Change logs for linux-gcp source package in Cosmic

  • linux-gcp (4.18.0-1016.17) cosmic; urgency=medium
    
      * linux-gcp: 4.18.0-1016.17 -proposed tracker (LP: #1834899)
    
      [ Ubuntu: 4.18.0-26.27 ]
    
      * linux: 4.18.0-26.27 -proposed tracker (LP: #1834904)
      * QCA9377 isn't being recognized sometimes (LP: #1757218)
        - SAUCE: USB: Disable USB2 LPM at shutdown
      * hns: fix ICMP6 neighbor solicitation messages discard problem (LP: #1833140)
        - net: hns: fix ICMP6 neighbor solicitation messages discard problem
        - net: hns: fix unsigned comparison to less than zero
      * Fix occasional boot time crash in hns driver (LP: #1833138)
        - net: hns: Fix probabilistic memory overwrite when HNS driver initialized
      *  use-after-free in hns_nic_net_xmit_hw (LP: #1833136)
        - net: hns: fix KASAN: use-after-free in hns_nic_net_xmit_hw()
      * hns: attempt to restart autoneg when disabled should report error
        (LP: #1833147)
        - net: hns: Restart autoneg need return failed when autoneg off
      * [UBUNTU] pkey: Indicate old mkvp only if old and curr. mkvp are different
        (LP: #1832625)
        - pkey: Indicate old mkvp only if old and current mkvp are different
      * [UBUNTU] kernel: Fix gcm-aes-s390 wrong scatter-gather list processing
        (LP: #1832623)
        - s390/crypto: fix gcm-aes-s390 selftest failures
      * rtlwifi: aggressive memory leak (LP: #1831751)
        - rtlwifi: Fix leak of skb when processing C2H_BT_INFO
      * Kernel modules generated incorrectly when system is localized to a non-
        English language (LP: #1828084)
        - scripts: override locale from environment when running recordmcount.pl
      * CVE-2019-11815
        - net: rds: force to destroy connection if t_sock is NULL in
          rds_tcp_kill_sock().
      * Sound device not detected after resume from hibernate (LP: #1826868)
        - drm/i915: Force 2*96 MHz cdclk on glk/cnl when audio power is enabled
        - drm/i915: Save the old CDCLK atomic state
        - drm/i915: Remove redundant store of logical CDCLK state
        - drm/i915: Skip modeset for cdclk changes if possible
      * Handle overflow in proc_get_long of sysctl (LP: #1833935)
        - sysctl: handle overflow in proc_get_long
      * Dell XPS 13 (9370) defaults to s2idle sleep/suspend instead of deep, NVMe
        drains lots of power under s2idle (LP: #1808957)
        - Revert "UBUNTU: SAUCE: pci/nvme: prevent WDC PC SN720 NVMe from entering D3
          and being disabled"
        - Revert "UBUNTU: SAUCE: nvme: add quirk to not call disable function when
          suspending"
        - Revert "UBUNTU: SAUCE: pci: prevent Intel NVMe SSDPEKKF from entering D3"
        - Revert "SAUCE: nvme: add quirk to not call disable function when suspending"
        - Revert "SAUCE: pci: prevent sk hynix nvme from entering D3"
        - PCI: PM: Avoid possible suspend-to-idle issue
        - PCI: PM: Skip devices in D0 for suspend-to-idle
        - nvme-pci: Sync queues on reset
        - nvme: Export get and set features
        - nvme-pci: Use host managed power state for suspend
      * hinic: fix oops due to race in set_rx_mode (LP: #1832048)
        - hinic: fix a bug in set rx mode
      * ubuntu 18.04 flickering screen with Radeon X1600 (LP: #1791312)
        - drm/radeon: prefer lower reference dividers
      * [linux-azure] Block Layer Commits Requested in Azure Kernels (LP: #1834499)
        - block: Clear kernel memory before copying to user
        - block/bio: Do not zero user pages
      * CONFIG_LOG_BUF_SHIFT set to 14 is too low on arm64 (LP: #1824864)
        - [Config] CONFIG_LOG_BUF_SHIFT=18 on all 64bit arches
      * Handle overflow for file-max (LP: #1834310)
        - sysctl: handle overflow for file-max
        - kernel/sysctl.c: fix out-of-bounds access when setting file-max
      * [ALSA] [PATCH] Headset fixup for System76 Gazelle (gaze14) (LP: #1827555)
        - ALSA: hda/realtek - Headset fixup for System76 Gazelle (gaze14)
        - ALSA: hda/realtek - Corrected fixup for System76 Gazelle (gaze14)
      * crashdump fails on HiSilicon D06 (LP: #1828868)
        - iommu/arm-smmu-v3: Don't disable SMMU in kdump kernel
      * CVE-2019-11833
        - ext4: zero out the unused memory region in the extent tree block
      * does not detect headphone when there is no other output devices
        (LP: #1831065)
        - ALSA: hda/realtek - Fixed hp_pin no value
        - ALSA: hda/realtek - Use a common helper for hp pin reference
      * Support new ums-realtek device (LP: #1831840)
        - USB: usb-storage: Add new ID to ums-realtek
      * amd_iommu possible data corruption (LP: #1823037)
        - iommu/amd: Reserve exclusion range in iova-domain
        - iommu/amd: Set exclusion range correctly
      * Add new sound card PCIID into the alsa driver (LP: #1832299)
        - ALSA: hda/intel: add CometLake PCI IDs
      * sky2 ethernet card doesn't work after returning from suspend
        (LP: #1807259) // sky2 ethernet card link not up after suspend
        (LP: #1809843)
        - sky2: Disable MSI on Dell Inspiron 1545 and Gateway P-79
      * idle-page oopses when accessing page frames that are out of range
        (LP: #1833410)
        - mm/page_idle.c: fix oops because end_pfn is larger than max_pfn
      * Add pointstick support on HP ZBook 17 G5 (LP: #1833387)
        - Revert "HID: multitouch: Support ALPS PTP stick with pid 0x120A"
        - SAUCE: HID: multitouch: Add pointstick support for ALPS Touchpad
      * [SRU][B/B-OEM/B-OEM-OSP-1/C/D/E] Add trackpoint middle button support of 2
        new thinpads (LP: #1833637)
        - Input: elantech - enable middle button support on 2 ThinkPads
      * CVE-2019-11884
        - Bluetooth: hidp: fix buffer overflow
      * af_alg06 test from crypto test suite in LTP failed with kernel oops on B/C
        (LP: #1829725)
        - crypto: authenc - fix parsing key with misaligned rta_len
      * Address performance issue w/ GICv4-based guests (LP: #1829942)
        - arm64: KVM: Always set ICH_HCR_EL2.EN if GICv4 is enabled
      * CVE-2018-12126 // CVE-2018-12127 // CVE-2018-12130 // CVE-2019-11091
        - SAUCE: Synchronize MDS mitigations with upstream
        - Documentation: Correct the possible MDS sysfs values
        - x86/speculation/mds: Fix documentation typo
      * CVE-2019-11091
        - x86/mds: Add MDSUM variant to the MDS documentation
      * CVE-2019-11085
        - drm/i915/gvt: Fix mmap range check
      * alignment test in powerpc from ubuntu_kernel_selftests failed on B/C Power9
        (LP: #1813118)
        - selftests/powerpc: Remove Power9 copy_unaligned test
      * TRACE_syscall.ptrace_syscall_dropped in seccomp from ubuntu_kernel_selftests
        failed on B/C PowerPC (LP: #1812796)
        - selftests/seccomp: Enhance per-arch ptrace syscall skip tests
      * Eletrical noise occurred when external headset enter powersaving mode on a
        DEll machine (LP: #1828798)
        - ALSA: hda/realtek - Reduce click noise on Dell Precision 5820 headphone
        - ALSA: hda/realtek - Fixup headphone noise via runtime suspend
      * [18.04/18.10] File libperf-jvmti.so is missing in linux-tools-common deb on
        Ubuntu (LP: #1761379)
        - [Packaging] Support building libperf-jvmti.so
      * TCP : race condition on socket ownership in tcp_close() (LP: #1830813)
        - tcp: do not release socket ownership in tcp_close()
      * ethtool identify command doesn't blink LED on Hi1620 NICs (LP: #1829306)
        - net: phy: marvell: add new default led configure for m88e151x
      * Add support to Comet Lake LPSS (LP: #1830175)
        - mfd: intel-lpss: Add Intel Comet Lake PCI IDs
      * Reduce NAPI weight in hns driver from 256 to 64 (LP: #1830587)
        - net: hns: Use NAPI_POLL_WEIGHT for hns driver
    
     -- Connor Kuehl <email address hidden>  Wed, 03 Jul 2019 14:00:27 -0700
  • linux-gcp (4.18.0-1015.16) cosmic; urgency=medium
    
      * linux-gcp: 4.18.0-1015.16 -proposed tracker (LP: #1833948)
    
      [ Ubuntu: 4.18.0-25.26 ]
    
      * linux: 4.18.0-25.26 -proposed tracker (LP: #1833952)
      * CVE-2019-11479
        - SAUCE: tcp: add tcp_min_snd_mss sysctl
        - SAUCE: tcp: enforce tcp_min_snd_mss in tcp_mtu_probing()
      * Remote denial of service (resource exhaustion) caused by TCP SACK scoreboard
        manipulation (LP: #1831638) // CVE-2019-11478
        - tcp: refine memory limit test in tcp_fragment()
    
      [ Ubuntu: 4.18.0-24.25 ]
    
      * CVE-2019-12817
        - SAUCE: powerpc/mm/64s/hash: Reallocate context ids on fork
    
     -- Connor Kuehl <email address hidden>  Mon, 24 Jun 2019 14:56:23 -0700
  • linux-gcp (4.18.0-1014.15) cosmic; urgency=medium
    
      * linux-gcp: 4.18.0-1014.15 -proposed tracker (LP: #1832505)
    
      [ Ubuntu: 4.18.0-23.24 ]
    
      * linux: 4.18.0-23.24 -proposed tracker (LP: #1832508)
      * CVE-2019-11479
        - SAUCE: tcp: add tcp_min_snd_mss sysctl
        - SAUCE: tcp: enforce tcp_min_snd_mss in tcp_mtu_probing()
      * CVE-2019-11884
        - Bluetooth: hidp: fix buffer overflow
      * af_alg06 test from crypto test suite in LTP failed with kernel oops on B/C
        (LP: #1829725)
        - crypto: authenc - fix parsing key with misaligned rta_len
      * Address performance issue w/ GICv4-based guests (LP: #1829942)
        - arm64: KVM: Always set ICH_HCR_EL2.EN if GICv4 is enabled
      * CVE-2018-12126 // CVE-2018-12127 // CVE-2018-12130 // CVE-2019-11091
        - SAUCE: Synchronize MDS mitigations with upstream
        - Documentation: Correct the possible MDS sysfs values
        - x86/speculation/mds: Fix documentation typo
      * CVE-2019-11091
        - x86/mds: Add MDSUM variant to the MDS documentation
      * CVE-2019-11085
        - drm/i915/gvt: Fix mmap range check
      * alignment test in powerpc from ubuntu_kernel_selftests failed on B/C Power9
        (LP: #1813118)
        - selftests/powerpc: Remove Power9 copy_unaligned test
      * TRACE_syscall.ptrace_syscall_dropped in seccomp from ubuntu_kernel_selftests
        failed on B/C PowerPC (LP: #1812796)
        - selftests/seccomp: Enhance per-arch ptrace syscall skip tests
      * Eletrical noise occurred when external headset enter powersaving mode on a
        DEll machine (LP: #1828798)
        - ALSA: hda/realtek - Reduce click noise on Dell Precision 5820 headphone
        - ALSA: hda/realtek - Fixup headphone noise via runtime suspend
      * [18.04/18.10] File libperf-jvmti.so is missing in linux-tools-common deb on
        Ubuntu (LP: #1761379)
        - [Packaging] Support building libperf-jvmti.so
      * TCP : race condition on socket ownership in tcp_close() (LP: #1830813)
        - tcp: do not release socket ownership in tcp_close()
      * ethtool identify command doesn't blink LED on Hi1620 NICs (LP: #1829306)
        - net: phy: marvell: add new default led configure for m88e151x
      * Add support to Comet Lake LPSS (LP: #1830175)
        - mfd: intel-lpss: Add Intel Comet Lake PCI IDs
      * Reduce NAPI weight in hns driver from 256 to 64 (LP: #1830587)
        - net: hns: Use NAPI_POLL_WEIGHT for hns driver
    
     -- Stefan Bader <email address hidden>  Tue, 18 Jun 2019 13:59:27 +0200
  • linux-gcp (4.18.0-1013.14) cosmic; urgency=medium
    
      [ Ubuntu: 4.18.0-22.23 ]
    
      * Remote denial of service (resource exhaustion) caused by TCP SACK scoreboard
        manipulation (LP: #1831638)
        - SAUCE: tcp: tcp_fragment() should apply sane memory limits
      * Remote denial of service (system crash) caused by integer overflow in TCP
        SACK handling (LP: #1831637)
        - SAUCE: tcp: limit payload size of sacked skbs
    
     -- Stefan Bader <email address hidden>  Wed, 05 Jun 2019 17:07:07 +0200
  • linux-gcp (4.18.0-1012.13) cosmic; urgency=medium
    
      * linux-gcp: 4.18.0-1012.13 -proposed tracker (LP: #1829183)
    
      [ Ubuntu: 4.18.0-21.22 ]
    
      * linux: 4.18.0-21.22 -proposed tracker (LP: #1829186)
      * disable a.out support (LP: #1818552)
        - [Config] Turn off a.out support
      * ftrace in ubuntu_kernel_selftests hang with Cosmic kernel (LP: #1826385)
        - kprobes/x86: Fix instruction patching corruption when copying more than one
          RIP-relative instruction
      * touchpad not working on lenovo yoga 530 (LP: #1787775)
        - Revert "UBUNTU: SAUCE: i2c:amd Depends on ACPI"
        - Revert "UBUNTU: SAUCE: i2c:amd move out pointer in union i2c_event_base"
        - Revert "UBUNTU: SAUCE: i2c:amd I2C Driver based on PCI Interface for
          upcoming platform"
        - i2c: add extra check to safe DMA buffer helper
        - i2c: Add drivers for the AMD PCIe MP2 I2C controller
        - [Config] Update config for AMD MP2 I2C driver
        - [Config] Update I2C_AMD_MP2 annotations
      * Geneve tunnels don't work when ipv6 is disabled (LP: #1794232)
        - geneve: correctly handle ipv6.disable module parameter
      * There are 4 HDMI/Displayport audio output listed in sound setting without
        attach any HDMI/DP monitor (LP: #1827967)
        - ALSA: hda/hdmi - Read the pin sense from register when repolling
        - ALSA: hda/hdmi - Consider eld_valid when reporting jack event
      * Headphone jack switch sense is inverted: plugging in headphones disables
        headphone output (LP: #1824259)
        - ASoC: rt5645: Headphone Jack sense inverts on the LattePanda board
      * CTAUTO:DevOps:860.50:devops4fp1:Error occurred during LINUX Dmesg error
        Checking for all LINUX clients for devops4p10 (LP: #1766201)
        - SAUCE: integrity: downgrade error to warning
      * potential memory corruption on arm64 on dev release (LP: #1827437)
        - driver core: Postpone DMA tear-down until after devres release
      * powerpc/pmu/ebb test in ubuntu_kernel_selftest failed with "error while
        loading shared libraries" on Bionic/Cosmic PowerPC (LP: #1812805)
        - selftests/powerpc/pmu: Link ebb tests with -no-pie
      * unnecessary request_queue freeze (LP: #1815733)
        - block: avoid setting nr_requests to current value
        - block: avoid setting none scheduler if it's already none
      * Kprobe event string type argument failed in ftrace from
        ubuntu_kernel_selftests on B/C i386 (LP: #1825780)
        - selftests/ftrace: Fix kprobe string testcase to not probe notrace function
      * False positive test result in run_netsocktests from net in
        ubuntu_kernel_selftest (LP: #1825777)
        - selftests/net: correct the return value for run_netsocktests
    
     -- Connor Kuehl <email address hidden>  Thu, 16 May 2019 11:07:01 -0700
  • linux-gcp (4.18.0-1011.12) cosmic; urgency=medium
    
      [ Ubuntu: 4.18.0-20.21 ]
    
      * CVE-2018-12126 // CVE-2018-12127 // CVE-2018-12130
        - Documentation/l1tf: Fix small spelling typo
        - x86/cpu: Sanitize FAM6_ATOM naming
        - kvm: x86: Report STIBP on GET_SUPPORTED_CPUID
        - locking/atomics, asm-generic: Move some macros from <linux/bitops.h> to a
          new <linux/bits.h> file
        - tools include: Adopt linux/bits.h
        - x86/msr-index: Cleanup bit defines
        - x86/speculation: Consolidate CPU whitelists
        - x86/speculation/mds: Add basic bug infrastructure for MDS
        - x86/speculation/mds: Add BUG_MSBDS_ONLY
        - x86/kvm: Expose X86_FEATURE_MD_CLEAR to guests
        - x86/speculation/mds: Add mds_clear_cpu_buffers()
        - x86/speculation/mds: Clear CPU buffers on exit to user
        - x86/kvm/vmx: Add MDS protection when L1D Flush is not active
        - x86/speculation/mds: Conditionally clear CPU buffers on idle entry
        - x86/speculation/mds: Add mitigation control for MDS
        - x86/speculation/mds: Add sysfs reporting for MDS
        - x86/speculation/mds: Add mitigation mode VMWERV
        - Documentation: Move L1TF to separate directory
        - Documentation: Add MDS vulnerability documentation
        - x86/speculation/mds: Add mds=full,nosmt cmdline option
        - x86/speculation: Move arch_smt_update() call to after mitigation decisions
        - x86/speculation/mds: Add SMT warning message
        - x86/speculation/mds: Fix comment
        - x86/speculation/mds: Print SMT vulnerable on MSBDS with mitigations off
        - x86/speculation/mds: Add 'mitigations=' support for MDS
      * CVE-2017-5715 // CVE-2017-5753
        - s390/speculation: Support 'mitigations=' cmdline option
      * CVE-2017-5715 // CVE-2017-5753 // CVE-2017-5754 // CVE-2018-3639
        - powerpc/speculation: Support 'mitigations=' cmdline option
      * CVE-2017-5715 // CVE-2017-5754 // CVE-2018-3620 // CVE-2018-3639 //
        CVE-2018-3646
        - cpu/speculation: Add 'mitigations=' cmdline option
        - x86/speculation: Support 'mitigations=' cmdline option
      * Packaging resync (LP: #1786013)
        - [Packaging] resync git-ubuntu-log
    
    linux-gcp (4.18.0-1010.11) cosmic; urgency=medium
    
      * linux-gcp: 4.18.0-1010.11 -proposed tracker (LP: #1826168)
    
      [ Ubuntu: 4.18.0-19.20 ]
    
      * linux: 4.18.0-19.20 -proposed tracker (LP: #1826171)
      * Packaging resync (LP: #1786013)
        - [Packaging] resync git-ubuntu-log
      * autopkgtests run too often, too much and don't skip enough (LP: #1823056)
        - [Debian] Set +x on rebuild testcase.
        - [Debian] Skip rebuild test, for regression-suite deps.
        - [Debian] Make ubuntu-regression-suite skippable on unbootable kernels.
        - [Debian] make rebuild use skippable error codes when skipping.
        - [Debian] Only run regression-suite, if requested to.
      * CVE-2017-5753
        - s390/keyboard: sanitize array index in do_kdsk_ioctl
        - drm/bufs: Fix Spectre v1 vulnerability
        - drivers/misc/sgi-gru: fix Spectre v1 vulnerability
        - ipv4: Fix potential Spectre v1 vulnerability
        - aio: fix spectre gadget in lookup_ioctx
        - ALSA: emux: Fix potential Spectre v1 vulnerabilities
        - ALSA: pcm: Fix potential Spectre v1 vulnerability
        - ip6mr: Fix potential Spectre v1 vulnerability
        - ALSA: rme9652: Fix potential Spectre v1 vulnerability
        - ALSA: emu10k1: Fix potential Spectre v1 vulnerabilities
        - KVM: arm/arm64: vgic: Fix off-by-one bug in vgic_get_irq()
        - drm/ioctl: Fix Spectre v1 vulnerabilities
        - net: core: Fix Spectre v1 vulnerability
        - phonet: af_phonet: Fix Spectre v1 vulnerability
        - nfc: af_nfc: Fix Spectre v1 vulnerability
        - can: af_can: Fix Spectre v1 vulnerability
        - net: Revert recent Spectre-v1 patches.
        - char/mwave: fix potential Spectre v1 vulnerability
        - applicom: Fix potential Spectre v1 vulnerabilities
        - ipmi: msghandler: Fix potential Spectre v1 vulnerabilities
        - powerpc/ptrace: Mitigate potential Spectre v1
        - cfg80211: prevent speculation on cfg80211_classify8021d() return
        - ALSA: rawmidi: Fix potential Spectre v1 vulnerability
        - ALSA: seq: oss: Fix Spectre v1 vulnerability
      * NULL pointer dereference when using z3fold and zswap (LP: #1814874)
        - z3fold: fix possible reclaim races
      * The Realtek card reader does not enter PCIe 1.1/1.2 (LP: #1825487)
        - misc: rtsx: Enable OCP for rts522a rts524a rts525a rts5260
        - SAUCE: misc: rtsx: Fixed rts5260 power saving parameter and sd glitch
      * headset-mic doesn't work on two Dell laptops. (LP: #1825272)
        - ALSA: hda/realtek - add two more pin configuration sets to quirk table
      * CVE-2018-16884
        - sunrpc: use SVC_NET() in svcauth_gss_* functions
        - sunrpc: use-after-free in svc_process_common()
      * AMD Rome :  Minimal support patches (LP: #1816669)
        - x86: irq_remapping: Move irq remapping mode enum
        - iommu/amd: Add support for higher 64-bit IOMMU Control Register
        - iommu/amd: Add support for IOMMU XT mode
      * sky2 ethernet card don't work after returning from suspension (LP: #1798921)
        - sky2: Increase D3 delay again
      * CVE-2019-9500
        - brcmfmac: assure SSID length from firmware is limited
      * CVE-2019-9503
        - brcmfmac: add subtype check for event handling in data path
      * CVE-2019-3882
        - vfio/type1: Limit DMA mappings per container
      * CVE-2019-3887
        - KVM: x86: nVMX: close leak of L0's x2APIC MSRs (CVE-2019-3887)
        - KVM: x86: nVMX: fix x2APIC VTPR read intercept
      * CVE-2019-3874
        - sctp: use sk_wmem_queued to check for writable space
        - sctp: implement memory accounting on tx path
        - sctp: implement memory accounting on rx path
      * Intel I210 Ethernet card not working after hotplug [8086:1533]
        (LP: #1818490)
        - igb: Fix WARN_ONCE on runtime suspend
      * autofs kernel module missing (LP: #1824333)
        - [Config] Update autofs4 path in inclusion list
      * tasks doing write()/fsync() hit deadlock in write_cache_pages()
        (LP: #1824827)
        - mm/page-writeback.c: fix range_cyclic writeback vs writepages deadlock
      * Pop noise when headset is plugged in or removed from GHS/Line-out jack
        (LP: #1821290)
        - ALSA: hda/realtek - Add unplug function into unplug state of Headset Mode
          for ALC225
        - ALSA: hda/realtek - Disable headset Mic VREF for headset mode of ALC225
        - ALSA: hda/realtek - Add support headset mode for DELL WYSE AIO
        - ALSA: hda/realtek - Add support headset mode for New DELL WYSE NB
      * mac80211_hwsim unable to handle kernel NULL pointer dereference
        at0000000000000000  (LP: #1825058)
        - mac80211_hwsim: Timer should be initialized before device registered
      * [regression][snd_hda_codec_realtek] repeating crackling noise after 19.04
        upgrade (LP: #1821663)
        - ALSA: hda - add Lenovo IdeaCentre B550 to the power_save_blacklist
        - ALSA: hda - Add two more machines to the power_save_blacklist
      * systemd cause kernel trace "BUG: unable to handle kernel paging request at
        6db23a14" on Cosmic i386 (LP: #1813244) // systemd cause kernel trace "BUG:
        unable to handle kernel paging request at 6db23a14" on Cosmic i386
        (LP: #1813244)
        - openvswitch: fix flow actions reallocation
    
     -- Stefan Bader <email address hidden>  Wed, 08 May 2019 08:50:09 +0200
  • linux-gcp (4.18.0-1010.11) cosmic; urgency=medium
    
      * linux-gcp: 4.18.0-1010.11 -proposed tracker (LP: #1826168)
    
      [ Ubuntu: 4.18.0-19.20 ]
    
      * linux: 4.18.0-19.20 -proposed tracker (LP: #1826171)
      * Packaging resync (LP: #1786013)
        - [Packaging] resync git-ubuntu-log
      * autopkgtests run too often, too much and don't skip enough (LP: #1823056)
        - [Debian] Set +x on rebuild testcase.
        - [Debian] Skip rebuild test, for regression-suite deps.
        - [Debian] Make ubuntu-regression-suite skippable on unbootable kernels.
        - [Debian] make rebuild use skippable error codes when skipping.
        - [Debian] Only run regression-suite, if requested to.
      * CVE-2017-5753
        - s390/keyboard: sanitize array index in do_kdsk_ioctl
        - drm/bufs: Fix Spectre v1 vulnerability
        - drivers/misc/sgi-gru: fix Spectre v1 vulnerability
        - ipv4: Fix potential Spectre v1 vulnerability
        - aio: fix spectre gadget in lookup_ioctx
        - ALSA: emux: Fix potential Spectre v1 vulnerabilities
        - ALSA: pcm: Fix potential Spectre v1 vulnerability
        - ip6mr: Fix potential Spectre v1 vulnerability
        - ALSA: rme9652: Fix potential Spectre v1 vulnerability
        - ALSA: emu10k1: Fix potential Spectre v1 vulnerabilities
        - KVM: arm/arm64: vgic: Fix off-by-one bug in vgic_get_irq()
        - drm/ioctl: Fix Spectre v1 vulnerabilities
        - net: core: Fix Spectre v1 vulnerability
        - phonet: af_phonet: Fix Spectre v1 vulnerability
        - nfc: af_nfc: Fix Spectre v1 vulnerability
        - can: af_can: Fix Spectre v1 vulnerability
        - net: Revert recent Spectre-v1 patches.
        - char/mwave: fix potential Spectre v1 vulnerability
        - applicom: Fix potential Spectre v1 vulnerabilities
        - ipmi: msghandler: Fix potential Spectre v1 vulnerabilities
        - powerpc/ptrace: Mitigate potential Spectre v1
        - cfg80211: prevent speculation on cfg80211_classify8021d() return
        - ALSA: rawmidi: Fix potential Spectre v1 vulnerability
        - ALSA: seq: oss: Fix Spectre v1 vulnerability
      * NULL pointer dereference when using z3fold and zswap (LP: #1814874)
        - z3fold: fix possible reclaim races
      * The Realtek card reader does not enter PCIe 1.1/1.2 (LP: #1825487)
        - misc: rtsx: Enable OCP for rts522a rts524a rts525a rts5260
        - SAUCE: misc: rtsx: Fixed rts5260 power saving parameter and sd glitch
      * headset-mic doesn't work on two Dell laptops. (LP: #1825272)
        - ALSA: hda/realtek - add two more pin configuration sets to quirk table
      * CVE-2018-16884
        - sunrpc: use SVC_NET() in svcauth_gss_* functions
        - sunrpc: use-after-free in svc_process_common()
      * AMD Rome :  Minimal support patches (LP: #1816669)
        - x86: irq_remapping: Move irq remapping mode enum
        - iommu/amd: Add support for higher 64-bit IOMMU Control Register
        - iommu/amd: Add support for IOMMU XT mode
      * sky2 ethernet card don't work after returning from suspension (LP: #1798921)
        - sky2: Increase D3 delay again
      * CVE-2019-9500
        - brcmfmac: assure SSID length from firmware is limited
      * CVE-2019-9503
        - brcmfmac: add subtype check for event handling in data path
      * CVE-2019-3882
        - vfio/type1: Limit DMA mappings per container
      * CVE-2019-3887
        - KVM: x86: nVMX: close leak of L0's x2APIC MSRs (CVE-2019-3887)
        - KVM: x86: nVMX: fix x2APIC VTPR read intercept
      * CVE-2019-3874
        - sctp: use sk_wmem_queued to check for writable space
        - sctp: implement memory accounting on tx path
        - sctp: implement memory accounting on rx path
      * Intel I210 Ethernet card not working after hotplug [8086:1533]
        (LP: #1818490)
        - igb: Fix WARN_ONCE on runtime suspend
      * autofs kernel module missing (LP: #1824333)
        - [Config] Update autofs4 path in inclusion list
      * tasks doing write()/fsync() hit deadlock in write_cache_pages()
        (LP: #1824827)
        - mm/page-writeback.c: fix range_cyclic writeback vs writepages deadlock
      * Pop noise when headset is plugged in or removed from GHS/Line-out jack
        (LP: #1821290)
        - ALSA: hda/realtek - Add unplug function into unplug state of Headset Mode
          for ALC225
        - ALSA: hda/realtek - Disable headset Mic VREF for headset mode of ALC225
        - ALSA: hda/realtek - Add support headset mode for DELL WYSE AIO
        - ALSA: hda/realtek - Add support headset mode for New DELL WYSE NB
      * mac80211_hwsim unable to handle kernel NULL pointer dereference
        at0000000000000000  (LP: #1825058)
        - mac80211_hwsim: Timer should be initialized before device registered
      * [regression][snd_hda_codec_realtek] repeating crackling noise after 19.04
        upgrade (LP: #1821663)
        - ALSA: hda - add Lenovo IdeaCentre B550 to the power_save_blacklist
        - ALSA: hda - Add two more machines to the power_save_blacklist
      * systemd cause kernel trace "BUG: unable to handle kernel paging request at
        6db23a14" on Cosmic i386 (LP: #1813244) // systemd cause kernel trace "BUG:
        unable to handle kernel paging request at 6db23a14" on Cosmic i386
        (LP: #1813244)
        - openvswitch: fix flow actions reallocation
    
