)]}'
{
  "log": [
    {
      "commit": "a565623f44aeafafc74a5763f765d5c8224bc4ad",
      "tree": "ee36a64f0b2a0361ecc918a251a06f1b58c33700",
      "parents": [
        "2d2b65eeb598b687403aa0f06d4d7da97661958a"
      ],
      "author": {
        "name": "Lars-Peter Clausen",
        "email": "lars@metafoo.de",
        "time": "Fri Dec 07 18:30:51 2012 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Jan 17 08:50:43 2013 -0800"
      },
      "message": "ASoC: sigmadsp: Fix endianness conversion issue\n\ncommit a3adb1432d7a3ad86bb17a1638e44414537e4118 upstream.\n\nThe \u0027addr\u0027 field of the sigma_action struct is stored as big endian in the\nfirmware file.\n\nSigned-off-by: Lars-Peter Clausen \u003clars@metafoo.de\u003e\nSigned-off-by: Mark Brown \u003cbroonie@opensource.wolfsonmicro.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "2d2b65eeb598b687403aa0f06d4d7da97661958a",
      "tree": "9a54c68d6cde2c6ec6466c3900423b3edc890087",
      "parents": [
        "5004c75870b05d2ffd5974d1fd681a5a1b0d9f4c"
      ],
      "author": {
        "name": "Stephan Gatzka",
        "email": "stephan.gatzka@gmail.com",
        "time": "Wed Nov 28 20:04:32 2012 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Jan 17 08:50:43 2013 -0800"
      },
      "message": "firewire: net: Fix handling of fragmented multicast/broadcast packets.\n\ncommit 9d2373420900a39f5212a3b289331aa3535b1000 upstream.\n\nThis patch fixes both the transmit and receive portion of sending\nfragmented mutlicast and broadcast packets.\n\nThe transmit section was broken because the offset for INTFRAG and\nLASTFRAG packets were just miscalculated by IEEE1394_GASP_HDR_SIZE (which\nwas reserved with skb_push() in fwnet_send_packet).\n\nThe receive section was broken because in fwnet_incoming_packet is a call\nto fwnet_peer_find_by_node_id(). Called with generation \u003d\u003d -1 it will\nnot find a peer and the partial datagrams are associated to a peer.\n\n[Stefan R:  The fix to use context-\u003ecard-\u003egeneration is not perfect.\nIt relies on the IR tasklet which processes packets from the prior bus\ngeneration to run before the self-ID-complete worklet which sets the\ncurrent card generation.  Alas, there is no simple way of a race-free\nimplementation.  Let\u0027s do it this way for now.]\n\nSigned-off-by: Stephan Gatzka \u003cstephan.gatzka@gmail.com\u003e\nSigned-off-by: Stefan Richter \u003cstefanr@s5r6.in-berlin.de\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "5004c75870b05d2ffd5974d1fd681a5a1b0d9f4c",
      "tree": "b7051566a9a133010ad1adb0221bd32cf5cc750a",
      "parents": [
        "324b9bebea9e335c8588bf5eefdcca7d932508e6"
      ],
      "author": {
        "name": "Felix Fietkau",
        "email": "nbd@openwrt.org",
        "time": "Mon Dec 10 14:03:17 2012 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Jan 17 08:50:43 2013 -0800"
      },
      "message": "ath9k_hw: Fix signal strength / channel noise reporting\n\ncommit b7c0c238898d200e80487516e2b67aba2a522cc0 upstream.\n\nWhile AR_PHY_CCA_NOM_VAL_* does contain the expected internal noise floor\nfor a chip measured in clean air, it refers to the lowest expected reading.\n\nDepending on the frequency, this measurement can vary by about 6db, thus\ncausing a higher reported channel noise and signal strength.\n\nFactor in the 6db offset when converting internal noisefloor to channel noise.\n\nThis patch makes the reported values more accurate for all chips without\naffecting NF calibration behavior.\n\nSigned-off-by: Felix Fietkau \u003cnbd@openwrt.org\u003e\nSigned-off-by: John W. Linville \u003clinville@tuxdriver.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "324b9bebea9e335c8588bf5eefdcca7d932508e6",
      "tree": "21ea680f747db820625ff1d25183bad54121c1f3",
      "parents": [
        "867f263c648dee508e0cdd857a44f69a1bc2fad7"
      ],
      "author": {
        "name": "Gabor Juhos",
        "email": "juhosg@openwrt.org",
        "time": "Sun Dec 09 23:57:09 2012 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Jan 17 08:50:43 2013 -0800"
      },
      "message": "ath9k: ar9003: fix OTP register offsets for AR9340\n\ncommit b3cd8021379306c0be6932e4d3b4b01efc681769 upstream.\n\nTrying to access the OTP memory on the AR9340\ncauses a data bus error like this:\n\n  Data bus error, epc \u003d\u003d 86e84164, ra \u003d\u003d 86e84164\n  Oops[#1]:\n  Cpu 0\n  $ 0   : 00000000 00000061 deadc0de 00000000\n  $ 4   : b8115f18 00015f18 00000007 00000004\n  $ 8   : 00000001 7c7c3c7c 7c7c7c7c 7c7c7c7c\n  $12   : 7c7c3c7c 001f0041 00000000 7c7c7c3c\n  $16   : 86ee0000 00015f18 00000000 00000007\n  $20   : 00000004 00000064 00000004 86d71c44\n  $24   : 00000000 86e6ca00\n  $28   : 86d70000 86d71b20 86ece0c0 86e84164\n  Hi    : 00000000\n  Lo    : 00000064\n  epc   : 86e84164 ath9k_hw_wait+0x58/0xb0 [ath9k_hw]\n      Tainted: G           O\n  ra    : 86e84164 ath9k_hw_wait+0x58/0xb0 [ath9k_hw]\n  Status: 1100d403    KERNEL EXL IE\n  Cause : 4080801c\n  PrId  : 0001974c (MIPS 74Kc)\n  Modules linked in: ath9k(O+) ath9k_common(O) ath9k_hw(O) ath(O) ar934x_nfc\n  mac80211(O) usbcore usb_common scsi_mod nls_base nand nand_ecc nand_ids\n  crc_ccitt cfg80211(O) compat(O) arc4 aes_generic crypto_blkcipher cryptomgr\n  aead crypto_hash crypto_algapi ledtrig_timer ledtrig_default_on leds_gpio\n  Process insmod (pid: 459, threadinfo\u003d86d70000, task\u003d87942140, tls\u003d779ac440)\n  Stack : 802fb500 000200da 804db150 804e0000 87816130 86ee0000 00010000 86d71b88\n          86d71bc0 00000004 00000003 86e9fcd0 80305300 0002c0d0 86e74c50 800b4c20\n          000003e8 00000001 00000000 86ee0000 000003ff 86e9fd64 80305300 80123938\n          fffffffc 00000004 000058bc 00000000 86ea0000 86ee0000 000001ff 878d6000\n          99999999 86e9fdc0 86ee0fcc 86e9e664 0000c0d0 86ee0000 0000700000007000\n          ...\n  Call Trace:\n  [\u003c86e84164\u003e] ath9k_hw_wait+0x58/0xb0 [ath9k_hw]\n  [\u003c86e9fcd0\u003e] ath9k_hw_setup_statusring+0x16b8/0x1c7c [ath9k_hw]\n\n  Code: 0000a812  0040f809  00000000 \u003c00531024\u003e 1054000b  24020001  0c05b5dc  2404000a  26520001\n\nThe cause of the error is that the OTP register\noffsets are different on the AR9340 than the\nactually used values.\n\nSigned-off-by: Gabor Juhos \u003cjuhosg@openwrt.org\u003e\nSigned-off-by: John W. Linville \u003clinville@tuxdriver.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "867f263c648dee508e0cdd857a44f69a1bc2fad7",
      "tree": "eff80fa6ef3c09d48fe04292e4e338bfdfb08fb5",
      "parents": [
        "ce19422296fb5fb5997d81e1b0043d771def7996"
      ],
      "author": {
        "name": "Felix Fietkau",
        "email": "nbd@openwrt.org",
        "time": "Thu Dec 06 18:40:11 2012 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Jan 17 08:50:43 2013 -0800"
      },
      "message": "Revert \"ath9k_hw: Update AR9003 high_power tx gain table\"\n\ncommit 9c170e068636deb3e3f96114034bb711675f0faa upstream.\n\nThis reverts commit f74b9d365ddd33a375802b064f96a5d0e99af7c0.\n\nTurns out reverting commit a240dc7b3c7463bd60cf0a9b2a90f52f78aae0fd\n\"ath9k_hw: Updated AR9003 tx gain table for 5GHz\" was not enough to\nbring the tx power back to normal levels on devices like the\nBuffalo WZR-HP-G450H, this one needs to be reverted as well.\n\nThis revert improves tx power by ~10 db on that device\n\nSigned-off-by: Felix Fietkau \u003cnbd@openwrt.org\u003e\nCc: rmanohar@qca.qualcomm.com\nSigned-off-by: John W. Linville \u003clinville@tuxdriver.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "ce19422296fb5fb5997d81e1b0043d771def7996",
      "tree": "92b8292798661ad6d3d4e4e4a8649949b30872cf",
      "parents": [
        "c0b96525363543a1ba6a277546ebc26ad9a53aa1"
      ],
      "author": {
        "name": "Laura Abbott",
        "email": "lauraa@codeaurora.org",
        "time": "Fri Jan 11 14:31:51 2013 -0800"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Jan 17 08:50:43 2013 -0800"
      },
      "message": "mm: use aligned zone start for pfn_to_bitidx calculation\n\ncommit c060f943d0929f3e429c5d9522290584f6281d6e upstream.\n\nThe current calculation in pfn_to_bitidx assumes that (pfn -\nzone-\u003ezone_start_pfn) \u003e\u003e pageblock_order will return the same bit for\nall pfn in a pageblock.  If zone_start_pfn is not aligned to\npageblock_nr_pages, this may not always be correct.\n\nConsider the following with pageblock order \u003d 10, zone start 2MB:\n\n  pfn     | pfn - zone start | (pfn - zone start) \u003e\u003e page block order\n  ----------------------------------------------------------------\n  0x26000 | 0x25e00\t   |  0x97\n  0x26100 | 0x25f00\t   |  0x97\n  0x26200 | 0x26000\t   |  0x98\n  0x26300 | 0x26100\t   |  0x98\n\nThis means that calling {get,set}_pageblock_migratetype on a single page\nwill not set the migratetype for the full block.  Fix this by rounding\ndown zone_start_pfn when doing the bitidx calculation.\n\nFor our use case, the effects of this bug were mostly tied to the fact\nthat CMA allocations would either take a long time or fail to happen.\nDepending on the driver using CMA, this could result in anything from\nvisual glitches to application failures.\n\nSigned-off-by: Laura Abbott \u003clauraa@codeaurora.org\u003e\nAcked-by: Mel Gorman \u003cmgorman@suse.de\u003e\nSigned-off-by: Andrew Morton \u003cakpm@linux-foundation.org\u003e\nSigned-off-by: Linus Torvalds \u003ctorvalds@linux-foundation.org\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "c0b96525363543a1ba6a277546ebc26ad9a53aa1",
      "tree": "88515adb3db5516bc858a5ac00d941bfea786106",
      "parents": [
        "b1ca420793e505d04f3a47a74651af7c037774b7"
      ],
      "author": {
        "name": "Jason Liu",
        "email": "r64343@freescale.com",
        "time": "Fri Jan 11 14:31:47 2013 -0800"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Jan 17 08:50:43 2013 -0800"
      },
      "message": "mm: compaction: fix echo 1 \u003e compact_memory return error issue\n\ncommit 7964c06d66c76507d8b6b662bffea770c29ef0ce upstream.\n\nwhen run the folloing command under shell, it will return error\n\n  sh/$ echo 1 \u003e /proc/sys/vm/compact_memory\n  sh/$ sh: write error: Bad address\n\nAfter strace, I found the following log:\n\n  ...\n  write(1, \"1\\n\", 2)               \u003d 3\n  write(1, \"\", 4294967295)         \u003d -1 EFAULT (Bad address)\n  write(2, \"echo: write error: Bad address\\n\", 31echo: write error: Bad address\n  ) \u003d 31\n\nThis tells system return 3(COMPACT_COMPLETE) after write data to\ncompact_memory.\n\nThe fix is to make the system just return 0 instead 3(COMPACT_COMPLETE)\nfrom sysctl_compaction_handler after compaction_nodes finished.\n\nSigned-off-by: Jason Liu \u003cr64343@freescale.com\u003e\nSuggested-by: David Rientjes \u003crientjes@google.com\u003e\nAcked-by: Mel Gorman \u003cmgorman@suse.de\u003e\nCc: Rik van Riel \u003criel@redhat.com\u003e\nCc: Minchan Kim \u003cminchan@kernel.org\u003e\nCc: KAMEZAWA Hiroyuki \u003ckamezawa.hiroyu@jp.fujitsu.com\u003e\nAcked-by: David Rientjes \u003crientjes@google.com\u003e\nSigned-off-by: Andrew Morton \u003cakpm@linux-foundation.org\u003e\nSigned-off-by: Linus Torvalds \u003ctorvalds@linux-foundation.org\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "b1ca420793e505d04f3a47a74651af7c037774b7",
      "tree": "422517d51e576c8b352ceffbd8f7ddc13d2de8bb",
      "parents": [
        "4305c46a628974e21e7939893476e4e735cd603c"
      ],
      "author": {
        "name": "Huacai Chen",
        "email": "chenhc@lemote.com",
        "time": "Mon Aug 13 20:52:24 2012 +0800"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Jan 17 08:50:42 2013 -0800"
      },
      "message": "MIPS: Fix poweroff failure when HOTPLUG_CPU configured.\n\ncommit 8add1ecb81f541ef2fcb0b85a5470ad9ecfb4a84 upstream.\n\nWhen poweroff machine, kernel_power_off() call disable_nonboot_cpus().\nAnd if we have HOTPLUG_CPU configured, disable_nonboot_cpus() is not an\nempty function but attempt to actually disable the nonboot cpus. Since\nsystem state is SYSTEM_POWER_OFF, play_dead() won\u0027t be called and thus\ndisable_nonboot_cpus() hangs. Therefore, we make this patch to avoid\npoweroff failure.\n\nSigned-off-by: Huacai Chen \u003cchenhc@lemote.com\u003e\nSigned-off-by: Hongliang Tao \u003ctaohl@lemote.com\u003e\nSigned-off-by: Hua Yan \u003cyanh@lemote.com\u003e\nCc: Yong Zhang \u003cyong.zhang@windriver.com\u003e\nCc: Fuxin Zhang \u003czhangfx@lemote.com\u003e\nCc: Zhangjin Wu \u003cwuzhangjin@gmail.com\u003e\nPatchwork: https://patchwork.linux-mips.org/patch/4211/\nSigned-off-by: Ralf Baechle \u003cralf@linux-mips.org\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "4305c46a628974e21e7939893476e4e735cd603c",
      "tree": "6ae727a6f739c187ce296b501955d2ca53a71824",
      "parents": [
        "9d4c74b86237ac64376b92c54cf7b471e7e75f76"
      ],
      "author": {
        "name": "Sebastian Ott",
        "email": "sebott@linux.vnet.ibm.com",
        "time": "Fri Nov 30 16:48:59 2012 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Jan 17 08:50:42 2013 -0800"
      },
      "message": "s390/cio: fix pgid reserved check\n\ncommit d99e79ec5574fc556c988f613ed6175f6de66f4a upstream.\n\nThe check to whom a device is reserved is done by checking the path\nstate of the affected channel paths. If it turns out that one path is\nflagged as reserved by someone else the whole device is marked as such.\n\nHowever the meaning of the RESVD_ELSE bit is that the addressed device\nis reserved to a different pathgroup (and not reserved to a different\nLPAR). If we do this test on a path which is currently not a member of\nthe pathgroup we could erroneously mark the device as reserved to\nsomeone else.\n\nTo fix this collect the reserved state for all potential members of the\npathgroup and only mark the device as reserved if all of those potential\nmembers have the RESVD_ELSE bit set.\n\nAcked-by: Peter Oberparleiter \u003cpeter.oberparleiter@de.ibm.com\u003e\nSigned-off-by: Sebastian Ott \u003csebott@linux.vnet.ibm.com\u003e\nSigned-off-by: Martin Schwidefsky \u003cschwidefsky@de.ibm.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "9d4c74b86237ac64376b92c54cf7b471e7e75f76",
      "tree": "62dbe4253920ec2cc4419e3f6446fb531d6b7a2a",
      "parents": [
        "91534f7365982fa0c29192e73416dd798397310a"
      ],
      "author": {
        "name": "Alex Williamson",
        "email": "alex.williamson@redhat.com",
        "time": "Thu Nov 29 14:07:59 2012 -0700"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Jan 17 08:50:42 2013 -0800"
      },
      "message": "KVM: Fix user memslot overlap check\n\ncommit 5419369ed6bd4cf711fdda5e52a5999b940413f5 upstream.\n\nPrior to memory slot sorting this loop compared all of the user memory\nslots for overlap with new entries.  With memory slot sorting, we\u0027re\njust checking some number of entries in the array that may or may not\nbe user slots.  Instead, walk all the slots with kvm_for_each_memslot,\nwhich has the added benefit of terminating early when we hit the first\nempty slot, and skip comparison to private slots.\n\nSigned-off-by: Alex Williamson \u003calex.williamson@redhat.com\u003e\nSigned-off-by: Marcelo Tosatti \u003cmtosatti@redhat.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "91534f7365982fa0c29192e73416dd798397310a",
      "tree": "3074fa51b1becfd41341fd6b11fbfeaf4eb3947b",
      "parents": [
        "23c4e04a835e6b538efc431e7310af9e924d6978"
      ],
      "author": {
        "name": "Gabor Juhos",
        "email": "juhosg@openwrt.org",
        "time": "Thu Dec 20 03:44:28 2012 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Jan 17 08:50:42 2013 -0800"
      },
      "message": "powerpc: Add missing NULL terminator to avoid boot panic on PPC40x\n\ncommit e6449c9b2d90c1bd9a5985bf05ddebfd1631cd6b upstream.\n\nThe missing NULL terminator can cause a panic on\nPPC405 boards during boot:\n\n  Linux/PowerPC load: console\u003dttyS0,115200 root\u003d/dev/mtdblock1 rootfstype\u003dsquashfs,jffs2 noinitrd init\u003d/etc/preinit\n  Finalizing device tree... flat tree at 0x6a5160\n  bootconsole [udbg0] enabled\n  Page fault in user mode with in_atomic() \u003d 1 mm \u003d (null)\n  NIP \u003d c0275f50  MSR \u003d fffffffe\n  Oops: Weird page fault, sig: 11 [#1]\n  PowerPC 40x Platform\n  Modules linked in:\n  NIP: c0275f50 LR: c0275f60 CTR: c0280000\n  REGS: c0275eb0 TRAP: 636f7265   Not tainted  (3.7.1)\n  MSR: fffffffe \u003cVEC,VSX,EE,PR,FP,ME,SE,BE,IR,DR,PMM,RI\u003e CR: c06a6190  XER: 00000001\n  TASK \u003d c02662a8[0] \u0027swapper\u0027 THREAD: c0274000\n  GPR00: c0275ec0 c000c658 c027c4bf 00000000 c0275ee0 c000a0ec c020a1a8 c020a1f0\n  GPR08: c020f631 c020f404 c025f078 c025f080 c0275f10\n   Call Trace:\n   ---[ end trace 31fd0ba7d8756001 ]---\n\n  Kernel panic - not syncing: Attempted to kill the idle task!\n\nThe panic happens since commit 9597abe00c1bab2aedce6b49866bf6d1e81c9eed\n(sections: fix section conflicts in arch/powerpc), however the root\ncause of this is that the NULL terminator were not added in commit\na4f740cf33f7f6c164bbde3c0cdbcc77b0c4997c (of/flattree: Add of_flat_dt_match()\nhelper function).\n\nSigned-off-by: Gabor Juhos \u003cjuhosg@openwrt.org\u003e\nCc: Grant Likely \u003cgrant.likely@secretlab.ca\u003e\nSigned-off-by: Benjamin Herrenschmidt \u003cbenh@kernel.crashing.org\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "23c4e04a835e6b538efc431e7310af9e924d6978",
      "tree": "e0940ffcf7d0fd9a513289416ad97f6e14920609",
