proj/linux-patches:6.1 commit in: /
"Mike Pagano" <[email protected]>
| Newsgroups | gmane.linux.gentoo.cvs |
|---|---|
| Message-ID | <1787155068.05acb8e68be6b899371cca7427a100b5a0881eee.mpagano@gentoo> |
commit: 05acb8e68be6b899371cca7427a100b5a0881eee
Author: Mike Pagano <mpagano <AT> gentoo <DOT> org>
AuthorDate: Wed Aug 19 15:57:48 2026 +0000
Commit: Mike Pagano <mpagano <AT> gentoo <DOT> org>
CommitDate: Wed Aug 19 15:57:48 2026 +0000
URL: https://gitweb.gentoo.org/proj/linux-patches.git/commit/?id=05acb8e6
Linux patch 6.1.183
Signed-off-by: Mike Pagano <mpagano <AT> gentoo.org>
0000_README | 4 +
1182_linux-6.1.183.patch | 23159 +++++++++++++++++++++++++++++++++++++++++++++
2 files changed, 23163 insertions(+)
diff --git a/0000_README b/0000_README
index 6c0e4fe7..1e984b17 100644
--- a/0000_README
+++ b/0000_README
@@ -771,6 +771,10 @@ Patch: 1181_linux-6.1.182.patch
From: https://www.kernel.org
Desc: Linux 6.1.182
+Patch: 1182_linux-6.1.183.patch
+From: https://www.kernel.org
+Desc: Linux 6.1.183
+
Patch: 1500_XATTR_USER_PREFIX.patch
From: https://bugs.gentoo.org/show_bug.cgi?id=470644
Desc: Support for namespace user.pax.* on tmpfs.
diff --git a/1182_linux-6.1.183.patch b/1182_linux-6.1.183.patch
new file mode 100644
index 00000000..4f0e4de8
--- /dev/null
+++ b/1182_linux-6.1.183.patch
@@ -0,0 +1,23159 @@
+diff --git a/Documentation/driver-api/driver-model/devres.rst b/Documentation/driver-api/driver-model/devres.rst
+index 56082265e8e501..11234c12718d13 100644
+--- a/Documentation/driver-api/driver-model/devres.rst
++++ b/Documentation/driver-api/driver-model/devres.rst
+@@ -413,6 +413,7 @@ REGULATOR
+ devm_regulator_bulk_put()
+ devm_regulator_get()
+ devm_regulator_get_enable()
++ devm_regulator_get_enable_read_voltage()
+ devm_regulator_get_enable_optional()
+ devm_regulator_get_exclusive()
+ devm_regulator_get_optional()
+diff --git a/Makefile b/Makefile
+index a8d0a4d5fdc38f..3bcd978b96e35b 100644
+--- a/Makefile
++++ b/Makefile
+@@ -1,7 +1,7 @@
+ # SPDX-License-Identifier: GPL-2.0
+ VERSION = 6
+ PATCHLEVEL = 1
+-SUBLEVEL = 182
++SUBLEVEL = 183
+ EXTRAVERSION =
+ NAME = Curry Ramen
+
+diff --git a/arch/arm/mach-npcm/platsmp.c b/arch/arm/mach-npcm/platsmp.c
+index 21633c70fe7fee..fe63edc9886dfd 100644
+--- a/arch/arm/mach-npcm/platsmp.c
++++ b/arch/arm/mach-npcm/platsmp.c
+@@ -35,6 +35,7 @@ static int npcm7xx_smp_boot_secondary(unsigned int cpu,
+ goto out;
+ }
+ gcr_base = of_iomap(gcr_np, 0);
++ of_node_put(gcr_np);
+ if (!gcr_base) {
+ pr_err("could not iomap gcr");
+ ret = -ENOMEM;
+@@ -63,6 +64,7 @@ static void __init npcm7xx_smp_prepare_cpus(unsigned int max_cpus)
+ return;
+ }
+ scu_base = of_iomap(scu_np, 0);
++ of_node_put(scu_np);
+ if (!scu_base) {
+ pr_err("could not iomap scu");
+ return;
+diff --git a/arch/arm64/boot/dts/nvidia/tegra234.dtsi b/arch/arm64/boot/dts/nvidia/tegra234.dtsi
+index 94eff4092b3858..482c913915a774 100644
+--- a/arch/arm64/boot/dts/nvidia/tegra234.dtsi
++++ b/arch/arm64/boot/dts/nvidia/tegra234.dtsi
+@@ -2659,7 +2659,7 @@
+ #size-cells = <0>;
+
+ cpu0_0: cpu@0 {
+- compatible = "arm,cortex-a78";
++ compatible = "arm,cortex-a78ae";
+ device_type = "cpu";
+ reg = <0x00000>;
+
+@@ -2675,7 +2675,7 @@
+ };
+
+ cpu0_1: cpu@100 {
+- compatible = "arm,cortex-a78";
++ compatible = "arm,cortex-a78ae";
+ device_type = "cpu";
+ reg = <0x00100>;
+
+@@ -2691,7 +2691,7 @@
+ };
+
+ cpu0_2: cpu@200 {
+- compatible = "arm,cortex-a78";
++ compatible = "arm,cortex-a78ae";
+ device_type = "cpu";
+ reg = <0x00200>;
+
+@@ -2707,7 +2707,7 @@
+ };
+
+ cpu0_3: cpu@300 {
+- compatible = "arm,cortex-a78";
++ compatible = "arm,cortex-a78ae";
+ device_type = "cpu";
+ reg = <0x00300>;
+
+@@ -2723,7 +2723,7 @@
+ };
+
+ cpu1_0: cpu@10000 {
+- compatible = "arm,cortex-a78";
++ compatible = "arm,cortex-a78ae";
+ device_type = "cpu";
+ reg = <0x10000>;
+
+@@ -2739,7 +2739,7 @@
+ };
+
+ cpu1_1: cpu@10100 {
+- compatible = "arm,cortex-a78";
++ compatible = "arm,cortex-a78ae";
+ device_type = "cpu";
+ reg = <0x10100>;
+
+@@ -2755,7 +2755,7 @@
+ };
+
+ cpu1_2: cpu@10200 {
+- compatible = "arm,cortex-a78";
++ compatible = "arm,cortex-a78ae";
+ device_type = "cpu";
+ reg = <0x10200>;
+
+@@ -2771,7 +2771,7 @@
+ };
+
+ cpu1_3: cpu@10300 {
+- compatible = "arm,cortex-a78";
++ compatible = "arm,cortex-a78ae";
+ device_type = "cpu";
+ reg = <0x10300>;
+
+@@ -2787,7 +2787,7 @@
+ };
+
+ cpu2_0: cpu@20000 {
+- compatible = "arm,cortex-a78";
++ compatible = "arm,cortex-a78ae";
+ device_type = "cpu";
+ reg = <0x20000>;
+
+@@ -2803,7 +2803,7 @@
+ };
+
+ cpu2_1: cpu@20100 {
+- compatible = "arm,cortex-a78";
++ compatible = "arm,cortex-a78ae";
+ device_type = "cpu";
+ reg = <0x20100>;
+
+@@ -2819,7 +2819,7 @@
+ };
+
+ cpu2_2: cpu@20200 {
+- compatible = "arm,cortex-a78";
++ compatible = "arm,cortex-a78ae";
+ device_type = "cpu";
+ reg = <0x20200>;
+
+@@ -2835,7 +2835,7 @@
+ };
+
+ cpu2_3: cpu@20300 {
+- compatible = "arm,cortex-a78";
++ compatible = "arm,cortex-a78ae";
+ device_type = "cpu";
+ reg = <0x20300>;
+
+diff --git a/arch/powerpc/boot/simpleboot.c b/arch/powerpc/boot/simpleboot.c
+index c80691d83880b8..27591df41e9e84 100644
+--- a/arch/powerpc/boot/simpleboot.c
++++ b/arch/powerpc/boot/simpleboot.c
+@@ -68,7 +68,7 @@ void platform_init(unsigned long r3, unsigned long r4, unsigned long r5,
+ /* finally, setup the timebase */
+ node = fdt_node_offset_by_prop_value(_dtb_start, -1, "device_type",
+ "cpu", sizeof("cpu"));
+- if (!node)
++ if (node < 0)
+ fatal("Cannot find cpu node\n");
+ timebase = fdt_getprop(_dtb_start, node, "timebase-frequency", &size);
+ if (timebase && (size == 4))
+diff --git a/arch/powerpc/boot/treeboot-akebono.c b/arch/powerpc/boot/treeboot-akebono.c
+index e3cc2599869ccc..1b529037480fbe 100644
+--- a/arch/powerpc/boot/treeboot-akebono.c
++++ b/arch/powerpc/boot/treeboot-akebono.c
+@@ -146,7 +146,7 @@ void platform_init(char *userdata)
+
+ node = fdt_node_offset_by_prop_value(_dtb_start, -1, "device_type",
+ "cpu", sizeof("cpu"));
+- if (!node)
++ if (node < 0)
+ fatal("Cannot find cpu node\n");
+ timebase = fdt_getprop(_dtb_start, node, "timebase-frequency", &size);
+ if (timebase && (size == 4))
+diff --git a/arch/powerpc/boot/treeboot-currituck.c b/arch/powerpc/boot/treeboot-currituck.c
+index d53e8a592f816e..5b5363b74f9f36 100644
+--- a/arch/powerpc/boot/treeboot-currituck.c
++++ b/arch/powerpc/boot/treeboot-currituck.c
+@@ -102,7 +102,7 @@ void platform_init(void)
+
+ node = fdt_node_offset_by_prop_value(_dtb_start, -1, "device_type",
+ "cpu", sizeof("cpu"));
+- if (!node)
++ if (node < 0)
+ fatal("Cannot find cpu node\n");
+ timebase = fdt_getprop(_dtb_start, node, "timebase-frequency", &size);
+ if (timebase && (size == 4))
+diff --git a/arch/powerpc/platforms/ps3/mm.c b/arch/powerpc/platforms/ps3/mm.c
+index 1326de55fda655..e04952bb4360b2 100644
+--- a/arch/powerpc/platforms/ps3/mm.c
++++ b/arch/powerpc/platforms/ps3/mm.c
+@@ -615,6 +615,7 @@ static int dma_ioc0_map_pages(struct ps3_dma_region *r, unsigned long phys_addr,
+
+ fail_map:
+ for (iopage--; 0 <= iopage; iopage--) {
++ offset = (1 << r->page_size) * iopage;
+ lv1_put_iopte(0,
+ c->bus_addr + offset,
+ c->lpar_addr + offset,
+diff --git a/arch/riscv/include/asm/kvm_host.h b/arch/riscv/include/asm/kvm_host.h
+index dbbf43d5262348..dc5e553e136992 100644
+--- a/arch/riscv/include/asm/kvm_host.h
++++ b/arch/riscv/include/asm/kvm_host.h
+@@ -192,12 +192,12 @@ struct kvm_vcpu_arch {
+ /*
+ * VCPU interrupts
+ *
+- * We have a lockless approach for tracking pending VCPU interrupts
+- * implemented using atomic bitops. The irqs_pending bitmap represent
+- * pending interrupts whereas irqs_pending_mask represent bits changed
+- * in irqs_pending. Our approach is modeled around multiple producer
+- * and single consumer problem where the consumer is the VCPU itself.
++ * The irqs_pending field represents pending interrupts whereas
++ * irqs_pending_mask represents bits changed in irqs_pending. Updates
++ * to these fields are serialized so vcpu interrupt sync/flush cannot
++ * drop a newly injected interrupt while syncing guest-visible HVIP.
+ */
++ raw_spinlock_t irqs_pending_lock;
+ unsigned long irqs_pending;
+ unsigned long irqs_pending_mask;
+
+diff --git a/arch/riscv/kvm/vcpu.c b/arch/riscv/kvm/vcpu.c
+index 5174ef54ad1d9e..c6afbf0a9916fb 100644
+--- a/arch/riscv/kvm/vcpu.c
++++ b/arch/riscv/kvm/vcpu.c
+@@ -112,6 +112,7 @@ static void kvm_riscv_reset_vcpu(struct kvm_vcpu *vcpu)
+ struct kvm_vcpu_csr *reset_csr = &vcpu->arch.guest_reset_csr;
+ struct kvm_cpu_context *cntx = &vcpu->arch.guest_context;
+ struct kvm_cpu_context *reset_cntx = &vcpu->arch.guest_reset_context;
++ unsigned long flags;
+ bool loaded;
+
+ /**
+@@ -134,8 +135,10 @@ static void kvm_riscv_reset_vcpu(struct kvm_vcpu *vcpu)
+
+ kvm_riscv_vcpu_timer_reset(vcpu);
+
+- WRITE_ONCE(vcpu->arch.irqs_pending, 0);
+- WRITE_ONCE(vcpu->arch.irqs_pending_mask, 0);
++ raw_spin_lock_irqsave(&vcpu->arch.irqs_pending_lock, flags);
++ vcpu->arch.irqs_pending = 0;
++ vcpu->arch.irqs_pending_mask = 0;
++ raw_spin_unlock_irqrestore(&vcpu->arch.irqs_pending_lock, flags);
+
+ vcpu->arch.hfence_head = 0;
+ vcpu->arch.hfence_tail = 0;
+@@ -173,6 +176,7 @@ int kvm_arch_vcpu_create(struct kvm_vcpu *vcpu)
+
+ /* Setup VCPU hfence queue */
+ spin_lock_init(&vcpu->arch.hfence_lock);
++ raw_spin_lock_init(&vcpu->arch.irqs_pending_lock);
+
+ /* Setup reset state of shadow SSTATUS and HSTATUS CSRs */
+ cntx = &vcpu->arch.guest_reset_context;
+@@ -444,7 +448,7 @@ static int kvm_riscv_vcpu_set_reg_csr(struct kvm_vcpu *vcpu,
+ unsigned long reg_num = reg->id & ~(KVM_REG_ARCH_MASK |
+ KVM_REG_SIZE_MASK |
+ KVM_REG_RISCV_CSR);
+- unsigned long reg_val;
++ unsigned long flags, reg_val;
+
+ if (KVM_REG_SIZE(reg->id) != sizeof(unsigned long))
+ return -EINVAL;
+@@ -461,8 +465,11 @@ static int kvm_riscv_vcpu_set_reg_csr(struct kvm_vcpu *vcpu,
+
+ ((unsigned long *)csr)[reg_num] = reg_val;
+
+- if (reg_num == KVM_REG_RISCV_CSR_REG(sip))
+- WRITE_ONCE(vcpu->arch.irqs_pending_mask, 0);
++ if (reg_num == KVM_REG_RISCV_CSR_REG(sip)) {
++ raw_spin_lock_irqsave(&vcpu->arch.irqs_pending_lock, flags);
++ vcpu->arch.irqs_pending_mask = 0;
++ raw_spin_unlock_irqrestore(&vcpu->arch.irqs_pending_lock, flags);
++ }
+
+ return 0;
+ }
+@@ -679,19 +686,26 @@ void kvm_riscv_vcpu_flush_interrupts(struct kvm_vcpu *vcpu)
+ {
+ struct kvm_vcpu_csr *csr = &vcpu->arch.guest_csr;
+ unsigned long mask, val;
++ unsigned long flags;
+
+- if (READ_ONCE(vcpu->arch.irqs_pending_mask)) {
+- mask = xchg_acquire(&vcpu->arch.irqs_pending_mask, 0);
+- val = READ_ONCE(vcpu->arch.irqs_pending) & mask;
++ raw_spin_lock_irqsave(&vcpu->arch.irqs_pending_lock, flags);
++
++ mask = vcpu->arch.irqs_pending_mask;
++ if (mask) {
++ vcpu->arch.irqs_pending_mask = 0;
++ val = vcpu->arch.irqs_pending & mask;
+
+ csr->hvip &= ~mask;
+ csr->hvip |= val;
+ }
++
++ raw_spin_unlock_irqrestore(&vcpu->arch.irqs_pending_lock, flags);
+ }
+
+ void kvm_riscv_vcpu_sync_interrupts(struct kvm_vcpu *vcpu)
+ {
+ unsigned long hvip;
++ unsigned long flags;
+ struct kvm_vcpu_arch *v = &vcpu->arch;
+ struct kvm_vcpu_csr *csr = &vcpu->arch.guest_csr;
+
+@@ -700,32 +714,40 @@ void kvm_riscv_vcpu_sync_interrupts(struct kvm_vcpu *vcpu)
+
+ /* Sync-up HVIP.VSSIP bit changes does by Guest */
+ hvip = csr_read(CSR_HVIP);
++
++ raw_spin_lock_irqsave(&v->irqs_pending_lock, flags);
++
+ if ((csr->hvip ^ hvip) & (1UL << IRQ_VS_SOFT)) {
+ if (hvip & (1UL << IRQ_VS_SOFT)) {
+- if (!test_and_set_bit(IRQ_VS_SOFT,
+- &v->irqs_pending_mask))
+- set_bit(IRQ_VS_SOFT, &v->irqs_pending);
++ if (!__test_and_set_bit(IRQ_VS_SOFT,
++ &v->irqs_pending_mask))
++ __set_bit(IRQ_VS_SOFT, &v->irqs_pending);
+ } else {
+- if (!test_and_set_bit(IRQ_VS_SOFT,
+- &v->irqs_pending_mask))
+- clear_bit(IRQ_VS_SOFT, &v->irqs_pending);
++ if (!__test_and_set_bit(IRQ_VS_SOFT,
++ &v->irqs_pending_mask))
++ __clear_bit(IRQ_VS_SOFT, &v->irqs_pending);
+ }
+ }
+
++ raw_spin_unlock_irqrestore(&v->irqs_pending_lock, flags);
++
+ /* Sync-up timer CSRs */
+ kvm_riscv_vcpu_timer_sync(vcpu);
+ }
+
+ int kvm_riscv_vcpu_set_interrupt(struct kvm_vcpu *vcpu, unsigned int irq)
+ {
++ unsigned long flags;
++
+ if (irq != IRQ_VS_SOFT &&
+ irq != IRQ_VS_TIMER &&
+ irq != IRQ_VS_EXT)
+ return -EINVAL;
+
+- set_bit(irq, &vcpu->arch.irqs_pending);
+- smp_mb__before_atomic();
+- set_bit(irq, &vcpu->arch.irqs_pending_mask);
++ raw_spin_lock_irqsave(&vcpu->arch.irqs_pending_lock, flags);
++ __set_bit(irq, &vcpu->arch.irqs_pending);
++ __set_bit(irq, &vcpu->arch.irqs_pending_mask);
++ raw_spin_unlock_irqrestore(&vcpu->arch.irqs_pending_lock, flags);
+
+ kvm_vcpu_kick(vcpu);
+
+@@ -734,24 +756,34 @@ int kvm_riscv_vcpu_set_interrupt(struct kvm_vcpu *vcpu, unsigned int irq)
+
+ int kvm_riscv_vcpu_unset_interrupt(struct kvm_vcpu *vcpu, unsigned int irq)
+ {
++ unsigned long flags;
++
+ if (irq != IRQ_VS_SOFT &&
+ irq != IRQ_VS_TIMER &&
+ irq != IRQ_VS_EXT)
+ return -EINVAL;
+
+- clear_bit(irq, &vcpu->arch.irqs_pending);
+- smp_mb__before_atomic();
+- set_bit(irq, &vcpu->arch.irqs_pending_mask);
++ raw_spin_lock_irqsave(&vcpu->arch.irqs_pending_lock, flags);
++ __clear_bit(irq, &vcpu->arch.irqs_pending);
++ __set_bit(irq, &vcpu->arch.irqs_pending_mask);
++ raw_spin_unlock_irqrestore(&vcpu->arch.irqs_pending_lock, flags);
+
+ return 0;
+ }
+
+ bool kvm_riscv_vcpu_has_interrupts(struct kvm_vcpu *vcpu, unsigned long mask)
+ {
+- unsigned long ie = ((vcpu->arch.guest_csr.vsie & VSIP_VALID_MASK)
+- << VSIP_TO_HVIP_SHIFT) & mask;
++ unsigned long flags;
++ unsigned long ie;
++ bool ret;
++
++ raw_spin_lock_irqsave(&vcpu->arch.irqs_pending_lock, flags);
++ ie = ((vcpu->arch.guest_csr.vsie & VSIP_VALID_MASK)
++ << VSIP_TO_HVIP_SHIFT) & mask;
++ ret = vcpu->arch.irqs_pending & ie;
++ raw_spin_unlock_irqrestore(&vcpu->arch.irqs_pending_lock, flags);
+
+- return (READ_ONCE(vcpu->arch.irqs_pending) & ie) ? true : false;
++ return ret;
+ }
+
+ void kvm_riscv_vcpu_power_off(struct kvm_vcpu *vcpu)
+diff --git a/arch/s390/kvm/pci.c b/arch/s390/kvm/pci.c
+index 9fe8c7237eacd2..45fb77ada977c3 100644
+--- a/arch/s390/kvm/pci.c
++++ b/arch/s390/kvm/pci.c
+@@ -225,7 +225,7 @@ static int kvm_s390_pci_aif_enable(struct zpci_dev *zdev, struct zpci_fib *fib,
+ bool assist)
+ {
+ struct page *pages[1], *aibv_page, *aisb_page = NULL;
+- unsigned int msi_vecs, idx;
++ unsigned int msi_vecs, idx, size;
+ struct zpci_gaite *gaite;
+ unsigned long hva, bit;
+ struct kvm *kvm;
+@@ -239,6 +239,10 @@ static int kvm_s390_pci_aif_enable(struct zpci_dev *zdev, struct zpci_fib *fib,
+ if (zdev->gisa == 0)
+ return -EINVAL;
+
++ /* AIF already enabled for the device */
++ if (zdev->kzdev->fib.fmt0.aibv != 0)
++ return -EINVAL;
++
+ kvm = zdev->kzdev->kvm;
+ msi_vecs = min_t(unsigned int, fib->fmt0.noi, zdev->max_msi);
+
+@@ -248,6 +252,14 @@ static int kvm_s390_pci_aif_enable(struct zpci_dev *zdev, struct zpci_fib *fib,
+ return gisc;
+
+ /* Replace AIBV address */
++ size = BITS_TO_LONGS(msi_vecs + fib->fmt0.aibvo) * sizeof(unsigned long);
++ npages = DIV_ROUND_UP((fib->fmt0.aibv & ~PAGE_MASK) + size, PAGE_SIZE);
++ /* AIBV cannot span more than 1 page */
++ if (npages > 1) {
++ rc = -EINVAL;
++ goto out;
++ }
++
+ idx = srcu_read_lock(&kvm->srcu);
+ hva = gfn_to_hva(kvm, gpa_to_gfn((gpa_t)fib->fmt0.aibv));
+ npages = pin_user_pages_fast(hva, 1, FOLL_WRITE | FOLL_LONGTERM, pages);
+@@ -263,6 +275,12 @@ static int kvm_s390_pci_aif_enable(struct zpci_dev *zdev, struct zpci_fib *fib,
+
+ /* Pin the guest AISB if one was specified */
+ if (fib->fmt0.sum == 1) {
++ /* AISB must be dword aligned */
++ if (fib->fmt0.aisb & 0x7) {
++ rc = -EINVAL;
++ goto unpin1;
++ }
++
+ idx = srcu_read_lock(&kvm->srcu);
+ hva = gfn_to_hva(kvm, gpa_to_gfn((gpa_t)fib->fmt0.aisb));
+ npages = pin_user_pages_fast(hva, 1, FOLL_WRITE | FOLL_LONGTERM,
+@@ -291,6 +309,11 @@ static int kvm_s390_pci_aif_enable(struct zpci_dev *zdev, struct zpci_fib *fib,
+ AIRQ_IV_GUESTVEC,
+ phys_to_virt(fib->fmt0.aibv));
+
++ if (!zdev->aibv) {
++ rc = -ENOMEM;
++ goto free_aisb;
++ }
++
+ spin_lock_irq(&aift->gait_lock);
+ gaite = aift->gait + zdev->aisb;
+
+@@ -327,6 +350,9 @@ static int kvm_s390_pci_aif_enable(struct zpci_dev *zdev, struct zpci_fib *fib,
+ rc = kvm_zpci_set_airq(zdev);
+ return rc;
+
++free_aisb:
++ airq_iv_free_bit(aift->sbv, zdev->aisb);
++ zdev->aisb = 0;
+ unlock:
+ mutex_unlock(&aift->aift_lock);
+ unpin2:
+diff --git a/arch/um/drivers/vector_kern.c b/arch/um/drivers/vector_kern.c
+index 1a068859a41850..001777f77b3a22 100644
+--- a/arch/um/drivers/vector_kern.c
++++ b/arch/um/drivers/vector_kern.c
+@@ -1007,6 +1007,9 @@ static int vector_mmsg_rx(struct vector_private *vp, int budget)
+ */
+ dev_kfree_skb_irq(skb);
+ vp->estats.rx_encaps_errors++;
++ (*skbuff_vector) = NULL;
++ mmsg_vector++;
++ skbuff_vector++;
+ continue;
+ }
+ if (header_check > 0) {
+diff --git a/arch/x86/boot/compressed/Makefile b/arch/x86/boot/compressed/Makefile
+index 21e1a3b6639da9..85002f6e3f71f5 100644
+--- a/arch/x86/boot/compressed/Makefile
++++ b/arch/x86/boot/compressed/Makefile
+@@ -36,6 +36,7 @@ targets := vmlinux vmlinux.bin vmlinux.bin.gz vmlinux.bin.bz2 vmlinux.bin.lzma \
+ KBUILD_CFLAGS := -m$(BITS) -O2 $(CLANG_FLAGS)
+ KBUILD_CFLAGS += -std=gnu11
+ KBUILD_CFLAGS += -fno-strict-aliasing -fPIE
++KBUILD_CFLAGS += -fno-jump-tables
+ KBUILD_CFLAGS += -Wundef
+ KBUILD_CFLAGS += -DDISABLE_BRANCH_PROFILING
+ cflags-$(CONFIG_X86_32) := -march=i386
+diff --git a/arch/x86/events/amd/brs.c b/arch/x86/events/amd/brs.c
+index f1bff153d94578..fd46e73cb8e716 100644
+--- a/arch/x86/events/amd/brs.c
++++ b/arch/x86/events/amd/brs.c
+@@ -262,13 +262,13 @@ void amd_brs_disable_all(void)
+ amd_brs_disable();
+ }
+
+-static bool amd_brs_match_plm(struct perf_event *event, u64 to)
++static bool amd_brs_match_plm(struct perf_event *event, u64 from, u64 to)
+ {
+ int type = event->attr.branch_sample_type;
+ int plm_k = PERF_SAMPLE_BRANCH_KERNEL | PERF_SAMPLE_BRANCH_HV;
+ int plm_u = PERF_SAMPLE_BRANCH_USER;
+
+- if (!(type & plm_k) && kernel_ip(to))
++ if (!(type & plm_k) && (kernel_ip(to) || kernel_ip(from)))
+ return 0;
+
+ if (!(type & plm_u) && !kernel_ip(to))
+@@ -341,11 +341,11 @@ void amd_brs_drain(void)
+ */
+ to = (u64)(((s64)to << shift) >> shift);
+
+- if (!amd_brs_match_plm(event, to))
+- continue;
+-
+ rdmsrl(brs_from(brs_idx), from);
+
++ if (!amd_brs_match_plm(event, from, to))
++ continue;
++
+ perf_clear_branch_entry_bitfields(br+nr);
+
+ br[nr].from = from;
+diff --git a/arch/x86/include/asm/nospec-branch.h b/arch/x86/include/asm/nospec-branch.h
+index 6a0071b560f9bd..353344b8bb9613 100644
+--- a/arch/x86/include/asm/nospec-branch.h
++++ b/arch/x86/include/asm/nospec-branch.h
+@@ -293,6 +293,10 @@ void srso_safe_ret(void);
+ void srso_alias_safe_ret(void);
+ void handle_interrupted_saferet(struct pt_regs *regs);
+
++#ifdef CONFIG_BPF_JIT
++extern void bpf_arch_ibpb(void);
++#endif
++
+ #ifdef CONFIG_X86_64
+ extern void clear_bhb_loop(void);
+ #endif
+diff --git a/arch/x86/kernel/cpu/bugs.c b/arch/x86/kernel/cpu/bugs.c
+index 3af97b5097927c..04e7c4e70dcc6c 100644
+--- a/arch/x86/kernel/cpu/bugs.c
++++ b/arch/x86/kernel/cpu/bugs.c
+@@ -16,6 +16,7 @@
+ #include <linux/sched/smt.h>
+ #include <linux/pgtable.h>
+ #include <linux/bpf.h>
++#include <linux/filter.h>
+
+ #include <asm/spec-ctrl.h>
+ #include <asm/cmdline.h>
+@@ -1298,8 +1299,21 @@ static inline const char *spectre_v2_module_string(void)
+ {
+ return spectre_v2_bad_module ? " - vulnerable module loaded" : "";
+ }
++
++/*
++ * The "retpoline sequence" is the "call;mov;ret" sequence that
++ * replaces normal indirect branch instructions. Differentiate
++ * *the* retpoline sequence from the LFENCE-prefixed indirect
++ * branches that simply use the retpoline infrastructure.
++ */
++static inline bool retpoline_seq_enabled(void)
++{
++ return boot_cpu_has(X86_FEATURE_RETPOLINE) && !boot_cpu_has(X86_FEATURE_RETPOLINE_LFENCE);
++}
++
+ #else
+ static inline const char *spectre_v2_module_string(void) { return ""; }
++static inline bool retpoline_seq_enabled(void) { return false; }
+ #endif
+
+ #define SPECTRE_V2_LFENCE_MSG "WARNING: LFENCE mitigation is not recommended for this CPU, data leaks possible!\n"
+@@ -1780,8 +1794,7 @@ static void __init bhi_select_mitigation(void)
+ return;
+
+ /* Retpoline mitigates against BHI unless the CPU has RRSBA behavior */
+- if (boot_cpu_has(X86_FEATURE_RETPOLINE) &&
+- !boot_cpu_has(X86_FEATURE_RETPOLINE_LFENCE)) {
++ if (retpoline_seq_enabled()) {
+ spec_ctrl_disable_kernel_rrsba();
+ if (rrsba_disabled)
+ return;
+@@ -1803,6 +1816,27 @@ static void __init bhi_select_mitigation(void)
+ pr_info("Spectre BHI mitigation: SW BHB clearing on syscall\n");
+ }
+
++#ifdef CONFIG_BPF_JIT
++static void __bpf_arch_ibpb(void *unused)
++{
++ entry_ibpb();
++}
++
++void bpf_arch_ibpb(void)
++{
++ on_each_cpu(__bpf_arch_ibpb, NULL, 1);
++}
++
++static bool __init cpu_wants_ibpb_bpf(void)
++{
++ /* A genuine retpoline already neutralizes ring0 indirect predictions */
++ if (retpoline_seq_enabled())
++ return false;
++
++ return boot_cpu_has(X86_FEATURE_IBPB);
++}
++#endif
++
+ static void __init spectre_v2_select_mitigation(void)
+ {
+ enum spectre_v2_mitigation_cmd cmd = spectre_v2_parse_cmdline();
+@@ -1985,6 +2019,14 @@ static void __init spectre_v2_select_mitigation(void)
+ pr_info("Enabling Restricted Speculation for firmware calls\n");
+ }
+
++#ifdef CONFIG_BPF_JIT
++ if (cpu_wants_ibpb_bpf()) {
++ static_call_update(bpf_arch_pred_flush, bpf_arch_ibpb);
++ static_branch_enable(&bpf_pred_flush_enabled);
++ pr_info("Enabling IBPB for BPF\n");
++ }
++#endif
++
+ /* Set up IBPB and STIBP depending on the general spectre V2 command */
+ spectre_v2_cmd = cmd;
+ }
+@@ -3157,9 +3199,7 @@ static const char *spectre_bhi_state(void)
+ return "; BHI: BHI_DIS_S";
+ else if (boot_cpu_has(X86_FEATURE_CLEAR_BHB_LOOP))
+ return "; BHI: SW loop, KVM: SW loop";
+- else if (boot_cpu_has(X86_FEATURE_RETPOLINE) &&
+- !boot_cpu_has(X86_FEATURE_RETPOLINE_LFENCE) &&
+- rrsba_disabled)
++ else if (retpoline_seq_enabled() && rrsba_disabled)
+ return "; BHI: Retpoline";
+ else if (boot_cpu_has(X86_FEATURE_CLEAR_BHB_LOOP_ON_VMEXIT))
+ return "; BHI: Vulnerable, KVM: SW loop";
+diff --git a/arch/x86/kvm/mmu/mmu.c b/arch/x86/kvm/mmu/mmu.c
+index 7785da8f0ad339..d7f1fbf8a83d0f 100644
+--- a/arch/x86/kvm/mmu/mmu.c
++++ b/arch/x86/kvm/mmu/mmu.c
+@@ -2201,6 +2201,9 @@ static union kvm_mmu_page_role kvm_mmu_child_role(u64 *sptep, bool direct,
+ role.direct = direct;
+ role.passthrough = 0;
+
++ WARN_ON_ONCE(role.invalid);
++ role.invalid = 0;
++
+ /*
+ * If the guest has 4-byte PTEs then that means it's using 32-bit,
+ * 2-level, non-PAE paging. KVM shadows such guests with PAE paging
+@@ -3102,11 +3105,11 @@ void disallowed_hugepage_adjust(struct kvm_page_fault *fault, u64 spte, int cur_
+ is_shadow_present_pte(spte) &&
+ !is_large_pte(spte)) {
+ /*
+- * A small SPTE exists for this pfn, but FNAME(fetch)
+- * and __direct_map would like to create a large PTE
+- * instead: just force them to go down another level,
+- * patching back for them into pfn the next 9 bits of
+- * the address.
++ * A small SPTE exists for this pfn, but FNAME(fetch),
++ * direct_map(), or kvm_tdp_mmu_map() would like to create a
++ * large PTE instead: just force them to go down another level,
++ * patching back for them into pfn the next 9 bits of the
++ * address.
+ */
+ u64 page_mask = KVM_PAGES_PER_HPAGE(cur_level) -
+ KVM_PAGES_PER_HPAGE(cur_level - 1);
+@@ -3115,7 +3118,7 @@ void disallowed_hugepage_adjust(struct kvm_page_fault *fault, u64 spte, int cur_
+ }
+ }
+
+-static int __direct_map(struct kvm_vcpu *vcpu, struct kvm_page_fault *fault)
++static int direct_map(struct kvm_vcpu *vcpu, struct kvm_page_fault *fault)
+ {
+ struct kvm_shadow_walk_iterator it;
+ struct kvm_mmu_page *sp;
+@@ -4157,6 +4160,9 @@ static int kvm_faultin_pfn(struct kvm_vcpu *vcpu, struct kvm_page_fault *fault)
+ struct kvm_memory_slot *slot = fault->slot;
+ bool async;
+
++ fault->mmu_seq = vcpu->kvm->mmu_invalidate_seq;
++ smp_rmb();
++
+ /*
+ * Retry the page fault if the gfn hit a memslot that is being deleted
+ * or moved. This ensures any existing SPTEs for the old memslot will
+@@ -4213,8 +4219,7 @@ static int kvm_faultin_pfn(struct kvm_vcpu *vcpu, struct kvm_page_fault *fault)
+ * root was invalidated by a memslot update or a relevant mmu_notifier fired.
+ */
+ static bool is_page_fault_stale(struct kvm_vcpu *vcpu,
+- struct kvm_page_fault *fault,
+- unsigned long mmu_seq)
++ struct kvm_page_fault *fault)
+ {
+ struct kvm_mmu_page *sp = to_shadow_page(vcpu->arch.mmu->root.hpa);
+
+@@ -4234,14 +4239,13 @@ static bool is_page_fault_stale(struct kvm_vcpu *vcpu,
+ return true;
+
+ return fault->slot &&
+- mmu_invalidate_retry_hva(vcpu->kvm, mmu_seq, fault->hva);
++ mmu_invalidate_retry_hva(vcpu->kvm, fault->mmu_seq, fault->hva);
+ }
+
+ static int direct_page_fault(struct kvm_vcpu *vcpu, struct kvm_page_fault *fault)
+ {
+ bool is_tdp_mmu_fault = is_tdp_mmu(vcpu->arch.mmu);
+
+- unsigned long mmu_seq;
+ kvm_pfn_t orig_pfn;
+ int r;
+
+@@ -4259,43 +4263,42 @@ static int direct_page_fault(struct kvm_vcpu *vcpu, struct kvm_page_fault *fault
+ if (r)
+ return r;
+
+- mmu_seq = vcpu->kvm->mmu_invalidate_seq;
+- smp_rmb();
+-
+ r = kvm_faultin_pfn(vcpu, fault);
+ if (r != RET_PF_CONTINUE)
+ return r;
+-
+ r = handle_abnormal_pfn(vcpu, fault, ACC_ALL);
+ if (r != RET_PF_CONTINUE)
+ return r;
+
+ orig_pfn = fault->pfn;
+
+- r = RET_PF_RETRY;
+-
+- if (is_tdp_mmu_fault)
++ if (is_tdp_mmu_fault) {
++ r = RET_PF_RETRY;
+ read_lock(&vcpu->kvm->mmu_lock);
+- else
+- write_lock(&vcpu->kvm->mmu_lock);
+
+- if (is_page_fault_stale(vcpu, fault, mmu_seq))
++ if (!is_page_fault_stale(vcpu, fault))
++ r = kvm_tdp_mmu_map(vcpu, fault);
++
++ read_unlock(&vcpu->kvm->mmu_lock);
++ kvm_release_pfn_clean(orig_pfn);
++ return r;
++ }
++
++ write_lock(&vcpu->kvm->mmu_lock);
++
++ r = make_mmu_pages_available(vcpu);
++ if (r)
+ goto out_unlock;
+
+- if (is_tdp_mmu_fault) {
+- r = kvm_tdp_mmu_map(vcpu, fault);
+- } else {
+- r = make_mmu_pages_available(vcpu);
+- if (r)
+- goto out_unlock;
+- r = __direct_map(vcpu, fault);
++ if (is_page_fault_stale(vcpu, fault)) {
++ r = RET_PF_RETRY;
++ goto out_unlock;
+ }
+
++ r = direct_map(vcpu, fault);
++
+ out_unlock:
+- if (is_tdp_mmu_fault)
+- read_unlock(&vcpu->kvm->mmu_lock);
+- else
+- write_unlock(&vcpu->kvm->mmu_lock);
++ write_unlock(&vcpu->kvm->mmu_lock);
+ kvm_release_pfn_clean(orig_pfn);
+ return r;
+ }
+@@ -6643,7 +6646,9 @@ static struct shrinker mmu_shrinker = {
+ static void mmu_destroy_caches(void)
+ {
+ kmem_cache_destroy(pte_list_desc_cache);
++ pte_list_desc_cache = NULL;
+ kmem_cache_destroy(mmu_page_header_cache);
++ mmu_page_header_cache = NULL;
+ }
+
+ static int get_nx_huge_pages(char *buffer, const struct kernel_param *kp)
+diff --git a/arch/x86/kvm/mmu/mmu_internal.h b/arch/x86/kvm/mmu/mmu_internal.h
+index 5e4be3bb3624ce..009024d421831a 100644
+--- a/arch/x86/kvm/mmu/mmu_internal.h
++++ b/arch/x86/kvm/mmu/mmu_internal.h
+@@ -197,7 +197,7 @@ struct kvm_page_fault {
+
+ /*
+ * Maximum page size that can be created for this fault; input to
+- * FNAME(fetch), __direct_map and kvm_tdp_mmu_map.
++ * FNAME(fetch), direct_map() and kvm_tdp_mmu_map().
+ */
+ u8 max_level;
+
+@@ -220,6 +220,7 @@ struct kvm_page_fault {
+ struct kvm_memory_slot *slot;
+
+ /* Outputs of kvm_faultin_pfn. */
++ unsigned long mmu_seq;
+ kvm_pfn_t pfn;
+ hva_t hva;
+ bool map_writable;
+diff --git a/arch/x86/kvm/mmu/paging_tmpl.h b/arch/x86/kvm/mmu/paging_tmpl.h
+index 1c7d73b8081c60..2ea7bd1a6bb5f4 100644
+--- a/arch/x86/kvm/mmu/paging_tmpl.h
++++ b/arch/x86/kvm/mmu/paging_tmpl.h
+@@ -792,7 +792,6 @@ static int FNAME(page_fault)(struct kvm_vcpu *vcpu, struct kvm_page_fault *fault
+ struct guest_walker walker;
+ kvm_pfn_t orig_pfn;
+ int r;
+- unsigned long mmu_seq;
+ bool is_self_change_mapping;
+
+ pgprintk("%s: addr %lx err %x\n", __func__, fault->addr, fault->error_code);
+@@ -837,9 +836,6 @@ static int FNAME(page_fault)(struct kvm_vcpu *vcpu, struct kvm_page_fault *fault
+ else
+ fault->max_level = walker.level;
+
+- mmu_seq = vcpu->kvm->mmu_invalidate_seq;
+- smp_rmb();
+-
+ r = kvm_faultin_pfn(vcpu, fault);
+ if (r != RET_PF_CONTINUE)
+ return r;
+@@ -869,15 +865,17 @@ static int FNAME(page_fault)(struct kvm_vcpu *vcpu, struct kvm_page_fault *fault
+
+ orig_pfn = fault->pfn;
+
+- r = RET_PF_RETRY;
+ write_lock(&vcpu->kvm->mmu_lock);
+
+- if (is_page_fault_stale(vcpu, fault, mmu_seq))
+- goto out_unlock;
+-
+ r = make_mmu_pages_available(vcpu);
+ if (r)
+ goto out_unlock;
++
++ if (is_page_fault_stale(vcpu, fault)) {
++ r = RET_PF_RETRY;
++ goto out_unlock;
++ }
++
+ r = FNAME(fetch)(vcpu, fault, &walker);
+
+ out_unlock:
+diff --git a/arch/x86/kvm/svm/avic.c b/arch/x86/kvm/svm/avic.c
+index 8ca9bfc7654009..3292f8b9517e3f 100644
+--- a/arch/x86/kvm/svm/avic.c
++++ b/arch/x86/kvm/svm/avic.c
+@@ -120,14 +120,6 @@ static void avic_deactivate_vmcb(struct vcpu_svm *svm)
+ if (!sev_es_guest(svm->vcpu.kvm))
+ svm_set_intercept(svm, INTERCEPT_CR8_WRITE);
+
+- /*
+- * If running nested and the guest uses its own MSR bitmap, there
+- * is no need to update L0's msr bitmap
+- */
+- if (is_guest_mode(&svm->vcpu) &&
+- vmcb12_is_intercept(&svm->nested.ctl, INTERCEPT_MSR_PROT))
+- return;
+-
+ /* Enabling MSR intercept for x2APIC registers */
+ svm_set_x2apic_msr_interception(svm, true);
+ }
+diff --git a/arch/x86/kvm/svm/svm.c b/arch/x86/kvm/svm/svm.c
+index 4dae35d8696727..88979fefaa284d 100644
+--- a/arch/x86/kvm/svm/svm.c
++++ b/arch/x86/kvm/svm/svm.c
+@@ -589,7 +589,12 @@ static int svm_hardware_enable(void)
+ return -EINVAL;
+ }
+ sd = per_cpu_ptr(&svm_data, me);
+- sd->asid_generation = 1;
++ /*
++ * Bump the current asid_generation value to ensure any vCPU that
++ * previously ran on this CPU sees a stale generation and is forced
++ * to acquire a new ASID, preventing a latent ASID collision.
++ */
++ sd->asid_generation++;
+ sd->max_asid = cpuid_ebx(SVM_CPUID_FUNC) - 1;
+ sd->next_asid = sd->max_asid + 1;
+ sd->min_asid = max_sev_asid + 1;
+diff --git a/arch/x86/kvm/vmx/nested.c b/arch/x86/kvm/vmx/nested.c
+index f7a790a28b9eee..b122ec81ecb375 100644
+--- a/arch/x86/kvm/vmx/nested.c
++++ b/arch/x86/kvm/vmx/nested.c
+@@ -287,6 +287,7 @@ static void vmx_switch_vmcs(struct kvm_vcpu *vcpu, struct loaded_vmcs *vmcs)
+ static void free_nested(struct kvm_vcpu *vcpu)
+ {
+ struct vcpu_vmx *vmx = to_vmx(vcpu);
++ struct vmcs *shadow_vmcs;
+
+ if (WARN_ON_ONCE(vmx->loaded_vmcs != &vmx->vmcs01))
+ vmx_switch_vmcs(vcpu, &vmx->vmcs01);
+@@ -304,9 +305,15 @@ static void free_nested(struct kvm_vcpu *vcpu)
+ vmx->nested.current_vmptr = INVALID_GPA;
+ if (enable_shadow_vmcs) {
+ vmx_disable_shadow_vmcs(vmx);
+- vmcs_clear(vmx->vmcs01.shadow_vmcs);
+- free_vmcs(vmx->vmcs01.shadow_vmcs);
++
++ /*
++ * Keep the pointer visible until after VMCLEAR, so migration
++ * can clear an active shadow VMCS on the old CPU.
++ */
++ shadow_vmcs = vmx->vmcs01.shadow_vmcs;
++ vmcs_clear(shadow_vmcs);
+ vmx->vmcs01.shadow_vmcs = NULL;
++ free_vmcs(shadow_vmcs);
+ }
+ kfree(vmx->nested.cached_vmcs12);
+ vmx->nested.cached_vmcs12 = NULL;
+diff --git a/arch/x86/net/bpf_jit_comp.c b/arch/x86/net/bpf_jit_comp.c
+index 095fec941bb739..30c6a021abcaf0 100644
+--- a/arch/x86/net/bpf_jit_comp.c
++++ b/arch/x86/net/bpf_jit_comp.c
+@@ -2553,7 +2553,8 @@ out_image:
+ /* allocate module memory for x86 insns and extable */
+ header = bpf_jit_binary_pack_alloc(roundup(proglen, align) + extable_size,
+ &image, align, &rw_header, &rw_image,
+- jit_fill_hole);
++ jit_fill_hole,
++ bpf_prog_was_classic(prog));
+ if (!header) {
+ prog = orig_prog;
+ goto out_addrs;
+diff --git a/crypto/rsa-pkcs1pad.c b/crypto/rsa-pkcs1pad.c
+index 1cf267bc6f9ea1..5d732977bba0d4 100644
+--- a/crypto/rsa-pkcs1pad.c
++++ b/crypto/rsa-pkcs1pad.c
+@@ -537,7 +537,7 @@ static int pkcs1pad_verify(struct akcipher_request *req)
+ const unsigned int digest_size = req->dst_len;
+ int err;
+
+- if (WARN_ON(req->dst) || WARN_ON(!digest_size) ||
++ if (WARN_ON(req->dst) || !digest_size ||
+ !ctx->key_size || sig_size != ctx->key_size)
+ return -EINVAL;
+
+diff --git a/drivers/ata/ahci.h b/drivers/ata/ahci.h
+index f9c5906a8afa8c..c911ae970cbbe0 100644
+--- a/drivers/ata/ahci.h
++++ b/drivers/ata/ahci.h
+@@ -330,7 +330,7 @@ struct ahci_port_priv {
+ struct ahci_host_priv {
+ /* Input fields */
+ unsigned int flags; /* AHCI_HFLAG_* */
+- u32 mask_port_map; /* mask out particular bits */
++ u32 mask_port_map; /* Mask of valid ports */
+
+ void __iomem * mmio; /* bus-independent mem map */
+ u32 cap; /* cap to use */
+@@ -381,6 +381,21 @@ struct ahci_host_priv {
+ int port);
+ };
+
++/*
++ * Return true if a port should be ignored because it is excluded from
++ * the host port map.
++ */
++static inline bool ahci_ignore_port(struct ahci_host_priv *hpriv,
++ unsigned int portid)
++{
++ if (portid >= hpriv->nports)
++ return true;
++ /* mask_port_map not set means that all ports are available */
++ if (!hpriv->mask_port_map)
++ return false;
++ return !(hpriv->mask_port_map & (1 << portid));
++}
++
+ extern int ahci_ignore_sss;
+
+ extern const struct attribute_group *ahci_shost_groups[];
+diff --git a/drivers/ata/ahci_brcm.c b/drivers/ata/ahci_brcm.c
+index 6f216eb2561004..ee708dafd08d1f 100644
+--- a/drivers/ata/ahci_brcm.c
++++ b/drivers/ata/ahci_brcm.c
+@@ -288,6 +288,9 @@ static unsigned int brcm_ahci_read_id(struct ata_device *dev,
+
+ /* Re-initialize and calibrate the PHY */
+ for (i = 0; i < hpriv->nports; i++) {
++ if (ahci_ignore_port(hpriv, i))
++ continue;
++
+ rc = phy_init(hpriv->phys[i]);
+ if (rc)
+ goto disable_phys;
+diff --git a/drivers/ata/ahci_ceva.c b/drivers/ata/ahci_ceva.c
+index 50e07ea60e45c8..0651d4065f7f77 100644
+--- a/drivers/ata/ahci_ceva.c
++++ b/drivers/ata/ahci_ceva.c
+@@ -206,15 +206,21 @@ static int ceva_ahci_platform_enable_resources(struct ahci_host_priv *hpriv)
+ goto disable_clks;
+
+ for (i = 0; i < hpriv->nports; i++) {
++ if (ahci_ignore_port(hpriv, i))
++ continue;
++
+ rc = phy_init(hpriv->phys[i]);
+ if (rc)
+- goto disable_rsts;
++ goto exit_phys;
+ }
+
+ /* De-assert the controller reset */
+ ahci_platform_deassert_rsts(hpriv);
+
+ for (i = 0; i < hpriv->nports; i++) {
++ if (ahci_ignore_port(hpriv, i))
++ continue;
++
+ rc = phy_power_on(hpriv->phys[i]);
+ if (rc) {
+ phy_exit(hpriv->phys[i]);
+@@ -224,14 +230,24 @@ static int ceva_ahci_platform_enable_resources(struct ahci_host_priv *hpriv)
+
+ return 0;
+
+-disable_rsts:
+- ahci_platform_deassert_rsts(hpriv);
+-
+ disable_phys:
+ while (--i >= 0) {
++ if (ahci_ignore_port(hpriv, i))
++ continue;
++
+ phy_power_off(hpriv->phys[i]);
+ phy_exit(hpriv->phys[i]);
+ }
++ ahci_platform_assert_rsts(hpriv);
++ goto disable_clks;
++
++exit_phys:
++ while (--i >= 0) {
++ if (ahci_ignore_port(hpriv, i))
++ continue;
++
++ phy_exit(hpriv->phys[i]);
++ }
+
+ disable_clks:
+ ahci_platform_disable_clks(hpriv);
+diff --git a/drivers/ata/libahci.c b/drivers/ata/libahci.c
+index 1b1671c027cd34..ec4809862918f3 100644
+--- a/drivers/ata/libahci.c
++++ b/drivers/ata/libahci.c
+@@ -539,6 +539,7 @@ void ahci_save_initial_config(struct device *dev, struct ahci_host_priv *hpriv)
+ hpriv->saved_port_map = port_map;
+ }
+
++ /* mask_port_map not set means that all ports are available */
+ if (hpriv->mask_port_map) {
+ dev_warn(dev, "masking port_map 0x%lx -> 0x%lx\n",
+ port_map,
+diff --git a/drivers/ata/libahci_platform.c b/drivers/ata/libahci_platform.c
+index b9e336bacf179b..d4fccc0625800d 100644
+--- a/drivers/ata/libahci_platform.c
++++ b/drivers/ata/libahci_platform.c
+@@ -48,6 +48,9 @@ int ahci_platform_enable_phys(struct ahci_host_priv *hpriv)
+ int rc, i;
+
+ for (i = 0; i < hpriv->nports; i++) {
++ if (ahci_ignore_port(hpriv, i))
++ continue;
++
+ rc = phy_init(hpriv->phys[i]);
+ if (rc)
+ goto disable_phys;
+@@ -69,6 +72,9 @@ int ahci_platform_enable_phys(struct ahci_host_priv *hpriv)
+
+ disable_phys:
+ while (--i >= 0) {
++ if (ahci_ignore_port(hpriv, i))
++ continue;
++
+ phy_power_off(hpriv->phys[i]);
+ phy_exit(hpriv->phys[i]);
+ }
+@@ -87,6 +93,9 @@ void ahci_platform_disable_phys(struct ahci_host_priv *hpriv)
+ int i;
+
+ for (i = 0; i < hpriv->nports; i++) {
++ if (ahci_ignore_port(hpriv, i))
++ continue;
++
+ phy_power_off(hpriv->phys[i]);
+ phy_exit(hpriv->phys[i]);
+ }
+@@ -434,6 +443,20 @@ static int ahci_platform_get_firmware(struct ahci_host_priv *hpriv,
+ return 0;
+ }
+
++static u32 ahci_platform_find_max_port_id(struct device *dev)
++{
++ u32 max_port = 0;
++
++ for_each_child_of_node_scoped(dev->of_node, child) {
++ u32 port;
++
++ if (!of_property_read_u32(child, "reg", &port))
++ max_port = max(max_port, port);
++ }
++
++ return max_port;
++}
++
+ /**
+ * ahci_platform_get_resources - Get platform resources
+ * @pdev: platform device to get resources for
+@@ -461,6 +484,7 @@ struct ahci_host_priv *ahci_platform_get_resources(struct platform_device *pdev,
+ struct ahci_host_priv *hpriv;
+ struct device_node *child;
+ u32 mask_port_map = 0;
++ u32 max_port;
+
+ if (!devres_open_group(dev, NULL, GFP_KERNEL))
+ return ERR_PTR(-ENOMEM);
+@@ -552,15 +576,17 @@ struct ahci_host_priv *ahci_platform_get_resources(struct platform_device *pdev,
+ goto err_out;
+ }
+
++ /* find maximum port id for allocating structures */
++ max_port = ahci_platform_find_max_port_id(dev);
+ /*
+- * If no sub-node was found, we still need to set nports to
+- * one in order to be able to use the
++ * Set nports according to maximum port id. Clamp at
++ * AHCI_MAX_PORTS, warning message for invalid port id
++ * is generated later.
++ * When DT has no sub-nodes max_port is 0, nports is 1,
++ * in order to be able to use the
+ * ahci_platform_[en|dis]able_[phys|regulators] functions.
+ */
+- if (child_nodes)
+- hpriv->nports = child_nodes;
+- else
+- hpriv->nports = 1;
++ hpriv->nports = min(AHCI_MAX_PORTS, max_port + 1);
+
+ hpriv->phys = devm_kcalloc(dev, hpriv->nports, sizeof(*hpriv->phys), GFP_KERNEL);
+ if (!hpriv->phys) {
+diff --git a/drivers/ata/pata_sl82c105.c b/drivers/ata/pata_sl82c105.c
+index 8487470e2e01ef..c32f3b490bb35f 100644
+--- a/drivers/ata/pata_sl82c105.c
++++ b/drivers/ata/pata_sl82c105.c
+@@ -265,6 +265,7 @@ static struct ata_port_operations sl82c105_port_ops = {
+ static int sl82c105_bridge_revision(struct pci_dev *pdev)
+ {
+ struct pci_dev *bridge;
++ u8 revision;
+
+ /*
+ * The bridge should be part of the same device, but function 0.
+@@ -286,8 +287,9 @@ static int sl82c105_bridge_revision(struct pci_dev *pdev)
+ /*
+ * We need to find function 0's revision, not function 1
+ */
++ revision = bridge->revision;
+ pci_dev_put(bridge);
+- return bridge->revision;
++ return revision;
+ }
+
+ static void sl82c105_fixup(struct pci_dev *pdev)
+diff --git a/drivers/ata/sata_dwc_460ex.c b/drivers/ata/sata_dwc_460ex.c
+index e3263e961045ac..24bc1b755dc748 100644
+--- a/drivers/ata/sata_dwc_460ex.c
++++ b/drivers/ata/sata_dwc_460ex.c
+@@ -403,8 +403,7 @@ static void clear_serror(struct ata_port *ap)
+
+ static void clear_interrupt_bit(struct sata_dwc_device *hsdev, u32 bit)
+ {
+- sata_dwc_writel(&hsdev->sata_dwc_regs->intpr,
+- sata_dwc_readl(&hsdev->sata_dwc_regs->intpr));
++ sata_dwc_writel(&hsdev->sata_dwc_regs->intpr, bit);
+ }
+
+ static u32 qcmd_tag_to_mask(u8 tag)
+@@ -1175,9 +1174,6 @@ static int sata_dwc_probe(struct platform_device *ofdev)
+ /* Save dev for later use in dev_xxx() routines */
+ hsdev->dev = dev;
+
+- /* Enable SATA Interrupts */
+- sata_dwc_enable_interrupts(hsdev);
+-
+ /* Get SATA interrupt number */
+ irq = irq_of_parse_and_map(np, 0);
+ if (irq == NO_IRQ) {
+@@ -1210,6 +1206,8 @@ static int sata_dwc_probe(struct platform_device *ofdev)
+ if (err)
+ dev_err(dev, "failed to activate host");
+
++ /* Enable SATA Interrupts */
++ sata_dwc_enable_interrupts(hsdev);
+ return 0;
+
+ error_out:
+diff --git a/drivers/ata/sata_mv.c b/drivers/ata/sata_mv.c
+index 9cf540017a5e56..298bf6330de577 100644
+--- a/drivers/ata/sata_mv.c
++++ b/drivers/ata/sata_mv.c
+@@ -4026,7 +4026,7 @@ static int mv_platform_probe(struct platform_device *pdev)
+ /*
+ * Simple resource validation ..
+ */
+- if (unlikely(pdev->num_resources != 1)) {
++ if (unlikely(pdev->num_resources != 1 && pdev->num_resources != 2)) {
+ dev_err(&pdev->dev, "invalid number of resources\n");
+ return -EINVAL;
+ }
+diff --git a/drivers/block/rbd.c b/drivers/block/rbd.c
+index d41615a7ce6194..4beadd97be04bc 100644
+--- a/drivers/block/rbd.c
++++ b/drivers/block/rbd.c
+@@ -1957,9 +1957,14 @@ static int rbd_object_map_update_finish(struct rbd_obj_request *obj_req,
+ bool has_current_state;
+ void *p;
+
+- if (osd_req->r_result)
++ if (osd_req->r_result < 0)
+ return osd_req->r_result;
+
++ /*
++ * Writes aren't allowed to return a data payload.
++ */
++ WARN_ON_ONCE(osd_req->r_result > 0);
++
+ /*
+ * Nothing to do for a snapshot object map.
+ */
+diff --git a/drivers/block/ublk_drv.c b/drivers/block/ublk_drv.c
+index 00d29a3c3d2849..c41bb08efb12c3 100644
+--- a/drivers/block/ublk_drv.c
++++ b/drivers/block/ublk_drv.c
+@@ -1726,6 +1726,15 @@ static int ublk_ctrl_add_dev(struct io_uring_cmd *cmd)
+ /* update device id */
+ ub->dev_info.dev_id = ub->ub_number;
+
++ /*
++ * ->state and ->ublksrv_pid are owned by the driver and only read back
++ * by userspace, but they come from the copied-in dev_info, so reset
++ * them. Otherwise a device added with ->state != DEAD looks live while
++ * ->ub_disk is still NULL.
++ */
++ ub->dev_info.state = UBLK_S_DEV_DEAD;
++ ub->dev_info.ublksrv_pid = -1;
++
+ /*
+ * 64bit flags will be copied back to userspace as feature
+ * negotiation result, so have to clear flags which driver
+diff --git a/drivers/bluetooth/btqca.c b/drivers/bluetooth/btqca.c
+index 5b34da23adce7c..09ef7df5c231bf 100644
+--- a/drivers/bluetooth/btqca.c
++++ b/drivers/bluetooth/btqca.c
+@@ -430,7 +430,7 @@ static int qca_tlv_check_data(struct hci_dev *hdev,
+
+ idx = 0;
+ data = tlv->data;
+- while (idx < length - sizeof(struct tlv_type_nvm)) {
++ while (idx + sizeof(struct tlv_type_nvm) <= length) {
+ tlv_nvm = (struct tlv_type_nvm *)(data + idx);
+
+ tag_id = le16_to_cpu(tlv_nvm->tag_id);
+diff --git a/drivers/cdrom/cdrom.c b/drivers/cdrom/cdrom.c
+index bba9eb8e2ca903..a638f86229bf58 100644
+--- a/drivers/cdrom/cdrom.c
++++ b/drivers/cdrom/cdrom.c
+@@ -3205,6 +3205,7 @@ static noinline int mmc_ioctl_cdrom_volume(struct cdrom_device_info *cdi,
+
+ /* set volume */
+ cgc->buffer = buffer + offset - 8;
++ cgc->buflen -= offset - 8;
+ memset(cgc->buffer, 0, 8);
+ return cdrom_mode_select(cdi, cgc);
+ }
+diff --git a/drivers/comedi/drivers/comedi_parport.c b/drivers/comedi/drivers/comedi_parport.c
+index 098738a688fe64..db9f58792ab919 100644
+--- a/drivers/comedi/drivers/comedi_parport.c
++++ b/drivers/comedi/drivers/comedi_parport.c
+@@ -211,6 +211,13 @@ static irqreturn_t parport_interrupt(int irq, void *d)
+ unsigned int ctrl;
+ unsigned short val = 0;
+
++ /*
++ * Check device is fully attached. Device interrupts should have
++ * been disabled, but do this in case of bad hardware.
++ */
++ if (!dev->attached)
++ return IRQ_NONE;
++
+ ctrl = inb(dev->iobase + PARPORT_CTRL_REG);
+ if (!(ctrl & PARPORT_CTRL_IRQ_ENA))
+ return IRQ_NONE;
+@@ -231,6 +238,9 @@ static int parport_attach(struct comedi_device *dev,
+ if (ret)
+ return ret;
+
++ outb(0, dev->iobase + PARPORT_DATA_REG);
++ outb(0, dev->iobase + PARPORT_CTRL_REG);
++
+ if (it->options[1]) {
+ ret = request_irq(it->options[1], parport_interrupt, 0,
+ dev->board_name, dev);
+@@ -286,9 +296,6 @@ static int parport_attach(struct comedi_device *dev,
+ s->cancel = parport_intr_cancel;
+ }
+
+- outb(0, dev->iobase + PARPORT_DATA_REG);
+- outb(0, dev->iobase + PARPORT_CTRL_REG);
+-
+ return 0;
+ }
+
+diff --git a/drivers/counter/microchip-tcb-capture.c b/drivers/counter/microchip-tcb-capture.c
+index 2f631729a870bb..f2cd7b599e44ec 100644
+--- a/drivers/counter/microchip-tcb-capture.c
++++ b/drivers/counter/microchip-tcb-capture.c
+@@ -310,7 +310,7 @@ static int mchp_tc_probe(struct platform_device *pdev)
+ char clk_name[7];
+ struct regmap *regmap;
+ struct clk *clk[3];
+- int channel;
++ u32 channel;
+ int ret, i;
+
+ counter = devm_counter_alloc(&pdev->dev, sizeof(*priv));
+@@ -344,7 +344,7 @@ static int mchp_tc_probe(struct platform_device *pdev)
+
+ priv->channel[i] = channel;
+
+- snprintf(clk_name, sizeof(clk_name), "t%d_clk", channel);
++ snprintf(clk_name, sizeof(clk_name), "t%u_clk", channel);
+
+ clk[i] = of_clk_get_by_name(np->parent, clk_name);
+ if (IS_ERR(clk[i])) {
+diff --git a/drivers/cpufreq/powernow-k8.c b/drivers/cpufreq/powernow-k8.c
+index b10f7a1b77f113..508bd6f68f1ee8 100644
+--- a/drivers/cpufreq/powernow-k8.c
++++ b/drivers/cpufreq/powernow-k8.c
+@@ -1083,6 +1083,7 @@ static int powernowk8_cpu_init(struct cpufreq_policy *pol)
+
+ err_out_exit_acpi:
+ powernow_k8_cpu_exit_acpi(data);
++ kfree(data->powernow_table);
+
+ err_out:
+ kfree(data);
+diff --git a/drivers/dma/sh/rz-dmac.c b/drivers/dma/sh/rz-dmac.c
+index 498e6e24ab0a37..b956292e861940 100644
+--- a/drivers/dma/sh/rz-dmac.c
++++ b/drivers/dma/sh/rz-dmac.c
+@@ -779,27 +779,6 @@ static int rz_dmac_chan_probe(struct rz_dmac *dmac,
+ channel->index = index;
+ channel->mid_rid = -EINVAL;
+
+- /* Request the channel interrupt. */
+- sprintf(pdev_irqname, "ch%u", index);
+- channel->irq = platform_get_irq_byname(pdev, pdev_irqname);
+- if (channel->irq < 0)
+- return channel->irq;
+-
+- irqname = devm_kasprintf(dmac->dev, GFP_KERNEL, "%s:%u",
+- dev_name(dmac->dev), index);
+- if (!irqname)
+- return -ENOMEM;
+-
+- ret = devm_request_threaded_irq(dmac->dev, channel->irq,
+- rz_dmac_irq_handler,
+- rz_dmac_irq_handler_thread, 0,
+- irqname, channel);
+- if (ret) {
+- dev_err(dmac->dev, "failed to request IRQ %u (%d)\n",
+- channel->irq, ret);
+- return ret;
+- }
+-
+ /* Set io base address for each channel */
+ if (index < 8) {
+ channel->ch_base = dmac->base + CHANNEL_0_7_OFFSET +
+@@ -812,9 +791,9 @@ static int rz_dmac_chan_probe(struct rz_dmac *dmac,
+ }
+
+ /* Allocate descriptors */
+- lmdesc = dma_alloc_coherent(&pdev->dev,
+- sizeof(struct rz_lmdesc) * DMAC_NR_LMDESC,
+- &channel->lmdesc.base_dma, GFP_KERNEL);
++ lmdesc = dmam_alloc_coherent(&pdev->dev,
++ sizeof(struct rz_lmdesc) * DMAC_NR_LMDESC,
++ &channel->lmdesc.base_dma, GFP_KERNEL);
+ if (!lmdesc) {
+ dev_err(&pdev->dev, "Can't allocate memory (lmdesc)\n");
+ return -ENOMEM;
+@@ -830,7 +809,26 @@ static int rz_dmac_chan_probe(struct rz_dmac *dmac,
+ INIT_LIST_HEAD(&channel->ld_free);
+ INIT_LIST_HEAD(&channel->ld_active);
+
+- return 0;
++ /* Request the channel interrupt. */
++ sprintf(pdev_irqname, "ch%u", index);
++ channel->irq = platform_get_irq_byname(pdev, pdev_irqname);
++ if (channel->irq < 0)
++ return channel->irq;
++
++ irqname = devm_kasprintf(dmac->dev, GFP_KERNEL, "%s:%u",
++ dev_name(dmac->dev), index);
++ if (!irqname)
++ return -ENOMEM;
++
++ ret = devm_request_threaded_irq(dmac->dev, channel->irq,
++ rz_dmac_irq_handler,
++ rz_dmac_irq_handler_thread, 0,
++ irqname, channel);
++ if (ret)
++ dev_err(dmac->dev, "failed to request IRQ %u (%d)\n",
++ channel->irq, ret);
++
++ return ret;
+ }
+
+ static int rz_dmac_parse_of(struct device *dev, struct rz_dmac *dmac)
+@@ -857,7 +855,6 @@ static int rz_dmac_probe(struct platform_device *pdev)
+ const char *irqname = "error";
+ struct dma_device *engine;
+ struct rz_dmac *dmac;
+- int channel_num;
+ unsigned int i;
+ int ret;
+ int irq;
+@@ -887,19 +884,6 @@ static int rz_dmac_probe(struct platform_device *pdev)
+ if (IS_ERR(dmac->ext_base))
+ return PTR_ERR(dmac->ext_base);
+
+- /* Register interrupt handler for error */
+- irq = platform_get_irq_byname(pdev, irqname);
+- if (irq < 0)
+- return irq;
+-
+- ret = devm_request_irq(&pdev->dev, irq, rz_dmac_irq_handler, 0,
+- irqname, NULL);
+- if (ret) {
+- dev_err(&pdev->dev, "failed to request IRQ %u (%d)\n",
+- irq, ret);
+- return ret;
+- }
+-
+ /* Initialize the channels. */
+ INIT_LIST_HEAD(&dmac->engine.channels);
+
+@@ -916,6 +900,21 @@ static int rz_dmac_probe(struct platform_device *pdev)
+ goto err;
+ }
+
++ /* Register interrupt handler for error */
++ irq = platform_get_irq_byname(pdev, irqname);
++ if (irq < 0) {
++ ret = irq;
++ goto err;
++ }
++
++ ret = devm_request_irq(&pdev->dev, irq, rz_dmac_irq_handler, 0,
++ irqname, NULL);
++ if (ret) {
++ dev_err(&pdev->dev, "failed to request IRQ %u (%d)\n",
++ irq, ret);
++ goto err;
++ }
++
+ /* Register the DMAC as a DMA provider for DT. */
+ ret = of_dma_controller_register(pdev->dev.of_node, rz_dmac_of_xlate,
+ NULL);
+@@ -954,16 +953,6 @@ static int rz_dmac_probe(struct platform_device *pdev)
+ dma_register_err:
+ of_dma_controller_free(pdev->dev.of_node);
+ err:
+- channel_num = i ? i - 1 : 0;
+- for (i = 0; i < channel_num; i++) {
+- struct rz_dmac_chan *channel = &dmac->channels[i];
+-
+- dma_free_coherent(&pdev->dev,
+- sizeof(struct rz_lmdesc) * DMAC_NR_LMDESC,
+- channel->lmdesc.base,
+- channel->lmdesc.base_dma);
+- }
+-
+ pm_runtime_put(&pdev->dev);
+ err_pm_disable:
+ pm_runtime_disable(&pdev->dev);
+@@ -974,16 +963,7 @@ err_pm_disable:
+ static int rz_dmac_remove(struct platform_device *pdev)
+ {
+ struct rz_dmac *dmac = platform_get_drvdata(pdev);
+- unsigned int i;
+-
+- for (i = 0; i < dmac->n_channels; i++) {
+- struct rz_dmac_chan *channel = &dmac->channels[i];
+
+- dma_free_coherent(&pdev->dev,
+- sizeof(struct rz_lmdesc) * DMAC_NR_LMDESC,
+- channel->lmdesc.base,
+- channel->lmdesc.base_dma);
+- }
+ of_dma_controller_free(pdev->dev.of_node);
+ dma_async_device_unregister(&dmac->engine);
+ pm_runtime_put(&pdev->dev);
+diff --git a/drivers/dma/sun6i-dma.c b/drivers/dma/sun6i-dma.c
+index 7ca0c26f9e872b..f6b5ad76837347 100644
+--- a/drivers/dma/sun6i-dma.c
++++ b/drivers/dma/sun6i-dma.c
+@@ -933,16 +933,13 @@ static int sun6i_dma_terminate_all(struct dma_chan *chan)
+
+ spin_lock_irqsave(&vchan->vc.lock, flags);
+
+- if (vchan->cyclic) {
+- vchan->cyclic = false;
+- if (pchan && pchan->desc) {
+- struct virt_dma_desc *vd = &pchan->desc->vd;
+- struct virt_dma_chan *vc = &vchan->vc;
++ if (pchan && pchan->desc && pchan->desc != pchan->done) {
++ struct virt_dma_desc *vd = &pchan->desc->vd;
+
+- list_add_tail(&vd->node, &vc->desc_completed);
+- }
++ vchan_terminate_vdesc(vd);
+ }
+
++ vchan->cyclic = false;
+ vchan_get_all_descriptors(&vchan->vc, &head);
+
+ if (pchan) {
+diff --git a/drivers/firewire/net.c b/drivers/firewire/net.c
+index a53eacebca3391..75fdda6171dfab 100644
+--- a/drivers/firewire/net.c
++++ b/drivers/firewire/net.c
+@@ -297,31 +297,34 @@ static struct fwnet_fragment_info *fwnet_frag_new(
+ if (fi->offset + fi->len == offset) {
+ /* The new fragment can be tacked on to the end */
+ /* Did the new fragment plug a hole? */
+- fi2 = list_entry(fi->fi_link.next,
+- struct fwnet_fragment_info, fi_link);
+- if (fi->offset + fi->len == fi2->offset) {
+- /* glue fragments together */
+- fi->len += len + fi2->len;
+- list_del(&fi2->fi_link);
+- kfree(fi2);
+- } else {
+- fi->len += len;
++ if (!list_is_last(&fi->fi_link, &pd->fi_list)) {
++ fi2 = list_next_entry(fi, fi_link);
++ if (offset + len == fi2->offset) {
++ /* glue fragments together */
++ fi->len += len + fi2->len;
++ list_del(&fi2->fi_link);
++ kfree(fi2);
++
++ return fi;
++ }
+ }
++ fi->len += len;
+
+ return fi;
+ }
+ if (offset + len == fi->offset) {
+ /* The new fragment can be tacked on to the beginning */
+ /* Did the new fragment plug a hole? */
+- fi2 = list_entry(fi->fi_link.prev,
+- struct fwnet_fragment_info, fi_link);
+- if (fi2->offset + fi2->len == fi->offset) {
+- /* glue fragments together */
+- fi2->len += fi->len + len;
+- list_del(&fi->fi_link);
+- kfree(fi);
+-
+- return fi2;
++ if (!list_is_first(&fi->fi_link, &pd->fi_list)) {
++ fi2 = list_prev_entry(fi, fi_link);
++ if (fi2->offset + fi2->len == offset) {
++ /* glue fragments together */
++ fi2->len += fi->len + len;
++ list_del(&fi->fi_link);
++ kfree(fi);
++
++ return fi2;
++ }
+ }
+ fi->offset = offset;
+ fi->len += len;
+diff --git a/drivers/firmware/arm_ffa/driver.c b/drivers/firmware/arm_ffa/driver.c
+index f7c72fcc9b5e32..67ab5698a14241 100644
+--- a/drivers/firmware/arm_ffa/driver.c
++++ b/drivers/firmware/arm_ffa/driver.c
+@@ -655,7 +655,7 @@ static int ffa_partition_info_get(const char *uuid_str,
+ uuid_t uuid;
+ struct ffa_partition_info *pbuf;
+
+- if (uuid_parse(uuid_str, &uuid)) {
++ if (!uuid_str || uuid_parse(uuid_str, &uuid)) {
+ pr_err("invalid uuid (%s)\n", uuid_str);
+ return -ENODEV;
+ }
+diff --git a/drivers/firmware/arm_scmi/notify.c b/drivers/firmware/arm_scmi/notify.c
+index 4782b115e6ec51..1bc715fe3968c3 100644
+--- a/drivers/firmware/arm_scmi/notify.c
++++ b/drivers/firmware/arm_scmi/notify.c
+@@ -595,9 +595,9 @@ int scmi_notify(const struct scmi_handle *handle, u8 proto_id, u8 evt_id,
+ return -EINVAL;
+ }
+ if (kfifo_avail(&r_evt->proto->equeue.kfifo) < sizeof(eh) + len) {
+- dev_warn(handle->dev,
+- "queue full, dropping proto_id:%d evt_id:%d ts:%lld\n",
+- proto_id, evt_id, ktime_to_ns(ts));
++ dev_warn_ratelimited(handle->dev,
++ "queue full, dropping proto_id:%d evt_id:%d ts:%lld\n",
++ proto_id, evt_id, ktime_to_ns(ts));
+ return -ENOMEM;
+ }
+
+diff --git a/drivers/firmware/stratix10-svc.c b/drivers/firmware/stratix10-svc.c
+index b25d793805ce02..c4a709f2bbc7a0 100644
+--- a/drivers/firmware/stratix10-svc.c
++++ b/drivers/firmware/stratix10-svc.c
+@@ -1065,14 +1065,16 @@ void *stratix10_svc_allocate_memory(struct stratix10_svc_chan *chan,
+ struct gen_pool *genpool = chan->ctrl->genpool;
+ size_t s = roundup(size, 1 << genpool->min_alloc_order);
+
+- pmem = devm_kzalloc(chan->ctrl->dev, sizeof(*pmem), GFP_KERNEL);
++ pmem = kzalloc(sizeof(*pmem), GFP_KERNEL);
+ if (!pmem)
+ return ERR_PTR(-ENOMEM);
+
+ guard(mutex)(&svc_mem_lock);
+ va = gen_pool_alloc(genpool, s);
+- if (!va)
++ if (!va) {
++ kfree(pmem);
+ return ERR_PTR(-ENOMEM);
++ }
+
+ memset((void *)va, 0, s);
+ pa = gen_pool_virt_to_phys(genpool, va);
+@@ -1098,6 +1100,7 @@ EXPORT_SYMBOL_GPL(stratix10_svc_allocate_memory);
+ void stratix10_svc_free_memory(struct stratix10_svc_chan *chan, void *kaddr)
+ {
+ struct stratix10_svc_data_mem *pmem;
++
+ guard(mutex)(&svc_mem_lock);
+
+ list_for_each_entry(pmem, &svc_data_mem, node)
+@@ -1106,10 +1109,9 @@ void stratix10_svc_free_memory(struct stratix10_svc_chan *chan, void *kaddr)
+ (unsigned long)kaddr, pmem->size);
+ pmem->vaddr = NULL;
+ list_del(&pmem->node);
++ kfree(pmem);
+ return;
+ }
+-
+- list_del(&svc_data_mem);
+ }
+ EXPORT_SYMBOL_GPL(stratix10_svc_free_memory);
+
+diff --git a/drivers/gpio/gpio-pca953x.c b/drivers/gpio/gpio-pca953x.c
+index f81d79a297a5cc..7b683553adf5e0 100644
+--- a/drivers/gpio/gpio-pca953x.c
++++ b/drivers/gpio/gpio-pca953x.c
+@@ -1247,9 +1247,20 @@ static int pca953x_restore_context(struct pca953x_chip *chip)
+ regcache_mark_dirty(chip->regmap);
+ ret = pca953x_regcache_sync(chip);
+ if (ret)
+- return ret;
++ goto err;
++
++ ret = regcache_sync(chip->regmap);
++ if (ret)
++ goto err;
++
++ return 0;
+
+- return regcache_sync(chip->regmap);
++err:
++ if (chip->client->irq > 0)
++ disable_irq(chip->client->irq);
++ regcache_cache_only(chip->regmap, true);
++
++ return ret;
+ }
+
+ static void pca953x_save_context(struct pca953x_chip *chip)
+diff --git a/drivers/gpio/gpio-pch.c b/drivers/gpio/gpio-pch.c
+index ee37ecb615cb17..77e84e0e6c1ba8 100644
+--- a/drivers/gpio/gpio-pch.c
++++ b/drivers/gpio/gpio-pch.c
+@@ -97,7 +97,7 @@ struct pch_gpio {
+ struct pch_gpio_reg_data pch_gpio_reg;
+ int irq_base;
+ enum pch_type_t ioh;
+- spinlock_t spinlock;
++ raw_spinlock_t spinlock;
+ };
+
+ static void pch_gpio_set(struct gpio_chip *gpio, unsigned int nr, int val)
+@@ -106,7 +106,7 @@ static void pch_gpio_set(struct gpio_chip *gpio, unsigned int nr, int val)
+ struct pch_gpio *chip = gpiochip_get_data(gpio);
+ unsigned long flags;
+
+- spin_lock_irqsave(&chip->spinlock, flags);
++ raw_spin_lock_irqsave(&chip->spinlock, flags);
+ reg_val = ioread32(&chip->reg->po);
+ if (val)
+ reg_val |= BIT(nr);
+@@ -114,7 +114,7 @@ static void pch_gpio_set(struct gpio_chip *gpio, unsigned int nr, int val)
+ reg_val &= ~BIT(nr);
+
+ iowrite32(reg_val, &chip->reg->po);
+- spin_unlock_irqrestore(&chip->spinlock, flags);
++ raw_spin_unlock_irqrestore(&chip->spinlock, flags);
+ }
+
+ static int pch_gpio_get(struct gpio_chip *gpio, unsigned int nr)
+@@ -132,7 +132,7 @@ static int pch_gpio_direction_output(struct gpio_chip *gpio, unsigned int nr,
+ u32 reg_val;
+ unsigned long flags;
+
+- spin_lock_irqsave(&chip->spinlock, flags);
++ raw_spin_lock_irqsave(&chip->spinlock, flags);
+
+ reg_val = ioread32(&chip->reg->po);
+ if (val)
+@@ -146,7 +146,7 @@ static int pch_gpio_direction_output(struct gpio_chip *gpio, unsigned int nr,
+ pm |= BIT(nr);
+ iowrite32(pm, &chip->reg->pm);
+
+- spin_unlock_irqrestore(&chip->spinlock, flags);
++ raw_spin_unlock_irqrestore(&chip->spinlock, flags);
+
+ return 0;
+ }
+@@ -157,12 +157,12 @@ static int pch_gpio_direction_input(struct gpio_chip *gpio, unsigned int nr)
+ u32 pm;
+ unsigned long flags;
+
+- spin_lock_irqsave(&chip->spinlock, flags);
++ raw_spin_lock_irqsave(&chip->spinlock, flags);
+ pm = ioread32(&chip->reg->pm);
+ pm &= BIT(gpio_pins[chip->ioh]) - 1;
+ pm &= ~BIT(nr);
+ iowrite32(pm, &chip->reg->pm);
+- spin_unlock_irqrestore(&chip->spinlock, flags);
++ raw_spin_unlock_irqrestore(&chip->spinlock, flags);
+
+ return 0;
+ }
+@@ -264,7 +264,7 @@ static int pch_irq_type(struct irq_data *d, unsigned int type)
+ return 0;
+ }
+
+- spin_lock_irqsave(&chip->spinlock, flags);
++ raw_spin_lock_irqsave(&chip->spinlock, flags);
+
+ /* Set interrupt mode */
+ im = ioread32(im_reg) & ~(PCH_IM_MASK << (im_pos * 4));
+@@ -276,7 +276,7 @@ static int pch_irq_type(struct irq_data *d, unsigned int type)
+ else if (type & IRQ_TYPE_EDGE_BOTH)
+ irq_set_handler_locked(d, handle_edge_irq);
+
+- spin_unlock_irqrestore(&chip->spinlock, flags);
++ raw_spin_unlock_irqrestore(&chip->spinlock, flags);
+ return 0;
+ }
+
+@@ -373,7 +373,7 @@ static int pch_gpio_probe(struct pci_dev *pdev,
+ chip->ioh = id->driver_data;
+ chip->reg = chip->base;
+ pci_set_drvdata(pdev, chip);
+- spin_lock_init(&chip->spinlock);
++ raw_spin_lock_init(&chip->spinlock);
+ pch_gpio_setup(chip);
+
+ ret = devm_gpiochip_add_data(dev, &chip->gpio, chip);
+@@ -406,9 +406,9 @@ static int __maybe_unused pch_gpio_suspend(struct device *dev)
+ struct pch_gpio *chip = dev_get_drvdata(dev);
+ unsigned long flags;
+
+- spin_lock_irqsave(&chip->spinlock, flags);
++ raw_spin_lock_irqsave(&chip->spinlock, flags);
+ pch_gpio_save_reg_conf(chip);
+- spin_unlock_irqrestore(&chip->spinlock, flags);
++ raw_spin_unlock_irqrestore(&chip->spinlock, flags);
+
+ return 0;
+ }
+@@ -418,11 +418,11 @@ static int __maybe_unused pch_gpio_resume(struct device *dev)
+ struct pch_gpio *chip = dev_get_drvdata(dev);
+ unsigned long flags;
+
+- spin_lock_irqsave(&chip->spinlock, flags);
++ raw_spin_lock_irqsave(&chip->spinlock, flags);
+ iowrite32(0x01, &chip->reg->reset);
+ iowrite32(0x00, &chip->reg->reset);
+ pch_gpio_restore_reg_conf(chip);
+- spin_unlock_irqrestore(&chip->spinlock, flags);
++ raw_spin_unlock_irqrestore(&chip->spinlock, flags);
+
+ return 0;
+ }
+diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_acp.c b/drivers/gpu/drm/amd/amdgpu/amdgpu_acp.c
+index 6d72355ac4928f..31c3aaeb3bb41e 100644
+--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_acp.c
++++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_acp.c
+@@ -559,7 +559,9 @@ static int acp_hw_fini(void *handle)
+
+ mfd_remove_devices(adev->acp.parent);
+ kfree(adev->acp.acp_res);
++ pm_genpd_remove(&adev->acp.acp_genpd->gpd);
+ kfree(adev->acp.acp_genpd);
++ adev->acp.acp_genpd = NULL;
+ kfree(adev->acp.acp_cell);
+
+ return 0;
+diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_bios.c b/drivers/gpu/drm/amd/amdgpu/amdgpu_bios.c
+index e4ad2bd8d81106..d57fa0aee358b4 100644
+--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_bios.c
++++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_bios.c
+@@ -363,6 +363,45 @@ static bool amdgpu_read_disabled_bios(struct amdgpu_device *adev)
+ }
+
+ #ifdef CONFIG_ACPI
++/**
++ * amdgpu_acpi_vfct_match() - Check if a VFCT entry matches the device
++ * @adev: AMDGPU device
++ * @vhdr: VFCT image header to check
++ *
++ * VFCT entries contain the PCI bus number as recorded during BIOS POST.
++ * On systems where the kernel renumbers PCI buses (e.g. pci=realloc or
++ * resource conflicts), the runtime bus number may differ from the POST
++ * value. Match by device identity (vendor + device + function) and use
++ * the bus number as a preference: exact bus match is preferred, but when
++ * the bus numbers disagree we accept the entry if the device identity
++ * matches.
++ *
++ * Returns: 0 on match, -ENODEV on no match
++ */
++static int amdgpu_acpi_vfct_match(struct amdgpu_device *adev,
++ VFCT_IMAGE_HEADER *vhdr)
++{
++ /* Vendor and device IDs must always match */
++ if (vhdr->VendorID != adev->pdev->vendor ||
++ vhdr->DeviceID != adev->pdev->device)
++ return -ENODEV;
++
++ if (vhdr->PCIDevice != PCI_SLOT(adev->pdev->devfn) ||
++ vhdr->PCIFunction != PCI_FUNC(adev->pdev->devfn))
++ return -ENODEV;
++
++ /* Exact bus number match - preferred */
++ if (vhdr->PCIBus == adev->pdev->bus->number)
++ return 0;
++
++ /* Bus mismatch but device identity matches (PCI renumbering case) */
++ dev_notice(adev->dev,
++ "VFCT bus number mismatch: table %u != runtime %u, matching by device identity (vendor 0x%04x device 0x%04x)\n",
++ vhdr->PCIBus, adev->pdev->bus->number,
++ adev->pdev->vendor, adev->pdev->device);
++ return 0;
++}
++
+ static bool amdgpu_acpi_vfct_bios(struct amdgpu_device *adev)
+ {
+ struct acpi_table_header *hdr;
+@@ -398,11 +437,7 @@ static bool amdgpu_acpi_vfct_bios(struct amdgpu_device *adev)
+ }
+
+ if (vhdr->ImageLength &&
+- vhdr->PCIBus == adev->pdev->bus->number &&
+- vhdr->PCIDevice == PCI_SLOT(adev->pdev->devfn) &&
+- vhdr->PCIFunction == PCI_FUNC(adev->pdev->devfn) &&
+- vhdr->VendorID == adev->pdev->vendor &&
+- vhdr->DeviceID == adev->pdev->device) {
++ !amdgpu_acpi_vfct_match(adev, vhdr)) {
+ adev->bios = kmemdup(&vbios->VbiosContent,
+ vhdr->ImageLength,
+ GFP_KERNEL);
+diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_drv.c b/drivers/gpu/drm/amd/amdgpu/amdgpu_drv.c
+index 3c01bb46424844..fe485fa0a1418e 100644
+--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_drv.c
++++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_drv.c
+@@ -2637,6 +2637,19 @@ static int amdgpu_pmops_runtime_suspend(struct device *dev)
+ return 0;
+ }
+
++static void amdgpu_restore_umd_profile_pstate_after_runpm(struct amdgpu_device *adev)
++{
++ enum amd_dpm_forced_level level;
++ uint32_t profile_mode_mask = AMD_DPM_FORCED_LEVEL_PROFILE_STANDARD |
++ AMD_DPM_FORCED_LEVEL_PROFILE_MIN_SCLK |
++ AMD_DPM_FORCED_LEVEL_PROFILE_MIN_MCLK |
++ AMD_DPM_FORCED_LEVEL_PROFILE_PEAK;
++
++ level = amdgpu_dpm_get_performance_level(adev);
++ if (level & profile_mode_mask)
++ amdgpu_asic_update_umd_stable_pstate(adev, true);
++}
++
+ static int amdgpu_pmops_runtime_resume(struct device *dev)
+ {
+ struct pci_dev *pdev = to_pci_dev(dev);
+@@ -2680,6 +2693,8 @@ static int amdgpu_pmops_runtime_resume(struct device *dev)
+
+ if (amdgpu_device_supports_px(drm_dev))
+ drm_dev->switch_power_state = DRM_SWITCH_POWER_ON;
++
++ amdgpu_restore_umd_profile_pstate_after_runpm(adev);
+ adev->in_runpm = false;
+ return 0;
+ }
+diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_object.c b/drivers/gpu/drm/amd/amdgpu/amdgpu_object.c
+index 7acf1586882e1d..3e68830246a0c9 100644
+--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_object.c
++++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_object.c
+@@ -267,10 +267,12 @@ int amdgpu_bo_create_reserved(struct amdgpu_device *adev,
+ goto error_free;
+ }
+
+- r = amdgpu_bo_pin(*bo_ptr, domain);
+- if (r) {
+- dev_err(adev->dev, "(%d) kernel bo pin failed\n", r);
+- goto error_unreserve;
++ if (free) {
++ r = amdgpu_bo_pin(*bo_ptr, domain);
++ if (r) {
++ dev_err(adev->dev, "(%d) kernel bo pin failed\n", r);
++ goto error_unreserve;
++ }
+ }
+
+ r = amdgpu_ttm_alloc_gart(&(*bo_ptr)->tbo);
+@@ -293,7 +295,8 @@ int amdgpu_bo_create_reserved(struct amdgpu_device *adev,
+ return 0;
+
+ error_unpin:
+- amdgpu_bo_unpin(*bo_ptr);
++ if (free)
++ amdgpu_bo_unpin(*bo_ptr);
+ error_unreserve:
+ amdgpu_bo_unreserve(*bo_ptr);
+
+diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_ttm.c b/drivers/gpu/drm/amd/amdgpu/amdgpu_ttm.c
+index 4e50b308808646..2c8ee880cefa4a 100644
+--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_ttm.c
++++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_ttm.c
+@@ -463,6 +463,15 @@ static int amdgpu_bo_move(struct ttm_buffer_object *bo, bool evict,
+
+ if (new_mem->mem_type == TTM_PL_TT ||
+ new_mem->mem_type == AMDGPU_PL_PREEMPT) {
++ if (old_mem && (old_mem->mem_type == TTM_PL_TT ||
++ old_mem->mem_type == AMDGPU_PL_PREEMPT)) {
++ r = ttm_bo_wait_ctx(bo, ctx);
++ if (r)
++ return r;
++
++ amdgpu_ttm_backend_unbind(bo->bdev, bo->ttm);
++ }
++
+ r = amdgpu_ttm_backend_bind(bo->bdev, bo->ttm, new_mem);
+ if (r)
+ return r;
+@@ -501,6 +510,15 @@ static int amdgpu_bo_move(struct ttm_buffer_object *bo, bool evict,
+ ttm_bo_assign_mem(bo, new_mem);
+ return 0;
+ }
++ if ((old_mem->mem_type == TTM_PL_TT ||
++ old_mem->mem_type == AMDGPU_PL_PREEMPT) &&
++ (new_mem->mem_type == TTM_PL_TT ||
++ new_mem->mem_type == AMDGPU_PL_PREEMPT)) {
++ amdgpu_bo_move_notify(bo, evict, new_mem);
++ ttm_resource_free(bo, &bo->resource);
++ ttm_bo_assign_mem(bo, new_mem);
++ return 0;
++ }
+
+ if (old_mem->mem_type == AMDGPU_PL_GDS ||
+ old_mem->mem_type == AMDGPU_PL_GWS ||
+@@ -1844,6 +1862,18 @@ int amdgpu_ttm_init(struct amdgpu_device *adev)
+ gtt_size = (uint64_t)amdgpu_gtt_size << 20;
+ }
+
++ /* Cap GTT so that it does not exceed total physical RAM. */
++ if (adev->flags & AMD_IS_APU) {
++ u64 phys_ram = (u64)totalram_pages() << PAGE_SHIFT;
++
++ if (gtt_size > phys_ram) {
++ gtt_size = phys_ram;
++ dev_info(adev->dev,
++ "Capping GTT to %uM to not exceed available system memory\n",
++ (unsigned int)(gtt_size / (1024 * 1024)));
++ }
++ }
++
+ /* Initialize GTT memory pool */
+ r = amdgpu_gtt_mgr_init(adev, gtt_size);
+ if (r) {
+diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c b/drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c
+index 8baddf79635b52..638993b9376e0e 100644
+--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c
++++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c
+@@ -630,6 +630,14 @@ static int amdgpu_uvd_cs_msg_decode(struct amdgpu_device *adev, uint32_t *msg,
+ unsigned image_size, tmp, min_dpb_size, num_dpb_buffer;
+ unsigned min_ctx_size = ~0;
+
++ /* Reject invalid dimensions to prevent division by zero */
++ if (width < 16 || height < 16) {
++ dev_WARN_ONCE(adev->dev, 1,
++ "Invalid UVD decoding dimensions (%dx%d)!\n",
++ width, height);
++ return -EINVAL;
++ }
++
+ image_size = width * height;
+ image_size += image_size / 2;
+ image_size = ALIGN(image_size, 1024);
+diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_vce.c b/drivers/gpu/drm/amd/amdgpu/amdgpu_vce.c
+index 9df4214ccf23d3..4161be20d766ca 100644
+--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_vce.c
++++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_vce.c
+@@ -856,9 +856,20 @@ int amdgpu_vce_ring_parse_cs(struct amdgpu_cs_parser *p,
+ goto out;
+ }
+
+- *size = amdgpu_ib_get_value(ib, idx + 8) *
+- amdgpu_ib_get_value(ib, idx + 10) *
+- 8 * 3 / 2;
++ uint32_t width, height;
++ width = amdgpu_ib_get_value(ib, idx + 8);
++ height = amdgpu_ib_get_value(ib, idx + 10);
++
++ if (width == 0 || height == 0 ||
++ width > 4096 || height > 2304) {
++ DRM_ERROR("invalid VCE image size: %ux%u\n",
++ width, height);
++ r = -EINVAL;
++ goto out;
++ }
++
++ *size = width * height * 8 * 3 / 2;
++
+ break;
+
+ case 0x04000001: /* config extension */
+diff --git a/drivers/gpu/drm/amd/amdgpu/gfx_v10_0.c b/drivers/gpu/drm/amd/amdgpu/gfx_v10_0.c
+index 8953f093b96173..4f336e708258a2 100644
+--- a/drivers/gpu/drm/amd/amdgpu/gfx_v10_0.c
++++ b/drivers/gpu/drm/amd/amdgpu/gfx_v10_0.c
+@@ -3769,7 +3769,7 @@ static void gfx_v10_0_wait_reg_mem(struct amdgpu_ring *ring, int eng_sel,
+ WAIT_REG_MEM_ENGINE(eng_sel)));
+
+ if (mem_space)
+- BUG_ON(addr0 & 0x3); /* Dword align */
++ WARN_ON(addr0 & 0x3); /* Dword align */
+ amdgpu_ring_write(ring, addr0);
+ amdgpu_ring_write(ring, addr1);
+ amdgpu_ring_write(ring, ref);
+@@ -8513,7 +8513,7 @@ static void gfx_v10_0_ring_emit_ib_gfx(struct amdgpu_ring *ring,
+ control |= 0x400000;
+
+ amdgpu_ring_write(ring, header);
+- BUG_ON(ib->gpu_addr & 0x3); /* Dword align */
++ WARN_ON(ib->gpu_addr & 0x3); /* Dword align */
+ amdgpu_ring_write(ring,
+ #ifdef __BIG_ENDIAN
+ (2 << 0) |
+@@ -8552,7 +8552,7 @@ static void gfx_v10_0_ring_emit_ib_compute(struct amdgpu_ring *ring,
+ }
+
+ amdgpu_ring_write(ring, PACKET3(PACKET3_INDIRECT_BUFFER, 2));
+- BUG_ON(ib->gpu_addr & 0x3); /* Dword align */
++ WARN_ON(ib->gpu_addr & 0x3); /* Dword align */
+ amdgpu_ring_write(ring,
+ #ifdef __BIG_ENDIAN
+ (2 << 0) |
+@@ -8585,9 +8585,9 @@ static void gfx_v10_0_ring_emit_fence(struct amdgpu_ring *ring, u64 addr,
+ * aligned if only send 32bit data low (discard data high)
+ */
+ if (write64bit)
+- BUG_ON(addr & 0x7);
++ WARN_ON(addr & 0x7);
+ else
+- BUG_ON(addr & 0x3);
++ WARN_ON(addr & 0x3);
+ amdgpu_ring_write(ring, lower_32_bits(addr));
+ amdgpu_ring_write(ring, upper_32_bits(addr));
+ amdgpu_ring_write(ring, lower_32_bits(seq));
+@@ -8639,9 +8639,6 @@ static void gfx_v10_0_ring_emit_fence_kiq(struct amdgpu_ring *ring, u64 addr,
+ {
+ struct amdgpu_device *adev = ring->adev;
+
+- /* we only allocate 32bit for each seq wb address */
+- BUG_ON(flags & AMDGPU_FENCE_FLAG_64BIT);
+-
+ /* write fence seq to the "addr" */
+ amdgpu_ring_write(ring, PACKET3(PACKET3_WRITE_DATA, 3));
+ amdgpu_ring_write(ring, (WRITE_DATA_ENGINE_SEL(0) |
+diff --git a/drivers/gpu/drm/amd/amdgpu/gfx_v11_0.c b/drivers/gpu/drm/amd/amdgpu/gfx_v11_0.c
+index 6e3a32779168bb..b60f3b8a3ae5ed 100644
+--- a/drivers/gpu/drm/amd/amdgpu/gfx_v11_0.c
++++ b/drivers/gpu/drm/amd/amdgpu/gfx_v11_0.c
+@@ -309,7 +309,7 @@ static void gfx_v11_0_wait_reg_mem(struct amdgpu_ring *ring, int eng_sel,
+ WAIT_REG_MEM_ENGINE(eng_sel)));
+
+ if (mem_space)
+- BUG_ON(addr0 & 0x3); /* Dword align */
++ WARN_ON(addr0 & 0x3); /* Dword align */
+ amdgpu_ring_write(ring, addr0);
+ amdgpu_ring_write(ring, addr1);
+ amdgpu_ring_write(ring, ref);
+@@ -5400,7 +5400,7 @@ static void gfx_v11_0_ring_emit_ib_gfx(struct amdgpu_ring *ring,
+ control |= 0x400000;
+
+ amdgpu_ring_write(ring, header);
+- BUG_ON(ib->gpu_addr & 0x3); /* Dword align */
++ WARN_ON(ib->gpu_addr & 0x3); /* Dword align */
+ amdgpu_ring_write(ring,
+ #ifdef __BIG_ENDIAN
+ (2 << 0) |
+@@ -5439,7 +5439,7 @@ static void gfx_v11_0_ring_emit_ib_compute(struct amdgpu_ring *ring,
+ }
+
+ amdgpu_ring_write(ring, PACKET3(PACKET3_INDIRECT_BUFFER, 2));
+- BUG_ON(ib->gpu_addr & 0x3); /* Dword align */
++ WARN_ON(ib->gpu_addr & 0x3); /* Dword align */
+ amdgpu_ring_write(ring,
+ #ifdef __BIG_ENDIAN
+ (2 << 0) |
+@@ -5476,9 +5476,9 @@ static void gfx_v11_0_ring_emit_fence(struct amdgpu_ring *ring, u64 addr,
+ * aligned if only send 32bit data low (discard data high)
+ */
+ if (write64bit)
+- BUG_ON(addr & 0x7);
++ WARN_ON(addr & 0x7);
+ else
+- BUG_ON(addr & 0x3);
++ WARN_ON(addr & 0x3);
+ amdgpu_ring_write(ring, lower_32_bits(addr));
+ amdgpu_ring_write(ring, upper_32_bits(addr));
+ amdgpu_ring_write(ring, lower_32_bits(seq));
+@@ -5530,9 +5530,6 @@ static void gfx_v11_0_ring_emit_fence_kiq(struct amdgpu_ring *ring, u64 addr,
+ {
+ struct amdgpu_device *adev = ring->adev;
+
+- /* we only allocate 32bit for each seq wb address */
+- BUG_ON(flags & AMDGPU_FENCE_FLAG_64BIT);
+-
+ /* write fence seq to the "addr" */
+ amdgpu_ring_write(ring, PACKET3(PACKET3_WRITE_DATA, 3));
+ amdgpu_ring_write(ring, (WRITE_DATA_ENGINE_SEL(0) |
+diff --git a/drivers/gpu/drm/amd/amdgpu/gfx_v8_0.c b/drivers/gpu/drm/amd/amdgpu/gfx_v8_0.c
+index 71ef25425c7f60..bed870a42c44c9 100644
+--- a/drivers/gpu/drm/amd/amdgpu/gfx_v8_0.c
++++ b/drivers/gpu/drm/amd/amdgpu/gfx_v8_0.c
+@@ -6291,9 +6291,6 @@ static void gfx_v8_0_ring_emit_fence_compute(struct amdgpu_ring *ring,
+ static void gfx_v8_0_ring_emit_fence_kiq(struct amdgpu_ring *ring, u64 addr,
+ u64 seq, unsigned int flags)
+ {
+- /* we only allocate 32bit for each seq wb address */
+- BUG_ON(flags & AMDGPU_FENCE_FLAG_64BIT);
+-
+ /* write fence seq to the "addr" */
+ amdgpu_ring_write(ring, PACKET3(PACKET3_WRITE_DATA, 3));
+ amdgpu_ring_write(ring, (WRITE_DATA_ENGINE_SEL(0) |
+diff --git a/drivers/gpu/drm/amd/amdgpu/gfx_v9_0.c b/drivers/gpu/drm/amd/amdgpu/gfx_v9_0.c
+index e781d92d295cd6..4884a3c0739e1a 100644
+--- a/drivers/gpu/drm/amd/amdgpu/gfx_v9_0.c
++++ b/drivers/gpu/drm/amd/amdgpu/gfx_v9_0.c
+@@ -978,7 +978,7 @@ static void gfx_v9_0_wait_reg_mem(struct amdgpu_ring *ring, int eng_sel,
+ WAIT_REG_MEM_ENGINE(eng_sel)));
+
+ if (mem_space)
+- BUG_ON(addr0 & 0x3); /* Dword align */
++ WARN_ON(addr0 & 0x3); /* Dword align */
+ amdgpu_ring_write(ring, addr0);
+ amdgpu_ring_write(ring, addr1);
+ amdgpu_ring_write(ring, ref);
+@@ -5178,7 +5178,7 @@ static void gfx_v9_0_ring_emit_ib_gfx(struct amdgpu_ring *ring,
+ }
+
+ amdgpu_ring_write(ring, header);
+- BUG_ON(ib->gpu_addr & 0x3); /* Dword align */
++ WARN_ON(ib->gpu_addr & 0x3); /* Dword align */
+ amdgpu_ring_write(ring,
+ #ifdef __BIG_ENDIAN
+ (2 << 0) |
+@@ -5213,7 +5213,7 @@ static void gfx_v9_0_ring_emit_ib_compute(struct amdgpu_ring *ring,
+ }
+
+ amdgpu_ring_write(ring, PACKET3(PACKET3_INDIRECT_BUFFER, 2));
+- BUG_ON(ib->gpu_addr & 0x3); /* Dword align */
++ WARN_ON(ib->gpu_addr & 0x3); /* Dword align */
+ amdgpu_ring_write(ring,
+ #ifdef __BIG_ENDIAN
+ (2 << 0) |
+@@ -5247,9 +5247,9 @@ static void gfx_v9_0_ring_emit_fence(struct amdgpu_ring *ring, u64 addr,
+ * aligned if only send 32bit data low (discard data high)
+ */
+ if (write64bit)
+- BUG_ON(addr & 0x7);
++ WARN_ON(addr & 0x7);
+ else
+- BUG_ON(addr & 0x3);
++ WARN_ON(addr & 0x3);
+ amdgpu_ring_write(ring, lower_32_bits(addr));
+ amdgpu_ring_write(ring, upper_32_bits(addr));
+ amdgpu_ring_write(ring, lower_32_bits(seq));
+diff --git a/drivers/gpu/drm/amd/amdgpu/sdma_v5_0.c b/drivers/gpu/drm/amd/amdgpu/sdma_v5_0.c
+index d4d9f196db834e..6590f9e5127df9 100644
+--- a/drivers/gpu/drm/amd/amdgpu/sdma_v5_0.c
++++ b/drivers/gpu/drm/amd/amdgpu/sdma_v5_0.c
+@@ -548,7 +548,7 @@ static void sdma_v5_0_ring_emit_fence(struct amdgpu_ring *ring, u64 addr, u64 se
+ amdgpu_ring_write(ring, SDMA_PKT_HEADER_OP(SDMA_OP_FENCE) |
+ SDMA_PKT_FENCE_HEADER_MTYPE(0x3)); /* Ucached(UC) */
+ /* zero in first two bits */
+- BUG_ON(addr & 0x3);
++ WARN_ON(addr & 0x3);
+ amdgpu_ring_write(ring, lower_32_bits(addr));
+ amdgpu_ring_write(ring, upper_32_bits(addr));
+ amdgpu_ring_write(ring, lower_32_bits(seq));
+@@ -559,7 +559,7 @@ static void sdma_v5_0_ring_emit_fence(struct amdgpu_ring *ring, u64 addr, u64 se
+ amdgpu_ring_write(ring, SDMA_PKT_HEADER_OP(SDMA_OP_FENCE) |
+ SDMA_PKT_FENCE_HEADER_MTYPE(0x3));
+ /* zero in first two bits */
+- BUG_ON(addr & 0x3);
++ WARN_ON(addr & 0x3);
+ amdgpu_ring_write(ring, lower_32_bits(addr));
+ amdgpu_ring_write(ring, upper_32_bits(addr));
+ amdgpu_ring_write(ring, upper_32_bits(seq));
+diff --git a/drivers/gpu/drm/amd/amdgpu/sdma_v5_2.c b/drivers/gpu/drm/amd/amdgpu/sdma_v5_2.c
+index 38f57455bc747c..bc4738bfeb1a63 100644
+--- a/drivers/gpu/drm/amd/amdgpu/sdma_v5_2.c
++++ b/drivers/gpu/drm/amd/amdgpu/sdma_v5_2.c
+@@ -390,7 +390,7 @@ static void sdma_v5_2_ring_emit_fence(struct amdgpu_ring *ring, u64 addr, u64 se
+ amdgpu_ring_write(ring, SDMA_PKT_HEADER_OP(SDMA_OP_FENCE) |
+ SDMA_PKT_FENCE_HEADER_MTYPE(0x3)); /* Ucached(UC) */
+ /* zero in first two bits */
+- BUG_ON(addr & 0x3);
++ WARN_ON(addr & 0x3);
+ amdgpu_ring_write(ring, lower_32_bits(addr));
+ amdgpu_ring_write(ring, upper_32_bits(addr));
+ amdgpu_ring_write(ring, lower_32_bits(seq));
+@@ -401,7 +401,7 @@ static void sdma_v5_2_ring_emit_fence(struct amdgpu_ring *ring, u64 addr, u64 se
+ amdgpu_ring_write(ring, SDMA_PKT_HEADER_OP(SDMA_OP_FENCE) |
+ SDMA_PKT_FENCE_HEADER_MTYPE(0x3));
+ /* zero in first two bits */
+- BUG_ON(addr & 0x3);
++ WARN_ON(addr & 0x3);
+ amdgpu_ring_write(ring, lower_32_bits(addr));
+ amdgpu_ring_write(ring, upper_32_bits(addr));
+ amdgpu_ring_write(ring, upper_32_bits(seq));
+diff --git a/drivers/gpu/drm/amd/amdgpu/sdma_v6_0.c b/drivers/gpu/drm/amd/amdgpu/sdma_v6_0.c
+index da3beb0bf2fa2e..e036d7f14bc7cb 100644
+--- a/drivers/gpu/drm/amd/amdgpu/sdma_v6_0.c
++++ b/drivers/gpu/drm/amd/amdgpu/sdma_v6_0.c
+@@ -363,7 +363,7 @@ static void sdma_v6_0_ring_emit_fence(struct amdgpu_ring *ring, u64 addr, u64 se
+ amdgpu_ring_write(ring, SDMA_PKT_COPY_LINEAR_HEADER_OP(SDMA_OP_FENCE) |
+ SDMA_PKT_FENCE_HEADER_MTYPE(0x3)); /* Ucached(UC) */
+ /* zero in first two bits */
+- BUG_ON(addr & 0x3);
++ WARN_ON(addr & 0x3);
+ amdgpu_ring_write(ring, lower_32_bits(addr));
+ amdgpu_ring_write(ring, upper_32_bits(addr));
+ amdgpu_ring_write(ring, lower_32_bits(seq));
+@@ -374,7 +374,7 @@ static void sdma_v6_0_ring_emit_fence(struct amdgpu_ring *ring, u64 addr, u64 se
+ amdgpu_ring_write(ring, SDMA_PKT_COPY_LINEAR_HEADER_OP(SDMA_OP_FENCE) |
+ SDMA_PKT_FENCE_HEADER_MTYPE(0x3));
+ /* zero in first two bits */
+- BUG_ON(addr & 0x3);
++ WARN_ON(addr & 0x3);
+ amdgpu_ring_write(ring, lower_32_bits(addr));
+ amdgpu_ring_write(ring, upper_32_bits(addr));
+ amdgpu_ring_write(ring, upper_32_bits(seq));
+diff --git a/drivers/gpu/drm/amd/amdkfd/kfd_events.c b/drivers/gpu/drm/amd/amdkfd/kfd_events.c
+index 3f4cb39c852525..2d88b219470645 100644
+--- a/drivers/gpu/drm/amd/amdkfd/kfd_events.c
++++ b/drivers/gpu/drm/amd/amdkfd/kfd_events.c
+@@ -106,6 +106,9 @@ static int allocate_event_notification_slot(struct kfd_process *p,
+ }
+
+ if (restore_id) {
++ if (*restore_id >= KFD_SIGNAL_EVENT_LIMIT)
++ return -EINVAL;
++
+ id = idr_alloc(&p->event_idr, ev, *restore_id, *restore_id + 1,
+ GFP_KERNEL);
+ } else {
+@@ -516,6 +519,9 @@ int kfd_criu_restore_event(struct file *devkfd,
+
+ ret = create_other_event(p, ev, &ev_priv->event_id);
+ break;
++ default:
++ ret = -EINVAL;
++ break;
+ }
+ mutex_unlock(&p->event_mutex);
+
+@@ -537,15 +543,27 @@ int kfd_criu_checkpoint_events(struct kfd_process *p,
+ int ret = 0;
+ struct kfd_event *ev;
+ uint32_t ev_id;
++ uint32_t num_events;
+
+- uint32_t num_events = kfd_get_num_events(p);
++ /* Serialize the count and the walk below against concurrent event
++ * create/destroy. Those paths take only p->event_mutex, not the
++ * p->mutex held by the CRIU checkpoint caller, so without this the
++ * event_idr can grow between kfd_get_num_events() and the loop and the
++ * walk writes past the ev_privs allocation.
++ */
++ mutex_lock(&p->event_mutex);
+
+- if (!num_events)
++ num_events = kfd_get_num_events(p);
++ if (!num_events) {
++ mutex_unlock(&p->event_mutex);
+ return 0;
++ }
+
+ ev_privs = kvzalloc(num_events * sizeof(*ev_privs), GFP_KERNEL);
+- if (!ev_privs)
++ if (!ev_privs) {
++ mutex_unlock(&p->event_mutex);
+ return -ENOMEM;
++ }
+
+
+ idr_for_each_entry(&p->event_idr, ev, ev_id) {
+@@ -586,6 +604,8 @@ int kfd_criu_checkpoint_events(struct kfd_process *p,
+ i++;
+ }
+
++ mutex_unlock(&p->event_mutex);
++
+ ret = copy_to_user(user_priv_data + *priv_data_offset,
+ ev_privs, num_events * sizeof(*ev_privs));
+ if (ret) {
+diff --git a/drivers/gpu/drm/amd/display/modules/info_packet/info_packet.c b/drivers/gpu/drm/amd/display/modules/info_packet/info_packet.c
+index 6602ac882d6bce..69691058ab8981 100644
+--- a/drivers/gpu/drm/amd/display/modules/info_packet/info_packet.c
++++ b/drivers/gpu/drm/amd/display/modules/info_packet/info_packet.c
+@@ -445,8 +445,6 @@ void mod_build_vsc_infopacket(const struct dc_stream_state *stream,
+ *
+ * @stream: contains data we may need to construct VSIF (i.e. timing_3d_format, etc.)
+ * @info_packet: output structure where to store VSIF
+- * @ALLMEnabled: indicates whether ALLM HF-VSIF should be generated
+- * @ALLMValue: ALLM bit value to advertise in HF-VSIF
+ */
+ void mod_build_hf_vsif_infopacket(const struct dc_stream_state *stream,
+ struct dc_info_packet *info_packet)
+diff --git a/drivers/gpu/drm/amd/pm/amdgpu_pm.c b/drivers/gpu/drm/amd/pm/amdgpu_pm.c
+index cdb406690b7e7e..5c87d59a61f272 100644
+--- a/drivers/gpu/drm/amd/pm/amdgpu_pm.c
++++ b/drivers/gpu/drm/amd/pm/amdgpu_pm.c
+@@ -2004,6 +2004,11 @@ static int default_attr_update(struct amdgpu_device *adev, struct amdgpu_device_
+ } else if (DEVICE_ATTR_IS(pp_features)) {
+ if (adev->flags & AMD_IS_APU || gc_ver < IP_VERSION(9, 0, 0))
+ *states = ATTR_STATE_UNSUPPORTED;
++
++ if (adev->scpm_enabled) {
++ dev_attr->attr.mode &= ~S_IWUGO;
++ dev_attr->store = NULL;
++ }
+ } else if (DEVICE_ATTR_IS(gpu_metrics)) {
+ if (gc_ver < IP_VERSION(9, 1, 0))
+ *states = ATTR_STATE_UNSUPPORTED;
+diff --git a/drivers/gpu/drm/amd/pm/powerplay/hwmgr/hwmgr.c b/drivers/gpu/drm/amd/pm/powerplay/hwmgr/hwmgr.c
+index 997435a50f21ee..2e2bc4f28ee580 100644
+--- a/drivers/gpu/drm/amd/pm/powerplay/hwmgr/hwmgr.c
++++ b/drivers/gpu/drm/amd/pm/powerplay/hwmgr/hwmgr.c
+@@ -106,11 +106,8 @@ int hwmgr_early_init(struct pp_hwmgr *hwmgr)
+ hwmgr->od_enabled = false;
+ switch (hwmgr->chip_id) {
+ case CHIP_BONAIRE:
+- /* R9 M380 in iMac 2015: SMU hangs when enabling MCLK DPM
+- * R7 260X cards with old MC ucode: MCLK DPM is unstable
+- */
+- if (adev->pdev->subsystem_vendor == 0x106B ||
+- adev->pdev->device == 0x6658) {
++ /* R9 M380 in iMac 2015: SMU hangs when enabling MCLK DPM */
++ if (adev->pdev->subsystem_vendor == 0x106B) {
+ dev_info(adev->dev, "disabling MCLK DPM on quirky ASIC");
+ adev->pm.pp_feature &= ~PP_MCLK_DPM_MASK;
+ hwmgr->feature_mask &= ~PP_MCLK_DPM_MASK;
+diff --git a/drivers/gpu/drm/display/drm_dp_helper.c b/drivers/gpu/drm/display/drm_dp_helper.c
+index e839981c7b2f78..14dcaca0d8c14e 100644
+--- a/drivers/gpu/drm/display/drm_dp_helper.c
++++ b/drivers/gpu/drm/display/drm_dp_helper.c
+@@ -2930,6 +2930,18 @@ int drm_dp_get_pcon_max_frl_bw(const u8 dpcd[DP_RECEIVER_CAP_SIZE],
+ int bw;
+ u8 buf;
+
++ if (!drm_dp_is_branch(dpcd))
++ return 0;
++
++ if (dpcd[DP_DPCD_REV] < 0x11)
++ return 0;
++
++ if ((dpcd[DP_DOWNSTREAMPORT_PRESENT] & DP_DETAILED_CAP_INFO_AVAILABLE) == 0)
++ return 0;
++
++ if ((port_cap[0] & DP_DS_PORT_TYPE_MASK) != DP_DS_PORT_TYPE_HDMI)
++ return 0;
++
+ buf = port_cap[2];
+ bw = buf & DP_PCON_MAX_FRL_BW;
+
+diff --git a/drivers/gpu/drm/display/drm_dp_mst_topology.c b/drivers/gpu/drm/display/drm_dp_mst_topology.c
+index 65722f4b30ae84..f803d154c4cb55 100644
+--- a/drivers/gpu/drm/display/drm_dp_mst_topology.c
++++ b/drivers/gpu/drm/display/drm_dp_mst_topology.c
+@@ -779,6 +779,12 @@ static bool drm_dp_sideband_append_payload(struct drm_dp_sideband_msg_rx *msg,
+ {
+ u8 crc4;
+
++ /* curchunk_len must be >= 1 (min 1 CRC byte) and fit in chunk[] */
++ if (!msg->curchunk_len ||
++ msg->curchunk_len > ARRAY_SIZE(msg->chunk) ||
++ msg->curchunk_idx + replybuflen > ARRAY_SIZE(msg->chunk))
++ return false;
++
+ memcpy(&msg->chunk[msg->curchunk_idx], replybuf, replybuflen);
+ msg->curchunk_idx += replybuflen;
+
+@@ -789,6 +795,9 @@ static bool drm_dp_sideband_append_payload(struct drm_dp_sideband_msg_rx *msg,
+ print_hex_dump(KERN_DEBUG, "wrong crc",
+ DUMP_PREFIX_NONE, 16, 1,
+ msg->chunk, msg->curchunk_len, false);
++ /* Guard against accumulated msg[] overflow */
++ if (msg->curlen + msg->curchunk_len - 1 > ARRAY_SIZE(msg->msg))
++ return false;
+ /* copy chunk into bigger msg */
+ memcpy(&msg->msg[msg->curlen], msg->chunk, msg->curchunk_len - 1);
+ msg->curlen += msg->curchunk_len - 1;
+@@ -861,7 +870,7 @@ static bool drm_dp_sideband_parse_remote_dpcd_read(struct drm_dp_sideband_msg_rx
+ goto fail_len;
+ repmsg->u.remote_dpcd_read_ack.num_bytes = raw->msg[idx];
+ idx++;
+- if (idx > raw->curlen)
++ if (idx + repmsg->u.remote_dpcd_read_ack.num_bytes > raw->curlen)
+ goto fail_len;
+
+ memcpy(repmsg->u.remote_dpcd_read_ack.bytes, &raw->msg[idx], repmsg->u.remote_dpcd_read_ack.num_bytes);
+@@ -897,7 +906,9 @@ static bool drm_dp_sideband_parse_remote_i2c_read_ack(struct drm_dp_sideband_msg
+ goto fail_len;
+ repmsg->u.remote_i2c_read_ack.num_bytes = raw->msg[idx];
+ idx++;
+- /* TODO check */
++ if (idx + repmsg->u.remote_i2c_read_ack.num_bytes > raw->curlen)
++ goto fail_len;
++
+ memcpy(repmsg->u.remote_i2c_read_ack.bytes, &raw->msg[idx], repmsg->u.remote_i2c_read_ack.num_bytes);
+ return true;
+ fail_len:
+@@ -913,16 +924,13 @@ static bool drm_dp_sideband_parse_enum_path_resources_ack(struct drm_dp_sideband
+ repmsg->u.path_resources.port_number = (raw->msg[idx] >> 4) & 0xf;
+ repmsg->u.path_resources.fec_capable = raw->msg[idx] & 0x1;
+ idx++;
+- if (idx > raw->curlen)
++ if (idx + 2 > raw->curlen)
+ goto fail_len;
+ repmsg->u.path_resources.full_payload_bw_number = (raw->msg[idx] << 8) | (raw->msg[idx+1]);
+ idx += 2;
+- if (idx > raw->curlen)
++ if (idx + 2 > raw->curlen)
+ goto fail_len;
+ repmsg->u.path_resources.avail_payload_bw_number = (raw->msg[idx] << 8) | (raw->msg[idx+1]);
+- idx += 2;
+- if (idx > raw->curlen)
+- goto fail_len;
+ return true;
+ fail_len:
+ DRM_DEBUG_KMS("enum resource parse length fail %d %d\n", idx, raw->curlen);
+@@ -940,12 +948,9 @@ static bool drm_dp_sideband_parse_allocate_payload_ack(struct drm_dp_sideband_ms
+ goto fail_len;
+ repmsg->u.allocate_payload.vcpi = raw->msg[idx];
+ idx++;
+- if (idx > raw->curlen)
++ if (idx + 2 > raw->curlen)
+ goto fail_len;
+ repmsg->u.allocate_payload.allocated_pbn = (raw->msg[idx] << 8) | (raw->msg[idx+1]);
+- idx += 2;
+- if (idx > raw->curlen)
+- goto fail_len;
+ return true;
+ fail_len:
+ DRM_DEBUG_KMS("allocate payload parse length fail %d %d\n", idx, raw->curlen);
+@@ -959,12 +964,9 @@ static bool drm_dp_sideband_parse_query_payload_ack(struct drm_dp_sideband_msg_r
+
+ repmsg->u.query_payload.port_number = (raw->msg[idx] >> 4) & 0xf;
+ idx++;
+- if (idx > raw->curlen)
++ if (idx + 2 > raw->curlen)
+ goto fail_len;
+ repmsg->u.query_payload.allocated_pbn = (raw->msg[idx] << 8) | (raw->msg[idx + 1]);
+- idx += 2;
+- if (idx > raw->curlen)
+- goto fail_len;
+ return true;
+ fail_len:
+ DRM_DEBUG_KMS("query payload parse length fail %d %d\n", idx, raw->curlen);
+diff --git a/drivers/gpu/drm/i915/gem/i915_gem_context.c b/drivers/gpu/drm/i915/gem/i915_gem_context.c
+index 5e1b11db748162..1f71b5a659b035 100644
+--- a/drivers/gpu/drm/i915/gem/i915_gem_context.c
++++ b/drivers/gpu/drm/i915/gem/i915_gem_context.c
+@@ -610,6 +610,7 @@ set_proto_ctx_engines_parallel_submit(struct i915_user_extension __user *base,
+ return -EINVAL;
+ }
+
++ slot = array_index_nospec(slot, set->num_engines);
+ if (set->engines[slot].type != I915_GEM_ENGINE_TYPE_INVALID) {
+ drm_dbg(&i915->drm,
+ "Invalid placement[%d], already occupied\n", slot);
+@@ -767,8 +768,8 @@ static int set_proto_ctx_engines(struct drm_i915_file_private *fpriv,
+ struct intel_engine_cs *engine;
+
+ if (copy_from_user(&ci, &user->engines[n], sizeof(ci))) {
+- kfree(set.engines);
+- return -EFAULT;
++ err = -EFAULT;
++ goto err;
+ }
+
+ memset(&set.engines[n], 0, sizeof(set.engines[n]));
+@@ -784,8 +785,8 @@ static int set_proto_ctx_engines(struct drm_i915_file_private *fpriv,
+ drm_dbg(&i915->drm,
+ "Invalid engine[%d]: { class:%d, instance:%d }\n",
+ n, ci.engine_class, ci.engine_instance);
+- kfree(set.engines);
+- return -ENOENT;
++ err = -ENOENT;
++ goto err;
+ }
+
+ set.engines[n].type = I915_GEM_ENGINE_TYPE_PHYSICAL;
+@@ -798,15 +799,21 @@ static int set_proto_ctx_engines(struct drm_i915_file_private *fpriv,
+ set_proto_ctx_engines_extensions,
+ ARRAY_SIZE(set_proto_ctx_engines_extensions),
+ &set);
+- if (err) {
+- kfree(set.engines);
+- return err;
+- }
++ if (err)
++ goto err_extensions;
+
+ pc->num_user_engines = set.num_engines;
+ pc->user_engines = set.engines;
+
+ return 0;
++
++err_extensions:
++ for (n = 0; n < set.num_engines; n++)
++ kfree(set.engines[n].siblings);
++err:
++ kfree(set.engines);
++
++ return err;
+ }
+
+ static int set_proto_ctx_sseu(struct drm_i915_file_private *fpriv,
+@@ -848,7 +855,7 @@ static int set_proto_ctx_sseu(struct drm_i915_file_private *fpriv,
+ pe = &pc->user_engines[idx];
+
+ /* Only render engine supports RPCS configuration. */
+- if (pe->engine->class != RENDER_CLASS)
++ if (!pe->engine || pe->engine->class != RENDER_CLASS)
+ return -EINVAL;
+
+ sseu = &pe->sseu;
+diff --git a/drivers/gpu/drm/i915/gt/intel_engine_user.c b/drivers/gpu/drm/i915/gt/intel_engine_user.c
+index 46a174f8aa0076..9a4309c30f0ea8 100644
+--- a/drivers/gpu/drm/i915/gt/intel_engine_user.c
++++ b/drivers/gpu/drm/i915/gt/intel_engine_user.c
+@@ -239,7 +239,7 @@ void intel_engines_driver_register(struct drm_i915_private *i915)
+ p = &prev->rb_right;
+ }
+
+- if (IS_ENABLED(CONFIG_DRM_I915_SELFTESTS) &&
++ if (IS_ENABLED(CONFIG_DRM_I915_SELFTEST) &&
+ IS_ENABLED(CONFIG_DRM_I915_DEBUG_GEM)) {
+ struct intel_engine_cs *engine;
+ unsigned int isolation;
+diff --git a/drivers/gpu/drm/i915/gt/selftest_gt_pm.c b/drivers/gpu/drm/i915/gt/selftest_gt_pm.c
+index be94f863bdefff..0e237bcf324a83 100644
+--- a/drivers/gpu/drm/i915/gt/selftest_gt_pm.c
++++ b/drivers/gpu/drm/i915/gt/selftest_gt_pm.c
+@@ -16,9 +16,9 @@ static int cmp_u64(const void *A, const void *B)
+ {
+ const u64 *a = A, *b = B;
+
+- if (a < b)
++ if (*a < *b)
+ return -1;
+- else if (a > b)
++ else if (*a > *b)
+ return 1;
+ else
+ return 0;
+@@ -28,9 +28,9 @@ static int cmp_u32(const void *A, const void *B)
+ {
+ const u32 *a = A, *b = B;
+
+- if (a < b)
++ if (*a < *b)
+ return -1;
+- else if (a > b)
++ else if (*a > *b)
+ return 1;
+ else
+ return 0;
+diff --git a/drivers/gpu/drm/i915/i915_active.c b/drivers/gpu/drm/i915/i915_active.c
+index 5ec293011d9902..40f84d547274a4 100644
+--- a/drivers/gpu/drm/i915/i915_active.c
++++ b/drivers/gpu/drm/i915/i915_active.c
+@@ -319,7 +319,7 @@ active_instance(struct i915_active *ref, u64 idx)
+ */
+ node = kmem_cache_alloc(slab_cache, GFP_ATOMIC);
+ if (!node)
+- goto out;
++ goto err;
+
+ __i915_active_fence_init(&node->base, NULL, node_retire);
+ node->ref = ref;
+@@ -333,6 +333,11 @@ out:
+ spin_unlock_irq(&ref->tree_lock);
+
+ return &node->base;
++
++err:
++ spin_unlock_irq(&ref->tree_lock);
++
++ return NULL;
+ }
+
+ void __i915_active_init(struct i915_active *ref,
+diff --git a/drivers/gpu/drm/mediatek/mtk_drm_crtc.c b/drivers/gpu/drm/mediatek/mtk_drm_crtc.c
+index aba26ec9a1425c..59b310f7327c86 100644
+--- a/drivers/gpu/drm/mediatek/mtk_drm_crtc.c
++++ b/drivers/gpu/drm/mediatek/mtk_drm_crtc.c
+@@ -183,10 +183,10 @@ static void mtk_drm_crtc_reset(struct drm_crtc *crtc)
+ {
+ struct mtk_crtc_state *state;
+
+- if (crtc->state)
++ if (crtc->state) {
+ __drm_atomic_helper_crtc_destroy_state(crtc->state);
+-
+- kfree(to_mtk_crtc_state(crtc->state));
++ kfree(to_mtk_crtc_state(crtc->state));
++ }
+ crtc->state = NULL;
+
+ state = kzalloc(sizeof(*state), GFP_KERNEL);
+diff --git a/drivers/gpu/drm/nouveau/nvkm/subdev/acr/base.c b/drivers/gpu/drm/nouveau/nvkm/subdev/acr/base.c
+index af6cac696d434c..78869b15916450 100644
+--- a/drivers/gpu/drm/nouveau/nvkm/subdev/acr/base.c
++++ b/drivers/gpu/drm/nouveau/nvkm/subdev/acr/base.c
+@@ -314,6 +314,7 @@ nvkm_acr_oneinit(struct nvkm_subdev *subdev)
+ i, us, fw);
+ }
+ }
++ nvkm_done(acr->wpr);
+ return -EINVAL;
+ }
+ nvkm_done(acr->wpr);
+diff --git a/drivers/gpu/drm/radeon/r100.c b/drivers/gpu/drm/radeon/r100.c
+index 42605e2765f8fe..88af6d2264a23b 100644
+--- a/drivers/gpu/drm/radeon/r100.c
++++ b/drivers/gpu/drm/radeon/r100.c
+@@ -905,6 +905,7 @@ struct radeon_fence *r100_copy_blit(struct radeon_device *rdev,
+ {
+ struct radeon_ring *ring = &rdev->ring[RADEON_RING_TYPE_GFX_INDEX];
+ struct radeon_fence *fence;
++ uint64_t cur_src_offset, cur_dst_offset;
+ uint32_t cur_pages;
+ uint32_t stride_bytes = RADEON_GPU_PAGE_SIZE;
+ uint32_t pitch;
+@@ -933,6 +934,10 @@ struct radeon_fence *r100_copy_blit(struct radeon_device *rdev,
+ cur_pages = 8191;
+ }
+ num_gpu_pages -= cur_pages;
++ cur_src_offset = src_offset +
++ (uint64_t)num_gpu_pages * RADEON_GPU_PAGE_SIZE;
++ cur_dst_offset = dst_offset +
++ (uint64_t)num_gpu_pages * RADEON_GPU_PAGE_SIZE;
+
+ /* pages are in Y direction - height
+ page width in X direction - width */
+@@ -949,13 +954,13 @@ struct radeon_fence *r100_copy_blit(struct radeon_device *rdev,
+ RADEON_DP_SRC_SOURCE_MEMORY |
+ RADEON_GMC_CLR_CMP_CNTL_DIS |
+ RADEON_GMC_WR_MSK_DIS);
+- radeon_ring_write(ring, (pitch << 22) | (src_offset >> 10));
+- radeon_ring_write(ring, (pitch << 22) | (dst_offset >> 10));
++ radeon_ring_write(ring, (pitch << 22) | (cur_src_offset >> 10));
++ radeon_ring_write(ring, (pitch << 22) | (cur_dst_offset >> 10));
+ radeon_ring_write(ring, (0x1fff) | (0x1fff << 16));
+ radeon_ring_write(ring, 0);
+ radeon_ring_write(ring, (0x1fff) | (0x1fff << 16));
+- radeon_ring_write(ring, num_gpu_pages);
+- radeon_ring_write(ring, num_gpu_pages);
++ radeon_ring_write(ring, 0);
++ radeon_ring_write(ring, 0);
+ radeon_ring_write(ring, cur_pages | (stride_pixels << 16));
+ }
+ radeon_ring_write(ring, PACKET0(RADEON_DSTCACHE_CTLSTAT, 0));
+diff --git a/drivers/gpu/drm/rockchip/cdn-dp-reg.c b/drivers/gpu/drm/rockchip/cdn-dp-reg.c
+index 33fb4d05c50657..7b16c28ba25a63 100644
+--- a/drivers/gpu/drm/rockchip/cdn-dp-reg.c
++++ b/drivers/gpu/drm/rockchip/cdn-dp-reg.c
+@@ -683,6 +683,8 @@ int cdn_dp_config_video(struct cdn_dp_device *dp)
+ val = div_u64(8 * (symbol + 1), bit_per_pix) - val;
+ val += 2;
+ ret = cdn_dp_reg_write(dp, DP_VC_TABLE(15), val);
++ if (ret)
++ goto err_config_video;
+
+ switch (video->color_depth) {
+ case 6:
+diff --git a/drivers/gpu/drm/vc4/vc4_irq.c b/drivers/gpu/drm/vc4/vc4_irq.c
+index 1e6db0121ccd5f..e1e50198d96981 100644
+--- a/drivers/gpu/drm/vc4/vc4_irq.c
++++ b/drivers/gpu/drm/vc4/vc4_irq.c
+@@ -106,7 +106,7 @@ vc4_overflow_mem_work(struct work_struct *work)
+ vc4->bin_alloc_overflow = BIT(bin_bo_slot);
+
+ V3D_WRITE(V3D_BPOA, bo->base.dma_addr + bin_bo_slot * vc4->bin_alloc_size);
+- V3D_WRITE(V3D_BPOS, bo->base.base.size);
++ V3D_WRITE(V3D_BPOS, vc4->bin_alloc_size);
+ V3D_WRITE(V3D_INTCTL, V3D_INT_OUTOMEM);
+ V3D_WRITE(V3D_INTENA, V3D_INT_OUTOMEM);
+ spin_unlock_irqrestore(&vc4->job_lock, irqflags);
+diff --git a/drivers/gpu/drm/vc4/vc4_validate.c b/drivers/gpu/drm/vc4/vc4_validate.c
+index 520231af4df9c4..2a2d576b0f52f2 100644
+--- a/drivers/gpu/drm/vc4/vc4_validate.c
++++ b/drivers/gpu/drm/vc4/vc4_validate.c
+@@ -387,6 +387,23 @@ validate_tile_binning_config(VALIDATE_ARGS)
+ return -EINVAL;
+ }
+
++ /* The tile state data array is 48 bytes per tile, and we put it at
++ * the start of a BO containing both it and the tile alloc.
++ */
++ tile_state_size = 48 * tile_count;
++
++ /* Since the tile alloc array will follow us, align. */
++ tile_state_size = roundup(tile_state_size, 4096);
++
++ /* Reject configurations whose tile state would leave no room for
++ * the tile alloc pool that follows it in the slot.
++ */
++ if (tile_state_size >= vc4->bin_alloc_size) {
++ DRM_DEBUG("Tile binning config of %dx%d too large\n",
++ exec->bin_tiles_x, exec->bin_tiles_y);
++ return -EINVAL;
++ }
++
+ bin_slot = vc4_v3d_get_bin_slot(vc4);
+ if (bin_slot < 0) {
+ if (bin_slot != -EINTR && bin_slot != -ERESTARTSYS) {
+@@ -402,13 +419,13 @@ validate_tile_binning_config(VALIDATE_ARGS)
+ exec->bin_slots |= BIT(bin_slot);
+ bin_addr = vc4->bin_bo->base.dma_addr + bin_slot * vc4->bin_alloc_size;
+
+- /* The tile state data array is 48 bytes per tile, and we put it at
+- * the start of a BO containing both it and the tile alloc.
+- */
+- tile_state_size = 48 * tile_count;
++ exec->tile_alloc_offset = bin_addr + tile_state_size;
+
+- /* Since the tile alloc array will follow us, align. */
+- exec->tile_alloc_offset = bin_addr + roundup(tile_state_size, 4096);
++ /* The TSDA area must be zeroed out before use, otherwise the PTB might
++ * consume a stale tile state.
