)]}'
{
  "log": [
    {
      "commit": "54bf0ca8b15b687cfd932777a3894731c08d79a2",
      "tree": "53ad1366ffef2eb4ab055d5f6c939f7aed4c02fb",
      "parents": [
        "36d5b7b83ab7931290de2ce533f75c540cb90702"
      ],
      "author": {
        "name": "Ilya Dryomov",
        "email": "ilya.dryomov@inktank.com",
        "time": "Mon Sep 08 17:25:34 2014 +0400"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Mon Dec 01 18:02:29 2014 +0800"
      },
      "message": "libceph: add process_one_ticket() helper\n\ncommit 597cda357716a3cf8d994cb11927af917c8d71fa upstream.\n\nAdd a helper for processing individual cephx auth tickets.  Needed for\nthe next commit, which deals with allocating ticket buffers.  (Most of\nthe diff here is whitespace - view with git diff -b).\n\nSigned-off-by: Ilya Dryomov \u003cilya.dryomov@inktank.com\u003e\nReviewed-by: Sage Weil \u003csage@redhat.com\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "36d5b7b83ab7931290de2ce533f75c540cb90702",
      "tree": "eb9961bdee1f8ee80a821aac4730b712f7fefd12",
      "parents": [
        "386ba13164c2c136c0fbf585aa7b63831c96d7c8"
      ],
      "author": {
        "name": "Sage Weil",
        "email": "sage@redhat.com",
        "time": "Mon Aug 04 07:01:54 2014 -0700"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Mon Dec 01 18:02:28 2014 +0800"
      },
      "message": "libceph: gracefully handle large reply messages from the mon\n\ncommit 73c3d4812b4c755efeca0140f606f83772a39ce4 upstream.\n\nWe preallocate a few of the message types we get back from the mon.  If we\nget a larger message than we are expecting, fall back to trying to allocate\na new one instead of blindly using the one we have.\n\nSigned-off-by: Sage Weil \u003csage@redhat.com\u003e\nReviewed-by: Ilya Dryomov \u003cilya.dryomov@inktank.com\u003e\n[lizf: Backported to 3.4: s/front_alloc_len/front_max/g]\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "386ba13164c2c136c0fbf585aa7b63831c96d7c8",
      "tree": "affcf42c30def25c1ca75e020e816bcd1506a10d",
      "parents": [
        "96eb53749fbfd77b92031cc6b97458fe5c4244ae"
      ],
      "author": {
        "name": "Dmitry Torokhov",
        "email": "dmitry.torokhov@gmail.com",
        "time": "Sat Aug 30 13:51:06 2014 -0700"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Mon Dec 01 18:02:28 2014 +0800"
      },
      "message": "Input: synaptics - add support for ForcePads\n\ncommit 5715fc764f7753d464dbe094b5ef9cffa6e479a4 upstream.\n\nForcePads are found on HP EliteBook 1040 laptops. They lack any kind of\nphysical buttons, instead they generate primary button click when user\npresses somewhat hard on the surface of the touchpad. Unfortunately they\nalso report primary button click whenever there are 2 or more contacts\non the pad, messing up all multi-finger gestures (2-finger scrolling,\nmulti-finger tapping, etc). To cope with this behavior we introduce a\ndelay (currently 50 msecs) in reporting primary press in case more\ncontacts appear.\n\nReviewed-by: Hans de Goede \u003chdegoede@redhat.com\u003e\nSigned-off-by: Dmitry Torokhov \u003cdmitry.torokhov@gmail.com\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "96eb53749fbfd77b92031cc6b97458fe5c4244ae",
      "tree": "7b8072a73eb00703e9877f5f20a27169a3d85145",
      "parents": [
        "0d69cbb4a932a244ed2d5344b6ef0ccdf99fc8a3"
      ],
      "author": {
        "name": "Thomas Pugliese",
        "email": "thomas.pugliese@gmail.com",
        "time": "Thu Aug 07 15:45:35 2014 -0500"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Mon Dec 01 18:02:28 2014 +0800"
      },
      "message": "uwb: init beacon cache entry before registering uwb device\n\ncommit 675f0ab2fe5a0f7325208e60b617a5f32b86d72c upstream.\n\nMake sure the uwb_dev-\u003ebce entry is set before calling uwb_dev_add in\nuwbd_dev_onair so that usermode will only see the device after it is\nproperly initialized.  This fixes a kernel panic that can occur if\nusermode tries to access the IEs sysfs attribute of a UWB device before\nthe driver has had a chance to set the beacon cache entry.\n\nSigned-off-by: Thomas Pugliese \u003cthomas.pugliese@gmail.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n[lizf: Backported to 3.4: adjust context]\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "0d69cbb4a932a244ed2d5344b6ef0ccdf99fc8a3",
      "tree": "dc962d4e6216b208c32364d8468dd4102fecf042",
      "parents": [
        "32b45e0ec8c6d1b613e074adc13385d4c63769a4"
      ],
      "author": {
        "name": "Taylor Braun-Jones",
        "email": "taylor.braun-jones@ge.com",
        "time": "Thu Aug 07 14:25:06 2014 -0400"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Mon Dec 01 18:02:27 2014 +0800"
      },
      "message": "USB: ftdi_sio: Add support for GE Healthcare Nemo Tracker device\n\ncommit 9c491c372d677b6420e0f8c6361fe422791662cc upstream.\n\nSigned-off-by: Taylor Braun-Jones \u003ctaylor.braun-jones@ge.com\u003e\nCc: Johan Hovold \u003cjohan@kernel.org\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n[lizf: Backported to 3.4: adjust context]\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "32b45e0ec8c6d1b613e074adc13385d4c63769a4",
      "tree": "1dd10d094f543f22a964262bae61a9d27644cb13",
      "parents": [
        "488d89601e77e23b18755a0563579b67d950d9fb"
      ],
      "author": {
        "name": "Hans de Goede",
        "email": "hdegoede@redhat.com",
        "time": "Mon Sep 08 14:39:52 2014 -0700"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Mon Dec 01 18:02:27 2014 +0800"
      },
      "message": "Input: elantech - fix detection of touchpad on ASUS s301l\n\ncommit 271329b3c798b2102120f5df829071c211ef00ed upstream.\n\nAdjust Elantech signature validation to account fo rnewer models of\ntouchpads.\n\nReported-and-tested-by: Màrius Monton \u003cmarius.monton@gmail.com\u003e\nSigned-off-by: Hans de Goede \u003chdegoede@redhat.com\u003e\nSigned-off-by: Dmitry Torokhov \u003cdmitry.torokhov@gmail.com\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "488d89601e77e23b18755a0563579b67d950d9fb",
      "tree": "19520dc0069aad504f9d1a51eee901f31c73cef5",
      "parents": [
        "2c858d84af5c7bebbee0c27383916e5fee649717"
      ],
      "author": {
        "name": "Felipe Balbi",
        "email": "balbi@ti.com",
        "time": "Wed Aug 27 16:38:04 2014 -0500"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Mon Dec 01 18:02:27 2014 +0800"
      },
      "message": "usb: host: xhci: fix compliance mode workaround\n\ncommit 96908589a8b2584b1185f834d365f5cc360e8226 upstream.\n\nCommit 71c731a (usb: host: xhci: Fix Compliance Mode\non SN65LVP3502CP Hardware) implemented a workaround\nfor a known issue with Texas Instruments\u0027 USB 3.0\nredriver IC but it left a condition where any xHCI\nhost would be taken out of reset if port was placed\nin compliance mode and there was no device connected\nto the port.\n\nThat condition would trigger a fake connection to a\nnon-existent device so that usbcore would trigger a\nwarm reset of the port, thus taking the link out of\nreset.\n\nThis has the side-effect of preventing any xHCI host\nconnected to a Linux machine from starting and running\nthe USB 3.0 Electrical Compliance Suite because the\nport will mysteriously taken out of compliance mode\nand, thus, xHCI won\u0027t step through the necessary\ncompliance patterns for link validation.\n\nThis patch fixes the issue by just adding a missing\ncheck for XHCI_COMP_MODE_QUIRK inside\nxhci_hub_report_usb3_link_state() when PORT_CAS isn\u0027t\nset.\n\nThis patch should be backported to all kernels containing\ncommit 71c731a.\n\nFixes: 71c731a (usb: host: xhci: Fix Compliance Mode on SN65LVP3502CP Hardware)\nCc: Alexis R. Cortes \u003calexis.cortes@ti.com\u003e\nSigned-off-by: Felipe Balbi \u003cbalbi@ti.com\u003e\nAcked-by: Mathias Nyman \u003cmathias.nyman@linux.intel.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n[lizf: Backported to 3.4:\n - s/xhci_hub_report_usb3_link_state/xhci_hub_report_link_state/]\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "2c858d84af5c7bebbee0c27383916e5fee649717",
      "tree": "4bdc541f516dd6c01f35c0f26abda4c83ba7ab09",
      "parents": [
        "e77f3791c866b24fbb0ddd27f46590ea72f14be6"
      ],
      "author": {
        "name": "Alex Deucher",
        "email": "alexander.deucher@amd.com",
        "time": "Mon Sep 08 13:55:51 2014 -0400"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Mon Dec 01 18:02:26 2014 +0800"
      },
      "message": "drm/radeon: add connector quirk for fujitsu board\n\ncommit 1952f24d0fa6292d65f886887af87ba8ac79b3ba upstream.\n\nVbios connector table lists non-existent VGA port.\n\nBug:\nhttps://bugs.freedesktop.org/show_bug.cgi?id\u003d83184\n\nSigned-off-by: Alex Deucher \u003calexander.deucher@amd.com\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "e77f3791c866b24fbb0ddd27f46590ea72f14be6",
      "tree": "61ca762647ca5b06a9c5d765a04c06f841c3db06",
      "parents": [
        "93408be9e1ea67f14fe0c1c46a430f33cbef4180"
      ],
      "author": {
        "name": "Murali Karicheri",
        "email": "m-karicheri2@ti.com",
        "time": "Fri Sep 05 13:21:00 2014 -0400"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Mon Dec 01 18:02:26 2014 +0800"
      },
      "message": "ahci: add pcid for Marvel 0x9182 controller\n\ncommit c5edfff9db6f4d2c35c802acb4abe0df178becee upstream.\n\nKeystone K2E EVM uses Marvel 0x9182 controller. This requires support\nfor the ID in the ahci driver.\n\nSigned-off-by: Murali Karicheri \u003cm-karicheri2@ti.com\u003e\nSigned-off-by: Tejun Heo \u003ctj@kernel.org\u003e\nCc: Santosh Shilimkar \u003csantosh.shilimkar@ti.com\u003e\n[lizf: Backported to 3.4:\n - adjust context\n - s/PCI_VENDOR_ID_MARVELL_EXT/0x1b4b/]\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "93408be9e1ea67f14fe0c1c46a430f33cbef4180",
      "tree": "378f618f574b7d00ac303ffe1666771a87ae78b2",
      "parents": [
        "45b95d1615eaf3efde4f7f9dd4ca83884d96db67"
      ],
      "author": {
        "name": "Felipe Balbi",
        "email": "balbi@ti.com",
        "time": "Tue Sep 02 14:57:20 2014 -0500"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Mon Dec 01 18:02:26 2014 +0800"
      },
      "message": "usb: dwc3: core: fix order of PM runtime calls\n\ncommit fed33afce0eda44a46ae24d93aec1b5198c0bac4 upstream.\n\nCurrently, we disable pm_runtime before all register\naccesses are done, this is dangerous and might lead\nto abort exceptions due to the driver trying to access\na register which is clocked by a clock which was long\ngated.\n\nFix that by moving pm_runtime_put_sync() and pm_runtime_disable()\nas the last thing we do before returning from our -\u003eremove()\nmethod.\n\nFixes: 72246da (usb: Introduce DesignWare USB3 DRD Driver)\nSigned-off-by: Felipe Balbi \u003cbalbi@ti.com\u003e\n[lizf: Backported to 3.4: adjust context]\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "45b95d1615eaf3efde4f7f9dd4ca83884d96db67",
      "tree": "ddb9394d2862a22a34be78faa2572e08043bad99",
      "parents": [
        "b8fad710c579f795c7821bc3202a64b9065c6aec"
      ],
      "author": {
        "name": "Keith Busch",
        "email": "keith.busch@intel.com",
        "time": "Tue Aug 26 09:05:36 2014 -0600"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Mon Dec 01 18:02:26 2014 +0800"
      },
      "message": "block: Fix dev_t minor allocation lifetime\n\ncommit 2da78092dda13f1efd26edbbf99a567776913750 upstream.\n\nReleases the dev_t minor when all references are closed to prevent\nanother device from acquiring the same major/minor.\n\nSince the partition\u0027s release may be invoked from call_rcu\u0027s soft-irq\ncontext, the ext_dev_idr\u0027s mutex had to be replaced with a spinlock so\nas not so sleep.\n\nSigned-off-by: Keith Busch \u003ckeith.busch@intel.com\u003e\nSigned-off-by: Jens Axboe \u003caxboe@fb.com\u003e\n[lizf: Backported to 3.4:\n - adjust context\n - remove idr_preload() and idr_preload_end()]\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "b8fad710c579f795c7821bc3202a64b9065c6aec",
      "tree": "e4de9ddf938f3e94fdbbea3a4f5cff58aaf1f391",
      "parents": [
        "70512a744225525019a698a21ac34c9ebe55dd24"
      ],
      "author": {
        "name": "Ross Lagerwall",
        "email": "ross.lagerwall@citrix.com",
        "time": "Mon Aug 18 10:41:36 2014 +0100"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Mon Dec 01 18:02:25 2014 +0800"
      },
      "message": "xen/manage: Always freeze/thaw processes when suspend/resuming\n\ncommit 61a734d305e16944b42730ef582a7171dc733321 upstream.\n\nAlways freeze processes when suspending and thaw processes when resuming\nto prevent a race noticeable with HVM guests.\n\nThis prevents a deadlock where the khubd kthread (which is designed to\nbe freezable) acquires a usb device lock and then tries to allocate\nmemory which requires the disk which hasn\u0027t been resumed yet.\nMeanwhile, the xenwatch thread deadlocks waiting for the usb device\nlock.\n\nFreezing processes fixes this because the khubd thread is only thawed\nafter the xenwatch thread finishes resuming all the devices.\n\nSigned-off-by: Ross Lagerwall \u003cross.lagerwall@citrix.com\u003e\nSigned-off-by: David Vrabel \u003cdavid.vrabel@citrix.com\u003e\n[lizf: Backported to 3.4: adjust context]\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "70512a744225525019a698a21ac34c9ebe55dd24",
      "tree": "1f342df4a7dc6aea4d6cbfffd18749b3a31e954e",
      "parents": [
        "7a2e66bbc012a990d53dfd764e0a41672203a486"
      ],
      "author": {
        "name": "Bjørn Mork",
        "email": "bjorn@mork.no",
        "time": "Thu Aug 28 15:08:16 2014 +0200"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Mon Dec 01 18:02:25 2014 +0800"
      },
      "message": "USB: sierra: add 1199:68AA device ID\n\ncommit 5b3da69285c143b7ea76b3b9f73099ff1093ab73 upstream.\n\nThis VID:PID is used for some Direct IP devices behaving\nidentical to the already supported 0F3D:68AA devices.\n\nReported-by: Lars Melin \u003clarsm17@gmail.com\u003e\nSigned-off-by: Bjørn Mork \u003cbjorn@mork.no\u003e\nSigned-off-by: Johan Hovold \u003cjohan@kernel.org\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "7a2e66bbc012a990d53dfd764e0a41672203a486",
      "tree": "74c74eb5dd5f20862e235861d7bfae2c635be997",
      "parents": [
        "3adec40f48241e94ee0572434753a0f0f9fd29a9"
      ],
      "author": {
        "name": "Bjørn Mork",
        "email": "bjorn@mork.no",
        "time": "Thu Aug 28 14:11:23 2014 +0200"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Mon Dec 01 18:02:25 2014 +0800"
      },
      "message": "USB: sierra: avoid CDC class functions on \"68A3\" devices\n\ncommit 049255f51644c1105775af228396d187402a5934 upstream.\n\nSierra Wireless Direct IP devices using the 68A3 product ID\ncan be configured for modes including a CDC ECM class function.\nThe known example uses interface numbers 12 and 13 for the ECM\ncontrol and data interfaces respectively, consistent with CDC\nMBIM function interface numbering on other Sierra devices.\n\nIt seems cleaner to restrict this driver to the ff/ff/ff\nvendor specific interfaces rather than increasing the already\nlong interface number blacklist.  This should be more future\nproof if Sierra adds more class functions using interface\nnumbers not yet in the blacklist.\n\nSigned-off-by: Bjørn Mork \u003cbjorn@mork.no\u003e\nSigned-off-by: Johan Hovold \u003cjohan@kernel.org\u003e\n[lizf: Backported to 3.4: adjust context]\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "3adec40f48241e94ee0572434753a0f0f9fd29a9",
      "tree": "c5715653dce89dfdf110a3a483b03b904a382137",
      "parents": [
        "c348b015e25f29e7e7e1dcb2eb5c51e425ffcfa2"
      ],
      "author": {
        "name": "Johan Hovold",
        "email": "johan@kernel.org",
        "time": "Mon Aug 18 18:33:11 2014 +0200"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Mon Dec 01 18:02:24 2014 +0800"
      },
      "message": "USB: ftdi_sio: add support for NOVITUS Bono E thermal printer\n\ncommit ee444609dbae8afee420c3243ce4c5f442efb622 upstream.\n\nAdd device id for NOVITUS Bono E thermal printer.\n\nReported-by: Emanuel Koczwara \u003cpoczta@emanuelkoczwara.pl\u003e\nSigned-off-by: Johan Hovold \u003cjohan@kernel.org\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "c348b015e25f29e7e7e1dcb2eb5c51e425ffcfa2",
      "tree": "59e6edf36a7077ea9f0d4aa29b79630e03e80856",
      "parents": [
        "ffe2456ca91334c76830a015803c76bc62fd7a88"
      ],
      "author": {
