From: Sasha Levin Date: Thu, 7 May 2020 01:32:47 +0000 (-0400) Subject: Fixes for 4.14 X-Git-Tag: v4.4.223~48 X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=bc93077c722d0546ef94a1d075ac65c4354f86f5;p=thirdparty%2Fkernel%2Fstable-queue.git Fixes for 4.14 Signed-off-by: Sasha Levin --- diff --git a/queue-4.14/asoc-codecs-hdac_hdmi-fix-incorrect-use-of-list_for_.patch b/queue-4.14/asoc-codecs-hdac_hdmi-fix-incorrect-use-of-list_for_.patch new file mode 100644 index 00000000000..8e026d0b804 --- /dev/null +++ b/queue-4.14/asoc-codecs-hdac_hdmi-fix-incorrect-use-of-list_for_.patch @@ -0,0 +1,49 @@ +From ab14a3f3390d782b0e94a15d8ebd81013989b12b Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Wed, 15 Apr 2020 12:28:49 -0400 +Subject: ASoC: codecs: hdac_hdmi: Fix incorrect use of list_for_each_entry +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +From: Amadeusz Sławiński + +[ Upstream commit 326b509238171d37402dbe308e154cc234ed1960 ] + +If we don't find any pcm, pcm will point at address at an offset from +the the list head and not a meaningful structure. Fix this by returning +correct pcm if found and NULL if not. Found with coccinelle. + +Signed-off-by: Amadeusz Sławiński +Link: https://lore.kernel.org/r/20200415162849.308-1-amadeuszx.slawinski@linux.intel.com +Signed-off-by: Mark Brown +Signed-off-by: Sasha Levin +--- + sound/soc/codecs/hdac_hdmi.c | 6 +++--- + 1 file changed, 3 insertions(+), 3 deletions(-) + +diff --git a/sound/soc/codecs/hdac_hdmi.c b/sound/soc/codecs/hdac_hdmi.c +index 1c3626347e12b..aeeec1144558e 100644 +--- a/sound/soc/codecs/hdac_hdmi.c ++++ b/sound/soc/codecs/hdac_hdmi.c +@@ -142,14 +142,14 @@ static struct hdac_hdmi_pcm * + hdac_hdmi_get_pcm_from_cvt(struct hdac_hdmi_priv *hdmi, + struct hdac_hdmi_cvt *cvt) + { +- struct hdac_hdmi_pcm *pcm = NULL; ++ struct hdac_hdmi_pcm *pcm; + + list_for_each_entry(pcm, &hdmi->pcm_list, head) { + if (pcm->cvt == cvt) +- break; ++ return pcm; + } + +- return pcm; ++ return NULL; + } + + static void hdac_hdmi_jack_report(struct hdac_hdmi_pcm *pcm, +-- +2.20.1 + diff --git a/queue-4.14/asoc-rsnd-fix-hdmi-channel-mapping-for-multi-ssi-mod.patch b/queue-4.14/asoc-rsnd-fix-hdmi-channel-mapping-for-multi-ssi-mod.patch new file mode 100644 index 00000000000..e65d068c1fd --- /dev/null +++ b/queue-4.14/asoc-rsnd-fix-hdmi-channel-mapping-for-multi-ssi-mod.patch @@ -0,0 +1,49 @@ +From 85c0e6aa1e596983b3a97a8660f27afa20f0fe61 Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Wed, 15 Apr 2020 16:10:17 +0200 +Subject: ASoC: rsnd: Fix HDMI channel mapping for multi-SSI mode + +From: Matthias Blankertz + +[ Upstream commit b94e164759b82d0c1c80d4b1c8f12c9bee83f11d ] + +The HDMI?_SEL register maps up to four stereo SSI data lanes onto the +sdata[0..3] inputs of the HDMI output block. The upper half of the +register contains four blocks of 4 bits, with the most significant +controlling the sdata3 line and the least significant the sdata0 line. + +The shift calculation has an off-by-one error, causing the parent SSI to +be mapped to sdata3, the first multi-SSI child to sdata0 and so forth. +As the parent SSI transmits the stereo L/R channels, and the HDMI core +expects it on the sdata0 line, this causes no audio to be output when +playing stereo audio on a multichannel capable HDMI out, and +multichannel audio has permutated channels. + +Fix the shift calculation to map the parent SSI to sdata0, the first +child to sdata1 etc. + +Signed-off-by: Matthias Blankertz +Acked-by: Kuninori Morimoto +Link: https://lore.kernel.org/r/20200415141017.384017-3-matthias.blankertz@cetitec.com +Signed-off-by: Mark Brown +Signed-off-by: Sasha Levin +--- + sound/soc/sh/rcar/ssiu.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/sound/soc/sh/rcar/ssiu.c b/sound/soc/sh/rcar/ssiu.c +index 4d948757d300d..5e5ed54754739 100644 +--- a/sound/soc/sh/rcar/ssiu.c ++++ b/sound/soc/sh/rcar/ssiu.c +@@ -172,7 +172,7 @@ static int rsnd_ssiu_init_gen2(struct rsnd_mod *mod, + i; + + for_each_rsnd_mod_array(i, pos, io, rsnd_ssi_array) { +- shift = (i * 4) + 16; ++ shift = (i * 4) + 20; + val = (val & ~(0xF << shift)) | + rsnd_mod_id(pos) << shift; + } +-- +2.20.1 + diff --git a/queue-4.14/asoc-sgtl5000-fix-vag-power-on-handling.patch b/queue-4.14/asoc-sgtl5000-fix-vag-power-on-handling.patch new file mode 100644 index 00000000000..08b1db4a922 --- /dev/null +++ b/queue-4.14/asoc-sgtl5000-fix-vag-power-on-handling.patch @@ -0,0 +1,89 @@ +From 59ae80ef0fd59a33cac66193e91e58d232c565af Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Tue, 14 Apr 2020 20:11:40 +0200 +Subject: ASoC: sgtl5000: Fix VAG power-on handling + +From: Sebastian Reichel + +[ Upstream commit aa7812737f2877e192d57626cbe8825cc7cf6de9 ] + +As mentioned slightly out of patch context in the code, there +is no reset routine for the chip. On boards where the chip is +supplied by a fixed