linux-signed-arm64 (4.19.20+1) unstable; urgency=medium

  * Sign kernel from linux 4.19.20-1

  * New upstream stable update:
    - tty/ldsem: Wake up readers after timed out down_write()
    - tty: Hold tty_ldisc_lock() during tty_reopen()
    - tty: Simplify tty->count math in tty_reopen()
    - tty: Don't hold ldisc lock in tty_reopen() if ldisc present
    - can: gw: ensure DLC boundaries after CAN frame modification
    - netfilter: nf_conncount: don't skip eviction when age is negative
    - netfilter: nf_conncount: split gc in two phases
    - netfilter: nf_conncount: restart search when nodes have been erased
      (Closes: #921616)
    - netfilter: nf_conncount: merge lookup and add functions
    - netfilter: nf_conncount: move all list iterations under spinlock
    - netfilter: nf_conncount: speculative garbage collection on empty lists
    - netfilter: nf_conncount: fix argument order to find_next_bit
    - [arm64] mmc: sdhci-msm: Disable CDR function on TX
    - Revert "scsi: target: iscsi: cxgbit: fix csk leak"
    - scsi: target: iscsi: cxgbit: fix csk leak
    - scsi: target: iscsi: cxgbit: fix csk leak
    - [arm64] kvm: consistently handle host HCR_EL2 flags
    - [arm64] Don't trap host pointer auth use to EL2
    - ipv6: fix kernel-infoleak in ipv6_local_error()
    - net: bridge: fix a bug on using a neighbour cache entry without checking
      its state
    - packet: Do not leak dev refcounts on error exit
    - tcp: change txhash on SYN-data timeout
    - tun: publish tfile after it's fully initialized
    - r8169: don't try to read counters if chip is in a PCI power-save state
    - bonding: update nest level on unlink
    - ip: on queued skb use skb_header_pointer instead of pskb_may_pull
    - r8169: load Realtek PHY driver module before r8169
    - crypto: authencesn - Avoid twice completion call in decrypt path
    - crypto: authenc - fix parsing key with misaligned rta_len
    - [x86] xen: Fix x86 sched_clock() interface for xen
    - Revert "btrfs: balance dirty metadata pages in btrfs_finish_ordered_io"
    - btrfs: wait on ordered extents on abort cleanup
    - Yama: Check for pid death before checking ancestry
    - scsi: core: Synchronize request queue PM status only on successful resume
    - [x86] scsi: sd: Fix cache_type_store()
    - [mips*] fix n32 compat_ipc_parse_version
    - [mips*] BCM47XX: Setup struct device for the SoC
    - [mips*] lantiq: Fix IPI interrupt handling
    - of: properties: add missing of_node_put
    - RDMA/nldev: Don't expose unsafe global rkey to regular user
    - [arm64] kaslr: ensure randomized quantities are clean to the PoC
    - [arm64] dts: marvell: armada-ap806: reserve PSCI area
    - [mips*] Disable MSI also when pcie-octeon.pcie_disable on
    - fix int_sqrt64() for very large numbers
    - media: vivid: fix error handling of kthread_run
    - media: vivid: set min width/height to a value > 0
    - bpf: in __bpf_redirect_no_mac pull mac only if present
    - ipv6: make icmp6_send() robust against null skb->dev
    - LSM: Check for NULL cred-security on free
    - netfilter: ebtables: account ebt_table_info to kmemcg
    - block: use rcu_work instead of call_rcu to avoid sleep in softirq
    - selinux: fix GPF on invalid policy
    - blockdev: Fix livelocks on loop device
    - sctp: allocate sctp_sockaddr_entry with kzalloc
    - tipc: fix uninit-value in in tipc_conn_rcv_sub
    - tipc: fix uninit-value in tipc_nl_compat_link_reset_stats
    - tipc: fix uninit-value in tipc_nl_compat_bearer_enable
    - tipc: fix uninit-value in tipc_nl_compat_link_set
    - tipc: fix uninit-value in tipc_nl_compat_name_table_dump
    - tipc: fix uninit-value in tipc_nl_compat_doit
    - block/loop: Don't grab "struct file" for vfs_getattr() operation.
