commit:     e08a74ee61a711c59997b2bb8cc79fec33ca3c25
Author:     Mike Pagano <mpagano <AT> gentoo <DOT> org>
AuthorDate: Thu Mar 19 12:42:21 2015 +0000
Commit:     Mike Pagano <mpagano <AT> gentoo <DOT> org>
CommitDate: Thu Mar 19 12:42:21 2015 +0000
URL:        https://gitweb.gentoo.org/proj/linux-patches.git/commit/?id=e08a74ee

Linux patch 3.14.36

 0000_README              |    4 +
 1035_linux-3.14.36.patch | 3477 ++++++++++++++++++++++++++++++++++++++++++++++
 2 files changed, 3481 insertions(+)

diff --git a/0000_README b/0000_README
index a9fbb65..66a1015 100644
--- a/0000_README
+++ b/0000_README
@@ -182,6 +182,10 @@ Patch:  1034_linux-3.14.35.patch
 From:   http://www.kernel.org
 Desc:   Linux 3.14.35
 
+Patch:  1035_linux-3.14.36.patch
+From:   http://www.kernel.org
+Desc:   Linux 3.14.36
+
 Patch:  1500_XATTR_USER_PREFIX.patch
 From:   https://bugs.gentoo.org/show_bug.cgi?id=470644
 Desc:   Support for namespace user.pax.* on tmpfs.

diff --git a/1035_linux-3.14.36.patch b/1035_linux-3.14.36.patch
new file mode 100644
index 0000000..ea99fa6
--- /dev/null
+++ b/1035_linux-3.14.36.patch
@@ -0,0 +1,3477 @@
+diff --git a/Makefile b/Makefile
+index 9720e863c06f..4e6537bd8aa0 100644
+--- a/Makefile
++++ b/Makefile
+@@ -1,6 +1,6 @@
+ VERSION = 3
+ PATCHLEVEL = 14
+-SUBLEVEL = 35
++SUBLEVEL = 36
+ EXTRAVERSION =
+ NAME = Remembering Coco
+ 
+diff --git a/arch/arc/include/asm/processor.h 
b/arch/arc/include/asm/processor.h
+index 15334ab66b56..fb95aa807215 100644
+--- a/arch/arc/include/asm/processor.h
++++ b/arch/arc/include/asm/processor.h
+@@ -69,18 +69,19 @@ unsigned long thread_saved_pc(struct task_struct *t);
+ #define release_segments(mm)        do { } while (0)
+ 
+ #define KSTK_EIP(tsk)   (task_pt_regs(tsk)->ret)
++#define KSTK_ESP(tsk)   (task_pt_regs(tsk)->sp)
+ 
+ /*
+  * Where abouts of Task's sp, fp, blink when it was last seen in kernel mode.
+  * Look in process.c for details of kernel stack layout
+  */
+-#define KSTK_ESP(tsk)   (tsk->thread.ksp)
++#define TSK_K_ESP(tsk)                (tsk->thread.ksp)
+ 
+-#define KSTK_REG(tsk, off)    (*((unsigned int *)(KSTK_ESP(tsk) + \
++#define TSK_K_REG(tsk, off)   (*((unsigned int *)(TSK_K_ESP(tsk) + \
+                                       sizeof(struct callee_regs) + off)))
+ 
+-#define KSTK_BLINK(tsk) KSTK_REG(tsk, 4)
+-#define KSTK_FP(tsk)    KSTK_REG(tsk, 0)
++#define TSK_K_BLINK(tsk)      TSK_K_REG(tsk, 4)
++#define TSK_K_FP(tsk)         TSK_K_REG(tsk, 0)
+ 
+ /*
+  * Do necessary setup to start up a newly executed thread.
+diff --git a/arch/arc/kernel/stacktrace.c b/arch/arc/kernel/stacktrace.c
+index 9ce47cfe2303..fb98769b6a98 100644
+--- a/arch/arc/kernel/stacktrace.c
++++ b/arch/arc/kernel/stacktrace.c
+@@ -64,9 +64,9 @@ static void seed_unwind_frame_info(struct task_struct *tsk,
+ 
+               frame_info->task = tsk;
+ 
+-              frame_info->regs.r27 = KSTK_FP(tsk);
+-              frame_info->regs.r28 = KSTK_ESP(tsk);
+-              frame_info->regs.r31 = KSTK_BLINK(tsk);
++              frame_info->regs.r27 = TSK_K_FP(tsk);
++              frame_info->regs.r28 = TSK_K_ESP(tsk);
++              frame_info->regs.r31 = TSK_K_BLINK(tsk);
+               frame_info->regs.r63 = (unsigned int)__switch_to;
+ 
+               /* In the prologue of __switch_to, first FP is saved on stack
+diff --git a/arch/mips/kvm/trace.h b/arch/mips/kvm/trace.h
+index bc9e0f406c08..e51621e36152 100644
+--- a/arch/mips/kvm/trace.h
++++ b/arch/mips/kvm/trace.h
+@@ -26,18 +26,18 @@ TRACE_EVENT(kvm_exit,
+           TP_PROTO(struct kvm_vcpu *vcpu, unsigned int reason),
+           TP_ARGS(vcpu, reason),
+           TP_STRUCT__entry(
+-                      __field(struct kvm_vcpu *, vcpu)
++                      __field(unsigned long, pc)
+                       __field(unsigned int, reason)
+           ),
+ 
+           TP_fast_assign(
+-                      __entry->vcpu = vcpu;
++                      __entry->pc = vcpu->arch.pc;
+                       __entry->reason = reason;
+           ),
+ 
+           TP_printk("[%s]PC: 0x%08lx",
+                     kvm_mips_exit_types_str[__entry->reason],
+-                    __entry->vcpu->arch.pc)
++                    __entry->pc)
+ );
+ 
+ #endif /* _TRACE_KVM_H */
+diff --git a/arch/x86/kernel/entry_64.S b/arch/x86/kernel/entry_64.S
+index 02553d6d183d..06469ee0f26e 100644
+--- a/arch/x86/kernel/entry_64.S
++++ b/arch/x86/kernel/entry_64.S
+@@ -542,11 +542,14 @@ ENTRY(ret_from_fork)
+       testl $3, CS-ARGOFFSET(%rsp)            # from kernel_thread?
+       jz   1f
+ 
+-      testl $_TIF_IA32, TI_flags(%rcx)        # 32-bit compat task needs IRET
+-      jnz  int_ret_from_sys_call
+-
+-      RESTORE_TOP_OF_STACK %rdi, -ARGOFFSET
+-      jmp ret_from_sys_call                   # go to the SYSRET fastpath
++      /*
++       * By the time we get here, we have no idea whether our pt_regs,
++       * ti flags, and ti status came from the 64-bit SYSCALL fast path,
++       * the slow path, or one of the ia32entry paths.
++       * Use int_ret_from_sys_call to return, since it can safely handle
++       * all of the above.
++       */
++      jmp  int_ret_from_sys_call
+ 
+ 1:
+       subq $REST_SKIP, %rsp   # leave space for volatiles
+diff --git a/arch/x86/kvm/emulate.c b/arch/x86/kvm/emulate.c
+index 38d3751472e4..09651d4a9038 100644
+--- a/arch/x86/kvm/emulate.c
++++ b/arch/x86/kvm/emulate.c
+@@ -4646,7 +4646,8 @@ int x86_emulate_insn(struct x86_emulate_ctxt *ctxt)
+               if (rc != X86EMUL_CONTINUE)
+                       goto done;
+       }
+-      ctxt->dst.orig_val = ctxt->dst.val;
++      /* Copy full 64-bit value for CMPXCHG8B.  */
++      ctxt->dst.orig_val64 = ctxt->dst.val64;
+ 
+ special_insn:
+ 
+diff --git a/drivers/acpi/video.c b/drivers/acpi/video.c
+index bb0b90461a6b..997540dc8250 100644
+--- a/drivers/acpi/video.c
++++ b/drivers/acpi/video.c
+@@ -2064,6 +2064,17 @@ EXPORT_SYMBOL(acpi_video_unregister);
+ 
+ static int __init acpi_video_init(void)
+ {
++      /*
++       * Let the module load even if ACPI is disabled (e.g. due to
++       * a broken BIOS) so that i915.ko can still be loaded on such
++       * old systems without an AcpiOpRegion.
++       *
++       * acpi_video_register() will report -ENODEV later as well due
++       * to acpi_disabled when i915.ko tries to register itself afterwards.
++       */
++      if (acpi_disabled)
++              return 0;
++
+       dmi_check_system(video_dmi_table);
+ 
+       if (intel_opregion_present())
+diff --git a/drivers/clk/clk-gate.c b/drivers/clk/clk-gate.c
+index 4a58c55255bd..797bab97cea6 100644
+--- a/drivers/clk/clk-gate.c
++++ b/drivers/clk/clk-gate.c
+@@ -128,7 +128,7 @@ struct clk *clk_register_gate(struct device *dev, const 
char *name,
+       struct clk_init_data init;
+ 
+       if (clk_gate_flags & CLK_GATE_HIWORD_MASK) {
+-              if (bit_idx > 16) {
++              if (bit_idx > 15) {
+                       pr_err("gate bit exceeds LOWORD field\n");
+                       return ERR_PTR(-EINVAL);
+               }
+diff --git a/drivers/clk/sunxi/clk-factors.c b/drivers/clk/sunxi/clk-factors.c
+index 9e232644f07e..ea4db844aee3 100644
+--- a/drivers/clk/sunxi/clk-factors.c
++++ b/drivers/clk/sunxi/clk-factors.c
+@@ -62,7 +62,7 @@ static unsigned long clk_factors_recalc_rate(struct clk_hw 
*hw,
+               p = FACTOR_GET(config->pshift, config->pwidth, reg);
+ 
+       /* Calculate the rate */
+-      rate = (parent_rate * n * (k + 1) >> p) / (m + 1);
++      rate = (parent_rate * (n + config->n_start) * (k + 1) >> p) / (m + 1);
+ 
+       return rate;
+ }
+diff --git a/drivers/clk/sunxi/clk-factors.h b/drivers/clk/sunxi/clk-factors.h
+index 02e1a43ebac7..d2d0efa39379 100644
+--- a/drivers/clk/sunxi/clk-factors.h
++++ b/drivers/clk/sunxi/clk-factors.h
+@@ -15,6 +15,7 @@ struct clk_factors_config {
+       u8 mwidth;
+       u8 pshift;
+       u8 pwidth;
++      u8 n_start;
+ };
+ 
+ struct clk_factors {
+diff --git a/drivers/clk/sunxi/clk-sunxi.c b/drivers/clk/sunxi/clk-sunxi.c
+index abb6c5ac8a10..06a14b808683 100644
+--- a/drivers/clk/sunxi/clk-sunxi.c
++++ b/drivers/clk/sunxi/clk-sunxi.c
+@@ -407,6 +407,7 @@ static struct clk_factors_config sun6i_a31_pll1_config = {
+       .kwidth = 2,
+       .mshift = 0,
+       .mwidth = 2,
++      .n_start = 1,
+ };
+ 
+ static struct clk_factors_config sun4i_pll5_config = {
+diff --git a/drivers/clk/zynq/clkc.c b/drivers/clk/zynq/clkc.c
+index 09dd0173ea0a..5f52f3f62644 100644
+--- a/drivers/clk/zynq/clkc.c
++++ b/drivers/clk/zynq/clkc.c
+@@ -300,6 +300,7 @@ static void __init zynq_clk_setup(struct device_node *np)
+       clks[cpu_2x] = clk_register_gate(NULL, clk_output_name[cpu_2x],
+                       "cpu_2x_div", CLK_IGNORE_UNUSED, SLCR_ARM_CLK_CTRL,
+                       26, 0, &armclk_lock);
++      clk_prepare_enable(clks[cpu_2x]);
+ 
+       clk = clk_register_fixed_factor(NULL, "cpu_1x_div", "cpu_div", 0, 1,
+                       4 + 2 * tmp);
+diff --git a/drivers/firmware/efi/runtime-map.c 
b/drivers/firmware/efi/runtime-map.c
+index 97cdd16a2169..c98b101a73ae 100644
+--- a/drivers/firmware/efi/runtime-map.c
++++ b/drivers/firmware/efi/runtime-map.c
+@@ -170,7 +170,7 @@ int __init efi_runtime_map_init(struct kobject *efi_kobj)
+ 
+       return 0;
+ out_add_entry:
+-      for (j = i - 1; j > 0; j--) {
++      for (j = i - 1; j >= 0; j--) {
+               entry = *(map_entries + j);
+               kobject_put(&entry->kobj);
+       }
+diff --git a/drivers/gpu/drm/radeon/cik.c b/drivers/gpu/drm/radeon/cik.c
+index 8ef67cb4ef1e..f0ed0baddf70 100644
+--- a/drivers/gpu/drm/radeon/cik.c
++++ b/drivers/gpu/drm/radeon/cik.c
+@@ -3558,7 +3558,21 @@ void cik_fence_gfx_ring_emit(struct radeon_device *rdev,
+       struct radeon_ring *ring = &rdev->ring[fence->ring];
+       u64 addr = rdev->fence_drv[fence->ring].gpu_addr;
+ 
+-      /* EVENT_WRITE_EOP - flush caches, send int */
++      /* Workaround for cache flush problems. First send a dummy EOP
++       * event down the pipe with seq one below.
++       */
++      radeon_ring_write(ring, PACKET3(PACKET3_EVENT_WRITE_EOP, 4));
++      radeon_ring_write(ring, (EOP_TCL1_ACTION_EN |
++                               EOP_TC_ACTION_EN |
++                               EVENT_TYPE(CACHE_FLUSH_AND_INV_TS_EVENT) |
++                               EVENT_INDEX(5)));
++      radeon_ring_write(ring, addr & 0xfffffffc);
++      radeon_ring_write(ring, (upper_32_bits(addr) & 0xffff) |
++                              DATA_SEL(1) | INT_SEL(0));
++      radeon_ring_write(ring, fence->seq - 1);
++      radeon_ring_write(ring, 0);
++
++      /* Then send the real EOP event down the pipe. */
+       radeon_ring_write(ring, PACKET3(PACKET3_EVENT_WRITE_EOP, 4));
+       radeon_ring_write(ring, (EOP_TCL1_ACTION_EN |
+                                EOP_TC_ACTION_EN |
+@@ -6809,7 +6823,6 @@ int cik_irq_set(struct radeon_device *rdev)
+       u32 hpd1, hpd2, hpd3, hpd4, hpd5, hpd6;
+       u32 grbm_int_cntl = 0;
+       u32 dma_cntl, dma_cntl1;
+-      u32 thermal_int;
+ 
+       if (!rdev->irq.installed) {
+               WARN(1, "Can't enable IRQ/MSI because no handler is 
installed\n");
+@@ -6846,13 +6859,6 @@ int cik_irq_set(struct radeon_device *rdev)
+       cp_m2p2 = RREG32(CP_ME2_PIPE2_INT_CNTL) & ~TIME_STAMP_INT_ENABLE;
+       cp_m2p3 = RREG32(CP_ME2_PIPE3_INT_CNTL) & ~TIME_STAMP_INT_ENABLE;
+ 
+-      if (rdev->flags & RADEON_IS_IGP)
+-              thermal_int = RREG32_SMC(CG_THERMAL_INT_CTRL) &
+-                      ~(THERM_INTH_MASK | THERM_INTL_MASK);
+-      else
+-              thermal_int = RREG32_SMC(CG_THERMAL_INT) &
+-                      ~(THERM_INT_MASK_HIGH | THERM_INT_MASK_LOW);
+-
+       /* enable CP interrupts on all rings */
+       if (atomic_read(&rdev->irq.ring_int[RADEON_RING_TYPE_GFX_INDEX])) {
+               DRM_DEBUG("cik_irq_set: sw int gfx\n");
+@@ -7010,14 +7016,6 @@ int cik_irq_set(struct radeon_device *rdev)
+               hpd6 |= DC_HPDx_INT_EN;
+       }
+ 
+-      if (rdev->irq.dpm_thermal) {
+-              DRM_DEBUG("dpm thermal\n");
+-              if (rdev->flags & RADEON_IS_IGP)
+-                      thermal_int |= THERM_INTH_MASK | THERM_INTL_MASK;
+-              else
+-                      thermal_int |= THERM_INT_MASK_HIGH | THERM_INT_MASK_LOW;
+-      }
+-
+       WREG32(CP_INT_CNTL_RING0, cp_int_cntl);
+ 
+       WREG32(SDMA0_CNTL + SDMA0_REGISTER_OFFSET, dma_cntl);
+@@ -7071,11 +7069,6 @@ int cik_irq_set(struct radeon_device *rdev)
+       WREG32(DC_HPD5_INT_CONTROL, hpd5);
+       WREG32(DC_HPD6_INT_CONTROL, hpd6);
+ 
+-      if (rdev->flags & RADEON_IS_IGP)
+-              WREG32_SMC(CG_THERMAL_INT_CTRL, thermal_int);
+-      else
+-              WREG32_SMC(CG_THERMAL_INT, thermal_int);
+-
+       return 0;
+ }
+ 
+diff --git a/drivers/gpu/drm/radeon/kv_dpm.c b/drivers/gpu/drm/radeon/kv_dpm.c
+index 351db361239d..c7c7bc5d573f 100644
+--- a/drivers/gpu/drm/radeon/kv_dpm.c
++++ b/drivers/gpu/drm/radeon/kv_dpm.c
+@@ -1121,6 +1121,19 @@ void kv_dpm_enable_bapm(struct radeon_device *rdev, 
bool enable)
+       }
+ }
+ 
++static void kv_enable_thermal_int(struct radeon_device *rdev, bool enable)
++{
++      u32 thermal_int;
++
++      thermal_int = RREG32_SMC(CG_THERMAL_INT_CTRL);
++      if (enable)
++              thermal_int |= THERM_INTH_MASK | THERM_INTL_MASK;
++      else
++              thermal_int &= ~(THERM_INTH_MASK | THERM_INTL_MASK);
++      WREG32_SMC(CG_THERMAL_INT_CTRL, thermal_int);
++
++}
++
+ int kv_dpm_enable(struct radeon_device *rdev)
+ {
+       struct kv_power_info *pi = kv_get_pi(rdev);
+@@ -1232,8 +1245,7 @@ int kv_dpm_late_enable(struct radeon_device *rdev)
+                       DRM_ERROR("kv_set_thermal_temperature_range failed\n");
+                       return ret;
+               }
+-              rdev->irq.dpm_thermal = true;
+-              radeon_irq_set(rdev);
++              kv_enable_thermal_int(rdev, true);
+       }
+ 
+       /* powerdown unused blocks for now */
+@@ -1261,6 +1273,7 @@ void kv_dpm_disable(struct radeon_device *rdev)
+       kv_stop_dpm(rdev);
+       kv_enable_ulv(rdev, false);
+       kv_reset_am(rdev);
++      kv_enable_thermal_int(rdev, false);
+ 
+       kv_update_current_ps(rdev, rdev->pm.dpm.boot_ps);
+ }
+diff --git a/drivers/gpu/drm/radeon/ni.c b/drivers/gpu/drm/radeon/ni.c
+index bf6300cfd62d..f8c01b8d1594 100644
+--- a/drivers/gpu/drm/radeon/ni.c
++++ b/drivers/gpu/drm/radeon/ni.c
+@@ -1073,12 +1073,12 @@ static void cayman_gpu_init(struct radeon_device *rdev)
+ 
+       if ((rdev->config.cayman.max_backends_per_se == 1) &&
+           (rdev->flags & RADEON_IS_IGP)) {
+-              if ((disabled_rb_mask & 3) == 1) {
+-                      /* RB0 disabled, RB1 enabled */
+-                      tmp = 0x11111111;
+-              } else {
++              if ((disabled_rb_mask & 3) == 2) {
+                       /* RB1 disabled, RB0 enabled */
+                       tmp = 0x00000000;
++              } else {
++                      /* RB0 disabled, RB1 enabled */
++                      tmp = 0x11111111;
+               }
+       } else {
+               tmp = gb_addr_config & NUM_PIPES_MASK;
+diff --git a/drivers/gpu/drm/radeon/r600_dpm.c 
b/drivers/gpu/drm/radeon/r600_dpm.c
+index 3334f916945b..e98108236e04 100644
+--- a/drivers/gpu/drm/radeon/r600_dpm.c
++++ b/drivers/gpu/drm/radeon/r600_dpm.c
+@@ -187,7 +187,7 @@ u32 r600_dpm_get_vrefresh(struct radeon_device *rdev)
+               list_for_each_entry(crtc, &dev->mode_config.crtc_list, head) {
+                       radeon_crtc = to_radeon_crtc(crtc);
+                       if (crtc->enabled && radeon_crtc->enabled && 
radeon_crtc->hw_mode.clock) {
+-                              vrefresh = radeon_crtc->hw_mode.vrefresh;
++                              vrefresh = 
drm_mode_vrefresh(&radeon_crtc->hw_mode);
+                               break;
+                       }
+               }
+diff --git a/drivers/gpu/drm/radeon/radeon_atombios.c 
b/drivers/gpu/drm/radeon/radeon_atombios.c
+index e2de749327ad..2fa3cf615a67 100644
+--- a/drivers/gpu/drm/radeon/radeon_atombios.c
++++ b/drivers/gpu/drm/radeon/radeon_atombios.c
+@@ -3272,6 +3272,7 @@ int radeon_atom_get_voltage_evv(struct radeon_device 
*rdev,
+ 
+       args.in.ucVoltageType = VOLTAGE_TYPE_VDDC;
+       args.in.ucVoltageMode = ATOM_GET_VOLTAGE_EVV_VOLTAGE;
++      args.in.usVoltageLevel = cpu_to_le16(virtual_voltage_id);
+       args.in.ulSCLKFreq =
+               
cpu_to_le32(rdev->pm.dpm.dyn_state.vddc_dependency_on_sclk.entries[entry_id].clk);
+ 
+diff --git a/drivers/hid/hid-input.c b/drivers/hid/hid-input.c
+index 4b87bb164f30..a413f76e84d4 100644
+--- a/drivers/hid/hid-input.c
++++ b/drivers/hid/hid-input.c
+@@ -1066,6 +1066,23 @@ void hidinput_hid_event(struct hid_device *hid, struct 
hid_field *field, struct
+               return;
+       }
+ 
++      /*
++       * Ignore reports for absolute data if the data didn't change. This is
++       * not only an optimization but also fixes 'dead' key reports. Some
++       * RollOver implementations for localized keys (like BACKSLASH/PIPE; HID
++       * 0x31 and 0x32) report multiple keys, even though a localized keyboard
++       * can only have one of them physically available. The 'dead' keys
++       * report constant 0. As all map to the same keycode, they'd confuse
++       * the input layer. If we filter the 'dead' keys on the HID level, we
++       * skip the keycode translation and only forward real events.