++ */
++ memset(vc4->bin_bo->base.vaddr + bin_slot * vc4->bin_alloc_size, 0,
++ tile_state_size);
+
+ *(uint8_t *)(validated + 14) =
+ ((flags & ~(VC4_BIN_CONFIG_ALLOC_INIT_BLOCK_SIZE_MASK |
+diff --git a/drivers/gpu/drm/virtio/virtgpu_vq.c b/drivers/gpu/drm/virtio/virtgpu_vq.c
+index 208e9434cb28d1..01a231d21119d1 100644
+--- a/drivers/gpu/drm/virtio/virtgpu_vq.c
++++ b/drivers/gpu/drm/virtio/virtgpu_vq.c
+@@ -719,7 +719,8 @@ static int virtio_get_edid_block(void *data, u8 *buf,
+ struct virtio_gpu_resp_edid *resp = data;
+ size_t start = block * EDID_LENGTH;
+
+- if (start + len > le32_to_cpu(resp->size))
++ if (start + len > le32_to_cpu(resp->size) ||
++ start + len > sizeof(resp->edid))
+ return -EINVAL;
+ memcpy(buf, resp->edid + start, len);
+ return 0;
+diff --git a/drivers/gpu/drm/vmwgfx/ttm_object.c b/drivers/gpu/drm/vmwgfx/ttm_object.c
+index ddf8373c1d779c..f6b59f7db461e1 100644
+--- a/drivers/gpu/drm/vmwgfx/ttm_object.c
++++ b/drivers/gpu/drm/vmwgfx/ttm_object.c
+@@ -551,14 +551,17 @@ int ttm_prime_fd_to_handle(struct ttm_object_file *tfile,
+ if (IS_ERR(dma_buf))
+ return PTR_ERR(dma_buf);
+
+- if (dma_buf->ops != &tdev->ops)
+- return -ENOSYS;
++ if (dma_buf->ops != &tdev->ops) {
++ ret = -ENOSYS;
++ goto out;
++ }
+
+ prime = (struct ttm_prime_object *) dma_buf->priv;
+ base = &prime->base;
+ *handle = base->handle;
+ ret = ttm_ref_object_add(tfile, base, NULL, false);
+
++out:
+ dma_buf_put(dma_buf);
+
+ return ret;
+diff --git a/drivers/gpu/drm/vmwgfx/vmwgfx_execbuf.c b/drivers/gpu/drm/vmwgfx/vmwgfx_execbuf.c
+index 34b9161ec7e818..ef2ee93f5e3434 100644
+--- a/drivers/gpu/drm/vmwgfx/vmwgfx_execbuf.c
++++ b/drivers/gpu/drm/vmwgfx/vmwgfx_execbuf.c
+@@ -1516,6 +1516,12 @@ static int vmw_cmd_dma(struct vmw_private *dev_priv,
+ bool dirty;
+
+ cmd = container_of(header, typeof(*cmd), header);
++
++ if (unlikely(header->size < sizeof(cmd->body) + sizeof(*suffix))) {
++ VMW_DEBUG_USER("Illegal SVGA_3D_CMD_SURFACE_DMA size.\n");
++ return -EINVAL;
++ }
++
+ suffix = (SVGA3dCmdSurfaceDMASuffix *)((unsigned long) &cmd->body +
+ header->size - sizeof(*suffix));
+
+@@ -1577,11 +1583,17 @@ static int vmw_cmd_draw(struct vmw_private *dev_priv,
+ uint32_t maxnum;
+ int ret;
+
++ cmd = container_of(header, typeof(*cmd), header);
++
++ if (unlikely(header->size < sizeof(cmd->body))) {
++ VMW_DEBUG_USER("Illegal DRAW_PRIMITIVES header size.\n");
++ return -EINVAL;
++ }
++
+ ret = vmw_cmd_cid_check(dev_priv, sw_context, header);
+ if (unlikely(ret != 0))
+ return ret;
+
+- cmd = container_of(header, typeof(*cmd), header);
+ maxnum = (header->size - sizeof(cmd->body)) / sizeof(*decl);
+
+ if (unlikely(cmd->body.numVertexDecls > maxnum)) {
+diff --git a/drivers/gpu/drm/vmwgfx/vmwgfx_surface.c b/drivers/gpu/drm/vmwgfx/vmwgfx_surface.c
+index 50769528c3f3c6..13e81ddb983129 100644
+--- a/drivers/gpu/drm/vmwgfx/vmwgfx_surface.c
++++ b/drivers/gpu/drm/vmwgfx/vmwgfx_surface.c
+@@ -98,7 +98,7 @@ static int vmw_gb_surface_unbind(struct vmw_resource *res,
+ static int vmw_gb_surface_destroy(struct vmw_resource *res);
+ static int
+ vmw_gb_surface_define_internal(struct drm_device *dev,
+- struct drm_vmw_gb_surface_create_ext_req *req,
++ const struct drm_vmw_gb_surface_create_ext_req *req,
+ struct drm_vmw_gb_surface_create_rep *rep,
+ struct drm_file *file_priv);
+ static int
+@@ -1406,7 +1406,7 @@ int vmw_gb_surface_reference_ext_ioctl(struct drm_device *dev, void *data,
+ */
+ static int
+ vmw_gb_surface_define_internal(struct drm_device *dev,
+- struct drm_vmw_gb_surface_create_ext_req *req,
++ const struct drm_vmw_gb_surface_create_ext_req *req,
+ struct drm_vmw_gb_surface_create_rep *rep,
+ struct drm_file *file_priv)
+ {
+@@ -1424,9 +1424,21 @@ vmw_gb_surface_define_internal(struct drm_device *dev,
+ req->base.svga3d_flags);
+
+ /* array_size must be null for non-GL3 host. */
+- if (req->base.array_size > 0 && !has_sm4_context(dev_priv)) {
+- VMW_DEBUG_USER("SM4 surface not supported.\n");
+- return -EINVAL;
++ if (req->base.array_size > 0) {
++ if (has_sm5_context(dev_priv)) {
++ if (req->base.array_size > SVGA3D_SM5_MAX_SURFACE_ARRAYSIZE) {
++ VMW_DEBUG_USER("Invalid Surface Array Size.\n");
++ return -EINVAL;
++ }
++ } else if (has_sm4_context(dev_priv)) {
++ if (req->base.array_size > SVGA3D_SM4_MAX_SURFACE_ARRAYSIZE) {
++ VMW_DEBUG_USER("Invalid Surface Array Size.\n");
++ return -EINVAL;
++ }
++ } else {
++ VMW_DEBUG_USER("SM4+ surface not supported.\n");
++ return -EINVAL;
++ }
+ }
+
+ if (!has_sm4_1_context(dev_priv)) {
+diff --git a/drivers/gpu/host1x/bus.c b/drivers/gpu/host1x/bus.c
+index 819f0c4fdfa899..8c819af1bce697 100644
+--- a/drivers/gpu/host1x/bus.c
++++ b/drivers/gpu/host1x/bus.c
+@@ -1025,10 +1025,10 @@ void host1x_bo_clear_cached_mappings(struct host1x_bo *bo)
+ if (WARN_ON(!cache))
+ continue;
+
+- mutex_lock(&mapping->cache->lock);
++ mutex_lock(&cache->lock);
+ WARN_ON(kref_read(&mapping->ref) != 1);
+ __host1x_bo_unpin(&mapping->ref);
+- mutex_unlock(&mapping->cache->lock);
++ mutex_unlock(&cache->lock);
+ }
+ }
+ EXPORT_SYMBOL(host1x_bo_clear_cached_mappings);
+diff --git a/drivers/hid/hid-logitech-dj.c b/drivers/hid/hid-logitech-dj.c
+index be9fbf14f13711..015974b4f5eee8 100644
+--- a/drivers/hid/hid-logitech-dj.c
++++ b/drivers/hid/hid-logitech-dj.c
+@@ -1749,7 +1749,8 @@ static int logi_dj_raw_event(struct hid_device *hdev,
+ static int logi_dj_probe(struct hid_device *hdev,
+ const struct hid_device_id *id)
+ {
+- struct hid_report_enum *rep_enum;
++ struct hid_report_enum *input_report_enum;
++ struct hid_report_enum *output_report_enum;
+ struct hid_report *rep;
+ struct dj_receiver_dev *djrcv_dev;
+ struct usb_interface *intf;
+@@ -1793,10 +1794,25 @@ static int logi_dj_probe(struct hid_device *hdev,
+ }
+ }
+
+- rep_enum = &hdev->report_enum[HID_INPUT_REPORT];
++ output_report_enum = &hdev->report_enum[HID_OUTPUT_REPORT];
++ rep = output_report_enum->report_id_hash[REPORT_ID_DJ_SHORT];
++
++ if (rep && rep->maxfield < 1) {
++ hid_err(hdev, "Expected size of DJ short report is %d, but got 0",
++ DJREPORT_SHORT_LENGTH - 1);
++ return -EINVAL;
++ }
++
++ if (rep && rep->field[0]->report_count != DJREPORT_SHORT_LENGTH - 1) {
++ hid_err(hdev, "Expected size of DJ short report is %d, but got %d",
++ DJREPORT_SHORT_LENGTH - 1, rep->field[0]->report_count);
++ return -EINVAL;
++ }
++
++ input_report_enum = &hdev->report_enum[HID_INPUT_REPORT];
+
+ /* no input reports, bail out */
+- if (list_empty(&rep_enum->report_list))
++ if (list_empty(&input_report_enum->report_list))
+ return -ENODEV;
+
+ /*
+@@ -1804,7 +1820,7 @@ static int logi_dj_probe(struct hid_device *hdev,
+ * Note: we should theoretically check for HID++ and DJ
+ * collections, but this will do.
+ */
+- list_for_each_entry(rep, &rep_enum->report_list, list) {
++ list_for_each_entry(rep, &input_report_enum->report_list, list) {
+ if (rep->application == 0xff000001)
+ has_hidpp = true;
+ }
+@@ -1817,7 +1833,7 @@ static int logi_dj_probe(struct hid_device *hdev,
+ return -ENODEV;
+
+ /* get the current application attached to the node */
+- rep = list_first_entry(&rep_enum->report_list, struct hid_report, list);
++ rep = list_first_entry(&input_report_enum->report_list, struct hid_report, list);
+ djrcv_dev = dj_get_receiver_dev(hdev, id->driver_data,
+ rep->application, has_hidpp);
+ if (!djrcv_dev) {
+@@ -1825,7 +1841,7 @@ static int logi_dj_probe(struct hid_device *hdev,
+ return -ENOMEM;
+ }
+
+- if (!rep_enum->numbered)
++ if (!input_report_enum->numbered)
+ djrcv_dev->unnumbered_application = rep->application;
+
+ /* Starts the usb device and connects to upper interfaces hiddev and
+diff --git a/drivers/hwmon/ads7828.c b/drivers/hwmon/ads7828.c
+index 7246198f09013a..efd60b52e29b95 100644
+--- a/drivers/hwmon/ads7828.c
++++ b/drivers/hwmon/ads7828.c
+@@ -108,12 +108,11 @@ static int ads7828_probe(struct i2c_client *client)
+ struct ads7828_data *data;
+ struct device *hwmon_dev;
+ unsigned int vref_mv = ADS7828_INT_VREF_MV;
+- unsigned int vref_uv;
++ int vref_uv;
+ bool diff_input = false;
+ bool ext_vref = false;
+ unsigned int regval;
+ enum ads7828_chips chip;
+- struct regulator *reg;
+
+ data = devm_kzalloc(dev, sizeof(struct ads7828_data), GFP_KERNEL);
+ if (!data)
+@@ -127,9 +126,11 @@ static int ads7828_probe(struct i2c_client *client)
+ } else if (dev->of_node) {
+ diff_input = of_property_read_bool(dev->of_node,
+ "ti,differential-input");
+- reg = devm_regulator_get_optional(dev, "vref");
+- if (!IS_ERR(reg)) {
+- vref_uv = regulator_get_voltage(reg);
++ vref_uv = devm_regulator_get_enable_read_voltage(dev, "vref");
++ if (vref_uv < 0) {
++ if (vref_uv != -ENODEV)
++ return vref_uv;
++ } else {
+ vref_mv = DIV_ROUND_CLOSEST(vref_uv, 1000);
+ if (vref_mv < ADS7828_EXT_VREF_MV_MIN ||
+ vref_mv > ADS7828_EXT_VREF_MV_MAX)
+diff --git a/drivers/hwmon/adt7470.c b/drivers/hwmon/adt7470.c
+index 927f8df05b7c93..9783593a1de76f 100644
+--- a/drivers/hwmon/adt7470.c
++++ b/drivers/hwmon/adt7470.c
+@@ -70,8 +70,8 @@ static const unsigned short normal_i2c[] = { 0x2C, 0x2E, 0x2F, I2C_CLIENT_END };
+ #define ADT7470_PWM1_AUTO_MASK 0x80
+ #define ADT7470_PWM_AUTO_MASK 0xC0
+ #define ADT7470_REG_PWM34_CFG 0x69
+-#define ADT7470_PWM3_AUTO_MASK 0x40
+-#define ADT7470_PWM4_AUTO_MASK 0x80
++#define ADT7470_PWM4_AUTO_MASK 0x40
++#define ADT7470_PWM3_AUTO_MASK 0x80
+ #define ADT7470_REG_PWM_MIN_BASE_ADDR 0x6A
+ #define ADT7470_REG_PWM_MIN_MAX_ADDR 0x6D
+ #define ADT7470_REG_PWM_TEMP_MIN_BASE_ADDR 0x6E
+@@ -110,6 +110,21 @@ static const unsigned short normal_i2c[] = { 0x2C, 0x2E, 0x2F, I2C_CLIENT_END };
+
+ #define ALARM2(x) ((x) << 8)
+
++/* TEMP1..TEMP7 (ch 0..6) are, respectively BIT(0)..BIT(6) of reg 0x41 and
++ * 0x72, or BIT(0)..BIT(6) of data->alarm.
++ * TEMP8..TEMP9 (ch 7..9) are, respectively BIT(0)..BIT(2) of reg 0x42 and
++ * 0x73, or BIT(8)..BIT(10) of data->alarm.
++ */
++#define TEMP_ALARM_BIT(ch) ({ \
++ typeof(ch) _ch = (ch); \
++ (1 << (_ch < 7 ? _ch : _ch + 1)); \
++})
++
++/* FAN1..FAN4 (ch 0..3) are respectively BIT(4)..BIT(7) in
++ * reg 0x42 and 0x73 or BIT(12)..BIT(15) in data->alarm.
++ */
++#define FAN_ALARM_BIT(ch) (1 << (12 + (ch)))
++
+ #define ADT7470_VENDOR 0x41
+ #define ADT7470_DEVICE 0x70
+ /* datasheet only mentions a revision 2 */
+@@ -167,6 +182,7 @@ struct adt7470_data {
+ u8 pwm_min[ADT7470_PWM_COUNT];
+ s8 pwm_tmin[ADT7470_PWM_COUNT];
+ u8 pwm_auto_temp[ADT7470_PWM_COUNT];
++ u32 pwm_freq;
+
+ struct task_struct *auto_update;
+ unsigned int auto_update_interval;
+@@ -205,11 +221,12 @@ static inline int adt7470_write_word_data(struct adt7470_data *data, unsigned in
+ /* Probe for temperature sensors. Assumes lock is held */
+ static int adt7470_read_temperatures(struct adt7470_data *data)
+ {
+- unsigned long res;
++ struct device *dev = regmap_get_device(data->regmap);
++ u8 pwm[ADT7470_FAN_COUNT];
+ unsigned int pwm_cfg[2];
+- int err;
++ unsigned long res;
++ int err, err2;
+ int i;
+- u8 pwm[ADT7470_FAN_COUNT];
+
+ /* save pwm[1-4] config register */
+ err = regmap_read(data->regmap, ADT7470_REG_PWM_CFG(0), &pwm_cfg[0]);
+@@ -233,19 +250,19 @@ static int adt7470_read_temperatures(struct adt7470_data *data)
+ err = regmap_update_bits(data->regmap, ADT7470_REG_PWM_CFG(2),
+ ADT7470_PWM_AUTO_MASK, 0);
+ if (err < 0)
+- return err;
++ goto out_restore;
+
+ /* write pwm control to whatever it was */
+ err = regmap_bulk_write(data->regmap, ADT7470_REG_PWM(0), &pwm[0],
+ ADT7470_PWM_COUNT);
+ if (err < 0)
+- return err;
++ goto out_restore;
+
+ /* start reading temperature sensors */
+ err = regmap_update_bits(data->regmap, ADT7470_REG_CFG,
+ ADT7470_T05_STB_MASK, ADT7470_T05_STB_MASK);
+ if (err < 0)
+- return err;
++ goto out_restore;
+
+ /* Delay is 200ms * number of temp sensors. */
+ res = msleep_interruptible((data->num_temp_sensors >= 0 ?
+@@ -256,13 +273,30 @@ static int adt7470_read_temperatures(struct adt7470_data *data)
+ err = regmap_update_bits(data->regmap, ADT7470_REG_CFG,
+ ADT7470_T05_STB_MASK, 0);
+ if (err < 0)
+- return err;
++ goto out_restore;
+
++out_restore:
+ /* restore pwm[1-4] config registers */
+- err = regmap_write(data->regmap, ADT7470_REG_PWM_CFG(0), pwm_cfg[0]);
+- if (err < 0)
+- return err;
+- err = regmap_write(data->regmap, ADT7470_REG_PWM_CFG(2), pwm_cfg[1]);
++ err2 = regmap_write(data->regmap, ADT7470_REG_PWM_CFG(0), pwm_cfg[0]);
++ if (err2 < 0) {
++ dev_warn_ratelimited(dev,
++ "failed to restore PWM{1,2} config (%d)\n",
++ err2);
++
++ if (!err)
++ err = err2;
++ }
++
++ err2 = regmap_write(data->regmap, ADT7470_REG_PWM_CFG(2), pwm_cfg[1]);
++ if (err2 < 0) {
++ dev_warn_ratelimited(dev,
++ "failed to restore PWM{3,4} config (%d)\n",
++ err2);
++
++ if (!err)
++ err = err2;
++ }
++
+ if (err < 0)
+ return err;
+
+@@ -491,7 +525,7 @@ static ssize_t auto_update_interval_store(struct device *dev,
+ if (kstrtol(buf, 10, &temp))
+ return -EINVAL;
+
+- temp = clamp_val(temp, 0, 60000);
++ temp = clamp_val(temp, 500, 60000);
+
+ mutex_lock(&data->lock);
+ data->auto_update_interval = temp;
+@@ -551,7 +585,7 @@ static int adt7470_temp_read(struct device *dev, u32 attr, int channel, long *va
+ *val = 1000 * data->temp_max[channel];
+ break;
+ case hwmon_temp_alarm:
+- *val = !!(data->alarm & channel);
++ *val = !!(data->alarm & TEMP_ALARM_BIT(channel));
+ break;
+ default:
+ return -EOPNOTSUPP;
+@@ -571,14 +605,16 @@ static int adt7470_temp_write(struct device *dev, u32 attr, int channel, long va
+ switch (attr) {
+ case hwmon_temp_min:
+ mutex_lock(&data->lock);
+- data->temp_min[channel] = val;
+ err = regmap_write(data->regmap, ADT7470_TEMP_MIN_REG(channel), val);
++ if (!err)
++ data->temp_min[channel] = val;
+ mutex_unlock(&data->lock);
+ break;
+ case hwmon_temp_max:
+ mutex_lock(&data->lock);
+- data->temp_max[channel] = val;
+ err = regmap_write(data->regmap, ADT7470_TEMP_MAX_REG(channel), val);
++ if (!err)
++ data->temp_max[channel] = val;
+ mutex_unlock(&data->lock);
+ break;
+ default:
+@@ -624,36 +660,33 @@ static ssize_t alarm_mask_store(struct device *dev,
+ static int adt7470_fan_read(struct device *dev, u32 attr, int channel, long *val)
+ {
+ struct adt7470_data *data = adt7470_update_device(dev);
++ u16 fan_data;
+
+ if (IS_ERR(data))
+ return PTR_ERR(data);
+
+ switch (attr) {
+ case hwmon_fan_input:
+- if (FAN_DATA_VALID(data->fan[channel]))
+- *val = FAN_PERIOD_TO_RPM(data->fan[channel]);
+- else
+- *val = 0;
++ fan_data = READ_ONCE(data->fan[channel]);
+ break;
+ case hwmon_fan_min:
+- if (FAN_DATA_VALID(data->fan_min[channel]))
+- *val = FAN_PERIOD_TO_RPM(data->fan_min[channel]);
+- else
+- *val = 0;
++ fan_data = READ_ONCE(data->fan_min[channel]);
+ break;
+ case hwmon_fan_max:
+- if (FAN_DATA_VALID(data->fan_max[channel]))
+- *val = FAN_PERIOD_TO_RPM(data->fan_max[channel]);
+- else
+- *val = 0;
++ fan_data = READ_ONCE(data->fan_max[channel]);
+ break;
+ case hwmon_fan_alarm:
+- *val = !!(data->alarm & (1 << (12 + channel)));
+- break;
++ *val = !!(data->alarm & FAN_ALARM_BIT(channel));
++ return 0;
+ default:
+ return -EOPNOTSUPP;
+ }
+
++ if (FAN_DATA_VALID(fan_data))
++ *val = FAN_PERIOD_TO_RPM(fan_data);
++ else
++ *val = 0;
++
+ return 0;
+ }
+
+@@ -721,7 +754,7 @@ static ssize_t force_pwm_max_store(struct device *dev,
+ }
+
+ /* These are the valid PWM frequencies to the nearest Hz */
+-static const int adt7470_freq_map[] = {
++static const u32 adt7470_freq_map[] = {
+ 11, 15, 22, 29, 35, 44, 59, 88, 1400, 22500
+ };
+
+@@ -769,7 +802,7 @@ static int adt7470_pwm_read(struct device *dev, u32 attr, int channel, long *val
+ *val = 1 + data->pwm_automatic[channel];
+ break;
+ case hwmon_pwm_freq:
+- *val = pwm1_freq_get(dev);
++ *val = data->pwm_freq;
+ break;
+ default:
+ return -EOPNOTSUPP;
+@@ -782,12 +815,14 @@ static int pwm1_freq_set(struct device *dev, long freq)
+ {
+ struct adt7470_data *data = dev_get_drvdata(dev);
+ unsigned int low_freq = ADT7470_CFG_LF;
++ u32 closest_freq;
+ int index;
+ int err;
+
+ /* Round the user value given to the closest available frequency */
+ index = find_closest(freq, adt7470_freq_map,
+ ARRAY_SIZE(adt7470_freq_map));
++ closest_freq = adt7470_freq_map[index];
+
+ if (index >= 8) {
+ index -= 8;
+@@ -805,6 +840,10 @@ static int pwm1_freq_set(struct device *dev, long freq)
+ err = regmap_update_bits(data->regmap, ADT7470_REG_CFG_2,
+ ADT7470_FREQ_MASK,
+ index << ADT7470_FREQ_SHIFT);
++ if (err < 0)
++ goto out;
++
++ data->pwm_freq = closest_freq;
+ out:
+ mutex_unlock(&data->lock);
+
+@@ -821,9 +860,10 @@ static int adt7470_pwm_write(struct device *dev, u32 attr, int channel, long val
+ case hwmon_pwm_input:
+ val = clamp_val(val, 0, 255);
+ mutex_lock(&data->lock);
+- data->pwm[channel] = val;
+ err = regmap_write(data->regmap, ADT7470_REG_PWM(channel),
+- data->pwm[channel]);
++ val);
++ if (!err)
++ data->pwm[channel] = val;
+ mutex_unlock(&data->lock);
+ break;
+ case hwmon_pwm_enable:
+@@ -837,10 +877,11 @@ static int adt7470_pwm_write(struct device *dev, u32 attr, int channel, long val
+ val--;
+
+ mutex_lock(&data->lock);
+- data->pwm_automatic[channel] = val;
+ err = regmap_update_bits(data->regmap, ADT7470_REG_PWM_CFG(channel),
+ pwm_auto_reg_mask,
+ val ? pwm_auto_reg_mask : 0);
++ if (!err)
++ data->pwm_automatic[channel] = val;
+ mutex_unlock(&data->lock);
+ break;
+ case hwmon_pwm_freq:
+@@ -1016,8 +1057,10 @@ static ssize_t pwm_auto_temp_store(struct device *dev,
+ if (temp < 0)
+ return temp;
+
++ if (temp > 0xF)
++ return -EINVAL;
++
+ mutex_lock(&data->lock);
+- data->pwm_automatic[attr->index] = temp;
+
+ if (!(attr->index % 2)) {
+ mask = 0xF0;
+@@ -1028,6 +1071,9 @@ static ssize_t pwm_auto_temp_store(struct device *dev,
+ }
+
+ err = regmap_update_bits(data->regmap, pwm_auto_reg, mask, val);
++ if (!err)
++ data->pwm_auto_temp[attr->index] = temp;
++
+ mutex_unlock(&data->lock);
+
+ return err < 0 ? err : count;
+@@ -1256,6 +1302,7 @@ static int adt7470_probe(struct i2c_client *client)
+ struct device *dev = &client->dev;
+ struct adt7470_data *data;
+ struct device *hwmon_dev;
++ int freq_val;
+ int err;
+
+ data = devm_kzalloc(dev, sizeof(struct adt7470_data), GFP_KERNEL);
+@@ -1280,6 +1327,14 @@ static int adt7470_probe(struct i2c_client *client)
+ if (err < 0)
+ return err;
+
++ freq_val = pwm1_freq_get(dev);
++ if (freq_val <= 0) {
++ err = freq_val < 0 ? freq_val : -EINVAL;
++ return err;
++ }
++
++ data->pwm_freq = (u32)freq_val;
++
+ /* Register sysfs hooks */
+ hwmon_dev = devm_hwmon_device_register_with_info(dev, client->name, data,
+ &adt7470_chip_info,
+diff --git a/drivers/hwmon/asus-ec-sensors.c b/drivers/hwmon/asus-ec-sensors.c
+index c9222c83ba2409..d7a40070185ec2 100644
+--- a/drivers/hwmon/asus-ec-sensors.c
++++ b/drivers/hwmon/asus-ec-sensors.c
+@@ -525,7 +525,7 @@ struct ec_sensors_data {
+ /* sorted list of unique register banks */
+ u8 banks[ASUS_EC_MAX_BANK + 1];
+ /* in jiffies */
+- unsigned long last_updated;
++ u64 next_update;
+ struct lock_data lock_data;
+ /* number of board EC sensors */
+ u8 nr_sensors;
+@@ -705,7 +705,7 @@ static int asus_ec_block_read(const struct device *dev,
+ }
+ for (ireg = 0; ireg < ec->nr_registers; ireg++) {
+ reg_bank = register_bank(ec->registers[ireg]);
+- if (reg_bank < bank) {
++ if (reg_bank != bank) {
+ continue;
+ }
+ ec_read(register_index(ec->registers[ireg]),
+@@ -794,13 +794,12 @@ static int get_cached_value_or_update(const struct device *dev,
+ int sensor_index,
+ struct ec_sensors_data *state, s32 *value)
+ {
+- if (time_after(jiffies, state->last_updated + HZ)) {
++ if (time_after64(get_jiffies_64(), state->next_update)) {
+ if (update_ec_sensors(dev, state)) {
+ dev_err(dev, "update_ec_sensors() failure\n");
+ return -EIO;
+ }
+-
+- state->last_updated = jiffies;
++ state->next_update = get_jiffies_64() + HZ;
+ }
+
+ *value = state->sensors[sensor_index].cached_value;
+@@ -918,6 +917,7 @@ static int asus_ec_probe(struct platform_device *pdev)
+ if (!ec_data)
+ return -ENOMEM;
+
++ ec_data->next_update = INITIAL_JIFFIES;
+ dev_set_drvdata(dev, ec_data);
+ ec_data->board_info = pboard_info;
+
+@@ -990,9 +990,11 @@ static int asus_ec_probe(struct platform_device *pdev)
+ if (!nr_count[type])
+ continue;
+
+- asus_ec_hwmon_add_chan_info(asus_ec_hwmon_chan, dev,
+- nr_count[type], type,
+- hwmon_attributes[type]);
++ status = asus_ec_hwmon_add_chan_info(asus_ec_hwmon_chan, dev,
++ nr_count[type], type,
++ hwmon_attributes[type]);
++ if (status)
++ return status;
+ *ptr_asus_ec_ci++ = asus_ec_hwmon_chan++;
+ }
+
+diff --git a/drivers/hwmon/corsair-cpro.c b/drivers/hwmon/corsair-cpro.c
+index 18da3e013c20b7..62f9372f2d3551 100644
+--- a/drivers/hwmon/corsair-cpro.c
++++ b/drivers/hwmon/corsair-cpro.c
+@@ -558,6 +558,7 @@ static int ccp_probe(struct hid_device *hdev, const struct hid_device_id *id)
+
+ out_hw_close:
+ hid_hw_close(hdev);
++ hid_device_io_stop(hdev);
+ out_hw_stop:
+ hid_hw_stop(hdev);
+ return ret;
+diff --git a/drivers/hwmon/corsair-psu.c b/drivers/hwmon/corsair-psu.c
+index 1ecd6c58b4567b..8392a18758d218 100644
+--- a/drivers/hwmon/corsair-psu.c
++++ b/drivers/hwmon/corsair-psu.c
+@@ -647,7 +647,7 @@ static int vendor_show(struct seq_file *seqf, void *unused)
+ {
+ struct corsairpsu_data *priv = seqf->private;
+
+- seq_printf(seqf, "%s\n", priv->vendor);
++ seq_printf(seqf, "%.*s\n", REPLY_SIZE, priv->vendor);
+
+ return 0;
+ }
+@@ -657,7 +657,7 @@ static int product_show(struct seq_file *seqf, void *unused)
+ {
+ struct corsairpsu_data *priv = seqf->private;
+
+- seq_printf(seqf, "%s\n", priv->product);
++ seq_printf(seqf, "%.*s\n", REPLY_SIZE, priv->product);
+
+ return 0;
+ }
+@@ -769,6 +769,7 @@ static int corsairpsu_probe(struct hid_device *hdev, const struct hid_device_id
+
+ fail_and_close:
+ hid_hw_close(hdev);
++ hid_device_io_stop(hdev);
+ fail_and_stop:
+ hid_hw_stop(hdev);
+ return ret;
+diff --git a/drivers/hwmon/lm90.c b/drivers/hwmon/lm90.c
+index db595f7d01f8ad..7ce75e64cc3ca6 100644
+--- a/drivers/hwmon/lm90.c
++++ b/drivers/hwmon/lm90.c
+@@ -1148,7 +1148,7 @@ static int lm90_update_alarms_locked(struct lm90_data *data, bool force)
+ check_enable = (client->irq || !(data->config_orig & 0x80)) &&
+ (data->config & 0x80);
+
+- if (force || check_enable)
++ if (data->hwmon_dev && (force || check_enable))
+ schedule_work(&data->report_work);
+
+ /*
+@@ -1156,7 +1156,7 @@ static int lm90_update_alarms_locked(struct lm90_data *data, bool force)
+ * alarms are all clear, and alerts are currently disabled.
+ * Otherwise (re)schedule worker if needed.
+ */
+- if (check_enable) {
++ if (check_enable && data->hwmon_dev) {
+ if (!(data->current_alarms & data->alert_alarms)) {
+ dev_dbg(&client->dev, "Re-enabling ALERT#\n");
+ lm90_update_confreg(data, data->config & ~0x80);
+diff --git a/drivers/hwmon/nct6775-core.c b/drivers/hwmon/nct6775-core.c
+index ec3ff4e9a9abd9..7e8e265cc6c18a 100644
+--- a/drivers/hwmon/nct6775-core.c
++++ b/drivers/hwmon/nct6775-core.c
+@@ -33,6 +33,7 @@
+ * (0xd451)
+ * nct6798d 14 7 7 2+6 0xd428 0xc1 0x5ca3
+ * (0xd429)
++ * nct6799d 14 7 7 2+6 0xd802 0xc1 0x5ca3
+ *
+ * #temp lists the number of monitored temperature sources (first value) plus
+ * the number of directly connectable temperature sensors (second value).
+@@ -73,18 +74,22 @@ static const char * const nct6775_device_names[] = {
+ "nct6796",
+ "nct6797",
+ "nct6798",
++ "nct6799",
+ };
+
+ /* Common and NCT6775 specific data */
+
+-/* Voltage min/max registers for nr=7..14 are in bank 5 */
++/*
++ * Voltage min/max registers for nr=7..14 are in bank 5
++ * min/max: 15-17 for NCT6799 only
++ */
+
+ static const u16 NCT6775_REG_IN_MAX[] = {
+ 0x2b, 0x2d, 0x2f, 0x31, 0x33, 0x35, 0x37, 0x554, 0x556, 0x558, 0x55a,
+- 0x55c, 0x55e, 0x560, 0x562 };
++ 0x55c, 0x55e, 0x560, 0x562, 0x564, 0x570, 0x572 };
+ static const u16 NCT6775_REG_IN_MIN[] = {
+ 0x2c, 0x2e, 0x30, 0x32, 0x34, 0x36, 0x38, 0x555, 0x557, 0x559, 0x55b,
+- 0x55d, 0x55f, 0x561, 0x563 };
++ 0x55d, 0x55f, 0x561, 0x563, 0x565, 0x571, 0x573 };
+ static const u16 NCT6775_REG_IN[] = {
+ 0x20, 0x21, 0x22, 0x23, 0x24, 0x25, 0x26, 0x550, 0x551, 0x552
+ };
+@@ -95,31 +100,23 @@ static const u16 NCT6775_REG_IN[] = {
+
+ static const u16 NCT6775_REG_ALARM[NUM_REG_ALARM] = { 0x459, 0x45A, 0x45B };
+
+-/* 0..15 voltages, 16..23 fans, 24..29 temperatures, 30..31 intrusion */
+-
+-static const s8 NCT6775_ALARM_BITS[] = {
+- 0, 1, 2, 3, 8, 21, 20, 16, /* in0.. in7 */
+- 17, -1, -1, -1, -1, -1, -1, /* in8..in14 */
+- -1, /* unused */
+- 6, 7, 11, -1, -1, /* fan1..fan5 */
+- -1, -1, -1, /* unused */
+- 4, 5, 13, -1, -1, -1, /* temp1..temp6 */
+- 12, -1 }; /* intrusion0, intrusion1 */
++static const s8 NCT6775_ALARM_BITS[NUM_ALARM_BITS] = {
++ 0, 1, 2, 3, 8, 21, 20, 16, 17, -1, -1, -1, /* in0-in11 */
++ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, /* in12-in23 */
++ 6, 7, 11, -1, -1, -1, -1, -1, -1, -1, -1, -1, /* fan1-fan12 */
++ 4, 5, 13, -1, -1, -1, -1, -1, -1, -1, -1, -1, /* temp1-temp12 */
++ 12, -1, /* intr0-intr1 */
++};
+
+ static const u16 NCT6775_REG_BEEP[NUM_REG_BEEP] = { 0x56, 0x57, 0x453, 0x4e };
+
+-/*
+- * 0..14 voltages, 15 global beep enable, 16..23 fans, 24..29 temperatures,
+- * 30..31 intrusion
+- */
+-static const s8 NCT6775_BEEP_BITS[] = {
+- 0, 1, 2, 3, 8, 9, 10, 16, /* in0.. in7 */
+- 17, -1, -1, -1, -1, -1, -1, /* in8..in14 */
+- 21, /* global beep enable */
+- 6, 7, 11, 28, -1, /* fan1..fan5 */
+- -1, -1, -1, /* unused */
+- 4, 5, 13, -1, -1, -1, /* temp1..temp6 */
+- 12, -1 }; /* intrusion0, intrusion1 */
++static const s8 NCT6775_BEEP_BITS[NUM_BEEP_BITS] = {
++ 0, 1, 2, 3, 8, 9, 10, 16, 17, -1, -1, -1, /* in0-in11 */
++ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, /* in12-in23 */
++ 6, 7, 11, 28, -1, -1, -1, -1, -1, -1, -1, -1, /* fan1-fan12 */
++ 4, 5, 13, -1, -1, -1, -1, -1, -1, -1, -1, -1, /* temp1-temp12 */
++ 12, -1, 21 /* intr0-intr1, beep_en */
++};
+
+ /* DC or PWM output fan configuration */
+ static const u8 NCT6775_REG_PWM_MODE[] = { 0x04, 0x04, 0x12 };
+@@ -253,25 +250,24 @@ static const u16 NCT6775_REG_TSI_TEMP[] = { 0x669 };
+ #define NCT6776_REG_FAN_STEP_UP_TIME NCT6775_REG_FAN_STEP_DOWN_TIME
+ #define NCT6776_REG_FAN_STEP_DOWN_TIME NCT6775_REG_FAN_STEP_UP_TIME
+
+-static const s8 NCT6776_ALARM_BITS[] = {
+- 0, 1, 2, 3, 8, 21, 20, 16, /* in0.. in7 */
+- 17, -1, -1, -1, -1, -1, -1, /* in8..in14 */
+- -1, /* unused */
+- 6, 7, 11, 10, 23, /* fan1..fan5 */
+- -1, -1, -1, /* unused */
+- 4, 5, 13, -1, -1, -1, /* temp1..temp6 */
+- 12, 9 }; /* intrusion0, intrusion1 */
+-
+-static const u16 NCT6776_REG_BEEP[NUM_REG_BEEP] = { 0xb2, 0xb3, 0xb4, 0xb5 };
+-
+-static const s8 NCT6776_BEEP_BITS[] = {
+- 0, 1, 2, 3, 4, 5, 6, 7, /* in0.. in7 */
+- 8, -1, -1, -1, -1, -1, -1, /* in8..in14 */
+- 24, /* global beep enable */
+- 25, 26, 27, 28, 29, /* fan1..fan5 */
+- -1, -1, -1, /* unused */
+- 16, 17, 18, 19, 20, 21, /* temp1..temp6 */
+- 30, 31 }; /* intrusion0, intrusion1 */
++static const s8 NCT6776_ALARM_BITS[NUM_ALARM_BITS] = {
++ 0, 1, 2, 3, 8, 21, 20, 16, 17, -1, -1, -1, /* in0-in11 */
++ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, /* in12-in23 */
++ 6, 7, 11, 10, 23, -1, -1, -1, -1, -1, -1, -1, /* fan1-fan12 */
++ 4, 5, 13, -1, -1, -1, -1, -1, -1, -1, -1, -1, /* temp1-temp12 */
++ 12, 9, /* intr0-intr1 */
++};
++
++/* 0xbf: nct6799 only */
++static const u16 NCT6776_REG_BEEP[NUM_REG_BEEP] = { 0xb2, 0xb3, 0xb4, 0xb5, 0xbf };
++
++static const s8 NCT6776_BEEP_BITS[NUM_BEEP_BITS] = {
++ 0, 1, 2, 3, 4, 5, 6, 7, 8, -1, -1, -1, /* in0-in11 */
++ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, /* in12-in23 */
++ 25, 26, 27, 28, 29, -1, -1, -1, -1, -1, -1, -1, /* fan1-fan12 */
++ 16, 17, 18, 19, 20, 21, -1, -1, -1, -1, -1, -1, /* temp1-temp12 */
++ 30, 31, 24 /* intr0-intr1, beep_en */
++};
+
+ static const u16 NCT6776_REG_TOLERANCE_H[] = {
+ 0x10c, 0x20c, 0x30c, 0x80c, 0x90c, 0xa0c, 0xb0c };
+@@ -335,30 +331,35 @@ static const u16 NCT6776_REG_TSI_TEMP[] = {
+
+ /* NCT6779 specific data */
+
++/*
++ * 15-17 for NCT6799 only, register labels are:
++ * CPUVC, VIN1, AVSB, 3VCC, VIN0, VIN8, VIN4, 3VSB
++ * VBAT, VTT, VIN5, VIN6, VIN2, VIN3, VIN7, VIN9
++ * VHIF, VIN10
++ */
+ static const u16 NCT6779_REG_IN[] = {
+ 0x480, 0x481, 0x482, 0x483, 0x484, 0x485, 0x486, 0x487,
+- 0x488, 0x489, 0x48a, 0x48b, 0x48c, 0x48d, 0x48e };
++ 0x488, 0x489, 0x48a, 0x48b, 0x48c, 0x48d, 0x48e, 0x48f,
++ 0x470, 0x471};
+
+ static const u16 NCT6779_REG_ALARM[NUM_REG_ALARM] = {
+ 0x459, 0x45A, 0x45B, 0x568 };
+
+-static const s8 NCT6779_ALARM_BITS[] = {
+- 0, 1, 2, 3, 8, 21, 20, 16, /* in0.. in7 */
+- 17, 24, 25, 26, 27, 28, 29, /* in8..in14 */
+- -1, /* unused */
+- 6, 7, 11, 10, 23, /* fan1..fan5 */
+- -1, -1, -1, /* unused */
+- 4, 5, 13, -1, -1, -1, /* temp1..temp6 */
+- 12, 9 }; /* intrusion0, intrusion1 */
+-
+-static const s8 NCT6779_BEEP_BITS[] = {
+- 0, 1, 2, 3, 4, 5, 6, 7, /* in0.. in7 */
+- 8, 9, 10, 11, 12, 13, 14, /* in8..in14 */
+- 24, /* global beep enable */
+- 25, 26, 27, 28, 29, /* fan1..fan5 */
+- -1, -1, -1, /* unused */
+- 16, 17, -1, -1, -1, -1, /* temp1..temp6 */
+- 30, 31 }; /* intrusion0, intrusion1 */
++static const s8 NCT6779_ALARM_BITS[NUM_ALARM_BITS] = {
++ 0, 1, 2, 3, 8, 21, 20, 16, 17, 24, 25, 26, /* in0-in11 */
++ 27, 28, 29, -1, -1, -1, -1, -1, -1, -1, -1, -1, /* in12-in23 */
++ 6, 7, 11, 10, 23, -1, -1, -1, -1, -1, -1, -1, /* fan1-fan12 */
++ 4, 5, 13, -1, -1, -1, -1, -1, -1, -1, -1, -1, /* temp1-temp12 */
++ 12, 9, /* intr0-intr1 */
++};
++
++static const s8 NCT6779_BEEP_BITS[NUM_BEEP_BITS] = {
++ 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, /* in0-in11 */
++ 12, 13, 14, -1, -1, -1, -1, -1, -1, -1, -1, -1, /* in12-in23 */
++ 25, 26, 27, 28, 29, -1, -1, -1, -1, -1, -1, -1, /* fan1-fan12 */
++ 16, 17, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, /* temp1-temp12 */
++ 30, 31, 24 /* intr0-intr1, beep_en */
++};
+
+ static const u16 NCT6779_REG_FAN[] = {
+ 0x4c0, 0x4c2, 0x4c4, 0x4c6, 0x4c8, 0x4ca, 0x4ce };
+@@ -381,7 +382,7 @@ static const u16 NCT6779_REG_TEMP_OVER[ARRAY_SIZE(NCT6779_REG_TEMP)] = {
+ 0x39, 0x155 };
+
+ static const u16 NCT6779_REG_TEMP_OFFSET[] = {
+- 0x454, 0x455, 0x456, 0x44a, 0x44b, 0x44c };
++ 0x454, 0x455, 0x456, 0x44a, 0x44b, 0x44c, 0x44d, 0x449 };
+
+ static const char *const nct6779_temp_label[] = {
+ "",
+@@ -446,14 +447,13 @@ static const u16 NCT6791_REG_WEIGHT_DUTY_BASE[NUM_FAN] = { 0, 0x23e };
+ static const u16 NCT6791_REG_ALARM[NUM_REG_ALARM] = {
+ 0x459, 0x45A, 0x45B, 0x568, 0x45D };
+
+-static const s8 NCT6791_ALARM_BITS[] = {
+- 0, 1, 2, 3, 8, 21, 20, 16, /* in0.. in7 */
+- 17, 24, 25, 26, 27, 28, 29, /* in8..in14 */
+- -1, /* unused */
+- 6, 7, 11, 10, 23, 33, /* fan1..fan6 */
+- -1, -1, /* unused */
+- 4, 5, 13, -1, -1, -1, /* temp1..temp6 */
+- 12, 9 }; /* intrusion0, intrusion1 */
++static const s8 NCT6791_ALARM_BITS[NUM_ALARM_BITS] = {
++ 0, 1, 2, 3, 8, 21, 20, 16, 17, 24, 25, 26, /* in0-in11 */
++ 27, 28, 29, -1, -1, -1, -1, -1, -1, -1, -1, -1, /* in12-in23 */
++ 6, 7, 11, 10, 23, 33, -1, -1, -1, -1, -1, -1, /* fan1-fan12 */
++ 4, 5, 13, -1, -1, -1, -1, -1, -1, -1, -1, -1, /* temp1-temp12 */
++ 12, 9, /* intr0-intr1 */
++};
+
+ /* NCT6792/NCT6793 specific data */
+
+@@ -616,6 +616,28 @@ static const char *const nct6796_temp_label[] = {
+
+ static const u16 NCT6796_REG_TSI_TEMP[] = { 0x409, 0x40b };
+
++static const u16 NCT6798_REG_TEMP[] = {
++ 0x27, 0x150, 0x670, 0x672, 0x674, 0x676, 0x678, 0x67a};
++
++static const u16 NCT6798_REG_TEMP_SOURCE[] = {
++ 0x621, 0x622, 0xc26, 0xc27, 0xc28, 0xc29, 0xc2a, 0xc2b };
++
++static const u16 NCT6798_REG_TEMP_MON[] = {
++ 0x73, 0x75, 0x77, 0x79, 0x7b, 0x7d, 0x4a0 };
++static const u16 NCT6798_REG_TEMP_OVER[] = {
++ 0x39, 0x155, 0xc1a, 0xc1b, 0xc1c, 0xc1d, 0xc1e, 0xc1f };
++static const u16 NCT6798_REG_TEMP_HYST[] = {
++ 0x3a, 0x153, 0xc20, 0xc21, 0xc22, 0xc23, 0xc24, 0xc25 };
++
++static const u16 NCT6798_REG_TEMP_CRIT[32] = {
++ 0x135, 0x235, 0x335, 0x835, 0x935, 0xa35, 0xb35, 0 };
++
++static const u16 NCT6798_REG_TEMP_ALTERNATE[32] = {
++ 0x490, 0x491, 0x492, 0x493, 0x494, 0x495, 0x496, 0,
++ 0, 0, 0, 0, 0x4a2, 0, 0, 0,
++ 0, 0x400, 0x401, 0x402, 0x404, 0x405, 0x406, 0x407,
++ 0x408, 0x419, 0x41a, 0x4f4, 0x4f5 };
++
+ static const char *const nct6798_temp_label[] = {
+ "",
+ "SYSTIN",
+@@ -654,6 +676,64 @@ static const char *const nct6798_temp_label[] = {
+ #define NCT6798_TEMP_MASK 0xbfff0ffe
+ #define NCT6798_VIRT_TEMP_MASK 0x80000c00
+
++static const u16 NCT6799_REG_ALARM[NUM_REG_ALARM] = {
++ 0x459, 0x45A, 0x45B, 0x568, 0x45D, 0xc01 };
++
++static const s8 NCT6799_ALARM_BITS[NUM_ALARM_BITS] = {
++ 0, 1, 2, 3, 8, -1, 20, 16, 17, 24, 25, 26, /* in0-in11 */
++ 27, 28, 29, 30, 31, -1, -1, -1, -1, -1, -1, -1, /* in12-in23 */
++ 6, 7, 11, 10, 23, 33, -1, -1, -1, -1, -1, -1, /* fan1-fan12 */
++ 4, 5, 40, 41, 42, 43, 44, -1, -1, -1, -1, -1, /* temp1-temp12 */
++ 12, 9, /* intr0-intr1 */
++};
++
++static const s8 NCT6799_BEEP_BITS[NUM_BEEP_BITS] = {
++ 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, /* in0-in11 */
++ 12, 13, 14, 15, 34, 35, -1, -1, -1, -1, -1, -1, /* in12-in23 */
++ 25, 26, 27, 28, 29, -1, -1, -1, -1, -1, -1, -1, /* fan1-fan12 */
++ 16, 17, 18, 19, 20, 21, 22, 23, -1, -1, -1, -1, /* temp1-temp12 */
++ 30, 31, 24 /* intr0-intr1, beep_en */
++};
++
++/* PECI Calibration only for NCT6799D, not NCT6796D-S */
++static const char *const nct6799_temp_label[] = {
++ "",
++ "SYSTIN",
++ "CPUTIN",
++ "AUXTIN0",
++ "AUXTIN1",
++ "AUXTIN2",
++ "AUXTIN3",
++ "AUXTIN4",
++ "SMBUSMASTER 0",
++ "SMBUSMASTER 1",
++ "Virtual_TEMP",
++ "Virtual_TEMP",
++ "",
++ "AUXTIN5",
++ "",
++ "",
++ "PECI Agent 0",
++ "PECI Agent 1",
++ "PCH_CHIP_CPU_MAX_TEMP",
++ "PCH_CHIP_TEMP",
++ "PCH_CPU_TEMP",
++ "PCH_MCH_TEMP",
++ "Agent0 Dimm0",
++ "Agent0 Dimm1",
++ "Agent1 Dimm0",
++ "Agent1 Dimm1",
++ "BYTE_TEMP0",
++ "BYTE_TEMP1",
++ "PECI/TSI Agent 0 Calibration",
++ "PECI/TSI Agent 1 Calibration",
++ "",
++ "Virtual_TEMP"
++};
++
++#define NCT6799_TEMP_MASK 0xbfff2ffe
++#define NCT6799_VIRT_TEMP_MASK 0x80000c00
++
+ /* NCT6102D/NCT6106D specific data */
+
+ #define NCT6106_REG_VBAT 0x318
+@@ -710,12 +790,12 @@ static const u16 NCT6106_REG_TOLERANCE_H[] = { 0x112, 0x122, 0x132 };
+
+ static const u16 NCT6106_REG_TARGET[] = { 0x111, 0x121, 0x131 };
+
+-static const u16 NCT6106_REG_WEIGHT_TEMP_SEL[] = { 0x168, 0x178, 0x188 };
+-static const u16 NCT6106_REG_WEIGHT_TEMP_STEP[] = { 0x169, 0x179, 0x189 };
+-static const u16 NCT6106_REG_WEIGHT_TEMP_STEP_TOL[] = { 0x16a, 0x17a, 0x18a };
+-static const u16 NCT6106_REG_WEIGHT_DUTY_STEP[] = { 0x16b, 0x17b, 0x18b };
+-static const u16 NCT6106_REG_WEIGHT_TEMP_BASE[] = { 0x16c, 0x17c, 0x18c };
+-static const u16 NCT6106_REG_WEIGHT_DUTY_BASE[] = { 0x16d, 0x17d, 0x18d };
++static const u16 NCT6106_REG_WEIGHT_TEMP_SEL[] = { 0x168, 0x178, 0x188, 0, 0 };
++static const u16 NCT6106_REG_WEIGHT_TEMP_STEP[] = { 0x169, 0x179, 0x189, 0, 0 };
++static const u16 NCT6106_REG_WEIGHT_TEMP_STEP_TOL[] = { 0x16a, 0x17a, 0x18a, 0, 0 };
++static const u16 NCT6106_REG_WEIGHT_DUTY_STEP[] = { 0x16b, 0x17b, 0x18b, 0, 0 };
++static const u16 NCT6106_REG_WEIGHT_TEMP_BASE[] = { 0x16c, 0x17c, 0x18c, 0, 0 };
++static const u16 NCT6106_REG_WEIGHT_DUTY_BASE[] = { 0x16d, 0x17d, 0x18d, 0, 0 };
+
+ static const u16 NCT6106_REG_AUTO_TEMP[] = { 0x160, 0x170, 0x180 };
+ static const u16 NCT6106_REG_AUTO_PWM[] = { 0x164, 0x174, 0x184 };
+@@ -723,27 +803,23 @@ static const u16 NCT6106_REG_AUTO_PWM[] = { 0x164, 0x174, 0x184 };
+ static const u16 NCT6106_REG_ALARM[NUM_REG_ALARM] = {
+ 0x77, 0x78, 0x79, 0x7a, 0x7b, 0x7c, 0x7d };
+
+-static const s8 NCT6106_ALARM_BITS[] = {
+- 0, 1, 2, 3, 4, 5, 7, 8, /* in0.. in7 */
+- 9, -1, -1, -1, -1, -1, -1, /* in8..in14 */
+- -1, /* unused */
+- 32, 33, 34, -1, -1, /* fan1..fan5 */
+- -1, -1, -1, /* unused */
+- 16, 17, 18, 19, 20, 21, /* temp1..temp6 */
+- 48, -1 /* intrusion0, intrusion1 */
++static const s8 NCT6106_ALARM_BITS[NUM_ALARM_BITS] = {
++ 0, 1, 2, 3, 4, 5, 7, 8, 9, -1, -1, -1, /* in0-in11 */
++ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, /* in12-in23 */
++ 32, 33, 34, -1, -1, -1, -1, -1, -1, -1, -1, -1, /* fan1-fan12 */
++ 16, 17, 18, 19, 20, 21, -1, -1, -1, -1, -1, -1, /* temp1-temp12 */
++ 48, -1, /* intr0-intr1 */
+ };
+
+ static const u16 NCT6106_REG_BEEP[NUM_REG_BEEP] = {
+ 0x3c0, 0x3c1, 0x3c2, 0x3c3, 0x3c4 };
+
+-static const s8 NCT6106_BEEP_BITS[] = {
+- 0, 1, 2, 3, 4, 5, 7, 8, /* in0.. in7 */
+- 9, 10, 11, 12, -1, -1, -1, /* in8..in14 */
+- 32, /* global beep enable */
+- 24, 25, 26, 27, 28, /* fan1..fan5 */
+- -1, -1, -1, /* unused */
+- 16, 17, 18, 19, 20, 21, /* temp1..temp6 */
+- 34, -1 /* intrusion0, intrusion1 */
++static const s8 NCT6106_BEEP_BITS[NUM_BEEP_BITS] = {
++ 0, 1, 2, 3, 4, 5, 7, 8, 9, 10, 11, 12, /* in0-in11 */
++ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, /* in12-in23 */
++ 24, 25, 26, 27, 28, -1, -1, -1, -1, -1, -1, -1, /* fan1-fan12 */
++ 16, 17, 18, 19, 20, 21, -1, -1, -1, -1, -1, -1, /* temp1-temp12 */
++ 34, -1, 32 /* intr0-intr1, beep_en */
+ };
+
+ static const u16 NCT6106_REG_TEMP_ALTERNATE[32] = {
+@@ -769,8 +845,6 @@ static const u16 NCT6116_FAN_PULSE_SHIFT[] = { 0, 2, 4, 6, 6 };
+ static const u16 NCT6116_REG_PWM[] = { 0x119, 0x129, 0x139, 0x199, 0x1a9 };
+ static const u16 NCT6116_REG_FAN_MODE[] = { 0x113, 0x123, 0x133, 0x193, 0x1a3 };
+ static const u16 NCT6116_REG_TEMP_SEL[] = { 0x110, 0x120, 0x130, 0x190, 0x1a0 };
+-static const u16 NCT6116_REG_TEMP_SOURCE[] = {
+- 0xb0, 0xb1, 0xb2 };
+
+ static const u16 NCT6116_REG_CRITICAL_TEMP[] = {
+ 0x11a, 0x12a, 0x13a, 0x19a, 0x1aa };
+@@ -803,24 +877,20 @@ static const u16 NCT6116_REG_AUTO_TEMP[] = {
+ static const u16 NCT6116_REG_AUTO_PWM[] = {
+ 0x164, 0x174, 0x184, 0x1d4, 0x1e4 };
+
+-static const s8 NCT6116_ALARM_BITS[] = {
+- 0, 1, 2, 3, 4, 5, 7, 8, /* in0.. in7 */
+- 9, -1, -1, -1, -1, -1, -1, /* in8..in9 */
+- -1, /* unused */
+- 32, 33, 34, 35, 36, /* fan1..fan5 */
+- -1, -1, -1, /* unused */
+- 16, 17, 18, -1, -1, -1, /* temp1..temp6 */
+- 48, -1 /* intrusion0, intrusion1 */
++static const s8 NCT6116_ALARM_BITS[NUM_ALARM_BITS] = {
++ 0, 1, 2, 3, 4, 5, 7, 8, 9, -1, -1, -1, /* in0-in11 */
++ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, /* in12-in23 */
++ 32, 33, 34, 35, 36, -1, -1, -1, -1, -1, -1, -1, /* fan1-fan12 */
++ 16, 17, 18, -1, -1, -1, -1, -1, -1, -1, -1, -1, /* temp1-temp12 */
++ 48, -1, /* intr0-intr1 */
+ };
+
+-static const s8 NCT6116_BEEP_BITS[] = {
+- 0, 1, 2, 3, 4, 5, 7, 8, /* in0.. in7 */
+- 9, 10, 11, 12, -1, -1, -1, /* in8..in14 */
+- 32, /* global beep enable */
+- 24, 25, 26, 27, 28, /* fan1..fan5 */
+- -1, -1, -1, /* unused */
+- 16, 17, 18, -1, -1, -1, /* temp1..temp6 */
+- 34, -1 /* intrusion0, intrusion1 */
++static const s8 NCT6116_BEEP_BITS[NUM_BEEP_BITS] = {
++ 0, 1, 2, 3, 4, 5, 7, 8, 9, 10, 11, 12, /* in0-in11 */
++ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, /* in12-in23 */
++ 24, 25, 26, 27, 28, -1, -1, -1, -1, -1, -1, -1, /* fan1-fan12 */
++ 16, 17, 18, -1, -1, -1, -1, -1, -1, -1, -1, -1, /* temp1-temp12 */
++ 34, -1, 32 /* intr0-intr1, beep_en */
+ };
+
+ static const u16 NCT6116_REG_TSI_TEMP[] = { 0x59, 0x5b };
+@@ -915,14 +985,25 @@ static const u16 scale_in[15] = {
+ 800, 800
+ };
+
+-static inline long in_from_reg(u8 reg, u8 nr)
++/*
++ * NCT6798 scaling:
++ * CPUVC, IN1, AVSB, 3VCC, IN0, IN8, IN4, 3VSB, VBAT, VTT, IN5, IN6, IN2,
++ * IN3, IN7, IN9, VHIF, IN10
++ * 15-17 for NCT6799 only
++ */
++static const u16 scale_in_6798[NUM_IN] = {
++ 800, 800, 1600, 1600, 800, 800, 800, 1600, 1600, 1600, 1600, 1600, 800,
++ 800, 800, 800, 1600, 800
++};
++
++static inline long in_from_reg(u8 reg, u8 nr, const u16 *scales)
+ {
+- return DIV_ROUND_CLOSEST(reg * scale_in[nr], 100);
++ return DIV_ROUND_CLOSEST(reg * scales[nr], 100);
+ }
+
+-static inline u8 in_to_reg(u32 val, u8 nr)
++static inline u8 in_to_reg(u32 val, u8 nr, const u16 *scales)
+ {
+- return clamp_val(DIV_ROUND_CLOSEST(val * 100, scale_in[nr]), 0, 255);
++ return clamp_val(DIV_ROUND_CLOSEST(val * 100, scales[nr]), 0, 255);
+ }
+
+ /* TSI temperatures are in 8.3 format */
+@@ -1109,6 +1190,7 @@ bool nct6775_reg_is_word_sized(struct nct6775_data *data, u16 reg)
+ case nct6796:
+ case nct6797:
+ case nct6798:
++ case nct6799:
+ return reg == 0x150 || reg == 0x153 || reg == 0x155 ||
+ (reg & 0xfff0) == 0x4c0 ||
+ reg == 0x402 ||
+@@ -1462,6 +1544,7 @@ static int nct6775_update_pwm_limits(struct device *dev)
+ case nct6796:
+ case nct6797:
+ case nct6798:
++ case nct6799:
+ err = nct6775_read_value(data, data->REG_CRITICAL_PWM_ENABLE[i], ®);
+ if (err)
+ return err;
+@@ -1635,7 +1718,8 @@ show_in_reg(struct device *dev, struct device_attribute *attr, char *buf)
+ if (IS_ERR(data))
+ return PTR_ERR(data);
+
+- return sprintf(buf, "%ld\n", in_from_reg(data->in[nr][index], nr));
++ return sprintf(buf, "%ld\n",
++ in_from_reg(data->in[nr][index], nr, data->scale_in));
+ }
+
+ static ssize_t
+@@ -1653,7 +1737,7 @@ store_in_reg(struct device *dev, struct device_attribute *attr, const char *buf,
+ if (err < 0)
+ return err;
+ mutex_lock(&data->update_lock);
+- data->in[nr][index] = in_to_reg(val, nr);
++ data->in[nr][index] = in_to_reg(val, nr, data->scale_in);
+ err = nct6775_write_value(data, data->REG_IN_MINMAX[index - 1][nr], data->in[nr][index]);
+ mutex_unlock(&data->update_lock);
+ return err ? : count;
+@@ -1827,6 +1911,10 @@ static umode_t nct6775_in_is_visible(struct kobject *kobj,
+ struct device *dev = kobj_to_dev(kobj);
+ struct nct6775_data *data = dev_get_drvdata(dev);
+ int in = index / 5; /* voltage index */
++ int nr = index % 5; /* attribute index */
++
++ if (nr == 1 && data->ALARM_BITS[in] == -1)
++ return 0;
+
+ if (!(data->have_in & BIT(in)))
+ return 0;
+@@ -3119,6 +3207,7 @@ store_auto_pwm(struct device *dev, struct device_attribute *attr,
+ case nct6796:
+ case nct6797:
+ case nct6798:
++ case nct6799:
+ err = nct6775_write_value(data, data->REG_CRITICAL_PWM[nr], val);
+ if (err)
+ break;
+@@ -3419,6 +3508,7 @@ int nct6775_probe(struct device *dev, struct nct6775_data *data,
+ const u16 *reg_temp_mon, *reg_temp_alternate, *reg_temp_crit;
+ const u16 *reg_temp_crit_l = NULL, *reg_temp_crit_h = NULL;
+ int num_reg_temp, num_reg_temp_mon, num_reg_tsi_temp;
++ int num_reg_temp_config;
+ struct device *hwmon_dev;
+ struct sensor_template_group tsi_temp_tg;
+
+@@ -3429,6 +3519,7 @@ int nct6775_probe(struct device *dev, struct nct6775_data *data,
+ mutex_init(&data->update_lock);
+ data->name = nct6775_device_names[data->kind];
+ data->bank = 0xff; /* Force initial bank selection */
++ data->scale_in = scale_in;
+
+ switch (data->kind) {
+ case nct6106:
+@@ -3500,6 +3591,7 @@ int nct6775_probe(struct device *dev, struct nct6775_data *data,
+ reg_temp_over = NCT6106_REG_TEMP_OVER;
+ reg_temp_hyst = NCT6106_REG_TEMP_HYST;
+ reg_temp_config = NCT6106_REG_TEMP_CONFIG;
++ num_reg_temp_config = ARRAY_SIZE(NCT6106_REG_TEMP_CONFIG);
+ reg_temp_alternate = NCT6106_REG_TEMP_ALTERNATE;
+ reg_temp_crit = NCT6106_REG_TEMP_CRIT;
+ reg_temp_crit_l = NCT6106_REG_TEMP_CRIT_L;
+@@ -3555,7 +3647,7 @@ int nct6775_probe(struct device *dev, struct nct6775_data *data,
+ = NCT6106_CRITICAL_PWM_ENABLE_MASK;
+ data->REG_CRITICAL_PWM = NCT6116_REG_CRITICAL_PWM;
+ data->REG_TEMP_OFFSET = NCT6106_REG_TEMP_OFFSET;
+- data->REG_TEMP_SOURCE = NCT6116_REG_TEMP_SOURCE;
++ data->REG_TEMP_SOURCE = NCT6106_REG_TEMP_SOURCE;
+ data->REG_TEMP_SEL = NCT6116_REG_TEMP_SEL;
+ data->REG_WEIGHT_TEMP_SEL = NCT6106_REG_WEIGHT_TEMP_SEL;
+ data->REG_WEIGHT_TEMP[0] = NCT6106_REG_WEIGHT_TEMP_STEP;
+@@ -3569,12 +3661,13 @@ int nct6775_probe(struct device *dev, struct nct6775_data *data,
+
+ reg_temp = NCT6106_REG_TEMP;
+ reg_temp_mon = NCT6106_REG_TEMP_MON;
+- num_reg_temp = ARRAY_SIZE(NCT6106_REG_TEMP);
++ num_reg_temp = 3;
+ num_reg_temp_mon = ARRAY_SIZE(NCT6106_REG_TEMP_MON);
+ num_reg_tsi_temp = ARRAY_SIZE(NCT6116_REG_TSI_TEMP);
+ reg_temp_over = NCT6106_REG_TEMP_OVER;
+ reg_temp_hyst = NCT6106_REG_TEMP_HYST;
+ reg_temp_config = NCT6106_REG_TEMP_CONFIG;
++ num_reg_temp_config = 3;
+ reg_temp_alternate = NCT6106_REG_TEMP_ALTERNATE;
+ reg_temp_crit = NCT6106_REG_TEMP_CRIT;
+ reg_temp_crit_l = NCT6106_REG_TEMP_CRIT_L;
+@@ -3652,6 +3745,7 @@ int nct6775_probe(struct device *dev, struct nct6775_data *data,
+ reg_temp_over = NCT6775_REG_TEMP_OVER;
+ reg_temp_hyst = NCT6775_REG_TEMP_HYST;
+ reg_temp_config = NCT6775_REG_TEMP_CONFIG;
++ num_reg_temp_config = ARRAY_SIZE(NCT6775_REG_TEMP_CONFIG);
+ reg_temp_alternate = NCT6775_REG_TEMP_ALTERNATE;
+ reg_temp_crit = NCT6775_REG_TEMP_CRIT;
+
+@@ -3727,6 +3821,7 @@ int nct6775_probe(struct device *dev, struct nct6775_data *data,
+ reg_temp_over = NCT6775_REG_TEMP_OVER;
+ reg_temp_hyst = NCT6775_REG_TEMP_HYST;
+ reg_temp_config = NCT6776_REG_TEMP_CONFIG;
++ num_reg_temp_config = ARRAY_SIZE(NCT6776_REG_TEMP_CONFIG);
+ reg_temp_alternate = NCT6776_REG_TEMP_ALTERNATE;
+ reg_temp_crit = NCT6776_REG_TEMP_CRIT;
+
+@@ -3806,6 +3901,7 @@ int nct6775_probe(struct device *dev, struct nct6775_data *data,
+ reg_temp_over = NCT6779_REG_TEMP_OVER;
+ reg_temp_hyst = NCT6779_REG_TEMP_HYST;
+ reg_temp_config = NCT6779_REG_TEMP_CONFIG;
++ num_reg_temp_config = ARRAY_SIZE(NCT6779_REG_TEMP_CONFIG);
+ reg_temp_alternate = NCT6779_REG_TEMP_ALTERNATE;
+ reg_temp_crit = NCT6779_REG_TEMP_CRIT;
+
+@@ -3816,11 +3912,9 @@ int nct6775_probe(struct device *dev, struct nct6775_data *data,
+ case nct6795:
+ case nct6796:
+ case nct6797:
+- case nct6798:
+ data->in_num = 15;
+ data->pwm_num = (data->kind == nct6796 ||
+- data->kind == nct6797 ||
+- data->kind == nct6798) ? 7 : 6;
++ data->kind == nct6797) ? 7 : 6;
+ data->auto_pwm_num = 4;
+ data->has_fan_div = false;
+ data->temp_fixed_num = 6;
+@@ -3864,11 +3958,6 @@ int nct6775_probe(struct device *dev, struct nct6775_data *data,
+ data->temp_mask = NCT6796_TEMP_MASK;
+ data->virt_temp_mask = NCT6796_VIRT_TEMP_MASK;
+ break;
+- case nct6798:
+- data->temp_label = nct6798_temp_label;
+- data->temp_mask = NCT6798_TEMP_MASK;
+- data->virt_temp_mask = NCT6798_VIRT_TEMP_MASK;
+- break;
+ }
+
+ data->REG_CONFIG = NCT6775_REG_CONFIG;
+@@ -3927,7 +4016,6 @@ int nct6775_probe(struct device *dev, struct nct6775_data *data,
+ case nct6795:
+ case nct6796:
+ case nct6797:
+- case nct6798:
+ data->REG_TSI_TEMP = NCT6796_REG_TSI_TEMP;
+ num_reg_tsi_temp = ARRAY_SIZE(NCT6796_REG_TSI_TEMP);
+ break;
+@@ -3948,9 +4036,100 @@ int nct6775_probe(struct device *dev, struct nct6775_data *data,
+ reg_temp_over = NCT6779_REG_TEMP_OVER;
+ reg_temp_hyst = NCT6779_REG_TEMP_HYST;
+ reg_temp_config = NCT6779_REG_TEMP_CONFIG;
++ num_reg_temp_config = ARRAY_SIZE(NCT6779_REG_TEMP_CONFIG);
+ reg_temp_alternate = NCT6779_REG_TEMP_ALTERNATE;
+ reg_temp_crit = NCT6779_REG_TEMP_CRIT;
+
++ break;
++ case nct6798:
++ case nct6799:
++ data->in_num = data->kind == nct6799 ? 18 : 15;
++ data->scale_in = scale_in_6798;
++ data->pwm_num = 7;
++ data->auto_pwm_num = 4;
++ data->has_fan_div = false;
++ data->temp_fixed_num = 6;
++ data->num_temp_alarms = 7;
++ data->num_temp_beeps = 8;
++
++ data->ALARM_BITS = NCT6799_ALARM_BITS;
++ data->BEEP_BITS = NCT6799_BEEP_BITS;
++
++ data->fan_from_reg = fan_from_reg_rpm;
++ data->fan_from_reg_min = fan_from_reg13;
++ data->target_temp_mask = 0xff;
++ data->tolerance_mask = 0x07;
++ data->speed_tolerance_limit = 63;
++
++ switch (data->kind) {
++ default:
++ case nct6798:
++ data->temp_label = nct6798_temp_label;
++ data->temp_mask = NCT6798_TEMP_MASK;
++ data->virt_temp_mask = NCT6798_VIRT_TEMP_MASK;
++ break;
++ case nct6799:
++ data->temp_label = nct6799_temp_label;
++ data->temp_mask = NCT6799_TEMP_MASK;
++ data->virt_temp_mask = NCT6799_VIRT_TEMP_MASK;
++ break;
++ }
++
++ data->REG_CONFIG = NCT6775_REG_CONFIG;
++ data->REG_VBAT = NCT6775_REG_VBAT;
++ data->REG_DIODE = NCT6775_REG_DIODE;
++ data->DIODE_MASK = NCT6775_DIODE_MASK;
++ data->REG_VIN = NCT6779_REG_IN;
++ data->REG_IN_MINMAX[0] = NCT6775_REG_IN_MIN;
++ data->REG_IN_MINMAX[1] = NCT6775_REG_IN_MAX;
++ data->REG_TARGET = NCT6775_REG_TARGET;
++ data->REG_FAN = NCT6779_REG_FAN;
++ data->REG_FAN_MODE = NCT6775_REG_FAN_MODE;
++ data->REG_FAN_MIN = NCT6776_REG_FAN_MIN;
++ data->REG_FAN_PULSES = NCT6779_REG_FAN_PULSES;
++ data->FAN_PULSE_SHIFT = NCT6775_FAN_PULSE_SHIFT;
++ data->REG_FAN_TIME[0] = NCT6775_REG_FAN_STOP_TIME;
++ data->REG_FAN_TIME[1] = NCT6776_REG_FAN_STEP_UP_TIME;
++ data->REG_FAN_TIME[2] = NCT6776_REG_FAN_STEP_DOWN_TIME;
++ data->REG_TOLERANCE_H = NCT6776_REG_TOLERANCE_H;
++ data->REG_PWM[0] = NCT6775_REG_PWM;
++ data->REG_PWM[1] = NCT6775_REG_FAN_START_OUTPUT;
++ data->REG_PWM[2] = NCT6775_REG_FAN_STOP_OUTPUT;
++ data->REG_PWM[5] = NCT6791_REG_WEIGHT_DUTY_STEP;
++ data->REG_PWM[6] = NCT6791_REG_WEIGHT_DUTY_BASE;
++ data->REG_PWM_READ = NCT6775_REG_PWM_READ;
++ data->REG_PWM_MODE = NCT6776_REG_PWM_MODE;
++ data->PWM_MODE_MASK = NCT6776_PWM_MODE_MASK;
++ data->REG_AUTO_TEMP = NCT6775_REG_AUTO_TEMP;
++ data->REG_AUTO_PWM = NCT6775_REG_AUTO_PWM;
++ data->REG_CRITICAL_TEMP = NCT6775_REG_CRITICAL_TEMP;
++ data->REG_CRITICAL_TEMP_TOLERANCE = NCT6775_REG_CRITICAL_TEMP_TOLERANCE;
++ data->REG_CRITICAL_PWM_ENABLE = NCT6779_REG_CRITICAL_PWM_ENABLE;
++ data->CRITICAL_PWM_ENABLE_MASK = NCT6779_CRITICAL_PWM_ENABLE_MASK;
++ data->REG_CRITICAL_PWM = NCT6779_REG_CRITICAL_PWM;
++ data->REG_TEMP_OFFSET = NCT6779_REG_TEMP_OFFSET;
++ data->REG_TEMP_SOURCE = NCT6798_REG_TEMP_SOURCE;
++ data->REG_TEMP_SEL = NCT6775_REG_TEMP_SEL;
++ data->REG_WEIGHT_TEMP_SEL = NCT6791_REG_WEIGHT_TEMP_SEL;
++ data->REG_WEIGHT_TEMP[0] = NCT6791_REG_WEIGHT_TEMP_STEP;
++ data->REG_WEIGHT_TEMP[1] = NCT6791_REG_WEIGHT_TEMP_STEP_TOL;
++ data->REG_WEIGHT_TEMP[2] = NCT6791_REG_WEIGHT_TEMP_BASE;
++ data->REG_ALARM = NCT6799_REG_ALARM;
++ data->REG_BEEP = NCT6792_REG_BEEP;
++ data->REG_TSI_TEMP = NCT6796_REG_TSI_TEMP;
++ num_reg_tsi_temp = ARRAY_SIZE(NCT6796_REG_TSI_TEMP);
++
++ reg_temp = NCT6798_REG_TEMP;
++ num_reg_temp = ARRAY_SIZE(NCT6798_REG_TEMP);
++ reg_temp_mon = NCT6798_REG_TEMP_MON;
++ num_reg_temp_mon = ARRAY_SIZE(NCT6798_REG_TEMP_MON);
++ reg_temp_over = NCT6798_REG_TEMP_OVER;
++ reg_temp_hyst = NCT6798_REG_TEMP_HYST;
++ reg_temp_config = NCT6779_REG_TEMP_CONFIG;
++ num_reg_temp_config = ARRAY_SIZE(NCT6779_REG_TEMP_CONFIG);
++ reg_temp_alternate = NCT6798_REG_TEMP_ALTERNATE;
++ reg_temp_crit = NCT6798_REG_TEMP_CRIT;
++
+ break;
+ default:
+ return -ENODEV;
+@@ -4029,7 +4208,8 @@ int nct6775_probe(struct device *dev, struct nct6775_data *data,
+ = reg_temp_crit[src - 1];
+ if (reg_temp_crit_l && reg_temp_crit_l[i])
+ data->reg_temp[4][src - 1] = reg_temp_crit_l[i];
+- data->reg_temp_config[src - 1] = reg_temp_config[i];
++ if (i < num_reg_temp_config)
++ data->reg_temp_config[src - 1] = reg_temp_config[i];
+ data->temp_src[src - 1] = src;
+ continue;
+ }
+@@ -4042,7 +4222,8 @@ int nct6775_probe(struct device *dev, struct nct6775_data *data,
+ data->reg_temp[0][s] = reg_temp[i];
+ data->reg_temp[1][s] = reg_temp_over[i];
+ data->reg_temp[2][s] = reg_temp_hyst[i];
+- data->reg_temp_config[s] = reg_temp_config[i];
++ if (i < num_reg_temp_config)
++ data->reg_temp_config[s] = reg_temp_config[i];
+ if (reg_temp_crit_h && reg_temp_crit_h[i])
+ data->reg_temp[3][s] = reg_temp_crit_h[i];
+ else if (reg_temp_crit[src - 1])
+diff --git a/drivers/hwmon/nct6775-i2c.c b/drivers/hwmon/nct6775-i2c.c
+index e1bcd114619131..779ce65db1a152 100644
+--- a/drivers/hwmon/nct6775-i2c.c
++++ b/drivers/hwmon/nct6775-i2c.c
+@@ -87,6 +87,7 @@ static const struct of_device_id __maybe_unused nct6775_i2c_of_match[] = {
+ { .compatible = "nuvoton,nct6796", .data = (void *)nct6796, },
+ { .compatible = "nuvoton,nct6797", .data = (void *)nct6797, },
+ { .compatible = "nuvoton,nct6798", .data = (void *)nct6798, },
++ { .compatible = "nuvoton,nct6799", .data = (void *)nct6799, },
+ { },
+ };
+ MODULE_DEVICE_TABLE(of, nct6775_i2c_of_match);
+@@ -104,6 +105,7 @@ static const struct i2c_device_id nct6775_i2c_id[] = {
+ { "nct6796", nct6796 },
+ { "nct6797", nct6797 },
+ { "nct6798", nct6798 },
++ { "nct6799", nct6799 },
+ { }
+ };
+ MODULE_DEVICE_TABLE(i2c, nct6775_i2c_id);
+diff --git a/drivers/hwmon/nct6775-platform.c b/drivers/hwmon/nct6775-platform.c
+index 76c6b564d7fc46..f43cb418c03382 100644
+--- a/drivers/hwmon/nct6775-platform.c
++++ b/drivers/hwmon/nct6775-platform.c
+@@ -35,6 +35,7 @@ static const char * const nct6775_sio_names[] __initconst = {
+ "NCT6796D",
+ "NCT6797D",
+ "NCT6798D",
++ "NCT6799D",
+ };
+
+ static unsigned short force_id;
+@@ -85,6 +86,7 @@ MODULE_PARM_DESC(fan_debounce, "Enable debouncing for fan RPM signal");
+ #define SIO_NCT6796_ID 0xd420
+ #define SIO_NCT6797_ID 0xd450
+ #define SIO_NCT6798_ID 0xd428
++#define SIO_NCT6799_ID 0xd800
+ #define SIO_ID_MASK 0xFFF8
+
+ /*
+@@ -418,7 +420,7 @@ static int nct6775_resume(struct device *dev)
+ if (data->kind == nct6791 || data->kind == nct6792 ||
+ data->kind == nct6793 || data->kind == nct6795 ||
+ data->kind == nct6796 || data->kind == nct6797 ||
+- data->kind == nct6798)
++ data->kind == nct6798 || data->kind == nct6799)
+ nct6791_enable_io_mapping(sio_data);
+
+ sio_data->sio_exit(sio_data);
+@@ -565,7 +567,7 @@ nct6775_check_fan_inputs(struct nct6775_data *data, struct nct6775_sio_data *sio
+ } else {
+ /*
+ * NCT6779D, NCT6791D, NCT6792D, NCT6793D, NCT6795D, NCT6796D,
+- * NCT6797D, NCT6798D
++ * NCT6797D, NCT6798D, NCT6799D
+ */
+ int cr1a = sio_data->sio_inb(sio_data, 0x1a);
+ int cr1b = sio_data->sio_inb(sio_data, 0x1b);
+@@ -575,12 +577,17 @@ nct6775_check_fan_inputs(struct nct6775_data *data, struct nct6775_sio_data *sio
+ int cr2b = sio_data->sio_inb(sio_data, 0x2b);
+ int cr2d = sio_data->sio_inb(sio_data, 0x2d);
+ int cr2f = sio_data->sio_inb(sio_data, 0x2f);
++ bool vsb_ctl_en = cr2f & BIT(0);
+ bool dsw_en = cr2f & BIT(3);
+ bool ddr4_en = cr2f & BIT(4);
++ bool as_seq1_en = cr2f & BIT(7);
+ int cre0;
++ int cre6;
+ int creb;
+ int cred;
+
++ cre6 = sio_data->sio_inb(sio_data, 0xe6);
++
+ sio_data->sio_select(sio_data, NCT6775_LD_12);
+ cre0 = sio_data->sio_inb(sio_data, 0xe0);
+ creb = sio_data->sio_inb(sio_data, 0xeb);
+@@ -683,6 +690,29 @@ nct6775_check_fan_inputs(struct nct6775_data *data, struct nct6775_sio_data *sio
+ pwm7pin = !(cr1d & (BIT(2) | BIT(3)));
+ pwm7pin |= cr2d & BIT(7);
+ pwm7pin |= creb & BIT(2);
++ break;
++ case nct6799:
++ fan4pin = cr1c & BIT(6);
++ fan5pin = cr1c & BIT(7);
++
++ fan6pin = !(cr1b & BIT(0)) && (cre0 & BIT(3));
++ fan6pin |= cre6 & BIT(5);
++ fan6pin |= creb & BIT(5);
++ fan6pin |= !as_seq1_en && (cr2a & BIT(4));
++
++ fan7pin = cr1b & BIT(5);
++ fan7pin |= !vsb_ctl_en && !(cr2b & BIT(2));
++ fan7pin |= creb & BIT(3);
++
++ pwm6pin = !(cr1b & BIT(0)) && (cre0 & BIT(4));
++ pwm6pin |= !as_seq1_en && !(cred & BIT(2)) && (cr2a & BIT(3));
++ pwm6pin |= (creb & BIT(4)) && !(cr2a & BIT(0));
++ pwm6pin |= cre6 & BIT(3);
++
++ pwm7pin = !vsb_ctl_en && !(cr1d & (BIT(2) | BIT(3)));
++ pwm7pin |= creb & BIT(2);
++ pwm7pin |= cr2d & BIT(7);
++
+ break;
+ default: /* NCT6779D */
+ break;
+@@ -838,6 +868,7 @@ static int nct6775_platform_probe_init(struct nct6775_data *data)
+ case nct6796:
+ case nct6797:
+ case nct6798:
++ case nct6799:
+ break;
+ }
+
+@@ -876,6 +907,7 @@ static int nct6775_platform_probe_init(struct nct6775_data *data)
+ case nct6796:
+ case nct6797:
+ case nct6798:
++ case nct6799:
+ tmp |= 0x7e;
+ break;
+ }
+@@ -1005,6 +1037,9 @@ static int __init nct6775_find(int sioaddr, struct nct6775_sio_data *sio_data)
+ case SIO_NCT6798_ID:
+ sio_data->kind = nct6798;
+ break;
++ case SIO_NCT6799_ID:
++ sio_data->kind = nct6799;
++ break;
+ default:
+ if (val != 0xffff)
+ pr_debug("unsupported chip ID: 0x%04x\n", val);
+@@ -1033,7 +1068,7 @@ static int __init nct6775_find(int sioaddr, struct nct6775_sio_data *sio_data)
+ if (sio_data->kind == nct6791 || sio_data->kind == nct6792 ||
+ sio_data->kind == nct6793 || sio_data->kind == nct6795 ||
+ sio_data->kind == nct6796 || sio_data->kind == nct6797 ||
+- sio_data->kind == nct6798)
++ sio_data->kind == nct6798 || sio_data->kind == nct6799)
+ nct6791_enable_io_mapping(sio_data);
+
+ sio_data->sio_exit(sio_data);
+diff --git a/drivers/hwmon/nct6775.h b/drivers/hwmon/nct6775.h
+index be41848c3cd29f..296eff99d00383 100644
+--- a/drivers/hwmon/nct6775.h
++++ b/drivers/hwmon/nct6775.h
+@@ -5,10 +5,10 @@
+ #include <linux/types.h>
+
+ enum kinds { nct6106, nct6116, nct6775, nct6776, nct6779, nct6791, nct6792,
+- nct6793, nct6795, nct6796, nct6797, nct6798 };
++ nct6793, nct6795, nct6796, nct6797, nct6798, nct6799 };
+ enum pwm_enable { off, manual, thermal_cruise, speed_cruise, sf3, sf4 };
+
+-#define NUM_TEMP 10 /* Max number of temp attribute sets w/ limits*/
++#define NUM_TEMP 12 /* Max number of temp attribute sets w/ limits*/
+ #define NUM_TEMP_FIXED 6 /* Max number of fixed temp attribute sets */
+ #define NUM_TSI_TEMP 8 /* Max number of TSI temp register pairs */
+
+@@ -16,6 +16,7 @@ enum pwm_enable { off, manual, thermal_cruise, speed_cruise, sf3, sf4 };
+ #define NUM_REG_BEEP 5 /* Max number of beep registers */
+
+ #define NUM_FAN 7
++#define NUM_IN 18
+
+ struct nct6775_data {
+ int addr; /* IO base of hw monitor block */
+@@ -97,7 +98,8 @@ struct nct6775_data {
+ /* Register values */
+ u8 bank; /* current register bank */
+ u8 in_num; /* number of in inputs we have */
+- u8 in[15][3]; /* [0]=in, [1]=in_max, [2]=in_min */
++ u8 in[NUM_IN][3]; /* [0]=in, [1]=in_max, [2]=in_min */
++ const u16 *scale_in; /* internal scaling factors */
+ unsigned int rpm[NUM_FAN];
+ u16 fan_min[NUM_FAN];
+ u8 fan_pulses[NUM_FAN];
+@@ -165,7 +167,7 @@ struct nct6775_data {
+ u16 have_temp;
+ u16 have_temp_fixed;
+ u16 have_tsi_temp;
+- u16 have_in;
++ u32 have_in;
+
+ /* Remember extra register values over suspend/resume */
+ u8 vbat;
+@@ -238,10 +240,25 @@ nct6775_add_attr_group(struct nct6775_data *data, const struct attribute_group *
+
+ #define NCT6791_REG_HM_IO_SPACE_LOCK_ENABLE 0x28
+
+-#define FAN_ALARM_BASE 16
+-#define TEMP_ALARM_BASE 24
+-#define INTRUSION_ALARM_BASE 30
+-#define BEEP_ENABLE_BASE 15
++/*
++ * ALARM_BITS and BEEP_BITS store bit-index for the mask of the registers
++ * loaded into data->alarm and data->beep.
++ *
++ * Every input register (IN/TEMP/FAN) must have a corresponding
++ * ALARM/BEEP bit at the same index BITS[BASE + index]
++ * Set value to -1 to disable the visibility of that '*_alarm' attribute and
++ * to pad the bits until the next BASE
++ *
++ * Beep has an additional GLOBAL_BEEP_ENABLE bit
++ */
++#define VIN_ALARM_BASE 0
++#define FAN_ALARM_BASE 24
++#define TEMP_ALARM_BASE 36
++#define INTRUSION_ALARM_BASE 48
++#define BEEP_ENABLE_BASE 50
++
++#define NUM_ALARM_BITS (INTRUSION_ALARM_BASE + 4)
++#define NUM_BEEP_BITS (BEEP_ENABLE_BASE + 1)
+
+ /*
+ * Not currently used:
+diff --git a/drivers/hwmon/npcm750-pwm-fan.c b/drivers/hwmon/npcm750-pwm-fan.c
+index 11a28609da3c76..aa81ea308f80bf 100644
+--- a/drivers/hwmon/npcm750-pwm-fan.c
++++ b/drivers/hwmon/npcm750-pwm-fan.c
+@@ -360,6 +360,11 @@ static void npcm7xx_fan_polling(struct timer_list *t)
+ add_timer(&data->fan_timer);
+ }
+
++static void npcm7xx_fan_cleanup(void *timer)
++{
++ timer_shutdown_sync(timer);
++}
++
+ static inline void npcm7xx_fan_compute(struct npcm7xx_pwm_fan_data *data,
+ u8 fan, u8 cmp, u8 fan_id, u8 flag_int,
+ u8 flag_mode, u8 flag_clear)
+@@ -1003,6 +1008,12 @@ static int npcm7xx_pwm_fan_probe(struct platform_device *pdev)
+ msecs_to_jiffies(NPCM7XX_FAN_POLL_TIMER_200MS);
+ timer_setup(&data->fan_timer,
+ npcm7xx_fan_polling, 0);
++ ret = devm_add_action_or_reset(dev,
++ npcm7xx_fan_cleanup,
++ &data->fan_timer);
++ if (ret)
++ return ret;
++
+ add_timer(&data->fan_timer);
+ break;
+ }
+diff --git a/drivers/hwmon/nzxt-smart2.c b/drivers/hwmon/nzxt-smart2.c
+index a8e72d8fd06050..9f30ec0883fbc6 100644
+--- a/drivers/hwmon/nzxt-smart2.c
++++ b/drivers/hwmon/nzxt-smart2.c
+@@ -203,7 +203,7 @@ struct drvdata {
+ */
+ struct mutex mutex;
+ long update_interval;
+- u8 output_buffer[OUTPUT_REPORT_SIZE];
++ u8 output_buffer[OUTPUT_REPORT_SIZE] __aligned(ARCH_DMA_MINALIGN);
+ };
+
+ static long scale_pwm_value(long val, long orig_max, long new_max)
+@@ -754,7 +754,11 @@ static int nzxt_smart2_hid_probe(struct hid_device *hdev,
+
+ hid_device_io_start(hdev);
+
+- init_device(drvdata, UPDATE_INTERVAL_DEFAULT_MS);
++ ret = init_device(drvdata, UPDATE_INTERVAL_DEFAULT_MS);
++ if (ret) {
++ dev_err(&hdev->dev, "init_device failed: %d\n", ret);
++ goto out_hw_close;
++ }
+
+ drvdata->hwmon =
+ hwmon_device_register_with_info(&hdev->dev, "nzxtsmart2", drvdata,
+@@ -768,7 +772,7 @@ static int nzxt_smart2_hid_probe(struct hid_device *hdev,
+
+ out_hw_close:
+ hid_hw_close(hdev);
+-
++ hid_device_io_stop(hdev);
+ out_hw_stop:
+ hid_hw_stop(hdev);
+ return ret;
+diff --git a/drivers/hwmon/occ/common.c b/drivers/hwmon/occ/common.c
+index c92d08e9827ac5..d0c8a043445a25 100644
+--- a/drivers/hwmon/occ/common.c
++++ b/drivers/hwmon/occ/common.c
+@@ -1052,32 +1052,49 @@ static int occ_setup_sensor_attrs(struct occ *occ)
+ }
+
+ /* only need to do this once at startup, as OCC won't change sensors on us */
+-static void occ_parse_poll_response(struct occ *occ)
++static int occ_parse_poll_response(struct occ *occ)
+ {
+ unsigned int i, old_offset, offset = 0, size = 0;
++ u16 data_length;
+ struct occ_sensor *sensor;
+- struct occ_sensors *sensors = &occ->sensors;
++ struct occ_sensors parsed = {};
++ struct occ_sensors *sensors = &parsed;
+ struct occ_response *resp = &occ->resp;
+ struct occ_poll_response *poll =
+ (struct occ_poll_response *)&resp->data[0];
+ struct occ_poll_response_header *header = &poll->header;
+ struct occ_sensor_data_block *block = &poll->block;
+
++ data_length = get_unaligned_be16(&resp->data_length);
++ if (data_length < sizeof(*header) || data_length > OCC_RESP_DATA_BYTES) {
++ dev_err(occ->bus_dev, "invalid OCC poll response length %u\n",
++ data_length);
++ return -EMSGSIZE;
++ }
++
+ dev_info(occ->bus_dev, "OCC found, code level: %.16s\n",
+ header->occ_code_level);
+
+ for (i = 0; i < header->num_sensor_data_blocks; ++i) {
+ block = (struct occ_sensor_data_block *)((u8 *)block + offset);
++ if (size + sizeof(*header) + sizeof(block->header) >
++ data_length) {
++ dev_err(occ->bus_dev,
++ "truncated OCC sensor block header\n");
++ return -EMSGSIZE;
++ }
++
+ old_offset = offset;
+ offset = (block->header.num_sensors *
+ block->header.sensor_length) + sizeof(block->header);
+- size += offset;
+
+ /* validate all the length/size fields */
+- if ((size + sizeof(*header)) >= OCC_RESP_DATA_BYTES) {
+- dev_warn(occ->bus_dev, "exceeded response buffer\n");
+- return;
++ if (size + sizeof(*header) + offset > data_length) {
++ dev_err(occ->bus_dev,
++ "exceeded OCC poll response length\n");
++ return -EMSGSIZE;
+ }
++ size += offset;
+
+ dev_dbg(occ->bus_dev, " %04x..%04x: %.4s (%d sensors)\n",
+ old_offset, offset - 1, block->header.eye_catcher,
+@@ -1107,6 +1124,9 @@ static void occ_parse_poll_response(struct occ *occ)
+
+ dev_dbg(occ->bus_dev, "Max resp size: %u+%zd=%zd\n", size,
+ sizeof(*header), size + sizeof(*header));
++ occ->sensors = parsed;
++
++ return 0;
+ }
+
+ int occ_active(struct occ *occ, bool active)
+@@ -1138,10 +1158,12 @@ int occ_active(struct occ *occ, bool active)
+ goto unlock;
+ }
+
+- occ->active = true;
+ occ->next_update = jiffies + OCC_UPDATE_FREQUENCY;
+- occ_parse_poll_response(occ);
++ rc = occ_parse_poll_response(occ);
++ if (rc)
++ goto unlock;
+
++ occ->active = true;
+ rc = occ_setup_sensor_attrs(occ);
+ if (rc) {
+ dev_err(occ->bus_dev,
+diff --git a/drivers/hwmon/pmbus/lm25066.c b/drivers/hwmon/pmbus/lm25066.c
+index 09792cd03d9fde..8fef24a25d7283 100644
+--- a/drivers/hwmon/pmbus/lm25066.c
++++ b/drivers/hwmon/pmbus/lm25066.c
+@@ -14,10 +14,11 @@
+ #include <linux/slab.h>
+ #include <linux/i2c.h>
+ #include <linux/log2.h>
+-#include <linux/of_device.h>
++#include <linux/math.h>
++#include <linux/of.h>
+ #include "pmbus.h"
+
+-enum chips { lm25056, lm25066, lm5064, lm5066, lm5066i };
++enum chips { lm25056 = 1, lm25066, lm5064, lm5066, lm5066i };
+
+ #define LM25066_READ_VAUX 0xd0
+ #define LM25066_MFR_READ_IIN 0xd1
+@@ -468,8 +469,6 @@ static int lm25066_probe(struct i2c_client *client)
+ struct lm25066_data *data;
+ struct pmbus_driver_info *info;
+ const struct __coeff *coeff;
+- const struct of_device_id *of_id;
+- const struct i2c_device_id *i2c_id;
+
+ if (!i2c_check_functionality(client->adapter,
+ I2C_FUNC_SMBUS_READ_BYTE_DATA))
+@@ -484,14 +483,8 @@ static int lm25066_probe(struct i2c_client *client)
+ if (config < 0)
+ return config;
+
+- i2c_id = i2c_match_id(lm25066_id, client);
++ data->id = (enum chips)(unsigned long)i2c_get_match_data(client);
+
+- of_id = of_match_device(lm25066_of_match, &client->dev);
+- if (of_id && (unsigned long)of_id->data != i2c_id->driver_data)
+- dev_notice(&client->dev, "Device mismatch: %s in device tree, %s detected\n",
+- of_id->name, i2c_id->name);
+-
+- data->id = i2c_id->driver_data;
+ info = &data->info;
+
+ info->pages = 1;
+@@ -548,8 +541,8 @@ static int lm25066_probe(struct i2c_client *client)
+ if (of_property_read_u32(client->dev.of_node, "shunt-resistor-micro-ohms", &shunt))
+ shunt = 1000;
+
+- info->m[PSC_CURRENT_IN] = info->m[PSC_CURRENT_IN] * shunt / 1000;
+- info->m[PSC_POWER] = info->m[PSC_POWER] * shunt / 1000;
++ info->m[PSC_CURRENT_IN] = DIV_ROUND_CLOSEST_ULL((u64)info->m[PSC_CURRENT_IN] * shunt, 1000);
++ info->m[PSC_POWER] = DIV_ROUND_CLOSEST_ULL((u64)info->m[PSC_POWER] * shunt, 1000);
+
+ #if IS_ENABLED(CONFIG_SENSORS_LM25066_REGULATOR)
+ /* LM25056 doesn't support OPERATION */
+diff --git a/drivers/hwmon/pmbus/pmbus_core.c b/drivers/hwmon/pmbus/pmbus_core.c
+index 1715fafc4152fb..d69fd8ca66eb5b 100644
+--- a/drivers/hwmon/pmbus/pmbus_core.c
++++ b/drivers/hwmon/pmbus/pmbus_core.c
+@@ -442,7 +442,7 @@ int pmbus_update_byte_data(struct i2c_client *client, int page, u8 reg,
+ if (tmp != rv)
+ rv = _pmbus_write_byte_data(client, page, reg, tmp);
+
+- return rv;
++ return rv < 0 ? rv : 0;
+ }
+ EXPORT_SYMBOL_NS_GPL(pmbus_update_byte_data, PMBUS);
+
+diff --git a/drivers/hwtracing/intel_th/core.c b/drivers/hwtracing/intel_th/core.c
+index 4efd64a6755ff6..ee8082ebb3ccb1 100644
+--- a/drivers/hwtracing/intel_th/core.c
++++ b/drivers/hwtracing/intel_th/core.c
+@@ -843,18 +843,8 @@ out_put_device:
+ return err;
+ }
+
+-static int intel_th_output_release(struct inode *inode, struct file *file)
+-{
+- struct intel_th_device *thdev = file->private_data;
+-
+- put_device(&thdev->dev);
+-
+- return 0;
+-}
+-
+ static const struct file_operations intel_th_output_fops = {
+ .open = intel_th_output_open,
+- .release = intel_th_output_release,
+ .llseek = noop_llseek,
+ };
+
+diff --git a/drivers/hwtracing/intel_th/msu.c b/drivers/hwtracing/intel_th/msu.c
+index 6c8215a47a6011..7b51830c45f9c6 100644
+--- a/drivers/hwtracing/intel_th/msu.c
++++ b/drivers/hwtracing/intel_th/msu.c
+@@ -1477,8 +1477,10 @@ static int intel_th_msc_release(struct inode *inode, struct file *file)
+ {
+ struct msc_iter *iter = file->private_data;
+ struct msc *msc = iter->msc;
++ struct intel_th_device *thdev = msc->thdev;
+
+ msc_iter_remove(iter, msc);
++ put_device(&thdev->dev);
+
+ return 0;
+ }
+diff --git a/drivers/i2c/busses/i2c-amd-mp2-plat.c b/drivers/i2c/busses/i2c-amd-mp2-plat.c
+index 423fe0c8a471e0..f5e2599c5482fc 100644
+--- a/drivers/i2c/busses/i2c-amd-mp2-plat.c
++++ b/drivers/i2c/busses/i2c-amd-mp2-plat.c
+@@ -316,8 +316,10 @@ static int i2c_amd_probe(struct platform_device *pdev)
+
+ amd_mp2_pm_runtime_put(mp2_dev);
+
+- if (ret < 0)
++ if (ret < 0) {
+ dev_err(&pdev->dev, "i2c add adapter failed = %d\n", ret);
++ amd_mp2_unregister_cb(&i2c_dev->common);
++ }
+
+ return ret;
+ }
+diff --git a/drivers/i2c/busses/i2c-imx.c b/drivers/i2c/busses/i2c-imx.c
+index 76d5b80abfc700..b1938c2d58498f 100644
+--- a/drivers/i2c/busses/i2c-imx.c
++++ b/drivers/i2c/busses/i2c-imx.c
+@@ -871,9 +871,6 @@ static int i2c_imx_reg_slave(struct i2c_client *client)
+ if (i2c_imx->slave)
+ return -EBUSY;
+
+- i2c_imx->slave = client;
+- i2c_imx->last_slave_event = I2C_SLAVE_STOP;
+-
+ /* Resume */
+ ret = pm_runtime_resume_and_get(i2c_imx->adapter.dev.parent);
+ if (ret < 0) {
+@@ -881,6 +878,11 @@ static int i2c_imx_reg_slave(struct i2c_client *client)
+ return ret;
+ }
+
++ scoped_guard(spinlock_irqsave, &i2c_imx->slave_lock) {
++ i2c_imx->slave = client;
++ i2c_imx->last_slave_event = I2C_SLAVE_STOP;
++ }
++
+ i2c_imx_slave_init(i2c_imx);
+
+ return 0;
+@@ -899,6 +901,7 @@ static int i2c_imx_unreg_slave(struct i2c_client *client)
+
+ i2c_imx_reset_regs(i2c_imx);
+
++ hrtimer_cancel(&i2c_imx->slave_timer);
+ i2c_imx->slave = NULL;
+
+ /* Suspend */
+diff --git a/drivers/i2c/busses/i2c-jz4780.c b/drivers/i2c/busses/i2c-jz4780.c
+index baa7319eee5397..09c7066d0fb2f4 100644
+--- a/drivers/i2c/busses/i2c-jz4780.c
++++ b/drivers/i2c/busses/i2c-jz4780.c
+@@ -141,6 +141,7 @@ struct jz4780_i2c {
+ void __iomem *iomem;
+ int irq;
+ struct clk *clk;
++ unsigned long clk_rate_khz;
+ struct i2c_adapter adap;
+ const struct ingenic_i2c_config *cdata;
+
+@@ -246,7 +247,7 @@ static int jz4780_i2c_set_target(struct jz4780_i2c *i2c, unsigned char address)
+
+ static int jz4780_i2c_set_speed(struct jz4780_i2c *i2c)
+ {
+- int dev_clk_khz = clk_get_rate(i2c->clk) / 1000;
++ int dev_clk_khz = i2c->clk_rate_khz;
+ int cnt_high = 0; /* HIGH period count of the SCL clock */
+ int cnt_low = 0; /* LOW period count of the SCL clock */
+ int cnt_period = 0; /* period count of the SCL clock */
+@@ -800,6 +801,8 @@ static int jz4780_i2c_probe(struct platform_device *pdev)
+ if (ret)
+ return ret;
+
++ i2c->clk_rate_khz = clk_get_rate(i2c->clk) / 1000;
++
+ ret = of_property_read_u32(pdev->dev.of_node, "clock-frequency",
+ &clk_freq);
+ if (ret) {
+diff --git a/drivers/infiniband/core/addr.c b/drivers/infiniband/core/addr.c
+index 3e87e92e9993e1..579fd879716dcc 100644
+--- a/drivers/infiniband/core/addr.c
++++ b/drivers/infiniband/core/addr.c
+@@ -338,15 +338,15 @@ static int dst_fetch_ha(const struct dst_entry *dst,
+
+ static bool has_gateway(const struct dst_entry *dst, sa_family_t family)
+ {
+- struct rtable *rt;
+- struct rt6_info *rt6;
++ const struct rtable *rt;
++ const struct rt6_info *rt6;
+
+ if (family == AF_INET) {
+ rt = container_of(dst, struct rtable, dst);
+ return rt->rt_uses_gateway;
+ }
+
+- rt6 = container_of(dst, struct rt6_info, dst);
++ rt6 = dst_rt6_info(dst);
+ return rt6->rt6i_flags & RTF_GATEWAY;
+ }
+
+diff --git a/drivers/infiniband/core/cma.c b/drivers/infiniband/core/cma.c
+index b5924919e7f06f..e7827352409026 100644
+--- a/drivers/infiniband/core/cma.c
++++ b/drivers/infiniband/core/cma.c
+@@ -5190,7 +5190,7 @@ static int cma_netevent_callback(struct notifier_block *self,
+
+ list_for_each_entry(current_id, &ips_node->id_list, id_list_entry) {
+ if (!memcmp(current_id->id.route.addr.dev_addr.dst_dev_addr,
+- neigh->ha, ETH_ALEN))
++ neigh->ha, neigh->dev->addr_len))
+ continue;
+ cma_id_get(current_id);
+ if (!queue_work(cma_wq, ¤t_id->id.net_work))
+diff --git a/drivers/infiniband/core/mad.c b/drivers/infiniband/core/mad.c
+index 242434c09e8d8f..bddb1c607aff62 100644
+--- a/drivers/infiniband/core/mad.c
++++ b/drivers/infiniband/core/mad.c
+@@ -1778,6 +1778,24 @@ void ib_mark_mad_done(struct ib_mad_send_wr_private *mad_send_wr)
+ &mad_send_wr->mad_agent_priv->done_list);
+ }
+
++static bool is_kernel_rmpp_data_response(struct ib_mad_agent_private *agent,
++ struct ib_mad_recv_wc *mad_recv_wc)
++{
++ const struct ib_mad_hdr *mad_hdr = &mad_recv_wc->recv_buf.mad->mad_hdr;
++ struct ib_rmpp_mad *rmpp_mad;
++
++ if (!ib_mad_kernel_rmpp_agent(&agent->agent) ||
++ !ib_response_mad(mad_hdr) ||
++ !ib_is_mad_class_rmpp(mad_hdr->mgmt_class))
++ return false;
++
++ rmpp_mad = (struct ib_rmpp_mad *)mad_recv_wc->recv_buf.mad;
++
++ return (ib_get_rmpp_flags(&rmpp_mad->rmpp_hdr) &
++ IB_MGMT_RMPP_FLAG_ACTIVE) &&
++ rmpp_mad->rmpp_hdr.rmpp_type == IB_MGMT_RMPP_TYPE_DATA;
++}
++
+ static void ib_mad_complete_recv(struct ib_mad_agent_private *mad_agent_priv,
+ struct ib_mad_recv_wc *mad_recv_wc)
+ {
+@@ -1796,6 +1814,18 @@ static void ib_mad_complete_recv(struct ib_mad_agent_private *mad_agent_priv,
+ }
+
+ list_add(&mad_recv_wc->recv_buf.list, &mad_recv_wc->rmpp_list);
++ if (is_kernel_rmpp_data_response(mad_agent_priv, mad_recv_wc)) {
++ spin_lock_irqsave(&mad_agent_priv->lock, flags);
++ mad_send_wr = ib_find_send_mad(mad_agent_priv, mad_recv_wc);
++ spin_unlock_irqrestore(&mad_agent_priv->lock, flags);
++
++ if (!mad_send_wr) {
++ ib_free_recv_mad(mad_recv_wc);
++ deref_mad_agent(mad_agent_priv);
++ return;
++ }
++ }
++
+ if (ib_mad_kernel_rmpp_agent(&mad_agent_priv->agent)) {
+ mad_recv_wc = ib_process_rmpp_recv_wc(mad_agent_priv,
+ mad_recv_wc);
+diff --git a/drivers/infiniband/hw/erdma/erdma_qp.c b/drivers/infiniband/hw/erdma/erdma_qp.c
+index e3b0baa703e681..74cb47ab827e14 100644
+--- a/drivers/infiniband/hw/erdma/erdma_qp.c
++++ b/drivers/infiniband/hw/erdma/erdma_qp.c
+@@ -537,7 +537,7 @@ int erdma_post_recv(struct ib_qp *ibqp, const struct ib_recv_wr *recv_wr,
+ const struct ib_recv_wr *wr = recv_wr;
+ struct erdma_qp *qp = to_eqp(ibqp);
+ unsigned long flags;
+- int ret;
++ int ret = 0;
+
+ spin_lock_irqsave(&qp->lock, flags);
+
+diff --git a/drivers/infiniband/hw/hns/hns_roce_hem.c b/drivers/infiniband/hw/hns/hns_roce_hem.c
+index 862acdf59867a9..ce115dbba13020 100644
+--- a/drivers/infiniband/hw/hns/hns_roce_hem.c
++++ b/drivers/infiniband/hw/hns/hns_roce_hem.c
+@@ -907,7 +907,7 @@ static void hns_roce_cleanup_mhop_hem_table(struct hns_roce_dev *hr_dev,
+ mhop.bt_chunk_size;
+
+ for (i = 0; i < table->num_hem; ++i) {
+- obj = i * buf_chunk_size / table->obj_size;
++ obj = (u64)i * buf_chunk_size / table->obj_size;
+ if (table->hem[i])
+ hns_roce_table_mhop_put(hr_dev, table, obj, 0);
+ }
+diff --git a/drivers/infiniband/hw/irdma/verbs.c b/drivers/infiniband/hw/irdma/verbs.c
+index b43ce455050c66..56e3103aa77f91 100644
+--- a/drivers/infiniband/hw/irdma/verbs.c
++++ b/drivers/infiniband/hw/irdma/verbs.c
+@@ -2336,7 +2336,7 @@ static bool irdma_check_mem_contiguous(u64 *arr, u32 npages, u32 pg_size)
+ u32 pg_idx;
+
+ for (pg_idx = 0; pg_idx < npages; pg_idx++) {
+- if ((*arr + (pg_size * pg_idx)) != arr[pg_idx])
++ if ((*arr + ((u64)pg_size * pg_idx)) != arr[pg_idx])
+ return false;
+ }
+
+@@ -2369,7 +2369,7 @@ static bool irdma_check_mr_contiguous(struct irdma_pble_alloc *palloc,
+
+ for (i = 0; i < lvl2->leaf_cnt; i++, leaf++) {
+ arr = leaf->addr;
+- if ((*start_addr + (i * pg_size * PBLE_PER_PAGE)) != *arr)
++ if ((*start_addr + ((u64)i * pg_size * PBLE_PER_PAGE)) != *arr)
+ return false;
+ ret = irdma_check_mem_contiguous(arr, leaf->cnt, pg_size);
+ if (!ret)
+diff --git a/drivers/infiniband/sw/rxe/rxe_mmap.c b/drivers/infiniband/sw/rxe/rxe_mmap.c
+index 9149b609542960..2749ed48b014ad 100644
+--- a/drivers/infiniband/sw/rxe/rxe_mmap.c
++++ b/drivers/infiniband/sw/rxe/rxe_mmap.c
+@@ -93,18 +93,31 @@ int rxe_mmap(struct ib_ucontext *context, struct vm_area_struct *vma)
+ goto done;
+
+ found_it:
++ /*
++ * Increment refcount and check whether it is being freed atm while
++ * holding lock to prevent UAF
++ */
++ if (!kref_get_unless_zero(&ip->ref)) {
++ spin_unlock_bh(&rxe->pending_lock);
++ ret = -ENXIO;
++ goto done;
++ }
++
+ list_del_init(&ip->pending_mmaps);
+ spin_unlock_bh(&rxe->pending_lock);
+
++ vma->vm_ops = &rxe_vm_ops;
++ vma->vm_private_data = ip;
++
+ ret = remap_vmalloc_range(vma, ip->obj, 0);
+ if (ret) {
++ vma->vm_private_data = NULL;
++ vma->vm_ops = NULL;
++ kref_put(&ip->ref, rxe_mmap_release);
+ pr_err("err %d from remap_vmalloc_range\n", ret);
+ goto done;
+ }
+
+- vma->vm_ops = &rxe_vm_ops;
+- vma->vm_private_data = ip;
+- rxe_vma_open(vma);
+ done:
+ return ret;
+ }
+diff --git a/drivers/infiniband/sw/siw/siw_verbs.c b/drivers/infiniband/sw/siw/siw_verbs.c
+index dce86f5aee1f76..8e89e32435d455 100644
+--- a/drivers/infiniband/sw/siw/siw_verbs.c
++++ b/drivers/infiniband/sw/siw/siw_verbs.c
+@@ -302,6 +302,7 @@ int siw_create_qp(struct ib_qp *ibqp, struct ib_qp_init_attr *attrs,
+ struct siw_ucontext *uctx =
+ rdma_udata_to_drv_context(udata, struct siw_ucontext,
+ base_ucontext);
++ struct siw_uresp_create_qp uresp = {};
+ unsigned long flags;
+ int num_sqe, num_rqe, rv = 0;
+ size_t length;
+@@ -336,11 +337,10 @@ int siw_create_qp(struct ib_qp *ibqp, struct ib_qp_init_attr *attrs,
+ goto err_atomic;
+ }
+ /*
+- * NOTE: we allow for zero element SQ and RQ WQE's SGL's
+- * but not for a QP unable to hold any WQE (SQ + RQ)
++ * NOTE: we don't allow for a QP unable to hold any SQ WQE
+ */
+- if (attrs->cap.max_send_wr + attrs->cap.max_recv_wr == 0) {
+- siw_dbg(base_dev, "QP must have send or receive queue\n");
++ if (attrs->cap.max_send_wr == 0) {
++ siw_dbg(base_dev, "QP must have send queue\n");
+ rv = -EINVAL;
+ goto err_atomic;
+ }
+@@ -356,25 +356,13 @@ int siw_create_qp(struct ib_qp *ibqp, struct ib_qp_init_attr *attrs,
+ spin_lock_init(&qp->rq_lock);
+ spin_lock_init(&qp->orq_lock);
+
+- rv = siw_qp_add(sdev, qp);
+- if (rv)
+- goto err_atomic;
+-
+- num_sqe = attrs->cap.max_send_wr;
+- num_rqe = attrs->cap.max_recv_wr;
+-
+ /* All queue indices are derived from modulo operations
+ * on a free running 'get' (consumer) and 'put' (producer)
+ * unsigned counter. Having queue sizes at power of two
+ * avoids handling counter wrap around.
+ */
+- if (num_sqe)
+- num_sqe = roundup_pow_of_two(num_sqe);
+- else {
+- /* Zero sized SQ is not supported */
+- rv = -EINVAL;
+- goto err_out_xa;
+- }
++ num_sqe = roundup_pow_of_two(attrs->cap.max_send_wr);
++ num_rqe = attrs->cap.max_recv_wr;
+ if (num_rqe)
+ num_rqe = roundup_pow_of_two(num_rqe);
+
+@@ -385,14 +373,14 @@ int siw_create_qp(struct ib_qp *ibqp, struct ib_qp_init_attr *attrs,
+
+ if (qp->sendq == NULL) {
+ rv = -ENOMEM;
+- goto err_out_xa;
++ goto err_out;
+ }
+ if (attrs->sq_sig_type != IB_SIGNAL_REQ_WR) {
+ if (attrs->sq_sig_type == IB_SIGNAL_ALL_WR)
+ qp->attrs.flags |= SIW_SIGNAL_ALL_WR;
+ else {
+ rv = -EINVAL;
+- goto err_out_xa;
++ goto err_out;
+ }
+ }
+ qp->pd = pd;
+@@ -418,7 +406,7 @@ int siw_create_qp(struct ib_qp *ibqp, struct ib_qp_init_attr *attrs,
+
+ if (qp->recvq == NULL) {
+ rv = -ENOMEM;
+- goto err_out_xa;
++ goto err_out;
+ }
+ qp->attrs.rq_size = num_rqe;
+ }
+@@ -433,11 +421,8 @@ int siw_create_qp(struct ib_qp *ibqp, struct ib_qp_init_attr *attrs,
+ qp->attrs.state = SIW_QP_STATE_IDLE;
+
+ if (udata) {
+- struct siw_uresp_create_qp uresp = {};
+-
+ uresp.num_sqe = num_sqe;
+ uresp.num_rqe = num_rqe;
+- uresp.qp_id = qp_id(qp);
+
+ if (qp->sendq) {
+ length = num_sqe * sizeof(struct siw_sqe);
+@@ -446,7 +431,7 @@ int siw_create_qp(struct ib_qp *ibqp, struct ib_qp_init_attr *attrs,
+ length, &uresp.sq_key);
+ if (!qp->sq_entry) {
+ rv = -ENOMEM;
+- goto err_out_xa;
++ goto err_out;
+ }
+ }
+
+@@ -458,9 +443,23 @@ int siw_create_qp(struct ib_qp *ibqp, struct ib_qp_init_attr *attrs,
+ if (!qp->rq_entry) {
+ uresp.sq_key = SIW_INVAL_UOBJ_KEY;
+ rv = -ENOMEM;
+- goto err_out_xa;
++ goto err_out;
+ }
+ }
++ }
++ qp->tx_cpu = siw_get_tx_cpu(sdev);
++ if (qp->tx_cpu < 0) {
++ rv = -EINVAL;
++ goto err_out;
++ }
++ init_completion(&qp->qp_free);
++
++ rv = siw_qp_add(sdev, qp);
++ if (rv)
++ goto err_out_tx;
++
++ if (udata) {
++ uresp.qp_id = qp_id(qp);
+
+ if (udata->outlen < sizeof(uresp)) {
+ rv = -EINVAL;
+@@ -470,22 +469,19 @@ int siw_create_qp(struct ib_qp *ibqp, struct ib_qp_init_attr *attrs,
+ if (rv)
+ goto err_out_xa;
+ }
+- qp->tx_cpu = siw_get_tx_cpu(sdev);
+- if (qp->tx_cpu < 0) {
+- rv = -EINVAL;
+- goto err_out_xa;
+- }
++
+ INIT_LIST_HEAD(&qp->devq);
+ spin_lock_irqsave(&sdev->lock, flags);
+ list_add_tail(&qp->devq, &sdev->qp_list);
+ spin_unlock_irqrestore(&sdev->lock, flags);
+
+- init_completion(&qp->qp_free);
+-
+ return 0;
+
+ err_out_xa:
+ xa_erase(&sdev->qp_xa, qp_id(qp));
++err_out_tx:
++ siw_put_tx_cpu(qp->tx_cpu);
++err_out:
+ if (uctx) {
+ rdma_user_mmap_entry_remove(qp->sq_entry);
+ rdma_user_mmap_entry_remove(qp->rq_entry);
+diff --git a/drivers/input/evdev.c b/drivers/input/evdev.c
+index 95f90699d2b17b..db014dae950018 100644
+--- a/drivers/input/evdev.c
++++ b/drivers/input/evdev.c
+@@ -21,6 +21,7 @@
+ #include <linux/init.h>
+ #include <linux/input/mt.h>
+ #include <linux/major.h>
++#include <linux/nospec.h>
+ #include <linux/device.h>
+ #include <linux/cdev.h>
+ #include "input-compat.h"
+@@ -67,8 +68,10 @@ static size_t evdev_get_mask_cnt(unsigned int type)
+ [EV_SND] = SND_CNT,
+ [EV_FF] = FF_CNT,
+ };
++ unsigned long mask = array_index_mask_nospec(type, EV_CNT);
+
+- return (type < EV_CNT) ? counts[type] : 0;
++ /* Returns 0 for out-of-bounds types, including speculatively */
++ return counts[type & mask] & mask;
+ }
+
+ /* requires the buffer lock to be held */
+@@ -146,11 +149,11 @@ static void __evdev_queue_syn_dropped(struct evdev_client *client)
+ struct timespec64 ts = ktime_to_timespec64(ev_time[client->clk_type]);
+ struct input_event ev;
+
++ memset(&ev, 0, sizeof(ev));
+ ev.input_event_sec = ts.tv_sec;
+ ev.input_event_usec = ts.tv_nsec / NSEC_PER_USEC;
+ ev.type = EV_SYN;
+ ev.code = SYN_DROPPED;
+- ev.value = 0;
+
+ client->buffer[client->head++] = ev;
+ client->head &= client->bufsize - 1;
+@@ -218,20 +221,20 @@ static void __pass_event(struct evdev_client *client,
+ client->head &= client->bufsize - 1;
+
+ if (unlikely(client->head == client->tail)) {
++ struct input_event ev;
++
++ memset(&ev, 0, sizeof(ev));
++ ev.input_event_sec = event->input_event_sec;
++ ev.input_event_usec = event->input_event_usec;
++ ev.type = EV_SYN;
++ ev.code = SYN_DROPPED;
++
+ /*
+ * This effectively "drops" all unconsumed events, leaving
+ * EV_SYN/SYN_DROPPED plus the newest event in the queue.
+ */
+ client->tail = (client->head - 2) & (client->bufsize - 1);
+-
+- client->buffer[client->tail] = (struct input_event) {
+- .input_event_sec = event->input_event_sec,
+- .input_event_usec = event->input_event_usec,
+- .type = EV_SYN,
+- .code = SYN_DROPPED,
+- .value = 0,
+- };
+-
++ client->buffer[client->tail] = ev;
+ client->packet_head = client->tail;
+ }
+
+@@ -253,6 +256,8 @@ static void evdev_pass_values(struct evdev_client *client,
+ if (client->revoked)
+ return;
+
++ memset(&event, 0, sizeof(event));
++
+ ts = ktime_to_timespec64(ev_time[client->clk_type]);
+ event.input_event_sec = ts.tv_sec;
+ event.input_event_usec = ts.tv_nsec / NSEC_PER_USEC;
+diff --git a/drivers/input/misc/ims-pcu.c b/drivers/input/misc/ims-pcu.c
+index 2bac9d9c7b0c9c..6b2aeaa50812f2 100644
+--- a/drivers/input/misc/ims-pcu.c
++++ b/drivers/input/misc/ims-pcu.c
+@@ -448,6 +448,14 @@ static void ims_pcu_handle_response(struct ims_pcu *pcu)
+ }
+ }
+
++static void ims_pcu_reset_packet(struct ims_pcu *pcu)
++{
++ pcu->have_stx = false;
++ pcu->have_dle = false;
++ pcu->read_pos = 0;
++ pcu->check_sum = 0;
++}
++
+ static void ims_pcu_process_data(struct ims_pcu *pcu, struct urb *urb)
+ {
+ int i;
+@@ -460,6 +468,14 @@ static void ims_pcu_process_data(struct ims_pcu *pcu, struct urb *urb)
+ continue;
+
+ if (pcu->have_dle) {
++ if (pcu->read_pos >= IMS_PCU_BUF_SIZE) {
++ dev_warn(pcu->dev,
++ "Packet too long (%d bytes), discarding\n",
++ pcu->read_pos);
++ ims_pcu_reset_packet(pcu);
++ continue;
++ }
++
+ pcu->have_dle = false;
+ pcu->read_buf[pcu->read_pos++] = data;
+ pcu->check_sum += data;
+@@ -472,10 +488,8 @@ static void ims_pcu_process_data(struct ims_pcu *pcu, struct urb *urb)
+ dev_warn(pcu->dev,
+ "Unexpected STX at byte %d, discarding old data\n",
+ pcu->read_pos);
++ ims_pcu_reset_packet(pcu);
+ pcu->have_stx = true;
+- pcu->have_dle = false;
+- pcu->read_pos = 0;
+- pcu->check_sum = 0;
+ break;
+
+ case IMS_PCU_PROTOCOL_DLE:
+@@ -495,12 +509,18 @@ static void ims_pcu_process_data(struct ims_pcu *pcu, struct urb *urb)
+ ims_pcu_handle_response(pcu);
+ }
+
+- pcu->have_stx = false;
+- pcu->have_dle = false;
+- pcu->read_pos = 0;
++ ims_pcu_reset_packet(pcu);
+ break;
+
+ default:
++ if (pcu->read_pos >= IMS_PCU_BUF_SIZE) {
++ dev_warn(pcu->dev,
++ "Packet too long (%d bytes), discarding\n",
++ pcu->read_pos);
++ ims_pcu_reset_packet(pcu);
++ continue;
++ }
++
+ pcu->read_buf[pcu->read_pos++] = data;
+ pcu->check_sum += data;
+ break;
+diff --git a/drivers/iommu/amd/init.c b/drivers/iommu/amd/init.c
+index 9cb53e384247e9..a0342682c01d24 100644
+--- a/drivers/iommu/amd/init.c
++++ b/drivers/iommu/amd/init.c
+@@ -3603,6 +3603,12 @@ not_found:
+ return 1;
+
+ found:
++ if (early_acpihid_map_size == EARLY_MAP_SIZE) {
++ pr_err("Early ACPI HID map overflow - ignoring ivrs_acpihid%s\n",
++ str);
++ return 1;
++ }
++
+ p = acpiid;
+ hid = strsep(&p, ":");
+ uid = p;
+diff --git a/drivers/iommu/intel/perf.c b/drivers/iommu/intel/perf.c
+index ae64e1123f2571..08ffebdbd09cec 100644
+--- a/drivers/iommu/intel/perf.c
++++ b/drivers/iommu/intel/perf.c
+@@ -63,7 +63,7 @@ void dmar_latency_disable(struct intel_iommu *iommu, enum latency_type type)
+ return;
+
+ spin_lock_irqsave(&latency_lock, flags);
+- memset(&lstat[type], 0, sizeof(*lstat) * DMAR_LATENCY_NUM);
++ memset(&lstat[type], 0, sizeof(*lstat));
+ spin_unlock_irqrestore(&latency_lock, flags);
+ }
+
+diff --git a/drivers/iommu/intel/svm.c b/drivers/iommu/intel/svm.c
+index cb862ab96873e4..d23ae13a4c0d3a 100644
+--- a/drivers/iommu/intel/svm.c
++++ b/drivers/iommu/intel/svm.c
+@@ -153,7 +153,7 @@ int intel_svm_finish_prq(struct intel_iommu *iommu)
+
+ void intel_svm_check(struct intel_iommu *iommu)
+ {
+- if (!pasid_supported(iommu))
++ if (!pasid_supported(iommu) || !ecap_smpwc(iommu->ecap))
+ return;
+
+ if (cpu_feature_enabled(X86_FEATURE_GBPAGES) &&
+diff --git a/drivers/media/cec/platform/seco/seco-cec.c b/drivers/media/cec/platform/seco/seco-cec.c
+index 580905e3d06676..197d448a2a19e6 100644
+--- a/drivers/media/cec/platform/seco/seco-cec.c
++++ b/drivers/media/cec/platform/seco/seco-cec.c
+@@ -649,7 +649,7 @@ static int secocec_probe(struct platform_device *pdev)
+
+ ret = secocec_ir_probe(secocec);
+ if (ret)
+- goto err_notifier;
++ goto err_unregister_adapter;
+
+ platform_set_drvdata(pdev, secocec);
+
+@@ -657,6 +657,10 @@ static int secocec_probe(struct platform_device *pdev)
+
+ return ret;
+
++err_unregister_adapter:
++ cec_notifier_cec_adap_unregister(secocec->notifier, secocec->cec_adap);
++ cec_unregister_adapter(secocec->cec_adap);
++ goto err;
+ err_notifier:
+ cec_notifier_cec_adap_unregister(secocec->notifier, secocec->cec_adap);
+ err_delete_adapter:
+diff --git a/drivers/media/common/videobuf2/videobuf2-core.c b/drivers/media/common/videobuf2/videobuf2-core.c
+index a50a1f0a7342c0..a20d9d5cf3d094 100644
+--- a/drivers/media/common/videobuf2/videobuf2-core.c
++++ b/drivers/media/common/videobuf2/videobuf2-core.c
+@@ -2770,8 +2770,8 @@ static int __vb2_cleanup_fileio(struct vb2_queue *q)
+ * @nonblock: mode selector (1 means blocking calls, 0 means nonblocking)
+ * @read: access mode selector (1 means read, 0 means write)
+ */
+-static size_t __vb2_perform_fileio(struct vb2_queue *q, char __user *data, size_t count,
+- loff_t *ppos, int nonblock, int read)
++static ssize_t __vb2_perform_fileio(struct vb2_queue *q, char __user *data, size_t count,
++ loff_t *ppos, int nonblock, int read)
+ {
+ struct vb2_fileio_data *fileio;
+ struct vb2_fileio_buf *buf;
+@@ -2931,15 +2931,15 @@ static size_t __vb2_perform_fileio(struct vb2_queue *q, char __user *data, size_
+ return ret;
+ }
+
+-size_t vb2_read(struct vb2_queue *q, char __user *data, size_t count,
+- loff_t *ppos, int nonblocking)
++ssize_t vb2_read(struct vb2_queue *q, char __user *data, size_t count,
++ loff_t *ppos, int nonblocking)
+ {
+ return __vb2_perform_fileio(q, data, count, ppos, nonblocking, 1);
+ }
+ EXPORT_SYMBOL_GPL(vb2_read);
+
+-size_t vb2_write(struct vb2_queue *q, const char __user *data, size_t count,
+- loff_t *ppos, int nonblocking)
++ssize_t vb2_write(struct vb2_queue *q, const char __user *data, size_t count,
++ loff_t *ppos, int nonblocking)
+ {
+ return __vb2_perform_fileio(q, (char __user *) data, count,
+ ppos, nonblocking, 0);
+diff --git a/drivers/media/dvb-frontends/rtl2832.c b/drivers/media/dvb-frontends/rtl2832.c
+index c27cbddc42b7b9..d1c2117153997b 100644
+--- a/drivers/media/dvb-frontends/rtl2832.c
++++ b/drivers/media/dvb-frontends/rtl2832.c
+@@ -1116,10 +1116,10 @@ static void rtl2832_remove(struct i2c_client *client)
+
+ dev_dbg(&client->dev, "\n");
+
+- cancel_delayed_work_sync(&dev->i2c_gate_work);
+-
+ i2c_mux_del_adapters(dev->muxc);
+
++ cancel_delayed_work_sync(&dev->i2c_gate_work);
++
+ regmap_exit(dev->regmap);
+
+ kfree(dev);
+diff --git a/drivers/media/dvb-frontends/rtl2832_sdr.c b/drivers/media/dvb-frontends/rtl2832_sdr.c
+index 05f71d1697267e..8f74cd4b707c15 100644
+--- a/drivers/media/dvb-frontends/rtl2832_sdr.c
++++ b/drivers/media/dvb-frontends/rtl2832_sdr.c
+@@ -399,7 +399,8 @@ static int rtl2832_sdr_alloc_urbs(struct rtl2832_sdr_dev *dev)
+ }
+
+ /* Must be called with vb_queue_lock hold */
+-static void rtl2832_sdr_cleanup_queued_bufs(struct rtl2832_sdr_dev *dev)
++static void rtl2832_sdr_cleanup_queued_bufs(struct rtl2832_sdr_dev *dev,
++ enum vb2_buffer_state state)
+ {
+ struct platform_device *pdev = dev->pdev;
+ unsigned long flags;
+@@ -413,7 +414,7 @@ static void rtl2832_sdr_cleanup_queued_bufs(struct rtl2832_sdr_dev *dev)
+ buf = list_entry(dev->queued_bufs.next,
+ struct rtl2832_sdr_frame_buf, list);
+ list_del(&buf->list);
+- vb2_buffer_done(&buf->vb.vb2_buf, VB2_BUF_STATE_ERROR);
++ vb2_buffer_done(&buf->vb.vb2_buf, state);
+ }
+ spin_unlock_irqrestore(&dev->queued_bufs_lock, flags);
+ }
+@@ -854,11 +855,15 @@ static int rtl2832_sdr_start_streaming(struct vb2_queue *vq, unsigned int count)
+
+ dev_dbg(&pdev->dev, "\n");
+
+- if (!dev->udev)
++ if (!dev->udev) {
++ rtl2832_sdr_cleanup_queued_bufs(dev, VB2_BUF_STATE_QUEUED);
+ return -ENODEV;
++ }
+
+- if (mutex_lock_interruptible(&dev->v4l2_lock))
++ if (mutex_lock_interruptible(&dev->v4l2_lock)) {
++ rtl2832_sdr_cleanup_queued_bufs(dev, VB2_BUF_STATE_QUEUED);
+ return -ERESTARTSYS;
++ }
+
+ if (d->props->power_ctrl)
+ d->props->power_ctrl(d, 1);
+@@ -899,7 +904,11 @@ static int rtl2832_sdr_start_streaming(struct vb2_queue *vq, unsigned int count)
+ if (ret)
+ goto err;
+
++ mutex_unlock(&dev->v4l2_lock);
++ return 0;
++
+ err:
++ rtl2832_sdr_cleanup_queued_bufs(dev, VB2_BUF_STATE_QUEUED);
+ mutex_unlock(&dev->v4l2_lock);
+
+ return ret;
+@@ -919,7 +928,7 @@ static void rtl2832_sdr_stop_streaming(struct vb2_queue *vq)
+ rtl2832_sdr_kill_urbs(dev);
+ rtl2832_sdr_free_urbs(dev);
+ rtl2832_sdr_free_stream_bufs(dev);
+- rtl2832_sdr_cleanup_queued_bufs(dev);
++ rtl2832_sdr_cleanup_queued_bufs(dev, VB2_BUF_STATE_ERROR);
+ rtl2832_sdr_unset_adc(dev);
+
+ /* sleep tuner */
+diff --git a/drivers/media/pci/cx23885/cx23885-core.c b/drivers/media/pci/cx23885/cx23885-core.c
+index 2ce2914576cf2a..243c0afe267cd1 100644
+--- a/drivers/media/pci/cx23885/cx23885-core.c
++++ b/drivers/media/pci/cx23885/cx23885-core.c
+@@ -990,8 +990,12 @@ static int cx23885_dev_setup(struct cx23885_dev *dev)
+ }
+
+ /* PCIe stuff */
+- dev->lmmio = ioremap(pci_resource_start(dev->pci, 0),
+- pci_resource_len(dev->pci, 0));
++ dev->lmmio = pci_ioremap_bar(dev->pci, 0);
++ if (!dev->lmmio) {
++ dev_err(&dev->pci->dev, "CORE %s: can't ioremap MMIO memory\n",
++ dev->name);
++ goto err_release_region;
++ }
+
+ dev->bmmio = (u8 __iomem *)dev->lmmio;
+
+@@ -1096,6 +1100,12 @@ static int cx23885_dev_setup(struct cx23885_dev *dev)
+ }
+
+ return 0;
++
++err_release_region:
++ release_mem_region(pci_resource_start(dev->pci, 0),
++ pci_resource_len(dev->pci, 0));
++ cx23885_devcount--;
++ return -ENODEV;
+ }
+
+ static void cx23885_dev_unregister(struct cx23885_dev *dev)
+diff --git a/drivers/media/pci/dm1105/dm1105.c b/drivers/media/pci/dm1105/dm1105.c
+index 9e9c7c071accce..57f7e4df41b224 100644
+--- a/drivers/media/pci/dm1105/dm1105.c
++++ b/drivers/media/pci/dm1105/dm1105.c
+@@ -1193,6 +1193,7 @@ static void dm1105_remove(struct pci_dev *pdev)
+
+ dm1105_hw_exit(dev);
+ free_irq(pdev->irq, dev);
++ destroy_workqueue(dev->wq);
+ pci_iounmap(pdev, dev->io_mem);
+ pci_release_regions(pdev);
+ pci_disable_device(pdev);
+diff --git a/drivers/media/pci/saa7134/saa7134-video.c b/drivers/media/pci/saa7134/saa7134-video.c
+index 29124756a62bc3..56b2e13efb0656 100644
+--- a/drivers/media/pci/saa7134/saa7134-video.c
++++ b/drivers/media/pci/saa7134/saa7134-video.c
+@@ -2119,8 +2119,10 @@ int saa7134_video_init1(struct saa7134_dev *dev)
+ q->dev = &dev->pci->dev;
+ ret = vb2_queue_init(q);
+ if (ret)
+- return ret;
+- saa7134_pgtable_alloc(dev->pci, &dev->video_q.pt);
++ goto err_free_ctrl;
++ ret = saa7134_pgtable_alloc(dev->pci, &dev->video_q.pt);
++ if (ret)
++ goto err_free_ctrl;
+
+ q = &dev->vbi_vbq;
+ q->type = V4L2_BUF_TYPE_VBI_CAPTURE;
+@@ -2137,11 +2139,24 @@ int saa7134_video_init1(struct saa7134_dev *dev)
+ q->lock = &dev->lock;
+ q->dev = &dev->pci->dev;
+ ret = vb2_queue_init(q);
+- if (ret)
+- return ret;
+- saa7134_pgtable_alloc(dev->pci, &dev->vbi_q.pt);
++ if (ret) {
++ saa7134_pgtable_free(dev->pci, &dev->video_q.pt);
++ goto err_free_ctrl;
++ }
++
++ ret = saa7134_pgtable_alloc(dev->pci, &dev->vbi_q.pt);
++ if (ret) {
++ saa7134_pgtable_free(dev->pci, &dev->video_q.pt);
++ goto err_free_ctrl;
++ }
+
+ return 0;
++
++err_free_ctrl:
++ v4l2_ctrl_handler_free(&dev->ctrl_handler);
++ if (card_has_radio(dev))
++ v4l2_ctrl_handler_free(&dev->radio_ctrl_handler);
++ return ret;
+ }
+
+ void saa7134_video_fini(struct saa7134_dev *dev)
+diff --git a/drivers/media/platform/aspeed/aspeed-video.c b/drivers/media/platform/aspeed/aspeed-video.c
+index c5af28bf0e96cc..888ad7183b4eaf 100644
+--- a/drivers/media/platform/aspeed/aspeed-video.c
++++ b/drivers/media/platform/aspeed/aspeed-video.c
+@@ -1994,6 +1994,7 @@ static int aspeed_video_probe(struct platform_device *pdev)
+ rc = aspeed_video_setup_video(video);
+ if (rc) {
+ aspeed_video_free_buf(video, &video->jpeg);
++ of_reserved_mem_device_release(&pdev->dev);
+ clk_unprepare(video->vclk);
+ clk_unprepare(video->eclk);
+ return rc;
+diff --git a/drivers/media/platform/marvell/cafe-driver.c b/drivers/media/platform/marvell/cafe-driver.c
+index ae97ce4ead9886..ed06be421da9ba 100644
+--- a/drivers/media/platform/marvell/cafe-driver.c
++++ b/drivers/media/platform/marvell/cafe-driver.c
+@@ -601,6 +601,7 @@ static void cafe_pci_remove(struct pci_dev *pdev)
+ return;
+ }
+ cafe_shutdown(cam);
++ pci_disable_device(pdev);
+ kfree(cam);
+ }
+
+diff --git a/drivers/media/platform/st/stm32/stm32-dcmi.c b/drivers/media/platform/st/stm32/stm32-dcmi.c
+index 06be28b361f1a1..ab3b8f57df4887 100644
+--- a/drivers/media/platform/st/stm32/stm32-dcmi.c
++++ b/drivers/media/platform/st/stm32/stm32-dcmi.c
+@@ -2122,6 +2122,7 @@ static int dcmi_probe(struct platform_device *pdev)
+ return 0;
+
+ err_cleanup:
++ v4l2_async_nf_unregister(&dcmi->notifier);
+ v4l2_async_nf_cleanup(&dcmi->notifier);
+ err_media_entity_cleanup:
+ media_entity_cleanup(&dcmi->vdev->entity);
+diff --git a/drivers/media/platform/sunxi/sun4i-csi/sun4i_dma.c b/drivers/media/platform/sunxi/sun4i-csi/sun4i_dma.c
+index a3e826a755fc34..8fe749df2c194e 100644
+--- a/drivers/media/platform/sunxi/sun4i-csi/sun4i_dma.c
++++ b/drivers/media/platform/sunxi/sun4i-csi/sun4i_dma.c
+@@ -234,8 +234,10 @@ static int sun4i_csi_start_streaming(struct vb2_queue *vq, unsigned int count)
+ int ret;
+
+ csi_fmt = sun4i_csi_find_format(&csi->fmt.pixelformat, NULL);
+- if (!csi_fmt)
+- return -EINVAL;
++ if (!csi_fmt) {
++ ret = -EINVAL;
++ goto err_clear_dma_queue;
++ }
+
+ dev_dbg(csi->dev, "Starting capture\n");
+
+diff --git a/drivers/media/platform/ti/davinci/vpif_capture.c b/drivers/media/platform/ti/davinci/vpif_capture.c
+index 0fe0a3f8a053ff..ced6392c46d2ea 100644
+--- a/drivers/media/platform/ti/davinci/vpif_capture.c
++++ b/drivers/media/platform/ti/davinci/vpif_capture.c
+@@ -1499,7 +1499,7 @@ vpif_capture_get_pdata(struct platform_device *pdev)
+ * video ports & endpoints data.