    - block/loop: Use global lock for ioctl() operation.
    - loop: Fold __loop_release into loop_release
    - loop: Get rid of loop_index_mutex
    - loop: Push lo_ctl_mutex down into individual ioctls
    - loop: Split setting of lo_state from loop_clr_fd
    - loop: Push loop_ctl_mutex down into loop_clr_fd()
    - loop: Push loop_ctl_mutex down to loop_get_status()
    - loop: Push loop_ctl_mutex down to loop_set_status()
    - loop: Push loop_ctl_mutex down to loop_set_fd()
    - loop: Push loop_ctl_mutex down to loop_change_fd()
    - loop: Move special partition reread handling in loop_clr_fd()
    - loop: Move loop_reread_partitions() out of loop_ctl_mutex
    - loop: Fix deadlock when calling blkdev_reread_part()
    - loop: Avoid circular locking dependency between loop_ctl_mutex and
    - loop: Get rid of 'nested' acquisition of loop_ctl_mutex
    - loop: Fix double mutex_unlock(&loop_ctl_mutex) in loop_control_ioctl()
    - loop: drop caches if offset or block_size are changed
    - drm/fb-helper: Ignore the value of fb_var_screeninfo.pixclock
    - nbd: Use set_blocksize() to set device blocksize
    - ipv6: Consider sk_bound_dev_if when binding a socket to a v4 mapped
    - [armhf, arm64 net: dsa: mv88x6xxx: mv88e6390 errata
    - net, skbuff: do not prefer skb allocation fails early
    - qmi_wwan: add MTU default to qmap network interface
    - r8169: Add support for new Realtek Ethernet
    - ipv6: Take rcu_read_lock in __inet6_bind for mapped addresses
    - net: clear skb->tstamp in bridge forwarding path
    - netfilter: ipset: Allow matching on destination MAC address for mac and
      ipmac sets
    - [arm64] gpio: pl061: Move irq_chip definition inside struct pl061
    - drm/amd/display: Guard against null stream_state in set_crc_source
    - [x86] drm/amdkfd: fix interrupt spin lock
    - ixgbe: allow IPsec Tx offload in VEPA mode
    - [x86] platform: asus-wmi: Tell the EC the OS will handle the display
      off hotkey
    - e1000e: allow non-monotonic SYSTIM readings
    - [x86] usb: typec: tcpm: Do not disconnect link for self powered devices
    - of: overlay: add missing of_node_put() after add new node to changeset
    - writeback: don't decrement wb->refcnt if !wb->bdi
    - serial: set suppress_bind_attrs flag only if builtin
    - bpf: Allow narrow loads with offset > 0
    - ALSA: oxfw: add support for APOGEE duet FireWire
    - [x86] mce: Fix -Wmissing-prototypes warnings
    - [mips] SiByte: Enable swiotlb for SWARM, LittleSur and BigSur
    - [arm64] perf: set suppress_bind_attrs flag to true
    - drm/atomic-helper: Complete fake_commit->flip_done potentially earlier
    - [arm64] clk: meson: meson8b: fix incorrect divider mapping in
    - samples: bpf: fix: error handling regarding kprobe_events
    - usb: gadget: udc: renesas_usb3: add a safety connection way for
    - fpga: altera-cvp: fix probing for multiple FPGAs on the bus
    - selinux: always allow mounting submounts
    - ASoC: pcm3168a: Don't disable pcm3168a when CONFIG_PM defined
    - scsi: qedi: Check for session online before getting iSCSI TLV data.