++       */
++      if (!(field->flags & (HID_MAIN_ITEM_RELATIVE |
++                            HID_MAIN_ITEM_BUFFERED_BYTE)) &&
++                            (field->flags & HID_MAIN_ITEM_VARIABLE) &&
++          usage->usage_index < field->maxusage &&
++          value == field->value[usage->usage_index])
++              return;
++
+       /* report the usage code as scancode if the key status has changed */
+       if (usage->type == EV_KEY && !!test_bit(usage->code, input->key) != 
value)
+               input_event(input, EV_MSC, MSC_SCAN, usage->hid);
+diff --git a/drivers/iio/adc/mcp3422.c b/drivers/iio/adc/mcp3422.c
+index 47dcb34ff44c..3a615f3b5d80 100644
+--- a/drivers/iio/adc/mcp3422.c
++++ b/drivers/iio/adc/mcp3422.c
+@@ -57,20 +57,11 @@
+               .info_mask_shared_by_type = BIT(IIO_CHAN_INFO_SAMP_FREQ), \
+       }
+ 
+-/* LSB is in nV to eliminate floating point */
+-static const u32 rates_to_lsb[] = {1000000, 250000, 62500, 15625};
+-
+-/*
+- *  scales calculated as:
+- *  rates_to_lsb[sample_rate] / (1 << pga);
+- *  pga is 1 for 0, 2
+- */
+-
+ static const int mcp3422_scales[4][4] = {
+-      { 1000000, 250000, 62500, 15625 },
+-      { 500000 , 125000, 31250, 7812 },
+-      { 250000 , 62500 , 15625, 3906 },
+-      { 125000 , 31250 , 7812 , 1953 } };
++      { 1000000, 500000, 250000, 125000 },
++      { 250000 , 125000, 62500 , 31250  },
++      { 62500  , 31250 , 15625 , 7812   },
++      { 15625  , 7812  , 3906  , 1953   } };
+ 
+ /* Constant msleep times for data acquisitions */
+ static const int mcp3422_read_times[4] = {
+diff --git a/drivers/iio/dac/ad5686.c b/drivers/iio/dac/ad5686.c
+index 17aca4d9bd06..861ba3d60163 100644
+--- a/drivers/iio/dac/ad5686.c
++++ b/drivers/iio/dac/ad5686.c
+@@ -322,7 +322,7 @@ static int ad5686_probe(struct spi_device *spi)
+       st = iio_priv(indio_dev);
+       spi_set_drvdata(spi, indio_dev);
+ 
+-      st->reg = devm_regulator_get(&spi->dev, "vcc");
++      st->reg = devm_regulator_get_optional(&spi->dev, "vcc");
+       if (!IS_ERR(st->reg)) {
+               ret = regulator_enable(st->reg);
+               if (ret)
+diff --git a/drivers/iio/imu/adis16400_core.c 
b/drivers/iio/imu/adis16400_core.c
+index 7c582f7ae34e..70753bf23a86 100644
+--- a/drivers/iio/imu/adis16400_core.c
++++ b/drivers/iio/imu/adis16400_core.c
+@@ -26,6 +26,7 @@
+ #include <linux/list.h>
+ #include <linux/module.h>
+ #include <linux/debugfs.h>
++#include <linux/bitops.h>
+ 
+ #include <linux/iio/iio.h>
+ #include <linux/iio/sysfs.h>
+@@ -447,7 +448,7 @@ static int adis16400_read_raw(struct iio_dev *indio_dev,
+               mutex_unlock(&indio_dev->mlock);
+               if (ret)
+                       return ret;
+-              val16 = ((val16 & 0xFFF) << 4) >> 4;
++              val16 = sign_extend32(val16, 11);
+               *val = val16;
+               return IIO_VAL_INT;
+       case IIO_CHAN_INFO_OFFSET:
+diff --git a/drivers/infiniband/core/ucma.c b/drivers/infiniband/core/ucma.c
+index 56a4b7ca7ee3..45d67e9228d7 100644
+--- a/drivers/infiniband/core/ucma.c
++++ b/drivers/infiniband/core/ucma.c
+@@ -1124,6 +1124,9 @@ static int ucma_set_ib_path(struct ucma_context *ctx,
+       if (!optlen)
+               return -EINVAL;
+ 
++      memset(&sa_path, 0, sizeof(sa_path));
++      sa_path.vlan_id = 0xffff;
++
+       ib_sa_unpack_path(path_data->path_rec, &sa_path);
+       ret = rdma_set_ib_paths(ctx->cm_id, &sa_path, 1);
+       if (ret)
+diff --git a/drivers/infiniband/core/uverbs_cmd.c 
b/drivers/infiniband/core/uverbs_cmd.c
+index 23467a2abd62..2adc14372b94 100644
+--- a/drivers/infiniband/core/uverbs_cmd.c
++++ b/drivers/infiniband/core/uverbs_cmd.c
+@@ -1964,20 +1964,21 @@ ssize_t ib_uverbs_modify_qp(struct ib_uverbs_file 
*file,
+       if (qp->real_qp == qp) {
+               ret = ib_resolve_eth_l2_attrs(qp, attr, &cmd.attr_mask);
+               if (ret)
+-                      goto out;
++                      goto release_qp;
+               ret = qp->device->modify_qp(qp, attr,
+                       modify_qp_mask(qp->qp_type, cmd.attr_mask), &udata);
+       } else {
+               ret = ib_modify_qp(qp, attr, modify_qp_mask(qp->qp_type, 
cmd.attr_mask));
+       }
+ 
+-      put_qp_read(qp);
+-
+       if (ret)
+-              goto out;
++              goto release_qp;
+ 
+       ret = in_len;
+ 
++release_qp:
++      put_qp_read(qp);
++
+ out:
+       kfree(attr);
+ 
+diff --git a/drivers/infiniband/hw/mlx4/main.c 
b/drivers/infiniband/hw/mlx4/main.c
+index 11f0606792bb..1a3d924744cc 100644
+--- a/drivers/infiniband/hw/mlx4/main.c
++++ b/drivers/infiniband/hw/mlx4/main.c
+@@ -1161,8 +1161,7 @@ static int mlx4_ib_mcg_attach(struct ib_qp *ibqp, union 
ib_gid *gid, u16 lid)
+       struct mlx4_ib_qp *mqp = to_mqp(ibqp);
+       u64 reg_id;
+       struct mlx4_ib_steering *ib_steering = NULL;
+-      enum mlx4_protocol prot = (gid->raw[1] == 0x0e) ?
+-              MLX4_PROT_IB_IPV4 : MLX4_PROT_IB_IPV6;
++      enum mlx4_protocol prot = MLX4_PROT_IB_IPV6;
+ 
+       if (mdev->dev->caps.steering_mode ==
+           MLX4_STEERING_MODE_DEVICE_MANAGED) {
+@@ -1175,8 +1174,10 @@ static int mlx4_ib_mcg_attach(struct ib_qp *ibqp, union 
ib_gid *gid, u16 lid)
+                                   !!(mqp->flags &
+                                      MLX4_IB_QP_BLOCK_MULTICAST_LOOPBACK),
+                                   prot, &reg_id);
+-      if (err)
++      if (err) {
++              pr_err("multicast attach op failed, err %d\n", err);
+               goto err_malloc;
++      }
+ 
+       err = add_gid_entry(ibqp, gid);
+       if (err)
+@@ -1224,8 +1225,7 @@ static int mlx4_ib_mcg_detach(struct ib_qp *ibqp, union 
ib_gid *gid, u16 lid)
+       struct net_device *ndev;
+       struct mlx4_ib_gid_entry *ge;
+       u64 reg_id = 0;
+-      enum mlx4_protocol prot = (gid->raw[1] == 0x0e) ?
+-              MLX4_PROT_IB_IPV4 : MLX4_PROT_IB_IPV6;
++      enum mlx4_protocol prot =  MLX4_PROT_IB_IPV6;
+ 
+       if (mdev->dev->caps.steering_mode ==
+           MLX4_STEERING_MODE_DEVICE_MANAGED) {
+diff --git a/drivers/infiniband/hw/qib/qib.h b/drivers/infiniband/hw/qib/qib.h
+index 1946101419a3..675d3c796b9f 100644
+--- a/drivers/infiniband/hw/qib/qib.h
++++ b/drivers/infiniband/hw/qib/qib.h
+@@ -1080,12 +1080,6 @@ struct qib_devdata {
+       /* control high-level access to EEPROM */
+       struct mutex eep_lock;
+       uint64_t traffic_wds;
+-      /* active time is kept in seconds, but logged in hours */
+-      atomic_t active_time;
+-      /* Below are nominal shadow of EEPROM, new since last EEPROM update */
+-      uint8_t eep_st_errs[QIB_EEP_LOG_CNT];
+-      uint8_t eep_st_new_errs[QIB_EEP_LOG_CNT];
+-      uint16_t eep_hrs;
+       /*
+        * masks for which bits of errs, hwerrs that cause
+        * each of the counters to increment.
+@@ -1307,8 +1301,7 @@ int qib_twsi_blk_rd(struct qib_devdata *dd, int dev, int 
addr, void *buffer,
+ int qib_twsi_blk_wr(struct qib_devdata *dd, int dev, int addr,
+                   const void *buffer, int len);
+ void qib_get_eeprom_info(struct qib_devdata *);
+-int qib_update_eeprom_log(struct qib_devdata *dd);
+-void qib_inc_eeprom_err(struct qib_devdata *dd, u32 eidx, u32 incr);
++#define qib_inc_eeprom_err(dd, eidx, incr)
+ void qib_dump_lookup_output_queue(struct qib_devdata *);
+ void qib_force_pio_avail_update(struct qib_devdata *);
+ void qib_clear_symerror_on_linkup(unsigned long opaque);
+diff --git a/drivers/infiniband/hw/qib/qib_eeprom.c 
b/drivers/infiniband/hw/qib/qib_eeprom.c
+index 4d5d71aaa2b4..e2280b07df02 100644
+--- a/drivers/infiniband/hw/qib/qib_eeprom.c
++++ b/drivers/infiniband/hw/qib/qib_eeprom.c
+@@ -267,190 +267,9 @@ void qib_get_eeprom_info(struct qib_devdata *dd)
+                       "Board SN %s did not pass functional test: %s\n",
+                       dd->serial, ifp->if_comment);
+ 
+-      memcpy(&dd->eep_st_errs, &ifp->if_errcntp, QIB_EEP_LOG_CNT);
+-      /*
+-       * Power-on (actually "active") hours are kept as little-endian value
+-       * in EEPROM, but as seconds in a (possibly as small as 24-bit)
+-       * atomic_t while running.
+-       */
+-      atomic_set(&dd->active_time, 0);
+-      dd->eep_hrs = ifp->if_powerhour[0] | (ifp->if_powerhour[1] << 8);
+-
+ done:
+       vfree(buf);
+ 
+ bail:;
+ }
+ 
+-/**
+- * qib_update_eeprom_log - copy active-time and error counters to eeprom
+- * @dd: the qlogic_ib device
+- *
+- * Although the time is kept as seconds in the qib_devdata struct, it is
+- * rounded to hours for re-write, as we have only 16 bits in EEPROM.
+- * First-cut code reads whole (expected) struct qib_flash, modifies,
+- * re-writes. Future direction: read/write only what we need, assuming
+- * that the EEPROM had to have been "good enough" for driver init, and
+- * if not, we aren't making it worse.
+- *
+- */
+-int qib_update_eeprom_log(struct qib_devdata *dd)
+-{
+-      void *buf;
+-      struct qib_flash *ifp;
+-      int len, hi_water;
+-      uint32_t new_time, new_hrs;
+-      u8 csum;
+-      int ret, idx;
+-      unsigned long flags;
+-
+-      /* first, check if we actually need to do anything. */
+-      ret = 0;
+-      for (idx = 0; idx < QIB_EEP_LOG_CNT; ++idx) {
+-              if (dd->eep_st_new_errs[idx]) {
+-                      ret = 1;
+-                      break;
+-              }
+-      }
+-      new_time = atomic_read(&dd->active_time);
+-
+-      if (ret == 0 && new_time < 3600)
+-              goto bail;
+-
+-      /*
+-       * The quick-check above determined that there is something worthy
+-       * of logging, so get current contents and do a more detailed idea.
+-       * read full flash, not just currently used part, since it may have
+-       * been written with a newer definition
+-       */
+-      len = sizeof(struct qib_flash);
+-      buf = vmalloc(len);
+-      ret = 1;
+-      if (!buf) {
+-              qib_dev_err(dd,
+-                      "Couldn't allocate memory to read %u bytes from eeprom 
for logging\n",
+-                      len);
+-              goto bail;
+-      }
+-
+-      /* Grab semaphore and read current EEPROM. If we get an
+-       * error, let go, but if not, keep it until we finish write.
+-       */
+-      ret = mutex_lock_interruptible(&dd->eep_lock);
+-      if (ret) {
+-              qib_dev_err(dd, "Unable to acquire EEPROM for logging\n");
+-              goto free_bail;
+-      }
+-      ret = qib_twsi_blk_rd(dd, dd->twsi_eeprom_dev, 0, buf, len);
+-      if (ret) {
+-              mutex_unlock(&dd->eep_lock);
+-              qib_dev_err(dd, "Unable read EEPROM for logging\n");
+-              goto free_bail;
+-      }
+-      ifp = (struct qib_flash *)buf;
+-
+-      csum = flash_csum(ifp, 0);
+-      if (csum != ifp->if_csum) {
+-              mutex_unlock(&dd->eep_lock);
+-              qib_dev_err(dd, "EEPROM cks err (0x%02X, S/B 0x%02X)\n",
+-                          csum, ifp->if_csum);
+-              ret = 1;
+-              goto free_bail;
+-      }
+-      hi_water = 0;
+-      spin_lock_irqsave(&dd->eep_st_lock, flags);
+-      for (idx = 0; idx < QIB_EEP_LOG_CNT; ++idx) {
+-              int new_val = dd->eep_st_new_errs[idx];
+-              if (new_val) {
+-                      /*
+-                       * If we have seen any errors, add to EEPROM values
+-                       * We need to saturate at 0xFF (255) and we also
+-                       * would need to adjust the checksum if we were
+-                       * trying to minimize EEPROM traffic
+-                       * Note that we add to actual current count in EEPROM,
+-                       * in case it was altered while we were running.
+-                       */
+-                      new_val += ifp->if_errcntp[idx];
+-                      if (new_val > 0xFF)
+-                              new_val = 0xFF;
+-                      if (ifp->if_errcntp[idx] != new_val) {
+-                              ifp->if_errcntp[idx] = new_val;
+-                              hi_water = offsetof(struct qib_flash,
+-                                                  if_errcntp) + idx;
+-                      }
+-                      /*
+-                       * update our shadow (used to minimize EEPROM
+-                       * traffic), to match what we are about to write.
+-                       */
+-                      dd->eep_st_errs[idx] = new_val;
+-                      dd->eep_st_new_errs[idx] = 0;
+-              }
+-      }
+-      /*
+-       * Now update active-time. We would like to round to the nearest hour
+-       * but unless atomic_t are sure to be proper signed ints we cannot,
+-       * because we need to account for what we "transfer" to EEPROM and
+-       * if we log an hour at 31 minutes, then we would need to set
+-       * active_time to -29 to accurately count the _next_ hour.
+-       */
+-      if (new_time >= 3600) {
+-              new_hrs = new_time / 3600;
+-              atomic_sub((new_hrs * 3600), &dd->active_time);
+-              new_hrs += dd->eep_hrs;
+-              if (new_hrs > 0xFFFF)
+-                      new_hrs = 0xFFFF;
+-              dd->eep_hrs = new_hrs;
+-              if ((new_hrs & 0xFF) != ifp->if_powerhour[0]) {
+-                      ifp->if_powerhour[0] = new_hrs & 0xFF;
+-                      hi_water = offsetof(struct qib_flash, if_powerhour);
+-              }
+-              if ((new_hrs >> 8) != ifp->if_powerhour[1]) {
+-                      ifp->if_powerhour[1] = new_hrs >> 8;
+-                      hi_water = offsetof(struct qib_flash, if_powerhour) + 1;
+-              }
+-      }
+-      /*
+-       * There is a tiny possibility that we could somehow fail to write
+-       * the EEPROM after updating our shadows, but problems from holding
+-       * the spinlock too long are a much bigger issue.
+-       */
+-      spin_unlock_irqrestore(&dd->eep_st_lock, flags);
+-      if (hi_water) {
+-              /* we made some change to the data, uopdate cksum and write */
+-              csum = flash_csum(ifp, 1);
+-              ret = eeprom_write_with_enable(dd, 0, buf, hi_water + 1);
+-      }
+-      mutex_unlock(&dd->eep_lock);
+-      if (ret)
+-              qib_dev_err(dd, "Failed updating EEPROM\n");
+-
+-free_bail:
+-      vfree(buf);
+-bail:
+-      return ret;
+-}
+-
+-/**
+- * qib_inc_eeprom_err - increment one of the four error counters
+- * that are logged to EEPROM.
+- * @dd: the qlogic_ib device
+- * @eidx: 0..3, the counter to increment
+- * @incr: how much to add
+- *
+- * Each counter is 8-bits, and saturates at 255 (0xFF). They
+- * are copied to the EEPROM (aka flash) whenever qib_update_eeprom_log()
+- * is called, but it can only be called in a context that allows sleep.
+- * This function can be called even at interrupt level.
+- */
+-void qib_inc_eeprom_err(struct qib_devdata *dd, u32 eidx, u32 incr)
+-{
+-      uint new_val;
+-      unsigned long flags;
+-
+-      spin_lock_irqsave(&dd->eep_st_lock, flags);
+-      new_val = dd->eep_st_new_errs[eidx] + incr;
+-      if (new_val > 255)
+-              new_val = 255;
+-      dd->eep_st_new_errs[eidx] = new_val;
+-      spin_unlock_irqrestore(&dd->eep_st_lock, flags);
+-}
+diff --git a/drivers/infiniband/hw/qib/qib_iba6120.c 
b/drivers/infiniband/hw/qib/qib_iba6120.c
+index 84e593d6007b..295f6312e6a9 100644
+--- a/drivers/infiniband/hw/qib/qib_iba6120.c
++++ b/drivers/infiniband/hw/qib/qib_iba6120.c
+@@ -2682,8 +2682,6 @@ static void qib_get_6120_faststats(unsigned long opaque)
+       spin_lock_irqsave(&dd->eep_st_lock, flags);
+       traffic_wds -= dd->traffic_wds;
+       dd->traffic_wds += traffic_wds;
+-      if (traffic_wds  >= QIB_TRAFFIC_ACTIVE_THRESHOLD)
+-              atomic_add(5, &dd->active_time); /* S/B #define */
+       spin_unlock_irqrestore(&dd->eep_st_lock, flags);
+ 
+       qib_chk_6120_errormask(dd);
+diff --git a/drivers/infiniband/hw/qib/qib_iba7220.c 
b/drivers/infiniband/hw/qib/qib_iba7220.c
+index 454c2e7668fe..c86e71b9e160 100644
+--- a/drivers/infiniband/hw/qib/qib_iba7220.c
++++ b/drivers/infiniband/hw/qib/qib_iba7220.c
+@@ -3299,8 +3299,6 @@ static void qib_get_7220_faststats(unsigned long opaque)
+       spin_lock_irqsave(&dd->eep_st_lock, flags);
+       traffic_wds -= dd->traffic_wds;
+       dd->traffic_wds += traffic_wds;
+-      if (traffic_wds  >= QIB_TRAFFIC_ACTIVE_THRESHOLD)
+-              atomic_add(5, &dd->active_time); /* S/B #define */
+       spin_unlock_irqrestore(&dd->eep_st_lock, flags);
+ done:
+       mod_timer(&dd->stats_timer, jiffies + HZ * ACTIVITY_TIMER);
+diff --git a/drivers/infiniband/hw/qib/qib_iba7322.c 
b/drivers/infiniband/hw/qib/qib_iba7322.c
+index d1bd21319d7d..0f8d1f0bd929 100644
+--- a/drivers/infiniband/hw/qib/qib_iba7322.c
++++ b/drivers/infiniband/hw/qib/qib_iba7322.c
+@@ -5191,8 +5191,6 @@ static void qib_get_7322_faststats(unsigned long opaque)
+               spin_lock_irqsave(&ppd->dd->eep_st_lock, flags);
+               traffic_wds -= ppd->dd->traffic_wds;
+               ppd->dd->traffic_wds += traffic_wds;
+-              if (traffic_wds >= QIB_TRAFFIC_ACTIVE_THRESHOLD)
+-                      atomic_add(ACTIVITY_TIMER, &ppd->dd->active_time);
+               spin_unlock_irqrestore(&ppd->dd->eep_st_lock, flags);
+               if (ppd->cpspec->qdr_dfe_on && (ppd->link_speed_active &
+                                               QIB_IB_QDR) &&
+diff --git a/drivers/infiniband/hw/qib/qib_init.c 
b/drivers/infiniband/hw/qib/qib_init.c
+index 76c3e177164d..8c9bb6c35838 100644
+--- a/drivers/infiniband/hw/qib/qib_init.c
++++ b/drivers/infiniband/hw/qib/qib_init.c
+@@ -922,7 +922,6 @@ static void qib_shutdown_device(struct qib_devdata *dd)
+               }
+       }
+ 
+-      qib_update_eeprom_log(dd);
+ }
+ 
+ /**
+diff --git a/drivers/infiniband/hw/qib/qib_sysfs.c 
b/drivers/infiniband/hw/qib/qib_sysfs.c
+index 3c8e4e3caca6..b9ccbda7817d 100644
+--- a/drivers/infiniband/hw/qib/qib_sysfs.c
++++ b/drivers/infiniband/hw/qib/qib_sysfs.c
+@@ -611,28 +611,6 @@ bail:
+       return ret < 0 ? ret : count;
+ }
+ 
+-static ssize_t show_logged_errs(struct device *device,
+-                              struct device_attribute *attr, char *buf)
+-{
+-      struct qib_ibdev *dev =
+-              container_of(device, struct qib_ibdev, ibdev.dev);
+-      struct qib_devdata *dd = dd_from_dev(dev);
+-      int idx, count;
+-
+-      /* force consistency with actual EEPROM */
+-      if (qib_update_eeprom_log(dd) != 0)
+-              return -ENXIO;
+-
+-      count = 0;
+-      for (idx = 0; idx < QIB_EEP_LOG_CNT; ++idx) {
+-              count += scnprintf(buf + count, PAGE_SIZE - count, "%d%c",
+-                                 dd->eep_st_errs[idx],
+-                                 idx == (QIB_EEP_LOG_CNT - 1) ? '\n' : ' ');
+-      }
+-
+-      return count;
+-}
+-
+ /*
+  * Dump tempsense regs. in decimal, to ease shell-scripts.