     -- Khalid Elmously <email address hidden>  Wed, 24 Apr 2019 20:09:54 -0400
  • linux-gcp (4.18.0-1009.10) cosmic; urgency=medium
    
      * linux-gcp: 4.18.0-1009.10 -proposed tracker (LP: #1822793)
    
      [ Ubuntu: 4.18.0-18.19 ]
    
      * linux: 4.18.0-18.19 -proposed tracker (LP: #1822796)
      * Packaging resync (LP: #1786013)
        - [Packaging] update helper scripts
        - [Packaging] resync retpoline extraction
      * 3b080b2564287be91605bfd1d5ee985696e61d3c in ubuntu_btrfs_kernel_fixes
        triggers system hang on i386 (LP: #1812845)
        - btrfs: raid56: properly unmap parity page in finish_parity_scrub()
      * [SRU][B/C/OEM]IOMMU: add kernel dma protection (LP: #1820153)
        - ACPI / property: Allow multiple property compatible _DSD entries
        - PCI / ACPI: Identify untrusted PCI devices
        - iommu/vt-d: Force IOMMU on for platform opt in hint
        - iommu/vt-d: Do not enable ATS for untrusted devices
        - thunderbolt: Export IOMMU based DMA protection support to userspace
        - iommu/vt-d: Disable ATS support on untrusted devices
      * Huawei Hi1822 NIC has poor performance (LP: #1820187)
        - net-next: hinic: fix a problem in free_tx_poll()
        - hinic: remove ndo_poll_controller
        - net-next/hinic: add checksum offload and TSO support
        - hinic: Fix l4_type parameter in hinic_task_set_tunnel_l4
        - net-next/hinic:replace multiply and division operators
        - net-next/hinic:add rx checksum offload for HiNIC
        - net-next/hinic:fix a bug in set mac address
        - net-next/hinic: fix a bug in rx data flow
        - net: hinic: fix null pointer dereference on pointer hwdev
        - hinic: optmize rx refill buffer mechanism
        - net-next/hinic:add shutdown callback
        - net-next/hinic: replace disable_irq_nosync/enable_irq
      * [CONFIG] please enable highdpi font FONT_TER16x32 (LP: #1819881)
        - Fonts: New Terminus large console font
        - [Config]: enable highdpi Terminus 16x32 font support
      * [19.04 FEAT] qeth: Enhanced link speed - kernel part (LP: #1814892)
        - s390/qeth: report 25Gbit link speed
      * Avoid potential memory corruption on HiSilicon SoCs (LP: #1819546)
        - iommu/arm-smmu-v3: Avoid memory corruption from Hisilicon MSI payloads
      * CVE-2017-5715
        - x86/speculation: Apply IBPB more strictly to avoid cross-process data leak
        - x86/speculation: Propagate information about RSB filling mitigation to sysfs
        - x86/speculation: Add RETPOLINE_AMD support to the inline asm CALL_NOSPEC
          variant
        - x86/retpoline: Make CONFIG_RETPOLINE depend on compiler support
        - x86/retpoline: Remove minimal retpoline support
        - x86/speculation: Update the TIF_SSBD comment
        - x86/speculation: Clean up spectre_v2_parse_cmdline()
        - x86/speculation: Remove unnecessary ret variable in cpu_show_common()
        - x86/speculation: Move STIPB/IBPB string conditionals out of
          cpu_show_common()
        - x86/speculation: Disable STIBP when enhanced IBRS is in use
        - x86/speculation: Rename SSBD update functions
        - x86/speculation: Reorganize speculation control MSRs update
        - sched/smt: Make sched_smt_present track topology
        - x86/Kconfig: Select SCHED_SMT if SMP enabled
        - sched/smt: Expose sched_smt_present static key
        - x86/speculation: Rework SMT state change
        - x86/l1tf: Show actual SMT state
        - x86/speculation: Reorder the spec_v2 code
        - x86/speculation: Mark string arrays const correctly
        - x86/speculataion: Mark command line parser data __initdata
        - x86/speculation: Unify conditional spectre v2 print functions
        - x86/speculation: Add command line control for indirect branch speculation
        - x86/speculation: Prepare for per task indirect branch speculation control
        - x86/process: Consolidate and simplify switch_to_xtra() code
        - x86/speculation: Avoid __switch_to_xtra() calls
        - x86/speculation: Prepare for conditional IBPB in switch_mm()
        - ptrace: Remove unused ptrace_may_access_sched() and MODE_IBRS
        - x86/speculation: Split out TIF update
        - x86/speculation: Prevent stale SPEC_CTRL msr content
        - x86/speculation: Prepare arch_smt_update() for PRCTL mode
        - x86/speculation: Add prctl() control for indirect branch speculation
        - x86/speculation: Enable prctl mode for spectre_v2_user
        - x86/speculation: Add seccomp Spectre v2 user space protection mode
        - x86/speculation: Provide IBPB always command line options
        - kvm: svm: Ensure an IBPB on all affected CPUs when freeing a vmcb
        - x86/speculation: Change misspelled STIPB to STIBP
        - x86/speculation: Add support for STIBP always-on preferred mode
        - x86, modpost: Replace last remnants of RETPOLINE with CONFIG_RETPOLINE
      * [Ubuntu] vfio-ap: add subsystem to matrix device to avoid libudev failures
        (LP: #1818854)
        - s390: vfio_ap: link the vfio_ap devices to the vfio_ap bus subsystem
      * Kernel regularly logs: Bluetooth: hci0: last event is not cmd complete
        (0x0f) (LP: #1748565)
        - Bluetooth: Fix unnecessary error message for HCI request completion
      * HiSilicon HNS ethernet broken in 4.15.0-45 (LP: #1818294)
        - net: hns: Fix WARNING when hns modules installed
      * Lenovo ideapad 330-15ICH Wifi rfkill hard blocked (LP: #1811815)
        - platform/x86: ideapad: Add ideapad 330-15ICH to no_hw_rfkill
      * Qualcomm Atheros QCA9377 wireless does not work (LP: #1818204)
        - platform/x86: ideapad-laptop: Add Ideapad 530S-14ARR to no_hw_rfkill list
      * fscache: jobs might hang when fscache disk is full (LP: #1821395)
        - fscache: fix race between enablement and dropping of object
      * hns3: fix oops in hns3_clean_rx_ring() (LP: #1821064)
        - net: hns3: add dma_rmb() for rx description
      * tcm_loop.ko: move from modules-extra into main modules package
        (LP: #1817786)
        - [Packaging] move tcm_loop.lo to main linux-modules package
      * tcmu user space crash results in kernel module hang. (LP: #1819504)
        - scsi: tcmu: delete unused __wait
        - scsi: tcmu: track nl commands
        - scsi: tcmu: simplify nl interface
        - scsi: tcmu: add module wide block/reset_netlink support
      * Intel XL710 - i40e driver does not work with kernel 4.15 (Ubuntu 18.04)
        (LP: #1779756)
        - i40e: prevent overlapping tx_timeout recover
      * some codecs stop working after S3 (LP: #1820930)
        - ALSA: hda - Enforces runtime_resume after S3 and S4 for each codec
      * 4.15 s390x kernel BUG at /build/linux-
        Gycr4Z/linux-4.15.0/drivers/block/virtio_blk.c:565! (LP: #1788432)
        - virtio/s390: avoid race on vcdev->config
        - virtio/s390: fix race in ccw_io_helper()
      * [SRU][B/B-OEM/C/D] Fix AMD IOMMU NULL dereference (LP: #1820990)
        - iommu/amd: Fix NULL dereference bug in match_hid_uid
      * New Intel Wireless-AC 9260 [8086:2526] card not correctly probed in Ubuntu
        system (LP: #1821271)
        - iwlwifi: add new card for 9260 series
      * Add support for MAC address pass through on RTL8153-BD (LP: #1821276)
        - r8152: Add support for MAC address pass through on RTL8153-BD
        - r8152: Fix an error on RTL8153-BD MAC Address Passthrough support
    
     -- Khalid Elmously <email address hidden>  Wed, 03 Apr 2019 02:38:50 -0400
  • linux-gcp (4.18.0-1008.9) cosmic; urgency=medium
    
      * linux-gcp: 4.18.0-1008.9 -proposed tracker (LP: #1819620)
    
      * [Packaging] Improve config annotations check on custom kernels
        (LP: #1820075)
        - [Config] linux-gcp: Replace annotations symlink with overlay
        - [Config] linux-gcp: Include master annotations to linux-gcp annotations
        - [Config] linux-gcp: Update annotations file
    
      * tcm_loop.ko: move from modules-extra into main modules-gcp package
        (LP: #1817786)
        - [Packaging] move tcm_loop.lo to main linux-modules-gcp package
    
      [ Ubuntu: 4.18.0-17.18 ]
    
      * linux: 4.18.0-17.18 -proposed tracker (LP: #1819624)
      * Packaging resync (LP: #1786013)
        - [Packaging] resync getabis
        - [Packaging] update helper scripts
      * C++ demangling support missing from perf (LP: #1396654)
        - [Packaging] fix a mistype
      * arm-smmu-v3 arm-smmu-v3.3.auto: CMD_SYNC timeout (LP: #1818162)
        - iommu/arm-smmu-v3: Fix unexpected CMD_SYNC timeout
      * Crash in nvme_irq_check() when using threaded interrupts (LP: #1818747)
        - nvme-pci: fix out of bounds access in nvme_cqe_pending
      * CVE-2019-9003
        - ipmi: fix use-after-free of user->release_barrier.rda
      * CVE-2019-9162
        - netfilter: nf_nat_snmp_basic: add missing length checks in ASN.1 cbs
      * CVE-2019-9213
        - mm: enforce min addr even if capable() in expand_downwards()
      * CVE-2019-3460
        - Bluetooth: Check L2CAP option sizes returned from l2cap_get_conf_opt
      * tun/tap: unable to manage carrier state from userland (LP: #1806392)
        - tun: implement carrier change
      * CVE-2019-8980
        - exec: Fix mem leak in kernel_read_file
      * [Packaging] Allow overlay of config annotations (LP: #1752072)
        - [Packaging] config-check: Add an include directive
      * amdgpu with mst WARNING on blanking (LP: #1814308)
        - drm/amd/display: Fix MST dp_blank REG_WAIT timeout
      * CVE-2019-7308
        - bpf: move {prev_,}insn_idx into verifier env
        - bpf: move tmp variable into ax register in interpreter
        - bpf: enable access to ax register also from verifier rewrite
        - bpf: restrict map value pointer arithmetic for unprivileged
        - bpf: restrict stack pointer arithmetic for unprivileged
        - bpf: restrict unknown scalars of mixed signed bounds for unprivileged
        - bpf: fix check_map_access smin_value test when pointer contains offset
        - bpf: prevent out of bounds speculation on pointer arithmetic
        - bpf: fix sanitation of alu op with pointer / scalar type from different
          paths
        - bpf: add various test cases to test_verifier
        - bpf: add various test cases to selftests
      * CVE-2017-5753
        - bpf: fix inner map masking to prevent oob under speculation
      * Use memblock quirk instead of delayed allocation for GICv3 LPI tables
        (LP: #1816425)
        - efi/arm: Revert "Defer persistent reservations until after paging_init()"
        - arm64, mm, efi: Account for GICv3 LPI tables in static memblock reserve
          table
      * efi/arm/arm64: Allow SetVirtualAddressMap() to be omitted (LP: #1814982)
        - efi/arm/arm64: Allow SetVirtualAddressMap() to be omitted
      * Update ENA driver to version 2.0.3K (LP: #1816806)
        - net: ena: update driver version from 2.0.2 to 2.0.3
        - net: ena: fix race between link up and device initalization
        - net: ena: fix crash during failed resume from hibernation
      * Silent "Unknown key" message when pressing keyboard backlight hotkey
        (LP: #1817063)
        - platform/x86: dell-wmi: Ignore new keyboard backlight change event
      * CVE-2018-19824
        - ALSA: usb-audio: Fix UAF decrement if card has no live interfaces in card.c
      * CVE-2019-3459
        - Bluetooth: Verify that l2cap_get_conf_opt provides large enough buffer
      * CONFIG_TEST_BPF is disabled (LP: #1813955)
        - [Config]: Reenable TEST_BPF
      * installer does not support iSCSI iBFT (LP: #1817321)
        - d-i: add iscsi_ibft to scsi-modules
      * CVE-2019-7222
        - KVM: x86: work around leak of uninitialized stack contents (CVE-2019-7222)
      * CVE-2019-7221
        - KVM: nVMX: unconditionally cancel preemption timer in free_nested
          (CVE-2019-7221)
      * CVE-2019-6974
        - kvm: fix kvm_ioctl_create_device() reference counting (CVE-2019-6974)
      * hns3 nic speed may not match optical port speed (LP: #1817969)
        - net: hns3: Config NIC port speed same as that of optical module
      * [Hyper-V] srcu: Lock srcu_data structure in srcu_gp_start() (LP: #1802021)
        - srcu: Lock srcu_data structure in srcu_gp_start()
      * libsas disks can have non-unique by-path names (LP: #1817784)
        - scsi: libsas: Fix rphy phy_identifier for PHYs with end devices attached
      * Bluetooth not working (Intel CyclonePeak) (LP: #1817518)
        - Bluetooth: btusb: Add support for Intel bluetooth device 8087:0029
      * CVE-2019-8912
        - net: crypto set sk to NULL when af_alg_release.
        - net: socket: set sock->sk to NULL after calling proto_ops::release()
      * 4.18.0 thinkpad_acpi : thresholds for BAT1 not writable (LP: #1812099)
        - platform/x86: thinkpad_acpi: Fix multi-battery bug
      * [ALSA] [PATCH] System76 darp5 and oryp5 fixups (LP: #1815831)
        - ALSA: hda/realtek - Headset microphone support for System76 darp5
        - ALSA: hda/realtek - Headset microphone and internal speaker support for
          System76 oryp5
      * CVE-2019-8956
        - sctp: walk the list of asoc safely
      * Constant noise in the headphone on Lenovo X1 machines (LP: #1817263)
        - ALSA: hda/realtek: Disable PC beep in passthrough on alc285
    
     -- Kleber Sacilotto de Souza <email address hidden>  Thu, 14 Mar 2019 17:05:02 +0100
  • linux-gcp (4.18.0-1007.8) cosmic; urgency=medium
    
      * linux-gcp: 4.18.0-1007.8 -proposed tracker (LP: #1814759)
    
      * bluetooth controller not detected with 4.15 kernel (LP: #1810797)
        - [Config] Disable BT_QCOMSMD_HACK
    
      [ Ubuntu: 4.18.0-16.17 ]
    
      * linux: 4.18.0-16.17 -proposed tracker (LP: #1814749)
      * Packaging resync (LP: #1786013)
        - [Packaging] update helper scripts
      * CVE-2018-16880
        - vhost: fix OOB in get_rx_bufs()
      * RTL8822BE WiFi Disabled in Kernel 4.18.0-12 (LP: #1806472)
        - SAUCE: staging: rtlwifi: allow RTLWIFI_DEBUG_ST to be disabled
        - [Config] CONFIG_RTLWIFI_DEBUG_ST=n
        - SAUCE: Add r8822be to signature inclusion list
      * kernel oops in bcache module (LP: #1793901)
        - SAUCE: bcache: never writeback a discard operation
      * CVE-2018-18397
        - userfaultfd: use ENOENT instead of EFAULT if the atomic copy user fails
        - userfaultfd: shmem: allocate anonymous memory for MAP_PRIVATE shmem
        - userfaultfd: shmem/hugetlbfs: only allow to register VM_MAYWRITE vmas
        - userfaultfd: shmem: add i_size checks
        - userfaultfd: shmem: UFFDIO_COPY: set the page dirty if VM_WRITE is not set
      * Ignore "incomplete report" from Elan touchpanels (LP: #1813733)
        - HID: i2c-hid: Ignore input report if there's no data present on Elan
          touchpanels
      * Vsock connect fails with ENODEV for large CID (LP: #1813934)
        - vhost/vsock: fix vhost vsock cid hashing inconsistent
      * Fix non-working pinctrl-intel (LP: #1811777)
        - pinctrl: intel: Do pin translation in other GPIO operations as well
      * ip6_gre: fix tunnel list corruption for x-netns (LP: #1812875)
        - ip6_gre: fix tunnel list corruption for x-netns
      * Backported commit breaks audio (fixed upstream) (LP: #1811566)
        - ASoC: intel: cht_bsw_max98090_ti: Add quirk for boards using pmc_plt_clk_0
        - ASoC: intel: cht_bsw_max98090_ti: Add pmc_plt_clk_0 quirk for Chromebook
          Clapper
        - ASoC: intel: cht_bsw_max98090_ti: Add pmc_plt_clk_0 quirk for Chromebook
          Gnawty
      * kvm_stat : missing python dependency (LP: #1798776)
        - tools/kvm_stat: switch to python3
      * [SRU] Fix Xorg crash with nomodeset when BIOS enable 64-bit fb addr
        (LP: #1812797)
        - vgaarb: Add support for 64-bit frame buffer address
        - vgaarb: Keep adding VGA device in queue
      * Fix non-working QCA Rome Bluetooth after S3 (LP: #1812812)
        - USB: Add new USB LPM helpers
        - USB: Consolidate LPM checks to avoid enabling LPM twice
      * [SRU] IO's are issued with incorrect Scatter Gather Buffer (LP: #1795453)
        - scsi: megaraid_sas: Use 63-bit DMA addressing
      * x86/mm: Found insecure W+X mapping at address (ptrval)/0xc00a0000
        (LP: #1813532)
        - x86/mm: Do not warn about PCI BIOS W+X mappings
      * CVE-2019-6133
        - fork: record start_time late
      * Fix not working Goodix touchpad (LP: #1811929)
        - HID: i2c-hid: Disable runtime PM on Goodix touchpad
      * bluetooth controller not detected with 4.15 kernel (LP: #1810797)
        - SAUCE: btqcomsmd: introduce BT_QCOMSMD_HACK
        - [Config] arm64: snapdragon: BT_QCOMSMD_HACK=y
      * X1 Extreme: only one of the two SSDs is loaded (LP: #1811755)
        - nvme-core: rework a NQN copying operation
        - nvme: pad fake subsys NQN vid and ssvid with zeros
        - nvme: introduce NVME_QUIRK_IGNORE_DEV_SUBNQN
      * Crash on "ip link add foo type ipip" (LP: #1811803)
        - SAUCE: fan: Fix NULL pointer dereference
    
      [ Ubuntu: 4.18.0-15.16 ]
    
      * Ubuntu boot failure. 4.18.0-14 boot stalls. (does not boot) (LP: #1814555)
        - Revert "drm/i915/ringbuffer: Delay after EMIT_INVALIDATE for gen4/gen5"
      * Userspace break as a result of missing patch backport (LP: #1813873)
        - tty: Don't hold ldisc lock in tty_reopen() if ldisc present
    
     -- Khalid Elmously <email address hidden>  Tue, 12 Feb 2019 01:13:50 +0000
  • linux-gcp (4.18.0-1006.7) cosmic; urgency=medium
    
      * linux-gcp: 4.18.0-1006.7 -proposed tracker (LP: #1811416)
    
      * Add support for ALC3277 codec on new Dell edge gateways (LP: #1807334) //
        Cosmic update: 4.18.19 upstream stable release (LP: #1810820)
        - [Config] Update config after 4.18.0-14.15 rebase
    
      * Packaging resync (LP: #1786013)
        - [Packaging] update helper scripts
    
      [ Ubuntu: 4.18.0-14.15 ]
    
