xt_sctp: validate the flag_info count
| * 28ce8495b5 netfilter: xt_u32: validate user space input
| * 109e830585 netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet.c
| * 3d54e99499 igmp: limit igmpv3_newpack() packet size to IP_MAX_MTU
| * ec6ad9d99e virtio_ring: fix avail_wrap_counter in virtqueue_add_packed
| * 12fcca2ee4 cpufreq: Fix the race condition while updating the transition_task of policy
| * fe5dd39501 dmaengine: ste_dma40: Add missing IRQ check in d40_probe
| * e0f2d85ea3 um: Fix hostaudio build errors
| * 88d508faf3 mtd: rawnand: fsmc: handle clk prepare error in fsmc_nand_resume()
| * efa7f31669 rpmsg: glink: Add check for kstrdup
| * d2473df751 phy/rockchip: inno-hdmi: do not power on rk3328 post pll on reg write
| * f36a06988c phy/rockchip: inno-hdmi: round fractal pixclock in rk3328 recalc_rate
| * b0d5d77b14 phy/rockchip: inno-hdmi: use correct vco_div_5 macro on rk3328
| * 90e037cabc tracing: Fix race issue between cpu buffer write and swap
| * ac78921ec2 x86/speculation: Mark all Skylake CPUs as vulnerable to GDS
| * df7ca43fe0 HID: multitouch: Correct devm device reference for hidinput input_dev name
| * cf48a7ba5c HID: logitech-dj: Fix error handling in logi_dj_recv_switch_to_dj_mode()
| * 011daffb53 RDMA/siw: Correct wrong debug message
| * 35a78898cd RDMA/siw: Balance the reference of cep->kref in the error path
| * 9b6296861a Revert "IB/isert: Fix incorrect release of isert connection"
| * 03db4fe791 amba: bus: fix refcount leak
| * 93a4aefa57 serial: tegra: handle clk prepare error in tegra_uart_hw_init()
| * d2bf25674c scsi: fcoe: Fix potential deadlock on &fip->ctlr_lock
| * b1e3199bad scsi: core: Use 32-bit hostnum in scsi_host_lookup()
| * 103b41e972 media: ov2680: Fix regulators being left enabled on ov2680_power_on() errors
| * 009b1202a0 media: ov2680: Fix vflip / hflip set functions
| * 560624cf1d media: ov2680: Fix ov2680_bayer_order()
| * 218b60bc06 media: ov2680: Remove auto-gain and auto-exposure controls
| * 768d4d230c media: i2c: ov2680: Set V4L2_CTRL_FLAG_MODIFY_LAYOUT on flips
| * c04ae531ee media: ov5640: Enable MIPI interface in ov5640_set_power_mipi()
| * 916219c523 media: i2c: ov5640: Configure HVP lines in s_power callback
| * 93c518d286 USB: gadget: f_mass_storage: Fix unused variable warning
| * 0d8c677098 media: go7007: Remove redundant if statement
| * 38269b9ec8 iommu/vt-d: Fix to flush cache of PASID directory table
| * a94aaffe92 IB/uverbs: Fix an potential error pointer dereference
| * c3a6798538 driver core: test_async: fix an error code
| * 27a218419c dma-buf/sync_file: Fix docs syntax
| * c9e6c1fefc coresight: tmc: Explicit type conversions to prevent integer overflow
| * 463934ca5d scsi: qedf: Do not touch __user pointer in qedf_dbg_fp_int_cmd_read() directly
| * 668ce8d508 scsi: qedf: Do not touch __user pointer in qedf_dbg_debug_cmd_read() directly
| * 06a2dde58f scsi: qedf: Do not touch __user pointer in qedf_dbg_stop_io_on_error_cmd_read() directly
| * e26d521286 x86/APM: drop the duplicate APM_MINOR_DEV macro
| * c65be6ad55 serial: sprd: Fix DMA buffer leak issue
| * 730d1b7ec9 serial: sprd: Assign sprd_port after initialized to avoid wrong access
| * dff8066579 serial: sprd: remove redundant sprd_port cleanup
| * a7d80271a1 serial: sprd: getting port index via serial aliases only
| * 47f3be62ea scsi: qla4xxx: Add length check when parsing nlattrs
| * bc66e701ca scsi: be2iscsi: Add length check when parsing nlattrs
| * 161d4509dd scsi: iscsi: Add strlen() check in iscsi_if_set{_host}_param()
| * bc4fbf2dab usb: phy: mxs: fix getting wrong state with mxs_phy_is_otg_host()
| * de4345fe43 media: mediatek: vcodec: Return NULL if no vdec_fb is found
| * 02c0ea731f media: cx24120: Add retval check for cx24120_message_send()
| * 75d6ef197c media: dvb-usb: m920x: Fix a potential memory leak in m920x_i2c_xfer()
| * 74697b4176 media: dib7000p: Fix potential division by zero
| * afd90d353f drivers: usb: smsusb: fix error handling code in smsusb_init_device
| * 4bc5ffaf8a media: v4l2-core: Fix a potential resource leak in v4l2_fwnode_parse_link()
| * 008b334af8 media: v4l2-fwnode: simplify v4l2_fwnode_parse_link
| * 064e156e9f media: v4l2-fwnode: fix v4l2_fwnode_parse_link handling
| * 7a9619e38c NFS: Guard against READDIR loop when entry names exceed MAXNAMELEN
| * 16282aeca4 NFSD: da_addr_body field missing in some GETDEVICEINFO replies
| * 93a14ab675 fs: lockd: avoid possible wrong NULL parameter
| * d3351799be jfs: validate max amount of blocks before allocation.