regulator, it might not even be resetted +during (e.g. watchdog) reboot and can be in any state. + +If the device is probed with VAG enabled, the driver's probe +routine will generate a loud pop sound when ANA_POWER is +being programmed. Avoid this by properly disabling just the +VAG bit and waiting the required power down time. + +Signed-off-by: Sebastian Reichel +Reviewed-by: Fabio Estevam +Link: https://lore.kernel.org/r/20200414181140.145825-1-sebastian.reichel@collabora.com +Signed-off-by: Mark Brown +Signed-off-by: Sasha Levin +--- + sound/soc/codecs/sgtl5000.c | 34 ++++++++++++++++++++++++++++++++++ + sound/soc/codecs/sgtl5000.h | 1 + + 2 files changed, 35 insertions(+) + +diff --git a/sound/soc/codecs/sgtl5000.c b/sound/soc/codecs/sgtl5000.c +index ca8a70ab22a82..d64cb28e8dc5c 100644 +--- a/sound/soc/codecs/sgtl5000.c ++++ b/sound/soc/codecs/sgtl5000.c +@@ -1563,6 +1563,40 @@ static int sgtl5000_i2c_probe(struct i2c_client *client, + dev_err(&client->dev, + "Error %d initializing CHIP_CLK_CTRL\n", ret); + ++ /* Mute everything to avoid pop from the following power-up */ ++ ret = regmap_write(sgtl5000->regmap, SGTL5000_CHIP_ANA_CTRL, ++ SGTL5000_CHIP_ANA_CTRL_DEFAULT); ++ if (ret) { ++ dev_err(&client->dev, ++ "Error %d muting outputs via CHIP_ANA_CTRL\n", ret); ++ goto disable_clk; ++ } ++ ++ /* ++ * If VAG is powered-on (e.g. from previous boot), it would be disabled ++ * by the write to ANA_POWER in later steps of the probe code. This ++ * may create a loud pop even with all outputs muted. The proper way ++ * to circumvent this is disabling the bit first and waiting the proper ++ * cool-down time. ++ */ ++ ret = regmap_read(sgtl5000->regmap, SGTL5000_CHIP_ANA_POWER, &value); ++ if (ret) { ++ dev_err(&client->dev, "Failed to read ANA_POWER: %d\n", ret); ++ goto disable_clk; ++ } ++ if (value & SGTL5000_VAG_POWERUP) { ++ ret = regmap_update_bits(sgtl5000->regmap, ++ SGTL5000_CHIP_ANA_POWER, ++ SGTL5000_VAG_POWERUP, ++ 0); ++ if (ret) { ++ dev_err(&client->dev, "Error %d disabling VAG\n", ret); ++ goto disable_clk; ++ } ++ ++ msleep(SGTL5000_VAG_POWERDOWN_DELAY); ++ } ++ + /* Follow section 2.2.1.1 of AN3663 */ + ana_pwr = SGTL5000_ANA_POWER_DEFAULT; + if (sgtl5000->num_supplies <= VDDD) { +diff --git a/sound/soc/codecs/sgtl5000.h b/sound/soc/codecs/sgtl5000.h +index 22f3442af9826..9ea41749d0375 100644 +--- a/sound/soc/codecs/sgtl5000.h ++++ b/sound/soc/codecs/sgtl5000.h +@@ -236,6 +236,7 @@ + /* + * SGTL5000_CHIP_ANA_CTRL + */ ++#define SGTL5000_CHIP_ANA_CTRL_DEFAULT 0x0133 + #define SGTL5000_LINE_OUT_MUTE 0x0100 + #define SGTL5000_HP_SEL_MASK 0x0040 + #define SGTL5000_HP_SEL_SHIFT 6 +-- +2.20.1 + diff --git a/queue-4.14/asoc-topology-check-return-value-of-pcm_new_ver.patch b/queue-4.14/asoc-topology-check-return-value-of-pcm_new_ver.patch new file mode 100644 index 00000000000..84b52d18440 --- /dev/null +++ b/queue-4.14/asoc-topology-check-return-value-of-pcm_new_ver.patch @@ -0,0 +1,43 @@ +From b46654c50066b7b410e23f51569c97f51d89ae51 Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Fri, 27 Mar 2020 16:47:28 -0400 +Subject: ASoC: topology: Check return value of pcm_new_ver +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +From: Amadeusz Sławiński + +[ Upstream commit b3677fc3d68dd942c92de52f0bd9dd8b472a40e6 ] + +Function pcm_new_ver can fail, so we should check it's return value and +handle possible error. + +Signed-off-by: Amadeusz Sławiński +Reviewed-by: Ranjani Sridharan +Reviewed-by: Pierre-Louis Bossart +Link: https://lore.kernel.org/r/20200327204729.397-6-amadeuszx.slawinski@linux.intel.com +Signed-off-by: Mark Brown +Signed-off-by: Sasha Levin +--- + sound/soc/soc-topology.c | 4 +++- + 1 file changed, 3 insertions(+), 1 deletion(-) + +diff --git a/sound/soc/soc-topology.c b/sound/soc/soc-topology.c +index a215b9ad148c4..50aa45525be5a 100644 +--- a/sound/soc/soc-topology.c ++++ b/sound/soc/soc-topology.c +@@ -1954,7 +1954,9 @@ static int soc_tplg_pcm_elems_load(struct soc_tplg *tplg, + _pcm = pcm; + } else { + abi_match = false; +- pcm_new_ver(tplg, pcm, &_pcm); ++ ret = pcm_new_ver(tplg, pcm, &_pcm); ++ if (ret < 0) ++ return ret; + } + + /* create the FE DAIs and DAI links */ +-- +2.20.1 + diff --git a/queue-4.14/cifs-protect-updating-server-dstaddr-with-a-spinlock.patch b/queue-4.14/cifs-protect-updating-server-dstaddr-with-a-spinlock.patch new file mode 100644 index 00000000000..0de21f04422 --- /dev/null +++ b/queue-4.14/cifs-protect-updating-server-dstaddr-with-a-spinlock.patch @@ -0,0 +1,39 @@ +From 295b992b3abcee638d1ecb4141f3ec89d7b6f107 Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Tue, 21 Apr 2020 12:37:39 +1000 +Subject: cifs: protect updating server->dstaddr with a spinlock + +From: Ronnie Sahlberg + +[ Upstream commit fada37f6f62995cc449b36ebba1220594bfe55fe ] + +We use a spinlock while we are reading and accessing the destination address