      * linux: 4.18.0-14.15 -proposed tracker (LP: #1811406)
      * CPU hard lockup with rigorous writes to NVMe drive (LP: #1810998)
        - blk-wbt: Avoid lock contention and thundering herd issue in wbt_wait
        - blk-wbt: move disable check into get_limit()
        - blk-wbt: use wq_has_sleeper() for wq active check
        - blk-wbt: fix has-sleeper queueing check
        - blk-wbt: abstract out end IO completion handler
        - blk-wbt: improve waking of tasks
      * To reduce the Realtek USB cardreader power consumption (LP: #1811337)
        - mmc: core: Introduce MMC_CAP_SYNC_RUNTIME_PM
        - mmc: rtsx_usb_sdmmc: Don't runtime resume the device while changing led
        - mmc: rtsx_usb_sdmmc: Re-work runtime PM support
        - mmc: rtsx_usb_sdmmc: Re-work card detection/removal support
        - memstick: rtsx_usb_ms: Add missing pm_runtime_disable() in probe function
        - misc: rtsx_usb: Use USB remote wakeup signaling for card insertion detection
        - memstick: Prevent memstick host from getting runtime suspended during card
          detection
        - memstick: rtsx_usb_ms: Use ms_dev() helper
        - memstick: rtsx_usb_ms: Support runtime power management
      * Support non-strict iommu mode on arm64 (LP: #1806488)
        - iommu/io-pgtable-arm: Fix race handling in split_blk_unmap()
        - iommu/arm-smmu-v3: Implement flush_iotlb_all hook
        - iommu/dma: Add support for non-strict mode
        - iommu: Add "iommu.strict" command line option
        - iommu/io-pgtable-arm: Add support for non-strict mode
        - iommu/arm-smmu-v3: Add support for non-strict mode
        - iommu/io-pgtable-arm-v7s: Add support for non-strict mode
        - iommu/arm-smmu: Support non-strict mode
      * [Regression] crashkernel fails on HiSilicon D05 (LP: #1806766)
        - efi: honour memory reservations passed via a linux specific config table
        - efi/arm: libstub: add a root memreserve config table
        - efi: add API to reserve memory persistently across kexec reboot
        - irqchip/gic-v3-its: Change initialization ordering for LPIs
        - irqchip/gic-v3-its: Simplify LPI_PENDBASE_SZ usage
        - irqchip/gic-v3-its: Split property table clearing from allocation
        - irqchip/gic-v3-its: Move pending table allocation to init time
        - irqchip/gic-v3-its: Keep track of property table's PA and VA
        - irqchip/gic-v3-its: Allow use of pre-programmed LPI tables
        - irqchip/gic-v3-its: Use pre-programmed redistributor tables with kdump
          kernels
        - irqchip/gic-v3-its: Check that all RDs have the same property table
        - irqchip/gic-v3-its: Register LPI tables with EFI config table
        - irqchip/gic-v3-its: Allow use of LPI tables in reserved memory
        - arm64: memblock: don't permit memblock resizing until linear mapping is up
        - efi/arm: Defer persistent reservations until after paging_init()
        - efi: Permit calling efi_mem_reserve_persistent() from atomic context
        - efi: Prevent GICv3 WARN() by mapping the memreserve table before first use
      * ELAN900C:00 04F3:2844 touchscreen doesn't work (LP: #1811335)
        - pinctrl: cannonlake: Fix community ordering for H variant
        - pinctrl: cannonlake: Fix HOSTSW_OWN register offset of H variant
      * Add Cavium ThunderX2 SoC UNCORE PMU driver (LP: #1811200)
        - Documentation: perf: Add documentation for ThunderX2 PMU uncore driver
        - drivers/perf: Add Cavium ThunderX2 SoC UNCORE PMU driver
        - [Config] New config CONFIG_THUNDERX2_PMU=m
      * iptables connlimit allows more connections than the limit when using
        multiple CPUs (LP: #1811094)
        - netfilter: nf_conncount: don't skip eviction when age is negative
      * CVE-2018-16882
        - KVM: Fix UAF in nested posted interrupt processing
      * Cannot initialize ATA disk if IDENTIFY command fails (LP: #1809046)
        - scsi: libsas: check the ata device status by ata_dev_enabled()
      * scsi: libsas: fix a race condition when smp task timeout (LP: #1808912)
        - scsi: libsas: fix a race condition when smp task timeout
      * CVE-2018-14625
        - vhost/vsock: fix use-after-free in network stack callers
      * Fix and issue that LG I2C touchscreen stops working after reboot
        (LP: #1805085)
        - HID: i2c-hid: Disable runtime PM for LG touchscreen
      * Drivers: hv: vmbus: Offload the handling of channels to two workqueues
        (LP: #1807757)
        - Drivers: hv: vmbus: check the creation_status in vmbus_establish_gpadl()
        - Drivers: hv: vmbus: Offload the handling of channels to two workqueues
      * Disable LPM for Raydium Touchscreens (LP: #1802248)
        - USB: quirks: Add no-lpm quirk for Raydium touchscreens
      * Power leakage at S5 with Qualcomm Atheros QCA9377 802.11ac Wireless Network
        Adapter (LP: #1805607)
        - SAUCE: ath10k: provide reset function for QCA9377 chip
      * CVE-2018-19407
        - KVM: X86: Fix scan ioapic use-before-initialization
      * Fix USB2 device wrongly detected as USB1 (LP: #1806534)
        - xhci: Add quirk to workaround the errata seen on Cavium Thunder-X2 Soc
      * Add support for ALC3277 codec on new Dell edge gateways (LP: #1807334)
        - SAUCE: ASoC: rt5660: (no-up) Move platform code to board file
        - ASoC: Intel: kbl_rt5660: Add a new machine driver for kbl with rt5660
        - [Config] CONFIG_SND_SOC_INTEL_KBL_RT5660_MACH=m
      * armhf guests fail to boot in EFI mode (LP: #1809488)
        - efi/arm: Revert deferred unmap of early memmap mapping
      * audio output has constant noise on a Dell machine (LP: #1810891)
        - ALSA: hda/realtek - Fixed headphone issue for ALC700
      * ldisc crash on reopened tty (LP: #1791758)
        - tty: Hold tty_ldisc_lock() during tty_reopen()
        - tty: Don't block on IO when ldisc change is pending
        - tty: Simplify tty->count math in tty_reopen()
      * efi-lockdown patch causes -EPERM for some debugfs files even though
        CONFIG_LOCK_DOWN_KERNEL is not set (LP: #1807686)
        - SAUCE: debugfs: avoid EPERM when no open file operation defined
      * SATA device is not going to DEVSLP (LP: #1781533)
        - ata: ahci: Support state with min power but Partial low power state
        - ata: ahci: Enable DEVSLP by default on x86 with SLP_S0
      * Console got stuck using serial tty after logout (LP: #1808097)
        - tty: do not set TTY_IO_ERROR flag if console port
      * Workaround CSS timeout on AMD SNPS 3.0 xHC (LP: #1806838)
        - xhci: workaround CSS timeout on AMD SNPS 3.0 xHC
      * Add pointstick support for Cirque Touchpad (LP: #1805081)
        - HID: multitouch: Add pointstick support for Cirque Touchpad
      * Update hisilicon SoC-specific drivers (LP: #1810457)
        - SAUCE: Revert "net: hns3: Updates RX packet info fetch in case of multi BD"
        - net: hns3: remove redundant variable 'protocol'
        - scsi: hisi_sas: Drop hisi_sas_slot_abort()
        - net: hns: Make many functions static
        - net: hns: make hns_dsaf_roce_reset non static
        - net: hisilicon: hns: Replace mdelay() with msleep()
        - net: hns3: fix return value error while hclge_cmd_csq_clean failed
        - net: hns: remove redundant variables 'max_frm' and 'tmp_mac_key'
        - net: hns: Mark expected switch fall-through
        - net: hns3: Mark expected switch fall-through
        - net: hns3: Remove tx ring BD len register in hns3_enet
        - net: hns: modify variable type in hns_nic_reuse_page
        - net: hns: use eth_get_headlen interface instead of hns_nic_get_headlen
        - net: hns3: modify variable type in hns3_nic_reuse_page
        - net: hns3: Fix for multicast failure
        - net: hns3: Fix error of checking used vlan id
        - net: hns3: Implement shutdown ops in hns3 pci driver
        - net: hns3: Fix for loopback selftest failed problem
        - net: hns3: Only update mac configuation when necessary
        - net: hns3: Change the dst mac addr of loopback packet
        - net: hns3: Remove redundant codes of query advertised flow control abilitiy
        - net: hns3: Refine hns3_get_link_ksettings()
        - net: hns: make function hns_gmac_wait_fifo_clean() static
        - net: hns3: Add default irq affinity
        - net: hns3: Add unlikely for buf_num check
        - net: hns3: Remove tx budget to clean more TX descriptors in a napi
        - net: hns3: Remove packet statistics of public
        - net: hns3: Add support for hns3_nic_netdev_ops.ndo_do_ioctl
        - net: hns3: Fix for setting speed for phy failed problem
        - net: hns3: Fix cmdq registers initialization issue for vf
        - net: hns3: Clear client pointer when initialize client failed or unintialize
          finished
        - net: hns3: Fix client initialize state issue when roce client initialize
          failed
        - net: hns3: Fix parameter type for q_id in hclge_tm_q_to_qs_map_cfg()
        - net: hns3: Unify the type convert for desc.data
        - net: hns3: Adjust prefix of tx/rx statistic names
        - net: hns3: Fix tqp array traversal condition for vf
        - net: hns3: Unify the prefix of vf functions
        - net: hns3: Add handle for default case
        - net: hns3: Add unlikely for dma_mapping_error check
        - net: hns3: Remove print messages for error packet
        - net: hns3: Add get_media_type ops support for VF
        - net: hns3: Fix speed/duplex information loss problem when executing ethtool
          ethx cmd of VF
        - net: hns3: Remove redundant hclge_get_port_type()
        - net: hns3: Add support for sctp checksum offload
        - net: hns3: Set extra mac address of pause param for HW
        - net: hns3: Rename loop mode
        - net: hns3: Rename mac loopback to app loopback
        - net: hns3: Add serdes parallel inner loopback support
        - net: hns3: Fix for netdev not up problem when setting mtu
        - net: hns3: Change return type of hclge_tm_schd_info_update()
        - net: hns3: Modify hns3_get_max_available_channels
        - net: hns3: Fix loss of coal configuration while doing reset
        - net: hns: remove ndo_poll_controller
        - hns3: Fix the build.
        - hns3: Another build fix.
        - net: hns3: Add flow director initialization
        - net: hns3: Add input key and action config support for flow director
        - net: hns3: Add support for rule add/delete for flow director
        - net: hns3: Add support for rule query of flow director
        - net: hns3: Add reset handle for flow director
        - net: hns3: Remove all flow director rules when unload hns3 driver
        - net: hns3: Add support for enable/disable flow director
        - net: hns3: Remove the default mask configuration for mac vlan table
        - net: hns3: Clear mac vlan table entries when unload driver or function reset
        - net: hns3: Optimize for unicast mac vlan table
        - net: hns3: Drop depricated mta table support
        - net: hns3: Add egress/ingress vlan filter for revision 0x21
        - net: hns3: Fix for rx vlan id handle to support Rev 0x21 hardware
        - net: hns3: Add new RSS hash algorithm support for PF
        - net: hns3: Add RSS general configuration support for VF
        - net: hns3: Add RSS tuples support for VF
        - net: hns3: Add HW RSS hash information to RX skb
        - net: hns3: Enable promisc mode when mac vlan table is full
        - net: hns3: Resume promisc mode and vlan filter status after reset
        - net: hns3: Resume promisc mode and vlan filter status after loopback test
        - scsi: hisi_sas: Feed back linkrate(max/min) when re-attached
        - scsi: hisi_sas: Move evaluation of hisi_hba in hisi_sas_task_prep()
        - scsi: hisi_sas: Fix the race between IO completion and timeout for
          SMP/internal IO
        - scsi: hisi_sas: Free slot later in slot_complete_vx_hw()
        - scsi: hisi_sas: unmask interrupts ent72 and ent74
        - scsi: hisi_sas: Use block layer tag instead for IPTT
        - scsi: hisi_sas: Update v3 hw AIP_LIMIT and CFG_AGING_TIME register values
        - net: hns3: remove hns3_fill_desc_tso
        - net: hns3: move DMA map into hns3_fill_desc
        - net: hns3: add handling for big TX fragment
        - net: hns3: rename hns_nic_dma_unmap
        - net: hns3: fix for multiple unmapping DMA problem
        - scsi: hisi_sas: Fix spin lock management in slot_index_alloc_quirk_v2_hw()
        - scsi: hisi_sas: Fix NULL pointer dereference
        - net: hns3: Add PCIe AER callback error_detected
        - net: hns3: Add PCIe AER error recovery
        - net: hns3: Add support to enable and disable hw errors
        - net: hns3: Add enable and process common ecc errors
        - net: hns3: Add enable and process hw errors from IGU, EGU and NCSI
        - net: hns3: Add enable and process hw errors from PPP
        - net: hns3: Add enable and process hw errors of TM scheduler
        - net: hns3: Fix for warning uninitialized symbol hw_err_lst3
        - net: hns3: fix spelling mistake "intrerrupt" -> "interrupt"
        - net: hns3: add error handler for hns3_nic_init_vector_data()
        - net: hns3: bugfix for buffer not free problem during resetting
        - net: hns3: bugfix for reporting unknown vector0 interrupt repeatly problem
        - net: hns3: bugfix for the initialization of command queue's spin lock
        - net: hns3: remove unnecessary queue reset in the hns3_uninit_all_ring()
        - net: hns3: bugfix for is_valid_csq_clean_head()
        - net: hns3: bugfix for hclge_mdio_write and hclge_mdio_read
        - net: hns3: fix incorrect return value/type of some functions
        - net: hns3: bugfix for handling mailbox while the command queue reinitialized
        - net: hns3: bugfix for rtnl_lock's range in the hclge_reset()
        - net: hns3: bugfix for rtnl_lock's range in the hclgevf_reset()
        - net: hns3: Fix for out-of-bounds access when setting pfc back pressure
        - scsi: hisi_sas: Remove set but not used variable 'dq_list'
        - net: hns3: bugfix for not checking return value
        - net: hns: Incorrect offset address used for some registers.
        - net: hns: All ports can not work when insmod hns ko after rmmod.
        - net: hns: Some registers use wrong address according to the datasheet.
        - net: hns: Fixed bug that netdev was opened twice
        - net: hns: Clean rx fbd when ae stopped.
        - net: hns: Free irq when exit from abnormal branch
        - net: hns: Avoid net reset caused by pause frames storm
        - net: hns: Fix ntuple-filters status error.
        - net: hns: Add mac pcs config when enable|disable mac
        - net: hns: Fix ping failed when use net bridge and send multicast
        - net: hns3: use HNS3_NIC_STATE_INITED to indicate the initialization state of
          enet
        - net: hns3: add set_default_reset_request in the hnae3_ae_ops
        - net: hns3: provide some interface & information for the client
        - net: hns3: adjust the location of clearing the table when doing reset
        - net: hns3: enable/disable ring in the enet while doing UP/DOWN
        - net: hns3: use HNS3_NIC_STATE_RESETTING to indicate resetting
        - net: hns3: ignore new coming low-level reset while doing high-level reset
        - net: hns3: move some reset information from hnae3_handle into
          hclge_dev/hclgevf_dev
        - net: hns3: adjust the process of PF reset
        - net: hns3: call roce's reset notify callback when resetting
        - net: hns3: add error handler for hclge_reset()
        - net: hns3: fix for cmd queue memory not freed problem during reset
        - net: hns3: Remove set but not used variable 'reset_level'
        - net: hns3: fix spelling mistake, "assertting" -> "asserting"
        - net: hns3: add reset_hdev to reinit the hdev in VF's reset process
        - net: hns3: adjust VF's reset process
        - net: hns3: add reset handling for VF when doing PF reset
        - net: hns3: add reset handling for VF when doing Core/Global/IMP reset
        - net: hns3: stop handling command queue while resetting VF
        - net: hns3: add error handler for hclgevf_reset()
        - net: hns3: stop napi polling when HNS3_NIC_STATE_DOWN is set
        - net: hns3: implement the IMP reset processing for PF
        - net: hns3: add PCIe FLR support for PF
        - net: hns3: do VF's pci re-initialization while PF doing FLR
        - net: hns3: add PCIe FLR support for VF
        - net: hns3: Enable HW GRO for Rev B(=0x21) HNS3 hardware
        - net: hns3: Add handling of GRO Pkts not fully RX'ed in NAPI poll
        - net: hns3: Add support for ethtool -K to enable/disable HW GRO
        - net: hns3: Add skb chain when num of RX buf exceeds MAX_SKB_FRAGS
        - net: hns3: Adds GRO params to SKB for the stack
        - scsi: hisi_sas: use dma_set_mask_and_coherent
        - scsi: hisi_sas: Create separate host attributes per HBA
        - scsi: hisi_sas: Add support for interrupt converge for v3 hw
        - scsi: hisi_sas: Add support for interrupt coalescing for v3 hw
        - scsi: hisi_sas: Relocate some codes to avoid an unused check
        - scsi: hisi_sas: change the time of SAS SSP connection
        - net: hns3: fix spelling mistake "failded" -> "failed"
        - net: hns3: Support two vlan header when setting mtu
        - net: hns3: Refactor mac mtu setting related functions
        - net: hns3: Add vport alive state checking support
        - net: hns3: Add mtu setting support for vf
        - net: hns3: up/down netdev in hclge module when setting mtu
        - net: hns3: add common validation in hclge_dcb
        - net: hns3: Add debugfs framework registration
        - net: hns3: Add "queue info" query function
        - net: hns3: Add "FD flow table" info query function
        - net: hns3: Add "tc config" info query function
        - net: hns3: Add "tm config" info query function
        - net: hns3: Add "qos pause" config info query function
        - net: hns3: Add "qos prio map" info query function
        - net: hns3: Add "qos buffer" config info query function
        - net: hns3: Support "ethtool -d" for HNS3 VF driver
        - net: hns3: Adds support to dump(using ethool-d) PCIe regs in HNS3 PF driver
        - net: hns3: remove existing process error functions and reorder hw_blk table
        - net: hns3: rename enable error interrupt functions
        - net: hns3: re-enable error interrupts on hw reset
        - net: hns3: deletes unnecessary settings of the descriptor data
        - net: hns3: rename process_hw_error function
        - net: hns3: add optimization in the hclge_hw_error_set_state
        - net: hns3: add handling of hw ras errors using new set of commands
        - net: hns3: deleted logging 1 bit errors
        - net: hns3: add handling of hw errors reported through MSIX
        - net: hns3: add handling of hw errors of MAC
        - net: hns3: handle hw errors of PPP PF
        - net: hns3: handle hw errors of PPU(RCB)
        - net: hns3: handle hw errors of SSU
        - net: hns3: add handling of RDMA RAS errors
        - net: hns3: fix spelling mistake "offser" -> "offset"
        - scsi: hisi_sas: Fix warnings detected by sparse
        - scsi: hisi_sas: Relocate some code to reduce complexity
        - scsi: hisi_sas: Make sg_tablesize consistent value
        - hns3: prevent building without CONFIG_INET
        - net: hns3: Add "bd info" query function
        - net: hns3: Add "manager table" information query function
        - net: hns3: Add "status register" information query function
        - net: hns3: Add "dcb register" status information query function
        - net: hns3: Add "queue map" information query function
        - net: hns3: Add "tm map" status information query function
        - net: hns3: fix error handling int the hns3_get_vector_ring_chain
        - net: hns3: uninitialize pci in the hclgevf_uninit
        - net: hns3: fix napi_disable not return problem
        - net: hns3: update some variables while hclge_reset()/hclgevf_reset() done
        - net: hns3: remove unnecessary configuration recapture while resetting
        - net: hns3: fix incomplete uninitialization of IRQ in the
          hns3_nic_uninit_vector_data()
        - net: hns3: update coalesce param per second
        - net: hns3: remove 1000M/half support of phy
        - net: hns3: synchronize speed and duplex from phy when phy link up
        - net: hns3: getting tx and dv buffer size through firmware
        - net: hns3: aligning buffer size in SSU to 256 bytes
        - net: hns3: fix a SSU buffer checking bug
        - scsi: hisi_sas: Add support for DIF feature for v2 hw
        - net: hns3: refine the handle for hns3_nic_net_open/stop()
        - net: hns3: change default tc state to close
        - net: hns3: fix a bug caused by udelay
        - net: hns3: add max vector number check for pf
        - net: hns3: reset tqp while doing DOWN operation
        - net: hns3: fix vf id check issue when add flow director rule
        - net: hns3: don't restore rules when flow director is disabled
        - net: hns3: fix the descriptor index when get rss type
        - net: hns3: remove redundant variable initialization
        - net: hns3: call hns3_nic_net_open() while doing HNAE3_UP_CLIENT
      * Cosmic update: 4.18.20 upstream stable release (LP: #1810821)
        - powerpc/traps: restore recoverability of machine_check interrupts
        - powerpc/64/module: REL32 relocation range check
        - powerpc/mm: Fix page table dump to work on Radix
        - powerpc/mm: fix always true/false warning in slice.c
        - drm/amd/display: fix bug of accessing invalid memory
        - Input: wm97xx-ts - fix exit path
        - powerpc/Makefile: Fix PPC_BOOK3S_64 ASFLAGS
        - powerpc/eeh: Fix possible null deref in eeh_dump_dev_log()
        - tty: check name length in tty_find_polling_driver()
        - tracing/kprobes: Check the probe on unloaded module correctly
        - drm/amdgpu/powerplay: fix missing break in switch statements
        - ARM: imx_v6_v7_defconfig: Select CONFIG_TMPFS_POSIX_ACL
        - powerpc/nohash: fix undefined behaviour when testing page size support
        - powerpc/mm: Don't report hugepage tables as memory leaks when using kmemleak
        - drm/omap: fix memory barrier bug in DMM driver
        - drm/amd/display: fix gamma not being applied
        - drm/hisilicon: hibmc: Do not carry error code in HiBMC framebuffer pointer
        - media: pci: cx23885: handle adding to list failure
        - media: coda: don't overwrite h.264 profile_idc on decoder instance
        - MIPS: kexec: Mark CPU offline before disabling local IRQ
        - powerpc/boot: Ensure _zimage_start is a weak symbol
        - powerpc/memtrace: Remove memory in chunks
        - MIPS/PCI: Call pcie_bus_configure_settings() to set MPS/MRRS
        - sc16is7xx: Fix for multi-channel stall
        - media: tvp5150: fix width alignment during set_selection()
        - powerpc/selftests: Wait all threads to join
        - staging:iio:ad7606: fix voltage scales
        - drm: rcar-du: Update Gen3 output limitations
        - drm/amdgpu: Fix SDMA TO after GPU reset v3
        - staging: most: video: fix registration of an empty comp core_component
        - 9p locks: fix glock.client_id leak in do_lock
        - udf: Prevent write-unsupported filesystem to be remounted read-write
        - ARM: dts: imx6ull: keep IMX6UL_ prefix for signals on both i.MX6UL and
          i.MX6ULL
        - 9p: clear dangling pointers in p9stat_free
        - ovl: fix error handling in ovl_verify_set_fh()
        - ovl: check whiteout in ovl_create_over_whiteout()
        - serial: sh-sci: Fix could not remove dev_attr_rx_fifo_timeout
        - scsi: qla2xxx: Fix incorrect port speed being set for FC adapters
        - scsi: qla2xxx: Fix process response queue for ISP26XX and above
        - scsi: qla2xxx: Remove stale debug trace message from tcm_qla2xxx
        - scsi: qla2xxx: shutdown chip if reset fail
        - scsi: qla2xxx: Fix duplicate switch database entries
        - scsi: qla2xxx: Fix driver hang when FC-NVMe LUNs are configured
        - fuse: Fix use-after-free in fuse_dev_do_read()
        - fuse: Fix use-after-free in fuse_dev_do_write()
        - fuse: fix blocked_waitq wakeup
        - fuse: set FR_SENT while locked
        - ovl: fix recursive oi->lock in ovl_link()
        - scsi: qla2xxx: Fix re-using LoopID when handle is in use
        - scsi: qla2xxx: Fix NVMe session hang on unload
        - arm64: dts: stratix10: Support Ethernet Jumbo frame
        - arm64: dts: stratix10: fix multicast filtering
        - clk: meson-gxbb: set fclk_div3 as CLK_IS_CRITICAL
        - clk: meson: axg: mark fdiv2 and fdiv3 as critical
        - zram: close udev startup race condition as default groups
        - MIPS: Loongson-3: Fix CPU UART irq delivery problem
        - MIPS: Loongson-3: Fix BRIDGE irq delivery problem
        - xtensa: add NOTES section to the linker script
        - xtensa: make sure bFLT stack is 16 byte aligned
        - xtensa: fix boot parameters address translation
        - um: Drop own definition of PTRACE_SYSEMU/_SINGLESTEP
        - clk: s2mps11: Fix matching when built as module and DT node contains
          compatible
        - clk: at91: Fix division by zero in PLL recalc_rate()
        - clk: sunxi-ng: h6: fix bus clocks' divider position
        - clk: rockchip: fix wrong mmc sample phase shift for rk3328
        - clk: rockchip: Fix static checker warning in rockchip_ddrclk_get_parent call
        - libceph: bump CEPH_MSG_MAX_DATA_LEN
        - Revert "ceph: fix dentry leak in splice_dentry()"
        - thermal: core: Fix use-after-free in thermal_cooling_device_destroy_sysfs
        - mach64: fix display corruption on big endian machines
        - mach64: fix image corruption due to reading accelerator registers
        - acpi/nfit, x86/mce: Handle only uncorrectable machine checks
        - acpi/nfit, x86/mce: Validate a MCE's address before using it
        - acpi, nfit: Fix ARS overflow continuation
        - reset: hisilicon: fix potential NULL pointer dereference
        - vhost/scsi: truncate T10 PI iov_iter to prot_bytes
        - scsi: qla2xxx: Initialize port speed to avoid setting lower speed
        - SCSI: fix queue cleanup race before queue initialization is done
        - Revert "powerpc/8xx: Use L1 entry APG to handle _PAGE_ACCESSED for
          CONFIG_SWAP"
        - soc: ti: QMSS: Fix usage of irq_set_affinity_hint
        - ocfs2: fix a misuse a of brelse after failing ocfs2_check_dir_entry
        - ocfs2: free up write context when direct IO failed
        - mm: thp: relax __GFP_THISNODE for MADV_HUGEPAGE mappings
        - memory_hotplug: cond_resched in __remove_pages
        - netfilter: conntrack: fix calculation of next bucket number in early_drop
        - ARM: 8809/1: proc-v7: fix Thumb annotation of cpu_v7_hvc_switch_mm
        - bonding/802.3ad: fix link_failure_count tracking
        - mtd: spi-nor: cadence-quadspi: Return error code in
          cqspi_direct_read_execute()
        - mtd: nand: Fix nanddev_neraseblocks()
        - mtd: docg3: don't set conflicting BCH_CONST_PARAMS option
        - hwmon: (core) Fix double-free in __hwmon_device_register()
        - perf stat: Handle different PMU names with common prefix
        - of, numa: Validate some distance map rules
        - x86/cpu/vmware: Do not trace vmware_sched_clock()
        - x86/hyper-v: Enable PIT shutdown quirk
        - termios, tty/tty_baudrate.c: fix buffer overrun
        - arch/alpha, termios: implement BOTHER, IBSHIFT and termios2
        - watchdog/core: Add missing prototypes for weak functions
        - btrfs: fix pinned underflow after transaction aborted
        - Btrfs: fix cur_offset in the error case for nocow
        - Btrfs: fix infinite loop on inode eviction after deduplication of eof block
        - Btrfs: fix data corruption due to cloning of eof block
        - clockevents/drivers/i8253: Add support for PIT shutdown quirk
        - ext4: add missing brelse() update_backups()'s error path
        - ext4: add missing brelse() in set_flexbg_block_bitmap()'s error path
        - ext4: add missing brelse() add_new_gdb_meta_bg()'s error path
        - ext4: avoid potential extra brelse in setup_new_flex_group_blocks()
        - ext4: missing !bh check in ext4_xattr_inode_write()
        - ext4: fix possible inode leak in the retry loop of ext4_resize_fs()
        - ext4: avoid buffer leak on shutdown in ext4_mark_iloc_dirty()
        - ext4: avoid buffer leak in ext4_orphan_add() after prior errors
        - ext4: fix missing cleanup if ext4_alloc_flex_bg_array() fails while resizing
        - ext4: avoid possible double brelse() in add_new_gdb() on error path
        - ext4: fix possible leak of sbi->s_group_desc_leak in error path
        - ext4: fix possible leak of s_journal_flag_rwsem in error path
        - ext4: fix buffer leak in ext4_xattr_get_block() on error path
        - ext4: release bs.bh before re-using in ext4_xattr_block_find()
        - ext4: fix buffer leak in ext4_xattr_move_to_block() on error path
        - ext4: fix buffer leak in ext4_expand_extra_isize_ea() on error path
        - ext4: fix buffer leak in __ext4_read_dirblock() on error path
        - mount: Prevent MNT_DETACH from disconnecting locked mounts
        - mnt: fix __detach_mounts infinite loop
        - kdb: use correct pointer when 'btc' calls 'btt'
        - kdb: print real address of pointers instead of hashed addresses
        - sunrpc: correct the computation for page_ptr when truncating
        - NFSv4: Don't exit the state manager without clearing
          NFS4CLNT_MANAGER_RUNNING
        - nfsd: COPY and CLONE operations require the saved filehandle to be set
        - rtc: hctosys: Add missing range error reporting
        - fuse: fix use-after-free in fuse_direct_IO()
        - fuse: fix leaked notify reply
        - selinux: check length properly in SCTP bind hook
        - configfs: replace strncpy with memcpy
        - gfs2: Put bitmap buffers in put_super
        - gfs2: Fix metadata read-ahead during truncate (2)
        - libata: blacklist SAMSUNG MZ7TD256HAFV-000L9 SSD
        - crypto: user - fix leaking uninitialized memory to userspace
        - lib/ubsan.c: don't mark __ubsan_handle_builtin_unreachable as noreturn
        - hugetlbfs: fix kernel BUG at fs/hugetlbfs/inode.c:444!
        - mm/swapfile.c: use kvzalloc for swap_info_struct allocation
        - efi/arm/libstub: Pack FDT after populating it
        - drm/rockchip: Allow driver to be shutdown on reboot/kexec
        - drm/msm: fix OF child-node lookup
        - drm/amdgpu: Fix typo in amdgpu_vmid_mgr_init
        - drm/amdgpu: add missing CHIP_HAINAN in amdgpu_ucode_get_load_type
        - drm/nouveau: Check backlight IDs are >= 0, not > 0
        - drm/nouveau: Fix nv50_mstc->best_encoder()
        - drm/amd/powerplay: Enable/Disable NBPSTATE on On/OFF of UVD
        - drm/etnaviv: fix bogus fence complete check in timeout handler
        - drm/dp_mst: Check if primary mstb is null
        - drm: panel-orientation-quirks: Add quirk for Acer One 10 (S1003)
        - drm/i915/dp: Link train Fallback on eDP only if fallback link BW can fit
          panel's native mode
        - drm/i915: Restore vblank interrupts earlier
        - drm/i915: Don't unset intel_connector->mst_port
        - drm/i915: Skip vcpi allocation for MSTB ports that are gone
        - drm/i915: Large page offsets for pread/pwrite
        - drm/i915/dp: Fix link retraining comment in intel_dp_long_pulse()
        - drm/i915/dp: Restrict link retrain workaround to external monitors
        - drm/i915/hdmi: Add HDMI 2.0 audio clock recovery N values
        - drm/i915: Fix error handling for the NV12 fb dimensions check
        - drm/i915: Fix ilk+ watermarks when disabling pipes
        - drm/i915: Compare user's 64b GTT offset even on 32b
        - drm/i915: Don't oops during modeset shutdown after lpe audio deinit
        - drm/i915: Mark pin flags as u64
        - drm/i915/ringbuffer: Delay after EMIT_INVALIDATE for gen4/gen5
        - drm/i915/execlists: Force write serialisation into context image vs
          execution
        - drm/i915: Fix possible race in intel_dp_add_mst_connector()
        - CONFIG_XEN_PV breaks xen_create_contiguous_region on ARM
        - Linux 4.18.20
      * Cosmic update: 4.18.19 upstream stable release (LP: #1810820)
        - mtd: rawnand: marvell: fix the IRQ handler complete() condition
        - mtd: spi-nor: fsl-quadspi: fix read error for flash size larger than 16MB
        - mtd: spi-nor: intel-spi: Add support for Intel Ice Lake SPI serial flash
        - mtd: spi-nor: fsl-quadspi: Don't let -EINVAL on the bus
        - spi: spi-mem: Adjust op len based on message/transfer size limitations
        - spi: bcm-qspi: switch back to reading flash using smaller chunks
        - spi: bcm-qspi: fix calculation of address length
        - bcache: trace missed reading by cache_missed
        - bcache: correct dirty data statistics
        - bcache: fix miss key refill->end in writeback
        - hwmon: (pmbus) Fix page count auto-detection.
        - jffs2: free jffs2_sb_info through jffs2_kill_sb()
        - block: setup bounce bio_sets properly
        - block: don't deal with discard limit in blkdev_issue_discard()
        - block: make sure discard bio is aligned with logical block size
        - block: make sure writesame bio is aligned with logical block size
        - cpufreq: conservative: Take limits changes into account properly
        - dma-mapping: fix panic caused by passing empty cma command line argument
        - pcmcia: Implement CLKRUN protocol disabling for Ricoh bridges
        - ACPI / OSL: Use 'jiffies' as the time bassis for acpi_os_get_timer()
        - ACPICA: AML Parser: fix parse loop to correctly skip erroneous extended
          opcodes
        - kprobes/x86: Use preempt_enable() in optimized_callback()
        - mailbox: PCC: handle parse error
        - acpi, nfit: Fix Address Range Scrub completion tracking
        - parisc: Fix address in HPMC IVA
        - parisc: Fix map_pages() to not overwrite existing pte entries
        - parisc: Fix exported address of os_hpmc handler
        - ALSA: hda - Add quirk for ASUS G751 laptop
        - ALSA: hda - Fix headphone pin config for ASUS G751
        - ALSA: hda - Add mic quirk for the Lenovo G50-30 (17aa:3905)
        - ALSA: hda: Add 2 more models to the power_save blacklist
        - ALSA: ca0106: Disable IZD on SB0570 DAC to fix audio pops
        - x86/speculation: Enable cross-hyperthread spectre v2 STIBP mitigation
        - x86/xen: Fix boot loader version reported for PVH guests
        - x86/corruption-check: Fix panic in memory_corruption_check() when boot
          option without value is provided
        - x86/mm/pat: Disable preemption around __flush_tlb_all()
        - ARM: dts: exynos: Disable pull control for MAX8997 interrupts on Origen
        - drm: fix use of freed memory in drm_mode_setcrtc
        - bpf: do not blindly change rlimit in reuseport net selftest
        - nvme: remove ns sibling before clearing path
        - Revert "perf tools: Fix PMU term format max value calculation"
        - selftests: usbip: add wait after attach and before checking port status
        - xsk: do not call synchronize_net() under RCU read lock
        - xfrm: policy: use hlist rcu variants on insert
        - perf vendor events intel: Fix wrong filter_band* values for uncore events
        - nfp: flower: fix pedit set actions for multiple partial masks
        - nfp: flower: use offsets provided by pedit instead of index for ipv6
        - sched/fair: Fix the min_vruntime update logic in dequeue_entity()
        - perf evsel: Store ids for events with their own cpus
          perf_event__synthesize_event_update_cpus
        - perf tools: Fix use of alternatives to find JDIR
        - perf cpu_map: Align cpu map synthesized events properly.
        - perf report: Don't crash on invalid inline debug information
        - x86/fpu: Remove second definition of fpu in __fpu__restore_sig()
        - net: qla3xxx: Remove overflowing shift statement
        - drm: Get ref on CRTC commit object when waiting for flip_done
        - selftests: ftrace: Add synthetic event syntax testcase
        - i2c: rcar: cleanup DMA for all kinds of failure
        - net: socionext: Reset tx queue in ndo_stop
        - locking/lockdep: Fix debug_locks off performance problem
        - netfilter: xt_nat: fix DNAT target for shifted portmap ranges
        - ataflop: fix error handling during setup
        - swim: fix cleanup on setup error
        - arm64: cpufeature: ctr: Fix cpu capability check for late CPUs
        - nfp: devlink port split support for 1x100G CXP NIC
        - tun: Consistently configure generic netdev params via rtnetlink
        - s390/sthyi: Fix machine name validity indication
        - hwmon: (pwm-fan) Set fan speed to 0 on suspend
        - lightnvm: pblk: fix race on sysfs line state
        - lightnvm: pblk: fix two sleep-in-atomic-context bugs
        - lightnvm: pblk: fix race condition on metadata I/O
        - spi: spi-ep93xx: Use dma_data_direction for ep93xx_spi_dma_{finish,prepare}
        - perf tools: Free temporary 'sys' string in read_event_files()
        - perf tools: Cleanup trace-event-info 'tdata' leak
        - perf strbuf: Match va_{add,copy} with va_end
        - cpupower: Fix coredump on VMWare
        - bcache: Populate writeback_rate_minimum attribute
        - mmc: sdhci-pci-o2micro: Add quirk for O2 Micro dev 0x8620 rev 0x01
        - sdhci: acpi: add free_slot callback
        - mtd: rawnand: denali: set SPARE_AREA_SKIP_BYTES register to 8 if unset
        - iwlwifi: pcie: avoid empty free RB queue
        - iwlwifi: mvm: clear HW_RESTART_REQUESTED when stopping the interface
        - iwlwifi: mvm: check for n_profiles validity in EWRD ACPI
        - x86/olpc: Indicate that legacy PC XO-1 platform should not register RTC
        - ACPI/PPTT: Handle architecturally unknown cache types
        - ACPI / PM: LPIT: Register sysfs attributes based on FADT
        - ACPI / processor: Fix the return value of acpi_processor_ids_walk()
        - cpufreq: dt: Try freeing static OPPs only if we have added them
        - x86/intel_rdt: Show missing resctrl mount options
        - mtd: rawnand: atmel: Fix potential NULL pointer dereference
        - signal: Introduce COMPAT_SIGMINSTKSZ for use in compat_sys_sigaltstack
        - ice: fix changing of ring descriptor size (ethtool -G)
        - ice: update fw version check logic
        - net: hns3: Fix for packet buffer setting bug
        - Bluetooth: btbcm: Add entry for BCM4335C0 UART bluetooth
        - x86: boot: Fix EFI stub alignment
        - net: hns3: Add nic state check before calling netif_tx_wake_queue
        - net: hns3: Fix ets validate issue
        - pinctrl: sunxi: fix 'pctrl->functions' allocation in
          sunxi_pinctrl_build_state
        - pinctrl: qcom: spmi-mpp: Fix err handling of pmic_mpp_set_mux
        - brcmfmac: fix for proper support of 160MHz bandwidth
        - net: hns3: Check hdev state when getting link status
        - net: hns3: Set STATE_DOWN bit of hdev state when stopping net
        - net: phy: phylink: ensure the carrier is off when starting phylink
        - block, bfq: correctly charge and reset entity service in all cases
        - arm64: entry: Allow handling of undefined instructions from EL1
        - kprobes: Return error if we fail to reuse kprobe instead of BUG_ON()
        - spi: gpio: No MISO does not imply no RX
        - ACPI / LPSS: Add alternative ACPI HIDs for Cherry Trail DMA controllers
        - pinctrl: qcom: spmi-mpp: Fix drive strength setting
        - bpf/verifier: fix verifier instability
        - failover: Add missing check to validate 'slave_dev' in
          net_failover_slave_unregister
        - perf tests: Fix record+probe_libc_inet_pton.sh without ping's debuginfo
        - pinctrl: spmi-mpp: Fix pmic_mpp_config_get() to be compliant
        - pinctrl: ssbi-gpio: Fix pm8xxx_pin_config_get() to be compliant
        - net: hns3: Preserve vlan 0 in hardware table
        - net: hns3: Fix ping exited problem when doing lp selftest
        - net: hns3: Fix for vf vlan delete failed problem
        - net: dsa: mv88e6xxx: Fix writing to a PHY page.
        - rsi: fix memory alignment issue in ARM32 platforms
        - iwlwifi: mvm: fix BAR seq ctrl reporting
        - gpio: brcmstb: allow 0 width GPIO banks
        - ixgbe: disallow IPsec Tx offload when in SR-IOV mode
        - ixgbevf: VF2VF TCP RSS
        - ath10k: schedule hardware restart if WMI command times out
        - libata: Apply NOLPM quirk for SAMSUNG MZ7TD256HAFV-000L9
        - thermal: rcar_thermal: Prevent doing work after unbind
        - thermal: da9062/61: Prevent hardware access during system suspend
        - cgroup, netclassid: add a preemption point to write_classid
        - net: stmmac: dwmac-sun8i: fix OF child-node lookup
        - f2fs: fix to account IO correctly for cgroup writeback
        - MD: Memory leak when flush bio size is zero
        - md: fix memleak for mempool
        - scsi: esp_scsi: Track residual for PIO transfers
        - scsi: ufs: Schedule clk gating work on correct queue
        - UAPI: ndctl: Fix g++-unsupported initialisation in headers
        - KVM: nVMX: Clear reserved bits of #DB exit qualification
        - scsi: megaraid_sas: fix a missing-check bug
        - RDMA/core: Do not expose unsupported counters
        - IB/ipoib: Clear IPCB before icmp_send
        - RDMA/bnxt_re: Avoid accessing nq->bar_reg_iomem in failure case
        - RDMA/bnxt_re: Fix recursive lock warning in debug kernel
        - usb: host: ohci-at91: fix request of irq for optional gpio
        - PCI: mediatek: Fix mtk_pcie_find_port() endpoint/port matching logic
        - PCI: cadence: Use AXI region 0 to signal interrupts from EP
        - usb: typec: tcpm: Report back negotiated PPS voltage and current
        - tpm: suppress transmit cmd error logs when TPM 1.2 is disabled/deactivated
        - f2fs: clear PageError on the read path
        - Drivers: hv: vmbus: Use cpumask_var_t for on-stack cpu mask
        - VMCI: Resource wildcard match fixed
        - PCI / ACPI: Enable wake automatically for power managed bridges
        - xprtrdma: Reset credit grant properly after a disconnect
        - irqchip/pdc: Setup all edge interrupts as rising edge at GIC
        - usb: dwc2: fix a race with external vbus supply
        - usb: gadget: udc: atmel: handle at91sam9rl PMC
        - ext4: fix argument checking in EXT4_IOC_MOVE_EXT
        - MD: fix invalid stored role for a disk
        - nvmem: check the return value of nvmem_add_cells()
        - xhci: Avoid USB autosuspend when resuming USB2 ports.
        - f2fs: fix to recover inode's crtime during POR
        - f2fs: fix to recover inode's i_flags during POR
        - PCI/MSI: Warn and return error if driver enables MSI/MSI-X twice
        - coresight: etb10: Fix handling of perf mode
        - PCI: dwc: pci-dra7xx: Enable errata i870 for both EP and RC mode
        - crypto: caam - fix implicit casts in endianness helpers
        - usb: chipidea: Prevent unbalanced IRQ disable
        - Smack: ptrace capability use fixes
        - driver/dma/ioat: Call del_timer_sync() without holding prep_lock
        - firmware: coreboot: Unmap ioregion after device population
        - IB/mlx5: Allow transition of DCI QP to reset
        - uio: ensure class is registered before devices
        - scsi: lpfc: Correct soft lockup when running mds diagnostics
        - scsi: lpfc: Correct race with abort on completion path
        - f2fs: avoid sleeping under spin_lock
        - f2fs: report error if quota off error during umount
        - signal: Always deliver the kernel's SIGKILL and SIGSTOP to a pid namespace
          init
        - mfd: menelaus: Fix possible race condition and leak
        - dmaengine: dma-jz4780: Return error if not probed from DT
        - IB/rxe: fix for duplicate request processing and ack psns
        - ALSA: hda: Check the non-cached stream buffers more explicitly
        - cpupower: Fix AMD Family 0x17 msr_pstate size
        - Revert "f2fs: fix to clear PG_checked flag in set_page_dirty()"
        - f2fs: fix to recover cold bit of inode block during POR
        - f2fs: fix to account IO correctly
        - OPP: Free OPP table properly on performance state irregularities
        - arm: dts: exynos: Add missing cooling device properties for CPUs
        - ARM: dts: exynos: Convert exynos5250.dtsi to opp-v2 bindings
        - ARM: dts: exynos: Mark 1 GHz CPU OPP as suspend OPP on Exynos5250
        - xen-swiotlb: use actually allocated size on check physical continuous
        - tpm: Restore functionality to xen vtpm driver.
        - xen/blkfront: avoid NULL blkfront_info dereference on device removal
        - xen/balloon: Support xend-based toolstack
        - xen: fix race in xen_qlock_wait()
        - xen: make xen_qlock_wait() nestable
        - xen/pvh: increase early stack size
        - xen/pvh: don't try to unplug emulated devices
        - libertas: don't set URB_ZERO_PACKET on IN USB transfer
        - usbip:vudc: BUG kmalloc-2048 (Not tainted): Poison overwritten
        - usb: typec: tcpm: Fix APDO PPS order checking to be based on voltage
        - usb: gadget: udc: renesas_usb3: Fix b-device mode for "workaround"
        - mt76: mt76x2: fix multi-interface beacon configuration
        - iwlwifi: mvm: check return value of rs_rate_from_ucode_rate()
        - net/ipv4: defensive cipso option parsing
        - dmaengine: ppc4xx: fix off-by-one build failure
        - libnvdimm: Hold reference on parent while scheduling async init
        - libnvdimm, region: Fail badblocks listing for inactive regions
        - libnvdimm, pmem: Fix badblocks population for 'raw' namespaces
        - ASoC: intel: skylake: Add missing break in skl_tplg_get_token()
        - ASoC: sta32x: set ->component pointer in private struct
        - IB/mlx5: Fix MR cache initialization
        - IB/rxe: Revise the ib_wr_opcode enum
        - jbd2: fix use after free in jbd2_log_do_checkpoint()
        - gfs2_meta: ->mount() can get NULL dev_name
        - ext4: fix EXT4_IOC_SWAP_BOOT
        - ext4: initialize retries variable in ext4_da_write_inline_data_begin()
        - ext4: fix setattr project check in fssetxattr ioctl
        - ext4: propagate error from dquot_initialize() in EXT4_IOC_FSSETXATTR
        - ext4: fix use-after-free race in ext4_remount()'s error path
        - selinux: fix mounting of cgroup2 under older policies
        - HID: wacom: Work around HID descriptor bug in DTK-2451 and DTH-2452
        - HID: hiddev: fix potential Spectre v1
        - EDAC, amd64: Add Family 17h, models 10h-2fh support
        - EDAC, {i7core,sb,skx}_edac: Fix uncorrected error counting
        - EDAC, skx_edac: Fix logical channel intermediate decoding
        - ARM: dts: dra7: Fix up unaligned access setting for PCIe EP
        - PCI/ASPM: Fix link_state teardown on device removal
        - PCI: Add Device IDs for Intel GPU "spurious interrupt" quirk
        - PCI: vmd: White list for fast interrupt handlers
        - signal/GenWQE: Fix sending of SIGKILL
        - signal: Guard against negative signal numbers in copy_siginfo_from_user32
        - crypto: lrw - Fix out-of bounds access on counter overflow
        - crypto: tcrypt - fix ghash-generic speed test
        - crypto: aesni - don't use GFP_ATOMIC allocation if the request doesn't cross
          a page in gcm
        - crypto: morus/generic - fix for big endian systems
        - crypto: aegis/generic - fix for big endian systems
        - [config] remove deprecated CRYPTO_SPECK, CRYPTO_SPECK_NEON
        - crypto: speck - remove Speck
        - mm: /proc/pid/smaps_rollup: fix NULL pointer deref in smaps_pte_range()
        - ima: fix showing large 'violations' or 'runtime_measurements_count'
        - hugetlbfs: dirty pages as they are added to pagecache
        - mm/rmap: map_pte() was not handling private ZONE_DEVICE page properly
        - mm/hmm: fix race between hmm_mirror_unregister() and mmu_notifier callback
        - KVM: arm/arm64: Ensure only THP is candidate for adjustment
        - KVM: arm64: Fix caching of host MDCR_EL2 value
        - kbuild: fix kernel/bounds.c 'W=1' warning
        - iio: ad5064: Fix regulator handling
        - iio: adc: imx25-gcq: Fix leak of device_node in mx25_gcq_setup_cfgs()
        - iio: adc: at91: fix acking DRDY irq on simple conversions
        - iio: adc: at91: fix wrong channel number in triggered buffer mode
        - w1: omap-hdq: fix missing bus unregister at removal
        - smb3: allow stats which track session and share reconnects to be reset
        - smb3: do not attempt cifs operation in smb3 query info error path
        - smb3: on kerberos mount if server doesn't specify auth type use krb5
        - printk: Fix panic caused by passing log_buf_len to command line
        - genirq: Fix race on spurious interrupt detection
        - NFC: nfcmrvl_uart: fix OF child-node lookup
        - NFSv4.1: Fix the r/wsize checking
        - nfs: Fix a missed page unlock after pg_doio()
        - nfsd: correctly decrement odstate refcount in error path
        - nfsd: Fix an Oops in free_session()
        - lockd: fix access beyond unterminated strings in prints
        - dm ioctl: harden copy_params()'s copy_from_user() from malicious users
        - dm zoned: fix metadata block ref counting
        - dm zoned: fix various dmz_get_mblock() issues
        - media: ov7670: make "xclk" clock optional
        - fsnotify: Fix busy inodes during unmount
        - powerpc/msi: Fix compile error on mpc83xx
        - powerpc/tm: Fix HFSCR bit for no suspend case
        - powerpc/64s/hash: Do not use PPC_INVALIDATE_ERAT on CPUs before POWER9
        - MIPS: memset: Fix CPU_DADDI_WORKAROUNDS `small_fixup' regression
        - MIPS: OCTEON: fix out of bounds array access on CN68XX
        - rtc: ds1307: fix ds1339 wakealarm support
        - rtc: cmos: Fix non-ACPI undefined reference to `hpet_rtc_interrupt'
        - rtc: cmos: Remove the `use_acpi_alarm' module parameter for !ACPI
        - power: supply: twl4030-charger: fix OF sibling-node lookup
        - ocxl: Fix access to the AFU Descriptor Data
        - iommu/arm-smmu: Ensure that page-table updates are visible before TLBI
        - TC: Set DMA masks for devices
        - net: bcmgenet: fix OF child-node lookup
        - media: v4l2-tpg: fix kernel oops when enabling HFLIP and OSD
        - Revert "media: dvbsky: use just one mutex for serializing device R/W ops"
        - kgdboc: Passing ekgdboc to command line causes panic
        - media: cec: make cec_get_edid_spa_location() an inline function
        - media: cec: integrate cec_validate_phys_addr() in cec-api.c
        - xen: fix xen_qlock_wait()
        - xen: remove size limit of privcmd-buf mapping interface
        - xen-blkfront: fix kernel panic with negotiate_mq error path
        - media: cec: add new tx/rx status bits to detect aborts/timeouts
        - media: cec: fix the Signal Free Time calculation
        - media: cec: forgot to cancel delayed work
        - media: em28xx: use a default format if TRY_FMT fails
        - media: tvp5150: avoid going past array on v4l2_querymenu()
        - media: em28xx: fix input name for Terratec AV 350
        - media: em28xx: make v4l2-compliance happier by starting sequence on zero
        - media: em28xx: fix handler for vidioc_s_input()
        - media: adv7604: when the EDID is cleared, unconfigure CEC as well
        - media: adv7842: when the EDID is cleared, unconfigure CEC as well
        - drm/mediatek: fix OF sibling-node lookup
        - media: media colorspaces*.rst: rename AdobeRGB to opRGB
        - media: replace ADOBERGB by OPRGB
        - media: hdmi.h: rename ADOBE_RGB to OPRGB and ADOBE_YCC to OPYCC
        - arm64: lse: remove -fcall-used-x0 flag
        - rpmsg: smd: fix memory leak on channel create
        - Cramfs: fix abad comparison when wrap-arounds occur
        - ARM: dts: socfpga: Fix SDRAM node address for Arria10
        - arm64: dts: stratix10: Correct System Manager register size
        - soc: qcom: rmtfs-mem: Validate that scm is available
        - soc/tegra: pmc: Fix child-node lookup
        - selftests/ftrace: Fix synthetic event test to delete event correctly
        - selftests/powerpc: Fix ptrace tm failure
        - tracing: Return -ENOENT if there is no target synthetic event
        - btrfs: qgroup: Avoid calling qgroup functions if qgroup is not enabled
        - btrfs: Handle owner mismatch gracefully when walking up tree
        - btrfs: locking: Add extra check in btrfs_init_new_buffer() to avoid deadlock
        - btrfs: fix error handling in free_log_tree
        - btrfs: fix error handling in btrfs_dev_replace_start
        - btrfs: Enhance btrfs_trim_fs function to handle error better
        - btrfs: Ensure btrfs_trim_fs can trim the whole filesystem
        - btrfs: iterate all devices during trim, instead of fs_devices::alloc_list
        - btrfs: don't attempt to trim devices that don't support it
        - btrfs: keep trim from interfering with transaction commits
        - btrfs: wait on caching when putting the bg cache
        - Btrfs: don't clean dirty pages during buffered writes
        - btrfs: release metadata before running delayed refs
        - btrfs: protect space cache inode alloc with GFP_NOFS
        - btrfs: reset max_extent_size on clear in a bitmap
        - btrfs: make sure we create all new block groups
        - Btrfs: fix warning when replaying log after fsync of a tmpfile
        - Btrfs: fix wrong dentries after fsync of file that got its parent replaced
        - btrfs: qgroup: Dirty all qgroups before rescan
        - Btrfs: fix null pointer dereference on compressed write path error
        - Btrfs: fix assertion on fsync of regular file when using no-holes feature
        - Btrfs: fix deadlock when writing out free space caches
        - btrfs: reset max_extent_size properly
        - btrfs: set max_extent_size properly
        - btrfs: don't use ctl->free_space for max_extent_size
        - btrfs: only free reserved extent if we didn't insert it
        - btrfs: fix insert_reserved error handling
        - btrfs: don't run delayed_iputs in commit
        - btrfs: move the dio_sem higher up the callchain
        - Btrfs: fix use-after-free during inode eviction
        - Btrfs: fix use-after-free when dumping free space
        - net: sched: Remove TCA_OPTIONS from policy
        - bpf: wait for running BPF programs when updating map-in-map
        - MD: fix invalid stored role for a disk - try2
        - Linux 4.18.19
      * Cosmic update: 4.18.18 upstream stable release (LP: #1810818)
        - eeprom: at24: Add support for address-width property
        - vfs: swap names of {do,vfs}_clone_file_range()
        - bpf: fix partial copy of map_ptr when dst is scalar
        - gpio: mxs: Get rid of external API call
        - clk: sunxi-ng: sun4i: Set VCO and PLL bias current to lowest setting
        - fscache: Fix incomplete initialisation of inline key space
        - cachefiles: fix the race between cachefiles_bury_object() and rmdir(2)
        - fscache: Fix out of bound read in long cookie keys
        - ptp: fix Spectre v1 vulnerability
        - drm/edid: VSDB yCBCr420 Deep Color mode bit definitions
        - drm: fb-helper: Reject all pixel format changing requests
        - RDMA/ucma: Fix Spectre v1 vulnerability
        - IB/ucm: Fix Spectre v1 vulnerability
        - cdc-acm: do not reset notification buffer index upon urb unlinking
        - cdc-acm: correct counting of UART states in serial state notification
        - cdc-acm: fix race between reset and control messaging
        - usb: usbip: Fix BUG: KASAN: slab-out-of-bounds in vhci_hub_control()
        - usb: gadget: storage: Fix Spectre v1 vulnerability
        - usb: roles: intel_xhci: Fix Unbalanced pm_runtime_enable
        - usb: xhci: pci: Enable Intel USB role mux on Apollo Lake platforms
        - USB: fix the usbfs flag sanitization for control transfers
        - tracing: Fix synthetic event to accept unsigned modifier
        - tracing: Fix synthetic event to allow semicolon at end
        - Input: elan_i2c - add ACPI ID for Lenovo IdeaPad 330-15IGM
        - drm/sun4i: Fix an ulong overflow in the dotclock driver
        - sched/fair: Fix throttle_list starvation with low CFS quota
        - x86/tsc: Force inlining of cyc2ns bits
        - x86, hibernate: Fix nosave_regions setup for hibernation
        - x86/percpu: Fix this_cpu_read()
        - x86/time: Correct the attribute on jiffies' definition
        - x86/swiotlb: Enable swiotlb for > 4GiG RAM on 32-bit kernels
        - x86/fpu: Fix i486 + no387 boot crash by only saving FPU registers on context
          switch if there is an FPU
        - Linux 4.18.18
      * Colour banding in HP Pavilion 15-n233sl integrated display (LP: #1794387) //
        Cosmic update: 4.18.18 upstream stable release (LP: #1810818)
        - drm/edid: Add 6 bpc quirk for BOE panel in HP Pavilion 15-n233sl
      * lineout jack can't work on a Dell machine (LP: #1810892)
        - ALSA: hda/realtek - Support Dell headset mode for New AIO platform
      * Ethernet[10ec:8136] doesn't work after S3 with kernel 4.15.0.43.64
        (LP: #1809847)
        - r8169: Enable MSI-X on RTL8106e
        - r8169: re-enable MSI-X on RTL8168g
      * Support new Realtek ethernet chips (LP: #1811055)
        - r8169: Add support for new Realtek Ethernet
      * PC SN720 NVMe WDC 256GB consumes more power in S2Idle than during long idle
        (LP: #1805775)
        - SAUCE: pci/nvme: prevent WDC PC SN720 NVMe from entering D3 and being
          disabled
      * Power consumption during s2idle is higher than long idle (Intel SSDPEKKF)
        (LP: #1804588)
        - SAUCE: pci: prevent Intel NVMe SSDPEKKF from entering D3
        - SAUCE: nvme: add quirk to not call disable function when suspending
      * mpt3sas - driver using the wrong register to update a queue index in FW
        (LP: #1810781)
        - scsi: mpt3sas: As per MPI-spec, use combined reply queue for SAS3.5
          controllers when HBA supports more than 16 MSI-x vectors.
      * Enable new Realtek card reader (LP: #1806335)
        - USB: usb-storage: Add new IDs to ums-realtek
        - SAUCE: (noup) USB: usb-storage: Make MMC support optional on ums-realtek
      * The line-out on the Dell Dock station can't work (LP: #1806532)
        - ALSA: usb-audio: Add vendor and product name for Dell WD19 Dock
      * linux-buildinfo: pull out ABI information into its own package
        (LP: #1806380)
        - [Packaging] getabis -- handle all known package combinations
        - [Packaging] getabis -- support parsing a simple version
      * Fix Intel I210 doesn't work when ethernet cable gets plugged (LP: #1806818)
        - igb: Fix an issue that PME is not enabled during runtime suspend
      * Fix Terminus USB hub that may breaks connected USB devices after S3
        (LP: #1806850)
        - USB: Wait for extra delay time after USB_PORT_FEAT_RESET for quirky hub
      * Add support for 0cf3:535b QCA_ROME device (LP: #1807333)
        - Bluetooth: btusb: Add support for 0cf3:535b QCA_ROME device
      * the new Steam Controller driver breaks it on Steam (LP: #1798583)
        - HID: steam: remove input device when a hid client is running.
      * The mute led can't work anymore on the lenovo x1 carbon (LP: #1808465)
        - ALSA: hda/realtek - Fix the mute LED regresion on Lenovo X1 Carbon
      * click/pop noise in the headphone on several lenovo laptops (LP: #1805079) //
        click/pop noise in the headphone on several lenovo laptops (LP: #1805079)
        - ALSA: hda/realtek - fix the pop noise on headphone for lenovo laptops
      * MAC address pass through on RTL8153-BND for docking station (LP: #1808729)
        - r8152: Add support for MAC address pass through on RTL8153-BND
      * powerpc test in ubuntu_kernel_selftest failed on Cosmic P8/P9 (LP: #1808318)
        - selftests/powerpc: Fix Makefiles for headers_install change
      * [Ubuntu] kernel: zcrypt: reinit ap queue state machine (LP: #1805414)
        - s390/zcrypt: reinit ap queue state machine during device probe
      * [UBUNTU] qeth: fix length check in SNMP processing (LP: #1805802)
        - s390/qeth: fix length check in SNMP processing
      * ASPEED server console output extremely slow after upgrade to 18.04
        (LP: #1808183)
        - drm/ast: Remove existing framebuffers before loading driver
    