      "parents": [
        "55800cd51f64300f66c9c0e6eda015e1d6626a57"
      ],
      "author": {
        "name": "Shan Hai",
        "email": "shan.hai@windriver.com",
        "time": "Thu Nov 08 15:57:49 2012 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Jan 17 08:50:42 2013 -0800"
      },
      "message": "powerpc/vdso: Remove redundant locking in update_vsyscall_tz()\n\ncommit ce73ec6db47af84d1466402781ae0872a9e7873c upstream.\n\nThe locking in update_vsyscall_tz() is not only unnecessary because the vdso\ncode copies the data unproteced in __kernel_gettimeofday() but also\nintroduces a hard to reproduce race condition between update_vsyscall()\nand update_vsyscall_tz(), which causes user space process to loop\nforever in vdso code.\n\nThe following patch removes the locking from update_vsyscall_tz().\n\nLocking is not only unnecessary because the vdso code copies the data\nunprotected in __kernel_gettimeofday() but also erroneous because updating\nthe tb_update_count is not atomic and introduces a hard to reproduce race\ncondition between update_vsyscall() and update_vsyscall_tz(), which further\ncauses user space process to loop forever in vdso code.\n\nThe below scenario describes the race condition,\nx\u003d\u003d0\tBoot CPU\t\t\tother CPU\n\tproc_P: x\u003d\u003d0\n\t    timer interrupt\n\t\tupdate_vsyscall\nx\u003d\u003d1\t\t    x++;sync\t\tsettimeofday\n\t\t\t\t\t    update_vsyscall_tz\nx\u003d\u003d2\t\t\t\t\t\tx++;sync\nx\u003d\u003d3\t\t    sync;x++\n\t\t\t\t\t\tsync;x++\n\tproc_P: x\u003d\u003d3 (loops until x becomes even)\n\nBecause the ++ operator would be implemented as three instructions and not\natomic on powerpc.\n\nA similar change was made for x86 in commit 6c260d58634\n(\"x86: vdso: Remove bogus locking in update_vsyscall_tz\")\n\nSigned-off-by: Shan Hai \u003cshan.hai@windriver.com\u003e\nSigned-off-by: Benjamin Herrenschmidt \u003cbenh@kernel.crashing.org\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "55800cd51f64300f66c9c0e6eda015e1d6626a57",
      "tree": "c96fc877889a1c4c6112d3da39cb3d8d0bb092c0",
      "parents": [
        "8fcd6a440a3d01216bd6d88ce00e7353b1813ec6"
      ],
      "author": {
        "name": "Anton Blanchard",
        "email": "anton@samba.org",
        "time": "Sun Nov 11 19:01:05 2012 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Jan 17 08:50:42 2013 -0800"
      },
      "message": "powerpc: Fix CONFIG_RELOCATABLE\u003dy CONFIG_CRASH_DUMP\u003dn build\n\ncommit 11ee7e99f35ecb15f59b21da6a82d96d2cd3fcc8 upstream.\n\nIf we build a kernel with CONFIG_RELOCATABLE\u003dy CONFIG_CRASH_DUMP\u003dn,\nthe kernel fails when we run at a non zero offset. It turns out\nwe were incorrectly wrapping some of the relocatable kernel code\nwith CONFIG_CRASH_DUMP.\n\nSigned-off-by: Anton Blanchard \u003canton@samba.org\u003e\nSigned-off-by: Benjamin Herrenschmidt \u003cbenh@kernel.crashing.org\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "8fcd6a440a3d01216bd6d88ce00e7353b1813ec6",
      "tree": "d1b024b9518f76d476a0353150b95dcf4ed88f4e",
      "parents": [
        "2686f897e696630f02455b5fa269dd90312f5c8d"
      ],
      "author": {
        "name": "Rafał Miłecki",
        "email": "zajec5@gmail.com",
        "time": "Mon Dec 10 07:53:56 2012 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Jan 17 08:50:41 2013 -0800"
      },
      "message": "bcma: mips: fix clearing device IRQ\n\ncommit cbbc0138efe1dcd5426b8fc5d87741f5057aee72 upstream.\n\nWe were using wrong IRQ number so clearing wasn\u0027t working at all.\nDepending on a platform this could result in a one device having two\ninterrupts assigned. On BCM4706 this resulted in all IRQs being broken.\n\nSigned-off-by: Rafał Miłecki \u003czajec5@gmail.com\u003e\nCc: Hauke Mehrtens \u003chauke@hauke-m.de\u003e\nAcked-by: Hauke Mehrtens \u003chauke@hauke-m.de\u003e\nSigned-off-by: John W. Linville \u003clinville@tuxdriver.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "2686f897e696630f02455b5fa269dd90312f5c8d",
      "tree": "7084c5103f780c4ebf6f160e1c5b2a27ddd15da2",
      "parents": [
        "7e7791e17f932363b8194a68f531d11952861993"
      ],
      "author": {
        "name": "Felix Fietkau",
        "email": "nbd@openwrt.org",
        "time": "Mon Dec 10 16:40:41 2012 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Jan 17 08:50:41 2013 -0800"
      },
      "message": "ath5k: fix tx path skb leaks\n\ncommit 596ab5ec3bf10a22be30d7cb1d903a4b83fd607c upstream.\n\nieee80211_free_txskb() needs to be used instead of dev_kfree_skb_any for\ntx packets passed to the driver from mac80211\n\nSigned-off-by: Felix Fietkau \u003cnbd@openwrt.org\u003e\nSigned-off-by: John W. Linville \u003clinville@tuxdriver.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "7e7791e17f932363b8194a68f531d11952861993",
      "tree": "3b04a6e8dd8a5189bab31c60c9fb884986a1a032",
      "parents": [
        "0ba1cd8da86b7c4717852e786bacc7154b62d95c"
      ],
      "author": {
        "name": "Mark Brown",
        "email": "broonie@opensource.wolfsonmicro.com",
        "time": "Tue Nov 20 10:02:06 2012 +0900"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Thu Jan 17 08:50:41 2013 -0800"
      },
      "message": "regulator: wm831x: Set the new rather than old value for DVS VSEL\n\ncommit 13ae633cf729b0ecb677b75b04886ff8fada8fad upstream.\n\nReported-by: Guennadi Liakhovetski \u003cg.liakhovetski@gmx.de\u003e\nSigned-off-by: Mark Brown \u003cbroonie@opensource.wolfsonmicro.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "0ba1cd8da86b7c4717852e786bacc7154b62d95c",
      "tree": "f2c526a92ee9f714bff05b076503a6a8bffa8a83",
      "parents": [
        "4ca05c86fde5ea8fd6b1929cb0e14b7993de9ba1"
      ],
      "author": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:09:13 2013 -0800"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:09:13 2013 -0800"
      },
      "message": "Linux 3.4.25\n"
    },
    {
      "commit": "4ca05c86fde5ea8fd6b1929cb0e14b7993de9ba1",
      "tree": "aef77458a5bcf79ba78f34b0752ff0dc9f5cef54",
      "parents": [
        "c0c7cf289528474c46ce4e851ed33c467c32720c"
      ],
      "author": {
        "name": "Alexander Stein",
        "email": "alexander.stein@systec-electronic.com",
        "time": "Tue Nov 27 08:52:34 2012 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:07:18 2013 -0800"
      },
      "message": "can: Do not call dev_put if restart timer is running upon close\n\ncommit ab48b03ec9ae1840a1e427e2375bd0d9d554b4ed upstream.\n\nIf the restart timer is running due to BUS-OFF and the device is\ndisconnected an dev_put will decrease the usage counter to -1 thus\nblocking the interface removal, resulting in the following dmesg\nlines repeating every 10s:\ncan: notifier: receive list not found for dev can0\ncan: notifier: receive list not found for dev can0\ncan: notifier: receive list not found for dev can0\nunregister_netdevice: waiting for can0 to become free. Usage count \u003d -1\n\nSigned-off-by: Alexander Stein \u003calexander.stein@systec-electronic.com\u003e\nSigned-off-by: Marc Kleine-Budde \u003cmkl@pengutronix.de\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "c0c7cf289528474c46ce4e851ed33c467c32720c",
      "tree": "c8e6f9eaf6889bab0e723ee51c59334010dfb0ae",
      "parents": [
        "b14d552774ed848ca1ca94d8adedcd743e3aa671"
      ],
      "author": {
        "name": "Ben Hutchings",
        "email": "ben@decadent.org.uk",
        "time": "Sun Dec 02 14:38:23 2012 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:07:18 2013 -0800"
      },
      "message": "HID: Add Apple wireless keyboard 2011 ANSI to special driver list\n\ncommit f9af7b9edccb87d4d80b58687ab63e58f3b64c4c upstream.\n\nCommit 0a97e1e9f9a6 (\u0027HID: apple: Add Apple wireless keyboard 2011 ANSI PID\u0027)\ndid not update the special driver list in hid-core.c, so hid-generic may\nstill bind to this device.\n\nReported-by: Ari Pollak \u003cari@scvngr.com\u003e\nReferences: http://bugs.debian.org/694546\nSigned-off-by: Ben Hutchings \u003cben@decadent.org.uk\u003e\nSigned-off-by: Jiri Kosina \u003cjkosina@suse.cz\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "b14d552774ed848ca1ca94d8adedcd743e3aa671",
      "tree": "36e3c23c3b3a2923a95b01583a48a31fccafff40",
      "parents": [
        "e0996e350216f727b0f0e6219e79c8da5b3d1416"
      ],
      "author": {
        "name": "Michal Hocko",
        "email": "mhocko@suse.cz",
        "time": "Fri Jan 04 15:35:12 2013 -0800"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:07:18 2013 -0800"
      },
      "message": "mm: limit mmu_gather batching to fix soft lockups on !CONFIG_PREEMPT\n\ncommit 53a59fc67f97374758e63a9c785891ec62324c81 upstream.\n\nSince commit e303297e6c3a (\"mm: extended batches for generic\nmmu_gather\") we are batching pages to be freed until either\ntlb_next_batch cannot allocate a new batch or we are done.\n\nThis works just fine most of the time but we can get in troubles with\nnon-preemptible kernel (CONFIG_PREEMPT_NONE or CONFIG_PREEMPT_VOLUNTARY)\non large machines where too aggressive batching might lead to soft\nlockups during process exit path (exit_mmap) because there are no\nscheduling points down the free_pages_and_swap_cache path and so the\nfreeing can take long enough to trigger the soft lockup.\n\nThe lockup is harmless except when the system is setup to panic on\nsoftlockup which is not that unusual.\n\nThe simplest way to work around this issue is to limit the maximum\nnumber of batches in a single mmu_gather.  10k of collected pages should\nbe safe to prevent from soft lockups (we would have 2ms for one) even if\nthey are all freed without an explicit scheduling point.\n\nThis patch doesn\u0027t add any new explicit scheduling points because it\nrelies on zap_pmd_range during page tables zapping which calls\ncond_resched per PMD.\n\nThe following lockup has been reported for 3.0 kernel with a huge\nprocess (in order of hundreds gigs but I do know any more details).\n\n  BUG: soft lockup - CPU#56 stuck for 22s! [kernel:31053]\n  Modules linked in: af_packet nfs lockd fscache auth_rpcgss nfs_acl sunrpc mptctl mptbase autofs4 binfmt_misc dm_round_robin dm_multipath bonding cpufreq_conservative cpufreq_userspace cpufreq_powersave pcc_cpufreq mperf microcode fuse loop osst sg sd_mod crc_t10dif st qla2xxx scsi_transport_fc scsi_tgt netxen_nic i7core_edac iTCO_wdt joydev e1000e serio_raw pcspkr edac_core iTCO_vendor_support acpi_power_meter rtc_cmos hpwdt hpilo button container usbhid hid dm_mirror dm_region_hash dm_log linear uhci_hcd ehci_hcd usbcore usb_common scsi_dh_emc scsi_dh_alua scsi_dh_hp_sw scsi_dh_rdac scsi_dh dm_snapshot pcnet32 mii edd dm_mod raid1 ext3 mbcache jbd fan thermal processor thermal_sys hwmon cciss scsi_mod\n  Supported: Yes\n  CPU 56\n  Pid: 31053, comm: kernel Not tainted 3.0.31-0.9-default #1 HP ProLiant DL580 G7\n  RIP: 0010:  _raw_spin_unlock_irqrestore+0x8/0x10\n  RSP: 0018:ffff883ec1037af0  EFLAGS: 00000206\n  RAX: 0000000000000e00 RBX: ffffea01a0817e28 RCX: ffff88803ffd9e80\n  RDX: 0000000000000200 RSI: 0000000000000206 RDI: 0000000000000206\n  RBP: 0000000000000002 R08: 0000000000000001 R09: ffff887ec724a400\n  R10: 0000000000000000 R11: dead000000200200 R12: ffffffff8144c26e\n  R13: 0000000000000030 R14: 0000000000000297 R15: 000000000000000e\n  FS:  00007ed834282700(0000) GS:ffff88c03f200000(0000) knlGS:0000000000000000\n  CS:  0010 DS: 0000 ES: 0000 CR0: 000000008005003b\n  CR2: 000000000068b240 CR3: 0000003ec13c5000 CR4: 00000000000006e0\n  DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n  DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400\n  Process kernel (pid: 31053, threadinfo ffff883ec1036000, task ffff883ebd5d4100)\n  Call Trace:\n    release_pages+0xc5/0x260\n    free_pages_and_swap_cache+0x9d/0xc0\n    tlb_flush_mmu+0x5c/0x80\n    tlb_finish_mmu+0xe/0x50\n    exit_mmap+0xbd/0x120\n    mmput+0x49/0x120\n    exit_mm+0x122/0x160\n    do_exit+0x17a/0x430\n    do_group_exit+0x3d/0xb0\n    get_signal_to_deliver+0x247/0x480\n    do_signal+0x71/0x1b0\n    do_notify_resume+0x98/0xb0\n    int_signal+0x12/0x17\n  DWARF2 unwinder stuck at int_signal+0x12/0x17\n\nSigned-off-by: Michal Hocko \u003cmhocko@suse.cz\u003e\nCc: Mel Gorman \u003cmgorman@suse.de\u003e\nCc: Rik van Riel \u003criel@redhat.com\u003e\nCc: Peter Zijlstra \u003ca.p.zijlstra@chello.nl\u003e\nSigned-off-by: Andrew Morton \u003cakpm@linux-foundation.org\u003e\nSigned-off-by: Linus Torvalds \u003ctorvalds@linux-foundation.org\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "e0996e350216f727b0f0e6219e79c8da5b3d1416",
      "tree": "08f3694fe61e83d9ef53bc5f7c6d7953e16e580b",
      "parents": [
        "8f4d9c2f748cab8ef5a30e9d9e5261679af3462f"
      ],
      "author": {
        "name": "Tony Prisk",
        "email": "linux@prisktech.co.nz",
        "time": "Fri Jan 04 15:35:48 2013 -0800"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:07:18 2013 -0800"
      },
      "message": "drivers/rtc/rtc-vt8500.c: fix handling of data passed in struct rtc_time\n\ncommit 2f90b68309683f2c5765a1b04ca23d71e51f1494 upstream.\n\ntm_mon is 0..11, whereas vt8500 expects 1..12 for the month field,\ncausing invalid date errors for January, and causing the day field to\nroll over incorrectly.\n\nThe century flag is only handled in vt8500_rtc_read_time, but not set in\nvt8500_rtc_set_time.  This patch corrects the behaviour of the century\nflag.\n\nSigned-off-by: Edgar Toernig \u003cfroese@gmx.de\u003e\nSigned-off-by: Tony Prisk \u003clinux@prisktech.co.nz\u003e\nSigned-off-by: Andrew Morton \u003cakpm@linux-foundation.org\u003e\nSigned-off-by: Linus Torvalds \u003ctorvalds@linux-foundation.org\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "8f4d9c2f748cab8ef5a30e9d9e5261679af3462f",
      "tree": "caf14b812534b3d50d445e526defcefade8471f9",
      "parents": [
        "850fcad11762fae7b25c6a9d3fdb5ff4d7a39420"
      ],
      "author": {
        "name": "Tony Prisk",
        "email": "linux@prisktech.co.nz",
        "time": "Fri Jan 04 15:35:47 2013 -0800"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:07:18 2013 -0800"
      },
      "message": "drivers/rtc/rtc-vt8500.c: correct handling of CR_24H bitfield\n\ncommit 532db570e5181abc8f4f7bfa6c77c69ec2240198 upstream.\n\nControl register bitfield for 12H/24H mode is handled incorrectly.\nSetting CR_24H actually enables 12H mode.  This patch renames the define\nand changes the initialization code to correctly set 24H mode.\n\nSigned-off-by: Tony Prisk \u003clinux@prisktech.co.nz\u003e\nCc: Edgar Toernig \u003cfroese@gmx.de\u003e\nSigned-off-by: Andrew Morton \u003cakpm@linux-foundation.org\u003e\nSigned-off-by: Linus Torvalds \u003ctorvalds@linux-foundation.org\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "850fcad11762fae7b25c6a9d3fdb5ff4d7a39420",
      "tree": "810661f659544c8cb5458b150ed45fa1d79649c0",
      "parents": [
        "0f7ac9c81bdb08763e7ca02317592281e22542bc"
      ],
      "author": {
        "name": "Corey Minyard",
        "email": "cminyard@mvista.com",
        "time": "Tue Dec 18 14:21:19 2012 -0800"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:07:17 2013 -0800"
      },
      "message": "CRIS: fix I/O macros\n\ncommit c24bf9b4cc6a0f330ea355d73bfdf1dae7e63a05 upstream.\n\nThe inb/outb macros for CRIS are broken from a number of points of view,\nmissing () around parameters and they have an unprotected if statement\nin them.  This was breaking the compile of IPMI on CRIS and thus I was\nbeing annoyed by build regressions, so I fixed them.\n\nPlus I don\u0027t think they would have worked at all, since the data values\nwere missing \"\u0026\" and the outsl had a \"3\" instead of a \"4\" for the size.\nFrom what I can tell, this stuff is not used at all, so this can\u0027t be\nany more broken than it was before, anyway.\n\nSigned-off-by: Corey Minyard \u003ccminyard@mvista.com\u003e\nCc: Jesper Nilsson \u003cjesper.nilsson@axis.com\u003e\nCc: Mikael Starvik \u003cstarvik@axis.com\u003e\nAcked-by: Geert Uytterhoeven \u003cgeert@linux-m68k.org\u003e\nSigned-off-by: Andrew Morton \u003cakpm@linux-foundation.org\u003e\nSigned-off-by: Linus Torvalds \u003ctorvalds@linux-foundation.org\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "0f7ac9c81bdb08763e7ca02317592281e22542bc",
      "tree": "d898118dd31890d4383ae33597c4a02a33463bf6",
      "parents": [
        "1a0da46b46bc9b27414fcb1f1ad6f0eeee311f5e"
      ],
      "author": {
        "name": "Stephen Boyd",
        "email": "sboyd@codeaurora.org",
        "time": "Wed Dec 19 23:39:48 2012 -0800"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:07:17 2013 -0800"
      },
