)]}'
{
  "log": [
    {
      "commit": "284aeebb312c2b2464673bf68b9a32e415b5145a",
      "tree": "71fbc5fdade725cba28c6fe25da459cdd7a5d4b8",
      "parents": [
        "57b41f6193014b2a4a67c270dd77d801fd337d98"
      ],
      "author": {
        "name": "Shan Hai",
        "email": "shan.hai@windriver.com",
        "time": "Mon Mar 18 10:30:44 2013 +0800"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 12 09:38:44 2013 -0700"
      },
      "message": "libata: Set max sector to 65535 for Slimtype DVD A DS8A8SH drive\n\ncommit a32450e127fc6e5ca6d958ceb3cfea4d30a00846 upstream.\n\nThe Slimtype DVD A  DS8A8SH drive locks up when max sector is smaller than\n65535, and the blow backtrace is observed on locking up:\n\nINFO: task flush-8:32:1130 blocked for more than 120 seconds.\n\"echo 0 \u003e /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\nflush-8:32      D ffffffff8180cf60     0  1130      2 0x00000000\n ffff880273aef618 0000000000000046 0000000000000005 ffff880273aee000\n ffff880273aee000 ffff880273aeffd8 ffff880273aee010 ffff880273aee000\n ffff880273aeffd8 ffff880273aee000 ffff88026e842ea0 ffff880274a10000\nCall Trace:\n [\u003cffffffff8168fc2d\u003e] schedule+0x5d/0x70\n [\u003cffffffff8168fccc\u003e] io_schedule+0x8c/0xd0\n [\u003cffffffff81324461\u003e] get_request+0x731/0x7d0\n [\u003cffffffff8133dc60\u003e] ? cfq_allow_merge+0x50/0x90\n [\u003cffffffff81083aa0\u003e] ? wake_up_bit+0x40/0x40\n [\u003cffffffff81320443\u003e] ? bio_attempt_back_merge+0x33/0x110\n [\u003cffffffff813248ea\u003e] blk_queue_bio+0x23a/0x3f0\n [\u003cffffffff81322176\u003e] generic_make_request+0xc6/0x120\n [\u003cffffffff81322308\u003e] submit_bio+0x138/0x160\n [\u003cffffffff811d7596\u003e] ? bio_alloc_bioset+0x96/0x120\n [\u003cffffffff811d1f61\u003e] submit_bh+0x1f1/0x220\n [\u003cffffffff811d48b8\u003e] __block_write_full_page+0x228/0x340\n [\u003cffffffff811d3650\u003e] ? attach_nobh_buffers+0xc0/0xc0\n [\u003cffffffff811d8960\u003e] ? I_BDEV+0x10/0x10\n [\u003cffffffff811d8960\u003e] ? I_BDEV+0x10/0x10\n [\u003cffffffff811d4ab6\u003e] block_write_full_page_endio+0xe6/0x100\n [\u003cffffffff811d4ae5\u003e] block_write_full_page+0x15/0x20\n [\u003cffffffff811d9268\u003e] blkdev_writepage+0x18/0x20\n [\u003cffffffff81142527\u003e] __writepage+0x17/0x40\n [\u003cffffffff811438ba\u003e] write_cache_pages+0x34a/0x4a0\n [\u003cffffffff81142510\u003e] ? set_page_dirty+0x70/0x70\n [\u003cffffffff81143a61\u003e] generic_writepages+0x51/0x80\n [\u003cffffffff81143ab0\u003e] do_writepages+0x20/0x50\n [\u003cffffffff811c9ed6\u003e] __writeback_single_inode+0xa6/0x2b0\n [\u003cffffffff811ca861\u003e] writeback_sb_inodes+0x311/0x4d0\n [\u003cffffffff811caaa6\u003e] __writeback_inodes_wb+0x86/0xd0\n [\u003cffffffff811cad43\u003e] wb_writeback+0x1a3/0x330\n [\u003cffffffff816916cf\u003e] ? _raw_spin_lock_irqsave+0x3f/0x50\n [\u003cffffffff811b8362\u003e] ? get_nr_inodes+0x52/0x70\n [\u003cffffffff811cb0ac\u003e] wb_do_writeback+0x1dc/0x260\n [\u003cffffffff8168dd34\u003e] ? schedule_timeout+0x204/0x240\n [\u003cffffffff811cb232\u003e] bdi_writeback_thread+0x102/0x2b0\n [\u003cffffffff811cb130\u003e] ? wb_do_writeback+0x260/0x260\n [\u003cffffffff81083550\u003e] kthread+0xc0/0xd0\n [\u003cffffffff81083490\u003e] ? kthread_worker_fn+0x1b0/0x1b0\n [\u003cffffffff8169a3ec\u003e] ret_from_fork+0x7c/0xb0\n [\u003cffffffff81083490\u003e] ? kthread_worker_fn+0x1b0/0x1b0\n\n The above trace was triggered by\n   \"dd if\u003d/dev/zero of\u003d/dev/sr0 bs\u003d2048 count\u003d32768\"\n\n It was previously working by accident, since another bug introduced\n by 4dce8ba94c7 (libata: Use \u0027bool\u0027 return value for ata_id_XXX) caused\n all drives to use maxsect\u003d65535.\n\nSigned-off-by: Shan Hai \u003cshan.hai@windriver.com\u003e\nSigned-off-by: Jeff Garzik \u003cjgarzik@redhat.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "57b41f6193014b2a4a67c270dd77d801fd337d98",
      "tree": "e7ba3d038511ab08027428518796f3edeaf8dc92",
      "parents": [
        "91777f102bc6c5d72bf637281b74ba96c1447850"
      ],
      "author": {
        "name": "Shan Hai",
        "email": "shan.hai@windriver.com",
        "time": "Mon Mar 18 10:30:43 2013 +0800"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 12 09:38:44 2013 -0700"
      },
      "message": "libata: Use integer return value for atapi_command_packet_set\n\ncommit d8668fcb0b257d9fdcfbe5c172a99b8d85e1cd82 upstream.\n\nThe function returns type of ATAPI drives so it should return integer value.\nThe commit 4dce8ba94c7 (libata: Use \u0027bool\u0027 return value for ata_id_XXX) since\nv2.6.39 changed the type of return value from int to bool, the change would\ncause all of the ATAPI class drives to be treated as TYPE_TAPE and the\nmax_sectors of the drives to be set to 65535 because of the commit\nf8d8e5799b7(libata: increase 128 KB / cmd limit for ATAPI tape drives), for the\nfunction would return true for all ATAPI class drives and the TYPE_TAPE is\ndefined as 0x01.\n\nSigned-off-by: Shan Hai \u003cshan.hai@windriver.com\u003e\nSigned-off-by: Jeff Garzik \u003cjgarzik@redhat.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "91777f102bc6c5d72bf637281b74ba96c1447850",
      "tree": "7a286f06b3e462c3426e7f3c39834a1258f76221",
      "parents": [
        "27bd92ff68526e05f50490a708693e319c29f332"
      ],
      "author": {
        "name": "Yinghai Lu",
        "email": "yinghai@kernel.org",
        "time": "Mon Apr 01 11:48:59 2013 -0600"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 12 09:38:44 2013 -0700"
      },
      "message": "EISA/PCI: Fix bus res reference\n\ncommit 2cfda637e29ce9e3df31b59f64516b2e571cc985 upstream.\n\nMatthew found that 3.8.3 is having problems with an old (ancient)\nPCI-to-EISA bridge, the Intel 82375. It worked with the 3.2 kernel.\nHe identified the 82375, but doesn\u0027t assign the struct resource *res\npointer inside the struct eisa_root_device, and panics.\n\npci_eisa_init() was using bus-\u003eresource[] directly instead of\npci_bus_resource_n().  The bus-\u003eresource[] array is a PCI-internal\nimplementation detail, and after commit 45ca9e97 (PCI: add helpers for\nbuilding PCI bus resource lists) and commit 0efd5aab (PCI: add struct\npci_host_bridge_window with CPU/bus address offset), bus-\u003eresource[] is not\nused for PCI root buses any more.\n\nThe 82375 is a subtractive-decode PCI device, so handle it the same\nway we handle PCI-PCI bridges in subtractive-decode mode in\npci_read_bridge_bases().\n\n[bhelgaas: changelog]\nReported-by: Matthew Whitehead \u003cmwhitehe@redhat.com\u003e\nTested-by: Matthew Whitehead \u003cmwhitehe@redhat.com\u003e\nSigned-off-by: Yinghai Lu \u003cyinghai@kernel.org\u003e\nSigned-off-by: Bjorn Helgaas \u003cbhelgaas@google.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "27bd92ff68526e05f50490a708693e319c29f332",
      "tree": "75d1a321e8f7c965cccfdfde747840160cbd714d",
      "parents": [
        "54144193ab339572e21719ca327afb6583cda537"
      ],
      "author": {
        "name": "Yinghai Lu",
        "email": "yinghai@kernel.org",
        "time": "Wed Mar 27 21:28:05 2013 -0700"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 12 09:38:44 2013 -0700"
      },
      "message": "EISA/PCI: Init EISA early, before PNP\n\ncommit c5fb301ae83bec6892e54984e6ec765c47df8e10 upstream.\n\nMatthew reported kernels fail the pci_eisa probe and are later successful\nwith the virtual_eisa_root_init force probe without slot0.\n\nThe reason for that is: PNP probing is before pci_eisa_init gets called\nas pci_eisa_init is called via pci_driver.\n\npnp 00:0f has 0xc80 - 0xc84 reserved.\n[    9.700409] pnp 00:0f: [io  0x0c80-0x0c84]\n\nso eisa_probe will fail from pci_eisa_init\n\t\t\t\t\u003d\u003d\u003eeisa_root_register\n\t\t\t\t\t\u003d\u003d\u003eeisa_probe path.\nas force_probe is not set in pci_eisa_root, it will bail early when\nslot0 is not probed and initialized.\n\nTry to use subsys_initcall_sync instead, and will keep following sequence:\n\tpci_subsys_init\n\tpci_eisa_init_early\n\tpnpacpi_init/isapnp_init\n\nAfter this patch EISA can be initialized properly, and PNP overlapping\nresource will not be reserved.\n[   10.104434] system 00:0f: [io  0x0c80-0x0c84] could not be reserved\n\nReported-by: Matthew Whitehead \u003cmwhitehe@redhat.com\u003e\nTested-by: Matthew Whitehead \u003cmwhitehe@redhat.com\u003e\nSigned-off-by: Yinghai Lu \u003cyinghai@kernel.org\u003e\nSigned-off-by: Bjorn Helgaas \u003cbhelgaas@google.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "54144193ab339572e21719ca327afb6583cda537",
      "tree": "18260868ebf329768dd130cf54905bbcda2208b9",
      "parents": [
        "3379d5230307b19c32401da4ac05d95770e80872"
      ],
      "author": {
        "name": "David Henningsson",
        "email": "david.henningsson@canonical.com",
        "time": "Thu Apr 04 11:47:13 2013 +0200"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 12 09:38:44 2013 -0700"
      },
      "message": "ALSA: hda - fix typo in proc output\n\ncommit aeb3a97222832e5457c4b72d72235098ce4bfe8d upstream.\n\nRename \"Digitial In\" to \"Digital In\". This function is only used for\nproc output, so should not cause any problems to change.\n\nSigned-off-by: David Henningsson \u003cdavid.henningsson@canonical.com\u003e\nSigned-off-by: Takashi Iwai \u003ctiwai@suse.de\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "3379d5230307b19c32401da4ac05d95770e80872",
      "tree": "d2d5df2486e26e00136d033e1c922f085d87beae",
      "parents": [
        "276674490c2f110d12c7009bb6d74757a678cd0c"
      ],
      "author": {
        "name": "Rainer Koenig",
        "email": "Rainer.Koenig@ts.fujitsu.com",
        "time": "Thu Apr 04 08:40:38 2013 +0200"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 12 09:38:44 2013 -0700"
      },
      "message": "ALSA: hda - Enabling Realtek ALC 671 codec\n\ncommit 1d87caa69c04008e09f5ff47b5e6acb6116febc7 upstream.\n\n* Added the device ID to the modalias list and assinged ALC662 patches\nfor it\n* Added 4 port support for the device ID 0671 in alc662_parse_auto_config\n\nSigned-off-by: Rainer Koenig \u003cRainer.Koenig@ts.fujitsu.com\u003e\nSigned-off-by: Takashi Iwai \u003ctiwai@suse.de\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "276674490c2f110d12c7009bb6d74757a678cd0c",
      "tree": "2b0ed6663370c7c818a6cffe93beee1f446d9c54",
      "parents": [
        "b57644a59a635af74fde8e4548754de338752422"
      ],
      "author": {
        "name": "Mengdong Lin",
        "email": "mengdong.lin@intel.com",
        "time": "Thu Mar 28 05:20:22 2013 -0400"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 12 09:38:44 2013 -0700"
      },
      "message": "ALSA: hda - bug fix on return value when getting HDMI ELD info\n\ncommit 2ef5692efad330b67a234e2c49edad38538751e7 upstream.\n\nIn function snd_hdmi_get_eld(), the variable \u0027ret\u0027 should be initialized to 0.\nOtherwise it will be returned uninitialized as non-zero after ELD info is got\nsuccessfully. Thus hdmi_present_sense() will always assume ELD info is invalid\nby mistake, and /proc file system cannot show the proper ELD info.\n\nSigned-off-by: Mengdong Lin \u003cmengdong.lin@intel.com\u003e\nAcked-by: David Henningsson \u003cdavid.henningsson@canonical.com\u003e\nSigned-off-by: Takashi Iwai \u003ctiwai@suse.de\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "b57644a59a635af74fde8e4548754de338752422",
      "tree": "cf1037468c6b9dce8b7a80793fe8af8d62ab4d03",
      "parents": [
        "0d18994cb19855aa6ea892985c19aa54e4192fb0"
      ],
      "author": {
        "name": "Jan Kara",
        "email": "jack@suse.cz",
        "time": "Fri Mar 29 15:39:16 2013 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 12 09:38:43 2013 -0700"
      },
      "message": "reiserfs: Fix warning and inode leak when deleting inode with xattrs\n\ncommit 35e5cbc0af240778e61113286c019837e06aeec6 upstream.\n\nAfter commit 21d8a15a (lookup_one_len: don\u0027t accept . and ..) reiserfs\nstarted failing to delete xattrs from inode. This was due to a buggy\ntest for \u0027.\u0027 and \u0027..\u0027 in fill_with_dentries() which resulted in passing\n\u0027.\u0027 and \u0027..\u0027 entries to lookup_one_len() in some cases. That returned\nerror and so we failed to iterate over all xattrs of and inode.\n\nFix the test in fill_with_dentries() along the lines of the one in\nlookup_one_len().\n\nReported-by: Pawel Zawora \u003cpzawora@gmail.com\u003e\nSigned-off-by: Jan Kara \u003cjack@suse.cz\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "0d18994cb19855aa6ea892985c19aa54e4192fb0",
      "tree": "9ee55a7eb1a626eb2c248d79d6b65528e47872d1",
      "parents": [
        "a41c384e8308a7d25fa778f0b24656ef50e05766"
      ],
      "author": {
        "name": "Artem Bityutskiy",
        "email": "artem.bityutskiy@linux.intel.com",
        "time": "Thu Mar 14 10:49:23 2013 +0200"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 12 09:38:43 2013 -0700"
      },
      "message": "UBIFS: make space fixup work in the remount case\n\ncommit 67e753ca41782913d805ff4a8a2b0f60b26b7915 upstream.\n\nThe UBIFS space fixup is a useful feature which allows to fixup the \"broken\"\nflash space at the time of the first mount. The \"broken\" space is usually the\nresult of using a \"dumb\" industrial flasher which is not able to skip empty\nNAND pages and just writes all 0xFFs to the empty space, which has grave\nside-effects for UBIFS when UBIFS trise to write useful data to those empty\npages.\n\nThe fix-up feature works roughly like this:\n1. mkfs.ubifs sets the fixup flag in UBIFS superblock when creating the image\n   (see -F option)\n2. when the file-system is mounted for the first time, UBIFS notices the fixup\n   flag and re-writes the entire media atomically, which may take really a lot\n   of time.\n3. UBIFS clears the fixup flag in the superblock.\n\nThis works fine when the file system is mounted R/W for the very first time.\nBut it did not really work in the case when we first mount the file-system R/O,\nand then re-mount R/W. The reason was that we started the fixup procedure too\nlate, which we cannot really do because we have to fixup the space before it\nstarts being used.\n\nSigned-off-by: Artem Bityutskiy \u003cartem.bityutskiy@linux.intel.com\u003e\nReported-by: Mark Jackson \u003cmpfj-list@mimc.co.uk\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "a41c384e8308a7d25fa778f0b24656ef50e05766",
      "tree": "9c2267a327f842885bb69aedfebd9da6daaab9be",
      "parents": [
        "c8c76a4e4615ae959543cc8332339384ccb4f192"
      ],
      "author": {
        "name": "Anatolij Gustschin",
        "email": "agust@denx.de",
        "time": "Wed Mar 13 14:57:43 2013 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 12 09:38:43 2013 -0700"
      },
      "message": "spi/mpc512x-psc: optionally keep PSC SS asserted across xfer segmensts\n\ncommit 1ad849aee5f53353ed88d9cd3d68a51b03a7d44f upstream.\n\nSome SPI slave devices require asserted chip select signal across\nmultiple transfer segments of an SPI message. Currently the driver\nalways de-asserts the internal SS signal for every single transfer\nsegment of the message and ignores the \u0027cs_change\u0027 flag of the\ntransfer description. Disable the internal chip select (SS) only\nif this is needed and indicated by the \u0027cs_change\u0027 flag.\n\nWithout this change, each partial transfer of a surrounding\nmulti-part SPI transaction might erroneously change the SS\nsignal, which might prevent slaves from answering the request\nthat was sent in a previous transfer segment because the\ntransaction could be considered aborted (SS was de-asserted\nbefore reading the response).\n\nReported-by: Gerhard Sittig \u003cgerhard.sittig@ifm.com\u003e\nSigned-off-by: Anatolij Gustschin \u003cagust@denx.de\u003e\nSigned-off-by: Mark Brown \u003cbroonie@opensource.wolfsonmicro.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "c8c76a4e4615ae959543cc8332339384ccb4f192",
      "tree": "816ca06da019531112a3be9afc7866bdb43658d6",
      "parents": [
        "6ec0e8e15ecc310464185db7820c5d30be409d1e"
      ],
      "author": {
        "name": "Girish K S",
        "email": "girishks2000@gmail.com",
        "time": "Wed Mar 13 12:13:30 2013 +0530"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 12 09:38:43 2013 -0700"
      },
      "message": "spi/s3c64xx: modified error interrupt handling and init\n\ncommit 375981f2e14868be16cafbffd34a4f16a6ee01c6 upstream.\n\nThe status of the interrupt is available in the status register,\nso reading the clear pending register and writing back the same\nvalue will not actually clear the pending interrupts. This patch\nmodifies the interrupt handler to read the status register and\nclear the corresponding pending bit in the clear pending register.\n\nModified the hwInit function to clear all the pending interrupts.\n\nSigned-off-by: Girish K S \u003cks.giri@samsung.com\u003e\nSigned-off-by: Mark Brown \u003cbroonie@opensource.wolfsonmicro.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "6ec0e8e15ecc310464185db7820c5d30be409d1e",
      "tree": "35bd1748d9e516b7809941f9e3693def4499acab",
      "parents": [
        "93c86c4916e247e5e8de4d98c0e855d664e41468"
      ],
      "author": {
        "name": "Lars-Peter Clausen",
        "email": "lars@metafoo.de",
        "time": "Wed Mar 13 16:38:33 2013 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 12 09:38:43 2013 -0700"
      },