     -- Stefan Bader <email address hidden>  Tue, 15 Jan 2019 11:54:36 +0100
  • linux-gcp (4.18.0-1005.6) cosmic; urgency=medium
    
      * linux-gcp: 4.18.0-1005.6 -proposed tracker (LP: #1806423)
    
      * Packaging resync (LP: #1786013)
        - [Packaging] update helper scripts
        - [Packaging] update update.conf
    
      [ Ubuntu: 4.18.0-13.14 ]
    
      * linux: 4.18.0-13.14 -proposed tracker (LP: #1806409)
      * linux-buildinfo: pull out ABI information into its own package
        (LP: #1806380)
        - [Packaging] limit preparation to linux-libc-dev in headers
        - [Packaging] commonise debhelper invocation
        - [Packaging] ABI -- accumulate abi information at the end of the build
        - [Packaging] buildinfo -- add basic build information
        - [Packaging] buildinfo -- add firmware information to the flavour ABI
        - [Packaging] buildinfo -- add compiler information to the flavour ABI
        - [Packaging] buildinfo -- add buildinfo support to getabis
      * linux packages should own /usr/lib/linux/triggers (LP: #1770256)
        - [Packaging] own /usr/lib/linux/triggers
      * Regression: hinic performance degrades over time (LP: #1805248)
        - Revert "net-next/hinic: add checksum offload and TSO support"
      * CVE-2018-18710
        - cdrom: fix improper type cast, which can leat to information leak.
    
     -- Stefan Bader <email address hidden>  Wed, 05 Dec 2018 15:06:00 +0100
  • linux-gcp (4.18.0-1004.5) cosmic; urgency=medium
    
      * linux-gcp: 4.18.0-1004.5 -proposed tracker (LP: #1802750)
    
      [ Ubuntu: 4.18.0-12.13 ]
    