+  */
+@@ -679,7 +657,6 @@ static DEVICE_ATTR(nctxts, S_IRUGO, show_nctxts, NULL);
+ static DEVICE_ATTR(nfreectxts, S_IRUGO, show_nfreectxts, NULL);
+ static DEVICE_ATTR(serial, S_IRUGO, show_serial, NULL);
+ static DEVICE_ATTR(boardversion, S_IRUGO, show_boardversion, NULL);
+-static DEVICE_ATTR(logged_errors, S_IRUGO, show_logged_errs, NULL);
+ static DEVICE_ATTR(tempsense, S_IRUGO, show_tempsense, NULL);
+ static DEVICE_ATTR(localbus_info, S_IRUGO, show_localbus_info, NULL);
+ static DEVICE_ATTR(chip_reset, S_IWUSR, NULL, store_chip_reset);
+@@ -693,7 +670,6 @@ static struct device_attribute *qib_attributes[] = {
+       &dev_attr_nfreectxts,
+       &dev_attr_serial,
+       &dev_attr_boardversion,
+-      &dev_attr_logged_errors,
+       &dev_attr_tempsense,
+       &dev_attr_localbus_info,
+       &dev_attr_chip_reset,
+diff --git a/drivers/input/tablet/wacom_wac.c 
b/drivers/input/tablet/wacom_wac.c
+index 05f371df6c40..d4b0a31ab66b 100644
+--- a/drivers/input/tablet/wacom_wac.c
++++ b/drivers/input/tablet/wacom_wac.c
+@@ -700,6 +700,12 @@ static int wacom_intuos_irq(struct wacom_wac *wacom)
+                       input_report_key(input, BTN_7, (data[4] & 0x40));  /* 
Left   */
+                       input_report_key(input, BTN_8, (data[4] & 0x80));  /* 
Down   */
+                       input_report_key(input, BTN_0, (data[3] & 0x01));  /* 
Center */
++
++                      if (data[4] | (data[3] & 0x01)) {
++                              input_report_abs(input, ABS_MISC, 
PAD_DEVICE_ID);
++                      } else {
++                              input_report_abs(input, ABS_MISC, 0);
++                      }
+               } else if (features->type >= INTUOS5S && features->type <= 
INTUOSPL) {
+                       int i;
+ 
+diff --git a/drivers/md/dm-io.c b/drivers/md/dm-io.c
+index db404a0f7e2c..d2a8d64f8526 100644
+--- a/drivers/md/dm-io.c
++++ b/drivers/md/dm-io.c
+@@ -292,6 +292,12 @@ static void do_region(int rw, unsigned region, struct 
dm_io_region *where,
+       unsigned short logical_block_size = queue_logical_block_size(q);
+       sector_t num_sectors;
+ 
++      /* Reject unsupported discard requests */
++      if ((rw & REQ_DISCARD) && !blk_queue_discard(q)) {
++              dec_count(io, region, -EOPNOTSUPP);
++              return;
++      }
++
+       /*
+        * where->count may be zero if rw holds a flush and we need to
+        * send a zero-sized flush.
+diff --git a/drivers/md/dm-raid1.c b/drivers/md/dm-raid1.c
+index 7dfdb5c746d6..089d62751f7f 100644
+--- a/drivers/md/dm-raid1.c
++++ b/drivers/md/dm-raid1.c
+@@ -604,6 +604,15 @@ static void write_callback(unsigned long error, void 
*context)
+               return;
+       }
+ 
++      /*
++       * If the bio is discard, return an error, but do not
++       * degrade the array.
++       */
++      if (bio->bi_rw & REQ_DISCARD) {
++              bio_endio(bio, -EOPNOTSUPP);
++              return;
++      }
++
+       for (i = 0; i < ms->nr_mirrors; i++)
+               if (test_bit(i, &error))
+                       fail_mirror(ms->mirror + i, DM_RAID1_WRITE_ERROR);
+diff --git a/drivers/md/dm-snap.c b/drivers/md/dm-snap.c
+index ebddef5237e4..c356a10b9ba5 100644
+--- a/drivers/md/dm-snap.c
++++ b/drivers/md/dm-snap.c
+@@ -1440,8 +1440,6 @@ out:
+               full_bio->bi_private = pe->full_bio_private;
+               atomic_inc(&full_bio->bi_remaining);
+       }
+-      free_pending_exception(pe);
+-
+       increment_pending_exceptions_done_count();
+ 
+       up_write(&s->lock);
+@@ -1458,6 +1456,8 @@ out:
+       }
+ 
+       retry_origin_bios(s, origin_bios);
++
++      free_pending_exception(pe);
+ }
+ 
+ static void commit_callback(void *context, int success)
+diff --git a/drivers/md/dm.c b/drivers/md/dm.c
+index 65ee3a0d4683..1582c3dac3ac 100644
+--- a/drivers/md/dm.c
++++ b/drivers/md/dm.c
+@@ -2288,7 +2288,7 @@ int dm_setup_md_queue(struct mapped_device *md)
+       return 0;
+ }
+ 
+-static struct mapped_device *dm_find_md(dev_t dev)
++struct mapped_device *dm_get_md(dev_t dev)
+ {
+       struct mapped_device *md;
+       unsigned minor = MINOR(dev);
+@@ -2299,12 +2299,15 @@ static struct mapped_device *dm_find_md(dev_t dev)
+       spin_lock(&_minor_lock);
+ 
+       md = idr_find(&_minor_idr, minor);
+-      if (md && (md == MINOR_ALLOCED ||
+-                 (MINOR(disk_devt(dm_disk(md))) != minor) ||
+-                 dm_deleting_md(md) ||
+-                 test_bit(DMF_FREEING, &md->flags))) {
+-              md = NULL;
+-              goto out;
++      if (md) {
++              if ((md == MINOR_ALLOCED ||
++                   (MINOR(disk_devt(dm_disk(md))) != minor) ||
++                   dm_deleting_md(md) ||
++                   test_bit(DMF_FREEING, &md->flags))) {
++                      md = NULL;
++                      goto out;
++              }
++              dm_get(md);
+       }
+ 
+ out:
+@@ -2312,16 +2315,6 @@ out:
+ 
+       return md;
+ }
+-
+-struct mapped_device *dm_get_md(dev_t dev)
+-{
+-      struct mapped_device *md = dm_find_md(dev);
+-
+-      if (md)
+-              dm_get(md);
+-
+-      return md;
+-}
+ EXPORT_SYMBOL_GPL(dm_get_md);
+ 
+ void *dm_get_mdptr(struct mapped_device *md)
+diff --git a/drivers/misc/mei/init.c b/drivers/misc/mei/init.c
+index cdd31c2a2a2b..b2965382d0ec 100644
+--- a/drivers/misc/mei/init.c
++++ b/drivers/misc/mei/init.c
+@@ -275,6 +275,8 @@ void mei_stop(struct mei_device *dev)
+ 
+       dev->dev_state = MEI_DEV_POWER_DOWN;
+       mei_reset(dev);
++      /* move device to disabled state unconditionally */
++      dev->dev_state = MEI_DEV_DISABLED;
+ 
+       mutex_unlock(&dev->device_lock);
+ 
+diff --git a/drivers/net/macvtap.c b/drivers/net/macvtap.c
+index 07c942b6ae01..e8c21f911b6f 100644
+--- a/drivers/net/macvtap.c
++++ b/drivers/net/macvtap.c
+@@ -637,12 +637,15 @@ static void macvtap_skb_to_vnet_hdr(const struct sk_buff 
*skb,
+       } /* else everything is zero */
+ }
+ 
++/* Neighbour code has some assumptions on HH_DATA_MOD alignment */
++#define MACVTAP_RESERVE HH_DATA_OFF(ETH_HLEN)
++
+ /* Get packet from user space buffer */
+ static ssize_t macvtap_get_user(struct macvtap_queue *q, struct msghdr *m,
+                               const struct iovec *iv, unsigned long total_len,
+                               size_t count, int noblock)
+ {
+-      int good_linear = SKB_MAX_HEAD(NET_IP_ALIGN);
++      int good_linear = SKB_MAX_HEAD(MACVTAP_RESERVE);
+       struct sk_buff *skb;
+       struct macvlan_dev *vlan;
+       unsigned long len = total_len;
+@@ -701,7 +704,7 @@ static ssize_t macvtap_get_user(struct macvtap_queue *q, 
struct msghdr *m,
+                       linear = vnet_hdr.hdr_len;
+       }
+ 
+-      skb = macvtap_alloc_skb(&q->sk, NET_IP_ALIGN, copylen,
++      skb = macvtap_alloc_skb(&q->sk, MACVTAP_RESERVE, copylen,
+                               linear, noblock, &err);
+       if (!skb)
+               goto err;
+diff --git a/drivers/net/phy/phy.c b/drivers/net/phy/phy.c
+index 76d96b9ebcdb..1d568788c3e3 100644
+--- a/drivers/net/phy/phy.c
++++ b/drivers/net/phy/phy.c
+@@ -194,6 +194,25 @@ static inline unsigned int phy_find_valid(unsigned int 
idx, u32 features)
+ }
+ 
+ /**
++ * phy_check_valid - check if there is a valid PHY setting which matches
++ *                 speed, duplex, and feature mask
++ * @speed: speed to match
++ * @duplex: duplex to match
++ * @features: A mask of the valid settings
++ *
++ * Description: Returns true if there is a valid setting, false otherwise.
++ */
++static inline bool phy_check_valid(int speed, int duplex, u32 features)
++{
++      unsigned int idx;
++
++      idx = phy_find_valid(phy_find_setting(speed, duplex), features);
++
++      return settings[idx].speed == speed && settings[idx].duplex == duplex &&
++              (settings[idx].setting & features);
++}
++
++/**
+  * phy_sanitize_settings - make sure the PHY is set to supported speed and 
duplex
+  * @phydev: the target phy_device struct
+  *
+@@ -955,7 +974,6 @@ int phy_init_eee(struct phy_device *phydev, bool 
clk_stop_enable)
+               int eee_lp, eee_cap, eee_adv;
+               u32 lp, cap, adv;
+               int status;
+-              unsigned int idx;
+ 
+               /* Read phy status to properly get the right settings */
+               status = phy_read_status(phydev);
+@@ -987,8 +1005,7 @@ int phy_init_eee(struct phy_device *phydev, bool 
clk_stop_enable)
+ 
+               adv = mmd_eee_adv_to_ethtool_adv_t(eee_adv);
+               lp = mmd_eee_adv_to_ethtool_adv_t(eee_lp);
+-              idx = phy_find_setting(phydev->speed, phydev->duplex);
+-              if (!(lp & adv & settings[idx].setting))
++              if (!phy_check_valid(phydev->speed, phydev->duplex, lp & adv))
+                       return -EPROTONOSUPPORT;
+ 
+               if (clk_stop_enable) {
+diff --git a/drivers/net/team/team.c b/drivers/net/team/team.c
+index 32efe8371ff8..c28e2dafb3f0 100644
+--- a/drivers/net/team/team.c
++++ b/drivers/net/team/team.c
+@@ -42,9 +42,7 @@
+ 
+ static struct team_port *team_port_get_rcu(const struct net_device *dev)
+ {
+-      struct team_port *port = rcu_dereference(dev->rx_handler_data);
+-
+-      return team_port_exists(dev) ? port : NULL;
++      return rcu_dereference(dev->rx_handler_data);
+ }
+ 
+ static struct team_port *team_port_get_rtnl(const struct net_device *dev)
+@@ -1725,11 +1723,11 @@ static int team_set_mac_address(struct net_device 
*dev, void *p)
+       if (dev->type == ARPHRD_ETHER && !is_valid_ether_addr(addr->sa_data))
+               return -EADDRNOTAVAIL;
+       memcpy(dev->dev_addr, addr->sa_data, dev->addr_len);
+-      rcu_read_lock();
+-      list_for_each_entry_rcu(port, &team->port_list, list)
++      mutex_lock(&team->lock);
++      list_for_each_entry(port, &team->port_list, list)
+               if (team->ops.port_change_dev_addr)
+                       team->ops.port_change_dev_addr(team, port);
+-      rcu_read_unlock();
++      mutex_unlock(&team->lock);
+       return 0;
+ }
+ 
+diff --git a/drivers/net/usb/plusb.c b/drivers/net/usb/plusb.c
+index 3d18bb0eee85..1bfe0fcaccf5 100644
+--- a/drivers/net/usb/plusb.c
++++ b/drivers/net/usb/plusb.c
+@@ -134,6 +134,11 @@ static const struct usb_device_id products [] = {
+ }, {
+       USB_DEVICE(0x050d, 0x258a),     /* Belkin F5U258/F5U279 (PL-25A1) */
+       .driver_info =  (unsigned long) &prolific_info,
++}, {
++      USB_DEVICE(0x3923, 0x7825),     /* National Instruments USB
++                                       * Host-to-Host Cable
++                                       */
++      .driver_info =  (unsigned long) &prolific_info,
+ },
+ 
+       { },            // END
+diff --git a/drivers/net/wireless/ath/ath5k/reset.c 
b/drivers/net/wireless/ath/ath5k/reset.c
+index a3399c4f13a9..b9b651ea9851 100644
+--- a/drivers/net/wireless/ath/ath5k/reset.c
++++ b/drivers/net/wireless/ath/ath5k/reset.c
+@@ -478,7 +478,7 @@ ath5k_hw_wisoc_reset(struct ath5k_hw *ah, u32 flags)
+       regval = ioread32(reg);
+       iowrite32(regval | val, reg);
+       regval = ioread32(reg);
+-      usleep_range(100, 150);
++      udelay(100);    /* NB: should be atomic */
+ 
+       /* Bring BB/MAC out of reset */
+       iowrite32(regval & ~val, reg);
+diff --git a/drivers/net/wireless/ath/ath6kl/hif.h 
b/drivers/net/wireless/ath/ath6kl/hif.h
+index 61f6b21fb0ae..dc6bd8cd9b83 100644
+--- a/drivers/net/wireless/ath/ath6kl/hif.h
++++ b/drivers/net/wireless/ath/ath6kl/hif.h
+@@ -197,9 +197,9 @@ struct hif_scatter_req {
+       /* bounce buffer for upper layers to copy to/from */
+       u8 *virt_dma_buf;
+ 
+-      struct hif_scatter_item scat_list[1];
+-
+       u32 scat_q_depth;
++
++      struct hif_scatter_item scat_list[0];
+ };
+ 
+ struct ath6kl_irq_proc_registers {
+diff --git a/drivers/net/wireless/ath/ath6kl/sdio.c 
b/drivers/net/wireless/ath/ath6kl/sdio.c
+index 7126bdd4236c..6bf15a331714 100644
+--- a/drivers/net/wireless/ath/ath6kl/sdio.c
++++ b/drivers/net/wireless/ath/ath6kl/sdio.c
+@@ -348,7 +348,7 @@ static int ath6kl_sdio_alloc_prep_scat_req(struct 
ath6kl_sdio *ar_sdio,
+       int i, scat_req_sz, scat_list_sz, size;
+       u8 *virt_buf;
+ 
+-      scat_list_sz = (n_scat_entry - 1) * sizeof(struct hif_scatter_item);
++      scat_list_sz = n_scat_entry * sizeof(struct hif_scatter_item);
+       scat_req_sz = sizeof(*s_req) + scat_list_sz;
+ 
+       if (!virt_scat)
+diff --git a/drivers/scsi/be2iscsi/be_main.c b/drivers/scsi/be2iscsi/be_main.c
+index 5642a9b250c2..953bd0bfdf0d 100644
+--- a/drivers/scsi/be2iscsi/be_main.c
++++ b/drivers/scsi/be2iscsi/be_main.c
+@@ -581,7 +581,6 @@ static struct beiscsi_hba *beiscsi_hba_alloc(struct 
pci_dev *pcidev)
+                       "beiscsi_hba_alloc - iscsi_host_alloc failed\n");
+               return NULL;
+       }
+-      shost->dma_boundary = pcidev->dma_mask;
+       shost->max_id = BE2_MAX_SESSIONS;
+       shost->max_channel = 0;
+       shost->max_cmd_len = BEISCSI_MAX_CMD_LEN;
+diff --git a/drivers/scsi/sg.c b/drivers/scsi/sg.c
+index df5e961484e1..eb81c98386b9 100644
+--- a/drivers/scsi/sg.c
++++ b/drivers/scsi/sg.c
+@@ -522,7 +522,7 @@ static ssize_t
+ sg_new_read(Sg_fd * sfp, char __user *buf, size_t count, Sg_request * srp)
+ {
+       sg_io_hdr_t *hp = &srp->header;
+-      int err = 0;
++      int err = 0, err2;
+       int len;
+ 
+       if (count < SZ_SG_IO_HDR) {
+@@ -551,8 +551,8 @@ sg_new_read(Sg_fd * sfp, char __user *buf, size_t count, 
Sg_request * srp)
+               goto err_out;
+       }
+ err_out:
+-      err = sg_finish_rem_req(srp);
+-      return (0 == err) ? count : err;
++      err2 = sg_finish_rem_req(srp);
++      return err ? : err2 ? : count;
+ }
+ 
+ static ssize_t
+diff --git a/drivers/staging/comedi/comedi_compat32.c 
b/drivers/staging/comedi/comedi_compat32.c
+index 1e9da405d833..528781049ad5 100644
+--- a/drivers/staging/comedi/comedi_compat32.c
++++ b/drivers/staging/comedi/comedi_compat32.c
+@@ -262,7 +262,7 @@ static int compat_cmd(struct file *file, unsigned long arg)
+ {
+       struct comedi_cmd __user *cmd;
+       struct comedi32_cmd_struct __user *cmd32;
+-      int rc;
++      int rc, err;
+ 
+       cmd32 = compat_ptr(arg);
+       cmd = compat_alloc_user_space(sizeof(*cmd));
+@@ -271,7 +271,15 @@ static int compat_cmd(struct file *file, unsigned long 
arg)
+       if (rc)
+               return rc;
+ 
+-      return translated_ioctl(file, COMEDI_CMD, (unsigned long)cmd);
++      rc = translated_ioctl(file, COMEDI_CMD, (unsigned long)cmd);
++      if (rc == -EAGAIN) {
++              /* Special case: copy cmd back to user. */
++              err = put_compat_cmd(cmd32, cmd);
++              if (err)
++                      rc = err;
++      }
++
++      return rc;
+ }
+ 
+ /* Handle 32-bit COMEDI_CMDTEST ioctl. */
+diff --git a/drivers/staging/comedi/drivers/cb_pcidas64.c 
b/drivers/staging/comedi/drivers/cb_pcidas64.c
+index 4fff1738e3f8..3d1cb5b0a956 100644
+--- a/drivers/staging/comedi/drivers/cb_pcidas64.c
++++ b/drivers/staging/comedi/drivers/cb_pcidas64.c
+@@ -441,6 +441,29 @@ static const struct comedi_lrange ai_ranges_64xx = {
+       }
+ };
+ 
++static const uint8_t ai_range_code_64xx[8] = {
++      0x0, 0x1, 0x2, 0x3,     /* bipolar 10, 5, 2,5, 1.25 */
++      0x8, 0x9, 0xa, 0xb      /* unipolar 10, 5, 2.5, 1.25 */
++};
++
++/* analog input ranges for 64-Mx boards */
++static const struct comedi_lrange ai_ranges_64_mx = {
++      7, {
++              BIP_RANGE(5),
++              BIP_RANGE(2.5),
++              BIP_RANGE(1.25),
++              BIP_RANGE(0.625),
++              UNI_RANGE(5),
++              UNI_RANGE(2.5),
++              UNI_RANGE(1.25)
++      }
++};
++
++static const uint8_t ai_range_code_64_mx[7] = {
++      0x0, 0x1, 0x2, 0x3,     /* bipolar 5, 2.5, 1.25, 0.625 */
++      0x9, 0xa, 0xb           /* unipolar 5, 2.5, 1.25 */
++};
++
+ /* analog input ranges for 60xx boards */
+ static const struct comedi_lrange ai_ranges_60xx = {
+       4, {
+@@ -451,6 +474,10 @@ static const struct comedi_lrange ai_ranges_60xx = {
+       }
+ };
+ 
++static const uint8_t ai_range_code_60xx[4] = {
++      0x0, 0x1, 0x4, 0x7      /* bipolar 10, 5, 0.5, 0.05 */
++};
++
+ /* analog input ranges for 6030, etc boards */
+ static const struct comedi_lrange ai_ranges_6030 = {
+       14, {
+@@ -471,6 +498,11 @@ static const struct comedi_lrange ai_ranges_6030 = {
+       }
+ };
+ 
++static const uint8_t ai_range_code_6030[14] = {
++      0x0, 0x1, 0x2, 0x3, 0x4, 0x5, 0x6, /* bip 10, 5, 2, 1, 0.5, 0.2, 0.1 */
++      0x9, 0xa, 0xb, 0xc, 0xd, 0xe, 0xf  /* uni 10, 5, 2, 1, 0.5, 0.2, 0.1 */
++};
++
+ /* analog input ranges for 6052, etc boards */
+ static const struct comedi_lrange ai_ranges_6052 = {
+       15, {
+@@ -492,6 +524,11 @@ static const struct comedi_lrange ai_ranges_6052 = {
+       }
+ };
+ 
++static const uint8_t ai_range_code_6052[15] = {
++      0x0, 0x1, 0x2, 0x3, 0x4, 0x5, 0x6, 0x7, /* bipolar 10 ... 0.05 */
++      0x9, 0xa, 0xb, 0xc, 0xd, 0xe, 0xf       /* unipolar 10 ... 0.1 */
++};
++
+ /* analog input ranges for 4020 board */
+ static const struct comedi_lrange ai_ranges_4020 = {
+       2, {
+@@ -595,6 +632,7 @@ struct pcidas64_board {
+       int ai_bits;            /*  analog input resolution */
+       int ai_speed;           /*  fastest conversion period in ns */
+       const struct comedi_lrange *ai_range_table;