      "message": "lib: atomic64: Initialize locks statically to fix early users\n\ncommit fcc16882ac4532aaa644bff444f0c5d6228ba71e upstream.\n\nThe atomic64 library uses a handful of static spin locks to implement\natomic 64-bit operations on architectures without support for atomic\n64-bit instructions.\n\nUnfortunately, the spinlocks are initialized in a pure initcall and that\nis too late for the vfs namespace code which wants to use atomic64\noperations before the initcall is run.\n\nThis became a problem as of commit 8823c079ba71: \"vfs: Add setns support\nfor the mount namespace\".\n\nThis leads to BUG messages such as:\n\n  BUG: spinlock bad magic on CPU#0, swapper/0/0\n   lock: atomic64_lock+0x240/0x400, .magic: 00000000, .owner: \u003cnone\u003e/-1, .owner_cpu: 0\n    do_raw_spin_lock+0x158/0x198\n    _raw_spin_lock_irqsave+0x4c/0x58\n    atomic64_add_return+0x30/0x5c\n    alloc_mnt_ns.clone.14+0x44/0xac\n    create_mnt_ns+0xc/0x54\n    mnt_init+0x120/0x1d4\n    vfs_caches_init+0xe0/0x10c\n    start_kernel+0x29c/0x300\n\ncoming out early on during boot when spinlock debugging is enabled.\n\nFix this by initializing the spinlocks statically at compile time.\n\nReported-and-tested-by: Vaibhav Bedia \u003cvaibhav.bedia@ti.com\u003e\nTested-by: Tony Lindgren \u003ctony@atomide.com\u003e\nCc: Eric W. Biederman \u003cebiederm@xmission.com\u003e\nSigned-off-by: Stephen Boyd \u003csboyd@codeaurora.org\u003e\nSigned-off-by: Linus Torvalds \u003ctorvalds@linux-foundation.org\u003e\nSigned-off-by: Andrew Morton \u003cakpm@linux-foundation.org\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "1a0da46b46bc9b27414fcb1f1ad6f0eeee311f5e",
      "tree": "9c1e1a6bd1e689fc93213f7db5fbf7cee4de5b03",
      "parents": [
        "7e2741804be03faf0eaba1df228e2ba5c07ecdd7"
      ],
      "author": {
        "name": "Gustavo Padovan",
        "email": "gustavo.padovan@collabora.co.uk",
        "time": "Wed Nov 21 00:50:21 2012 -0200"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:07:17 2013 -0800"
      },
      "message": "Bluetooth: cancel power_on work when unregistering the device\n\ncommit b9b5ef188e5a2222cfc16ef62a4703080750b451 upstream.\n\nWe need to cancel the hci_power_on work in order to avoid it run when we\ntry to free the hdev.\n\n[ 1434.201149] ------------[ cut here ]------------\n[ 1434.204998] WARNING: at lib/debugobjects.c:261 debug_print_object+0x8e/0xb0()\n[ 1434.208324] ODEBUG: free active (active state 0) object type: work_struct hint: hci\n_power_on+0x0/0x90\n[ 1434.210386] Pid: 8564, comm: trinity-child25 Tainted: G        W    3.7.0-rc5-next-\n20121112-sasha-00018-g2f4ce0e #127\n[ 1434.210760] Call Trace:\n[ 1434.210760]  [\u003cffffffff819f3d6e\u003e] ? debug_print_object+0x8e/0xb0\n[ 1434.210760]  [\u003cffffffff8110b887\u003e] warn_slowpath_common+0x87/0xb0\n[ 1434.210760]  [\u003cffffffff8110b911\u003e] warn_slowpath_fmt+0x41/0x50\n[ 1434.210760]  [\u003cffffffff819f3d6e\u003e] debug_print_object+0x8e/0xb0\n[ 1434.210760]  [\u003cffffffff8376b750\u003e] ? hci_dev_open+0x310/0x310\n[ 1434.210760]  [\u003cffffffff83bf94e5\u003e] ? _raw_spin_unlock_irqrestore+0x55/0xa0\n[ 1434.210760]  [\u003cffffffff819f3ee5\u003e] __debug_check_no_obj_freed+0xa5/0x230\n[ 1434.210760]  [\u003cffffffff83785db0\u003e] ? bt_host_release+0x10/0x20\n[ 1434.210760]  [\u003cffffffff819f4d15\u003e] debug_check_no_obj_freed+0x15/0x20\n[ 1434.210760]  [\u003cffffffff8125eee7\u003e] kfree+0x227/0x330\n[ 1434.210760]  [\u003cffffffff83785db0\u003e] bt_host_release+0x10/0x20\n[ 1434.210760]  [\u003cffffffff81e539e5\u003e] device_release+0x65/0xc0\n[ 1434.210760]  [\u003cffffffff819d3975\u003e] kobject_cleanup+0x145/0x190\n[ 1434.210760]  [\u003cffffffff819d39cd\u003e] kobject_release+0xd/0x10\n[ 1434.210760]  [\u003cffffffff819d33cc\u003e] kobject_put+0x4c/0x60\n[ 1434.210760]  [\u003cffffffff81e548b2\u003e] put_device+0x12/0x20\n[ 1434.210760]  [\u003cffffffff8376a334\u003e] hci_free_dev+0x24/0x30\n[ 1434.210760]  [\u003cffffffff82fd8fe1\u003e] vhci_release+0x31/0x60\n[ 1434.210760]  [\u003cffffffff8127be12\u003e] __fput+0x122/0x250\n[ 1434.210760]  [\u003cffffffff811cab0d\u003e] ? rcu_user_exit+0x9d/0xd0\n[ 1434.210760]  [\u003cffffffff8127bf49\u003e] ____fput+0x9/0x10\n[ 1434.210760]  [\u003cffffffff81133402\u003e] task_work_run+0xb2/0xf0\n[ 1434.210760]  [\u003cffffffff8106cfa7\u003e] do_notify_resume+0x77/0xa0\n[ 1434.210760]  [\u003cffffffff83bfb0ea\u003e] int_signal+0x12/0x17\n[ 1434.210760] ---[ end trace a6d57fefbc8a8cc7 ]---\n\nReported-by: Sasha Levin \u003csasha.levin@oracle.com\u003e\nSigned-off-by: Gustavo Padovan \u003cgustavo.padovan@collabora.co.uk\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "7e2741804be03faf0eaba1df228e2ba5c07ecdd7",
      "tree": "e9740f5b6e5a6f93343732adfc8e55b75680de1c",
      "parents": [
        "2145cea1e0be3262768fef384a87f426ecad06fe"
      ],
      "author": {
        "name": "Gustavo Padovan",
        "email": "gustavo.padovan@collabora.co.uk",
        "time": "Tue Nov 20 23:25:54 2012 -0200"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:07:17 2013 -0800"
      },
      "message": "Bluetooth: Add missing lock nesting notation\n\ncommit dc2a0e20fbc85a71c63aa4330b496fda33f6bf80 upstream.\n\nThis patch fixes the following report, it happens when accepting rfcomm\nconnections:\n\n[  228.165378] \u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n[  228.165378] [ INFO: possible recursive locking detected ]\n[  228.165378] 3.7.0-rc1-00536-gc1d5dc4 #120 Tainted: G        W\n[  228.165378] ---------------------------------------------\n[  228.165378] bluetoothd/1341 is trying to acquire lock:\n[  228.165378]  (sk_lock-AF_BLUETOOTH-BTPROTO_RFCOMM){+.+...}, at:\n[\u003cffffffffa0000aa0\u003e] bt_accept_dequeue+0xa0/0x180 [bluetooth]\n[  228.165378]\n[  228.165378] but task is already holding lock:\n[  228.165378]  (sk_lock-AF_BLUETOOTH-BTPROTO_RFCOMM){+.+...}, at:\n[\u003cffffffffa0205118\u003e] rfcomm_sock_accept+0x58/0x2d0 [rfcomm]\n[  228.165378]\n[  228.165378] other info that might help us debug this:\n[  228.165378]  Possible unsafe locking scenario:\n[  228.165378]\n[  228.165378]        CPU0\n[  228.165378]        ----\n[  228.165378]   lock(sk_lock-AF_BLUETOOTH-BTPROTO_RFCOMM);\n[  228.165378]   lock(sk_lock-AF_BLUETOOTH-BTPROTO_RFCOMM);\n[  228.165378]\n[  228.165378]  *** DEADLOCK ***\n[  228.165378]\n[  228.165378]  May be due to missing lock nesting notation\n\nSigned-off-by: Gustavo Padovan \u003cgustavo.padovan@collabora.co.uk\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "2145cea1e0be3262768fef384a87f426ecad06fe",
      "tree": "692cd5a32ed977eb73c3d77b0a3f1e5e465b89bc",
      "parents": [
        "7164ac211086207dc371e3b32165226e28e2dcfa"
      ],
      "author": {
        "name": "Marcos Chaparro",
        "email": "marcos@mrkindustries.com.ar",
        "time": "Tue Nov 06 16:19:11 2012 -0300"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:07:17 2013 -0800"
      },
      "message": "Bluetooth: ath3k: Add support for VAIO VPCEH [0489:e027]\n\ncommit acd9454433e28c1a365d8b069813c35c1c3a8ac3 upstream.\n\nAdded Atheros AR3011 internal bluetooth device found in Sony VAIO VPCEH to the\ndevices list.\nBefore this, the bluetooth module was identified as an Foxconn / Hai bluetooth\ndevice [0489:e027], now it claims to be an AtherosAR3011 Bluetooth\n[0cf3:3005].\n\nT:  Bus\u003d01 Lev\u003d02 Prnt\u003d02 Port\u003d04 Cnt\u003d02 Dev#\u003d  4 Spd\u003d12   MxCh\u003d 0\nD:  Ver\u003d 1.10 Cls\u003de0(wlcon) Sub\u003d01 Prot\u003d01 MxPS\u003d64 #Cfgs\u003d  1\nP:  Vendor\u003d0489 ProdID\u003de027 Rev\u003d 0.01\nC:* #Ifs\u003d 2 Cfg#\u003d 1 Atr\u003de0 MxPwr\u003d100mA\nI:* If#\u003d 0 Alt\u003d 0 #EPs\u003d 3 Cls\u003de0(wlcon) Sub\u003d01 Prot\u003d01 Driver\u003dbtusb\nE:  Ad\u003d81(I) Atr\u003d03(Int.) MxPS\u003d  16 Ivl\u003d1ms\nE:  Ad\u003d82(I) Atr\u003d02(Bulk) MxPS\u003d  64 Ivl\u003d0ms\nE:  Ad\u003d02(O) Atr\u003d02(Bulk) MxPS\u003d  64 Ivl\u003d0ms\nI:* If#\u003d 1 Alt\u003d 0 #EPs\u003d 2 Cls\u003de0(wlcon) Sub\u003d01 Prot\u003d01 Driver\u003dbtusb\nE:  Ad\u003d83(I) Atr\u003d01(Isoc) MxPS\u003d   0 Ivl\u003d1ms\nE:  Ad\u003d03(O) Atr\u003d01(Isoc) MxPS\u003d   0 Ivl\u003d1ms\nI:  If#\u003d 1 Alt\u003d 1 #EPs\u003d 2 Cls\u003de0(wlcon) Sub\u003d01 Prot\u003d01 Driver\u003dbtusb\nE:  Ad\u003d83(I) Atr\u003d01(Isoc) MxPS\u003d   9 Ivl\u003d1ms\nE:  Ad\u003d03(O) Atr\u003d01(Isoc) MxPS\u003d   9 Ivl\u003d1ms\nI:  If#\u003d 1 Alt\u003d 2 #EPs\u003d 2 Cls\u003de0(wlcon) Sub\u003d01 Prot\u003d01 Driver\u003dbtusb\nE:  Ad\u003d83(I) Atr\u003d01(Isoc) MxPS\u003d  17 Ivl\u003d1ms\nE:  Ad\u003d03(O) Atr\u003d01(Isoc) MxPS\u003d  17 Ivl\u003d1ms\nI:  If#\u003d 1 Alt\u003d 3 #EPs\u003d 2 Cls\u003de0(wlcon) Sub\u003d01 Prot\u003d01 Driver\u003dbtusb\nE:  Ad\u003d83(I) Atr\u003d01(Isoc) MxPS\u003d  25 Ivl\u003d1ms\nE:  Ad\u003d03(O) Atr\u003d01(Isoc) MxPS\u003d  25 Ivl\u003d1ms\nI:  If#\u003d 1 Alt\u003d 4 #EPs\u003d 2 Cls\u003de0(wlcon) Sub\u003d01 Prot\u003d01 Driver\u003dbtusb\nE:  Ad\u003d83(I) Atr\u003d01(Isoc) MxPS\u003d  33 Ivl\u003d1ms\nE:  Ad\u003d03(O) Atr\u003d01(Isoc) MxPS\u003d  33 Ivl\u003d1ms\nI:  If#\u003d 1 Alt\u003d 5 #EPs\u003d 2 Cls\u003de0(wlcon) Sub\u003d01 Prot\u003d01 Driver\u003dbtusb\nE:  Ad\u003d83(I) Atr\u003d01(Isoc) MxPS\u003d  49 Ivl\u003d1ms\nE:  Ad\u003d03(O) Atr\u003d01(Isoc) MxPS\u003d  49 Ivl\u003d1ms\n\nSigned-off-by: Marcos Chaparro \u003cmarcos@mrkindustries.com.ar\u003e\nSigned-off-by: Gustavo Padovan \u003cgustavo.padovan@collabora.co.uk\u003e\nCc: Ben Hutchings \u003cben@decadent.org.uk\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "7164ac211086207dc371e3b32165226e28e2dcfa",
      "tree": "e7dc397786bda21d8476ce0174433a34c5b99bee",
      "parents": [
        "fdbe6fecef94b6171de7a2ccfe543a694c9c41bc"
      ],
      "author": {
        "name": "Andy Lutomirski",
        "email": "luto@amacapital.net",
        "time": "Sat Dec 01 12:37:20 2012 -0800"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:07:16 2013 -0800"
      },
      "message": "PCI: Reduce Ricoh 0xe822 SD card reader base clock frequency to 50MHz\n\ncommit 812089e01b9f65f90fc8fc670d8cce72a0e01fbb upstream.\n\nOtherwise it fails like this on cards like the Transcend 16GB SDHC card:\n\n    mmc0: new SDHC card at address b368\n    mmcblk0: mmc0:b368 SDC   15.0 GiB\n    mmcblk0: error -110 sending status command, retrying\n    mmcblk0: error -84 transferring data, sector 0, nr 8, cmd response 0x900, card status 0xb0\n\nTested on my Lenovo x200 laptop.\n\n[bhelgaas: changelog]\nSigned-off-by: Andy Lutomirski \u003cluto@amacapital.net\u003e\nSigned-off-by: Bjorn Helgaas \u003cbhelgaas@google.com\u003e\nAcked-by: Chris Ball \u003ccjb@laptop.org\u003e\nCC: Manoj Iyer \u003cmanoj.iyer@canonical.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "fdbe6fecef94b6171de7a2ccfe543a694c9c41bc",
      "tree": "07e41788190fe7045db8ac98d052b9af5bf12fc9",
      "parents": [
        "042279bf26576ada65948ea45ab7ac86e0490c0a"
      ],
      "author": {
        "name": "David Woodhouse",
        "email": "dwmw2@infradead.org",
        "time": "Tue Dec 11 14:57:14 2012 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:07:16 2013 -0800"
      },
      "message": "solos-pci: fix double-free of TX skb in DMA mode\n\ncommit cae49ede00ec3d0cda290b03fee55b72b49efc11 upstream.\n\nWe weren\u0027t clearing card-\u003etx_skb[port] when processing the TX done interrupt.\nIf there wasn\u0027t another skb ready to transmit immediately, this led to a\ndouble-free because we\u0027d free it *again* next time we did have a packet to\nsend.\n\nSigned-off-by: David Woodhouse \u003cDavid.Woodhouse@intel.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "042279bf26576ada65948ea45ab7ac86e0490c0a",
      "tree": "add35d24a73a76a42a9783833e02c8c8b522ec53",
      "parents": [
        "ebd3b1a320baa264c7662363fa4b930634470a4b"
      ],
      "author": {
        "name": "Will Deacon",
        "email": "will.deacon@arm.com",
        "time": "Wed Dec 19 15:01:50 2012 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:07:16 2013 -0800"
      },
      "message": "ARM: 7607/1: realview: fix private peripheral memory base for EB rev. B boards\n\ncommit e6ee4b2b57a8e0d8e551031173de080b338d3969 upstream.\n\nCommit 34ae6c96a6a7 (\"ARM: 7298/1: realview: fix mapping of MPCore\nprivate memory region\") accidentally broke the definition for the base\naddress of the private peripheral region on revision B Realview-EB\nboards.\n\nThis patch uses the correct address for REALVIEW_EB11MP_PRIV_MEM_BASE.\n\nAcked-by: Marc Zyngier \u003cmarc.zyngier@arm.com\u003e\nTested-by: Florian Fainelli \u003cflorian@openwrt.org\u003e\nSigned-off-by: Will Deacon \u003cwill.deacon@arm.com\u003e\nSigned-off-by: Russell King \u003crmk+kernel@arm.linux.org.uk\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "ebd3b1a320baa264c7662363fa4b930634470a4b",
      "tree": "37b48c62993286f17718003f721625c7c42e6894",
      "parents": [
        "99574fa03e407cad20953d7cbfcb0056f02e811e"
      ],
      "author": {
        "name": "Al Viro",
        "email": "viro@ZenIV.linux.org.uk",
        "time": "Sun Dec 16 00:25:57 2012 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:07:16 2013 -0800"
      },
      "message": "ARM: missing -\u003emmap_sem around find_vma() in swp_emulate.c\n\ncommit 7bf9b7bef881aac820bf1f2e9951a17b09bd7e04 upstream.\n\nfind_vma() is *not* safe when somebody else is removing vmas.  Not just\nthe return value might get bogus just as you are getting it (this instance\ndoesn\u0027t try to dereference the resulting vma), the search itself can get\nbuggered in rather spectacular ways.  IOW, -\u003emmap_sem really, really is\nnot optional here.\n\nSigned-off-by: Al Viro \u003cviro@zeniv.linux.org.uk\u003e\nSigned-off-by: Russell King \u003crmk+kernel@arm.linux.org.uk\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "99574fa03e407cad20953d7cbfcb0056f02e811e",
      "tree": "f2f96ae490b89959329802232ae1415eb2b5c4fe",
      "parents": [
        "2ee4432e82437a7c051c254b065fbf5d4581e1a3"
      ],
      "author": {
        "name": "Will Deacon",
        "email": "will.deacon@arm.com",
        "time": "Tue Sep 18 19:18:35 2012 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:07:16 2013 -0800"
      },
      "message": "ARM: mm: use pteval_t to represent page protection values\n\ncommit 864aa04cd02979c2c755cb28b5f4fe56039171c0 upstream.\n\nWhen updating the page protection map after calculating the user_pgprot\nvalue, the base protection map is temporarily stored in an unsigned long\ntype, causing truncation of the protection bits when LPAE is enabled.\nThis effectively means that calls to mprotect() will corrupt the upper\npage attributes, clearing the XN bit unconditionally.\n\nThis patch uses pteval_t to store the intermediate protection values,\npreserving the upper bits for 64-bit descriptors.\n\nAcked-by: Nicolas Pitre \u003cnico@linaro.org\u003e\nAcked-by: Catalin Marinas \u003ccatalin.marinas@arm.com\u003e\nSigned-off-by: Will Deacon \u003cwill.deacon@arm.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "2ee4432e82437a7c051c254b065fbf5d4581e1a3",
      "tree": "67e44acf4a1296e1bb719746b579c0a7e8efacad",
      "parents": [
        "29eac3795e2bb2a319f84438d45a4dbcc500cc6c"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "edumazet@google.com",
        "time": "Sun Oct 21 19:57:11 2012 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:07:15 2013 -0800"
      },
      "message": "tcp: RFC 5961 5.2 Blind Data Injection Attack Mitigation\n\n[ Upstream commit 354e4aa391ed50a4d827ff6fc11e0667d0859b25 ]\n\nRFC 5961 5.2 [Blind Data Injection Attack].[Mitigation]\n\n  All TCP stacks MAY implement the following mitigation.  TCP stacks\n  that implement this mitigation MUST add an additional input check to\n  any incoming segment.  The ACK value is considered acceptable only if\n  it is in the range of ((SND.UNA - MAX.SND.WND) \u003c\u003d SEG.ACK \u003c\u003d\n  SND.NXT).  All incoming segments whose ACK value doesn\u0027t satisfy the\n  above condition MUST be discarded and an ACK sent back.\n\nMove tcp_send_challenge_ack() before tcp_ack() to avoid a forward\ndeclaration.\n\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nCc: Neal Cardwell \u003cncardwell@google.com\u003e\nCc: Yuchung Cheng \u003cycheng@google.com\u003e\nCc: Jerry Chu \u003chkchu@google.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "29eac3795e2bb2a319f84438d45a4dbcc500cc6c",
      "tree": "649547e7bd72a54fa349d90aa7d50f0ef7d635b2",
      "parents": [
        "f451931e294c83d811783799f8a6c29929fc8e85"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "edumazet@google.com",
        "time": "Tue Nov 13 05:37:18 2012 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:07:15 2013 -0800"
      },
      "message": "tcp: tcp_replace_ts_recent() should not be called from tcp_validate_incoming()\n\n[ Upstream commit bd090dfc634ddd711a5fbd0cadc6e0ab4977bcaf ]\n\nWe added support for RFC 5961 in latest kernels but TCP fails\nto perform exhaustive check of ACK sequence.\n\nWe can update our view of peer tsval from a frame that is\nlater discarded by tcp_ack()\n\nThis makes timestamps enabled sessions vulnerable to injection of\na high tsval : peers start an ACK storm, since the victim\nsends a dupack each time it receives an ACK from the other peer.\n\nAs tcp_validate_incoming() is called before tcp_ack(), we should\nnot peform tcp_replace_ts_recent() from it, and let callers do it\nat the right time.\n\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nCc: Neal Cardwell \u003cncardwell@google.com\u003e\nCc: Yuchung Cheng \u003cycheng@google.com\u003e\nCc: Nandita Dukkipati \u003cnanditad@google.com\u003e\nCc: H.K. Jerry Chu \u003chkchu@google.com\u003e\nCc: Romain Francoise \u003cromain@orebokech.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "f451931e294c83d811783799f8a6c29929fc8e85",
      "tree": "2ea952d980f047320f2ad1358117dbb65877cc1d",
      "parents": [
        "d21383fcbb535f90b429279852988d675ed22d67"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "edumazet@google.com",
        "time": "Tue Jul 17 12:29:30 2012 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:07:15 2013 -0800"