for a server. +We need to also use this spinlock to protect when we are modifying this address from +reconn_set_ipaddr(). + +Signed-off-by: Ronnie Sahlberg +Reviewed-by: Jeff Layton +Signed-off-by: Steve French +Signed-off-by: Sasha Levin +--- + fs/cifs/connect.c | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/fs/cifs/connect.c b/fs/cifs/connect.c +index 697edc92dff27..58e7288e5151c 100644 +--- a/fs/cifs/connect.c ++++ b/fs/cifs/connect.c +@@ -348,8 +348,10 @@ static int reconn_set_ipaddr(struct TCP_Server_Info *server) + return rc; + } + ++ spin_lock(&cifs_tcp_ses_lock); + rc = cifs_convert_address((struct sockaddr *)&server->dstaddr, ipaddr, + strlen(ipaddr)); ++ spin_unlock(&cifs_tcp_ses_lock); + kfree(ipaddr); + + return !rc ? -1 : 0; +-- +2.20.1 + diff --git a/queue-4.14/lib-mpi-fix-building-for-powerpc-with-clang.patch b/queue-4.14/lib-mpi-fix-building-for-powerpc-with-clang.patch new file mode 100644 index 00000000000..493ebbbdd86 --- /dev/null +++ b/queue-4.14/lib-mpi-fix-building-for-powerpc-with-clang.patch @@ -0,0 +1,123 @@ +From 9e0234c9dc45ac5e41244e06a7b94a7f6ba3be0a Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Mon, 13 Apr 2020 12:50:42 -0700 +Subject: lib/mpi: Fix building for powerpc with clang + +From: Nathan Chancellor + +[ Upstream commit 5990cdee689c6885b27c6d969a3d58b09002b0bc ] + +0day reports over and over on an powerpc randconfig with clang: + +lib/mpi/generic_mpih-mul1.c:37:13: error: invalid use of a cast in a +inline asm context requiring an l-value: remove the cast or build with +-fheinous-gnu-extensions + +Remove the superfluous casts, which have been done previously for x86 +and arm32 in commit dea632cadd12 ("lib/mpi: fix build with clang") and +commit 7b7c1df2883d ("lib/mpi/longlong.h: fix building with 32-bit +x86"). + +Reported-by: kbuild test robot +Signed-off-by: Nathan Chancellor +Acked-by: Herbert Xu +Signed-off-by: Michael Ellerman +Link: https://github.com/ClangBuiltLinux/linux/issues/991 +Link: https://lore.kernel.org/r/20200413195041.24064-1-natechancellor@gmail.com +Signed-off-by: Sasha Levin +--- + lib/mpi/longlong.h | 34 +++++++++++++++++----------------- + 1 file changed, 17 insertions(+), 17 deletions(-) + +diff --git a/lib/mpi/longlong.h b/lib/mpi/longlong.h +index 08c60d10747fd..e01b705556aa6 100644 +--- a/lib/mpi/longlong.h ++++ b/lib/mpi/longlong.h +@@ -756,22 +756,22 @@ do { \ + do { \ + if (__builtin_constant_p(bh) && (bh) == 0) \ + __asm__ ("{a%I4|add%I4c} %1,%3,%4\n\t{aze|addze} %0,%2" \ +- : "=r" ((USItype)(sh)), \ +- "=&r" ((USItype)(sl)) \ ++ : "=r" (sh), \ ++ "=&r" (sl) \ + : "%r" ((USItype)(ah)), \ + "%r" ((USItype)(al)), \ + "rI" ((USItype)(bl))); \ + else if (__builtin_constant_p(bh) && (bh) == ~(USItype) 0) \ + __asm__ ("{a%I4|add%I4c} %1,%3,%4\n\t{ame|addme} %0,%2" \ +- : "=r" ((USItype)(sh)), \ +- "=&r" ((USItype)(sl)) \ ++ : "=r" (sh), \ ++ "=&r" (sl) \ + : "%r" ((USItype)(ah)), \ + "%r" ((USItype)(al)), \ + "rI" ((USItype)(bl))); \ + else \ + __asm__ ("{a%I5|add%I5c} %1,%4,%5\n\t{ae|adde} %0,%2,%3" \ +- : "=r" ((USItype)(sh)), \ +- "=&r" ((USItype)(sl)) \ ++ : "=r" (sh), \ ++ "=&r" (sl) \ + : "%r" ((USItype)(ah)), \ + "r" ((USItype)(bh)), \ + "%r" ((USItype)(al)), \ +@@ -781,36 +781,36 @@ do { \ + do { \ + if (__builtin_constant_p(ah) && (ah) == 0) \ + __asm__ ("{sf%I3|subf%I3c} %1,%4,%3\n\t{sfze|subfze} %0,%2" \ +- : "=r" ((USItype)(sh)), \ +- "=&r" ((USItype)(sl)) \ ++ : "=r" (sh), \ ++ "=&r" (sl) \ + : "r" ((USItype)(bh)), \ + "rI" ((USItype)(al)), \ + "r" ((USItype)(bl))); \ + else if (__builtin_constant_p(ah) && (ah) == ~(USItype) 0) \ + __asm__ ("{sf%I3|subf%I3c} %1,%4,%3\n\t{sfme|subfme} %0,%2" \ +- : "=r" ((USItype)(sh)), \ +- "=&r" ((USItype)(sl)) \ ++ : "=r" (sh), \ ++ "=&r" (sl) \ + : "r" ((USItype)(bh)), \ + "rI" ((USItype)(al)), \ + "r" ((USItype)(bl))); \ + else if (__builtin_constant_p(bh) && (bh) == 0) \ + __asm__ ("{sf%I3|subf%I3c} %1,%4,%3\n\t{ame|addme} %0,%2" \ +- : "=r" ((USItype)(sh)), \ +- "=&r" ((USItype)(sl)) \ ++ : "=r" (sh), \ ++ "=&r" (sl) \ + : "r" ((USItype)(ah)), \ + "rI" ((USItype)(al)), \ + "r" ((USItype)(bl))); \ + else if (__builtin_constant_p(bh) && (bh) == ~(USItype) 0) \ + __asm__ ("{sf%I3|subf%I3c} %1,%4,%3\n\t{aze|addze} %0,%2" \ +- : "=r" ((USItype)(sh)), \ +- "=&r" ((USItype)(sl)) \ ++ : "=r" (sh), \ ++ "=&r" (sl) \ + : "r" ((USItype)(ah)), \ + "rI" ((USItype)(al)), \ + "r" ((USItype)(bl))); \ + else \ + __asm__ ("{sf%I4|subf%I4c} %1,%5,%4\n\t{sfe|subfe} %0,%3,%2" \ +- : "=r" ((USItype)(sh)), \ +- "=&r" ((USItype)(sl)) \ ++ : "=r" (sh), \ ++ "=&r" (sl) \ + : "r" ((USItype)(ah)), \ + "r" ((USItype)(bh)), \ + "rI" ((USItype)(al)), \ +@@ -821,7 +821,7 @@ do { \ + do { \ + USItype __m0 = (m0), __m1 = (m1); \ + __asm__ ("mulhwu %0,%1,%2" \ +- : "=r" ((USItype) ph) \ ++ : "=r" (ph) \ + : "%r" (__m0), \ + "r" (__m1)); \ + (pl) = __m0 * __m1; \ +-- +2.20.1 + diff --git a/queue-4.14/net-bcmgenet-suppress-warnings-on-failed-rx-skb-allo.patch b/queue-4.14/net-bcmgenet-suppress-warnings-on-failed-rx-skb-allo.patch new file mode 100644 index 00000000000..3ad1334b899 --- /dev/null +++ b/queue-4.14/net-bcmgenet-suppress-warnings-on-failed-rx-skb-allo.patch @@ -0,0 +1,47 @@ +From bfb37e0b4d38277406127c107e8586a950a9839d Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Thu, 23 Apr 2020 16:02:11 -0700 +Subject: net: bcmgenet: suppress warnings on failed Rx SKB allocations + +From: Doug Berger + +[ Upstream commit ecaeceb8a8a145d93c7e136f170238229165348f ] + +The driver is designed to drop Rx packets and reclaim the buffers +when an allocation fails, and the network interface needs to safely +handle this packet loss. Therefore, an allocation failure of Rx +SKBs is relatively benign. + +However, the output of the warning message occurs with a high +scheduling priority that can cause excessive jitter/latency for +other high priority processing. + +This commit suppresses the warning messages to prevent scheduling +problems while retaining the failure count in the statistics of +the network interface. + +Signed-off-by: Doug Berger +Acked-by: Florian Fainelli +Signed-off-by: David S. Miller +Signed-off-by: Sasha Levin +--- + drivers/net/ethernet/broadcom/genet/bcmgenet.c | 3 ++- + 1 file changed, 2 insertions(+), 1 deletion(-) + +diff --git a/drivers/net/ethernet/broadcom/genet/bcmgenet.c b/drivers/net/ethernet/broadcom/genet/bcmgenet.c +index 4b3660c63b864..38391230ca860 100644 +--- a/drivers/net/ethernet/broadcom/genet/bcmgenet.c ++++ b/drivers/net/ethernet/broadcom/genet/bcmgenet.c +@@ -1674,7 +1674,8 @@ static struct sk_buff *bcmgenet_rx_refill(struct bcmgenet_priv *priv, + dma_addr_t mapping; + + /* Allocate a new Rx skb */ +- skb = netdev_alloc_skb(priv->dev, priv->rx_buf_len + SKB_ALIGNMENT); ++ skb = __netdev_alloc_skb(priv->dev, priv->rx_buf_len + SKB_ALIGNMENT, ++ GFP_ATOMIC | __GFP_NOWARN); + if (!skb) { + priv->mib.alloc_rx_buff_failed++; + netif_err(priv, rx_err, priv->dev, +-- +2.20.1 + diff --git a/queue-4.14/net-dsa-b53-rework-arl-bin-logic.patch b/queue-4.14/net-dsa-b53-rework-arl-bin-logic.patch new file mode 100644 index 00000000000..b40db76553f --- /dev/null +++ b/queue-4.14/net-dsa-b53-rework-arl-bin-logic.patch @@ -0,0 +1,119 @@ +From 7622b0e4aa1273906ceaf0c3d43e6ca80b0b7a86 Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Mon, 20 Apr 2020 20:26:54 -0700 +Subject: net: dsa: b53: Rework ARL bin logic + +From: Florian Fainelli + +[ Upstream commit 6344dbde6a27d10d16246d734b968f84887841e2 ] + +When asking the ARL to read a MAC address, we will get a number of bins +returned in a single read. Out of those bins, there can essentially be 3 +states: + +- all bins are full, we have no space left, and we can either replace an + existing address or return that full condition + +- the MAC address was found, then we need to return its bin index and + modify that one, and only that one + +- the MAC address was not found and we have a least one bin free, we use + that bin index location then + +The code would unfortunately fail on all counts. + +Fixes: 1da6df85c6fb ("net: dsa: b53: Implement ARL add/del/dump operations") +Signed-off-by: Florian Fainelli +Signed-off-by: David S. Miller +Signed-off-by: Sasha Levin +--- + drivers/net/dsa/b53/b53_common.c | 30 ++++++++++++++++++++++++++---- + drivers/net/dsa/b53/b53_regs.h | 3 +++ + 2 files changed, 29 insertions(+), 4 deletions(-) + +diff --git a/drivers/net/dsa/b53/b53_common.c b/drivers/net/dsa/b53/b53_common.c +index 434e6dced6b7f..274d369151107 100644 +--- a/drivers/net/dsa/b53/b53_common.c ++++ b/drivers/net/dsa/b53/b53_common.c +@@ -1094,6 +1094,7 @@ static int b53_arl_read(struct b53_device *dev, u64 mac, + u16 vid, struct b53_arl_entry *ent, u8 *idx, + bool is_valid) + { ++ DECLARE_BITMAP(free_bins, B53_ARLTBL_MAX_BIN_ENTRIES); + unsigned int i; + int ret; + +@@ -1101,6 +1102,8 @@ static int b53_arl_read(struct b53_device *dev, u64 mac, + if (ret) + return ret; + ++ bitmap_zero(free_bins, dev->num_arl_entries); ++ + /* Read the bins */ + for (i = 0; i < dev->num_arl_entries; i++) { + u64 mac_vid; +@@ -1112,13 +1115,21 @@ static int b53_arl_read(struct b53_device *dev, u64 mac, + B53_ARLTBL_DATA_ENTRY(i), &fwd_entry); + b53_arl_to_entry(ent, mac_vid, fwd_entry); + +- if (!(fwd_entry & ARLTBL_VALID)) ++ if (!