+ */
+ if (pdev->dev.parent && pdev->dev.parent->of_node)
+- pdev->dev.of_node = pdev->dev.parent->of_node;
++ device_set_of_node_from_dev(&pdev->dev, pdev->dev.parent);
+ if (!IS_ENABLED(CONFIG_OF) || !pdev->dev.of_node)
+ return pdev->dev.platform_data;
+
+diff --git a/drivers/media/platform/ti/vpe/vpe.c b/drivers/media/platform/ti/vpe/vpe.c
+index 5b1c5d96a40799..8ac7c917101b5d 100644
+--- a/drivers/media/platform/ti/vpe/vpe.c
++++ b/drivers/media/platform/ti/vpe/vpe.c
+@@ -2545,7 +2545,8 @@ static int vpe_probe(struct platform_device *pdev)
+ "vpe_top");
+ if (!dev->res) {
+ dev_err(&pdev->dev, "missing 'vpe_top' resources data\n");
+- return -ENODEV;
++ ret = -ENODEV;
++ goto v4l2_dev_unreg;
+ }
+
+ /*
+diff --git a/drivers/media/radio/radio-si476x.c b/drivers/media/radio/radio-si476x.c
+index 171f9cc9ee5ea4..45f80dc1252822 100644
+--- a/drivers/media/radio/radio-si476x.c
++++ b/drivers/media/radio/radio-si476x.c
+@@ -1495,6 +1495,7 @@ static int si476x_radio_probe(struct platform_device *pdev)
+ return 0;
+ exit:
+ v4l2_ctrl_handler_free(radio->videodev.ctrl_handler);
++ v4l2_device_unregister(&radio->v4l2dev);
+ return rval;
+ }
+
+diff --git a/drivers/media/test-drivers/vidtv/vidtv_bridge.c b/drivers/media/test-drivers/vidtv/vidtv_bridge.c
+index f7c5fb8654959f..9741aaa2ec9256 100644
+--- a/drivers/media/test-drivers/vidtv/vidtv_bridge.c
++++ b/drivers/media/test-drivers/vidtv/vidtv_bridge.c
+@@ -596,8 +596,10 @@ static int __init vidtv_bridge_init(void)
+ int ret;
+
+ ret = platform_device_register(&vidtv_bridge_dev);
+- if (ret)
++ if (ret) {
++ platform_device_put(&vidtv_bridge_dev);
+ return ret;
++ }
+
+ ret = platform_driver_register(&vidtv_bridge_driver);
+ if (ret)
+diff --git a/drivers/media/test-drivers/vimc/vimc-core.c b/drivers/media/test-drivers/vimc/vimc-core.c
+index e82cfa5ffbf47e..6e5867c730acb1 100644
+--- a/drivers/media/test-drivers/vimc/vimc-core.c
++++ b/drivers/media/test-drivers/vimc/vimc-core.c
+@@ -426,6 +426,7 @@ static int __init vimc_init(void)
+ if (ret) {
+ dev_err(&vimc_pdev.dev,
+ "platform device registration failed (err=%d)\n", ret);
++ platform_device_put(&vimc_pdev);
+ return ret;
+ }
+
+diff --git a/drivers/media/test-drivers/vivid/vivid-ctrls.c b/drivers/media/test-drivers/vivid/vivid-ctrls.c
+index 0e549777860fb7..9364b8786e6364 100644
+--- a/drivers/media/test-drivers/vivid/vivid-ctrls.c
++++ b/drivers/media/test-drivers/vivid/vivid-ctrls.c
+@@ -516,17 +516,24 @@ static int vivid_vid_cap_s_ctrl(struct v4l2_ctrl *ctrl)
+ break;
+ case VIVID_CID_REDUCED_FPS:
+ dev->reduced_fps = ctrl->val;
+- vivid_update_format_cap(dev, true);
++ if (dev->input_type[dev->input] == HDMI)
++ vivid_update_reduced_fps(dev);
+ break;
+ case VIVID_CID_HAS_CROP_CAP:
++ if (vb2_is_busy(&dev->vb_vid_cap_q))
++ return -EBUSY;
+ dev->has_crop_cap = ctrl->val;
+ vivid_update_format_cap(dev, true);
+ break;
+ case VIVID_CID_HAS_COMPOSE_CAP:
++ if (vb2_is_busy(&dev->vb_vid_cap_q))
++ return -EBUSY;
+ dev->has_compose_cap = ctrl->val;
+ vivid_update_format_cap(dev, true);
+ break;
+ case VIVID_CID_HAS_SCALER_CAP:
++ if (vb2_is_busy(&dev->vb_vid_cap_q))
++ return -EBUSY;
+ dev->has_scaler_cap = ctrl->val;
+ vivid_update_format_cap(dev, true);
+ break;
+@@ -1011,14 +1018,20 @@ static int vivid_vid_out_s_ctrl(struct v4l2_ctrl *ctrl)
+
+ switch (ctrl->id) {
+ case VIVID_CID_HAS_CROP_OUT:
++ if (vb2_is_busy(&dev->vb_vid_out_q))
++ return -EBUSY;
+ dev->has_crop_out = ctrl->val;
+ vivid_update_format_out(dev);
+ break;
+ case VIVID_CID_HAS_COMPOSE_OUT:
++ if (vb2_is_busy(&dev->vb_vid_out_q))
++ return -EBUSY;
+ dev->has_compose_out = ctrl->val;
+ vivid_update_format_out(dev);
+ break;
+ case VIVID_CID_HAS_SCALER_OUT:
++ if (vb2_is_busy(&dev->vb_vid_out_q))
++ return -EBUSY;
+ dev->has_scaler_out = ctrl->val;
+ vivid_update_format_out(dev);
+ break;
+diff --git a/drivers/media/test-drivers/vivid/vivid-vid-cap.c b/drivers/media/test-drivers/vivid/vivid-vid-cap.c
+index e3e3237206ab26..11b7498a3b5397 100644
+--- a/drivers/media/test-drivers/vivid/vivid-vid-cap.c
++++ b/drivers/media/test-drivers/vivid/vivid-vid-cap.c
+@@ -375,6 +375,24 @@ static enum tpg_pixel_aspect vivid_get_pixel_aspect(const struct vivid_dev *dev)
+ return TPG_PIXEL_ASPECT_SQUARE;
+ }
+
++void vivid_update_reduced_fps(struct vivid_dev *dev)
++{
++ struct v4l2_bt_timings *bt = &dev->dv_timings_cap[dev->input].bt;
++ unsigned int size = V4L2_DV_BT_FRAME_WIDTH(bt) * V4L2_DV_BT_FRAME_HEIGHT(bt);
++ u64 pixelclock;
++
++ if (dev->reduced_fps && can_reduce_fps(bt)) {
++ pixelclock = div_u64(bt->pixelclock * 1000, 1001);
++ bt->flags |= V4L2_DV_FL_REDUCED_FPS;
++ } else {
++ pixelclock = bt->pixelclock;
++ bt->flags &= ~V4L2_DV_FL_REDUCED_FPS;
++ }
++ dev->timeperframe_vid_cap = (struct v4l2_fract) {
++ size / 100, (u32)pixelclock / 100
++ };
++}
++
+ /*
+ * Called whenever the format has to be reset which can occur when
+ * changing inputs, standard, timings, etc.
+@@ -383,8 +401,12 @@ void vivid_update_format_cap(struct vivid_dev *dev, bool keep_controls)
+ {
+ struct v4l2_bt_timings *bt = &dev->dv_timings_cap[dev->input].bt;
+ u32 dims[V4L2_CTRL_MAX_DIMS] = {};
+- unsigned size;
+- u64 pixelclock;
++
++ /*
++ * This resets the format, so must never be called while vb2_is_busy().
++ */
++ if (WARN_ON(vb2_is_busy(&dev->vb_vid_cap_q)))
++ return;
+
+ switch (dev->input_type[dev->input]) {
+ case WEBCAM:
+@@ -413,17 +435,7 @@ void vivid_update_format_cap(struct vivid_dev *dev, bool keep_controls)
+ case HDMI:
+ dev->src_rect.width = bt->width;
+ dev->src_rect.height = bt->height;
+- size = V4L2_DV_BT_FRAME_WIDTH(bt) * V4L2_DV_BT_FRAME_HEIGHT(bt);
+- if (dev->reduced_fps && can_reduce_fps(bt)) {
+- pixelclock = div_u64(bt->pixelclock * 1000, 1001);
+- bt->flags |= V4L2_DV_FL_REDUCED_FPS;
+- } else {
+- pixelclock = bt->pixelclock;
+- bt->flags &= ~V4L2_DV_FL_REDUCED_FPS;
+- }
+- dev->timeperframe_vid_cap = (struct v4l2_fract) {
+- size / 100, (u32)pixelclock / 100
+- };
++ vivid_update_reduced_fps(dev);
+ if (bt->interlaced)
+ dev->field_cap = V4L2_FIELD_ALTERNATE;
+ else
+diff --git a/drivers/media/test-drivers/vivid/vivid-vid-cap.h b/drivers/media/test-drivers/vivid/vivid-vid-cap.h
+index 1e422a59eeabf1..42dcf85c74c5ec 100644
+--- a/drivers/media/test-drivers/vivid/vivid-vid-cap.h
++++ b/drivers/media/test-drivers/vivid/vivid-vid-cap.h
+@@ -9,6 +9,7 @@
+ #define _VIVID_VID_CAP_H_
+
+ void vivid_update_quality(struct vivid_dev *dev);
++void vivid_update_reduced_fps(struct vivid_dev *dev);
+ void vivid_update_format_cap(struct vivid_dev *dev, bool keep_controls);
+ enum tpg_video_aspect vivid_get_video_aspect(const struct vivid_dev *dev);
+
+diff --git a/drivers/media/test-drivers/vivid/vivid-vid-out.c b/drivers/media/test-drivers/vivid/vivid-vid-out.c
+index e96d3d014143fa..4ef4885134c0fe 100644
+--- a/drivers/media/test-drivers/vivid/vivid-vid-out.c
++++ b/drivers/media/test-drivers/vivid/vivid-vid-out.c
+@@ -222,6 +222,12 @@ void vivid_update_format_out(struct vivid_dev *dev)
+ unsigned size, p;
+ u64 pixelclock;
+
++ /*
++ * This resets the format, so must never be called while vb2_is_busy().
++ */
++ if (WARN_ON(vb2_is_busy(&dev->vb_vid_out_q)))
++ return;
++
+ switch (dev->output_type[dev->output]) {
+ case SVID:
+ default:
+diff --git a/drivers/media/usb/airspy/airspy.c b/drivers/media/usb/airspy/airspy.c
+index 462eb84235063a..3c5c0b16370893 100644
+--- a/drivers/media/usb/airspy/airspy.c
++++ b/drivers/media/usb/airspy/airspy.c
+@@ -521,11 +521,13 @@ static int airspy_start_streaming(struct vb2_queue *vq, unsigned int count)
+
+ dev_dbg(s->dev, "\n");
+
+- if (!s->udev)
+- return -ENODEV;
+-
+ mutex_lock(&s->v4l2_lock);
+
++ if (!s->udev) {
++ ret = -ENODEV;
++ goto err_clear_bit;
++ }
++
+ s->sequence = 0;
+
+ set_bit(POWER_ON, &s->flags);
+diff --git a/drivers/media/usb/cx231xx/cx231xx-cards.c b/drivers/media/usb/cx231xx/cx231xx-cards.c
+index bda729b42d05fe..64c3cb8fc2bf00 100644
+--- a/drivers/media/usb/cx231xx/cx231xx-cards.c
++++ b/drivers/media/usb/cx231xx/cx231xx-cards.c
+@@ -1577,7 +1577,8 @@ static int cx231xx_init_v4l2(struct cx231xx *dev,
+ dev->video_mode.end_point_addr,
+ dev->video_mode.num_alt);
+
+- dev->video_mode.alt_max_pkt_size = devm_kmalloc_array(&udev->dev, 32, dev->video_mode.num_alt, GFP_KERNEL);
++ dev->video_mode.alt_max_pkt_size = devm_kmalloc_array(&interface->dev, 32,
++ dev->video_mode.num_alt, GFP_KERNEL);
+ if (dev->video_mode.alt_max_pkt_size == NULL)
+ return -ENOMEM;
+
+@@ -1618,7 +1619,8 @@ static int cx231xx_init_v4l2(struct cx231xx *dev,
+ dev->vbi_mode.num_alt);
+
+ /* compute alternate max packet sizes for vbi */
+- dev->vbi_mode.alt_max_pkt_size = devm_kmalloc_array(&udev->dev, 32, dev->vbi_mode.num_alt, GFP_KERNEL);
++ dev->vbi_mode.alt_max_pkt_size = devm_kmalloc_array(&interface->dev, 32,
++ dev->vbi_mode.num_alt, GFP_KERNEL);
+ if (dev->vbi_mode.alt_max_pkt_size == NULL)
+ return -ENOMEM;
+
+@@ -1660,7 +1662,9 @@ static int cx231xx_init_v4l2(struct cx231xx *dev,
+ "sliced CC EndPoint Addr 0x%x, Alternate settings: %i\n",
+ dev->sliced_cc_mode.end_point_addr,
+ dev->sliced_cc_mode.num_alt);
+- dev->sliced_cc_mode.alt_max_pkt_size = devm_kmalloc_array(&udev->dev, 32, dev->sliced_cc_mode.num_alt, GFP_KERNEL);
++ dev->sliced_cc_mode.alt_max_pkt_size = devm_kmalloc_array(&interface->dev, 32,
++ dev->sliced_cc_mode.num_alt,
++ GFP_KERNEL);
+ if (dev->sliced_cc_mode.alt_max_pkt_size == NULL)
+ return -ENOMEM;
+
+@@ -1724,7 +1728,7 @@ static int cx231xx_usb_probe(struct usb_interface *interface,
+ udev = usb_get_dev(interface_to_usbdev(interface));
+
+ /* allocate memory for our device state and initialize it */
+- dev = devm_kzalloc(&udev->dev, sizeof(*dev), GFP_KERNEL);
++ dev = devm_kzalloc(&interface->dev, sizeof(*dev), GFP_KERNEL);
+ if (dev == NULL) {
+ retval = -ENOMEM;
+ goto err_if;
+@@ -1854,7 +1858,9 @@ static int cx231xx_usb_probe(struct usb_interface *interface,
+ dev->ts1_mode.end_point_addr,
+ dev->ts1_mode.num_alt);
+
+- dev->ts1_mode.alt_max_pkt_size = devm_kmalloc_array(&udev->dev, 32, dev->ts1_mode.num_alt, GFP_KERNEL);
++ dev->ts1_mode.alt_max_pkt_size = devm_kmalloc_array(&interface->dev, 32,
++ dev->ts1_mode.num_alt,
++ GFP_KERNEL);
+ if (dev->ts1_mode.alt_max_pkt_size == NULL) {
+ retval = -ENOMEM;
+ goto err_video_alt;
+diff --git a/drivers/media/usb/msi2500/msi2500.c b/drivers/media/usb/msi2500/msi2500.c
+index 9759996ee6a4cc..856bf295f719b6 100644
+--- a/drivers/media/usb/msi2500/msi2500.c
++++ b/drivers/media/usb/msi2500/msi2500.c
+@@ -541,7 +541,8 @@ static int msi2500_isoc_init(struct msi2500_dev *dev)
+ }
+
+ /* Must be called with vb_queue_lock hold */
+-static void msi2500_cleanup_queued_bufs(struct msi2500_dev *dev)
++static void msi2500_cleanup_queued_bufs(struct msi2500_dev *dev,
++ enum vb2_buffer_state state)
+ {
+ unsigned long flags;
+
+@@ -554,7 +555,7 @@ static void msi2500_cleanup_queued_bufs(struct msi2500_dev *dev)
+ buf = list_entry(dev->queued_bufs.next,
+ struct msi2500_frame_buf, list);
+ list_del(&buf->list);
+- vb2_buffer_done(&buf->vb.vb2_buf, VB2_BUF_STATE_ERROR);
++ vb2_buffer_done(&buf->vb.vb2_buf, state);
+ }
+ spin_unlock_irqrestore(&dev->queued_bufs_lock, flags);
+ }
+@@ -830,25 +831,40 @@ static int msi2500_start_streaming(struct vb2_queue *vq, unsigned int count)
+
+ dev_dbg(dev->dev, "\n");
+
+- if (!dev->udev)
+- return -ENODEV;
++ if (!dev->udev) {
++ ret = -ENODEV;
++ goto err_cleanup;
++ }
+
+- if (mutex_lock_interruptible(&dev->v4l2_lock))
+- return -ERESTARTSYS;
++ if (mutex_lock_interruptible(&dev->v4l2_lock)) {
++ ret = -ERESTARTSYS;
++ goto err_cleanup;
++ }
+
+ /* wake-up tuner */
+ v4l2_subdev_call(dev->v4l2_subdev, core, s_power, 1);
+
+ ret = msi2500_set_usb_adc(dev);
++ if (ret)
++ goto err_unlock_cleanup;
+
+ ret = msi2500_isoc_init(dev);
+ if (ret)
+- msi2500_cleanup_queued_bufs(dev);
++ goto err_unlock_cleanup;
+
+ ret = msi2500_ctrl_msg(dev, CMD_START_STREAMING, 0);
++ if (ret)
++ goto err_isoc_cleanup;
+
+ mutex_unlock(&dev->v4l2_lock);
++ return 0;
+
++err_isoc_cleanup:
++ msi2500_isoc_cleanup(dev);
++err_unlock_cleanup:
++ mutex_unlock(&dev->v4l2_lock);
++err_cleanup:
++ msi2500_cleanup_queued_bufs(dev, VB2_BUF_STATE_QUEUED);
+ return ret;
+ }
+
+@@ -863,7 +879,7 @@ static void msi2500_stop_streaming(struct vb2_queue *vq)
+ if (dev->udev)
+ msi2500_isoc_cleanup(dev);
+
+- msi2500_cleanup_queued_bufs(dev);
++ msi2500_cleanup_queued_bufs(dev, VB2_BUF_STATE_ERROR);
+
+ /* according to tests, at least 700us delay is required */
+ msleep(20);
+diff --git a/drivers/media/usb/pwc/pwc-if.c b/drivers/media/usb/pwc/pwc-if.c
+index e342199711d397..0ab96c4c7eccd4 100644
+--- a/drivers/media/usb/pwc/pwc-if.c
++++ b/drivers/media/usb/pwc/pwc-if.c
+@@ -711,11 +711,15 @@ static int start_streaming(struct vb2_queue *vq, unsigned int count)
+ struct pwc_device *pdev = vb2_get_drv_priv(vq);
+ int r;
+
+- if (!pdev->udev)
++ if (!pdev->udev) {
++ pwc_cleanup_queued_bufs(pdev, VB2_BUF_STATE_QUEUED);
+ return -ENODEV;
++ }
+
+- if (mutex_lock_interruptible(&pdev->v4l2_lock))
++ if (mutex_lock_interruptible(&pdev->v4l2_lock)) {
++ pwc_cleanup_queued_bufs(pdev, VB2_BUF_STATE_QUEUED);
+ return -ERESTARTSYS;
++ }
+ /* Turn on camera and set LEDS on */
+ pwc_camera_power(pdev, 1);
+ pwc_set_leds(pdev, leds[0], leds[1]);
+@@ -727,6 +731,11 @@ static int start_streaming(struct vb2_queue *vq, unsigned int count)
+ pwc_camera_power(pdev, 0);
+ /* And cleanup any queued bufs!! */
+ pwc_cleanup_queued_bufs(pdev, VB2_BUF_STATE_QUEUED);
++ if (pdev->fill_buf) {
++ vb2_buffer_done(&pdev->fill_buf->vb.vb2_buf,
++ VB2_BUF_STATE_QUEUED);
++ pdev->fill_buf = NULL;
++ }
+ }
+ mutex_unlock(&pdev->v4l2_lock);
+
+diff --git a/drivers/media/usb/uvc/uvc_video.c b/drivers/media/usb/uvc/uvc_video.c
+index e33b9bedddda53..2cc00f4be793b1 100644
+--- a/drivers/media/usb/uvc/uvc_video.c
++++ b/drivers/media/usb/uvc/uvc_video.c
+@@ -24,6 +24,8 @@
+
+ #include "uvcvideo.h"
+
++#define JPEG_MARKER_SOI 0xd8
++
+ /* ------------------------------------------------------------------------
+ * UVC Controls
+ */
+@@ -1089,6 +1091,7 @@ static int uvc_video_decode_start(struct uvc_streaming *stream,
+ struct uvc_buffer *meta_buf,
+ const u8 *data, int len)
+ {
++ u8 header_len;
+ u8 fid;
+
+ /*
+@@ -1102,8 +1105,56 @@ static int uvc_video_decode_start(struct uvc_streaming *stream,
+ return -EINVAL;
+ }
+
++ header_len = data[0];
+ fid = data[1] & UVC_STREAM_FID;
+
++ /*
++ * Mark the buffer as done if we're at the beginning of a new frame.
++ * End of frame detection is better implemented by checking the EOF
++ * bit (FID bit toggling is delayed by one frame compared to the EOF
++ * bit), but some devices don't set the bit at end of frame (and the
++ * last payload can be lost anyway). We thus must check if the FID has
++ * been toggled.
++ *
++ * stream->last_fid is initialized to -1, and buf->bytesused to 0,
++ * so the first isochronous frame will never trigger an end of frame
++ * detection.
++ *
++ * Empty buffers (bytesused == 0) don't trigger end of frame detection
++ * as it doesn't make sense to return an empty buffer. This also
++ * avoids detecting end of frame conditions at FID toggling if the
++ * previous payload had the EOF bit set.
++ */
++ if (fid != stream->last_fid && buf && buf->bytesused != 0) {
++ uvc_dbg(stream->dev, FRAME,
++ "Frame complete (FID bit toggled)\n");
++ buf->state = UVC_BUF_STATE_READY;
++
++ return -EAGAIN;
++ }
++
++ /*
++ * Some cameras, when running two parallel streams (one MJPEG alongside
++ * another non-MJPEG stream), are known to lose the EOF packet for a frame.
++ * We can detect the end of a frame by checking for a new SOI marker, as
++ * the SOI always lies on the packet boundary between two frames for
++ * these devices.
++ */
++ if (stream->dev->quirks & UVC_QUIRK_MJPEG_NO_EOF &&
++ (stream->cur_format->fcc == V4L2_PIX_FMT_MJPEG ||
++ stream->cur_format->fcc == V4L2_PIX_FMT_JPEG) &&
++ buf && buf->bytesused != 0) {
++ const u8 *packet = data + header_len;
++
++ if (len >= header_len + 2 &&
++ packet[0] == 0xff && packet[1] == JPEG_MARKER_SOI) {
++ buf->state = UVC_BUF_STATE_READY;
++ buf->error = 1;
++ stream->last_fid ^= UVC_STREAM_FID;
++ return -EAGAIN;
++ }
++ }
++
+ /*
+ * Increase the sequence number regardless of any buffer states, so
+ * that discontinuous sequence numbers always indicate lost frames.
+@@ -1171,32 +1222,9 @@ static int uvc_video_decode_start(struct uvc_streaming *stream,
+ meta_buf->state = UVC_BUF_STATE_ACTIVE;
+ }
+
+- /*
+- * Mark the buffer as done if we're at the beginning of a new frame.
+- * End of frame detection is better implemented by checking the EOF
+- * bit (FID bit toggling is delayed by one frame compared to the EOF
+- * bit), but some devices don't set the bit at end of frame (and the
+- * last payload can be lost anyway). We thus must check if the FID has
+- * been toggled.
+- *
+- * stream->last_fid is initialized to -1, so the first isochronous
+- * frame will never trigger an end of frame detection.
+- *
+- * Empty buffers (bytesused == 0) don't trigger end of frame detection
+- * as it doesn't make sense to return an empty buffer. This also
+- * avoids detecting end of frame conditions at FID toggling if the
+- * previous payload had the EOF bit set.
+- */
+- if (fid != stream->last_fid && buf->bytesused != 0) {
+- uvc_dbg(stream->dev, FRAME,
+- "Frame complete (FID bit toggled)\n");
+- buf->state = UVC_BUF_STATE_READY;
+- return -EAGAIN;
+- }
+-
+ stream->last_fid = fid;
+
+- return data[0];
++ return header_len;
+ }
+
+ static inline enum dma_data_direction uvc_stream_dir(
+diff --git a/drivers/media/usb/uvc/uvcvideo.h b/drivers/media/usb/uvc/uvcvideo.h
+index a7182305390b44..8404814fa8993b 100644
+--- a/drivers/media/usb/uvc/uvcvideo.h
++++ b/drivers/media/usb/uvc/uvcvideo.h
+@@ -77,6 +77,10 @@
+ #define UVC_QUIRK_FORCE_Y8 0x00000800
+ #define UVC_QUIRK_FORCE_BPP 0x00001000
+ #define UVC_QUIRK_WAKE_AUTOSUSPEND 0x00002000
++#define UVC_QUIRK_NO_RESET_RESUME 0x00004000
++#define UVC_QUIRK_DISABLE_AUTOSUSPEND 0x00008000
++#define UVC_QUIRK_INVALID_DEVICE_SOF 0x00010000
++#define UVC_QUIRK_MJPEG_NO_EOF 0x00020000
+
+ /* Format flags */
+ #define UVC_FMT_FLAG_COMPRESSED 0x00000001
+diff --git a/drivers/media/v4l2-core/v4l2-ctrls-core.c b/drivers/media/v4l2-core/v4l2-ctrls-core.c
+index 0514e04793466e..5bc9287bae49ee 100644
+--- a/drivers/media/v4l2-core/v4l2-ctrls-core.c
++++ b/drivers/media/v4l2-core/v4l2-ctrls-core.c
+@@ -566,6 +566,7 @@ static int std_validate_compound(const struct v4l2_ctrl *ctrl, u32 idx,
+ struct v4l2_ctrl_h264_decode_params *p_h264_dec_params;
+ struct v4l2_ctrl_hevc_sps *p_hevc_sps;
+ struct v4l2_ctrl_hevc_pps *p_hevc_pps;
++ struct v4l2_ctrl_hevc_slice_params *p_hevc_slice_params;
+ struct v4l2_ctrl_hdr10_mastering_display *p_hdr10_mastering;
+ struct v4l2_ctrl_hevc_decode_params *p_hevc_decode_params;
+ struct v4l2_area *area;
+@@ -854,6 +855,18 @@ static int std_validate_compound(const struct v4l2_ctrl *ctrl, u32 idx,
+ break;
+
+ case V4L2_CTRL_TYPE_HEVC_SLICE_PARAMS:
++ p_hevc_slice_params = p;
++
++ if (p_hevc_slice_params->num_ref_idx_l0_active_minus1 >=
++ V4L2_HEVC_DPB_ENTRIES_NUM_MAX)
++ return -EINVAL;
++
++ if (p_hevc_slice_params->slice_type != V4L2_HEVC_SLICE_TYPE_B)
++ break;
++
++ if (p_hevc_slice_params->num_ref_idx_l1_active_minus1 >=
++ V4L2_HEVC_DPB_ENTRIES_NUM_MAX)
++ return -EINVAL;
+ break;
+
+ case V4L2_CTRL_TYPE_HDR10_CLL_INFO:
+diff --git a/drivers/media/v4l2-core/v4l2-ctrls-request.c b/drivers/media/v4l2-core/v4l2-ctrls-request.c
+index c637049d7a2b3f..dd6ca914349035 100644
+--- a/drivers/media/v4l2-core/v4l2-ctrls-request.c
++++ b/drivers/media/v4l2-core/v4l2-ctrls-request.c
+@@ -348,13 +348,12 @@ void v4l2_ctrl_request_complete(struct media_request *req,
+ ret = v4l2_ctrl_handler_init(hdl, (main_hdl->nr_of_buckets - 1) * 8);
+ if (!ret)
+ ret = v4l2_ctrl_request_bind(req, hdl, main_hdl);
+- if (ret) {
+- v4l2_ctrl_handler_free(hdl);
+- kfree(hdl);
+- return;
+- }
++ if (ret)
++ goto error;
+ hdl->request_is_queued = true;
+ obj = media_request_object_find(req, &req_ops, main_hdl);
++ if (!obj)
++ goto error;
+ }
+ hdl = container_of(obj, struct v4l2_ctrl_handler, req_obj);
+
+@@ -389,6 +388,11 @@ void v4l2_ctrl_request_complete(struct media_request *req,
+ mutex_unlock(main_hdl->lock);
+ media_request_object_complete(obj);
+ media_request_object_put(obj);
++ return;
++
++error:
++ v4l2_ctrl_handler_free(hdl);
++ kfree(hdl);
+ }
+ EXPORT_SYMBOL(v4l2_ctrl_request_complete);
+
+diff --git a/drivers/misc/fastrpc.c b/drivers/misc/fastrpc.c
+index 83670f1d3bf10b..c1de0644c370c3 100644
+--- a/drivers/misc/fastrpc.c
++++ b/drivers/misc/fastrpc.c
+@@ -426,6 +426,7 @@ static void fastrpc_channel_ctx_free(struct kref *ref)
+
+ cctx = container_of(ref, struct fastrpc_channel_ctx, refcount);
+
++ idr_destroy(&cctx->ctx_idr);
+ kfree(cctx);
+ }
+
+@@ -1448,7 +1449,7 @@ static int fastrpc_device_open(struct inode *inode, struct file *filp)
+ dev_err(&cctx->rpdev->dev, "No session available\n");
+ mutex_destroy(&fl->mutex);
+ kfree(fl);
+-
++ fastrpc_channel_ctx_put(cctx);
+ return -EBUSY;
+ }
+
+diff --git a/drivers/mtd/mtdswap.c b/drivers/mtd/mtdswap.c
+index 680366616da240..4d695875ea1b23 100644
+--- a/drivers/mtd/mtdswap.c
++++ b/drivers/mtd/mtdswap.c
+@@ -125,6 +125,7 @@ struct mtdswap_dev {
+
+ char *page_buf;
+ char *oob_buf;
++ struct dentry *debugfs_stats;
+ };
+
+ struct mtdswap_oobdata {
+@@ -1262,7 +1263,8 @@ static int mtdswap_add_debugfs(struct mtdswap_dev *d)
+ if (IS_ERR_OR_NULL(root))
+ return -1;
+
+- debugfs_create_file("mtdswap_stats", S_IRUSR, root, d, &mtdswap_fops);
++ d->debugfs_stats = debugfs_create_file("mtdswap_stats", 0400, root,
++ d, &mtdswap_fops);
+
+ return 0;
+ }
+@@ -1463,6 +1465,7 @@ static void mtdswap_remove_dev(struct mtd_blktrans_dev *dev)
+ {
+ struct mtdswap_dev *d = MTDSWAP_MBD_TO_MTDSWAP(dev);
+
++ debugfs_remove(d->debugfs_stats);
+ del_mtd_blktrans_dev(dev);
+ mtdswap_cleanup(d);
+ kfree(d);
+diff --git a/drivers/mtd/nand/ecc-mtk.c b/drivers/mtd/nand/ecc-mtk.c
+index 9f9b201fe706a8..e2fb7596f49d71 100644
+--- a/drivers/mtd/nand/ecc-mtk.c
++++ b/drivers/mtd/nand/ecc-mtk.c
+@@ -115,8 +115,8 @@ static int mt7622_ecc_regs[] = {
+ [ECC_DECIRQ_STA] = 0x144,
+ };
+
+-static inline void mtk_ecc_wait_idle(struct mtk_ecc *ecc,
+- enum mtk_ecc_operation op)
++static inline int mtk_ecc_wait_idle(struct mtk_ecc *ecc,
++ enum mtk_ecc_operation op)
+ {
+ struct device *dev = ecc->dev;
+ u32 val;
+@@ -128,6 +128,8 @@ static inline void mtk_ecc_wait_idle(struct mtk_ecc *ecc,
+ if (ret)
+ dev_warn(dev, "%s NOT idle\n",
+ op == ECC_ENCODE ? "encoder" : "decoder");
++
++ return ret;
+ }
+
+ static irqreturn_t mtk_ecc_irq(int irq, void *id)
+@@ -304,7 +306,11 @@ int mtk_ecc_enable(struct mtk_ecc *ecc, struct mtk_ecc_config *config)
+ return ret;
+ }
+
+- mtk_ecc_wait_idle(ecc, op);
++ ret = mtk_ecc_wait_idle(ecc, op);
++ if (ret) {
++ mutex_unlock(&ecc->lock);
++ return ret;
++ }
+
+ ret = mtk_ecc_config(ecc, config);
+ if (ret) {
+@@ -404,7 +410,9 @@ int mtk_ecc_encode(struct mtk_ecc *ecc, struct mtk_ecc_config *config,
+ if (ret)
+ goto timeout;
+
+- mtk_ecc_wait_idle(ecc, ECC_ENCODE);
++ ret = mtk_ecc_wait_idle(ecc, ECC_ENCODE);
++ if (ret)
++ goto timeout;
+
+ /* Program ECC bytes to OOB: per sector oob = FDM + ECC + SPARE */
+ len = (config->strength * ecc->caps->parity_bits + 7) >> 3;
+diff --git a/drivers/net/amt.c b/drivers/net/amt.c
+index f2da0c49171f5d..4799f8fd03c45c 100644
+--- a/drivers/net/amt.c
++++ b/drivers/net/amt.c
+@@ -1206,7 +1206,7 @@ static netdev_tx_t amt_dev_xmit(struct sk_buff *skb, struct net_device *dev)
+ data = true;
+ }
+ v6 = false;
+- group.ip4 = iph->daddr;
++ group.ip4 = ip_hdr(skb)->daddr;
+ #if IS_ENABLED(CONFIG_IPV6)
+ } else if (iph->version == 6) {
+ ip6h = ipv6_hdr(skb);
+@@ -1230,7 +1230,7 @@ static netdev_tx_t amt_dev_xmit(struct sk_buff *skb, struct net_device *dev)
+ data = true;
+ }
+ v6 = true;
+- group.ip6 = ip6h->daddr;
++ group.ip6 = ipv6_hdr(skb)->daddr;
+ #endif
+ } else {
+ dev->stats.tx_errors++;
+@@ -1273,12 +1273,12 @@ static netdev_tx_t amt_dev_xmit(struct sk_buff *skb, struct net_device *dev)
+ hlist_for_each_entry_rcu(gnode, &tunnel->groups[hash],
+ node) {
+ if (!v6) {
+- if (gnode->group_addr.ip4 == iph->daddr)
++ if (gnode->group_addr.ip4 == group.ip4)
+ goto found;
+ #if IS_ENABLED(CONFIG_IPV6)
+ } else {
+ if (ipv6_addr_equal(&gnode->group_addr.ip6,
+- &ip6h->daddr))
++ &group.ip6))
+ goto found;
+ #endif
+ }
+@@ -1995,14 +1995,18 @@ static void amt_igmpv3_report_handler(struct amt_dev *amt, struct sk_buff *skb,
+ struct igmpv3_report *ihrv3 = igmpv3_report_hdr(skb);
+ int len = skb_transport_offset(skb) + sizeof(*ihrv3);
+ void *zero_grec = (void *)&igmpv3_zero_grec;
+- struct iphdr *iph = ip_hdr(skb);
+ struct amt_group_node *gnode;
+ union amt_addr group, host;
+ struct igmpv3_grec *grec;
++ __be32 saddr;
+ u16 nsrcs;
++ u16 ngrec;
+ int i;
+
+- for (i = 0; i < ntohs(ihrv3->ngrec); i++) {
++ saddr = ip_hdr(skb)->saddr;
++ ngrec = ntohs(ihrv3->ngrec);
++
++ for (i = 0; i < ngrec; i++) {
+ len += sizeof(*grec);
+ if (!ip_mc_may_pull(skb, len))
+ break;
+@@ -2014,10 +2018,13 @@ static void amt_igmpv3_report_handler(struct amt_dev *amt, struct sk_buff *skb,
+ if (!ip_mc_may_pull(skb, len))
+ break;
+
++ grec = (void *)(skb->data + len - sizeof(*grec) -
++ nsrcs * sizeof(__be32));
++
+ memset(&group, 0, sizeof(union amt_addr));
+ group.ip4 = grec->grec_mca;
+ memset(&host, 0, sizeof(union amt_addr));
+- host.ip4 = iph->saddr;
++ host.ip4 = saddr;
+ gnode = amt_lookup_group(tunnel, &group, &host, false);
+ if (!gnode) {
+ gnode = amt_add_group(amt, tunnel, &group, &host,
+@@ -2157,14 +2164,18 @@ static void amt_mldv2_report_handler(struct amt_dev *amt, struct sk_buff *skb,
+ struct mld2_report *mld2r = (struct mld2_report *)icmp6_hdr(skb);
+ int len = skb_transport_offset(skb) + sizeof(*mld2r);
+ void *zero_grec = (void *)&mldv2_zero_grec;
+- struct ipv6hdr *ip6h = ipv6_hdr(skb);
+ struct amt_group_node *gnode;
+ union amt_addr group, host;
+ struct mld2_grec *grec;
++ struct in6_addr saddr;
+ u16 nsrcs;
++ u16 ngrec;
+ int i;
+
+- for (i = 0; i < ntohs(mld2r->mld2r_ngrec); i++) {
++ saddr = ipv6_hdr(skb)->saddr;
++ ngrec = ntohs(mld2r->mld2r_ngrec);
++
++ for (i = 0; i < ngrec; i++) {
+ len += sizeof(*grec);
+ if (!ipv6_mc_may_pull(skb, len))
+ break;
+@@ -2176,10 +2187,13 @@ static void amt_mldv2_report_handler(struct amt_dev *amt, struct sk_buff *skb,
+ if (!ipv6_mc_may_pull(skb, len))
+ break;
+
++ grec = (void *)(skb->data + len - sizeof(*grec) -
++ nsrcs * sizeof(struct in6_addr));
++
+ memset(&group, 0, sizeof(union amt_addr));
+ group.ip6 = grec->grec_mca;
+ memset(&host, 0, sizeof(union amt_addr));
+- host.ip6 = ip6h->saddr;
++ host.ip6 = saddr;
+ gnode = amt_lookup_group(tunnel, &group, &host, true);
+ if (!gnode) {
+ gnode = amt_add_group(amt, tunnel, &group, &host,
+@@ -2300,7 +2314,9 @@ static bool amt_multicast_data_handler(struct amt_dev *amt, struct sk_buff *skb)
+ skb_push(skb, sizeof(*eth));
+ skb_reset_mac_header(skb);
+ skb_pull(skb, sizeof(*eth));
+- eth = eth_hdr(skb);
++
++ if (skb_cow_head(skb, 0))
++ return true;
+
+ if (!pskb_may_pull(skb, sizeof(*iph)))
+ return true;
+@@ -2310,6 +2326,7 @@ static bool amt_multicast_data_handler(struct amt_dev *amt, struct sk_buff *skb)
+ if (!ipv4_is_multicast(iph->daddr))
+ return true;
+ skb->protocol = htons(ETH_P_IP);
++ eth = eth_hdr(skb);
+ eth->h_proto = htons(ETH_P_IP);
+ ip_eth_mc_map(iph->daddr, eth->h_dest);
+ #if IS_ENABLED(CONFIG_IPV6)
+@@ -2323,6 +2340,7 @@ static bool amt_multicast_data_handler(struct amt_dev *amt, struct sk_buff *skb)
+ if (!ipv6_addr_is_multicast(&ip6h->daddr))
+ return true;
+ skb->protocol = htons(ETH_P_IPV6);
++ eth = eth_hdr(skb);
+ eth->h_proto = htons(ETH_P_IPV6);
+ ipv6_eth_mc_map(&ip6h->daddr, eth->h_dest);
+ #endif
+@@ -2346,10 +2364,12 @@ static bool amt_membership_query_handler(struct amt_dev *amt,
+ struct sk_buff *skb)
+ {
+ struct amt_header_membership_query *amtmq;
+- struct igmpv3_query *ihv3;
+ struct ethhdr *eth, *oeth;
++ struct igmpv3_query *ihv3;
++ u8 h_source[ETH_ALEN];
+ struct iphdr *iph;
+ int hdr_size, len;
++ u64 response_mac;
+
+ hdr_size = sizeof(*amtmq) + sizeof(struct udphdr);
+ if (!pskb_may_pull(skb, hdr_size))
+@@ -2362,6 +2382,8 @@ static bool amt_membership_query_handler(struct amt_dev *amt,
+ if (amtmq->nonce != amt->nonce)
+ return true;
+
++ response_mac = amtmq->response_mac;
++
+ hdr_size -= sizeof(*eth);
+ if (iptunnel_pull_header(skb, hdr_size, htons(ETH_P_TEB), false))
+ return true;
+@@ -2371,6 +2393,9 @@ static bool amt_membership_query_handler(struct amt_dev *amt,
+ skb_pull(skb, sizeof(*eth));
+ skb_reset_network_header(skb);
+ eth = eth_hdr(skb);
++ ether_addr_copy(h_source, oeth->h_source);
++ if (skb_cow_head(skb, 0))
++ return true;
+ if (!pskb_may_pull(skb, sizeof(*iph)))
+ return true;
+
+@@ -2383,6 +2408,7 @@ static bool amt_membership_query_handler(struct amt_dev *amt,
+ sizeof(*ihv3)))
+ return true;
+
++ iph = ip_hdr(skb);
+ if (!ipv4_is_multicast(iph->daddr))
+ return true;
+
+@@ -2390,10 +2416,11 @@ static bool amt_membership_query_handler(struct amt_dev *amt,
+ skb_reset_transport_header(skb);
+ skb_push(skb, sizeof(*iph) + AMT_IPHDR_OPTS);
+ WRITE_ONCE(amt->ready4, true);
+- amt->mac = amtmq->response_mac;
++ amt->mac = response_mac;
+ amt->req_cnt = 0;
+ amt->qi = ihv3->qqic;
+ skb->protocol = htons(ETH_P_IP);
++ eth = eth_hdr(skb);
+ eth->h_proto = htons(ETH_P_IP);
+ ip_eth_mc_map(iph->daddr, eth->h_dest);
+ #if IS_ENABLED(CONFIG_IPV6)
+@@ -2416,10 +2443,11 @@ static bool amt_membership_query_handler(struct amt_dev *amt,
+ skb_reset_transport_header(skb);
+ skb_push(skb, sizeof(*ip6h) + AMT_IP6HDR_OPTS);
+ WRITE_ONCE(amt->ready6, true);
+- amt->mac = amtmq->response_mac;
++ amt->mac = response_mac;
+ amt->req_cnt = 0;
+ amt->qi = mld2q->mld2q_qqic;
+ skb->protocol = htons(ETH_P_IPV6);
++ eth = eth_hdr(skb);
+ eth->h_proto = htons(ETH_P_IPV6);
+ ipv6_eth_mc_map(&ip6h->daddr, eth->h_dest);
+ #endif
+@@ -2427,7 +2455,7 @@ static bool amt_membership_query_handler(struct amt_dev *amt,
+ return true;
+ }
+
+- ether_addr_copy(eth->h_source, oeth->h_source);
++ ether_addr_copy(eth->h_source, h_source);
+ skb->pkt_type = PACKET_MULTICAST;
+ skb->ip_summed = CHECKSUM_NONE;
+ len = skb->len;
+@@ -2450,8 +2478,11 @@ static bool amt_update_handler(struct amt_dev *amt, struct sk_buff *skb)
+ struct ethhdr *eth;
+ struct iphdr *iph;
+ int len, hdr_size;
++ u64 response_mac;
++ __be32 saddr;
++ __be32 nonce;
+
+- iph = ip_hdr(skb);
++ saddr = ip_hdr(skb)->saddr;
+
+ hdr_size = sizeof(*amtmu) + sizeof(struct udphdr);
+ if (!pskb_may_pull(skb, hdr_size))
+@@ -2461,15 +2492,18 @@ static bool amt_update_handler(struct amt_dev *amt, struct sk_buff *skb)
+ if (amtmu->reserved || amtmu->version)
+ return true;
+
++ nonce = amtmu->nonce;
++ response_mac = amtmu->response_mac;
++
+ if (iptunnel_pull_header(skb, hdr_size, skb->protocol, false))
+ return true;
+
+ skb_reset_network_header(skb);
+
+ list_for_each_entry_rcu(tunnel, &amt->tunnel_list, list) {
+- if (tunnel->ip4 == iph->saddr) {
+- if ((amtmu->nonce == tunnel->nonce &&
+- amtmu->response_mac == tunnel->mac)) {
++ if (tunnel->ip4 == saddr) {
++ if ((nonce == tunnel->nonce &&
++ response_mac == tunnel->mac)) {
+ mod_delayed_work(amt_wq, &tunnel->gc_wq,
+ msecs_to_jiffies(amt_gmi(amt))
+ * 3);
+@@ -2487,6 +2521,9 @@ report:
+ if (!pskb_may_pull(skb, sizeof(*iph)))
+ return true;
+
++ if (skb_cow_head(skb, 0))
++ return true;
++
+ iph = ip_hdr(skb);
+ if (iph->version == 4) {
+ if (ip_mc_check_igmp(skb)) {
+@@ -2503,6 +2540,7 @@ report:
+ eth = eth_hdr(skb);
+ skb->protocol = htons(ETH_P_IP);
+ eth->h_proto = htons(ETH_P_IP);
++ iph = ip_hdr(skb);
+ ip_eth_mc_map(iph->daddr, eth->h_dest);
+ #if IS_ENABLED(CONFIG_IPV6)
+ } else if (iph->version == 6) {
+@@ -2522,6 +2560,7 @@ report:
+ eth = eth_hdr(skb);
+ skb->protocol = htons(ETH_P_IPV6);
+ eth->h_proto = htons(ETH_P_IPV6);
++ ip6h = ipv6_hdr(skb);
+ ipv6_eth_mc_map(&ip6h->daddr, eth->h_dest);
+ #endif
+ } else {
+@@ -2767,7 +2806,7 @@ drop:
+ static int amt_rcv(struct sock *sk, struct sk_buff *skb)
+ {
+ struct amt_dev *amt;
+- struct iphdr *iph;
++ __be32 saddr;
+ int type;
+ bool err;
+
+@@ -2780,7 +2819,7 @@ static int amt_rcv(struct sock *sk, struct sk_buff *skb)
+ }
+
+ skb->dev = amt->dev;
+- iph = ip_hdr(skb);
++ saddr = ip_hdr(skb)->saddr;
+ type = amt_parse_type(skb);
+ if (type == -1) {
+ err = true;
+@@ -2790,7 +2829,7 @@ static int amt_rcv(struct sock *sk, struct sk_buff *skb)
+ if (amt->mode == AMT_MODE_GATEWAY) {
+ switch (type) {
+ case AMT_MSG_ADVERTISEMENT:
+- if (iph->saddr != amt->discovery_ip) {
++ if (saddr != amt->discovery_ip) {
+ netdev_dbg(amt->dev, "Invalid Relay IP\n");
+ err = true;
+ goto drop;
+@@ -2802,7 +2841,7 @@ static int amt_rcv(struct sock *sk, struct sk_buff *skb)
+ }
+ goto out;
+ case AMT_MSG_MULTICAST_DATA:
+- if (iph->saddr != amt->remote_ip) {
++ if (saddr != amt->remote_ip) {
+ netdev_dbg(amt->dev, "Invalid Relay IP\n");
+ err = true;
+ goto drop;
+@@ -2813,7 +2852,7 @@ static int amt_rcv(struct sock *sk, struct sk_buff *skb)
+ else
+ goto out;
+ case AMT_MSG_MEMBERSHIP_QUERY:
+- if (iph->saddr != amt->remote_ip) {
++ if (saddr != amt->remote_ip) {
+ netdev_dbg(amt->dev, "Invalid Relay IP\n");
+ err = true;
+ goto drop;
+diff --git a/drivers/net/bonding/bond_alb.c b/drivers/net/bonding/bond_alb.c
+index 9c4c2c7d90ef5f..c44a9358f8b27e 100644
+--- a/drivers/net/bonding/bond_alb.c
++++ b/drivers/net/bonding/bond_alb.c
+@@ -1535,8 +1535,8 @@ void bond_alb_monitor(struct work_struct *work)
+ struct bonding *bond = container_of(work, struct bonding,
+ alb_work.work);
+ struct alb_bond_info *bond_info = &(BOND_ALB_INFO(bond));
++ struct slave *slave, *curr;
+ struct list_head *iter;
+- struct slave *slave;
+
+ if (!bond_has_slaves(bond)) {
+ atomic_set(&bond_info->tx_rebalance_counter, 0);
+@@ -1598,9 +1598,11 @@ void bond_alb_monitor(struct work_struct *work)
+ * because a slave was disabled then
+ * it can now leave promiscuous mode.
+ */
+- dev_set_promiscuity(rtnl_dereference(bond->curr_active_slave)->dev,
+- -1);
+- bond_info->primary_is_promisc = 0;
++ curr = rtnl_dereference(bond->curr_active_slave);
++ if (bond_info->primary_is_promisc && curr) {
++ dev_set_promiscuity(curr->dev, -1);
++ bond_info->primary_is_promisc = 0;
++ }
+
+ rtnl_unlock();
+ rcu_read_lock();
+diff --git a/drivers/net/bonding/bond_main.c b/drivers/net/bonding/bond_main.c
+index 9898d85075d150..5a71893fc6a962 100644
+--- a/drivers/net/bonding/bond_main.c
++++ b/drivers/net/bonding/bond_main.c
+@@ -3415,7 +3415,8 @@ static void bond_send_validate(struct bonding *bond, struct slave *slave)
+ {
+ bond_arp_send_all(bond, slave);
+ #if IS_ENABLED(CONFIG_IPV6)
+- bond_ns_send_all(bond, slave);
++ if (likely(ipv6_mod_enabled()))
++ bond_ns_send_all(bond, slave);
+ #endif
+ }
+
+diff --git a/drivers/net/can/c_can/c_can_main.c b/drivers/net/can/c_can/c_can_main.c
+index cc371d0c9f3c76..2ea5224ebfcb57 100644
+--- a/drivers/net/can/c_can/c_can_main.c
++++ b/drivers/net/can/c_can/c_can_main.c
+@@ -597,20 +597,20 @@ static int c_can_chip_config(struct net_device *dev)
+ return err;
+
+ /* enable automatic retransmission */
+- priv->write_reg(priv, C_CAN_CTRL_REG, CONTROL_ENABLE_AR);
++ priv->write_reg(priv, C_CAN_CTRL_REG, CONTROL_ENABLE_AR | CONTROL_INIT);
+
+ if ((priv->can.ctrlmode & CAN_CTRLMODE_LISTENONLY) &&
+ (priv->can.ctrlmode & CAN_CTRLMODE_LOOPBACK)) {
+ /* loopback + silent mode : useful for hot self-test */
+- priv->write_reg(priv, C_CAN_CTRL_REG, CONTROL_TEST);
++ priv->write_reg(priv, C_CAN_CTRL_REG, CONTROL_TEST | CONTROL_INIT);
+ priv->write_reg(priv, C_CAN_TEST_REG, TEST_LBACK | TEST_SILENT);
+ } else if (priv->can.ctrlmode & CAN_CTRLMODE_LOOPBACK) {
+ /* loopback mode : useful for self-test function */
+- priv->write_reg(priv, C_CAN_CTRL_REG, CONTROL_TEST);
++ priv->write_reg(priv, C_CAN_CTRL_REG, CONTROL_TEST | CONTROL_INIT);
+ priv->write_reg(priv, C_CAN_TEST_REG, TEST_LBACK);
+ } else if (priv->can.ctrlmode & CAN_CTRLMODE_LISTENONLY) {
+ /* silent mode : bus-monitoring mode */
+- priv->write_reg(priv, C_CAN_CTRL_REG, CONTROL_TEST);
++ priv->write_reg(priv, C_CAN_CTRL_REG, CONTROL_TEST | CONTROL_INIT);
+ priv->write_reg(priv, C_CAN_TEST_REG, TEST_SILENT);
+ }
+
+diff --git a/drivers/net/can/ctucanfd/ctucanfd_base.c b/drivers/net/can/ctucanfd/ctucanfd_base.c
+index 0d40564febeef0..31fc0b8573bbd8 100644
+--- a/drivers/net/can/ctucanfd/ctucanfd_base.c
++++ b/drivers/net/can/ctucanfd/ctucanfd_base.c
+@@ -340,8 +340,8 @@ static void ctucan_set_mode(struct ctucan_priv *priv, const struct can_ctrlmode
+ (mode_reg & ~REG_MODE_FDE);
+
+ mode_reg = (mode->flags & CAN_CTRLMODE_PRESUME_ACK) ?
+- (mode_reg | REG_MODE_ACF) :
+- (mode_reg & ~REG_MODE_ACF);
++ (mode_reg | REG_MODE_STM) :
++ (mode_reg & ~REG_MODE_STM);
+
+ mode_reg = (mode->flags & CAN_CTRLMODE_FD_NON_ISO) ?
+ (mode_reg | REG_MODE_NISOFD) :
+@@ -868,7 +868,7 @@ static void ctucan_err_interrupt(struct net_device *ndev, u32 isr)
+ break;
+ case CAN_STATE_ERROR_ACTIVE:
+ if (skb) {
+- cf->can_id |= CAN_ERR_CNT;
++ cf->can_id |= CAN_ERR_CRTL | CAN_ERR_CNT;
+ cf->data[1] = CAN_ERR_CRTL_ACTIVE;
+ cf->data[6] = bec.txerr;
+ cf->data[7] = bec.rxerr;
+@@ -1135,8 +1135,12 @@ static irqreturn_t ctucan_interrupt(int irq, void *dev_id)
+ /* Error interrupts */
+ if (FIELD_GET(REG_INT_STAT_EWLI, isr) ||
+ FIELD_GET(REG_INT_STAT_FCSI, isr) ||
+- FIELD_GET(REG_INT_STAT_ALI, isr)) {
+- icr = isr & (REG_INT_STAT_EWLI | REG_INT_STAT_FCSI | REG_INT_STAT_ALI);
++ FIELD_GET(REG_INT_STAT_ALI, isr) ||
++ FIELD_GET(REG_INT_STAT_BEI, isr)) {
++ icr = isr & (REG_INT_STAT_EWLI |
++ REG_INT_STAT_FCSI |
++ REG_INT_STAT_ALI |
++ REG_INT_STAT_BEI);
+
+ ctucan_netdev_dbg(ndev, "some ERR interrupt: clearing 0x%08x\n", icr);
+ ctucan_write32(priv, CTUCANFD_INT_STAT, icr);
+diff --git a/drivers/net/can/ctucanfd/ctucanfd_pci.c b/drivers/net/can/ctucanfd/ctucanfd_pci.c
+index 8f2956a8ae4330..bc54f94267473b 100644
+--- a/drivers/net/can/ctucanfd/ctucanfd_pci.c
++++ b/drivers/net/can/ctucanfd/ctucanfd_pci.c
+@@ -202,7 +202,7 @@ err_free_board:
+ pci_set_drvdata(pdev, NULL);
+ kfree(bdata);
+ err_pci_iounmap_bar0:
+- pci_iounmap(pdev, cra_addr);
++ pci_iounmap(pdev, bar0_base);
+ err_pci_iounmap_bar1:
+ pci_iounmap(pdev, addr);
+ err_release_regions:
+@@ -278,6 +278,7 @@ static const struct pci_device_id ctucan_pci_tbl[] = {
+ CTUCAN_WITH_CTUCAN_ID)},
+ {},
+ };
++MODULE_DEVICE_TABLE(pci, ctucan_pci_tbl);
+
+ static struct pci_driver ctucan_pci_driver = {
+ .name = KBUILD_MODNAME,
+diff --git a/drivers/net/can/softing/softing_fw.c b/drivers/net/can/softing/softing_fw.c
+index 32286f861a1956..6776577a0bbaa8 100644
+--- a/drivers/net/can/softing/softing_fw.c
++++ b/drivers/net/can/softing/softing_fw.c
+@@ -91,12 +91,12 @@ int softing_bootloader_command(struct softing *card, int16_t cmd,
+ return ret;
+ }
+
+-static int fw_parse(const uint8_t **pmem, uint16_t *ptype, uint32_t *paddr,
+- uint16_t *plen, const uint8_t **pdat)
++static int fw_parse(const u8 **pmem, const u8 *limit, u16 *ptype,
++ u32 *paddr, u16 *plen, const u8 **pdat)
+ {
+ uint16_t checksum[2];
+- const uint8_t *mem;
+- const uint8_t *end;
++ const u8 *mem;
++ const u8 *record_end;
+
+ /*
+ * firmware records are a binary, unaligned stream composed of:
+@@ -114,14 +114,21 @@ static int fw_parse(const uint8_t **pmem, uint16_t *ptype, uint32_t *paddr,
+ * endianness & alignment.
+ */
+ mem = *pmem;
++ /* A record needs an 8-byte prefix and a 2-byte checksum. */
++ if (mem > limit || limit - mem < 10)
++ return -EINVAL;
++
+ *ptype = le16_to_cpup((void *)&mem[0]);
+ *paddr = le32_to_cpup((void *)&mem[2]);
+ *plen = le16_to_cpup((void *)&mem[6]);
++ if (*plen > limit - mem - 10)
++ return -EINVAL;
++
+ *pdat = &mem[8];
+ /* verify checksum */
+- end = &mem[8 + *plen];
+- checksum[0] = le16_to_cpup((void *)end);
+- for (checksum[1] = 0; mem < end; ++mem)
++ record_end = &mem[8 + *plen];
++ checksum[0] = le16_to_cpup((void *)record_end);
++ for (checksum[1] = 0; mem < record_end; ++mem)
+ checksum[1] += *mem;
+ if (checksum[0] != checksum[1])
+ return -EINVAL;
+@@ -139,6 +146,7 @@ int softing_load_fw(const char *file, struct softing *card,
+ uint16_t type, len;
+ uint32_t addr;
+ uint8_t *buf = NULL, *new_buf;
++ s64 dpram_offset;
+ int buflen = 0;
+ int8_t type_end = 0;
+
+@@ -153,7 +161,7 @@ int softing_load_fw(const char *file, struct softing *card,
+ mem = fw->data;
+ end = &mem[fw->size];
+ /* look for header record */
+- ret = fw_parse(&mem, &type, &addr, &len, &dat);
++ ret = fw_parse(&mem, end, &type, &addr, &len, &dat);
+ if (ret < 0)
+ goto failed;
+ if (type != 0xffff)
+@@ -164,7 +172,7 @@ int softing_load_fw(const char *file, struct softing *card,
+ }
+ /* ok, we had a header */
+ while (mem < end) {
+- ret = fw_parse(&mem, &type, &addr, &len, &dat);
++ ret = fw_parse(&mem, end, &type, &addr, &len, &dat);
+ if (ret < 0)
+ goto failed;
+ if (type == 3) {
+@@ -179,9 +187,13 @@ int softing_load_fw(const char *file, struct softing *card,
+ goto failed;
+ }
+
+- if ((addr + len + offset) > size)
++ dpram_offset = (s64)addr + offset;
++ if (dpram_offset < 0 || dpram_offset > size ||
++ len > size - dpram_offset) {
++ ret = -EINVAL;
+ goto failed;
+- memcpy_toio(&dpram[addr + offset], dat, len);
++ }
++ memcpy_toio(&dpram[dpram_offset], dat, len);
+ /* be sure to flush caches from IO space */
+ mb();
+ if (len > buflen) {
+@@ -195,7 +207,7 @@ int softing_load_fw(const char *file, struct softing *card,
+ buf = new_buf;
+ }
+ /* verify record data */
+- memcpy_fromio(buf, &dpram[addr + offset], len);
++ memcpy_fromio(buf, &dpram[dpram_offset], len);
+ if (memcmp(buf, dat, len)) {
+ /* is not ok */
+ dev_alert(&card->pdev->dev, "DPRAM readback failed\n");
+@@ -237,7 +249,7 @@ int softing_load_app_fw(const char *file, struct softing *card)
+ mem = fw->data;
+ end = &mem[fw->size];
+ /* look for header record */
+- ret = fw_parse(&mem, &type, &addr, &len, &dat);
++ ret = fw_parse(&mem, end, &type, &addr, &len, &dat);
+ if (ret)
+ goto failed;
+ ret = -EINVAL;
+@@ -253,7 +265,7 @@ int softing_load_app_fw(const char *file, struct softing *card)
+ }
+ /* ok, we had a header */
+ while (mem < end) {
+- ret = fw_parse(&mem, &type, &addr, &len, &dat);
++ ret = fw_parse(&mem, end, &type, &addr, &len, &dat);
+ if (ret)
+ goto failed;
+
+@@ -279,6 +291,12 @@ int softing_load_app_fw(const char *file, struct softing *card)
+ /* work in 16bit (target) */
+ sum &= 0xffff;
+
++ if (card->pdat->app.offs > card->dpram_size ||
++ len > card->dpram_size - card->pdat->app.offs) {
++ ret = -EINVAL;
++ goto failed;
++ }
++
+ memcpy_toio(&card->dpram[card->pdat->app.offs], dat, len);
+ iowrite32(card->pdat->app.offs + card->pdat->app.addr,
+ &card->dpram[DPRAM_COMMAND + 2]);
+diff --git a/drivers/net/can/usb/ems_usb.c b/drivers/net/can/usb/ems_usb.c
+index d8c881130e9008..4b130c96c9ab20 100644
+--- a/drivers/net/can/usb/ems_usb.c
++++ b/drivers/net/can/usb/ems_usb.c
+@@ -409,6 +409,40 @@ static void ems_usb_rx_err(struct ems_usb *dev, struct ems_cpc_msg *msg)
+ netif_rx(skb);
+ }
+
++static bool ems_usb_rx_msg_len_valid(struct ems_cpc_msg *msg)
++{
++ size_t len = msg->length;
++ size_t can_len;
++
++ switch (msg->type) {
++ case CPC_MSG_TYPE_CAN_STATE:
++ return len >= sizeof(msg->msg.can_state);
++
++ case CPC_MSG_TYPE_CAN_FRAME:
++ case CPC_MSG_TYPE_EXT_CAN_FRAME:
++ case CPC_MSG_TYPE_RTR_FRAME:
++ case CPC_MSG_TYPE_EXT_RTR_FRAME:
++ if (len < CPC_CAN_MSG_MIN_SIZE)
++ return false;
++
++ if (msg->type == CPC_MSG_TYPE_RTR_FRAME ||
++ msg->type == CPC_MSG_TYPE_EXT_RTR_FRAME)
++ return true;
++
++ can_len = can_cc_dlc2len(msg->msg.can_msg.length & 0xf);
++ return len >= CPC_CAN_MSG_MIN_SIZE + can_len;
++
++ case CPC_MSG_TYPE_CAN_FRAME_ERROR:
++ return len >= sizeof(msg->msg.error);
++
++ case CPC_MSG_TYPE_OVERRUN:
++ return len >= sizeof(msg->msg.overrun);
++
++ default:
++ return true;
++ }
++}
++
+ /*
+ * callback for bulk IN urb
+ */
+@@ -451,6 +485,15 @@ static void ems_usb_read_bulk_callback(struct urb *urb)
+ }
+
+ msg = (struct ems_cpc_msg *)&ibuf[start];
++ if (msg->length >
++ urb->actual_length - start - CPC_MSG_HEADER_LEN) {
++ netdev_err(netdev, "format error\n");
++ break;
++ }
++ if (!ems_usb_rx_msg_len_valid(msg)) {
++ netdev_err(netdev, "format error\n");
++ break;
++ }
+
+ switch (msg->type) {
+ case CPC_MSG_TYPE_CAN_STATE:
+diff --git a/drivers/net/can/usb/etas_es58x/es58x_core.c b/drivers/net/can/usb/etas_es58x/es58x_core.c
+index d43c7da06229b3..ae881024b4bce2 100644
+--- a/drivers/net/can/usb/etas_es58x/es58x_core.c
++++ b/drivers/net/can/usb/etas_es58x/es58x_core.c
+@@ -1475,7 +1475,6 @@ static void es58x_read_bulk_callback(struct urb *urb)
+ dev_err_ratelimited(dev,
+ "Failed resubmitting read bulk urb: %pe\n",
+ ERR_PTR(ret));
+- return;
+
+ free_urb:
+ usb_free_coherent(urb->dev, urb->transfer_buffer_length,
+diff --git a/drivers/net/can/usb/kvaser_usb/kvaser_usb_hydra.c b/drivers/net/can/usb/kvaser_usb/kvaser_usb_hydra.c
+index ef341c4254fc8b..25de0e76ad2c77 100644
+--- a/drivers/net/can/usb/kvaser_usb/kvaser_usb_hydra.c
++++ b/drivers/net/can/usb/kvaser_usb/kvaser_usb_hydra.c
+@@ -1605,6 +1605,7 @@ static int kvaser_usb_hydra_get_busparams(struct kvaser_usb_net_priv *priv,
+ reinit_completion(&priv->get_busparams_comp);
+
+ err = kvaser_usb_send_cmd(dev, cmd, cmd_len);
++ kfree(cmd);
+ if (err)
+ return err;
+
+diff --git a/drivers/net/can/usb/kvaser_usb/kvaser_usb_leaf.c b/drivers/net/can/usb/kvaser_usb/kvaser_usb_leaf.c
+index 57c68bc926d8d3..a4c0c49f5bfa28 100644
+--- a/drivers/net/can/usb/kvaser_usb/kvaser_usb_leaf.c
++++ b/drivers/net/can/usb/kvaser_usb/kvaser_usb_leaf.c
+@@ -614,13 +614,22 @@ static int kvaser_usb_leaf_wait_cmd(const struct kvaser_usb *dev, u8 id,
+ continue;
+ }
+
+- if (pos + tmp->len > actual_len) {
++ if (tmp->len < CMD_HEADER_LEN ||
++ tmp->len > actual_len - pos) {
+ dev_err_ratelimited(&dev->intf->dev,
+ "Format error\n");
+ break;
+ }
+
+ if (tmp->id == id) {
++ if (tmp->len > sizeof(*cmd)) {
++ dev_err_ratelimited(&dev->intf->dev,
++ "Received command %u too large (%u)\n",
++ tmp->id, tmp->len);
++ err = -EIO;
++ goto end;
++ }
++
+ memcpy(cmd, tmp, tmp->len);
+ goto end;
+ }
+@@ -1572,7 +1581,7 @@ static void kvaser_usb_leaf_read_bulk_callback(struct kvaser_usb *dev,
+ continue;
+ }
+
+- if (pos + cmd->len > len) {
++ if (cmd->len < CMD_HEADER_LEN || cmd->len > len - pos) {
+ dev_err_ratelimited(&dev->intf->dev, "Format error\n");
+ break;
+ }
+diff --git a/drivers/net/can/usb/peak_usb/pcan_usb_core.c b/drivers/net/can/usb/peak_usb/pcan_usb_core.c
+index 928a78947cb0b3..aed667f4ce983b 100644
+--- a/drivers/net/can/usb/peak_usb/pcan_usb_core.c
++++ b/drivers/net/can/usb/peak_usb/pcan_usb_core.c
+@@ -461,7 +461,6 @@ static int peak_usb_start(struct peak_usb_device *dev)
+ netif_device_detach(dev->netdev);
+
+ usb_unanchor_urb(urb);
+- kfree(buf);
+ usb_free_urb(urb);
+ break;
+ }
+diff --git a/drivers/net/can/usb/peak_usb/pcan_usb_fd.c b/drivers/net/can/usb/peak_usb/pcan_usb_fd.c
+index a203b7fca2f363..f42084e44caaef 100644
+--- a/drivers/net/can/usb/peak_usb/pcan_usb_fd.c
++++ b/drivers/net/can/usb/peak_usb/pcan_usb_fd.c
+@@ -519,6 +519,13 @@ static int pcan_usb_fd_decode_canmsg(struct pcan_usb_fd_if *usb_if,
+ dev->can.ctrlmode);
+ }
+
++ if (!(rx_msg_flags & PUCAN_MSG_RTR) &&
++ le16_to_cpu(rx_msg->size) - offsetof(struct pucan_rx_msg, d) <
++ cfd->len) {
++ kfree_skb(skb);
++ return -EBADMSG;
++ }
++
+ cfd->can_id = le32_to_cpu(rm->can_id);
+
+ if (rx_msg_flags & PUCAN_MSG_EXT_ID)
+@@ -667,6 +674,24 @@ static void pcan_usb_fd_decode_ts(struct pcan_usb_fd_if *usb_if,
+ peak_usb_set_ts_now(&usb_if->time_ref, le32_to_cpu(ts->ts_low));
+ }
+
++static size_t pcan_usb_fd_rx_msg_min_size(u16 rx_msg_type)
++{
++ switch (rx_msg_type) {
++ case PUCAN_MSG_CAN_RX:
++ return offsetof(struct pucan_rx_msg, d);
++ case PCAN_UFD_MSG_CALIBRATION:
++ return sizeof(struct pcan_ufd_ts_msg);
++ case PUCAN_MSG_ERROR:
++ return sizeof(struct pucan_error_msg);
++ case PUCAN_MSG_STATUS:
++ return sizeof(struct pucan_status_msg);
++ case PCAN_UFD_MSG_OVERRUN:
++ return sizeof(struct pcan_ufd_ovr_msg);
++ default:
++ return sizeof(struct pucan_msg);
++ }
++}
++
+ /* callback for bulk IN urb */
+ static int pcan_usb_fd_decode_buf(struct peak_usb_device *dev, struct urb *urb)
+ {
+@@ -681,6 +706,12 @@ static int pcan_usb_fd_decode_buf(struct peak_usb_device *dev, struct urb *urb)
+ msg_end = urb->transfer_buffer + urb->actual_length;
+ for (; msg_ptr < msg_end;) {
+ u16 rx_msg_type, rx_msg_size;
++ size_t rx_msg_min_size;
++
++ if (msg_end - msg_ptr < sizeof(*rx_msg)) {
++ err = -EBADMSG;
++ break;
++ }
+
+ rx_msg = (struct pucan_msg *)msg_ptr;
+ if (!rx_msg->size) {
+@@ -692,13 +723,20 @@ static int pcan_usb_fd_decode_buf(struct peak_usb_device *dev, struct urb *urb)
+ rx_msg_type = le16_to_cpu(rx_msg->type);
+
+ /* check if the record goes out of current packet */
+- if (msg_ptr + rx_msg_size > msg_end) {
++ if (rx_msg_size > msg_end - msg_ptr) {
+ netdev_err(netdev,
+ "got frag rec: should inc usb rx buf sze\n");
+ err = -EBADMSG;
+ break;
+ }
+
++ rx_msg_min_size = pcan_usb_fd_rx_msg_min_size(rx_msg_type);
++ if (rx_msg_size < rx_msg_min_size) {
++ netdev_err(netdev, "got short rec\n");
++ err = -EBADMSG;
++ break;
++ }
++
+ switch (rx_msg_type) {
+ case PUCAN_MSG_CAN_RX:
+ err = pcan_usb_fd_decode_canmsg(usb_if, rx_msg);
+diff --git a/drivers/net/can/usb/peak_usb/pcan_usb_pro.c b/drivers/net/can/usb/peak_usb/pcan_usb_pro.c
+index 5d8f6a40bb2c1a..5550bee11148e9 100644
+--- a/drivers/net/can/usb/peak_usb/pcan_usb_pro.c
++++ b/drivers/net/can/usb/peak_usb/pcan_usb_pro.c
+@@ -520,12 +520,18 @@ static int pcan_usb_pro_handle_canmsg(struct pcan_usb_pro_interface *usb_if,
+ struct pcan_usb_pro_rxmsg *rx)
+ {
+ const unsigned int ctrl_idx = (rx->len >> 4) & 0x0f;
+- struct peak_usb_device *dev = usb_if->dev[ctrl_idx];
+- struct net_device *netdev = dev->netdev;
++ struct peak_usb_device *dev;
++ struct net_device *netdev;
+ struct can_frame *can_frame;
+ struct sk_buff *skb;
+ struct skb_shared_hwtstamps *hwts;
+
++ if (ctrl_idx >= ARRAY_SIZE(usb_if->dev))
++ return -EINVAL;
++
++ dev = usb_if->dev[ctrl_idx];
++ netdev = dev->netdev;
++
+ skb = alloc_can_skb(netdev, &can_frame);
+ if (!skb)
+ return -ENOMEM;
+@@ -559,14 +565,20 @@ static int pcan_usb_pro_handle_error(struct pcan_usb_pro_interface *usb_if,
+ {
+ const u16 raw_status = le16_to_cpu(er->status);
+ const unsigned int ctrl_idx = (er->channel >> 4) & 0x0f;
+- struct peak_usb_device *dev = usb_if->dev[ctrl_idx];
+- struct net_device *netdev = dev->netdev;
++ struct peak_usb_device *dev;
++ struct net_device *netdev;
+ struct can_frame *can_frame;
+ enum can_state new_state = CAN_STATE_ERROR_ACTIVE;
+ u8 err_mask = 0;
+ struct sk_buff *skb;
+ struct skb_shared_hwtstamps *hwts;
+
++ if (ctrl_idx >= ARRAY_SIZE(usb_if->dev))
++ return -EINVAL;
++
++ dev = usb_if->dev[ctrl_idx];
++ netdev = dev->netdev;
++
+ /* nothing should be sent while in BUS_OFF state */
+ if (dev->can.state == CAN_STATE_BUS_OFF)
+ return 0;
+diff --git a/drivers/net/ethernet/amd/xgbe/xgbe-mdio.c b/drivers/net/ethernet/amd/xgbe/xgbe-mdio.c
+index ebb8b3e5b9a882..01c37ffc9ceb81 100644
+--- a/drivers/net/ethernet/amd/xgbe/xgbe-mdio.c
++++ b/drivers/net/ethernet/amd/xgbe/xgbe-mdio.c
+@@ -364,9 +364,14 @@ static void xgbe_an37_set(struct xgbe_prv_data *pdata, bool enable,
+
+ XMDIO_WRITE(pdata, MDIO_MMD_VEND2, MDIO_CTRL1, reg);
+
+- reg = XMDIO_READ(pdata, MDIO_MMD_VEND2, MDIO_PCS_DIG_CTRL);
+- reg |= XGBE_VEND2_MAC_AUTO_SW;
+- XMDIO_WRITE(pdata, MDIO_MMD_VEND2, MDIO_PCS_DIG_CTRL, reg);
++ if (pdata->an_mode == XGBE_AN_MODE_CL37_SGMII) {
++ reg = XMDIO_READ(pdata, MDIO_MMD_VEND2, MDIO_PCS_DIG_CTRL);
++ if (enable)
++ reg |= XGBE_VEND2_MAC_AUTO_SW;
++ else
++ reg &= ~XGBE_VEND2_MAC_AUTO_SW;
++ XMDIO_WRITE(pdata, MDIO_MMD_VEND2, MDIO_PCS_DIG_CTRL, reg);
++ }
+ }
+
+ static void xgbe_an37_restart(struct xgbe_prv_data *pdata)
+diff --git a/drivers/net/ethernet/aquantia/atlantic/aq_ring.c b/drivers/net/ethernet/aquantia/atlantic/aq_ring.c
+index c8466ebd4a0317..0cc779d58cc42b 100644
+--- a/drivers/net/ethernet/aquantia/atlantic/aq_ring.c
++++ b/drivers/net/ethernet/aquantia/atlantic/aq_ring.c
+@@ -336,6 +336,35 @@ out:
+ return !!budget;
+ }
+
++void aq_ring_tx_deinit(struct aq_ring_s *self)
++{
++ if (!self)
++ return;
++
++ for (; self->sw_head != self->sw_tail;
++ self->sw_head = aq_ring_next_dx(self, self->sw_head)) {
++ struct aq_ring_buff_s *buff = &self->buff_ring[self->sw_head];
++ struct device *ndev = aq_nic_get_dev(self->aq_nic);
++
++ if (buff->is_mapped) {
++ if (buff->is_sop) {
++ dma_unmap_single(ndev, buff->pa, buff->len,
++ DMA_TO_DEVICE);
++ } else {
++ dma_unmap_page(ndev, buff->pa, buff->len,
++ DMA_TO_DEVICE);
++ }
++ }
++
++ if (buff->is_eop) {
++ if (buff->skb)
++ dev_kfree_skb_any(buff->skb);
++ else if (buff->xdpf)
++ xdp_return_frame(buff->xdpf);
++ }
++ }
++}
++
+ static void aq_rx_checksum(struct aq_ring_s *self,
+ struct aq_ring_buff_s *buff,
+ struct sk_buff *skb)
+@@ -897,15 +926,29 @@ err_exit:
+
+ void aq_ring_rx_deinit(struct aq_ring_s *self)
+ {
+- if (!self)
++ unsigned int i;
++
++ if (!self || !self->buff_ring)
+ return;
+
+- for (; self->sw_head != self->sw_tail;
+- self->sw_head = aq_ring_next_dx(self, self->sw_head)) {
+- struct aq_ring_buff_s *buff = &self->buff_ring[self->sw_head];
++ /* Release every page still owned by the ring.
++ *
++ * Walking [sw_head, sw_tail) is not enough: refill is batched
++ * (aq_ring_rx_fill() waits for AQ_CFG_RX_REFILL_THRES free slots),
++ * so slots that were cleaned but not yet reposted accumulate in the
++ * [sw_tail, sw_head) gap, and they keep their page for reuse. Walk
++ * the whole ring and release whatever is left.
++ */
++ for (i = 0; i < self->size; i++) {
++ struct aq_ring_buff_s *buff = &self->buff_ring[i];
++
++ if (!buff->rxdata.page)
++ continue;
+
+ aq_free_rxpage(&buff->rxdata, aq_nic_get_dev(self->aq_nic));
+ }
++
++ self->sw_head = self->sw_tail;
+ }
+
+ void aq_ring_free(struct aq_ring_s *self)
+diff --git a/drivers/net/ethernet/aquantia/atlantic/aq_ring.h b/drivers/net/ethernet/aquantia/atlantic/aq_ring.h
+index d627ace850ff54..67503c51267605 100644
+--- a/drivers/net/ethernet/aquantia/atlantic/aq_ring.h
++++ b/drivers/net/ethernet/aquantia/atlantic/aq_ring.h
+@@ -199,6 +199,7 @@ void aq_ring_update_queue_state(struct aq_ring_s *ring);
+ void aq_ring_queue_wake(struct aq_ring_s *ring);
+ void aq_ring_queue_stop(struct aq_ring_s *ring);
+ bool aq_ring_tx_clean(struct aq_ring_s *self);
++void aq_ring_tx_deinit(struct aq_ring_s *self);
+ int aq_xdp_xmit(struct net_device *dev, int num_frames,
+ struct xdp_frame **frames, u32 flags);
+ int aq_ring_rx_clean(struct aq_ring_s *self,
+diff --git a/drivers/net/ethernet/aquantia/atlantic/aq_vec.c b/drivers/net/ethernet/aquantia/atlantic/aq_vec.c
+index 9769ab4f9bef01..62b5967b6dcc66 100644
+--- a/drivers/net/ethernet/aquantia/atlantic/aq_vec.c
++++ b/drivers/net/ethernet/aquantia/atlantic/aq_vec.c
+@@ -275,7 +275,7 @@ void aq_vec_deinit(struct aq_vec_s *self)
+
+ for (i = 0U; self->tx_rings > i; ++i) {
+ ring = self->ring[i];
+- aq_ring_tx_clean(&ring[AQ_VEC_TX_ID]);
++ aq_ring_tx_deinit(&ring[AQ_VEC_TX_ID]);
+ aq_ring_rx_deinit(&ring[AQ_VEC_RX_ID]);
+ }
+
+diff --git a/drivers/net/ethernet/broadcom/bnxt/bnxt.c b/drivers/net/ethernet/broadcom/bnxt/bnxt.c
+index e9cc604834c51d..f69ad1ffc0c9d5 100644
+--- a/drivers/net/ethernet/broadcom/bnxt/bnxt.c
++++ b/drivers/net/ethernet/broadcom/bnxt/bnxt.c
+@@ -3764,7 +3764,17 @@ static int bnxt_init_one_rx_ring(struct bnxt *bp, int ring_nr)
+
+ if ((bp->flags & BNXT_FLAG_AGG_RINGS)) {
+ type = ((u32)BNXT_RX_PAGE_SIZE << RX_BD_LEN_SHIFT) |
+- RX_BD_TYPE_RX_AGG_BD | RX_BD_FLAGS_SOP;
++ RX_BD_TYPE_RX_AGG_BD;
++
++ /* Disable EOP if TPA is enabled to prevent overlapping zero
++ * padding with the next segment's data. On P7_PLUS, EOP will
++ * automatically disable Relaxed Ordering (RO) to prevent
++ * potential data corruption (and may degrade performance). On
++ * older chips, RO will not be automatically disabled and may
++ * cause corruption.
++ */
++ if (!(bp->flags & BNXT_FLAG_TPA))
++ type |= RX_BD_FLAGS_AGG_EOP;
+
+ bnxt_init_rxbd_pages(ring, type);
+ }
+diff --git a/drivers/net/ethernet/broadcom/bnxt/bnxt.h b/drivers/net/ethernet/broadcom/bnxt/bnxt.h
+index 2c12a5b34b11f4..006987d3caa1a7 100644
+--- a/drivers/net/ethernet/broadcom/bnxt/bnxt.h
++++ b/drivers/net/ethernet/broadcom/bnxt/bnxt.h
+@@ -103,6 +103,7 @@ struct rx_bd {
+ #define RX_BD_TYPE_48B_BD_SIZE (2 << 4)
+ #define RX_BD_TYPE_64B_BD_SIZE (3 << 4)
+ #define RX_BD_FLAGS_SOP (1 << 6)
++ #define RX_BD_FLAGS_AGG_EOP (1 << 6)
+ #define RX_BD_FLAGS_EOP (1 << 7)
+ #define RX_BD_FLAGS_BUFFERS (3 << 8)
+ #define RX_BD_FLAGS_1_BUFFER_PACKET (0 << 8)
+diff --git a/drivers/net/ethernet/broadcom/bnxt/bnxt_ptp.c b/drivers/net/ethernet/broadcom/bnxt/bnxt_ptp.c
+index 1c888d6c3aee85..850e4c44044ac5 100644
+--- a/drivers/net/ethernet/broadcom/bnxt/bnxt_ptp.c
++++ b/drivers/net/ethernet/broadcom/bnxt/bnxt_ptp.c
+@@ -460,12 +460,15 @@ static int bnxt_ptp_enable(struct ptp_clock_info *ptp_info,
+ return rc;
+ case PTP_CLK_REQ_PPS:
+ /* Configure PHC PPS IN */
+- rc = bnxt_ptp_cfg_pin(bp, 0, BNXT_PPS_PIN_PPS_IN);
++ pin_id = 0;
++ if (!on)
++ break;
++ rc = bnxt_ptp_cfg_pin(bp, pin_id, BNXT_PPS_PIN_PPS_IN);
+ if (rc)
+ return rc;
+ rc = bnxt_ptp_cfg_event(bp, BNXT_PPS_EVENT_INTERNAL);
+ if (!rc)
+- ptp->pps_info.pins[0].event = BNXT_PPS_EVENT_INTERNAL;
++ ptp->pps_info.pins[pin_id].event = BNXT_PPS_EVENT_INTERNAL;
+ return rc;
+ default:
+ netdev_err(ptp->bp->dev, "Unrecognized PIN function\n");
+diff --git a/drivers/net/ethernet/freescale/dpaa2/dpaa2-eth.c b/drivers/net/ethernet/freescale/dpaa2/dpaa2-eth.c
+index 3c19be56af22e5..bae533897f63f9 100644
+--- a/drivers/net/ethernet/freescale/dpaa2/dpaa2-eth.c
++++ b/drivers/net/ethernet/freescale/dpaa2/dpaa2-eth.c
+@@ -4466,9 +4466,8 @@ static int dpaa2_eth_connect_mac(struct dpaa2_eth_priv *priv)
+ err = dpaa2_mac_open(mac);
+ if (err)
+ goto err_free_mac;
+- priv->mac = mac;
+
+- if (dpaa2_eth_is_type_phy(priv)) {
++ if (dpaa2_mac_is_type_phy(mac)) {
+ err = dpaa2_mac_connect(mac);
+ if (err && err != -EPROBE_DEFER)
+ netdev_err(priv->net_dev, "Error connecting to the MAC endpoint: %pe",
+@@ -4477,11 +4476,12 @@ static int dpaa2_eth_connect_mac(struct dpaa2_eth_priv *priv)
+ goto err_close_mac;
+ }
+
++ priv->mac = mac;
++
+ return 0;
+
+ err_close_mac:
+ dpaa2_mac_close(mac);
+- priv->mac = NULL;
+ err_free_mac:
+ kfree(mac);
+ out_put_device:
+@@ -4491,15 +4491,19 @@ out_put_device:
+
+ static void dpaa2_eth_disconnect_mac(struct dpaa2_eth_priv *priv)
+ {
+- if (dpaa2_eth_is_type_phy(priv))
+- dpaa2_mac_disconnect(priv->mac);
++ struct dpaa2_mac *mac = priv->mac;
+
+- if (!dpaa2_eth_has_mac(priv))
++ priv->mac = NULL;
++
++ if (!mac)
+ return;
+
+- dpaa2_mac_close(priv->mac);
+- kfree(priv->mac);
+- priv->mac = NULL;
++ if (dpaa2_mac_is_type_phy(mac))
++ dpaa2_mac_disconnect(mac);
++
++ dpaa2_mac_close(mac);
++ put_device(&mac->mc_dev->dev);
++ kfree(mac);
+ }
+
+ static irqreturn_t dpni_irq0_handler_thread(int irq_num, void *arg)
+diff --git a/drivers/net/ethernet/freescale/dpaa2/dpaa2-switch.c b/drivers/net/ethernet/freescale/dpaa2/dpaa2-switch.c
+index c8478fdcb3aa5f..8f7c3466f52c45 100644
+--- a/drivers/net/ethernet/freescale/dpaa2/dpaa2-switch.c
++++ b/drivers/net/ethernet/freescale/dpaa2/dpaa2-switch.c
+@@ -1514,6 +1514,7 @@ static void dpaa2_switch_port_disconnect_mac(struct ethsw_port_priv *port_priv)
+ dpaa2_mac_disconnect(mac);
+
+ dpaa2_mac_close(mac);
++ put_device(&mac->mc_dev->dev);
+ kfree(mac);
+ }
+
+diff --git a/drivers/net/ethernet/google/gve/gve.h b/drivers/net/ethernet/google/gve/gve.h
+index c5e1312b928323..7de492b0d3611a 100644
+--- a/drivers/net/ethernet/google/gve/gve.h
++++ b/drivers/net/ethernet/google/gve/gve.h
+@@ -10,6 +10,7 @@
+ #include <linux/dma-mapping.h>
+ #include <linux/netdevice.h>
+ #include <linux/pci.h>
++#include <linux/timer.h>
+ #include <linux/u64_stats_sync.h>
+
+ #include "gve_desc.h"
+@@ -35,6 +36,7 @@
+
+ /* Interval to schedule a stats report update, 20000ms. */
+ #define GVE_STATS_REPORT_TIMER_PERIOD 20000
++#define GVE_RX_NAPI_RESCHED_MS 20 /* msecs */
+
+ /* Numbers of NIC tx/rx stats in stats report. */
+ #define NIC_TX_STATS_REPORT_NUM 0
+@@ -226,6 +228,7 @@ struct gve_rx_ring {
+ struct u64_stats_sync statss; /* sync stats for 32bit archs */
+
+ struct gve_rx_ctx ctx; /* Info for packet currently being processed in this ring. */
++ struct timer_list starvation_timer; /* for queue starvation recovery */
+ };
+
+ /* A TX desc ring entry */
+diff --git a/drivers/net/ethernet/google/gve/gve_main.c b/drivers/net/ethernet/google/gve/gve_main.c
+index 209e9526a6fd8c..fc2a516a3bee14 100644
+--- a/drivers/net/ethernet/google/gve/gve_main.c
++++ b/drivers/net/ethernet/google/gve/gve_main.c
+@@ -529,6 +529,9 @@ static void gve_remove_napi(struct gve_priv *priv, int ntfy_idx)
+ {
+ struct gve_notify_block *block = &priv->ntfy_blocks[ntfy_idx];
+
++ if (block->rx && !gve_is_gqi(priv))
++ timer_shutdown_sync(&block->rx->starvation_timer);
++
+ netif_napi_del(&block->napi);
+ disable_irq(block->irq);
+ }
+diff --git a/drivers/net/ethernet/google/gve/gve_rx_dqo.c b/drivers/net/ethernet/google/gve/gve_rx_dqo.c
+index 0a36b284de10ea..adae0f5181ead8 100644
+--- a/drivers/net/ethernet/google/gve/gve_rx_dqo.c
++++ b/drivers/net/ethernet/google/gve/gve_rx_dqo.c
+@@ -16,6 +16,16 @@
+ #include <net/ipv6.h>
+ #include <net/tcp.h>
+
++static void gve_rx_starvation_timer(struct timer_list *t)
++{
++ struct gve_rx_ring *rx = from_timer(rx, t, starvation_timer);
++ struct gve_priv *priv = rx->gve;
++ struct gve_notify_block *block;
++
++ block = &priv->ntfy_blocks[rx->ntfy_id];
++ napi_schedule(&block->napi);
++}
++
+ static int gve_buf_ref_cnt(struct gve_rx_buf_state_dqo *bs)
+ {
+ return page_count(bs->page_info.page) - bs->page_info.pagecnt_bias;
+@@ -185,6 +195,7 @@ static void gve_rx_free_ring_dqo(struct gve_priv *priv, int idx)
+ completion_queue_slots = rx->dqo.complq.mask + 1;
+ buffer_queue_slots = rx->dqo.bufq.mask + 1;
+
++ timer_shutdown_sync(&rx->starvation_timer);
+ gve_rx_remove_from_block(priv, idx);
+
+ if (rx->q_resources) {
+@@ -237,6 +248,7 @@ static int gve_rx_alloc_ring_dqo(struct gve_priv *priv, int idx)
+ memset(rx, 0, sizeof(*rx));
+ rx->gve = priv;
+ rx->q_num = idx;
++ timer_setup(&rx->starvation_timer, gve_rx_starvation_timer, 0);
+ rx->dqo.bufq.mask = buffer_queue_slots - 1;
+ rx->dqo.complq.num_free_slots = completion_queue_slots;
+ rx->dqo.complq.mask = completion_queue_slots - 1;
+@@ -337,6 +349,7 @@ void gve_rx_post_buffers_dqo(struct gve_rx_ring *rx)
+ u32 num_avail_slots;
+ u32 num_full_slots;
+ u32 num_posted = 0;
++ u32 num_bufs_avail_to_hw;
+
+ num_full_slots = (bufq->tail - bufq->head) & bufq->mask;
+ num_avail_slots = bufq->mask - num_full_slots;
+@@ -374,6 +387,26 @@ void gve_rx_post_buffers_dqo(struct gve_rx_ring *rx)
+ }
+
+ rx->fill_cnt += num_posted;
++
++ /* If the queue has fewer than GVE_RX_BUF_THRESH_DQO descriptors
++ * visible to the hardware, the hardware is in danger of starving
++ * and cannot trigger interrupts.
++ *
++ * We use a threshold of 32 because a single maximum-sized RSC
++ * packet can consume up to 19 descriptors in the Rx path. Lower
++ * thresholds (e.g., 8 or 16) would be unsafe as they could cause
++ * the device to drop/stall on a maximum-sized RSC packet.
++ *
++ * Start the timer to periodically reschedule NAPI and recover.
++ */
++ num_bufs_avail_to_hw =
++ ((bufq->tail & ~(GVE_RX_BUF_THRESH_DQO - 1)) -
++ bufq->head) & bufq->mask;
++
++ if (num_bufs_avail_to_hw < GVE_RX_BUF_THRESH_DQO) {
++ mod_timer(&rx->starvation_timer,
++ jiffies + msecs_to_jiffies(GVE_RX_NAPI_RESCHED_MS));
++ }
+ }
+
+ static void gve_try_recycle_buf(struct gve_priv *priv, struct gve_rx_ring *rx,
+diff --git a/drivers/net/ethernet/hisilicon/hip04_eth.c b/drivers/net/ethernet/hisilicon/hip04_eth.c
+index 2abdb5d9869140..dfd260fbff1f2c 100644
+--- a/drivers/net/ethernet/hisilicon/hip04_eth.c
++++ b/drivers/net/ethernet/hisilicon/hip04_eth.c
+@@ -594,7 +594,11 @@ static int hip04_rx_poll(struct napi_struct *napi, int budget)
+ skb = build_skb(buf, priv->rx_buf_size);
+ if (unlikely(!skb)) {
+ net_dbg_ratelimited("build_skb failed\n");
+- goto refill;
++ /* Retain the slot; return budget so NAPI retries this
++ * buffer. Refill would overwrite rx_buf[]/rx_phys[]
++ * and leak them.
++ */
++ return budget;
+ }
+
+ dma_unmap_single(priv->dev, priv->rx_phys[priv->rx_head],
+@@ -622,14 +626,15 @@ static int hip04_rx_poll(struct napi_struct *napi, int budget)
+ rx++;
+ }
+
+-refill:
+ buf = netdev_alloc_frag(priv->rx_buf_size);
+ if (!buf)
+ goto done;
+ phys = dma_map_single(priv->dev, buf,
+ RX_BUF_SIZE, DMA_FROM_DEVICE);
+- if (dma_mapping_error(priv->dev, phys))
++ if (dma_mapping_error(priv->dev, phys)) {
++ skb_free_frag(buf);
+ goto done;
++ }
+ priv->rx_buf[priv->rx_head] = buf;
+ priv->rx_phys[priv->rx_head] = phys;
+ hip04_set_recv_desc(priv, phys);
+diff --git a/drivers/net/ethernet/hisilicon/hix5hd2_gmac.c b/drivers/net/ethernet/hisilicon/hix5hd2_gmac.c
+index f867e95311173f..4834cf1cd9b3e2 100644
+--- a/drivers/net/ethernet/hisilicon/hix5hd2_gmac.c
++++ b/drivers/net/ethernet/hisilicon/hix5hd2_gmac.c
+@@ -1288,7 +1288,6 @@ static int hix5hd2_dev_remove(struct platform_device *pdev)
+ struct net_device *ndev = platform_get_drvdata(pdev);
+ struct hix5hd2_priv *priv = netdev_priv(ndev);
+
+- netif_napi_del(&priv->napi);
+ unregister_netdev(ndev);
+ mdiobus_unregister(priv->bus);
+ mdiobus_free(priv->bus);
+diff --git a/drivers/net/ethernet/huawei/hinic/hinic_dev.h b/drivers/net/ethernet/huawei/hinic/hinic_dev.h
+index a4fbf44f944cd3..46b24f3c5e168d 100644
+--- a/drivers/net/ethernet/huawei/hinic/hinic_dev.h
++++ b/drivers/net/ethernet/huawei/hinic/hinic_dev.h
+@@ -100,8 +100,6 @@ struct hinic_dev {
+ u16 num_rss;
+ u16 rss_limit;
+ struct hinic_rss_type rss_type;
+- u8 *rss_hkey_user;
+- s32 *rss_indir_user;
+ struct hinic_intr_coal_info *rx_intr_coalesce;
+ struct hinic_intr_coal_info *tx_intr_coalesce;
+ struct hinic_sriov_info sriov_info;
+diff --git a/drivers/net/ethernet/huawei/hinic/hinic_ethtool.c b/drivers/net/ethernet/huawei/hinic/hinic_ethtool.c
+index f4b68028691194..660ab3edf73939 100644
+--- a/drivers/net/ethernet/huawei/hinic/hinic_ethtool.c
++++ b/drivers/net/ethernet/huawei/hinic/hinic_ethtool.c
+@@ -1061,17 +1061,6 @@ static int __set_rss_rxfh(struct net_device *netdev,
+ int err;
+
+ if (indir) {
+- if (!nic_dev->rss_indir_user) {
+- nic_dev->rss_indir_user =
+- kzalloc(sizeof(u32) * HINIC_RSS_INDIR_SIZE,
+- GFP_KERNEL);
+- if (!nic_dev->rss_indir_user)
+- return -ENOMEM;
+- }
+-
+- memcpy(nic_dev->rss_indir_user, indir,
+- sizeof(u32) * HINIC_RSS_INDIR_SIZE);
+-
+ err = hinic_rss_set_indir_tbl(nic_dev,
+ nic_dev->rss_tmpl_idx, indir);
+ if (err)
+@@ -1079,16 +1068,6 @@ static int __set_rss_rxfh(struct net_device *netdev,
+ }
+
+ if (key) {
+- if (!nic_dev->rss_hkey_user) {
+- nic_dev->rss_hkey_user =
+- kzalloc(HINIC_RSS_KEY_SIZE * 2, GFP_KERNEL);
+-
+- if (!nic_dev->rss_hkey_user)
+- return -ENOMEM;
+- }
+-
+- memcpy(nic_dev->rss_hkey_user, key, HINIC_RSS_KEY_SIZE);
+-
+ err = hinic_rss_set_template_tbl(nic_dev,
+ nic_dev->rss_tmpl_idx, key);
+ if (err)
+diff --git a/drivers/net/ethernet/intel/e1000/e1000_main.c b/drivers/net/ethernet/intel/e1000/e1000_main.c
+index 372481e945513d..14f87488fedad3 100644
+--- a/drivers/net/ethernet/intel/e1000/e1000_main.c
++++ b/drivers/net/ethernet/intel/e1000/e1000_main.c
+@@ -1228,11 +1228,11 @@ err_eeprom:
+
+ if (hw->flash_address)
+ iounmap(hw->flash_address);
++err_mdio_ioremap:
+ kfree(adapter->tx_ring);
+ kfree(adapter->rx_ring);
+ err_dma:
+ err_sw_init:
+-err_mdio_ioremap:
+ iounmap(hw->ce4100_gbe_mdio_base_virt);
+ iounmap(hw->hw_addr);
+ err_ioremap:
+diff --git a/drivers/net/ethernet/intel/i40e/i40e_debugfs.c b/drivers/net/ethernet/intel/i40e/i40e_debugfs.c
+index b438cf846c41b2..5b59db6a5439cd 100644
+--- a/drivers/net/ethernet/intel/i40e/i40e_debugfs.c
++++ b/drivers/net/ethernet/intel/i40e/i40e_debugfs.c
+@@ -57,47 +57,6 @@ static struct i40e_veb *i40e_dbg_find_veb(struct i40e_pf *pf, int seid)
+ * setup, adding or removing filters, or other things. Many of
+ * these will be useful for some forms of unit testing.
+ **************************************************************/
+-static char i40e_dbg_command_buf[256] = "";
+-
+-/**
+- * i40e_dbg_command_read - read for command datum
+- * @filp: the opened file
+- * @buffer: where to write the data for the user to read
+- * @count: the size of the user's buffer
+- * @ppos: file position offset
+- **/
+-static ssize_t i40e_dbg_command_read(struct file *filp, char __user *buffer,
+- size_t count, loff_t *ppos)
+-{
+- struct i40e_pf *pf = filp->private_data;
+- int bytes_not_copied;
+- int buf_size = 256;
+- char *buf;
+- int len;
+-
+- /* don't allow partial reads */
+- if (*ppos != 0)
+- return 0;
+- if (count < buf_size)
+- return -ENOSPC;
+-
+- buf = kzalloc(buf_size, GFP_KERNEL);
+- if (!buf)
+- return -ENOSPC;
+-
+- len = snprintf(buf, buf_size, "%s: %s\n",
+- pf->vsi[pf->lan_vsi]->netdev->name,
+- i40e_dbg_command_buf);
+-
+- bytes_not_copied = copy_to_user(buffer, buf, len);
+- kfree(buf);
+-
+- if (bytes_not_copied)
+- return -EFAULT;
+-
+- *ppos = len;
+- return len;
+-}
+
+ static char *i40e_filter_state_string[] = {
+ "INVALID",
+@@ -1636,7 +1595,6 @@ command_write_done:
+ static const struct file_operations i40e_dbg_command_fops = {
+ .owner = THIS_MODULE,
+ .open = simple_open,
+- .read = i40e_dbg_command_read,
+ .write = i40e_dbg_command_write,
+ };
+
+@@ -1645,47 +1603,6 @@ static const struct file_operations i40e_dbg_command_fops = {
+ * The netdev_ops entry in debugfs is for giving the driver commands
+ * to be executed from the netdev operations.
+ **************************************************************/
+-static char i40e_dbg_netdev_ops_buf[256] = "";
+-
+-/**
+- * i40e_dbg_netdev_ops_read - read for netdev_ops datum
+- * @filp: the opened file
+- * @buffer: where to write the data for the user to read
+- * @count: the size of the user's buffer
+- * @ppos: file position offset
+- **/
+-static ssize_t i40e_dbg_netdev_ops_read(struct file *filp, char __user *buffer,
+- size_t count, loff_t *ppos)
+-{
+- struct i40e_pf *pf = filp->private_data;
+- int bytes_not_copied;
+- int buf_size = 256;
+- char *buf;
+- int len;
+-
+- /* don't allow partal reads */
+- if (*ppos != 0)
+- return 0;
+- if (count < buf_size)
+- return -ENOSPC;
+-
+- buf = kzalloc(buf_size, GFP_KERNEL);
+- if (!buf)
+- return -ENOSPC;
+-
+- len = snprintf(buf, buf_size, "%s: %s\n",
+- pf->vsi[pf->lan_vsi]->netdev->name,
+- i40e_dbg_netdev_ops_buf);
+-
+- bytes_not_copied = copy_to_user(buffer, buf, len);
+- kfree(buf);
+-
+- if (bytes_not_copied)
+- return -EFAULT;
+-
+- *ppos = len;
+- return len;
+-}
+
+ /**
+ * i40e_dbg_netdev_ops_write - write into netdev_ops datum
+@@ -1699,35 +1616,36 @@ static ssize_t i40e_dbg_netdev_ops_write(struct file *filp,
+ size_t count, loff_t *ppos)
+ {
+ struct i40e_pf *pf = filp->private_data;
++ char *cmd_buf, *buf_tmp;
+ int bytes_not_copied;
+ struct i40e_vsi *vsi;
+- char *buf_tmp;
+ int vsi_seid;
+ int i, cnt;
+
+ /* don't allow partial writes */
+ if (*ppos != 0)
+ return 0;
+- if (count >= sizeof(i40e_dbg_netdev_ops_buf))
+- return -ENOSPC;
+
+- memset(i40e_dbg_netdev_ops_buf, 0, sizeof(i40e_dbg_netdev_ops_buf));
+- bytes_not_copied = copy_from_user(i40e_dbg_netdev_ops_buf,
+- buffer, count);
+- if (bytes_not_copied)
++ cmd_buf = kzalloc(count + 1, GFP_KERNEL);
++ if (!cmd_buf)
++ return count;
++ bytes_not_copied = copy_from_user(cmd_buf, buffer, count);
++ if (bytes_not_copied) {
++ kfree(cmd_buf);
+ return -EFAULT;
+- i40e_dbg_netdev_ops_buf[count] = '\0';
++ }
++ cmd_buf[count] = '\0';
+
+- buf_tmp = strchr(i40e_dbg_netdev_ops_buf, '\n');
++ buf_tmp = strchr(cmd_buf, '\n');
+ if (buf_tmp) {
+ *buf_tmp = '\0';
+- count = buf_tmp - i40e_dbg_netdev_ops_buf + 1;
++ count = buf_tmp - cmd_buf + 1;
+ }
+
+- if (strncmp(i40e_dbg_netdev_ops_buf, "change_mtu", 10) == 0) {
++ if (strncmp(cmd_buf, "change_mtu", 10) == 0) {
+ int mtu;
+
+- cnt = sscanf(&i40e_dbg_netdev_ops_buf[11], "%i %i",
++ cnt = sscanf(&cmd_buf[11], "%i %i",
+ &vsi_seid, &mtu);
+ if (cnt != 2) {
+ dev_info(&pf->pdev->dev, "change_mtu <vsi_seid> <mtu>\n");
+@@ -1749,8 +1667,8 @@ static ssize_t i40e_dbg_netdev_ops_write(struct file *filp,
+ dev_info(&pf->pdev->dev, "Could not acquire RTNL - please try again\n");
+ }
+
+- } else if (strncmp(i40e_dbg_netdev_ops_buf, "set_rx_mode", 11) == 0) {
+- cnt = sscanf(&i40e_dbg_netdev_ops_buf[11], "%i", &vsi_seid);
++ } else if (strncmp(cmd_buf, "set_rx_mode", 11) == 0) {
++ cnt = sscanf(&cmd_buf[11], "%i", &vsi_seid);
+ if (cnt != 1) {
+ dev_info(&pf->pdev->dev, "set_rx_mode <vsi_seid>\n");
+ goto netdev_ops_write_done;
+@@ -1770,8 +1688,8 @@ static ssize_t i40e_dbg_netdev_ops_write(struct file *filp,
+ dev_info(&pf->pdev->dev, "Could not acquire RTNL - please try again\n");
+ }
+
+- } else if (strncmp(i40e_dbg_netdev_ops_buf, "napi", 4) == 0) {
+- cnt = sscanf(&i40e_dbg_netdev_ops_buf[4], "%i", &vsi_seid);
++ } else if (strncmp(cmd_buf, "napi", 4) == 0) {
++ cnt = sscanf(&cmd_buf[4], "%i", &vsi_seid);
+ if (cnt != 1) {
+ dev_info(&pf->pdev->dev, "napi <vsi_seid>\n");
+ goto netdev_ops_write_done;
+@@ -1789,21 +1707,20 @@ static ssize_t i40e_dbg_netdev_ops_write(struct file *filp,
+ dev_info(&pf->pdev->dev, "napi called\n");
+ }
+ } else {
+- dev_info(&pf->pdev->dev, "unknown command '%s'\n",
+- i40e_dbg_netdev_ops_buf);
++ dev_info(&pf->pdev->dev, "unknown command '%s'\n", cmd_buf);
+ dev_info(&pf->pdev->dev, "available commands\n");
+ dev_info(&pf->pdev->dev, " change_mtu <vsi_seid> <mtu>\n");
+ dev_info(&pf->pdev->dev, " set_rx_mode <vsi_seid>\n");
+ dev_info(&pf->pdev->dev, " napi <vsi_seid>\n");
+ }
+ netdev_ops_write_done:
++ kfree(cmd_buf);
+ return count;
+ }
+
+ static const struct file_operations i40e_dbg_netdev_ops_fops = {
+ .owner = THIS_MODULE,
+ .open = simple_open,
+- .read = i40e_dbg_netdev_ops_read,
+ .write = i40e_dbg_netdev_ops_write,
+ };
+
+diff --git a/drivers/net/ethernet/intel/ice/ice_main.c b/drivers/net/ethernet/intel/ice/ice_main.c
+index 8cd072c30015ad..e923b64f2a668e 100644
+--- a/drivers/net/ethernet/intel/ice/ice_main.c
++++ b/drivers/net/ethernet/intel/ice/ice_main.c
+@@ -5369,6 +5369,16 @@ static int __maybe_unused ice_resume(struct device *dev)
+ /* Restart the service task */
+ mod_timer(&pf->serv_tmr, round_jiffies(jiffies + pf->serv_tmr_period));
+
++ /* Best-effort wait for the scheduled reset to finish so that the
++ * device is operational before returning. Without this, userspace
++ * (e.g. NetworkManager) may try to open the net device while the
++ * asynchronous reset is still in progress, hitting -EBUSY.
++ */
++ ret = ice_wait_for_reset(pf, secs_to_jiffies(10));
++ if (ret)
++ dev_err(dev, "Wait for reset timed out (10s) during resume: %d\n",
++ ret);
++
+ return 0;
+ }
+ #endif /* CONFIG_PM */
+diff --git a/drivers/net/ethernet/intel/ice/ice_ptp.c b/drivers/net/ethernet/intel/ice/ice_ptp.c
+index 46b0063a5e128d..06c5a165e06682 100644
+--- a/drivers/net/ethernet/intel/ice/ice_ptp.c
++++ b/drivers/net/ethernet/intel/ice/ice_ptp.c
+@@ -595,7 +595,7 @@ static u64 ice_ptp_extend_40b_ts(struct ice_pf *pf, u64 in_tstamp)
+ return 0;
+ }
+
+- return ice_ptp_extend_32b_ts(pf->ptp.cached_phc_time,
++ return ice_ptp_extend_32b_ts(READ_ONCE(pf->ptp.cached_phc_time),
+ (in_tstamp >> 8) & mask);
+ }
+
+diff --git a/drivers/net/ethernet/intel/igbvf/netdev.c b/drivers/net/ethernet/intel/igbvf/netdev.c
+index 72cb1b56e9f240..f4b038503b4b27 100644
+--- a/drivers/net/ethernet/intel/igbvf/netdev.c
++++ b/drivers/net/ethernet/intel/igbvf/netdev.c
+@@ -2202,8 +2202,6 @@ dma_error:
+ buffer_info->time_stamp = 0;
+ buffer_info->length = 0;
+ buffer_info->mapped_as_page = false;
+- if (count)
+- count--;
+
+ /* clear timestamp and dma mappings for remaining portion of packet */
+ while (count--) {
+diff --git a/drivers/net/ethernet/marvell/octeontx2/nic/otx2_flows.c b/drivers/net/ethernet/marvell/octeontx2/nic/otx2_flows.c
+index 7c7f8814fb3f95..cbf44f0d7d8bb6 100644
+--- a/drivers/net/ethernet/marvell/octeontx2/nic/otx2_flows.c
++++ b/drivers/net/ethernet/marvell/octeontx2/nic/otx2_flows.c
+@@ -153,6 +153,7 @@ exit:
+ if (allocated) {
+ pfvf->flags |= OTX2_FLAG_MCAM_ENTRIES_ALLOC;
+ pfvf->flags |= OTX2_FLAG_NTUPLE_SUPPORT;
++ pfvf->flags |= OTX2_FLAG_TC_FLOWER_SUPPORT;
+ }
+
+ if (allocated != count)
+diff --git a/drivers/net/ethernet/marvell/octeontx2/nic/otx2_pf.c b/drivers/net/ethernet/marvell/octeontx2/nic/otx2_pf.c
+index 49f21c7f5c1fd1..187d0a71e64ad6 100644
+--- a/drivers/net/ethernet/marvell/octeontx2/nic/otx2_pf.c
++++ b/drivers/net/ethernet/marvell/octeontx2/nic/otx2_pf.c
+@@ -842,8 +842,8 @@ static void otx2_handle_link_event(struct otx2_nic *pf)
+ netif_carrier_on(netdev);
+ netif_tx_start_all_queues(netdev);
+ } else {
+- netif_tx_stop_all_queues(netdev);
+ netif_carrier_off(netdev);
++ netif_tx_stop_all_queues(netdev);
+ }
+ }
+
+diff --git a/drivers/net/ethernet/marvell/octeontx2/nic/otx2_tc.c b/drivers/net/ethernet/marvell/octeontx2/nic/otx2_tc.c
+index 6833cbf8534458..b23ac8f38aaad8 100644
+--- a/drivers/net/ethernet/marvell/octeontx2/nic/otx2_tc.c
++++ b/drivers/net/ethernet/marvell/octeontx2/nic/otx2_tc.c
+@@ -86,10 +86,12 @@ static void otx2_get_egress_burst_cfg(struct otx2_nic *nic, u32 burst,
+ if (burst) {
+ *burst_exp = ilog2(burst) ? ilog2(burst) - 1 : 0;
+ tmp = burst - rounddown_pow_of_two(burst);
+- if (burst < max_mantissa)
++ if (burst <= max_mantissa) {
+ *burst_mantissa = tmp * 2;
+- else
++ } else {
++ WARN_ON(*burst_exp < 7);
+ *burst_mantissa = tmp / (1ULL << (*burst_exp - 7));
++ }
+ } else {
+ *burst_exp = MAX_BURST_EXPONENT;
+ *burst_mantissa = max_mantissa;
+diff --git a/drivers/net/ethernet/marvell/prestera/prestera_pci.c b/drivers/net/ethernet/marvell/prestera/prestera_pci.c
+index a37dbbda8de394..bc6af7b4909d9e 100644
+--- a/drivers/net/ethernet/marvell/prestera/prestera_pci.c
++++ b/drivers/net/ethernet/marvell/prestera/prestera_pci.c
+@@ -673,6 +673,9 @@ static int prestera_fw_hdr_parse(struct prestera_fw *fw)
+ struct prestera_fw_header *hdr;
+ u32 magic;
+
++ if (fw->bin->size < sizeof(*hdr))
++ return -EINVAL;
++
+ hdr = (struct prestera_fw_header *)fw->bin->data;
+
+ magic = be32_to_cpu(hdr->magic_number);
+diff --git a/drivers/net/ethernet/mellanox/mlx5/core/diag/fw_tracer.c b/drivers/net/ethernet/mellanox/mlx5/core/diag/fw_tracer.c
+index c216634c8919e7..de0bb2669e4ce6 100644
+--- a/drivers/net/ethernet/mellanox/mlx5/core/diag/fw_tracer.c
++++ b/drivers/net/ethernet/mellanox/mlx5/core/diag/fw_tracer.c
+@@ -1036,13 +1036,11 @@ struct mlx5_fw_tracer *mlx5_fw_tracer_create(struct mlx5_core_dev *dev)
+
+ tracer = kvzalloc(sizeof(*tracer), GFP_KERNEL);
+ if (!tracer)
+- return ERR_PTR(-ENOMEM);
++ return NULL;
+
+ tracer->work_queue = create_singlethread_workqueue("mlx5_fw_tracer");
+- if (!tracer->work_queue) {
+- err = -ENOMEM;
++ if (!tracer->work_queue)
+ goto free_tracer;
+- }
+
+ tracer->dev = dev;
+
+@@ -1082,7 +1080,7 @@ destroy_workqueue:
+ destroy_workqueue(tracer->work_queue);
+ free_tracer:
+ kvfree(tracer);
+- return ERR_PTR(err);
++ return NULL;
+ }
+
+ static int fw_tracer_event(struct notifier_block *nb, unsigned long action, void *data);
+@@ -1093,7 +1091,7 @@ int mlx5_fw_tracer_init(struct mlx5_fw_tracer *tracer)
+ struct mlx5_core_dev *dev;
+ int err;
+
+- if (IS_ERR_OR_NULL(tracer))
++ if (!tracer)
+ return 0;
+
+ dev = tracer->dev;
+@@ -1136,7 +1134,7 @@ err_cancel_work:
+ /* Stop tracer + Cleanup HW resources */
+ void mlx5_fw_tracer_cleanup(struct mlx5_fw_tracer *tracer)
+ {
+- if (IS_ERR_OR_NULL(tracer))
++ if (!tracer)
+ return;
+
+ mlx5_core_dbg(tracer->dev, "FWTracer: Cleanup, is owner ? (%d)\n",
+@@ -1155,7 +1153,7 @@ void mlx5_fw_tracer_cleanup(struct mlx5_fw_tracer *tracer)
+ /* Free software resources (Buffers, etc ..) */
+ void mlx5_fw_tracer_destroy(struct mlx5_fw_tracer *tracer)
+ {
+- if (IS_ERR_OR_NULL(tracer))
++ if (!tracer)
+ return;
+
+ mlx5_core_dbg(tracer->dev, "FWTracer: Destroy\n");
+@@ -1203,7 +1201,7 @@ int mlx5_fw_tracer_reload(struct mlx5_fw_tracer *tracer)
+ struct mlx5_core_dev *dev;
+ int err;
+
+- if (IS_ERR_OR_NULL(tracer))
++ if (!tracer)
+ return 0;
+
+ dev = tracer->dev;
+diff --git a/drivers/net/ethernet/mellanox/mlx5/core/en_dcbnl.c b/drivers/net/ethernet/mellanox/mlx5/core/en_dcbnl.c
+index e29a8ed7e7ac13..1a73fa436a1368 100644
+--- a/drivers/net/ethernet/mellanox/mlx5/core/en_dcbnl.c
++++ b/drivers/net/ethernet/mellanox/mlx5/core/en_dcbnl.c
+@@ -158,6 +158,13 @@ static int mlx5e_dcbnl_ieee_getets(struct net_device *netdev,
+ }
+ memcpy(ets->tc_tsa, priv->dcbx.tc_tsa, sizeof(ets->tc_tsa));
+
++ /* Report 0 for non ETS TSA */
++ for (i = 0; i < ets->ets_cap; i++) {
++ if (ets->tc_tx_bw[i] == MLX5E_MAX_BW_ALLOC &&
++ priv->dcbx.tc_tsa[i] != IEEE_8021QAZ_TSA_ETS)
++ ets->tc_tx_bw[i] = 0;
++ }
++
+ return err;
+ }
+
+@@ -302,6 +309,14 @@ static int mlx5e_dbcnl_validate_ets(struct net_device *netdev,
+ }
+ }
+
++ for (i = 0; i < IEEE_8021QAZ_MAX_TCS; i++) {
++ if (ets->tc_tsa[i] == IEEE_8021QAZ_TSA_CB_SHAPER) {
++ netdev_err(netdev,
++ "Failed to validate ETS: CB Shaper is not supported\n");
++ return -EOPNOTSUPP;
++ }
++ }
++
+ /* Validate Bandwidth Sum */
+ for (i = 0; i < IEEE_8021QAZ_MAX_TCS; i++) {
+ if (ets->tc_tsa[i] == IEEE_8021QAZ_TSA_ETS) {
+diff --git a/drivers/net/ethernet/mellanox/mlx5/core/esw/acl/helper.c b/drivers/net/ethernet/mellanox/mlx5/core/esw/acl/helper.c
+index 45b839116212df..61d299f8ca25ce 100644
+--- a/drivers/net/ethernet/mellanox/mlx5/core/esw/acl/helper.c
++++ b/drivers/net/ethernet/mellanox/mlx5/core/esw/acl/helper.c
+@@ -70,7 +70,7 @@ int esw_egress_acl_vlan_create(struct mlx5_eswitch *esw,
+ flow_act.action = flow_action;
+ vport->egress.allowed_vlan =
+ mlx5_add_flow_rules(vport->egress.acl, spec,
+- &flow_act, fwd_dest, 0);
++ &flow_act, fwd_dest, fwd_dest ? 1 : 0);
+ if (IS_ERR(vport->egress.allowed_vlan)) {
+ err = PTR_ERR(vport->egress.allowed_vlan);
+ esw_warn(esw->dev,
+diff --git a/drivers/net/ethernet/mellanox/mlxsw/spectrum_span.c b/drivers/net/ethernet/mellanox/mlxsw/spectrum_span.c
+index 8883ef01274772..fa3fef2b74db0d 100644
+--- a/drivers/net/ethernet/mellanox/mlxsw/spectrum_span.c
++++ b/drivers/net/ethernet/mellanox/mlxsw/spectrum_span.c
+@@ -538,7 +538,7 @@ mlxsw_sp_span_gretap6_route(const struct net_device *to_dev,
+ if (!dst || dst->error)
+ goto out;
+
+- rt6 = container_of(dst, struct rt6_info, dst);
++ rt6 = dst_rt6_info(dst);
+
+ dev = dst->dev;
+ *saddrp = fl6.saddr;
+diff --git a/drivers/net/ethernet/netronome/nfp/nfpcore/nfp_resource.c b/drivers/net/ethernet/netronome/nfp/nfpcore/nfp_resource.c
+index ce7492a6a98fad..908d99f398b819 100644
+--- a/drivers/net/ethernet/netronome/nfp/nfpcore/nfp_resource.c
++++ b/drivers/net/ethernet/netronome/nfp/nfpcore/nfp_resource.c
+@@ -96,6 +96,9 @@ static int nfp_cpp_resource_find(struct nfp_cpp *cpp, struct nfp_resource *res)
+ res->mutex =
+ nfp_cpp_mutex_alloc(cpp,
+ NFP_RESOURCE_TBL_TARGET, addr, key);
++ if (!res->mutex)
++ return -ENOMEM;
++
+ res->cpp_id = NFP_CPP_ID(entry.region.cpp_target,
+ entry.region.cpp_action,
+ entry.region.cpp_token);
+diff --git a/drivers/net/ethernet/nvidia/forcedeth.c b/drivers/net/ethernet/nvidia/forcedeth.c
+index 486cbc8ab22423..866267df1f2c9d 100644
+--- a/drivers/net/ethernet/nvidia/forcedeth.c
++++ b/drivers/net/ethernet/nvidia/forcedeth.c
+@@ -6199,10 +6199,10 @@ static void nv_remove(struct pci_dev *pci_dev)
+ struct net_device *dev = pci_get_drvdata(pci_dev);
+ struct fe_priv *np = netdev_priv(dev);
+
+- free_percpu(np->txrx_stats);
+-
+ unregister_netdev(dev);
+
++ free_percpu(np->txrx_stats);
++
+ nv_restore_mac_addr(pci_dev);
+
+ /* restore any phy related changes */
+diff --git a/drivers/net/ethernet/qlogic/qede/qede_main.c b/drivers/net/ethernet/qlogic/qede/qede_main.c
+index 4bc950d3660738..8148c16c851eaa 100644
+--- a/drivers/net/ethernet/qlogic/qede/qede_main.c
++++ b/drivers/net/ethernet/qlogic/qede/qede_main.c
+@@ -108,7 +108,7 @@ static void qede_remove(struct pci_dev *pdev);
+ static void qede_shutdown(struct pci_dev *pdev);
+ static void qede_link_update(void *dev, struct qed_link_output *link);
+ static void qede_schedule_recovery_handler(void *dev);
+-static void qede_recovery_handler(struct qede_dev *edev);
++static bool qede_recovery_handler(struct qede_dev *edev);
+ static void qede_schedule_hw_err_handler(void *dev,
+ enum qed_hw_err_type err_type);
+ static void qede_get_eth_tlv_data(void *edev, void *data);
+@@ -1063,21 +1063,6 @@ void __qede_unlock(struct qede_dev *edev)
+ mutex_unlock(&edev->qede_lock);
+ }
+
+-/* This version of the lock should be used when acquiring the RTNL lock is also
+- * needed in addition to the internal qede lock.
+- */
+-static void qede_lock(struct qede_dev *edev)
+-{
+- rtnl_lock();
+- __qede_lock(edev);
+-}
+-
+-static void qede_unlock(struct qede_dev *edev)
+-{
+- __qede_unlock(edev);
+- rtnl_unlock();
+-}
+-
+ static void qede_periodic_task(struct work_struct *work)
+ {
+ struct qede_dev *edev = container_of(work, struct qede_dev,
+@@ -1114,6 +1099,8 @@ static void qede_sp_task(struct work_struct *work)
+ */
+
+ if (test_and_clear_bit(QEDE_SP_RECOVERY, &edev->sp_flags)) {
++ bool reloaded;
++
+ cancel_delayed_work_sync(&edev->periodic_task);
+ #ifdef CONFIG_QED_SRIOV
+ /* SRIOV must be disabled outside the lock to avoid a deadlock.
+@@ -1122,9 +1109,17 @@ static void qede_sp_task(struct work_struct *work)
+ if (pci_num_vf(edev->pdev))
+ qede_sriov_configure(edev->pdev, 0);
+ #endif
+- qede_lock(edev);
+- qede_recovery_handler(edev);
+- qede_unlock(edev);
++ rtnl_lock();
++ __qede_lock(edev);
++ reloaded = qede_recovery_handler(edev);
++ __qede_unlock(edev);
++
++ /* The udp_tunnel core synchronously calls back into
++ * qede_udp_tunnel_sync(), which takes the qede lock.
++ */
++ if (reloaded)
++ udp_tunnel_nic_reset_ntf(edev->ndev);
++ rtnl_unlock();
+ }
+
+ __qede_lock(edev);
+@@ -2665,9 +2660,13 @@ static void qede_recovery_failed(struct qede_dev *edev)
+ edev->ops->common->set_power_state(edev->cdev, PCI_D3hot);
+ }
+
+-static void qede_recovery_handler(struct qede_dev *edev)
++/* Returns true if an open device was successfully reloaded and its
++ * udp_tunnel ports need to be re-synced by the caller.
++ */
++static bool qede_recovery_handler(struct qede_dev *edev)
+ {
+ u32 curr_state = edev->state;
++ bool reloaded = false;
+ int rc;
+
+ DP_NOTICE(edev, "Starting a recovery process\n");
+@@ -2697,17 +2696,18 @@ static void qede_recovery_handler(struct qede_dev *edev)
+ goto err;
+
+ qede_config_rx_mode(edev->ndev);
+- udp_tunnel_nic_reset_ntf(edev->ndev);
++ reloaded = true;
+ }
+
+ edev->state = curr_state;
+
+ DP_NOTICE(edev, "Recovery handling is done\n");
+
+- return;
++ return reloaded;
+
+ err:
+ qede_recovery_failed(edev);
++ return false;
+ }
+
+ static void qede_atomic_hw_err_handler(struct qede_dev *edev)
+diff --git a/drivers/net/ethernet/samsung/sxgbe/sxgbe_main.c b/drivers/net/ethernet/samsung/sxgbe/sxgbe_main.c
+index f6f99712d562e7..342faeb6c8afa6 100644
+--- a/drivers/net/ethernet/samsung/sxgbe/sxgbe_main.c
++++ b/drivers/net/ethernet/samsung/sxgbe/sxgbe_main.c
+@@ -599,14 +599,13 @@ static int init_dma_desc_rings(struct net_device *netd)
+
+ return 0;
+
+-txalloc_err:
+- while (queue_num--)
+- free_tx_ring(priv->device, priv->txq[queue_num], tx_rsize);
+- return ret;
+-
+ rxalloc_err:
+ while (queue_num--)
+ free_rx_ring(priv->device, priv->rxq[queue_num], rx_rsize);
++ queue_num = SXGBE_TX_QUEUES;
++txalloc_err:
++ while (queue_num--)
++ free_tx_ring(priv->device, priv->txq[queue_num], tx_rsize);
+ return ret;
+ }
+
+@@ -1081,7 +1080,9 @@ static int sxgbe_open(struct net_device *dev)
+ priv->dma_buf_sz = SXGBE_ALIGN(DMA_BUFFER_SIZE);
+ priv->tx_tc = TC_DEFAULT;
+ priv->rx_tc = TC_DEFAULT;
+- init_dma_desc_rings(dev);
++ ret = init_dma_desc_rings(dev);
++ if (ret)
++ goto init_phy_error;
+
+ /* DMA initialization and SW reset */
+ ret = sxgbe_init_dma_engine(priv);
+@@ -1190,6 +1191,7 @@ static int sxgbe_open(struct net_device *dev)
+
+ init_error:
+ free_dma_desc_resources(priv);
++init_phy_error:
+ if (dev->phydev)
+ phy_disconnect(dev->phydev);
+ phy_error:
+diff --git a/drivers/net/ethernet/stmicro/stmmac/stmmac_tc.c b/drivers/net/ethernet/stmicro/stmmac/stmmac_tc.c
+index 27187f5286206a..e9aac51c1b9b78 100644
+--- a/drivers/net/ethernet/stmicro/stmmac/stmmac_tc.c
++++ b/drivers/net/ethernet/stmicro/stmmac/stmmac_tc.c
+@@ -456,6 +456,7 @@ static int tc_parse_flow_actions(struct stmmac_priv *priv,
+ }
+
+ #define ETHER_TYPE_FULL_MASK cpu_to_be16(~0)
++#define IP_PROTO_FULL_MASK 0xFF
+
+ static int tc_add_basic_flow(struct stmmac_priv *priv,
+ struct flow_cls_offload *cls,
+@@ -471,6 +472,37 @@ static int tc_add_basic_flow(struct stmmac_priv *priv,
+
+ flow_rule_match_basic(rule, &match);
+
++ /* Both network proto and transport proto not present in the key */
++ if (!match.mask || !(match.mask->n_proto || match.mask->ip_proto)) {
++ NL_SET_ERR_MSG_MOD(cls->common.extack,
++ "filter must specify network or transport protocol");
++ return -EOPNOTSUPP;
++ }
++
++ /* If the proto is present in the key and is not full mask */
++ if ((match.mask->n_proto && match.mask->n_proto != ETHER_TYPE_FULL_MASK) ||
++ (match.mask->ip_proto && match.mask->ip_proto != IP_PROTO_FULL_MASK)) {
++ NL_SET_ERR_MSG_MOD(cls->common.extack,
++ "only full protocol mask is supported");
++ return -EOPNOTSUPP;
++ }
++
++ /* Network proto is present in the key and is not IPv4 */
++ if (match.mask->n_proto && match.key->n_proto != cpu_to_be16(ETH_P_IP)) {
++ NL_SET_ERR_MSG_MOD(cls->common.extack,
++ "only IPv4 network protocol is supported");
++ return -EOPNOTSUPP;
++ }
++
++ /* Transport proto is present in the key and is not TCP or UDP */
++ if (match.mask->ip_proto &&
++ match.key->ip_proto != IPPROTO_TCP &&
++ match.key->ip_proto != IPPROTO_UDP) {
++ NL_SET_ERR_MSG_MOD(cls->common.extack,
++ "only TCP and UDP transport protocols are supported");
++ return -EOPNOTSUPP;
++ }
++
+ entry->ip_proto = match.key->ip_proto;
+ return 0;
+ }
+@@ -608,6 +640,8 @@ static int tc_add_flow(struct stmmac_priv *priv,
+ ret = tc_flow_parsers[i].fn(priv, cls, entry);
+ if (!ret)
+ entry->in_use = true;
++ else if (ret == -EOPNOTSUPP)
++ return ret;
+ }
+
+ if (!entry->in_use)
+@@ -637,6 +671,7 @@ static int tc_del_flow(struct stmmac_priv *priv,
+ entry->in_use = false;
+ entry->cookie = 0;
+ entry->is_l4 = false;
++ entry->action = 0;
+ return ret;
+ }
+
+diff --git a/drivers/net/geneve.c b/drivers/net/geneve.c
+index 8ebdf397718787..19c4ace8f0d711 100644
+--- a/drivers/net/geneve.c
++++ b/drivers/net/geneve.c
+@@ -1760,6 +1760,9 @@ static int geneve_changelink(struct net_device *dev, struct nlattr *tb[],
+ struct geneve_config cfg;
+ int err;
+
++ if (!rtnl_dev_link_net_capable(dev, geneve->net))
++ return -EPERM;
++
+ /* If the geneve device is configured for metadata (or externally
+ * controlled, for example, OVS), then nothing can be changed.
+ */
+diff --git a/drivers/net/gtp.c b/drivers/net/gtp.c
+index 797886f10868af..59c9bd459b2fb5 100644
+--- a/drivers/net/gtp.c
++++ b/drivers/net/gtp.c
+@@ -489,8 +489,9 @@ static int gtp1u_send_echo_resp(struct gtp_dev *gtp, struct sk_buff *skb)
+ return -1;
+
+ /* pull GTP and UDP headers */
+- skb_pull_data(skb,
+- sizeof(struct gtp1_header_long) + sizeof(struct udphdr));
++ if (!skb_pull_data(skb, sizeof(struct gtp1_header_long) +
++ sizeof(struct udphdr)))
++ return -1;
+
+ gtp_pkt = skb_push(skb, sizeof(struct gtp1u_packet));
+ memset(gtp_pkt, 0, sizeof(struct gtp1u_packet));
+diff --git a/drivers/net/mctp/mctp-serial.c b/drivers/net/mctp/mctp-serial.c
+index fae9628f9615fd..e11dc47d4baf0d 100644
+--- a/drivers/net/mctp/mctp-serial.c
++++ b/drivers/net/mctp/mctp-serial.c
+@@ -316,7 +316,7 @@ static void mctp_serial_push_header(struct mctp_serial *dev, unsigned char c)
+ } else {
+ dev->rxlen = c;
+ dev->rxpos = 0;
+- dev->rxstate = STATE_DATA;
++ dev->rxstate = c > 0 ? STATE_DATA : STATE_TRAILER;
+ dev->rxfcs = crc_ccitt_byte(dev->rxfcs, c);
+ }
+ break;
+diff --git a/drivers/net/phy/phylink.c b/drivers/net/phy/phylink.c
+index 3069a7df25d3ff..8109a049a74e43 100644
+--- a/drivers/net/phy/phylink.c
++++ b/drivers/net/phy/phylink.c
+@@ -1483,8 +1483,8 @@ struct phylink *phylink_create(struct phylink_config *config,
+ } else if (config->type == PHYLINK_DEV) {
+ pl->dev = config->dev;
+ } else {
+- kfree(pl);
+- return ERR_PTR(-EINVAL);
++ ret = -EINVAL;
++ goto free_pl;
+ }
+
+ pl->using_mac_select_pcs = using_mac_select_pcs;
+@@ -1508,28 +1508,29 @@ struct phylink *phylink_create(struct phylink_config *config,
+ phylink_validate(pl, pl->supported, &pl->link_config);
+
+ ret = phylink_parse_mode(pl, fwnode);
+- if (ret < 0) {
+- kfree(pl);
+- return ERR_PTR(ret);
+- }
++ if (ret < 0)
++ goto free_pl;
+
+ if (pl->cfg_link_an_mode == MLO_AN_FIXED) {
+ ret = phylink_parse_fixedlink(pl, fwnode);
+- if (ret < 0) {
+- kfree(pl);
+- return ERR_PTR(ret);
+- }
++ if (ret < 0)
++ goto release_link_gpio;
+ }
+
+ pl->cur_link_an_mode = pl->cfg_link_an_mode;
+
+ ret = phylink_register_sfp(pl, fwnode);
+- if (ret < 0) {
+- kfree(pl);
+- return ERR_PTR(ret);
+- }
++ if (ret < 0)
++ goto release_link_gpio;
+
+ return pl;
++
++release_link_gpio:
++ if (pl->link_gpio)
++ gpiod_put(pl->link_gpio);
++free_pl:
++ kfree(pl);
++ return ERR_PTR(ret);
+ }
+ EXPORT_SYMBOL_GPL(phylink_create);
+
+diff --git a/drivers/net/ppp/ppp_generic.c b/drivers/net/ppp/ppp_generic.c
+index df72070a3879dd..51e5c872552805 100644
+--- a/drivers/net/ppp/ppp_generic.c
++++ b/drivers/net/ppp/ppp_generic.c
+@@ -107,18 +107,6 @@ struct ppp_file {
+ #define PF_TO_PPP(pf) PF_TO_X(pf, struct ppp)
+ #define PF_TO_CHANNEL(pf) PF_TO_X(pf, struct channel)
+
+-/*
+- * Data structure to hold primary network stats for which
+- * we want to use 64 bit storage. Other network stats
+- * are stored in dev->stats of the ppp strucute.
+- */
+-struct ppp_link_stats {
+- u64 rx_packets;
+- u64 tx_packets;
+- u64 rx_bytes;
+- u64 tx_bytes;
+-};
+-
+ /*
+ * Data structure describing one ppp unit.