      },
      "message": "tcp: refine SYN handling in tcp_validate_incoming\n\n[ Upstream commit e371589917011efe6ff8c7dfb4e9e81934ac5855 ]\n\nFollowup of commit 0c24604b68fc (tcp: implement RFC 5961 4.2)\n\nAs reported by Vijay Subramanian, we should send a challenge ACK\ninstead of a dup ack if a SYN flag is set on a packet received out of\nwindow.\n\nThis permits the ratelimiting to work as intended, and to increase\ncorrect SNMP counters.\n\nSuggested-by: Vijay Subramanian \u003csubramanian.vijay@gmail.com\u003e\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nAcked-by: Vijay Subramanian \u003csubramanian.vijay@gmail.com\u003e\nCc: Kiran Kumar Kella \u003ckkiran@broadcom.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "d21383fcbb535f90b429279852988d675ed22d67",
      "tree": "7f395982de610bfc355082ae351deb01a19a5060",
      "parents": [
        "34fb350281ced2a72707a5c0064f69992d440edb"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "edumazet@google.com",
        "time": "Tue Jul 17 01:41:30 2012 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:07:15 2013 -0800"
      },
      "message": "tcp: implement RFC 5961 4.2\n\n[ Upstream commit 0c24604b68fc7810d429d6c3657b6f148270e528 ]\n\nImplement the RFC 5691 mitigation against Blind\nReset attack using SYN bit.\n\nSection 4.2 of RFC 5961 advises to send a Challenge ACK and drop\nincoming packet, instead of resetting the session.\n\nAdd a new SNMP counter to count number of challenge acks sent\nin response to SYN packets.\n(netstat -s | grep TCPSYNChallenge)\n\nRemove obsolete TCPAbortOnSyn, since we no longer abort a TCP session\nbecause of a SYN flag.\n\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nCc: Kiran Kumar Kella \u003ckkiran@broadcom.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "34fb350281ced2a72707a5c0064f69992d440edb",
      "tree": "91f806c64e65601adf09564a83b4c44f4db080be",
      "parents": [
        "c87b45599a4e0d8741abeb85d1d8d5f0c1fb13be"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "edumazet@google.com",
        "time": "Tue Jul 17 10:13:05 2012 +0200"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:07:14 2013 -0800"
      },
      "message": "tcp: implement RFC 5961 3.2\n\n[ Upstream commit 282f23c6ee343126156dd41218b22ece96d747e3 ]\n\nImplement the RFC 5691 mitigation against Blind\nReset attack using RST bit.\n\nIdea is to validate incoming RST sequence,\nto match RCV.NXT value, instead of previouly accepted\nwindow : (RCV.NXT \u003c\u003d SEG.SEQ \u003c RCV.NXT+RCV.WND)\n\nIf sequence is in window but not an exact match, send\na \"challenge ACK\", so that the other part can resend an\nRST with the appropriate sequence.\n\nAdd a new sysctl, tcp_challenge_ack_limit, to limit\nnumber of challenge ACK sent per second.\n\nAdd a new SNMP counter to count number of challenge acks sent.\n(netstat -s | grep TCPChallengeACK)\n\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nCc: Kiran Kumar Kella \u003ckkiran@broadcom.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "c87b45599a4e0d8741abeb85d1d8d5f0c1fb13be",
      "tree": "dc87094b0a76abb86f6856d824bd50bb3a26a138",
      "parents": [
        "c7078c2c5da80e387420795a5a0857b1cd711fc9"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "edumazet@google.com",
        "time": "Sun Jan 06 18:21:49 2013 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:07:14 2013 -0800"
      },
      "message": "tcp: fix MSG_SENDPAGE_NOTLAST logic\n\n[ Upstream commit ae62ca7b03217be5e74759dc6d7698c95df498b3 ]\n\ncommit 35f9c09fe9c72e (tcp: tcp_sendpages() should call tcp_push() once)\nadded an internal flag : MSG_SENDPAGE_NOTLAST meant to be set on all\nfrags but the last one for a splice() call.\n\nThe condition used to set the flag in pipe_to_sendpage() relied on\nsplice() user passing the exact number of bytes present in the pipe,\nor a smaller one.\n\nBut some programs pass an arbitrary high value, and the test fails.\n\nThe effect of this bug is a lack of tcp_push() at the end of a\nsplice(pipe -\u003e socket) call, and possibly very slow or erratic TCP\nsessions.\n\nWe should both test sd-\u003etotal_len and fact that another fragment\nis in the pipe (pipe-\u003enrbufs \u003e 1)\n\nMany thanks to Willy for providing very clear bug report, bisection\nand test programs.\n\nReported-by: Willy Tarreau \u003cw@1wt.eu\u003e\nBisected-by: Willy Tarreau \u003cw@1wt.eu\u003e\nTested-by: Willy Tarreau \u003cw@1wt.eu\u003e\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "c7078c2c5da80e387420795a5a0857b1cd711fc9",
      "tree": "02bb5384d076eac6a05edc3d441db0228abe337f",
      "parents": [
        "d46699a94ddf2dd4d83e986a759b64981b37fc5b"
      ],
      "author": {
        "name": "Stefan Hasko",
        "email": "hasko.stevo@gmail.com",
        "time": "Fri Dec 21 15:04:59 2012 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:07:14 2013 -0800"
      },
      "message": "net: sched: integer overflow fix\n\n[ Upstream commit d2fe85da52e89b8012ffad010ef352a964725d5f ]\n\nFixed integer overflow in function htb_dequeue\n\nSigned-off-by: Stefan Hasko \u003chasko.stevo@gmail.com\u003e\nAcked-by: Eric Dumazet \u003cedumazet@google.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "d46699a94ddf2dd4d83e986a759b64981b37fc5b",
      "tree": "c2de686ba7429ce5ac341c97ccdf673374c3f1be",
      "parents": [
        "6eec2413cb320bdd0139ba0db3888d27f746ea2b"
      ],
      "author": {
        "name": "Christoph Paasch",
        "email": "christoph.paasch@uclouvain.be",
        "time": "Fri Dec 14 04:07:58 2012 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:07:14 2013 -0800"
      },
      "message": "inet: Fix kmemleak in tcp_v4/6_syn_recv_sock and dccp_v4/6_request_recv_sock\n\n[ Upstream commit e337e24d6624e74a558aa69071e112a65f7b5758 ]\n\nIf in either of the above functions inet_csk_route_child_sock() or\n__inet_inherit_port() fails, the newsk will not be freed:\n\nunreferenced object 0xffff88022e8a92c0 (size 1592):\n  comm \"softirq\", pid 0, jiffies 4294946244 (age 726.160s)\n  hex dump (first 32 bytes):\n    0a 01 01 01 0a 01 01 02 00 00 00 00 a7 cc 16 00  ................\n    02 00 03 01 00 00 00 00 00 00 00 00 00 00 00 00  ................\n  backtrace:\n    [\u003cffffffff8153d190\u003e] kmemleak_alloc+0x21/0x3e\n    [\u003cffffffff810ab3e7\u003e] kmem_cache_alloc+0xb5/0xc5\n    [\u003cffffffff8149b65b\u003e] sk_prot_alloc.isra.53+0x2b/0xcd\n    [\u003cffffffff8149b784\u003e] sk_clone_lock+0x16/0x21e\n    [\u003cffffffff814d711a\u003e] inet_csk_clone_lock+0x10/0x7b\n    [\u003cffffffff814ebbc3\u003e] tcp_create_openreq_child+0x21/0x481\n    [\u003cffffffff814e8fa5\u003e] tcp_v4_syn_recv_sock+0x3a/0x23b\n    [\u003cffffffff814ec5ba\u003e] tcp_check_req+0x29f/0x416\n    [\u003cffffffff814e8e10\u003e] tcp_v4_do_rcv+0x161/0x2bc\n    [\u003cffffffff814eb917\u003e] tcp_v4_rcv+0x6c9/0x701\n    [\u003cffffffff814cea9f\u003e] ip_local_deliver_finish+0x70/0xc4\n    [\u003cffffffff814cec20\u003e] ip_local_deliver+0x4e/0x7f\n    [\u003cffffffff814ce9f8\u003e] ip_rcv_finish+0x1fc/0x233\n    [\u003cffffffff814cee68\u003e] ip_rcv+0x217/0x267\n    [\u003cffffffff814a7bbe\u003e] __netif_receive_skb+0x49e/0x553\n    [\u003cffffffff814a7cc3\u003e] netif_receive_skb+0x50/0x82\n\nThis happens, because sk_clone_lock initializes sk_refcnt to 2, and thus\na single sock_put() is not enough to free the memory. Additionally, things\nlike xfrm, memcg, cookie_values,... may have been initialized.\nWe have to free them properly.\n\nThis is fixed by forcing a call to tcp_done(), ending up in\ninet_csk_destroy_sock, doing the final sock_put(). tcp_done() is necessary,\nbecause it ends up doing all the cleanup on xfrm, memcg, cookie_values,\nxfrm,...\n\nBefore calling tcp_done, we have to set the socket to SOCK_DEAD, to\nforce it entering inet_csk_destroy_sock. To avoid the warning in\ninet_csk_destroy_sock, inet_num has to be set to 0.\nAs inet_csk_destroy_sock does a dec on orphan_count, we first have to\nincrease it.\n\nCalling tcp_done() allows us to remove the calls to\ntcp_clear_xmit_timer() and tcp_cleanup_congestion_control().\n\nA similar approach is taken for dccp by calling dccp_done().\n\nThis is in the kernel since 093d282321 (tproxy: fix hash locking issue\nwhen using port redirection in __inet_inherit_port()), thus since\nversion \u003e\u003d 2.6.37.\n\nSigned-off-by: Christoph Paasch \u003cchristoph.paasch@uclouvain.be\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "6eec2413cb320bdd0139ba0db3888d27f746ea2b",
      "tree": "10b2a223fa456da36a25132ac2a8a65917476f07",
      "parents": [
        "a9b876220838f045ab3c365f668477771e149c3c"
      ],
      "author": {
        "name": "Akinobu Mita",
        "email": "akinobu.mita@gmail.com",
        "time": "Wed Dec 26 02:32:10 2012 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:07:03 2013 -0800"
      },
      "message": "batman-adv: fix random jitter calculation\n\n[ Upstream commit 143cdd8f33909ff5a153e3f02048738c5964ba26 ]\n\nbatadv_iv_ogm_emit_send_time() attempts to calculates a random integer\nin the range of \u0027orig_interval +- BATADV_JITTER\u0027 by the below lines.\n\n        msecs \u003d atomic_read(\u0026bat_priv-\u003eorig_interval) - BATADV_JITTER;\n        msecs +\u003d (random32() % 2 * BATADV_JITTER);\n\nBut it actually gets \u0027orig_interval\u0027 or \u0027orig_interval - BATADV_JITTER\u0027\nbecause \u0027%\u0027 and \u0027*\u0027 have same precedence and associativity is\nleft-to-right.\n\nThis adds the parentheses at the appropriate position so that it matches\noriginal intension.\n\nSigned-off-by: Akinobu Mita \u003cakinobu.mita@gmail.com\u003e\nAcked-by: Antonio Quartulli \u003cordex@autistici.org\u003e\nCc: Marek Lindner \u003clindner_marek@yahoo.de\u003e\nCc: Simon Wunderlich \u003csiwu@hrz.tu-chemnitz.de\u003e\nCc: Antonio Quartulli \u003cordex@autistici.org\u003e\nCc: b.a.t.m.a.n@lists.open-mesh.org\nCc: \"David S. Miller\" \u003cdavem@davemloft.net\u003e\nCc: netdev@vger.kernel.org\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "a9b876220838f045ab3c365f668477771e149c3c",
      "tree": "b1fcc174f39844139baa71e3616f2a9dcb057f8d",
      "parents": [
        "af445c0d36202fe86bc50f0a1831c5661f5b1189"
      ],
      "author": {
        "name": "Dave Kleikamp",
        "email": "dave.kleikamp@oracle.com",
        "time": "Mon Dec 17 11:52:47 2012 -0600"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:59 2013 -0800"
      },
      "message": "sparc: huge_ptep_set_* functions need to call set_huge_pte_at()\n\n[ Upstream commit 6cb9c3697585c47977c42c5cc1b9fc49247ac530 ]\n\nModifying the huge pte\u0027s requires that all the underlying pte\u0027s be\nmodified.\n\nVersion 2: added missing flush_tlb_page()\n\nSigned-off-by: Dave Kleikamp \u003cdave.kleikamp@oracle.com\u003e\nCc: \"David S. Miller\" \u003cdavem@davemloft.net\u003e\nCc: sparclinux@vger.kernel.org\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "af445c0d36202fe86bc50f0a1831c5661f5b1189",
      "tree": "12cd3d6b57012b343f2d87fd0feac3b0c76ccf8c",
      "parents": [
        "cd924e960d3c2ae1654109b5b9e88cec334f7126"
      ],
      "author": {
        "name": "Andre Przywara",
        "email": "andre.przywara@amd.com",
        "time": "Wed Oct 31 17:20:50 2012 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:58 2013 -0800"
      },
      "message": "x86, amd: Disable way access filter on Piledriver CPUs\n\ncommit 2bbf0a1427c377350f001fbc6260995334739ad7 upstream.\n\nThe Way Access Filter in recent AMD CPUs may hurt the performance of\nsome workloads, caused by aliasing issues in the L1 cache.\nThis patch disables it on the affected CPUs.\n\nThe issue is similar to that one of last year:\nhttp://lkml.indiana.edu/hypermail/linux/kernel/1107.3/00041.html\nThis new patch does not replace the old one, we just need another\nquirk for newer CPUs.\n\nThe performance penalty without the patch depends on the\ncircumstances, but is a bit less than the last year\u0027s 3%.\n\nThe workloads affected would be those that access code from the same\nphysical page under different virtual addresses, so different\nprocesses using the same libraries with ASLR or multiple instances of\nPIE-binaries. The code needs to be accessed simultaneously from both\ncores of the same compute unit.\n\nMore details can be found here:\nhttp://developer.amd.com/Assets/SharedL1InstructionCacheonAMD15hCPU.pdf\n\nCPUs affected are anything with the core known as Piledriver.\nThat includes the new parts of the AMD A-Series (aka Trinity) and the\njust released new CPUs of the FX-Series (aka Vishera).\nThe model numbering is a bit odd here: FX CPUs have model 2,\nA-Series has model 10h, with possible extensions to 1Fh. Hence the\nrange of model ids.\n\nSigned-off-by: Andre Przywara \u003cosp@andrep.de\u003e\nLink: http://lkml.kernel.org/r/1351700450-9277-1-git-send-email-osp@andrep.de\nSigned-off-by: H. Peter Anvin \u003chpa@linux.intel.com\u003e\nSigned-off-by: CAI Qian \u003ccaiqian@redhat.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "cd924e960d3c2ae1654109b5b9e88cec334f7126",
      "tree": "ed7bec78c3e2930df0c86d44aae32d2c4dddb23f",
      "parents": [
        "475261dbbf5d85e1a298886385d859ada787ae1f"
      ],
      "author": {
        "name": "Tejun Heo",
        "email": "tj@kernel.org",
        "time": "Tue Oct 16 15:03:14 2012 -0700"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:58 2013 -0800"
      },
      "message": "freezer: add missing mb\u0027s to freezer_count() and freezer_should_skip()\n\ncommit dd67d32dbc5de299d70cc9e10c6c1e29ffa56b92 upstream.\n\nA task is considered frozen enough between freezer_do_not_count() and\nfreezer_count() and freezers use freezer_should_skip() to test this\ncondition.  This supposedly works because freezer_count() always calls\ntry_to_freezer() after clearing %PF_FREEZER_SKIP.\n\nHowever, there currently is nothing which guarantees that\nfreezer_count() sees %true freezing() after clearing %PF_FREEZER_SKIP\nwhen freezing is in progress, and vice-versa.  A task can escape the\nfreezing condition in effect by freezer_count() seeing !freezing() and\nfreezer_should_skip() seeing %PF_FREEZER_SKIP.\n\nThis patch adds smp_mb()\u0027s to freezer_count() and\nfreezer_should_skip() such that either %true freezing() is visible to\nfreezer_count() or !PF_FREEZER_SKIP is visible to\nfreezer_should_skip().\n\nSigned-off-by: Tejun Heo \u003ctj@kernel.org\u003e\nCc: Oleg Nesterov \u003coleg@redhat.com\u003e\nCc: Rafael J. Wysocki \u003crjw@sisk.pl\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "475261dbbf5d85e1a298886385d859ada787ae1f",
      "tree": "8f6505342bc36ca3d51798e65ea6d71cb4b10dc7",
      "parents": [
        "66f8b956aeeeea9e5b3024f860251687f13f9013"
      ],
      "author": {
        "name": "Tejun Heo",
        "email": "tj@kernel.org",
        "time": "Mon Nov 19 08:13:35 2012 -0800"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:58 2013 -0800"
      },
      "message": "cgroup: remove incorrect dget/dput() pair in cgroup_create_dir()\n\ncommit 175431635ec09b1d1bba04979b006b99e8305a83 upstream.\n\ncgroup_create_dir() does weird dancing with dentry refcnt.  On\nsuccess, it gets and then puts it achieving nothing.  On failure, it\nputs but there isn\u0027t no matching get anywhere leading to the following\noops if cgroup_create_file() fails for whatever reason.\n\n  ------------[ cut here ]------------\n  kernel BUG at /work/os/work/fs/dcache.c:552!\n  invalid opcode: 0000 [#1] PREEMPT SMP DEBUG_PAGEALLOC\n  Modules linked in:\n  CPU 2\n  Pid: 697, comm: mkdir Not tainted 3.7.0-rc4-work+ #3 Bochs Bochs\n  RIP: 0010:[\u003cffffffff811d9c0c\u003e]  [\u003cffffffff811d9c0c\u003e] dput+0x1dc/0x1e0\n  RSP: 0018:ffff88001a3ebef8  EFLAGS: 00010246\n  RAX: 0000000000000000 RBX: ffff88000e5b1ef8 RCX: 0000000000000403\n  RDX: 0000000000000303 RSI: 2000000000000000 RDI: ffff88000e5b1f58\n  RBP: ffff88001a3ebf18 R08: ffffffff82c76960 R09: 0000000000000001\n  R10: ffff880015022080 R11: ffd9bed70f48a041 R12: 00000000ffffffea\n  R13: 0000000000000001 R14: ffff88000e5b1f58 R15: 00007fff57656d60\n  FS:  00007ff05fcb3800(0000) GS:ffff88001fd00000(0000) knlGS:0000000000000000\n  CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n  CR2: 00000000004046f0 CR3: 000000001315f000 CR4: 00000000000006e0\n  DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n  DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400\n  Process mkdir (pid: 697, threadinfo ffff88001a3ea000, task ffff880015022080)\n  Stack:\n   ffff88001a3ebf48 00000000ffffffea 0000000000000001 0000000000000000\n   ffff88001a3ebf38 ffffffff811cc889 0000000000000001 ffff88000e5b1ef8\n   ffff88001a3ebf68 ffffffff811d1fc9 ffff8800198d7f18 ffff880019106ef8\n  Call Trace:\n   [\u003cffffffff811cc889\u003e] done_path_create+0x19/0x50\n   [\u003cffffffff811d1fc9\u003e] sys_mkdirat+0x59/0x80\n   [\u003cffffffff811d2009\u003e] sys_mkdir+0x19/0x20\n   [\u003cffffffff81be1e02\u003e] system_call_fastpath+0x16/0x1b\n  Code: 00 48 8d 90 18 01 00 00 48 89 93 c0 00 00 00 4c 89 a0 18 01 00 00 48 8b 83 a0 00 00 00 83 80 28 01 00 00 01 e8 e6 6f a0 00 eb 92 \u003c0f\u003e 0b 66 90 0f 1f 44 00 00 55 48 89 e5 41 57 41 56 49 89 fe 41\n  RIP  [\u003cffffffff811d9c0c\u003e] dput+0x1dc/0x1e0\n   RSP \u003cffff88001a3ebef8\u003e\n  ---[ end trace 1277bcfd9561ddb0 ]---\n\nFix it by dropping the unnecessary dget/dput() pair.\n\nSigned-off-by: Tejun Heo \u003ctj@kernel.org\u003e\nAcked-by: Li Zefan \u003clizefan@huawei.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "66f8b956aeeeea9e5b3024f860251687f13f9013",