(fwd_entry & ARLTBL_VALID)) { ++ set_bit(i, free_bins); + continue; ++ } + if ((mac_vid & ARLTBL_MAC_MASK) != mac) + continue; + *idx = i; ++ return 0; + } + ++ if (bitmap_weight(free_bins, dev->num_arl_entries) == 0) ++ return -ENOSPC; ++ ++ *idx = find_first_bit(free_bins, dev->num_arl_entries); ++ + return -ENOENT; + } + +@@ -1148,10 +1159,21 @@ static int b53_arl_op(struct b53_device *dev, int op, int port, + if (op) + return ret; + +- /* We could not find a matching MAC, so reset to a new entry */ +- if (ret) { ++ switch (ret) { ++ case -ENOSPC: ++ dev_dbg(dev->dev, "{%pM,%.4d} no space left in ARL\n", ++ addr, vid); ++ return is_valid ? ret : 0; ++ case -ENOENT: ++ /* We could not find a matching MAC, so reset to a new entry */ ++ dev_dbg(dev->dev, "{%pM,%.4d} not found, using idx: %d\n", ++ addr, vid, idx); + fwd_entry = 0; +- idx = 1; ++ break; ++ default: ++ dev_dbg(dev->dev, "{%pM,%.4d} found, using idx: %d\n", ++ addr, vid, idx); ++ break; + } + + memset(&ent, 0, sizeof(ent)); +diff --git a/drivers/net/dsa/b53/b53_regs.h b/drivers/net/dsa/b53/b53_regs.h +index 1b2a337d673dd..247aef92b7594 100644 +--- a/drivers/net/dsa/b53/b53_regs.h ++++ b/drivers/net/dsa/b53/b53_regs.h +@@ -313,6 +313,9 @@ + #define ARLTBL_STATIC BIT(15) + #define ARLTBL_VALID BIT(16) + ++/* Maximum number of bin entries in the ARL for all switches */ ++#define B53_ARLTBL_MAX_BIN_ENTRIES 4 ++ + /* ARL Search Control Register (8 bit) */ + #define B53_ARL_SRCH_CTL 0x50 + #define B53_ARL_SRCH_CTL_25 0x20 +-- +2.20.1 + diff --git a/queue-4.14/net-stmmac-fix-enabling-socfpga-s-ptp_ref_clock.patch b/queue-4.14/net-stmmac-fix-enabling-socfpga-s-ptp_ref_clock.patch new file mode 100644 index 00000000000..aa2bcecc8ec --- /dev/null +++ b/queue-4.14/net-stmmac-fix-enabling-socfpga-s-ptp_ref_clock.patch @@ -0,0 +1,57 @@ +From aaf0616fcebbc07296ba4a2d717dbda40e78f58e Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Wed, 15 Apr 2020 14:24:31 +0200 +Subject: net: stmmac: fix enabling socfpga's ptp_ref_clock + +From: Julien Beraud + +[ Upstream commit 15ce30609d1e88d42fb1cd948f453e6d5f188249 ] + +There are 2 registers to write to enable a ptp ref clock coming from the +fpga. +One that enables the usage of the clock from the fpga for emac0 and emac1 +as a ptp ref clock, and the other to allow signals from the fpga to reach +emac0 and emac1. +Currently, if the dwmac-socfpga has phymode set to PHY_INTERFACE_MODE_MII, +PHY_INTERFACE_MODE_GMII, or PHY_INTERFACE_MODE_SGMII, both registers will +be written and the ptp ref clock will be set as coming from the fpga. +Separate the 2 register writes to only enable signals from the fpga to +reach emac0 or emac1 when ptp ref clock is not coming from the fpga. + +Signed-off-by: Julien Beraud +Signed-off-by: David S. Miller +Signed-off-by: Sasha Levin +--- + drivers/net/ethernet/stmicro/stmmac/dwmac-socfpga.c | 9 ++++++--- + 1 file changed, 6 insertions(+), 3 deletions(-) + +diff --git a/drivers/net/ethernet/stmicro/stmmac/dwmac-socfpga.c b/drivers/net/ethernet/stmicro/stmmac/dwmac-socfpga.c +index 5b3b06a0a3bf5..33407df6bea69 100644 +--- a/drivers/net/ethernet/stmicro/stmmac/dwmac-socfpga.c ++++ b/drivers/net/ethernet/stmicro/stmmac/dwmac-socfpga.c +@@ -274,16 +274,19 @@ static int socfpga_dwmac_set_phy_mode(struct socfpga_dwmac *dwmac) + phymode == PHY_INTERFACE_MODE_MII || + phymode == PHY_INTERFACE_MODE_GMII || + phymode == PHY_INTERFACE_MODE_SGMII) { +- ctrl |= SYSMGR_EMACGRP_CTRL_PTP_REF_CLK_MASK << (reg_shift / 2); + regmap_read(sys_mgr_base_addr, SYSMGR_FPGAGRP_MODULE_REG, + &module); + module |= (SYSMGR_FPGAGRP_MODULE_EMAC << (reg_shift / 2)); + regmap_write(sys_mgr_base_addr, SYSMGR_FPGAGRP_MODULE_REG, + module); +- } else { +- ctrl &= ~(SYSMGR_EMACGRP_CTRL_PTP_REF_CLK_MASK << (reg_shift / 2)); + } + ++ if (dwmac->f2h_ptp_ref_clk) ++ ctrl |= SYSMGR_EMACGRP_CTRL_PTP_REF_CLK_MASK << (reg_shift / 2); ++ else ++ ctrl &= ~(SYSMGR_EMACGRP_CTRL_PTP_REF_CLK_MASK << ++ (reg_shift / 2)); ++ + regmap_write(sys_mgr_base_addr, reg_offset, ctrl); + + /* Deassert reset for the phy configuration to be sampled by +-- +2.20.1 + diff --git a/queue-4.14/net-stmmac-fix-sub-second-increment.patch b/queue-4.14/net-stmmac-fix-sub-second-increment.patch new file mode 100644 index 00000000000..ec462785642 --- /dev/null +++ b/queue-4.14/net-stmmac-fix-sub-second-increment.patch @@ -0,0 +1,78 @@ +From a9f139bafd3ef30c62a90296ecee2a4edc09c06c Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Wed, 15 Apr 2020 14:24:32 +0200 +Subject: net: stmmac: Fix sub-second increment + +From: Julien Beraud + +[ Upstream commit 91a2559c1dc5b0f7e1256d42b1508935e8eabfbf ] + +In fine adjustement mode, which is the current default, the sub-second + increment register is the number of nanoseconds that will be added to + the clock when the accumulator overflows. At each clock cycle, the + value of the addend register is added to the accumulator. + Currently, we use 20ns = 1e09ns / 50MHz as this value whatever the + frequency of the ptp clock actually is. + The adjustment is then done on the addend register, only incrementing + every X clock cycles X being the ratio between 50MHz and ptp_clock_rate + (addend = 2^32 * 50MHz/ptp_clock_rate). + This causes the following issues : + - In case the frequency of the ptp clock is inferior or equal to 50MHz, + the addend value calculation will overflow