| * 65bf8a196b powerpc/iommu: Fix notifiers being shared by PCI and VIO buses
| * 650803f93d nfs/blocklayout: Use the passed in gfp flags
| * 68ba08ab40 wifi: ath10k: Use RMW accessors for changing LNKCTL
| * ab28c56192 drm/radeon: Use RMW accessors for changing LNKCTL
| * d835a13232 drm/radeon: Prefer pcie_capability_read_word()
| * 06c0c15ab0 drm/radeon: Replace numbers with PCI_EXP_LNKCTL2 definitions
| * 30e633dbcd drm/radeon: Correct Transmit Margin masks
| * 108ce391d6 drm/amdgpu: Use RMW accessors for changing LNKCTL
| * 7085f1aab1 drm/amdgpu: Prefer pcie_capability_read_word()
| * 62a1c1bd45 drm/amdgpu: Replace numbers with PCI_EXP_LNKCTL2 definitions
| * adf810206c drm/amdgpu: Correct Transmit Margin masks
| * 7f9129b66c PCI: Add #defines for Enter Compliance, Transmit Margin
| * 81d1de3b97 powerpc/fadump: reset dump area size if fadump memory reserve fails
| * 7159a27b1a clk: imx: composite-8m: fix clock pauses when set_rate would be a no-op
| * 044ff5356a PCI/ASPM: Use RMW accessors for changing LNKCTL
| * 73d73556ed PCI: pciehp: Use RMW accessors for changing LNKCTL
| * e7e3268ae9 PCI: Mark NVIDIA T4 GPUs to avoid bus reset
| * a611e38d5b clk: sunxi-ng: Modify mismatched function name
| * 9ad9cca12b drivers: clk: keystone: Fix parameter judgment in _of_pll_clk_init()
| * de677f4379 ipmi:ssif: Fix a memory leak when scanning for an adapter
| * ef0d286989 ipmi:ssif: Add check for kstrdup
| * 90fddb8789 ALSA: ac97: Fix possible error value of *rac97
| * 0b1e48e4dc of: unittest: Fix overlay type in apply/revert check
| * 0a6f39488c drm/mediatek: Fix potential memory leak if vmap() fail
| * f6364fa751 audit: fix possible soft lockup in __audit_inode_child()
| * 43f0c2bb16 smackfs: Prevent underflow in smk_set_cipso()
| * b8a61df6f4 drm/msm/mdp5: Don't leak some plane state
| * 1f3d0e65d1 ima: Remove deprecated IMA_TRUSTED_KEYRING Kconfig
| * dbdc828991 drm/panel: simple: Add missing connector type and pixel format for AUO T215HVN01
| * 4db0a85cf8 drm/armada: Fix off-by-one error in armada_overlay_get_property()
| * dadf0d0dfc of: unittest: fix null pointer dereferencing in of_unittest_find_node_by_name()
| * def1fd88ae drm/tegra: dpaux: Fix incorrect return value of platform_get_irq
| * c1ff601e1a drm/tegra: Remove superfluous error messages around platform_get_irq()
| * 1603f08620 md/md-bitmap: hold 'reconfig_mutex' in backlog_store()
| * 630be0110e md/bitmap: don't set max_write_behind if there is no write mostly device
| * a8f8c4e728 drm/amdgpu: Update min() to min_t() in 'amdgpu_info_ioctl'
| * c6b423ab65 arm64: dts: qcom: sdm845: Add missing RPMh power domain to GCC
| * 69d9fb3948 ARM: dts: BCM53573: Fix Ethernet info for Luxul devices
| * e6fc20a542 drm: adv7511: Fix low refresh rate register for ADV7533/5
| * 88d32b9ad2 ARM: dts: samsung: s5pv210-smdkv210: correct ethernet reg addresses (split)
| * dfe36c23ab ARM: dts: s5pv210: add dummy 5V regulator for backlight on SMDKv210
| * febead0030 ARM: dts: s5pv210: correct ethernet unit address in SMDKV210
| * 00b3f8004b ARM: dts: s5pv210: use defines for IRQ flags in SMDKV210
| * 9dff1deb25 ARM: dts: s5pv210: add RTC 32 KHz clock in SMDKV210
| * df9929c61c ARM: dts: samsung: s3c6410-mini6410: correct ethernet reg addresses (split)
| * c20456c2cd ARM: dts: s3c64xx: align pinctrl with dtschema
| * a355d140eb ARM: dts: s3c6410: align node SROM bus node name with dtschema in Mini6410
| * e5deee40fa ARM: dts: s3c6410: move fixed clocks under root node in Mini6410
| * d38b67da15 drm/etnaviv: fix dumping of active MMU context
| * 5b8c8527a2 ARM: dts: BCM53573: Use updated "spi-gpio" binding properties
| * 5680c01363 ARM: dts: BCM53573: Add cells sizes to PCIe node
| * 17a5848bdc ARM: dts: BCM53573: Drop nonexistent "default-off" LED trigger
| * c01cbe6c03 drm/amdgpu: avoid integer overflow warning in amdgpu_device_resize_fb_bar()
| * d40c192e11 quota: fix dqput() to follow the guarantees dquot_srcu should provide
| * dd918952b1 quota: add new helper dquot_active()
| * 88c0cdfe10 quota: rename dquot_active() to inode_quota_active()
| * 29d7249bb6 quota: factor out dquot_write_dquot()
| * f2f64c2951 quota: avoid increasing DQST_LOOKUPS when iterating over dirty/inuse list
| * 1e4f7ce32a drm/bridge: tc358764: Fix debug print parameter order
| * 835f0a848a netrom: Deny concurrent connect().
| * da13749d5f net/sched: sch_hfsc: Ensure inner classes have fsc curve
| * 83382eafc7 mlxsw: i2c: Limit single transaction buffer size
