openwrt/staging/blogic.git
13 years agofeature-removal-schedule.txt: schedule the deprecated form of kmap_atomic() for removal
Cong Wang [Sat, 26 Nov 2011 03:12:30 +0000 (11:12 +0800)]
feature-removal-schedule.txt: schedule the deprecated form of kmap_atomic() for removal

Signed-off-by: Cong Wang <[email protected]>
13 years agohighmem: kill all __kmap_atomic()
Cong Wang [Sat, 26 Nov 2011 02:53:39 +0000 (10:53 +0800)]
highmem: kill all __kmap_atomic()
[[email protected]: highmem: Fix ARM build break due to __kmap_atomic rename]

Signed-off-by: Stephen Warren <[email protected]>
Signed-off-by: Cong Wang <[email protected]>
13 years agodrbd: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:51:58 +0000 (23:51 +0800)]
drbd: remove the second argument of k[un]map_atomic()

Signed-off-by: Cong Wang <[email protected]>
13 years agozcache: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:50:19 +0000 (23:50 +0800)]
zcache: remove the second argument of k[un]map_atomic()

Acked-by: Greg Kroah-Hartman <[email protected]>
Signed-off-by: Cong Wang <[email protected]>
13 years agogma500: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:46:51 +0000 (23:46 +0800)]
gma500: remove the second argument of k[un]map_atomic()

Signed-off-by: Cong Wang <[email protected]>
13 years agodm: remove the second argument of k[un]map_atomic()
Cong Wang [Mon, 28 Nov 2011 05:26:02 +0000 (13:26 +0800)]
dm: remove the second argument of k[un]map_atomic()

Acked-by: Milan Broz <[email protected]>
Signed-off-by: Cong Wang <[email protected]>
13 years agotomoyo: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:26:35 +0000 (23:26 +0800)]
tomoyo: remove the second argument of k[un]map_atomic()

Acked-by: Tetsuo Handa <[email protected]>
Signed-off-by: Cong Wang <[email protected]>
13 years agosunrpc: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:40 +0000 (23:14 +0800)]
sunrpc: remove the second argument of k[un]map_atomic()

Signed-off-by: Cong Wang <[email protected]>
13 years agords: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:40 +0000 (23:14 +0800)]
rds: remove the second argument of k[un]map_atomic()

Acked-by: David S. Miller <[email protected]>
Signed-off-by: Cong Wang <[email protected]>
13 years agonet: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:39 +0000 (23:14 +0800)]
net: remove the second argument of k[un]map_atomic()

Acked-by: David S. Miller <[email protected]>
Signed-off-by: Cong Wang <[email protected]>
13 years agomm: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:39 +0000 (23:14 +0800)]
mm: remove the second argument of k[un]map_atomic()

Signed-off-by: Cong Wang <[email protected]>
13 years agolib: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:39 +0000 (23:14 +0800)]
lib: remove the second argument of k[un]map_atomic()

Signed-off-by: Cong Wang <[email protected]>
13 years agopower: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:38 +0000 (23:14 +0800)]
power: remove the second argument of k[un]map_atomic()

Acked-by: Rafael J. Wysocki <[email protected]>
Signed-off-by: Cong Wang <[email protected]>
13 years agokdb: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:38 +0000 (23:14 +0800)]
kdb: remove the second argument of k[un]map_atomic()

Signed-off-by: Cong Wang <[email protected]>
13 years agoudf: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:36 +0000 (23:14 +0800)]
udf: remove the second argument of k[un]map_atomic()

Acked-by: Jan Kara <[email protected]>
Signed-off-by: Cong Wang <[email protected]>
13 years agoubifs: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:36 +0000 (23:14 +0800)]
ubifs: remove the second argument of k[un]map_atomic()

Signed-off-by: Cong Wang <[email protected]>
13 years agosquashfs: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:36 +0000 (23:14 +0800)]
squashfs: remove the second argument of k[un]map_atomic()

Signed-off-by: Cong Wang <[email protected]>
13 years agoreiserfs: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:35 +0000 (23:14 +0800)]
reiserfs: remove the second argument of k[un]map_atomic()

Signed-off-by: Cong Wang <[email protected]>
13 years agoocfs2: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:34 +0000 (23:14 +0800)]
ocfs2: remove the second argument of k[un]map_atomic()

Acked-by: Joel Becker <[email protected]>
Signed-off-by: Cong Wang <[email protected]>
13 years agontfs: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:34 +0000 (23:14 +0800)]
ntfs: remove the second argument of k[un]map_atomic()

Signed-off-by: Cong Wang <[email protected]>
13 years agonilfs2: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:33 +0000 (23:14 +0800)]
nilfs2: remove the second argument of k[un]map_atomic()

Acked-by: Ryusuke Konishi <[email protected]>
Signed-off-by: Cong Wang <[email protected]>
13 years agonfs: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:33 +0000 (23:14 +0800)]
nfs: remove the second argument of k[un]map_atomic()

Signed-off-by: Cong Wang <[email protected]>
13 years agominix: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:32 +0000 (23:14 +0800)]
minix: remove the second argument of k[un]map_atomic()

Signed-off-by: Cong Wang <[email protected]>
13 years agologfs: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:31 +0000 (23:14 +0800)]
logfs: remove the second argument of k[un]map_atomic()

Signed-off-by: Cong Wang <[email protected]>
13 years agojbd2: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:31 +0000 (23:14 +0800)]
jbd2: remove the second argument of k[un]map_atomic()

Signed-off-by: Cong Wang <[email protected]>
13 years agojbd: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:31 +0000 (23:14 +0800)]
jbd: remove the second argument of k[un]map_atomic()

Acked-by: Jan Kara <[email protected]>
Signed-off-by: Cong Wang <[email protected]>
13 years agogfs2: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:30 +0000 (23:14 +0800)]
gfs2: remove the second argument of k[un]map_atomic()

Signed-off-by: Cong Wang <[email protected]>
13 years agofuse: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:30 +0000 (23:14 +0800)]
fuse: remove the second argument of k[un]map_atomic()

Signed-off-by: Cong Wang <[email protected]>
13 years agoext2: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:29 +0000 (23:14 +0800)]
ext2: remove the second argument of k[un]map_atomic()