++      const uint8_t *ai_range_code;
+       int ao_nchan;           /*  number of analog out channels */
+       int ao_bits;            /*  analog output resolution */
+       int ao_scan_speed;      /*  analog output scan speed */
+@@ -653,6 +691,7 @@ static const struct pcidas64_board pcidas64_boards[] = {
+               .ao_scan_speed  = 10000,
+               .layout         = LAYOUT_64XX,
+               .ai_range_table = &ai_ranges_64xx,
++              .ai_range_code  = ai_range_code_64xx,
+               .ao_range_table = &ao_ranges_64xx,
+               .ao_range_code  = ao_range_code_64xx,
+               .ai_fifo        = &ai_fifo_64xx,
+@@ -668,6 +707,7 @@ static const struct pcidas64_board pcidas64_boards[] = {
+               .ao_scan_speed  = 10000,
+               .layout         = LAYOUT_64XX,
+               .ai_range_table = &ai_ranges_64xx,
++              .ai_range_code  = ai_range_code_64xx,
+               .ao_range_table = &ao_ranges_64xx,
+               .ao_range_code  = ao_range_code_64xx,
+               .ai_fifo        = &ai_fifo_64xx,
+@@ -682,7 +722,8 @@ static const struct pcidas64_board pcidas64_boards[] = {
+               .ao_bits        = 16,
+               .ao_scan_speed  = 10000,
+               .layout         = LAYOUT_64XX,
+-              .ai_range_table = &ai_ranges_64xx,
++              .ai_range_table = &ai_ranges_64_mx,
++              .ai_range_code  = ai_range_code_64_mx,
+               .ao_range_table = &ao_ranges_64xx,
+               .ao_range_code  = ao_range_code_64xx,
+               .ai_fifo        = &ai_fifo_64xx,
+@@ -697,7 +738,8 @@ static const struct pcidas64_board pcidas64_boards[] = {
+               .ao_bits        = 16,
+               .ao_scan_speed  = 10000,
+               .layout         = LAYOUT_64XX,
+-              .ai_range_table = &ai_ranges_64xx,
++              .ai_range_table = &ai_ranges_64_mx,
++              .ai_range_code  = ai_range_code_64_mx,
+               .ao_range_table = &ao_ranges_64xx,
+               .ao_range_code  = ao_range_code_64xx,
+               .ai_fifo        = &ai_fifo_64xx,
+@@ -712,7 +754,8 @@ static const struct pcidas64_board pcidas64_boards[] = {
+               .ao_bits        = 16,
+               .ao_scan_speed  = 10000,
+               .layout         = LAYOUT_64XX,
+-              .ai_range_table = &ai_ranges_64xx,
++              .ai_range_table = &ai_ranges_64_mx,
++              .ai_range_code  = ai_range_code_64_mx,
+               .ao_range_table = &ao_ranges_64xx,
+               .ao_range_code  = ao_range_code_64xx,
+               .ai_fifo        = &ai_fifo_64xx,
+@@ -727,6 +770,7 @@ static const struct pcidas64_board pcidas64_boards[] = {
+               .ao_bits        = 16,
+               .layout         = LAYOUT_60XX,
+               .ai_range_table = &ai_ranges_60xx,
++              .ai_range_code  = ai_range_code_60xx,
+               .ao_range_table = &range_bipolar10,
+               .ao_range_code  = ao_range_code_60xx,
+               .ai_fifo        = &ai_fifo_60xx,
+@@ -742,6 +786,7 @@ static const struct pcidas64_board pcidas64_boards[] = {
+               .ao_scan_speed  = 100000,
+               .layout         = LAYOUT_60XX,
+               .ai_range_table = &ai_ranges_60xx,
++              .ai_range_code  = ai_range_code_60xx,
+               .ao_range_table = &range_bipolar10,
+               .ao_range_code  = ao_range_code_60xx,
+               .ai_fifo        = &ai_fifo_60xx,
+@@ -756,6 +801,7 @@ static const struct pcidas64_board pcidas64_boards[] = {
+               .ao_scan_speed  = 100000,
+               .layout         = LAYOUT_60XX,
+               .ai_range_table = &ai_ranges_60xx,
++              .ai_range_code  = ai_range_code_60xx,
+               .ao_range_table = &range_bipolar10,
+               .ao_range_code  = ao_range_code_60xx,
+               .ai_fifo        = &ai_fifo_60xx,
+@@ -771,6 +817,7 @@ static const struct pcidas64_board pcidas64_boards[] = {
+               .ao_scan_speed  = 100000,
+               .layout         = LAYOUT_60XX,
+               .ai_range_table = &ai_ranges_60xx,
++              .ai_range_code  = ai_range_code_60xx,
+               .ao_range_table = &range_bipolar10,
+               .ao_range_code  = ao_range_code_60xx,
+               .ai_fifo        = &ai_fifo_60xx,
+@@ -786,6 +833,7 @@ static const struct pcidas64_board pcidas64_boards[] = {
+               .ao_scan_speed  = 10000,
+               .layout         = LAYOUT_60XX,
+               .ai_range_table = &ai_ranges_6030,
++              .ai_range_code  = ai_range_code_6030,
+               .ao_range_table = &ao_ranges_6030,
+               .ao_range_code  = ao_range_code_6030,
+               .ai_fifo        = &ai_fifo_60xx,
+@@ -801,6 +849,7 @@ static const struct pcidas64_board pcidas64_boards[] = {
+               .ao_scan_speed  = 10000,
+               .layout         = LAYOUT_60XX,
+               .ai_range_table = &ai_ranges_6030,
++              .ai_range_code  = ai_range_code_6030,
+               .ao_range_table = &ao_ranges_6030,
+               .ao_range_code  = ao_range_code_6030,
+               .ai_fifo        = &ai_fifo_60xx,
+@@ -814,6 +863,7 @@ static const struct pcidas64_board pcidas64_boards[] = {
+               .ao_nchan       = 0,
+               .layout         = LAYOUT_60XX,
+               .ai_range_table = &ai_ranges_6030,
++              .ai_range_code  = ai_range_code_6030,
+               .ai_fifo        = &ai_fifo_60xx,
+               .has_8255       = 0,
+       },
+@@ -825,6 +875,7 @@ static const struct pcidas64_board pcidas64_boards[] = {
+               .ao_nchan       = 0,
+               .layout         = LAYOUT_60XX,
+               .ai_range_table = &ai_ranges_6030,
++              .ai_range_code  = ai_range_code_6030,
+               .ai_fifo        = &ai_fifo_60xx,
+               .has_8255       = 0,
+       },
+@@ -837,6 +888,7 @@ static const struct pcidas64_board pcidas64_boards[] = {
+               .ao_scan_speed  = 0,
+               .layout         = LAYOUT_60XX,
+               .ai_range_table = &ai_ranges_60xx,
++              .ai_range_code  = ai_range_code_60xx,
+               .ai_fifo        = &ai_fifo_60xx,
+               .has_8255       = 0,
+       },
+@@ -850,6 +902,7 @@ static const struct pcidas64_board pcidas64_boards[] = {
+               .ao_scan_speed  = 100000,
+               .layout         = LAYOUT_60XX,
+               .ai_range_table = &ai_ranges_60xx,
++              .ai_range_code  = ai_range_code_60xx,
+               .ao_range_table = &range_bipolar10,
+               .ao_range_code  = ao_range_code_60xx,
+               .ai_fifo        = &ai_fifo_60xx,
+@@ -865,6 +918,7 @@ static const struct pcidas64_board pcidas64_boards[] = {
+               .ao_scan_speed  = 100000,
+               .layout         = LAYOUT_60XX,
+               .ai_range_table = &ai_ranges_60xx,
++              .ai_range_code  = ai_range_code_60xx,
+               .ao_range_table = &range_bipolar10,
+               .ao_range_code  = ao_range_code_60xx,
+               .ai_fifo        = &ai_fifo_60xx,
+@@ -880,6 +934,7 @@ static const struct pcidas64_board pcidas64_boards[] = {
+               .ao_scan_speed  = 1000,
+               .layout         = LAYOUT_60XX,
+               .ai_range_table = &ai_ranges_6052,
++              .ai_range_code  = ai_range_code_6052,
+               .ao_range_table = &ao_ranges_6030,
+               .ao_range_code  = ao_range_code_6030,
+               .ai_fifo        = &ai_fifo_60xx,
+@@ -895,6 +950,7 @@ static const struct pcidas64_board pcidas64_boards[] = {
+               .ao_scan_speed  = 3333,
+               .layout         = LAYOUT_60XX,
+               .ai_range_table = &ai_ranges_6052,
++              .ai_range_code  = ai_range_code_6052,
+               .ao_range_table = &ao_ranges_6030,
+               .ao_range_code  = ao_range_code_6030,
+               .ai_fifo        = &ai_fifo_60xx,
+@@ -910,6 +966,7 @@ static const struct pcidas64_board pcidas64_boards[] = {
+               .ao_scan_speed  = 1000,
+               .layout         = LAYOUT_60XX,
+               .ai_range_table = &ai_ranges_6052,
++              .ai_range_code  = ai_range_code_6052,
+               .ao_range_table = &ao_ranges_6030,
+               .ao_range_code  = ao_range_code_6030,
+               .ai_fifo        = &ai_fifo_60xx,
+@@ -925,6 +982,7 @@ static const struct pcidas64_board pcidas64_boards[] = {
+               .ao_scan_speed  = 1000,
+               .layout         = LAYOUT_60XX,
+               .ai_range_table = &ai_ranges_6052,
++              .ai_range_code  = ai_range_code_6052,
+               .ao_range_table = &ao_ranges_6030,
+               .ao_range_code  = ao_range_code_6030,
+               .ai_fifo        = &ai_fifo_60xx,
+@@ -959,6 +1017,7 @@ static const struct pcidas64_board pcidas64_boards[] = {
+               .ao_scan_speed  = 10000,
+               .layout         = LAYOUT_64XX,
+               .ai_range_table = &ai_ranges_64xx,
++              .ai_range_code  = ai_range_code_64xx,
+               .ai_fifo        = ai_fifo_64xx,
+               .has_8255       = 1,
+       },
+@@ -970,7 +1029,8 @@ static const struct pcidas64_board pcidas64_boards[] = {
+               .ao_nchan       = 0,
+               .ao_scan_speed  = 10000,
+               .layout         = LAYOUT_64XX,
+-              .ai_range_table = &ai_ranges_64xx,
++              .ai_range_table = &ai_ranges_64_mx,
++              .ai_range_code  = ai_range_code_64_mx,
+               .ai_fifo        = ai_fifo_64xx,
+               .has_8255       = 1,
+       },
+@@ -982,7 +1042,8 @@ static const struct pcidas64_board pcidas64_boards[] = {
+               .ao_nchan       = 0,
+               .ao_scan_speed  = 10000,
+               .layout         = LAYOUT_64XX,
+-              .ai_range_table = &ai_ranges_64xx,
++              .ai_range_table = &ai_ranges_64_mx,
++              .ai_range_code  = ai_range_code_64_mx,
+               .ai_fifo        = ai_fifo_64xx,
+               .has_8255       = 1,
+       },
+@@ -994,7 +1055,8 @@ static const struct pcidas64_board pcidas64_boards[] = {
+               .ao_nchan       = 0,
+               .ao_scan_speed  = 10000,
+               .layout         = LAYOUT_64XX,
+-              .ai_range_table = &ai_ranges_64xx,
++              .ai_range_table = &ai_ranges_64_mx,
++              .ai_range_code  = ai_range_code_64_mx,
+               .ai_fifo        = ai_fifo_64xx,
+               .has_8255       = 1,
+       },
+@@ -1006,7 +1068,8 @@ static const struct pcidas64_board pcidas64_boards[] = {
+               .ao_nchan       = 2,
+               .ao_scan_speed  = 10000,
+               .layout         = LAYOUT_64XX,
+-              .ai_range_table = &ai_ranges_64xx,
++              .ai_range_table = &ai_ranges_64_mx,
++              .ai_range_code  = ai_range_code_64_mx,
+               .ai_fifo        = ai_fifo_64xx,
+               .has_8255       = 1,
+       },
+@@ -1018,7 +1081,8 @@ static const struct pcidas64_board pcidas64_boards[] = {
+               .ao_nchan       = 2,
+               .ao_scan_speed  = 10000,
+               .layout         = LAYOUT_64XX,
+-              .ai_range_table = &ai_ranges_64xx,
++              .ai_range_table = &ai_ranges_64_mx,
++              .ai_range_code  = ai_range_code_64_mx,
+               .ai_fifo        = ai_fifo_64xx,
+               .has_8255       = 1,
+       },
+@@ -1030,7 +1094,8 @@ static const struct pcidas64_board pcidas64_boards[] = {
+               .ao_nchan       = 2,
+               .ao_scan_speed  = 10000,
+               .layout         = LAYOUT_64XX,
+-              .ai_range_table = &ai_ranges_64xx,
++              .ai_range_table = &ai_ranges_64_mx,
++              .ai_range_code  = ai_range_code_64_mx,
+               .ai_fifo        = ai_fifo_64xx,
+               .has_8255       = 1,
+       },
+@@ -1127,45 +1192,8 @@ static unsigned int ai_range_bits_6xxx(const struct 
comedi_device *dev,
+                                      unsigned int range_index)
+ {
+       const struct pcidas64_board *thisboard = comedi_board(dev);
+-      const struct comedi_krange *range =
+-              &thisboard->ai_range_table->range[range_index];
+-      unsigned int bits = 0;
+ 
+-      switch (range->max) {
+-      case 10000000:
+-              bits = 0x000;
+-              break;
+-      case 5000000:
+-              bits = 0x100;
+-              break;
+-      case 2000000:
+-      case 2500000:
+-              bits = 0x200;
+-              break;
+-      case 1000000:
+-      case 1250000:
+-              bits = 0x300;
+-              break;
+-      case 500000:
+-              bits = 0x400;
+-              break;
+-      case 200000:
+-      case 250000:
+-              bits = 0x500;
+-              break;
+-      case 100000:
+-              bits = 0x600;
+-              break;
+-      case 50000:
+-              bits = 0x700;
+-              break;
+-      default:
+-              comedi_error(dev, "bug! in ai_range_bits_6xxx");
+-              break;
+-      }
+-      if (range->min == 0)
+-              bits += 0x900;
+-      return bits;
++      return thisboard->ai_range_code[range_index] << 8;
+ }
+ 
+ static unsigned int hw_revision(const struct comedi_device *dev,
+diff --git a/drivers/staging/iio/adc/mxs-lradc.c 
b/drivers/staging/iio/adc/mxs-lradc.c
+index 9ec1df9cff95..be89260c23a6 100644
+--- a/drivers/staging/iio/adc/mxs-lradc.c
++++ b/drivers/staging/iio/adc/mxs-lradc.c
+@@ -214,11 +214,17 @@ struct mxs_lradc {
+       unsigned long           is_divided;
+ 
+       /*
+-       * Touchscreen LRADC channels receives a private slot in the CTRL4
+-       * register, the slot #7. Therefore only 7 slots instead of 8 in the
+-       * CTRL4 register can be mapped to LRADC channels when using the
+-       * touchscreen.
+-       *
++       * When the touchscreen is enabled, we give it two private virtual
++       * channels: #6 and #7. This means that only 6 virtual channels (instead
++       * of 8) will be available for buffered capture.
++       */
++#define TOUCHSCREEN_VCHANNEL1         7
++#define TOUCHSCREEN_VCHANNEL2         6
++#define BUFFER_VCHANS_LIMITED         0x3f
++#define BUFFER_VCHANS_ALL             0xff
++      u8                      buffer_vchans;
++
++      /*
+        * Furthermore, certain LRADC channels are shared between touchscreen
+        * and/or touch-buttons and generic LRADC block. Therefore when using
+        * either of these, these channels are not available for the regular
+@@ -342,6 +348,9 @@ struct mxs_lradc {
+ #define       LRADC_CTRL4                             0x140
+ #define       LRADC_CTRL4_LRADCSELECT_MASK(n)         (0xf << ((n) * 4))
+ #define       LRADC_CTRL4_LRADCSELECT_OFFSET(n)       ((n) * 4)
++#define       LRADC_CTRL4_LRADCSELECT(n, x) \
++                              (((x) << LRADC_CTRL4_LRADCSELECT_OFFSET(n)) & \
++                              LRADC_CTRL4_LRADCSELECT_MASK(n))
+ 
+ #define LRADC_RESOLUTION                      12
+ #define LRADC_SINGLE_SAMPLE_MASK              ((1 << LRADC_RESOLUTION) - 1)
+@@ -423,6 +432,14 @@ static bool mxs_lradc_check_touch_event(struct mxs_lradc 
*lradc)
+                                       LRADC_STATUS_TOUCH_DETECT_RAW);
+ }
+ 
++static void mxs_lradc_map_channel(struct mxs_lradc *lradc, unsigned vch,
++                                unsigned ch)
++{
++      mxs_lradc_reg_clear(lradc, LRADC_CTRL4_LRADCSELECT_MASK(vch),
++                              LRADC_CTRL4);
++      mxs_lradc_reg_set(lradc, LRADC_CTRL4_LRADCSELECT(vch, ch), LRADC_CTRL4);
++}
++
+ static void mxs_lradc_setup_ts_channel(struct mxs_lradc *lradc, unsigned ch)
+ {
+       /*
+@@ -450,12 +467,8 @@ static void mxs_lradc_setup_ts_channel(struct mxs_lradc 
*lradc, unsigned ch)
+               LRADC_DELAY_DELAY(lradc->over_sample_delay - 1),
+                       LRADC_DELAY(3));
+ 
+-      mxs_lradc_reg_clear(lradc, LRADC_CTRL1_LRADC_IRQ(2) |
+-                      LRADC_CTRL1_LRADC_IRQ(3) | LRADC_CTRL1_LRADC_IRQ(4) |
+-                      LRADC_CTRL1_LRADC_IRQ(5), LRADC_CTRL1);
++      mxs_lradc_reg_clear(lradc, LRADC_CTRL1_LRADC_IRQ(ch), LRADC_CTRL1);
+ 
+-      /* wake us again, when the complete conversion is done */
+-      mxs_lradc_reg_set(lradc, LRADC_CTRL1_LRADC_IRQ_EN(ch), LRADC_CTRL1);
+       /*
+        * after changing the touchscreen plates setting
+        * the signals need some initial time to settle. Start the
+@@ -508,12 +521,8 @@ static void mxs_lradc_setup_ts_pressure(struct mxs_lradc 
*lradc, unsigned ch1,
+               LRADC_DELAY_DELAY(lradc->over_sample_delay - 1),
+                                       LRADC_DELAY(3));
+ 
+-      mxs_lradc_reg_clear(lradc, LRADC_CTRL1_LRADC_IRQ(2) |
+-                      LRADC_CTRL1_LRADC_IRQ(3) | LRADC_CTRL1_LRADC_IRQ(4) |
+-                      LRADC_CTRL1_LRADC_IRQ(5), LRADC_CTRL1);
++      mxs_lradc_reg_clear(lradc, LRADC_CTRL1_LRADC_IRQ(ch2), LRADC_CTRL1);
+ 
+-      /* wake us again, when the conversions are done */
+-      mxs_lradc_reg_set(lradc, LRADC_CTRL1_LRADC_IRQ_EN(ch2), LRADC_CTRL1);
+       /*
+        * after changing the touchscreen plates setting
+        * the signals need some initial time to settle. Start the
+@@ -578,36 +587,6 @@ static unsigned mxs_lradc_read_ts_pressure(struct 
mxs_lradc *lradc,
+ #define TS_CH_XM 4
