--- /dev/null
+From ed3b6679936801fa2dab47e7a6ef74e383400ed9 Mon Sep 17 00:00:00 2001
+From: Rafael Barbalho <rafael.barbalho@intel.com>
+Date: Thu, 24 Jul 2014 15:16:12 +0100
+Subject: drm/i915: Fix crash when failing to parse MIPI VBT
+
+From: Rafael Barbalho <rafael.barbalho@intel.com>
+
+commit ed3b6679936801fa2dab47e7a6ef74e383400ed9 upstream.
+
+This particular nasty presented itself while trying to register the
+intelfb device (intel_fbdev.c). During the process of registering the device
+the driver will disable the crtc via i9xx_crtc_disable. These will
+also disable the panel using the generic mipi panel functions in
+dsi_mod_vbt_generic.c. The stale MIPI generic data sequence pointers would
+cause a crash within those functions. However, all of this is happening
+while console_lock is held from do_register_framebuffer inside fbcon.c. Which
+means that you got kernel log and just the device appearing to reboot/hang for
+no apparent reason.
+
+The fault started from the FB_EVENT_FB_REGISTERED event using the
+fb_notifier_call_chain call in fbcon.c.
+
+This regression has been introduced in
+
+commit d3b542fcfc72d7724585e3fd2c5e75351bc3df47
+Author: Shobhit Kumar <shobhit.kumar@intel.com>
+Date: Mon Apr 14 11:00:34 2014 +0530
+
+ drm/i915: Add parsing support for new MIPI blocks in VBT
+
+Cc: Shobhit Kumar <shobhit.kumar@intel.com>
+Signed-off-by: Rafael Barbalho <rafael.barbalho@intel.com>
+Reviewed-by: Shobhit Kumar <shobhit.kumar@intel.com>
+[danvet: Add regression citation.]
+Signed-off-by: Daniel Vetter <daniel.vetter@ffwll.ch>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+
+---
+ drivers/gpu/drm/i915/intel_bios.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+--- a/drivers/gpu/drm/i915/intel_bios.c
++++ b/drivers/gpu/drm/i915/intel_bios.c
+@@ -877,7 +877,7 @@ err:
+
+ /* error during parsing so set all pointers to null
+ * because of partial parsing */
+- memset(dev_priv->vbt.dsi.sequence, 0, MIPI_SEQ_MAX);
++ memset(dev_priv->vbt.dsi.sequence, 0, sizeof(dev_priv->vbt.dsi.sequence));
+ }
+
+ static void parse_ddi_port(struct drm_i915_private *dev_priv, enum port port,
--- /dev/null
+From ece4a17d237a79f63fbfaf3f724a12b6d500555c Mon Sep 17 00:00:00 2001
+From: Jiri Kosina <jkosina@suse.cz>
+Date: Thu, 7 Aug 2014 16:29:53 +0200
+Subject: drm/i915: read HEAD register back in init_ring_common() to enforce ordering
+
+From: Jiri Kosina <jkosina@suse.cz>
+
+commit ece4a17d237a79f63fbfaf3f724a12b6d500555c upstream.
+
+Withtout this, ring initialization fails reliabily during resume with
+
+ [drm:init_ring_common] *ERROR* render ring initialization failed ctl 0001f001 head ffffff8804 tail 00000000 start 000e4000
+
+This is not a complete fix, but it is verified to make the ring
+initialization failures during resume much less likely.
+
+We were not able to root-cause this bug (likely HW-specific to Gen4 chips)
+yet. This is therefore used as a ducttape before problem is fully
+understood and proper fix created, so that people don't suffer from
+completely unusable systems in the meantime.
+
+The discussion and debugging is happening at
+
+ https://bugs.freedesktop.org/show_bug.cgi?id=76554
+
+Signed-off-by: Jiri Kosina <jkosina@suse.cz>
+Signed-off-by: Daniel Vetter <daniel.vetter@ffwll.ch>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+
+---
+ drivers/gpu/drm/i915/intel_ringbuffer.c | 3 +++
+ 1 file changed, 3 insertions(+)
+
+--- a/drivers/gpu/drm/i915/intel_ringbuffer.c
++++ b/drivers/gpu/drm/i915/intel_ringbuffer.c
+@@ -517,6 +517,9 @@ static int init_ring_common(struct intel
+ else
+ ring_setup_phys_status_page(ring);
+
++ /* Enforce ordering by reading HEAD register back */
++ I915_READ_HEAD(ring);
++
+ /* Initialize the ring. This must happen _after_ we've cleared the ring
+ * registers with the above sequence (the readback of the HEAD registers
+ * also enforces ordering), otherwise the hw might lose the new ring