    - drm/amdgpu: Reorder uvd ring init before uvd resume
    - rxe: IB_WR_REG_MR does not capture MR's iova field
    - efi/libstub: Disable some warnings for x86{,_64}
    - jffs2: Fix use of uninitialized delayed_work, lockdep breakage
    - clk: imx: make mux parent strings const
    - pstore/ram: Do not treat empty buffers as valid
    - media: uvcvideo: Refactor teardown of uvc on USB disconnect
    - powerpc/xmon: Fix invocation inside lock region
    - powerpc/pseries/cpuidle: Fix preempt warning
    - media: firewire: Fix app_info parameter type in avc_ca{,_app}_info
    - ASoC: use dma_ops of parent device for acp_audio_dma
    - media: venus: core: Set dma maximum segment size
    - staging: erofs: fix use-after-free of on-stack `z_erofs_vle_unzip_io'
    - net: call sk_dst_reset when set SO_DONTROUTE
    - scsi: target: use consistent left-aligned ASCII INQUIRY data
    - scsi: target/core: Make sure that target_wait_for_sess_cmds() waits long
    - [arm64] kasan: Increase stack size for KASAN_EXTRA
    - clk: imx6q: reset exclusive gates on init
    - [arm64] Fix minor issues with the dcache_by_line_op macro
    - bpf: relax verifier restriction on BPF_MOV | BPF_ALU
    - mmc: atmel-mci: do not assume idle after atmci_request_end
    - btrfs: volumes: Make sure there is no overlap of dev extents at mount
    - btrfs: alloc_chunk: fix more DUP stripe size handling
    - btrfs: fix use-after-free due to race between replace start and cancel
    - btrfs: improve error handling of btrfs_add_link
    - tty/serial: do not free trasnmit buffer page under port lock
    - perf intel-pt: Fix error with config term "pt=0"
    - perf tests ARM: Disable breakpoint tests 32-bit
    - perf svghelper: Fix unchecked usage of strncpy()
    - perf parse-events: Fix unchecked usage of strncpy()
    - perf vendor events intel: Fix Load_Miss_Real_Latency on SKL/SKX
    - netfilter: ipt_CLUSTERIP: check MAC address when duplicate config is set
    - netfilter: ipt_CLUSTERIP: remove wrong WARN_ON_ONCE in netns exit routine
    - netfilter: ipt_CLUSTERIP: fix deadlock in netns exit routine
    - [x86] topology: Use total_cpus for max logical packages calculation
    - dm crypt: use u64 instead of sector_t to store iv_offset
    - dm kcopyd: Fix bug causing workqueue stalls
    - perf stat: Avoid segfaults caused by negated options
    - tools lib subcmd: Don't add the kernel sources to the include path
    - dm snapshot: Fix excessive memory usage and workqueue stalls
    - perf cs-etm: Correct packets swapping in cs_etm__flush()
    - perf tools: Add missing sigqueue() prototype for systems lacking it
    - perf tools: Add missing open_memstream() prototype for systems lacking it
    - quota: Lock s_umount in exclusive mode for Q_XQUOTA{ON,OFF} quotactls.
