+linux (4.15.0-56.62) bionic; urgency=medium
+
+ * bionic/linux: 4.15.0-56.62 -proposed tracker (LP: #1837626)
+
+ * Packaging resync (LP: #1786013)
+ - [Packaging] resync git-ubuntu-log
+ - [Packaging] update helper scripts
+
+ * CVE-2019-2101
+ - media: uvcvideo: Fix 'type' check leading to overflow
+
+ * hibmc-drm Causes Unreadable Display for Huawei amd64 Servers (LP: #1762940)
+ - [Config] Set CONFIG_DRM_HISI_HIBMC to arm64 only
+ - SAUCE: Make CONFIG_DRM_HISI_HIBMC depend on ARM64
+
+ * Bionic: support for Solarflare X2542 network adapter (sfc driver)
+ (LP: #1836635)
+ - sfc: make mem_bar a function rather than a constant
+ - sfc: support VI strides other than 8k
+ - sfc: add Medford2 (SFC9250) PCI Device IDs
+ - sfc: improve PTP error reporting
+ - sfc: update EF10 register definitions
+ - sfc: populate the timer reload field
+ - sfc: update MCDI protocol headers
+ - sfc: support variable number of MAC stats
+ - sfc: expose FEC stats on Medford2
+ - sfc: expose CTPIO stats on NICs that support them
+ - sfc: basic MCDI mapping of 25/50/100G link speeds
+ - sfc: support the ethtool ksettings API properly so that 25/50/100G works
+ - sfc: add bits for 25/50/100G supported/advertised speeds
+ - sfc: remove tx and MCDI handling from NAPI budget consideration
+ - sfc: handle TX timestamps in the normal data path
+ - sfc: add function to determine which TX timestamping method to use
+ - sfc: use main datapath for HW timestamps if available
+ - sfc: only enable TX timestamping if the adapter is licensed for it
+ - sfc: MAC TX timestamp handling on the 8000 series
+ - sfc: on 8000 series use TX queues for TX timestamps
+ - sfc: only advertise TX timestamping if we have the license for it
+ - sfc: simplify RX datapath timestamping
+ - sfc: support separate PTP and general timestamping
+ - sfc: support second + quarter ns time format for receive datapath
+ - sfc: support Medford2 frequency adjustment format
+ - sfc: add suffix to large constant in ptp
+ - sfc: mark some unexported symbols as static
+ - sfc: update MCDI protocol headers
+ - sfc: support FEC configuration through ethtool
+ - sfc: remove ctpio_dmabuf_start from stats
+ - sfc: stop the TX queue before pushing new buffers
+
+ * [18.04 FEAT] zKVM: Add hardware CPU Model - kernel part (LP: #1836153)
+ - KVM: s390: add debug logging for cpu model subfunctions
+ - KVM: s390: implement subfunction processor calls
+ - KVM: s390: add vector enhancements facility 2 to cpumodel
+ - KVM: s390: add vector BCD enhancements facility to cpumodel
+ - KVM: s390: add MSA9 to cpumodel
+ - KVM: s390: provide query function for instructions returning 32 byte
+ - KVM: s390: add enhanced sort facilty to cpu model
+ - KVM: s390: add deflate conversion facilty to cpu model
+ - KVM: s390: enable MSA9 keywrapping functions depending on cpu model
+
+ * Intel ethernet I219 has slow RX speed (LP: #1836152)
+ - SAUCE: e1000e: add workaround for possible stalled packet
+ - SAUCE: e1000e: disable force K1-off feature
+
+ * Intel ethernet I219 may wrongly detect connection speed as 10Mbps
+ (LP: #1836177)
+ - SAUCE: e1000e: Make watchdog use delayed work
+
+ * Unhide Nvidia HDA audio controller (LP: #1836308)
+ - PCI: Enable NVIDIA HDA controllers
+
+ * selftests: Remove broken Power9 paste tests and fix compilation issue
+ (LP: #1836715)
+ - selftests/powerpc: Remove Power9 paste tests
+ - selftests/powerpc: Fix Makefiles for headers_install change
+
+ * ixgbe{vf} - Physical Function gets IRQ when VF checks link state
+ (LP: #1836760)
+ - ixgbevf: Use cached link state instead of re-reading the value for ethtool
+
+ * Fix nf_conntrack races when dealing with same origin requests in NAT
+ environments (LP: #1836816)
+ - netfilter: nf_conntrack: resolve clash for matching conntracks
+ - netfilter: nf_nat: skip nat clash resolution for same-origin entries
+
+ * CVE-2018-5383
+ - crypto: ecdh - add public key verification test
+
+ * sched: Prevent CPU lockups when task groups take longer than the period
+ (LP: #1836971)
+ - sched/fair: Limit sched_cfs_period_timer() loop to avoid hard lockup
+
+ * depmod may prefer unsigned l-r-m nvidia modules to signed modules
+ (LP: #1834479)
+ - [Packaging] dkms-build--nvidia-N -- clean up unsigned ko files
+ - [Packaging] Add update-version-dkms
+ - update dkms package versions
+
+ * Build Nvidia drivers in conjunction with kernel (LP: #1764792) // zfs/spl
+ build in conjunction with the kernel from DKMS source (LP: #1807378)
+ - [Packaging] dkms-build--nvidia-* -- convert to generic -N form
+
+ * zfs/spl build in conjunction with the kernel from DKMS source (LP: #1807378)
+ - [Packaging] dkms -- dkms package build packaging support
+ - [Packaging] dkms -- build zfs/spl packages
+ - [Packaging] dkms -- drop zfs/spl source code from kernel
+
+ * Build Nvidia drivers in conjunction with kernel (LP: #1764792)
+ - [Packaging] dkms -- introduce dkms package versions
+ - [Packaging] dkms -- add per package post-process step
+ - [Packaging] dkms -- switch to a consistent build prefix length and strip
+ - [Packaging] dkms-build -- support building against packages in PPAs
+ - [Packaging] dkms-build: do not redownload files on subsequent passes
+ - [Packaging] dkms-build -- add support for unversioned overrides
+ - [Packaging] dkms-build -- backport latest version from disco
+ - [Packaging] nvidia -- build and sign nvidia packages and ship signatures
+ - [Packaging] nvidia -- make nvidia package version explicit
+
+ * CVE-2019-13233
+ - x86/insn-eval: Fix use-after-free access to LDT entry
+
+ * kernel panic using CIFS share in smb2_push_mandatory_locks() (LP: #1795659)
+ - CIFS: keep FileInfo handle live during oplock break
+
+ * cifs set_oplock buffer overflow in strcat (LP: #1824981)
+ - cifs: fix strcat buffer overflow and reduce raciness in
+ smb21_set_oplock_level()
+
+ * CVE-2019-13272
+ - ptrace: Fix ->ptracer_cred handling for PTRACE_TRACEME
+
+ * Bionic update: upstream stable patchset 2019-07-18 (LP: #1837161)
+ - Kbuild: suppress packed-not-aligned warning for default setting only
+ - disable stringop truncation warnings for now
+ - test_hexdump: use memcpy instead of strncpy
+ - kobject: Replace strncpy with memcpy
+ - ALSA: intel_hdmi: Use strlcpy() instead of strncpy()
+ - unifdef: use memcpy instead of strncpy
+ - kernfs: Replace strncpy with memcpy
+ - ip_tunnel: Fix name string concatenate in __ip_tunnel_create()
+ - scsi: bfa: convert to strlcpy/strlcat
+ - kdb: use memmove instead of overlapping memcpy
+ - iser: set sector for ambiguous mr status errors
+ - uprobes: Fix handle_swbp() vs. unregister() + register() race once more
+ - MIPS: ralink: Fix mt7620 nd_sd pinmux
+ - mips: fix mips_get_syscall_arg o32 check
+ - IB/mlx5: Avoid load failure due to unknown link width
+ - drm/ast: Fix incorrect free on ioregs
+ - drm: set is_master to 0 upon drm_new_set_master() failure
+ - drm/meson: Enable fast_io in meson_dw_hdmi_regmap_config
+ - drm/meson: Fix OOB memory accesses in meson_viu_set_osd_lut()
+ - ALSA: trident: Suppress gcc string warning
+ - kgdboc: Fix restrict error
+ - kgdboc: Fix warning with module build
+ - svm: Add mutex_lock to protect apic_access_page_done on AMD systems
+ - drm/msm: fix OF child-node lookup
+ - Input: xpad - quirk all PDP Xbox One gamepads
+ - Input: synaptics - add PNP ID for ThinkPad P50 to SMBus
+ - Input: matrix_keypad - check for errors from of_get_named_gpio()
+ - Input: cros_ec_keyb - fix button/switch capability reports
+ - Input: elan_i2c - add ELAN0620 to the ACPI table
+ - Input: elan_i2c - add ACPI ID for Lenovo IdeaPad 330-15ARR
+ - Input: elan_i2c - add support for ELAN0621 touchpad
+ - btrfs: tree-checker: Don't check max block group size as current max chunk
+ size limit is unreliable
+ - ARC: change defconfig defaults to ARCv2
+ - arc: [devboards] Add support of NFSv3 ACL
+ - reset: make device_reset_optional() really optional
+ - reset: remove remaining WARN_ON() in <linux/reset.h>
+ - mm: hide incomplete nr_indirectly_reclaimable in /proc/zoneinfo
+ - net: qed: use correct strncpy() size
+ - tipc: use destination length for copy string
+ - arm64: ftrace: Fix to enable syscall events on arm64
+ - sched, trace: Fix prev_state output in sched_switch tracepoint
+ - tracing/fgraph: Fix set_graph_function from showing interrupts
+ - drm/meson: Fixes for drm_crtc_vblank_on/off support
+ - scsi: lpfc: fix block guard enablement on SLI3 adapters
+ - media: omap3isp: Unregister media device as first
+ - iommu/vt-d: Fix NULL pointer dereference in prq_event_thread()
+ - brcmutil: really fix decoding channel info for 160 MHz bandwidth
+ - iommu/ipmmu-vmsa: Fix crash on early domain free
+ - can: rcar_can: Fix erroneous registration
+ - test_firmware: fix error return getting clobbered
+ - HID: input: Ignore battery reported by Symbol DS4308
+ - batman-adv: Use explicit tvlv padding for ELP packets
+ - batman-adv: Expand merged fragment buffer for full packet
+ - amd/iommu: Fix Guest Virtual APIC Log Tail Address Register
+ - bnx2x: Assign unique DMAE channel number for FW DMAE transactions.
+ - qed: Fix PTT leak in qed_drain()
+ - qed: Fix reading wrong value in loop condition
+ - net/mlx4_core: Zero out lkey field in SW2HW_MPT fw command
+ - net/mlx4_core: Fix uninitialized variable compilation warning
+ - net/mlx4: Fix UBSAN warning of signed integer overflow
+ - gpio: mockup: fix indicated direction
+ - mtd: rawnand: qcom: Namespace prefix some commands
+ - mtd: spi-nor: Fix Cadence QSPI page fault kernel panic
+ - qed: Fix bitmap_weight() check
+ - qed: Fix QM getters to always return a valid pq
+ - net: faraday: ftmac100: remove netif_running(netdev) check before disabling
+ interrupts
+ - iommu/vt-d: Use memunmap to free memremap
+ - flexfiles: use per-mirror specified stateid for IO
+ - ibmvnic: Fix RX queue buffer cleanup
+ - team: no need to do team_notify_peers or team_mcast_rejoin when disabling
+ port
+ - net: amd: add missing of_node_put()
+ - usb: quirk: add no-LPM quirk on SanDisk Ultra Flair device
+ - usb: appledisplay: Add 27" Apple Cinema Display
+ - USB: check usb_get_extra_descriptor for proper size
+ - ALSA: hda: Add support for AMD Stoney Ridge
+ - ALSA: pcm: Fix starvation on down_write_nonblock()
+ - ALSA: pcm: Call snd_pcm_unlink() conditionally at closing
+ - ALSA: pcm: Fix interval evaluation with openmin/max
+ - ALSA: hda/realtek - Fix speaker output regression on Thinkpad T570
+ - SUNRPC: Fix leak of krb5p encode pages
+ - dmaengine: dw: Fix FIFO size for Intel Merrifield
+ - dmaengine: cppi41: delete channel from pending list when stop channel
+ - ARM: 8806/1: kprobes: Fix false positive with FORTIFY_SOURCE
+ - xhci: Prevent U1/U2 link pm states if exit latency is too long
+ - f2fs: fix to do sanity check with block address in main area v2
+ - swiotlb: clean up reporting
+ - Staging: lustre: remove two build warnings
+ - staging: atomisp: remove "fun" strncpy warning
+ - cifs: Fix separator when building path from dentry
+ - staging: rtl8712: Fix possible buffer overrun
+ - Revert commit ef9209b642f "staging: rtl8723bs: Fix indenting errors and an
+ off-by-one mistake in core/rtw_mlme_ext.c"
+ - drm/amdgpu: update mc firmware image for polaris12 variants
+ - drm/amdgpu/gmc8: update MC firmware for polaris
+ - tty: serial: 8250_mtk: always resume the device in probe.
+ - kgdboc: fix KASAN global-out-of-bounds bug in param_set_kgdboc_var()
+ - libnvdimm, pfn: Pad pfn namespaces relative to other regions
+ - mac80211: Clear beacon_int in ieee80211_do_stop
+ - mac80211: ignore tx status for PS stations in ieee80211_tx_status_ext
+ - mac80211: fix reordering of buffered broadcast packets
+ - mac80211: ignore NullFunc frames in the duplicate detection
+ - qed: Fix rdma_info structure allocation
+ - drm/amdgpu: Add amdgpu "max bpc" connector property (v2)
+ - drivers/net/ethernet/qlogic/qed/qed_rdma.h: fix typo
+ - gpio: pxa: fix legacy non pinctrl aware builds again
+ - tc-testing: tdc.py: ignore errors when decoding stdout/stderr
+ - NFSv4: Fix a NFSv4 state manager deadlock
+ - USB: serial: console: fix reported terminal settings
+ - ALSA: usb-audio: Add SMSL D1 to quirks for native DSD support
+ - ALSA: hda/realtek: ALC286 mic and headset-mode fixups for Acer Aspire
+ U27-880
+ - ALSA: hda/realtek - Add support for Acer Aspire C24-860 headset mic
+ - ALSA: hda/realtek: Fix mic issue on Acer AIO Veriton Z4660G
+ - ALSA: hda/realtek: Fix mic issue on Acer AIO Veriton Z4860G/Z6860G
+ - media: dvb-pll: don't re-validate tuner frequencies
+ - parisc: Enable -ffunction-sections for modules on 32-bit kernel
+ - Revert "x86/e820: put !E820_TYPE_RAM regions into memblock.reserved"
+ - drm/lease: Send a distinct uevent
+ - drm/msm: Move fence put to where failure occurs
+ - drm/amdgpu/gmc8: always load MC firmware in the driver
+ - drm/i915: Downgrade Gen9 Plane WM latency error
+ - x86/efi: Allocate e820 buffer before calling efi_exit_boot_service
+ - cfg80211: Fix busy loop regression in ieee80211_ie_split_ric()
+ - ipv4: ipv6: netfilter: Adjust the frag mem limit when truesize changes
+ - ipv6: Check available headroom in ip6_xmit() even without options
+ - neighbour: Avoid writing before skb->head in neigh_hh_output()
+ - ipv6: sr: properly initialize flowi6 prior passing to ip6_route_output
+ - net: 8139cp: fix a BUG triggered by changing mtu with network traffic
+ - net/mlx4_core: Correctly set PFC param if global pause is turned off.
+ - net/mlx4_en: Change min MTU size to ETH_MIN_MTU
+ - net: phy: don't allow __set_phy_supported to add unsupported modes
+ - net: Prevent invalid access to skb->prev in __qdisc_drop_all
+ - rtnetlink: ndo_dflt_fdb_dump() only work for ARPHRD_ETHER devices
+ - sctp: kfree_rcu asoc
+ - tcp: Do not underestimate rwnd_limited
+ - tcp: fix NULL ref in tail loss probe
+ - tun: forbid iface creation with rtnl ops
+ - virtio-net: keep vnet header zeroed after processing XDP
+ - ARM: OMAP2+: prm44xx: Fix section annotation on
+ omap44xx_prm_enable_io_wakeup
+ - ASoC: rsnd: fixup clock start checker
+ - staging: rtl8723bs: Fix the return value in case of error in
+ 'rtw_wx_read32()'
+ - ARM: dts: logicpd-somlv: Fix interrupt on mmc3_dat1
+ - ARM: OMAP1: ams-delta: Fix possible use of uninitialized field
+ - sysv: return 'err' instead of 0 in __sysv_write_inode
+ - selftests: add script to stress-test nft packet path vs. control plane
+ - netfilter: nf_tables: fix use-after-free when deleting compat expressions
+ - hwmon (ina2xx) Fix NULL id pointer in probe()
+ - ASoC: wm_adsp: Fix dma-unsafe read of scratch registers
+ - s390/cpum_cf: Reject request for sampling in event initialization
+ - hwmon: (ina2xx) Fix current value calculation
+ - ASoC: omap-abe-twl6040: Fix missing audio card caused by deferred probing
+ - ASoC: dapm: Recalculate audio map forcely when card instantiated
+ - netfilter: xt_hashlimit: fix a possible memory leak in htable_create()
+ - hwmon: (w83795) temp4_type has writable permission
+ - perf tools: Restore proper cwd on return from mnt namespace
+ - PCI: imx6: Fix link training status detection in link up check
+ - objtool: Fix double-free in .cold detection error path
+ - objtool: Fix segfault in .cold detection with -ffunction-sections
+ - ARM: dts: at91: sama5d2: use the divided clock for SMC
+ - Btrfs: send, fix infinite loop due to directory rename dependencies
+ - RDMA/mlx5: Fix fence type for IB_WR_LOCAL_INV WR
+ - RDMA/rdmavt: Fix rvt_create_ah function signature
+ - ASoC: omap-mcbsp: Fix latency value calculation for pm_qos
+ - ASoC: omap-mcpdm: Add pm_qos handling to avoid under/overruns with CPU_IDLE
+ - ASoC: omap-dmic: Add pm_qos handling to avoid overruns with CPU_IDLE
+ - exportfs: do not read dentry after free
+ - bpf: fix check of allowed specifiers in bpf_trace_printk
+ - ipvs: call ip_vs_dst_notifier earlier than ipv6_dev_notf
+ - USB: omap_udc: use devm_request_irq()
+ - USB: omap_udc: fix crashes on probe error and module removal
+ - USB: omap_udc: fix omap_udc_start() on 15xx machines
+ - USB: omap_udc: fix USB gadget functionality on Palm Tungsten E
+ - USB: omap_udc: fix rejection of out transfers when DMA is used
+ - drm/meson: add support for 1080p25 mode
+ - netfilter: ipv6: Preserve link scope traffic original oif
+ - IB/mlx5: Fix page fault handling for MW
+ - KVM: x86: fix empty-body warnings
+ - x86/kvm/vmx: fix old-style function declaration
+ - net: thunderx: fix NULL pointer dereference in nic_remove
+ - usb: gadget: u_ether: fix unsafe list iteration
+ - netfilter: nf_tables: deactivate expressions in rule replecement routine
+ - igb: fix uninitialized variables
+ - ixgbe: recognize 1000BaseLX SFP modules as 1Gbps
+ - net: hisilicon: remove unexpected free_netdev
+ - drm/amdgpu: Add delay after enable RLC ucode
+ - drm/ast: fixed reading monitor EDID not stable issue
+ - xen: xlate_mmu: add missing header to fix 'W=1' warning
+ - Revert "xen/balloon: Mark unallocated host memory as UNUSABLE"
+ - pstore/ram: Correctly calculate usable PRZ bytes
+ - fscache, cachefiles: remove redundant variable 'cache'
+ - nvme: flush namespace scanning work just before removing namespaces
+ - ACPI/IORT: Fix iort_get_platform_device_domain() uninitialized pointer value
+ - ocfs2: fix deadlock caused by ocfs2_defrag_extent()
+ - mm/page_alloc.c: fix calculation of pgdat->nr_zones
+ - hfs: do not free node before using
+ - hfsplus: do not free node before using
+ - debugobjects: avoid recursive calls with kmemleak
+ - ocfs2: fix potential use after free
+ - printk: Add console owner and waiter logic to load balance console writes
+ - printk: Hide console waiter logic into helpers
+ - printk: Never set console_may_schedule in console_trylock()
+ - printk: Wake klogd when passing console_lock owner
+ - flexfiles: enforce per-mirror stateid only for v4 DSes
+ - staging: speakup: Replace strncpy with memcpy
+ - ALSA: fireface: fix reference to wrong register for clock configuration
+ - IB/hfi1: Fix an out-of-bounds access in get_hw_stats
+ - tcp: lack of available data can also cause TSO defer
+ - Revert "net/ibm/emac: wrong bit is used for STA control"
+ - tools: bpftool: prevent infinite loop in get_fdinfo()
+ - ASoC: sun8i-codec: fix crash on module removal
+ - ASoC: acpi: fix: continue searching when machine is ignored
+ - RDMA/bnxt_re: Fix system hang when registration with L2 driver fails
+ - RDMA/bnxt_re: Avoid accessing the device structure after it is freed
+ - RDMA/hns: Bugfix pbl configuration for rereg mr
+ - thunderbolt: Prevent root port runtime suspend during NVM upgrade
+ - netfilter: add missing error handling code for register functions
+ - netfilter: nat: fix double register in masquerade modules
+ - cachefiles: Fix an assertion failure when trying to update a failed object
+ - fscache: Fix race in fscache_op_complete() due to split atomic_sub & read
+ - pvcalls-front: fixes incorrect error handling
+ - nvme: warn when finding multi-port subsystems without multipathing enabled
+ - kernel/kcov.c: mark funcs in __sanitizer_cov_trace_pc() as notrace
+ - ALSA: hda/realtek: ALC294 mic and headset-mode fixups for ASUS X542UN
+ - ALSA: hda/realtek: Enable audio jacks of ASUS UX533FD with ALC294
+ - ALSA: hda/realtek: Enable audio jacks of ASUS UX433FN/UX333FA with ALC294
+
+ * Bionic update: upstream stable patchset 2019-07-17 (LP: #1836968)
+ - flow_dissector: do not dissect l4 ports for fragments
+ - ibmvnic: fix accelerated VLAN handling
+ - ip_tunnel: don't force DF when MTU is locked
+ - ipv6: Fix PMTU updates for UDP/raw sockets in presence of VRF
+ - net-gro: reset skb->pkt_type in napi_reuse_skb()
+ - sctp: not allow to set asoc prsctp_enable by sockopt
+ - tg3: Add PHY reset for 5717/5719/5720 in change ring and flow control paths
+ - tuntap: fix multiqueue rx
+ - net: systemport: Protect stop from timeout
+ - net: qualcomm: rmnet: Fix incorrect assignment of real_dev
+ - net: dsa: microchip: initialize mutex before use
+ - sctp: fix strchange_flags name for Stream Change Event
+ - net: phy: mdio-gpio: Fix working over slow can_sleep GPIOs
+ - sctp: not increase stream's incnt before sending addstrm_in request
+ - mlxsw: spectrum: Fix IP2ME CPU policer configuration
+ - net: smsc95xx: Fix MTU range
+ - usbnet: smsc95xx: disable carrier check while suspending
+ - inet: frags: better deal with smp races
+ - ARM: dts: r8a7791: Correct critical CPU temperature
+ - ARM: dts: r8a7793: Correct critical CPU temperature
+ - net: bcmgenet: protect stop from timeout
+ - tcp: Fix SOF_TIMESTAMPING_RX_HARDWARE to use the latest timestamp during TCP
+ coalescing
+ - tipc: don't assume linear buffer when reading ancillary data
+ - tipc: fix link re-establish failure
+ - net/mlx5e: Claim TC hw offloads support only under a proper build config
+ - net/mlx5e: Adjust to max number of channles when re-attaching
+ - net/mlx5e: Fix selftest for small MTUs
+ - l2tp: fix a sock refcnt leak in l2tp_tunnel_register
+ - net/mlx5e: IPoIB, Reset QP after channels are closed
+ - net: dsa: mv88e6xxx: Fix clearing of stats counters
+ - net: phy: realtek: fix RTL8201F sysfs name
+ - sctp: define SCTP_SS_DEFAULT for Stream schedulers
+ - rxrpc: Fix lockup due to no error backoff after ack transmit error
+ - cifs: don't dereference smb_file_target before null check
+ - cifs: fix return value for cifs_listxattr
+ - arm64: kprobe: make page to RO mode when allocate it
+ - ixgbe: fix MAC anti-spoofing filter after VFLR
+ - reiserfs: propagate errors from fill_with_dentries() properly
+ - hfs: prevent btree data loss on root split
+ - hfsplus: prevent btree data loss on root split
+ - um: Give start_idle_thread() a return code
+ - drm/edid: Add 6 bpc quirk for BOE panel.
+ - platform/x86: intel_telemetry: report debugfs failure
+ - clk: fixed-rate: fix of_node_get-put imbalance
+ - perf symbols: Set PLT entry/header sizes properly on Sparc
+ - fs/exofs: fix potential memory leak in mount option parsing
+ - clk: samsung: exynos5420: Enable PERIS clocks for suspend
+ - apparmor: Fix uninitialized value in aa_split_fqname
+ - x86/earlyprintk: Add a force option for pciserial device
+ - platform/x86: acerhdf: Add BIOS entry for Gateway LT31 v1.3307
+ - arm64: percpu: Initialize ret in the default case
+ - s390/vdso: add missing FORCE to build targets
+ - netfilter: ipset: list:set: Decrease refcount synchronously on deletion and
+ replace
+ - netfilter: ipset: actually allow allowable CIDR 0 in hash:net,port,net
+ - s390/mm: Fix ERROR: "__node_distance" undefined!
+ - netfilter: ipset: Correct rcu_dereference() call in ip_set_put_comment()
+ - netfilter: xt_IDLETIMER: add sysfs filename checking routine
+ - s390/qeth: fix HiperSockets sniffer
+ - hwmon: (ibmpowernv) Remove bogus __init annotations
+ - Revert "drm/exynos/decon5433: implement frame counter"
+ - clk: fixed-factor: fix of_node_get-put imbalance
+ - lib/raid6: Fix arm64 test build
+ - s390/perf: Change CPUM_CF return code in event init function
+ - sched/core: Take the hotplug lock in sched_init_smp()
+ - i40e: restore NETIF_F_GSO_IPXIP[46] to netdev features
+ - qed: Fix memory/entry leak in qed_init_sp_request()
+ - qed: Fix blocking/unlimited SPQ entries leak
+ - qed: Fix potential memory corruption
+ - net: stmmac: Fix RX packet size > 8191
+ - SUNRPC: drop pointless static qualifier in xdr_get_next_encode_buffer()
+ - ACPI / watchdog: Prefer iTCO_wdt always when WDAT table uses RTC SRAM
+ - perf machine: Add machine__is() to identify machine arch
+ - perf tools: Fix kernel_start for PTI on x86
+ - perf machine: Add nr_cpus_avail()
+ - perf machine: Workaround missing maps for x86 PTI entry trampolines
+ - perf test code-reading: Fix perf_env setup for PTI entry trampolines
+ - media: v4l: event: Add subscription to list before calling "add" operation
+ - MIPS: OCTEON: cavium_octeon_defconfig: re-enable OCTEON USB driver
+ - uio: Fix an Oops on load
+ - usb: cdc-acm: add entry for Hiro (Conexant) modem
+ - usb: quirks: Add delay-init quirk for Corsair K70 LUX RGB
+ - misc: atmel-ssc: Fix section annotation on atmel_ssc_get_driver_data
+ - USB: misc: appledisplay: add 20" Apple Cinema Display
+ - ACPI / platform: Add SMB0001 HID to forbidden_id_list
+ - HID: uhid: forbid UHID_CREATE under KERNEL_DS or elevated privileges
+ - libceph: fall back to sendmsg for slab pages
+ - drm/i915: Replace some PAGE_SIZE with I915_GTT_PAGE_SIZE
+ - perf unwind: Take pgoff into account when reporting elf to libdwfl
+ - netfilter: bridge: define INT_MIN & INT_MAX in userspace
+ - s390/decompressor: add missing FORCE to build targets
+ - Revert "HID: add NOGET quirk for Eaton Ellipse MAX UPS"
+ - HID: alps: allow incoming reports when only the trackstick is opened
+ - s390/mm: fix mis-accounting of pgtable_bytes
+ - drm/amd/display: Stop leaking planes
+ - drm/amd/amdgpu/dm: Fix dm_dp_create_fake_mst_encoder()
+ - ceph: quota: fix null pointer dereference in quota check
+ - nvme: make sure ns head inherits underlying device limits
+ - i2c: omap: Enable for ARCH_K3
+ - net: aquantia: fix potential IOMMU fault after driver unbind
+ - net: aquantia: fixed enable unicast on 32 macvlan
+ - net: aquantia: invalid checksumm offload implementation
+ - mtd: rawnand: atmel: fix OF child-node lookup
+ - efi/libstub: arm: support building with clang
+ - ARM: 8766/1: drop no-thumb-interwork in EABI mode
+ - ARM: 8767/1: add support for building ARM kernel with clang
+ - bus: arm-cci: remove unnecessary unreachable()
+ - ARM: trusted_foundations: do not use naked function
+ - usb: core: Fix hub port connection events lost
+ - usb: dwc3: gadget: fix ISOC TRB type on unaligned transfers
+ - usb: dwc3: gadget: Properly check last unaligned/zero chain TRB
+ - usb: dwc3: core: Clean up ULPI device
+ - xhci: Add check for invalid byte size error when UAS devices are connected.
+ - ALSA: oss: Use kvzalloc() for local buffer allocations
+ - MAINTAINERS: Add Sasha as a stable branch maintainer
+ - mmc: sdhci-pci: Try "cd" for card-detect lookup before using NULL
+ - gpio: don't free unallocated ida on gpiochip_add_data_with_key() error path
+ - iwlwifi: mvm: support sta_statistics() even on older firmware
+ - iwlwifi: mvm: fix regulatory domain update when the firmware starts
+ - iwlwifi: mvm: don't use SAR Geo if basic SAR is not used
+ - brcmfmac: fix reporting support for 160 MHz channels
+ - tools/power/cpupower: fix compilation with STATIC=true
+ - v9fs_dir_readdir: fix double-free on p9stat_read error
+ - selinux: Add __GFP_NOWARN to allocation at str_read()
+ - Input: synaptics - avoid using uninitialized variable when probing
+ - bfs: add sanity check at bfs_fill_super()
+ - sctp: clear the transport of some out_chunk_list chunks in
+ sctp_assoc_rm_peer
+ - gfs2: Don't leave s_fs_info pointing to freed memory in init_sbd
+ - llc: do not use sk_eat_skb()
+ - mm: don't warn about large allocations for slab
+ - mm/memory.c: recheck page table entry with page table lock held
+ - IB/core: Perform modify QP on real one
+ - usb: xhci: Prevent bus suspend if a port connect change or polling state is
+ detected
+ - drm/ast: change resolution may cause screen blurred
+ - drm/ast: fixed cursor may disappear sometimes
+ - can: dev: can_get_echo_skb(): factor out non sending code to
+ __can_get_echo_skb()
+ - can: dev: __can_get_echo_skb(): replace struct can_frame by canfd_frame to
+ access frame length
+ - can: dev: __can_get_echo_skb(): Don't crash the kernel if can_priv::echo_skb
+ is accessed out of bounds
+ - can: dev: __can_get_echo_skb(): print error message, if trying to echo non
+ existing skb
+ - can: rx-offload: introduce can_rx_offload_get_echo_skb() and
+ can_rx_offload_queue_sorted() functions
+ - can: rx-offload: rename can_rx_offload_irq_queue_err_skb() to
+ can_rx_offload_queue_tail()
+ - can: raw: check for CAN FD capable netdev in raw_sendmsg()
+ - can: hi311x: Use level-triggered interrupt
+ - IB/hfi1: Eliminate races in the SDMA send error path
+ - pinctrl: meson: fix pinconf bias disable
+ - KVM: PPC: Move and undef TRACE_INCLUDE_PATH/FILE
+ - cpufreq: imx6q: add return value check for voltage scale
+ - rtc: pcf2127: fix a kmemleak caused in pcf2127_i2c_gather_write
+ - crypto: simd - correctly take reqsize of wrapped skcipher into account
+ - floppy: fix race condition in __floppy_read_block_0()
+ - powerpc/io: Fix the IO workarounds code to work with Radix
+ - perf/x86/intel/uncore: Add more IMC PCI IDs for KabyLake and CoffeeLake CPUs
+ - SUNRPC: Fix a bogus get/put in generic_key_to_expire()
+ - kdb: Use strscpy with destination buffer size
+ - powerpc/numa: Suppress "VPHN is not supported" messages
+ - tmpfs: make lseek(SEEK_DATA/SEK_HOLE) return ENXIO with a negative offset
+ - mm, page_alloc: check for max order in hot path
+ - arm64: remove no-op -p linker flag
+ - ubi: fastmap: Check each mapping only once
+ - Input: xpad - add PDP device id 0x02a4
+ - Input: xpad - fix some coding style issues
+ - Input: xpad - avoid using __set_bit() for capabilities
+ - Input: xpad - add support for Xbox1 PDP Camo series gamepad
+ - iwlwifi: fix wrong WGDS_WIFI_DATA_SIZE
+ - kbuild: allow to use GCC toolchain not in Clang search path
+ - PCI: endpoint: Populate func_no before calling pci_epc_add_epf()
+ - i40iw: Fix memory leak in error path of create QP
+ - clk: samsung: exynos5250: Add missing clocks for FIMC LITE SYSMMU devices
+ - ARM: dts: exynos: Fix invalid node referenced by i2c20 alias in Peach Pit
+ and Pi
+ - include/linux/pfn_t.h: force '~' to be parsed as an unary operator
+ - tty: wipe buffer.
+ - tty: wipe buffer if not echoing data
+ - lan78xx: Read MAC address from DT if present
+ - s390/mm: Check for valid vma before zapping in gmap_discard
+ - rcu: Make need_resched() respond to urgent RCU-QS needs
+ - net: ieee802154: 6lowpan: fix frag reassembly
+ - EVM: Add support for portable signature format
+ - ima: re-introduce own integrity cache lock
+ - ima: re-initialize iint->atomic_flags
+ - xhci: Fix leaking USB3 shared_hcd at xhci removal
+ - Documentation/security-bugs: Clarify treatment of embargoed information
+ - Documentation/security-bugs: Postpone fix publication in exceptional cases
+ - ACPICA: AML interpreter: add region addresses in global list during
+ initialization
+ - fsnotify: generalize handling of extra event flags
+ - pinctrl: meson: fix gxbb ao pull register bits
+ - pinctrl: meson: fix gxl ao pull register bits
+ - pinctrl: meson: fix meson8 ao pull register bits
+ - pinctrl: meson: fix meson8b ao pull register bits
+ - riscv: add missing vdso_install target
+ - media: ov5640: fix wrong binning value in exposure calculation
+ - media: ov5640: fix auto controls values when switching to manual mode
+ - mm/huge_memory: rename freeze_page() to unmap_page()
+ - mm/huge_memory.c: reorder operations in __split_huge_page_tail()
+ - mm/huge_memory: splitting set mapping+index before unfreeze
+ - mm/huge_memory: fix lockdep complaint on 32-bit i_size_read()
+ - mm/khugepaged: collapse_shmem() stop if punched or truncated
+ - mm/khugepaged: fix crashes due to misaccounted holes
+ - mm/khugepaged: collapse_shmem() remember to clear holes
+ - mm/khugepaged: minor reorderings in collapse_shmem()
+ - mm/khugepaged: collapse_shmem() without freezing new_page
+ - mm/khugepaged: collapse_shmem() do not crash on Compound
+ - media: em28xx: Fix use-after-free when disconnecting
+ - ubi: Initialize Fastmap checkmapping correctly
+ - libceph: store ceph_auth_handshake pointer in ceph_connection
+ - libceph: factor out __prepare_write_connect()
+ - libceph: factor out __ceph_x_decrypt()
+ - libceph: factor out encrypt_authorizer()
+ - libceph: add authorizer challenge
+ - libceph: implement CEPHX_V2 calculation mode
+ - net/tls: Fixed return value when tls_complete_pending_work() fails
+ - wil6210: missing length check in wmi_set_ie
+ - btrfs: validate type when reading a chunk
+ - btrfs: Verify that every chunk has corresponding block group at mount time
+ - btrfs: tree-checker: Add checker for dir item
+ - btrfs: tree-checker: use %zu format string for size_t
+ - btrfs: tree-check: reduce stack consumption in check_dir_item
+ - btrfs: tree-checker: Verify block_group_item
+ - btrfs: tree-checker: Detect invalid and empty essential trees
+ - btrfs: Check that each block group has corresponding chunk at mount time
+ - btrfs: tree-checker: Check level for leaves and nodes
+ - btrfs: tree-checker: Fix misleading group system information
+ - f2fs: check blkaddr more accuratly before issue a bio
+ - f2fs: enhance sanity_check_raw_super() to avoid potential overflow
+ - f2fs: clean up with is_valid_blkaddr()
+ - f2fs: introduce and spread verify_blkaddr
+ - f2fs: fix to do sanity check with secs_per_zone
+ - f2fs: fix to do sanity check with user_block_count
+ - f2fs: fix to do sanity check with node footer and iblocks
+ - f2fs: fix to do sanity check with block address in main area
+ - f2fs: fix to do sanity check with i_extra_isize
+ - f2fs: fix to do sanity check with cp_pack_start_sum
+ - net: skb_scrub_packet(): Scrub offload_fwd_mark
+ - net: thunderx: set xdp_prog to NULL if bpf_prog_add fails
+ - virtio-net: disable guest csum during XDP set
+ - virtio-net: fail XDP set if guest csum is negotiated
+ - net: thunderx: set tso_hdrs pointer to NULL in nicvf_free_snd_queue
+ - packet: copy user buffers before orphan or clone
+ - rapidio/rionet: do not free skb before reading its length
+ - usbnet: ipheth: fix potential recvmsg bug and recvmsg bug 2
+ - kvm: mmu: Fix race in emulated page table writes
+ - KVM: x86: Fix kernel info-leak in KVM_HC_CLOCK_PAIRING hypercall
+ - xtensa: enable coprocessors that are being flushed
+ - xtensa: fix coprocessor context offset definitions
+ - xtensa: fix coprocessor part of ptrace_{get,set}xregs
+ - Btrfs: ensure path name is null terminated at btrfs_control_ioctl
+ - btrfs: relocation: set trans to be NULL after ending transaction
+ - PCI: layerscape: Fix wrong invocation of outbound window disable accessor
+ - arm64: dts: rockchip: Fix PCIe reset polarity for rk3399-puma-haikou.
+ - x86/fpu: Disable bottom halves while loading FPU registers
+ - perf/x86/intel: Move branch tracing setup to the Intel-specific source file
+ - perf/x86/intel: Add generic branch tracing check to intel_pmu_has_bts()
+ - fs: fix lost error code in dio_complete
+ - ALSA: wss: Fix invalid snd_free_pages() at error path
+ - ALSA: ac97: Fix incorrect bit shift at AC97-SPSA control write
+ - ALSA: control: Fix race between adding and removing a user element
+ - ALSA: sparc: Fix invalid snd_free_pages() at error path
+ - ALSA: hda/realtek - Support ALC300
+ - ALSA: hda/realtek - fix headset mic detection for MSI MS-B171
+ - ext2: fix potential use after free
+ - ARM: dts: rockchip: Remove @0 from the veyron memory node
+ - dmaengine: at_hdmac: fix memory leak in at_dma_xlate()
+ - dmaengine: at_hdmac: fix module unloading
+ - staging: vchiq_arm: fix compat VCHIQ_IOC_AWAIT_COMPLETION
+ - staging: rtl8723bs: Add missing return for cfg80211_rtw_get_station
+ - usb: core: quirks: add RESET_RESUME quirk for Cherry G230 Stream series
+ - Revert "usb: dwc3: gadget: skip Set/Clear Halt when invalid"
+ - iio:st_magn: Fix enable device after trigger
+ - lib/test_kmod.c: fix rmmod double free
+ - mm: use swp_offset as key in shmem_replace_page()
+ - misc: mic/scif: fix copy-paste error in scif_create_remote_lookup
+ - binder: fix race that allows malicious free of live buffer
+ - libceph: weaken sizeof check in ceph_x_verify_authorizer_reply()
+ - libceph: check authorizer reply/challenge length before reading
+ - f2fs: fix missing up_read
+ - net: don't keep lonely packets forever in the gro hash
+ - net: phy: add workaround for issue where PHY driver doesn't bind to the
+ device
+ - KVM: nVMX/nSVM: Fix bug which sets vcpu->arch.tsc_offset to L1 tsc_offset
+ - udf: Allow mounting volumes with incorrect identification strings
+ - btrfs: Always try all copies when reading extent buffers
+ - Btrfs: fix rare chances for data loss when doing a fast fsync
+ - Btrfs: fix race between enabling quotas and subvolume creation
+ - perf/x86/intel: Disallow precise_ip on BTS events
+ - ALSA: hda: Add ASRock H81M-HDS to the power_save blacklist
+ - ALSA: hda: Add ASRock N68C-S UCC the power_save blacklist
+ - function_graph: Create function_graph_enter() to consolidate architecture
+ code
+ - ARM: function_graph: Simplify with function_graph_enter()
+ - microblaze: function_graph: Simplify with function_graph_enter()
+ - x86/function_graph: Simplify with function_graph_enter()
+ - powerpc/function_graph: Simplify with function_graph_enter()
+ - sh/function_graph: Simplify with function_graph_enter()
+ - sparc/function_graph: Simplify with function_graph_enter()
+ - parisc: function_graph: Simplify with function_graph_enter()
+ - s390/function_graph: Simplify with function_graph_enter()
+ - arm64: function_graph: Simplify with function_graph_enter()
+ - MIPS: function_graph: Simplify with function_graph_enter()
+ - function_graph: Make ftrace_push_return_trace() static
+ - function_graph: Use new curr_ret_depth to manage depth instead of
+ curr_ret_stack
+ - function_graph: Have profiler use curr_ret_stack and not depth
+ - function_graph: Move return callback before update of curr_ret_stack
+ - function_graph: Reverse the order of pushing the ret_stack and the callback
+ - ext2: initialize opts.s_mount_opt as zero before using it
+ - ASoC: intel: cht_bsw_max98090_ti: Add quirk for boards using pmc_plt_clk_0
+ - staging: most: use format specifier "%s" in snprintf
+ - iio/hid-sensors: Fix IIO_CHAN_INFO_RAW returning wrong values for signed
+ numbers
+ - mm: cleancache: fix corruption on missed inode invalidation
+
+ * Bionic update: upstream stable patchset 2019-07-17 (LP: #1836968) //
+ CVE-2000-1134 // CVE-2007-3852 // CVE-2008-0525 // CVE-2009-0416 //
+ CVE-2011-4834 // CVE-2015-1838 // CVE-2015-7442 // CVE-2016-7489
+ - namei: allow restricted O_CREAT of FIFOs and regular files
+
+ * bcache: risk of data loss on I/O errors in backing or caching devices
+ (LP: #1829563)
+ - bcache: add CACHE_SET_IO_DISABLE to struct cache_set flags
+ - bcache: add stop_when_cache_set_failed option to backing device
+ - bcache: fix inaccurate io state for detached bcache devices
+ - bcache: add backing_request_endio() for bi_end_io
+ - bcache: add io_disable to struct cached_dev
+ - bcache: store disk name in struct cache and struct cached_dev
+ - bcache: count backing device I/O error for writeback I/O
+ - bcache: add wait_for_kthread_stop() in bch_allocator_thread()
+ - bcache: set dc->io_disable to true in conditional_stop_bcache_device()
+ - bcache: stop bcache device when backing device is offline
+ - bcache: fix ioctl in flash device
+
+ * Bionic update: upstream stable patchset 2019-07-16 (LP: #1836802)
+ - mtd: spi-nor: fsl-quadspi: fix read error for flash size larger than 16MB
+ - spi: bcm-qspi: switch back to reading flash using smaller chunks
+ - bcache: trace missed reading by cache_missed
+ - bcache: fix miss key refill->end in writeback
+ - hwmon: (pmbus) Fix page count auto-detection.
+ - jffs2: free jffs2_sb_info through jffs2_kill_sb()
+ - cpufreq: conservative: Take limits changes into account properly
+ - pcmcia: Implement CLKRUN protocol disabling for Ricoh bridges
+ - parisc: Fix address in HPMC IVA
+ - parisc: Fix map_pages() to not overwrite existing pte entries
+ - parisc: Fix exported address of os_hpmc handler
+ - ALSA: hda - Add quirk for ASUS G751 laptop
+ - ALSA: hda - Fix headphone pin config for ASUS G751
+ - ALSA: hda - Add mic quirk for the Lenovo G50-30 (17aa:3905)
+ - ALSA: ca0106: Disable IZD on SB0570 DAC to fix audio pops
+ - x86/xen: Fix boot loader version reported for PVH guests
+ - x86/corruption-check: Fix panic in memory_corruption_check() when boot
+ option without value is provided
+ - ARM: dts: exynos: Disable pull control for MAX8997 interrupts on Origen
+ - bpf: do not blindly change rlimit in reuseport net selftest
+ - Revert "perf tools: Fix PMU term format max value calculation"
+ - xfrm: policy: use hlist rcu variants on insert
+ - perf vendor events intel: Fix wrong filter_band* values for uncore events
+ - sched/fair: Fix the min_vruntime update logic in dequeue_entity()
+ - perf tools: Fix use of alternatives to find JDIR
+ - perf cpu_map: Align cpu map synthesized events properly.
+ - x86/fpu: Remove second definition of fpu in __fpu__restore_sig()
+ - net: qla3xxx: Remove overflowing shift statement
+ - selftests: ftrace: Add synthetic event syntax testcase
+ - i2c: rcar: cleanup DMA for all kinds of failure
+ - locking/lockdep: Fix debug_locks off performance problem
+ - ataflop: fix error handling during setup
+ - swim: fix cleanup on setup error
+ - nfp: devlink port split support for 1x100G CXP NIC
+ - tun: Consistently configure generic netdev params via rtnetlink
+ - s390/sthyi: Fix machine name validity indication
+ - hwmon: (pwm-fan) Set fan speed to 0 on suspend
+ - lightnvm: pblk: fix two sleep-in-atomic-context bugs
+ - spi: spi-ep93xx: Use dma_data_direction for ep93xx_spi_dma_{finish,prepare}
+ - perf tools: Free temporary 'sys' string in read_event_files()
+ - perf tools: Cleanup trace-event-info 'tdata' leak
+ - perf strbuf: Match va_{add,copy} with va_end
+ - cpupower: Fix coredump on VMWare
+ - mmc: sdhci-pci-o2micro: Add quirk for O2 Micro dev 0x8620 rev 0x01
+ - iwlwifi: pcie: avoid empty free RB queue
+ - iwlwifi: mvm: clear HW_RESTART_REQUESTED when stopping the interface
+ - x86/olpc: Indicate that legacy PC XO-1 platform should not register RTC
+ - ACPI / processor: Fix the return value of acpi_processor_ids_walk()
+ - cpufreq: dt: Try freeing static OPPs only if we have added them
+ - mtd: rawnand: atmel: Fix potential NULL pointer dereference
+ - signal: Introduce COMPAT_SIGMINSTKSZ for use in compat_sys_sigaltstack
+ - Bluetooth: btbcm: Add entry for BCM4335C0 UART bluetooth
+ - x86: boot: Fix EFI stub alignment
+ - pinctrl: qcom: spmi-mpp: Fix err handling of pmic_mpp_set_mux
+ - brcmfmac: fix for proper support of 160MHz bandwidth
+ - net: phy: phylink: ensure the carrier is off when starting phylink
+ - block, bfq: correctly charge and reset entity service in all cases
+ - kprobes: Return error if we fail to reuse kprobe instead of BUG_ON()
+ - ACPI / LPSS: Add alternative ACPI HIDs for Cherry Trail DMA controllers
+ - pinctrl: qcom: spmi-mpp: Fix drive strength setting
+ - pinctrl: spmi-mpp: Fix pmic_mpp_config_get() to be compliant
+ - pinctrl: ssbi-gpio: Fix pm8xxx_pin_config_get() to be compliant
+ - net: dsa: mv88e6xxx: Fix writing to a PHY page.
+ - iwlwifi: mvm: fix BAR seq ctrl reporting
+ - ixgbevf: VF2VF TCP RSS
+ - ath10k: schedule hardware restart if WMI command times out
+ - thermal: da9062/61: Prevent hardware access during system suspend
+ - cgroup, netclassid: add a preemption point to write_classid
+ - scsi: esp_scsi: Track residual for PIO transfers
+ - UAPI: ndctl: Fix g++-unsupported initialisation in headers
+ - KVM: nVMX: Clear reserved bits of #DB exit qualification
+ - scsi: megaraid_sas: fix a missing-check bug
+ - RDMA/core: Do not expose unsupported counters
+ - IB/ipoib: Clear IPCB before icmp_send
+ - RDMA/bnxt_re: Fix recursive lock warning in debug kernel
+ - usb: host: ohci-at91: fix request of irq for optional gpio
+ - PCI: mediatek: Fix mtk_pcie_find_port() endpoint/port matching logic
+ - tpm: suppress transmit cmd error logs when TPM 1.2 is disabled/deactivated
+ - Drivers: hv: vmbus: Use cpumask_var_t for on-stack cpu mask
+ - VMCI: Resource wildcard match fixed
+ - PCI / ACPI: Enable wake automatically for power managed bridges
+ - usb: gadget: udc: atmel: handle at91sam9rl PMC
+ - ext4: fix argument checking in EXT4_IOC_MOVE_EXT
+ - MD: fix invalid stored role for a disk
+ - f2fs: fix to recover inode's i_flags during POR
+ - PCI/MSI: Warn and return error if driver enables MSI/MSI-X twice
+ - coresight: etb10: Fix handling of perf mode
+ - PCI: dwc: pci-dra7xx: Enable errata i870 for both EP and RC mode
+ - crypto: caam - fix implicit casts in endianness helpers
+ - usb: chipidea: Prevent unbalanced IRQ disable
+ - driver/dma/ioat: Call del_timer_sync() without holding prep_lock
+ - uio: ensure class is registered before devices
+ - scsi: lpfc: Correct soft lockup when running mds diagnostics
+ - scsi: lpfc: Correct race with abort on completion path
+ - f2fs: report error if quota off error during umount
+ - signal: Always deliver the kernel's SIGKILL and SIGSTOP to a pid namespace
+ init
+ - mfd: menelaus: Fix possible race condition and leak
+ - dmaengine: dma-jz4780: Return error if not probed from DT
+ - IB/rxe: fix for duplicate request processing and ack psns
+ - ALSA: hda: Check the non-cached stream buffers more explicitly
+ - cpupower: Fix AMD Family 0x17 msr_pstate size
+ - f2fs: fix to account IO correctly
+ - ARM: dts: exynos: Remove "cooling-{min|max}-level" for CPU nodes
+ - arm: dts: exynos: Add missing cooling device properties for CPUs
+ - ARM: dts: exynos: Convert exynos5250.dtsi to opp-v2 bindings
+ - ARM: dts: exynos: Mark 1 GHz CPU OPP as suspend OPP on Exynos5250
+ - xen-swiotlb: use actually allocated size on check physical continuous
+ - tpm: Restore functionality to xen vtpm driver.
+ - xen/blkfront: avoid NULL blkfront_info dereference on device removal
+ - xen/balloon: Support xend-based toolstack
+ - xen: fix race in xen_qlock_wait()
+ - xen: make xen_qlock_wait() nestable
+ - xen/pvh: increase early stack size
+ - xen/pvh: don't try to unplug emulated devices
+ - libertas: don't set URB_ZERO_PACKET on IN USB transfer
+ - usbip:vudc: BUG kmalloc-2048 (Not tainted): Poison overwritten
+ - usb: gadget: udc: renesas_usb3: Fix b-device mode for "workaround"
+ - iwlwifi: mvm: check return value of rs_rate_from_ucode_rate()
+ - net/ipv4: defensive cipso option parsing
+ - dmaengine: ppc4xx: fix off-by-one build failure
+ - dmaengine: stm32-dma: fix incomplete configuration in cyclic mode
+ - libnvdimm: Hold reference on parent while scheduling async init
+ - libnvdimm, region: Fail badblocks listing for inactive regions
+ - ASoC: intel: skylake: Add missing break in skl_tplg_get_token()
+ - IB/mlx5: Fix MR cache initialization
+ - jbd2: fix use after free in jbd2_log_do_checkpoint()
+ - gfs2_meta: ->mount() can get NULL dev_name
+ - ext4: initialize retries variable in ext4_da_write_inline_data_begin()
+ - ext4: fix setattr project check in fssetxattr ioctl
+ - ext4: propagate error from dquot_initialize() in EXT4_IOC_FSSETXATTR
+ - ext4: fix use-after-free race in ext4_remount()'s error path
+ - EDAC, amd64: Add Family 17h, models 10h-2fh support
+ - EDAC, {i7core,sb,skx}_edac: Fix uncorrected error counting
+ - EDAC, skx_edac: Fix logical channel intermediate decoding
+ - ARM: dts: dra7: Fix up unaligned access setting for PCIe EP
+ - PCI/ASPM: Fix link_state teardown on device removal
+ - PCI: Add Device IDs for Intel GPU "spurious interrupt" quirk
+ - PCI: vmd: White list for fast interrupt handlers
+ - signal/GenWQE: Fix sending of SIGKILL
+ - signal: Guard against negative signal numbers in copy_siginfo_from_user32
+ - crypto: lrw - Fix out-of bounds access on counter overflow
+ - crypto: tcrypt - fix ghash-generic speed test
+ - mm: /proc/pid/smaps_rollup: fix NULL pointer deref in smaps_pte_range()
+ - ima: fix showing large 'violations' or 'runtime_measurements_count'
+ - hugetlbfs: dirty pages as they are added to pagecache
+ - mm/rmap: map_pte() was not handling private ZONE_DEVICE page properly
+ - KVM: arm64: Fix caching of host MDCR_EL2 value
+ - kbuild: fix kernel/bounds.c 'W=1' warning
+ - iio: ad5064: Fix regulator handling
+ - iio: adc: imx25-gcq: Fix leak of device_node in mx25_gcq_setup_cfgs()
+ - iio: adc: at91: fix acking DRDY irq on simple conversions
+ - iio: adc: at91: fix wrong channel number in triggered buffer mode
+ - w1: omap-hdq: fix missing bus unregister at removal
+ - smb3: allow stats which track session and share reconnects to be reset
+ - smb3: do not attempt cifs operation in smb3 query info error path
+ - smb3: on kerberos mount if server doesn't specify auth type use krb5
+ - printk: Fix panic caused by passing log_buf_len to command line
+ - genirq: Fix race on spurious interrupt detection
+ - NFSv4.1: Fix the r/wsize checking
+ - nfs: Fix a missed page unlock after pg_doio()
+ - nfsd: Fix an Oops in free_session()
+ - lockd: fix access beyond unterminated strings in prints
+ - dm ioctl: harden copy_params()'s copy_from_user() from malicious users
+ - dm zoned: fix metadata block ref counting
+ - dm zoned: fix various dmz_get_mblock() issues
+ - powerpc/msi: Fix compile error on mpc83xx
+ - MIPS: OCTEON: fix out of bounds array access on CN68XX
+ - iommu/arm-smmu: Ensure that page-table updates are visible before TLBI
+ - TC: Set DMA masks for devices
+ - media: v4l2-tpg: fix kernel oops when enabling HFLIP and OSD
+ - kgdboc: Passing ekgdboc to command line causes panic
+ - xen: fix xen_qlock_wait()
+ - xen-blkfront: fix kernel panic with negotiate_mq error path
+ - media: em28xx: use a default format if TRY_FMT fails
+ - media: tvp5150: avoid going past array on v4l2_querymenu()
+ - media: em28xx: fix input name for Terratec AV 350
+ - media: em28xx: make v4l2-compliance happier by starting sequence on zero
+ - media: media colorspaces*.rst: rename AdobeRGB to opRGB
+ - arm64: lse: remove -fcall-used-x0 flag
+ - rpmsg: smd: fix memory leak on channel create
+ - Cramfs: fix abad comparison when wrap-arounds occur
+ - ARM: dts: socfpga: Fix SDRAM node address for Arria10
+ - arm64: dts: stratix10: Correct System Manager register size
+ - soc/tegra: pmc: Fix child-node lookup
+ - btrfs: qgroup: Avoid calling qgroup functions if qgroup is not enabled
+ - btrfs: Handle owner mismatch gracefully when walking up tree
+ - btrfs: locking: Add extra check in btrfs_init_new_buffer() to avoid deadlock
+ - btrfs: fix error handling in free_log_tree
+ - btrfs: Enhance btrfs_trim_fs function to handle error better
+ - btrfs: Ensure btrfs_trim_fs can trim the whole filesystem
+ - btrfs: iterate all devices during trim, instead of fs_devices::alloc_list
+ - btrfs: don't attempt to trim devices that don't support it
+ - btrfs: wait on caching when putting the bg cache
+ - btrfs: protect space cache inode alloc with GFP_NOFS
+ - btrfs: reset max_extent_size on clear in a bitmap
+ - btrfs: make sure we create all new block groups
+ - Btrfs: fix warning when replaying log after fsync of a tmpfile
+ - Btrfs: fix wrong dentries after fsync of file that got its parent replaced
+ - btrfs: qgroup: Dirty all qgroups before rescan
+ - Btrfs: fix null pointer dereference on compressed write path error
+ - Btrfs: fix assertion on fsync of regular file when using no-holes feature
+ - btrfs: set max_extent_size properly
+ - btrfs: don't use ctl->free_space for max_extent_size
+ - btrfs: only free reserved extent if we didn't insert it
+ - btrfs: don't run delayed_iputs in commit
+ - btrfs: move the dio_sem higher up the callchain
+ - Btrfs: fix use-after-free during inode eviction
+ - Btrfs: fix use-after-free when dumping free space
+ - Btrfs: fix fsync after hole punching when using no-holes feature
+ - net: sched: Remove TCA_OPTIONS from policy
+ - bpf: wait for running BPF programs when updating map-in-map
+ - MD: fix invalid stored role for a disk - try2
+ - mtd: spi-nor: intel-spi: Add support for Intel Ice Lake SPI serial flash
+ - mtd: spi-nor: fsl-quadspi: Don't let -EINVAL on the bus
+ - bcache: correct dirty data statistics
+ - block: don't deal with discard limit in blkdev_issue_discard()
+ - block: make sure discard bio is aligned with logical block size
+ - block: make sure writesame bio is aligned with logical block size
+ - dma-mapping: fix panic caused by passing empty cma command line argument
+ - ACPI / OSL: Use 'jiffies' as the time bassis for acpi_os_get_timer()
+ - ACPICA: AML Parser: fix parse loop to correctly skip erroneous extended
+ opcodes
+ - kprobes/x86: Use preempt_enable() in optimized_callback()
+ - mailbox: PCC: handle parse error
+ - ALSA: hda: Add 2 more models to the power_save blacklist
+ - drm: fix use of freed memory in drm_mode_setcrtc
+ - nvme: remove ns sibling before clearing path
+ - nfp: flower: fix pedit set actions for multiple partial masks
+ - nfp: flower: use offsets provided by pedit instead of index for ipv6
+ - perf report: Don't crash on invalid inline debug information
+ - drm: Get ref on CRTC commit object when waiting for flip_done
+ - net: socionext: Reset tx queue in ndo_stop
+ - lightnvm: pblk: fix race on sysfs line state
+ - lightnvm: pblk: fix race condition on metadata I/O
+ - bcache: Populate writeback_rate_minimum attribute
+ - sdhci: acpi: add free_slot callback
+ - mtd: rawnand: denali: set SPARE_AREA_SKIP_BYTES register to 8 if unset
+ - iwlwifi: mvm: check for n_profiles validity in EWRD ACPI
+ - ACPI/PPTT: Handle architecturally unknown cache types
+ - ACPI / PM: LPIT: Register sysfs attributes based on FADT
+ - pinctrl: sunxi: fix 'pctrl->functions' allocation in
+ sunxi_pinctrl_build_state
+ - arm64: entry: Allow handling of undefined instructions from EL1
+ - bpf/verifier: fix verifier instability
+ - gpio: brcmstb: allow 0 width GPIO banks
+ - libata: Apply NOLPM quirk for SAMSUNG MZ7TD256HAFV-000L9
+ - thermal: rcar_thermal: Prevent doing work after unbind
+ - net: stmmac: dwmac-sun8i: fix OF child-node lookup
+ - f2fs: clear PageError on the read path
+ - xprtrdma: Reset credit grant properly after a disconnect
+ - nvmem: check the return value of nvmem_add_cells()
+ - f2fs: avoid sleeping under spin_lock
+ - f2fs: fix to recover cold bit of inode block during POR
+ - OPP: Free OPP table properly on performance state irregularities
+ - IB/rxe: Revise the ib_wr_opcode enum
+ - ext4: fix EXT4_IOC_SWAP_BOOT
+ - selinux: fix mounting of cgroup2 under older policies
+ - KVM: arm/arm64: Ensure only THP is candidate for adjustment
+ - NFC: nfcmrvl_uart: fix OF child-node lookup
+ - media: ov7670: make "xclk" clock optional
+ - powerpc/tm: Fix HFSCR bit for no suspend case
+ - powerpc/64s/hash: Do not use PPC_INVALIDATE_ERAT on CPUs before POWER9
+ - MIPS: memset: Fix CPU_DADDI_WORKAROUNDS `small_fixup' regression
+ - power: supply: twl4030-charger: fix OF sibling-node lookup
+ - ocxl: Fix access to the AFU Descriptor Data
+ - net: bcmgenet: fix OF child-node lookup
+ - media: cec: make cec_get_edid_spa_location() an inline function
+ - media: cec: integrate cec_validate_phys_addr() in cec-api.c
+ - media: adv7604: when the EDID is cleared, unconfigure CEC as well
+ - media: adv7842: when the EDID is cleared, unconfigure CEC as well
+ - drm/mediatek: fix OF sibling-node lookup
+ - media: replace ADOBERGB by OPRGB
+ - media: hdmi.h: rename ADOBE_RGB to OPRGB and ADOBE_YCC to OPYCC
+ - btrfs: fix error handling in btrfs_dev_replace_start
+ - btrfs: keep trim from interfering with transaction commits
+ - Btrfs: don't clean dirty pages during buffered writes
+ - btrfs: release metadata before running delayed refs
+ - Btrfs: fix deadlock when writing out free space caches
+ - btrfs: reset max_extent_size properly
+ - btrfs: fix insert_reserved error handling
+ - powerpc/traps: restore recoverability of machine_check interrupts
+ - powerpc/64/module: REL32 relocation range check
+ - powerpc/mm: Fix page table dump to work on Radix
+ - powerpc/eeh: Fix possible null deref in eeh_dump_dev_log()
+ - tty: check name length in tty_find_polling_driver()
+ - ARM: imx_v6_v7_defconfig: Select CONFIG_TMPFS_POSIX_ACL
+ - powerpc/nohash: fix undefined behaviour when testing page size support
+ - powerpc/mm: Don't report hugepage tables as memory leaks when using kmemleak
+ - drm/omap: fix memory barrier bug in DMM driver
+ - drm/hisilicon: hibmc: Do not carry error code in HiBMC framebuffer pointer
+ - media: pci: cx23885: handle adding to list failure
+ - media: coda: don't overwrite h.264 profile_idc on decoder instance
+ - MIPS: kexec: Mark CPU offline before disabling local IRQ
+ - powerpc/boot: Ensure _zimage_start is a weak symbol
+ - powerpc/memtrace: Remove memory in chunks
+ - MIPS/PCI: Call pcie_bus_configure_settings() to set MPS/MRRS
+ - sc16is7xx: Fix for multi-channel stall
+ - media: tvp5150: fix width alignment during set_selection()
+ - powerpc/selftests: Wait all threads to join
+ - staging:iio:ad7606: fix voltage scales
+ - 9p locks: fix glock.client_id leak in do_lock
+ - 9p: clear dangling pointers in p9stat_free
+ - ovl: fix error handling in ovl_verify_set_fh()
+ - scsi: qla2xxx: Fix incorrect port speed being set for FC adapters
+ - scsi: qla2xxx: Fix process response queue for ISP26XX and above
+ - scsi: qla2xxx: Remove stale debug trace message from tcm_qla2xxx
+ - scsi: qla2xxx: shutdown chip if reset fail
+ - scsi: qla2xxx: Fix re-using LoopID when handle is in use
+ - ovl: fix recursive oi->lock in ovl_link()
+ - MIPS: Loongson-3: Fix CPU UART irq delivery problem
+ - MIPS: Loongson-3: Fix BRIDGE irq delivery problem
+ - xtensa: add NOTES section to the linker script
+ - xtensa: make sure bFLT stack is 16 byte aligned
+ - xtensa: fix boot parameters address translation
+ - um: Drop own definition of PTRACE_SYSEMU/_SINGLESTEP
+ - clk: s2mps11: Fix matching when built as module and DT node contains
+ compatible
+ - clk: at91: Fix division by zero in PLL recalc_rate()
+ - clk: rockchip: Fix static checker warning in rockchip_ddrclk_get_parent call
+ - clk: mvebu: use correct bit for 98DX3236 NAND
+ - libceph: bump CEPH_MSG_MAX_DATA_LEN
+ - mach64: fix display corruption on big endian machines
+ - mach64: fix image corruption due to reading accelerator registers
+ - reset: hisilicon: fix potential NULL pointer dereference
+ - vhost/scsi: truncate T10 PI iov_iter to prot_bytes
+ - scsi: qla2xxx: Initialize port speed to avoid setting lower speed
+ - SCSI: fix queue cleanup race before queue initialization is done
+ - soc: ti: QMSS: Fix usage of irq_set_affinity_hint
+ - ocfs2: fix a misuse a of brelse after failing ocfs2_check_dir_entry
+ - ocfs2: free up write context when direct IO failed
+ - mm: thp: relax __GFP_THISNODE for MADV_HUGEPAGE mappings
+ - netfilter: conntrack: fix calculation of next bucket number in early_drop
+ - ARM: 8809/1: proc-v7: fix Thumb annotation of cpu_v7_hvc_switch_mm
+ - mtd: docg3: don't set conflicting BCH_CONST_PARAMS option
+ - of, numa: Validate some distance map rules
+ - x86/cpu/vmware: Do not trace vmware_sched_clock()
+ - x86/hyper-v: Enable PIT shutdown quirk
+ - termios, tty/tty_baudrate.c: fix buffer overrun
+ - arch/alpha, termios: implement BOTHER, IBSHIFT and termios2
+ - watchdog/core: Add missing prototypes for weak functions
+ - btrfs: fix pinned underflow after transaction aborted
+ - Btrfs: fix cur_offset in the error case for nocow
+ - Btrfs: fix infinite loop on inode eviction after deduplication of eof block
+ - Btrfs: fix data corruption due to cloning of eof block
+ - clockevents/drivers/i8253: Add support for PIT shutdown quirk
+ - ext4: add missing brelse() update_backups()'s error path
+ - ext4: add missing brelse() in set_flexbg_block_bitmap()'s error path
+ - ext4: add missing brelse() add_new_gdb_meta_bg()'s error path
+ - ext4: avoid potential extra brelse in setup_new_flex_group_blocks()
+ - ext4: missing !bh check in ext4_xattr_inode_write()
+ - ext4: fix possible inode leak in the retry loop of ext4_resize_fs()
+ - ext4: avoid buffer leak on shutdown in ext4_mark_iloc_dirty()
+ - ext4: avoid buffer leak in ext4_orphan_add() after prior errors
+ - ext4: fix missing cleanup if ext4_alloc_flex_bg_array() fails while resizing
+ - ext4: avoid possible double brelse() in add_new_gdb() on error path
+ - ext4: fix possible leak of sbi->s_group_desc_leak in error path
+ - ext4: fix possible leak of s_journal_flag_rwsem in error path
+ - ext4: fix buffer leak in ext4_xattr_get_block() on error path
+ - ext4: release bs.bh before re-using in ext4_xattr_block_find()
+ - ext4: fix buffer leak in ext4_xattr_move_to_block() on error path
+ - ext4: fix buffer leak in ext4_expand_extra_isize_ea() on error path
+ - ext4: fix buffer leak in __ext4_read_dirblock() on error path
+ - mount: Prevent MNT_DETACH from disconnecting locked mounts
+ - kdb: use correct pointer when 'btc' calls 'btt'
+ - kdb: print real address of pointers instead of hashed addresses
+ - sunrpc: correct the computation for page_ptr when truncating
+ - rtc: hctosys: Add missing range error reporting
+ - configfs: replace strncpy with memcpy
+ - gfs2: Put bitmap buffers in put_super
+ - lib/ubsan.c: don't mark __ubsan_handle_builtin_unreachable as noreturn
+ - hugetlbfs: fix kernel BUG at fs/hugetlbfs/inode.c:444!