      "message": "regmap: cache Fix regcache-rbtree sync\n\ncommit 8abac3ba51b5525354e9b2ec0eed1c9e95c905d9 upstream.\n\nThe last register block, which falls into the specified range, is not handled\ncorrectly. The formula which calculates the number of register which should be\nsynced is inverse (and off by one). E.g. if all registers in that block should\nbe synced only one is synced, and if only one should be synced all (but one) are\nsynced. To calculate the number of registers that need to be synced we need to\nsubtract the number of the first register in the block from the max register\nnumber and add one. This patch updates the code accordingly.\n\nThe issue was introduced in commit ac8d91c (\"regmap: Supply ranges to the sync\noperations\").\n\nSigned-off-by: Lars-Peter Clausen \u003clars@metafoo.de\u003e\nSigned-off-by: Mark Brown \u003cbroonie@opensource.wolfsonmicro.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "93c86c4916e247e5e8de4d98c0e855d664e41468",
      "tree": "a2430162d37e782082ba596186f7eb36a7be864d",
      "parents": [
        "cbfed955f40d15c12da468e4b67a4ba882ed0068"
      ],
      "author": {
        "name": "Lars-Peter Clausen",
        "email": "lars@metafoo.de",
        "time": "Fri Mar 15 11:26:15 2013 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 12 09:38:43 2013 -0700"
      },
      "message": "ASoC: dma-sh7760: Fix compile error\n\ncommit 417a1178f1bf3cdc606376b3ded3a22489fbb3eb upstream.\n\nThe dma-sh7760 currently fails with the following compile error:\n\tsound/soc/sh/dma-sh7760.c:346:2: error: unknown field \u0027pcm_ops\u0027 specified in initializer\n\tsound/soc/sh/dma-sh7760.c:346:2: warning: initialization from incompatible pointer type\n\tsound/soc/sh/dma-sh7760.c:347:2: error: unknown field \u0027pcm_new\u0027 specified in initializer\n\tsound/soc/sh/dma-sh7760.c:347:2: warning: initialization makes integer from pointer without a cast\n\tsound/soc/sh/dma-sh7760.c:348:2: error: unknown field \u0027pcm_free\u0027 specified in initializer\n\tsound/soc/sh/dma-sh7760.c:348:2: warning: initialization from incompatible pointer type\n\tsound/soc/sh/dma-sh7760.c: In function \u0027sh7760_soc_platform_probe\u0027:\n\tsound/soc/sh/dma-sh7760.c:353:2: warning: passing argument 2 of \u0027snd_soc_register_platform\u0027 from incompatible pointer type\n\tinclude/sound/soc.h:368:5: note: expected \u0027struct snd_soc_platform_driver *\u0027 but argument is of type \u0027struct snd_soc_platform *\u0027\n\nThis is due the misnaming of the snd_soc_platform_driver type name and \u0027ops\u0027\nfield. The issue was introduced in commit f0fba2a(\"ASoC: multi-component - ASoC\nMulti-Component Support\").\n\nSigned-off-by: Lars-Peter Clausen \u003clars@metafoo.de\u003e\nSigned-off-by: Mark Brown \u003cbroonie@opensource.wolfsonmicro.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "cbfed955f40d15c12da468e4b67a4ba882ed0068",
      "tree": "a1280bc8d622fed2fe45c07060fdabda3c76f587",
      "parents": [
        "29fcbcb3e028d63c3bb8a396bd696f82803f8053"
      ],
      "author": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:08:54 2013 -0700"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:08:54 2013 -0700"
      },
      "message": "Linux 3.4.39\n"
    },
    {
      "commit": "29fcbcb3e028d63c3bb8a396bd696f82803f8053",
      "tree": "53fab10e06799550291a46d423645942d04b3f14",
      "parents": [
        "aa5ec2292c944b46ac536056b89ddfeb4e35fde3"
      ],
      "author": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Wed Apr 03 10:05:41 2013 -0700"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:52 2013 -0700"
      },
      "message": "Revert \"xen/blkback: Don\u0027t trust the handle from the frontend.\"\n\nThis reverts commit c93c85196e2c7001daa8a04b83a9d6dd4febfb59 which is\ncommit 01c681d4c70d64cb72142a2823f27c4146a02e63 upstream.\n\nIt shouldn\u0027t have been applied to the 3.4-stable tree, sorry about that.\n\nReported-by: William Dauchy \u003cwdauchy@gmail.com\u003e\nCc: Jan Beulich \u003cjbeulich@suse.com\u003e\nCc: Ian Campbell \u003cian.campbell@citrix.com\u003e\nCc: Konrad Rzeszutek Wilk \u003ckonrad.wilk@oracle.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "aa5ec2292c944b46ac536056b89ddfeb4e35fde3",
      "tree": "80528f8a1a1a55f5d7e52154b4a825a7278ded05",
      "parents": [
        "c8438198c033eb85ecc20c30568934d3e8fd2f0a"
      ],
      "author": {
        "name": "Veaceslav Falico",
        "email": "vfalico@redhat.com",
        "time": "Tue Apr 02 05:15:16 2013 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:52 2013 -0700"
      },
      "message": "bonding: get netdev_rx_handler_unregister out of locks\n\n[ Upstream commit fcd99434fb5c137274d2e15dd2a6a7455f0f29ff ]\n\nNow that netdev_rx_handler_unregister contains synchronize_net(), we need\nto call it outside of bond-\u003elock, cause it might sleep. Also, remove the\nalready unneded synchronize_net().\n\nSigned-off-by: Veaceslav Falico \u003cvfalico@redhat.com\u003e\nAcked-by: Eric Dumazet \u003cedumazet@google.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "c8438198c033eb85ecc20c30568934d3e8fd2f0a",
      "tree": "c7688ca2a86d56e0a384f132ff1c1d23c489e8bb",
      "parents": [
        "74bed69914a63f2b412e5f837226d88da52323ca"
      ],
      "author": {
        "name": "Steve Glendinning",
        "email": "steve.glendinning@shawell.net",
        "time": "Thu Mar 28 02:34:41 2013 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:51 2013 -0700"
      },
      "message": "smsc75xx: fix jumbo frame support\n\n[ Upstream commit 4c51e53689569398d656e631c17308d9b8e84650 ]\n\nThis patch enables RX of jumbo frames for LAN7500.\n\nPreviously the driver would transmit jumbo frames succesfully but\nwould drop received jumbo frames (incrementing the interface errors\ncount).\n\nWith this patch applied the device can succesfully receive jumbo\nframes up to MTU 9000 (9014 bytes on the wire including ethernet\nheader).\n\nSigned-off-by: Steve Glendinning \u003csteve.glendinning@shawell.net\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "74bed69914a63f2b412e5f837226d88da52323ca",
      "tree": "1076102d4afdf2758d7c69dcab26632cbd490134",
      "parents": [
        "f0180de2669df4b9e83a37417369ae7ef7cb71ff"
      ],
      "author": {
        "name": "Veaceslav Falico",
        "email": "vfalico@redhat.com",
        "time": "Mon Mar 25 22:26:21 2013 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:51 2013 -0700"
      },
      "message": "pch_gbe: fix ip_summed checksum reporting on rx\n\n[ Upstream commit 76a0e68129d7d24eb995a6871ab47081bbfa0acc ]\n\nskb-\u003eip_summed should be CHECKSUM_UNNECESSARY when the driver reports that\nchecksums were correct and CHECKSUM_NONE in any other case. They\u0027re\ncurrently placed vice versa, which breaks the forwarding scenario. Fix it\nby placing them as described above.\n\nSigned-off-by: Veaceslav Falico \u003cvfalico@redhat.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "f0180de2669df4b9e83a37417369ae7ef7cb71ff",
      "tree": "dbda6dcb85ef632ebb22529a227a1779ae39ff99",
      "parents": [
        "5afd933cc476e33339eeca8928de1357857657ea"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "edumazet@google.com",
        "time": "Fri Mar 29 03:01:22 2013 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:47 2013 -0700"
      },
      "message": "net: add a synchronize_net() in netdev_rx_handler_unregister()\n\n[ Upstream commit 00cfec37484761a44a3b6f4675a54caa618210ae ]\n\ncommit 35d48903e97819 (bonding: fix rx_handler locking) added a race\nin bonding driver, reported by Steven Rostedt who did a very good\ndiagnosis :\n\n\u003cquoting Steven\u003e\n\nI\u0027m currently debugging a crash in an old 3.0-rt kernel that one of our\ncustomers is seeing. The bug happens with a stress test that loads and\nunloads the bonding module in a loop (I don\u0027t know all the details as\nI\u0027m not the one that is directly interacting with the customer). But the\nbug looks to be something that may still be present and possibly present\nin mainline too. It will just be much harder to trigger it in mainline.\n\nIn -rt, interrupts are threads, and can schedule in and out just like\nany other thread. Note, mainline now supports interrupt threads so this\nmay be easily reproducible in mainline as well. I don\u0027t have the ability\nto tell the customer to try mainline or other kernels, so my hands are\nsomewhat tied to what I can do.\n\nBut according to a core dump, I tracked down that the eth irq thread\ncrashed in bond_handle_frame() here:\n\n        slave \u003d bond_slave_get_rcu(skb-\u003edev);\n        bond \u003d slave-\u003ebond; \u003c--- BUG\n\nthe slave returned was NULL and accessing slave-\u003ebond caused a NULL\npointer dereference.\n\nLooking at the code that unregisters the handler:\n\nvoid netdev_rx_handler_unregister(struct net_device *dev)\n{\n\n        ASSERT_RTNL();\n        RCU_INIT_POINTER(dev-\u003erx_handler, NULL);\n        RCU_INIT_POINTER(dev-\u003erx_handler_data, NULL);\n}\n\nWhich is basically:\n        dev-\u003erx_handler \u003d NULL;\n        dev-\u003erx_handler_data \u003d NULL;\n\nAnd looking at __netif_receive_skb() we have:\n\n        rx_handler \u003d rcu_dereference(skb-\u003edev-\u003erx_handler);\n        if (rx_handler) {\n                if (pt_prev) {\n                        ret \u003d deliver_skb(skb, pt_prev, orig_dev);\n                        pt_prev \u003d NULL;\n                }\n                switch (rx_handler(\u0026skb)) {\n\nMy question to all of you is, what stops this interrupt from happening\nwhile the bonding module is unloading?  What happens if the interrupt\ntriggers and we have this:\n\n        CPU0                    CPU1\n        ----                    ----\n  rx_handler \u003d skb-\u003edev-\u003erx_handler\n\n                        netdev_rx_handler_unregister() {\n                           dev-\u003erx_handler \u003d NULL;\n                           dev-\u003erx_handler_data \u003d NULL;\n\n  rx_handler()\n   bond_handle_frame() {\n    slave \u003d skb-\u003edev-\u003erx_handler;\n    bond \u003d slave-\u003ebond; \u003c-- NULL pointer dereference!!!\n\nWhat protection am I missing in the bond release handler that would\nprevent the above from happening?\n\n\u003c/quoting Steven\u003e\n\nWe can fix bug this in two ways. First is adding a test in\nbond_handle_frame() and others to check if rx_handler_data is NULL.\n\nA second way is adding a synchronize_net() in\nnetdev_rx_handler_unregister() to make sure that a rcu protected reader\nhas the guarantee to see a non NULL rx_handler_data.\n\nThe second way is better as it avoids an extra test in fast path.\n\nReported-by: Steven Rostedt \u003crostedt@goodmis.org\u003e\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nCc: Jiri Pirko \u003cjpirko@redhat.com\u003e\nCc: Paul E. McKenney \u003cpaulmck@us.ibm.com\u003e\nAcked-by: Steven Rostedt \u003crostedt@goodmis.org\u003e\nReviewed-by: Paul E. McKenney \u003cpaulmck@linux.vnet.ibm.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "5afd933cc476e33339eeca8928de1357857657ea",
      "tree": "4ccacdd6cafb4f0cd3b33488467cdbc3b55790c3",
      "parents": [
        "567a4ac4b7d48e186a28168e40388503d5b7eb01"
      ],
      "author": {
        "name": "Max.Nekludov@us.elster.com",
        "email": "Max.Nekludov@us.elster.com",
        "time": "Fri Mar 29 05:27:36 2013 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:41 2013 -0700"
      },
      "message": "ks8851: Fix interpretation of rxlen field.\n\n[ Upstream commit 14bc435ea54cb888409efb54fc6b76c13ef530e9 ]\n\nAccording to the Datasheet (page 52):\n15-12 Reserved\n11-0 RXBC Receive Byte Count\nThis field indicates the present received frame byte size.\n\nThe code has a bug:\n                 rxh \u003d ks8851_rdreg32(ks, KS_RXFHSR);\n                 rxstat \u003d rxh \u0026 0xffff;\n                 rxlen \u003d rxh \u003e\u003e 16; // BUG!!! 0xFFF mask should be applied\n\nSigned-off-by: Max Nekludov \u003cMax.Nekludov@us.elster.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "567a4ac4b7d48e186a28168e40388503d5b7eb01",
      "tree": "baa45bfd1c88169339885d48e00f461a5d7e889c",
      "parents": [
        "6a519979f9787fc326fd58dce983dda1cdf215dc"
      ],
      "author": {
        "name": "Hannes Frederic Sowa",
        "email": "hannes@stressinduktion.org",
        "time": "Tue Mar 26 08:13:34 2013 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:41 2013 -0700"
      },
      "message": "ipv6: don\u0027t accept node local multicast traffic from the wire\n\n[ Upstream commit 1c4a154e5253687c51123956dfcee9e9dfa8542d ]\n\nErik Hugne\u0027s errata proposal (Errata ID: 3480) to RFC4291 has been\nverified: http://www.rfc-editor.org/errata_search.php?eid\u003d3480\n\nWe have to check for pkt_type and loopback flag because either the\npackets are allowed to travel over the loopback interface (in which case\npkt_type is PACKET_HOST and IFF_LOOPBACK flag is set) or they travel\nover a non-loopback interface back to us (in which case PACKET_TYPE is\nPACKET_LOOPBACK and IFF_LOOPBACK flag is not set).\n\nSigned-off-by: Hannes Frederic Sowa \u003channes@stressinduktion.org\u003e\nCc: Erik Hugne \u003cerik.hugne@ericsson.com\u003e\nCc: YOSHIFUJI Hideaki \u003cyoshfuji@linux-ipv6.org\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "6a519979f9787fc326fd58dce983dda1cdf215dc",
      "tree": "f1171348f431d53b7c44d210382e7a916fe3160f",
      "parents": [
        "df19106f4574ba16d8575bbc206573f53cf1f4a9"
      ],
      "author": {
        "name": "Hong Zhiguo",
        "email": "honkiko@gmail.com",
        "time": "Tue Mar 26 01:52:45 2013 +0800"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:41 2013 -0700"
      },
      "message": "ipv6: fix bad free of addrconf_init_net\n\n[ Upstream commit a79ca223e029aa4f09abb337accf1812c900a800 ]\n\nSigned-off-by: Hong Zhiguo \u003chonkiko@gmail.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "df19106f4574ba16d8575bbc206573f53cf1f4a9",
      "tree": "2db506e318413dbda1d31a3c161631bbe2c0a93a",
      "parents": [
        "ccb926f51c4e5e4b79e5023c0c0735482ce18757"
      ],
      "author": {
        "name": "Hannes Frederic Sowa",
        "email": "hannes@stressinduktion.org",
        "time": "Sun Feb 10 05:35:22 2013 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:41 2013 -0700"
      },
      "message": "ipv6: don\u0027t accept multicast traffic with scope 0\n\n[ Upstream commit 20314092c1b41894d8c181bf9aa6f022be2416aa ]\n\nv2:\na) moved before multicast source address check\nb) changed comment to netdev style\n\nAcked-by: YOSHIFUJI Hideaki \u003cyoshfuji@linux-ipv6.org\u003e\nCc: Erik Hugne \u003cerik.hugne@ericsson.com\u003e\nCc: YOSHIFUJI Hideaki \u003cyoshfuji@linux-ipv6.org\u003e\nSigned-off-by: Hannes Frederic Sowa \u003channes@stressinduktion.org\u003e\nAcked-by: YOSHIFUJI Hideaki \u003cyoshfuji@linux-ipv6.org\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "ccb926f51c4e5e4b79e5023c0c0735482ce18757",
      "tree": "b3932aeacc5b0c0b9107488ebf7b04ed748161c6",
      "parents": [
        "98b3a5734c7dea6b62adae480bf6676fa128a19c"
      ],
      "author": {
        "name": "Joseph CHANG",
        "email": "josright123@gmail.com",
        "time": "Thu Mar 28 23:13:42 2013 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:40 2013 -0700"
      },
      "message": "DM9000B: driver initialization upgrade\n\n[ Upstream commit 6741f40d198c6a5feb23653a1efd4ca47f93d83d ]\n\nFix bug for DM9000 revision B which contain a DSP PHY\n\nDM9000B use DSP PHY instead previouse DM9000 revisions\u0027 analog PHY,\nSo need extra change in initialization, For\nexplicity PHY Reset and PHY init parameter, and\nfirst DM9000_NCR reset need NCR_MAC_LBK bit by dm9000_probe().\n\nFollowing DM9000_NCR reset cause by dm9000_open() clear the\nNCR_MAC_LBK bit.\n\nWithout this fix, Power-up FIFO pointers error happen around 2%\nrate among Davicom\u0027s customers\u0027 boards. With this fix, All above\ncases can be solved.\n\nSigned-off-by: Joseph CHANG \u003cjosright123@gmail.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "98b3a5734c7dea6b62adae480bf6676fa128a19c",
      "tree": "68b0f07628aecc32c141da326e8d1a920e72db0c",
      "parents": [
        "d97bcfae8bae32b72c12781fea0cf2ac1fd26776"
      ],
      "author": {
        "name": "Hannes Frederic Sowa",
        "email": "hannes@stressinduktion.org",
        "time": "Thu Mar 28 18:10:50 2013 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:40 2013 -0700"
      },
      "message": "atl1e: drop pci-msi support because of packet corruption\n\n[ Upstream commit 188ab1b105c96656f6bcfb49d0d8bb1b1936b632 ]\n\nUsage of pci-msi results in corrupted dma packet transfers to the host.\n\nReported-by: rebelyouth \u003crebelyouth.hacklab@gmail.com\u003e\nCc: Huang, Xiong \u003cxiong@qca.qualcomm.com\u003e\nTested-by: Christian Sünkenberg \u003cchristian.suenkenberg@student.kit.edu\u003e\nSigned-off-by: Hannes Frederic Sowa \u003channes@stressinduktion.org\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "d97bcfae8bae32b72c12781fea0cf2ac1fd26776",
      "tree": "0ffd6dd18e6855310480ff71c41d618727f108b5",
      "parents": [
        "a9304844277ca08288b54df5ee9201c5ce3e4cbf"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "edumazet@google.com",
        "time": "Wed Mar 27 18:28:41 2013 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:40 2013 -0700"
      },