+ #define TS_CH_YM 5
+ 
+-static int mxs_lradc_read_ts_channel(struct mxs_lradc *lradc)
+-{
+-      u32 reg;
+-      int val;
+-
+-      reg = readl(lradc->base + LRADC_CTRL1);
+-
+-      /* only channels 3 to 5 are of interest here */
+-      if (reg & LRADC_CTRL1_LRADC_IRQ(TS_CH_YP)) {
+-              mxs_lradc_reg_clear(lradc, LRADC_CTRL1_LRADC_IRQ_EN(TS_CH_YP) |
+-                      LRADC_CTRL1_LRADC_IRQ(TS_CH_YP), LRADC_CTRL1);
+-              val = mxs_lradc_read_raw_channel(lradc, TS_CH_YP);
+-      } else if (reg & LRADC_CTRL1_LRADC_IRQ(TS_CH_XM)) {
+-              mxs_lradc_reg_clear(lradc, LRADC_CTRL1_LRADC_IRQ_EN(TS_CH_XM) |
+-                      LRADC_CTRL1_LRADC_IRQ(TS_CH_XM), LRADC_CTRL1);
+-              val = mxs_lradc_read_raw_channel(lradc, TS_CH_XM);
+-      } else if (reg & LRADC_CTRL1_LRADC_IRQ(TS_CH_YM)) {
+-              mxs_lradc_reg_clear(lradc, LRADC_CTRL1_LRADC_IRQ_EN(TS_CH_YM) |
+-                      LRADC_CTRL1_LRADC_IRQ(TS_CH_YM), LRADC_CTRL1);
+-              val = mxs_lradc_read_raw_channel(lradc, TS_CH_YM);
+-      } else {
+-              return -EIO;
+-      }
+-
+-      mxs_lradc_reg_wrt(lradc, 0, LRADC_DELAY(2));
+-      mxs_lradc_reg_wrt(lradc, 0, LRADC_DELAY(3));
+-
+-      return val;
+-}
+-
+ /*
+  * YP(open)--+-------------+
+  *           |             |--+
+@@ -651,7 +630,8 @@ static void mxs_lradc_prepare_x_pos(struct mxs_lradc 
*lradc)
+       mxs_lradc_reg_set(lradc, mxs_lradc_drive_x_plate(lradc), LRADC_CTRL0);
+ 
+       lradc->cur_plate = LRADC_SAMPLE_X;
+-      mxs_lradc_setup_ts_channel(lradc, TS_CH_YP);
++      mxs_lradc_map_channel(lradc, TOUCHSCREEN_VCHANNEL1, TS_CH_YP);
++      mxs_lradc_setup_ts_channel(lradc, TOUCHSCREEN_VCHANNEL1);
+ }
+ 
+ /*
+@@ -672,7 +652,8 @@ static void mxs_lradc_prepare_y_pos(struct mxs_lradc 
*lradc)
+       mxs_lradc_reg_set(lradc, mxs_lradc_drive_y_plate(lradc), LRADC_CTRL0);
+ 
+       lradc->cur_plate = LRADC_SAMPLE_Y;
+-      mxs_lradc_setup_ts_channel(lradc, TS_CH_XM);
++      mxs_lradc_map_channel(lradc, TOUCHSCREEN_VCHANNEL1, TS_CH_XM);
++      mxs_lradc_setup_ts_channel(lradc, TOUCHSCREEN_VCHANNEL1);
+ }
+ 
+ /*
+@@ -693,7 +674,10 @@ static void mxs_lradc_prepare_pressure(struct mxs_lradc 
*lradc)
+       mxs_lradc_reg_set(lradc, mxs_lradc_drive_pressure(lradc), LRADC_CTRL0);
+ 
+       lradc->cur_plate = LRADC_SAMPLE_PRESSURE;
+-      mxs_lradc_setup_ts_pressure(lradc, TS_CH_XP, TS_CH_YM);
++      mxs_lradc_map_channel(lradc, TOUCHSCREEN_VCHANNEL1, TS_CH_YM);
++      mxs_lradc_map_channel(lradc, TOUCHSCREEN_VCHANNEL2, TS_CH_XP);
++      mxs_lradc_setup_ts_pressure(lradc, TOUCHSCREEN_VCHANNEL2,
++                                              TOUCHSCREEN_VCHANNEL1);
+ }
+ 
+ static void mxs_lradc_enable_touch_detection(struct mxs_lradc *lradc)
+@@ -706,6 +690,19 @@ static void mxs_lradc_enable_touch_detection(struct 
mxs_lradc *lradc)
+       mxs_lradc_reg_set(lradc, LRADC_CTRL1_TOUCH_DETECT_IRQ_EN, LRADC_CTRL1);
+ }
+ 
++static void mxs_lradc_start_touch_event(struct mxs_lradc *lradc)
++{
++      mxs_lradc_reg_clear(lradc, LRADC_CTRL1_TOUCH_DETECT_IRQ_EN,
++                              LRADC_CTRL1);
++      mxs_lradc_reg_set(lradc,
++              LRADC_CTRL1_LRADC_IRQ_EN(TOUCHSCREEN_VCHANNEL1), LRADC_CTRL1);
++      /*
++       * start with the Y-pos, because it uses nearly the same plate
++       * settings like the touch detection
++       */
++      mxs_lradc_prepare_y_pos(lradc);
++}
++
+ static void mxs_lradc_report_ts_event(struct mxs_lradc *lradc)
+ {
+       input_report_abs(lradc->ts_input, ABS_X, lradc->ts_x_pos);
+@@ -723,10 +720,12 @@ static void mxs_lradc_complete_touch_event(struct 
mxs_lradc *lradc)
+        * start a dummy conversion to burn time to settle the signals
+        * note: we are not interested in the conversion's value
+        */
+-      mxs_lradc_reg_wrt(lradc, 0, LRADC_CH(5));
+-      mxs_lradc_reg_clear(lradc, LRADC_CTRL1_LRADC_IRQ(5), LRADC_CTRL1);
+-      mxs_lradc_reg_set(lradc, LRADC_CTRL1_LRADC_IRQ_EN(5), LRADC_CTRL1);
+-      mxs_lradc_reg_wrt(lradc, LRADC_DELAY_TRIGGER(1 << 5) |
++      mxs_lradc_reg_wrt(lradc, 0, LRADC_CH(TOUCHSCREEN_VCHANNEL1));
++      mxs_lradc_reg_clear(lradc,
++              LRADC_CTRL1_LRADC_IRQ(TOUCHSCREEN_VCHANNEL1) |
++              LRADC_CTRL1_LRADC_IRQ(TOUCHSCREEN_VCHANNEL2), LRADC_CTRL1);
++      mxs_lradc_reg_wrt(lradc,
++              LRADC_DELAY_TRIGGER(1 << TOUCHSCREEN_VCHANNEL1) |
+               LRADC_DELAY_KICK | LRADC_DELAY_DELAY(10), /* waste 5 ms */
+                       LRADC_DELAY(2));
+ }
+@@ -758,59 +757,45 @@ static void mxs_lradc_finish_touch_event(struct 
mxs_lradc *lradc, bool valid)
+ 
+       /* if it is released, wait for the next touch via IRQ */
+       lradc->cur_plate = LRADC_TOUCH;
+-      mxs_lradc_reg_clear(lradc, LRADC_CTRL1_TOUCH_DETECT_IRQ, LRADC_CTRL1);
++      mxs_lradc_reg_wrt(lradc, 0, LRADC_DELAY(2));
++      mxs_lradc_reg_wrt(lradc, 0, LRADC_DELAY(3));
++      mxs_lradc_reg_clear(lradc, LRADC_CTRL1_TOUCH_DETECT_IRQ |
++              LRADC_CTRL1_LRADC_IRQ_EN(TOUCHSCREEN_VCHANNEL1) |
++              LRADC_CTRL1_LRADC_IRQ(TOUCHSCREEN_VCHANNEL1), LRADC_CTRL1);
+       mxs_lradc_reg_set(lradc, LRADC_CTRL1_TOUCH_DETECT_IRQ_EN, LRADC_CTRL1);
+ }
+ 
+ /* touchscreen's state machine */
+ static void mxs_lradc_handle_touch(struct mxs_lradc *lradc)
+ {
+-      int val;
+-
+       switch (lradc->cur_plate) {
+       case LRADC_TOUCH:
+-              /*
+-               * start with the Y-pos, because it uses nearly the same plate
+-               * settings like the touch detection
+-               */
+-              if (mxs_lradc_check_touch_event(lradc)) {
+-                      mxs_lradc_reg_clear(lradc,
+-                                      LRADC_CTRL1_TOUCH_DETECT_IRQ_EN,
+-                                      LRADC_CTRL1);
+-                      mxs_lradc_prepare_y_pos(lradc);
+-              }
++              if (mxs_lradc_check_touch_event(lradc))
++                      mxs_lradc_start_touch_event(lradc);
+               mxs_lradc_reg_clear(lradc, LRADC_CTRL1_TOUCH_DETECT_IRQ,
+                                       LRADC_CTRL1);
+               return;
+ 
+       case LRADC_SAMPLE_Y:
+-              val = mxs_lradc_read_ts_channel(lradc);
+-              if (val < 0) {
+-                      mxs_lradc_enable_touch_detection(lradc); /* re-start */
+-                      return;
+-              }
+-              lradc->ts_y_pos = val;
++              lradc->ts_y_pos = mxs_lradc_read_raw_channel(lradc,
++                                                      TOUCHSCREEN_VCHANNEL1);
+               mxs_lradc_prepare_x_pos(lradc);
+               return;
+ 
+       case LRADC_SAMPLE_X:
+-              val = mxs_lradc_read_ts_channel(lradc);
+-              if (val < 0) {
+-                      mxs_lradc_enable_touch_detection(lradc); /* re-start */
+-                      return;
+-              }
+-              lradc->ts_x_pos = val;
++              lradc->ts_x_pos = mxs_lradc_read_raw_channel(lradc,
++                                                      TOUCHSCREEN_VCHANNEL1);
+               mxs_lradc_prepare_pressure(lradc);
+               return;
+ 
+       case LRADC_SAMPLE_PRESSURE:
+-              lradc->ts_pressure =
+-                      mxs_lradc_read_ts_pressure(lradc, TS_CH_XP, TS_CH_YM);
++              lradc->ts_pressure = mxs_lradc_read_ts_pressure(lradc,
++                                                      TOUCHSCREEN_VCHANNEL2,
++                                                      TOUCHSCREEN_VCHANNEL1);
+               mxs_lradc_complete_touch_event(lradc);
+               return;
+ 
+       case LRADC_SAMPLE_VALID:
+-              val = mxs_lradc_read_ts_channel(lradc); /* ignore the value */
+               mxs_lradc_finish_touch_event(lradc, 1);
+               break;
+       }
+@@ -842,9 +827,9 @@ static int mxs_lradc_read_single(struct iio_dev *iio_dev, 
int chan, int *val)
+        * used if doing raw sampling.
+        */
+       if (lradc->soc == IMX28_LRADC)
+-              mxs_lradc_reg_clear(lradc, LRADC_CTRL1_MX28_LRADC_IRQ_EN_MASK,
++              mxs_lradc_reg_clear(lradc, LRADC_CTRL1_LRADC_IRQ_EN(0),
+                       LRADC_CTRL1);
+-      mxs_lradc_reg_clear(lradc, 0xff, LRADC_CTRL0);
++      mxs_lradc_reg_clear(lradc, 0x1, LRADC_CTRL0);
+ 
+       /* Enable / disable the divider per requirement */
+       if (test_bit(chan, &lradc->is_divided))
+@@ -1091,9 +1076,8 @@ static void mxs_lradc_disable_ts(struct mxs_lradc *lradc)
+ {
+       /* stop all interrupts from firing */
+       mxs_lradc_reg_clear(lradc, LRADC_CTRL1_TOUCH_DETECT_IRQ_EN |
+-              LRADC_CTRL1_LRADC_IRQ_EN(2) | LRADC_CTRL1_LRADC_IRQ_EN(3) |
+-              LRADC_CTRL1_LRADC_IRQ_EN(4) | LRADC_CTRL1_LRADC_IRQ_EN(5),
+-              LRADC_CTRL1);
++              LRADC_CTRL1_LRADC_IRQ_EN(TOUCHSCREEN_VCHANNEL1) |
++              LRADC_CTRL1_LRADC_IRQ_EN(TOUCHSCREEN_VCHANNEL2), LRADC_CTRL1);
+ 
+       /* Power-down touchscreen touch-detect circuitry. */
+       mxs_lradc_reg_clear(lradc, mxs_lradc_plate_mask(lradc), LRADC_CTRL0);
+@@ -1159,25 +1143,31 @@ static irqreturn_t mxs_lradc_handle_irq(int irq, void 
*data)
+       struct iio_dev *iio = data;
+       struct mxs_lradc *lradc = iio_priv(iio);
+       unsigned long reg = readl(lradc->base + LRADC_CTRL1);
++      uint32_t clr_irq = mxs_lradc_irq_mask(lradc);
+       const uint32_t ts_irq_mask =
+               LRADC_CTRL1_TOUCH_DETECT_IRQ |
+-              LRADC_CTRL1_LRADC_IRQ(2) |
+-              LRADC_CTRL1_LRADC_IRQ(3) |
+-              LRADC_CTRL1_LRADC_IRQ(4) |
+-              LRADC_CTRL1_LRADC_IRQ(5);
++              LRADC_CTRL1_LRADC_IRQ(TOUCHSCREEN_VCHANNEL1) |
++              LRADC_CTRL1_LRADC_IRQ(TOUCHSCREEN_VCHANNEL2);
+ 
+       if (!(reg & mxs_lradc_irq_mask(lradc)))
+               return IRQ_NONE;
+ 
+-      if (lradc->use_touchscreen && (reg & ts_irq_mask))
++      if (lradc->use_touchscreen && (reg & ts_irq_mask)) {
+               mxs_lradc_handle_touch(lradc);
++              /* Make sure we don't clear the next conversion's interrupt. */
++              clr_irq &= ~(LRADC_CTRL1_LRADC_IRQ(TOUCHSCREEN_VCHANNEL1) |
++                              LRADC_CTRL1_LRADC_IRQ(TOUCHSCREEN_VCHANNEL2));
++      }
+ 
+       if (iio_buffer_enabled(iio))
+-              iio_trigger_poll(iio->trig, iio_get_time_ns());
+-      else if (reg & LRADC_CTRL1_LRADC_IRQ(0))
++      if (iio_buffer_enabled(iio)) {
++              if (reg & lradc->buffer_vchans)
++                      iio_trigger_poll(iio->trig, iio_get_time_ns());
++      } else if (reg & LRADC_CTRL1_LRADC_IRQ(0)) {
+               complete(&lradc->completion);
++      }
+ 
+-      mxs_lradc_reg_clear(lradc, reg & mxs_lradc_irq_mask(lradc), 
LRADC_CTRL1);
++      mxs_lradc_reg_clear(lradc, reg & clr_irq, LRADC_CTRL1);
+ 
+       return IRQ_HANDLED;
+ }
+@@ -1288,9 +1278,10 @@ static int mxs_lradc_buffer_preenable(struct iio_dev 
*iio)
+       }
+ 
+       if (lradc->soc == IMX28_LRADC)
+-              mxs_lradc_reg_clear(lradc, LRADC_CTRL1_MX28_LRADC_IRQ_EN_MASK,
+-                                                      LRADC_CTRL1);
+-      mxs_lradc_reg_clear(lradc, 0xff, LRADC_CTRL0);
++              mxs_lradc_reg_clear(lradc,
++                      lradc->buffer_vchans << LRADC_CTRL1_LRADC_IRQ_EN_OFFSET,
++                      LRADC_CTRL1);
++      mxs_lradc_reg_clear(lradc, lradc->buffer_vchans, LRADC_CTRL0);
+ 
+       for_each_set_bit(chan, iio->active_scan_mask, LRADC_MAX_TOTAL_CHANS) {
+               ctrl4_set |= chan << LRADC_CTRL4_LRADCSELECT_OFFSET(ofs);
+@@ -1323,10 +1314,11 @@ static int mxs_lradc_buffer_postdisable(struct iio_dev 
*iio)
+       mxs_lradc_reg_clear(lradc, LRADC_DELAY_TRIGGER_LRADCS_MASK |
+                                       LRADC_DELAY_KICK, LRADC_DELAY(0));
+ 
+-      mxs_lradc_reg_clear(lradc, 0xff, LRADC_CTRL0);
++      mxs_lradc_reg_clear(lradc, lradc->buffer_vchans, LRADC_CTRL0);
+       if (lradc->soc == IMX28_LRADC)
+-              mxs_lradc_reg_clear(lradc, LRADC_CTRL1_MX28_LRADC_IRQ_EN_MASK,
+-                                      LRADC_CTRL1);
++              mxs_lradc_reg_clear(lradc,
++                      lradc->buffer_vchans << LRADC_CTRL1_LRADC_IRQ_EN_OFFSET,
++                      LRADC_CTRL1);
+ 
+       kfree(lradc->buffer);
+       mutex_unlock(&lradc->lock);
+@@ -1352,7 +1344,7 @@ static bool mxs_lradc_validate_scan_mask(struct iio_dev 
*iio,
+       if (lradc->use_touchbutton)
+               rsvd_chans++;
+       if (lradc->use_touchscreen)
+-              rsvd_chans++;
++              rsvd_chans += 2;
+ 
+       /* Test for attempts to map channels with special mode of operation. */
+       if (bitmap_intersects(mask, &rsvd_mask, LRADC_MAX_TOTAL_CHANS))
+@@ -1412,6 +1404,13 @@ static const struct iio_chan_spec mxs_lradc_chan_spec[] 
= {
+               .channel = 8,
+               .scan_type = {.sign = 'u', .realbits = 18, .storagebits = 32,},
+       },
++      /* Hidden channel to keep indexes */
++      {
++              .type = IIO_TEMP,
++              .indexed = 1,
++              .scan_index = -1,
++              .channel = 9,
++      },
+       MXS_ADC_CHAN(10, IIO_VOLTAGE),  /* VDDIO */
+       MXS_ADC_CHAN(11, IIO_VOLTAGE),  /* VTH */
+       MXS_ADC_CHAN(12, IIO_VOLTAGE),  /* VDDA */
+@@ -1563,6 +1562,11 @@ static int mxs_lradc_probe(struct platform_device *pdev)
+ 
+       touch_ret = mxs_lradc_probe_touchscreen(lradc, node);
+ 
++      if (touch_ret == 0)
++              lradc->buffer_vchans = BUFFER_VCHANS_LIMITED;
++      else
++              lradc->buffer_vchans = BUFFER_VCHANS_ALL;
++
+       /* Grab all IRQ sources */
+       for (i = 0; i < of_cfg->irq_count; i++) {
+               lradc->irq[i] = platform_get_irq(pdev, i);
+diff --git a/drivers/target/target_core_pr.c b/drivers/target/target_core_pr.c
+index 1205dbd4f83d..0fccdcfd1015 100644
+--- a/drivers/target/target_core_pr.c
++++ b/drivers/target/target_core_pr.c
+@@ -1877,8 +1877,8 @@ static int core_scsi3_update_aptpl_buf(
+               }
+ 
+               if ((len + strlen(tmp) >= pr_aptpl_buf_len)) {
+-                      pr_err("Unable to update renaming"
+-                              " APTPL metadata\n");
++                      pr_err("Unable to update renaming APTPL metadata,"
++                             " reallocating larger buffer\n");
+                       ret = -EMSGSIZE;
+                       goto out;
+               }
+@@ -1895,8 +1895,8 @@ static int core_scsi3_update_aptpl_buf(
+                       lun->lun_sep->sep_rtpi, lun->unpacked_lun, reg_count);
+ 
+               if ((len + strlen(tmp) >= pr_aptpl_buf_len)) {
+-                      pr_err("Unable to update renaming"
+-                              " APTPL metadata\n");
++                      pr_err("Unable to update renaming APTPL metadata,"
++                             " reallocating larger buffer\n");
+                       ret = -EMSGSIZE;
+                       goto out;
+               }
+@@ -1959,7 +1959,7 @@ static int __core_scsi3_write_aptpl_to_file(
+ static sense_reason_t core_scsi3_update_and_write_aptpl(struct se_device 
*dev, bool aptpl)
+ {
+       unsigned char *buf;
+-      int rc;
++      int rc, len = PR_APTPL_BUF_LEN;
+ 
+       if (!aptpl) {
+               char *null_buf = "No Registrations or Reservations\n";
+@@ -1973,25 +1973,26 @@ static sense_reason_t 
core_scsi3_update_and_write_aptpl(struct se_device *dev, b
+ 
+               return 0;
+       }
+-
+-      buf = kzalloc(PR_APTPL_BUF_LEN, GFP_KERNEL);
++retry:
++      buf = vzalloc(len);
+       if (!buf)
+               return TCM_OUT_OF_RESOURCES;
+ 
+-      rc = core_scsi3_update_aptpl_buf(dev, buf, PR_APTPL_BUF_LEN);
++      rc = core_scsi3_update_aptpl_buf(dev, buf, len);
+       if (rc < 0) {
+-              kfree(buf);
+-              return TCM_OUT_OF_RESOURCES;
++              vfree(buf);
++              len *= 2;
++              goto retry;
+       }
+ 
+       rc = __core_scsi3_write_aptpl_to_file(dev, buf);
+       if (rc != 0) {
+               pr_err("SPC-3 PR: Could not update APTPL\n");
+-              kfree(buf);
++              vfree(buf);
+               return TCM_LOGICAL_UNIT_COMMUNICATION_FAILURE;
+       }
+       dev->t10_pr.pr_aptpl_active = 1;
+-      kfree(buf);
++      vfree(buf);
+       pr_debug("SPC-3 PR: Set APTPL Bit Activated\n");
+       return 0;
+ }
+diff --git a/drivers/target/target_core_sbc.c 
b/drivers/target/target_core_sbc.c
+index 5216acd68b4b..68511e83486b 100644
+--- a/drivers/target/target_core_sbc.c
++++ b/drivers/target/target_core_sbc.c
+@@ -266,6 +266,8 @@ static inline unsigned long long 
transport_lba_64_ext(unsigned char *cdb)
+ static sense_reason_t
+ sbc_setup_write_same(struct se_cmd *cmd, unsigned char *flags, struct sbc_ops 
*ops)
+ {
++      struct se_device *dev = cmd->se_dev;
++      sector_t end_lba = dev->transport->get_blocks(dev) + 1;
+       unsigned int sectors = sbc_get_write_same_sectors(cmd);
+ 
+       if ((flags[0] & 0x04) || (flags[0] & 0x02)) {
+@@ -279,6 +281,16 @@ sbc_setup_write_same(struct se_cmd *cmd, unsigned char 
*flags, struct sbc_ops *o
+                       sectors, cmd->se_dev->dev_attrib.max_write_same_len);
+               return TCM_INVALID_CDB_FIELD;
+       }
++      /*
++       * Sanity check for LBA wrap and request past end of device.