    - clocksource/drivers/integrator-ap: Add missing of_node_put()
    - dm: Check for device sector overflow if CONFIG_LBDAF is not set
    - Bluetooth: btusb: Add support for Intel bluetooth device 8087:0029
    - ALSA: bebob: fix model-id of unit for Apogee Ensemble
    - sysfs: Disable lockdep for driver bind/unbind files
    - IB/usnic: Fix potential deadlock
    - scsi: mpt3sas: fix memory ordering on 64bit writes
    - scsi: smartpqi: correct lun reset issues
    - ath10k: fix peer stats null pointer dereference
    - scsi: smartpqi: call pqi_free_interrupts() in pqi_shutdown()
    - scsi: megaraid: fix out-of-bound array accesses
    - iomap: don't search past page end in iomap_is_partially_uptodate
    - ocfs2: fix panic due to unrecovered local alloc
    - mm/page-writeback.c: don't break integrity writeback on ->writepage()
    - mm/swap: use nr_node_ids for avail_lists in swap_info_struct
    - userfaultfd: clear flag if remap event not enabled
    - mm, proc: be more verbose about unstable VMA flags in /proc/<pid>/smaps
    - iwlwifi: mvm: Send LQ command as async when necessary
    - Bluetooth: Fix unnecessary error message for HCI request completion
    - ipmi: fix use-after-free of user->release_barrier.rda
    - ipmi: msghandler: Fix potential Spectre v1 vulnerabilities
    - ipmi: Prevent use-after-free in deliver_response
    - ipmi:ssif: Fix handling of multi-part return messages
    - ipmi: Don't initialize anything in the core until something uses it
    - amd-xgbe: Fix mdio access for non-zero ports and clause 45 PHYs
    - net: bridge: Fix ethernet header pointer before check skb forwardable
    - net: Fix usage of pskb_trim_rcsum
    - net: phy: marvell: Errata for mv88e6390 internal PHYs
    - net: phy: mdio_bus: add missing device_del() in mdiobus_register() error
    - net/sched: act_tunnel_key: fix memory leak in case of action replace
    - net_sched: refetch skb protocol for each filter
    - openvswitch: Avoid OOB read when parsing flow nlattrs
    - vhost: log dirty page correctly
    - net: ipv4: Fix memory leak in network namespace dismantle
    - net/sched: cls_flower: allocate mask dynamically in fl_change()
    - udp: with udp_segment release on error path
    - ip6_gre: fix tunnel list corruption for x-netns
    - erspan: build the header with the right proto according to erspan_ver
    - net: phy: marvell: Fix deadlock from wrong locking
    - ip6_gre: update version related info when changing link
    - tcp: allow MSG_ZEROCOPY transmission also in CLOSE_WAIT state
    - mei: me: mark LBG devices as having dma support
    - mei: me: add denverton innovation engine device IDs
    - USB: leds: fix regression in usbport led trigger
    - USB: serial: simple: add Motorola Tetra TPG2200 device id
    - USB: serial: pl2303: add new PID to support PL2303TB
    - ceph: clear inode pointer when snap realm gets dropped by its inode
    - ASoC: atom: fix a missing check of snd_pcm_lib_malloc_pages
    - ASoC: rt5514-spi: Fix potential NULL pointer dereference
    - ASoC: tlv320aic32x4: Kernel OOPS while entering DAPM standby mode
    - clk: socfpga: stratix10: fix rate calculation for pll clocks
    - clk: socfpga: stratix10: fix naming convention for the fixed-clocks
    - inotify: Fix fd refcount leak in inotify_add_watch().
    - ALSA: hda/realtek - Fix typo for ALC225 model
    - ALSA: hda - Add mute LED support for HP ProBook 470 G5
    - ARCv2: lib: memeset: fix doing prefetchw outside of buffer
    - ARC: adjust memblock_reserve of kernel memory
    - ARC: perf: map generic branches to correct hardware condition
    - s390/mm: always force a load of the primary ASCE on context switch
    - s390/early: improve machine detection
    - s390/smp: fix CPU hotplug deadlock with CPU rescan
    - misc: ibmvsm: Fix potential NULL pointer dereference
    - char/mwave: fix potential Spectre v1 vulnerability
    - [arm64] mmc: dw_mmc-bluefield: : Fix the license information
