From: Sasha Levin Date: Mon, 2 May 2022 04:06:25 +0000 (-0400) Subject: Fixes for 4.19 X-Git-Tag: v5.4.192~46 X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=f915403a72c5185151d4ba1083b072e0177e3cfc;p=thirdparty%2Fkernel%2Fstable-queue.git Fixes for 4.19 Signed-off-by: Sasha Levin --- diff --git a/queue-4.19/arm-dts-at91-map-mclk-for-wm8731-on-at91sam9g20ek.patch b/queue-4.19/arm-dts-at91-map-mclk-for-wm8731-on-at91sam9g20ek.patch new file mode 100644 index 00000000000..14ac4bac7d7 --- /dev/null +++ b/queue-4.19/arm-dts-at91-map-mclk-for-wm8731-on-at91sam9g20ek.patch @@ -0,0 +1,45 @@ +From ad600b40ee0b44f26a5bbbe203e53667d90d98b2 Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Mon, 4 Apr 2022 11:28:05 +0100 +Subject: ARM: dts: at91: Map MCLK for wm8731 on at91sam9g20ek + +From: Mark Brown + +[ Upstream commit 0e486fe341fabd8e583f3d601a874cd394979c45 ] + +The MCLK of the WM8731 on the AT91SAM9G20-EK board is connected to the +PCK0 output of the SoC and is expected to be set to 12MHz. Previously +this was mapped using pre-common clock API calls in the audio machine +driver but the conversion to the common clock framework broke that so +describe things in the DT instead. + +Fixes: ff78a189b0ae55f ("ARM: at91: remove old at91-specific clock driver") +Signed-off-by: Mark Brown +Reviewed-by: Claudiu Beznea +Signed-off-by: Nicolas Ferre +Link: https://lore.kernel.org/r/20220404102806.581374-2-broonie@kernel.org +Signed-off-by: Sasha Levin +--- + arch/arm/boot/dts/at91sam9g20ek_common.dtsi | 6 ++++++ + 1 file changed, 6 insertions(+) + +diff --git a/arch/arm/boot/dts/at91sam9g20ek_common.dtsi b/arch/arm/boot/dts/at91sam9g20ek_common.dtsi +index ec1f17ab6753..ae64d54cc96c 100644 +--- a/arch/arm/boot/dts/at91sam9g20ek_common.dtsi ++++ b/arch/arm/boot/dts/at91sam9g20ek_common.dtsi +@@ -218,6 +218,12 @@ i2c-gpio-0 { + wm8731: wm8731@1b { + compatible = "wm8731"; + reg = <0x1b>; ++ ++ /* PCK0 at 12MHz */ ++ clocks = <&pmc PMC_TYPE_SYSTEM 8>; ++ clock-names = "mclk"; ++ assigned-clocks = <&pmc PMC_TYPE_SYSTEM 8>; ++ assigned-clock-rates = <12000000>; + }; + }; + +-- +2.35.1 + diff --git a/queue-4.19/arm-dts-fix-mmc-order-for-omap3-gta04.patch b/queue-4.19/arm-dts-fix-mmc-order-for-omap3-gta04.patch new file mode 100644 index 00000000000..9cc97def2fa --- /dev/null +++ b/queue-4.19/arm-dts-fix-mmc-order-for-omap3-gta04.patch @@ -0,0 +1,38 @@ +From 80b5a351ccb3eb71c6c368100a20e9226c34a677 Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Tue, 8 Mar 2022 14:00:20 +0100 +Subject: ARM: dts: Fix mmc order for omap3-gta04 + +From: H. Nikolaus Schaller + +[ Upstream commit 09269dd050094593fc747f2a5853d189fefcb6b5 ] + +Commit a1ebdb374199 ("ARM: dts: Fix swapped mmc order for omap3") +introduces general mmc aliases. Let's tailor them to the need +of the GTA04 board which does not make use of mmc2 and mmc3 interfaces. + +Fixes: a1ebdb374199 ("ARM: dts: Fix swapped mmc order for omap3") +Signed-off-by: H. Nikolaus Schaller +Message-Id: +Signed-off-by: Tony Lindgren +Signed-off-by: Sasha Levin +--- + arch/arm/boot/dts/omap3-gta04.dtsi | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/arch/arm/boot/dts/omap3-gta04.dtsi b/arch/arm/boot/dts/omap3-gta04.dtsi +index a5aed92ab54b..820bdd5326ab 100644 +--- a/arch/arm/boot/dts/omap3-gta04.dtsi ++++ b/arch/arm/boot/dts/omap3-gta04.dtsi +@@ -29,6 +29,8 @@ memory@80000000 { + aliases { + display0 = &lcd; + display1 = &tv0; ++ /delete-property/ mmc2; ++ /delete-property/ mmc3; + }; + + /* fixed 26MHz oscillator */ +-- +2.35.1 + diff --git a/queue-4.19/arm-dts-imx6qdl-apalis-fix-sgtl5000-detection-issue.patch b/queue-4.19/arm-dts-imx6qdl-apalis-fix-sgtl5000-detection-issue.patch new file mode 100644 index 00000000000..0b8680c3727 --- /dev/null +++ b/queue-4.19/arm-dts-imx6qdl-apalis-fix-sgtl5000-detection-issue.patch @@ -0,0 +1,71 @@ +From e95a8f749ad4dfcb279c962e5a9cfca7f9e9fb04 Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Sat, 26 Mar 2022 12:14:55 -0300 +Subject: ARM: dts: imx6qdl-apalis: Fix sgtl5000 detection issue + +From: Fabio Estevam + +[ Upstream commit fa51e1dc4b91375bc18349663a52395ad585bd3c ] + +On a custom carrier board with a i.MX6Q Apalis SoM, the sgtl5000 codec +on the SoM is often not detected and the following error message is +seen when the sgtl5000 driver tries to read the ID register: + +sgtl5000 1-000a: Error reading chip id -6 + +The reason for the error is that the MCLK clock is not provided +early enough. + +Fix the problem by describing the MCLK pinctrl inside the codec +node instead of placing it inside the audmux pinctrl group. + +With this change applied the sgtl5000 is always detected on every boot. + +Fixes: 693e3ffaae5a ("ARM: dts: imx6: Add support for Toradex Apalis iMX6Q/D SoM") +Signed-off-by: Fabio Estevam +Reviewed-by: Tim Harvey +Acked-by: Max Krummenacher +Signed-off-by: Shawn Guo +Signed-off-by: Sasha Levin +--- + arch/arm/boot/dts/imx6qdl-apalis.dtsi | 10 ++++++++-- + 1 file changed, 8 insertions(+), 2 deletions(-) + +diff --git a/arch/arm/boot/dts/imx6qdl-apalis.dtsi b/arch/arm/boot/dts/imx6qdl-apalis.dtsi +index 05f07ea3e8c8..ed783c91b002 100644 +--- a/arch/arm/boot/dts/imx6qdl-apalis.dtsi ++++ b/arch/arm/boot/dts/imx6qdl-apalis.dtsi +@@ -313,6 +313,8 @@ vgen6_reg: vgen6 { + codec: sgtl5000@a { + compatible = "fsl,sgtl5000"; + reg = <0x0a>; ++ pinctrl-names = "default"; ++ pinctrl-0 = <&pinctrl_sgtl5000>; + clocks = <&clks IMX6QDL_CLK_CKO>; + VDDA-supply = <®_module_3v3_audio>; + VDDIO-supply = <®_module_3v3>; +@@ -540,8 +542,6 @@ MX6QDL_PAD_DISP0_DAT20__AUD4_TXC 0x130b0 + MX6QDL_PAD_DISP0_DAT21__AUD4_TXD 0x130b0 + MX6QDL_PAD_DISP0_DAT22__AUD4_TXFS 0x130b0 + MX6QDL_PAD_DISP0_DAT23__AUD4_RXD 0x130b0 +- /* SGTL5000 sys_mclk */ +- MX6QDL_PAD_GPIO_5__CCM_CLKO1 0x130b0 + >; + }; + +@@ -807,6 +807,12 @@ MX6QDL_PAD_NANDF_CS1__GPIO6_IO14 0x000b0 + >; + }; + ++ pinctrl_sgtl5000: sgtl5000grp { ++ fsl,pins = < ++ MX6QDL_PAD_GPIO_5__CCM_CLKO1 0x130b0 ++ >; ++ }; ++ + pinctrl_spdif: spdifgrp { + fsl,pins = < + MX6QDL_PAD_GPIO_16__SPDIF_IN 0x1b0b0 +-- +2.35.1 + diff --git a/queue-4.19/arm-dts-imx6ull-colibri-fix-vqmmc-regulator.patch b/queue-4.19/arm-dts-imx6ull-colibri-fix-vqmmc-regulator.patch new file mode 100644 index 00000000000..25579e34d37 --- /dev/null +++ b/queue-4.19/arm-dts-imx6ull-colibri-fix-vqmmc-regulator.patch @@ -0,0 +1,39 @@ +From 8aa9fe2f1764748936e9c013379f96082a510e03 Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Thu, 14 Apr 2022 10:50:54 +0200 +Subject: ARM: dts: imx6ull-colibri: fix vqmmc regulator + +From: Max Krummenacher + +[ Upstream commit 45974e4276a8d6653394f66666fc57d8ffa6de9a ] + +The correct spelling for the property is gpios. Otherwise, the regulator +will neither reserve nor control any GPIOs. Thus, any SD/MMC card which +can use UHS-I modes will fail. + +Fixes: c2e4987e0e02 ("ARM: dts: imx6ull: add Toradex Colibri iMX6ULL support") +Signed-off-by: Max Krummenacher +Signed-off-by: Denys Drozdov +Signed-off-by: Marcel Ziswiler +Signed-off-by: Shawn Guo +Signed-off-by: Sasha Levin +--- + arch/arm/boot/dts/imx6ull-colibri.dtsi | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/arch/arm/boot/dts/imx6ull-colibri.dtsi b/arch/arm/boot/dts/imx6ull-colibri.dtsi +index 6c63a7384611..4219239f0b58 100644 +--- a/arch/arm/boot/dts/imx6ull-colibri.dtsi ++++ b/arch/arm/boot/dts/imx6ull-colibri.dtsi +@@ -37,7 +37,7 @@ reg_module_3v3_avdd: regulator-module-3v3-avdd { + + reg_sd1_vmmc: regulator-sd1-vmmc { + compatible = "regulator-gpio"; +- gpio = <&gpio5 9 GPIO_ACTIVE_HIGH>; ++ gpios = <&gpio5 9 GPIO_ACTIVE_HIGH>; + pinctrl-names = "default"; + pinctrl-0 = <&pinctrl_snvs_reg_sd>; + regulator-always-on; +-- +2.35.1 + diff --git a/queue-4.19/arm-dts-logicpd-som-lv-fix-wrong-pinmuxing-on-omap35.patch b/queue-4.19/arm-dts-logicpd-som-lv-fix-wrong-pinmuxing-on-omap35.patch new file mode 100644 index 00000000000..90a67e16f9c --- /dev/null +++ b/queue-4.19/arm-dts-logicpd-som-lv-fix-wrong-pinmuxing-on-omap35.patch @@ -0,0 +1,104 @@ +From 9e6ed6e29b7fe12cc71381aaafddd2f75a13f0d4 Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Thu, 3 Mar 2022 11:18:17 -0600 +Subject: ARM: dts: logicpd-som-lv: Fix wrong pinmuxing on OMAP35 + +From: Adam Ford + +[ Upstream commit 46ff3df87215ff42c0cd2c4bdb7d74540384a69c ] + +The pinout of the OMAP35 and DM37 variants of the SOM-LV are the +same, but the macros which define the pinmuxing are different +between OMAP3530 and DM3730. The pinmuxing was correct for +for the DM3730, but wrong for the OMAP3530. Since the boot loader +was correctly pin-muxing the pins, this was not obvious. As the +bootloader not guaranteed to pinmux all the pins any more, this +causes an issue, so the pinmux needs to be moved from a common +file to their respective board files. + +Fixes: f8a2e3ff7103 ("ARM: dts: Add minimal support for LogicPD OMAP35xx SOM-LV