++       */
++      if (((cmd->t_task_lba + sectors) < cmd->t_task_lba) ||
++          ((cmd->t_task_lba + sectors) > end_lba)) {
++              pr_err("WRITE_SAME exceeds last lba %llu (lba %llu, sectors 
%u)\n",
++                     (unsigned long long)end_lba, cmd->t_task_lba, sectors);
++              return TCM_ADDRESS_OUT_OF_RANGE;
++      }
++
+       /* We always have ANC_SUP == 0 so setting ANCHOR is always an error */
+       if (flags[0] & 0x10) {
+               pr_warn("WRITE SAME with ANCHOR not supported\n");
+@@ -911,7 +923,8 @@ sbc_parse_cdb(struct se_cmd *cmd, struct sbc_ops *ops)
+               unsigned long long end_lba;
+ 
+               end_lba = dev->transport->get_blocks(dev) + 1;
+-              if (cmd->t_task_lba + sectors > end_lba) {
++              if (((cmd->t_task_lba + sectors) < cmd->t_task_lba) ||
++                  ((cmd->t_task_lba + sectors) > end_lba)) {
+                       pr_err("cmd exceeds last lba %llu "
+                               "(lba %llu, sectors %u)\n",
+                               end_lba, cmd->t_task_lba, sectors);
+diff --git a/drivers/tty/tty_io.c b/drivers/tty/tty_io.c
+index 25d07412e08e..39988fa91294 100644
+--- a/drivers/tty/tty_io.c
++++ b/drivers/tty/tty_io.c
+@@ -996,8 +996,8 @@ EXPORT_SYMBOL(start_tty);
+ /* We limit tty time update visibility to every 8 seconds or so. */
+ static void tty_update_time(struct timespec *time)
+ {
+-      unsigned long sec = get_seconds() & ~7;
+-      if ((long)(sec - time->tv_sec) > 0)
++      unsigned long sec = get_seconds();
++      if (abs(sec - time->tv_sec) & ~7)
+               time->tv_sec = sec;
+ }
+ 
+diff --git a/drivers/tty/tty_ioctl.c b/drivers/tty/tty_ioctl.c
+index 6fd60fece6b4..22da05d27009 100644
+--- a/drivers/tty/tty_ioctl.c
++++ b/drivers/tty/tty_ioctl.c
+@@ -217,11 +217,17 @@ void tty_wait_until_sent(struct tty_struct *tty, long 
timeout)
+ #endif
+       if (!timeout)
+               timeout = MAX_SCHEDULE_TIMEOUT;
++
+       if (wait_event_interruptible_timeout(tty->write_wait,
+-                      !tty_chars_in_buffer(tty), timeout) >= 0) {
+-              if (tty->ops->wait_until_sent)
+-                      tty->ops->wait_until_sent(tty, timeout);
++                      !tty_chars_in_buffer(tty), timeout) < 0) {
++              return;
+       }
++
++      if (timeout == MAX_SCHEDULE_TIMEOUT)
++              timeout = 0;
++
++      if (tty->ops->wait_until_sent)
++              tty->ops->wait_until_sent(tty, timeout);
+ }
+ EXPORT_SYMBOL(tty_wait_until_sent);
+ 
+diff --git a/drivers/usb/core/devio.c b/drivers/usb/core/devio.c
+index 9ca77166d37e..45b7b96f9ed3 100644
+--- a/drivers/usb/core/devio.c
++++ b/drivers/usb/core/devio.c
+@@ -501,6 +501,7 @@ static void async_completed(struct urb *urb)
+       as->status = urb->status;
+       signr = as->signr;
+       if (signr) {
++              memset(&sinfo, 0, sizeof(sinfo));
+               sinfo.si_signo = as->signr;
+               sinfo.si_errno = as->status;
+               sinfo.si_code = SI_ASYNCIO;
+@@ -2227,6 +2228,7 @@ static void usbdev_remove(struct usb_device *udev)
+               wake_up_all(&ps->wait);
+               list_del_init(&ps->list);
+               if (ps->discsignr) {
++                      memset(&sinfo, 0, sizeof(sinfo));
+                       sinfo.si_signo = ps->discsignr;
+                       sinfo.si_errno = EPIPE;
+                       sinfo.si_code = SI_ASYNCIO;
+diff --git a/drivers/usb/dwc3/dwc3-omap.c b/drivers/usb/dwc3/dwc3-omap.c
+index 2a6841c95b64..cfca302d3d88 100644
+--- a/drivers/usb/dwc3/dwc3-omap.c
++++ b/drivers/usb/dwc3/dwc3-omap.c
+@@ -211,6 +211,18 @@ static void dwc3_omap_write_irq0_set(struct dwc3_omap 
*omap, u32 value)
+                                               omap->irq0_offset, value);
+ }
+ 
++static void dwc3_omap_write_irqmisc_clr(struct dwc3_omap *omap, u32 value)
++{
++      dwc3_omap_writel(omap->base, USBOTGSS_IRQENABLE_CLR_MISC +
++                                              omap->irqmisc_offset, value);
++}
++
++static void dwc3_omap_write_irq0_clr(struct dwc3_omap *omap, u32 value)
++{
++      dwc3_omap_writel(omap->base, USBOTGSS_IRQENABLE_CLR_0 -
++                                              omap->irq0_offset, value);
++}
++
+ static void dwc3_omap_set_mailbox(struct dwc3_omap *omap,
+       enum omap_dwc3_vbus_id_status status)
+ {
+@@ -351,9 +363,23 @@ static void dwc3_omap_enable_irqs(struct dwc3_omap *omap)
+ 
+ static void dwc3_omap_disable_irqs(struct dwc3_omap *omap)
+ {
++      u32                     reg;
++
+       /* disable all IRQs */
+-      dwc3_omap_write_irqmisc_set(omap, 0x00);
+-      dwc3_omap_write_irq0_set(omap, 0x00);
++      reg = USBOTGSS_IRQO_COREIRQ_ST;
++      dwc3_omap_write_irq0_clr(omap, reg);
++
++      reg = (USBOTGSS_IRQMISC_OEVT |
++                      USBOTGSS_IRQMISC_DRVVBUS_RISE |
++                      USBOTGSS_IRQMISC_CHRGVBUS_RISE |
++                      USBOTGSS_IRQMISC_DISCHRGVBUS_RISE |
++                      USBOTGSS_IRQMISC_IDPULLUP_RISE |
++                      USBOTGSS_IRQMISC_DRVVBUS_FALL |
++                      USBOTGSS_IRQMISC_CHRGVBUS_FALL |
++                      USBOTGSS_IRQMISC_DISCHRGVBUS_FALL |
++                      USBOTGSS_IRQMISC_IDPULLUP_FALL);
++
++      dwc3_omap_write_irqmisc_clr(omap, reg);
+ }
+ 
+ static u64 dwc3_omap_dma_mask = DMA_BIT_MASK(32);
+diff --git a/drivers/usb/host/xhci-ring.c b/drivers/usb/host/xhci-ring.c
+index faa8b98954d9..a95eee8ddc38 100644
+--- a/drivers/usb/host/xhci-ring.c
++++ b/drivers/usb/host/xhci-ring.c
+@@ -2133,7 +2133,7 @@ static int process_ctrl_td(struct xhci_hcd *xhci, struct 
xhci_td *td,
+       if (event_trb != ep_ring->dequeue) {
+               /* The event was for the status stage */
+               if (event_trb == td->last_trb) {
+-                      if (td->urb->actual_length != 0) {
++                      if (td->urb_length_set) {
+                               /* Don't overwrite a previously set error code
+                                */
+                               if ((*status == -EINPROGRESS || *status == 0) &&
+@@ -2147,7 +2147,13 @@ static int process_ctrl_td(struct xhci_hcd *xhci, 
struct xhci_td *td,
+                                       td->urb->transfer_buffer_length;
+                       }
+               } else {
+-              /* Maybe the event was for the data stage? */
++                      /*
++                       * Maybe the event was for the data stage? If so, update
++                       * already the actual_length of the URB and flag it as
++                       * set, so that it is not overwritten in the event for
++                       * the last TRB.
++                       */
++                      td->urb_length_set = true;
+                       td->urb->actual_length =
+                               td->urb->transfer_buffer_length -
+                               EVENT_TRB_LEN(le32_to_cpu(event->transfer_len));
+diff --git a/drivers/usb/host/xhci.h b/drivers/usb/host/xhci.h
+index 96e9e780ccae..7225dd242bfa 100644
+--- a/drivers/usb/host/xhci.h
++++ b/drivers/usb/host/xhci.h
+@@ -1,3 +1,4 @@
++
+ /*
+  * xHCI host controller driver
+  *
+@@ -88,9 +89,10 @@ struct xhci_cap_regs {
+ #define HCS_IST(p)            (((p) >> 0) & 0xf)
+ /* bits 4:7, max number of Event Ring segments */
+ #define HCS_ERST_MAX(p)               (((p) >> 4) & 0xf)
++/* bits 21:25 Hi 5 bits of Scratchpad buffers SW must allocate for the HW */
+ /* bit 26 Scratchpad restore - for save/restore HW state - not used yet */
+-/* bits 27:31 number of Scratchpad buffers SW must allocate for the HW */
+-#define HCS_MAX_SCRATCHPAD(p)   (((p) >> 27) & 0x1f)
++/* bits 27:31 Lo 5 bits of Scratchpad buffers SW must allocate for the HW */
++#define HCS_MAX_SCRATCHPAD(p)   ((((p) >> 16) & 0x3e0) | (((p) >> 27) & 0x1f))
+ 
+ /* HCSPARAMS3 - hcs_params3 - bitmasks */
+ /* bits 0:7, Max U1 to U0 latency for the roothub ports */
+@@ -1289,6 +1291,8 @@ struct xhci_td {
+       struct xhci_segment     *start_seg;
+       union xhci_trb          *first_trb;
+       union xhci_trb          *last_trb;
++      /* actual_length of the URB has already been set */
++      bool                    urb_length_set;
+ };
+ 
+ /* xHCI command default timeout value */
+diff --git a/drivers/usb/serial/bus.c b/drivers/usb/serial/bus.c
+index 9374bd2aba20..6f91eb9ae81a 100644
+--- a/drivers/usb/serial/bus.c
++++ b/drivers/usb/serial/bus.c
+@@ -51,6 +51,7 @@ static int usb_serial_device_probe(struct device *dev)
+ {
+       struct usb_serial_driver *driver;
+       struct usb_serial_port *port;
++      struct device *tty_dev;
+       int retval = 0;
+       int minor;
+ 
+@@ -75,12 +76,20 @@ static int usb_serial_device_probe(struct device *dev)
+       retval = device_create_file(dev, &dev_attr_port_number);
+       if (retval) {
+               if (driver->port_remove)
+-                      retval = driver->port_remove(port);
++                      driver->port_remove(port);
+               goto exit_with_autopm;
+       }
+ 
+       minor = port->minor;
+-      tty_register_device(usb_serial_tty_driver, minor, dev);
++      tty_dev = tty_register_device(usb_serial_tty_driver, minor, dev);
++      if (IS_ERR(tty_dev)) {
++              retval = PTR_ERR(tty_dev);
++              device_remove_file(dev, &dev_attr_port_number);
++              if (driver->port_remove)
++                      driver->port_remove(port);
++              goto exit_with_autopm;
++      }
++
+       dev_info(&port->serial->dev->dev,
+                "%s converter now attached to ttyUSB%d\n",
+                driver->description, minor);
+diff --git a/drivers/usb/serial/cp210x.c b/drivers/usb/serial/cp210x.c
+index a2d040971afe..8d114b9733ed 100644
+--- a/drivers/usb/serial/cp210x.c
++++ b/drivers/usb/serial/cp210x.c
+@@ -147,6 +147,8 @@ static const struct usb_device_id id_table[] = {
+       { USB_DEVICE(0x166A, 0x0305) }, /* Clipsal C-5000CT2 C-Bus Spectrum 
Colour Touchscreen */
+       { USB_DEVICE(0x166A, 0x0401) }, /* Clipsal L51xx C-Bus Architectural 
Dimmer */
+       { USB_DEVICE(0x166A, 0x0101) }, /* Clipsal 5560884 C-Bus Multi-room 
Audio Matrix Switcher */
++      { USB_DEVICE(0x16C0, 0x09B0) }, /* Lunatico Seletek */
++      { USB_DEVICE(0x16C0, 0x09B1) }, /* Lunatico Seletek */
+       { USB_DEVICE(0x16D6, 0x0001) }, /* Jablotron serial interface */
+       { USB_DEVICE(0x16DC, 0x0010) }, /* W-IE-NE-R Plein & Baus GmbH PL512 
Power Supply */
+       { USB_DEVICE(0x16DC, 0x0011) }, /* W-IE-NE-R Plein & Baus GmbH RCM 
Remote Control for MARATON Power Supply */
+diff --git a/drivers/usb/serial/ftdi_sio.c b/drivers/usb/serial/ftdi_sio.c
+index debcdef4cbf0..923500595357 100644
+--- a/drivers/usb/serial/ftdi_sio.c
++++ b/drivers/usb/serial/ftdi_sio.c
+@@ -812,6 +812,8 @@ static const struct usb_device_id id_table_combined[] = {
+       { USB_DEVICE(FTDI_VID, FTDI_ELSTER_UNICOM_PID) },
+       { USB_DEVICE(FTDI_VID, FTDI_PROPOX_JTAGCABLEII_PID) },
+       { USB_DEVICE(FTDI_VID, FTDI_PROPOX_ISPCABLEIII_PID) },
++      { USB_DEVICE(FTDI_VID, CYBER_CORTEX_AV_PID),
++              .driver_info = (kernel_ulong_t)&ftdi_jtag_quirk },
+       { USB_DEVICE(OLIMEX_VID, OLIMEX_ARM_USB_OCD_PID),
+               .driver_info = (kernel_ulong_t)&ftdi_jtag_quirk },
+       { USB_DEVICE(OLIMEX_VID, OLIMEX_ARM_USB_OCD_H_PID),
+@@ -991,6 +993,23 @@ static const struct usb_device_id id_table_combined[] = {
+       { USB_DEVICE_INTERFACE_NUMBER(INFINEON_VID, INFINEON_TRIBOARD_PID, 1) },
+       /* GE Healthcare devices */
+       { USB_DEVICE(GE_HEALTHCARE_VID, GE_HEALTHCARE_NEMO_TRACKER_PID) },
++      /* Active Research (Actisense) devices */
++      { USB_DEVICE(FTDI_VID, ACTISENSE_NDC_PID) },
++      { USB_DEVICE(FTDI_VID, ACTISENSE_USG_PID) },
++      { USB_DEVICE(FTDI_VID, ACTISENSE_NGT_PID) },
++      { USB_DEVICE(FTDI_VID, ACTISENSE_NGW_PID) },
++      { USB_DEVICE(FTDI_VID, ACTISENSE_D9AC_PID) },
++      { USB_DEVICE(FTDI_VID, ACTISENSE_D9AD_PID) },
++      { USB_DEVICE(FTDI_VID, ACTISENSE_D9AE_PID) },
++      { USB_DEVICE(FTDI_VID, ACTISENSE_D9AF_PID) },
++      { USB_DEVICE(FTDI_VID, CHETCO_SEAGAUGE_PID) },
++      { USB_DEVICE(FTDI_VID, CHETCO_SEASWITCH_PID) },
++      { USB_DEVICE(FTDI_VID, CHETCO_SEASMART_NMEA2000_PID) },
++      { USB_DEVICE(FTDI_VID, CHETCO_SEASMART_ETHERNET_PID) },
++      { USB_DEVICE(FTDI_VID, CHETCO_SEASMART_WIFI_PID) },
++      { USB_DEVICE(FTDI_VID, CHETCO_SEASMART_DISPLAY_PID) },
++      { USB_DEVICE(FTDI_VID, CHETCO_SEASMART_LITE_PID) },
++      { USB_DEVICE(FTDI_VID, CHETCO_SEASMART_ANALOG_PID) },
+       { }                                     /* Terminating entry */
+ };
+ 
+diff --git a/drivers/usb/serial/ftdi_sio_ids.h 
b/drivers/usb/serial/ftdi_sio_ids.h
+index e52409c9be99..56b1b55c4751 100644
+--- a/drivers/usb/serial/ftdi_sio_ids.h
++++ b/drivers/usb/serial/ftdi_sio_ids.h
+@@ -38,6 +38,9 @@
+ 
+ #define FTDI_LUMEL_PD12_PID   0x6002
+ 
++/* Cyber Cortex AV by Fabulous Silicon (http://fabuloussilicon.com) */
++#define CYBER_CORTEX_AV_PID   0x8698
++
+ /*
+  * Marvell OpenRD Base, Client
+  * http://www.open-rd.org
+@@ -1438,3 +1441,23 @@
+  */
+ #define GE_HEALTHCARE_VID             0x1901
+ #define GE_HEALTHCARE_NEMO_TRACKER_PID        0x0015
++
++/*
++ * Active Research (Actisense) devices
++ */
++#define ACTISENSE_NDC_PID             0xD9A8 /* NDC USB Serial Adapter */
++#define ACTISENSE_USG_PID             0xD9A9 /* USG USB Serial Adapter */
++#define ACTISENSE_NGT_PID             0xD9AA /* NGT NMEA2000 Interface */
++#define ACTISENSE_NGW_PID             0xD9AB /* NGW NMEA2000 Gateway */
++#define ACTISENSE_D9AC_PID            0xD9AC /* Actisense Reserved */
++#define ACTISENSE_D9AD_PID            0xD9AD /* Actisense Reserved */
++#define ACTISENSE_D9AE_PID            0xD9AE /* Actisense Reserved */
++#define ACTISENSE_D9AF_PID            0xD9AF /* Actisense Reserved */
++#define CHETCO_SEAGAUGE_PID           0xA548 /* SeaGauge USB Adapter */
++#define CHETCO_SEASWITCH_PID          0xA549 /* SeaSwitch USB Adapter */
++#define CHETCO_SEASMART_NMEA2000_PID  0xA54A /* SeaSmart NMEA2000 Gateway */
++#define CHETCO_SEASMART_ETHERNET_PID  0xA54B /* SeaSmart Ethernet Gateway */
++#define CHETCO_SEASMART_WIFI_PID      0xA5AC /* SeaSmart Wifi Gateway */
++#define CHETCO_SEASMART_DISPLAY_PID   0xA5AD /* SeaSmart NMEA2000 Display */
++#define CHETCO_SEASMART_LITE_PID      0xA5AE /* SeaSmart Lite USB Adapter */
++#define CHETCO_SEASMART_ANALOG_PID    0xA5AF /* SeaSmart Analog Adapter */
+diff --git a/drivers/usb/serial/generic.c b/drivers/usb/serial/generic.c
+index b63ce023f96f..d6a197917ebd 100644
+--- a/drivers/usb/serial/generic.c
++++ b/drivers/usb/serial/generic.c
+@@ -258,7 +258,8 @@ void usb_serial_generic_wait_until_sent(struct tty_struct 
*tty, long timeout)
+        * character or at least one jiffy.
+        */
+       period = max_t(unsigned long, (10 * HZ / bps), 1);
+-      period = min_t(unsigned long, period, timeout);
++      if (timeout)
++              period = min_t(unsigned long, period, timeout);
+ 
+       dev_dbg(&port->dev, "%s - timeout = %u ms, period = %u ms\n",
+                                       __func__, jiffies_to_msecs(timeout),
+@@ -268,7 +269,7 @@ void usb_serial_generic_wait_until_sent(struct tty_struct 
*tty, long timeout)
+               schedule_timeout_interruptible(period);
+               if (signal_pending(current))
+                       break;
+-              if (time_after(jiffies, expire))
++              if (timeout && time_after(jiffies, expire))
+                       break;
+       }
+ }
+diff --git a/drivers/usb/serial/mxuport.c b/drivers/usb/serial/mxuport.c
+index ab1d690274ae..460a40669967 100644
+--- a/drivers/usb/serial/mxuport.c
++++ b/drivers/usb/serial/mxuport.c
+@@ -1284,7 +1284,8 @@ static int mxuport_open(struct tty_struct *tty, struct 
usb_serial_port *port)
+       }
+ 
+       /* Initial port termios */
+-      mxuport_set_termios(tty, port, NULL);
++      if (tty)
++              mxuport_set_termios(tty, port, NULL);
+ 
+       /*
+        * TODO: use RQ_VENDOR_GET_MSR, once we know what it
+diff --git a/fs/autofs4/dev-ioctl.c b/fs/autofs4/dev-ioctl.c
+index 3182c0e68b42..e3399dc2453b 100644
+--- a/fs/autofs4/dev-ioctl.c
++++ b/fs/autofs4/dev-ioctl.c
+@@ -95,7 +95,7 @@ static int check_dev_ioctl_version(int cmd, struct 
autofs_dev_ioctl *param)
+  */
+ static struct autofs_dev_ioctl *copy_dev_ioctl(struct autofs_dev_ioctl __user 
*in)
+ {
+-      struct autofs_dev_ioctl tmp;
++      struct autofs_dev_ioctl tmp, *res;
+ 
+       if (copy_from_user(&tmp, in, sizeof(tmp)))
+               return ERR_PTR(-EFAULT);
+@@ -103,7 +103,11 @@ static struct autofs_dev_ioctl *copy_dev_ioctl(struct 
autofs_dev_ioctl __user *i
+       if (tmp.size < sizeof(tmp))
+               return ERR_PTR(-EINVAL);
+ 
+-      return memdup_user(in, tmp.size);
++      res = memdup_user(in, tmp.size);
++      if (!IS_ERR(res))
++              res->size = tmp.size;
++
++      return res;
+ }
+ 
+ static inline void free_dev_ioctl(struct autofs_dev_ioctl *param)
+diff --git a/fs/btrfs/file.c b/fs/btrfs/file.c
+index 279b06ef5522..0a841ddd6843 100644
+--- a/fs/btrfs/file.c
++++ b/fs/btrfs/file.c
+@@ -1774,22 +1774,10 @@ static ssize_t btrfs_file_aio_write(struct kiocb *iocb,
+       mutex_unlock(&inode->i_mutex);
+ 
+       /*
+-       * we want to make sure fsync finds this change
+-       * but we haven't joined a transaction running right now.
+-       *
+-       * Later on, someone is sure to update the inode and get the
+-       * real transid recorded.
+-       *
+-       * We set last_trans now to the fs_info generation + 1,
+-       * this will either be one more than the running transaction
+-       * or the generation used for the next transaction if there isn't
+-       * one running right now.
+-       *
+        * We also have to set last_sub_trans to the current log transid,
+        * otherwise subsequent syncs to a file that's been synced in this
+        * transaction will appear to have already occured.
+        */
+-      BTRFS_I(inode)->last_trans = root->fs_info->generation + 1;
+       BTRFS_I(inode)->last_sub_trans = root->log_transid;
+       if (num_written > 0) {
+               err = generic_write_sync(file, pos, num_written);
+@@ -1892,25 +1880,37 @@ int btrfs_sync_file(struct file *file, loff_t start, 
loff_t end, int datasync)
+       atomic_inc(&root->log_batch);
+ 
+       /*
+-       * check the transaction that last modified this inode
+-       * and see if its already been committed
+-       */
+-      if (!BTRFS_I(inode)->last_trans) {
+-              mutex_unlock(&inode->i_mutex);
+-              goto out;
+-      }
+-
+-      /*
+-       * if the last transaction that changed this file was before
+-       * the current transaction, we can bail out now without any
+-       * syncing
++       * If the last transaction that changed this file was before the current
++       * transaction and we have the full sync flag set in our inode, we can
++       * bail out now without any syncing.
++       *
++       * Note that we can't bail out if the full sync flag isn't set. This is
++       * because when the full sync flag is set we start all ordered extents
++       * and wait for them to fully complete - when they complete they update
++       * the inode's last_trans field through:
++       *
++       *     btrfs_finish_ordered_io() ->
++       *         btrfs_update_inode_fallback() ->
++       *             btrfs_update_inode() ->
++       *                 btrfs_set_inode_last_trans()
++       *
++       * So we are sure that last_trans is up to date and can do this check to
++       * bail out safely. For the fast path, when the full sync flag is not
++       * set in our inode, we can not do it because we start only our ordered
++       * extents and don't wait for them to complete (that is when
++       * btrfs_finish_ordered_io runs), so here at this point their last_trans
++       * value might be less than or equals to fs_info->last_trans_committed,
++       * and setting a speculative last_trans for an inode when a buffered
++       * write is made (such as fs_info->generation + 1 for example) would not
++       * be reliable since after setting the value and before fsync is called
++       * any number of transactions can start and commit (transaction kthread
++       * commits the current transaction periodically), and a transaction
++       * commit does not start nor waits for ordered extents to complete.