+ - mm/swapfile.c: use kvzalloc for swap_info_struct allocation
+ - efi/arm/libstub: Pack FDT after populating it
+ - drm/amdgpu: add missing CHIP_HAINAN in amdgpu_ucode_get_load_type
+ - drm/nouveau: Check backlight IDs are >= 0, not > 0
+ - drm/dp_mst: Check if primary mstb is null
+ - drm/i915: Restore vblank interrupts earlier
+ - drm/i915: Don't unset intel_connector->mst_port
+ - drm/i915: Skip vcpi allocation for MSTB ports that are gone
+ - drm/i915: Large page offsets for pread/pwrite
+ - drm/i915/hdmi: Add HDMI 2.0 audio clock recovery N values
+ - drm/i915: Don't oops during modeset shutdown after lpe audio deinit
+ - drm/i915: Mark pin flags as u64
+ - drm/i915/execlists: Force write serialisation into context image vs
+ execution
+ - CONFIG_XEN_PV breaks xen_create_contiguous_region on ARM
+ - ovl: check whiteout in ovl_create_over_whiteout()
+ - nvme-loop: fix kernel oops in case of unhandled command
+ - Input: wm97xx-ts - fix exit path
+ - powerpc/Makefile: Fix PPC_BOOK3S_64 ASFLAGS
+ - tracing/kprobes: Check the probe on unloaded module correctly
+ - drm/amdgpu/powerplay: fix missing break in switch statements
+ - udf: Prevent write-unsupported filesystem to be remounted read-write
+ - serial: sh-sci: Fix could not remove dev_attr_rx_fifo_timeout
+ - zram: close udev startup race condition as default groups
+ - clk: rockchip: fix wrong mmc sample phase shift for rk3328
+ - bonding/802.3ad: fix link_failure_count tracking
+ - hwmon: (core) Fix double-free in __hwmon_device_register()
+ - perf stat: Handle different PMU names with common prefix
+ - mnt: fix __detach_mounts infinite loop
+ - NFSv4: Don't exit the state manager without clearing
+ NFS4CLNT_MANAGER_RUNNING
+ - libata: blacklist SAMSUNG MZ7TD256HAFV-000L9 SSD
+ - drm/i915/dp: Link train Fallback on eDP only if fallback link BW can fit
+ panel's native mode
+ - drm/i915: Fix ilk+ watermarks when disabling pipes
+ - drm/i915: Fix possible race in intel_dp_add_mst_connector()
+
+ * [SRU][B/B-OEM]Fix resume failure on some TPM chips (LP: #1836031)
+ - tpm: tpm_try_transmit() refactor error flow.
+
+ * Linux md raid-10 freezes during resync (LP: #1767992)
+ - md: fix raid10 hang issue caused by barrier
+
+ * hda/realtek: can't detect external mic on a Dell machine (LP: #1836755)
+ - ALSA: hda/realtek: apply ALC891 headset fixup to one Dell machine
+
+ * CVE-2019-12614
+ - powerpc/pseries/dlpar: Fix a missing check in dlpar_parse_cc_property()
+
+ * x86: mm: early boot problem on i386 with KPTI enabled (LP: #1827884)
+ - Revert "perf/core: Make sure the ring-buffer is mapped in all page-tables"
+ - x86/mm: Clarify hardware vs. software "error_code"
+ - x86/mm: Break out kernel address space handling
+ - x86/mm: Break out user address space handling
+ - x86/mm/fault: Allow stack access below %rsp
+
+ * bnx2x driver causes 100% CPU load (LP: #1832082)
+ - bnx2x: Prevent ptp_task to be rescheduled indefinitely
+
+ * Sometimes touchpad detected as mouse(i2c designware fails to get adapter
+ number) (LP: #1835150)
+ - i2c: i2c-designware-platdrv: Cleanup setting of the adapter number
+ - i2c: i2c-designware-platdrv: Always use a dynamic adapter number
+
+ * HP EliteBook 745 G5 (Ryzen 2500U) fails to boot unless `mce=off` is set on
+ command line (LP: #1796443)
+ - x86/MCE/AMD: Turn off MC4_MISC thresholding on all family 0x15 models
+ - x86/MCE/AMD: Carve out the MC4_MISC thresholding quirk
+ - x86/MCE: Add an MCE-record filtering function
+ - x86/MCE/AMD: Don't report L1 BTB MCA errors on some family 17h models
+
+ * Bionic update: upstream stable patchset 2019-07-15 (LP: #1836654)
+ - media: af9035: prevent buffer overflow on write
+ - batman-adv: Avoid probe ELP information leak
+ - batman-adv: Fix segfault when writing to throughput_override
+ - batman-adv: Fix segfault when writing to sysfs elp_interval
+ - batman-adv: Prevent duplicated gateway_node entry
+ - batman-adv: Prevent duplicated nc_node entry
+ - batman-adv: Prevent duplicated softif_vlan entry
+ - batman-adv: Prevent duplicated global TT entry
+ - batman-adv: Prevent duplicated tvlv handler
+ - batman-adv: fix backbone_gw refcount on queue_work() failure
+ - batman-adv: fix hardif_neigh refcount on queue_work() failure
+ - clocksource/drivers/ti-32k: Add CLOCK_SOURCE_SUSPEND_NONSTOP flag for non-
+ am43 SoCs
+ - scsi: ibmvscsis: Fix a stringop-overflow warning
+ - scsi: ibmvscsis: Ensure partition name is properly NUL terminated
+ - intel_th: pci: Add Ice Lake PCH support
+ - Input: atakbd - fix Atari keymap
+ - Input: atakbd - fix Atari CapsLock behaviour
+ - net: emac: fix fixed-link setup for the RTL8363SB switch
+ - ravb: do not write 1 to reserved bits
+ - PCI: dwc: Fix scheduling while atomic issues
+ - drm: mali-dp: Call drm_crtc_vblank_reset on device init
+ - scsi: ipr: System hung while dlpar adding primary ipr adapter back
+ - scsi: sd: don't crash the host on invalid commands
+ - net/mlx4: Use cpumask_available for eq->affinity_mask
+ - clocksource/drivers/fttmr010: Fix set_next_event handler
+ - powerpc/tm: Fix userspace r13 corruption
+ - powerpc/tm: Avoid possible userspace r1 corruption on reclaim
+ - iommu/amd: Return devid as alias for ACPI HID devices
+ - ARC: build: Get rid of toolchain check
+ - ARC: build: Don't set CROSS_COMPILE in arch's Makefile
+ - HID: quirks: fix support for Apple Magic Keyboards
+ - staging: ccree: check DMA pool buf !NULL before free
+ - net/smc: fix sizeof to int comparison
+ - qed: Fix populating the invalid stag value in multi function mode.
+ - RDMA/uverbs: Fix validity check for modify QP
+ - bpf: test_maps, only support ESTABLISHED socks
+ - RDMA/bnxt_re: Fix system crash during RDMA resource initialization
+ - RISC-V: include linux/ftrace.h in asm-prototypes.h
+ - powerpc/numa: Use associativity if VPHN hcall is successful
+ - x86/boot: Fix kexec booting failure in the SEV bit detection code
+ - xfrm: Validate address prefix lengths in the xfrm selector.
+ - xfrm6: call kfree_skb when skb is toobig
+ - xfrm: reset transport header back to network header after all input
+ transforms ahave been applied
+ - xfrm: reset crypto_done when iterating over multiple input xfrms
+ - mac80211: Always report TX status
+ - cfg80211: reg: Init wiphy_idx in regulatory_hint_core()
+ - mac80211: fix pending queue hang due to TX_DROP
+ - cfg80211: Address some corner cases in scan result channel updating
+ - mac80211: TDLS: fix skb queue/priority assignment
+ - mac80211: fix TX status reporting for ieee80211s
+ - ARM: 8799/1: mm: fix pci_ioremap_io() offset check
+ - xfrm: validate template mode
+ - netfilter: bridge: Don't sabotage nf_hook calls from an l3mdev
+ - arm64: hugetlb: Fix handling of young ptes
+ - ARM: dts: BCM63xx: Fix incorrect interrupt specifiers
+ - net: macb: Clean 64b dma addresses if they are not detected
+ - soc: fsl: qbman: qman: avoid allocating from non existing gen_pool
+ - soc: fsl: qe: Fix copy/paste bug in ucc_get_tdm_sync_shift()
+ - mac80211_hwsim: do not omit multicast announce of first added radio
+ - Bluetooth: SMP: fix crash in unpairing
+ - pxa168fb: prepare the clock
+ - qed: Avoid implicit enum conversion in qed_set_tunn_cls_info
+ - qed: Fix mask parameter in qed_vf_prep_tunn_req_tlv
+ - qed: Avoid implicit enum conversion in qed_roce_mode_to_flavor
+ - qed: Avoid constant logical operation warning in qed_vf_pf_acquire
+ - qed: Avoid implicit enum conversion in qed_iwarp_parse_rx_pkt
+ - asix: Check for supported Wake-on-LAN modes
+ - ax88179_178a: Check for supported Wake-on-LAN modes
+ - lan78xx: Check for supported Wake-on-LAN modes
+ - sr9800: Check for supported Wake-on-LAN modes
+ - r8152: Check for supported Wake-on-LAN Modes
+ - smsc75xx: Check for Wake-on-LAN modes
+ - smsc95xx: Check for Wake-on-LAN modes
+ - cfg80211: fix use-after-free in reg_process_hint()
+ - perf/core: Fix perf_pmu_unregister() locking
+ - perf/ring_buffer: Prevent concurent ring buffer access
+ - perf/x86/intel/uncore: Fix PCI BDF address of M3UPI on SKX
+ - perf/x86/amd/uncore: Set ThreadMask and SliceMask for L3 Cache perf events
+ - net: fec: fix rare tx timeout
+ - declance: Fix continuation with the adapter identification message
+ - locking/ww_mutex: Fix runtime warning in the WW mutex selftest
+ - be2net: don't flip hw_features when VXLANs are added/deleted
+ - net: cxgb3_main: fix a missing-check bug
+ - yam: fix a missing-check bug
+ - ocfs2: fix crash in ocfs2_duplicate_clusters_by_page()
+ - iwlwifi: mvm: check for short GI only for OFDM
+ - iwlwifi: dbg: allow wrt collection before ALIVE
+ - iwlwifi: fix the ALIVE notification layout
+ - usbip: vhci_hcd: update 'status' file header and format
+ - net/mlx5: Fix mlx5_get_vector_affinity function
+ - powerpc/pseries: Add empty update_numa_cpu_lookup_table() for NUMA=n
+ - dm integrity: fail early if required HMAC key is not available
+ - net: phy: realtek: Use the dummy stubs for MMD register access for rtl8211b
+ - net: phy: Add general dummy stubs for MMD register access
+ - scsi: qla2xxx: Avoid double completion of abort command
+ - kbuild: set no-integrated-as before incl. arch Makefile
+ - IB/mlx5: Avoid passing an invalid QP type to firmware
+ - l2tp: remove configurable payload offset
+ - cifs: Use ULL suffix for 64-bit constant
+ - KVM: x86: Update the exit_qualification access bits while walking an address
+ - sparc64: Fix regression in pmdp_invalidate().
+ - tpm: move the delay_msec increment after sleep in tpm_transmit()
+ - bpf: sockmap, map_release does not hold refcnt for pinned maps
+ - tpm: tpm_crb: relinquish locality on error path.
+ - IB/usnic: Update with bug fixes from core code
+ - mmc: dw_mmc-rockchip: correct property names in debug
+ - MIPS: Workaround GCC __builtin_unreachable reordering bug
+ - iio: buffer: fix the function signature to match implementation
+ - selftests/powerpc: Add ptrace hw breakpoint test
+ - scsi: ibmvfc: Avoid unnecessary port relogin
+ - scsi: sd: Remember that READ CAPACITY(16) succeeded
+ - btrfs: quota: Set rescan progress to (u64)-1 if we hit last leaf
+ - net: phy: phylink: Don't release NULL GPIO
+ - x86/paravirt: Fix some warning messages
+ - net: stmmac: mark PM functions as __maybe_unused
+ - kconfig: fix the rule of mainmenu_stmt symbol
+ - libertas: call into generic suspend code before turning off power
+ - compiler.h: Allow arch-specific asm/compiler.h
+ - ARM: dts: imx53-qsb: disable 1.2GHz OPP
+ - perf python: Use -Wno-redundant-decls to build with PYTHON=python3
+ - rxrpc: Don't check RXRPC_CALL_TX_LAST after calling rxrpc_rotate_tx_window()
+ - rxrpc: Only take the rwind and mtu values from latest ACK
+ - rxrpc: Fix connection-level abort handling
+ - selftests: rtnetlink.sh explicitly requires bash.
+ - fs/fat/fatent.c: add cond_resched() to fat_count_free_clusters()
+ - mtd: spi-nor: Add support for is25wp series chips
+ - ARM: dts: r8a7790: Correct critical CPU temperature
+ - media: uvcvideo: Fix driver reference counting
+ - Revert "netfilter: ipv6: nf_defrag: drop skb dst before queueing"
+ - perf tools: Disable parallelism for 'make clean'
+ - drm/i915/gvt: fix memory leak of a cmd_entry struct on error exit path
+ - bridge: do not add port to router list when receives query with source
+ 0.0.0.0
+ - net: bridge: remove ipv6 zero address check in mcast queries
+ - ipv6: mcast: fix a use-after-free in inet6_mc_check
+ - ipv6/ndisc: Preserve IPv6 control buffer if protocol error handlers are
+ called
+ - llc: set SOCK_RCU_FREE in llc_sap_add_socket()
+ - net: fec: don't dump RX FIFO register when not available
+ - net/ipv6: Fix index counter for unicast addresses in in6_dump_addrs
+ - net: sched: gred: pass the right attribute to gred_change_table_def()
+ - net: socket: fix a missing-check bug
+ - net: stmmac: Fix stmmac_mdio_reset() when building stmmac as modules
+ - net: udp: fix handling of CHECKSUM_COMPLETE packets
+ - r8169: fix NAPI handling under high load
+ - sctp: fix race on sctp_id2asoc
+ - udp6: fix encap return code for resubmitting
+ - virtio_net: avoid using netif_tx_disable() for serializing tx routine
+ - ethtool: fix a privilege escalation bug
+ - bonding: fix length of actor system
+ - ip6_tunnel: Fix encapsulation layout
+ - openvswitch: Fix push/pop ethernet validation
+ - net/mlx5: Take only bit 24-26 of wqe.pftype_wq for page fault type
+ - net: sched: Fix for duplicate class dump
+ - net: drop skb on failure in ip_check_defrag()
+ - net: fix pskb_trim_rcsum_slow() with odd trim offset
+ - net/mlx5e: fix csum adjustments caused by RXFCS
+ - rtnetlink: Disallow FDB configuration for non-Ethernet device
+ - net: ipmr: fix unresolved entry dumps
+ - net: bcmgenet: Poll internal PHY for GENETv5
+ - net/sched: cls_api: add missing validation of netlink attributes
+ - net/mlx5: Fix build break when CONFIG_SMP=n
+ - mac80211_hwsim: fix locking when iterating radios during ns exit
+ - rxrpc: Fix checks as to whether we should set up a new call
+ - rxrpc: Fix transport sockopts to get IPv4 errors on an IPv6 socket
+ - thunderbolt: Do not handle ICM events after domain is stopped
+ - thunderbolt: Initialize after IOMMUs
+ - RISCV: Fix end PFN for low memory
+ - drm/amd/display: Signal hw_done() after waiting for flip_done()
+ - powerpc/numa: Skip onlining a offline node in kdump path
+ - mm/gup_benchmark: fix unsigned comparison to zero in __gup_benchmark_ioctl
+ - perf report: Don't try to map ip to invalid map
+ - perf record: Use unmapped IP for inline callchain cursors
+ - rxrpc: Carry call state out of locked section in rxrpc_rotate_tx_window()
+ - gpio: Assign gpio_irq_chip::parents to non-stack pointer
+ - IB/mlx5: Unmap DMA addr from HCA before IOMMU
+ - rds: RDS (tcp) hangs on sendto() to unresponding address
+ - sparc64: Export __node_distance.
+ - sparc64: Make corrupted user stacks more debuggable.
+ - sparc64: Make proc_id signed.
+ - sparc64: Set %l4 properly on trap return after handling signals.
+ - sparc: Fix single-pcr perf event counter management.
+ - sparc: Fix syscall fallback bugs in VDSO.
+ - sparc: Throttle perf events properly.
+ - eeprom: at24: Add support for address-width property
+ - vfs: swap names of {do,vfs}_clone_file_range()
+ - bpf: fix partial copy of map_ptr when dst is scalar
+ - gpio: mxs: Get rid of external API call
+ - xfs: truncate transaction does not modify the inobt
+ - cachefiles: fix the race between cachefiles_bury_object() and rmdir(2)
+ - drm/edid: VSDB yCBCr420 Deep Color mode bit definitions
+ - drm: fb-helper: Reject all pixel format changing requests
+ - cdc-acm: do not reset notification buffer index upon urb unlinking
+ - cdc-acm: correct counting of UART states in serial state notification
+ - cdc-acm: fix race between reset and control messaging
+ - usb: usbip: Fix BUG: KASAN: slab-out-of-bounds in vhci_hub_control()
+ - USB: fix the usbfs flag sanitization for control transfers
+ - Input: elan_i2c - add ACPI ID for Lenovo IdeaPad 330-15IGM
+ - sched/fair: Fix throttle_list starvation with low CFS quota
+ - x86/tsc: Force inlining of cyc2ns bits
+ - x86, hibernate: Fix nosave_regions setup for hibernation
+ - x86/percpu: Fix this_cpu_read()
+ - x86/time: Correct the attribute on jiffies' definition
+ - x86/fpu: Fix i486 + no387 boot crash by only saving FPU registers on context
+ switch if there is an FPU
+ - clk: sunxi-ng: sun4i: Set VCO and PLL bias current to lowest setting
+ - drm/sun4i: Fix an ulong overflow in the dotclock driver
+ - x86/swiotlb: Enable swiotlb for > 4GiG RAM on 32-bit kernels
+
+ * Colour banding in HP Pavilion 15-n233sl integrated display (LP: #1794387) //
+ Bionic update: upstream stable patchset 2019-07-15 (LP: #1836654)
+ - drm/edid: Add 6 bpc quirk for BOE panel in HP Pavilion 15-n233sl
+
+ * Bionic update: upstream stable patchset 2019-07-12 (LP: #1836426)
+ - drm/amd/pp: initialize result to before or'ing in data
+ - drm/amdgpu: add another ATPX quirk for TOPAZ
+ - tools/power turbostat: fix possible sprintf buffer overflow
+ - mac80211: Run TXQ teardown code before de-registering interfaces
+ - mac80211_hwsim: require at least one channel
+ - btrfs: btrfs_shrink_device should call commit transaction at the end
+ - scsi: csiostor: add a check for NULL pointer after kmalloc()
+ - mac80211: correct use of IEEE80211_VHT_CAP_RXSTBC_X
+ - mac80211_hwsim: correct use of IEEE80211_VHT_CAP_RXSTBC_X
+ - gpio: adp5588: Fix sleep-in-atomic-context bug
+ - mac80211: mesh: fix HWMP sequence numbering to follow standard
+ - mac80211: avoid kernel panic when building AMSDU from non-linear SKB
+ - gpiolib: acpi: Switch to cansleep version of GPIO library call
+ - gpiolib-acpi: Register GpioInt ACPI event handlers from a late_initcall
+ - cfg80211: nl80211_update_ft_ies() to validate NL80211_ATTR_IE
+ - mac80211: do not convert to A-MSDU if frag/subframe limited
+ - mac80211: always account for A-MSDU header changes
+ - tools/kvm_stat: fix handling of invalid paths in debugfs provider
+ - gpio: Fix crash due to registration race
+ - ARC: atomics: unbork atomic_fetch_##op()
+ - md/raid5-cache: disable reshape completely
+ - RAID10 BUG_ON in raise_barrier when force is true and conf->barrier is 0
+ - i2c: uniphier: issue STOP only for last message or I2C_M_STOP
+ - i2c: uniphier-f: issue STOP only for last message or I2C_M_STOP
+ - net: cadence: Fix a sleep-in-atomic-context bug in macb_halt_tx()
+ - fs/cifs: don't translate SFM_SLASH (U+F026) to backslash
+ - mac80211: fix an off-by-one issue in A-MSDU max_subframe computation
+ - cfg80211: fix a type issue in ieee80211_chandef_to_operating_class()
+ - mac80211: fix a race between restart and CSA flows
+ - mac80211: Fix station bandwidth setting after channel switch
+ - mac80211: don't Tx a deauth frame if the AP forbade Tx
+ - mac80211: shorten the IBSS debug messages
+ - tools/vm/slabinfo.c: fix sign-compare warning
+ - tools/vm/page-types.c: fix "defined but not used" warning
+ - mm: madvise(MADV_DODUMP): allow hugetlbfs pages
+ - netfilter: xt_cluster: add dependency on conntrack module
+ - HID: add support for Apple Magic Keyboards
+ - usb: gadget: fotg210-udc: Fix memory leak of fotg210->ep[i]
+ - HID: hid-saitek: Add device ID for RAT 7 Contagion
+ - scsi: qedi: Add the CRC size within iSCSI NVM image
+ - perf evsel: Fix potential null pointer dereference in perf_evsel__new_idx()
+ - perf util: Fix bad memory access in trace info.
+ - perf probe powerpc: Ignore SyS symbols irrespective of endianness
+ - netfilter: nf_tables: release chain in flushing set
+ - Revert "iio: temperature: maxim_thermocouple: add MAX31856 part"
+ - RDMA/ucma: check fd type in ucma_migrate_id()
+ - HID: sensor-hub: Restore fixup for Lenovo ThinkPad Helix 2 sensor hub report
+ - USB: yurex: Check for truncation in yurex_read()
+ - nvmet-rdma: fix possible bogus dereference under heavy load
+ - net/mlx5: Consider PCI domain in search for next dev
+ - drm/nouveau/TBDdevinit: don't fail when PMU/PRE_OS is missing from VBIOS
+ - drm/nouveau/disp: fix DP disable race
+ - dm raid: fix rebuild of specific devices by updating superblock
+ - fs/cifs: suppress a string overflow warning
+ - perf/x86/intel: Add support/quirk for the MISPREDICT bit on Knights Landing
+ CPUs
+ - dm thin metadata: try to avoid ever aborting transactions
+ - arch/hexagon: fix kernel/dma.c build warning
+ - hexagon: modify ffs() and fls() to return int
+ - arm64: jump_label.h: use asm_volatile_goto macro instead of "asm goto"
+ - drm/amdgpu: fix error handling in amdgpu_cs_user_fence_chunk
+ - r8169: Clear RTL_FLAG_TASK_*_PENDING when clearing RTL_FLAG_TASK_ENABLED
+ - s390/qeth: don't dump past end of unknown HW header
+ - cifs: read overflow in is_valid_oplock_break()
+ - xen/manage: don't complain about an empty value in control/sysrq node
+ - xen: avoid crash in disable_hotplug_cpu
+ - xen: fix GCC warning and remove duplicate EVTCHN_ROW/EVTCHN_COL usage
+ - ovl: fix access beyond unterminated strings
+ - ovl: fix memory leak on unlink of indexed file
+ - ovl: fix format of setxattr debug
+ - sysfs: Do not return POSIX ACL xattrs via listxattr
+ - smb2: fix missing files in root share directory listing
+ - iommu/amd: Clear memory encryption mask from physical address
+ - crypto: qat - Fix KASAN stack-out-of-bounds bug in adf_probe()
+ - crypto: mxs-dcp - Fix wait logic on chan threads
+ - crypto: caam/jr - fix ablkcipher_edesc pointer arithmetic
+ - gpiolib: Free the last requested descriptor
+ - Drivers: hv: vmbus: Use get/put_cpu() in vmbus_connect()
+ - tools: hv: fcopy: set 'error' in case an unknown operation was requested
+ - ocfs2: fix locking for res->tracking and dlm->tracking_list
+ - ixgbe: check return value of napi_complete_done()
+ - dm thin metadata: fix __udivdi3 undefined on 32-bit
+ - Btrfs: fix unexpected failure of nocow buffered writes after snapshotting
+ when low on space
+ - scsi: aacraid: fix a signedness bug
+ - tipc: switch to rhashtable iterator
+ - net: mvpp2: initialize port of_node pointer
+ - tc-testing: add test-cases for numeric and invalid control action
+ - tools/kvm_stat: fix updates for dead guests
+ - ibmvnic: Include missing return code checks in reset function
+ - net/ibm/emac: wrong emac_calc_base call was used by typo
+ - ceph: avoid a use-after-free in ceph_destroy_options()
+ - afs: Fix cell specification to permit an empty address list
+ - netfilter: xt_checksum: ignore gso skbs
+ - HID: intel-ish-hid: Enable Sunrise Point-H ish driver
+ - iio: imu: st_lsm6dsx: take into account ts samples in wm configuration
+ - riscv: Do not overwrite initrd_start and initrd_end
+ - drm/nouveau: fix oops in client init failure path
+ - drm/nouveau/mmu: don't attempt to dereference vmm without valid instance
+ pointer
+ - drm/nouveau/disp/gm200-: enforce identity-mapped SOR assignment for LVDS/eDP
+ panels
+ - sched/topology: Set correct NUMA topology type
+ - drm/amdgpu: Fix SDMA hang in prt mode v2
+ - asm-generic: io: Fix ioport_map() for !CONFIG_GENERIC_IOMAP &&
+ CONFIG_INDIRECT_PIO
+ - x86/APM: Fix build warning when PROC_FS is not enabled
+ - new primitive: discard_new_inode()
+ - ovl: set I_CREATING on inode being created
+ - crypto: chelsio - Fix memory corruption in DMA Mapped buffers.
+ - perf/core: Add sanity check to deal with pinned event failure
+ - mm: migration: fix migration of huge PMD shared pages
+ - mm, thp: fix mlocking THP page with migration enabled
+ - mm/vmstat.c: skip NR_TLB_REMOTE_FLUSH* properly
+ - KVM: x86: fix L1TF's MMIO GFN calculation
+ - blk-mq: I/O and timer unplugs are inverted in blktrace
+ - clocksource/drivers/timer-atmel-pit: Properly handle error cases
+ - fbdev/omapfb: fix omapfb_memory_read infoleak
+ - drm/amdgpu: Fix vce work queue was not cancelled when suspend
+ - x86/vdso: Fix asm constraints on vDSO syscall fallbacks
+ - selftests/x86: Add clock_gettime() tests to test_vdso
+ - x86/vdso: Only enable vDSO retpolines when enabled and supported
+ - x86/vdso: Fix vDSO syscall fallback asm constraint regression
+ - mac80211: fix setting IEEE80211_KEY_FLAG_RX_MGMT for AP mode keys
+ - PM / core: Clear the direct_complete flag on errors
+ - dm cache metadata: ignore hints array being too small during resize
+ - dm cache: fix resize crash if user doesn't reload cache table
+ - xhci: Add missing CAS workaround for Intel Sunrise Point xHCI
+ - usb: xhci-mtk: resume USB3 roothub first
+ - USB: serial: simple: add Motorola Tetra MTP6550 id
+ - usb: cdc_acm: Do not leak URB buffers
+ - of: unittest: Disable interrupt node tests for old world MAC systems
+ - perf annotate: Use asprintf when formatting objdump command line
+ - perf tools: Fix python extension build for gcc 8
+ - ath10k: fix use-after-free in ath10k_wmi_cmd_send_nowait
+ - ath10k: fix kernel panic issue during pci probe
+ - nvme_fc: fix ctrl create failures racing with workq items
+ - powerpc/lib: fix book3s/32 boot failure due to code patching
+ - ARC: clone syscall to setp r25 as thread pointer
+ - perf utils: Move is_directory() to path.h
+ - f2fs: fix invalid memory access
+ - ucma: fix a use-after-free in ucma_resolve_ip()
+ - ubifs: Check for name being NULL while mounting
+ - rds: rds_ib_recv_alloc_cache() should call alloc_percpu_gfp() instead
+ - ath10k: fix scan crash due to incorrect length calculation
+ - pstore/ram: Fix failure-path memory leak in ramoops_init
+ - mac80211: allocate TXQs for active monitor interfaces
+ - drm: fix use-after-free read in drm_mode_create_lease_ioctl()
+ - USB: serial: option: improve Quectel EP06 detection
+ - USB: serial: option: add two-endpoints device-id flag
+ - tipc: call start and done ops directly in __tipc_nl_compat_dumpit()
+ - bnxt_en: Fix TX timeout during netpoll.
+ - bnxt_en: free hwrm resources, if driver probe fails.
+ - bonding: avoid possible dead-lock
+ - ip6_tunnel: be careful when accessing the inner header
+ - ip_tunnel: be careful when accessing the inner header
+ - ipv4: fix use-after-free in ip_cmsg_recv_dstaddr()
+ - ipv6: take rcu lock in rawv6_send_hdrinc()
+ - net: dsa: bcm_sf2: Call setup during switch resume
+ - net: hns: fix for unmapping problem when SMMU is on
+ - net: ipv4: update fnhe_pmtu when first hop's MTU changes
+ - net/ipv6: Display all addresses in output of /proc/net/if_inet6
+ - netlabel: check for IPV4MASK in addrinfo_get
+ - net: mvpp2: Extract the correct ethtype from the skb for tx csum offload
+ - net: mvpp2: fix a txq_done race condition
+ - net: sched: Add policy validation for tc attributes
+ - net: systemport: Fix wake-up interrupt race during resume
+ - net/usb: cancel pending work when unbinding smsc75xx
+ - qmi_wwan: Added support for Gemalto's Cinterion ALASxx WWAN interface
+ - rtnl: limit IFLA_NUM_TX_QUEUES and IFLA_NUM_RX_QUEUES to 4096
+ - sctp: update dst pmtu with the correct daddr
+ - team: Forbid enslaving team device to itself
+ - tipc: fix flow control accounting for implicit connect
+ - udp: Unbreak modules that rely on external __skb_recv_udp() availability
+ - net: stmmac: Fixup the tail addr setting in xmit path
+ - net/packet: fix packet drop as of virtio gso
+ - net: dsa: bcm_sf2: Fix unbind ordering
+ - net/mlx5e: Set vlan masks for all offloaded TC rules
+ - net: aquantia: memory corruption on jumbo frames
+ - net/mlx5: E-Switch, Fix out of bound access when setting vport rate
+ - bonding: pass link-local packets to bonding master also.
+ - bonding: fix warning message
+ - nfp: avoid soft lockups under control message storm
+ - bnxt_en: don't try to offload VLAN 'modify' action
+ - net-ethtool: ETHTOOL_GUFO did not and should not require CAP_NET_ADMIN
+ - tcp/dccp: fix lockdep issue when SYN is backlogged
+ - inet: make sure to grab rcu_read_lock before using ireq->ireq_opt
+ - ASoC: rt5514: Fix the issue of the delay volume applied again
+ - ASoC: wm8804: Add ACPI support
+ - ASoC: sigmadsp: safeload should not have lower byte limit
+ - selftests/efivarfs: add required kernel configs
+ - selftests: memory-hotplug: add required configs
+ - ASoC: rsnd: adg: care clock-frequency size
+ - ASoC: rsnd: don't fallback to PIO mode when -EPROBE_DEFER
+ - Bluetooth: hci_ldisc: Free rw_semaphore on close
+ - mfd: omap-usb-host: Fix dts probe of children
+ - scsi: iscsi: target: Don't use stack buffer for scatterlist
+ - scsi: qla2xxx: Fix an endian bug in fcpcmd_is_corrupted()
+ - sound: enable interrupt after dma buffer initialization
+ - sound: don't call skl_init_chip() to reset intel skl soc
+ - stmmac: fix valid numbers of unicast filter entries
+ - net: macb: disable scatter-gather for macb on sama5d3
+ - ARM: dts: at91: add new compatibility string for macb on sama5d3
+ - PCI: hv: support reporting serial number as slot information
+ - clk: x86: add "ether_clk" alias for Bay Trail / Cherry Trail
+ - clk: x86: Stop marking clocks as CLK_IS_CRITICAL
+ - x86/kvm/lapic: always disable MMIO interface in x2APIC mode
+ - drm/amdgpu: Fix SDMA HQD destroy error on gfx_v7
+ - mm/vmstat.c: fix outdated vmstat_text
+ - MIPS: VDSO: Always map near top of user memory
+ - mach64: detect the dot clock divider correctly on sparc
+ - percpu: stop leaking bitmap metadata blocks
+ - perf script python: Fix export-to-postgresql.py occasional failure
+ - perf script python: Fix export-to-sqlite.py sample columns
+ - s390/cio: Fix how vfio-ccw checks pinned pages
+ - dm cache: destroy migration_cache if cache target registration failed
+ - dm: fix report zone remapping to account for partition offset
+ - dm linear: eliminate linear_end_io call if CONFIG_DM_ZONED disabled
+ - dm linear: fix linear_end_io conditional definition
+ - cgroup: Fix dom_cgrp propagation when enabling threaded mode
+ - mmc: block: avoid multiblock reads for the last sector in SPI mode
+ - pinctrl: mcp23s08: fix irq and irqchip setup order
+ - arm64: perf: Reject stand-alone CHAIN events for PMUv3
+ - mm/thp: fix call to mmu_notifier in set_pmd_migration_entry() v2
+ - mm: Preserve _PAGE_DEVMAP across mprotect() calls
+ - i2c: i2c-scmi: fix for i2c_smbus_write_block_data
+ - xhci: Don't print a warning when setting link state for disabled ports
+ - mm: introduce NR_INDIRECTLY_RECLAIMABLE_BYTES
+ - mm: treat indirectly reclaimable memory as available in MemAvailable
+ - dcache: account external names as indirectly reclaimable memory
+ - mm: treat indirectly reclaimable memory as free in overcommit logic
+ - mm: don't show nr_indirectly_reclaimable in /proc/vmstat
+ - ARM: add more CPU part numbers for Cortex and Brahma B15 CPUs
+ - ARM: bugs: prepare processor bug infrastructure
+ - ARM: bugs: hook processor bug checking into SMP and suspend paths
+ - ARM: bugs: add support for per-processor bug checking
+ - [Config] updateconfigs for CPU_SPECTRE
+ - ARM: spectre: add Kconfig symbol for CPUs vulnerable to Spectre
+ - ARM: spectre-v2: harden branch predictor on context switches
+ - ARM: spectre-v2: add Cortex A8 and A15 validation of the IBE bit
+ - ARM: spectre-v2: harden user aborts in kernel space
+ - ARM: spectre-v2: add firmware based hardening
+ - ARM: spectre-v2: warn about incorrect context switching functions
+ - ARM: KVM: invalidate BTB on guest exit for Cortex-A12/A17
+ - ARM: KVM: invalidate icache on guest exit for Cortex-A15
+ - ARM: spectre-v2: KVM: invalidate icache on guest exit for Brahma B15
+ - ARM: KVM: Add SMCCC_ARCH_WORKAROUND_1 fast handling
+ - ARM: KVM: report support for SMCCC_ARCH_WORKAROUND_1
+ - ARM: spectre-v1: add speculation barrier (csdb) macros
+ - ARM: spectre-v1: add array_index_mask_nospec() implementation
+ - ARM: spectre-v1: fix syscall entry
+ - ARM: signal: copy registers using __copy_from_user()
+ - ARM: vfp: use __copy_from_user() when restoring VFP state
+ - ARM: oabi-compat: copy semops using __copy_from_user()
+ - ARM: use __inttype() in get_user()
+ - ARM: spectre-v1: use get_user() for __get_user()
+ - ARM: spectre-v1: mitigate user accesses
+ - perf tools: Fix snprint warnings for gcc 8
+ - net: sched: cls_u32: fix hnode refcounting
+ - net: qualcomm: rmnet: Skip processing loopback packets
+ - net: qualcomm: rmnet: Fix incorrect allocation flag in transmit
+ - tun: remove unused parameters
+ - tun: initialize napi_mutex unconditionally
+ - tun: napi flags belong to tfile
+ - net: dsa: b53: Keep CPU port as tagged in all VLANs
+ - rtnetlink: Fail dump if target netnsid is invalid
+ - net: ipv4: don't let PMTU updates increase route MTU
+ - ASoC: dapm: Fix NULL pointer deference on CODEC to CODEC DAIs
+ - selftests: android: move config up a level
+ - selftests: add headers_install to lib.mk
+ - Bluetooth: SMP: Fix trying to use non-existent local OOB data
+ - Bluetooth: Use correct tfm to generate OOB data
+ - net: ethernet: ti: add missing GENERIC_ALLOCATOR dependency
+ - afs: Fix afs_server struct leak
+ - afs: Fix clearance of reply
+
+ * Volume control not working Dell XPS 27 (7760) (LP: #1775068) // Bionic
+ update: upstream stable patchset 2019-07-12 (LP: #1836426)
+ - ALSA: hda/realtek - Cannot adjust speaker's volume on Dell XPS 27 7760
+
+ * Bionic update: upstream stable patchset 2019-07-11 (LP: #1836287)
+ - perf tools: Fix undefined symbol scnprintf in libperf-jvmti.so
+ - gso_segment: Reset skb->mac_len after modifying network header
+ - ipv6: fix possible use-after-free in ip6_xmit()
+ - net/appletalk: fix minor pointer leak to userspace in SIOCFINDIPDDPRT
+ - net: hp100: fix always-true check for link up state
+ - pppoe: fix reception of frames with no mac header
+ - qmi_wwan: set DTR for modems in forced USB2 mode
+ - udp4: fix IP_CMSG_CHECKSUM for connected sockets
+ - neighbour: confirm neigh entries when ARP packet is received
+ - udp6: add missing checks on edumux packet processing
+ - net/sched: act_sample: fix NULL dereference in the data path
+ - tls: don't copy the key out of tls12_crypto_info_aes_gcm_128
+ - tls: zero the crypto information from tls_context before freeing
+ - tls: clear key material from kernel memory when do_tls_setsockopt_conf fails
+ - NFC: Fix possible memory corruption when handling SHDLC I-Frame commands
+ - NFC: Fix the number of pipes
+ - ASoC: cs4265: fix MMTLR Data switch control
+ - ASoC: rsnd: fixup not to call clk_get/set under non-atomic
+ - ALSA: bebob: fix memory leak for M-Audio FW1814 and ProjectMix I/O at error
+ path
+ - ALSA: bebob: use address returned by kmalloc() instead of kernel stack for
+ streaming DMA mapping
+ - ALSA: emu10k1: fix possible info leak to userspace on
+ SNDRV_EMU10K1_IOCTL_INFO
+ - ALSA: fireface: fix memory leak in ff400_switch_fetching_mode()
+ - ALSA: firewire-digi00x: fix memory leak of private data
+ - ALSA: firewire-tascam: fix memory leak of private data
+ - ALSA: fireworks: fix memory leak of response buffer at error path
+ - ALSA: oxfw: fix memory leak for model-dependent data at error path
+ - ALSA: oxfw: fix memory leak of discovered stream formats at error path
+ - ALSA: oxfw: fix memory leak of private data
+ - platform/x86: alienware-wmi: Correct a memory leak
+ - xen/netfront: don't bug in case of too many frags
+ - xen/x86/vpmu: Zero struct pt_regs before calling into sample handling code
+ - spi: fix IDR collision on systems with both fixed and dynamic SPI bus
+ numbers
+ - ring-buffer: Allow for rescheduling when removing pages
+ - mm: shmem.c: Correctly annotate new inodes for lockdep
+ - scsi: target: iscsi: Use bin2hex instead of a re-implementation
+ - ocfs2: fix ocfs2 read block panic
+ - drm/nouveau: Fix deadlocks in nouveau_connector_detect()
+ - drm/nouveau/drm/nouveau: Don't forget to cancel hpd_work on suspend/unload
+ - drm/nouveau/drm/nouveau: Fix bogus drm_kms_helper_poll_enable() placement
+ - drm/nouveau/drm/nouveau: Use pm_runtime_get_noresume() in connector_detect()
+ - drm/nouveau/drm/nouveau: Prevent handling ACPI HPD events too early
+ - drm/vc4: Fix the "no scaling" case on multi-planar YUV formats
+ - drm: udl: Destroy framebuffer only if it was initialized
+ - drm/amdgpu: add new polaris pci id
+ - ext4: check to make sure the rename(2)'s destination is not freed
+ - ext4: avoid divide by zero fault when deleting corrupted inline directories
+ - ext4: avoid arithemetic overflow that can trigger a BUG
+ - ext4: recalucate superblock checksum after updating free blocks/inodes
+ - ext4: fix online resize's handling of a too-small final block group
+ - ext4: fix online resizing for bigalloc file systems with a 1k block size
+ - ext4: don't mark mmp buffer head dirty
+ - ext4: show test_dummy_encryption mount option in /proc/mounts
+ - sched/fair: Fix vruntime_normalized() for remote non-migration wakeup
+ - PCI: aardvark: Size bridges before resources allocation
+ - vmw_balloon: include asm/io.h
+ - iw_cxgb4: only allow 1 flush on user qps
+ - tick/nohz: Prevent bogus softirq pending warning
+ - spi: Fix double IDR allocation with DT aliases
+ - hv_netvsc: fix schedule in RCU context
+ - bnxt_en: Fix VF mac address regression.
+ - net: rtnl_configure_link: fix dev flags changes arg to __dev_notify_flags
+ - mtd: rawnand: denali: fix a race condition when DMA is kicked
+ - platform/x86: dell-smbios-wmi: Correct a memory leak
+ - fork: report pid exhaustion correctly
+ - mm: disable deferred struct page for 32-bit arches
+ - libata: mask swap internal and hardware tag
+ - drm/i915/bdw: Increase IPS disable timeout to 100ms
+ - drm/nouveau: Reset MST branching unit before enabling
+ - drm/nouveau: Only write DP_MSTM_CTRL when needed
+ - drm/nouveau: Remove duplicate poll_enable() in pmops_runtime_suspend()
+ - ext4, dax: set ext4_dax_aops for dax files
+ - crypto: skcipher - Fix -Wstringop-truncation warnings
+ - iio: adc: ina2xx: avoid kthread_stop() with stale task_struct
+ - tsl2550: fix lux1_input error in low light
+ - vmci: type promotion bug in qp_host_get_user_memory()
+ - x86/numa_emulation: Fix emulated-to-physical node mapping
+ - staging: rts5208: fix missing error check on call to rtsx_write_register
+ - power: supply: axp288_charger: Fix initial constant_charge_current value
+ - misc: sram: enable clock before registering regions
+ - serial: sh-sci: Stop RX FIFO timer during port shutdown
+ - uwb: hwa-rc: fix memory leak at probe
+ - power: vexpress: fix corruption in notifier registration
+ - iommu/amd: make sure TLB to be flushed before IOVA freed
+ - Bluetooth: Add a new Realtek 8723DE ID 0bda:b009
+ - USB: serial: kobil_sct: fix modem-status error handling
+ - 6lowpan: iphc: reset mac_header after decompress to fix panic
+ - iommu/msm: Don't call iommu_device_{,un}link from atomic context
+ - s390/mm: correct allocate_pgste proc_handler callback
+ - power: remove possible deadlock when unregistering power_supply
+ - md-cluster: clear another node's suspend_area after the copy is finished
+ - RDMA/bnxt_re: Fix a couple off by one bugs
+ - RDMA/i40w: Hold read semaphore while looking after VMA
+ - IB/core: type promotion bug in rdma_rw_init_one_mr()
+ - media: exynos4-is: Prevent NULL pointer dereference in __isp_video_try_fmt()
+ - IB/mlx4: Test port number before querying type.
+ - powerpc/kdump: Handle crashkernel memory reservation failure
+ - media: fsl-viu: fix error handling in viu_of_probe()
+ - media: staging/imx: fill vb2_v4l2_buffer field entry
+ - x86/tsc: Add missing header to tsc_msr.c
+ - ARM: hwmod: RTC: Don't assume lock/unlock will be called with irq enabled
+ - x86/entry/64: Add two more instruction suffixes
+ - ARM: dts: ls1021a: Add missing cooling device properties for CPUs
+ - scsi: target/iscsi: Make iscsit_ta_authentication() respect the output
+ buffer size
+ - scsi: klist: Make it safe to use klists in atomic context
+ - scsi: ibmvscsi: Improve strings handling
+ - scsi: target: Avoid that EXTENDED COPY commands trigger lock inversion
+ - usb: wusbcore: security: cast sizeof to int for comparison
+ - ath10k: sdio: use same endpoint id for all packets in a bundle
+ - ath10k: sdio: set skb len for all rx packets
+ - powerpc/powernv/ioda2: Reduce upper limit for DMA window size
+ - s390/sysinfo: add missing #ifdef CONFIG_PROC_FS
+ - alarmtimer: Prevent overflow for relative nanosleep
+ - s390/dasd: correct numa_node in dasd_alloc_queue
+ - s390/scm_blk: correct numa_node in scm_blk_dev_setup
+ - s390/extmem: fix gcc 8 stringop-overflow warning
+ - mtd: rawnand: atmel: add module param to avoid using dma
+ - iio: accel: adxl345: convert address field usage in iio_chan_spec
+ - posix-timers: Make forward callback return s64
+ - ALSA: snd-aoa: add of_node_put() in error path
+ - media: s3c-camif: ignore -ENOIOCTLCMD from v4l2_subdev_call for s_power
+ - media: soc_camera: ov772x: correct setting of banding filter
+ - media: omap3isp: zero-initialize the isp cam_xclk{a,b} initial data
+ - staging: android: ashmem: Fix mmap size validation
+ - drivers/tty: add error handling for pcmcia_loop_config
+ - media: tm6000: add error handling for dvb_register_adapter
+ - net: phy: xgmiitorgmii: Check read_status results
+ - ath10k: protect ath10k_htt_rx_ring_free with rx_ring.lock
+ - net: phy: xgmiitorgmii: Check phy_driver ready before accessing
+ - drm/sun4i: Fix releasing node when enumerating enpoints
+ - ath10k: transmit queued frames after processing rx packets
+ - rndis_wlan: potential buffer overflow in rndis_wlan_auth_indication()
+ - brcmsmac: fix wrap around in conversion from constant to s16
+ - ARM: mvebu: declare asm symbols as character arrays in pmsu.c
+ - arm: dts: mediatek: Add missing cooling device properties for CPUs
+ - HID: hid-ntrig: add error handling for sysfs_create_group
+ - MIPS: boot: fix build rule of vmlinux.its.S
+ - perf/x86/intel/lbr: Fix incomplete LBR call stack
+ - scsi: bnx2i: add error handling for ioremap_nocache
+ - iomap: complete partial direct I/O writes synchronously
+ - scsi: megaraid_sas: Update controller info during resume
+ - EDAC, i7core: Fix memleaks and use-after-free on probe and remove
+ - ASoC: dapm: Fix potential DAI widget pointer deref when linking DAIs
+ - module: exclude SHN_UNDEF symbols from kallsyms api
+ - gpio: Fix wrong rounding in gpio-menz127
+ - nfsd: fix corrupted reply to badly ordered compound
+ - EDAC: Fix memleak in module init error path
+ - fs/lock: skip lock owner pid translation in case we are in init_pid_ns
+ - Input: xen-kbdfront - fix multi-touch XenStore node's locations
+ - iio: 104-quad-8: Fix off-by-one error in register selection
+ - ARM: dts: dra7: fix DCAN node addresses
+ - x86/mm: Expand static page table for fixmap space
+ - tty: serial: lpuart: avoid leaking struct tty_struct
+ - serial: cpm_uart: return immediately from console poll
+ - intel_th: Fix device removal logic
+ - spi: tegra20-slink: explicitly enable/disable clock
+ - spi: sh-msiof: Fix invalid SPI use during system suspend
+ - spi: sh-msiof: Fix handling of write value for SISTR register
+ - spi: rspi: Fix invalid SPI use during system suspend
+ - spi: rspi: Fix interrupted DMA transfers
+ - regulator: fix crash caused by null driver data
+ - USB: fix error handling in usb_driver_claim_interface()
+ - USB: handle NULL config in usb_find_alt_setting()
+ - usb: musb: dsps: do not disable CPPI41 irq in driver teardown
+ - slub: make ->cpu_partial unsigned int
+ - USB: usbdevfs: sanitize flags more
+ - USB: usbdevfs: restore warning for nonsensical flags
+ - USB: remove LPM management from usb_driver_claim_interface()
+ - IB/srp: Avoid that sg_reset -d ${srp_device} triggers an infinite loop
+ - IB/hfi1: Fix SL array bounds check
+ - IB/hfi1: Invalid user input can result in crash
+ - IB/hfi1: Fix context recovery when PBC has an UnsupportedVL
+ - RDMA/uverbs: Atomically flush and mark closed the comp event queue
+ - ovl: hash non-dir by lower inode for fsnotify
+ - drm/i915: Remove vma from object on destroy, not close
+ - serial: imx: restore handshaking irq for imx1
+ - qed: Wait for ready indication before rereading the shmem
+ - qed: Wait for MCP halt and resume commands to take place
+ - qed: Prevent a possible deadlock during driver load and unload
+ - qed: Avoid sending mailbox commands when MFW is not responsive
+ - thermal: of-thermal: disable passive polling when thermal zone is disabled
+ - isofs: reject hardware sector size > 2048 bytes
+ - tls: possible hang when do_tcp_sendpages hits sndbuf is full case
+ - bpf: sockmap: write_space events need to be passed to TCP handler
+ - net: hns: fix length and page_offset overflow when CONFIG_ARM64_64K_PAGES
+ - e1000: check on netif_running() before calling e1000_up()
+ - e1000: ensure to free old tx/rx rings in set_ringparam()
+ - crypto: cavium/nitrox - fix for command corruption in queue full case with
+ backlog submissions.
+ - hwmon: (ina2xx) fix sysfs shunt resistor read access
+ - hwmon: (adt7475) Make adt7475_read_word() return errors
+ - Revert "ARM: dts: imx7d: Invert legacy PCI irq mapping"
+ - drm/amdgpu: Enable/disable gfx PG feature in rlc safe mode
+ - drm/amdgpu: Update power state at the end of smu hw_init.
+ - ata: ftide010: Add a quirk for SQ201
+ - nvme-fcloop: Fix dropped LS's to removed target port
+ - ARM: dts: omap4-droid4: Fix emmc errors seen on some devices
+ - arm/arm64: smccc-1.1: Make return values unsigned long
+ - arm/arm64: smccc-1.1: Handle function result as parameters
+ - i2c: i801: Allow ACPI AML access I/O ports not reserved for SMBus
+ - x86/pti: Fix section mismatch warning/error
+ - media: v4l: event: Prevent freeing event subscriptions while accessed
+ - drm/amd/display/dc/dce: Fix multiple potential integer overflows
+ - drm/amd/display: fix use of uninitialized memory
+ - RDMA/bnxt_re: Fix a bunch of off by one bugs in qplib_fp.c
+ - vhost_net: Avoid tx vring kicks during busyloop
+ - thermal: i.MX: Allow thermal probe to fail gracefully in case of bad
+ calibration.
+ - platform/x86: asus-wireless: Fix uninitialized symbol usage
+ - ACPI / button: increment wakeup count only when notified
+ - media: ov772x: add checks for register read errors
+ - media: ov772x: allow i2c controllers without I2C_FUNC_PROTOCOL_MANGLING
+ - drm/omap: gem: Fix mm_list locking
+ - ASoC: rsnd: SSI parent cares SWSP bit
+ - staging: pi433: fix race condition in pi433_ioctl
+ - perf tests: Fix indexing when invoking subtests
+ - gpio: tegra: Fix tegra_gpio_irq_set_type()
+ - block: fix deadline elevator drain for zoned block devices
+ - serial: mvebu-uart: Fix reporting of effective CSIZE to userspace
+ - intel_th: Fix resource handling for ACPI glue layer
+ - ext2, dax: set ext2_dax_aops for dax files
+ - IB/hfi1: Fix destroy_qp hang after a link down
+ - ARM: OMAP2+: Fix null hwmod for ti-sysc debug
+ - ARM: OMAP2+: Fix module address for modules using mpu_rt_idx
+ - bus: ti-sysc: Fix module register ioremap for larger offsets
+ - drm/amdgpu: fix preamble handling
+ - amdgpu: fix multi-process hang issue
+ - tcp_bbr: add bbr_check_probe_rtt_done() helper
+ - tcp_bbr: in restart from idle, see if we should exit PROBE_RTT
+ - net: hns3: fix page_offset overflow when CONFIG_ARM64_64K_PAGES
+ - ixgbe: fix driver behaviour after issuing VFLR
+ - powerpc/pseries: Fix unitialized timer reset on migration
+
+ * Kernel 4.15.0-50 or newer wont boot as Xen-DomU with PVH (LP: #1829378)
+ - SAUCE: ACPI / bus: Fix NULL pointer dereference in
+ acpi_quirk_matches_bios_ids()
+
+ * CVE-2019-10126
+ - mwifiex: Fix heap overflow in mwifiex_uap_parse_tail_ies()
+
+ * CVE-2019-3846
+ - mwifiex: Fix possible buffer overflows at parsing bss descriptor
+
+ * CVE-2019-12818
+ - net: nfc: Fix NULL dereference on nfc_llcp_build_tlv fails
+
+ * CVE-2019-12984
+ - nfc: Ensure presence of required attributes in the deactivate_target handler
+
+ * Bionic update: upstream stable patchset 2019-07-10 (LP: #1836117)
+ - i2c: xiic: Make the start and the byte count write atomic
+ - i2c: i801: fix DNV's SMBCTRL register offset
+ - scsi: lpfc: Correct MDS diag and nvmet configuration
+ - nbd: don't allow invalid blocksize settings
+ - block: bfq: swap puts in bfqg_and_blkg_put
+ - android: binder: fix the race mmap and alloc_new_buf_locked
+ - MIPS: VDSO: Match data page cache colouring when D$ aliases
+ - SMB3: Backup intent flag missing for directory opens with backupuid mounts
+ - smb3: check for and properly advertise directory lease support
+ - Btrfs: fix data corruption when deduplicating between different files
+ - KVM: s390: vsie: copy wrapping keys to right place
+ - KVM: VMX: Do not allow reexecute_instruction() when skipping MMIO instr
+ - ALSA: hda - Fix cancel_work_sync() stall from jackpoll work
+ - cpu/hotplug: Adjust misplaced smb() in cpuhp_thread_fun()
+ - cpu/hotplug: Prevent state corruption on error rollback
+ - x86/microcode: Make sure boot_cpu_data.microcode is up-to-date
+ - x86/microcode: Update the new microcode revision unconditionally
+ - crypto: aes-generic - fix aes-generic regression on powerpc
+ - tpm: separate cmd_ready/go_idle from runtime_pm
+ - ARC: [plat-axs*]: Enable SWAP
+ - misc: mic: SCIF Fix scif_get_new_port() error handling
+ - ethtool: Remove trailing semicolon for static inline
+ - i2c: aspeed: Add an explicit type casting for *get_clk_reg_val
+ - Bluetooth: h5: Fix missing dependency on BT_HCIUART_SERDEV
+ - gpio: tegra: Move driver registration to subsys_init level
+ - selftests/bpf: fix a typo in map in map test
+ - media: davinci: vpif_display: Mix memory leak on probe error path
+ - media: dw2102: Fix memleak on sequence of probes
+ - net: phy: Fix the register offsets in Broadcom iProc mdio mux driver
+ - blk-mq: fix updating tags depth
+ - scsi: target: fix __transport_register_session locking
+ - md/raid5: fix data corruption of replacements after originals dropped
+ - timers: Clear timer_base::must_forward_clk with timer_base::lock held
+ - media: camss: csid: Configure data type and decode format properly
+ - gpu: ipu-v3: default to id 0 on missing OF alias
+ - misc: ti-st: Fix memory leak in the error path of probe()
+ - uio: potential double frees if __uio_register_device() fails
+ - firmware: vpd: Fix section enabled flag on vpd_section_destroy
+ - Drivers: hv: vmbus: Cleanup synic memory free path
+ - tty: rocket: Fix possible buffer overwrite on register_PCI
+ - f2fs: fix to active page in lru list for read path
+ - f2fs: do not set free of current section
+ - f2fs: fix defined but not used build warnings
+ - perf tools: Allow overriding MAX_NR_CPUS at compile time
+ - NFSv4.0 fix client reference leak in callback
+ - perf c2c report: Fix crash for empty browser
+ - perf evlist: Fix error out while applying initial delay and LBR
+ - macintosh/via-pmu: Add missing mmio accessors
+ - ath9k: report tx status on EOSP
+ - ath9k_hw: fix channel maximum power level test
+ - ath10k: prevent active scans on potential unusable channels
+ - wlcore: Set rx_status boottime_ns field on rx
+ - MIPS: Fix ISA virt/bus conversion for non-zero PHYS_OFFSET
+ - scsi: 3ware: fix return 0 on the error path of probe
+ - tools/testing/nvdimm: kaddr and pfn can be NULL to ->direct_access()
+ - ath10k: disable bundle mgmt tx completion event support
+ - Bluetooth: hidp: Fix handling of strncpy for hid->name information
+ - pinctrl: imx: off by one in imx_pinconf_group_dbg_show()
+ - gpio: ml-ioh: Fix buffer underwrite on probe error path
+ - pinctrl/amd: only handle irq if it is pending and unmasked
+ - net: mvneta: fix mtu change on port without link
+ - f2fs: try grabbing node page lock aggressively in sync scenario
+ - f2fs: fix to skip GC if type in SSA and SIT is inconsistent
+ - tpm_tis_spi: Pass the SPI IRQ down to the driver
+ - tpm/tpm_i2c_infineon: switch to i2c_lock_bus(..., I2C_LOCK_SEGMENT)
+ - f2fs: fix to do sanity check with reserved blkaddr of inline inode
+ - MIPS: Octeon: add missing of_node_put()
+ - MIPS: generic: fix missing of_node_put()
+ - net: dcb: For wild-card lookups, use priority -1, not 0
+ - dm cache: only allow a single io_mode cache feature to be requested
+ - Input: atmel_mxt_ts - only use first T9 instance
+ - media: s5p-mfc: Fix buffer look up in s5p_mfc_handle_frame_{new, copy_time}
+ functions
+ - media: helene: fix xtal frequency setting at power on
+ - f2fs: fix to wait on page writeback before updating page
+ - f2fs: Fix uninitialized return in f2fs_ioc_shutdown()
+ - iommu/ipmmu-vmsa: Fix allocation in atomic context
+ - mfd: ti_am335x_tscadc: Fix struct clk memory leak
+ - f2fs: fix to do sanity check with {sit,nat}_ver_bitmap_bytesize
+ - NFSv4.1: Fix a potential layoutget/layoutrecall deadlock
+ - MIPS: WARN_ON invalid DMA cache maintenance, not BUG_ON
+ - RDMA/cma: Do not ignore net namespace for unbound cm_id
+ - inet: frags: change inet_frags_init_net() return value
+ - inet: frags: add a pointer to struct netns_frags
+ - inet: frags: refactor ipfrag_init()
+ - inet: frags: refactor ipv6_frag_init()
+ - inet: frags: refactor lowpan_net_frag_init()
+ - ipv6: export ip6 fragments sysctl to unprivileged users
+ - rhashtable: add schedule points
+ - inet: frags: use rhashtables for reassembly units
+ - inet: frags: remove some helpers
+ - inet: frags: get rif of inet_frag_evicting()
+ - inet: frags: remove inet_frag_maybe_warn_overflow()
+ - inet: frags: break the 2GB limit for frags storage
+ - inet: frags: do not clone skb in ip_expire()
+ - ipv6: frags: rewrite ip6_expire_frag_queue()
+ - rhashtable: reorganize struct rhashtable layout
+ - inet: frags: reorganize struct netns_frags
+ - inet: frags: get rid of ipfrag_skb_cb/FRAG_CB
+ - inet: frags: fix ip6frag_low_thresh boundary
+ - ip: discard IPv4 datagrams with overlapping segments.
+ - net: modify skb_rbtree_purge to return the truesize of all purged skbs.
+ - ipv6: defrag: drop non-last frags smaller than min mtu
+ - net: pskb_trim_rcsum() and CHECKSUM_COMPLETE are friends
+ - mtd: ubi: wl: Fix error return code in ubi_wl_init()
+ - tun: fix use after free for ptr_ring
+ - tuntap: fix use after free during release
+ - autofs: fix autofs_sbi() does not check super block type
+ - KVM: PPC: Book3S HV: Use correct pagesize in kvm_unmap_radix()
+ - ARC: [plat-axs*/plat-hsdk]: Allow U-Boot to pass MAC-address to the kernel
+ - x86/apic/vector: Make error return value negative
+ - tc-testing: flush gact actions on test teardown
+ - pinctrl: berlin: fix 'pctrl->functions' allocation in
+ berlin_pinctrl_build_state
+ - powerpc/4xx: Fix error return path in ppc4xx_msi_probe()
+ - scsi: qla2xxx: Fix unintended Logout
+ - iwlwifi: pcie: don't access periphery registers when not available
+ - f2fs: Keep alloc_valid_block_count in sync
+ - f2fs: issue discard align to section in LFS mode
+ - device-dax: avoid hang on error before devm_memremap_pages()
+ - regulator: tps65217: Fix NULL pointer dereference on probe
+ - gpio: pxa: disable pinctrl calls for PXA3xx
+ - thermal_hwmon: Sanitize attribute name passed to hwmon
+ - f2fs: fix to do sanity check with extra_attr feature
+ - RDMA/hns: Add illegal hop_num judgement
+ - RDMA/hns: Update the data type of immediate data
+ - be2net: Fix memory leak in be_cmd_get_profile_config()
+ - net/mlx5: Fix use-after-free in self-healing flow
+ - net: qca_spi: Fix race condition in spi transfers
+ - rds: fix two RCU related problems
+ - net/mlx5: Check for error in mlx5_attach_interface
+ - net/mlx5: Fix debugfs cleanup in the device init/remove flow
+ - net/mlx5: E-Switch, Fix memory leak when creating switchdev mode FDB tables
+ - net/tls: Set count of SG entries if sk_alloc_sg returns -ENOSPC
+ - erspan: fix error handling for erspan tunnel
+ - erspan: return PACKET_REJECT when the appropriate tunnel is not found
+ - tcp: really ignore MSG_ZEROCOPY if no SO_ZEROCOPY
+ - usb: dwc3: change stream event enable bit back to 13
+ - iommu/io-pgtable-arm-v7s: Abort allocation when table address overflows the
+ PTE
+ - ALSA: msnd: Fix the default sample sizes
+ - ALSA: usb-audio: Fix multiple definitions in AU0828_DEVICE() macro
+ - xfrm: fix 'passing zero to ERR_PTR()' warning
+ - amd-xgbe: use dma_mapping_error to check map errors
+ - gfs2: Special-case rindex for gfs2_grow
+ - clk: imx6ul: fix missing of_node_put()
+ - clk: core: Potentially free connection id
+ - clk: clk-fixed-factor: Clear OF_POPULATED flag in case of failure
+ - kbuild: add .DELETE_ON_ERROR special target
+ - media: tw686x: Fix oops on buffer alloc failure
+ - dmaengine: pl330: fix irq race with terminate_all
+ - MIPS: ath79: fix system restart
+ - media: videobuf2-core: check for q->error in vb2_core_qbuf()
+ - IB/rxe: Drop QP0 silently
+ - block: allow max_discard_segments to be stacked
+ - IB/ipoib: Fix error return code in ipoib_dev_init()
+ - mtd/maps: fix solutionengine.c printk format warnings
+ - media: ov5645: Supported external clock is 24MHz
+ - perf test: Fix subtest number when showing results
+ - gfs2: Don't reject a supposedly full bitmap if we have blocks reserved
+ - perf tools: Synthesize GROUP_DESC feature in pipe mode
+ - fbdev: omapfb: off by one in omapfb_register_client()
+ - perf tools: Fix struct comm_str removal crash
+ - video: goldfishfb: fix memory leak on driver remove
+ - fbdev/via: fix defined but not used warning
+ - perf powerpc: Fix callchain ip filtering when return address is in a
+ register
+ - video: fbdev: pxafb: clear allocated memory for video modes
+ - fbdev: Distinguish between interlaced and progressive modes
+ - ARM: exynos: Clear global variable on init error path
+ - perf powerpc: Fix callchain ip filtering
+ - nvme-rdma: unquiesce queues when deleting the controller
+ - powerpc/powernv: opal_put_chars partial write fix
+ - staging: bcm2835-camera: fix timeout handling in wait_for_completion_timeout
+ - staging: bcm2835-camera: handle wait_for_completion_timeout return properly
+ - ASoC: rt5514: Fix the issue of the delay volume applied
+ - MIPS: jz4740: Bump zload address
+ - mac80211: restrict delayed tailroom needed decrement
+ - Smack: Fix handling of IPv4 traffic received by PF_INET6 sockets
+ - wan/fsl_ucc_hdlc: use IS_ERR_VALUE() to check return value of qe_muram_alloc
+ - reset: imx7: Fix always writing bits as 0
+ - nfp: avoid buffer leak when FW communication fails
+ - xen-netfront: fix queue name setting
+ - arm64: dts: qcom: db410c: Fix Bluetooth LED trigger
+ - ARM: dts: qcom: msm8974-hammerhead: increase load on l20 for sdhci
+ - s390/qeth: fix race in used-buffer accounting
+ - s390/qeth: reset layer2 attribute on layer switch
+ - platform/x86: toshiba_acpi: Fix defined but not used build warnings
+ - KVM: arm/arm64: Fix vgic init race
+ - drivers/base: stop new probing during shutdown
+ - i2c: aspeed: Fix initial values of master and slave state
+ - dmaengine: mv_xor_v2: kill the tasklets upon exit
+ - crypto: sharah - Unregister correct algorithms for SAHARA 3
+ - xen-netfront: fix warn message as irq device name has '/'
+ - RDMA/cma: Protect cma dev list with lock
+ - pstore: Fix incorrect persistent ram buffer mapping
+ - xen/netfront: fix waiting for xenbus state change
+ - IB/ipoib: Avoid a race condition between start_xmit and cm_rep_handler
+ - mmc: omap_hsmmc: fix wakeirq handling on removal
+ - ipmi: Fix I2C client removal in the SSIF driver
+ - Tools: hv: Fix a bug in the key delete code
+ - xhci: Fix use after free for URB cancellation on a reallocated endpoint
+ - usb: Don't die twice if PCI xhci host is not responding in resume
+ - mei: ignore not found client in the enumeration
+ - mei: bus: need to unlink client before freeing
+ - USB: Add quirk to support DJI CineSSD
+ - usb: uas: add support for more quirk flags
+ - usb: Avoid use-after-free by flushing endpoints early in usb_set_interface()
+ - usb: host: u132-hcd: Fix a sleep-in-atomic-context bug in u132_get_frame()
+ - USB: add quirk for WORLDE Controller KS49 or Prodipe MIDI 49C USB controller
+ - usb: gadget: udc: renesas_usb3: fix maxpacket size of ep0
+ - USB: net2280: Fix erroneous synchronization change
+ - USB: serial: io_ti: fix array underflow in completion handler
+ - usb: misc: uss720: Fix two sleep-in-atomic-context bugs
+ - USB: serial: ti_usb_3410_5052: fix array underflow in completion handler
+ - USB: yurex: Fix buffer over-read in yurex_write()
+ - Revert "cdc-acm: implement put_char() and flush_chars()"
+ - cifs: prevent integer overflow in nxt_dir_entry()
+ - CIFS: fix wrapping bugs in num_entries()
+ - xtensa: ISS: don't allocate memory in platform_setup
+ - perf/core: Force USER_DS when recording user stack data
+ - NFSv4.1 fix infinite loop on I/O.
+ - binfmt_elf: Respect error return from `regset->active'
+ - net/mlx5: Add missing SET_DRIVER_VERSION command translation
+ - arm64: dts: uniphier: Add missing cooling device properties for CPUs
+ - audit: fix use-after-free in audit_add_watch
+ - mtdchar: fix overflows in adjustment of `count`
+ - Bluetooth: Use lock_sock_nested in bt_accept_enqueue
+ - evm: Don't deadlock if a crypto algorithm is unavailable
+ - KVM: PPC: Book3S HV: Add of_node_put() in success path
+ - security: check for kstrdup() failure in lsm_append()
+ - MIPS: loongson64: cs5536: Fix PCI_OHCI_INT_REG reads
+ - configfs: fix registered group removal
+ - pinctrl: rza1: Fix selector use for groups and functions
+ - sched/core: Use smp_mb() in wake_woken_function()
+ - efi/esrt: Only call efi_mem_reserve() for boot services memory
+ - ARM: hisi: handle of_iomap and fix missing of_node_put
+ - ARM: hisi: fix error handling and missing of_node_put
+ - ARM: hisi: check of_iomap and fix missing of_node_put
+ - liquidio: fix hang when re-binding VF host drv after running DPDK VF driver
+ - gpu: ipu-v3: csi: pass back mbus_code_to_bus_cfg error codes
+ - tty: fix termios input-speed encoding when using BOTHER
+ - tty: fix termios input-speed encoding
+ - mmc: sdhci-of-esdhc: set proper dma mask for ls104x chips
+ - mmc: tegra: prevent HS200 on Tegra 3
+ - mmc: sdhci: do not try to use 3.3V signaling if not supported
+ - drm/nouveau: Fix runtime PM leak in drm_open()
+ - drm/nouveau/debugfs: Wake up GPU before doing any reclocking
+ - drm/nouveau: tegra: Detach from ARM DMA/IOMMU mapping
+ - parport: sunbpp: fix error return code
+ - sched/fair: Fix util_avg of new tasks for asymmetric systems
+ - coresight: Handle errors in finding input/output ports
+ - coresight: tpiu: Fix disabling timeouts
+ - coresight: ETM: Add support for Arm Cortex-A73 and Cortex-A35
+ - staging: bcm2835-audio: Don't leak workqueue if open fails
+ - gpio: pxa: Fix potential NULL dereference
+ - gpiolib: Mark gpio_suffixes array with __maybe_unused
+ - mfd: 88pm860x-i2c: switch to i2c_lock_bus(..., I2C_LOCK_SEGMENT)
+ - input: rohm_bu21023: switch to i2c_lock_bus(..., I2C_LOCK_SEGMENT)
+ - drm/amdkfd: Fix error codes in kfd_get_process
+ - rtc: bq4802: add error handling for devm_ioremap
+ - ALSA: pcm: Fix snd_interval_refine first/last with open min/max
+ - scsi: libfc: fixup 'sleeping function called from invalid context'
+ - drm/panel: type promotion bug in s6e8aa0_read_mtp_id()
+ - blk-mq: only attempt to merge bio if there is rq in sw queue
+ - blk-mq: avoid to synchronize rcu inside blk_cleanup_queue()
+ - pinctrl: msm: Fix msm_config_group_get() to be compliant
+ - pinctrl: qcom: spmi-gpio: Fix pmic_gpio_config_get() to be compliant
+ - clk: tegra: bpmp: Don't crash when a clock fails to register
+ - mei: bus: type promotion bug in mei_nfc_if_version()
+ - earlycon: Initialize port->uartclk based on clock-frequency property
+ - earlycon: Remove hardcoded port->uartclk initialization in of_setup_earlycon
+ - net/ipv6: prevent use after free in ip6_route_mpath_notify
+ - Partial revert "e1000e: Avoid receiver overrun interrupt bursts"
+ - e1000e: Fix queue interrupt re-raising in Other interrupt
+ - e1000e: Avoid missed interrupts following ICR read
+ - Revert "e1000e: Separate signaling for link check/link up"
+ - e1000e: Fix link check race condition
+ - e1000e: Fix check_for_link return value with autoneg off
+ - tipc: orphan sock in tipc_release()
+ - net/mlx5: Fix not releasing read lock when adding flow rules
+ - iommu/arm-smmu-v3: sync the OVACKFLG to PRIQ consumer register
+ - iwlwifi: cancel the injective function between hw pointers to tfd entry
+ index
+ - kbuild: do not update config when running install targets
+ - omapfb: rename omap2 module to omap2fb.ko
+ - [Config] Rename omapfb to omap2fb
+ - perf script: Show correct offsets for DWARF-based unwinding
+ - iommu/ipmmu-vmsa: IMUCTRn.TTSEL needs a special usage on R-Car Gen3
+ - ipmi: Move BT capabilities detection to the detect call
+ - ovl: fix oopses in ovl_fill_super() failure paths
+ - usb: xhci: fix interrupt transfer error happened on MTK platforms
+ - usb: mtu3: fix error of xhci port id when enable U3 dual role
+ - dm verity: fix crash on bufio buffer that was allocated with vmalloc
+ - cifs: integer overflow in in SMB2_ioctl()
+ - perf tools: Fix maps__find_symbol_by_name()
+ - NFSv4: Fix a tracepoint Oops in initiate_file_draining()
+ - of: add helper to lookup compatible child node
+ - mmc: meson-mx-sdio: fix OF child-node lookup
+ - bpf: fix rcu annotations in compute_effective_progs()
+ - spi: dw: fix possible race condition
+ - PM / devfreq: use put_device() instead of kfree()
+ - ASoC: hdmi-codec: fix routing
+ - drm/amd/display: support access ddc for mst branch
+ - rcutorture: Use monotonic timestamp for stall detection
+ - selftests: vDSO - fix to return KSFT_SKIP when test couldn't be run
+ - selftests/android: initialize heap_type to avoid compiling warning
+ - scsi: lpfc: Fix NVME Target crash in defer rcv logic
+ - scsi: lpfc: Fix panic if driver unloaded when port is offline
+ - arm64: perf: Disable PMU while processing counter overflows
+ - staging: fsl-dpaa2/eth: Fix DMA mapping direction
+ - block/DAC960.c: fix defined but not used build warnings
+ - IB/mlx5: fix uaccess beyond "count" in debugfs read/write handlers
+
+ * Bionic update: upstream stable patchset 2019-07-09 (LP: #1835972)
+ - vti6: fix PMTU caching and reporting on xmit
+ - xfrm: fix missing dst_release() after policy blocking lbcast and multicast
+ - xfrm: free skb if nlsk pointer is NULL
+ - esp6: fix memleak on error path in esp6_input
+ - mac80211: add stations tied to AP_VLANs during hw reconfig
+ - ext4: clear mmp sequence number when remounting read-only
+ - nl80211: Add a missing break in parse_station_flags
+ - drm/bridge: adv7511: Reset registers on hotplug
+ - scsi: target: iscsi: cxgbit: fix max iso npdu calculation
+ - scsi: libiscsi: fix possible NULL pointer dereference in case of TMF
+ - drm/imx: imx-ldb: disable LDB on driver bind
+ - drm/imx: imx-ldb: check if channel is enabled before printing warning
+ - nbd: don't requeue the same request twice.