    - [arm64] mmc: meson-gx: Free irq in release() callback
    - staging: rtl8188eu: Add device code for D-Link DWA-121 rev B1
    - tty: Handle problem if line discipline does not have receive_buf
    - uart: Fix crash in uart_write and uart_put_char
    - tty/n_hdlc: fix __might_sleep warning
    - hv_balloon: avoid touching uninitialized struct page during tail onlining
    - Drivers: hv: vmbus: Check for ring when getting debug info
    - vgacon: unconfuse vc_origin when using soft scrollback
    - CIFS: Fix possible hang during async MTU reads and writes
    - CIFS: Fix credits calculations for reads with errors
    - CIFS: Fix credit calculation for encrypted reads with errors
    - CIFS: Do not reconnect TCP session in add_credits()
    - smb3: add credits we receive from oplock/break PDUs
    - Input: xpad - add support for SteelSeries Stratus Duo
    - Input: input_event - provide override for sparc64
    - Input: uinput - fix undefined behavior in uinput_validate_absinfo()
    - acpi/nfit: Block function zero DSMs
    - acpi/nfit: Fix command-supported detection
    - scsi: ufs: Use explicit access size in ufshcd_dump_regs
    - dm thin: fix passdown_double_checking_shared_status()
    - dm crypt: fix parsing of extended IV arguments
    - [x86] drm/amdgpu: Add APTX quirk for Lenovo laptop
    - [x86] KVM: Fix single-step debugging
    - [x86] KVM: Fix PV IPIs for 32-bit KVM host
    - [x86] KVM: WARN_ONCE if sending a PV IPI returns a fatal error
    - [x86] kvm: vmx: Use kzalloc for cached_vmcs12
    - [x86] KVM/nVMX: Do not validate that posted_intr_desc_addr is page
    - [x86] pkeys: Properly copy pkey state at fork()
    - [x86] selftests/pkeys: Fork() to check for state being preserved
    - [x86] kaslr: Fix incorrect i8254 outb() parameters
    - [x86] entry/64/compat: Fix stack switching for XEN PV
    - [arm64] irqchip/gic-v3-its: Align PCI Multi-MSI allocation on their size
    - can: dev: __can_get_echo_skb(): fix bogous check for non-existing skb by
      removing it
    - can: bcm: check timer values before ktime conversion
    - can: flexcan: fix NULL pointer exception during bringup
    - vt: make vt_console_print() compatible with the unicode screen buffer
    - vt: always call notifier with the console lock held
    - vt: invoke notifier on screen size change
    - [arm64] drm/meson: Fix atomic mode switching regression
    - bpf: improve verifier branch analysis
    - bpf: add per-insn complexity limit
    - bpf: move {prev_,}insn_idx into verifier env
    - bpf: move tmp variable into ax register in interpreter
    - bpf: enable access to ax register also from verifier rewrite
    - bpf: restrict map value pointer arithmetic for unprivileged
    - bpf: restrict stack pointer arithmetic for unprivileged
    - bpf: restrict unknown scalars of mixed signed bounds for unprivileged
    - bpf: fix check_map_access smin_value test when pointer contains offset
    - bpf: prevent out of bounds speculation on pointer arithmetic
    - bpf: fix sanitation of alu op with pointer / scalar type from different
      paths (CVE-2019-7308)
    - bpf: fix inner map masking to prevent oob under speculation
    - [s390*] smp: Fix calling smp_call_ipl_cpu() from ipl CPU
    - nvmet-rdma: Add unlikely for response allocated check
    - nvmet-rdma: fix null dereference under heavy load
    - Revert "mm, memory_hotplug: initialize struct pages for the full memory
    - usb: dwc3: gadget: Clear req->needs_extra_trb flag on cleanup
    - ide: fix a typo in the settings proc file name
    - Input: input_event - fix the CONFIG_SPARC64 mixup
    - Fix "net: ipv4: do not handle duplicate fragments as overlapping"
    - ipv6: sr: clear IP6CB(skb) on SRH ip4ip6 encapsulation
    - ipvlan, l3mdev: fix broken l3s mode wrt local routes
    - l2tp: copy 4 more bytes to linear part if necessary
    - l2tp: fix reading optional fields of L2TPv3