+ * A ppp unit corresponds to a ppp network interface device
+@@ -162,7 +150,6 @@ struct ppp {
+ struct bpf_prog *active_filter; /* filter for pkts to reset idle */
+ #endif /* CONFIG_PPP_FILTER */
+ struct net *ppp_net; /* the net we belong to */
+- struct ppp_link_stats stats64; /* 64 bit network stats */
+ };
+
+ /*
+@@ -192,6 +179,7 @@ struct channel {
+ struct list_head clist; /* link in list of channels per unit */
+ rwlock_t upl; /* protects `ppp' and 'bridge' */
+ struct channel __rcu *bridge; /* "bridged" ppp channel */
++ struct rcu_head rcu; /* for RCU-deferred free of the channel */
+ #ifdef CONFIG_PPP_MULTILINK
+ u8 avail; /* flag used in multilink stuff */
+ u8 had_frag; /* >= 1 fragments have been sent */
+@@ -823,7 +811,9 @@ static long ppp_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
+ case PPPIOCSMRU:
+ if (get_user(val, p))
+ break;
++ ppp_recv_lock(ppp);
+ ppp->mru = val;
++ ppp_recv_unlock(ppp);
+ err = 0;
+ break;
+
+@@ -844,7 +834,9 @@ static long ppp_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
+ break;
+
+ case PPPIOCGFLAGS:
++ ppp_lock(ppp);
+ val = ppp->flags | ppp->xstate | ppp->rstate;
++ ppp_unlock(ppp);
+ if (put_user(val, p))
+ break;
+ err = 0;
+@@ -868,7 +860,7 @@ static long ppp_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
+ case PPPIOCSDEBUG:
+ if (get_user(val, p))
+ break;
+- ppp->debug = val;
++ WRITE_ONCE(ppp->debug, val);
+ err = 0;
+ break;
+
+@@ -879,16 +871,16 @@ static long ppp_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
+ break;
+
+ case PPPIOCGIDLE32:
+- idle32.xmit_idle = (jiffies - ppp->last_xmit) / HZ;
+- idle32.recv_idle = (jiffies - ppp->last_recv) / HZ;
+- if (copy_to_user(argp, &idle32, sizeof(idle32)))
++ idle32.xmit_idle = max(0L, (long)(jiffies - READ_ONCE(ppp->last_xmit))) / HZ;
++ idle32.recv_idle = max(0L, (long)(jiffies - READ_ONCE(ppp->last_recv))) / HZ;
++ if (copy_to_user(argp, &idle32, sizeof(idle32)))
+ break;
+ err = 0;
+ break;
+
+ case PPPIOCGIDLE64:
+- idle64.xmit_idle = (jiffies - ppp->last_xmit) / HZ;
+- idle64.recv_idle = (jiffies - ppp->last_recv) / HZ;
++ idle64.xmit_idle = max(0L, (long)(jiffies - READ_ONCE(ppp->last_xmit))) / HZ;
++ idle64.recv_idle = max(0L, (long)(jiffies - READ_ONCE(ppp->last_recv))) / HZ;
+ if (copy_to_user(argp, &idle64, sizeof(idle64)))
+ break;
+ err = 0;
+@@ -929,7 +921,7 @@ static long ppp_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
+ if (copy_to_user(argp, &npi, sizeof(npi)))
+ break;
+ } else {
+- ppp->npmode[i] = npi.mode;
++ WRITE_ONCE(ppp->npmode[i], npi.mode);
+ /* we may be able to transmit more packets now (??) */
+ netif_wake_queue(ppp->dev);
+ }
+@@ -1466,7 +1458,7 @@ ppp_start_xmit(struct sk_buff *skb, struct net_device *dev)
+ goto outf;
+
+ /* Drop, accept or reject the packet */
+- switch (ppp->npmode[npi]) {
++ switch (READ_ONCE(ppp->npmode[npi])) {
+ case NPMODE_PASS:
+ break;
+ case NPMODE_QUEUE:
+@@ -1544,23 +1536,12 @@ ppp_net_siocdevprivate(struct net_device *dev, struct ifreq *ifr,
+ static void
+ ppp_get_stats64(struct net_device *dev, struct rtnl_link_stats64 *stats64)
+ {
+- struct ppp *ppp = netdev_priv(dev);
+-
+- ppp_recv_lock(ppp);
+- stats64->rx_packets = ppp->stats64.rx_packets;
+- stats64->rx_bytes = ppp->stats64.rx_bytes;
+- ppp_recv_unlock(ppp);
+-
+- ppp_xmit_lock(ppp);
+- stats64->tx_packets = ppp->stats64.tx_packets;
+- stats64->tx_bytes = ppp->stats64.tx_bytes;
+- ppp_xmit_unlock(ppp);
+-
+ stats64->rx_errors = dev->stats.rx_errors;
+ stats64->tx_errors = dev->stats.tx_errors;
+ stats64->rx_dropped = dev->stats.rx_dropped;
+ stats64->tx_dropped = dev->stats.tx_dropped;
+ stats64->rx_length_errors = dev->stats.rx_length_errors;
++ dev_fetch_sw_netstats(stats64, dev->tstats);
+ }
+
+ static int ppp_dev_init(struct net_device *dev)
+@@ -1658,6 +1639,9 @@ static void ppp_setup(struct net_device *dev)
+ dev->type = ARPHRD_PPP;
+ dev->flags = IFF_POINTOPOINT | IFF_NOARP | IFF_MULTICAST;
+ dev->priv_destructor = ppp_dev_priv_destructor;
++ dev->pcpu_stat_type = NETDEV_PCPU_STAT_TSTATS;
++ dev->features = NETIF_F_SG | NETIF_F_FRAGLIST;
++ dev->hw_features = dev->features;
+ netif_keep_dst(dev);
+ }
+
+@@ -1722,6 +1706,10 @@ pad_compress_skb(struct ppp *ppp, struct sk_buff *skb)
+ ppp->xcomp->comp_extra + ppp->dev->hard_header_len;
+ int compressor_skb_size = ppp->dev->mtu +
+ ppp->xcomp->comp_extra + PPP_HDRLEN;
++
++ if (skb_linearize(skb))
++ return NULL;
++
+ new_skb = alloc_skb(new_skb_size, GFP_ATOMIC);
+ if (!new_skb) {
+ if (net_ratelimit())
+@@ -1785,7 +1773,7 @@ ppp_send_frame(struct ppp *ppp, struct sk_buff *skb)
+ *(__be16 *)skb_push(skb, 2) = htons(PPP_FILTER_OUTBOUND_TAG);
+ if (ppp->pass_filter &&
+ bpf_prog_run(ppp->pass_filter, skb) == 0) {
+- if (ppp->debug & 1)
++ if (READ_ONCE(ppp->debug) & 1)
+ netdev_printk(KERN_DEBUG, ppp->dev,
+ "PPP: outbound frame "
+ "not passed\n");
+@@ -1795,21 +1783,24 @@ ppp_send_frame(struct ppp *ppp, struct sk_buff *skb)
+ /* if this packet passes the active filter, record the time */
+ if (!(ppp->active_filter &&
+ bpf_prog_run(ppp->active_filter, skb) == 0))
+- ppp->last_xmit = jiffies;
++ WRITE_ONCE(ppp->last_xmit, jiffies);
+ skb_pull(skb, 2);
+ #else
+ /* for data packets, record the time */
+- ppp->last_xmit = jiffies;
++ WRITE_ONCE(ppp->last_xmit, jiffies);
+ #endif /* CONFIG_PPP_FILTER */
+ }
+
+- ++ppp->stats64.tx_packets;
+- ppp->stats64.tx_bytes += skb->len - PPP_PROTO_LEN;
++ dev_sw_netstats_tx_add(ppp->dev, 1, skb->len - PPP_PROTO_LEN);
+
+ switch (proto) {
+ case PPP_IP:
+ if (!ppp->vj || (ppp->flags & SC_COMP_TCP) == 0)
+ break;
++
++ if (skb_linearize(skb))
++ goto drop;
++
+ /* try to do VJ TCP header compression */
+ new_skb = alloc_skb(skb->len + ppp->dev->hard_header_len - 2,
+ GFP_ATOMIC);
+@@ -1907,19 +1898,26 @@ ppp_push(struct ppp *ppp)
+ }
+
+ if ((ppp->flags & SC_MULTILINK) == 0) {
++ struct ppp_channel *chan;
+ /* not doing multilink: send it down the first channel */
+ list = list->next;
+ pch = list_entry(list, struct channel, clist);
+
+ spin_lock(&pch->downl);
+- if (pch->chan) {
+- if (pch->chan->ops->start_xmit(pch->chan, skb))
+- ppp->xmit_pending = NULL;
+- } else {
+- /* channel got unregistered */
++ chan = pch->chan;
++ if (unlikely(!chan || (!chan->direct_xmit && skb_linearize(skb)))) {
++ /* channel got unregistered, or it requires a linear
++ * skb but linearization failed
++ */
+ kfree_skb(skb);
+ ppp->xmit_pending = NULL;
++ goto out;
+ }
++
++ if (chan->ops->start_xmit(chan, skb))
++ ppp->xmit_pending = NULL;
++
++out:
+ spin_unlock(&pch->downl);
+ return;
+ }
+@@ -2004,6 +2002,8 @@ static int ppp_mp_explode(struct ppp *ppp, struct sk_buff *skb)
+ return 0; /* can't take now, leave it in xmit_pending */
+
+ /* Do protocol field compression */
++ if (skb_linearize(skb))
++ goto err_linearize;
+ p = skb->data;
+ len = skb->len;
+ if (*p == 0 && mp_protocol_compress) {
+@@ -2162,7 +2162,8 @@ static int ppp_mp_explode(struct ppp *ppp, struct sk_buff *skb)
+
+ noskb:
+ spin_unlock(&pch->downl);
+- if (ppp->debug & 1)
++ err_linearize:
++ if (READ_ONCE(ppp->debug) & 1)
+ netdev_err(ppp->dev, "PPP: no memory (fragment)\n");
+ ++ppp->dev->stats.tx_errors;
+ ++ppp->nxseq;
+@@ -2482,8 +2483,7 @@ ppp_receive_nonmp_frame(struct ppp *ppp, struct sk_buff *skb)
+ break;
+ }
+
+- ++ppp->stats64.rx_packets;
+- ppp->stats64.rx_bytes += skb->len - 2;
++ dev_sw_netstats_rx_add(ppp->dev, skb->len - PPP_PROTO_LEN);
+
+ npi = proto_to_npindex(proto);
+ if (npi < 0) {
+@@ -2509,7 +2509,7 @@ ppp_receive_nonmp_frame(struct ppp *ppp, struct sk_buff *skb)
+ *(__be16 *)skb_push(skb, 2) = htons(PPP_FILTER_INBOUND_TAG);
+ if (ppp->pass_filter &&
+ bpf_prog_run(ppp->pass_filter, skb) == 0) {
+- if (ppp->debug & 1)
++ if (READ_ONCE(ppp->debug) & 1)
+ netdev_printk(KERN_DEBUG, ppp->dev,
+ "PPP: inbound frame "
+ "not passed\n");
+@@ -2518,14 +2518,14 @@ ppp_receive_nonmp_frame(struct ppp *ppp, struct sk_buff *skb)
+ }
+ if (!(ppp->active_filter &&
+ bpf_prog_run(ppp->active_filter, skb) == 0))
+- ppp->last_recv = jiffies;
++ WRITE_ONCE(ppp->last_recv, jiffies);
+ __skb_pull(skb, 2);
+ } else
+ #endif /* CONFIG_PPP_FILTER */
+- ppp->last_recv = jiffies;
++ WRITE_ONCE(ppp->last_recv, jiffies);
+
+ if ((ppp->dev->flags & IFF_UP) == 0 ||
+- ppp->npmode[npi] != NPMODE_PASS) {
++ READ_ONCE(ppp->npmode[npi]) != NPMODE_PASS) {
+ kfree_skb(skb);
+ } else {
+ /* chop off protocol */
+@@ -2778,7 +2778,7 @@ ppp_mp_reconstruct(struct ppp *ppp)
+ seq = seq_before(minseq, PPP_MP_CB(p)->sequence)?
+ minseq + 1: PPP_MP_CB(p)->sequence;
+
+- if (ppp->debug & 1)
++ if (READ_ONCE(ppp->debug) & 1)
+ netdev_printk(KERN_DEBUG, ppp->dev,
+ "lost frag %u..%u\n",
+ oldseq, seq-1);
+@@ -2827,7 +2827,7 @@ ppp_mp_reconstruct(struct ppp *ppp)
+ struct sk_buff *tmp2;
+
+ skb_queue_reverse_walk_from_safe(list, p, tmp2) {
+- if (ppp->debug & 1)
++ if (READ_ONCE(ppp->debug) & 1)
+ netdev_printk(KERN_DEBUG, ppp->dev,
+ "discarding frag %u\n",
+ PPP_MP_CB(p)->sequence);
+@@ -2849,7 +2849,7 @@ ppp_mp_reconstruct(struct ppp *ppp)
+ skb_queue_walk_safe(list, p, tmp) {
+ if (p == head)
+ break;
+- if (ppp->debug & 1)
++ if (READ_ONCE(ppp->debug) & 1)
+ netdev_printk(KERN_DEBUG, ppp->dev,
+ "discarding frag %u\n",
+ PPP_MP_CB(p)->sequence);
+@@ -2857,7 +2857,7 @@ ppp_mp_reconstruct(struct ppp *ppp)
+ kfree_skb(p);
+ }
+
+- if (ppp->debug & 1)
++ if (READ_ONCE(ppp->debug) & 1)
+ netdev_printk(KERN_DEBUG, ppp->dev,
+ " missed pkts %u..%u\n",
+ ppp->nextseq,
+@@ -3167,7 +3167,8 @@ ppp_ccp_peek(struct ppp *ppp, struct sk_buff *skb, int inbound)
+ if (!ppp->rc_state)
+ break;
+ if (ppp->rcomp->decomp_init(ppp->rc_state, dp, len,
+- ppp->file.index, 0, ppp->mru, ppp->debug)) {
++ ppp->file.index, 0, ppp->mru,
++ READ_ONCE(ppp->debug))) {
+ ppp->rstate |= SC_DECOMP_RUN;
+ ppp->rstate &= ~(SC_DC_ERROR | SC_DC_FERROR);
+ }
+@@ -3176,7 +3177,8 @@ ppp_ccp_peek(struct ppp *ppp, struct sk_buff *skb, int inbound)
+ if (!ppp->xc_state)
+ break;
+ if (ppp->xcomp->comp_init(ppp->xc_state, dp, len,
+- ppp->file.index, 0, ppp->debug))
++ ppp->file.index, 0,
++ READ_ONCE(ppp->debug)))
+ ppp->xstate |= SC_COMP_RUN;
+ }
+ break;
+@@ -3311,14 +3313,25 @@ static void
+ ppp_get_stats(struct ppp *ppp, struct ppp_stats *st)
+ {
+ struct slcompress *vj = ppp->vj;
++ int cpu;
+
+ memset(st, 0, sizeof(*st));
+- st->p.ppp_ipackets = ppp->stats64.rx_packets;
++ for_each_possible_cpu(cpu) {
++ struct pcpu_sw_netstats *p = per_cpu_ptr(ppp->dev->tstats, cpu);
++ u64 rx_packets, rx_bytes, tx_packets, tx_bytes;
++
++ rx_packets = u64_stats_read(&p->rx_packets);
++ rx_bytes = u64_stats_read(&p->rx_bytes);
++ tx_packets = u64_stats_read(&p->tx_packets);
++ tx_bytes = u64_stats_read(&p->tx_bytes);
++
++ st->p.ppp_ipackets += rx_packets;
++ st->p.ppp_ibytes += rx_bytes;
++ st->p.ppp_opackets += tx_packets;
++ st->p.ppp_obytes += tx_bytes;
++ }
+ st->p.ppp_ierrors = ppp->dev->stats.rx_errors;
+- st->p.ppp_ibytes = ppp->stats64.rx_bytes;
+- st->p.ppp_opackets = ppp->stats64.tx_packets;
+ st->p.ppp_oerrors = ppp->dev->stats.tx_errors;
+- st->p.ppp_obytes = ppp->stats64.tx_bytes;
+ if (!vj)
+ return;
+ st->vj.vjs_packets = vj->sls_o_compressed + vj->sls_o_uncompressed;
+@@ -3507,6 +3520,10 @@ ppp_connect_channel(struct channel *pch, int unit)
+ ret = -ENOTCONN;
+ goto outl;
+ }
++ if (pch->chan->direct_xmit)
++ ppp->dev->priv_flags |= IFF_NO_QUEUE;
++ else
++ ppp->dev->priv_flags &= ~IFF_NO_QUEUE;
+ spin_unlock_bh(&pch->downl);
+ if (pch->file.hdrlen > ppp->file.hdrlen)
+ ppp->file.hdrlen = pch->file.hdrlen;
+@@ -3555,6 +3572,18 @@ ppp_disconnect_channel(struct channel *pch)
+ return err;
+ }
+
++/* Purge after the grace period: a late ppp_input() may still queue an
++ * skb on pch->file.rq before the last RCU reader drains.
++ */
++static void ppp_release_channel_free(struct rcu_head *rcu)
++{
++ struct channel *pch = container_of(rcu, struct channel, rcu);
++
++ skb_queue_purge(&pch->file.xq);
++ skb_queue_purge(&pch->file.rq);
++ kfree(pch);
++}
++
+ /*
+ * Free up the resources used by a ppp channel.
+ */
+@@ -3570,9 +3599,7 @@ static void ppp_destroy_channel(struct channel *pch)
+ pr_err("ppp: destroying undead channel %p !\n", pch);
+ return;
+ }
+- skb_queue_purge(&pch->file.xq);
+- skb_queue_purge(&pch->file.rq);
+- kfree(pch);
++ call_rcu(&pch->rcu, ppp_release_channel_free);
+ }
+
+ static void __exit ppp_cleanup(void)
+@@ -3585,6 +3612,7 @@ static void __exit ppp_cleanup(void)
+ device_destroy(ppp_class, MKDEV(PPP_MAJOR, 0));
+ class_destroy(ppp_class);
+ unregister_pernet_device(&ppp_net_ops);
++ rcu_barrier(); /* wait for RCU callbacks before module unload */
+ }
+
+ /*
+diff --git a/drivers/net/ppp/pppoe.c b/drivers/net/ppp/pppoe.c
+index 1744a3e3ae2cf7..0f8fc720ae00de 100644
+--- a/drivers/net/ppp/pppoe.c
++++ b/drivers/net/ppp/pppoe.c
+@@ -699,6 +699,7 @@ static int pppoe_connect(struct socket *sock, struct sockaddr *uservaddr,
+ po->chan.mtu = dev->mtu - sizeof(struct pppoe_hdr) - 2;
+ po->chan.private = sk;
+ po->chan.ops = &pppoe_chan_ops;
++ po->chan.direct_xmit = true;
+
+ error = ppp_register_net_channel(dev_net(dev), &po->chan);
+ if (error) {
+@@ -899,6 +900,7 @@ static int pppoe_sendmsg(struct socket *sock, struct msghdr *m,
+ dev_hard_header(skb, dev, ETH_P_PPP_SES,
+ po->pppoe_pa.remote, NULL, total_len);
+
++ ph = pppoe_hdr(skb);
+ memcpy(ph, &hdr, sizeof(struct pppoe_hdr));
+
+ ph->length = htons(total_len);
+diff --git a/drivers/net/ppp/pptp.c b/drivers/net/ppp/pptp.c
+index bf011bbb610589..466dd4575f9983 100644
+--- a/drivers/net/ppp/pptp.c
++++ b/drivers/net/ppp/pptp.c
+@@ -469,6 +469,7 @@ static int pptp_connect(struct socket *sock, struct sockaddr *uservaddr,
+ po->chan.mtu -= PPTP_HEADER_OVERHEAD;
+
+ po->chan.hdrlen = 2 + sizeof(struct pptp_gre_header);
++ po->chan.direct_xmit = true;
+ error = ppp_register_channel(&po->chan);
+ if (error) {
+ pr_err("PPTP: failed to register PPP channel (%d)\n", error);
+diff --git a/drivers/net/slip/slip.c b/drivers/net/slip/slip.c
+index 6865d32270e5d0..32260658a04957 100644
+--- a/drivers/net/slip/slip.c
++++ b/drivers/net/slip/slip.c
+@@ -693,6 +693,8 @@ static void slip_receive_buf(struct tty_struct *tty, const unsigned char *cp,
+ if (!sl || sl->magic != SLIP_MAGIC || !netif_running(sl->dev))
+ return;
+
++ spin_lock_bh(&sl->lock);
++
+ /* Read the characters out of the buffer */
+ while (count--) {
+ if (fp && *fp++) {
+@@ -708,6 +710,8 @@ static void slip_receive_buf(struct tty_struct *tty, const unsigned char *cp,
+ #endif
+ slip_unesc(sl, *cp++);
+ }
++
++ spin_unlock_bh(&sl->lock);
+ }
+
+ /************************************
+diff --git a/drivers/net/thunderbolt.c b/drivers/net/thunderbolt.c
+index ef13aa36e55e8d..a14655b795cca1 100644
+--- a/drivers/net/thunderbolt.c
++++ b/drivers/net/thunderbolt.c
+@@ -379,11 +379,16 @@ static void tbnet_tear_down(struct tbnet *net, bool send_logout)
+ break;
+ }
+
+- tb_ring_stop(net->rx_ring.ring);
+- tb_ring_stop(net->tx_ring.ring);
+- tbnet_free_buffers(&net->rx_ring);
+- tbnet_free_buffers(&net->tx_ring);
+-
++ /* Tear the paths down before stopping the rings. This mirrors
++ * tbnet_connected_work(), which enables the paths last so the
++ * Rx ring is primed before packets can arrive. Stopping a
++ * ring zeroes its descriptor base and tbnet_free_buffers()
++ * unmaps and frees the frame buffers, leaving anything still
++ * in flight with nowhere to drain to;
++ * __tb_path_deactivate_hop() then waits for the hop's
++ * 'pending' bit, which on some host routers never clears in
++ * that state.
++ */
+ ret = tb_xdomain_disable_paths(net->xd,
+ net->local_transmit_path,
+ net->tx_ring.ring->hop,
+@@ -392,6 +397,11 @@ static void tbnet_tear_down(struct tbnet *net, bool send_logout)
+ if (ret)
+ netdev_warn(net->dev, "failed to disable DMA paths\n");
+
++ tb_ring_stop(net->rx_ring.ring);
++ tb_ring_stop(net->tx_ring.ring);
++ tbnet_free_buffers(&net->rx_ring);
++ tbnet_free_buffers(&net->tx_ring);
++
+ tb_xdomain_release_in_hopid(net->xd, net->remote_transmit_path);
+ net->remote_transmit_path = 0;
+ }
+@@ -884,12 +894,8 @@ static int tbnet_open(struct net_device *dev)
+
+ netif_carrier_off(dev);
+
+- flags = RING_FLAG_FRAME;
+- /* Only enable full E2E if the other end supports it too */
+- if (tbnet_e2e && net->svc->prtcstns & TBNET_E2E)
+- flags |= RING_FLAG_E2E;
+-
+- ring = tb_ring_alloc_tx(xd->tb->nhi, -1, TBNET_RING_SIZE, flags);
++ ring = tb_ring_alloc_tx(xd->tb->nhi, -1, TBNET_RING_SIZE,
++ RING_FLAG_FRAME);
+ if (!ring) {
+ netdev_err(dev, "failed to allocate Tx ring\n");
+ return -ENOMEM;
+@@ -908,6 +914,11 @@ static int tbnet_open(struct net_device *dev)
+ sof_mask = BIT(TBIP_PDF_FRAME_START);
+ eof_mask = BIT(TBIP_PDF_FRAME_END);
+
++ flags = RING_FLAG_FRAME;
++ /* Only enable full E2E if the other end supports it too */
++ if (tbnet_e2e && net->svc->prtcstns & TBNET_E2E)
++ flags |= RING_FLAG_E2E;
++
+ ring = tb_ring_alloc_rx(xd->tb->nhi, -1, TBNET_RING_SIZE, flags,
+ net->tx_ring.ring->hop, sof_mask,
+ eof_mask, tbnet_start_poll, net);
+diff --git a/drivers/net/usb/ax88179_178a.c b/drivers/net/usb/ax88179_178a.c
+index 73de34179f3525..619093d3337320 100644
+--- a/drivers/net/usb/ax88179_178a.c
++++ b/drivers/net/usb/ax88179_178a.c
+@@ -1491,8 +1491,10 @@ ax88179_tx_fixup(struct usbnet *dev, struct sk_buff *skb, gfp_t flags)
+
+ headroom = skb_headroom(skb) - 8;
+
+- if ((dev->net->features & NETIF_F_SG) && skb_linearize(skb))
++ if ((dev->net->features & NETIF_F_SG) && skb_linearize(skb)) {
++ dev_kfree_skb_any(skb);
+ return NULL;
++ }
+
+ if ((skb_header_cloned(skb) || headroom < 0) &&
+ pskb_expand_head(skb, headroom < 0 ? 8 : 0, 0, GFP_ATOMIC)) {
+diff --git a/drivers/net/vmxnet3/vmxnet3_drv.c b/drivers/net/vmxnet3/vmxnet3_drv.c
+index 86b913d5ac5b7c..e6fb6c0ce27f5a 100644
+--- a/drivers/net/vmxnet3/vmxnet3_drv.c
++++ b/drivers/net/vmxnet3/vmxnet3_drv.c
+@@ -1365,7 +1365,11 @@ vmxnet3_get_hdr_len(struct vmxnet3_adapter *adapter, struct sk_buff *skb,
+ struct ipv6hdr *ipv6;
+ struct tcphdr *tcp;
+ } hdr;
+- BUG_ON(gdesc->rcd.tcp == 0);
++
++ /* v4/v6/tcp then describe the inner header, which we can't locate. */
++ if ((le32_to_cpu(gdesc->dword[0]) & (1UL << VMXNET3_RCD_HDR_INNER_SHIFT)) ||
++ gdesc->rcd.tcp == 0)
++ return 0;
+
+ maplen = skb_headlen(skb);
+ if (unlikely(sizeof(struct iphdr) + sizeof(struct tcphdr) > maplen))
+@@ -1379,15 +1383,21 @@ vmxnet3_get_hdr_len(struct vmxnet3_adapter *adapter, struct sk_buff *skb,
+
+ hdr.eth = eth_hdr(skb);
+ if (gdesc->rcd.v4) {
+- BUG_ON(hdr.eth->h_proto != htons(ETH_P_IP) &&
+- hdr.veth->h_vlan_encapsulated_proto != htons(ETH_P_IP));
++ if (hdr.eth->h_proto != htons(ETH_P_IP) &&
++ hdr.veth->h_vlan_encapsulated_proto != htons(ETH_P_IP))
++ return 0;
++
+ hdr.ptr += hlen;
+- BUG_ON(hdr.ipv4->protocol != IPPROTO_TCP);
++ if (hdr.ipv4->protocol != IPPROTO_TCP)
++ return 0;
++
+ hlen = hdr.ipv4->ihl << 2;
+ hdr.ptr += hdr.ipv4->ihl << 2;
+ } else if (gdesc->rcd.v6) {
+- BUG_ON(hdr.eth->h_proto != htons(ETH_P_IPV6) &&
+- hdr.veth->h_vlan_encapsulated_proto != htons(ETH_P_IPV6));
++ if (hdr.eth->h_proto != htons(ETH_P_IPV6) &&
++ hdr.veth->h_vlan_encapsulated_proto != htons(ETH_P_IPV6))
++ return 0;
++
+ hdr.ptr += hlen;
+ /* Use an estimated value, since we also need to handle
+ * TSO case.
+diff --git a/drivers/net/vrf.c b/drivers/net/vrf.c
+index 51b34882827e97..65668113f715e3 100644
+--- a/drivers/net/vrf.c
++++ b/drivers/net/vrf.c
+@@ -655,7 +655,7 @@ static int vrf_finish_output6(struct net *net, struct sock *sk,
+ skb->dev = dev;
+
+ rcu_read_lock();
+- nexthop = rt6_nexthop((struct rt6_info *)dst, &ipv6_hdr(skb)->daddr);
++ nexthop = rt6_nexthop(dst_rt6_info(dst), &ipv6_hdr(skb)->daddr);
+ neigh = __ipv6_neigh_lookup_noref(dst->dev, nexthop);
+ if (unlikely(!neigh))
+ neigh = __neigh_create(&nd_tbl, nexthop, dst->dev, false);
+diff --git a/drivers/net/vxlan/vxlan_core.c b/drivers/net/vxlan/vxlan_core.c
+index 4f689fe2f8c5a1..245c4c70504596 100644
+--- a/drivers/net/vxlan/vxlan_core.c
++++ b/drivers/net/vxlan/vxlan_core.c
+@@ -2156,7 +2156,7 @@ static bool route_shortcircuit(struct net_device *dev, struct sk_buff *skb)
+ {
+ struct iphdr *pip;
+
+- if (!pskb_may_pull(skb, sizeof(struct iphdr)))
++ if (!pskb_network_may_pull(skb, sizeof(struct iphdr)))
+ return false;
+ pip = ip_hdr(skb);
+ n = neigh_lookup(&arp_tbl, &pip->daddr, dev);
+@@ -2182,7 +2182,7 @@ static bool route_shortcircuit(struct net_device *dev, struct sk_buff *skb)
+ */
+ if (!ipv6_stub->nd_tbl)
+ return false;
+- if (!pskb_may_pull(skb, sizeof(struct ipv6hdr)))
++ if (!pskb_network_may_pull(skb, sizeof(struct ipv6hdr)))
+ return false;
+ pip6 = ipv6_hdr(skb);
+ n = neigh_lookup(ipv6_stub->nd_tbl, &pip6->daddr, dev);
+@@ -2204,13 +2204,19 @@ static bool route_shortcircuit(struct net_device *dev, struct sk_buff *skb)
+ }
+
+ if (n) {
++ u8 haddr[ETH_ALEN];
+ bool diff;
+
+- diff = !ether_addr_equal(eth_hdr(skb)->h_dest, n->ha);
++ neigh_ha_snapshot(haddr, n, dev);
++ diff = !ether_addr_equal_unaligned(eth_hdr(skb)->h_dest, haddr);
+ if (diff) {
++ if (skb_cow_head(skb, 0)) {
++ neigh_release(n);
++ return false;
++ }
+ memcpy(eth_hdr(skb)->h_source, eth_hdr(skb)->h_dest,
+ dev->addr_len);
+- memcpy(eth_hdr(skb)->h_dest, n->ha, dev->addr_len);
++ memcpy(eth_hdr(skb)->h_dest, haddr, dev->addr_len);
+ }
+ neigh_release(n);
+ return diff;
+@@ -2715,7 +2721,7 @@ static void vxlan_xmit_one(struct sk_buff *skb, struct net_device *dev,
+ }
+
+ if (!info) {
+- u32 rt6i_flags = ((struct rt6_info *)ndst)->rt6i_flags;
++ u32 rt6i_flags = dst_rt6_info(ndst)->rt6i_flags;
+
+ err = encap_bypass_if_local(skb, dev, vxlan, dst,
+ dst_port, ifindex, vni,
+@@ -2879,6 +2885,7 @@ static netdev_tx_t vxlan_xmit(struct sk_buff *skb, struct net_device *dev)
+ (ntohs(eth->h_proto) == ETH_P_IP ||
+ ntohs(eth->h_proto) == ETH_P_IPV6)) {
+ did_rsc = route_shortcircuit(dev, skb);
++ eth = eth_hdr(skb);
+ if (did_rsc)
+ f = vxlan_find_mac(vxlan, eth->h_dest, vni);
+ }
+@@ -4249,6 +4256,9 @@ static int vxlan_changelink(struct net_device *dev, struct nlattr *tb[],
+ struct vxlan_rdst *dst;
+ int err;
+
++ if (!rtnl_dev_link_net_capable(dev, vxlan->net))
++ return -EPERM;
++
+ dst = &vxlan->default_dst;
+ err = vxlan_nl2conf(tb, data, dev, &conf, true, extack);
+ if (err)
+@@ -4320,7 +4330,7 @@ static int vxlan_changelink(struct net_device *dev, struct nlattr *tb[],
+ if (change_igmp && vxlan_addr_multicast(&dst->remote_ip))
+ err = vxlan_multicast_leave(vxlan);
+
+- if (conf.age_interval != vxlan->cfg.age_interval)
++ if (netif_running(dev) && conf.age_interval != vxlan->cfg.age_interval)
+ mod_timer(&vxlan->age_timer, jiffies);
+
+ netdev_adjacent_change_commit(dst->remote_dev, lowerdev, dev);
+diff --git a/drivers/net/wan/wanxl.c b/drivers/net/wan/wanxl.c
+index 5a9e262188efe1..c38dd741401e13 100644
+--- a/drivers/net/wan/wanxl.c
++++ b/drivers/net/wan/wanxl.c
+@@ -514,7 +514,8 @@ static void wanxl_pci_remove_one(struct pci_dev *pdev)
+ if (card->irq)
+ free_irq(card->irq, card);
+
+- wanxl_reset(card);
++ if (card->plx)
++ wanxl_reset(card);
+
+ for (i = 0; i < RX_QUEUE_LENGTH; i++)
+ if (card->rx_skbs[i]) {
+diff --git a/drivers/net/wireless/ath/ath11k/dp_rx.c b/drivers/net/wireless/ath/ath11k/dp_rx.c
+index 397ce654bb3fd5..ac9796e8cd595c 100644
+--- a/drivers/net/wireless/ath/ath11k/dp_rx.c
++++ b/drivers/net/wireless/ath/ath11k/dp_rx.c
+@@ -4549,6 +4549,9 @@ static void ath11k_hal_rx_msdu_list_get(struct ath11k *ar,
+ msdu_details = &msdu_link->msdu_link[0];
+
+ for (i = 0; i < HAL_RX_NUM_MSDU_DESC; i++) {
++ if (!i && FIELD_GET(BUFFER_ADDR_INFO0_ADDR,
++ msdu_details[i].buf_addr_info.info0) == 0)
++ break;
+ if (FIELD_GET(BUFFER_ADDR_INFO0_ADDR,
+ msdu_details[i].buf_addr_info.info0) == 0) {
+ msdu_desc_info = &msdu_details[i - 1].rx_msdu_info;
+diff --git a/drivers/net/wireless/ath/ath11k/pci.c b/drivers/net/wireless/ath/ath11k/pci.c
+index a8431ce1ab9acb..9f00245f73cd7b 100644
+--- a/drivers/net/wireless/ath/ath11k/pci.c
++++ b/drivers/net/wireless/ath/ath11k/pci.c
+@@ -180,6 +180,8 @@ static void ath11k_pci_soc_global_reset(struct ath11k_base *ab)
+ val |= PCIE_SOC_GLOBAL_RESET_V;
+
+ ath11k_pcic_write32(ab, PCIE_SOC_GLOBAL_RESET, val);
++ /* Flush the posted write to the device */
++ ath11k_pcic_read32(ab, PCIE_SOC_GLOBAL_RESET);
+
+ /* TODO: exact time to sleep is uncertain */
+ delay = 10;
+@@ -189,6 +191,8 @@ static void ath11k_pci_soc_global_reset(struct ath11k_base *ab)
+ val &= ~PCIE_SOC_GLOBAL_RESET_V;
+
+ ath11k_pcic_write32(ab, PCIE_SOC_GLOBAL_RESET, val);
++ /* Flush the posted write to the device */
++ ath11k_pcic_read32(ab, PCIE_SOC_GLOBAL_RESET);
+
+ mdelay(delay);
+
+diff --git a/drivers/net/wireless/ath/ath11k/qmi.c b/drivers/net/wireless/ath/ath11k/qmi.c
+index f790759c86115a..396f87a77dfcdb 100644
+--- a/drivers/net/wireless/ath/ath11k/qmi.c
++++ b/drivers/net/wireless/ath/ath11k/qmi.c
+@@ -3235,9 +3235,14 @@ static void ath11k_qmi_driver_event_work(struct work_struct *work)
+ clear_bit(ATH11K_FLAG_CRASH_FLUSH,
+ &ab->dev_flags);
+ clear_bit(ATH11K_FLAG_RECOVERY, &ab->dev_flags);
+- ath11k_core_qmi_firmware_ready(ab);
+- set_bit(ATH11K_FLAG_REGISTERED, &ab->dev_flags);
+-
++ if (!test_bit(ATH11K_FLAG_REGISTERED, &ab->dev_flags)) {
++ ret = ath11k_core_qmi_firmware_ready(ab);
++ if (ret) {
++ set_bit(ATH11K_FLAG_QMI_FAIL, &ab->dev_flags);
++ break;
++ }
++ set_bit(ATH11K_FLAG_REGISTERED, &ab->dev_flags);
++ }
+ break;
+ case ATH11K_QMI_EVENT_COLD_BOOT_CAL_DONE:
+ break;
+diff --git a/drivers/net/wireless/ath/ath6kl/txrx.c b/drivers/net/wireless/ath/ath6kl/txrx.c
+index a56fab6232a9ba..159ec376baff8b 100644
+--- a/drivers/net/wireless/ath/ath6kl/txrx.c
++++ b/drivers/net/wireless/ath/ath6kl/txrx.c
+@@ -1722,13 +1722,15 @@ void aggr_recv_addba_req_evt(struct ath6kl_vif *vif, u8 tid_mux, u16 seq_no,
+
+ rxtid = &aggr_conn->rx_tid[tid];
+
+- if (win_sz < AGGR_WIN_SZ_MIN || win_sz > AGGR_WIN_SZ_MAX)
+- ath6kl_dbg(ATH6KL_DBG_WLAN_RX, "%s: win_sz %d, tid %d\n",
+- __func__, win_sz, tid);
+-
+ if (rxtid->aggr)
+ aggr_delete_tid_state(aggr_conn, tid);
+
++ if (win_sz < AGGR_WIN_SZ_MIN || win_sz > AGGR_WIN_SZ_MAX) {
++ ath6kl_dbg(ATH6KL_DBG_WLAN_RX, "%s: win_sz %d, tid %d\n",
++ __func__, win_sz, tid);
++ return;
++ }
++
+ rxtid->seq_next = seq_no;
+ hold_q_size = TID_WINDOW_SZ(win_sz) * sizeof(struct skb_hold_q);
+ rxtid->hold_q = kzalloc(hold_q_size, GFP_KERNEL);
+diff --git a/drivers/net/wireless/ath/ath6kl/wmi.c b/drivers/net/wireless/ath/ath6kl/wmi.c
+index 3787b9fb007559..447896b871c3e2 100644
+--- a/drivers/net/wireless/ath/ath6kl/wmi.c
++++ b/drivers/net/wireless/ath/ath6kl/wmi.c
+@@ -484,6 +484,18 @@ static int ath6kl_wmi_tx_complete_event_rx(u8 *datap, int len)
+
+ evt = (struct wmi_tx_complete_event *) datap;
+
++ if (len < sizeof(*evt)) {
++ ath6kl_dbg(ATH6KL_DBG_WMI, "tx complete: invalid len %d\n",
++ len);
++ return -EINVAL;
++ }
++
++ if (len < sizeof(*evt) + evt->num_msg * sizeof(struct tx_complete_msg_v1)) {
++ ath6kl_dbg(ATH6KL_DBG_WMI, "tx complete: invalid len %d for %u msgs\n",
++ len, evt->num_msg);
++ return -EINVAL;
++ }
++
+ ath6kl_dbg(ATH6KL_DBG_WMI, "comp: %d %d %d\n",
+ evt->num_msg, evt->msg_len, evt->msg_type);
+
+@@ -862,6 +874,14 @@ static int ath6kl_wmi_connect_event_rx(struct wmi *wmi, u8 *datap, int len,
+
+ ev = (struct wmi_connect_event *) datap;
+
++ if (len < sizeof(*ev) + ev->beacon_ie_len +
++ ev->assoc_req_len + ev->assoc_resp_len) {
++ ath6kl_dbg(ATH6KL_DBG_WMI,
++ "connect event: IE lengths %u+%u+%u exceed buffer %d\n",
++ ev->beacon_ie_len, ev->assoc_req_len,
++ ev->assoc_resp_len, len);
++ return -EINVAL;
++ }
+ if (vif->nw_type == AP_NETWORK) {
+ /* AP mode start/STA connected event */
+ struct net_device *dev = vif->ndev;
+diff --git a/drivers/net/wireless/ath/ath9k/hif_usb.c b/drivers/net/wireless/ath/ath9k/hif_usb.c
+index 6c73c0c0b82a99..7650f14dca8dad 100644
+--- a/drivers/net/wireless/ath/ath9k/hif_usb.c
++++ b/drivers/net/wireless/ath/ath9k/hif_usb.c
+@@ -1227,15 +1227,10 @@ static int ath9k_hif_request_firmware(struct hif_device_usb *hif_dev,
+ ret = request_firmware_nowait(THIS_MODULE, true, hif_dev->fw_name,
+ &hif_dev->udev->dev, GFP_KERNEL,
+ hif_dev, ath9k_hif_usb_firmware_cb);
+- if (ret) {
++ if (ret)
+ dev_err(&hif_dev->udev->dev,
+ "ath9k_htc: Async request for firmware %s failed\n",
+ hif_dev->fw_name);
+- return ret;
+- }
+-
+- dev_info(&hif_dev->udev->dev, "ath9k_htc: Firmware %s requested\n",
+- hif_dev->fw_name);
+
+ return ret;
+ }
+diff --git a/drivers/net/wireless/ath/carl9170/rx.c b/drivers/net/wireless/ath/carl9170/rx.c
+index 908c4c8b7f8256..bda30b1f940459 100644
+--- a/drivers/net/wireless/ath/carl9170/rx.c
++++ b/drivers/net/wireless/ath/carl9170/rx.c
+@@ -150,7 +150,8 @@ static void carl9170_cmd_callback(struct ar9170 *ar, u32 len, void *buffer)
+ spin_lock(&ar->cmd_lock);
+ if (ar->readbuf) {
+ if (len >= 4)
+- memcpy(ar->readbuf, buffer + 4, len - 4);
++ memcpy(ar->readbuf, buffer + 4,
++ min_t(u32, len - 4, ar->readlen));
+
+ ar->readbuf = NULL;
+ }
+@@ -917,7 +918,9 @@ static void carl9170_rx_stream(struct ar9170 *ar, void *buf, unsigned int len)
+ }
+ }
+
+- skb_put_data(ar->rx_failover, tbuf, tlen);
++ skb_put_data(ar->rx_failover, tbuf,
++ min_t(unsigned int, tlen,
++ ar->rx_failover_missing));
+ ar->rx_failover_missing -= tlen;
+
+ if (ar->rx_failover_missing <= 0) {
+diff --git a/drivers/net/wireless/ath/carl9170/tx.c b/drivers/net/wireless/ath/carl9170/tx.c
+index 88ef6e023f8266..d036ebb42c0d24 100644
+--- a/drivers/net/wireless/ath/carl9170/tx.c
++++ b/drivers/net/wireless/ath/carl9170/tx.c
+@@ -693,7 +693,7 @@ void carl9170_tx_process_status(struct ar9170 *ar,
+ unsigned int i;
+
+ for (i = 0; i < cmd->hdr.ext; i++) {
+- if (WARN_ON(i > ((cmd->hdr.len / 2) + 1))) {
++ if (WARN_ON(i >= (cmd->hdr.len / 2))) {
+ print_hex_dump_bytes("UU:", DUMP_PREFIX_NONE,
+ (void *) cmd, cmd->hdr.len + 4);
+ break;
+diff --git a/drivers/net/wireless/atmel/at76c50x-usb.c b/drivers/net/wireless/atmel/at76c50x-usb.c
+index 4a15c22cf348d6..3ea843c5663442 100644
+--- a/drivers/net/wireless/atmel/at76c50x-usb.c
++++ b/drivers/net/wireless/atmel/at76c50x-usb.c
+@@ -1527,13 +1527,16 @@ static inline int at76_guess_freq(struct at76_priv *priv)
+
+ if (ieee80211_is_probe_resp(hdr->frame_control)) {
+ el_off = offsetof(struct ieee80211_mgmt, u.probe_resp.variable);
+- el = ((struct ieee80211_mgmt *)hdr)->u.probe_resp.variable;
+ } else if (ieee80211_is_beacon(hdr->frame_control)) {
+ el_off = offsetof(struct ieee80211_mgmt, u.beacon.variable);
+- el = ((struct ieee80211_mgmt *)hdr)->u.beacon.variable;
+ } else {
+ goto exit;
+ }
++
++ if (len < el_off)
++ goto exit;
++
++ el = priv->rx_skb->data + el_off;
+ len -= el_off;
+
+ el = cfg80211_find_ie(WLAN_EID_DS_PARAMS, el, len);
+diff --git a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c
+index 6e7de5dce49eb7..66c139bf49283a 100644
+--- a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c
++++ b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c
+@@ -1791,7 +1791,7 @@ brcmf_set_key_mgmt(struct net_device *ndev, struct cfg80211_connect_params *sme)
+ sme->crypto.akm_suites[0]);
+ return -EINVAL;
+ }
+- } else if (val & (WPA2_AUTH_PSK | WPA2_AUTH_UNSPECIFIED)) {
++ } else if (val & (WPA2_AUTH_PSK | WPA2_AUTH_UNSPECIFIED | WPA2_AUTH_1X_SHA256)) {
+ switch (sme->crypto.akm_suites[0]) {
+ case WLAN_AKM_SUITE_8021X:
+ val = WPA2_AUTH_UNSPECIFIED;
+diff --git a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/pcie.c b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/pcie.c
+index 99cc41135473af..802c9dd89a0ec4 100644
+--- a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/pcie.c
++++ b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/pcie.c
+@@ -1356,16 +1356,20 @@ fail:
+ static void
+ brcmf_pcie_release_scratchbuffers(struct brcmf_pciedev_info *devinfo)
+ {
+- if (devinfo->shared.scratch)
++ if (devinfo->shared.scratch) {
+ dma_free_coherent(&devinfo->pdev->dev,
+ BRCMF_DMA_D2H_SCRATCH_BUF_LEN,
+ devinfo->shared.scratch,
+ devinfo->shared.scratch_dmahandle);
+- if (devinfo->shared.ringupd)
++ devinfo->shared.scratch = NULL;
++ }
++ if (devinfo->shared.ringupd) {
+ dma_free_coherent(&devinfo->pdev->dev,
+ BRCMF_DMA_D2H_RINGUPD_BUF_LEN,
+ devinfo->shared.ringupd,
+ devinfo->shared.ringupd_dmahandle);
++ devinfo->shared.ringupd = NULL;
++ }
+ }
+
+ static int brcmf_pcie_init_scratchbuffers(struct brcmf_pciedev_info *devinfo)
+diff --git a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/sdio.c b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/sdio.c
+index 5f6c0afe22d49c..fb09d76ea053cb 100644
+--- a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/sdio.c
++++ b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/sdio.c
+@@ -4451,6 +4451,7 @@ struct brcmf_sdio *brcmf_sdio_probe(struct brcmf_sdio_dev *sdiodev)
+ bus->sdiodev = sdiodev;
+ sdiodev->bus = bus;
+ skb_queue_head_init(&bus->glom);
++ INIT_WORK(&bus->datawork, brcmf_sdio_dataworker);
+ bus->txbound = BRCMF_TXBOUND;
+ bus->rxbound = BRCMF_RXBOUND;
+ bus->txminmax = BRCMF_TXMINMAX;
+@@ -4464,7 +4465,6 @@ struct brcmf_sdio *brcmf_sdio_probe(struct brcmf_sdio_dev *sdiodev)
+ goto fail;
+ }
+ brcmf_sdiod_freezer_count(sdiodev);
+- INIT_WORK(&bus->datawork, brcmf_sdio_dataworker);
+ bus->brcmf_wq = wq;
+
+ /* attempt to attach to the dongle */
+diff --git a/drivers/net/wireless/intel/ipw2x00/ipw2100.c b/drivers/net/wireless/intel/ipw2x00/ipw2100.c
+index b0f23cf1a621b6..a76e94fcb29558 100644
+--- a/drivers/net/wireless/intel/ipw2x00/ipw2100.c
++++ b/drivers/net/wireless/intel/ipw2x00/ipw2100.c
+@@ -6183,6 +6183,8 @@ static int ipw2100_pci_init_one(struct pci_dev *pci_dev,
+ if (err) {
+ printk(KERN_WARNING DRV_NAME
+ "Error calling pci_enable_device.\n");
++ free_libipw(dev, 0);
++ pci_iounmap(pci_dev, ioaddr);
+ return err;
+ }
+
+@@ -6195,16 +6197,14 @@ static int ipw2100_pci_init_one(struct pci_dev *pci_dev,
+ if (err) {
+ printk(KERN_WARNING DRV_NAME
+ "Error calling pci_set_dma_mask.\n");
+- pci_disable_device(pci_dev);
+- return err;
++ goto fail;
+ }
+
+ err = pci_request_regions(pci_dev, DRV_NAME);
+ if (err) {
+ printk(KERN_WARNING DRV_NAME
+ "Error calling pci_request_regions.\n");
+- pci_disable_device(pci_dev);
+- return err;
++ goto fail;
+ }
+
+ /* We disable the RETRY_TIMEOUT register (0x41) to keep
+diff --git a/drivers/net/wireless/intel/iwlwifi/mvm/d3.c b/drivers/net/wireless/intel/iwlwifi/mvm/d3.c
+index 1425763fec4ea1..d7b2781a1eeaf1 100644
+--- a/drivers/net/wireless/intel/iwlwifi/mvm/d3.c
++++ b/drivers/net/wireless/intel/iwlwifi/mvm/d3.c
+@@ -2627,7 +2627,7 @@ static int iwl_mvm_wowlan_store_wake_pkt(struct iwl_mvm *mvm,
+ struct iwl_wowlan_status_data *status,
+ u32 len)
+ {
+- u32 data_size, packet_len = le32_to_cpu(notif->wake_packet_length);
++ u32 data_size, packet_len;
+
+ if (len < sizeof(*notif)) {
+ IWL_ERR(mvm, "Invalid WoWLAN wake packet notification!\n");
+@@ -2646,6 +2646,7 @@ static int iwl_mvm_wowlan_store_wake_pkt(struct iwl_mvm *mvm,
+ return -EIO;
+ }
+
++ packet_len = le32_to_cpu(notif->wake_packet_length);
+ data_size = len - offsetof(struct iwl_wowlan_wake_pkt_notif, wake_packet);
+
+ /* data_size got the padding from the notification, remove it. */
+diff --git a/drivers/net/wireless/intersil/p54/txrx.c b/drivers/net/wireless/intersil/p54/txrx.c
+index 2deb1bb54f24bd..dc7bf54e30bba1 100644
+--- a/drivers/net/wireless/intersil/p54/txrx.c
++++ b/drivers/net/wireless/intersil/p54/txrx.c
+@@ -499,11 +499,19 @@ static void p54_rx_eeprom_readback(struct p54_common *priv,
+ if (le16_to_cpu(eeprom->v2.len) != priv->eeprom_slice_size)
+ return;
+
++ if (eeprom->v2.data + priv->eeprom_slice_size >
++ skb_tail_pointer(skb))
++ return;
++
+ memcpy(priv->eeprom, eeprom->v2.data, priv->eeprom_slice_size);
+ } else {
+ if (le16_to_cpu(eeprom->v1.len) != priv->eeprom_slice_size)
+ return;
+
++ if (eeprom->v1.data + priv->eeprom_slice_size >
++ skb_tail_pointer(skb))
++ return;
++
+ memcpy(priv->eeprom, eeprom->v1.data, priv->eeprom_slice_size);
+ }
+
+diff --git a/drivers/net/wireless/mac80211_hwsim.c b/drivers/net/wireless/mac80211_hwsim.c
+index 316b5f56b6e53f..bb9dabbf1f22c6 100644
+--- a/drivers/net/wireless/mac80211_hwsim.c
++++ b/drivers/net/wireless/mac80211_hwsim.c
+@@ -5564,6 +5564,7 @@ static void hwsim_virtio_rx_work(struct work_struct *work)
+
+ skb->data = skb->head;
+ skb_reset_tail_pointer(skb);
++ len = min(len, skb_end_offset(skb));
+ skb_put(skb, len);
+ hwsim_virtio_handle_cmd(skb);
+
+diff --git a/drivers/net/wireless/marvell/libertas/firmware.c b/drivers/net/wireless/marvell/libertas/firmware.c
+index f124110944b7e9..9bf7d4c207b9ed 100644
+--- a/drivers/net/wireless/marvell/libertas/firmware.c
++++ b/drivers/net/wireless/marvell/libertas/firmware.c
+@@ -78,6 +78,7 @@ static void helper_firmware_cb(const struct firmware *firmware, void *context)
+ } else {
+ /* No main firmware needed for this helper --> success! */
+ lbs_fw_loaded(priv, 0, firmware, NULL);
++ release_firmware(firmware);
+ }
+ }
+
+diff --git a/drivers/net/wireless/marvell/mwifiex/11n_rxreorder.c b/drivers/net/wireless/marvell/mwifiex/11n_rxreorder.c
+index a0d596c74c72b2..e3aa45aab11bc2 100644
+--- a/drivers/net/wireless/marvell/mwifiex/11n_rxreorder.c
++++ b/drivers/net/wireless/marvell/mwifiex/11n_rxreorder.c
+@@ -44,7 +44,7 @@ static int mwifiex_11n_dispatch_amsdu_pkt(struct mwifiex_private *priv,
+ ntohs(rx_hdr->eth803_hdr.h_proto) == ETH_P_TDLS) {
+ mwifiex_process_tdls_action_frame(priv,
+ (u8 *)rx_hdr,
+- skb->len);
++ rx_skb->len);
+ }
+
+ if (priv->bss_role == MWIFIEX_BSS_ROLE_UAP)
+diff --git a/drivers/net/wireless/marvell/mwifiex/tdls.c b/drivers/net/wireless/marvell/mwifiex/tdls.c
+index 6c60621b6cccb5..d503db3789c554 100644
+--- a/drivers/net/wireless/marvell/mwifiex/tdls.c
++++ b/drivers/net/wireless/marvell/mwifiex/tdls.c
+@@ -215,7 +215,7 @@ mwifiex_tdls_add_ht_oper(struct mwifiex_private *priv, const u8 *mac,
+
+ /* follow AP's channel bandwidth */
+ if (ISSUPP_CHANWIDTH40(priv->adapter->hw_dot_11n_dev_cap) &&
+- bss_desc->bcn_ht_cap &&
++ bss_desc->bcn_ht_oper &&
+ ISALLOWED_CHANWIDTH40(bss_desc->bcn_ht_oper->ht_param))
+ ht_oper->ht_param = bss_desc->bcn_ht_oper->ht_param;
+
+diff --git a/drivers/net/wireless/marvell/mwifiex/uap_event.c b/drivers/net/wireless/marvell/mwifiex/uap_event.c
+index 58ef5020a46a73..c7383abf064f50 100644
+--- a/drivers/net/wireless/marvell/mwifiex/uap_event.c
++++ b/drivers/net/wireless/marvell/mwifiex/uap_event.c
+@@ -123,11 +123,31 @@ int mwifiex_process_uap_event(struct mwifiex_private *priv)
+ len = ETH_ALEN;
+
+ if (len != -1) {
++ u16 evt_len = le16_to_cpu(event->len);
++
+ sinfo->assoc_req_ies = &event->data[len];
+ len = (u8 *)sinfo->assoc_req_ies -
+ (u8 *)&event->frame_control;
+- sinfo->assoc_req_ies_len =
+- le16_to_cpu(event->len) - (u16)len;
++
++ /*
++ * event->len is reported by the device firmware
++ * and is not otherwise validated. Reject a
++ * length that underflows the header, or that
++ * would place the association request IEs
++ * outside the fixed-size event_body[] buffer the
++ * event was copied into; otherwise the IE walk
++ * in mwifiex_set_sta_ht_cap() reads past
++ * event_body and out of the adapter slab object.
++ */
++ if (evt_len < len ||
++ (u8 *)&event->frame_control + evt_len >
++ adapter->event_body + MAX_EVENT_SIZE) {
++ mwifiex_dbg(adapter, ERROR,
++ "invalid STA assoc event length\n");
++ kfree(sinfo);
++ return -1;
++ }
++ sinfo->assoc_req_ies_len = evt_len - (u16)len;
+ }
+ }
+ cfg80211_new_sta(priv->netdev, event->sta_addr, sinfo,
+diff --git a/drivers/net/wireless/mediatek/mt76/mt7615/mac.c b/drivers/net/wireless/mediatek/mt76/mt7615/mac.c
+index 40c80d09d108a3..ea22a4e5efe4f3 100644
+--- a/drivers/net/wireless/mediatek/mt76/mt7615/mac.c
++++ b/drivers/net/wireless/mediatek/mt76/mt7615/mac.c
+@@ -1618,6 +1618,8 @@ bool mt7615_rx_check(struct mt76_dev *mdev, void *data, int len)
+
+ switch (type) {
+ case PKT_TYPE_TXRX_NOTIFY:
++ if (!mt76_is_mmio(mdev))
++ return false;
+ mt7615_mac_tx_free(dev, data, len);
+ return false;
+ case PKT_TYPE_TXS:
+@@ -1651,6 +1653,10 @@ void mt7615_queue_rx_skb(struct mt76_dev *mdev, enum mt76_rxq_id q,
+ dev_kfree_skb(skb);
+ break;
+ case PKT_TYPE_TXRX_NOTIFY:
++ if (!mt76_is_mmio(mdev)) {
++ dev_kfree_skb(skb);
++ break;
++ }
+ mt7615_mac_tx_free(dev, skb->data, skb->len);
+ dev_kfree_skb(skb);
+ break;
+diff --git a/drivers/net/wireless/mediatek/mt76/mt76_connac_mcu.c b/drivers/net/wireless/mediatek/mt76/mt76_connac_mcu.c
+index 6b5bfdbec8b11d..6f4b1a784a0786 100644
+--- a/drivers/net/wireless/mediatek/mt76/mt76_connac_mcu.c
++++ b/drivers/net/wireless/mediatek/mt76/mt76_connac_mcu.c
+@@ -1298,6 +1298,8 @@ mt76_connac_mcu_uni_bss_he_tlv(struct mt76_phy *phy, struct ieee80211_vif *vif,
+ struct bss_info_uni_he *he;
+
+ cap = mt76_connac_get_he_phy_cap(phy, vif);
++ if (!cap)
++ return;
+
+ he = (struct bss_info_uni_he *)tlv;
+ he->he_pe_duration = vif->bss_conf.htc_trig_based_pkt_ext;
+diff --git a/drivers/net/wireless/mediatek/mt76/mt7915/mcu.c b/drivers/net/wireless/mediatek/mt76/mt7915/mcu.c
+index 44fbfe3775e060..777ae8206df0ca 100644
+--- a/drivers/net/wireless/mediatek/mt76/mt7915/mcu.c
++++ b/drivers/net/wireless/mediatek/mt76/mt7915/mcu.c
+@@ -518,6 +518,8 @@ mt7915_mcu_bss_he_tlv(struct sk_buff *skb, struct ieee80211_vif *vif,
+ struct tlv *tlv;
+
+ cap = mt76_connac_get_he_phy_cap(phy->mt76, vif);
++ if (!cap)
++ return;
+
+ tlv = mt76_connac_mcu_add_tlv(skb, BSS_INFO_HE_BASIC, sizeof(*he));
+
+@@ -1098,13 +1100,12 @@ mt7915_mcu_sta_bfer_vht(struct ieee80211_sta *sta, struct mt7915_phy *phy,
+ }
+
+ static void
+-mt7915_mcu_sta_bfer_he(struct ieee80211_sta *sta, struct ieee80211_vif *vif,
+- struct mt7915_phy *phy, struct sta_rec_bf *bf)
++mt7915_mcu_sta_bfer_he(struct ieee80211_sta *sta,
++ const struct ieee80211_sta_he_cap *vc,
++ struct sta_rec_bf *bf)
+ {
+ struct ieee80211_sta_he_cap *pc = &sta->deflink.he_cap;
+ struct ieee80211_he_cap_elem *pe = &pc->he_cap_elem;
+- const struct ieee80211_sta_he_cap *vc =
+- mt76_connac_get_he_phy_cap(phy->mt76, vif);
+ const struct ieee80211_he_cap_elem *ve = &vc->he_cap_elem;
+ u16 mcs_map = le16_to_cpu(pc->he_mcs_nss_supp.rx_mcs_80);
+ u8 nss_mcs = mt7915_mcu_get_sta_nss(mcs_map);
+@@ -1163,6 +1164,7 @@ mt7915_mcu_sta_bfer_tlv(struct mt7915_dev *dev, struct sk_buff *skb,
+ {
+ struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
+ struct mt7915_phy *phy = mvif->phy;
++ const struct ieee80211_sta_he_cap *vc = NULL;
+ int tx_ant = hweight8(phy->mt76->chainmask) - 1;
+ struct sta_rec_bf *bf;
+ struct tlv *tlv;
+@@ -1181,6 +1183,12 @@ mt7915_mcu_sta_bfer_tlv(struct mt7915_dev *dev, struct sk_buff *skb,
+ if (!ebf && !dev->ibf)
+ return;
+
++ if (sta->deflink.he_cap.has_he && ebf) {
++ vc = mt76_connac_get_he_phy_cap(phy->mt76, vif);
++ if (!vc)
++ return;
++ }
++
+ tlv = mt76_connac_mcu_add_tlv(skb, STA_REC_BF, sizeof(*bf));
+ bf = (struct sta_rec_bf *)tlv;
+
+@@ -1189,7 +1197,7 @@ mt7915_mcu_sta_bfer_tlv(struct mt7915_dev *dev, struct sk_buff *skb,
+ * ht: iBF only, since mac80211 lacks of eBF support
+ */
+ if (sta->deflink.he_cap.has_he && ebf)
+- mt7915_mcu_sta_bfer_he(sta, vif, phy, bf);
++ mt7915_mcu_sta_bfer_he(sta, vc, bf);
+ else if (sta->deflink.vht_cap.vht_supported)
+ mt7915_mcu_sta_bfer_vht(sta, phy, bf, ebf);
+ else if (sta->deflink.ht_cap.ht_supported)
+diff --git a/drivers/net/wireless/mediatek/mt76/mt7921/mac.c b/drivers/net/wireless/mediatek/mt76/mt7921/mac.c
+index cae7c21ca1f8b0..cb9a86a701f1d2 100644
+--- a/drivers/net/wireless/mediatek/mt76/mt7921/mac.c
++++ b/drivers/net/wireless/mediatek/mt76/mt7921/mac.c
+@@ -678,8 +678,9 @@ bool mt7921_rx_check(struct mt76_dev *mdev, void *data, int len)
+
+ switch (type) {
+ case PKT_TYPE_TXRX_NOTIFY:
+- /* PKT_TYPE_TXRX_NOTIFY can be received only by mmio devices */
+- mt7921_mac_tx_free(dev, data, len); /* mmio */
++ if (!mt76_is_mmio(mdev))
++ return false;
++ mt7921_mac_tx_free(dev, data, len);
+ return false;
+ case PKT_TYPE_TXS:
+ for (rxd += 2; rxd + 8 <= end; rxd += 8)
+@@ -708,7 +709,10 @@ void mt7921_queue_rx_skb(struct mt76_dev *mdev, enum mt76_rxq_id q,
+
+ switch (type) {
+ case PKT_TYPE_TXRX_NOTIFY:
+- /* PKT_TYPE_TXRX_NOTIFY can be received only by mmio devices */
++ if (!mt76_is_mmio(mdev)) {
++ napi_consume_skb(skb, 1);
++ break;
++ }
+ mt7921_mac_tx_free(dev, skb->data, skb->len);
+ napi_consume_skb(skb, 1);
+ break;
+diff --git a/drivers/net/wireless/microchip/wilc1000/hif.c b/drivers/net/wireless/microchip/wilc1000/hif.c
+index 4dbd0f86a71e4d..06d0c2ef10889d 100644
+--- a/drivers/net/wireless/microchip/wilc1000/hif.c
++++ b/drivers/net/wireless/microchip/wilc1000/hif.c
+@@ -597,6 +597,11 @@ static s32 wilc_parse_assoc_resp_info(u8 *buffer, u32 buffer_len,
+ u16 ies_len;
+ struct wilc_assoc_resp *res = (struct wilc_assoc_resp *)buffer;
+
++ if (buffer_len < sizeof(*res)) {
++ ret_conn_info->status = WLAN_STATUS_UNSPECIFIED_FAILURE;
++ return -EINVAL;
++ }
++
+ ret_conn_info->status = le16_to_cpu(res->status_code);
+ if (ret_conn_info->status == WLAN_STATUS_SUCCESS) {
+ ies = &buffer[sizeof(*res)];
+diff --git a/drivers/phy/xilinx/phy-zynqmp.c b/drivers/phy/xilinx/phy-zynqmp.c
+index cc36fb7616ae44..9e3177845a4092 100644
+--- a/drivers/phy/xilinx/phy-zynqmp.c
++++ b/drivers/phy/xilinx/phy-zynqmp.c
+@@ -53,7 +53,7 @@
+ #define L0_TM_DIG_6 0x106c
+ #define L0_TM_DIS_DESCRAMBLE_DECODER 0x0f
+ #define L0_TX_DIG_61 0x00f4
+-#define L0_TM_DISABLE_SCRAMBLE_ENCODER 0x0f
++#define L0_TM_DISABLE_SCRAMBLE_ENCODER (BIT(3) | GENMASK(1, 0))
+
+ /* PLL Test Mode register parameters */
+ #define L0_TM_PLL_DIG_37 0x2094
+@@ -228,7 +228,6 @@ struct xpsgtr_phy {
+ * @siou: siou base address
+ * @gtr_mutex: mutex for locking
+ * @phys: PHY lanes
+- * @refclk_sscs: spread spectrum settings for the reference clocks
+ * @clk: reference clocks
+ * @tx_term_fix: fix for GT issue
+ * @saved_icm_cfg0: stored value of ICM CFG0 register
+@@ -241,7 +240,6 @@ struct xpsgtr_dev {
+ void __iomem *siou;
+ struct mutex gtr_mutex; /* mutex for locking */
+ struct xpsgtr_phy phys[NUM_LANES];
+- const struct xpsgtr_ssc *refclk_sscs[NUM_LANES];
+ struct clk *clk[NUM_LANES];
+ bool tx_term_fix;
+ unsigned int saved_icm_cfg0;
+@@ -384,13 +382,40 @@ static int xpsgtr_wait_pll_lock(struct phy *phy)
+ return ret;
+ }
+
++/* Get the spread spectrum (SSC) settings for the reference clock rate */
++static const struct xpsgtr_ssc *xpsgtr_find_sscs(struct xpsgtr_phy *gtr_phy)
++{
++ unsigned long rate;
++ struct clk *clk;
++ unsigned int i;
++
++ clk = gtr_phy->dev->clk[gtr_phy->refclk];
++ rate = clk_get_rate(clk);
++
++ for (i = 0 ; i < ARRAY_SIZE(ssc_lookup); i++) {
++ /* Allow an error of 100 ppm */
++ unsigned long error = ssc_lookup[i].refclk_rate / 10000;
++
++ if (abs(rate - ssc_lookup[i].refclk_rate) < error)
++ return &ssc_lookup[i];
++ }
++
++ dev_err(gtr_phy->dev->dev, "Invalid rate %lu for reference clock %u\n",
++ rate, gtr_phy->refclk);
++
++ return NULL;
++}
++
+ /* Configure PLL and spread-sprectrum clock. */
+-static void xpsgtr_configure_pll(struct xpsgtr_phy *gtr_phy)
++static int xpsgtr_configure_pll(struct xpsgtr_phy *gtr_phy)
+ {
+ const struct xpsgtr_ssc *ssc;
+ u32 step_size;
+
+- ssc = gtr_phy->dev->refclk_sscs[gtr_phy->refclk];
++ ssc = xpsgtr_find_sscs(gtr_phy);
++ if (!ssc)
++ return -EINVAL;
++
+ step_size = ssc->step_size;
+
+ xpsgtr_clr_set(gtr_phy->dev, PLL_REF_SEL(gtr_phy->lane),
+@@ -432,6 +457,8 @@ static void xpsgtr_configure_pll(struct xpsgtr_phy *gtr_phy)
+ xpsgtr_clr_set_phy(gtr_phy, L0_PLL_SS_STEP_SIZE_3_MSB,
+ STEP_SIZE_3_MASK, (step_size & STEP_SIZE_3_MASK) |
+ FORCE_STEP_SIZE | FORCE_STEPS);
++
++ return 0;
+ }
+
+ /* Configure the lane protocol. */
+@@ -461,11 +488,30 @@ static void xpsgtr_lane_set_protocol(struct xpsgtr_phy *gtr_phy)
+ }
+ }
+
+-/* Bypass (de)scrambler and 8b/10b decoder and encoder. */
+-static void xpsgtr_bypass_scrambler_8b10b(struct xpsgtr_phy *gtr_phy)
++/**
++ * xpsgtr_bypass_scrambler_8b10b - Configure scrambler/encoder behavior
++ * @gtr_phy: pointer to lane context
++ * @bypass: true to enable scrambler/encoder bypass (SATA/SGMII),
++ * false to disable scrambler/encoder bypass (USB3)
++ *
++ * Uses RMW to preserve reserved and unrelated register fields.
++ */
++static void xpsgtr_bypass_scrambler_8b10b(struct xpsgtr_phy *gtr_phy,
++ bool bypass)
+ {
+- xpsgtr_write_phy(gtr_phy, L0_TM_DIG_6, L0_TM_DIS_DESCRAMBLE_DECODER);
+- xpsgtr_write_phy(gtr_phy, L0_TX_DIG_61, L0_TM_DISABLE_SCRAMBLE_ENCODER);
++ if (bypass) {
++ xpsgtr_clr_set_phy(gtr_phy, L0_TM_DIG_6,
++ L0_TM_DIS_DESCRAMBLE_DECODER,
++ L0_TM_DIS_DESCRAMBLE_DECODER);
++ xpsgtr_clr_set_phy(gtr_phy, L0_TX_DIG_61,
++ L0_TM_DISABLE_SCRAMBLE_ENCODER,
++ L0_TM_DISABLE_SCRAMBLE_ENCODER);
++ } else {
++ xpsgtr_clr_set_phy(gtr_phy, L0_TM_DIG_6,
++ L0_TM_DIS_DESCRAMBLE_DECODER, 0);
++ xpsgtr_clr_set_phy(gtr_phy, L0_TX_DIG_61,
++ L0_TM_DISABLE_SCRAMBLE_ENCODER, 0);
++ }
+ }
+
+ /* DP-specific initialization. */
+@@ -486,7 +532,7 @@ static void xpsgtr_phy_init_sata(struct xpsgtr_phy *gtr_phy)
+ {
+ struct xpsgtr_dev *gtr_dev = gtr_phy->dev;
+
+- xpsgtr_bypass_scrambler_8b10b(gtr_phy);
++ xpsgtr_bypass_scrambler_8b10b(gtr_phy, true);
+
+ writel(gtr_phy->lane, gtr_dev->siou + SATA_CONTROL_OFFSET);
+ }
+@@ -502,7 +548,7 @@ static void xpsgtr_phy_init_sgmii(struct xpsgtr_phy *gtr_phy)
+ xpsgtr_clr_set(gtr_dev, TX_PROT_BUS_WIDTH, mask, val);
+ xpsgtr_clr_set(gtr_dev, RX_PROT_BUS_WIDTH, mask, val);
+
+- xpsgtr_bypass_scrambler_8b10b(gtr_phy);
++ xpsgtr_bypass_scrambler_8b10b(gtr_phy, true);
+ }
+
+ /* Configure TX de-emphasis and margining for DP. */
+@@ -617,12 +663,13 @@ static int xpsgtr_phy_init(struct phy *phy)
+ {
+ struct xpsgtr_phy *gtr_phy = phy_get_drvdata(phy);
+ struct xpsgtr_dev *gtr_dev = gtr_phy->dev;
+- int ret = 0;
++ int ret;
+
+ mutex_lock(>r_dev->gtr_mutex);
+
+ /* Configure and enable the clock when peripheral phy_init call */
+- if (clk_prepare_enable(gtr_dev->clk[gtr_phy->refclk]))
++ ret = clk_prepare_enable(gtr_dev->clk[gtr_phy->refclk]);
++ if (ret)
+ goto out;
+
+ /* Skip initialization if not required. */
+@@ -632,7 +679,7 @@ static int xpsgtr_phy_init(struct phy *phy)
+ if (gtr_dev->tx_term_fix) {
+ ret = xpsgtr_phy_tx_term_fix(gtr_phy);
+ if (ret < 0)
+- goto out;
++ goto out_disable_clk;
+
+ gtr_dev->tx_term_fix = false;
+ }
+@@ -644,7 +691,10 @@ static int xpsgtr_phy_init(struct phy *phy)
+ * Configure the PLL, the lane protocol, and perform protocol-specific
+ * initialization.
+ */
+- xpsgtr_configure_pll(gtr_phy);
++ ret = xpsgtr_configure_pll(gtr_phy);
++ if (ret)
++ goto out_disable_clk;
++
+ xpsgtr_lane_set_protocol(gtr_phy);
+
+ switch (gtr_phy->protocol) {
+@@ -659,8 +709,16 @@ static int xpsgtr_phy_init(struct phy *phy)
+ case ICM_PROTOCOL_SGMII:
+ xpsgtr_phy_init_sgmii(gtr_phy);
+ break;
++
++ case ICM_PROTOCOL_USB:
++ xpsgtr_bypass_scrambler_8b10b(gtr_phy, false);
++ break;
+ }
+
++ goto out;
++
++out_disable_clk:
++ clk_disable_unprepare(gtr_dev->clk[gtr_phy->refclk]);
+ out:
+ mutex_unlock(>r_dev->gtr_mutex);
+ return ret;
+@@ -855,8 +913,7 @@ static struct phy *xpsgtr_xlate(struct device *dev,
+ }
+
+ refclk = args->args[3];
+- if (refclk >= ARRAY_SIZE(gtr_dev->refclk_sscs) ||
+- !gtr_dev->refclk_sscs[refclk]) {
++ if (refclk >= ARRAY_SIZE(gtr_dev->clk)) {
+ dev_err(dev, "Invalid reference clock number %u\n", refclk);
+ return ERR_PTR(-EINVAL);
+ }
+@@ -932,9 +989,7 @@ static int xpsgtr_get_ref_clocks(struct xpsgtr_dev *gtr_dev)
+ {
+ unsigned int refclk;
+
+- for (refclk = 0; refclk < ARRAY_SIZE(gtr_dev->refclk_sscs); ++refclk) {
+- unsigned long rate;
+- unsigned int i;
++ for (refclk = 0; refclk < ARRAY_SIZE(gtr_dev->clk); ++refclk) {
+ struct clk *clk;
+ char name[8];
+
+@@ -950,26 +1005,6 @@ static int xpsgtr_get_ref_clocks(struct xpsgtr_dev *gtr_dev)
+ continue;
+
+ gtr_dev->clk[refclk] = clk;
+-
+- /*
+- * Get the spread spectrum (SSC) settings for the reference
+- * clock rate.
+- */
+- rate = clk_get_rate(clk);
+-
+- for (i = 0 ; i < ARRAY_SIZE(ssc_lookup); i++) {
+- if (rate == ssc_lookup[i].refclk_rate) {
+- gtr_dev->refclk_sscs[refclk] = &ssc_lookup[i];
+- break;
+- }
+- }
+-
+- if (i == ARRAY_SIZE(ssc_lookup)) {
+- dev_err(gtr_dev->dev,
+- "Invalid rate %lu for reference clock %u\n",
+- rate, refclk);
+- return -EINVAL;
+- }
+ }
+
+ return 0;
+@@ -1034,6 +1069,12 @@ static int xpsgtr_probe(struct platform_device *pdev)
+ return PTR_ERR(provider);
+ }
+
++ gtr_dev->saved_regs = devm_kmalloc(gtr_dev->dev,
++ sizeof(save_reg_address),
++ GFP_KERNEL);
++ if (!gtr_dev->saved_regs)
++ return -ENOMEM;
++
+ pm_runtime_set_active(gtr_dev->dev);
+ pm_runtime_enable(gtr_dev->dev);
+
+@@ -1043,12 +1084,6 @@ static int xpsgtr_probe(struct platform_device *pdev)
+ return ret;
+ }
+
+- gtr_dev->saved_regs = devm_kmalloc(gtr_dev->dev,
+- sizeof(save_reg_address),
+- GFP_KERNEL);
+- if (!gtr_dev->saved_regs)
+- return -ENOMEM;
+-
+ return 0;
+ }
+
+diff --git a/drivers/pinctrl/Kconfig b/drivers/pinctrl/Kconfig
+index 6d61be061ff547..6bccb0906e2a0b 100644
+--- a/drivers/pinctrl/Kconfig
++++ b/drivers/pinctrl/Kconfig
+@@ -132,6 +132,7 @@ config PINCTRL_BM1880
+ depends on OF && (ARCH_BITMAIN || COMPILE_TEST)
+ default ARCH_BITMAIN
+ select PINMUX
++ select GENERIC_PINCONF
+ help
+ Pinctrl driver for Bitmain BM1880 SoC.
+
+@@ -315,6 +316,7 @@ config PINCTRL_MICROCHIP_SGPIO
+ select GENERIC_PINCTRL_GROUPS
+ select GENERIC_PINMUX_FUNCTIONS
+ select OF_GPIO
++ select REGMAP_MMIO
+ help
+ Support for the serial GPIO interface used on Microsemi and
+ Microchip SoCs. By using a serial interface, the SIO
+diff --git a/drivers/pinctrl/devicetree.c b/drivers/pinctrl/devicetree.c
+index 6520b88db1105b..bd6dc5ff53eef6 100644
+--- a/drivers/pinctrl/devicetree.c
++++ b/drivers/pinctrl/devicetree.c
+@@ -69,6 +69,10 @@ static int dt_remember_or_free_map(struct pinctrl *p, const char *statename,
+ int i;
+ struct pinctrl_dt_map *dt_map;
+
++ /* Initialize dev_name before any allocation can fail */
++ for (i = 0; i < num_maps; i++)
++ map[i].dev_name = NULL;
++
+ /* Initialize common mapping table entry fields */
+ for (i = 0; i < num_maps; i++) {
+ const char *devname;
+diff --git a/drivers/pinctrl/pinctrl-amd.c b/drivers/pinctrl/pinctrl-amd.c
+index 2b6d996e393e09..51506492302ef7 100644
+--- a/drivers/pinctrl/pinctrl-amd.c
++++ b/drivers/pinctrl/pinctrl-amd.c
+@@ -869,8 +869,7 @@ static void amd_gpio_irq_init(struct amd_gpio *gpio_dev)
+ u32 pin_reg, mask;
+ int i;
+
+- mask = BIT(WAKE_CNTRL_OFF_S0I3) | BIT(WAKE_CNTRL_OFF_S3) |
+- BIT(WAKE_CNTRL_OFF_S4);
++ mask = BIT(WAKE_CNTRL_OFF_S0I3) | BIT(WAKE_CNTRL_OFF_S3);
+
+ for (i = 0; i < desc->npins; i++) {
+ int pin = desc->pins[i].number;
+diff --git a/drivers/pinctrl/qcom/pinctrl-sc8280xp.c b/drivers/pinctrl/qcom/pinctrl-sc8280xp.c
+index e96c00686a25bc..aeeb40f4aa3dae 100644
+--- a/drivers/pinctrl/qcom/pinctrl-sc8280xp.c
++++ b/drivers/pinctrl/qcom/pinctrl-sc8280xp.c
+@@ -1892,16 +1892,17 @@ static const struct msm_gpio_wakeirq_map sc8280xp_pdc_map[] = {
+ { 126, 200 }, { 127, 225 }, { 128, 262 }, { 129, 201 },
+ { 130, 209 }, { 131, 173 }, { 132, 202 }, { 136, 210 },
+ { 138, 171 }, { 139, 226 }, { 140, 227 }, { 142, 228 },
+- { 144, 229 }, { 145, 230 }, { 146, 231 }, { 148, 232 },
+- { 149, 233 }, { 150, 234 }, { 152, 235 }, { 154, 212 },
+- { 157, 213 }, { 161, 219 }, { 170, 236 }, { 171, 221 },
+- { 174, 222 }, { 175, 237 }, { 176, 223 }, { 177, 170 },
+- { 180, 238 }, { 181, 239 }, { 182, 240 }, { 183, 241 },
+- { 184, 242 }, { 185, 243 }, { 190, 178 }, { 193, 184 },
+- { 196, 185 }, { 198, 186 }, { 200, 174 }, { 201, 175 },
+- { 205, 176 }, { 206, 177 }, { 208, 187 }, { 210, 198 },
+- { 211, 199 }, { 212, 204 }, { 215, 205 }, { 220, 188 },
+- { 221, 194 }, { 223, 195 }, { 225, 196 }, { 227, 197 },
++ { 143, 261 }, { 144, 229 }, { 145, 230 }, { 146, 231 },
++ { 148, 232 }, { 149, 233 }, { 150, 234 }, { 151, 264 },
++ { 152, 235 }, { 154, 212 }, { 157, 213 }, { 161, 219 },
++ { 170, 236 }, { 171, 221 }, { 174, 222 }, { 175, 237 },
++ { 176, 223 }, { 177, 170 }, { 180, 238 }, { 181, 239 },
++ { 182, 240 }, { 183, 241 }, { 184, 242 }, { 185, 243 },
++ { 190, 178 }, { 193, 184 }, { 196, 185 }, { 198, 186 },
++ { 200, 174 }, { 201, 175 }, { 205, 176 }, { 206, 177 },
++ { 208, 187 }, { 210, 198 }, { 211, 199 }, { 212, 204 },
++ { 215, 205 }, { 220, 188 }, { 221, 194 }, { 223, 195 },
++ { 225, 196 }, { 227, 197 },
+ };
+
+ static struct msm_pinctrl_soc_data sc8280xp_pinctrl = {
+diff --git a/drivers/pinctrl/renesas/pinctrl-rzg2l.c b/drivers/pinctrl/renesas/pinctrl-rzg2l.c
+index 1304ab0bcac1e6..85bcc9bbe67707 100644
+--- a/drivers/pinctrl/renesas/pinctrl-rzg2l.c
++++ b/drivers/pinctrl/renesas/pinctrl-rzg2l.c
+@@ -708,7 +708,7 @@ static int rzg2l_pinctrl_pinconf_set(struct pinctrl_dev *pctldev,
+ }
+
+ default:
+- return -EOPNOTSUPP;
++ return -ENOTSUPP;
+ }
+ }
+
+@@ -757,7 +757,7 @@ static int rzg2l_pinctrl_pinconf_group_get(struct pinctrl_dev *pctldev,
+
+ /* Check config matching between to pin */
+ if (i && prev_config != *config)
+- return -EOPNOTSUPP;
++ return -ENOTSUPP;
+
+ prev_config = *config;
+ }
+diff --git a/drivers/platform/loongarch/loongson-laptop.c b/drivers/platform/loongarch/loongson-laptop.c
+index 5fcfa3a7970b75..f3adee7515d346 100644
+--- a/drivers/platform/loongarch/loongson-laptop.c
++++ b/drivers/platform/loongarch/loongson-laptop.c
+@@ -189,6 +189,7 @@ static int __init setup_acpi_notify(struct generic_sub_driver *sub_driver)
+
+ static int loongson_hotkey_suspend(struct device *dev)
+ {
++ bl_powered = false;
+ return 0;
+ }
+
+diff --git a/drivers/platform/x86/intel/uncore-frequency/uncore-frequency-common.c b/drivers/platform/x86/intel/uncore-frequency/uncore-frequency-common.c
+index dd2e654daf4b17..88316ceb4c6c4d 100644
+--- a/drivers/platform/x86/intel/uncore-frequency/uncore-frequency-common.c
++++ b/drivers/platform/x86/intel/uncore-frequency/uncore-frequency-common.c
+@@ -197,13 +197,18 @@ int uncore_freq_add_entry(struct uncore_data *data, int cpu)
+
+ sprintf(data->name, "package_%02d_die_%02d", data->package_id, data->die_id);
+
++ /*
++ * Set the control CPU before any read path so entry recreation after CPU
++ * hotplug can populate read-only attributes from the new online CPU.
++ */
++ data->control_cpu = cpu;
+ uncore_read(data, &data->initial_min_freq_khz, &data->initial_max_freq_khz);
+
+ ret = create_attr_group(data, data->name);
+- if (!ret) {
+- data->control_cpu = cpu;
++ if (ret)
++ data->control_cpu = -1;
++ else
+ data->valid = true;
+- }
+
+ uncore_unlock:
+ mutex_unlock(&uncore_lock);
+diff --git a/drivers/power/supply/bq25890_charger.c b/drivers/power/supply/bq25890_charger.c
+index ee6e28f1d52dc5..47bc9cde0ccdba 100644
+--- a/drivers/power/supply/bq25890_charger.c
++++ b/drivers/power/supply/bq25890_charger.c
+@@ -310,7 +310,7 @@ static const u32 bq25890_tspct_tbl[] = {
+ 145, 140, 130, 120, 115, 110, 100, 90,
+ 80, 70, 60, 50, 40, 30, 20, 10,
+ 0, -10, -20, -30, -40, -60, -70, -80,
+- -90, -10, -120, -140, -150, -170, -190, -210,
++ -90, -100, -120, -140, -150, -170, -190, -210,
+ };
+
+ #define BQ25890_TSPCT_TBL_SIZE ARRAY_SIZE(bq25890_tspct_tbl)
+diff --git a/drivers/ptp/ptp_ocp.c b/drivers/ptp/ptp_ocp.c
+index b6f66a9886ce25..c4793bb13e3cbf 100644
+--- a/drivers/ptp/ptp_ocp.c
++++ b/drivers/ptp/ptp_ocp.c
+@@ -1483,9 +1483,11 @@ ptp_ocp_devlink_info_get(struct devlink *devlink, struct devlink_info_req *req,
+ if (err)
+ return err;
+
++ snprintf(buf, sizeof(buf), "%.*s", OCP_BOARD_ID_LEN,
++ (const char *)bp->board_id);
+ err = devlink_info_version_fixed_put(req,
+ DEVLINK_INFO_VERSION_GENERIC_BOARD_ID,
+- bp->board_id);
++ buf);
+ if (err)
+ return err;
+
+diff --git a/drivers/regulator/devres.c b/drivers/regulator/devres.c
+index 5c7ff9b3e8a79b..f1bc8608dd2dc6 100644
+--- a/drivers/regulator/devres.c
++++ b/drivers/regulator/devres.c
+@@ -145,6 +145,65 @@ struct regulator *devm_regulator_get_optional(struct device *dev,
+ }
+ EXPORT_SYMBOL_GPL(devm_regulator_get_optional);
+
++/**
++ * devm_regulator_get_enable_read_voltage - Resource managed regulator get and
++ * enable that returns the voltage
++ * @dev: device to supply
++ * @id: supply name or regulator ID.
++ *
++ * Get and enable regulator for duration of the device life-time.
++ * regulator_disable() and regulator_put() are automatically called on driver
++ * detach. See regulator_get_optional(), regulator_enable(), and
++ * regulator_get_voltage() for more information.
++ *
++ * This is a convenience function for supplies that provide a reference voltage
++ * where the consumer driver just needs to know the voltage and keep the
++ * regulator enabled.
++ *
++ * In cases where the supply is not strictly required, callers can check for
++ * -ENODEV error and handle it accordingly.
++ *
++ * Returns: voltage in microvolts on success, or an error code on failure.
++ */
++int devm_regulator_get_enable_read_voltage(struct device *dev, const char *id)
++{
++ struct regulator *r;
++ int ret;
++
++ /*
++ * Since we need a real voltage, we use devm_regulator_get_optional()
++ * rather than getting a dummy regulator with devm_regulator_get() and
++ * then letting regulator_get_voltage() fail with -EINVAL. This way, the
++ * caller can handle the -ENODEV error code if needed instead of the
++ * ambiguous -EINVAL.
++ */
++ r = devm_regulator_get_optional(dev, id);
++ if (IS_ERR(r))
++ return PTR_ERR(r);
++
++ ret = regulator_enable(r);
++ if (ret)
++ goto err_regulator_put;
++
++ ret = devm_add_action_or_reset(dev, regulator_action_disable, r);
++ if (ret)
++ goto err_regulator_put;
++
++ ret = regulator_get_voltage(r);
++ if (ret < 0)
++ goto err_release_action;
++
++ return ret;
++
++err_release_action:
++ devm_release_action(dev, regulator_action_disable, r);
++err_regulator_put:
++ devm_regulator_put(r);
++
++ return ret;
++}
++EXPORT_SYMBOL_GPL(devm_regulator_get_enable_read_voltage);
++
+ static int devm_regulator_match(struct device *dev, void *res, void *data)
+ {
+ struct regulator **r = res;
+diff --git a/drivers/s390/block/dasd_ioctl.c b/drivers/s390/block/dasd_ioctl.c
+index 87890b6efcdcfb..e22e5bd7a1cdab 100644
+--- a/drivers/s390/block/dasd_ioctl.c
++++ b/drivers/s390/block/dasd_ioctl.c
+@@ -330,7 +330,7 @@ out_err:
+ static int dasd_release_space(struct dasd_device *device,
+ struct format_data_t *rdata)
+ {
+- if (!device->discipline->is_ese && !device->discipline->is_ese(device))
++ if (!device->discipline->is_ese || !device->discipline->is_ese(device))
+ return -ENOTSUPP;
+ if (!device->discipline->release_space)
+ return -ENOTSUPP;
+diff --git a/drivers/s390/crypto/zcrypt_api.c b/drivers/s390/crypto/zcrypt_api.c
+index 6f44963d34bbfa..d75affe6f4b67b 100644
+--- a/drivers/s390/crypto/zcrypt_api.c
++++ b/drivers/s390/crypto/zcrypt_api.c
+@@ -1119,7 +1119,7 @@ static long _zcrypt_send_ep11_cprb(bool userspace, struct ap_perms *perms,
+ if (rc)
+ goto out_free;
+
+- if (perms != &ap_perms && domain < AUTOSEL_DOM) {
++ if (perms != &ap_perms && domain < AP_DOMAINS) {
+ if (ap_msg.flags & AP_MSG_FLAG_ADMIN) {
+ if (!test_bit_inv(domain, perms->adm)) {
+ rc = -ENODEV;
+diff --git a/drivers/s390/crypto/zcrypt_ccamisc.c b/drivers/s390/crypto/zcrypt_ccamisc.c
+index a2cea4f4a6b85c..622d960098ad32 100644
+--- a/drivers/s390/crypto/zcrypt_ccamisc.c
++++ b/drivers/s390/crypto/zcrypt_ccamisc.c
+@@ -946,7 +946,8 @@ static int _ip_cprb_helper(u16 cardnr, u16 domain,
+ const u8 *clr_key_value,
+ int clr_key_bit_size,
+ u8 *key_token,
+- int *key_token_size)
++ int *key_token_size,
++ bool scrub)
+ {
+ int rc, n;
+ u8 *mem, *ptr;
+@@ -1087,7 +1088,7 @@ static int _ip_cprb_helper(u16 cardnr, u16 domain,
+ *key_token_size = t->len;
+
+ out:
+- free_cprbmem(mem, PARMBSIZE, 0);
++ free_cprbmem(mem, PARMBSIZE, scrub);
+ return rc;
+ }
+
+@@ -1130,7 +1131,8 @@ int cca_clr2cipherkey(u16 card, u16 dom, u32 keybitsize, u32 keygenflags,
+ * 4/4 COMPLETE the secure cipher key import
+ */
+ rc = _ip_cprb_helper(card, dom, "AES ", "FIRST ", "MIN3PART",
+- exorbuf, keybitsize, token, &tokensize);
++ exorbuf, keybitsize, token, &tokensize,
++ true);
+ if (rc) {
+ DEBUG_ERR(
+ "%s clear key import 1/4 with CSNBKPI2 failed, rc=%d\n",
+@@ -1138,7 +1140,8 @@ int cca_clr2cipherkey(u16 card, u16 dom, u32 keybitsize, u32 keygenflags,
+ goto out;
+ }
+ rc = _ip_cprb_helper(card, dom, "AES ", "ADD-PART", NULL,
+- clrkey, keybitsize, token, &tokensize);
++ clrkey, keybitsize, token, &tokensize,
++ true);
+ if (rc) {
+ DEBUG_ERR(
+ "%s clear key import 2/4 with CSNBKPI2 failed, rc=%d\n",
+@@ -1146,7 +1149,8 @@ int cca_clr2cipherkey(u16 card, u16 dom, u32 keybitsize, u32 keygenflags,
+ goto out;
+ }
+ rc = _ip_cprb_helper(card, dom, "AES ", "ADD-PART", NULL,
+- exorbuf, keybitsize, token, &tokensize);
++ exorbuf, keybitsize, token, &tokensize,
++ true);
+ if (rc) {
+ DEBUG_ERR(
+ "%s clear key import 3/4 with CSNBKPI2 failed, rc=%d\n",
+@@ -1154,7 +1158,8 @@ int cca_clr2cipherkey(u16 card, u16 dom, u32 keybitsize, u32 keygenflags,
+ goto out;
+ }
+ rc = _ip_cprb_helper(card, dom, "AES ", "COMPLETE", NULL,
+- NULL, keybitsize, token, &tokensize);
++ NULL, keybitsize, token, &tokensize,
++ true);
+ if (rc) {
+ DEBUG_ERR(
+ "%s clear key import 4/4 with CSNBKPI2 failed, rc=%d\n",
+@@ -1172,7 +1177,8 @@ int cca_clr2cipherkey(u16 card, u16 dom, u32 keybitsize, u32 keygenflags,
+ *keybufsize = tokensize;
+
+ out:
+- kfree(token);
++ memzero_explicit(exorbuf, sizeof(exorbuf));
++ kfree_sensitive(token);
+ return rc;
+ }
+ EXPORT_SYMBOL(cca_clr2cipherkey);
+@@ -1232,6 +1238,9 @@ int cca_cipher2protkey(u16 cardnr, u16 domain, const u8 *ckey,
+ } __packed * prepparm;
+ int keytoklen = ((struct cipherkeytoken *)ckey)->len;
+
++ if (keytoklen > PARMBSIZE - sizeof(struct aureqparm))
++ return -EINVAL;
++
+ /* get already prepared memory for 2 cprbs with param block each */
+ rc = alloc_and_prep_cprbmem(PARMBSIZE, &mem, &preqcblk, &prepcblk);
+ if (rc)
+@@ -1401,6 +1410,9 @@ int cca_ecc2protkey(u16 cardnr, u16 domain, const u8 *key,
+ } __packed * prepparm;
+ int keylen = ((struct eccprivkeytoken *)key)->len;
+
++ if (keylen > PARMBSIZE - sizeof(struct aureqparm))
++ return -EINVAL;
++
+ /* get already prepared memory for 2 cprbs with param block each */
+ rc = alloc_and_prep_cprbmem(PARMBSIZE, &mem, &preqcblk, &prepcblk);
+ if (rc)
+diff --git a/drivers/s390/net/qeth_core.h b/drivers/s390/net/qeth_core.h
+index 613eab72970464..5f17a2a5d0e337 100644
+--- a/drivers/s390/net/qeth_core.h
++++ b/drivers/s390/net/qeth_core.h
+@@ -956,7 +956,7 @@ static inline struct dst_entry *qeth_dst_check_rcu(struct sk_buff *skb,
+ struct dst_entry *dst = skb_dst(skb);
+ struct rt6_info *rt;
+
+- rt = (struct rt6_info *) dst;
++ rt = dst_rt6_info(dst);
+ if (dst) {
+ if (proto == htons(ETH_P_IPV6))
+ dst = dst_check(dst, rt6_get_cookie(rt));
+@@ -978,7 +978,7 @@ static inline __be32 qeth_next_hop_v4_rcu(struct sk_buff *skb,
+ static inline struct in6_addr *qeth_next_hop_v6_rcu(struct sk_buff *skb,
+ struct dst_entry *dst)
+ {
+- struct rt6_info *rt = (struct rt6_info *) dst;
++ struct rt6_info *rt = dst_rt6_info(dst);
+
+ if (rt && !ipv6_addr_any(&rt->rt6i_gateway))
+ return &rt->rt6i_gateway;
+diff --git a/drivers/s390/net/qeth_core_main.c b/drivers/s390/net/qeth_core_main.c
+index f99d1d325f3ea7..e1e7a4c030f45d 100644
+--- a/drivers/s390/net/qeth_core_main.c
++++ b/drivers/s390/net/qeth_core_main.c
+@@ -6524,6 +6524,9 @@ int qeth_siocdevprivate(struct net_device *dev, struct ifreq *rq, void __user *d
+ struct qeth_card *card = dev->ml_priv;
+ int rc = 0;
+
++ if (!capable(CAP_NET_ADMIN))
++ return -EPERM;
++
+ switch (cmd) {
+ case SIOC_QETH_ADP_SET_SNMP_CONTROL:
+ rc = qeth_snmp_command(card, data);
+diff --git a/drivers/s390/scsi/zfcp_aux.c b/drivers/s390/scsi/zfcp_aux.c
+index ab2f35bc294da8..d3cc884ccd5998 100644
+--- a/drivers/s390/scsi/zfcp_aux.c
++++ b/drivers/s390/scsi/zfcp_aux.c
+@@ -254,6 +254,7 @@ static int zfcp_allocate_low_mem_buffers(struct zfcp_adapter *adapter)
+ static void zfcp_free_low_mem_buffers(struct zfcp_adapter *adapter)
+ {
+ mempool_destroy(adapter->pool.erp_req);
++ mempool_destroy(adapter->pool.gid_pn_req);
+ mempool_destroy(adapter->pool.scsi_req);
+ mempool_destroy(adapter->pool.scsi_abort);
+ mempool_destroy(adapter->pool.qtcb_pool);
+diff --git a/drivers/scsi/aic94xx/aic94xx_hwi.c b/drivers/scsi/aic94xx/aic94xx_hwi.c
+index 3dd1101434715a..8f515aae0a8dd4 100644
+--- a/drivers/scsi/aic94xx/aic94xx_hwi.c
++++ b/drivers/scsi/aic94xx/aic94xx_hwi.c
+@@ -28,7 +28,7 @@ static int asd_get_user_sas_addr(struct asd_ha_struct *asd_ha)
+ if (asd_ha->hw_prof.sas_addr[0])
+ return 0;
+
+- return sas_request_addr(asd_ha->sas_ha.core.shost,
++ return sas_request_addr(asd_ha->sas_ha.shost,
+ asd_ha->hw_prof.sas_addr);
+ }
+
+diff --git a/drivers/scsi/aic94xx/aic94xx_init.c b/drivers/scsi/aic94xx/aic94xx_init.c
+index 1766302053da6d..f204714ad7536f 100644
+--- a/drivers/scsi/aic94xx/aic94xx_init.c
++++ b/drivers/scsi/aic94xx/aic94xx_init.c
+@@ -688,8 +688,8 @@ static int asd_unregister_sas_ha(struct asd_ha_struct *asd_ha)
+
+ err = sas_unregister_ha(&asd_ha->sas_ha);
+
+- sas_remove_host(asd_ha->sas_ha.core.shost);
+- scsi_host_put(asd_ha->sas_ha.core.shost);
++ sas_remove_host(asd_ha->sas_ha.shost);
++ scsi_host_put(asd_ha->sas_ha.shost);
+
+ kfree(asd_ha->sas_ha.sas_phy);
+ kfree(asd_ha->sas_ha.sas_port);
+@@ -739,7 +739,7 @@ static int asd_pci_probe(struct pci_dev *dev, const struct pci_device_id *id)
+ asd_printk("found %s, device %s\n", asd_ha->name, pci_name(dev));
+
+ SHOST_TO_SAS_HA(shost) = &asd_ha->sas_ha;
+- asd_ha->sas_ha.core.shost = shost;
++ asd_ha->sas_ha.shost = shost;
+ shost->transportt = aic94xx_transport_template;
+ shost->max_id = ~0;
+ shost->max_lun = ~0;
+diff --git a/drivers/scsi/hisi_sas/hisi_sas_main.c b/drivers/scsi/hisi_sas/hisi_sas_main.c
+index 360f2799f2a13a..10ea1d434c48db 100644
+--- a/drivers/scsi/hisi_sas/hisi_sas_main.c
++++ b/drivers/scsi/hisi_sas/hisi_sas_main.c
+@@ -2458,7 +2458,7 @@ int hisi_sas_probe(struct platform_device *pdev,
+ sha->lldd_module = THIS_MODULE;
+ sha->sas_addr = &hisi_hba->sas_addr[0];
+ sha->num_phys = hisi_hba->n_phy;
+- sha->core.shost = hisi_hba->shost;
++ sha->shost = hisi_hba->shost;
+
+ for (i = 0; i < hisi_hba->n_phy; i++) {
+ sha->sas_phy[i] = &hisi_hba->phy[i].sas_phy;
+@@ -2500,12 +2500,12 @@ int hisi_sas_remove(struct platform_device *pdev)
+ {
+ struct sas_ha_struct *sha = platform_get_drvdata(pdev);
+ struct hisi_hba *hisi_hba = sha->lldd_ha;
+- struct Scsi_Host *shost = sha->core.shost;
++ struct Scsi_Host *shost = sha->shost;
+
+ del_timer_sync(&hisi_hba->timer);
+
+ sas_unregister_ha(sha);
+- sas_remove_host(sha->core.shost);
++ sas_remove_host(shost);
+
+ hisi_sas_free(hisi_hba);
+ scsi_host_put(shost);
+diff --git a/drivers/scsi/hisi_sas/hisi_sas_v3_hw.c b/drivers/scsi/hisi_sas/hisi_sas_v3_hw.c
+index 20b4d76e071494..ccd52fc7d34a2c 100644
+--- a/drivers/scsi/hisi_sas/hisi_sas_v3_hw.c
++++ b/drivers/scsi/hisi_sas/hisi_sas_v3_hw.c
+@@ -4820,7 +4820,7 @@ hisi_sas_v3_probe(struct pci_dev *pdev, const struct pci_device_id *id)
+
+ sha->sas_phy = arr_phy;
+ sha->sas_port = arr_port;
+- sha->core.shost = shost;
++ sha->shost = shost;
+ sha->lldd_ha = hisi_hba;
+
+ shost->transportt = hisi_sas_stt;
+@@ -4921,14 +4921,14 @@ static void hisi_sas_v3_remove(struct pci_dev *pdev)
+ struct device *dev = &pdev->dev;
+ struct sas_ha_struct *sha = dev_get_drvdata(dev);
+ struct hisi_hba *hisi_hba = sha->lldd_ha;
+- struct Scsi_Host *shost = sha->core.shost;
++ struct Scsi_Host *shost = sha->shost;
+
+ pm_runtime_get_noresume(dev);
+ del_timer_sync(&hisi_hba->timer);
+
+ sas_unregister_ha(sha);
+ flush_workqueue(hisi_hba->wq);
+- sas_remove_host(sha->core.shost);
++ sas_remove_host(shost);
+
+ hisi_sas_v3_destroy_irqs(pdev, hisi_hba);
+ hisi_sas_free(hisi_hba);
+@@ -5047,15 +5047,7 @@ static int _resume_v3_hw(struct device *device)
+ return rc;
+ }
+ phys_init_v3_hw(hisi_hba);
+-
+- /*
+- * If a directly-attached disk is removed during suspend, a deadlock
+- * may occur, as the PHYE_RESUME_TIMEOUT processing will require the
+- * hisi_hba->device to be active, which can only happen when resume
+- * completes. So don't wait for the HA event workqueue to drain upon
+- * resume.
+- */
+- sas_resume_ha_no_sync(sha);
++ sas_resume_ha(sha);
+ clear_bit(HISI_SAS_RESETTING_BIT, &hisi_hba->flags);
+
+ dev_warn(dev, "end of resuming controller\n");
+diff --git a/drivers/scsi/isci/host.h b/drivers/scsi/isci/host.h
+index 6bc3f022630a28..52388374cf3159 100644
+--- a/drivers/scsi/isci/host.h
++++ b/drivers/scsi/isci/host.h
+@@ -306,7 +306,7 @@ static inline struct isci_pci_info *to_pci_info(struct pci_dev *pdev)
+
+ static inline struct Scsi_Host *to_shost(struct isci_host *ihost)
+ {
+- return ihost->sas_ha.core.shost;
++ return ihost->sas_ha.shost;
+ }
+
+ #define for_each_isci_host(id, ihost, pdev) \
+diff --git a/drivers/scsi/isci/init.c b/drivers/scsi/isci/init.c
+index 012cd2dade8624..ee8c87dbe5ef39 100644
+--- a/drivers/scsi/isci/init.c
++++ b/drivers/scsi/isci/init.c
+@@ -571,7 +571,7 @@ static struct isci_host *isci_host_alloc(struct pci_dev *pdev, int id)
+ goto err_shost;
+
+ SHOST_TO_SAS_HA(shost) = &ihost->sas_ha;
+- ihost->sas_ha.core.shost = shost;
++ ihost->sas_ha.shost = shost;
+ shost->transportt = isci_transport_template;
+
+ shost->max_id = ~0;
+@@ -726,7 +726,7 @@ static int isci_resume(struct device *dev)
+ sas_prep_resume_ha(&ihost->sas_ha);
+
+ isci_host_init(ihost);
+- isci_host_start(ihost->sas_ha.core.shost);
++ isci_host_start(ihost->sas_ha.shost);
+ wait_for_start(ihost);
+
+ sas_resume_ha(&ihost->sas_ha);
+diff --git a/drivers/scsi/libiscsi.c b/drivers/scsi/libiscsi.c
+index ee4e3feedd10b5..b858efe3972e96 100644
+--- a/drivers/scsi/libiscsi.c
++++ b/drivers/scsi/libiscsi.c
+@@ -918,7 +918,7 @@ invalid_datalen:
+ }
+
+ senselen = get_unaligned_be16(data);
+- if (datalen < senselen)
++ if (datalen < senselen + 2)
+ goto invalid_datalen;
+
+ memcpy(sc->sense_buffer, data + 2,
+diff --git a/drivers/scsi/libiscsi_tcp.c b/drivers/scsi/libiscsi_tcp.c
+index c182aa83f2c93e..4d232051294326 100644
+--- a/drivers/scsi/libiscsi_tcp.c
++++ b/drivers/scsi/libiscsi_tcp.c
+@@ -763,13 +763,6 @@ iscsi_tcp_hdr_dissect(struct iscsi_conn *conn, struct iscsi_hdr *hdr)
+ rc = __iscsi_complete_pdu(conn, hdr, NULL, 0);
+ spin_unlock(&conn->session->back_lock);
+ break;
+- case ISCSI_OP_SCSI_CMD_RSP:
+- if (tcp_conn->in.datalen) {
+- iscsi_tcp_data_recv_prep(tcp_conn);
+- return 0;
+- }
+- rc = iscsi_complete_pdu(conn, hdr, NULL, 0);
+- break;
+ case ISCSI_OP_R2T:
+ if (ahslen) {
+ rc = ISCSI_ERR_AHSLEN;
+@@ -777,6 +770,7 @@ iscsi_tcp_hdr_dissect(struct iscsi_conn *conn, struct iscsi_hdr *hdr)
+ }
+ rc = iscsi_tcp_r2t_rsp(conn, hdr);
+ break;
++ case ISCSI_OP_SCSI_CMD_RSP:
+ case ISCSI_OP_LOGIN_RSP:
+ case ISCSI_OP_TEXT_RSP:
+ case ISCSI_OP_REJECT:
+diff --git a/drivers/scsi/libsas/sas_ata.c b/drivers/scsi/libsas/sas_ata.c
+index 6b045be947b14d..1d06daac1d9274 100644
+--- a/drivers/scsi/libsas/sas_ata.c
++++ b/drivers/scsi/libsas/sas_ata.c
+@@ -162,7 +162,7 @@ static unsigned int sas_ata_qc_issue(struct ata_queued_cmd *qc)
+ struct ata_port *ap = qc->ap;
+ struct domain_device *dev = ap->private_data;
+ struct sas_ha_struct *sas_ha = dev->port->ha;
+- struct Scsi_Host *host = sas_ha->core.shost;
++ struct Scsi_Host *host = sas_ha->shost;
+ struct sas_internal *i = to_sas_internal(host->transportt);
+
+ /* TODO: we should try to remove that unlock */
+@@ -236,7 +236,7 @@ static bool sas_ata_qc_fill_rtf(struct ata_queued_cmd *qc)
+
+ static struct sas_internal *dev_to_sas_internal(struct domain_device *dev)
+ {
+- return to_sas_internal(dev->port->ha->core.shost->transportt);
++ return to_sas_internal(dev->port->ha->shost->transportt);
+ }
+
+ static int sas_get_ata_command_set(struct domain_device *dev);
+@@ -576,7 +576,7 @@ static struct ata_port_info sata_port_info = {
+ int sas_ata_init(struct domain_device *found_dev)
+ {
+ struct sas_ha_struct *ha = found_dev->port->ha;
+- struct Scsi_Host *shost = ha->core.shost;
++ struct Scsi_Host *shost = ha->shost;
+ struct ata_host *ata_host;
+ struct ata_port *ap;
+ int rc;
+@@ -766,7 +766,7 @@ static void async_sas_ata_eh(void *data, async_cookie_t cookie)
+ struct sas_ha_struct *ha = dev->port->ha;
+
+ sas_ata_printk(KERN_DEBUG, dev, "dev error handler\n");
+- ata_scsi_port_error_handler(ha->core.shost, ap);
++ ata_scsi_port_error_handler(ha->shost, ap);
+ sas_put_device(dev);
+ }
+
+diff --git a/drivers/scsi/libsas/sas_discover.c b/drivers/scsi/libsas/sas_discover.c
+index d5bc1314c34154..4e8cdd3ae5ab95 100644
+--- a/drivers/scsi/libsas/sas_discover.c
++++ b/drivers/scsi/libsas/sas_discover.c
+@@ -170,7 +170,7 @@ int sas_notify_lldd_dev_found(struct domain_device *dev)
+ {
+ int res = 0;
+ struct sas_ha_struct *sas_ha = dev->port->ha;
+- struct Scsi_Host *shost = sas_ha->core.shost;
++ struct Scsi_Host *shost = sas_ha->shost;
+ struct sas_internal *i = to_sas_internal(shost->transportt);
+
+ if (!i->dft->lldd_dev_found)
+@@ -192,7 +192,7 @@ int sas_notify_lldd_dev_found(struct domain_device *dev)
+ void sas_notify_lldd_dev_gone(struct domain_device *dev)
+ {
+ struct sas_ha_struct *sas_ha = dev->port->ha;
+- struct Scsi_Host *shost = sas_ha->core.shost;
++ struct Scsi_Host *shost = sas_ha->shost;
+ struct sas_internal *i = to_sas_internal(shost->transportt);
+
+ if (!i->dft->lldd_dev_gone)
+@@ -234,7 +234,7 @@ static void sas_suspend_devices(struct work_struct *work)
+ struct domain_device *dev;
+ struct sas_discovery_event *ev = to_sas_discovery_event(work);
+ struct asd_sas_port *port = ev->port;
+- struct Scsi_Host *shost = port->ha->core.shost;
++ struct Scsi_Host *shost = port->ha->shost;
+ struct sas_internal *si = to_sas_internal(shost->transportt);
+
+ clear_bit(DISCE_SUSPEND, &port->disc.pending);
+@@ -360,6 +360,33 @@ static void sas_destruct_ports(struct asd_sas_port *port)
+ }
+ }
+
++static bool sas_abort_cmd(struct request *req, void *data)
++{
++ struct scsi_cmnd *cmd = blk_mq_rq_to_pdu(req);
++ struct domain_device *dev = data;
++
++ if (dev == cmd_to_domain_dev(cmd))
++ blk_abort_request(req);
++ return true;
++}
++
++static void sas_abort_device_scsi_cmds(struct domain_device *dev)
++{
++ struct sas_ha_struct *sas_ha = dev->port->ha;
++ struct Scsi_Host *shost = sas_ha->shost;
++
++ if (dev_is_expander(dev->dev_type))
++ return;
++
++ /*
++ * For removed device with active IOs, the user space applications have
++ * to spend very long time waiting for the timeout. This is not
++ * necessary because a removed device will not return the IOs.
++ * Abort the inflight IOs here so that EH can be quickly kicked in.
++ */
++ blk_mq_tagset_busy_iter(&shost->tag_set, sas_abort_cmd, dev);
++}
++
+ void sas_unregister_dev(struct asd_sas_port *port, struct domain_device *dev)
+ {
+ if (!test_bit(SAS_DEV_DESTROY, &dev->state) &&
+@@ -372,6 +399,8 @@ void sas_unregister_dev(struct asd_sas_port *port, struct domain_device *dev)
+ }
+
+ if (!test_and_set_bit(SAS_DEV_DESTROY, &dev->state)) {
++ if (test_bit(SAS_DEV_GONE, &dev->state))
++ sas_abort_device_scsi_cmds(dev);
+ sas_rphy_unlink(dev->rphy);
+ list_move_tail(&dev->disco_list_node, &port->destroy_list);
+ }
+diff --git a/drivers/scsi/libsas/sas_expander.c b/drivers/scsi/libsas/sas_expander.c
+index ffec7f0e51fcdd..03d367c2f0a7ab 100644
+--- a/drivers/scsi/libsas/sas_expander.c
++++ b/drivers/scsi/libsas/sas_expander.c
+@@ -37,7 +37,7 @@ static int smp_execute_task_sg(struct domain_device *dev,
+ int res, retry;
+ struct sas_task *task = NULL;
+ struct sas_internal *i =
+- to_sas_internal(dev->port->ha->core.shost->transportt);
++ to_sas_internal(dev->port->ha->shost->transportt);
+ struct sas_ha_struct *ha = dev->port->ha;
+
+ pm_runtime_get_sync(ha->dev);
+diff --git a/drivers/scsi/libsas/sas_host_smp.c b/drivers/scsi/libsas/sas_host_smp.c
+index 32cdc969b736af..2ecb8535634c15 100644
+--- a/drivers/scsi/libsas/sas_host_smp.c
++++ b/drivers/scsi/libsas/sas_host_smp.c
+@@ -114,7 +114,7 @@ static int sas_host_smp_write_gpio(struct sas_ha_struct *sas_ha, u8 *resp_data,
+ u8 reg_type, u8 reg_index, u8 reg_count,
+ u8 *req_data)
+ {
+- struct sas_internal *i = to_sas_internal(sas_ha->core.shost->transportt);
++ struct sas_internal *i = to_sas_internal(sas_ha->shost->transportt);
+ int written;
+
+ if (i->dft->lldd_write_gpio == NULL) {
+@@ -182,7 +182,7 @@ static void sas_phy_control(struct sas_ha_struct *sas_ha, u8 phy_id,
+ enum sas_linkrate max, u8 *resp_data)
+ {
+ struct sas_internal *i =
+- to_sas_internal(sas_ha->core.shost->transportt);
++ to_sas_internal(sas_ha->shost->transportt);
+ struct sas_phy_linkrates rates;
+ struct asd_sas_phy *asd_phy;
+
+diff --git a/drivers/scsi/libsas/sas_init.c b/drivers/scsi/libsas/sas_init.c
+index e4f77072a58d27..f1e24534d12fe6 100644
+--- a/drivers/scsi/libsas/sas_init.c
++++ b/drivers/scsi/libsas/sas_init.c
+@@ -186,7 +186,7 @@ static int sas_get_linkerrors(struct sas_phy *phy)
+ struct sas_ha_struct *sas_ha = SHOST_TO_SAS_HA(shost);
+ struct asd_sas_phy *asd_phy = sas_ha->sas_phy[phy->number];
+ struct sas_internal *i =
+- to_sas_internal(sas_ha->core.shost->transportt);
++ to_sas_internal(sas_ha->shost->transportt);
+
+ return i->dft->lldd_control_phy(asd_phy, PHY_FUNC_GET_EVENTS, NULL);
+ }
+@@ -235,7 +235,7 @@ static int transport_sas_phy_reset(struct sas_phy *phy, int hard_reset)
+ struct sas_ha_struct *sas_ha = SHOST_TO_SAS_HA(shost);
+ struct asd_sas_phy *asd_phy = sas_ha->sas_phy[phy->number];
+ struct sas_internal *i =
+- to_sas_internal(sas_ha->core.shost->transportt);
++ to_sas_internal(sas_ha->shost->transportt);
+
+ if (!hard_reset && sas_try_ata_reset(asd_phy) == 0)
+ return 0;
+@@ -269,7 +269,7 @@ int sas_phy_enable(struct sas_phy *phy, int enable)
+ struct sas_ha_struct *sas_ha = SHOST_TO_SAS_HA(shost);
+ struct asd_sas_phy *asd_phy = sas_ha->sas_phy[phy->number];
+ struct sas_internal *i =
+- to_sas_internal(sas_ha->core.shost->transportt);
++ to_sas_internal(sas_ha->shost->transportt);
+
+ if (enable)
+ ret = transport_sas_phy_reset(phy, 0);
+@@ -306,7 +306,7 @@ int sas_phy_reset(struct sas_phy *phy, int hard_reset)
+ struct sas_ha_struct *sas_ha = SHOST_TO_SAS_HA(shost);
+ struct asd_sas_phy *asd_phy = sas_ha->sas_phy[phy->number];
+ struct sas_internal *i =
+- to_sas_internal(sas_ha->core.shost->transportt);
++ to_sas_internal(sas_ha->shost->transportt);
+
+ ret = i->dft->lldd_control_phy(asd_phy, reset_type, NULL);
+ } else {
+@@ -342,7 +342,7 @@ int sas_set_phy_speed(struct sas_phy *phy,
+ struct sas_ha_struct *sas_ha = SHOST_TO_SAS_HA(shost);
+ struct asd_sas_phy *asd_phy = sas_ha->sas_phy[phy->number];
+ struct sas_internal *i =
+- to_sas_internal(sas_ha->core.shost->transportt);
++ to_sas_internal(sas_ha->shost->transportt);
+
+ ret = i->dft->lldd_control_phy(asd_phy, PHY_FUNC_SET_LINK_RATE,
+ rates);
+@@ -412,7 +412,7 @@ static void sas_resume_insert_broadcast_ha(struct sas_ha_struct *ha)
+ }
+ }
+
+-static void _sas_resume_ha(struct sas_ha_struct *ha, bool drain)
++void sas_resume_ha(struct sas_ha_struct *ha)
+ {
+ const unsigned long tmo = msecs_to_jiffies(25000);
+ int i;
+@@ -428,6 +428,23 @@ static void _sas_resume_ha(struct sas_ha_struct *ha, bool drain)
+ dev_info(ha->dev, "waiting up to 25 seconds for %d phy%s to resume\n",
+ i, i > 1 ? "s" : "");
+ wait_event_timeout(ha->eh_wait_q, phys_suspended(ha) == 0, tmo);
++
++ /*
++ * All phys are back up or timed out. Turn on I/O and drain
++ * pending work.
++ */
++ scsi_unblock_requests(ha->shost);
++ sas_drain_work(ha);
++
++ /*
++ * Send PHYE_RESUME_TIMEOUT after sas_drain_work(). The handler
++ * calls sas_deform_port() -> sas_destruct_devices(), which removes
++ * SCSI devices and, for LLDDs using device_link() PM sync, waits
++ * for the host to be runtime-active. Sending it before the drain
++ * would deadlock: the drain waits for the handler, the handler
++ * waits for host resume, and host resume waits for the drain to
++ * finish.
++ */
+ for (i = 0; i < ha->num_phys; i++) {
+ struct asd_sas_phy *phy = ha->sas_phy[i];
+
+@@ -438,12 +455,6 @@ static void _sas_resume_ha(struct sas_ha_struct *ha, bool drain)
+ }
+ }
+
+- /* all phys are back up or timed out, turn on i/o so we can
+- * flush out disks that did not return
+- */
+- scsi_unblock_requests(ha->core.shost);
+- if (drain)
+- sas_drain_work(ha);
+ clear_bit(SAS_HA_RESUMING, &ha->state);
+
+ sas_queue_deferred_work(ha);
+@@ -452,26 +463,14 @@ static void _sas_resume_ha(struct sas_ha_struct *ha, bool drain)
+ */
+ sas_resume_insert_broadcast_ha(ha);
+ }
+-
+-void sas_resume_ha(struct sas_ha_struct *ha)
+-{
+- _sas_resume_ha(ha, true);
+-}
+ EXPORT_SYMBOL(sas_resume_ha);
+
+-/* A no-sync variant, which does not call sas_drain_ha(). */
+-void sas_resume_ha_no_sync(struct sas_ha_struct *ha)
+-{
+- _sas_resume_ha(ha, false);
+-}
+-EXPORT_SYMBOL(sas_resume_ha_no_sync);
+-
+ void sas_suspend_ha(struct sas_ha_struct *ha)
+ {
+ int i;
+
+ sas_disable_events(ha);
+- scsi_block_requests(ha->core.shost);
++ scsi_block_requests(ha->shost);
+ for (i = 0; i < ha->num_phys; i++) {
+ struct asd_sas_port *port = ha->sas_port[i];
+
+@@ -644,7 +643,7 @@ struct asd_sas_event *sas_alloc_event(struct asd_sas_phy *phy,
+ struct asd_sas_event *event;
+ struct sas_ha_struct *sas_ha = phy->ha;
+ struct sas_internal *i =
+- to_sas_internal(sas_ha->core.shost->transportt);
++ to_sas_internal(sas_ha->shost->transportt);
+
+ event = kmem_cache_zalloc(sas_event_cache, gfp_flags);
+ if (!event)
+diff --git a/drivers/scsi/libsas/sas_phy.c b/drivers/scsi/libsas/sas_phy.c
+index a0d592d11dfb11..57494ac97076d8 100644
+--- a/drivers/scsi/libsas/sas_phy.c
++++ b/drivers/scsi/libsas/sas_phy.c
+@@ -38,7 +38,7 @@ static void sas_phye_oob_error(struct work_struct *work)
+ struct sas_ha_struct *sas_ha = phy->ha;
+ struct asd_sas_port *port = phy->port;
+ struct sas_internal *i =
+- to_sas_internal(sas_ha->core.shost->transportt);
++ to_sas_internal(sas_ha->shost->transportt);
+
+ sas_deform_port(phy, 1);
+
+@@ -66,7 +66,7 @@ static void sas_phye_spinup_hold(struct work_struct *work)
+ struct asd_sas_phy *phy = ev->phy;
+ struct sas_ha_struct *sas_ha = phy->ha;
+ struct sas_internal *i =
+- to_sas_internal(sas_ha->core.shost->transportt);
++ to_sas_internal(sas_ha->shost->transportt);
+
+ phy->error = 0;
+ i->dft->lldd_control_phy(phy, PHY_FUNC_RELEASE_SPINUP_HOLD, NULL);
+@@ -95,7 +95,7 @@ static void sas_phye_shutdown(struct work_struct *work)
+ struct asd_sas_phy *phy = ev->phy;
+ struct sas_ha_struct *sas_ha = phy->ha;
+ struct sas_internal *i =
+- to_sas_internal(sas_ha->core.shost->transportt);
++ to_sas_internal(sas_ha->shost->transportt);
+
+ if (phy->enabled) {
+ int ret;
+@@ -131,7 +131,7 @@ int sas_register_phys(struct sas_ha_struct *sas_ha)
+ spin_lock_init(&phy->sas_prim_lock);
+ phy->frame_rcvd_size = 0;
+
+- phy->phy = sas_phy_alloc(&sas_ha->core.shost->shost_gendev, i);
++ phy->phy = sas_phy_alloc(&sas_ha->shost->shost_gendev, i);
+ if (!phy->phy)
+ return -ENOMEM;
+
+diff --git a/drivers/scsi/libsas/sas_port.c b/drivers/scsi/libsas/sas_port.c
+index 11599c0e3fc344..60ad1486d15c26 100644
+--- a/drivers/scsi/libsas/sas_port.c
++++ b/drivers/scsi/libsas/sas_port.c
+@@ -28,7 +28,7 @@ static void sas_resume_port(struct asd_sas_phy *phy)
+ struct domain_device *dev, *n;
+ struct asd_sas_port *port = phy->port;
+ struct sas_ha_struct *sas_ha = phy->ha;
+- struct sas_internal *si = to_sas_internal(sas_ha->core.shost->transportt);
++ struct sas_internal *si = to_sas_internal(sas_ha->shost->transportt);
+
+ if (si->dft->lldd_port_formed)
+ si->dft->lldd_port_formed(phy);
+@@ -109,7 +109,7 @@ static void sas_form_port(struct asd_sas_phy *phy)
+ struct asd_sas_port *port = phy->port;
+ struct domain_device *port_dev = NULL;
+ struct sas_internal *si =
+- to_sas_internal(sas_ha->core.shost->transportt);
++ to_sas_internal(sas_ha->shost->transportt);
+ unsigned long flags;
+
+ if (port) {
+@@ -212,7 +212,7 @@ void sas_deform_port(struct asd_sas_phy *phy, int gone)
+ struct sas_ha_struct *sas_ha = phy->ha;
+ struct asd_sas_port *port = phy->port;
+ struct sas_internal *si =
+- to_sas_internal(sas_ha->core.shost->transportt);
++ to_sas_internal(sas_ha->shost->transportt);
+ struct domain_device *dev;
+ unsigned long flags;
+
+diff --git a/drivers/scsi/libsas/sas_scsi_host.c b/drivers/scsi/libsas/sas_scsi_host.c
+index a36fa1c128a841..83ea14ce2330af 100644
+--- a/drivers/scsi/libsas/sas_scsi_host.c
++++ b/drivers/scsi/libsas/sas_scsi_host.c
+@@ -279,7 +279,7 @@ static enum task_disposition sas_scsi_find_task(struct sas_task *task)
+ unsigned long flags;
+ int i, res;
+ struct sas_internal *si =
+- to_sas_internal(task->dev->port->ha->core.shost->transportt);
++ to_sas_internal(task->dev->port->ha->shost->transportt);
+
+ for (i = 0; i < 5; i++) {
+ pr_notice("%s: aborting task 0x%p\n", __func__, task);
+@@ -327,7 +327,7 @@ static int sas_recover_lu(struct domain_device *dev, struct scsi_cmnd *cmd)
+ int res = TMF_RESP_FUNC_FAILED;
+ struct scsi_lun lun;
+ struct sas_internal *i =
+- to_sas_internal(dev->port->ha->core.shost->transportt);
++ to_sas_internal(dev->port->ha->shost->transportt);
+
+ int_to_scsilun(cmd->device->lun, &lun);
+
+@@ -355,7 +355,7 @@ static int sas_recover_I_T(struct domain_device *dev)
+ {
+ int res = TMF_RESP_FUNC_FAILED;
+ struct sas_internal *i =
+- to_sas_internal(dev->port->ha->core.shost->transportt);
++ to_sas_internal(dev->port->ha->shost->transportt);
+
+ pr_notice("I_T nexus reset for dev %016llx\n",
+ SAS_ADDR(dev->sas_addr));
+@@ -410,7 +410,7 @@ static void sas_wait_eh(struct domain_device *dev)
+ spin_unlock_irq(&ha->lock);
+
+ /* make sure SCSI EH is complete */
+- if (scsi_host_in_recovery(ha->core.shost)) {
++ if (scsi_host_in_recovery(ha->shost)) {
+ msleep(10);
+ goto retry;
+ }
+@@ -440,7 +440,7 @@ static int sas_queue_reset(struct domain_device *dev, int reset_type,
+ set_bit(SAS_DEV_EH_PENDING, &dev->state);
+ set_bit(reset_type, &dev->state);
+ int_to_scsilun(lun, &dev->ssp_dev.reset_lun);
+- scsi_schedule_eh(ha->core.shost);
++ scsi_schedule_eh(ha->shost);
+ }
+ spin_unlock_irq(&ha->lock);
+
+@@ -926,7 +926,7 @@ static int sas_execute_internal_abort(struct domain_device *device,
+ unsigned int qid, void *data)
+ {
+ struct sas_ha_struct *ha = device->port->ha;
+- struct sas_internal *i = to_sas_internal(ha->core.shost->transportt);
++ struct sas_internal *i = to_sas_internal(ha->shost->transportt);
+ struct sas_task *task = NULL;
+ int res, retry;
+
+@@ -1016,7 +1016,7 @@ int sas_execute_tmf(struct domain_device *device, void *parameter,
+ {
+ struct sas_task *task;
+ struct sas_internal *i =
+- to_sas_internal(device->port->ha->core.shost->transportt);
++ to_sas_internal(device->port->ha->shost->transportt);
+ int res, retry;
+
+ for (retry = 0; retry < TASK_RETRY; retry++) {
+diff --git a/drivers/scsi/mvsas/mv_init.c b/drivers/scsi/mvsas/mv_init.c
+index b500c343cad755..4182e004d775fa 100644
+--- a/drivers/scsi/mvsas/mv_init.c
++++ b/drivers/scsi/mvsas/mv_init.c
+@@ -416,7 +416,7 @@ static int mvs_prep_sas_ha_init(struct Scsi_Host *shost,
+
+ sha->sas_phy = arr_phy;
+ sha->sas_port = arr_port;
+- sha->core.shost = shost;
++ sha->shost = shost;
+
+ sha->lldd_ha = kzalloc(sizeof(struct mvs_prv_info), GFP_KERNEL);
+ if (!sha->lldd_ha)
+@@ -473,7 +473,7 @@ static void mvs_post_sas_ha_init(struct Scsi_Host *shost,
+ shost->sg_tablesize = min_t(u16, SG_ALL, MVS_MAX_SG);
+ shost->can_queue = can_queue;
+ mvi->shost->cmd_per_lun = MVS_QUEUE_SIZE;
+- sha->core.shost = mvi->shost;
++ sha->shost = mvi->shost;
+ }
+
+ static void mvs_init_sas_add(struct mvs_info *mvi)
+diff --git a/drivers/scsi/pm8001/pm8001_init.c b/drivers/scsi/pm8001/pm8001_init.c
+index 60b477e65a66a8..914a30b3dfc2ee 100644
+--- a/drivers/scsi/pm8001/pm8001_init.c
++++ b/drivers/scsi/pm8001/pm8001_init.c
+@@ -653,7 +653,7 @@ static void pm8001_post_sas_ha_init(struct Scsi_Host *shost,
+ sha->lldd_module = THIS_MODULE;
+ sha->sas_addr = &pm8001_ha->sas_addr[0];
+ sha->num_phys = chip_info->n_phy;
+- sha->core.shost = shost;
++ sha->shost = shost;
+ }
+
+ /**
+diff --git a/drivers/scsi/scsi_debug.c b/drivers/scsi/scsi_debug.c
+index 2493e07a1a5bac..08dfdc00d9ea36 100644
+--- a/drivers/scsi/scsi_debug.c
++++ b/drivers/scsi/scsi_debug.c
+@@ -3089,8 +3089,8 @@ static bool comp_write_worker(struct sdeb_store_info *sip, u64 lba, u32 num,
+ if (!res)
+ return res;
+ if (rest)
+- res = memcmp(fsp, arr + ((num - rest) * lb_size),
+- rest * lb_size);
++ res = !memcmp(fsp, arr + ((num - rest) * lb_size),
++ rest * lb_size);
+ if (!res)
+ return res;
+ if (compare_only)
+@@ -4481,6 +4481,7 @@ static int resp_report_zones(struct scsi_cmnd *scp,
+ u32 alloc_len, rep_opts, rep_len;
+ bool partial;
+ u64 lba, zs_lba;
++ u64 arr_len;
+ u8 *arr = NULL, *desc;
+ u8 *cmd = scp->cmnd;
+ struct sdeb_zone_state *zsp = NULL;
+@@ -4502,9 +4503,12 @@ static int resp_report_zones(struct scsi_cmnd *scp,
+ return check_condition_result;
+ }
+
+- rep_max_zones = (alloc_len - 64) >> ilog2(RZONES_DESC_HD);
++ rep_max_zones = (ALIGN((u64)alloc_len, RZONES_DESC_HD) - RZONES_DESC_HD) >>
++ ilog2(RZONES_DESC_HD);
++ rep_max_zones = min_t(unsigned int, rep_max_zones, devip->nr_zones);
++ arr_len = (u64)RZONES_DESC_HD * (rep_max_zones + 1);
+
+- arr = kzalloc(alloc_len, GFP_ATOMIC | __GFP_NOWARN);
++ arr = kzalloc(arr_len, GFP_ATOMIC | __GFP_NOWARN);
+ if (!arr) {
+ mk_sense_buffer(scp, ILLEGAL_REQUEST, INSUFF_RES_ASC,
+ INSUFF_RES_ASCQ);
+diff --git a/drivers/spi/spi-fsl-dspi.c b/drivers/spi/spi-fsl-dspi.c
+index 3a33156f52740f..840b97ae6ec30e 100644
+--- a/drivers/spi/spi-fsl-dspi.c
++++ b/drivers/spi/spi-fsl-dspi.c
+@@ -751,8 +751,12 @@ static void dspi_setup_accel(struct fsl_dspi *dspi)
+ struct spi_transfer *xfer = dspi->cur_transfer;
+ bool odd = !!(dspi->len & 1);
+
+- /* No accel for frames not multiple of 8 bits at the moment */
+- if (xfer->bits_per_word % 8)
++ /*
++ * No accel for DMA transfers or frames not multiples of 8 bits at the
++ * moment.
++ */
++ if (dspi->devtype_data->trans_mode == DSPI_DMA_MODE ||
++ xfer->bits_per_word % 8)
+ goto no_accel;
+
+ if (!odd && dspi->len <= dspi->devtype_data->fifo_size * 2) {
+@@ -761,10 +765,7 @@ static void dspi_setup_accel(struct fsl_dspi *dspi)
+ dspi->oper_bits_per_word = 8;
+ } else {
+ /* Start off with maximum supported by hardware */
+- if (dspi->devtype_data->trans_mode == DSPI_XSPI_MODE)
+- dspi->oper_bits_per_word = 32;
+- else
+- dspi->oper_bits_per_word = 16;
++ dspi->oper_bits_per_word = 32;
+
+ /*
+ * And go down only if the buffer can't be sent with
+diff --git a/drivers/staging/media/meson/vdec/vdec.c b/drivers/staging/media/meson/vdec/vdec.c
+index 52f224d8def104..b8858a49349d90 100644
+--- a/drivers/staging/media/meson/vdec/vdec.c
++++ b/drivers/staging/media/meson/vdec/vdec.c
+@@ -897,7 +897,7 @@ static int vdec_open(struct file *file)
+
+ ret = vdec_init_ctrls(sess);
+ if (ret)
+- goto err_m2m_release;
++ goto err_m2m_ctx_release;
+
+ sess->pixfmt_cap = formats[0].pixfmts_cap[0];
+ sess->fmt_out = &formats[0];
+@@ -922,6 +922,8 @@ static int vdec_open(struct file *file)
+
+ return 0;
+
++err_m2m_ctx_release:
++ v4l2_m2m_ctx_release(sess->m2m_ctx);
+ err_m2m_release:
+ v4l2_m2m_release(sess->m2m_dev);
+ err_free_sess:
+diff --git a/drivers/staging/media/sunxi/cedrus/cedrus.c b/drivers/staging/media/sunxi/cedrus/cedrus.c
+index f73988e3b1e90b..937d11ee8a9f8a 100644
+--- a/drivers/staging/media/sunxi/cedrus/cedrus.c
++++ b/drivers/staging/media/sunxi/cedrus/cedrus.c
+@@ -381,6 +381,7 @@ static int cedrus_open(struct file *file)
+ err_ctrls:
+ v4l2_ctrl_handler_free(&ctx->hdl);
+ err_free:
++ v4l2_fh_exit(&ctx->fh);
+ kfree(ctx);
+ mutex_unlock(&dev->dev_mutex);
+
+@@ -503,7 +504,7 @@ static int cedrus_probe(struct platform_device *pdev)
+ ret = video_register_device(vfd, VFL_TYPE_VIDEO, 0);
+ if (ret) {
+ v4l2_err(&dev->v4l2_dev, "Failed to register video device\n");
+- goto err_m2m;
++ goto err_media;
+ }
+
+ v4l2_info(&dev->v4l2_dev,
+@@ -529,7 +530,8 @@ err_m2m_mc:
+ v4l2_m2m_unregister_media_controller(dev->m2m_dev);
+ err_video:
+ video_unregister_device(&dev->vfd);
+-err_m2m:
++err_media:
++ media_device_cleanup(&dev->mdev);
+ v4l2_m2m_release(dev->m2m_dev);
+ err_v4l2:
+ v4l2_device_unregister(&dev->v4l2_dev);
+diff --git a/drivers/staging/media/sunxi/cedrus/cedrus_h264.c b/drivers/staging/media/sunxi/cedrus/cedrus_h264.c
+index a8b236cd380056..8aa4e3f479e40c 100644
+--- a/drivers/staging/media/sunxi/cedrus/cedrus_h264.c
++++ b/drivers/staging/media/sunxi/cedrus/cedrus_h264.c
+@@ -190,6 +190,9 @@ static void _cedrus_write_ref_list(struct cedrus_ctx *ctx,
+ u8 dpb_idx;
+
+ dpb_idx = ref_list[i].index;
++ if (dpb_idx >= V4L2_H264_NUM_DPB_ENTRIES)
++ continue;
++
+ dpb = &decode->dpb[dpb_idx];
+
+ if (!(dpb->flags & V4L2_H264_DPB_ENTRY_FLAG_ACTIVE))
+diff --git a/drivers/staging/media/tegra-video/vi.c b/drivers/staging/media/tegra-video/vi.c
+index ea96fd67035c7c..a6a5feb0fe9088 100644
+--- a/drivers/staging/media/tegra-video/vi.c
++++ b/drivers/staging/media/tegra-video/vi.c
+@@ -76,8 +76,8 @@ static int tegra_get_format_idx_by_code(struct tegra_vi *vi,
+ static u32 tegra_get_format_fourcc_by_idx(struct tegra_vi *vi,
+ unsigned int index)
+ {
+- if (index >= vi->soc->nformats)
+- return -EINVAL;
++ if (WARN_ON_ONCE(index >= vi->soc->nformats))
++ return vi->soc->video_formats[0].fourcc;
+
+ return vi->soc->video_formats[index].fourcc;
+ }
+diff --git a/drivers/staging/rtl8723bs/core/rtw_ieee80211.c b/drivers/staging/rtl8723bs/core/rtw_ieee80211.c
+index 79ec71287b689a..ddb9fccb86fc5b 100644
+--- a/drivers/staging/rtl8723bs/core/rtw_ieee80211.c
++++ b/drivers/staging/rtl8723bs/core/rtw_ieee80211.c
+@@ -371,6 +371,9 @@ unsigned char *rtw_get_wpa_ie(unsigned char *pie, int *wpa_ie_len, int limit)
+ pbuf = rtw_get_ie(pbuf, WLAN_EID_VENDOR_SPECIFIC, &len, limit_new);
+
+ if (pbuf) {
++ if (len < 6)
++ goto check_next_ie;
++
+ /* check if oui matches... */
+ if (memcmp((pbuf + 2), wpa_oui_type, sizeof(wpa_oui_type)))
+ goto check_next_ie;
+@@ -678,7 +681,14 @@ u8 *rtw_get_wps_ie(u8 *in_ie, uint in_len, u8 *wps_ie, uint *wps_ielen)
+ while (cnt < in_len) {
+ eid = in_ie[cnt];
+
+- if ((eid == WLAN_EID_VENDOR_SPECIFIC) && (!memcmp(&in_ie[cnt + 2], wps_oui, 4))) {
++ if (cnt + 2 > in_len)
++ break;
++
++ if (in_ie[cnt + 1] + 2 > in_len - cnt)
++ break;
++
++ if ((eid == WLAN_EID_VENDOR_SPECIFIC) && (in_ie[cnt + 1] >= 4) &&
++ (!memcmp(&in_ie[cnt + 2], wps_oui, 4))) {
+ wpsie_ptr = &in_ie[cnt];
+
+ if (wps_ie)
+diff --git a/drivers/staging/rtl8723bs/core/rtw_mlme_ext.c b/drivers/staging/rtl8723bs/core/rtw_mlme_ext.c
+index 0d0edf5d055a4d..78c9425cd5f444 100644
+--- a/drivers/staging/rtl8723bs/core/rtw_mlme_ext.c
++++ b/drivers/staging/rtl8723bs/core/rtw_mlme_ext.c
+@@ -907,7 +907,7 @@ unsigned int OnAuthClient(struct adapter *padapter, union recv_frame *precv_fram
+ p = rtw_get_ie(pframe + WLAN_HDR_A3_LEN + _AUTH_IE_OFFSET_, WLAN_EID_CHALLENGE, (int *)&len,
+ pkt_len - WLAN_HDR_A3_LEN - _AUTH_IE_OFFSET_);
+
+- if (!p)
++ if (!p || len != WLAN_AUTH_CHALLENGE_LEN)
+ goto authclnt_fail;
+
+ memcpy((void *)(pmlmeinfo->chg_txt), (void *)(p + 2), len);
+diff --git a/drivers/staging/rtl8723bs/core/rtw_wlan_util.c b/drivers/staging/rtl8723bs/core/rtw_wlan_util.c
+index 74234b5f5610fd..e782f18d34e36a 100644
+--- a/drivers/staging/rtl8723bs/core/rtw_wlan_util.c
++++ b/drivers/staging/rtl8723bs/core/rtw_wlan_util.c
+@@ -731,6 +731,9 @@ int WMM_param_handler(struct adapter *padapter, struct ndis_80211_var_ie *pIE)
+ return false;
+ }
+
++ if (pIE->length != WLAN_WMM_LEN)
++ return false;
++
+ if (!memcmp(&(pmlmeinfo->WMM_param), (pIE->data + 6), sizeof(struct WMM_para_element)))
+ return false;
+ else
+diff --git a/drivers/staging/rtl8723bs/os_dep/ioctl_cfg80211.c b/drivers/staging/rtl8723bs/os_dep/ioctl_cfg80211.c
+index edc34f93102216..ba52733f0333ee 100644
+--- a/drivers/staging/rtl8723bs/os_dep/ioctl_cfg80211.c
++++ b/drivers/staging/rtl8723bs/os_dep/ioctl_cfg80211.c
+@@ -1999,7 +1999,7 @@ static u8 rtw_get_chan_type(struct adapter *adapter)
+ else
+ return NL80211_CHAN_NO_HT;
+ case CHANNEL_WIDTH_40:
+- if (mlme_ext->cur_ch_offset == HAL_PRIME_CHNL_OFFSET_UPPER)
++ if (mlme_ext->cur_ch_offset == HAL_PRIME_CHNL_OFFSET_LOWER)
+ return NL80211_CHAN_HT40PLUS;
+ else
+ return NL80211_CHAN_HT40MINUS;
+@@ -2075,6 +2075,8 @@ static netdev_tx_t rtw_cfg80211_monitor_if_xmit_entry(struct sk_buff *skb, struc
+
+ /* Skip the ratio tap header */
+ skb_pull(skb, rtap_len);
++ if (skb->len < dot11_hdr_len)
++ goto fail;
+
+ dot11_hdr = (struct ieee80211_hdr *)skb->data;
+ frame_control = le16_to_cpu(dot11_hdr->frame_control);
+@@ -2087,6 +2089,8 @@ static netdev_tx_t rtw_cfg80211_monitor_if_xmit_entry(struct sk_buff *skb, struc
+ qos_len = 2;
+ if ((frame_control & 0x0300) == 0x0300)
+ dot11_hdr_len += 6;
++ if (skb->len < dot11_hdr_len + qos_len + snap_len)
++ goto fail;
+
+ memcpy(dst_mac_addr, dot11_hdr->addr1, sizeof(dst_mac_addr));
+ memcpy(src_mac_addr, dot11_hdr->addr2, sizeof(src_mac_addr));
+diff --git a/drivers/target/target_core_transport.c b/drivers/target/target_core_transport.c
+index b9a144a59dff3a..f4e3ba173dbe38 100644
+--- a/drivers/target/target_core_transport.c
++++ b/drivers/target/target_core_transport.c
+@@ -1670,6 +1670,7 @@ int target_init_cmd(struct se_cmd *se_cmd, struct se_session *se_sess,
+ u32 data_length, int task_attr, int data_dir, int flags)
+ {
+ struct se_portal_group *se_tpg;
++ int ret;
+
+ se_tpg = se_sess->se_tpg;
+ BUG_ON(!se_tpg);
+@@ -1699,7 +1700,11 @@ int target_init_cmd(struct se_cmd *se_cmd, struct se_session *se_sess,
+ * necessary for fabrics using TARGET_SCF_ACK_KREF that expect a second
+ * kref_put() to happen during fabric packet acknowledgement.