+ - nbd: handle unexpected replies better
+ - usb: gadget: r8a66597: Fix two possible sleep-in-atomic-context bugs in
+ init_controller()
+ - usb: gadget: r8a66597: Fix a possible sleep-in-atomic-context bugs in
+ r8a66597_queue()
+ - usb: gadget: f_uac2: fix error handling in afunc_bind (again)
+ - usb: gadget: u_audio: fix pcm/card naming in g_audio_setup()
+ - usb: gadget: u_audio: update hw_ptr in iso_complete after data copied
+ - usb: gadget: u_audio: remove caching of stream buffer parameters
+ - usb: gadget: u_audio: remove cached period bytes value
+ - usb: gadget: u_audio: protect stream runtime fields with stream spinlock
+ - usb/phy: fix PPC64 build errors in phy-fsl-usb.c
+ - tools: usb: ffs-test: Fix build on big endian systems
+ - usb: gadget: f_uac2: fix endianness of 'struct cntrl_*_lay3'
+ - netfilter: nft_set_hash: add rcu_barrier() in the nft_rhash_destroy()
+ - bpf, ppc64: fix unexpected r0=0 exit path inside bpf_xadd
+ - netfilter: nf_tables: fix memory leaks on chain rename
+ - netfilter: nf_tables: don't allow to rename to already-pending name
+ - KVM: vmx: use local variable for current_vmptr when emulating VMPTRST
+ - tools/power turbostat: fix -S on UP systems
+ - net: caif: Add a missing rcu_read_unlock() in caif_flow_cb
+ - qed: Fix link flap issue due to mismatching EEE capabilities.
+ - qed: Fix possible race for the link state value.
+ - qed: Correct Multicast API to reflect existence of 256 approximate buckets.
+ - atl1c: reserve min skb headroom
+ - net: prevent ISA drivers from building on PPC32
+ - can: mpc5xxx_can: check of_iomap return before use
+ - can: m_can: Move accessing of message ram to after clocks are enabled
+ - i2c: davinci: Avoid zero value of CLKH
+ - perf/x86/amd/ibs: Don't access non-started event
+ - media: staging: omap4iss: Include asm/cacheflush.h after generic includes
+ - bnx2x: Fix invalid memory access in rss hash config path.
+ - net: axienet: Fix double deregister of mdio
+ - locking/rtmutex: Allow specifying a subclass for nested locking
+ - i2c/mux, locking/core: Annotate the nested rt_mutex usage
+ - sched/rt: Restore rt_runtime after disabling RT_RUNTIME_SHARE
+ - x86/boot: Fix if_changed build flip/flop bug
+ - selftests/ftrace: Add snapshot and tracing_on test case
+ - ipc/sem.c: prevent queue.status tearing in semop
+ - zswap: re-check zswap_is_full() after do zswap_shrink()
+ - tools/power turbostat: Read extended processor family from CPUID
+ - ARC: dma [non-IOC] setup SMP_CACHE_BYTES and cache_line_size
+ - bpf: use GFP_ATOMIC instead of GFP_KERNEL in bpf_parse_prog()
+ - nfp: flower: fix port metadata conversion bug
+ - enic: handle mtu change for vf properly
+ - ARC: [plat-eznps] Add missing struct nps_host_reg_aux_dpc
+ - arc: [plat-eznps] fix data type errors in platform headers
+ - arc: [plat-eznps] fix printk warning in arc/plat-eznps/mtm.c
+ - arc: fix build errors in arc/include/asm/delay.h
+ - arc: fix type warnings in arc/mm/cache.c
+ - sparc/time: Add missing __init to init_tick_ops()
+ - sparc: use asm-generic version of msi.h
+ - enic: do not call enic_change_mtu in enic_probe
+ - mm: delete historical BUG from zap_pmd_range()
+ - drivers: net: lmc: fix case value for target abort error
+ - memcg: remove memcg_cgroup::id from IDR on mem_cgroup_css_alloc() failure
+ - gpiolib-acpi: make sure we trigger edge events at least once on boot
+ - scsi: fcoe: fix use-after-free in fcoe_ctlr_els_send
+ - scsi: fcoe: drop frames in ELS LOGO error path
+ - scsi: vmw_pvscsi: Return DID_RESET for status SAM_STAT_COMMAND_TERMINATED
+ - mm/memory.c: check return value of ioremap_prot
+ - mei: don't update offset in write
+ - cifs: add missing debug entries for kconfig options
+ - cifs: check kmalloc before use
+ - smb3: enumerating snapshots was leaving part of the data off end
+ - smb3: Do not send SMB3 SET_INFO if nothing changed
+ - smb3: don't request leases in symlink creation and query
+ - smb3: fill in statfs fsid and correct namelen
+ - btrfs: use correct compare function of dirty_metadata_bytes
+ - btrfs: don't leak ret from do_chunk_alloc
+ - Btrfs: fix btrfs_write_inode vs delayed iput deadlock
+ - iommu/arm-smmu: Error out only if not enough context interrupts
+ - printk: Split the code for storing a message into the log buffer
+ - printk: Create helper function to queue deferred console handling
+ - printk/nmi: Prevent deadlock when accessing the main log buffer in NMI
+ - kprobes/arm64: Fix %p uses in error messages
+ - arm64: mm: check for upper PAGE_SHIFT bits in pfn_valid()
+ - arm64: dts: rockchip: corrected uart1 clock-names for rk3328
+ - KVM: arm/arm64: Skip updating PMD entry if no change
+ - KVM: arm/arm64: Skip updating PTE entry if no change
+ - stop_machine: Reflow cpu_stop_queue_two_works()
+ - ext4: check for NUL characters in extended attribute's name
+ - ext4: sysfs: print ext4_super_block fields as little-endian
+ - ext4: reset error code in ext4_find_entry in fallback
+ - platform/x86: ideapad-laptop: Apply no_hw_rfkill to Y20-15IKBM, too
+ - x86/vdso: Fix vDSO build if a retpoline is emitted
+ - x86/process: Re-export start_thread()
+ - x86/kvm/vmx: Remove duplicate l1d flush definitions
+ - fuse: Add missed unlock_page() to fuse_readpages_fill()
+ - udl-kms: change down_interruptible to down
+ - udl-kms: handle allocation failure
+ - udl-kms: fix crash due to uninitialized memory
+ - udl-kms: avoid division
+ - b43legacy/leds: Ensure NUL-termination of LED name string
+ - b43/leds: Ensure NUL-termination of LED name string
+ - ASoC: dpcm: don't merge format from invalid codec dai
+ - ASoC: zte: Fix incorrect PCM format bit usages
+ - ASoC: sirf: Fix potential NULL pointer dereference
+ - pinctrl: freescale: off by one in imx1_pinconf_group_dbg_show()
+ - x86/vdso: Fix lsl operand order
+ - x86/irqflags: Mark native_restore_fl extern inline
+ - x86/entry/64: Wipe KASAN stack shadow before rewind_stack_do_exit()
+ - s390/mm: fix addressing exception after suspend/resume
+ - s390/numa: move initial setup of node_to_cpumask_map
+ - kprobes/arm: Fix %p uses in error messages
+ - kprobes: Make list and blacklist root user read only
+ - MIPS: Correct the 64-bit DSP accumulator register size
+ - MIPS: Always use -march=<arch>, not -<arch> shortcuts
+ - MIPS: Change definition of cpu_relax() for Loongson-3
+ - MIPS: lib: Provide MIPS64r6 __multi3() for GCC < 7
+ - tpm: Return the actual size when receiving an unsupported command
+ - scsi: mpt3sas: Fix _transport_smp_handler() error path
+ - scsi: sysfs: Introduce sysfs_{un,}break_active_protection()
+ - scsi: core: Avoid that SCSI device removal through sysfs triggers a deadlock
+ - clk: rockchip: fix clk_i2sout parent selection bits on rk3399
+ - PM / clk: signedness bug in of_pm_clk_add_clks()
+ - power: generic-adc-battery: fix out-of-bounds write when copying channel
+ properties
+ - power: generic-adc-battery: check for duplicate properties copied from iio
+ channels
+ - watchdog: Mark watchdog touch functions as notrace
+ - gcc-plugins: Add include required by GCC release 8
+ - gcc-plugins: Use dynamic initializers
+ - Btrfs: fix send failure when root has deleted files still open
+ - Btrfs: send, fix incorrect file layout after hole punching beyond eof
+ - hwmon: (k10temp) 27C Offset needed for Threadripper2
+ - KVM: arm/arm64: Fix potential loss of ptimer interrupts
+ - KVM: arm/arm64: Fix lost IRQs from emulated physcial timer when blocked
+ - perf kvm: Fix subcommands on s390
+ - ext4: use ext4_warning() for sb_getblk failure
+ - platform/x86: wmi: Do not mix pages and kmalloc
+ - KVM: x86: ensure all MSRs can always be KVM_GET/SET_MSR'd
+ - lib/vsprintf: Do not handle %pO[^F] as %px
+ - soc: qcom: rmtfs-mem: fix memleak in probe error paths
+ - kprobes: Show blacklist addresses as same as kallsyms does
+ - kprobes: Replace %p with other pointer types
+ - MIPS: memset.S: Fix byte_fixup for MIPSr6
+ - mtd: rawnand: qcom: wait for desc completion in all BAM channels
+ - net: 6lowpan: fix reserved space for single frames
+ - net: mac802154: tx: expand tailroom if necessary
+ - 9p/net: Fix zero-copy path in the 9p virtio transport
+ - spi: davinci: fix a NULL pointer dereference
+ - spi: pxa2xx: Add support for Intel Ice Lake
+ - spi: spi-fsl-dspi: Fix imprecise abort on VF500 during probe
+ - spi: cadence: Change usleep_range() to udelay(), for atomic context
+ - mmc: renesas_sdhi_internal_dmac: fix #define RST_RESERVED_BITS
+ - readahead: stricter check for bdi io_pages
+ - block: blk_init_allocated_queue() set q->fq as NULL in the fail case
+ - block: really disable runtime-pm for blk-mq
+ - drm/i915/userptr: reject zero user_size
+ - libertas: fix suspend and resume for SDIO connected cards
+ - media: Revert "[media] tvp5150: fix pad format frame height"
+ - mailbox: xgene-slimpro: Fix potential NULL pointer dereference
+ - Replace magic for trusting the secondary keyring with #define
+ - powerpc/fadump: handle crash memory ranges array index overflow
+ - powerpc/pseries: Fix endianness while restoring of r3 in MCE handler.
+ - PCI: Add wrappers for dev_printk()
+ - cxl: Fix wrong comparison in cxl_adapter_context_get()
+ - ib_srpt: Fix a use-after-free in srpt_close_ch()
+ - RDMA/rxe: Set wqe->status correctly if an unexpected response is received
+ - 9p: fix multiple NULL-pointer-dereferences
+ - fs/9p/xattr.c: catch the error of p9_client_clunk when setting xattr failed
+ - 9p/virtio: fix off-by-one error in sg list bounds check
+ - net/9p/client.c: version pointer uninitialized
+ - net/9p/trans_fd.c: fix race-condition by flushing workqueue before the
+ kfree()
+ - dm integrity: change 'suspending' variable from bool to int
+ - dm thin: stop no_space_timeout worker when switching to write-mode
+ - dm cache metadata: save in-core policy_hint_size to on-disk superblock
+ - dm cache metadata: set dirty on all cache blocks after a crash
+ - dm crypt: don't decrease device limits
+ - uart: fix race between uart_put_char() and uart_shutdown()
+ - Drivers: hv: vmbus: Reset the channel callback in vmbus_onoffer_rescind()
+ - iio: sca3000: Fix missing return in switch
+ - iio: ad9523: Fix displayed phase
+ - iio: ad9523: Fix return value for ad952x_store()
+ - extcon: Release locking when sending the notification of connector state
+ - vmw_balloon: fix inflation of 64-bit GFNs
+ - vmw_balloon: do not use 2MB without batching
+ - vmw_balloon: VMCI_DOORBELL_SET does not check status
+ - vmw_balloon: fix VMCI use when balloon built into kernel
+ - rtc: omap: fix potential crash on power off
+ - tracing: Do not call start/stop() functions when tracing_on does not change
+ - tracing/blktrace: Fix to allow setting same value
+ - printk/tracing: Do not trace printk_nmi_enter()
+ - livepatch: Validate module/old func name length
+ - uprobes: Use synchronize_rcu() not synchronize_sched()
+ - mfd: hi655x: Fix regmap area declared size for hi655x
+ - ovl: fix wrong use of impure dir cache in ovl_iterate()
+ - drivers/block/zram/zram_drv.c: fix bug storing backing_dev
+ - cpufreq: governor: Avoid accessing invalid governor_data
+ - PM / sleep: wakeup: Fix build error caused by missing SRCU support
+ - KVM: PPC: Book3S: Fix guest DMA when guest partially backed by THP pages
+ - xtensa: limit offsets in __loop_cache_{all,page}
+ - xtensa: increase ranges in ___invalidate_{i,d}cache_all
+ - block, bfq: return nbytes and not zero from struct cftype .write() method
+ - pnfs/blocklayout: off by one in bl_map_stripe()
+ - NFSv4 client live hangs after live data migration recovery
+ - NFSv4: Fix locking in pnfs_generic_recover_commit_reqs
+ - NFSv4: Fix a sleep in atomic context in nfs4_callback_sequence()
+ - ARM: tegra: Fix Tegra30 Cardhu PCA954x reset
+ - iommu/vt-d: Add definitions for PFSID
+ - iommu/vt-d: Fix dev iotlb pfsid use
+ - sys: don't hold uts_sem while accessing userspace memory
+ - userns: move user access out of the mutex
+ - ubifs: Fix memory leak in lprobs self-check
+ - ubifs: Check data node size before truncate
+ - ubifs: Fix synced_i_size calculation for xattr inodes
+ - pwm: tiehrpwm: Don't use emulation mode bits to control PWM output
+ - pwm: tiehrpwm: Fix disabling of output of PWMs
+ - fb: fix lost console when the user unplugs a USB adapter
+ - udlfb: set optimal write delay
+ - libnvdimm: fix ars_status output length calculation
+ - bcache: release dc->writeback_lock properly in bch_writeback_thread()
+ - perf auxtrace: Fix queue resize
+ - crypto: caam - fix DMA mapping direction for RSA forms 2 & 3
+ - crypto: caam/jr - fix descriptor DMA unmapping
+ - crypto: caam/qi - fix error path in xts setkey
+ - arm64: mm: always enable CONFIG_HOLES_IN_ZONE
+ - mmc: renesas_sdhi_internal_dmac: mask DMAC interrupts
+ - blkcg: Introduce blkg_root_lookup()
+ - powerpc64/ftrace: Include ftrace.h needed for enable/disable calls
+ - IB/mlx5: Fix leaking stack memory to userspace
+ - rtc: omap: fix resource leak in registration error path
+ - ACPICA: AML Parser: skip opcodes that open a scope upon parse failure
+ - ALSA: ac97: fix device initialization in the compat layer
+ - ALSA: ac97: fix check of pm_runtime_get_sync failure
+ - ALSA: ac97: fix unbalanced pm_runtime_enable
+ - nfsd: fix leaked file lock with nfs exported overlayfs
+ - ubifs: Fix directory size calculation for symlinks
+ - mm, dev_pagemap: Do not clear ->mapping on final put
+ - act_ife: fix a potential use-after-free
+ - ipv4: tcp: send zero IPID for RST and ACK sent in SYN-RECV and TIME-WAIT
+ state
+ - net: bcmgenet: use MAC link status for fixed phy
+ - net: macb: do not disable MDIO bus at open/close time
+ - qlge: Fix netdev features configuration.
+ - r8169: add support for NCube 8168 network card
+ - tcp: do not restart timewait timer on rst reception
+ - vti6: remove !skb->ignore_df check from vti6_xmit()
+ - net/sched: act_pedit: fix dump of extended layered op
+ - tipc: fix a missing rhashtable_walk_exit()
+ - nfp: wait for posted reconfigs when disabling the device
+ - sctp: hold transport before accessing its asoc in sctp_transport_get_next
+ - mlxsw: spectrum_switchdev: Do not leak RIFs when removing bridge
+ - vhost: correctly check the iova range when waking virtqueue
+ - hv_netvsc: ignore devices that are not PCI
+ - act_ife: move tcfa_lock down to where necessary
+ - act_ife: fix a potential deadlock
+ - net: sched: action_ife: take reference to meta module
+ - cifs: check if SMB2 PDU size has been padded and suppress the warning
+ - hfsplus: don't return 0 when fill_super() failed
+ - hfs: prevent crash on exit from failed search
+ - sunrpc: Don't use stack buffer with scatterlist
+ - fork: don't copy inconsistent signal handler state to child
+ - reiserfs: change j_timestamp type to time64_t
+ - hfsplus: fix NULL dereference in hfsplus_lookup()
+ - fs/proc/kcore.c: use __pa_symbol() for KCORE_TEXT list entries
+ - fat: validate ->i_start before using
+ - scripts: modpost: check memory allocation results
+ - virtio: pci-legacy: Validate queue pfn
+ - x86/mce: Add notifier_block forward declaration
+ - IB/hfi1: Invalid NUMA node information can cause a divide by zero
+ - pwm: meson: Fix mux clock names
+ - mm/fadvise.c: fix signed overflow UBSAN complaint
+ - fs/dcache.c: fix kmemcheck splat at take_dentry_name_snapshot()
+ - platform/x86: intel_punit_ipc: fix build errors
+ - netfilter: ip6t_rpfilter: set F_IFACE for linklocal addresses
+ - s390/kdump: Fix memleak in nt_vmcoreinfo
+ - ipvs: fix race between ip_vs_conn_new() and ip_vs_del_dest()
+ - mfd: sm501: Set coherent_dma_mask when creating subdevices
+ - platform/x86: asus-nb-wmi: Add keymap entry for lid flip action on UX360
+ - netfilter: fix memory leaks on netlink_dump_start error
+ - tcp, ulp: add alias for all ulp modules
+ - RDMA/hns: Fix usage of bitmap allocation functions return values
+ - net: hns3: Fix for command format parsing error in
+ hclge_is_all_function_id_zero
+ - perf tools: Check for null when copying nsinfo.
+ - irqchip/bcm7038-l1: Hide cpu offline callback when building for !SMP
+ - net/9p/trans_fd.c: fix race by holding the lock
+ - net/9p: fix error path of p9_virtio_probe
+ - powerpc/uaccess: Enable get_user(u64, *p) on 32-bit
+ - powerpc: Fix size calculation using resource_size()
+ - perf probe powerpc: Fix trace event post-processing
+ - block: bvec_nr_vecs() returns value for wrong slab
+ - s390/dasd: fix hanging offline processing due to canceled worker
+ - s390/dasd: fix panic for failed online processing
+ - ACPI / scan: Initialize status to ACPI_STA_DEFAULT
+ - scsi: aic94xx: fix an error code in aic94xx_init()
+ - NFSv4: Fix error handling in nfs4_sp4_select_mode()
+ - Input: do not use WARN() in input_alloc_absinfo()
+ - xen/balloon: fix balloon initialization for PVH Dom0
+ - PCI: mvebu: Fix I/O space end address calculation
+ - dm kcopyd: avoid softlockup in run_complete_job
+ - staging: comedi: ni_mio_common: fix subdevice flags for PFI subdevice
+ - ASoC: rt5677: Fix initialization of rt5677_of_match.data
+ - iommu/omap: Fix cache flushes on L2 table entries
+ - selftests/powerpc: Kill child processes on SIGINT
+ - RDS: IB: fix 'passing zero to ERR_PTR()' warning
+ - cfq: Suppress compiler warnings about comparisons
+ - smb3: fix reset of bytes read and written stats
+ - SMB3: Number of requests sent should be displayed for SMB3 not just CIFS
+ - powerpc/platforms/85xx: fix t1042rdb_diu.c build errors & warning
+ - powerpc/64s: Make rfi_flush_fallback a little more robust
+ - powerpc/pseries: Avoid using the size greater than RTAS_ERROR_LOG_MAX.
+ - clk: rockchip: Add pclk_rkpwm_pmu to PMU critical clocks in rk3399
+ - KVM: vmx: track host_state.loaded using a loaded_vmcs pointer
+ - kvm: nVMX: Fix fault vector for VMX operation at CPL > 0
+ - btrfs: Exit gracefully when chunk map cannot be inserted to the tree
+ - btrfs: replace: Reset on-disk dev stats value after replace
+ - btrfs: relocation: Only remove reloc rb_trees if reloc control has been
+ initialized
+ - btrfs: Don't remove block group that still has pinned down bytes
+ - arm64: rockchip: Force CONFIG_PM on Rockchip systems
+ - ARM: rockchip: Force CONFIG_PM on Rockchip systems
+ - drm/i915/lpe: Mark LPE audio runtime pm as "no callbacks"
+ - drm/amdgpu: Fix RLC safe mode test in gfx_v9_0_enter_rlc_safe_mode
+ - drm/amd/pp/Polaris12: Fix a chunk of registers missed to program
+ - drm/amdgpu: update tmr mc address
+ - drm/amdgpu:add tmr mc address into amdgpu_firmware_info
+ - drm/amdgpu:add new firmware id for VCN
+ - drm/amdgpu:add VCN support in PSP driver
+ - drm/amdgpu:add VCN booting with firmware loaded by PSP
+ - debugobjects: Make stack check warning more informative
+ - mm: Fix devm_memremap_pages() collision handling
+ - HID: add quirk for another PIXART OEM mouse used by HP
+ - usb: dwc3: core: Fix ULPI PHYs and prevent phy_get/ulpi_init during
+ suspend/resume
+ - x86/pae: use 64 bit atomic xchg function in native_ptep_get_and_clear
+ - x86/xen: don't write ptes directly in 32-bit PV guests
+ - drm/i915: Increase LSPCON timeout
+ - kbuild: make missing $DEPMOD a Warning instead of an Error
+ - kvm: x86: Set highest physical address bits in non-present/reserved SPTEs
+ - x86: kvm: avoid unused variable warning
+ - arm64: cpu_errata: include required headers
+ - ASoC: wm8994: Fix missing break in switch
+ - arm64: Fix mismatched cache line size detection
+ - arm64: Handle mismatched cache type
+ - tipc: fix the big/little endian issue in tipc_dest
+ - ip6_vti: fix a null pointer deference when destroy vti6 tunnel
+ - workqueue: skip lockdep wq dependency in cancel_work_sync()
+ - workqueue: re-add lockdep dependencies for flushing
+ - apparmor: fix an error code in __aa_create_ns()
+ - tcp, ulp: fix leftover icsk_ulp_ops preventing sock from reattach
+ - netfilter: x_tables: do not fail xt_alloc_table_info too easilly
+ - ACPICA: ACPICA: add status check for acpi_hw_read before assigning return
+ value
+ - PCI: Match Root Port's MPS to endpoint's MPSS as necessary
+ - coccicheck: return proper error code on fail
+ - RISC-V: Use KBUILD_CFLAGS instead of KCFLAGS when building the vDSO
+ - blk-mq: count the hctx as active before allocating tag
+ - selinux: cleanup dentry and inodes on error in selinuxfs
+ - drm/amd/display: Read back max backlight value at boot
+ - btrfs: check-integrity: Fix NULL pointer dereference for degraded mount
+ - btrfs: lift uuid_mutex to callers of btrfs_open_devices
+ - btrfs: Fix a C compliance issue
+ - drm/i915: Nuke the LVDS lid notifier
+ - drm/edid: Quirk Vive Pro VR headset non-desktop.
+ - drm/amd/display: fix type of variable
+ - drm/amd/display: Don't share clk source between DP and HDMI
+ - drm/amd/display: update clk for various HDMI color depths
+ - drm/amd/display: Use requested HDMI aspect ratio
+ - drm/rockchip: lvds: add missing of_node_put
+ - drm/amd/display: Pass connector id when executing VBIOS CT
+ - drm/amd/display: Check if clock source in use before disabling
+ - drm/amdgpu: fix incorrect use of fcheck
+ - drm/amdgpu: fix incorrect use of drm_file->pid
+ - drm/i915: set DP Main Stream Attribute for color range on DDI platforms
+ - x86/tsc: Prevent result truncation on 32bit
+
+ * [Regression] Colour banding appears on Lenovo B50-80 integrated display
+ (LP: #1788308) // Bionic update: upstream stable patchset 2019-07-09
+ (LP: #1835972)
+ - drm/edid: Add 6 bpc quirk for SDC panel in Lenovo B50-80
+
+ * CVE-2019-12819
+ - mdio_bus: Fix use-after-free on device_register fails
+
+ * proc_thermal flooding dmesg (LP: #1824690)
+ - drivers: thermal: processor_thermal: Downgrade error message
+
+ * Bionic update: upstream stable patchset 2019-07-08 (LP: #1835845)
+ - bonding: avoid lockdep confusion in bond_get_stats()
+ - inet: frag: enforce memory limits earlier
+ - ipv4: frags: handle possible skb truesize change
+ - net: dsa: Do not suspend/resume closed slave_dev
+ - net: stmmac: Fix WoL for PCI-based setups
+ - rxrpc: Fix user call ID check in rxrpc_service_prealloc_one
+ - can: ems_usb: Fix memory leak on ems_usb_disconnect()
+ - virtio_balloon: fix another race between migration and ballooning
+ - x86/apic: Future-proof the TSC_DEADLINE quirk for SKX
+ - kvm: x86: vmx: fix vpid leak
+ - audit: fix potential null dereference 'context->module.name'
+ - userfaultfd: remove uffd flags from vma->vm_flags if UFFD_EVENT_FORK fails
+ - RDMA/uverbs: Expand primary and alt AV port checks
+ - crypto: padlock-aes - Fix Nano workaround data corruption
+ - drm/vc4: Reset ->{x, y}_scaling[1] when dealing with uniplanar formats
+ - scsi: sg: fix minor memory leak in error path
+ - net/mlx5e: E-Switch, Initialize eswitch only if eswitch manager
+ - net/mlx5e: Set port trust mode to PCP as default
+ - x86/efi: Access EFI MMIO data as unencrypted when SEV is active
+ - drm/atomic: Check old_plane_state->crtc in drm_atomic_helper_async_check()
+ - drm/atomic: Initialize variables in drm_atomic_helper_async_check() to make
+ gcc happy
+ - scsi: qla2xxx: Fix unintialized List head crash
+ - scsi: qla2xxx: Fix NPIV deletion by calling wait_for_sess_deletion
+ - scsi: qla2xxx: Fix ISP recovery on unload
+ - scsi: qla2xxx: Return error when TMF returns
+ - genirq: Make force irq threading setup more robust
+ - nohz: Fix local_timer_softirq_pending()
+ - nohz: Fix missing tick reprogram when interrupting an inline softirq
+ - ring_buffer: tracing: Inherit the tracing setting to next ring buffer
+ - i2c: imx: Fix reinit_completion() use
+ - Btrfs: fix file data corruption after cloning a range and fsync
+ - nvme-pci: allocate device queues storage space at probe
+ - nvme-pci: Fix queue double allocations
+ - xfs: catch inode allocation state mismatch corruption
+ - xfs: validate cached inodes are free when allocated
+ - perf/x86/intel/uncore: Fix hardcoded index of Broadwell extra PCI devices
+ - parisc: Enable CONFIG_MLONGCALLS by default
+ - parisc: Define mb() and add memory barriers to assembler unlock sequences
+ - kasan: add no_sanitize attribute for clang builds
+ - Mark HI and TASKLET softirq synchronous
+ - xen/netfront: don't cache skb_shinfo()
+ - scsi: sr: Avoid that opening a CD-ROM hangs with runtime power management
+ enabled
+ - scsi: qla2xxx: Fix memory leak for allocating abort IOCB
+ - init: rename and re-order boot_cpu_state_init()
+ - root dentries need RCU-delayed freeing
+ - make sure that __dentry_kill() always invalidates d_seq, unhashed or not
+ - fix mntput/mntput race
+ - fix __legitimize_mnt()/mntput() race
+ - mtd: nand: qcom: Add a NULL check for devm_kasprintf()
+ - phy: phy-mtk-tphy: use auto instead of force to bypass utmi signals
+ - ARM: dts: imx6sx: fix irq for pcie bridge
+ - kprobes/x86: Fix %p uses in error messages
+ - x86/irqflags: Provide a declaration for native_save_fl
+ - x86/apic: Ignore secondary threads if nosmt=force
+ - x86/mm/kmmio: Make the tracer robust against L1TF
+ - tools headers: Synchronise x86 cpufeatures.h for L1TF additions
+ - x86/microcode: Allow late microcode loading with SMT disabled
+ - x86/smp: fix non-SMP broken build due to redefinition of
+ apic_id_is_primary_thread
+ - cpu/hotplug: Non-SMP machines do not make use of booted_once
+ - sched/deadline: Update rq_clock of later_rq when pushing a task
+ - zram: remove BD_CAP_SYNCHRONOUS_IO with writeback feature
+ - x86/l1tf: Fix build error seen if CONFIG_KVM_INTEL is disabled
+ - x86: i8259: Add missing include file
+ - kbuild: verify that $DEPMOD is installed
+ - crypto: x86/sha256-mb - fix digest copy in sha256_mb_mgr_get_comp_job_avx2()
+ - crypto: vmac - require a block cipher with 128-bit block size
+ - crypto: vmac - separate tfm and request context
+ - crypto: blkcipher - fix crash flushing dcache in error path
+ - crypto: ablkcipher - fix crash flushing dcache in error path
+ - crypto: skcipher - fix aligning block size in skcipher_copy_iv()
+ - crypto: skcipher - fix crash flushing dcache in error path
+ - x86/platform/UV: Mark memblock related init code and data correctly
+ - dccp: fix undefined behavior with 'cwnd' shift in ccid2_cwnd_restart()
+ - l2tp: use sk_dst_check() to avoid race on sk->sk_dst_cache
+ - llc: use refcount_inc_not_zero() for llc_sap_find()
+ - vsock: split dwork to avoid reinitializations
+ - net_sched: Fix missing res info when create new tc_index filter
+ - vhost: reset metadata cache when initializing new IOTLB
+ - ip6_tunnel: use the right value for ipv4 min mtu check in ip6_tnl_xmit
+ - net: aquantia: Fix IFF_ALLMULTI flag functionality
+ - ALSA: hda - Sleep for 10ms after entering D3 on Conexant codecs
+ - ALSA: hda - Turn CX8200 into D3 as well upon reboot
+ - ALSA: vx222: Fix invalid endian conversions
+ - ALSA: virmidi: Fix too long output trigger loop
+ - ALSA: cs5535audio: Fix invalid endian conversion
+ - ALSA: hda: Correct Asrock B85M-ITX power_save blacklist entry
+ - ALSA: memalloc: Don't exceed over the requested size
+ - ALSA: vxpocket: Fix invalid endian conversions
+ - USB: serial: sierra: fix potential deadlock at close
+ - USB: serial: pl2303: add a new device id for ATEN
+ - ACPI / PM: save NVS memory for ASUS 1025C laptop
+ - tty: serial: 8250: Revert NXP SC16C2552 workaround
+ - serial: 8250_exar: Read INT0 from slave device, too
+ - serial: 8250_dw: always set baud rate in dw8250_set_termios
+ - serial: 8250_dw: Add ACPI support for uart on Broadcom SoC
+ - misc: sram: fix resource leaks in probe error path
+ - Bluetooth: avoid killing an already killed socket
+ - isdn: Disable IIOCDBGVAR
+ - cls_matchall: fix tcf_unbind_filter missing
+ - mlxsw: core_acl_flex_actions: Return error for conflicting actions
+ - ip_vti: fix a null pointer deferrence when create vti fallback tunnel
+ - net: ethernet: mvneta: Fix napi structure mixup on armada 3700
+ - net: mvneta: fix mvneta_config_rss on armada 3700
+ - EDAC: Add missing MEM_LRDDR4 entry in edac_mem_types[]
+ - pty: fix O_CLOEXEC for TIOCGPTPEER
+ - arm: dts: armada: Fix "#cooling-cells" property's name
+ - vfio: ccw: fix error return in vfio_ccw_sch_event
+ - perf tools: Fix error index for pmu event parser
+ - Input: synaptics-rmi4 - fix axis-swap behavior
+ - IB/mlx4: Fix an error handling path in 'mlx4_ib_rereg_user_mr()'
+ - drm/bridge/sii8620: fix loops in EDID fetch logic
+ - drm/bridge/sii8620: fix potential buffer overflow
+ - ARC: Explicitly add -mmedium-calls to CFLAGS
+ - hwmon: (nct6775) Fix loop limit
+ - soc: imx: gpcv2: correct PGC offset
+ - usb: dwc3: pci: add support for Intel IceLake
+ - usb: dwc2: gadget: Fix issue in dwc2_gadget_start_isoc()
+ - usb: dwc3: of-simple: fix use-after-free on remove
+ - ACPI / EC: Use ec_no_wakeup on Thinkpad X1 Carbon 6th
+ - netfilter: ipv6: nf_defrag: reduce struct net memory waste
+ - netfilter: nf_ct_helper: Fix possible panic after
+ nf_conntrack_helper_unregister
+ - selftests: pstore: return Kselftest Skip code for skipped tests
+ - selftests: static_keys: return Kselftest Skip code for skipped tests
+ - selftests: sysctl: return Kselftest Skip code for skipped tests
+ - selftests: zram: return Kselftest Skip code for skipped tests
+ - selftests: vm: return Kselftest Skip code for skipped tests
+ - selftests: sync: add config fragment for testing sync framework
+ - ARM: dts: NSP: Fix i2c controller interrupt type
+ - ARM: dts: NSP: Fix PCIe controllers interrupt types
+ - ARM: dts: BCM5301x: Fix i2c controller interrupt type
+ - ARM: dts: Cygnus: Fix I2C controller interrupt type
+ - ARM: dts: Cygnus: Fix PCIe controller interrupt type
+ - arm64: dts: specify 1.8V EMMC capabilities for bcm958742k
+ - arm64: dts: specify 1.8V EMMC capabilities for bcm958742t
+ - arm64: dts: ns2: Fix I2C controller interrupt type
+ - arm64: dts: ns2: Fix PCIe controller interrupt type
+ - arm64: dts: Stingray: Fix I2C controller interrupt type
+ - drivers/perf: xgene_pmu: Fix IOB SLOW PMU parser error
+ - drm: mali-dp: Enable Global SE interrupts mask for DP500
+ - drm/arm/malidp: Preserve LAYER_FORMAT contents when setting format
+ - IB/rxe: Fix missing completion for mem_reg work requests
+ - usb: dwc2: alloc dma aligned buffer for isoc split in
+ - usb: dwc2: fix isoc split in transfer with no data
+ - usb: gadget: composite: fix delayed_status race condition when set_interface
+ - usb: gadget: dwc2: fix memory leak in gadget_init()
+ - dwc2: gadget: Fix ISOC IN DDMA PID bitfield value calculation
+ - xen: add error handling for xenbus_printf
+ - pNFS: Always free the session slot on error in
+ nfs4_layoutget_handle_exception
+ - scsi: xen-scsifront: add error handling for xenbus_printf
+ - xen/scsiback: add error handling for xenbus_printf
+ - arm64: dma-mapping: clear buffers allocated with FORCE_CONTIGUOUS flag
+ - arm64: make secondary_start_kernel() notrace
+ - qed: Fix possible memory leak in Rx error path handling.
+ - qed: Add sanity check for SIMD fastpath handler.
+ - qed: Do not advertise DCBX_LLD_MANAGED capability.
+ - enic: initialize enic->rfs_h.lock in enic_probe
+ - net: hamradio: use eth_broadcast_addr
+ - net: propagate dev_get_valid_name return code
+ - net: stmmac: socfpga: add additional ocp reset line for Stratix10
+ - nvmet: reset keep alive timer in controller enable
+ - block: sed-opal: Fix a couple off by one bugs
+ - ARC: Enable machine_desc->init_per_cpu for !CONFIG_SMP
+ - nbd: Add the nbd NBD_DISCONNECT_ON_CLOSE config flag.
+ - net: davinci_emac: match the mdio device against its compatible if possible
+ - sctp: fix erroneous inc of snmp SctpFragUsrMsgs
+ - KVM: arm/arm64: Drop resource size check for GICV window
+ - drm/bridge/sii8620: fix display of packed pixel modes in MHL2
+ - locking/lockdep: Do not record IRQ state within lockdep code
+ - selftests: bpf: notification about privilege required to run test_kmod.sh
+ testing script
+ - mtd: dataflash: Use ULL suffix for 64-bit constants
+ - x86/microcode/intel: Fix memleak in save_microcode_patch()
+ - ipv6: mcast: fix unsolicited report interval after receiving querys
+ - Smack: Mark inode instant in smack_task_to_inode
+ - arm64: dts: msm8916: fix Coresight ETF graph connections
+ - batman-adv: Fix bat_ogm_iv best gw refcnt after netlink dump
+ - batman-adv: Fix bat_v best gw refcnt after netlink dump
+ - batman-adv: Avoid storing non-TT-sync flags on singular entries too
+ - batman-adv: Fix multicast TT issues with bogus ROAM flags
+ - cxgb4: when disabling dcb set txq dcb priority to 0
+ - iio: pressure: bmp280: fix relative humidity unit
+ - brcmfmac: stop watchdog before detach and free everything
+ - ARM: dts: am437x: make edt-ft5x06 a wakeup source
+ - ALSA: seq: Fix UBSAN warning at SNDRV_SEQ_IOCTL_QUERY_NEXT_CLIENT ioctl
+ - usb: xhci: remove the code build warning
+ - usb: xhci: increase CRS timeout value
+ - NFC: pn533: Fix wrong GFP flag usage
+ - typec: tcpm: Fix a msecs vs jiffies bug
+ - kconfig: fix line numbers for if-entries in menu tree
+ - perf record: Support s390 random socket_id assignment
+ - perf test session topology: Fix test on s390
+ - perf report powerpc: Fix crash if callchain is empty
+ - perf tools: Fix a clang 7.0 compilation error
+ - perf bench: Fix numa report output code
+ - ARM: davinci: board-da850-evm: fix WP pin polarity for MMC/SD
+ - netfilter: nf_log: fix uninit read in nf_log_proc_dostring
+ - net/mlx5: E-Switch, Disallow vlan/spoofcheck setup if not being esw manager
+ - nfp: cast sizeof() to int when comparing with error code
+ - selftests/x86/sigreturn/64: Fix spurious failures on AMD CPUs
+ - selftests/x86/sigreturn: Do minor cleanups
+ - ARM: dts: da850: Fix interrups property for gpio
+ - ARM64: dts: meson-gxl: fix Mali GPU compatible string
+ - dmaengine: pl330: report BURST residue granularity
+ - dmaengine: k3dma: Off by one in k3_of_dma_simple_xlate()
+ - ath10k: update the phymode along with bandwidth change request
+ - md/raid10: fix that replacement cannot complete recovery after reassemble
+ - dev-dax: check_vma: ratelimit dev_info-s
+ - nl80211: relax ht operation checks for mesh
+ - nl80211: check nla_parse_nested() return values
+ - drm/exynos: gsc: Fix support for NV16/61, YUV420/YVU420 and YUV422 modes
+ - drm/exynos: decon5433: Fix per-plane global alpha for XRGB modes
+ - drm/exynos: decon5433: Fix WINCONx reset value
+ - drbd: Fix drbd_request_prepare() discard handling
+ - bpf, s390: fix potential memleak when later bpf_jit_prog fails
+ - PCI: xilinx: Add missing of_node_put()
+ - PCI: xilinx-nwl: Add missing of_node_put()
+ - PCI: faraday: Add missing of_node_put()
+ - bnx2x: Fix receiving tx-timeout in error or recovery state.
+ - fsl/fman: fix parser reporting bad checksum on short frames
+ - dpaa_eth: DPAA SGT needs to be 256B
+ - acpi/nfit: fix cmd_rc for acpi_nfit_ctl to always return a value
+ - openrisc: entry: Fix delay slot exception detection
+ - m68k: fix "bad page state" oops on ColdFire boot
+ - objtool: Support GCC 8 '-fnoreorder-functions'
+ - ipvlan: call dev_change_flags when ipvlan mode is reset
+ - drm/amdgpu: fix swapped emit_ib_size in vce3
+ - x86/mm/32: Initialize the CR4 shadow before __flush_tlb_all()
+ - HID: wacom: Correct touch maximum XY of 2nd-gen Intuos
+ - ARM: imx_v4_v5_defconfig: Select ULPI support
+ - bpf: hash map: decrement counter on error
+ - tracing: Use __printf markup to silence compiler
+ - kasan: fix shadow_size calculation error in kasan_module_alloc
+ - smsc75xx: Add workaround for gigabit link up hardware errata.
+ - drm/bridge/sii8620: Fix display of packed pixel modes
+ - samples/bpf: add missing <linux/if_vlan.h>
+ - samples/bpf: Check the result of system()
+ - samples/bpf: Check the error of write() and read()
+ - ieee802154: 6lowpan: set IFLA_LINK
+ - netfilter: x_tables: set module owner for icmp(6) matches
+ - ipv6: make ipv6_renew_options() interrupt/kernel safe
+ - net: qrtr: Broadcast messages only from control port
+ - sh_eth: fix invalid context bug while calling auto-negotiation by ethtool
+ - sh_eth: fix invalid context bug while changing link options by ethtool
+ - ravb: fix invalid context bug while calling auto-negotiation by ethtool
+ - ravb: fix invalid context bug while changing link options by ethtool
+ - ARM: pxa: irq: fix handling of ICMR registers in suspend/resume
+ - net/sched: act_tunnel_key: fix NULL dereference when 'goto chain' is used
+ - nvmem: Don't let a NULL cell_id for nvmem_cell_get() crash us
+ - ieee802154: at86rf230: switch from BUG_ON() to WARN_ON() on problem
+ - ieee802154: at86rf230: use __func__ macro for debug messages
+ - ieee802154: fakelb: switch from BUG_ON() to WARN_ON() on problem
+ - gpu: host1x: Check whether size of unpin isn't 0
+ - drm/tegra: Fix comparison operator for buffer size
+ - drm/armada: fix colorkey mode property
+ - drm/armada: fix irq handling
+ - netfilter: nft_compat: explicitly reject ERROR and standard target
+ - netfilter: nf_conntrack: Fix possible possible crash on module loading.
+ - ARC: Improve cmpxchg syscall implementation
+ - bnxt_en: Fix inconsistent BNXT_FLAG_AGG_RINGS logic.
+ - bnxt_en: Always set output parameters in bnxt_get_max_rings().
+ - bnxt_en: Fix for system hang if request_irq fails
+ - scsi: qedf: Send the driver state to MFW
+ - scsi: qedi: Send driver state to MFW
+ - perf llvm-utils: Remove bashism from kernel include fetch script
+ - perf tools: Fix compilation errors on gcc8
+ - perf script python: Fix dict reference counting
+ - nfit: fix unchecked dereference in acpi_nfit_ctl
+ - RDMA/mlx5: Fix memory leak in mlx5_ib_create_srq() error path
+ - ARM: 8780/1: ftrace: Only set kernel memory back to read-only after boot
+ - ARM: DRA7/OMAP5: Enable ACTLR[0] (Enable invalidates of BTB) for secondary
+ cores
+ - ARM: dts: am3517.dtsi: Disable reference to OMAP3 OTG controller
+ - ixgbe: Be more careful when modifying MAC filters
+ - tools: build: Use HOSTLDFLAGS with fixdep
+ - kbuild: suppress warnings from 'getconf LFS_*'
+ - packet: reset network header if packet shorter than ll reserved space
+ - qlogic: check kstrtoul() for errors
+ - tcp: remove DELAYED ACK events in DCTCP
+ - pinctrl: ingenic: Fix inverted direction for < JZ4770
+ - pinctrl: nsp: off by ones in nsp_pinmux_enable()
+ - pinctrl: nsp: Fix potential NULL dereference
+ - drm/nouveau/gem: off by one bugs in nouveau_gem_pushbuf_reloc_apply()
+ - net/ethernet/freescale/fman: fix cross-build error
+ - ibmvnic: Fix error recovery on login failure
+ - btrfs: scrub: Don't use inode page cache in scrub_handle_errored_block()
+ - octeon_mgmt: Fix MIX registers configuration on MTU setup
+ - net: usb: rtl8150: demote allmulti message to dev_dbg()
+ - PCI: OF: Fix I/O space page leak
+ - PCI: versatile: Fix I/O space page leak
+ - net: qca_spi: Avoid packet drop during initial sync
+ - net: qca_spi: Make sure the QCA7000 reset is triggered
+ - net: qca_spi: Fix log level if probe fails
+ - tcp: identify cryptic messages as TCP seq # bugs
+ - soc: imx: gpc: restrict register range for regmap access
+ - ACPI / EC: Use ec_no_wakeup on more Thinkpad X1 Carbon 6th systems
+ - ARM: dts: imx6: RDU2: fix irq type for mv88e6xxx switch
+ - nvme: fix handling of metadata_len for NVME_IOCTL_IO_CMD
+ - parisc: Remove ordered stores from syscall.S
+ - xfrm_user: prevent leaking 2 bytes of kernel memory
+ - netfilter: conntrack: dccp: treat SYNC/SYNCACK as invalid if no prior state
+ - packet: refine ring v3 block size test to hold one frame
+ - net/smc: no shutdown in state SMC_LISTEN
+ - parisc: Remove unnecessary barriers from spinlock.h
+ - PCI: hotplug: Don't leak pci_slot on registration failure
+ - PCI: Skip MPS logic for Virtual Functions (VFs)
+ - PCI: pciehp: Fix use-after-free on unplug
+ - PCI: pciehp: Fix unprotected list iteration in IRQ handler
+ - i2c: core: ACPI: Properly set status byte to 0 for multi-byte writes
+ - i2c: imx: Fix race condition in dma read
+ - reiserfs: fix broken xattr handling (heap corruption, bad retval)
+ - updateconfigs for v4.14.67
+ - IB/rxe: avoid double kfree skb
+ - RDMA/qedr: Fix NULL pointer dereference when running over iWARP without
+ RDMA-CM
+ - smb3: increase initial number of credits requested to allow write
+ - hwmon: (dell-smm) Disable fan support for Dell XPS13 9333
+ - ARM: dts: HR2: Fix interrupt types for i2c and PCIe
+ - drm/arm/malidp: Ensure that the crtcs are shutdown before removing any
+ encoder/connector
+ - drm/mali-dp: Rectify the width and height passed to rotmem_required()
+ - dmaengine: ti: omap-dma: Fix OMAP1510 incorrect residue_granularity
+ - nvme-rdma: fix possible double free condition when failing to create a
+ controller
+ - nvme-rdma: Fix command completion race at error recovery
+ - nvme-pci: move nvme_kill_queues to nvme_remove_dead_ctrl
+ - clk: sunxi-ng: replace lib-y with obj-y
+ - batman-adv: Fix debugfs path for renamed hardif
+ - batman-adv: Fix debugfs path for renamed softif
+ - nfp: bpf: don't stop offload if replace failed
+ - perf tests: Add event parsing error handling to parse events test
+ - perf script: Fix crash because of missing evsel->priv
+ - perf tools: Fix crash caused by accessing feat_ops[HEADER_LAST_FEATURE]
+ - s390/qeth: consistently re-enable device features
+ - sched/fair: Fix bandwidth timer clock drift condition
+ - r8169: fix mac address change
+ - RISC-V: Don't include irq-riscv-intc.h
+ - RISC-V: Fix PTRACE_SETREGSET bug.
+ - net: qrtr: Reset the node and port ID of broadcast messages
+ - cxgb4: assume flash part size to be 4MB, if it can't be determined
+ - bpf: fix sk_skb programs without skb->dev assigned
+ - ipfrag: really prevent allocation on netns exit
+ - gpu: host1x: Skip IOMMU initialization if firewall is enabled
+ - ARC: [plat-hsdk]: Configure APB GPIO controller on ARC HSDK platform
+ - bnxt_en: Do not modify max IRQ count after RDMA driver requests/frees IRQs.
+ - scsi: hpsa: correct enclosure sas address
+ - perf tools: Use python-config --includes rather than --cflags
+ - sfp: ensure we clean up properly on bus registration failure
+ - amd/dc/dce100: On dce100, set clocks to 0 on suspend
+ - tools: build: Fixup host c flags
+ - kvm: nVMX: Restore exit qual for VM-entry failure due to MSR loading
+ - ibmvnic: Revise RX/TX queue error messages
+ - net/smc: reset recv timeout after clc handshake
+ - PCI: xgene: Fix I/O space page leak
+ - PCI: designware: Fix I/O space page leak
+ - PCI: aardvark: Fix I/O space page leak
+ - PCI: faraday: Fix I/O space page leak
+ - PCI: mediatek: Fix I/O space page leak
+ - PCI: v3-semi: Fix I/O space page leak
+ - platform/x86: dell-laptop: Fix backlight detection
+ - mm: use helper functions for allocating and freeing vm_area structs
+ - mm: make vm_area_dup() actually copy the old vma data
+ - mm: make vm_area_alloc() initialize core fields
+ - PCI / ACPI / PM: Resume all bridges on suspend-to-RAM
+
+ -- Sultan Alsawaf <sultan.alsawaf@canonical.com> Wed, 24 Jul 2019 09:50:49 -0600
+
+linux (4.15.0-55.60) bionic; urgency=medium
+
+ * linux: 4.15.0-55.60 -proposed tracker (LP: #1834954)
+
+ * Request backport of ceph commits into bionic (LP: #1834235)
+ - ceph: use atomic_t for ceph_inode_info::i_shared_gen
+ - ceph: define argument structure for handle_cap_grant
+ - ceph: flush pending works before shutdown super
+ - ceph: send cap releases more aggressively
+ - ceph: single workqueue for inode related works
+ - ceph: avoid dereferencing invalid pointer during cached readdir
+ - ceph: quota: add initial infrastructure to support cephfs quotas
+ - ceph: quota: support for ceph.quota.max_files
+ - ceph: quota: don't allow cross-quota renames
+ - ceph: fix root quota realm check
+ - ceph: quota: support for ceph.quota.max_bytes
+ - ceph: quota: update MDS when max_bytes is approaching
+ - ceph: quota: add counter for snaprealms with quota
+ - ceph: avoid iput_final() while holding mutex or in dispatch thread
+
+ * QCA9377 isn't being recognized sometimes (LP: #1757218)
+ - SAUCE: USB: Disable USB2 LPM at shutdown
+
+ * hns: fix ICMP6 neighbor solicitation messages discard problem (LP: #1833140)
+ - net: hns: fix ICMP6 neighbor solicitation messages discard problem
+ - net: hns: fix unsigned comparison to less than zero
+
+ * Fix occasional boot time crash in hns driver (LP: #1833138)
+ - net: hns: Fix probabilistic memory overwrite when HNS driver initialized
+
+ * use-after-free in hns_nic_net_xmit_hw (LP: #1833136)
+ - net: hns: fix KASAN: use-after-free in hns_nic_net_xmit_hw()
+
+ * hns: attempt to restart autoneg when disabled should report error
+ (LP: #1833147)
+ - net: hns: Restart autoneg need return failed when autoneg off
+
+ * systemd 237-3ubuntu10.14 ADT test failure on Bionic ppc64el (test-seccomp)
+ (LP: #1821625)
+ - powerpc: sys_pkey_alloc() and sys_pkey_free() system calls
+ - powerpc: sys_pkey_mprotect() system call
+
+ * [UBUNTU] pkey: Indicate old mkvp only if old and curr. mkvp are different
+ (LP: #1832625)
+ - pkey: Indicate old mkvp only if old and current mkvp are different
+
+ * [UBUNTU] kernel: Fix gcm-aes-s390 wrong scatter-gather list processing
+ (LP: #1832623)
+ - s390/crypto: fix gcm-aes-s390 selftest failures
+
+ * System crashes on hot adding a core with drmgr command (4.15.0-48-generic)
+ (LP: #1833716)
+ - powerpc/numa: improve control of topology updates
+ - powerpc/numa: document topology_updates_enabled, disable by default
+
+ * Kernel modules generated incorrectly when system is localized to a non-
+ English language (LP: #1828084)
+ - scripts: override locale from environment when running recordmcount.pl
+
+ * [UBUNTU] kernel: Fix wrong dispatching for control domain CPRBs
+ (LP: #1832624)
+ - s390/zcrypt: Fix wrong dispatching for control domain CPRBs
+
+ * CVE-2019-11815
+ - net: rds: force to destroy connection if t_sock is NULL in
+ rds_tcp_kill_sock().
+
+ * Sound device not detected after resume from hibernate (LP: #1826868)
+ - drm/i915: Force 2*96 MHz cdclk on glk/cnl when audio power is enabled
+ - drm/i915: Save the old CDCLK atomic state
+ - drm/i915: Remove redundant store of logical CDCLK state
+ - drm/i915: Skip modeset for cdclk changes if possible
+
+ * Handle overflow in proc_get_long of sysctl (LP: #1833935)
+ - sysctl: handle overflow in proc_get_long
+
+ * Dell XPS 13 (9370) defaults to s2idle sleep/suspend instead of deep, NVMe
+ drains lots of power under s2idle (LP: #1808957)
+ - Revert "UBUNTU: SAUCE: pci/nvme: prevent WDC PC SN720 NVMe from entering D3
+ and being disabled"
+ - Revert "UBUNTU: SAUCE: nvme: add quirk to not call disable function when
+ suspending"
+ - Revert "UBUNTU: SAUCE: pci: prevent Intel NVMe SSDPEKKF from entering D3"
+ - Revert "SAUCE: nvme: add quirk to not call disable function when suspending"
+ - Revert "SAUCE: pci: prevent sk hynix nvme from entering D3"
+ - PCI: PM: Avoid possible suspend-to-idle issue
+ - PCI: PM: Skip devices in D0 for suspend-to-idle
+ - nvme-pci: Sync queues on reset
+ - nvme: Export get and set features
+ - nvme-pci: Use host managed power state for suspend
+
+ * linux v4.15 ftbfs on a newer host kernel (e.g. hwe) (LP: #1823429)
+ - selinux: use kernel linux/socket.h for genheaders and mdp
+
+ * 32-bit x86 kernel 4.15.0-50 crash in vmalloc_sync_all (LP: #1830433)
+ - x86/mm/pat: Disable preemption around __flush_tlb_all()
+ - x86/mm: Drop usage of __flush_tlb_all() in kernel_physical_mapping_init()
+ - x86/mm: Disable ioremap free page handling on x86-PAE
+ - ioremap: Update pgtable free interfaces with addr
+ - x86/mm: Add TLB purge to free pmd/pte page interfaces
+ - x86/init: fix build with CONFIG_SWAP=n
+ - x86/mm: provide pmdp_establish() helper
+ - x86/mm: Use WRITE_ONCE() when setting PTEs
+
+ * hinic: fix oops due to race in set_rx_mode (LP: #1832048)
+ - hinic: fix a bug in set rx mode
+
+ * ubuntu 18.04 flickering screen with Radeon X1600 (LP: #1791312)
+ - drm/radeon: prefer lower reference dividers
+
+ * Login screen never appears on vmwgfx using bionic kernel 4.15 (LP: #1832138)
+ - drm/vmwgfx: use monotonic event timestamps
+
+ * [linux-azure] Block Layer Commits Requested in Azure Kernels (LP: #1834499)
+ - block: Clear kernel memory before copying to user
+ - block/bio: Do not zero user pages
+
+ * CONFIG_LOG_BUF_SHIFT set to 14 is too low on arm64 (LP: #1824864)
+ - [Config] CONFIG_LOG_BUF_SHIFT=18 on all 64bit arches
+
+ * Handle overflow for file-max (LP: #1834310)
+ - sysctl: handle overflow for file-max
+ - kernel/sysctl.c: fix out-of-bounds access when setting file-max
+
+ * [ALSA] [PATCH] Headset fixup for System76 Gazelle (gaze14) (LP: #1827555)
+ - ALSA: hda/realtek - Headset fixup for System76 Gazelle (gaze14)
+ - ALSA: hda/realtek - Corrected fixup for System76 Gazelle (gaze14)
+
+ * crashdump fails on HiSilicon D06 (LP: #1828868)
+ - iommu/arm-smmu-v3: Abort all transactions if SMMU is enabled in kdump kernel
+ - iommu/arm-smmu-v3: Don't disable SMMU in kdump kernel
+
+ * CVE-2019-11833
+ - ext4: zero out the unused memory region in the extent tree block
+
+ * zfs 0.7.9 fixes a bug (https://github.com/zfsonlinux/zfs/pull/7343) that
+ hangs the system completely (LP: #1772412)
+ - SAUCE: (noup) Update zfs to 0.7.5-1ubuntu16.6
+
+ * does not detect headphone when there is no other output devices
+ (LP: #1831065)
+ - ALSA: hda/realtek - Fixed hp_pin no value
+ - ALSA: hda/realtek - Use a common helper for hp pin reference
+
+ * kernel crash : net_sched race condition in tcindex_destroy() (LP: #1825942)
+ - net_sched: fix NULL pointer dereference when delete tcindex filter
+ - RCU, workqueue: Implement rcu_work
+ - net_sched: switch to rcu_work
+ - net_sched: fix a race condition in tcindex_destroy()
+ - net_sched: fix a memory leak in cls_tcindex
+ - net_sched: initialize net pointer inside tcf_exts_init()
+ - net_sched: fix two more memory leaks in cls_tcindex
+
+ * Support new ums-realtek device (LP: #1831840)
+ - USB: usb-storage: Add new ID to ums-realtek
+
+ * amd_iommu possible data corruption (LP: #1823037)
+ - iommu/amd: Reserve exclusion range in iova-domain
+ - iommu/amd: Set exclusion range correctly
+
+ * Add new sound card PCIID into the alsa driver (LP: #1832299)
+ - ALSA: hda: Add Icelake PCI ID
+ - ALSA: hda/intel: add CometLake PCI IDs
+
+ * sky2 ethernet card doesn't work after returning from suspend
+ (LP: #1807259) // sky2 ethernet card link not up after suspend
+ (LP: #1809843)
+ - sky2: Disable MSI on Dell Inspiron 1545 and Gateway P-79
+
+ * idle-page oopses when accessing page frames that are out of range
+ (LP: #1833410)
+ - mm/page_idle.c: fix oops because end_pfn is larger than max_pfn
+
+ * Add pointstick support on HP ZBook 17 G5 (LP: #1833387)
+ - Revert "HID: multitouch: Support ALPS PTP stick with pid 0x120A"
+ - SAUCE: HID: multitouch: Add pointstick support for ALPS Touchpad
+
+ * [SRU][B/B-OEM/B-OEM-OSP-1/C/D/E] Add trackpoint middle button support of 2
+ new thinpads (LP: #1833637)
+ - Input: elantech - enable middle button support on 2 ThinkPads
+
+ * CVE-2019-11085
+ - drm/i915/gvt: Fix mmap range check
+ - drm/i915: make mappable struct resource centric
+ - drm/i915/gvt: Fix aperture read/write emulation when enable x-no-mmap=on
+
+ * CVE-2019-11884
+ - Bluetooth: hidp: fix buffer overflow
+
+ * af_alg06 test from crypto test suite in LTP failed with kernel oops on B/C
+ (LP: #1829725)
+ - crypto: authenc - fix parsing key with misaligned rta_len
+
+ * CVE-2018-12126 // CVE-2018-12127 // CVE-2018-12130 // CVE-2019-11091
+ - SAUCE: Synchronize MDS mitigations with upstream
+ - Documentation: Correct the possible MDS sysfs values
+ - x86/speculation/mds: Fix documentation typo
+
+ * CVE-2019-11091
+ - x86/mds: Add MDSUM variant to the MDS documentation
+
+ * alignment test in powerpc from ubuntu_kernel_selftests failed on B/C Power9
+ (LP: #1813118)
+ - selftests/powerpc: Remove Power9 copy_unaligned test
+
+ * TRACE_syscall.ptrace_syscall_dropped in seccomp from ubuntu_kernel_selftests
+ failed on B/C PowerPC (LP: #1812796)
+ - selftests/seccomp: Enhance per-arch ptrace syscall skip tests
+
+ * Add powerpc/alignment_handler test for selftests (LP: #1828935)
+ - selftests/powerpc: Add alignment handler selftest
+ - selftests/powerpc: Fix to use ucontext_t instead of struct ucontext
+
+ * Cannot build kernel 4.15.0-48.51 due to an in-source-tree ZFS module.
+ (LP: #1828763)
+ - SAUCE: (noup) Update zfs to 0.7.5-1ubuntu16.5
+
+ * Eletrical noise occurred when external headset enter powersaving mode on a
+ DEll machine (LP: #1828798)
+ - ALSA: hda/realtek - Reduce click noise on Dell Precision 5820 headphone
+ - ALSA: hda/realtek - Fixup headphone noise via runtime suspend
+
+ * [18.04/18.10] File libperf-jvmti.so is missing in linux-tools-common deb on
+ Ubuntu (LP: #1761379)
+ - [Packaging] Support building libperf-jvmti.so
+
+ * TCP : race condition on socket ownership in tcp_close() (LP: #1830813)
+ - tcp: do not release socket ownership in tcp_close()
+
+ * bionic: netlink: potential shift overflow in netlink_bind() (LP: #1831103)
+ - netlink: Don't shift on 64 for ngroups
+
+ * Add support to Comet Lake LPSS (LP: #1830175)
+ - mfd: intel-lpss: Add Intel Comet Lake PCI IDs
+
+ * Reduce NAPI weight in hns driver from 256 to 64 (LP: #1830587)
+ - net: hns: Use NAPI_POLL_WEIGHT for hns driver
+
+ * x86: add support for AMD Rome (LP: #1819485)
+ - x86: irq_remapping: Move irq remapping mode enum
+ - iommu/amd: Add support for higher 64-bit IOMMU Control Register
+ - iommu/amd: Add support for IOMMU XT mode
+ - hwmon/k10temp, x86/amd_nb: Consolidate shared device IDs
+ - hwmon/k10temp: Add support for AMD family 17h, model 30h CPUs
+ - x86/amd_nb: Add PCI device IDs for family 17h, model 30h
+ - x86/MCE/AMD: Fix the thresholding machinery initialization order
+ - x86/amd_nb: Add support for newer PCI topologies
+
+ * nx842 - CRB request time out (-110) when uninstall NX modules and initiate
+ NX request (LP: #1827755)
+ - crypto/nx: Initialize 842 high and normal RxFIFO control registers
+
+ * Require improved hypervisor detection patch in Ubuntu 18.04 (LP: #1829972)
+ - s390/early: improve machine detection
+
+ -- Kleber Sacilotto de Souza <kleber.souza@canonical.com> Tue, 02 Jul 2019 18:41:49 +0200
+
+linux (4.15.0-54.58) bionic; urgency=medium
+
+ * linux: 4.15.0-54.58 -proposed tracker (LP: #1833987)
+
+ * Remote denial of service (resource exhaustion) caused by TCP SACK scoreboard
+ manipulation (LP: #1831638) // CVE-2019-11478
+ - tcp: refine memory limit test in tcp_fragment()
+
+ * CVE-2019-11479
+ - SAUCE: tcp: add tcp_min_snd_mss sysctl
+ - SAUCE: tcp: enforce tcp_min_snd_mss in tcp_mtu_probing()
+
+ -- Kleber Sacilotto de Souza <kleber.souza@canonical.com> Mon, 24 Jun 2019 11:39:50 +0200
+
+linux (4.15.0-52.56) bionic; urgency=medium
+
+ * Remote denial of service (resource exhaustion) caused by TCP SACK scoreboard
+ manipulation (LP: #1831638)
+ - SAUCE: tcp: tcp_fragment() should apply sane memory limits
+
+ * Remote denial of service (system crash) caused by integer overflow in TCP
+ SACK handling (LP: #1831637)
+ - SAUCE: tcp: limit payload size of sacked skbs
+
+ -- Marcelo Henrique Cerri <marcelo.cerri@canonical.com> Tue, 04 Jun 2019 17:33:24 -0300
+
+linux (4.15.0-51.55) bionic; urgency=medium
+
+ * linux: 4.15.0-51.55 -proposed tracker (LP: #1829219)
+
+ * disable a.out support (LP: #1818552)
+ - [Config] Disable a.out support
+
+ * [UBUNTU] qdio: clear intparm during shutdown (LP: #1828394)
+ - s390/qdio: clear intparm during shutdown
+
+ * ftrace in ubuntu_kernel_selftests hang with Cosmic kernel (LP: #1826385)
+ - kprobes/x86: Fix instruction patching corruption when copying more than one
+ RIP-relative instruction
+
+ * touchpad not working on lenovo yoga 530 (LP: #1787775)
+ - Revert "UBUNTU: SAUCE: i2c:amd Depends on ACPI"
+ - Revert "UBUNTU: SAUCE: i2c:amd move out pointer in union i2c_event_base"
+ - Revert "UBUNTU: SAUCE: i2c:amd I2C Driver based on PCI Interface for
+ upcoming platform"
+ - i2c: add helpers to ease DMA handling
+ - i2c: add a message flag for DMA safe buffers
+ - i2c: add extra check to safe DMA buffer helper
+ - i2c: Add drivers for the AMD PCIe MP2 I2C controller
+ - [Config] Update config for AMD MP2 I2C driver
+ - [Config] Update I2C_AMD_MP2 annotations
+
+ * tm-unavailable in powerpc/tm failed on Bionic Power9 (LP: #1813129)
+ - selftests/powerpc: Check for pthread errors in tm-unavailable
+ - selftests/powerpc: Skip tm-unavailable if TM is not enabled
+
+ * cp_abort in powerpc/context_switch from ubunut_kernel_selftests failed on
+ Bionic P9 (LP: #1813134)
+ - selftests/powerpc: Remove redundant cp_abort test
+
+ * bionic/linux: completely remove snapdragon files from sources (LP: #1827880)
+ - [Packaging] remove snapdragon dead files
+ - [Config] update configs after snapdragon removal
+
+ * The noise keeps occurring when Headset is plugged in on a Dell machine
+ (LP: #1827972)
+ - ALSA: hda/realtek - Fixed Dell AIO speaker noise
+
+ * Geneve tunnels don't work when ipv6 is disabled (LP: #1794232)
+ - geneve: correctly handle ipv6.disable module parameter
+
+ * There are 4 HDMI/Displayport audio output listed in sound setting without
+ attach any HDMI/DP monitor (LP: #1827967)
+ - ALSA: hda/hdmi - Read the pin sense from register when repolling
+ - ALSA: hda/hdmi - Consider eld_valid when reporting jack event
+
+ * Headphone jack switch sense is inverted: plugging in headphones disables
+ headphone output (LP: #1824259)
+ - ASoC: rt5645: Headphone Jack sense inverts on the LattePanda board
+
+ * CTAUTO:DevOps:860.50:devops4fp1:Error occurred during LINUX Dmesg error
+ Checking for all LINUX clients for devops4p10 (LP: #1766201)
+ - SAUCE: integrity: downgrade error to warning
+
+ * Screen freeze after resume from S3 when HDMI monitor plugged on Dell
+ Precision 7740 (LP: #1825958)
+ - PCI: Restore resized BAR state on resume
+
+ * potential memory corruption on arm64 on dev release (LP: #1827437)
+ - driver core: Postpone DMA tear-down until after devres release
+
+ * powerpc/pmu/ebb test in ubuntu_kernel_selftest failed with "error while
+ loading shared libraries" on Bionic/Cosmic PowerPC (LP: #1812805)
+ - selftests/powerpc/pmu: Link ebb tests with -no-pie
+
+ * unnecessary request_queue freeze (LP: #1815733)
+ - block: avoid setting nr_requests to current value
+ - block: avoid setting none scheduler if it's already none
+
+ * Kprobe event string type argument failed in ftrace from
+ ubuntu_kernel_selftests on B/C i386 (LP: #1825780)
+ - selftests/ftrace: Fix kprobe string testcase to not probe notrace function
+
+ * hns: fix socket accounting (LP: #1826911)
+ - net: hns: fix skb->truesize underestimation
+
+ * False positive test result in run_netsocktests from net in
+ ubuntu_kernel_selftest (LP: #1825777)
+ - selftests/net: correct the return value for run_netsocktests
+
+ -- Kleber Sacilotto de Souza <kleber.souza@canonical.com> Wed, 15 May 2019 14:48:35 +0200
+
+linux (4.15.0-50.54) bionic; urgency=medium
+
+ * CVE-2018-12126 // CVE-2018-12127 // CVE-2018-12130
+ - Documentation/l1tf: Fix small spelling typo
+ - x86/cpu: Sanitize FAM6_ATOM naming
+ - kvm: x86: Report STIBP on GET_SUPPORTED_CPUID
+ - locking/atomics, asm-generic: Move some macros from <linux/bitops.h> to a
+ new <linux/bits.h> file
+ - tools include: Adopt linux/bits.h
+ - x86/msr-index: Cleanup bit defines
+ - x86/speculation: Consolidate CPU whitelists
+ - x86/speculation/mds: Add basic bug infrastructure for MDS
+ - x86/speculation/mds: Add BUG_MSBDS_ONLY
+ - x86/kvm: Expose X86_FEATURE_MD_CLEAR to guests
+ - x86/speculation/mds: Add mds_clear_cpu_buffers()
+ - x86/speculation/mds: Clear CPU buffers on exit to user
+ - x86/kvm/vmx: Add MDS protection when L1D Flush is not active
+ - x86/speculation/mds: Conditionally clear CPU buffers on idle entry
+ - x86/speculation/mds: Add mitigation control for MDS
+ - x86/speculation/mds: Add sysfs reporting for MDS
+ - x86/speculation/mds: Add mitigation mode VMWERV
+ - Documentation: Move L1TF to separate directory
+ - Documentation: Add MDS vulnerability documentation
+ - x86/speculation/mds: Add mds=full,nosmt cmdline option
+ - x86/speculation: Move arch_smt_update() call to after mitigation decisions
+ - x86/speculation/mds: Add SMT warning message
+ - x86/speculation/mds: Fix comment
+ - x86/speculation/mds: Print SMT vulnerable on MSBDS with mitigations off
+ - x86/speculation/mds: Add 'mitigations=' support for MDS
+
+ * CVE-2017-5715 // CVE-2017-5753
+ - s390/speculation: Support 'mitigations=' cmdline option
+
+ * CVE-2017-5715 // CVE-2017-5753 // CVE-2017-5754 // CVE-2018-3639
+ - powerpc/speculation: Support 'mitigations=' cmdline option
+
+ * CVE-2017-5715 // CVE-2017-5754 // CVE-2018-3620 // CVE-2018-3639 //
+ CVE-2018-3646
+ - cpu/speculation: Add 'mitigations=' cmdline option
+ - x86/speculation: Support 'mitigations=' cmdline option
+
+ * Packaging resync (LP: #1786013)
+ - [Packaging] resync git-ubuntu-log
+
+ -- Stefan Bader <stefan.bader@canonical.com> Mon, 06 May 2019 18:59:24 +0200
+
+linux (4.15.0-49.53) bionic; urgency=medium
+
+ * linux: 4.15.0-49.53 -proposed tracker (LP: #1826358)
+
+ * Backport support for software count cache flush Spectre v2 mitigation. (CVE)
+ (required for POWER9 DD2.3) (LP: #1822870)
+ - powerpc/64s: Add support for ori barrier_nospec patching
+ - powerpc/64s: Patch barrier_nospec in modules
+ - powerpc/64s: Enable barrier_nospec based on firmware settings
+ - powerpc: Use barrier_nospec in copy_from_user()
+ - powerpc/64: Use barrier_nospec in syscall entry
+ - powerpc/64s: Enhance the information in cpu_show_spectre_v1()
+ - powerpc/64: Disable the speculation barrier from the command line
+ - powerpc/64: Make stf barrier PPC_BOOK3S_64 specific.