| * b2d7f0f313 mlxsw: i2c: Fix chunk size setting in output mailbox buffer
| * 400ef5f79c net: arcnet: Do not call kfree_skb() under local_irq_disable()
| * f306bbdce6 wifi: ath9k: use IS_ERR() with debugfs_create_dir()
| * 231086e6a3 wifi: mwifiex: avoid possible NULL skb pointer dereference
| * 5f6f00bcf9 wifi: ath9k: protect WMI command response buffer replacement with a lock
| * ff703b5f3f wifi: ath9k: fix races between ath9k_wmi_cmd and ath9k_wmi_ctrl_rx
| * df1753eae7 wifi: mwifiex: Fix missed return in oob checks failed path
| * 8f717752f9 wifi: mwifiex: fix memory leak in mwifiex_histogram_read()
| * ab4810042c fs: ocfs2: namei: check return value of ocfs2_add_entry()
| * dbe64279ae lwt: Check LWTUNNEL_XMIT_CONTINUE strictly
| * 67f8f2bae8 lwt: Fix return values of BPF xmit ops
| * 12bf7d9cc6 hwrng: iproc-rng200 - Implement suspend and resume calls
| * 4f1ca8e397 hwrng: iproc-rng200 - use semicolons rather than commas to separate statements
| * 6c015ebce1 crypto: caam - fix unchecked return value error
| * ec348676c7 Bluetooth: nokia: fix value check in nokia_bluetooth_serdev_probe()
| * 0ce06035ea crypto: stm32 - Properly handle pm_runtime_get failing
| * 34de9f1d63 wifi: mwifiex: fix error recovery in PCIE buffer descriptor management
| * 87f8c54423 mwifiex: switch from 'pci_' to 'dma_' API
| * 29eca8b786 wifi: mwifiex: Fix OOB and integer underflow when rx packets
| * 042aeb45e4 can: gs_usb: gs_usb_receive_bulk_callback(): count RX overflow errors also in case of OOM
| * 516f21f210 spi: tegra20-sflash: fix to check return value of platform_get_irq() in tegra_sflash_probe()
| * 4fb6fcc04a regmap: rbtree: Use alloc_flags for memory allocations
| * 57935355dc tcp: tcp_enter_quickack_mode() should be static
| * 75b8b5b529 bpf: Clear the probe_addr for uprobe
| * a0fa690894 cpufreq: powernow-k8: Use related_cpus instead of cpus in driver.exit()
| * 991b7c2604 perf/imx_ddr: don't enable counter0 if none of 4 counters are used
| * 07415be140 x86/decompressor: Don't rely on upper 32 bits of GPRs being preserved
| * 6dbac48ea3 x86/boot: Annotate local functions
| * c418814fae x86/asm: Make more symbols local
| * 3eb241e47d OPP: Fix passing 0 to PTR_ERR in _opp_attach_genpd()
| * 5d3975e36c tmpfs: verify {g,u}id mount options correctly
| * 48c54877ce fs: Fix error checking for d_hash_and_lookup()
| * 0c8c205381 new helper: lookup_positive_unlocked()
| * 0a2b1eb8a9 eventfd: prevent underflow for eventfd semaphores
| * 3e9617d63e eventfd: Export eventfd_ctx_do_read()
| * f59ff66698 reiserfs: Check the return value from __getblk()
| * e74903b5fb Revert "net: macsec: preserve ingress frame ordering"
| * b36c4a731a udf: Handle error when adding extent to a file
| * 7648ea9896 udf: Check consistency of Space Bitmap Descriptor
| * 3e2265cda1 powerpc/32s: Fix assembler warning about r0
| * aea73dde71 net: Avoid address overwrite in kernel_connect
| * d7d42f1142 platform/mellanox: Fix mlxbf-tmfifo not handling all virtio CONSOLE notifications
| * 6614af25e1 ALSA: seq: oss: Fix racy open/close of MIDI devices
| * 601dc776a0 scsi: storvsc: Always set no_report_opcodes
| * 107f5cad23 cifs: add a warning when the in-flight count goes negative
| * f31618e4fc sctp: handle invalid error codes without calling BUG()
| * 8d7395d0ea bnx2x: fix page fault following EEH recovery
| * c1ce2f0957 netlabel: fix shift wrapping bug in netlbl_catmap_setlong()
| * 499eb477f7 scsi: qedi: Fix potential deadlock on &qedi_percpu->p_work_lock
| * d0189e40c2 idmaengine: make FSL_EDMA and INTEL_IDMA64 depends on HAS_IOMEM
| * 617d1d0e17 net: usb: qmi_wwan: add Quectel EM05GV2
| * 5d2481bc92 clk: fixed-mmio: make COMMON_CLK_FIXED_MMIO depend on HAS_IOMEM
| * 3899c1d158 security: keys: perform capable check only on privileged operations
| * 97ed1be29b platform/x86: huawei-wmi: Silence ambient light sensor
| * 762c352dfc platform/x86: intel: hid: Always call BTNL ACPI method
| * 0e3f0e5597 ASoC: atmel: Fix the 8K sample parameter in I2SC master
| * 0b718d1d57 ASoc: codecs: ES8316: Fix DMIC config
| * b796adfc98 fs/nls: make load_nls() take a const parameter
| * 35a9b057bf s390/dasd: fix hanging device after request requeue
| * d7768b33d0 s390/dasd: use correct number of retries for ERP requests
| * a21ff228f0 m68k: Fix invalid .section syntax
| * 4dfc0d1eda vxlan: generalize vxlan_parse_gpe_hdr and remove unused args
| * d65c5ef975 ethernet: atheros: fix return value check in atl1c_tso_csum()
| * ea95a01114 ASoC: da7219: Check for failure reading AAD IRQ events