and the default + addend value will be set to 0, causing the clock to not work at + all. (For instance, for ptp_clock_rate = 50MHz, addend = 2^32). + - The resolution of the timestamping clock is limited to 20ns while it + is not needed, thus limiting the accuracy of the timestamping to + 20ns. + + Fix this by setting sub-second increment to 2e09ns / ptp_clock_rate. + It will allow to reach the minimum possible frequency for + ptp_clk_ref, which is 5MHz for GMII 1000Mps Full-Duplex by setting the + sub-second-increment to a higher value. For instance, for 25MHz, it + gives ssinc = 80ns and default_addend = 2^31. + It will also allow to use a lower value for sub-second-increment, thus + improving the timestamping accuracy with frequencies higher than + 100MHz, for instance, for 200MHz, ssinc = 10ns and default_addend = + 2^31. + +v1->v2: + - Remove modifications to the calculation of default addend, which broke + compatibility with clock frequencies for which 2000000000 / ptp_clk_freq + is not an integer. + - Modify description according to discussions. + +Signed-off-by: Julien Beraud +Signed-off-by: David S. Miller +Signed-off-by: Sasha Levin +--- + .../net/ethernet/stmicro/stmmac/stmmac_hwtstamp.c | 12 ++++++++---- + 1 file changed, 8 insertions(+), 4 deletions(-) + +diff --git a/drivers/net/ethernet/stmicro/stmmac/stmmac_hwtstamp.c b/drivers/net/ethernet/stmicro/stmmac/stmmac_hwtstamp.c +index 41d528fbebb41..ccf7381c8baec 100644 +--- a/drivers/net/ethernet/stmicro/stmmac/stmmac_hwtstamp.c ++++ b/drivers/net/ethernet/stmicro/stmmac/stmmac_hwtstamp.c +@@ -36,12 +36,16 @@ static u32 stmmac_config_sub_second_increment(void __iomem *ioaddr, + unsigned long data; + u32 reg_value; + +- /* For GMAC3.x, 4.x versions, convert the ptp_clock to nano second +- * formula = (1/ptp_clock) * 1000000000 +- * where ptp_clock is 50MHz if fine method is used to update system ++ /* For GMAC3.x, 4.x versions, in "fine adjustement mode" set sub-second ++ * increment to twice the number of nanoseconds of a clock cycle. ++ * The calculation of the default_addend value by the caller will set it ++ * to mid-range = 2^31 when the remainder of this division is zero, ++ * which will make the accumulator overflow once every 2 ptp_clock ++ * cycles, adding twice the number of nanoseconds of a clock cycle : ++ * 2000000000ULL / ptp_clock. + */ + if (value & PTP_TCR_TSCFUPDT) +- data = (1000000000ULL / 50000000); ++ data = (2000000000ULL / ptp_clock); + else + data = (1000000000ULL / ptp_clock); + +-- +2.20.1 + diff --git a/queue-4.14/net-systemport-suppress-warnings-on-failed-rx-skb-al.patch b/queue-4.14/net-systemport-suppress-warnings-on-failed-rx-skb-al.patch new file mode 100644 index 00000000000..1e98a8b07ba --- /dev/null +++ b/queue-4.14/net-systemport-suppress-warnings-on-failed-rx-skb-al.patch @@ -0,0 +1,47 @@ +From 2aa3d1d96c7b67375c9769b2a15526d5b82d8aeb Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Thu, 23 Apr 2020 16:13:30 -0700 +Subject: net: systemport: suppress warnings on failed Rx SKB allocations + +From: Doug Berger + +[ Upstream commit 3554e54a46125030c534820c297ed7f6c3907e24 ] + +The driver is designed to drop Rx packets and reclaim the buffers +when an allocation fails, and the network interface needs to safely +handle this packet loss. Therefore, an allocation failure of Rx +SKBs is relatively benign. + +However, the output of the warning message occurs with a high +scheduling priority that can cause excessive jitter/latency for +other high priority processing. + +This commit suppresses the warning messages to prevent scheduling +problems while retaining the failure count in the statistics of +the network interface. + +Signed-off-by: Doug Berger +Acked-by: Florian Fainelli +Signed-off-by: David S. Miller +Signed-off-by: Sasha Levin +--- + drivers/net/ethernet/broadcom/bcmsysport.c | 3 ++- + 1 file changed, 2 insertions(+), 1 deletion(-) + +diff --git a/drivers/net/ethernet/broadcom/bcmsysport.c b/drivers/net/ethernet/broadcom/bcmsysport.c +index f48f7d104af21..123ee5c11bc0c 100644 +--- a/drivers/net/ethernet/broadcom/bcmsysport.c ++++ b/drivers/net/ethernet/broadcom/bcmsysport.c +@@ -645,7 +645,8 @@ static struct sk_buff *bcm_sysport_rx_refill(struct bcm_sysport_priv *priv, + dma_addr_t mapping; + + /* Allocate a new SKB for a new packet */ +- skb = netdev_alloc_skb(priv->netdev, RX_BUF_LENGTH); ++ skb = __netdev_alloc_skb(priv->netdev, RX_BUF_LENGTH, ++ GFP_ATOMIC | __GFP_NOWARN); + if (!skb) { + priv->mib.alloc_rx_buff_failed++; + netif_err(priv, rx_err, ndev, "SKB alloc failed\n"); +-- +2.20.1 + diff --git a/queue-4.14/s390-ftrace-fix-potential-crashes-when-switching-tra.patch b/queue-4.14/s390-ftrace-fix-potential-crashes-when-switching-tra.patch new file mode 100644 index 00000000000..b254a0cec02 --- /dev/null +++ b/queue-4.14/s390-ftrace-fix-potential-crashes-when-switching-tra.patch @@ -0,0 +1,78 @@ +From d96539f36aed3633a8629e99c73f13e1871759e3 Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Mon, 6 Apr 2020 14:47:48 +0200 +Subject: s390/ftrace: fix potential crashes when switching tracers + +From: Philipp Rudo + +[ Upstream commit 8ebf6da9db1b2a20bb86cc1bee2552e894d03308 ] + +Switching tracers include instruction patching. To prevent that a +instruction is patched while it's read the instruction patching is done +in stop_machine 'context'. This also means that any function called +during stop_machine must not be traced. Thus add 'notrace' to all +functions called within stop_machine. + +Fixes: 1ec2772e0c3c ("s390/diag: add a statistic for diagnose calls") +Fixes: 38f2c691a4b3 ("s390: improve wait logic of stop_machine") +Fixes: 4ecf0a43e729 ("processor: get rid of cpu_relax_yield") +Signed-off-by: Philipp Rudo +Signed-off-by: Vasily Gorbik +Signed-off-by: Sasha Levin +--- + arch/s390/kernel/diag.c | 2 +- + arch/s390/kernel/smp.c | 4 ++-- + arch/s390/kernel/trace.c | 2 +- + 3 files changed, 4 insertions(+), 4 deletions(-) + +diff --git a/arch/s390/kernel/diag.c b/arch/s390/kernel/diag.c +index 35c842aa87058..4c7cf8787a848 100644 +--- a/arch/s390/kernel/diag.c ++++ b/arch/s390/kernel/diag.c +@@ -128,7 +128,7 @@ void diag_stat_inc(enum diag_stat_enum nr) + } + EXPORT_SYMBOL(diag_stat_inc); + +-void diag_stat_inc_norecursion(enum diag_stat_enum nr) ++void notrace diag_stat_inc_norecursion(enum diag_stat_enum nr) + { + this_cpu_inc(diag_stat.counter[nr]); + trace_s390_diagnose_norecursion(diag_map[nr].code); +diff --git a/arch/s390/kernel/smp.c b/arch/s390/kernel/smp.c +index b649a6538350d..808f4fbe869e7 100644 +--- a/arch/s390/kernel/smp.c ++++ b/arch/s390/kernel/smp.c +@@ -406,7 +406,7 @@ int smp_find_processor_id(u16 address) + return -1; + } + +-bool arch_vcpu_is_preempted(int cpu) ++bool notrace arch_vcpu_is_preempted(int cpu) + { + if (test_cpu_flag_of(CIF_ENABLED_WAIT, cpu)) + return false; +@@ -416,7 +416,7 @@ bool arch_vcpu_is_preempted(int cpu) + } + EXPORT_SYMBOL(arch_vcpu_is_preempted); + +-void smp_yield_cpu(int cpu) ++void notrace smp_yield_cpu(int cpu) + { + if (MACHINE_HAS_DIAG9C) { + diag_stat_inc_norecursion(DIAG_STAT_X09C); +diff --git a/arch/s390/kernel/trace.c b/arch/s390/kernel/trace.c +index 490b52e850145..11a669f3cc93c 100644 +--- a/arch/s390/kernel/trace.c ++++ b/arch/s390/kernel/trace.c +@@ -14,7 +14,7 @@ EXPORT_TRACEPOINT_SYMBOL(s390_diagnose); + + static DEFINE_PER_CPU(unsigned int, diagnose_trace_depth); + +-void trace_s390_diagnose_norecursion(int diag_nr) ++void notrace trace_s390_diagnose_norecursion(int diag_nr) + { + unsigned long flags; + unsigned int *depth; +-- +2.20.1 + diff --git a/queue-4.14/scripts-config-allow-colons-in-option-strings-for-se.patch b/queue-4.14/scripts-config-allow-colons-in-option-strings-for-se.patch new file mode 100644 index 00000000000..967cc5a82d4 --- /dev/null +++ b/queue-4.14/scripts-config-allow-colons-in-option-strings-for-se.patch @@ -0,0 +1,48 @@ +From 070f0ae86da66283919c6c68fe89f8b3dd5f1c60 Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Fri, 10 Apr 2020 18:57:40 +0200 +Subject: scripts/config: allow colons in option strings for sed + +From: Jeremie Francois (on alpha) + +[ Upstream commit e461bc9f9ab105637b86065d24b0b83f182d477c ] + +Sed broke on some strings as it used colon as a separator. +I made it more robust by using \001, which is legit POSIX AFAIK. + +E.g. ./config --set-str CONFIG_USBNET_DEVADDR "de:ad:be:ef:00:01" +failed with: sed: -e expression #1, char 55: unknown option to `s' + +Signed-off-by: Jeremie Francois (on alpha) +Signed-off-by: Masahiro Yamada +Signed-off-by: Sasha Levin +--- + scripts/config | 5 ++++- + 1 file changed, 4 insertions(+), 1 deletion(-) + +diff --git a/scripts/config b/scripts/config +index e0e39826dae90..eee5b7f3a092a 100755 +--- a/scripts/config ++++ b/scripts/config +@@ -7,6 +7,9 @@ myname=${0##*/} + # If no prefix forced, use the default CONFIG_ + CONFIG_="${CONFIG_-CONFIG_}" + ++# We use an uncommon delimiter for sed substitutions ++SED_DELIM=$(echo -en "\001") ++ + usage() { + cat >&2 <"$tmpfile" ++ sed -e "s$SED_DELIM$before$SED_DELIM$after$SED_DELIM" "$infile" >"$tmpfile" + # replace original file with the edited one + mv "$tmpfile" "$infile" + } +-- +2.20.1 + diff --git a/queue-4.14/selftests-ipc-fix-test-failure-seen-after-initial-te.patch b/queue-4.14/selftests-ipc-fix-test-failure-seen-after-initial-te.patch new file mode 100644 index 00000000000..b6ff09a25bc --- /dev/null +++ b/queue-4.14/selftests-ipc-fix-test-failure-seen-after-initial-te.patch @@ -0,0 +1,61 @@ +From f3092c78de7ddf680a11535c0cce8a5ce575970f Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Mon, 13 Apr 2020 15:21:45 -0500 +Subject: selftests/ipc: Fix test failure seen after initial test run + +From: Tyler Hicks + +[ Upstream commit