Alexander Viro [Thu, 3 Jun 2004 17:38:18 +0000 (10:38 -0700)]
[PATCH] sparse: ->ifr_data fixes
b44.c: ->ioctl() is broken, since it uses &ifr->ifr_data instead of
ifr->ifr_data itself. Surprise, surprise, copy_from_user() on that address
doesn't do any good...
baycom_epp.c: does get_user() of the first word of structure, then
immediately does copy_from_user() on the entire thing and completely ignores
the value read by get_user() (it uses the same value in copied structure
instead). Bogus get_user() call removed.
Paul Mackerras [Thu, 3 Jun 2004 15:43:54 +0000 (08:43 -0700)]
[PATCH] ppc64: don't clear MSR.RI in do_hash_page_DSI
Some code that is used on iSeries (do_hash_page_DSI in head.S) was
clearing the RI (recoverable interrupt) bit in the MSR when it
shouldn't. We were getting SLB miss interrupts following that which
were panicking because they appeared to have occurred at a bad place.
This patch fixes the problem. In fact it isn't necessary for
do_hash_page_DSI to do anything to RI, so the patch changes the code
to not set or clear it.
Signed-off-by: Paul Mackerras <paulus@samba.org> Signed-off-by: Linus Torvalds <torvalds@osdl.org>
Alexander Viro [Thu, 3 Jun 2004 14:37:55 +0000 (07:37 -0700)]
[PATCH] sparse: net/bridge annotation
net/bridge partially annotated.
There are nasty problems with net/bridge/netfilter/* and they'll need to
be dealt with at some point - it mixes kernel and userland pointers a
lot and while it seems to avoid obvious breakage, it's not a nice code.
Alexander Viro [Thu, 3 Jun 2004 14:37:33 +0000 (07:37 -0700)]
[PATCH] sparse: econet annotation
econet partially annotated.
It's still badly broken - it mixes userland and kernel chunks in the
same iovec, then does set_fs(KERNEL_FS) and sends that to
sock_sendmsg(). Do we still want to support that protocol family,
anyway?
Dave Jones [Fri, 4 Jun 2004 00:46:25 +0000 (01:46 +0100)]
[CPUFREQ] Remove bogus longhaul v4
The code only supports 3 versions, so numbering them 1,2 and 4
doesn't make a lot of sense. Signed-off-by: Dave Jones <davej@redhat.com>
Dave Jones [Fri, 4 Jun 2004 00:44:00 +0000 (01:44 +0100)]
[CPUFREQ] Move longhaul multiplier debug printk to somewhere more useful.
If we abort due to a reserved FSB being found, we probably want to know the multipliers.
Dave Jones [Fri, 4 Jun 2004 00:29:42 +0000 (01:29 +0100)]
[CPUFREQ] Remove lots of redundant code from longhaul driver.
The recent Nehemiah changes introduced lots of stuff that does
a whole lot of nothing. Nuke it.
Alexander Viro [Thu, 3 Jun 2004 11:19:22 +0000 (04:19 -0700)]
[PATCH] sparse: wavefront annotation
Both ALSA and OSS drivers + wavefront ioctl structure annotated. NB:
both should be switched to generic firmware loading - as it is, they are
using a homegrown and rather ugly variant
Alexander Viro [Thu, 3 Jun 2004 11:18:29 +0000 (04:18 -0700)]
[PATCH] sparse: sound/core/pcm* annotation
The tricky part here was an iterator that used to take a callback and
argument for that callback as parameters. Iterator itself didn't care
what type that argument had been; it's entirely up to callback. The
thing is, two callbacks expect (and get) char __user * while other two
expect (and also get) char __user **.
Iterator used to use void * as "opaque data"; I've switched it to
unsigned long. Note that there was nothing that said "it's a pointer" -
use of callback that would take e.g. int is also perfectly legitimate.
Alexander Viro [Thu, 3 Jun 2004 09:47:28 +0000 (02:47 -0700)]
[PATCH] sparse: msnd sound fix
msnd_pinnacle/msnd_classic do copy_{to,from}_user under a spinlock.
Taken out of spinlock (into a temp. buffer). Calls of msnd_fifo_{read,write}
always go from kernel buffer now, so we can drop the 'int user' argument in
them _and_ simplify error handling - all errors were from copy_..._user() and
now these are called directly by dsp_read()/dsp_write().
Alexander Viro [Thu, 3 Jun 2004 09:47:17 +0000 (02:47 -0700)]
[PATCH] sparse: sound sb fix
In some cases snd_sb_csp_load() did kmalloc() and copy_from_user()
under a spinlock. Split into snd_sb_csp_load() and snd_sb_csp_load_user() -
ther former always from kernel pointer, the latter - from userland.
snd_sb_csp_load_user() doesn't take any locks itself, it just
does kmalloc, copy_from_user and calls snd_sb_csp_load() to do the rest.