Acked-by: Jan Kara <[email protected]>
Signed-off-by: Cong Wang <[email protected]>
13 years agoexofs: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:29 +0000 (23:14 +0800)]
exofs: remove the second argument of k[un]map_atomic()

Ack-by: Boaz Harrosh <[email protected]>
Signed-off-by: Cong Wang <[email protected]>
13 years agoafs: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:26 +0000 (23:14 +0800)]
afs: remove the second argument of k[un]map_atomic()

Signed-off-by: Cong Wang <[email protected]>
13 years agobtrfs: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:28 +0000 (23:14 +0800)]
btrfs: remove the second argument of k[un]map_atomic()

Signed-off-by: Cong Wang <[email protected]>
13 years agofs: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:27 +0000 (23:14 +0800)]
fs: remove the second argument of k[un]map_atomic()

Acked-by: Benjamin LaHaise <[email protected]>
Signed-off-by: Cong Wang <[email protected]>
13 years agovhost: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:26 +0000 (23:14 +0800)]
vhost: remove the second argument of k[un]map_atomic()

Signed-off-by: Cong Wang <[email protected]>
13 years agotarget: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:25 +0000 (23:14 +0800)]
target: remove the second argument of k[un]map_atomic()

Signed-off-by: Cong Wang <[email protected]>
13 years agozram: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:25 +0000 (23:14 +0800)]
zram: remove the second argument of k[un]map_atomic()

Acked-by: Greg Kroah-Hartman <[email protected]>
Signed-off-by: Cong Wang <[email protected]>
13 years agortl8192u: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:25 +0000 (23:14 +0800)]
rtl8192u: remove the second argument of k[un]map_atomic()

Acked-by: Greg Kroah-Hartman <[email protected]>
Signed-off-by: Cong Wang <[email protected]>
13 years agohv: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:24 +0000 (23:14 +0800)]
hv: remove the second argument of k[un]map_atomic()

Acked-by: Greg Kroah-Hartman <[email protected]>
Signed-off-by: Cong Wang <[email protected]>
13 years agoscsi: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:23 +0000 (23:14 +0800)]
scsi: remove the second argument of k[un]map_atomic()

Signed-off-by: Cong Wang <[email protected]>
13 years agonet: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:23 +0000 (23:14 +0800)]
net: remove the second argument of k[un]map_atomic()

Acked-by: David S. Miller <[email protected]>
Signed-off-by: Cong Wang <[email protected]>
13 years agomemstick: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:22 +0000 (23:14 +0800)]
memstick: remove the second argument of k[un]map_atomic()

Signed-off-by: Cong Wang <[email protected]>
13 years agomedia: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:21 +0000 (23:14 +0800)]
media: remove the second argument of k[un]map_atomic()

Acked-by: Andy Walls <[email protected]>
Signed-off-by: Cong Wang <[email protected]>
13 years agomd: remove the second argument of k[un]map_atomic()
Cong Wang [Mon, 28 Nov 2011 05:25:44 +0000 (13:25 +0800)]
md: remove the second argument of k[un]map_atomic()

Acked-by: NeilBrown <[email protected]>
Signed-off-by: Cong Wang <[email protected]>
13 years agoinfiniband: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:20 +0000 (23:14 +0800)]
infiniband: remove the second argument of k[un]map_atomic()

Acked-by: Roland Dreier <[email protected]>
Signed-off-by: Cong Wang <[email protected]>
13 years agoide: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:20 +0000 (23:14 +0800)]
ide: remove the second argument of k[un]map_atomic()

Acked-by: David S. Miller <[email protected]>
Signed-off-by: Cong Wang <[email protected]>
13 years agodrm: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:20 +0000 (23:14 +0800)]
drm: remove the second argument of k[un]map_atomic()

Signed-off-by: Cong Wang <[email protected]>
13 years agoedac: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:19 +0000 (23:14 +0800)]
edac: remove the second argument of k[un]map_atomic()

Signed-off-by: Cong Wang <[email protected]>
13 years agocrypto: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:19 +0000 (23:14 +0800)]
crypto: remove the second argument of k[un]map_atomic()

Signed-off-by: Cong Wang <[email protected]>
13 years agoblock: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:18 +0000 (23:14 +0800)]
block: remove the second argument of k[un]map_atomic()

Signed-off-by: Cong Wang <[email protected]>
13 years agoata: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:18 +0000 (23:14 +0800)]
ata: remove the second argument of k[un]map_atomic()

Acked-by: Jeff Garzik <[email protected]>
Signed-off-by: Cong Wang <[email protected]>
13 years agocrypto: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:17 +0000 (23:14 +0800)]
crypto: remove the second argument of k[un]map_atomic()

Signed-off-by: Cong Wang <[email protected]>
13 years agox86: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:17 +0000 (23:14 +0800)]
x86: remove the second argument of k[un]map_atomic()

Acked-by: Avi Kivity <[email protected]>
Acked-by: Herbert Xu <[email protected]>
Signed-off-by: Cong Wang <[email protected]>
13 years agoum: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:17 +0000 (23:14 +0800)]
um: remove the second argument of k[un]map_atomic()

Signed-off-by: Cong Wang <[email protected]>
13 years agosh: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:16 +0000 (23:14 +0800)]
sh: remove the second argument of k[un]map_atomic()

Signed-off-by: Cong Wang <[email protected]>
13 years agopowerpc: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:16 +0000 (23:14 +0800)]
powerpc: remove the second argument of k[un]map_atomic()

Signed-off-by: Cong Wang <[email protected]>
13 years agomips: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:15 +0000 (23:14 +0800)]
mips: remove the second argument of k[un]map_atomic()

Signed-off-by: Cong Wang <[email protected]>
13 years agoarm: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:15 +0000 (23:14 +0800)]
arm: remove the second argument of k[un]map_atomic()

Signed-off-by: Cong Wang <[email protected]>
13 years agoinclude/linux/highmem.h: remove the second argument of k[un]map_atomic()
Cong Wang [Fri, 25 Nov 2011 15:14:14 +0000 (23:14 +0800)]
include/linux/highmem.h: remove the second argument of k[un]map_atomic()

Signed-off-by: Cong Wang <[email protected]>
13 years agohighmem: mark k[un]map_atomic() with two arguments as deprecated
Cong Wang [Fri, 25 Nov 2011 14:08:45 +0000 (22:08 +0800)]
highmem: mark k[un]map_atomic() with two arguments as deprecated

For backward compatibility, we still keep the deprecated form,
and will warn the users if they still use the deprecated one, like this:

drivers/block/drbd/drbd_bitmap.c: In function â€˜bm_page_io_async’:
drivers/block/drbd/drbd_bitmap.c:973:3: warning: â€˜kmap_atomic_deprecated’ is deprecated (declared at /home/wangcong/linux-2.6/include/linux/highmem.h:124)
drivers/block/drbd/drbd_bitmap.c:977:3: warning: â€˜kunmap_atomic_deprecated’ is deprecated (declared at /home/wangcong/linux-2.6/include/linux/highmem.h:144)

Thanks to Nick Bowler for the cpp trick!