      "tree": "d8251188001a93b7193404a311eb31700368ba39",
      "parents": [
        "4b2e61048c2c51882dc268dc2916a5b3bfab00ea"
      ],
      "author": {
        "name": "Russell Webb",
        "email": "russell.webb@linux.intel.com",
        "time": "Fri Nov 09 13:58:49 2012 -0800"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:58 2013 -0800"
      },
      "message": "xhci: Add Lynx Point LP to list of Intel switchable hosts\n\ncommit bb1e5dd7113d2fd178d3af9aca8f480ae0468edf upstream.\n\nLike Lynx Point, Lynx Point LP is also switchable.  See\n1c12443ab8eba71a658fae4572147e56d1f84f66 for more details.\n\nThis patch should be backported to stable kernels as old as 3.0,\nthat contain commit 69e848c2090aebba5698a1620604c7dccb448684\n\"Intel xhci: Support EHCI/xHCI port switching.\"\n\nSigned-off-by: Russell Webb \u003crussell.webb@linux.intel.com\u003e\nSigned-off-by: Sarah Sharp \u003csarah.a.sharp@linux.intel.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "4b2e61048c2c51882dc268dc2916a5b3bfab00ea",
      "tree": "3e7fbcb63d0cafd1c14274f0373fbe8337d7768a",
      "parents": [
        "a50afb91545b5a7e32a508b3eecaffe9538f018b"
      ],
      "author": {
        "name": "Alexis R. Cortes",
        "email": "alexis.cortes@ti.com",
        "time": "Thu Nov 08 16:59:27 2012 -0600"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:57 2013 -0800"
      },
      "message": "usb: host: xhci: Stricter conditional for Z1 system models for Compliance Mode Patch\n\ncommit b0e4e606ff6ff26da0f60826e75577b56ba4e463 upstream.\n\nThis minor patch creates a more stricter conditional for the Z1 sytems for applying\nthe Compliance Mode Patch, this to avoid the quirk to be applied to models that\ncontain a \"Z1\" in their dmi product string but are different from Z1 systems.\n\nThis patch should be backported to stable kernels as old as 3.2, that\ncontain the commit 71c731a296f1b08a3724bd1b514b64f1bda87a23 \"usb: host:\nxhci: Fix Compliance Mode on SN65LVPE502CP Hardware\"\n\nSigned-off-by: Alexis R. Cortes \u003calexis.cortes@ti.com\u003e\nSigned-off-by: Sarah Sharp \u003csarah.a.sharp@linux.intel.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "a50afb91545b5a7e32a508b3eecaffe9538f018b",
      "tree": "83e9d65b28baa7231201034f4780fd315ec1021b",
      "parents": [
        "ceb58b9ffa579690f6124fd49dc1734071544f50"
      ],
      "author": {
        "name": "Julius Werner",
        "email": "jwerner@chromium.org",
        "time": "Thu Nov 01 12:47:59 2012 -0700"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:57 2013 -0800"
      },
      "message": "xhci: fix null-pointer dereference when destroying half-built segment rings\n\ncommit 68e5254adb88bede68285f11fb442a4d34fb550c upstream.\n\nxhci_alloc_segments_for_ring() builds a list of xhci_segments and links\nthe tail to head at the end (forming a ring). When it bails out for OOM\nreasons half-way through, it tries to destroy its half-built list with\nxhci_free_segments_for_ring(), even though it is not a ring yet. This\ncauses a null-pointer dereference upon hitting the last element.\n\nFurthermore, one of its callers (xhci_ring_alloc()) mistakenly believes\nthe output parameters to be valid upon this kind of OOM failure, and\ncalls xhci_ring_free() on them. Since the (incomplete) list/ring should\nalready be destroyed in that case, this would lead to a use after free.\n\nThis patch fixes those issues by having xhci_alloc_segments_for_ring()\ndestroy its half-built, non-circular list manually and destroying the\ninvalid struct xhci_ring in xhci_ring_alloc() with a plain kfree().\n\nThis patch should be backported to kernels as old as 2.6.31, that\ncontains the commit 0ebbab37422315a5d0cb29792271085bafdf38c0 \"USB: xhci:\nRing allocation and initialization.\"\n\nA separate patch will need to be developed for kernels older than 3.4,\nsince the ring allocation code was refactored in that kernel.\n\nSigned-off-by: Julius Werner \u003cjwerner@chromium.org\u003e\nSigned-off-by: Sarah Sharp \u003csarah.a.sharp@linux.intel.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "ceb58b9ffa579690f6124fd49dc1734071544f50",
      "tree": "fb9c1aa1efa065ba77ae17aec187e9be645a0f2f",
      "parents": [
        "363cfe8903364aed741cc5c7f31610581a135be8"
      ],
      "author": {
        "name": "Sarah Sharp",
        "email": "sarah.a.sharp@linux.intel.com",
        "time": "Thu Oct 25 15:56:40 2012 -0700"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:57 2013 -0800"
      },
      "message": "xHCI: Fix TD Size calculation on 1.0 hosts.\n\ncommit 4525c0a10dff7ad3669763c28016c7daffc3900e upstream.\n\nThe xHCI 1.0 specification made a change to the TD Size field in TRBs.\nThe value is now the number of packets that remain to be sent in the TD,\nnot including this TRB.  The TD Size value for the last TRB in a TD must\nalways be zero.\n\nThe xHCI function xhci_v1_0_td_remainder() attempts to calculate this,\nbut it gets it wrong.  First, it erroneously reuses the old\nxhci_td_remainder function, which will right shift the value by 10.  The\nxHCI 1.0 spec as of June 2011 says nothing about right shifting by 10.\nSecond, it does not set the TD size for the last TRB in a TD to zero.\n\nThird, it uses roundup instead of DIV_ROUND_UP.  The total packet count\nis supposed to be the total number of bytes in this TD, divided by the\nmax packet size, rounded up.  DIV_ROUND_UP is the right function to use\nin that case.\n\nWith the old code, a TD on an endpoint with max packet size 1024 would\nbe set up like so:\nTRB 1, TRB length \u003d 600 bytes, TD size \u003d 0\nTRB 1, TRB length \u003d 200 bytes, TD size \u003d 0\nTRB 1, TRB length \u003d 100 bytes, TD size \u003d 0\n\nWith the new code, the TD would be set up like this:\nTRB 1, TRB length \u003d 600 bytes, TD size \u003d 1\nTRB 1, TRB length \u003d 200 bytes, TD size \u003d 1\nTRB 1, TRB length \u003d 100 bytes, TD size \u003d 0\n\nThis commit should be backported to kernels as old as 3.0, that contain\nthe commit 4da6e6f247a2601ab9f1e63424e4d944ed4124f3 \"xhci 1.0: Update TD\nsize field format.\"\n\nSigned-off-by: Sarah Sharp \u003csarah.a.sharp@linux.intel.com\u003e\nReported-by: Chintan Mehta \u003cchintan.mehta@sibridgetech.com\u003e\nReported-by: Shimmer Huang \u003cshimmering.h@gmail.com\u003e\nTested-by: Bhavik Kothari \u003cbhavik.kothari@sibridgetech.com\u003e\nTested-by: Shimmer Huang \u003cshimmering.h@gmail.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "363cfe8903364aed741cc5c7f31610581a135be8",
      "tree": "e7cf152bdc9b0e2765cc495faa7ed6535791be10",
      "parents": [
        "9044dea3b603b7f0246aa7bed4039df3666fc611"
      ],
      "author": {
        "name": "Sarah Sharp",
        "email": "sarah.a.sharp@linux.intel.com",
        "time": "Thu Oct 25 13:44:12 2012 -0700"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:57 2013 -0800"
      },
      "message": "xhci: Fix conditional check in bandwidth calculation.\n\ncommit 392a07ae3316f2b90b39ce41e66d6f6b5c95de90 upstream.\n\nDavid reports that at drivers/usb/host/xhci.c:2257:\n\nstatic bool xhci_is_sync_in_ep(unsigned int ep_type)\n{\n    return (ep_type \u003d\u003d ISOC_IN_EP || ep_type !\u003d INT_IN_EP);\n}\n\nThe static analyser cppcheck says\n\n[linux-3.7-rc2/drivers/usb/host/xhci.c:2257]: (style) Redundant condition: If ep_type \u003d\u003d 5, the comparison ep_type !\u003d 7 is always true.\n\nMaybe the original programmer intention was something like\n\nstatic bool xhci_is_sync_in_ep(unsigned int ep_type)\n{\n    return (ep_type \u003d\u003d ISOC_IN_EP || ep_type \u003d\u003d INT_IN_EP);\n}\n\nFix this.\n\nThis patch should be backported to stable kernels as old as 3.2, that\ncontain the commit 2b69899934c63b7b9432568584fb4c4a2924f40c \"xhci: USB\n3.0 BW checking.\"\n\nSigned-off-by: Sarah Sharp \u003csarah.a.sharp@linux.intel.com\u003e\nReported-by: David Binderman \u003cdcb314@hotmail.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "9044dea3b603b7f0246aa7bed4039df3666fc611",
      "tree": "6cde32ccc68a34d9f2b3f0415cc2d9af7fe35ce8",
      "parents": [
        "09c4161c8a1fe8900561029a5d1dce8887231afd"
      ],
      "author": {
        "name": "Sergei Shtylyov",
        "email": "sshtylyov@ru.mvista.com",
        "time": "Mon Nov 05 22:26:40 2012 +0300"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:57 2013 -0800"
      },
      "message": "usb: musb: cppi_dma: export cppi_interrupt()\n\ncommit 8b416b0b25d5d8ddb3a91c1d20e1373582c50405 upstream.\n\nNow that DaVinci glue layer can be modular, we must export cppi_interrupt()\nthat it may call...\n\nSigned-off-by: Sergei Shtylyov \u003csshtylyov@ru.mvista.com\u003e\nSigned-off-by: Felipe Balbi \u003cbalbi@ti.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "09c4161c8a1fe8900561029a5d1dce8887231afd",
      "tree": "dde521f62d7a805dfc0ef269bc031e6b46d9af6a",
      "parents": [
        "1a37441ae4ad38d98c39b349137c0fb7f76b32ad"
      ],
      "author": {
        "name": "Thomas Gleixner",
        "email": "tglx@linutronix.de",
        "time": "Sat Nov 03 11:52:09 2012 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:56 2013 -0800"
      },
      "message": "genirq: Always force thread affinity\n\ncommit 04aa530ec04f61875b99c12721162e2964e3318c upstream.\n\nSankara reported that the genirq core code fails to adjust the\naffinity of an interrupt thread in several cases:\n\n 1) On request/setup_irq() the call to setup_affinity() happens before\n    the new action is registered, so the new thread is not notified.\n\n 2) For secondary shared interrupts nothing notifies the new thread to\n    change its affinity.\n\n 3) Interrupts which have the IRQ_NO_BALANCE flag set are not moving\n    the thread either.\n\nFix this by setting the thread affinity flag right on thread creation\ntime. This ensures that under all circumstances the thread moves to\nthe right place. Requires a check in irq_thread_check_affinity for an\nexisting affinity mask (CONFIG_CPU_MASK_OFFSTACK\u003dy)\n\nReported-and-tested-by: Sankara Muthukrishnan \u003csankara.m@gmail.com\u003e\nLink: http://lkml.kernel.org/r/alpine.LFD.2.02.1209041738200.2754@ionos\nSigned-off-by: Thomas Gleixner \u003ctglx@linutronix.de\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "1a37441ae4ad38d98c39b349137c0fb7f76b32ad",
      "tree": "afd9e849dc5ede014da96143ff42eacad3ef6b99",
      "parents": [
        "c815c83dfd1aef11d4197dc46b21a2471b81af2c"
      ],
      "author": {
        "name": "Christophe TORDEUX",
        "email": "christophe@tordeux.net",
        "time": "Mon Dec 24 09:20:40 2012 -0800"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:56 2013 -0800"
      },
      "message": "Input: sentelic - only report position of first finger as ST coordinates\n\ncommit a25461659050b913e114d282bf58823682eb56b6 upstream.\n\nReport only the position of the first finger as absolute non-MT coordinates,\ninstead of reporting both fingers alternatively. Actual MT events are\nunaffected.\n\nThis fixes horizontal and improves vertical scrolling with the touchpad.\n\nSigned-off-by: Christophe TORDEUX \u003cchristophe@tordeux.net\u003e\nSigned-off-by: Dmitry Torokhov \u003cdmitry.torokhov@gmail.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "c815c83dfd1aef11d4197dc46b21a2471b81af2c",
      "tree": "2a27444c361e8a40a3b4828091b9cbb289e242dd",
      "parents": [
        "042cf2fb1d2ac4b4b27b2ccc4ac317a2f53df3c3"
      ],
      "author": {
        "name": "Peter Popovec",
        "email": "popovec@oko.fei.tuke.sk",
        "time": "Fri Dec 14 22:57:25 2012 -0800"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:56 2013 -0800"
      },
      "message": "Input: walkera0701 - fix crash on startup\n\ncommit a455e2985f57e2a71566bb8850094af38b2c932d upstream.\n\nThe driver\u0027s timer must be set up before enabling IRQ handler, otherwise\nbad things may happen.\n\nReported-and-tested-by: Fengguang Wu \u003cfengguang.wu@intel.com\u003e\nSigned-off-by: Peter Popovec \u003cpopovec@fei.tuke.sk\u003e\nSigned-off-by: Dmitry Torokhov \u003cdmitry.torokhov@gmail.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "042cf2fb1d2ac4b4b27b2ccc4ac317a2f53df3c3",
      "tree": "bbce5817e153568d44ff0c927c0461bf57deabe2",
      "parents": [
        "59d6ce4370c17dbd3db789740a036f158e8ba9a0"
      ],
      "author": {
        "name": "Xi Wang",
        "email": "xi.wang@gmail.com",
        "time": "Fri Jan 04 03:22:57 2013 -0500"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:56 2013 -0800"
      },
      "message": "nfs: fix null checking in nfs_get_option_str()\n\ncommit e25fbe380c4e3c09afa98bcdcd9d3921443adab8 upstream.\n\nThe following null pointer check is broken.\n\n\t*option \u003d match_strdup(args);\n\treturn !option;\n\nThe pointer `option\u0027 must be non-null, and thus `!option\u0027 is always false.\nUse `!*option\u0027 instead.\n\nThe bug was introduced in commit c5cb09b6f8 (\"Cleanup: Factor out some\ncut-and-paste code.\").\n\nSigned-off-by: Xi Wang \u003cxi.wang@gmail.com\u003e\nSigned-off-by: Trond Myklebust \u003cTrond.Myklebust@netapp.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "59d6ce4370c17dbd3db789740a036f158e8ba9a0",
      "tree": "24691f3b5974f964c13088c0c51acf522b8f6e18",
      "parents": [
        "4cbb3d03810a50cb5d9eab0a6cfe3152a65911f2"
      ],
      "author": {
        "name": "Neil Brown",
        "email": "neilb@suse.de",
        "time": "Fri Dec 07 15:40:55 2012 -0500"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:55 2013 -0800"
      },
      "message": "nfsd: avoid permission checks on EXCLUSIVE_CREATE replay\n\ncommit 7007c90fb9fef593b4aeaeee57e6a6754276c97c upstream.\n\nWith NFSv4, if we create a file then open it we explicit avoid checking\nthe permissions on the file during the open because the fact that we\ncreated it ensures we should be allow to open it (the create and the\nopen should appear to be a single operation).\n\nHowever if the reply to an EXCLUSIVE create gets lots and the client\nresends the create, the current code will perform the permission check -\nbecause it doesn\u0027t realise that it did the open already..\n\nThis patch should fix this.\n\nNote that I haven\u0027t actually seen this cause a problem.  I was just\nlooking at the code trying to figure out a different EXCLUSIVE open\nrelated issue, and this looked wrong.\n\n(Fix confirmed with pynfs 4.0 test OPEN4--bfields)\n\nSigned-off-by: NeilBrown \u003cneilb@suse.de\u003e\n[bfields: use OWNER_OVERRIDE and update for 4.1]\nSigned-off-by: J. Bruce Fields \u003cbfields@redhat.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "4cbb3d03810a50cb5d9eab0a6cfe3152a65911f2",
      "tree": "7dfbc5a2a91e1940a5a30302d654755ea46bf3cb",
      "parents": [
        "12c93e196764a2092f35b30a1e924a5071f164ee"
      ],
      "author": {
        "name": "J. Bruce Fields",
        "email": "bfields@redhat.com",
        "time": "Tue Dec 04 18:25:10 2012 -0500"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:55 2013 -0800"
      },
      "message": "nfsd4: fix oops on unusual readlike compound\n\ncommit d5f50b0c290431c65377c4afa1c764e2c3fe5305 upstream.\n\nIf the argument and reply together exceed the maximum payload size, then\na reply with a read-like operation can overlow the rq_pages array.\n\nSigned-off-by: J. Bruce Fields \u003cbfields@redhat.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "12c93e196764a2092f35b30a1e924a5071f164ee",
      "tree": "98380f00492fc6b1cae4670aba007b60339e86c0",
      "parents": [
        "aa8dc4af9a1ed18d71da58e883bb8260ba47afb5"
      ],
      "author": {
        "name": "J. Bruce Fields",
        "email": "bfields@redhat.com",
        "time": "Fri Nov 16 15:22:43 2012 -0500"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:55 2013 -0800"
      },
      "message": "nfsd: fix v4 reply caching\n\ncommit 57d276d71aef7d8305ff002a070cb98deb2edced upstream.\n\nVery embarassing: 1091006c5eb15cba56785bd5b498a8d0b9546903 \"nfsd: turn\non reply cache for NFSv4\" missed a line, effectively leaving the reply\ncache off in the v4 case.  I thought I\u0027d tested that, but I guess not.\n\nThis time, wrote a pynfs test to confirm it works.\n\nSigned-off-by: J. Bruce Fields \u003cbfields@redhat.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "aa8dc4af9a1ed18d71da58e883bb8260ba47afb5",
      "tree": "ee3c657f408d1f39f31e19bef68bca4edc51f481",
      "parents": [
        "0d965378563d9e73e52b11fcd8576a90f071b2af"
      ],
      "author": {
        "name": "Yanchuan Nian",
        "email": "ycnian@gmail.com",
        "time": "Wed Oct 24 14:44:19 2012 +0800"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:55 2013 -0800"
      },
      "message": "nfs: fix wrong object type in lockowner_slab\n\ncommit 3c40794b2dd0f355ef4e6bf8d85af5dcd7da7ece upstream.\n\nThe object type in the cache of lockowner_slab is wrong, and it is\nbetter to fix it.\n\nSigned-off-by: Yanchuan Nian \u003cycnian@gmail.com\u003e\nSigned-off-by: J. Bruce Fields \u003cbfields@redhat.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "0d965378563d9e73e52b11fcd8576a90f071b2af",
      "tree": "0b6e60be40a37b8b48c3af416a8c1d2e449970f6",
      "parents": [
        "1627e18aed860a61cc740e9ec9883c63059ae2a3"
      ],
      "author": {
        "name": "Trond Myklebust",
        "email": "Trond.Myklebust@netapp.com",