+ */
+- return target_get_sess_cmd(se_cmd, flags & TARGET_SCF_ACK_KREF);
++ ret = target_get_sess_cmd(se_cmd, flags & TARGET_SCF_ACK_KREF);
++ if (ret)
++ se_cmd->cmd_cnt = NULL;
++
++ return ret;
+ }
+ EXPORT_SYMBOL_GPL(target_init_cmd);
+
+@@ -1994,8 +1999,10 @@ int target_submit_tmr(struct se_cmd *se_cmd, struct se_session *se_sess,
+ * allocation failure.
+ */
+ ret = core_tmr_alloc_req(se_cmd, fabric_tmr_ptr, tm_type, gfp);
+- if (ret < 0)
++ if (ret < 0) {
++ se_cmd->cmd_cnt = NULL;
+ return -ENOMEM;
++ }
+
+ if (tm_type == TMR_ABORT_TASK)
+ se_cmd->se_tmr_req->ref_task_tag = tag;
+@@ -2003,6 +2010,7 @@ int target_submit_tmr(struct se_cmd *se_cmd, struct se_session *se_sess,
+ /* See target_submit_cmd for commentary */
+ ret = target_get_sess_cmd(se_cmd, flags & TARGET_SCF_ACK_KREF);
+ if (ret) {
++ se_cmd->cmd_cnt = NULL;
+ core_tmr_release_req(se_cmd->se_tmr_req);
+ return ret;
+ }
+diff --git a/drivers/thermal/thermal_hwmon.c b/drivers/thermal/thermal_hwmon.c
+index d520d2b7c00791..1013e0221e3715 100644
+--- a/drivers/thermal/thermal_hwmon.c
++++ b/drivers/thermal/thermal_hwmon.c
+@@ -209,7 +209,8 @@ int thermal_add_hwmon_sysfs(struct thermal_zone_device *tz)
+ if (new_hwmon_device)
+ hwmon_device_unregister(hwmon->device);
+ free_mem:
+- kfree(hwmon);
++ if (new_hwmon_device)
++ kfree(hwmon);
+
+ return result;
+ }
+diff --git a/drivers/thunderbolt/eeprom.c b/drivers/thunderbolt/eeprom.c
+index c90d22f56d4e1c..36456cd064eb48 100644
+--- a/drivers/thunderbolt/eeprom.c
++++ b/drivers/thunderbolt/eeprom.c
+@@ -392,9 +392,16 @@ static int tb_drom_parse_entry_port(struct tb_switch *sw,
+ return -EIO;
+ }
+ port->link_nr = entry->link_nr;
+- if (entry->has_dual_link_port)
++ if (entry->has_dual_link_port) {
++ if (entry->dual_link_port_nr > sw->config.max_port_number) {
++ tb_sw_warn(sw,
++ "port entry has invalid dual link port number %u\n",
++ entry->dual_link_port_nr);
++ return -EIO;
++ }
+ port->dual_link_port =
+ &port->sw->ports[entry->dual_link_port_nr];
++ }
+ }
+ return 0;
+ }
+diff --git a/drivers/thunderbolt/icm.c b/drivers/thunderbolt/icm.c
+index 69b2ca95fe37a0..6d354392fcbc4c 100644
+--- a/drivers/thunderbolt/icm.c
++++ b/drivers/thunderbolt/icm.c
+@@ -2293,7 +2293,7 @@ static int icm_usb4_switch_op(struct tb_switch *sw, u16 opcode, u32 *metadata,
+ if (tx_data_len) {
+ request.data_len_valid |= ICM_USB4_SWITCH_DATA_VALID;
+ if (tx_data_len < ARRAY_SIZE(request.data))
+- request.data_len_valid =
++ request.data_len_valid |=
+ tx_data_len & ICM_USB4_SWITCH_DATA_LEN_MASK;
+ memcpy(request.data, tx_data, tx_data_len * sizeof(u32));
+ }
+diff --git a/drivers/tty/serial/8250/8250_dma.c b/drivers/tty/serial/8250/8250_dma.c
+index dd4c7155db4cda..d62bd22893c4ba 100644
+--- a/drivers/tty/serial/8250/8250_dma.c
++++ b/drivers/tty/serial/8250/8250_dma.c
+@@ -195,11 +195,12 @@ void serial8250_rx_dma_flush(struct uart_8250_port *p)
+ {
+ struct uart_8250_dma *dma = p->dma;
+
+- if (dma->rx_running) {
+- dmaengine_pause(dma->rxchan);
+- __dma_rx_complete(p);
+- dmaengine_terminate_async(dma->rxchan);
+- }
++ if (!dma || !dma->rxchan || !dma->rx_running)
++ return;
++
++ dmaengine_pause(dma->rxchan);
++ __dma_rx_complete(p);
++ dmaengine_terminate_async(dma->rxchan);
+ }
+ EXPORT_SYMBOL_GPL(serial8250_rx_dma_flush);
+
+@@ -308,6 +309,7 @@ void serial8250_release_dma(struct uart_8250_port *p)
+
+ /* Release RX resources */
+ dmaengine_terminate_sync(dma->rxchan);
++ dma->rx_running = 0;
+ dma_free_coherent(dma->rxchan->device->dev, dma->rx_size, dma->rx_buf,
+ dma->rx_addr);
+ dma_release_channel(dma->rxchan);
+diff --git a/drivers/tty/serial/8250/8250_mid.c b/drivers/tty/serial/8250/8250_mid.c
+index f88809ff370b73..82656645b8a64b 100644
+--- a/drivers/tty/serial/8250/8250_mid.c
++++ b/drivers/tty/serial/8250/8250_mid.c
+@@ -318,9 +318,11 @@ static int mid8250_probe(struct pci_dev *pdev, const struct pci_device_id *id)
+ if (!uart.port.membase)
+ return -ENOMEM;
+
+- ret = mid->board->setup(mid, &uart.port);
+- if (ret)
+- return ret;
++ if (mid->board->setup) {
++ ret = mid->board->setup(mid, &uart.port);
++ if (ret)
++ return ret;
++ }
+
+ ret = mid8250_dma_setup(mid, &uart);
+ if (ret)
+@@ -336,7 +338,8 @@ static int mid8250_probe(struct pci_dev *pdev, const struct pci_device_id *id)
+ return 0;
+
+ err:
+- mid->board->exit(mid);
++ if (mid->board->exit)
++ mid->board->exit(mid);
+ return ret;
+ }
+
+@@ -346,7 +349,8 @@ static void mid8250_remove(struct pci_dev *pdev)
+
+ serial8250_unregister_port(mid->line);
+
+- mid->board->exit(mid);
++ if (mid->board->exit)
++ mid->board->exit(mid);
+ }
+
+ static const struct mid8250_board pnw_board = {
+diff --git a/drivers/tty/serial/sc16is7xx.c b/drivers/tty/serial/sc16is7xx.c
+index 458bf165437243..34abce41f92d22 100644
+--- a/drivers/tty/serial/sc16is7xx.c
++++ b/drivers/tty/serial/sc16is7xx.c
+@@ -1311,6 +1311,17 @@ static void sc16is7xx_gpio_set(struct gpio_chip *chip, unsigned offset, int val)
+ val ? BIT(offset) : 0);
+ }
+
++static int sc16is7xx_gpio_get_direction(struct gpio_chip *chip, unsigned int offset)
++{
++ struct sc16is7xx_port *s = gpiochip_get_data(chip);
++ struct uart_port *port = &s->p[0].port;
++ unsigned int val;
++
++ val = sc16is7xx_port_read(port, SC16IS7XX_IODIR_REG);
++
++ return val & BIT(offset) ? GPIO_LINE_DIRECTION_OUT : GPIO_LINE_DIRECTION_IN;
++}
++
+ static int sc16is7xx_gpio_direction_input(struct gpio_chip *chip,
+ unsigned offset)
+ {
+@@ -1388,6 +1399,7 @@ static int sc16is7xx_setup_gpio_chip(struct sc16is7xx_port *s)
+ s->gpio.parent = dev;
+ s->gpio.label = dev_name(dev);
+ s->gpio.init_valid_mask = sc16is7xx_gpio_init_valid_mask;
++ s->gpio.get_direction = sc16is7xx_gpio_get_direction;
+ s->gpio.direction_input = sc16is7xx_gpio_direction_input;
+ s->gpio.get = sc16is7xx_gpio_get;
+ s->gpio.direction_output = sc16is7xx_gpio_direction_output;
+diff --git a/drivers/tty/vt/keyboard.c b/drivers/tty/vt/keyboard.c
+index d8ad642655d3ad..94ac6dd7397e20 100644
+--- a/drivers/tty/vt/keyboard.c
++++ b/drivers/tty/vt/keyboard.c
+@@ -1405,7 +1405,7 @@ static void kbd_keycode(unsigned int keycode, int down, bool hw_raw)
+ struct keyboard_notifier_param param = { .vc = vc, .value = keycode, .down = down };
+ int rc;
+
+- tty = vc->port.tty;
++ tty = tty_port_tty_get(&vc->port);
+
+ if (tty && (!tty->driver_data)) {
+ /* No driver data? Strange. Okay we fix it then. */
+@@ -1465,9 +1465,12 @@ static void kbd_keycode(unsigned int keycode, int down, bool hw_raw)
+ * characters get aren't echoed locally. This makes key repeat
+ * usable with slow applications and under heavy loads.
+ */
++ tty_kref_put(tty);
+ return;
+ }
+
++ tty_kref_put(tty);
++
+ param.shift = shift_final = (shift_state | kbd->slockstate) ^ kbd->lockstate;
+ param.ledstate = kbd->ledflagstate;
+ key_map = key_maps[shift_final];
+diff --git a/drivers/tty/vt/vt_ioctl.c b/drivers/tty/vt/vt_ioctl.c
+index 5b21b60547da1f..e8abf4572dae2a 100644
+--- a/drivers/tty/vt/vt_ioctl.c
++++ b/drivers/tty/vt/vt_ioctl.c
+@@ -408,6 +408,8 @@ static int vt_k_ioctl(struct tty_struct *tty, unsigned int cmd,
+ /* this could be folded into KDSKBMODE, but for compatibility
+ reasons it is not so easy to fold KDGKBMETA into KDGKBMODE */
+ case KDSKBMETA:
++ if (!perm)
++ return -EPERM;
+ return vt_do_kdskbmeta(console, arg);
+
+ case KDGKBMETA:
+diff --git a/drivers/usb/atm/cxacru.c b/drivers/usb/atm/cxacru.c
+index db9a8f2731f1a4..071d2a079f141b 100644
+--- a/drivers/usb/atm/cxacru.c
++++ b/drivers/usb/atm/cxacru.c
+@@ -700,6 +700,8 @@ static int cxacru_cm(struct cxacru_data *instance, enum cxacru_cm_request cm,
+ ret = offd;
+ usb_dbg(instance->usbatm, "cm %#x\n", cm);
+ fail:
++ if (ret < 0)
++ usb_kill_urb(instance->rcv_urb);
+ mutex_unlock(&instance->cm_serialize);
+ err:
+ return ret;
+diff --git a/drivers/usb/atm/ueagle-atm.c b/drivers/usb/atm/ueagle-atm.c
+index b41f352769f072..5dfe82a4c130da 100644
+--- a/drivers/usb/atm/ueagle-atm.c
++++ b/drivers/usb/atm/ueagle-atm.c
+@@ -2591,6 +2591,7 @@ static struct usbatm_driver uea_usbatm_driver = {
+ static int uea_probe(struct usb_interface *intf, const struct usb_device_id *id)
+ {
+ struct usb_device *usb = interface_to_usbdev(intf);
++ bool single_iface = usb->config->desc.bNumInterfaces == 1;
+ int ret;
+
+ uea_enters(usb);
+@@ -2600,6 +2601,22 @@ static int uea_probe(struct usb_interface *intf, const struct usb_device_id *id)
+ le16_to_cpu(usb->descriptor.bcdDevice),
+ chip_name[UEA_CHIP_VERSION(id)]);
+
++ /*
++ * uea_probe() decides between the pre-firmware and post-firmware case
++ * from the USB id and stores a different object as interface data in
++ * each case: a struct completion for a pre-firmware device, a struct
++ * usbatm_data for a post-firmware one. uea_disconnect() instead tells
++ * the two apart by the number of interfaces (a pre-firmware device
++ * exposes a single interface, ADI930 has 2 and eagle has 3). A crafted
++ * device advertising a pre-firmware id together with a multi-interface
++ * descriptor (or the other way around) makes the two disagree, so that
++ * usbatm_usb_disconnect() treats the small completion object as a
++ * struct usbatm_data and reads out of bounds. Reject such inconsistent
++ * descriptors so both paths make the same decision.
++ */
++ if (UEA_IS_PREFIRM(id) != single_iface)
++ return -ENODEV;
++
+ usb_reset_device(usb);
+
+ if (UEA_IS_PREFIRM(id)) {
+diff --git a/drivers/usb/cdns3/cdnsp-gadget.c b/drivers/usb/cdns3/cdnsp-gadget.c
+index 51dac7db528417..01bfa58a3cc72b 100644
+--- a/drivers/usb/cdns3/cdnsp-gadget.c
++++ b/drivers/usb/cdns3/cdnsp-gadget.c
+@@ -154,9 +154,9 @@ static void cdnsp_set_apb_timeout_value(struct cdnsp_device *pdev)
+ offset = cdnsp_find_next_ext_cap(base, offset, D_XEC_PRE_REGS_CAP);
+ reg = base + offset + REG_CHICKEN_BITS_3_OFFSET;
+
+- val = le32_to_cpu(readl(reg));
++ val = readl(reg);
+ val = CHICKEN_APB_TIMEOUT_SET(val, cdns->override_apb_timeout);
+- writel(cpu_to_le32(val), reg);
++ writel(val, reg);
+ }
+
+ static void cdnsp_set_chicken_bits_2(struct cdnsp_device *pdev, u32 bit)
+diff --git a/drivers/usb/chipidea/core.c b/drivers/usb/chipidea/core.c
+index 460a71f2046c50..064191de546d08 100644
+--- a/drivers/usb/chipidea/core.c
++++ b/drivers/usb/chipidea/core.c
+@@ -1251,6 +1251,7 @@ static int ci_hdrc_remove(struct platform_device *pdev)
+ usb_role_switch_unregister(ci->role_switch);
+
+ if (ci->supports_runtime_pm) {
++ pm_runtime_dont_use_autosuspend(&pdev->dev);
+ pm_runtime_get_sync(&pdev->dev);
+ pm_runtime_disable(&pdev->dev);
+ pm_runtime_put_noidle(&pdev->dev);
+diff --git a/drivers/usb/gadget/function/f_midi.c b/drivers/usb/gadget/function/f_midi.c
+index dd1cfeeffb6718..3b4ec6c0a39b3f 100644
+--- a/drivers/usb/gadget/function/f_midi.c
++++ b/drivers/usb/gadget/function/f_midi.c
+@@ -1302,6 +1302,7 @@ static void f_midi_free(struct usb_function *f)
+ opts = container_of(f->fi, struct f_midi_opts, func_inst);
+ mutex_lock(&opts->lock);
+ if (!--midi->free_ref) {
++ cancel_work_sync(&midi->work);
+ kfree(midi->id);
+ kfifo_free(&midi->in_req_fifo);
+ kfree(midi);
+diff --git a/drivers/usb/gadget/function/f_ncm.c b/drivers/usb/gadget/function/f_ncm.c
+index 5e240cafbe9ee8..68e8f42f281051 100644
+--- a/drivers/usb/gadget/function/f_ncm.c
++++ b/drivers/usb/gadget/function/f_ncm.c
+@@ -1176,7 +1176,7 @@ static int ncm_unwrap_ntb(struct gether *port,
+ unsigned char *ntb_ptr = skb->data;
+ __le16 *tmp;
+ unsigned index, index2;
+- int ndp_index;
++ unsigned int ndp_index;
+ unsigned dg_len, dg_len2;
+ unsigned ndp_len;
+ unsigned block_len;
+@@ -1190,6 +1190,10 @@ static int ncm_unwrap_ntb(struct gether *port,
+ int to_process = skb->len;
+
+ parse_ntb:
++ if (to_process < (int)opts->nth_size) {
++ INFO(port->func.config->cdev, "Packet too small for headers\n");
++ goto err;
++ }
+ tmp = (__le16 *)ntb_ptr;
+
+ /* dwSignature */
+@@ -1210,8 +1214,12 @@ parse_ntb:
+ tmp++; /* skip wSequence */
+
+ block_len = get_ncm(&tmp, opts->block_length);
++ if (block_len == 0)
++ block_len = to_process;
++
+ /* (d)wBlockLength */
+- if ((block_len < opts->nth_size + opts->ndp_size) || (block_len > ntb_max)) {
++ if ((block_len < opts->nth_size + opts->ndp_size) || (block_len > ntb_max) ||
++ (block_len > to_process)) {
+ INFO(port->func.config->cdev, "Bad block length: %#X\n", block_len);
+ goto err;
+ }
+@@ -1274,7 +1282,7 @@ parse_ntb:
+ index = index2;
+ /* wDatagramIndex[0] */
+ if ((index < opts->nth_size) ||
+- (index > block_len - opts->dpe_size)) {
++ (index > block_len)) {
+ INFO(port->func.config->cdev,
+ "Bad index: %#X\n", index);
+ goto err;
+@@ -1286,7 +1294,8 @@ parse_ntb:
+ * ethernet hdr + crc or larger than max frame size
+ */
+ if ((dg_len < 14 + crc_len) ||
+- (dg_len > frame_max)) {
++ (dg_len > frame_max) ||
++ (dg_len > block_len - index)) {
+ INFO(port->func.config->cdev,
+ "Bad dgram length: %#X\n", dg_len);
+ goto err;
+@@ -1311,7 +1320,7 @@ parse_ntb:
+ dg_len2 = get_ncm(&tmp, opts->dgram_item_len);
+
+ /* wDatagramIndex[1] */
+- if (index2 > block_len - opts->dpe_size) {
++ if (index2 > block_len) {
+ INFO(port->func.config->cdev,
+ "Bad index: %#X\n", index2);
+ goto err;
+diff --git a/drivers/usb/gadget/function/f_printer.c b/drivers/usb/gadget/function/f_printer.c
+index 65378266fd84e8..e4d35f59269410 100644
+--- a/drivers/usb/gadget/function/f_printer.c
++++ b/drivers/usb/gadget/function/f_printer.c
+@@ -430,7 +430,7 @@ printer_read(struct file *fd, char __user *buf, size_t len, loff_t *ptr)
+ {
+ struct printer_dev *dev = fd->private_data;
+ unsigned long flags;
+- size_t size;
++ size_t size, not_copied, copied;
+ size_t bytes_copied;
+ struct usb_request *req;
+ /* This is a pointer to the current USB rx request. */
+@@ -523,10 +523,12 @@ printer_read(struct file *fd, char __user *buf, size_t len, loff_t *ptr)
+ else
+ size = len;
+
+- size -= copy_to_user(buf, current_rx_buf, size);
+- bytes_copied += size;
+- len -= size;
+- buf += size;
++ not_copied = copy_to_user(buf, current_rx_buf, size);
++ copied = size - not_copied;
++
++ bytes_copied += copied;
++ len -= copied;
++ buf += copied;
+
+ spin_lock_irqsave(&dev->lock, flags);
+
+@@ -541,6 +543,17 @@ printer_read(struct file *fd, char __user *buf, size_t len, loff_t *ptr)
+ if (dev->interface < 0)
+ goto out_disabled;
+
++ if (!copied) {
++ dev->current_rx_req = current_rx_req;
++ dev->current_rx_bytes = current_rx_bytes;
++ dev->current_rx_buf = current_rx_buf;
++ spin_unlock_irqrestore(&dev->lock, flags);
++ mutex_unlock(&dev->lock_printer_io);
++ return bytes_copied ? bytes_copied : -EFAULT;
++ }
++
++ size = copied;
++
+ /* If we not returning all the data left in this RX request
+ * buffer then adjust the amount of data left in the buffer.
+ * Othewise if we are done with this RX request buffer then
+diff --git a/drivers/usb/gadget/function/uvc_v4l2.c b/drivers/usb/gadget/function/uvc_v4l2.c
+index 6b646f3cf620a9..eb49669ef50000 100644
+--- a/drivers/usb/gadget/function/uvc_v4l2.c
++++ b/drivers/usb/gadget/function/uvc_v4l2.c
+@@ -191,6 +191,8 @@ uvc_send_response(struct uvc_device *uvc, struct uvc_request_data *data)
+ return usb_ep_set_halt(cdev->gadget->ep0);
+
+ req->length = min_t(unsigned int, uvc->event_length, data->length);
++ if (req->length > sizeof(data->data))
++ req->length = sizeof(data->data);
+ req->zero = data->length < uvc->event_length;
+
+ memcpy(req->buf, data->data, req->length);
+diff --git a/drivers/usb/gadget/udc/bdc/bdc_core.c b/drivers/usb/gadget/udc/bdc/bdc_core.c
+index 9460ef0a7f892f..79c1ed0553d048 100644
+--- a/drivers/usb/gadget/udc/bdc/bdc_core.c
++++ b/drivers/usb/gadget/udc/bdc/bdc_core.c
+@@ -586,9 +586,29 @@ disable_clk:
+ static int bdc_remove(struct platform_device *pdev)
+ {
+ struct bdc *bdc;
++ unsigned long flags;
++ u32 temp;
+
+ bdc = platform_get_drvdata(pdev);
+ dev_dbg(bdc->dev, "%s ()\n", __func__);
++ /*
++ * Disable the device interrupt source before freeing the IRQ:
++ * clear BDC_GIE so the controller stops asserting interrupts,
++ * then free_irq drains any in-flight handler.
++ */
++ spin_lock_irqsave(&bdc->lock, flags);
++ temp = bdc_readl(bdc->regs, BDC_BDCSC);
++ temp &= ~BDC_GIE;
++ bdc_writel(bdc->regs, BDC_BDCSC, temp);
++ spin_unlock_irqrestore(&bdc->lock, flags);
++ free_irq(bdc->irq, bdc);
++ /*
++ * Drain func_wake_notify after free_irq: the IRQ handler arms this
++ * delayed_work via bdc_sr_uspc -> handle_link_state_change ->
++ * schedule_delayed_work (self-rearmed in bdc_func_wake_timer), so
++ * the IRQ must be released first to prevent re-arm after cancel.
++ */
++ cancel_delayed_work_sync(&bdc->func_wake_notify);
+ bdc_udc_exit(bdc);
+ bdc_hw_exit(bdc);
+ bdc_phy_exit(bdc);
+diff --git a/drivers/usb/gadget/udc/bdc/bdc_udc.c b/drivers/usb/gadget/udc/bdc/bdc_udc.c
+index 53ffaf4e2e3762..b5e573f9ef55ed 100644
+--- a/drivers/usb/gadget/udc/bdc/bdc_udc.c
++++ b/drivers/usb/gadget/udc/bdc/bdc_udc.c
+@@ -530,8 +530,8 @@ int bdc_udc_init(struct bdc *bdc)
+
+
+ bdc->gadget.name = BRCM_BDC_NAME;
+- ret = devm_request_irq(bdc->dev, bdc->irq, bdc_udc_interrupt,
+- IRQF_SHARED, BRCM_BDC_NAME, bdc);
++ ret = request_irq(bdc->irq, bdc_udc_interrupt, IRQF_SHARED,
++ BRCM_BDC_NAME, bdc);
+ if (ret) {
+ dev_err(bdc->dev,
+ "failed to request irq #%d %d\n",
+@@ -542,7 +542,7 @@ int bdc_udc_init(struct bdc *bdc)
+ ret = bdc_init_ep(bdc);
+ if (ret) {
+ dev_err(bdc->dev, "bdc init ep fail: %d\n", ret);
+- return ret;
++ goto err0;
+ }
+
+ ret = usb_add_gadget_udc(bdc->dev, &bdc->gadget);
+@@ -571,6 +571,7 @@ int bdc_udc_init(struct bdc *bdc)
+ err1:
+ usb_del_gadget_udc(&bdc->gadget);
+ err0:
++ free_irq(bdc->irq, bdc);
+ bdc_free_ep(bdc);
+
+ return ret;
+diff --git a/drivers/usb/gadget/udc/dummy_hcd.c b/drivers/usb/gadget/udc/dummy_hcd.c
+index 1330c03b6a345f..77393fc628eb0e 100644
+--- a/drivers/usb/gadget/udc/dummy_hcd.c
++++ b/drivers/usb/gadget/udc/dummy_hcd.c
+@@ -277,6 +277,7 @@ struct dummy {
+ unsigned ints_enabled:1;
+ unsigned udc_suspended:1;
+ unsigned pullup:1;
++ unsigned fifo_req_busy:1;
+
+ /*
+ * HOST side support
+@@ -328,6 +329,26 @@ static inline struct dummy *gadget_dev_to_dummy(struct device *dev)
+
+ /* DEVICE/GADGET SIDE UTILITY ROUTINES */
+
++/*
++ * Give back a gadget request with dum->lock dropped around the callback.
++ * If @req is the shared fifo_req, clear fifo_req_busy afterward: the flag
++ * was set in dummy_queue() when the shared request was taken and must stay
++ * set until its completion callback has returned; list_del_init() alone
++ * makes the request look idle while the callback is still running.
++ * Caller holds dum->lock and has already done list_del_init() + status.
++ */
++static void dummy_giveback(struct dummy *dum, struct usb_ep *_ep,
++ struct dummy_request *req)
++{
++ bool fifo = req == &dum->fifo_req;
++
++ spin_unlock(&dum->lock);
++ usb_gadget_giveback_request(_ep, &req->req);
++ spin_lock(&dum->lock);
++ if (fifo)
++ dum->fifo_req_busy = 0;
++}
++
+ /* called with spinlock held */
+ static void nuke(struct dummy *dum, struct dummy_ep *ep)
+ {
+@@ -338,9 +359,7 @@ static void nuke(struct dummy *dum, struct dummy_ep *ep)
+ list_del_init(&req->queue);
+ req->req.status = -ESHUTDOWN;
+
+- spin_unlock(&dum->lock);
+- usb_gadget_giveback_request(&ep->ep, &req->req);
+- spin_lock(&dum->lock);
++ dummy_giveback(dum, &ep->ep, req);
+ }
+ }
+
+@@ -727,10 +746,11 @@ static int dummy_queue(struct usb_ep *_ep, struct usb_request *_req,
+
+ /* implement an emulated single-request FIFO */
+ if (ep->desc && (ep->desc->bEndpointAddress & USB_DIR_IN) &&
+- list_empty(&dum->fifo_req.queue) &&
++ !dum->fifo_req_busy &&
+ list_empty(&ep->queue) &&
+ _req->length <= FIFO_SIZE) {
+ req = &dum->fifo_req;
++ dum->fifo_req_busy = 1;
+ req->req = *_req;
+ req->req.buf = dum->fifo_buf;
+ memcpy(dum->fifo_buf, _req->buf, _req->length);
+@@ -784,9 +804,7 @@ static int dummy_dequeue(struct usb_ep *_ep, struct usb_request *_req)
+ dev_dbg(udc_dev(dum),
+ "dequeued req %p from %s, len %d buf %p\n",
+ req, _ep->name, _req->length, _req->buf);
+- spin_unlock(&dum->lock);
+- usb_gadget_giveback_request(_ep, _req);
+- spin_lock(&dum->lock);
++ dummy_giveback(dum, _ep, req);
+ }
+ spin_unlock_irqrestore(&dum->lock, flags);
+ return retval;
+@@ -1523,9 +1541,7 @@ top:
+ if (req->req.status != -EINPROGRESS) {
+ list_del_init(&req->queue);
+
+- spin_unlock(&dum->lock);
+- usb_gadget_giveback_request(&ep->ep, &req->req);
+- spin_lock(&dum->lock);
++ dummy_giveback(dum, &ep->ep, req);
+
+ /* requests might have been unlinked... */
+ rescan = 1;
+@@ -1909,9 +1925,7 @@ restart:
+ dev_dbg(udc_dev(dum), "stale req = %p\n",
+ req);
+
+- spin_unlock(&dum->lock);
+- usb_gadget_giveback_request(&ep->ep, &req->req);
+- spin_lock(&dum->lock);
++ dummy_giveback(dum, &ep->ep, req);
+ ep->already_seen = 0;
+ goto restart;
+ }
+diff --git a/drivers/usb/gadget/udc/fsl_udc_core.c b/drivers/usb/gadget/udc/fsl_udc_core.c
+index c1a62ebd78d664..8c28d5c38c75fa 100644
+--- a/drivers/usb/gadget/udc/fsl_udc_core.c
++++ b/drivers/usb/gadget/udc/fsl_udc_core.c
+@@ -2466,7 +2466,6 @@ static int fsl_udc_probe(struct platform_device *pdev)
+ udc_controller->gadget.name = driver_name;
+
+ /* Setup gadget.dev and register with kernel */
+- dev_set_name(&udc_controller->gadget.dev, "gadget");
+ udc_controller->gadget.dev.of_node = pdev->dev.of_node;
+
+ if (!IS_ERR_OR_NULL(udc_controller->transceiver))
+diff --git a/drivers/usb/gadget/udc/snps_udc_core.c b/drivers/usb/gadget/udc/snps_udc_core.c
+index 2fc5d4d277bc4a..fcb58b0d5c4e48 100644
+--- a/drivers/usb/gadget/udc/snps_udc_core.c
++++ b/drivers/usb/gadget/udc/snps_udc_core.c
+@@ -3133,7 +3133,6 @@ int udc_probe(struct udc *dev)
+ /* device struct setup */
+ dev->gadget.ops = &udc_ops;
+
+- dev_set_name(&dev->gadget.dev, "gadget");
+ dev->gadget.name = name;
+ dev->gadget.max_speed = USB_SPEED_HIGH;
+
+diff --git a/drivers/usb/host/xhci-pci.c b/drivers/usb/host/xhci-pci.c
+index 7ad6d13d65ee94..8fffc84d014779 100644
+--- a/drivers/usb/host/xhci-pci.c
++++ b/drivers/usb/host/xhci-pci.c
+@@ -337,6 +337,7 @@ static void xhci_pci_quirks(struct device *dev, struct xhci_hcd *xhci)
+ if (pdev->vendor == PCI_VENDOR_ID_VIA && pdev->device == PCI_DEVICE_ID_VIA_VL805) {
+ xhci->quirks |= XHCI_LPM_SUPPORT;
+ xhci->quirks |= XHCI_TRB_OVERFETCH;
++ xhci->dma_mask_bits = 36;
+ }
+
+ if (pdev->vendor == PCI_VENDOR_ID_ASMEDIA &&
+diff --git a/drivers/usb/host/xhci.c b/drivers/usb/host/xhci.c
+index e00baa3b7324cb..37fb2491d88f22 100644
+--- a/drivers/usb/host/xhci.c
++++ b/drivers/usb/host/xhci.c
+@@ -5394,6 +5394,7 @@ int xhci_gen_setup(struct usb_hcd *hcd, xhci_get_quirks_t get_quirks)
+ if (xhci->hci_version > 0x100)
+ xhci->hcc_params2 = readl(&xhci->cap_regs->hcc_params2);
+
++ xhci->dma_mask_bits = 64;
+ /* xhci-plat or xhci-pci might have set max_interrupters already */
+ if ((!xhci->max_interrupters) ||
+ xhci->max_interrupters > HCS_MAX_INTRS(xhci->hcs_params1))
+@@ -5434,12 +5435,16 @@ int xhci_gen_setup(struct usb_hcd *hcd, xhci_get_quirks_t get_quirks)
+ if (xhci->quirks & XHCI_NO_64BIT_SUPPORT)
+ xhci->hcc_params &= ~BIT(0);
+
+- /* Set dma_mask and coherent_dma_mask to 64-bits,
+- * if xHC supports 64-bit addressing */
++ /*
++ * Set dma_mask and coherent_dma_mask to 64-bits if xHC supports
++ * 64-bit addressing, unless a controller-specific quirk callback
++ * limits the usable address width.
++ */
+ if (HCC_64BIT_ADDR(xhci->hcc_params) &&
+- !dma_set_mask(dev, DMA_BIT_MASK(64))) {
+- xhci_dbg(xhci, "Enabling 64-bit DMA addresses.\n");
+- dma_set_coherent_mask(dev, DMA_BIT_MASK(64));
++ !dma_set_mask(dev, DMA_BIT_MASK(xhci->dma_mask_bits))) {
++ xhci_dbg(xhci, "Enabling %u-bit DMA addresses.\n",
++ xhci->dma_mask_bits);
++ dma_set_coherent_mask(dev, DMA_BIT_MASK(xhci->dma_mask_bits));
+ } else {
+ /*
+ * This is to avoid error in cases where a 32-bit USB
+diff --git a/drivers/usb/host/xhci.h b/drivers/usb/host/xhci.h
+index b43e88102200e5..b446fa9eb8370b 100644
+--- a/drivers/usb/host/xhci.h
++++ b/drivers/usb/host/xhci.h
+@@ -1543,6 +1543,7 @@ struct xhci_hcd {
+ int event_ring_max;
+ /* 4KB min, 128MB max */
+ int page_size;
++ unsigned int dma_mask_bits;
+ /* Valid values are 12 to 20, inclusive */
+ int page_shift;
+ /* msi-x vectors */
+diff --git a/drivers/usb/serial/ftdi_sio.c b/drivers/usb/serial/ftdi_sio.c
+index 6d21dd340d462f..8c54dcc746a980 100644
+--- a/drivers/usb/serial/ftdi_sio.c
++++ b/drivers/usb/serial/ftdi_sio.c
+@@ -1075,6 +1075,8 @@ static const struct usb_device_id id_table_combined[] = {
+ { USB_DEVICE_INTERFACE_NUMBER(ALTERA_VID, ALTERA_UB3_602E_PID, 3) },
+ /* Abacus Electrics */
+ { USB_DEVICE(FTDI_VID, ABACUS_OPTICAL_PROBE_PID) },
++ /* Endress+Hauser AG devices */
++ { USB_DEVICE(FTDI_VID, FTDI_EH_FXA291_PID) },
+ { } /* Terminating entry */
+ };
+
+diff --git a/drivers/usb/serial/ftdi_sio_ids.h b/drivers/usb/serial/ftdi_sio_ids.h
+index 6c76cfebfd0e42..9c83c17853c871 100644
+--- a/drivers/usb/serial/ftdi_sio_ids.h
++++ b/drivers/usb/serial/ftdi_sio_ids.h
+@@ -313,6 +313,11 @@
+ #define FTDI_ELV_UDF77_PID 0xFB5E /* USB DCF Funkuhr (UDF 77) */
+ #define FTDI_ELV_UIO88_PID 0xFB5F /* USB-I/O Interface (UIO 88) */
+
++/*
++ * Endress+Hauser AG product ids (FTDI_VID)
++ */
++#define FTDI_EH_FXA291_PID 0xE510
++
+ /*
+ * EVER Eco Pro UPS (http://www.ever.com.pl/)
+ */
+diff --git a/drivers/usb/serial/io_edgeport.c b/drivers/usb/serial/io_edgeport.c
+index 408b774cc223f3..c5ada8debfd614 100644
+--- a/drivers/usb/serial/io_edgeport.c
++++ b/drivers/usb/serial/io_edgeport.c
+@@ -646,7 +646,8 @@ static void edge_interrupt_callback(struct urb *urb)
+ if (edge_port && edge_port->open) {
+ spin_lock_irqsave(&edge_port->ep_lock,
+ flags);
+- edge_port->txCredits += txCredits;
++ edge_port->txCredits = min(edge_port->txCredits + txCredits,
++ edge_port->maxTxCredits);
+ spin_unlock_irqrestore(&edge_port->ep_lock,
+ flags);
+ dev_dbg(dev, "%s - txcredits for port%d = %d\n",
+diff --git a/drivers/usb/serial/keyspan_pda.c b/drivers/usb/serial/keyspan_pda.c
+index 82f0ea2547ae4c..264efa6ce8e491 100644
+--- a/drivers/usb/serial/keyspan_pda.c
++++ b/drivers/usb/serial/keyspan_pda.c
+@@ -35,6 +35,8 @@ struct keyspan_pda_private {
+ struct work_struct unthrottle_work;
+ struct usb_serial *serial;
+ struct usb_serial_port *port;
++ bool throttled;
++ bool throttle_req;
+ };
+
+ static int keyspan_pda_write_start(struct usb_serial_port *port);
+@@ -150,6 +152,7 @@ static void keyspan_pda_rx_interrupt(struct urb *urb)
+ int retval;
+ int status = urb->status;
+ struct keyspan_pda_private *priv;
++ bool throttled = false;
+ unsigned long flags;
+
+ priv = usb_get_serial_port_data(port);
+@@ -211,16 +214,24 @@ static void keyspan_pda_rx_interrupt(struct urb *urb)
+ }
+
+ exit:
+- retval = usb_submit_urb(urb, GFP_ATOMIC);
+- if (retval)
+- dev_err(&port->dev,
+- "%s - usb_submit_urb failed with result %d\n",
+- __func__, retval);
++ spin_lock_irqsave(&port->lock, flags);
++ if (priv->throttle_req) {
++ priv->throttled = true;
++ throttled = true;
++ }
++ spin_unlock_irqrestore(&port->lock, flags);
++
++ if (!throttled) {
++ retval = usb_submit_urb(urb, GFP_ATOMIC);
++ if (retval)
++ dev_err(&port->dev, "failed to resubmit in urb: %d\n", retval);
++ }
+ }
+
+ static void keyspan_pda_rx_throttle(struct tty_struct *tty)
+ {
+ struct usb_serial_port *port = tty->driver_data;
++ struct keyspan_pda_private *priv = usb_get_serial_port_data(port);
+
+ /*
+ * Stop receiving characters. We just turn off the URB request, and
+@@ -230,16 +241,29 @@ static void keyspan_pda_rx_throttle(struct tty_struct *tty)
+ * send an XOFF, although it might make sense to foist that off upon
+ * the device too.
+ */
+- usb_kill_urb(port->interrupt_in_urb);
++ spin_lock_irq(&port->lock);
++ priv->throttle_req = true;
++ spin_unlock_irq(&port->lock);
+ }
+
+ static void keyspan_pda_rx_unthrottle(struct tty_struct *tty)
+ {
+ struct usb_serial_port *port = tty->driver_data;
++ struct keyspan_pda_private *priv = usb_get_serial_port_data(port);
++ bool throttled;
++ int ret;
+
+- /* just restart the receive interrupt URB */
+- if (usb_submit_urb(port->interrupt_in_urb, GFP_KERNEL))
+- dev_dbg(&port->dev, "usb_submit_urb(read urb) failed\n");
++ spin_lock_irq(&port->lock);
++ throttled = priv->throttled;
++ priv->throttled = false;
++ priv->throttle_req = false;
++ spin_unlock_irq(&port->lock);
++
++ if (throttled) {
++ ret = usb_submit_urb(port->interrupt_in_urb, GFP_KERNEL);
++ if (ret)
++ dev_err(&port->dev, "failed to submit in urb: %d\n", ret);
++ }
+ }
+
+ static speed_t keyspan_pda_setbaud(struct usb_serial *serial, speed_t baud)
+@@ -575,6 +599,8 @@ static int keyspan_pda_open(struct tty_struct *tty,
+
+ spin_lock_irq(&port->lock);
+ priv->tx_room = rc;
++ priv->throttled = false;
++ priv->throttle_req = false;
+ spin_unlock_irq(&port->lock);
+
+ rc = usb_submit_urb(port->interrupt_in_urb, GFP_KERNEL);
+diff --git a/drivers/usb/serial/option.c b/drivers/usb/serial/option.c
+index 47c5069a125c1e..500472b3485512 100644
+--- a/drivers/usb/serial/option.c
++++ b/drivers/usb/serial/option.c
+@@ -2497,6 +2497,7 @@ static const struct usb_device_id option_ids[] = {
+ .driver_info = RSVD(5) },
+ { USB_DEVICE_INTERFACE_CLASS(0x33f8, 0x1003, 0xff), /* Rolling RW135R-GL (laptop MBIM) */
+ .driver_info = RSVD(5) },
++ { USB_DEVICE_INTERFACE_CLASS(0x3466, 0x3301, 0xff) }, /* TDTECH MT5710-CN */
+ { USB_DEVICE_AND_INTERFACE_INFO(0x3731, 0x0100, 0xff, 0xff, 0x30) }, /* NetPrisma LCUK54-WWD for Global */
+ { USB_DEVICE_AND_INTERFACE_INFO(0x3731, 0x0100, 0xff, 0x00, 0x40) },
+ { USB_DEVICE_AND_INTERFACE_INFO(0x3731, 0x0100, 0xff, 0xff, 0x40) },
+diff --git a/drivers/usb/storage/unusual_devs.h b/drivers/usb/storage/unusual_devs.h
+index 255968f9ca42ae..ac22fa31873439 100644
+--- a/drivers/usb/storage/unusual_devs.h
++++ b/drivers/usb/storage/unusual_devs.h
+@@ -395,6 +395,13 @@ UNUSUAL_DEV( 0x04b3, 0x4001, 0x0110, 0x0110,
+ USB_SC_DEVICE, USB_PR_CB, NULL,
+ US_FL_MAX_SECTORS_MIN),
+
++/* Reported by Ai Chao <aichao-UOlijcLmZ/[email protected]> */
++UNUSUAL_DEV( 0x04b4, 0xb708, 0x0000, 0xffff,
++ "Longmai Technologies",
++ "USB Key",
++ USB_SC_SCSI, USB_PR_BULK, NULL,
++ US_FL_NO_ATA_1X),
++
+ /*
+ * Reported by Simon Levitt <simon-V/[email protected]>
+ * This entry needs Sub and Proto fields
+diff --git a/drivers/vhost/vdpa.c b/drivers/vhost/vdpa.c
+index 7684c16e9e07a2..df71ca25a1012f 100644
+--- a/drivers/vhost/vdpa.c
++++ b/drivers/vhost/vdpa.c
+@@ -920,6 +920,7 @@ static int vhost_vdpa_pa_map(struct vhost_vdpa *v,
+ unsigned int gup_flags = FOLL_LONGTERM;
+ unsigned long npages, cur_base, map_pfn, last_pfn = 0;
+ unsigned long lock_limit, sz2pin, nchunks, i;
++ unsigned long page_offset;
+ u64 start = iova;
+ long pinned;
+ int ret = 0;
+@@ -932,7 +933,13 @@ static int vhost_vdpa_pa_map(struct vhost_vdpa *v,
+ if (perm & VHOST_ACCESS_WO)
+ gup_flags |= FOLL_WRITE;
+
+- npages = PFN_UP(size + (iova & ~PAGE_MASK));
++ page_offset = iova & ~PAGE_MASK;
++ if (size > ULONG_MAX - page_offset) {
++ ret = -EINVAL;
++ goto free;
++ }
++
++ npages = PFN_UP(size + page_offset);
+ if (!npages) {
+ ret = -EINVAL;
+ goto free;
+diff --git a/drivers/vhost/vhost.c b/drivers/vhost/vhost.c
+index 0db46b016004a6..3cd58e9ae99b97 100644
+--- a/drivers/vhost/vhost.c
++++ b/drivers/vhost/vhost.c
+@@ -1587,6 +1587,14 @@ static long vhost_vring_set_num_addr(struct vhost_dev *d,
+ BUG();
+ }
+
++ /*
++ * The metadata cache holds the IOTLB mapping that backed the previous
++ * desc/avail/used addresses and vring size, both of which are being
++ * replaced here. iotlb_access_ok() takes a cache hit as proof that the
++ * region was validated, so the stale entries have to go.
++ */
++ __vhost_vq_meta_reset(vq);
++
+ mutex_unlock(&vq->mutex);
+
+ return r;
+diff --git a/drivers/video/fbdev/core/bitblit.c b/drivers/video/fbdev/core/bitblit.c
+index 8563264d11fac6..036e0ffca08a25 100644
+--- a/drivers/video/fbdev/core/bitblit.c
++++ b/drivers/video/fbdev/core/bitblit.c
+@@ -274,9 +274,14 @@ static void bit_cursor(struct vc_data *vc, struct fb_info *info, int mode,
+ if (!vc->vc_font.data)
+ return;
+
+- c = scr_readw((u16 *) vc->vc_pos);
++ c = scr_readw((u16 *) vc->vc_pos);
+ attribute = get_attribute(info, c);
+- src = vc->vc_font.data + ((c & charmask) * (w * vc->vc_font.height));
++ c &= charmask;
++
++ /* Clamp to font size, same as bit_putcs_aligned() */
++ if (c >= vc->vc_font.charcount)
++ c = 0;
++ src = vc->vc_font.data + (c * (w * vc->vc_font.height));
+
+ if (ops->cursor_state.image.data != src ||
+ ops->cursor_reset) {
+diff --git a/drivers/watchdog/watchdog_pretimeout.c b/drivers/watchdog/watchdog_pretimeout.c
+index 376a495ab80c49..3c109f1db8f0e5 100644
+--- a/drivers/watchdog/watchdog_pretimeout.c
++++ b/drivers/watchdog/watchdog_pretimeout.c
+@@ -165,6 +165,8 @@ void watchdog_unregister_governor(struct watchdog_governor *gov)
+ }
+
+ spin_lock_irq(&pretimeout_lock);
++ if (default_gov == gov)
++ default_gov = NULL;
+ list_for_each_entry(p, &pretimeout_list, entry)
+ if (p->wdd->gov == gov)
+ p->wdd->gov = default_gov;
+diff --git a/fs/binfmt_elf_fdpic.c b/fs/binfmt_elf_fdpic.c
+index b2d3b6e43bb56f..b61a2d0e08cd08 100644
+--- a/fs/binfmt_elf_fdpic.c
++++ b/fs/binfmt_elf_fdpic.c
+@@ -231,6 +231,10 @@ static int load_elf_fdpic_binary(struct linux_binprm *bprm)
+ for (i = 0; i < exec_params.hdr.e_phnum; i++, phdr++) {
+ switch (phdr->p_type) {
+ case PT_INTERP:
++ /* elf ABI allows only one interpreter */
++ if (interpreter_name)
++ continue;
++
+ retval = -ENOMEM;
+ if (phdr->p_filesz > PATH_MAX)
+ goto error;
+diff --git a/fs/binfmt_misc.c b/fs/binfmt_misc.c
+index 05c2353094217f..a26ae2ca96e808 100644
+--- a/fs/binfmt_misc.c
++++ b/fs/binfmt_misc.c
+@@ -199,9 +199,6 @@ static int load_misc_binary(struct linux_binprm *bprm)
+ goto ret;
+ }
+
+- if (fmt->flags & MISC_FMT_OPEN_BINARY)
+- bprm->have_execfd = 1;
+-
+ /* make argv[1] be the path to the binary */
+ retval = copy_string_kernel(bprm->interp, bprm);
+ if (retval < 0)
+@@ -231,6 +228,8 @@ static int load_misc_binary(struct linux_binprm *bprm)
+ goto ret;
+
+ bprm->interpreter = interp_file;
++ if (fmt->flags & MISC_FMT_OPEN_BINARY)
++ bprm->have_execfd = 1;
+ if (fmt->flags & MISC_FMT_CREDENTIALS)
+ bprm->execfd_creds = 1;
+
+@@ -348,6 +347,10 @@ static Node *create_entry(const char __user *buffer, size_t count)
+
+ pr_debug("register: delim: %#x {%c}\n", del, del);
+
++ /* A flag-char delimiter runs the flag scan off the buffer. */
++ if (del == 'P' || del == 'O' || del == 'C' || del == 'F')
++ goto einval;
++
+ /* Pad the buffer with the delim to simplify parsing below. */
+ memset(buf + count, del, 8);
+
+diff --git a/fs/btrfs/free-space-cache.c b/fs/btrfs/free-space-cache.c
+index 9f4dae426037b8..92933cc5596e0f 100644
+--- a/fs/btrfs/free-space-cache.c
++++ b/fs/btrfs/free-space-cache.c
+@@ -569,6 +569,9 @@ static int io_ctl_check_crc(struct btrfs_io_ctl *io_ctl, int index)
+ u32 crc = ~(u32)0;
+ unsigned offset = 0;
+
++ if (index >= io_ctl->num_pages)
++ return -EIO;
++
+ if (index == 0)
+ offset = sizeof(u32) * io_ctl->num_pages;
+
+diff --git a/fs/btrfs/inode.c b/fs/btrfs/inode.c
+index 77b436bf1db768..b2a1d96a806a92 100644
+--- a/fs/btrfs/inode.c
++++ b/fs/btrfs/inode.c
+@@ -11181,6 +11181,7 @@ out_pages:
+ }
+ kvfree(pages);
+ out:
++ extent_changeset_free(data_reserved);
+ if (ret >= 0)
+ iocb->ki_pos += encoded->len;
+ return ret;
+diff --git a/fs/btrfs/relocation.c b/fs/btrfs/relocation.c
+index 93916c52b50e94..d37904a806d6a0 100644
+--- a/fs/btrfs/relocation.c
++++ b/fs/btrfs/relocation.c
+@@ -645,6 +645,7 @@ static int __must_check __add_reloc_root(struct btrfs_root *root)
+ btrfs_err(fs_info,
+ "Duplicate root found for start=%llu while inserting into relocation tree",
+ node->bytenr);
++ kfree(node);
+ return -EEXIST;
+ }
+
+@@ -2045,6 +2046,7 @@ again:
+ * corruption, e.g. bad reloc tree key offset.
+ */
+ ret = -EINVAL;
++ btrfs_put_root(root);
+ goto out;
+ }
+ ret = merge_reloc_root(rc, root);
+diff --git a/fs/ceph/caps.c b/fs/ceph/caps.c
+index 57603782e7e2a6..08530f9407c714 100644
+--- a/fs/ceph/caps.c
++++ b/fs/ceph/caps.c
+@@ -4117,6 +4117,7 @@ void ceph_handle_caps(struct ceph_mds_session *session,
+
+ snaptrace = h + 1;
+ snaptrace_len = le32_to_cpu(h->snap_trace_len);
++ ceph_decode_need(&snaptrace, end, snaptrace_len, bad);
+ p = snaptrace + snaptrace_len;
+
+ if (msg_version >= 2) {
+diff --git a/fs/crypto/fscrypt_private.h b/fs/crypto/fscrypt_private.h
+index 88414cbd97aee1..aabc3a4751df7f 100644
+--- a/fs/crypto/fscrypt_private.h
++++ b/fs/crypto/fscrypt_private.h
+@@ -423,6 +423,19 @@ fscrypt_is_key_prepared(struct fscrypt_prepared_key *prep_key,
+
+ /* keyring.c */
+
++/*
++ * fscrypt_master_key_user - a user's claim to a master key
++ */
++struct fscrypt_master_key_user {
++ struct list_head link;
++ kuid_t uid;
++ /*
++ * This 'struct key' contains no secret. It exists solely to charge the
++ * appropriate user's key quota.
++ */
++ struct key *quota_key;
++};
++
+ /*
+ * fscrypt_master_key_secret - secret key material of an in-use master key
+ */
+@@ -513,19 +526,18 @@ struct fscrypt_master_key {
+ struct fscrypt_key_specifier mk_spec;
+
+ /*
+- * Keyring which contains a key of type 'key_type_fscrypt_user' for each
+- * user who has added this key. Normally each key will be added by just
+- * one user, but it's possible that multiple users share a key, and in
+- * that case we need to keep track of those users so that one user can't
+- * remove the key before the others want it removed too.
++ * List of user claims to this key (struct fscrypt_master_key_user).
++ * Normally each key will be added by just one user, but it's possible
++ * that multiple users share a key, and in that case we need to keep
++ * track of those users so that one user can't remove the key before the
++ * others want it removed too.
+ *
+- * This is NULL for v1 policy keys; those can only be added by root.
++ * Used only for v2 policy keys. v1 policy keys can be added only by
++ * root, so user tracking doesn't apply to them.
+ *
+- * Locking: protected by ->mk_sem. (We don't just rely on the keyrings
+- * subsystem semaphore ->mk_users->sem, as we need support for atomic
+- * search+insert along with proper synchronization with ->mk_secret.)
++ * Locking: protected by ->mk_sem.
+ */
+- struct key *mk_users;
++ struct list_head mk_users;
+
+ /*
+ * List of inodes that were unlocked using this key. This allows the
+diff --git a/fs/crypto/inline_crypt.c b/fs/crypto/inline_crypt.c
+index 8bfb3ce864766e..47645c5539bc84 100644
+--- a/fs/crypto/inline_crypt.c
++++ b/fs/crypto/inline_crypt.c
+@@ -21,22 +21,14 @@
+
+ #include "fscrypt_private.h"
+
+-static struct block_device **fscrypt_get_devices(struct super_block *sb,
+- unsigned int *num_devs)
++static unsigned int
++fscrypt_get_devices(struct super_block *sb,
++ struct block_device *devs[FSCRYPT_MAX_DEVICES])
+ {
+- struct block_device **devs;
+-
+- if (sb->s_cop->get_devices) {
+- devs = sb->s_cop->get_devices(sb, num_devs);
+- if (devs)
+- return devs;
+- }
+- devs = kmalloc(sizeof(*devs), GFP_KERNEL);
+- if (!devs)
+- return ERR_PTR(-ENOMEM);
++ if (sb->s_cop->get_devices)
++ return sb->s_cop->get_devices(sb, devs);
+ devs[0] = sb->s_bdev;
+- *num_devs = 1;
+- return devs;
++ return 1;
+ }
+
+ static unsigned int fscrypt_get_dun_bytes(const struct fscrypt_info *ci)
+@@ -95,7 +87,7 @@ int fscrypt_select_encryption_impl(struct fscrypt_info *ci)
+ const struct inode *inode = ci->ci_inode;
+ struct super_block *sb = inode->i_sb;
+ struct blk_crypto_config crypto_cfg;
+- struct block_device **devs;
++ struct block_device *devs[FSCRYPT_MAX_DEVICES];
+ unsigned int num_devs;
+ unsigned int i;
+
+@@ -132,20 +124,15 @@ int fscrypt_select_encryption_impl(struct fscrypt_info *ci)
+ crypto_cfg.data_unit_size = sb->s_blocksize;
+ crypto_cfg.dun_bytes = fscrypt_get_dun_bytes(ci);
+
+- devs = fscrypt_get_devices(sb, &num_devs);
+- if (IS_ERR(devs))
+- return PTR_ERR(devs);
+-
++ num_devs = fscrypt_get_devices(sb, devs);
+ for (i = 0; i < num_devs; i++) {
+ if (!blk_crypto_config_supported(devs[i], &crypto_cfg))
+- goto out_free_devs;
++ return 0;
+ }
+
+ fscrypt_log_blk_crypto_impl(ci->ci_mode, devs, num_devs, &crypto_cfg);
+
+ ci->ci_inlinecrypt = true;
+-out_free_devs:
+- kfree(devs);
+
+ return 0;
+ }
+@@ -158,7 +145,7 @@ int fscrypt_prepare_inline_crypt_key(struct fscrypt_prepared_key *prep_key,
+ struct super_block *sb = inode->i_sb;
+ enum blk_crypto_mode_num crypto_mode = ci->ci_mode->blk_crypto_mode;
+ struct blk_crypto_key *blk_key;
+- struct block_device **devs;
++ struct block_device *devs[FSCRYPT_MAX_DEVICES];
+ unsigned int num_devs;
+ unsigned int i;
+ int err;
+@@ -175,17 +162,12 @@ int fscrypt_prepare_inline_crypt_key(struct fscrypt_prepared_key *prep_key,
+ }
+
+ /* Start using blk-crypto on all the filesystem's block devices. */
+- devs = fscrypt_get_devices(sb, &num_devs);
+- if (IS_ERR(devs)) {
+- err = PTR_ERR(devs);
+- goto fail;
+- }
++ num_devs = fscrypt_get_devices(sb, devs);
+ for (i = 0; i < num_devs; i++) {
+ err = blk_crypto_start_using_key(devs[i], blk_key);
+ if (err)
+ break;
+ }
+- kfree(devs);
+ if (err) {
+ fscrypt_err(inode, "error %d starting to use blk-crypto", err);
+ goto fail;
+@@ -209,20 +191,21 @@ void fscrypt_destroy_inline_crypt_key(struct super_block *sb,
+ struct fscrypt_prepared_key *prep_key)
+ {
+ struct blk_crypto_key *blk_key = prep_key->blk_key;
+- struct block_device **devs;
++ struct block_device *devs[FSCRYPT_MAX_DEVICES];
+ unsigned int num_devs;
+ unsigned int i;
+
+ if (!blk_key)
+ return;
+
+- /* Evict the key from all the filesystem's block devices. */
+- devs = fscrypt_get_devices(sb, &num_devs);
+- if (!IS_ERR(devs)) {
+- for (i = 0; i < num_devs; i++)
+- blk_crypto_evict_key(devs[i], blk_key);
+- kfree(devs);
+- }
++ /*
++ * Evict the key from all the filesystem's block devices.
++ * This *must* be done before the key is freed.
++ */
++ num_devs = fscrypt_get_devices(sb, devs);
++ for (i = 0; i < num_devs; i++)
++ blk_crypto_evict_key(devs[i], blk_key);
++
+ kfree_sensitive(blk_key);
+ }
+
+diff --git a/fs/crypto/keyring.c b/fs/crypto/keyring.c
+index 2a24b1f0ae688b..e1cce06f43439b 100644
+--- a/fs/crypto/keyring.c
++++ b/fs/crypto/keyring.c
+@@ -64,18 +64,19 @@ static void fscrypt_free_master_key(struct rcu_head *head)
+ kfree_sensitive(mk);
+ }
+
++static void clear_mk_users(struct fscrypt_master_key *mk);
++
+ void fscrypt_put_master_key(struct fscrypt_master_key *mk)
+ {
+ if (!refcount_dec_and_test(&mk->mk_struct_refs))
+ return;
+ /*
+- * No structural references left, so free ->mk_users, and also free the
++ * No structural references left, so clear ->mk_users, and also free the
+ * fscrypt_master_key struct itself after an RCU grace period ensures
+ * that concurrent keyring lookups can no longer find it.
+ */
+ WARN_ON(refcount_read(&mk->mk_active_refs) != 0);
+- key_put(mk->mk_users);
+- mk->mk_users = NULL;
++ clear_mk_users(mk);
+ call_rcu(&mk->mk_rcu_head, fscrypt_free_master_key);
+ }
+
+@@ -144,8 +145,8 @@ static void fscrypt_user_key_describe(const struct key *key, struct seq_file *m)
+ }
+
+ /*
+- * Type of key in ->mk_users. Each key of this type represents a particular
+- * user who has added a particular master key.
++ * Type of fscrypt_master_key_user::quota_key. This contains no secret; it
++ * exists solely to charge a user's key quota.
+ *
+ * Note that the name of this key type really should be something like
+ * ".fscrypt-user" instead of simply ".fscrypt". But the shorter name is chosen
+@@ -159,30 +160,9 @@ static struct key_type key_type_fscrypt_user = {
+ .describe = fscrypt_user_key_describe,
+ };
+
+-#define FSCRYPT_MK_USERS_DESCRIPTION_SIZE \
+- (CONST_STRLEN("fscrypt-") + 2 * FSCRYPT_KEY_IDENTIFIER_SIZE + \
+- CONST_STRLEN("-users") + 1)
+-
+ #define FSCRYPT_MK_USER_DESCRIPTION_SIZE \
+ (2 * FSCRYPT_KEY_IDENTIFIER_SIZE + CONST_STRLEN(".uid.") + 10 + 1)
+
+-static void format_mk_users_keyring_description(
+- char description[FSCRYPT_MK_USERS_DESCRIPTION_SIZE],
+- const u8 mk_identifier[FSCRYPT_KEY_IDENTIFIER_SIZE])
+-{
+- sprintf(description, "fscrypt-%*phN-users",
+- FSCRYPT_KEY_IDENTIFIER_SIZE, mk_identifier);
+-}
+-
+-static void format_mk_user_description(
+- char description[FSCRYPT_MK_USER_DESCRIPTION_SIZE],
+- const u8 mk_identifier[FSCRYPT_KEY_IDENTIFIER_SIZE])
+-{
+-
+- sprintf(description, "%*phN.uid.%u", FSCRYPT_KEY_IDENTIFIER_SIZE,
+- mk_identifier, __kuid_val(current_fsuid()));
+-}
+-
+ /* Create ->s_master_keys if needed. Synchronized by fscrypt_add_key_mutex. */
+ static int allocate_filesystem_keyring(struct super_block *sb)
+ {
+@@ -321,91 +301,94 @@ out:
+ return mk;
+ }
+
+-static int allocate_master_key_users_keyring(struct fscrypt_master_key *mk)
++/* Find the current user's claim in ->mk_users. ->mk_sem must be held. */
++static struct fscrypt_master_key_user *
++find_master_key_user(struct fscrypt_master_key *mk)
+ {
+- char description[FSCRYPT_MK_USERS_DESCRIPTION_SIZE];
+- struct key *keyring;
+-
+- format_mk_users_keyring_description(description,
+- mk->mk_spec.u.identifier);
+- keyring = keyring_alloc(description, GLOBAL_ROOT_UID, GLOBAL_ROOT_GID,
+- current_cred(), KEY_POS_SEARCH |
+- KEY_USR_SEARCH | KEY_USR_READ | KEY_USR_VIEW,
+- KEY_ALLOC_NOT_IN_QUOTA, NULL, NULL);
+- if (IS_ERR(keyring))
+- return PTR_ERR(keyring);
+-
+- mk->mk_users = keyring;
+- return 0;
+-}
++ struct fscrypt_master_key_user *mk_user;
++ kuid_t uid = current_fsuid();
+
+-/*
+- * Find the current user's "key" in the master key's ->mk_users.
+- * Returns ERR_PTR(-ENOKEY) if not found.
+- */
+-static struct key *find_master_key_user(struct fscrypt_master_key *mk)
+-{
+- char description[FSCRYPT_MK_USER_DESCRIPTION_SIZE];
+- key_ref_t keyref;
+-
+- format_mk_user_description(description, mk->mk_spec.u.identifier);
+-
+- /*
+- * We need to mark the keyring reference as "possessed" so that we
+- * acquire permission to search it, via the KEY_POS_SEARCH permission.
+- */
+- keyref = keyring_search(make_key_ref(mk->mk_users, true /*possessed*/),
+- &key_type_fscrypt_user, description, false);
+- if (IS_ERR(keyref)) {
+- if (PTR_ERR(keyref) == -EAGAIN || /* not found */
+- PTR_ERR(keyref) == -EKEYREVOKED) /* recently invalidated */
+- keyref = ERR_PTR(-ENOKEY);
+- return ERR_CAST(keyref);
++ list_for_each_entry(mk_user, &mk->mk_users, link) {
++ if (uid_eq(mk_user->uid, uid))
++ return mk_user;
+ }
+- return key_ref_to_ptr(keyref);
++ return NULL;
+ }
+
+ /*
+- * Give the current user a "key" in ->mk_users. This charges the user's quota
++ * Give the current user a claim in ->mk_users. This charges the user's quota
+ * and marks the master key as added by the current user, so that it cannot be
+ * removed by another user with the key. Either ->mk_sem must be held for
+ * write, or the master key must be still undergoing initialization.
+ */
+ static int add_master_key_user(struct fscrypt_master_key *mk)
+ {
++ kuid_t uid = current_fsuid();
+ char description[FSCRYPT_MK_USER_DESCRIPTION_SIZE];
+- struct key *mk_user;
++ struct key *quota_key;
++ struct fscrypt_master_key_user *mk_user;
+ int err;
+
+- format_mk_user_description(description, mk->mk_spec.u.identifier);
+- mk_user = key_alloc(&key_type_fscrypt_user, description,
+- current_fsuid(), current_gid(), current_cred(),
+- KEY_POS_SEARCH | KEY_USR_VIEW, 0, NULL);
+- if (IS_ERR(mk_user))
+- return PTR_ERR(mk_user);
++ snprintf(description, sizeof(description), "%*phN.uid.%u",
++ FSCRYPT_KEY_IDENTIFIER_SIZE, mk->mk_spec.u.identifier,
++ __kuid_val(uid));
++ quota_key = key_alloc(&key_type_fscrypt_user, description, uid,
++ current_gid(), current_cred(),
++ KEY_POS_SEARCH | KEY_USR_VIEW, 0, NULL);
++ if (IS_ERR(quota_key))
++ return PTR_ERR(quota_key);
++
++ err = key_instantiate_and_link(quota_key, NULL, 0, NULL, NULL);
++ if (err) {
++ key_put(quota_key);
++ return err;
++ }
+
+- err = key_instantiate_and_link(mk_user, NULL, 0, mk->mk_users, NULL);
+- key_put(mk_user);
+- return err;
++ mk_user = kzalloc(sizeof(*mk_user), GFP_KERNEL);
++ if (!mk_user) {
++ key_put(quota_key);
++ return -ENOMEM;
++ }
++ mk_user->uid = uid;
++ mk_user->quota_key = quota_key;
++ list_add(&mk_user->link, &mk->mk_users);
++ return 0;
++}
++
++static void unlink_and_free_mk_user(struct fscrypt_master_key_user *mk_user)
++{
++ list_del(&mk_user->link);
++ key_put(mk_user->quota_key);
++ kfree(mk_user);
+ }
+
+ /*
+- * Remove the current user's "key" from ->mk_users.
++ * Remove the current user's claim from ->mk_users.
+ * ->mk_sem must be held for write.
+ *
+- * Returns 0 if removed, -ENOKEY if not found, or another -errno code.
++ * Returns 0 if removed or -ENOKEY if not found.
+ */
+ static int remove_master_key_user(struct fscrypt_master_key *mk)
+ {
+- struct key *mk_user;
+- int err;
++ struct fscrypt_master_key_user *mk_user;
+
+ mk_user = find_master_key_user(mk);
+- if (IS_ERR(mk_user))
+- return PTR_ERR(mk_user);
+- err = key_unlink(mk->mk_users, mk_user);
+- key_put(mk_user);
+- return err;
++ if (!mk_user)
++ return -ENOKEY;
++ unlink_and_free_mk_user(mk_user);
++ return 0;
++}
++
++/*
++ * Clear ->mk_users. Either ->mk_sem must be held for write, or 'mk' must have
++ * no structural references left.
++ */
++static void clear_mk_users(struct fscrypt_master_key *mk)
++{
++ struct fscrypt_master_key_user *mk_user, *tmp;
++
++ list_for_each_entry_safe(mk_user, tmp, &mk->mk_users, link)
++ unlink_and_free_mk_user(mk_user);
+ }
+
+ /*
+@@ -429,13 +412,12 @@ static int add_new_master_key(struct super_block *sb,
+ refcount_set(&mk->mk_struct_refs, 1);
+ mk->mk_spec = *mk_spec;
+
++ INIT_LIST_HEAD(&mk->mk_users);
++
+ INIT_LIST_HEAD(&mk->mk_decrypted_inodes);
+ spin_lock_init(&mk->mk_decrypted_inodes_lock);
+
+ if (mk_spec->type == FSCRYPT_KEY_SPEC_TYPE_IDENTIFIER) {
+- err = allocate_master_key_users_keyring(mk);
+- if (err)
+- goto out_put;
+ err = add_master_key_user(mk);
+ if (err)
+ goto out_put;
+@@ -463,19 +445,13 @@ static int add_existing_master_key(struct fscrypt_master_key *mk,
+ int err;
+
+ /*
+- * If the current user is already in ->mk_users, then there's nothing to
+- * do. Otherwise, we need to add the user to ->mk_users. (Neither is
+- * applicable for v1 policy keys, which have NULL ->mk_users.)
++ * For v2 policy keys (FSCRYPT_KEY_SPEC_TYPE_IDENTIFIER): If the current
++ * user is already in ->mk_users, then there's nothing to do.
++ * Otherwise, add the user to ->mk_users.
+ */
+- if (mk->mk_users) {
+- struct key *mk_user = find_master_key_user(mk);
+-
+- if (mk_user != ERR_PTR(-ENOKEY)) {
+- if (IS_ERR(mk_user))
+- return PTR_ERR(mk_user);
+- key_put(mk_user);
++ if (mk->mk_spec.type == FSCRYPT_KEY_SPEC_TYPE_IDENTIFIER) {
++ if (find_master_key_user(mk) != NULL)
+ return 0;
+- }
+ err = add_master_key_user(mk);
+ if (err)
+ return err;
+@@ -830,7 +806,6 @@ int fscrypt_verify_key_added(struct super_block *sb,
+ {
+ struct fscrypt_key_specifier mk_spec;
+ struct fscrypt_master_key *mk;
+- struct key *mk_user;
+ int err;
+
+ mk_spec.type = FSCRYPT_KEY_SPEC_TYPE_IDENTIFIER;
+@@ -842,13 +817,10 @@ int fscrypt_verify_key_added(struct super_block *sb,
+ goto out;
+ }
+ down_read(&mk->mk_sem);
+- mk_user = find_master_key_user(mk);
+- if (IS_ERR(mk_user)) {
+- err = PTR_ERR(mk_user);
+- } else {
+- key_put(mk_user);
++ if (find_master_key_user(mk) != NULL)
+ err = 0;
+- }
++ else
++ err = -ENOKEY;
+ up_read(&mk->mk_sem);
+ fscrypt_put_master_key(mk);
+ out:
+@@ -1041,16 +1013,18 @@ static int do_remove_key(struct file *filp, void __user *_uarg, bool all_users)
+ down_write(&mk->mk_sem);
+
+ /* If relevant, remove current user's (or all users) claim to the key */
+- if (mk->mk_users && mk->mk_users->keys.nr_leaves_on_tree != 0) {
+- if (all_users)
+- err = keyring_clear(mk->mk_users);
+- else
++ if (!list_empty(&mk->mk_users)) {
++ if (all_users) {
++ clear_mk_users(mk);
++ err = 0;
++ } else {
+ err = remove_master_key_user(mk);
++ }
+ if (err) {
+ up_write(&mk->mk_sem);
+ goto out_put_key;
+ }
+- if (mk->mk_users->keys.nr_leaves_on_tree != 0) {
++ if (!list_empty(&mk->mk_users)) {
+ /*
+ * Other users have still added the key too. We removed
+ * the current user's claim to the key, but we still
+@@ -1138,6 +1112,8 @@ int fscrypt_ioctl_get_key_status(struct file *filp, void __user *uarg)
+ struct super_block *sb = file_inode(filp)->i_sb;
+ struct fscrypt_get_key_status_arg arg;
+ struct fscrypt_master_key *mk;
++ kuid_t uid;
++ const struct fscrypt_master_key_user *mk_user;
+ int err;
+
+ if (copy_from_user(&arg, uarg, sizeof(arg)))
+@@ -1170,19 +1146,13 @@ int fscrypt_ioctl_get_key_status(struct file *filp, void __user *uarg)
+ }
+
+ arg.status = FSCRYPT_KEY_STATUS_PRESENT;
+- if (mk->mk_users) {
+- struct key *mk_user;
+
+- arg.user_count = mk->mk_users->keys.nr_leaves_on_tree;
+- mk_user = find_master_key_user(mk);
+- if (!IS_ERR(mk_user)) {
++ uid = current_fsuid();
++ list_for_each_entry(mk_user, &mk->mk_users, link) {
++ arg.user_count++;
++ if (uid_eq(mk_user->uid, uid))
+ arg.status_flags |=
+ FSCRYPT_KEY_STATUS_FLAG_ADDED_BY_SELF;
+- key_put(mk_user);
+- } else if (mk_user != ERR_PTR(-ENOKEY)) {
+- err = PTR_ERR(mk_user);
+- goto out_release_key;
+- }
+ }
+ err = 0;
+ out_release_key:
+diff --git a/fs/crypto/keysetup_v1.c b/fs/crypto/keysetup_v1.c
+index 159dd0288349a0..7e0bb9a75c5906 100644
+--- a/fs/crypto/keysetup_v1.c
++++ b/fs/crypto/keysetup_v1.c
+@@ -199,13 +199,19 @@ find_or_insert_direct_key(struct fscrypt_direct_key *to_insert,
+ if (memcmp(ci->ci_policy.v1.master_key_descriptor,
+ dk->dk_descriptor, FSCRYPT_KEY_DESCRIPTOR_SIZE) != 0)
+ continue;
++ /* The sb is used at eviction time, so it must be the same. */
++ if (ci->ci_inode->i_sb != dk->dk_sb)
++ continue;
+ if (ci->ci_mode != dk->dk_mode)
+ continue;
+ if (!fscrypt_is_key_prepared(&dk->dk_key, ci))
+ continue;
+ if (crypto_memneq(raw_key, dk->dk_raw, ci->ci_mode->keysize))
+ continue;
+- /* using existing tfm with same (descriptor, mode, raw_key) */
++ /*
++ * Use an existing prepared key with the same (descriptor, sb,
++ * mode, inlinecrypt, raw_key) combination.
++ */
+ refcount_inc(&dk->dk_refcount);
+ spin_unlock(&fscrypt_direct_keys_lock);
+ free_direct_key(to_insert);
+diff --git a/fs/exec.c b/fs/exec.c
+index a4d21a67723d7d..9172cafa3f4c99 100644
+--- a/fs/exec.c
++++ b/fs/exec.c
+@@ -884,7 +884,7 @@ int transfer_args_to_stack(struct linux_binprm *bprm,
+ stop = bprm->p >> PAGE_SHIFT;
+ sp = *sp_location;
+
+- for (index = MAX_ARG_PAGES - 1; index >= stop; index--) {
++ for (index = MAX_ARG_PAGES; index-- > stop; ) {
+ unsigned int offset = index == stop ? bprm->p & ~PAGE_MASK : 0;
+ char *src = kmap_local_page(bprm->page[index]) + offset;
+ sp -= PAGE_SIZE - offset;
+diff --git a/fs/exfat/balloc.c b/fs/exfat/balloc.c
+index 32209acd51be4f..2d4fe3d754bbc5 100644
+--- a/fs/exfat/balloc.c
++++ b/fs/exfat/balloc.c
+@@ -45,12 +45,37 @@ static const unsigned char used_bit[] = {
+ /*
+ * Allocation Bitmap Management Functions
+ */
++static bool exfat_test_bitmap_range(struct super_block *sb, unsigned int clu,
++ unsigned int count)
++{
++ struct exfat_sb_info *sbi = EXFAT_SB(sb);
++ unsigned int start = clu;
++ unsigned int end = clu + count;
++ unsigned int ent_idx, i, b;
++
++ if (!is_valid_cluster(sbi, start) || !is_valid_cluster(sbi, end - 1))
++ return false;
++
++ while (start < end) {
++ ent_idx = CLUSTER_TO_BITMAP_ENT(start);
++ i = BITMAP_OFFSET_SECTOR_INDEX(sb, ent_idx);
++ b = BITMAP_OFFSET_BIT_IN_SECTOR(sb, ent_idx);
++
++ if (!test_bit_le(b, sbi->vol_amap[i]->b_data))
++ return false;
++
++ start++;
++ }
++
++ return true;
++}
++
+ static int exfat_allocate_bitmap(struct super_block *sb,
+ struct exfat_dentry *ep)
+ {
+ struct exfat_sb_info *sbi = EXFAT_SB(sb);
+ long long map_size;
+- unsigned int i, need_map_size;
++ unsigned int i, j, need_map_size;
+ sector_t sector;
+
+ sbi->map_clu = le32_to_cpu(ep->dentry.bitmap.start_clu);
+@@ -77,20 +102,25 @@ static int exfat_allocate_bitmap(struct super_block *sb,
+ sector = exfat_cluster_to_sector(sbi, sbi->map_clu);
+ for (i = 0; i < sbi->map_sectors; i++) {
+ sbi->vol_amap[i] = sb_bread(sb, sector + i);
+- if (!sbi->vol_amap[i]) {
+- /* release all buffers and free vol_amap */
+- int j = 0;
+-
+- while (j < i)
+- brelse(sbi->vol_amap[j++]);
+-
+- kvfree(sbi->vol_amap);
+- sbi->vol_amap = NULL;
+- return -EIO;
+- }
++ if (!sbi->vol_amap[i])
++ goto err_out;
+ }
+
++ if (exfat_test_bitmap_range(sb, sbi->map_clu,
++ EXFAT_B_TO_CLU_ROUND_UP(map_size, sbi)) == false)
++ goto err_out;
++
+ return 0;
++
++err_out:
++ j = 0;
++ /* release all buffers and free vol_amap */
++ while (j < i)
++ brelse(sbi->vol_amap[j++]);
++
++ kvfree(sbi->vol_amap);
++ sbi->vol_amap = NULL;
++ return -EIO;
+ }
+
+ int exfat_load_bitmap(struct super_block *sb)
+diff --git a/fs/f2fs/super.c b/fs/f2fs/super.c
+index 7c8e05a81a0c63..9d1b5699f5bf1a 100644
+--- a/fs/f2fs/super.c
++++ b/fs/f2fs/super.c
+@@ -3126,24 +3126,27 @@ static void f2fs_get_ino_and_lblk_bits(struct super_block *sb,
+ *lblk_bits_ret = 8 * sizeof(block_t);
+ }
+
+-static struct block_device **f2fs_get_devices(struct super_block *sb,
+- unsigned int *num_devs)
++static unsigned int
++f2fs_get_devices(struct super_block *sb,
++ struct block_device *devs[FSCRYPT_MAX_DEVICES])
+ {
+ struct f2fs_sb_info *sbi = F2FS_SB(sb);
+- struct block_device **devs;
++ int ndevs;
+ int i;
+
+- if (!f2fs_is_multi_device(sbi))
+- return NULL;
++ static_assert(MAX_DEVICES <= FSCRYPT_MAX_DEVICES);
+
+- devs = kmalloc_array(sbi->s_ndevs, sizeof(*devs), GFP_KERNEL);
+- if (!devs)
+- return ERR_PTR(-ENOMEM);
++ if (!f2fs_is_multi_device(sbi)) {
++ devs[0] = sb->s_bdev;
++ return 1;
++ }
++ ndevs = sbi->s_ndevs;
++ if (WARN_ON_ONCE(ndevs > FSCRYPT_MAX_DEVICES))
++ ndevs = FSCRYPT_MAX_DEVICES;
+
+- for (i = 0; i < sbi->s_ndevs; i++)
++ for (i = 0; i < ndevs; i++)
+ devs[i] = FDEV(i).bdev;
+- *num_devs = sbi->s_ndevs;
+- return devs;
++ return ndevs;
+ }
+
+ static const struct fscrypt_operations f2fs_cryptops = {
+diff --git a/fs/namespace.c b/fs/namespace.c
+index f22f76d9c22f97..ed5e9e7251e34b 100644
+--- a/fs/namespace.c
++++ b/fs/namespace.c
+@@ -3744,6 +3744,11 @@ SYSCALL_DEFINE3(fsmount, int, fs_fd, unsigned int, flags,
+ ret = PTR_ERR(newmount.mnt);
+ goto err_unlock;
+ }
++ if (newmount.mnt->mnt_sb->s_flags & SB_NOUSER) {
++ mntput(newmount.mnt);
++ ret = -EINVAL;
++ goto err_unlock;
++ }
+ newmount.dentry = dget(fc->root);
+ newmount.mnt->mnt_flags = mnt_flags;
+
+diff --git a/fs/nfs/nfs4proc.c b/fs/nfs/nfs4proc.c
+index 8258bce82e5bc8..9f352f1a6eb1e9 100644
+--- a/fs/nfs/nfs4proc.c
++++ b/fs/nfs/nfs4proc.c
+@@ -10388,6 +10388,7 @@ static void nfs41_free_stateid_release(void *calldata)
+ struct nfs_free_stateid_data *data = calldata;
+ struct nfs_client *clp = data->server->nfs_client;
+
++ nfs_sb_deactive(data->server->super);
+ nfs_put_client(clp);
+ kfree(calldata);
+ }
+@@ -10429,6 +10430,10 @@ static int nfs41_free_stateid(struct nfs_server *server,
+
+ if (!refcount_inc_not_zero(&clp->cl_count))
+ return -EIO;
++ if (!nfs_sb_active(server->super)) {
++ nfs_put_client(clp);
++ return -EIO;
++ }
+
+ nfs4_state_protect(server->nfs_client, NFS_SP4_MACH_CRED_STATEID,
+ &task_setup.rpc_client, &msg);
+diff --git a/fs/proc/namespaces.c b/fs/proc/namespaces.c
+index 2a3fc96ca62230..203d3363e3d5a2 100644
+--- a/fs/proc/namespaces.c
++++ b/fs/proc/namespaces.c
+@@ -46,7 +46,7 @@ static const char *proc_ns_get_link(struct dentry *dentry,
+ const struct proc_ns_operations *ns_ops = PROC_I(inode)->ns_ops;
+ struct task_struct *task;
+ struct path ns_path;
+- int error = -EACCES;
++ int error;
+
+ if (!dentry)
+ return ERR_PTR(-ECHILD);
+@@ -59,6 +59,7 @@ static const char *proc_ns_get_link(struct dentry *dentry,
+ if (error)
+ goto out_put_task;
+
++ error = -EACCES;
+ if (!ptrace_may_access(task, PTRACE_MODE_READ_FSCREDS))
+ goto out;
+
+@@ -90,6 +91,7 @@ static int proc_ns_readlink(struct dentry *dentry, char __user *buffer, int bufl
+ if (res)
+ goto out_put_task;
+
++ res = -EACCES;
+ if (ptrace_may_access(task, PTRACE_MODE_READ_FSCREDS)) {
+ res = ns_get_name(name, sizeof(name), task, ns_ops);
+ if (res >= 0)
+diff --git a/fs/smb/client/cifssmb.c b/fs/smb/client/cifssmb.c
+index 49d7726830044e..95cf7e69a411dc 100644
+--- a/fs/smb/client/cifssmb.c
++++ b/fs/smb/client/cifssmb.c
+@@ -1409,8 +1409,10 @@ CIFSSMBRead(const unsigned int xid, struct cifs_io_parms *io_parms,
+ pSMB->hdr.PidHigh = cpu_to_le16((__u16)(pid >> 16));
+
+ /* tcon and ses pointer are checked in smb_init */
+- if (tcon->ses->server == NULL)
++ if (!tcon->ses->server) {
++ cifs_small_buf_release(pSMB);
+ return -ECONNABORTED;
++ }
+
+ pSMB->AndXCommand = 0xFF; /* none */
+ pSMB->Fid = netfid;
+@@ -1522,8 +1524,10 @@ CIFSSMBWrite(const unsigned int xid, struct cifs_io_parms *io_parms,
+ pSMB->hdr.PidHigh = cpu_to_le16((__u16)(pid >> 16));
+
+ /* tcon and ses pointer are checked in smb_init */
+- if (tcon->ses->server == NULL)
++ if (!tcon->ses->server) {
++ cifs_buf_release(pSMB);
+ return -ECONNABORTED;
++ }
+
+ pSMB->AndXCommand = 0xFF; /* none */
+ pSMB->Fid = netfid;
+@@ -1776,8 +1780,10 @@ CIFSSMBWrite2(const unsigned int xid, struct cifs_io_parms *io_parms,
+ pSMB->hdr.PidHigh = cpu_to_le16((__u16)(pid >> 16));
+
+ /* tcon and ses pointer are checked in smb_init */
+- if (tcon->ses->server == NULL)
++ if (!tcon->ses->server) {
++ cifs_small_buf_release(pSMB);
+ return -ECONNABORTED;
++ }
+
+ pSMB->AndXCommand = 0xFF; /* none */
+ pSMB->Fid = netfid;
+diff --git a/fs/smb/client/misc.c b/fs/smb/client/misc.c
+index 85e615ed7ca915..ddf105336f6607 100644
+--- a/fs/smb/client/misc.c
++++ b/fs/smb/client/misc.c
+@@ -913,6 +913,8 @@ parse_dfs_referrals(struct get_dfs_referral_rsp *rsp, u32 rsp_size,
+ int i, rc = 0;
+ char *data_end;
+ struct dfs_referral_level_3 *ref;
++ unsigned int path_consumed;
++ size_t search_name_len;
+
+ if (rsp_size < sizeof(*rsp)) {
+ cifs_dbg(VFS | ONCE,
+@@ -960,6 +962,7 @@ parse_dfs_referrals(struct get_dfs_referral_rsp *rsp, u32 rsp_size,
+ rc = -ENOMEM;
+ goto parse_DFS_referrals_exit;
+ }
++ search_name_len = strlen(searchName);
+
+ /* collect necessary data from referrals */
+ for (i = 0; i < *num_of_nodes; i++) {
+@@ -968,21 +971,34 @@ parse_dfs_referrals(struct get_dfs_referral_rsp *rsp, u32 rsp_size,
+ struct dfs_info3_param *node = (*target_nodes)+i;
+
+ node->flags = le32_to_cpu(rsp->DFSFlags);
++ path_consumed = le16_to_cpu(rsp->PathConsumed);
+ if (is_unicode) {
+- __le16 *tmp = kmalloc(strlen(searchName)*2 + 2,
+- GFP_KERNEL);
+- if (tmp == NULL) {
++ size_t search_name_utf16_len = search_name_len * 2 + 2;
++ __le16 *tmp;
++
++ if (path_consumed > search_name_utf16_len) {
++ rc = -EINVAL;
++ goto parse_DFS_referrals_exit;
++ }
++
++ tmp = kmalloc(search_name_utf16_len, GFP_KERNEL);
++ if (!tmp) {
+ rc = -ENOMEM;
+ goto parse_DFS_referrals_exit;
+ }
+- cifsConvertToUTF16((__le16 *) tmp, searchName,
++ cifsConvertToUTF16((__le16 *)tmp, searchName,
+ PATH_MAX, nls_codepage, remap);
+- node->path_consumed = cifs_utf16_bytes(tmp,
+- le16_to_cpu(rsp->PathConsumed),
+- nls_codepage);
++ node->path_consumed = cifs_utf16_bytes(tmp, path_consumed,
++ nls_codepage);
+ kfree(tmp);
+- } else
+- node->path_consumed = le16_to_cpu(rsp->PathConsumed);
++ } else {
++ if (path_consumed > search_name_len) {
++ rc = -EINVAL;
++ goto parse_DFS_referrals_exit;
++ }
++
++ node->path_consumed = path_consumed;
++ }
+
+ node->server_type = le16_to_cpu(ref->ServerType);
+ node->ref_flag = le16_to_cpu(ref->ReferralEntryFlags);
+diff --git a/fs/smb/client/sess.c b/fs/smb/client/sess.c
+index 41174b9dc7343d..ffeb3e7d34d5ca 100644
+--- a/fs/smb/client/sess.c
++++ b/fs/smb/client/sess.c
+@@ -247,9 +247,9 @@ int cifs_try_adding_channels(struct cifs_sb_info *cifs_sb, struct cifs_ses *ses)
+ cifs_dbg(VFS, "failed to open extra channel on iface:%pIS rc=%d\n",
+ &iface->sockaddr,
+ rc);
+- kref_put(&iface->refcount, release_iface);
+ /* failure to add chan should increase weight */
+ iface->weight_fulfilled++;
++ kref_put(&iface->refcount, release_iface);
+ continue;
+ }
+
+diff --git a/fs/smb/client/smb2ops.c b/fs/smb/client/smb2ops.c
+index a80c5f07fc718c..05b7b02a6b0352 100644
+--- a/fs/smb/client/smb2ops.c
++++ b/fs/smb/client/smb2ops.c
+@@ -3655,6 +3655,7 @@ static int smb3_simple_fallocate_range(unsigned int xid,
+ struct file_allocated_range_buffer in_data, *out_data = NULL, *tmp_data;
+ u32 out_data_len;
+ char *buf = NULL;
++ u64 range_start, range_len, range_end;
+ loff_t l;
+ int rc;
+
+@@ -3691,13 +3692,21 @@ static int smb3_simple_fallocate_range(unsigned int xid,
+ goto out;
+ }
+
+- if (off < le64_to_cpu(tmp_data->file_offset)) {
++ range_start = le64_to_cpu(tmp_data->file_offset);
++ range_len = le64_to_cpu(tmp_data->length);
++ if (check_add_overflow(range_start, range_len, &range_end) ||
++ range_end > S64_MAX) {
++ rc = -EINVAL;
++ goto out;
++ }
++
++ if (off < range_start) {
+ /*
+ * We are at a hole. Write until the end of the region
+ * or until the next allocated data,
+ * whichever comes next.
+ */
+- l = le64_to_cpu(tmp_data->file_offset) - off;
++ l = range_start - off;
+ if (len < l)
+ l = len;
+ rc = smb3_simple_fallocate_write_range(xid, tcon,
+@@ -3714,11 +3723,13 @@ static int smb3_simple_fallocate_range(unsigned int xid,
+ * until the end of the data or the end of the region
+ * we are supposed to fallocate, whichever comes first.
+ */
+- l = le64_to_cpu(tmp_data->length);
+- if (len < l)
+- l = len;
+- off += l;
+- len -= l;
++ if (off < range_end) {
++ l = range_end - off;
++ if (len < l)
++ l = len;
++ off += l;
++ len -= l;
++ }
+
+ tmp_data = &tmp_data[1];
+ out_data_len -= sizeof(struct file_allocated_range_buffer);
+diff --git a/fs/smb/server/smb2misc.c b/fs/smb/server/smb2misc.c
+index f257e096c8e17f..6a4f1b8a0b13c9 100644
+--- a/fs/smb/server/smb2misc.c
++++ b/fs/smb/server/smb2misc.c
+@@ -400,6 +400,11 @@ int ksmbd_smb2_check_message(struct ksmbd_work *work)
+ return 1;
+ }
+
++ if (len < __SMB2_HEADER_STRUCTURE_SIZE + sizeof(__le16)) {
++ ksmbd_debug(SMB, "Message is too small for StructureSize2\n");
++ return 1;
++ }
++
+ if (smb2_req_struct_sizes[command] != pdu->StructureSize2) {
+ if (!(command == SMB2_OPLOCK_BREAK_HE &&
+ (le16_to_cpu(pdu->StructureSize2) == OP_BREAK_STRUCT_SIZE_20 ||
+diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c
+index 8ea6d4ce3a1f13..147066ced4ee5e 100644
+--- a/fs/smb/server/smb2pdu.c
++++ b/fs/smb/server/smb2pdu.c
+@@ -1491,11 +1491,6 @@ static int ntlm_authenticate(struct ksmbd_work *work,
+ return -EPERM;
+ }
+
+- /* Check for previous session */
+- prev_id = le64_to_cpu(req->PreviousSessionId);
+- if (prev_id && prev_id != sess->id)
+- destroy_previous_session(conn, user, prev_id);
+-
+ if (sess->state == SMB2_SESSION_VALID) {
+ /*
+ * Reuse session if anonymous try to connect
+@@ -1533,6 +1528,10 @@ static int ntlm_authenticate(struct ksmbd_work *work,
+ }
+ }
+
++ prev_id = le64_to_cpu(req->PreviousSessionId);
++ if (prev_id && prev_id != sess->id)
++ destroy_previous_session(conn, sess->user, prev_id);
++
+ /*
+ * If session state is SMB2_SESSION_VALID, We can assume
+ * that it is reauthentication. And the user/password
+diff --git a/fs/smb/server/vfs_cache.c b/fs/smb/server/vfs_cache.c
+index 4911d1e325cd27..5b3a55bd700dc3 100644
+--- a/fs/smb/server/vfs_cache.c
++++ b/fs/smb/server/vfs_cache.c
+@@ -394,6 +394,7 @@ int ksmbd_close_fd(struct ksmbd_work *work, u64 id)
+ {
+ struct ksmbd_file *fp;
+ struct ksmbd_file_table *ft;
++ bool closed = false;
+
+ if (!has_file_id(id))
+ return 0;
+@@ -408,6 +409,9 @@ int ksmbd_close_fd(struct ksmbd_work *work, u64 id)
+ fp = NULL;
+ else {
+ fp->f_state = FP_CLOSED;
++ idr_remove(ft->idr, id);
++ fp->volatile_id = KSMBD_NO_FID;
++ closed = true;
+ if (!atomic_dec_and_test(&fp->refcount))
+ fp = NULL;
+ }
+@@ -415,7 +419,7 @@ int ksmbd_close_fd(struct ksmbd_work *work, u64 id)
+ write_unlock(&ft->lock);
+
+ if (!fp)
+- return -EINVAL;
++ return closed ? 0 : -EINVAL;
+
+ __put_fd_final(work, fp);
+ return 0;
+diff --git a/include/linux/dma/qcom_bam_dma.h b/include/linux/dma/qcom_bam_dma.h
+index 68fc0e643b1b97..d9d07a9ab31328 100644
+--- a/include/linux/dma/qcom_bam_dma.h
++++ b/include/linux/dma/qcom_bam_dma.h
+@@ -13,9 +13,12 @@
+ * supported by BAM DMA Engine.
+ *
+ * @cmd_and_addr - upper 8 bits command and lower 24 bits register address.
+- * @data - for write command: content to be written into peripheral register.
+- * for read command: dest addr to write peripheral register value.
+- * @mask - register mask.
++ * @data - For write command: content to be written into peripheral register.
++ * For read command: lower 32 bits of destination address.
++ * @mask - For write command: register write mask.
++ * For read command on BAM v1.6.0+: upper 4 bits of destination address.
++ * For read command on BAM < v1.6.0: ignored by hardware.
++ * Setting to 0 ensures 32-bit addressing compatibility.
+ * @reserved - for future usage.
+ *
+ */
+@@ -42,6 +45,10 @@ enum bam_command_type {
+ * @addr: target address
+ * @cmd: BAM command
+ * @data: actual data for write and dest addr for read in le32
++ *
++ * For BAM v1.6.0+, the mask field behavior depends on command type:
++ * - Write commands: mask = write mask (typically 0xffffffff)
++ * - Read commands: mask = upper 4 bits of destination address (0 for 32-bit)
+ */
+ static inline void
+ bam_prep_ce_le32(struct bam_cmd_element *bam_ce, u32 addr,
+@@ -50,7 +57,11 @@ bam_prep_ce_le32(struct bam_cmd_element *bam_ce, u32 addr,
+ bam_ce->cmd_and_addr =
+ cpu_to_le32((addr & 0xffffff) | ((cmd & 0xff) << 24));
+ bam_ce->data = data;
+- bam_ce->mask = cpu_to_le32(0xffffffff);
++ if (cmd == BAM_READ_COMMAND)
++ bam_ce->mask = cpu_to_le32(0x0); /* 32-bit addressing */
++ else
++ bam_ce->mask = cpu_to_le32(0xffffffff); /* Write mask */
++ bam_ce->reserved = 0;
+ }
+
+ /*
+@@ -60,7 +71,7 @@ bam_prep_ce_le32(struct bam_cmd_element *bam_ce, u32 addr,
+ * @bam_ce: BAM command element
+ * @addr: target address
+ * @cmd: BAM command
+- * @data: actual data for write and dest addr for read
++ * @data: actual data for write and destination address for read
+ */
+ static inline void
+ bam_prep_ce(struct bam_cmd_element *bam_ce, u32 addr,
+diff --git a/include/linux/filter.h b/include/linux/filter.h
+index 37260c48fad495..673aef4e1465af 100644
+--- a/include/linux/filter.h
++++ b/include/linux/filter.h
+@@ -21,6 +21,7 @@
+ #include <linux/vmalloc.h>
+ #include <linux/sockptr.h>
+ #include <crypto/sha1.h>
++#include <linux/static_call.h>
+ #include <linux/u64_stats_sync.h>
+
+ #include <net/sch_generic.h>
+@@ -1058,6 +1059,15 @@ extern long bpf_jit_limit_max;
+
+ typedef void (*bpf_jit_fill_hole_t)(void *area, unsigned int size);
+
++/*
++ * Flush the indirect branch predictors before reusing JIT memory, so that
++ * indirect jumps into a newly written program don't reuse predictions left
++ * behind by an old program that occupied the same space.
++ */
++void bpf_arch_pred_flush(void);
++DECLARE_STATIC_CALL(bpf_arch_pred_flush, bpf_arch_pred_flush);
++DECLARE_STATIC_KEY_FALSE(bpf_pred_flush_enabled);
++
+ void bpf_jit_fill_hole_with_zero(void *area, unsigned int size);
+
+ struct bpf_binary_header *
+@@ -1072,7 +1082,7 @@ void bpf_jit_free(struct bpf_prog *fp);
+ struct bpf_binary_header *
+ bpf_jit_binary_pack_hdr(const struct bpf_prog *fp);
+
+-void *bpf_prog_pack_alloc(u32 size, bpf_jit_fill_hole_t bpf_fill_ill_insns);
++void *bpf_prog_pack_alloc(u32 size, bpf_jit_fill_hole_t bpf_fill_ill_insns, bool was_classic);
+ void bpf_prog_pack_free(struct bpf_binary_header *hdr);
+
+ static inline bool bpf_prog_kallsyms_verify_off(const struct bpf_prog *fp)
+@@ -1086,7 +1096,8 @@ bpf_jit_binary_pack_alloc(unsigned int proglen, u8 **ro_image,
+ unsigned int alignment,
+ struct bpf_binary_header **rw_hdr,
+ u8 **rw_image,
+- bpf_jit_fill_hole_t bpf_fill_ill_insns);
++ bpf_jit_fill_hole_t bpf_fill_ill_insns,
++ bool was_classic);
+ int bpf_jit_binary_pack_finalize(struct bpf_prog *prog,
+ struct bpf_binary_header *ro_header,
+ struct bpf_binary_header *rw_header);
+diff --git a/include/linux/fscrypt.h b/include/linux/fscrypt.h
+index 4f5f8a65121328..fe842c9af9dcb8 100644
+--- a/include/linux/fscrypt.h
++++ b/include/linux/fscrypt.h
+@@ -57,6 +57,9 @@ struct fscrypt_name {
+ /* Maximum value for the third parameter of fscrypt_operations.set_context(). */
+ #define FSCRYPT_SET_CONTEXT_MAX_SIZE 40
+
++/* Maximum supported number of block devices per filesystem */
++#define FSCRYPT_MAX_DEVICES 8
++
+ #ifdef CONFIG_FS_ENCRYPTION
+
+ /*
+@@ -161,21 +164,20 @@ struct fscrypt_operations {
+ int *ino_bits_ret, int *lblk_bits_ret);
+
+ /*
+- * Return an array of pointers to the block devices to which the
+- * filesystem may write encrypted file contents, NULL if the filesystem
+- * only has a single such block device, or an ERR_PTR() on error.
++ * Retrieve the list of block devices to which the filesystem may write
++ * encrypted file contents.
+ *
+- * On successful non-NULL return, *num_devs is set to the number of
+- * devices in the returned array. The caller must free the returned
+- * array using kfree().
++ * This writes the block_device pointers to @devs and returns the count
++ * (between 1 and FSCRYPT_MAX_DEVICES inclusively).
+ *
+ * If the filesystem can use multiple block devices (other than block
+ * devices that aren't used for encrypted file contents, such as
+ * external journal devices), and wants to support inline encryption,
+ * then it must implement this function. Otherwise it's not needed.
+ */
+- struct block_device **(*get_devices)(struct super_block *sb,
+- unsigned int *num_devs);
++ unsigned int (*get_devices)(
++ struct super_block *sb,
++ struct block_device *devs[FSCRYPT_MAX_DEVICES]);
+ };
+
+ static inline struct fscrypt_info *fscrypt_get_info(const struct inode *inode)
+diff --git a/include/linux/netdevice.h b/include/linux/netdevice.h
+index e0df5fc6727901..5b2b19287dc1b8 100644
+--- a/include/linux/netdevice.h
++++ b/include/linux/netdevice.h
+@@ -3131,11 +3131,6 @@ static inline bool dev_validate_header(const struct net_device *dev,
+ if (len < dev->min_header_len)
+ return false;
+
+- if (capable(CAP_SYS_RAWIO)) {
+- memset(ll_header + len, 0, dev->hard_header_len - len);
+- return true;
+- }
+-
+ if (dev->header_ops && dev->header_ops->validate)
+ return dev->header_ops->validate(ll_header, len);
+
+diff --git a/include/linux/netfilter/ipset/ip_set.h b/include/linux/netfilter/ipset/ip_set.h
+index d82413e6098a70..b2ee80b4b0d39c 100644
+--- a/include/linux/netfilter/ipset/ip_set.h
++++ b/include/linux/netfilter/ipset/ip_set.h
+@@ -273,7 +273,7 @@ struct ip_set {
+ /* Number of elements (vs timeout) */
+ u32 elements;
+ /* Size of the dynamic extensions (vs timeout) */
+- size_t ext_size;
++ atomic64_t ext_size;
+ /* Element data size */
+ size_t dsize;
+ /* Offsets to extensions in elements */
+diff --git a/include/linux/netfilter/nf_conntrack_sip.h b/include/linux/netfilter/nf_conntrack_sip.h
+index dbc614dfe0d565..aafa0c04f917eb 100644
+--- a/include/linux/netfilter/nf_conntrack_sip.h
++++ b/include/linux/netfilter/nf_conntrack_sip.h
+@@ -115,7 +115,7 @@ struct nf_nat_sip_hooks {
+ unsigned int *datalen);
+
+ void (*seq_adjust)(struct sk_buff *skb,
+- unsigned int protoff, s16 off);
++ unsigned int protoff, s32 off);
+
+ unsigned int (*expect)(struct sk_buff *skb,
+ unsigned int protoff,
+diff --git a/include/linux/ppp_channel.h b/include/linux/ppp_channel.h
+index 45e6e427ceb8a0..f73fbea0dbc239 100644
+--- a/include/linux/ppp_channel.h
++++ b/include/linux/ppp_channel.h
+@@ -42,8 +42,7 @@ struct ppp_channel {
+ int hdrlen; /* amount of headroom channel needs */
+ void *ppp; /* opaque to channel */
+ int speed; /* transfer rate (bytes/second) */
+- /* the following is not used at present */
+- int latency; /* overhead time in milliseconds */
++ bool direct_xmit; /* no qdisc, xmit directly */
+ };
+
+ #ifdef __KERNEL__
+diff --git a/include/linux/regulator/consumer.h b/include/linux/regulator/consumer.h
+index 60bc7e143869b6..8d3afff87b6e33 100644
+--- a/include/linux/regulator/consumer.h
++++ b/include/linux/regulator/consumer.h
+@@ -209,6 +209,7 @@ struct regulator *__must_check devm_regulator_get_optional(struct device *dev,
+ const char *id);
+ int devm_regulator_get_enable(struct device *dev, const char *id);
+ int devm_regulator_get_enable_optional(struct device *dev, const char *id);
++int devm_regulator_get_enable_read_voltage(struct device *dev, const char *id);
+ void regulator_put(struct regulator *regulator);
+ void devm_regulator_put(struct regulator *regulator);
+
+@@ -372,6 +373,12 @@ static inline int devm_regulator_get_enable_optional(struct device *dev,
+ return 0;
+ }
+
++static inline int devm_regulator_get_enable_read_voltage(struct device *dev,
++ const char *id)
++{
++ return -ENODEV;
++}
++
+ static inline struct regulator *__must_check
+ regulator_get_optional(struct device *dev, const char *id)
+ {
+diff --git a/include/linux/seqlock.h b/include/linux/seqlock.h
+index 995f29dd545516..c5f5a988798418 100644
+--- a/include/linux/seqlock.h
++++ b/include/linux/seqlock.h
+@@ -1281,7 +1281,7 @@ struct ss_tmp {
+ spinlock_t *lock_irqsave;
+ };
+
+-static inline void __scoped_seqlock_cleanup(struct ss_tmp *sst)
++static __always_inline void __scoped_seqlock_cleanup(struct ss_tmp *sst)
+ {
+ if (sst->lock)
+ spin_unlock(sst->lock);
+@@ -1291,11 +1291,15 @@ static inline void __scoped_seqlock_cleanup(struct ss_tmp *sst)
+
+ extern void __scoped_seqlock_invalid_target(void);
+
+-#if defined(CONFIG_CC_IS_GCC) && CONFIG_GCC_VERSION < 90000
++#if (defined(CONFIG_CC_IS_GCC) && CONFIG_GCC_VERSION < 90000) || \
++ defined(CONFIG_KASAN) || defined(CONFIG_UBSAN_ALIGNMENT)
+ /*
+ * For some reason some GCC-8 architectures (nios2, alpha) have trouble
+ * determining that the ss_done state is impossible in __scoped_seqlock_next()
+ * below.
++ *
++ * Similarly KASAN and UBSAN_ALIGNMENT are known to confuse compilers enough
++ * to break this. But we don't care about code quality for such builds anyway.
+ */
+ static inline void __scoped_seqlock_bug(void) { }
+ #else
+@@ -1306,7 +1310,7 @@ static inline void __scoped_seqlock_bug(void) { }
+ extern void __scoped_seqlock_bug(void);
+ #endif
+
+-static inline void
++static __always_inline void
+ __scoped_seqlock_next(struct ss_tmp *sst, seqlock_t *lock, enum ss_state target)
+ {
+ switch (sst->state) {
+diff --git a/include/media/videobuf2-core.h b/include/media/videobuf2-core.h
+index 3253bd2f6feed5..bae2710e8c4554 100644
+--- a/include/media/videobuf2-core.h
++++ b/include/media/videobuf2-core.h
+@@ -1050,8 +1050,8 @@ __poll_t vb2_core_poll(struct vb2_queue *q, struct file *file,
+ * @ppos: file handle position tracking pointer
+ * @nonblock: mode selector (1 means blocking calls, 0 means nonblocking)
+ */
+-size_t vb2_read(struct vb2_queue *q, char __user *data, size_t count,
+- loff_t *ppos, int nonblock);
++ssize_t vb2_read(struct vb2_queue *q, char __user *data, size_t count,
++ loff_t *ppos, int nonblock);
+ /**
+ * vb2_write() - implements write() syscall logic.
+ * @q: pointer to &struct vb2_queue with videobuf2 queue.
+@@ -1060,8 +1060,8 @@ size_t vb2_read(struct vb2_queue *q, char __user *data, size_t count,
+ * @ppos: file handle position tracking pointer
+ * @nonblock: mode selector (1 means blocking calls, 0 means nonblocking)
+ */
+-size_t vb2_write(struct vb2_queue *q, const char __user *data, size_t count,
+- loff_t *ppos, int nonblock);
++ssize_t vb2_write(struct vb2_queue *q, const char __user *data, size_t count,
++ loff_t *ppos, int nonblock);
+
+ /**
+ * typedef vb2_thread_fnc - callback function for use with vb2_thread.
+diff --git a/include/net/act_api.h b/include/net/act_api.h
+index 55e3b5ec1d92d8..fe213da14d2a94 100644
+--- a/include/net/act_api.h
++++ b/include/net/act_api.h
+@@ -267,6 +267,25 @@ int tcf_action_check_ctrlact(int action, struct tcf_proto *tp,
+ struct tcf_chain *tcf_action_set_ctrlact(struct tc_action *a, int action,
+ struct tcf_chain *newchain);
+
++/* Range check for a control action supplied by user space.
++ *
++ * This is the same test tcf_action_check_ctrlact() applies to the primary
++ * control action, factored out for the *fallback* control actions
++ * (act_gact's TCA_GACT_PROB.paction and act_police's TCA_POLICE_RESULT),
++ * which must not reach tcf_action_check_ctrlact() because they have no
++ * goto_chain to allocate. Without it, user space can store kernel-internal
++ * verdicts such as TC_ACT_CONSUMED, which is TC_ACT_VALUE_MAX + 1 and is
++ * deliberately not part of the UAPI value range.
++ */
++static inline bool tcf_action_valid(int action)
++{
++ int opcode = TC_ACT_EXT_OPCODE(action);
++
++ if (!opcode)
++ return action <= TC_ACT_VALUE_MAX;
++ return opcode <= TC_ACT_EXT_OPCODE_MAX || action == TC_ACT_UNSPEC;
++}
++
+ #ifdef CONFIG_INET
+ DECLARE_STATIC_KEY_FALSE(tcf_frag_xmit_count);
+ #endif
+diff --git a/include/net/addrconf.h b/include/net/addrconf.h
+index 95c08ed65a90f3..1363f88eb11e0c 100644
+--- a/include/net/addrconf.h
++++ b/include/net/addrconf.h
+@@ -370,8 +370,8 @@ static inline struct inet6_dev *in6_dev_get(const struct net_device *dev)
+
+ rcu_read_lock();
+ idev = rcu_dereference(dev->ip6_ptr);
+- if (idev)
+- refcount_inc(&idev->refcnt);
++ if (idev && !refcount_inc_not_zero(&idev->refcnt))
++ idev = NULL;
+ rcu_read_unlock();
+ return idev;
+ }
+diff --git a/include/net/af_unix.h b/include/net/af_unix.h
+index b1f82d74339ef1..339d41d9a58679 100644
+--- a/include/net/af_unix.h
++++ b/include/net/af_unix.h
+@@ -23,6 +23,7 @@ void unix_del_edges(struct scm_fp_list *fpl);
+ void unix_update_edges(struct unix_sock *receiver);
+ int unix_prepare_fpl(struct scm_fp_list *fpl);
+ void unix_destroy_fpl(struct scm_fp_list *fpl);
++void unix_peek_fpl(struct scm_fp_list *fpl);
+ void unix_gc(void);
+ void wait_for_unix_gc(struct scm_fp_list *fpl);
+
+diff --git a/include/net/bluetooth/hci_core.h b/include/net/bluetooth/hci_core.h
+index e67b1e5e0d2c8f..76764d399b23ef 100644
+--- a/include/net/bluetooth/hci_core.h
++++ b/include/net/bluetooth/hci_core.h
+@@ -1069,6 +1069,24 @@ static inline unsigned int hci_conn_count(struct hci_dev *hdev)
+ return c->acl_num + c->amp_num + c->sco_num + c->le_num + c->iso_num;
+ }
+
++static inline bool hci_conn_valid(struct hci_dev *hdev, struct hci_conn *conn)
++{
++ struct hci_conn_hash *h = &hdev->conn_hash;
++ struct hci_conn *c;
++
++ rcu_read_lock();
++
++ list_for_each_entry_rcu(c, &h->list, list) {
++ if (c == conn) {
++ rcu_read_unlock();
++ return true;
++ }
++ }
++ rcu_read_unlock();
++
++ return false;
++}
++
+ static inline __u8 hci_conn_lookup_type(struct hci_dev *hdev, __u16 handle)
+ {
+ struct hci_conn_hash *h = &hdev->conn_hash;
+diff --git a/include/net/bluetooth/l2cap.h b/include/net/bluetooth/l2cap.h
+index 97ad02840530e3..ba230c3cf43155 100644
+--- a/include/net/bluetooth/l2cap.h
++++ b/include/net/bluetooth/l2cap.h
+@@ -743,6 +743,7 @@ enum {
+ FLAG_ECRED_CONN_REQ_SENT,
+ FLAG_PENDING_SECURITY,
+ FLAG_HOLD_HCI_CONN,
++ FLAG_DEL,
+ };
+
+ /* Lock nesting levels for L2CAP channels. We need these because lockdep
+diff --git a/include/net/bluetooth/rfcomm.h b/include/net/bluetooth/rfcomm.h
+index 99d26879b02a53..ba8d3702853d25 100644
+--- a/include/net/bluetooth/rfcomm.h
++++ b/include/net/bluetooth/rfcomm.h
+@@ -229,6 +229,9 @@ int rfcomm_send_rpn(struct rfcomm_session *s, int cr, u8 dlci,
+ u8 bit_rate, u8 data_bits, u8 stop_bits,
+ u8 parity, u8 flow_ctrl_settings,
+ u8 xon_char, u8 xoff_char, u16 param_mask);
++int rfcomm_dlc_send_rpn(struct rfcomm_dlc *d, u8 bit_rate, u8 data_bits,
++ u8 stop_bits, u8 parity, u8 flow_ctrl_settings,
++ u8 xon_char, u8 xoff_char, u16 param_mask);
+
+ /* ---- RFCOMM DLCs (channels) ---- */
+ struct rfcomm_dlc *rfcomm_dlc_alloc(gfp_t prio);
+diff --git a/include/net/ip6_fib.h b/include/net/ip6_fib.h
+index fa4e6af382e2ad..ef38ee0912e1a8 100644
+--- a/include/net/ip6_fib.h
++++ b/include/net/ip6_fib.h
+@@ -240,9 +240,11 @@ struct fib6_result {
+ for (rt = (w)->leaf; rt; \
+ rt = rcu_dereference_protected(rt->fib6_next, 1))
+
+-static inline struct inet6_dev *ip6_dst_idev(struct dst_entry *dst)
++#define dst_rt6_info(_ptr) container_of_const(_ptr, struct rt6_info, dst)
++
++static inline struct inet6_dev *ip6_dst_idev(const struct dst_entry *dst)
+ {
+- return ((struct rt6_info *)dst)->rt6i_idev;
++ return dst_rt6_info(dst)->rt6i_idev;
+ }
+
+ static inline bool fib6_requires_src(const struct fib6_info *rt)
+diff --git a/include/net/ip6_route.h b/include/net/ip6_route.h
+index 4cd0839c86c92e..7c0184c09392fb 100644
+--- a/include/net/ip6_route.h
++++ b/include/net/ip6_route.h
+@@ -222,12 +222,11 @@ void rt6_uncached_list_del(struct rt6_info *rt);
+ static inline const struct rt6_info *skb_rt6_info(const struct sk_buff *skb)
+ {
+ const struct dst_entry *dst = skb_dst(skb);
+- const struct rt6_info *rt6 = NULL;
+
+ if (dst)
+- rt6 = container_of(dst, struct rt6_info, dst);
++ return dst_rt6_info(dst);
+
+- return rt6;
++ return NULL;
+ }
+
+ /*
+@@ -239,7 +238,7 @@ static inline void ip6_dst_store(struct sock *sk, struct dst_entry *dst,
+ {
+ struct ipv6_pinfo *np = inet6_sk(sk);
+
+- np->dst_cookie = rt6_get_cookie((struct rt6_info *)dst);
++ np->dst_cookie = rt6_get_cookie(dst_rt6_info(dst));
+ sk_setup_caps(sk, dst);
+ np->daddr_cache = daddr;
+ #ifdef CONFIG_IPV6_SUBTREES
+@@ -252,7 +251,7 @@ void ip6_sk_dst_store_flow(struct sock *sk, struct dst_entry *dst,
+
+ static inline bool ipv6_unicast_destination(const struct sk_buff *skb)
+ {
+- struct rt6_info *rt = (struct rt6_info *) skb_dst(skb);
++ const struct rt6_info *rt = dst_rt6_info(skb_dst(skb));
+
+ return rt->rt6i_flags & RTF_LOCAL;
+ }
+@@ -260,7 +259,7 @@ static inline bool ipv6_unicast_destination(const struct sk_buff *skb)
+ static inline bool ipv6_anycast_destination(const struct dst_entry *dst,
+ const struct in6_addr *daddr)
+ {
+- struct rt6_info *rt = (struct rt6_info *)dst;
++ const struct rt6_info *rt = dst_rt6_info(dst);
+
+ return rt->rt6i_flags & RTF_ANYCAST ||
+ (rt->rt6i_dst.plen < 127 &&
+diff --git a/include/net/ip_vs.h b/include/net/ip_vs.h
+index 35961160ebdec1..9a229aeed75f6f 100644
+--- a/include/net/ip_vs.h
++++ b/include/net/ip_vs.h
+@@ -675,10 +675,11 @@ struct ip_vs_dest {
+
+ /* connection counters and thresholds */
+ atomic_t activeconns; /* active connections */
+- atomic_t inactconns; /* inactive connections */
++ atomic_t totalconns; /* total connections */
+ atomic_t persistconns; /* persistent connections */
+ __u32 u_threshold; /* upper threshold */
+ __u32 l_threshold; /* lower threshold */
++ __u32 l_threshold_val;/* used lower threshold */
+
+ /* for destination cache */
+ spinlock_t dst_lock; /* lock of dst_cache */
+@@ -1468,6 +1469,8 @@ static inline void ip_vs_dest_put_and_free(struct ip_vs_dest *dest)
+ kfree(dest);
+ }
+
++void ip_vs_dest_update_overload(struct ip_vs_dest *dest, int mode);
++
+ /* IPVS sync daemon data and function prototypes
+ * (from ip_vs_sync.c)
+ */
+@@ -1494,8 +1497,8 @@ int ip_vs_tunnel_xmit(struct sk_buff *skb, struct ip_vs_conn *cp,
+ int ip_vs_dr_xmit(struct sk_buff *skb, struct ip_vs_conn *cp,
+ struct ip_vs_protocol *pp, struct ip_vs_iphdr *iph);
+ int ip_vs_icmp_xmit(struct sk_buff *skb, struct ip_vs_conn *cp,
+- struct ip_vs_protocol *pp, int offset,
+- unsigned int hooknum, struct ip_vs_iphdr *iph);
++ struct ip_vs_protocol *pp, unsigned int toff,
++ unsigned int hooknum, struct ip_vs_iphdr *ciph);
+ void ip_vs_dest_dst_rcu_free(struct rcu_head *head);
+
+ #ifdef CONFIG_IP_VS_IPV6
+@@ -1508,8 +1511,8 @@ int ip_vs_tunnel_xmit_v6(struct sk_buff *skb, struct ip_vs_conn *cp,
+ int ip_vs_dr_xmit_v6(struct sk_buff *skb, struct ip_vs_conn *cp,
+ struct ip_vs_protocol *pp, struct ip_vs_iphdr *iph);
+ int ip_vs_icmp_xmit_v6(struct sk_buff *skb, struct ip_vs_conn *cp,
+- struct ip_vs_protocol *pp, int offset,
+- unsigned int hooknum, struct ip_vs_iphdr *iph);
++ struct ip_vs_protocol *pp, unsigned int toff,
++ unsigned int hooknum, struct ip_vs_iphdr *ciph);
+ #endif
+
+ #ifdef CONFIG_SYSCTL
+@@ -1574,15 +1577,15 @@ static inline char ip_vs_fwd_tag(struct ip_vs_conn *cp)
+ }
+
+ void ip_vs_nat_icmp(struct sk_buff *skb, struct ip_vs_protocol *pp,
+- struct ip_vs_conn *cp, int dir);
++ struct ip_vs_conn *cp, int dir, unsigned int toff,
++ bool has_ports, struct ip_vs_iphdr *ciph);
+
+ #ifdef CONFIG_IP_VS_IPV6
+ void ip_vs_nat_icmp_v6(struct sk_buff *skb, struct ip_vs_protocol *pp,
+- struct ip_vs_conn *cp, int dir);
++ struct ip_vs_conn *cp, int dir, unsigned int toff,
++ bool has_ports, struct ip_vs_iphdr *ciph);
+ #endif
+
+-__sum16 ip_vs_checksum_complete(struct sk_buff *skb, int offset);
+-
+ static inline __wsum ip_vs_check_diff4(__be32 old, __be32 new, __wsum oldsum)
+ {
+ __be32 diff[2] = { ~old, new };
+@@ -1608,6 +1611,26 @@ static inline __wsum ip_vs_check_diff2(__be16 old, __be16 new, __wsum oldsum)
+ return csum_partial(diff, sizeof(diff), oldsum);
+ }
+
++static inline bool ip_vs_checksum_needed(struct sk_buff *skb)
++{
++ /* Checksum unnecessary or already validated? */
++ if (skb_csum_unnecessary(skb))
++ return false;
++ /* Locally generated ? */
++ if (!skb->dev)
++ return false;
++ return true;
++}
++
++static inline bool ip_vs_checksum_common_check(struct sk_buff *skb,
++ int offset, int proto, int af)
++{
++ if (!ip_vs_checksum_needed(skb))
++ return true;
++ /* Validate csum even for FORWARD */
++ return !nf_checksum(skb, NF_INET_LOCAL_IN, offset, proto, af);
++}
++
+ /* Forget current conntrack (unconfirmed) and attach notrack entry */
+ static inline void ip_vs_notrack(struct sk_buff *skb)
+ {
+@@ -1715,14 +1738,21 @@ void ip_vs_unregister_hooks(struct netns_ipvs *ipvs, unsigned int af);
+ static inline int
+ ip_vs_dest_conn_overhead(struct ip_vs_dest *dest)
+ {
+- /* We think the overhead of processing active connections is 256
++ /* We think the overhead of processing active connections is 257
+ * times higher than that of inactive connections in average. (This
+- * 256 times might not be accurate, we will change it later) We
++ * 257 times might not be accurate, we will change it later) We
+ * use the following formula to estimate the overhead now:
+- * dest->activeconns*256 + dest->inactconns
++ * dest->activeconns*256 + dest->totalconns
+ */
+ return (atomic_read(&dest->activeconns) << 8) +
+- atomic_read(&dest->inactconns);
++ atomic_read(&dest->totalconns);
++}
++
++static inline int
++ip_vs_dest_inactconns(const struct ip_vs_dest *dest)
++{
++ return max(atomic_read(&dest->totalconns) -
++ atomic_read(&dest->activeconns), 0);
+ }
+
+ #ifdef CONFIG_IP_VS_PROTO_TCP
+diff --git a/include/net/neighbour.h b/include/net/neighbour.h
+index 93aecfaa7628a7..b8b385a2a31c10 100644
+--- a/include/net/neighbour.h
++++ b/include/net/neighbour.h
+@@ -478,11 +478,15 @@ static inline int neigh_event_send(struct neighbour *neigh, struct sk_buff *skb)
+ #if IS_ENABLED(CONFIG_BRIDGE_NETFILTER)
+ static inline int neigh_hh_bridge(struct hh_cache *hh, struct sk_buff *skb)
+ {
+- unsigned int seq, hh_alen;
++ unsigned int seq, hh_alen = HH_DATA_ALIGN(ETH_HLEN);
++ int err;
++
++ err = skb_cow_head(skb, hh_alen);
++ if (err)
++ return err;
+
+ do {
+ seq = read_seqbegin(&hh->hh_lock);
+- hh_alen = HH_DATA_ALIGN(ETH_HLEN);
+ memcpy(skb->data - hh_alen, hh->hh_data, ETH_ALEN + hh_alen - ETH_HLEN);
+ } while (read_seqretry(&hh->hh_lock, seq));
+ return 0;
+diff --git a/include/net/netfilter/nf_conntrack_expect.h b/include/net/netfilter/nf_conntrack_expect.h
+index e9a8350e7ccfb0..80f50fd0f7ad27 100644
+--- a/include/net/netfilter/nf_conntrack_expect.h
++++ b/include/net/netfilter/nf_conntrack_expect.h
+@@ -45,9 +45,12 @@ struct nf_conntrack_expect {
+ void (*expectfn)(struct nf_conn *new,
+ struct nf_conntrack_expect *this);
+
+- /* Helper to assign to new connection */
++ /* Helper that created this expectation */
+ struct nf_conntrack_helper __rcu *helper;
+
++ /* Helper to assign to new connection */
++ struct nf_conntrack_helper __rcu *assign_helper;
++
+ /* The conntrack of the master connection */
+ struct nf_conn *master;
+
+diff --git a/include/net/route.h b/include/net/route.h
+index 568da3b95b06eb..4fa45dda2bb325 100644
+--- a/include/net/route.h
++++ b/include/net/route.h
+@@ -247,6 +247,8 @@ int fib_dump_info_fnhe(struct sk_buff *skb, struct netlink_callback *cb,
+ u32 table_id, struct fib_info *fi,
+ int *fa_index, int fa_start, unsigned int flags);
+
++void fnhe_update_pmtu(struct fib_nh_exception *fnhe, u32 new, u32 orig);
++
+ static inline void ip_rt_put(struct rtable *rt)
+ {
+ /* dst_release() accepts a NULL parameter.
+diff --git a/include/net/sch_generic.h b/include/net/sch_generic.h
+index c5df4b7fe820c9..a0499bff7ff40d 100644
+--- a/include/net/sch_generic.h
++++ b/include/net/sch_generic.h
+@@ -100,6 +100,7 @@ struct Qdisc {
+ struct hlist_node hash;
+ u32 handle;
+ u32 parent;
++ int depth;
+
+ struct netdev_queue *dev_queue;
+
+diff --git a/include/net/sctp/structs.h b/include/net/sctp/structs.h
+index 8995914916ca6e..cef44fa66fb36b 100644
+--- a/include/net/sctp/structs.h
++++ b/include/net/sctp/structs.h
+@@ -322,7 +322,8 @@ struct sctp_cookie {
+
+ __u8 auth_random[sizeof(struct sctp_paramhdr) +
+ SCTP_AUTH_RANDOM_LENGTH];
+- __u8 auth_hmacs[SCTP_AUTH_NUM_HMACS * sizeof(__u16) + 2];
++ __u8 auth_hmacs[sizeof(struct sctp_paramhdr) +
++ SCTP_AUTH_NUM_HMACS * sizeof(__u16)];
+ __u8 auth_chunks[sizeof(struct sctp_paramhdr) + SCTP_AUTH_MAX_CHUNKS];
+
+ /* This is a shim for my peer's INIT packet, followed by
+diff --git a/include/scsi/libsas.h b/include/scsi/libsas.h
+index 9e9dff75a02bc0..7165d3aee11768 100644
+--- a/include/scsi/libsas.h
++++ b/include/scsi/libsas.h
+@@ -346,11 +346,6 @@ struct asd_sas_phy {
+ void *lldd_phy; /* not touched by the sas_class_code */
+ };
+
+-struct scsi_core {
+- struct Scsi_Host *shost;
+-
+-};
+-
+ enum sas_ha_state {
+ SAS_HA_REGISTERED,
+ SAS_HA_DRAINING,
+@@ -371,7 +366,7 @@ struct sas_ha_struct {
+
+ struct mutex disco_mutex;
+
+- struct scsi_core core;
++ struct Scsi_Host *shost;
+
+ /* public: */
+ char *sas_ha_name;
+@@ -708,7 +703,6 @@ extern int sas_register_ha(struct sas_ha_struct *);
+ extern int sas_unregister_ha(struct sas_ha_struct *);
+ extern void sas_prep_resume_ha(struct sas_ha_struct *sas_ha);
+ extern void sas_resume_ha(struct sas_ha_struct *sas_ha);
+-extern void sas_resume_ha_no_sync(struct sas_ha_struct *sas_ha);
+ extern void sas_suspend_ha(struct sas_ha_struct *sas_ha);
+
+ int sas_set_phy_speed(struct sas_phy *phy, struct sas_phy_linkrates *rates);
+diff --git a/include/uapi/linux/btrfs.h b/include/uapi/linux/btrfs.h
+index 24b54635bae90f..7b9e199de89286 100644
+--- a/include/uapi/linux/btrfs.h
++++ b/include/uapi/linux/btrfs.h
+@@ -568,7 +568,7 @@ struct btrfs_ioctl_search_args_v2 {
+ __u64 buf_size; /* in - size of buffer
+ * out - on EOVERFLOW: needed size
+ * to store item */
+- __u64 buf[]; /* out - found items */
++ __u8 buf[]; /* out - found items */
+ };
+
+ struct btrfs_ioctl_clone_range_args {
+diff --git a/io_uring/rw.c b/io_uring/rw.c
+index b75f62dccce6c9..cbd3ee9a9373a3 100644
+--- a/io_uring/rw.c
++++ b/io_uring/rw.c
+@@ -129,27 +129,37 @@ void io_readv_writev_cleanup(struct io_kiocb *req)
+ kfree(io->free_iovec);
+ }
+
+-static inline void io_rw_done(struct kiocb *kiocb, ssize_t ret)
++static inline ssize_t io_fixup_restart_res(ssize_t ret)
+ {
+ switch (ret) {
+- case -EIOCBQUEUED:
+- break;
+ case -ERESTARTSYS:
+ case -ERESTARTNOINTR:
+ case -ERESTARTNOHAND:
+ case -ERESTART_RESTARTBLOCK:
+ /*
+ * We can't just restart the syscall, since previously
+- * submitted sqes may already be in progress. Just fail this
+- * IO with EINTR.
++ * submitted sqes may already be in progress. Just fail
++ * this IO with EINTR.
+ */
+- ret = -EINTR;
+- fallthrough;
++ return -EINTR;
+ default:
+- kiocb->ki_complete(kiocb, ret);
++ return ret;
+ }
+ }
+
++static inline void io_rw_done(struct kiocb *kiocb, ssize_t ret)
++{
++ /* IO was queued async, completion will happen later */
++ if (ret == -EIOCBQUEUED)
++ return;
++
++ /* transform internal restart error codes */
++ if (unlikely(ret < 0))
++ ret = io_fixup_restart_res(ret);
++
++ kiocb->ki_complete(kiocb, ret);
++}
++
+ static inline loff_t *io_kiocb_update_pos(struct io_kiocb *req)
+ {
+ struct io_rw *rw = io_kiocb_to_cmd(req, struct io_rw);
+@@ -854,7 +864,7 @@ int io_read(struct io_kiocb *req, unsigned int issue_flags)
+ if (ret >= 0)
+ return kiocb_done(req, ret, issue_flags);
+
+- return ret;
++ return io_fixup_restart_res(ret);
+ }
+
+ static bool io_kiocb_start_write(struct io_kiocb *req, struct kiocb *kiocb)
+diff --git a/kernel/audit.c b/kernel/audit.c
+index 72f28cbad8a6c9..97b41d73eb69a3 100644
+--- a/kernel/audit.c
++++ b/kernel/audit.c
+@@ -2075,7 +2075,8 @@ void audit_log_n_hex(struct audit_buffer *ab, const unsigned char *buf,
+ void audit_log_n_string(struct audit_buffer *ab, const char *string,
+ size_t slen)
+ {
+- int avail, new_len;
++ int avail;
++ size_t new_len;
+ unsigned char *ptr;
+ struct sk_buff *skb;
+
+@@ -2085,7 +2086,13 @@ void audit_log_n_string(struct audit_buffer *ab, const char *string,
+ BUG_ON(!ab->skb);
+ skb = ab->skb;
+ avail = skb_tailroom(skb);
+- new_len = slen + 3; /* enclosing quotes + null terminator */
++
++ /* enclosing quotes + null terminator */
++ if (check_add_overflow(slen, 3, &new_len)) {
++ audit_log_format(ab, "?");
++ return;
++ }
++
+ if (new_len > avail) {
+ avail = audit_expand(ab, new_len);
+ if (!avail)
+diff --git a/kernel/auditfilter.c b/kernel/auditfilter.c
+index 6c9a4d322309f2..9eeac3ee16a903 100644
+--- a/kernel/auditfilter.c
++++ b/kernel/auditfilter.c
+@@ -1045,6 +1045,10 @@ int audit_del_rule(struct audit_entry *entry)
+ goto out;
+ }
+
++ list_del_rcu(&e->list);
++ list_del(&e->rule.list);
++ synchronize_rcu();
++
+ if (e->rule.watch)
+ audit_remove_watch_rule(&e->rule);
+
+@@ -1062,8 +1066,6 @@ int audit_del_rule(struct audit_entry *entry)
+ audit_signals--;
+ #endif
+
+- list_del_rcu(&e->list);
+- list_del(&e->rule.list);
+ call_rcu(&e->rcu, audit_free_rule_rcu);
+
+ out:
+diff --git a/kernel/bpf/bpf_lsm.c b/kernel/bpf/bpf_lsm.c
+index 4bb8c363c0bfde..61e93253b6b5e7 100644
+--- a/kernel/bpf/bpf_lsm.c
++++ b/kernel/bpf/bpf_lsm.c
+@@ -42,7 +42,6 @@ BTF_ID(func, bpf_lsm_inode_need_killpriv)
+ BTF_ID(func, bpf_lsm_inode_getsecurity)
+ BTF_ID(func, bpf_lsm_inode_listsecurity)
+ BTF_ID(func, bpf_lsm_inode_copy_up_xattr)
+-BTF_ID(func, bpf_lsm_getselfattr)
+ BTF_ID(func, bpf_lsm_getprocattr)
+ BTF_ID(func, bpf_lsm_setprocattr)
+ #ifdef CONFIG_KEYS
+diff --git a/kernel/bpf/core.c b/kernel/bpf/core.c
+index 77044d4a80cc16..4ea21434bf78e6 100644
+--- a/kernel/bpf/core.c
++++ b/kernel/bpf/core.c
+@@ -35,6 +35,7 @@
+ #include <linux/bpf_verifier.h>
+ #include <linux/nodemask.h>
+ #include <linux/nospec.h>
++#include <linux/static_call.h>
+
+ #include <asm/barrier.h>
+ #include <asm/unaligned.h>
+@@ -844,6 +845,7 @@ int bpf_jit_add_poke_descriptor(struct bpf_prog *prog,
+ struct bpf_prog_pack {
+ struct list_head list;
+ void *ptr;
++ bool arch_flush_needed;
+ unsigned long bitmap[];
+ };
+
+@@ -852,6 +854,15 @@ void bpf_jit_fill_hole_with_zero(void *area, unsigned int size)
+ memset(area, 0, size);
+ }
+
++DEFINE_STATIC_CALL_NULL(bpf_arch_pred_flush, bpf_arch_pred_flush);
++
++/*
++ * Enabled once bpf_arch_pred_flush points at a real flush routine. Lets the
++ * pack allocator test "is a predictor flush wired up at all" with a cheap
++ * static branch instead of repeatedly querying the static call target.
++ */
++DEFINE_STATIC_KEY_FALSE(bpf_pred_flush_enabled);
++
+ #define BPF_PROG_SIZE_TO_NBITS(size) (round_up(size, BPF_PROG_CHUNK_SIZE) / BPF_PROG_CHUNK_SIZE)
+
+ static DEFINE_MUTEX(pack_mutex);
+@@ -890,21 +901,31 @@ static struct bpf_prog_pack *alloc_new_pack(bpf_jit_fill_hole_t bpf_fill_ill_ins
+ bitmap_zero(pack->bitmap, BPF_PROG_PACK_SIZE / BPF_PROG_CHUNK_SIZE);
+ list_add_tail(&pack->list, &pack_list);
+
++ if (static_branch_unlikely(&bpf_pred_flush_enabled))
++ pack->arch_flush_needed = true;
+ set_vm_flush_reset_perms(pack->ptr);
+ set_memory_ro((unsigned long)pack->ptr, BPF_PROG_PACK_SIZE / PAGE_SIZE);
+ set_memory_x((unsigned long)pack->ptr, BPF_PROG_PACK_SIZE / PAGE_SIZE);
+ return pack;
+ }
+
+-void *bpf_prog_pack_alloc(u32 size, bpf_jit_fill_hole_t bpf_fill_ill_insns)
++void *bpf_prog_pack_alloc(u32 size, bpf_jit_fill_hole_t bpf_fill_ill_insns, bool was_classic)
+ {
+ unsigned int nbits = BPF_PROG_SIZE_TO_NBITS(size);
+- struct bpf_prog_pack *pack;
+- unsigned long pos;
++ struct bpf_prog_pack *pack, *fallback_pack = NULL;
++ unsigned long pos, fallback_pos = 0;
+ void *ptr = NULL;
+
+ mutex_lock(&pack_mutex);
+ if (size > BPF_PROG_PACK_SIZE) {
++ /*
++ * Allocations larger than a pack get their own pages, and
++ * predictors are not flushed for such allocation. This is only
++ * safe because cBPF programs (the unprivileged attack surface)
++ * are bounded well below a pack size.