| * 216953c3de ASoC: da7219: Flush pending AAD IRQ when suspending
| * b6f827c3f8 9p: virtio: make sure 'offs' is initialized in zc_request
| * b6fefef07d pinctrl: amd: Don't show `Invalid config param` errors
| * 99a73016a5 nilfs2: fix WARNING in mark_buffer_dirty due to discarded buffer reuse
| * 724474dfaa nilfs2: fix general protection fault in nilfs_lookup_dirty_data_buffers()
| * efe8244ba9 fsi: master-ast-cf: Add MODULE_FIRMWARE macro
| * 6b701dab19 firmware: stratix10-svc: Fix an NULL vs IS_ERR() bug in probe
| * bee7f3a494 serial: sc16is7xx: fix bug when first setting GPIO direction
| * a6650d27ab Bluetooth: btsdio: fix use after free bug in btsdio_remove due to race condition
| * 5876cae6d6 staging: rtl8712: fix race condition
| * a17c6efa14 HID: wacom: remove the battery when the EKR is off
| * e4f5ad7b53 USB: serial: option: add FOXCONN T99W368/T99W373 product
| * 837f6647b2 USB: serial: option: add Quectel EM05G variant (0x030e)
| * 1d24328048 modules: only allow symbol_get of EXPORT_SYMBOL_GPL modules
| * 6938ef59e3 rtc: ds1685: use EXPORT_SYMBOL_GPL for ds1685_rtc_poweroff
| * 0e0914f9a8 net: enetc: use EXPORT_SYMBOL_GPL for enetc_phc_index
| * 6b39bd898b mmc: au1xmmc: force non-modular build and remove symbol_get usage
| * 7a67c5d932 ARM: pxa: remove use of symbol_get()
| * e83f5d13cb erofs: ensure that the post-EOF tails are all zeroed
* | ab08e05dca Merge 5.4.256 into android11-5.4-lts
|\|
| * 0c2544add9 Linux 5.4.256
| * 1ba96e65ef Revert "MIPS: Alchemy: fix dbdma2"
| * 94aef0fe5a powerpc/pmac/smp: Drop unnecessary volatile qualifier
| * b29a10fd07 powerpc/pmac/smp: Avoid unused-variable warnings
* | 1becc9d04d Revert "drm/display/dp: Fix the DP DSC Receiver cap size"
* | 201ea79b6f Revert "macsec: Fix traffic counters/statistics"
* | bcdfbf8d8d Revert "macsec: use DEV_STATS_INC()"
* | 8e2d221d14 ANDROID: GKI: add back pm_runtime_get_if_in_use()
* | 933d3af2e3 Revert "interconnect: Add helpers for enabling/disabling a path"
* | 9caf727a6d Revert "interconnect: Do not skip aggregation for disabled paths"
* | 1abd0630e0 Revert "ALSA: pcm: Set per-card upper limit of PCM buffer allocations"
* | c648a16974 Revert "ALSA: pcm: Use SG-buffer only when direct DMA is available"
* | bd7fae9e3e Revert "ALSA: pcm: Fix potential data race at PCM memory allocation helpers"
* | cebc239dda Revert "ALSA: pcm: Fix build error on m68k and others"
* | 639cd43433 Revert "Revert "ALSA: pcm: Use SG-buffer only when direct DMA is available""
* | 3a3afa870a Revert "ALSA: pcm: Check for null pointer of pointer substream before dereferencing it"
* | ef75d6901c Merge 5.4.255 into android11-5.4-stable
|/
* 5eb967dd50 Linux 5.4.255
* e171795856 dma-buf/sw_sync: Avoid recursive lock during fence signal
* f49cac7634 pinctrl: renesas: rza2: Add lock around pinctrl_generic{{add,remove}_group,{add,remove}_function}
* 197c546a59 clk: Fix undefined reference to `clk_rate_exclusive_{get,put}'
* 7fd9cded56 scsi: core: raid_class: Remove raid_component_add()
* 56428d89a0 scsi: snic: Fix double free in snic_tgt_create()
* b6db4ef5ea irqchip/mips-gic: Don't touch vl_map if a local interrupt is not routable
* 61b5d77169 Documentation/sysctl: document page_lock_unfairness
* b2421a196c ALSA: pcm: Check for null pointer of pointer substream before dereferencing it
* e8bf830efa interconnect: Do not skip aggregation for disabled paths
* 456a7a7340 Revert "ALSA: pcm: Use SG-buffer only when direct DMA is available"
* 52a7c86e63 ALSA: pcm: Fix build error on m68k and others
* a1ef12540e rtnetlink: Reject negative ifindexes in RTM_NEWLINK
* c404e1e197 mm: allow a controlled amount of unfairness in the page lock
* 97640d8e2c x86/fpu: Set X86_FEATURE_OSXSAVE feature after enabling OSXSAVE in CR4
* b156ce3b3b drm/display/dp: Fix the DP DSC Receiver cap size
* 9e5fe282f9 PCI: acpiphp: Use pci_assign_unassigned_bridge_resources() only for non-root bus
* ac0e0df518 media: vcodec: Fix potential array out-of-bounds in encoder queue_setup
* 79a05ca736 radix tree: remove unused variable
* 32639f1344 lib/clz_ctz.c: Fix __clzdi2() and __ctzdi2() for 32-bit kernels
* c5f261825f batman-adv: Hold rtnl lock during MTU update via netlink
* 61b71562be batman-adv: Fix batadv_v_ogm_aggr_send memory leak
* 5fb1a21337 batman-adv: Fix TT global entry leak when client roamed back
* e6e9d78081 batman-adv: Do not get eth header before batadv_check_management_packet
* c97442e098 batman-adv: Don't increase MTU when set by user
* 22288ea6be batman-adv: Trigger events for auto adjusted MTU