        "time": "Fri Dec 14 16:38:46 2012 -0500"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:54 2013 -0800"
      },
      "message": "NFS: Fix calls to drop_nlink()\n\ncommit 1f018458b30b0d5c535c94e577aa0acbb92e1395 upstream.\n\nIt is almost always wrong for NFS to call drop_nlink() after removing a\nfile. What we really want is to mark the inode\u0027s attributes for\nrevalidation, and we want to ensure that the VFS drops it if we\u0027re\nreasonably sure that this is the final unlink().\nDo the former using the usual cache validity flags, and the latter\nby testing if inode-\u003ei_nlink \u003d\u003d 1, and clearing it in that case.\n\nThis also fixes the following warning reported by Neil Brown and\nJeff Layton (among others).\n\n[634155.004438] WARNING:\nat /home/abuild/rpmbuild/BUILD/kernel-desktop-3.5.0/lin [634155.004442]\nHardware name: Latitude E6510 [634155.004577]  crc_itu_t crc32c_intel\nsnd_hwdep snd_pcm snd_timer snd soundcor [634155.004609] Pid: 13402, comm:\nbash Tainted: G        W    3.5.0-36-desktop # [634155.004611] Call Trace:\n[634155.004630]  [\u003cffffffff8100444a\u003e] dump_trace+0xaa/0x2b0\n[634155.004641]  [\u003cffffffff815a23dc\u003e] dump_stack+0x69/0x6f\n[634155.004653]  [\u003cffffffff81041a0b\u003e] warn_slowpath_common+0x7b/0xc0\n[634155.004662]  [\u003cffffffff811832e4\u003e] drop_nlink+0x34/0x40\n[634155.004687]  [\u003cffffffffa05bb6c3\u003e] nfs_dentry_iput+0x33/0x70 [nfs]\n[634155.004714]  [\u003cffffffff8118049e\u003e] dput+0x12e/0x230\n[634155.004726]  [\u003cffffffff8116b230\u003e] __fput+0x170/0x230\n[634155.004735]  [\u003cffffffff81167c0f\u003e] filp_close+0x5f/0x90\n[634155.004743]  [\u003cffffffff81167cd7\u003e] sys_close+0x97/0x100\n[634155.004754]  [\u003cffffffff815c3b39\u003e] system_call_fastpath+0x16/0x1b\n[634155.004767]  [\u003c00007f2a73a0d110\u003e] 0x7f2a73a0d10f\n\nSigned-off-by: Trond Myklebust \u003cTrond.Myklebust@netapp.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "1627e18aed860a61cc740e9ec9883c63059ae2a3",
      "tree": "7bb27c280eeb8bed2bfe1c6e5bf98aa7eed6d6de",
      "parents": [
        "d1967aac70c3eaf8f93710035b313904deabf6a9"
      ],
      "author": {
        "name": "NeilBrown",
        "email": "neilb@suse.de",
        "time": "Thu Dec 13 15:14:36 2012 +1100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:54 2013 -0800"
      },
      "message": "NFS: avoid NULL dereference in nfs_destroy_server\n\ncommit f259613a1e4b44a0cf85a5dafd931be96ee7c9e5 upstream.\n\nIn rare circumstances, nfs_clone_server() of a v2 or v3 server can get\nan error between setting server-\u003edestory (to nfs_destroy_server), and\ncalling nfs_start_lockd (which will set server-\u003enlm_host).\n\nIf this happens, nfs_clone_server will call nfs_free_server which\nwill call nfs_destroy_server and thence nlmclnt_done(NULL).  This\ncauses the NULL to be dereferenced.\n\nSo add a guard to only call nlmclnt_done() if -\u003enlm_host is not NULL.\n\nThe other guards there are irrelevant as nlm_host can only be non-NULL\nif one of these flags are set - so remove those tests.  (Thanks to Trond\nfor this suggestion).\n\nThis is suitable for any stable kernel since 2.6.25.\n\nSigned-off-by: NeilBrown \u003cneilb@suse.de\u003e\nSigned-off-by: Trond Myklebust \u003cTrond.Myklebust@netapp.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "d1967aac70c3eaf8f93710035b313904deabf6a9",
      "tree": "320969118322e7a56bb293c0a89e228c3ec7807d",
      "parents": [
        "eb9422b448fdd814ca566c0509f72dc41971ba6b"
      ],
      "author": {
        "name": "Bryan Schumaker",
        "email": "bjschuma@netapp.com",
        "time": "Mon Nov 12 16:55:38 2012 -0500"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:54 2013 -0800"
      },
      "message": "NFS: Add sequence_priviliged_ops for nfs4_proc_sequence()\n\ncommit 6bdb5f213c4344324f600dde885f25768fbd14db upstream.\n\nIf I mount an NFS v4.1 server to a single client multiple times and then\nrun xfstests over each mountpoint I usually get the client into a state\nwhere recovery deadlocks.  The server informs the client of a\ncb_path_down sequence error, the client then does a\nbind_connection_to_session and checks the status of the lease.\n\nI found that bind_connection_to_session sets the NFS4_SESSION_DRAINING\nflag on the client, but this flag is never unset before\nnfs4_check_lease() reaches nfs4_proc_sequence().  This causes the client\nto deadlock, halting all NFS activity to the server.  nfs4_proc_sequence()\nis only called by the state manager, so I can change it to run in privileged\nmode to bypass the NFS4_SESSION_DRAINING check and avoid the deadlock.\n\nSigned-off-by: Bryan Schumaker \u003cbjschuma@netapp.com\u003e\nSigned-off-by: Trond Myklebust \u003cTrond.Myklebust@netapp.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "eb9422b448fdd814ca566c0509f72dc41971ba6b",
      "tree": "16964a90703cb326d24cf518e24c50874a6f6343",
      "parents": [
        "dc2306834bff03132beb1f18d7a13b6e5080e488"
      ],
      "author": {
        "name": "Rafael J. Wysocki",
        "email": "rafael.j.wysocki@intel.com",
        "time": "Fri Jan 04 23:00:54 2013 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:54 2013 -0800"
      },
      "message": "ACPI / scan: Do not use dummy HID for system bus ACPI nodes\n\ncommit 4f5f64cf0cc916220aaa055992e31195470cfe37 upstream.\n\nAt one point acpi_device_set_id() checks if acpi_device_hid(device)\nreturns NULL, but that never happens, so system bus devices with an\nempty list of PNP IDs are given the dummy HID (\"device\") instead of\nthe \"system bus HID\" (\"LNXSYBUS\").  Fix the code to use the right\ncheck.\n\nSigned-off-by: Rafael J. Wysocki \u003crafael.j.wysocki@intel.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "dc2306834bff03132beb1f18d7a13b6e5080e488",
      "tree": "127f89dbf882554385dd20e00bdc4b1deccba143",
      "parents": [
        "c96158c87f8f3bc41ff6e1343c680a10fb747d31"
      ],
      "author": {
        "name": "Zhang Rui",
        "email": "rui.zhang@intel.com",
        "time": "Fri Nov 30 12:57:03 2012 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:54 2013 -0800"
      },
      "message": "ACPI: do acpisleep dmi check when CONFIG_ACPI_SLEEP is set\n\ncommit 0ac1b1d7b7424cd6f129b5454b504b3cae746f0e upstream.\n\nThe current acpisleep DMI checks only run when CONFIG_SUSPEND is set.\nAnd this may break hibernation on some platforms when CONFIG_SUSPEND\nis cleared.\n\nMove acpisleep DMI check into #ifdef CONFIG_ACPI_SLEEP instead.\n\n[rjw: Added acpi_sleep_dmi_check() and rebased on top of earlier\n patches adding entries to acpisleep_dmi_table[].]\nReferences: https://bugzilla.kernel.org/show_bug.cgi?id\u003d45921\nSigned-off-by: Zhang Rui \u003crui.zhang@intel.com\u003e\nSigned-off-by: Rafael J. Wysocki \u003crafael.j.wysocki@intel.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "c96158c87f8f3bc41ff6e1343c680a10fb747d31",
      "tree": "71c6e0c49acbe49c3c2bc62a68044f2a82074d45",
      "parents": [
        "e7a4b0efe62e56a0acc81d16091c6efc2a282be8"
      ],
      "author": {
        "name": "Sebastian Andrzej Siewior",
        "email": "bigeasy@linutronix.de",
        "time": "Mon Oct 22 22:15:00 2012 +0200"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:53 2013 -0800"
      },
      "message": "usb: gadget: network: fix bind() error path\n\ncommit e79cc615a9bb44da72c499ccfa2c9c4bbea3aa84 upstream.\n\nI think this is wrong since 72c973dd (\"usb: gadget: add\nusb_endpoint_descriptor to struct usb_ep\"). If we fail to allocate an ep\nor bail out early we shouldn\u0027t check for the descriptor which is\nassigned at ep_enable() time.\n\nSigned-off-by: Sebastian Andrzej Siewior \u003cbigeasy@linutronix.de\u003e\nCc: Tatyana Brokhman \u003ctlinder@codeaurora.org\u003e\nSigned-off-by: Felipe Balbi \u003cbalbi@ti.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "e7a4b0efe62e56a0acc81d16091c6efc2a282be8",
      "tree": "d017b07243814bb0c0ea33db4b879e6c0e1ef308",
      "parents": [
        "bb355e4833e30947197b58c8886dff40a5f6ee50"
      ],
      "author": {
        "name": "Sebastian Andrzej Siewior",
        "email": "bigeasy@linutronix.de",
        "time": "Mon Oct 22 22:15:05 2012 +0200"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:53 2013 -0800"
      },
      "message": "usb: gadget: uvc: fix error path in uvc_function_bind()\n\ncommit 0f9df939385527049c8062a099fbfa1479fe7ce0 upstream.\n\nThe \"video-\u003eminor \u003d -1\" assigment is done in V4L2 by\nvideo_register_device() so it is removed here.\nNow. uvc_function_bind() calls in error case uvc_function_unbind() for\ncleanup. The problem is that uvc_function_unbind() frees the uvc struct\nand uvc_bind_config() does as well in error case of usb_add_function().\nRemoving kfree() in usb_add_function() would make the patch smaller but\nit would look odd because the new allocated memory is not cleaned up.\nHowever it is not guaranteed that if we call usb_add_function() we also\nget to the bind function.\nTherefore the patch extracts the conditional cleanup from\nuvc_function_unbind() applies to uvc_function_bind().\nuvc_function_unbind() now contains only the complete cleanup which is\nrequired once everything has been registrated.\n\nSigned-off-by: Sebastian Andrzej Siewior \u003cbigeasy@linutronix.de\u003e\nCc: Laurent Pinchart \u003claurent.pinchart@ideasonboard.com\u003e\nCc: Bhupesh Sharma \u003cbhupesh.sharma@st.com\u003e\nSigned-off-by: Felipe Balbi \u003cbalbi@ti.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "bb355e4833e30947197b58c8886dff40a5f6ee50",
      "tree": "c1ae8d12bb39fad94ea0ae2bcb1051a430970fff",
      "parents": [
        "9784404f31f7001186c5fc1f8e4a3c8091711dfa"
      ],
      "author": {
        "name": "Sebastian Andrzej Siewior",
        "email": "bigeasy@linutronix.de",
        "time": "Mon Oct 22 22:15:04 2012 +0200"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:53 2013 -0800"
      },
      "message": "usb: gadget: phonet: free requests in pn_bind()\u0027s error path\n\ncommit d0eca719dd11ad0619e8dd6a1f3eceb95b0216dd upstream.\n\nSigned-off-by: Sebastian Andrzej Siewior \u003cbigeasy@linutronix.de\u003e\nSigned-off-by: Felipe Balbi \u003cbalbi@ti.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "9784404f31f7001186c5fc1f8e4a3c8091711dfa",
      "tree": "d3e5daf986a77a32863175aac5979314c779872b",
      "parents": [
        "44c818b94f8b3d3ad173ef9556414944e6da6efb"
      ],
      "author": {
        "name": "Sebastian Andrzej Siewior",
        "email": "bigeasy@linutronix.de",
        "time": "Mon Oct 22 22:15:02 2012 +0200"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:53 2013 -0800"
      },
      "message": "usb: gadget: midi: free hs descriptors\n\ncommit d185039f7982eb82cf8d03b6fb6689587ca5af24 upstream.\n\nThe HS descriptors are only created if HS is supported by the UDC but we\nnever free them.\n\nSigned-off-by: Sebastian Andrzej Siewior \u003cbigeasy@linutronix.de\u003e\nSigned-off-by: Felipe Balbi \u003cbalbi@ti.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "44c818b94f8b3d3ad173ef9556414944e6da6efb",
      "tree": "d429dee9bcf68b55ae7df6528c03e7e94eec9fd1",
      "parents": [
        "0e70111a128bd15f7ff90186deca1b6306a793e6"
      ],
      "author": {
        "name": "Christian Lamparter",
        "email": "chunkeey@googlemail.com",
        "time": "Thu Dec 27 15:18:20 2012 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:52 2013 -0800"
      },
      "message": "p54usb: add USBIDs for two more p54usb devices\n\ncommit 4010fe21a315b4223c25376714c6a2b61b722e5c upstream.\n\nThis patch adds USBIDs for:\n\t- DrayTek Vigor 530\n\t- Zoom 4410a\n\nIt also adds a note about Gemtek WUBI-100GW\nand SparkLAN WL-682 USBID conflict [WUBI-100GW\nis a ISL3886+NET2280 (LM86 firmare) solution,\nwhereas WL-682 is a ISL3887 (LM87 firmware)]\ndevice.\n\nSource: \u003chttp://www.wikidevi.com/wiki/Intersil/p54/usb/windows\u003e\n\nSigned-off-by: Christian Lamparter \u003cchunkeey@googlemail.com\u003e\nSigned-off-by: John W. Linville \u003clinville@tuxdriver.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "0e70111a128bd15f7ff90186deca1b6306a793e6",
      "tree": "c52a2ca87105f37a25e636114f5147a82133000b",
      "parents": [
        "a86cd75b2fd681c71dd4a04877bc62151648e8c0"
      ],
      "author": {
        "name": "Tomasz Guszkowski",
        "email": "tsg@o2.pl",
        "time": "Sat Dec 22 18:30:01 2012 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:51 2013 -0800"
      },
      "message": "p54usb: add USB ID for T-Com Sinus 154 data II\n\ncommit 3194b7fcdf6caea338b5d2c72d76fed80437649c upstream.\n\nAdded USB ID for T-Com Sinus 154 data II.\n\nSigned-off-by: Tomasz Guszkowski \u003ctsg@o2.pl\u003e\nAcked-by: Christian Lamparter \u003cchunkeey@googlemail.com\u003e\nSigned-off-by: John W. Linville \u003clinville@tuxdriver.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "a86cd75b2fd681c71dd4a04877bc62151648e8c0",
      "tree": "5f8314c8f9c8ccc9049f9abd57a1f039cccecb0d",
      "parents": [
        "73396089a501bdaa98a70efbd358c29daa7af0d9"
      ],
      "author": {
        "name": "Jussi Kivilinna",
        "email": "jussi.kivilinna@mbnet.fi",
        "time": "Thu Dec 20 16:24:43 2012 +0200"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:50 2013 -0800"
      },
      "message": "rtlwifi: fix incorrect use of usb_alloc_coherent with usb_control_msg\n\ncommit 4c3de5920c486b8eefa6187ee6a181864c161100 upstream.\n\nIncorrect use of usb_alloc_coherent memory as input buffer to usb_control_msg\ncan cause problems in arch DMA code, for example kernel BUG at\n\u0027arch/arm/include/asm/dma-mapping.h:321\u0027 on ARM (linux-3.4).\n\nChange _usb_writeN_sync use kmalloc\u0027d buffer instead.\n\nSigned-off-by: Jussi Kivilinna \u003cjussi.kivilinna@mbnet.fi\u003e\nAcked-by: Larry Finger \u003cLarry.Finger@lwfinger.net\u003e\nSigned-off-by: John W. Linville \u003clinville@tuxdriver.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "73396089a501bdaa98a70efbd358c29daa7af0d9",
      "tree": "46c6518f2b15f80301124b9740bc11f30476d118",
      "parents": [
        "37cb3a0366a60bca8f0bb4123639404c36402f70"
      ],
      "author": {
        "name": "Takashi Iwai",
        "email": "tiwai@suse.de",
        "time": "Thu Dec 13 14:33:42 2012 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:50 2013 -0800"
      },
      "message": "ALSA: hda - Fix pin configuration of HP Pavilion dv7\n\ncommit 8ae5865ec77c22462c736846a0679947a6953548 upstream.\n\nFix the quirk entry for HP Pavilion dv7 in order to make the bass\nspeaker working.\n\nReported-and-tested-by: Tomas Pospisek \u003ctpo2@sourcepole.ch\u003e\nSigned-off-by: Takashi Iwai \u003ctiwai@suse.de\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "37cb3a0366a60bca8f0bb4123639404c36402f70",
      "tree": "5894ee3175ebae6c9d24684b4c649dfa2a4ac5e8",
      "parents": [
        "740ccbaa57110e49f2296c4c610d745baaecc530"
      ],
      "author": {
        "name": "Takashi Iwai",
        "email": "tiwai@suse.de",
        "time": "Mon Dec 17 20:06:49 2012 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:49 2013 -0800"
      },
      "message": "ALSA: hda - Fix the wrong pincaps set in ALC861VD dallas/hp fixup\n\ncommit b78562b10fa66175e30b76073e32a0ad8d92aa83 upstream.\n\nThe workaround to force VREF50 for dallas/hp model with ALC861VD\nwas introduced in commit 8fdcb6fe4204bdb4c6991652717ab5063751414e,\nbut it contained wrong pincap override bits.\n\nThis patch fixes to exclude VREF80 pincap bit correctly.\n\nSigned-off-by: Takashi Iwai \u003ctiwai@suse.de\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "740ccbaa57110e49f2296c4c610d745baaecc530",
      "tree": "317da7a37729752eb8cc5709b0a00dbbdc1c85c4",
      "parents": [
        "929cfe920d276f8d09b89c83f4ee0c721652d921"
      ],
      "author": {
        "name": "Takashi Iwai",
        "email": "tiwai@suse.de",
        "time": "Mon Dec 03 11:30:50 2012 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:49 2013 -0800"
      },
      "message": "ALSA: usb-audio: Fix missing autopm for MIDI input\n\ncommit f5f165418cabf2218eb466c0e94693b8b1aee88b upstream.\n\nThe commit [88a8516a: ALSA: usbaudio: implement USB autosuspend] added\nthe support of autopm for USB MIDI output, but it didn\u0027t take the MIDI\ninput into account.\n\nThis patch adds the following for fixing the autopm:\n- Manage the URB start at the first MIDI input stream open, instead of\n  the time of instance creation\n- Move autopm code to the common substream_open()\n- Make snd_usbmidi_input_start/_stop() more robust and add the running\n  state check\n\nReviewd-by: Clemens Ladisch \u003cclemens@ladisch.de\u003e\nTested-by: Clemens Ladisch \u003cclemens@ladisch.de\u003e\nSigned-off-by: Takashi Iwai \u003ctiwai@suse.de\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "929cfe920d276f8d09b89c83f4ee0c721652d921",
      "tree": "e62d9c9483834ac59fc2ffb269b216a378bd7136",
      "parents": [
        "6718272b115afbf5d80ea1e0a4d18f9fcb32351f"
      ],
      "author": {
        "name": "Takashi Iwai",
        "email": "tiwai@suse.de",
        "time": "Mon Dec 03 11:12:46 2012 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:49 2013 -0800"
      },