      * linux: 4.18.0-12.13 -proposed tracker (LP: #1802743)
      * [FEAT] Guest-dedicated Crypto Adapters (LP: #1787405)
        - s390/zcrypt: Add ZAPQ inline function.
        - s390/zcrypt: Review inline assembler constraints.
        - s390/zcrypt: Integrate ap_asm.h into include/asm/ap.h.
        - s390/zcrypt: fix ap_instructions_available() returncodes
        - KVM: s390: vsie: simulate VCPU SIE entry/exit
        - KVM: s390: introduce and use KVM_REQ_VSIE_RESTART
        - KVM: s390: refactor crypto initialization
        - s390: vfio-ap: base implementation of VFIO AP device driver
        - s390: vfio-ap: register matrix device with VFIO mdev framework
        - s390: vfio-ap: sysfs interfaces to configure adapters
        - s390: vfio-ap: sysfs interfaces to configure domains
        - s390: vfio-ap: sysfs interfaces to configure control domains
        - s390: vfio-ap: sysfs interface to view matrix mdev matrix
        - KVM: s390: interface to clear CRYCB masks
        - s390: vfio-ap: implement mediated device open callback
        - s390: vfio-ap: implement VFIO_DEVICE_GET_INFO ioctl
        - s390: vfio-ap: zeroize the AP queues
        - s390: vfio-ap: implement VFIO_DEVICE_RESET ioctl
        - KVM: s390: Clear Crypto Control Block when using vSIE
        - KVM: s390: vsie: Do the CRYCB validation first
        - KVM: s390: vsie: Make use of CRYCB FORMAT2 clear
        - KVM: s390: vsie: Allow CRYCB FORMAT-2
        - KVM: s390: vsie: allow CRYCB FORMAT-1
        - KVM: s390: vsie: allow CRYCB FORMAT-0
        - KVM: s390: vsie: allow guest FORMAT-0 CRYCB on host FORMAT-1
        - KVM: s390: vsie: allow guest FORMAT-1 CRYCB on host FORMAT-2
        - KVM: s390: vsie: allow guest FORMAT-0 CRYCB on host FORMAT-2
        - KVM: s390: device attrs to enable/disable AP interpretation
        - KVM: s390: CPU model support for AP virtualization
        - s390: doc: detailed specifications for AP virtualization
        - KVM: s390: fix locking for crypto setting error path
        - KVM: s390: Tracing APCB changes
        - s390: vfio-ap: setup APCB mask using KVM dedicated function
        - [Config:] Enable CONFIG_S390_AP_IOMMU and set CONFIG_VFIO_AP to module.
      * Bypass of mount visibility through userns + mount propagation (LP: #1789161)
        - mount: Retest MNT_LOCKED in do_umount
        - mount: Don't allow copying MNT_UNBINDABLE|MNT_LOCKED mounts
      *  CVE-2018-18955: nested user namespaces with more than five extents
        incorrectly grant privileges over inode (LP: #1801924) // CVE-2018-18955
        - userns: also map extents in the reverse map to kernel IDs
      * kdump fail due to an IRQ storm (LP: #1797990)
        - SAUCE: x86/PCI: Export find_cap() to be used in early PCI code
        - SAUCE: x86/quirks: Add parameter to clear MSIs early on boot
        - SAUCE: x86/quirks: Scan all busses for early PCI quirks
      * crash in ENA driver on removing an interface (LP: #1802341)
        - SAUCE: net: ena: fix crash during ena_remove()
      * Ubuntu 18.04.1 - [s390x] Kernel panic while stressing network bonding
        (LP: #1797367)
        - s390/qeth: reduce hard-coded access to ccw channels
        - s390/qeth: sanitize strings in debug messages
      * Add checksum offload and TSO support for HiNIC adapters (LP: #1800664)
        - net-next/hinic: add checksum offload and TSO support
      * smartpqi updates for ubuntu 18.04.2 (LP: #1798208)
        - scsi: smartpqi: improve handling for sync requests
        - scsi: smartpqi: improve error checking for sync requests
        - scsi: smartpqi: add inspur advantech ids
        - scsi: smartpqi: fix critical ARM issue reading PQI index registers
        - scsi: smartpqi: bump driver version to 1.1.4-130
      * [GLK/CLX] Enhanced IBRS (LP: #1786139)
        - x86/speculation: Remove SPECTRE_V2_IBRS in enum spectre_v2_mitigation
        - x86/speculation: Support Enhanced IBRS on future CPUs
      * Enable keyboard wakeup for S2Idle laptops (LP: #1798552)
        - Input: i8042 - enable keyboard wakeups by default when s2idle is used
      * Overlayfs in user namespace leaks directory content of inaccessible
        directories (LP: #1793458) // CVE-2018-6559
        - SAUCE: overlayfs: ensure mounter privileges when reading directories
      * Update ENA driver to version 2.0.1K (LP: #1798182)
        - net: ena: remove ndo_poll_controller
        - net: ena: fix auto casting to boolean
        - net: ena: minor performance improvement
        - net: ena: complete host info to match latest ENA spec
        - net: ena: introduce Low Latency Queues data structures according to ENA spec
        - net: ena: add functions for handling Low Latency Queues in ena_com
        - net: ena: add functions for handling Low Latency Queues in ena_netdev
        - net: ena: use CSUM_CHECKED device indication to report skb's checksum status
        - net: ena: explicit casting and initialization, and clearer error handling
        - net: ena: limit refill Rx threshold to 256 to avoid latency issues
        - net: ena: change rx copybreak default to reduce kernel memory pressure
        - net: ena: remove redundant parameter in ena_com_admin_init()
        - net: ena: update driver version to 2.0.1
        - net: ena: fix indentations in ena_defs for better readability
        - net: ena: Fix Kconfig dependency on X86
        - net: ena: enable Low Latency Queues
        - net: ena: fix compilation error in xtensa architecture
      * Cosmic update: 4.18.17 upstream stable release (LP: #1802119)
        - xfrm: Validate address prefix lengths in the xfrm selector.
        - xfrm6: call kfree_skb when skb is toobig
        - xfrm: reset transport header back to network header after all input
          transforms ahave been applied
        - xfrm: reset crypto_done when iterating over multiple input xfrms
        - mac80211: Always report TX status
        - cfg80211: reg: Init wiphy_idx in regulatory_hint_core()
        - mac80211: fix pending queue hang due to TX_DROP
        - cfg80211: Address some corner cases in scan result channel updating
        - mac80211: TDLS: fix skb queue/priority assignment
        - mac80211: fix TX status reporting for ieee80211s
        - ARM: 8799/1: mm: fix pci_ioremap_io() offset check
        - xfrm: validate template mode
        - drm/i2c: tda9950: fix timeout counter check
        - drm/i2c: tda9950: set MAX_RETRIES for errors only
        - netfilter: bridge: Don't sabotage nf_hook calls from an l3mdev
        - netfilter: conntrack: get rid of double sizeof
        - arm64: hugetlb: Fix handling of young ptes
        - ARM: dts: BCM63xx: Fix incorrect interrupt specifiers
        - net: macb: Clean 64b dma addresses if they are not detected
        - soc: fsl: qbman: qman: avoid allocating from non existing gen_pool
        - soc: fsl: qe: Fix copy/paste bug in ucc_get_tdm_sync_shift()
        - nl80211: Fix possible Spectre-v1 for NL80211_TXRATE_HT
        - mac80211_hwsim: fix locking when iterating radios during ns exit
        - mac80211_hwsim: fix race in radio destruction from netlink notifier
        - mac80211_hwsim: do not omit multicast announce of first added radio
        - Bluetooth: SMP: fix crash in unpairing
        - pxa168fb: prepare the clock
        - qed: Avoid implicit enum conversion in qed_set_tunn_cls_info
        - qed: Fix mask parameter in qed_vf_prep_tunn_req_tlv
        - qed: Avoid implicit enum conversion in qed_roce_mode_to_flavor
        - qed: Avoid constant logical operation warning in qed_vf_pf_acquire
        - qed: Avoid implicit enum conversion in qed_iwarp_parse_rx_pkt
        - nl80211: Fix possible Spectre-v1 for CQM RSSI thresholds
        - scsi: qedi: Initialize the stats mutex lock
        - rxrpc: Fix checks as to whether we should set up a new call
        - rxrpc: Fix RTT gathering
        - rxrpc: Fix transport sockopts to get IPv4 errors on an IPv6 socket
        - rxrpc: Fix error distribution
        - netfilter: nft_set_rbtree: add missing rb_erase() in GC routine
        - netfilter: avoid erronous array bounds warning
        - asix: Check for supported Wake-on-LAN modes
        - ax88179_178a: Check for supported Wake-on-LAN modes
        - lan78xx: Check for supported Wake-on-LAN modes
        - sr9800: Check for supported Wake-on-LAN modes
        - r8152: Check for supported Wake-on-LAN Modes
        - smsc75xx: Check for Wake-on-LAN modes
        - smsc95xx: Check for Wake-on-LAN modes
        - cfg80211: fix use-after-free in reg_process_hint()
        - KVM: nVMX: Do not expose MPX VMX controls when guest MPX disabled
        - KVM: x86: Do not use kvm_x86_ops->mpx_supported() directly
        - KVM: nVMX: Fix emulation of VM_ENTRY_LOAD_BNDCFGS
        - perf/core: Fix perf_pmu_unregister() locking
        - perf/x86/intel/uncore: Use boot_cpu_data.phys_proc_id instead of hardcorded
          physical package ID 0
        - perf/ring_buffer: Prevent concurent ring buffer access
        - perf/x86/intel/uncore: Fix PCI BDF address of M3UPI on SKX
        - perf/x86/amd/uncore: Set ThreadMask and SliceMask for L3 Cache perf events
        - thunderbolt: Do not handle ICM events after domain is stopped
        - thunderbolt: Initialize after IOMMUs
        - net: fec: fix rare tx timeout
        - declance: Fix continuation with the adapter identification message
        - RISCV: Fix end PFN for low memory
        - Revert "serial: 8250_dw: Fix runtime PM handling"
        - locking/ww_mutex: Fix runtime warning in the WW mutex selftest
        - drm/amd/display: Signal hw_done() after waiting for flip_done()
        - be2net: don't flip hw_features when VXLANs are added/deleted
        - powerpc/numa: Skip onlining a offline node in kdump path
        - net: cxgb3_main: fix a missing-check bug
        - yam: fix a missing-check bug
        - ocfs2: fix crash in ocfs2_duplicate_clusters_by_page()
        - mm/gup_benchmark: fix unsigned comparison to zero in __gup_benchmark_ioctl
        - mm/migrate.c: split only transparent huge pages when allocation fails
        - x86/paravirt: Fix some warning messages
        - clk: mvebu: armada-37xx-periph: Remove unused var num_parents
        - libertas: call into generic suspend code before turning off power
        - perf report: Don't try to map ip to invalid map
        - tls: Fix improper revert in zerocopy_from_iter
        - HID: i2c-hid: Remove RESEND_REPORT_DESCR quirk and its handling
        - compiler.h: Allow arch-specific asm/compiler.h
        - ARM: dts: imx53-qsb: disable 1.2GHz OPP
        - perf python: Use -Wno-redundant-decls to build with PYTHON=python3
        - perf record: Use unmapped IP for inline callchain cursors
        - rxrpc: Don't check RXRPC_CALL_TX_LAST after calling rxrpc_rotate_tx_window()
        - rxrpc: Carry call state out of locked section in rxrpc_rotate_tx_window()
        - rxrpc: Only take the rwind and mtu values from latest ACK
        - rxrpc: Fix connection-level abort handling
        - KVM: x86: support CONFIG_KVM_AMD=y with CONFIG_CRYPTO_DEV_CCP_DD=m
        - net: ena: fix warning in rmmod caused by double iounmap
        - net: ena: fix rare bug when failed restart/resume is followed by driver
          removal
        - net: ena: fix NULL dereference due to untimely napi initialization
        - gpio: Assign gpio_irq_chip::parents to non-stack pointer
        - IB/mlx5: Unmap DMA addr from HCA before IOMMU
        - rds: RDS (tcp) hangs on sendto() to unresponding address
        - selftests: rtnetlink.sh explicitly requires bash.
        - selftests: udpgso_bench.sh explicitly requires bash
        - vmlinux.lds.h: Fix incomplete .text.exit discards
        - vmlinux.lds.h: Fix linker warnings about orphan .LPBX sections
        - afs: Fix cell proc list
        - fs/fat/fatent.c: add cond_resched() to fat_count_free_clusters()
        - Revert "mm: slowly shrink slabs with a relatively small number of objects"
        - Revert "netfilter: ipv6: nf_defrag: drop skb dst before queueing"
        - perf tools: Disable parallelism for 'make clean'
        - bridge: do not add port to router list when receives query with source
          0.0.0.0
        - ipv6: mcast: fix a use-after-free in inet6_mc_check
        - ipv6/ndisc: Preserve IPv6 control buffer if protocol error handlers are
          called
        - ipv6: rate-limit probes for neighbourless routes
        - llc: set SOCK_RCU_FREE in llc_sap_add_socket()
        - net: fec: don't dump RX FIFO register when not available
        - net/ipv6: Fix index counter for unicast addresses in in6_dump_addrs
        - net/mlx5e: fix csum adjustments caused by RXFCS
        - net: sched: gred: pass the right attribute to gred_change_table_def()
        - net: socket: fix a missing-check bug
        - net: stmmac: Fix stmmac_mdio_reset() when building stmmac as modules
        - net: udp: fix handling of CHECKSUM_COMPLETE packets
        - r8169: fix NAPI handling under high load
        - rtnetlink: Disallow FDB configuration for non-Ethernet device
        - sctp: fix race on sctp_id2asoc
        - tipc: fix unsafe rcu locking when accessing publication list
        - udp6: fix encap return code for resubmitting
        - vhost: Fix Spectre V1 vulnerability
        - virtio_net: avoid using netif_tx_disable() for serializing tx routine
        - ethtool: fix a privilege escalation bug
        - bonding: fix length of actor system
        - ip6_tunnel: Fix encapsulation layout
        - openvswitch: Fix push/pop ethernet validation
        - net: ipmr: fix unresolved entry dumps
        - net/mlx5: Take only bit 24-26 of wqe.pftype_wq for page fault type
        - net: bcmgenet: Poll internal PHY for GENETv5
        - net: sched: Fix for duplicate class dump
        - net/sched: cls_api: add missing validation of netlink attributes
        - net/ipv6: Allow onlink routes to have a device mismatch if it is the default
          route
        - sctp: fix the data size calculation in sctp_data_size
        - sctp: not free the new asoc when sctp_wait_for_connect returns err
        - net/mlx5: Fix memory leak when setting fpga ipsec caps
        - net/smc: fix smc_buf_unuse to use the lgr pointer
        - mlxsw: spectrum_switchdev: Don't ignore deletions of learned MACs
        - net: bpfilter: use get_pid_task instead of pid_task
        - net: drop skb on failure in ip_check_defrag()
        - net: fix pskb_trim_rcsum_slow() with odd trim offset
        - mlxsw: core: Fix devlink unregister flow
        - sparc64: Export __node_distance.
        - sparc64: Make corrupted user stacks more debuggable.
        - sparc64: Make proc_id signed.
        - sparc64: Set %l4 properly on trap return after handling signals.
        - sparc64: Wire up compat getpeername and getsockname.
        - sparc: Fix single-pcr perf event counter management.
        - sparc: Fix syscall fallback bugs in VDSO.
        - sparc: Throttle perf events properly.
        - net: bridge: remove ipv6 zero address check in mcast queries
        - Linux 4.18.17
      * Cosmic update: 4.18.16 upstream stable release (LP: #1802100)
        - soundwire: Fix duplicate stream state assignment
        - soundwire: Fix incorrect exit after configuring stream
        - soundwire: Fix acquiring bus lock twice during master release
        - media: af9035: prevent buffer overflow on write
        - spi: gpio: Fix copy-and-paste error
        - batman-adv: Avoid probe ELP information leak
        - batman-adv: Fix segfault when writing to throughput_override
        - batman-adv: Fix segfault when writing to sysfs elp_interval
        - batman-adv: Prevent duplicated gateway_node entry
        - batman-adv: Prevent duplicated nc_node entry
        - batman-adv: Prevent duplicated softif_vlan entry
        - batman-adv: Prevent duplicated global TT entry
        - batman-adv: Prevent duplicated tvlv handler
        - batman-adv: fix backbone_gw refcount on queue_work() failure
        - batman-adv: fix hardif_neigh refcount on queue_work() failure
        - cxgb4: fix abort_req_rss6 struct
        - clocksource/drivers/ti-32k: Add CLOCK_SOURCE_SUSPEND_NONSTOP flag for non-
          am43 SoCs
        - scsi: ibmvscsis: Fix a stringop-overflow warning
        - scsi: ibmvscsis: Ensure partition name is properly NUL terminated
        - intel_th: pci: Add Ice Lake PCH support
        - Input: atakbd - fix Atari keymap
        - Input: atakbd - fix Atari CapsLock behaviour
        - selftests: pmtu: properly redirect stderr to /dev/null
        - net: emac: fix fixed-link setup for the RTL8363SB switch
        - ravb: do not write 1 to reserved bits
        - net/smc: fix non-blocking connect problem
        - net/smc: fix sizeof to int comparison
        - qed: Fix populating the invalid stag value in multi function mode.
        - qed: Do not add VLAN 0 tag to untagged frames in multi-function mode.
        - PCI: dwc: Fix scheduling while atomic issues
        - RDMA/uverbs: Fix validity check for modify QP
        - scsi: lpfc: Synchronize access to remoteport via rport
        - drm: mali-dp: Call drm_crtc_vblank_reset on device init
        - scsi: ipr: System hung while dlpar adding primary ipr adapter back
        - scsi: sd: don't crash the host on invalid commands
        - bpf: sockmap only allow ESTABLISHED sock state
        - bpf: sockmap, fix transition through disconnect without close
        - bpf: test_maps, only support ESTABLISHED socks
        - net/mlx4: Use cpumask_available for eq->affinity_mask
        - clocksource/drivers/fttmr010: Fix set_next_event handler
        - RDMA/bnxt_re: Fix system crash during RDMA resource initialization
        - RISC-V: include linux/ftrace.h in asm-prototypes.h
        - iommu/rockchip: Free irqs in shutdown handler
        - pinctrl/amd: poll InterruptEnable bits in amd_gpio_irq_set_type
        - powerpc/tm: Fix userspace r13 corruption
        - powerpc/tm: Avoid possible userspace r1 corruption on reclaim
        - powerpc/numa: Use associativity if VPHN hcall is successful
        - iommu/amd: Return devid as alias for ACPI HID devices
        - x86/boot: Fix kexec booting failure in the SEV bit detection code
        - Revert "vfs: fix freeze protection in mnt_want_write_file() for overlayfs"
        - mremap: properly flush TLB before releasing the page
        - ARC: build: Get rid of toolchain check
        - ARC: build: Don't set CROSS_COMPILE in arch's Makefile
        - Linux 4.18.16
      * Cosmic update: 4.18.15 upstream stable release (LP: #1802082)
        - bnxt_en: Fix TX timeout during netpoll.
        - bnxt_en: free hwrm resources, if driver probe fails.
        - bonding: avoid possible dead-lock
        - ip6_tunnel: be careful when accessing the inner header
        - ip_tunnel: be careful when accessing the inner header
        - ipv4: fix use-after-free in ip_cmsg_recv_dstaddr()
        - ipv6: take rcu lock in rawv6_send_hdrinc()
        - net: dsa: bcm_sf2: Call setup during switch resume
        - net: hns: fix for unmapping problem when SMMU is on
        - net: ipv4: update fnhe_pmtu when first hop's MTU changes
        - net/ipv6: Display all addresses in output of /proc/net/if_inet6
        - netlabel: check for IPV4MASK in addrinfo_get
        - net: mvpp2: Extract the correct ethtype from the skb for tx csum offload
        - net: mvpp2: fix a txq_done race condition
        - net: sched: Add policy validation for tc attributes
        - net: sched: cls_u32: fix hnode refcounting
        - net: systemport: Fix wake-up interrupt race during resume
        - net/usb: cancel pending work when unbinding smsc75xx
        - qlcnic: fix Tx descriptor corruption on 82xx devices
        - qmi_wwan: Added support for Gemalto's Cinterion ALASxx WWAN interface
        - rtnl: limit IFLA_NUM_TX_QUEUES and IFLA_NUM_RX_QUEUES to 4096
        - sctp: update dst pmtu with the correct daddr
        - team: Forbid enslaving team device to itself
        - tipc: fix flow control accounting for implicit connect
        - udp: Unbreak modules that rely on external __skb_recv_udp() availability
        - net: qualcomm: rmnet: Skip processing loopback packets
        - net: qualcomm: rmnet: Fix incorrect allocation flag in transmit
        - net: qualcomm: rmnet: Fix incorrect allocation flag in receive path
        - tun: remove unused parameters
        - tun: initialize napi_mutex unconditionally
        - tun: napi flags belong to tfile
        - net: stmmac: Fixup the tail addr setting in xmit path
        - net/packet: fix packet drop as of virtio gso
        - net: dsa: bcm_sf2: Fix unbind ordering
        - net/mlx5e: Set vlan masks for all offloaded TC rules
        - net: aquantia: memory corruption on jumbo frames
        - net/mlx5: E-Switch, Fix out of bound access when setting vport rate
        - bonding: pass link-local packets to bonding master also.
        - bonding: fix warning message
        - net: stmmac: Rework coalesce timer and fix multi-queue races
        - nfp: avoid soft lockups under control message storm
        - bnxt_en: don't try to offload VLAN 'modify' action
        - net-ethtool: ETHTOOL_GUFO did not and should not require CAP_NET_ADMIN
        - net: phy: phylink: fix SFP interface autodetection
        - sfp: fix oops with ethtool -m
        - tcp/dccp: fix lockdep issue when SYN is backlogged
        - inet: make sure to grab rcu_read_lock before using ireq->ireq_opt
        - net: dsa: b53: Keep CPU port as tagged in all VLANs
        - rtnetlink: Fail dump if target netnsid is invalid
        - bnxt_en: Fix VNIC reservations on the PF.
        - net: ipv4: don't let PMTU updates increase route MTU
        - net/mlx5: Check for SQ and not RQ state when modifying hairpin SQ
        - bnxt_en: Fix enables field in HWRM_QUEUE_COS2BW_CFG request
        - bnxt_en: get the reduced max_irqs by the ones used by RDMA
        - net/ipv6: Remove extra call to ip6_convert_metrics for multipath case
        - net/ipv6: stop leaking percpu memory in fib6 info
        - net: mscc: fix the frame extraction into the skb
        - qed: Fix shmem structure inconsistency between driver and the mfw.
        - r8169: fix network stalls due to missing bit TXCFG_AUTO_FIFO
        - r8169: set RX_MULTI_EN bit in RxConfig for 8168F-family chips
        - vxlan: fill ttl inherit info
        - ASoC: dapm: Fix NULL pointer deference on CODEC to CODEC DAIs
        - ASoC: max98373: Added speaker FS gain cotnrol register to volatile.
        - ASoC: rt5514: Fix the issue of the delay volume applied again
        - selftests: android: move config up a level
        - selftests: kselftest: Remove outdated comment
        - ASoC: max98373: Added 10ms sleep after amp software reset
        - ASoC: wm8804: Add ACPI support
        - ASoC: sigmadsp: safeload should not have lower byte limit
        - ASoC: q6routing: initialize data correctly
        - selftests: add headers_install to lib.mk
        - selftests/efivarfs: add required kernel configs
        - selftests: memory-hotplug: add required configs
        - ASoC: rsnd: adg: care clock-frequency size
        - ASoC: rsnd: don't fallback to PIO mode when -EPROBE_DEFER
        - hwmon: (nct6775) Fix access to fan pulse registers
        - Fix cg_read_strcmp()
        - ASoC: AMD: Ensure reset bit is cleared before configuring
        - drm/pl111: Make sure of_device_id tables are NULL terminated
        - Bluetooth: SMP: Fix trying to use non-existent local OOB data
        - Bluetooth: Use correct tfm to generate OOB data
        - Bluetooth: hci_ldisc: Free rw_semaphore on close
        - mfd: omap-usb-host: Fix dts probe of children
        - KVM: PPC: Book3S HV: Don't use compound_order to determine host mapping size
        - scsi: iscsi: target: Don't use stack buffer for scatterlist
        - scsi: qla2xxx: Fix an endian bug in fcpcmd_is_corrupted()
        - sound: enable interrupt after dma buffer initialization
        - sound: don't call skl_init_chip() to reset intel skl soc
        - bpf: btf: Fix end boundary calculation for type section
        - bpf: use __GFP_COMP while allocating page
        - hwmon: (nct6775) Fix virtual temperature sources for NCT6796D
        - hwmon: (nct6775) Fix RPM output for fan7 on NCT6796D
        - stmmac: fix valid numbers of unicast filter entries
        - hwmon: (nct6775) Use different register to get fan RPM for fan7
        - net: ethernet: ti: add missing GENERIC_ALLOCATOR dependency
        - net: macb: disable scatter-gather for macb on sama5d3
        - ARM: dts: at91: add new compatibility string for macb on sama5d3
        - PCI: hv: support reporting serial number as slot information
        - clk: x86: add "ether_clk" alias for Bay Trail / Cherry Trail
        - clk: x86: Stop marking clocks as CLK_IS_CRITICAL
        - pinctrl: cannonlake: Fix gpio base for GPP-E
        - x86/kvm/lapic: always disable MMIO interface in x2APIC mode
        - drm/amdgpu: Fix SDMA HQD destroy error on gfx_v7
        - drm/amdkfd: Change the control stack MTYPE from UC to NC on GFX9
        - drm/amdkfd: Fix ATS capablity was not reported correctly on some APUs
        - mm: slowly shrink slabs with a relatively small number of objects
        - mm/vmstat.c: fix outdated vmstat_text
        - afs: Fix afs_server struct leak
        - afs: Fix clearance of reply
        - MIPS: Fix CONFIG_CMDLINE handling
        - MIPS: VDSO: Always map near top of user memory
        - mach64: detect the dot clock divider correctly on sparc
        - vsprintf: Fix off-by-one bug in bstr_printf() processing dereferenced
          pointers
        - percpu: stop leaking bitmap metadata blocks
        - perf script python: Fix export-to-postgresql.py occasional failure
        - perf script python: Fix export-to-sqlite.py sample columns
        - s390/cio: Fix how vfio-ccw checks pinned pages
        - dm cache: destroy migration_cache if cache target registration failed
        - dm: fix report zone remapping to account for partition offset
        - dm linear: eliminate linear_end_io call if CONFIG_DM_ZONED disabled
        - dm linear: fix linear_end_io conditional definition
        - cgroup: Fix dom_cgrp propagation when enabling threaded mode
        - Input: xpad - add support for Xbox1 PDP Camo series gamepad
        - drm/nouveau/drm/nouveau: Grab runtime PM ref in nv50_mstc_detect()
        - mmc: block: avoid multiblock reads for the last sector in SPI mode
        - pinctrl: mcp23s08: fix irq and irqchip setup order
        - arm64: perf: Reject stand-alone CHAIN events for PMUv3
        - mm/mmap.c: don't clobber partially overlapping VMA with MAP_FIXED_NOREPLACE
        - mm/thp: fix call to mmu_notifier in set_pmd_migration_entry() v2
        - filesystem-dax: Fix dax_layout_busy_page() livelock
        - mm: Preserve _PAGE_DEVMAP across mprotect() calls
        - i2c: i2c-scmi: fix for i2c_smbus_write_block_data
        - KVM: PPC: Book3S HV: Avoid crash from THP collapse during radix page fault
        - Linux 4.18.15
      * Cosmic update: 4.18.14 upstream stable release (LP: #1801986)
        - perf/core: Add sanity check to deal with pinned event failure
        - mm: migration: fix migration of huge PMD shared pages
        - mm, thp: fix mlocking THP page with migration enabled
        - mm/vmstat.c: skip NR_TLB_REMOTE_FLUSH* properly
        - KVM: VMX: check for existence of secondary exec controls before accessing
        - blk-mq: I/O and timer unplugs are inverted in blktrace
        - pstore/ram: Fix failure-path memory leak in ramoops_init
        - clocksource/drivers/timer-atmel-pit: Properly handle error cases
        - fbdev/omapfb: fix omapfb_memory_read infoleak
        - mmc: core: Fix debounce time to use microseconds
        - mmc: slot-gpio: Fix debounce time to use miliseconds again
        - mac80211: allocate TXQs for active monitor interfaces
        - drm/amdgpu: Fix vce work queue was not cancelled when suspend
        - drm: fix use-after-free read in drm_mode_create_lease_ioctl()
        - x86/vdso: Fix asm constraints on vDSO syscall fallbacks
        - selftests/x86: Add clock_gettime() tests to test_vdso
        - x86/vdso: Only enable vDSO retpolines when enabled and supported
        - x86/vdso: Fix vDSO syscall fallback asm constraint regression
        - Revert "UBUNTU: SAUCE: PCI: Reprogram bridge prefetch registers on resume"
        - PCI: Reprogram bridge prefetch registers on resume
        - mac80211: fix setting IEEE80211_KEY_FLAG_RX_MGMT for AP mode keys
        - PM / core: Clear the direct_complete flag on errors
        - dm mpath: fix attached_handler_name leak and dangling hw_handler_name
          pointer
        - dm cache metadata: ignore hints array being too small during resize
        - dm cache: fix resize crash if user doesn't reload cache table
        - xhci: Add missing CAS workaround for Intel Sunrise Point xHCI
        - usb: xhci-mtk: resume USB3 roothub first
        - USB: serial: simple: add Motorola Tetra MTP6550 id
        - USB: serial: option: improve Quectel EP06 detection
        - USB: serial: option: add two-endpoints device-id flag
        - usb: cdc_acm: Do not leak URB buffers
        - tty: Drop tty->count on tty_reopen() failure
        - of: unittest: Disable interrupt node tests for old world MAC systems
        - powerpc: Avoid code patching freed init sections
        - powerpc/lib: fix book3s/32 boot failure due to code patching
        - ARC: clone syscall to setp r25 as thread pointer
        - f2fs: fix invalid memory access
        - tipc: call start and done ops directly in __tipc_nl_compat_dumpit()
        - ucma: fix a use-after-free in ucma_resolve_ip()
        - ubifs: Check for name being NULL while mounting
        - rds: rds_ib_recv_alloc_cache() should call alloc_percpu_gfp() instead
        - ath10k: fix scan crash due to incorrect length calculation
        - Linux 4.18.14
      * Cosmic update: 4.18.13 upstream stable release (LP: #1801931)
        - rseq/selftests: fix parametrized test with -fpie
        - mac80211: Run TXQ teardown code before de-registering interfaces
        - mac80211_hwsim: require at least one channel
        - Btrfs: fix unexpected failure of nocow buffered writes after snapshotting
          when low on space
        - KVM: PPC: Book3S HV: Don't truncate HPTE index in xlate function
        - cfg80211: remove division by size of sizeof(struct ieee80211_wmm_rule)
        - btrfs: btrfs_shrink_device should call commit transaction at the end
        - scsi: csiostor: add a check for NULL pointer after kmalloc()
        - scsi: csiostor: fix incorrect port capabilities
        - scsi: libata: Add missing newline at end of file
        - scsi: aacraid: fix a signedness bug
        - bpf, sockmap: fix potential use after free in bpf_tcp_close
        - bpf, sockmap: fix psock refcount leak in bpf_tcp_recvmsg
        - bpf: sockmap, decrement copied count correctly in redirect error case
        - mac80211: correct use of IEEE80211_VHT_CAP_RXSTBC_X
        - mac80211_hwsim: correct use of IEEE80211_VHT_CAP_RXSTBC_X
        - cfg80211: make wmm_rule part of the reg_rule structure
        - mac80211_hwsim: Fix possible Spectre-v1 for hwsim_world_regdom_custom
        - nl80211: Fix nla_put_u8 to u16 for NL80211_WMMR_TXOP
        - nl80211: Pass center frequency in kHz instead of MHz
        - bpf: fix several offset tests in bpf_msg_pull_data
        - gpio: adp5588: Fix sleep-in-atomic-context bug
        - mac80211: mesh: fix HWMP sequence numbering to follow standard
        - mac80211: avoid kernel panic when building AMSDU from non-linear SKB
        - gpiolib: acpi: Switch to cansleep version of GPIO library call
        - gpiolib-acpi: Register GpioInt ACPI event handlers from a late_initcall
        - gpio: dwapb: Fix error handling in dwapb_gpio_probe()
        - bpf: fix msg->data/data_end after sg shift repair in bpf_msg_pull_data
        - bpf: fix shift upon scatterlist ring wrap-around in bpf_msg_pull_data
        - bpf: fix sg shift repair start offset in bpf_msg_pull_data
        - tipc: switch to rhashtable iterator
        - sh_eth: Add R7S9210 support
        - net: mvpp2: initialize port of_node pointer
        - tc-testing: add test-cases for numeric and invalid control action
        - cfg80211: nl80211_update_ft_ies() to validate NL80211_ATTR_IE
        - mac80211: do not convert to A-MSDU if frag/subframe limited
        - mac80211: always account for A-MSDU header changes
        - tools/kvm_stat: fix python3 issues
        - tools/kvm_stat: fix handling of invalid paths in debugfs provider
        - tools/kvm_stat: fix updates for dead guests
        - gpio: Fix crash due to registration race
        - ARC: atomics: unbork atomic_fetch_##op()
        - Revert "blk-throttle: fix race between blkcg_bio_issue_check() and
          cgroup_rmdir()"
        - md/raid5-cache: disable reshape completely
        - RAID10 BUG_ON in raise_barrier when force is true and conf->barrier is 0
        - selftests: pmtu: maximum MTU for vti4 is 2^16-1-20
        - selftests: pmtu: detect correct binary to ping ipv6 addresses
        - ibmvnic: Include missing return code checks in reset function
        - bpf: Fix bpf_msg_pull_data()
        - bpf: avoid misuse of psock when TCP_ULP_BPF collides with another ULP
        - i2c: uniphier: issue STOP only for last message or I2C_M_STOP
        - i2c: uniphier-f: issue STOP only for last message or I2C_M_STOP
        - net: cadence: Fix a sleep-in-atomic-context bug in macb_halt_tx()
        - fs/cifs: don't translate SFM_SLASH (U+F026) to backslash
        - mac80211: fix an off-by-one issue in A-MSDU max_subframe computation
        - cfg80211: fix a type issue in ieee80211_chandef_to_operating_class()
        - mac80211: fix WMM TXOP calculation
        - mac80211: fix a race between restart and CSA flows
        - mac80211: Fix station bandwidth setting after channel switch
        - mac80211: don't Tx a deauth frame if the AP forbade Tx
        - mac80211: shorten the IBSS debug messages
        - fsnotify: fix ignore mask logic in fsnotify()
        - net/ibm/emac: wrong emac_calc_base call was used by typo
        - nds32: fix logic for module
        - nds32: add NULL entry to the end of_device_id array
        - nds32: Fix empty call trace
        - nds32: Fix get_user/put_user macro expand pointer problem
        - nds32: fix build error because of wrong semicolon
        - tools/vm/slabinfo.c: fix sign-compare warning
        - tools/vm/page-types.c: fix "defined but not used" warning
        - nds32: linker script: GCOV kernel may refers data in __exit
        - ceph: avoid a use-after-free in ceph_destroy_options()
        - firmware: arm_scmi: fix divide by zero when sustained_perf_level is zero
        - afs: Fix cell specification to permit an empty address list
        - mm: madvise(MADV_DODUMP): allow hugetlbfs pages
        - bpf: 32-bit RSH verification must truncate input before the ALU op
        - netfilter: xt_cluster: add dependency on conntrack module
        - netfilter: xt_checksum: ignore gso skbs
        - HID: intel-ish-hid: Enable Sunrise Point-H ish driver
        - HID: add support for Apple Magic Keyboards
        - usb: gadget: fotg210-udc: Fix memory leak of fotg210->ep[i]
        - HID: hid-saitek: Add device ID for RAT 7 Contagion
        - scsi: iscsi: target: Set conn->sess to NULL when iscsi_login_set_conn_values
          fails
        - scsi: iscsi: target: Fix conn_ops double free
        - scsi: qedi: Add the CRC size within iSCSI NVM image
        - perf annotate: Properly interpret indirect call
        - perf evsel: Fix potential null pointer dereference in perf_evsel__new_idx()
        - perf util: Fix bad memory access in trace info.
        - perf probe powerpc: Ignore SyS symbols irrespective of endianness
        - perf annotate: Fix parsing aarch64 branch instructions after objdump update
        - netfilter: kconfig: nat related expression depend on nftables core
        - netfilter: nf_tables: release chain in flushing set
        - Revert "iio: temperature: maxim_thermocouple: add MAX31856 part"
        - iio: imu: st_lsm6dsx: take into account ts samples in wm configuration
        - RDMA/ucma: check fd type in ucma_migrate_id()
        - riscv: Do not overwrite initrd_start and initrd_end
        - HID: sensor-hub: Restore fixup for Lenovo ThinkPad Helix 2 sensor hub report
        - usb: host: xhci-plat: Iterate over parent nodes for finding quirks
        - USB: yurex: Check for truncation in yurex_read()
        - nvmet-rdma: fix possible bogus dereference under heavy load
        - bnxt_re: Fix couple of memory leaks that could lead to IOMMU call traces
        - net/mlx5: Consider PCI domain in search for next dev
        - dm raid: fix reshape race on small devices
        - drm/nouveau: fix oops in client init failure path
        - drm/nouveau/mmu: don't attempt to dereference vmm without valid instance
          pointer
        - drm/nouveau/TBDdevinit: don't fail when PMU/PRE_OS is missing from VBIOS
        - drm/nouveau/disp: fix DP disable race
        - drm/nouveau/disp/gm200-: enforce identity-mapped SOR assignment for LVDS/eDP
          panels
        - dm raid: fix stripe adding reshape deadlock
        - dm raid: fix rebuild of specific devices by updating superblock
        - dm raid: fix RAID leg rebuild errors
        - r8169: set TxConfig register after TX / RX is enabled, just like RxConfig
        - fs/cifs: suppress a string overflow warning
        - perf/x86/intel: Add support/quirk for the MISPREDICT bit on Knights Landing
          CPUs
        - sched/topology: Set correct NUMA topology type
        - dm thin metadata: try to avoid ever aborting transactions
        - netfilter: nfnetlink_queue: Solve the NFQUEUE/conntrack clash for NF_REPEAT
        - netfilter: xt_hashlimit: use s->file instead of s->private
        - arch/hexagon: fix kernel/dma.c build warning
        - hexagon: modify ffs() and fls() to return int
        - drm/amdgpu: Fix SDMA hang in prt mode v2
        - arm64: jump_label.h: use asm_volatile_goto macro instead of "asm goto"
        - drm/amdgpu: fix error handling in amdgpu_cs_user_fence_chunk
        - r8169: Clear RTL_FLAG_TASK_*_PENDING when clearing RTL_FLAG_TASK_ENABLED
        - s390/qeth: don't dump past end of unknown HW header
        - cifs: read overflow in is_valid_oplock_break()
        - asm-generic: io: Fix ioport_map() for !CONFIG_GENERIC_IOMAP &&
          CONFIG_INDIRECT_PIO
        - xen/manage: don't complain about an empty value in control/sysrq node
        - xen: avoid crash in disable_hotplug_cpu
        - xen: fix GCC warning and remove duplicate EVTCHN_ROW/EVTCHN_COL usage
        - x86/APM: Fix build warning when PROC_FS is not enabled
        - new primitive: discard_new_inode()
        - vfs: don't evict uninitialized inode
        - ovl: set I_CREATING on inode being created
        - ovl: fix access beyond unterminated strings
        - ovl: fix memory leak on unlink of indexed file
        - ovl: fix format of setxattr debug
        - sysfs: Do not return POSIX ACL xattrs via listxattr
        - b43: fix DMA error related regression with proprietary firmware
        - firmware: Fix security issue with request_firmware_into_buf()
        - firmware: Always initialize the fw_priv list object
        - cpufreq: qcom-kryo: Fix section annotations
        - smb2: fix missing files in root share directory listing
        - iommu/amd: Clear memory encryption mask from physical address
        - crypto: qat - Fix KASAN stack-out-of-bounds bug in adf_probe()
        - crypto: chelsio - Fix memory corruption in DMA Mapped buffers.
        - crypto: mxs-dcp - Fix wait logic on chan threads
        - crypto: caam/jr - fix ablkcipher_edesc pointer arithmetic
        - gpiolib: Free the last requested descriptor
        - Drivers: hv: vmbus: Use get/put_cpu() in vmbus_connect()
        - tools: hv: fcopy: set 'error' in case an unknown operation was requested
        - proc: restrict kernel stack dumps to root
        - ocfs2: fix locking for res->tracking and dlm->tracking_list
        - HID: i2c-hid: disable runtime PM operations on hantick touchpad
        - ixgbe: check return value of napi_complete_done()
        - dm thin metadata: fix __udivdi3 undefined on 32-bit
        - Revert "drm/amd/pp: Send khz clock values to DC for smu7/8"
        - Linux 4.18.13
      * Volume control not working Dell XPS 27 (7760) (LP: #1775068) // Cosmic
        update: 4.18.13 upstream stable release (LP: #1801931)
        - ALSA: hda/realtek - Cannot adjust speaker's volume on Dell XPS 27 7760
      * [Bionic][Cosmic]  ipmi: Fix timer race with module unload (LP: #1799281)
        - ipmi: Fix timer race with module unload
      * [Bionic][Cosmic] Fix to ipmi to support vendor specific messages greater
        than 255 bytes (LP: #1799794)
        - ipmi:ssif: Add support for multi-part transmit messages > 2 parts
      * 18.10 kernel does not appear to validate kernel module signatures correctly
        (LP: #1798863) // CVE-2018-18653
        - SAUCE: (efi-lockdown) module: remove support for deferring module signature
          verification to IMA
      * 18.10 kernel does not appear to validate kernel module signatures correctly
        (LP: #1798863)
        - SAUCE: (efi-lockdown) module: trust keys from secondary keyring for module
          signing
      * [Ubuntu] net/af_iucv: fix skb leaks for HiperTransport (LP: #1800639)
        - net/af_iucv: drop inbound packets with invalid flags
        - net/af_iucv: fix skb handling on HiperTransport xmit error
      * Power consumption during s2idle is higher than long idle(sk hynix)
        (LP: #1801875)
        - SAUCE: pci: prevent sk hynix nvme from entering D3
        - SAUCE: nvme: add quirk to not call disable function when suspending
      * NULL pointer dereference at 0000000000000020 when access
        dst_orig->ops->family in function  xfrm_lookup_with_ifid() (LP: #1801878)
        - xfrm: Fix NULL pointer dereference when skb_dst_force clears the dst_entry.
      * hns3: map tx ring to tc (LP: #1802023)
        - net: hns3: Set tx ring' tc info when netdev is up
      * [Ubuntu] qeth: Fix potential array overrun in cmd/rc lookup (LP: #1800641)
        - s390: qeth_core_mpc: Use ARRAY_SIZE instead of reimplementing its function
        - s390: qeth: Fix potential array overrun in cmd/rc lookup
      * Mellanox CX5 stops pinging with rx_wqe_err (mlx5_core) (LP: #1799393)
        - net/mlx5: WQ, fixes for fragmented WQ buffers API
      * Vulkan applications cause permanent memory leak with Intel GPU
        (LP: #1798165)
        - drm/syncobj: Don't leak fences when WAIT_FOR_SUBMIT is set
      * Packaging resync (LP: #1786013)
        - [Package] add support for specifying the primary makefile
    