Cc: Cesar Eduardo Barros <[email protected]>
Cc: Nick Bowler <[email protected]>
Cc: Peter Zijlstra <[email protected]>
Signed-off-by: Cong Wang <[email protected]>
13 years agoLinux 3.3
Linus Torvalds [Sun, 18 Mar 2012 23:15:34 +0000 (16:15 -0700)]
Linux 3.3

13 years agoDon't limit non-nested epoll paths
Jason Baron [Fri, 16 Mar 2012 20:34:03 +0000 (16:34 -0400)]
Don't limit non-nested epoll paths

Commit 28d82dc1c4ed ("epoll: limit paths") that I did to limit the
number of possible wakeup paths in epoll is causing a few applications
to longer work (dovecot for one).

The original patch is really about limiting the amount of epoll nesting
(since epoll fds can be attached to other fds). Thus, we probably can
allow an unlimited number of paths of depth 1. My current patch limits
it at 1000. And enforce the limits on paths that have a greater depth.

This is captured in: https://bugzilla.redhat.com/show_bug.cgi?id=681578

Signed-off-by: Jason Baron <[email protected]>
Cc: Andrew Morton <[email protected]>
Signed-off-by: Linus Torvalds <[email protected]>
13 years agoMerge git://git.kernel.org/pub/scm/linux/kernel/git/davem/net
Linus Torvalds [Sun, 18 Mar 2012 02:22:24 +0000 (19:22 -0700)]
Merge git://git./linux/kernel/git/davem/net

Pull networking changes from David Miller:
 "1) icmp6_dst_alloc() returns NULL instead of ERR_PTR() leading to
     crashes, particularly during shutdown.  Reported by Dave Jones and
     fixed by Eric Dumazet.

  2) hyperv and wimax/i2400m return NETDEV_TX_BUSY when they have
     already freed the SKB, which causes crashes as to the caller this
     means requeue the packet.  Fixes from Eric Dumazet.

  3) usbnet driver doesn't allocate the right amount of headroom on
     fresh RX SKBs, fix from Eric Dumazet.

  4) Fix regression in ip6_mc_find_dev_rcu(), as an RCU lookup it
     abolutely should not take a reference to 'dev', this leads to
     leaks.  Fix from RonQing Li.

  5) Fix netfilter ctnetlink race between delete and timeout expiration.
     From Pablo Neira Ayuso.

  6) Revert SFQ change which causes regressions, specifically queueing
     to tail can lead to unavoidable flow starvation.  From Eric
     Dumazet.

  7) Fix a memory leak and a crash on corrupt firmware files in bnx2x,
     from Michal Schmidt."

* git://git.kernel.org/pub/scm/linux/kernel/git/davem/net:
  netfilter: ctnetlink: fix race between delete and timeout expiration
  ipv6: Don't dev_hold(dev) in ip6_mc_find_dev_rcu.
  wimax/i2400m: fix erroneous NETDEV_TX_BUSY use
  net/hyperv: fix erroneous NETDEV_TX_BUSY use
  net/usbnet: reserve headroom on rx skbs
  bnx2x: fix memory leak in bnx2x_init_firmware()
  bnx2x: fix a crash on corrupt firmware file
  sch_sfq: revert dont put new flow at the end of flows
  ipv6: fix icmp6_dst_alloc()

13 years agoMerge branch 'perf-urgent-for-linus' of git://git.kernel.org/pub/scm/linux/kernel...
Linus Torvalds [Sat, 17 Mar 2012 16:54:16 +0000 (09:54 -0700)]
Merge branch 'perf-urgent-for-linus' of git://git./linux/kernel/git/tip/tip

Pull perf fixes from Ingo Molnar.

* 'perf-urgent-for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  perf tools, x86: Build perf on older user-space as well
  perf tools: Use scnprintf where applicable
  perf tools: Incorrect use of snprintf results in SEGV

13 years agonetfilter: ctnetlink: fix race between delete and timeout expiration
Pablo Neira Ayuso [Fri, 16 Mar 2012 02:00:34 +0000 (02:00 +0000)]
netfilter: ctnetlink: fix race between delete and timeout expiration

Kerin Millar reported hardlockups while running `conntrackd -c'
in a busy firewall. That system (with several processors) was
acting as backup in a primary-backup setup.

After several tries, I found a race condition between the deletion
operation of ctnetlink and timeout expiration. This patch fixes
this problem.

Tested-by: Kerin Millar <[email protected]>
Reported-by: Kerin Millar <[email protected]>
Signed-off-by: Pablo Neira Ayuso <[email protected]>
Signed-off-by: David S. Miller <[email protected]>
13 years agoipv6: Don't dev_hold(dev) in ip6_mc_find_dev_rcu.
RongQing.Li [Thu, 15 Mar 2012 22:54:14 +0000 (22:54 +0000)]
ipv6: Don't dev_hold(dev) in ip6_mc_find_dev_rcu.

ip6_mc_find_dev_rcu() is called with rcu_read_lock(), so don't
need to dev_hold().
With dev_hold(), not corresponding dev_put(), will lead to leak.