++ */
++ if (was_classic && static_branch_unlikely(&bpf_pred_flush_enabled))
++ pr_warn_once("BPF: Predictors not flushed for allocations greater than BPF_PROG_PACK_SIZE\n");
+ size = round_up(size, PAGE_SIZE);
+ ptr = module_alloc(size);
+ if (ptr) {
+@@ -918,8 +939,29 @@ void *bpf_prog_pack_alloc(u32 size, bpf_jit_fill_hole_t bpf_fill_ill_insns)
+ list_for_each_entry(pack, &pack_list, list) {
+ pos = bitmap_find_next_zero_area(pack->bitmap, BPF_PROG_CHUNK_COUNT, 0,
+ nbits, 0);
+- if (pos < BPF_PROG_CHUNK_COUNT)
++ if (pos >= BPF_PROG_CHUNK_COUNT)
++ continue;
++ /* Flush not enabled, use any pack */
++ if (!static_branch_unlikely(&bpf_pred_flush_enabled))
+ goto found_free_area;
++ /*
++ * cBPF reuse of a dirty pack triggers a flush, so prefer a
++ * clean pack for cBPF. eBPF never flushes, so steer it to a
++ * dirty pack and keep clean packs free for cBPF.
++ */
++ if (was_classic ^ pack->arch_flush_needed)
++ goto found_free_area;
++ if (!fallback_pack) {
++ fallback_pack = pack;
++ fallback_pos = pos;
++ }
++ }
++
++ /* No preferred pack found */
++ if (fallback_pack) {
++ pack = fallback_pack;
++ pos = fallback_pos;
++ goto found_free_area;
+ }
+
+ pack = alloc_new_pack(bpf_fill_ill_insns);
+@@ -929,6 +971,16 @@ void *bpf_prog_pack_alloc(u32 size, bpf_jit_fill_hole_t bpf_fill_ill_insns)
+ pos = 0;
+
+ found_free_area:
++ /* Flush only for cBPF as it may contain a crafted gadget */
++ if (static_branch_unlikely(&bpf_pred_flush_enabled) &&
++ pack->arch_flush_needed &&
++ was_classic) {
++ struct bpf_prog_pack *p;
++
++ static_call_cond(bpf_arch_pred_flush)();
++ list_for_each_entry(p, &pack_list, list)
++ p->arch_flush_needed = false;
++ }
+ bitmap_set(pack->bitmap, pos, nbits);
+ ptr = (void *)(pack->ptr) + (pos << BPF_PROG_CHUNK_SHIFT);
+
+@@ -966,6 +1018,9 @@ void bpf_prog_pack_free(struct bpf_binary_header *hdr)
+ "bpf_prog_pack bug: missing bpf_arch_text_invalidate?\n");
+
+ bitmap_clear(pack->bitmap, pos, nbits);
++
++ if (static_branch_unlikely(&bpf_pred_flush_enabled))
++ pack->arch_flush_needed = true;
+ if (bitmap_find_next_zero_area(pack->bitmap, BPF_PROG_CHUNK_COUNT, 0,
+ BPF_PROG_CHUNK_COUNT, 0) == 0) {
+ list_del(&pack->list);
+@@ -1088,7 +1143,8 @@ bpf_jit_binary_pack_alloc(unsigned int proglen, u8 **image_ptr,
+ unsigned int alignment,
+ struct bpf_binary_header **rw_header,
+ u8 **rw_image,
+- bpf_jit_fill_hole_t bpf_fill_ill_insns)
++ bpf_jit_fill_hole_t bpf_fill_ill_insns,
++ bool was_classic)
+ {
+ struct bpf_binary_header *ro_header;
+ u32 size, hole, start;
+@@ -1101,7 +1157,7 @@ bpf_jit_binary_pack_alloc(unsigned int proglen, u8 **image_ptr,
+
+ if (bpf_jit_charge_modmem(size))
+ return NULL;
+- ro_header = bpf_prog_pack_alloc(size, bpf_fill_ill_insns);
++ ro_header = bpf_prog_pack_alloc(size, bpf_fill_ill_insns, was_classic);
+ if (!ro_header) {
+ bpf_jit_uncharge_modmem(size);
+ return NULL;
+diff --git a/kernel/bpf/dispatcher.c b/kernel/bpf/dispatcher.c
+index fa3e9225aedc0a..b3f164e31c6bb4 100644
+--- a/kernel/bpf/dispatcher.c
++++ b/kernel/bpf/dispatcher.c
+@@ -145,7 +145,7 @@ void bpf_dispatcher_change_prog(struct bpf_dispatcher *d, struct bpf_prog *from,
+
+ mutex_lock(&d->mutex);
+ if (!d->image) {
+- d->image = bpf_prog_pack_alloc(PAGE_SIZE, bpf_jit_fill_hole_with_zero);
++ d->image = bpf_prog_pack_alloc(PAGE_SIZE, bpf_jit_fill_hole_with_zero, false);
+ if (!d->image)
+ goto out;
+ d->rw_image = bpf_jit_alloc_exec(PAGE_SIZE);
+diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
+index 4380082f321c7a..abb62b3e4f8734 100644
+--- a/kernel/bpf/verifier.c
++++ b/kernel/bpf/verifier.c
+@@ -8491,11 +8491,12 @@ static int adjust_ptr_min_max_vals(struct bpf_verifier_env *env,
+ break;
+ }
+
+- /* In case of 'scalar += pointer', dst_reg inherits pointer type and id.
+- * The id may be overwritten later if we create a new variable offset.
++ /* For 'scalar += pointer', dst_reg inherits the complete pointer
++ * register state. Individual fields may be adjusted later by pointer
++ * arithmetic. Callers guarantee that below does not overwrite off_reg.
+ */
+- dst_reg->type = ptr_reg->type;
+- dst_reg->id = ptr_reg->id;
++ if (dst_reg != ptr_reg)
++ *dst_reg = *ptr_reg;
+
+ if (!check_reg_sane_offset(env, off_reg, ptr_reg->type) ||
+ !check_reg_sane_offset(env, ptr_reg, ptr_reg->type))
+@@ -8563,7 +8564,7 @@ static int adjust_ptr_min_max_vals(struct bpf_verifier_env *env,
+ }
+ break;
+ case BPF_SUB:
+- if (dst_reg == off_reg) {
++ if (dst_reg != ptr_reg) {
+ /* scalar -= pointer. Creates an unknown scalar */
+ verbose(env, "R%d tried to subtract pointer from scalar\n",
+ dst);
+@@ -9422,8 +9423,8 @@ static int adjust_reg_min_max_vals(struct bpf_verifier_env *env,
+ err = mark_chain_precision(env, insn->dst_reg);
+ if (err)
+ return err;
+- return adjust_ptr_min_max_vals(env, insn,
+- src_reg, dst_reg);
++ off_reg = *dst_reg;
++ return adjust_ptr_min_max_vals(env, insn, src_reg, &off_reg);
+ }
+ } else if (ptr_reg) {
+ /* pointer += scalar */
+@@ -10751,6 +10752,23 @@ static int check_ld_abs(struct bpf_verifier_env *env, struct bpf_insn *insn)
+ mark_reg_unknown(env, regs, BPF_REG_0);
+ /* ld_abs load up to 32-bit skb data. */
+ regs[BPF_REG_0].subreg_def = env->insn_idx + 1;
++ /*
++ * See bpf_gen_ld_abs() which emits a hidden BPF_EXIT with r0=0
++ * which must be explored by the verifier when in a subprog.
++ */
++ if (env->cur_state->curframe) {
++ struct bpf_verifier_state *branch;
++
++ mark_reg_scratched(env, BPF_REG_0);
++ branch = push_stack(env, env->insn_idx + 1, env->insn_idx, false);
++ if (!branch)
++ return -EFAULT;
++ mark_reg_known_zero(env, regs, BPF_REG_0);
++ err = prepare_func_exit(env, &env->insn_idx);
++ if (err)
++ return err;
++ env->insn_idx--;
++ }
+ return 0;
+ }
+
+diff --git a/kernel/futex/core.c b/kernel/futex/core.c
+index d4141b05471873..b370fdea7c2179 100644
+--- a/kernel/futex/core.c
++++ b/kernel/futex/core.c
+@@ -660,8 +660,11 @@ retry:
+ return -1;
+
+ /*
+- * Special case for regular (non PI) futexes. The unlock path in
+- * user space has two race scenarios:
++ * Special case for regular (non PI) futexes. Ordinarily, we do
++ * not perform any processing here unless the current thread was
++ * the owner of the futex (by the TID check below).
++ *
++ * However, the unlock path has three race scenarios:
+ *
+ * 1. The unlock path releases the user space futex value and
+ * before it can execute the futex() syscall to wake up
+@@ -670,41 +673,68 @@ retry:
+ * 2. A woken up waiter is killed before it can acquire the
+ * futex in user space.
+ *
+- * In the second case, the wake up notification could be generated
+- * by the unlock path in user space after setting the futex value
+- * to zero or by the kernel after setting the OWNER_DIED bit below.
++ * 3. A woken up waiter is killed in user space after another
++ * thread has acquired the futex, but before it can set
++ * FUTEX_WAITERS.
++ *
++ * Note that, if userspace uses the FUTEX_ROBUST_UNLOCK flag, we
++ * will not see case 1 here.
++ *
++ * In the second and third case, the wake up notification could
++ * be generated from any of:
++ *
++ * i. An ordinary futex wakeup after unlock (with or
++ * without FUTEX_ROBUST_UNLOCK)
++ * ii. A robust wakeup from another thread's death
++ * iii. A previous round through this special case
++ *
++ * As a result, the futex world will be in one of four states:
+ *
+- * In both cases the TID validation below prevents a wakeup of
+- * potential waiters which can cause these waiters to block
+- * forever.
++ * A. The futex word is 0 (unlocked)
++ * B. The futex word is owned by another thread
++ * (FUTEX_WAITERS is not set)
++ * C. The futex word is owned by another thread
++ * (FUTEX_WAITERS set)
++ * D. The futex's owner died and OWNER_DIED is set
++ * (the owner part of the word is 0)
+ *
+- * In both cases the following conditions are met:
++ * The key issue is that the kernel usually (at least from
++ * sources ii. and iii. or when so requested by userspace from
++ * source i.) only ever wakes *one* waiter at a time. If this
++ * waiter dies before acquiring the futex (or setting the
++ * FUTEX_WAITERS bit), the kernel *must* still wake the next
++ * waiter down the line to uphold the futex invariants and
++ * avoid lost wakeups. Note we do not need to handle state C,
++ * as it does not matter to us whether *we* successfully set
++ * the bit or a third thread did so in the meantime.
+ *
+- * 1) task->robust_list->list_op_pending != NULL
+- * @pending_op == true
+- * 2) The owner part of user space futex value == 0
++ * Therefore, in these cases we must issue an additional
++ * futex_wake(). Note however that we *must not* set OWNER_DIED
++ * here. Our thread is *not* the owner of the futex.
++ *
++ * Thus to summarize, the conditions for needing the additional
++ * futex_wake() are:
++ *
++ * 1) @pending_op == true (the thread has not finished the
++ * mutex operation)
++ * 2) The futex word is in one of the states A, B or D
+ * 3) Regular futex: @pi == false
+ *
+- * If these conditions are met, it is safe to attempt waking up a
+- * potential waiter without touching the user space futex value and
+- * trying to set the OWNER_DIED bit. If the futex value is zero,
+- * the rest of the user space mutex state is consistent, so a woken
+- * waiter will just take over the uncontended futex. Setting the
+- * OWNER_DIED bit would create inconsistent state and malfunction
+- * of the user space owner died handling. Otherwise, the OWNER_DIED
+- * bit is already set, and the woken waiter is expected to deal with
+- * this.
++ * Note in particular that in all of the states A-D the owner
++ * portion of the futex word differs from our thread's TID
++ * (unless the actual owner has the same TID in another PID
++ * namespace, but we cannot currently distinguish that
++ * scenario), so this can be a special-case wakeup in the bail
++ * path of the ordinary TID check.
+ */
+ owner = uval & FUTEX_TID_MASK;
+
+- if (pending_op && !pi && !owner) {
+- futex_wake(uaddr, 1, 1, FUTEX_BITSET_MATCH_ANY);
++ if (owner != task_pid_vnr(curr)) {
++ if (pending_op && !pi && (!owner || !(uval & FUTEX_WAITERS)))
++ futex_wake(uaddr, 1, 1, FUTEX_BITSET_MATCH_ANY);
+ return 0;
+ }
+
+- if (owner != task_pid_vnr(curr))
+- return 0;
+-
+ /*
+ * Ok, this dying thread is truly holding a futex
+ * of interest. Set the OWNER_DIED bit atomically
+diff --git a/kernel/sched/psi.c b/kernel/sched/psi.c
+index fb56fcce29cd7a..5294ba4664c606 100644
+--- a/kernel/sched/psi.c
++++ b/kernel/sched/psi.c
+@@ -1134,6 +1134,12 @@ void psi_cgroup_free(struct cgroup *cgroup)
+ return;
+
+ cancel_delayed_work_sync(&cgroup->psi->avgs_work);
++ /*
++ * A psi_schedule_rtpoll_work() call racing the last trigger's
++ * destruction may have re-armed the timer after psi_trigger_destroy()
++ * deleted it. Spurious firing while the group is alive is harmless.
++ */
++ timer_shutdown_sync(&cgroup->psi->rtpoll_timer);
+ free_percpu(cgroup->psi->pcpu);
+ /* All triggers must be removed by now */
+ WARN_ONCE(cgroup->psi->rtpoll_states, "psi: trigger leak\n");
+diff --git a/kernel/trace/ftrace.c b/kernel/trace/ftrace.c
+index 7217b872ff4ff8..574e516654b885 100644
+--- a/kernel/trace/ftrace.c
++++ b/kernel/trace/ftrace.c
+@@ -1036,6 +1036,12 @@ struct ftrace_ops global_ops = {
+ FTRACE_OPS_FL_PID,
+ };
+
++/*
++ * parser_lock - Protects trace_parser state against concurrent operations.
++ * Held across trace_get_user() and subsequent buffer parsing to prevent races.
++ */
++static DEFINE_MUTEX(parser_lock);
++
+ /*
+ * Used by the stack unwinder to know about dynamic ftrace trampolines.
+ */
+@@ -5077,6 +5083,8 @@ ftrace_regex_write(struct file *file, const char __user *ubuf,
+ /* iter->hash is a local copy, so we don't need regex_lock */
+
+ parser = &iter->parser;
++
++ guard(mutex)(&parser_lock);
+ read = trace_get_user(parser, ubuf, cnt, ppos);
+
+ if (read >= 0 && trace_parser_loaded(parser) &&
+@@ -6129,12 +6137,14 @@ int ftrace_regex_release(struct inode *inode, struct file *file)
+ iter = file->private_data;
+
+ parser = &iter->parser;
++ mutex_lock(&parser_lock);
+ if (trace_parser_loaded(parser)) {
+ int enable = !(iter->flags & FTRACE_ITER_NOTRACE);
+
+ ftrace_process_regex(iter, parser->buffer,
+ parser->idx, enable);
+ }
++ mutex_unlock(&parser_lock);
+
+ trace_parser_put(parser);
+
+@@ -6452,10 +6462,12 @@ ftrace_graph_release(struct inode *inode, struct file *file)
+
+ parser = &fgd->parser;
+
++ mutex_lock(&parser_lock);
+ if (trace_parser_loaded((parser))) {
+ ret = ftrace_graph_set_hash(fgd->new_hash,
+ parser->buffer);
+ }
++ mutex_unlock(&parser_lock);
+
+ trace_parser_put(parser);
+
+@@ -6575,6 +6587,7 @@ ftrace_graph_write(struct file *file, const char __user *ubuf,
+
+ parser = &fgd->parser;
+
++ guard(mutex)(&parser_lock);
+ read = trace_get_user(parser, ubuf, cnt, ppos);
+
+ if (read >= 0 && trace_parser_loaded(parser) &&
+diff --git a/kernel/trace/ring_buffer.c b/kernel/trace/ring_buffer.c
+index 089c49f17398e5..3c64ec64c27e9e 100644
+--- a/kernel/trace/ring_buffer.c
++++ b/kernel/trace/ring_buffer.c
+@@ -6089,7 +6089,7 @@ static __init int test_ringbuffer(void)
+
+ out_free:
+ for_each_online_cpu(cpu) {
+- if (!rb_threads[cpu])
++ if (IS_ERR_OR_NULL(rb_threads[cpu]))
+ break;
+ kthread_stop(rb_threads[cpu]);
+ }
+diff --git a/kernel/trace/trace_eprobe.c b/kernel/trace/trace_eprobe.c
+index 66ad0b70c6c17d..2c98e831808c0e 100644
+--- a/kernel/trace/trace_eprobe.c
++++ b/kernel/trace/trace_eprobe.c
+@@ -164,7 +164,8 @@ static bool eprobe_dyn_event_match(const char *system, const char *event,
+ if (!slash)
+ return false;
+
+- if (strncmp(ep->event_system, argv[0], slash - argv[0]))
++ if (strncmp(ep->event_system, argv[0], slash - argv[0]) ||
++ ep->event_system[slash - argv[0]] != '\0')
+ return false;
+ if (strcmp(ep->event_name, slash + 1))
+ return false;
+diff --git a/kernel/trace/trace_events.c b/kernel/trace/trace_events.c
+index c4c900b69f0610..d7e059c202e619 100644
+--- a/kernel/trace/trace_events.c
++++ b/kernel/trace/trace_events.c
+@@ -2904,6 +2904,7 @@ void trace_event_eval_update(struct trace_eval_map **map, int len)
+ int last_i;
+ int i;
+
++ mutex_lock(&event_mutex);
+ down_write(&trace_event_sem);
+ list_for_each_entry_safe(call, p, &ftrace_events, list) {
+ /* events are usually grouped together with systems */
+@@ -2937,6 +2938,7 @@ void trace_event_eval_update(struct trace_eval_map **map, int len)
+ cond_resched();
+ }
+ up_write(&trace_event_sem);
++ mutex_unlock(&event_mutex);
+ }
+
+ static struct trace_event_file *
+@@ -3122,8 +3124,8 @@ static void trace_module_add_events(struct module *mod)
+ end = mod->trace_events + mod->num_trace_events;
+
+ for_each_event(call, start, end) {
+- __register_event(*call, mod);
+- __add_event_to_tracers(*call);
++ if (!__register_event(*call, mod))
++ __add_event_to_tracers(*call);
+ }
+ }
+
+diff --git a/kernel/trace/trace_events_filter.c b/kernel/trace/trace_events_filter.c
+index 560a7d71ebfcc2..7e3cb495406c8b 100644
+--- a/kernel/trace/trace_events_filter.c
++++ b/kernel/trace/trace_events_filter.c
+@@ -894,6 +894,9 @@ static int regex_match_full(char *str, struct regex *r, int len)
+ if (!len)
+ return strcmp(str, r->pattern) == 0;
+
++ if (len < r->len)
++ return 0;
++
+ return strncmp(str, r->pattern, len) == 0;
+ }
+
+diff --git a/kernel/trace/trace_mmiotrace.c b/kernel/trace/trace_mmiotrace.c
+index 64e77b51369748..c523ce5aa4958e 100644
+--- a/kernel/trace/trace_mmiotrace.c
++++ b/kernel/trace/trace_mmiotrace.c
+@@ -29,6 +29,7 @@ static void mmio_reset_data(struct trace_array *tr)
+ {
+ overrun_detected = false;
+ prev_overruns = 0;
++ atomic_set(&dropped_count, 0);
+
+ tracing_reset_online_cpus(&tr->array_buffer);
+ }
+@@ -109,7 +110,6 @@ static void mmio_pipe_open(struct trace_iterator *iter)
+ iter->private = hiter;
+ }
+
+-/* XXX: This is not called when the pipe is closed! */
+ static void mmio_close(struct trace_iterator *iter)
+ {
+ struct header_iter *hiter = iter->private;
+@@ -146,7 +146,7 @@ static ssize_t mmio_read(struct trace_iterator *iter, struct file *filp,
+ goto print_out;
+ }
+
+- if (!hiter)
++ if (!hiter || !hiter->dev)
+ return 0;
+
+ mmio_print_pcidev(s, hiter->dev);
+@@ -279,6 +279,7 @@ static struct tracer mmio_tracer __read_mostly =
+ .start = mmio_trace_start,
+ .pipe_open = mmio_pipe_open,
+ .close = mmio_close,
++ .pipe_close = mmio_close,
+ .read = mmio_read,
+ .print_line = mmio_print_line,
+ .noboot = true,
+diff --git a/kernel/trace/trace_probe.c b/kernel/trace/trace_probe.c
+index 125111d310d1ba..e394c90540f283 100644
+--- a/kernel/trace/trace_probe.c
++++ b/kernel/trace/trace_probe.c
+@@ -176,7 +176,7 @@ void __trace_probe_log_err(int offset, int err_type)
+
+ lockdep_assert_held(&dyn_event_ops_mutex);
+
+- if (!trace_probe_log.argv)
++ if (!trace_probe_log.argv || !trace_probe_log.argc)
+ return;
+
+ /* Recalculate the length and allocate buffer */
+@@ -900,7 +900,7 @@ int traceprobe_update_arg(struct probe_arg *arg)
+ }
+
+ /* When len=0, we just calculate the needed length */
+-#define LEN_OR_ZERO (len ? len - pos : 0)
++#define LEN_OR_ZERO (len > pos ? len - pos : 0)
+ static int __set_print_fmt(struct trace_probe *tp, char *buf, int len,
+ enum probe_print_type ptype)
+ {
+@@ -1215,16 +1215,17 @@ int trace_probe_compare_arg_type(struct trace_probe *a, struct trace_probe *b)
+ bool trace_probe_match_command_args(struct trace_probe *tp,
+ int argc, const char **argv)
+ {
+- char buf[MAX_ARGSTR_LEN + 1];
+ int i;
+
+ if (tp->nr_args < argc)
+ return false;
+
+ for (i = 0; i < argc; i++) {
+- snprintf(buf, sizeof(buf), "%s=%s",
+- tp->args[i].name, tp->args[i].comm);
+- if (strcmp(buf, argv[i]))
++ int len = strlen(tp->args[i].name);
++
++ if (strncmp(argv[i], tp->args[i].name, len) ||
++ argv[i][len] != '=' ||
++ strcmp(argv[i] + len + 1, tp->args[i].comm))
+ return false;
+ }
+ return true;
+diff --git a/lib/.gitignore b/lib/.gitignore
+index 54596b634ecbff..101a4aa92fb537 100644
+--- a/lib/.gitignore
++++ b/lib/.gitignore
+@@ -5,5 +5,3 @@
+ /gen_crc32table
+ /gen_crc64table
+ /oid_registry_data.c
+-/test_fortify.log
+-/test_fortify/*.log
+diff --git a/lib/Makefile b/lib/Makefile
+index 6ae66e13f31943..1081d0c1611599 100644
+--- a/lib/Makefile
++++ b/lib/Makefile
+@@ -394,36 +394,4 @@ CFLAGS_longest_symbol_kunit.o += $(call cc-disable-warning, missing-prototypes)
+
+ obj-$(CONFIG_GENERIC_LIB_DEVMEM_IS_ALLOWED) += devmem_is_allowed.o
+
+-# FORTIFY_SOURCE compile-time behavior tests
+-TEST_FORTIFY_SRCS = $(wildcard $(srctree)/$(src)/test_fortify/*-*.c)
+-TEST_FORTIFY_LOGS = $(patsubst $(srctree)/$(src)/%.c, %.log, $(TEST_FORTIFY_SRCS))
+-TEST_FORTIFY_LOG = test_fortify.log
+-
+-quiet_cmd_test_fortify = TEST $@
+- cmd_test_fortify = $(CONFIG_SHELL) $(srctree)/scripts/test_fortify.sh \
+- $< $@ "$(NM)" $(CC) $(c_flags) \
+- $(call cc-disable-warning,fortify-source) \
+- -DKBUILD_EXTRA_WARN1
+-
+-targets += $(TEST_FORTIFY_LOGS)
+-clean-files += $(TEST_FORTIFY_LOGS)
+-clean-files += $(addsuffix .o, $(TEST_FORTIFY_LOGS))
+-$(obj)/test_fortify/%.log: $(src)/test_fortify/%.c \
+- $(src)/test_fortify/test_fortify.h \
+- $(srctree)/include/linux/fortify-string.h \
+- $(srctree)/scripts/test_fortify.sh \
+- FORCE
+- $(call if_changed,test_fortify)
+-
+-quiet_cmd_gen_fortify_log = GEN $@
+- cmd_gen_fortify_log = cat </dev/null $(filter-out FORCE,$^) 2>/dev/null > $@ || true
+-
+-targets += $(TEST_FORTIFY_LOG)
+-clean-files += $(TEST_FORTIFY_LOG)
+-$(obj)/$(TEST_FORTIFY_LOG): $(addprefix $(obj)/, $(TEST_FORTIFY_LOGS)) FORCE
+- $(call if_changed,gen_fortify_log)
+-
+-# Fake dependency to trigger the fortify tests.
+-ifeq ($(CONFIG_FORTIFY_SOURCE),y)
+-$(obj)/string.o: $(obj)/$(TEST_FORTIFY_LOG)
+-endif
++subdir-$(CONFIG_FORTIFY_SOURCE) += test_fortify
+diff --git a/lib/assoc_array.c b/lib/assoc_array.c
+index ca0b4f360c1a0b..65409f0d2e0e5f 100644
+--- a/lib/assoc_array.c
++++ b/lib/assoc_array.c
+@@ -255,7 +255,8 @@ follow_shortcut:
+ sc_segments = shortcut->index_key[sc_level >> ASSOC_ARRAY_KEY_CHUNK_SHIFT];
+ dissimilarity = segments ^ sc_segments;
+
+- if (round_up(sc_level, ASSOC_ARRAY_KEY_CHUNK_SIZE) > shortcut->skip_to_level) {
++ if (shortcut->skip_to_level < round_down(sc_level,
++ ASSOC_ARRAY_KEY_CHUNK_SIZE) + ASSOC_ARRAY_KEY_CHUNK_SIZE) {
+ /* Trim segments that are beyond the shortcut */
+ int shift = shortcut->skip_to_level & ASSOC_ARRAY_KEY_CHUNK_MASK;
+ dissimilarity &= ~(ULONG_MAX << shift);
+diff --git a/lib/rhashtable.c b/lib/rhashtable.c
+index e12bbfb240b812..c977468291ea0a 100644
+--- a/lib/rhashtable.c
++++ b/lib/rhashtable.c
+@@ -730,6 +730,7 @@ int rhashtable_walk_start_check(struct rhashtable_iter *iter)
+ iter->walker.tbl = rht_dereference_rcu(ht->tbl, ht);
+ iter->slot = 0;
+ iter->skip = 0;
++ iter->p = NULL;
+ return -EAGAIN;
+ }
+
+diff --git a/lib/test_fortify/.gitignore b/lib/test_fortify/.gitignore
+new file mode 100644
+index 00000000000000..c1ba37d14b50e3
+--- /dev/null
++++ b/lib/test_fortify/.gitignore
+@@ -0,0 +1,2 @@
++# SPDX-License-Identifier: GPL-2.0-only
++/*.log
+diff --git a/lib/test_fortify/Makefile b/lib/test_fortify/Makefile
+new file mode 100644
+index 00000000000000..eba2ba0faeb6a4
+--- /dev/null
++++ b/lib/test_fortify/Makefile
+@@ -0,0 +1,29 @@
++# SPDX-License-Identifier: GPL-2.0
++
++ccflags-y := $(call cc-disable-warning,fortify-source)
++ccflags-y += $(call cc-disable-warning,stringop-overread)
++
++quiet_cmd_test_fortify = TEST $@
++ cmd_test_fortify = $(CONFIG_SHELL) $(srctree)/scripts/test_fortify.sh \
++ $< $@ "$(NM)" $(CC) $(c_flags) -DKBUILD_EXTRA_WARN1
++
++$(obj)/%.log: $(src)/%.c $(srctree)/scripts/test_fortify.sh \
++ $(src)/test_fortify.h \
++ $(srctree)/include/linux/fortify-string.h \
++ FORCE
++ $(call if_changed,test_fortify)
++
++logs = $(patsubst $(srctree)/$(src)/%.c, %.log, $(wildcard $(srctree)/$(src)/*-*.c))
++targets += $(logs)
++
++quiet_cmd_gen_fortify_log = CAT $@
++ cmd_gen_fortify_log = cat $(or $(real-prereqs),/dev/null) > $@
++
++$(obj)/test_fortify.log: $(addprefix $(obj)/, $(logs)) FORCE
++ $(call if_changed,gen_fortify_log)
++
++always-y += test_fortify.log
++
++# Some architectures define __NO_FORTIFY if __SANITIZE_ADDRESS__ is undefined.
++# Pass CFLAGS_KASAN to avoid warnings.
++KASAN_SANITIZE := y
+diff --git a/mm/damon/core.c b/mm/damon/core.c
+index 4b434ebd37c538..dd4eafe8b96112 100644
+--- a/mm/damon/core.c
++++ b/mm/damon/core.c
+@@ -210,8 +210,21 @@ int damon_set_regions(struct damon_target *t, struct damon_addr_range *ranges,
+ {
+ struct damon_region *r, *next;
+ unsigned int i;
++ unsigned long last_end;
+ int err;
+
++ for (i = 0; i < nr_ranges; i++) {
++ unsigned long start, end;
++
++ start = ALIGN_DOWN(ranges[i].start, DAMON_MIN_REGION);
++ end = ALIGN(ranges[i].end, DAMON_MIN_REGION);
++ if (start >= end)
++ return -EINVAL;
++ if (i > 0 && last_end > start)
++ return -EINVAL;
++ last_end = end;
++ }
++
+ /* Remove regions which are not in the new ranges */
+ damon_for_each_region_safe(r, next, t) {
+ for (i = 0; i < nr_ranges; i++) {
+diff --git a/mm/huge_memory.c b/mm/huge_memory.c
+index 7023bdf4896055..153f06e42866ce 100644
+--- a/mm/huge_memory.c
++++ b/mm/huge_memory.c
+@@ -2516,7 +2516,7 @@ static void __split_huge_page_tail(struct page *head, int tail,
+ }
+
+ static void __split_huge_page(struct page *page, struct list_head *list,
+- pgoff_t end)
++ pgoff_t end, struct address_space *mapping)
+ {
+ struct folio *folio = page_folio(page);
+ struct page *head = &folio->page;
+@@ -2594,6 +2594,16 @@ static void __split_huge_page(struct page *page, struct list_head *list,
+ split_swap_cluster(entry);
+ }
+
++ /*
++ * Drop the mapping while the head page is still locked and thus pins
++ * the inode. The loop below may free the after-split subpages --
++ * including the head, when @page is a tail beyond EOF that the split
++ * dropped from the page cache -- which could otherwise let the inode,
++ * and @mapping, be freed before this unlock.
++ */
++ if (mapping)
++ i_mmap_unlock_read(mapping);
++
+ for (i = 0; i < nr; i++) {
+ struct page *subpage = head + i;
+ if (subpage == page)
+@@ -2774,7 +2784,9 @@ int split_huge_page_to_list(struct page *page, struct list_head *list)
+ }
+ }
+
+- __split_huge_page(page, list, end);
++ __split_huge_page(page, list, end, mapping);
++ /* __split_huge_page() dropped the i_mmap lock */
++ mapping = NULL;
+ ret = 0;
+ } else {
+ spin_unlock(&ds_queue->split_queue_lock);
+diff --git a/mm/hugetlb.c b/mm/hugetlb.c
+index 74203552fec072..ffe5196b4afa63 100644
+--- a/mm/hugetlb.c
++++ b/mm/hugetlb.c
+@@ -679,7 +679,7 @@ static int allocate_file_region_entries(struct resv_map *resv,
+
+ spin_lock(&resv->lock);
+
+- list_splice(&allocated_regions, &resv->region_cache);
++ list_splice_init(&allocated_regions, &resv->region_cache);
+ resv->region_cache_count += to_allocate;
+ }
+
+@@ -5106,14 +5106,16 @@ again:
+ */
+ ;
+ } else if (unlikely(is_hugetlb_entry_hwpoisoned(entry))) {
+- bool uffd_wp = huge_pte_uffd_wp(entry);
+-
+- if (!userfaultfd_wp(dst_vma) && uffd_wp)
+- entry = huge_pte_clear_uffd_wp(entry);
++ /*
++ * A hwpoison entry never carries the uffd-wp bit: it is
++ * installed fresh by make_hwpoison_entry() and
++ * hugetlb_change_protection() leaves it untouched, so
++ * there is nothing to clear for the child.
++ */
+ set_huge_pte_at(dst, addr, dst_pte, entry);
+ } else if (unlikely(is_hugetlb_entry_migration(entry))) {
+ swp_entry_t swp_entry = pte_to_swp_entry(entry);
+- bool uffd_wp = huge_pte_uffd_wp(entry);
++ bool uffd_wp = pte_swp_uffd_wp(entry);
+
+ if (!is_readable_migration_entry(swp_entry) && cow) {
+ /*
+@@ -5124,11 +5126,11 @@ again:
+ swp_offset(swp_entry));
+ entry = swp_entry_to_pte(swp_entry);
+ if (userfaultfd_wp(src_vma) && uffd_wp)
+- entry = huge_pte_mkuffd_wp(entry);
++ entry = pte_swp_mkuffd_wp(entry);
+ set_huge_pte_at(src, addr, src_pte, entry);
+ }
+- if (!userfaultfd_wp(dst_vma) && uffd_wp)
+- entry = huge_pte_clear_uffd_wp(entry);
++ if (!userfaultfd_wp(dst_vma))
++ entry = pte_swp_clear_uffd_wp(entry);
+ set_huge_pte_at(dst, addr, dst_pte, entry);
+ } else if (unlikely(is_pte_marker(entry))) {
+ /*
+diff --git a/mm/page_reporting.c b/mm/page_reporting.c
+index 382958eef8a928..cf111a88d95c03 100644
+--- a/mm/page_reporting.c
++++ b/mm/page_reporting.c
+@@ -48,7 +48,8 @@ __page_reporting_request(struct page_reporting_dev_info *prdev)
+ * now we are limiting this to running no more than once every
+ * couple of seconds.
+ */
+- schedule_delayed_work(&prdev->work, PAGE_REPORTING_DELAY);
++ queue_delayed_work(system_freezable_wq, &prdev->work,
++ PAGE_REPORTING_DELAY);
+ }
+
+ /* notify prdev of free page reporting request */
+@@ -311,7 +312,8 @@ err_out:
+ */
+ state = atomic_cmpxchg(&prdev->state, state, PAGE_REPORTING_IDLE);
+ if (state == PAGE_REPORTING_REQUESTED)
+- schedule_delayed_work(&prdev->work, PAGE_REPORTING_DELAY);
++ queue_delayed_work(system_freezable_wq, &prdev->work,
++ PAGE_REPORTING_DELAY);
+ }
+
+ static DEFINE_MUTEX(page_reporting_mutex);
+diff --git a/mm/percpu-km.c b/mm/percpu-km.c
+index fe31aa19db81aa..86d31190524d42 100644
+--- a/mm/percpu-km.c
++++ b/mm/percpu-km.c
+@@ -75,7 +75,7 @@ static struct pcpu_chunk *pcpu_create_chunk(gfp_t gfp)
+ chunk->base_addr = page_address(pages);
+
+ spin_lock_irqsave(&pcpu_lock, flags);
+- pcpu_chunk_populated(chunk, 0, nr_pages);
++ pcpu_chunk_populated(chunk, 0, chunk->nr_pages);
+ spin_unlock_irqrestore(&pcpu_lock, flags);
+
+ pcpu_stats_chunk_alloc();
+diff --git a/net/atm/common.c b/net/atm/common.c
+index 96f680a45e306d..f3f68c231935aa 100644
+--- a/net/atm/common.c
++++ b/net/atm/common.c
+@@ -760,7 +760,7 @@ int vcc_setsockopt(struct socket *sock, int level, int optname,
+ sockptr_t optval, unsigned int optlen)
+ {
+ struct atm_vcc *vcc;
+- unsigned long value;
++ int value;
+ int error;
+
+ if (__SO_LEVEL_MATCH(optname, level) && optlen != __SO_SIZE(optname))
+@@ -772,8 +772,10 @@ int vcc_setsockopt(struct socket *sock, int level, int optname,
+ {
+ struct atm_qos qos;
+
+- if (copy_from_sockptr(&qos, optval, sizeof(qos)))
+- return -EFAULT;
++ error = copy_safe_from_sockptr(&qos, sizeof(qos), optval,
++ optlen);
++ if (error)
++ return error;
+ error = check_qos(&qos);
+ if (error)
+ return error;
+@@ -786,8 +788,10 @@ int vcc_setsockopt(struct socket *sock, int level, int optname,
+ return 0;
+ }
+ case SO_SETCLP:
+- if (copy_from_sockptr(&value, optval, sizeof(value)))
+- return -EFAULT;
++ error = copy_safe_from_sockptr(&value, sizeof(value), optval,
++ optlen);
++ if (error)
++ return error;
+ if (value)
+ vcc->atm_options |= ATM_ATMOPT_CLP;
+ else
+diff --git a/net/bluetooth/6lowpan.c b/net/bluetooth/6lowpan.c
+index c94e59b1f71335..723ead2c04f16a 100644
+--- a/net/bluetooth/6lowpan.c
++++ b/net/bluetooth/6lowpan.c
+@@ -140,7 +140,7 @@ static inline struct lowpan_peer *peer_lookup_dst(struct lowpan_btle_dev *dev,
+ struct in6_addr *daddr,
+ struct sk_buff *skb)
+ {
+- struct rt6_info *rt = (struct rt6_info *)skb_dst(skb);
++ struct rt6_info *rt = dst_rt6_info(skb_dst(skb));
+ int count = atomic_read(&dev->peer_count);
+ const struct in6_addr *nexthop;
+ struct lowpan_peer *peer;
+@@ -781,20 +781,10 @@ static void chan_close_cb(struct l2cap_chan *chan)
+ struct lowpan_btle_dev *dev = NULL;
+ struct lowpan_peer *peer;
+ int err = -ENOENT;
+- bool last = false, remove = true;
++ bool last = false;
+
+ BT_DBG("chan %p conn %p", chan, chan->conn);
+
+- if (chan->conn && chan->conn->hcon) {
+- if (!is_bt_6lowpan(chan->conn->hcon))
+- return;
+-
+- /* If conn is set, then the netdev is also there and we should
+- * not remove it.
+- */
+- remove = false;
+- }
+-
+ spin_lock(&devices_lock);
+
+ list_for_each_entry_rcu(entry, &bt_6lowpan_devices, list) {
+@@ -821,10 +811,8 @@ static void chan_close_cb(struct l2cap_chan *chan)
+
+ ifdown(dev->netdev);
+
+- if (remove) {
+- INIT_WORK(&entry->delete_netdev, delete_netdev);
+- schedule_work(&entry->delete_netdev);
+- }
++ INIT_WORK(&entry->delete_netdev, delete_netdev);
++ schedule_work(&entry->delete_netdev);
+ } else {
+ spin_unlock(&devices_lock);
+ }
+diff --git a/net/bluetooth/hci_conn.c b/net/bluetooth/hci_conn.c
+index 54cfcab7636380..aa5404412cbd34 100644
+--- a/net/bluetooth/hci_conn.c
++++ b/net/bluetooth/hci_conn.c
+@@ -2088,6 +2088,9 @@ static int create_big_sync(struct hci_dev *hdev, void *data)
+ u32 flags = 0;
+ int err;
+
++ if (!hci_conn_valid(hdev, conn))
++ return -ECANCELED;
++
+ if (qos->out.phy == 0x02)
+ flags |= MGMT_ADV_FLAG_SEC_2M;
+
+@@ -2194,11 +2197,24 @@ static void create_big_complete(struct hci_dev *hdev, void *data, int err)
+
+ bt_dev_dbg(hdev, "conn %p", conn);
+
++ if (err == -ECANCELED)
++ goto done;
++
++ hci_dev_lock(hdev);
++
++ if (!hci_conn_valid(hdev, conn))
++ goto unlock;
++
+ if (err) {
+ bt_dev_err(hdev, "Unable to create BIG: %d", err);
+ hci_connect_cfm(conn, err);
+ hci_conn_del(conn);
+ }
++
++unlock:
++ hci_dev_unlock(hdev);
++done:
++ hci_conn_put(conn);
+ }
+
+ struct hci_conn *hci_connect_bis(struct hci_dev *hdev, bdaddr_t *dst,
+@@ -2223,10 +2239,11 @@ struct hci_conn *hci_connect_bis(struct hci_dev *hdev, bdaddr_t *dst,
+ }
+
+ /* Queue start periodic advertising and create BIG */
+- err = hci_cmd_sync_queue(hdev, create_big_sync, conn,
++ err = hci_cmd_sync_queue(hdev, create_big_sync, hci_conn_get(conn),
+ create_big_complete);
+ if (err < 0) {
+ hci_conn_drop(conn);
++ hci_conn_put(conn);
+ return ERR_PTR(err);
+ }
+
+diff --git a/net/bluetooth/hci_sync.c b/net/bluetooth/hci_sync.c
+index 81c0589554a82c..c541de5ec28a1f 100644
+--- a/net/bluetooth/hci_sync.c
++++ b/net/bluetooth/hci_sync.c
+@@ -903,12 +903,16 @@ int hci_update_eir_sync(struct hci_dev *hdev)
+
+ memset(&cp, 0, sizeof(cp));
+
++ hci_dev_lock(hdev);
+ eir_create(hdev, cp.data);
+
+- if (memcmp(cp.data, hdev->eir, sizeof(cp.data)) == 0)
++ if (memcmp(cp.data, hdev->eir, sizeof(cp.data)) == 0) {
++ hci_dev_unlock(hdev);
+ return 0;
++ }
+
+ memcpy(hdev->eir, cp.data, sizeof(cp.data));
++ hci_dev_unlock(hdev);
+
+ return __hci_cmd_sync_status(hdev, HCI_OP_WRITE_EIR, sizeof(cp), &cp,
+ HCI_CMD_TIMEOUT);
+@@ -940,6 +944,7 @@ int hci_update_class_sync(struct hci_dev *hdev)
+ if (hci_dev_test_flag(hdev, HCI_SERVICE_CACHE))
+ return 0;
+
++ hci_dev_lock(hdev);
+ cod[0] = hdev->minor_class;
+ cod[1] = hdev->major_class;
+ cod[2] = get_service_classes(hdev);
+@@ -947,8 +952,12 @@ int hci_update_class_sync(struct hci_dev *hdev)
+ if (hci_dev_test_flag(hdev, HCI_LIMITED_DISCOVERABLE))
+ cod[1] |= 0x20;
+
+- if (memcmp(cod, hdev->dev_class, 3) == 0)
++ if (memcmp(cod, hdev->dev_class, 3) == 0) {
++ hci_dev_unlock(hdev);
+ return 0;
++ }
++
++ hci_dev_unlock(hdev);
+
+ return __hci_cmd_sync_status(hdev, HCI_OP_WRITE_CLASS_OF_DEV,
+ sizeof(cod), cod, HCI_CMD_TIMEOUT);
+diff --git a/net/bluetooth/hidp/core.c b/net/bluetooth/hidp/core.c
+index 80ccbbeb52572f..2823b31069e352 100644
+--- a/net/bluetooth/hidp/core.c
++++ b/net/bluetooth/hidp/core.c
+@@ -546,9 +546,10 @@ static int hidp_process_data(struct hidp_session *session, struct sk_buff *skb,
+ }
+
+ if (test_bit(HIDP_WAITING_FOR_RETURN, &session->flags) &&
+- param == session->waiting_report_type) {
++ param == session->waiting_report_type) {
+ if (session->waiting_report_number < 0 ||
+- session->waiting_report_number == skb->data[0]) {
++ (skb->len &&
++ session->waiting_report_number == skb->data[0])) {
+ /* hidp_get_raw_report() is waiting on this report. */
+ session->report_return = skb;
+ done_with_skb = 0;
+@@ -563,16 +564,18 @@ static int hidp_process_data(struct hidp_session *session, struct sk_buff *skb,
+ static void hidp_recv_ctrl_frame(struct hidp_session *session,
+ struct sk_buff *skb)
+ {
+- unsigned char hdr, type, param;
++ unsigned char type, param;
++ u8 *hdr;
+ int free_skb = 1;
+
+ BT_DBG("session %p skb %p len %u", session, skb, skb->len);
+
+- hdr = skb->data[0];
+- skb_pull(skb, 1);
++ hdr = skb_pull_data(skb, 1);
++ if (!hdr)
++ goto free;
+
+- type = hdr & HIDP_HEADER_TRANS_MASK;
+- param = hdr & HIDP_HEADER_PARAM_MASK;
++ type = *hdr & HIDP_HEADER_TRANS_MASK;
++ param = *hdr & HIDP_HEADER_PARAM_MASK;
+
+ switch (type) {
+ case HIDP_TRANS_HANDSHAKE:
+@@ -593,6 +596,7 @@ static void hidp_recv_ctrl_frame(struct hidp_session *session,
+ break;
+ }
+
++free:
+ if (free_skb)
+ kfree_skb(skb);
+ }
+@@ -600,14 +604,15 @@ static void hidp_recv_ctrl_frame(struct hidp_session *session,
+ static void hidp_recv_intr_frame(struct hidp_session *session,
+ struct sk_buff *skb)
+ {
+- unsigned char hdr;
++ u8 *hdr;
+
+ BT_DBG("session %p skb %p len %u", session, skb, skb->len);
+
+- hdr = skb->data[0];
+- skb_pull(skb, 1);
++ hdr = skb_pull_data(skb, 1);
++ if (!hdr)
++ goto free;
+
+- if (hdr == (HIDP_TRANS_DATA | HIDP_DATA_RTYPE_INPUT)) {
++ if (*hdr == (HIDP_TRANS_DATA | HIDP_DATA_RTYPE_INPUT)) {
+ hidp_set_timer(session);
+
+ if (session->input)
+@@ -619,9 +624,10 @@ static void hidp_recv_intr_frame(struct hidp_session *session,
+ BT_DBG("report len %d", skb->len);
+ }
+ } else {
+- BT_DBG("Unsupported protocol header 0x%02x", hdr);
++ BT_DBG("Unsupported protocol header 0x%02x", *hdr);
+ }
+
++free:
+ kfree_skb(skb);
+ }
+
+diff --git a/net/bluetooth/l2cap_core.c b/net/bluetooth/l2cap_core.c
+index 1da637f81db34c..d1881f48cd11c6 100644
+--- a/net/bluetooth/l2cap_core.c
++++ b/net/bluetooth/l2cap_core.c
+@@ -415,7 +415,7 @@ static void l2cap_chan_timeout(struct work_struct *work)
+
+ BT_DBG("chan %p state %s", chan, state_to_string(chan->state));
+
+- if (!conn) {
++ if (test_bit(FLAG_DEL, &chan->flags)) {
+ l2cap_chan_put(chan);
+ return;
+ }
+@@ -426,6 +426,9 @@ static void l2cap_chan_timeout(struct work_struct *work)
+ */
+ l2cap_chan_lock(chan);
+
++ if (test_bit(FLAG_DEL, &chan->flags))
++ goto unlock;
++
+ if (chan->state == BT_CONNECTED || chan->state == BT_CONFIG)
+ reason = ECONNREFUSED;
+ else if (chan->state == BT_CONNECT &&
+@@ -438,10 +441,11 @@ static void l2cap_chan_timeout(struct work_struct *work)
+
+ chan->ops->close(chan);
+
++unlock:
+ l2cap_chan_unlock(chan);
+- l2cap_chan_put(chan);
+
+ mutex_unlock(&conn->chan_lock);
++ l2cap_chan_put(chan);
+ }
+
+ struct l2cap_chan *l2cap_chan_create(void)
+@@ -494,6 +498,9 @@ static void l2cap_chan_destroy(struct kref *kref)
+ list_del(&chan->global_l);
+ write_unlock(&chan_list_lock);
+
++ if (chan->conn)
++ l2cap_conn_put(chan->conn);
++
+ kfree(chan);
+ }
+
+@@ -625,7 +632,7 @@ void __l2cap_chan_add(struct l2cap_conn *conn, struct l2cap_chan *chan)
+
+ conn->disc_reason = HCI_ERROR_REMOTE_USER_TERM;
+
+- chan->conn = conn;
++ chan->conn = l2cap_conn_get(conn);
+
+ switch (chan->chan_type) {
+ case L2CAP_CHAN_CONN_ORIENTED:
+@@ -680,30 +687,26 @@ void l2cap_chan_add(struct l2cap_conn *conn, struct l2cap_chan *chan)
+
+ void l2cap_chan_del(struct l2cap_chan *chan, int err)
+ {
+- struct l2cap_conn *conn = chan->conn;
+-
+ __clear_chan_timer(chan);
+
+- BT_DBG("chan %p, conn %p, err %d, state %s", chan, conn, err,
++ BT_DBG("chan %p, err %d, state %s", chan, err,
+ state_to_string(chan->state));
+
+ chan->ops->teardown(chan, err);
+
+- if (conn) {
++ if (!test_and_set_bit(FLAG_DEL, &chan->flags)) {
+ /* Delete from channel list */
+ list_del(&chan->list);
+
+ l2cap_chan_put(chan);
+
+- chan->conn = NULL;
+-
+ /* Reference was only held for non-fixed channels or
+ * fixed channels that explicitly requested it using the
+ * FLAG_HOLD_HCI_CONN flag.
+ */
+ if (chan->chan_type != L2CAP_CHAN_FIXED ||
+ test_bit(FLAG_HOLD_HCI_CONN, &chan->flags))
+- hci_conn_drop(conn->hcon);
++ hci_conn_drop(chan->conn->hcon);
+ }
+
+ if (test_bit(CONF_NOT_COMPLETE, &chan->conf_state))
+@@ -1930,7 +1933,7 @@ static void l2cap_monitor_timeout(struct work_struct *work)
+
+ l2cap_chan_lock(chan);
+
+- if (!chan->conn) {
++ if (test_bit(FLAG_DEL, &chan->flags)) {
+ l2cap_chan_unlock(chan);
+ l2cap_chan_put(chan);
+ return;
+@@ -1951,7 +1954,7 @@ static void l2cap_retrans_timeout(struct work_struct *work)
+
+ l2cap_chan_lock(chan);
+
+- if (!chan->conn) {
++ if (test_bit(FLAG_DEL, &chan->flags)) {
+ l2cap_chan_unlock(chan);
+ l2cap_chan_put(chan);
+ return;
+@@ -2566,7 +2569,7 @@ int l2cap_chan_send(struct l2cap_chan *chan, struct msghdr *msg, size_t len)
+ int err;
+ struct sk_buff_head seg_queue;
+
+- if (!chan->conn)
++ if (test_bit(FLAG_DEL, &chan->flags))
+ return -ENOTCONN;
+
+ /* Connectionless channel */
+@@ -3167,12 +3170,16 @@ static void l2cap_ack_timeout(struct work_struct *work)
+
+ l2cap_chan_lock(chan);
+
++ if (test_bit(FLAG_DEL, &chan->flags))
++ goto unlock;
++
+ frames_to_ack = __seq_offset(chan, chan->buffer_seq,
+ chan->last_acked_seq);
+
+ if (frames_to_ack)
+ l2cap_send_rr_or_rnr(chan, 0);
+
++unlock:
+ l2cap_chan_unlock(chan);
+ l2cap_chan_put(chan);
+ }
+@@ -4831,6 +4838,10 @@ static int l2cap_le_connect_rsp(struct l2cap_conn *conn,
+ goto unlock;
+ }
+
++ chan = l2cap_chan_hold_unless_zero(chan);
++ if (!chan)
++ return -EBADSLT;
++
+ err = 0;
+
+ l2cap_chan_lock(chan);
+@@ -4876,6 +4887,7 @@ static int l2cap_le_connect_rsp(struct l2cap_conn *conn,
+ }
+
+ l2cap_chan_unlock(chan);
++ l2cap_chan_put(chan);
+
+ unlock:
+ mutex_unlock(&conn->chan_lock);
+diff --git a/net/bluetooth/rfcomm/core.c b/net/bluetooth/rfcomm/core.c
+index 374187def190da..8a8afcd075ebb7 100644
+--- a/net/bluetooth/rfcomm/core.c
++++ b/net/bluetooth/rfcomm/core.c
+@@ -1027,6 +1027,23 @@ int rfcomm_send_rpn(struct rfcomm_session *s, int cr, u8 dlci,
+ return rfcomm_send_frame(s, buf, ptr - buf);
+ }
+
++int rfcomm_dlc_send_rpn(struct rfcomm_dlc *d, u8 bit_rate, u8 data_bits,
++ u8 stop_bits, u8 parity, u8 flow_ctrl_settings,
++ u8 xon_char, u8 xoff_char, u16 param_mask)
++{
++ int err = -ENOTCONN;
++
++ rfcomm_lock();
++ if (d->session)
++ err = rfcomm_send_rpn(d->session, 1, d->dlci, bit_rate,
++ data_bits, stop_bits, parity,
++ flow_ctrl_settings, xon_char, xoff_char,
++ param_mask);
++ rfcomm_unlock();
++
++ return err;
++}
++
+ static int rfcomm_send_rls(struct rfcomm_session *s, int cr, u8 dlci, u8 status)
+ {
+ struct rfcomm_hdr *hdr;
+diff --git a/net/bluetooth/rfcomm/tty.c b/net/bluetooth/rfcomm/tty.c
+index 9bf23be5e7dfaf..4edd2b1709db57 100644
+--- a/net/bluetooth/rfcomm/tty.c
++++ b/net/bluetooth/rfcomm/tty.c
+@@ -863,7 +863,7 @@ static void rfcomm_tty_set_termios(struct tty_struct *tty,
+
+ BT_DBG("tty %p termios %p", tty, old);
+
+- if (!dev || !dev->dlc || !dev->dlc->session)
++ if (!dev || !dev->dlc)
+ return;
+
+ /* Handle turning off CRTSCTS */
+@@ -984,9 +984,8 @@ static void rfcomm_tty_set_termios(struct tty_struct *tty,
+ }
+
+ if (changes)
+- rfcomm_send_rpn(dev->dlc->session, 1, dev->dlc->dlci, baud,
+- data_bits, stop_bits, parity,
+- RFCOMM_RPN_FLOW_NONE, x_on, x_off, changes);
++ rfcomm_dlc_send_rpn(dev->dlc, baud, data_bits, stop_bits, parity,
++ RFCOMM_RPN_FLOW_NONE, x_on, x_off, changes);
+ }
+
+ static void rfcomm_tty_throttle(struct tty_struct *tty)
+diff --git a/net/bridge/br_mrp.c b/net/bridge/br_mrp.c
+index fd2de35ffb3cf8..a837ff7d6f36d9 100644
+--- a/net/bridge/br_mrp.c
++++ b/net/bridge/br_mrp.c
+@@ -215,7 +215,7 @@ static struct sk_buff *br_mrp_alloc_test_skb(struct br_mrp *mrp,
+ struct br_mrp_oui_hdr *oui = NULL;
+ u8 length;
+
+- length = sizeof(*sub_opt) + sizeof(*sub_tlv) + sizeof(oui) +
++ length = sizeof(*sub_opt) + sizeof(*sub_tlv) + sizeof(*oui) +
+ MRP_OPT_PADDING;
+ br_mrp_skb_tlv(skb, BR_MRP_TLV_HEADER_OPTION, length);
+
+@@ -224,11 +224,9 @@ static struct sk_buff *br_mrp_alloc_test_skb(struct br_mrp *mrp,
+ sub_opt = skb_put(skb, sizeof(*sub_opt));
+ memset(sub_opt, 0x0, sizeof(*sub_opt));
+
+- sub_tlv = skb_put(skb, sizeof(*sub_tlv));
+- sub_tlv->type = BR_MRP_SUB_TLV_HEADER_TEST_AUTO_MGR;
+-
+ /* 32 bit alligment shall be ensured therefore add 2 bytes */
+- skb_put(skb, MRP_OPT_PADDING);
++ sub_tlv = skb_put_zero(skb, sizeof(*sub_tlv) + MRP_OPT_PADDING);
++ sub_tlv->type = BR_MRP_SUB_TLV_HEADER_TEST_AUTO_MGR;
+ }
+
+ br_mrp_skb_tlv(skb, BR_MRP_TLV_HEADER_END, 0x0);
+diff --git a/net/bridge/br_multicast.c b/net/bridge/br_multicast.c
+index 9b54fe10d280a5..1d65f7c165416f 100644
+--- a/net/bridge/br_multicast.c
++++ b/net/bridge/br_multicast.c
+@@ -3511,6 +3511,7 @@ br_multicast_leave_group(struct net_bridge_mcast *brmctx,
+
+ p->flags |= MDB_PG_FLAGS_FAST_LEAVE;
+ br_multicast_del_pg(mp, p, pp);
++ break;
+ }
+ goto out;
+ }
+diff --git a/net/bridge/br_netfilter_hooks.c b/net/bridge/br_netfilter_hooks.c
+index c4765691e78156..ffd100a242a047 100644
+--- a/net/bridge/br_netfilter_hooks.c
++++ b/net/bridge/br_netfilter_hooks.c
+@@ -292,7 +292,11 @@ int br_nf_pre_routing_finish_bridge(struct net *net, struct sock *sk, struct sk_
+ goto free_skb;
+ }
+
+- neigh_hh_bridge(&neigh->hh, skb);
++ if (neigh_hh_bridge(&neigh->hh, skb)) {
++ neigh_release(neigh);
++ goto free_skb;
++ }
++
+ skb->dev = br_indev;
+
+ ret = br_handle_frame_finish(net, sk, skb);
+diff --git a/net/bridge/br_netlink_tunnel.c b/net/bridge/br_netlink_tunnel.c
+index 8914290c75d480..e4aab077527011 100644
+--- a/net/bridge/br_netlink_tunnel.c
++++ b/net/bridge/br_netlink_tunnel.c
+@@ -268,7 +268,8 @@ static void __vlan_tunnel_handle_range(const struct net_bridge_port *p,
+ if (!*v_start)
+ goto out_init;
+
+- if (v && curr_change && br_vlan_can_enter_range(v, *v_end)) {
++ if (v && curr_change &&
++ br_vlan_can_enter_range(v, *v_end, br_get_pvid(vg))) {
+ *v_end = v;
+ return;
+ }
+diff --git a/net/bridge/br_private.h b/net/bridge/br_private.h
+index 7d2491c187d4ad..617e636a8a4c2b 100644
+--- a/net/bridge/br_private.h
++++ b/net/bridge/br_private.h
+@@ -1487,7 +1487,8 @@ void br_vlan_notify(const struct net_bridge *br,
+ u16 vid, u16 vid_range,
+ int cmd);
+ bool br_vlan_can_enter_range(const struct net_bridge_vlan *v_curr,
+- const struct net_bridge_vlan *range_end);
++ const struct net_bridge_vlan *range_end,
++ u16 pvid);
+
+ void br_vlan_fill_forward_path_pvid(struct net_bridge *br,
+ struct net_device_path_ctx *ctx,
+@@ -1727,7 +1728,8 @@ static inline void br_vlan_notify(const struct net_bridge *br,
+ }
+
+ static inline bool br_vlan_can_enter_range(const struct net_bridge_vlan *v_curr,
+- const struct net_bridge_vlan *range_end)
++ const struct net_bridge_vlan *range_end,
++ u16 pvid)
+ {
+ return true;
+ }
+diff --git a/net/bridge/br_vlan.c b/net/bridge/br_vlan.c
+index 54b0f24eb08ff2..c442ed83c01f48 100644
+--- a/net/bridge/br_vlan.c
++++ b/net/bridge/br_vlan.c
+@@ -1942,9 +1942,11 @@ out_kfree:
+
+ /* check if v_curr can enter a range ending in range_end */
+ bool br_vlan_can_enter_range(const struct net_bridge_vlan *v_curr,
+- const struct net_bridge_vlan *range_end)
++ const struct net_bridge_vlan *range_end,
++ u16 pvid)
+ {
+- return v_curr->vid - range_end->vid == 1 &&
++ return v_curr->vid != pvid && range_end->vid != pvid &&
++ v_curr->vid - range_end->vid == 1 &&
+ range_end->flags == v_curr->flags &&
+ br_vlan_opts_eq_range(v_curr, range_end);
+ }
+@@ -2026,8 +2028,8 @@ static int br_vlan_dump_dev(const struct net_device *dev,
+ idx += range_end->vid - range_start->vid + 1;
+
+ range_start = v;
+- } else if (dump_stats || v->vid == pvid ||
+- !br_vlan_can_enter_range(v, range_end)) {
++ } else if (dump_stats ||
++ !br_vlan_can_enter_range(v, range_end, pvid)) {
+ u16 vlan_flags = br_vlan_flags(range_start, pvid);
+
+ if (!br_vlan_fill_vids(skb, range_start->vid,
+diff --git a/net/bridge/br_vlan_options.c b/net/bridge/br_vlan_options.c
+index a2724d03278c3b..166b96cc600312 100644
+--- a/net/bridge/br_vlan_options.c
++++ b/net/bridge/br_vlan_options.c
+@@ -267,8 +267,7 @@ int br_vlan_process_options(const struct net_bridge *br,
+ continue;
+ }
+
+- if (v->vid == pvid ||
+- !br_vlan_can_enter_range(v, curr_end)) {
++ if (!br_vlan_can_enter_range(v, curr_end, pvid)) {
+ br_vlan_notify(br, p, curr_start->vid,
+ curr_end->vid, RTM_NEWVLAN);
+ curr_start = v;
+diff --git a/net/bridge/netfilter/ebt_nflog.c b/net/bridge/netfilter/ebt_nflog.c
+index 61bf8f4465ab7d..426f8adc912c75 100644
+--- a/net/bridge/netfilter/ebt_nflog.c
++++ b/net/bridge/netfilter/ebt_nflog.c
+@@ -41,11 +41,25 @@ ebt_nflog_tg(struct sk_buff *skb, const struct xt_action_param *par)
+ static int ebt_nflog_tg_check(const struct xt_tgchk_param *par)
+ {
+ struct ebt_nflog_info *info = par->targinfo;
++ int ret;
+
+ if (info->flags & ~EBT_NFLOG_MASK)
+ return -EINVAL;
+ info->prefix[EBT_NFLOG_PREFIX_SIZE - 1] = '\0';
+- return 0;
++
++ ret = nf_logger_find_get(par->family, NF_LOG_TYPE_ULOG);
++ if (ret != 0 && !par->nft_compat) {
++ request_module("%s", "nfnetlink_log");
++
++ ret = nf_logger_find_get(par->family, NF_LOG_TYPE_ULOG);
++ }
++
++ return ret;
++}
++
++static void ebt_nflog_tg_destroy(const struct xt_tgdtor_param *par)
++{
++ nf_logger_put(par->family, NF_LOG_TYPE_ULOG);
+ }
+
+ static struct xt_target ebt_nflog_tg_reg __read_mostly = {
+@@ -54,6 +68,7 @@ static struct xt_target ebt_nflog_tg_reg __read_mostly = {
+ .family = NFPROTO_BRIDGE,
+ .target = ebt_nflog_tg,
+ .checkentry = ebt_nflog_tg_check,
++ .destroy = ebt_nflog_tg_destroy,
+ .targetsize = sizeof(struct ebt_nflog_info),
+ .me = THIS_MODULE,
+ };
+diff --git a/net/bridge/netfilter/nf_conntrack_bridge.c b/net/bridge/netfilter/nf_conntrack_bridge.c
+index e7df2911d2be72..a22ff6767f6f92 100644
+--- a/net/bridge/netfilter/nf_conntrack_bridge.c
++++ b/net/bridge/netfilter/nf_conntrack_bridge.c
+@@ -281,6 +281,7 @@ static unsigned int nf_ct_bridge_pre(void *priv, struct sk_buff *skb,
+ ret = nf_ct_br_defrag6(skb, &bridge_state);
+ break;
+ default:
++ nf_reset_ct(skb);
+ nf_ct_set(skb, NULL, IP_CT_UNTRACKED);
+ return NF_ACCEPT;
+ }
+diff --git a/net/can/bcm.c b/net/can/bcm.c
+index 9fc733b54a86a0..16640650c43384 100644
+--- a/net/can/bcm.c
++++ b/net/can/bcm.c
+@@ -109,11 +109,12 @@ struct bcm_op {
+ int ifindex;
+ canid_t can_id;
+ u32 flags;
+- unsigned long frames_abs, frames_filtered;
++ atomic_long_t frames_abs, frames_filtered;
+ struct bcm_timeval ival1, ival2;
+ struct hrtimer timer, thrtimer;
+ ktime_t rx_stamp, kt_ival1, kt_ival2, kt_lastmsg;
+ int rx_ifindex;
++ int if_detected; /* first received ifindex in ANYDEV rx_op mode */
+ int cfsiz;
+ u32 count;
+ u32 nframes;
+@@ -125,7 +126,8 @@ struct bcm_op {
+ struct canfd_frame last_sframe;
+ struct sock *sk;
+ struct net_device *rx_reg_dev;
+- spinlock_t bcm_tx_lock; /* protect currframe/count in runtime updates */
++ spinlock_t bcm_tx_lock; /* protect tx data and timer updates */
++ spinlock_t bcm_rx_update_lock; /* protect filter/timer data updates */
+ };
+
+ struct bcm_sock {
+@@ -215,10 +217,13 @@ static int bcm_proc_show(struct seq_file *m, void *v)
+
+ list_for_each_entry_rcu(op, &bo->rx_ops, list) {
+
+- unsigned long reduction;
++ long reduction, frames_filtered, frames_abs;
++
++ frames_filtered = atomic_long_read(&op->frames_filtered);
++ frames_abs = atomic_long_read(&op->frames_abs);
+
+ /* print only active entries & prevent division by zero */
+- if (!op->frames_abs)
++ if (!frames_abs)
+ continue;
+
+ seq_printf(m, "rx_op: %03X %-5s ", op->can_id,
+@@ -240,9 +245,9 @@ static int bcm_proc_show(struct seq_file *m, void *v)
+ (long long)ktime_to_us(op->kt_ival2));
+
+ seq_printf(m, "# recv %ld (%ld) => reduction: ",
+- op->frames_filtered, op->frames_abs);
++ frames_filtered, frames_abs);
+
+- reduction = 100 - (op->frames_filtered * 100) / op->frames_abs;
++ reduction = 100 - (frames_filtered * 100) / frames_abs;
+
+ seq_printf(m, "%s%ld%%\n",
+ (reduction == 100) ? "near " : "", reduction);
+@@ -266,7 +271,8 @@ static int bcm_proc_show(struct seq_file *m, void *v)
+ seq_printf(m, "t2=%lld ",
+ (long long)ktime_to_us(op->kt_ival2));
+
+- seq_printf(m, "# sent %ld\n", op->frames_abs);
++ seq_printf(m, "# sent %ld\n",
++ atomic_long_read(&op->frames_abs));
+ }
+ seq_putc(m, '\n');
+
+@@ -276,25 +282,49 @@ static int bcm_proc_show(struct seq_file *m, void *v)
+ }
+ #endif /* CONFIG_PROC_FS */
+
++static void bcm_update_rx_stats(struct bcm_op *op)
++{
++ /* prevent overflow of the reduction% calculation in bcm_proc_show() */
++ if (atomic_long_inc_return(&op->frames_abs) > LONG_MAX / 100) {
++ atomic_long_set(&op->frames_filtered, 0);
++ atomic_long_set(&op->frames_abs, 0);
++ }
++}
++
++static void bcm_update_tx_stats(struct bcm_op *op)
++{
++ /* tx_op has no reduction% calculation - use the full range and
++ * just keep the displayed counter non-negative on overflow
++ */
++ if (atomic_long_inc_return(&op->frames_abs) == LONG_MAX)
++ atomic_long_set(&op->frames_abs, 0);
++}
++
+ /*
+ * bcm_can_tx - send the (next) CAN frame to the appropriate CAN interface
+ * of the given bcm tx op
+ */
+-static void bcm_can_tx(struct bcm_op *op)
++static void bcm_can_tx(struct bcm_op *op, struct canfd_frame *cf)
+ {
+ struct sk_buff *skb;
+ struct net_device *dev;
+- struct canfd_frame *cf;
++ struct canfd_frame cframe;
++ bool cyclic = !cf;
++ unsigned int idx = 0;
+ int err;
+
+ /* no target device? => exit */
+ if (!op->ifindex)
+ return;
+
+- /* read currframe under lock protection */
+- spin_lock_bh(&op->bcm_tx_lock);
+- cf = op->frames + op->cfsiz * op->currframe;
+- spin_unlock_bh(&op->bcm_tx_lock);
++ if (cyclic) {
++ /* read currframe under lock protection */
++ spin_lock_bh(&op->bcm_tx_lock);
++ idx = op->currframe;
++ memcpy(&cframe, op->frames + op->cfsiz * idx, op->cfsiz);
++ cf = &cframe;
++ spin_unlock_bh(&op->bcm_tx_lock);
++ }
+
+ dev = dev_get_by_index(sock_net(op->sk), op->ifindex);
+ if (!dev) {
+@@ -321,16 +351,22 @@ static void bcm_can_tx(struct bcm_op *op)
+ spin_lock_bh(&op->bcm_tx_lock);
+
+ if (!err)
+- op->frames_abs++;
++ bcm_update_tx_stats(op);
+
+- op->currframe++;
++ /* only advance the cyclic sequence if nothing reset currframe while
++ * we were sending - a concurrent TX_RESET_MULTI_IDX means this
++ * frame's bookkeeping belongs to a sequence that no longer exists
++ */
++ if (!cyclic || op->currframe == idx) {
++ op->currframe++;
+
+- /* reached last frame? */
+- if (op->currframe >= op->nframes)
+- op->currframe = 0;
++ /* reached last frame? */
++ if (op->currframe >= op->nframes)
++ op->currframe = 0;
+
+- if (op->count > 0)
+- op->count--;
++ if (op->count > 0)
++ op->count--;
++ }
+
+ spin_unlock_bh(&op->bcm_tx_lock);
+ out:
+@@ -405,12 +441,18 @@ static bool bcm_tx_set_expiry(struct bcm_op *op, struct hrtimer *hrt)
+ {
+ ktime_t ival;
+
++ spin_lock_bh(&op->bcm_tx_lock);
++
+ if (op->kt_ival1 && op->count)
+ ival = op->kt_ival1;
+- else if (op->kt_ival2)
++ else if (op->kt_ival2) {
+ ival = op->kt_ival2;
+- else
++ } else {
++ spin_unlock_bh(&op->bcm_tx_lock);
+ return false;
++ }
++
++ spin_unlock_bh(&op->bcm_tx_lock);
+
+ hrtimer_set_expires(hrt, ktime_add(ktime_get(), ival));
+ return true;
+@@ -427,26 +469,48 @@ static enum hrtimer_restart bcm_tx_timeout_handler(struct hrtimer *hrtimer)
+ {
+ struct bcm_op *op = container_of(hrtimer, struct bcm_op, timer);
+ struct bcm_msg_head msg_head;
++ bool tx_ival1, tx_ival2;
++
++ /* snapshot kt_ival1/kt_ival2/count under lock to avoid torn
++ * ktime_t reads racing with concurrent bcm_tx_setup() updates
++ */
++ spin_lock_bh(&op->bcm_tx_lock);
++ tx_ival1 = op->kt_ival1 && (op->count > 0);
++ tx_ival2 = !!op->kt_ival2;
++ spin_unlock_bh(&op->bcm_tx_lock);
++
++ if (tx_ival1) {
++ u32 flags, count;
++ struct bcm_timeval ival1, ival2;
+
+- if (op->kt_ival1 && (op->count > 0)) {
+- bcm_can_tx(op);
+- if (!op->count && (op->flags & TX_COUNTEVT)) {
++ bcm_can_tx(op, NULL);
+
++ /* snapshot variables under lock to avoid torn reads racing
++ * with concurrent bcm_tx_setup() updates
++ */
++ spin_lock_bh(&op->bcm_tx_lock);
++ flags = op->flags;
++ count = op->count;
++ ival1 = op->ival1;
++ ival2 = op->ival2;
++ spin_unlock_bh(&op->bcm_tx_lock);
++
++ if (!count && (flags & TX_COUNTEVT)) {
+ /* create notification to user */
+ memset(&msg_head, 0, sizeof(msg_head));
+ msg_head.opcode = TX_EXPIRED;
+- msg_head.flags = op->flags;
+- msg_head.count = op->count;
+- msg_head.ival1 = op->ival1;
+- msg_head.ival2 = op->ival2;
++ msg_head.flags = flags;
++ msg_head.count = count;
++ msg_head.ival1 = ival1;
++ msg_head.ival2 = ival2;
+ msg_head.can_id = op->can_id;
+ msg_head.nframes = 0;
+
+ bcm_send_to_user(op, &msg_head, NULL, 0);
+ }
+
+- } else if (op->kt_ival2) {
+- bcm_can_tx(op);
++ } else if (tx_ival2) {
++ bcm_can_tx(op, NULL);
+ }
+
+ return bcm_tx_set_expiry(op, &op->timer) ?
+@@ -460,12 +524,9 @@ static void bcm_rx_changed(struct bcm_op *op, struct canfd_frame *data)
+ {
+ struct bcm_msg_head head;
+
+- /* update statistics */
+- op->frames_filtered++;
+-
+- /* prevent statistics overflow */
+- if (op->frames_filtered > ULONG_MAX/100)
+- op->frames_filtered = op->frames_abs = 0;
++ /* update statistics (frames_filtered <= frames_abs) */
++ if (atomic_long_read(&op->frames_abs))
++ atomic_long_inc(&op->frames_filtered);
+
+ /* this element is not throttled anymore */
+ data->flags &= (BCM_CAN_FLAGS_MASK|RX_RECV);
+@@ -585,6 +646,8 @@ static enum hrtimer_restart bcm_rx_timeout_handler(struct hrtimer *hrtimer)
+ struct bcm_op *op = container_of(hrtimer, struct bcm_op, timer);
+ struct bcm_msg_head msg_head;
+
++ spin_lock_bh(&op->bcm_rx_update_lock);
++
+ /* if user wants to be informed, when cyclic CAN-Messages come back */
+ if ((op->flags & RX_ANNOUNCE_RESUME) && op->last_frames) {
+ /* clear received CAN frames to indicate 'nothing received' */
+@@ -601,6 +664,8 @@ static enum hrtimer_restart bcm_rx_timeout_handler(struct hrtimer *hrtimer)
+ msg_head.can_id = op->can_id;
+ msg_head.nframes = 0;
+
++ spin_unlock_bh(&op->bcm_rx_update_lock);
++
+ bcm_send_to_user(op, &msg_head, NULL, 0);
+
+ return HRTIMER_NORESTART;
+@@ -649,15 +714,26 @@ static int bcm_rx_thr_flush(struct bcm_op *op)
+ static enum hrtimer_restart bcm_rx_thr_handler(struct hrtimer *hrtimer)
+ {
+ struct bcm_op *op = container_of(hrtimer, struct bcm_op, thrtimer);
++ enum hrtimer_restart ret;
++
++ spin_lock_bh(&op->bcm_rx_update_lock);
+
+- if (bcm_rx_thr_flush(op)) {
++ /* kt_ival2 may have been concurrently cleared by bcm_rx_setup()
++ * before it cancels this timer - never forward with a zero
++ * interval in that case.
++ */
++ if (bcm_rx_thr_flush(op) && op->kt_ival2) {
+ hrtimer_forward_now(hrtimer, op->kt_ival2);
+- return HRTIMER_RESTART;
++ ret = HRTIMER_RESTART;
+ } else {
+ /* rearm throttle handling */
+ op->kt_lastmsg = 0;
+- return HRTIMER_NORESTART;
++ ret = HRTIMER_NORESTART;
+ }
++
++ spin_unlock_bh(&op->bcm_rx_update_lock);
++
++ return ret;
+ }
+
+ /*
+@@ -667,7 +743,9 @@ static void bcm_rx_handler(struct sk_buff *skb, void *data)
+ {
+ struct bcm_op *op = (struct bcm_op *)data;
+ const struct canfd_frame *rxframe = (struct canfd_frame *)skb->data;
++ struct canfd_frame rtrframe;
+ unsigned int i;
++ bool rtr_frame;
+
+ if (op->can_id != rxframe->can_id)
+ return;
+@@ -681,22 +759,66 @@ static void bcm_rx_handler(struct sk_buff *skb, void *data)
+ return;
+ }
+
++ /* An ANYDEV op with an active RX timeout and/or throttle timer
++ * tracks a single source interface: claim the first interface that
++ * delivers a matching frame and reject frames from any other one,
++ * before hrtimer_cancel() below can touch op->timer - this avoids
++ * racing bcm_rx_timeout_handler() across concurrent interfaces.
++ * RX_RTR_FRAME ops are excluded, as kt_ival1/kt_ival2 may briefly
++ * hold a stale value from an earlier non-RTR configuration.
++ */
++ if (!op->ifindex) {
++ spin_lock_bh(&op->bcm_rx_update_lock);
++
++ if (!(op->flags & RX_RTR_FRAME) &&
++ (op->kt_ival1 || op->kt_ival2)) {
++ /* don't claim to vanishing interface */
++ if (!op->if_detected &&
++ skb->dev->reg_state == NETREG_REGISTERED)
++ op->if_detected = skb->dev->ifindex;
++
++ if (op->if_detected != skb->dev->ifindex) {
++ spin_unlock_bh(&op->bcm_rx_update_lock);
++ return;
++ }
++ }
++
++ spin_unlock_bh(&op->bcm_rx_update_lock);
++ }
++
+ /* disable timeout */
+ hrtimer_cancel(&op->timer);
+
+- /* save rx timestamp */
+- op->rx_stamp = skb->tstamp;
+- /* save originator for recvfrom() */
+- op->rx_ifindex = skb->dev->ifindex;
+- /* update statistics */
+- op->frames_abs++;
++ /* op->flags/op->frames may be updated concurrently by bcm_rx_setup() */
++ spin_lock_bh(&op->bcm_rx_update_lock);
++
++ rtr_frame = op->flags & RX_RTR_FRAME;
++ if (rtr_frame) {
++ bcm_update_rx_stats(op);
++ /* snapshot RTR content under lock */
++ memcpy(&rtrframe, op->frames, op->cfsiz);
++ spin_unlock_bh(&op->bcm_rx_update_lock);
+
+- if (op->flags & RX_RTR_FRAME) {
+ /* send reply for RTR-request (placed in op->frames[0]) */
+- bcm_can_tx(op);
++ bcm_can_tx(op, &rtrframe);
+ return;
+ }
+
++ /* update statistics in the same critical section as bcm_rx_changed()
++ * below: frames_filtered must never be checked/incremented against a
++ * frames_abs snapshot from a concurrent bcm_rx_handler() call on
++ * another CPU for the same (wildcard) op, or frames_filtered can end
++ * up larger than frames_abs.
++ */
++ bcm_update_rx_stats(op);
++
++ /* save rx timestamp and originator for recvfrom() under lock: an
++ * ANYDEV op without an active timer can still run concurrently on
++ * different CPUs, so content and meta data must be bundled here.
++ */
++ op->rx_stamp = skb->tstamp;
++ op->rx_ifindex = skb->dev->ifindex;
++
+ if (op->flags & RX_FILTER_ID) {
+ /* the easiest case */
+ bcm_rx_update_and_send(op, op->last_frames, rxframe);
+@@ -730,6 +852,8 @@ static void bcm_rx_handler(struct sk_buff *skb, void *data)
+
+ rx_starttimer:
+ bcm_rx_starttimer(op);
++
++ spin_unlock_bh(&op->bcm_rx_update_lock);
+ }
+
+ /*
+@@ -795,6 +919,7 @@ static void bcm_rx_unreg(struct net_device *dev, struct bcm_op *op)
+
+ /* mark as removed subscription */
+ op->rx_reg_dev = NULL;
++ dev_put(dev);
+ } else
+ printk(KERN_ERR "can-bcm: bcm_rx_unreg: registered device "
+ "mismatch %p %p\n", op->rx_reg_dev, dev);
+@@ -825,17 +950,14 @@ static int bcm_delete_rx_op(struct list_head *ops, struct bcm_msg_head *mh,
+ * Only remove subscriptions that had not
+ * been removed due to NETDEV_UNREGISTER
+ * in bcm_notifier()
++ *
++ * op->rx_reg_dev is a tracked reference taken
++ * when the subscription was registered, so it
++ * stays valid here even if a concurrent
++ * NETDEV_UNREGISTER already unlisted the dev.
+ */
+- if (op->rx_reg_dev) {
+- struct net_device *dev;
+-
+- dev = dev_get_by_index(sock_net(op->sk),
+- op->ifindex);
+- if (dev) {
+- bcm_rx_unreg(dev, op);
+- dev_put(dev);
+- }
+- }
++ if (op->rx_reg_dev)
++ bcm_rx_unreg(op->rx_reg_dev, op);
+ } else
+ can_rx_unregister(sock_net(op->sk), NULL,
+ op->can_id,
+@@ -922,6 +1044,8 @@ static int bcm_tx_setup(struct bcm_msg_head *msg_head, struct msghdr *msg,
+ /* check the given can_id */
+ op = bcm_find_op(&bo->tx_ops, msg_head, ifindex);
+ if (op) {
++ void *new_frames;
++
+ /* update existing BCM operation */
+
+ /*
+@@ -932,11 +1056,23 @@ static int bcm_tx_setup(struct bcm_msg_head *msg_head, struct msghdr *msg,
+ if (msg_head->nframes > op->nframes)
+ return -E2BIG;
+
+- /* update CAN frames content */
++ /* get new CAN frames content into a staging buffer before
++ * locking: validate and normalize the frames there so that
++ * bcm_can_tx() / bcm_tx_timeout_handler() never observe a
++ * partially updated or unvalidated frame in op->frames
++ */
++ new_frames = kmalloc(msg_head->nframes * op->cfsiz, GFP_KERNEL);
++ if (!new_frames)
++ return -ENOMEM;
++
+ for (i = 0; i < msg_head->nframes; i++) {
+
+- cf = op->frames + op->cfsiz * i;
++ cf = new_frames + op->cfsiz * i;
+ err = memcpy_from_msg((u8 *)cf, msg, op->cfsiz);
++ if (err < 0) {
++ kfree(new_frames);
++ return err;
++ }
+
+ if (op->flags & CAN_FD_FRAME) {
+ if (cf->len > 64)
+@@ -946,36 +1082,38 @@ static int bcm_tx_setup(struct bcm_msg_head *msg_head, struct msghdr *msg,
+ err = -EINVAL;
+ }
+
+- if (err < 0)
++ if (err < 0) {
++ kfree(new_frames);
+ return err;
++ }
+
+ if (msg_head->flags & TX_CP_CAN_ID) {
+ /* copy can_id into frame */
+ cf->can_id = msg_head->can_id;
+ }
+ }
++
++ spin_lock_bh(&op->bcm_tx_lock);
++
++ /* update CAN frames content */
++ memcpy(op->frames, new_frames, msg_head->nframes * op->cfsiz);
++
+ op->flags = msg_head->flags;
+
+- /* only lock for unlikely count/nframes/currframe changes */
+ if (op->nframes != msg_head->nframes ||
+- op->flags & TX_RESET_MULTI_IDX ||
+- op->flags & SETTIMER) {
+-
+- spin_lock_bh(&op->bcm_tx_lock);
++ op->flags & TX_RESET_MULTI_IDX) {
++ /* potentially update changed nframes */
++ op->nframes = msg_head->nframes;
++ /* restart multiple frame transmission */
++ op->currframe = 0;
++ }
+
+- if (op->nframes != msg_head->nframes ||
+- op->flags & TX_RESET_MULTI_IDX) {
+- /* potentially update changed nframes */
+- op->nframes = msg_head->nframes;
+- /* restart multiple frame transmission */
+- op->currframe = 0;
+- }
++ if (op->flags & SETTIMER)
++ op->count = msg_head->count;
+
+- if (op->flags & SETTIMER)
+- op->count = msg_head->count;
++ spin_unlock_bh(&op->bcm_tx_lock);
+
+- spin_unlock_bh(&op->bcm_tx_lock);
+- }
++ kfree(new_frames);
+
+ } else {
+ /* insert new BCM operation for the given can_id */
+@@ -1052,10 +1190,12 @@ static int bcm_tx_setup(struct bcm_msg_head *msg_head, struct msghdr *msg,
+
+ if (op->flags & SETTIMER) {
+ /* set timer values */
++ spin_lock_bh(&op->bcm_tx_lock);
+ op->ival1 = msg_head->ival1;
+ op->ival2 = msg_head->ival2;
+ op->kt_ival1 = bcm_timeval_to_ktime(msg_head->ival1);
+ op->kt_ival2 = bcm_timeval_to_ktime(msg_head->ival2);
++ spin_unlock_bh(&op->bcm_tx_lock);
+
+ /* disable an active timer due to zero values? */
+ if (!op->kt_ival1 && !op->kt_ival2)
+@@ -1073,7 +1213,7 @@ static int bcm_tx_setup(struct bcm_msg_head *msg_head, struct msghdr *msg,
+ list_add_rcu(&op->list, &bo->tx_ops);
+
+ if (op->flags & TX_ANNOUNCE)
+- bcm_can_tx(op);
++ bcm_can_tx(op, NULL);
+
+ if (op->flags & STARTTIMER)
+ bcm_tx_start_timer(op);
+@@ -1087,6 +1227,39 @@ free_op:
+ return err;
+ }
+
++static int bcm_rx_setup_rtr_check(struct bcm_msg_head *msg_head,
++ struct bcm_op *op, void *new_frames)
++{
++ struct canfd_frame *frame0 = new_frames;
++
++ if (!(msg_head->flags & RX_RTR_FRAME))
++ return 0;
++
++ /* this frame is sent out as-is by bcm_can_tx() whenever a matching
++ * remote request is received, so validate its length the same way
++ * bcm_tx_setup() validates TX_SETUP frames before installing it
++ */
++ if (msg_head->flags & CAN_FD_FRAME) {
++ if (frame0->len > 64)
++ return -EINVAL;
++ } else {
++ if (frame0->len > 8)
++ return -EINVAL;
++ }
++
++ /* funny feature in RX(!)_SETUP only for RTR-mode:
++ * copy can_id into frame BUT without RTR-flag to
++ * prevent a full-load-loopback-test ... ;-]
++ * normalize this on the staged buffer, before it is
++ * ever installed into op->frames.
++ */
++ if ((msg_head->flags & TX_CP_CAN_ID) ||
++ frame0->can_id == op->can_id)
++ frame0->can_id = op->can_id & ~CAN_RTR_FLAG;
++
++ return 0;
++}
++
+ /*
+ * bcm_rx_setup - create or update a bcm rx op (for bcm_sendmsg)
+ */
+@@ -1096,6 +1269,7 @@ static int bcm_rx_setup(struct bcm_msg_head *msg_head, struct msghdr *msg,
+ struct bcm_sock *bo = bcm_sk(sk);
+ struct bcm_op *op;
+ int do_rx_register;
++ int new_op = 0;
+ int err = 0;
+
+ if ((msg_head->flags & RX_FILTER_ID) || (!(msg_head->nframes))) {
+@@ -1121,6 +1295,8 @@ static int bcm_rx_setup(struct bcm_msg_head *msg_head, struct msghdr *msg,
+ /* check the given can_id */
+ op = bcm_find_op(&bo->rx_ops, msg_head, ifindex);
+ if (op) {
++ void *new_frames = NULL;
++
+ /* update existing BCM operation */
+
+ /*
+@@ -1132,21 +1308,62 @@ static int bcm_rx_setup(struct bcm_msg_head *msg_head, struct msghdr *msg,
+ return -E2BIG;
+
+ if (msg_head->nframes) {
+- /* update CAN frames content */
+- err = memcpy_from_msg(op->frames, msg,
++ /* get new CAN frames content before locking */
++ new_frames = kmalloc(msg_head->nframes * op->cfsiz,
++ GFP_KERNEL);
++ if (!new_frames)
++ return -ENOMEM;
++
++ err = memcpy_from_msg(new_frames, msg,
+ msg_head->nframes * op->cfsiz);
+- if (err < 0)
++ if (err < 0) {
++ kfree(new_frames);
+ return err;
++ }
+
+- /* clear last_frames to indicate 'nothing received' */
+- memset(op->last_frames, 0, msg_head->nframes * op->cfsiz);
++ err = bcm_rx_setup_rtr_check(msg_head, op, new_frames);
++ if (err < 0) {
++ kfree(new_frames);
++ return err;
++ }
+ }
+
++ spin_lock_bh(&op->bcm_rx_update_lock);
+ op->nframes = msg_head->nframes;
+ op->flags = msg_head->flags;
+
+- /* Only an update -> do not call can_rx_register() */
+- do_rx_register = 0;
++ if (msg_head->nframes) {
++ /* update CAN frames content */
++ memcpy(op->frames, new_frames,
++ msg_head->nframes * op->cfsiz);
++
++ /* clear last_frames to indicate 'nothing received' */
++ memset(op->last_frames, 0,
++ msg_head->nframes * op->cfsiz);
++ }
++
++ if (msg_head->flags & SETTIMER) {
++ op->ival1 = msg_head->ival1;
++ op->ival2 = msg_head->ival2;
++ op->kt_ival1 = bcm_timeval_to_ktime(msg_head->ival1);
++ op->kt_ival2 = bcm_timeval_to_ktime(msg_head->ival2);
++ op->kt_lastmsg = 0;
++ op->if_detected = 0; /* reclaim ifindex in ANYDEV mode */
++ }
++ spin_unlock_bh(&op->bcm_rx_update_lock);
++
++ /* free temporary frames / kfree(NULL) is safe */
++ kfree(new_frames);
++
++ /* Don't register a new CAN filter for the rx_op update unless
++ * a concurrent NETDEV_UNREGISTER notifier already tore down
++ * the previous registration. In this case the receiver needs
++ * to be re-registered here so that this update doesn't
++ * silently stop delivering frames for the given ifindex.
++ * Ops with ifindex = 0 (all CAN interfaces) never carry a
++ * tracked rx_reg_dev and stay registered as-is.
++ */
++ do_rx_register = (ifindex && !op->rx_reg_dev) ? 1 : 0;
+
+ } else {
+ /* insert new BCM operation for the given can_id */
+@@ -1155,6 +1372,7 @@ static int bcm_rx_setup(struct bcm_msg_head *msg_head, struct msghdr *msg,
+ return -ENOMEM;
+
+ spin_lock_init(&op->bcm_tx_lock);
++ spin_lock_init(&op->bcm_rx_update_lock);
+ op->can_id = msg_head->can_id;
+ op->nframes = msg_head->nframes;
+ op->cfsiz = CFSIZ(msg_head->flags);
+@@ -1188,14 +1406,12 @@ static int bcm_rx_setup(struct bcm_msg_head *msg_head, struct msghdr *msg,
+ if (msg_head->nframes) {
+ err = memcpy_from_msg(op->frames, msg,
+ msg_head->nframes * op->cfsiz);
+- if (err < 0) {
+- if (op->frames != &op->sframe)
+- kfree(op->frames);
+- if (op->last_frames != &op->last_sframe)
+- kfree(op->last_frames);
+- kfree(op);
+- return err;
+- }
++ if (err < 0)
++ goto free_op;
++
++ err = bcm_rx_setup_rtr_check(msg_head, op, op->frames);
++ if (err < 0)
++ goto free_op;
+ }
+
+ /* bcm_can_tx / bcm_tx_timeout_handler needs this */
+@@ -1217,35 +1433,29 @@ static int bcm_rx_setup(struct bcm_msg_head *msg_head, struct msghdr *msg,
+
+ /* call can_rx_register() */
+ do_rx_register = 1;
++ new_op = 1;
+
+ } /* if ((op = bcm_find_op(&bo->rx_ops, msg_head->can_id, ifindex))) */
+
+ /* check flags */
+
+ if (op->flags & RX_RTR_FRAME) {
+- struct canfd_frame *frame0 = op->frames;
+-
+ /* no timers in RTR-mode */
+ hrtimer_cancel(&op->thrtimer);
+ hrtimer_cancel(&op->timer);
+-
+- /*
+- * funny feature in RX(!)_SETUP only for RTR-mode:
+- * copy can_id into frame BUT without RTR-flag to
+- * prevent a full-load-loopback-test ... ;-]
+- */
+- if ((op->flags & TX_CP_CAN_ID) ||
+- (frame0->can_id == op->can_id))
+- frame0->can_id = op->can_id & ~CAN_RTR_FLAG;
+-
+ } else {
+ if (op->flags & SETTIMER) {
+
+- /* set timer value */
+- op->ival1 = msg_head->ival1;
+- op->ival2 = msg_head->ival2;
+- op->kt_ival1 = bcm_timeval_to_ktime(msg_head->ival1);
+- op->kt_ival2 = bcm_timeval_to_ktime(msg_head->ival2);
++ /* set timers (locked) for newly created op */
++ if (new_op) {
++ spin_lock_bh(&op->bcm_rx_update_lock);
++ op->ival1 = msg_head->ival1;
++ op->ival2 = msg_head->ival2;
++ op->kt_ival1 = bcm_timeval_to_ktime(msg_head->ival1);
++ op->kt_ival2 = bcm_timeval_to_ktime(msg_head->ival2);
++ op->kt_lastmsg = 0;
++ spin_unlock_bh(&op->bcm_rx_update_lock);
++ }
+
+ /* disable an active timer due to zero value? */
+ if (!op->kt_ival1)
+@@ -1255,9 +1465,11 @@ static int bcm_rx_setup(struct bcm_msg_head *msg_head, struct msghdr *msg,
+ * In any case cancel the throttle timer, flush
+ * potentially blocked msgs and reset throttle handling
+ */
+- op->kt_lastmsg = 0;
+ hrtimer_cancel(&op->thrtimer);
++
++ spin_lock_bh(&op->bcm_rx_update_lock);
+ bcm_rx_thr_flush(op);
++ spin_unlock_bh(&op->bcm_rx_update_lock);
+ }
+
+ if ((op->flags & STARTTIMER) && op->kt_ival1)
+@@ -1265,7 +1477,10 @@ static int bcm_rx_setup(struct bcm_msg_head *msg_head, struct msghdr *msg,
+ HRTIMER_MODE_REL_SOFT);
+ }
+
+- /* now we can register for can_ids, if we added a new bcm_op */
++ /* now we can register for can_ids, if we added a new bcm_op
++ * or need to re-register after a NETDEV_UNREGISTER tore down
++ * the previous registration of an existing op
++ */
+ if (do_rx_register) {
+ if (ifindex) {
+ struct net_device *dev;
+@@ -1278,7 +1493,15 @@ static int bcm_rx_setup(struct bcm_msg_head *msg_head, struct msghdr *msg,
+ bcm_rx_handler, op,
+ "bcm", sk);
+
+- op->rx_reg_dev = dev;
++ /* keep a reference so that a later
++ * unregister can safely reach the device even
++ * if a concurrent NETDEV_UNREGISTER has
++ * already unlisted it by ifindex
++ */
++ if (!err) {
++ op->rx_reg_dev = dev;
++ dev_hold(dev);
++ }
+ dev_put(dev);
+ } else {
+ /* the requested device is gone - do not
+@@ -1287,21 +1510,43 @@ static int bcm_rx_setup(struct bcm_msg_head *msg_head, struct msghdr *msg,
+ err = -ENODEV;
+ }
+
+- } else
++ } else {
+ err = can_rx_register(sock_net(sk), NULL, op->can_id,
+ REGMASK(op->can_id),
+ bcm_rx_handler, op, "bcm", sk);
++ }
++
+ if (err) {
+- /* this bcm rx op is broken -> remove it */
+- bcm_remove_op(op);
++ /* newly created bcm rx op is broken -> remove it */
++ if (new_op) {
++ bcm_remove_op(op);
++ return err;
++ }
++
++ /* an existing op just stays unregistered.
++ * Cancel op->timer and (defensively) op->thrtimer.
++ * Other settings can't be reached until the next
++ * successful RX_SETUP.
++ */
++ hrtimer_cancel(&op->timer);
++ hrtimer_cancel(&op->thrtimer);
+ return err;
+ }
+
+- /* add this bcm_op to the list of the rx_ops */
+- list_add_rcu(&op->list, &bo->rx_ops);
++ /* add a new bcm_op to the list of the rx_ops */
++ if (new_op)
++ list_add_rcu(&op->list, &bo->rx_ops);
+ }
+
+ return msg_head->nframes * op->cfsiz + MHSIZ;
++
++free_op:
++ if (op->frames != &op->sframe)
++ kfree(op->frames);
++ if (op->last_frames != &op->last_sframe)
++ kfree(op->last_frames);
++ kfree(op);
++ return err;
+ }
+
+ /*
+@@ -1506,11 +1751,30 @@ static void bcm_notify(struct bcm_sock *bo, unsigned long msg,
+ case NETDEV_UNREGISTER:
+ lock_sock(sk);
+
+- /* remove device specific receive entries */
+- list_for_each_entry(op, &bo->rx_ops, list)
++ /* rx_ops: remove device specific receive entries */
++ list_for_each_entry(op, &bo->rx_ops, list) {
+ if (op->rx_reg_dev == dev)
+ bcm_rx_unreg(dev, op);
+
++ /* release an ANYDEV op's claim (see bcm_rx_handler())
++ * on this now confirmed-gone interface.
++ */
++ if (!op->ifindex) {
++ spin_lock_bh(&op->bcm_rx_update_lock);
++ if (op->if_detected == dev->ifindex)
++ op->if_detected = 0;
++ spin_unlock_bh(&op->bcm_rx_update_lock);
++ }
++ }
++
++ /* tx_ops: stop device specific cyclic transmissions on the
++ * vanishing ifindex. Cancelling the timer is enough to stop
++ * cyclic bcm_can_tx() calls as there is no re-arming.
++ */
++ list_for_each_entry(op, &bo->tx_ops, list)
++ if (op->ifindex == dev->ifindex)
++ hrtimer_cancel(&op->timer);
++
+ /* remove device reference, if this is our bound device */
+ if (bo->bound && bo->ifindex == dev->ifindex) {
+ #if IS_ENABLED(CONFIG_PROC_FS)
+@@ -1643,16 +1907,14 @@ static int bcm_release(struct socket *sock)
+ * Only remove subscriptions that had not
+ * been removed due to NETDEV_UNREGISTER
+ * in bcm_notifier()
++ *
++ * op->rx_reg_dev is a tracked reference taken
++ * when the subscription was registered, so it
++ * stays valid here even if a concurrent
++ * NETDEV_UNREGISTER already unlisted the device.
+ */
+- if (op->rx_reg_dev) {
+- struct net_device *dev;
+-
+- dev = dev_get_by_index(net, op->ifindex);
+- if (dev) {
+- bcm_rx_unreg(dev, op);
+- dev_put(dev);
+- }
+- }
++ if (op->rx_reg_dev)
++ bcm_rx_unreg(op->rx_reg_dev, op);
+ } else
+ can_rx_unregister(net, NULL, op->can_id,
+ REGMASK(op->can_id),
+diff --git a/net/can/isotp.c b/net/can/isotp.c
+index 7d9327b3211078..645e0bd16782d6 100644
+--- a/net/can/isotp.c
++++ b/net/can/isotp.c
+@@ -137,11 +137,12 @@ struct isotp_sock {
+ struct sock sk;
+ int bound;
+ int ifindex;
++ struct net_device *dev;
+ canid_t txid;
+ canid_t rxid;
+ ktime_t tx_gap;
+ ktime_t lastrxcf_tstamp;
+- struct hrtimer rxtimer, txtimer, txfrtimer;
++ struct hrtimer rxtimer, txtimer, txfrtimer, echotimer;
+ struct can_isotp_options opt;
+ struct can_isotp_fc_options rxfc, txfc;
+ struct can_isotp_ll_options ll;
+@@ -149,6 +150,7 @@ struct isotp_sock {
+ u32 force_tx_stmin;
+ u32 force_rx_stmin;
+ u32 cfecho; /* consecutive frame echo tag */
++ u32 tx_gen; /* generation, bumped per new tx transfer */
+ struct tpcon rx, tx;
+ struct list_head notifier;
+ wait_queue_head_t wait;
+@@ -355,6 +357,15 @@ static int isotp_rcv_fc(struct isotp_sock *so, struct canfd_frame *cf, int ae)
+
+ hrtimer_cancel(&so->txtimer);
+
++ /* isotp_tx_timeout() may have given up on this job while
++ * hrtimer_cancel() above waited for it to finish; so->rx_lock
++ * (held by our caller isotp_rcv()) rules out a concurrent claim,
++ * so a plain recheck is enough here.
++ */
++ if (so->tx.state != ISOTP_WAIT_FC &&
++ so->tx.state != ISOTP_WAIT_FIRST_FC)
++ return 1;
++
+ if ((cf->len < ae + FC_CONTENT_SZ) ||
+ ((so->opt.flags & ISOTP_CHECK_PADDING) &&
+ check_pad(so, cf, ae + FC_CONTENT_SZ, so->opt.rxpad_content))) {
+@@ -400,7 +411,7 @@ static int isotp_rcv_fc(struct isotp_sock *so, struct canfd_frame *cf, int ae)
+ so->tx.bs = 0;
+ so->tx.state = ISOTP_SENDING;
+ /* send CF frame and enable echo timeout handling */
+- hrtimer_start(&so->txtimer, ktime_set(ISOTP_ECHO_TIMEOUT, 0),
++ hrtimer_start(&so->echotimer, ktime_set(ISOTP_ECHO_TIMEOUT, 0),
+ HRTIMER_MODE_REL_SOFT);
+ isotp_send_cframe(so);
+ break;
+@@ -543,6 +554,14 @@ static int isotp_rcv_cf(struct sock *sk, struct canfd_frame *cf, int ae,
+
+ hrtimer_cancel(&so->rxtimer);
+
++ /* isotp_rx_timer_handler() may have raced us for so->rx.state
++ * while hrtimer_cancel() above waited for it to finish, already
++ * reporting ETIMEDOUT and resetting the reception; don't process
++ * this CF into a reassembly that has already been given up on.
++ */
++ if (so->rx.state != ISOTP_WAIT_DATA)
++ return 1;
++
+ /* CFs are never longer than the FF */
+ if (cf->len > so->rx.ll_dl)
+ return 1;
+@@ -832,20 +851,36 @@ static void isotp_rcv_echo(struct sk_buff *skb, void *data)
+ struct canfd_frame *cf = (struct canfd_frame *)skb->data;
+
+ /* only handle my own local echo CF/SF skb's (no FF!) */
+- if (skb->sk != sk || so->cfecho != *(u32 *)cf->data)
++ if (skb->sk != sk)
+ return;
+
++ /* unlike isotp_rcv_fc()/isotp_rcv_cf(), not already under so->rx_lock
++ * (no isotp_rcv() caller here), so take it ourselves
++ */
++ spin_lock(&so->rx_lock);
++
++ /* so->cfecho may since belong to a new transfer; recheck under lock */
++ if (so->cfecho != *(u32 *)cf->data)
++ goto out_unlock;
++
+ /* cancel local echo timeout */
+- hrtimer_cancel(&so->txtimer);
++ hrtimer_cancel(&so->echotimer);
+
+ /* local echo skb with consecutive frame has been consumed */
+ so->cfecho = 0;
+
++ /* claiming a transfer also takes so->rx_lock, so a plain recheck
++ * is enough: so->tx.state can't have flipped to ISOTP_SENDING for
++ * a new claim while we're still in here
++ */
++ if (so->tx.state != ISOTP_SENDING)
++ goto out_unlock;
++
+ if (so->tx.idx >= so->tx.len) {
+ /* we are done */
+ so->tx.state = ISOTP_IDLE;
+ wake_up_interruptible(&so->wait);
+- return;
++ goto out_unlock;
+ }
+
+ if (so->txfc.bs && so->tx.bs >= so->txfc.bs) {
+@@ -853,53 +888,83 @@ static void isotp_rcv_echo(struct sk_buff *skb, void *data)
+ so->tx.state = ISOTP_WAIT_FC;
+ hrtimer_start(&so->txtimer, ktime_set(ISOTP_FC_TIMEOUT, 0),
+ HRTIMER_MODE_REL_SOFT);
+- return;
++ goto out_unlock;
+ }
+
+ /* no gap between data frames needed => use burst mode */
+ if (!so->tx_gap) {
+ /* enable echo timeout handling */
+- hrtimer_start(&so->txtimer, ktime_set(ISOTP_ECHO_TIMEOUT, 0),
++ hrtimer_start(&so->echotimer, ktime_set(ISOTP_ECHO_TIMEOUT, 0),
+ HRTIMER_MODE_REL_SOFT);
+ isotp_send_cframe(so);
+- return;
++ goto out_unlock;
+ }
+
+ /* start timer to send next consecutive frame with correct delay */
+ hrtimer_start(&so->txfrtimer, so->tx_gap, HRTIMER_MODE_REL_SOFT);
++
++out_unlock:
++ spin_unlock(&so->rx_lock);
+ }
+
+-static enum hrtimer_restart isotp_tx_timer_handler(struct hrtimer *hrtimer)
++/* shared by so->txtimer's and so->echotimer's callbacks. Both timers get
++ * cancelled under so->rx_lock elsewhere, so this must stay lock-free to
++ * avoid deadlocking with that; uses so->tx_gen instead to avoid tainting
++ * a new transfer with an error from the one that just timed out.
++ */
++static enum hrtimer_restart isotp_tx_timeout(struct isotp_sock *so)
+ {
+- struct isotp_sock *so = container_of(hrtimer, struct isotp_sock,
+- txtimer);
+ struct sock *sk = &so->sk;
++ u32 gen = READ_ONCE(so->tx_gen);
++ u32 old_state = READ_ONCE(so->tx.state);
+
+ /* don't handle timeouts in IDLE or SHUTDOWN state */
+- if (so->tx.state == ISOTP_IDLE || so->tx.state == ISOTP_SHUTDOWN)
++ if (old_state == ISOTP_IDLE || old_state == ISOTP_SHUTDOWN)
++ return HRTIMER_NORESTART;
++
++ /* only claim the timeout if the state is still unchanged */
++ if (cmpxchg(&so->tx.state, old_state, ISOTP_IDLE) != old_state)
+ return HRTIMER_NORESTART;
+
+ /* we did not get any flow control or echo frame in time */
+
+- /* report 'communication error on send' */
+- sk->sk_err = ECOMM;
+- if (!sock_flag(sk, SOCK_DEAD))
+- sk_error_report(sk);
++ if (READ_ONCE(so->tx_gen) == gen) {
++ /* report 'communication error on send' */
++ sk->sk_err = ECOMM;
++ if (!sock_flag(sk, SOCK_DEAD))
++ sk_error_report(sk);
++ }
+
+- /* reset tx state */
+- so->tx.state = ISOTP_IDLE;
+ wake_up_interruptible(&so->wait);
+
+ return HRTIMER_NORESTART;
+ }
+
++/* so->txtimer: fires when a Flow Control frame does not arrive in time */
++static enum hrtimer_restart isotp_tx_timer_handler(struct hrtimer *hrtimer)
++{
++ struct isotp_sock *so = container_of(hrtimer, struct isotp_sock,
++ txtimer);
++
++ return isotp_tx_timeout(so);
++}
++
++/* so->echotimer: fires when a sent CF/SF's local echo does not arrive */
++static enum hrtimer_restart isotp_echo_timer_handler(struct hrtimer *hrtimer)
++{
++ struct isotp_sock *so = container_of(hrtimer, struct isotp_sock,
++ echotimer);
++
++ return isotp_tx_timeout(so);
++}
++
+ static enum hrtimer_restart isotp_txfr_timer_handler(struct hrtimer *hrtimer)
+ {
+ struct isotp_sock *so = container_of(hrtimer, struct isotp_sock,
+ txfrtimer);
+
+ /* start echo timeout handling and cover below protocol error */
+- hrtimer_start(&so->txtimer, ktime_set(ISOTP_ECHO_TIMEOUT, 0),
++ hrtimer_start(&so->echotimer, ktime_set(ISOTP_ECHO_TIMEOUT, 0),
+ HRTIMER_MODE_REL_SOFT);
+
+ /* cfecho should be consumed by isotp_rcv_echo() here */
+@@ -919,13 +984,24 @@ static int isotp_sendmsg(struct socket *sock, struct msghdr *msg, size_t size)
+ int ae = (so->opt.flags & CAN_ISOTP_EXTEND_ADDR) ? 1 : 0;
+ int wait_tx_done = (so->opt.flags & CAN_ISOTP_WAIT_TX_DONE) ? 1 : 0;
+ s64 hrtimer_sec = ISOTP_ECHO_TIMEOUT;
++ struct hrtimer *tx_hrt = &so->echotimer;
++ u32 new_state = ISOTP_SENDING;
+ int off;
+ int err;
+
+ if (!so->bound || so->tx.state == ISOTP_SHUTDOWN)
+ return -EADDRNOTAVAIL;
+
+- while (cmpxchg(&so->tx.state, ISOTP_IDLE, ISOTP_SENDING) != ISOTP_IDLE) {
++ /* claim the socket under so->rx_lock: this serializes the claim
++ * with the RX path and with sendmsg()'s own error paths below, so
++ * none of them can ever see a transfer mid-claim
++ */
++ for (;;) {
++ spin_lock_bh(&so->rx_lock);
++ if (READ_ONCE(so->tx.state) == ISOTP_IDLE)
++ break;
++ spin_unlock_bh(&so->rx_lock);
++
+ /* we do not support multiple buffers - for now */
+ if (msg->msg_flags & MSG_DONTWAIT)
+ return -EAGAIN;
+@@ -934,9 +1010,29 @@ static int isotp_sendmsg(struct socket *sock, struct msghdr *msg, size_t size)
+ return -EADDRNOTAVAIL;
+
+ /* wait for complete transmission of current pdu */
+- err = wait_event_interruptible(so->wait, so->tx.state == ISOTP_IDLE);
++ err = wait_event_interruptible(so->wait,
++ so->tx.state == ISOTP_IDLE);
+ if (err)
+- goto err_event_drop;
++ return err;
++ }
++
++ /* new transfer: bump so->tx_gen and drain the old one's timers,
++ * still under the so->rx_lock we just claimed the socket with
++ */
++ WRITE_ONCE(so->tx.state, ISOTP_SENDING);
++ WRITE_ONCE(so->tx_gen, READ_ONCE(so->tx_gen) + 1);
++ hrtimer_cancel(&so->txtimer);
++ hrtimer_cancel(&so->echotimer);
++ hrtimer_cancel(&so->txfrtimer);
++ so->cfecho = 0;
++ spin_unlock_bh(&so->rx_lock);
++
++ /* so->bound is only checked once above - a wakeup may have
++ * unbound/rebound the socket meanwhile, so re-validate it
++ */
++ if (!so->bound) {
++ err = -EADDRNOTAVAIL;
++ goto err_out_drop;
+ }
+
+ if (!size || size > MAX_MSG_LENGTH) {
+@@ -1031,18 +1127,33 @@ static int isotp_sendmsg(struct socket *sock, struct msghdr *msg, size_t size)
+ so->cfecho = *(u32 *)cf->data;
+ } else {
+ /* standard flow control check */
+- so->tx.state = ISOTP_WAIT_FIRST_FC;
++ new_state = ISOTP_WAIT_FIRST_FC;
+
+ /* start timeout for FC */
+ hrtimer_sec = ISOTP_FC_TIMEOUT;
++ tx_hrt = &so->txtimer;
+
+ /* no CF echo tag for isotp_rcv_echo() (FF-mode) */
+ so->cfecho = 0;
+ }
+ }
+
+- hrtimer_start(&so->txtimer, ktime_set(hrtimer_sec, 0),
++ spin_lock_bh(&so->rx_lock);
++ if (so->tx.state == ISOTP_SHUTDOWN) {
++ /* isotp_release() has since taken over and already drained
++ * our timers - don't send into a socket that's going away
++ */
++ spin_unlock_bh(&so->rx_lock);
++ kfree_skb(skb);
++ dev_put(dev);
++ wake_up_interruptible(&so->wait);
++ return -EADDRNOTAVAIL;
++ }
++ /* WAIT_FIRST_FC for standard FF, else stays ISOTP_SENDING */
++ so->tx.state = new_state;
++ hrtimer_start(tx_hrt, ktime_set(hrtimer_sec, 0),
+ HRTIMER_MODE_REL_SOFT);
++ spin_unlock_bh(&so->rx_lock);
+
+ /* send the first or only CAN frame */
+ cf->flags = so->ll.tx_flags;
+@@ -1055,13 +1166,10 @@ static int isotp_sendmsg(struct socket *sock, struct msghdr *msg, size_t size)
+ pr_notice_once("can-isotp: %s: can_send_ret %pe\n",
+ __func__, ERR_PTR(err));
+
++ spin_lock_bh(&so->rx_lock);
+ /* no transmission -> no timeout monitoring */
+- hrtimer_cancel(&so->txtimer);
+-
+- /* reset consecutive frame echo tag */
+- so->cfecho = 0;
+-
+- goto err_out_drop;
++ hrtimer_cancel(tx_hrt);
++ goto err_out_drop_locked;
+ }
+
+ if (wait_tx_done) {
+@@ -1077,14 +1185,21 @@ static int isotp_sendmsg(struct socket *sock, struct msghdr *msg, size_t size)
+
+ return size;
+
++err_out_drop:
++ /* claimed but nothing sent yet - no timer to cancel */
++ spin_lock_bh(&so->rx_lock);
++ goto err_out_drop_locked;
+ err_event_drop:
+- /* got signal: force tx state machine to be idle */
+- so->tx.state = ISOTP_IDLE;
++ /* interrupted waiting on our own transfer - drain its timers */
++ spin_lock_bh(&so->rx_lock);
+ hrtimer_cancel(&so->txfrtimer);
+ hrtimer_cancel(&so->txtimer);
+-err_out_drop:
+- /* drop this PDU and unlock a potential wait queue */
++ hrtimer_cancel(&so->echotimer);
++err_out_drop_locked:
++ /* release the claim; so->rx_lock still held from above */
++ so->cfecho = 0;
+ so->tx.state = ISOTP_IDLE;
++ spin_unlock_bh(&so->rx_lock);
+ wake_up_interruptible(&so->wait);
+
+ return err;
+@@ -1146,13 +1261,20 @@ static int isotp_release(struct socket *sock)
+ so = isotp_sk(sk);
+ net = sock_net(sk);
+
+- /* wait for complete transmission of current pdu */
+- while (wait_event_interruptible(so->wait, so->tx.state == ISOTP_IDLE) == 0 &&
+- cmpxchg(&so->tx.state, ISOTP_IDLE, ISOTP_SHUTDOWN) != ISOTP_IDLE)
++ /* best-effort: wait for a running pdu to finish, but don't block on
++ * it forever - give up after the first signal
++ */
++ while (so->tx.state != ISOTP_IDLE &&
++ wait_event_interruptible(so->wait, so->tx.state == ISOTP_IDLE) == 0)
+ ;
+
+- /* force state machines to be idle also when a signal occurred */
++ /* claim the socket under so->rx_lock like sendmsg() does, so its
++ * claim can't race the forced ISOTP_SHUTDOWN below; force it
++ * unconditionally, even when a signal cut the wait above short
++ */
++ spin_lock_bh(&so->rx_lock);
+ so->tx.state = ISOTP_SHUTDOWN;
++ spin_unlock_bh(&so->rx_lock);
+ so->rx.state = ISOTP_IDLE;
+
+ spin_lock(&isotp_notifier_lock);
+@@ -1164,28 +1286,30 @@ static int isotp_release(struct socket *sock)
+ list_del(&so->notifier);
+ spin_unlock(&isotp_notifier_lock);
+
++ rtnl_lock();
+ lock_sock(sk);
+
+- /* remove current filters & unregister */
+- if (so->bound) {
+- if (so->ifindex) {
+- struct net_device *dev;
+-
+- dev = dev_get_by_index(net, so->ifindex);
+- if (dev) {
+- if (isotp_register_rxid(so))
+- can_rx_unregister(net, dev, so->rxid,
+- SINGLE_MASK(so->rxid),
+- isotp_rcv, sk);
+-
+- can_rx_unregister(net, dev, so->txid,
+- SINGLE_MASK(so->txid),
+- isotp_rcv_echo, sk);
+- dev_put(dev);
+- }
+- }
++ /* remove current filters & unregister
++ * tracked reference so->dev is taken at bind() time with rtnl_lock
++ */
++ if (so->bound && so->dev) {
++ if (isotp_register_rxid(so))
++ can_rx_unregister(net, so->dev, so->rxid,
++ SINGLE_MASK(so->rxid),
++ isotp_rcv, sk);
++
++ can_rx_unregister(net, so->dev, so->txid,
++ SINGLE_MASK(so->txid),
++ isotp_rcv_echo, sk);
++ dev_put(so->dev);
+ }
+
++ so->ifindex = 0;
++ so->bound = 0;
++ so->dev = NULL;
++
++ rtnl_unlock();
++
+ /* Always wait for a grace period before touching the timers below.
+ * A concurrent NETDEV_UNREGISTER may have already unregistered our
+ * filters and cleared so->bound in isotp_notify() without waiting
+@@ -1196,11 +1320,9 @@ static int isotp_release(struct socket *sock)
+
+ hrtimer_cancel(&so->txfrtimer);
+ hrtimer_cancel(&so->txtimer);
++ hrtimer_cancel(&so->echotimer);
+ hrtimer_cancel(&so->rxtimer);
+
+- so->ifindex = 0;
+- so->bound = 0;
+-
+ sock_orphan(sk);
+ sock->sk = NULL;
+
+@@ -1254,6 +1376,7 @@ static int isotp_bind(struct socket *sock, struct sockaddr *uaddr, int len)
+ if (!addr->can_ifindex)
+ return -ENODEV;
+
++ rtnl_lock();
+ lock_sock(sk);
+
+ if (so->bound) {
+@@ -1261,6 +1384,17 @@ static int isotp_bind(struct socket *sock, struct sockaddr *uaddr, int len)
+ goto out;
+ }
+
++ /* A transmission or reception that outlived a previous binding
++ * (unbound by NETDEV_UNREGISTER) may still be draining; the FC/echo
++ * and RX watchdog timers bound how long this takes. Checked together
++ * with so->bound in the same lock_sock() section above, so there is
++ * no window in which a concurrent isotp_notify() could be missed.
++ */
++ if (so->tx.state != ISOTP_IDLE || so->rx.state != ISOTP_IDLE) {
++ err = -EAGAIN;
++ goto out;
++ }
++
+ /* ensure different CAN IDs when the rx_id is to be registered */
+ if (isotp_register_rxid(so) && rx_id == tx_id) {
+ err = -EADDRNOTAVAIL;
+@@ -1273,14 +1407,12 @@ static int isotp_bind(struct socket *sock, struct sockaddr *uaddr, int len)
+ goto out;
+ }
+ if (dev->type != ARPHRD_CAN) {
+- dev_put(dev);
+ err = -ENODEV;
+- goto out;
++ goto out_put_dev;
+ }
+- if (dev->mtu < so->ll.mtu) {
+- dev_put(dev);
++ if (READ_ONCE(dev->mtu) < so->ll.mtu) {
+ err = -EINVAL;
+- goto out;
++ goto out_put_dev;
+ }
+ if (!(dev->flags & IFF_UP))
+ notify_enetdown = 1;
+@@ -1298,16 +1430,25 @@ static int isotp_bind(struct socket *sock, struct sockaddr *uaddr, int len)
+ can_rx_register(net, dev, tx_id, SINGLE_MASK(tx_id),
+ isotp_rcv_echo, sk, "isotpe", sk);
+
+- dev_put(dev);
+-
+ /* switch to new settings */
+ so->ifindex = ifindex;
+ so->rxid = rx_id;
+ so->txid = tx_id;
+ so->bound = 1;
+
++ /* bind() ok -> hold a reference for so->dev so that isotp_release()
++ * can safely reach the device later, even if a concurrent
++ * NETDEV_UNREGISTER has already unlisted it by ifindex.
++ */
++ so->dev = dev;
++ dev_hold(so->dev);
++
++out_put_dev:
++ /* remove potential reference from dev_get_by_index() */
++ dev_put(dev);
+ out:
+ release_sock(sk);
++ rtnl_unlock();
+
+ if (notify_enetdown) {
+ sk->sk_err = ENETDOWN;
+@@ -1510,7 +1651,7 @@ static void isotp_notify(struct isotp_sock *so, unsigned long msg,
+ if (!net_eq(dev_net(dev), sock_net(sk)))
+ return;
+
+- if (so->ifindex != dev->ifindex)
++ if (so->dev != dev)
+ return;
+
+ switch (msg) {
+@@ -1526,10 +1667,12 @@ static void isotp_notify(struct isotp_sock *so, unsigned long msg,
+ can_rx_unregister(dev_net(dev), dev, so->txid,
+ SINGLE_MASK(so->txid),
+ isotp_rcv_echo, sk);
++ dev_put(so->dev);
+ }
+
+ so->ifindex = 0;
+ so->bound = 0;
++ so->dev = NULL;
+ release_sock(sk);
+
+ sk->sk_err = ENODEV;
+@@ -1574,6 +1717,7 @@ static int isotp_init(struct sock *sk)
+
+ so->ifindex = 0;
+ so->bound = 0;
++ so->dev = NULL;
+
+ so->opt.flags = CAN_ISOTP_DEFAULT_FLAGS;
+ so->opt.ext_address = CAN_ISOTP_DEFAULT_EXT_ADDRESS;
+@@ -1599,6 +1743,8 @@ static int isotp_init(struct sock *sk)
+ so->rxtimer.function = isotp_rx_timer_handler;
+ hrtimer_init(&so->txtimer, CLOCK_MONOTONIC, HRTIMER_MODE_REL_SOFT);
+ so->txtimer.function = isotp_tx_timer_handler;
++ hrtimer_init(&so->echotimer, CLOCK_MONOTONIC, HRTIMER_MODE_REL_SOFT);
++ so->echotimer.function = isotp_echo_timer_handler;
+ hrtimer_init(&so->txfrtimer, CLOCK_MONOTONIC, HRTIMER_MODE_REL_SOFT);
+ so->txfrtimer.function = isotp_txfr_timer_handler;
+
+@@ -1679,13 +1825,18 @@ static __init int isotp_module_init(void)
+
+ pr_info("can: isotp protocol\n");
+
++ err = register_netdevice_notifier(&canisotp_notifier);
++ if (err)
++ return err;
++
+ err = can_proto_register(&isotp_can_proto);
+- if (err < 0)
++ if (err < 0) {
+ pr_err("can: registration of isotp protocol failed %pe\n", ERR_PTR(err));
+- else
+- register_netdevice_notifier(&canisotp_notifier);
++ unregister_netdevice_notifier(&canisotp_notifier);
++ return err;
++ }
+
+- return err;
++ return 0;
+ }
+
+ static __exit void isotp_module_exit(void)
+diff --git a/net/can/j1939/bus.c b/net/can/j1939/bus.c
+index e0b966c2517cf1..aabe4fa9154301 100644
+--- a/net/can/j1939/bus.c
++++ b/net/can/j1939/bus.c
+@@ -20,6 +20,7 @@ static void __j1939_ecu_release(struct kref *kref)
+ struct j1939_priv *priv = ecu->priv;
+
+ list_del(&ecu->list);
++ netdev_put(priv->ndev, &ecu->priv_dev_tracker);
+ kfree(ecu);
+ j1939_priv_put(priv);
+ }
+@@ -155,6 +156,7 @@ struct j1939_ecu *j1939_ecu_create_locked(struct j1939_priv *priv, name_t name)
+ if (!ecu)
+ return ERR_PTR(-ENOMEM);
+ kref_init(&ecu->kref);
++ netdev_hold(priv->ndev, &ecu->priv_dev_tracker, gfp_any());
+ ecu->addr = J1939_IDLE_ADDR;
+ ecu->name = name;
+
+diff --git a/net/can/j1939/j1939-priv.h b/net/can/j1939/j1939-priv.h
+index 31a93cae5111b5..1d3d5d0551e0f3 100644
+--- a/net/can/j1939/j1939-priv.h
++++ b/net/can/j1939/j1939-priv.h
+@@ -38,6 +38,7 @@ struct j1939_ecu {
+ struct hrtimer ac_timer;
+ struct kref kref;
+ struct j1939_priv *priv;
++ netdevice_tracker priv_dev_tracker;
+
+ /* count users, to help transport protocol decide for interaction */
+ int nusers;
+@@ -60,6 +61,7 @@ struct j1939_priv {
+ rwlock_t lock;
+
+ struct net_device *ndev;
++ netdevice_tracker dev_tracker;
+
+ /* list of 256 ecu ptrs, that cache the claimed addresses.
+ * also protected by the above lock
+@@ -229,6 +231,7 @@ enum j1939_session_state {
+
+ struct j1939_session {
+ struct j1939_priv *priv;
++ netdevice_tracker priv_dev_tracker;
+ struct list_head active_session_list_entry;
+ struct list_head sk_session_queue_entry;
+ struct kref kref;
+diff --git a/net/can/j1939/main.c b/net/can/j1939/main.c
+index 7e8a20f2fc42b5..b45f834ff2cf63 100644
+--- a/net/can/j1939/main.c
++++ b/net/can/j1939/main.c
+@@ -137,7 +137,7 @@ static struct j1939_priv *j1939_priv_create(struct net_device *ndev)
+ priv->ndev = ndev;
+ kref_init(&priv->kref);
+ kref_init(&priv->rx_kref);
+- dev_hold(ndev);
++ netdev_hold(ndev, &priv->dev_tracker, GFP_KERNEL);
+
+ netdev_dbg(priv->ndev, "%s : 0x%p\n", __func__, priv);
+
+@@ -163,7 +163,7 @@ static void __j1939_priv_release(struct kref *kref)
+ WARN_ON_ONCE(!list_empty(&priv->ecus));
+ WARN_ON_ONCE(!list_empty(&priv->j1939_socks));
+
+- dev_put(ndev);
++ netdev_put(ndev, &priv->dev_tracker);
+ kfree(priv);
+ }
+
+@@ -281,7 +281,7 @@ struct j1939_priv *j1939_netdev_start(struct net_device *ndev)
+ */
+ kref_get(&priv_new->rx_kref);
+ mutex_unlock(&j1939_netdev_lock);
+- dev_put(ndev);
++ netdev_put(ndev, &priv->dev_tracker);
+ kfree(priv);
+ return priv_new;
+ }
+@@ -298,7 +298,7 @@ struct j1939_priv *j1939_netdev_start(struct net_device *ndev)
+ j1939_priv_set(ndev, NULL);
+ mutex_unlock(&j1939_netdev_lock);
+
+- dev_put(ndev);
++ netdev_put(ndev, &priv->dev_tracker);
+ kfree(priv);
+
+ return ERR_PTR(ret);
+diff --git a/net/can/j1939/transport.c b/net/can/j1939/transport.c
+index e17a166a73c422..b11febe2b5fbba 100644
+--- a/net/can/j1939/transport.c
++++ b/net/can/j1939/transport.c
+@@ -282,6 +282,7 @@ static void j1939_session_destroy(struct j1939_session *session)
+ kfree_skb(skb);
+ }
+ __j1939_session_drop(session);
++ netdev_put(session->priv->ndev, &session->priv_dev_tracker);
+ j1939_priv_put(session->priv);
+ kfree(session);
+ }
+@@ -350,6 +351,18 @@ static void j1939_session_skb_drop_old(struct j1939_session *session)
+ }
+ }
+
++static bool j1939_address_is_local(struct j1939_priv *priv, u8 addr)
++{
++ bool local = false;
++
++ read_lock_bh(&priv->lock);
++ if (j1939_address_is_unicast(addr) && priv->ents[addr].nusers)
++ local = true;
++ read_unlock_bh(&priv->lock);
++
++ return local;
++}
++
+ void j1939_session_skb_queue(struct j1939_session *session,
+ struct sk_buff *skb)
+ {
+@@ -358,8 +371,7 @@ void j1939_session_skb_queue(struct j1939_session *session,
+
+ j1939_ac_fixup(priv, skb);
+
+- if (j1939_address_is_unicast(skcb->addr.da) &&
+- priv->ents[skcb->addr.da].nusers)
++ if (j1939_address_is_local(priv, skcb->addr.da))
+ skcb->flags |= J1939_ECU_LOCAL_DST;
+
+ skcb->flags |= J1939_ECU_LOCAL_SRC;
+@@ -1499,6 +1511,7 @@ static struct j1939_session *j1939_session_new(struct j1939_priv *priv,
+ INIT_LIST_HEAD(&session->active_session_list_entry);
+ INIT_LIST_HEAD(&session->sk_session_queue_entry);
+ kref_init(&session->kref);
++ netdev_hold(priv->ndev, &session->priv_dev_tracker, gfp_any());
+
+ j1939_priv_get(priv);
+ session->priv = priv;
+@@ -1551,7 +1564,7 @@ j1939_session *j1939_session_fresh_new(struct j1939_priv *priv,
+ }
+
+ /* alloc data area */
+- skb_put(skb, size);
++ skb_put_zero(skb, size);
+ /* skb is recounted in j1939_session_new() */
+ return session;
+ }
+@@ -2021,8 +2034,7 @@ struct j1939_session *j1939_tp_send(struct j1939_priv *priv,
+ return ERR_PTR(ret);
+
+ /* fix DST flags, it may be used there soon */
+- if (j1939_address_is_unicast(skcb->addr.da) &&
+- priv->ents[skcb->addr.da].nusers)
++ if (j1939_address_is_local(priv, skcb->addr.da))
+ skcb->flags |= J1939_ECU_LOCAL_DST;
+
+ /* src is always local, I'm sending ... */
+diff --git a/net/ceph/auth_x.c b/net/ceph/auth_x.c
+index a21c157daf7dd3..c83559f015e465 100644
+--- a/net/ceph/auth_x.c
++++ b/net/ceph/auth_x.c
+@@ -781,9 +781,16 @@ static int ceph_x_update_authorizer(
+
+ au = (struct ceph_x_authorizer *)auth->authorizer;
+ if (au->secret_id < th->secret_id) {
++ int ret;
++
+ dout("ceph_x_update_authorizer service %u secret %llu < %llu\n",
+ au->service, au->secret_id, th->secret_id);
+- return ceph_x_build_authorizer(ac, th, au);
++ ret = ceph_x_build_authorizer(ac, th, au);
++ if (ret)
++ return ret;
++
++ auth->authorizer_buf = au->buf->vec.iov_base;
++ auth->authorizer_buf_len = au->buf->vec.iov_len;
+ }
+ return 0;
+ }
+diff --git a/net/ceph/ceph_common.c b/net/ceph/ceph_common.c
+index 285e981730e5cb..15bba470960d8b 100644
+--- a/net/ceph/ceph_common.c
++++ b/net/ceph/ceph_common.c
+@@ -763,13 +763,13 @@ void ceph_destroy_client(struct ceph_client *client)
+
+ atomic_set(&client->msgr.stopping, 1);
+
++ ceph_debugfs_client_cleanup(client);
++
+ /* unmount */
+ ceph_osdc_stop(&client->osdc);
+ ceph_monc_stop(&client->monc);
+ ceph_messenger_fini(&client->msgr);
+
+- ceph_debugfs_client_cleanup(client);
+-
+ ceph_destroy_options(client->options);
+
+ kfree(client);
+diff --git a/net/ceph/mon_client.c b/net/ceph/mon_client.c
+index c5133c0b2ddf19..a5db42c3c3cdcc 100644
+--- a/net/ceph/mon_client.c
++++ b/net/ceph/mon_client.c
+@@ -114,7 +114,7 @@ static struct ceph_monmap *ceph_monmap_decode(void **p, void *end, bool msgr2)
+
+ dout("%s fsid %pU epoch %u num_mon %u\n", __func__, &fsid, epoch,
+ num_mon);
+- if (num_mon > CEPH_MAX_MON)
++ if (num_mon == 0 || num_mon > CEPH_MAX_MON)
+ goto e_inval;
+
+ monmap = kmalloc(struct_size(monmap, mon_inst, num_mon), GFP_NOIO);
+@@ -821,7 +821,7 @@ static void handle_get_version_reply(struct ceph_mon_client *monc,
+ struct ceph_mon_generic_request *req;
+ u64 tid = le64_to_cpu(msg->hdr.tid);
+ void *p = msg->front.iov_base;
+- void *end = p + msg->front_alloc_len;
++ void *const end = p + msg->front.iov_len;
+ u64 handle;
+
+ dout("%s msg %p tid %llu\n", __func__, msg, tid);
+diff --git a/net/ceph/osdmap.c b/net/ceph/osdmap.c
+index c34a5bf86831b3..30d75970be4496 100644
+--- a/net/ceph/osdmap.c
++++ b/net/ceph/osdmap.c
+@@ -520,6 +520,8 @@ static struct crush_map *crush_decode(void *pbyval, void *end)
+ ceph_decode_need(p, end, 4*sizeof(u32), bad);
+ b->id = ceph_decode_32(p);
+ b->type = ceph_decode_16(p);
++ if (b->type == 0)
++ goto bad;
+ b->alg = ceph_decode_8(p);
+ if (b->alg != alg) {
+ b->alg = 0;
+@@ -1844,6 +1846,8 @@ static int decode_new_up_state_weight(void **p, void *end, u8 struct_v,
+ void *new_up_client;
+ void *new_state;
+ void *new_weight_end;
++ const u32 new_state_item_size =
++ sizeof(u32) + (struct_v >= 5 ? sizeof(u32) : sizeof(u8));
+ u32 len;
+ int ret;
+ int i;
+@@ -1864,7 +1868,8 @@ static int decode_new_up_state_weight(void **p, void *end, u8 struct_v,
+
+ new_state = *p;
+ ceph_decode_32_safe(p, end, len, e_inval);
+- len *= sizeof(u32) + (struct_v >= 5 ? sizeof(u32) : sizeof(u8));
++ if (check_mul_overflow(len, new_state_item_size, &len))
++ goto e_inval;
+ ceph_decode_need(p, end, len, e_inval);
+ *p += len;
+
+@@ -3057,8 +3062,11 @@ static int get_immediate_parent(struct crush_map *c, int id,
+ if (b->items[j] != id)
+ continue;
+
+- *parent_type_id = b->type;
+ type_cn = lookup_crush_name(&c->type_names, b->type);
++ if (WARN_ON_ONCE(!type_cn))
++ continue;
++
++ *parent_type_id = b->type;
+ parent_loc->cl_type_name = type_cn->cn_name;
+ parent_loc->cl_name = cn->cn_name;
+ return b->id;
+diff --git a/net/core/dst_cache.c b/net/core/dst_cache.c
+index 0ccfd5fa5cb9b5..b17171345d649b 100644
+--- a/net/core/dst_cache.c
++++ b/net/core/dst_cache.c
+@@ -112,7 +112,7 @@ void dst_cache_set_ip6(struct dst_cache *dst_cache, struct dst_entry *dst,
+
+ idst = this_cpu_ptr(dst_cache->cache);
+ dst_cache_per_cpu_dst_set(this_cpu_ptr(dst_cache->cache), dst,
+- rt6_get_cookie((struct rt6_info *)dst));
++ rt6_get_cookie(dst_rt6_info(dst)));
+ idst->in6_saddr = *saddr;
+ }
+ EXPORT_SYMBOL_GPL(dst_cache_set_ip6);
+diff --git a/net/core/filter.c b/net/core/filter.c
+index ce9f079d46e3b3..91d337252fc90b 100644
+--- a/net/core/filter.c
++++ b/net/core/filter.c
+@@ -2226,7 +2226,7 @@ static int bpf_out_neigh_v6(struct net *net, struct sk_buff *skb,
+ rcu_read_lock();
+ if (!nh) {
+ dst = skb_dst(skb);
+- nexthop = rt6_nexthop(container_of(dst, struct rt6_info, dst),
++ nexthop = rt6_nexthop(dst_rt6_info(dst),
+ &ipv6_hdr(skb)->daddr);
+ } else {
+ nexthop = &nh->ipv6_nh;
+diff --git a/net/core/lwt_bpf.c b/net/core/lwt_bpf.c
+index efbd9eecb00d17..c5b90a309685ec 100644
+--- a/net/core/lwt_bpf.c
++++ b/net/core/lwt_bpf.c
+@@ -246,8 +246,10 @@ static int bpf_lwt_xmit_reroute(struct sk_buff *skb)
+ * if there is enough header space in skb.