     -- Khalid Elmously <email address hidden>  Wed, 14 Nov 2018 22:31:51 -0500
  • linux-gcp (4.18.0-1003.4) cosmic; urgency=medium
    
      * linux-gcp: 4.18.0-1003.4 -proposed tracker (LP: #1799452)
    
      * Shared folders cannot be mounted in ubuntu/cosmic64 due to missing vbox
        modules (LP: #1796647)
        - [Config] gcp: CONFIG_VBOXGUEST=n
    
      [ Ubuntu: 4.18.0-11.12 ]
    
      * linux: 4.18.0-11.12 -proposed tracker (LP: #1799445)
      * arm64: snapdragon: WARNING: CPU: 0 PID: 1 arch/arm64/kernel/setup.c:271
        reserve_memblock_reserved_regions (LP: #1797139)
        - SAUCE: arm64: Fix /proc/iomem for reserved but not memory regions
      * arm64: snapdragon: WARNING: CPU: 0 PID: 1 at drivers/irqchip/irq-gic.c:1016
        gic_irq_domain_translate (LP: #1797143)
        - SAUCE: arm64: dts: msm8916: camms: fix gic_irq_domain_translate warnings
      * The front MIC can't work on the Lenovo M715 (LP: #1797292)
        - ALSA: hda/realtek - Fix the problem of the front MIC on the Lenovo M715
      * Provide mode where all vCPUs on a core must be the same VM (LP: #1792957)
        - KVM: PPC: Book3S HV: Provide mode where all vCPUs on a core must be the same
          VM
      * fscache: bad refcounting in fscache_op_complete leads to OOPS (LP: #1797314)
        - SAUCE: fscache: Fix race in decrementing refcount of op->npages
      * hns3: autoneg settings get lost on down/up (LP: #1797654)
        - net: hns3: Fix for information of phydev lost problem when down/up
      * not able to unwind the stack from within __kernel_clock_gettime in the Linux
        vDSO (LP: #1797963)
        - powerpc/vdso: Correct call frame information
      * Signal 7 error when running GPFS tracing in cluster (LP: #1792195)
        - powerpc/mm/books3s: Add new pte bit to mark pte temporarily invalid.
        - powerpc/mm/radix: Only need the Nest MMU workaround for R -> RW transition
      * Support Edge Gateway's WIFI LED (LP: #1798330)
        - SAUCE: mwifiex: Switch WiFi LED state according to the device status
      * Support Edge Gateway's Bluetooth LED (LP: #1798332)
        - SAUCE: Bluetooth: Support for LED on Edge Gateways
      * kvm doesn't work on 36 physical bits systems (LP: #1798427)
        - KVM: x86: fix L1TF's MMIO GFN calculation
      * CVE-2018-15471
        - xen-netback: fix input validation in xenvif_set_hash_mapping()
      * regression in 'ip --family bridge neigh' since linux v4.12 (LP: #1796748)
        - rtnetlink: fix rtnl_fdb_dump() for ndmsg header
    
      [ Ubuntu: 4.18.0-10.11 ]
    
      * linux: 4.18.0-10.11 -proposed tracker (LP: #1797379)
      * the machine of lenovo M715 with the AMD GPU (Radeon Vega 8 Mobile, rev ca,
        1002:15dd) often hangs randomly (LP: #1796789)
        - drm/amd: Add missing fields in atom_integrated_system_info_v1_11
      * Miscellaneous Ubuntu changes
        - [Config] CONFIG_VBOXGUEST=n
        - ubuntu: vbox -- update to 5.2.18-dfsg-2
        - ubuntu: enable vbox build
    
     -- Stefan Bader <email address hidden>  Wed, 24 Oct 2018 15:15:41 +0200
  • linux-gcp (4.18.0-1002.3) cosmic; urgency=medium
    
      * linux-gcp: 4.18.0-1002.3 -proposed tracker (LP: #1796351)
    
      * iptables --list --numeric fails on -virtual kernel / -virtual missing
        bpfilter (LP: #1795036)
        - [Config] gcp -- add bpfilter.ko to generic inclusion list
    
      [ Ubuntu: 4.18.0-9.10 ]
    