+ - powerpc/64: Add CONFIG_PPC_BARRIER_NOSPEC
+ - powerpc/64: Call setup_barrier_nospec() from setup_arch()
+ - powerpc/64: Make meltdown reporting Book3S 64 specific
+ - powerpc/lib/code-patching: refactor patch_instruction()
+ - powerpc/lib/feature-fixups: use raw_patch_instruction()
+ - powerpc/asm: Add a patch_site macro & helpers for patching instructions
+ - powerpc/64s: Add new security feature flags for count cache flush
+ - powerpc/64s: Add support for software count cache flush
+ - powerpc/pseries: Query hypervisor for count cache flush settings
+ - powerpc/powernv: Query firmware for count cache flush settings
+ - powerpc/fsl: Add nospectre_v2 command line argument
+ - KVM: PPC: Book3S: Add count cache flush parameters to kvmppc_get_cpu_char()
+ - [Config] Add CONFIG_PPC_BARRIER_NOSPEC
+
+ * Packaging resync (LP: #1786013)
+ - [Packaging] resync git-ubuntu-log
+
+ * autopkgtests run too often, too much and don't skip enough (LP: #1823056)
+ - [Debian] Set +x on rebuild testcase.
+ - [Debian] Skip rebuild test, for regression-suite deps.
+ - [Debian] Make ubuntu-regression-suite skippable on unbootable kernels.
+ - [Debian] make rebuild use skippable error codes when skipping.
+ - [Debian] Only run regression-suite, if requested to.
+
+ * bionic: fork out linux-snapdragon into its own topic kernel (LP: #1820868)
+ - [Packaging] remove arm64 snapdragon from getabis
+ - [Config] config changes for snapdragon split
+ - packaging: arm64: disable building the snapdragon flavour
+ - [Packaging] arm64: Drop snapdragon from kernel-versions
+
+ * CVE-2017-5753
+ - KVM: arm/arm64: vgic: fix possible spectre-v1 in vgic_get_irq()
+ - media: dvb_ca_en50221: prevent using slot_info for Spectre attacs
+ - sysvipc/sem: mitigate semnum index against spectre v1
+ - libahci: Fix possible Spectre-v1 pmp indexing in ahci_led_store()
+ - s390/keyboard: sanitize array index in do_kdsk_ioctl
+ - arm64: fix possible spectre-v1 write in ptrace_hbp_set_event()
+ - KVM: arm/arm64: vgic: Fix possible spectre-v1 write in vgic_mmio_write_apr()
+ - pktcdvd: Fix possible Spectre-v1 for pkt_devs
+ - net: socket: fix potential spectre v1 gadget in socketcall
+ - net: socket: Fix potential spectre v1 gadget in sock_is_registered
+ - drm/amdgpu/pm: Fix potential Spectre v1
+ - netlink: Fix spectre v1 gadget in netlink_create()
+ - ext4: fix spectre gadget in ext4_mb_regular_allocator()
+ - drm/i915/kvmgt: Fix potential Spectre v1
+ - net: sock_diag: Fix spectre v1 gadget in __sock_diag_cmd()
+ - fs/quota: Fix spectre gadget in do_quotactl
+ - hwmon: (nct6775) Fix potential Spectre v1
+ - mac80211_hwsim: Fix possible Spectre-v1 for hwsim_world_regdom_custom
+ - switchtec: Fix Spectre v1 vulnerability
+ - misc: hmc6352: fix potential Spectre v1
+ - tty: vt_ioctl: fix potential Spectre v1
+ - nl80211: Fix possible Spectre-v1 for NL80211_TXRATE_HT
+ - nl80211: Fix possible Spectre-v1 for CQM RSSI thresholds
+ - IB/ucm: Fix Spectre v1 vulnerability
+ - RDMA/ucma: Fix Spectre v1 vulnerability
+ - drm/bufs: Fix Spectre v1 vulnerability
+ - usb: gadget: storage: Fix Spectre v1 vulnerability
+ - ptp: fix Spectre v1 vulnerability
+ - HID: hiddev: fix potential Spectre v1
+ - vhost: Fix Spectre V1 vulnerability
+ - drivers/misc/sgi-gru: fix Spectre v1 vulnerability
+ - ipv4: Fix potential Spectre v1 vulnerability
+ - aio: fix spectre gadget in lookup_ioctx
+ - ALSA: emux: Fix potential Spectre v1 vulnerabilities
+ - ALSA: pcm: Fix potential Spectre v1 vulnerability
+ - ip6mr: Fix potential Spectre v1 vulnerability
+ - ALSA: rme9652: Fix potential Spectre v1 vulnerability
+ - ALSA: emu10k1: Fix potential Spectre v1 vulnerabilities
+ - KVM: arm/arm64: vgic: Fix off-by-one bug in vgic_get_irq()
+ - drm/ioctl: Fix Spectre v1 vulnerabilities
+ - char/mwave: fix potential Spectre v1 vulnerability
+ - applicom: Fix potential Spectre v1 vulnerabilities
+ - ipmi: msghandler: Fix potential Spectre v1 vulnerabilities
+ - powerpc/ptrace: Mitigate potential Spectre v1
+ - cfg80211: prevent speculation on cfg80211_classify8021d() return
+ - ALSA: rawmidi: Fix potential Spectre v1 vulnerability
+ - ALSA: seq: oss: Fix Spectre v1 vulnerability
+
+ * Bionic: Sync to Xenial (Spectre) (LP: #1822760)
+ - x86/speculation/l1tf: Suggest what to do on systems with too much RAM
+ - KVM: SVM: Add MSR-based feature support for serializing LFENCE
+ - KVM: VMX: fixes for vmentry_l1d_flush module parameter
+ - KVM: X86: Allow userspace to define the microcode version
+ - SAUCE: [Fix] x86/KVM/VMX: Add L1D flush logic
+ - SAUCE: [Fix] x86/speculation: Use ARCH_CAPABILITIES to skip L1D flush on
+ vmentry
+
+ * [SRU] [B/OEM] Fix ACPI bug that causes boot failure (LP: #1819921)
+ - SAUCE: ACPI / bus: Add some Lenovo laptops in list of acpi table term list
+
+ * Bionic update: upstream stable patchset for fuse 2019-04-12 (LP: #1824553)
+ - fuse: fix double request_end()
+ - fuse: fix unlocked access to processing queue
+ - fuse: umount should wait for all requests
+ - fuse: Fix oops at process_init_reply()
+ - fuse: Don't access pipe->buffers without pipe_lock()
+ - fuse: Fix use-after-free in fuse_dev_do_read()
+ - fuse: Fix use-after-free in fuse_dev_do_write()
+ - fuse: set FR_SENT while locked
+ - fuse: fix blocked_waitq wakeup
+ - fuse: fix leaked notify reply
+ - fuse: fix possibly missed wake-up after abort
+ - fuse: fix use-after-free in fuse_direct_IO()
+ - fuse: continue to send FUSE_RELEASEDIR when FUSE_OPEN returns ENOSYS
+ - fuse: handle zero sized retrieve correctly
+ - fuse: call pipe_buf_release() under pipe lock
+ - fuse: decrement NR_WRITEBACK_TEMP on the right page
+
+ * Backport support for software count cache flush Spectre v2 mitigation. (CVE)
+ (required for POWER9 DD2.3) (LP: #1822870) // Backport support for software
+ count cache flush Spectre v2 mitigation. (CVE) (required for POWER9 DD2.3)
+ (LP: #1822870)
+ - powerpc64s: Show ori31 availability in spectre_v1 sysfs file not v2
+ - powerpc/fsl: Fix spectre_v2 mitigations reporting
+ - powerpc: Avoid code patching freed init sections
+
+ * Backport support for software count cache flush Spectre v2 mitigation. (CVE)
+ (required for POWER9 DD2.3) (LP: #1822870) // Backport support for software
+ count cache flush Spectre v2 mitigation. (CVE) (required for POWER9 DD2.3)
+ (LP: #1822870) // Backport support for software count cache flush Spectre v2
+ mitigation. (CVE) (required for POWER9 DD2.3) (LP: #1822870)
+ - powerpc/security: Fix spectre_v2 reporting
+
+ * CVE-2019-3874
+ - sctp: use sk_wmem_queued to check for writable space
+ - sctp: implement memory accounting on tx path
+ - sctp: implement memory accounting on rx path
+
+ * NULL pointer dereference when using z3fold and zswap (LP: #1814874)
+ - z3fold: fix possible reclaim races
+
+ * Kprobe event argument syntax in ftrace from ubuntu_kernel_selftests failed
+ on B PowerPC (LP: #1812809)
+ - selftests/ftrace: Add ppc support for kprobe args tests
+
+ * The Realtek card reader does not enter PCIe 1.1/1.2 (LP: #1825487)
+ - misc: rtsx: make various functions static
+ - misc: rtsx: Enable OCP for rts522a rts524a rts525a rts5260
+ - SAUCE: misc: rtsx: Fixed rts5260 power saving parameter and sd glitch
+
+ * headset-mic doesn't work on two Dell laptops. (LP: #1825272)
+ - ALSA: hda/realtek - add two more pin configuration sets to quirk table
+
+ * CVE-2018-16884
+ - sunrpc: use SVC_NET() in svcauth_gss_* functions
+ - sunrpc: use-after-free in svc_process_common()
+
+ * sky2 ethernet card don't work after returning from suspension (LP: #1798921)
+ - sky2: Increase D3 delay again
+
+ * CVE-2019-9500
+ - brcmfmac: assure SSID length from firmware is limited
+
+ * CVE-2019-9503
+ - brcmfmac: add subtype check for event handling in data path
+
+ * CVE-2019-3882
+ - vfio/type1: Limit DMA mappings per container
+
+ * Intel I210 Ethernet card not working after hotplug [8086:1533]
+ (LP: #1818490)
+ - igb: Fix WARN_ONCE on runtime suspend
+
+ * bionic, xenial/hwe: misses "fuse: fix initial parallel dirops" patch
+ (LP: #1823972)
+ - fuse: fix initial parallel dirops
+
+ * amdgpu resume failure: failed to allocate wb slot (LP: #1825074)
+ - drm/amdgpu: fix&cleanups for wb_clear
+
+ * Pop noise when headset is plugged in or removed from GHS/Line-out jack
+ (LP: #1821290)
+ - ALSA: hda/realtek - Add unplug function into unplug state of Headset Mode
+ for ALC225
+ - ALSA: hda/realtek - Disable headset Mic VREF for headset mode of ALC225
+ - ALSA: hda/realtek - Add support headset mode for DELL WYSE AIO
+ - ALSA: hda/realtek - Add support headset mode for New DELL WYSE NB
+
+ * mac80211_hwsim unable to handle kernel NULL pointer dereference
+ at0000000000000000 (LP: #1825058)
+ - mac80211_hwsim: Timer should be initialized before device registered
+
+ * [regression][snd_hda_codec_realtek] repeating crackling noise after 19.04
+ upgrade (LP: #1821663)
+ - ALSA: hda: Add Intel NUC7i3BNB to the power_save blacklist
+ - ALSA: hda - add Lenovo IdeaCentre B550 to the power_save_blacklist
+ - ALSA: hda - Add two more machines to the power_save_blacklist
+
+ * ubuntu_nbd_smoke_test failed on P9 with Bionic kernel (LP: #1822247)
+ - nbd: fix how we set bd_invalidated
+
+ * TSC clocksource not available in nested guests (LP: #1822821)
+ - kvmclock: fix TSC calibration for nested guests
+
+ * 4.15 kernel ip_vs --ops causes performance and hang problem (LP: #1819786)
+ - ipvs: fix refcount usage for conns in ops mode
+
+ * systemd cause kernel trace "BUG: unable to handle kernel paging request at
+ 6db23a14" on Cosmic i386 (LP: #1813244) // systemd cause kernel trace "BUG:
+ unable to handle kernel paging request at 6db23a14" on Cosmic i386
+ (LP: #1813244)
+ - openvswitch: fix flow actions reallocation
+
+ -- Stefan Bader <stefan.bader@canonical.com> Thu, 25 Apr 2019 10:40:22 +0200
+
+linux (4.15.0-48.51) bionic; urgency=medium
+
+ * linux: 4.15.0-48.51 -proposed tracker (LP: #1822820)
+
+ * Packaging resync (LP: #1786013)
+ - [Packaging] update helper scripts
+ - [Packaging] resync retpoline extraction
+
+ * 3b080b2564287be91605bfd1d5ee985696e61d3c in ubuntu_btrfs_kernel_fixes
+ triggers system hang on i386 (LP: #1812845)
+ - btrfs: raid56: properly unmap parity page in finish_parity_scrub()
+
+ * [P9][LTCTest][Opal][FW910] cpupower monitor shows multiple stop Idle_Stats
+ (LP: #1719545)
+ - cpupower : Fix header name to read idle state name
+
+ * [amdgpu] screen corruption when using touchpad (LP: #1818617)
+ - drm/amdgpu/gmc: steal the appropriate amount of vram for fw hand-over (v3)
+ - drm/amdgpu: Free VGA stolen memory as soon as possible.
+
+ * [SRU][B/C/OEM]IOMMU: add kernel dma protection (LP: #1820153)
+ - ACPICA: AML parser: attempt to continue loading table after error
+ - ACPI / property: Allow multiple property compatible _DSD entries
+ - PCI / ACPI: Identify untrusted PCI devices
+ - iommu/vt-d: Force IOMMU on for platform opt in hint
+ - iommu/vt-d: Do not enable ATS for untrusted devices
+ - thunderbolt: Export IOMMU based DMA protection support to userspace
+ - iommu/vt-d: Disable ATS support on untrusted devices
+
+ * Add basic support to NVLink2 passthrough (LP: #1819989)
+ - powerpc/powernv/npu: Do not try invalidating 32bit table when 64bit table is
+ enabled
+ - powerpc/powernv: call OPAL_QUIESCE before OPAL_SIGNAL_SYSTEM_RESET
+ - powerpc/powernv: Export opal_check_token symbol
+ - powerpc/powernv: Make possible for user to force a full ipl cec reboot
+ - powerpc/powernv/idoa: Remove unnecessary pcidev from pci_dn
+ - powerpc/powernv: Move npu struct from pnv_phb to pci_controller
+ - powerpc/powernv/npu: Move OPAL calls away from context manipulation
+ - powerpc/pseries/iommu: Use memory@ nodes in max RAM address calculation
+ - powerpc/pseries/npu: Enable platform support
+ - powerpc/pseries: Remove IOMMU API support for non-LPAR systems
+ - powerpc/powernv/npu: Check mmio_atsd array bounds when populating
+ - powerpc/powernv/npu: Fault user page into the hypervisor's pagetable
+
+ * Huawei Hi1822 NIC has poor performance (LP: #1820187)
+ - net-next: hinic: fix a problem in free_tx_poll()
+ - hinic: remove ndo_poll_controller
+ - net-next/hinic: add checksum offload and TSO support
+ - hinic: Fix l4_type parameter in hinic_task_set_tunnel_l4
+ - net-next/hinic:replace multiply and division operators
+ - net-next/hinic:add rx checksum offload for HiNIC
+ - net-next/hinic:fix a bug in set mac address
+ - net-next/hinic: fix a bug in rx data flow
+ - net: hinic: fix null pointer dereference on pointer hwdev
+ - hinic: optmize rx refill buffer mechanism
+ - net-next/hinic:add shutdown callback
+ - net-next/hinic: replace disable_irq_nosync/enable_irq
+
+ * [CONFIG] please enable highdpi font FONT_TER16x32 (LP: #1819881)
+ - Fonts: New Terminus large console font
+ - [Config]: enable highdpi Terminus 16x32 font support
+
+ * [19.04 FEAT] qeth: Enhanced link speed - kernel part (LP: #1814892)
+ - s390/qeth: report 25Gbit link speed
+
+ * CVE-2017-5754
+ - x86/nmi: Fix NMI uaccess race against CR3 switching
+ - x86/mm: Fix documentation of module mapping range with 4-level paging
+ - x86/pti: Enable global pages for shared areas
+ - x86/pti: Never implicitly clear _PAGE_GLOBAL for kernel image
+ - x86/pti: Leave kernel text global for !PCID
+ - x86/pti: Fix boot problems from Global-bit setting
+ - x86/pti: Fix boot warning from Global-bit setting
+ - x86/pti: Reduce amount of kernel text allowed to be Global
+ - x86/pti: Disallow global kernel text with RANDSTRUCT
+ - x86/entry/32: Add explicit 'l' instruction suffix
+ - x86/asm-offsets: Move TSS_sp0 and TSS_sp1 to asm-offsets.c
+ - x86/entry/32: Rename TSS_sysenter_sp0 to TSS_entry2task_stack
+ - x86/entry/32: Load task stack from x86_tss.sp1 in SYSENTER handler
+ - x86/entry/32: Put ESPFIX code into a macro
+ - x86/entry/32: Unshare NMI return path
+ - x86/entry/32: Split off return-to-kernel path
+ - x86/entry/32: Enter the kernel via trampoline stack
+ - x86/entry/32: Leave the kernel via trampoline stack
+ - x86/entry/32: Introduce SAVE_ALL_NMI and RESTORE_ALL_NMI
+ - x86/entry/32: Handle Entry from Kernel-Mode on Entry-Stack
+ - x86/entry/32: Simplify debug entry point
+ - x86/entry/32: Add PTI cr3 switch to non-NMI entry/exit points
+ - x86/entry/32: Add PTI CR3 switches to NMI handler code
+ - x86/entry: Rename update_sp0 to update_task_stack
+ - x86/pgtable: Rename pti_set_user_pgd() to pti_set_user_pgtbl()
+ - x86/pgtable/pae: Unshare kernel PMDs when PTI is enabled
+ - x86/pgtable/32: Allocate 8k page-tables when PTI is enabled
+ - x86/pgtable: Move pgdp kernel/user conversion functions to pgtable.h
+ - x86/pgtable: Move pti_set_user_pgtbl() to pgtable.h
+ - x86/pgtable: Move two more functions from pgtable_64.h to pgtable.h
+ - x86/mm/pae: Populate valid user PGD entries
+ - x86/mm/pae: Populate the user page-table with user pgd's
+ - x86/mm/pti: Add an overflow check to pti_clone_pmds()
+ - x86/mm/pti: Define X86_CR3_PTI_PCID_USER_BIT on x86_32
+ - x86/mm/pti: Clone CPU_ENTRY_AREA on PMD level on x86_32
+ - x86/mm/pti: Make pti_clone_kernel_text() compile on 32 bit
+ - x86/mm/pti: Keep permissions when cloning kernel text in
+ pti_clone_kernel_text()
+ - x86/mm/pti: Introduce pti_finalize()
+ - x86/mm/pti: Clone entry-text again in pti_finalize()
+ - x86/mm/dump_pagetables: Define INIT_PGD
+ - x86/pgtable/pae: Use separate kernel PMDs for user page-table
+ - x86/ldt: Reserve address-space range on 32 bit for the LDT
+ - x86/ldt: Define LDT_END_ADDR
+ - x86/ldt: Split out sanity check in map_ldt_struct()
+ - x86/ldt: Enable LDT user-mapping for PAE
+ - x86/pti: Allow CONFIG_PAGE_TABLE_ISOLATION for x86_32
+ - [Config] Update PAGE_TABLE_ISOLATION annotations
+ - x86/mm/pti: Add Warning when booting on a PCID capable CPU
+ - x86/entry/32: Add debug code to check entry/exit CR3
+ - x86/pti: Check the return value of pti_user_pagetable_walk_p4d()
+ - x86/pti: Check the return value of pti_user_pagetable_walk_pmd()
+ - perf/core: Make sure the ring-buffer is mapped in all page-tables
+ - x86/entry/32: Check for VM86 mode in slow-path check
+ - x86/mm: Remove in_nmi() warning from vmalloc_fault()
+ - x86/kexec: Allocate 8k PGDs for PTI
+ - x86/mm/pti: Clear Global bit more aggressively
+ - mm: Allow non-direct-map arguments to free_reserved_area()
+ - x86/mm/init: Pass unconverted symbol addresses to free_init_pages()
+ - x86/mm/init: Add helper for freeing kernel image pages
+ - x86/mm/init: Remove freed kernel image areas from alias mapping
+ - x86/mm/pti: Fix 32 bit PCID check
+ - x86/mm/pti: Don't clear permissions in pti_clone_pmd()
+ - x86/mm/pti: Clone kernel-image on PTE level for 32 bit
+ - x86/relocs: Add __end_rodata_aligned to S_REL
+ - x86/mm/pti: Move user W+X check into pti_finalize()
+ - x86/efi: Load fixmap GDT in efi_call_phys_epilog()
+ - x86/efi: Load fixmap GDT in efi_call_phys_epilog() before setting %cr3
+ - x86/mm/doc: Clean up the x86-64 virtual memory layout descriptions
+ - x86/mm/doc: Enhance the x86-64 virtual memory layout descriptions
+ - x86/entry/32: Clear the CS high bits
+ - x86/mm: Move LDT remap out of KASLR region on 5-level paging
+ - x86/ldt: Unmap PTEs for the slot before freeing LDT pages
+ - x86/ldt: Remove unused variable in map_ldt_struct()
+ - x86/mm: Fix guard hole handling
+ - x86/dump_pagetables: Fix LDT remap address marker
+
+ * Avoid potential memory corruption on HiSilicon SoCs (LP: #1819546)
+ - iommu/arm-smmu-v3: Avoid memory corruption from Hisilicon MSI payloads
+
+ * Ubuntu18.04.01: [Power9] power8 Compat guest(RHEL7.6) crashes during guest
+ boot with > 256G of memory (kernel/kvm) (LP: #1818645)
+ - ]PATCH] KVM: PPC: Book3S HV: Don't truncate HPTE index in xlate function
+
+ * Fix for dual Intel NVMes (LP: #1821961)
+ - SAUCE: nvme: Merge two quirk entries into one for Intel 760p/Pro 7600p
+
+ * CVE-2017-5715
+ - tools headers: Synchronize prctl.h ABI header
+ - x86/spectre: Add missing family 6 check to microcode check
+ - x86/speculation: Enable cross-hyperthread spectre v2 STIBP mitigation
+ - x86/speculation: Apply IBPB more strictly to avoid cross-process data leak
+ - x86/speculation: Propagate information about RSB filling mitigation to sysfs
+ - x86/speculation: Add RETPOLINE_AMD support to the inline asm CALL_NOSPEC
+ variant
+ - x86/retpoline: Make CONFIG_RETPOLINE depend on compiler support
+ - x86/retpoline: Remove minimal retpoline support
+ - x86/speculation: Update the TIF_SSBD comment
+ - x86/speculation: Clean up spectre_v2_parse_cmdline()
+ - x86/speculation: Remove unnecessary ret variable in cpu_show_common()
+ - x86/speculation: Move STIPB/IBPB string conditionals out of
+ cpu_show_common()
+ - x86/speculation: Disable STIBP when enhanced IBRS is in use
+ - x86/speculation: Rename SSBD update functions
+ - x86/speculation: Reorganize speculation control MSRs update
+ - sched/smt: Make sched_smt_present track topology
+ - x86/Kconfig: Select SCHED_SMT if SMP enabled
+ - sched/smt: Expose sched_smt_present static key
+ - x86/speculation: Rework SMT state change
+ - x86/l1tf: Show actual SMT state
+ - x86/speculation: Reorder the spec_v2 code
+ - x86/speculation: Mark string arrays const correctly
+ - x86/speculataion: Mark command line parser data __initdata
+ - x86/speculation: Unify conditional spectre v2 print functions
+ - x86/speculation: Add command line control for indirect branch speculation
+ - x86/speculation: Prepare for per task indirect branch speculation control
+ - x86/process: Consolidate and simplify switch_to_xtra() code
+ - x86/speculation: Avoid __switch_to_xtra() calls
+ - x86/speculation: Prepare for conditional IBPB in switch_mm()
+ - ptrace: Remove unused ptrace_may_access_sched() and MODE_IBRS
+ - x86/speculation: Split out TIF update
+ - x86/speculation: Prevent stale SPEC_CTRL msr content
+ - x86/speculation: Prepare arch_smt_update() for PRCTL mode
+ - x86/speculation: Add prctl() control for indirect branch speculation
+ - x86/speculation: Enable prctl mode for spectre_v2_user
+ - x86/speculation: Add seccomp Spectre v2 user space protection mode
+ - x86/speculation: Provide IBPB always command line options
+ - kvm: svm: Ensure an IBPB on all affected CPUs when freeing a vmcb
+ - x86/speculation: Change misspelled STIPB to STIBP
+ - x86/speculation: Add support for STIBP always-on preferred mode
+ - x86, modpost: Replace last remnants of RETPOLINE with CONFIG_RETPOLINE
+ - s390: remove closung punctuation from spectre messages
+ - x86/speculation: Simplify the CPU bug detection logic
+
+ * CVE-2018-3639
+ - x86/bugs: Add AMD's variant of SSB_NO
+ - x86/bugs: Add AMD's SPEC_CTRL MSR usage
+ - x86/bugs: Switch the selection of mitigation from CPU vendor to CPU features
+ - x86/bugs: Update when to check for the LS_CFG SSBD mitigation
+ - x86/bugs: Fix the AMD SSBD usage of the SPEC_CTRL MSR
+ - KVM: x86: SVM: Call x86_spec_ctrl_set_guest/host() with interrupts disabled
+
+ * [Ubuntu] vfio-ap: add subsystem to matrix device to avoid libudev failures
+ (LP: #1818854)
+ - s390: vfio_ap: link the vfio_ap devices to the vfio_ap bus subsystem
+
+ * Kernel regularly logs: Bluetooth: hci0: last event is not cmd complete
+ (0x0f) (LP: #1748565)
+ - Bluetooth: Fix unnecessary error message for HCI request completion
+
+ * HiSilicon HNS ethernet broken in 4.15.0-45 (LP: #1818294)
+ - net: hns: Fix WARNING when hns modules installed
+
+ * rtl8723be wifi does not work under linux-modules-extra-4.15.0-33-generic
+ (LP: #1788997)
+ - SAUCE: Revert "rtlwifi: cleanup 8723be ant_sel definition"
+
+ * Crash from :i915 module with 4.15.0-46-generic using multi-display
+ (LP: #1819486)
+ - SAUCE: Revert "drm/i915: Fix hotplug irq ack on i965/g4x"
+
+ * kernel linux-image-4.15.0-44 not booting on Hyperv Server 2008R2
+ (LP: #1814069)
+ - hv/netvsc: fix handling of fallback to single queue mode
+ - hv/netvsc: Fix NULL dereference at single queue mode fallback
+
+ * Lenovo ideapad 330-15ICH Wifi rfkill hard blocked (LP: #1811815)
+ - platform/x86: ideapad: Add ideapad 330-15ICH to no_hw_rfkill
+
+ * Qualcomm Atheros QCA9377 wireless does not work (LP: #1818204)
+ - platform/x86: ideapad-laptop: Add Ideapad 530S-14ARR to no_hw_rfkill list
+
+ * fscache: jobs might hang when fscache disk is full (LP: #1821395)
+ - fscache: fix race between enablement and dropping of object
+
+ * hns3: fix oops in hns3_clean_rx_ring() (LP: #1821064)
+ - net: hns3: add dma_rmb() for rx description
+
+ * Hard lockup in 2 CPUs due to deadlock in cpu_stoppers (LP: #1821259)
+ - stop_machine: Disable preemption after queueing stopper threads
+ - stop_machine: Atomically queue and wake stopper threads
+
+ * tcm_loop.ko: move from modules-extra into main modules package
+ (LP: #1817786)
+ - [Packaging] move tcm_loop.lo to main linux-modules package
+
+ * tcmu user space crash results in kernel module hang. (LP: #1819504)
+ - scsi: tcmu: delete unused __wait
+ - scsi: tcmu: track nl commands
+ - scsi: tcmu: simplify nl interface
+ - scsi: tcmu: add module wide block/reset_netlink support
+
+ * Intel XL710 - i40e driver does not work with kernel 4.15 (Ubuntu 18.04)
+ (LP: #1779756)
+ - i40e: Fix for Tx timeouts when interface is brought up if DCB is enabled
+ - i40e: prevent overlapping tx_timeout recover
+
+ * some codecs stop working after S3 (LP: #1820930)
+ - ALSA: hda - Enforces runtime_resume after S3 and S4 for each codec
+
+ * i40e xps management broken when > 64 queues/cpus (LP: #1820948)
+ - i40e: Do not allow use more TC queue pairs than MSI-X vectors exist
+ - i40e: Fix the number of queues available to be mapped for use
+
+ * 4.15 s390x kernel BUG at /build/linux-
+ Gycr4Z/linux-4.15.0/drivers/block/virtio_blk.c:565! (LP: #1788432)
+ - virtio/s390: avoid race on vcdev->config
+ - virtio/s390: fix race in ccw_io_helper()
+
+ * [SRU][B/B-OEM/C/D] Fix AMD IOMMU NULL dereference (LP: #1820990)
+ - iommu/amd: Fix NULL dereference bug in match_hid_uid
+
+ * New Intel Wireless-AC 9260 [8086:2526] card not correctly probed in Ubuntu
+ system (LP: #1821271)
+ - iwlwifi: add new card for 9260 series
+
+ * Add support for MAC address pass through on RTL8153-BD (LP: #1821276)
+ - r8152: Add support for MAC address pass through on RTL8153-BD
+ - r8152: Fix an error on RTL8153-BD MAC Address Passthrough support
+
+ -- Andrea Righi <andrea.righi@canonical.com> Tue, 02 Apr 2019 18:31:55 +0200
+
+linux (4.15.0-47.50) bionic; urgency=medium
+
+ * linux: 4.15.0-47.50 -proposed tracker (LP: #1819716)
+
+ * Packaging resync (LP: #1786013)
+ - [Packaging] resync getabis
+ - [Packaging] update helper scripts
+ - [Packaging] resync retpoline extraction
+
+ * C++ demangling support missing from perf (LP: #1396654)
+ - [Packaging] fix a mistype
+
+ * arm-smmu-v3 arm-smmu-v3.3.auto: CMD_SYNC timeout (LP: #1818162)
+ - iommu/arm-smmu-v3: Fix unexpected CMD_SYNC timeout
+
+ * Crash in nvme_irq_check() when using threaded interrupts (LP: #1818747)
+ - nvme-pci: fix out of bounds access in nvme_cqe_pending
+
+ * CVE-2019-9213
+ - mm: enforce min addr even if capable() in expand_downwards()
+
+ * CVE-2019-3460
+ - Bluetooth: Check L2CAP option sizes returned from l2cap_get_conf_opt
+
+ * amdgpu with mst WARNING on blanking (LP: #1814308)
+ - drm/amd/display: Don't use dc_link in link_encoder
+ - drm/amd/display: Move wait for hpd ready out from edp power control.
+ - drm/amd/display: eDP sequence BL off first then DP blank.
+ - drm/amd/display: Fix unused variable compilation error
+ - drm/amd/display: Fix warning about misaligned code
+ - drm/amd/display: Fix MST dp_blank REG_WAIT timeout
+
+ * tun/tap: unable to manage carrier state from userland (LP: #1806392)
+ - tun: implement carrier change
+
+ * CVE-2019-8980
+ - exec: Fix mem leak in kernel_read_file
+
+ * raw_skew in timer from the ubuntu_kernel_selftests failed on Bionic
+ (LP: #1811194)
+ - selftest: timers: Tweak raw_skew to SKIP when ADJ_OFFSET/other clock
+ adjustments are in progress
+
+ * [Packaging] Allow overlay of config annotations (LP: #1752072)
+ - [Packaging] config-check: Add an include directive
+
+ * CVE-2019-7308
+ - bpf: move {prev_,}insn_idx into verifier env
+ - bpf: move tmp variable into ax register in interpreter
+ - bpf: enable access to ax register also from verifier rewrite
+ - bpf: restrict map value pointer arithmetic for unprivileged
+ - bpf: restrict stack pointer arithmetic for unprivileged
+ - bpf: restrict unknown scalars of mixed signed bounds for unprivileged
+ - bpf: fix check_map_access smin_value test when pointer contains offset
+ - bpf: prevent out of bounds speculation on pointer arithmetic
+ - bpf: fix sanitation of alu op with pointer / scalar type from different
+ paths
+ - bpf: add various test cases to selftests
+
+ * CVE-2017-5753
+ - bpf: properly enforce index mask to prevent out-of-bounds speculation
+ - bpf: fix inner map masking to prevent oob under speculation
+
+ * BPF: kernel pointer leak to unprivileged userspace (LP: #1815259)
+ - bpf/verifier: disallow pointer subtraction
+
+ * squashfs hardening (LP: #1816756)
+ - squashfs: more metadata hardening
+ - squashfs metadata 2: electric boogaloo
+ - squashfs: more metadata hardening
+ - Squashfs: Compute expected length from inode size rather than block length
+
+ * efi/arm/arm64: Allow SetVirtualAddressMap() to be omitted (LP: #1814982)
+ - efi/arm/arm64: Allow SetVirtualAddressMap() to be omitted
+
+ * Update ENA driver to version 2.0.3K (LP: #1816806)
+ - net: ena: update driver version from 2.0.2 to 2.0.3
+ - net: ena: fix race between link up and device initalization
+ - net: ena: fix crash during failed resume from hibernation
+
+ * ipset kernel error: 4.15.0-43-generic (LP: #1811394)
+ - netfilter: ipset: Fix wraparound in hash:*net* types
+
+ * Silent "Unknown key" message when pressing keyboard backlight hotkey
+ (LP: #1817063)
+ - platform/x86: dell-wmi: Ignore new keyboard backlight change event
+
+ * CVE-2018-18021
+ - arm64: KVM: Tighten guest core register access from userspace
+ - KVM: arm/arm64: Introduce vcpu_el1_is_32bit
+ - arm64: KVM: Sanitize PSTATE.M when being set from userspace
+
+ * CVE-2018-14678
+ - x86/entry/64: Remove %ebx handling from error_entry/exit
+
+ * CVE-2018-19824
+ - ALSA: usb-audio: Fix UAF decrement if card has no live interfaces in card.c
+
+ * CVE-2019-3459
+ - Bluetooth: Verify that l2cap_get_conf_opt provides large enough buffer
+
+ * Bionic update: upstream stable patchset 2019-02-08 (LP: #1815234)
+ - fork: unconditionally clear stack on fork
+ - spi: spi-s3c64xx: Fix system resume support
+ - Input: elan_i2c - add ACPI ID for lenovo ideapad 330
+ - Input: i8042 - add Lenovo LaVie Z to the i8042 reset list
+ - Input: elan_i2c - add another ACPI ID for Lenovo Ideapad 330-15AST
+ - kvm, mm: account shadow page tables to kmemcg
+ - delayacct: fix crash in delayacct_blkio_end() after delayacct init failure
+ - tracing: Fix double free of event_trigger_data
+ - tracing: Fix possible double free in event_enable_trigger_func()
+ - kthread, tracing: Don't expose half-written comm when creating kthreads
+ - tracing/kprobes: Fix trace_probe flags on enable_trace_kprobe() failure
+ - tracing: Quiet gcc warning about maybe unused link variable
+ - arm64: fix vmemmap BUILD_BUG_ON() triggering on !vmemmap setups
+ - mlxsw: spectrum_switchdev: Fix port_vlan refcounting
+ - kcov: ensure irq code sees a valid area
+ - xen/netfront: raise max number of slots in xennet_get_responses()
+ - skip LAYOUTRETURN if layout is invalid
+ - ALSA: emu10k1: add error handling for snd_ctl_add
+ - ALSA: fm801: add error handling for snd_ctl_add
+ - NFSv4.1: Fix the client behaviour on NFS4ERR_SEQ_FALSE_RETRY
+ - nfsd: fix potential use-after-free in nfsd4_decode_getdeviceinfo
+ - vfio: platform: Fix reset module leak in error path
+ - vfio/mdev: Check globally for duplicate devices
+ - vfio/type1: Fix task tracking for QEMU vCPU hotplug
+ - kernel/hung_task.c: show all hung tasks before panic
+ - mm: /proc/pid/pagemap: hide swap entries from unprivileged users
+ - mm: vmalloc: avoid racy handling of debugobjects in vunmap
+ - mm/slub.c: add __printf verification to slab_err()
+ - rtc: ensure rtc_set_alarm fails when alarms are not supported
+ - perf tools: Fix pmu events parsing rule
+ - netfilter: ipset: forbid family for hash:mac sets
+ - netfilter: ipset: List timing out entries with "timeout 1" instead of zero
+ - irqchip/ls-scfg-msi: Map MSIs in the iommu
+ - watchdog: da9063: Fix updating timeout value
+ - printk: drop in_nmi check from printk_safe_flush_on_panic()
+ - bpf, arm32: fix inconsistent naming about emit_a32_lsr_{r64,i64}
+ - ceph: fix alignment of rasize
+ - e1000e: Ignore TSYNCRXCTL when getting I219 clock attributes
+ - powerpc/lib: Adjust .balign inside string functions for PPC32
+ - powerpc/64s: Add barrier_nospec
+ - powerpc/eeh: Fix use-after-release of EEH driver
+ - hvc_opal: don't set tb_ticks_per_usec in udbg_init_opal_common()
+ - powerpc/64s: Fix compiler store ordering to SLB shadow area
+ - RDMA/mad: Convert BUG_ONs to error flows
+ - lightnvm: pblk: warn in case of corrupted write buffer
+ - netfilter: nf_tables: check msg_type before nft_trans_set(trans)
+ - pnfs: Don't release the sequence slot until we've processed layoutget on
+ open
+ - disable loading f2fs module on PAGE_SIZE > 4KB
+ - f2fs: fix error path of move_data_page
+ - f2fs: fix to don't trigger writeback during recovery
+ - f2fs: fix to wait page writeback during revoking atomic write
+ - f2fs: Fix deadlock in shutdown ioctl
+ - f2fs: fix to detect failure of dquot_initialize
+ - f2fs: fix race in between GC and atomic open
+ - block, bfq: remove wrong lock in bfq_requests_merged
+ - usbip: usbip_detach: Fix memory, udev context and udev leak
+ - usbip: dynamically allocate idev by nports found in sysfs
+ - perf/x86/intel/uncore: Correct fixed counter index check in generic code
+ - perf/x86/intel/uncore: Correct fixed counter index check for NHM
+ - selftests/intel_pstate: Improve test, minor fixes
+ - selftests: memfd: return Kselftest Skip code for skipped tests
+ - selftests: intel_pstate: return Kselftest Skip code for skipped tests
+ - PCI: Fix devm_pci_alloc_host_bridge() memory leak
+ - iwlwifi: pcie: fix race in Rx buffer allocator
+ - Bluetooth: hci_qca: Fix "Sleep inside atomic section" warning
+ - Bluetooth: btusb: Add a new Realtek 8723DE ID 2ff8:b011
+ - ASoC: dpcm: fix BE dai not hw_free and shutdown
+ - mfd: cros_ec: Fail early if we cannot identify the EC
+ - mwifiex: handle race during mwifiex_usb_disconnect
+ - wlcore: sdio: check for valid platform device data before suspend
+ - media: tw686x: Fix incorrect vb2_mem_ops GFP flags
+ - media: videobuf2-core: don't call memop 'finish' when queueing
+ - Btrfs: don't return ino to ino cache if inode item removal fails
+ - Btrfs: don't BUG_ON() in btrfs_truncate_inode_items()
+ - btrfs: add barriers to btrfs_sync_log before log_commit_wait wakeups
+ - btrfs: qgroup: Finish rescan when hit the last leaf of extent tree
+ - x86/microcode: Make the late update update_lock a raw lock for RT
+ - PM / wakeup: Make s2idle_lock a RAW_SPINLOCK
+ - PCI: Prevent sysfs disable of device while driver is attached
+ - nvme-rdma: stop admin queue before freeing it
+ - nvme-pci: Fix AER reset handling
+ - ath: Add regulatory mapping for FCC3_ETSIC
+ - ath: Add regulatory mapping for ETSI8_WORLD
+ - ath: Add regulatory mapping for APL13_WORLD
+ - ath: Add regulatory mapping for APL2_FCCA
+ - ath: Add regulatory mapping for Uganda
+ - ath: Add regulatory mapping for Tanzania
+ - ath: Add regulatory mapping for Serbia
+ - ath: Add regulatory mapping for Bermuda
+ - ath: Add regulatory mapping for Bahamas
+ - powerpc/32: Add a missing include header
+ - powerpc/chrp/time: Make some functions static, add missing header include
+ - powerpc/powermac: Add missing prototype for note_bootable_part()
+ - powerpc/powermac: Mark variable x as unused
+ - powerpc: Add __printf verification to prom_printf
+ - spi: sh-msiof: Fix setting SIRMDR1.SYNCAC to match SITMDR1.SYNCAC
+ - powerpc/8xx: fix invalid register expression in head_8xx.S
+ - pinctrl: at91-pio4: add missing of_node_put
+ - bpf: powerpc64: pad function address loads with NOPs
+ - PCI: pciehp: Request control of native hotplug only if supported
+ - net: dsa: qca8k: Add support for QCA8334 switch
+ - mwifiex: correct histogram data with appropriate index
+ - ima: based on policy verify firmware signatures (pre-allocated buffer)
+ - drivers/perf: arm-ccn: don't log to dmesg in event_init
+ - spi: Add missing pm_runtime_put_noidle() after failed get
+ - fscrypt: use unbound workqueue for decryption
+ - scsi: ufs: ufshcd: fix possible unclocked register access
+ - scsi: ufs: fix exception event handling
+ - scsi: zfcp: assert that the ERP lock is held when tracing a recovery trigger
+ - drm/nouveau/fifo/gk104-: poll for runlist update completion
+ - Bluetooth: btusb: add ID for LiteOn 04ca:301a
+ - rtc: tps6586x: fix possible race condition
+ - rtc: vr41xx: fix possible race condition
+ - rtc: tps65910: fix possible race condition
+ - ALSA: emu10k1: Rate-limit error messages about page errors
+ - regulator: pfuze100: add .is_enable() for pfuze100_swb_regulator_ops
+ - md/raid1: add error handling of read error from FailFast device
+ - md: fix NULL dereference of mddev->pers in remove_and_add_spares()
+ - ixgbevf: fix MAC address changes through ixgbevf_set_mac()
+ - media: smiapp: fix timeout checking in smiapp_read_nvm
+ - net: ethernet: ti: cpsw-phy-sel: check bus_find_device() ret value
+ - ALSA: usb-audio: Apply rate limit to warning messages in URB complete
+ callback
+ - media: atomisp: ov2680: don't declare unused vars
+ - arm64: cmpwait: Clear event register before arming exclusive monitor
+ - HID: hid-plantronics: Re-resend Update to map button for PTT products
+ - arm64: dts: renesas: salvator-common: use audio-graph-card for Sound
+ - drm/radeon: fix mode_valid's return type
+ - drm/amdgpu: Remove VRAM from shared bo domains.
+ - powerpc/embedded6xx/hlwd-pic: Prevent interrupts from being handled by
+ Starlet
+ - HID: i2c-hid: check if device is there before really probing
+ - EDAC, altera: Fix ARM64 build warning
+ - ARM: dts: stih407-pinctrl: Fix complain about IRQ_TYPE_NONE usage
+ - ARM: dts: emev2: Add missing interrupt-affinity to PMU node
+ - ARM: dts: sh73a0: Add missing interrupt-affinity to PMU node
+ - nvmem: properly handle returned value nvmem_reg_read
+ - i40e: free the skb after clearing the bitlock
+ - tty: Fix data race in tty_insert_flip_string_fixed_flag
+ - dma-iommu: Fix compilation when !CONFIG_IOMMU_DMA
+ - net: phy: phylink: Release link GPIO
+ - media: rcar_jpu: Add missing clk_disable_unprepare() on error in jpu_open()
+ - libata: Fix command retry decision
+ - ACPI / LPSS: Only call pwm_add_table() for Bay Trail PWM if PMIC HRV is 2
+ - media: media-device: fix ioctl function types
+ - media: saa7164: Fix driver name in debug output
+ - mtd: rawnand: fsl_ifc: fix FSL NAND driver to read all ONFI parameter pages
+ - brcmfmac: Add support for bcm43364 wireless chipset
+ - s390/cpum_sf: Add data entry sizes to sampling trailer entry
+ - perf: fix invalid bit in diagnostic entry
+ - bnxt_en: Check unsupported speeds in bnxt_update_link() on PF only.
+ - scsi: 3w-9xxx: fix a missing-check bug
+ - scsi: 3w-xxxx: fix a missing-check bug
+ - scsi: megaraid: silence a static checker bug
+ - scsi: qedf: Set the UNLOADING flag when removing a vport
+ - staging: lustre: o2iblnd: fix race at kiblnd_connect_peer
+ - staging: lustre: o2iblnd: Fix FastReg map/unmap for MLX5
+ - thermal: exynos: fix setting rising_threshold for Exynos5433
+ - bpf: fix references to free_bpf_prog_info() in comments
+ - f2fs: avoid fsync() failure caused by EAGAIN in writepage()
+ - media: siano: get rid of __le32/__le16 cast warnings
+ - drm/atomic: Handling the case when setting old crtc for plane
+ - ALSA: hda/ca0132: fix build failure when a local macro is defined
+ - mmc: dw_mmc: update actual clock for mmc debugfs
+ - mmc: pwrseq: Use kmalloc_array instead of stack VLA
+ - dt-bindings: pinctrl: meson: add support for the Meson8m2 SoC
+ - spi: meson-spicc: Fix error handling in meson_spicc_probe()
+ - dt-bindings: net: meson-dwmac: new compatible name for AXG SoC
+ - backlight: pwm_bl: Don't use GPIOF_* with gpiod_get_direction
+ - stop_machine: Use raw spinlocks
+ - delayacct: Use raw_spinlocks
+ - memory: tegra: Do not handle spurious interrupts
+ - memory: tegra: Apply interrupts mask per SoC
+ - nvme: lightnvm: add granby support
+ - arm64: defconfig: Enable Rockchip io-domain driver
+ - igb: Fix queue selection on MAC filters on i210
+ - drm/gma500: fix psb_intel_lvds_mode_valid()'s return type
+ - ipconfig: Correctly initialise ic_nameservers
+ - rsi: Fix 'invalid vdd' warning in mmc
+ - rsi: fix nommu_map_sg overflow kernel panic
+ - audit: allow not equal op for audit by executable
+ - staging: vchiq_core: Fix missing semaphore release in error case
+ - staging: lustre: llite: correct removexattr detection
+ - staging: lustre: ldlm: free resource when ldlm_lock_create() fails.
+ - serial: core: Make sure compiler barfs for 16-byte earlycon names
+ - soc: imx: gpcv2: Do not pass static memory as platform data
+ - microblaze: Fix simpleImage format generation
+ - usb: hub: Don't wait for connect state at resume for powered-off ports
+ - crypto: authencesn - don't leak pointers to authenc keys
+ - crypto: authenc - don't leak pointers to authenc keys
+ - media: omap3isp: fix unbalanced dma_iommu_mapping
+ - regulator: Don't return or expect -errno from of_map_mode()
+ - scsi: scsi_dh: replace too broad "TP9" string with the exact models
+ - scsi: megaraid_sas: Increase timeout by 1 sec for non-RAID fastpath IOs
+ - media: atomisp: compat32: fix __user annotations
+ - media: si470x: fix __be16 annotations
+ - ASoC: topology: Fix bclk and fsync inversion in set_link_hw_format()
+ - ASoC: topology: Add missing clock gating parameter when parsing hw_configs
+ - drm: Add DP PSR2 sink enable bit
+ - drm/atomic-helper: Drop plane->fb references only for
+ drm_atomic_helper_shutdown()
+ - drm/dp/mst: Fix off-by-one typo when dump payload table
+ - block: reset bi_iter.bi_done after splitting bio
+ - random: mix rdrand with entropy sent in from userspace
+ - squashfs: be more careful about metadata corruption
+ - ext4: fix inline data updates with checksums enabled
+ - ext4: fix check to prevent initializing reserved inodes
+ - PCI: xgene: Remove leftover pci_scan_child_bus() call
+ - RDMA/uverbs: Protect from attempts to create flows on unsupported QP
+ - net: dsa: qca8k: Force CPU port to its highest bandwidth
+ - net: dsa: qca8k: Enable RXMAC when bringing up a port
+ - net: dsa: qca8k: Add QCA8334 binding documentation
+ - net: dsa: qca8k: Allow overwriting CPU port setting
+ - ipv4: remove BUG_ON() from fib_compute_spec_dst
+ - net: fix amd-xgbe flow-control issue
+ - net: lan78xx: fix rx handling before first packet is send
+ - net: mdio-mux: bcm-iproc: fix wrong getter and setter pair
+ - NET: stmmac: align DMA stuff to largest cache line length
+ - tcp_bbr: fix bw probing to raise in-flight data for very small BDPs
+ - xen-netfront: wait xenbus state change when load module manually
+ - netlink: Do not subscribe to non-existent groups
+ - netlink: Don't shift with UB on nlk->ngroups
+ - tcp: do not force quickack when receiving out-of-order packets
+ - tcp: add max_quickacks param to tcp_incr_quickack and
+ tcp_enter_quickack_mode
+ - tcp: do not aggressively quick ack after ECN events
+ - tcp: refactor tcp_ecn_check_ce to remove sk type cast
+ - tcp: add one more quick ack after after ECN events
+ - mm: disallow mappings that conflict for devm_memremap_pages()
+ - drm/i915/glk: Add Quirk for GLK NUC HDMI port issues.
+ - mm: check for SIGKILL inside dup_mmap() loop
+ - rxrpc: Fix terminal retransmission connection ID to include the channel
+ - ceph: fix use-after-free in ceph_statfs()
+ - lightnvm: proper error handling for pblk_bio_add_pages
+ - f2fs: don't drop dentry pages after fs shutdown
+ - selftests: filesystems: return Kselftest Skip code for skipped tests
+ - selftests/filesystems: devpts_pts included wrong header
+ - iwlwifi: mvm: open BA session only when sta is authorized
+ - drm/amd/display: Do not program interrupt status on disabled crtc
+ - soc: qcom: smem: fix qcom_smem_set_global_partition()
+ - soc: qcom: smem: byte swap values properly
+ - pinctrl: msm: fix gpio-hog related boot issues
+ - net: mvpp2: Add missing VLAN tag detection
+ - drm/nouveau: remove fence wait code from deferred client work handler
+ - drm/nouveau/gem: lookup VMAs for buffers referenced by pushbuf ioctl
+ - clocksource: Move inline keyword to the beginning of function declarations
+ - media: staging: atomisp: Comment out several unused sensor resolutions
+ - IB: Fix RDMA_RXE and INFINIBAND_RDMAVT dependencies for DMA_VIRT_OPS
+ - rsi: Add null check for virtual interfaces in wowlan config
+ - ARM: dts: stih410: Fix complain about IRQ_TYPE_NONE usage
+ - ARM: dts: imx53: Fix LDB OF graph warning
+ - soc/tegra: pmc: Don't allocate struct tegra_powergate on stack
+ - mlxsw: spectrum_router: Return an error for non-default FIB rules
+ - i40e: Add advertising 10G LR mode
+ - i40e: avoid overflow in i40e_ptp_adjfreq()
+ - ath10k: fix kernel panic while reading tpc_stats
+ - ASoC: fsl_ssi: Use u32 variable type when using regmap_read()
+ - platform/x86: dell-smbios: Match on www.dell.com in OEM strings too
+ - staging: ks7010: fix error handling in ks7010_upload_firmware
+ - media: rc: mce_kbd decoder: low timeout values cause double keydowns
+ - ath10k: search all IEs for variant before falling back
+ - PCI/ASPM: Disable ASPM L1.2 Substate if we don't have LTR
+ - ARM: dts: imx6qdl-wandboard: Let the codec control MCLK pinctrl
+ - drm/amdgpu: Avoid reclaim while holding locks taken in MMU notifier
+ - nvmet-fc: fix target sgl list on large transfers
+ - i2c: rcar: handle RXDMA HW behaviour on Gen3
+ - gpio: uniphier: set legitimate irq trigger type in .to_irq hook
+ - tcp: ack immediately when a cwr packet arrives
+ - ACPICA: AML Parser: ignore control method status in module-level code
+
+ * Bionic update: upstream stable patchset 2019-02-05 (LP: #1814813)
+ - MIPS: ath79: fix register address in ath79_ddr_wb_flush()
+ - MIPS: Fix off-by-one in pci_resource_to_user()
+ - xen/PVH: Set up GS segment for stack canary
+ - drm/nouveau/drm/nouveau: Fix runtime PM leak in nv50_disp_atomic_commit()
+ - drm/nouveau: Set DRIVER_ATOMIC cap earlier to fix debugfs
+ - bonding: set default miimon value for non-arp modes if not set
+ - ip: hash fragments consistently
+ - ip: in cmsg IP(V6)_ORIGDSTADDR call pskb_may_pull
+ - net/mlx4_core: Save the qpn from the input modifier in RST2INIT wrapper
+ - net: skb_segment() should not return NULL
+ - net/mlx5: Adjust clock overflow work period
+ - net/mlx5e: Don't allow aRFS for encapsulated packets
+ - net/mlx5e: Fix quota counting in aRFS expire flow
+ - net/ipv6: Fix linklocal to global address with VRF
+ - multicast: do not restore deleted record source filter mode to new one
+ - net: phy: consider PHY_IGNORE_INTERRUPT in phy_start_aneg_priv
+ - sock: fix sg page frag coalescing in sk_alloc_sg
+ - rtnetlink: add rtnl_link_state check in rtnl_configure_link
+ - vxlan: add new fdb alloc and create helpers
+ - vxlan: make netlink notify in vxlan_fdb_destroy optional
+ - vxlan: fix default fdb entry netlink notify ordering during netdev create
+ - tcp: fix dctcp delayed ACK schedule
+ - tcp: helpers to send special DCTCP ack
+ - tcp: do not cancel delay-AcK on DCTCP special ACK
+ - tcp: do not delay ACK in DCTCP upon CE status change
+ - staging: speakup: fix wraparound in uaccess length check
+ - usb: cdc_acm: Add quirk for Castles VEGA3000
+ - usb: core: handle hub C_PORT_OVER_CURRENT condition
+ - usb: dwc2: Fix DMA alignment to start at allocated boundary
+ - usb: gadget: f_fs: Only return delayed status when len is 0
+ - driver core: Partially revert "driver core: correct device's shutdown order"
+ - can: xilinx_can: fix RX loop if RXNEMP is asserted without RXOK
+ - can: xilinx_can: fix power management handling
+ - can: xilinx_can: fix recovery from error states not being propagated
+ - can: xilinx_can: fix device dropping off bus on RX overrun
+ - can: xilinx_can: keep only 1-2 frames in TX FIFO to fix TX accounting
+ - can: xilinx_can: fix incorrect clear of non-processed interrupts
+ - can: xilinx_can: fix RX overflow interrupt not being enabled
+ - can: peak_canfd: fix firmware < v3.3.0: limit allocation to 32-bit DMA addr
+ only
+ - can: m_can.c: fix setup of CCCR register: clear CCCR NISO bit before
+ checking can.ctrlmode
+ - turn off -Wattribute-alias
+ - net-next/hinic: fix a problem in hinic_xmit_frame()
+ - net/mlx5e: Refine ets validation function
+ - nfp: flower: ensure dead neighbour entries are not offloaded
+ - usb: gadget: Fix OS descriptors support
+ - ACPICA: AML Parser: ignore dispatcher error status during table load
+
+ * installer does not support iSCSI iBFT (LP: #1817321)
+ - d-i: add iscsi_ibft to scsi-modules
+
+ * CVE-2019-7222
+ - KVM: x86: work around leak of uninitialized stack contents (CVE-2019-7222)
+
+ * CVE-2019-7221
+ - KVM: nVMX: unconditionally cancel preemption timer in free_nested
+ (CVE-2019-7221)
+
+ * CVE-2019-6974
+ - kvm: fix kvm_ioctl_create_device() reference counting (CVE-2019-6974)
+
+ * Regular D-state processes impacting LXD containers (LP: #1817628)
+ - mm: do not stall register_shrinker()
+
+ * hns3 nic speed may not match optical port speed (LP: #1817969)
+ - net: hns3: Config NIC port speed same as that of optical module
+
+ * [Hyper-V] srcu: Lock srcu_data structure in srcu_gp_start() (LP: #1802021)
+ - srcu: Prohibit call_srcu() use under raw spinlocks
+ - srcu: Lock srcu_data structure in srcu_gp_start()
+
+ * libsas disks can have non-unique by-path names (LP: #1817784)
+ - scsi: libsas: Fix rphy phy_identifier for PHYs with end devices attached
+
+ * Bluetooth not working (Intel CyclonePeak) (LP: #1817518)
+ - Bluetooth: btusb: Add support for Intel bluetooth device 8087:0029
+
+ * CVE-2019-8912
+ - net: crypto set sk to NULL when af_alg_release.
+ - net: socket: set sock->sk to NULL after calling proto_ops::release()
+
+ * Trackpad is not recognized. (LP: #1817200)
+ - pinctrl: cannonlake: Fix gpio base for GPP-E
+
+ * [ALSA] [PATCH] System76 darp5 and oryp5 fixups (LP: #1815831)
+ - ALSA: hda/realtek - Headset microphone support for System76 darp5
+ - ALSA: hda/realtek - Headset microphone and internal speaker support for
+ System76 oryp5
+
+ * Constant noise in the headphone on Lenovo X1 machines (LP: #1817263)
+ - ALSA: hda/realtek: Disable PC beep in passthrough on alc285
+
+ * AC adapter status not detected on Asus ZenBook UX410UAK (LP: #1745032)
+ - Revert "ACPI / battery: Add quirk for Asus GL502VSK and UX305LA"
+ - ACPI / AC: Remove initializer for unused ident dmi_system_id
+ - ACPI / battery: Remove initializer for unused ident dmi_system_id
+ - ACPI / battery: Add handling for devices which wrongly report discharging
+ state
+ - ACPI / battery: Ignore AC state in handle_discharging on systems where it is
+ broken
+
+ * TPM intermittently fails after cold-boot (LP: #1762672)
+ - tpm: fix intermittent failure with self tests
+
+ * qlcnic: Firmware aborts/hangs in QLogic NIC (LP: #1815033)
+ - qlcnic: fix Tx descriptor corruption on 82xx devices
+
+ -- Khalid Elmously <khalid.elmously@canonical.com> Wed, 13 Mar 2019 04:37:49 +0000
+
+linux (4.15.0-46.49) bionic; urgency=medium
+
+ * linux: 4.15.0-46.49 -proposed tracker (LP: #1814726)
+
+ * mprotect fails on ext4 with dax (LP: #1799237)
+ - x86/speculation/l1tf: Exempt zeroed PTEs from inversion
+
+ * kernel BUG at /build/linux-vxxS7y/linux-4.15.0/mm/slub.c:296! (LP: #1812086)
+ - iscsi target: fix session creation failure handling
+ - scsi: iscsi: target: Set conn->sess to NULL when iscsi_login_set_conn_values
+ fails
+ - scsi: iscsi: target: Fix conn_ops double free
+
+ * user_copy in user from ubuntu_kernel_selftests failed on KVM kernel
+ (LP: #1812198)
+ - selftests: user: return Kselftest Skip code for skipped tests
+ - selftests: kselftest: change KSFT_SKIP=4 instead of KSFT_PASS
+ - selftests: kselftest: Remove outdated comment
+
+ * RTL8822BE WiFi Disabled in Kernel 4.18.0-12 (LP: #1806472)
+ - SAUCE: staging: rtlwifi: allow RTLWIFI_DEBUG_ST to be disabled
+ - [Config] CONFIG_RTLWIFI_DEBUG_ST=n
+ - SAUCE: Add r8822be to signature inclusion list
+
+ * kernel oops in bcache module (LP: #1793901)
+ - SAUCE: bcache: never writeback a discard operation
+
+ * CVE-2018-18397
+ - userfaultfd: use ENOENT instead of EFAULT if the atomic copy user fails
+ - userfaultfd: shmem: allocate anonymous memory for MAP_PRIVATE shmem
+ - userfaultfd: shmem/hugetlbfs: only allow to register VM_MAYWRITE vmas
+ - userfaultfd: shmem: add i_size checks
+ - userfaultfd: shmem: UFFDIO_COPY: set the page dirty if VM_WRITE is not set
+
+ * Ignore "incomplete report" from Elan touchpanels (LP: #1813733)
+ - HID: i2c-hid: Ignore input report if there's no data present on Elan
+ touchpanels
+
+ * Vsock connect fails with ENODEV for large CID (LP: #1813934)
+ - vhost/vsock: fix vhost vsock cid hashing inconsistent
+
+ * SRU: Fix thinkpad 11e 3rd boot hang (LP: #1804604)
+ - ACPI / LPSS: Force LPSS quirks on boot
+
+ * Bionic update: upstream stable patchset 2019-01-17 (LP: #1812229)
+ - scsi: sd_zbc: Fix variable type and bogus comment
+ - KVM/Eventfd: Avoid crash when assign and deassign specific eventfd in
+ parallel.
+ - x86/apm: Don't access __preempt_count with zeroed fs
+ - x86/events/intel/ds: Fix bts_interrupt_threshold alignment
+ - x86/MCE: Remove min interval polling limitation
+ - fat: fix memory allocation failure handling of match_strdup()
+ - ALSA: hda/realtek - Add Panasonic CF-SZ6 headset jack quirk
+ - ARCv2: [plat-hsdk]: Save accl reg pair by default
+ - ARC: Fix CONFIG_SWAP
+ - ARC: configs: Remove CONFIG_INITRAMFS_SOURCE from defconfigs
+ - ARC: mm: allow mprotect to make stack mappings executable
+ - mm: memcg: fix use after free in mem_cgroup_iter()
+ - mm/huge_memory.c: fix data loss when splitting a file pmd
+ - cpufreq: intel_pstate: Register when ACPI PCCH is present
+ - vfio/pci: Fix potential Spectre v1
+ - stop_machine: Disable preemption when waking two stopper threads
+ - drm/i915: Fix hotplug irq ack on i965/g4x
+ - drm/nouveau: Use drm_connector_list_iter_* for iterating connectors
+ - drm/nouveau: Avoid looping through fake MST connectors
+ - gen_stats: Fix netlink stats dumping in the presence of padding
+ - ipv4: Return EINVAL when ping_group_range sysctl doesn't map to user ns
+ - ipv6: fix useless rol32 call on hash
+ - ipv6: ila: select CONFIG_DST_CACHE
+ - lib/rhashtable: consider param->min_size when setting initial table size
+ - net: diag: Don't double-free TCP_NEW_SYN_RECV sockets in tcp_abort
+ - net: Don't copy pfmemalloc flag in __copy_skb_header()
+ - skbuff: Unconditionally copy pfmemalloc in __skb_clone()
+ - net/ipv4: Set oif in fib_compute_spec_dst
+ - net: phy: fix flag masking in __set_phy_supported
+ - ptp: fix missing break in switch
+ - qmi_wwan: add support for Quectel EG91
+ - tg3: Add higher cpu clock for 5762.
+ - hv_netvsc: Fix napi reschedule while receive completion is busy
+ - net/mlx4_en: Don't reuse RX page when XDP is set
+ - net: systemport: Fix CRC forwarding check for SYSTEMPORT Lite
+ - ipv6: make DAD fail with enhanced DAD when nonce length differs
+ - net: usb: asix: replace mii_nway_restart in resume path
+ - alpha: fix osf_wait4() breakage
+ - cxl_getfile(): fix double-iput() on alloc_file() failures
+ - powerpc/powernv: Fix save/restore of SPRG3 on entry/exit from stop (idle)
+ - xhci: Fix perceived dead host due to runtime suspend race with event handler
+ - KVM: irqfd: fix race between EPOLLHUP and irq_bypass_register_consumer
+ - x86/kvmclock: set pvti_cpu0_va after enabling kvmclock
+ - ALSA: hda/realtek - Yet another Clevo P950 quirk entry
+ - drm/amdgpu: Reserve VM root shared fence slot for command submission (v3)
+ - rhashtable: add restart routine in rhashtable_free_and_destroy()
+ - sch_fq_codel: zero q->flows_cnt when fq_codel_init fails
+ - sctp: introduce sctp_dst_mtu
+ - sctp: fix the issue that pathmtu may be set lower than MINSEGMENT
+ - net: aquantia: vlan unicast address list correct handling
+ - drm_mode_create_lease_ioctl(): fix open-coded filp_clone_open()
+
+ * Bionic update: upstream stable patchset 2019-01-15 (LP: #1811877)
+ - compiler-gcc.h: Add __attribute__((gnu_inline)) to all inline declarations
+ - x86/asm: Add _ASM_ARG* constants for argument registers to <asm/asm.h>
+ - x86/paravirt: Make native_save_fl() extern inline
+ - Btrfs: fix duplicate extents after fsync of file with prealloc extents
+ - cpufreq / CPPC: Set platform specific transition_delay_us
+ - PCI: exynos: Fix a potential init_clk_resources NULL pointer dereference
+ - alx: take rtnl before calling __alx_open from resume
+ - atm: Preserve value of skb->truesize when accounting to vcc
+ - atm: zatm: Fix potential Spectre v1
+ - ipv6: sr: fix passing wrong flags to crypto_alloc_shash()
+ - ipvlan: fix IFLA_MTU ignored on NEWLINK
+ - ixgbe: split XDP_TX tail and XDP_REDIRECT map flushing
+ - net: dccp: avoid crash in ccid3_hc_rx_send_feedback()
+ - net: dccp: switch rx_tstamp_last_feedback to monotonic clock
+ - net: fix use-after-free in GRO with ESP
+ - net: macb: Fix ptp time adjustment for large negative delta
+ - net/mlx5e: Avoid dealing with vport representors if not being e-switch
+ manager
+ - net/mlx5: E-Switch, Avoid setup attempt if not being e-switch manager
+ - net/mlx5: Fix command interface race in polling mode
+ - net/mlx5: Fix incorrect raw command length parsing
+ - net/mlx5: Fix required capability for manipulating MPFS
+ - net/mlx5: Fix wrong size allocation for QoS ETC TC regitster
+ - net: mvneta: fix the Rx desc DMA address in the Rx path
+ - net/packet: fix use-after-free
+ - net_sched: blackhole: tell upper qdisc about dropped packets
+ - net: sungem: fix rx checksum support
+ - net/tcp: Fix socket lookups with SO_BINDTODEVICE
+ - qede: Adverstise software timestamp caps when PHC is not available.