devkit") +Signed-off-by: Adam Ford +Message-Id: <20220303171818.11060-1-aford173@gmail.com> +Signed-off-by: Tony Lindgren +Signed-off-by: Sasha Levin +--- + arch/arm/boot/dts/logicpd-som-lv-35xx-devkit.dts | 15 +++++++++++++++ + arch/arm/boot/dts/logicpd-som-lv-37xx-devkit.dts | 15 +++++++++++++++ + arch/arm/boot/dts/logicpd-som-lv.dtsi | 15 --------------- + 3 files changed, 30 insertions(+), 15 deletions(-) + +diff --git a/arch/arm/boot/dts/logicpd-som-lv-35xx-devkit.dts b/arch/arm/boot/dts/logicpd-som-lv-35xx-devkit.dts +index 32d0dc371fc3..4cd72b5e612b 100644 +--- a/arch/arm/boot/dts/logicpd-som-lv-35xx-devkit.dts ++++ b/arch/arm/boot/dts/logicpd-som-lv-35xx-devkit.dts +@@ -15,3 +15,18 @@ / { + model = "LogicPD Zoom OMAP35xx SOM-LV Development Kit"; + compatible = "logicpd,dm3730-som-lv-devkit", "ti,omap3"; + }; ++ ++&omap3_pmx_core2 { ++ pinctrl-names = "default"; ++ pinctrl-0 = <&hsusb2_2_pins>; ++ hsusb2_2_pins: pinmux_hsusb2_2_pins { ++ pinctrl-single,pins = < ++ OMAP3430_CORE2_IOPAD(0x25f0, PIN_OUTPUT | MUX_MODE3) /* etk_d10.hsusb2_clk */ ++ OMAP3430_CORE2_IOPAD(0x25f2, PIN_OUTPUT | MUX_MODE3) /* etk_d11.hsusb2_stp */ ++ OMAP3430_CORE2_IOPAD(0x25f4, PIN_INPUT_PULLDOWN | MUX_MODE3) /* etk_d12.hsusb2_dir */ ++ OMAP3430_CORE2_IOPAD(0x25f6, PIN_INPUT_PULLDOWN | MUX_MODE3) /* etk_d13.hsusb2_nxt */ ++ OMAP3430_CORE2_IOPAD(0x25f8, PIN_INPUT_PULLDOWN | MUX_MODE3) /* etk_d14.hsusb2_data0 */ ++ OMAP3430_CORE2_IOPAD(0x25fa, PIN_INPUT_PULLDOWN | MUX_MODE3) /* etk_d15.hsusb2_data1 */ ++ >; ++ }; ++}; +diff --git a/arch/arm/boot/dts/logicpd-som-lv-37xx-devkit.dts b/arch/arm/boot/dts/logicpd-som-lv-37xx-devkit.dts +index 24283739526c..2aca9111c699 100644 +--- a/arch/arm/boot/dts/logicpd-som-lv-37xx-devkit.dts ++++ b/arch/arm/boot/dts/logicpd-som-lv-37xx-devkit.dts +@@ -15,3 +15,18 @@ / { + model = "LogicPD Zoom DM3730 SOM-LV Development Kit"; + compatible = "logicpd,dm3730-som-lv-devkit", "ti,omap3630", "ti,omap3"; + }; ++ ++&omap3_pmx_core2 { ++ pinctrl-names = "default"; ++ pinctrl-0 = <&hsusb2_2_pins>; ++ hsusb2_2_pins: pinmux_hsusb2_2_pins { ++ pinctrl-single,pins = < ++ OMAP3630_CORE2_IOPAD(0x25f0, PIN_OUTPUT | MUX_MODE3) /* etk_d10.hsusb2_clk */ ++ OMAP3630_CORE2_IOPAD(0x25f2, PIN_OUTPUT | MUX_MODE3) /* etk_d11.hsusb2_stp */ ++ OMAP3630_CORE2_IOPAD(0x25f4, PIN_INPUT_PULLDOWN | MUX_MODE3) /* etk_d12.hsusb2_dir */ ++ OMAP3630_CORE2_IOPAD(0x25f6, PIN_INPUT_PULLDOWN | MUX_MODE3) /* etk_d13.hsusb2_nxt */ ++ OMAP3630_CORE2_IOPAD(0x25f8, PIN_INPUT_PULLDOWN | MUX_MODE3) /* etk_d14.hsusb2_data0 */ ++ OMAP3630_CORE2_IOPAD(0x25fa, PIN_INPUT_PULLDOWN | MUX_MODE3) /* etk_d15.hsusb2_data1 */ ++ >; ++ }; ++}; +diff --git a/arch/arm/boot/dts/logicpd-som-lv.dtsi b/arch/arm/boot/dts/logicpd-som-lv.dtsi +index c5d54c4d3747..499eea86e102 100644 +--- a/arch/arm/boot/dts/logicpd-som-lv.dtsi ++++ b/arch/arm/boot/dts/logicpd-som-lv.dtsi +@@ -269,21 +269,6 @@ OMAP3_WKUP_IOPAD(0x2a0c, PIN_OUTPUT | MUX_MODE4) /* sys_boot1.gpio_3 */ + }; + }; + +-&omap3_pmx_core2 { +- pinctrl-names = "default"; +- pinctrl-0 = <&hsusb2_2_pins>; +- hsusb2_2_pins: pinmux_hsusb2_2_pins { +- pinctrl-single,pins = < +- OMAP3630_CORE2_IOPAD(0x25f0, PIN_OUTPUT | MUX_MODE3) /* etk_d10.hsusb2_clk */ +- OMAP3630_CORE2_IOPAD(0x25f2, PIN_OUTPUT | MUX_MODE3) /* etk_d11.hsusb2_stp */ +- OMAP3630_CORE2_IOPAD(0x25f4, PIN_INPUT_PULLDOWN | MUX_MODE3) /* etk_d12.hsusb2_dir */ +- OMAP3630_CORE2_IOPAD(0x25f6, PIN_INPUT_PULLDOWN | MUX_MODE3) /* etk_d13.hsusb2_nxt */ +- OMAP3630_CORE2_IOPAD(0x25f8, PIN_INPUT_PULLDOWN | MUX_MODE3) /* etk_d14.hsusb2_data0 */ +- OMAP3630_CORE2_IOPAD(0x25fa, PIN_INPUT_PULLDOWN | MUX_MODE3) /* etk_d15.hsusb2_data1 */ +- >; +- }; +-}; +- + &uart2 { + interrupts-extended = <&intc 73 &omap3_pmx_core OMAP3_UART2_RX>; + pinctrl-names = "default"; +-- +2.35.1 + diff --git a/queue-4.19/arm-omap2-fix-refcount-leak-in-omap_gic_of_init.patch b/queue-4.19/arm-omap2-fix-refcount-leak-in-omap_gic_of_init.patch new file mode 100644 index 00000000000..877dfe74c84 --- /dev/null +++ b/queue-4.19/arm-omap2-fix-refcount-leak-in-omap_gic_of_init.patch @@ -0,0 +1,42 @@ +From c37bf3ad868e393eb5c905cf625e20a35d63d957 Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Wed, 9 Mar 2022 10:43:01 +0000 +Subject: ARM: OMAP2+: Fix refcount leak in omap_gic_of_init + +From: Miaoqian Lin + +[ Upstream commit 0f83e6b4161617014017a694888dd8743f46f071 ] + +The of_find_compatible_node() function returns a node pointer with +refcount incremented, We should use of_node_put() on it when done +Add the missing of_node_put() to release the refcount. + +Fixes: fd1c07861491 ("ARM: OMAP4: Fix the init code to have OMAP4460 errata available in DT build") +Signed-off-by: Miaoqian Lin +Message-Id: <20220309104302.18398-1-linmq006@gmail.com> +Signed-off-by: Tony Lindgren +Signed-off-by: Sasha Levin +--- + arch/arm/mach-omap2/omap4-common.c | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/arch/arm/mach-omap2/omap4-common.c b/arch/arm/mach-omap2/omap4-common.c +index 7074cfd1ff41..79a1e4c51e3d 100644 +--- a/arch/arm/mach-omap2/omap4-common.c ++++ b/arch/arm/mach-omap2/omap4-common.c +@@ -318,10 +318,12 @@ void __init omap_gic_of_init(void) + + np = of_find_compatible_node(NULL, NULL, "arm,cortex-a9-gic"); + gic_dist_base_addr = of_iomap(np, 0); ++ of_node_put(np); + WARN_ON(!gic_dist_base_addr); + + np = of_find_compatible_node(NULL, NULL, "arm,cortex-a9-twd-timer"); + twd_base = of_iomap(np, 0); ++ of_node_put(np); + WARN_ON(!twd_base); + + skip_errata_init: +-- +2.35.1 + diff --git a/queue-4.19/asoc-wm8731-disable-the-regulator-when-probing-fails.patch b/queue-4.19/asoc-wm8731-disable-the-regulator-when-probing-fails.patch new file mode 100644 index 00000000000..e1a4e300c5a --- /dev/null +++ b/queue-4.19/asoc-wm8731-disable-the-regulator-when-probing-fails.patch @@ -0,0 +1,90 @@ +From 0b266d8faa21428d02f54b0cd10b7d52159018d4 Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Tue, 5 Apr 2022 20:10:38 +0800 +Subject: ASoC: wm8731: Disable the regulator when probing fails + +From: Zheyu Ma + +[ Upstream commit 92ccbf17eeacf510cf1eed9c252d9332ca24f02d ] + +When the driver fails during probing, the driver should disable the +regulator, not just handle it in wm8731_hw_init(). + +The following log reveals it: + +[ 17.812483] WARNING: CPU: 1 PID: 364 at drivers/regulator/core.c:2257 _regulator_put+0x3ec/0x4e0 +[ 17.815958] RIP: 0010:_regulator_put+0x3ec/0x4e0 +[ 17.824467] Call Trace: +[ 17.824774] +[ 17.825040] regulator_bulk_free+0x82/0xe0 +[ 17.825514] devres_release_group+0x319/0x3d0 +[ 17.825882] i2c_device_probe+0x766/0x940 +[ 17.829198] i2c_register_driver+0xb5/0x130 + +Signed-off-by: Zheyu Ma +Link: https://lore.kernel.org/r/20220405121038.4094051-1-zheyuma97@gmail.com +Signed-off-by: Mark Brown +Signed-off-by: Sasha Levin +--- + sound/soc/codecs/wm8731.c | 19 +++++++++++-------- + 1 file changed, 11 insertions(+), 8 deletions(-) + +diff --git a/sound/soc/codecs/wm8731.c b/sound/soc/codecs/wm8731.c +index 7c8fad865d6b..3c5c02b034a9 100644 +--- a/sound/soc/codecs/wm8731.c ++++ b/sound/soc/codecs/wm8731.c +@@ -604,7 +604,7 @@ static int wm8731_hw_init(struct device *dev, struct wm8731_priv *wm8731) + ret = wm8731_reset(wm8731->regmap); + if (ret < 0) { + dev_err(dev, "Failed to issue reset: %d\n", ret); +- goto err_regulator_enable; ++ goto err; + } + + /* Clear POWEROFF, keep everything else disabled */ +@@ -621,10 +621,7 @@ static int wm8731_hw_init(struct device *dev, struct wm8731_priv *wm8731) + + regcache_mark_dirty(wm8731->regmap); + +-err_regulator_enable: +- /* Regulators will be enabled by bias management */ +- regulator_bulk_disable(ARRAY_SIZE(wm8731->supplies), wm8731->supplies); +- ++err: + return ret; + } + +@@ -768,21 +765,27 @@ static int wm8731_i2c_probe(struct i2c_client *i2c, + ret = PTR_ERR(wm8731->regmap); + dev_err(&i2c->dev, "Failed to allocate register map: %d\n", + ret); +- return ret; ++ goto err_regulator_enable; + } + + ret = wm8731_hw_init(&i2c->dev, wm8731); + if (ret != 0) +- return ret; ++ goto err_regulator_enable; + + ret = devm_snd_soc_register_component(&i2c->dev, + &soc_component_dev_wm8731, &wm8731_dai, 1); + if (ret != 0) { + dev_err(&i2c->dev, "Failed to register CODEC: %d\n", ret); +- return ret; ++ goto err_regulator_enable; + } + + return 0; ++ ++err_regulator_enable: ++ /* Regulators will be enabled by bias management */ ++ regulator_bulk_disable(ARRAY_SIZE(wm8731->supplies), wm8731->supplies); ++ ++ return ret; + } + + static int wm8731_i2c_remove(struct i2c_client *client) +-- +2.35.1 + diff --git a/queue-4.19/bnx2x-fix-napi-api-usage-sequence.patch b/queue-4.19/bnx2x-fix-napi-api-usage-sequence.patch new file mode 100644 index 00000000000..ab3ad96c19b --- /dev/null +++ b/queue-4.19/bnx2x-fix-napi-api-usage-sequence.patch @@ -0,0 +1,152 @@ +From b70b8dcc29e1148e1ced06f0c91a5ca24728ec18 Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Tue, 26 Apr 2022 08:39:13 -0700 +Subject: bnx2x: fix napi API usage sequence + +From: Manish Chopra + +[ Upstream commit af68656d66eda219b7f55ce8313a1da0312c79e1 ] + +While handling PCI errors (AER flow) driver tries to +disable NAPI [napi_disable()] after NAPI is deleted +[__netif_napi_del()] which causes unexpected system +hang/crash. + +System message log shows the following: +======================================= +[ 3222.537510] EEH: Detected PCI bus error on PHB#384-PE#800000 [ 3222.537511] EEH: This PCI device has failed 2 times in the last hour and will be permanently disabled after 5 failures. +[ 3222.537512] EEH: Notify device drivers to shutdown [ 3222.537513] EEH: Beginning: 'error_detected(IO frozen)' +[ 3222.537514] EEH: PE#800000 (PCI 0384:80:00.0): Invoking +bnx2x->error_detected(IO frozen) +[ 3222.537516] bnx2x: [bnx2x_io_error_detected:14236(eth14)]IO error detected [ 3222.537650] EEH: PE#800000 (PCI 0384:80:00.0): bnx2x driver reports: +'need reset' +[ 3222.537651] EEH: PE#800000 (PCI 0384:80:00.1): Invoking +bnx2x->error_detected(IO frozen) +[ 3222.537651] bnx2x: [bnx2x_io_error_detected:14236(eth13)]IO error detected [ 3222.537729] EEH: PE#800000 (PCI 0384:80:00.1): bnx2x driver reports: +'need reset' +[ 3222.537729] EEH: Finished:'error_detected(IO frozen)' with aggregate recovery state:'need reset' +[ 3222.537890] EEH: Collect temporary log [ 3222.583481] EEH: of node=0384:80:00.0 [ 3222.583519] EEH: PCI device/vendor: 168e14e4 [ 3222.583557] EEH: PCI cmd/status register: 00100140 [ 3222.583557] EEH: PCI-E capabilities and status follow: +[ 3222.583744] EEH: PCI-E 00: 00020010 012c8da2 00095d5e 00455c82 [ 3222.583892] EEH: PCI-E 10: 10820000 00000000 00000000 00000000 [ 3222.583893] EEH: PCI-E 20: 00000000 [ 3222.583893] EEH: PCI-E AER capability register set follows: +[ 3222.584079] EEH: PCI-E AER 00: 13c10001 00000000 00000000 00062030 [ 3222.584230] EEH: PCI-E AER 10: 00002000 000031c0 000001e0 00000000 [ 3222.584378] EEH: PCI-E AER 20: 00000000 00000000 00000000 00000000 [ 3222.584416] EEH: PCI-E AER 30: 00000000 00000000 [ 3222.584416] EEH: of node=0384:80:00.1 [ 3222.584454] EEH: PCI device/vendor: 168e14e4 [ 3222.584491] EEH: PCI cmd/status register: 00100140 [ 3222.584492] EEH: PCI-E capabilities and status follow: +[ 3222.584677] EEH: PCI-E 00: 00020010 012c8da2 00095d5e 00455c82 [ 3222.584825] EEH: PCI-E 10: 10820000 00000000 00000000 00000000 [ 3222.584826] EEH: PCI-E 20: 00000000 [ 3222.584826] EEH: PCI-E AER capability register set follows: +[ 3222.585011] EEH: PCI-E AER 00: 13c10001 00000000 00000000 00062030 [ 3222.585160] EEH: PCI-E AER 10: 00002000 000031c0 000001e0 00000000 [ 3222.585309] EEH: PCI-E AER 20: 00000000 00000000 00000000 00000000 [ 3222.585347] EEH: PCI-E AER 30: 00000000 00000000 [ 3222.586872] RTAS: event: 5, Type: Platform Error (224), Severity: 2 [ 3222.586873] EEH: Reset without hotplug activity [ 3224.762767] EEH: Beginning: 'slot_reset' +[ 3224.762770] EEH: PE#800000 (PCI 0384:80:00.0): Invoking +bnx2x->slot_reset() +[ 3224.762771] bnx2x: [bnx2x_io_slot_reset:14271(eth14)]IO slot reset initializing... +[ 3224.762887] bnx2x 0384:80:00.0: enabling device (0140 -> 0142) [ 3224.768157] bnx2x: [bnx2x_io_slot_reset:14287(eth14)]IO slot reset +--> driver unload + +Uninterruptible tasks +===================== +crash> ps | grep UN + 213 2 11 c000000004c89e00 UN 0.0 0 0 [eehd] + 215 2 0 c000000004c80000 UN 0.0 0 0 +[kworker/0:2] + 2196 1 28 c000000004504f00 UN 0.1 15936 11136 wickedd + 4287 1 9 c00000020d076800 UN 0.0 4032 3008 agetty + 4289 1 20 c00000020d056680 UN 0.0 7232 3840 agetty + 32423 2 26 c00000020038c580 UN 0.0 0 0 +[kworker/26:3] + 32871 4241 27 c0000002609ddd00 UN 0.1 18624 11648 sshd + 32920 10130 16 c00000027284a100 UN 0.1 48512 12608 sendmail + 33092 32987 0 c000000205218b00 UN 0.1 48512 12608 sendmail + 33154 4567 16 c000000260e51780 UN 0.1 48832 12864 pickup + 33209 4241 36 c000000270cb6500 UN 0.1 18624 11712 sshd + 33473 33283 0 c000000205211480 UN 0.1 48512 12672 sendmail + 33531 4241 37 c00000023c902780 UN 0.1 18624 11648 sshd + +EEH handler hung while bnx2x sleeping and holding RTNL lock +=========================================================== +crash> bt 213 +PID: 213 TASK: c000000004c89e00 CPU: 11 COMMAND: "eehd" + #0 [c000000004d477e0] __schedule at c000000000c70808 + #1 [c000000004d478b0] schedule at c000000000c70ee0 + #2 [c000000004d478e0] schedule_timeout at c000000000c76dec + #3 [c000000004d479c0] msleep at c0000000002120cc + #4 [c000000004d479f0] napi_disable at c000000000a06448 + ^^^^^^^^^^^^^^^^ + #5 [c000000004d47a30] bnx2x_netif_stop at c0080000018dba94 [bnx2x] + #6 [c000000004d47a60] bnx2x_io_slot_reset at c0080000018a551c [bnx2x] + #7 [c000000004d47b20] eeh_report_reset at c00000000004c9bc + #8 [c000000004d47b90] eeh_pe_report at c00000000004d1a8 + #9 [c000000004d47c40] eeh_handle_normal_event at c00000000004da64 + +And the sleeping source code +============================ +crash> dis -ls c000000000a06448 +FILE: ../net/core/dev.c +LINE: 6702 + + 6697 { + 6698 might_sleep(); + 6699 set_bit(NAPI_STATE_DISABLE, &n->state); + 6700 + 6701 while (test_and_set_bit(NAPI_STATE_SCHED, &n->state)) +* 6702 msleep(1); + 6703 while (test_and_set_bit(NAPI_STATE_NPSVC, &n->state)) + 6704 msleep(1); + 6705 + 6706 hrtimer_cancel(&n->timer); + 6707 + 6708 clear_bit(NAPI_STATE_DISABLE, &n->state); + 6709 } + +EEH calls into bnx2x twice based on the system log above, first through +bnx2x_io_error_detected() and then bnx2x_io_slot_reset(), and executes +the following call chains: + +bnx2x_io_error_detected() + +-> bnx2x_eeh_nic_unload() + +-> bnx2x_del_all_napi() + +-> __netif_napi_del() + +bnx2x_io_slot_reset() + +-> bnx2x_netif_stop() + +-> bnx2x_napi_disable() + +->napi_disable() + +Fix this by correcting the sequence of NAPI APIs usage, +that is delete the NAPI after disabling it. + +Fixes: 7fa6f34081f1 ("bnx2x: AER revised") +Reported-by: David Christensen +Tested-by: David Christensen +Signed-off-by: Manish Chopra +Signed-off-by: Ariel Elior +Link: https://lore.kernel.org/r/20220426153913.6966-1-manishc@marvell.com +Signed-off-by: Jakub Kicinski +Signed-off-by: Sasha Levin +--- + drivers/net/ethernet/broadcom/bnx2x/bnx2x_main.c | 9 +++++---- + 1 file changed, 5 insertions(+), 4 deletions(-) + +diff --git a/drivers/net/ethernet/broadcom/bnx2x/bnx2x_main.c b/drivers/net/ethernet/broadcom/bnx2x/bnx2x_main.c +index df4f77ad95c4..91ddde4d647c 100644 +--- a/drivers/net/ethernet/broadcom/bnx2x/bnx2x_main.c ++++ b/drivers/net/ethernet/broadcom/bnx2x/bnx2x_main.c +@@ -14297,10 +14297,6 @@ static int bnx2x_eeh_nic_unload(struct bnx2x *bp) + + /* Stop Tx */ + bnx2x_tx_disable(bp); +- /* Delete all NAPI objects */ +- bnx2x_del_all_napi(bp); +- if (CNIC_LOADED(bp)) +- bnx2x_del_all_napi_cnic(bp); + netdev_reset_tc(bp->dev); + + del_timer_sync(&bp->timer); +@@ -14405,6 +14401,11 @@ static pci_ers_result_t bnx2x_io_slot_reset(struct pci_dev *pdev) + bnx2x_drain_tx_queues(bp); + bnx2x_send_unload_req(bp, UNLOAD_RECOVERY); + bnx2x_netif_stop(bp, 1); ++ bnx2x_del_all_napi(bp); ++ ++ if (CNIC_LOADED(bp)) ++ bnx2x_del_all_napi_cnic(bp); ++ + bnx2x_free_irq(bp); + + /* Report UNLOAD_DONE to MCP */ +-- +2.35.1 + diff --git a/queue-4.19/bus-sunxi-rsb-fix-the-return-value-of-sunxi_rsb_devi.patch b/queue-4.19/bus-sunxi-rsb-fix-the-return-value-of-sunxi_rsb_devi.patch new file mode 100644 index 00000000000..676f1afad3a --- /dev/null +++ b/queue-4.19/bus-sunxi-rsb-fix-the-return-value-of-sunxi_rsb_devi.patch @@ -0,0 +1,43 @@ +From e69906e0f3e49fe7c8b90500f312c23bfcf969ef Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Thu, 21 Apr 2022 16:35:49 +0200 +Subject: bus: sunxi-rsb: Fix the return value of sunxi_rsb_device_create() + +From: Christophe JAILLET + +[ Upstream commit fff8c10368e64e7f8960f149375c12ca5f3b30af ] + +This code is really spurious. +It always returns an ERR_PTR, even when err is known to be 0 and calls +put_device() after a successful device_register() call. + +It is likely that the return statement in the normal path is missing. +Add 'return rdev;' to fix it. + +Fixes: d787dcdb9c8f ("bus: sunxi-rsb: Add driver for Allwinner Reduced Serial Bus") +Signed-off-by: Christophe JAILLET +Reviewed-by: Samuel Holland +Tested-by: Samuel Holland +Signed-off-by: Jernej Skrabec +Link: https://lore.kernel.org/r/ef2b9576350bba4c8e05e669e9535e9e2a415763.1650551719.git.christophe.jaillet@wanadoo.fr +Signed-off-by: Sasha Levin +--- + drivers/bus/sunxi-rsb.c | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/drivers/bus/sunxi-rsb.c b/drivers/bus/sunxi-rsb.c +index 2ca2cc56bcef..b85d013a9185 100644 +--- a/drivers/bus/sunxi-rsb.c ++++ b/drivers/bus/sunxi-rsb.c +@@ -224,6 +224,8 @@ static struct sunxi_rsb_device *sunxi_rsb_device_create(struct sunxi_rsb *rsb, + + dev_dbg(&rdev->dev, "device %s registered\n", dev_name(&rdev->dev)); + ++ return rdev; ++ + err_device_add: + put_device(&rdev->dev); + +-- +2.35.1 + diff --git a/queue-4.19/cifs-destage-any-unwritten-data-to-the-server-before.patch b/queue-4.19/cifs-destage-any-unwritten-data-to-the-server-before.patch new file mode 100644 index 00000000000..7abb23d9268 --- /dev/null +++ b/queue-4.19/cifs-destage-any-unwritten-data-to-the-server-before.patch @@ -0,0 +1,59 @@ +From cce2bea73f7a294b07980a79f1784a46505e608a Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Thu, 21 Apr 2022 11:15:36 +1000 +Subject: cifs: destage any unwritten data to the server before calling + copychunk_write + +From: Ronnie Sahlberg + +[ Upstream commit f5d0f921ea362636e4a2efb7c38d1ead373a8700 ] + +because the copychunk_write might cover a region of the file that has not yet +been sent to the server and thus fail. + +A simple way to reproduce this is: +truncate -s 0 /mnt/testfile; strace -f -o x -ttT xfs_io -i -f -c 'pwrite 0k 128k' -c 'fcollapse 16k 24k' /mnt/testfile + +the issue is that the 'pwrite 0k 128k' becomes rearranged on the wire with +the 'fcollapse 16k 24k' due to write-back caching. + +fcollapse is implemented in cifs.ko as a SMB2 IOCTL(COPYCHUNK_WRITE) call +and it will fail serverside since the file is still 0b in size serverside +until the writes have been destaged. +To avoid this we must ensure that we destage any unwritten data to the +server before calling COPYCHUNK_WRITE. + +Bugzilla: https://bugzilla.redhat.com/show_bug.cgi?id=1997373 +Reported-by: Xiaoli Feng +Signed-off-by: Ronnie Sahlberg +Signed-off-by: Steve French +Signed-off-by: Sasha Levin +--- + fs/cifs/smb2ops.c | 8 ++++++++ + 1 file changed, 8 insertions(+) + +diff --git a/fs/cifs/smb2ops.c b/fs/cifs/smb2ops.c +index 61955a7c838b..cc34a28aecbc 100644 +--- a/fs/cifs/smb2ops.c ++++ b/fs/cifs/smb2ops.c +@@ -1144,9 +1144,17 @@ smb2_copychunk_range(const unsigned int xid, + int chunks_copied = 0; + bool chunk_sizes_updated = false; + ssize_t bytes_written, total_bytes_written = 0; ++ struct inode *inode; + + pcchunk = kmalloc(sizeof(struct copychunk_ioctl), GFP_KERNEL); + ++ /* ++ * We need to flush all unwritten data before we can send the ++ * copychunk ioctl to the server. ++ */ ++ inode = d_inode(trgtfile->dentry); ++ filemap_write_and_wait(inode->i_mapping); ++ + if (pcchunk == NULL) + return -ENOMEM; + +-- +2.35.1 + diff --git a/queue-4.19/clk-sunxi-sun9i-mmc-check-return-value-after-calling.patch b/queue-4.19/clk-sunxi-sun9i-mmc-check-return-value-after-calling.patch new file mode 100644 index 00000000000..65527019e14 --- /dev/null +++ b/queue-4.19/clk-sunxi-sun9i-mmc-check-return-value-after-calling.patch @@ -0,0 +1,39 @@ +From 9d11aa45aefa9ee1f8183945090dad8b7e1a7834 Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Thu, 21 Apr 2022 21:43:08 +0800 +Subject: clk: sunxi: sun9i-mmc: check return value after calling + platform_get_resource() + +From: Yang Yingliang + +[ Upstream commit f58ca215cda1975f77b2b762903684a3c101bec9 ] + +It will cause null-ptr-deref if platform_get_resource() returns NULL, +we need check the return value. + +Fixes: 7a6fca879f59 ("clk: sunxi: Add driver for A80 MMC config clocks/resets") +Signed-off-by: Yang Yingliang +Reviewed-by: Samuel Holland +Signed-off-by: Jernej Skrabec +Link: https://lore.kernel.org/r/20220421134308.2885094-1-yangyingliang@huawei.com +Signed-off-by: Sasha Levin +--- + drivers/clk/sunxi/clk-sun9i-mmc.c | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/drivers/clk/sunxi/clk-sun9i-mmc.c b/drivers/clk/sunxi/clk-sun9i-mmc.c +index f00d8758ba24..a706ae9a010a 100644 +--- a/drivers/clk/sunxi/clk-sun9i-mmc.c ++++ b/drivers/clk/sunxi/clk-sun9i-mmc.c +@@ -117,6 +117,8 @@ static int sun9i_a80_mmc_config_clk_probe(struct platform_device *pdev) + spin_lock_init(&data->lock); + + r = platform_get_resource(pdev, IORESOURCE_MEM, 0); ++ if (!r) ++ return -EINVAL; + /* one clock/reset pair per word */ + count = DIV_ROUND_UP((resource_size(r)), SUN9I_MMC_WIDTH); + data->membase = devm_ioremap_resource(&pdev->dev, r); +-- +2.35.1 + diff --git a/queue-4.19/drivers-net-hippi-fix-deadlock-in-rr_close.patch b/queue-4.19/drivers-net-hippi-fix-deadlock-in-rr_close.patch new file mode 100644 index 00000000000..ae70a884932 --- /dev/null +++ b/queue-4.19/drivers-net-hippi-fix-deadlock-in-rr_close.patch @@ -0,0 +1,53 @@ +From 2c8bb062800ef3bc09b76734808150f34b34a1c0 Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Sun, 17 Apr 2022 20:55:19 +0800 +Subject: drivers: net: hippi: Fix deadlock in rr_close() + +From: Duoming Zhou + +[ Upstream commit bc6de2878429e85c1f1afaa566f7b5abb2243eef ] + +There is a deadlock in rr_close(), which is shown below: + + (Thread 1) | (Thread 2) + | rr_open() +rr_close() | add_timer() + spin_lock_irqsave() //(1) | (wait a time) + ... | rr_timer() + del_timer_sync() | spin_lock_irqsave() //(2) + (wait timer to stop) | ... + +We hold rrpriv->lock in position (1) of thread 1 and +use del_timer_sync() to wait timer to stop, but timer handler +also need rrpriv->lock in position (2) of thread 2. +As a result, rr_close() will block forever. + +This patch extracts del_timer_sync() from the protection of +spin_lock_irqsave(), which could let timer handler to obtain +the needed lock. + +Signed-off-by: Duoming Zhou +Link: https://lore.kernel.org/r/20220417125519.82618-1-duoming@zju.edu.cn +Signed-off-by: Paolo Abeni +Signed-off-by: Sasha Levin +--- + drivers/net/hippi/rrunner.c | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/drivers/net/hippi/rrunner.c b/drivers/net/hippi/rrunner.c +index 2a8c33abb363..a24c55a6c79a 100644 +--- a/drivers/net/hippi/rrunner.c ++++ b/drivers/net/hippi/rrunner.c +@@ -1352,7 +1352,9 @@ static int rr_close(struct net_device *dev) + + rrpriv->fw_running = 0; + ++ spin_unlock_irqrestore(&rrpriv->lock, flags); + del_timer_sync(&rrpriv->timer); ++ spin_lock_irqsave(&rrpriv->lock, flags); + + writel(0, ®s->TxPi); + writel(0, ®s->IpRxPi); +-- +2.35.1 + diff --git a/queue-4.19/ip6_gre-avoid-updating-tunnel-tun_hlen-in-__gre6_xmi.patch b/queue-4.19/ip6_gre-avoid-updating-tunnel-tun_hlen-in-__gre6_xmi.patch new file mode 100644 index 00000000000..7d36393b7f9 --- /dev/null +++ b/queue-4.19/ip6_gre-avoid-updating-tunnel-tun_hlen-in-__gre6_xmi.patch @@ -0,0 +1,48 @@ +From 3902bc5843bd499782f5fb76084188d645c01479 Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Thu, 14 Apr 2022 13:34:26 -0700 +Subject: ip6_gre: Avoid updating tunnel->tun_hlen in __gre6_xmit() + +From: Peilin Ye + +[ Upstream commit f40c064e933d7787ca7411b699504d7a2664c1f5 ] + +Do not update tunnel->tun_hlen in data plane code. Use a local variable +instead, just like "tunnel_hlen" in net/ipv4/ip_gre.c:gre_fb_xmit(). + +Co-developed-by: Cong Wang +Signed-off-by: Cong Wang +Signed-off-by: Peilin Ye +Signed-off-by: David S. Miller +Signed-off-by: Sasha Levin +--- + net/ipv6/ip6_gre.c | 5 +++-- + 1 file changed, 3 insertions(+), 2 deletions(-) + +diff --git a/net/ipv6/ip6_gre.c b/net/ipv6/ip6_gre.c +index 043e57d08a3e..4fd6c0929b14 100644 +--- a/net/ipv6/ip6_gre.c ++++ b/net/ipv6/ip6_gre.c +@@ -750,6 +750,7 @@ static netdev_tx_t __gre6_xmit(struct sk_buff *skb, + struct ip_tunnel_info *tun_info; + const struct ip_tunnel_key *key; + __be16 flags; ++ int tun_hlen; + + tun_info = skb_tunnel_info(skb); + if (unlikely(!tun_info || +@@ -767,9 +768,9 @@ static netdev_tx_t __gre6_xmit(struct sk_buff *skb, + dsfield = key->tos; + flags = key->tun_flags & + (TUNNEL_CSUM | TUNNEL_KEY | TUNNEL_SEQ); +- tunnel->tun_hlen = gre_calc_hlen(flags); ++ tun_hlen = gre_calc_hlen(flags); + +- gre_build_header(skb, tunnel->tun_hlen, ++ gre_build_header(skb, tun_hlen, + flags, protocol, + tunnel_id_to_key32(tun_info->key.tun_id), + (flags & TUNNEL_SEQ) ? htonl(tunnel->o_seqno++) +-- +2.35.1 + diff --git a/queue-4.19/ip_gre-make-o_seqno-start-from-0-in-native-mode.patch b/queue-4.19/ip_gre-make-o_seqno-start-from-0-in-native-mode.patch new file mode 100644 index 00000000000..ab357d2d10d --- /dev/null +++ b/queue-4.19/ip_gre-make-o_seqno-start-from-0-in-native-mode.patch @@ -0,0 +1,51 @@ +From b91d33351edadce048bd20e2eca6131f1aff36f8 Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Thu, 21 Apr 2022 15:07:57 -0700 +Subject: ip_gre: Make o_seqno start from 0 in native mode + +From: Peilin Ye + +[ Upstream commit ff827beb706ed719c766acf36449801ded0c17fc ] + +For GRE and GRETAP devices, currently o_seqno starts from 1 in native +mode. According to RFC 2890 2.2., "The first datagram is sent with a +sequence number of 0." Fix it. + +It is worth mentioning that o_seqno already starts from 0 in collect_md +mode, see gre_fb_xmit(), where tunnel->o_seqno is passed to +gre_build_header() before getting incremented. + +Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") +Signed-off-by: Peilin Ye +Acked-by: William Tu +Signed-off-by: David S. Miller +Signed-off-by: Sasha Levin +--- + net/ipv4/ip_gre.c | 8 +++----- + 1 file changed, 3 insertions(+), 5 deletions(-) + +diff --git a/net/ipv4/ip_gre.c b/net/ipv4/ip_gre.c +index 0c431fd4b120..41d0f9bb5191 100644 +--- a/net/ipv4/ip_gre.c ++++ b/net/ipv4/ip_gre.c +@@ -435,14 +435,12 @@ static void __gre_xmit(struct sk_buff *skb, struct net_device *dev, + __be16 proto) + { + struct ip_tunnel *tunnel = netdev_priv(dev); +- +- if (tunnel->parms.o_flags & TUNNEL_SEQ) +- tunnel->o_seqno++; ++ __be16 flags = tunnel->parms.o_flags; + + /* Push GRE header. */ + gre_build_header(skb, tunnel->tun_hlen, +- tunnel->parms.o_flags, proto, tunnel->parms.o_key, +- htonl(tunnel->o_seqno)); ++ flags, proto, tunnel->parms.o_key, ++ (flags & TUNNEL_SEQ) ? htonl(tunnel->o_seqno++) : 0); + + ip_tunnel_xmit(skb, dev, tnl_params, tnl_params->protocol); + } +-- +2.35.1 + diff --git a/queue-4.19/ipvs-correctly-print-the-memory-size-of-ip_vs_conn_t.patch b/queue-4.19/ipvs-correctly-print-the-memory-size-of-ip_vs_conn_t.patch new file mode 100644 index 00000000000..f388dfd1c31 --- /dev/null +++ b/queue-4.19/ipvs-correctly-print-the-memory-size-of-ip_vs_conn_t.patch @@ -0,0 +1,38 @@ +From c06b153ed049fc9fe9da5e8db05ad84396216feb Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Tue, 12 Apr 2022 19:05:45 +0800 +Subject: ipvs: correctly print the memory size of ip_vs_conn_tab + +From: Pengcheng Yang + +[ Upstream commit eba1a872cb73314280d5448d934935b23e30b7ca ] + +The memory size of ip_vs_conn_tab changed after we use hlist +instead of list. + +Fixes: 731109e78415 ("ipvs: use hlist instead of list") +Signed-off-by: Pengcheng Yang +Acked-by: Julian Anastasov +Acked-by: Simon Horman +Signed-off-by: Pablo Neira Ayuso +Signed-off-by: Sasha Levin +--- + net/netfilter/ipvs/ip_vs_conn.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/net/netfilter/ipvs/ip_vs_conn.c b/net/netfilter/ipvs/ip_vs_conn.c +index 2780a847701e..95c35aa639ec 100644 +--- a/net/netfilter/ipvs/ip_vs_conn.c ++++ b/net/netfilter/ipvs/ip_vs_conn.c +@@ -1426,7 +1426,7 @@ int __init ip_vs_conn_init(void) + pr_info("Connection hash table configured " + "(size=%d, memory=%ldKbytes)\n", + ip_vs_conn_tab_size, +- (long)(ip_vs_conn_tab_size*sizeof(struct list_head))/1024); ++ (long)(ip_vs_conn_tab_size*sizeof(*ip_vs_conn_tab))/1024); + IP_VS_DBG(0, "Each connection entry needs %zd bytes at least\n", + sizeof(struct ip_vs_conn)); + +-- +2.35.1 + diff --git a/queue-4.19/mtd-rawnand-fix-ecc-parameters-for-mt7622.patch b/queue-4.19/mtd-rawnand-fix-ecc-parameters-for-mt7622.patch new file mode 100644 index 00000000000..6e1afd37fd8 --- /dev/null +++ b/queue-4.19/mtd-rawnand-fix-ecc-parameters-for-mt7622.patch @@ -0,0 +1,99 @@ +From d7f324c1575b9331ecbc5541f07ac304c77c7882 Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Sun, 3 Apr 2022 00:03:13 +0800 +Subject: mtd: rawnand: fix ecc parameters for mt7622 + +From: Chuanhong Guo + +[ Upstream commit 9fe4e0d3cbfe90152137963cc024ecb63db6e8e6 ] + +According to the datasheet, mt7622 only has 5 ECC capabilities instead +of 7, and the decoding error register is arranged as follows: ++------+---------+---------+---------+---------+ +| Bits | 19:15 | 14:10 | 9:5 | 4:0 | ++------+---------+---------+---------+---------+ +| Name | ERRNUM3 | ERRNUM2 | ERRNUM1 | ERRNUM0 | ++------+---------+---------+---------+---------+ +This means err_mask should be 0x1f instead of 0x3f and the number of +bits shifted in mtk_ecc_get_stats should be 5 instead of 8. + +This commit introduces err_shift for the difference in this register +and fix other existing parameters. + +Public MT7622 reference manual can be found on [0] and the info this +commit is based on is from page 656 and page 660. + +[0]: https://wiki.banana-pi.org/Banana_Pi_BPI-R64#Documents + +Fixes: 98dea8d71931 ("mtd: nand: mtk: Support MT7622 NAND flash controller.") +Signed-off-by: Chuanhong Guo +Signed-off-by: Miquel Raynal +Link: https://lore.kernel.org/linux-mtd/20220402160315.919094-1-gch981213@gmail.com +Signed-off-by: Sasha Levin +--- + drivers/mtd/nand/raw/mtk_ecc.c | 12 ++++++++---- + 1 file changed, 8 insertions(+), 4 deletions(-) + +diff --git a/drivers/mtd/nand/raw/mtk_ecc.c b/drivers/mtd/nand/raw/mtk_ecc.c +index 6432bd70c3b3..9e4a78a80802 100644 +--- a/drivers/mtd/nand/raw/mtk_ecc.c ++++ b/drivers/mtd/nand/raw/mtk_ecc.c +@@ -51,6 +51,7 @@ + + struct mtk_ecc_caps { + u32 err_mask; ++ u32 err_shift; + const u8 *ecc_strength; + const u32 *ecc_regs; + u8 num_ecc_strength; +@@ -84,7 +85,7 @@ static const u8 ecc_strength_mt2712[] = { + }; + + static const u8 ecc_strength_mt7622[] = { +- 4, 6, 8, 10, 12, 14, 16 ++ 4, 6, 8, 10, 12 + }; + + enum mtk_ecc_regs { +@@ -229,7 +230,7 @@ void mtk_ecc_get_stats(struct mtk_ecc *ecc, struct mtk_ecc_stats *stats, + for (i = 0; i < sectors; i++) { + offset = (i >> 2) << 2; + err = readl(ecc->regs + ECC_DECENUM0 + offset); +- err = err >> ((i % 4) * 8); ++ err = err >> ((i % 4) * ecc->caps->err_shift); + err &= ecc->caps->err_mask; + if (err == ecc->caps->err_mask) { + /* uncorrectable errors */ +@@ -453,6 +454,7 @@ EXPORT_SYMBOL(mtk_ecc_get_parity_bits); + + static const struct mtk_ecc_caps mtk_ecc_caps_mt2701 = { + .err_mask = 0x3f, ++ .err_shift = 8, + .ecc_strength = ecc_strength_mt2701, + .ecc_regs = mt2701_ecc_regs, + .num_ecc_strength = 20, +@@ -463,6 +465,7 @@ static const struct mtk_ecc_caps mtk_ecc_caps_mt2701 = { + + static const struct mtk_ecc_caps mtk_ecc_caps_mt2712 = { + .err_mask = 0x7f, ++ .err_shift = 8, + .ecc_strength = ecc_strength_mt2712, + .ecc_regs = mt2712_ecc_regs, + .num_ecc_strength = 23, +@@ -472,10 +475,11 @@ static const struct mtk_ecc_caps mtk_ecc_caps_mt2712 = { + }; + + static const struct mtk_ecc_caps mtk_ecc_caps_mt7622 = { +- .err_mask = 0x3f, ++ .err_mask = 0x1f, ++ .err_shift = 5, + .ecc_strength = ecc_strength_mt7622, + .ecc_regs = mt7622_ecc_regs, +- .num_ecc_strength = 7, ++ .num_ecc_strength = 5, + .ecc_mode_shift = 4, + .parity_bits = 13, + .pg_irq_sel = 0, +-- +2.35.1 + diff --git a/queue-4.19/mtd-rawnand-fix-return-value-check-of-wait_for_compl.patch b/queue-4.19/mtd-rawnand-fix-return-value-check-of-wait_for_compl.patch new file mode 100644 index 00000000000..bd406f2cd37 --- /dev/null +++ b/queue-4.19/mtd-rawnand-fix-return-value-check-of-wait_for_compl.patch @@ -0,0 +1,84 @@ +From 988ea7a43d9ef8ffe4bc38ee37dfcb226216ce89 Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Tue, 12 Apr 2022 08:34:31 +0000 +Subject: mtd: rawnand: Fix return value check of wait_for_completion_timeout + +From: Miaoqian Lin + +[ Upstream commit 084c16ab423a8890121b902b405823bfec5b4365 ] + +wait_for_completion_timeout() returns unsigned long not int. +It returns 0 if timed out, and positive if completed. +The check for <= 0 is ambiguous and should be == 0 here +indicating timeout which is the only error case. + +Fixes: 83738d87e3a0 ("mtd: sh_flctl: Add DMA capabilty") +Signed-off-by: Miaoqian Lin +Signed-off-by: Miquel Raynal +Link: https://lore.kernel.org/linux-mtd/20220412083435.29254-1-linmq006@gmail.com +Signed-off-by: Sasha Levin +--- + drivers/mtd/nand/raw/sh_flctl.c | 14 ++++++++------ + 1 file changed, 8 insertions(+), 6 deletions(-) + +diff --git a/drivers/mtd/nand/raw/sh_flctl.c b/drivers/mtd/nand/raw/sh_flctl.c +index 683df1a12989..07ba149fa971 100644 +--- a/drivers/mtd/nand/raw/sh_flctl.c ++++ b/drivers/mtd/nand/raw/sh_flctl.c +@@ -399,7 +399,8 @@ static int flctl_dma_fifo0_transfer(struct sh_flctl *flctl, unsigned long *buf, + dma_addr_t dma_addr; + dma_cookie_t cookie; + uint32_t reg; +- int ret; ++ int ret = 0; ++ unsigned long time_left; + + if (dir == DMA_FROM_DEVICE) { + chan = flctl->chan_fifo0_rx; +@@ -440,13 +441,14 @@ static int flctl_dma_fifo0_transfer(struct sh_flctl *flctl, unsigned long *buf, + goto out; + } + +- ret = ++ time_left = + wait_for_completion_timeout(&flctl->dma_complete, + msecs_to_jiffies(3000)); + +- if (ret <= 0) { ++ if (time_left == 0) { + dmaengine_terminate_all(chan); + dev_err(&flctl->pdev->dev, "wait_for_completion_timeout\n"); ++ ret = -ETIMEDOUT; + } + + out: +@@ -456,7 +458,7 @@ static int flctl_dma_fifo0_transfer(struct sh_flctl *flctl, unsigned long *buf, + + dma_unmap_single(chan->device->dev, dma_addr, len, dir); + +- /* ret > 0 is success */ ++ /* ret == 0 is success */ + return ret; + } + +@@ -480,7 +482,7 @@ static void read_fiforeg(struct sh_flctl *flctl, int rlen, int offset) + + /* initiate DMA transfer */ + if (flctl->chan_fifo0_rx && rlen >= 32 && +- flctl_dma_fifo0_transfer(flctl, buf, rlen, DMA_FROM_DEVICE) > 0) ++ !flctl_dma_fifo0_transfer(flctl, buf, rlen, DMA_FROM_DEVICE)) + goto convert; /* DMA success */ + + /* do polling transfer */ +@@ -539,7 +541,7 @@ static void write_ec_fiforeg(struct sh_flctl *flctl, int rlen, + + /* initiate DMA transfer */ + if (flctl->chan_fifo0_tx && rlen >= 32 && +- flctl_dma_fifo0_transfer(flctl, buf, rlen, DMA_TO_DEVICE) > 0) ++ !flctl_dma_fifo0_transfer(flctl, buf, rlen, DMA_TO_DEVICE)) + return; /* DMA success */ + + /* do polling transfer */ +-- +2.35.1 + diff --git a/queue-4.19/net-bcmgenet-hide-status-block-before-tx-timestampin.patch b/queue-4.19/net-bcmgenet-hide-status-block-before-tx-timestampin.patch new file mode 100644 index 00000000000..e98722855c5 --- /dev/null +++ b/queue-4.19/net-bcmgenet-hide-status-block-before-tx-timestampin.patch @@ -0,0 +1,61 @@ +From fc300273cf7d1bf662d8bb77fcd3caad2585d997 Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Sun, 24 Apr 2022 09:53:07 -0700 +Subject: net: bcmgenet: hide status block before TX timestamping + +From: Jonathan Lemon + +[ Upstream commit acac0541d1d65e81e599ec399d34d184d2424401 ] + +The hardware checksum offloading requires use of a transmit +status block inserted before the outgoing frame data, this was +updated in '9a9ba2a4aaaa ("net: bcmgenet: always enable status blocks")' + +However, skb_tx_timestamp() assumes that it is passed a raw frame +and PTP parsing chokes on this status block. + +Fix this by calling __skb_pull(), which hides the TSB before calling +skb_tx_timestamp(), so an outgoing PTP packet is parsed correctly. + +As the data in the skb has already been set up for DMA, and the +dma_unmap_* calls use a separately stored address, there is no +no effective change in the data transmission. + +Signed-off-by: Jonathan Lemon +Acked-by: Florian Fainelli +Link: https://lore.kernel.org/r/20220424165307.591145-1-jonathan.lemon@gmail.com +Fixes: d03825fba459 ("net: bcmgenet: add skb_tx_timestamp call") +Signed-off-by: Paolo Abeni +Signed-off-by: Sasha Levin +--- + drivers/net/ethernet/broadcom/genet/bcmgenet.c | 7 +++++++ + 1 file changed, 7 insertions(+) + +diff --git a/drivers/net/ethernet/broadcom/genet/bcmgenet.c b/drivers/net/ethernet/broadcom/genet/bcmgenet.c +index d4be107ea4cd..96ef2dd46c78 100644 +--- a/drivers/net/ethernet/broadcom/genet/bcmgenet.c ++++ b/drivers/net/ethernet/broadcom/genet/bcmgenet.c +@@ -1549,6 +1549,11 @@ static struct sk_buff *bcmgenet_put_tx_csum(struct net_device *dev, + return skb; + } + ++static void bcmgenet_hide_tsb(struct sk_buff *skb) ++{ ++ __skb_pull(skb, sizeof(struct status_64)); ++} ++ + static netdev_tx_t bcmgenet_xmit(struct sk_buff *skb, struct net_device *dev) + { + struct bcmgenet_priv *priv = netdev_priv(dev); +@@ -1657,6 +1662,8 @@ static netdev_tx_t bcmgenet_xmit(struct sk_buff *skb, struct net_device *dev) + } + + GENET_CB(skb)->last_cb = tx_cb_ptr; ++ ++ bcmgenet_hide_tsb(skb); + skb_tx_timestamp(skb); + + /* Decrement total BD count and advance our write pointer */ +-- +2.35.1 + diff --git a/queue-4.19/net-hns3-add-validity-check-for-message-data-length.patch b/queue-4.19/net-hns3-add-validity-check-for-message-data-length.patch new file mode 100644 index 00000000000..b2a7be8dbda --- /dev/null +++ b/queue-4.19/net-hns3-add-validity-check-for-message-data-length.patch @@ -0,0 +1,42 @@ +From e516bf701ef2b335057e6ce16b6d59c947d948b0 Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Sun, 24 Apr 2022 20:57:24 +0800 +Subject: net: hns3: add validity check for message data length + +From: Jian Shen + +[ Upstream commit 7d413735cb18ff73aaba3457b16b08332e8d3cc4 ] + +Add validity check for message data length in function +hclge_send_mbx_msg(), avoid unexpected overflow. + +Fixes: dde1a86e93ca ("net: hns3: Add mailbox support to PF driver") +Signed-off-by: Jian Shen +Signed-off-by: Guangbin Huang +Signed-off-by: David S. Miller +Signed-off-by: Sasha Levin +--- + drivers/net/ethernet/hisilicon/hns3/hns3pf/hclge_mbx.c | 7 +++++++ + 1 file changed, 7 insertions(+) + +diff --git a/drivers/net/ethernet/hisilicon/hns3/hns3pf/hclge_mbx.c b/drivers/net/ethernet/hisilicon/hns3/hns3pf/hclge_mbx.c +index 997ca79ed892..7e49188c3009 100644 +--- a/drivers/net/ethernet/hisilicon/hns3/hns3pf/hclge_mbx.c ++++ b/drivers/net/ethernet/hisilicon/hns3/hns3pf/hclge_mbx.c +@@ -60,6 +60,13 @@ static int hclge_send_mbx_msg(struct hclge_vport *vport, u8 *msg, u16 msg_len, + enum hclge_cmd_status status; + struct hclge_desc desc; + ++ if (msg_len > HCLGE_MBX_MAX_MSG_SIZE) { ++ dev_err(&hdev->pdev->dev, ++ "msg data length(=%u) exceeds maximum(=%u)\n", ++ msg_len, HCLGE_MBX_MAX_MSG_SIZE); ++ return -EMSGSIZE; ++ } ++ + resp_pf_to_vf = (struct hclge_mbx_pf_to_vf_cmd *)desc.data; + + hclge_cmd_setup_basic_desc(&desc, HCLGEVF_OPC_MBX_PF_TO_VF, false); +-- +2.35.1 + diff --git a/queue-4.19/phy-samsung-exynos5250-sata-fix-missing-device-put-i.patch b/queue-4.19/phy-samsung-exynos5250-sata-fix-missing-device-put-i.patch new file mode 100644 index 00000000000..eb377961b82 --- /dev/null +++ b/queue-4.19/phy-samsung-exynos5250-sata-fix-missing-device-put-i.patch @@ -0,0 +1,77 @@ +From 390866292cc17a8d92f8f6d1a87bd2d5a61ce323 Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Thu, 7 Apr 2022 11:18:57 +0200 +Subject: phy: samsung: exynos5250-sata: fix missing device put in probe error + paths + +From: Krzysztof Kozlowski + +[ Upstream commit 5c8402c4db45dd55c2c93c8d730f5dfa7c78a702 ] + +The actions of of_find_i2c_device_by_node() in probe function should be +reversed in error paths by putting the reference to obtained device. + +Fixes: bcff4cba41bc ("PHY: Exynos: Add Exynos5250 SATA PHY driver") +Signed-off-by: Krzysztof Kozlowski +Reviewed-by: Alim Akhtar +Link: https://lore.kernel.org/r/20220407091857.230386-2-krzysztof.kozlowski@linaro.org +Signed-off-by: Vinod Koul +Signed-off-by: Sasha Levin +--- + drivers/phy/samsung/phy-exynos5250-sata.c | 20 ++++++++++++++------ + 1 file changed, 14 insertions(+), 6 deletions(-) + +diff --git a/drivers/phy/samsung/phy-exynos5250-sata.c b/drivers/phy/samsung/phy-exynos5250-sata.c +index 7960c69d09a6..2c39d2fd3cd8 100644 +--- a/drivers/phy/samsung/phy-exynos5250-sata.c ++++ b/drivers/phy/samsung/phy-exynos5250-sata.c +@@ -202,20 +202,21 @@ static int exynos_sata_phy_probe(struct platform_device *pdev) + sata_phy->phyclk = devm_clk_get(dev, "sata_phyctrl"); + if (IS_ERR(sata_phy->phyclk)) { + dev_err(dev, "failed to get clk for PHY\n"); +- return PTR_ERR(sata_phy->phyclk); ++ ret = PTR_ERR(sata_phy->phyclk); ++ goto put_dev; + } + + ret = clk_prepare_enable(sata_phy->phyclk); + if (ret < 0) { + dev_err(dev, "failed to enable source clk\n"); +- return ret; ++ goto put_dev; + } + + sata_phy->phy = devm_phy_create(dev, NULL, &exynos_sata_phy_ops); + if (IS_ERR(sata_phy->phy)) { +- clk_disable_unprepare(sata_phy->phyclk); + dev_err(dev, "failed to create PHY\n"); +- return PTR_ERR(sata_phy->phy); ++ ret = PTR_ERR(sata_phy->phy); ++ goto clk_disable; + } + + phy_set_drvdata(sata_phy->phy, sata_phy); +@@ -223,11 +224,18 @@ static int exynos_sata_phy_probe(struct platform_device *pdev) + phy_provider = devm_of_phy_provider_register(dev, + of_phy_simple_xlate); + if (IS_ERR(phy_provider)) { +- clk_disable_unprepare(sata_phy->phyclk); +- return PTR_ERR(phy_provider); ++ ret = PTR_ERR(phy_provider); ++ goto clk_disable; + } + + return 0; ++ ++clk_disable: ++ clk_disable_unprepare(sata_phy->phyclk); ++put_dev: ++ put_device(&sata_phy->client->dev); ++ ++ return ret; + } + + static const struct of_device_id exynos_sata_phy_of_match[] = { +-- +2.35.1 + diff --git a/queue-4.19/phy-samsung-fix-missing-of_node_put-in-exynos_sata_p.patch b/queue-4.19/phy-samsung-fix-missing-of_node_put-in-exynos_sata_p.patch new file mode 100644 index 00000000000..6842cfb562e --- /dev/null +++ b/queue-4.19/phy-samsung-fix-missing-of_node_put-in-exynos_sata_p.patch @@ -0,0 +1,38 @@ +From c373f9811eb87fca124aed5692c0a04dc62250ed Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Thu, 7 Apr 2022 11:18:56 +0200 +Subject: phy: samsung: Fix missing of_node_put() in exynos_sata_phy_probe + +From: Miaoqian Lin + +[ Upstream commit 388ec8f079f2f20d5cd183c3bc6f33cbc3ffd3ef ] + +The device_node pointer is returned by of_parse_phandle() with refcount +incremented. We should use of_node_put() on it when done. + +Fixes: bcff4cba41bc ("PHY: Exynos: Add Exynos5250 SATA PHY driver") +Signed-off-by: Miaoqian Lin +Reviewed-by: Krzysztof Kozlowski +Signed-off-by: Krzysztof Kozlowski +Link: https://lore.kernel.org/r/20220407091857.230386-1-krzysztof.kozlowski@linaro.org +Signed-off-by: Vinod Koul +Signed-off-by: Sasha Levin +--- + drivers/phy/samsung/phy-exynos5250-sata.c | 1 + + 1 file changed, 1 insertion(+) + +diff --git a/drivers/phy/samsung/phy-exynos5250-sata.c b/drivers/phy/samsung/phy-exynos5250-sata.c +index 60e13afcd9b8..7960c69d09a6 100644 +--- a/drivers/phy/samsung/phy-exynos5250-sata.c ++++ b/drivers/phy/samsung/phy-exynos5250-sata.c +@@ -193,6 +193,7 @@ static int exynos_sata_phy_probe(struct platform_device *pdev) + return -EINVAL; + + sata_phy->client = of_find_i2c_device_by_node(node); ++ of_node_put(node); + if (!sata_phy->client) + return -EPROBE_DEFER; + +-- +2.35.1 + diff --git a/queue-4.19/pinctrl-pistachio-fix-use-of-irq_of_parse_and_map.patch b/queue-4.19/pinctrl-pistachio-fix-use-of-irq_of_parse_and_map.patch new file mode 100644 index 00000000000..7cf612b98de --- /dev/null +++ b/queue-4.19/pinctrl-pistachio-fix-use-of-irq_of_parse_and_map.patch @@ -0,0 +1,43 @@ +From c007be95b512d6f50e521506dd8cb0199a39415d Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Sun, 24 Apr 2022 03:14:30 +0000 +Subject: pinctrl: pistachio: fix use of irq_of_parse_and_map() + +From: Lv Ruyi + +[ Upstream commit 0c9843a74a85224a89daa81fa66891dae2f930e1 ] + +The irq_of_parse_and_map() function returns 0 on failure, and does not +return an negative value. + +Fixes: cefc03e5995e ("pinctrl: Add Pistachio SoC pin control driver") +Reported-by: Zeal Robot +Signed-off-by: Lv Ruyi +Link: https://lore.kernel.org/r/20220424031430.3170759-1-lv.ruyi@zte.com.cn +Signed-off-by: Linus Walleij +Signed-off-by: Sasha Levin +--- + drivers/pinctrl/pinctrl-pistachio.c | 6 +++--- + 1 file changed, 3 insertions(+), 3 deletions(-) + +diff --git a/drivers/pinctrl/pinctrl-pistachio.c b/drivers/pinctrl/pinctrl-pistachio.c +index 0d7d379e9bb8..fb7340ad15b3 100644 +--- a/drivers/pinctrl/pinctrl-pistachio.c ++++ b/drivers/pinctrl/pinctrl-pistachio.c +@@ -1374,10 +1374,10 @@ static int pistachio_gpio_register(struct pistachio_pinctrl *pctl) + } + + irq = irq_of_parse_and_map(child, 0); +- if (irq < 0) { +- dev_err(pctl->dev, "No IRQ for bank %u: %d\n", i, irq); ++ if (!irq) { ++ dev_err(pctl->dev, "No IRQ for bank %u\n", i); + of_node_put(child); +- ret = irq; ++ ret = -EINVAL; + goto err; + } + +-- +2.35.1 + diff --git a/queue-4.19/sctp-check-asoc-strreset_chunk-in-sctp_generate_reco.patch b/queue-4.19/sctp-check-asoc-strreset_chunk-in-sctp_generate_reco.patch new file mode 100644 index 00000000000..426fec6e66d --- /dev/null +++ b/queue-4.19/sctp-check-asoc-strreset_chunk-in-sctp_generate_reco.patch @@ -0,0 +1,66 @@ +From 2beaaf3350414c34865c1ff8372bf295452e142f Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Wed, 20 Apr 2022 16:52:41 -0400 +Subject: sctp: check asoc strreset_chunk in sctp_generate_reconf_event + +From: Xin Long + +[ Upstream commit 165e3e17fe8fe6a8aab319bc6e631a2e23b9a857 ] + +A null pointer reference issue can be triggered when the response of a +stream reconf request arrives after the timer is triggered, such as: + + send Incoming SSN Reset Request ---> + CPU0: + reconf timer is triggered, + go to the handler code before hold sk lock + <--- reply with Outgoing SSN Reset Request + CPU1: + process Outgoing SSN Reset Request, + and set asoc->strreset_chunk to NULL + CPU0: + continue the handler code, hold sk lock, + and try to hold asoc->strreset_chunk, crash! + +In Ying Xu's testing, the call trace is: + + [ ] BUG: kernel NULL pointer dereference, address: 0000000000000010 + [ ] RIP: 0010:sctp_chunk_hold+0xe/0x40 [sctp] + [ ] Call Trace: + [ ] + [ ] sctp_sf_send_reconf+0x2c/0x100 [sctp] + [ ] sctp_do_sm+0xa4/0x220 [sctp] + [ ] sctp_generate_reconf_event+0xbd/0xe0 [sctp] + [ ] call_timer_fn+0x26/0x130 + +This patch is to fix it by returning from the timer handler if asoc +strreset_chunk is already set to NULL. + +Fixes: 7b9438de0cd4 ("sctp: add stream reconf timer") +Reported-by: Ying Xu +Signed-off-by: Xin Long +Acked-by: Marcelo Ricardo Leitner +Signed-off-by: David S. Miller +Signed-off-by: Sasha Levin +--- + net/sctp/sm_sideeffect.c | 4 ++++ + 1 file changed, 4 insertions(+) + +diff --git a/net/sctp/sm_sideeffect.c b/net/sctp/sm_sideeffect.c +index 2a94240eac36..82d96441e64d 100644 +--- a/net/sctp/sm_sideeffect.c ++++ b/net/sctp/sm_sideeffect.c +@@ -473,6 +473,10 @@ void sctp_generate_reconf_event(struct timer_list *t) + goto out_unlock; + } + ++ /* This happens when the response arrives after the timer is triggered. */ ++ if (!asoc->strreset_chunk) ++ goto out_unlock; ++ + error = sctp_do_sm(net, SCTP_EVENT_T_TIMEOUT, + SCTP_ST_TIMEOUT(SCTP_EVENT_TIMEOUT_RECONF), + asoc->state, asoc->ep, asoc, +-- +2.35.1 + diff --git a/queue-4.19/series b/queue-4.19/series index f33ceefc536..3c0512980fb 100644 --- a/queue-4.19/series +++ b/queue-4.19/series @@ -19,3 +19,30 @@ serial-8250-also-set-sticky-mcr-bits-in-console-restoration.patch serial-8250-correct-the-clock-for-endrun-ptp-1588-pcie-device.patch hex2bin-make-the-function-hex_to_bin-constant-time.patch hex2bin-fix-access-beyond-string-end.patch +mtd-rawnand-fix-ecc-parameters-for-mt7622.patch +usb-fix-xhci-event-ring-dequeue-pointer-erdp-update-.patch +arm-dts-imx6qdl-apalis-fix-sgtl5000-detection-issue.patch +phy-samsung-fix-missing-of_node_put-in-exynos_sata_p.patch +phy-samsung-exynos5250-sata-fix-missing-device-put-i.patch +arm-omap2-fix-refcount-leak-in-omap_gic_of_init.patch +arm-dts-at91-map-mclk-for-wm8731-on-at91sam9g20ek.patch +arm-dts-fix-mmc-order-for-omap3-gta04.patch +arm-dts-logicpd-som-lv-fix-wrong-pinmuxing-on-omap35.patch +ipvs-correctly-print-the-memory-size-of-ip_vs_conn_t.patch +mtd-rawnand-fix-return-value-check-of-wait_for_compl.patch +tcp-md5-incorrect-tcp_header_len-for-incoming-connec.patch +sctp-check-asoc-strreset_chunk-in-sctp_generate_reco.patch +arm-dts-imx6ull-colibri-fix-vqmmc-regulator.patch +pinctrl-pistachio-fix-use-of-irq_of_parse_and_map.patch +net-hns3-add-validity-check-for-message-data-length.patch +ip_gre-make-o_seqno-start-from-0-in-native-mode.patch +tcp-fix-potential-xmit-stalls-caused-by-tcp_notsent_.patch +bus-sunxi-rsb-fix-the-return-value-of-sunxi_rsb_devi.patch +clk-sunxi-sun9i-mmc-check-return-value-after-calling.patch +net-bcmgenet-hide-status-block-before-tx-timestampin.patch +bnx2x-fix-napi-api-usage-sequence.patch +asoc-wm8731-disable-the-regulator-when-probing-fails.patch +ip6_gre-avoid-updating-tunnel-tun_hlen-in-__gre6_xmi.patch +x86-__memcpy_flushcache-fix-wrong-alignment-if-size-.patch +cifs-destage-any-unwritten-data-to-the-server-before.patch +drivers-net-hippi-fix-deadlock-in-rr_close.patch diff --git a/queue-4.19/tcp-fix-potential-xmit-stalls-caused-by-tcp_notsent_.patch b/queue-4.19/tcp-fix-potential-xmit-stalls-caused-by-tcp_notsent_.patch new file mode 100644 index 00000000000..cc3ed8f0760 --- /dev/null +++ b/queue-4.19/tcp-fix-potential-xmit-stalls-caused-by-tcp_notsent_.patch @@ -0,0 +1,145 @@ +From 948bdee2249276bdc8f67f58be371ee565a1c3f9 Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Sun, 24 Apr 2022 17:34:07 -0700 +Subject: tcp: fix potential xmit stalls caused by TCP_NOTSENT_LOWAT + +From: Eric Dumazet + +[ Upstream commit 4bfe744ff1644fbc0a991a2677dc874475dd6776 ] + +I had this bug sitting for too long in my pile, it is time to fix it. + +Thanks to Doug Porter for reminding me of it! + +We had various attempts in the past, including commit +0cbe6a8f089e ("tcp: remove SOCK_QUEUE_SHRUNK"), +but the issue is that TCP stack currently only generates +EPOLLOUT from input path, when tp->snd_una has advanced +and skb(s) cleaned from rtx queue. + +If a flow has a big RTT, and/or receives SACKs, it is possible +that the notsent part (tp->write_seq - tp->snd_nxt) reaches 0 +and no more data can be sent until tp->snd_una finally advances. + +What is needed is to also check if POLLOUT needs to be generated +whenever tp->snd_nxt is advanced, from output path. + +This bug triggers more often after an idle period, as +we do not receive ACK for at least one RTT. tcp_notsent_lowat +could be a fraction of what CWND and pacing rate would allow to +send during this RTT. + +In a followup patch, I will remove the bogus call +to tcp_chrono_stop(sk, TCP_CHRONO_SNDBUF_LIMITED) +from tcp_check_space(). Fact that we have decided to generate +an EPOLLOUT does not mean the application has immediately +refilled the transmit queue. This optimistic call +might have been the reason the bug seemed not too serious. + +Tested: + +200 ms rtt, 1% packet loss, 32 MB tcp_rmem[2] and tcp_wmem[2] + +$ echo 500000 >/proc/sys/net/ipv4/tcp_notsent_lowat +$ cat bench_rr.sh +SUM=0 +for i in {1..10} +do + V=`netperf -H remote_host -l30 -t TCP_RR -- -r 10000000,10000 -o LOCAL_BYTES_SENT | egrep -v "MIGRATED|Bytes"` + echo $V + SUM=$(($SUM + $V)) +done +echo SUM=$SUM + +Before patch: +$ bench_rr.sh +130000000 +80000000 +140000000 +140000000 +140000000 +140000000 +130000000 +40000000 +90000000 +110000000 +SUM=1140000000 + +After patch: +$ bench_rr.sh +430000000 +590000000 +530000000 +450000000 +450000000 +350000000 +450000000 +490000000 +480000000 +460000000 +SUM=4680000000 # This is 410 % of the value before patch. + +Fixes: c9bee3b7fdec ("tcp: TCP_NOTSENT_LOWAT socket option") +Signed-off-by: Eric Dumazet +Reported-by: Doug Porter +Cc: Soheil Hassas Yeganeh +Cc: Neal Cardwell +Acked-by: Soheil Hassas Yeganeh +Signed-off-by: David S. Miller +Signed-off-by: Sasha Levin +--- + include/net/tcp.h | 1 + + net/ipv4/tcp_input.c | 12 +++++++++++- + net/ipv4/tcp_output.c | 1 + + 3 files changed, 13 insertions(+), 1 deletion(-) + +diff --git a/include/net/tcp.h b/include/net/tcp.h +index 3f0d654984cf..f0d2e2571f56 100644 +--- a/include/net/tcp.h ++++ b/include/net/tcp.h +@@ -594,6 +594,7 @@ void tcp_synack_rtt_meas(struct sock *sk, struct request_sock *req); + void tcp_reset(struct sock *sk); + void tcp_skb_mark_lost_uncond_verify(struct tcp_sock *tp, struct sk_buff *skb); + void tcp_fin(struct sock *sk); ++void tcp_check_space(struct sock *sk); + + /* tcp_timer.c */ + void tcp_init_xmit_timers(struct sock *); +diff --git a/net/ipv4/tcp_input.c b/net/ipv4/tcp_input.c +index 757e1f60e00d..d71326f3777c 100644 +--- a/net/ipv4/tcp_input.c ++++ b/net/ipv4/tcp_input.c +@@ -5167,7 +5167,17 @@ static void tcp_new_space(struct sock *sk) + sk->sk_write_space(sk); + } + +-static void tcp_check_space(struct sock *sk) ++/* Caller made space either from: ++ * 1) Freeing skbs in rtx queues (after tp->snd_una has advanced) ++ * 2) Sent skbs from output queue (and thus advancing tp->snd_nxt) ++ * ++ * We might be able to generate EPOLLOUT to the application if: ++ * 1) Space consumed in output/rtx queues is below sk->sk_sndbuf/2 ++ * 2) notsent amount (tp->write_seq - tp->snd_nxt) became ++ * small enough that tcp_stream_memory_free() decides it ++ * is time to generate EPOLLOUT. ++ */ ++void tcp_check_space(struct sock *sk) + { + if (sock_flag(sk, SOCK_QUEUE_SHRUNK)) { + sock_reset_flag(sk, SOCK_QUEUE_SHRUNK); +diff --git a/net/ipv4/tcp_output.c b/net/ipv4/tcp_output.c +index 97c3b616d594..8543cd724d54 100644 +--- a/net/ipv4/tcp_output.c ++++ b/net/ipv4/tcp_output.c +@@ -69,6 +69,7 @@ static void tcp_event_new_data_sent(struct sock *sk, struct sk_buff *skb) + + NET_ADD_STATS(sock_net(sk), LINUX_MIB_TCPORIGDATASENT, + tcp_skb_pcount(skb)); ++ tcp_check_space(sk); + } + + /* SND.NXT, if window was not shrunk or the amount of shrunk was less than one +-- +2.35.1 + diff --git a/queue-4.19/tcp-md5-incorrect-tcp_header_len-for-incoming-connec.patch b/queue-4.19/tcp-md5-incorrect-tcp_header_len-for-incoming-connec.patch new file mode 100644 index 00000000000..58879e539ec --- /dev/null +++ b/queue-4.19/tcp-md5-incorrect-tcp_header_len-for-incoming-connec.patch @@ -0,0 +1,40 @@ +From 0a1b2085fe71ee1ef6ca740a3b513d2154d9a3ef Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Wed, 20 Apr 2022 17:50:26 -0700 +Subject: tcp: md5: incorrect tcp_header_len for incoming connections + +From: Francesco Ruggeri + +[ Upstream commit 5b0b9e4c2c895227c8852488b3f09839233bba54 ] + +In tcp_create_openreq_child we adjust tcp_header_len for md5 using the +remote address in newsk. But that address is still 0 in newsk at this +point, and it is only set later by the callers (tcp_v[46]_syn_recv_sock). +Use the address from the request socket instead. + +Fixes: cfb6eeb4c860 ("[TCP]: MD5 Signature Option (RFC2385) support.") +Signed-off-by: Francesco Ruggeri +Reviewed-by: Eric Dumazet +Link: https://lore.kernel.org/r/20220421005026.686A45EC01F2@us226.sjc.aristanetworks.com +Signed-off-by: Jakub Kicinski +Signed-off-by: Sasha Levin +--- + net/ipv4/tcp_minisocks.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/net/ipv4/tcp_minisocks.c b/net/ipv4/tcp_minisocks.c +index a20b393b4501..c79cb949da66 100644 +--- a/net/ipv4/tcp_minisocks.c ++++ b/net/ipv4/tcp_minisocks.c +@@ -550,7 +550,7 @@ struct sock *tcp_create_openreq_child(const struct sock *sk, + newtp->tsoffset = treq->ts_off; + #ifdef CONFIG_TCP_MD5SIG + newtp->md5sig_info = NULL; /*XXX*/ +- if (newtp->af_specific->md5_lookup(sk, newsk)) ++ if (treq->af_specific->req_md5_lookup(sk, req_to_sk(req))) + newtp->tcp_header_len += TCPOLEN_MD5SIG_ALIGNED; + #endif + if (skb->len >= TCP_MSS_DEFAULT + newtp->tcp_header_len) +-- +2.35.1 + diff --git a/queue-4.19/usb-fix-xhci-event-ring-dequeue-pointer-erdp-update-.patch b/queue-4.19/usb-fix-xhci-event-ring-dequeue-pointer-erdp-update-.patch new file mode 100644 index 00000000000..72cf48d8ee5 --- /dev/null +++ b/queue-4.19/usb-fix-xhci-event-ring-dequeue-pointer-erdp-update-.patch @@ -0,0 +1,65 @@ +From 877cb1fc4dcea7cca12397718a8c8f67fdd5bb3b Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Fri, 8 Apr 2022 16:48:21 +0300 +Subject: USB: Fix xhci event ring dequeue pointer ERDP update issue + +From: Weitao Wang + +[ Upstream commit e91ac20889d1a26d077cc511365cd7ff4346a6f3 ] + +In some situations software handles TRB events slower than adding TRBs. +If the number of TRB events to be processed in a given interrupt is exactly +the same as the event ring size 256, then the local variable +"event_ring_deq" that holds the initial dequeue position is equal to +software_dequeue after handling all 256 interrupts. + +It will cause driver to not update ERDP to hardware, + +Software dequeue pointer is out of sync with ERDP on interrupt exit. +On the next interrupt, the event ring may full but driver will not +update ERDP as software_dequeue is equal to ERDP. + +[ 536.377115] xhci_hcd 0000:00:12.0: ERROR unknown event type 37 +[ 566.933173] sd 8:0:0:0: [sdb] tag#27 uas_eh_abort_handler 0 uas-tag 7 inflight: CMD OUT +[ 566.933181] sd 8:0:0:0: [sdb] tag#27 CDB: Write(10) 2a 00 17 71 e6 78 00 00 08 00 +[ 572.041186] xhci_hcd On some situataions,the0000:00:12.0: xHCI host not responding to stop endpoint command. +[ 572.057193] xhci_hcd 0000:00:12.0: Host halt failed, -110 +[ 572.057196] xhci_hcd 0000:00:12.0: xHCI host controller not responding, assume dead +[ 572.057236] sd 8:0:0:0: [sdb] tag#26 uas_eh_abort_handler 0 uas-tag 6 inflight: CMD +[ 572.057240] sd 8:0:0:0: [sdb] tag#26 CDB: Write(10) 2a 00 38 eb cc d8 00 00 08 00 +[ 572.057244] sd 8:0:0:0: [sdb] tag#25 uas_eh_abort_handler 0 uas-tag 5 inflight: CMD + +Hardware ERDP is updated mid event handling if there are more than 128 +events in an interrupt (half of ring size). +Fix this by updating the software local variable at the same time as +hardware ERDP. + +[commit message rewording -Mathias] + +Fixes: dc0ffbea5729 ("usb: host: xhci: update event ring dequeue pointer on purpose") +Reviewed-by: Peter Chen +Signed-off-by: Weitao Wang +Signed-off-by: Mathias Nyman +Link: https://lore.kernel.org/r/20220408134823.2527272-2-mathias.nyman@linux.intel.com +Signed-off-by: Greg Kroah-Hartman +Signed-off-by: Sasha Levin +--- + drivers/usb/host/xhci-ring.c | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/drivers/usb/host/xhci-ring.c b/drivers/usb/host/xhci-ring.c +index f5bd91752f2d..e18b675fb7af 100644 +--- a/drivers/usb/host/xhci-ring.c ++++ b/drivers/usb/host/xhci-ring.c +@@ -2848,6 +2848,8 @@ irqreturn_t xhci_irq(struct usb_hcd *hcd) + if (event_loop++ < TRBS_PER_SEGMENT / 2) + continue; + xhci_update_erst_dequeue(xhci, event_ring_deq); ++ event_ring_deq = xhci->event_ring->dequeue; ++ + event_loop = 0; + } + +-- +2.35.1 + diff --git a/queue-4.19/x86-__memcpy_flushcache-fix-wrong-alignment-if-size-.patch b/queue-4.19/x86-__memcpy_flushcache-fix-wrong-alignment-if-size-.patch new file mode 100644 index 00000000000..00e7a37e127 --- /dev/null +++ b/queue-4.19/x86-__memcpy_flushcache-fix-wrong-alignment-if-size-.patch @@ -0,0 +1,51 @@ +From b0a5975d8b1181d3732489224fe3b721a5d54827 Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Tue, 19 Apr 2022 09:56:23 -0400 +Subject: x86: __memcpy_flushcache: fix wrong alignment if size > 2^32 + +From: Mikulas Patocka + +[ Upstream commit a6823e4e360fe975bd3da4ab156df7c74c8b07f3 ] + +The first "if" condition in __memcpy_flushcache is supposed to align the +"dest" variable to 8 bytes and copy data up to this alignment. However, +this condition may misbehave if "size" is greater than 4GiB. + +The statement min_t(unsigned, size, ALIGN(dest, 8) - dest); casts both +arguments to unsigned int and selects the smaller one. However, the +cast truncates high bits in "size" and it results in misbehavior. + +For example: + + suppose that size == 0x100000001, dest == 0x200000002 + min_t(unsigned, size, ALIGN(dest, 8) - dest) == min_t(0x1, 0xe) == 0x1; + ... + dest += 0x1; + +so we copy just one byte "and" dest remains unaligned. + +This patch fixes the bug by replacing unsigned with size_t. + +Signed-off-by: Mikulas Patocka +Signed-off-by: Linus Torvalds +Signed-off-by: Sasha Levin +--- + arch/x86/lib/usercopy_64.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/arch/x86/lib/usercopy_64.c b/arch/x86/lib/usercopy_64.c +index 40dbbd8f1fe4..8c6d0fb72b3a 100644 +--- a/arch/x86/lib/usercopy_64.c ++++ b/arch/x86/lib/usercopy_64.c +@@ -161,7 +161,7 @@ void memcpy_flushcache(void *_dst, const void *_src, size_t size) + + /* cache copy and flush to align dest */ + if (!IS_ALIGNED(dest, 8)) { +- unsigned len = min_t(unsigned, size, ALIGN(dest, 8) - dest); ++ size_t len = min_t(size_t, size, ALIGN(dest, 8) - dest); + + memcpy((void *) dest, (void *) source, len); + clean_cache_range((void *) dest, len); +-- +2.35.1 +