* 3b83759fd4 nfsd: Fix race to FREE_STATEID and cl_revoked
* c0284760f4 clk: Fix slab-out-of-bounds error in devm_clk_release()
* a0bc5cf2e7 NFSv4: Fix dropped lock for racing OPEN and delegation return
* 815fb2531a ibmveth: Use dcbf rather than dcbfl
* 35e31aff61 bonding: fix macvlan over alb bond support
* faf3f988cc net: remove bond_slave_has_mac_rcu()
* eebd074af2 net/sched: fix a qdisc modification with ambiguous command request
* 62383d9fa1 igb: Avoid starting unnecessary workqueues
* adef04cc48 net: validate veth and vxcan peer ifindexes
* 52ddda8d21 net: bcmgenet: Fix return value check for fixed_phy_register()
* 189ad377d1 net: bgmac: Fix return value check for fixed_phy_register()
* dcbfcb54a2 ipvlan: Fix a reference count leak warning in ipvlan_ns_exit()
* 8e6433fecb dccp: annotate data-races in dccp_poll()
* 7d6cc69199 sock: annotate data-races around prot->memory_pressure
* d28ea7acfa octeontx2-af: SDP: fix receive link config
* 05319d7077 tracing: Fix memleak due to race between current_tracer and trace
* c8920972d0 drm/amd/display: check TG is non-null before checking if enabled
* 7d4174a99b drm/amd/display: do not wait for mpc idle if tg is disabled
* 94239d1830 ASoC: fsl_sai: Disable bit clock with transmitter
* ef9cae4a6c ASoC: fsl_sai: Add new added registers and new bit definition
* 1b3d751045 ASoC: fsl_sai: Refine enable/disable TE/RE sequence in trigger()
* f9afb326b7 regmap: Account for register length in SMBus I/O limits
* 7e1d1456c8 ALSA: pcm: Fix potential data race at PCM memory allocation helpers
* 140797d0a4 ALSA: pcm: Use SG-buffer only when direct DMA is available
* 95b30a4312 ALSA: pcm: Set per-card upper limit of PCM buffer allocations
* d0ef103e19 dm integrity: reduce vmalloc space footprint on 32-bit architectures
* 072d247d7a dm integrity: increase RECALC_SECTORS to improve recalculate speed
* 4e96ee1175 fbdev: fix potential OOB read in fast_imageblit()
* ebf84320a5 fbdev: Fix sys_imageblit() for arbitrary image widths
* 96f8e80656 fbdev: Improve performance of sys_imageblit()
* 7e5b7360df MIPS: cpu-features: Use boot_cpu_type for CPU type based features
* 302a8fbf8c MIPS: cpu-features: Enable octeon_cache by cpu_type
* 7b57fc3f4c fs: dlm: fix mismatch of plock results from userspace
* 721d5b514d fs: dlm: use dlm_plock_info for do_unlock_close
* da794f6dd5 fs: dlm: change plock interrupted message to debug again
* f03726ef19 fs: dlm: add pid to debug log
* 8b73497e50 dlm: replace usage of found with dedicated list iterator variable
* 526cc04d71 dlm: improve plock logging if interrupted
* 7abd6dce29 PCI: acpiphp: Reassign resources on bridge if necessary
* fce0815552 net: phy: broadcom: stub c45 read/write for 54810
* e91d5ace70 mmc: f-sdh30: fix order of function calls in sdhci_f_sdh30_remove
* a0e20e267a net: xfrm: Amend XFRMA_SEC_CTX nla_policy structure
* f0c10a4497 net: fix the RTO timer retransmitting skb every 1ms if linear option is enabled
* b1be2cfcf6 virtio-net: set queues after driver_ok
* 4821df2ffe af_unix: Fix null-ptr-deref in unix_stream_sendpage().
* 0afc186aba netfilter: set default timeout to 3 secs for sctp shutdown send and recv state
* 6875690b0e mmc: block: Fix in_flight[issue_type] value error
* 54deee3fab mmc: wbsd: fix double mmc_free_host() in wbsd_init()
* 4259dd5342 cifs: Release folio lock on fscache read hit.
* 0337341024 ALSA: usb-audio: Add support for Mythware XA001AU capture and playback interfaces.
* b653289ca6 serial: 8250: Fix oops for port->pm on uart_change_pm()
* 7b4e6bff03 ASoC: meson: axg-tdm-formatter: fix channel slot allocation
* 29d862ee5f ASoC: rt5665: add missed regulator_bulk_disable
* f21fa1892d ARM: dts: imx: Set default tuning step for imx6sx usdhc
* aadee0ae0a ARM: dts: imx: Set default tuning step for imx7d usdhc
* a23e10dafd ARM: dts: imx: Adjust dma-apbh node name
* 536c1bbedd ARM: dts: imx7s: Drop dma-apb interrupt-names
* 37cfbf847c bus: ti-sysc: Flush posted write on enable before reset
* 4637b2fa65 bus: ti-sysc: Improve reset to work with modules with no sysconfig
* 210ff31342 net: do not allow gso_size to be set to GSO_BY_FRAGS
* 1c7db7abd4 sock: Fix misuse of sk_under_memory_pressure()
* aa670bdefc net: dsa: mv88e6xxx: Wait for EEPROM done before HW reset
* 702c58a05e i40e: fix misleading debug logs
* ac16de2d02 team: Fix incorrect deletion of ETH_P_8021AD protocol vid from slaves
* 81da9e2c42 netfilter: nft_dynset: disallow object maps
* bdd7c2ff41 ipvs: fix racy memcpy in proc_do_sync_threshold