      "message": "aoe: reserve enough headroom on skbs\n\n[ Upstream commit 91c5746425aed8f7188a351f1224a26aa232e4b3 ]\n\nSome network drivers use a non default hard_header_len\n\nTransmitted skb should take into account dev-\u003ehard_header_len, or risk\ncrashes or expensive reallocations.\n\nIn the case of aoe, lets reserve MAX_HEADER bytes.\n\nDavid reported a crash in defxx driver, solved by this patch.\n\nReported-by: David Oostdyk \u003cdaveo@ll.mit.edu\u003e\nTested-by: David Oostdyk \u003cdaveo@ll.mit.edu\u003e\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nCc: Ed Cashin \u003cecashin@coraid.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "a9304844277ca08288b54df5ee9201c5ce3e4cbf",
      "tree": "1bca8c782dbd681644066a6f512beacc8f41801c",
      "parents": [
        "71ec40e8f0a5eefca7b318f133f90dc4f2302c4f"
      ],
      "author": {
        "name": "Andrey Vagin",
        "email": "avagin@openvz.org",
        "time": "Thu Mar 21 20:33:46 2013 +0400"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:40 2013 -0700"
      },
      "message": "net: fix *_DIAG_MAX constants\n\n[ Upstream commit ae5fc98728c8bbbd6d7cab0b9781671fc4419c1b ]\n\nFollow the common pattern and define *_DIAG_MAX like:\n\n        [...]\n        __XXX_DIAG_MAX,\n};\n\nBecause everyone is used to do:\n\n        struct nlattr *attrs[XXX_DIAG_MAX+1];\n\n        nla_parse([...], XXX_DIAG_MAX, [...]\n\nReported-by: Thomas Graf \u003ctgraf@suug.ch\u003e\nCc: \"David S. Miller\" \u003cdavem@davemloft.net\u003e\nCc: Pavel Emelyanov \u003cxemul@parallels.com\u003e\nCc: Eric Dumazet \u003cedumazet@google.com\u003e\nCc: \"Paul E. McKenney\" \u003cpaulmck@linux.vnet.ibm.com\u003e\nCc: David Howells \u003cdhowells@redhat.com\u003e\nSigned-off-by: Andrey Vagin \u003cavagin@openvz.org\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "71ec40e8f0a5eefca7b318f133f90dc4f2302c4f",
      "tree": "3790a49b12117a10a522c0dbf6d9679d98aa3fee",
      "parents": [
        "86f1b8c36b64a22e4e21e542b99c8b9ef5e95694"
      ],
      "author": {
        "name": "Mugunthan V N",
        "email": "mugunthanvnm@ti.com",
        "time": "Wed Mar 27 04:41:59 2013 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:40 2013 -0700"
      },
      "message": "drivers: net: ethernet: cpsw: use netif_wake_queue() while restarting tx queue\n\n[ Upstream commit b56d6b3fca6d1214dbc9c5655f26e5d4ec04afc8 ]\n\nTo restart tx queue use netif_wake_queue() intead of netif_start_queue()\nso that net schedule will restart transmission immediately which will\nincrease network performance while doing huge data transfers.\n\nReported-by: Dan Franke \u003cdan.franke@schneider-electric.com\u003e\nSuggested-by: Sriramakrishnan A G \u003csrk@ti.com\u003e\nSigned-off-by: Mugunthan V N \u003cmugunthanvnm@ti.com\u003e\nAcked-by: Eric Dumazet \u003cedumazet@google.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "86f1b8c36b64a22e4e21e542b99c8b9ef5e95694",
      "tree": "362d9ef39612d64e955a0b3d65b9ee091dd9ae2e",
      "parents": [
        "ae8c63b03d7b70c0b65f1b6e304ed1976fb3019b"
      ],
      "author": {
        "name": "Mugunthan V N",
        "email": "mugunthanvnm@ti.com",
        "time": "Wed Mar 27 04:42:00 2013 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:40 2013 -0700"
      },
      "message": "drivers: net: ethernet: davinci_emac: use netif_wake_queue() while restarting tx queue\n\nTo restart tx queue use netif_wake_queue() intead of netif_start_queue()\nso that net schedule will restart transmission immediately which will\nincrease network performance while doing huge data transfers.\n\nReported-by: Dan Franke \u003cdan.franke@schneider-electric.com\u003e\nSuggested-by: Sriramakrishnan A G \u003csrk@ti.com\u003e\nSigned-off-by: Mugunthan V N \u003cmugunthanvnm@ti.com\u003e\nAcked-by: Eric Dumazet \u003cedumazet@google.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "ae8c63b03d7b70c0b65f1b6e304ed1976fb3019b",
      "tree": "89e31294541328af9027334a82afd6f38ea7019c",
      "parents": [
        "d98ea1888738fea067a1411eaefc46637f1dad8d"
      ],
      "author": {
        "name": "nikolay@redhat.com",
        "email": "nikolay@redhat.com",
        "time": "Wed Mar 27 03:32:41 2013 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:39 2013 -0700"
      },
      "message": "bonding: fix disabling of arp_interval and miimon\n\n[ Upstream commit 1bc7db16782c2a581fb4d53ca853631050f31611 ]\n\nCurrently if either arp_interval or miimon is disabled, they both get\ndisabled, and upon disabling they get executed once more which is not\nthe proper behaviour. Also when doing a no-op and disabling an already\ndisabled one, the other again gets disabled.\nAlso fix the error messages with the proper valid ranges, and a small\ntypo fix in the up delay error message (outputting \"down delay\", instead\nof \"up delay\").\n\nSigned-off-by: Nikolay Aleksandrov \u003cnikolay@redhat.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "d98ea1888738fea067a1411eaefc46637f1dad8d",
      "tree": "39b625ba1b41db9c0eceaba5328fbdae033bb3fe",
      "parents": [
        "b11b7d9b968aebaf70618db4393612784dfbebcd"
      ],
      "author": {
        "name": "nikolay@redhat.com",
        "email": "nikolay@redhat.com",
        "time": "Thu Nov 29 01:31:31 2012 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:39 2013 -0700"
      },
      "message": "bonding: fix miimon and arp_interval delayed work race conditions\n\n[ Upstream commit fbb0c41b814d497c656fc7be9e35456f139cb2fb ]\n\nFirst I would give three observations which will be used later.\nObservation 1: if (delayed_work_pending(wq)) cancel_delayed_work(wq)\n This usage is wrong because the pending bit is cleared just before the\n work\u0027s fn is executed and if the function re-arms itself we might end up\n with the work still running. It\u0027s safe to call cancel_delayed_work_sync()\n even if the work is not queued at all.\nObservation 2: Use of INIT_DELAYED_WORK()\n Work needs to be initialized only once prior to (de/en)queueing.\nObservation 3: IFF_UP is set only after ndo_open is called\n\nRelated race conditions:\n1. Race between bonding_store_miimon() and bonding_store_arp_interval()\n Because of Obs.1 we can end up having both works enqueued.\n2. Multiple races with INIT_DELAYED_WORK()\n Since the works are not protected by anything between INIT_DELAYED_WORK()\n and calls to (en/de)queue it is possible for races between the following\n functions:\n (races are also possible between the calls to INIT_DELAYED_WORK()\n  and workqueue code)\n bonding_store_miimon() - bonding_store_arp_interval(), bond_close(),\n\t\t\t  bond_open(), enqueued functions\n bonding_store_arp_interval() - bonding_store_miimon(), bond_close(),\n\t\t\t\tbond_open(), enqueued functions\n3. By Obs.1 we need to change bond_cancel_all()\n\nBugs 1 and 2 are fixed by moving all work initializations in bond_open\nwhich by Obs. 2 and Obs. 3 and the fact that we make sure that all works\nare cancelled in bond_close(), is guaranteed not to have any work\nenqueued.\nAlso RTNL lock is now acquired in bonding_store_miimon/arp_interval so\nthey can\u0027t race with bond_close and bond_open. The opposing work is\ncancelled only if the IFF_UP flag is set and it is cancelled\nunconditionally. The opposing work is already cancelled if the interface\nis down so no need to cancel it again. This way we don\u0027t need new\nsynchronizations for the bonding workqueue. These bugs (and fixes) are\ntied together and belong in the same patch.\nNote: I have left 1 line intentionally over 80 characters (84) because I\n      didn\u0027t like how it looks broken down. If you\u0027d prefer it otherwise,\n      then simply break it.\n\n v2: Make description text \u003c 75 columns\n\nSigned-off-by: Nikolay Aleksandrov \u003cnikolay@redhat.com\u003e\nSigned-off-by: Jay Vosburgh \u003cfubar@us.ibm.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "b11b7d9b968aebaf70618db4393612784dfbebcd",
      "tree": "1d4fb543c95b820bcebdff753694f9ea11906787",
      "parents": [
        "fbb7347e856f5116114c3ef5945980a3afab121e"
      ],
      "author": {
        "name": "Veaceslav Falico",
        "email": "vfalico@redhat.com",
        "time": "Tue Mar 26 17:43:28 2013 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:39 2013 -0700"
      },
      "message": "bonding: remove already created master sysfs link on failure\n\n[ Upstream commit 9fe16b78ee17579cb4f333534cf7043e94c67024 ]\n\nIf slave sysfs symlink failes to be created - we end up without removing\nthe master sysfs symlink. Remove it in case of failure.\n\nSigned-off-by: Veaceslav Falico \u003cvfalico@redhat.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "fbb7347e856f5116114c3ef5945980a3afab121e",
      "tree": "5a1c7ede9cfb8647f84ab20ad262fa97b7bb1159",
      "parents": [
        "b9f3bf1d0fe1e9ef11d1d607906138e9f84f7616"
      ],
      "author": {
        "name": "Paul Moore",
        "email": "pmoore@redhat.com",
        "time": "Mon Mar 25 03:18:33 2013 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:39 2013 -0700"
      },
      "message": "unix: fix a race condition in unix_release()\n\n[ Upstream commit ded34e0fe8fe8c2d595bfa30626654e4b87621e0 ]\n\nAs reported by Jan, and others over the past few years, there is a\nrace condition caused by unix_release setting the sock-\u003esk pointer\nto NULL before properly marking the socket as dead/orphaned.  This\ncan cause a problem with the LSM hook security_unix_may_send() if\nthere is another socket attempting to write to this partially\nreleased socket in between when sock-\u003esk is set to NULL and it is\nmarked as dead/orphaned.  This patch fixes this by only setting\nsock-\u003esk to NULL after the socket has been marked as dead; I also\ntake the opportunity to make unix_release_sock() a void function\nas it only ever returned 0/success.\n\nDave, I think this one should go on the -stable pile.\n\nSpecial thanks to Jan for coming up with a reproducer for this\nproblem.\n\nReported-by: Jan Stancek \u003cjan.stancek@gmail.com\u003e\nSigned-off-by: Paul Moore \u003cpmoore@redhat.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "b9f3bf1d0fe1e9ef11d1d607906138e9f84f7616",
      "tree": "34b9e1f7679eb5f563c0e506ff811d736878774c",
      "parents": [
        "a83417946df6c57fbb4d4383c992c5ffd59b56c2"
      ],
      "author": {
        "name": "Masatake YAMATO",
        "email": "yamato@redhat.com",
        "time": "Mon Apr 01 14:50:40 2013 -0400"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:38 2013 -0700"
      },
      "message": "thermal: shorten too long mcast group name\n\n[ Upstream commits 73214f5d9f33b79918b1f7babddd5c8af28dd23d\n  and f1e79e208076ffe7bad97158275f1c572c04f5c7, the latter\n  adds an assertion to genetlink to prevent this from happening\n  again in the future. ]\n\nThe original name is too long.\n\nSigned-off-by: Masatake YAMATO \u003cyamato@redhat.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "a83417946df6c57fbb4d4383c992c5ffd59b56c2",
      "tree": "b3f4589670a0d6846f498628eb76f4d881cf44ff",
      "parents": [
        "d1f60c6d91df21978218af4f5442993749ecbf7e"
      ],
      "author": {
        "name": "Cong Wang",
        "email": "amwang@redhat.com",
        "time": "Fri Mar 22 19:14:07 2013 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:38 2013 -0700"
      },
      "message": "8021q: fix a potential use-after-free\n\n[ Upstream commit 4a7df340ed1bac190c124c1601bfc10cde9fb4fb ]\n\nvlan_vid_del() could possibly free -\u003evlan_info after a RCU grace\nperiod, however, we may still refer to the freed memory area\nby \u0027grp\u0027 pointer. Found by code inspection.\n\nThis patch moves vlan_vid_del() as behind as possible.\n\nSigned-off-by: Cong Wang \u003camwang@redhat.com\u003e\nCc: Patrick McHardy \u003ckaber@trash.net\u003e\nCc: \"David S. Miller\" \u003cdavem@davemloft.net\u003e\nAcked-by: Eric Dumazet \u003cedumazet@google.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "d1f60c6d91df21978218af4f5442993749ecbf7e",
      "tree": "9a950b44637f7df25d1c79d50c4820500a3664aa",
      "parents": [
        "21b56e0f081f321334ef90d0d4ebe95e79d70a46"
      ],
      "author": {
        "name": "Yuchung Cheng",
        "email": "ycheng@google.com",
        "time": "Sun Mar 24 10:42:25 2013 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:38 2013 -0700"
      },
      "message": "tcp: undo spurious timeout after SACK reneging\n\n[ Upstream commit 7ebe183c6d444ef5587d803b64a1f4734b18c564 ]\n\nOn SACK reneging the sender immediately retransmits and forces a\ntimeout but disables Eifel (undo). If the (buggy) receiver does not\ndrop any packet this can trigger a false slow-start retransmit storm\ndriven by the ACKs of the original packets. This can be detected with\nundo and TCP timestamps.\n\nSigned-off-by: Yuchung Cheng \u003cycheng@google.com\u003e\nAcked-by: Neal Cardwell \u003cncardwell@google.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "21b56e0f081f321334ef90d0d4ebe95e79d70a46",
      "tree": "d2fc44f186394bc880f8ea497c657b4d8bb0abd0",
      "parents": [
        "8787606847fdd1402390fe603774873809a97c01"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "edumazet@google.com",
        "time": "Thu Mar 21 17:36:09 2013 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:38 2013 -0700"
      },
      "message": "tcp: preserve ACK clocking in TSO\n\n[ Upstream commit f4541d60a449afd40448b06496dcd510f505928e ]\n\nA long standing problem with TSO is the fact that tcp_tso_should_defer()\nrearms the deferred timer, while it should not.\n\nCurrent code leads to following bad bursty behavior :\n\n20:11:24.484333 IP A \u003e B: . 297161:316921(19760) ack 1 win 119\n20:11:24.484337 IP B \u003e A: . ack 263721 win 1117\n20:11:24.485086 IP B \u003e A: . ack 265241 win 1117\n20:11:24.485925 IP B \u003e A: . ack 266761 win 1117\n20:11:24.486759 IP B \u003e A: . ack 268281 win 1117\n20:11:24.487594 IP B \u003e A: . ack 269801 win 1117\n20:11:24.488430 IP B \u003e A: . ack 271321 win 1117\n20:11:24.489267 IP B \u003e A: . ack 272841 win 1117\n20:11:24.490104 IP B \u003e A: . ack 274361 win 1117\n20:11:24.490939 IP B \u003e A: . ack 275881 win 1117\n20:11:24.491775 IP B \u003e A: . ack 277401 win 1117\n20:11:24.491784 IP A \u003e B: . 316921:332881(15960) ack 1 win 119\n20:11:24.492620 IP B \u003e A: . ack 278921 win 1117\n20:11:24.493448 IP B \u003e A: . ack 280441 win 1117\n20:11:24.494286 IP B \u003e A: . ack 281961 win 1117\n20:11:24.495122 IP B \u003e A: . ack 283481 win 1117\n20:11:24.495958 IP B \u003e A: . ack 285001 win 1117\n20:11:24.496791 IP B \u003e A: . ack 286521 win 1117\n20:11:24.497628 IP B \u003e A: . ack 288041 win 1117\n20:11:24.498459 IP B \u003e A: . ack 289561 win 1117\n20:11:24.499296 IP B \u003e A: . ack 291081 win 1117\n20:11:24.500133 IP B \u003e A: . ack 292601 win 1117\n20:11:24.500970 IP B \u003e A: . ack 294121 win 1117\n20:11:24.501388 IP B \u003e A: . ack 295641 win 1117\n20:11:24.501398 IP A \u003e B: . 332881:351881(19000) ack 1 win 119\n\nWhile the expected behavior is more like :\n\n20:19:49.259620 IP A \u003e B: . 197601:202161(4560) ack 1 win 119\n20:19:49.260446 IP B \u003e A: . ack 154281 win 1212\n20:19:49.261282 IP B \u003e A: . ack 155801 win 1212\n20:19:49.262125 IP B \u003e A: . ack 157321 win 1212\n20:19:49.262136 IP A \u003e B: . 202161:206721(4560) ack 1 win 119\n20:19:49.262958 IP B \u003e A: . ack 158841 win 1212\n20:19:49.263795 IP B \u003e A: . ack 160361 win 1212\n20:19:49.264628 IP B \u003e A: . ack 161881 win 1212\n20:19:49.264637 IP A \u003e B: . 206721:211281(4560) ack 1 win 119\n20:19:49.265465 IP B \u003e A: . ack 163401 win 1212\n20:19:49.265886 IP B \u003e A: . ack 164921 win 1212\n20:19:49.266722 IP B \u003e A: . ack 166441 win 1212\n20:19:49.266732 IP A \u003e B: . 211281:215841(4560) ack 1 win 119\n20:19:49.267559 IP B \u003e A: . ack 167961 win 1212\n20:19:49.268394 IP B \u003e A: . ack 169481 win 1212\n20:19:49.269232 IP B \u003e A: . ack 171001 win 1212\n20:19:49.269241 IP A \u003e B: . 215841:221161(5320) ack 1 win 119\n\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nCc: Yuchung Cheng \u003cycheng@google.com\u003e\nCc: Van Jacobson \u003cvanj@google.com\u003e\nCc: Neal Cardwell \u003cncardwell@google.com\u003e\nCc: Nandita Dukkipati \u003cnanditad@google.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "8787606847fdd1402390fe603774873809a97c01",
      "tree": "a5d044aa3da7eaa9bcb39204e3bb1eac63a884dc",
      "parents": [
        "27d365a6d2c59816190a7cbde367b59bd2969232"
      ],
      "author": {
        "name": "Mirko Lindner",
        "email": "mlindner@marvell.com",
        "time": "Tue Mar 26 06:38:42 2013 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:38 2013 -0700"
      },
      "message": "sky2: Threshold for Pause Packet is set wrong\n\n[ Upstream commit 74f9f42c1c1650e74fb464f76644c9041f996851 ]\n\nThe sky2 driver sets the Rx Upper Threshold for Pause Packet generation to a\nwrong value which leads to only 2kB of RAM remaining space. This can lead to\nRx overflow errors even with activated flow-control.\n\nFix: We should increase the value to 8192/8\n\nSigned-off-by: Mirko Lindner \u003cmlindner@marvell.com\u003e\nAcked-by: Stephen Hemminger \u003cstephen@networkplumber.org\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "27d365a6d2c59816190a7cbde367b59bd2969232",
      "tree": "7e47599dcac42aae44bb08f2e82aa6fd4f0e8b1b",
      "parents": [