        "name": "James Ralston",
        "email": "james.d.ralston@intel.com",
        "time": "Wed Aug 27 14:31:58 2014 -0700"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Mon Dec 01 18:02:24 2014 +0800"
      },
      "message": "ata_piix: Add Device IDs for Intel 9 Series PCH\n\ncommit 6cad1376954e591c3c41500c4e586e183e7ffe6d upstream.\n\nThis patch adds the IDE mode SATA Device IDs for the Intel 9 Series PCH.\n\nSigned-off-by: James Ralston \u003cjames.d.ralston@intel.com\u003e\nSigned-off-by: Tejun Heo \u003ctj@kernel.org\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "ffe2456ca91334c76830a015803c76bc62fd7a88",
      "tree": "c415df714b7557ed3d3e588bc227ec9346061dce",
      "parents": [
        "69dfe16b2bfb488a4b8bb5dadbf3706e82893c85"
      ],
      "author": {
        "name": "James Ralston",
        "email": "james.d.ralston@intel.com",
        "time": "Wed Aug 27 14:29:07 2014 -0700"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Mon Dec 01 18:02:24 2014 +0800"
      },
      "message": "ahci: Add Device IDs for Intel 9 Series PCH\n\ncommit 1b071a0947dbce5c184c12262e02540fbc493457 upstream.\n\nThis patch adds the AHCI mode SATA Device IDs for the Intel 9 Series PCH.\n\nSigned-off-by: James Ralston \u003cjames.d.ralston@intel.com\u003e\nSigned-off-by: Tejun Heo \u003ctj@kernel.org\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "69dfe16b2bfb488a4b8bb5dadbf3706e82893c85",
      "tree": "1580fe944b7d8461566a0793822fb1d72e8c9318",
      "parents": [
        "a48fec2f276f8003fb8098df892ea3acb5d7149a"
      ],
      "author": {
        "name": "Larry Finger",
        "email": "Larry.Finger@lwfinger.net",
        "time": "Sun Aug 24 17:49:43 2014 -0500"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Mon Dec 01 18:02:23 2014 +0800"
      },
      "message": "rtlwifi: rtl8192cu: Add new ID\n\ncommit c66517165610b911e4c6d268f28d8c640832dbd1 upstream.\n\nThe Sitecom WLA-2102 adapter uses this driver.\n\nReported-by: Nico Baggus \u003cnico-linux@noci.xs4all.nl\u003e\nSigned-off-by: Larry Finger \u003cLarry.Finger@lwfinger.net\u003e\nCc: Nico Baggus \u003cnico-linux@noci.xs4all.nl\u003e\nSigned-off-by: John W. Linville \u003clinville@tuxdriver.com\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "a48fec2f276f8003fb8098df892ea3acb5d7149a",
      "tree": "f9215afbe8d73833a7c5eaba2f6dc54ed4b8f96c",
      "parents": [
        "c16060dfda1c8418a9e638b79f5d2101b482e89f"
      ],
      "author": {
        "name": "Alban Crequy",
        "email": "alban.crequy@collabora.co.uk",
        "time": "Mon Aug 18 12:20:20 2014 +0100"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Mon Dec 01 18:02:23 2014 +0800"
      },
      "message": "cgroup: reject cgroup names with \u0027 \u0027\n\ncommit 71b1fb5c4473a5b1e601d41b109bdfe001ec82e0 upstream.\n\n/proc/\u003cpid\u003e/cgroup contains one cgroup path on each line. If cgroup names are\nallowed to contain \"\\n\", applications cannot parse /proc/\u003cpid\u003e/cgroup safely.\n\nSigned-off-by: Alban Crequy \u003calban.crequy@collabora.co.uk\u003e\nSigned-off-by: Tejun Heo \u003ctj@kernel.org\u003e\n[lizf: Backported to 3.4:\n - adjust context\n - s/name/dentry-\u003ed_name.name/]\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "c16060dfda1c8418a9e638b79f5d2101b482e89f",
      "tree": "383e904ef99f3271af0556aff4940030d6ee6aec",
      "parents": [
        "bd188dc72de0ce3e4671eea2641b14858bd28788"
      ],
      "author": {
        "name": "Honggang Li",
        "email": "enjoymindful@gmail.com",
        "time": "Tue Aug 12 21:36:15 2014 +0800"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Mon Dec 01 18:02:23 2014 +0800"
      },
      "message": "percpu: free percpu allocation info for uniprocessor system\n\ncommit 3189eddbcafcc4d827f7f19facbeddec4424eba8 upstream.\n\nCurrently, only SMP system free the percpu allocation info.\nUniprocessor system should free it too. For example, one x86 UML\nvirtual machine with 256MB memory, UML kernel wastes one page memory.\n\nSigned-off-by: Honggang Li \u003cenjoymindful@gmail.com\u003e\nSigned-off-by: Tejun Heo \u003ctj@kernel.org\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "bd188dc72de0ce3e4671eea2641b14858bd28788",
      "tree": "e4eb8d2917da6584ae4f43c8484b1fd1ff84ff86",
      "parents": [
        "240269ae890ff269c384c94746b57d904f756205"
      ],
      "author": {
        "name": "Tejun Heo",
        "email": "tj@kernel.org",
        "time": "Fri Aug 15 16:06:10 2014 -0400"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Mon Dec 01 18:02:23 2014 +0800"
      },
      "message": "percpu: perform tlb flush after pcpu_map_pages() failure\n\ncommit 849f5169097e1ba35b90ac9df76b5bb6f9c0aabd upstream.\n\nIf pcpu_map_pages() fails midway, it unmaps the already mapped pages.\nCurrently, it doesn\u0027t flush tlb after the partial unmapping.  This may\nbe okay in most cases as the established mapping hasn\u0027t been used at\nthat point but it can go wrong and when it goes wrong it\u0027d be\nextremely difficult to track down.\n\nFlush tlb after the partial unmapping.\n\nSigned-off-by: Tejun Heo \u003ctj@kernel.org\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "240269ae890ff269c384c94746b57d904f756205",
      "tree": "6e970e4caf218efdb475cda2a97ded6867c1620a",
      "parents": [
        "be93eea739598a5bf2562110323d79d80d0e6a33"
      ],
      "author": {
        "name": "Tejun Heo",
        "email": "tj@kernel.org",
        "time": "Fri Aug 15 16:06:06 2014 -0400"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Mon Dec 01 18:02:22 2014 +0800"
      },
      "message": "percpu: fix pcpu_alloc_pages() failure path\n\ncommit f0d279654dea22b7a6ad34b9334aee80cda62cde upstream.\n\nWhen pcpu_alloc_pages() fails midway, pcpu_free_pages() is invoked to\nfree what has already been allocated.  The invocation is across the\nwhole requested range and pcpu_free_pages() will try to free all\nnon-NULL pages; unfortunately, this is incorrect as\npcpu_get_pages_and_bitmap(), unlike what its comment suggests, doesn\u0027t\nclear the pages array and thus the array may have entries from the\nprevious invocations making the partial failure path free incorrect\npages.\n\nFix it by open-coding the partial freeing of the already allocated\npages.\n\nSigned-off-by: Tejun Heo \u003ctj@kernel.org\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "be93eea739598a5bf2562110323d79d80d0e6a33",
      "tree": "58479ef6306aea7696730678edfe87d6523ed4e5",
      "parents": [
        "a51b4d7710d1a3593c3bdc4592fdecbbb8df4f16"
      ],
      "author": {
        "name": "Eliad Peller",
        "email": "eliad@wizery.com",
        "time": "Wed Jun 11 10:23:35 2014 +0300"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Mon Dec 01 18:02:22 2014 +0800"
      },
      "message": "regulatory: add NUL to alpha2\n\ncommit a5fe8e7695dc3f547e955ad2b662e3e72969e506 upstream.\n\nalpha2 is defined as 2-chars array, but is used in multiple\nplaces as string (e.g. with nla_put_string calls), which\nmight leak kernel data.\n\nSolve it by simply adding an extra char for the NULL\nterminator, making such operations safe.\n\nSigned-off-by: Eliad Peller \u003celiadx.peller@intel.com\u003e\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\n[lizf: Backported to 3.4: adjust context]\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "a51b4d7710d1a3593c3bdc4592fdecbbb8df4f16",
      "tree": "3cb4ef6c1f4a55cb93cc4e47039932873e78ed9e",
      "parents": [
        "a643fab2d72b817d72320aa504a9887bd6d01046"
      ],
      "author": {
        "name": "Jiri Kosina",
        "email": "jkosina@suse.cz",
        "time": "Wed Sep 03 15:04:28 2014 +0200"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Mon Dec 01 18:02:22 2014 +0800"
      },
      "message": "ACPI / cpuidle: fix deadlock between cpuidle_lock and cpu_hotplug.lock\n\ncommit 6726655dfdd2dc60c035c690d9f10cb69d7ea075 upstream.\n\nThere is a following AB-BA dependency between cpu_hotplug.lock and\ncpuidle_lock:\n\n1) cpu_hotplug.lock -\u003e cpuidle_lock\nenable_nonboot_cpus()\n _cpu_up()\n  cpu_hotplug_begin()\n   LOCK(cpu_hotplug.lock)\n cpu_notify()\n  ...\n  acpi_processor_hotplug()\n   cpuidle_pause_and_lock()\n    LOCK(cpuidle_lock)\n\n2) cpuidle_lock -\u003e cpu_hotplug.lock\nacpi_os_execute_deferred() workqueue\n ...\n acpi_processor_cst_has_changed()\n  cpuidle_pause_and_lock()\n   LOCK(cpuidle_lock)\n  get_online_cpus()\n   LOCK(cpu_hotplug.lock)\n\nFix this by reversing the order acpi_processor_cst_has_changed() does\nthigs -- let it first execute the protection against CPU hotplug by\ncalling get_online_cpus() and obtain the cpuidle lock only after that (and\nperform the symmentric change when allowing CPUs hotplug again and\ndropping cpuidle lock).\n\nSpotted by lockdep.\n\nSigned-off-by: Jiri Kosina \u003cjkosina@suse.cz\u003e\nSigned-off-by: Rafael J. Wysocki \u003crafael.j.wysocki@intel.com\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "a643fab2d72b817d72320aa504a9887bd6d01046",
      "tree": "98c70a4dff3d1cd14e0720d07e0277391fbf8d64",
      "parents": [
        "94667ee06fc9383403396c5a8e9b5df55f98a2e2"
      ],
      "author": {
        "name": "Takashi Iwai",
        "email": "tiwai@suse.de",
        "time": "Tue Sep 02 07:21:56 2014 +0200"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Mon Dec 01 18:02:21 2014 +0800"
      },
      "message": "ALSA: hda - Fix COEF setups for ALC1150 codec\n\ncommit acf08081adb5e8fe0519eb97bb49797ef52614d6 upstream.\n\nALC1150 codec seems to need the COEF- and PLL-setups just like its\ncompatible ALC882 codec.  Some machines (e.g. SunMicro X10SAT) show\nthe problem like too low output volumes unless the COEF setup is\napplied.\n\nReported-and-tested-by: Dana Goyette \u003cdanagoyette@gmail.com\u003e\nSigned-off-by: Takashi Iwai \u003ctiwai@suse.de\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "94667ee06fc9383403396c5a8e9b5df55f98a2e2",
      "tree": "01cc8caf747d0cb994b2867faecad69e31540539",
      "parents": [
        "f9c3484ebd0a5a4918c50612c8400e4ab91ebf92"
      ],
      "author": {
        "name": "Thomas Hellstrom",
        "email": "thellstrom@vmware.com",
        "time": "Thu Aug 28 11:53:23 2014 +0200"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Mon Dec 01 18:02:21 2014 +0800"
      },
      "message": "drm/vmwgfx: Fix a potential infinite spin waiting for fifo idle\n\ncommit f01ea0c3d9db536c64d47922716d8b3b8f21d850 upstream.\n\nThe code waiting for fifo idle was incorrect and could possibly spin\nforever under certain circumstances.\n\nSigned-off-by: Thomas Hellstrom \u003cthellstrom@vmware.com\u003e\nReported-by: Mark Sheldon \u003cmarkshel@vmware.com\u003e\nReviewed-by: Jakob Bornecrantz \u003cjakob@vmware.com\u003e\nReivewed-by: Mark Sheldon \u003cmarkshel@vmware.com\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "f9c3484ebd0a5a4918c50612c8400e4ab91ebf92",
      "tree": "cebe659d48131e32ff6bbcbc7aab423b27c287e0",
      "parents": [
        "9b9d7b3078f8f4a8fa4b72aa2abd118602f942f2"
      ],
      "author": {
        "name": "Al Viro",
        "email": "viro@zeniv.linux.org.uk",
        "time": "Mon Aug 18 15:09:26 2014 -0400"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Mon Dec 01 18:02:21 2014 +0800"
      },
      "message": "get rid of propagate_umount() mistakenly treating slaves as busy.\n\ncommit 88b368f27a094277143d8ecd5a056116f6a41520 upstream.\n\nThe check in __propagate_umount() (\"has somebody explicitly mounted\nsomething on that slave?\") is done *before* taking the already doomed\nvictims out of the child lists.\n\nSigned-off-by: Al Viro \u003cviro@zeniv.linux.org.uk\u003e\n[lizf: Backported to 3.4:\n - adjust context\n - s/hlist_for_each_entry/list_for_each_entry/]\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "9b9d7b3078f8f4a8fa4b72aa2abd118602f942f2",
      "tree": "2cf6e5f4cac732b6d8492f67d6696d5c983d3a80",
      "parents": [
        "219fb6410b9e4ba3a3a28c12c73579eef921cb31"
      ],
      "author": {
        "name": "Mathias Krause",
        "email": "minipli@googlemail.com",
        "time": "Wed Aug 27 18:41:19 2014 +0200"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Mon Dec 01 18:02:20 2014 +0800"
      },
      "message": "drm/i915: Remove bogus __init annotation from DMI callbacks\n\ncommit bbe1c2740d3a25aa1dbe5d842d2ff09cddcdde0a upstream.\n\nThe __init annotations for the DMI callback functions are wrong as this\ncode can be called even after the module has been initialized, e.g. like\nthis:\n\n  # echo 1 \u003e /sys/bus/pci/devices/0000:00:02.0/remove\n  # modprobe i915\n  # echo 1 \u003e /sys/bus/pci/rescan\n\nThe first command will remove the PCI device from the kernel\u0027s device\nlist so the second command won\u0027t see it right away. But as it registers\na PCI driver it\u0027ll see it on the third command. If the system happens to\nmatch one of the DMI table entries we\u0027ll try to call a function in long\nreleased memory and generate an Oops, at best.\n\nFix this by removing the bogus annotation.\n\nModpost should have caught that one but it ignores section reference\nmismatches from the .rodata section. :/\n\nFixes: 25e341cfc33d (\"drm/i915: quirk away broken OpRegion VBT\")\nFixes: 8ca4013d702d (\"CHROMIUM: i915: Add DMI override to skip CRT...\")\nFixes: 425d244c8670 (\"drm/i915: ignore LVDS on intel graphics systems...\")\nSigned-off-by: Mathias Krause \u003cminipli@googlemail.com\u003e\nCc: Daniel Vetter \u003cdaniel.vetter@ffwll.ch\u003e\nCc: Duncan Laurie \u003cdlaurie@chromium.org\u003e\nCc: Jarod Wilson \u003cjarod@redhat.com\u003e\nCc: Rusty Russell \u003crusty@rustcorp.com.au\u003e\t# Can modpost be fixed?\nSigned-off-by: Jani Nikula \u003cjani.nikula@intel.com\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "219fb6410b9e4ba3a3a28c12c73579eef921cb31",
      "tree": "17b07ded15604eb74b9c2c1153478769d4dcdee0",
      "parents": [
        "f999b1962a34f97cec52c3adff81d79890697a7f"
      ],
      "author": {
        "name": "Mark Brown",
        "email": "broonie@linaro.org",
        "time": "Tue Aug 26 12:12:17 2014 +0100"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Mon Dec 01 18:02:20 2014 +0800"
      },
      "message": "regmap: Fix handling of volatile registers for format_write() chips\n\ncommit 5844a8b9d98ec11ce1d77610daacf3f0a0e14715 upstream.\n\nA previous over-zealous factorisation of code means that we only treat\nregisters as volatile if they are readable. For most devices this is fine\nsince normally most registers can be read and volatility implies\nreadability but for format_write() devices where there is no readback from\nthe hardware and we use volatility to mean simply uncacheability this means\nthat we end up treating all registers as cacheble.\n\nA bigger refactoring of the code to clarify this is in order but as a fix\nmake a minimal change and only check readability when checking volatility\nif there is no format_write() operation defined for the device.\n\nSigned-off-by: Mark Brown \u003cbroonie@linaro.org\u003e\nTested-by: Lars-Peter Clausen \u003clars@metafoo.de\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "f999b1962a34f97cec52c3adff81d79890697a7f",
      "tree": "e342566145f1d86c288ba1aa423886295ce8e15e",
      "parents": [
        "bb4a05a0400ed6d2f1e13d1f82f289ff74300a70"
      ],
      "author": {
        "name": "Christian Borntraeger",
        "email": "borntraeger@de.ibm.com",
        "time": "Wed Aug 06 16:17:58 2014 +0200"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Mon Dec 01 18:02:20 2014 +0800"
      },
      "message": "KVM: s390: Fix user triggerable bug in dead code\n\ncommit 614a80e474b227cace52fd6e3c790554db8a396e upstream.\n\nIn the early days, we had some special handling for the\nKVM_EXIT_S390_SIEIC exit, but this was gone in 2009 with commit\nd7b0b5eb3000 (KVM: s390: Make psw available on all exits, not\njust a subset).\n\nNow this switch statement is just a sanity check for userspace\nnot messing with the kvm_run structure. Unfortunately, this\nallows userspace to trigger a kernel BUG. Let\u0027s just remove\nthis switch statement.\n\nSigned-off-by: Christian Borntraeger \u003cborntraeger@de.ibm.com\u003e\nReviewed-by: Cornelia Huck \u003ccornelia.huck@de.ibm.com\u003e\nReviewed-by: David Hildenbrand \u003cdahi@linux.vnet.ibm.com\u003e\n[lizf: Backported to 3.4:\n - adjust context\n - no KVM_EXIT_S390_TSCH and KVM_EXIT_DEBUG in 3.4]\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "bb4a05a0400ed6d2f1e13d1f82f289ff74300a70",