[ bug introduced in 96b52e61be1 (ipv6: mcast: RCU conversions) ]

Signed-off-by: RongQing.Li <[email protected]>
Acked-by: Eric Dumazet <[email protected]>
Signed-off-by: David S. Miller <[email protected]>
13 years agoMerge branch 'akpm' (more patches from Andrew)
Linus Torvalds [Sat, 17 Mar 2012 00:14:55 +0000 (17:14 -0700)]
Merge branch 'akpm' (more patches from Andrew)

Merge some more email patches from Andrew Morton:
 "A couple of nilfs fixes"

* emailed from Andrew Morton <[email protected]>:
  nilfs2: fix NULL pointer dereference in nilfs_load_super_block()
  nilfs2: clamp ns_r_segments_percentage to [1, 99]

13 years agonilfs2: fix NULL pointer dereference in nilfs_load_super_block()
Ryusuke Konishi [Sat, 17 Mar 2012 00:08:39 +0000 (17:08 -0700)]
nilfs2: fix NULL pointer dereference in nilfs_load_super_block()

According to the report from Slicky Devil, nilfs caused kernel oops at
nilfs_load_super_block function during mount after he shrank the
partition without resizing the filesystem:

 BUG: unable to handle kernel NULL pointer dereference at 00000048
 IP: [<d0d7a08e>] nilfs_load_super_block+0x17e/0x280 [nilfs2]
 *pde = 00000000
 Oops: 0000 [#1] PREEMPT SMP
 ...
 Call Trace:
  [<d0d7a87b>] init_nilfs+0x4b/0x2e0 [nilfs2]
  [<d0d6f707>] nilfs_mount+0x447/0x5b0 [nilfs2]
  [<c0226636>] mount_fs+0x36/0x180
  [<c023d961>] vfs_kern_mount+0x51/0xa0
  [<c023ddae>] do_kern_mount+0x3e/0xe0
  [<c023f189>] do_mount+0x169/0x700
  [<c023fa9b>] sys_mount+0x6b/0xa0
  [<c04abd1f>] sysenter_do_call+0x12/0x28
 Code: 53 18 8b 43 20 89 4b 18 8b 4b 24 89 53 1c 89 43 24 89 4b 20 8b 43
 20 c7 43 2c 00 00 00 00 23 75 e8 8b 50 68 89 53 28 8b 54 b3 20 <8b> 72
 48 8b 7a 4c 8b 55 08 89 b3 84 00 00 00 89 bb 88 00 00 00
 EIP: [<d0d7a08e>] nilfs_load_super_block+0x17e/0x280 [nilfs2] SS:ESP 0068:ca9bbdcc
 CR2: 0000000000000048

This turned out due to a defect in an error path which runs if the
calculated location of the secondary super block was invalid.

This patch fixes it and eliminates the reported oops.

Reported-by: Slicky Devil <[email protected]>
Signed-off-by: Ryusuke Konishi <[email protected]>
Tested-by: Slicky Devil <[email protected]>
Cc: <[email protected]> [2.6.30+]
Signed-off-by: Andrew Morton <[email protected]>
Signed-off-by: Linus Torvalds <[email protected]>
13 years agonilfs2: clamp ns_r_segments_percentage to [1, 99]
Haogang Chen [Sat, 17 Mar 2012 00:08:38 +0000 (17:08 -0700)]
nilfs2: clamp ns_r_segments_percentage to [1, 99]

ns_r_segments_percentage is read from the disk.  Bogus or malicious
value could cause integer overflow and malfunction due to meaningless
disk usage calculation.  This patch reports error when mounting such
bogus volumes.

Signed-off-by: Haogang Chen <[email protected]>
Signed-off-by: Ryusuke Konishi <[email protected]>
Signed-off-by: Andrew Morton <[email protected]>
Signed-off-by: Linus Torvalds <[email protected]>
13 years agoMerge branch 'for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris...
Linus Torvalds [Sat, 17 Mar 2012 00:04:02 +0000 (17:04 -0700)]
Merge branch 'for-linus' of git://git./linux/kernel/git/jmorris/linux-security

Pull maintainer update from James Morris:
 "Please pull this patch which adds Serge as maintainer of the
  capabilities code, as discussed on lwn and the lsm list.

  New capabilities must be signed off by the maintainer, and new uses of
  any capabilities should at be cc'd to the maintainer."

* 'for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/linux-security:
  MAINTAINERS: Add Serge as maintainer of capabilities

13 years agoMerge tag 'for-linus' of git://linux-c6x.org/git/projects/linux-c6x-upstreaming
Linus Torvalds [Sat, 17 Mar 2012 00:03:15 +0000 (17:03 -0700)]
Merge tag 'for-linus' of git://linux-c6x.org/git/projects/linux-c6x-upstreaming

Pull c6x bugfix from Mark Salter:
 "Remove dead code from entry.S which causes a build failure when using
  a newer assembler (v2.22 complains about it, v2.20 ignores it)."

* tag 'for-linus' of git://linux-c6x.org/git/projects/linux-c6x-upstreaming:
  C6X: remove dead code from entry.S

13 years agoafs: Remote abort can cause BUG in rxrpc code
Anton Blanchard [Fri, 16 Mar 2012 10:28:19 +0000 (10:28 +0000)]
afs: Remote abort can cause BUG in rxrpc code

When writing files to afs I sometimes hit a BUG:

kernel BUG at fs/afs/rxrpc.c:179!

With a backtrace of:

afs_free_call
afs_make_call
afs_fs_store_data
afs_vnode_store_data
afs_write_back_from_locked_page
afs_writepages_region
afs_writepages

The cause is:

ASSERT(skb_queue_empty(&call->rx_queue));

Looking at a tcpdump of the session the abort happens because we
are exceeding our disk quota:

rx abort fs reply store-data error diskquota exceeded (32)

So the abort error is valid. We hit the BUG because we haven't
freed all the resources for the call.

By freeing any skbs in call->rx_queue before calling afs_free_call
we avoid hitting leaking memory and avoid hitting the BUG.