        "a897b791b846a7c023f6860d6e2477152244d486"
      ],
      "author": {
        "name": "Mirko Lindner",
        "email": "mlindner@marvell.com",
        "time": "Tue Mar 26 06:38:35 2013 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:37 2013 -0700"
      },
      "message": "sky2: Receive Overflows not counted\n\n[ Upstream commit 9cfe8b156c21cf340b3a10ecb3022fbbc1c39185 ]\n\nThe sky2 driver doesn\u0027t count the Receive Overflows because the MAC\ninterrupt for this event is not set in the MAC\u0027s interrupt mask.\nThe MAC\u0027s interrupt mask is set only for Transmit FIFO Underruns.\n\nFix: The correct setting should be (GM_IS_TX_FF_UR | GM_IS_RX_FF_OR)\nOtherwise the Receive Overflow event will not generate any interrupt.\nThe  Receive Overflow interrupt is handled correctly\n\nSigned-off-by: Mirko Lindner \u003cmlindner@marvell.com\u003e\nAcked-by: Stephen Hemminger \u003cstephen@networkplumber.org\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "a897b791b846a7c023f6860d6e2477152244d486",
      "tree": "7f7592b0daebe82153c6b2e698662ea788198b29",
      "parents": [
        "7b7cf9fa6d3406c1c7410afa861d524f732e4a7c"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "edumazet@google.com",
        "time": "Fri Mar 22 14:38:28 2013 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:37 2013 -0700"
      },
      "message": "net: remove a WARN_ON() in net_enable_timestamp()\n\n[ Upstream commit 9979a55a833883242e3a29f3596676edd7199c46 ]\n\nThe WARN_ON(in_interrupt()) in net_enable_timestamp() can get false\npositive, in socket clone path, run from softirq context :\n\n[ 3641.624425] WARNING: at net/core/dev.c:1532 net_enable_timestamp+0x7b/0x80()\n[ 3641.668811] Call Trace:\n[ 3641.671254]  \u003cIRQ\u003e  [\u003cffffffff80286817\u003e] warn_slowpath_common+0x87/0xc0\n[ 3641.677871]  [\u003cffffffff8028686a\u003e] warn_slowpath_null+0x1a/0x20\n[ 3641.683683]  [\u003cffffffff80742f8b\u003e] net_enable_timestamp+0x7b/0x80\n[ 3641.689668]  [\u003cffffffff80732ce5\u003e] sk_clone_lock+0x425/0x450\n[ 3641.695222]  [\u003cffffffff8078db36\u003e] inet_csk_clone_lock+0x16/0x170\n[ 3641.701213]  [\u003cffffffff807ae449\u003e] tcp_create_openreq_child+0x29/0x820\n[ 3641.707663]  [\u003cffffffff807d62e2\u003e] ? ipt_do_table+0x222/0x670\n[ 3641.713354]  [\u003cffffffff807aaf5b\u003e] tcp_v4_syn_recv_sock+0xab/0x3d0\n[ 3641.719425]  [\u003cffffffff807af63a\u003e] tcp_check_req+0x3da/0x530\n[ 3641.724979]  [\u003cffffffff8078b400\u003e] ? inet_hashinfo_init+0x60/0x80\n[ 3641.730964]  [\u003cffffffff807ade6f\u003e] ? tcp_v4_rcv+0x79f/0xbe0\n[ 3641.736430]  [\u003cffffffff807ab9bd\u003e] tcp_v4_do_rcv+0x38d/0x4f0\n[ 3641.741985]  [\u003cffffffff807ae14a\u003e] tcp_v4_rcv+0xa7a/0xbe0\n\nIts safe at this point because the parent socket owns a reference\non the netstamp_needed, so we cant have a 0 -\u003e 1 transition, which\nrequires to lock a mutex.\n\nInstead of refining the check, lets remove it, as all known callers\nare safe. If it ever changes in the future, static_key_slow_inc()\nwill complain anyway.\n\nReported-by: Laurent Chavey \u003cchavey@google.com\u003e\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "7b7cf9fa6d3406c1c7410afa861d524f732e4a7c",
      "tree": "0695fbf0df793cbc91d723893f77eafd60e31d10",
      "parents": [
        "2f6b6e28ca9af9c1f745efa9277e3e7c9ad64883"
      ],
      "author": {
        "name": "Steven Rostedt (Red Hat)",
        "email": "rostedt@goodmis.org",
        "time": "Thu Mar 14 15:03:53 2013 -0400"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:37 2013 -0700"
      },
      "message": "tracing: Prevent buffer overwrite disabled for latency tracers\n\ncommit 613f04a0f51e6e68ac6fe571ab79da3c0a5eb4da upstream.\n\nThe latency tracers require the buffers to be in overwrite mode,\notherwise they get screwed up. Force the buffers to stay in overwrite\nmode when latency tracers are enabled.\n\nAdded a flag_changed() method to the tracer structure to allow\nthe tracers to see what flags are being changed, and also be able\nto prevent the change from happing.\n\n[Backported for 3.4-stable. Re-added current_trace NULL checks; removed\nallocated_snapshot field; adapted to tracing_trace_options_write without\ntrace_set_options.]\n\nSigned-off-by: Steven Rostedt \u003crostedt@goodmis.org\u003e\nSigned-off-by: Lingzhu Xiang \u003clxiang@redhat.com\u003e\nReviewed-by: CAI Qian \u003ccaiqian@redhat.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "2f6b6e28ca9af9c1f745efa9277e3e7c9ad64883",
      "tree": "2e66c696fe47845e4d2f3ed4cd12d02441ddf9b5",
      "parents": [
        "2457a4005a53bd8d9a266ab8f9f6388b57ca133a"
      ],
      "author": {
        "name": "Steven Rostedt (Red Hat)",
        "email": "rostedt@goodmis.org",
        "time": "Thu Mar 14 13:50:56 2013 -0400"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:37 2013 -0700"
      },
      "message": "tracing: Protect tracer flags with trace_types_lock\n\ncommit 69d34da2984c95b33ea21518227e1f9470f11d95 upstream.\n\nSeems that the tracer flags have never been protected from\nsynchronous writes. Luckily, admins don\u0027t usually modify the\ntracing flags via two different tasks. But if scripts were to\nbe used to modify them, then they could get corrupted.\n\nMove the trace_types_lock that protects against tracers changing\nto also protect the flags being set.\n\n[Backported for 3.4, 3.0-stable. Moved return to after unlock.]\n\nSigned-off-by: Steven Rostedt \u003crostedt@goodmis.org\u003e\nSigned-off-by: Lingzhu Xiang \u003clxiang@redhat.com\u003e\nReviewed-by: CAI Qian \u003ccaiqian@redhat.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "2457a4005a53bd8d9a266ab8f9f6388b57ca133a",
      "tree": "02f579c0eca7f90e7c5dd0ca1d494676a1f8fb1f",
      "parents": [
        "46c14b9d861886d7abb66088ffeafa9301a34397"
      ],
      "author": {
        "name": "Theodore Ts\u0027o",
        "email": "tytso@mit.edu",
        "time": "Mon Mar 11 23:39:59 2013 -0400"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:37 2013 -0700"
      },
      "message": "ext4: use atomic64_t for the per-flexbg free_clusters count\n\ncommit 90ba983f6889e65a3b506b30dc606aa9d1d46cd2 upstream.\n\nA user who was using a 8TB+ file system and with a very large flexbg\nsize (\u003e 65536) could cause the atomic_t used in the struct flex_groups\nto overflow.  This was detected by PaX security patchset:\n\nhttp://forums.grsecurity.net/viewtopic.php?f\u003d3\u0026t\u003d3289\u0026p\u003d12551#p12551\n\nThis bug was introduced in commit 9f24e4208f7e, so it\u0027s been around\nsince 2.6.30.  :-(\n\nFix this by using an atomic64_t for struct orlav_stats\u0027s\nfree_clusters.\n\nSigned-off-by: \"Theodore Ts\u0027o\" \u003ctytso@mit.edu\u003e\nReviewed-by: Lukas Czerner \u003clczerner@redhat.com\u003e\nSigned-off-by: Lingzhu Xiang \u003clxiang@redhat.com\u003e\nReviewed-by: CAI Qian \u003ccaiqian@redhat.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "46c14b9d861886d7abb66088ffeafa9301a34397",
      "tree": "69e2b64b43849c8a936cdf807cd350ee7365b372",
      "parents": [
        "4025b05599996ca2866ceec0606c77d2ce2b4830"
      ],
      "author": {
        "name": "Lukas Czerner",
        "email": "lczerner@redhat.com",
        "time": "Sat Mar 02 17:18:58 2013 -0500"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:36 2013 -0700"
      },
      "message": "ext4: convert number of blocks to clusters properly\n\ncommit 810da240f221d64bf90020f25941b05b378186fe upstream.\n\nWe\u0027re using macro EXT4_B2C() to convert number of blocks to number of\nclusters for bigalloc file systems.  However, we should be using\nEXT4_NUM_B2C().\n\nSigned-off-by: Lukas Czerner \u003clczerner@redhat.com\u003e\nSigned-off-by: \"Theodore Ts\u0027o\" \u003ctytso@mit.edu\u003e\nSigned-off-by: CAI Qian \u003ccaiqian@redhat.com\u003e\nSigned-off-by: Lingzhu Xiang \u003clxiang@redhat.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "4025b05599996ca2866ceec0606c77d2ce2b4830",
      "tree": "6523ab5c94c5bb0d53b40fa4bd900a1ad4d38da0",
      "parents": [
        "5c44dddefa48c1a9541e3e451a0f395c6cc57ea0"
      ],
      "author": {
        "name": "Matt Fleming",
        "email": "matt.fleming@intel.com",
        "time": "Thu Mar 07 11:59:14 2013 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:36 2013 -0700"
      },
      "message": "efivars: Handle duplicate names from get_next_variable()\n\ncommit e971318bbed610e28bb3fde9d548e6aaf0a6b02e upstream.\n\nSome firmware exhibits a bug where the same VariableName and\nVendorGuid values are returned on multiple invocations of\nGetNextVariableName(). See,\n\n    https://bugzilla.kernel.org/show_bug.cgi?id\u003d47631\n\nAs a consequence of such a bug, Andre reports hitting the following\nWARN_ON() in the sysfs code after updating the BIOS on his, \"Gigabyte\nTechnology Co., Ltd. To be filled by O.E.M./Z77X-UD3H, BIOS F19e\n11/21/2012)\" machine,\n\n[    0.581554] EFI Variables Facility v0.08 2004-May-17\n[    0.584914] ------------[ cut here ]------------\n[    0.585639] WARNING: at /home/andre/linux/fs/sysfs/dir.c:536 sysfs_add_one+0xd4/0x100()\n[    0.586381] Hardware name: To be filled by O.E.M.\n[    0.587123] sysfs: cannot create duplicate filename \u0027/firmware/efi/vars/SbAslBufferPtrVar-01f33c25-764d-43ea-aeea-6b5a41f3f3e8\u0027\n[    0.588694] Modules linked in:\n[    0.589484] Pid: 1, comm: swapper/0 Not tainted 3.8.0+ #7\n[    0.590280] Call Trace:\n[    0.591066]  [\u003cffffffff81208954\u003e] ? sysfs_add_one+0xd4/0x100\n[    0.591861]  [\u003cffffffff810587bf\u003e] warn_slowpath_common+0x7f/0xc0\n[    0.592650]  [\u003cffffffff810588bc\u003e] warn_slowpath_fmt+0x4c/0x50\n[    0.593429]  [\u003cffffffff8134dd85\u003e] ? strlcat+0x65/0x80\n[    0.594203]  [\u003cffffffff81208954\u003e] sysfs_add_one+0xd4/0x100\n[    0.594979]  [\u003cffffffff81208b78\u003e] create_dir+0x78/0xd0\n[    0.595753]  [\u003cffffffff81208ec6\u003e] sysfs_create_dir+0x86/0xe0\n[    0.596532]  [\u003cffffffff81347e4c\u003e] kobject_add_internal+0x9c/0x220\n[    0.597310]  [\u003cffffffff81348307\u003e] kobject_init_and_add+0x67/0x90\n[    0.598083]  [\u003cffffffff81584a71\u003e] ? efivar_create_sysfs_entry+0x61/0x1c0\n[    0.598859]  [\u003cffffffff81584b2b\u003e] efivar_create_sysfs_entry+0x11b/0x1c0\n[    0.599631]  [\u003cffffffff8158517e\u003e] register_efivars+0xde/0x420\n[    0.600395]  [\u003cffffffff81d430a7\u003e] ? edd_init+0x2f5/0x2f5\n[    0.601150]  [\u003cffffffff81d4315f\u003e] efivars_init+0xb8/0x104\n[    0.601903]  [\u003cffffffff8100215a\u003e] do_one_initcall+0x12a/0x180\n[    0.602659]  [\u003cffffffff81d05d80\u003e] kernel_init_freeable+0x13e/0x1c6\n[    0.603418]  [\u003cffffffff81d05586\u003e] ? loglevel+0x31/0x31\n[    0.604183]  [\u003cffffffff816a6530\u003e] ? rest_init+0x80/0x80\n[    0.604936]  [\u003cffffffff816a653e\u003e] kernel_init+0xe/0xf0\n[    0.605681]  [\u003cffffffff816ce7ec\u003e] ret_from_fork+0x7c/0xb0\n[    0.606414]  [\u003cffffffff816a6530\u003e] ? rest_init+0x80/0x80\n[    0.607143] ---[ end trace 1609741ab737eb29 ]---\n\nThere\u0027s not much we can do to work around and keep traversing the\nvariable list once we hit this firmware bug. Our only solution is to\nterminate the loop because, as Lingzhu reports, some machines get\nstuck when they encounter duplicate names,\n\n  \u003e I had an IBM System x3100 M4 and x3850 X5 on which kernel would\n  \u003e get stuck in infinite loop creating duplicate sysfs files because,\n  \u003e for some reason, there are several duplicate boot entries in nvram\n  \u003e getting GetNextVariableName into a circle of iteration (with\n  \u003e period \u003e 2).\n\nAlso disable the workqueue, as efivar_update_sysfs_entries() uses\nGetNextVariableName() to figure out which variables have been created\nsince the last iteration. That algorithm isn\u0027t going to work if\nGetNextVariableName() returns duplicates. Note that we don\u0027t disable\nEFI variable creation completely on the affected machines, it\u0027s just\nthat any pstore dump-* files won\u0027t appear in sysfs until the next\nboot.\n\n[Backported for 3.4-stable. Removed code related to pstore\nworkqueue but pulled in helper function variable_is_present\nfrom a93bc0c; Moved the definition of __efivars to the top\nfor being referenced in variable_is_present.]\n\nReported-by: Andre Heider \u003ca.heider@gmail.com\u003e\nReported-by: Lingzhu Xiang \u003clxiang@redhat.com\u003e\nTested-by: Lingzhu Xiang \u003clxiang@redhat.com\u003e\nCc: Seiji Aguchi \u003cseiji.aguchi@hds.com\u003e\nSigned-off-by: Matt Fleming \u003cmatt.fleming@intel.com\u003e\nSigned-off-by: Lingzhu Xiang \u003clxiang@redhat.com\u003e\nReviewed-by: CAI Qian \u003ccaiqian@redhat.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n\n"
    },
    {
      "commit": "5c44dddefa48c1a9541e3e451a0f395c6cc57ea0",
      "tree": "3c2c88d6a239a890082b6d3042f2e22542342161",
      "parents": [
        "2ee4a8e3c9b8225703611097a0a410ca52de3d51"
      ],
      "author": {
        "name": "Matt Fleming",
        "email": "matt.fleming@intel.com",
        "time": "Fri Mar 01 14:49:12 2013 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:36 2013 -0700"
      },
      "message": "efivars: explicitly calculate length of VariableName\n\ncommit ec50bd32f1672d38ddce10fb1841cbfda89cfe9a upstream.\n\nIt\u0027s not wise to assume VariableNameSize represents the length of\nVariableName, as not all firmware updates VariableNameSize in the same\nway (some don\u0027t update it at all if EFI_SUCCESS is returned). There\nare even implementations out there that update VariableNameSize with\nvalues that are both larger than the string returned in VariableName\nand smaller than the buffer passed to GetNextVariableName(), which\nresulted in the following bug report from Michael Schroeder,\n\n  \u003e On HP z220 system (firmware version 1.54), some EFI variables are\n  \u003e incorrectly named :\n  \u003e\n  \u003e ls -d /sys/firmware/efi/vars/*8be4d* | grep -v -- -8be returns\n  \u003e /sys/firmware/efi/vars/dbxDefault-pport8be4df61-93ca-11d2-aa0d-00e098032b8c\n  \u003e /sys/firmware/efi/vars/KEKDefault-pport8be4df61-93ca-11d2-aa0d-00e098032b8c\n  \u003e /sys/firmware/efi/vars/SecureBoot-pport8be4df61-93ca-11d2-aa0d-00e098032b8c\n  \u003e /sys/firmware/efi/vars/SetupMode-Information8be4df61-93ca-11d2-aa0d-00e098032b8c\n\nThe issue here is that because we blindly use VariableNameSize without\nverifying its value, we can potentially read garbage values from the\nbuffer containing VariableName if VariableNameSize is larger than the\nlength of VariableName.\n\nSince VariableName is a string, we can calculate its size by searching\nfor the terminating NULL character.\n\n[Backported for 3.8-stable. Removed workqueue code added in\na93bc0c 3.9-rc1.]\n\nReported-by: Frederic Crozat \u003cfcrozat@suse.com\u003e\nCc: Matthew Garrett \u003cmjg59@srcf.ucam.org\u003e\nCc: Josh Boyer \u003cjwboyer@redhat.com\u003e\nCc: Michael Schroeder \u003cmls@suse.com\u003e\nCc: Lee, Chun-Yi \u003cjlee@suse.com\u003e\nCc: Lingzhu Xiang \u003clxiang@redhat.com\u003e\nCc: Seiji Aguchi \u003cseiji.aguchi@hds.com\u003e\nSigned-off-by: Matt Fleming \u003cmatt.fleming@intel.com\u003e\nSigned-off-by: Lingzhu Xiang \u003clxiang@redhat.com\u003e\nReviewed-by: CAI Qian \u003ccaiqian@redhat.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "2ee4a8e3c9b8225703611097a0a410ca52de3d51",
      "tree": "54ff51156d024dc286677555577b6769a0f64c26",
      "parents": [
        "3c7fe7b4421b23733eddfb53167c78c0bee71169"
      ],
      "author": {
        "name": "Josef Bacik",
        "email": "jbacik@fusionio.com",
        "time": "Mon Mar 25 16:03:35 2013 -0400"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:36 2013 -0700"
      },
      "message": "Btrfs: fix space leak when we fail to reserve metadata space\n\ncommit f4881bc7a83eff263789dd524b7c269d138d4af5 upstream.\n\nDave reported a warning when running xfstest 275.  We have been leaking delalloc\nmetadata space when our reservations fail.  This is because we were improperly\ncalculating how much space to free for our checksum reservations.  The problem\nis we would sometimes free up space that had already been freed in another\nthread and we would end up with negative usage for the delalloc space.  This\npatch fixes the problem by calculating how much space the other threads would\nhave already freed, and then calculate how much space we need to free had we not\ndone the reservation at all, and then freeing any excess space.  This makes\nxfstests 275 no longer have leaked space.  Thanks\n\nReported-by: David Sterba \u003cdsterba@suse.cz\u003e\nSigned-off-by: Josef Bacik \u003cjbacik@fusionio.com\u003e\nSigned-off-by: Lingzhu Xiang \u003clxiang@redhat.com\u003e\nReviewed-by: CAI Qian \u003ccaiqian@redhat.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "3c7fe7b4421b23733eddfb53167c78c0bee71169",
      "tree": "bb8658dff2d9603b67d47a62111db731cbd33ae7",
      "parents": [
        "49e67244a577002dcb37bbfdb0698a5306e769ec"
      ],
      "author": {
        "name": "Ville Syrjälä",
        "email": "ville.syrjala@linux.intel.com",
        "time": "Fri Feb 22 16:53:38 2013 +0200"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:36 2013 -0700"
      },