      "tree": "2cc19badf62131b24409a7c870db22e94ef7fa2a",
      "parents": [
        "618dea44abf8e7766501ea94e9eda9308e1e4593"
      ],
      "author": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:19 2014 +0800"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:19 2014 +0800"
      },
      "message": "Linux 3.4.104\n"
    },
    {
      "commit": "618dea44abf8e7766501ea94e9eda9308e1e4593",
      "tree": "7ba01b5147f7852b8399c692ab9e1ce0cb18828e",
      "parents": [
        "3a8f61352a884762e6485ab21af08054b76cff69"
      ],
      "author": {
        "name": "Michael Cree",
        "email": "mcree@orcon.net.nz",
        "time": "Wed Nov 30 08:01:40 2011 -0500"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:19 2014 +0800"
      },
      "message": "alpha: add io{read,write}{16,32}be functions\n\ncommit 25534eb7707821b796fd84f7115367e02f36aa60 upstream.\n\nThese functions are used in some PCI drivers with big-endian\nMMIO space.\n\nAdmittedly it is almost certain that no one this side of the\nMoon would use such a card in an Alpha but it does get us\ncloser to being able to build allyesconfig or allmodconfig,\nand it enables the Debian default generic config to build.\n\nTested-by: Raúl Porcel \u003carmin76@gentoo.org\u003e\nSigned-off-by: Michael Cree \u003cmcree@orcon.net.nz\u003e\nSigned-off-by: Matt Turner \u003cmattst88@gmail.com\u003e\nCc: Guenter Roeck \u003clinux@roeck-us.net\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "3a8f61352a884762e6485ab21af08054b76cff69",
      "tree": "d2fd8c697703799b1eae0d0c21b1fa7c9ec5b6b0",
      "parents": [
        "f79bb94b5ae6581d81f7b65cfc8f11e86bc2c8de"
      ],
      "author": {
        "name": "Jan Kara",
        "email": "jack@suse.cz",
        "time": "Tue Nov 05 01:15:38 2013 +0100"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:19 2014 +0800"
      },
      "message": "ext2: Fix fs corruption in ext2_get_xip_mem()\n\ncommit 7ba3ec5749ddb61f79f7be17b5fd7720eebc52de upstream.\n\nCommit 8e3dffc651cb \"Ext2: mark inode dirty after the function\ndquot_free_block_nodirty is called\" unveiled a bug in __ext2_get_block()\ncalled from ext2_get_xip_mem(). That function called ext2_get_block()\nmistakenly asking it to map 0 blocks while 1 was intended. Before the\nabove mentioned commit things worked out fine by luck but after that commit\nwe started returning that we allocated 0 blocks while we in fact\nallocated 1 block and thus allocation was looping until all blocks in\nthe filesystem were exhausted.\n\nFix the problem by properly asking for one block and also add assertion\nin ext2_get_blocks() to catch similar problems.\n\nReported-and-tested-by: Andiry Xu \u003candiry.xu@gmail.com\u003e\nSigned-off-by: Jan Kara \u003cjack@suse.cz\u003e\nCc: Wang Nan \u003cwangnan0@huawei.com\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "f79bb94b5ae6581d81f7b65cfc8f11e86bc2c8de",
      "tree": "3798a4ad1b94a66f3c89f36f796193e44f5f7e37",
      "parents": [
        "92a6e26fd0c8ba921890dd6adc0166f5ef927f8c"
      ],
      "author": {
        "name": "Michael Cree",
        "email": "mcree@orcon.net.nz",
        "time": "Sun Aug 19 14:41:04 2012 +1200"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:18 2014 +0800"
      },
      "message": "alpha: Fix fall-out from disintegrating asm/system.h\n\ncommit d1b5153f3ec83789b71d64efaf2a880c8fe6358e upstream.\n\nCommit ec2212088c42 (\"Disintegrate asm/system.h for Alpha\") removed\nasm/system.h however arch/alpha/oprofile/common.c requires definitions\nthat were shifted from asm/system.h to asm/special_insns.h.  Include\nthat.\n\nSigned-off-by: Michael Cree \u003cmcree@orcon.net.nz\u003e\nAcked-by: Matt Turner \u003cmattst88@gmail.com\u003e\nSigned-off-by: Linus Torvalds \u003ctorvalds@linux-foundation.org\u003e\nCc: Guenter Roeck \u003clinux@roeck-us.net\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "92a6e26fd0c8ba921890dd6adc0166f5ef927f8c",
      "tree": "c006595a1e13ef403dd94f47595e0004e1c63057",
      "parents": [
        "4e36063eb13e743f1fdac0a65055c3f5fe28e387"
      ],
      "author": {
        "name": "Guan Xuetao",
        "email": "gxt@mprc.pku.edu.cn",
        "time": "Thu Jun 14 15:39:48 2012 +0800"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:18 2014 +0800"
      },
      "message": "UniCore32-bugfix: fix mismatch return value of __xchg_bad_pointer\n\ncommit 195d4577d1d7ab1f0398b3190547c116b56f435f upstream.\n\nWhen disintegrate system.h, I left an error in asm/cmpxchg.h, which\nwill result in following error:\n\narch/unicore32/include/asm/cmpxchg.h: In function \u0027__xchg\u0027:\narch/unicore32/include/asm/cmpxchg.h:38: error: void value not ignored as it ought to be\n\nSigned-off-by: Guan Xuetao \u003cgxt@mprc.pku.edu.cn\u003e\nCc: Guenter Roeck \u003clinux@roeck-us.net\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "4e36063eb13e743f1fdac0a65055c3f5fe28e387",
      "tree": "de75799127880ca1053e7821df9597e0bf518e65",
      "parents": [
        "62cdcceec9ccfac48f59bd03a258f91cb9700f45"
      ],
      "author": {
        "name": "Guan Xuetao",
        "email": "gxt@mprc.pku.edu.cn",
        "time": "Thu Jun 14 11:38:25 2012 +0800"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:18 2014 +0800"
      },
      "message": "UniCore32-bugfix: Remove definitions in asm/bug.h to solve difference between native and cross compiler\n\ncommit 10e1e99e55378a65529c48753703c069aebce7af upstream.\n\nFor kernel/bound.c being compiled by native compiler, it will generate following errors in gcc 4.4.3:\n  CC      kernel/bounds.s\nIn file included from include/linux/bug.h:4,\n                 from include/linux/page-flags.h:9,\n                 from kernel/bounds.c:9:\narch/unicore32/include/asm/bug.h:22: error: expected \u0027\u003d\u0027, \u0027,\u0027, \u0027;\u0027, \u0027asm\u0027 or \u0027__attribute__\u0027 before \u0027void\u0027\narch/unicore32/include/asm/bug.h:23: error: expected \u0027\u003d\u0027, \u0027,\u0027, \u0027;\u0027, \u0027asm\u0027 or \u0027__attribute__\u0027 before \u0027void\u0027\n\nSo, we moved definitions in asm/bug.h to arch/unicore32/kernel/setup.h to solve the problem.\n\nSigned-off-by: Guan Xuetao \u003cgxt@mprc.pku.edu.cn\u003e\nCc: Guenter Roeck \u003clinux@roeck-us.net\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "62cdcceec9ccfac48f59bd03a258f91cb9700f45",
      "tree": "6f6a6eaa57ebbe48855f83429198724ef8e82e49",
      "parents": [
        "82a938ab75f966ee228ee85665cd074c5d078b42"
      ],
      "author": {
        "name": "Fengguang Wu",
        "email": "fengguang.wu@intel.com",
        "time": "Thu Oct 04 17:11:23 2012 -0700"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:18 2014 +0800"
      },
      "message": "unicore32: select generic atomic64_t support\n\ncommit 82e54a6aaf8aec971fb16afa3a4404e238a1b98b upstream.\n\nIt\u0027s required for the core fs/namespace.c and many other basic features.\n\nSigned-off-by: Guan Xuetao \u003cgxt@mprc.pku.edu.cn\u003e\nSigned-off-by: Fengguang Wu \u003cfengguang.wu@intel.com\u003e\nCc: \"Eric W. Biederman\" \u003cebiederm@xmission.com\u003e\nSigned-off-by: Andrew Morton \u003cakpm@linux-foundation.org\u003e\nSigned-off-by: Linus Torvalds \u003ctorvalds@linux-foundation.org\u003e\nCc: Guenter Roeck \u003clinux@roeck-us.net\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "82a938ab75f966ee228ee85665cd074c5d078b42",
      "tree": "3b4a11bb7dde3b9bb4f9eba4ad5eba465368422e",
      "parents": [
        "69db2d4044cc494b03bad01b2e106f7324ef3fdf"
      ],
      "author": {
        "name": "Paul Gortmaker",
        "email": "paul.gortmaker@windriver.com",
        "time": "Mon Aug 25 13:33:20 2014 -0400"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:18 2014 +0800"
      },
      "message": "8250_pci: fix warnings in backport of Broadcom TruManage support\n\ncommit 7400ce7ee9595432b2a1402b6ffcac9faf38d9ae (v3.4.92-76-g7400ce7ee959)\nwas a backport of commit ebebd49a8eab5e9aa1b1f8f1614ccc3c2120f886 upstream\n(\"8250/16?50: Add support for Broadcom TruManage redirected serial port\")\n\nHowever, in the context of 3.4.x kernels, the pci setup code was\nexpecting a struct uart_port and not a struct uart_8250_port, leading to\nthe following concerning warnings:\n\ndrivers/tty/serial/8250/8250_pci.c: In function ‘pci_brcm_trumanage_setup’:\ndrivers/tty/serial/8250/8250_pci.c:1086:2: warning: passing argument 3 of ‘pci_default_setup’ from incompatible pointer type [enabled by default]\n  int ret \u003d pci_default_setup(priv, board, port, idx);\n  ^\ndrivers/tty/serial/8250/8250_pci.c:1036:1: note: expected ‘struct uart_port *’ but argument is of type ‘struct uart_8250_port *’\n pci_default_setup(struct serial_private *priv,\n ^\ndrivers/tty/serial/8250/8250_pci.c: At top level:\ndrivers/tty/serial/8250/8250_pci.c:1746:3: warning: initialization from incompatible pointer type [enabled by default]\n   .setup  \u003d pci_brcm_trumanage_setup,\n   ^\ndrivers/tty/serial/8250/8250_pci.c:1746:3: warning: (near initialization for ‘pci_serial_quirks[56].setup’) [enabled by default]\n\nI\u0027d also expect the initialization to not function correctly, and\nperhaps dereference random garbage due to this.  Since the uart_port\nis a field within the uart_8250_port, the adaptation to fix these\nwarnings is a straightforward removal of a layer of indirection.\n\nCc: Stephen Hurd \u003cshurd@broadcom.com\u003e\nCc: Michael Chan \u003cmchan@broadcom.com\u003e\nCc: Ben Hutchings \u003cben@decadent.org.uk\u003e\nCc: Rui Xiang \u003crui.xiang@huawei.com\u003e\nCc: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\nSigned-off-by: Paul Gortmaker \u003cpaul.gortmaker@windriver.com\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "69db2d4044cc494b03bad01b2e106f7324ef3fdf",
      "tree": "ce09bfaf1099abfdd23e71c52652fde1e8ba35a3",
      "parents": [
        "ab22539512b325240dac92e92bbaf1d9aebaa2e5"
      ],
      "author": {
        "name": "Andi Kleen",
        "email": "ak@linux.intel.com",
        "time": "Sat Jun 09 02:40:03 2012 -0700"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:17 2014 +0800"
      },
      "message": "slab/mempolicy: always use local policy from interrupt context\n\ncommit e7b691b085fda913830e5280ae6f724b2a63c824 upstream.\n\nslab_node() could access current-\u003emempolicy from interrupt context.\nHowever there\u0027s a race condition during exit where the mempolicy\nis first freed and then the pointer zeroed.\n\nUsing this from interrupts seems bogus anyways. The interrupt\nwill interrupt a random process and therefore get a random\nmempolicy. Many times, this will be idle\u0027s, which noone can change.\n\nJust disable this here and always use local for slab\nfrom interrupts. I also cleaned up the callers of slab_node a bit\nwhich always passed the same argument.\n\nI believe the original mempolicy code did that in fact,\nso it\u0027s likely a regression.\n\nv2: send version with correct logic\nv3: simplify. fix typo.\nReported-by: Arun Sharma \u003casharma@fb.com\u003e\nCc: penberg@kernel.org\nCc: cl@linux.com\nSigned-off-by: Andi Kleen \u003cak@linux.intel.com\u003e\n[tdmackey@twitter.com: Rework control flow based on feedback from\ncl@linux.com, fix logic, and cleanup current task_struct reference]\nAcked-by: David Rientjes \u003crientjes@google.com\u003e\nAcked-by: Christoph Lameter \u003ccl@linux.com\u003e\nAcked-by: KOSAKI Motohiro \u003ckosaki.motohiro@jp.fujitsu.com\u003e\nSigned-off-by: David Mackey \u003ctdmackey@twitter.com\u003e\nSigned-off-by: Pekka Enberg \u003cpenberg@kernel.org\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "ab22539512b325240dac92e92bbaf1d9aebaa2e5",
      "tree": "5a76ec72da3a47a4682d99945a98cb67ca5401cf",
      "parents": [
        "c1bc007ebe663237823bb9548f658c35c2e8f925"
      ],
      "author": {
        "name": "Stefan Kristiansson",
        "email": "stefan.kristiansson@saunalahti.fi",
        "time": "Tue Feb 26 07:36:29 2013 +0100"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:17 2014 +0800"
      },
      "message": "openrisc: add missing header inclusion\n\ncommit 160d83781a32e94a1e337efd6722939001e62398 upstream.\n\nPrevents build issue with updated toolchain\n\nReported-by: Jack Thomasson \u003cjkt@moonlitsw.com\u003e\nTested-by: Christian Svensson \u003cblue@cmd.nu\u003e\nSigned-off-by: Stefan Kristiansson \u003cstefan.kristiansson@saunalahti.fi\u003e\nSigned-off-by: Jonas Bonn \u003cjonas@southpole.se\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "c1bc007ebe663237823bb9548f658c35c2e8f925",
      "tree": "fddabcbdb73ce362da3033532ca876285166e54e",
      "parents": [
        "9a8fa93c3da316ca32c91baead518d0308ae3472"
      ],
      "author": {
        "name": "Ralf Baechle",
        "email": "ralf@linux-mips.org",
        "time": "Tue Sep 17 12:44:31 2013 +0200"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:17 2014 +0800"
      },
      "message": "MIPS: Fix accessing to per-cpu data when flushing the cache\n\ncommit ff522058bd717506b2fa066fa564657f2b86477e upstream.\n\nThis fixes the following issue\n\nBUG: using smp_processor_id() in preemptible [00000000] code: kjournald/1761\ncaller is blast_dcache32+0x30/0x254\nCall Trace:\n[\u003c8047f02c\u003e] dump_stack+0x8/0x34\n[\u003c802e7e40\u003e] debug_smp_processor_id+0xe0/0xf0\n[\u003c80114d94\u003e] blast_dcache32+0x30/0x254\n[\u003c80118484\u003e] r4k_dma_cache_wback_inv+0x200/0x288\n[\u003c80110ff0\u003e] mips_dma_map_sg+0x108/0x180\n[\u003c80355098\u003e] ide_dma_prepare+0xf0/0x1b8\n[\u003c8034eaa4\u003e] do_rw_taskfile+0x1e8/0x33c\n[\u003c8035951c\u003e] ide_do_rw_disk+0x298/0x3e4\n[\u003c8034a3c4\u003e] do_ide_request+0x2e0/0x704\n[\u003c802bb0dc\u003e] __blk_run_queue+0x44/0x64\n[\u003c802be000\u003e] queue_unplugged.isra.36+0x1c/0x54\n[\u003c802beb94\u003e] blk_flush_plug_list+0x18c/0x24c\n[\u003c802bec6c\u003e] blk_finish_plug+0x18/0x48\n[\u003c8026554c\u003e] journal_commit_transaction+0x3b8/0x151c\n[\u003c80269648\u003e] kjournald+0xec/0x238\n[\u003c8014ac00\u003e] kthread+0xb8/0xc0\n[\u003c8010268c\u003e] ret_from_kernel_thread+0x14/0x1c\n\nCaches in most systems are identical - but not always, so we can\u0027t avoid\nthe use of smp_call_function() by just looking at the boot CPU\u0027s data,\nhave to fiddle with preemption instead.\n\nSigned-off-by: Ralf Baechle \u003cralf@linux-mips.org\u003e\nCc: Markos Chandras \u003cmarkos.chandras@imgtec.com\u003e\nCc: linux-mips@linux-mips.org\nPatchwork: https://patchwork.linux-mips.org/patch/5835\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "9a8fa93c3da316ca32c91baead518d0308ae3472",
      "tree": "893520c993738f13c2f21dda6bb817ac68495566",
      "parents": [
        "c804743181ad14578d8ea5b2e7b8bd7a2efe64ae"
      ],
      "author": {
        "name": "Florian Fainelli",
        "email": "florian@openwrt.org",
        "time": "Thu Jul 19 09:13:52 2012 +0200"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:17 2014 +0800"
      },
      "message": "MIPS: perf: Fix build error caused by unused counters_per_cpu_to_total()\n\ncommit 6c37c9580409af7dc664bb6af0a85d540d63aeea upstream.\n\ncc1: warnings being treated as errors\narch/mips/kernel/perf_event_mipsxx.c:166: error: \u0027counters_per_cpu_to_total\u0027 defined but not used\nmake[2]: *** [arch/mips/kernel/perf_event_mipsxx.o] Error 1\nmake[2]: *** Waiting for unfinished jobs....\n\nIt was first introduced by 82091564cfd7ab8def42777a9c662dbf655c5d25 [MIPS:\nperf: Add support for 64-bit perf counters.] in 3.2.\n\nSigned-off-by: Florian Fainelli \u003cflorian@openwrt.org\u003e\nCc: linux-mips@linux-mips.org\nCc: david.daney@cavium.com\nPatchwork: https://patchwork.linux-mips.org/patch/3357/\nSigned-off-by: Ralf Baechle \u003cralf@linux-mips.org\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "c804743181ad14578d8ea5b2e7b8bd7a2efe64ae",
      "tree": "6dbdaa1273cc39cf8d229bd84ea9c3ab1d974eec",
      "parents": [
        "62148f769ff1041f92bf0bad4dd820615f29861f"
      ],
      "author": {
        "name": "Johan Hovold",
        "email": "johan@kernel.org",
        "time": "Wed Aug 27 11:55:19 2014 +0200"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:16 2014 +0800"
      },