* 38e5c37bfa selftests: mirror_gre_changes: Tighten up the TTL test match
* 8046beb890 xfrm: add NULL check in xfrm_update_ae_params
* d34c30442d ip_vti: fix potential slab-use-after-free in decode_session6
* eb47e612e5 ip6_vti: fix slab-use-after-free in decode_session6
* db0e50741f xfrm: fix slab-use-after-free in decode_session6
* 64c6df80d3 xfrm: interface: rename xfrm_interface.c to xfrm_interface_core.c
* 32cc777c0a net: af_key: fix sadb_x_filter validation
* 373848d51f net: xfrm: Fix xfrm_address_filter OOB read
* a0a462a0f2 btrfs: fix BUG_ON condition in btrfs_cancel_balance
* cc423a972c tty: serial: fsl_lpuart: Clear the error flags by writing 1 for lpuart32 platforms
* 1d29e21ed0 powerpc/rtas_flash: allow user copy to flash block cache objects
* 97ddf1c210 fbdev: mmp: fix value check in mmphw_probe()
* 3259e2d878 i2c: bcm-iproc: Fix bcm_iproc_i2c_isr deadlock issue
* b788ad3b24 virtio-mmio: don't break lifecycle of vm_dev
* e22a4b77b6 virtio-mmio: Use to_virtio_mmio_device() to simply code
* 432429d1b2 virtio-mmio: convert to devm_platform_ioremap_resource
* 12c4c22789 nfsd: Remove incorrect check in nfsd4_validate_stateid
* a4e3c4cd02 nfsd4: kill warnings on testing stateids with mismatched clientids
* ff652b0150 net/ncsi: Fix gma flag setting after response
* b66a1defb2 tracing/probes: Fix to update dynamic data counter if fetcharg uses it
* bdc309d89b tracing/probes: Have process_fetch_insn() take a void * instead of pt_regs
* cc93a372e0 leds: trigger: netdev: Recheck NETDEV_LED_MODE_LINKUP on dev rename
* 939b8b312a mmc: sunxi: fix deferred probing
* c6d1a281ae mmc: bcm2835: fix deferred probing
* b48b4b1885 USB: dwc3: qcom: fix NULL-deref on suspend
* 6da1f9fd9c usb: dwc3: qcom: Add helper functions to enable,disable wake irqs
* 5335bb0cef interconnect: Add helpers for enabling/disabling a path
* e062fb9794 interconnect: Move internal structs into a separate file
* abc25a18a6 irqchip/mips-gic: Use raw spinlock for gic_lock
* 05de6069b5 irqchip/mips-gic: Get rid of the reliance on irq_cpu_online()
* 1224e5a978 ALSA: hda: Fix unhandled register update during auto-suspend period
* a55d55a307 PM: runtime: Add pm_runtime_get_if_active()
* e5d98d42bc PM-runtime: add tracepoints for usage_count changes
* 59aba9d5cd iommu/amd: Fix "Guest Virtual APIC Table Root Pointer" configuration in IRTE
* 8f302378c7 iio: addac: stx104: Fix race condition when converting analog-to-digital
* 7251b2915d iio: addac: stx104: Fix race condition for stx104_write_raw()
* 70d135e7de iio: stx104: Move to addac subdirectory
* 8ba99f7fc7 iio: adc: stx104: Implement and utilize register structures
* 4edf338ade iio: adc: stx104: Utilize iomap interface
* e13b26d0dd iio: add addac subdirectory
* e6f66a0ad7 IMA: allow/fix UML builds
* 635278e97a powerpc/kasan: Disable KCOV in KASAN code
* 109f0aaa0b ALSA: hda: fix a possible null-pointer dereference due to data race in snd_hdac_regmap_sync()
* 97ed584377 ALSA: hda/realtek: Add quirks for Unis H3C Desktop B760 & Q760
* c6059af6bf drm/amdgpu: Fix potential fence use-after-free v2
* fe49aa73cc Bluetooth: L2CAP: Fix use-after-free
* 22100df1d5 pcmcia: rsrc_nonstatic: Fix memory leak in nonstatic_release_resource_db()
* b4a7ab57ef gfs2: Fix possible data races in gfs2_show_options()
* c4d5c945b6 usb: chipidea: imx: don't request QoS for imx8ulp
* c1c5826223 media: platform: mediatek: vpu: fix NULL ptr dereference
* ef009fe201 media: v4l2-mem2mem: add lock to protect parameter num_rdy
* 2a8807f9f5 FS: JFS: Check for read-only mounted filesystem in txBegin
* a7d17d6bd7 FS: JFS: Fix null-ptr-deref Read in txBegin
* 2225000d62 MIPS: dec: prom: Address -Warray-bounds warning
* 6e7d9d76e5 fs: jfs: Fix UBSAN: array-index-out-of-bounds in dbAllocDmapLev
* 3f1368af47 udf: Fix uninitialized array access for some pathnames
* 8f203dd401 ovl: check type and offset of struct vfsmount in ovl_entry
* 8abed186aa HID: add quirk for 03f0:464a HP Elite Presenter Mouse
* 3f378783c4 quota: fix warning in dqgrab()
* c3a1f5ba11 quota: Properly disable quotas when add_dquot_ref() fails
* dd445ebbee ALSA: emu10k1: roll up loops in DSP setup code for Audigy
* b8fab6aebd drm/radeon: Fix integer overflow in radeon_cs_parser_init
* 3a3bb438da macsec: use DEV_STATS_INC()
* b5e20a3dde macsec: Fix traffic counters/statistics
* 4b854879f8 selftests: forwarding: tc_flower: Relax success criterion
* e5883ffdd0 mmc: sdhci-f-sdh30: Replace with sdhci_pltfm
* e7bd70c3bc mmc: sdhci_f_sdh30: convert to devm_platform_ioremap_resource