      "message": "drm/i915: Don\u0027t clobber crtc-\u003efb when queue_flip fails\n\ncommit 4a35f83b2b7c6aae3fc0d1c4554fdc99dc33ad07 upstream.\n\nRestore crtc-\u003efb to the old framebuffer if queue_flip fails.\n\nWhile at it, kill the pointless intel_fb temp variable.\n\nv2: Update crtc-\u003efb before queue_flip and restore it back\n    after a failure.\n\nBackported for 3.4-stable. Adjusted context only.\n\nSigned-off-by: Ville Syrjälä \u003cville.syrjala@linux.intel.com\u003e\nReviewed-by: Chris Wilson \u003cchris@chris-wilson.co.uk\u003e\nReported-and-Tested-by: Mika Kuoppala \u003cmika.kuoppala@intel.com\u003e\nSigned-off-by: Daniel Vetter \u003cdaniel.vetter@ffwll.ch\u003e\nSigned-off-by: Lingzhu Xiang \u003clxiang@redhat.com\u003e\nReviewed-by: CAI Qian \u003ccaiqian@redhat.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "49e67244a577002dcb37bbfdb0698a5306e769ec",
      "tree": "20fe7ca2a57f45fa66e99533dc52327087e09a1f",
      "parents": [
        "c14d7523633171e0a950047fe729ec2190c690b0"
      ],
      "author": {
        "name": "J. Bruce Fields",
        "email": "bfields@redhat.com",
        "time": "Tue Mar 26 14:11:13 2013 -0400"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:35 2013 -0700"
      },
      "message": "nfsd4: reject \"negative\" acl lengths\n\ncommit 64a817cfbded8674f345d1117b117f942a351a69 upstream.\n\nSince we only enforce an upper bound, not a lower bound, a \"negative\"\nlength can get through here.\n\nThe symptom seen was a warning when we attempt to a kmalloc with an\nexcessive size.\n\nReported-by: Toralf Förster \u003ctoralf.foerster@gmx.de\u003e\nSigned-off-by: J. Bruce Fields \u003cbfields@redhat.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "c14d7523633171e0a950047fe729ec2190c690b0",
      "tree": "26070306738b0583f62cb09f198690b0ef18da18",
      "parents": [
        "ccb3d567d5c7aef76879349a192339569da94c17"
      ],
      "author": {
        "name": "Mac Lin",
        "email": "mkl0301@gmail.com",
        "time": "Mon Mar 25 17:23:33 2013 +0800"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:35 2013 -0700"
      },
      "message": "ARM: cns3xxx: fix mapping of private memory region\n\ncommit a3d9052c6296ad3398d3ad649c3c682c3e7ecfa6 upstream.\n\nSince commit 0536bdf33faf (ARM: move iotable mappings within the vmalloc\nregion), the Cavium CNS3xxx cannot boot anymore.\n\nThis is caused by the pre-defined iotable mappings is not in the vmalloc\nregion. This patch move the iotable mappings into the vmalloc region, and\nmerge the MPCore private memory region (containing the SCU, the GIC and\nthe TWD) as a single region.\n\nSigned-off-by: Mac Lin \u003cmkl0301@gmail.com\u003e\nSigned-off-by: Anton Vorontsov \u003canton@enomsg.org\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "ccb3d567d5c7aef76879349a192339569da94c17",
      "tree": "b203946c299c34ab3cbf1472689448a55bae9e2c",
      "parents": [
        "39d4978d231b56c2c39ddb784a8eb8bd48311456"
      ],
      "author": {
        "name": "Anatol Pomozov",
        "email": "anatol.pomozov@gmail.com",
        "time": "Mon Apr 01 09:47:56 2013 -0700"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:35 2013 -0700"
      },
      "message": "loop: prevent bdev freeing while device in use\n\ncommit c1681bf8a7b1b98edee8b862a42c19c4e53205fd upstream.\n\nstruct block_device lifecycle is defined by its inode (see fs/block_dev.c) -\nblock_device allocated first time we access /dev/loopXX and deallocated on\nbdev_destroy_inode. When we create the device \"losetup /dev/loopXX afile\"\nwe want that block_device stay alive until we destroy the loop device\nwith \"losetup -d\".\n\nBut because we do not hold /dev/loopXX inode its counter goes 0, and\ninode/bdev can be destroyed at any moment. Usually it happens at memory\npressure or when user drops inode cache (like in the test below). When later in\nloop_clr_fd() we want to use bdev we have use-after-free error with following\nstack:\n\nBUG: unable to handle kernel NULL pointer dereference at 0000000000000280\n  bd_set_size+0x10/0xa0\n  loop_clr_fd+0x1f8/0x420 [loop]\n  lo_ioctl+0x200/0x7e0 [loop]\n  lo_compat_ioctl+0x47/0xe0 [loop]\n  compat_blkdev_ioctl+0x341/0x1290\n  do_filp_open+0x42/0xa0\n  compat_sys_ioctl+0xc1/0xf20\n  do_sys_open+0x16e/0x1d0\n  sysenter_dispatch+0x7/0x1a\n\nTo prevent use-after-free we need to grab the device in loop_set_fd()\nand put it later in loop_clr_fd().\n\nThe issue is reprodusible on current Linus head and v3.3. Here is the test:\n\n  dd if\u003d/dev/zero of\u003dloop.file bs\u003d1M count\u003d1\n  while [ true ]; do\n    losetup /dev/loop0 loop.file\n    echo 2 \u003e /proc/sys/vm/drop_caches\n    losetup -d /dev/loop0\n  done\n\n[ Doing bdgrab/bput in loop_set_fd/loop_clr_fd is safe, because every\n  time we call loop_set_fd() we check that loop_device-\u003elo_state is\n  Lo_unbound and set it to Lo_bound If somebody will try to set_fd again\n  it will get EBUSY.  And if we try to loop_clr_fd() on unbound loop\n  device we\u0027ll get ENXIO.\n\n  loop_set_fd/loop_clr_fd (and any other loop ioctl) is called under\n  loop_device-\u003elo_ctl_mutex. ]\n\nSigned-off-by: Anatol Pomozov \u003canatol.pomozov@gmail.com\u003e\nCc: Al Viro \u003cviro@zeniv.linux.org.uk\u003e\nSigned-off-by: Linus Torvalds \u003ctorvalds@linux-foundation.org\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "39d4978d231b56c2c39ddb784a8eb8bd48311456",
      "tree": "b2b828f1607da7e8ceb496aea6f869236a76ec3d",
      "parents": [
        "d50597f63bebaf9de515398c95f0ed4b88ea5224"
      ],
      "author": {
        "name": "Alan Stern",
        "email": "stern@rowland.harvard.edu",
        "time": "Fri Mar 15 14:02:14 2013 -0400"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:35 2013 -0700"
      },
      "message": "usb: gadget: udc-core: fix a regression during gadget driver unbinding\n\ncommit 511f3c5326eabe1ece35202a404c24c0aeacc246 upstream.\n\nThis patch (as1666) fixes a regression in the UDC core.  The core\ntakes care of unbinding gadget drivers, and it does the unbinding\nbefore telling the UDC driver to turn off the controller hardware.\nWhen the call to the udc_stop callback is made, the gadget no longer\nhas a driver.  The callback routine should not be invoked with a\npointer to the old driver; doing so can cause problems (such as\nuse-after-free accesses in net2280).\n\nThis patch should be applied, with appropriate context changes, to all\nthe stable kernels going back to 3.1.\n\nSigned-off-by: Alan Stern \u003cstern@rowland.harvard.edu\u003e\nSigned-off-by: Felipe Balbi \u003cbalbi@ti.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n\n"
    },
    {
      "commit": "d50597f63bebaf9de515398c95f0ed4b88ea5224",
      "tree": "ff991a07077d8e8732b53faa8e0cd163dea3c8e9",
      "parents": [
        "1c7b6ea87236a0c10943379a6476e2354c133cab"
      ],
      "author": {
        "name": "Josef Bacik",
        "email": "jbacik@fusionio.com",
        "time": "Fri Mar 29 08:09:34 2013 -0600"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:34 2013 -0700"
      },
      "message": "Btrfs: don\u0027t drop path when printing out tree errors in scrub\n\ncommit d8fe29e9dea8d7d61fd140d8779326856478fc62 upstream.\n\nA user reported a panic where we were panicing somewhere in\ntree_backref_for_extent from scrub_print_warning.  He only captured the trace\nbut looking at scrub_print_warning we drop the path right before we mess with\nthe extent buffer to print out a bunch of stuff, which isn\u0027t right.  So fix this\nby dropping the path after we use the eb if we need to.  Thanks,\n\nSigned-off-by: Josef Bacik \u003cjbacik@fusionio.com\u003e\nSigned-off-by: Chris Mason \u003cchris.mason@fusionio.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "1c7b6ea87236a0c10943379a6476e2354c133cab",
      "tree": "5dedda779b5d902ecb288893e0a1043086b22804",
      "parents": [
        "84519c0cb119e2a025dc6496440acedc855d9b21"
      ],
      "author": {
        "name": "Josef Bacik",
        "email": "jbacik@fusionio.com",
        "time": "Tue Mar 26 15:31:45 2013 -0400"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:34 2013 -0700"
      },
      "message": "Btrfs: limit the global reserve to 512mb\n\ncommit fdf30d1c1b386e1b73116cc7e0fb14e962b763b0 upstream.\n\nA user reported a problem where he was getting early ENOSPC with hundreds of\ngigs of free data space and 6 gigs of free metadata space.  This is because the\nglobal block reserve was taking up the entire free metadata space.  This is\nridiculous, we have infrastructure in place to throttle if we start using too\nmuch of the global reserve, so instead of letting it get this huge just limit it\nto 512mb so that users can still get work done.  This allowed the user to\ncomplete his rsync without issues.  Thanks\n\nReported-and-tested-by: Stefan Priebe \u003cs.priebe@profihost.ag\u003e\nSigned-off-by: Josef Bacik \u003cjbacik@fusionio.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "84519c0cb119e2a025dc6496440acedc855d9b21",
      "tree": "b01bbab183ce84a817b90fd59d7176fb5a7a0cfe",
      "parents": [
        "e18e8665134f6adb079861d3676e7d838ce658ca"
      ],
      "author": {
        "name": "Chris Mason",
        "email": "chris.mason@fusionio.com",
        "time": "Tue Mar 26 13:07:00 2013 -0400"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:34 2013 -0700"
      },
      "message": "Btrfs: fix race between mmap writes and compression\n\ncommit 4adaa611020fa6ac65b0ac8db78276af4ec04e63 upstream.\n\nBtrfs uses page_mkwrite to ensure stable pages during\ncrc calculations and mmap workloads.  We call clear_page_dirty_for_io\nbefore we do any crcs, and this forces any application with the file\nmapped to wait for the crc to finish before it is allowed to change\nthe file.\n\nWith compression on, the clear_page_dirty_for_io step is happening after\nwe\u0027ve compressed the pages.  This means the applications might be\nchanging the pages while we are compressing them, and some of those\nmodifications might not hit the disk.\n\nThis commit adds the clear_page_dirty_for_io before compression starts\nand makes sure to redirty the page if we have to fallback to\nuncompressed IO as well.\n\nSigned-off-by: Chris Mason \u003cchris.mason@fusionio.com\u003e\nReported-by: Alexandre Oliva \u003coliva@gnu.org\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "e18e8665134f6adb079861d3676e7d838ce658ca",
      "tree": "4ea0ad1c6aefb494f8704cebfb8f373461be9cee",
      "parents": [
        "afc309756f7bf90739eb24f04ce302ea70a69645"
      ],
      "author": {
        "name": "Vivek Gautam",
        "email": "gautam.vivek@samsung.com",
        "time": "Thu Mar 21 12:06:48 2013 +0530"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:34 2013 -0700"
      },
      "message": "usb: xhci: Fix TRB transfer length macro used for Event TRB.\n\ncommit 1c11a172cb30492f5f6a82c6e118fdcd9946c34f upstream.\n\nUse proper macro while extracting TRB transfer length from\nTransfer event TRBs. Adding a macro EVENT_TRB_LEN (bits 0:23)\nfor the same, and use it instead of TRB_LEN (bits 0:16) in\ncase of event TRBs.\n\nThis patch should be backported to kernels as old as 2.6.31, that\ncontain the commit b10de142119a676552df3f0d2e3a9d647036c26a \"USB: xhci:\nBulk transfer support\".  This patch will have issues applying to older\nkernels.\n\nSigned-off-by: Vivek gautam \u003cgautam.vivek@samsung.com\u003e\nSigned-off-by: Sarah Sharp \u003csarah.a.sharp@linux.intel.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "afc309756f7bf90739eb24f04ce302ea70a69645",
      "tree": "3e2cc986b43b34cced6dd0f9a0d99a0b86cb8d0a",
      "parents": [
        "75e4839c59268b4880b82fa9584980478ef8ca29"
      ],
      "author": {
        "name": "Kees Cook",
        "email": "keescook@chromium.org",
        "time": "Wed Mar 20 05:19:24 2013 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:34 2013 -0700"
      },
      "message": "net/irda: add missing error path release_sock call\n\ncommit 896ee0eee6261e30c3623be931c3f621428947df upstream.\n\nThis makes sure that release_sock is called for all error conditions in\nirda_getsockopt.\n\nSigned-off-by: Kees Cook \u003ckeescook@chromium.org\u003e\nReported-by: Brad Spengler \u003cspender@grsecurity.net\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "75e4839c59268b4880b82fa9584980478ef8ca29",
      "tree": "53983ab75f76f64d684f2ff1b899dd831b54877f",
      "parents": [
        "e92c5efcb2af2afe9a7fa297dcc325f8d04469b3"
      ],
      "author": {
        "name": "fanchaoting",
        "email": "fanchaoting@cn.fujitsu.com",
        "time": "Thu Mar 21 09:15:30 2013 +0800"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:30 2013 -0700"
      },
      "message": "pnfs-block: removing DM device maybe cause oops when call dev_remove\n\ncommit 4376c94618c26225e69e17b7c91169c45a90b292 upstream.\n\nwhen pnfs block using device mapper,if umounting later,it maybe\ncause oops. we apply \"1 + sizeof(bl_umount_request)\" memory for\nmsg-\u003edata, the memory maybe overflow when we do \"memcpy(\u0026dataptr\n[sizeof(bl_msg)], \u0026bl_umount_request, sizeof(bl_umount_request))\",\nbecause the size of bl_msg is more than 1 byte.\n\nSigned-off-by: fanchaoting\u003cfanchaoting@cn.fujitsu.com\u003e\nSigned-off-by: Trond Myklebust \u003cTrond.Myklebust@netapp.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "e92c5efcb2af2afe9a7fa297dcc325f8d04469b3",
      "tree": "bdc3065b60cba31201aa2d078f55ff6c37033e29",
      "parents": [
        "86302600f82d715647154e18a96245642f1bf71e"
      ],
      "author": {
        "name": "Bing Zhao",
        "email": "bzhao@marvell.com",
        "time": "Fri Mar 15 18:47:07 2013 -0700"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:19 2013 -0700"
      },
      "message": "mwifiex: cancel cmd timer and free curr_cmd in shutdown process\n\ncommit 084c7189acb3f969c855536166042e27f5dd703f upstream.\n\ncurr_cmd points to the command that is in processing or waiting\nfor its command response from firmware. If the function shutdown\nhappens to occur at this time we should cancel the cmd timer and\nput the command back to free queue.\n\nTested-by: Marco Cesarano \u003cmarco@marvell.com\u003e\nSigned-off-by: Bing Zhao \u003cbzhao@marvell.com\u003e\nSigned-off-by: John W. Linville \u003clinville@tuxdriver.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "86302600f82d715647154e18a96245642f1bf71e",
      "tree": "b586260ea3bcd7a9e94fd328b53f0c12280efcb3",
      "parents": [
        "840d38a30d24c15fa29555f10a114feeff02cd80"
      ],
      "author": {
        "name": "Al Viro",
        "email": "viro@zeniv.linux.org.uk",
        "time": "Tue Mar 26 20:30:17 2013 -0400"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:19 2013 -0700"
      },
      "message": "vt: synchronize_rcu() under spinlock is not nice...\n\ncommit e8cd81693bbbb15db57d3c9aa7dd90eda4842874 upstream.\n\nvcs_poll_data_free() calls unregister_vt_notifier(), which calls\natomic_notifier_chain_unregister(), which calls synchronize_rcu().\nDo it *after* we\u0027d dropped -\u003ef_lock.\n\nSigned-off-by: Al Viro \u003cviro@zeniv.linux.org.uk\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "840d38a30d24c15fa29555f10a114feeff02cd80",
      "tree": "23220c9faa6be48ce66032fd7a61c2273b20fc5f",
      "parents": [
        "d32cdd3f703100a028276ac9a6afb848a203906e"
      ],
      "author": {
        "name": "Konstantin Holoborodko",
        "email": "klh.kernel@gmail.com",
        "time": "Fri Mar 29 00:06:13 2013 +0900"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:19 2013 -0700"
      },
      "message": "usb: ftdi_sio: Add support for Mitsubishi FX-USB-AW/-BD\n\ncommit 482b0b5d82bd916cc0c55a2abf65bdc69023b843 upstream.\n\nIt enhances the driver for FTDI-based USB serial adapters\nto recognize Mitsubishi Electric Corp. USB/RS422 Converters\nas FT232BM chips and support them.\nhttps://search.meau.com/?q\u003dFX-USB-AW\n\nSigned-off-by: Konstantin Holoborodko \u003cklh.kernel@gmail.com\u003e\nTested-by: Konstantin Holoborodko \u003cklh.kernel@gmail.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "d32cdd3f703100a028276ac9a6afb848a203906e",
      "tree": "d21122dc249427f765bc56a4dce0cf97edae5db5",
      "parents": [
        "2f21ae28ec704aa79dbbb912f20dd687ca0c001c"
      ],
      "author": {
        "name": "Pawel Wieczorkiewicz",
        "email": "wpawel@gmail.com",
        "time": "Wed Feb 20 17:26:20 2013 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:18 2013 -0700"
      },
      "message": "tty: atmel_serial_probe(): index of atmel_ports[] fix\n\ncommit 503bded92da283b2f31d87e054c4c6d30c3c2340 upstream.\n\nIndex of atmel_ports[ATMEL_MAX_UART] should be smaller\nthan ATMEL_MAX_UART.\n\nSigned-off-by: Pawel Wieczorkiewicz \u003cwpawel@gmail.com\u003e\nAcked-by: Nicolas Ferre \u003cnicolas.ferre@atmel.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "2f21ae28ec704aa79dbbb912f20dd687ca0c001c",
      "tree": "ee8b60e8b1d33942e8446145c1bcd3aeae6d8b51",
      "parents": [
        "119016c59b6a83cf168f0f1202f2251122f0d5b3"
      ],
      "author": {
        "name": "Jan Beulich",
        "email": "JBeulich@suse.com",
        "time": "Mon Mar 11 09:39:55 2013 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:18 2013 -0700"
      },