      "message": "USB: serial: fix potential heap buffer overflow\n\ncommit 5654699fb38512bdbfc0f892ce54fce75bdc2bab upstream.\n\nMake sure to verify the number of ports requested by subdriver to avoid\nwriting beyond the end of fixed-size array in interface data.\n\nThe current usb-serial implementation is limited to eight ports per\ninterface but failed to verify that the number of ports requested by a\nsubdriver (which could have been determined from device descriptors) did\nnot exceed this limit.\n\nSigned-off-by: Johan Hovold \u003cjohan@kernel.org\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n[lizf: Backported to 3.4: s/ddev/\\\u0026interface-\u003edev/]\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "62148f769ff1041f92bf0bad4dd820615f29861f",
      "tree": "d73ca763fe4375a6debb7c5474b955cb6683797b",
      "parents": [
        "2f3e285da53ae6002cabb028438a65b9f9cee534"
      ],
      "author": {
        "name": "Johan Hovold",
        "email": "johan@kernel.org",
        "time": "Wed Aug 27 11:55:18 2014 +0200"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:16 2014 +0800"
      },
      "message": "USB: serial: fix potential stack buffer overflow\n\ncommit d979e9f9ecab04c1ecca741370e30a8a498893f5 upstream.\n\nMake sure to verify the maximum number of endpoints per type to avoid\nwriting beyond the end of a stack-allocated array.\n\nThe current usb-serial implementation is limited to eight ports per\ninterface but failed to verify that the number of endpoints of a certain\ntype reported by a device did not exceed this limit.\n\nSigned-off-by: Johan Hovold \u003cjohan@kernel.org\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n[lizf: Backported to 3.4: adjust context]\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "2f3e285da53ae6002cabb028438a65b9f9cee534",
      "tree": "da3943e7a063b9bcfc004cd016f55a0ef1a894e5",
      "parents": [
        "5624bb35686b13e17438aaf211586556bcba58da"
      ],
      "author": {
        "name": "Mark Rutland",
        "email": "mark.rutland@arm.com",
        "time": "Fri Aug 15 12:11:50 2014 +0100"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:16 2014 +0800"
      },
      "message": "ARM: 8129/1: errata: work around Cortex-A15 erratum 830321 using dummy strex\n\ncommit 2c32c65e3726c773760038910be30cce1b4d4149 upstream.\n\nOn revisions of Cortex-A15 prior to r3p3, a CLREX instruction at PL1 may\nfalsely trigger a watchpoint exception, leading to potential data aborts\nduring exception return and/or livelock.\n\nThis patch resolves the issue in the following ways:\n\n  - Replacing our uses of CLREX with a dummy STREX sequence instead (as\n    we did for v6 CPUs).\n\n  - Removing the clrex code from v7_exit_coherency_flush and derivatives,\n    since this only exists as a minor performance improvement when\n    non-cached exclusives are in use (Linux doesn\u0027t use these).\n\nBenchmarking on a variety of ARM cores revealed no measurable\nperformance difference with this change applied, so the change is\nperformed unconditionally and no new Kconfig entry is added.\n\nSigned-off-by: Mark Rutland \u003cmark.rutland@arm.com\u003e\nSigned-off-by: Will Deacon \u003cwill.deacon@arm.com\u003e\nSigned-off-by: Russell King \u003crmk+kernel@arm.linux.org.uk\u003e\n[lizf: Backported to 3.4:\n - Drop changes to arch/arm/include/asm/cacheflush.h and\n   arch/arm/mach-exynos/mcpm-exynos.c]\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "5624bb35686b13e17438aaf211586556bcba58da",
      "tree": "2587d0dde2f895b721a1a01ec50691a84e7cc365",
      "parents": [
        "e78c127e8ee714142edb1d76956ebf40750ab218"
      ],
      "author": {
        "name": "Mark Rutland",
        "email": "mark.rutland@arm.com",
        "time": "Fri Aug 15 12:11:49 2014 +0100"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:16 2014 +0800"
      },
      "message": "ARM: 8128/1: abort: don\u0027t clear the exclusive monitors\n\ncommit 85868313177700d20644263a782351262d2aff84 upstream.\n\nThe ARMv6 and ARMv7 early abort handlers clear the exclusive monitors\nupon entry to the kernel, but this is redundant:\n\n  - We clear the monitors on every exception return since commit\n    200b812d0084 (\"Clear the exclusive monitor when returning from an\n    exception\"), so this is not necessary to ensure the monitors are\n    cleared before returning from a fault handler.\n\n  - Any dummy STREX will target a temporary scratch area in memory, and\n    may succeed or fail without corrupting useful data. Its status value\n    will not be used.\n\n  - Any other STREX in the kernel must be preceded by an LDREX, which\n    will initialise the monitors consistently and will not depend on the\n    earlier state of the monitors.\n\nTherefore we have no reason to care about the initial state of the\nexclusive monitors when a data abort is taken, and clearing the monitors\nprior to exception return (as we already do) is sufficient.\n\nThis patch removes the redundant clearing of the exclusive monitors from\nthe early abort handlers.\n\nSigned-off-by: Mark Rutland \u003cmark.rutland@arm.com\u003e\nAcked-by: Will Deacon \u003cwill.deacon@arm.com\u003e\nSigned-off-by: Russell King \u003crmk+kernel@arm.linux.org.uk\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "e78c127e8ee714142edb1d76956ebf40750ab218",
      "tree": "2dfdfd058a332c4ee71f8232d6ce7578b21e8578",
      "parents": [
        "e115f02bda5dc98fc31cec1fe6160bcee887789c"
      ],
      "author": {
        "name": "Jiri Kosina",
        "email": "jkosina@suse.cz",
        "time": "Wed Aug 27 09:13:15 2014 +0200"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:15 2014 +0800"
      },
      "message": "HID: picolcd: sanity check report size in raw_event() callback\n\ncommit 844817e47eef14141cf59b8d5ac08dd11c0a9189 upstream.\n\nThe report passed to us from transport driver could potentially be\narbitrarily large, therefore we better sanity-check it so that raw_data\nthat we hold in picolcd_pending structure are always kept within proper\nbounds.\n\nReported-by: Steven Vittitoe \u003cscvitti@google.com\u003e\nSigned-off-by: Jiri Kosina \u003cjkosina@suse.cz\u003e\n[lizf: Backported to 3.4: adjust filename]\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "e115f02bda5dc98fc31cec1fe6160bcee887789c",
      "tree": "127d4fbbebace1a0be01a23aa7d620a4664cb314",
      "parents": [
        "0bfb000447ffec4e7245c9c761fd0770acba504d"
      ],
      "author": {
        "name": "Jiri Kosina",
        "email": "jkosina@suse.cz",
        "time": "Wed Aug 27 09:12:24 2014 +0200"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:15 2014 +0800"
      },
      "message": "HID: magicmouse: sanity check report size in raw_event() callback\n\ncommit c54def7bd64d7c0b6993336abcffb8444795bf38 upstream.\n\nThe report passed to us from transport driver could potentially be\narbitrarily large, therefore we better sanity-check it so that\nmagicmouse_emit_touch() gets only valid values of raw_id.\n\nReported-by: Steven Vittitoe \u003cscvitti@google.com\u003e\nSigned-off-by: Jiri Kosina \u003cjkosina@suse.cz\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "0bfb000447ffec4e7245c9c761fd0770acba504d",
      "tree": "2bb3296fa8b61bd47b85387aea3f20cb097e8db2",
      "parents": [
        "818ee415d57c89ab36cbd2b9a57cc3c257afc1b9"
      ],
      "author": {
        "name": "Trond Myklebust",
        "email": "trond.myklebust@primarydata.com",
        "time": "Mon Aug 25 22:33:12 2014 -0400"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:15 2014 +0800"
      },
      "message": "NFSv4: Fix problems with close in the presence of a delegation\n\ncommit aee7af356e151494d5014f57b33460b162f181b5 upstream.\n\nIn the presence of delegations, we can no longer assume that the\nstate-\u003en_rdwr, state-\u003en_rdonly, state-\u003en_wronly reflect the open\nstateid share mode, and so we need to calculate the initial value\nfor calldata-\u003earg.fmode using the state-\u003eflags.\n\nReported-by: James Drews \u003cdrews@engr.wisc.edu\u003e\nFixes: 88069f77e1ac5 (NFSv41: Fix a potential state leakage when...)\nSigned-off-by: Trond Myklebust \u003ctrond.myklebust@primarydata.com\u003e\n[lizf: Backport to 3.4: adjust context]\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "818ee415d57c89ab36cbd2b9a57cc3c257afc1b9",
      "tree": "9b6d0d3f3520b327c7ee6471108a614664012731",
      "parents": [
        "86d165eb7959308faf75c2023f7273d08dc288be"
      ],
      "author": {
        "name": "Stephen Hemminger",
        "email": "stephen@networkplumber.org",
        "time": "Mon Aug 25 21:07:47 2014 -0700"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:15 2014 +0800"
      },
      "message": "USB: sisusb: add device id for Magic Control USB video\n\ncommit 5b6b80aeb21091ed3030b9b6aae597d81326f1aa upstream.\n\nI have a j5 create (JUA210) USB 2 video device and adding it device id\nto SIS USB video gets it to work.\n\nSigned-off-by: Stephen Hemminger \u003cstephen@networkplumber.org\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "86d165eb7959308faf75c2023f7273d08dc288be",
      "tree": "756f2b109d6194591a88f672fe59fea368ef5416",
      "parents": [
        "2f2c7048ff5a577ff268140e66ae26be69c808a7"
      ],
      "author": {
        "name": "Benjamin Tissoires",
        "email": "benjamin.tissoires@redhat.com",
        "time": "Fri Aug 22 16:16:05 2014 -0400"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:14 2014 +0800"
      },
      "message": "HID: logitech-dj: prevent false errors to be shown\n\ncommit 5abfe85c1d4694d5d4bbd13ecc166262b937adf0 upstream.\n\nCommit \"HID: logitech: perform bounds checking on device_id early\nenough\" unfortunately leaks some errors to dmesg which are not real\nones:\n- if the report is not a DJ one, then there is not point in checking\n  the device_id\n- the receiver (index 0) can also receive some notifications which\n  can be safely ignored given the current implementation\n\nMove out the test regarding the report_id and also discards\nprinting errors when the receiver got notified.\n\nFixes: ad3e14d7c5268c2e24477c6ef54bbdf88add5d36\n\nReported-and-tested-by: Markus Trippelsdorf \u003cmarkus@trippelsdorf.de\u003e\nSigned-off-by: Benjamin Tissoires \u003cbenjamin.tissoires@redhat.com\u003e\nSigned-off-by: Jiri Kosina \u003cjkosina@suse.cz\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "2f2c7048ff5a577ff268140e66ae26be69c808a7",
      "tree": "6c2b9ab42c2064d16c8b1b1b6d96cf9ce969dc61",
      "parents": [
        "1d37c3ed4792831e34460bb6d7c6bfc388927941"
      ],
      "author": {
        "name": "James Forshaw",
        "email": "forshaw@google.com",
        "time": "Sat Aug 23 14:39:48 2014 -0700"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:14 2014 +0800"
      },
      "message": "USB: whiteheat: Added bounds checking for bulk command response\n\ncommit 6817ae225cd650fb1c3295d769298c38b1eba818 upstream.\n\nThis patch fixes a potential security issue in the whiteheat USB driver\nwhich might allow a local attacker to cause kernel memory corrpution. This\nis due to an unchecked memcpy into a fixed size buffer (of 64 bytes). On\nEHCI and XHCI busses it\u0027s possible to craft responses greater than 64\nbytes leading a buffer overflow.\n\nSigned-off-by: James Forshaw \u003cforshaw@google.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n[lizf: Backported to 3.4: adjust context]\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "1d37c3ed4792831e34460bb6d7c6bfc388927941",
      "tree": "66f00aae4af317feec20fba2c2dd38c319a601d2",
      "parents": [
        "42494f024b957baa879f35bacb8b2353253ea7b8"
      ],
      "author": {
        "name": "Huang Rui",
        "email": "ray.huang@amd.com",
        "time": "Tue Aug 19 15:17:57 2014 +0300"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:14 2014 +0800"
      },
      "message": "usb: xhci: amd chipset also needs short TX quirk\n\ncommit 2597fe99bb0259387111d0431691f5daac84f5a5 upstream.\n\nAMD xHC also needs short tx quirk after tested on most of chipset\ngenerations. That\u0027s because there is the same incorrect behavior like\nFresco Logic host. Please see below message with on USB webcam\nattached on xHC host:\n\n[  139.262944] xhci_hcd 0000:00:10.0: WARN Successful completion on short TX: needs XHCI_TRUST_TX_LENGTH quirk?\n[  139.266934] xhci_hcd 0000:00:10.0: WARN Successful completion on short TX: needs XHCI_TRUST_TX_LENGTH quirk?\n[  139.270913] xhci_hcd 0000:00:10.0: WARN Successful completion on short TX: needs XHCI_TRUST_TX_LENGTH quirk?\n[  139.274937] xhci_hcd 0000:00:10.0: WARN Successful completion on short TX: needs XHCI_TRUST_TX_LENGTH quirk?\n[  139.278914] xhci_hcd 0000:00:10.0: WARN Successful completion on short TX: needs XHCI_TRUST_TX_LENGTH quirk?\n[  139.282936] xhci_hcd 0000:00:10.0: WARN Successful completion on short TX: needs XHCI_TRUST_TX_LENGTH quirk?\n[  139.286915] xhci_hcd 0000:00:10.0: WARN Successful completion on short TX: needs XHCI_TRUST_TX_LENGTH quirk?\n[  139.290938] xhci_hcd 0000:00:10.0: WARN Successful completion on short TX: needs XHCI_TRUST_TX_LENGTH quirk?\n[  139.294913] xhci_hcd 0000:00:10.0: WARN Successful completion on short TX: needs XHCI_TRUST_TX_LENGTH quirk?\n[  139.298917] xhci_hcd 0000:00:10.0: WARN Successful completion on short TX: needs XHCI_TRUST_TX_LENGTH quirk?\n\nReported-by: Arindam Nath \u003carindam.nath@amd.com\u003e\nTested-by: Shriraj-Rai P \u003cshriraj-rai.p@amd.com\u003e\nSigned-off-by: Huang Rui \u003cray.huang@amd.com\u003e\nSigned-off-by: Mathias Nyman \u003cmathias.nyman@linux.intel.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n[lizf: Backported to 3.4: adjust context]\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "42494f024b957baa879f35bacb8b2353253ea7b8",
      "tree": "eb47e8b1afca84d73957f0cc38b0d76647acf3fa",
      "parents": [
        "d232e2cabf543a2a36361110e89d82a535b4be1a"
      ],
      "author": {
        "name": "Hans de Goede",
        "email": "hdegoede@redhat.com",
        "time": "Tue Aug 19 15:17:56 2014 +0300"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:14 2014 +0800"
      },
      "message": "xhci: Treat not finding the event_seg on COMP_STOP the same as COMP_STOP_INVAL\n\ncommit 9a54886342e227433aebc9d374f8ae268a836475 upstream.\n\nWhen using a Renesas uPD720231 chipset usb-3 uas to sata bridge with a 120G\nCrucial M500 ssd, model string: Crucial_ CT120M500SSD1, together with a\nthe integrated Intel xhci controller on a Haswell laptop:\n\n00:14.0 USB controller [0c03]: Intel Corporation 8 Series USB xHCI HC [8086:9c31] (rev 04)\n\nThe following error gets logged to dmesg:\n\nxhci error: Transfer event TRB DMA ptr not part of current TD\n\nTreating COMP_STOP the same as COMP_STOP_INVAL when no event_seg gets found\nfixes this.\n\nSigned-off-by: Hans de Goede \u003chdegoede@redhat.com\u003e\nSigned-off-by: Mathias Nyman \u003cmathias.nyman@linux.intel.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "d232e2cabf543a2a36361110e89d82a535b4be1a",
      "tree": "621591ef80ce0fdfa4ca37711f16684d24bfda19",
      "parents": [
        "68e992960207daddc87b6d7203c2ed5beb79f2d7"
      ],
      "author": {
        "name": "Jaša Bartelj",
        "email": "jasa.bartelj@gmail.com",
        "time": "Sat Aug 16 12:44:27 2014 +0200"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:13 2014 +0800"
      },
      "message": "USB: ftdi_sio: Added PID for new ekey device\n\ncommit 646907f5bfb0782c731ae9ff6fb63471a3566132 upstream.\n\nAdded support to the ftdi_sio driver for ekey Converter USB which\nuses an FT232BM chip.\n\nSigned-off-by: Jaša Bartelj \u003cjasa.bartelj@gmail.com\u003e\nSigned-off-by: Johan Hovold \u003cjohan@kernel.org\u003e\n[lizf: Backported to 3.4: adjust context]\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "68e992960207daddc87b6d7203c2ed5beb79f2d7",
      "tree": "354aba705b1cf5d87ee286c6f5a847b7587c359e",
      "parents": [
        "262548e748b233113c4798336c88b9cd52d5a6e2"
      ],
      "author": {
        "name": "Greg KH",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Aug 15 15:22:21 2014 +0800"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:13 2014 +0800"
      },
      "message": "USB: serial: pl2303: add device id for ztek device\n\ncommit 91fcb1ce420e0a5f8d92d556d7008a78bc6ce1eb upstream.\n\nThis adds a new device id to the pl2303 driver for the ZTEK device.\n\nReported-by: Mike Chu \u003cMike-Chu@prolific.com.tw\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\nSigned-off-by: Johan Hovold \u003cjohan@kernel.org\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "262548e748b233113c4798336c88b9cd52d5a6e2",
      "tree": "d36b3c832f6af0a5d54e07750559dd3721025688",
      "parents": [
        "78aea3aa321b67d478b5d8e9626364c4739cdf28"
      ],
      "author": {
        "name": "Johan Hovold",
        "email": "johan@kernel.org",