      "message": "ALSA: usb-audio: Avoid autopm calls after disconnection\n\ncommit 59866da9e4ae54819e3c4e0a8f426bdb0c2ef993 upstream.\n\nAdd a similar protection against the disconnection race and the\ninvalid use of usb instance after disconnection, as well as we\u0027ve done\nfor the USB audio PCM.\n\nBugzilla: https://bugzilla.kernel.org/show_bug.cgi?id\u003d51201\n\nReviewd-by: Clemens Ladisch \u003cclemens@ladisch.de\u003e\nTested-by: Clemens Ladisch \u003cclemens@ladisch.de\u003e\nSigned-off-by: Takashi Iwai \u003ctiwai@suse.de\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "6718272b115afbf5d80ea1e0a4d18f9fcb32351f",
      "tree": "b46ec69ae31ba7534be322f62e7d47a4c99687c1",
      "parents": [
        "25747cc45825ffc0192779a224d3bb9bc4b9edbd"
      ],
      "author": {
        "name": "Hugh Dickins",
        "email": "hughd@google.com",
        "time": "Wed Jan 02 02:01:33 2013 -0800"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:49 2013 -0800"
      },
      "message": "tmpfs mempolicy: fix /proc/mounts corrupting memory\n\ncommit f2a07f40dbc603c15f8b06e6ec7f768af67b424f upstream.\n\nRecently I suggested using \"mount -o remount,mpol\u003dlocal /tmp\" in NUMA\nmempolicy testing.  Very nasty.  Reading /proc/mounts, /proc/pid/mounts\nor /proc/pid/mountinfo may then corrupt one bit of kernel memory, often\nin a page table (causing \"Bad swap\" or \"Bad page map\" warning or \"Bad\npagetable\" oops), sometimes in a vm_area_struct or rbnode or somewhere\nworse.  \"mpol\u003dprefer\" and \"mpol\u003dprefer:Node\" are equally toxic.\n\nRecent NUMA enhancements are not to blame: this dates back to 2.6.35,\nwhen commit e17f74af351c \"mempolicy: don\u0027t call mpol_set_nodemask() when\nno_context\" skipped mpol_parse_str()\u0027s call to mpol_set_nodemask(),\nwhich used to initialize v.preferred_node, or set MPOL_F_LOCAL in flags.\nWith slab poisoning, you can then rely on mpol_to_str() to set the bit\nfor node 0x6b6b, probably in the next page above the caller\u0027s stack.\n\nmpol_parse_str() is only called from shmem_parse_options(): no_context\nis always true, so call it unused for now, and remove !no_context code.\nSet v.nodes or v.preferred_node or MPOL_F_LOCAL as mpol_to_str() might\nexpect.  Then mpol_to_str() can ignore its no_context argument also,\nthe mpol being appropriately initialized whether contextualized or not.\nRename its no_context unused too, and let subsequent patch remove them\n(that\u0027s not needed for stable backporting, which would involve rejects).\n\nI don\u0027t understand why MPOL_LOCAL is described as a pseudo-policy:\nit\u0027s a reasonable policy which suffers from a confusing implementation\nin terms of MPOL_PREFERRED with MPOL_F_LOCAL.  I believe this would be\nmuch more robust if MPOL_LOCAL were recognized in switch statements\nthroughout, MPOL_F_LOCAL deleted, and MPOL_PREFERRED use the (possibly\nempty) nodes mask like everyone else, instead of its preferred_node\nvariant (I presume an optimization from the days before MPOL_LOCAL).\nBut that would take me too long to get right and fully tested.\n\nSigned-off-by: Hugh Dickins \u003chughd@google.com\u003e\nSigned-off-by: Linus Torvalds \u003ctorvalds@linux-foundation.org\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "25747cc45825ffc0192779a224d3bb9bc4b9edbd",
      "tree": "eec6ef8ba6fcf4b5177efa110be793568dd8de02",
      "parents": [
        "711cf004f2148f1d1967bc5eca025019e5001212"
      ],
      "author": {
        "name": "Christoffer Dall",
        "email": "cdall@cs.columbia.edu",
        "time": "Fri Dec 21 13:03:50 2012 -0500"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:48 2013 -0800"
      },
      "message": "mm: Fix PageHead when !CONFIG_PAGEFLAGS_EXTENDED\n\ncommit ad4b3fb7ff9940bcdb1e4cd62bd189d10fa636ba upstream.\n\nUnfortunately with !CONFIG_PAGEFLAGS_EXTENDED, (!PageHead) is false, and\n(PageHead) is true, for tail pages.  If this is indeed the intended\nbehavior, which I doubt because it breaks cache cleaning on some ARM\nsystems, then the nomenclature is highly problematic.\n\nThis patch makes sure PageHead is only true for head pages and PageTail\nis only true for tail pages, and neither is true for non-compound pages.\n\n[ This buglet seems ancient - seems to have been introduced back in Apr\n  2008 in commit 6a1e7f777f61: \"pageflags: convert to the use of new\n  macros\".  And the reason nobody noticed is because the PageHead()\n  tests are almost all about just sanity-checking, and only used on\n  pages that are actual page heads.  The fact that the old code returned\n  true for tail pages too was thus not really noticeable.   - Linus ]\n\nSigned-off-by: Christoffer Dall \u003ccdall@cs.columbia.edu\u003e\nAcked-by:  Andrea Arcangeli \u003caarcange@redhat.com\u003e\nCc: Andrew Morton \u003cakpm@linux-foundation.org\u003e\nCc: Will Deacon \u003cWill.Deacon@arm.com\u003e\nCc: Steve Capper \u003cSteve.Capper@arm.com\u003e\nCc: Christoph Lameter \u003ccl@linux.com\u003e\nSigned-off-by: Linus Torvalds \u003ctorvalds@linux-foundation.org\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "711cf004f2148f1d1967bc5eca025019e5001212",
      "tree": "83ba439251b29610cc5ea1f6626d0190521769d9",
      "parents": [
        "6cb6a94380506d9e5491b8e145811bd676ce6f3d"
      ],
      "author": {
        "name": "Sonny Rao",
        "email": "sonnyrao@chromium.org",
        "time": "Thu Dec 20 15:05:07 2012 -0800"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:48 2013 -0800"
      },
      "message": "mm: fix calculation of dirtyable memory\n\ncommit c8b74c2f6604923de91f8aa6539f8bb934736754 upstream.\n\nThe system uses global_dirtyable_memory() to calculate number of\ndirtyable pages/pages that can be allocated to the page cache.  A bug\ncauses an underflow thus making the page count look like a big unsigned\nnumber.  This in turn confuses the dirty writeback throttling to\naggressively write back pages as they become dirty (usually 1 page at a\ntime).  This generally only affects systems with highmem because the\nunderflowed count gets subtracted from the global count of dirtyable\nmemory.\n\nThe problem was introduced with v3.2-4896-gab8fabd\n\nFix is to ensure we don\u0027t get an underflowed total of either highmem or\nglobal dirtyable memory.\n\nSigned-off-by: Sonny Rao \u003csonnyrao@chromium.org\u003e\nSigned-off-by: Puneet Kumar \u003cpuneetster@chromium.org\u003e\nAcked-by: Johannes Weiner \u003channes@cmpxchg.org\u003e\nTested-by: Damien Wyart \u003cdamien.wyart@free.fr\u003e\nSigned-off-by: Andrew Morton \u003cakpm@linux-foundation.org\u003e\nSigned-off-by: Linus Torvalds \u003ctorvalds@linux-foundation.org\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "6cb6a94380506d9e5491b8e145811bd676ce6f3d",
      "tree": "4f1dfd2b85e55b09f971439ca8bee7bbde63cd32",
      "parents": [
        "4511ba021ea5ee7f2b76d954fc23c3814ac07cba"
      ],
      "author": {
        "name": "Will Deacon",
        "email": "will.deacon@arm.com",
        "time": "Fri Oct 19 14:03:33 2012 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:47 2013 -0800"
      },
      "message": "virtio: force vring descriptors to be allocated from lowmem\n\ncommit b92b1b89a33c172c075edccf6afb0edc41d851fd upstream.\n\nVirtio devices may attempt to add descriptors to a virtqueue from atomic\ncontext using GFP_ATOMIC allocation. This is problematic because such\nallocations can fall outside of the lowmem mapping, causing virt_to_phys\nto report bogus physical addresses which are subsequently passed to\nuserspace via the buffers for the virtual device.\n\nThis patch masks out __GFP_HIGH and __GFP_HIGHMEM from the requested\nflags when allocating descriptors for a virtqueue. If an atomic\nallocation is requested and later fails, we will return -ENOSPC which\nwill be handled by the driver.\n\nSigned-off-by: Will Deacon \u003cwill.deacon@arm.com\u003e\nCc: Sasha Levin \u003clevinsasha928@gmail.com\u003e\nSigned-off-by: Rusty Russell \u003crusty@rustcorp.com.au\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "4511ba021ea5ee7f2b76d954fc23c3814ac07cba",
      "tree": "4686aa2bbb62181f67771882c59850eec14d4a71",
      "parents": [
        "7361a9019ff8d45dc835f987ccefbbeb4f560f09"
      ],
      "author": {
        "name": "Ondrej Zary",
        "email": "linux@rainbow-software.org",
        "time": "Tue Dec 11 22:18:05 2012 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:44 2013 -0800"
      },
      "message": "x86, 8042: Enable A20 using KBC to fix S3 resume on some MSI laptops\n\ncommit ad68652412276f68ad4fe3e1ecf5ee6880876783 upstream.\n\nSome MSI laptop BIOSes are broken - INT 15h code uses port 92h to enable A20\nline but resume code assumes that KBC was used.\nThe laptop will not resume from S3 otherwise but powers off after a while\nand then powers on again stuck with a blank screen.\n\nFix it by enabling A20 using KBC in i8042_platform_init for x86.\n\nFixes https://bugzilla.kernel.org/show_bug.cgi?id\u003d12878\n\nSigned-off-by: Ondrej Zary \u003clinux@rainbow-software.org\u003e\nCc: Dmitry Torokhov \u003cdmitry.torokhov@gmail.com\u003e\nCc: Alan Cox \u003calan@lxorguk.ukuu.org.uk\u003e\nCc: Rafael J. Wysocki \u003crjw@sisk.pl\u003e\nLink: http://lkml.kernel.org/r/201212112218.06551.linux@rainbow-software.org\nSigned-off-by: H. Peter Anvin \u003chpa@linux.intel.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "7361a9019ff8d45dc835f987ccefbbeb4f560f09",
      "tree": "3744f41659abc558471e7c5ce040b230486f070e",
      "parents": [
        "5a76bf41fe85c0ebdf4fe1fcdf729697b11a5338"
      ],
      "author": {
        "name": "Kees Cook",
        "email": "keescook@chromium.org",
        "time": "Thu Dec 20 15:05:16 2012 -0800"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:30 2013 -0800"
      },
      "message": "exec: do not leave bprm-\u003einterp on stack\n\ncommit b66c5984017533316fd1951770302649baf1aa33 upstream.\n\nIf a series of scripts are executed, each triggering module loading via\nunprintable bytes in the script header, kernel stack contents can leak\ninto the command line.\n\nNormally execution of binfmt_script and binfmt_misc happens recursively.\nHowever, when modules are enabled, and unprintable bytes exist in the\nbprm-\u003ebuf, execution will restart after attempting to load matching\nbinfmt modules.  Unfortunately, the logic in binfmt_script and\nbinfmt_misc does not expect to get restarted.  They leave bprm-\u003einterp\npointing to their local stack.  This means on restart bprm-\u003einterp is\nleft pointing into unused stack memory which can then be copied into the\nuserspace argv areas.\n\nAfter additional study, it seems that both recursion and restart remains\nthe desirable way to handle exec with scripts, misc, and modules.  As\nsuch, we need to protect the changes to interp.\n\nThis changes the logic to require allocation for any changes to the\nbprm-\u003einterp.  To avoid adding a new kmalloc to every exec, the default\nvalue is left as-is.  Only when passing through binfmt_script or\nbinfmt_misc does an allocation take place.\n\nFor a proof of concept, see DoTest.sh from:\n\n   http://www.halfdog.net/Security/2012/LinuxKernelBinfmtScriptStackDataDisclosure/\n\nSigned-off-by: Kees Cook \u003ckeescook@chromium.org\u003e\nCc: halfdog \u003cme@halfdog.net\u003e\nCc: P J P \u003cppandit@redhat.com\u003e\nCc: Alexander Viro \u003cviro@zeniv.linux.org.uk\u003e\nSigned-off-by: Andrew Morton \u003cakpm@linux-foundation.org\u003e\nSigned-off-by: Linus Torvalds \u003ctorvalds@linux-foundation.org\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "5a76bf41fe85c0ebdf4fe1fcdf729697b11a5338",
      "tree": "8569f633e92e10d72e3f30e998ff2e0de6c58759",
      "parents": [
        "745a4b9a8bedb82d56e23a2e14452ab71df9cf60"
      ],
      "author": {
        "name": "Robin Holt",
        "email": "holt@sgi.com",
        "time": "Thu Dec 20 15:05:50 2012 -0800"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:29 2013 -0800"
      },
      "message": "SGI-XP: handle non-fatal traps\n\ncommit 891348ca0f66206f1dc0e30d63757e3df1ae2d15 upstream.\n\nWe found a user code which was raising a divide-by-zero trap.  That trap\nwould lead to XPC connections between system-partitions being torn down\ndue to the die_chain notifier callouts it received.\n\nThis also revealed a different issue where multiple callers into\nxpc_die_deactivate() would all attempt to do the disconnect in parallel\nwhich would sometimes lock up but often overwhelm the console on very\nlarge machines as each would print at least one line of output at the\nend of the deactivate.\n\nI reviewed all the users of the die_chain notifier and changed the code\nto ignore the notifier callouts for reasons which will not actually lead\nto a system to continue on to call die().\n\n[akpm@linux-foundation.org: fix ia64]\nSigned-off-by: Robin Holt \u003cholt@sgi.com\u003e\nCc: Thomas Gleixner \u003ctglx@linutronix.de\u003e\nCc: Ingo Molnar \u003cmingo@elte.hu\u003e\nSigned-off-by: Andrew Morton \u003cakpm@linux-foundation.org\u003e\nSigned-off-by: Linus Torvalds \u003ctorvalds@linux-foundation.org\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "745a4b9a8bedb82d56e23a2e14452ab71df9cf60",
      "tree": "37e6261d4161e0461b29b6b85a2ebe8e0ce93fbb",
      "parents": [
        "6afc22ba722253aafc389264edc7134e73700e60"
      ],
      "author": {
        "name": "Alan Cox",
        "email": "alan@lxorguk.ukuu.org.uk",
        "time": "Fri Dec 07 23:11:14 2012 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:29 2013 -0800"
      },
      "message": "pnpacpi: fix incorrect TEST_ALPHA() test\n\ncommit cdc87c5a30f407ed1ce43d8a22261116873d5ef1 upstream.\n\nTEST_ALPHA() is broken and always returns 0.\n\n[akpm@linux-foundation.org: return false for \u0027@\u0027 as well, per Bjorn]\nSigned-off-by: Alan Cox \u003calan@lxorguk.ukuu.org.uk\u003e\nSigned-off-by: Andrew Morton \u003cakpm@linux-foundation.org\u003e\nSigned-off-by: Rafael J. Wysocki \u003crafael.j.wysocki@intel.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "6afc22ba722253aafc389264edc7134e73700e60",
      "tree": "6f477789afcf76b7bbbfc51432babd4ea8bf0fb4",
      "parents": [
        "0752c77c0f04ac2649d5175fbc25dd3c5d414870"
      ],
      "author": {
        "name": "Felix Fietkau",
        "email": "nbd@openwrt.org",
        "time": "Mon Dec 10 17:40:21 2012 +0100"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:29 2013 -0800"
      },
      "message": "b43: fix tx path skb leaks\n\ncommit 78f18df4b323d2ac14d6c82e2fc3c8dc4556bccc upstream.\n\nieee80211_free_txskb() needs to be used instead of dev_kfree_skb_any for\ntx packets passed to the driver from mac80211\n\nSigned-off-by: Felix Fietkau \u003cnbd@openwrt.org\u003e\nSigned-off-by: John W. Linville \u003clinville@tuxdriver.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "0752c77c0f04ac2649d5175fbc25dd3c5d414870",
      "tree": "e2d6907a53b979f589b599d92e1213f259b6e35f",
      "parents": [
        "f762136f85f60e7d9e8a0422f078bb187fbfc9f0"
      ],
      "author": {
        "name": "Larry Finger",
        "email": "Larry.Finger@lwfinger.net",
        "time": "Thu Dec 06 21:55:16 2012 -0600"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:29 2013 -0800"
      },
      "message": "b43legacy: Fix firmware loading when driver is built into the kernel\n\ncommit 576d28a7c73013717311cfcb514dbcae27c82eeb upstream.\n\nRecent versions of udev cause synchronous firmware loading from the\nprobe routine to fail because the request to user space times out.\nThe original fix for b43legacy (commit a3ea2c7) moved the firmware\nload from the probe routine to a work queue, but it still used synchronous\nfirmware loading. This method is OK when b43legacy is built as a module;\nhowever, it fails when the driver is compiled into the kernel.\n\nThis version changes the code to load the initial firmware file\nusing request_firmware_nowait(). A completion event is used to\nhold the work queue until that file is available. The remaining\nfirmware files are read synchronously.\n\nSigned-off-by: Larry Finger \u003cLarry.Finger@lwfinger.net\u003e\nSigned-off-by: John W. Linville \u003clinville@tuxdriver.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "f762136f85f60e7d9e8a0422f078bb187fbfc9f0",
      "tree": "9d986bde672f6ec0a4a090bc5d2a2fca7d6b1d91",
      "parents": [
        "b2aa2e70f9d6d5c4aadccdda5956991e8d1869e8"
      ],
      "author": {
        "name": "Neal Cardwell",
        "email": "ncardwell@google.com",
        "time": "Sun Dec 09 11:09:54 2012 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:29 2013 -0800"
      },
      "message": "inet_diag: validate port comparison byte code to prevent unsafe reads\n\n[ Upstream commit 5e1f54201cb481f40a04bc47e1bc8c093a189e23 ]\n\nAdd logic to verify that a port comparison byte code operation\nactually has the second inet_diag_bc_op from which we read the port\nfor such operations.\n\nPreviously the code blindly referenced op[1] without first checking\nwhether a second inet_diag_bc_op struct could fit there. So a\nmalicious user could make the kernel read 4 bytes beyond the end of\nthe bytecode array by claiming to have a whole port comparison byte\ncode (2 inet_diag_bc_op structs) when in fact the bytecode was not\nlong enough to hold both.\n\nSigned-off-by: Neal Cardwell \u003cncardwell@google.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "b2aa2e70f9d6d5c4aadccdda5956991e8d1869e8",
      "tree": "51ca0f2c9904ab94cbcabf5d18484daf24fdd0b7",
      "parents": [
        "879fc99ecd078f64849b95c47cf7e28705ac8884"
      ],
      "author": {
        "name": "Neal Cardwell",
        "email": "ncardwell@google.com",