Signed-off-by: Anton Blanchard <[email protected]>
Signed-off-by: David Howells <[email protected]>
Cc: <[email protected]>
Signed-off-by: Linus Torvalds <[email protected]>
13 years agoafs: Read of file returns EBADMSG
Anton Blanchard [Fri, 16 Mar 2012 10:28:07 +0000 (10:28 +0000)]
afs: Read of file returns EBADMSG

A read of a large file on an afs mount failed:

# cat junk.file > /dev/null
cat: junk.file: Bad message

Looking at the trace, call->offset wrapped since it is only an
unsigned short. In afs_extract_data:

        _enter("{%u},{%zu},%d,,%zu", call->offset, len, last, count);
...

        if (call->offset < count) {
                if (last) {
                        _leave(" = -EBADMSG [%d < %zu]", call->offset, count);
                        return -EBADMSG;
                }

Which matches the trace:

[cat   ] ==> afs_extract_data({65132},{524},1,,65536)
[cat   ] <== afs_extract_data() = -EBADMSG [0 < 65536]

call->offset went from 65132 to 0. Fix this by making call->offset an
unsigned int.

Signed-off-by: Anton Blanchard <[email protected]>
Signed-off-by: David Howells <[email protected]>
Cc: <[email protected]>
Signed-off-by: Linus Torvalds <[email protected]>
13 years agoC6X: remove dead code from entry.S
Mark Salter [Fri, 16 Mar 2012 13:27:57 +0000 (09:27 -0400)]
C6X: remove dead code from entry.S

The ENDPROC() on sys_fadvise64_c6x() in arch/c6x/kernel/entry.S is
outside of the conditional block with the matching ENTRY() macro. This
leads a newer (v2.22 vs. v2.20) assembler to complain:

  /tmp/ccGZBaPT.s: Assembler messages:
  /tmp/ccGZBaPT.s: Error: .size expression for sys_fadvise64_c6x does not evaluate to a constant

The conditional block became dead code when c6x switched to generic
unistd.h and should be removed along with the offending ENDPROC().

Signed-off-by: Mark Salter <[email protected]>
Acked-by: David Howells <[email protected]>
13 years agowimax/i2400m: fix erroneous NETDEV_TX_BUSY use
Eric Dumazet [Wed, 14 Mar 2012 09:21:44 +0000 (09:21 +0000)]
wimax/i2400m: fix erroneous NETDEV_TX_BUSY use

A driver start_xmit() method cannot free skb and return NETDEV_TX_BUSY,
since caller is going to reuse freed skb.

In fact netif_tx_stop_queue() / netif_stop_queue() is needed before
returning NETDEV_TX_BUSY or you can trigger a ksoftirqd fatal loop.

In case of memory allocation error, only safe way is to drop the packet
and return NETDEV_TX_OK

Also increments tx_dropped counter

Signed-off-by: Eric Dumazet <[email protected]>
Cc: Inaky Perez-Gonzalez <[email protected]>
Signed-off-by: David S. Miller <[email protected]>
13 years agonet/hyperv: fix erroneous NETDEV_TX_BUSY use
Eric Dumazet [Wed, 14 Mar 2012 08:53:34 +0000 (08:53 +0000)]
net/hyperv: fix erroneous NETDEV_TX_BUSY use

A driver start_xmit() method cannot free skb and return NETDEV_TX_BUSY,
since caller is going to reuse freed skb.

This is mostly a revert of commit bf769375c (staging: hv: fix the return
status of netvsc_start_xmit())

In fact netif_tx_stop_queue() / netif_stop_queue() is needed before
returning NETDEV_TX_BUSY or you can trigger a ksoftirqd fatal loop.

In case of memory allocation error, only safe way is to drop the packet
and return NETDEV_TX_OK

Signed-off-by: Eric Dumazet <[email protected]>
Cc: "K. Y. Srinivasan" <[email protected]>
Cc: Haiyang Zhang <[email protected]>
Cc: Greg Kroah-Hartman <[email protected]>
Reviewed-by: Haiyang Zhang <[email protected]>
Signed-off-by: David S. Miller <[email protected]>
13 years agonet/usbnet: reserve headroom on rx skbs
Eric Dumazet [Wed, 14 Mar 2012 06:56:25 +0000 (06:56 +0000)]
net/usbnet: reserve headroom on rx skbs

network drivers should reserve some headroom on incoming skbs so that we
dont need expensive reallocations, eg forwarding packets in tunnels.

This NET_SKB_PAD padding is done in various helpers, like
__netdev_alloc_skb_ip_align() in this patch, combining NET_SKB_PAD and
NET_IP_ALIGN magic.

Signed-off-by: Eric Dumazet <[email protected]>
Cc: Oliver Neukum <[email protected]>
Cc: Greg Kroah-Hartman <[email protected]>
Acked-by: Oliver Neukum <[email protected]>
Signed-off-by: David S. Miller <[email protected]>
13 years agobnx2x: fix memory leak in bnx2x_init_firmware()
Michal Schmidt [Thu, 15 Mar 2012 14:08:29 +0000 (14:08 +0000)]
bnx2x: fix memory leak in bnx2x_init_firmware()

When cycling the interface down and up, bnx2x_init_firmware() knows that
the firmware is already loaded, but nevertheless it allocates certain
arrays anew (init_data, init_ops, init_ops_offsets, iro_arr). The old
arrays are leaked.

Fix the leaks by returning early if the firmware was already loaded.
Because if the firmware is loaded, so are the arrays.

Signed-off-by: Michal Schmidt <[email protected]>
Acked-by: Eilon Greenstein <[email protected]>
Signed-off-by: David S. Miller <[email protected]>
13 years agobnx2x: fix a crash on corrupt firmware file
Michal Schmidt [Thu, 15 Mar 2012 14:08:28 +0000 (14:08 +0000)]
bnx2x: fix a crash on corrupt firmware file

If the requested firmware is deemed corrupt and then released, reset the
pointer to NULL in order to avoid double-freeing it in
bnx2x_release_firmware() or dereferencing it in bnx2x_init_firmware().

Signed-off-by: Michal Schmidt <[email protected]>
Acked-by: Eilon Greenstein <[email protected]>
Signed-off-by: David S. Miller <[email protected]>
13 years agosch_sfq: revert dont put new flow at the end of flows
Eric Dumazet [Tue, 13 Mar 2012 18:04:25 +0000 (18:04 +0000)]
sch_sfq: revert dont put new flow at the end of flows

This reverts commit d47a0ac7b6 (sch_sfq: dont put new flow at the end of
flows)

As Jesper found out, patch sounded great but has bad side effects.