        "time": "Wed Aug 13 17:56:52 2014 +0200"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:13 2014 +0800"
      },
      "message": "USB: ftdi_sio: add Basic Micro ATOM Nano USB2Serial PID\n\ncommit 6552cc7f09261db2aeaae389aa2c05a74b3a93b4 upstream.\n\nAdd device id for Basic Micro ATOM Nano USB2Serial adapters.\n\nReported-by: Nicolas Alt \u003cn.alt@mytum.de\u003e\nTested-by: Nicolas Alt \u003cn.alt@mytum.de\u003e\nSigned-off-by: Johan Hovold \u003cjohan@kernel.org\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "78aea3aa321b67d478b5d8e9626364c4739cdf28",
      "tree": "09c93eadfda5f5c7109dcc88a678f431c0b92918",
      "parents": [
        "c2aa9b7965a33be8995e9482175381186316bea5"
      ],
      "author": {
        "name": "Brennan Ashton",
        "email": "bashton@brennanashton.com",
        "time": "Wed Aug 06 08:46:44 2014 -0700"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:13 2014 +0800"
      },
      "message": "USB: option: add VIA Telecom CDS7 chipset device id\n\ncommit d77302739d900bbca5e901a3b7ac48c907ee6c93 upstream.\n\nThis VIA Telecom baseband processor is used is used by by u-blox in both the\nFW2770 and FW2760 products and may be used in others as well.\n\nThis patch has been tested on both of these modem versions.\n\nSigned-off-by: Brennan Ashton \u003cbashton@brennanashton.com\u003e\nSigned-off-by: Johan Hovold \u003cjohan@kernel.org\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "c2aa9b7965a33be8995e9482175381186316bea5",
      "tree": "caf9881d9bb116e69913db6374073e494ef59788",
      "parents": [
        "f40751b1c75f30a3d4029f6f1419e2f79bb995c3"
      ],
      "author": {
        "name": "Mark Einon",
        "email": "mark.einon@gmail.com",
        "time": "Sun Aug 10 22:16:55 2014 +0100"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:12 2014 +0800"
      },
      "message": "staging: et131x: Fix errors caused by phydev-\u003eaddr accesses before initialisation\n\ncommit ec0a38bf8b28b036202070cf3ef271e343d9eafc upstream.\n\nFix two reported bugs, caused by et131x_adapter-\u003ephydev-\u003eaddr being accessed\nbefore it is initialised, by:\n\n- letting et131x_mii_write() take a phydev address, instead of using the one\n  stored in adapter by default. This is so et131x_mdio_write() can use it\u0027s own\n  addr value.\n- removing implementation of et131x_mdio_reset(), as it\u0027s not needed.\n- moving a call to et131x_disable_phy_coma() in et131x_pci_setup(), which uses\n  phydev-\u003eaddr, until after the mdiobus has been registered.\n\nLink: https://bugzilla.kernel.org/show_bug.cgi?id\u003d80751\nLink: https://bugzilla.kernel.org/show_bug.cgi?id\u003d77121\nSigned-off-by: Mark Einon \u003cmark.einon@gmail.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n[lizf: Backported to 3.4:\n- adjust context\n- update more update more et131x_mii_write() calls in \n  et1310_phy_access_mii_bit() and et131x_xcvr_init()]\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "f40751b1c75f30a3d4029f6f1419e2f79bb995c3",
      "tree": "577d5690a77b9cad01d78e9a2aa7169633c51752",
      "parents": [
        "bcf20fd278687960f794b46aa1e06bc0dd99eecf"
      ],
      "author": {
        "name": "Max Filippov",
        "email": "jcmvbkbc@gmail.com",
        "time": "Thu Jul 31 22:40:57 2014 +0400"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:12 2014 +0800"
      },
      "message": "xtensa: fix a6 and a7 handling in fast_syscall_xtensa\n\ncommit d1b6ba82a50cecf94be540a3a153aa89d97511a0 upstream.\n\nRemove restoring a6 on some return paths and instead modify and restore\nit in a single place, using symbolic name.\nCorrectly restore a7 from PT_AREG7 in case of illegal a6 value.\n\nSigned-off-by: Max Filippov \u003cjcmvbkbc@gmail.com\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "bcf20fd278687960f794b46aa1e06bc0dd99eecf",
      "tree": "d18ad4a990af74bbcc8b873fb0371ed32a13abb2",
      "parents": [
        "fb2ae73e3a0ae4abdae30bfc086e52944713520b"
      ],
      "author": {
        "name": "Max Filippov",
        "email": "jcmvbkbc@gmail.com",
        "time": "Mon Jul 21 22:01:51 2014 +0400"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:12 2014 +0800"
      },
      "message": "xtensa: fix TLBTEMP_BASE_2 region handling in fast_second_level_miss\n\ncommit 7128039fe2dd3d59da9e4ffa036f3aaa3ba87b9f upstream.\n\nCurrent definition of TLBTEMP_BASE_2 is always 32K above the\nTLBTEMP_BASE_1, whereas fast_second_level_miss handler for the TLBTEMP\nregion analyzes virtual address bit (PAGE_SHIFT + DCACHE_ALIAS_ORDER)\nto determine TLBTEMP region where the fault happened. The size of the\nTLBTEMP region is also checked incorrectly: not 64K, but twice data\ncache way size (whicht may as well be less than the instruction cache\nway size).\n\nFix TLBTEMP_BASE_2 to be TLBTEMP_BASE_1 + data cache way size.\nProvide TLBTEMP_SIZE that is a greater of doubled data cache way size or\nthe instruction cache way size, and use it to determine if the second\nlevel TLB miss occured in the TLBTEMP region.\n\nPractical occurence of page faults in the TLBTEMP area is extremely\nrare, this code can be tested by deletion of all w[di]tlb instructions\nin the tlbtemp_mapping region.\n\nSigned-off-by: Max Filippov \u003cjcmvbkbc@gmail.com\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "fb2ae73e3a0ae4abdae30bfc086e52944713520b",
      "tree": "f1b719e9446da8429f1c5667d149d0ede91b0067",
      "parents": [
        "2297927578135dd7abf9306b08628c12ae8eeaa0"
      ],
      "author": {
        "name": "Alan Douglas",
        "email": "adouglas@cadence.com",
        "time": "Wed Jul 23 14:06:40 2014 +0400"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:12 2014 +0800"
      },
      "message": "xtensa: fix address checks in dma_{alloc,free}_coherent\n\ncommit 1ca49463c44c970b1ab1d71b0f268bfdf8427a7e upstream.\n\nVirtual address is translated to the XCHAL_KSEG_CACHED region in the\ndma_free_coherent, but is checked to be in the 0...XCHAL_KSEG_SIZE\nrange.\n\nChange check for end of the range from \u0027addr \u003e\u003d X\u0027 to \u0027addr \u003e X - 1\u0027 to\nhandle the case of X \u003d\u003d 0.\n\nReplace \u0027if (C) BUG();\u0027 construct with \u0027BUG_ON(C);\u0027.\n\nSigned-off-by: Alan Douglas \u003cadouglas@cadence.com\u003e\nSigned-off-by: Max Filippov \u003cjcmvbkbc@gmail.com\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "2297927578135dd7abf9306b08628c12ae8eeaa0",
      "tree": "82c8f2c9a57e6407b4479717d2143f9f72632928",
      "parents": [
        "483320c2bc1981d960750b02ced9ae4d11fc0e1c"
      ],
      "author": {
        "name": "Max Filippov",
        "email": "jcmvbkbc@gmail.com",
        "time": "Sun Jul 20 03:38:53 2014 +0400"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:12 2014 +0800"
      },
      "message": "xtensa: replace IOCTL code definitions with constants\n\ncommit f61bf8e7d19e0a3456a7a9ed97c399e4353698dc upstream.\n\nThis fixes userspace code that builds on other architectures but fails\non xtensa due to references to structures that other architectures don\u0027t\nrefer to. E.g. this fixes the following issue with python-2.7.8:\n\n  python-2.7.8/Modules/termios.c:861:25: error: invalid application\n     of \u0027sizeof\u0027 to incomplete type \u0027struct serial_multiport_struct\u0027\n     {\"TIOCSERGETMULTI\", TIOCSERGETMULTI},\n  python-2.7.8/Modules/termios.c:870:25: error: invalid application\n     of \u0027sizeof\u0027 to incomplete type \u0027struct serial_multiport_struct\u0027\n     {\"TIOCSERSETMULTI\", TIOCSERSETMULTI},\n  python-2.7.8/Modules/termios.c:900:24: error: invalid application\n     of \u0027sizeof\u0027 to incomplete type \u0027struct tty_struct\u0027\n     {\"TIOCTTYGSTRUCT\", TIOCTTYGSTRUCT},\n\nSigned-off-by: Max Filippov \u003cjcmvbkbc@gmail.com\u003e\n[lizf: Backported to 3.4: adjust filename]\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "483320c2bc1981d960750b02ced9ae4d11fc0e1c",
      "tree": "ced6ea58c9a3aee4c064a2ed778b41cbae5094c7",
      "parents": [
        "d06e4b08aa764b2999b6a67f1cf2b7794ae5b0e1"
      ],
      "author": {
        "name": "Takashi Iwai",
        "email": "tiwai@suse.de",
        "time": "Fri Aug 15 17:35:00 2014 +0200"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:11 2014 +0800"
      },
      "message": "ALSA: hda/realtek - Avoid setting wrong COEF on ALC269 \u0026 co\n\ncommit f3ee07d8b6e061bf34a7167c3f564e8da4360a99 upstream.\n\nALC269 \u0026 co have many vendor-specific setups with COEF verbs.\nHowever, some verbs seem specific to some codec versions and they\nresult in the codec stalling.  Typically, such a case can be avoided\nby checking the return value from reading a COEF.  If the return value\nis -1, it implies that the COEF is invalid, thus it shouldn\u0027t be\nwritten.\n\nThis patch adds the invalid COEF checks in appropriate places\naccessing ALC269 and its variants.  The patch actually fixes the\nresume problem on Acer AO725 laptop.\n\nBugzilla: https://bugzilla.kernel.org/show_bug.cgi?id\u003d52181\nTested-by: Francesco Muzio \u003cmuziofg@gmail.com\u003e\nSigned-off-by: Takashi Iwai \u003ctiwai@suse.de\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "d06e4b08aa764b2999b6a67f1cf2b7794ae5b0e1",
      "tree": "65783bdbf7d8adb45b2701b0bdf6e72c68c14cc7",
      "parents": [
        "a0e5b9d2c3cdaf1f980409ec1a84db22abfd6958"
      ],
      "author": {
        "name": "Pavel Shilovsky",
        "email": "pshilovsky@samba.org",
        "time": "Mon Aug 18 20:49:58 2014 +0400"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:11 2014 +0800"
      },
      "message": "CIFS: Fix wrong directory attributes after rename\n\ncommit b46799a8f28c43c5264ac8d8ffa28b311b557e03 upstream.\n\nWhen we requests rename we also need to update attributes\nof both source and target parent directories. Not doing it\ncauses generic/309 xfstest to fail on SMB2 mounts. Fix this\nby marking these directories for force revalidating.\n\nSigned-off-by: Pavel Shilovsky \u003cpshilovsky@samba.org\u003e\nSigned-off-by: Steve French \u003csmfrench@gmail.com\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "a0e5b9d2c3cdaf1f980409ec1a84db22abfd6958",
      "tree": "f73a3d79c04ee5b460447e6ba83335d1960d360f",
      "parents": [
        "77e5657567adc61ab425a070c5a9ec13b20913e8"
      ],
      "author": {
        "name": "NeilBrown",
        "email": "neilb@suse.de",
        "time": "Wed Aug 13 09:57:07 2014 +1000"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:11 2014 +0800"
      },
      "message": "md/raid6: avoid data corruption during recovery of double-degraded RAID6\n\ncommit 9c4bdf697c39805078392d5ddbbba5ae5680e0dd upstream.\n\nDuring recovery of a double-degraded RAID6 it is possible for\nsome blocks not to be recovered properly, leading to corruption.\n\nIf a write happens to one block in a stripe that would be written to a\nmissing device, and at the same time that stripe is recovering data\nto the other missing device, then that recovered data may not be written.\n\nThis patch skips, in the double-degraded case, an optimisation that is\nonly safe for single-degraded arrays.\n\nBug was introduced in 2.6.32 and fix is suitable for any kernel since\nthen.  In an older kernel with separate handle_stripe5() and\nhandle_stripe6() functions the patch must change handle_stripe6().\n\nFixes: 6c0069c0ae9659e3a91b68eaed06a5c6c37f45c8\nCc: Yuri Tikhonov \u003cyur@emcraft.com\u003e\nCc: Dan Williams \u003cdan.j.williams@intel.com\u003e\nReported-by: \"Manibalan P\" \u003cpmanibalan@amiindia.co.in\u003e\nTested-by: \"Manibalan P\" \u003cpmanibalan@amiindia.co.in\u003e\nResolves: https://bugzilla.redhat.com/show_bug.cgi?id\u003d1090423\nSigned-off-by: NeilBrown \u003cneilb@suse.de\u003e\nAcked-by: Dan Williams \u003cdan.j.williams@intel.com\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "77e5657567adc61ab425a070c5a9ec13b20913e8",
      "tree": "07956e00130747421b9f235927c4d81b4bed6c1c",
      "parents": [
        "db83744afb3a43a21722d3bb17c8e1e8da5a9cf7"
      ],
      "author": {
        "name": "Joerg Roedel",
        "email": "jroedel@suse.de",
        "time": "Tue Aug 05 17:50:15 2014 +0200"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:11 2014 +0800"
      },
      "message": "iommu/amd: Fix cleanup_domain for mass device removal\n\ncommit 9b29d3c6510407d91786c1cf9183ff4debb3473a upstream.\n\nWhen multiple devices are detached in __detach_device, they\nare also removed from the domains dev_list. This makes it\nunsafe to use list_for_each_entry_safe, as the next pointer\nmight also not be in the list anymore after __detach_device\nreturns. So just repeatedly remove the first element of the\nlist until it is empty.\n\nTested-by: Marti Raudsepp \u003cmarti@juffo.org\u003e\nSigned-off-by: Joerg Roedel \u003cjroedel@suse.de\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "db83744afb3a43a21722d3bb17c8e1e8da5a9cf7",
      "tree": "3a9d72007e043058d4ad28823a42c9680cb22767",
      "parents": [
        "f0634a3e2f4eea6ff149bf62aa97269fb8d65107"
      ],
      "author": {
        "name": "Arjun Sreedharan",
        "email": "arjun024@gmail.com",
        "time": "Sun Aug 17 20:00:09 2014 +0530"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:11 2014 +0800"
      },
      "message": "pata_scc: propagate return value of scc_wait_after_reset\n\ncommit 4dc7c76cd500fa78c64adfda4b070b870a2b993c upstream.\n\nscc_bus_softreset not necessarily should return zero.\nPropagate the error code.\n\nSigned-off-by: Arjun Sreedharan \u003carjun024@gmail.com\u003e\nSigned-off-by: Tejun Heo \u003ctj@kernel.org\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "f0634a3e2f4eea6ff149bf62aa97269fb8d65107",
      "tree": "f721b43516fd5162ed4dc29151d48c1baf033691",
      "parents": [
        "33df36f48f2877f37037e185b6f11b077de27e5b"
      ],
      "author": {
        "name": "Michael S. Tsirkin",
        "email": "mst@redhat.com",
        "time": "Tue Aug 19 19:14:50 2014 +0800"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:10 2014 +0800"
      },
      "message": "kvm: iommu: fix the third parameter of kvm_iommu_put_pages (CVE-2014-3601)\n\ncommit 350b8bdd689cd2ab2c67c8a86a0be86cfa0751a7 upstream.\n\nThe third parameter of kvm_iommu_put_pages is wrong,\nIt should be \u0027gfn - slot-\u003ebase_gfn\u0027.\n\nBy making gfn very large, malicious guest or userspace can cause kvm to\ngo to this error path, and subsequently to pass a huge value as size.\nAlternatively if gfn is small, then pages would be pinned but never\nunpinned, causing host memory leak and local DOS.\n\nPassing a reasonable but large value could be the most dangerous case,\nbecause it would unpin a page that should have stayed pinned, and thus\nallow the device to DMA into arbitrary memory.  However, this cannot\nhappen because of the condition that can trigger the error:\n\n- out of memory (where you can\u0027t allocate even a single page)\n  should not be possible for the attacker to trigger\n\n- when exceeding the iommu\u0027s address space, guest pages after gfn\n  will also exceed the iommu\u0027s address space, and inside\n  kvm_iommu_put_pages() the iommu_iova_to_phys() will fail.  The\n  page thus would not be unpinned at all.\n\nReported-by: Jack Morgenstein \u003cjackm@mellanox.com\u003e\nSigned-off-by: Michael S. Tsirkin \u003cmst@redhat.com\u003e\nSigned-off-by: Paolo Bonzini \u003cpbonzini@redhat.com\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "33df36f48f2877f37037e185b6f11b077de27e5b",
      "tree": "c6b5e1543c7efe9ec06614f9511c9d2b7a5bec59",
      "parents": [
        "5ccd3e2a9ec54a2e9a9b0a7d9256f2433304fa24"
      ],
      "author": {
        "name": "Aaro Koskinen",
        "email": "aaro.koskinen@nsn.com",
        "time": "Tue Jul 22 14:51:08 2014 +0300"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:10 2014 +0800"
      },
      "message": "MIPS: OCTEON: make get_system_type() thread-safe\n\ncommit 608308682addfdc7b8e2aee88f0e028331d88e4d upstream.\n\nget_system_type() is not thread-safe on OCTEON. It uses static data,\nalso more dangerous issue is that it\u0027s calling cvmx_fuse_read_byte()\nevery time without any synchronization. Currently it\u0027s possible to get\nprocesses stuck looping forever in kernel simply by launching multiple\nreaders of /proc/cpuinfo:\n\n\t(while true; do cat /proc/cpuinfo \u003e /dev/null; done) \u0026\n\t(while true; do cat /proc/cpuinfo \u003e /dev/null; done) \u0026\n\t...\n\nFix by initializing the system type string only once during the early\nboot.\n\nSigned-off-by: Aaro Koskinen \u003caaro.koskinen@nsn.com\u003e\nReviewed-by: Markos Chandras \u003cmarkos.chandras@imgtec.com\u003e\nPatchwork: http://patchwork.linux-mips.org/patch/7437/\nSigned-off-by: James Hogan \u003cjames.hogan@imgtec.com\u003e\n[lizf: Backport to 3.x: adjust context]\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "5ccd3e2a9ec54a2e9a9b0a7d9256f2433304fa24",