+ - qed: Fix setting of incorrect eswitch mode.
+ - qed: Fix use of incorrect size in memcpy call.
+ - qed: Limit msix vectors in kdump kernel to the minimum required count.
+ - r8152: napi hangup fix after disconnect
+ - stmmac: fix DMA channel hang in half-duplex mode
+ - strparser: Remove early eaten to fix full tcp receive buffer stall
+ - tcp: fix Fast Open key endianness
+ - tcp: prevent bogus FRTO undos with non-SACK flows
+ - vhost_net: validate sock before trying to put its fd
+ - VSOCK: fix loopback on big-endian systems
+ - net: cxgb3_main: fix potential Spectre v1
+ - rtlwifi: Fix kernel Oops "Fw download fail!!"
+ - rtlwifi: rtl8821ae: fix firmware is not ready to run
+ - net: lan78xx: Fix race in tx pending skb size calculation
+ - crypto: af_alg - Initialize sg_num_bytes in error code path
+ - mtd: rawnand: denali_dt: set clk_x_rate to 200 MHz unconditionally
+ - PCI: hv: Disable/enable IRQs rather than BH in hv_compose_msi_msg()
+ - netfilter: ebtables: reject non-bridge targets
+ - reiserfs: fix buffer overflow with long warning messages
+ - KEYS: DNS: fix parsing multiple options
+ - tls: Stricter error checking in zerocopy sendmsg path
+ - autofs: fix slab out of bounds read in getname_kernel()
+ - nsh: set mac len based on inner packet
+ - bdi: Fix another oops in wb_workfn()
+ - rds: avoid unenecessary cong_update in loop transport
+ - net/nfc: Avoid stalls when nfc_alloc_send_skb() returned NULL.
+ - string: drop __must_check from strscpy() and restore strscpy() usages in
+ cgroup
+ - nfsd: COPY and CLONE operations require the saved filehandle to be set
+ - net/sched: act_ife: fix recursive lock and idr leak
+ - net/sched: act_ife: preserve the action control in case of error
+ - hinic: reset irq affinity before freeing irq
+ - nfp: flower: fix mpls ether type detection
+ - net: macb: initialize bp->queues[0].bp for at91rm9200
+ - enic: do not overwrite error code
+ - virtio_net: fix memory leak in XDP_REDIRECT
+ - netfilter: ipv6: nf_defrag: drop skb dst before queueing
+ - ipvs: initialize tbl->entries after allocation
+ - ipvs: initialize tbl->entries in ip_vs_lblc_init_svc()
+ - bpf: enforce correct alignment for instructions
+ - bpf, arm32: fix to use bpf_jit_binary_lock_ro api
+
+ * Fix non-working pinctrl-intel (LP: #1811777)
+ - pinctrl: intel: Implement intel_gpio_get_direction callback
+ - pinctrl: intel: Do pin translation in other GPIO operations as well
+
+ * ip6_gre: fix tunnel list corruption for x-netns (LP: #1812875)
+ - ip6_gre: fix tunnel list corruption for x-netns
+
+ * Userspace break as a result of missing patch backport (LP: #1813873)
+ - tty: Don't hold ldisc lock in tty_reopen() if ldisc present
+
+ * kvm_stat : missing python dependency (LP: #1798776)
+ - tools/kvm_stat: fix python3 issues
+ - tools/kvm_stat: switch to python3
+
+ * [SRU] Fix Xorg crash with nomodeset when BIOS enable 64-bit fb addr
+ (LP: #1812797)
+ - vgaarb: Add support for 64-bit frame buffer address
+ - vgaarb: Keep adding VGA device in queue
+
+ * Fix non-working QCA Rome Bluetooth after S3 (LP: #1812812)
+ - USB: Add new USB LPM helpers
+ - USB: Consolidate LPM checks to avoid enabling LPM twice
+
+ * ptrace-tm-spd-gpr in powerpc/ptrace from ubuntu_kerenl_selftests failed on
+ Bionic P8 (LP: #1813127)
+ - selftests/powerpc: Fix ptrace tm failure
+
+ * [SRU] IO's are issued with incorrect Scatter Gather Buffer (LP: #1795453)
+ - scsi: megaraid_sas: Use 63-bit DMA addressing
+
+ * Consider enabling CONFIG_NETWORK_PHY_TIMESTAMPING (LP: #1785816)
+ - [Config] Enable timestamping in network PHY devices
+
+ * CVE-2018-19854
+ - crypto: user - fix leaking uninitialized memory to userspace
+
+ * x86/mm: Found insecure W+X mapping at address (ptrval)/0xc00a0000
+ (LP: #1813532)
+ - x86/mm: Do not warn about PCI BIOS W+X mappings
+
+ * CVE-2019-6133
+ - fork: record start_time late
+
+ * Fix not working Goodix touchpad (LP: #1811929)
+ - HID: i2c-hid: Disable runtime PM on Goodix touchpad
+
+ * bluetooth controller not detected with 4.15 kernel (LP: #1810797)
+ - SAUCE: btqcomsmd: introduce BT_QCOMSMD_HACK
+ - [Config] arm64: snapdragon: BT_QCOMSMD_HACK=y
+
+ * X1 Extreme: only one of the two SSDs is loaded (LP: #1811755)
+ - nvme-core: rework a NQN copying operation
+ - nvme: pad fake subsys NQN vid and ssvid with zeros
+ - nvme: introduce NVME_QUIRK_IGNORE_DEV_SUBNQN
+
+ * Crash on "ip link add foo type ipip" (LP: #1811803)
+ - SAUCE: fan: Fix NULL pointer dereference
+
+ -- Khalid Elmously <khalid.elmously@canonical.com> Wed, 06 Feb 2019 04:57:21 +0000
+
+linux (4.15.0-45.48) bionic; urgency=medium
+
+ * linux: 4.15.0-45.48 -proposed tracker (LP: #1813779)
+
+ * External monitors does not work anymore 4.15.0-44 (LP: #1813663)
+ - SAUCE: Revert "drm/i915/dp: Send DPCD ON for MST before phy_up"
+
+ * kernel 4.15.0-44 cannot mount ext4 fs with meta_bg enabled (LP: #1813727)
+ - ext4: fix false negatives *and* false positives in ext4_check_descriptors()
+
+ -- Stefan Bader <stefan.bader@canonical.com> Tue, 29 Jan 2019 16:39:15 +0100
+
+linux (4.15.0-44.47) bionic; urgency=medium
+
+ * linux: 4.15.0-44.47 -proposed tracker (LP: #1811419)
+
+ * Packaging resync (LP: #1786013)
+ - [Packaging] update helper scripts
+
+ * CPU hard lockup with rigorous writes to NVMe drive (LP: #1810998)
+ - blk-wbt: pass in enum wbt_flags to get_rq_wait()
+ - blk-wbt: Avoid lock contention and thundering herd issue in wbt_wait
+ - blk-wbt: move disable check into get_limit()
+ - blk-wbt: use wq_has_sleeper() for wq active check
+ - blk-wbt: fix has-sleeper queueing check
+ - blk-wbt: abstract out end IO completion handler
+ - blk-wbt: improve waking of tasks
+
+ * To reduce the Realtek USB cardreader power consumption (LP: #1811337)
+ - mmc: sdhci: Disable 1.8v modes (HS200/HS400/UHS) if controller can't support
+ 1.8v
+ - mmc: core: Introduce MMC_CAP_SYNC_RUNTIME_PM
+ - mmc: rtsx_usb_sdmmc: Don't runtime resume the device while changing led
+ - mmc: rtsx_usb: Use MMC_CAP2_NO_SDIO
+ - mmc: rtsx_usb: Enable MMC_CAP_ERASE to allow erase/discard/trim requests
+ - mmc: rtsx_usb_sdmmc: Re-work runtime PM support
+ - mmc: rtsx_usb_sdmmc: Re-work card detection/removal support
+ - memstick: rtsx_usb_ms: Add missing pm_runtime_disable() in probe function
+ - misc: rtsx_usb: Use USB remote wakeup signaling for card insertion detection
+ - memstick: Prevent memstick host from getting runtime suspended during card
+ detection
+ - memstick: rtsx_usb_ms: Use ms_dev() helper
+ - memstick: rtsx_usb_ms: Support runtime power management
+
+ * Support non-strict iommu mode on arm64 (LP: #1806488)
+ - iommu/io-pgtable-arm: Fix race handling in split_blk_unmap()
+ - iommu/arm-smmu-v3: Implement flush_iotlb_all hook
+ - iommu/dma: Add support for non-strict mode
+ - iommu: Add "iommu.strict" command line option
+ - iommu/io-pgtable-arm: Add support for non-strict mode
+ - iommu/arm-smmu-v3: Add support for non-strict mode
+ - iommu/io-pgtable-arm-v7s: Add support for non-strict mode
+ - iommu/arm-smmu: Support non-strict mode
+
+ * ELAN900C:00 04F3:2844 touchscreen doesn't work (LP: #1811335)
+ - pinctrl: cannonlake: Fix community ordering for H variant
+ - pinctrl: cannonlake: Fix HOSTSW_OWN register offset of H variant
+
+ * Add Cavium ThunderX2 SoC UNCORE PMU driver (LP: #1811200)
+ - perf: Export perf_event_update_userpage
+ - Documentation: perf: Add documentation for ThunderX2 PMU uncore driver
+ - drivers/perf: Add Cavium ThunderX2 SoC UNCORE PMU driver
+ - [Config] New config CONFIG_THUNDERX2_PMU=m
+
+ * Update hisilicon SoC-specific drivers (LP: #1810457)
+ - SAUCE: Revert "net: hns3: Updates RX packet info fetch in case of multi BD"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: separate roce from nic when
+ resetting"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: Use roce handle when calling roce
+ callback function"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: Add calling roce callback
+ function when link status change"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: optimize the process of notifying
+ roce client"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: Add pf reset for hip08 RoCE"
+ - scsi: hisi_sas: Remove depends on HAS_DMA in case of platform dependency
+ - ethernet: hisilicon: hns: hns_dsaf_mac: Use generic eth_broadcast_addr
+ - scsi: hisi_sas: consolidate command check in hisi_sas_get_ata_protocol()
+ - scsi: hisi_sas: remove some unneeded structure members
+ - scsi: hisi_sas: Introduce hisi_sas_phy_set_linkrate()
+ - net: hns: Fix the process of adding broadcast addresses to tcam
+ - net: hns3: remove redundant variable 'protocol'
+ - scsi: hisi_sas: Drop hisi_sas_slot_abort()
+ - net: hns: Make many functions static
+ - net: hns: make hns_dsaf_roce_reset non static
+ - net: hisilicon: hns: Replace mdelay() with msleep()
+ - net: hns3: fix return value error while hclge_cmd_csq_clean failed
+ - net: hns: remove redundant variables 'max_frm' and 'tmp_mac_key'
+ - net: hns: Mark expected switch fall-through
+ - net: hns3: Mark expected switch fall-through
+ - net: hns3: Remove tx ring BD len register in hns3_enet
+ - net: hns: modify variable type in hns_nic_reuse_page
+ - net: hns: use eth_get_headlen interface instead of hns_nic_get_headlen
+ - net: hns3: modify variable type in hns3_nic_reuse_page
+ - net: hns3: Fix for vf vlan delete failed problem
+ - net: hns3: Fix for multicast failure
+ - net: hns3: Fix error of checking used vlan id
+ - net: hns3: Implement shutdown ops in hns3 pci driver
+ - net: hns3: Fix for loopback selftest failed problem
+ - net: hns3: Fix ping exited problem when doing lp selftest
+ - net: hns3: Preserve vlan 0 in hardware table
+ - net: hns3: Only update mac configuation when necessary
+ - net: hns3: Change the dst mac addr of loopback packet
+ - net: hns3: Remove redundant codes of query advertised flow control abilitiy
+ - net: hns3: Refine hns3_get_link_ksettings()
+ - net: hns: make function hns_gmac_wait_fifo_clean() static
+ - net: hns3: Add default irq affinity
+ - net: hns3: Add unlikely for buf_num check
+ - net: hns3: Remove tx budget to clean more TX descriptors in a napi
+ - net: hns3: Remove packet statistics of public
+ - net: hns3: Add support for hns3_nic_netdev_ops.ndo_do_ioctl
+ - net: hns3: Set STATE_DOWN bit of hdev state when stopping net
+ - net: hns3: Check hdev state when getting link status
+ - net: hns3: Fix for setting speed for phy failed problem
+ - net: hns3: Fix cmdq registers initialization issue for vf
+ - net: hns3: Clear client pointer when initialize client failed or unintialize
+ finished
+ - net: hns3: Fix client initialize state issue when roce client initialize
+ failed
+ - net: hns3: Fix parameter type for q_id in hclge_tm_q_to_qs_map_cfg()
+ - net: hns3: Fix ets validate issue
+ - net: hns3: Unify the type convert for desc.data
+ - net: hns3: Adjust prefix of tx/rx statistic names
+ - net: hns3: Fix tqp array traversal condition for vf
+ - net: hns3: Unify the prefix of vf functions
+ - net: hns3: Add handle for default case
+ - net: hns3: Add nic state check before calling netif_tx_wake_queue
+ - net: hns3: Add unlikely for dma_mapping_error check
+ - net: hns3: Remove print messages for error packet
+ - net: hns3: Add get_media_type ops support for VF
+ - net: hns3: Fix speed/duplex information loss problem when executing ethtool
+ ethx cmd of VF
+ - net: hns3: Remove redundant hclge_get_port_type()
+ - net: hns3: Add support for sctp checksum offload
+ - net: hns3: Set extra mac address of pause param for HW
+ - net: hns3: Rename loop mode
+ - net: hns3: Rename mac loopback to app loopback
+ - net: hns3: Add serdes parallel inner loopback support
+ - net: hns3: Fix for packet buffer setting bug
+ - net: hns3: Fix for netdev not up problem when setting mtu
+ - net: hns3: Change return type of hclge_tm_schd_info_update()
+ - net: hns3: Modify hns3_get_max_available_channels
+ - net: hns3: Fix loss of coal configuration while doing reset
+ - net: hns: remove ndo_poll_controller
+ - hns3: Fix the build.
+ - hns3: Another build fix.
+ - net: hns3: Add flow director initialization
+ - net: hns3: Add input key and action config support for flow director
+ - net: hns3: Add support for rule add/delete for flow director
+ - net: hns3: Add support for rule query of flow director
+ - net: hns3: Add reset handle for flow director
+ - net: hns3: Remove all flow director rules when unload hns3 driver
+ - net: hns3: Add support for enable/disable flow director
+ - net: hns3: Remove the default mask configuration for mac vlan table
+ - net: hns3: Clear mac vlan table entries when unload driver or function reset
+ - net: hns3: Optimize for unicast mac vlan table
+ - net: hns3: Drop depricated mta table support
+ - net: hns3: Add egress/ingress vlan filter for revision 0x21
+ - net: hns3: Fix for rx vlan id handle to support Rev 0x21 hardware
+ - net: hns3: Add new RSS hash algorithm support for PF
+ - net: hns3: Add RSS general configuration support for VF
+ - net: hns3: Add RSS tuples support for VF
+ - net: hns3: Add HW RSS hash information to RX skb
+ - net: hns3: Enable promisc mode when mac vlan table is full
+ - net: hns3: Resume promisc mode and vlan filter status after reset
+ - net: hns3: Resume promisc mode and vlan filter status after loopback test
+ - scsi: hisi_sas: Feed back linkrate(max/min) when re-attached
+ - scsi: hisi_sas: Move evaluation of hisi_hba in hisi_sas_task_prep()
+ - scsi: hisi_sas: Fix the race between IO completion and timeout for
+ SMP/internal IO
+ - scsi: hisi_sas: Free slot later in slot_complete_vx_hw()
+ - scsi: hisi_sas: unmask interrupts ent72 and ent74
+ - scsi: hisi_sas: Use block layer tag instead for IPTT
+ - scsi: hisi_sas: Update v3 hw AIP_LIMIT and CFG_AGING_TIME register values
+ - net: hns3: remove hns3_fill_desc_tso
+ - net: hns3: move DMA map into hns3_fill_desc
+ - net: hns3: add handling for big TX fragment
+ - net: hns3: rename hns_nic_dma_unmap
+ - net: hns3: fix for multiple unmapping DMA problem
+ - scsi: hisi_sas: Fix spin lock management in slot_index_alloc_quirk_v2_hw()
+ - scsi: hisi_sas: Fix NULL pointer dereference
+ - net: hns3: Add PCIe AER callback error_detected
+ - net: hns3: Add PCIe AER error recovery
+ - net: hns3: Add support to enable and disable hw errors
+ - net: hns3: Add enable and process common ecc errors
+ - net: hns3: Add enable and process hw errors from IGU, EGU and NCSI
+ - net: hns3: Add enable and process hw errors from PPP
+ - net: hns3: Add enable and process hw errors of TM scheduler
+ - net: hns3: Fix for warning uninitialized symbol hw_err_lst3
+ - net: hns3: fix spelling mistake "intrerrupt" -> "interrupt"
+ - net: hns3: add error handler for hns3_nic_init_vector_data()
+ - net: hns3: bugfix for buffer not free problem during resetting
+ - net: hns3: bugfix for reporting unknown vector0 interrupt repeatly problem
+ - net: hns3: bugfix for the initialization of command queue's spin lock
+ - net: hns3: remove unnecessary queue reset in the hns3_uninit_all_ring()
+ - net: hns3: bugfix for is_valid_csq_clean_head()
+ - net: hns3: bugfix for hclge_mdio_write and hclge_mdio_read
+ - net: hns3: fix incorrect return value/type of some functions
+ - net: hns3: bugfix for handling mailbox while the command queue reinitialized
+ - net: hns3: bugfix for rtnl_lock's range in the hclge_reset()
+ - net: hns3: bugfix for rtnl_lock's range in the hclgevf_reset()
+ - net: hns3: Fix for out-of-bounds access when setting pfc back pressure
+ - scsi: hisi_sas: Remove set but not used variable 'dq_list'
+ - net: hns3: bugfix for not checking return value
+ - net: hns: Incorrect offset address used for some registers.
+ - net: hns: All ports can not work when insmod hns ko after rmmod.
+ - net: hns: Some registers use wrong address according to the datasheet.
+ - net: hns: Fixed bug that netdev was opened twice
+ - net: hns: Clean rx fbd when ae stopped.
+ - net: hns: Free irq when exit from abnormal branch
+ - net: hns: Avoid net reset caused by pause frames storm
+ - net: hns: Fix ntuple-filters status error.
+ - net: hns: Add mac pcs config when enable|disable mac
+ - net: hns: Fix ping failed when use net bridge and send multicast
+ - net: hns3: use HNS3_NIC_STATE_INITED to indicate the initialization state of
+ enet
+ - net: hns3: add set_default_reset_request in the hnae3_ae_ops
+ - net: hns3: provide some interface & information for the client
+ - net: hns3: adjust the location of clearing the table when doing reset
+ - net: hns3: enable/disable ring in the enet while doing UP/DOWN
+ - net: hns3: use HNS3_NIC_STATE_RESETTING to indicate resetting
+ - net: hns3: ignore new coming low-level reset while doing high-level reset
+ - net: hns3: move some reset information from hnae3_handle into
+ hclge_dev/hclgevf_dev
+ - net: hns3: adjust the process of PF reset
+ - net: hns3: call roce's reset notify callback when resetting
+ - net: hns3: add error handler for hclge_reset()
+ - net: hns3: fix for cmd queue memory not freed problem during reset
+ - net: hns3: Remove set but not used variable 'reset_level'
+ - net: hns3: fix spelling mistake, "assertting" -> "asserting"
+ - net: hns3: add reset_hdev to reinit the hdev in VF's reset process
+ - net: hns3: adjust VF's reset process
+ - net: hns3: add reset handling for VF when doing PF reset
+ - net: hns3: add reset handling for VF when doing Core/Global/IMP reset
+ - net: hns3: stop handling command queue while resetting VF
+ - net: hns3: add error handler for hclgevf_reset()
+ - net: hns3: stop napi polling when HNS3_NIC_STATE_DOWN is set
+ - net: hns3: implement the IMP reset processing for PF
+ - net: hns3: add PCIe FLR support for PF
+ - net: hns3: do VF's pci re-initialization while PF doing FLR
+ - net: hns3: add PCIe FLR support for VF
+ - net: hns3: Enable HW GRO for Rev B(=0x21) HNS3 hardware
+ - net: hns3: Add handling of GRO Pkts not fully RX'ed in NAPI poll
+ - net: hns3: Add skb chain when num of RX buf exceeds MAX_SKB_FRAGS
+ - net: hns3: Adds GRO params to SKB for the stack
+ - scsi: hisi_sas: use dma_set_mask_and_coherent
+ - scsi: hisi_sas: Create separate host attributes per HBA
+ - scsi: hisi_sas: Add support for interrupt converge for v3 hw
+ - scsi: hisi_sas: Add support for interrupt coalescing for v3 hw
+ - scsi: hisi_sas: Relocate some codes to avoid an unused check
+ - scsi: hisi_sas: change the time of SAS SSP connection
+ - net: hns3: fix spelling mistake "failded" -> "failed"
+ - net: hns3: Support two vlan header when setting mtu
+ - net: hns3: Refactor mac mtu setting related functions
+ - net: hns3: Add vport alive state checking support
+ - net: hns3: Add mtu setting support for vf
+ - net: hns3: up/down netdev in hclge module when setting mtu
+ - net: hns3: add common validation in hclge_dcb
+ - net: hns3: Add debugfs framework registration
+ - net: hns3: Add "queue info" query function
+ - net: hns3: Add "FD flow table" info query function
+ - net: hns3: Add "tc config" info query function
+ - net: hns3: Add "tm config" info query function
+ - net: hns3: Add "qos pause" config info query function
+ - net: hns3: Add "qos prio map" info query function
+ - net: hns3: Add "qos buffer" config info query function
+ - net: hns3: Support "ethtool -d" for HNS3 VF driver
+ - net: hns3: Adds support to dump(using ethool-d) PCIe regs in HNS3 PF driver
+ - net: hns3: remove existing process error functions and reorder hw_blk table
+ - net: hns3: rename enable error interrupt functions
+ - net: hns3: re-enable error interrupts on hw reset
+ - net: hns3: deletes unnecessary settings of the descriptor data
+ - net: hns3: rename process_hw_error function
+ - net: hns3: add optimization in the hclge_hw_error_set_state
+ - net: hns3: add handling of hw ras errors using new set of commands
+ - net: hns3: deleted logging 1 bit errors
+ - net: hns3: add handling of hw errors reported through MSIX
+ - net: hns3: add handling of hw errors of MAC
+ - net: hns3: handle hw errors of PPP PF
+ - net: hns3: handle hw errors of PPU(RCB)
+ - net: hns3: handle hw errors of SSU
+ - net: hns3: add handling of RDMA RAS errors
+ - net: hns3: fix spelling mistake "offser" -> "offset"
+ - scsi: hisi_sas: Fix warnings detected by sparse
+ - scsi: hisi_sas: Relocate some code to reduce complexity
+ - scsi: hisi_sas: Make sg_tablesize consistent value
+ - hns3: prevent building without CONFIG_INET
+ - net: hns3: Add "bd info" query function
+ - net: hns3: Add "manager table" information query function
+ - net: hns3: Add "status register" information query function
+ - net: hns3: Add "dcb register" status information query function
+ - net: hns3: Add "queue map" information query function
+ - net: hns3: Add "tm map" status information query function
+ - net: hns3: fix error handling int the hns3_get_vector_ring_chain
+ - net: hns3: uninitialize pci in the hclgevf_uninit
+ - net: hns3: fix napi_disable not return problem
+ - net: hns3: update some variables while hclge_reset()/hclgevf_reset() done
+ - net: hns3: remove unnecessary configuration recapture while resetting
+ - net: hns3: fix incomplete uninitialization of IRQ in the
+ hns3_nic_uninit_vector_data()
+ - net: hns3: update coalesce param per second
+ - net: hns3: remove 1000M/half support of phy
+ - net: hns3: synchronize speed and duplex from phy when phy link up
+ - net: hns3: getting tx and dv buffer size through firmware
+ - net: hns3: aligning buffer size in SSU to 256 bytes
+ - net: hns3: fix a SSU buffer checking bug
+ - scsi: hisi_sas: Add support for DIF feature for v2 hw
+ - net: hns3: refine the handle for hns3_nic_net_open/stop()
+ - net: hns3: change default tc state to close
+ - net: hns3: fix a bug caused by udelay
+ - net: hns3: add max vector number check for pf
+ - net: hns3: reset tqp while doing DOWN operation
+ - net: hns3: fix vf id check issue when add flow director rule
+ - net: hns3: don't restore rules when flow director is disabled
+ - net: hns3: fix the descriptor index when get rss type
+ - net: hns3: remove redundant variable initialization
+ - net: hns3: call hns3_nic_net_open() while doing HNAE3_UP_CLIENT
+
+ * iptables connlimit allows more connections than the limit when using
+ multiple CPUs (LP: #1811094)
+ - SAUCE: netfilter: xt_connlimit: remove the 'addr' parameter in add_hlist()
+ - netfilter: nf_conncount: expose connection list interface
+ - netfilter: nf_conncount: Fix garbage collection with zones
+ - netfilter: nf_conncount: fix garbage collection confirm race
+ - netfilter: nf_conncount: don't skip eviction when age is negative
+
+ * CVE-2018-16882
+ - KVM: Fix UAF in nested posted interrupt processing
+
+ * Cannot initialize ATA disk if IDENTIFY command fails (LP: #1809046)
+ - scsi: libsas: check the ata device status by ata_dev_enabled()
+
+ * scsi: libsas: fix a race condition when smp task timeout (LP: #1808912)
+ - scsi: libsas: fix a race condition when smp task timeout
+
+ * CVE-2018-14625
+ - vhost/vsock: fix use-after-free in network stack callers
+
+ * Fix and issue that LG I2C touchscreen stops working after reboot
+ (LP: #1805085)
+ - HID: i2c-hid: Disable runtime PM for LG touchscreen
+
+ * powerpc/powernv/pci: Work around races in PCI bridge enabling (LP: #1805245)
+ - powerpc/powernv/pci: Work around races in PCI bridge enabling
+
+ * Drivers: hv: vmbus: Offload the handling of channels to two workqueues
+ (LP: #1807757)
+ - hv_netvsc: fix network namespace issues with VF support
+ - hv_netvsc: split sub-channel setup into async and sync
+ - Drivers: hv: vmbus: Fix the offer_in_progress in vmbus_process_offer()
+ - hv_netvsc: Fix a deadlock by getting rtnl lock earlier in netvsc_probe()
+ - vmbus: don't return values for uninitalized channels
+ - Drivers: hv: vmbus: check the creation_status in vmbus_establish_gpadl()
+ - Drivers: hv: vmbus: Offload the handling of channels to two workqueues
+
+ * Disable LPM for Raydium Touchscreens (LP: #1802248)
+ - USB: quirks: Add no-lpm quirk for Raydium touchscreens
+
+ * Power leakage at S5 with Qualcomm Atheros QCA9377 802.11ac Wireless Network
+ Adapter (LP: #1805607)
+ - SAUCE: ath10k: provide reset function for QCA9377 chip
+
+ * CVE-2018-17972
+ - proc: restrict kernel stack dumps to root
+
+ * CVE-2018-19407
+ - KVM: X86: Fix scan ioapic use-before-initialization
+
+ * CVE-2018-18281
+ - mremap: properly flush TLB before releasing the page
+
+ * Fix USB2 device wrongly detected as USB1 (LP: #1806534)
+ - xhci: Add quirk to workaround the errata seen on Cavium Thunder-X2 Soc
+
+ * armhf guests fail to boot in EFI mode (LP: #1809488)
+ - efi/arm: Revert deferred unmap of early memmap mapping
+
+ * Bionic shows incorrect warning about number of pointers in TFD
+ (LP: #1801102)
+ - iwlwifi: pcie: don't warn if we use all the transmit pointers
+
+ * audio output has constant noise on a Dell machine (LP: #1810891)
+ - ALSA: hda/realtek - Fixed headphone issue for ALC700
+
+ * ldisc crash on reopened tty (LP: #1791758)
+ - tty: Drop tty->count on tty_reopen() failure
+ - tty: Hold tty_ldisc_lock() during tty_reopen()
+ - tty: Don't block on IO when ldisc change is pending
+ - tty: Simplify tty->count math in tty_reopen()
+
+ * SATA device is not going to DEVSLP (LP: #1781533)
+ - ahci: Allow setting a default LPM policy for mobile chipsets
+ - ata: libahci: Correct setting of DEVSLP register
+ - ata: libahci: Allow reconfigure of DEVSLP register
+ - ata: ahci: Support state with min power but Partial low power state
+ - ata: ahci: Enable DEVSLP by default on x86 with SLP_S0
+ - [Config] set CONFIG_SATA_MOBILE_LPM_POLICY=0
+
+ * Console got stuck using serial tty after logout (LP: #1808097)
+ - tty: do not set TTY_IO_ERROR flag if console port
+
+ * fanotify10 in ubuntu_ltp_syscalls failed (LP: #1802454)
+ - fsnotify: fix ignore mask logic in fsnotify()
+
+ * SRU: Fix kernel xhci hang when resume from S3 (LP: #1805344)
+ - usb: xhci: fix uninitialized completion when USB3 port got wrong status
+ - usb: xhci: fix timeout for transition from RExit to U0
+
+ * Add pointstick support for Cirque Touchpad (LP: #1805081)
+ - HID: multitouch: Add pointstick support for Cirque Touchpad
+
+ * Intel NVMe drives timeout when nvme format is attempted (LP: #1797587)
+ - nvme: Use admin command effects for admin commands
+
+ * lineout jack can't work on a Dell machine (LP: #1810892)
+ - ALSA: hda/realtek - Support Dell headset mode for New AIO platform
+
+ * Bionic update: upstream stable patchset 2019-01-04 (LP: #1810554)
+ - MIPS: Call dump_stack() from show_regs()
+ - MIPS: Use async IPIs for arch_trigger_cpumask_backtrace()
+ - MIPS: Fix ioremap() RAM check
+ - mmc: sdhci-esdhc-imx: allow 1.8V modes without 100/200MHz pinctrl states
+ - mmc: dw_mmc: fix card threshold control configuration
+ - ibmasm: don't write out of bounds in read handler
+ - staging: rtl8723bs: Prevent an underflow in rtw_check_beacon_data().
+ - staging: r8822be: Fix RTL8822be can't find any wireless AP
+ - ata: Fix ZBC_OUT command block check
+ - ata: Fix ZBC_OUT all bit handling
+ - vmw_balloon: fix inflation with batching
+ - ahci: Disable LPM on Lenovo 50 series laptops with a too old BIOS
+ - USB: serial: ch341: fix type promotion bug in ch341_control_in()
+ - USB: serial: cp210x: add another USB ID for Qivicon ZigBee stick
+ - USB: serial: keyspan_pda: fix modem-status error handling
+ - USB: serial: mos7840: fix status-register error handling
+ - usb: quirks: add delay quirks for Corsair Strafe
+ - xhci: xhci-mem: off by one in xhci_stream_id_to_ring()
+ - ALSA: hda - Handle pm failure during hotplug
+ - fs/proc/task_mmu.c: fix Locked field in /proc/pid/smaps*
+ - fs, elf: make sure to page align bss in load_elf_library
+ - mm: do not bug_on on incorrect length in __mm_populate()
+ - tracing: Reorder display of TGID to be after PID
+ - kbuild: delete INSTALL_FW_PATH from kbuild documentation
+ - arm64: neon: Fix function may_use_simd() return error status
+ - tools build: fix # escaping in .cmd files for future Make
+ - IB/hfi1: Fix incorrect mixing of ERR_PTR and NULL return values
+ - i2c: tegra: Fix NACK error handling
+ - iw_cxgb4: correctly enforce the max reg_mr depth
+ - xen: setup pv irq ops vector earlier
+ - nvme-pci: Remap CMB SQ entries on every controller reset
+ - crypto: x86/salsa20 - remove x86 salsa20 implementations
+ - uprobes/x86: Remove incorrect WARN_ON() in uprobe_init_insn()
+ - netfilter: nf_queue: augment nfqa_cfg_policy
+ - netfilter: x_tables: initialise match/target check parameter struct
+ - loop: add recursion validation to LOOP_CHANGE_FD
+ - PM / hibernate: Fix oops at snapshot_write()
+ - RDMA/ucm: Mark UCM interface as BROKEN
+ - loop: remember whether sysfs_create_group() was done
+ - f2fs: give message and set need_fsck given broken node id
+ - mm: do not drop unused pages when userfaultd is running
+ - bpf: reject passing modified ctx to helper functions
+ - mei: discard messages from not connected client during power down.
+ - mm: zero unavailable pages before memmap init
+ - xen: remove global bit from __default_kernel_pte_mask for pv guests
+ - f2fs: return error during fill_super
+ - f2fs: avoid bug_on on corrupted inode
+ - f2fs: sanity check on sit entry
+ - f2fs: sanity check for total valid node blocks
+ - ARM: dts: armada-38x: use the new thermal binding
+ - mm: don't do zero_resv_unavail if memmap is not allocated
+
+ * Blacklist Realtek Virtual IPMI device (LP: #1808353)
+ - ipmi:pci: Blacklist a Realtek "IPMI" device
+
+ * Ethernet[10ec:8136] doesn't work after S3 with kernel 4.15.0.43.64
+ (LP: #1809847)
+ - SAUCE: Revert "r8169: don't use MSI-X on RTL8106e"
+ - r8169: re-enable MSI-X on RTL8168g
+
+ * Killer 802.11ac 2x2 (1550 or 1550i) [8086:2526][1a56:1550] is not supported
+ (LP: #1809219)
+ - iwlwifi: add more card IDs for 9000 series
+
+ * Support new Realtek ethernet chips (LP: #1811055)
+ - r8169: Add support for new Realtek Ethernet
+
+ * PC SN720 NVMe WDC 256GB consumes more power in S2Idle than during long idle
+ (LP: #1805775)
+ - SAUCE: pci/nvme: prevent WDC PC SN720 NVMe from entering D3 and being
+ disabled
+
+ * Power consumption during s2idle is higher than long idle (Intel SSDPEKKF)
+ (LP: #1804588)
+ - SAUCE: pci: prevent Intel NVMe SSDPEKKF from entering D3
+ - SAUCE: nvme: add quirk to not call disable function when suspending
+
+ * mpt3sas - driver using the wrong register to update a queue index in FW
+ (LP: #1810781)
+ - scsi: mpt3sas: As per MPI-spec, use combined reply queue for SAS3.5
+ controllers when HBA supports more than 16 MSI-x vectors.
+
+ * HP mobile workstations with hybrid graphics support, can not directly output
+ to external monitors by dGPU (LP: #1810702)
+ - ACPI / OSI: Add OEM _OSI string to enable dGPU direct output
+
+ * broken touchpad after i2c-i801 blacklist change (LP: #1802135)
+ - i2c: i801: Don't restore config registers on runtime PM
+
+ * Enable new Realtek card reader (LP: #1806335)
+ - USB: usb-storage: Add new IDs to ums-realtek
+ - SAUCE: (noup) USB: usb-storage: Make MMC support optional on ums-realtek
+
+ * The line-out on the Dell Dock station can't work (LP: #1806532)
+ - ALSA: usb-audio: Allow to override the longname string
+ - ALSA: usb-audio: Give proper vendor/product name for Dell WD15 Dock
+ - ALSA: usb-audio: Add vendor and product name for Dell WD19 Dock
+
+ * linux-buildinfo: pull out ABI information into its own package
+ (LP: #1806380)
+ - [Packaging] getabis -- handle all known package combinations
+ - [Packaging] getabis -- support parsing a simple version
+
+ * Fix Intel I210 doesn't work when ethernet cable gets plugged (LP: #1806818)
+ - igb: Fix an issue that PME is not enabled during runtime suspend
+
+ * Fix Terminus USB hub that may breaks connected USB devices after S3
+ (LP: #1806850)
+ - USB: Wait for extra delay time after USB_PORT_FEAT_RESET for quirky hub
+
+ * Add support for Dell DW5821e WWAN/GPS module (LP: #1807342)
+ - qmi_wwan: add support for the Dell Wireless 5821e module
+ - qmi_wwan: fix interface number for DW5821e production firmware
+ - USB: option: add support for DW5821e
+
+ * Add support for 0cf3:535b QCA_ROME device (LP: #1807333)
+ - Bluetooth: btusb: Add support for 0cf3:535b QCA_ROME device
+
+ * The mute led can't work anymore on the lenovo x1 carbon (LP: #1808465)
+ - ALSA: hda/realtek - Fix the mute LED regresion on Lenovo X1 Carbon
+
+ * click/pop noise in the headphone on several lenovo laptops (LP: #1805079) //
+ click/pop noise in the headphone on several lenovo laptops (LP: #1805079)
+ - ALSA: hda/realtek - fix the pop noise on headphone for lenovo laptops
+
+ * Touchpad stops working after reboot on Apollo Lake (LP: #1728244)
+ - HID: i2c-hid: disable runtime PM operations on hantick touchpad
+
+ * MAC address pass through on RTL8153-BND for docking station (LP: #1808729)
+ - r8152: Add support for MAC address pass through on RTL8153-BND
+
+ * [Ubuntu] kernel: zcrypt: reinit ap queue state machine (LP: #1805414)
+ - s390/zcrypt: reinit ap queue state machine during device probe
+
+ * [UBUNTU] qeth: fix length check in SNMP processing (LP: #1805802)
+ - s390/qeth: fix length check in SNMP processing
+
+ * ASPEED server console output extremely slow after upgrade to 18.04
+ (LP: #1808183)
+ - drm/ast: Remove existing framebuffers before loading driver
+
+ * Bionic update: upstream stable patchset 2018-12-13 (LP: #1808399)
+ - userfaultfd: hugetlbfs: fix userfaultfd_huge_must_wait() pte access
+ - mm: hugetlb: yield when prepping struct pages
+ - tracing: Fix missing return symbol in function_graph output
+ - scsi: target: Fix truncated PR-in ReadKeys response
+ - s390: Correct register corruption in critical section cleanup
+ - drbd: fix access after free
+ - vfio: Use get_user_pages_longterm correctly
+ - cifs: Fix use after free of a mid_q_entry
+ - cifs: Fix memory leak in smb2_set_ea()
+ - cifs: Fix infinite loop when using hard mount option
+ - drm: Use kvzalloc for allocating blob property memory
+ - drm/udl: fix display corruption of the last line
+ - jbd2: don't mark block as modified if the handle is out of credits
+ - ext4: add corruption check in ext4_xattr_set_entry()
+ - ext4: always verify the magic number in xattr blocks
+ - ext4: make sure bitmaps and the inode table don't overlap with bg
+ descriptors
+ - ext4: always check block group bounds in ext4_init_block_bitmap()
+ - ext4: only look at the bg_flags field if it is valid
+ - ext4: verify the depth of extent tree in ext4_find_extent()
+ - ext4: include the illegal physical block in the bad map ext4_error msg
+ - ext4: never move the system.data xattr out of the inode body
+ - ext4: avoid running out of journal credits when appending to an inline file
+ - ext4: add more inode number paranoia checks
+ - ext4: add more mount time checks of the superblock
+ - ext4: check superblock mapped prior to committing
+ - HID: i2c-hid: Fix "incomplete report" noise
+ - HID: hiddev: fix potential Spectre v1
+ - HID: debug: check length before copy_to_user()
+ - media: vb2: core: Finish buffers at the end of the stream
+ - f2fs: truncate preallocated blocks in error case
+ - Revert "dpaa_eth: fix error in dpaa_remove()"
+ - Kbuild: fix # escaping in .cmd files for future Make
+ - media: cx25840: Use subdev host data for PLL override
+ - fs: allow per-device dax status checking for filesystems
+ - dax: change bdev_dax_supported() to support boolean returns
+ - dax: check for QUEUE_FLAG_DAX in bdev_dax_supported()
+ - dm: set QUEUE_FLAG_DAX accordingly in dm_table_set_restrictions()
+ - dm: prevent DAX mounts if not supported
+ - mtd: cfi_cmdset_0002: Change definition naming to retry write operation
+ - mtd: cfi_cmdset_0002: Change erase functions to retry for error
+ - mtd: cfi_cmdset_0002: Change erase functions to check chip good only
+ - netfilter: nf_log: don't hold nf_log_mutex during user access
+ - staging: comedi: quatech_daqp_cs: fix no-op loop daqp_ao_insn_write()
+ - sched, tracing: Fix trace_sched_pi_setprio() for deboosting
+ - PCI / ACPI / PM: Resume bridges w/o drivers on suspend-to-RAM
+ - drm/amdgpu: Make struct amdgpu_atif private to amdgpu_acpi.c
+ - scsi: aacraid: Fix PD performance regression over incorrect qd being set
+ - ARM: dts: imx51-zii-rdu1: fix touchscreen pinctrl
+ - drm/amdgpu: Add amdgpu_atpx_get_dhandle()
+ - drm/amdgpu: Dynamically probe for ATIF handle (v2)
+ - i2c: core: smbus: fix a potential missing-check bug
+
+ * Bionic update: upstream stable patchset 2018-12-12 (LP: #1808185)
+ - usb: cdc_acm: Add quirk for Uniden UBC125 scanner
+ - USB: serial: cp210x: add CESINEL device ids
+ - USB: serial: cp210x: add Silicon Labs IDs for Windows Update
+ - usb: dwc2: fix the incorrect bitmaps for the ports of multi_tt hub
+ - acpi: Add helper for deactivating memory region
+ - usb: typec: ucsi: acpi: Workaround for cache mode issue
+ - usb: typec: ucsi: Fix for incorrect status data issue
+ - xhci: Fix kernel oops in trace_xhci_free_virt_device
+ - n_tty: Fix stall at n_tty_receive_char_special().
+ - n_tty: Access echo_* variables carefully.
+ - staging: android: ion: Return an ERR_PTR in ion_map_kernel
+ - serial: 8250_pci: Remove stalled entries in blacklist
+ - serdev: fix memleak on module unload
+ - vt: prevent leaking uninitialized data to userspace via /dev/vcs*
+ - drm/amdgpu: Add APU support in vi_set_uvd_clocks
+ - drm/amdgpu: Add APU support in vi_set_vce_clocks
+ - drm/amdgpu: fix the missed vcn fw version report
+ - drm/qxl: Call qxl_bo_unref outside atomic context
+ - drm/atmel-hlcdc: check stride values in the first plane
+ - drm/amdgpu: Use kvmalloc_array for allocating VRAM manager nodes array
+ - drm/amdgpu: Refactor amdgpu_vram_mgr_bo_invisible_size helper
+ - drm/i915: Enable provoking vertex fix on Gen9 systems.
+ - netfilter: nf_tables: nft_compat: fix refcount leak on xt module
+ - netfilter: nft_compat: prepare for indirect info storage
+ - netfilter: nft_compat: fix handling of large matchinfo size
+ - netfilter: nf_tables: don't assume chain stats are set when jumplabel is set
+ - netfilter: nf_tables: bogus EBUSY in chain deletions
+ - netfilter: nft_meta: fix wrong value dereference in nft_meta_set_eval
+ - netfilter: nf_tables: disable preemption in nft_update_chain_stats()
+ - netfilter: nf_tables: increase nft_counters_enabled in
+ nft_chain_stats_replace()
+ - netfilter: nf_tables: fix memory leak on error exit return
+ - netfilter: nf_tables: add missing netlink attrs to policies
+ - netfilter: nf_tables: fix NULL-ptr in nf_tables_dump_obj()
+ - netfilter: don't set F_IFACE on ipv6 fib lookups
+ - netfilter: ip6t_rpfilter: provide input interface for route lookup
+ - netfilter: nf_tables: use WARN_ON_ONCE instead of BUG_ON in nft_do_chain()
+ - ARM: dts: imx6q: Use correct SDMA script for SPI5 core
+ - xfrm6: avoid potential infinite loop in _decode_session6()
+ - afs: Fix directory permissions check
+ - netfilter: ebtables: handle string from userspace with care
+ - s390/dasd: use blk_mq_rq_from_pdu for per request data
+ - netfilter: nft_limit: fix packet ratelimiting
+ - ipvs: fix buffer overflow with sync daemon and service
+ - iwlwifi: pcie: compare with number of IRQs requested for, not number of CPUs
+ - atm: zatm: fix memcmp casting
+ - net: qmi_wwan: Add Netgear Aircard 779S
+ - perf test: "Session topology" dumps core on s390
+ - perf bpf: Fix NULL return handling in bpf__prepare_load()
+ - fs: clear writeback errors in inode_init_always
+ - sched/core: Fix rules for running on online && !active CPUs
+ - sched/core: Require cpu_active() in select_task_rq(), for user tasks
+ - platform/x86: asus-wmi: Fix NULL pointer dereference
+ - net/sonic: Use dma_mapping_error()
+ - net: dsa: b53: Add BCM5389 support
+ - usb: typec: tcpm: fix logbuffer index is wrong if _tcpm_log is re-entered
+ - iio: mma8452: Fix ignoring MMA8452_INT_DRDY
+ - drm/amdgpu: fix clear_all and replace handling in the VM (v2)
+ - drm/amd/display: Clear connector's edid pointer
+ - drm/i915/dp: Send DPCD ON for MST before phy_up
+ - drm/amdgpu: remove DC special casing for KB/ML
+ - drm/amdgpu: Don't default to DC support for Kaveri and older
+ - drm/amdgpu: GPU vs CPU page size fixes in amdgpu_vm_bo_split_mapping
+ - drm/amd/display: release spinlock before committing updates to stream
+ - drm/i915: Fix PIPESTAT irq ack on i965/g4x
+ - ARM64: dts: meson-gxl-s905x-p212: Add phy-supply for usb0
+ - x86/mm: Don't free P4D table when it is folded at runtime
+
+ * Bionic update: upstream stable patchset 2018-12-07 (LP: #1807469)
+ - x86/spectre_v1: Disable compiler optimizations over
+ array_index_mask_nospec()
+ - x86/mce: Improve error message when kernel cannot recover
+ - x86/mce: Check for alternate indication of machine check recovery on Skylake
+ - x86/mce: Fix incorrect "Machine check from unknown source" message
+ - x86/mce: Do not overwrite MCi_STATUS in mce_no_way_out()
+ - x86: Call fixup_exception() before notify_die() in math_error()
+ - m68k/mm: Adjust VM area to be unmapped by gap size for __iounmap()
+ - m68k/mac: Fix SWIM memory resource end address
+ - serial: sh-sci: Use spin_{try}lock_irqsave instead of open coding version
+ - signal/xtensa: Consistenly use SIGBUS in do_unaligned_user
+ - PM / Domains: Fix error path during attach in genpd
+ - PM / core: Fix supplier device runtime PM usage counter imbalance
+ - PM / OPP: Update voltage in case freq == old_freq
+ - usb: do not reset if a low-speed or full-speed device timed out
+ - 1wire: family module autoload fails because of upper/lower case mismatch.
+ - ASoC: dapm: delete dapm_kcontrol_data paths list before freeing it
+ - ASoC: cs35l35: Add use_single_rw to regmap config
+ - ASoC: cirrus: i2s: Fix LRCLK configuration
+ - ASoC: cirrus: i2s: Fix {TX|RX}LinCtrlData setup
+ - thermal: bcm2835: Stop using printk format %pCr
+ - clk: renesas: cpg-mssr: Stop using printk format %pCr
+ - lib/vsprintf: Remove atomic-unsafe support for %pCr
+ - ftrace/selftest: Have the reset_trigger code be a bit more careful
+ - mips: ftrace: fix static function graph tracing
+ - branch-check: fix long->int truncation when profiling branches
+ - ipmi:bt: Set the timeout before doing a capabilities check
+ - Bluetooth: hci_qca: Avoid missing rampatch failure with userspace fw loader
+ - printk: fix possible reuse of va_list variable
+ - fuse: fix congested state leak on aborted connections
+ - fuse: atomic_o_trunc should truncate pagecache
+ - fuse: don't keep dead fuse_conn at fuse_fill_super().
+ - fuse: fix control dir setup and teardown
+ - powerpc/mm/hash: Add missing isync prior to kernel stack SLB switch
+ - powerpc/ptrace: Fix setting 512B aligned breakpoints with
+ PTRACE_SET_DEBUGREG
+ - powerpc/ptrace: Fix enforcement of DAWR constraints
+ - powerpc/powernv/ioda2: Remove redundant free of TCE pages
+ - powerpc/powernv: copy/paste - Mask SO bit in CR
+ - powerpc/fadump: Unregister fadump on kexec down path.
+ - soc: rockchip: power-domain: Fix wrong value when power up pd with writemask
+ - ARM: 8764/1: kgdb: fix NUMREGBYTES so that gdb_regs[] is the correct size
+ - ARM: dts: Fix SPI node for Arria10
+ - ARM: dts: socfpga: Fix NAND controller node compatible
+ - ARM: dts: socfpga: Fix NAND controller clock supply
+ - ARM: dts: socfpga: Fix NAND controller node compatible for Arria10
+ - arm64: Fix syscall restarting around signal suppressed by tracer
+ - arm64: kpti: Use early_param for kpti= command-line option
+ - arm64: mm: Ensure writes to swapper are ordered wrt subsequent cache
+ maintenance
+ - ARM64: dts: meson: disable sd-uhs modes on the libretech-cc
+ - of: overlay: validate offset from property fixups
+ - of: unittest: for strings, account for trailing \0 in property length field
+ - of: platform: stop accessing invalid dev in of_platform_device_destroy
+ - tpm: fix use after free in tpm2_load_context()
+ - tpm: fix race condition in tpm_common_write()
+ - IB/qib: Fix DMA api warning with debug kernel
+ - IB/{hfi1, qib}: Add handling of kernel restart
+ - IB/mlx4: Mark user MR as writable if actual virtual memory is writable
+ - IB/core: Make testing MR flags for writability a static inline function
+ - IB/mlx5: Fetch soft WQE's on fatal error state
+ - IB/isert: Fix for lib/dma_debug check_sync warning
+ - IB/isert: fix T10-pi check mask setting
+ - IB/hfi1: Fix fault injection init/exit issues
+ - IB/hfi1: Reorder incorrect send context disable
+ - IB/hfi1: Optimize kthread pointer locking when queuing CQ entries
+ - IB/hfi1: Fix user context tail allocation for DMA_RTAIL
+ - RDMA/mlx4: Discard unknown SQP work requests
+ - xprtrdma: Return -ENOBUFS when no pages are available
+ - mtd: cfi_cmdset_0002: Change write buffer to check correct value
+ - mtd: cfi_cmdset_0002: Use right chip in do_ppb_xxlock()
+ - mtd: cfi_cmdset_0002: fix SEGV unlocking multiple chips
+ - mtd: cfi_cmdset_0002: Fix unlocking requests crossing a chip boudary
+ - mtd: cfi_cmdset_0002: Avoid walking all chips when unlocking.
+ - PCI: hv: Make sure the bus domain is really unique
+ - PCI: Add ACS quirk for Intel 7th & 8th Gen mobile
+ - PCI: pciehp: Clear Presence Detect and Data Link Layer Status Changed on
+ resume
+ - auxdisplay: fix broken menu
+ - pinctrl: samsung: Correct EINTG banks order
+ - pinctrl: devicetree: Fix pctldev pointer overwrite
+ - cpufreq: intel_pstate: Fix scaling max/min limits with Turbo 3.0
+ - MIPS: io: Add barrier after register read in inX()
+ - time: Make sure jiffies_to_msecs() preserves non-zero time periods
+ - irqchip/gic-v3-its: Don't bind LPI to unavailable NUMA node
+ - X.509: unpack RSA signatureValue field from BIT STRING
+ - Btrfs: fix return value on rename exchange failure
+ - iio: adc: ad7791: remove sample freq sysfs attributes
+ - iio: sca3000: Fix an error handling path in 'sca3000_probe()'
+ - mm: fix __gup_device_huge vs unmap
+ - scsi: qla2xxx: Fix setting lower transfer speed if GPSC fails
+ - scsi: qla2xxx: Mask off Scope bits in retry delay
+ - scsi: zfcp: fix missing SCSI trace for result of eh_host_reset_handler
+ - scsi: zfcp: fix missing SCSI trace for retry of abort / scsi_eh TMF
+ - scsi: zfcp: fix misleading REC trigger trace where erp_action setup failed
+ - scsi: zfcp: fix missing REC trigger trace on terminate_rport_io early return
+ - scsi: zfcp: fix missing REC trigger trace on terminate_rport_io for
+ ERP_FAILED
+ - scsi: zfcp: fix missing REC trigger trace for all objects in ERP_FAILED
+ - scsi: zfcp: fix missing REC trigger trace on enqueue without ERP thread
+ - linvdimm, pmem: Preserve read-only setting for pmem devices
+ - clk: at91: PLL recalc_rate() now using cached MUL and DIV values
+ - rtc: sun6i: Fix bit_idx value for clk_register_gate
+ - md: fix two problems with setting the "re-add" device state.
+ - rpmsg: smd: do not use mananged resources for endpoints and channels
+ - ubi: fastmap: Cancel work upon detach
+ - ubi: fastmap: Correctly handle interrupted erasures in EBA
+ - backlight: as3711_bl: Fix Device Tree node lookup
+ - backlight: max8925_bl: Fix Device Tree node lookup
+ - backlight: tps65217_bl: Fix Device Tree node lookup
+ - mfd: intel-lpss: Program REMAP register in PIO mode
+ - arm: dts: mt7623: fix invalid memory node being generated
+ - perf tools: Fix symbol and object code resolution for vdso32 and vdsox32
+ - perf intel-pt: Fix sync_switch INTEL_PT_SS_NOT_TRACING
+ - perf intel-pt: Fix decoding to accept CBR between FUP and corresponding TIP
+ - perf intel-pt: Fix MTC timing after overflow
+ - perf intel-pt: Fix "Unexpected indirect branch" error
+ - perf intel-pt: Fix packet decoding of CYC packets
+ - media: vsp1: Release buffers for each video node
+ - media: v4l2-compat-ioctl32: prevent go past max size
+ - media: dvb_frontend: fix locking issues at dvb_frontend_get_event()
+ - nfsd: restrict rd_maxcount to svc_max_payload in nfsd_encode_readdir
+ - NFSv4: Fix possible 1-byte stack overflow in
+ nfs_idmap_read_and_verify_message
+ - NFSv4: Revert commit 5f83d86cf531d ("NFSv4.x: Fix wraparound issues..")
+ - NFSv4: Fix a typo in nfs41_sequence_process
+ - ACPI / LPSS: Add missing prv_offset setting for byt/cht PWM devices
+ - Input: elan_i2c - add ELAN0618 (Lenovo v330 15IKB) ACPI ID
+ - pwm: lpss: platform: Save/restore the ctrl register over a suspend/resume
+ - rbd: flush rbd_dev->watch_dwork after watch is unregistered
+ - mm/ksm.c: ignore STABLE_FLAG of rmap_item->address in rmap_walk_ksm()
+ - mm: fix devmem_is_allowed() for sub-page System RAM intersections
+ - xen: Remove unnecessary BUG_ON from __unbind_from_irq()
+ - udf: Detect incorrect directory size
+ - Input: xpad - fix GPD Win 2 controller name
+ - Input: elan_i2c_smbus - fix more potential stack buffer overflows
+ - ALSA: timer: Fix UBSAN warning at SNDRV_TIMER_IOCTL_NEXT_DEVICE ioctl
+ - ALSA: hda/realtek - Fix pop noise on Lenovo P50 & co
+ - ALSA: hda/realtek - Add a quirk for FSC ESPRIMO U9210
+ - slub: fix failure when we delete and create a slab cache
+ - block: Fix transfer when chunk sectors exceeds max
+ - block: Fix cloning of requests with a special payload
+ - x86/efi: Fix efi_call_phys_epilog() with CONFIG_X86_5LEVEL=y
+ - dm zoned: avoid triggering reclaim from inside dmz_map()
+ - dm thin: handle running out of data space vs concurrent discard
+ - x86/platform/UV: Use new set memory block size function
+ - x86/platform/UV: Add kernel parameter to set memory block size
+ - platform/chrome: cros_ec_lpc: Register the driver if ACPI entry is missing.
+ - platform/chrome: cros_ec_lpc: do not try DMI match when ACPI device found
+ - hwmon: (k10temp) Add support for Stoney Ridge and Bristol Ridge CPUs
+ - spi-nor: intel-spi: Remove unused preopcodes field
+ - mtd: spi-nor: intel-spi: Fix atomic sequence handling
+ - PCI / PM: Do not clear state_saved for devices that remain suspended
+ - ASoC: mediatek: preallocate pages use platform device
+ - libnvdimm, pmem: Do not flush power-fail protected CPU caches
+ - powerpc/64s: Set assembler machine type to POWER4
+ - powerpc/e500mc: Set assembler machine type to e500mc
+ - hwrng: core - Always drop the RNG in hwrng_unregister()
+ - softirq: Reorder trace_softirqs_on to prevent lockdep splat
+ - ARM64: dts: meson-gx: fix ATF reserved memory region
+ - mtd: rawnand: fix return value check for bad block status
+ - mtd: rawnand: mxc: set spare area size register explicitly
+ - PCI: Account for all bridges on bus when distributing bus numbers
+ - pinctrl: armada-37xx: Fix spurious irq management
+ - MIPS: pb44: Fix i2c-gpio GPIO descriptor table
+ - locking/rwsem: Fix up_read_non_owner() warning with DEBUG_RWSEMS
+ - scsi: scsi_debug: Fix memory leak on module unload
+ - scsi: qla2xxx: Spinlock recursion in qla_target
+ - libnvdimm, pmem: Unconditionally deep flush on *sync
+ - f2fs: don't use GFP_ZERO for page caches
+ - mfd: twl-core: Fix clock initialization
+ - remoteproc: Prevent incorrect rproc state on xfer mem ownership failure
+ - media: rc: mce_kbd decoder: fix stuck keys
+ - Input: silead - add Chuwi Hi8 support
+ - Input: silead - add MSSL0002 ACPI HID
+ - ALSA: hda - Force to link down at runtime suspend on ATI/AMD HDMI
+ - i2c: gpio: initialize SCL to HIGH again
+ - kasan: depend on CONFIG_SLUB_DEBUG
+ - dm: ensure bio submission follows a depth-first tree walk
+ - dm: rename 'bio' member of dm_io structure to 'orig_bio'
+ - dm: use bio_split() when splitting out the already processed bio
+ - x86/e820: put !E820_TYPE_RAM regions into memblock.reserved
+
+ * Support AverMedia DVD EZMaker 7 USB video capture dongle (LP: #1620762) //
+ Bionic update: upstream stable patchset 2018-12-07 (LP: #1807469)
+ - media: cx231xx: Add support for AverMedia DVD EZMaker 7
+
+ -- Kleber Sacilotto de Souza <kleber.souza@canonical.com> Mon, 14 Jan 2019 09:38:05 +0000
+
+linux (4.15.0-43.46) bionic; urgency=medium
+
+ * linux: 4.15.0-43.46 -proposed tracker (LP: #1806659)
+
+ * System randomly hangs during suspend when mei_wdt is loaded (LP: #1803942)
+ - SAUCE: base/dd: limit release function changes to vfio driver only
+
+ * Workaround CSS timeout on AMD SNPS 3.0 xHC (LP: #1806838)
+ - xhci: Allow more than 32 quirks
+ - xhci: workaround CSS timeout on AMD SNPS 3.0 xHC
+
+ * linux-buildinfo: pull out ABI information into its own package
+ (LP: #1806380)
+ - [Packaging] limit preparation to linux-libc-dev in headers
+ - [Packaging] commonise debhelper invocation
+ - [Packaging] ABI -- accumulate abi information at the end of the build
+ - [Packaging] buildinfo -- add basic build information
+ - [Packaging] buildinfo -- add firmware information to the flavour ABI
+ - [Packaging] buildinfo -- add compiler information to the flavour ABI
+ - [Packaging] buildinfo -- add buildinfo support to getabis
+ - [Config] buildinfo -- add retpoline version markers
+
+ * linux packages should own /usr/lib/linux/triggers (LP: #1770256)
+ - [Packaging] own /usr/lib/linux/triggers
+
+ * CVE-2018-12896
+ - posix-timers: Sanitize overrun handling
+
+ * CVE-2018-16276
+ - USB: yurex: fix out-of-bounds uaccess in read handler
+
+ * CVE-2018-10902
+ - ALSA: rawmidi: Change resized buffers atomically
+
+ * CVE-2018-18710
+ - cdrom: fix improper type cast, which can leat to information leak.
+
+ * CVE-2018-18690
+ - xfs: don't fail when converting shortform attr to long form during
+ ATTR_REPLACE
+
+ * CVE-2018-14734
+ - infiniband: fix a possible use-after-free bug
+
+ * CVE-2018-18445
+ - bpf: 32-bit RSH verification must truncate input before the ALU op
+
+ * Packaging resync (LP: #1786013)
+ - [Packaging] update helper scripts
+
+ -- Kleber Sacilotto de Souza <kleber.souza@canonical.com> Thu, 06 Dec 2018 13:52:12 +0000
+
+linux (4.15.0-42.45) bionic; urgency=medium
+
+ * linux: 4.15.0-42.45 -proposed tracker (LP: #1803592)
+
+ * [FEAT] Guest-dedicated Crypto Adapters (LP: #1787405)
+ - KVM: s390: reset crypto attributes for all vcpus
+ - KVM: s390: vsie: simulate VCPU SIE entry/exit
+ - KVM: s390: introduce and use KVM_REQ_VSIE_RESTART
+ - KVM: s390: refactor crypto initialization
+ - s390: vfio-ap: base implementation of VFIO AP device driver
+ - s390: vfio-ap: register matrix device with VFIO mdev framework
+ - s390: vfio-ap: sysfs interfaces to configure adapters
+ - s390: vfio-ap: sysfs interfaces to configure domains
+ - s390: vfio-ap: sysfs interfaces to configure control domains
+ - s390: vfio-ap: sysfs interface to view matrix mdev matrix
+ - KVM: s390: interface to clear CRYCB masks
+ - s390: vfio-ap: implement mediated device open callback
+ - s390: vfio-ap: implement VFIO_DEVICE_GET_INFO ioctl
+ - s390: vfio-ap: zeroize the AP queues
+ - s390: vfio-ap: implement VFIO_DEVICE_RESET ioctl
+ - KVM: s390: Clear Crypto Control Block when using vSIE
+ - KVM: s390: vsie: Do the CRYCB validation first
+ - KVM: s390: vsie: Make use of CRYCB FORMAT2 clear
+ - KVM: s390: vsie: Allow CRYCB FORMAT-2
+ - KVM: s390: vsie: allow CRYCB FORMAT-1
+ - KVM: s390: vsie: allow CRYCB FORMAT-0
+ - KVM: s390: vsie: allow guest FORMAT-0 CRYCB on host FORMAT-1
+ - KVM: s390: vsie: allow guest FORMAT-1 CRYCB on host FORMAT-2
+ - KVM: s390: vsie: allow guest FORMAT-0 CRYCB on host FORMAT-2
+ - KVM: s390: device attrs to enable/disable AP interpretation
+ - KVM: s390: CPU model support for AP virtualization
+ - s390: doc: detailed specifications for AP virtualization
+ - KVM: s390: fix locking for crypto setting error path
+ - KVM: s390: Tracing APCB changes
+ - s390: vfio-ap: setup APCB mask using KVM dedicated function
+ - s390/zcrypt: Add ZAPQ inline function.
+ - s390/zcrypt: Review inline assembler constraints.
+ - s390/zcrypt: Integrate ap_asm.h into include/asm/ap.h.
+ - s390/zcrypt: fix ap_instructions_available() returncodes
+ - s390/zcrypt: remove VLA usage from the AP bus
+ - s390/zcrypt: Remove deprecated ioctls.
+ - s390/zcrypt: Remove deprecated zcrypt proc interface.
+ - s390/zcrypt: Support up to 256 crypto adapters.
+ - [Config:] Enable CONFIG_S390_AP_IOMMU and set CONFIG_VFIO_AP to module.
+
+ * Bypass of mount visibility through userns + mount propagation (LP: #1789161)
+ - mount: Retest MNT_LOCKED in do_umount
+ - mount: Don't allow copying MNT_UNBINDABLE|MNT_LOCKED mounts
+
+ * CVE-2018-18955: nested user namespaces with more than five extents
+ incorrectly grant privileges over inode (LP: #1801924) // CVE-2018-18955
+ - userns: also map extents in the reverse map to kernel IDs
+
+ * kdump fail due to an IRQ storm (LP: #1797990)
+ - SAUCE: x86/PCI: Export find_cap() to be used in early PCI code
+ - SAUCE: x86/quirks: Add parameter to clear MSIs early on boot
+ - SAUCE: x86/quirks: Scan all busses for early PCI quirks
+
+ -- Thadeu Lima de Souza Cascardo <cascardo@canonical.com> Thu, 15 Nov 2018 17:01:46 -0200
+
+linux (4.15.0-40.43) bionic; urgency=medium
+
+ * linux: 4.15.0-40.43 -proposed tracker (LP: #1802554)
+
+ * crash in ENA driver on removing an interface (LP: #1802341)
+ - SAUCE: net: ena: fix crash during ena_remove()
+
+ * Ubuntu 18.04.1 - [s390x] Kernel panic while stressing network bonding
+ (LP: #1797367)
+ - s390/qeth: don't keep track of MAC address's cast type
+ - s390/qeth: consolidate qeth MAC address helpers
+ - s390/qeth: avoid using is_multicast_ether_addr_64bits on (u8 *)[6]
+ - s390/qeth: remove outdated portname debug msg
+ - s390/qeth: reduce hard-coded access to ccw channels
+ - s390/qeth: sanitize strings in debug messages
+
+ * [18.04 FEAT] zcrypt DD: introduce APQN tags to support deterministic driver
+ binding (LP: #1799184)
+ - s390/zcrypt: code beautify
+ - s390/zcrypt: AP bus support for alternate driver(s)
+ - s390/zcrypt: hex string mask improvements for apmask and aqmask.
+ - s390/zcrypt: remove unused functions and declarations
+ - s390/zcrypt: Show load of cards and queues in sysfs
+
+ * [GLK/CLX] Enhanced IBRS (LP: #1786139)
+ - x86/speculation: Remove SPECTRE_V2_IBRS in enum spectre_v2_mitigation
+ - x86/speculation: Support Enhanced IBRS on future CPUs
+
+ * Allow signed kernels to be kexec'ed under lockdown (LP: #1798441)
+ - Fix kexec forbidding kernels signed with keys in the secondary keyring to
+ boot
+
+ * Overlayfs in user namespace leaks directory content of inaccessible
+ directories (LP: #1793458) // CVE-2018-6559
+ - SAUCE: overlayfs: ensure mounter privileges when reading directories
+
+ * Update ENA driver to version 2.0.1K (LP: #1798182)
+ - net: ena: remove ndo_poll_controller
+ - net: ena: fix warning in rmmod caused by double iounmap
+ - net: ena: fix rare bug when failed restart/resume is followed by driver
+ removal
+ - net: ena: fix NULL dereference due to untimely napi initialization
+ - net: ena: fix auto casting to boolean
+ - net: ena: minor performance improvement
+ - net: ena: complete host info to match latest ENA spec
+ - net: ena: introduce Low Latency Queues data structures according to ENA spec
+ - net: ena: add functions for handling Low Latency Queues in ena_com
+ - net: ena: add functions for handling Low Latency Queues in ena_netdev
+ - net: ena: use CSUM_CHECKED device indication to report skb's checksum status
+ - net: ena: explicit casting and initialization, and clearer error handling
+ - net: ena: limit refill Rx threshold to 256 to avoid latency issues
+ - net: ena: change rx copybreak default to reduce kernel memory pressure
+ - net: ena: remove redundant parameter in ena_com_admin_init()
+ - net: ena: update driver version to 2.0.1
+ - net: ena: fix indentations in ena_defs for better readability
+ - net: ena: Fix Kconfig dependency on X86
+ - net: ena: enable Low Latency Queues
+ - net: ena: fix compilation error in xtensa architecture
+
+ * Bionic update: upstream stable patchset 2018-10-29 (LP: #1800537)
+ - bonding: re-evaluate force_primary when the primary slave name changes
+ - cdc_ncm: avoid padding beyond end of skb
+ - ipv6: allow PMTU exceptions to local routes
+ - net: dsa: add error handling for pskb_trim_rcsum
+ - net/sched: act_simple: fix parsing of TCA_DEF_DATA
+ - tcp: verify the checksum of the first data segment in a new connection
+ - udp: fix rx queue len reported by diag and proc interface
+ - net: in virtio_net_hdr only add VLAN_HLEN to csum_start if payload holds
+ vlan
+ - tls: fix use-after-free in tls_push_record
+ - ext4: fix hole length detection in ext4_ind_map_blocks()
+ - ext4: update mtime in ext4_punch_hole even if no blocks are released
+ - ext4: bubble errors from ext4_find_inline_data_nolock() up to ext4_iget()
+ - ext4: fix fencepost error in check for inode count overflow during resize
+ - driver core: Don't ignore class_dir_create_and_add() failure.