+ */
+ err = skb_cow_head(skb, LL_RESERVED_SPACE(dst->dev));
+- if (unlikely(err))
++ if (unlikely(err)) {
++ dst_release(dst);
+ goto err;
++ }
+
+ skb_dst_drop(skb);
+ skb_dst_set(skb, dst);
+diff --git a/net/core/sock.c b/net/core/sock.c
+index 5f79f0b78321c8..2a701e0b052b79 100644
+--- a/net/core/sock.c
++++ b/net/core/sock.c
+@@ -772,7 +772,6 @@ bool sk_mc_loop(struct sock *sk)
+ return inet6_sk(sk)->mc_loop;
+ #endif
+ }
+- WARN_ON_ONCE(1);
+ return true;
+ }
+ EXPORT_SYMBOL(sk_mc_loop);
+diff --git a/net/core/sock_map.c b/net/core/sock_map.c
+index f4cca477b0477e..fb10c33acc3fd2 100644
+--- a/net/core/sock_map.c
++++ b/net/core/sock_map.c
+@@ -542,6 +542,8 @@ static bool sock_map_sk_state_allowed(const struct sock *sk)
+ {
+ if (sk_is_tcp(sk))
+ return (1 << sk->sk_state) & (TCPF_ESTABLISHED | TCPF_LISTEN);
++ if (sk_is_udp(sk))
++ return sk_hashed(sk);
+ if (sk_is_stream_unix(sk))
+ return (1 << sk->sk_state) & TCPF_ESTABLISHED;
+ return true;
+diff --git a/net/core/xdp.c b/net/core/xdp.c
+index 90de33b7c9ce3e..8a9c06dfe7a9ef 100644
+--- a/net/core/xdp.c
++++ b/net/core/xdp.c
+@@ -688,7 +688,7 @@ struct xdp_frame *xdpf_clone(struct xdp_frame *xdpf)
+ headroom = xdpf->headroom + sizeof(*xdpf);
+ totalsize = headroom + xdpf->len;
+
+- if (unlikely(totalsize > PAGE_SIZE))
++ if (unlikely(totalsize > SKB_WITH_OVERHEAD(PAGE_SIZE)))
+ return NULL;
+ page = dev_alloc_page();
+ if (!page)
+diff --git a/net/hsr/hsr_slave.c b/net/hsr/hsr_slave.c
+index b8230faa567f77..58e757dc555461 100644
+--- a/net/hsr/hsr_slave.c
++++ b/net/hsr/hsr_slave.c
+@@ -228,6 +228,8 @@ void hsr_del_port(struct hsr_port *port)
+ netdev_rx_handler_unregister(port->dev);
+ if (!port->hsr->fwd_offloaded)
+ dev_set_promiscuity(port->dev, -1);
++ if (port->type == HSR_PT_SLAVE_A || port->type == HSR_PT_SLAVE_B)
++ vlan_vids_del_by_dev(port->dev, master->dev);
+ netdev_upper_dev_unlink(port->dev, master->dev);
+ }
+
+diff --git a/net/ipv4/fib_semantics.c b/net/ipv4/fib_semantics.c
+index e3268615a65a1b..674062511ce0de 100644
+--- a/net/ipv4/fib_semantics.c
++++ b/net/ipv4/fib_semantics.c
+@@ -462,6 +462,34 @@ int ip_fib_check_default(__be32 gw, struct net_device *dev)
+ return -1;
+ }
+
++static size_t fib_nexthop_nlmsg_size(const struct fib_nh_common *nhc,
++ bool skip_oif)
++{
++ size_t nhsize = 0;
++
++ switch (nhc->nhc_gw_family) {
++ case AF_INET:
++ nhsize += nla_total_size(4); /* RTA_GATEWAY */
++ break;
++ case AF_INET6:
++ nhsize += nla_total_size(sizeof(struct rtvia) +
++ sizeof(struct in6_addr));
++ break;
++ }
++
++ if (!skip_oif && nhc->nhc_dev)
++ nhsize += nla_total_size(4); /* RTA_OIF */
++
++ if (nhc->nhc_lwtstate) {
++ /* RTA_ENCAP */
++ nhsize += lwtunnel_get_encap_size(nhc->nhc_lwtstate);
++ /* RTA_ENCAP_TYPE */
++ nhsize += nla_total_size(2);
++ }
++
++ return nhsize;
++}
++
+ size_t fib_nlmsg_size(struct fib_info *fi)
+ {
+ size_t payload = NLMSG_ALIGN(sizeof(struct rtmsg))
+@@ -479,32 +507,35 @@ size_t fib_nlmsg_size(struct fib_info *fi)
+ payload += nla_total_size(4); /* RTA_NH_ID */
+
+ if (nhs) {
+- size_t nh_encapsize = 0;
+- /* Also handles the special case nhs == 1 */
+-
+- /* each nexthop is packed in an attribute */
+- size_t nhsize = nla_total_size(sizeof(struct rtnexthop));
++ size_t mpsize = 0;
+ unsigned int i;
+
+- /* may contain flow and gateway attribute */
+- nhsize += 2 * nla_total_size(4);
+-
+- /* grab encap info */
+ for (i = 0; i < fib_info_num_path(fi); i++) {
+ struct fib_nh_common *nhc = fib_info_nhc(fi, i);
++ size_t nhsize;
++
++ nhsize = fib_nexthop_nlmsg_size(nhc, nhs != 1);
++
++ if (nhs != 1)
++ nhsize += NLA_ALIGN(sizeof(struct rtnexthop));
++
++#ifdef CONFIG_IP_ROUTE_CLASSID
++ if (nhc->nhc_family == AF_INET) {
++ struct fib_nh *nh;
+
+- if (nhc->nhc_lwtstate) {
+- /* RTA_ENCAP_TYPE */
+- nh_encapsize += lwtunnel_get_encap_size(
+- nhc->nhc_lwtstate);
+- /* RTA_ENCAP */
+- nh_encapsize += nla_total_size(2);
++ nh = container_of(nhc, struct fib_nh, nh_common);
++ if (nh->nh_tclassid)
++ nhsize += nla_total_size(4);
+ }
++#endif
++ if (nhs == 1)
++ payload += nhsize;
++ else
++ mpsize += nhsize;
+ }
+
+- /* all nexthops are packed in a nested attribute */
+- payload += nla_total_size((nhs * nhsize) + nh_encapsize);
+-
++ if (nhs != 1)
++ payload += nla_total_size(mpsize);
+ }
+
+ return payload;
+@@ -1927,42 +1958,30 @@ static int call_fib_nh_notifiers(struct fib_nh *nh,
+ return NOTIFY_DONE;
+ }
+
+-/* Update the PMTU of exceptions when:
+- * - the new MTU of the first hop becomes smaller than the PMTU
+- * - the old MTU was the same as the PMTU, and it limited discovery of
+- * larger MTUs on the path. With that limit raised, we can now
+- * discover larger MTUs
+- * A special case is locked exceptions, for which the PMTU is smaller
+- * than the minimal accepted PMTU:
+- * - if the new MTU is greater than the PMTU, don't make any change
+- * - otherwise, unlock and set PMTU
++/* Walk the exceptions of a nexthop after its first hop MTU changed. The
++ * chain is RCU protected here, while fnhe_update_pmtu() takes fnhe_lock
++ * for the update of each entry.
+ */
+ void fib_nhc_update_mtu(struct fib_nh_common *nhc, u32 new, u32 orig)
+ {
+ struct fnhe_hash_bucket *bucket;
+ int i;
+
+- bucket = rcu_dereference_protected(nhc->nhc_exceptions, 1);
++ rcu_read_lock();
++ bucket = rcu_dereference(nhc->nhc_exceptions);
+ if (!bucket)
+- return;
++ goto out;
+
+ for (i = 0; i < FNHE_HASH_SIZE; i++) {
+ struct fib_nh_exception *fnhe;
+
+- for (fnhe = rcu_dereference_protected(bucket[i].chain, 1);
++ for (fnhe = rcu_dereference(bucket[i].chain);
+ fnhe;
+- fnhe = rcu_dereference_protected(fnhe->fnhe_next, 1)) {
+- if (fnhe->fnhe_mtu_locked) {
+- if (new <= fnhe->fnhe_pmtu) {
+- fnhe->fnhe_pmtu = new;
+- fnhe->fnhe_mtu_locked = false;
+- }
+- } else if (new < fnhe->fnhe_pmtu ||
+- orig == fnhe->fnhe_pmtu) {
+- fnhe->fnhe_pmtu = new;
+- }
+- }
++ fnhe = rcu_dereference(fnhe->fnhe_next))
++ fnhe_update_pmtu(fnhe, new, orig);
+ }
++out:
++ rcu_read_unlock();
+ }
+
+ void fib_sync_mtu(struct net_device *dev, u32 orig_mtu)
+diff --git a/net/ipv4/fib_trie.c b/net/ipv4/fib_trie.c
+index c9e1526e749b2b..53e7664eeb0a2a 100644
+--- a/net/ipv4/fib_trie.c
++++ b/net/ipv4/fib_trie.c
+@@ -1390,7 +1390,7 @@ succeeded:
+ out_remove_new_fa:
+ fib_remove_alias(t, tp, l, new_fa);
+ out_free_new_fa:
+- kmem_cache_free(fn_alias_kmem, new_fa);
++ alias_free_mem_rcu(new_fa);
+ out:
+ fib_release_info(fi);
+ err:
+diff --git a/net/ipv4/icmp.c b/net/ipv4/icmp.c
+index a9aef281631ee0..e8c59c2051c2de 100644
+--- a/net/ipv4/icmp.c
++++ b/net/ipv4/icmp.c
+@@ -536,11 +536,23 @@ static struct rtable *icmp_route_lookup(struct net *net, struct flowi4 *fl4,
+ if (IS_ERR(rt2))
+ err = PTR_ERR(rt2);
+ } else {
+- struct flowi4 fl4_2 = {};
++ struct flowi4 fl4_2 = fl4_dec;
+ unsigned long orefdst;
+
+- fl4_2.daddr = fl4_dec.saddr;
+- rt2 = ip_route_output_key(net, &fl4_2);
++ swap(fl4_2.daddr, fl4_2.saddr);
++ switch (fl4_2.flowi4_proto) {
++ case IPPROTO_TCP:
++ case IPPROTO_UDP:
++ case IPPROTO_SCTP:
++ case IPPROTO_DCCP:
++ swap(fl4_2.fl4_sport, fl4_2.fl4_dport);
++ break;
++ }
++
++ fl4_2.flowi4_oif = l3mdev_master_ifindex(route_lookup_dev);
++ fl4_2.flowi4_flags |= FLOWI_FLAG_ANYSRC;
++
++ rt2 = __ip_route_output_key(net, &fl4_2);
+ if (IS_ERR(rt2)) {
+ err = PTR_ERR(rt2);
+ goto relookup_failed;
+diff --git a/net/ipv4/inet_connection_sock.c b/net/ipv4/inet_connection_sock.c
+index a275ab5321a96a..a0014311c520cc 100644
+--- a/net/ipv4/inet_connection_sock.c
++++ b/net/ipv4/inet_connection_sock.c
+@@ -927,11 +927,23 @@ static struct request_sock *inet_reqsk_clone(struct request_sock *req,
+
+ nreq->rsk_listener = sk;
+
+- /* We need not acquire fastopenq->lock
+- * because the child socket is locked in inet_csk_listen_stop().
+- */
+- if (sk->sk_protocol == IPPROTO_TCP && tcp_rsk(nreq)->tfo_listener)
++ if (sk->sk_protocol == IPPROTO_TCP && tcp_rsk(nreq)->tfo_listener) {
++ struct fastopen_queue *fastopenq;
++
++ /* reqsk_fastopen_remove() will uncharge nreq->rsk_listener,
++ * that is @sk, so charge it here. Unlike the listener
++ * being closed, @sk is live and needs its lock.
++ */
++ fastopenq = &inet_csk(sk)->icsk_accept_queue.fastopenq;
++ spin_lock_bh(&fastopenq->lock);
++ fastopenq->qlen++;
++ spin_unlock_bh(&fastopenq->lock);
++
++ /* We need not acquire fastopenq->lock
++ * because the child socket is locked in inet_csk_listen_stop().
++ */
+ rcu_assign_pointer(tcp_sk(nreq->sk)->fastopen_rsk, nreq);
++ }
+
+ return nreq;
+ }
+diff --git a/net/ipv4/ip_tunnel.c b/net/ipv4/ip_tunnel.c
+index dcf9e9c52a22a6..5dfb007f7792d7 100644
+--- a/net/ipv4/ip_tunnel.c
++++ b/net/ipv4/ip_tunnel.c
+@@ -544,7 +544,7 @@ static int tnl_update_pmtu(struct net_device *dev, struct sk_buff *skb,
+ struct rt6_info *rt6;
+ __be32 daddr;
+
+- rt6 = skb_valid_dst(skb) ? (struct rt6_info *)skb_dst(skb) :
++ rt6 = skb_valid_dst(skb) ? dst_rt6_info(skb_dst(skb)) :
+ NULL;
+ daddr = md ? dst : tunnel->parms.iph.daddr;
+
+diff --git a/net/ipv4/nexthop.c b/net/ipv4/nexthop.c
+index 49871e5f46802d..13a798f9dc9cb4 100644
+--- a/net/ipv4/nexthop.c
++++ b/net/ipv4/nexthop.c
+@@ -1504,8 +1504,8 @@ static bool nh_res_bucket_migrate(struct nh_res_table *res_table,
+ bool notify_nl, bool force)
+ {
+ struct nh_res_bucket *bucket = &res_table->nh_buckets[bucket_index];
++ struct netlink_ext_ack extack = {};
+ struct nh_grp_entry *new_nhge;
+- struct netlink_ext_ack extack;
+ int err;
+
+ new_nhge = list_first_entry_or_null(&res_table->uw_nh_entries,
+diff --git a/net/ipv4/route.c b/net/ipv4/route.c
+index 60516c6ae62e0d..783460ebfc4716 100644
+--- a/net/ipv4/route.c
++++ b/net/ipv4/route.c
+@@ -751,6 +751,35 @@ out_unlock:
+ spin_unlock_bh(&fnhe_lock);
+ }
+
++/* Update the PMTU of an exception when:
++ * - the new MTU of the first hop becomes smaller than the PMTU
++ * - the old MTU was the same as the PMTU, and it limited discovery of
++ * larger MTUs on the path. With that limit raised, we can now
++ * discover larger MTUs
++ * A special case is locked exceptions, for which the PMTU is smaller
++ * than the minimal accepted PMTU:
++ * - if the new MTU is greater than the PMTU, don't make any change
++ * - otherwise, unlock and set PMTU
++ *
++ * fnhe_lock keeps fnhe_pmtu and fnhe_mtu_locked consistent against
++ * update_or_create_fnhe(), which sets both under the same lock.
++ */
++void fnhe_update_pmtu(struct fib_nh_exception *fnhe, u32 new, u32 orig)
++{
++ spin_lock_bh(&fnhe_lock);
++
++ if (fnhe->fnhe_mtu_locked) {
++ if (new <= fnhe->fnhe_pmtu) {
++ fnhe->fnhe_pmtu = new;
++ fnhe->fnhe_mtu_locked = false;
++ }
++ } else if (new < fnhe->fnhe_pmtu || orig == fnhe->fnhe_pmtu) {
++ fnhe->fnhe_pmtu = new;
++ }
++
++ spin_unlock_bh(&fnhe_lock);
++}
++
+ static void __ip_do_redirect(struct rtable *rt, struct sk_buff *skb, struct flowi4 *fl4,
+ bool kill_route)
+ {
+@@ -902,8 +931,6 @@ void ip_rt_send_redirect(struct sk_buff *skb)
+ peer = inet_getpeer_v4(net->ipv4.peers, ip_hdr(skb)->saddr, vif);
+ if (!peer) {
+ rcu_read_unlock();
+- icmp_send(skb, ICMP_REDIRECT, ICMP_REDIR_HOST,
+- rt_nexthop(rt, ip_hdr(skb)->daddr));
+ return;
+ }
+
+diff --git a/net/ipv4/tcp_bpf.c b/net/ipv4/tcp_bpf.c
+index 9af7595bf8c452..9051b28f1983a1 100644
+--- a/net/ipv4/tcp_bpf.c
++++ b/net/ipv4/tcp_bpf.c
+@@ -431,6 +431,7 @@ more_data:
+ case __SK_REDIRECT:
+ redir_ingress = psock->redir_ingress;
+ sk_redir = psock->sk_redir;
++ sock_hold(sk_redir);
+ sk_msg_apply_bytes(psock, tosend);
+ if (!psock->apply_bytes) {
+ /* Clean up before releasing the sock lock. */
+@@ -451,6 +452,7 @@ more_data:
+
+ if (eval == __SK_REDIRECT)
+ sock_put(sk_redir);
++ sock_put(sk_redir);
+
+ lock_sock(sk);
+ sk_mem_uncharge(sk, sent);
+@@ -566,7 +568,7 @@ wait_for_sndbuf:
+ wait_for_memory:
+ err = sk_stream_wait_memory(sk, &timeo);
+ if (err) {
+- if (msg_tx && msg_tx != psock->cork)
++ if (msg_tx == &tmp)
+ sk_msg_free(sk, msg_tx);
+ goto out_err;
+ }
+diff --git a/net/ipv4/tcp_ipv4.c b/net/ipv4/tcp_ipv4.c
+index 00348cb9a211ba..753a881ce3cdf4 100644
+--- a/net/ipv4/tcp_ipv4.c
++++ b/net/ipv4/tcp_ipv4.c
+@@ -57,6 +57,8 @@
+ #include <linux/init.h>
+ #include <linux/times.h>
+ #include <linux/slab.h>
++#include <linux/sched.h>
++#include <linux/sock_diag.h>
+
+ #include <net/net_namespace.h>
+ #include <net/icmp.h>
+@@ -2412,6 +2414,8 @@ static void *established_get_first(struct seq_file *seq)
+ struct hlist_nulls_node *node;
+ spinlock_t *lock = inet_ehash_lockp(hinfo, st->bucket);
+
++ cond_resched();
++
+ /* Lockless fast path for the common case of empty buckets */
+ if (empty_bucket(hinfo, st))
+ continue;
+@@ -2722,13 +2726,17 @@ out:
+ }
+
+ #ifdef CONFIG_BPF_SYSCALL
++union bpf_tcp_iter_batch_item {
++ struct sock *sk;
++ __u64 cookie;
++};
++
+ struct bpf_tcp_iter_state {
+ struct tcp_iter_state state;
+ unsigned int cur_sk;
+ unsigned int end_sk;
+ unsigned int max_sk;
+- struct sock **batch;
+- bool st_bucket_done;
++ union bpf_tcp_iter_batch_item *batch;
+ };
+
+ struct bpf_iter__tcp {
+@@ -2751,21 +2759,32 @@ static int tcp_prog_seq_show(struct bpf_prog *prog, struct bpf_iter_meta *meta,
+
+ static void bpf_iter_tcp_put_batch(struct bpf_tcp_iter_state *iter)
+ {
+- while (iter->cur_sk < iter->end_sk)
+- sock_gen_put(iter->batch[iter->cur_sk++]);
++ union bpf_tcp_iter_batch_item *item;
++ unsigned int cur_sk = iter->cur_sk;
++ __u64 cookie;
++
++ /* Remember the cookies of the sockets we haven't seen yet, so we can
++ * pick up where we left off next time around.
++ */
++ while (cur_sk < iter->end_sk) {
++ item = &iter->batch[cur_sk++];
++ cookie = sock_gen_cookie(item->sk);
++ sock_gen_put(item->sk);
++ item->cookie = cookie;
++ }
+ }
+
+ static int bpf_iter_tcp_realloc_batch(struct bpf_tcp_iter_state *iter,
+- unsigned int new_batch_sz)
++ unsigned int new_batch_sz, gfp_t flags)
+ {
+- struct sock **new_batch;
++ union bpf_tcp_iter_batch_item *new_batch;
+
+ new_batch = kvmalloc(sizeof(*new_batch) * new_batch_sz,
+- GFP_USER | __GFP_NOWARN);
++ flags | __GFP_NOWARN);
+ if (!new_batch)
+ return -ENOMEM;
+
+- bpf_iter_tcp_put_batch(iter);
++ memcpy(new_batch, iter->batch, sizeof(*iter->batch) * iter->end_sk);
+ kvfree(iter->batch);
+ iter->batch = new_batch;
+ iter->max_sk = new_batch_sz;
+@@ -2773,112 +2792,242 @@ static int bpf_iter_tcp_realloc_batch(struct bpf_tcp_iter_state *iter,
+ return 0;
+ }
+
+-static unsigned int bpf_iter_tcp_listening_batch(struct seq_file *seq,
+- struct sock *start_sk)
++static struct sock *bpf_iter_tcp_resume_bucket(struct sock *first_sk,
++ union bpf_tcp_iter_batch_item *cookies,
++ int n_cookies)
++{
++ struct hlist_nulls_node *node;
++ struct sock *sk;
++ int i;
++
++ for (i = 0; i < n_cookies; i++) {
++ sk = first_sk;
++ sk_nulls_for_each_from(sk, node)
++ if (cookies[i].cookie == atomic64_read(&sk->sk_cookie))
++ return sk;
++ }
++
++ return NULL;
++}
++
++static struct sock *bpf_iter_tcp_resume_listening(struct seq_file *seq)
+ {
+ struct inet_hashinfo *hinfo = seq_file_net(seq)->ipv4.tcp_death_row.hashinfo;
+ struct bpf_tcp_iter_state *iter = seq->private;
+ struct tcp_iter_state *st = &iter->state;
+- struct hlist_nulls_node *node;
+- unsigned int expected = 1;
++ unsigned int find_cookie = iter->cur_sk;
++ unsigned int end_cookie = iter->end_sk;
++ int resume_bucket = st->bucket;
+ struct sock *sk;
+
+- sock_hold(start_sk);
+- iter->batch[iter->end_sk++] = start_sk;
++ if (end_cookie && find_cookie == end_cookie)
++ ++st->bucket;
+
+- sk = sk_nulls_next(start_sk);
+- sk_nulls_for_each_from(sk, node) {
+- if (seq_sk_match(seq, sk)) {
+- if (iter->end_sk < iter->max_sk) {
+- sock_hold(sk);
+- iter->batch[iter->end_sk++] = sk;
+- }
+- expected++;
++ sk = listening_get_first(seq);
++ iter->cur_sk = 0;
++ iter->end_sk = 0;
++
++ if (sk && st->bucket == resume_bucket && end_cookie) {
++ sk = bpf_iter_tcp_resume_bucket(sk, &iter->batch[find_cookie],
++ end_cookie - find_cookie);
++ if (!sk) {
++ spin_unlock(&hinfo->lhash2[st->bucket].lock);
++ ++st->bucket;
++ sk = listening_get_first(seq);
+ }
+ }
+- spin_unlock(&hinfo->lhash2[st->bucket].lock);
+
+- return expected;
++ return sk;
+ }
+
+-static unsigned int bpf_iter_tcp_established_batch(struct seq_file *seq,
+- struct sock *start_sk)
++static struct sock *bpf_iter_tcp_resume_established(struct seq_file *seq)
+ {
+ struct inet_hashinfo *hinfo = seq_file_net(seq)->ipv4.tcp_death_row.hashinfo;
+ struct bpf_tcp_iter_state *iter = seq->private;
+ struct tcp_iter_state *st = &iter->state;
++ unsigned int find_cookie = iter->cur_sk;
++ unsigned int end_cookie = iter->end_sk;
++ int resume_bucket = st->bucket;
++ struct sock *sk;
++
++ if (end_cookie && find_cookie == end_cookie)
++ ++st->bucket;
++
++ sk = established_get_first(seq);
++ iter->cur_sk = 0;
++ iter->end_sk = 0;
++
++ if (sk && st->bucket == resume_bucket && end_cookie) {
++ sk = bpf_iter_tcp_resume_bucket(sk, &iter->batch[find_cookie],
++ end_cookie - find_cookie);
++ if (!sk) {
++ spin_unlock_bh(inet_ehash_lockp(hinfo, st->bucket));
++ ++st->bucket;
++ sk = established_get_first(seq);
++ }
++ }
++
++ return sk;
++}
++
++static struct sock *bpf_iter_tcp_resume(struct seq_file *seq)
++{
++ struct bpf_tcp_iter_state *iter = seq->private;
++ struct tcp_iter_state *st = &iter->state;
++ struct sock *sk = NULL;
++
++ switch (st->state) {
++ case TCP_SEQ_STATE_LISTENING:
++ sk = bpf_iter_tcp_resume_listening(seq);
++ if (sk)
++ break;
++ st->bucket = 0;
++ st->state = TCP_SEQ_STATE_ESTABLISHED;
++ fallthrough;
++ case TCP_SEQ_STATE_ESTABLISHED:
++ sk = bpf_iter_tcp_resume_established(seq);
++ break;
++ }
++
++ return sk;
++}
++
++static unsigned int bpf_iter_tcp_listening_batch(struct seq_file *seq,
++ struct sock **start_sk)
++{
++ struct bpf_tcp_iter_state *iter = seq->private;
+ struct hlist_nulls_node *node;
+ unsigned int expected = 1;
+ struct sock *sk;
+
+- sock_hold(start_sk);
+- iter->batch[iter->end_sk++] = start_sk;
++ sock_hold(*start_sk);
++ iter->batch[iter->end_sk++].sk = *start_sk;
+
+- sk = sk_nulls_next(start_sk);
++ sk = sk_nulls_next(*start_sk);
++ *start_sk = NULL;
+ sk_nulls_for_each_from(sk, node) {
+ if (seq_sk_match(seq, sk)) {
+ if (iter->end_sk < iter->max_sk) {
+ sock_hold(sk);
+- iter->batch[iter->end_sk++] = sk;
++ iter->batch[iter->end_sk++].sk = sk;
++ } else if (!*start_sk) {
++ /* Remember where we left off. */
++ *start_sk = sk;
+ }
+ expected++;
+ }
+ }
+- spin_unlock_bh(inet_ehash_lockp(hinfo, st->bucket));
+
+ return expected;
+ }
+
+-static struct sock *bpf_iter_tcp_batch(struct seq_file *seq)
++static unsigned int bpf_iter_tcp_established_batch(struct seq_file *seq,
++ struct sock **start_sk)
++{
++ struct bpf_tcp_iter_state *iter = seq->private;
++ struct hlist_nulls_node *node;
++ struct sock *sk = *start_sk;
++ unsigned int expected = 0;
++
++ *start_sk = NULL;
++ sk_nulls_for_each_from(sk, node) {
++ if (!seq_sk_match(seq, sk))
++ continue;
++ expected++;
++ if (iter->end_sk < iter->max_sk) {
++ /* reqsk_queue_hash_req() inserts with sk_refcnt == 0
++ * and refcount_set()s it after the bucket lock drops.
++ */
++ if (unlikely(!refcount_inc_not_zero(&sk->sk_refcnt)))
++ continue;
++ iter->batch[iter->end_sk++].sk = sk;
++ } else if (!*start_sk) {
++ /* Remember where we left off. */
++ *start_sk = sk;
++ }
++ }
++
++ return expected;
++}
++
++static unsigned int bpf_iter_fill_batch(struct seq_file *seq,
++ struct sock **start_sk)
++{
++ struct bpf_tcp_iter_state *iter = seq->private;
++ struct tcp_iter_state *st = &iter->state;
++
++ if (st->state == TCP_SEQ_STATE_LISTENING)
++ return bpf_iter_tcp_listening_batch(seq, start_sk);
++ else
++ return bpf_iter_tcp_established_batch(seq, start_sk);
++}
++
++static void bpf_iter_tcp_unlock_bucket(struct seq_file *seq)
+ {
+ struct inet_hashinfo *hinfo = seq_file_net(seq)->ipv4.tcp_death_row.hashinfo;
+ struct bpf_tcp_iter_state *iter = seq->private;
+ struct tcp_iter_state *st = &iter->state;
++
++ if (st->state == TCP_SEQ_STATE_LISTENING)
++ spin_unlock(&hinfo->lhash2[st->bucket].lock);
++ else
++ spin_unlock_bh(inet_ehash_lockp(hinfo, st->bucket));
++}
++
++static struct sock *bpf_iter_tcp_batch(struct seq_file *seq)
++{
++ struct bpf_tcp_iter_state *iter = seq->private;
+ unsigned int expected;
+- bool resized = false;
+ struct sock *sk;
+-
+- /* The st->bucket is done. Directly advance to the next
+- * bucket instead of having the tcp_seek_last_pos() to skip
+- * one by one in the current bucket and eventually find out
+- * it has to advance to the next bucket.
+- */
+- if (iter->st_bucket_done) {
+- st->offset = 0;
+- st->bucket++;
+- if (st->state == TCP_SEQ_STATE_LISTENING &&
+- st->bucket > hinfo->lhash2_mask) {
+- st->state = TCP_SEQ_STATE_ESTABLISHED;
+- st->bucket = 0;
+- }
+- }
++ int err;
+
+ again:
+- /* Get a new batch */
+- iter->cur_sk = 0;
+- iter->end_sk = 0;
+- iter->st_bucket_done = false;
++ sk = bpf_iter_tcp_resume(seq);
++ if (!sk)
++ return NULL; /* Done */
+
+- sk = tcp_seek_last_pos(seq);
++ expected = bpf_iter_fill_batch(seq, &sk);
++ if (likely(!sk))
++ goto done;
++
++ /* Batch size was too small. */
++ bpf_iter_tcp_unlock_bucket(seq);
++ bpf_iter_tcp_put_batch(iter);
++ err = bpf_iter_tcp_realloc_batch(iter, expected * 3 / 2,
++ GFP_USER);
++ if (err) {
++ iter->cur_sk = 0;
++ iter->end_sk = 0;
++ return ERR_PTR(err);
++ }
++
++ sk = bpf_iter_tcp_resume(seq);
+ if (!sk)
+ return NULL; /* Done */
+
+- if (st->state == TCP_SEQ_STATE_LISTENING)
+- expected = bpf_iter_tcp_listening_batch(seq, sk);
+- else
+- expected = bpf_iter_tcp_established_batch(seq, sk);
++ expected = bpf_iter_fill_batch(seq, &sk);
++ if (likely(!sk))
++ goto done;
+
+- if (iter->end_sk == expected) {
+- iter->st_bucket_done = true;
+- return sk;
++ /* Batch size was still too small. Hold onto the lock while we try
++ * again with a larger batch to make sure the current bucket's size
++ * does not change in the meantime.
++ */
++ err = bpf_iter_tcp_realloc_batch(iter, expected, GFP_NOWAIT);
++ if (err) {
++ bpf_iter_tcp_unlock_bucket(seq);
++ return ERR_PTR(err);
+ }
+
+- if (!resized && !bpf_iter_tcp_realloc_batch(iter, expected * 3 / 2)) {
+- resized = true;
++ bpf_iter_fill_batch(seq, &sk);
++ WARN_ON_ONCE(sk);
++done:
++ bpf_iter_tcp_unlock_bucket(seq);
++ if (unlikely(!iter->end_sk)) {
++ ++iter->state.bucket;
+ goto again;
+ }
+-
+- return sk;
++ return iter->batch[0].sk;
+ }
+
+ static void *bpf_iter_tcp_seq_start(struct seq_file *seq, loff_t *pos)
+@@ -2908,16 +3057,11 @@ static void *bpf_iter_tcp_seq_next(struct seq_file *seq, void *v, loff_t *pos)
+ * meta.seq_num is used instead.
+ */
+ st->num++;
+- /* Move st->offset to the next sk in the bucket such that
+- * the future start() will resume at st->offset in
+- * st->bucket. See tcp_seek_last_pos().
+- */
+- st->offset++;
+- sock_gen_put(iter->batch[iter->cur_sk++]);
++ sock_gen_put(iter->batch[iter->cur_sk++].sk);
+ }
+
+ if (iter->cur_sk < iter->end_sk)
+- sk = iter->batch[iter->cur_sk];
++ sk = iter->batch[iter->cur_sk].sk;
+ else
+ sk = bpf_iter_tcp_batch(seq);
+
+@@ -2983,10 +3127,8 @@ static void bpf_iter_tcp_seq_stop(struct seq_file *seq, void *v)
+ (void)tcp_prog_seq_show(prog, &meta, v, 0);
+ }
+
+- if (iter->cur_sk < iter->end_sk) {
++ if (iter->cur_sk < iter->end_sk)
+ bpf_iter_tcp_put_batch(iter);
+- iter->st_bucket_done = false;
+- }
+ }
+
+ static const struct seq_operations bpf_iter_tcp_seq_ops = {
+@@ -3290,7 +3432,7 @@ static int bpf_iter_init_tcp(void *priv_data, struct bpf_iter_aux_info *aux)
+ if (err)
+ return err;
+
+- err = bpf_iter_tcp_realloc_batch(iter, INIT_BATCH_SZ);
++ err = bpf_iter_tcp_realloc_batch(iter, INIT_BATCH_SZ, GFP_USER);
+ if (err) {
+ bpf_iter_fini_seq_net(priv_data);
+ return err;
+diff --git a/net/ipv4/udp_offload.c b/net/ipv4/udp_offload.c
+index 35c014e10f24be..60fbb4ca34e001 100644
+--- a/net/ipv4/udp_offload.c
++++ b/net/ipv4/udp_offload.c
+@@ -21,17 +21,19 @@ static struct sk_buff *__skb_udp_tunnel_segment(struct sk_buff *skb,
+ int tnl_hlen = skb_inner_mac_header(skb) - skb_transport_header(skb);
+ bool remcsum, need_csum, offload_csum, gso_partial;
+ struct sk_buff *segs = ERR_PTR(-EINVAL);
+- struct udphdr *uh = udp_hdr(skb);
+ u16 mac_offset = skb->mac_header;
+ __be16 protocol = skb->protocol;
+ u16 mac_len = skb->mac_len;
+ int udp_offset, outer_hlen;
++ struct udphdr *uh;
+ __wsum partial;
+ bool need_ipsec;
+
+ if (unlikely(!pskb_may_pull(skb, tnl_hlen)))
+ goto out;
+
++ uh = udp_hdr(skb);
++
+ /* Adjust partial header checksum to negate old length.
+ * We cannot rely on the value contained in uh->len as it is
+ * possible that the actual value exceeds the boundaries of the
+diff --git a/net/ipv6/fib6_rules.c b/net/ipv6/fib6_rules.c
+index e0f0c5f8cccdaa..2fd020e868c1ac 100644
+--- a/net/ipv6/fib6_rules.c
++++ b/net/ipv6/fib6_rules.c
+@@ -301,6 +301,7 @@ INDIRECT_CALLABLE_SCOPE bool fib6_rule_suppress(struct fib_rule *rule,
+
+ suppress_route:
+ ip6_rt_put_flags(rt, flags);
++ res->rt6 = NULL;
+ return true;
+ }
+
+diff --git a/net/ipv6/icmp.c b/net/ipv6/icmp.c
+index 877cb5e8ded7ba..f8f7c1246f43be 100644
+--- a/net/ipv6/icmp.c
++++ b/net/ipv6/icmp.c
+@@ -214,7 +214,7 @@ static bool icmpv6_xrlim_allow(struct sock *sk, u8 type,
+ } else if (dst->dev && (dst->dev->flags&IFF_LOOPBACK)) {
+ res = true;
+ } else {
+- struct rt6_info *rt = (struct rt6_info *)dst;
++ struct rt6_info *rt = dst_rt6_info(dst);
+ int tmo = net->ipv6.sysctl.icmpv6_time;
+ struct inet_peer *peer;
+
+@@ -245,7 +245,7 @@ static bool icmpv6_rt_has_prefsrc(struct sock *sk, u8 type,
+
+ dst = ip6_route_output(net, sk, fl6);
+ if (!dst->error) {
+- struct rt6_info *rt = (struct rt6_info *)dst;
++ struct rt6_info *rt = dst_rt6_info(dst);
+ struct in6_addr prefsrc;
+
+ rt6_get_prefsrc(rt, &prefsrc);
+@@ -624,7 +624,7 @@ void icmp6_send(struct sk_buff *skb, u8 type, u8 code, __u32 info,
+ if (ip6_append_data(sk, icmpv6_getfrag, &msg,
+ len + sizeof(struct icmp6hdr),
+ sizeof(struct icmp6hdr),
+- &ipc6, &fl6, (struct rt6_info *)dst,
++ &ipc6, &fl6, dst_rt6_info(dst),
+ MSG_DONTWAIT)) {
+ ICMP6_INC_STATS(net, idev, ICMP6_MIB_OUTERRORS);
+ ip6_flush_pending_frames(sk);
+@@ -817,7 +817,7 @@ static void icmpv6_echo_reply(struct sk_buff *skb)
+ if (ip6_append_data(sk, icmpv6_getfrag, &msg,
+ skb->len + sizeof(struct icmp6hdr),
+ sizeof(struct icmp6hdr), &ipc6, &fl6,
+- (struct rt6_info *)dst, MSG_DONTWAIT)) {
++ dst_rt6_info(dst), MSG_DONTWAIT)) {
+ __ICMP6_INC_STATS(net, idev, ICMP6_MIB_OUTERRORS);
+ ip6_flush_pending_frames(sk);
+ } else {
+diff --git a/net/ipv6/ila/ila_common.c b/net/ipv6/ila/ila_common.c
+index b8d43ed4689db9..ca54a227fc2f63 100644
+--- a/net/ipv6/ila/ila_common.c
++++ b/net/ipv6/ila/ila_common.c
+@@ -84,6 +84,7 @@ static void ila_csum_adjust_transport(struct sk_buff *skb,
+ struct tcphdr *th = (struct tcphdr *)
+ (skb_network_header(skb) + nhoff);
+
++ ip6h = ipv6_hdr(skb);
+ diff = get_csum_diff(ip6h, p);
+ inet_proto_csum_replace_by_diff(&th->check, skb,
+ diff, true, true);
+@@ -95,6 +96,7 @@ static void ila_csum_adjust_transport(struct sk_buff *skb,
+ (skb_network_header(skb) + nhoff);
+
+ if (uh->check || skb->ip_summed == CHECKSUM_PARTIAL) {
++ ip6h = ipv6_hdr(skb);
+ diff = get_csum_diff(ip6h, p);
+ inet_proto_csum_replace_by_diff(&uh->check, skb,
+ diff, true, true);
+@@ -109,6 +111,7 @@ static void ila_csum_adjust_transport(struct sk_buff *skb,
+ struct icmp6hdr *ih = (struct icmp6hdr *)
+ (skb_network_header(skb) + nhoff);
+
++ ip6h = ipv6_hdr(skb);
+ diff = get_csum_diff(ip6h, p);
+ inet_proto_csum_replace_by_diff(&ih->icmp6_cksum, skb,
+ diff, true, true);
+@@ -126,6 +129,15 @@ void ila_update_ipv6_locator(struct sk_buff *skb, struct ila_params *p,
+ switch (p->csum_mode) {
+ case ILA_CSUM_ADJUST_TRANSPORT:
+ ila_csum_adjust_transport(skb, p);
++ /*
++ * ila_csum_adjust_transport() calls pskb_may_pull(), which can
++ * reallocate the skb head and leave ip6h (and the iaddr derived
++ * from it) dangling; reload both before the write below. The
++ * other csum modes do not pull, so their cached pointers stay
++ * valid.
++ */
++ ip6h = ipv6_hdr(skb);
++ iaddr = ila_a2i(&ip6h->daddr);
+ break;
+ case ILA_CSUM_NEUTRAL_MAP:
+ if (sir2ila) {
+diff --git a/net/ipv6/ila/ila_lwt.c b/net/ipv6/ila/ila_lwt.c
+index 7397f764c66cca..7d574f5132e2fb 100644
+--- a/net/ipv6/ila/ila_lwt.c
++++ b/net/ipv6/ila/ila_lwt.c
+@@ -38,7 +38,7 @@ static inline struct ila_params *ila_params_lwtunnel(
+ static int ila_output(struct net *net, struct sock *sk, struct sk_buff *skb)
+ {
+ struct dst_entry *orig_dst = skb_dst(skb);
+- struct rt6_info *rt = (struct rt6_info *)orig_dst;
++ struct rt6_info *rt = dst_rt6_info(orig_dst);
+ struct ila_lwt *ilwt = ila_lwt_lwtunnel(orig_dst->lwtstate);
+ struct dst_entry *dst;
+ int err = -EINVAL;
+@@ -72,7 +72,7 @@ static int ila_output(struct net *net, struct sock *sk, struct sk_buff *skb)
+ memset(&fl6, 0, sizeof(fl6));
+ fl6.flowi6_oif = orig_dst->dev->ifindex;
+ fl6.flowi6_iif = LOOPBACK_IFINDEX;
+- fl6.daddr = *rt6_nexthop((struct rt6_info *)orig_dst,
++ fl6.daddr = *rt6_nexthop(dst_rt6_info(orig_dst),
+ &ip6h->daddr);
+
+ dst = ip6_route_output(net, NULL, &fl6);
+diff --git a/net/ipv6/ip6_fib.c b/net/ipv6/ip6_fib.c
+index bb51a911a6ce76..b1276c247190fd 100644
+--- a/net/ipv6/ip6_fib.c
++++ b/net/ipv6/ip6_fib.c
+@@ -625,11 +625,11 @@ static int inet6_dump_fib(struct sk_buff *skb, struct netlink_callback *cb)
+ const struct nlmsghdr *nlh = cb->nlh;
+ struct net *net = sock_net(skb->sk);
+ unsigned int h, s_h;
+- unsigned int e = 0, s_e;
+ struct fib6_walker *w;
+ struct fib6_table *tb;
+ struct hlist_head *head;
+ int res = 0;
++ u32 s_id;
+
+ if (cb->strict_check) {
+ int err;
+@@ -687,25 +687,24 @@ static int inet6_dump_fib(struct sk_buff *skb, struct netlink_callback *cb)
+ }
+
+ s_h = cb->args[0];
+- s_e = cb->args[1];
++ s_id = cb->args[1];
+
+ rcu_read_lock();
+- for (h = s_h; h < FIB6_TABLE_HASHSZ; h++, s_e = 0) {
+- e = 0;
++ for (h = s_h; h < FIB6_TABLE_HASHSZ; h++, s_id = 0) {
+ head = &net->ipv6.fib_table_hash[h];
+ hlist_for_each_entry_rcu(tb, head, tb6_hlist) {
+- if (e < s_e)
+- goto next;
++ if (s_id && tb->tb6_id != s_id)
++ continue;
++
++ s_id = 0;
++ cb->args[1] = tb->tb6_id;
+ res = fib6_dump_table(tb, skb, cb);
+ if (res != 0)
+ goto out_unlock;
+-next:
+- e++;
+ }
+ }
+ out_unlock:
+ rcu_read_unlock();
+- cb->args[1] = e;
+ cb->args[0] = h;
+ out:
+ res = res < 0 ? res : skb->len;
+diff --git a/net/ipv6/ip6_output.c b/net/ipv6/ip6_output.c
+index d8ce708fcb3c45..93e55ab7e0f6d1 100644
+--- a/net/ipv6/ip6_output.c
++++ b/net/ipv6/ip6_output.c
+@@ -121,7 +121,7 @@ static int ip6_finish_output2(struct net *net, struct sock *sk, struct sk_buff *
+ }
+
+ rcu_read_lock();
+- nexthop = rt6_nexthop((struct rt6_info *)dst, daddr);
++ nexthop = rt6_nexthop(dst_rt6_info(dst), daddr);
+ neigh = __ipv6_neigh_lookup_noref(dev, nexthop);
+
+ if (unlikely(IS_ERR_OR_NULL(neigh))) {
+@@ -611,7 +611,7 @@ int ip6_forward(struct sk_buff *skb)
+ * send a redirect.
+ */
+
+- rt = (struct rt6_info *) dst;
++ rt = dst_rt6_info(dst);
+ if (rt->rt6i_flags & RTF_GATEWAY)
+ target = &rt->rt6i_gateway;
+ else
+@@ -623,7 +623,7 @@ int ip6_forward(struct sk_buff *skb)
+ /* Limit redirects both by destination (here)
+ and by source (inside ndisc_send_redirect)
+ */
+- if (inet_peer_xrlim_allow(peer, 1*HZ))
++ if (peer && inet_peer_xrlim_allow(peer, 1*HZ))
+ ndisc_send_redirect(skb, target);
+ rcu_read_unlock();
+ } else {
+@@ -866,7 +866,7 @@ int ip6_fragment(struct net *net, struct sock *sk, struct sk_buff *skb,
+ int (*output)(struct net *, struct sock *, struct sk_buff *))
+ {
+ struct sk_buff *frag;
+- struct rt6_info *rt = (struct rt6_info *)skb_dst(skb);
++ struct rt6_info *rt = dst_rt6_info(skb_dst(skb));
+ struct ipv6_pinfo *np = skb->sk && !dev_recursion_level() ?
+ inet6_sk(skb->sk) : NULL;
+ bool mono_delivery_time = skb->mono_delivery_time;
+@@ -1074,7 +1074,7 @@ static struct dst_entry *ip6_sk_dst_check(struct sock *sk,
+ return NULL;
+ }
+
+- rt = (struct rt6_info *)dst;
++ rt = dst_rt6_info(dst);
+ /* Yes, checking route validity in not connected
+ * case is not very simple. Take into account,
+ * that we do not support routing by source, TOS,
+@@ -1129,7 +1129,7 @@ static int ip6_dst_lookup_tail(struct net *net, const struct sock *sk,
+ struct rt6_info *rt;
+
+ *dst = ip6_route_output(net, sk, fl6);
+- rt = (*dst)->error ? NULL : (struct rt6_info *)*dst;
++ rt = (*dst)->error ? NULL : dst_rt6_info(*dst);
+
+ rcu_read_lock();
+ from = rt ? rcu_dereference(rt->from) : NULL;
+@@ -1171,7 +1171,7 @@ static int ip6_dst_lookup_tail(struct net *net, const struct sock *sk,
+ * dst entry and replace it instead with the
+ * dst entry of the nexthop router
+ */
+- rt = (struct rt6_info *) *dst;
++ rt = dst_rt6_info(*dst);
+ rcu_read_lock();
+ n = __ipv6_neigh_lookup_noref(rt->dst.dev,
+ rt6_nexthop(rt, &fl6->daddr));
+@@ -1437,7 +1437,7 @@ static int __ip6_append_data(struct sock *sk,
+ int offset = 0;
+ bool zc = false;
+ u32 tskey = 0;
+- struct rt6_info *rt = (struct rt6_info *)cork->dst;
++ struct rt6_info *rt = dst_rt6_info(cork->dst);
+ bool paged, hold_tskey, extra_uref = false;
+ struct ipv6_txoptions *opt = v6_cork->opt;
+ int csummode = CHECKSUM_NONE;
+@@ -1869,7 +1869,7 @@ struct sk_buff *__ip6_make_skb(struct sock *sk,
+ struct net *net = sock_net(sk);
+ struct ipv6hdr *hdr;
+ struct ipv6_txoptions *opt = v6_cork->opt;
+- struct rt6_info *rt = (struct rt6_info *)cork->base.dst;
++ struct rt6_info *rt = dst_rt6_info(cork->base.dst);
+ struct flowi6 *fl6 = &cork->fl.u.ip6;
+ unsigned char proto = fl6->flowi6_proto;
+
+@@ -1941,7 +1941,7 @@ out:
+ int ip6_send_skb(struct sk_buff *skb)
+ {
+ struct net *net = sock_net(skb->sk);
+- struct rt6_info *rt = (struct rt6_info *)skb_dst(skb);
++ struct rt6_info *rt = dst_rt6_info(skb_dst(skb));
+ int err;
+
+ rcu_read_lock();
+diff --git a/net/ipv6/ip6_tunnel.c b/net/ipv6/ip6_tunnel.c
+index a1a2e785063c35..3cb2331cb2428c 100644
+--- a/net/ipv6/ip6_tunnel.c
++++ b/net/ipv6/ip6_tunnel.c
+@@ -675,6 +675,9 @@ ip6ip6_err(struct sk_buff *skb, struct inet6_skb_parm *opt,
+ if (!skb2)
+ return 0;
+
++ /* Remove debris left by outer IPv6 stack. */
++ memset(IP6CB(skb2), 0, sizeof(*IP6CB(skb2)));
++
+ skb_dst_drop(skb2);
+ skb_pull(skb2, offset);
+ skb_reset_network_header(skb2);
+diff --git a/net/ipv6/ip6mr.c b/net/ipv6/ip6mr.c
+index 06f66531628fec..00774cfa011af2 100644
+--- a/net/ipv6/ip6mr.c
++++ b/net/ipv6/ip6mr.c
+@@ -2301,7 +2301,7 @@ int ip6mr_get_route(struct net *net, struct sk_buff *skb, struct rtmsg *rtm,
+ int err;
+ struct mr_table *mrt;
+ struct mfc6_cache *cache;
+- struct rt6_info *rt = (struct rt6_info *)skb_dst(skb);
++ struct rt6_info *rt = dst_rt6_info(skb_dst(skb));
+
+ rcu_read_lock();
+ mrt = __ip6mr_get_table(net, RT6_TABLE_DFLT);
+diff --git a/net/ipv6/ndisc.c b/net/ipv6/ndisc.c
+index f1c4c4dbefb0c9..585a9135cf267c 100644
+--- a/net/ipv6/ndisc.c
++++ b/net/ipv6/ndisc.c
+@@ -972,10 +972,8 @@ out:
+ in6_dev_put(idev);
+ }
+
+-static int accept_untracked_na(struct net_device *dev, struct in6_addr *saddr)
++static int accept_untracked_na(struct inet6_dev *idev, struct in6_addr *saddr)
+ {
+- struct inet6_dev *idev = __in6_dev_get(dev);
+-
+ switch (idev->cnf.accept_untracked_na) {
+ case 0: /* Don't accept untracked na (absent in neighbor cache) */
+ return 0;
+@@ -985,7 +983,7 @@ static int accept_untracked_na(struct net_device *dev, struct in6_addr *saddr)
+ * same subnet as an address configured on the interface that
+ * received the na
+ */
+- return !!ipv6_chk_prefix(saddr, dev);
++ return !!ipv6_chk_prefix(saddr, idev->dev);
+ default:
+ return 0;
+ }
+@@ -1086,7 +1084,7 @@ static void ndisc_recv_na(struct sk_buff *skb)
+ */
+ new_state = msg->icmph.icmp6_solicited ? NUD_REACHABLE : NUD_STALE;
+ if (!neigh && lladdr && idev && idev->cnf.forwarding) {
+- if (accept_untracked_na(dev, saddr)) {
++ if (accept_untracked_na(idev, saddr)) {
+ neigh = neigh_create(&nd_tbl, &msg->target, dev);
+ new_state = NUD_STALE;
+ }
+@@ -1719,7 +1717,7 @@ void ndisc_send_redirect(struct sk_buff *skb, const struct in6_addr *target)
+ if (IS_ERR(dst))
+ return;
+
+- rt = (struct rt6_info *) dst;
++ rt = dst_rt6_info(dst);
+
+ if (rt->rt6i_flags & RTF_GATEWAY) {
+ ND_PRINTK(2, warn,
+@@ -1729,6 +1727,8 @@ void ndisc_send_redirect(struct sk_buff *skb, const struct in6_addr *target)
+
+ rcu_read_lock();
+ peer = inet_getpeer_v6(net->ipv6.peers, &ipv6_hdr(skb)->saddr);
++ if (!peer)
++ goto release;
+ ret = inet_peer_xrlim_allow(peer, 1*HZ);
+ rcu_read_unlock();
+
+diff --git a/net/ipv6/ping.c b/net/ipv6/ping.c
+index a5d7d1915ba7e4..c9550fddc6b3d2 100644
+--- a/net/ipv6/ping.c
++++ b/net/ipv6/ping.c
+@@ -154,7 +154,7 @@ static int ping_v6_sendmsg(struct sock *sk, struct msghdr *msg, size_t len)
+ dst = ip6_sk_dst_lookup_flow(sk, &fl6, daddr, false);
+ if (IS_ERR(dst))
+ return PTR_ERR(dst);
+- rt = (struct rt6_info *) dst;
++ rt = dst_rt6_info(dst);
+
+ if (!fl6.flowi6_oif && ipv6_addr_is_multicast(&fl6.daddr))
+ fl6.flowi6_oif = np->mcast_oif;
+diff --git a/net/ipv6/raw.c b/net/ipv6/raw.c
+index c644300680ba67..7b17f1b2a61280 100644
+--- a/net/ipv6/raw.c
++++ b/net/ipv6/raw.c
+@@ -342,7 +342,7 @@ void raw6_icmp_error(struct sk_buff *skb, int nexthdr,
+ const struct ipv6hdr *ip6h = (const struct ipv6hdr *)skb->data;
+
+ if (!raw_v6_match(net, sk, nexthdr, &ip6h->saddr, &ip6h->daddr,
+- inet6_iif(skb), inet6_iif(skb)))
++ inet6_iif(skb), inet6_sdif(skb)))
+ continue;
+ rawv6_err(sk, skb, NULL, type, code, inner_offset, info);
+ }
+@@ -591,7 +591,7 @@ static int rawv6_send_hdrinc(struct sock *sk, struct msghdr *msg, int length,
+ struct ipv6hdr *iph;
+ struct sk_buff *skb;
+ int err;
+- struct rt6_info *rt = (struct rt6_info *)*dstp;
++ struct rt6_info *rt = dst_rt6_info(*dstp);
+ int hlen = LL_RESERVED_SPACE(rt->dst.dev);
+ int tlen = rt->dst.dev->needed_tailroom;
+
+@@ -915,7 +915,7 @@ back_from_confirm:
+ ipc6.opt = opt;
+ lock_sock(sk);
+ err = ip6_append_data(sk, raw6_getfrag, &rfv,
+- len, 0, &ipc6, &fl6, (struct rt6_info *)dst,
++ len, 0, &ipc6, &fl6, dst_rt6_info(dst),
+ msg->msg_flags);
+
+ if (err)
+diff --git a/net/ipv6/route.c b/net/ipv6/route.c
+index f047000e2c55ce..e198a5eb24c64e 100644
+--- a/net/ipv6/route.c
++++ b/net/ipv6/route.c
+@@ -227,7 +227,7 @@ static struct neighbour *ip6_dst_neigh_lookup(const struct dst_entry *dst,
+ struct sk_buff *skb,
+ const void *daddr)
+ {
+- const struct rt6_info *rt = container_of(dst, struct rt6_info, dst);
++ const struct rt6_info *rt = dst_rt6_info(dst);
+
+ return ip6_neigh_lookup(rt6_nexthop(rt, &in6addr_any),
+ dst->dev, skb, daddr);
+@@ -235,8 +235,8 @@ static struct neighbour *ip6_dst_neigh_lookup(const struct dst_entry *dst,
+
+ static void ip6_confirm_neigh(const struct dst_entry *dst, const void *daddr)
+ {
++ const struct rt6_info *rt = dst_rt6_info(dst);
+ struct net_device *dev = dst->dev;
+- struct rt6_info *rt = (struct rt6_info *)dst;
+
+ daddr = choose_neigh_daddr(rt6_nexthop(rt, &in6addr_any), NULL, daddr);
+ if (!daddr)
+@@ -356,7 +356,7 @@ EXPORT_SYMBOL(ip6_dst_alloc);
+
+ static void ip6_dst_destroy(struct dst_entry *dst)
+ {
+- struct rt6_info *rt = (struct rt6_info *)dst;
++ struct rt6_info *rt = dst_rt6_info(dst);
+ struct fib6_info *from;
+ struct inet6_dev *idev;
+
+@@ -376,7 +376,7 @@ static void ip6_dst_destroy(struct dst_entry *dst)
+ static void ip6_dst_ifdown(struct dst_entry *dst, struct net_device *dev,
+ int how)
+ {
+- struct rt6_info *rt = (struct rt6_info *)dst;
++ struct rt6_info *rt = dst_rt6_info(dst);
+ struct inet6_dev *idev = rt->rt6i_idev;
+ struct fib6_info *from;
+
+@@ -990,13 +990,13 @@ int rt6_route_rcv(struct net_device *dev, u8 *opt, int len,
+ } else if (rinfo->prefix_len > 128) {
+ return -EINVAL;
+ } else if (rinfo->prefix_len > 64) {
+- if (rinfo->length < 2) {
++ /* RFC 4191: Length MUST be 3 when Prefix Length > 64 */
++ if (rinfo->length < 3)
+ return -EINVAL;
+- }
+ } else if (rinfo->prefix_len > 0) {
+- if (rinfo->length < 1) {
++ /* RFC 4191: Length MUST be 2 or 3 when Prefix Length > 0 */
++ if (rinfo->length < 2)
+ return -EINVAL;
+- }
+ }
+
+ pref = rinfo->route_pref;
+@@ -1324,7 +1324,7 @@ struct rt6_info *rt6_lookup(struct net *net, const struct in6_addr *daddr,
+
+ dst = fib6_rule_lookup(net, &fl6, skb, flags, ip6_pol_route_lookup);
+ if (dst->error == 0)
+- return (struct rt6_info *) dst;
++ return dst_rt6_info(dst);
+
+ dst_release(dst);
+
+@@ -2681,7 +2681,7 @@ struct dst_entry *ip6_route_output_flags(struct net *net,
+
+ rcu_read_lock();
+ dst = ip6_route_output_flags_noref(net, sk, fl6, flags);
+- rt6 = (struct rt6_info *)dst;
++ rt6 = dst_rt6_info(dst);
+ /* For dst cached in uncached_list, refcnt is already taken. */
+ if (list_empty(&rt6->rt6i_uncached) && !dst_hold_safe(dst)) {
+ dst = &net->ipv6.ip6_null_entry->dst;
+@@ -2695,7 +2695,7 @@ EXPORT_SYMBOL_GPL(ip6_route_output_flags);
+
+ struct dst_entry *ip6_blackhole_route(struct net *net, struct dst_entry *dst_orig)
+ {
+- struct rt6_info *rt, *ort = (struct rt6_info *) dst_orig;
++ struct rt6_info *rt, *ort = dst_rt6_info(dst_orig);
+ struct net_device *loopback_dev = net->loopback_dev;
+ struct dst_entry *new = NULL;
+
+@@ -2778,7 +2778,7 @@ INDIRECT_CALLABLE_SCOPE struct dst_entry *ip6_dst_check(struct dst_entry *dst,
+ struct fib6_info *from;
+ struct rt6_info *rt;
+
+- rt = container_of(dst, struct rt6_info, dst);
++ rt = dst_rt6_info(dst);
+
+ if (rt->sernum)
+ return rt6_is_valid(rt) ? dst : NULL;
+@@ -2807,7 +2807,7 @@ EXPORT_INDIRECT_CALLABLE(ip6_dst_check);
+ static void ip6_negative_advice(struct sock *sk,
+ struct dst_entry *dst)
+ {
+- struct rt6_info *rt = (struct rt6_info *) dst;
++ struct rt6_info *rt = dst_rt6_info(dst);
+
+ if (rt->rt6i_flags & RTF_CACHE) {
+ rcu_read_lock();
+@@ -2830,7 +2830,7 @@ static void ip6_link_failure(struct sk_buff *skb)
+
+ icmpv6_send(skb, ICMPV6_DEST_UNREACH, ICMPV6_ADDR_UNREACH, 0);
+
+- rt = (struct rt6_info *) skb_dst(skb);
++ rt = dst_rt6_info(skb_dst(skb));
+ if (rt) {
+ rcu_read_lock();
+ if (rt->rt6i_flags & RTF_CACHE) {
+@@ -2886,7 +2886,7 @@ static void __ip6_rt_update_pmtu(struct dst_entry *dst, const struct sock *sk,
+ bool confirm_neigh)
+ {
+ const struct in6_addr *daddr, *saddr;
+- struct rt6_info *rt6 = (struct rt6_info *)dst;
++ struct rt6_info *rt6 = dst_rt6_info(dst);
+
+ /* Note: do *NOT* check dst_metric_locked(dst, RTAX_MTU)
+ * IPv6 pmtu discovery isn't optional, so 'mtu lock' cannot disable it.
+@@ -4214,7 +4214,7 @@ static void rt6_do_redirect(struct dst_entry *dst, struct sock *sk, struct sk_bu
+ }
+ }
+
+- rt = (struct rt6_info *) dst;
++ rt = dst_rt6_info(dst);
+ if (rt->rt6i_flags & RTF_REJECT) {
+ net_dbg_ratelimited("rt6_redirect: source isn't a valid nexthop for redirect target\n");
+ return;
+@@ -5665,7 +5665,7 @@ static int rt6_fill_node(struct net *net, struct sk_buff *skb,
+ int iif, int type, u32 portid, u32 seq,
+ unsigned int flags)
+ {
+- struct rt6_info *rt6 = (struct rt6_info *)dst;
++ struct rt6_info *rt6 = dst_rt6_info(dst);
+ struct rt6key *rt6_dst, *rt6_src;
+ u32 *pmetrics, table, rt6_flags;
+ unsigned char nh_flags = 0;
+@@ -6182,7 +6182,7 @@ static int inet6_rtm_getroute(struct sk_buff *in_skb, struct nlmsghdr *nlh,
+ }
+
+
+- rt = container_of(dst, struct rt6_info, dst);
++ rt = dst_rt6_info(dst);
+ if (rt->dst.error) {
+ err = rt->dst.error;
+ ip6_rt_put(rt);
+diff --git a/net/ipv6/tcp_ipv6.c b/net/ipv6/tcp_ipv6.c
+index a1e31fe5967089..3d909982d81874 100644
+--- a/net/ipv6/tcp_ipv6.c
++++ b/net/ipv6/tcp_ipv6.c
+@@ -106,11 +106,9 @@ static void inet6_sk_rx_dst_set(struct sock *sk, const struct sk_buff *skb)
+ struct dst_entry *dst = skb_dst(skb);
+
+ if (dst && dst_hold_safe(dst)) {
+- const struct rt6_info *rt = (const struct rt6_info *)dst;
+-
+ rcu_assign_pointer(sk->sk_rx_dst, dst);
+ sk->sk_rx_dst_ifindex = skb->skb_iif;
+- sk->sk_rx_dst_cookie = rt6_get_cookie(rt);
++ sk->sk_rx_dst_cookie = rt6_get_cookie(dst_rt6_info(dst));
+ }
+ }
+
+diff --git a/net/ipv6/udp.c b/net/ipv6/udp.c
+index 184fc7a5e4d171..96a46dc4733607 100644
+--- a/net/ipv6/udp.c
++++ b/net/ipv6/udp.c
+@@ -925,11 +925,8 @@ start_lookup:
+
+ static void udp6_sk_rx_dst_set(struct sock *sk, struct dst_entry *dst)
+ {
+- if (udp_sk_rx_dst_set(sk, dst)) {
+- const struct rt6_info *rt = (const struct rt6_info *)dst;
+-
+- sk->sk_rx_dst_cookie = rt6_get_cookie(rt);
+- }
++ if (udp_sk_rx_dst_set(sk, dst))
++ sk->sk_rx_dst_cookie = rt6_get_cookie(dst_rt6_info(dst));
+ }
+
+ /* wrapper for udp_queue_rcv_skb tacking care of csum conversion and
+@@ -1593,7 +1590,7 @@ back_from_confirm:
+
+ skb = ip6_make_skb(sk, getfrag, msg, ulen,
+ sizeof(struct udphdr), &ipc6,
+- (struct rt6_info *)dst,
++ dst_rt6_info(dst),
+ msg->msg_flags, &cork);
+ err = PTR_ERR(skb);
+ if (!IS_ERR_OR_NULL(skb))
+@@ -1620,7 +1617,7 @@ do_append_data:
+ ipc6.dontfrag = np->dontfrag;
+ up->len += ulen;
+ err = ip6_append_data(sk, getfrag, msg, ulen, sizeof(struct udphdr),
+- &ipc6, fl6, (struct rt6_info *)dst,
++ &ipc6, fl6, dst_rt6_info(dst),
+ corkreq ? msg->msg_flags|MSG_MORE : msg->msg_flags);
+ if (err)
+ udp_v6_flush_pending_frames(sk);
+diff --git a/net/ipv6/xfrm6_policy.c b/net/ipv6/xfrm6_policy.c
+index c936e083f5d8ab..0342efd0a0b0ac 100644
+--- a/net/ipv6/xfrm6_policy.c
++++ b/net/ipv6/xfrm6_policy.c
+@@ -80,7 +80,7 @@ static int xfrm6_get_saddr(xfrm_address_t *saddr,
+ static int xfrm6_fill_dst(struct xfrm_dst *xdst, struct net_device *dev,
+ const struct flowi *fl)
+ {
+- struct rt6_info *rt = (struct rt6_info *)xdst->route;
++ struct rt6_info *rt = dst_rt6_info(xdst->route);
+
+ xdst->u.dst.dev = dev;
+ netdev_hold(dev, &xdst->u.dst.dev_tracker, GFP_ATOMIC);
+@@ -88,6 +88,7 @@ static int xfrm6_fill_dst(struct xfrm_dst *xdst, struct net_device *dev,
+ xdst->u.rt6.rt6i_idev = in6_dev_get(dev);
+ if (!xdst->u.rt6.rt6i_idev) {
+ netdev_put(dev, &xdst->u.dst.dev_tracker);
++ xdst->u.dst.dev = NULL;
+ return -ENODEV;
+ }
+
+diff --git a/net/iucv/af_iucv.c b/net/iucv/af_iucv.c
+index e9a9bb0dee065a..965167bf3abddc 100644
+--- a/net/iucv/af_iucv.c
++++ b/net/iucv/af_iucv.c
+@@ -334,6 +334,7 @@ static void iucv_sever_path(struct sock *sk, int with_user_data)
+ unsigned char user_data[16];
+ struct iucv_sock *iucv = iucv_sk(sk);
+ struct iucv_path *path = iucv->path;
++ struct sock_msg_q *p, *n;
+
+ /* Whoever resets the path pointer, must sever and free it. */
+ if (xchg(&iucv->path, NULL)) {
+@@ -345,6 +346,19 @@ static void iucv_sever_path(struct sock *sk, int with_user_data)
+ } else
+ pr_iucv->path_sever(path, NULL);
+ iucv_path_free(path);
++
++ /*
++ * Message notifications queued on message_q still reference
++ * the now freed path; drop them, otherwise a later recvmsg()
++ * would pass the freed iucv_path to message_receive() via
++ * iucv_process_message_q().
++ */
++ spin_lock_bh(&iucv->message_q.lock);
++ list_for_each_entry_safe(p, n, &iucv->message_q.list, list) {
++ list_del(&p->list);
++ kfree(p);
++ }
++ spin_unlock_bh(&iucv->message_q.lock);
+ }
+ }
+
+@@ -1873,7 +1887,8 @@ static int afiucv_hs_callback_syn(struct sock *sk, struct sk_buff *skb)
+ afiucv_swap_src_dest(skb);
+ trans_hdr->flags = AF_IUCV_FLAG_SYN | AF_IUCV_FLAG_FIN;
+ err = dev_queue_xmit(skb);
+- iucv_sock_kill(nsk);
++ if (nsk)
++ iucv_sock_kill(nsk);
+ bh_unlock_sock(sk);
+ goto out;
+ }
+@@ -2090,6 +2105,8 @@ static int afiucv_hs_rcv(struct sk_buff *skb, struct net_device *dev,
+ }
+ }
+ }
++ if (sk)
++ sock_hold(sk);
+ read_unlock(&iucv_sk_list.lock);
+ if (!iucv)
+ sk = NULL;
+@@ -2139,6 +2156,8 @@ static int afiucv_hs_rcv(struct sk_buff *skb, struct net_device *dev,
+ kfree_skb(skb);
+ }
+
++ if (sk)
++ sock_put(sk);
+ return err;
+ }
+
+diff --git a/net/l2tp/l2tp_ip6.c b/net/l2tp/l2tp_ip6.c
+index bb92dc8b82f393..e282b91b396c72 100644
+--- a/net/l2tp/l2tp_ip6.c
++++ b/net/l2tp/l2tp_ip6.c
+@@ -633,7 +633,7 @@ back_from_confirm:
+ ulen = len + (skb_queue_empty(&sk->sk_write_queue) ? transhdrlen : 0);
+ err = ip6_append_data(sk, ip_generic_getfrag, msg,
+ ulen, transhdrlen, &ipc6,
+- &fl6, (struct rt6_info *)dst,
++ &fl6, dst_rt6_info(dst),
+ msg->msg_flags);
+ if (err)
+ ip6_flush_pending_frames(sk);
+diff --git a/net/l2tp/l2tp_ppp.c b/net/l2tp/l2tp_ppp.c
+index 34d8582c0c072e..2e856a83a7506b 100644
+--- a/net/l2tp/l2tp_ppp.c
++++ b/net/l2tp/l2tp_ppp.c
+@@ -810,6 +810,7 @@ static int pppol2tp_connect(struct socket *sock, struct sockaddr *uservaddr,
+ po->chan.private = sk;
+ po->chan.ops = &pppol2tp_chan_ops;
+ po->chan.mtu = pppol2tp_tunnel_mtu(tunnel);
++ po->chan.direct_xmit = true;
+
+ error = ppp_register_net_channel(sock_net(sk), &po->chan);
+ if (error) {
+diff --git a/net/mac80211/iface.c b/net/mac80211/iface.c
+index 6818c9d852e8e5..4224a7c244a3d0 100644
+--- a/net/mac80211/iface.c
++++ b/net/mac80211/iface.c
+@@ -593,6 +593,7 @@ static void ieee80211_do_stop(struct ieee80211_sub_if_data *sdata, bool going_do
+ WARN_ON(!list_empty(&sdata->u.ap.vlans));
+ } else if (sdata->vif.type == NL80211_IFTYPE_AP_VLAN) {
+ /* remove all packets in parent bc_buf pointing to this dev */
++ __skb_queue_head_init(&freeq);
+ ps = &sdata->bss->ps;
+
+ spin_lock_irqsave(&ps->bc_buf.lock, flags);
+@@ -600,10 +601,15 @@ static void ieee80211_do_stop(struct ieee80211_sub_if_data *sdata, bool going_do
+ if (skb->dev == sdata->dev) {
+ __skb_unlink(skb, &ps->bc_buf);
+ local->total_ps_buffered--;
+- ieee80211_free_txskb(&local->hw, skb);
++ __skb_queue_tail(&freeq, skb);
+ }
+ }
+ spin_unlock_irqrestore(&ps->bc_buf.lock, flags);
++
++ skb_queue_walk_safe(&freeq, skb, tmp) {
++ __skb_unlink(skb, &freeq);
++ ieee80211_free_txskb(&local->hw, skb);
++ }
+ }
+
+ if (going_down)
+diff --git a/net/mac80211/rx.c b/net/mac80211/rx.c
+index a6636e9f5c087a..1fbccdb37166a6 100644
+--- a/net/mac80211/rx.c
++++ b/net/mac80211/rx.c
+@@ -1590,6 +1590,8 @@ static void sta_ps_start(struct sta_info *sta)
+ else
+ clear_bit(tid, &sta->txq_buffered_tids);
+ }
++
++ sta_info_recalc_tim(sta);
+ }
+
+ static void sta_ps_end(struct sta_info *sta)
+diff --git a/net/mac80211/s1g.c b/net/mac80211/s1g.c
+index c1f964e9991cd2..9914390ff31ff3 100644
+--- a/net/mac80211/s1g.c
++++ b/net/mac80211/s1g.c
+@@ -100,6 +100,10 @@ ieee80211_s1g_rx_twt_setup(struct ieee80211_sub_if_data *sdata,
+ struct ieee80211_twt_setup *twt = (void *)mgmt->u.action.u.s1g.variable;
+ struct ieee80211_twt_params *twt_agrt = (void *)twt->params;
+
++ if (!(twt->control & IEEE80211_TWT_CONTROL_NEG_TYPE_BROADCAST) &&
++ twt->length < sizeof(twt->control) + sizeof(*twt_agrt))
++ return;
++
+ twt_agrt->req_type &= cpu_to_le16(~IEEE80211_TWT_REQTYPE_REQUEST);
+
+ /* broadcast TWT not supported yet */
+diff --git a/net/mac802154/llsec.c b/net/mac802154/llsec.c
+index af6a7e39b7b793..7c8593d7abadb1 100644
+--- a/net/mac802154/llsec.c
++++ b/net/mac802154/llsec.c
+@@ -888,6 +888,11 @@ llsec_do_decrypt_auth(struct sk_buff *skb, const struct mac802154_llsec *sec,
+ data = skb_mac_header(skb) + skb->mac_len;
+ datalen = skb_tail_pointer(skb) - data;
+
++ if (datalen < authlen) {
++ kfree_sensitive(req);
++ return -EBADMSG;
++ }
++
+ sg_init_one(&sg, skb_mac_header(skb), assoclen + datalen);
+
+ if (!(hdr->sec.level & IEEE802154_SCF_SECLEVEL_ENC)) {
+diff --git a/net/mpls/af_mpls.c b/net/mpls/af_mpls.c
+index 2d29d230f56989..11131f6a5a94e8 100644
+--- a/net/mpls/af_mpls.c
++++ b/net/mpls/af_mpls.c
+@@ -2139,6 +2139,9 @@ static int mpls_valid_fib_dump_req(struct net *net, const struct nlmsghdr *nlh,
+ int ifindex;
+
+ if (i == RTA_OIF) {
++ if (!tb[i])
++ continue;
++
+ ifindex = nla_get_u32(tb[i]);
+ filter->dev = __dev_get_by_index(net, ifindex);
+ if (!filter->dev)
+@@ -2480,6 +2483,7 @@ static int mpls_getroute(struct sk_buff *in_skb, struct nlmsghdr *in_nlh,
+ r->rtm_family = AF_MPLS;
+ r->rtm_dst_len = 20;
+ r->rtm_src_len = 0;
++ r->rtm_tos = 0;
+ r->rtm_table = RT_TABLE_MAIN;
+ r->rtm_type = RTN_UNICAST;
+ r->rtm_scope = RT_SCOPE_UNIVERSE;
+diff --git a/net/mpls/mpls_iptunnel.c b/net/mpls/mpls_iptunnel.c
+index ef59e25dc48276..8985abcb7a0582 100644
+--- a/net/mpls/mpls_iptunnel.c
++++ b/net/mpls/mpls_iptunnel.c
+@@ -92,7 +92,7 @@ static int mpls_xmit(struct sk_buff *skb)
+ ttl = net->mpls.default_ttl;
+ else
+ ttl = ipv6_hdr(skb)->hop_limit;
+- rt6 = (struct rt6_info *)dst;
++ rt6 = dst_rt6_info(dst);
+ } else {
+ goto drop;
+ }
+diff --git a/net/mptcp/options.c b/net/mptcp/options.c
+index b525bcb4e89aa5..937223fe4c7564 100644
+--- a/net/mptcp/options.c
++++ b/net/mptcp/options.c
+@@ -152,17 +152,11 @@ static void mptcp_parse_option(const struct sk_buff *skb,
+ ptr++;
+
+ flags = (*ptr++) & MPTCP_DSS_FLAG_MASK;
+- mp_opt->data_fin = (flags & MPTCP_DSS_DATA_FIN) != 0;
+ mp_opt->dsn64 = (flags & MPTCP_DSS_DSN64) != 0;
+ mp_opt->use_map = (flags & MPTCP_DSS_HAS_MAP) != 0;
+ mp_opt->ack64 = (flags & MPTCP_DSS_ACK64) != 0;
+ mp_opt->use_ack = (flags & MPTCP_DSS_HAS_ACK);
+
+- pr_debug("data_fin=%d dsn64=%d use_map=%d ack64=%d use_ack=%d\n",
+- mp_opt->data_fin, mp_opt->dsn64,
+- mp_opt->use_map, mp_opt->ack64,
+- mp_opt->use_ack);
+-
+ expected_opsize = TCPOLEN_MPTCP_DSS_BASE;
+
+ if (mp_opt->use_ack) {
+@@ -173,12 +167,18 @@ static void mptcp_parse_option(const struct sk_buff *skb,
+ }
+
+ if (mp_opt->use_map) {
++ mp_opt->data_fin = (flags & MPTCP_DSS_DATA_FIN) != 0;
+ if (mp_opt->dsn64)
+ expected_opsize += TCPOLEN_MPTCP_DSS_MAP64;
+ else
+ expected_opsize += TCPOLEN_MPTCP_DSS_MAP32;
+ }
+
++ pr_debug("data_fin=%d dsn64=%d use_map=%d ack64=%d use_ack=%d\n",
++ mp_opt->data_fin, mp_opt->dsn64,
++ mp_opt->use_map, mp_opt->ack64,
++ mp_opt->use_ack);
++
+ /* Always parse any csum presence combination, we will enforce
+ * RFC 8684 Section 3.3.0 checks later in subflow_data_ready
+ */
+diff --git a/net/mptcp/protocol.c b/net/mptcp/protocol.c
+index 0655e1c438aba6..00314933da2a7f 100644
+--- a/net/mptcp/protocol.c
++++ b/net/mptcp/protocol.c
+@@ -3795,6 +3795,7 @@ bool mptcp_finish_join(struct sock *ssk)
+ mptcp_data_unlock(parent);
+
+ if (!ret) {
++ mptcp_pm_close_subflow(msk);
+ err_prohibited:
+ subflow->reset_reason = MPTCP_RST_EPROHIBIT;
+ return false;
+diff --git a/net/ncsi/ncsi-netlink.c b/net/ncsi/ncsi-netlink.c
+index fe681680b5d919..a4ba1f6c9d2280 100644
+--- a/net/ncsi/ncsi-netlink.c
++++ b/net/ncsi/ncsi-netlink.c
+@@ -461,6 +461,10 @@ static int ncsi_send_cmd_nl(struct sk_buff *msg, struct genl_info *info)
+ nca.req_flags = NCSI_REQ_FLAG_NETLINK_DRIVEN;
+ nca.info = info;
+ nca.payload = ntohs(hdr->length);
++ if (nca.payload > len - sizeof(*hdr)) {
++ ret = -EINVAL;
++ goto out_netlink;
++ }
+ nca.data = data + sizeof(*hdr);
+
+ ret = ncsi_xmit_cmd(&nca);
+diff --git a/net/netfilter/ipset/ip_set_bitmap_gen.h b/net/netfilter/ipset/ip_set_bitmap_gen.h
+index 9523104a90da47..40f0383883f9db 100644
+--- a/net/netfilter/ipset/ip_set_bitmap_gen.h
++++ b/net/netfilter/ipset/ip_set_bitmap_gen.h
+@@ -75,7 +75,7 @@ mtype_flush(struct ip_set *set)
+ mtype_ext_cleanup(set);
+ bitmap_zero(map->members, map->elements);
+ set->elements = 0;
+- set->ext_size = 0;
++ atomic64_set(&set->ext_size, 0);
+ }
+
+ /* Calculate the actual memory size of the set data */
+@@ -91,7 +91,7 @@ mtype_head(struct ip_set *set, struct sk_buff *skb)
+ {
+ const struct mtype *map = set->data;
+ struct nlattr *nested;
+- size_t memsize = mtype_memsize(map, set->dsize) + set->ext_size;
++ size_t memsize = mtype_memsize(map, set->dsize) + atomic64_read(&set->ext_size);
+
+ nested = nla_nest_start(skb, IPSET_ATTR_DATA);
+ if (!nested)
+diff --git a/net/netfilter/ipset/ip_set_core.c b/net/netfilter/ipset/ip_set_core.c
+index 1d6579358f9ba2..7601e4ca02775a 100644
+--- a/net/netfilter/ipset/ip_set_core.c
++++ b/net/netfilter/ipset/ip_set_core.c
+@@ -350,7 +350,7 @@ ip_set_init_comment(struct ip_set *set, struct ip_set_comment *comment,
+ size_t len = ext->comment ? strlen(ext->comment) : 0;
+
+ if (unlikely(c)) {
+- set->ext_size -= sizeof(*c) + strlen(c->str) + 1;
++ atomic64_sub(sizeof(*c) + strlen(c->str) + 1, &set->ext_size);
+ rcu_assign_pointer(comment->c, NULL);
+ kfree_rcu(c, rcu);
+ }
+@@ -362,7 +362,7 @@ ip_set_init_comment(struct ip_set *set, struct ip_set_comment *comment,
+ if (unlikely(!c))
+ return;
+ strscpy(c->str, ext->comment, len + 1);
+- set->ext_size += sizeof(*c) + strlen(c->str) + 1;
++ atomic64_add(sizeof(*c) + strlen(c->str) + 1, &set->ext_size);
+ rcu_assign_pointer(comment->c, c);
+ }
+ EXPORT_SYMBOL_GPL(ip_set_init_comment);
+@@ -392,7 +392,7 @@ ip_set_comment_free(struct ip_set *set, void *ptr)
+ c = rcu_dereference_protected(comment->c, 1);
+ if (unlikely(!c))
+ return;
+- set->ext_size -= sizeof(*c) + strlen(c->str) + 1;
++ atomic64_sub(sizeof(*c) + strlen(c->str) + 1, &set->ext_size);
+ rcu_assign_pointer(comment->c, NULL);
+ kfree_rcu(c, rcu);
+ }
+diff --git a/net/netfilter/ipset/ip_set_hash_gen.h b/net/netfilter/ipset/ip_set_hash_gen.h
+index d2da54de4d15bc..6588571648ead3 100644
+--- a/net/netfilter/ipset/ip_set_hash_gen.h
++++ b/net/netfilter/ipset/ip_set_hash_gen.h
+@@ -971,7 +971,7 @@ overwrite_extensions:
+ #endif
+ if (SET_WITH_COUNTER(set))
+ ip_set_init_counter(ext_counter(data, set), ext);
+- if (SET_WITH_COMMENT(set))
++ if (SET_WITH_COMMENT(set) && !ext->target)
+ ip_set_init_comment(set, ext_comment(data, set), ext);
+ if (SET_WITH_SKBINFO(set))
+ ip_set_init_skbinfo(ext_skbinfo(data, set), ext);
+@@ -1276,7 +1276,7 @@ mtype_head(struct ip_set *set, struct sk_buff *skb)
+ rcu_read_lock_bh();
+ t = rcu_dereference_bh(h->table);
+ mtype_ext_size(set, &elements, &ext_size);
+- memsize = mtype_ahash_memsize(h, t) + ext_size + set->ext_size;
++ memsize = mtype_ahash_memsize(h, t) + ext_size + atomic64_read(&set->ext_size);
+ htable_bits = t->htable_bits;
+ rcu_read_unlock_bh();
+
+diff --git a/net/netfilter/ipset/ip_set_list_set.c b/net/netfilter/ipset/ip_set_list_set.c
+index 7d1ba6ad514f56..bc37bc59e28287 100644
+--- a/net/netfilter/ipset/ip_set_list_set.c
++++ b/net/netfilter/ipset/ip_set_list_set.c
+@@ -421,7 +421,7 @@ list_set_flush(struct ip_set *set)
+ list_for_each_entry_safe(e, n, &map->members, list)
+ list_set_del(set, e);
+ set->elements = 0;
+- set->ext_size = 0;
++ atomic64_set(&set->ext_size, 0);
+ }
+
+ static void
+@@ -455,7 +455,7 @@ list_set_head(struct ip_set *set, struct sk_buff *skb)
+ {
+ const struct list_set *map = set->data;
+ struct nlattr *nested;
+- size_t memsize = list_set_memsize(map, set->dsize) + set->ext_size;
++ size_t memsize = list_set_memsize(map, set->dsize) + atomic64_read(&set->ext_size);
+
+ nested = nla_nest_start(skb, IPSET_ATTR_DATA);
+ if (!nested)
+diff --git a/net/netfilter/ipvs/ip_vs_app.c b/net/netfilter/ipvs/ip_vs_app.c
+index f9132b359f0c66..0c690a30a85dc4 100644
+--- a/net/netfilter/ipvs/ip_vs_app.c
++++ b/net/netfilter/ipvs/ip_vs_app.c
+@@ -368,7 +368,7 @@ static inline int app_tcp_pkt_out(struct ip_vs_conn *cp, struct sk_buff *skb,
+ if (skb_ensure_writable(skb, ipvsh->len + sizeof(*th)))
+ return 0;
+
+- th = (struct tcphdr *)(skb_network_header(skb) + ipvsh->len);
++ th = (struct tcphdr *)(skb->data + ipvsh->len);
+
+ /*
+ * Remember seq number in case this pkt gets resized
+@@ -444,7 +444,7 @@ static inline int app_tcp_pkt_in(struct ip_vs_conn *cp, struct sk_buff *skb,
+ if (skb_ensure_writable(skb, ipvsh->len + sizeof(*th)))
+ return 0;
+
+- th = (struct tcphdr *)(skb_network_header(skb) + ipvsh->len);
++ th = (struct tcphdr *)(skb->data + ipvsh->len);
+
+ /*
+ * Remember seq number in case this pkt gets resized
+diff --git a/net/netfilter/ipvs/ip_vs_conn.c b/net/netfilter/ipvs/ip_vs_conn.c
+index 49f8e51f4836ec..6c89295ffb299b 100644
+--- a/net/netfilter/ipvs/ip_vs_conn.c
++++ b/net/netfilter/ipvs/ip_vs_conn.c
+@@ -570,12 +570,6 @@ static inline void ip_vs_bind_xmit_v6(struct ip_vs_conn *cp)
+ #endif
+
+
+-static inline int ip_vs_dest_totalconns(struct ip_vs_dest *dest)
+-{
+- return atomic_read(&dest->activeconns)
+- + atomic_read(&dest->inactconns);
+-}
+-
+ /*
+ * Bind a connection entry with a virtual service destination
+ * Called just after a new connection entry is created.
+@@ -599,6 +593,9 @@ ip_vs_bind_dest(struct ip_vs_conn *cp, struct ip_vs_dest *dest)
+ flags = cp->flags;
+ /* Bind with the destination and its corresponding transmitter */
+ if (flags & IP_VS_CONN_F_SYNC) {
++ /* Synced conns are hashed, so they can not get this flag */
++ conn_flags &= ~IP_VS_CONN_F_ONE_PACKET;
++
+ /* if the connection is not template and is created
+ * by sync, preserve the activity flag.
+ */
+@@ -624,23 +621,22 @@ ip_vs_bind_dest(struct ip_vs_conn *cp, struct ip_vs_dest *dest)
+
+ /* Update the connection counters */
+ if (!(flags & IP_VS_CONN_F_TEMPLATE)) {
++ int tc;
++
+ /* It is a normal connection, so modify the counters
+ * according to the flags, later the protocol can
+ * update them on state change
+ */
+ if (!(flags & IP_VS_CONN_F_INACTIVE))
+ atomic_inc(&dest->activeconns);
+- else
+- atomic_inc(&dest->inactconns);
++ tc = atomic_inc_return(&dest->totalconns);
++ if (tc == READ_ONCE(dest->u_threshold))
++ ip_vs_dest_update_overload(dest, 1);
+ } else {
+ /* It is a persistent connection/template, so increase
+ the persistent connection counter */
+ atomic_inc(&dest->persistconns);
+ }
+-
+- if (dest->u_threshold != 0 &&
+- ip_vs_dest_totalconns(dest) >= dest->u_threshold)
+- dest->flags |= IP_VS_DEST_F_OVERLOAD;
+ }
+
+
+@@ -721,30 +717,20 @@ static inline void ip_vs_unbind_dest(struct ip_vs_conn *cp)
+
+ /* Update the connection counters */
+ if (!(cp->flags & IP_VS_CONN_F_TEMPLATE)) {
+- /* It is a normal connection, so decrease the inactconns
+- or activeconns counter */
+- if (cp->flags & IP_VS_CONN_F_INACTIVE) {
+- atomic_dec(&dest->inactconns);
+- } else {
++ int tc;
++
++ /* It is a normal connection, so decrease the counters */
++ if (!(cp->flags & IP_VS_CONN_F_INACTIVE))
+ atomic_dec(&dest->activeconns);
+- }
++ tc = atomic_fetch_dec(&dest->totalconns);
++ if (tc == READ_ONCE(dest->l_threshold_val))
++ ip_vs_dest_update_overload(dest, -1);
+ } else {
+ /* It is a persistent connection/template, so decrease
+ the persistent connection counter */
+ atomic_dec(&dest->persistconns);
+ }
+
+- if (dest->l_threshold != 0) {
+- if (ip_vs_dest_totalconns(dest) < dest->l_threshold)
+- dest->flags &= ~IP_VS_DEST_F_OVERLOAD;
+- } else if (dest->u_threshold != 0) {
+- if (ip_vs_dest_totalconns(dest) * 4 < dest->u_threshold * 3)
+- dest->flags &= ~IP_VS_DEST_F_OVERLOAD;
+- } else {
+- if (dest->flags & IP_VS_DEST_F_OVERLOAD)
+- dest->flags &= ~IP_VS_DEST_F_OVERLOAD;
+- }
+-
+ ip_vs_dest_put(dest);
+ }
+
+diff --git a/net/netfilter/ipvs/ip_vs_core.c b/net/netfilter/ipvs/ip_vs_core.c
+index 4b03857e41d770..21628f9a6ba001 100644
+--- a/net/netfilter/ipvs/ip_vs_core.c
++++ b/net/netfilter/ipvs/ip_vs_core.c
+@@ -689,7 +689,7 @@ static int sysctl_nat_icmp_send(struct netns_ipvs *ipvs) { return 0; }
+
+ #endif
+
+-__sum16 ip_vs_checksum_complete(struct sk_buff *skb, int offset)
++static __sum16 ip_vs_checksum_complete(struct sk_buff *skb, int offset)
+ {
+ return csum_fold(skb_checksum(skb, offset, skb->len - offset, 0));
+ }
+@@ -746,30 +746,28 @@ static int ip_vs_route_me_harder(struct netns_ipvs *ipvs, int af,
+ * - inout: 1=in->out, 0=out->in
+ */
+ void ip_vs_nat_icmp(struct sk_buff *skb, struct ip_vs_protocol *pp,
+- struct ip_vs_conn *cp, int inout)
++ struct ip_vs_conn *cp, int inout, unsigned int toff,
++ bool has_ports, struct ip_vs_iphdr *ciph)
+ {
+ struct iphdr *iph = ip_hdr(skb);
+- unsigned int icmp_offset = iph->ihl*4;
+- struct icmphdr *icmph = (struct icmphdr *)(skb_network_header(skb) +
+- icmp_offset);
+- struct iphdr *ciph = (struct iphdr *)(icmph + 1);
++ struct icmphdr *icmph = (struct icmphdr *)(skb->data + toff);
++ struct iphdr *cih = (struct iphdr *)(icmph + 1);
+
+ if (inout) {
+ iph->saddr = cp->vaddr.ip;
+ ip_send_check(iph);
+- ciph->daddr = cp->vaddr.ip;
+- ip_send_check(ciph);
++ cih->daddr = cp->vaddr.ip;
++ ip_send_check(cih);
+ } else {
+ iph->daddr = cp->daddr.ip;
+ ip_send_check(iph);
+- ciph->saddr = cp->daddr.ip;
+- ip_send_check(ciph);
++ cih->saddr = cp->daddr.ip;
++ ip_send_check(cih);
+ }
+
+ /* the TCP/UDP/SCTP port */
+- if (IPPROTO_TCP == ciph->protocol || IPPROTO_UDP == ciph->protocol ||
+- IPPROTO_SCTP == ciph->protocol) {
+- __be16 *ports = (void *)ciph + ciph->ihl*4;
++ if (has_ports) {
++ __be16 *ports = (void *)(skb->data + ciph->len);
+
+ if (inout)
+ ports[1] = cp->vport;
+@@ -779,48 +777,40 @@ void ip_vs_nat_icmp(struct sk_buff *skb, struct ip_vs_protocol *pp,
+
+ /* And finally the ICMP checksum */
+ icmph->checksum = 0;
+- icmph->checksum = ip_vs_checksum_complete(skb, icmp_offset);
++ icmph->checksum = ip_vs_checksum_complete(skb, toff);
+ skb->ip_summed = CHECKSUM_UNNECESSARY;
+
+ if (inout)
+- IP_VS_DBG_PKT(11, AF_INET, pp, skb, (void *)ciph - (void *)iph,
+- "Forwarding altered outgoing ICMP");
++ IP_VS_DBG_PKT(11, AF_INET, pp, skb, ciph->off,
++ "Forwarding altered outgoing ICMP");
+ else
+- IP_VS_DBG_PKT(11, AF_INET, pp, skb, (void *)ciph - (void *)iph,
+- "Forwarding altered incoming ICMP");
++ IP_VS_DBG_PKT(11, AF_INET, pp, skb, ciph->off,
++ "Forwarding altered incoming ICMP");
+ }
+
+ #ifdef CONFIG_IP_VS_IPV6
+ void ip_vs_nat_icmp_v6(struct sk_buff *skb, struct ip_vs_protocol *pp,
+- struct ip_vs_conn *cp, int inout)
++ struct ip_vs_conn *cp, int inout, unsigned int toff,
++ bool has_ports, struct ip_vs_iphdr *ciph)
+ {
+ struct ipv6hdr *iph = ipv6_hdr(skb);
+- unsigned int icmp_offset = 0;
+- unsigned int offs = 0; /* header offset*/
+- int protocol;
+ struct icmp6hdr *icmph;
+- struct ipv6hdr *ciph;
+- unsigned short fragoffs;
++ struct ipv6hdr *cih;
+
+- ipv6_find_hdr(skb, &icmp_offset, IPPROTO_ICMPV6, &fragoffs, NULL);
+- icmph = (struct icmp6hdr *)(skb_network_header(skb) + icmp_offset);
+- offs = icmp_offset + sizeof(struct icmp6hdr);
+- ciph = (struct ipv6hdr *)(skb_network_header(skb) + offs);
+-
+- protocol = ipv6_find_hdr(skb, &offs, -1, &fragoffs, NULL);
++ icmph = (struct icmp6hdr *)(skb->data + toff);
++ cih = (struct ipv6hdr *)(skb->data + ciph->off);
+
+ if (inout) {
+ iph->saddr = cp->vaddr.in6;
+- ciph->daddr = cp->vaddr.in6;
++ cih->daddr = cp->vaddr.in6;
+ } else {
+ iph->daddr = cp->daddr.in6;
+- ciph->saddr = cp->daddr.in6;
++ cih->saddr = cp->daddr.in6;
+ }
+
+ /* the TCP/UDP/SCTP port */
+- if (!fragoffs && (IPPROTO_TCP == protocol || IPPROTO_UDP == protocol ||
+- IPPROTO_SCTP == protocol)) {
+- __be16 *ports = (void *)(skb_network_header(skb) + offs);
++ if (has_ports) {
++ __be16 *ports = (void *)(skb->data + ciph->len);
+
+ IP_VS_DBG(11, "%s() changed port %d to %d\n", __func__,
+ ntohs(inout ? ports[1] : ports[0]),
+@@ -833,19 +823,17 @@ void ip_vs_nat_icmp_v6(struct sk_buff *skb, struct ip_vs_protocol *pp,
+
+ /* And finally the ICMP checksum */
+ icmph->icmp6_cksum = ~csum_ipv6_magic(&iph->saddr, &iph->daddr,
+- skb->len - icmp_offset,
++ skb->len - toff,
+ IPPROTO_ICMPV6, 0);
+- skb->csum_start = skb_network_header(skb) - skb->head + icmp_offset;
++ skb->csum_start = skb_headroom(skb) + toff;
+ skb->csum_offset = offsetof(struct icmp6hdr, icmp6_cksum);
+ skb->ip_summed = CHECKSUM_PARTIAL;
+
+ if (inout)
+- IP_VS_DBG_PKT(11, AF_INET6, pp, skb,
+- (void *)ciph - (void *)iph,
++ IP_VS_DBG_PKT(11, AF_INET6, pp, skb, ciph->off,
+ "Forwarding altered outgoing ICMPv6");
+ else
+- IP_VS_DBG_PKT(11, AF_INET6, pp, skb,
+- (void *)ciph - (void *)iph,
++ IP_VS_DBG_PKT(11, AF_INET6, pp, skb, ciph->off,
+ "Forwarding altered incoming ICMPv6");
+ }
+ #endif
+@@ -855,36 +843,41 @@ void ip_vs_nat_icmp_v6(struct sk_buff *skb, struct ip_vs_protocol *pp,
+ */
+ static int handle_response_icmp(int af, struct sk_buff *skb,
+ union nf_inet_addr *snet,
+- __u8 protocol, struct ip_vs_conn *cp,
++ struct ip_vs_conn *cp,
+ struct ip_vs_protocol *pp,
+- unsigned int offset, unsigned int ihl,
+- unsigned int hooknum)
++ struct ip_vs_iphdr *ciph,
++ unsigned int toff, unsigned int hooknum)
+ {
++ int iproto = af == AF_INET6 ? IPPROTO_ICMPV6 : IPPROTO_ICMP;
+ unsigned int verdict = NF_DROP;
++ unsigned int ctoff = ciph->len;
++ bool has_ports = false;
+
+ if (IP_VS_FWD_METHOD(cp) != IP_VS_CONN_F_MASQ)
+ goto after_nat;
+
+ /* Ensure the checksum is correct */
+- if (!skb_csum_unnecessary(skb) && ip_vs_checksum_complete(skb, ihl)) {
++ if (!ip_vs_checksum_common_check(skb, toff, iproto, af)) {
+ /* Failed checksum! */
+ IP_VS_DBG_BUF(1, "Forward ICMP: failed checksum from %s!\n",
+ IP_VS_DBG_ADDR(af, snet));
+ goto out;
+ }
+
+- if (IPPROTO_TCP == protocol || IPPROTO_UDP == protocol ||
+- IPPROTO_SCTP == protocol)
+- offset += 2 * sizeof(__u16);
+- if (skb_ensure_writable(skb, offset))
++ if (ciph->protocol == IPPROTO_TCP || ciph->protocol == IPPROTO_UDP ||
++ ciph->protocol == IPPROTO_SCTP) {
++ ctoff += 2 * sizeof(__u16);
++ has_ports = true;
++ }
++ if (skb_ensure_writable(skb, ctoff))
+ goto out;
+
+ #ifdef CONFIG_IP_VS_IPV6
+ if (af == AF_INET6)
+- ip_vs_nat_icmp_v6(skb, pp, cp, 1);
++ ip_vs_nat_icmp_v6(skb, pp, cp, 1, toff, has_ports, ciph);
+ else
+ #endif
+- ip_vs_nat_icmp(skb, pp, cp, 1);
++ ip_vs_nat_icmp(skb, pp, cp, 1, toff, has_ports, ciph);
+
+ if (ip_vs_route_me_harder(cp->ipvs, af, skb, hooknum))
+ goto out;
+@@ -912,15 +905,15 @@ out:
+ * Currently handles error types - unreachable, quench, ttl exceeded.
+ */
+ static int ip_vs_out_icmp(struct netns_ipvs *ipvs, struct sk_buff *skb,
+- int *related, unsigned int hooknum)
++ int *related, unsigned int hooknum,
++ struct ip_vs_iphdr *ipvsh)
+ {
+- struct iphdr *iph;
+ struct icmphdr _icmph, *ic;
+ struct iphdr _ciph, *cih; /* The ip header contained within the ICMP */
+ struct ip_vs_iphdr ciph;
+ struct ip_vs_conn *cp;
+ struct ip_vs_protocol *pp;
+- unsigned int offset, ihl;
++ unsigned int offset;
+ union nf_inet_addr snet;
+
+ *related = 1;
+@@ -929,17 +922,18 @@ static int ip_vs_out_icmp(struct netns_ipvs *ipvs, struct sk_buff *skb,
+ if (ip_is_fragment(ip_hdr(skb))) {
+ if (ip_vs_gather_frags(ipvs, skb, ip_vs_defrag_user(hooknum)))
+ return NF_STOLEN;
++ if (!ip_vs_fill_iph_skb(AF_INET, skb, false, ipvsh))
++ return NF_ACCEPT;
+ }
+
+- iph = ip_hdr(skb);
+- offset = ihl = iph->ihl * 4;
++ offset = ipvsh->len;
+ ic = skb_header_pointer(skb, offset, sizeof(_icmph), &_icmph);
+ if (ic == NULL)
+ return NF_DROP;
+
+ IP_VS_DBG(12, "Outgoing ICMP (%d,%d) %pI4->%pI4\n",
+ ic->type, ntohs(icmp_id(ic)),
+- &iph->saddr, &iph->daddr);
++ &ipvsh->saddr.ip, &ipvsh->daddr.ip);
+
+ /*
+ * Work through seeing if this is for us.
+@@ -957,33 +951,34 @@ static int ip_vs_out_icmp(struct netns_ipvs *ipvs, struct sk_buff *skb,
+
+ /* Now find the contained IP header */
+ offset += sizeof(_icmph);
++ if (!ip_vs_fill_iph_skb_icmp(AF_INET, skb, offset, true, &ciph))
++ return NF_ACCEPT; /* The packet looks wrong, ignore */
++
+ cih = skb_header_pointer(skb, offset, sizeof(_ciph), &_ciph);
+- if (cih == NULL)
++ if (!(cih && cih->version == 4 &&
++ ciph.len - ciph.off >= sizeof(struct iphdr)))
+ return NF_ACCEPT; /* The packet looks wrong, ignore */
+
+- pp = ip_vs_proto_get(cih->protocol);
++ pp = ip_vs_proto_get(ciph.protocol);
+ if (!pp)
+ return NF_ACCEPT;
+
+ /* Is the embedded protocol header present? */
+- if (unlikely(cih->frag_off & htons(IP_OFFSET) &&
+- pp->dont_defrag))
++ if (unlikely(cih->frag_off & htons(IP_OFFSET) && !pp->dont_defrag))
+ return NF_ACCEPT;
+
+ IP_VS_DBG_PKT(11, AF_INET, pp, skb, offset,
+ "Checking outgoing ICMP for");
+
+- ip_vs_fill_iph_skb_icmp(AF_INET, skb, offset, true, &ciph);
+-
+ /* The embedded headers contain source and dest in reverse order */
+ cp = INDIRECT_CALL_1(pp->conn_out_get, ip_vs_conn_out_get_proto,
+ ipvs, AF_INET, skb, &ciph);
+ if (!cp)
+ return NF_ACCEPT;
+
+- snet.ip = iph->saddr;
+- return handle_response_icmp(AF_INET, skb, &snet, cih->protocol, cp,
+- pp, ciph.len, ihl, hooknum);
++ snet.ip = ipvsh->saddr.ip;
++ return handle_response_icmp(AF_INET, skb, &snet, cp, pp, &ciph,
++ ipvsh->len, hooknum);
+ }
+
+ #ifdef CONFIG_IP_VS_IPV6
+@@ -996,7 +991,6 @@ static int ip_vs_out_icmp_v6(struct netns_ipvs *ipvs, struct sk_buff *skb,
+ struct ip_vs_conn *cp;
+ struct ip_vs_protocol *pp;
+ union nf_inet_addr snet;
+- unsigned int offset;
+
+ *related = 1;
+ ic = frag_safe_skb_hp(skb, ipvsh->len, sizeof(_icmph), &_icmph);
+@@ -1032,6 +1026,10 @@ static int ip_vs_out_icmp_v6(struct netns_ipvs *ipvs, struct sk_buff *skb,
+ if (!pp)
+ return NF_ACCEPT;
+
++ /* Is the embedded protocol header present? */
++ if (unlikely(ciph.fragoffs && !pp->dont_defrag))
++ return NF_ACCEPT;
++
+ /* The embedded headers contain source and dest in reverse order */
+ cp = INDIRECT_CALL_1(pp->conn_out_get, ip_vs_conn_out_get_proto,
+ ipvs, AF_INET6, skb, &ciph);
+@@ -1039,9 +1037,8 @@ static int ip_vs_out_icmp_v6(struct netns_ipvs *ipvs, struct sk_buff *skb,
+ return NF_ACCEPT;
+
+ snet.in6 = ciph.saddr.in6;
+- offset = ciph.len;
+- return handle_response_icmp(AF_INET6, skb, &snet, ciph.protocol, cp,
+- pp, offset, ipvsh->len, hooknum);
++ return handle_response_icmp(AF_INET6, skb, &snet, cp, pp, &ciph,
++ ipvsh->len, hooknum);
+ }
+ #endif
+
+@@ -1376,7 +1373,8 @@ ip_vs_out_hook(void *priv, struct sk_buff *skb, const struct nf_hook_state *stat
+ #endif
+ if (unlikely(iph.protocol == IPPROTO_ICMP)) {
+ int related;
+- int verdict = ip_vs_out_icmp(ipvs, skb, &related, hooknum);
++ int verdict = ip_vs_out_icmp(ipvs, skb, &related,
++ hooknum, &iph);
+
+ if (related)
+ return verdict;
+@@ -1580,9 +1578,8 @@ unk:
+ */
+ static int
+ ip_vs_in_icmp(struct netns_ipvs *ipvs, struct sk_buff *skb, int *related,
+- unsigned int hooknum)
++ unsigned int hooknum, struct ip_vs_iphdr *iph)
+ {
+- struct iphdr *iph;
+ struct icmphdr _icmph, *ic;
+ struct iphdr _ciph, *cih; /* The ip header contained within the ICMP */
+ struct ip_vs_iphdr ciph;
+@@ -1592,7 +1589,7 @@ ip_vs_in_icmp(struct netns_ipvs *ipvs, struct sk_buff *skb, int *related,
+ unsigned int offset, offset2, ihl, verdict;
+ bool tunnel, new_cp = false;
+ union nf_inet_addr *raddr;
+- char *outer_proto = "IPIP";
++ char *outer_proto __maybe_unused = "IPIP";
+ unsigned int hlen_ipip;
+ int ulen = 0;
+
+@@ -1602,17 +1599,19 @@ ip_vs_in_icmp(struct netns_ipvs *ipvs, struct sk_buff *skb, int *related,
+ if (ip_is_fragment(ip_hdr(skb))) {
+ if (ip_vs_gather_frags(ipvs, skb, ip_vs_defrag_user(hooknum)))
+ return NF_STOLEN;
++ if (!ip_vs_fill_iph_skb(AF_INET, skb, false, iph))
++ return NF_ACCEPT;
+ }
+
+- iph = ip_hdr(skb);
+- offset = ihl = iph->ihl * 4;
++ ihl = iph->len;
++ offset = iph->len;
+ ic = skb_header_pointer(skb, offset, sizeof(_icmph), &_icmph);
+ if (ic == NULL)
+ return NF_DROP;
+
+ IP_VS_DBG(12, "Incoming ICMP (%d,%d) %pI4->%pI4\n",
+ ic->type, ntohs(icmp_id(ic)),
+- &iph->saddr, &iph->daddr);
++ &iph->saddr.ip, &iph->daddr.ip);
+
+ /*
+ * Work through seeing if this is for us.
+@@ -1631,10 +1630,12 @@ ip_vs_in_icmp(struct netns_ipvs *ipvs, struct sk_buff *skb, int *related,
+ /* Now find the contained IP header */
+ offset += sizeof(_icmph);
+ cih = skb_header_pointer(skb, offset, sizeof(_ciph), &_ciph);
+- if (!(cih && cih->version == 4 && cih->ihl >= 5))
++ if (!cih)
+ return NF_ACCEPT; /* The packet looks wrong, ignore */
+- raddr = (union nf_inet_addr *)&cih->daddr;
+ hlen_ipip = cih->ihl * 4;
++ if (!(cih->version == 4 && hlen_ipip >= sizeof(struct iphdr)))
++ return NF_ACCEPT; /* The packet looks wrong, ignore */
++ raddr = (union nf_inet_addr *)&cih->daddr;
+
+ /* Special case for errors for IPIP/UDP/GRE tunnel packets */
+ tunnel = false;
+@@ -1651,9 +1652,6 @@ ip_vs_in_icmp(struct netns_ipvs *ipvs, struct sk_buff *skb, int *related,
+ if (!dest || dest->tun_type != IP_VS_CONN_F_TUNNEL_TYPE_IPIP)
+ return NF_ACCEPT;
+ offset += hlen_ipip;
+- cih = skb_header_pointer(skb, offset, sizeof(_ciph), &_ciph);
+- if (!(cih && cih->version == 4 && cih->ihl >= 5))
+- return NF_ACCEPT; /* The packet looks wrong, ignore */
+ tunnel = true;
+ } else if ((cih->protocol == IPPROTO_UDP || /* Can be UDP encap */
+ cih->protocol == IPPROTO_GRE) && /* Can be GRE encap */
+@@ -1678,33 +1676,32 @@ ip_vs_in_icmp(struct netns_ipvs *ipvs, struct sk_buff *skb, int *related,
+ /* Skip IP and UDP/GRE tunnel headers */
+ offset = offset2 + ulen;
+ /* Now we should be at the original IP header */
+- cih = skb_header_pointer(skb, offset, sizeof(_ciph),
+- &_ciph);
+- if (cih && cih->version == 4 && cih->ihl >= 5 &&
+- iproto == IPPROTO_IPIP)
++ if (iproto == IPPROTO_IPIP)
+ tunnel = true;
+ else
+ return NF_ACCEPT;
+ }
+ }
+
+- pd = ip_vs_proto_data_get(ipvs, cih->protocol);
++ if (!ip_vs_fill_iph_skb_icmp(AF_INET, skb, offset, !tunnel, &ciph))
++ return NF_ACCEPT;
++ pd = ip_vs_proto_data_get(ipvs, ciph.protocol);
+ if (!pd)
+ return NF_ACCEPT;
+ pp = pd->pp;
+
++ cih = skb_header_pointer(skb, offset, sizeof(_ciph), &_ciph);
++ if (!(cih && cih->version == 4 &&
++ ciph.len - ciph.off >= sizeof(struct iphdr)))
++ return NF_ACCEPT; /* The packet looks wrong, ignore */
++
+ /* Is the embedded protocol header present? */
+- if (unlikely(cih->frag_off & htons(IP_OFFSET) &&
+- pp->dont_defrag))
++ if (unlikely(cih->frag_off & htons(IP_OFFSET) && !pp->dont_defrag))
+ return NF_ACCEPT;
+
+ IP_VS_DBG_PKT(11, AF_INET, pp, skb, offset,
+ "Checking incoming ICMP for");
+
+- offset2 = offset;
+- ip_vs_fill_iph_skb_icmp(AF_INET, skb, offset, !tunnel, &ciph);
+- offset = ciph.len;
+-
+ /* The embedded headers contain source and dest in reverse order.
+ * For IPIP/UDP/GRE tunnel this is error for request, not for reply.
+ */
+@@ -1725,19 +1722,21 @@ ip_vs_in_icmp(struct netns_ipvs *ipvs, struct sk_buff *skb, int *related,
+ verdict = NF_DROP;
+
+ /* Ensure the checksum is correct */
+- if (!skb_csum_unnecessary(skb) && ip_vs_checksum_complete(skb, ihl)) {
++ if ((IP_VS_FWD_METHOD(cp) == IP_VS_CONN_F_MASQ || tunnel) &&
++ !ip_vs_checksum_common_check(skb, ihl, IPPROTO_ICMP, AF_INET)) {
+ /* Failed checksum! */
+ IP_VS_DBG(1, "Incoming ICMP: failed checksum from %pI4!\n",
+- &iph->saddr);
++ &iph->saddr.ip);
+ goto out;
+ }
+
+ if (tunnel) {
+- unsigned int hlen_orig = cih->ihl * 4;
++ unsigned int hlen_orig = ciph.len - ciph.off;
+ __be32 info = ic->un.gateway;
+ __u8 type = ic->type;
+ __u8 code = ic->code;
+
++ offset2 = offset;
+ /* Update the MTU */
+ if (ic->type == ICMP_DEST_UNREACH &&
+ ic->code == ICMP_FRAG_NEEDED) {
+@@ -1778,6 +1777,7 @@ ip_vs_in_icmp(struct netns_ipvs *ipvs, struct sk_buff *skb, int *related,
+ if (pskb_pull(skb, offset2) == NULL)
+ goto ignore_tunnel;
+ skb_reset_network_header(skb);
++ memset(&(IPCB(skb)->opt), 0, sizeof(IPCB(skb)->opt));
+ /* Ensure the IP header is present in headroom */
+ if (!pskb_may_pull(skb, hlen_orig))
+ goto ignore_tunnel;
+@@ -1796,10 +1796,7 @@ ignore_tunnel:
+
+ /* do the statistics and put it back */
+ ip_vs_in_stats(cp, skb);
+- if (IPPROTO_TCP == cih->protocol || IPPROTO_UDP == cih->protocol ||
+- IPPROTO_SCTP == cih->protocol)
+- offset += 2 * sizeof(__u16);
+- verdict = ip_vs_icmp_xmit(skb, cp, pp, offset, hooknum, &ciph);
++ verdict = ip_vs_icmp_xmit(skb, cp, pp, iph->len, hooknum, &ciph);
+
+ out:
+ if (likely(!new_cp))
+@@ -1859,8 +1856,8 @@ static int ip_vs_in_icmp_v6(struct netns_ipvs *ipvs, struct sk_buff *skb,
+ return NF_ACCEPT;
+ pp = pd->pp;
+
+- /* Cannot handle fragmented embedded protocol */
+- if (ciph.fragoffs)
++ /* Is the embedded protocol header present? */
++ if (ciph.fragoffs && !pp->dont_defrag)
+ return NF_ACCEPT;
+
+ IP_VS_DBG_PKT(11, AF_INET6, pp, skb, offset,
+@@ -1884,23 +1881,22 @@ static int ip_vs_in_icmp_v6(struct netns_ipvs *ipvs, struct sk_buff *skb,
+ new_cp = true;
+ }
+
+- /* VS/TUN, VS/DR and LOCALNODE just let it go */
+- if ((hooknum == NF_INET_LOCAL_OUT) &&
+- (IP_VS_FWD_METHOD(cp) != IP_VS_CONN_F_MASQ)) {
+- verdict = NF_ACCEPT;
++ verdict = NF_DROP;
++
++ /* Ensure the checksum is correct */
++ if (IP_VS_FWD_METHOD(cp) == IP_VS_CONN_F_MASQ &&
++ !ip_vs_checksum_common_check(skb, iph->len, IPPROTO_ICMPV6,
++ AF_INET6)) {
++ /* Failed checksum! */
++ IP_VS_DBG(1, "Incoming ICMPv6: failed checksum from %pI6c!\n",
++ &iph->saddr);
+ goto out;
+ }
+
+ /* do the statistics and put it back */
+ ip_vs_in_stats(cp, skb);
+
+- /* Need to mangle contained IPv6 header in ICMPv6 packet */
+- offset = ciph.len;
+- if (IPPROTO_TCP == ciph.protocol || IPPROTO_UDP == ciph.protocol ||
+- IPPROTO_SCTP == ciph.protocol)
+- offset += 2 * sizeof(__u16); /* Also mangle ports */
+-
+- verdict = ip_vs_icmp_xmit_v6(skb, cp, pp, offset, hooknum, &ciph);
++ verdict = ip_vs_icmp_xmit_v6(skb, cp, pp, iph->len, hooknum, &ciph);
+
+ out:
+ if (likely(!new_cp))
+@@ -1979,7 +1975,7 @@ ip_vs_in_hook(void *priv, struct sk_buff *skb, const struct nf_hook_state *state
+ if (unlikely(iph.protocol == IPPROTO_ICMP)) {
+ int related;
+ int verdict = ip_vs_in_icmp(ipvs, skb, &related,
+- hooknum);
++ hooknum, &iph);
+
+ if (related)
+ return verdict;
+@@ -2115,6 +2111,7 @@ ip_vs_forward_icmp(void *priv, struct sk_buff *skb,
+ const struct nf_hook_state *state)
+ {
+ struct netns_ipvs *ipvs = net_ipvs(state->net);
++ struct ip_vs_iphdr iphdr;
+ int r;
+
+ /* ipvs enabled in this netns ? */
+@@ -2124,10 +2121,9 @@ ip_vs_forward_icmp(void *priv, struct sk_buff *skb,
+ if (state->pf == NFPROTO_IPV4) {
+ if (ip_hdr(skb)->protocol != IPPROTO_ICMP)
+ return NF_ACCEPT;
++ ip_vs_fill_iph_skb(AF_INET, skb, false, &iphdr);
+ #ifdef CONFIG_IP_VS_IPV6
+ } else {
+- struct ip_vs_iphdr iphdr;
+-
+ ip_vs_fill_iph_skb(AF_INET6, skb, false, &iphdr);
+
+ if (iphdr.protocol != IPPROTO_ICMPV6)
+@@ -2137,7 +2133,7 @@ ip_vs_forward_icmp(void *priv, struct sk_buff *skb,
+ #endif
+ }
+
+- return ip_vs_in_icmp(ipvs, skb, &r, state->hook);
++ return ip_vs_in_icmp(ipvs, skb, &r, state->hook, &iphdr);
+ }
+
+ static const struct nf_hook_ops ip_vs_ops4[] = {
+diff --git a/net/netfilter/ipvs/ip_vs_ctl.c b/net/netfilter/ipvs/ip_vs_ctl.c
+index 15a083dd459737..c4b46607d9ba86 100644
+--- a/net/netfilter/ipvs/ip_vs_ctl.c
++++ b/net/netfilter/ipvs/ip_vs_ctl.c
+@@ -864,6 +864,40 @@ ip_vs_zero_stats(struct ip_vs_stats *stats)
+ spin_unlock_bh(&stats->lock);
+ }
+
++/* Update overload flag based on number of dest conns and lower/upper
++ * connection thresholds:
++ * - conns reach u_threshold and exceed it: set the flag
++ * - conns go below l_threshold (or 75% of u_threshold): clear the flag
++ */
++static void __ip_vs_dest_update_overload(struct ip_vs_dest *dest, int mode)
++{
++ int conns;
++ u32 l, u;
++
++ lockdep_assert_held(&dest->dst_lock);
++ u = READ_ONCE(dest->u_threshold);
++ if (!u)
++ goto unset;
++ l = READ_ONCE(dest->l_threshold_val);
++ conns = atomic_read(&dest->totalconns);
++ if (conns >= (mode > 0 ? l : u)) {
++ dest->flags |= IP_VS_DEST_F_OVERLOAD;
++ return;
++ }
++ if (conns >= (mode < 0 ? u : l))
++ return;
++
++unset:
++ dest->flags &= ~IP_VS_DEST_F_OVERLOAD;
++}
++
++void ip_vs_dest_update_overload(struct ip_vs_dest *dest, int mode)
++{
++ spin_lock_bh(&dest->dst_lock);
++ __ip_vs_dest_update_overload(dest, mode);
++ spin_unlock_bh(&dest->dst_lock);
++}
++
+ /*
+ * Update a destination in the given service
+ */
+@@ -930,10 +964,19 @@ __ip_vs_update_dest(struct ip_vs_service *svc, struct ip_vs_dest *dest,
+ /* set the dest status flags */
+ dest->flags |= IP_VS_DEST_F_AVAILABLE;
+
+- if (udest->u_threshold == 0 || udest->u_threshold > dest->u_threshold)
+- dest->flags &= ~IP_VS_DEST_F_OVERLOAD;
+- dest->u_threshold = udest->u_threshold;
+- dest->l_threshold = udest->l_threshold;
++ if (READ_ONCE(dest->u_threshold) != udest->u_threshold ||
++ READ_ONCE(dest->l_threshold) != udest->l_threshold) {
++ spin_lock_bh(&dest->dst_lock);
++ WRITE_ONCE(dest->u_threshold, udest->u_threshold);
++ WRITE_ONCE(dest->l_threshold, udest->l_threshold);
++ /* Low threshold defaults to 75% of upper threshold */
++ WRITE_ONCE(dest->l_threshold_val,
++ udest->l_threshold ? :
++ (udest->u_threshold -
++ (udest->u_threshold >> 2)));
++ __ip_vs_dest_update_overload(dest, 0);
++ spin_unlock_bh(&dest->dst_lock);
++ }
+
+ dest->af = udest->af;
+
+@@ -1011,7 +1054,7 @@ ip_vs_new_dest(struct ip_vs_service *svc, struct ip_vs_dest_user_kern *udest)
+ dest->port = udest->port;
+
+ atomic_set(&dest->activeconns, 0);
+- atomic_set(&dest->inactconns, 0);
++ atomic_set(&dest->totalconns, 0);
+ atomic_set(&dest->persistconns, 0);
+ refcount_set(&dest->refcnt, 1);
+
+@@ -1053,6 +1096,9 @@ ip_vs_add_dest(struct ip_vs_service *svc, struct ip_vs_dest_user_kern *udest)
+ return -ERANGE;
+ }
+
++ if (udest->u_threshold > INT_MAX)
++ return -EINVAL;
++
+ if (udest->tun_type == IP_VS_CONN_F_TUNNEL_TYPE_GUE) {
+ if (udest->tun_port == 0) {
+ pr_err("%s(): tunnel port is zero\n", __func__);
+@@ -1124,6 +1170,9 @@ ip_vs_edit_dest(struct ip_vs_service *svc, struct ip_vs_dest_user_kern *udest)
+ return -ERANGE;
+ }
+
++ if (udest->u_threshold > INT_MAX)
++ return -EINVAL;
++
+ if (udest->tun_type == IP_VS_CONN_F_TUNNEL_TYPE_GUE) {
+ if (udest->tun_port == 0) {
+ pr_err("%s(): tunnel port is zero\n", __func__);
+@@ -2225,7 +2274,7 @@ static int ip_vs_info_seq_show(struct seq_file *seq, void *v)
+ ip_vs_fwd_name(atomic_read(&dest->conn_flags)),
+ atomic_read(&dest->weight),
+ atomic_read(&dest->activeconns),
+- atomic_read(&dest->inactconns));
++ ip_vs_dest_inactconns(dest));
+ else
+ #endif
+ seq_printf(seq,
+@@ -2236,7 +2285,7 @@ static int ip_vs_info_seq_show(struct seq_file *seq, void *v)
+ ip_vs_fwd_name(atomic_read(&dest->conn_flags)),
+ atomic_read(&dest->weight),
+ atomic_read(&dest->activeconns),
+- atomic_read(&dest->inactconns));
++ ip_vs_dest_inactconns(dest));
+
+ }
+ }
+@@ -2714,10 +2763,10 @@ __ip_vs_get_dest_entries(struct netns_ipvs *ipvs, const struct ip_vs_get_dests *
+ entry.port = dest->port;
+ entry.conn_flags = atomic_read(&dest->conn_flags);
+ entry.weight = atomic_read(&dest->weight);
+- entry.u_threshold = dest->u_threshold;
+- entry.l_threshold = dest->l_threshold;
++ entry.u_threshold = READ_ONCE(dest->u_threshold);
++ entry.l_threshold = READ_ONCE(dest->l_threshold);
+ entry.activeconns = atomic_read(&dest->activeconns);
+- entry.inactconns = atomic_read(&dest->inactconns);
++ entry.inactconns = ip_vs_dest_inactconns(dest);
+ entry.persistconns = atomic_read(&dest->persistconns);
+ ip_vs_copy_stats(&kstats, &dest->stats);
+ ip_vs_export_stats_user(&entry.stats, &kstats);
+@@ -3316,12 +3365,14 @@ static int ip_vs_genl_fill_dest(struct sk_buff *skb, struct ip_vs_dest *dest)
+ dest->tun_port) ||
+ nla_put_u16(skb, IPVS_DEST_ATTR_TUN_FLAGS,
+ dest->tun_flags) ||
+- nla_put_u32(skb, IPVS_DEST_ATTR_U_THRESH, dest->u_threshold) ||
+- nla_put_u32(skb, IPVS_DEST_ATTR_L_THRESH, dest->l_threshold) ||
++ nla_put_u32(skb, IPVS_DEST_ATTR_U_THRESH,
++ READ_ONCE(dest->u_threshold)) ||
++ nla_put_u32(skb, IPVS_DEST_ATTR_L_THRESH,
++ READ_ONCE(dest->l_threshold)) ||
+ nla_put_u32(skb, IPVS_DEST_ATTR_ACTIVE_CONNS,
+ atomic_read(&dest->activeconns)) ||
+ nla_put_u32(skb, IPVS_DEST_ATTR_INACT_CONNS,
+- atomic_read(&dest->inactconns)) ||
++ ip_vs_dest_inactconns(dest)) ||
+ nla_put_u32(skb, IPVS_DEST_ATTR_PERSIST_CONNS,
+ atomic_read(&dest->persistconns)) ||
+ nla_put_u16(skb, IPVS_DEST_ATTR_ADDR_FAMILY, dest->af))
+diff --git a/net/netfilter/ipvs/ip_vs_lc.c b/net/netfilter/ipvs/ip_vs_lc.c
+index 9d34d81fc6f1c0..534db3c4a0160f 100644
+--- a/net/netfilter/ipvs/ip_vs_lc.c
++++ b/net/netfilter/ipvs/ip_vs_lc.c
+@@ -31,7 +31,7 @@ ip_vs_lc_schedule(struct ip_vs_service *svc, const struct sk_buff *skb,
+
+ /*
+ * Simply select the server with the least number of
+- * (activeconns<<5) + inactconns
++ * (activeconns*256) + totalconns
+ * Except whose weight is equal to zero.