    - net: ip_gre: always reports o_key to userspace
    - net: ip_gre: use erspan key field for tunnel lookup
    - net/mlx4_core: Add masking for a few queries on HCA caps
    - netrom: switch to sock timer API
    - net/rose: fix NULL ax25_cb kernel panic
    - net: set default network namespace in init_dummy_netdev()
    - sctp: improve the events for sctp stream reset
    - tun: move the call to tun_set_real_num_queues
    - vhost: fix OOB in get_rx_bufs()
    - net: ip6_gre: always reports o_key to userspace
    - sctp: improve the events for sctp stream adding
    - net/mlx5e: Allow MAC invalidation while spoofchk is ON
    - ip6mr: Fix notifiers call on mroute_clean_tables()
    - sctp: set chunk transport correctly when it's a new asoc
    - sctp: set flow sport from saddr only when it's 0
    - virtio_net: Don't enable NAPI when interface is down
    - virtio_net: Don't call free_old_xmit_skbs for xdp_frames
    - virtio_net: Fix not restoring real_num_rx_queues
    - virtio_net: Fix out of bounds access of sq
    - virtio_net: Don't process redirected XDP frames when XDP is disabled
    - virtio_net: Use xdp_return_frame to free xdp_frames on destroying vqs
    - virtio_net: Differentiate sk_buff and xdp_frame on freeing
    - CIFS: Do not count -ENODATA as failure for query directory
    - CIFS: Fix trace command logging for SMB2 reads and writes
    - CIFS: Do not consider -ENODATA as stat failure for reads
    - fs/dcache: Fix incorrect nr_dentry_unused accounting in
    - iommu/vt-d: Fix memory leak in intel_iommu_put_resv_regions()
    - NFS: Fix up return value on fatal errors in nfs_page_async_flush()
    - [arm64] kaslr: ensure randomized quantities are clean also when kaslr is
    - [arm64] Do not issue IPIs for user executable ptes
    - [arm64] hyp-stub: Forbid kprobing of the hyp-stub
    - [arm64] hibernate: Clean the __hyp_text to PoC after resume
    - gpiolib: fix line event timestamps for nested irqs
    - gpio: pcf857x: Fix interrupts on multiple instances
    - gfs2: Revert "Fix loop in gfs2_rbm_find"
    - [arm*] mmc: bcm2835: Fix DMA channel leak on probe error
    - mmc: mediatek: fix incorrect register setting of hs400_cmd_int_delay
    - ALSA: usb-audio: Add Opus #3 to quirks for native DSD support
    - ALSA: hda/realtek - Fixed hp_pin no value
    - IB/hfi1: Remove overly conservative VM_EXEC flag check
    - [x86] platform: asus-nb-wmi: Map 0x35 to KEY_SCREENLOCK
    - [x86] platform: asus-nb-wmi: Drop mapping of 0x33 and 0x34 scan codes
    - mmc: sdhci-iproc: handle mmc_of_parse() errors during probe
    - Btrfs: fix deadlock when allocating tree block during leaf/node split
    - btrfs: On error always free subvol_name in btrfs_mount
    - kernel/exit.c: release ptraced tasks before zap_pid_ns_processes
    - mm/hugetlb.c: teach follow_hugetlb_page() to handle FOLL_NOWAIT
    - oom, oom_reaper: do not enqueue same task twice
    - mm,memory_hotplug: fix scan_movable_pages() for gigantic hugepages
    - mm, oom: fix use-after-free in oom_kill_process
    - mm: hwpoison: use do_send_sig_info() instead of force_sig()
    - mm: migrate: don't rely on __PageMovable() of newpage after unlocking it
    - of: Convert to using %pOFn instead of
    - of: overlay: add tests to validate kfrees from overlay removal
    - of: overlay: add missing of_node_get() in __of_attach_node_sysfs
    - of: overlay: use prop add changeset entry for property in new nodes
    - of: overlay: do not duplicate properties from overlay for new nodes
    - md/raid5: fix 'out of memory' during raid cache recovery
    - cifs: Always resolve hostname before reconnecting

  [ Luca Boccassi ]
  * Do not generate linux-source-$ver stanza in debian/control if
    source is set to disabled in debian/config/defines.
  * linux-perf: explicitly disable the jvmti feature and shared library.
  * Document pkg.linux.nosource in debian/README.source.
  * [amd64] enable UIO_HV_GENERIC for Azure's VMBus access.