      * linux: 4.18.0-9.10 -proposed tracker (LP: #1796346)
      * Cosmic update: v4.18.12 upstream stable release (LP: #1796139)
        - crypto: skcipher - Fix -Wstringop-truncation warnings
        - iio: adc: ina2xx: avoid kthread_stop() with stale task_struct
        - tsl2550: fix lux1_input error in low light
        - misc: ibmvmc: Use GFP_ATOMIC under spin lock
        - vmci: type promotion bug in qp_host_get_user_memory()
        - siox: don't create a thread without starting it
        - x86/numa_emulation: Fix emulated-to-physical node mapping
        - staging: rts5208: fix missing error check on call to rtsx_write_register
        - power: supply: axp288_charger: Fix initial constant_charge_current value
        - misc: sram: enable clock before registering regions
        - serial: sh-sci: Stop RX FIFO timer during port shutdown
        - uwb: hwa-rc: fix memory leak at probe
        - power: vexpress: fix corruption in notifier registration
        - iommu/amd: make sure TLB to be flushed before IOVA freed
        - Bluetooth: Add a new Realtek 8723DE ID 0bda:b009
        - USB: serial: kobil_sct: fix modem-status error handling
        - 6lowpan: iphc: reset mac_header after decompress to fix panic
        - iommu/msm: Don't call iommu_device_{,un}link from atomic context
        - s390/mm: correct allocate_pgste proc_handler callback
        - power: remove possible deadlock when unregistering power_supply
        - drm/amd/display/dc/dce: Fix multiple potential integer overflows
        - drm/amd/display: fix use of uninitialized memory
        - md-cluster: clear another node's suspend_area after the copy is finished
        - cxgb4: Fix the condition to check if the card is T5
        - RDMA/bnxt_re: Fix a couple off by one bugs
        - RDMA/i40w: Hold read semaphore while looking after VMA
        - RDMA/bnxt_re: Fix a bunch of off by one bugs in qplib_fp.c
        - IB/core: type promotion bug in rdma_rw_init_one_mr()
        - media: exynos4-is: Prevent NULL pointer dereference in __isp_video_try_fmt()
        - IB/mlx4: Test port number before querying type.
        - powerpc/kdump: Handle crashkernel memory reservation failure
        - media: fsl-viu: fix error handling in viu_of_probe()
        - vhost_net: Avoid tx vring kicks during busyloop
        - media: staging/imx: fill vb2_v4l2_buffer field entry
        - IB/mlx5: Fix GRE flow specification
        - include/rdma/opa_addr.h: Fix an endianness issue
        - x86/tsc: Add missing header to tsc_msr.c
        - ARM: hwmod: RTC: Don't assume lock/unlock will be called with irq enabled
        - x86/entry/64: Add two more instruction suffixes
        - ARM: dts: ls1021a: Add missing cooling device properties for CPUs
        - scsi: target/iscsi: Make iscsit_ta_authentication() respect the output
          buffer size
        - thermal: i.MX: Allow thermal probe to fail gracefully in case of bad
          calibration.
        - scsi: klist: Make it safe to use klists in atomic context
        - scsi: ibmvscsi: Improve strings handling
        - scsi: target: Avoid that EXTENDED COPY commands trigger lock inversion
        - usb: wusbcore: security: cast sizeof to int for comparison
        - ath10k: sdio: use same endpoint id for all packets in a bundle
        - ath10k: sdio: set skb len for all rx packets
        - powerpc/powernv/ioda2: Reduce upper limit for DMA window size
        - platform/x86: asus-wireless: Fix uninitialized symbol usage
        - ACPI / button: increment wakeup count only when notified
        - s390/sysinfo: add missing #ifdef CONFIG_PROC_FS
        - alarmtimer: Prevent overflow for relative nanosleep
        - s390/dasd: correct numa_node in dasd_alloc_queue
        - s390/scm_blk: correct numa_node in scm_blk_dev_setup
        - s390/extmem: fix gcc 8 stringop-overflow warning
        - mtd: rawnand: atmel: add module param to avoid using dma
        - iio: accel: adxl345: convert address field usage in iio_chan_spec
        - posix-timers: Make forward callback return s64
        - posix-timers: Sanitize overrun handling
        - ALSA: snd-aoa: add of_node_put() in error path
        - selftests: forwarding: Tweak tc filters for mirror-to-gretap tests
        - ath10k: use locked skb_dequeue for rx completions
        - media: s3c-camif: ignore -ENOIOCTLCMD from v4l2_subdev_call for s_power
        - media: soc_camera: ov772x: correct setting of banding filter
        - media: omap3isp: zero-initialize the isp cam_xclk{a,b} initial data
        - media: ov772x: add checks for register read errors
        - staging: android: ashmem: Fix mmap size validation
        - media: ov772x: allow i2c controllers without I2C_FUNC_PROTOCOL_MANGLING
        - staging: mt7621-eth: Fix memory leak in mtk_add_mac() error path
        - drivers/tty: add error handling for pcmcia_loop_config
        - arm64: dts: renesas: salvator-common: Fix adv7482 decimal unit addresses
        - serial: pxa: Fix an error handling path in 'serial_pxa_probe()'
        - staging: mt7621-dts: Fix remaining pcie warnings
        - media: tm6000: add error handling for dvb_register_adapter
        - ASoC: qdsp6: qdafe: fix some off by one bugs
        - net: phy: xgmiitorgmii: Check read_status results
        - ath10k: protect ath10k_htt_rx_ring_free with rx_ring.lock
        - drm/sun4i: Enable DW HDMI PHY clock
        - net: phy: xgmiitorgmii: Check phy_driver ready before accessing
        - drm/sun4i: Fix releasing node when enumerating enpoints
        - ath10k: transmit queued frames after processing rx packets
        - mt76x2: fix mrr idx/count estimation in mt76x2_mac_fill_tx_status()
        - rndis_wlan: potential buffer overflow in rndis_wlan_auth_indication()
        - brcmsmac: fix wrap around in conversion from constant to s16
        - bitfield: fix *_encode_bits()
        - wlcore: Add missing PM call for wlcore_cmd_wait_for_event_or_timeout()
        - drm/omap: gem: Fix mm_list locking
        - ARM: mvebu: declare asm symbols as character arrays in pmsu.c
        - RDMA/uverbs: Don't overwrite NULL pointer with ZERO_SIZE_PTR
        - Documentation/process: fix reST table border error
        - perf/hw_breakpoint: Split attribute parse and commit
        - arm: dts: mediatek: Add missing cooling device properties for CPUs
        - HID: hid-ntrig: add error handling for sysfs_create_group
        - HID: i2c-hid: Use devm to allocate i2c_hid struct
        - MIPS: boot: fix build rule of vmlinux.its.S
        - arm64: dts: renesas: Fix VSPD registers range
        - drm/v3d: Take a lock across GPU scheduler job creation and queuing.
        - perf/x86/intel/lbr: Fix incomplete LBR call stack
        - scsi: bnx2i: add error handling for ioremap_nocache
        - iomap: complete partial direct I/O writes synchronously
        - spi: orion: fix CS GPIO handling again
        - scsi: megaraid_sas: Update controller info during resume
        - ASoC: Intel: bytcr_rt5640: Fix Acer Iconia 8 over-current detect threshold
        - ASoC: rt1305: Use ULL suffixes for 64-bit constants
        - ASoC: rsnd: SSI parent cares SWSP bit
        - EDAC, i7core: Fix memleaks and use-after-free on probe and remove
        - ASoC: dapm: Fix potential DAI widget pointer deref when linking DAIs
        - module: exclude SHN_UNDEF symbols from kallsyms api
        - gpio: Fix wrong rounding in gpio-menz127
        - nfsd: fix corrupted reply to badly ordered compound
        - EDAC: Fix memleak in module init error path
        - EDAC, altera: Fix an error handling path in altr_s10_sdram_probe()
        - staging: pi433: fix race condition in pi433_ioctl
        - ath10k: fix incorrect size of dma_free_coherent in
          ath10k_ce_alloc_src_ring_64
        - ath10k: snoc: use correct bus-specific pointer in RX retry
        - fs/lock: skip lock owner pid translation in case we are in init_pid_ns
        - ath10k: fix memory leak of tpc_stats
        - Input: xen-kbdfront - fix multi-touch XenStore node's locations
        - iio: 104-quad-8: Fix off-by-one error in register selection
        - drm/vc4: Add missing formats to vc4_format_mod_supported().
        - ARM: dts: dra7: fix DCAN node addresses
        - drm/vc4: plane: Expand the lower bits by repeating the higher bits
        - perf tests: Fix indexing when invoking subtests
        - gpio: tegra: Fix tegra_gpio_irq_set_type()
        - block: fix deadline elevator drain for zoned block devices
        - x86/mm: Expand static page table for fixmap space
        - tty: serial: lpuart: avoid leaking struct tty_struct
        - serial: imx: restore handshaking irq for imx1
        - serial: mvebu-uart: Fix reporting of effective CSIZE to userspace
        - serial: cpm_uart: return immediately from console poll
        - intel_th: Fix device removal logic
        - intel_th: Fix resource handling for ACPI glue layer
        - spi: tegra20-slink: explicitly enable/disable clock
        - spi: sh-msiof: Fix invalid SPI use during system suspend
        - spi: sh-msiof: Fix handling of write value for SISTR register
        - spi: rspi: Fix invalid SPI use during system suspend
        - spi: rspi: Fix interrupted DMA transfers
        - regulator: fix crash caused by null driver data
        - regulator: Fix 'do-nothing' value for regulators without suspend state
        - USB: fix error handling in usb_driver_claim_interface()
        - USB: handle NULL config in usb_find_alt_setting()
        - usb: roles: Take care of driver module reference counting
        - usb: musb: dsps: do not disable CPPI41 irq in driver teardown
        - USB: usbdevfs: sanitize flags more
        - USB: usbdevfs: restore warning for nonsensical flags
        - Revert "usb: cdc-wdm: Fix a sleep-in-atomic-context bug in
          service_outstanding_interrupt()"
        - USB: remove LPM management from usb_driver_claim_interface()
        - uaccess: Fix is_source param for check_copy_size() in copy_to_iter_mcsafe()
        - ext2, dax: set ext2_dax_aops for dax files
        - filesystem-dax: Fix use of zero page
        - IB/srp: Avoid that sg_reset -d ${srp_device} triggers an infinite loop
        - IB/hfi1: Fix SL array bounds check
        - IB/hfi1: Invalid user input can result in crash
        - IB/hfi1: Fix context recovery when PBC has an UnsupportedVL
        - IB/hfi1: Fix destroy_qp hang after a link down
        - ACPI / hotplug / PCI: Don't scan for non-hotplug bridges if slot is not
          bridge
        - RDMA/uverbs: Atomically flush and mark closed the comp event queue
        - arm64: KVM: Tighten guest core register access from userspace
        - ARM: OMAP2+: Fix null hwmod for ti-sysc debug
        - ARM: OMAP2+: Fix module address for modules using mpu_rt_idx
        - bus: ti-sysc: Fix module register ioremap for larger offsets
        - qed: Wait for ready indication before rereading the shmem
        - qed: Wait for MCP halt and resume commands to take place
        - qed: Prevent a possible deadlock during driver load and unload
        - qed: Avoid sending mailbox commands when MFW is not responsive
        - thermal: of-thermal: disable passive polling when thermal zone is disabled
        - isofs: reject hardware sector size > 2048 bytes
        - mmc: atmel-mci: fix bad logic of sg_copy_{from,to}_buffer conversion
        - mmc: android-goldfish: fix bad logic of sg_copy_{from,to}_buffer conversion
        - bus: ti-sysc: Fix no_console_suspend handling
        - ARM: dts: omap4-droid4: fix vibrations on Droid 4
        - bpf, sockmap: fix sock_hash_alloc and reject zero-sized keys
        - bpf, sockmap: fix sock hash count in alloc_sock_hash_elem
        - tls: possible hang when do_tcp_sendpages hits sndbuf is full case
        - bpf: sockmap: write_space events need to be passed to TCP handler
        - drm/amdgpu: fix VM clearing for the root PD
        - drm/amdgpu: fix preamble handling
        - amdgpu: fix multi-process hang issue
        - net/ncsi: Fixup .dumpit message flags and ID check in Netlink handler
        - tcp_bbr: add bbr_check_probe_rtt_done() helper
        - tcp_bbr: in restart from idle, see if we should exit PROBE_RTT
        - net: hns: fix length and page_offset overflow when CONFIG_ARM64_64K_PAGES
        - net: hns: fix skb->truesize underestimation
        - net: hns3: fix page_offset overflow when CONFIG_ARM64_64K_PAGES
        - ice: Fix multiple static analyser warnings
        - ice: Report stats for allocated queues via ethtool stats
        - ice: Clean control queues only when they are initialized
        - ice: Fix bugs in control queue processing
        - ice: Use order_base_2 to calculate higher power of 2
        - ice: Set VLAN flags correctly
        - tools: bpftool: return from do_event_pipe() on bad arguments
        - ice: Fix a few null pointer dereference issues
        - ice: Fix potential return of uninitialized value
        - e1000: check on netif_running() before calling e1000_up()
        - e1000: ensure to free old tx/rx rings in set_ringparam()
        - ixgbe: fix driver behaviour after issuing VFLR
        - i40e: Fix for Tx timeouts when interface is brought up if DCB is enabled
        - i40e: fix condition of WARN_ONCE for stat strings
        - crypto: chtls - fix null dereference chtls_free_uld()
        - crypto: cavium/nitrox - fix for command corruption in queue full case with
          backlog submissions.
        - hwmon: (ina2xx) fix sysfs shunt resistor read access
        - hwmon: (adt7475) Make adt7475_read_word() return errors
        - Revert "ARM: dts: imx7d: Invert legacy PCI irq mapping"
        - drm/amdgpu: Enable/disable gfx PG feature in rlc safe mode
        - drm/amdgpu: Update power state at the end of smu hw_init.
        - ata: ftide010: Add a quirk for SQ201
        - nvme-fcloop: Fix dropped LS's to removed target port
        - ARM: dts: omap4-droid4: Fix emmc errors seen on some devices
        - drm/amdgpu: Need to set moved to true when evict bo
        - arm/arm64: smccc-1.1: Make return values unsigned long
        - arm/arm64: smccc-1.1: Handle function result as parameters
        - i2c: i801: Allow ACPI AML access I/O ports not reserved for SMBus
        - clk: x86: Set default parent to 48Mhz
        - x86/pti: Fix section mismatch warning/error
        - KVM: PPC: Book3S HV: Fix guest r11 corruption with POWER9 TM workarounds
        - powerpc: fix csum_ipv6_magic() on little endian platforms
        - powerpc/pkeys: Fix reading of ibm, processor-storage-keys property
        - powerpc/pseries: Fix unitialized timer reset on migration
        - arm64: KVM: Sanitize PSTATE.M when being set from userspace
        - media: v4l: event: Prevent freeing event subscriptions while accessed
        - Linux 4.18.12
      * Fix usbcore.quirks when used at boot (LP: #1795784)
        - usb: core: safely deal with the dynamic quirk lists
      * Dell new AIO requires a new uart backlight driver (LP: #1727235)
        - SAUCE: platform/x86: dell-uart-backlight: new backlight driver for DELL AIO
        - updateconfigs for Dell UART backlight driver
      * Please make CONFIG_PWM_LPSS_PCI and CONFIG_PWM_LPSS_PLATFORM built in to
        make brightness adjustment working on various BayTrail/CherryTrail-based
        devices (LP: #1783964)
        - [Config]: Make PWM_LPSS_* built-in
      * CVE-2018-5391
        - SAUCE: Revert "net: increase fragment memory usage limits"
      * check and fix zkey required kernel modules locations in debs, udebs, and
        initramfs (LP: #1794346)
        - [Config] add s390 crypto modules to crypt-modules udeb
      * iptables --list --numeric fails on -virtual kernel / -virtual missing
        bpfilter (LP: #1795036)
        - [Config] add bpfilter.ko to generic inclusion list
      * fails to build  on armhf because of module rename (LP: #1795665)
        - [Config] omapfb was renamed to omap2fb
      * qeth: use vzalloc for QUERY OAT buffer (LP: #1793086)
        - s390/qeth: use vzalloc for QUERY OAT buffer
      * Cosmic update to 4.18.11 stable release (LP: #1795486)
        - gso_segment: Reset skb->mac_len after modifying network header
        - ipv6: fix possible use-after-free in ip6_xmit()
        - net/appletalk: fix minor pointer leak to userspace in SIOCFINDIPDDPRT
        - net: hp100: fix always-true check for link up state
        - pppoe: fix reception of frames with no mac header
        - qmi_wwan: set DTR for modems in forced USB2 mode
        - udp4: fix IP_CMSG_CHECKSUM for connected sockets
        - tls: don't copy the key out of tls12_crypto_info_aes_gcm_128
        - tls: zero the crypto information from tls_context before freeing
        - tls: clear key material from kernel memory when do_tls_setsockopt_conf fails
        - neighbour: confirm neigh entries when ARP packet is received
        - udp6: add missing checks on edumux packet processing
        - net/sched: act_sample: fix NULL dereference in the data path
        - hv_netvsc: fix schedule in RCU context
        - net: dsa: mv88e6xxx: Fix ATU Miss Violation
        - socket: fix struct ifreq size in compat ioctl
        - tls: fix currently broken MSG_PEEK behavior
        - ipv6: use rt6_info members when dst is set in rt6_fill_node
        - net/ipv6: do not copy dst flags on rt init
        - net: mvpp2: let phylink manage the carrier state
        - net: rtnl_configure_link: fix dev flags changes arg to __dev_notify_flags
        - NFC: Fix possible memory corruption when handling SHDLC I-Frame commands
        - NFC: Fix the number of pipes
        - ASoC: wm9712: fix replace codec to component
        - ASoC: cs4265: fix MMTLR Data switch control
        - ASoC: tas6424: Save last fault register even when clear
        - ASoC: rsnd: fixup not to call clk_get/set under non-atomic
        - ASoC: uapi: fix sound/skl-tplg-interface.h userspace compilation errors
        - ALSA: bebob: fix memory leak for M-Audio FW1814 and ProjectMix I/O at error
          path
        - ALSA: bebob: use address returned by kmalloc() instead of kernel stack for
          streaming DMA mapping
        - ALSA: emu10k1: fix possible info leak to userspace on
          SNDRV_EMU10K1_IOCTL_INFO
        - ALSA: fireface: fix memory leak in ff400_switch_fetching_mode()
        - ALSA: firewire-digi00x: fix memory leak of private data
        - ALSA: firewire-tascam: fix memory leak of private data
        - ALSA: fireworks: fix memory leak of response buffer at error path
        - ALSA: oxfw: fix memory leak for model-dependent data at error path
        - ALSA: oxfw: fix memory leak of discovered stream formats at error path
        - ALSA: oxfw: fix memory leak of private data
        - mtd: devices: m25p80: Make sure the buffer passed in op is DMA-able
        - mtd: rawnand: denali: fix a race condition when DMA is kicked
        - platform/x86: dell-smbios-wmi: Correct a memory leak
        - platform/x86: alienware-wmi: Correct a memory leak
        - xen/netfront: don't bug in case of too many frags
        - xen/x86/vpmu: Zero struct pt_regs before calling into sample handling code
        - spi: fix IDR collision on systems with both fixed and dynamic SPI bus
          numbers
        - Revert "PCI: Add ACS quirk for Intel 300 series"
        - ring-buffer: Allow for rescheduling when removing pages
        - crypto: x86/aegis,morus - Do not require OSXSAVE for SSE2
        - fork: report pid exhaustion correctly
        - mm: disable deferred struct page for 32-bit arches
        - mm: shmem.c: Correctly annotate new inodes for lockdep
        - Revert "rpmsg: core: add support to power domains for devices"
        - bpf/verifier: disallow pointer subtraction
        - Revert "uapi/linux/keyctl.h: don't use C++ reserved keyword as a struct
          member name"
        - scsi: target: iscsi: Use bin2hex instead of a re-implementation
        - Revert "ubifs: xattr: Don't operate on deleted inodes"
        - libata: mask swap internal and hardware tag
        - ocfs2: fix ocfs2 read block panic
        - drm/i915/bdw: Increase IPS disable timeout to 100ms
        - drm/nouveau: Reset MST branching unit before enabling
        - drm/nouveau: Only write DP_MSTM_CTRL when needed
        - drm/nouveau: Remove duplicate poll_enable() in pmops_runtime_suspend()
        - drm/nouveau: Fix deadlocks in nouveau_connector_detect()
        - drm/nouveau/drm/nouveau: Don't forget to cancel hpd_work on suspend/unload
        - drm/nouveau/drm/nouveau: Fix bogus drm_kms_helper_poll_enable() placement
        - drm/nouveau/drm/nouveau: Fix deadlock with fb_helper with async RPM requests
        - drm/nouveau/drm/nouveau: Use pm_runtime_get_noresume() in connector_detect()
        - drm/nouveau/drm/nouveau: Prevent handling ACPI HPD events too early
        - drm/vc4: Fix the "no scaling" case on multi-planar YUV formats
        - drm: udl: Destroy framebuffer only if it was initialized
        - drm/amdgpu: add new polaris pci id
        - tty: vt_ioctl: fix potential Spectre v1
        - ext4: check to make sure the rename(2)'s destination is not freed
        - ext4: avoid divide by zero fault when deleting corrupted inline directories
        - ext4: avoid arithemetic overflow that can trigger a BUG
        - ext4: recalucate superblock checksum after updating free blocks/inodes
        - ext4: fix online resize's handling of a too-small final block group
        - ext4: fix online resizing for bigalloc file systems with a 1k block size
        - ext4: don't mark mmp buffer head dirty
        - ext4: show test_dummy_encryption mount option in /proc/mounts
        - ext4, dax: add ext4_bmap to ext4_dax_aops
        - ext4, dax: set ext4_dax_aops for dax files
        - sched/fair: Fix vruntime_normalized() for remote non-migration wakeup
        - vmw_balloon: include asm/io.h
        - iw_cxgb4: only allow 1 flush on user qps
        - spi: Fix double IDR allocation with DT aliases
        - Linux 4.18.11
      * CVE-2018-14633
        - scsi: target: iscsi: Use hex2bin instead of a re-implementation
      * Cosmic update to 4.18.10 stable release (LP: #1794597)
        - be2net: Fix memory leak in be_cmd_get_profile_config()
        - net/mlx5: Fix use-after-free in self-healing flow
        - net: qca_spi: Fix race condition in spi transfers
        - rds: fix two RCU related problems
        - tipc: orphan sock in tipc_release()
        - net/mlx5: E-Switch, Fix memory leak when creating switchdev mode FDB tables
        - net/tls: Set count of SG entries if sk_alloc_sg returns -ENOSPC
        - net/mlx5: Check for error in mlx5_attach_interface
        - net/mlx5: Fix debugfs cleanup in the device init/remove flow
        - erspan: fix error handling for erspan tunnel
        - erspan: return PACKET_REJECT when the appropriate tunnel is not found
        - tcp: really ignore MSG_ZEROCOPY if no SO_ZEROCOPY
        - net/mlx5: Fix not releasing read lock when adding flow rules
        - net/mlx5: Fix possible deadlock from lockdep when adding fte to fg
        - net/mlx5: Use u16 for Work Queue buffer fragment size
        - usb: dwc3: change stream event enable bit back to 13
        - iommu/arm-smmu-v3: sync the OVACKFLG to PRIQ consumer register
        - iommu/io-pgtable-arm-v7s: Abort allocation when table address overflows the
          PTE
        - iommu/io-pgtable-arm: Fix pgtable allocation in selftest
        - ALSA: msnd: Fix the default sample sizes
        - ALSA: usb-audio: Add support for Encore mDSD USB DAC
        - ALSA: usb-audio: Fix multiple definitions in AU0828_DEVICE() macro
        - xfrm: fix 'passing zero to ERR_PTR()' warning
        - amd-xgbe: use dma_mapping_error to check map errors
        - nfp: don't fail probe on pci_sriov_set_totalvfs() errors
        - iwlwifi: cancel the injective function between hw pointers to tfd entry
          index
        - gfs2: Special-case rindex for gfs2_grow
        - clk: imx6ul: fix missing of_node_put()
        - clk: imx6sll: fix missing of_node_put()
        - clk: mvebu: armada-37xx-periph: Fix wrong return value in get_parent
        - Input: pxrc - fix freeing URB on device teardown
        - clk: core: Potentially free connection id
        - clk: clk-fixed-factor: Clear OF_POPULATED flag in case of failure
        - kbuild: add .DELETE_ON_ERROR special target
        - kbuild: do not update config when running install targets
        - media: tw686x: Fix oops on buffer alloc failure
        - dmaengine: pl330: fix irq race with terminate_all
        - MIPS: ath79: fix system restart
        - media: videobuf2-core: check for q->error in vb2_core_qbuf()
        - IB/rxe: Drop QP0 silently
        - block: allow max_discard_segments to be stacked
        - IB/ipoib: Fix error return code in ipoib_dev_init()
        - mtd/maps: fix solutionengine.c printk format warnings
        - media: ov5645: Supported external clock is 24MHz
        - perf test: Fix subtest number when showing results
        - gfs2: Don't reject a supposedly full bitmap if we have blocks reserved
        - perf tools: Synthesize GROUP_DESC feature in pipe mode
        - perf tests: Fix record+probe_libc_inet_pton.sh for powerpc64
        - perf tests: Fix record+probe_libc_inet_pton.sh when event exists
        - perf tests: Fix record+probe_libc_inet_pton.sh to ensure cleanups
        - fbdev: omapfb: off by one in omapfb_register_client()
        - perf tools: Fix struct comm_str removal crash
        - video: goldfishfb: fix memory leak on driver remove
        - fbdev/via: fix defined but not used warning
        - perf powerpc: Fix callchain ip filtering when return address is in a
          register
        - video: fbdev: pxafb: clear allocated memory for video modes
        - fbdev: Distinguish between interlaced and progressive modes
        - omapfb: rename omap2 module to omap2fb.ko
        - ARM: exynos: Clear global variable on init error path
        - perf powerpc: Fix callchain ip filtering
        - nvmet: fix file discard return status
        - nvme-rdma: unquiesce queues when deleting the controller
        - KVM: arm/arm64: vgic: Fix possible spectre-v1 write in vgic_mmio_write_apr()
        - powerpc/powernv: opal_put_chars partial write fix
        - perf script: Show correct offsets for DWARF-based unwinding
        - staging: bcm2835-camera: fix timeout handling in wait_for_completion_timeout
        - staging: bcm2835-camera: handle wait_for_completion_timeout return properly
        - ASoC: rt5514: Fix the issue of the delay volume applied
        - MIPS: jz4740: Bump zload address
        - mac80211: restrict delayed tailroom needed decrement
        - Smack: Fix handling of IPv4 traffic received by PF_INET6 sockets
        - wan/fsl_ucc_hdlc: use IS_ERR_VALUE() to check return value of qe_muram_alloc
        - arm64: fix possible spectre-v1 write in ptrace_hbp_set_event()
        - reset: imx7: Fix always writing bits as 0
        - ALSA: usb-audio: Generic DSD detection for Thesycon-based implementations
        - nfp: avoid buffer leak when FW communication fails
        - xen-netfront: fix queue name setting
        - arm64: dts: qcom: db410c: Fix Bluetooth LED trigger
        - ARM: dts: qcom: msm8974-hammerhead: increase load on l20 for sdhci
        - soc: qcom: smem: Correct check for global partition
        - s390/qeth: fix race in used-buffer accounting
        - s390/qeth: reset layer2 attribute on layer switch
        - platform/x86: toshiba_acpi: Fix defined but not used build warnings
        - KVM: arm/arm64: Fix vgic init race
        - drivers/base: stop new probing during shutdown
        - i2c: aspeed: Fix initial values of master and slave state
        - drm/amd/pp: Set Max clock level to display by default
        - regulator: qcom_spmi: Use correct regmap when checking for error
        - regulator: qcom_spmi: Fix warning Bad of_node_put()
        - iommu/ipmmu-vmsa: IMUCTRn.TTSEL needs a special usage on R-Car Gen3
        - dmaengine: mv_xor_v2: kill the tasklets upon exit
        - crypto: sharah - Unregister correct algorithms for SAHARA 3
        - x86/pti: Check the return value of pti_user_pagetable_walk_p4d()
        - x86/pti: Check the return value of pti_user_pagetable_walk_pmd()
        - x86/mm/pti: Add an overflow check to pti_clone_pmds()
        - PCI/AER: Honor "pcie_ports=native" even if HEST sets FIRMWARE_FIRST
        - xen-netfront: fix warn message as irq device name has '/'
        - RDMA/cma: Protect cma dev list with lock
        - pstore: Fix incorrect persistent ram buffer mapping
        - xen/netfront: fix waiting for xenbus state change
        - IB/ipoib: Avoid a race condition between start_xmit and cm_rep_handler
        - mmc: omap_hsmmc: fix wakeirq handling on removal
        - ipmi: Rework SMI registration failure
        - ipmi: Move BT capabilities detection to the detect call
        - ipmi: Fix I2C client removal in the SSIF driver
        - ovl: fix oopses in ovl_fill_super() failure paths
        - vmbus: don't return values for uninitalized channels
        - Tools: hv: Fix a bug in the key delete code
        - misc: ibmvsm: Fix wrong assignment of return code
        - misc: hmc6352: fix potential Spectre v1
        - xhci: Fix use after free for URB cancellation on a reallocated endpoint
        - usb: Don't die twice if PCI xhci host is not responding in resume
        - usb: xhci: fix interrupt transfer error happened on MTK platforms
        - usb: mtu3: fix error of xhci port id when enable U3 dual role
        - mei: ignore not found client in the enumeration
        - mei: bus: fix hw module get/put balance
        - mei: bus: need to unlink client before freeing
        - dm verity: fix crash on bufio buffer that was allocated with vmalloc
        - USB: Add quirk to support DJI CineSSD
        - usb: uas: add support for more quirk flags
        - usb: Avoid use-after-free by flushing endpoints early in usb_set_interface()
        - usb: host: u132-hcd: Fix a sleep-in-atomic-context bug in u132_get_frame()
        - USB: add quirk for WORLDE Controller KS49 or Prodipe MIDI 49C USB controller
        - usb: gadget: udc: renesas_usb3: fix maxpacket size of ep0
        - USB: net2280: Fix erroneous synchronization change
        - USB: serial: io_ti: fix array underflow in completion handler
        - usb: misc: uss720: Fix two sleep-in-atomic-context bugs
        - USB: serial: ti_usb_3410_5052: fix array underflow in completion handler
        - USB: yurex: Fix buffer over-read in yurex_write()
        - usb: cdc-wdm: Fix a sleep-in-atomic-context bug in
          service_outstanding_interrupt()
        - Revert "cdc-acm: implement put_char() and flush_chars()"
        - cifs: prevent integer overflow in nxt_dir_entry()
        - CIFS: fix wrapping bugs in num_entries()
        - cifs: integer overflow in in SMB2_ioctl()
        - xtensa: ISS: don't allocate memory in platform_setup
        - perf/core: Force USER_DS when recording user stack data
        - perf tools: Fix maps__find_symbol_by_name()
        - of: fix phandle cache creation for DTs with no phandles
        - x86/EISA: Don't probe EISA bus for Xen PV guests
        - NFSv4: Fix a tracepoint Oops in initiate_file_draining()
        - NFSv4.1 fix infinite loop on I/O.
        - of: add helper to lookup compatible child node
        - mmc: meson-mx-sdio: fix OF child-node lookup
        - binfmt_elf: Respect error return from `regset->active'
        - net/mlx5: Add missing SET_DRIVER_VERSION command translation
        - arm64: dts: uniphier: Add missing cooling device properties for CPUs
        - audit: fix use-after-free in audit_add_watch
        - mtdchar: fix overflows in adjustment of `count`
        - vfs: fix freeze protection in mnt_want_write_file() for overlayfs
        - bpf: fix rcu annotations in compute_effective_progs()
        - spi: dw: fix possible race condition
        - Bluetooth: Use lock_sock_nested in bt_accept_enqueue
        - evm: Don't deadlock if a crypto algorithm is unavailable
        - KVM: PPC: Book3S HV: Add of_node_put() in success path
        - security: check for kstrdup() failure in lsm_append()
        - PM / devfreq: use put_device() instead of kfree()
        - KVM: PPC: Book3S: Fix matching of hardware and emulated TCE tables
        - MIPS: loongson64: cs5536: Fix PCI_OHCI_INT_REG reads
        - configfs: fix registered group removal
        - pinctrl: mt7622: Fix probe fail by misuse the selector
        - pinctrl: rza1: Fix selector use for groups and functions
        - arm64: dts: mt7622: update a clock property for UART0
        - sched/core: Use smp_mb() in wake_woken_function()
        - efi/esrt: Only call efi_mem_reserve() for boot services memory
        - ARM: hisi: handle of_iomap and fix missing of_node_put
        - ARM: hisi: fix error handling and missing of_node_put
        - ARM: hisi: check of_iomap and fix missing of_node_put
        - liquidio: fix hang when re-binding VF host drv after running DPDK VF driver
        - gpu: ipu-v3: csi: pass back mbus_code_to_bus_cfg error codes
        - ASoC: hdmi-codec: fix routing
        - serial: 8250: of: Correct of_platform_serial_setup() error handling
        - tty: fix termios input-speed encoding when using BOTHER
        - tty: fix termios input-speed encoding
        - mmc: sdhci-of-esdhc: set proper dma mask for ls104x chips
        - mmc: tegra: prevent HS200 on Tegra 3
        - mmc: sdhci: do not try to use 3.3V signaling if not supported
        - drm/nouveau: Fix runtime PM leak in drm_open()
        - drm/nouveau/debugfs: Wake up GPU before doing any reclocking
        - drm/nouveau: tegra: Detach from ARM DMA/IOMMU mapping
        - tls: Fix zerocopy_from_iter iov handling
        - parport: sunbpp: fix error return code
        - sched/fair: Fix util_avg of new tasks for asymmetric systems
        - coresight: Handle errors in finding input/output ports
        - coresight: tpiu: Fix disabling timeouts
        - coresight: ETM: Add support for Arm Cortex-A73 and Cortex-A35
        - f2fs: do checkpoint in kill_sb
        - tools/testing/nvdimm: Fix support for emulating controller temperature
        - drm/amd/display: support access ddc for mst branch
        - ASoC: qdsp6: q6afe-dai: fix a range check in of_q6afe_parse_dai_data()
        - lightnvm: pblk: assume that chunks are closed on 1.2 devices
        - lightnvm: pblk: enable line minor version detection
        - staging: bcm2835-audio: Don't leak workqueue if open fails
        - gpio: pxa: Fix potential NULL dereference
        - gpiolib: Mark gpio_suffixes array with __maybe_unused
        - net: gemini: Allow multiple ports to instantiate
        - net: mvpp2: make sure we use single queue mode on PPv2.1
        - rcutorture: Use monotonic timestamp for stall detection
        - mfd: 88pm860x-i2c: switch to i2c_lock_bus(..., I2C_LOCK_SEGMENT)
        - input: rohm_bu21023: switch to i2c_lock_bus(..., I2C_LOCK_SEGMENT)
        - drm/amdkfd: Fix kernel queue 64 bit doorbell offset calculation
        - drm/amdkfd: Fix error codes in kfd_get_process
        - rtc: bq4802: add error handling for devm_ioremap
        - selftests: vDSO - fix to return KSFT_SKIP when test couldn't be run
        - selftests/android: initialize heap_type to avoid compiling warning
        - ALSA: pcm: Fix snd_interval_refine first/last with open min/max
        - scsi: libfc: fixup 'sleeping function called from invalid context'
        - scsi: lpfc: Fix NVME Target crash in defer rcv logic
        - scsi: lpfc: Fix panic if driver unloaded when port is offline
        - remoteproc: qcom: q6v5-pil: fix modem hang on SDM845 after axis2 clk unvote
        - selftest: timers: Tweak raw_skew to SKIP when ADJ_OFFSET/other clock
          adjustments are in progress
        - ASoC: rt5651: Fix workqueue cancel vs irq free race on remove
        - drm/panel: type promotion bug in s6e8aa0_read_mtp_id()
        - arm64: perf: Disable PMU while processing counter overflows
        - drm/amd/pp: Send khz clock values to DC for smu7/8
        - dmaengine: sh: rcar-dmac: avoid to write CHCR.TE to 1 if TCR is set to 0
        - staging: fsl-dpaa2/eth: Fix DMA mapping direction
        - block/DAC960.c: fix defined but not used build warnings
        - IB/mlx5: fix uaccess beyond "count" in debugfs read/write handlers
        - blk-mq: only attempt to merge bio if there is rq in sw queue
        - blk-mq: avoid to synchronize rcu inside blk_cleanup_queue()
        - pinctrl: msm: Fix msm_config_group_get() to be compliant
        - pinctrl: qcom: spmi-gpio: Fix pmic_gpio_config_get() to be compliant
        - clk: tegra: bpmp: Don't crash when a clock fails to register
        - mei: bus: type promotion bug in mei_nfc_if_version()
        - crypto: ccp - add timeout support in the SEV command
        - Linux 4.18.10
      * Fix MCE handling for user access of poisoned device-dax mapping
        (LP: #1774366)
        - x86/mce: Fix set_mce_nospec() to avoid #GP fault
      * [Ubuntu] s390/crypto: Fix return code checking in cbc_paes_crypt.
        (LP: #1794294)
        - s390/crypto: Fix return code checking in cbc_paes_crypt()
      * Oracle cosmic image does not find broadcom network device in Shape
        VMStandard2.1 (LP: #1790652)
        - SAUCE: bnxt_en: Fix VF mac address regression.
      * Page leaking in cachefiles_read_backing_file while vmscan is active
        (LP: #1793430)
        - SAUCE: cachefiles: Page leaking in cachefiles_read_backing_file while vmscan
          is active
      * hns3: enable ethtool rx-vlan-filter on supported hw (LP: #1793394)
        - net: hns3: Add vlan filter setting by ethtool command -K
      * hns3: Modifying channel parameters will reset ring parameters back to
        defaults (LP: #1793404)
        - net: hns3: Fix desc num set to default when setting channel
      * hisi_sas: Add SATA FIX check for v3 hw (LP: #1794151)
        - scsi: hisi_sas: Add SATA FIS check for v3 hw
      * Fix potential corruption using SAS controller on HiSilicon arm64 boards
        (LP: #1794156)
        - scsi: hisi_sas: add memory barrier in task delivery function
      * hisi_sas: Reduce unnecessary spin lock contention (LP: #1794165)
        - scsi: hisi_sas: Tidy hisi_sas_task_prep()
      * Add functional level reset support for the SAS controller on HiSilicon D06
        systems (LP: #1794166)
        - scsi: hisi_sas: tidy host controller reset function a bit
        - scsi: hisi_sas: relocate some common code for v3 hw
        - scsi: hisi_sas: Implement handlers of PCIe FLR for v3 hw
      * HiSilicon SAS controller doesn't recover from PHY STP link timeout
        (LP: #1794172)
        - scsi: hisi_sas: tidy channel interrupt handler for v3 hw
        - scsi: hisi_sas: Fix the failure of recovering PHY from STP link timeout
      * Cosmic update to 4.18.9 stable release (LP: #1793682)
        - i2c: xiic: Make the start and the byte count write atomic
        - i2c: i801: fix DNV's SMBCTRL register offset
        - HID: multitouch: fix Elan panels with 2 input modes declaration
        - HID: core: fix grouping by application
        - HID: input: fix leaking custom input node name
        - mm/hugetlb: filter out hugetlb pages if HUGEPAGE migration is not supported.
        - memory_hotplug: fix kernel_panic on offline page processing
        - mac80211: don't update the PM state of a peer upon a multicast frame
        - scsi: lpfc: Correct MDS diag and nvmet configuration
        - nbd: don't allow invalid blocksize settings
        - block: don't warn when doing fsync on read-only devices
        - block: bfq: swap puts in bfqg_and_blkg_put
        - android: binder: fix the race mmap and alloc_new_buf_locked
        - MIPS: VDSO: Match data page cache colouring when D$ aliases
        - SMB3: Backup intent flag missing for directory opens with backupuid mounts
        - smb3: check for and properly advertise directory lease support
        - cifs: connect to servername instead of IP for IPC$ share
        - btrfs: fix qgroup_free wrong num_bytes in btrfs_subvolume_reserve_metadata
        - Btrfs: fix data corruption when deduplicating between different files
        - arm64: KVM: Only force FPEXC32_EL2.EN if trapping FPSIMD
        - KVM: arm/arm64: Clean dcache to PoC when changing PTE due to CoW
        - KVM: PPC: Book3S HV: Use correct pagesize in kvm_unmap_radix()
        - KVM: s390: vsie: copy wrapping keys to right place
        - KVM: x86: SVM: Set EMULTYPE_NO_REEXECUTE for RSM emulation
        - KVM: VMX: Do not allow reexecute_instruction() when skipping MMIO instr
        - KVM: x86: Invert emulation re-execute behavior to make it opt-in
        - KVM: x86: Merge EMULTYPE_RETRY and EMULTYPE_ALLOW_REEXECUTE
        - KVM: x86: Default to not allowing emulation retry in kvm_mmu_page_fault
        - KVM: x86: Do not re-{try,execute} after failed emulation in L2
        - ARC: [plat-axs*/plat-hsdk]: Allow U-Boot to pass MAC-address to the kernel
        - ACPI / LPSS: Force LPSS quirks on boot
        - memory: ti-aemif: fix a potential NULL-pointer dereference
        - ALSA: hda - Fix cancel_work_sync() stall from jackpoll work
        - cpu/hotplug: Adjust misplaced smb() in cpuhp_thread_fun()
        - cpu/hotplug: Prevent state corruption on error rollback
        - x86/microcode: Make sure boot_cpu_data.microcode is up-to-date
        - x86/microcode: Update the new microcode revision unconditionally
        - x86/process: Don't mix user/kernel regs in 64bit __show_regs()
        - x86/apic/vector: Make error return value negative
        - switchtec: Fix Spectre v1 vulnerability
        - ARC: [plat-axs*]: Enable SWAP
        - tc-testing: flush gact actions on test teardown
        - tc-testing: remove duplicate spaces in connmark match patterns
        - misc: mic: SCIF Fix scif_get_new_port() error handling
        - ALSA: hda/realtek - Add mute LED quirk for HP Spectre x360
        - ethtool: Remove trailing semicolon for static inline
        - i2c: aspeed: Add an explicit type casting for *get_clk_reg_val
        - Bluetooth: h5: Fix missing dependency on BT_HCIUART_SERDEV
        - pinctrl: berlin: fix 'pctrl->functions' allocation in
          berlin_pinctrl_build_state
        - gpio: tegra: Move driver registration to subsys_init level
        - powerpc/4xx: Fix error return path in ppc4xx_msi_probe()
        - selftests/bpf: fix a typo in map in map test
        - media: davinci: vpif_display: Mix memory leak on probe error path
        - media: dw2102: Fix memleak on sequence of probes
        - net: phy: Fix the register offsets in Broadcom iProc mdio mux driver
        - scsi: qla2xxx: Fix unintended Logout
        - scsi: qla2xxx: Fix session state stuck in Get Port DB
        - scsi: qla2xxx: Silent erroneous message
        - clk: scmi: Fix the rounding of clock rate
        - blk-mq: fix updating tags depth
        - scsi: lpfc: Fix driver crash when re-registering NVME rports.
        - scsi: target: fix __transport_register_session locking
        - md/raid5: fix data corruption of replacements after originals dropped
        - timers: Clear timer_base::must_forward_clk with timer_base::lock held
        - media: camss: csid: Configure data type and decode format properly
        - gpu: ipu-v3: default to id 0 on missing OF alias
        - misc: ti-st: Fix memory leak in the error path of probe()
        - uio: potential double frees if __uio_register_device() fails
        - firmware: vpd: Fix section enabled flag on vpd_section_destroy
        - Drivers: hv: vmbus: Cleanup synic memory free path
        - tty: rocket: Fix possible buffer overwrite on register_PCI
        - uio: fix possible circular locking dependency
        - iwlwifi: pcie: don't access periphery registers when not available
        - IB/IPoIB: Set ah valid flag in multicast send flow
        - f2fs: fix to active page in lru list for read path
        - f2fs: do not set free of current section
        - f2fs: Keep alloc_valid_block_count in sync
        - f2fs: issue discard align to section in LFS mode
        - f2fs: fix defined but not used build warnings
        - f2fs: fix to detect looped node chain correctly
        - ASoC: soc-pcm: Use delay set in component pointer function
        - perf tools: Allow overriding MAX_NR_CPUS at compile time
        - device-dax: avoid hang on error before devm_memremap_pages()
        - NFSv4.0 fix client reference leak in callback
        - perf c2c report: Fix crash for empty browser
        - perf evlist: Fix error out while applying initial delay and LBR
        - powerpc/pseries: fix EEH recovery of some IOV devices
        - macintosh/via-pmu: Add missing mmio accessors
        - perf build: Fix installation directory for eBPF
        - ath9k: report tx status on EOSP
        - ath9k_hw: fix channel maximum power level test
        - ath10k: prevent active scans on potential unusable channels
        - wlcore: Set rx_status boottime_ns field on rx
        - rpmsg: core: add support to power domains for devices
        - mtd: rawnand: make subop helpers return unsigned values
        - scsi: tcmu: do not set max_blocks if data_bitmap has been setup
        - MIPS: Fix ISA virt/bus conversion for non-zero PHYS_OFFSET
        - ata: libahci: Allow reconfigure of DEVSLP register
        - ata: libahci: Correct setting of DEVSLP register
        - nfs: Referrals not inheriting proto setting from parent
        - scsi: 3ware: fix return 0 on the error path of probe
        - tools/testing/nvdimm: kaddr and pfn can be NULL to ->direct_access()
        - ath10k: disable bundle mgmt tx completion event support
        - media: em28xx: explicitly disable TS packet filter
        - PCI: mobiveil: Add missing ../pci.h include
        - PCI: mobiveil: Fix struct mobiveil_pcie.pcie_reg_base address type
        - powerpc/mm: Don't report PUDs as memory leaks when using kmemleak
        - Bluetooth: hidp: Fix handling of strncpy for hid->name information
        - x86/mm: Remove in_nmi() warning from vmalloc_fault()
        - regulator: tps65217: Fix NULL pointer dereference on probe
        - pinctrl: imx: off by one in imx_pinconf_group_dbg_show()
        - gpio: pxa: disable pinctrl calls for PXA3xx
        - gpio: ml-ioh: Fix buffer underwrite on probe error path
        - pinctrl/amd: only handle irq if it is pending and unmasked
        - net: mvneta: fix mtu change on port without link
        - f2fs: try grabbing node page lock aggressively in sync scenario
        - pktcdvd: Fix possible Spectre-v1 for pkt_devs
        - f2fs: fix to skip GC if type in SSA and SIT is inconsistent
        - tpm_tis_spi: Pass the SPI IRQ down to the driver
        - tpm/tpm_i2c_infineon: switch to i2c_lock_bus(..., I2C_LOCK_SEGMENT)
        - f2fs: fix to do sanity check with reserved blkaddr of inline inode
        - MIPS: Octeon: add missing of_node_put()
        - MIPS: generic: fix missing of_node_put()
        - thermal: rcar_thermal: avoid NULL dereference in absence of IRQ resources
        - thermal_hwmon: Sanitize attribute name passed to hwmon
        - net: dcb: For wild-card lookups, use priority -1, not 0
        - dm cache: only allow a single io_mode cache feature to be requested
        - Input: atmel_mxt_ts - only use first T9 instance
        - media: s5p-mfc: Fix buffer look up in s5p_mfc_handle_frame_{new, copy_time}
          functions
        - media: rcar-csi2: update stream start for V3M
        - media: helene: fix xtal frequency setting at power on
        - drm/amd/display: Prevent PSR from being enabled if initialization fails
        - media: em28xx: Fix dual transport stream operation
        - iommu/arm-smmu-v3: Abort all transactions if SMMU is enabled in kdump kernel
        - f2fs: fix to wait on page writeback before updating page
        - f2fs: Fix uninitialized return in f2fs_ioc_shutdown()
        - media: em28xx: Fix DualHD disconnect oops
        - f2fs: avoid potential deadlock in f2fs_sbi_store
        - f2fs: fix to do sanity check with secs_per_zone
        - mfd: rave-sp: Initialize flow control and parity of the port
        - iommu/ipmmu-vmsa: Fix allocation in atomic context
        - mfd: ti_am335x_tscadc: Fix struct clk memory leak
        - f2fs: fix to do sanity check with {sit,nat}_ver_bitmap_bytesize
        - f2fs: fix to propagate return value of scan_nat_page()
        - f2fs: fix to do sanity check with extra_attr feature
        - RDMA/hns: Add illegal hop_num judgement
        - NFSv4.1: Fix a potential layoutget/layoutrecall deadlock
        - RDMA/hns: Update the data type of immediate data
        - MIPS: WARN_ON invalid DMA cache maintenance, not BUG_ON
        - MIPS: mscc: ocelot: fix length of memory address space for MIIM
        - RDMA/cma: Do not ignore net namespace for unbound cm_id
        - clocksource: Revert "Remove kthread"
        - autofs: fix autofs_sbi() does not check super block type
        - mm: get rid of vmacache_flush_all() entirely
        - Linux 4.18.9
      * SRU: Enable middle button of touchpad on ThinkPad P72 (LP: #1793463)
        - Input: elantech - enable middle button of touchpad on ThinkPad P72
      * Improvements to the kernel source package preparation (LP: #1793461)
        - [Packaging] startnewrelease: add support for backport kernels
      * hns3: Retrieve RoCE MSI-X config from firmware (LP: #1793221)
        - net: hns3: Fix MSIX allocation issue for VF
        - net: hns3: Refine the MSIX allocation for PF
      * Fix unusable NVIDIA GPU after S3 (LP: #1793338)
        - SAUCE: PCI: Reprogram bridge prefetch registers on resume
      * net: hns: Avoid hang when link is changed while handling packets
        (LP: #1792209)
        - net: hns: add the code for cleaning pkt in chip
        - net: hns: add netif_carrier_off before change speed and duplex
      * Cosmic update to v4.18.8 stable release (LP: #1793069)
        - act_ife: fix a potential use-after-free
        - ipv4: tcp: send zero IPID for RST and ACK sent in SYN-RECV and TIME-WAIT
          state
        - net: bcmgenet: use MAC link status for fixed phy
        - net: macb: do not disable MDIO bus at open/close time
        - net: sched: Fix memory exposure from short TCA_U32_SEL
        - qlge: Fix netdev features configuration.
        - r8169: add support for NCube 8168 network card
        - tcp: do not restart timewait timer on rst reception
        - vti6: remove !skb->ignore_df check from vti6_xmit()
        - act_ife: move tcfa_lock down to where necessary
        - act_ife: fix a potential deadlock
        - net: sched: action_ife: take reference to meta module
        - bnxt_en: Clean up unused functions.
        - bnxt_en: Do not adjust max_cp_rings by the ones used by RDMA.
        - net/sched: act_pedit: fix dump of extended layered op
        - tipc: fix a missing rhashtable_walk_exit()
        - hv_netvsc: Fix a deadlock by getting rtnl lock earlier in netvsc_probe()
        - tipc: fix the big/little endian issue in tipc_dest
        - sctp: remove useless start_fail from sctp_ht_iter in proc
        - erspan: set erspan_ver to 1 by default when adding an erspan dev
        - net: macb: Fix regression breaking non-MDIO fixed-link PHYs
        - ipv6: don't get lwtstate twice in ip6_rt_copy_init()
        - net/ipv6: init ip6 anycast rt->dst.input as ip6_input
        - net/ipv6: Only update MTU metric if it set
        - net/ipv6: Put lwtstate when destroying fib6_info
        - net/mlx5: Fix SQ offset in QPs with small RQ
        - r8169: set RxConfig after tx/rx is enabled for RTL8169sb/8110sb devices
        - Revert "net: stmmac: Do not keep rearming the coalesce timer in stmmac_xmit"
        - ip6_vti: fix creating fallback tunnel device for vti6
        - ip6_vti: fix a null pointer deference when destroy vti6 tunnel
        - nfp: wait for posted reconfigs when disabling the device
        - sctp: hold transport before accessing its asoc in sctp_transport_get_next
        - mlxsw: spectrum_switchdev: Do not leak RIFs when removing bridge
        - vhost: correctly check the iova range when waking virtqueue
        - hv_netvsc: ignore devices that are not PCI
        - cifs: check if SMB2 PDU size has been padded and suppress the warning
        - hfsplus: don't return 0 when fill_super() failed
        - hfs: prevent crash on exit from failed search
        - sunrpc: Don't use stack buffer with scatterlist
        - fork: don't copy inconsistent signal handler state to child
        - fs/proc/vmcore.c: hide vmcoredd_mmap_dumps() for nommu builds
        - reiserfs: change j_timestamp type to time64_t
        - iommu/rockchip: Handle errors returned from PM framework
        - hfsplus: fix NULL dereference in hfsplus_lookup()
        - iommu/rockchip: Move irq request past pm_runtime_enable
        - fs/proc/kcore.c: use __pa_symbol() for KCORE_TEXT list entries
        - fat: validate ->i_start before using
        - workqueue: skip lockdep wq dependency in cancel_work_sync()
        - workqueue: re-add lockdep dependencies for flushing
        - scripts: modpost: check memory allocation results
        - apparmor: fix an error code in __aa_create_ns()
        - virtio: pci-legacy: Validate queue pfn
        - x86/mce: Add notifier_block forward declaration
        - i2c: core: ACPI: Make acpi_gsb_i2c_read_bytes() check i2c_transfer return
          value
        - IB/hfi1: Invalid NUMA node information can cause a divide by zero
        - pwm: meson: Fix mux clock names
        - powerpc/topology: Get topology for shared processors at boot
        - mm/fadvise.c: fix signed overflow UBSAN complaint
        - mm: make DEFERRED_STRUCT_PAGE_INIT explicitly depend on SPARSEMEM
        - fs/dcache.c: fix kmemcheck splat at take_dentry_name_snapshot()
        - platform/x86: intel_punit_ipc: fix build errors
        - bpf, sockmap: fix map elem deletion race with smap_stop_sock
        - tcp, ulp: fix leftover icsk_ulp_ops preventing sock from reattach
        - bpf, sockmap: fix sock_map_ctx_update_elem race with exist/noexist
        - net/xdp: Fix suspicious RCU usage warning
        - bpf, sockmap: fix leakage of smap_psock_map_entry
        - samples/bpf: all XDP samples should unload xdp/bpf prog on SIGTERM
        - netfilter: ip6t_rpfilter: set F_IFACE for linklocal addresses
        - s390/kdump: Fix memleak in nt_vmcoreinfo
        - ipvs: fix race between ip_vs_conn_new() and ip_vs_del_dest()
        - mfd: sm501: Set coherent_dma_mask when creating subdevices
        - netfilter: x_tables: do not fail xt_alloc_table_info too easilly
        - platform/x86: asus-nb-wmi: Add keymap entry for lid flip action on UX360
        - netfilter: fix memory leaks on netlink_dump_start error
        - tcp, ulp: add alias for all ulp modules
        - ubi: Initialize Fastmap checkmapping correctly
        - RDMA/hns: Fix usage of bitmap allocation functions return values
        - ACPICA: ACPICA: add status check for acpi_hw_read before assigning return
          value
        - perf arm spe: Fix uninitialized record error variable
        - net: hns3: Fix for command format parsing error in
          hclge_is_all_function_id_zero
        - block: don't warn for flush on read-only device
        - PCI: Match Root Port's MPS to endpoint's MPSS as necessary
        - drm/amd/display: Guard against null crtc in CRC IRQ
        - coccicheck: return proper error code on fail
        - perf tools: Check for null when copying nsinfo.
        - f2fs: avoid race between zero_range and background GC
        - f2fs: fix avoid race between truncate and background GC
        - RISC-V: Use KBUILD_CFLAGS instead of KCFLAGS when building the vDSO
        - irqchip/stm32: Fix init error handling
        - irqchip/bcm7038-l1: Hide cpu offline callback when building for !SMP
        - net/9p/trans_fd.c: fix race by holding the lock
        - net/9p: fix error path of p9_virtio_probe
        - f2fs: fix to clear PG_checked flag in set_page_dirty()
        - pinctrl: axp209: Fix NULL pointer dereference after allocation
        - bpf: fix bpffs non-array map seq_show issue
        - powerpc/uaccess: Enable get_user(u64, *p) on 32-bit
        - powerpc: Fix size calculation using resource_size()
        - perf probe powerpc: Fix trace event post-processing
        - block: bvec_nr_vecs() returns value for wrong slab
        - brcmfmac: fix brcmf_wiphy_wowl_params() NULL pointer dereference
        - s390/dasd: fix hanging offline processing due to canceled worker
        - s390/dasd: fix panic for failed online processing
        - ACPI / scan: Initialize status to ACPI_STA_DEFAULT
        - blk-mq: count the hctx as active before allocating tag
        - scsi: aic94xx: fix an error code in aic94xx_init()
        - NFSv4: Fix error handling in nfs4_sp4_select_mode()
        - Input: do not use WARN() in input_alloc_absinfo()
        - xen/balloon: fix balloon initialization for PVH Dom0
        - PCI: mvebu: Fix I/O space end address calculation
        - dm kcopyd: avoid softlockup in run_complete_job
        - staging: comedi: ni_mio_common: fix subdevice flags for PFI subdevice
        - ASoC: rt5677: Fix initialization of rt5677_of_match.data
        - iommu/omap: Fix cache flushes on L2 table entries
        - selftests/powerpc: Kill child processes on SIGINT
        - selinux: cleanup dentry and inodes on error in selinuxfs
        - RDS: IB: fix 'passing zero to ERR_PTR()' warning
        - cfq: Suppress compiler warnings about comparisons
        - smb3: fix reset of bytes read and written stats
        - CIFS: fix memory leak and remove dead code
        - SMB3: Number of requests sent should be displayed for SMB3 not just CIFS
        - smb3: if server does not support posix do not allow posix mount option
        - powerpc/platforms/85xx: fix t1042rdb_diu.c build errors & warning
        - powerpc/64s: Make rfi_flush_fallback a little more robust
        - um: fix parallel building with O= option
        - powerpc/pseries: Avoid using the size greater than RTAS_ERROR_LOG_MAX.
        - clk: rockchip: Add pclk_rkpwm_pmu to PMU critical clocks in rk3399
        - drm/amd/display: Read back max backlight value at boot
        - KVM: vmx: track host_state.loaded using a loaded_vmcs pointer
        - kvm: nVMX: Fix fault vector for VMX operation at CPL > 0
        - drm/etnaviv: fix crash in GPU suspend when init failed due to buffer
          placement
        - btrfs: Exit gracefully when chunk map cannot be inserted to the tree
        - btrfs: replace: Reset on-disk dev stats value after replace
        - btrfs: fix in-memory value of total_devices after seed device deletion
        - btrfs: relocation: Only remove reloc rb_trees if reloc control has been
          initialized
        - btrfs: tree-checker: Detect invalid and empty essential trees
        - btrfs: check-integrity: Fix NULL pointer dereference for degraded mount
        - btrfs: lift uuid_mutex to callers of btrfs_open_devices
        - btrfs: Don't remove block group that still has pinned down bytes
        - btrfs: Fix a C compliance issue
        - arm64: rockchip: Force CONFIG_PM on Rockchip systems
        - ARM: rockchip: Force CONFIG_PM on Rockchip systems
        - btrfs: do btrfs_free_stale_devices outside of device_list_add
        - btrfs: extend locked section when adding a new device in device_list_add
        - btrfs: rename local devices for fs_devices in btrfs_free_stale_devices(
        - btrfs: use device_list_mutex when removing stale devices
        - btrfs: lift uuid_mutex to callers of btrfs_scan_one_device
        - btrfs: lift uuid_mutex to callers of btrfs_parse_early_options
        - btrfs: reorder initialization before the mount locks uuid_mutex
        - btrfs: fix mount and ioctl device scan ioctl race
        - drm/i915/lpe: Mark LPE audio runtime pm as "no callbacks"
        - drm/i915: Nuke the LVDS lid notifier
        - drm/i915: Increase LSPCON timeout
        - drm/i915: Free write_buf that we allocated with kzalloc.
        - drm/amdgpu: update uvd_v6_0_ring_vm_funcs to use new nop packet
        - drm/amdgpu: fix a reversed condition
        - drm/amdgpu: Fix RLC safe mode test in gfx_v9_0_enter_rlc_safe_mode
        - drm/amd/pp: Convert voltage unit in mV*4 to mV on CZ/ST
        - drm/amd/powerplay: fixed uninitialized value
        - drm/amd/pp/Polaris12: Fix a chunk of registers missed to program
        - drm/edid: Quirk Vive Pro VR headset non-desktop.
        - drm/amd/display: fix type of variable
        - drm/amd/display: Don't share clk source between DP and HDMI
        - drm/amd/display: update clk for various HDMI color depths
        - drm/amd/display: Use requested HDMI aspect ratio
        - drm/amd/display: Report non-DP display as disconnected without EDID
        - drm/rockchip: lvds: add missing of_node_put
        - drm/rockchip: vop: split out core clock enablement into separate functions
        - drm/rockchip: vop: fix irq disabled after vop driver probed
        - drm/amd/display: Pass connector id when executing VBIOS CT
        - drm/amd/display: Check if clock source in use before disabling
        - drm/amdgpu: update tmr mc address
        - drm/amdgpu:add tmr mc address into amdgpu_firmware_info
        - drm/amdgpu:add new firmware id for VCN
        - drm/amdgpu:add VCN support in PSP driver
        - drm/amdgpu:add VCN booting with firmware loaded by PSP
        - drm/amdgpu: fix incorrect use of fcheck
        - drm/amdgpu: fix incorrect use of drm_file->pid
        - drm/i915: Re-apply "Perform link quality check, unconditionally during long
          pulse"
        - uapi/linux/keyctl.h: don't use C++ reserved keyword as a struct member name
        - mm: respect arch_dup_mmap() return value
        - drm/i915: set DP Main Stream Attribute for color range on DDI platforms
        - x86/tsc: Prevent result truncation on 32bit
        - drm/amdgpu: Keep track of amount of pinned CPU visible VRAM
        - drm/amdgpu: Make pin_size values atomic
        - drm/amdgpu: Warn and update pin_size values when destroying a pinned BO
        - drm/amdgpu: Don't warn on destroying a pinned BO
        - debugobjects: Make stack check warning more informative
        - x86/pae: use 64 bit atomic xchg function in native_ptep_get_and_clear
        - x86/xen: don't write ptes directly in 32-bit PV guests
        - kbuild: make missing $DEPMOD a Warning instead of an Error
        - kvm: x86: Set highest physical address bits in non-present/reserved SPTEs
        - x86: kvm: avoid unused variable warning
        - HID: redragon: fix num lock and caps lock LEDs
        - ASoC: wm8994: Fix missing break in switch
        - Linux 4.18.8
      * [Regression] Colour banding appears on Lenovo B50-80 integrated display
        (LP: #1788308) // Cosmic update to v4.18.8 stable release (LP: #1793069)
        - drm/edid: Add 6 bpc quirk for SDC panel in Lenovo B50-80
      * Fix I2C touchpanels' interrupt storms after system suspend (LP: #1792309)
        - HID: i2c-hid: Fix flooded incomplete report after S3 on Rayd touchscreen
        - HID: i2c-hid: Don't reset device upon system resume
      * Error reported when creating ZFS pool with "-t" option, despite successful
        pool creation (LP: #1769937)
        - SAUCE: (noup) Update zfs to 0.7.9-3ubuntu6
      * update ENA driver to latest mainline version (LP: #1792044)
        - net: ena: fix surprise unplug NULL dereference kernel crash
        - net: ena: fix driver when PAGE_SIZE == 64kB
        - net: ena: fix device destruction to gracefully free resources
        - net: ena: fix potential double ena_destroy_device()
        - net: ena: fix missing lock during device destruction
        - net: ena: fix missing calls to READ_ONCE
        - net: ena: fix incorrect usage of memory barriers
      * device hotplug of vfio devices can lead to deadlock in vfio_pci_release
        (LP: #1792099)
        - SAUCE: vfio -- release device lock before userspace requests
      * [AEP-bug] ext4: more rare direct I/O vs unmap failures (LP: #1787089)
        - dax: dax_layout_busy_page() warn on !exceptional
        - ext4: handle layout changes to pinned DAX mappings
        - xfs: Close race between direct IO and xfs_break_layouts()
      * [Bug][CLX]assertion failure with util_range_rw using libpmemlog, possible
        kernel DAX bug (LP: #1789146)
        - dax: remove VM_MIXEDMAP for fsdax and device dax
      * [Feature] Optimize huge page clear/copy cache behavior (LP: #1730836)
        - mm, clear_huge_page: move order algorithm into a separate function
        - mm, huge page: copy target sub-page last when copy huge page
        - mm, hugetlbfs: rename address to haddr in hugetlb_cow()
        - mm, hugetlbfs: pass fault address to cow handler
      * [ICL] Touch support (LP: #1771245)
        - mfd: intel-lpss: Add Ice Lake PCI IDs
      * Miscellaneous Ubuntu changes
        - [Packaging] retpoline -- fix temporary filenaming
        - SAUCE: update aufs to aufs4.18 20180910
        - CONFIG_BCH_CONST_PARAMS=n
        - Packaging: final-checks: remove trailing backport suffix
    