      "message": "xen-blkback: fix dispatch_rw_block_io() error path\n\ncommit 0e5e098ac22dae38f957e951b70d3cf73beff0f7 upstream.\n\nCommit 7708992 (\"xen/blkback: Seperate the bio allocation and the bio\nsubmission\") consolidated the pendcnt updates to just a single write,\nneglecting the fact that the error path relied on it getting set to 1\nup front (such that the decrement in __end_block_io_op() would actually\ndrop the count to zero, triggering the necessary cleanup actions).\n\nAlso remove a misleading and a stale (after said commit) comment.\n\nSigned-off-by: Jan Beulich \u003cjbeulich@suse.com\u003e\nSigned-off-by: Konrad Rzeszutek Wilk \u003ckonrad.wilk@oracle.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "119016c59b6a83cf168f0f1202f2251122f0d5b3",
      "tree": "8a9ccdc968b15db1a845276aaa9be4492c8b2986",
      "parents": [
        "2c0260b234031e0dd0266baafbc4d8e1eb580bb6"
      ],
      "author": {
        "name": "David Vrabel",
        "email": "david.vrabel@citrix.com",
        "time": "Thu Mar 07 17:32:01 2013 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:18 2013 -0700"
      },
      "message": "xen/blkback: correctly respond to unknown, non-native requests\n\ncommit 0e367ae46503cfe7791460c8ba8434a5d60b2bd5 upstream.\n\nIf the frontend is using a non-native protocol (e.g., a 64-bit\nfrontend with a 32-bit backend) and it sent an unrecognized request,\nthe request was not translated and the response would have the\nincorrect ID.  This may cause the frontend driver to behave\nincorrectly or crash.\n\nSince the ID field in the request is always in the same place,\nregardless of the request type we can get the correct ID and make a\nvalid response (which will report BLKIF_RSP_EOPNOTSUPP).\n\nThis bug affected 64-bit SLES 11 guests when using a 32-bit backend.\nThis guest does a BLKIF_OP_RESERVED_1 (BLKIF_OP_PACKET in the SLES\nsource) and would crash in blkif_int() as the ID in the response would\nbe invalid.\n\nSigned-off-by: David Vrabel \u003cdavid.vrabel@citrix.com\u003e\nSigned-off-by: Konrad Rzeszutek Wilk \u003ckonrad.wilk@oracle.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "2c0260b234031e0dd0266baafbc4d8e1eb580bb6",
      "tree": "9bf15f7e6d8e03f6f4713679aea140f39b7b19a4",
      "parents": [
        "60f18f483ee41bfc61d31b9da18f91fd19ab872b"
      ],
      "author": {
        "name": "Joerg Roedel",
        "email": "joro@8bytes.org",
        "time": "Tue Mar 26 22:48:23 2013 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:18 2013 -0700"
      },
      "message": "iommu/amd: Make sure dma_ops are set for hotplug devices\n\ncommit c2a2876e863356b092967ea62bebdb4dd663af80 upstream.\n\nThere is a bug introduced with commit 27c2127 that causes\ndevices which are hot unplugged and then hot-replugged to\nnot have per-device dma_ops set. This causes these devices\nto not function correctly. Fixed with this patch.\n\nReported-by: Andreas Degert \u003candreas.degert@googlemail.com\u003e\nSigned-off-by: Joerg Roedel \u003cjoro@8bytes.org\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "60f18f483ee41bfc61d31b9da18f91fd19ab872b",
      "tree": "b30e00edaffe40f877d02a29744dd4d950b787cd",
      "parents": [
        "554293beaa09b578559058834e72725f977cebd0"
      ],
      "author": {
        "name": "Kees Cook",
        "email": "keescook@chromium.org",
        "time": "Wed Mar 27 06:40:50 2013 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:18 2013 -0700"
      },
      "message": "tg3: fix length overflow in VPD firmware parsing\n\ncommit 715230a44310a8cf66fbfb5a46f9a62a9b2de424 upstream.\n\nCommit 184b89044fb6e2a74611dafa69b1dce0d98612c6 (\"tg3: Use VPD fw version\nwhen present\") introduced VPD parsing that contained a potential length\noverflow.\n\nLimit the hardware\u0027s reported firmware string length (max 255 bytes) to\nstay inside the driver\u0027s firmware string length (32 bytes). On overflow,\ntruncate the formatted firmware string instead of potentially overwriting\nportions of the tg3 struct.\n\nhttp://cansecwest.com/slides/2013/PrivateCore%20CSW%202013.pdf\n\nSigned-off-by: Kees Cook \u003ckeescook@chromium.org\u003e\nReported-by: Oded Horovitz \u003coded@privatecore.com\u003e\nReported-by: Brad Spengler \u003cspender@grsecurity.net\u003e\nCc: Matt Carlson \u003cmcarlson@broadcom.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "554293beaa09b578559058834e72725f977cebd0",
      "tree": "08530407ad86de616ad054c0441e9baff3106cd5",
      "parents": [
        "123dad7cf60c6c584d50cea021668d07b6a33e42"
      ],
      "author": {
        "name": "Rafał Miłecki",
        "email": "zajec5@gmail.com",
        "time": "Wed Mar 27 08:37:08 2013 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:17 2013 -0700"
      },
      "message": "b43: N-PHY: use more bits for offset in RSSI calibration\n\ncommit 2e1253d640eb7f8707d2591c93097c1e9f9c71d5 upstream.\n\nWhen calculating \"offset\" for final RSSI calibration we\u0027re using numbers\nbigger than s8 can hold. We have for example:\noffset[j] \u003d 232 - poll_results[j];\nformula. If poll_results[j] is small enough (it usually is) we treat\nnumber\u0027s bit as a sign bit. For example 232 - 1 becomes:\n0xE8 - 0x1 \u003d 0xE7, which is not 231 but -25.\n\nThis code was introduced in e0c9a0219a8f542e3946fe972a68aacf8c3f906c\nand caused stability regression on some cards, for ex. BCM4322.\n\nSigned-off-by: Rafał Miłecki \u003czajec5@gmail.com\u003e\nSigned-off-by: John W. Linville \u003clinville@tuxdriver.com\u003e\n\n"
    },
    {
      "commit": "123dad7cf60c6c584d50cea021668d07b6a33e42",
      "tree": "466d26938a97e5678a25681b75d00302d82613a2",
      "parents": [
        "0883afbbe42455096931bb976bbf1418b94f3f77"
      ],
      "author": {
        "name": "Iestyn C. Elfick",
        "email": "isedev@gmail.com",
        "time": "Wed Mar 20 14:02:31 2013 -0500"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:17 2013 -0700"
      },
      "message": "b43: A fix for DMA transmission sequence errors\n\ncommit b251412db99ccd4495ce372fec7daee27bf06923 upstream.\n\nIntermittently, b43 will report \"Out of order TX status report on DMA ring\".\nWhen this happens, the driver must be reset before communication can resume.\nThe cause of the problem is believed to be an error in the closed-source\nfirmware; however, all versions of the firmware are affected.\n\nThis change uses the observation that the expected status is always 2 less\nthan the observed value, and supplies a fake status report to skip one\nheader/data pair.\n\nNot all devices suffer from this problem, but it can occur several times\nper second under heavy load. As each occurence kills the unmodified driver,\nthis patch makes if possible for the affected devices to function. The patch\nlogs only the first instance of the reset operation to prevent spamming\nthe logs.\n\nTested-by: Chris Vine \u003cchris@cvine.freeserve.co.uk\u003e\nSigned-off-by: Larry Finger \u003cLarry.Finger@lwfinger.net\u003e\nSigned-off-by: John W. Linville \u003clinville@tuxdriver.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "0883afbbe42455096931bb976bbf1418b94f3f77",
      "tree": "134f8234837ad35ce801887a89e6036a379c350b",
      "parents": [
        "e401e130f3510a254e4018db71f5272f7118879a"
      ],
      "author": {
        "name": "Rafał Miłecki",
        "email": "zajec5@gmail.com",
        "time": "Tue Mar 19 07:52:48 2013 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:17 2013 -0700"
      },
      "message": "b43: N-PHY: increase initial value of \"mind\" in RSSI calibration\n\ncommit e67dd874e60529dbd2e8232babb1e23479ba2ffa upstream.\n\nWe\u0027re using \"mind\" variable to find the VCM that got the best polling\nresults. For each VCM we calculte \"currd\" which is compared to the\n\"mind\". For PHY rev3+ \"currd\" gets values around 14k-40k. Looking for a\nvalue smaller than 40 makes no sense, so increase the initial value.\n\nThis fixes a regression introduced in 3.4 by commit:\ne0c9a0219a8f542e3946fe972a68aacf8c3f906c\n(my BCM4322 performance dropped from 18,4Mb/s to 9,26Mb/s)\n\nSigned-off-by: Rafał Miłecki \u003czajec5@gmail.com\u003e\nSigned-off-by: John W. Linville \u003clinville@tuxdriver.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "e401e130f3510a254e4018db71f5272f7118879a",
      "tree": "4b51eb3c33c8df0e0f5c3684a292bca59865d6f7",
      "parents": [
        "698d31b7a08e5ff83ce58eb45744ce3ee846b0fe"
      ],
      "author": {
        "name": "Jussi Kivilinna",
        "email": "jussi.kivilinna@iki.fi",
        "time": "Sun Mar 17 11:54:04 2013 +0200"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:17 2013 -0700"
      },
      "message": "rtlwifi: usb: add missing freeing of skbuff\n\ncommit 36ef0b473fbf43d5db23eea4616cc1d18cec245f upstream.\n\nSigned-off-by: Jussi Kivilinna \u003cjussi.kivilinna@iki.fi\u003e\nAcked-by: Larry Finger \u003cLarry.Finger@lwfinger.net\u003e\nSigned-off-by: John W. Linville \u003clinville@tuxdriver.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "698d31b7a08e5ff83ce58eb45744ce3ee846b0fe",
      "tree": "acd4eeccd65a77e21729e834a54488ce9b56ea3b",
      "parents": [
        "50506331604d0eed543027940b326566edb92719"
      ],
      "author": {
        "name": "Josh Boyer",
        "email": "jwboyer@redhat.com",
        "time": "Mon Mar 18 09:45:42 2013 -0400"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:16 2013 -0700"
      },
      "message": "HID: usbhid: quirk for Realtek Multi-card reader\n\ncommit 3d464d9b71ef2f2b40a4bc9dcf06794fd1be9d12 upstream.\n\nThis device needs to be added to the quirks list with HID_QUIRK_NO_INIT_REPORTS,\notherwise it causes 10 seconds timeout during report initialization.\n\nThis fixes Red Hat bugzilla https://bugzilla.redhat.com/show_bug.cgi?id\u003d806587\n\nSigned-off-by: Josh Boyer \u003cjwboyer@redhat.com\u003e\nSigned-off-by: Jiri Kosina \u003cjkosina@suse.cz\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "50506331604d0eed543027940b326566edb92719",
      "tree": "a5da2e8d6734685d5df9918a398dd89a54eb921b",
      "parents": [
        "bb4619ed5fd25a8ec2dd5f8841c9e3662539af26"
      ],
      "author": {
        "name": "Felix Fietkau",
        "email": "nbd@openwrt.org",
        "time": "Fri Mar 15 14:53:31 2013 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:16 2013 -0700"
      },
      "message": "ath9k_hw: revert chainmask to user configuration after calibration\n\ncommit 74632d11a133b5baf6b9d622dd19d2f944d93d94 upstream.\n\nThe commit \u0027ath9k_hw: fix calibration issues on chainmask that don\u0027t\ninclude chain 0\u0027 changed the hardware chainmask to the chip chainmask\nfor the duration of the calibration, but the revert to user\nconfiguration in the reset path runs too early.\n\nThat causes some issues with limiting the number of antennas (including\nspurious failure in hardware-generated packets).\n\nFix this by reverting the chainmask after the essential parts of the\ncalibration that need the workaround, and before NF calibration is run.\n\nSigned-off-by: Felix Fietkau \u003cnbd@openwrt.org\u003e\nReported-by: Wojciech Dubowik \u003cWojciech.Dubowik@neratec.com\u003e\nTested-by: Wojciech Dubowik \u003cWojciech.Dubowik@neratec.com\u003e\nSigned-off-by: John W. Linville \u003clinville@tuxdriver.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "bb4619ed5fd25a8ec2dd5f8841c9e3662539af26",
      "tree": "bd6545e7166c823f88e2c846f589efb6aef8deda",
      "parents": [
        "cde9833c97c4ad06e569e1f0e7e6b1c84c948aa3"
      ],
      "author": {
        "name": "Marc Kleine-Budde",
        "email": "mkl@pengutronix.de",
        "time": "Wed Mar 27 11:36:42 2013 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:16 2013 -0700"
      },
      "message": "can: sja1000: fix define conflict on SH\n\ncommit f901b6bc404b67d96eca739857c097e022727b71 upstream.\n\nThias patch fixes a define conflict between the SH architecture and the sja1000\ndriver:\n\n    drivers/net/can/sja1000/sja1000.h:59:0: warning:\n        \"REG_SR\" redefined [enabled by default]\n    arch/sh/include/asm/ptrace_32.h:25:0: note:\n         this is the location of the previous definition\n\nA SJA1000_ prefix is added to the offending sja1000 define only, to make a\nminimal patch suited for stable. A later patch will add a SJA1000_ prefix to\nall defines in sja1000.h.\n\nReported-by: Fengguang Wu \u003cfengguang.wu@intel.com\u003e\nSigned-off-by: Marc Kleine-Budde \u003cmkl@pengutronix.de\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "cde9833c97c4ad06e569e1f0e7e6b1c84c948aa3",
      "tree": "f3331bd49143517413c85326385409ec45110890",
      "parents": [
        "01fadbb46b6da196c594ac2266674136cda465a6"
      ],
      "author": {
        "name": "Ming Lei",
        "email": "ming.lei@canonical.com",
        "time": "Wed Mar 20 23:25:25 2013 +0800"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:16 2013 -0700"
      },
      "message": "sysfs: handle failure path correctly for readdir()\n\ncommit e5110f411d2ee35bf8d202ccca2e89c633060dca upstream.\n\nIn case of \u0027if (filp-\u003ef_pos \u003d\u003d  0 or 1)\u0027 of sysfs_readdir(),\nthe failure from filldir() isn\u0027t handled, and the reference counter\nof the sysfs_dirent object pointed by filp-\u003eprivate_data will be\nreleased without clearing filp-\u003eprivate_data, so use after free\nbug will be triggered later.\n\nThis patch returns immeadiately under the situation for fixing the bug,\nand it is reasonable to return from readdir() when filldir() fails.\n\nReported-by: Dave Jones \u003cdavej@redhat.com\u003e\nTested-by: Sasha Levin \u003clevinsasha928@gmail.com\u003e\nSigned-off-by: Ming Lei \u003cming.lei@canonical.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "01fadbb46b6da196c594ac2266674136cda465a6",
      "tree": "d6618c8c8da329a875715c42dd37e913ffd6c90e",
      "parents": [
        "d8022cb2b0ea2e5d926c9e2a041e411d71fd3d9e"
      ],
      "author": {
        "name": "Ming Lei",
        "email": "ming.lei@canonical.com",
        "time": "Wed Mar 20 23:25:24 2013 +0800"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:16 2013 -0700"
      },
      "message": "sysfs: fix race between readdir and lseek\n\ncommit 991f76f837bf22c5bb07261cfd86525a0a96650c upstream.\n\nWhile readdir() is running, lseek() may set filp-\u003ef_pos as zero,\nthen may leave filp-\u003eprivate_data pointing to one sysfs_dirent\nobject without holding its reference counter, so the sysfs_dirent\nobject may be used after free in next readdir().\n\nThis patch holds inode-\u003ei_mutex to avoid the problem since\nthe lock is always held in readdir path.\n\nReported-by: Dave Jones \u003cdavej@redhat.com\u003e\nTested-by: Sasha Levin \u003clevinsasha928@gmail.com\u003e\nSigned-off-by: Ming Lei \u003cming.lei@canonical.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "d8022cb2b0ea2e5d926c9e2a041e411d71fd3d9e",
      "tree": "452a28cbf2d52e5f112130450a63e8085af87026",
      "parents": [
        "c643e0110bcfa6ccc06aed03699e7ede40a8b1a3"
      ],
      "author": {
        "name": "Ian Abbott",
        "email": "abbotti@mev.co.uk",
        "time": "Fri Mar 22 15:16:29 2013 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:15 2013 -0700"
      },
      "message": "staging: comedi: s626: fix continuous acquisition\n\ncommit e4317ce877a31dbb9d96375391c1c4ad2210d637 upstream.\n\nFor the s626 driver, there is a bug in the handling of asynchronous\ncommands on the AI subdevice when the stop source is `TRIG_NONE`.  The\ncommand should run continuously until cancelled, but the interrupt\nhandler stops the command running after the first scan.\n\nThe command set-up function `s626_ai_cmd()` contains this code:\n\n\tswitch (cmd-\u003estop_src) {\n\tcase TRIG_COUNT:\n\t\t/*  data arrives as one packet */\n\t\tdevpriv-\u003eai_sample_count \u003d cmd-\u003estop_arg;\n\t\tdevpriv-\u003eai_continous \u003d 0;\n\t\tbreak;\n\tcase TRIG_NONE:\n\t\t/*  continous acquisition */\n\t\tdevpriv-\u003eai_continous \u003d 1;\n\t\tdevpriv-\u003eai_sample_count \u003d 0;\n\t\tbreak;\n\t}\n\nThe interrupt handler `s626_irq_handler()` contains this code:\n\n\t\tif (!(devpriv-\u003eai_continous))\n\t\t\tdevpriv-\u003eai_sample_count--;\n\t\tif (devpriv-\u003eai_sample_count \u003c\u003d 0) {\n\t\t\tdevpriv-\u003eai_cmd_running \u003d 0;\n\t\t\t/* ... */\n\t\t}\n\nSo `devpriv-\u003eai_sample_count` is only decremented for the `TRIG_COUNT`\ncase, but `devpriv-\u003eai_cmd_running` is set to 0 (and the command\nstopped) regardless.\n\nFix this in `s626_ai_cmd()` by setting `devpriv-\u003eai_sample_count \u003d 1`\nfor the `TRIG_NONE` case.  The interrupt handler will not decrement it\nso it will remain greater than 0 and the check for stopping the\nacquisition will fail.\n\nSigned-off-by: Ian Abbott \u003cabbotti@mev.co.uk\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "c643e0110bcfa6ccc06aed03699e7ede40a8b1a3",
      "tree": "e24afa79e344fddd96cd291975f1f62fc609e724",
      "parents": [
        "42c4b74a986e7710755a8b48f3ebf7f60f5d20b0"
      ],
      "author": {
        "name": "Ming Lei",
        "email": "ming.lei@canonical.com",
        "time": "Mon Mar 18 23:45:11 2013 +0800"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:15 2013 -0700"
      },