In stress situation, pushing new flows in front of the queue can prevent
old flows doing any progress. Packets can stay in SFQ queue for
unlimited amount of time.

It's possible to add heuristics to limit this problem, but this would
add complexity outside of SFQ scope.

A more sensible answer to Dave Taht concerns (who reported the issued I
tried to solve in original commit) is probably to use a qdisc hierarchy
so that high prio packets dont enter a potentially crowded SFQ qdisc.

Reported-by: Jesper Dangaard Brouer <[email protected]>
Cc: Dave Taht <[email protected]>
Signed-off-by: Eric Dumazet <[email protected]>
Signed-off-by: David S. Miller <[email protected]>
13 years agoipv6: fix icmp6_dst_alloc()
Eric Dumazet [Wed, 14 Mar 2012 21:13:11 +0000 (21:13 +0000)]
ipv6: fix icmp6_dst_alloc()

commit 87a115783 ( ipv6: Move xfrm_lookup() call down into
icmp6_dst_alloc().) forgot to convert one error path, leading
to crashes in mld_sendpack()

Many thanks to Dave Jones for providing a very complete bug report.

Reported-by: Dave Jones <[email protected]>
Signed-off-by: Eric Dumazet <[email protected]>
Signed-off-by: David S. Miller <[email protected]>
13 years agoMAINTAINERS: Add Serge as maintainer of capabilities
James Morris [Fri, 16 Mar 2012 01:05:48 +0000 (12:05 +1100)]
MAINTAINERS: Add Serge as maintainer of capabilities

Add Serge as maintainer of capabilities, per suggestion on LWN:
http://lwn.net/Articles/486306/

Signed-off-by: James Morris <[email protected]>
13 years agoMerge branch 'akpm' (Andrew's patch-bomb)
Linus Torvalds [Fri, 16 Mar 2012 00:16:22 +0000 (17:16 -0700)]
Merge branch 'akpm' (Andrew's patch-bomb)

Merge patches from Andrew Morton:
 "Nine patches - some bug fixes and some MAINTAINERS fiddling."

* emailed from Andrew Morton <[email protected]>:
  drivers/video/backlight/s6e63m0.c: fix corruption storing gamma mode
  MAINTAINERS: add entry for exynos mipi display drivers
  MAINTAINERS: fix link to Gustavo Padovans tree
  MAINTAINERS: add Johan to Bluetooth maintainers
  MAINTAINERS: Gustavo has moved
  prctl: use CAP_SYS_RESOURCE for PR_SET_MM option
  rapidio/tsi721: fix bug in register offset definitions
  MAINTAINERS: update ST's Mailing list for SPEAr
  memcg: free mem_cgroup by RCU to fix oops

13 years agoMerge branch 'i2c-for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/jdelvar...
Linus Torvalds [Fri, 16 Mar 2012 00:14:35 +0000 (17:14 -0700)]
Merge branch 'i2c-for-linus' of git://git./linux/kernel/git/jdelvare/staging

Pull i2c subsystem fixes from Jean Delvare.

* 'i2c-for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/jdelvare/staging:
  i2c-algo-bit: Fix spurious SCL timeouts under heavy load
  i2c-core: Comment says "transmitted" but means "received"

13 years agoMerge tag 'hwmon-for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/groeck...
Linus Torvalds [Fri, 16 Mar 2012 00:13:39 +0000 (17:13 -0700)]
Merge tag 'hwmon-for-linus' of git://git./linux/kernel/git/groeck/linux-staging

Pull hwmon fixes from Guenter Roeck.

* tag 'hwmon-for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/groeck/linux-staging:
  hwmon: (zl6100) Enable interval between chip accesses for all chips
  hwmon: (w83627ehf) Describe undocumented pwm attributes
  hwmon: (w83627ehf) Fix temp2 source for W83627UHG
  hwmon: (w83627ehf) Fix memory leak in probe function
  hwmon: (w83627ehf) Fix writing into fan_stop_time for NCT6775F/NCT6776F

13 years agoMerge branch 'drm-fixes' of git://people.freedesktop.org/~airlied/linux
Linus Torvalds [Fri, 16 Mar 2012 00:07:25 +0000 (17:07 -0700)]
Merge branch 'drm-fixes' of git://people.freedesktop.org/~airlied/linux

Pull drm exynos/intel updates from Dave Airlie:
 "Two minor updates from Jesse for Intel SNB fixes, and a few fixes from
  Samsung for exynos.  The pull req has Alan's commit in it since Intel
  based their tree on my tree at that time, but it all seems fine wrt
  merging."

* 'drm-fixes' of git://people.freedesktop.org/~airlied/linux:
  drm exynos: use drm_fb_helper_set_par directly
  drm/exynos: Fix fb_videomode <-> drm_mode_modeinfo conversion
  drm/exynos: fix runtime_pm fimd device state on probe
  drm/exynos: use correct 'exynos-drm' name for platform device
  drm/i915: support 32 bit BGR formats in sprite planes
  drm/i915: fix color order for BGR formats on SNB
  drm/gma500: Fix Cedarview boot failures in 3.3-rc

13 years agoMerge branch 'v4l_for_linus' of git://git.kernel.org/pub/scm/linux/kernel/git/mchehab...
Linus Torvalds [Fri, 16 Mar 2012 00:06:05 +0000 (17:06 -0700)]
Merge branch 'v4l_for_linus' of git://git./linux/kernel/git/mchehab/linux-media

Pull media fixes from Mauro Carvalho Chehab:
 "For 4 fixes for 3.3 (all trivial):
       - uvc video driver: fixes a division by zero;
       - davinci: add module.h to fix compilation;
       - smsusb: fix the delivery system setting;
       - smsdvb: the get_frontend implementation there is broken.

  The smsdvb patch has 127 lines, but it is trivial: instead of
  returning a cache of the set_frontend (with is wrong, as it doesn't
  have the updated values for the data, and the implementation there is
  buggy), it copies the information of the detected DVB parameters from
  the smsdvb private structures into the corresponding DVBv5 struct
  fields."