+ - Btrfs: fix clone vs chattr NODATASUM race
+ - Btrfs: fix memory and mount leak in btrfs_ioctl_rm_dev_v2()
+ - btrfs: return error value if create_io_em failed in cow_file_range
+ - btrfs: scrub: Don't use inode pages for device replace
+ - ALSA: hda/conexant - Add fixup for HP Z2 G4 workstation
+ - ALSA: hda - Handle kzalloc() failure in snd_hda_attach_pcm_stream()
+ - ALSA: hda: add dock and led support for HP EliteBook 830 G5
+ - ALSA: hda: add dock and led support for HP ProBook 640 G4
+ - x86/MCE: Fix stack out-of-bounds write in mce-inject.c: Flags_read()
+ - smb3: fix various xid leaks
+ - CIFS: 511c54a2f69195b28afb9dd119f03787b1625bb4 adds a check for session
+ expiry
+ - cifs: For SMB2 security informaion query, check for minimum sized security
+ descriptor instead of sizeof FileAllInformation class
+ - nbd: fix nbd device deletion
+ - nbd: update size when connected
+ - nbd: use bd_set_size when updating disk size
+ - blk-mq: reinit q->tag_set_list entry only after grace period
+ - bdi: Move cgroup bdi_writeback to a dedicated low concurrency workqueue
+ - cpufreq: Fix new policy initialization during limits updates via sysfs
+ - cpufreq: governors: Fix long idle detection logic in load calculation
+ - libata: zpodd: small read overflow in eject_tray()
+ - libata: Drop SanDisk SD7UB3Q*G1001 NOLPM quirk
+ - w1: mxc_w1: Enable clock before calling clk_get_rate() on it
+ - x86/intel_rdt: Enable CMT and MBM on new Skylake stepping
+ - iwlwifi: fw: harden page loading code
+ - orangefs: set i_size on new symlink
+ - orangefs: report attributes_mask and attributes for statx
+ - HID: intel_ish-hid: ipc: register more pm callbacks to support hibernation
+ - HID: wacom: Correct logical maximum Y for 2nd-gen Intuos Pro large
+ - mm, page_alloc: do not break __GFP_THISNODE by zonelist reset
+ - net: phy: dp83822: use BMCR_ANENABLE instead of BMSR_ANEGCAPABLE for DP83620
+ - cpufreq: ti-cpufreq: Fix an incorrect error return value
+ - x86/vector: Fix the args of vector_alloc tracepoint
+ - x86/apic/vector: Prevent hlist corruption and leaks
+ - x86/apic: Provide apic_ack_irq()
+ - x86/ioapic: Use apic_ack_irq()
+ - x86/platform/uv: Use apic_ack_irq()
+ - irq_remapping: Use apic_ack_irq()
+ - genirq/generic_pending: Do not lose pending affinity update
+ - genirq/affinity: Defer affinity setting if irq chip is busy
+ - genirq/migration: Avoid out of line call if pending is not set
+
+ * [bionic]mlx5: reading SW stats through ifstat cause kernel crash
+ (LP: #1799049)
+ - net/mlx5e: Don't attempt to dereference the ppriv struct if not being
+ eswitch manager
+
+ * [Bionic][Cosmic] ipmi: Fix timer race with module unload (LP: #1799281)
+ - ipmi: Fix timer race with module unload
+
+ * [Bionic] ipmi: Remove ACPI SPMI probing from the SSIF (I2C) driver
+ (LP: #1799276)
+ - ipmi: Remove ACPI SPMI probing from the SSIF (I2C) driver
+
+ * execveat03 in ubuntu_ltp_syscalls failed on X/B (LP: #1786729)
+ - cap_inode_getsecurity: use d_find_any_alias() instead of d_find_alias()
+
+ * [Bionic][Cosmic] Fix to ipmi to support vendor specific messages greater
+ than 255 bytes (LP: #1799794)
+ - ipmi:ssif: Add support for multi-part transmit messages > 2 parts
+
+ * libvirtd is unable to configure bridge devices inside of LXD containers
+ (LP: #1784501)
+ - kernfs: allow creating kernfs objects with arbitrary uid/gid
+ - sysfs, kobject: allow creating kobject belonging to arbitrary users
+ - kobject: kset_create_and_add() - fetch ownership info from parent
+ - driver core: set up ownership of class devices in sysfs
+ - net-sysfs: require net admin in the init ns for setting tx_maxrate
+ - net-sysfs: make sure objects belong to container's owner
+ - net: create reusable function for getting ownership info of sysfs inodes
+ - bridge: make sure objects belong to container's owner
+ - sysfs: Fix regression when adding a file to an existing group
+
+ * [Ubuntu] kvm: fix deadlock when killed by oom (LP: #1800849)
+ - s390/kvm: fix deadlock when killed by oom
+
+ * [Ubuntu] net/af_iucv: fix skb leaks for HiperTransport (LP: #1800639)
+ - net/af_iucv: drop inbound packets with invalid flags
+ - net/af_iucv: fix skb handling on HiperTransport xmit error
+
+ * Power consumption during s2idle is higher than long idle(sk hynix)
+ (LP: #1801875)
+ - SAUCE: pci: prevent sk hynix nvme from entering D3
+ - SAUCE: nvme: add quirk to not call disable function when suspending
+
+ * Enable keyboard wakeup for S2Idle laptops (LP: #1798552)
+ - Input: i8042 - enable keyboard wakeups by default when s2idle is used
+
+ * NULL pointer dereference at 0000000000000020 when access
+ dst_orig->ops->family in function xfrm_lookup_with_ifid() (LP: #1801878)
+ - xfrm: Fix NULL pointer dereference when skb_dst_force clears the dst_entry.
+
+ * [Ubuntu] qdio: reset old sbal_state flags (LP: #1801686)
+ - s390/qdio: reset old sbal_state flags
+
+ * hns3: map tx ring to tc (LP: #1802023)
+ - net: hns3: Set tx ring' tc info when netdev is up
+
+ * [Ubuntu] qeth: Fix potential array overrun in cmd/rc lookup (LP: #1800641)
+ - s390: qeth_core_mpc: Use ARRAY_SIZE instead of reimplementing its function
+ - s390: qeth: Fix potential array overrun in cmd/rc lookup
+
+ * Vulkan applications cause permanent memory leak with Intel GPU
+ (LP: #1798165)
+ - drm/syncobj: Don't leak fences when WAIT_FOR_SUBMIT is set
+
+ * Mounting SOFS SMB shares fails (LP: #1792580)
+ - cifs: connect to servername instead of IP for IPC$ share
+
+ * Packaging resync (LP: #1786013)
+ - [Package] add support for specifying the primary makefile
+
+ -- Thadeu Lima de Souza Cascardo <cascardo@canonical.com> Fri, 09 Nov 2018 17:29:18 -0200
+
+linux (4.15.0-39.42) bionic; urgency=medium
+
+ * linux: 4.15.0-39.42 -proposed tracker (LP: #1799411)
+
+ * Linux: insufficient shootdown for paging-structure caches (LP: #1798897)
+ - mm: move tlb_table_flush to tlb_flush_mmu_free
+ - mm/tlb: Remove tlb_remove_table() non-concurrent condition
+ - mm/tlb, x86/mm: Support invalidating TLB caches for RCU_TABLE_FREE
+ - [Config] CONFIG_HAVE_RCU_TABLE_INVALIDATE=y
+
+ * Ubuntu18.04: GPU total memory is reduced (LP: #1792102)
+ - Revert "powerpc/powernv: Increase memory block size to 1GB on radix"
+
+ * arm64: snapdragon: reduce boot noise (LP: #1797154)
+ - [Config] arm64: snapdragon: DRM_MSM=m
+ - [Config] arm64: snapdragon: SND*=m
+ - [Config] arm64: snapdragon: disable ARM_SDE_INTERFACE
+ - [Config] arm64: snapdragon: disable DRM_I2C_ADV7511_CEC
+ - [Config] arm64: snapdragon: disable VIDEO_ADV7511, VIDEO_COBALT
+
+ * [Bionic] CPPC bug fixes (LP: #1796949)
+ - ACPI / CPPC: Update all pr_(debug/err) messages to log the susbspace id
+ - cpufreq: CPPC: Don't set transition_latency
+ - ACPI / CPPC: Fix invalid PCC channel status errors
+
+ * regression in 'ip --family bridge neigh' since linux v4.12 (LP: #1796748)
+ - rtnetlink: fix rtnl_fdb_dump() for ndmsg header
+
+ * screen displays abnormally on the lenovo M715 with the AMD GPU (Radeon Vega
+ 8 Mobile, rev ca, 1002:15dd) (LP: #1796786)
+ - drm/amd/display: Fix takover from VGA mode
+ - drm/amd/display: early return if not in vga mode in disable_vga
+ - drm/amd/display: Refine disable VGA
+
+ * arm64: snapdragon: WARNING: CPU: 0 PID: 1 arch/arm64/kernel/setup.c:271
+ reserve_memblock_reserved_regions (LP: #1797139)
+ - SAUCE: arm64: Fix /proc/iomem for reserved but not memory regions
+
+ * The front MIC can't work on the Lenovo M715 (LP: #1797292)
+ - ALSA: hda/realtek - Fix the problem of the front MIC on the Lenovo M715
+
+ * Keyboard backlight sysfs sometimes is missing on Dell laptops (LP: #1797304)
+ - platform/x86: dell-smbios: Correct some style warnings
+ - platform/x86: dell-smbios: Rename dell-smbios source to dell-smbios-base
+ - platform/x86: dell-smbios: Link all dell-smbios-* modules together
+ - [Config] CONFIG_DELL_SMBIOS_SMM=y, CONFIG_DELL_SMBIOS_WMI=y
+
+ * rpi3b+: ethernet not working (LP: #1797406)
+ - lan78xx: Don't reset the interface on open
+
+ * 87cdf3148b11 was never backported to 4.15 (LP: #1795653)
+ - xfrm: Verify MAC header exists before overwriting eth_hdr(skb)->h_proto
+
+ * [Ubuntu18.04][Power9][DD2.2]package installation segfaults inside debian
+ chroot env in P9 KVM guest with HTM enabled (kvm) (LP: #1792501)
+ - KVM: PPC: Book3S HV: Fix guest r11 corruption with POWER9 TM workarounds
+
+ * Provide mode where all vCPUs on a core must be the same VM (LP: #1792957)
+ - KVM: PPC: Book3S HV: Provide mode where all vCPUs on a core must be the same
+ VM
+
+ * fscache: bad refcounting in fscache_op_complete leads to OOPS (LP: #1797314)
+ - SAUCE: fscache: Fix race in decrementing refcount of op->npages
+
+ * CVE-2018-9363
+ - Bluetooth: hidp: buffer overflow in hidp_process_report
+
+ * CVE-2017-13168
+ - scsi: sg: mitigate read/write abuse
+
+ * [Bionic] ACPI / PPTT: use ACPI ID whenever ACPI_PPTT_ACPI_PROCESSOR_ID_VALID
+ is set (LP: #1797200)
+ - ACPI / PPTT: use ACPI ID whenever ACPI_PPTT_ACPI_PROCESSOR_ID_VALID is set
+
+ * [Bionic] arm64: topology: Avoid checking numa mask for scheduler MC
+ selection (LP: #1797202)
+ - arm64: topology: Avoid checking numa mask for scheduler MC selection
+
+ * crypto/vmx - Backport of Fix sleep-in-atomic bugs patch for 18.04
+ (LP: #1790832)
+ - crypto: vmx - Fix sleep-in-atomic bugs
+
+ * hns3: autoneg settings get lost on down/up (LP: #1797654)
+ - net: hns3: Fix for information of phydev lost problem when down/up
+
+ * not able to unwind the stack from within __kernel_clock_gettime in the Linux
+ vDSO (LP: #1797963)
+ - powerpc/vdso: Correct call frame information
+
+ * Signal 7 error when running GPFS tracing in cluster (LP: #1792195)
+ - powerpc/mm/books3s: Add new pte bit to mark pte temporarily invalid.
+ - powerpc/mm/radix: Only need the Nest MMU workaround for R -> RW transition
+
+ * Support Edge Gateway's WIFI LED (LP: #1798330)
+ - SAUCE: mwifiex: Switch WiFi LED state according to the device status
+
+ * Support Edge Gateway's Bluetooth LED (LP: #1798332)
+ - SAUCE: Bluetooth: Support for LED on Edge Gateways
+
+ * USB cardreader (0bda:0328) make the system can't enter s3 or hang
+ (LP: #1798328)
+ - usb: Don't disable Latency tolerance Messaging (LTM) before port reset
+
+ * CVE-2018-15471
+ - xen-netback: fix input validation in xenvif_set_hash_mapping()
+
+ * CVE-2018-16658
+ - cdrom: Fix info leak/OOB read in cdrom_ioctl_drive_status
+
+ * [Bionic] Update ThunderX2 implementation defined pmu core events
+ (LP: #1796904)
+ - perf vendor events arm64: Update ThunderX2 implementation defined pmu core
+ events
+
+ * the machine of lenovo M715 with the AMD GPU (Radeon Vega 8 Mobile, rev ca,
+ 1002:15dd) often hangs randomly (LP: #1796789)
+ - drm/amd: Add missing fields in atom_integrated_system_info_v1_11
+
+ * [18.04] GLK hang after a while (LP: #1760545)
+ - drm/i915/glk: Add MODULE_FIRMWARE for Geminilake
+
+ * Fix usbcore.quirks when used at boot (LP: #1795784)
+ - usb: core: safely deal with the dynamic quirk lists
+
+ -- Kleber Sacilotto de Souza <kleber.souza@canonical.com> Tue, 23 Oct 2018 14:44:55 +0000
+
+linux (4.15.0-38.41) bionic; urgency=medium
+
+ * linux: 4.15.0-38.41 -proposed tracker (LP: #1797061)
+
+ * Silent data corruption in Linux kernel 4.15 (LP: #1796542)
+ - block: add a lower-level bio_add_page interface
+ - block: bio_iov_iter_get_pages: fix size of last iovec
+ - blkdev: __blkdev_direct_IO_simple: fix leak in error case
+ - block: bio_iov_iter_get_pages: pin more pages for multi-segment IOs
+
+ -- Stefan Bader <stefan.bader@canonical.com> Wed, 10 Oct 2018 11:20:35 +0200
+
+linux (4.15.0-37.40) bionic; urgency=medium
+
+ * linux: 4.15.0-37.40 -proposed tracker (LP: #1795564)
+
+ * hns3: enable ethtool rx-vlan-filter on supported hw (LP: #1793394)
+ - net: hns3: Add vlan filter setting by ethtool command -K
+
+ * hns3: Modifying channel parameters will reset ring parameters back to
+ defaults (LP: #1793404)
+ - net: hns3: Fix desc num set to default when setting channel
+
+ * hisi_sas: Add SATA FIX check for v3 hw (LP: #1794151)
+ - scsi: hisi_sas: Add SATA FIS check for v3 hw
+
+ * Fix potential corruption using SAS controller on HiSilicon arm64 boards
+ (LP: #1794156)
+ - scsi: hisi_sas: add memory barrier in task delivery function
+
+ * hisi_sas: Reduce unnecessary spin lock contention (LP: #1794165)
+ - scsi: hisi_sas: Tidy hisi_sas_task_prep()
+
+ * Add functional level reset support for the SAS controller on HiSilicon D06
+ systems (LP: #1794166)
+ - scsi: hisi_sas: tidy host controller reset function a bit
+ - scsi: hisi_sas: relocate some common code for v3 hw
+ - scsi: hisi_sas: Implement handlers of PCIe FLR for v3 hw
+
+ * HiSilicon SAS controller doesn't recover from PHY STP link timeout
+ (LP: #1794172)
+ - scsi: hisi_sas: tidy channel interrupt handler for v3 hw
+ - scsi: hisi_sas: Fix the failure of recovering PHY from STP link timeout
+
+ * getxattr: always handle namespaced attributes (LP: #1789746)
+ - getxattr: use correct xattr length
+
+ * Fix unusable NVIDIA GPU after S3 (LP: #1793338)
+ - PCI: Reprogram bridge prefetch registers on resume
+
+ * Fails to boot under Xen PV: BUG: unable to handle kernel paging request at
+ edc21fd9 (LP: #1789118)
+ - x86/EISA: Don't probe EISA bus for Xen PV guests
+
+ * qeth: use vzalloc for QUERY OAT buffer (LP: #1793086)
+ - s390/qeth: use vzalloc for QUERY OAT buffer
+
+ * SRU: Enable middle button of touchpad on ThinkPad P72 (LP: #1793463)
+ - Input: elantech - enable middle button of touchpad on ThinkPad P72
+
+ * Dell new AIO requires a new uart backlight driver (LP: #1727235)
+ - SAUCE: platform/x86: dell-uart-backlight: new backlight driver for DELL AIO
+ - updateconfigs for Dell UART backlight driver
+
+ * [Ubuntu] s390/crypto: Fix return code checking in cbc_paes_crypt.
+ (LP: #1794294)
+ - s390/crypto: Fix return code checking in cbc_paes_crypt()
+
+ * hns3: Retrieve RoCE MSI-X config from firmware (LP: #1793221)
+ - net: hns3: Fix MSIX allocation issue for VF
+ - net: hns3: Refine the MSIX allocation for PF
+
+ * net: hns: Avoid hang when link is changed while handling packets
+ (LP: #1792209)
+ - net: hns: add the code for cleaning pkt in chip
+ - net: hns: add netif_carrier_off before change speed and duplex
+
+ * Page leaking in cachefiles_read_backing_file while vmscan is active
+ (LP: #1793430)
+ - SAUCE: cachefiles: Page leaking in cachefiles_read_backing_file while vmscan
+ is active
+
+ * some nvidia p1000 graphic cards hang during the boot (LP: #1791569)
+ - drm/nouveau/gr/gf100-: virtualise tpc_mask + apply fixes from traces
+
+ * Error reported when creating ZFS pool with "-t" option, despite successful
+ pool creation (LP: #1769937)
+ - SAUCE: (noup) Update zfs to 0.7.5-1ubuntu16.4
+
+ * Fix I2C touchpanels' interrupt storms after system suspend (LP: #1792309)
+ - HID: i2c-hid: Fix flooded incomplete report after S3 on Rayd touchscreen
+ - HID: i2c-hid: Don't reset device upon system resume
+
+ * ipmmu is always registered (LP: #1783746)
+ - iommu/ipmmu-vmsa: Don't register as BUS IOMMU if machine doesn't have IPMMU-
+ VMSA
+
+ * Bionic update: upstream stable patchset 2018-09-27 (LP: #1794889)
+ - clocksource/drivers/imx-tpm: Correct some registers operation flow
+ - Input: synaptics-rmi4 - fix an unchecked out of memory error path
+ - KVM: X86: fix incorrect reference of trace_kvm_pi_irte_update
+ - x86: Add check for APIC access address for vmentry of L2 guests
+ - MIPS: io: Prevent compiler reordering writeX()
+ - nfp: ignore signals when communicating with management FW
+ - perf report: Fix switching to another perf.data file
+ - fsnotify: fix ignore mask logic in send_to_group()
+ - MIPS: io: Add barrier after register read in readX()
+ - s390/smsgiucv: disable SMSG on module unload
+ - isofs: fix potential memory leak in mount option parsing
+ - MIPS: dts: Boston: Fix PCI bus dtc warnings:
+ - spi: sh-msiof: Fix bit field overflow writes to TSCR/RSCR
+ - doc: Add vendor prefix for Kieback & Peter GmbH
+ - dt-bindings: pinctrl: sunxi: Fix reference to driver
+ - dt-bindings: serial: sh-sci: Add support for r8a77965 (H)SCIF
+ - dt-bindings: dmaengine: rcar-dmac: document R8A77965 support
+ - clk: honor CLK_MUX_ROUND_CLOSEST in generic clk mux
+ - ASoC: rt5514: Add the missing register in the readable table
+ - eCryptfs: don't pass up plaintext names when using filename encryption
+ - soc: bcm: raspberrypi-power: Fix use of __packed
+ - soc: bcm2835: Make !RASPBERRYPI_FIRMWARE dummies return failure
+ - PCI: kirin: Fix reset gpio name
+ - ASoC: topology: Fix bugs of freeing soc topology
+ - xen: xenbus_dev_frontend: Really return response string
+ - ASoC: topology: Check widget kcontrols before deref.
+ - spi: cadence: Add usleep_range() for cdns_spi_fill_tx_fifo()
+ - blkcg: don't hold blkcg lock when deactivating policy
+ - tipc: fix infinite loop when dumping link monitor summary
+ - scsi: iscsi: respond to netlink with unicast when appropriate
+ - scsi: megaraid_sas: Do not log an error if FW successfully initializes.
+ - scsi: target: fix crash with iscsi target and dvd
+ - netfilter: nf_tables: NAT chain and extensions require NF_TABLES
+ - netfilter: nf_tables: fix out-of-bounds in nft_chain_commit_update
+ - ASoC: msm8916-wcd-analog: use threaded context for mbhc events
+ - drm/msm: Fix possible null dereference on failure of get_pages()
+ - drm/msm/dsi: use correct enum in dsi_get_cmd_fmt
+ - drm/msm: don't deref error pointer in the msm_fbdev_create error path
+ - blkcg: init root blkcg_gq under lock
+ - vfs: Undo an overly zealous MS_RDONLY -> SB_RDONLY conversion
+ - parisc: time: Convert read_persistent_clock() to read_persistent_clock64()
+ - scsi: storvsc: Set up correct queue depth values for IDE devices
+ - scsi: isci: Fix infinite loop in while loop
+ - mm, pagemap: fix swap offset value for PMD migration entry
+ - proc: revalidate kernel thread inodes to root:root
+ - kexec_file: do not add extra alignment to efi memmap
+ - mm: memcg: add __GFP_NOWARN in __memcg_schedule_kmem_cache_create()
+ - usb: typec: ucsi: fix tracepoint related build error
+ - ACPI / PM: Blacklist Low Power S0 Idle _DSM for ThinkPad X1 Tablet(2016)
+ - dt-bindings: meson-uart: DT fix s/clocks-names/clock-names/
+ - net: phy: marvell: clear wol event before setting it
+ - ARM: dts: da850: fix W=1 warnings with pinmux node
+ - ACPI / watchdog: Prefer iTCO_wdt on Lenovo Z50-70
+ - drm/amdkfd: fix clock counter retrieval for node without GPU
+ - thermal: int3403_thermal: Fix NULL pointer deref on module load / probe
+ - net: ethtool: Add missing kernel doc for FEC parameters
+ - arm64: ptrace: remove addr_limit manipulation
+ - HID: lenovo: Add support for IBM/Lenovo Scrollpoint mice
+ - HID: wacom: Release device resource data obtained by devres_alloc()
+ - selftests: ftrace: Add a testcase for multiple actions on trigger
+ - rds: ib: Fix missing call to rds_ib_dev_put in rds_ib_setup_qp
+ - perf/x86/intel: Don't enable freeze-on-smi for PerfMon V1
+ - remoteproc: qcom: Fix potential device node leaks
+ - rpmsg: added MODULE_ALIAS for rpmsg_char
+ - HID: intel-ish-hid: use put_device() instead of kfree()
+ - blk-mq: fix sysfs inflight counter
+ - arm64: fix possible spectre-v1 in ptrace_hbp_get_event()
+ - KVM: arm/arm64: vgic: fix possible spectre-v1 in vgic_mmio_read_apr()
+ - libahci: Allow drivers to override stop_engine
+ - ata: ahci: mvebu: override ahci_stop_engine for mvebu AHCI
+ - x86/cpu/intel: Add missing TLB cpuid values
+ - bpf: fix uninitialized variable in bpf tools
+ - i2c: sprd: Prevent i2c accesses after suspend is called
+ - i2c: sprd: Fix the i2c count issue
+ - tipc: fix bug in function tipc_nl_node_dump_monitor
+ - nvme: depend on INFINIBAND_ADDR_TRANS
+ - nvmet-rdma: depend on INFINIBAND_ADDR_TRANS
+ - ib_srpt: depend on INFINIBAND_ADDR_TRANS
+ - ib_srp: depend on INFINIBAND_ADDR_TRANS
+ - IB: make INFINIBAND_ADDR_TRANS configurable
+ - IB/uverbs: Fix validating mandatory attributes
+ - RDMA/cma: Fix use after destroy access to net namespace for IPoIB
+ - RDMA/iwpm: fix memory leak on map_info
+ - IB/rxe: add RXE_START_MASK for rxe_opcode IB_OPCODE_RC_SEND_ONLY_INV
+ - IB/rxe: avoid double kfree_skb
+ - <linux/stringhash.h>: fix end_name_hash() for 64bit long
+ - IB/core: Make ib_mad_client_id atomic
+ - ARM: davinci: board-da830-evm: fix GPIO lookup for MMC/SD
+ - ARM: davinci: board-da850-evm: fix GPIO lookup for MMC/SD
+ - ARM: davinci: board-omapl138-hawk: fix GPIO numbers for MMC/SD lookup
+ - ARM: davinci: board-dm355-evm: fix broken networking
+ - dt-bindings: panel: lvds: Fix path to display timing bindings
+ - ARM: OMAP2+: powerdomain: use raw_smp_processor_id() for trace
+ - ARM: dts: logicpd-som-lv: Fix WL127x Startup Issues
+ - ARM: dts: logicpd-som-lv: Fix Audio Mute
+ - Input: atmel_mxt_ts - fix the firmware update
+ - hexagon: add memset_io() helper
+ - hexagon: export csum_partial_copy_nocheck
+ - scsi: vmw-pvscsi: return DID_BUS_BUSY for adapter-initated aborts
+ - bpf, x64: fix memleak when not converging after image
+ - parisc: drivers.c: Fix section mismatches
+ - stop_machine, sched: Fix migrate_swap() vs. active_balance() deadlock
+ - kthread, sched/wait: Fix kthread_parkme() wait-loop
+ - arm64: tegra: Make BCM89610 PHY interrupt as active low
+ - iommu/vt-d: fix shift-out-of-bounds in bug checking
+ - nvme: fix potential memory leak in option parsing
+ - nvme: Set integrity flag for user passthrough commands
+ - ARM: OMAP1: ams-delta: fix deferred_fiq handler
+ - smc: fix sendpage() call
+ - IB/hfi1 Use correct type for num_user_context
+ - IB/hfi1: Fix memory leak in exception path in get_irq_affinity()
+ - RDMA/cma: Do not query GID during QP state transition to RTR
+ - spi: bcm2835aux: ensure interrupts are enabled for shared handler
+ - sched/core: Introduce set_special_state()
+ - sh: fix build failure for J2 cpu with SMP disabled
+ - tee: check shm references are consistent in offset/size
+ - mac80211: Adjust SAE authentication timeout
+ - drm/omap: silence unititialized variable warning
+ - drm/omap: fix uninitialized ret variable
+ - drm/omap: fix possible NULL ref issue in tiler_reserve_2d
+ - drm/omap: check return value from soc_device_match
+ - drm/omap: handle alloc failures in omap_connector
+ - driver core: add __printf verification to __ata_ehi_pushv_desc
+ - ARM: dts: cygnus: fix irq type for arm global timer
+ - mac80211: use timeout from the AddBA response instead of the request
+ - net: aquantia: driver should correctly declare vlan_features bits
+ - can: dev: increase bus-off message severity
+ - arm64: Add MIDR encoding for NVIDIA CPUs
+ - cifs: smb2ops: Fix listxattr() when there are no EAs
+ - agp: uninorth: make two functions static
+ - tipc: eliminate KMSAN uninit-value in strcmp complaint
+ - qed: Fix l2 initializations over iWARP personality
+ - qede: Fix gfp flags sent to rdma event node allocation
+ - rxrpc: Fix error reception on AF_INET6 sockets
+ - rxrpc: Fix the min security level for kernel calls
+ - KVM: Extend MAX_IRQ_ROUTES to 4096 for all archs
+ - x86: Delay skip of emulated hypercall instruction
+ - ixgbe: return error on unsupported SFP module when resetting
+ - net sched actions: fix invalid pointer dereferencing if skbedit flags
+ missing
+ - proc/kcore: don't bounds check against address 0
+ - ocfs2: take inode cluster lock before moving reflinked inode from orphan dir
+ - kprobes/x86: Prohibit probing on exception masking instructions
+ - uprobes/x86: Prohibit probing on MOV SS instruction
+ - objtool, kprobes/x86: Sync the latest <asm/insn.h> header with
+ tools/objtool/arch/x86/include/asm/insn.h
+ - x86/pkeys/selftests: Adjust the self-test to fresh distros that export the
+ pkeys ABI
+ - x86/mpx/selftests: Adjust the self-test to fresh distros that export the MPX
+ ABI
+ - x86/selftests: Add mov_to_ss test
+ - x86/pkeys/selftests: Give better unexpected fault error messages
+ - x86/pkeys/selftests: Stop using assert()
+ - x86/pkeys/selftests: Remove dead debugging code, fix dprint_in_signal
+ - x86/pkeys/selftests: Allow faults on unknown keys
+ - x86/pkeys/selftests: Factor out "instruction page"
+ - x86/pkeys/selftests: Add PROT_EXEC test
+ - x86/pkeys/selftests: Fix pkey exhaustion test off-by-one
+ - x86/pkeys/selftests: Fix pointer math
+ - x86/pkeys/selftests: Save off 'prot' for allocations
+ - x86/pkeys/selftests: Add a test for pkey 0
+ - mtd: Fix comparison in map_word_andequal()
+ - afs: Fix the non-encryption of calls
+ - usb: musb: fix remote wakeup racing with suspend
+ - ARM: keystone: fix platform_domain_notifier array overrun
+ - i2c: pmcmsp: return message count on master_xfer success
+ - i2c: pmcmsp: fix error return from master_xfer
+ - i2c: viperboard: return message count on master_xfer success
+ - ARM: davinci: dm646x: fix timer interrupt generation
+ - ARM: davinci: board-dm646x-evm: pass correct I2C adapter id for VPIF
+ - ARM: davinci: board-dm646x-evm: set VPIF capture card name
+ - clk: imx6ull: use OSC clock during AXI rate change
+ - locking/rwsem: Add a new RWSEM_ANONYMOUSLY_OWNED flag
+ - locking/percpu-rwsem: Annotate rwsem ownership transfer by setting
+ RWSEM_OWNER_UNKNOWN
+ - drm/dumb-buffers: Integer overflow in drm_mode_create_ioctl()
+ - sched/debug: Move the print_rt_rq() and print_dl_rq() declarations to
+ kernel/sched/sched.h
+ - sched/deadline: Make the grub_reclaim() function static
+ - parisc: Move setup_profiling_timer() out of init section
+ - efi/libstub/arm64: Handle randomized TEXT_OFFSET
+ - ARM: 8753/1: decompressor: add a missing parameter to the addruart macro
+ - ARM: 8758/1: decompressor: restore r1 and r2 just before jumping to the
+ kernel
+ - ARM: kexec: fix kdump register saving on panic()
+ - Revert "Btrfs: fix scrub to repair raid6 corruption"
+ - Btrfs: fix scrub to repair raid6 corruption
+ - Btrfs: make raid6 rebuild retry more
+ - tcp: do not overshoot window_clamp in tcp_rcv_space_adjust()
+ - ibmvnic: Do not notify peers on parameter change resets
+ - dt-bindings: net: ravb: Add support for r8a77965 SoC
+ - X86/KVM: Properly update 'tsc_offset' to represent the running guest
+ - kvm: x86: move MSR_IA32_TSC handling to x86.c
+ - ARM: dts: Fix cm2 and prm sizes for omap4
+ - powerpc/64s: Default l1d_size to 64K in RFI fallback flush
+ - KVM: arm/arm64: vgic: Kick new VCPU on interrupt migration
+ - arm64: kasan: avoid pfn_to_nid() before page array is initialized
+ - ARM64: dts: meson-gxl: add USB host support
+ - ARM64: dts: meson-gxm: add GXM specific USB host configuration
+ - ARM64: dts: meson-gxl-s905x-p212: enable the USB controller
+ - ARM64: dts: meson-gx-p23x-q20x: enable the USB controller
+ - ARM64: dts: meson-gxl-s905x-libretech-cc: enable the USB controller
+ - ARM64: dts: meson-gxl-nexbox-a95x: enable the USB controller
+ - ARM64: dts: meson-gxm-khadas-vim2: enable the USB controller
+ - arm64: dts: correct SATA addresses for Stingray
+ - afs: Fix server record deletion
+ - proc: fix /proc/loadavg regression
+ - s390/qeth: fix request-side race during cmd IO timeout
+ - ACPI / scan: Initialize watchdog before PNP
+ - CIFS: set *resp_buf_type to NO_BUFFER on error
+ - arm64: dts: uniphier: fix input delay value for legacy mode of eMMC
+ - igb: Fix the transmission mode of queue 0 for Qav mode
+ - RISC-V: build vdso-dummy.o with -no-pie
+ - arm64: only advance singlestep for user instruction traps
+ - perf pmu: Fix core PMU alias list for X86 platform
+ - bpf, x64: fix JIT emission for dead code
+ - powerpc/kvm/booke: Fix altivec related build break
+ - reset: uniphier: fix USB clock line for LD20
+ - nfp: don't depend on eth_tbl being available
+ - net: mvpp2: Fix clk error path in mvpp2_probe
+ - kvm: apic: Flush TLB after APIC mode/address change if VPIDs are in use
+ - IB/uverbs: Fix validating mandatory attributes
+ - RDMA/hns: Intercept illegal RDMA operation when use inline data
+ - pinctrl: cherryview: Associate IRQ descriptors to irqdomain
+ - kthread, sched/wait: Fix kthread_parkme() completion issue
+ - iommu/vt-d: Fix usage of force parameter in intel_ir_reconfigure_irte()
+ - nvme/multipath: Disable runtime writable enabling parameter
+ - ARM: dts: correct missing "compatible" entry for ti81xx SoCs
+ - usb: typec: tps6598x: handle block reads separately with plain-I2C adapters
+ - IB/mlx4: Fix integer overflow when calculating optimal MTT size
+ - bpf: add map_alloc_check callback
+ - bpf: fix possible spectre-v1 in find_and_alloc_map()
+ - drm/exynos/mixer: fix synchronization check in interlaced mode
+ - drm/exynos: mixer: avoid Oops in vp_video_buffer()
+ - bpf: use array_index_nospec in find_prog_type
+ - gcc-plugins: fix build condition of SANCOV plugin
+ - drm/vc4: Fix oops dereferencing DPI's connector since panel_bridge.
+ - nvme: fix use-after-free in nvme_free_ns_head
+ - powerpc/pseries: Fix CONFIG_NUMA=n build
+ - HID: i2c-hid: Add RESEND_REPORT_DESCR quirk for Toshiba Click Mini L9W-B
+ - cifs: Allocate validate negotiation request through kmalloc
+ - drm/amdgpu: Switch to interruptable wait to recover from ring hang.
+ - rxrpc: Fix missing start of call timeout
+ - ARM: dts: imx51-zii-rdu1: fix touchscreen bindings
+ - sh: switch to NO_BOOTMEM
+ - lib/find_bit_benchmark.c: avoid soft lockup in test_find_first_bit()
+ - x86/pkeys/selftests: Avoid printf-in-signal deadlocks
+ - afs: Fix address list parsing
+ - afs: Fix refcounting in callback registration
+ - afs: Fix server rotation's handling of fileserver probe failure
+ - afs: Fix VNOVOL handling in address rotation
+ - afs: Fix the handling of CB.InitCallBackState3 to find the server by UUID
+ - afs: Fix afs_find_server search loop
+ - KVM: X86: Lower the default timer frequency limit to 200us
+ - platform/x86: DELL_WMI use depends on instead of select for DELL_SMBIOS
+ - ARM: replace unnecessary perl with sed and the shell $(( )) operator
+
+ * Improvements to the kernel source package preparation (LP: #1793461)
+ - [Packaging] startnewrelease: add support for backport kernels
+
+ * Kernel 4.15.0-35.38 fails to build with CONFIG_XFS_ONLINE_SCRUB enabled
+ (LP: #1792393)
+ - SAUCE: xfs: fix build error with CONFIG_XFS_ONLINE_SCRUB enabled
+
+ * update ENA driver to latest mainline version (LP: #1792044)
+ - net: ena: add detection and recovery mechanism for handling missed/misrouted
+ MSI-X
+ - net: ena: increase ena driver version to 1.5.0
+ - net: ena: Eliminate duplicate barriers on weakly-ordered archs
+ - SAUCE: ena: devm_kzalloc() -> devm_kcalloc()
+ - net: ena: Fix use of uninitialized DMA address bits field
+ - net: ena: fix surprise unplug NULL dereference kernel crash
+ - net: ena: fix driver when PAGE_SIZE == 64kB
+ - net: ena: fix device destruction to gracefully free resources
+ - net: ena: fix potential double ena_destroy_device()
+ - net: ena: fix missing lock during device destruction
+ - net: ena: fix missing calls to READ_ONCE
+ - net: ena: fix incorrect usage of memory barriers
+
+ -- Stefan Bader <stefan.bader@canonical.com> Tue, 02 Oct 2018 14:33:09 +0200
+
+linux (4.15.0-36.39) bionic; urgency=medium
+
+ * CVE-2018-14633
+ - iscsi target: Use hex2bin instead of a re-implementation
+
+ * CVE-2018-17182
+ - mm: get rid of vmacache_flush_all() entirely
+
+ -- Kleber Sacilotto de Souza <kleber.souza@canonical.com> Mon, 24 Sep 2018 16:08:41 +0200
+
+linux (4.15.0-35.38) bionic; urgency=medium
+
+ * linux: 4.15.0-35.38 -proposed tracker (LP: #1791719)
+
+ * device hotplug of vfio devices can lead to deadlock in vfio_pci_release
+ (LP: #1792099)
+ - SAUCE: vfio -- release device lock before userspace requests
+
+ * L1TF mitigation not effective in some CPU and RAM combinations
+ (LP: #1788563)
+ - x86/speculation/l1tf: Fix overflow in l1tf_pfn_limit() on 32bit
+ - x86/speculation/l1tf: Fix off-by-one error when warning that system has too
+ much RAM
+ - x86/speculation/l1tf: Increase l1tf memory limit for Nehalem+
+
+ * CVE-2018-15594
+ - x86/paravirt: Fix spectre-v2 mitigations for paravirt guests
+
+ * CVE-2017-5715 (Spectre v2 s390x)
+ - KVM: s390: implement CPU model only facilities
+ - s390: detect etoken facility
+ - KVM: s390: add etoken support for guests
+ - s390/lib: use expoline for all bcr instructions
+ - s390: fix br_r1_trampoline for machines without exrl
+ - SAUCE: s390: use expoline thunks for all branches generated by the BPF JIT
+
+ * Ubuntu18.04.1: cpuidle: powernv: Fix promotion from snooze if next state
+ disabled (performance) (LP: #1790602)
+ - cpuidle: powernv: Fix promotion from snooze if next state disabled
+
+ * Watchdog CPU:19 Hard LOCKUP when kernel crash was triggered (LP: #1790636)
+ - powerpc: hard disable irqs in smp_send_stop loop
+ - powerpc: Fix deadlock with multiple calls to smp_send_stop
+ - powerpc: smp_send_stop do not offline stopped CPUs
+ - powerpc/powernv: Fix opal_event_shutdown() called with interrupts disabled
+
+ * Security fix: check if IOMMU page is contained in the pinned physical page
+ (LP: #1785675)
+ - vfio/spapr: Use IOMMU pageshift rather than pagesize
+ - KVM: PPC: Check if IOMMU page is contained in the pinned physical page
+
+ * Missing Intel GPU pci-id's (LP: #1789924)
+ - drm/i915/kbl: Add KBL GT2 sku
+ - drm/i915/whl: Introducing Whiskey Lake platform
+ - drm/i915/aml: Introducing Amber Lake platform
+ - drm/i915/cfl: Add a new CFL PCI ID.
+
+ * CVE-2018-15572
+ - x86/speculation: Protect against userspace-userspace spectreRSB
+
+ * Support Power Management for Thunderbolt Controller (LP: #1789358)
+ - thunderbolt: Handle NULL boot ACL entries properly
+ - thunderbolt: Notify userspace when boot_acl is changed
+ - thunderbolt: Use 64-bit DMA mask if supported by the platform
+ - thunderbolt: Do not unnecessarily call ICM get route
+ - thunderbolt: No need to take tb->lock in domain suspend/complete
+ - thunderbolt: Use correct ICM commands in system suspend
+ - thunderbolt: Add support for runtime PM
+
+ * random oopses on s390 systems using NVMe devices (LP: #1790480)
+ - s390/pci: fix out of bounds access during irq setup
+
+ * [Bionic] Spectre v4 mitigation (Speculative Store Bypass Disable) support
+ for arm64 using SMC firmware call to set a hardware chicken bit
+ (LP: #1787993) // CVE-2018-3639 (arm64)
+ - arm64: alternatives: Add dynamic patching feature
+ - KVM: arm/arm64: Do not use kern_hyp_va() with kvm_vgic_global_state
+ - KVM: arm64: Avoid storing the vcpu pointer on the stack
+ - arm/arm64: smccc: Add SMCCC-specific return codes
+ - arm64: Call ARCH_WORKAROUND_2 on transitions between EL0 and EL1
+ - arm64: Add per-cpu infrastructure to call ARCH_WORKAROUND_2
+ - arm64: Add ARCH_WORKAROUND_2 probing
+ - arm64: Add 'ssbd' command-line option
+ - arm64: ssbd: Add global mitigation state accessor
+ - arm64: ssbd: Skip apply_ssbd if not using dynamic mitigation
+ - arm64: ssbd: Restore mitigation status on CPU resume
+ - arm64: ssbd: Introduce thread flag to control userspace mitigation
+ - arm64: ssbd: Add prctl interface for per-thread mitigation
+ - arm64: KVM: Add HYP per-cpu accessors
+ - arm64: KVM: Add ARCH_WORKAROUND_2 support for guests
+ - arm64: KVM: Handle guest's ARCH_WORKAROUND_2 requests
+ - arm64: KVM: Add ARCH_WORKAROUND_2 discovery through ARCH_FEATURES_FUNC_ID
+ - [Config] ARM64_SSBD=y
+
+ * Reconcile hns3 SAUCE patches with upstream (LP: #1787477)
+ - Revert "UBUNTU: SAUCE: net: hns3: Optimize PF CMDQ interrupt switching
+ process"
+ - Revert "UBUNTU: SAUCE: net: hns3: Fix for VF mailbox receiving unknown
+ message"
+ - Revert "UBUNTU: SAUCE: net: hns3: Fix for VF mailbox cannot receiving PF
+ response"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix comments for
+ hclge_get_ring_chain_from_mbx"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix for using wrong mask and
+ shift in hclge_get_ring_chain_from_mbx"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix for reset_level default
+ assignment probelm"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove unnecessary ring
+ configuration operation while resetting"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix return value error in
+ hns3_reset_notify_down_enet"
+ - Revert "UBUNTU: SAUCE: net: hns3: Fix for phy link issue when using marvell
+ phy driver"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: separate roce from nic when
+ resetting"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: correct reset event status
+ register"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: prevent to request reset
+ frequently"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: reset net device with rtnl_lock"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: modify the order of initializeing
+ command queue register"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: prevent sending command during
+ global or core reset"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove the warning when clear
+ reset cause"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix get_vector ops in
+ hclgevf_main module"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix warning bug when doing lp
+ selftest"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: Add configure for mac minimal
+ frame size"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix for mailbox message truncated
+ problem"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix for l4 checksum offload bug"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix for waterline not setting
+ correctly"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix for mac pause not disable in
+ pfc mode"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix tc setup when netdev is first
+ up"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: Add SPDX tags to hns3 driver"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove unused struct member and
+ definition"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix mislead parameter name"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: modify inconsistent bit mask
+ macros"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: use decimal for bit offset
+ macros"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix unreasonable code comments"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove extra space and brackets"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: standardize the handle of return
+ value"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove some redundant
+ assignments"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix unused function warning in VF
+ driver"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: modify hnae_ to hnae3_"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: use dma_zalloc_coherent instead
+ of kzalloc/dma_map_single"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: give default option while
+ dependency HNS3 set"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove some unused members of
+ some structures"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove a redundant
+ hclge_cmd_csq_done"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: using modulo for cyclic counters
+ in hclge_cmd_send"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: simplify hclge_cmd_csq_clean"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove some redundant
+ assignments"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove useless code in
+ hclge_cmd_send"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove unused
+ hclge_ring_to_dma_dir"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: use lower_32_bits and
+ upper_32_bits"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove back in struct hclge_hw"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: add unlikely for error check"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove the Redundant put_vector
+ in hns3_client_uninit"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: print the ret value in error
+ information"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: extraction an interface for state
+ state init|uninit"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove unused head file in
+ hnae3.c"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: add l4_type check for both ipv4
+ and ipv6"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: add vector status check before
+ free vector"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: rename the interface for
+ init_client_instance and uninit_client_instance"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove hclge_get_vector_index
+ from hclge_bind_ring_with_vector"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: RX BD information valid only in
+ last BD except VLD bit and buffer size"
+ - Revert "UBUNTU: SAUCE: {topost} net: hns3: add support for serdes loopback
+ selftest"
+ - net: hns3: Updates RX packet info fetch in case of multi BD
+ - net: hns3: remove unused hclgevf_cfg_func_mta_filter
+ - net: hns3: Fix for VF mailbox cannot receiving PF response
+ - net: hns3: Fix for VF mailbox receiving unknown message
+ - net: hns3: Optimize PF CMDQ interrupt switching process
+ - net: hns3: remove hclge_get_vector_index from hclge_bind_ring_with_vector
+ - net: hns3: rename the interface for init_client_instance and
+ uninit_client_instance
+ - net: hns3: add vector status check before free vector
+ - net: hns3: add l4_type check for both ipv4 and ipv6
+ - net: hns3: add unlikely for error check
+ - net: hns3: remove unused head file in hnae3.c
+ - net: hns3: extraction an interface for state init|uninit
+ - net: hns3: print the ret value in error information
+ - net: hns3: remove the Redundant put_vector in hns3_client_uninit
+ - net: hns3: remove back in struct hclge_hw
+ - net: hns3: use lower_32_bits and upper_32_bits
+ - net: hns3: remove unused hclge_ring_to_dma_dir
+ - net: hns3: remove useless code in hclge_cmd_send
+ - net: hns3: remove some redundant assignments
+ - net: hns3: simplify hclge_cmd_csq_clean
+ - net: hns3: remove a redundant hclge_cmd_csq_done
+ - net: hns3: remove some unused members of some structures
+ - net: hns3: give default option while dependency HNS3 set
+ - net: hns3: use dma_zalloc_coherent instead of kzalloc/dma_map_single
+ - net: hns3: modify hnae_ to hnae3_
+ - net: hns3: Fix tc setup when netdev is first up
+ - net: hns3: Fix for mac pause not disable in pfc mode
+ - net: hns3: Fix for waterline not setting correctly
+ - net: hns3: Fix for l4 checksum offload bug
+ - net: hns3: Fix for mailbox message truncated problem
+ - net: hns3: Add configure for mac minimal frame size
+ - net: hns3: Fix warning bug when doing lp selftest
+ - net: hns3: Fix get_vector ops in hclgevf_main module
+ - net: hns3: Remove the warning when clear reset cause
+ - net: hns3: Prevent sending command during global or core reset
+ - net: hns3: Modify the order of initializing command queue register
+ - net: hns3: Reset net device with rtnl_lock
+ - net: hns3: Prevent to request reset frequently
+ - net: hns3: Correct reset event status register
+ - net: hns3: Fix return value error in hns3_reset_notify_down_enet
+ - net: hns3: remove unnecessary ring configuration operation while resetting
+ - net: hns3: Fix for reset_level default assignment probelm
+ - net: hns3: Fix for using wrong mask and shift in
+ hclge_get_ring_chain_from_mbx
+ - net: hns3: Fix comments for hclge_get_ring_chain_from_mbx
+ - net: hns3: Remove some redundant assignments
+ - net: hns3: Standardize the handle of return value
+ - net: hns3: Remove extra space and brackets
+ - net: hns3: Correct unreasonable code comments
+ - net: hns3: Use decimal for bit offset macros
+ - net: hns3: Modify inconsistent bit mask macros
+ - net: hns3: Fix misleading parameter name
+ - net: hns3: Remove unused struct member and definition
+ - net: hns3: Add SPDX tags to HNS3 PF driver
+ - net: hns3: Add support for serdes loopback selftest
+ - net: hns3: Fix for phy link issue when using marvell phy driver
+ - SAUCE: {topost} net: hns3: separate roce from nic when resetting
+
+ * CVE-2018-6555
+ - SAUCE: irda: Only insert new objects into the global database via setsockopt
+
+ * CVE-2018-6554
+ - SAUCE: irda: Fix memory leak caused by repeated binds of irda socket
+
+ * Bionic update: upstream stable patchset 2018-08-31 (LP: #1790188)
+ - netfilter: nf_tables: fix NULL pointer dereference on
+ nft_ct_helper_obj_dump()
+ - blkdev_report_zones_ioctl(): Use vmalloc() to allocate large buffers
+ - af_key: Always verify length of provided sadb_key
+ - gpio: No NULL owner
+ - KVM: X86: Fix reserved bits check for MOV to CR3
+ - KVM: x86: introduce linear_{read,write}_system
+ - KVM: x86: pass kvm_vcpu to kvm_read_guest_virt and
+ kvm_write_guest_virt_system
+ - staging: android: ion: Switch to pr_warn_once in ion_buffer_destroy
+ - NFC: pn533: don't send USB data off of the stack
+ - usbip: vhci_sysfs: fix potential Spectre v1
+ - usb-storage: Add support for FL_ALWAYS_SYNC flag in the UAS driver
+ - usb-storage: Add compatibility quirk flags for G-Technologies G-Drive
+ - Input: xpad - add GPD Win 2 Controller USB IDs
+ - phy: qcom-qusb2: Fix crash if nvmem cell not specified
+ - usb: gadget: function: printer: avoid wrong list handling in printer_write()
+ - usb: gadget: udc: renesas_usb3: disable the controller's irqs for
+ reconnecting
+ - serial: sh-sci: Stop using printk format %pCr
+ - tty/serial: atmel: use port->name as name in request_irq()
+ - serial: samsung: fix maxburst parameter for DMA transactions
+ - serial: 8250: omap: Fix idling of clocks for unused uarts
+ - vmw_balloon: fixing double free when batching mode is off
+ - tty: pl011: Avoid spuriously stuck-off interrupts
+ - kvm: x86: use correct privilege level for sgdt/sidt/fxsave/fxrstor access
+ - Input: goodix - add new ACPI id for GPD Win 2 touch screen
+ - crypto: caam - strip input zeros from RSA input buffer
+ - crypto: caam - fix DMA mapping dir for generated IV
+ - crypto: caam - fix IV DMA mapping and updating
+ - crypto: caam/qi - fix IV DMA mapping and updating
+ - crypto: caam - fix size of RSA prime factor q
+ - crypto: vmx - Remove overly verbose printk from AES init routines
+ - crypto: vmx - Remove overly verbose printk from AES XTS init
+ - crypto: omap-sham - fix memleak
+ - usb: typec: wcove: Remove dependency on HW FSM
+ - usb: gadget: udc: renesas_usb3: fix double phy_put()
+ - usb: gadget: udc: renesas_usb3: should remove debugfs
+ - usb: gadget: udc: renesas_usb3: should call pm_runtime_enable() before add
+ udc
+ - usb: gadget: udc: renesas_usb3: should call devm_phy_get() before add udc
+ - usb: gadget: udc: renesas_usb3: should fail if devm_phy_get() returns error
+
+ * Bionic update: upstream stable patchset 2018-08-29 (LP: #1789666)
+ - scsi: sd_zbc: Avoid that resetting a zone fails sporadically
+ - mmap: introduce sane default mmap limits
+ - mmap: relax file size limit for regular files
+ - btrfs: define SUPER_FLAG_METADUMP_V2
+ - kconfig: Avoid format overflow warning from GCC 8.1
+ - be2net: Fix error detection logic for BE3
+ - bnx2x: use the right constant
+ - dccp: don't free ccid2_hc_tx_sock struct in dccp_disconnect()
+ - enic: set DMA mask to 47 bit
+ - ip6mr: only set ip6mr_table from setsockopt when ip6mr_new_table succeeds
+ - ip6_tunnel: remove magic mtu value 0xFFF8
+ - ipmr: properly check rhltable_init() return value
+ - ipv4: remove warning in ip_recv_error
+ - ipv6: omit traffic class when calculating flow hash
+ - isdn: eicon: fix a missing-check bug
+ - kcm: Fix use-after-free caused by clonned sockets
+ - netdev-FAQ: clarify DaveM's position for stable backports
+ - net: ipv4: add missing RTA_TABLE to rtm_ipv4_policy
+ - net: metrics: add proper netlink validation
+ - net/packet: refine check for priv area size
+ - net: phy: broadcom: Fix bcm_write_exp()
+ - net: usb: cdc_mbim: add flag FLAG_SEND_ZLP
+ - packet: fix reserve calculation
+ - qed: Fix mask for physical address in ILT entry
+ - sctp: not allow transport timeout value less than HZ/5 for hb_timer
+ - team: use netdev_features_t instead of u32
+ - vhost: synchronize IOTLB message with dev cleanup
+ - vrf: check the original netdevice for generating redirect
+ - ipv6: sr: fix memory OOB access in seg6_do_srh_encap/inline
+ - net: phy: broadcom: Fix auxiliary control register reads
+ - net-sysfs: Fix memory leak in XPS configuration
+ - virtio-net: correctly transmit XDP buff after linearizing
+ - net/mlx4: Fix irq-unsafe spinlock usage
+ - tun: Fix NULL pointer dereference in XDP redirect
+ - virtio-net: correctly check num_buf during err path
+ - net/mlx5e: When RXFCS is set, add FCS data into checksum calculation
+ - virtio-net: fix leaking page for gso packet during mergeable XDP
+ - rtnetlink: validate attributes in do_setlink()
+ - cls_flower: Fix incorrect idr release when failing to modify rule
+ - PCI: hv: Do not wait forever on a device that has disappeared
+ - drm: set FMODE_UNSIGNED_OFFSET for drm files
+ - l2tp: fix refcount leakage on PPPoL2TP sockets
+ - mlxsw: spectrum: Forbid creation of VLAN 1 over port/LAG
+ - net: ethernet: ti: cpdma: correct error handling for chan create
+ - net: ethernet: davinci_emac: fix error handling in probe()
+ - net: dsa: b53: Fix for brcm tag issue in Cygnus SoC
+ - net : sched: cls_api: deal with egdev path only if needed
+
+ * Bionic update: upstream stable patchset 2018-08-24 (LP: #1788897)
+ - fix io_destroy()/aio_complete() race
+ - mm: fix the NULL mapping case in __isolate_lru_page()
+ - objtool: Support GCC 8's cold subfunctions
+ - objtool: Support GCC 8 switch tables
+ - objtool: Detect RIP-relative switch table references
+ - objtool: Detect RIP-relative switch table references, part 2
+ - objtool: Fix "noreturn" detection for recursive sibling calls
+ - xfs: convert XFS_AGFL_SIZE to a helper function
+ - xfs: detect agfl count corruption and reset agfl
+ - Input: synaptics - Lenovo Carbon X1 Gen5 (2017) devices should use RMI
+ - Input: synaptics - add Lenovo 80 series ids to SMBus
+ - Input: elan_i2c_smbus - fix corrupted stack
+ - tracing: Fix crash when freeing instances with event triggers
+ - tracing: Make the snapshot trigger work with instances
+ - selinux: KASAN: slab-out-of-bounds in xattr_getsecurity
+ - cfg80211: further limit wiphy names to 64 bytes
+ - drm/amd/powerplay: Fix enum mismatch
+ - rtlwifi: rtl8192cu: Remove variable self-assignment in rf.c
+ - platform/chrome: cros_ec_lpc: remove redundant pointer request
+ - kbuild: clang: disable unused variable warnings only when constant
+ - tcp: avoid integer overflows in tcp_rcv_space_adjust()
+ - iio: ad7793: implement IIO_CHAN_INFO_SAMP_FREQ
+ - iio:buffer: make length types match kfifo types
+ - iio:kfifo_buf: check for uint overflow
+ - iio: adc: select buffer for at91-sama5d2_adc
+ - MIPS: lantiq: gphy: Drop reboot/remove reset asserts
+ - MIPS: ptrace: Fix PTRACE_PEEKUSR requests for 64-bit FGRs
+ - MIPS: prctl: Disallow FRE without FR with PR_SET_FP_MODE requests
+ - scsi: scsi_transport_srp: Fix shost to rport translation
+ - stm class: Use vmalloc for the master map
+ - hwtracing: stm: fix build error on some arches
+ - IB/core: Fix error code for invalid GID entry
+ - mm/huge_memory.c: __split_huge_page() use atomic ClearPageDirty()
+ - Revert "rt2800: use TXOP_BACKOFF for probe frames"
+ - intel_th: Use correct device when freeing buffers
+ - drm/psr: Fix missed entry in PSR setup time table.
+ - drm/i915/lvds: Move acpi lid notification registration to registration phase
+ - drm/i915: Disable LVDS on Radiant P845
+ - drm/vmwgfx: Use kasprintf
+ - drm/vmwgfx: Fix host logging / guestinfo reading error paths
+ - nvme: fix extended data LBA supported setting
+ - iio: hid-sensor-trigger: Fix sometimes not powering up the sensor after
+ resume
+ - x86/MCE/AMD: Define a function to get SMCA bank type
+ - x86/mce/AMD: Pass the bank number to smca_get_bank_type()
+ - x86/mce/AMD, EDAC/mce_amd: Enumerate Reserved SMCA bank type
+ - x86/mce/AMD: Carve out SMCA get_block_address() code
+ - x86/MCE/AMD: Cache SMCA MISC block addresses
+
+ * errors when scanning partition table of corrupted AIX disk (LP: #1787281)
+ - partitions/aix: fix usage of uninitialized lv_info and lvname structures
+ - partitions/aix: append null character to print data from disk
+
+ * tlbie master timeout checkstop (using NVidia/GPU) (LP: #1789772)
+ - powerpc/mm/hugetlb: Update huge_ptep_set_access_flags to call
+ __ptep_set_access_flags directly
+ - powerpc/mm/radix: Move function from radix.h to pgtable-radix.c
+ - powerpc/mm: Change function prototype
+ - powerpc/mm/radix: Change pte relax sequence to handle nest MMU hang
+
+ * performance drop with ATS enabled (LP: #1788097)
+ - powerpc/powernv: Fix concurrency issue with npu->mmio_atsd_usage
+
+ * [Regression] kernel crashdump fails on arm64 (LP: #1786878)
+ - arm64: export memblock_reserve()d regions via /proc/iomem
+ - drivers: acpi: add dependency of EFI for arm64
+ - efi/arm: preserve early mapping of UEFI memory map longer for BGRT
+ - efi/arm: map UEFI memory map even w/o runtime services enabled
+ - arm64: acpi: fix alignment fault in accessing ACPI
+ - [Config] CONFIG_ARCH_SUPPORTS_ACPI=y
+ - arm64: fix ACPI dependencies
+ - ACPI: fix menuconfig presentation of ACPI submenu
+
+ * TB 16 issue on Dell Lattitude 7490 with large amount of data (LP: #1785780)
+ - r8152: disable RX aggregation on new Dell TB16 dock
+
+ * dell_wmi: Unknown key codes (LP: #1762385)
+ - platform/x86: dell-wmi: Ignore new rfkill and fn-lock events
+
+ * Enable AMD PCIe MP2 for AMDI0011 (LP: #1773940)
+ - SAUCE: i2c:amd I2C Driver based on PCI Interface for upcoming platform
+ - SAUCE: i2c:amd move out pointer in union i2c_event_base
+ - SAUCE: i2c:amd Depends on ACPI
+ - [Config] i2c: CONFIG_I2C_AMD_MP2=y on x86
+
+ * r8169 no internet after suspending (LP: #1779817)
+ - r8169: restore previous behavior to accept BIOS WoL settings
+ - r8169: don't use MSI-X on RTL8168g
+ - r8169: don't use MSI-X on RTL8106e
+
+ * Fix Intel Cannon Lake LPSS I2C input clock (LP: #1789790)
+ - mfd: intel-lpss: Fix Intel Cannon Lake LPSS I2C input clock
+
+ * Microphone cannot be detected with front panel audio combo jack on HP Z8-G4
+ machine (LP: #1789145)
+ - ALSA: hda/realtek - Fix HP Headset Mic can't record
+
+ * Tango platform uses __initcall without further checks (LP: #1787945)
+ - [Config] disable ARCH_TANGO
+
+ * [18.10 FEAT] Add kernel config option "CONFIG_SCLP_OFB" (LP: #1787898)
+ - [Config] CONFIG_SCLP_OFB=y for s390x
+
+ -- Kleber Sacilotto de Souza <kleber.souza@canonical.com> Wed, 12 Sep 2018 11:39:17 +0200
+
+linux (4.15.0-34.37) bionic; urgency=medium
+
+ * linux: 4.15.0-34.37 -proposed tracker (LP: #1788744)
+
+ * Bionic update: upstream stable patchset 2018-08-09 (LP: #1786352)
+ - MIPS: c-r4k: Fix data corruption related to cache coherence
+ - MIPS: ptrace: Expose FIR register through FP regset
+ - MIPS: Fix ptrace(2) PTRACE_PEEKUSR and PTRACE_POKEUSR accesses to o32 FGRs
+ - KVM: Fix spelling mistake: "cop_unsuable" -> "cop_unusable"
+ - affs_lookup(): close a race with affs_remove_link()
+ - fs: don't scan the inode cache before SB_BORN is set
+ - aio: fix io_destroy(2) vs. lookup_ioctx() race
+ - ALSA: timer: Fix pause event notification
+ - do d_instantiate/unlock_new_inode combinations safely
+ - mmc: sdhci-iproc: remove hard coded mmc cap 1.8v
+ - mmc: sdhci-iproc: fix 32bit writes for TRANSFER_MODE register
+ - mmc: sdhci-iproc: add SDHCI_QUIRK2_HOST_OFF_CARD_ON for cygnus
+ - libata: Blacklist some Sandisk SSDs for NCQ
+ - libata: blacklist Micron 500IT SSD with MU01 firmware
+ - xen-swiotlb: fix the check condition for xen_swiotlb_free_coherent
+ - drm/vmwgfx: Fix 32-bit VMW_PORT_HB_[IN|OUT] macros
+ - arm64: lse: Add early clobbers to some input/output asm operands
+ - powerpc/64s: Clear PCR on boot
+ - IB/hfi1: Use after free race condition in send context error path
+ - IB/umem: Use the correct mm during ib_umem_release
+ - idr: fix invalid ptr dereference on item delete
+ - Revert "ipc/shm: Fix shmat mmap nil-page protection"
+ - ipc/shm: fix shmat() nil address after round-down when remapping
+ - mm/kasan: don't vfree() nonexistent vm_area
+ - kasan: free allocated shadow memory on MEM_CANCEL_ONLINE
+ - kasan: fix memory hotplug during boot
+ - kernel/sys.c: fix potential Spectre v1 issue
+ - KVM: s390: vsie: fix < 8k check for the itdba
+ - KVM: x86: Update cpuid properly when CR4.OSXAVE or CR4.PKE is changed
+ - kvm: x86: IA32_ARCH_CAPABILITIES is always supported
+ - powerpc/64s: Improve RFI L1-D cache flush fallback
+ - powerpc/pseries: Restore default security feature flags on setup
+ - powerpc/64s: Fix section mismatch warnings from setup_rfi_flush()
+ - MIPS: generic: Fix machine compatible matching
+ - mac80211: mesh: fix wrong mesh TTL offset calculation
+ - ARC: Fix malformed ARC_EMUL_UNALIGNED default
+ - ptr_ring: prevent integer overflow when calculating size
+ - arm64: dts: rockchip: fix rock64 gmac2io stability issues
+ - arm64: dts: rockchip: correct ep-gpios for rk3399-sapphire
+ - libata: Fix compile warning with ATA_DEBUG enabled
+ - selftests: sync: missing CFLAGS while compiling
+ - selftest/vDSO: fix O=
+ - selftests: pstore: Adding config fragment CONFIG_PSTORE_RAM=m
+ - selftests: memfd: add config fragment for fuse
+ - ARM: OMAP2+: timer: fix a kmemleak caused in omap_get_timer_dt
+ - ARM: OMAP3: Fix prm wake interrupt for resume
+ - ARM: OMAP2+: Fix sar_base inititalization for HS omaps
+ - ARM: OMAP1: clock: Fix debugfs_create_*() usage
+ - tls: retrun the correct IV in getsockopt
+ - xhci: workaround for AMD Promontory disabled ports wakeup
+ - IB/uverbs: Fix method merging in uverbs_ioctl_merge
+ - IB/uverbs: Fix possible oops with duplicate ioctl attributes
+ - IB/uverbs: Fix unbalanced unlock on error path for rdma_explicit_destroy
+ - arm64: dts: rockchip: Fix DWMMC clocks
+ - ARM: dts: rockchip: Fix DWMMC clocks
+ - iwlwifi: mvm: fix security bug in PN checking
+ - iwlwifi: mvm: fix IBSS for devices that support station type API
+ - iwlwifi: mvm: always init rs with 20mhz bandwidth rates
+ - NFC: llcp: Limit size of SDP URI
+ - rxrpc: Work around usercopy check
+ - MD: Free bioset when md_run fails
+ - md: fix md_write_start() deadlock w/o metadata devices
+ - s390/dasd: fix handling of internal requests
+ - xfrm: do not call rcu_read_unlock when afinfo is NULL in xfrm_get_tos
+ - mac80211: round IEEE80211_TX_STATUS_HEADROOM up to multiple of 4
+ - mac80211: fix a possible leak of station stats
+ - mac80211: fix calling sleeping function in atomic context
+ - cfg80211: clear wep keys after disconnection
+ - mac80211: Do not disconnect on invalid operating class
+ - mac80211: Fix sending ADDBA response for an ongoing session
+ - gpu: ipu-v3: pre: fix device node leak in ipu_pre_lookup_by_phandle
+ - gpu: ipu-v3: prg: fix device node leak in ipu_prg_lookup_by_phandle
+ - md raid10: fix NULL deference in handle_write_completed()
+ - drm/exynos: g2d: use monotonic timestamps
+ - drm/exynos: fix comparison to bitshift when dealing with a mask
+ - drm/meson: fix vsync buffer update
+ - arm64: perf: correct PMUVer probing
+ - RDMA/bnxt_re: Unpin SQ and RQ memory if QP create fails
+ - RDMA/bnxt_re: Fix system crash during load/unload
+ - net/mlx5e: Return error if prio is specified when offloading eswitch vlan
+ push
+ - locking/xchg/alpha: Add unconditional memory barrier to cmpxchg()
+ - md: raid5: avoid string overflow warning
+ - virtio_net: fix XDP code path in receive_small()
+ - kernel/relay.c: limit kmalloc size to KMALLOC_MAX_SIZE
+ - bug.h: work around GCC PR82365 in BUG()
+ - selftests/memfd: add run_fuse_test.sh to TEST_FILES
+ - seccomp: add a selftest for get_metadata
+ - soc: imx: gpc: de-register power domains only if initialized
+ - powerpc/bpf/jit: Fix 32-bit JIT for seccomp_data access
+ - s390/cio: fix ccw_device_start_timeout API
+ - s390/cio: fix return code after missing interrupt
+ - s390/cio: clear timer when terminating driver I/O
+ - selftests/bpf/test_maps: exit child process without error in ENOMEM case
+ - PKCS#7: fix direct verification of SignerInfo signature
+ - arm64: dts: cavium: fix PCI bus dtc warnings
+ - nfs: system crashes after NFS4ERR_MOVED recovery
+ - ARM: OMAP: Fix dmtimer init for omap1
+ - smsc75xx: fix smsc75xx_set_features()
+ - regulatory: add NUL to request alpha2
+ - integrity/security: fix digsig.c build error with header file
+ - x86/intel_rdt: Fix incorrect returned value when creating rdgroup sub-
+ directory in resctrl file system
+ - locking/xchg/alpha: Fix xchg() and cmpxchg() memory ordering bugs
+ - x86/topology: Update the 'cpu cores' field in /proc/cpuinfo correctly across
+ CPU hotplug operations
+ - mac80211: drop frames with unexpected DS bits from fast-rx to slow path
+ - arm64: fix unwind_frame() for filtered out fn for function graph tracing
+ - macvlan: fix use-after-free in macvlan_common_newlink()
+ - KVM: nVMX: Don't halt vcpu when L1 is injecting events to L2
+ - kvm: fix warning for CONFIG_HAVE_KVM_EVENTFD builds
+ - ARM: dts: imx6dl: Include correct dtsi file for Engicam i.CoreM6
+ DualLite/Solo RQS
+ - fs: dcache: Avoid livelock between d_alloc_parallel and __d_add
+ - fs: dcache: Use READ_ONCE when accessing i_dir_seq
+ - md: fix a potential deadlock of raid5/raid10 reshape
+ - md/raid1: fix NULL pointer dereference
+ - batman-adv: fix packet checksum in receive path
+ - batman-adv: invalidate checksum on fragment reassembly
+ - netfilter: ipt_CLUSTERIP: put config struct if we can't increment ct
+ refcount
+ - netfilter: ipt_CLUSTERIP: put config instead of freeing it
+ - netfilter: ebtables: convert BUG_ONs to WARN_ONs
+ - batman-adv: Ignore invalid batadv_iv_gw during netlink send
+ - batman-adv: Ignore invalid batadv_v_gw during netlink send
+ - batman-adv: Fix netlink dumping of BLA claims
+ - batman-adv: Fix netlink dumping of BLA backbones
+ - nvme-pci: Fix nvme queue cleanup if IRQ setup fails
+ - clocksource/drivers/fsl_ftm_timer: Fix error return checking
+ - libceph, ceph: avoid memory leak when specifying same option several times
+ - ceph: fix dentry leak when failing to init debugfs
+ - xen/pvcalls: fix null pointer dereference on map->sock
+ - ARM: orion5x: Revert commit 4904dbda41c8.
+ - qrtr: add MODULE_ALIAS macro to smd
+ - selftests/futex: Fix line continuation in Makefile
+ - r8152: fix tx packets accounting
+ - virtio-gpu: fix ioctl and expose the fixed status to userspace.