+ * If the weight is equal to zero, it means that the server is
+ * quiesced, the existing connections to the server still get
+@@ -57,7 +57,7 @@ ip_vs_lc_schedule(struct ip_vs_service *svc, const struct sk_buff *skb,
+ IP_VS_DBG_ADDR(least->af, &least->addr),
+ ntohs(least->port),
+ atomic_read(&least->activeconns),
+- atomic_read(&least->inactconns));
++ ip_vs_dest_inactconns(least));
+
+ return least;
+ }
+diff --git a/net/netfilter/ipvs/ip_vs_proto_sctp.c b/net/netfilter/ipvs/ip_vs_proto_sctp.c
+index c67317be17dfaf..fb8af6b15a3999 100644
+--- a/net/netfilter/ipvs/ip_vs_proto_sctp.c
++++ b/net/netfilter/ipvs/ip_vs_proto_sctp.c
+@@ -11,7 +11,7 @@
+
+ static int
+ sctp_csum_check(int af, struct sk_buff *skb, struct ip_vs_protocol *pp,
+- unsigned int sctphoff);
++ struct ip_vs_iphdr *iph);
+
+ static int
+ sctp_conn_schedule(struct netns_ipvs *ipvs, int af, struct sk_buff *skb,
+@@ -109,7 +109,7 @@ sctp_snat_handler(struct sk_buff *skb, struct ip_vs_protocol *pp,
+ int ret;
+
+ /* Some checks before mangling */
+- if (!sctp_csum_check(cp->af, skb, pp, sctphoff))
++ if (!sctp_csum_check(cp->af, skb, pp, iph))
+ return 0;
+
+ /* Call application helper if needed */
+@@ -121,7 +121,7 @@ sctp_snat_handler(struct sk_buff *skb, struct ip_vs_protocol *pp,
+ payload_csum = true;
+ }
+
+- sctph = (void *) skb_network_header(skb) + sctphoff;
++ sctph = (void *)skb->data + sctphoff;
+
+ /* Only update csum if we really have to */
+ if (sctph->source != cp->vport || payload_csum ||
+@@ -157,7 +157,7 @@ sctp_dnat_handler(struct sk_buff *skb, struct ip_vs_protocol *pp,
+ int ret;
+
+ /* Some checks before mangling */
+- if (!sctp_csum_check(cp->af, skb, pp, sctphoff))
++ if (!sctp_csum_check(cp->af, skb, pp, iph))
+ return 0;
+
+ /* Call application helper if needed */
+@@ -169,7 +169,7 @@ sctp_dnat_handler(struct sk_buff *skb, struct ip_vs_protocol *pp,
+ payload_csum = true;
+ }
+
+- sctph = (void *) skb_network_header(skb) + sctphoff;
++ sctph = (void *)skb->data + sctphoff;
+
+ /* Only update csum if we really have to */
+ if (sctph->dest != cp->dport || payload_csum ||
+@@ -187,19 +187,22 @@ sctp_dnat_handler(struct sk_buff *skb, struct ip_vs_protocol *pp,
+
+ static int
+ sctp_csum_check(int af, struct sk_buff *skb, struct ip_vs_protocol *pp,
+- unsigned int sctphoff)
++ struct ip_vs_iphdr *iph)
+ {
++ unsigned int sctphoff = iph->len;
+ struct sctphdr *sh;
+ __le32 cmp, val;
+
++ if (!ip_vs_checksum_needed(skb))
++ return 1;
+ sh = (struct sctphdr *)(skb->data + sctphoff);
+ cmp = sh->checksum;
+ val = sctp_compute_cksum(skb, sctphoff);
+
+ if (val != cmp) {
+ /* CRC failure, dump it. */
+- IP_VS_DBG_RL_PKT(0, af, pp, skb, 0,
+- "Failed checksum for");
++ IP_VS_DBG_RL_PKT(0, af, pp, skb, iph->off,
++ "Failed checksum for");
+ return 0;
+ }
+ return 1;
+@@ -443,12 +446,10 @@ set_sctp_state(struct ip_vs_proto_data *pd, struct ip_vs_conn *cp,
+ if (!(cp->flags & IP_VS_CONN_F_INACTIVE) &&
+ (next_state != IP_VS_SCTP_S_ESTABLISHED)) {
+ atomic_dec(&dest->activeconns);
+- atomic_inc(&dest->inactconns);
+ cp->flags |= IP_VS_CONN_F_INACTIVE;
+ } else if ((cp->flags & IP_VS_CONN_F_INACTIVE) &&
+ (next_state == IP_VS_SCTP_S_ESTABLISHED)) {
+ atomic_inc(&dest->activeconns);
+- atomic_dec(&dest->inactconns);
+ cp->flags &= ~IP_VS_CONN_F_INACTIVE;
+ }
+ }
+diff --git a/net/netfilter/ipvs/ip_vs_proto_tcp.c b/net/netfilter/ipvs/ip_vs_proto_tcp.c
+index b382810156b2c6..944efd34290cde 100644
+--- a/net/netfilter/ipvs/ip_vs_proto_tcp.c
++++ b/net/netfilter/ipvs/ip_vs_proto_tcp.c
+@@ -30,7 +30,7 @@
+
+ static int
+ tcp_csum_check(int af, struct sk_buff *skb, struct ip_vs_protocol *pp,
+- unsigned int tcphoff);
++ struct ip_vs_iphdr *iph);
+
+ static int
+ tcp_conn_schedule(struct netns_ipvs *ipvs, int af, struct sk_buff *skb,
+@@ -167,7 +167,7 @@ tcp_snat_handler(struct sk_buff *skb, struct ip_vs_protocol *pp,
+ int ret;
+
+ /* Some checks before mangling */
+- if (!tcp_csum_check(cp->af, skb, pp, tcphoff))
++ if (!tcp_csum_check(cp->af, skb, pp, iph))
+ return 0;
+
+ /* Call application helper if needed */
+@@ -180,7 +180,7 @@ tcp_snat_handler(struct sk_buff *skb, struct ip_vs_protocol *pp,
+ payload_csum = true;
+ }
+
+- tcph = (void *)skb_network_header(skb) + tcphoff;
++ tcph = (void *)skb->data + tcphoff;
+ tcph->source = cp->vport;
+
+ /* Adjust TCP checksums */
+@@ -245,7 +245,7 @@ tcp_dnat_handler(struct sk_buff *skb, struct ip_vs_protocol *pp,
+ int ret;
+
+ /* Some checks before mangling */
+- if (!tcp_csum_check(cp->af, skb, pp, tcphoff))
++ if (!tcp_csum_check(cp->af, skb, pp, iph))
+ return 0;
+
+ /*
+@@ -261,7 +261,7 @@ tcp_dnat_handler(struct sk_buff *skb, struct ip_vs_protocol *pp,
+ payload_csum = true;
+ }
+
+- tcph = (void *)skb_network_header(skb) + tcphoff;
++ tcph = (void *)skb->data + tcphoff;
+ tcph->dest = cp->dport;
+
+ /*
+@@ -303,41 +303,13 @@ tcp_dnat_handler(struct sk_buff *skb, struct ip_vs_protocol *pp,
+
+ static int
+ tcp_csum_check(int af, struct sk_buff *skb, struct ip_vs_protocol *pp,
+- unsigned int tcphoff)
++ struct ip_vs_iphdr *iph)
+ {
+- switch (skb->ip_summed) {
+- case CHECKSUM_NONE:
+- skb->csum = skb_checksum(skb, tcphoff, skb->len - tcphoff, 0);
+- fallthrough;
+- case CHECKSUM_COMPLETE:
+-#ifdef CONFIG_IP_VS_IPV6
+- if (af == AF_INET6) {
+- if (csum_ipv6_magic(&ipv6_hdr(skb)->saddr,
+- &ipv6_hdr(skb)->daddr,
+- skb->len - tcphoff,
+- IPPROTO_TCP,
+- skb->csum)) {
+- IP_VS_DBG_RL_PKT(0, af, pp, skb, 0,
+- "Failed checksum for");
+- return 0;
+- }
+- } else
+-#endif
+- if (csum_tcpudp_magic(ip_hdr(skb)->saddr,
+- ip_hdr(skb)->daddr,
+- skb->len - tcphoff,
+- ip_hdr(skb)->protocol,
+- skb->csum)) {
+- IP_VS_DBG_RL_PKT(0, af, pp, skb, 0,
+- "Failed checksum for");
+- return 0;
+- }
+- break;
+- default:
+- /* No need to checksum. */
+- break;
++ if (!ip_vs_checksum_common_check(skb, iph->len, IPPROTO_TCP, af)) {
++ IP_VS_DBG_RL_PKT(0, af, pp, skb, iph->off,
++ "Failed checksum for");
++ return 0;
+ }
+-
+ return 1;
+ }
+
+@@ -555,12 +527,10 @@ set_tcp_state(struct ip_vs_proto_data *pd, struct ip_vs_conn *cp,
+ if (!(cp->flags & IP_VS_CONN_F_INACTIVE) &&
+ !tcp_state_active(new_state)) {
+ atomic_dec(&dest->activeconns);
+- atomic_inc(&dest->inactconns);
+ cp->flags |= IP_VS_CONN_F_INACTIVE;
+ } else if ((cp->flags & IP_VS_CONN_F_INACTIVE) &&
+ tcp_state_active(new_state)) {
+ atomic_inc(&dest->activeconns);
+- atomic_dec(&dest->inactconns);
+ cp->flags &= ~IP_VS_CONN_F_INACTIVE;
+ }
+ }
+diff --git a/net/netfilter/ipvs/ip_vs_proto_udp.c b/net/netfilter/ipvs/ip_vs_proto_udp.c
+index dbd4155bb07526..96ac882df15c1f 100644
+--- a/net/netfilter/ipvs/ip_vs_proto_udp.c
++++ b/net/netfilter/ipvs/ip_vs_proto_udp.c
+@@ -26,7 +26,7 @@
+
+ static int
+ udp_csum_check(int af, struct sk_buff *skb, struct ip_vs_protocol *pp,
+- unsigned int udphoff);
++ struct ip_vs_iphdr *iph);
+
+ static int
+ udp_conn_schedule(struct netns_ipvs *ipvs, int af, struct sk_buff *skb,
+@@ -156,7 +156,7 @@ udp_snat_handler(struct sk_buff *skb, struct ip_vs_protocol *pp,
+ int ret;
+
+ /* Some checks before mangling */
+- if (!udp_csum_check(cp->af, skb, pp, udphoff))
++ if (!udp_csum_check(cp->af, skb, pp, iph))
+ return 0;
+
+ /*
+@@ -171,7 +171,7 @@ udp_snat_handler(struct sk_buff *skb, struct ip_vs_protocol *pp,
+ payload_csum = true;
+ }
+
+- udph = (void *)skb_network_header(skb) + udphoff;
++ udph = (void *)skb->data + udphoff;
+ udph->source = cp->vport;
+
+ /*
+@@ -239,7 +239,7 @@ udp_dnat_handler(struct sk_buff *skb, struct ip_vs_protocol *pp,
+ int ret;
+
+ /* Some checks before mangling */
+- if (!udp_csum_check(cp->af, skb, pp, udphoff))
++ if (!udp_csum_check(cp->af, skb, pp, iph))
+ return 0;
+
+ /*
+@@ -255,7 +255,7 @@ udp_dnat_handler(struct sk_buff *skb, struct ip_vs_protocol *pp,
+ payload_csum = true;
+ }
+
+- udph = (void *)skb_network_header(skb) + udphoff;
++ udph = (void *)skb->data + udphoff;
+ udph->dest = cp->dport;
+
+ /*
+@@ -299,48 +299,20 @@ udp_dnat_handler(struct sk_buff *skb, struct ip_vs_protocol *pp,
+
+ static int
+ udp_csum_check(int af, struct sk_buff *skb, struct ip_vs_protocol *pp,
+- unsigned int udphoff)
++ struct ip_vs_iphdr *iph)
+ {
+ struct udphdr _udph, *uh;
+
+- uh = skb_header_pointer(skb, udphoff, sizeof(_udph), &_udph);
++ uh = skb_header_pointer(skb, iph->len, sizeof(_udph), &_udph);
+ if (uh == NULL)
+ return 0;
+
+- if (uh->check != 0) {
+- switch (skb->ip_summed) {
+- case CHECKSUM_NONE:
+- skb->csum = skb_checksum(skb, udphoff,
+- skb->len - udphoff, 0);
+- fallthrough;
+- case CHECKSUM_COMPLETE:
+-#ifdef CONFIG_IP_VS_IPV6
+- if (af == AF_INET6) {
+- if (csum_ipv6_magic(&ipv6_hdr(skb)->saddr,
+- &ipv6_hdr(skb)->daddr,
+- skb->len - udphoff,
+- IPPROTO_UDP,
+- skb->csum)) {
+- IP_VS_DBG_RL_PKT(0, af, pp, skb, 0,
+- "Failed checksum for");
+- return 0;
+- }
+- } else
+-#endif
+- if (csum_tcpudp_magic(ip_hdr(skb)->saddr,
+- ip_hdr(skb)->daddr,
+- skb->len - udphoff,
+- ip_hdr(skb)->protocol,
+- skb->csum)) {
+- IP_VS_DBG_RL_PKT(0, af, pp, skb, 0,
+- "Failed checksum for");
+- return 0;
+- }
+- break;
+- default:
+- /* No need to checksum. */
+- break;
+- }
++ if (!uh->check)
++ return 1;
++ if (!ip_vs_checksum_common_check(skb, iph->len, IPPROTO_UDP, af)) {
++ IP_VS_DBG_RL_PKT(0, af, pp, skb, iph->off,
++ "Failed checksum for");
++ return 0;
+ }
+ return 1;
+ }
+diff --git a/net/netfilter/ipvs/ip_vs_sync.c b/net/netfilter/ipvs/ip_vs_sync.c
+index e1dea9a8205055..bade3fa936f137 100644
+--- a/net/netfilter/ipvs/ip_vs_sync.c
++++ b/net/netfilter/ipvs/ip_vs_sync.c
+@@ -879,13 +879,10 @@ static void ip_vs_proc_conn(struct netns_ipvs *ipvs, struct ip_vs_conn_param *pa
+ spin_lock_bh(&cp->lock);
+ if ((cp->flags ^ flags) & IP_VS_CONN_F_INACTIVE &&
+ !(flags & IP_VS_CONN_F_TEMPLATE) && dest) {
+- if (flags & IP_VS_CONN_F_INACTIVE) {
++ if (flags & IP_VS_CONN_F_INACTIVE)
+ atomic_dec(&dest->activeconns);
+- atomic_inc(&dest->inactconns);
+- } else {
++ else
+ atomic_inc(&dest->activeconns);
+- atomic_dec(&dest->inactconns);
+- }
+ }
+ flags &= IP_VS_CONN_F_BACKUP_UPD_MASK;
+ flags |= cp->flags & ~IP_VS_CONN_F_BACKUP_UPD_MASK;
+diff --git a/net/netfilter/ipvs/ip_vs_xmit.c b/net/netfilter/ipvs/ip_vs_xmit.c
+index 9793eb88843732..63dd0a3d251f8d 100644
+--- a/net/netfilter/ipvs/ip_vs_xmit.c
++++ b/net/netfilter/ipvs/ip_vs_xmit.c
+@@ -184,7 +184,7 @@ static inline bool crosses_local_route_boundary(int skb_af, struct sk_buff *skb,
+ (!skb->dev || skb->dev->flags & IFF_LOOPBACK) &&
+ (addr_type & IPV6_ADDR_LOOPBACK);
+ old_rt_is_local = __ip_vs_is_local_route6(
+- (struct rt6_info *)skb_dst(skb));
++ dst_rt6_info(skb_dst(skb)));
+ } else
+ #endif
+ {
+@@ -484,7 +484,7 @@ __ip_vs_get_out_rt_v6(struct netns_ipvs *ipvs, int skb_af, struct sk_buff *skb,
+ if (dest) {
+ dest_dst = __ip_vs_dst_check(dest);
+ if (likely(dest_dst))
+- rt = (struct rt6_info *) dest_dst->dst_cache;
++ rt = dst_rt6_info(dest_dst->dst_cache);
+ else {
+ u32 cookie;
+
+@@ -504,7 +504,7 @@ __ip_vs_get_out_rt_v6(struct netns_ipvs *ipvs, int skb_af, struct sk_buff *skb,
+ ip_vs_dest_dst_free(dest_dst);
+ goto err_unreach;
+ }
+- rt = (struct rt6_info *) dst;
++ rt = dst_rt6_info(dst);
+ cookie = rt6_get_cookie(rt);
+ __ip_vs_dst_set(dest, dest_dst, &rt->dst, cookie);
+ spin_unlock_bh(&dest->dst_lock);
+@@ -520,7 +520,7 @@ __ip_vs_get_out_rt_v6(struct netns_ipvs *ipvs, int skb_af, struct sk_buff *skb,
+ rt_mode);
+ if (!dst)
+ goto err_unreach;
+- rt = (struct rt6_info *) dst;
++ rt = dst_rt6_info(dst);
+ }
+
+ local = __ip_vs_is_local_route6(rt);
+@@ -879,7 +879,7 @@ ip_vs_nat_xmit_v6(struct sk_buff *skb, struct ip_vs_conn *cp,
+ IP_VS_RT_MODE_RDR);
+ if (local < 0)
+ goto tx_error;
+- rt = (struct rt6_info *) skb_dst(skb);
++ rt = dst_rt6_info(skb_dst(skb));
+ /*
+ * Avoid duplicate tuple in reply direction for NAT traffic
+ * to local address when connection is sync-ed
+@@ -1315,7 +1315,7 @@ ip_vs_tunnel_xmit_v6(struct sk_buff *skb, struct ip_vs_conn *cp,
+ if (local)
+ return ip_vs_send_or_cont(NFPROTO_IPV6, skb, cp, 1);
+
+- rt = (struct rt6_info *) skb_dst(skb);
++ rt = dst_rt6_info(skb_dst(skb));
+ tdev = rt->dst.dev;
+
+ /*
+@@ -1511,13 +1511,15 @@ tx_error:
+ */
+ int
+ ip_vs_icmp_xmit(struct sk_buff *skb, struct ip_vs_conn *cp,
+- struct ip_vs_protocol *pp, int offset, unsigned int hooknum,
+- struct ip_vs_iphdr *iph)
++ struct ip_vs_protocol *pp, unsigned int toff,
++ unsigned int hooknum, struct ip_vs_iphdr *ciph)
+ {
+ struct rtable *rt; /* Route to the other host */
+ int rc;
+ int local;
+ int rt_mode, was_input;
++ bool has_ports = false;
++ unsigned int wlen;
+
+ EnterFunction(10);
+
+@@ -1526,7 +1528,7 @@ ip_vs_icmp_xmit(struct sk_buff *skb, struct ip_vs_conn *cp,
+ translate address/port back */
+ if (IP_VS_FWD_METHOD(cp) != IP_VS_CONN_F_MASQ) {
+ if (cp->packet_xmit)
+- rc = cp->packet_xmit(skb, cp, pp, iph);
++ rc = cp->packet_xmit(skb, cp, pp, ciph);
+ else
+ rc = NF_ACCEPT;
+ /* do not touch skb anymore */
+@@ -1544,7 +1546,7 @@ ip_vs_icmp_xmit(struct sk_buff *skb, struct ip_vs_conn *cp,
+ IP_VS_RT_MODE_LOCAL | IP_VS_RT_MODE_NON_LOCAL |
+ IP_VS_RT_MODE_RDR : IP_VS_RT_MODE_NON_LOCAL;
+ local = __ip_vs_get_out_rt(cp->ipvs, cp->af, skb, cp->dest, cp->daddr.ip, rt_mode,
+- NULL, iph);
++ NULL, ciph);
+ if (local < 0)
+ goto tx_error;
+ rt = skb_rtable(skb);
+@@ -1575,14 +1577,21 @@ ip_vs_icmp_xmit(struct sk_buff *skb, struct ip_vs_conn *cp,
+ goto tx_error;
+ }
+
++ wlen = ciph->len;
++ if (ciph->protocol == IPPROTO_TCP || ciph->protocol == IPPROTO_UDP ||
++ ciph->protocol == IPPROTO_SCTP) {
++ wlen += 2 * sizeof(__u16); /* Also mangle ports */
++ has_ports = true;
++ }
++
+ /* copy-on-write the packet before mangling it */
+- if (skb_ensure_writable(skb, offset))
++ if (skb_ensure_writable(skb, wlen))
+ goto tx_error;
+
+ if (skb_cow(skb, rt->dst.dev->hard_header_len))
+ goto tx_error;
+
+- ip_vs_nat_icmp(skb, pp, cp, 0);
++ ip_vs_nat_icmp(skb, pp, cp, 0, toff, has_ports, ciph);
+
+ /* Another hack: avoid icmp_send in ip_fragment */
+ skb->ignore_df = 1;
+@@ -1601,10 +1610,12 @@ ip_vs_icmp_xmit(struct sk_buff *skb, struct ip_vs_conn *cp,
+ #ifdef CONFIG_IP_VS_IPV6
+ int
+ ip_vs_icmp_xmit_v6(struct sk_buff *skb, struct ip_vs_conn *cp,
+- struct ip_vs_protocol *pp, int offset, unsigned int hooknum,
+- struct ip_vs_iphdr *ipvsh)
++ struct ip_vs_protocol *pp, unsigned int toff,
++ unsigned int hooknum, struct ip_vs_iphdr *ciph)
+ {
++ bool has_ports = false;
+ struct rt6_info *rt; /* Route to the other host */
++ unsigned int wlen;
+ int rc;
+ int local;
+ int rt_mode;
+@@ -1616,7 +1627,7 @@ ip_vs_icmp_xmit_v6(struct sk_buff *skb, struct ip_vs_conn *cp,
+ translate address/port back */
+ if (IP_VS_FWD_METHOD(cp) != IP_VS_CONN_F_MASQ) {
+ if (cp->packet_xmit)
+- rc = cp->packet_xmit(skb, cp, pp, ipvsh);
++ rc = cp->packet_xmit(skb, cp, pp, ciph);
+ else
+ rc = NF_ACCEPT;
+ /* do not touch skb anymore */
+@@ -1633,10 +1644,10 @@ ip_vs_icmp_xmit_v6(struct sk_buff *skb, struct ip_vs_conn *cp,
+ IP_VS_RT_MODE_LOCAL | IP_VS_RT_MODE_NON_LOCAL |
+ IP_VS_RT_MODE_RDR : IP_VS_RT_MODE_NON_LOCAL;
+ local = __ip_vs_get_out_rt_v6(cp->ipvs, cp->af, skb, cp->dest,
+- &cp->daddr.in6, NULL, ipvsh, 0, rt_mode);
++ &cp->daddr.in6, NULL, ciph, 0, rt_mode);
+ if (local < 0)
+ goto tx_error;
+- rt = (struct rt6_info *) skb_dst(skb);
++ rt = dst_rt6_info(skb_dst(skb));
+ /*
+ * Avoid duplicate tuple in reply direction for NAT traffic
+ * to local address when connection is sync-ed
+@@ -1664,14 +1675,21 @@ ip_vs_icmp_xmit_v6(struct sk_buff *skb, struct ip_vs_conn *cp,
+ goto tx_error;
+ }
+
++ wlen = ciph->len;
++ if (ciph->protocol == IPPROTO_TCP || ciph->protocol == IPPROTO_UDP ||
++ ciph->protocol == IPPROTO_SCTP) {
++ wlen += 2 * sizeof(__u16); /* Also mangle ports */
++ has_ports = true;
++ }
++
+ /* copy-on-write the packet before mangling it */
+- if (skb_ensure_writable(skb, offset))
++ if (skb_ensure_writable(skb, wlen))
+ goto tx_error;
+
+ if (skb_cow(skb, rt->dst.dev->hard_header_len))
+ goto tx_error;
+
+- ip_vs_nat_icmp_v6(skb, pp, cp, 0);
++ ip_vs_nat_icmp_v6(skb, pp, cp, 0, toff, has_ports, ciph);
+
+ /* Another hack: avoid icmp_send in ip_fragment */
+ skb->ignore_df = 1;
+diff --git a/net/netfilter/nf_conntrack_broadcast.c b/net/netfilter/nf_conntrack_broadcast.c
+index d44d9379a8a084..ef8a7ca8c11613 100644
+--- a/net/netfilter/nf_conntrack_broadcast.c
++++ b/net/netfilter/nf_conntrack_broadcast.c
+@@ -72,6 +72,7 @@ int nf_conntrack_broadcast_help(struct sk_buff *skb,
+ exp->flags = NF_CT_EXPECT_PERMANENT;
+ exp->class = NF_CT_EXPECT_CLASS_DEFAULT;
+ rcu_assign_pointer(exp->helper, helper);
++ rcu_assign_pointer(exp->assign_helper, NULL);
+ write_pnet(&exp->net, net);
+ #ifdef CONFIG_NF_CONNTRACK_ZONES
+ exp->zone = ct->zone;
+diff --git a/net/netfilter/nf_conntrack_core.c b/net/netfilter/nf_conntrack_core.c
+index f5c466ea1e7df7..342627b0d32b53 100644
+--- a/net/netfilter/nf_conntrack_core.c
++++ b/net/netfilter/nf_conntrack_core.c
+@@ -1800,16 +1800,19 @@ init_conntrack(struct net *net, struct nf_conn *tmpl,
+ spin_lock_bh(&nf_conntrack_expect_lock);
+ exp = nf_ct_find_expectation(net, zone, tuple, !tmpl || nf_ct_is_confirmed(tmpl));
+ if (exp) {
++ struct nf_conntrack_helper *assign_helper;
++
+ pr_debug("expectation arrives ct=%p exp=%p\n",
+ ct, exp);
+ /* Welcome, Mr. Bond. We've been expecting you... */
+ __set_bit(IPS_EXPECTED_BIT, &ct->status);
+ /* exp->master safe, refcnt bumped in nf_ct_find_expectation */
+ ct->master = exp->master;
+- if (exp->helper) {
++ assign_helper = rcu_dereference(exp->assign_helper);
++ if (assign_helper) {
+ help = nf_ct_helper_ext_add(ct, GFP_ATOMIC);
+ if (help)
+- rcu_assign_pointer(help->helper, exp->helper);
++ rcu_assign_pointer(help->helper, assign_helper);
+ }
+
+ #ifdef CONFIG_NF_CONNTRACK_MARK
+diff --git a/net/netfilter/nf_conntrack_expect.c b/net/netfilter/nf_conntrack_expect.c
+index 379711ea5ab67e..34324dece89df8 100644
+--- a/net/netfilter/nf_conntrack_expect.c
++++ b/net/netfilter/nf_conntrack_expect.c
+@@ -344,6 +344,7 @@ void nf_ct_expect_init(struct nf_conntrack_expect *exp, unsigned int class,
+ helper = rcu_dereference(help->helper);
+
+ rcu_assign_pointer(exp->helper, helper);
++ rcu_assign_pointer(exp->assign_helper, NULL);
+ write_pnet(&exp->net, net);
+ #ifdef CONFIG_NF_CONNTRACK_ZONES
+ exp->zone = ct->zone;
+diff --git a/net/netfilter/nf_conntrack_h323_main.c b/net/netfilter/nf_conntrack_h323_main.c
+index 791aafe9f39601..c42547284f3518 100644
+--- a/net/netfilter/nf_conntrack_h323_main.c
++++ b/net/netfilter/nf_conntrack_h323_main.c
+@@ -642,7 +642,7 @@ static int expect_h245(struct sk_buff *skb, struct nf_conn *ct,
+ &ct->tuplehash[!dir].tuple.src.u3,
+ &ct->tuplehash[!dir].tuple.dst.u3,
+ IPPROTO_TCP, NULL, &port);
+- rcu_assign_pointer(exp->helper, &nf_conntrack_helper_h245);
++ rcu_assign_pointer(exp->assign_helper, &nf_conntrack_helper_h245);
+
+ nathook = rcu_dereference(nfct_h323_nat_hook);
+ if (memcmp(&ct->tuplehash[dir].tuple.src.u3,
+@@ -766,7 +766,7 @@ static int expect_callforwarding(struct sk_buff *skb,
+ nf_ct_expect_init(exp, NF_CT_EXPECT_CLASS_DEFAULT, nf_ct_l3num(ct),
+ &ct->tuplehash[!dir].tuple.src.u3, &addr,
+ IPPROTO_TCP, NULL, &port);
+- rcu_assign_pointer(exp->helper, nf_conntrack_helper_q931);
++ rcu_assign_pointer(exp->assign_helper, nf_conntrack_helper_q931);
+
+ nathook = rcu_dereference(nfct_h323_nat_hook);
+ if (memcmp(&ct->tuplehash[dir].tuple.src.u3,
+@@ -1233,7 +1233,7 @@ static int expect_q931(struct sk_buff *skb, struct nf_conn *ct,
+ &ct->tuplehash[!dir].tuple.src.u3 : NULL,
+ &ct->tuplehash[!dir].tuple.dst.u3,
+ IPPROTO_TCP, NULL, &port);
+- rcu_assign_pointer(exp->helper, nf_conntrack_helper_q931);
++ rcu_assign_pointer(exp->assign_helper, nf_conntrack_helper_q931);
+ exp->flags = NF_CT_EXPECT_PERMANENT; /* Accept multiple calls */
+
+ nathook = rcu_dereference(nfct_h323_nat_hook);
+@@ -1305,7 +1305,7 @@ static int process_gcf(struct sk_buff *skb, struct nf_conn *ct,
+ nf_ct_expect_init(exp, NF_CT_EXPECT_CLASS_DEFAULT, nf_ct_l3num(ct),
+ &ct->tuplehash[!dir].tuple.src.u3, &addr,
+ IPPROTO_UDP, NULL, &port);
+- rcu_assign_pointer(exp->helper, nf_conntrack_helper_ras);
++ rcu_assign_pointer(exp->assign_helper, nf_conntrack_helper_ras);
+
+ if (nf_ct_expect_related(exp, 0) == 0) {
+ pr_debug("nf_ct_ras: expect RAS ");
+@@ -1522,7 +1522,7 @@ static int process_acf(struct sk_buff *skb, struct nf_conn *ct,
+ &ct->tuplehash[!dir].tuple.src.u3, &addr,
+ IPPROTO_TCP, NULL, &port);
+ exp->flags = NF_CT_EXPECT_PERMANENT;
+- rcu_assign_pointer(exp->helper, nf_conntrack_helper_q931);
++ rcu_assign_pointer(exp->assign_helper, nf_conntrack_helper_q931);
+
+ if (nf_ct_expect_related(exp, 0) == 0) {
+ pr_debug("nf_ct_ras: expect Q.931 ");
+@@ -1576,7 +1576,7 @@ static int process_lcf(struct sk_buff *skb, struct nf_conn *ct,
+ &ct->tuplehash[!dir].tuple.src.u3, &addr,
+ IPPROTO_TCP, NULL, &port);
+ exp->flags = NF_CT_EXPECT_PERMANENT;
+- rcu_assign_pointer(exp->helper, nf_conntrack_helper_q931);
++ rcu_assign_pointer(exp->assign_helper, nf_conntrack_helper_q931);
+
+ if (nf_ct_expect_related(exp, 0) == 0) {
+ pr_debug("nf_ct_ras: expect Q.931 ");
+diff --git a/net/netfilter/nf_conntrack_helper.c b/net/netfilter/nf_conntrack_helper.c
+index 8e72c3d4db4ad1..efa080cb17096e 100644
+--- a/net/netfilter/nf_conntrack_helper.c
++++ b/net/netfilter/nf_conntrack_helper.c
+@@ -422,6 +422,11 @@ static bool expect_iter_me(struct nf_conntrack_expect *exp, void *data)
+
+ this = rcu_dereference_protected(exp->helper,
+ lockdep_is_held(&nf_conntrack_expect_lock));
++ if (this == me)
++ return true;
++
++ this = rcu_dereference_protected(exp->assign_helper,
++ lockdep_is_held(&nf_conntrack_expect_lock));
+ return this == me;
+ }
+
+diff --git a/net/netfilter/nf_conntrack_netlink.c b/net/netfilter/nf_conntrack_netlink.c
+index a3b18042adece3..55bc5626b96799 100644
+--- a/net/netfilter/nf_conntrack_netlink.c
++++ b/net/netfilter/nf_conntrack_netlink.c
+@@ -2628,6 +2628,7 @@ static const struct nla_policy exp_nla_policy[CTA_EXPECT_MAX+1] = {
+
+ static struct nf_conntrack_expect *
+ ctnetlink_alloc_expect(const struct nlattr *const cda[], struct nf_conn *ct,
++ const struct nf_conntrack_helper *assign_helper,
+ struct nf_conntrack_tuple *tuple,
+ struct nf_conntrack_tuple *mask);
+
+@@ -2854,6 +2855,7 @@ static int
+ ctnetlink_glue_attach_expect(const struct nlattr *attr, struct nf_conn *ct,
+ u32 portid, u32 report)
+ {
++ struct nf_conntrack_helper *assign_helper = NULL;
+ struct nlattr *cda[CTA_EXPECT_MAX+1];
+ struct nf_conntrack_tuple tuple, mask;
+ struct nf_conntrack_expect *exp;
+@@ -2869,8 +2871,18 @@ ctnetlink_glue_attach_expect(const struct nlattr *attr, struct nf_conn *ct,
+ if (err < 0)
+ return err;
+
++ if (cda[CTA_EXPECT_HELP_NAME]) {
++ const char *helpname = nla_data(cda[CTA_EXPECT_HELP_NAME]);
++
++ assign_helper = __nf_conntrack_helper_find(helpname,
++ nf_ct_l3num(ct),
++ tuple.dst.protonum);
++ if (!assign_helper)
++ return -EOPNOTSUPP;
++ }
++
+ exp = ctnetlink_alloc_expect((const struct nlattr * const *)cda, ct,
+- &tuple, &mask);
++ assign_helper, &tuple, &mask);
+ if (IS_ERR(exp))
+ return PTR_ERR(exp);
+
+@@ -3509,6 +3521,7 @@ ctnetlink_parse_expect_nat(const struct nlattr *attr,
+
+ static struct nf_conntrack_expect *
+ ctnetlink_alloc_expect(const struct nlattr * const cda[], struct nf_conn *ct,
++ const struct nf_conntrack_helper *assign_helper,
+ struct nf_conntrack_tuple *tuple,
+ struct nf_conntrack_tuple *mask)
+ {
+@@ -3562,6 +3575,7 @@ ctnetlink_alloc_expect(const struct nlattr * const cda[], struct nf_conn *ct,
+ exp->zone = ct->zone;
+ #endif
+ rcu_assign_pointer(exp->helper, helper);
++ rcu_assign_pointer(exp->assign_helper, assign_helper);
+ exp->tuple = *tuple;
+ exp->mask.src.u3 = mask->src.u3;
+ exp->mask.src.u.all = mask->src.u.all;
+@@ -3617,7 +3631,7 @@ ctnetlink_create_expect(struct net *net,
+ ct = nf_ct_tuplehash_to_ctrack(h);
+
+ rcu_read_lock();
+- exp = ctnetlink_alloc_expect(cda, ct, &tuple, &mask);
++ exp = ctnetlink_alloc_expect(cda, ct, NULL, &tuple, &mask);
+ if (IS_ERR(exp)) {
+ err = PTR_ERR(exp);
+ goto err_rcu;
+diff --git a/net/netfilter/nf_conntrack_sip.c b/net/netfilter/nf_conntrack_sip.c
+index ec31611b7a290b..6e8ad849d14c45 100644
+--- a/net/netfilter/nf_conntrack_sip.c
++++ b/net/netfilter/nf_conntrack_sip.c
+@@ -1384,7 +1384,7 @@ static int process_register_request(struct sk_buff *skb, unsigned int protoff,
+ nf_ct_expect_init(exp, SIP_EXPECT_SIGNALLING, nf_ct_l3num(ct),
+ saddr, &daddr, proto, NULL, &port);
+ exp->timeout.expires = sip_timeout * HZ;
+- rcu_assign_pointer(exp->helper, helper);
++ rcu_assign_pointer(exp->assign_helper, helper);
+ exp->flags = NF_CT_EXPECT_PERMANENT | NF_CT_EXPECT_INACTIVE;
+
+ hooks = rcu_dereference(nf_nat_sip_hooks);
+@@ -1627,7 +1627,7 @@ static int sip_help_tcp(struct sk_buff *skb, unsigned int protoff,
+ unsigned int matchoff, matchlen;
+ unsigned int msglen, origlen;
+ const char *dptr, *end;
+- s16 diff, tdiff = 0;
++ s32 diff, tdiff = 0;
+ int ret = NF_ACCEPT;
+ unsigned long clen;
+ bool term;
+diff --git a/net/netfilter/nf_flow_table_core.c b/net/netfilter/nf_flow_table_core.c
+index 99195cf6b26575..9edc627d94b9e1 100644
+--- a/net/netfilter/nf_flow_table_core.c
++++ b/net/netfilter/nf_flow_table_core.c
+@@ -77,12 +77,8 @@ EXPORT_SYMBOL_GPL(flow_offload_alloc);
+
+ static u32 flow_offload_dst_cookie(struct flow_offload_tuple *flow_tuple)
+ {
+- const struct rt6_info *rt;
+-
+- if (flow_tuple->l3proto == NFPROTO_IPV6) {
+- rt = (const struct rt6_info *)flow_tuple->dst_cache;
+- return rt6_get_cookie(rt);
+- }
++ if (flow_tuple->l3proto == NFPROTO_IPV6)
++ return rt6_get_cookie(dst_rt6_info(flow_tuple->dst_cache));
+
+ return 0;
+ }
+diff --git a/net/netfilter/nf_flow_table_ip.c b/net/netfilter/nf_flow_table_ip.c
+index 34be2c9bc39d83..523228e969ab47 100644
+--- a/net/netfilter/nf_flow_table_ip.c
++++ b/net/netfilter/nf_flow_table_ip.c
+@@ -665,7 +665,7 @@ nf_flow_offload_ipv6_hook(void *priv, struct sk_buff *skb,
+ nf_ct_acct_update(flow->ct, tuplehash->tuple.dir, skb->len);
+
+ if (unlikely(tuplehash->tuple.xmit_type == FLOW_OFFLOAD_XMIT_XFRM)) {
+- rt = (struct rt6_info *)tuplehash->tuple.dst_cache;
++ rt = dst_rt6_info(tuplehash->tuple.dst_cache);
+ memset(skb->cb, 0, sizeof(struct inet6_skb_parm));
+ IP6CB(skb)->iif = skb->dev->ifindex;
+ IP6CB(skb)->flags = IP6SKB_FORWARDED;
+@@ -674,7 +674,7 @@ nf_flow_offload_ipv6_hook(void *priv, struct sk_buff *skb,
+
+ switch (tuplehash->tuple.xmit_type) {
+ case FLOW_OFFLOAD_XMIT_NEIGH:
+- rt = (struct rt6_info *)tuplehash->tuple.dst_cache;
++ rt = dst_rt6_info(tuplehash->tuple.dst_cache);
+ outdev = rt->dst.dev;
+ skb->dev = outdev;
+ nexthop = rt6_nexthop(rt, &flow->tuplehash[!dir].tuple.src_v6);
+diff --git a/net/netfilter/nf_nat_sip.c b/net/netfilter/nf_nat_sip.c
+index f7be30c69b5c87..a1c41defaf22de 100644
+--- a/net/netfilter/nf_nat_sip.c
++++ b/net/netfilter/nf_nat_sip.c
+@@ -315,7 +315,7 @@ next:
+ }
+
+ static void nf_nat_sip_seq_adjust(struct sk_buff *skb, unsigned int protoff,
+- s16 off)
++ s32 off)
+ {
+ enum ip_conntrack_info ctinfo;
+ struct nf_conn *ct = nf_ct_get(skb, &ctinfo);
+diff --git a/net/netfilter/nft_payload.c b/net/netfilter/nft_payload.c
+index ae3277424b839e..2a58a81ed13cf2 100644
+--- a/net/netfilter/nft_payload.c
++++ b/net/netfilter/nft_payload.c
+@@ -241,9 +241,7 @@ static bool nft_payload_reduce(struct nft_regs_track *track,
+ static bool nft_payload_offload_mask(struct nft_offload_reg *reg,
+ u32 priv_len, u32 field_len)
+ {
+- unsigned int remainder, delta, k;
+ struct nft_data mask = {};
+- __be32 remainder_mask;
+
+ if (priv_len == field_len) {
+ memset(®->mask, 0xff, priv_len);
+@@ -252,15 +250,7 @@ static bool nft_payload_offload_mask(struct nft_offload_reg *reg,
+ return false;
+ }
+
+- memset(&mask, 0xff, field_len);
+- remainder = priv_len % sizeof(u32);
+- if (remainder) {
+- k = priv_len / sizeof(u32);
+- delta = field_len - priv_len;
+- remainder_mask = htonl(~((1 << (delta * BITS_PER_BYTE)) - 1));
+- mask.data[k] = (__force u32)remainder_mask;
+- }
+-
++ memset(&mask, 0xff, priv_len);
+ memcpy(®->mask, &mask, field_len);
+
+ return true;
+diff --git a/net/netfilter/nft_rt.c b/net/netfilter/nft_rt.c
+index 7d21e16499bfa1..eea3ee809c47da 100644
+--- a/net/netfilter/nft_rt.c
++++ b/net/netfilter/nft_rt.c
+@@ -80,7 +80,7 @@ void nft_rt_get_eval(const struct nft_expr *expr,
+ if (nft_pf(pkt) != NFPROTO_IPV6)
+ goto err;
+
+- memcpy(dest, rt6_nexthop((struct rt6_info *)dst,
++ memcpy(dest, rt6_nexthop(dst_rt6_info(dst),
+ &ipv6_hdr(skb)->daddr),
+ sizeof(struct in6_addr));
+ break;
+diff --git a/net/netfilter/xt_hashlimit.c b/net/netfilter/xt_hashlimit.c
+index 0859b8f767645c..61813010cd3195 100644
+--- a/net/netfilter/xt_hashlimit.c
++++ b/net/netfilter/xt_hashlimit.c
+@@ -118,6 +118,7 @@ struct xt_hashlimit_htable {
+ refcount_t use;
+ u_int8_t family;
+ bool rnd_initialized;
++ bool ratematch;
+
+ struct hashlimit_cfg3 cfg; /* config */
+
+@@ -325,6 +326,7 @@ static int htable_create(struct net *net, struct hashlimit_cfg3 *cfg,
+ vfree(hinfo);
+ return -ENOMEM;
+ }
++ hinfo->ratematch = !!(cfg->mode & XT_HASHLIMIT_RATE_MATCH);
+ spin_lock_init(&hinfo->lock);
+
+ switch (revision) {
+@@ -868,7 +870,10 @@ static int hashlimit_mt_check_common(const struct xt_mtchk_param *par,
+ }
+
+ /* Check for overflow. */
+- if (revision >= 3 && cfg->mode & XT_HASHLIMIT_RATE_MATCH) {
++ if (cfg->mode & XT_HASHLIMIT_RATE_MATCH) {
++ if (revision < 3)
++ return -EINVAL;
++
+ if (cfg->avg == 0 || cfg->avg > U32_MAX) {
+ pr_info_ratelimited("invalid rate\n");
+ return -ERANGE;
+@@ -901,6 +906,15 @@ static int hashlimit_mt_check_common(const struct xt_mtchk_param *par,
+ mutex_unlock(&hashlimit_mutex);
+ return ret;
+ }
++ } else {
++ if ((cfg->mode & XT_HASHLIMIT_RATE_MATCH &&
++ !(*hinfo)->ratematch) ||
++ (!(cfg->mode & XT_HASHLIMIT_RATE_MATCH) &&
++ (*hinfo)->ratematch)) {
++ mutex_unlock(&hashlimit_mutex);
++ htable_put(*hinfo);
++ return -EINVAL;
++ }
+ }
+ mutex_unlock(&hashlimit_mutex);
+
+diff --git a/net/openvswitch/actions.c b/net/openvswitch/actions.c
+index f7cc87e67d3c8c..679409953ac50b 100644
+--- a/net/openvswitch/actions.c
++++ b/net/openvswitch/actions.c
+@@ -856,12 +856,8 @@ static void do_output(struct datapath *dp, struct sk_buff *skb, int out_port,
+ u16 mru = OVS_CB(skb)->mru;
+ u32 cutlen = OVS_CB(skb)->cutlen;
+
+- if (unlikely(cutlen > 0)) {
+- if (skb->len - cutlen > ovs_mac_header_len(key))
+- pskb_trim(skb, skb->len - cutlen);
+- else
+- pskb_trim(skb, ovs_mac_header_len(key));
+- }
++ if (unlikely(cutlen < skb->len))
++ pskb_trim(skb, max(cutlen, ovs_mac_header_len(key)));
+
+ if (likely(!mru ||
+ (skb->len <= mru + vport->dev->hard_header_len))) {
+@@ -1111,6 +1107,10 @@ static int execute_masked_set_action(struct sk_buff *skb,
+ return err;
+ }
+
++/* When 'last' is true, recirc() should always consume the 'skb'.
++ * Otherwise, recirc() should keep 'skb' intact regardless what
++ * actions are executed on recirculation.
++ */
+ static int execute_recirc(struct datapath *dp, struct sk_buff *skb,
+ struct sw_flow_key *key,
+ const struct nlattr *a, bool last)
+@@ -1121,8 +1121,11 @@ static int execute_recirc(struct datapath *dp, struct sk_buff *skb,
+ int err;
+
+ err = ovs_flow_key_update(skb, key);
+- if (err)
++ if (err) {
++ if (last)
++ kfree_skb(skb);
+ return err;
++ }
+ }
+ BUG_ON(!is_flow_key_valid(key));
+
+@@ -1242,22 +1245,21 @@ static int do_execute_actions(struct datapath *dp, struct sk_buff *skb,
+ clone = skb_clone(skb, GFP_ATOMIC);
+ if (clone)
+ do_output(dp, clone, port, key);
+- OVS_CB(skb)->cutlen = 0;
++ OVS_CB(skb)->cutlen = U32_MAX;
+ break;
+ }
+
+ case OVS_ACTION_ATTR_TRUNC: {
+ struct ovs_action_trunc *trunc = nla_data(a);
+
+- if (skb->len > trunc->max_len)
+- OVS_CB(skb)->cutlen = skb->len - trunc->max_len;
++ OVS_CB(skb)->cutlen = trunc->max_len;
+ break;
+ }
+
+ case OVS_ACTION_ATTR_USERSPACE:
+ output_userspace(dp, skb, key, a, attr,
+ len, OVS_CB(skb)->cutlen);
+- OVS_CB(skb)->cutlen = 0;
++ OVS_CB(skb)->cutlen = U32_MAX;
+ break;
+
+ case OVS_ACTION_ATTR_HASH:
+@@ -1331,7 +1333,7 @@ static int do_execute_actions(struct datapath *dp, struct sk_buff *skb,
+ if (!is_flow_key_valid(key)) {
+ err = ovs_flow_key_update(skb, key);
+ if (err)
+- return err;
++ break;
+ }
+
+ err = ovs_ct_execute(ovs_dp_get_net(dp), skb, key,
+diff --git a/net/openvswitch/datapath.c b/net/openvswitch/datapath.c
+index 0c0d89470145a1..4052bb0c54347a 100644
+--- a/net/openvswitch/datapath.c
++++ b/net/openvswitch/datapath.c
+@@ -251,7 +251,7 @@ void ovs_dp_process_packet(struct sk_buff *skb, struct sw_flow_key *key)
+ upcall.portid = ovs_vport_find_upcall_portid(p, skb);
+
+ upcall.mru = OVS_CB(skb)->mru;
+- error = ovs_dp_upcall(dp, skb, key, &upcall, 0);
++ error = ovs_dp_upcall(dp, skb, key, &upcall, U32_MAX);
+ switch (error) {
+ case 0:
+ case -EAGAIN:
+@@ -414,7 +414,8 @@ static int queue_userspace_packet(struct datapath *dp, struct sk_buff *skb,
+ struct sk_buff *nskb = NULL;
+ struct sk_buff *user_skb = NULL; /* to be queued to userspace */
+ struct nlattr *nla;
+- size_t len;
++ size_t msg_size;
++ size_t skb_len;
+ unsigned int hlen;
+ int err, dp_ifindex;
+ u64 hash;
+@@ -435,7 +436,8 @@ static int queue_userspace_packet(struct datapath *dp, struct sk_buff *skb,
+ skb = nskb;
+ }
+
+- if (nla_attr_size(skb->len) > USHRT_MAX) {
++ skb_len = min(skb->len, cutlen);
++ if (nla_attr_size(skb_len) > USHRT_MAX) {
+ err = -EFBIG;
+ goto out;
+ }
+@@ -450,13 +452,13 @@ static int queue_userspace_packet(struct datapath *dp, struct sk_buff *skb,
+ * padding logic. Only perform zerocopy if padding is not required.
+ */
+ if (dp->user_features & OVS_DP_F_UNALIGNED)
+- hlen = skb_zerocopy_headlen(skb);
++ hlen = min(skb_zerocopy_headlen(skb), cutlen);
+ else
+- hlen = skb->len;
++ hlen = skb_len;
+
+- len = upcall_msg_size(upcall_info, hlen - cutlen,
+- OVS_CB(skb)->acts_origlen);
+- user_skb = genlmsg_new(len, GFP_ATOMIC);
++ msg_size = upcall_msg_size(upcall_info, hlen,
++ OVS_CB(skb)->acts_origlen);
++ user_skb = genlmsg_new(msg_size, GFP_ATOMIC);
+ if (!user_skb) {
+ err = -ENOMEM;
+ goto out;
+@@ -517,7 +519,7 @@ static int queue_userspace_packet(struct datapath *dp, struct sk_buff *skb,
+ }
+
+ /* Add OVS_PACKET_ATTR_LEN when packet is truncated */
+- if (cutlen > 0 &&
++ if (skb_len < skb->len &&
+ nla_put_u32(user_skb, OVS_PACKET_ATTR_LEN, skb->len)) {
+ err = -ENOBUFS;
+ goto out;
+@@ -542,9 +544,9 @@ static int queue_userspace_packet(struct datapath *dp, struct sk_buff *skb,
+ err = -ENOBUFS;
+ goto out;
+ }
+- nla->nla_len = nla_attr_size(skb->len - cutlen);
++ nla->nla_len = nla_attr_size(skb_len);
+
+- err = skb_zerocopy(user_skb, skb, skb->len - cutlen, hlen);
++ err = skb_zerocopy(user_skb, skb, skb_len, hlen);
+ if (err)
+ goto out;
+
+@@ -601,6 +603,7 @@ static int ovs_packet_cmd_execute(struct sk_buff *skb, struct genl_info *info)
+ packet->ignore_df = 1;
+ }
+ OVS_CB(packet)->mru = mru;
++ OVS_CB(packet)->cutlen = U32_MAX;
+
+ if (a[OVS_PACKET_ATTR_HASH]) {
+ hash = nla_get_u64(a[OVS_PACKET_ATTR_HASH]);
+@@ -1057,9 +1060,8 @@ static int ovs_flow_cmd_new(struct sk_buff *skb, struct genl_info *info)
+ error = -EEXIST;
+ goto err_unlock_ovs;
+ }
+- /* The flow identifier has to be the same for flow updates.
+- * Look for any overlapping flow.
+- */
++
++ /* Look for any overlapping flow. */
+ if (unlikely(!ovs_flow_cmp(flow, &match))) {
+ if (ovs_identifier_is_key(&flow->id))
+ flow = ovs_flow_tbl_lookup_exact(&dp->table,
+@@ -1071,6 +1073,30 @@ static int ovs_flow_cmd_new(struct sk_buff *skb, struct genl_info *info)
+ goto err_unlock_ovs;
+ }
+ }
++
++ if (unlikely(reply)) {
++ size_t cur, req;
++
++ cur = ovs_flow_cmd_msg_size(acts, &new_flow->id,
++ ufid_flags);
++ req = ovs_flow_cmd_msg_size(acts, &flow->id,
++ ufid_flags);
++ if (cur < req) {
++ struct sk_buff *resized;
++
++ resized = ovs_flow_cmd_alloc_info(acts,
++ &flow->id,
++ info, false,
++ ufid_flags);
++ if (IS_ERR(resized)) {
++ error = PTR_ERR(resized);
++ goto err_unlock_ovs;
++ }
++ kfree_skb(reply);
++ reply = resized;
++ }
++ }
++
+ /* Update actions. */
+ old_acts = ovsl_dereference(flow->sf_acts);
+ rcu_assign_pointer(flow->sf_acts, acts);
+diff --git a/net/openvswitch/datapath.h b/net/openvswitch/datapath.h
+index 0cd29971a907ca..88156a677f22c5 100644
+--- a/net/openvswitch/datapath.h
++++ b/net/openvswitch/datapath.h
+@@ -114,7 +114,7 @@ struct datapath {
+ * @mru: The maximum received fragement size; 0 if the packet is not
+ * fragmented.
+ * @acts_origlen: The netlink size of the flow actions applied to this skb.
+- * @cutlen: The number of bytes from the packet end to be removed.
++ * @cutlen: The number of bytes in the packet to preserve on output.
+ */
+ struct ovs_skb_cb {
+ struct vport *input_vport;
+diff --git a/net/openvswitch/flow.c b/net/openvswitch/flow.c
+index 60ebc42a20e7eb..3111817293aa03 100644
+--- a/net/openvswitch/flow.c
++++ b/net/openvswitch/flow.c
+@@ -890,8 +890,6 @@ static int key_extract_l3l4(struct sk_buff *skb, struct sw_flow_key *key)
+ * Ethernet header
+ * @key: output flow key
+ *
+- * The caller must ensure that skb->len >= ETH_HLEN.
+- *
+ * Initializes @skb header fields as follows:
+ *
+ * - skb->mac_header: the L2 header.
+@@ -911,8 +909,6 @@ static int key_extract_l3l4(struct sk_buff *skb, struct sw_flow_key *key)
+ */
+ static int key_extract(struct sk_buff *skb, struct sw_flow_key *key)
+ {
+- struct ethhdr *eth;
+-
+ /* Flags are always used as part of stats */
+ key->tp.flags = 0;
+
+@@ -927,6 +923,13 @@ static int key_extract(struct sk_buff *skb, struct sw_flow_key *key)
+ skb_reset_network_header(skb);
+ key->eth.type = skb->protocol;
+ } else {
++ struct ethhdr *eth;
++ int err;
++
++ err = check_header(skb, ETH_HLEN);
++ if (unlikely(err))
++ return err;
++
+ eth = eth_hdr(skb);
+ ether_addr_copy(key->eth.src, eth->h_source);
+ ether_addr_copy(key->eth.dst, eth->h_dest);
+diff --git a/net/openvswitch/meter.c b/net/openvswitch/meter.c
+index f2698d2316dfcb..ab120b3ca14ad8 100644
+--- a/net/openvswitch/meter.c
++++ b/net/openvswitch/meter.c
+@@ -135,18 +135,10 @@ static void dp_meter_instance_remove(struct dp_meter_instance *ti,
+
+ static int attach_meter(struct dp_meter_table *tbl, struct dp_meter *meter)
+ {
+- struct dp_meter_instance *ti = rcu_dereference_ovsl(tbl->ti);
+- u32 hash = meter_hash(ti, meter->id);
++ struct dp_meter_instance *ti;
++ u32 hash;
+ int err;
+
+- /* In generally, slots selected should be empty, because
+- * OvS uses id-pool to fetch a available id.
+- */
+- if (unlikely(rcu_dereference_ovsl(ti->dp_meters[hash])))
+- return -EBUSY;
+-
+- dp_meter_instance_insert(ti, meter);
+-
+ /* That function is thread-safe. */
+ tbl->count++;
+ if (tbl->count >= tbl->max_meters_allowed) {
+@@ -154,16 +146,29 @@ static int attach_meter(struct dp_meter_table *tbl, struct dp_meter *meter)
+ goto attach_err;
+ }
+
+- if (tbl->count >= ti->n_meters &&
+- dp_meter_instance_realloc(tbl, ti->n_meters * 2)) {
+- err = -ENOMEM;
++ ti = rcu_dereference_ovsl(tbl->ti);
++ if (tbl->count >= ti->n_meters) {
++ err = dp_meter_instance_realloc(tbl, ti->n_meters * 2);
++ if (err)
++ goto attach_err;
++
++ ti = rcu_dereference_ovsl(tbl->ti);
++ }
++
++ hash = meter_hash(ti, meter->id);
++
++ /* In general, selected slots should be empty, because
++ * OvS uses id-pool to fetch available ids.
++ */
++ if (unlikely(rcu_dereference_ovsl(ti->dp_meters[hash]))) {
++ err = -EBUSY;
+ goto attach_err;
+ }
+
++ dp_meter_instance_insert(ti, meter);
+ return 0;
+
+ attach_err:
+- dp_meter_instance_remove(ti, meter);
+ tbl->count--;
+ return err;
+ }
+diff --git a/net/openvswitch/vport.c b/net/openvswitch/vport.c
+index 5d7af559a20bed..e83aa6417ffde0 100644
+--- a/net/openvswitch/vport.c
++++ b/net/openvswitch/vport.c
+@@ -438,7 +438,7 @@ int ovs_vport_receive(struct vport *vport, struct sk_buff *skb,
+
+ OVS_CB(skb)->input_vport = vport;
+ OVS_CB(skb)->mru = 0;
+- OVS_CB(skb)->cutlen = 0;
++ OVS_CB(skb)->cutlen = U32_MAX;
+ if (unlikely(dev_net(skb->dev) != ovs_dp_get_net(vport->dp))) {
+ u32 mark;
+
+diff --git a/net/packet/af_packet.c b/net/packet/af_packet.c
+index f3850784d66404..64843368bf10a6 100644
+--- a/net/packet/af_packet.c
++++ b/net/packet/af_packet.c
+@@ -1978,11 +1978,12 @@ static void packet_parse_headers(struct sk_buff *skb, struct socket *sock)
+ {
+ int depth;
+
++ /* On TX skb->data is the L2 header; anchor it for all socket types. */
++ skb_reset_mac_header(skb);
++
+ if ((!skb->protocol || skb->protocol == htons(ETH_P_ALL)) &&
+- sock->type == SOCK_RAW) {
+- skb_reset_mac_header(skb);
++ sock->type == SOCK_RAW)
+ skb->protocol = dev_parse_header_protocol(skb);
+- }
+
+ /* Move network header to the right position for VLAN tagged packets */
+ if (likely(skb->dev->type == ARPHRD_ETHER) &&
+@@ -4584,7 +4585,11 @@ static int packet_set_ring(struct sock *sk, union tpacket_req_u *req_u,
+
+ spin_lock(&po->bind_lock);
+ WRITE_ONCE(po->num, num);
+- if (was_running)
++ /*
++ * NETDEV_UNREGISTER may have invalidated the binding while bind_lock
++ * was dropped above. Do not re-add a fanout hook to a dead device.
++ */
++ if (was_running && READ_ONCE(po->ifindex) != -1)
+ register_prot_hook(sk);
+
+ spin_unlock(&po->bind_lock);
+diff --git a/net/phonet/pep.c b/net/phonet/pep.c
+index b5c34148fffa24..0f109795984558 100644
+--- a/net/phonet/pep.c
++++ b/net/phonet/pep.c
+@@ -55,6 +55,8 @@ static unsigned char *pep_get_sb(struct sk_buff *skb, u8 *ptype, u8 *plen,
+ ph = skb_header_pointer(skb, 0, 2, &h);
+ if (ph == NULL || ph->sb_len < 2 || !pskb_may_pull(skb, ph->sb_len))
+ return NULL;
++ /* pskb_may_pull() may have reallocated the head; refetch ph. */
++ ph = skb_header_pointer(skb, 0, 2, &h);
+ ph->sb_len -= 2;
+ *ptype = ph->sb_type;
+ *plen = ph->sb_len;
+diff --git a/net/qrtr/af_qrtr.c b/net/qrtr/af_qrtr.c
+index b9d249004a0eec..d13ca058fef6db 100644
+--- a/net/qrtr/af_qrtr.c
++++ b/net/qrtr/af_qrtr.c
+@@ -1257,6 +1257,14 @@ static int qrtr_create(struct net *net, struct socket *sock,
+ if (sock->type != SOCK_DGRAM)
+ return -EPROTOTYPE;
+
++ /* QRTR keeps its port and node state in module-global variables that
++ * are not partitioned per network namespace, and the in-kernel name
++ * service only operates in init_net. Confine the family to init_net so
++ * a socket in another namespace cannot reach the global control plane.
++ */
++ if (!net_eq(net, &init_net))
++ return -EAFNOSUPPORT;
++
+ sk = sk_alloc(net, AF_QIPCRTR, GFP_KERNEL, &qrtr_proto, kern);
+ if (!sk)
+ return -ENOMEM;
+diff --git a/net/qrtr/ns.c b/net/qrtr/ns.c
+index 559aad0e362150..4df5f0a9b74191 100644
+--- a/net/qrtr/ns.c
++++ b/net/qrtr/ns.c
+@@ -68,22 +68,18 @@ struct qrtr_server {
+ struct qrtr_node {
+ unsigned int id;
+ struct xarray servers;
++ u32 server_count;
+ };
+
+-/* Max lookup limit is chosen based on the current platform requirements. If the
+- * requirement changes in the future, this value can be increased.
+- */
+-#define QRTR_NS_MAX_LOOKUPS 64
+-
+ /* Max nodes, server, lookup limits are chosen based on the current platform
+ * requirements. If the requirement changes in the future, these values can be
+ * increased.
+ */
+-#define QRTR_NS_MAX_NODES 64
++#define QRTR_NS_MAX_NODES 512
+ #define QRTR_NS_MAX_SERVERS 256
+-#define QRTR_NS_MAX_LOOKUPS 64
++#define QRTR_NS_MAX_LOOKUPS 128
+
+-static u8 node_count;
++static u16 node_count;
+
+ static struct qrtr_node *node_get(unsigned int node_id)
+ {
+@@ -249,6 +245,17 @@ static struct qrtr_server *server_add(unsigned int service,
+ if (!service || !port)
+ return NULL;
+
++ node = node_get(node_id);
++ if (!node)
++ return NULL;
++
++ /* Make sure the new servers per port are capped at the maximum value */
++ old = xa_load(&node->servers, port);
++ if (!old && node->server_count >= QRTR_NS_MAX_SERVERS) {
++ pr_err_ratelimited("QRTR client node %u exceeds max server limit!\n", node_id);
++ return NULL;
++ }
++
+ srv = kzalloc(sizeof(*srv), GFP_KERNEL);
+ if (!srv)
+ return NULL;
+@@ -258,10 +265,6 @@ static struct qrtr_server *server_add(unsigned int service,
+ srv->node = node_id;
+ srv->port = port;
+
+- node = node_get(node_id);
+- if (!node)
+- goto err;
+-
+ /* Delete the old server on the same port */
+ old = xa_store(&node->servers, port, srv, GFP_KERNEL);
+ if (old) {
+@@ -272,6 +275,8 @@ static struct qrtr_server *server_add(unsigned int service,
+ } else {
+ kfree(old);
+ }
++ } else {
++ node->server_count++;
+ }
+
+ trace_qrtr_ns_server_add(srv->service, srv->instance,
+@@ -312,6 +317,7 @@ static int server_del(struct qrtr_node *node, unsigned int port, bool bcast)
+ }
+
+ kfree(srv);
++ node->server_count--;
+
+ return 0;
+ }
+@@ -406,6 +412,7 @@ static int ctrl_cmd_bye(struct sockaddr_qrtr *from)
+ delete_node:
+ xa_erase(&nodes, from->sq_node);
+ kfree(node);
++ node_count--;
+
+ return ret;
+ }
+@@ -708,7 +715,7 @@ static void qrtr_ns_worker(struct work_struct *work)
+ }
+
+ if (ret < 0)
+- pr_err("failed while handling packet from %d:%d",
++ pr_err_ratelimited("failed while handling packet from %d:%d",
+ sq.sq_node, sq.sq_port);
+ }
+
+diff --git a/net/rds/ib.c b/net/rds/ib.c
+index ce5be43c5fbac3..1061bcf7d13151 100644
+--- a/net/rds/ib.c
++++ b/net/rds/ib.c
+@@ -431,6 +431,10 @@ static int rds_ib_laddr_check_cm(struct net *net, const struct in6_addr *addr,
+ sa = (struct sockaddr *)&sin;
+ } else {
+ #if IS_ENABLED(CONFIG_IPV6)
++ if (!ipv6_mod_enabled()) {
++ ret = -EADDRNOTAVAIL;
++ goto out;
++ }
+ memset(&sin6, 0, sizeof(sin6));
+ sin6.sin6_family = AF_INET6;
+ sin6.sin6_addr = *addr;
+diff --git a/net/rds/ib_cm.c b/net/rds/ib_cm.c
+index 5289afbb61aa70..e50e01abb07993 100644
+--- a/net/rds/ib_cm.c
++++ b/net/rds/ib_cm.c
+@@ -810,6 +810,10 @@ int rds_ib_cm_handle_connect(struct rdma_cm_id *cm_id,
+ dp = event->param.conn.private_data;
+ if (isv6) {
+ #if IS_ENABLED(CONFIG_IPV6)
++ if (!ipv6_mod_enabled()) {
++ err = -EOPNOTSUPP;
++ goto out;
++ }
+ dp_cmn = &dp->ricp_v6.dp_cmn;
+ saddr6 = &dp->ricp_v6.dp_saddr;
+ daddr6 = &dp->ricp_v6.dp_daddr;
+diff --git a/net/rds/recv.c b/net/rds/recv.c
+index a316180d3c32ec..7fd77e1b4fe71c 100644
+--- a/net/rds/recv.c
++++ b/net/rds/recv.c
+@@ -365,6 +365,21 @@ void rds_recv_incoming(struct rds_connection *conn, struct in6_addr *saddr,
+ goto out;
+ }
+
++ /*
++ * rds_find_bound() uses a global (netns-agnostic) hash table.
++ * An RDS connection created in netns A can match a socket bound
++ * in the init netns, delivering inc cross-netns with inc->i_conn
++ * pointing into netns A. When cleanup_net() then frees that conn,
++ * any subsequent dereference of inc->i_conn is a use-after-free.
++ * Drop the inc if the receiving socket lives in a different netns.
++ */
++ if (!net_eq(sock_net(rds_rs_to_sk(rs)), rds_conn_net(conn))) {
++ rds_stats_inc(s_recv_drop_no_sock);
++ rds_sock_put(rs);
++ rs = NULL;
++ goto out;
++ }
++
+ /* Process extension headers */
+ rds_recv_incoming_exthdrs(inc, rs);
+
+diff --git a/net/rds/tcp.c b/net/rds/tcp.c
+index 4444fd82b66df7..323fa5ed5c3ead 100644
+--- a/net/rds/tcp.c
++++ b/net/rds/tcp.c
+@@ -330,21 +330,25 @@ int rds_tcp_laddr_check(struct net *net, const struct in6_addr *addr,
+ /* If the scope_id is specified, check only those addresses
+ * hosted on the specified interface.
+ */
++ rcu_read_lock();
+ if (scope_id != 0) {
+- rcu_read_lock();
+ dev = dev_get_by_index_rcu(net, scope_id);
+ /* scope_id is not valid... */
+ if (!dev) {
+ rcu_read_unlock();
+ return -EADDRNOTAVAIL;
+ }
+- rcu_read_unlock();
+ }
+ #if IS_ENABLED(CONFIG_IPV6)
+- ret = ipv6_chk_addr(net, addr, dev, 0);
+- if (ret)
+- return 0;
++ if (ipv6_mod_enabled()) {
++ ret = ipv6_chk_addr(net, addr, dev, 0);
++ if (ret) {
++ rcu_read_unlock();
++ return 0;
++ }
++ }
+ #endif
++ rcu_read_unlock();
+ return -EADDRNOTAVAIL;
+ }
+
+diff --git a/net/sched/act_gact.c b/net/sched/act_gact.c
+index 62d682b96b8852..7e68b531908b81 100644
+--- a/net/sched/act_gact.c
++++ b/net/sched/act_gact.c
+@@ -88,6 +88,11 @@ static int tcf_gact_init(struct net *net, struct nlattr *nla,
+ p_parm = nla_data(tb[TCA_GACT_PROB]);
+ if (p_parm->ptype >= MAX_RAND)
+ return -EINVAL;
++ if (!tcf_action_valid(p_parm->paction)) {
++ NL_SET_ERR_MSG(extack,
++ "invalid fallback control action");
++ return -EINVAL;
++ }
+ if (TC_ACT_EXT_CMP(p_parm->paction, TC_ACT_GOTO_CHAIN)) {
+ NL_SET_ERR_MSG(extack,
+ "goto chain not allowed on fallback");
+diff --git a/net/sched/act_police.c b/net/sched/act_police.c
+index 94be21378e7ca5..6156a779f0a829 100644
+--- a/net/sched/act_police.c
++++ b/net/sched/act_police.c
+@@ -126,6 +126,12 @@ static int tcf_police_init(struct net *net, struct nlattr *nla,
+
+ if (tb[TCA_POLICE_RESULT]) {
+ tcfp_result = nla_get_u32(tb[TCA_POLICE_RESULT]);
++ if (!tcf_action_valid(tcfp_result)) {
++ NL_SET_ERR_MSG(extack,
++ "invalid fallback control action");
++ err = -EINVAL;
++ goto failure;
++ }
+ if (TC_ACT_EXT_CMP(tcfp_result, TC_ACT_GOTO_CHAIN)) {
+ NL_SET_ERR_MSG(extack,
+ "goto chain not allowed on fallback");
+diff --git a/net/sched/act_tunnel_key.c b/net/sched/act_tunnel_key.c
+index 55a9dff1cc1e6d..ca4c3776f0f045 100644
+--- a/net/sched/act_tunnel_key.c
++++ b/net/sched/act_tunnel_key.c
+@@ -342,14 +342,20 @@ static const struct nla_policy tunnel_key_policy[TCA_TUNNEL_KEY_MAX + 1] = {
+ [TCA_TUNNEL_KEY_ENC_TTL] = { .type = NLA_U8 },
+ };
+
+-static void tunnel_key_release_params(struct tcf_tunnel_key_params *p)
++static void tunnel_key_release_params_rcu(struct rcu_head *head)
+ {
+- if (!p)
+- return;
++ struct tcf_tunnel_key_params *p = container_of(head, typeof(*p), rcu);
++
+ if (p->tcft_action == TCA_TUNNEL_KEY_ACT_SET)
+ dst_release(&p->tcft_enc_metadata->dst);
++ kfree(p);
++}
+
+- kfree_rcu(p, rcu);
++static void tunnel_key_release_params(struct tcf_tunnel_key_params *p)
++{
++ if (!p)
++ return;
++ call_rcu(&p->rcu, tunnel_key_release_params_rcu);
+ }
+
+ static int tunnel_key_init(struct net *net, struct nlattr *nla,
+diff --git a/net/sched/cls_route.c b/net/sched/cls_route.c
+index 306188bf2d1fff..6c205fcb65475c 100644
+--- a/net/sched/cls_route.c
++++ b/net/sched/cls_route.c
+@@ -51,6 +51,7 @@ struct route4_filter {
+ struct tcf_result res;
+ struct tcf_exts exts;
+ u32 handle;
++ bool dying;
+ struct route4_bucket *bkt;
+ struct tcf_proto *tp;
+ struct rcu_work rwork;
+@@ -65,9 +66,11 @@ static inline int route4_fastmap_hash(u32 id, int iif)
+
+ static DEFINE_SPINLOCK(fastmap_lock);
+ static void
+-route4_reset_fastmap(struct route4_head *head)
++route4_reset_fastmap(struct route4_head *head, struct route4_filter *f)
+ {
+ spin_lock_bh(&fastmap_lock);
++ if (f)
++ f->dying = true;
+ memset(head->fastmap, 0, sizeof(head->fastmap));
+ spin_unlock_bh(&fastmap_lock);
+ }
+@@ -80,9 +83,11 @@ route4_set_fastmap(struct route4_head *head, u32 id, int iif,
+
+ /* fastmap updates must look atomic to aling id, iff, filter */
+ spin_lock_bh(&fastmap_lock);
+- head->fastmap[h].id = id;
+- head->fastmap[h].iif = iif;
+- head->fastmap[h].filter = f;
++ if (f == ROUTE4_FAILURE || !f->dying) {
++ head->fastmap[h].id = id;
++ head->fastmap[h].iif = iif;
++ head->fastmap[h].filter = f;
++ }
+ spin_unlock_bh(&fastmap_lock);
+ }
+
+@@ -295,6 +300,13 @@ static void route4_destroy(struct tcf_proto *tp, bool rtnl_held,
+ next = rtnl_dereference(f->next);
+ RCU_INIT_POINTER(b->ht[h2], next);
+ tcf_unbind_filter(tp, &f->res);
++ /* Mark the filter dying under fastmap_lock so
++ * any in-flight reader that still holds it
++ * will skip the republish in route4_set_fastmap().
++ */
++ spin_lock_bh(&fastmap_lock);
++ f->dying = true;
++ spin_unlock_bh(&fastmap_lock);
+ if (tcf_exts_get_net(&f->exts))
+ route4_queue_work(f);
+ else
+@@ -305,6 +317,11 @@ static void route4_destroy(struct tcf_proto *tp, bool rtnl_held,
+ kfree_rcu(b, rcu);
+ }
+ }
++
++ /* All filters are unlinked and marked dying, so no in-flight
++ * reader can republish a stale entry after this reset.
++ */
++ route4_reset_fastmap(head, NULL);
+ kfree_rcu(head, rcu);
+ }
+
+@@ -332,11 +349,11 @@ static int route4_delete(struct tcf_proto *tp, void *arg, bool *last,
+ /* unlink it */
+ RCU_INIT_POINTER(*fp, rtnl_dereference(f->next));
+
+- /* Remove any fastmap lookups that might ref filter
+- * notice we unlink'd the filter so we can't get it
+- * back in the fastmap.
++ /* Clear any fastmap entries that may ref this filter and
++ * mark it dying so in-flight readers can't republish it
++ * after the reset.
+ */
+- route4_reset_fastmap(head);
++ route4_reset_fastmap(head, f);
+
+ /* Delete it */
+ tcf_unbind_filter(tp, &f->res);
+@@ -551,7 +568,7 @@ static int route4_change(struct net *net, struct sk_buff *in_skb,
+ }
+ }
+
+- route4_reset_fastmap(head);
++ route4_reset_fastmap(head, fold);
+ *arg = f;
+ if (fold) {
+ tcf_unbind_filter(tp, &fold->res);
+diff --git a/net/sched/sch_api.c b/net/sched/sch_api.c
+index f3e7067f9bac21..c00e0a7c6c49d8 100644
+--- a/net/sched/sch_api.c
++++ b/net/sched/sch_api.c
+@@ -1063,6 +1063,9 @@ static int qdisc_graft(struct net_device *dev, struct Qdisc *parent,
+ unsigned int i, num_q, ingress;
+ struct netdev_queue *dev_queue;
+
++ if (new)
++ new->depth = 0;
++
+ ingress = 0;
+ num_q = dev->num_tx_queues;
+ if ((q && q->flags & TCQ_F_INGRESS) ||
+@@ -1160,9 +1163,15 @@ skip:
+ NL_SET_ERR_MSG(extack, "STAB not supported on a non root");
+ return -EINVAL;
+ }
++ if (new && parent->depth >= 7) {
++ NL_SET_ERR_MSG(extack, "Qdisc hierarchy is too deep");
++ return -E2BIG;
++ }
+ err = cops->graft(parent, cl, new, &old, extack);
+ if (err)
+ return err;
++ if (new)
++ new->depth = parent->depth + 1;
+ notify_and_destroy(net, skb, n, classid, old, new, extack);
+ }
+ return 0;
+diff --git a/net/sched/sch_cake.c b/net/sched/sch_cake.c
+index e210a676dc340b..1c6f2c623939f7 100644
+--- a/net/sched/sch_cake.c
++++ b/net/sched/sch_cake.c
+@@ -1281,7 +1281,6 @@ static struct sk_buff *cake_ack_filter(struct cake_sched_data *q,
+
+ seglen = ntohs(ipv6h_check->payload_len);
+ } else {
+- WARN_ON(1); /* shouldn't happen */
+ continue;
+ }
+
+diff --git a/net/sctp/associola.c b/net/sctp/associola.c
+index 8b97b13d4c2f03..c141f8a1262dfb 100644
+--- a/net/sctp/associola.c
++++ b/net/sctp/associola.c
+@@ -545,6 +545,9 @@ void sctp_assoc_rm_peer(struct sctp_association *asoc,
+ asoc->addip_last_asconf->transport == peer)
+ asoc->addip_last_asconf->transport = NULL;
+
++ if (asoc->new_transport == peer)
++ asoc->new_transport = NULL;
++
+ /* If we have something on the transmitted list, we have to
+ * save it off. The best place is the active path.
+ */
+@@ -575,6 +578,10 @@ void sctp_assoc_rm_peer(struct sctp_association *asoc,
+ if (ch->transport == peer)
+ ch->transport = NULL;
+
++ list_for_each_entry(ch, &asoc->outqueue.control_chunk_list, list)
++ if (ch->transport == peer)
++ ch->transport = NULL;
++
+ asoc->peer.transport_count--;
+
+ sctp_ulpevent_notify_peer_addr_change(peer, SCTP_ADDR_REMOVED, 0);
+@@ -616,6 +623,9 @@ struct sctp_transport *sctp_assoc_add_peer(struct sctp_association *asoc,
+ return peer;
+ }
+
++ if (asoc->peer.transport_count == U16_MAX)
++ return NULL;
++
+ peer = sctp_transport_new(asoc->base.net, addr, gfp);
+ if (!peer)
+ return NULL;
+@@ -1725,6 +1735,8 @@ void sctp_asconf_queue_teardown(struct sctp_association *asoc)
+ sctp_assoc_free_asconf_queue(asoc);
+
+ /* Free any cached ASCONF chunk. */
+- if (asoc->addip_last_asconf)
++ if (asoc->addip_last_asconf) {
+ sctp_chunk_free(asoc->addip_last_asconf);
++ asoc->addip_last_asconf = NULL;
++ }
+ }
+diff --git a/net/sctp/auth.c b/net/sctp/auth.c
+index 34964145514e6d..a983f96bb0c395 100644
+--- a/net/sctp/auth.c
++++ b/net/sctp/auth.c
+@@ -766,7 +766,7 @@ int sctp_auth_ep_add_chunkid(struct sctp_endpoint *ep, __u8 chunk_id)
+ /* Check if we can add this chunk to the array */
+ param_len = ntohs(p->param_hdr.length);
+ nchunks = param_len - sizeof(struct sctp_paramhdr);
+- if (nchunks == SCTP_NUM_CHUNK_TYPES)
++ if (nchunks == SCTP_AUTH_MAX_CHUNKS)
+ return -EINVAL;
+
+ p->chunks[nchunks] = chunk_id;
+diff --git a/net/sctp/ipv6.c b/net/sctp/ipv6.c
+index a1cb8ac0408af6..be190f5696d88e 100644
+--- a/net/sctp/ipv6.c
++++ b/net/sctp/ipv6.c
+@@ -416,7 +416,7 @@ out:
+ if (!IS_ERR_OR_NULL(dst)) {
+ struct rt6_info *rt;
+
+- rt = (struct rt6_info *)dst;
++ rt = dst_rt6_info(dst);
+ t->dst_cookie = rt6_get_cookie(rt);
+ pr_debug("rt6_dst:%pI6/%d rt6_src:%pI6\n",
+ &rt->rt6i_dst.addr, rt->rt6i_dst.plen,
+diff --git a/net/sctp/outqueue.c b/net/sctp/outqueue.c
+index 20831079fb09e7..987d2372e31c91 100644
+--- a/net/sctp/outqueue.c
++++ b/net/sctp/outqueue.c
+@@ -650,6 +650,7 @@ static int __sctp_outq_flush_rtx(struct sctp_outq *q, struct sctp_packet *pkt,
+ if (chunk->tsn_gap_acked) {
+ list_move_tail(&chunk->transmitted_list,
+ &transport->transmitted);
++ chunk->transport = transport;
+ continue;
+ }
+
+diff --git a/net/sctp/sm_make_chunk.c b/net/sctp/sm_make_chunk.c
+index 3089d5e577584f..6d738f95aff1d9 100644
+--- a/net/sctp/sm_make_chunk.c
++++ b/net/sctp/sm_make_chunk.c
+@@ -1821,9 +1821,9 @@ no_hmac:
+ goto fail;
+ }
+
+- /* Check to see if the cookie is stale. If there is already
+- * an association, there is no need to check cookie's expiration
+- * for init collision case of lost COOKIE ACK.
++ /* Check to see if the cookie is stale. RFC 9260 Section 5.2.4
++ * exempts an expired cookie only when both Verification Tags match
++ * the current association.
+ * If skb has been timestamped, then use the stamp, otherwise
+ * use current time. This introduces a small possibility that
+ * a cookie may be considered expired, but this would only slow
+@@ -1834,7 +1834,10 @@ no_hmac:
+ else
+ kt = ktime_get_real();
+
+- if (!asoc && ktime_before(bear_cookie->expiration, kt)) {
++ if ((!asoc ||
++ asoc->c.my_vtag != bear_cookie->my_vtag ||
++ asoc->c.peer_vtag != bear_cookie->peer_vtag) &&
++ ktime_before(bear_cookie->expiration, kt)) {
+ suseconds_t usecs = ktime_to_us(ktime_sub(kt, bear_cookie->expiration));
+ __be32 n = htonl(usecs);
+
+@@ -2187,7 +2190,13 @@ static enum sctp_ierror sctp_verify_param(struct net *net,
+ case SCTP_PARAM_HEARTBEAT_INFO:
+ case SCTP_PARAM_UNRECOGNIZED_PARAMETERS:
+ case SCTP_PARAM_ECN_CAPABLE:
++ break;
+ case SCTP_PARAM_ADAPTATION_LAYER_IND:
++ if (ntohs(param.p->length) != sizeof(*param.aind)) {
++ sctp_process_inv_paramlength(asoc, param.p,
++ chunk, err_chunk);
++ retval = SCTP_IERROR_ABORT;
++ }
+ break;
+
+ case SCTP_PARAM_SUPPORTED_EXT:
+@@ -3179,6 +3188,12 @@ static __be16 sctp_process_asconf_param(struct sctp_association *asoc,
+ if (!peer)
+ return SCTP_ERROR_DNS_FAILED;
+
++ /* Don't free asconf->transport; a later wildcard DEL-IP
++ * parameter reuses it.
++ */
++ if (peer == asconf->transport)
++ return SCTP_ERROR_REQ_REFUSED;
++
+ sctp_assoc_rm_peer(asoc, peer);
+ break;
+ case SCTP_PARAM_SET_PRIMARY:
+@@ -3347,12 +3362,11 @@ struct sctp_chunk *sctp_process_asconf(struct sctp_association *asoc,
+ goto done;
+ }
+ done:
+- asoc->peer.addip_serial++;
+-
+ /* If we are sending a new ASCONF_ACK hold a reference to it in assoc
+ * after freeing the reference to old asconf ack if any.
+ */
+ if (asconf_ack) {
++ asoc->peer.addip_serial++;
+ sctp_chunk_hold(asconf_ack);
+ list_add_tail(&asconf_ack->transmitted_list,
+ &asoc->asconf_ack_list);
+diff --git a/net/sctp/sm_statefuns.c b/net/sctp/sm_statefuns.c
+index d1cbc806fe84cb..4a029098a7f178 100644
+--- a/net/sctp/sm_statefuns.c
++++ b/net/sctp/sm_statefuns.c
+@@ -640,7 +640,7 @@ static bool sctp_auth_chunk_verify(struct net *net, struct sctp_chunk *chunk,
+ struct sctp_chunk auth;
+
+ if (!chunk->auth_chunk)
+- return true;
++ return !sctp_auth_recv_cid(chunk->chunk_hdr->type, asoc);
+
+ /* SCTP-AUTH: auth_chunk pointer is only set when the cookie-echo
+ * is supposed to be authenticated and we have to do delayed
+@@ -6111,8 +6111,12 @@ enum sctp_disposition sctp_sf_t4_timer_expire(
+ struct sctp_cmd_seq *commands)
+ {
+ struct sctp_chunk *chunk = asoc->addip_last_asconf;
+- struct sctp_transport *transport = chunk->transport;
++ struct sctp_transport *transport;
++
++ if (!chunk)
++ return SCTP_DISPOSITION_CONSUME;
+
++ transport = chunk->transport;
+ SCTP_INC_STATS(net, SCTP_MIB_T4_RTO_EXPIREDS);
+
+ /* ADDIP 4.1 B1) Increment the error counters and perform path failure
+diff --git a/net/sctp/stream.c b/net/sctp/stream.c
+index d38e5431f359dc..34754ba23198ae 100644
+--- a/net/sctp/stream.c
++++ b/net/sctp/stream.c
+@@ -308,7 +308,8 @@ int sctp_send_reset_streams(struct sctp_association *asoc,
+ goto out;
+
+ param_len += str_nums * sizeof(__u16) +
+- sizeof(struct sctp_strreset_inreq);
++ (out ? sizeof(struct sctp_strreset_inreq)
++ : sizeof(struct sctp_strreset_outreq));
+ }
+
+ if (param_len > SCTP_MAX_CHUNK_LEN -
+@@ -639,6 +640,9 @@ struct sctp_chunk *sctp_process_strreset_inreq(
+
+ nums = (ntohs(param.p->length) - sizeof(*inreq)) / sizeof(__u16);
+ str_p = inreq->list_of_streams;
++ if (nums * sizeof(__u16) + sizeof(struct sctp_strreset_outreq) >
++ SCTP_MAX_CHUNK_LEN - sizeof(struct sctp_reconf_chunk))
++ goto out;
+ for (i = 0; i < nums; i++) {
+ if (ntohs(str_p[i]) >= stream->outcnt) {
+ result = SCTP_STRRESET_ERR_WRONG_SSN;
+diff --git a/net/smc/af_smc.c b/net/smc/af_smc.c
+index ae97f47f4fda06..d069e5b156e513 100644
+--- a/net/smc/af_smc.c
++++ b/net/smc/af_smc.c
+@@ -1874,11 +1874,12 @@ static void smc_listen_out(struct smc_sock *new_smc)
+ atomic_dec(&lsmc->queued_smc_hs);
+
+ release_sock(newsmcsk); /* lock in smc_listen_work() */
++ lock_sock_nested(&lsmc->sk, SINGLE_DEPTH_NESTING);
+ if (lsmc->sk.sk_state == SMC_LISTEN) {
+- lock_sock_nested(&lsmc->sk, SINGLE_DEPTH_NESTING);
+ smc_accept_enqueue(&lsmc->sk, newsmcsk);
+ release_sock(&lsmc->sk);
+ } else { /* no longer listening */
++ release_sock(&lsmc->sk);
+ smc_close_non_accepted(newsmcsk);
+ }
+
+diff --git a/net/smc/smc_core.c b/net/smc/smc_core.c
+index 890785d4f6b69b..448b7bdf54be21 100644
+--- a/net/smc/smc_core.c
++++ b/net/smc/smc_core.c
+@@ -1468,10 +1468,10 @@ static void __smc_lgr_terminate(struct smc_link_group *lgr, bool soft)
+ read_lock_bh(&lgr->conns_lock);
+ node = rb_first(&lgr->conns_all);
+ while (node) {
+- read_unlock_bh(&lgr->conns_lock);
+ conn = rb_entry(node, struct smc_connection, alert_node);
+ smc = container_of(conn, struct smc_sock, conn);
+ sock_hold(&smc->sk); /* sock_put below */
++ read_unlock_bh(&lgr->conns_lock);
+ lock_sock(&smc->sk);
+ smc_conn_kill(conn, soft);
+ release_sock(&smc->sk);
+diff --git a/net/smc/smc_llc.c b/net/smc/smc_llc.c
+index fcb24a0ccf7619..761515b590f20c 100644
+--- a/net/smc/smc_llc.c
++++ b/net/smc/smc_llc.c
+@@ -1901,7 +1901,8 @@ static void smc_llc_event_handler(struct smc_llc_qentry *qentry)
+ return;
+ case SMC_LLC_CONFIRM_LINK:
+ case SMC_LLC_ADD_LINK_CONT:
+- if (lgr->llc_flow_lcl.type != SMC_LLC_FLOW_NONE) {
++ if (lgr->llc_flow_lcl.type != SMC_LLC_FLOW_NONE &&
++ !lgr->llc_flow_lcl.qentry) {
+ /* a flow is waiting for this message */
+ smc_llc_flow_qentry_set(&lgr->llc_flow_lcl, qentry);
+ wake_up(&lgr->llc_msg_waiter);
+diff --git a/net/smc/smc_rx.c b/net/smc/smc_rx.c
+index 8f838ddeaafe81..477d0156bd238a 100644
+--- a/net/smc/smc_rx.c
++++ b/net/smc/smc_rx.c
+@@ -146,7 +146,12 @@ static const struct pipe_buf_operations smc_pipe_ops = {
+ static void smc_rx_spd_release(struct splice_pipe_desc *spd,
+ unsigned int i)
+ {
++ struct smc_spd_priv *priv = (struct smc_spd_priv *)spd->partial[i].private;
++ struct sock *sk = &priv->smc->sk;
++
++ kfree(priv);
+ put_page(spd->pages[i]);
++ sock_put(sk);
+ }
+
+ static int smc_rx_splice(struct pipe_inode_info *pipe, char *src, size_t len,
+@@ -205,6 +210,10 @@ static int smc_rx_splice(struct pipe_inode_info *pipe, char *src, size_t len,
+ offset = 0;
+ }
+ }
++ for (i = 0; i < nr_pages; i++) {
++ get_page(pages[i]);
++ sock_hold(&smc->sk);
++ }
+ spd.nr_pages_max = nr_pages;
+ spd.nr_pages = nr_pages;
+ spd.pages = pages;
+@@ -213,16 +222,8 @@ static int smc_rx_splice(struct pipe_inode_info *pipe, char *src, size_t len,
+ spd.spd_release = smc_rx_spd_release;
+
+ bytes = splice_to_pipe(pipe, &spd);
+- if (bytes > 0) {
+- sock_hold(&smc->sk);
+- if (!lgr->is_smcd && smc->conn.rmb_desc->is_vm) {
+- for (i = 0; i < PAGE_ALIGN(bytes + offset) / PAGE_SIZE; i++)
+- get_page(pages[i]);
+- } else {
+- get_page(smc->conn.rmb_desc->pages);
+- }
++ if (bytes > 0)
+ atomic_add(bytes, &smc->conn.splice_pending);
+- }
+ kfree(priv);
+ kfree(partial);
+ kfree(pages);
+diff --git a/net/sunrpc/xprtrdma/rpc_rdma.c b/net/sunrpc/xprtrdma/rpc_rdma.c
+index e201b37578a70e..aa57e057ff451f 100644
+--- a/net/sunrpc/xprtrdma/rpc_rdma.c
++++ b/net/sunrpc/xprtrdma/rpc_rdma.c
+@@ -542,6 +542,7 @@ void rpcrdma_sendctx_unmap(struct rpcrdma_sendctx *sc)
+
+ rpcrdma_sendctx_dma_unmap(sc);
+ sc->sc_req = NULL;
++ req->rl_sendctx = NULL;
+ rpcrdma_req_put(req);
+ }
+
+@@ -550,8 +551,11 @@ void rpcrdma_sendctx_unmap(struct rpcrdma_sendctx *sc)
+ */
+ static void rpcrdma_sendctx_cancel(struct rpcrdma_sendctx *sc)
+ {
++ struct rpcrdma_req *req = sc->sc_req;
++
+ rpcrdma_sendctx_dma_unmap(sc);
+ sc->sc_req = NULL;
++ req->rl_sendctx = NULL;
+ }
+
+ /* Prepare an SGE for the RPC-over-RDMA transport header.
+diff --git a/net/sunrpc/xprtrdma/verbs.c b/net/sunrpc/xprtrdma/verbs.c
+index 27bb176f082f63..a97f0b18ac4294 100644
+--- a/net/sunrpc/xprtrdma/verbs.c
++++ b/net/sunrpc/xprtrdma/verbs.c
+@@ -1067,9 +1067,15 @@ static struct rpcrdma_rep *rpcrdma_rep_get_locked(struct rpcrdma_buffer *buf)
+ * @buf: buffer pool
+ * @rep: rep to release
+ *
++ * The rep's transient association with an rpc_rqst, established
++ * by rpcrdma_reply_handler() and torn down here, must not survive
++ * onto rb_free_reps: rpcrdma_post_recvs() pulls reps from the free
++ * list to re-post them, and a non-NULL rr_rqst on a free-listed rep
++ * would imply the rep is still referenced by a req.
+ */
+ void rpcrdma_rep_put(struct rpcrdma_buffer *buf, struct rpcrdma_rep *rep)
+ {
++ rep->rr_rqst = NULL;
+ llist_add(&rep->rr_node, &buf->rb_free_reps);
+ }
+
+@@ -1252,9 +1258,11 @@ rpcrdma_mr_get(struct rpcrdma_xprt *r_xprt)
+ */
+ void rpcrdma_reply_put(struct rpcrdma_buffer *buffers, struct rpcrdma_req *req)
+ {
+- if (req->rl_reply) {
+- rpcrdma_rep_put(buffers, req->rl_reply);
++ struct rpcrdma_rep *rep = req->rl_reply;
++
++ if (rep) {
+ req->rl_reply = NULL;
++ rpcrdma_rep_put(buffers, rep);
+ }
+ /* I2: rl_reply NULL after the put closes the
+ * 'rep on rb_free_reps still referenced by req' window.
+diff --git a/net/tipc/core.c b/net/tipc/core.c
+index 434e70eabe0812..1ddecea1df6e91 100644
+--- a/net/tipc/core.c
++++ b/net/tipc/core.c
+@@ -218,6 +218,11 @@ static void __exit tipc_exit(void)
+ unregister_pernet_device(&tipc_net_ops);
+ tipc_unregister_sysctl();
+
++ /* TODO: Wait for all timers that called call_rcu() to finish before
++ * calling rcu_barrier().
++ */
++ rcu_barrier();
++
+ pr_info("Deactivated\n");
+ }
+
+diff --git a/net/tipc/discover.c b/net/tipc/discover.c
+index e8dcdf267c0c3f..835ff27f8ea88c 100644
+--- a/net/tipc/discover.c
++++ b/net/tipc/discover.c
+@@ -58,6 +58,7 @@
+ * @skb: request message to be (repeatedly) sent
+ * @timer: timer governing period between requests
+ * @timer_intv: current interval between requests (in ms)
++ * @rcu: RCU head for deferred freeing
+ */
+ struct tipc_discoverer {
+ u32 bearer_id;
+@@ -69,6 +70,7 @@ struct tipc_discoverer {
+ struct sk_buff *skb;
+ struct timer_list timer;
+ unsigned long timer_intv;
++ struct rcu_head rcu;
+ };
+
+ /**
+@@ -382,6 +384,15 @@ int tipc_disc_create(struct net *net, struct tipc_bearer *b,
+ return 0;
+ }
+
++static void tipc_disc_free_rcu(struct rcu_head *rp)
++{
++ struct tipc_discoverer *d = container_of(rp, struct tipc_discoverer,
++ rcu);
++
++ kfree_skb(d->skb);
++ kfree(d);
++}
++
+ /**
+ * tipc_disc_delete - destroy object sending periodic link setup requests
+ * @d: ptr to link dest structure
+@@ -389,8 +400,7 @@ int tipc_disc_create(struct net *net, struct tipc_bearer *b,
+ void tipc_disc_delete(struct tipc_discoverer *d)
+ {
+ del_timer_sync(&d->timer);
+- kfree_skb(d->skb);
+- kfree(d);
++ call_rcu(&d->rcu, tipc_disc_free_rcu);
+ }
+
+ /**
+diff --git a/net/tipc/netlink.c b/net/tipc/netlink.c
+index 8336a9664703fe..575b6f71c09ecf 100644
+--- a/net/tipc/netlink.c
++++ b/net/tipc/netlink.c
+@@ -113,12 +113,16 @@ const struct nla_policy tipc_nl_node_policy[TIPC_NLA_NODE_MAX + 1] = {
+ };
+
+ /* Properties valid for media, bearer and link */
++static struct netlink_range_validation tipc_nl_mtu_range = {
++ .max = U16_MAX,
++};
++
+ const struct nla_policy tipc_nl_prop_policy[TIPC_NLA_PROP_MAX + 1] = {
+ [TIPC_NLA_PROP_UNSPEC] = { .type = NLA_UNSPEC },
+ [TIPC_NLA_PROP_PRIO] = { .type = NLA_U32 },
+ [TIPC_NLA_PROP_TOL] = { .type = NLA_U32 },
+ [TIPC_NLA_PROP_WIN] = { .type = NLA_U32 },
+- [TIPC_NLA_PROP_MTU] = { .type = NLA_U32 },
++ [TIPC_NLA_PROP_MTU] = NLA_POLICY_FULL_RANGE(NLA_U32, &tipc_nl_mtu_range),
+ [TIPC_NLA_PROP_BROADCAST] = { .type = NLA_U32 },
+ [TIPC_NLA_PROP_BROADCAST_RATIO] = { .type = NLA_U32 }
+ };
+diff --git a/net/tipc/netlink_compat.c b/net/tipc/netlink_compat.c
+index 9eb7cab6b2f60f..5a722a8fa36d1b 100644
+--- a/net/tipc/netlink_compat.c
++++ b/net/tipc/netlink_compat.c
+@@ -226,6 +226,10 @@ static int __tipc_nl_compat_dumpit(struct tipc_nl_compat_cmd_dump *cmd,
+ int rem;
+
+ len = (*cmd->dumpit)(buf, &cb);
++ if (len < 0) {
++ err = len;
++ goto err_out;
++ }
+
+ nlmsg_for_each_msg(nlmsg, nlmsg_hdr(buf), len, rem) {
+ err = nlmsg_parse_deprecated(nlmsg, GENL_HDRLEN,
+diff --git a/net/tipc/node.c b/net/tipc/node.c
+index d2b2adec808ba8..256904240987d3 100644
+--- a/net/tipc/node.c
++++ b/net/tipc/node.c
+@@ -1063,18 +1063,23 @@ static void __tipc_node_link_down(struct tipc_node *n, int *bearer_id,
+
+ static void tipc_node_link_down(struct tipc_node *n, int bearer_id, bool delete)
+ {
+- struct tipc_link_entry *le = &n->links[bearer_id];
+ struct tipc_media_addr *maddr = NULL;
+- struct tipc_link *l = le->link;
+ int old_bearer_id = bearer_id;
++ struct tipc_link_entry *le;
+ struct sk_buff_head xmitq;
+-
+- if (!l)
+- return;
++ struct tipc_link *l;
+
+ __skb_queue_head_init(&xmitq);
+
++ /* Synchronize the link lookup with bearer teardown. */
+ tipc_node_write_lock(n);
++ le = &n->links[bearer_id];
++ l = le->link;
++ if (!l) {
++ tipc_node_write_unlock_fast(n);
++ return;
++ }
++
+ if (!tipc_link_is_establishing(l)) {
+ __tipc_node_link_down(n, &bearer_id, &xmitq, &maddr);
+ } else {
+diff --git a/net/tipc/socket.c b/net/tipc/socket.c
+index c981bca5af5947..407a66a9487c86 100644
+--- a/net/tipc/socket.c
++++ b/net/tipc/socket.c
+@@ -503,6 +503,7 @@ static int tipc_sk_create(struct net *net, struct socket *sock,
+ tipc_set_sk_state(sk, TIPC_OPEN);
+ if (tipc_sk_insert(tsk)) {
+ sk_free(sk);
++ sock->sk = NULL;
+ pr_warn("Socket create failed; port number exhausted\n");
+ return -EINVAL;
+ }
+@@ -796,7 +797,7 @@ static __poll_t tipc_poll(struct file *file, struct socket *sock,
+ __poll_t revents = 0;
+
+ sock_poll_wait(file, sock, wait);
+- trace_tipc_sk_poll(sk, NULL, TIPC_DUMP_ALL, " ");
++ trace_tipc_sk_poll(sk, NULL, TIPC_DUMP_NONE, " ");
+
+ if (sk->sk_shutdown & RCV_SHUTDOWN)
+ revents |= EPOLLRDHUP | EPOLLIN | EPOLLRDNORM;
+diff --git a/net/tls/tls_sw.c b/net/tls/tls_sw.c
+index 1b4e35dcb996b3..5eec7c10acc20c 100644
+--- a/net/tls/tls_sw.c
++++ b/net/tls/tls_sw.c
+@@ -457,7 +457,7 @@ int tls_tx_records(struct sock *sk, int flags)
+ }
+
+ tx_err:
+- if (rc < 0 && rc != -EAGAIN)
++ if (rc < 0 && rc != -EAGAIN && rc != -EINTR && rc != -ERESTARTSYS)
+ tls_err_abort(sk, rc);
+
+ return rc;
+diff --git a/net/unix/af_unix.c b/net/unix/af_unix.c
+index 3e5dc698416f09..a4fa3c279a465e 100644
+--- a/net/unix/af_unix.c
++++ b/net/unix/af_unix.c
+@@ -1778,6 +1778,8 @@ static void unix_detach_fds(struct scm_cookie *scm, struct sk_buff *skb)
+ static void unix_peek_fds(struct scm_cookie *scm, struct sk_buff *skb)
+ {
+ scm->fp = scm_fp_dup(UNIXCB(skb).fp);
++
++ unix_peek_fpl(scm->fp);
+ }
+
+ static void unix_destruct_scm(struct sk_buff *skb)
+diff --git a/net/unix/garbage.c b/net/unix/garbage.c
+index 66fd606c43f45d..fa6983dc3181d9 100644
+--- a/net/unix/garbage.c
++++ b/net/unix/garbage.c
+@@ -306,6 +306,25 @@ void unix_destroy_fpl(struct scm_fp_list *fpl)
+ unix_free_vertices(fpl);
+ }
+
++static bool gc_in_progress;
++static seqcount_t unix_peek_seq = SEQCNT_ZERO(unix_peek_seq);
++
++void unix_peek_fpl(struct scm_fp_list *fpl)
++{
++ static DEFINE_SPINLOCK(unix_peek_lock);
++
++ if (!fpl || !fpl->count_unix)
++ return;
++
++ if (!READ_ONCE(gc_in_progress))
++ return;
++
++ /* Invalidate the final refcnt check in unix_vertex_dead(). */
++ spin_lock(&unix_peek_lock);
++ raw_write_seqcount_barrier(&unix_peek_seq);
++ spin_unlock(&unix_peek_lock);
++}
++
+ static bool unix_vertex_dead(struct unix_vertex *vertex)
+ {
+ struct unix_edge *edge;
+@@ -339,6 +358,36 @@ static bool unix_vertex_dead(struct unix_vertex *vertex)
+ return true;
+ }
+
++static LIST_HEAD(unix_visited_vertices);
++static unsigned long unix_vertex_grouped_index = UNIX_VERTEX_INDEX_MARK2;
++
++static bool unix_scc_dead(struct list_head *scc, bool fast)
++{
++ struct unix_vertex *vertex;
++ bool scc_dead = true;
++ unsigned int seq;
++
++ seq = read_seqcount_begin(&unix_peek_seq);
++
++ list_for_each_entry_reverse(vertex, scc, scc_entry) {
++ /* Don't restart DFS from this vertex. */
++ list_move_tail(&vertex->entry, &unix_visited_vertices);
++
++ /* Mark vertex as off-stack for __unix_walk_scc(). */
++ if (!fast)
++ vertex->index = unix_vertex_grouped_index;
++
++ if (scc_dead)
++ scc_dead = unix_vertex_dead(vertex);
++ }
++
++ /* If MSG_PEEK intervened, defer this SCC to the next round. */
++ if (read_seqcount_retry(&unix_peek_seq, seq))
++ return false;
++
++ return scc_dead;
++}
++
+ static void unix_collect_skb(struct list_head *scc, struct sk_buff_head *hitlist)
+ {
+ struct unix_vertex *vertex;
+@@ -392,9 +441,6 @@ static bool unix_scc_cyclic(struct list_head *scc)
+ return false;
+ }
+
+-static LIST_HEAD(unix_visited_vertices);
+-static unsigned long unix_vertex_grouped_index = UNIX_VERTEX_INDEX_MARK2;
+-
+ static void __unix_walk_scc(struct unix_vertex *vertex, unsigned long *last_index,
+ struct sk_buff_head *hitlist)
+ {
+@@ -460,9 +506,7 @@ prev_vertex:
+ }
+
+ if (vertex->index == vertex->scc_index) {
+- struct unix_vertex *v;
+ struct list_head scc;
+- bool scc_dead = true;
+
+ /* SCC finalised.
+ *
+@@ -471,18 +515,7 @@ prev_vertex:
+ */
+ __list_cut_position(&scc, &vertex_stack, &vertex->scc_entry);
+
+- list_for_each_entry_reverse(v, &scc, scc_entry) {
+- /* Don't restart DFS from this vertex in unix_walk_scc(). */
+- list_move_tail(&v->entry, &unix_visited_vertices);
+-
+- /* Mark vertex as off-stack. */
+- v->index = unix_vertex_grouped_index;
+-
+- if (scc_dead)
+- scc_dead = unix_vertex_dead(v);
+- }
+-
+- if (scc_dead) {
++ if (unix_scc_dead(&scc, false)) {
+ unix_collect_skb(&scc, hitlist);
+ } else {
+ if (unix_vertex_max_scc_index < vertex->scc_index)
+@@ -530,19 +563,11 @@ static void unix_walk_scc_fast(struct sk_buff_head *hitlist)
+ while (!list_empty(&unix_unvisited_vertices)) {
+ struct unix_vertex *vertex;
+ struct list_head scc;
+- bool scc_dead = true;
+
+ vertex = list_first_entry(&unix_unvisited_vertices, typeof(*vertex), entry);
+ list_add(&scc, &vertex->scc_entry);
+
+- list_for_each_entry_reverse(vertex, &scc, scc_entry) {
+- list_move_tail(&vertex->entry, &unix_visited_vertices);
+-
+- if (scc_dead)
+- scc_dead = unix_vertex_dead(vertex);
+- }
+-
+- if (scc_dead)
++ if (unix_scc_dead(&scc, true))
+ unix_collect_skb(&scc, hitlist);
+ else if (!unix_graph_maybe_cyclic)
+ unix_graph_maybe_cyclic = unix_scc_cyclic(&scc);
+@@ -553,13 +578,13 @@ static void unix_walk_scc_fast(struct sk_buff_head *hitlist)
+ list_replace_init(&unix_visited_vertices, &unix_unvisited_vertices);
+ }
+
+-static bool gc_in_progress;
+-
+ static void __unix_gc(struct work_struct *work)
+ {
+ struct sk_buff_head hitlist;
+ struct sk_buff *skb;
+
++ WRITE_ONCE(gc_in_progress, true);
++
+ spin_lock(&unix_gc_lock);
+
+ if (!unix_graph_maybe_cyclic) {
+diff --git a/net/vmw_vsock/virtio_transport.c b/net/vmw_vsock/virtio_transport.c
+index 52de4810d48d58..4f40ca59286a15 100644
+--- a/net/vmw_vsock/virtio_transport.c
++++ b/net/vmw_vsock/virtio_transport.c
+@@ -257,12 +257,13 @@ static void virtio_transport_tx_work(struct work_struct *work)
+ struct virtqueue *vq;
+ bool added = false;
+
+- vq = vsock->vqs[VSOCK_VQ_TX];
+ mutex_lock(&vsock->tx_lock);
+
+ if (!vsock->tx_run)
+ goto out;
+
++ vq = vsock->vqs[VSOCK_VQ_TX];
++
+ do {
+ struct sk_buff *skb;
+ unsigned int len;
+@@ -362,13 +363,13 @@ static void virtio_transport_event_work(struct work_struct *work)
+ container_of(work, struct virtio_vsock, event_work);
+ struct virtqueue *vq;
+
+- vq = vsock->vqs[VSOCK_VQ_EVENT];
+-
+ mutex_lock(&vsock->event_lock);
+
+ if (!vsock->event_run)
+ goto out;
+
++ vq = vsock->vqs[VSOCK_VQ_EVENT];
++
+ do {
+ struct virtio_vsock_event *event;
+ unsigned int len;
+@@ -484,12 +485,12 @@ static void virtio_transport_rx_work(struct work_struct *work)
+ container_of(work, struct virtio_vsock, rx_work);
+ struct virtqueue *vq;
+
+- vq = vsock->vqs[VSOCK_VQ_RX];
+-
+ mutex_lock(&vsock->rx_lock);
+
+ if (!vsock->rx_run)
+- goto out;
++ goto out_nofill;
++
++ vq = vsock->vqs[VSOCK_VQ_RX];
+
+ do {
+ virtqueue_disable_cb(vq);
+@@ -535,6 +536,7 @@ static void virtio_transport_rx_work(struct work_struct *work)
+ out:
+ if (vsock->rx_buf_nr < vsock->rx_buf_max_nr / 2)
+ virtio_vsock_rx_fill(vsock);
++out_nofill:
+ mutex_unlock(&vsock->rx_lock);
+ }
+
+diff --git a/net/wireless/core.c b/net/wireless/core.c
+index 2a6a8bdfa72484..6f83ea71b76057 100644
+--- a/net/wireless/core.c
++++ b/net/wireless/core.c
+@@ -1125,6 +1125,7 @@ void wiphy_unregister(struct wiphy *wiphy)
+ /* this has nothing to do now but make sure it's gone */
+ cancel_work_sync(&rdev->wiphy_work);
+
++ cancel_work_sync(&rdev->sched_scan_res_wk);
+ cancel_work_sync(&rdev->rfkill_block);
+ cancel_work_sync(&rdev->conn_work);
+ flush_work(&rdev->event_work);
+diff --git a/net/wireless/nl80211.c b/net/wireless/nl80211.c
+index 36a7b9707eabd2..bb2d19057480b4 100644
+--- a/net/wireless/nl80211.c
++++ b/net/wireless/nl80211.c
+@@ -309,7 +309,9 @@ nl80211_ftm_responder_policy[NL80211_FTM_RESP_ATTR_MAX + 1] = {
+ static const struct nla_policy
+ nl80211_pmsr_ftm_req_attr_policy[NL80211_PMSR_FTM_REQ_ATTR_MAX + 1] = {
+ [NL80211_PMSR_FTM_REQ_ATTR_ASAP] = { .type = NLA_FLAG },
+- [NL80211_PMSR_FTM_REQ_ATTR_PREAMBLE] = { .type = NLA_U32 },
++ [NL80211_PMSR_FTM_REQ_ATTR_PREAMBLE] =
++ NLA_POLICY_RANGE(NLA_U32, NL80211_PREAMBLE_LEGACY,
++ NL80211_PREAMBLE_HE),
+ [NL80211_PMSR_FTM_REQ_ATTR_NUM_BURSTS_EXP] =
+ NLA_POLICY_MAX(NLA_U8, 15),
+ [NL80211_PMSR_FTM_REQ_ATTR_BURST_PERIOD] = { .type = NLA_U16 },
+@@ -5433,7 +5435,8 @@ static int nl80211_parse_mbssid_config(struct wiphy *wiphy,
+ }
+
+ static struct cfg80211_mbssid_elems *
+-nl80211_parse_mbssid_elems(struct wiphy *wiphy, struct nlattr *attrs)
++nl80211_parse_mbssid_elems(struct wiphy *wiphy, struct nlattr *attrs,
++ struct netlink_ext_ack *extack)
+ {
+ struct nlattr *nl_elems;
+ struct cfg80211_mbssid_elems *elems;
+@@ -5444,6 +5447,12 @@ nl80211_parse_mbssid_elems(struct wiphy *wiphy, struct nlattr *attrs)
+ return ERR_PTR(-EINVAL);
+
+ nla_for_each_nested(nl_elems, attrs, rem_elems) {
++ int ret;
++
++ ret = validate_ie_attr(nl_elems, extack);
++ if (ret)
++ return ERR_PTR(ret);
++
+ if (num_elems >= 255)
+ return ERR_PTR(-EINVAL);
+ num_elems++;
+@@ -5615,7 +5624,8 @@ static int nl80211_parse_beacon(struct cfg80211_registered_device *rdev,
+ if (attrs[NL80211_ATTR_MBSSID_ELEMS]) {
+ struct cfg80211_mbssid_elems *mbssid =
+ nl80211_parse_mbssid_elems(&rdev->wiphy,
+- attrs[NL80211_ATTR_MBSSID_ELEMS]);
++ attrs[NL80211_ATTR_MBSSID_ELEMS],
++ extack);
+
+ if (IS_ERR(mbssid))
+ return PTR_ERR(mbssid);
+@@ -5631,8 +5641,10 @@ static int nl80211_parse_beacon(struct cfg80211_registered_device *rdev,
+ if (IS_ERR(rnr))
+ return PTR_ERR(rnr);
+
+- if (rnr && rnr->cnt < bcn->mbssid_ies->cnt)
++ if (rnr && rnr->cnt < bcn->mbssid_ies->cnt) {
++ kfree(rnr);
+ return -EINVAL;
++ }
+
+ bcn->rnr_ies = rnr;
+ }
+diff --git a/net/wireless/pmsr.c b/net/wireless/pmsr.c
+index 656464f2de516c..e3987ba2d40a07 100644
+--- a/net/wireless/pmsr.c
++++ b/net/wireless/pmsr.c
+@@ -114,6 +114,7 @@ static int pmsr_parse_ftm(struct cfg80211_registered_device *rdev,
+ NL_SET_ERR_MSG_ATTR(info->extack,
+ tb[NL80211_PMSR_FTM_REQ_ATTR_REQUEST_LCI],
+ "FTM: LCI request not supported");
++ return -EOPNOTSUPP;
+ }
+
+ out->ftm.request_civicloc =
+@@ -122,6 +123,7 @@ static int pmsr_parse_ftm(struct cfg80211_registered_device *rdev,
+ NL_SET_ERR_MSG_ATTR(info->extack,
+ tb[NL80211_PMSR_FTM_REQ_ATTR_REQUEST_CIVICLOC],
+ "FTM: civic location request not supported");
++ return -EOPNOTSUPP;
+ }
+
+ out->ftm.trigger_based =
+@@ -188,6 +190,7 @@ static int pmsr_parse_peer(struct cfg80211_registered_device *rdev,
+ {
+ struct nlattr *tb[NL80211_PMSR_PEER_ATTR_MAX + 1];
+ struct nlattr *req[NL80211_PMSR_REQ_ATTR_MAX + 1];
++ bool have_measurement_type = false;
+ struct nlattr *treq;
+ int err, rem;
+
+@@ -240,6 +243,14 @@ static int pmsr_parse_peer(struct cfg80211_registered_device *rdev,
+ }
+
+ nla_for_each_nested(treq, req[NL80211_PMSR_REQ_ATTR_DATA], rem) {
++ if (have_measurement_type) {
++ NL_SET_ERR_MSG_ATTR(info->extack, treq,
++ "multiple measurement types in request data");
++ return -EINVAL;
++ }
++
++ have_measurement_type = true;
++
+ switch (nla_type(treq)) {
+ case NL80211_PMSR_TYPE_FTM:
+ err = pmsr_parse_ftm(rdev, treq, out, info);
+@@ -249,10 +260,16 @@ static int pmsr_parse_peer(struct cfg80211_registered_device *rdev,
+ "unsupported measurement type");
+ err = -EINVAL;
+ }
++ if (err)
++ return err;
+ }
+
+- if (err)
+- return err;
++ if (!have_measurement_type) {
++ NL_SET_ERR_MSG_ATTR(info->extack,
++ req[NL80211_PMSR_REQ_ATTR_DATA],
++ "missing measurement type in request data");
++ return -EINVAL;
++ }
+
+ return 0;
+ }
+diff --git a/net/wireless/scan.c b/net/wireless/scan.c
+index ae899e25581d27..1ebe2f3f6f52ac 100644
+--- a/net/wireless/scan.c
++++ b/net/wireless/scan.c
+@@ -240,7 +240,7 @@ bool cfg80211_is_element_inherited(const struct element *elem,
+ return true;
+
+ if (elem->id == WLAN_EID_EXTENSION) {
+- if (!ext_id_len)
++ if (!ext_id_len || !elem->datalen)
+ return true;
+ loop_len = ext_id_len;
+ list = &non_inherit_elem->data[3 + id_len];
+diff --git a/net/x25/af_x25.c b/net/x25/af_x25.c
+index 5a8b2ea56564e3..9ab22a9fdad655 100644
+--- a/net/x25/af_x25.c
++++ b/net/x25/af_x25.c
+@@ -1773,15 +1773,19 @@ void x25_kill_by_neigh(struct x25_neigh *nb)
+ {
+ struct sock *s;
+
++again:
+ write_lock_bh(&x25_list_lock);
+
+ sk_for_each(s, &x25_list) {
+ if (x25_sk(s)->neighbour == nb) {
++ sock_hold(s);
+ write_unlock_bh(&x25_list_lock);
+ lock_sock(s);
+- x25_disconnect(s, ENETUNREACH, 0, 0);
++ if (x25_sk(s)->neighbour == nb)
++ x25_disconnect(s, ENETUNREACH, 0, 0);
+ release_sock(s);
+- write_lock_bh(&x25_list_lock);
++ sock_put(s);
++ goto again;
+ }
+ }
+ write_unlock_bh(&x25_list_lock);
+diff --git a/net/xfrm/xfrm_policy.c b/net/xfrm/xfrm_policy.c
+index a780fb581388b0..2a47f5b5776e8f 100644
+--- a/net/xfrm/xfrm_policy.c
++++ b/net/xfrm/xfrm_policy.c
+@@ -1295,8 +1295,8 @@ static void xfrm_hash_rebuild(struct work_struct *work)
+ }
+ }
+
+- if (policy->selector.prefixlen_d < dbits ||
+- policy->selector.prefixlen_s < sbits)
++ if (policy->selector.prefixlen_d >= dbits &&
++ policy->selector.prefixlen_s >= sbits)
+ continue;
+
+ bin = xfrm_policy_inexact_alloc_bin(policy, dir);
+@@ -2526,8 +2526,7 @@ static void xfrm_init_path(struct xfrm_dst *path, struct dst_entry *dst,
+ int nfheader_len)
+ {
+ if (dst->ops->family == AF_INET6) {
+- struct rt6_info *rt = (struct rt6_info *)dst;
+- path->path_cookie = rt6_get_cookie(rt);
++ path->path_cookie = rt6_get_cookie(dst_rt6_info(dst));
+ path->u.rt6.rt6i_nfheader_len = nfheader_len;
+ }
+ }
+diff --git a/scripts/remove-stale-files b/scripts/remove-stale-files
+index ccadfa3afb2b81..c22fe4630bac09 100755
+--- a/scripts/remove-stale-files
++++ b/scripts/remove-stale-files
+@@ -47,3 +47,5 @@ rm -f arch/riscv/purgatory/kexec-purgatory.c
+ rm -f scripts/extract-cert
+
+ rm -f arch/x86/purgatory/kexec-purgatory.c
++
++rm -f lib/test_fortify.log
+diff --git a/security/integrity/ima/ima_appraise.c b/security/integrity/ima/ima_appraise.c
+index 3e0fbbd995342f..19dbd8b9efd3e4 100644
+--- a/security/integrity/ima/ima_appraise.c
++++ b/security/integrity/ima/ima_appraise.c
+@@ -301,8 +301,13 @@ static int xattr_verify(enum ima_hooks func, struct integrity_iint_cache *iint,
+ } else {
+ set_bit(IMA_DIGSIG, &iint->atomic_flags);
+ }
+- if (xattr_len - sizeof(xattr_value->type) - hash_start >=
+- iint->ima_hash->length)
++ /*
++ * Use addition, not subtraction: sizeof() forces unsigned
++ * math and a short xattr_len would wrap around, bypassing
++ * this bounds check.
++ */
++ if (xattr_len >= (int)sizeof(xattr_value->type) + hash_start +
++ (int)iint->ima_hash->length)
+ /*
+ * xattr length may be longer. md5 hash in previous
+ * version occupied 20 bytes in xattr, instead of 16
+diff --git a/security/keys/keyring.c b/security/keys/keyring.c
+index e105349794f23e..fd95a0eb7a466b 100644
+--- a/security/keys/keyring.c
++++ b/security/keys/keyring.c
+@@ -271,6 +271,7 @@ static unsigned long keyring_get_key_chunk(const void *data, int level)
+ unsigned long chunk = 0;
+ const u8 *d;
+ int desc_len = index_key->desc_len, n = sizeof(chunk);
++ unsigned int offset;
+
+ level /= ASSOC_ARRAY_KEY_CHUNK_SIZE;
+ switch (level) {
+@@ -284,17 +285,18 @@ static unsigned long keyring_get_key_chunk(const void *data, int level)
+ return (unsigned long)index_key->domain_tag;
+ default:
+ level -= 4;
+- if (desc_len <= sizeof(index_key->desc))
++ offset = sizeof(index_key->desc) + level * sizeof(long);
++ if (desc_len <= offset)
+ return 0;
+
+- d = index_key->description + sizeof(index_key->desc);
+- d += level * sizeof(long);
+- desc_len -= sizeof(index_key->desc);
++ d = index_key->description + offset;
++ desc_len -= offset;
+ if (desc_len > n)
+ desc_len = n;
++ d += desc_len;
+ do {
+ chunk <<= 8;
+- chunk |= *d++;
++ chunk |= *--d;
+ } while (--desc_len > 0);
+ return chunk;
+ }
+@@ -375,7 +377,7 @@ same:
+ return -1;
+
+ differ_plus_i:
+- level += i;
++ level += i - (int)sizeof(a->desc);
+ differ:
+ i = level * 8 + __ffs(seg_a ^ seg_b);
+ return i;
+diff --git a/sound/core/pcm_native.c b/sound/core/pcm_native.c
+index 2ed9abb911a7aa..fcb5f176f0dfc3 100644
+--- a/sound/core/pcm_native.c
++++ b/sound/core/pcm_native.c
+@@ -2352,6 +2352,7 @@ static void relink_to_local(struct snd_pcm_substream *substream)
+
+ static int snd_pcm_unlink(struct snd_pcm_substream *substream)
+ {
++ struct snd_pcm_substream *s;
+ struct snd_pcm_group *group;
+ bool nonatomic = substream->pcm->nonatomic;
+ bool do_free = false;
+@@ -2367,6 +2368,12 @@ static int snd_pcm_unlink(struct snd_pcm_substream *substream)
+ group = substream->group;
+ snd_pcm_group_lock_irq(group, nonatomic);
+
++ /* release drain waiters before changing membership, else snd_pcm_drain()
++ * leaves its on-stack wait entry queued on a member's sleep list
++ */
++ snd_pcm_group_for_each_entry(s, substream)
++ wake_up(&s->runtime->sleep);
++
+ relink_to_local(substream);
+ refcount_dec(&group->refs);
+
+diff --git a/sound/core/seq/seq_timer.c b/sound/core/seq/seq_timer.c
+index 9863be6fd43e1a..09874291125e42 100644
+--- a/sound/core/seq/seq_timer.c
++++ b/sound/core/seq/seq_timer.c
+@@ -58,12 +58,23 @@ struct snd_seq_timer *snd_seq_timer_new(void)
+ void snd_seq_timer_delete(struct snd_seq_timer **tmr)
+ {
+ struct snd_seq_timer *t = *tmr;
+- *tmr = NULL;
++ struct snd_timer_instance *ti;
+
+ if (t == NULL) {
+ pr_debug("ALSA: seq: snd_seq_timer_delete() called with NULL timer\n");
+ return;
+ }
++
++ scoped_guard(spinlock_irq, &t->lock) {
++ ti = t->timeri;
++ t->timeri = NULL;
++ }
++ if (ti) {
++ snd_timer_close(ti);
++ snd_timer_instance_free(ti);
++ }
++
++ *tmr = NULL;
+ t->running = 0;
+
+ /* reset time */
+diff --git a/sound/pci/lx6464es/lx6464es.c b/sound/pci/lx6464es/lx6464es.c
+index bd9b6148dd6fbe..45ef869ae9e56d 100644
+--- a/sound/pci/lx6464es/lx6464es.c
++++ b/sound/pci/lx6464es/lx6464es.c
+@@ -410,11 +410,8 @@ static void lx_trigger_start(struct lx6464es *chip, struct lx_stream *lx_stream)
+
+ int err;
+
+- const u32 channels = substream->runtime->channels;
+- const u32 bytes_per_frame = channels * 3;
+- const u32 period_size = substream->runtime->period_size;
+ const u32 periods = substream->runtime->periods;
+- const u32 period_bytes = period_size * bytes_per_frame;
++ const u32 period_bytes = snd_pcm_lib_period_bytes(substream);
+
+ dma_addr_t buf = substream->dma_buffer.addr;
+ int i;
+diff --git a/sound/pci/lx6464es/lx_core.c b/sound/pci/lx6464es/lx_core.c
+index c3f2717aebf254..129199e3ac0674 100644
+--- a/sound/pci/lx6464es/lx_core.c
++++ b/sound/pci/lx6464es/lx_core.c
+@@ -1015,10 +1015,7 @@ static int lx_interrupt_request_new_buffer(struct lx6464es *chip,
+ const unsigned int is_capture = lx_stream->is_capture;
+ int err;
+
+- const u32 channels = substream->runtime->channels;
+- const u32 bytes_per_frame = channels * 3;
+- const u32 period_size = substream->runtime->period_size;
+- const u32 period_bytes = period_size * bytes_per_frame;
++ const u32 period_bytes = snd_pcm_lib_period_bytes(substream);
+ const u32 pos = lx_stream->frame_pos;
+ const u32 next_pos = ((pos+1) == substream->runtime->periods) ?
+ 0 : pos + 1;
+diff --git a/sound/soc/amd/ps/pci-ps.c b/sound/soc/amd/ps/pci-ps.c
+index 7c9751a7eedc22..c3bce6ed090d79 100644
+--- a/sound/soc/amd/ps/pci-ps.c
++++ b/sound/soc/amd/ps/pci-ps.c
+@@ -163,7 +163,7 @@ static int snd_acp63_probe(struct pci_dev *pci,
+ return -ENODEV;
+ }
+
+- ret = pci_request_regions(pci, "AMD ACP6.2 audio");
++ ret = pci_request_regions(pci, "AMD ACP6.3 audio");
+ if (ret < 0) {
+ dev_err(&pci->dev, "pci_request_regions failed\n");
+ goto disable_pci;
+diff --git a/sound/soc/codecs/bt-sco.c b/sound/soc/codecs/bt-sco.c
+index 4086b6a53de8ca..2a8796176c6da6 100644
+--- a/sound/soc/codecs/bt-sco.c
++++ b/sound/soc/codecs/bt-sco.c
+@@ -17,11 +17,17 @@ static const struct snd_soc_dapm_widget bt_sco_widgets[] = {
+ SND_SOC_NOPM, 0, 0),
+ SND_SOC_DAPM_AIF_OUT("BT_SCO_TX", "Capture", 0,
+ SND_SOC_NOPM, 0, 0),
++ SND_SOC_DAPM_AIF_IN("BT_SCO_RX_WB", "WB Playback", 0,
++ SND_SOC_NOPM, 0, 0),
++ SND_SOC_DAPM_AIF_OUT("BT_SCO_TX_WB", "WB Capture", 0,
++ SND_SOC_NOPM, 0, 0),
+ };
+
+ static const struct snd_soc_dapm_route bt_sco_routes[] = {
+ { "BT_SCO_TX", NULL, "RX" },
+ { "TX", NULL, "BT_SCO_RX" },
++ { "BT_SCO_TX_WB", NULL, "RX" },
++ { "TX", NULL, "BT_SCO_RX_WB" },
+ };
+
+ static struct snd_soc_dai_driver bt_sco_dai[] = {
+@@ -45,14 +51,14 @@ static struct snd_soc_dai_driver bt_sco_dai[] = {
+ {
+ .name = "bt-sco-pcm-wb",
+ .playback = {
+- .stream_name = "Playback",
++ .stream_name = "WB Playback",
+ .channels_min = 1,
+ .channels_max = 1,
+ .rates = SNDRV_PCM_RATE_8000 | SNDRV_PCM_RATE_16000,
+ .formats = SNDRV_PCM_FMTBIT_S16_LE,
+ },
+ .capture = {
+- .stream_name = "Capture",
++ .stream_name = "WB Capture",
+ .channels_min = 1,
+ .channels_max = 1,
+ .rates = SNDRV_PCM_RATE_8000 | SNDRV_PCM_RATE_16000,
+diff --git a/sound/soc/codecs/max98090.c b/sound/soc/codecs/max98090.c
+index f5acf84ee20cc9..e64e2352c6aa4b 100644
+--- a/sound/soc/codecs/max98090.c
++++ b/sound/soc/codecs/max98090.c
+@@ -2391,8 +2391,9 @@ static int max98090_probe(struct snd_soc_component *component)
+ dev_dbg(component->dev, "max98090_probe\n");
+
+ max98090->mclk = devm_clk_get(component->dev, "mclk");
+- if (PTR_ERR(max98090->mclk) == -EPROBE_DEFER)
+- return -EPROBE_DEFER;
++ if (IS_ERR(max98090->mclk))
++ if (PTR_ERR(max98090->mclk) == -EPROBE_DEFER)
++ return -EPROBE_DEFER;
+
+ max98090->component = component;
+
+diff --git a/sound/soc/codecs/max98095.c b/sound/soc/codecs/max98095.c
+index 44aa58fcc23f82..7b399564785c46 100644
+--- a/sound/soc/codecs/max98095.c
++++ b/sound/soc/codecs/max98095.c
+@@ -1984,8 +1984,9 @@ static int max98095_probe(struct snd_soc_component *component)
+ int ret = 0;
+
+ max98095->mclk = devm_clk_get(component->dev, "mclk");
+- if (PTR_ERR(max98095->mclk) == -EPROBE_DEFER)
+- return -EPROBE_DEFER;
++ if (IS_ERR(max98095->mclk))
++ if (PTR_ERR(max98095->mclk) == -EPROBE_DEFER)
++ return -EPROBE_DEFER;
+
+ /* reset the codec, the DSP core, and disable all interrupts */
+ max98095_reset(component);
+diff --git a/sound/soc/codecs/tas2562.c b/sound/soc/codecs/tas2562.c
+index b486d0bd86c991..07336352272b33 100644
+--- a/sound/soc/codecs/tas2562.c
++++ b/sound/soc/codecs/tas2562.c
+@@ -33,15 +33,16 @@
+ static const unsigned int float_vol_db_lookup[] = {
+ 0x00000d43, 0x000010b2, 0x00001505, 0x00001a67, 0x00002151,
+ 0x000029f1, 0x000034cd, 0x00004279, 0x000053af, 0x0000695b,
+-0x0000695b, 0x0000a6fa, 0x0000d236, 0x000108a4, 0x00014d2a,
++0x000084a3, 0x0000a6fa, 0x0000d236, 0x000108a4, 0x00014d2a,
+ 0x0001a36e, 0x00021008, 0x000298c0, 0x000344df, 0x00041d8f,
+ 0x00052e5a, 0x000685c8, 0x00083621, 0x000a566d, 0x000d03a7,
+ 0x0010624d, 0x0014a050, 0x0019f786, 0x0020b0bc, 0x0029279d,
+ 0x0033cf8d, 0x004139d3, 0x00521d50, 0x00676044, 0x0082248a,
+ 0x00a3d70a, 0x00ce4328, 0x0103ab3d, 0x0146e75d, 0x019b8c27,
+ 0x02061b89, 0x028c423f, 0x03352529, 0x0409c2b0, 0x05156d68,
+-0x080e9f96, 0x0a24b062, 0x0cc509ab, 0x10137987, 0x143d1362,
+-0x197a967f, 0x2013739e, 0x28619ae9, 0x32d64617, 0x40000000
++0x06666666, 0x080e9f96, 0x0a24b062, 0x0cc509ab, 0x10137987,
++0x143d1362, 0x197a967f, 0x2013739e, 0x28619ae9, 0x32d64617,
++0x40000000
+ };
+
+ struct tas2562_data {
+@@ -477,20 +478,27 @@ static int tas2562_volume_control_put(struct snd_kcontrol *kcontrol,
+ u32 reg_val;
+
+ reg_val = float_vol_db_lookup[ucontrol->value.integer.value[0]/2];
+- ret = snd_soc_component_write(component, TAS2562_DVC_CFG4,
+- (reg_val & 0xff));
+- if (ret)
+- return ret;
+- ret = snd_soc_component_write(component, TAS2562_DVC_CFG3,
+- ((reg_val >> 8) & 0xff));
++ /*
++ * The device applies the 32-bit coefficient to the playback path on
++ * the write to DVC_CFG4 (the LSB, book 0 page 2 reg 0x0F), so the
++ * bytes must be written MSB first and DVC_CFG4 last. Writing CFG4
++ * first latches a mix of the previous coefficient's upper bytes and
++ * the new LSB instead of the requested value.
++ */
++ ret = snd_soc_component_write(component, TAS2562_DVC_CFG1,
++ ((reg_val >> 24) & 0xff));
+ if (ret)
+ return ret;
+ ret = snd_soc_component_write(component, TAS2562_DVC_CFG2,
+ ((reg_val >> 16) & 0xff));
+ if (ret)
+ return ret;
+- ret = snd_soc_component_write(component, TAS2562_DVC_CFG1,
+- ((reg_val >> 24) & 0xff));
++ ret = snd_soc_component_write(component, TAS2562_DVC_CFG3,
++ ((reg_val >> 8) & 0xff));
++ if (ret)
++ return ret;
++ ret = snd_soc_component_write(component, TAS2562_DVC_CFG4,
++ (reg_val & 0xff));
+ if (ret)
+ return ret;
+
+@@ -685,11 +693,12 @@ static int tas2562_parse_dt(struct tas2562_data *tas2562)
+ if (tas2562->sdz_gpio == NULL) {
+ tas2562->sdz_gpio = devm_gpiod_get_optional(dev, "shut-down",
+ GPIOD_OUT_HIGH);
+- if (IS_ERR(tas2562->sdz_gpio))
++ if (IS_ERR(tas2562->sdz_gpio)) {
+ if (PTR_ERR(tas2562->sdz_gpio) == -EPROBE_DEFER)
+ return -EPROBE_DEFER;
+
+- tas2562->sdz_gpio = NULL;
++ tas2562->sdz_gpio = NULL;
++ }
+ }
+
+ if (tas2562->model_id == TAS2110)
+diff --git a/sound/soc/meson/aiu-fifo-spdif.c b/sound/soc/meson/aiu-fifo-spdif.c
+index 2fb30f89bf7a2c..515310e8eae79b 100644
+--- a/sound/soc/meson/aiu-fifo-spdif.c
++++ b/sound/soc/meson/aiu-fifo-spdif.c
+@@ -24,6 +24,7 @@
+ #define AIU_MEM_IEC958_CONTROL_MODE_16BIT BIT(7)
+ #define AIU_MEM_IEC958_CONTROL_MODE_LINEAR BIT(8)
+ #define AIU_MEM_IEC958_BUF_CNTL_INIT BIT(0)
++#define AIU_RST_SOFT_958_FAST BIT(2)
+
+ #define AIU_FIFO_SPDIF_BLOCK 8
+
+@@ -68,11 +69,15 @@ static int fifo_spdif_trigger(struct snd_pcm_substream *substream, int cmd,
+ case SNDRV_PCM_TRIGGER_START:
+ case SNDRV_PCM_TRIGGER_RESUME:
+ case SNDRV_PCM_TRIGGER_PAUSE_RELEASE:
++ snd_soc_component_write(component, AIU_RST_SOFT,
++ AIU_RST_SOFT_958_FAST);
+ fifo_spdif_dcu_enable(component, true);
+ break;
+ case SNDRV_PCM_TRIGGER_SUSPEND:
+ case SNDRV_PCM_TRIGGER_PAUSE_PUSH:
+ case SNDRV_PCM_TRIGGER_STOP:
++ snd_soc_component_write(component, AIU_RST_SOFT,
++ AIU_RST_SOFT_958_FAST);
+ fifo_spdif_dcu_enable(component, false);
+ break;
+ default:
+diff --git a/sound/usb/6fire/chip.c b/sound/usb/6fire/chip.c
+index 835295e0807d96..e5916c6b75aea8 100644
+--- a/sound/usb/6fire/chip.c
++++ b/sound/usb/6fire/chip.c
+@@ -158,6 +158,10 @@ static int usb6fire_chip_probe(struct usb_interface *intf,
+ return 0;
+
+ destroy_chip:
++ chip->shutdown = true;
++ if (card)
++ snd_card_disconnect(card);
++ usb6fire_chip_abort(chip);
+ snd_card_free(card);
+ return ret;
+ }
+diff --git a/sound/usb/endpoint.c b/sound/usb/endpoint.c
+index 20fcecb5e49a08..778466624f030d 100644
+--- a/sound/usb/endpoint.c
++++ b/sound/usb/endpoint.c
+@@ -388,13 +388,15 @@ static int prepare_inbound_urb(struct snd_usb_endpoint *ep,
+ case SND_USB_ENDPOINT_TYPE_DATA:
+ offs = 0;
+ for (i = 0; i < urb_ctx->packets; i++) {
++ if (offs + ep->curpacksize > urb_ctx->buffer_size)
++ break;
+ urb->iso_frame_desc[i].offset = offs;
+ urb->iso_frame_desc[i].length = ep->curpacksize;
+ offs += ep->curpacksize;
+ }
+
+ urb->transfer_buffer_length = offs;
+- urb->number_of_packets = urb_ctx->packets;
++ urb->number_of_packets = i;
+ break;
+
+ case SND_USB_ENDPOINT_TYPE_SYNC:
+@@ -1167,10 +1169,12 @@ static int data_ep_set_params(struct snd_usb_endpoint *ep)
+ << (16 - ep->datainterval);
+ }
+
+- if (ep->fill_max)
++ if (ep->fill_max) {
+ ep->curpacksize = ep->maxpacksize;
+- else
++ maxsize = ep->curpacksize;
++ } else {
+ ep->curpacksize = maxsize;
++ }
+
+ if (snd_usb_get_speed(chip->dev) != USB_SPEED_FULL) {
+ packs_per_ms = 8 >> ep->datainterval;
+@@ -1254,10 +1258,10 @@ static int data_ep_set_params(struct snd_usb_endpoint *ep)
+ u->index = i;
+ u->ep = ep;
+ u->packets = urb_packs;
+- u->buffer_size = maxsize * u->packets;
+
+ if (fmt->fmt_type == UAC_FORMAT_TYPE_II)
+ u->packets++; /* for transfer delimiter */
++ u->buffer_size = maxsize * u->packets;
+ u->urb = usb_alloc_urb(u->packets, GFP_KERNEL);
+ if (!u->urb)
+ goto out_of_memory;
+@@ -1824,11 +1828,13 @@ static void snd_usb_handle_sync_urb(struct snd_usb_endpoint *ep,
+
+ out_packet->packets = in_ctx->packets;
+ for (i = 0; i < in_ctx->packets; i++) {
+- if (urb->iso_frame_desc[i].status == 0)
+- out_packet->packet_size[i] =
++ if (urb->iso_frame_desc[i].status == 0) {
++ unsigned int frames =
+ urb->iso_frame_desc[i].actual_length / sender->stride;
+- else
++ out_packet->packet_size[i] = min(frames, ep->maxframesize);
++ } else {
+ out_packet->packet_size[i] = 0;
++ }
+ }
+
+ spin_unlock_irqrestore(&ep->lock, flags);
+diff --git a/sound/usb/midi.c b/sound/usb/midi.c
+index b7cb71900ede71..788cd63044f099 100644
+--- a/sound/usb/midi.c
++++ b/sound/usb/midi.c
+@@ -800,6 +800,8 @@ static void snd_usbmidi_akai_output(struct snd_usb_midi_out_endpoint *ep,
+
+ msg = urb->transfer_buffer + urb->transfer_buffer_length;
+ buf_end = ep->max_transfer - MAX_AKAI_SYSEX_LEN - 1;
++ if (buf_end <= 0)
++ return;
+
+ /* only try adding more data when there's space for at least 1 SysEx */
+ while (urb->transfer_buffer_length < buf_end) {
+diff --git a/sound/usb/quirks.c b/sound/usb/quirks.c
+index 8faf3731e3499d..ece6ae4a21ed9f 100644
+--- a/sound/usb/quirks.c
++++ b/sound/usb/quirks.c
+@@ -2261,6 +2261,8 @@ static const struct usb_audio_quirk_flags_table quirk_flags_table[] = {
+ QUIRK_FLAG_DSD_RAW),
+ DEVICE_FLG(0x2708, 0x0002, /* Audient iD14 */
+ QUIRK_FLAG_IGNORE_CTL_ERROR),
++ DEVICE_FLG(0x2772, 0x0502, /* Musical Fidelity M6s DAC */
++ 0), /* for avoiding QUIRK_FLAG_DSD_RAW with vendor match */
+ DEVICE_FLG(0x2912, 0x30c8, /* Audioengine D1 */
+ QUIRK_FLAG_GET_SAMPLE_RATE),
+ DEVICE_FLG(0x2a70, 0x1881, /* OnePlus Technology (Shenzhen) Co., Ltd. BE02T */
+diff --git a/sound/usb/usx2y/usX2Yhwdep.c b/sound/usb/usx2y/usX2Yhwdep.c
+index c29da0341bc5b3..c0293af448fe78 100644
+--- a/sound/usb/usx2y/usX2Yhwdep.c
++++ b/sound/usb/usx2y/usX2Yhwdep.c
+@@ -29,6 +29,8 @@ static vm_fault_t snd_us428ctls_vm_fault(struct vm_fault *vmf)
+ vmf->pgoff);
+
+ offset = vmf->pgoff << PAGE_SHIFT;
++ if (offset >= US428_SHAREDMEM_PAGES)
++ return VM_FAULT_SIGBUS;
+ vaddr = (char *)((struct usx2ydev *)vmf->vma->vm_private_data)->us428ctls_sharedmem + offset;
+ page = virt_to_page(vaddr);
+ get_page(page);
+diff --git a/sound/usb/usx2y/usx2yhwdeppcm.c b/sound/usb/usx2y/usx2yhwdeppcm.c
+index 767a227d54da49..80bcfb1e8e01a6 100644
+--- a/sound/usb/usx2y/usx2yhwdeppcm.c
++++ b/sound/usb/usx2y/usx2yhwdeppcm.c
+@@ -676,6 +676,8 @@ static vm_fault_t snd_usx2y_hwdep_pcm_vm_fault(struct vm_fault *vmf)
+ void *vaddr;
+
+ offset = vmf->pgoff << PAGE_SHIFT;
++ if (offset >= USX2Y_HWDEP_PCM_PAGES)
++ return VM_FAULT_SIGBUS;
+ vaddr = (char *)((struct usx2ydev *)vmf->vma->vm_private_data)->hwdep_pcm_shm + offset;
+ vmf->page = virt_to_page(vaddr);
+ get_page(vmf->page);
+diff --git a/tools/testing/selftests/alsa/mixer-test.c b/tools/testing/selftests/alsa/mixer-test.c
+index 9ad39db32d1442..960b137789d25e 100644
+--- a/tools/testing/selftests/alsa/mixer-test.c
++++ b/tools/testing/selftests/alsa/mixer-test.c
+@@ -130,6 +130,7 @@ static void find_controls(void)
+ if (err < 0) {
+ ksft_print_msg("Failed to get hctl for card %d: %s\n",
+ card, snd_strerror(err));
++ free(card_data);
+ goto next_card;
+ }
+
+diff --git a/tools/testing/selftests/bpf/prog_tests/sockmap_listen.c b/tools/testing/selftests/bpf/prog_tests/sockmap_listen.c
+index cef5d35951711b..2112b01a4b03a8 100644
+--- a/tools/testing/selftests/bpf/prog_tests/sockmap_listen.c
++++ b/tools/testing/selftests/bpf/prog_tests/sockmap_listen.c
+@@ -341,8 +341,8 @@ static void test_insert_invalid(int family, int sotype, int mapfd)
+ static void test_insert_opened(int family, int sotype, int mapfd)
+ {
+ u32 key = 0;
+- u64 value;
+ int err, s;
++ u64 value;
+
+ s = xsocket(family, sotype, 0);
+ if (s == -1)
+@@ -351,11 +351,8 @@ static void test_insert_opened(int family, int sotype, int mapfd)
+ errno = 0;
+ value = s;
+ err = bpf_map_update_elem(mapfd, &key, &value, BPF_NOEXIST);
+- if (sotype == SOCK_STREAM) {
+- if (!err || errno != EOPNOTSUPP)
+- FAIL_ERRNO("map_update: expected EOPNOTSUPP");
+- } else if (err)
+- FAIL_ERRNO("map_update: expected success");
++ ASSERT_ERR(err, "map_update");
++ ASSERT_EQ(errno, EOPNOTSUPP, "errno");
+ xclose(s);
+ }
+
+@@ -364,8 +361,8 @@ static void test_insert_bound(int family, int sotype, int mapfd)
+ struct sockaddr_storage addr;
+ socklen_t len;
+ u32 key = 0;
+- u64 value;
+ int err, s;
++ u64 value;
+
+ init_addr_loopback(family, &addr, &len);
+
+@@ -380,8 +377,12 @@ static void test_insert_bound(int family, int sotype, int mapfd)
+ errno = 0;
+ value = s;
+ err = bpf_map_update_elem(mapfd, &key, &value, BPF_NOEXIST);
+- if (!err || errno != EOPNOTSUPP)
+- FAIL_ERRNO("map_update: expected EOPNOTSUPP");
++ if (sotype == SOCK_STREAM) {
++ ASSERT_ERR(err, "map_update");
++ ASSERT_EQ(errno, EOPNOTSUPP, "errno");
++ } else {
++ ASSERT_OK(err, "map_update");
++ }
+ close:
+ xclose(s);
+ }
+@@ -1480,7 +1481,7 @@ static void test_ops(struct test_sockmap_listen *skel, struct bpf_map *map,
+ /* insert */
+ TEST(test_insert_invalid),
+ TEST(test_insert_opened),
+- TEST(test_insert_bound, SOCK_STREAM),
++ TEST(test_insert_bound),
+ TEST(test_insert),
+ /* delete */
+ TEST(test_delete_after_insert),
+diff --git a/tools/testing/selftests/bpf/test_maps.c b/tools/testing/selftests/bpf/test_maps.c
+index 81cd48cc80c23c..73878ec8ec7d0f 100644
+--- a/tools/testing/selftests/bpf/test_maps.c
++++ b/tools/testing/selftests/bpf/test_maps.c
+@@ -752,16 +752,15 @@ static void test_sockmap(unsigned int tasks, void *data)
+ goto out_sockmap;
+ }
+
+- /* Test update with unsupported UDP socket */
++ /* Test update with unsupported unbound UDP socket */
+ udp = socket(AF_INET, SOCK_DGRAM, 0);
+- i = 0;
+- err = bpf_map_update_elem(fd, &i, &udp, BPF_ANY);
+- if (err) {
+- printf("Failed socket update SOCK_DGRAM '%i:%i'\n",
+- i, udp);
++ CHECK(udp < 0, "socket(AF_INET, SOCK_DGRAM)", "errno:%d\n", errno);
++ err = bpf_map_update_elem(fd, &(int){0}, &udp, BPF_ANY);
++ close(udp);
++ if (!err) {
++ printf("Unexpectedly succeeded unbound UDP update '0:%i'\n", udp);
+ goto out_sockmap;
+ }
+- close(udp);
+
+ /* Test update without programs */
+ for (i = 0; i < 6; i++) {
+diff --git a/tools/testing/selftests/clone3/clone3_set_tid.c b/tools/testing/selftests/clone3/clone3_set_tid.c
+index 0229e9ebb995eb..a0cc8940e8f810 100644
+--- a/tools/testing/selftests/clone3/clone3_set_tid.c
++++ b/tools/testing/selftests/clone3/clone3_set_tid.c
+@@ -146,7 +146,7 @@ int main(int argc, char *argv[])
+ {
+ FILE *f;
+ char buf;
+- char *line;
++ char *line = NULL;
+ int status;
+ int ret = -1;
+ size_t len = 0;
+diff --git a/tools/testing/selftests/ftrace/test.d/dynevent/add_remove_eprobe.tc b/tools/testing/selftests/ftrace/test.d/dynevent/add_remove_eprobe.tc
+index c300eb0202620c..e2322693d0c320 100644
+--- a/tools/testing/selftests/ftrace/test.d/dynevent/add_remove_eprobe.tc
++++ b/tools/testing/selftests/ftrace/test.d/dynevent/add_remove_eprobe.tc
+@@ -1,16 +1,16 @@
+ #!/bin/sh
+ # SPDX-License-Identifier: GPL-2.0
+ # description: Generic dynamic event - add/remove eprobe events
+-# requires: dynamic_events events/syscalls/sys_enter_openat "<attached-group>.<attached-event> [<args>]":README
++# requires: dynamic_events events/syscalls/sys_enter_chdir "<attached-group>.<attached-event> [<args>]":README
+
+ echo 0 > events/enable
+
+ clear_dynamic_events
+
+ SYSTEM="syscalls"
+-EVENT="sys_enter_openat"
++EVENT="sys_enter_chdir"
+ FIELD="filename"
+-EPROBE="eprobe_open"
++EPROBE="eprobe_chdir"
+ OPTIONS="file=+0(\$filename):ustring"
+ echo "e:$EPROBE $SYSTEM/$EVENT $OPTIONS" >> dynamic_events
+
+@@ -18,20 +18,14 @@ grep -q "$EPROBE" dynamic_events
+ test -d events/eprobes/$EPROBE
+
+ echo 1 > events/eprobes/$EPROBE/enable
+-ls
++cd /sys/kernel/tracing
+ echo 0 > events/eprobes/$EPROBE/enable
+
+-content=`grep '^ *ls-' trace | grep 'file='`
+-nocontent=`grep '^ *ls-' trace | grep 'file=' | grep -v -e '"/' -e '"."' -e '(fault)' ` || true
+-
++content=`grep -e 'file="/sys/kernel/tracing"\|(fault)' trace`
+ if [ -z "$content" ]; then
+ exit_fail
+ fi
+
+-if [ ! -z "$nocontent" ]; then
+- exit_fail
+-fi
+-
+ echo "-:$EPROBE" >> dynamic_events
+
+ ! grep -q "$EPROBE" dynamic_events
+diff --git a/tools/testing/selftests/net/af_unix/config b/tools/testing/selftests/net/af_unix/config
+new file mode 100644
+index 00000000000000..9c4fb9c31c9506
+--- /dev/null
++++ b/tools/testing/selftests/net/af_unix/config
+@@ -0,0 +1,4 @@
++CONFIG_UNIX=y
++CONFIG_AF_UNIX_OOB=y
++CONFIG_UNIX_DIAG=m
++CONFIG_USER_NS=y
+diff --git a/tools/testing/selftests/net/openvswitch/config b/tools/testing/selftests/net/openvswitch/config
+new file mode 100644
+index 00000000000000..c659749cd086c7
+--- /dev/null
++++ b/tools/testing/selftests/net/openvswitch/config
+@@ -0,0 +1,16 @@
++CONFIG_GENEVE=m
++CONFIG_INET_DIAG=y
++CONFIG_IPV6=y
++CONFIG_NETFILTER=y
++CONFIG_NET_IPGRE=m
++CONFIG_NET_IPGRE_DEMUX=m
++CONFIG_NF_CONNTRACK=m
++CONFIG_NF_CONNTRACK_OVS=y
++CONFIG_OPENVSWITCH=m
++CONFIG_OPENVSWITCH_GENEVE=m
++CONFIG_OPENVSWITCH_GRE=m
++CONFIG_OPENVSWITCH_VXLAN=m
++CONFIG_PSAMPLE=m
++CONFIG_VETH=y
++CONFIG_VLAN_8021Q=y
++CONFIG_VXLAN=m