      "tree": "8953d59eb22b48a1630a3f9092b13701f607cb46",
      "parents": [
        "c945ed6b7e5812cfba4d292c3c54fc750bb9f65b"
      ],
      "author": {
        "name": "Jan Kara",
        "email": "jack@suse.cz",
        "time": "Sun Aug 17 11:49:57 2014 +0200"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:10 2014 +0800"
      },
      "message": "isofs: Fix unbounded recursion when processing relocated directories\n\ncommit 410dd3cf4c9b36f27ed4542ee18b1af5e68645a4 upstream.\n\nWe did not check relocated directory in any way when processing Rock\nRidge \u0027CL\u0027 tag. Thus a corrupted isofs image can possibly have a CL\nentry pointing to another CL entry leading to possibly unbounded\nrecursion in kernel code and thus stack overflow or deadlocks (if there\nis a loop created from CL entries).\n\nFix the problem by not allowing CL entry to point to a directory entry\nwith CL entry (such use makes no good sense anyway) and by checking\nwhether CL entry doesn\u0027t point to itself.\n\nReported-by: Chris Evans \u003ccevans@google.com\u003e\nSigned-off-by: Jan Kara \u003cjack@suse.cz\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "c945ed6b7e5812cfba4d292c3c54fc750bb9f65b",
      "tree": "148b6b36ae9ce5bbbf01e021275b01e1d8b395fd",
      "parents": [
        "dab2f9be0ad69d2fa2716c84a45e9baf31ec62bd"
      ],
      "author": {
        "name": "Jiri Kosina",
        "email": "jkosina@suse.cz",
        "time": "Thu Aug 21 09:57:17 2014 -0500"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:10 2014 +0800"
      },
      "message": "HID: logitech: perform bounds checking on device_id early enough\n\ncommit ad3e14d7c5268c2e24477c6ef54bbdf88add5d36 upstream.\n\ndevice_index is a char type and the size of paired_dj_deivces is 7\nelements, therefore proper bounds checking has to be applied to\ndevice_index before it is used.\n\nWe are currently performing the bounds checking in\nlogi_dj_recv_add_djhid_device(), which is too late, as malicious device\ncould send REPORT_TYPE_NOTIF_DEVICE_UNPAIRED early enough and trigger the\nproblem in one of the report forwarding functions called from\nlogi_dj_raw_event().\n\nFix this by performing the check at the earliest possible ocasion in\nlogi_dj_raw_event().\n\nReported-by: Ben Hawkes \u003chawkes@google.com\u003e\nReviewed-by: Benjamin Tissoires \u003cbenjamin.tissoires@redhat.com\u003e\nSigned-off-by: Jiri Kosina \u003cjkosina@suse.cz\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "dab2f9be0ad69d2fa2716c84a45e9baf31ec62bd",
      "tree": "bcab402aec9029b802d3f5ce2797d19ee9bfd59b",
      "parents": [
        "9220628427bc4e3fae475a150648b758f06ddfae"
      ],
      "author": {
        "name": "Jiri Kosina",
        "email": "jkosina@suse.cz",
        "time": "Thu Aug 21 09:57:48 2014 -0500"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:09 2014 +0800"
      },
      "message": "HID: fix a couple of off-by-ones\n\ncommit 4ab25786c87eb20857bbb715c3ae34ec8fd6a214 upstream.\n\nThere are a few very theoretical off-by-one bugs in report descriptor size\nchecking when performing a pre-parsing fixup. Fix those.\n\nReported-by: Ben Hawkes \u003chawkes@google.com\u003e\nReviewed-by: Benjamin Tissoires \u003cbenjamin.tissoires@redhat.com\u003e\nSigned-off-by: Jiri Kosina \u003cjkosina@suse.cz\u003e\n[lizf: Backported to 3.4: adjust context]\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "9220628427bc4e3fae475a150648b758f06ddfae",
      "tree": "7ab1d53b29d01ab12c9dbee59e655fc78ce94e68",
      "parents": [
        "c27d3b507ecfb78ce9d3ce9a02c0297a32001548"
      ],
      "author": {
        "name": "Anton Blanchard",
        "email": "anton@samba.org",
        "time": "Fri Aug 22 11:36:52 2014 +1000"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:09 2014 +0800"
      },
      "message": "ibmveth: Fix endian issues with rx_no_buffer statistic\n\ncommit cbd5228199d8be45d895d9d0cc2b8ce53835fc21 upstream.\n\nHidden away in the last 8 bytes of the buffer_list page is a solitary\nstatistic. It needs to be byte swapped or else ethtool -S will\nproduce numbers that terrify the user.\n\nSince we do this in multiple places, create a helper function with a\ncomment explaining what is going on.\n\nSigned-off-by: Anton Blanchard \u003canton@samba.org\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "c27d3b507ecfb78ce9d3ce9a02c0297a32001548",
      "tree": "4d12910f77e06447ca50261bab5f00067e157958",
      "parents": [
        "b402b721ef70eb296aa63ec54181167525b67a5a"
      ],
      "author": {
        "name": "Daniel Mack",
        "email": "zonque@gmail.com",
        "time": "Wed Aug 13 21:51:06 2014 +0200"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:09 2014 +0800"
      },
      "message": "ASoC: pxa-ssp: drop SNDRV_PCM_FMTBIT_S24_LE\n\ncommit 9301503af016eb537ccce76adec0c1bb5c84871e upstream.\n\nThis mode is unsupported, as the DMA controller can\u0027t do zero-padding\nof samples.\n\nSigned-off-by: Daniel Mack \u003czonque@gmail.com\u003e\nReported-by: Johannes Stezenbach \u003cjs@sig21.net\u003e\nSigned-off-by: Mark Brown \u003cbroonie@linaro.org\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "b402b721ef70eb296aa63ec54181167525b67a5a",
      "tree": "d77742bee4393d6561278b0c8dc3467438ac84cc",
      "parents": [
        "9f089cfb4be27efe7c1cd1d6261da02496820441"
      ],
      "author": {
        "name": "Dave Chiluk",
        "email": "chiluk@canonical.com",
        "time": "Tue Jun 24 10:11:26 2014 -0500"
      },
      "committer": {
        "name": "Zefan Li",
        "email": "lizefan@huawei.com",
        "time": "Thu Sep 25 11:49:09 2014 +0800"
      },
      "message": "stable_kernel_rules: Add pointer to netdev-FAQ for network patches\n\ncommit b76fc285337b6b256e9ba20a40cfd043f70c27af upstream.\n\nStable_kernel_rules should point submitters of network stable patches to the\nnetdev_FAQ.txt as requests for stable network patches should go to netdev\nfirst.\n\nSigned-off-by: Dave Chiluk \u003cchiluk@canonical.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\nSigned-off-by: Zefan Li \u003clizefan@huawei.com\u003e\n"
    },
    {
      "commit": "9f089cfb4be27efe7c1cd1d6261da02496820441",
      "tree": "ac3a1986c7d16e286ab87175d3d96304cc257a89",
      "parents": [
        "0ace429a33ac4e4f7909fa7976dcf94b997ea353"
      ],
      "author": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Aug 14 09:07:43 2014 +0800"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Aug 14 09:07:43 2014 +0800"
      },
      "message": "Linux 3.4.103\n"
    },
    {
      "commit": "0ace429a33ac4e4f7909fa7976dcf94b997ea353",
      "tree": "7c7a4c16f2fa0ac23ebb83cb6a6b967ebd9e3eeb",
      "parents": [
        "29fa649b993693ce21d10b841e93c07d1d8f2c7e"
      ],
      "author": {
        "name": "Andrey Utkin",
        "email": "andrey.krieger.utkin@gmail.com",
        "time": "Mon Aug 04 23:47:41 2014 +0300"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Aug 14 08:42:37 2014 +0800"
      },
      "message": "arch/sparc/math-emu/math_32.c: drop stray break operator\n\n[ Upstream commit 093758e3daede29cb4ce6aedb111becf9d4bfc57 ]\n\nThis commit is a guesswork, but it seems to make sense to drop this\nbreak, as otherwise the following line is never executed and becomes\ndead code. And that following line actually saves the result of\nlocal calculation by the pointer given in function argument. So the\nproposed change makes sense if this code in the whole makes sense (but I\nam unable to analyze it in the whole).\n\nBugzilla: https://bugzilla.kernel.org/show_bug.cgi?id\u003d81641\nReported-by: David Binderman \u003cdcb314@hotmail.com\u003e\nSigned-off-by: Andrey Utkin \u003candrey.krieger.utkin@gmail.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "29fa649b993693ce21d10b841e93c07d1d8f2c7e",
      "tree": "52cc0c78d70606276e3efbc710af0b1ad70fcbed",
      "parents": [
        "a46e9456f1516e8238d43dcff766595452c0ed48"
      ],
      "author": {
        "name": "Sowmini Varadhan",
        "email": "sowmini.varadhan@oracle.com",
        "time": "Fri Aug 01 09:50:40 2014 -0400"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Aug 14 08:42:37 2014 +0800"
      },
      "message": "sparc64: ldc_connect() should not return EINVAL when handshake is in progress.\n\n[ Upstream commit 4ec1b01029b4facb651b8ef70bc20a4be4cebc63 ]\n\nThe LDC handshake could have been asynchronously triggered\nafter ldc_bind() enables the ldc_rx() receive interrupt-handler\n(and thus intercepts incoming control packets)\nand before vio_port_up() calls ldc_connect(). If that is the case,\nldc_connect() should return 0 and let the state-machine\nprogress.\n\nSigned-off-by: Sowmini Varadhan \u003csowmini.varadhan@oracle.com\u003e\nAcked-by: Karl Volz \u003ckarl.volz@oracle.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "a46e9456f1516e8238d43dcff766595452c0ed48",
      "tree": "7adc35c842e4609d989cf48db118af29a6670892",
      "parents": [
        "7554c49edacf3caacdc71736bf92fc840e46d986"
      ],
      "author": {
        "name": "Christopher Alexander Tobias Schulze",
        "email": "cat.schulze@alice-dsl.net",
        "time": "Sun Aug 03 16:01:53 2014 +0200"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Aug 14 08:42:37 2014 +0800"
      },
      "message": "sunsab: Fix detection of BREAK on sunsab serial console\n\n[ Upstream commit fe418231b195c205701c0cc550a03f6c9758fd9e ]\n\nFix detection of BREAK on sunsab serial console: BREAK detection was only\nperformed when there were also serial characters received simultaneously.\nTo handle all BREAKs correctly, the check for BREAK and the corresponding\ncall to uart_handle_break() must also be done if count \u003d\u003d 0, therefore\nduplicate this code fragment and pull it out of the loop over the received\ncharacters.\n\nPatch applies to 3.16-rc6.\n\nSigned-off-by: Christopher Alexander Tobias Schulze \u003ccat.schulze@alice-dsl.net\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "7554c49edacf3caacdc71736bf92fc840e46d986",
      "tree": "8988f0801dbb9a1dee80ed1328a784a4ae3c89fe",
      "parents": [
        "d7bcdfe04e385f4420b2a8d22d62dbf48935da4f"
      ],
      "author": {
        "name": "Christopher Alexander Tobias Schulze",
        "email": "cat.schulze@alice-dsl.net",
        "time": "Sun Aug 03 15:44:52 2014 +0200"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Aug 14 08:42:37 2014 +0800"
      },
      "message": "bbc-i2c: Fix BBC I2C envctrl on SunBlade 2000\n\n[ Upstream commit 5cdceab3d5e02eb69ea0f5d8fa9181800baf6f77 ]\n\nFix regression in bbc i2c temperature and fan control on some Sun systems\nthat causes the driver to refuse to load due to the bbc_i2c_bussel resource not\nbeing present on the (second) i2c bus where the temperature sensors and fan\ncontrol are located. (The check for the number of resources was removed when\nthe driver was ported to a pure OF driver in mid 2008.)\n\nSigned-off-by: Christopher Alexander Tobias Schulze \u003ccat.schulze@alice-dsl.net\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "d7bcdfe04e385f4420b2a8d22d62dbf48935da4f",
      "tree": "2dc983eb34de583ae109e54f405164cb4fc78a69",
      "parents": [
        "afa9b047624f638f1cabc3c5bcbcbd86bea47ab3"
      ],
      "author": {
        "name": "David S. Miller",
        "email": "davem@davemloft.net",
        "time": "Mon Aug 04 20:07:37 2014 -0700"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Aug 14 08:42:37 2014 +0800"
      },
      "message": "sparc64: Guard against flushing openfirmware mappings.\n\n[ Upstream commit 4ca9a23765da3260058db3431faf5b4efd8cf926 ]\n\nBased almost entirely upon a patch by Christopher Alexander Tobias\nSchulze.\n\nIn commit db64fe02258f1507e13fe5212a989922323685ce (\"mm: rewrite vmap\nlayer\") lazy VMAP tlb flushing was added to the vmalloc layer.  This\ncauses problems on sparc64.\n\nSparc64 has two VMAP mapped regions and they are not contiguous with\neachother.  First we have the malloc mapping area, then another\nunrelated region, then the vmalloc region.\n\nThis \"another unrelated region\" is where the firmware is mapped.\n\nIf the lazy TLB flushing logic in the vmalloc code triggers after\nwe\u0027ve had both a module unload and a vfree or similar, it will pass an\naddress range that goes from somewhere inside the malloc region to\nsomewhere inside the vmalloc region, and thus covering the\nopenfirmware area entirely.\n\nThe sparc64 kernel learns about openfirmware\u0027s dynamic mappings in\nthis region early in the boot, and then services TLB misses in this\narea.  But openfirmware has some locked TLB entries which are not\nmentioned in those dynamic mappings and we should thus not disturb\nthem.\n\nThese huge lazy TLB flush ranges causes those openfirmware locked TLB\nentries to be removed, resulting in all kinds of problems including\nhard hangs and crashes during reboot/reset.\n\nBesides causing problems like this, such huge TLB flush ranges are\nalso incredibly inefficient.  A plea has been made with the author of\nthe VMAP lazy TLB flushing code, but for now we\u0027ll put a safety guard\ninto our flush_tlb_kernel_range() implementation.\n\nSince the implementation has become non-trivial, stop defining it as a\nmacro and instead make it a function in a C source file.\n\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "afa9b047624f638f1cabc3c5bcbcbd86bea47ab3",
      "tree": "0ff3b55c664927662808bb37671ae0ddcb44eecc",
      "parents": [
        "8e8955a262de468c34c83203375c1d405b9d6840"
      ],
      "author": {
        "name": "David S. Miller",
        "email": "davem@davemloft.net",
        "time": "Mon Aug 04 16:34:01 2014 -0700"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Aug 14 08:42:37 2014 +0800"
      },
      "message": "sparc64: Do not insert non-valid PTEs into the TSB hash table.\n\n[ Upstream commit 18f38132528c3e603c66ea464727b29e9bbcb91b ]\n\nThe assumption was that update_mmu_cache() (and the equivalent for PMDs) would\nonly be called when the PTE being installed will be accessible by the user.\n\nThis is not true for code paths originating from remove_migration_pte().\n\nThere are dire consequences for placing a non-valid PTE into the TSB.  The TLB\nmiss frramework assumes thatwhen a TSB entry matches we can just load it into\nthe TLB and return from the TLB miss trap.\n\nSo if a non-valid PTE is in there, we will deadlock taking the TLB miss over\nand over, never satisfying the miss.\n\nJust exit early from update_mmu_cache() and friends in this situation.\n\nBased upon a report and patch from Christopher Alexander Tobias Schulze.\n\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "8e8955a262de468c34c83203375c1d405b9d6840",
      "tree": "cf51cd66657eaa91249b80480f770a79640af514",
      "parents": [
        "fdd880110209aa34e5334797891e594b877c38aa"
      ],
      "author": {
        "name": "David S. Miller",
        "email": "davem@davemloft.net",
        "time": "Sat May 17 11:28:05 2014 -0700"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Aug 14 08:42:37 2014 +0800"
      },
      "message": "sparc64: Add membar to Niagara2 memcpy code.\n\n[ Upstream commit 5aa4ecfd0ddb1e6dcd1c886e6c49677550f581aa ]\n\nThis is the prevent previous stores from overlapping the block stores\ndone by the memcpy loop.\n\nBased upon a glibc patch by Jose E. Marchesi\n\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "fdd880110209aa34e5334797891e594b877c38aa",
      "tree": "acee9af3090835d62fe563add6138c943e10395a",
      "parents": [
        "0de492190948948d0ff5d3ad8f7e1f0942f0379e"
      ],
      "author": {
        "name": "David S. Miller",
        "email": "davem@davemloft.net",
        "time": "Wed May 07 14:07:32 2014 -0700"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Aug 14 08:42:37 2014 +0800"
      },