+ - dmaengine: rcar-dmac: fix max_chunk_size for R-Car Gen3
+ - bcache: fix kcrashes with fio in RAID5 backend dev
+ - ip_gre: fix IFLA_MTU ignored on NEWLINK
+ - ip6_tunnel: fix IFLA_MTU ignored on NEWLINK
+ - sit: fix IFLA_MTU ignored on NEWLINK
+ - nbd: fix return value in error handling path
+ - ARM: dts: NSP: Fix amount of RAM on BCM958625HR
+ - ARM: dts: bcm283x: Fix unit address of local_intc
+ - powerpc/boot: Fix random libfdt related build errors
+ - clocksource/drivers/mips-gic-timer: Use correct shift count to extract data
+ - gianfar: Fix Rx byte accounting for ndev stats
+ - net/tcp/illinois: replace broken algorithm reference link
+ - nvmet: fix PSDT field check in command format
+ - net/smc: use link_id of server in confirm link reply
+ - mlxsw: core: Fix flex keys scratchpad offset conflict
+ - mlxsw: spectrum: Treat IPv6 unregistered multicast as broadcast
+ - spectrum: Reference count VLAN entries
+ - ARC: mcip: halt GFRC counter when ARC cores halt
+ - ARC: mcip: update MCIP debug mask when the new cpu came online
+ - ARC: setup cpu possible mask according to possible-cpus dts property
+ - ipvs: remove IPS_NAT_MASK check to fix passive FTP
+ - IB/mlx: Set slid to zero in Ethernet completion struct
+ - RDMA/bnxt_re: Unconditionly fence non wire memory operations
+ - RDMA/bnxt_re: Fix incorrect DB offset calculation
+ - RDMA/bnxt_re: Fix the ib_reg failure cleanup
+ - xen/pirq: fix error path cleanup when binding MSIs
+ - drm/amd/amdgpu: Correct VRAM width for APUs with GMC9
+ - xfrm: Fix ESN sequence number handling for IPsec GSO packets.
+ - arm64: dts: rockchip: Fix rk3399-gru-* s2r (pinctrl hogs, wifi reset)
+ - drm/sun4i: Fix dclk_set_phase
+ - btrfs: use kvzalloc to allocate btrfs_fs_info
+ - Btrfs: send, fix issuing write op when processing hole in no data mode
+ - Btrfs: fix log replay failure after linking special file and fsync
+ - ceph: fix potential memory leak in init_caches()
+ - block: display the correct diskname for bio
+ - selftests/powerpc: Skip the subpage_prot tests if the syscall is unavailable
+ - net: ethtool: don't ignore return from driver get_fecparam method
+ - iwlwifi: mvm: fix TX of CCMP 256
+ - iwlwifi: mvm: Fix channel switch for count 0 and 1
+ - iwlwifi: mvm: fix assert 0x2B00 on older FWs
+ - iwlwifi: avoid collecting firmware dump if not loaded
+ - iwlwifi: mvm: Direct multicast frames to the correct station
+ - iwlwifi: mvm: Correctly set the tid for mcast queue
+ - rds: Incorrect reference counting in TCP socket creation
+ - watchdog: f71808e_wdt: Fix magic close handling
+ - batman-adv: Fix multicast packet loss with a single WANT_ALL_IPV4/6 flag
+ - hv_netvsc: use napi_schedule_irqoff
+ - hv_netvsc: filter multicast/broadcast
+ - hv_netvsc: propagate rx filters to VF
+ - ARM: dts: rockchip: Add missing #sound-dai-cells on rk3288
+ - e1000e: Fix check_for_link return value with autoneg off
+ - e1000e: allocate ring descriptors with dma_zalloc_coherent
+ - ia64/err-inject: Use get_user_pages_fast()
+ - RDMA/qedr: Fix kernel panic when running fio over NFSoRDMA
+ - RDMA/qedr: Fix iWARP write and send with immediate
+ - IB/mlx4: Fix corruption of RoCEv2 IPv4 GIDs
+ - IB/mlx4: Include GID type when deleting GIDs from HW table under RoCE
+ - IB/mlx5: Fix an error code in __mlx5_ib_modify_qp()
+ - fbdev: Fixing arbitrary kernel leak in case FBIOGETCMAP_SPARC in
+ sbusfb_ioctl_helper().
+ - fsl/fman: avoid sleeping in atomic context while adding an address
+ - qed: Free RoCE ILT Memory on rmmod qedr
+ - net: qcom/emac: Use proper free methods during TX
+ - net: smsc911x: Fix unload crash when link is up
+ - IB/core: Fix possible crash to access NULL netdev
+ - cxgb4: do not set needs_free_netdev for mgmt dev's
+ - xen-blkfront: move negotiate_mq to cover all cases of new VBDs
+ - xen: xenbus: use put_device() instead of kfree()
+ - hv_netvsc: fix filter flags
+ - hv_netvsc: fix locking for rx_mode
+ - hv_netvsc: fix locking during VF setup
+ - ARM: davinci: fix the GPIO lookup for omapl138-hawk
+ - arm64: Relax ARM_SMCCC_ARCH_WORKAROUND_1 discovery
+ - selftests/vm/run_vmtests: adjust hugetlb size according to nr_cpus
+ - lib/test_kmod.c: fix limit check on number of test devices created
+ - dmaengine: mv_xor_v2: Fix clock resource by adding a register clock
+ - netfilter: ebtables: fix erroneous reject of last rule
+ - can: m_can: change comparison to bitshift when dealing with a mask
+ - can: m_can: select pinctrl state in each suspend/resume function
+ - bnxt_en: Check valid VNIC ID in bnxt_hwrm_vnic_set_tpa().
+ - workqueue: use put_device() instead of kfree()
+ - ipv4: lock mtu in fnhe when received PMTU < net.ipv4.route.min_pmtu
+ - sunvnet: does not support GSO for sctp
+ - KVM: arm/arm64: vgic: Add missing irq_lock to vgic_mmio_read_pending
+ - gpu: ipu-v3: prg: avoid possible array underflow
+ - drm/imx: move arming of the vblank event to atomic_flush
+ - drm/nouveau/bl: fix backlight regression
+ - xfrm: fix rcu_read_unlock usage in xfrm_local_error
+ - iwlwifi: mvm: set the correct tid when we flush the MCAST sta
+ - iwlwifi: mvm: Correctly set IGTK for AP
+ - iwlwifi: mvm: fix error checking for multi/broadcast sta
+ - net: Fix vlan untag for bridge and vlan_dev with reorder_hdr off
+ - vlan: Fix out of order vlan headers with reorder header off
+ - batman-adv: fix header size check in batadv_dbg_arp()
+ - batman-adv: Fix skbuff rcsum on packet reroute
+ - vti4: Don't count header length twice on tunnel setup
+ - ip_tunnel: Clamp MTU to bounds on new link
+ - vti6: Fix dev->max_mtu setting
+ - iwlwifi: mvm: Increase session protection time after CS
+ - iwlwifi: mvm: clear tx queue id when unreserving aggregation queue
+ - iwlwifi: mvm: make sure internal station has a valid id
+ - iwlwifi: mvm: fix array out of bounds reference
+ - drm/tegra: Shutdown on driver unbind
+ - perf/cgroup: Fix child event counting bug
+ - brcmfmac: Fix check for ISO3166 code
+ - kbuild: make scripts/adjust_autoksyms.sh robust against timestamp races
+ - RDMA/ucma: Correct option size check using optlen
+ - RDMA/qedr: fix QP's ack timeout configuration
+ - RDMA/qedr: Fix rc initialization on CNQ allocation failure
+ - RDMA/qedr: Fix QP state initialization race
+ - net/sched: fix idr leak on the error path of tcf_bpf_init()
+ - net/sched: fix idr leak in the error path of tcf_simp_init()
+ - net/sched: fix idr leak in the error path of tcf_act_police_init()
+ - net/sched: fix idr leak in the error path of tcp_pedit_init()
+ - net/sched: fix idr leak in the error path of __tcf_ipt_init()
+ - net/sched: fix idr leak in the error path of tcf_skbmod_init()
+ - net: dsa: Fix functional dsa-loop dependency on FIXED_PHY
+ - drm/ast: Fixed 1280x800 Display Issue
+ - mm/mempolicy.c: avoid use uninitialized preferred_node
+ - mm, thp: do not cause memcg oom for thp
+ - xfrm: Fix transport mode skb control buffer usage.
+ - selftests: ftrace: Add probe event argument syntax testcase
+ - selftests: ftrace: Add a testcase for string type with kprobe_event
+ - selftests: ftrace: Add a testcase for probepoint
+ - drm/amdkfd: Fix scratch memory with HWS enabled
+ - batman-adv: fix multicast-via-unicast transmission with AP isolation
+ - batman-adv: fix packet loss for broadcasted DHCP packets to a server
+ - ARM: 8748/1: mm: Define vdso_start, vdso_end as array
+ - lan78xx: Set ASD in MAC_CR when EEE is enabled.
+ - net: qmi_wwan: add BroadMobi BM806U 2020:2033
+ - bonding: fix the err path for dev hwaddr sync in bond_enslave
+ - net: dsa: mt7530: fix module autoloading for OF platform drivers
+ - net/mlx5: Make eswitch support to depend on switchdev
+ - perf/x86/intel: Fix linear IP of PEBS real_ip on Haswell and later CPUs
+ - x86/alternatives: Fixup alternative_call_2
+ - llc: properly handle dev_queue_xmit() return value
+ - builddeb: Fix header package regarding dtc source links
+ - qede: Fix barrier usage after tx doorbell write.
+ - mm, slab: memcg_link the SLAB's kmem_cache
+ - mm/page_owner: fix recursion bug after changing skip entries
+ - mm/kmemleak.c: wait for scan completion before disabling free
+ - hv_netvsc: enable multicast if necessary
+ - qede: Do not drop rx-checksum invalidated packets.
+ - net: Fix untag for vlan packets without ethernet header
+ - vlan: Fix vlan insertion for packets without ethernet header
+ - net: mvneta: fix enable of all initialized RXQs
+ - sh: fix debug trap failure to process signals before return to user
+ - firmware: dmi_scan: Fix UUID length safety check
+ - nvme: don't send keep-alives to the discovery controller
+ - Btrfs: clean up resources during umount after trans is aborted
+ - Btrfs: fix loss of prealloc extents past i_size after fsync log replay
+ - x86/pgtable: Don't set huge PUD/PMD on non-leaf entries
+ - fs/proc/proc_sysctl.c: fix potential page fault while unregistering sysctl
+ table
+ - swap: divide-by-zero when zero length swap file on ssd
+ - z3fold: fix memory leak
+ - sr: get/drop reference to device in revalidate and check_events
+ - Force log to disk before reading the AGF during a fstrim
+ - cpufreq: CPPC: Initialize shared perf capabilities of CPUs
+ - powerpc/fscr: Enable interrupts earlier before calling get_user()
+ - perf tools: Fix perf builds with clang support
+ - perf clang: Add support for recent clang versions
+ - dp83640: Ensure against premature access to PHY registers after reset
+ - ibmvnic: Zero used TX descriptor counter on reset
+ - mm/ksm: fix interaction with THP
+ - mm: fix races between address_space dereference and free in page_evicatable
+ - mm: thp: fix potential clearing to referenced flag in
+ page_idle_clear_pte_refs_one()
+ - Btrfs: bail out on error during replay_dir_deletes
+ - Btrfs: fix NULL pointer dereference in log_dir_items
+ - btrfs: Fix possible softlock on single core machines
+ - IB/rxe: Fix for oops in rxe_register_device on ppc64le arch
+ - ocfs2/dlm: don't handle migrate lockres if already in shutdown
+ - powerpc/64s/idle: Fix restore of AMOR on POWER9 after deep sleep
+ - sched/rt: Fix rq->clock_update_flags < RQCF_ACT_SKIP warning
+ - x86/mm: Fix bogus warning during EFI bootup, use boot_cpu_has() instead of
+ this_cpu_has() in build_cr3_noflush()
+ - KVM: VMX: raise internal error for exception during invalid protected mode
+ state
+ - lan78xx: Connect phy early
+ - sparc64: Make atomic_xchg() an inline function rather than a macro.
+ - net: bgmac: Fix endian access in bgmac_dma_tx_ring_free()
+ - net: bgmac: Correctly annotate register space
+ - btrfs: tests/qgroup: Fix wrong tree backref level
+ - Btrfs: fix copy_items() return value when logging an inode
+ - btrfs: fix lockdep splat in btrfs_alloc_subvolume_writers
+ - btrfs: qgroup: Fix root item corruption when multiple same source snapshots
+ are created with quota enabled
+ - rxrpc: Fix Tx ring annotation after initial Tx failure
+ - rxrpc: Don't treat call aborts as conn aborts
+ - xen/acpi: off by one in read_acpi_id()
+ - drivers: macintosh: rack-meter: really fix bogus memsets
+ - ACPI: acpi_pad: Fix memory leak in power saving threads
+ - powerpc/mpic: Check if cpu_possible() in mpic_physmask()
+ - ieee802154: ca8210: fix uninitialised data read
+ - ath10k: advertize beacon_int_min_gcd
+ - iommu/amd: Take into account that alloc_dev_data() may return NULL
+ - intel_th: Use correct method of finding hub
+ - m68k: set dma and coherent masks for platform FEC ethernets
+ - iwlwifi: mvm: check if mac80211_queue is valid in iwl_mvm_disable_txq
+ - parisc/pci: Switch LBA PCI bus from Hard Fail to Soft Fail mode
+ - hwmon: (nct6775) Fix writing pwmX_mode
+ - powerpc/perf: Prevent kernel address leak to userspace via BHRB buffer
+ - powerpc/perf: Fix kernel address leak via sampling registers
+ - rsi: fix kernel panic observed on 64bit machine
+ - tools/thermal: tmon: fix for segfault
+ - selftests: Print the test we're running to /dev/kmsg
+ - net/mlx5: Protect from command bit overflow
+ - watchdog: davinci_wdt: fix error handling in davinci_wdt_probe()
+ - ath10k: Fix kernel panic while using worker (ath10k_sta_rc_update_wk)
+ - nvme-pci: disable APST for Samsung NVMe SSD 960 EVO + ASUS PRIME Z370-A
+ - ath9k: fix crash in spectral scan
+ - cxgb4: Setup FW queues before registering netdev
+ - ima: Fix Kconfig to select TPM 2.0 CRB interface
+ - ima: Fallback to the builtin hash algorithm
+ - watchdog: aspeed: Allow configuring for alternate boot
+ - arm: dts: socfpga: fix GIC PPI warning
+ - ext4: don't complain about incorrect features when probing
+ - drm/vmwgfx: Unpin the screen object backup buffer when not used
+ - iommu/mediatek: Fix protect memory setting
+ - cpufreq: cppc_cpufreq: Fix cppc_cpufreq_init() failure path
+ - IB/mlx5: Set the default active rate and width to QDR and 4X
+ - zorro: Set up z->dev.dma_mask for the DMA API
+ - bcache: quit dc->writeback_thread when BCACHE_DEV_DETACHING is set
+ - remoteproc: imx_rproc: Fix an error handling path in 'imx_rproc_probe()'
+ - dt-bindings: add device tree binding for Allwinner H6 main CCU
+ - ACPICA: Events: add a return on failure from acpi_hw_register_read
+ - ACPICA: Fix memory leak on unusual memory leak
+ - ACPICA: acpi: acpica: fix acpi operand cache leak in nseval.c
+ - cxgb4: Fix queue free path of ULD drivers
+ - i2c: mv64xxx: Apply errata delay only in standard mode
+ - KVM: lapic: stop advertising DIRECTED_EOI when in-kernel IOAPIC is in use
+ - perf top: Fix top.call-graph config option reading
+ - perf stat: Fix core dump when flag T is used
+ - IB/core: Honor port_num while resolving GID for IB link layer
+ - drm/amdkfd: add missing include of mm.h
+ - coresight: Use %px to print pcsr instead of %p
+ - regulator: gpio: Fix some error handling paths in 'gpio_regulator_probe()'
+ - spi: bcm-qspi: fIX some error handling paths
+ - net/smc: pay attention to MAX_ORDER for CQ entries
+ - MIPS: ath79: Fix AR724X_PLL_REG_PCIE_CONFIG offset
+ - watchdog: dw: RMW the control register
+ - watchdog: aspeed: Fix translation of reset mode to ctrl register
+ - drm/meson: Fix some error handling paths in 'meson_drv_bind_master()'
+ - drm/meson: Fix an un-handled error path in 'meson_drv_bind_master()'
+ - powerpc: Add missing prototype for arch_irq_work_raise()
+ - f2fs: fix to set KEEP_SIZE bit in f2fs_zero_range
+ - f2fs: fix to clear CP_TRIMMED_FLAG
+ - f2fs: fix to check extent cache in f2fs_drop_extent_tree
+ - perf/core: Fix installing cgroup events on CPU
+ - max17042: propagate of_node to power supply device
+ - perf/core: Fix perf_output_read_group()
+ - drm/panel: simple: Fix the bus format for the Ontat panel
+ - hwmon: (pmbus/max8688) Accept negative page register values
+ - hwmon: (pmbus/adm1275) Accept negative page register values
+ - perf/x86/intel: Properly save/restore the PMU state in the NMI handler
+ - cdrom: do not call check_disk_change() inside cdrom_open()
+ - efi/arm*: Only register page tables when they exist
+ - perf/x86/intel: Fix large period handling on Broadwell CPUs
+ - perf/x86/intel: Fix event update for auto-reload
+ - arm64: dts: qcom: Fix SPI5 config on MSM8996
+ - soc: qcom: wcnss_ctrl: Fix increment in NV upload
+ - gfs2: Fix fallocate chunk size
+ - x86/devicetree: Initialize device tree before using it
+ - x86/devicetree: Fix device IRQ settings in DT
+ - phy: rockchip-emmc: retry calpad busy trimming
+ - ALSA: vmaster: Propagate slave error
+ - phy: qcom-qmp: Fix phy pipe clock gating
+ - drm/bridge: sii902x: Retry status read after DDI I2C
+ - tools: hv: fix compiler warnings about major/target_fname
+ - block: null_blk: fix 'Invalid parameters' when loading module
+ - dmaengine: pl330: fix a race condition in case of threaded irqs
+ - dmaengine: rcar-dmac: Check the done lists in rcar_dmac_chan_get_residue()
+ - enic: enable rq before updating rq descriptors
+ - watchdog: asm9260_wdt: fix error handling in asm9260_wdt_probe()
+ - hwrng: stm32 - add reset during probe
+ - pinctrl: devicetree: Fix dt_to_map_one_config handling of hogs
+ - pinctrl: artpec6: dt: add missing pin group uart5nocts
+ - vfio-ccw: fence off transport mode
+ - dmaengine: qcom: bam_dma: get num-channels and num-ees from dt
+ - drm: omapdrm: dss: Move initialization code from component bind to probe
+ - ARM: dts: dra71-evm: Correct evm_sd regulator max voltage
+ - drm/amdgpu: disable GFX ring and disable PQ wptr in hw_fini
+ - drm/amdgpu: adjust timeout for ib_ring_tests(v2)
+ - net: stmmac: ensure that the device has released ownership before reading
+ data
+ - net: stmmac: ensure that the MSS desc is the last desc to set the own bit
+ - cpufreq: Reorder cpufreq_online() error code path
+ - dpaa_eth: fix SG mapping
+ - PCI: Add function 1 DMA alias quirk for Marvell 88SE9220
+ - udf: Provide saner default for invalid uid / gid
+ - ixgbe: prevent ptp_rx_hang from running when in FILTER_ALL mode
+ - sh_eth: fix TSU init on SH7734/R8A7740
+ - power: supply: ltc2941-battery-gauge: Fix temperature units
+ - ARM: dts: bcm283x: Fix probing of bcm2835-i2s
+ - ARM: dts: bcm283x: Fix pin function of JTAG pins
+ - PCMCIA / PM: Avoid noirq suspend aborts during suspend-to-idle
+ - audit: return on memory error to avoid null pointer dereference
+ - net: stmmac: call correct function in stmmac_mac_config_rx_queues_routing()
+ - rcu: Call touch_nmi_watchdog() while printing stall warnings
+ - pinctrl: sh-pfc: r8a7796: Fix MOD_SEL register pin assignment for SSI pins
+ group
+ - dpaa_eth: fix pause capability advertisement logic
+ - MIPS: Octeon: Fix logging messages with spurious periods after newlines
+ - drm/rockchip: Respect page offset for PRIME mmap calls
+ - x86/apic: Set up through-local-APIC mode on the boot CPU if 'noapic'
+ specified
+ - perf test: Fix test case inet_pton to accept inlines.
+ - perf report: Fix wrong jump arrow
+ - perf tests: Use arch__compare_symbol_names to compare symbols
+ - perf report: Fix memory corruption in --branch-history mode --branch-history
+ - perf tests: Fix dwarf unwind for stripped binaries
+ - selftests/net: fixes psock_fanout eBPF test case
+ - netlabel: If PF_INET6, check sk_buff ip header version
+ - drm: rcar-du: lvds: Fix LVDS startup on R-Car Gen3
+ - drm: rcar-du: lvds: Fix LVDS startup on R-Car Gen2
+ - ARM: dts: at91: tse850: use the correct compatible for the eeprom
+ - regmap: Correct comparison in regmap_cached
+ - i40e: Add delay after EMP reset for firmware to recover
+ - ARM: dts: imx7d: cl-som-imx7: fix pinctrl_enet
+ - ARM: dts: porter: Fix HDMI output routing
+ - regulator: of: Add a missing 'of_node_put()' in an error handling path of
+ 'of_regulator_match()'
+ - pinctrl: mcp23s08: spi: Fix regmap debugfs entries
+ - kdb: make "mdr" command repeat
+ - drm/vmwgfx: Set dmabuf_size when vmw_dmabuf_init is successful
+ - perf tools: Add trace/beauty/generated/ into .gitignore
+ - tools: sync up .h files with the repective arch and uapi .h files
+ - MIPS: xilfpga: Stop generating useless dtb.o
+ - MIPS: xilfpga: Actually include FDT in fitImage
+ - MIPS: Fix build with DEBUG_ZBOOT and MACH_JZ4770
+ - fix breakage caused by d_find_alias() semantics change
+ - Btrfs: fix error handling in btrfs_truncate()
+ - mmc: block: propagate correct returned value in mmc_rpmb_ioctl
+ - arm64: export tishift functions to modules
+ - bcma: fix buffer size caused crash in bcma_core_mips_print_irq()
+ - PM / core: Fix direct_complete handling for devices with no callbacks
+ - ARM: dts: sun4i: Fix incorrect clocks for displays
+ - bnxt_en: Ignore src port field in decap filter nodes
+ - kasan, slub: fix handling of kasan_slab_free hook
+ - riscv/spinlock: Strengthen implementations with fences
+ - platform/x86: dell-smbios: Fix memory leaks in build_tokens_sysfs()
+ - rxrpc: Fix resend event time calculation
+ - i40e: hold the RTNL lock while changing interrupt schemes
+ - hv_netvsc: Fix the return status in RX path
+ - firmware: fix checking for return values for fw_add_devm_name()
+ - bcache: set writeback_rate_update_seconds in range [1, 60] seconds
+ - bcache: fix cached_dev->count usage for bch_cache_set_error()
+ - bcache: stop dc->writeback_rate_update properly
+ - ibmvnic: Fix reset return from closed state
+ - powerpc/vas: Fix cleanup when VAS is not configured
+ - f2fs: flush cp pack except cp pack 2 page at first
+ - drm/amdgpu: Clean sdma wptr register when only enable wptr polling
+ - powerpc/mm/slice: Remove intermediate bitmap copy
+ - powerpc/mm/slice: create header files dedicated to slices
+ - powerpc/mm/slice: Enhance for supporting PPC32
+ - powerpc/mm/slice: Fix hugepage allocation at hint address on 8xx
+ - ibmvnic: Allocate statistics buffers during probe
+ - dt-bindings: display: msm/dsi: Fix the PHY regulator supply props
+ - drm/amd/display: Set vsc pack revision when DPCD revision is >= 1.2
+ - soc: renesas: r8a77970-sysc: fix power area parents
+ - drm/vblank: Data type fixes for 64-bit vblank sequences.
+ - selftests: Add FIB onlink tests
+ - soc: amlogic: meson-gx-pwrc-vpu: fix error on shutdown when domain is
+ powered off
+
+ * arm-smmu-v3 arm-smmu-v3.1.auto: failed to allocate MSIs (LP: #1785282)
+ - ACPICA: iasl: Add SMMUv3 device ID mapping index support
+ - ACPI/IORT: Remove temporary iort_get_id_mapping_index() ACPICA guard
+
+ * Driver iwlwifi for Intel Wireless-AC 9560 is slow and unreliable in kernel
+ 4.15.0-20-generic (LP: #1772467)
+ - scsi: hpsa: disable device during shutdown
+
+ * [Bionic] i2c: xlp9xx: Add SMBAlert support (LP: #1786981)
+ - i2c: xlp9xx: Add support for SMBAlert
+
+ * qeth: don't clobber buffer on async TX completion (LP: #1786057)
+ - s390/qeth: don't clobber buffer on async TX completion
+
+ * Linux 4.15.0-23 crashes during the boot process with a "Unable to handle
+ kernel NULL pointer dereference" message (LP: #1777338)
+ - x86/xen: Add call of speculative_store_bypass_ht_init() to PV paths
+
+ * ThinkPad systems have no HDMI sound when using the nvidia GPU (LP: #1787058)
+ - ACPI / OSI: Add OEM _OSI string to enable NVidia HDMI audio
+
+ * [Bionic] i2c: xlp9xx: Fix case where SSIF read transaction completes early
+ (LP: #1787240)
+ - i2c: xlp9xx: Fix case where SSIF read transaction completes early
+
+ * [Bionic] integrate upstream fix for Cavium zram driver (LP: #1787469)
+ - Revert "UBUNTU: SAUCE: crypto: thunderx_zip: Fix fallout from
+ CONFIG_VMAP_STACK"
+ - crypto: cavium - Fix fallout from CONFIG_VMAP_STACK
+ - crypto: cavium - Limit result reading attempts
+ - crypto: cavium - Prevent division by zero
+ - crypto: cavium - Fix statistics pending request value
+ - crypto: cavium - Fix smp_processor_id() warnings
+
+ * Bugfix for handling of shadow doorbell buffer (LP: #1788222)
+ - nvme-pci: add a memory barrier to nvme_dbbuf_update_and_check_event
+
+ * nvme devices namespace assigned to the wrong controller (LP: #1789227)
+ - nvme/multipath: Fix multipath disabled naming collisions
+
+ * linux-cloud-tools-common: Ensure hv-kvp-daemon.service starts before
+ walinuxagent.service (LP: #1739107)
+ - [Debian] hyper-v -- Ensure that hv-kvp-daemon.service starts before
+ walinuxagent.service
+
+ * hinic interfaces aren't getting predictable names (LP: #1783138)
+ - hinic: Link the logical network device to the pci device in sysfs
+
+ * Suspend fails in Ubuntu and Kubuntu 18.04 but works fine in Ubuntu and
+ Kubuntu 17.10 (and on Kubuntu 18.04 using kernel 4.14.47) (LP: #1774950)
+ - ACPI / LPSS: Avoid PM quirks on suspend and resume from S3
+ - ACPI / LPSS: Avoid PM quirks on suspend and resume from hibernation
+
+ * [Bionic] Bluetooth: Support RTL8723D and RTL8821C Devices (LP: #1784835)
+ - Bluetooth: btrtl: Add RTL8723D and RTL8821C devices
+
+ * CacheFiles: Error: Overlong wait for old active object to go away.
+ (LP: #1776254)
+ - cachefiles: Fix missing clear of the CACHEFILES_OBJECT_ACTIVE flag
+ - cachefiles: Wait rather than BUG'ing on "Unexpected object collision"
+
+ * fscache cookie refcount updated incorrectly during fscache object allocation
+ (LP: #1776277) // fscache cookie refcount updated incorrectly during fscache
+ object allocation (LP: #1776277)
+ - fscache: Fix reference overput in fscache_attach_object() error handling
+
+ * FS-Cache: Assertion failed: FS-Cache: 6 == 5 is false (LP: #1774336)
+ - Revert "UBUNTU: SAUCE: CacheFiles: fix a read_waiter/read_copier race"
+ - fscache: Allow cancelled operations to be enqueued
+ - cachefiles: Fix refcounting bug in backing-file read monitoring
+
+ * SMB3: Fix regression in server reconnect detection (LP: #1786110)
+ - smb3: on reconnect set PreviousSessionId field
+
+ * CVE-2018-1118
+ - vhost: fix info leak due to uninitialized memory
+
+ -- Kleber Sacilotto de Souza <kleber.souza@canonical.com> Mon, 27 Aug 2018 16:45:36 +0200
+
+linux (4.15.0-33.36) bionic; urgency=medium
+
+ * linux: 4.15.0-33.36 -proposed tracker (LP: #1787149)
+
+ * RTNL assertion failure on ipvlan (LP: #1776927)
+ - ipvlan: drop ipv6 dependency
+ - ipvlan: use per device spinlock to protect addrs list updates
+ - SAUCE: fix warning from "ipvlan: drop ipv6 dependency"
+
+ * ubuntu_bpf_jit test failed on Bionic s390x systems (LP: #1753941)
+ - test_bpf: flag tests that cannot be jited on s390
+
+ * HDMI/DP audio can't work on the laptop of Dell Latitude 5495 (LP: #1782689)
+ - drm/nouveau: fix nouveau_dsm_get_client_id()'s return type
+ - drm/radeon: fix radeon_atpx_get_client_id()'s return type
+ - drm/amdgpu: fix amdgpu_atpx_get_client_id()'s return type
+ - platform/x86: apple-gmux: fix gmux_get_client_id()'s return type
+ - ALSA: hda: use PCI_BASE_CLASS_DISPLAY to replace PCI_CLASS_DISPLAY_VGA
+ - vga_switcheroo: set audio client id according to bound GPU id
+
+ * locking sockets broken due to missing AppArmor socket mediation patches
+ (LP: #1780227)
+ - UBUNTU SAUCE: apparmor: fix apparmor mediating locking non-fs, unix sockets
+
+ * Update2 for ocxl driver (LP: #1781436)
+ - ocxl: Fix page fault handler in case of fault on dying process
+
+ * netns: unable to follow an interface that moves to another netns
+ (LP: #1774225)
+ - net: core: Expose number of link up/down transitions
+ - dev: always advertise the new nsid when the netns iface changes
+ - dev: advertise the new ifindex when the netns iface changes
+
+ * [Bionic] Disk IO hangs when using BFQ as io scheduler (LP: #1780066)
+ - block, bfq: fix occurrences of request finish method's old name
+ - block, bfq: remove batches of confusing ifdefs
+ - block, bfq: add requeue-request hook
+
+ * HP ProBook 455 G5 needs mute-led-gpio fixup (LP: #1781763)
+ - ALSA: hda: add mute led support for HP ProBook 455 G5
+
+ * [Bionic] bug fixes to improve stability of the ThunderX2 i2c driver
+ (LP: #1781476)
+ - i2c: xlp9xx: Fix issue seen when updating receive length
+ - i2c: xlp9xx: Make sure the transfer size is not more than
+ I2C_SMBUS_BLOCK_SIZE
+
+ * x86/kvm: fix LAPIC timer drift when guest uses periodic mode (LP: #1778486)
+ - x86/kvm: fix LAPIC timer drift when guest uses periodic mode
+
+ * Please include ax88179_178a and r8152 modules in d-i udeb (LP: #1771823)
+ - [Config:] d-i: Add ax88179_178a and r8152 to nic-modules
+
+ * Nvidia fails after switching its mode (LP: #1778658)
+ - PCI: Restore config space on runtime resume despite being unbound
+
+ * Kernel error "task zfs:pid blocked for more than 120 seconds" (LP: #1781364)
+ - SAUCE: (noup) zfs to 0.7.5-1ubuntu16.3
+
+ * CVE-2018-12232
+ - PATCH 1/1] socket: close race condition between sock_close() and
+ sockfs_setattr()
+
+ * CVE-2018-10323
+ - xfs: set format back to extents if xfs_bmap_extents_to_btree
+
+ * change front mic location for more lenovo m7/8/9xx machines (LP: #1781316)
+ - ALSA: hda/realtek - Fix the problem of two front mics on more machines
+ - ALSA: hda/realtek - two more lenovo models need fixup of MIC_LOCATION
+
+ * Cephfs + fscache: unable to handle kernel NULL pointer dereference at
+ 0000000000000000 IP: jbd2__journal_start+0x22/0x1f0 (LP: #1783246)
+ - ceph: track read contexts in ceph_file_info
+
+ * Touchpad of ThinkPad P52 failed to work with message "lost sync at byte"
+ (LP: #1779802)
+ - Input: elantech - fix V4 report decoding for module with middle key
+ - Input: elantech - enable middle button of touchpads on ThinkPad P52
+
+ * xhci_hcd 0000:00:14.0: Root hub is not suspended (LP: #1779823)
+ - usb: xhci: dbc: Fix lockdep warning
+ - usb: xhci: dbc: Don't decrement runtime PM counter if DBC is not started
+
+ * CVE-2018-13406
+ - video: uvesafb: Fix integer overflow in allocation
+
+ * CVE-2018-10840
+ - ext4: correctly handle a zero-length xattr with a non-zero e_value_offs
+
+ * CVE-2018-11412
+ - ext4: do not allow external inodes for inline data
+
+ * CVE-2018-10881
+ - ext4: clear i_data in ext4_inode_info when removing inline data
+
+ * CVE-2018-12233
+ - jfs: Fix inconsistency between memory allocation and ea_buf->max_size
+
+ * CVE-2018-12904
+ - kvm: nVMX: Enforce cpl=0 for VMX instructions
+
+ * Error parsing PCC subspaces from PCCT (LP: #1528684)
+ - mailbox: PCC: erroneous error message when parsing ACPI PCCT
+
+ * CVE-2018-13094
+ - xfs: don't call xfs_da_shrink_inode with NULL bp
+
+ * other users' coredumps can be read via setgid directory and killpriv bypass
+ (LP: #1779923) // CVE-2018-13405
+ - Fix up non-directory creation in SGID directories
+
+ * Invoking obsolete 'firmware_install' target breaks snap build (LP: #1782166)
+ - snapcraft.yaml: stop invoking the obsolete (and non-existing)
+ 'firmware_install' target
+
+ * snapcraft.yaml: missing ubuntu-retpoline-extract-one script breaks the build
+ (LP: #1782116)
+ - snapcraft.yaml: copy retpoline-extract-one to scripts before build
+
+ * Allow Raven Ridge's audio controller to be runtime suspended (LP: #1782540)
+ - ALSA: hda: Add AZX_DCAPS_PM_RUNTIME for AMD Raven Ridge
+
+ * CVE-2018-11506
+ - sr: pass down correctly sized SCSI sense buffer
+
+ * Bionic update: upstream stable patchset 2018-07-24 (LP: #1783418)
+ - net: Fix a bug in removing queues from XPS map
+ - net/mlx4_core: Fix error handling in mlx4_init_port_info.
+ - net/sched: fix refcnt leak in the error path of tcf_vlan_init()
+ - net: sched: red: avoid hashing NULL child
+ - net/smc: check for missing nlattrs in SMC_PNETID messages
+ - net: test tailroom before appending to linear skb
+ - packet: in packet_snd start writing at link layer allocation
+ - sock_diag: fix use-after-free read in __sk_free
+ - tcp: purge write queue in tcp_connect_init()
+ - vmxnet3: set the DMA mask before the first DMA map operation
+ - vmxnet3: use DMA memory barriers where required
+ - hv_netvsc: empty current transmit aggregation if flow blocked
+ - hv_netvsc: Use the num_online_cpus() for channel limit
+ - hv_netvsc: avoid retry on send during shutdown
+ - hv_netvsc: only wake transmit queue if link is up
+ - hv_netvsc: fix error unwind handling if vmbus_open fails
+ - hv_netvsc: cancel subchannel setup before halting device
+ - hv_netvsc: fix race in napi poll when rescheduling
+ - hv_netvsc: defer queue selection to VF
+ - hv_netvsc: disable NAPI before channel close
+ - hv_netvsc: use RCU to fix concurrent rx and queue changes
+ - hv_netvsc: change GPAD teardown order on older versions
+ - hv_netvsc: common detach logic
+ - hv_netvsc: Use Windows version instead of NVSP version on GPAD teardown
+ - hv_netvsc: Split netvsc_revoke_buf() and netvsc_teardown_gpadl()
+ - hv_netvsc: Ensure correct teardown message sequence order
+ - hv_netvsc: Fix a network regression after ifdown/ifup
+ - sparc: vio: use put_device() instead of kfree()
+ - ext2: fix a block leak
+ - s390: add assembler macros for CPU alternatives
+ - s390: move expoline assembler macros to a header
+ - s390/crc32-vx: use expoline for indirect branches
+ - s390/lib: use expoline for indirect branches
+ - s390/ftrace: use expoline for indirect branches
+ - s390/kernel: use expoline for indirect branches
+ - s390: move spectre sysfs attribute code
+ - s390: extend expoline to BC instructions
+ - s390: use expoline thunks in the BPF JIT
+ - scsi: sg: allocate with __GFP_ZERO in sg_build_indirect()
+ - scsi: zfcp: fix infinite iteration on ERP ready list
+ - loop: don't call into filesystem while holding lo_ctl_mutex
+ - loop: fix LOOP_GET_STATUS lock imbalance
+ - cfg80211: limit wiphy names to 128 bytes
+ - hfsplus: stop workqueue when fill_super() failed
+ - x86/kexec: Avoid double free_page() upon do_kexec_load() failure
+ - usb: gadget: f_uac2: fix bFirstInterface in composite gadget
+ - usb: dwc3: Undo PHY init if soft reset fails
+ - usb: dwc3: omap: don't miss events during suspend/resume
+ - usb: gadget: core: Fix use-after-free of usb_request
+ - usb: gadget: fsl_udc_core: fix ep valid checks
+ - usb: dwc2: Fix dwc2_hsotg_core_init_disconnected()
+ - usb: cdc_acm: prevent race at write to acm while system resumes
+ - net: usbnet: fix potential deadlock on 32bit hosts
+ - ARM: dts: imx7d-sdb: Fix regulator-usb-otg2-vbus node name
+ - usb: host: xhci-plat: revert "usb: host: xhci-plat: enable clk in resume
+ timing"
+ - USB: OHCI: Fix NULL dereference in HCDs using HCD_LOCAL_MEM
+ - net/usb/qmi_wwan.c: Add USB id for lt4120 modem
+ - net-usb: add qmi_wwan if on lte modem wistron neweb d18q1
+ - Bluetooth: btusb: Add USB ID 7392:a611 for Edimax EW-7611ULB
+ - ALSA: usb-audio: Add native DSD support for Luxman DA-06
+ - usb: dwc3: Add SoftReset PHY synchonization delay
+ - usb: dwc3: Update DWC_usb31 GTXFIFOSIZ reg fields
+ - usb: dwc3: Makefile: fix link error on randconfig
+ - xhci: zero usb device slot_id member when disabling and freeing a xhci slot
+ - usb: dwc2: Fix interval type issue
+ - usb: dwc2: hcd: Fix host channel halt flow
+ - usb: dwc2: host: Fix transaction errors in host mode
+ - usb: gadget: ffs: Let setup() return USB_GADGET_DELAYED_STATUS
+ - usb: gadget: ffs: Execute copy_to_user() with USER_DS set
+ - usbip: Correct maximum value of CONFIG_USBIP_VHCI_HC_PORTS
+ - usb: gadget: udc: change comparison to bitshift when dealing with a mask
+ - usb: gadget: composite: fix incorrect handling of OS desc requests
+ - media: lgdt3306a: Fix module count mismatch on usb unplug
+ - media: em28xx: USB bulk packet size fix
+ - Bluetooth: btusb: Add device ID for RTL8822BE
+ - xhci: Show what USB release number the xHC supports from protocol capablity
+ - staging: bcm2835-audio: Release resources on module_exit()
+ - staging: lustre: fix bug in osc_enter_cache_try
+ - staging: fsl-dpaa2/eth: Fix incorrect casts
+ - staging: rtl8192u: return -ENOMEM on failed allocation of priv->oldaddr
+ - staging: ks7010: Use constants from ieee80211_eid instead of literal ints.
+ - staging: lustre: lmv: correctly iput lmo_root
+ - crypto: inside-secure - wait for the request to complete if in the backlog
+ - crypto: atmel-aes - fix the keys zeroing on errors
+ - crypto: ccp - don't disable interrupts while setting up debugfs
+ - crypto: inside-secure - do not process request if no command was issued
+ - crypto: inside-secure - fix the cache_len computation
+ - crypto: inside-secure - fix the extra cache computation
+ - crypto: sunxi-ss - Add MODULE_ALIAS to sun4i-ss
+ - crypto: inside-secure - fix the invalidation step during cra_exit
+ - scsi: mpt3sas: fix an out of bound write
+ - scsi: ufs: Enable quirk to ignore sending WRITE_SAME command
+ - scsi: bnx2fc: Fix check in SCSI completion handler for timed out request
+ - scsi: sym53c8xx_2: iterator underflow in sym_getsync()
+ - scsi: mptfusion: Add bounds check in mptctl_hp_targetinfo()
+ - scsi: qla2xxx: Avoid triggering undefined behavior in
+ qla2x00_mbx_completion()
+ - scsi: storvsc: Increase cmd_per_lun for higher speed devices
+ - scsi: qedi: Fix truncation of CHAP name and secret
+ - scsi: aacraid: fix shutdown crash when init fails
+ - scsi: qla4xxx: skip error recovery in case of register disconnect.
+ - scsi: qedi: Fix kernel crash during port toggle
+ - scsi: mpt3sas: Do not mark fw_event workqueue as WQ_MEM_RECLAIM
+ - scsi: sd: Keep disk read-only when re-reading partition
+ - scsi: iscsi_tcp: set BDI_CAP_STABLE_WRITES when data digest enabled
+ - scsi: aacraid: Insure command thread is not recursively stopped
+ - scsi: core: Make SCSI Status CONDITION MET equivalent to GOOD
+ - scsi: mvsas: fix wrong endianness of sgpio api
+ - ASoC: hdmi-codec: Fix module unloading caused kernel crash
+ - ASoC: rockchip: rk3288-hdmi-analog: Select needed codecs
+ - ASoC: samsung: odroid: Fix 32000 sample rate handling
+ - ASoC: topology: create TLV data for dapm widgets
+ - ASoC: samsung: i2s: Ensure the RCLK rate is properly determined
+ - clk: rockchip: Fix wrong parent for SDMMC phase clock for rk3228
+ - clk: Don't show the incorrect clock phase
+ - clk: hisilicon: mark wdt_mux_p[] as const
+ - clk: tegra: Fix pll_u rate configuration
+ - clk: rockchip: Prevent calculating mmc phase if clock rate is zero
+ - clk: samsung: s3c2410: Fix PLL rates
+ - clk: samsung: exynos7: Fix PLL rates
+ - clk: samsung: exynos5260: Fix PLL rates
+ - clk: samsung: exynos5433: Fix PLL rates
+ - clk: samsung: exynos5250: Fix PLL rates
+ - clk: samsung: exynos3250: Fix PLL rates
+ - media: dmxdev: fix error code for invalid ioctls
+ - media: Don't let tvp5150_get_vbi() go out of vbi_ram_default array
+ - media: ov5645: add missing of_node_put() in error path
+ - media: cx23885: Override 888 ImpactVCBe crystal frequency
+ - media: cx23885: Set subdev host data to clk_freq pointer
+ - media: s3c-camif: fix out-of-bounds array access
+ - media: lgdt3306a: Fix a double kfree on i2c device remove
+ - media: em28xx: Add Hauppauge SoloHD/DualHD bulk models
+ - media: v4l: vsp1: Fix display stalls when requesting too many inputs
+ - media: i2c: adv748x: fix HDMI field heights
+ - media: vb2: Fix videobuf2 to map correct area
+ - media: vivid: fix incorrect capabilities for radio
+ - media: cx25821: prevent out-of-bounds read on array card
+ - serial: xuartps: Fix out-of-bounds access through DT alias
+ - serial: sh-sci: Fix out-of-bounds access through DT alias
+ - serial: samsung: Fix out-of-bounds access through serial port index
+ - serial: mxs-auart: Fix out-of-bounds access through serial port index
+ - serial: imx: Fix out-of-bounds access through serial port index
+ - serial: fsl_lpuart: Fix out-of-bounds access through DT alias
+ - serial: arc_uart: Fix out-of-bounds access through DT alias
+ - serial: 8250: Don't service RX FIFO if interrupts are disabled
+ - serial: altera: ensure port->regshift is honored consistently
+ - rtc: snvs: Fix usage of snvs_rtc_enable
+ - rtc: hctosys: Ensure system time doesn't overflow time_t
+ - rtc: rk808: fix possible race condition
+ - rtc: m41t80: fix race conditions
+ - rtc: tx4939: avoid unintended sign extension on a 24 bit shift
+ - rtc: rp5c01: fix possible race condition
+ - rtc: goldfish: Add missing MODULE_LICENSE
+ - cxgb4: Correct ntuple mask validation for hash filters
+ - net: dsa: bcm_sf2: Fix RX_CLS_LOC_ANY overwrite for last rule
+ - net: dsa: Do not register devlink for unused ports
+ - net: dsa: bcm_sf2: Fix IPv6 rules and chain ID
+ - net: dsa: bcm_sf2: Fix IPv6 rule half deletion
+ - 3c59x: convert to generic DMA API
+ - net: ip6_gre: Request headroom in __gre6_xmit()
+ - net: ip6_gre: Split up ip6gre_tnl_link_config()
+ - net: ip6_gre: Split up ip6gre_tnl_change()
+ - net: ip6_gre: Split up ip6gre_newlink()
+ - net: ip6_gre: Split up ip6gre_changelink()
+ - qed: LL2 flush isles when connection is closed
+ - qed: Fix possibility of list corruption during rmmod flows
+ - qed: Fix LL2 race during connection terminate
+ - powerpc: Move default security feature flags
+ - Bluetooth: btusb: Add support for Intel Bluetooth device 22560 [8087:0026]
+ - staging: fsl-dpaa2/eth: Fix incorrect kfree
+ - crypto: inside-secure - move the digest to the request context
+ - scsi: lpfc: Fix NVME Initiator FirstBurst
+ - serial: mvebu-uart: fix tx lost characters
+
+ * Bionic update: upstream stable patchset 2018-07-20 (LP: #1782846)
+ - usbip: usbip_host: refine probe and disconnect debug msgs to be useful
+ - usbip: usbip_host: delete device from busid_table after rebind
+ - usbip: usbip_host: run rebind from exit when module is removed
+ - usbip: usbip_host: fix NULL-ptr deref and use-after-free errors
+ - usbip: usbip_host: fix bad unlock balance during stub_probe()
+ - ALSA: usb: mixer: volume quirk for CM102-A+/102S+
+ - ALSA: hda: Add Lenovo C50 All in one to the power_save blacklist
+ - ALSA: control: fix a redundant-copy issue
+ - spi: pxa2xx: Allow 64-bit DMA
+ - spi: bcm-qspi: Avoid setting MSPI_CDRAM_PCS for spi-nor master
+ - spi: bcm-qspi: Always read and set BSPI_MAST_N_BOOT_CTRL
+ - KVM: arm/arm64: VGIC/ITS save/restore: protect kvm_read_guest() calls
+ - KVM: arm/arm64: VGIC/ITS: protect kvm_read_guest() calls with SRCU lock
+ - vfio: ccw: fix cleanup if cp_prefetch fails
+ - tracing/x86/xen: Remove zero data size trace events
+ trace_xen_mmu_flush_tlb{_all}
+ - tee: shm: fix use-after-free via temporarily dropped reference
+ - netfilter: nf_tables: free set name in error path
+ - netfilter: nf_tables: can't fail after linking rule into active rule list
+ - netfilter: nf_socket: Fix out of bounds access in nf_sk_lookup_slow_v{4,6}
+ - i2c: designware: fix poll-after-enable regression
+ - powerpc/powernv: Fix NVRAM sleep in invalid context when crashing
+ - drm: Match sysfs name in link removal to link creation
+ - lib/test_bitmap.c: fix bitmap optimisation tests to report errors correctly
+ - radix tree: fix multi-order iteration race
+ - mm: don't allow deferred pages with NEED_PER_CPU_KM
+ - drm/i915/gen9: Add WaClearHIZ_WM_CHICKEN3 for bxt and glk
+ - s390/qdio: fix access to uninitialized qdio_q fields
+ - s390/qdio: don't release memory in qdio_setup_irq()
+ - s390: remove indirect branch from do_softirq_own_stack
+ - x86/pkeys: Override pkey when moving away from PROT_EXEC
+ - x86/pkeys: Do not special case protection key 0
+ - efi: Avoid potential crashes, fix the 'struct efi_pci_io_protocol_32'
+ definition for mixed mode
+ - ARM: 8771/1: kprobes: Prohibit kprobes on do_undefinstr
+ - x86/mm: Drop TS_COMPAT on 64-bit exec() syscall
+ - tick/broadcast: Use for_each_cpu() specially on UP kernels
+ - ARM: 8769/1: kprobes: Fix to use get_kprobe_ctlblk after irq-disabed
+ - ARM: 8770/1: kprobes: Prohibit probing on optimized_callback
+ - ARM: 8772/1: kprobes: Prohibit kprobes on get_user functions
+ - Btrfs: fix xattr loss after power failure
+ - Btrfs: send, fix invalid access to commit roots due to concurrent
+ snapshotting
+ - btrfs: property: Set incompat flag if lzo/zstd compression is set
+ - btrfs: fix crash when trying to resume balance without the resume flag
+ - btrfs: Split btrfs_del_delalloc_inode into 2 functions
+ - btrfs: Fix delalloc inodes invalidation during transaction abort
+ - btrfs: fix reading stale metadata blocks after degraded raid1 mounts
+ - xhci: Fix USB3 NULL pointer dereference at logical disconnect.
+ - KVM: arm/arm64: Properly protect VGIC locks from IRQs
+ - KVM: arm/arm64: VGIC/ITS: Promote irq_lock() in update_affinity
+ - hwmon: (k10temp) Fix reading critical temperature register
+ - hwmon: (k10temp) Use API function to access System Management Network
+ - vsprintf: Replace memory barrier with static_key for random_ptr_key update
+ - x86/amd_nb: Add support for Raven Ridge CPUs
+ - x86/apic/x2apic: Initialize cluster ID properly
+
+ * Bionic update: upstream stable patchset 2018-07-09 (LP: #1780858)
+ - 8139too: Use disable_irq_nosync() in rtl8139_poll_controller()
+ - bridge: check iface upper dev when setting master via ioctl
+ - dccp: fix tasklet usage
+ - ipv4: fix fnhe usage by non-cached routes
+ - ipv4: fix memory leaks in udp_sendmsg, ping_v4_sendmsg
+ - llc: better deal with too small mtu
+ - net: ethernet: sun: niu set correct packet size in skb
+ - net: ethernet: ti: cpsw: fix packet leaking in dual_mac mode
+ - net/mlx4_en: Fix an error handling path in 'mlx4_en_init_netdev()'
+ - net/mlx4_en: Verify coalescing parameters are in range
+ - net/mlx5e: Err if asked to offload TC match on frag being first
+ - net/mlx5: E-Switch, Include VF RDMA stats in vport statistics
+ - net sched actions: fix refcnt leak in skbmod
+ - net_sched: fq: take care of throttled flows before reuse
+ - net: support compat 64-bit time in {s,g}etsockopt
+ - net/tls: Don't recursively call push_record during tls_write_space callbacks
+ - net/tls: Fix connection stall on partial tls record
+ - openvswitch: Don't swap table in nlattr_set() after OVS_ATTR_NESTED is found
+ - qmi_wwan: do not steal interfaces from class drivers
+ - r8169: fix powering up RTL8168h
+ - rds: do not leak kernel memory to user land
+ - sctp: delay the authentication for the duplicated cookie-echo chunk
+ - sctp: fix the issue that the cookie-ack with auth can't get processed
+ - sctp: handle two v4 addrs comparison in sctp_inet6_cmp_addr
+ - sctp: remove sctp_chunk_put from fail_mark err path in
+ sctp_ulpevent_make_rcvmsg
+ - sctp: use the old asoc when making the cookie-ack chunk in dupcook_d
+ - tcp_bbr: fix to zero idle_restart only upon S/ACKed data
+ - tcp: ignore Fast Open on repair mode
+ - tg3: Fix vunmap() BUG_ON() triggered from tg3_free_consistent().
+ - bonding: do not allow rlb updates to invalid mac
+ - bonding: send learning packets for vlans on slave
+ - net: sched: fix error path in tcf_proto_create() when modules are not
+ configured
+ - net/mlx5e: TX, Use correct counter in dma_map error flow
+ - net/mlx5: Avoid cleaning flow steering table twice during error flow
+ - hv_netvsc: set master device
+ - ipv6: fix uninit-value in ip6_multipath_l3_keys()
+ - net/mlx5e: Allow offloading ipv4 header re-write for icmp
+ - nsh: fix infinite loop
+ - udp: fix SO_BINDTODEVICE
+ - l2tp: revert "l2tp: fix missing print session offset info"
+ - proc: do not access cmdline nor environ from file-backed areas
+ - net/smc: restrict non-blocking connect finish
+ - mlxsw: spectrum_switchdev: Do not remove mrouter port from MDB's ports list
+ - net/mlx5e: DCBNL fix min inline header size for dscp
+ - net: systemport: Correclty disambiguate driver instances
+ - sctp: clear the new asoc's stream outcnt in sctp_stream_update
+ - tcp: restore autocorking
+ - tipc: fix one byte leak in tipc_sk_set_orig_addr()
+ - hv_netvsc: Fix net device attach on older Windows hosts
+
+ * Bionic update: upstream stable patchset 2018-07-06 (LP: #1780499)
+ - ext4: prevent right-shifting extents beyond EXT_MAX_BLOCKS
+ - ipvs: fix rtnl_lock lockups caused by start_sync_thread
+ - netfilter: ebtables: don't attempt to allocate 0-sized compat array
+ - kcm: Call strp_stop before strp_done in kcm_attach
+ - crypto: af_alg - fix possible uninit-value in alg_bind()
+ - netlink: fix uninit-value in netlink_sendmsg
+ - net: fix rtnh_ok()
+ - net: initialize skb->peeked when cloning
+ - net: fix uninit-value in __hw_addr_add_ex()
+ - dccp: initialize ireq->ir_mark
+ - ipv4: fix uninit-value in ip_route_output_key_hash_rcu()
+ - soreuseport: initialise timewait reuseport field
+ - inetpeer: fix uninit-value in inet_getpeer
+ - memcg: fix per_node_info cleanup
+ - perf: Remove superfluous allocation error check
+ - tcp: fix TCP_REPAIR_QUEUE bound checking
+ - bdi: wake up concurrent wb_shutdown() callers.
+ - bdi: Fix oops in wb_workfn()
+ - gpioib: do not free unrequested descriptors
+ - gpio: fix aspeed_gpio unmask irq
+ - gpio: fix error path in lineevent_create
+ - rfkill: gpio: fix memory leak in probe error path
+ - libata: Apply NOLPM quirk for SanDisk SD7UB3Q*G1001 SSDs
+ - dm integrity: use kvfree for kvmalloc'd memory
+ - tracing: Fix regex_match_front() to not over compare the test string
+ - z3fold: fix reclaim lock-ups
+ - mm: sections are not offlined during memory hotremove
+ - mm, oom: fix concurrent munlock and oom reaper unmap, v3
+ - ceph: fix rsize/wsize capping in ceph_direct_read_write()
+ - can: kvaser_usb: Increase correct stats counter in kvaser_usb_rx_can_msg()
+ - can: hi311x: Acquire SPI lock on ->do_get_berr_counter
+ - can: hi311x: Work around TX complete interrupt erratum
+ - drm/vc4: Fix scaling of uni-planar formats
+ - drm/i915: Fix drm:intel_enable_lvds ERROR message in kernel log
+ - drm/atomic: Clean old_state/new_state in drm_atomic_state_default_clear()
+ - drm/atomic: Clean private obj old_state/new_state in
+ drm_atomic_state_default_clear()
+ - net: atm: Fix potential Spectre v1
+ - atm: zatm: Fix potential Spectre v1
+ - cpufreq: schedutil: Avoid using invalid next_freq
+ - Revert "Bluetooth: btusb: Fix quirk for Atheros 1525/QCA6174"
+ - Bluetooth: btusb: Only check needs_reset_resume DMI table for QCA rome
+ chipsets
+ - thermal: exynos: Reading temperature makes sense only when TMU is turned on
+ - thermal: exynos: Propagate error value from tmu_read()
+ - nvme: add quirk to force medium priority for SQ creation
+ - smb3: directory sync should not return an error
+ - sched/autogroup: Fix possible Spectre-v1 indexing for sched_prio_to_weight[]
+ - tracing/uprobe_event: Fix strncpy corner case
+ - perf/x86: Fix possible Spectre-v1 indexing for hw_perf_event cache_*
+ - perf/x86/cstate: Fix possible Spectre-v1 indexing for pkg_msr
+ - perf/x86/msr: Fix possible Spectre-v1 indexing in the MSR driver
+ - perf/core: Fix possible Spectre-v1 indexing for ->aux_pages[]
+ - perf/x86: Fix possible Spectre-v1 indexing for x86_pmu::event_map()
+ - i2c: dev: prevent ZERO_SIZE_PTR deref in i2cdev_ioctl_rdwr()
+ - bdi: Fix use after free bug in debugfs_remove()
+ - drm/ttm: Use GFP_TRANSHUGE_LIGHT for allocating huge pages
+ - drm/i915: Adjust eDP's logical vco in a reliable place.
+ - drm/nouveau/ttm: don't dereference nvbo::cli, it can outlive client
+ - sched/core: Fix possible Spectre-v1 indexing for sched_prio_to_weight[]
+
+ * Bionic update: upstream stable patchset 2018-06-26 (LP: #1778759)
+ - percpu: include linux/sched.h for cond_resched()
+ - ACPI / button: make module loadable when booted in non-ACPI mode
+ - USB: serial: option: Add support for Quectel EP06
+ - ALSA: hda - Fix incorrect usage of IS_REACHABLE()
+ - ALSA: pcm: Check PCM state at xfern compat ioctl
+ - ALSA: seq: Fix races at MIDI encoding in snd_virmidi_output_trigger()
+ - ALSA: dice: fix kernel NULL pointer dereference due to invalid calculation
+ for array index
+ - ALSA: aloop: Mark paused device as inactive
+ - ALSA: aloop: Add missing cable lock to ctl API callbacks
+ - tracepoint: Do not warn on ENOMEM
+ - scsi: target: Fix fortify_panic kernel exception
+ - Input: leds - fix out of bound access
+ - Input: atmel_mxt_ts - add touchpad button mapping for Samsung Chromebook Pro
+ - rtlwifi: btcoex: Add power_on_setting routine
+ - rtlwifi: cleanup 8723be ant_sel definition
+ - xfs: prevent creating negative-sized file via INSERT_RANGE
+ - RDMA/cxgb4: release hw resources on device removal
+ - RDMA/ucma: Allow resolving address w/o specifying source address
+ - RDMA/mlx5: Fix multiple NULL-ptr deref errors in rereg_mr flow
+ - RDMA/mlx5: Protect from shift operand overflow
+ - NET: usb: qmi_wwan: add support for ublox R410M PID 0x90b2
+ - IB/mlx5: Use unlimited rate when static rate is not supported
+ - IB/hfi1: Fix handling of FECN marked multicast packet
+ - IB/hfi1: Fix loss of BECN with AHG
+ - IB/hfi1: Fix NULL pointer dereference when invalid num_vls is used
+ - iw_cxgb4: Atomically flush per QP HW CQEs
+ - drm/vmwgfx: Fix a buffer object leak
+ - drm/bridge: vga-dac: Fix edid memory leak
+ - test_firmware: fix setting old custom fw path back on exit, second try
+ - errseq: Always report a writeback error once
+ - USB: serial: visor: handle potential invalid device configuration
+ - usb: dwc3: gadget: Fix list_del corruption in dwc3_ep_dequeue
+ - USB: Accept bulk endpoints with 1024-byte maxpacket
+ - USB: serial: option: reimplement interface masking
+ - USB: serial: option: adding support for ublox R410M
+ - usb: musb: host: fix potential NULL pointer dereference
+ - usb: musb: trace: fix NULL pointer dereference in musb_g_tx()
+ - platform/x86: asus-wireless: Fix NULL pointer dereference
+ - irqchip/qcom: Fix check for spurious interrupts
+ - tracing: Fix bad use of igrab in trace_uprobe.c
+ - [Config] CONFIG_ARM64_ERRATUM_1024718=y
+ - arm64: Add work around for Arm Cortex-A55 Erratum 1024718
+ - Input: atmel_mxt_ts - add touchpad button mapping for Samsung Chromebook Pro
+ - infiniband: mlx5: fix build errors when INFINIBAND_USER_ACCESS=m
+ - btrfs: Take trans lock before access running trans in check_delayed_ref
+ - drm/vc4: Make sure vc4_bo_{inc,dec}_usecnt() calls are balanced
+ - xhci: Fix use-after-free in xhci_free_virt_device
+ - platform/x86: Kconfig: Fix dell-laptop dependency chain.
+ - KVM: x86: remove APIC Timer periodic/oneshot spikes
+ - clocksource: Allow clocksource_mark_unstable() on unregistered clocksources
+ - clocksource: Initialize cs->wd_list
+ - clocksource: Consistent de-rate when marking unstable
+
+ * Bionic update: upstream stable patchset 2018-06-22 (LP: #1778265)
+ - ext4: set h_journal if there is a failure starting a reserved handle
+ - ext4: add MODULE_SOFTDEP to ensure crc32c is included in the initramfs
+ - ext4: add validity checks for bitmap block numbers
+ - ext4: fix bitmap position validation
+ - random: fix possible sleeping allocation from irq context
+ - random: rate limit unseeded randomness warnings
+ - usbip: usbip_event: fix to not print kernel pointer address
+ - usbip: usbip_host: fix to hold parent lock for device_attach() calls
+ - usbip: vhci_hcd: Fix usb device and sockfd leaks
+ - usbip: vhci_hcd: check rhport before using in vhci_hub_control()
+ - Revert "xhci: plat: Register shutdown for xhci_plat"
+ - USB: serial: simple: add libtransistor console
+ - USB: serial: ftdi_sio: use jtag quirk for Arrow USB Blaster
+ - USB: serial: cp210x: add ID for NI USB serial console
+ - usb: core: Add quirk for HP v222w 16GB Mini
+ - USB: Increment wakeup count on remote wakeup.
+ - ALSA: usb-audio: Skip broken EU on Dell dock USB-audio
+ - virtio: add ability to iterate over vqs
+ - virtio_console: don't tie bufs to a vq
+ - virtio_console: free buffers after reset
+ - virtio_console: drop custom control queue cleanup
+ - virtio_console: move removal code
+ - virtio_console: reset on out of memory
+ - drm/virtio: fix vq wait_event condition
+ - tty: Don't call panic() at tty_ldisc_init()
+ - tty: n_gsm: Fix long delays with control frame timeouts in ADM mode
+ - tty: n_gsm: Fix DLCI handling for ADM mode if debug & 2 is not set
+ - tty: Avoid possible error pointer dereference at tty_ldisc_restore().
+ - tty: Use __GFP_NOFAIL for tty_ldisc_get()
+ - ALSA: dice: fix OUI for TC group
+ - ALSA: dice: fix error path to destroy initialized stream data
+ - ALSA: hda - Skip jack and others for non-existing PCM streams
+ - ALSA: opl3: Hardening for potential Spectre v1
+ - ALSA: asihpi: Hardening for potential Spectre v1
+ - ALSA: hdspm: Hardening for potential Spectre v1
+ - ALSA: rme9652: Hardening for potential Spectre v1
+ - ALSA: control: Hardening for potential Spectre v1
+ - ALSA: pcm: Return negative delays from SNDRV_PCM_IOCTL_DELAY.
+ - ALSA: core: Report audio_tstamp in snd_pcm_sync_ptr
+ - ALSA: seq: oss: Fix unbalanced use lock for synth MIDI device
+ - ALSA: seq: oss: Hardening for potential Spectre v1
+ - ALSA: hda: Hardening for potential Spectre v1
+ - ALSA: hda/realtek - Add some fixes for ALC233
+ - ALSA: hda/realtek - Update ALC255 depop optimize
+ - ALSA: hda/realtek - change the location for one of two front mics
+ - mtd: spi-nor: cadence-quadspi: Fix page fault kernel panic
+ - mtd: cfi: cmdset_0001: Do not allow read/write to suspend erase block.
+ - mtd: cfi: cmdset_0001: Workaround Micron Erase suspend bug.
+ - mtd: cfi: cmdset_0002: Do not allow read/write to suspend erase block.
+ - mtd: rawnand: tango: Fix struct clk memory leak
+ - kobject: don't use WARN for registration failures
+ - scsi: sd: Defer spinning up drive while SANITIZE is in progress
+ - bfq-iosched: ensure to clear bic/bfqq pointers when preparing request
+ - vfio: ccw: process ssch with interrupts disabled
+ - ANDROID: binder: prevent transactions into own process.
+ - PCI: aardvark: Fix logic in advk_pcie_{rd,wr}_conf()
+ - PCI: aardvark: Set PIO_ADDR_LS correctly in advk_pcie_rd_conf()
+ - PCI: aardvark: Use ISR1 instead of ISR0 interrupt in legacy irq mode
+ - PCI: aardvark: Fix PCIe Max Read Request Size setting
+ - ARM: amba: Make driver_override output consistent with other buses
+ - ARM: amba: Fix race condition with driver_override
+ - ARM: amba: Don't read past the end of sysfs "driver_override" buffer
+ - ARM: socfpga_defconfig: Remove QSPI Sector 4K size force
+ - KVM: arm/arm64: Close VMID generation race
+ - crypto: drbg - set freed buffers to NULL
+ - ASoC: fsl_esai: Fix divisor calculation failure at lower ratio
+ - libceph: un-backoff on tick when we have a authenticated session
+ - libceph: reschedule a tick in finish_hunting()
+ - libceph: validate con->state at the top of try_write()
+ - fpga-manager: altera-ps-spi: preserve nCONFIG state
+ - earlycon: Use a pointer table to fix __earlycon_table stride
+ - drm/amdgpu: set COMPUTE_PGM_RSRC1 for SGPR/VGPR clearing shaders
+ - drm/i915: Enable display WA#1183 from its correct spot
+ - objtool, perf: Fix GCC 8 -Wrestrict error
+ - tools/lib/subcmd/pager.c: do not alias select() params
+ - x86/ipc: Fix x32 version of shmid64_ds and msqid64_ds
+ - x86/smpboot: Don't use mwait_play_dead() on AMD systems
+ - x86/microcode/intel: Save microcode patch unconditionally
+ - x86/microcode: Do not exit early from __reload_late()
+ - tick/sched: Do not mess with an enqueued hrtimer
+ - arm/arm64: KVM: Add PSCI version selection API
+ - powerpc/eeh: Fix race with driver un/bind
+ - serial: mvebu-uart: Fix local flags handling on termios update
+ - block: do not use interruptible wait anywhere
+ - ASoC: dmic: Fix clock parenting
+ - PCI / PM: Do not clear state_saved in pci_pm_freeze() when smart suspend is
+ set
+ - module: Fix display of wrong module .text address
+ - drm/edid: Reset more of the display info
+ - drm/i915/fbdev: Enable late fbdev initial configuration
+ - drm/i915/audio: set minimum CD clock to twice the BCLK
+ - drm/amd/display: Fix deadlock when flushing irq
+ - drm/amd/display: Disallow enabling CRTC without primary plane with FB
+
+ * Bionic update: upstream stable patchset 2018-06-22 (LP: #1778265) //
+ CVE-2018-1108.
+ - random: set up the NUMA crng instances after the CRNG is fully initialized
+
+ * Ryzen/Raven Ridge USB ports do not work (LP: #1756700)
+ - xhci: Fix USB ports for Dell Inspiron 5775
+
+ * [Ubuntu 1804][boston][ixgbe] EEH causes kernel BUG at /build/linux-
+ jWa1Fv/linux-4.15.0/drivers/pci/msi.c:352 (i2S) (LP: #1776389)
+ - ixgbe/ixgbevf: Free IRQ when PCI error recovery removes the device
+
+ * Need fix to aacraid driver to prevent panic (LP: #1770095)
+ - scsi: aacraid: Correct hba_send to include iu_type
+
+ * kernel: Fix arch random implementation (LP: #1775391)
+ - s390/archrandom: Rework arch random implementation.
+
+ * kernel: Fix memory leak on CCA and EP11 CPRB processing. (LP: #1775390)
+ - s390/zcrypt: Fix CCA and EP11 CPRB processing failure memory leak.