Change-Id: I43c3bfbea90dd70354856472a720f46b1a43c148
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2023-10-30 16:33:57 +00:00
Yoshihiro Shimoda
756378d5aa BACKPORT: ravb: Fix use-after-free issue in ravb_tx_timeout_work()
[ Upstream commit 3971442870713de527684398416970cf025b4f89 ]

The ravb_stop() should call cancel_work_sync(). Otherwise,
ravb_tx_timeout_work() is possible to use the freed priv after
ravb_remove() was called like below:

CPU0			CPU1
			ravb_tx_timeout()
ravb_remove()
unregister_netdev()
free_netdev(ndev)
// free priv
			ravb_tx_timeout_work()
			// use priv

unregister_netdev() will call .ndo_stop() so that ravb_stop() is
called. And, after phy_stop() is called, netif_carrier_off()
is also called. So that .ndo_tx_timeout() will not be called
after phy_stop().

Bug: 289003868
Fixes: c156633f13 ("Renesas Ethernet AVB driver proper")
Reported-by: Zheng Wang <zyytlz.wz@163.com>
Closes: https://lore.kernel.org/netdev/20230725030026.1664873-1-zyytlz.wz@163.com/
Signed-off-by: Yoshihiro Shimoda <yoshihiro.shimoda.uh@renesas.com>
Reviewed-by: Sergey Shtylyov <s.shtylyov@omp.ru>
Link: https://lore.kernel.org/r/20231005011201.14368-3-yoshihiro.shimoda.uh@renesas.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
(cherry picked from commit 6f6fa8061f756aedb93af12a8a5d3cf659127965)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I36fcd769d93817adaa04162cae0b54b1addbb9bf
2023-10-30 16:27:33 +00:00
Yoshihiro Shimoda
0d7affc8ca UPSTREAM: ravb: Fix up dma_free_coherent() call in ravb_remove()
[ Upstream commit e6864af61493113558c502b5cd0d754c19b93277 ]