+        */
+       smp_mb();
+       if (btrfs_inode_in_log(inode, root->fs_info->generation) ||
+-          BTRFS_I(inode)->last_trans <=
+-          root->fs_info->last_trans_committed) {
+-              BTRFS_I(inode)->last_trans = 0;
+-
++          (full_sync && BTRFS_I(inode)->last_trans <=
++           root->fs_info->last_trans_committed)) {
+               /*
+                * We'v had everything committed since the last time we were
+                * modified so clear this flag in case it was set for whatever
+diff --git a/fs/btrfs/inode.c b/fs/btrfs/inode.c
+index d68a7250f00b..653cdd85e0f2 100644
+--- a/fs/btrfs/inode.c
++++ b/fs/btrfs/inode.c
+@@ -6870,7 +6870,6 @@ static int btrfs_get_blocks_direct(struct inode *inode, 
sector_t iblock,
+           ((BTRFS_I(inode)->flags & BTRFS_INODE_NODATACOW) &&
+            em->block_start != EXTENT_MAP_HOLE)) {
+               int type;
+-              int ret;
+               u64 block_start, orig_start, orig_block_len, ram_bytes;
+ 
+               if (test_bit(EXTENT_FLAG_PREALLOC, &em->flags))
+diff --git a/fs/btrfs/tree-log.c b/fs/btrfs/tree-log.c
+index aeb57b98c53f..a7f32bfdd5e7 100644
+--- a/fs/btrfs/tree-log.c
++++ b/fs/btrfs/tree-log.c
+@@ -979,7 +979,7 @@ again:
+               base = btrfs_item_ptr_offset(leaf, path->slots[0]);
+ 
+               while (cur_offset < item_size) {
+-                      extref = (struct btrfs_inode_extref *)base + cur_offset;
++                      extref = (struct btrfs_inode_extref *)(base + 
cur_offset);
+ 
+                       victim_name_len = btrfs_inode_extref_name_len(leaf, 
extref);
+ 
+diff --git a/fs/debugfs/inode.c b/fs/debugfs/inode.c
+index 15761957cc3f..1ff8fe5dab0d 100644
+--- a/fs/debugfs/inode.c
++++ b/fs/debugfs/inode.c
+@@ -245,10 +245,19 @@ static int debugfs_show_options(struct seq_file *m, 
struct dentry *root)
+       return 0;
+ }
+ 
++static void debugfs_evict_inode(struct inode *inode)
++{
++      truncate_inode_pages(&inode->i_data, 0);
++      clear_inode(inode);
++      if (S_ISLNK(inode->i_mode))
++              kfree(inode->i_private);
++}
++
+ static const struct super_operations debugfs_super_operations = {
+       .statfs         = simple_statfs,
+       .remount_fs     = debugfs_remount,
+       .show_options   = debugfs_show_options,
++      .evict_inode    = debugfs_evict_inode,
+ };
+ 
+ static int debug_fill_super(struct super_block *sb, void *data, int silent)
+@@ -465,23 +474,14 @@ static int __debugfs_remove(struct dentry *dentry, 
struct dentry *parent)
+       int ret = 0;
+ 
+       if (debugfs_positive(dentry)) {
+-              if (dentry->d_inode) {
+-                      dget(dentry);
+-                      switch (dentry->d_inode->i_mode & S_IFMT) {
+-                      case S_IFDIR:
+-                              ret = simple_rmdir(parent->d_inode, dentry);
+-                              break;
+-                      case S_IFLNK:
+-                              kfree(dentry->d_inode->i_private);
+-                              /* fall through */
+-                      default:
+-                              simple_unlink(parent->d_inode, dentry);
+-                              break;
+-                      }
+-                      if (!ret)
+-                              d_delete(dentry);
+-                      dput(dentry);
+-              }
++              dget(dentry);
++              if (S_ISDIR(dentry->d_inode->i_mode))
++                      ret = simple_rmdir(parent->d_inode, dentry);
++              else
++                      simple_unlink(parent->d_inode, dentry);
++              if (!ret)
++                      d_delete(dentry);
++              dput(dentry);
+       }
+       return ret;
+ }
+diff --git a/fs/nfs/delegation.c b/fs/nfs/delegation.c
+index 3ed1be9aade3..2ea3537b8bde 100644
+--- a/fs/nfs/delegation.c
++++ b/fs/nfs/delegation.c
+@@ -161,8 +161,8 @@ void nfs_inode_reclaim_delegation(struct inode *inode, 
struct rpc_cred *cred,
+                                 &delegation->flags);
+                       NFS_I(inode)->delegation_state = delegation->type;
+                       spin_unlock(&delegation->lock);
+-                      put_rpccred(oldcred);
+                       rcu_read_unlock();
++                      put_rpccred(oldcred);
+                       trace_nfs4_reclaim_delegation(inode, 
res->delegation_type);
+               } else {
+                       /* We appear to have raced with a delegation return. */
+diff --git a/fs/nilfs2/btree.c b/fs/nilfs2/btree.c
+index b2e3ff347620..ecdbae19a766 100644
+--- a/fs/nilfs2/btree.c
++++ b/fs/nilfs2/btree.c
+@@ -31,6 +31,8 @@
+ #include "alloc.h"
+ #include "dat.h"
+ 
++static void __nilfs_btree_init(struct nilfs_bmap *bmap);
++
+ static struct nilfs_btree_path *nilfs_btree_alloc_path(void)
+ {
+       struct nilfs_btree_path *path;
+@@ -368,6 +370,34 @@ static int nilfs_btree_node_broken(const struct 
nilfs_btree_node *node,
+       return ret;
+ }
+ 
++/**
++ * nilfs_btree_root_broken - verify consistency of btree root node
++ * @node: btree root node to be examined
++ * @ino: inode number
++ *
++ * Return Value: If node is broken, 1 is returned. Otherwise, 0 is returned.
++ */
++static int nilfs_btree_root_broken(const struct nilfs_btree_node *node,
++                                 unsigned long ino)
++{
++      int level, flags, nchildren;
++      int ret = 0;
++
++      level = nilfs_btree_node_get_level(node);
++      flags = nilfs_btree_node_get_flags(node);
++      nchildren = nilfs_btree_node_get_nchildren(node);
++
++      if (unlikely(level < NILFS_BTREE_LEVEL_NODE_MIN ||
++                   level > NILFS_BTREE_LEVEL_MAX ||
++                   nchildren < 0 ||
++                   nchildren > NILFS_BTREE_ROOT_NCHILDREN_MAX)) {
++              pr_crit("NILFS: bad btree root (inode number=%lu): level = %d, 
flags = 0x%x, nchildren = %d\n",
++                      ino, level, flags, nchildren);
++              ret = 1;
++      }
++      return ret;
++}
++
+ int nilfs_btree_broken_node_block(struct buffer_head *bh)
+ {
+       int ret;
+@@ -1713,7 +1743,7 @@ nilfs_btree_commit_convert_and_insert(struct nilfs_bmap 
*btree,
+ 
+       /* convert and insert */
+       dat = NILFS_BMAP_USE_VBN(btree) ? nilfs_bmap_get_dat(btree) : NULL;
+-      nilfs_btree_init(btree);
++      __nilfs_btree_init(btree);
+       if (nreq != NULL) {
+               nilfs_bmap_commit_alloc_ptr(btree, dreq, dat);
+               nilfs_bmap_commit_alloc_ptr(btree, nreq, dat);
+@@ -2294,12 +2324,23 @@ static const struct nilfs_bmap_operations 
nilfs_btree_ops_gc = {
+       .bop_gather_data        =       NULL,
+ };
+ 
+-int nilfs_btree_init(struct nilfs_bmap *bmap)
++static void __nilfs_btree_init(struct nilfs_bmap *bmap)
+ {
+       bmap->b_ops = &nilfs_btree_ops;
+       bmap->b_nchildren_per_block =
+               NILFS_BTREE_NODE_NCHILDREN_MAX(nilfs_btree_node_size(bmap));
+-      return 0;
++}
++
++int nilfs_btree_init(struct nilfs_bmap *bmap)
++{
++      int ret = 0;
++
++      __nilfs_btree_init(bmap);
++
++      if (nilfs_btree_root_broken(nilfs_btree_get_root(bmap),
++                                  bmap->b_inode->i_ino))
++              ret = -EIO;
++      return ret;
+ }
+ 
+ void nilfs_btree_init_gc(struct nilfs_bmap *bmap)
+diff --git a/fs/proc/generic.c b/fs/proc/generic.c
+index b7f268eb5f45..2e2d9d5d78d9 100644
+--- a/fs/proc/generic.c
++++ b/fs/proc/generic.c
+@@ -19,7 +19,6 @@
+ #include <linux/mount.h>
+ #include <linux/init.h>
+ #include <linux/idr.h>
+-#include <linux/namei.h>
+ #include <linux/bitops.h>
+ #include <linux/spinlock.h>
+ #include <linux/completion.h>
+@@ -162,17 +161,6 @@ void proc_free_inum(unsigned int inum)
+       spin_unlock_irqrestore(&proc_inum_lock, flags);
+ }
+ 
+-static void *proc_follow_link(struct dentry *dentry, struct nameidata *nd)
+-{
+-      nd_set_link(nd, __PDE_DATA(dentry->d_inode));
+-      return NULL;
+-}
+-
+-static const struct inode_operations proc_link_inode_operations = {
+-      .readlink       = generic_readlink,
+-      .follow_link    = proc_follow_link,
+-};
+-
+ /*
+  * Don't create negative dentries here, return -ENOENT by hand
+  * instead.
+diff --git a/fs/proc/inode.c b/fs/proc/inode.c
+index 124fc43c7090..2f2815f3176e 100644
+--- a/fs/proc/inode.c
++++ b/fs/proc/inode.c
+@@ -23,6 +23,7 @@
+ #include <linux/slab.h>
+ #include <linux/mount.h>
+ #include <linux/magic.h>
++#include <linux/namei.h>
+ 
+ #include <asm/uaccess.h>
+ 
+@@ -401,6 +402,26 @@ static const struct file_operations 
proc_reg_file_ops_no_compat = {
+ };
+ #endif
+ 
++static void *proc_follow_link(struct dentry *dentry, struct nameidata *nd)
++{
++      struct proc_dir_entry *pde = PDE(dentry->d_inode);
++      if (unlikely(!use_pde(pde)))
++              return ERR_PTR(-EINVAL);
++      nd_set_link(nd, pde->data);
++      return pde;
++}
++
++static void proc_put_link(struct dentry *dentry, struct nameidata *nd, void 
*p)
++{
++      unuse_pde(p);
++}
++
++const struct inode_operations proc_link_inode_operations = {
++      .readlink       = generic_readlink,
++      .follow_link    = proc_follow_link,
++      .put_link       = proc_put_link,
++};
++
+ struct inode *proc_get_inode(struct super_block *sb, struct proc_dir_entry 
*de)
+ {
+       struct inode *inode = new_inode_pseudo(sb);
+diff --git a/fs/proc/internal.h b/fs/proc/internal.h
+index 651d09a11dde..8b8ca1db6316 100644
+--- a/fs/proc/internal.h
++++ b/fs/proc/internal.h
+@@ -202,6 +202,7 @@ struct pde_opener {
+       int closing;
+       struct completion *c;
+ };
++extern const struct inode_operations proc_link_inode_operations;
+ 
+ extern const struct inode_operations proc_pid_link_inode_operations;
+ 
+diff --git a/include/target/target_core_base.h 
b/include/target/target_core_base.h
+index 1772fadcff62..349325404add 100644
+--- a/include/target/target_core_base.h
++++ b/include/target/target_core_base.h
+@@ -407,7 +407,7 @@ struct t10_reservation {
+       /* Activate Persistence across Target Power Loss enabled
+        * for SCSI device */
+       int pr_aptpl_active;
+-#define PR_APTPL_BUF_LEN                      8192
++#define PR_APTPL_BUF_LEN                      262144
+       u32 pr_generation;
+       spinlock_t registration_lock;
+       spinlock_t aptpl_reg_lock;
+diff --git a/include/trace/events/kmem.h b/include/trace/events/kmem.h
+index aece1346ceb7..4ad10baecd4d 100644
+--- a/include/trace/events/kmem.h
++++ b/include/trace/events/kmem.h
+@@ -268,11 +268,11 @@ TRACE_EVENT(mm_page_alloc_extfrag,
+ 
+       TP_PROTO(struct page *page,
+               int alloc_order, int fallback_order,
+-              int alloc_migratetype, int fallback_migratetype, int 
new_migratetype),
++              int alloc_migratetype, int fallback_migratetype),
+ 
+       TP_ARGS(page,
+               alloc_order, fallback_order,
+-              alloc_migratetype, fallback_migratetype, new_migratetype),
++              alloc_migratetype, fallback_migratetype),
+ 
+       TP_STRUCT__entry(
+               __field(        struct page *,  page                    )
+@@ -289,7 +289,8 @@ TRACE_EVENT(mm_page_alloc_extfrag,
+               __entry->fallback_order         = fallback_order;
+               __entry->alloc_migratetype      = alloc_migratetype;
+               __entry->fallback_migratetype   = fallback_migratetype;
+-              __entry->change_ownership       = (new_migratetype == 
alloc_migratetype);
++              __entry->change_ownership       = (alloc_migratetype ==
++                                      get_pageblock_migratetype(page));
+       ),
+ 
+       TP_printk("page=%p pfn=%lu alloc_order=%d fallback_order=%d 
pageblock_order=%d alloc_migratetype=%d fallback_migratetype=%d fragmenting=%d 
change_ownership=%d",
+diff --git a/mm/compaction.c b/mm/compaction.c
+index 4229fc22a477..a522208bb8ea 100644
+--- a/mm/compaction.c
++++ b/mm/compaction.c
+@@ -937,7 +937,7 @@ static int compact_finished(struct zone *zone,
+                       return COMPACT_PARTIAL;
+ 
+               /* Job done if allocation would set block type */
+-              if (cc->order >= pageblock_order && area->nr_free)
++              if (order >= pageblock_order && area->nr_free)
+                       return COMPACT_PARTIAL;
+       }
+ 
+diff --git a/mm/hugetlb.c b/mm/hugetlb.c
+index 472259b00618..c3e8660cb616 100644
+--- a/mm/hugetlb.c
++++ b/mm/hugetlb.c
+@@ -2488,9 +2488,10 @@ again:
+                       goto unlock;
+ 
+               /*
+-               * HWPoisoned hugepage is already unmapped and dropped reference
++               * Migrating hugepage or HWPoisoned hugepage is already
++               * unmapped and its refcount is dropped, so just clear pte here.
+                */
+-              if (unlikely(is_hugetlb_entry_hwpoisoned(pte))) {
++              if (unlikely(!pte_present(pte))) {
+                       huge_pte_clear(mm, address, ptep);
+                       goto unlock;
+               }
+@@ -3163,7 +3164,26 @@ unsigned long hugetlb_change_protection(struct 
vm_area_struct *vma,
+                       spin_unlock(ptl);
+                       continue;
+               }
+-              if (!huge_pte_none(huge_ptep_get(ptep))) {
++              pte = huge_ptep_get(ptep);
++              if (unlikely(is_hugetlb_entry_hwpoisoned(pte))) {
++                      spin_unlock(ptl);
++                      continue;
++              }
++              if (unlikely(is_hugetlb_entry_migration(pte))) {
++                      swp_entry_t entry = pte_to_swp_entry(pte);
++
++                      if (is_write_migration_entry(entry)) {
++                              pte_t newpte;
++
++                              make_migration_entry_read(&entry);
++                              newpte = swp_entry_to_pte(entry);
++                              set_huge_pte_at(mm, address, ptep, newpte);
++                              pages++;
++                      }
++                      spin_unlock(ptl);
++                      continue;
++              }
++              if (!huge_pte_none(pte)) {
+                       pte = huge_ptep_get_and_clear(mm, address, ptep);
+                       pte = pte_mkhuge(huge_pte_modify(pte, newprot));
+                       pte = arch_make_huge_pte(pte, vma, NULL, 0);
+diff --git a/mm/memory.c b/mm/memory.c
+index 7f30beaba74f..102af096cbc5 100644
+--- a/mm/memory.c
++++ b/mm/memory.c
+@@ -4024,7 +4024,7 @@ int generic_access_phys(struct vm_area_struct *vma, 
unsigned long addr,
+       if (follow_phys(vma, addr, write, &prot, &phys_addr))
+               return -EINVAL;
+ 
+-      maddr = ioremap_prot(phys_addr, PAGE_SIZE, prot);
++      maddr = ioremap_prot(phys_addr, PAGE_ALIGN(len + offset), prot);
+       if (write)
+               memcpy_toio(maddr + offset, buf, len);
+       else
+diff --git a/mm/mmap.c b/mm/mmap.c
+index 085bcd890ad2..d4c97ba6843b 100644
+--- a/mm/mmap.c
++++ b/mm/mmap.c
+@@ -129,7 +129,7 @@ EXPORT_SYMBOL_GPL(vm_memory_committed);
+  */
+ int __vm_enough_memory(struct mm_struct *mm, long pages, int cap_sys_admin)
+ {
+-      unsigned long free, allowed, reserve;
++      long free, allowed, reserve;
+ 
+       vm_acct_memory(pages);
+ 
+@@ -193,7 +193,7 @@ int __vm_enough_memory(struct mm_struct *mm, long pages, 
int cap_sys_admin)
+        */
+       if (mm) {
+               reserve = sysctl_user_reserve_kbytes >> (PAGE_SHIFT - 10);
+-              allowed -= min(mm->total_vm / 32, reserve);
++              allowed -= min_t(long, mm->total_vm / 32, reserve);
+       }
+ 
+       if (percpu_counter_read_positive(&vm_committed_as) < allowed)
+diff --git a/mm/nommu.c b/mm/nommu.c
+index 3ee4f74fbfbe..76b3f90ada7b 100644
+--- a/mm/nommu.c
++++ b/mm/nommu.c
+@@ -1905,7 +1905,7 @@ EXPORT_SYMBOL(unmap_mapping_range);
+  */
+ int __vm_enough_memory(struct mm_struct *mm, long pages, int cap_sys_admin)
+ {
+-      unsigned long free, allowed, reserve;
++      long free, allowed, reserve;
+ 
+       vm_acct_memory(pages);
+ 
+@@ -1969,7 +1969,7 @@ int __vm_enough_memory(struct mm_struct *mm, long pages, 
int cap_sys_admin)
+        */
+       if (mm) {
+               reserve = sysctl_user_reserve_kbytes >> (PAGE_SHIFT - 10);
+-              allowed -= min(mm->total_vm / 32, reserve);
++              allowed -= min_t(long, mm->total_vm / 32, reserve);
+       }
+ 
+       if (percpu_counter_read_positive(&vm_committed_as) < allowed)
+diff --git a/mm/page_alloc.c b/mm/page_alloc.c
+index ea419137f845..0479732f6b02 100644
+--- a/mm/page_alloc.c
++++ b/mm/page_alloc.c
+@@ -1081,8 +1081,8 @@ static void change_pageblock_range(struct page 
*pageblock_page,
+  * nor move CMA pages to different free lists. We don't want unmovable pages
+  * to be allocated from MIGRATE_CMA areas.
+  *
+- * Returns the new migratetype of the pageblock (or the same old migratetype
+- * if it was unchanged).
++ * Returns the allocation migratetype if free pages were stolen, or the
++ * fallback migratetype if it was decided not to steal.