  * [cloud-amd64] enable UIO for Azure's VMBus access, and VFIO for guests
    running on an hypervisor that exposes a vIOMMU.

  [ Ben Hutchings ]
  * debian/rules.d, debian/rules.real: Restore build of userland headers for
  * debian/rules.d: Delete now-unused recursive makefiles
  * debian/rules.d/tools/perf/Makefile: Delete redundant arch/profile checks
  * debian/control: Add !pkg.linux.nokernel to qualification for compiler
  * [i386] debian/control: Fix cross-compiler build-dependency
  * debian/README.source: Document how to run kconfigeditor2
  * [armhf,arm64] serial: 8250: Disable SERIAL_8250_DEPRECATED_OPTIONS
  * percpu: convert spin_lock_irq to spin_lock_irqsave (fixes boot failure with
    alpha-generic flavour)
  * debian/tests/python: Fix spurious failure due to misuse of stderr
  * Update "Revert "objtool: Fix CONFIG_STACK_VALIDATION=y warning for ..."
    to not duplicate the conditional warning/error
  * Bump ABI to 3
  * drivers/firmware: Enable FW_CFG_SYSFS as module (Closes: #882208)
  * [arm64,armhf,ia64,riscv64,sparc64] udeb: Add usb-serial-modules
    (Closes: #903824)
  * [powerpc*,sparc64] udeb: Add nic-usb-modules
  * [armhf,riscv64,s390x] udeb: Add cdrom-core-modules
  * 9p: Enable NET_9P_XEN as module
  * ACPI: Enable ACPI_TAD as module
  * amd-xgbe: Enable AMD_XGBE_DCB
  * ath9k: Enable ATH9K_CHANNEL_CONTEXT
  * block: Enable BLK_DEV_ZONED (except armel/marvell)
  * bluetooth: Enable BT_HCIUART_RTL; BT_HCIUART_NOKIA, BT_MTKUART as modules
  * bnxt: Enable BNXT_DCB
  * ethernet: Enable HINIC, ICE, LAN743X, LIQUIDIO_VF as modules
  * can: Enable CAN_VXCAN, CAN_MCBA_USB, CAN_UCAN as modules
  * dm: Enable DM_UNSTRIPED, DM_WRITECACHE, DM_ZONED as modules
  * [arm64,armhf] drm: Enable DRM_PANEL_RASPBERRYPI_TOUCHSCREEN as module
  * dvb-usb-v2: Enable DVB_USB_ZD1301 as module
  * gnss: Enable GNSS, GNSS_SIRF_SERIAL, GNSS_UBX_SERIAL as modules
  * gpio: Enable GPIO_EXAR, GPIO_PCI_IDIO_16, GPIO_PCIE_IDIO_24 as modules
  * [x86] i2c: Enable I2C_DESIGNWARE_BAYTRAIL
  * IB: Enable CGROUP_RDMA (except armel/marvell)
  * ieee802154: Enable IEEE802154_HWSIM as module
  * inet: Enable INET_RAW_DIAG as module
  * input: Enable INPUT_AXP20X_PEK as module
  * IPMI: Enable IPMI_SSIF as module
  * joystick: Enable JOYSTICK_PXRC as module
  * media/rc: Enable IR_IMON_DECODER, IR_IMON_RAW as modules
  * [x86] mfd: Enable INTEL_SOC_PMIC_BXTWC, INTEL_SOC_PMIC_CHTDC_TI as modules
  * mlx5: Enable MLX5_FPGA, MLX5_CORE_IPOIB; MLXFW as module
  * net: Enable BPF_STREAM_PARSER, XDP_SOCKETS (except armel/marvell)
    (Closes: #908860); NET_FAILOVER, SMC, SMC_DIAG, VSOCKMON as modules
  * net/phy: Enable LED_TRIGGER_PHY; CORTINA_PHY, DP83822_PHY, DP83TC811_PHY,
    as modules