      "message": "sparc64: Fix huge TSB mapping on pre-UltraSPARC-III cpus.\n\n[ Upstream commit b18eb2d779240631a098626cb6841ee2dd34fda0 ]\n\nAccess to the TSB hash tables during TLB misses requires that there be\nan atomic 128-bit quad load available so that we fetch a matching TAG\nand DATA field at the same time.\n\nOn cpus prior to UltraSPARC-III only virtual address based quad loads\nare available.  UltraSPARC-III and later provide physical address\nbased variants which are easier to use.\n\nWhen we only have virtual address based quad loads available this\nmeans that we have to lock the TSB into the TLB at a fixed virtual\naddress on each cpu when it runs that process.  We can\u0027t just access\nthe PAGE_OFFSET based aliased mapping of these TSBs because we cannot\ntake a recursive TLB miss inside of the TLB miss handler without\nrisking running out of hardware trap levels (some trap combinations\ncan be deep, such as those generated by register window spill and fill\ntraps).\n\nWithout huge pages it\u0027s working perfectly fine, but when the huge TSB\ngot added another chunk of fixed virtual address space was not\nallocated for this second TSB mapping.\n\nSo we were mapping both the 8K and 4MB TSBs to the same exact virtual\naddress, causing multiple TLB matches which gives undefined behavior.\n\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "0de492190948948d0ff5d3ad8f7e1f0942f0379e",
      "tree": "164a94e70c11dd9a9cb2134a68cf81778e8af3d4",
      "parents": [
        "86982cf46cf082ef705237b1ed7372ec772f3f8e"
      ],
      "author": {
        "name": "David S. Miller",
        "email": "davem@davemloft.net",
        "time": "Tue May 06 21:27:37 2014 -0700"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Aug 14 08:42:36 2014 +0800"
      },
      "message": "sparc64: Don\u0027t bark so loudly about 32-bit tasks generating 64-bit fault addresses.\n\n[ Upstream commit e5c460f46ae7ee94831cb55cb980f942aa9e5a85 ]\n\nThis was found using Dave Jone\u0027s trinity tool.\n\nWhen a user process which is 32-bit performs a load or a store, the\ncpu chops off the top 32-bits of the effective address before\ntranslating it.\n\nThis is because we run 32-bit tasks with the PSTATE_AM (address\nmasking) bit set.\n\nWe can\u0027t run the kernel with that bit set, so when the kernel accesses\nuserspace no address masking occurs.\n\nSince a 32-bit process will have no mappings in that region we will\nproperly fault, so we don\u0027t try to handle this using access_ok(),\nwhich can safely just be a NOP on sparc64.\n\nReal faults from 32-bit processes should never generate such addresses\nso a bug check was added long ago, and it barks in the logs if this\nhappens.\n\nBut it also barks when a kernel user access causes this condition, and\nthat _can_ happen.  For example, if a pointer passed into a system call\nis \"0xfffffffc\" and the kernel access 4 bytes offset from that pointer.\n\nJust handle such faults normally via the exception entries.\n\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "86982cf46cf082ef705237b1ed7372ec772f3f8e",
      "tree": "a526061ab2417f35920c1aae5b6c2295d998adc3",
      "parents": [
        "d2671e681d044d236c7a39b8c4b718216f2261df"
      ],
      "author": {
        "name": "David S. Miller",
        "email": "davem@davemloft.net",
        "time": "Mon Apr 28 23:52:11 2014 -0700"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Aug 14 08:42:36 2014 +0800"
      },
      "message": "sparc64: Fix top-level fault handling bugs.\n\n[ Upstream commit 70ffc6ebaead783ac8dafb1e87df0039bb043596 ]\n\nMake get_user_insn() able to cope with huge PMDs.\n\nNext, make do_fault_siginfo() more robust when get_user_insn() can\u0027t\nactually fetch the instruction.  In particular, use the MMU announced\nfault address when that happens, instead of calling\ncompute_effective_address() and computing garbage.\n\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "d2671e681d044d236c7a39b8c4b718216f2261df",
      "tree": "56243b8531ec84024d41b1bbb641709be56a36b6",
      "parents": [
        "4fdf73fb4a781e9b74e540d251a533fa7b2af8df"
      ],
      "author": {
        "name": "David S. Miller",
        "email": "davem@davemloft.net",
        "time": "Mon Apr 28 23:50:08 2014 -0700"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Aug 14 08:42:36 2014 +0800"
      },
      "message": "sparc64: Handle 32-bit tasks properly in compute_effective_address().\n\n[ Upstream commit d037d16372bbe4d580342bebbb8826821ad9edf0 ]\n\nIf we have a 32-bit task we must chop off the top 32-bits of the\n64-bit value just as the cpu would.\n\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "4fdf73fb4a781e9b74e540d251a533fa7b2af8df",
      "tree": "071e690cd6a9a63b18d8fed3765633db7af822e7",
      "parents": [
        "0da96858de3417f557410c3e6d585b928394e198"
      ],
      "author": {
        "name": "Kirill Tkhai",
        "email": "tkhai@yandex.ru",
        "time": "Thu Apr 17 00:45:24 2014 +0400"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Aug 14 08:42:36 2014 +0800"
      },
      "message": "sparc64: Make itc_sync_lock raw\n\n[ Upstream commit 49b6c01f4c1de3b5e5427ac5aba80f9f6d27837a ]\n\nOne more place where we must not be able\nto be preempted or to be interrupted in RT.\n\nAlways actually disable interrupts during\nsynchronization cycle.\n\nSigned-off-by: Kirill Tkhai \u003ctkhai@yandex.ru\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "0da96858de3417f557410c3e6d585b928394e198",
      "tree": "50b966c1e6c68581584c26b399266c00a7953a48",
      "parents": [
        "5c19acccf5233d73ed6c58440e301ba6828aa0c1"
      ],
      "author": {
        "name": "David S. Miller",
        "email": "davem@davemloft.net",
        "time": "Wed Apr 30 19:37:48 2014 -0700"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Aug 14 08:42:36 2014 +0800"
      },
      "message": "sparc64: Fix argument sign extension for compat_sys_futex().\n\n[ Upstream commit aa3449ee9c87d9b7660dd1493248abcc57769e31 ]\n\nOnly the second argument, \u0027op\u0027, is signed.\n\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "5c19acccf5233d73ed6c58440e301ba6828aa0c1",
      "tree": "c50553106e01cc0dd08c3222c608d3fb80e97f8d",
      "parents": [
        "8fbbef088e95f015f89cc155a02fe64017905765"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "edumazet@google.com",
        "time": "Tue Aug 05 16:49:52 2014 +0200"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Aug 14 08:42:36 2014 +0800"
      },
      "message": "sctp: fix possible seqlock seadlock in sctp_packet_transmit()\n\n[ Upstream commit 757efd32d5ce31f67193cc0e6a56e4dffcc42fb1 ]\n\nDave reported following splat, caused by improper use of\nIP_INC_STATS_BH() in process context.\n\nBUG: using __this_cpu_add() in preemptible [00000000] code: trinity-c117/14551\ncaller is __this_cpu_preempt_check+0x13/0x20\nCPU: 3 PID: 14551 Comm: trinity-c117 Not tainted 3.16.0+ #33\n ffffffff9ec898f0 0000000047ea7e23 ffff88022d32f7f0 ffffffff9e7ee207\n 0000000000000003 ffff88022d32f818 ffffffff9e397eaa ffff88023ee70b40\n ffff88022d32f970 ffff8801c026d580 ffff88022d32f828 ffffffff9e397ee3\nCall Trace:\n [\u003cffffffff9e7ee207\u003e] dump_stack+0x4e/0x7a\n [\u003cffffffff9e397eaa\u003e] check_preemption_disabled+0xfa/0x100\n [\u003cffffffff9e397ee3\u003e] __this_cpu_preempt_check+0x13/0x20\n [\u003cffffffffc0839872\u003e] sctp_packet_transmit+0x692/0x710 [sctp]\n [\u003cffffffffc082a7f2\u003e] sctp_outq_flush+0x2a2/0xc30 [sctp]\n [\u003cffffffff9e0d985c\u003e] ? mark_held_locks+0x7c/0xb0\n [\u003cffffffff9e7f8c6d\u003e] ? _raw_spin_unlock_irqrestore+0x5d/0x80\n [\u003cffffffffc082b99a\u003e] sctp_outq_uncork+0x1a/0x20 [sctp]\n [\u003cffffffffc081e112\u003e] sctp_cmd_interpreter.isra.23+0x1142/0x13f0 [sctp]\n [\u003cffffffffc081c86b\u003e] sctp_do_sm+0xdb/0x330 [sctp]\n [\u003cffffffff9e0b8f1b\u003e] ? preempt_count_sub+0xab/0x100\n [\u003cffffffffc083b350\u003e] ? sctp_cname+0x70/0x70 [sctp]\n [\u003cffffffffc08389ca\u003e] sctp_primitive_ASSOCIATE+0x3a/0x50 [sctp]\n [\u003cffffffffc083358f\u003e] sctp_sendmsg+0x88f/0xe30 [sctp]\n [\u003cffffffff9e0d673a\u003e] ? lock_release_holdtime.part.28+0x9a/0x160\n [\u003cffffffff9e0d62ce\u003e] ? put_lock_stats.isra.27+0xe/0x30\n [\u003cffffffff9e73b624\u003e] inet_sendmsg+0x104/0x220\n [\u003cffffffff9e73b525\u003e] ? inet_sendmsg+0x5/0x220\n [\u003cffffffff9e68ac4e\u003e] sock_sendmsg+0x9e/0xe0\n [\u003cffffffff9e1c0c09\u003e] ? might_fault+0xb9/0xc0\n [\u003cffffffff9e1c0bae\u003e] ? might_fault+0x5e/0xc0\n [\u003cffffffff9e68b234\u003e] SYSC_sendto+0x124/0x1c0\n [\u003cffffffff9e0136b0\u003e] ? syscall_trace_enter+0x250/0x330\n [\u003cffffffff9e68c3ce\u003e] SyS_sendto+0xe/0x10\n [\u003cffffffff9e7f9be4\u003e] tracesys+0xdd/0xe2\n\nThis is a followup of commits f1d8cba61c3c4b (\"inet: fix possible\nseqlock deadlocks\") and 7f88c6b23afbd315 (\"ipv6: fix possible seqlock\ndeadlock in ip6_finish_output2\")\n\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nCc: Hannes Frederic Sowa \u003channes@stressinduktion.org\u003e\nReported-by: Dave Jones \u003cdavej@redhat.com\u003e\nAcked-by: Neil Horman \u003cnhorman@tuxdriver.com\u003e\nAcked-by: Hannes Frederic Sowa \u003channes@stressinduktion.org\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "8fbbef088e95f015f89cc155a02fe64017905765",
      "tree": "f67cb337d573bf9acb474dc48971265dfc8a9e0a",
      "parents": [
        "80db1671bd9bf67acf9c3b21350442b4b77e7cc4"
      ],
      "author": {
        "name": "Sasha Levin",
        "email": "sasha.levin@oracle.com",
        "time": "Thu Jul 31 23:00:35 2014 -0400"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Aug 14 08:42:36 2014 +0800"
      },
      "message": "iovec: make sure the caller actually wants anything in memcpy_fromiovecend\n\n[ Upstream commit 06ebb06d49486676272a3c030bfeef4bd969a8e6 ]\n\nCheck for cases when the caller requests 0 bytes instead of running off\nand dereferencing potentially invalid iovecs.\n\nSigned-off-by: Sasha Levin \u003csasha.levin@oracle.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "80db1671bd9bf67acf9c3b21350442b4b77e7cc4",
      "tree": "9264f957cb7f11080f095c9030cd4d95dabd6490",
      "parents": [
        "e2a2802ad1526fbdf1dc989c27ecd203f2de7f5c"
      ],
      "author": {
        "name": "Vlad Yasevich",
        "email": "vyasevic@redhat.com",
        "time": "Thu Jul 31 10:33:06 2014 -0400"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Aug 14 08:42:36 2014 +0800"
      },
      "message": "net: Correctly set segment mac_len in skb_segment().\n\n[ Upstream commit fcdfe3a7fa4cb74391d42b6a26dc07c20dab1d82 ]\n\nWhen performing segmentation, the mac_len value is copied right\nout of the original skb.  However, this value is not always set correctly\n(like when the packet is VLAN-tagged) and we\u0027ll end up copying a bad\nvalue.\n\nOne way to demonstrate this is to configure a VM which tags\npackets internally and turn off VLAN acceleration on the forwarding\nbridge port.  The packets show up corrupt like this:\n16:18:24.985548 52:54:00:ab:be:25 \u003e 52:54:00:26:ce:a3, ethertype 802.1Q\n(0x8100), length 1518: vlan 100, p 0, ethertype 0x05e0,\n        0x0000:  8cdb 1c7c 8cdb 0064 4006 b59d 0a00 6402 ...|...d@.....d.\n        0x0010:  0a00 6401 9e0d b441 0a5e 64ec 0330 14fa ..d....A.^d..0..\n        0x0020:  29e3 01c9 f871 0000 0101 080a 000a e833)....q.........3\n        0x0030:  000f 8c75 6e65 7470 6572 6600 6e65 7470 ...unetperf.netp\n        0x0040:  6572 6600 6e65 7470 6572 6600 6e65 7470 erf.netperf.netp\n        0x0050:  6572 6600 6e65 7470 6572 6600 6e65 7470 erf.netperf.netp\n        0x0060:  6572 6600 6e65 7470 6572 6600 6e65 7470 erf.netperf.netp\n        ...\n\nThis also leads to awful throughput as GSO packets are dropped and\ncause retransmissions.\n\nThe solution is to set the mac_len using the values already available\nin then new skb.  We\u0027ve already adjusted all of the header offset, so we\nmight as well correctly figure out the mac_len using skb_reset_mac_len().\nAfter this change, packets are segmented correctly and performance\nis restored.\n\nCC: Eric Dumazet \u003cedumazet@google.com\u003e\nSigned-off-by: Vlad Yasevich \u003cvyasevic@redhat.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "e2a2802ad1526fbdf1dc989c27ecd203f2de7f5c",
      "tree": "76807a3e73a020cb87062e6c15c0f519dabc3ed4",
      "parents": [
        "0fd6471aacff6a6eb9c19b8686813cb3ff503466"
      ],
      "author": {
        "name": "Vlad Yasevich",
        "email": "vyasevic@redhat.com",
        "time": "Thu Jul 31 10:30:25 2014 -0400"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Aug 14 08:42:36 2014 +0800"
      },
      "message": "macvlan: Initialize vlan_features to turn on offload support.\n\n[ Upstream commit 081e83a78db9b0ae1f5eabc2dedecc865f509b98 ]\n\nMacvlan devices do not initialize vlan_features.  As a result,\nany vlan devices configured on top of macvlans perform very poorly.\nInitialize vlan_features based on the vlan features of the lower-level\ndevice.\n\nSigned-off-by: Vlad Yasevich \u003cvyasevic@redhat.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "0fd6471aacff6a6eb9c19b8686813cb3ff503466",
      "tree": "0663d8f8af5ee7648473319fac39ad57963d39b6",
      "parents": [
        "1d06a70abffa9d6bd52cef880105458e432294d4"
      ],
      "author": {
        "name": "Daniel Borkmann",
        "email": "dborkman@redhat.com",
        "time": "Tue Jul 22 15:22:45 2014 +0200"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Aug 14 08:42:36 2014 +0800"
      },
      "message": "net: sctp: inherit auth_capable on INIT collisions\n\n[ Upstream commit 1be9a950c646c9092fb3618197f7b6bfb50e82aa ]\n\nJason reported an oops caused by SCTP on his ARM machine with\nSCTP authentication enabled:\n\nInternal error: Oops: 17 [#1] ARM\nCPU: 0 PID: 104 Comm: sctp-test Not tainted 3.13.0-68744-g3632f30c9b20-dirty #1\ntask: c6eefa40 ti: c6f52000 task.ti: c6f52000\nPC is at sctp_auth_calculate_hmac+0xc4/0x10c\nLR is at sg_init_table+0x20/0x38\npc : [\u003cc024bb80\u003e]    lr : [\u003cc00f32dc\u003e]    psr: 40000013\nsp : c6f538e8  ip : 00000000  fp : c6f53924\nr10: c6f50d80  r9 : 00000000  r8 : 00010000\nr7 : 00000000  r6 : c7be4000  r5 : 00000000  r4 : c6f56254\nr3 : c00c8170  r2 : 00000001  r1 : 00000008  r0 : c6f1e660\nFlags: nZcv  IRQs on  FIQs on  Mode SVC_32  ISA ARM  Segment user\nControl: 0005397f  Table: 06f28000  DAC: 00000015\nProcess sctp-test (pid: 104, stack limit \u003d 0xc6f521c0)\nStack: (0xc6f538e8 to 0xc6f54000)\n[...]\nBacktrace:\n[\u003cc024babc\u003e] (sctp_auth_calculate_hmac+0x0/0x10c) from [\u003cc0249af8\u003e] (sctp_packet_transmit+0x33c/0x5c8)\n[\u003cc02497bc\u003e] (sctp_packet_transmit+0x0/0x5c8) from [\u003cc023e96c\u003e] (sctp_outq_flush+0x7fc/0x844)\n[\u003cc023e170\u003e] (sctp_outq_flush+0x0/0x844) from [\u003cc023ef78\u003e] (sctp_outq_uncork+0x24/0x28)\n[\u003cc023ef54\u003e] (sctp_outq_uncork+0x0/0x28) from [\u003cc0234364\u003e] (sctp_side_effects+0x1134/0x1220)\n[\u003cc0233230\u003e] (sctp_side_effects+0x0/0x1220) from [\u003cc02330b0\u003e] (sctp_do_sm+0xac/0xd4)\n[\u003cc0233004\u003e] (sctp_do_sm+0x0/0xd4) from [\u003cc023675c\u003e] (sctp_assoc_bh_rcv+0x118/0x160)\n[\u003cc0236644\u003e] (sctp_assoc_bh_rcv+0x0/0x160) from [\u003cc023d5bc\u003e] (sctp_inq_push+0x6c/0x74)\n[\u003cc023d550\u003e] (sctp_inq_push+0x0/0x74) from [\u003cc024a6b0\u003e] (sctp_rcv+0x7d8/0x888)\n\nWhile we already had various kind of bugs in that area\nec0223ec48a9 (\"net: sctp: fix sctp_sf_do_5_1D_ce to verify if\nwe/peer is AUTH capable\") and b14878ccb7fa (\"net: sctp: cache\nauth_enable per endpoint\"), this one is a bit of a different\nkind.\n\nGiving a bit more background on why SCTP authentication is\nneeded can be found in RFC4895:\n\n  SCTP uses 32-bit verification tags to protect itself against\n  blind attackers. These values are not changed during the\n  lifetime of an SCTP association.\n\n  Looking at new SCTP extensions, there is the need to have a\n  method of proving that an SCTP chunk(s) was really sent by\n  the original peer that started the association and not by a\n  malicious attacker.\n\nTo cause this bug, we\u0027re triggering an INIT collision between\npeers; normal SCTP handshake where both sides intent to\nauthenticate packets contains RANDOM; CHUNKS; HMAC-ALGO\nparameters that are being negotiated among peers:\n\n  ---------- INIT[RANDOM; CHUNKS; HMAC-ALGO] ----------\u003e\n  \u003c------- INIT-ACK[RANDOM; CHUNKS; HMAC-ALGO] ---------\n  -------------------- COOKIE-ECHO --------------------\u003e\n  \u003c-------------------- COOKIE-ACK ---------------------\n\nRFC4895 says that each endpoint therefore knows its own random\nnumber and the peer\u0027s random number *after* the association\nhas been established. The local and peer\u0027s random number along\nwith the shared key are then part of the secret used for\ncalculating the HMAC in the AUTH chunk.