b87080eab4c1377706c113fc9c0157f19ea8fed1 ] + +After successfully running the IPC msgque test once, subsequent runs +result in a test failure: + + $ sudo ./run_kselftest.sh + TAP version 13 + 1..1 + # selftests: ipc: msgque + # Failed to get stats for IPC queue with id 0 + # Failed to dump queue: -22 + # Bail out! + # # Pass 0 Fail 0 Xfail 0 Xpass 0 Skip 0 Error 0 + not ok 1 selftests: ipc: msgque # exit=1 + +The dump_queue() function loops through the possible message queue index +values using calls to msgctl(kern_id, MSG_STAT, ...) where kern_id +represents the index value. The first time the test is ran, the initial +index value of 0 is valid and the test is able to complete. The index +value of 0 is not valid in subsequent test runs and the loop attempts to +try index values of 1, 2, 3, and so on until a valid index value is +found that corresponds to the message queue created earlier in the test. + +The msgctl() syscall returns -1 and sets errno to EINVAL when invalid +index values are used. The test failure is caused by incorrectly +comparing errno to -EINVAL when cycling through possible index values. + +Fix invalid test failures on subsequent runs of the msgque test by +correctly comparing errno values to a non-negated EINVAL. + +Fixes: 3a665531a3b7 ("selftests: IPC message queue copy feature test") +Signed-off-by: Tyler Hicks +Signed-off-by: Shuah Khan +Signed-off-by: Sasha Levin +--- + tools/testing/selftests/ipc/msgque.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/tools/testing/selftests/ipc/msgque.c b/tools/testing/selftests/ipc/msgque.c +index c5587844fbb8c..ad723a5d0f831 100644 +--- a/tools/testing/selftests/ipc/msgque.c ++++ b/tools/testing/selftests/ipc/msgque.c +@@ -137,7 +137,7 @@ int dump_queue(struct msgque_data *msgque) + for (kern_id = 0; kern_id < 256; kern_id++) { + ret = msgctl(kern_id, MSG_STAT, &ds); + if (ret < 0) { +- if (errno == -EINVAL) ++ if (errno == EINVAL) + continue; + printf("Failed to get stats for IPC queue with id %d\n", + kern_id); +-- +2.20.1 + diff --git a/queue-4.14/series b/queue-4.14/series index ace00595c27..998485b5d26 100644 --- a/queue-4.14/series +++ b/queue-4.14/series @@ -1,2 +1,17 @@ vhost-vsock-kick-send_pkt-worker-once-device-is-started.patch powerpc-pci-of-parse-unassigned-resources.patch +asoc-topology-check-return-value-of-pcm_new_ver.patch +selftests-ipc-fix-test-failure-seen-after-initial-te.patch +asoc-sgtl5000-fix-vag-power-on-handling.patch +asoc-rsnd-fix-hdmi-channel-mapping-for-multi-ssi-mod.patch +asoc-codecs-hdac_hdmi-fix-incorrect-use-of-list_for_.patch +wimax-i2400m-fix-potential-urb-refcnt-leak.patch +net-stmmac-fix-enabling-socfpga-s-ptp_ref_clock.patch +net-stmmac-fix-sub-second-increment.patch +cifs-protect-updating-server-dstaddr-with-a-spinlock.patch +s390-ftrace-fix-potential-crashes-when-switching-tra.patch +scripts-config-allow-colons-in-option-strings-for-se.patch +net-dsa-b53-rework-arl-bin-logic.patch +lib-mpi-fix-building-for-powerpc-with-clang.patch +net-bcmgenet-suppress-warnings-on-failed-rx-skb-allo.patch +net-systemport-suppress-warnings-on-failed-rx-skb-al.patch diff --git a/queue-4.14/wimax-i2400m-fix-potential-urb-refcnt-leak.patch b/queue-4.14/wimax-i2400m-fix-potential-urb-refcnt-leak.patch new file mode 100644 index 00000000000..6e512849e91 --- /dev/null +++ b/queue-4.14/wimax-i2400m-fix-potential-urb-refcnt-leak.patch @@ -0,0 +1,46 @@ +From ea4a8b5ea653c3fb2cfbfe2766575282ee0ed170 Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Wed, 15 Apr 2020 16:41:20 +0800 +Subject: wimax/i2400m: Fix potential urb refcnt leak + +From: Xiyu Yang + +[ Upstream commit 7717cbec172c3554d470023b4020d5781961187e ] + +i2400mu_bus_bm_wait_for_ack() invokes usb_get_urb(), which increases the +refcount of the "notif_urb". + +When i2400mu_bus_bm_wait_for_ack() returns, local variable "notif_urb" +becomes invalid, so the refcount should be decreased to keep refcount +balanced. + +The issue happens in all paths of i2400mu_bus_bm_wait_for_ack(), which +forget to decrease the refcnt increased by usb_get_urb(), causing a +refcnt leak. + +Fix this issue by calling usb_put_urb() before the +i2400mu_bus_bm_wait_for_ack() returns. + +Signed-off-by: Xiyu Yang +Signed-off-by: Xin Tan +Signed-off-by: David S. Miller +Signed-off-by: Sasha Levin +--- + drivers/net/wimax/i2400m/usb-fw.c | 1 + + 1 file changed, 1 insertion(+) + +diff --git a/drivers/net/wimax/i2400m/usb-fw.c b/drivers/net/wimax/i2400m/usb-fw.c +index 502c346aa790b..7d396c81ec3eb 100644 +--- a/drivers/net/wimax/i2400m/usb-fw.c ++++ b/drivers/net/wimax/i2400m/usb-fw.c +@@ -354,6 +354,7 @@ ssize_t i2400mu_bus_bm_wait_for_ack(struct i2400m *i2400m, + usb_autopm_put_interface(i2400mu->usb_iface); + d_fnend(8, dev, "(i2400m %p ack %p size %zu) = %ld\n", + i2400m, ack, ack_size, (long) result); ++ usb_put_urb(¬if_urb); + return result; + + error_exceeded: +-- +2.20.1 +