  * PCMCIA: Enable SCR24X as module
  * [x86] rmi4: Re-enable RMI4_CORE, RMI4_SMB as modules (Closes: #875621);
    RMI4_F03, RMI4_F11, RMI4_F12, RMI4_F30, RMI4_F34, RMI4_F55
  * xfrm: Enable XFRM_INTERFACE as module
  * PCI: Enable PCI_PF_STUB as module
  * ptp: Change PTP_1588_CLOCK_KVM from built-in to module
  * random: Enable RANDOM_TRUST_CPU. This can be reverted using the kernel
    parameter: random.trust_cpu=off
  * SCSI: Enable QEDF, QEDI as modules
  * serial: Enable SERIAL_8250_EXAR, USB_SERIAL_F8153X, USB_SERIAL_UPD78F0730
    as modules
  * [x86] sound: Enable SND_SOC_AMD_CZ_DA7219MX98357_MACH,
    SND_SOC_INTEL_GLK_RT5682_MAX98357A_MACH as modules
  * tpm: Enable TCG_TIS_SPI, TCG_VTPM_PROXY as modules
  * usbtouchscreen: Enable TOUCHSCREEN_USB_EASYTOUCH
    WDAT_WDT as modules
  * [x86] watchdog: Enable INTEL_MEI_WDT, NI903X_WDT, NIC7018_WDT as modules
  * wireless: Enable MT76x0U, MT76x2E, MT76x2U, QTNFMAC_PEARL_PCIE as modules
    (Closes: #918331)
  * udeb: Add scsi-nic-modules containing Chelsio and Qlogic iSCSI/FC drivers

  [ Marcin Juszkiewicz ]
  * [arm64] enable ARM_CCI_PMU so ARM_CCI400_PMU and ARM_CCI5xx_PMU options
    get really enabled.
  * [arm64] enable PCI_PRI, PCI_PASID as PCI can be behind IOMMU in servers.
  * udeb: Add virtio-gpu into d-i to get graphical output in VM instances.
  * [arm64] Enable ARM64_ERRATUM_843419 (Closes: #920866)

  [ Salvatore Bonaccorso ]
  * [x86] kvmclock: set offset for kvm unstable clock (Closes: #918036)
  * kvm: fix kvm_ioctl_create_device() reference counting (CVE-2019-6974)
  * [x86] KVM: work around leak of uninitialized stack contents
  * [x86] KVM: nVMX: unconditionally cancel preemption timer in free_nested
  * HID: debug: fix the ring buffer implementation (CVE-2019-3819)

  [ Hideki Yamane ]
  * [x86] Enable Touchpad support on Gemini Lake via CONFIG_PINCTRL_GEMINILAKE
    (Closes: #917388)
  * [x86] Enable SND_SOC_ES8316 and Baytrail & Cherrytrail with ES8316 codec,
    too (Closes: #918589)
  * hwmon: Enable CONFIG_SENSORS_NCT7802,NCT7904,NPCM7XX,ASPEED and W83773G
    to use HWMON hardware (Closes: #912597)
  * net: can: Enable CONFIG_CAN_PEAK_PCIEFD for a PCI express CAN Bus adapter
    (Closes: #920809)
  * [armhf] Enable CONFIG_SENSORS_LM75 for armhf (Closes: #918114)
  * [armhf] Enable CONFIG_IMX_THERMAL for armhf (Closes: #883023)
  * [arm64] Enable CONFIG_ARM_ARMADA_37XX_CPUFREQ for arm64 (Closes: #917939)

  [ Vagrant Cascadian ]
  * [armhf] Enable CONFIG_MMC_SDHCI_OMAP=m, used on DRA7 and related SoCs.

  [ Uwe Kleine-K├Ânig ]
  * [armel] add spi-orion to mtd.udeb to be able to access spi flash on e.g.
    qnap ts-21x. (Closes: #920607)

 -- Ben Hutchings <email address hidden>  Mon, 11 Feb 2019 16:55:59 +0000