* 'v4l_for_linus' of git://git.kernel.org/pub/scm/linux/kernel/git/mchehab/linux-media:
  [media] smsdvb: fix get_frontend
  [media] smsusb: fix the default delivery system setting
  [media] media: davinci: added module.h to resolve unresolved macros
  [media] [FOR,v3.3] uvcvideo: Avoid division by 0 in timestamp calculation

13 years agoMerge branch '3.3-urgent' of git://git.kernel.org/pub/scm/linux/kernel/git/nab/target...
Linus Torvalds [Fri, 16 Mar 2012 00:04:56 +0000 (17:04 -0700)]
Merge branch '3.3-urgent' of git://git./linux/kernel/git/nab/target-pending

Pull target fixes from Nicholas Bellinger:
 "This series addresses two recently reported regression bugs related to
  legacy SCSI reservation usage in target core, and iscsi-target
  reservation conflict handling.

  The second patch in particular addresses possible data-corruption with
  SCSI reservations that is specific to iscsi-target fabric LUNs with
  multiple client writers.  Both patches need to go into v3.2 stable
  ASAP, and the branch based on the last target-pending/3.3-rc-fixes
  HEAD.

  Again, thanks to Martin Svec for his help to identify and address this
  regression bug with iscsi-target."

* '3.3-urgent' of git://git.kernel.org/pub/scm/linux/kernel/git/nab/target-pending:
  iscsi-target: Fix reservation conflict -EBUSY response handling bug
  target: Fix compatible reservation handling (CRH=1) with legacy RESERVE/RELEASE

13 years agodrivers/video/backlight/s6e63m0.c: fix corruption storing gamma mode
Dan Carpenter [Thu, 15 Mar 2012 22:17:12 +0000 (15:17 -0700)]
drivers/video/backlight/s6e63m0.c: fix corruption storing gamma mode

strict_strtoul() writes a long but ->gamma_mode only has space to store an
int, so on 64 bit systems we end up scribbling over ->gamma_table_count as
well.  I've changed it to use kstrtouint() instead.

Signed-off-by: Dan Carpenter <[email protected]>
Acked-by: Inki Dae <[email protected]>
Signed-off-by: Florian Tobias Schandinat <[email protected]>
Signed-off-by: Andrew Morton <[email protected]>
Signed-off-by: Linus Torvalds <[email protected]>
13 years agoMAINTAINERS: add entry for exynos mipi display drivers
Donghwa Lee [Thu, 15 Mar 2012 22:17:11 +0000 (15:17 -0700)]
MAINTAINERS: add entry for exynos mipi display drivers

I'd like to add Inki Dae, Donghwa Lee and Kyungmin Park as maintainers
who developers for exynos mipi display drivers for
video/driver/exynos/exynos_mipi* and include/video/exynos_mipi*.

Signed-off-by: Donghwa Lee <[email protected]>
Signed-off-by: Inki Dae <[email protected]>
Signed-off-by: Kyungmin Park <[email protected]>
Cc: Florian Tobias Schandinat <[email protected]>
Cc: Richard Purdie <[email protected]>
Cc: Kukjin Kim <[email protected]>
Cc: Jingoo Han <[email protected]>
Signed-off-by: Andrew Morton <[email protected]>
Signed-off-by: Linus Torvalds <[email protected]>
13 years agoMAINTAINERS: fix link to Gustavo Padovans tree
Johan Hedberg [Thu, 15 Mar 2012 22:17:11 +0000 (15:17 -0700)]
MAINTAINERS: fix link to Gustavo Padovans tree

Gustavo's tree is called just bluetooth.git and not bluetooth-2.6.git
anymore.

Signed-off-by: Johan Hedberg <[email protected]>
Cc: Marcel Holtmann <[email protected]>
Cc: "Gustavo F. Padovan" <[email protected]>
Signed-off-by: Andrew Morton <[email protected]>
Signed-off-by: Linus Torvalds <[email protected]>
13 years agoMAINTAINERS: add Johan to Bluetooth maintainers
Johan Hedberg [Thu, 15 Mar 2012 22:17:11 +0000 (15:17 -0700)]
MAINTAINERS: add Johan to Bluetooth maintainers

I've been coordinating Bluetooth patches in my tree for some time and
it's possible I'll do it in the future too, so add myself to the
Bluetooth sections as well as mention my tree there.

Signed-off-by: Johan Hedberg <[email protected]>
Cc: Marcel Holtmann <[email protected]>
Cc: "Gustavo F. Padovan" <[email protected]>
Signed-off-by: Andrew Morton <[email protected]>
Signed-off-by: Linus Torvalds <[email protected]>
13 years agoMAINTAINERS: Gustavo has moved
Gustavo Padovan [Thu, 15 Mar 2012 22:17:10 +0000 (15:17 -0700)]
MAINTAINERS: Gustavo has moved

This is going to be the primary e-mail for kernel development.

Signed-off-by: Gustavo Padovan <[email protected]>
Cc: Johan Hedberg <[email protected]>
Cc: Marcel Holtmann <[email protected]>
Signed-off-by: Andrew Morton <[email protected]>
Signed-off-by: Linus Torvalds <[email protected]>
13 years agoprctl: use CAP_SYS_RESOURCE for PR_SET_MM option
Cyrill Gorcunov [Thu, 15 Mar 2012 22:17:10 +0000 (15:17 -0700)]
prctl: use CAP_SYS_RESOURCE for PR_SET_MM option

CAP_SYS_ADMIN is already overloaded left and right, so to have more
fine-grained access control use CAP_SYS_RESOURCE here.

The CAP_SYS_RESOUCE is chosen because this prctl option allows a current
process to adjust some fields of memory map descriptor which rather
represents what the process owns: pointers to code, data, stack
segments, command line, auxiliary vector data and etc.

Suggested-by: Michael Kerrisk <[email protected]>
Acked-by: Kees Cook <[email protected]>
Acked-by: Michael Kerrisk <[email protected]>
Cc: Pavel Emelyanov <[email protected]>
Cc: Tejun Heo <[email protected]>
Cc: Oleg Nesterov <[email protected]>
Cc: Paul Bolle <[email protected]>
Cc: KOSAKI Motohiro <[email protected]>
Signed-off-by: Cyrill Gorcunov <[email protected]>
Signed-off-by: Andrew Morton <[email protected]>
Signed-off-by: Linus Torvalds <[email protected]>
13 years agorapidio/tsi721: fix bug in register offset definitions
Alexandre Bounine [Thu, 15 Mar 2012 22:17:09 +0000 (15:17 -0700)]
rapidio/tsi721: fix bug in register offset definitions

Fix indexed register offset definitions that use decimal (wrong) instead
of hexadecimal (correct) notation for indexing multipliers.