\n\nNow, in our scenario, we have 2 threads with 1 non-blocking\nSEQ_PACKET socket each, setting up common shared SCTP_AUTH_KEY\nand SCTP_AUTH_ACTIVE_KEY properly, and each of them calling\nsctp_bindx(3), listen(2) and connect(2) against each other,\nthus the handshake looks similar to this, e.g.:\n\n  ---------- INIT[RANDOM; CHUNKS; HMAC-ALGO] ----------\u003e\n  \u003c------- INIT-ACK[RANDOM; CHUNKS; HMAC-ALGO] ---------\n  \u003c--------- INIT[RANDOM; CHUNKS; HMAC-ALGO] -----------\n  -------- INIT-ACK[RANDOM; CHUNKS; HMAC-ALGO] --------\u003e\n  ...\n\nSince such collisions can also happen with verification tags,\nthe RFC4895 for AUTH rather vaguely says under section 6.1:\n\n  In case of INIT collision, the rules governing the handling\n  of this Random Number follow the same pattern as those for\n  the Verification Tag, as explained in Section 5.2.4 of\n  RFC 2960 [5]. Therefore, each endpoint knows its own Random\n  Number and the peer\u0027s Random Number after the association\n  has been established.\n\nIn RFC2960, section 5.2.4, we\u0027re eventually hitting Action B:\n\n  B) In this case, both sides may be attempting to start an\n     association at about the same time but the peer endpoint\n     started its INIT after responding to the local endpoint\u0027s\n     INIT. Thus it may have picked a new Verification Tag not\n     being aware of the previous Tag it had sent this endpoint.\n     The endpoint should stay in or enter the ESTABLISHED\n     state but it MUST update its peer\u0027s Verification Tag from\n     the State Cookie, stop any init or cookie timers that may\n     running and send a COOKIE ACK.\n\nIn other words, the handling of the Random parameter is the\nsame as behavior for the Verification Tag as described in\nAction B of section 5.2.4.\n\nLooking at the code, we exactly hit the sctp_sf_do_dupcook_b()\ncase which triggers an SCTP_CMD_UPDATE_ASSOC command to the\nside effect interpreter, and in fact it properly copies over\npeer_{random, hmacs, chunks} parameters from the newly created\nassociation to update the existing one.\n\nAlso, the old asoc_shared_key is being released and based on\nthe new params, sctp_auth_asoc_init_active_key() updated.\nHowever, the issue observed in this case is that the previous\nasoc-\u003epeer.auth_capable was 0, and has *not* been updated, so\nthat instead of creating a new secret, we\u0027re doing an early\nreturn from the function sctp_auth_asoc_init_active_key()\nleaving asoc-\u003easoc_shared_key as NULL. However, we now have to\nauthenticate chunks from the updated chunk list (e.g. COOKIE-ACK).\n\nThat in fact causes the server side when responding with ...\n\n  \u003c------------------ AUTH; COOKIE-ACK -----------------\n\n... to trigger a NULL pointer dereference, since in\nsctp_packet_transmit(), it discovers that an AUTH chunk is\nbeing queued for xmit, and thus it calls sctp_auth_calculate_hmac().\n\nSince the asoc-\u003eactive_key_id is still inherited from the\nendpoint, and the same as encoded into the chunk, it uses\nasoc-\u003easoc_shared_key, which is still NULL, as an asoc_key\nand dereferences it in ...\n\n  crypto_hash_setkey(desc.tfm, \u0026asoc_key-\u003edata[0], asoc_key-\u003elen)\n\n... causing an oops. All this happens because sctp_make_cookie_ack()\ncalled with the *new* association has the peer.auth_capable\u003d1\nand therefore marks the chunk with auth\u003d1 after checking\nsctp_auth_send_cid(), but it is *actually* sent later on over\nthe then *updated* association\u0027s transport that didn\u0027t initialize\nits shared key due to peer.auth_capable\u003d0. Since control chunks\nin that case are not sent by the temporary association which\nare scheduled for deletion, they are issued for xmit via\nSCTP_CMD_REPLY in the interpreter with the context of the\n*updated* association. peer.auth_capable was 0 in the updated\nassociation (which went from COOKIE_WAIT into ESTABLISHED state),\nsince all previous processing that performed sctp_process_init()\nwas being done on temporary associations, that we eventually\nthrow away each time.\n\nThe correct fix is to update to the new peer.auth_capable\nvalue as well in the collision case via sctp_assoc_update(),\nso that in case the collision migrated from 0 -\u003e 1,\nsctp_auth_asoc_init_active_key() can properly recalculate\nthe secret. This therefore fixes the observed server panic.\n\nFixes: 730fc3d05cd4 (\"[SCTP]: Implete SCTP-AUTH parameter processing\")\nReported-by: Jason Gunthorpe \u003cjgunthorpe@obsidianresearch.com\u003e\nSigned-off-by: Daniel Borkmann \u003cdborkman@redhat.com\u003e\nTested-by: Jason Gunthorpe \u003cjgunthorpe@obsidianresearch.com\u003e\nCc: Vlad Yasevich \u003cvyasevich@gmail.com\u003e\nAcked-by: Vlad Yasevich \u003cvyasevich@gmail.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "1d06a70abffa9d6bd52cef880105458e432294d4",
      "tree": "5ded94ebdc08353403f5b24c43527c7887c14485",
      "parents": [
        "1f9480d282a68d14ac2a650ae74063fd889bfdcd"
      ],
      "author": {
        "name": "Christoph Paasch",
        "email": "christoph.paasch@uclouvain.be",
        "time": "Tue Jul 29 13:40:57 2014 +0200"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Aug 14 08:42:36 2014 +0800"
      },
      "message": "tcp: Fix integer-overflow in TCP vegas\n\n[ Upstream commit 1f74e613ded11517db90b2bd57e9464d9e0fb161 ]\n\nIn vegas we do a multiplication of the cwnd and the rtt. This\nmay overflow and thus their result is stored in a u64. However, we first\nneed to cast the cwnd so that actually 64-bit arithmetic is done.\n\nThen, we need to do do_div to allow this to be used on 32-bit arches.\n\nCc: Stephen Hemminger \u003cstephen@networkplumber.org\u003e\nCc: Neal Cardwell \u003cncardwell@google.com\u003e\nCc: Eric Dumazet \u003ceric.dumazet@gmail.com\u003e\nCc: David Laight \u003cDavid.Laight@ACULAB.COM\u003e\nCc: Doug Leith \u003cdoug.leith@nuim.ie\u003e\nFixes: 8d3a564da34e (tcp: tcp_vegas cong avoid fix)\nSigned-off-by: Christoph Paasch \u003cchristoph.paasch@uclouvain.be\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "1f9480d282a68d14ac2a650ae74063fd889bfdcd",
      "tree": "6df83ec7a1f4e4274352d725922d4e70952fb735",
      "parents": [
        "c28d71cac875c4419cef60e33b5a1f260b0002dc"
      ],
      "author": {
        "name": "Christoph Paasch",
        "email": "christoph.paasch@uclouvain.be",
        "time": "Tue Jul 29 12:07:27 2014 +0200"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Aug 14 08:42:36 2014 +0800"
      },
      "message": "tcp: Fix integer-overflows in TCP veno\n\n[ Upstream commit 45a07695bc64b3ab5d6d2215f9677e5b8c05a7d0 ]\n\nIn veno we do a multiplication of the cwnd and the rtt. This\nmay overflow and thus their result is stored in a u64. However, we first\nneed to cast the cwnd so that actually 64-bit arithmetic is done.\n\nA first attempt at fixing 76f1017757aa0 ([TCP]: TCP Veno congestion\ncontrol) was made by 159131149c2 (tcp: Overflow bug in Vegas), but it\nfailed to add the required cast in tcp_veno_cong_avoid().\n\nFixes: 76f1017757aa0 ([TCP]: TCP Veno congestion control)\nSigned-off-by: Christoph Paasch \u003cchristoph.paasch@uclouvain.be\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "c28d71cac875c4419cef60e33b5a1f260b0002dc",
      "tree": "faf800c1526b60589e71661ba573ad7bd3c423e7",
      "parents": [
        "509a15a5d6b0cfd3e4e396844615df6335ff4c62"
      ],
      "author": {
        "name": "Andrey Ryabinin",
        "email": "ryabinin.a.a@gmail.com",
        "time": "Sat Jul 26 21:26:58 2014 +0400"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Aug 14 08:42:35 2014 +0800"
      },
      "message": "net: sendmsg: fix NULL pointer dereference\n\n[ Upstream commit 40eea803c6b2cfaab092f053248cbeab3f368412 ]\n\nSasha\u0027s report:\n\t\u003e While fuzzing with trinity inside a KVM tools guest running the latest -next\n\t\u003e kernel with the KASAN patchset, I\u0027ve stumbled on the following spew:\n\t\u003e\n\t\u003e [ 4448.949424] \u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\t\u003e [ 4448.951737] AddressSanitizer: user-memory-access on address 0\n\t\u003e [ 4448.952988] Read of size 2 by thread T19638:\n\t\u003e [ 4448.954510] CPU: 28 PID: 19638 Comm: trinity-c76 Not tainted 3.16.0-rc4-next-20140711-sasha-00046-g07d3099-dirty #813\n\t\u003e [ 4448.956823]  ffff88046d86ca40 0000000000000000 ffff880082f37e78 ffff880082f37a40\n\t\u003e [ 4448.958233]  ffffffffb6e47068 ffff880082f37a68 ffff880082f37a58 ffffffffb242708d\n\t\u003e [ 4448.959552]  0000000000000000 ffff880082f37a88 ffffffffb24255b1 0000000000000000\n\t\u003e [ 4448.961266] Call Trace:\n\t\u003e [ 4448.963158] dump_stack (lib/dump_stack.c:52)\n\t\u003e [ 4448.964244] kasan_report_user_access (mm/kasan/report.c:184)\n\t\u003e [ 4448.965507] __asan_load2 (mm/kasan/kasan.c:352)\n\t\u003e [ 4448.966482] ? netlink_sendmsg (net/netlink/af_netlink.c:2339)\n\t\u003e [ 4448.967541] netlink_sendmsg (net/netlink/af_netlink.c:2339)\n\t\u003e [ 4448.968537] ? get_parent_ip (kernel/sched/core.c:2555)\n\t\u003e [ 4448.970103] sock_sendmsg (net/socket.c:654)\n\t\u003e [ 4448.971584] ? might_fault (mm/memory.c:3741)\n\t\u003e [ 4448.972526] ? might_fault (./arch/x86/include/asm/current.h:14 mm/memory.c:3740)\n\t\u003e [ 4448.973596] ? verify_iovec (net/core/iovec.c:64)\n\t\u003e [ 4448.974522] ___sys_sendmsg (net/socket.c:2096)\n\t\u003e [ 4448.975797] ? put_lock_stats.isra.13 (./arch/x86/include/asm/preempt.h:98 kernel/locking/lockdep.c:254)\n\t\u003e [ 4448.977030] ? lock_release_holdtime (kernel/locking/lockdep.c:273)\n\t\u003e [ 4448.978197] ? lock_release_non_nested (kernel/locking/lockdep.c:3434 (discriminator 1))\n\t\u003e [ 4448.979346] ? check_chain_key (kernel/locking/lockdep.c:2188)\n\t\u003e [ 4448.980535] __sys_sendmmsg (net/socket.c:2181)\n\t\u003e [ 4448.981592] ? trace_hardirqs_on_caller (kernel/locking/lockdep.c:2600)\n\t\u003e [ 4448.982773] ? trace_hardirqs_on (kernel/locking/lockdep.c:2607)\n\t\u003e [ 4448.984458] ? syscall_trace_enter (arch/x86/kernel/ptrace.c:1500 (discriminator 2))\n\t\u003e [ 4448.985621] ? trace_hardirqs_on_caller (kernel/locking/lockdep.c:2600)\n\t\u003e [ 4448.986754] SyS_sendmmsg (net/socket.c:2201)\n\t\u003e [ 4448.987708] tracesys (arch/x86/kernel/entry_64.S:542)\n\t\u003e [ 4448.988929] \u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nThis reports means that we\u0027ve come to netlink_sendmsg() with msg-\u003emsg_name \u003d\u003d NULL and msg-\u003emsg_namelen \u003e 0.\n\nAfter this report there was no usual \"Unable to handle kernel NULL pointer dereference\"\nand this gave me a clue that address 0 is mapped and contains valid socket address structure in it.\n\nThis bug was introduced in f3d3342602f8bcbf37d7c46641cb9bca7618eb1c\n(net: rework recvmsg handler msg_name and msg_namelen logic).\nCommit message states that:\n\t\"Set msg-\u003emsg_name \u003d NULL if user specified a NULL in msg_name but had a\n\t non-null msg_namelen in verify_iovec/verify_compat_iovec. This doesn\u0027t\n\t affect sendto as it would bail out earlier while trying to copy-in the\n\t address.\"\nBut in fact this affects sendto when address 0 is mapped and contains\nsocket address structure in it. In such case copy-in address will succeed,\nverify_iovec() function will successfully exit with msg-\u003emsg_namelen \u003e 0\nand msg-\u003emsg_name \u003d\u003d NULL.\n\nThis patch fixes it by setting msg_namelen to 0 if msg_name \u003d\u003d NULL.\n\nCc: Hannes Frederic Sowa \u003channes@stressinduktion.org\u003e\nCc: Eric Dumazet \u003cedumazet@google.com\u003e\nCc: \u003cstable@vger.kernel.org\u003e\nReported-by: Sasha Levin \u003csasha.levin@oracle.com\u003e\nSigned-off-by: Andrey Ryabinin \u003ca.ryabinin@samsung.com\u003e\nAcked-by: Hannes Frederic Sowa \u003channes@stressinduktion.org\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "509a15a5d6b0cfd3e4e396844615df6335ff4c62",
      "tree": "a3f92b13246768ed53016216cac459a86ec1f772",
      "parents": [
        "ad52eef552c7896ec6024ee72fc126167fe5c4e2"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "edumazet@google.com",
        "time": "Sat Jul 26 08:58:10 2014 +0200"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Aug 14 08:42:35 2014 +0800"
      },
      "message": "ip: make IP identifiers less predictable\n\n[ Upstream commit 04ca6973f7c1a0d8537f2d9906a0cf8e69886d75 ]\n\nIn \"Counting Packets Sent Between Arbitrary Internet Hosts\", Jeffrey and\nJedidiah describe ways exploiting linux IP identifier generation to\ninfer whether two machines are exchanging packets.\n\nWith commit 73f156a6e8c1 (\"inetpeer: get rid of ip_id_count\"), we\nchanged IP id generation, but this does not really prevent this\nside-channel technique.\n\nThis patch adds a random amount of perturbation so that IP identifiers\nfor a given destination [1] are no longer monotonically increasing after\nan idle period.\n\nNote that prandom_u32_max(1) returns 0, so if generator is used at most\nonce per jiffy, this patch inserts no hole in the ID suite and do not\nincrease collision probability.\n\nThis is jiffies based, so in the worst case (HZ\u003d1000), the id can\nrollover after ~65 seconds of idle time, which should be fine.\n\nWe also change the hash used in __ip_select_ident() to not only hash\non daddr, but also saddr and protocol, so that ICMP probes can not be\nused to infer information for other protocols.\n\nFor IPv6, adds saddr into the hash as well, but not nexthdr.\n\nIf I ping the patched target, we can see ID are now hard to predict.\n\n21:57:11.008086 IP (...)\n    A \u003e target: ICMP echo request, seq 1, length 64\n21:57:11.010752 IP (... id 2081 ...)\n    target \u003e A: ICMP echo reply, seq 1, length 64\n\n21:57:12.013133 IP (...)\n    A \u003e target: ICMP echo request, seq 2, length 64\n21:57:12.015737 IP (... id 3039 ...)\n    target \u003e A: ICMP echo reply, seq 2, length 64\n\n21:57:13.016580 IP (...)\n    A \u003e target: ICMP echo request, seq 3, length 64\n21:57:13.019251 IP (... id 3437 ...)\n    target \u003e A: ICMP echo reply, seq 3, length 64\n\n[1] TCP sessions uses a per flow ID generator not changed by this patch.\n\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nReported-by: Jeffrey Knockel \u003cjeffk@cs.unm.edu\u003e\nReported-by: Jedidiah R. Crandall \u003ccrandall@cs.unm.edu\u003e\nCc: Willy Tarreau \u003cw@1wt.eu\u003e\nCc: Hannes Frederic Sowa \u003channes@redhat.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "ad52eef552c7896ec6024ee72fc126167fe5c4e2",
      "tree": "ad82cf940ab103a6b51260f681b22d21f6ecdb2c",
      "parents": [
        "0a9d91dca3b9f797f2fc615486c12afa59f19a3b"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "edumazet@google.com",
        "time": "Mon Jun 02 05:26:03 2014 -0700"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Aug 14 08:42:35 2014 +0800"
      },
      "message": "inetpeer: get rid of ip_id_count\n\n[ Upstream commit 73f156a6e8c1074ac6327e0abd1169e95eb66463 ]\n\nIdeally, we would need to generate IP ID using a per destination IP\ngenerator.\n\nlinux kernels used inet_peer cache for this purpose, but this had a huge\ncost on servers disabling MTU discovery.\n\n1) each inet_peer struct consumes 192 bytes\n\n2) inetpeer cache uses a binary tree of inet_peer structs,\n   with a nominal size of ~66000 elements under load.\n\n3) lookups in this tree are hitting a lot of cache lines, as tree depth\n   is about 20.\n\n4) If server deals with many tcp flows, we have a high probability of\n   not finding the inet_peer, allocating a fresh one, inserting it in\n   the tree with same initial ip_id_count, (cf secure_ip_id())\n\n5) We garbage collect inet_peer aggressively.\n\nIP ID generation do not have to be \u0027perfect\u0027\n\nGoal is trying to avoid duplicates in a short period of time,\nso that reassembly units have a chance to complete reassembly of\nfragments belonging to one message before receiving other fragments\nwith a recycled ID.\n\nWe simply use an array of generators, and a Jenkin hash using the dst IP\nas a key.\n\nipv6_select_ident() is put back into net/ipv6/ip6_output.c where it\nbelongs (it is only used from this file)\n\nsecure_ip_id() and secure_ipv6_id() no longer are needed.\n\nRename ip_select_ident_more() to ip_select_ident_segs() to avoid\nunnecessary decrement/increment of the number of segments.\n\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    }
  ],
  "next": "0a9d91dca3b9f797f2fc615486c12afa59f19a3b"
}