+  */
+ static int try_to_steal_freepages(struct zone *zone, struct page *page,
+                                 int start_type, int fallback_type)
+@@ -1113,12 +1113,10 @@ static int try_to_steal_freepages(struct zone *zone, 
struct page *page,
+ 
+               /* Claim the whole block if over half of it is free */
+               if (pages >= (1 << (pageblock_order-1)) ||
+-                              page_group_by_mobility_disabled) {
+-
++                              page_group_by_mobility_disabled)
+                       set_pageblock_migratetype(page, start_type);
+-                      return start_type;
+-              }
+ 
++              return start_type;
+       }
+ 
+       return fallback_type;
+@@ -1170,7 +1168,7 @@ __rmqueue_fallback(struct zone *zone, unsigned int 
order, int start_migratetype)
+                       set_freepage_migratetype(page, new_type);
+ 
+                       trace_mm_page_alloc_extfrag(page, order, current_order,
+-                              start_migratetype, migratetype, new_type);
++                              start_migratetype, migratetype);
+ 
+                       return page;
+               }
+diff --git a/net/compat.c b/net/compat.c
+index cbc1a2a26587..275af79c131b 100644
+--- a/net/compat.c
++++ b/net/compat.c
+@@ -738,24 +738,18 @@ static unsigned char nas[21] = {
+ 
+ asmlinkage long compat_sys_sendmsg(int fd, struct compat_msghdr __user *msg, 
unsigned int flags)
+ {
+-      if (flags & MSG_CMSG_COMPAT)
+-              return -EINVAL;
+       return __sys_sendmsg(fd, (struct msghdr __user *)msg, flags | 
MSG_CMSG_COMPAT);
+ }
+ 
+ asmlinkage long compat_sys_sendmmsg(int fd, struct compat_mmsghdr __user 
*mmsg,
+                                   unsigned int vlen, unsigned int flags)
+ {
+-      if (flags & MSG_CMSG_COMPAT)
+-              return -EINVAL;
+       return __sys_sendmmsg(fd, (struct mmsghdr __user *)mmsg, vlen,
+                             flags | MSG_CMSG_COMPAT);
+ }
+ 
+ asmlinkage long compat_sys_recvmsg(int fd, struct compat_msghdr __user *msg, 
unsigned int flags)
+ {
+-      if (flags & MSG_CMSG_COMPAT)
+-              return -EINVAL;
+       return __sys_recvmsg(fd, (struct msghdr __user *)msg, flags | 
MSG_CMSG_COMPAT);
+ }
+ 
+@@ -778,9 +772,6 @@ asmlinkage long compat_sys_recvmmsg(int fd, struct 
compat_mmsghdr __user *mmsg,
+       int datagrams;
+       struct timespec ktspec;
+ 
+-      if (flags & MSG_CMSG_COMPAT)
+-              return -EINVAL;
+-
+       if (timeout == NULL)
+               return __sys_recvmmsg(fd, (struct mmsghdr __user *)mmsg, vlen,
+                                     flags | MSG_CMSG_COMPAT, NULL);
+diff --git a/net/core/dev.c b/net/core/dev.c
+index 4ed77d7245c0..f6d8d7fe29ab 100644
+--- a/net/core/dev.c
++++ b/net/core/dev.c
+@@ -940,7 +940,7 @@ bool dev_valid_name(const char *name)
+               return false;
+ 
+       while (*name) {
+-              if (*name == '/' || isspace(*name))
++              if (*name == '/' || *name == ':' || isspace(*name))
+                       return false;
+               name++;
+       }
+diff --git a/net/core/gen_stats.c b/net/core/gen_stats.c
+index 9d3d9e78397b..372ac662adf9 100644
+--- a/net/core/gen_stats.c
++++ b/net/core/gen_stats.c
+@@ -32,6 +32,9 @@ gnet_stats_copy(struct gnet_dump *d, int type, void *buf, 
int size)
+       return 0;
+ 
+ nla_put_failure:
++      kfree(d->xstats);
++      d->xstats = NULL;
++      d->xstats_len = 0;
+       spin_unlock_bh(d->lock);
+       return -1;
+ }
+@@ -217,7 +220,9 @@ int
+ gnet_stats_copy_app(struct gnet_dump *d, void *st, int len)
+ {
+       if (d->compat_xstats) {
+-              d->xstats = st;
++              d->xstats = kmemdup(st, len, GFP_ATOMIC);
++              if (!d->xstats)
++                      goto err_out;
+               d->xstats_len = len;
+       }
+ 
+@@ -225,6 +230,11 @@ gnet_stats_copy_app(struct gnet_dump *d, void *st, int 
len)
+               return gnet_stats_copy(d, TCA_STATS_APP, st, len);
+ 
+       return 0;
++
++err_out:
++      d->xstats_len = 0;
++      spin_unlock_bh(d->lock);
++      return -1;
+ }
+ EXPORT_SYMBOL(gnet_stats_copy_app);
+ 
+@@ -257,6 +267,9 @@ gnet_stats_finish_copy(struct gnet_dump *d)
+                       return -1;
+       }
+ 
++      kfree(d->xstats);
++      d->xstats = NULL;
++      d->xstats_len = 0;
+       spin_unlock_bh(d->lock);
+       return 0;
+ }
+diff --git a/net/core/pktgen.c b/net/core/pktgen.c
+index fdac61cac1bd..ca68d32b49ba 100644
+--- a/net/core/pktgen.c
++++ b/net/core/pktgen.c
+@@ -2812,25 +2812,25 @@ static struct sk_buff *fill_packet_ipv4(struct 
net_device *odev,
+       skb->dev = odev;
+       skb->pkt_type = PACKET_HOST;
+ 
++      pktgen_finalize_skb(pkt_dev, skb, datalen);
++
+       if (!(pkt_dev->flags & F_UDPCSUM)) {
+               skb->ip_summed = CHECKSUM_NONE;
+       } else if (odev->features & NETIF_F_V4_CSUM) {
+               skb->ip_summed = CHECKSUM_PARTIAL;
+               skb->csum = 0;
+-              udp4_hwcsum(skb, udph->source, udph->dest);
++              udp4_hwcsum(skb, iph->saddr, iph->daddr);
+       } else {
+-              __wsum csum = udp_csum(skb);
++              __wsum csum = skb_checksum(skb, skb_transport_offset(skb), 
datalen + 8, 0);
+ 
+               /* add protocol-dependent pseudo-header */
+-              udph->check = csum_tcpudp_magic(udph->source, udph->dest,
++              udph->check = csum_tcpudp_magic(iph->saddr, iph->daddr,
+                                               datalen + 8, IPPROTO_UDP, csum);
+ 
+               if (udph->check == 0)
+                       udph->check = CSUM_MANGLED_0;
+       }
+ 
+-      pktgen_finalize_skb(pkt_dev, skb, datalen);
+-
+ #ifdef CONFIG_XFRM
+       if (!process_ipsec(pkt_dev, skb, protocol))
+               return NULL;
+@@ -2946,6 +2946,8 @@ static struct sk_buff *fill_packet_ipv6(struct 
net_device *odev,
+       skb->dev = odev;
+       skb->pkt_type = PACKET_HOST;
+ 
++      pktgen_finalize_skb(pkt_dev, skb, datalen);
++
+       if (!(pkt_dev->flags & F_UDPCSUM)) {
+               skb->ip_summed = CHECKSUM_NONE;
+       } else if (odev->features & NETIF_F_V6_CSUM) {
+@@ -2954,7 +2956,7 @@ static struct sk_buff *fill_packet_ipv6(struct 
net_device *odev,
+               skb->csum_offset = offsetof(struct udphdr, check);
+               udph->check = ~csum_ipv6_magic(&iph->saddr, &iph->daddr, 
udplen, IPPROTO_UDP, 0);
+       } else {
+-              __wsum csum = udp_csum(skb);
++              __wsum csum = skb_checksum(skb, skb_transport_offset(skb), 
udplen, 0);
+ 
+               /* add protocol-dependent pseudo-header */
+               udph->check = csum_ipv6_magic(&iph->saddr, &iph->daddr, udplen, 
IPPROTO_UDP, csum);
+@@ -2963,8 +2965,6 @@ static struct sk_buff *fill_packet_ipv6(struct 
net_device *odev,
+                       udph->check = CSUM_MANGLED_0;
+       }
+ 
+-      pktgen_finalize_skb(pkt_dev, skb, datalen);
+-
+       return skb;
+ }
+ 
+diff --git a/net/core/rtnetlink.c b/net/core/rtnetlink.c
+index a6613ff972c1..8aadd6a072a4 100644
+--- a/net/core/rtnetlink.c
++++ b/net/core/rtnetlink.c
+@@ -1264,14 +1264,10 @@ static const struct nla_policy 
ifla_vfinfo_policy[IFLA_VF_INFO_MAX+1] = {
+ };
+ 
+ static const struct nla_policy ifla_vf_policy[IFLA_VF_MAX+1] = {
+-      [IFLA_VF_MAC]           = { .type = NLA_BINARY,
+-                                  .len = sizeof(struct ifla_vf_mac) },
+-      [IFLA_VF_VLAN]          = { .type = NLA_BINARY,
+-                                  .len = sizeof(struct ifla_vf_vlan) },
+-      [IFLA_VF_TX_RATE]       = { .type = NLA_BINARY,
+-                                  .len = sizeof(struct ifla_vf_tx_rate) },
+-      [IFLA_VF_SPOOFCHK]      = { .type = NLA_BINARY,
+-                                  .len = sizeof(struct ifla_vf_spoofchk) },
++      [IFLA_VF_MAC]           = { .len = sizeof(struct ifla_vf_mac) },
++      [IFLA_VF_VLAN]          = { .len = sizeof(struct ifla_vf_vlan) },
++      [IFLA_VF_TX_RATE]       = { .len = sizeof(struct ifla_vf_tx_rate) },
++      [IFLA_VF_SPOOFCHK]      = { .len = sizeof(struct ifla_vf_spoofchk) },
+ };
+ 
+ static const struct nla_policy ifla_port_policy[IFLA_PORT_MAX+1] = {
+@@ -2034,8 +2030,16 @@ replay:
+                       }
+               }
+               err = rtnl_configure_link(dev, ifm);
+-              if (err < 0)
+-                      unregister_netdevice(dev);
++              if (err < 0) {
++                      if (ops->newlink) {
++                              LIST_HEAD(list_kill);
++
++                              ops->dellink(dev, &list_kill);
++                              unregister_netdevice_many(&list_kill);
++                      } else {
++                              unregister_netdevice(dev);
++                      }
++              }
+ out:
+               put_net(dest_net);
+               return err;
+diff --git a/net/ipv4/ip_fragment.c b/net/ipv4/ip_fragment.c
+index c10a3ce5cbff..9ff497d17545 100644
+--- a/net/ipv4/ip_fragment.c
++++ b/net/ipv4/ip_fragment.c
+@@ -679,27 +679,30 @@ EXPORT_SYMBOL(ip_defrag);
+ struct sk_buff *ip_check_defrag(struct sk_buff *skb, u32 user)
+ {
+       struct iphdr iph;
++      int netoff;
+       u32 len;
+ 
+       if (skb->protocol != htons(ETH_P_IP))
+               return skb;
+ 
+-      if (!skb_copy_bits(skb, 0, &iph, sizeof(iph)))
++      netoff = skb_network_offset(skb);
++
++      if (skb_copy_bits(skb, netoff, &iph, sizeof(iph)) < 0)
+               return skb;
+ 
+       if (iph.ihl < 5 || iph.version != 4)
+               return skb;
+ 
+       len = ntohs(iph.tot_len);
+-      if (skb->len < len || len < (iph.ihl * 4))
++      if (skb->len < netoff + len || len < (iph.ihl * 4))
+               return skb;
+ 
+       if (ip_is_fragment(&iph)) {
+               skb = skb_share_check(skb, GFP_ATOMIC);
+               if (skb) {
+-                      if (!pskb_may_pull(skb, iph.ihl*4))
++                      if (!pskb_may_pull(skb, netoff + iph.ihl * 4))
+                               return skb;
+-                      if (pskb_trim_rcsum(skb, len))
++                      if (pskb_trim_rcsum(skb, netoff + len))
+                               return skb;
+                       memset(IPCB(skb), 0, sizeof(struct inet_skb_parm));
+                       if (ip_defrag(skb, user))
+diff --git a/net/ipv4/ip_output.c b/net/ipv4/ip_output.c
+index dd637fc4b553..05686c47a289 100644
+--- a/net/ipv4/ip_output.c
++++ b/net/ipv4/ip_output.c
+@@ -843,7 +843,8 @@ static int __ip_append_data(struct sock *sk,
+       cork->length += length;
+       if (((length > mtu) || (skb && skb_is_gso(skb))) &&
+           (sk->sk_protocol == IPPROTO_UDP) &&
+-          (rt->dst.dev->features & NETIF_F_UFO) && !rt->dst.header_len) {
++          (rt->dst.dev->features & NETIF_F_UFO) && !rt->dst.header_len &&
++          (sk->sk_type == SOCK_DGRAM)) {
+               err = ip_ufo_append_data(sk, queue, getfrag, from, length,
+                                        hh_len, fragheaderlen, transhdrlen,
+                                        maxfraglen, flags);
+diff --git a/net/ipv4/ping.c b/net/ipv4/ping.c
+index 04ce671430cb..b94002ab8052 100644
+--- a/net/ipv4/ping.c
++++ b/net/ipv4/ping.c
+@@ -259,6 +259,10 @@ int ping_init_sock(struct sock *sk)
+       kgid_t low, high;
+       int ret = 0;
+ 
++#if IS_ENABLED(CONFIG_IPV6)
++      if (sk->sk_family == AF_INET6)
++              inet6_sk(sk)->ipv6only = 1;
++#endif
+       inet_get_ping_group_range_net(net, &low, &high);
+       if (gid_lte(low, group) && gid_lte(group, high))
+               return 0;
+@@ -305,6 +309,11 @@ static int ping_check_bind_addr(struct sock *sk, struct 
inet_sock *isk,
+               if (addr_len < sizeof(*addr))
+                       return -EINVAL;
+ 
++              if (addr->sin_family != AF_INET &&
++                  !(addr->sin_family == AF_UNSPEC &&
++                    addr->sin_addr.s_addr == htonl(INADDR_ANY)))
++                      return -EAFNOSUPPORT;
++
+               pr_debug("ping_check_bind_addr(sk=%p,addr=%pI4,port=%d)\n",
+                        sk, &addr->sin_addr.s_addr, ntohs(addr->sin_port));
+ 
+@@ -330,7 +339,7 @@ static int ping_check_bind_addr(struct sock *sk, struct 
inet_sock *isk,
+                       return -EINVAL;
+ 
+               if (addr->sin6_family != AF_INET6)
+-                      return -EINVAL;
++                      return -EAFNOSUPPORT;
+ 
+               pr_debug("ping_check_bind_addr(sk=%p,addr=%pI6c,port=%d)\n",
+                        sk, addr->sin6_addr.s6_addr, ntohs(addr->sin6_port));
+@@ -716,7 +725,7 @@ static int ping_v4_sendmsg(struct kiocb *iocb, struct sock 
*sk, struct msghdr *m
+               if (msg->msg_namelen < sizeof(*usin))
+                       return -EINVAL;
+               if (usin->sin_family != AF_INET)
+-                      return -EINVAL;
++                      return -EAFNOSUPPORT;
+               daddr = usin->sin_addr.s_addr;
+               /* no remote port */
+       } else {
+diff --git a/net/ipv6/ip6_output.c b/net/ipv6/ip6_output.c
+index 12f7ef0f243a..d7907ecf0b75 100644
+--- a/net/ipv6/ip6_output.c
++++ b/net/ipv6/ip6_output.c
+@@ -1294,7 +1294,8 @@ emsgsize:
+       if (((length > mtu) ||
+            (skb && skb_is_gso(skb))) &&
+           (sk->sk_protocol == IPPROTO_UDP) &&
+-          (rt->dst.dev->features & NETIF_F_UFO)) {
++          (rt->dst.dev->features & NETIF_F_UFO) &&
++          (sk->sk_type == SOCK_DGRAM)) {
+               err = ip6_ufo_append_data(sk, getfrag, from, length,
+                                         hh_len, fragheaderlen,
+                                         transhdrlen, mtu, flags, rt);
+diff --git a/net/ipv6/ping.c b/net/ipv6/ping.c
+index bda74291c3e0..461199533fe4 100644
+--- a/net/ipv6/ping.c
++++ b/net/ipv6/ping.c
+@@ -103,9 +103,10 @@ int ping_v6_sendmsg(struct kiocb *iocb, struct sock *sk, 
struct msghdr *msg,
+ 
+       if (msg->msg_name) {
+               DECLARE_SOCKADDR(struct sockaddr_in6 *, u, msg->msg_name);
+-              if (msg->msg_namelen < sizeof(struct sockaddr_in6) ||
+-                  u->sin6_family != AF_INET6) {
++              if (msg->msg_namelen < sizeof(*u))
+                       return -EINVAL;
++              if (u->sin6_family != AF_INET6) {
++                      return -EAFNOSUPPORT;
+               }
+               if (sk->sk_bound_dev_if &&
+                   sk->sk_bound_dev_if != u->sin6_scope_id) {
+diff --git a/net/ipv6/route.c b/net/ipv6/route.c
+index 6f1b8503a431..3809ca234c69 100644
+--- a/net/ipv6/route.c
++++ b/net/ipv6/route.c
+@@ -141,7 +141,7 @@ static u32 *ipv6_cow_metrics(struct dst_entry *dst, 
unsigned long old)
+       u32 *p = NULL;
+ 
+       if (!(rt->dst.flags & DST_HOST))
+-              return NULL;
++              return dst_cow_metrics_generic(dst, old);
+ 
+       peer = rt6_get_peer_create(rt);
+       if (peer) {
+diff --git a/net/irda/ircomm/ircomm_tty.c b/net/irda/ircomm/ircomm_tty.c
+index 2ba8b9705bb7..fdcb9688b5d3 100644
+--- a/net/irda/ircomm/ircomm_tty.c
++++ b/net/irda/ircomm/ircomm_tty.c
+@@ -818,7 +818,9 @@ static void ircomm_tty_wait_until_sent(struct tty_struct 
*tty, int timeout)
+       orig_jiffies = jiffies;
+ 
+       /* Set poll time to 200 ms */
+-      poll_time = IRDA_MIN(timeout, msecs_to_jiffies(200));
++      poll_time = msecs_to_jiffies(200);
++      if (timeout)
++              poll_time = min_t(unsigned long, timeout, poll_time);
+ 
+       spin_lock_irqsave(&self->spinlock, flags);
+       while (self->tx_skb && self->tx_skb->len) {
+diff --git a/net/mac80211/tx.c b/net/mac80211/tx.c
+index e5a7ac2f3687..dca076f6252c 100644
+--- a/net/mac80211/tx.c
++++ b/net/mac80211/tx.c
+@@ -562,6 +562,7 @@ ieee80211_tx_h_check_control_port_protocol(struct 
ieee80211_tx_data *tx)
+               if (tx->sdata->control_port_no_encrypt)
+                       info->flags |= IEEE80211_TX_INTFL_DONT_ENCRYPT;
+               info->control.flags |= IEEE80211_TX_CTRL_PORT_CTRL_PROTO;
++              info->flags |= IEEE80211_TX_CTL_USE_MINRATE;
+       }
+ 
+       return TX_CONTINUE;
+diff --git a/net/sched/ematch.c b/net/sched/ematch.c
+index 3a633debb6df..a2abc449ce8f 100644
+--- a/net/sched/ematch.c
++++ b/net/sched/ematch.c
+@@ -227,6 +227,7 @@ static int tcf_em_validate(struct tcf_proto *tp,
+                                * to replay the request.
+                                */
+                               module_put(em->ops->owner);
++                              em->ops = NULL;
+                               err = -EAGAIN;
+                       }
+ #endif
+diff --git a/net/sunrpc/cache.c b/net/sunrpc/cache.c
+index ae333c1845bb..0adc66caae2f 100644
+--- a/net/sunrpc/cache.c
++++ b/net/sunrpc/cache.c
+@@ -920,7 +920,7 @@ static unsigned int cache_poll(struct file *filp, 
poll_table *wait,
+       poll_wait(filp, &queue_wait, wait);
+ 
+       /* alway allow write */
+-      mask = POLL_OUT | POLLWRNORM;
++      mask = POLLOUT | POLLWRNORM;
+ 
+       if (!rp)
+               return mask;
+diff --git a/sound/core/pcm_native.c b/sound/core/pcm_native.c
+index 566b0f69d628..ee2405723188 100644
+--- a/sound/core/pcm_native.c
++++ b/sound/core/pcm_native.c
+@@ -1404,6 +1404,8 @@ static int snd_pcm_do_drain_init(struct 
snd_pcm_substream *substream, int state)
+                       if (! snd_pcm_playback_empty(substream)) {
+                               snd_pcm_do_start(substream, 
SNDRV_PCM_STATE_DRAINING);
+                               snd_pcm_post_start(substream, 
SNDRV_PCM_STATE_DRAINING);
++                      } else {
++                              runtime->status->state = SNDRV_PCM_STATE_SETUP;
+                       }
+                       break;
+               case SNDRV_PCM_STATE_RUNNING:
+diff --git a/sound/pci/hda/hda_intel.c b/sound/pci/hda/hda_intel.c
+index 103e85a13f35..2f3059b50ffa 100644
+--- a/sound/pci/hda/hda_intel.c
++++ b/sound/pci/hda/hda_intel.c
+@@ -3984,7 +3984,7 @@ static DEFINE_PCI_DEVICE_TABLE(azx_ids) = {
+         .driver_data = AZX_DRIVER_PCH | AZX_DCAPS_INTEL_PCH_NOPM },
+       /* Panther Point */
+       { PCI_DEVICE(0x8086, 0x1e20),
+-        .driver_data = AZX_DRIVER_PCH | AZX_DCAPS_INTEL_PCH },
++        .driver_data = AZX_DRIVER_PCH | AZX_DCAPS_INTEL_PCH_NOPM },
+       /* Lynx Point */
+       { PCI_DEVICE(0x8086, 0x8c20),
+         .driver_data = AZX_DRIVER_PCH | AZX_DCAPS_INTEL_PCH },
+diff --git a/sound/pci/hda/patch_sigmatel.c b/sound/pci/hda/patch_sigmatel.c
+index 12f28d7e0fdc..231b26471a63 100644
+--- a/sound/pci/hda/patch_sigmatel.c
++++ b/sound/pci/hda/patch_sigmatel.c
+@@ -85,6 +85,7 @@ enum {
+       STAC_ALIENWARE_M17X,
+       STAC_92HD89XX_HP_FRONT_JACK,
+       STAC_92HD89XX_HP_Z1_G2_RIGHT_MIC_JACK,
++      STAC_92HD73XX_ASUS_MOBO,
+       STAC_92HD73XX_MODELS
+ };
+ 
+@@ -1935,7 +1936,18 @@ static const struct hda_fixup stac92hd73xx_fixups[] = {
+       [STAC_92HD89XX_HP_Z1_G2_RIGHT_MIC_JACK] = {
+               .type = HDA_FIXUP_PINS,
+               .v.pins = stac92hd89xx_hp_z1_g2_right_mic_jack_pin_configs,
+-      }
++      },
++      [STAC_92HD73XX_ASUS_MOBO] = {
++              .type = HDA_FIXUP_PINS,
++              .v.pins = (const struct hda_pintbl[]) {
++                      /* enable 5.1 and SPDIF out */
++                      { 0x0c, 0x01014411 },
++                      { 0x0d, 0x01014410 },
++                      { 0x0e, 0x01014412 },
++                      { 0x22, 0x014b1180 },
++                      { }
++              }
++      },
+ };
+ 
+ static const struct hda_model_fixup stac92hd73xx_models[] = {
+@@ -1947,6 +1959,7 @@ static const struct hda_model_fixup 
stac92hd73xx_models[] = {
+       { .id = STAC_DELL_M6_BOTH, .name = "dell-m6" },
+       { .id = STAC_DELL_EQ, .name = "dell-eq" },
+       { .id = STAC_ALIENWARE_M17X, .name = "alienware" },
++      { .id = STAC_92HD73XX_ASUS_MOBO, .name = "asus-mobo" },
+       {}
+ };
+ 
+@@ -1999,6 +2012,8 @@ static const struct snd_pci_quirk 
stac92hd73xx_fixup_tbl[] = {
+                               "HP Z1 G2", 
STAC_92HD89XX_HP_Z1_G2_RIGHT_MIC_JACK),
+       SND_PCI_QUIRK(PCI_VENDOR_ID_HP, 0x2b17,
+                               "unknown HP", STAC_92HD89XX_HP_FRONT_JACK),
++      SND_PCI_QUIRK(PCI_VENDOR_ID_ASUSTEK, 0x83f8, "ASUS AT4NM10",
++                    STAC_92HD73XX_ASUS_MOBO),
+       {} /* terminator */
+ };
+ 
+diff --git a/sound/soc/omap/omap-pcm.c b/sound/soc/omap/omap-pcm.c
+index 07b8b7bc9d20..81f6a7545ef5 100644
+--- a/sound/soc/omap/omap-pcm.c
++++ b/sound/soc/omap/omap-pcm.c
+@@ -200,7 +200,7 @@ static int omap_pcm_new(struct snd_soc_pcm_runtime *rtd)
+       struct snd_pcm *pcm = rtd->pcm;
+       int ret;
+ 
+-      ret = dma_coerce_mask_and_coherent(card->dev, DMA_BIT_MASK(64));
++      ret = dma_coerce_mask_and_coherent(card->dev, DMA_BIT_MASK(32));
+       if (ret)
+               return ret;
+ 

Reply via email to