        "time": "Sat Dec 08 19:43:23 2012 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:28 2013 -0800"
      },
      "message": "inet_diag: avoid unsafe and nonsensical prefix matches in inet_diag_bc_run()\n\n[ Upstream commit f67caec9068cee426ec23cf9005a1dee2ecad187 ]\n\nAdd logic to check the address family of the user-supplied conditional\nand the address family of the connection entry. We now do not do\nprefix matching of addresses from different address families (AF_INET\nvs AF_INET6), except for the previously existing support for having an\nIPv4 prefix match an IPv4-mapped IPv6 address (which this commit\nmaintains as-is).\n\nThis change is needed for two reasons:\n\n(1) The addresses are different lengths, so comparing a 128-bit IPv6\nprefix match condition to a 32-bit IPv4 connection address can cause\nus to unwittingly walk off the end of the IPv4 address and read\ngarbage or oops.\n\n(2) The IPv4 and IPv6 address spaces are semantically distinct, so a\nsimple bit-wise comparison of the prefixes is not meaningful, and\nwould lead to bogus results (except for the IPv4-mapped IPv6 case,\nwhich this commit maintains).\n\nSigned-off-by: Neal Cardwell \u003cncardwell@google.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "879fc99ecd078f64849b95c47cf7e28705ac8884",
      "tree": "eb570cc6cfc09defa928478ba30d6718e07a8ab3",
      "parents": [
        "457a04b96314023464f8249975b1efb4eef1c925"
      ],
      "author": {
        "name": "Neal Cardwell",
        "email": "ncardwell@google.com",
        "time": "Sat Dec 08 19:43:22 2012 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:28 2013 -0800"
      },
      "message": "inet_diag: validate byte code to prevent oops in inet_diag_bc_run()\n\n[ Upstream commit 405c005949e47b6e91359159c24753519ded0c67 ]\n\nAdd logic to validate INET_DIAG_BC_S_COND and INET_DIAG_BC_D_COND\noperations.\n\nPreviously we did not validate the inet_diag_hostcond, address family,\naddress length, and prefix length. So a malicious user could make the\nkernel read beyond the end of the bytecode array by claiming to have a\nwhole inet_diag_hostcond when the bytecode was not long enough to\ncontain a whole inet_diag_hostcond of the given address family. Or\nthey could make the kernel read up to about 27 bytes beyond the end of\na connection address by passing a prefix length that exceeded the\nlength of addresses of the given family.\n\nSigned-off-by: Neal Cardwell \u003cncardwell@google.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "457a04b96314023464f8249975b1efb4eef1c925",
      "tree": "62ce6effc1ee518280963821970df01659e3bc29",
      "parents": [
        "1755fd2e38a0541dab207df5d42d92b567695497"
      ],
      "author": {
        "name": "Neal Cardwell",
        "email": "ncardwell@google.com",
        "time": "Sat Dec 08 19:43:21 2012 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:28 2013 -0800"
      },
      "message": "inet_diag: fix oops for IPv4 AF_INET6 TCP SYN-RECV state\n\n[ Upstream commit 1c95df85ca49640576de2f0a850925957b547b84 ]\n\nFix inet_diag to be aware of the fact that AF_INET6 TCP connections\ninstantiated for IPv4 traffic and in the SYN-RECV state were actually\ncreated with inet_reqsk_alloc(), instead of inet6_reqsk_alloc(). This\nmeans that for such connections inet6_rsk(req) returns a pointer to a\nrandom spot in memory up to roughly 64KB beyond the end of the\nrequest_sock.\n\nWith this bug, for a server using AF_INET6 TCP sockets and serving\nIPv4 traffic, an inet_diag user like `ss state SYN-RECV` would lead to\ninet_diag_fill_req() causing an oops or the export to user space of 16\nbytes of kernel memory as a garbage IPv6 address, depending on where\nthe garbage inet6_rsk(req) pointed.\n\nSigned-off-by: Neal Cardwell \u003cncardwell@google.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "1755fd2e38a0541dab207df5d42d92b567695497",
      "tree": "8bbc3914a5a8753ccca39ceff6c422d978630a4a",
      "parents": [
        "eab34a33cfdda79711f6c66a9f9d7a558238eed8"
      ],
      "author": {
        "name": "Jay Purohit",
        "email": "jspurohit@velocitylimitless.com",
        "time": "Sun Oct 14 07:07:21 2012 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:28 2013 -0800"
      },
      "message": "usb/ipheth: Add iPhone 5 support\n\n[ Upstream commit af1b85e49089f945deb46258b0fc4bc9910afb22 ]\n\nI noticed that the iPhone ethernet driver did not support\niPhone 5. I quickly added support to it in my kernel, here\u0027s\na patch.\n\nSigned-off-by: Jay Purohit \u003cjspurohit@velocitylimitless.com\u003e\nAcked-by: Valdis Kletnieks \u003cvaldis.kletnieks@vt.edu\u003e\nSigned-off-by: Jan Ceuleers \u003cjan.ceuleers@computer.org\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "eab34a33cfdda79711f6c66a9f9d7a558238eed8",
      "tree": "09d4e99697f1c9efc2787c2345fd32ebf01f0fa8",
      "parents": [
        "6b015f351d9c8a1800f4e234fbfbcc0198bf0b5f"
      ],
      "author": {
        "name": "Johannes Berg",
        "email": "johannes.berg@intel.com",
        "time": "Sun Dec 09 23:41:06 2012 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:28 2013 -0800"
      },
      "message": "ipv4: ip_check_defrag must not modify skb before unsharing\n\n[ Upstream commit 1bf3751ec90cc3174e01f0d701e8449ce163d113 ]\n\nip_check_defrag() might be called from af_packet within the\nRX path where shared SKBs are used, so it must not modify\nthe input SKB before it has unshared it for defragmentation.\nUse skb_copy_bits() to get the IP header and only pull in\neverything later.\n\nThe same is true for the other caller in macvlan as it is\ncalled from dev-\u003erx_handler which can also get a shared SKB.\n\nReported-by: Eric Leblond \u003ceric@regit.org\u003e\nCc: stable@vger.kernel.org\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "6b015f351d9c8a1800f4e234fbfbcc0198bf0b5f",
      "tree": "c4b03959544c497a189af9f7287e70df6401779c",
      "parents": [
        "aa335048531c58da34fed27b69a7ba0faf9a1eee"
      ],
      "author": {
        "name": "Alexander Shiyan",
        "email": "shc_work@mail.ru",
        "time": "Tue Nov 20 09:59:11 2012 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:27 2013 -0800"
      },
      "message": "irda: sir_dev: Fix copy/paste typo\n\n[ Upstream commit 2355a62bcbdcc4b567425bab036bfab6ade87eed ]\n\nSigned-off-by: Alexander Shiyan \u003cshc_work@mail.ru\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "aa335048531c58da34fed27b69a7ba0faf9a1eee",
      "tree": "7f0878d5fc191fdb8706aa9a19aab36ddcb925ff",
      "parents": [
        "dff343c7f4dfa5650d5d3a78f58f080ec9f14a25"
      ],
      "author": {
        "name": "Alan Cox",
        "email": "alan@linux.intel.com",
        "time": "Tue Nov 20 06:31:57 2012 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:27 2013 -0800"
      },
      "message": "ne2000: add the right platform device\n\n[ Upstream commit da9da01d9199b5bb15289d0859053c9aa3a34ac0 ]\n\nWithout this udev doesn\u0027t have a way to key the ne device to the platform\ndevice.\n\nSigned-off-by: Alan Cox \u003calan@linux.intel.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "dff343c7f4dfa5650d5d3a78f58f080ec9f14a25",
      "tree": "3d5b4f30adc719ef3475042cbe2d09b4c818f343",
      "parents": [
        "d0804c62db373041db42aa976edf2b9e5f5ae9ed"
      ],
      "author": {
        "name": "Tommi Rantala",
        "email": "tt.rantala@gmail.com",
        "time": "Thu Nov 22 03:23:16 2012 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:27 2013 -0800"
      },
      "message": "sctp: fix -ENOMEM result with invalid user space pointer in sendto() syscall\n\n[ Upstream commit 6e51fe7572590d8d86e93b547fab6693d305fd0d ]\n\nConsider the following program, that sets the second argument to the\nsendto() syscall incorrectly:\n\n #include \u003cstring.h\u003e\n #include \u003carpa/inet.h\u003e\n #include \u003csys/socket.h\u003e\n\n int main(void)\n {\n         int fd;\n         struct sockaddr_in sa;\n\n         fd \u003d socket(AF_INET, SOCK_STREAM, 132 /*IPPROTO_SCTP*/);\n         if (fd \u003c 0)\n                 return 1;\n\n         memset(\u0026sa, 0, sizeof(sa));\n         sa.sin_family \u003d AF_INET;\n         sa.sin_addr.s_addr \u003d inet_addr(\"127.0.0.1\");\n         sa.sin_port \u003d htons(11111);\n\n         sendto(fd, NULL, 1, 0, (struct sockaddr *)\u0026sa, sizeof(sa));\n\n         return 0;\n }\n\nWe get -ENOMEM:\n\n $ strace -e sendto ./demo\n sendto(3, NULL, 1, 0, {sa_family\u003dAF_INET, sin_port\u003dhtons(11111), sin_addr\u003dinet_addr(\"127.0.0.1\")}, 16) \u003d -1 ENOMEM (Cannot allocate memory)\n\nPropagate the error code from sctp_user_addto_chunk(), so that we will\ntell user space what actually went wrong:\n\n $ strace -e sendto ./demo\n sendto(3, NULL, 1, 0, {sa_family\u003dAF_INET, sin_port\u003dhtons(11111), sin_addr\u003dinet_addr(\"127.0.0.1\")}, 16) \u003d -1 EFAULT (Bad address)\n\nNoticed while running Trinity (the syscall fuzzer).\n\nSigned-off-by: Tommi Rantala \u003ctt.rantala@gmail.com\u003e\nAcked-by: Vlad Yasevich \u003cvyasevich@gmail.com\u003e\nAcked-by: Neil Horman \u003cnhorman@tuxdriver.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "d0804c62db373041db42aa976edf2b9e5f5ae9ed",
      "tree": "6144f8e82a58e3709a2b9e7c7f95e45f1e9d25cb",
      "parents": [
        "1097b6a83df844d5145a1f9821300028857d8ca9"
      ],
      "author": {
        "name": "Tommi Rantala",
        "email": "tt.rantala@gmail.com",
        "time": "Tue Nov 27 04:01:46 2012 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:27 2013 -0800"
      },
      "message": "sctp: fix memory leak in sctp_datamsg_from_user() when copy from user space fails\n\n[ Upstream commit be364c8c0f17a3dd42707b5a090b318028538eb9 ]\n\nTrinity (the syscall fuzzer) discovered a memory leak in SCTP,\nreproducible e.g. with the sendto() syscall by passing invalid\nuser space pointer in the second argument:\n\n #include \u003cstring.h\u003e\n #include \u003carpa/inet.h\u003e\n #include \u003csys/socket.h\u003e\n\n int main(void)\n {\n         int fd;\n         struct sockaddr_in sa;\n\n         fd \u003d socket(AF_INET, SOCK_STREAM, 132 /*IPPROTO_SCTP*/);\n         if (fd \u003c 0)\n                 return 1;\n\n         memset(\u0026sa, 0, sizeof(sa));\n         sa.sin_family \u003d AF_INET;\n         sa.sin_addr.s_addr \u003d inet_addr(\"127.0.0.1\");\n         sa.sin_port \u003d htons(11111);\n\n         sendto(fd, NULL, 1, 0, (struct sockaddr *)\u0026sa, sizeof(sa));\n\n         return 0;\n }\n\nAs far as I can tell, the leak has been around since ~2003.\n\nSigned-off-by: Tommi Rantala \u003ctt.rantala@gmail.com\u003e\nAcked-by: Vlad Yasevich \u003cvyasevich@gmail.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "1097b6a83df844d5145a1f9821300028857d8ca9",
      "tree": "de2710431a0a37c2e54f5d381dbfae68c35d0139",
      "parents": [
        "1789172140b7b61955b87b3070fb30da1a701d7c"
      ],
      "author": {
        "name": "nikolay@redhat.com",
        "email": "nikolay@redhat.com",
        "time": "Thu Nov 29 01:37:59 2012 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:26 2013 -0800"
      },
      "message": "bonding: fix race condition in bonding_store_slaves_active\n\n[ Upstream commit e196c0e579902f42cf72414461fb034e5a1ffbf7 ]\n\nRace between bonding_store_slaves_active() and slave manipulation\n functions. The bond_for_each_slave use in bonding_store_slaves_active()\n is not protected by any synchronization mechanism.\n NULL pointer dereference is easy to reach.\n Fixed by acquiring the bond-\u003elock for the slave walk.\n\n v2: Make description text \u003c 75 columns\n\nSigned-off-by: Nikolay Aleksandrov \u003cnikolay@redhat.com\u003e\nSigned-off-by: Jay Vosburgh \u003cfubar@us.ibm.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "1789172140b7b61955b87b3070fb30da1a701d7c",
      "tree": "e9112b907fc01ee593542cb8e18eb929e1999fc8",
      "parents": [
        "e56f8b7aeb0b8135ee29b0612b192a784450739e"
      ],
      "author": {
        "name": "Sarveshwar Bandi",
        "email": "sarveshwar.bandi@emulex.com",
        "time": "Wed Nov 21 04:35:03 2012 +0000"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Fri Jan 11 09:06:26 2013 -0800"
      },
      "message": "bonding: Bonding driver does not consider the gso_max_size/gso_max_segs setting of slave devices.\n\n[ Upstream commit 0e376bd0b791ac6ac6bdb051492df0769c840848 ]\n\nPatch sets the lowest gso_max_size and gso_max_segs values of the slave devices during enslave and detach.\n\nSigned-off-by: Sarveshwar Bandi \u003csarveshwar.bandi@emulex.com\u003e\nAcked-by: Eric Dumazet \u003cedumazet@google.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n"
    },
    {
      "commit": "e56f8b7aeb0b8135ee29b0612b192a784450739e",
      "tree": "39cae37804ca235f5fe7b51e63ed113b52135203",
      "parents": [
        "29251de53e1712158c29b3626a008d8b93a6e024"
      ],
      "author": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Mon Dec 17 10:38:05 2012 -0800"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Mon Dec 17 10:38:05 2012 -0800"
      },
      "message": "Linux 3.4.24\n"
    },
    {
      "commit": "29251de53e1712158c29b3626a008d8b93a6e024",
      "tree": "acbbbf18020a71fd5d01beba87453b70fc24b989",
      "parents": [
        "d5a79aa30b7e6cd68dfee6a76acbe6c7f7905f51"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "edumazet@google.com",
        "time": "Thu Oct 18 04:55:36 2012 -0700"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Mon Dec 17 10:37:46 2012 -0800"
      },
      "message": "rcu: Fix batch-limit size problem\n\ncommit 878d7439d0f45a95869e417576774673d1fa243f upstream.\n\nCommit 29c00b4a1d9e27 (rcu: Add event-tracing for RCU callback\ninvocation) added a regression in rcu_do_batch()\n\nUnder stress, RCU is supposed to allow to process all items in queue,\ninstead of a batch of 10 items (blimit), but an integer overflow makes\nthe effective limit being 1.  So, unless there is frequent idle periods\n(during which RCU ignores batch limits), RCU can be forced into a\nstate where it cannot keep up with the callback-generation rate,\neventually resulting in OOM.\n\nThis commit therefore converts a few variables in rcu_do_batch() from\nint to long to fix this problem, along with the module parameters\ncontrolling the batch limits.\n\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nSigned-off-by: Paul E. McKenney \u003cpaulmck@linux.vnet.ibm.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    },
    {
      "commit": "d5a79aa30b7e6cd68dfee6a76acbe6c7f7905f51",
      "tree": "cb9c1ceee906121ea033328a50f39c84102a2f19",
      "parents": [
        "1229a83d1ea3d11b4433f7080825d05044af45a9"
      ],
      "author": {
        "name": "Zheng Liu",
        "email": "gnehzuil.liu@gmail.com",
        "time": "Thu Nov 08 16:58:46 2012 -0800"
      },
      "committer": {
        "name": "Greg Kroah-Hartman",
        "email": "gregkh@linuxfoundation.org",
        "time": "Mon Dec 17 10:37:46 2012 -0800"
      },
      "message": "perf test: fix a build error on builtin-test\n\ncommit 12f8f74b2a4d26c4facfa7ef99487cf0930f6ef7 upstream.\n\nRecently I build perf and get a build error on builtin-test.c. The error is as\nfollowing:\n\n$ make\n    CC perf.o\n    CC builtin-test.o\ncc1: warnings being treated as errors\nbuiltin-test.c: In function ‘sched__get_first_possible_cpu’:\nbuiltin-test.c:977: warning: implicit declaration of function ‘CPU_ALLOC’\nbuiltin-test.c:977: warning: nested extern declaration of ‘CPU_ALLOC’\nbuiltin-test.c:977: warning: assignment makes pointer from integer without a cast\nbuiltin-test.c:978: warning: implicit declaration of function ‘CPU_ALLOC_SIZE’\nbuiltin-test.c:978: warning: nested extern declaration of ‘CPU_ALLOC_SIZE’\nbuiltin-test.c:979: warning: implicit declaration of function ‘CPU_ZERO_S’\nbuiltin-test.c:979: warning: nested extern declaration of ‘CPU_ZERO_S’\nbuiltin-test.c:982: warning: implicit declaration of function ‘CPU_FREE’\nbuiltin-test.c:982: warning: nested extern declaration of ‘CPU_FREE’\nbuiltin-test.c:992: warning: implicit declaration of function ‘CPU_ISSET_S’\nbuiltin-test.c:992: warning: nested extern declaration of ‘CPU_ISSET_S’\nbuiltin-test.c:998: warning: implicit declaration of function ‘CPU_CLR_S’\nbuiltin-test.c:998: warning: nested extern declaration of ‘CPU_CLR_S’\nmake: *** [builtin-test.o] Error 1\n\nThis problem is introduced in 3e7c439a. CPU_ALLOC and related macros are\nmissing in sched__get_first_possible_cpu function. In 54489c18, commiter\nmentioned that CPU_ALLOC has been removed. So CPU_ALLOC calls in this\nfunction are removed to let perf to be built.\n\nSigned-off-by: Vinson Lee \u003cvlee@twitter.com\u003e\nSigned-off-by: Zheng Liu \u003cwenqing.lz@taobao.com\u003e\nCc: David Ahern \u003cdsahern@gmail.com\u003e\nCc: Frederic Weisbecker \u003cfweisbec@gmail.com\u003e\nCc: Mike Galbraith \u003cefault@gmx.de\u003e\nCc: Paul Mackerras \u003cpaulus@samba.org\u003e\nCc: Peter Zijlstra \u003cpeterz@infradead.org\u003e\nCc: Stephane Eranian \u003ceranian@google.com\u003e\nCc: Vinson Lee \u003cvlee@twitter.com\u003e\nCc: Zheng Liu \u003cwenqing.lz@taobao.com\u003e\nLink: http://lkml.kernel.org/r/1352422726-31114-1-git-send-email-vlee@twitter.com\nSigned-off-by: Arnaldo Carvalho de Melo \u003cacme@redhat.com\u003e\nSigned-off-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\n\n"
    }
  ],
  "next": "1229a83d1ea3d11b4433f7080825d05044af45a9"
}