+
+ * Various fixes for CXL kernel module (LP: #1774471)
+ - cxl: Remove function write_timebase_ctrl_psl9() for PSL9
+ - cxl: Set the PBCQ Tunnel BAR register when enabling capi mode
+ - cxl: Report the tunneled operations status
+ - cxl: Configure PSL to not use APC virtual machines
+ - cxl: Disable prefault_mode in Radix mode
+
+ * Bluetooth not working (LP: #1764645)
+ - Bluetooth: btusb: Apply QCA Rome patches for some ATH3012 models
+
+ * linux-snapdragon: wcn36xx: mac address generation on boot (LP: #1776491)
+ - [Config] arm64: snapdragon: WCN36XX_SNAPDRAGON_HACKS=y
+ - SAUCE: wcn36xx: read MAC from file or randomly generate one
+
+ * fscache: Fix hanging wait on page discarded by writeback (LP: #1777029)
+ - fscache: Fix hanging wait on page discarded by writeback
+
+ -- Kleber Sacilotto de Souza <kleber.souza@canonical.com> Wed, 15 Aug 2018 14:50:38 +0200
+
+linux (4.15.0-32.35) bionic; urgency=medium
+
+ [ Stefan Bader ]
+ * CVE-2018-3620 // CVE-2018-3646
+ - x86/Centaur: Initialize supported CPU features properly
+ - x86/Centaur: Report correct CPU/cache topology
+ - x86/CPU/AMD: Have smp_num_siblings and cpu_llc_id always be present
+ - perf/events/amd/uncore: Fix amd_uncore_llc ID to use pre-defined cpu_llc_id
+ - x86/CPU: Rename intel_cacheinfo.c to cacheinfo.c
+ - x86/CPU/AMD: Calculate last level cache ID from number of sharing threads
+ - x86/CPU: Modify detect_extended_topology() to return result
+ - x86/CPU/AMD: Derive CPU topology from CPUID function 0xB when available
+ - x86/CPU: Move cpu local function declarations to local header
+ - x86/CPU: Make intel_num_cpu_cores() generic
+ - x86/CPU: Move cpu_detect_cache_sizes() into init_intel_cacheinfo()
+ - x86/CPU: Move x86_cpuinfo::x86_max_cores assignment to
+ detect_num_cpu_cores()
+ - x86/CPU/AMD: Fix LLC ID bit-shift calculation
+ - x86/mm: Factor out pageattr _PAGE_GLOBAL setting
+ - x86/mm: Undo double _PAGE_PSE clearing
+ - x86/mm: Introduce "default" kernel PTE mask
+ - x86/espfix: Document use of _PAGE_GLOBAL
+ - x86/mm: Do not auto-massage page protections
+ - x86/mm: Remove extra filtering in pageattr code
+ - x86/mm: Comment _PAGE_GLOBAL mystery
+ - x86/mm: Do not forbid _PAGE_RW before init for __ro_after_init
+ - x86/ldt: Fix support_pte_mask filtering in map_ldt_struct()
+ - x86/power/64: Fix page-table setup for temporary text mapping
+ - x86/pti: Filter at vma->vm_page_prot population
+ - x86/boot/64/clang: Use fixup_pointer() to access '__supported_pte_mask'
+ - x86/speculation/l1tf: Increase 32bit PAE __PHYSICAL_PAGE_SHIFT
+ - x86/speculation/l1tf: Change order of offset/type in swap entry
+ - x86/speculation/l1tf: Protect swap entries against L1TF
+ - x86/speculation/l1tf: Protect PROT_NONE PTEs against speculation
+ - x86/speculation/l1tf: Make sure the first page is always reserved
+ - x86/speculation/l1tf: Add sysfs reporting for l1tf
+ - x86/speculation/l1tf: Disallow non privileged high MMIO PROT_NONE mappings
+ - x86/speculation/l1tf: Limit swap file size to MAX_PA/2
+ - x86/bugs: Move the l1tf function and define pr_fmt properly
+ - sched/smt: Update sched_smt_present at runtime
+ - x86/smp: Provide topology_is_primary_thread()
+ - x86/topology: Provide topology_smt_supported()
+ - cpu/hotplug: Make bringup/teardown of smp threads symmetric
+ - cpu/hotplug: Split do_cpu_down()
+ - cpu/hotplug: Provide knobs to control SMT
+ - x86/cpu: Remove the pointless CPU printout
+ - x86/cpu/AMD: Remove the pointless detect_ht() call
+ - x86/cpu/common: Provide detect_ht_early()
+ - x86/cpu/topology: Provide detect_extended_topology_early()
+ - x86/cpu/intel: Evaluate smp_num_siblings early
+ - x86/CPU/AMD: Do not check CPUID max ext level before parsing SMP info
+ - x86/cpu/AMD: Evaluate smp_num_siblings early
+ - x86/apic: Ignore secondary threads if nosmt=force
+ - x86/speculation/l1tf: Extend 64bit swap file size limit
+ - x86/cpufeatures: Add detection of L1D cache flush support.
+ - x86/CPU/AMD: Move TOPOEXT reenablement before reading smp_num_siblings
+ - x86/speculation/l1tf: Protect PAE swap entries against L1TF
+ - x86/speculation/l1tf: Fix up pte->pfn conversion for PAE
+ - Revert "x86/apic: Ignore secondary threads if nosmt=force"
+ - cpu/hotplug: Boot HT siblings at least once
+ - x86/KVM: Warn user if KVM is loaded SMT and L1TF CPU bug being present
+ - x86/KVM/VMX: Add module argument for L1TF mitigation
+ - x86/KVM/VMX: Add L1D flush algorithm
+ - x86/KVM/VMX: Add L1D MSR based flush
+ - x86/KVM/VMX: Add L1D flush logic
+ - x86/KVM/VMX: Split the VMX MSR LOAD structures to have an host/guest numbers
+ - x86/KVM/VMX: Add find_msr() helper function
+ - x86/KVM/VMX: Separate the VMX AUTOLOAD guest/host number accounting
+ - x86/KVM/VMX: Extend add_atomic_switch_msr() to allow VMENTER only MSRs
+ - x86/KVM/VMX: Use MSR save list for IA32_FLUSH_CMD if required
+ - cpu/hotplug: Online siblings when SMT control is turned on
+ - x86/litf: Introduce vmx status variable
+ - x86/kvm: Drop L1TF MSR list approach
+ - x86/l1tf: Handle EPT disabled state proper
+ - x86/kvm: Move l1tf setup function
+ - x86/kvm: Add static key for flush always
+ - x86/kvm: Serialize L1D flush parameter setter
+ - x86/kvm: Allow runtime control of L1D flush
+ - cpu/hotplug: Expose SMT control init function
+ - cpu/hotplug: Set CPU_SMT_NOT_SUPPORTED early
+ - x86/bugs, kvm: Introduce boot-time control of L1TF mitigations
+ - Documentation: Add section about CPU vulnerabilities
+ - x86/speculation/l1tf: Unbreak !__HAVE_ARCH_PFN_MODIFY_ALLOWED architectures
+ - x86/KVM/VMX: Initialize the vmx_l1d_flush_pages' content
+ - Documentation/l1tf: Fix typos
+ - cpu/hotplug: detect SMT disabled by BIOS
+ - x86/KVM/VMX: Don't set l1tf_flush_l1d to true from vmx_l1d_flush()
+ - x86/KVM/VMX: Replace 'vmx_l1d_flush_always' with 'vmx_l1d_flush_cond'
+ - x86/KVM/VMX: Move the l1tf_flush_l1d test to vmx_l1d_flush()
+ - x86/irq: Demote irq_cpustat_t::__softirq_pending to u16
+ - x86/KVM/VMX: Introduce per-host-cpu analogue of l1tf_flush_l1d
+ - x86: Don't include linux/irq.h from asm/hardirq.h
+ - x86/irq: Let interrupt handlers set kvm_cpu_l1tf_flush_l1d
+ - x86/KVM/VMX: Don't set l1tf_flush_l1d from vmx_handle_external_intr()
+ - Documentation/l1tf: Remove Yonah processors from not vulnerable list
+ - x86/speculation: Simplify sysfs report of VMX L1TF vulnerability
+ - x86/speculation: Use ARCH_CAPABILITIES to skip L1D flush on vmentry
+ - KVM: x86: Add a framework for supporting MSR-based features
+ - KVM: X86: Introduce kvm_get_msr_feature()
+ - KVM: VMX: support MSR_IA32_ARCH_CAPABILITIES as a feature MSR
+ - KVM: VMX: Tell the nested hypervisor to skip L1D flush on vmentry
+ - cpu/hotplug: Fix SMT supported evaluation
+ - x86/speculation/l1tf: Invert all not present mappings
+ - x86/speculation/l1tf: Make pmd/pud_mknotpresent() invert
+ - x86/mm/pat: Make set_memory_np() L1TF safe
+ - cpu: Fix per-cpu regression on ARM64
+
+ * CVE-2018-5391
+ - Revert "net: increase fragment memory usage limits"
+
+ -- Thadeu Lima de Souza Cascardo <cascardo@canonical.com> Fri, 10 Aug 2018 14:22:53 -0300
+
+linux (4.15.0-30.32) bionic; urgency=medium
+
+ * CVE-2018-5390
+ - tcp: free batches of packets in tcp_prune_ofo_queue()
+ - tcp: avoid collapses in tcp_prune_queue() if possible
+ - tcp: detect malicious patterns in tcp_collapse_ofo_queue()
+ - tcp: call tcp_drop() from tcp_data_queue_ofo()
+ - tcp: add tcp_ooo_try_coalesce() helper
+
+ -- Stefan Bader <stefan.bader@canonical.com> Thu, 26 Jul 2018 17:20:29 +0200
+
+linux (4.15.0-29.31) bionic; urgency=medium
+
+ * linux: 4.15.0-29.31 -proposed tracker (LP: #1782173)
+
+ * [SRU Bionic][Cosmic] kernel panic in ipmi_ssif at msg_done_handler
+ (LP: #1777716)
+ - ipmi_ssif: Fix kernel panic at msg_done_handler
+
+ * Update to ocxl driver for 18.04.1 (LP: #1775786)
+ - misc: ocxl: use put_device() instead of device_unregister()
+ - powerpc: Add TIDR CPU feature for POWER9
+ - powerpc: Use TIDR CPU feature to control TIDR allocation
+ - powerpc: use task_pid_nr() for TID allocation
+ - ocxl: Rename pnv_ocxl_spa_remove_pe to clarify it's action
+ - ocxl: Expose the thread_id needed for wait on POWER9
+ - ocxl: Add an IOCTL so userspace knows what OCXL features are available
+ - ocxl: Document new OCXL IOCTLs
+ - ocxl: Fix missing unlock on error in afu_ioctl_enable_p9_wait()
+
+ * Critical upstream bugfix missing in Ubuntu 18.04 - frequent Xorg crash after
+ suspend (LP: #1776887)
+ - ocxl: Document the OCXL_IOCTL_GET_METADATA IOCTL
+
+ * Hard LOCKUP observed on stressing Ubuntu 18 04 (LP: #1777194)
+ - powerpc: use NMI IPI for smp_send_stop
+ - powerpc: Fix smp_send_stop NMI IPI handling
+
+ * IPL: ppc64_cpu --frequency hang with INFO: rcu_sched detected stalls on
+ CPUs/tasks on w34 and wsbmc016 with 920.1714.20170330n (LP: #1773964)
+ - rtc: opal: Fix OPAL RTC driver OPAL_BUSY loops
+
+ * [Regression] EXT4-fs error (device sda2): ext4_validate_block_bitmap:383:
+ comm stress-ng: bg 4705: bad block bitmap checksum (LP: #1781709)
+ - SAUCE: Revert "UBUNTU: SAUCE: ext4: fix ext4_validate_inode_bitmap: comm
+ stress-ng: Corrupt inode bitmap"
+ - SAUCE: ext4: check for allocation block validity with block group locked
+
+ -- Stefan Bader <stefan.bader@canonical.com> Tue, 17 Jul 2018 10:57:50 +0200
+
+linux (4.15.0-28.30) bionic; urgency=medium
+
+ * linux: 4.15.0-28.30 -proposed tracker (LP: #1781433)
+
+ * Cannot set MTU higher than 1500 in Xen instance (LP: #1781413)
+ - xen-netfront: Fix mismatched rtnl_unlock
+ - xen-netfront: Update features after registering netdev
+
+ -- Kamal Mostafa <kamal@canonical.com> Thu, 12 Jul 2018 09:47:07 -0700
+
+linux (4.15.0-27.29) bionic; urgency=medium
+
+ * linux: 4.15.0-27.29 -proposed tracker (LP: #1781062)
+
+ * [Regression] EXT4-fs error (device sda1): ext4_validate_inode_bitmap:99:
+ comm stress-ng: Corrupt inode bitmap (LP: #1780137)
+ - SAUCE: ext4: fix ext4_validate_inode_bitmap: comm stress-ng: Corrupt inode
+ bitmap
+
+ -- Khalid Elmously <khalid.elmously@canonical.com> Tue, 10 Jul 2018 19:05:00 -0400
+
+linux (4.15.0-26.28) bionic; urgency=medium
+
+ * linux: 4.15.0-26.28 -proposed tracker (LP: #1780112)
+
+ * failure to boot with linux-image-4.15.0-24-generic (LP: #1779827) // Cloud-
+ init causes potentially huge boot delays with 4.15 kernels (LP: #1780062)
+ - random: Make getrandom() ready earlier
+
+ -- Stefan Bader <stefan.bader@canonical.com> Wed, 04 Jul 2018 17:52:52 +0200
+
+linux (4.15.0-25.27) bionic; urgency=medium
+
+ * linux: 4.15.0-25.27 -proposed tracker (LP: #1779354)
+
+ * hisi_sas_v3_hw: internal task abort: timeout and not done. (LP: #1777736)
+ - scsi: hisi_sas: Update a couple of register settings for v3 hw
+
+ * hisi_sas: Add missing PHY spinlock init (LP: #1777734)
+ - scsi: hisi_sas: Add missing PHY spinlock init
+
+ * hisi_sas: improve read performance by pre-allocating slot DMA buffers
+ (LP: #1777727)
+ - scsi: hisi_sas: use dma_zalloc_coherent()
+ - scsi: hisi_sas: Use dmam_alloc_coherent()
+ - scsi: hisi_sas: Pre-allocate slot DMA buffers
+
+ * hisi_sas: Failures during host reset (LP: #1777696)
+ - scsi: hisi_sas: Only process broadcast change in phy_bcast_v3_hw()
+ - scsi: hisi_sas: Fix the conflict between dev gone and host reset
+ - scsi: hisi_sas: Adjust task reject period during host reset
+ - scsi: hisi_sas: Add a flag to filter PHY events during reset
+ - scsi: hisi_sas: Release all remaining resources in clear nexus ha
+
+ * Fake SAS addresses for SATA disks on HiSilicon D05 are non-unique
+ (LP: #1776750)
+ - scsi: hisi_sas: make SAS address of SATA disks unique
+
+ * Vcs-Git header on bionic linux source package points to zesty git tree
+ (LP: #1766055)
+ - [Packaging]: Update Vcs-Git
+
+ * large KVM instances run out of IRQ routes (LP: #1778261)
+ - SAUCE: kvm -- increase KVM_MAX_IRQ_ROUTES to 2048 on x86
+
+ -- Khalid Elmously <khalid.elmously@canonical.com> Sun, 01 Jul 2018 23:10:18 +0000
+
+linux (4.15.0-24.26) bionic; urgency=medium
+
+ * linux: 4.15.0-24.26 -proposed tracker (LP: #1776338)
+
+ * Bionic update: upstream stable patchset 2018-06-06 (LP: #1775483)
+ - drm: bridge: dw-hdmi: Fix overflow workaround for Amlogic Meson GX SoCs
+ - i40e: Fix attach VF to VM issue
+ - tpm: cmd_ready command can be issued only after granting locality
+ - tpm: tpm-interface: fix tpm_transmit/_cmd kdoc
+ - tpm: add retry logic
+ - Revert "ath10k: send (re)assoc peer command when NSS changed"
+ - bonding: do not set slave_dev npinfo before slave_enable_netpoll in
+ bond_enslave
+ - ipv6: add RTA_TABLE and RTA_PREFSRC to rtm_ipv6_policy
+ - ipv6: sr: fix NULL pointer dereference in seg6_do_srh_encap()- v4 pkts
+ - KEYS: DNS: limit the length of option strings
+ - l2tp: check sockaddr length in pppol2tp_connect()
+ - net: validate attribute sizes in neigh_dump_table()
+ - llc: delete timers synchronously in llc_sk_free()
+ - tcp: don't read out-of-bounds opsize
+ - net: af_packet: fix race in PACKET_{R|T}X_RING
+ - tcp: md5: reject TCP_MD5SIG or TCP_MD5SIG_EXT on established sockets
+ - net: fix deadlock while clearing neighbor proxy table
+ - team: avoid adding twice the same option to the event list
+ - net/smc: fix shutdown in state SMC_LISTEN
+ - team: fix netconsole setup over team
+ - packet: fix bitfield update race
+ - tipc: add policy for TIPC_NLA_NET_ADDR
+ - pppoe: check sockaddr length in pppoe_connect()
+ - vlan: Fix reading memory beyond skb->tail in skb_vlan_tagged_multi
+ - amd-xgbe: Add pre/post auto-negotiation phy hooks
+ - sctp: do not check port in sctp_inet6_cmp_addr
+ - amd-xgbe: Improve KR auto-negotiation and training
+ - strparser: Do not call mod_delayed_work with a timeout of LONG_MAX
+ - amd-xgbe: Only use the SFP supported transceiver signals
+ - strparser: Fix incorrect strp->need_bytes value.
+ - net: sched: ife: signal not finding metaid
+ - tcp: clear tp->packets_out when purging write queue
+ - net: sched: ife: handle malformed tlv length
+ - net: sched: ife: check on metadata length
+ - llc: hold llc_sap before release_sock()
+ - llc: fix NULL pointer deref for SOCK_ZAPPED
+ - net: ethernet: ti: cpsw: fix tx vlan priority mapping
+ - virtio_net: split out ctrl buffer
+ - virtio_net: fix adding vids on big-endian
+ - KVM: s390: force bp isolation for VSIE
+ - s390: correct module section names for expoline code revert
+ - microblaze: Setup dependencies for ASM optimized lib functions
+ - commoncap: Handle memory allocation failure.
+ - scsi: mptsas: Disable WRITE SAME
+ - cdrom: information leak in cdrom_ioctl_media_changed()
+ - m68k/mac: Don't remap SWIM MMIO region
+ - block/swim: Check drive type
+ - block/swim: Don't log an error message for an invalid ioctl
+ - block/swim: Remove extra put_disk() call from error path
+ - block/swim: Rename macros to avoid inconsistent inverted logic
+ - block/swim: Select appropriate drive on device open
+ - block/swim: Fix array bounds check
+ - block/swim: Fix IO error at end of medium
+ - tracing: Fix missing tab for hwlat_detector print format
+ - s390/cio: update chpid descriptor after resource accessibility event
+ - s390/dasd: fix IO error for newly defined devices
+ - s390/uprobes: implement arch_uretprobe_is_alive()
+ - ACPI / video: Only default only_lcd to true on Win8-ready _desktops_
+ - docs: ip-sysctl.txt: fix name of some ipv6 variables
+ - net: mvpp2: Fix DMA address mask size
+ - net: stmmac: Disable ACS Feature for GMAC >= 4
+ - l2tp: hold reference on tunnels in netlink dumps
+ - l2tp: hold reference on tunnels printed in pppol2tp proc file
+ - l2tp: hold reference on tunnels printed in l2tp/tunnels debugfs file
+ - l2tp: fix {pppol2tp, l2tp_dfs}_seq_stop() in case of seq_file overflow
+ - s390/qeth: fix error handling in adapter command callbacks
+ - s390/qeth: avoid control IO completion stalls
+ - s390/qeth: handle failure on workqueue creation
+ - bnxt_en: Fix memory fault in bnxt_ethtool_init()
+ - virtio-net: add missing virtqueue kick when flushing packets
+ - VSOCK: make af_vsock.ko removable again
+ - hwmon: (k10temp) Add temperature offset for Ryzen 2700X
+ - hwmon: (k10temp) Add support for AMD Ryzen w/ Vega graphics
+ - s390/cpum_cf: rename IBM z13/z14 counter names
+ - kprobes: Fix random address output of blacklist file
+ - Revert "pinctrl: intel: Initialize GPIO properly when used through irqchip"
+
+ * Lenovo V330 needs patch in ideapad_laptop module for rfkill (LP: #1774636)
+ - SAUCE: Add Lenovo V330 to the ideapad_laptop rfkill blacklist
+
+ * bluetooth controller fail after suspend with USB autosuspend on XPS 13 9360
+ (LP: #1775217)
+ - Bluetooth: btusb: Add Dell XPS 13 9360 to btusb_needs_reset_resume_table
+
+ * [Hyper-V] PCI: hv: Fix 2 hang issues in hv_compose_msi_msg (LP: #1758378)
+ - PCI: hv: Only queue new work items in hv_pci_devices_present() if necessary
+ - PCI: hv: Remove the bogus test in hv_eject_device_work()
+ - PCI: hv: Fix a comment typo in _hv_pcifront_read_config()
+
+ * register on binfmt_misc may overflow and crash the system (LP: #1775856)
+ - fs/binfmt_misc.c: do not allow offset overflow
+
+ * CVE-2018-11508
+ - compat: fix 4-byte infoleak via uninitialized struct field
+
+ * Network installs fail on SocioNext board (LP: #1775884)
+ - net: netsec: reduce DMA mask to 40 bits
+ - net: socionext: reset hardware in ndo_stop
+ - net: netsec: enable tx-irq during open callback
+
+ * r8169 ethernet card don't work after returning from suspension
+ (LP: #1752772)
+ - PCI: Add pcim_set_mwi(), a device-managed pci_set_mwi()
+ - r8169: switch to device-managed functions in probe
+ - r8169: remove netif_napi_del in probe error path
+ - r8169: remove some WOL-related dead code
+ - r8169: disable WOL per default
+ - r8169: improve interrupt handling
+ - r8169: fix interrupt number after adding support for MSI-X interrupts
+
+ * ISST-LTE:KVM:Ubuntu18.04:BostonLC:boslcp3:boslcp3g3:Guest conosle hangs
+ after hotplug CPU add operation. (LP: #1759723)
+ - genirq/affinity: assign vectors to all possible CPUs
+ - genirq/affinity: Don't return with empty affinity masks on error
+ - genirq/affinity: Rename *node_to_possible_cpumask as *node_to_cpumask
+ - genirq/affinity: Move actual irq vector spreading into a helper function
+ - genirq/affinity: Allow irq spreading from a given starting point
+ - genirq/affinity: Spread irq vectors among present CPUs as far as possible
+ - blk-mq: simplify queue mapping & schedule with each possisble CPU
+ - blk-mq: make sure hctx->next_cpu is set correctly
+ - blk-mq: Avoid that blk_mq_delay_run_hw_queue() introduces unintended delays
+ - blk-mq: make sure that correct hctx->next_cpu is set
+ - blk-mq: avoid to write intermediate result to hctx->next_cpu
+ - blk-mq: introduce blk_mq_hw_queue_first_cpu() to figure out first cpu
+ - blk-mq: don't check queue mapped in __blk_mq_delay_run_hw_queue()
+ - nvme: pci: pass max vectors as num_possible_cpus() to pci_alloc_irq_vectors
+ - scsi: hpsa: fix selection of reply queue
+ - scsi: megaraid_sas: fix selection of reply queue
+ - scsi: core: introduce force_blk_mq
+ - scsi: virtio_scsi: fix IO hang caused by automatic irq vector affinity
+ - scsi: virtio_scsi: unify scsi_host_template
+
+ * Fix several bugs in RDMA/hns driver (LP: #1770974)
+ - RDMA/hns: Use structs to describe the uABI instead of opencoding
+ - RDMA/hns: Remove unnecessary platform_get_resource() error check
+ - RDMA/hns: Remove unnecessary operator
+ - RDMA/hns: Add names to function arguments in function pointers
+ - RDMA/hns: Fix misplaced call to hns_roce_cleanup_hem_table
+ - RDMA/hns: Fix a bug with modifying mac address
+ - RDMA/hns: Use free_pages function instead of free_page
+ - RDMA/hns: Replace __raw_write*(cpu_to_le*()) with LE write*()
+ - RDMA/hns: Bugfix for init hem table
+ - RDMA/hns: Intercept illegal RDMA operation when use inline data
+ - RDMA/hns: Fix the qp context state diagram
+ - RDMA/hns: Only assign mtu if IB_QP_PATH_MTU bit is set
+ - RDMA/hns: Remove some unnecessary attr_mask judgement
+ - RDMA/hns: Only assign dqpn if IB_QP_PATH_DEST_QPN bit is set
+ - RDMA/hns: Adjust the order of cleanup hem table
+ - RDMA/hns: Update assignment method for owner field of send wqe
+ - RDMA/hns: Submit bad wr
+ - RDMA/hns: Fix a couple misspellings
+ - RDMA/hns: Add rq inline flags judgement
+ - RDMA/hns: Bugfix for rq record db for kernel
+ - RDMA/hns: Load the RoCE dirver automatically
+ - RDMA/hns: Update convert function of endian format
+ - RDMA/hns: Add return operation when configured global param fail
+ - RDMA/hns: Not support qp transition from reset to reset for hip06
+ - RDMA/hns: Fix the bug with rq sge
+ - RDMA/hns: Set desc_dma_addr for zero when free cmq desc
+ - RDMA/hns: Enable inner_pa_vld filed of mpt
+ - RDMA/hns: Set NULL for __internal_mr
+ - RDMA/hns: Fix the bug with NULL pointer
+ - RDMA/hns: Bugfix for cq record db for kernel
+ - RDMA/hns: Move the location for initializing tmp_len
+ - RDMA/hns: Drop local zgid in favor of core defined variable
+ - RDMA/hns: Add 64KB page size support for hip08
+ - RDMA/hns: Rename the idx field of db
+ - RDMA/hns: Modify uar allocation algorithm to avoid bitmap exhaust
+ - RDMA/hns: Increase checking CMQ status timeout value
+ - RDMA/hns: Add reset process for RoCE in hip08
+ - RDMA/hns: Fix the illegal memory operation when cross page
+ - RDMA/hns: Implement the disassociate_ucontext API
+
+ * powerpc/livepatch: Implement reliable stack tracing for the consistency
+ model (LP: #1771844)
+ - powerpc/livepatch: Implement reliable stack tracing for the consistency
+ model
+
+ * vmxnet3: update to latest ToT (LP: #1768143)
+ - vmxnet3: avoid xmit reset due to a race in vmxnet3
+ - vmxnet3: use correct flag to indicate LRO feature
+ - vmxnet3: fix incorrect dereference when rxvlan is disabled
+
+ * 4.15.0-22-generic fails to boot on IBM S822LC (POWER8 (raw), altivec
+ supported) (LP: #1773162)
+ - Revert "powerpc/64s: Add support for a store forwarding barrier at kernel
+ entry/exit"
+ - powerpc/64s: Add support for a store forwarding barrier at kernel entry/exit
+
+ * Decode ARM CPER records in kernel (LP: #1770244)
+ - [Config] CONFIG_UEFI_CPER_ARM=y
+ - efi: Move ARM CPER code to new file
+ - efi: Parse ARM error information value
+
+ * Adding back alx WoL feature (LP: #1772610)
+ - SAUCE: Revert "alx: remove WoL support"
+ - SAUCE: alx: add enable_wol paramenter
+
+ * Lancer A0 Asic HBA's won't boot with 18.04 (LP: #1768103)
+ - scsi: lpfc: Fix WQ/CQ creation for older asic's.
+ - scsi: lpfc: Fix 16gb hbas failing cq create.
+
+ * [LTCTest][OPAL][OP920] cpupower idle-info is not listing stop4 and stop5
+ idle states when all CORES are guarded (LP: #1771780)
+ - SAUCE: cpuidle/powernv : init all present cpus for deep states
+
+ * Huawei 25G/100G Network Adapters Unsupported (LP: #1770970)
+ - net-next/hinic: add pci device ids for 25ge and 100ge card
+
+ * [Ubuntu 18.04.1] POWER9 - Nvidia Volta - Kernel changes to enable Nvidia
+ driver on bare metal (LP: #1772991)
+ - powerpc/powernv/npu: Fix deadlock in mmio_invalidate()
+ - powerpc/powernv/mce: Don't silently restart the machine
+ - powerpc/npu-dma.c: Fix crash after __mmu_notifier_register failure
+ - powerpc/mm: Flush cache on memory hot(un)plug
+ - powerpc/powernv/memtrace: Let the arch hotunplug code flush cache
+ - powerpc/powernv/npu: Add lock to prevent race in concurrent context
+ init/destroy
+ - powerpc/powernv/npu: Prevent overwriting of pnv_npu2_init_contex() callback
+ parameters
+ - powerpc/powernv/npu: Do a PID GPU TLB flush when invalidating a large
+ address range
+ - powerpc/mce: Fix a bug where mce loops on memory UE.
+
+ * cpum_sf: ensure sample freq is non-zero (LP: #1772593)
+ - s390/cpum_sf: ensure sample frequency of perf event attributes is non-zero
+
+ * PCIe link speeds of 16 GT/s are shown as "Unknown speed" (LP: #1773243)
+ - PCI: Add decoding for 16 GT/s link speed
+
+ * False positive ACPI _PRS error messages (LP: #1773295)
+ - ACPI / PCI: pci_link: Allow the absence of _PRS and change log level
+
+ * Dell systems crash when disabling Nvidia dGPU (LP: #1773299)
+ - ACPI / OSI: Add OEM _OSI strings to disable NVidia RTD3
+
+ * wlp3s0: failed to remove key (1, ff:ff:ff:ff:ff:ff) from hardware (-22)
+ (LP: #1720930)
+ - iwlwifi: mvm: fix "failed to remove key" message
+
+ * Expose arm64 CPU topology to userspace (LP: #1770231)
+ - ACPICA: ACPI 6.2: Additional PPTT flags
+ - drivers: base: cacheinfo: move cache_setup_of_node()
+ - drivers: base: cacheinfo: setup DT cache properties early
+ - cacheinfo: rename of_node to fw_token
+ - arm64/acpi: Create arch specific cpu to acpi id helper
+ - ACPI/PPTT: Add Processor Properties Topology Table parsing
+ - [Config] CONFIG_ACPI_PPTT=y
+ - ACPI: Enable PPTT support on ARM64
+ - drivers: base cacheinfo: Add support for ACPI based firmware tables
+ - arm64: Add support for ACPI based firmware tables
+ - arm64: topology: rename cluster_id
+ - arm64: topology: enable ACPI/PPTT based CPU topology
+ - ACPI: Add PPTT to injectable table list
+ - arm64: topology: divorce MC scheduling domain from core_siblings
+
+ * hisi_sas robustness fixes (LP: #1774466)
+ - scsi: hisi_sas: delete timer when removing hisi_sas driver
+ - scsi: hisi_sas: print device id for errors
+ - scsi: hisi_sas: Add some checks to avoid free'ing a sas_task twice
+ - scsi: hisi_sas: check host frozen before calling "done" function
+ - scsi: hisi_sas: check sas_dev gone earlier in hisi_sas_abort_task()
+ - scsi: hisi_sas: stop controller timer for reset
+ - scsi: hisi_sas: update PHY linkrate after a controller reset
+ - scsi: hisi_sas: change slot index allocation mode
+ - scsi: hisi_sas: Change common allocation mode of device id
+ - scsi: hisi_sas: Reset disks when discovered
+ - scsi: hisi_sas: Create a scsi_host_template per HW module
+ - scsi: hisi_sas: Init disks after controller reset
+ - scsi: hisi_sas: Try wait commands before before controller reset
+ - scsi: hisi_sas: Include TMF elements in struct hisi_sas_slot
+ - scsi: hisi_sas: Add v2 hw force PHY function for internal ATA command
+ - scsi: hisi_sas: Terminate STP reject quickly for v2 hw
+ - scsi: hisi_sas: Fix return value when get_free_slot() failed
+ - scsi: hisi_sas: Mark PHY as in reset for nexus reset
+
+ * hisi_sas: Support newer v3 hardware (LP: #1774467)
+ - scsi: hisi_sas: update RAS feature for later revision of v3 HW
+ - scsi: hisi_sas: check IPTT is valid before using it for v3 hw
+ - scsi: hisi_sas: fix PI memory size
+ - scsi: hisi_sas: config ATA de-reset as an constrained command for v3 hw
+ - scsi: hisi_sas: remove redundant handling to event95 for v3
+ - scsi: hisi_sas: add readl poll timeout helper wrappers
+ - scsi: hisi_sas: workaround a v3 hw hilink bug
+ - scsi: hisi_sas: Add LED feature for v3 hw
+
+ * hisi_sas: improve performance by optimizing DQ locking (LP: #1774472)
+ - scsi: hisi_sas: initialize dq spinlock before use
+ - scsi: hisi_sas: optimise the usage of DQ locking
+ - scsi: hisi_sas: relocate smp sg map
+ - scsi: hisi_sas: make return type of prep functions void
+ - scsi: hisi_sas: allocate slot buffer earlier
+ - scsi: hisi_sas: Don't lock DQ for complete task sending
+ - scsi: hisi_sas: Use device lock to protect slot alloc/free
+ - scsi: hisi_sas: add check of device in hisi_sas_task_exec()
+ - scsi: hisi_sas: fix a typo in hisi_sas_task_prep()
+
+ * Request to revert SAUCE patches in the 18.04 SRU and update with upstream
+ version (LP: #1768431)
+ - scsi: cxlflash: Handle spurious interrupts
+ - scsi: cxlflash: Remove commmands from pending list on timeout
+ - scsi: cxlflash: Synchronize reset and remove ops
+ - SAUCE: (no-up) cxlflash: OCXL diff between v2 and v3
+
+ * After update to 4.13-43 Intel Graphics are Laggy (LP: #1773520)
+ - SAUCE: Revert "drm/i915/edp: Allow alternate fixed mode for eDP if
+ available."
+
+ * ELANPAD ELAN0612 does not work, patch available (LP: #1773509)
+ - SAUCE: Input: elan_i2c - add ELAN0612 to the ACPI table
+
+ * FS-Cache: Assertion failed: FS-Cache: 6 == 5 is false (LP: #1774336)
+ - SAUCE: CacheFiles: fix a read_waiter/read_copier race
+
+ * hns3 driver updates (LP: #1768670)
+ - net: hns3: VF should get the real rss_size instead of rss_size_max
+ - net: hns3: set the cmdq out_vld bit to 0 after used
+ - net: hns3: fix endian issue when PF get mbx message flag
+ - net: hns3: fix the queue id for tqp enable&&reset
+ - net: hns3: set the max ring num when alloc netdev
+ - net: hns3: add support for VF driver inner interface
+ hclgevf_ops.get_tqps_and_rss_info
+ - net: hns3: refactor the hclge_get/set_rss function
+ - net: hns3: refactor the hclge_get/set_rss_tuple function
+ - net: hns3: fix for RSS configuration loss problem during reset
+ - net: hns3: fix for pause configuration lost during reset
+ - net: hns3: fix for use-after-free when setting ring parameter
+ - net: hns3: refactor the get/put_vector function
+ - net: hns3: fix for coalesce configuration lost during reset
+ - net: hns3: refactor the coalesce related struct
+ - net: hns3: fix for coal configuation lost when setting the channel
+ - net: hns3: add existence check when remove old uc mac address
+ - net: hns3: fix for netdev not running problem after calling net_stop and
+ net_open
+ - net: hns3: fix for ipv6 address loss problem after setting channels
+ - net: hns3: unify the pause params setup function
+ - net: hns3: fix rx path skb->truesize reporting bug
+ - net: hns3: add support for querying pfc puase packets statistic
+ - net: hns3: fix for loopback failure when vlan filter is enable
+ - net: hns3: fix for buffer overflow smatch warning
+ - net: hns3: fix error type definition of return value
+ - net: hns3: fix return value error of hclge_get_mac_vlan_cmd_status()
+ - net: hns3: add existence checking before adding unicast mac address
+ - net: hns3: add result checking for VF when modify unicast mac address
+ - net: hns3: reallocate tx/rx buffer after changing mtu
+ - net: hns3: fix the VF queue reset flow error
+ - net: hns3: fix for vlan table lost problem when resetting
+ - net: hns3: increase the max time for IMP handle command
+ - net: hns3: change GL update rate
+ - net: hns3: change the time interval of int_gl calculating
+ - net: hns3: fix for getting wrong link mode problem
+ - net: hns3: add get_link support to VF
+ - net: hns3: add querying speed and duplex support to VF
+ - net: hns3: fix for not returning problem in get_link_ksettings when phy
+ exists
+ - net: hns3: Changes to make enet watchdog timeout func common for PF/VF
+ - net: hns3: Add VF Reset Service Task to support event handling
+ - net: hns3: Add VF Reset device state and its handling
+ - net: hns3: Add support to request VF Reset to PF
+ - net: hns3: Add support to reset the enet/ring mgmt layer
+ - net: hns3: Add support to re-initialize the hclge device
+ - net: hns3: Changes to support ARQ(Asynchronous Receive Queue)
+ - net: hns3: Add *Asserting Reset* mailbox message & handling in VF
+ - net: hns3: Changes required in PF mailbox to support VF reset
+ - net: hns3: hclge_inform_reset_assert_to_vf() can be static
+ - net: hns3: fix for returning wrong value problem in hns3_get_rss_key_size
+ - net: hns3: fix for returning wrong value problem in hns3_get_rss_indir_size
+ - net: hns3: fix for the wrong shift problem in hns3_set_txbd_baseinfo
+ - net: hns3: fix for not initializing VF rss_hash_key problem
+ - net: hns3: never send command queue message to IMP when reset
+ - net: hns3: remove unnecessary pci_set_drvdata() and devm_kfree()
+ - net: hns3: fix length overflow when CONFIG_ARM64_64K_PAGES
+ - net: hns3: Remove error log when getting pfc stats fails
+ - net: hns3: fix to correctly fetch l4 protocol outer header
+ - net: hns3: Fixes the out of bounds access in hclge_map_tqp
+ - net: hns3: Fixes the error legs in hclge_init_ae_dev function
+ - net: hns3: fix for phy_addr error in hclge_mac_mdio_config
+ - net: hns3: Fix to support autoneg only for port attached with phy
+ - net: hns3: fix a dead loop in hclge_cmd_csq_clean
+ - net: hns3: Fix for packet loss due wrong filter config in VLAN tbls
+ - net: hns3: Remove packet statistics in the range of 8192~12287
+ - net: hns3: Add support of hardware rx-vlan-offload to HNS3 VF driver
+ - net: hns3: Fix for setting mac address when resetting
+ - net: hns3: remove add/del_tunnel_udp in hns3_enet module
+ - net: hns3: fix for cleaning ring problem
+ - net: hns3: refactor the loopback related function
+ - net: hns3: Fix for deadlock problem occurring when unregistering ae_algo
+ - net: hns3: Fix for the null pointer problem occurring when initializing
+ ae_dev failed
+ - net: hns3: Add a check for client instance init state
+ - net: hns3: Change return type of hnae3_register_ae_dev
+ - net: hns3: Change return type of hnae3_register_ae_algo
+ - net: hns3: Change return value in hnae3_register_client
+ - net: hns3: Fixes the back pressure setting when sriov is enabled
+ - net: hns3: Fix for fiber link up problem
+ - net: hns3: Add support of .sriov_configure in HNS3 driver
+ - net: hns3: Fixes the missing PCI iounmap for various legs
+ - net: hns3: Fixes error reported by Kbuild and internal review
+ - net: hns3: Fixes API to fetch ethernet header length with kernel default
+ - net: hns3: cleanup of return values in hclge_init_client_instance()
+ - net: hns3: Fix the missing client list node initialization
+ - net: hns3: Fix for hns3 module is loaded multiple times problem
+ - net: hns3: Use enums instead of magic number in hclge_is_special_opcode
+ - net: hns3: Fix for netdev not running problem after calling net_stop and
+ net_open
+ - net: hns3: Fixes kernel panic issue during rmmod hns3 driver
+ - net: hns3: Fix for CMDQ and Misc. interrupt init order problem
+ - net: hns3: Updates RX packet info fetch in case of multi BD
+ - net: hns3: Add support for tx_accept_tag2 and tx_accept_untag2 config
+ - net: hns3: Add STRP_TAGP field support for hardware revision 0x21
+ - net: hns3: Add support to enable TX/RX promisc mode for H/W rev(0x21)
+ - net: hns3: Fix for PF mailbox receving unknown message
+ - net: hns3: Fixes the state to indicate client-type initialization
+ - net: hns3: Fixes the init of the VALID BD info in the descriptor
+ - net: hns3: Removes unnecessary check when clearing TX/RX rings
+ - net: hns3: Clear TX/RX rings when stopping port & un-initializing client
+ - net: hns3: Remove unused led control code
+ - net: hns3: Adds support for led locate command for copper port
+ - net: hns3: Fixes initalization of RoCE handle and makes it conditional
+ - net: hns3: Disable vf vlan filter when vf vlan table is full
+ - net: hns3: Add support for IFF_ALLMULTI flag
+ - net: hns3: Add repeat address checking for setting mac address
+ - net: hns3: Fix setting mac address error
+ - net: hns3: Fix for service_task not running problem after resetting
+ - net: hns3: Fix for hclge_reset running repeatly problem
+ - net: hns3: Fix for phy not link up problem after resetting
+ - net: hns3: Add missing break in misc_irq_handle
+ - net: hns3: Fix for vxlan tx checksum bug
+ - net: hns3: Optimize the PF's process of updating multicast MAC
+ - net: hns3: Optimize the VF's process of updating multicast MAC
+ - SAUCE: {topost} net: hns3: add support for serdes loopback selftest
+ - SAUCE: {topost} net: hns3: RX BD information valid only in last BD except
+ VLD bit and buffer size
+ - SAUCE: {topost} net: hns3: remove hclge_get_vector_index from
+ hclge_bind_ring_with_vector
+ - SAUCE: {topost} net: hns3: rename the interface for init_client_instance and
+ uninit_client_instance
+ - SAUCE: {topost} net: hns3: add vector status check before free vector
+ - SAUCE: {topost} net: hns3: add l4_type check for both ipv4 and ipv6
+ - SAUCE: {topost} net: hns3: remove unused head file in hnae3.c
+ - SAUCE: {topost} net: hns3: extraction an interface for state state
+ init|uninit
+ - SAUCE: {topost} net: hns3: print the ret value in error information
+ - SAUCE: {topost} net: hns3: remove the Redundant put_vector in
+ hns3_client_uninit
+ - SAUCE: {topost} net: hns3: add unlikely for error check
+ - SAUCE: {topost} net: hns3: remove back in struct hclge_hw
+ - SAUCE: {topost} net: hns3: use lower_32_bits and upper_32_bits
+ - SAUCE: {topost} net: hns3: remove unused hclge_ring_to_dma_dir
+ - SAUCE: {topost} net: hns3: remove useless code in hclge_cmd_send
+ - SAUCE: {topost} net: hns3: remove some redundant assignments
+ - SAUCE: {topost} net: hns3: simplify hclge_cmd_csq_clean
+ - SAUCE: {topost} net: hns3: using modulo for cyclic counters in
+ hclge_cmd_send
+ - SAUCE: {topost} net: hns3: remove a redundant hclge_cmd_csq_done
+ - SAUCE: {topost} net: hns3: remove some unused members of some structures
+ - SAUCE: {topost} net: hns3: give default option while dependency HNS3 set
+ - SAUCE: {topost} net: hns3: use dma_zalloc_coherent instead of
+ kzalloc/dma_map_single
+ - SAUCE: {topost} net: hns3: modify hnae_ to hnae3_
+ - SAUCE: {topost} net: hns3: fix unused function warning in VF driver
+ - SAUCE: {topost} net: hns3: remove some redundant assignments
+ - SAUCE: {topost} net: hns3: standardize the handle of return value
+ - SAUCE: {topost} net: hns3: remove extra space and brackets
+ - SAUCE: {topost} net: hns3: fix unreasonable code comments
+ - SAUCE: {topost} net: hns3: use decimal for bit offset macros
+ - SAUCE: {topost} net: hns3: modify inconsistent bit mask macros
+ - SAUCE: {topost} net: hns3: fix mislead parameter name
+ - SAUCE: {topost} net: hns3: remove unused struct member and definition
+ - SAUCE: {topost} net: hns3: Add SPDX tags to hns3 driver
+ - SAUCE: {topost} net: hns3: Add pf reset for hip08 RoCE
+ - SAUCE: {topost} net: hns3: optimize the process of notifying roce client
+ - SAUCE: {topost} net: hns3: Add calling roce callback function when link
+ status change
+ - SAUCE: {topost} net: hns3: fix tc setup when netdev is first up
+ - SAUCE: {topost} net: hns3: fix for mac pause not disable in pfc mode
+ - SAUCE: {topost} net: hns3: fix for waterline not setting correctly
+ - SAUCE: {topost} net: hns3: fix for l4 checksum offload bug
+ - SAUCE: {topost} net: hns3: fix for mailbox message truncated problem
+ - SAUCE: {topost} net: hns3: Add configure for mac minimal frame size
+ - SAUCE: {topost} net: hns3: fix warning bug when doing lp selftest
+ - SAUCE: {topost} net: hns3: fix get_vector ops in hclgevf_main module
+ - SAUCE: {topost} net: hns3: remove the warning when clear reset cause
+ - SAUCE: {topost} net: hns3: Use roce handle when calling roce callback
+ function
+ - SAUCE: {topost} net: hns3: prevent sending command during global or core
+ reset
+ - SAUCE: {topost} net: hns3: modify the order of initializeing command queue
+ register
+ - SAUCE: {topost} net: hns3: reset net device with rtnl_lock
+ - SAUCE: {topost} net: hns3: prevent to request reset frequently
+ - SAUCE: {topost} net: hns3: correct reset event status register
+ - SAUCE: {topost} net: hns3: separate roce from nic when resetting
+ - SAUCE: net: hns3: Fix for phy link issue when using marvell phy driver
+ - SAUCE: {topost} net: hns3: fix return value error in
+ hns3_reset_notify_down_enet
+ - SAUCE: {topost} net: hns3: remove unnecessary ring configuration operation
+ while resetting
+ - SAUCE: {topost} net: hns3: fix for reset_level default assignment probelm
+ - SAUCE: {topost} net: hns3: fix for using wrong mask and shift in
+ hclge_get_ring_chain_from_mbx
+ - SAUCE: {topost} net: hns3: fix comments for hclge_get_ring_chain_from_mbx
+ - SAUCE: net: hns3: Fix for VF mailbox cannot receiving PF response
+ - SAUCE: net: hns3: Fix for VF mailbox receiving unknown message
+ - SAUCE: net: hns3: Optimize PF CMDQ interrupt switching process
+
+ * enable mic-mute hotkey and led on Lenovo M820z and M920z (LP: #1774306)
+ - ALSA: hda/realtek - Enable mic-mute hotkey for several Lenovo AIOs
+
+ * Bionic update: upstream stable patchset 2018-05-29 (LP: #1774063)
+ - cifs: do not allow creating sockets except with SMB1 posix exensions
+ - btrfs: fix unaligned access in readdir
+ - x86/acpi: Prevent X2APIC id 0xffffffff from being accounted
+ - clocksource/imx-tpm: Correct -ETIME return condition check
+ - x86/tsc: Prevent 32bit truncation in calc_hpet_ref()
+ - drm/vc4: Fix memory leak during BO teardown
+ - drm/i915/gvt: throw error on unhandled vfio ioctls
+ - drm/i915/audio: Fix audio detection issue on GLK
+ - drm/i915: Do no use kfree() to free a kmem_cache_alloc() return value
+ - drm/i915: Fix LSPCON TMDS output buffer enabling from low-power state
+ - drm/i915/bxt, glk: Increase PCODE timeouts during CDCLK freq changing
+ - usb: musb: fix enumeration after resume
+ - usb: musb: call pm_runtime_{get,put}_sync before reading vbus registers
+ - usb: musb: Fix external abort in musb_remove on omap2430
+ - firewire-ohci: work around oversized DMA reads on JMicron controllers
+ - x86/tsc: Allow TSC calibration without PIT
+ - NFSv4: always set NFS_LOCK_LOST when a lock is lost.
+ - ACPI / LPSS: Do not instiate platform_dev for devs without MMIO resources
+ - ALSA: hda - Use IS_REACHABLE() for dependency on input
+ - ASoC: au1x: Fix timeout tests in au1xac97c_ac97_read()
+ - kvm: x86: fix KVM_XEN_HVM_CONFIG ioctl
+ - RDMA/core: Clarify rdma_ah_find_type
+ - KVM: PPC: Book3S HV: Enable migration of decrementer register
+ - netfilter: ipv6: nf_defrag: Pass on packets to stack per RFC2460
+ - tracing/hrtimer: Fix tracing bugs by taking all clock bases and modes into
+ account
+ - KVM: s390: use created_vcpus in more places
+ - platform/x86: dell-laptop: Filter out spurious keyboard backlight change
+ events
+ - xprtrdma: Fix backchannel allocation of extra rpcrdma_reps
+ - selftest: ftrace: Fix to pick text symbols for kprobes
+ - PCI: Add function 1 DMA alias quirk for Marvell 9128
+ - Input: psmouse - fix Synaptics detection when protocol is disabled
+ - libbpf: Makefile set specified permission mode
+ - Input: synaptics - reset the ABS_X/Y fuzz after initializing MT axes
+ - i40iw: Free IEQ resources
+ - i40iw: Zero-out consumer key on allocate stag for FMR
+ - perf unwind: Do not look just at the global callchain_param.record_mode
+ - tools lib traceevent: Simplify pointer print logic and fix %pF
+ - perf callchain: Fix attr.sample_max_stack setting
+ - tools lib traceevent: Fix get_field_str() for dynamic strings
+ - perf record: Fix failed memory allocation for get_cpuid_str
+ - iommu/exynos: Don't unconditionally steal bus ops
+ - powerpc: System reset avoid interleaving oops using die synchronisation
+ - iommu/vt-d: Use domain instead of cache fetching
+ - dm thin: fix documentation relative to low water mark threshold
+ - dm mpath: return DM_MAPIO_REQUEUE on blk-mq rq allocation failure
+ - ubifs: Fix uninitialized variable in search_dh_cookie()
+ - net: stmmac: dwmac-meson8b: fix setting the RGMII TX clock on Meson8b
+ - net: stmmac: dwmac-meson8b: propagate rate changes to the parent clock
+ - spi: a3700: Clear DATA_OUT when performing a read
+ - IB/cq: Don't force IB_POLL_DIRECT poll context for ib_process_cq_direct
+ - nfs: Do not convert nfs_idmap_cache_timeout to jiffies
+ - MIPS: Fix clean of vmlinuz.{32,ecoff,bin,srec}
+ - PCI: Add dummy pci_irqd_intx_xlate() for CONFIG_PCI=n build
+ - watchdog: sp5100_tco: Fix watchdog disable bit
+ - kconfig: Don't leak main menus during parsing
+ - kconfig: Fix automatic menu creation mem leak
+ - kconfig: Fix expr_free() E_NOT leak
+ - ipmi/powernv: Fix error return code in ipmi_powernv_probe()
+ - Btrfs: set plug for fsync
+ - btrfs: Fix out of bounds access in btrfs_search_slot
+ - Btrfs: fix scrub to repair raid6 corruption
+ - btrfs: fail mount when sb flag is not in BTRFS_SUPER_FLAG_SUPP
+ - Btrfs: fix unexpected EEXIST from btrfs_get_extent
+ - Btrfs: raid56: fix race between merge_bio and rbio_orig_end_io
+ - RDMA/cma: Check existence of netdevice during port validation
+ - f2fs: avoid hungtask when GC encrypted block if io_bits is set
+ - scsi: devinfo: fix format of the device list
+ - scsi: fas216: fix sense buffer initialization
+ - Input: stmfts - set IRQ_NOAUTOEN to the irq flag
+ - HID: roccat: prevent an out of bounds read in kovaplus_profile_activated()
+ - nfp: fix error return code in nfp_pci_probe()
+ - block: Set BIO_TRACE_COMPLETION on new bio during split
+ - bpf: test_maps: cleanup sockmaps when test ends
+ - i40evf: Don't schedule reset_task when device is being removed
+ - i40evf: ignore link up if not running
+ - platform/x86: thinkpad_acpi: suppress warning about palm detection
+ - KVM: s390: vsie: use READ_ONCE to access some SCB fields
+ - blk-mq-debugfs: don't allow write on attributes with seq_operations set
+ - ASoC: rockchip: Use dummy_dai for rt5514 dsp dailink
+ - igb: Allow to remove administratively set MAC on VFs
+ - igb: Clear TXSTMP when ptp_tx_work() is timeout
+ - fm10k: fix "failed to kill vid" message for VF
+ - x86/hyperv: Stop suppressing X86_FEATURE_PCID
+ - tty: serial: exar: Relocate sleep wake-up handling
+ - device property: Define type of PROPERTY_ENRTY_*() macros
+ - crypto: artpec6 - remove select on non-existing CRYPTO_SHA384
+ - RDMA/uverbs: Use an unambiguous errno for method not supported
+ - jffs2: Fix use-after-free bug in jffs2_iget()'s error handling path
+ - ixgbe: don't set RXDCTL.RLPML for 82599
+ - i40e: program fragmented IPv4 filter input set
+ - i40e: fix reported mask for ntuple filters
+ - samples/bpf: Partially fixes the bpf.o build
+ - powerpc/numa: Use ibm,max-associativity-domains to discover possible nodes
+ - powerpc/numa: Ensure nodes initialized for hotplug
+ - RDMA/mlx5: Avoid memory leak in case of XRCD dealloc failure
+ - ntb_transport: Fix bug with max_mw_size parameter
+ - gianfar: prevent integer wrapping in the rx handler
+ - x86/hyperv: Check for required priviliges in hyperv_init()
+ - netfilter: x_tables: fix pointer leaks to userspace
+ - tcp_nv: fix potential integer overflow in tcpnv_acked
+ - kvm: Map PFN-type memory regions as writable (if possible)
+ - x86/kvm/vmx: do not use vm-exit instruction length for fast MMIO when
+ running nested
+ - fs/dax.c: release PMD lock even when there is no PMD support in DAX
+ - ocfs2: return -EROFS to mount.ocfs2 if inode block is invalid
+ - ocfs2/acl: use 'ip_xattr_sem' to protect getting extended attribute
+ - ocfs2: return error when we attempt to access a dirty bh in jbd2
+ - mm/mempolicy: fix the check of nodemask from user
+ - mm/mempolicy: add nodes_empty check in SYSC_migrate_pages
+ - asm-generic: provide generic_pmdp_establish()
+ - sparc64: update pmdp_invalidate() to return old pmd value
+ - mm: thp: use down_read_trylock() in khugepaged to avoid long block
+ - mm: pin address_space before dereferencing it while isolating an LRU page
+ - mm/fadvise: discard partial page if endbyte is also EOF
+ - openvswitch: Remove padding from packet before L3+ conntrack processing
+ - blk-mq: fix discard merge with scheduler attached
+ - IB/hfi1: Re-order IRQ cleanup to address driver cleanup race
+ - IB/hfi1: Fix for potential refcount leak in hfi1_open_file()
+ - IB/ipoib: Fix for potential no-carrier state
+ - IB/core: Map iWarp AH type to undefined in rdma_ah_find_type
+ - drm/nouveau/pmu/fuc: don't use movw directly anymore
+ - s390/eadm: fix CONFIG_BLOCK include dependency
+ - netfilter: ipv6: nf_defrag: Kill frag queue on RFC2460 failure
+ - x86/power: Fix swsusp_arch_resume prototype
+ - x86/dumpstack: Avoid uninitlized variable
+ - firmware: dmi_scan: Fix handling of empty DMI strings
+ - ACPI: processor_perflib: Do not send _PPC change notification if not ready
+ - ACPI / bus: Do not call _STA on battery devices with unmet dependencies
+ - ACPI / scan: Use acpi_bus_get_status() to initialize ACPI_TYPE_DEVICE devs
+ - MIPS: TXx9: use IS_BUILTIN() for CONFIG_LEDS_CLASS
+ - perf record: Fix period option handling
+ - MIPS: Generic: Support GIC in EIC mode
+ - perf evsel: Fix period/freq terms setup
+ - xen-netfront: Fix race between device setup and open
+ - xen/grant-table: Use put_page instead of free_page
+ - bpf: sockmap, fix leaking maps with attached but not detached progs
+ - RDS: IB: Fix null pointer issue
+ - arm64: spinlock: Fix theoretical trylock() A-B-A with LSE atomics
+ - proc: fix /proc/*/map_files lookup
+ - PM / domains: Fix up domain-idle-states OF parsing
+ - cifs: silence compiler warnings showing up with gcc-8.0.0
+ - bcache: properly set task state in bch_writeback_thread()
+ - bcache: fix for allocator and register thread race
+ - bcache: fix for data collapse after re-attaching an attached device
+ - bcache: return attach error when no cache set exist
+ - cpufreq: intel_pstate: Enable HWP during system resume on CPU0
+ - selftests/ftrace: Add some missing glob checks
+ - rxrpc: Don't put crypto buffers on the stack
+ - svcrdma: Fix Read chunk round-up
+ - net: Extra '_get' in declaration of arch_get_platform_mac_address
+ - tools/libbpf: handle issues with bpf ELF objects containing .eh_frames
+ - SUNRPC: Don't call __UDPX_INC_STATS() from a preemptible context
+ - net: stmmac: discard disabled flags in interrupt status register
+ - bpf: fix rlimit in reuseport net selftest
+ - ACPI / EC: Restore polling during noirq suspend/resume phases
+ - PM / wakeirq: Fix unbalanced IRQ enable for wakeirq
+ - vfs/proc/kcore, x86/mm/kcore: Fix SMAP fault when dumping vsyscall user page
+ - powerpc/mm/hash64: Zero PGD pages on allocation
+ - x86/platform/UV: Fix GAM Range Table entries less than 1GB
+ - locking/qspinlock: Ensure node->count is updated before initialising node
+ - powerpc/powernv: IMC fix out of bounds memory access at shutdown
+ - perf test: Fix test trace+probe_libc_inet_pton.sh for s390x
+ - irqchip/gic-v3: Ignore disabled ITS nodes
+ - cpumask: Make for_each_cpu_wrap() available on UP as well
+ - irqchip/gic-v3: Change pr_debug message to pr_devel
+ - RDMA/core: Reduce poll batch for direct cq polling
+ - alarmtimer: Init nanosleep alarm timer on stack
+ - netfilter: x_tables: cap allocations at 512 mbyte
+ - netfilter: x_tables: add counters allocation wrapper
+ - netfilter: compat: prepare xt_compat_init_offsets to return errors
+ - netfilter: compat: reject huge allocation requests
+ - netfilter: x_tables: limit allocation requests for blob rule heads
+ - perf: Fix sample_max_stack maximum check
+ - perf: Return proper values for user stack errors
+ - RDMA/mlx5: Fix NULL dereference while accessing XRC_TGT QPs
+ - Revert "KVM: X86: Fix SMRAM accessing even if VM is shutdown"
+ - mac80211_hwsim: fix use-after-free bug in hwsim_exit_net
+ - btrfs: Fix race condition between delayed refs and blockgroup removal
+ - mm,vmscan: Allow preallocating memory for register_shrinker().
+
+ * Bionic update: upstream stable patchset 2018-05-24 (LP: #1773233)
+ - tty: make n_tty_read() always abort if hangup is in progress
+ - cpufreq: CPPC: Use transition_delay_us depending transition_latency
+ - ubifs: Check ubifs_wbuf_sync() return code
+ - ubi: fastmap: Don't flush fastmap work on detach
+ - ubi: Fix error for write access
+ - ubi: Reject MLC NAND
+ - mm/ksm.c: fix inconsistent accounting of zero pages
+ - mm/hmm: hmm_pfns_bad() was accessing wrong struct
+ - task_struct: only use anon struct under randstruct plugin
+ - fs/reiserfs/journal.c: add missing resierfs_warning() arg
+ - resource: fix integer overflow at reallocation
+ - ipc/shm: fix use-after-free of shm file via remap_file_pages()
+ - mm, slab: reschedule cache_reap() on the same CPU
+ - usb: musb: gadget: misplaced out of bounds check
+ - phy: allwinner: sun4i-usb: poll vbus changes on A23/A33 when driving VBUS
+ - usb: gadget: udc: core: update usb_ep_queue() documentation
+ - ARM64: dts: meson: reduce odroid-c2 eMMC maximum rate
+ - KVM: arm/arm64: vgic-its: Fix potential overrun in vgic_copy_lpi_list
+ - ARM: EXYNOS: Fix coupled CPU idle freeze on Exynos4210
+ - arm: dts: mt7623: fix USB initialization fails on bananapi-r2
+ - ARM: dts: at91: at91sam9g25: fix mux-mask pinctrl property
+ - ARM: dts: exynos: Fix IOMMU support for GScaler devices on Exynos5250
+ - ARM: dts: at91: sama5d4: fix pinctrl compatible string
+ - spi: atmel: init FIFOs before spi enable
+ - spi: Fix scatterlist elements size in spi_map_buf
+ - spi: Fix unregistration of controller with fixed SPI bus number
+ - media: atomisp_fops.c: disable atomisp_compat_ioctl32
+ - media: vivid: check if the cec_adapter is valid
+ - media: vsp1: Fix BRx conditional path in WPF
+ - x86/xen: Delay get_cpu_cap until stack canary is established
+ - regmap: Fix reversed bounds check in regmap_raw_write()
+ - ACPI / video: Add quirk to force acpi-video backlight on Samsung 670Z5E
+ - ACPI / hotplug / PCI: Check presence of slot itself in get_slot_status()
+ - USB: gadget: f_midi: fixing a possible double-free in f_midi
+ - USB:fix USB3 devices behind USB3 hubs not resuming at hibernate thaw
+ - usb: dwc3: prevent setting PRTCAP to OTG from debugfs
+ - usb: dwc3: pci: Properly cleanup resource
+ - usb: dwc3: gadget: never call ->complete() from ->ep_queue()
+ - cifs: fix memory leak in SMB2_open()
+ - fix smb3-encryption breakage when CONFIG_DEBUG_SG=y
+ - smb3: Fix root directory when server returns inode number of zero
+ - HID: i2c-hid: fix size check and type usage
+ - i2c: i801: Save register SMBSLVCMD value only once
+ - i2c: i801: Restore configuration at shutdown
+ - CIFS: refactor crypto shash/sdesc allocation&free
+ - CIFS: add sha512 secmech
+ - CIFS: fix sha512 check in cifs_crypto_secmech_release
+ - powerpc/64s: Fix dt_cpu_ftrs to have restore_cpu clear unwanted LPCR bits
+ - powerpc/64: Call H_REGISTER_PROC_TBL when running as a HPT guest on POWER9
+ - powerpc/64: Fix smp_wmb barrier definition use use lwsync consistently
+ - powerpc/kprobes: Fix call trace due to incorrect preempt count
+ - powerpc/kexec_file: Fix error code when trying to load kdump kernel
+ - powerpc/powernv: define a standard delay for OPAL_BUSY type retry loops
+ - powerpc/powernv: Fix OPAL NVRAM driver OPAL_BUSY loops
+ - HID: Fix hid_report_len usage
+ - HID: core: Fix size as type u32
+ - soc: mediatek: fix the mistaken pointer accessed when subdomains are added
+ - ASoC: ssm2602: Replace reg_default_raw with reg_default
+ - ASoC: topology: Fix kcontrol name string handling
+ - irqchip/gic: Take lock when updating irq type
+ - random: use a tighter cap in credit_entropy_bits_safe()
+ - extcon: intel-cht-wc: Set direction and drv flags for V5 boost GPIO
+ - block: use 32-bit blk_status_t on Alpha
+ - jbd2: if the journal is aborted then don't allow update of the log tail
+ - ext4: shutdown should not prevent get_write_access
+ - ext4: eliminate sleep from shutdown ioctl
+ - ext4: pass -ESHUTDOWN code to jbd2 layer
+ - ext4: don't update checksum of new initialized bitmaps
+ - ext4: protect i_disksize update by i_data_sem in direct write path
+ - ext4: limit xattr size to INT_MAX
+ - ext4: always initialize the crc32c checksum driver
+ - ext4: don't allow r/w mounts if metadata blocks overlap the superblock
+ - ext4: move call to ext4_error() into ext4_xattr_check_block()
+ - ext4: add bounds checking to ext4_xattr_find_entry()
+ - ext4: add extra checks to ext4_xattr_block_get()
+ - dm crypt: limit the number of allocated pages
+ - RDMA/ucma: Don't allow setting RDMA_OPTION_IB_PATH without an RDMA device
+ - RDMA/mlx5: Protect from NULL pointer derefence
+ - RDMA/rxe: Fix an out-of-bounds read
+ - ALSA: pcm: Fix UAF at PCM release via PCM timer access
+ - IB/srp: Fix srp_abort()
+ - IB/srp: Fix completion vector assignment algorithm
+ - dmaengine: at_xdmac: fix rare residue corruption
+ - cxl: Fix possible deadlock when processing page faults from cxllib
+ - tpm: self test failure should not cause suspend to fail
+ - libnvdimm, dimm: fix dpa reservation vs uninitialized label area
+ - libnvdimm, namespace: use a safe lookup for dimm device name
+ - nfit, address-range-scrub: fix scrub in-progress reporting
+ - nfit: skip region registration for incomplete control regions
+ - ring-buffer: Check if memory is available before allocation
+ - um: Compile with modern headers
+ - um: Use POSIX ucontext_t instead of struct ucontext
+ - iommu/vt-d: Fix a potential memory leak
+ - mmc: jz4740: Fix race condition in IRQ mask update
+ - mmc: tmio: Fix error handling when issuing CMD23
+ - PCI: Mark Broadcom HT1100 and HT2000 Root Port Extended Tags as broken
+ - clk: mvebu: armada-38x: add support for missing clocks
+ - clk: fix false-positive Wmaybe-uninitialized warning
+ - clk: mediatek: fix PWM clock source by adding a fixed-factor clock
+ - clk: bcm2835: De-assert/assert PLL reset signal when appropriate
+ - pwm: rcar: Fix a condition to prevent mismatch value setting to duty
+ - thermal: imx: Fix race condition in imx_thermal_probe()
+ - dt-bindings: clock: mediatek: add binding for fixed-factor clock axisel_d4
+ - watchdog: f71808e_wdt: Fix WD_EN register read
+ - ALSA: pcm: Use ERESTARTSYS instead of EINTR in OSS emulation
+ - ALSA: pcm: Avoid potential races between OSS ioctls and read/write
+ - ALSA: pcm: Return -EBUSY for OSS ioctls changing busy streams
+ - ALSA: pcm: Fix mutex unbalance in OSS emulation ioctls
+ - ALSA: pcm: Fix endless loop for XRUN recovery in OSS emulation
+ - drm/amdgpu: Add an ATPX quirk for hybrid laptop
+ - drm/amdgpu: Fix always_valid bos multiple LRU insertions.
+ - drm/amdgpu/sdma: fix mask in emit_pipeline_sync
+ - drm/amdgpu: Fix PCIe lane width calculation
+ - drm/amdgpu/si: implement get/set pcie_lanes asic callback
+ - drm/rockchip: Clear all interrupts before requesting the IRQ
+ - drm/radeon: add PX quirk for Asus K73TK
+ - drm/radeon: Fix PCIe lane width calculation
+ - ALSA: line6: Use correct endpoint type for midi output
+ - ALSA: rawmidi: Fix missing input substream checks in compat ioctls
+ - ALSA: hda - New VIA controller suppor no-snoop path
+ - random: fix crng_ready() test
+ - random: use a different mixing algorithm for add_device_randomness()
+ - random: crng_reseed() should lock the crng instance that it is modifying
+ - random: add new ioctl RNDRESEEDCRNG
+ - HID: input: fix battery level reporting on BT mice
+ - HID: hidraw: Fix crash on HIDIOCGFEATURE with a destroyed device
+ - HID: wacom: bluetooth: send exit report for recent Bluetooth devices
+ - MIPS: uaccess: Add micromips clobbers to bzero invocation
+ - MIPS: memset.S: EVA & fault support for small_memset
+ - MIPS: memset.S: Fix return of __clear_user from Lpartial_fixup
+ - MIPS: memset.S: Fix clobber of v1 in last_fixup
+ - powerpc/eeh: Fix enabling bridge MMIO windows
+ - powerpc/lib: Fix off-by-one in alternate feature patching
+ - udf: Fix leak of UTF-16 surrogates into encoded strings
+ - fanotify: fix logic of events on child
+ - mmc: sdhci-pci: Only do AMD tuning for HS200
+ - drm/i915: Correctly handle limited range YCbCr data on VLV/CHV
+ - jffs2_kill_sb(): deal with failed allocations
+ - hypfs_kill_super(): deal with failed allocations
+ - orangefs_kill_sb(): deal with allocation failures
+ - rpc_pipefs: fix double-dput()
+ - Don't leak MNT_INTERNAL away from internal mounts
+ - autofs: mount point create should honour passed in mode
+ - mm/filemap.c: fix NULL pointer in page_cache_tree_insert()
+ - Revert "media: lirc_zilog: driver only sends LIRCCODE"
+ - media: staging: lirc_zilog: incorrect reference counting
+ - writeback: safer lock nesting
+ - Bluetooth: hci_bcm: Add irq_polarity module option
+ - mm: hwpoison: disable memory error handling on 1GB hugepage
+ - media: rc: oops in ir_timer_keyup after device unplug
+ - acpi, nfit: rework NVDIMM leaf method detection
+ - ceph: always update atime/mtime/ctime for new inode
+ - ext4: fix offset overflow on 32-bit archs in ext4_iomap_begin()
+ - ext4: force revalidation of directory pointer after seekdir(2)
+ - RDMA/core: Avoid that ib_drain_qp() triggers an out-of-bounds stack access
+ - xprtrdma: Fix latency regression on NUMA NFS/RDMA clients
+ - xprtrdma: Fix corner cases when handling device removal
+ - IB/srpt: Fix an out-of-bounds stack access in srpt_zerolength_write()
+ - drivers/infiniband/core/verbs.c: fix build with gcc-4.4.4
+ - drivers/infiniband/ulp/srpt/ib_srpt.c: fix build with gcc-4.4.4
+ - mmc: core: Prevent bus reference leak in mmc_blk_init()
+ - drm/amd/display: HDMI has no sound after Panel power off/on
+ - trace_uprobe: Use %lx to display offset
+ - clk: tegra: Mark HCLK, SCLK and EMC as critical
+ - pwm: mediatek: Fix up PWM4 and PWM5 malfunction on MT7623
+ - pwm: mediatek: Improve precision in rate calculation
+ - HID: i2c-hid: Fix resume issue on Raydium touchscreen device
+ - s390: add support for IBM z14 Model ZR1
+ - drm/i915: Fix hibernation with ACPI S0 target state
+ - libnvdimm, dimm: handle EACCES failures from label reads
+ - device-dax: allow MAP_SYNC to succeed
+ - HID: i2c-hid: fix inverted return value from i2c_hid_command()
+
+ * CVE-2018-7755
+ - SAUCE: floppy: Do not copy a kernel pointer to user memory in FDGETPRM ioctl
+
+ -- Kleber Sacilotto de Souza <kleber.souza@canonical.com> Tue, 12 Jun 2018 18:09:35 +0200
+
linux (4.15.0-23.25) bionic; urgency=medium
* linux: 4.15.0-23.25 -proposed tracker (LP: #1772927)