Incorrect definitions do not affect Tsi721 driver in its current default
configuration because it uses only IDB queue 0.  Loss of inbound
doorbell functionality should be observed if queue other than 0 is used.

Signed-off-by: Alexandre Bounine <[email protected]>
Cc: Matt Porter <[email protected]>
Cc: Chul Kim <[email protected]>
Cc: <[email protected]> [3.2+]
Signed-off-by: Andrew Morton <[email protected]>
Signed-off-by: Linus Torvalds <[email protected]>
13 years agoMAINTAINERS: update ST's Mailing list for SPEAr
Viresh Kumar [Thu, 15 Mar 2012 22:17:09 +0000 (15:17 -0700)]
MAINTAINERS: update ST's Mailing list for SPEAr

We have created a ST's Mailing list for SPEAr.  This can be accessed
from non-st email ids.  I want people to cc this list, when they have
changes specific to SPEAr.  So, its better to get this updated in
MAINTAINERS file.

[email protected] is also added for SPEAr.

Signed-off-by: Viresh Kumar <[email protected]>
Cc: Russell King <[email protected]>
Signed-off-by: Andrew Morton <[email protected]>
Signed-off-by: Linus Torvalds <[email protected]>
13 years agomemcg: free mem_cgroup by RCU to fix oops
Hugh Dickins [Thu, 15 Mar 2012 22:17:07 +0000 (15:17 -0700)]
memcg: free mem_cgroup by RCU to fix oops

After fixing the GPF in mem_cgroup_lru_del_list(), three times one
machine running a similar load (moving and removing memcgs while
swapping) has oopsed in mem_cgroup_zone_nr_lru_pages(), when retrieving
memcg zone numbers for get_scan_count() for shrink_mem_cgroup_zone():
this is where a struct mem_cgroup is first accessed after being chosen
by mem_cgroup_iter().

Just what protects a struct mem_cgroup from being freed, in between
mem_cgroup_iter()'s css_get_next() and its css_tryget()? css_tryget()
fails once css->refcnt is zero with CSS_REMOVED set in flags, yes: but
what if that memory is freed and reused for something else, which sets
"refcnt" non-zero? Hmm, and scope for an indefinite freeze if refcnt is
left at zero but flags are cleared.

It's tempting to move the css_tryget() into css_get_next(), to make it
really "get" the css, but I don't think that actually solves anything:
the same difficulty in moving from css_id found to stable css remains.

But we already have rcu_read_lock() around the two, so it's easily fixed
if __mem_cgroup_free() just uses kfree_rcu() to free mem_cgroup.

However, a big struct mem_cgroup is allocated with vzalloc() instead of
kzalloc(), and we're not allowed to vfree() at interrupt time: there
doesn't appear to be a general vfree_rcu() to help with this, so roll
our own using schedule_work().  The compiler decently removes
vfree_work() and vfree_rcu() when the config doesn't need them.

Signed-off-by: Hugh Dickins <[email protected]>
Acked-by: KAMEZAWA Hiroyuki <[email protected]>
Acked-by: Johannes Weiner <[email protected]>
Cc: Konstantin Khlebnikov <[email protected]>
Cc: Tejun Heo <[email protected]>
Cc: Ying Han <[email protected]>
Signed-off-by: Andrew Morton <[email protected]>
Signed-off-by: Linus Torvalds <[email protected]>
13 years agoi2c-algo-bit: Fix spurious SCL timeouts under heavy load
Ville Syrjala [Thu, 15 Mar 2012 17:11:05 +0000 (18:11 +0100)]
i2c-algo-bit: Fix spurious SCL timeouts under heavy load

When the system is under heavy load, there can be a significant delay
between the getscl() and time_after() calls inside sclhi(). That delay
may cause the time_after() check to trigger after SCL has gone high,
causing sclhi() to return -ETIMEDOUT.

To fix the problem, double check that SCL is still low after the
timeout has been reached, before deciding to return -ETIMEDOUT.

Signed-off-by: Ville Syrjala <[email protected]>
Cc: [email protected]
Signed-off-by: Jean Delvare <[email protected]>
13 years agoi2c-core: Comment says "transmitted" but means "received"
Wolfram Sang [Thu, 15 Mar 2012 17:11:05 +0000 (18:11 +0100)]
i2c-core: Comment says "transmitted" but means "received"

Fix that. Also convert this and the related comment to proper commenting
style.

Signed-off-by: Wolfram Sang <[email protected]>
Signed-off-by: Jean Delvare <[email protected]>
13 years agoMerge branch 'exynos-drm-fixes' of git://git.infradead.org/users/kmpark/linux-samsung...
Dave Airlie [Thu, 15 Mar 2012 09:41:26 +0000 (09:41 +0000)]
Merge branch 'exynos-drm-fixes' of git://git.infradead.org/users/kmpark/linux-samsung into drm-fixes

* 'exynos-drm-fixes' of git://git.infradead.org/users/kmpark/linux-samsung:
  drm exynos: use drm_fb_helper_set_par directly
  drm/exynos: Fix fb_videomode <-> drm_mode_modeinfo conversion
  drm/exynos: fix runtime_pm fimd device state on probe
  drm/exynos: use correct 'exynos-drm' name for platform device

13 years agodrm exynos: use drm_fb_helper_set_par directly
Sascha Hauer [Wed, 14 Mar 2012 10:44:54 +0000 (19:44 +0900)]
drm exynos: use drm_fb_helper_set_par directly

info->fix.visual already is correctly set from drm_fb_helper_fill_fix.
info->fix.line_length is also set from drm_fb_helper_fill_fix,
so drm_fb_helper_set_par directly instead of a custom
exynos_drm_fbdev_set_par.

Signed-off-by: Sascha Hauer <[email protected]>
Signed-off-by: Inki Dae <[email protected]>
Signed-off-by: Kyungmin Park <[email protected]>