      "message": "Bluetooth: Add support for Dell[QCA 0cf3:817a]\n\ncommit ebaf5795ef57a70a042ea259448a465024e2821d upstream.\n\nAdd support for the AR9462 chip\n\nT:  Bus\u003d03 Lev\u003d01 Prnt\u003d01 Port\u003d08 Cnt\u003d01 Dev#\u003d  5 Spd\u003d12   MxCh\u003d 0\nD:  Ver\u003d 1.10 Cls\u003de0(wlcon) Sub\u003d01 Prot\u003d01 MxPS\u003d64 #Cfgs\u003d  1\nP:  Vendor\u003d0cf3 ProdID\u003d817a Rev\u003d 0.02\nC:* #Ifs\u003d 2 Cfg#\u003d 1 Atr\u003de0 MxPwr\u003d100mA\nI:* If#\u003d 0 Alt\u003d 0 #EPs\u003d 3 Cls\u003de0(wlcon) Sub\u003d01 Prot\u003d01 Driver\u003dbtusb\nE:  Ad\u003d81(I) Atr\u003d03(Int.) MxPS\u003d  16 Ivl\u003d1ms\nE:  Ad\u003d82(I) Atr\u003d02(Bulk) MxPS\u003d  64 Ivl\u003d0ms\nE:  Ad\u003d02(O) Atr\u003d02(Bulk) MxPS\u003d  64 Ivl\u003d0ms\nI:* If#\u003d 1 Alt\u003d 0 #EPs\u003d 2 Cls\u003de0(wlcon) Sub\u003d01 Prot\u003d01 Driver\u003dbtusb\nE:  Ad\u003d83(I) Atr\u003d01(Isoc) MxPS\u003d   0 Ivl\u003d1ms\nE:  Ad\u003d03(O) Atr\u003d01(Isoc) MxPS\u003d   0 Ivl\u003d1ms\nI:  If#\u003d 1 Alt\u003d 1 #EPs\u003d 2 Cls\u003de0(wlcon) Sub\u003d01 Prot\u003d01 Driver\u003dbtusb\nE:  Ad\u003d83(I) Atr\u003d01(Isoc) MxPS\u003d   9 Ivl\u003d1ms\nE:  Ad\u003d03(O) Atr\u003d01(Isoc) MxPS\u003d   9 Ivl\u003d1ms\nI:  If#\u003d 1 Alt\u003d 2 #EPs\u003d 2 Cls\u003de0(wlcon) Sub\u003d01 Prot\u003d01 Driver\u003dbtusb\nE:  Ad\u003d83(I) Atr\u003d01(Isoc) MxPS\u003d  17 Ivl\u003d1ms\nE:  Ad\u003d03(O) Atr\u003d01(Isoc) MxPS\u003d  17 Ivl\u003d1ms\nI:  If#\u003d 1 Alt\u003d 3 #EPs\u003d 2 Cls\u003de0(wlcon) Sub\u003d01 Prot\u003d01 Driver\u003dbtusb\nE:  Ad\u003d83(I) Atr\u003d01(Isoc) MxPS\u003d  25 Ivl\u003d1ms\nE:  Ad\u003d03(O) Atr\u003d01(Isoc) MxPS\u003d  25 Ivl\u003d1ms\nI:  If#\u003d 1 Alt\u003d 4 #EPs\u003d 2 Cls\u003de0(wlcon) Sub\u003d01 Prot\u003d01 Driver\u003dbtusb\nE:  Ad\u003d83(I) Atr\u003d01(Isoc) MxPS\u003d  33 Ivl\u003d1ms\nE:  Ad\u003d03(O) Atr\u003d01(Isoc) MxPS\u003d  33 Ivl\u003d1ms\nI:  If#\u003d 1 Alt\u003d 5 #EPs\u003d 2 Cls\u003de0(wlcon) Sub\u003d01 Prot\u003d01 Driver\u003dbtusb\nE:  Ad\u003d83(I) Atr\u003d01(Isoc) MxPS\u003d  49 Ivl\u003d1ms\nE:  Ad\u003d03(O) Atr\u003d01(Isoc) MxPS\u003d  49 Ivl\u003d1ms\n\nSigned-off-by: Ming Lei \u003cming.lei@canonical.com\u003e\nCc: Gustavo Padovan \u003cgustavo.padovan@collabora.co.uk\u003e\nSigned-off-by: Gustavo Padovan \u003cgustavo.padovan@collabora.co.uk\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "42c4b74a986e7710755a8b48f3ebf7f60f5d20b0",
      "tree": "8bb75a38a90d7e20a763d9b988a59cd1c2df30e3",
      "parents": [
        "caef33a4f3601f90ede96029c5c38a4b2b3cf80b"
      ],
      "author": {
        "name": "Ming Lei",
        "email": "ming.lei@canonical.com",
        "time": "Fri Mar 15 11:00:39 2013 +0800"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:15 2013 -0700"
      },
      "message": "Bluetooth: Add support for Dell[QCA 0cf3:0036]\n\ncommit d66629c1325399cf080ba8b2fb086c10e5439cdd upstream.\n\nAdd support for the AR9462 chip\n\nT:  Bus\u003d03 Lev\u003d01 Prnt\u003d01 Port\u003d01 Cnt\u003d01 Dev#\u003d  3 Spd\u003d12   MxCh\u003d 0\nD:  Ver\u003d 1.10 Cls\u003de0(wlcon) Sub\u003d01 Prot\u003d01 MxPS\u003d64 #Cfgs\u003d  1\nP:  Vendor\u003d0cf3 ProdID\u003d0036 Rev\u003d 0.02\nC:* #Ifs\u003d 2 Cfg#\u003d 1 Atr\u003de0 MxPwr\u003d100mA\nA:  FirstIf#\u003d 0 IfCount\u003d 2 Cls\u003de0(wlcon) Sub\u003d01 Prot\u003d01\nI:* If#\u003d 0 Alt\u003d 0 #EPs\u003d 3 Cls\u003de0(wlcon) Sub\u003d01 Prot\u003d01 Driver\u003dbtusb\nE:  Ad\u003d81(I) Atr\u003d03(Int.) MxPS\u003d  16 Ivl\u003d1ms\nE:  Ad\u003d82(I) Atr\u003d02(Bulk) MxPS\u003d  64 Ivl\u003d0ms\nE:  Ad\u003d02(O) Atr\u003d02(Bulk) MxPS\u003d  64 Ivl\u003d0ms\nI:* If#\u003d 1 Alt\u003d 0 #EPs\u003d 2 Cls\u003de0(wlcon) Sub\u003d01 Prot\u003d01 Driver\u003dbtusb\nE:  Ad\u003d83(I) Atr\u003d01(Isoc) MxPS\u003d   0 Ivl\u003d1ms\nE:  Ad\u003d03(O) Atr\u003d01(Isoc) MxPS\u003d   0 Ivl\u003d1ms\nI:  If#\u003d 1 Alt\u003d 1 #EPs\u003d 2 Cls\u003de0(wlcon) Sub\u003d01 Prot\u003d01 Driver\u003dbtusb\nE:  Ad\u003d83(I) Atr\u003d01(Isoc) MxPS\u003d   9 Ivl\u003d1ms\nE:  Ad\u003d03(O) Atr\u003d01(Isoc) MxPS\u003d   9 Ivl\u003d1ms\nI:  If#\u003d 1 Alt\u003d 2 #EPs\u003d 2 Cls\u003de0(wlcon) Sub\u003d01 Prot\u003d01 Driver\u003dbtusb\nE:  Ad\u003d83(I) Atr\u003d01(Isoc) MxPS\u003d  17 Ivl\u003d1ms\nE:  Ad\u003d03(O) Atr\u003d01(Isoc) MxPS\u003d  17 Ivl\u003d1ms\nI:  If#\u003d 1 Alt\u003d 3 #EPs\u003d 2 Cls\u003de0(wlcon) Sub\u003d01 Prot\u003d01 Driver\u003dbtusb\nE:  Ad\u003d83(I) Atr\u003d01(Isoc) MxPS\u003d  25 Ivl\u003d1ms\nE:  Ad\u003d03(O) Atr\u003d01(Isoc) MxPS\u003d  25 Ivl\u003d1ms\nI:  If#\u003d 1 Alt\u003d 4 #EPs\u003d 2 Cls\u003de0(wlcon) Sub\u003d01 Prot\u003d01 Driver\u003dbtusb\nE:  Ad\u003d83(I) Atr\u003d01(Isoc) MxPS\u003d  33 Ivl\u003d1ms\nE:  Ad\u003d03(O) Atr\u003d01(Isoc) MxPS\u003d  33 Ivl\u003d1ms\nI:  If#\u003d 1 Alt\u003d 5 #EPs\u003d 2 Cls\u003de0(wlcon) Sub\u003d01 Prot\u003d01 Driver\u003dbtusb\nE:  Ad\u003d83(I) Atr\u003d01(Isoc) MxPS\u003d  49 Ivl\u003d1ms\nE:  Ad\u003d03(O) Atr\u003d01(Isoc) MxPS\u003d  49 Ivl\u003d1ms\n\nSigned-off-by: Ming Lei \u003cming.lei@canonical.com\u003e\nCc: Gustavo Padovan \u003cgustavo.padovan@collabora.co.uk\u003e\nSigned-off-by: Gustavo Padovan \u003cgustavo.padovan@collabora.co.uk\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "caef33a4f3601f90ede96029c5c38a4b2b3cf80b",
      "tree": "279f8ead1f9f03bb277cacfc8579acc6ef05876e",
      "parents": [
        "c625222d5a11de4284ef6194c34f4e161c4cb9ef"
      ],
      "author": {
        "name": "Vinicius Costa Gomes",
        "email": "vinicius.gomes@openbossa.org",
        "time": "Wed Mar 13 19:46:20 2013 -0300"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:15 2013 -0700"
      },
      "message": "Bluetooth: Fix not closing SCO sockets in the BT_CONNECT2 state\n\ncommit eb20ff9c91ddcb2d55c1849a87d3db85af5e88a9 upstream.\n\nWith deferred setup for SCO, it is possible that userspace closes the\nsocket when it is in the BT_CONNECT2 state, after the Connect Request is\nreceived but before the Accept Synchonous Connection is sent.\n\nIf this happens the following crash was observed, when the connection is\nterminated:\n\n[  +0.000003] hci_sync_conn_complete_evt: hci0 status 0x10\n[  +0.000005] sco_connect_cfm: hcon ffff88003d1bd800 bdaddr 40:98:4e:32:d7:39 status 16\n[  +0.000003] sco_conn_del: hcon ffff88003d1bd800 conn ffff88003cc8e300, err 110\n[  +0.000015] BUG: unable to handle kernel NULL pointer dereference at 0000000000000199\n[  +0.000906] IP: [\u003cffffffff810620dd\u003e] __lock_acquire+0xed/0xe82\n[  +0.000000] PGD 3d21f067 PUD 3d291067 PMD 0\n[  +0.000000] Oops: 0002 [#1] SMP\n[  +0.000000] Modules linked in: rfcomm bnep btusb bluetooth\n[  +0.000000] CPU 0\n[  +0.000000] Pid: 1481, comm: kworker/u:2H Not tainted 3.9.0-rc1-25019-gad82cdd #1 Bochs Bochs\n[  +0.000000] RIP: 0010:[\u003cffffffff810620dd\u003e]  [\u003cffffffff810620dd\u003e] __lock_acquire+0xed/0xe82\n[  +0.000000] RSP: 0018:ffff88003c3c19d8  EFLAGS: 00010002\n[  +0.000000] RAX: 0000000000000001 RBX: 0000000000000246 RCX: 0000000000000000\n[  +0.000000] RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff88003d1be868\n[  +0.000000] RBP: ffff88003c3c1a98 R08: 0000000000000002 R09: 0000000000000000\n[  +0.000000] R10: ffff88003d1be868 R11: ffff88003e20b000 R12: 0000000000000002\n[  +0.000000] R13: ffff88003aaa8000 R14: 000000000000006e R15: ffff88003d1be850\n[  +0.000000] FS:  0000000000000000(0000) GS:ffff88003e200000(0000) knlGS:0000000000000000\n[  +0.000000] CS:  0010 DS: 0000 ES: 0000 CR0: 000000008005003b\n[  +0.000000] CR2: 0000000000000199 CR3: 000000003c1cb000 CR4: 00000000000006b0\n[  +0.000000] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[  +0.000000] DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400\n[  +0.000000] Process kworker/u:2H (pid: 1481, threadinfo ffff88003c3c0000, task ffff88003aaa8000)\n[  +0.000000] Stack:\n[  +0.000000]  ffffffff81b16342 0000000000000000 0000000000000000 ffff88003d1be868\n[  +0.000000]  ffffffff00000000 00018c0c7863e367 000000003c3c1a28 ffffffff8101efbd\n[  +0.000000]  0000000000000000 ffff88003e3d2400 ffff88003c3c1a38 ffffffff81007c7a\n[  +0.000000] Call Trace:\n[  +0.000000]  [\u003cffffffff8101efbd\u003e] ? kvm_clock_read+0x34/0x3b\n[  +0.000000]  [\u003cffffffff81007c7a\u003e] ? paravirt_sched_clock+0x9/0xd\n[  +0.000000]  [\u003cffffffff81007fd4\u003e] ? sched_clock+0x9/0xb\n[  +0.000000]  [\u003cffffffff8104fd7a\u003e] ? sched_clock_local+0x12/0x75\n[  +0.000000]  [\u003cffffffff810632d1\u003e] lock_acquire+0x93/0xb1\n[  +0.000000]  [\u003cffffffffa0022339\u003e] ? spin_lock+0x9/0xb [bluetooth]\n[  +0.000000]  [\u003cffffffff8105f3d8\u003e] ? lock_release_holdtime.part.22+0x4e/0x55\n[  +0.000000]  [\u003cffffffff814f6038\u003e] _raw_spin_lock+0x40/0x74\n[  +0.000000]  [\u003cffffffffa0022339\u003e] ? spin_lock+0x9/0xb [bluetooth]\n[  +0.000000]  [\u003cffffffff814f6936\u003e] ? _raw_spin_unlock+0x23/0x36\n[  +0.000000]  [\u003cffffffffa0022339\u003e] spin_lock+0x9/0xb [bluetooth]\n[  +0.000000]  [\u003cffffffffa00230cc\u003e] sco_conn_del+0x76/0xbb [bluetooth]\n[  +0.000000]  [\u003cffffffffa002391d\u003e] sco_connect_cfm+0x2da/0x2e9 [bluetooth]\n[  +0.000000]  [\u003cffffffffa000862a\u003e] hci_proto_connect_cfm+0x38/0x65 [bluetooth]\n[  +0.000000]  [\u003cffffffffa0008d30\u003e] hci_sync_conn_complete_evt.isra.79+0x11a/0x13e [bluetooth]\n[  +0.000000]  [\u003cffffffffa000cd96\u003e] hci_event_packet+0x153b/0x239d [bluetooth]\n[  +0.000000]  [\u003cffffffff814f68ff\u003e] ? _raw_spin_unlock_irqrestore+0x48/0x5c\n[  +0.000000]  [\u003cffffffffa00025f6\u003e] hci_rx_work+0xf3/0x2e3 [bluetooth]\n[  +0.000000]  [\u003cffffffff8103efed\u003e] process_one_work+0x1dc/0x30b\n[  +0.000000]  [\u003cffffffff8103ef83\u003e] ? process_one_work+0x172/0x30b\n[  +0.000000]  [\u003cffffffff8103e07f\u003e] ? spin_lock_irq+0x9/0xb\n[  +0.000000]  [\u003cffffffff8103fc8d\u003e] worker_thread+0x123/0x1d2\n[  +0.000000]  [\u003cffffffff8103fb6a\u003e] ? manage_workers+0x240/0x240\n[  +0.000000]  [\u003cffffffff81044211\u003e] kthread+0x9d/0xa5\n[  +0.000000]  [\u003cffffffff81044174\u003e] ? __kthread_parkme+0x60/0x60\n[  +0.000000]  [\u003cffffffff814f75bc\u003e] ret_from_fork+0x7c/0xb0\n[  +0.000000]  [\u003cffffffff81044174\u003e] ? __kthread_parkme+0x60/0x60\n[  +0.000000] Code: d7 44 89 8d 50 ff ff ff 4c 89 95 58 ff ff ff e8 44 fc ff ff 44 8b 8d 50 ff ff ff 48 85 c0 4c 8b 95 58 ff ff ff 0f 84 7a 04 00 00 \u003cf0\u003e ff 80 98 01 00 00 83 3d 25 41 a7 00 00 45 8b b5 e8 05 00 00\n[  +0.000000] RIP  [\u003cffffffff810620dd\u003e] __lock_acquire+0xed/0xe82\n[  +0.000000]  RSP \u003cffff88003c3c19d8\u003e\n[  +0.000000] CR2: 0000000000000199\n[  +0.000000] ---[ end trace e73cd3b52352dd34 ]---\n\nSigned-off-by: Vinicius Costa Gomes \u003cvinicius.gomes@openbossa.org\u003e\nTested-by: Frederic Dalleau \u003cfrederic.dalleau@intel.com\u003e\nSigned-off-by: Gustavo Padovan \u003cgustavo.padovan@collabora.co.uk\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "c625222d5a11de4284ef6194c34f4e161c4cb9ef",
      "tree": "8c350b0a7c538cb68b0e23ede8433bc629b92288",
      "parents": [
        "66156e6f66b648a7ca7f23e659552eed2db7bb9e"
      ],
      "author": {
        "name": "Chris Metcalf",
        "email": "cmetcalf@tilera.com",
        "time": "Fri Mar 29 13:50:21 2013 -0400"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:14 2013 -0700"
      },
      "message": "tile: expect new initramfs name from hypervisor file system\n\ncommit ff7f3efb9abf986f4ecd8793a9593f7ca4d6431a upstream.\n\nThe current Tilera boot infrastructure now provides the initramfs\nto Linux as a Tilera-hypervisor file named \"initramfs\", rather than\n\"initramfs.cpio.gz\", as before.  (This makes it reasonable to use\nother compression techniques than gzip on the file without having to\nworry about the name causing confusion.)  Adapt to use the new name,\nbut also fall back to checking for the old name.\n\nCc\u0027ing to stable so that older kernels will remain compatible with\nnewer Tilera boot infrastructure.\n\nSigned-off-by: Chris Metcalf \u003ccmetcalf@tilera.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "66156e6f66b648a7ca7f23e659552eed2db7bb9e",
      "tree": "6ad8976cb18b76a8dac12576dfd51ae003626657",
      "parents": [
        "30e8f45d7687bcc6ac4010ea37ae78d8e365d2b7"
      ],
      "author": {
        "name": "Trond Myklebust",
        "email": "Trond.Myklebust@netapp.com",
        "time": "Mon Mar 25 11:23:40 2013 -0400"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:14 2013 -0700"
      },
      "message": "SUNRPC: Add barriers to ensure read ordering in rpc_wake_up_task_queue_locked\n\ncommit 1166fde6a923c30f4351515b6a9a1efc513e7d00 upstream.\n\nWe need to be careful when testing task-\u003etk_waitqueue in\nrpc_wake_up_task_queue_locked, because it can be changed while we\nare holding the queue-\u003elock.\nBy adding appropriate memory barriers, we can ensure that it is safe to\ntest task-\u003etk_waitqueue for equality if the RPC_TASK_QUEUED bit is set.\n\nSigned-off-by: Trond Myklebust \u003cTrond.Myklebust@netapp.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "30e8f45d7687bcc6ac4010ea37ae78d8e365d2b7",
      "tree": "c344b733d36fa45ccd430574eebc7227bb014a06",
      "parents": [
        "556ba7075b9b95a0439cd7b52a1284b88b8fa755"
      ],
      "author": {
        "name": "Andrew Morton",
        "email": "akpm@linux-foundation.org",
        "time": "Wed Mar 13 14:59:34 2013 -0700"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:14 2013 -0700"
      },
      "message": "kernel/signal.c: use __ARCH_HAS_SA_RESTORER instead of SA_RESTORER\n\ncommit 522cff142d7d2f9230839c9e1f21a4d8bcc22a4a upstream.\n\n__ARCH_HAS_SA_RESTORER is the preferred conditional for use in 3.9 and\nlater kernels, per Kees.\n\nSigned-off-by: Andrew Morton \u003cakpm@linux-foundation.org\u003e\nCc: Emese Revfy \u003cre.emese@gmail.com\u003e\nCc: Emese Revfy \u003cre.emese@gmail.com\u003e\nCc: PaX Team \u003cpageexec@freemail.hu\u003e\nCc: Al Viro \u003cviro@zeniv.linux.org.uk\u003e\nCc: Oleg Nesterov \u003coleg@redhat.com\u003e\nCc: \"Eric W. Biederman\" \u003cebiederm@xmission.com\u003e\nCc: Serge Hallyn \u003cserge.hallyn@canonical.com\u003e\nCc: Julien Tinnes \u003cjln@google.com\u003e\nSigned-off-by: Linus Torvalds \u003ctorvalds@linux-foundation.org\u003e\nCc: Ben Hutchings \u003cben@decadent.org.uk\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "556ba7075b9b95a0439cd7b52a1284b88b8fa755",
      "tree": "83030591531a58bc4419a77e30123aedaaf5a33f",
      "parents": [
        "f3b5af9a6e2a873110bb8546b42ae7c51f2213b3"
      ],
      "author": {
        "name": "Ben Hutchings",
        "email": "ben@decadent.org.uk",
        "time": "Sun Nov 25 22:24:19 2012 -0500"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Apr 05 10:04:14 2013 -0700"
      },
      "message": "signal: Define __ARCH_HAS_SA_RESTORER so we know whether to clear sa_restorer\n\nVaguely based on upstream commit 574c4866e33d \u0027consolidate kernel-side\nstruct sigaction declarations\u0027.\n\nflush_signal_handlers() needs to know whether sigaction::sa_restorer\nis defined, not whether SA_RESTORER is defined.  Define the\n__ARCH_HAS_SA_RESTORER macro to indicate this.\n\nSigned-off-by: Ben Hutchings \u003cben@decadent.org.uk\u003e\nCc: Al Viro \u003cviro@zeniv.linux.org.uk\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "f3b5af9a6e2a873110bb8546b42ae7c51f2213b3",
      "tree": "bdffbb2b5110a8034fee03281012a19a9bfe953e",
      "parents": [
        "101498601754f4a2a43ff175e8063d1d21db6d26"
      ],
      "author": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Mar 28 12:12:41 2013 -0700"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Mar 28 12:12:41 2013 -0700"
      },
      "message": "Linux 3.4.38\n"
    },
    {
      "commit": "101498601754f4a2a43ff175e8063d1d21db6d26",
      "tree": "a42d3fda72b26265048d6e22e81e189a3a3fde2b",
      "parents": [
        "553ce45fd6abec3454b3900f66a06d3da1c494be"
      ],
      "author": {
        "name": "Ben Hutchings",
        "email": "ben@decadent.org.uk",
        "time": "Thu Nov 29 09:12:37 2012 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Mar 28 12:12:28 2013 -0700"
      },
      "message": "asus-laptop: Do not call HWRS on init\n\ncommit cb7da022450cdaaebd33078b6b32fb7dd2aaf6db upstream.\n\nSince commit 8871e99f89b7 (\u0027asus-laptop: HRWS/HWRS typo\u0027), module\ninitialisation is very slow on the Asus UL30A.  The HWRS method takes\nabout 12 seconds to run, and subsequent initialisation also seems to\nbe delayed.  Since we don\u0027t really need the result, don\u0027t bother\ncalling it on init.  Those who are curious can still get the result\nthrough the \u0027infos\u0027 device attribute.\n\nUpdate the comment about HWRS in show_infos().\n\nReported-by: ryan \u003cdraziw+deb@gmail.com\u003e\nReferences: http://bugs.debian.org/692436\nSigned-off-by: Ben Hutchings \u003cben@decadent.org.uk\u003e\nSigned-off-by: Corentin Chary \u003ccorentin.chary@gmail.com\u003e\nSigned-off-by: Matthew Garrett \u003cmatthew.garrett@nebula.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "553ce45fd6abec3454b3900f66a06d3da1c494be",
      "tree": "4f8c69066d64253dd7890f790770508315e3546d",
      "parents": [
        "023eae6de094c527f85c5fc3e9a8a364af56b1af"
      ],
      "author": {
        "name": "Felix Fietkau",
        "email": "nbd@openwrt.org",
        "time": "Tue Feb 26 16:09:55 2013 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Mar 28 12:12:28 2013 -0700"
      },
      "message": "rt2x00: error in configurations with mesh support disabled\n\ncommit 6ef9e2f6d12ce9e2120916804d2ddd46b954a70b upstream.\n\nIf CONFIG_MAC80211_MESH is not set, cfg80211 will now allow advertising\ninterface combinations with NL80211_IFTYPE_MESH_POINT present.\nAdd appropriate ifdefs to avoid running into errors.\n\n[Backported for 3.8-stable. Removed code of simultaneous AP and mesh\nmode added in 4a5fc6d 3.9-rc1.]\n\nSigned-off-by: Felix Fietkau \u003cnbd@openwrt.org\u003e\nAcked-by: Gertjan van Wingerde \u003cgwingerde@gmail.com\u003e\nSigned-off-by: John W. Linville \u003clinville@tuxdriver.com\u003e\nSigned-off-by: Lingzhu Xiang \u003clxiang@redhat.com\u003e\nReviewed-by: CAI Qian \u003ccaiqian@redhat.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "023eae6de094c527f85c5fc3e9a8a364af56b1af",