In ravb_remove(), dma_free_coherent() should be call after
unregister_netdev(). Otherwise, this controller is possible to use
the freed buffer.

Bug: 289003868
Fixes: c156633f13 ("Renesas Ethernet AVB driver proper")
Signed-off-by: Yoshihiro Shimoda <yoshihiro.shimoda.uh@renesas.com>
Reviewed-by: Sergey Shtylyov <s.shtylyov@omp.ru>
Link: https://lore.kernel.org/r/20231005011201.14368-2-yoshihiro.shimoda.uh@renesas.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
(cherry picked from commit 3f9295ad7f9478e65debcef496da4e4eb83db5ea)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I8e7da5816f715307c7d8bcd881a2a5ecb52439bb
2023-10-30 16:25:01 +00:00
Marco Zhang
7f6c5cf98e Revert "ALSA: compress: Allow pause and resume during draining"
This reverts commit abe2d9a800.

Reason for revert: <With GKI audio is not working>

Change-Id: I13afb5d8e34c94bb82bb480b227f417d8fc04064
2023-10-30 01:47:32 -07:00
Greg Kroah-Hartman
4934e8f7a8 Revert "perf: Disallow mis-matched inherited group reads"
This reverts commit 7252c8b981 which is
commit 32671e3799ca2e4590773fd0e63aaa4229e50c06 upstream.

It breaks the android ABI and if this is needed in the future, can be
brought back in an abi-safe way.

Bug: 161946584
Change-Id: Ia00890aeeef6153c7f3462a2a2189149734ac28a
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2023-10-26 10:18:51 +00:00
Greg Kroah-Hartman
231c81bbc8 Revert "xfrm: fix a data-race in xfrm_gen_index()"
This reverts commit bcacdf4deb which is
commit 3e4bc23926b83c3c67e5f61ae8571602754131a6 upstream.

It breaks the android ABI and if this is needed in the future, can be
brought back in an abi-safe way.

Bug: 161946584
Change-Id: I6af8ce540570c756ea9f16526c36f8815971e216
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2023-10-26 10:18:46 +00:00
Greg Kroah-Hartman
0ca22be029 Revert "Bluetooth: hci_core: Fix build warnings"
This reverts commit b48595f5b1 which is
commit dcda165706b9fbfd685898d46a6749d7d397e0c0 upstream.

It breaks the android ABI and if this is needed in the future, can be
brought back in an abi-safe way.

Bug: 161946584
Change-Id: I4a64dca20bcdfe9cbe33fc23c7d3d1b252f4b873
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2023-10-26 10:17:09 +00:00
Greg Kroah-Hartman
cf5d98b23e Revert "xfrm: interface: use DEV_STATS_INC()"
This reverts commit 0cb7b894e4 which is
commit 0cb7b894e4 upstream.

It breaks the build as it depends on an abi-breaking commit that was
previously reverted.  If this is needed in the future, it can come back
in an abi-safe way.

Bug: 161946584
Change-Id: Ib8c4c34c281fdbe75397a9508155b04ab1e63c8d
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2023-10-26 09:23:20 +00:00