--- /dev/null
+From 00a0eec59ddbb1ce966b19097d8a8d2f777e726a Mon Sep 17 00:00:00 2001
+From: Clement Leger <cleger@kalray.eu>
+Date: Fri, 4 Oct 2019 09:37:36 +0200
+Subject: remoteproc: Fix wrong rvring index computation
+
+From: Clement Leger <cleger@kalray.eu>
+
+commit 00a0eec59ddbb1ce966b19097d8a8d2f777e726a upstream.
+
+Index of rvring is computed using pointer arithmetic. However, since
+rvring->rvdev->vring is the base of the vring array, computation
+of rvring idx should be reversed. It previously lead to writing at negative
+indices in the resource table.
+
+Signed-off-by: Clement Leger <cleger@kalray.eu>
+Link: https://lore.kernel.org/r/20191004073736.8327-1-cleger@kalray.eu
+Signed-off-by: Bjorn Andersson <bjorn.andersson@linaro.org>
+Cc: Doug Anderson <dianders@chromium.org>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+
+---
+ drivers/remoteproc/remoteproc_core.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+--- a/drivers/remoteproc/remoteproc_core.c
++++ b/drivers/remoteproc/remoteproc_core.c
+@@ -400,7 +400,7 @@ rproc_parse_vring(struct rproc_vdev *rvd
+ void rproc_free_vring(struct rproc_vring *rvring)
+ {
+ struct rproc *rproc = rvring->rvdev->rproc;
+- int idx = rvring->rvdev->vring - rvring;
++ int idx = rvring - rvring->rvdev->vring;
+ struct fw_rsc_vdev *rsc;
+
+ idr_remove(&rproc->notifyids, rvring->notifyid);
--- /dev/null
+From 4ab25ac8b2b5514151d5f91cf9514df08dd26938 Mon Sep 17 00:00:00 2001
+From: Richard Weinberger <richard@nod.at>
+Date: Sun, 19 Jan 2020 22:52:33 +0100
+Subject: ubifs: Fix ubifs_tnc_lookup() usage in do_kill_orphans()
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+From: Richard Weinberger <richard@nod.at>
+
+commit 4ab25ac8b2b5514151d5f91cf9514df08dd26938 upstream.
+
+Orphans are allowed to point to deleted inodes.
+So -ENOENT is not a fatal error.
+
+Reported-by: Кочетков Максим <fido_max@inbox.ru>
+Reported-and-tested-by: "Christian Berger" <Christian.Berger@de.bosch.com>
+Tested-by: Karl Olsen <karl@micro-technic.com>
+Tested-by: Jef Driesen <jef.driesen@niko.eu>
+Fixes: ee1438ce5dc4 ("ubifs: Check link count of inodes when killing orphans.")
+Signed-off-by: Richard Weinberger <richard@nod.at>
+Cc: Christian Eggers <ceggers@arri.de>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+
+---
+ fs/ubifs/orphan.c | 4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+--- a/fs/ubifs/orphan.c
++++ b/fs/ubifs/orphan.c
+@@ -688,14 +688,14 @@ static int do_kill_orphans(struct ubifs_
+
+ ino_key_init(c, &key1, inum);
+ err = ubifs_tnc_lookup(c, &key1, ino);
+- if (err)
++ if (err && err != -ENOENT)
+ goto out_free;
+
+ /*
+ * Check whether an inode can really get deleted.
+ * linkat() with O_TMPFILE allows rebirth of an inode.
+ */
+- if (ino->nlink == 0) {
++ if (err == 0 && ino->nlink == 0) {
+ dbg_rcvry("deleting orphaned inode %lu",
+ (unsigned long)inum);
+