      "tree": "899b193a9ba356d2ac6b404a93b1c2545407d709",
      "parents": [
        "2f7dea37d1b0b3a26fb3c2bd97bbf836dfd04def"
      ],
      "author": {
        "name": "Kees Cook",
        "email": "keescook@chromium.org",
        "time": "Mon Dec 17 16:03:20 2012 -0800"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Mar 28 12:12:28 2013 -0700"
      },
      "message": "exec: use -ELOOP for max recursion depth\n\ncommit d740269867021faf4ce38a449353d2b986c34a67 upstream.\n\nTo avoid an explosion of request_module calls on a chain of abusive\nscripts, fail maximum recursion with -ELOOP instead of -ENOEXEC. As soon\nas maximum recursion depth is hit, the error will fail all the way back\nup the chain, aborting immediately.\n\nThis also has the side-effect of stopping the user\u0027s shell from attempting\nto reexecute the top-level file as a shell script. As seen in the\ndash source:\n\n        if (cmd !\u003d path_bshell \u0026\u0026 errno \u003d\u003d ENOEXEC) {\n                *argv-- \u003d cmd;\n                *argv \u003d cmd \u003d path_bshell;\n                goto repeat;\n        }\n\nThe above logic was designed for running scripts automatically that lacked\nthe \"#!\" header, not to re-try failed recursion. On a legitimate -ENOEXEC,\nthings continue to behave as the shell expects.\n\nAdditionally, when tracking recursion, the binfmt handlers should not be\ninvolved. The recursion being tracked is the depth of calls through\nsearch_binary_handler(), so that function should be exclusively responsible\nfor tracking the depth.\n\nSigned-off-by: Kees Cook \u003ckeescook@chromium.org\u003e\nCc: halfdog \u003cme@halfdog.net\u003e\nCc: P J P \u003cppandit@redhat.com\u003e\nCc: Alexander Viro \u003cviro@zeniv.linux.org.uk\u003e\nSigned-off-by: Andrew Morton \u003cakpm@linux-foundation.org\u003e\nSigned-off-by: Linus Torvalds \u003ctorvalds@linux-foundation.org\u003e\nCc: Ben Hutchings \u003cben@decadent.org.uk\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "2f7dea37d1b0b3a26fb3c2bd97bbf836dfd04def",
      "tree": "b8d5ba9b4dbafd6ecc706589eb2812c02f8ef6c2",
      "parents": [
        "5fb9149b0ee4c106fc73923a3751047bdb860993"
      ],
      "author": {
        "name": "Lekensteyn",
        "email": "lekensteyn@gmail.com",
        "time": "Tue Jun 26 00:36:24 2012 +0200"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Mar 28 12:12:28 2013 -0700"
      },
      "message": "i915: initialize CADL in opregion\n\ncommit d627b62ff8d4d36761adbcd90ff143d79c94ab22 upstream.\n\nThis is rather a hack to fix brightness hotkeys on a Clevo laptop. CADL is not\nused anywhere in the driver code at the moment, but it could be used in BIOS as\nis the case with the Clevo laptop.\n\nThe Clevo B7130 requires the CADL field to contain at least the ID of\nthe LCD device. If this field is empty, the ACPI methods that are called\non pressing brightness / display switching hotkeys will not trigger a\nnotification. As a result, it appears as no hotkey has been pressed.\n\nReference: https://bugs.freedesktop.org/show_bug.cgi?id\u003d45452\nTested-by: Peter Wu \u003clekensteyn@gmail.com\u003e\nSigned-off-by: Peter Wu \u003clekensteyn@gmail.com\u003e\nAcked-by: Jesse Barnes \u003cjbarnes@virtuousgeek.org\u003e\nSigned-off-by: Daniel Vetter \u003cdaniel.vetter@ffwll.ch\u003e\nCc: Ben Hutchings \u003cben@decadent.org.uk\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "5fb9149b0ee4c106fc73923a3751047bdb860993",
      "tree": "509e5506a2869f845a1ec94b6a2ceb8320a01b25",
      "parents": [
        "66de393d66371b070699ffcb6207cf1abc8b581a"
      ],
      "author": {
        "name": "Tomas Hozza",
        "email": "thozza@redhat.com",
        "time": "Thu Nov 08 10:53:29 2012 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Mar 28 12:12:28 2013 -0700"
      },
      "message": "tools: hv: Netlink source address validation allows DoS\n\ncommit 95a69adab9acfc3981c504737a2b6578e4d846ef upstream.\n\nThe source code without this patch caused hypervkvpd to exit when it processed\na spoofed Netlink packet which has been sent from an untrusted local user.\nNow Netlink messages with a non-zero nl_pid source address are ignored\nand a warning is printed into the syslog.\n\nSigned-off-by: Tomas Hozza \u003cthozza@redhat.com\u003e\nAcked-by:  K. Y. Srinivasan \u003ckys@microsoft.com\u003e\nCc: Ben Hutchings \u003cben@decadent.org.uk\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "66de393d66371b070699ffcb6207cf1abc8b581a",
      "tree": "8a09ac4ccb2669d72e1a92653f742b639f032301",
      "parents": [
        "19b437682b56a924993979dff408a72e2c5380e6"
      ],
      "author": {
        "name": "Mathias Krause",
        "email": "minipli@googlemail.com",
        "time": "Thu Jul 12 08:46:55 2012 +0200"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Mar 28 12:12:27 2013 -0700"
      },
      "message": "udf: avoid info leak on export\n\ncommit 0143fc5e9f6f5aad4764801015bc8d4b4a278200 upstream.\n\nFor type 0x51 the udf.parent_partref member in struct fid gets copied\nuninitialized to userland. Fix this by initializing it to 0.\n\nSigned-off-by: Mathias Krause \u003cminipli@googlemail.com\u003e\nSigned-off-by: Jan Kara \u003cjack@suse.cz\u003e\nCc: Ben Hutchings \u003cben@decadent.org.uk\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "19b437682b56a924993979dff408a72e2c5380e6",
      "tree": "963fb370a9a8d8773ca415e98176327b93303a0d",
      "parents": [
        "b647ebe6e7c171efd2003b1a8d07dcc26e6fa748"
      ],
      "author": {
        "name": "Mathias Krause",
        "email": "minipli@googlemail.com",
        "time": "Thu Jul 12 08:46:54 2012 +0200"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Mar 28 12:12:27 2013 -0700"
      },
      "message": "isofs: avoid info leak on export\n\ncommit fe685aabf7c8c9f138e5ea900954d295bf229175 upstream.\n\nFor type 1 the parent_offset member in struct isofs_fid gets copied\nuninitialized to userland. Fix this by initializing it to 0.\n\nSigned-off-by: Mathias Krause \u003cminipli@googlemail.com\u003e\nSigned-off-by: Jan Kara \u003cjack@suse.cz\u003e\nCc: Ben Hutchings \u003cben@decadent.org.uk\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "b647ebe6e7c171efd2003b1a8d07dcc26e6fa748",
      "tree": "d4fd13848f1ae194d3e450a5d26fd7f3d2191e50",
      "parents": [
        "8b55bf58c5f89681d37b19789bdae389fa54b0cd"
      ],
      "author": {
        "name": "Alan Cox",
        "email": "alan@linux.intel.com",
        "time": "Fri Sep 28 12:20:02 2012 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Mar 28 12:12:27 2013 -0700"
      },
      "message": "key: Fix resource leak\n\ncommit a84a921978b7d56e0e4b87ffaca6367429b4d8ff upstream.\n\nOn an error iov may still have been reallocated and need freeing\n\nSigned-off-by: Alan Cox \u003calan@linux.intel.com\u003e\nSigned-off-by: David Howells \u003cdhowells@redhat.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "8b55bf58c5f89681d37b19789bdae389fa54b0cd",
      "tree": "3f749f411cf6e97da09e829d1eebe10f508abc05",
      "parents": [
        "00de47e3ba24ddad37496c47aae5753862024900"
      ],
      "author": {
        "name": "Johan Hovold",
        "email": "jhovold@gmail.com",
        "time": "Tue Mar 19 09:21:08 2013 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Mar 28 12:12:27 2013 -0700"
      },
      "message": "USB: io_ti: fix get_icount for two port adapters\n\ncommit 5492bf3d5655b4954164f69c02955a7fca267611 upstream.\n\nAdd missing get_icount field to two-port driver.\n\nThe two-port driver was not updated when switching to the new icount\ninterface in commit 0bca1b913aff (\"tty: Convert the USB drivers to the\nnew icount interface\").\n\nSigned-off-by: Johan Hovold \u003cjhovold@gmail.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "00de47e3ba24ddad37496c47aae5753862024900",
      "tree": "82606b7bc4bd33e65f41726c9247ec165d9dd6a0",
      "parents": [
        "bc914c3b5ebcf158419c4901ec54ffbd7677d5a0"
      ],
      "author": {
        "name": "Johan Hovold",
        "email": "jhovold@gmail.com",
        "time": "Tue Mar 19 09:21:07 2013 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Mar 28 12:12:27 2013 -0700"
      },
      "message": "USB: garmin_gps: fix memory leak on disconnect\n\ncommit 618aa1068df29c37a58045fe940f9106664153fd upstream.\n\nRemove bogus disconnect test introduced by 95bef012e (\"USB: more serial\ndrivers writing after disconnect\") which prevented queued data from\nbeing freed on disconnect.\n\nThe possible IO it was supposed to prevent is long gone.\n\nSigned-off-by: Johan Hovold \u003cjhovold@gmail.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "bc914c3b5ebcf158419c4901ec54ffbd7677d5a0",
      "tree": "dda7c66c9d090e3187eec3fb3390cd59b218d77a",
      "parents": [
        "5899ef0b272b58f2927eb3376afaad2b02559180"
      ],
      "author": {
        "name": "Jan Kara",
        "email": "jack@suse.cz",
        "time": "Tue Feb 05 13:59:56 2013 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Mar 28 12:12:27 2013 -0700"
      },
      "message": "udf: Fix bitmap overflow on large filesystems with small block size\n\ncommit 89b1f39eb4189de745fae554b0d614d87c8d5c63 upstream.\n\nFor large UDF filesystems with 512-byte blocks the number of necessary\nbitmap blocks is larger than 2^16 so s_nr_groups in udf_bitmap overflows\n(the number will overflow for filesystems larger than 128 GB with\n512-byte blocks). That results in ENOSPC errors despite the filesystem\nhas plenty of free space.\n\nFix the problem by changing s_nr_groups\u0027 type to \u0027int\u0027. That is enough\neven for filesystems 2^32 blocks (UDF maximum) and 512-byte blocksize.\n\nReported-and-tested-by: v10lator@myway.de\nSigned-off-by: Jan Kara \u003cjack@suse.cz\u003e\nCc: Jim Trigg \u003cjtrigg@spamcop.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "5899ef0b272b58f2927eb3376afaad2b02559180",
      "tree": "e74731ea62cd7ba183152d23eef8e39a536f207e",
      "parents": [
        "cbff2b6d371dbbae19de1dcfd09051683eca02ca"
      ],
      "author": {
        "name": "Frederic Weisbecker",
        "email": "fweisbec@gmail.com",
        "time": "Wed Feb 20 16:15:36 2013 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Mar 28 12:12:27 2013 -0700"
      },
      "message": "nohz: Make tick_nohz_irq_exit() irq safe\n\ncommit e5ab012c3271990e8457055c25cafddc1ae8aa6b upstream.\n\nAs it stands, irq_exit() may or may not be called with\nirqs disabled, depending on __ARCH_IRQ_EXIT_IRQS_DISABLED\nthat the arch can define.\n\nIt makes tick_nohz_irq_exit() unsafe. For example two\ninterrupts can race in tick_nohz_stop_sched_tick(): the inner\nmost one computes the expiring time on top of the timer list,\nthen it\u0027s interrupted right before reprogramming the\nclock. The new interrupt enqueues a new timer list timer,\nit reprogram the clock to take it into account and it exits.\nThe CPUs resumes the inner most interrupt and performs the clock\nreprogramming without considering the new timer list timer.\n\nThis regression has been introduced by:\n     280f06774afedf849f0b34248ed6aff57d0f6908\n     (\"nohz: Separate out irq exit and idle loop dyntick logic\")\n\nLet\u0027s fix it right now with the appropriate protections.\n\nA saner long term solution will be to remove\n__ARCH_IRQ_EXIT_IRQS_DISABLED and mandate that irq_exit() is called\nwith interrupts disabled.\n\nSigned-off-by: Frederic Weisbecker \u003cfweisbec@gmail.com\u003e\nCc: Peter Zijlstra \u003cpeterz@infradead.org\u003e\nCc: Ingo Molnar \u003cmingo@kernel.org\u003e\nCc: Linus Torvalds \u003ctorvalds@linuxfoundation.org\u003e\nLink: http://lkml.kernel.org/r/1361373336-11337-1-git-send-email-fweisbec@gmail.com\nSigned-off-by: Thomas Gleixner \u003ctglx@linutronix.de\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\nSigned-off-by: Thomas Gleixner \u003ctglx@linutronix.de\u003e\nSigned-off-by: Lingzhu Xiang \u003clxiang@redhat.com\u003e\nReviewed-by: CAI Qian \u003ccaiqian@redhat.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "cbff2b6d371dbbae19de1dcfd09051683eca02ca",
      "tree": "376fa238a64110fd66e969ce6723fc9dcb9adb0f",
      "parents": [
        "10a00e38f3478eb899916f9a15d97e1b565106c3"
      ],
      "author": {
        "name": "Johan Hovold",
        "email": "jhovold@gmail.com",
        "time": "Tue Mar 19 09:21:09 2013 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Mar 28 12:12:27 2013 -0700"
      },
      "message": "USB: serial: fix interface refcounting\n\ncommit d7971051e4df825e0bc11b995e87bfe86355b8e5 upstream.\n\nMake sure the interface is not released before our serial device.\n\nNote that drivers are still not allowed to access the interface in\nany way that may interfere with another driver that may have gotten\nbound to the same interface after disconnect returns.\n\nSigned-off-by: Johan Hovold \u003cjhovold@gmail.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "10a00e38f3478eb899916f9a15d97e1b565106c3",
      "tree": "324d36afa24d272cfb6f934c11fbfe5afdad81f0",
      "parents": [
        "d581bb3819c5cda33531a0a67c02dbdb7d61f307"
      ],
      "author": {
        "name": "Johan Hovold",
        "email": "jhovold@gmail.com",
        "time": "Tue Mar 19 09:21:06 2013 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Mar 28 12:12:26 2013 -0700"
      },
      "message": "USB: cdc-acm: fix device unregistration\n\ncommit cb25505fc604292c70fc02143fc102f54c8595f0 upstream.\n\nUnregister tty device in disconnect as is required by the USB stack.\n\nBy deferring unregistration to when the last tty reference is dropped,\nthe parent interface device can get unregistered before the child\nresulting in broken hotplug events being generated when the tty is\nfinally closed:\n\nKERNEL[2290.798128] remove   /devices/pci0000:00/0000:00:1d.7/usb2/2-1/2-1:3.1 (usb)\nKERNEL[2290.804589] remove   /devices/pci0000:00/0000:00:1d.7/usb2/2-1 (usb)\nKERNEL[2294.554799] remove   /2-1:3.1/tty/ttyACM0 (tty)\n\nThe driver must deal with tty callbacks after disconnect by checking the\ndisconnected flag. Specifically, further opens must be prevented and\nthis is already implemented.\n\nAcked-by: Oliver Neukum \u003coneukum@suse.de\u003e\nCc: Oliver Neukum \u003coneukum@suse.de\u003e\nSigned-off-by: Johan Hovold \u003cjhovold@gmail.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "d581bb3819c5cda33531a0a67c02dbdb7d61f307",
      "tree": "ecbf9704196e0a453526b23697f4ede1b4a7379c",
      "parents": [
        "31e8d29ccf1844a84b7c07d511e6a92d9f99cc11"
      ],
      "author": {
        "name": "Hannes Reinecke",
        "email": "hare@suse.de",
        "time": "Mon Mar 04 17:14:43 2013 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Mar 28 12:12:26 2013 -0700"
      },
      "message": "USB: xhci: correctly enable interrupts\n\ncommit 00eed9c814cb8f281be6f0f5d8f45025dc0a97eb upstream.\n\nxhci has its own interrupt enabling routine, which will try to\nuse MSI-X/MSI if present. So the usb core shouldn\u0027t try to enable\nlegacy interrupts; on some machines the xhci legacy IRQ setting\nis invalid.\n\nv3: Be careful to not break XHCI_BROKEN_MSI workaround (by trenn)\n\nCc: Bjorn Helgaas \u003cbhelgaas@google.com\u003e\nCc: Oliver Neukum \u003coneukum@suse.de\u003e\nCc: Thomas Renninger \u003ctrenn@suse.de\u003e\nCc: Yinghai Lu \u003cyinghai@kernel.org\u003e\nCc: Frederik Himpe \u003cfhimpe@vub.ac.be\u003e\nCc: David Haerdeman \u003cdavid@hardeman.nu\u003e\nCc: Alan Stern \u003cstern@rowland.harvard.edu\u003e\nAcked-by: Sarah Sharp \u003csarah.a.sharp@linux.intel.com\u003e\nReviewed-by: Thomas Renninger \u003ctrenn@suse.de\u003e\nSigned-off-by: Hannes Reinecke \u003chare@suse.de\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "31e8d29ccf1844a84b7c07d511e6a92d9f99cc11",
      "tree": "512ab2a07fda6dcab2357bb2cd0aafc20a709c72",
      "parents": [
        "56d833d3ed356e861ede0dd1c530ed5185d1215e"
      ],
      "author": {
        "name": "Dmitry Torokhov",
        "email": "dtor@vmware.com",
        "time": "Mon Feb 25 10:56:01 2013 -0800"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Mar 28 12:12:26 2013 -0700"
      },
      "message": "USB: xhci - fix bit definitions for IMAN register\n\ncommit f8264340e694604863255cc0276491d17c402390 upstream.\n\nAccording to XHCI specification (5.5.2.1) the IP is bit 0 and IE is bit 1\nof IMAN register. Previously their definitions were reversed.\n\nEven though there are no ill effects being observed from the swapped\ndefinitions (because IMAN_IP is RW1C and in legacy PCI case we come in\nwith it already set to 1 so it was clearing itself even though we were\nsetting IMAN_IE instead of IMAN_IP), we should still correct the values.\n\nThis patch should be backported to kernels as old as 2.6.36, that\ncontain the commit 4e833c0b87a30798e67f06120cecebef6ee9644c \"xhci: don\u0027t\nre-enable IE constantly\".\n\nSigned-off-by: Dmitry Torokhov \u003cdtor@vmware.com\u003e\nSigned-off-by: Sarah Sharp \u003csarah.a.sharp@linux.intel.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    }
  ],
  "next": "56d833d3ed356e861ede0dd1c530ed5185d1215e"
}