     -- Seth Forshee <email address hidden>  Tue, 09 Oct 2018 11:46:27 -0500
  • linux-gcp (4.18.0-1001.2) cosmic; urgency=medium
    
      * Initial linux-gcp version based on linux-gcp (4.15.0-1021.22)
        in Bionic and linux (4.18.0-7.8) in Cosmic.
    
     -- Stefan Bader <email address hidden>  Wed, 26 Sep 2018 17:05:49 +0200
  • linux-gcp (4.15.0-1021.22) bionic; urgency=medium
    
      [ Ubuntu: 4.15.0-36.39 ]
    
      * CVE-2018-14633
        - iscsi target: Use hex2bin instead of a re-implementation
      * CVE-2018-17182
        - mm: get rid of vmacache_flush_all() entirely
    
    linux-gcp (4.15.0-1020.21) bionic; urgency=medium
    
      * linux-gcp: 4.15.0-1020.21 -proposed tracker (LP: #1791728)
    
      * Kernel 4.15.0-35.38 fails to build with CONFIG_XFS_ONLINE_SCRUB enabled
        (LP: #1792393)
        - SAUCE: xfs: fix build error with CONFIG_XFS_ONLINE_SCRUB enabled
    
      * [Regression] kernel crashdump fails on arm64 (LP: #1786878)
        - [config] update configs after rebase
    
      [ Ubuntu: 4.15.0-35.38 ]
    
      * linux: 4.15.0-35.38 -proposed tracker (LP: #1791719)
      * device hotplug of vfio devices can lead to deadlock in vfio_pci_release
        (LP: #1792099)
        - SAUCE: vfio -- release device lock before userspace requests
      * L1TF mitigation not effective in some CPU and RAM combinations
        (LP: #1788563)
        - x86/speculation/l1tf: Fix overflow in l1tf_pfn_limit() on 32bit
        - x86/speculation/l1tf: Fix off-by-one error when warning that system has too
          much RAM
        - x86/speculation/l1tf: Increase l1tf memory limit for Nehalem+
      * CVE-2018-15594
        - x86/paravirt: Fix spectre-v2 mitigations for paravirt guests
      * CVE-2017-5715 (Spectre v2 s390x)
        - KVM: s390: implement CPU model only facilities
        - s390: detect etoken facility
        - KVM: s390: add etoken support for guests
        - s390/lib: use expoline for all bcr instructions
        - s390: fix br_r1_trampoline for machines without exrl
        - SAUCE: s390: use expoline thunks for all branches generated by the BPF JIT
      * Ubuntu18.04.1: cpuidle: powernv: Fix promotion from snooze if next state
        disabled (performance) (LP: #1790602)
        - cpuidle: powernv: Fix promotion from snooze if next state disabled
      * Watchdog CPU:19 Hard LOCKUP when kernel crash was triggered (LP: #1790636)
        - powerpc: hard disable irqs in smp_send_stop loop
        - powerpc: Fix deadlock with multiple calls to smp_send_stop
        - powerpc: smp_send_stop do not offline stopped CPUs
        - powerpc/powernv: Fix opal_event_shutdown() called with interrupts disabled
      * Security fix: check if IOMMU page is contained in the pinned physical page
        (LP: #1785675)
        - vfio/spapr: Use IOMMU pageshift rather than pagesize
        - KVM: PPC: Check if IOMMU page is contained in the pinned physical page
      * Missing Intel GPU pci-id's (LP: #1789924)
        - drm/i915/kbl: Add KBL GT2 sku
        - drm/i915/whl: Introducing Whiskey Lake platform
        - drm/i915/aml: Introducing Amber Lake platform
        - drm/i915/cfl: Add a new CFL PCI ID.
      * CVE-2018-15572
        - x86/speculation: Protect against userspace-userspace spectreRSB
      * Support Power Management for Thunderbolt Controller  (LP: #1789358)
        - thunderbolt: Handle NULL boot ACL entries properly
        - thunderbolt: Notify userspace when boot_acl is changed
        - thunderbolt: Use 64-bit DMA mask if supported by the platform
        - thunderbolt: Do not unnecessarily call ICM get route
        - thunderbolt: No need to take tb->lock in domain suspend/complete
        - thunderbolt: Use correct ICM commands in system suspend
        - thunderbolt: Add support for runtime PM
      * random oopses on s390 systems using NVMe devices (LP: #1790480)
        - s390/pci: fix out of bounds access during irq setup
      * [Bionic] Spectre v4 mitigation (Speculative Store Bypass Disable) support
        for arm64 using SMC firmware call to set a hardware chicken bit
        (LP: #1787993) // CVE-2018-3639 (arm64)
        - arm64: alternatives: Add dynamic patching feature
        - KVM: arm/arm64: Do not use kern_hyp_va() with kvm_vgic_global_state
        - KVM: arm64: Avoid storing the vcpu pointer on the stack
        - arm/arm64: smccc: Add SMCCC-specific return codes
        - arm64: Call ARCH_WORKAROUND_2 on transitions between EL0 and EL1
        - arm64: Add per-cpu infrastructure to call ARCH_WORKAROUND_2
        - arm64: Add ARCH_WORKAROUND_2 probing
        - arm64: Add 'ssbd' command-line option
        - arm64: ssbd: Add global mitigation state accessor
        - arm64: ssbd: Skip apply_ssbd if not using dynamic mitigation
        - arm64: ssbd: Restore mitigation status on CPU resume
        - arm64: ssbd: Introduce thread flag to control userspace mitigation
        - arm64: ssbd: Add prctl interface for per-thread mitigation
        - arm64: KVM: Add HYP per-cpu accessors
        - arm64: KVM: Add ARCH_WORKAROUND_2 support for guests
        - arm64: KVM: Handle guest's ARCH_WORKAROUND_2 requests
        - arm64: KVM: Add ARCH_WORKAROUND_2 discovery through ARCH_FEATURES_FUNC_ID
        - [Config] ARM64_SSBD=y
      * Reconcile hns3 SAUCE patches with upstream (LP: #1787477)
        - Revert "UBUNTU: SAUCE: net: hns3: Optimize PF CMDQ interrupt switching
          process"
        - Revert "UBUNTU: SAUCE: net: hns3: Fix for VF mailbox receiving unknown
          message"
        - Revert "UBUNTU: SAUCE: net: hns3: Fix for VF mailbox cannot receiving PF
          response"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix comments for
          hclge_get_ring_chain_from_mbx"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix for using wrong mask and
          shift in hclge_get_ring_chain_from_mbx"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix for reset_level default
          assignment probelm"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove unnecessary ring
          configuration operation while resetting"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix return value error in
          hns3_reset_notify_down_enet"
        - Revert "UBUNTU: SAUCE: net: hns3: Fix for phy link issue when using marvell
          phy driver"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: separate roce from nic when
          resetting"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: correct reset event status
          register"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: prevent to request reset
          frequently"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: reset net device with rtnl_lock"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: modify the order of initializeing
          command queue register"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: prevent sending command during
          global or core reset"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove the warning when clear
          reset cause"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix get_vector ops in
          hclgevf_main module"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix warning bug when doing lp
          selftest"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: Add configure for mac minimal
          frame size"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix for mailbox message truncated
          problem"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix for l4 checksum offload bug"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix for waterline not setting
          correctly"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix for mac pause not disable in
          pfc mode"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix tc setup when netdev is first
          up"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: Add SPDX tags to hns3 driver"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove unused struct member and
          definition"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix mislead parameter name"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: modify inconsistent bit mask
          macros"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: use decimal for bit offset
          macros"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix unreasonable code comments"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove extra space and brackets"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: standardize the handle of return
          value"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove some redundant
          assignments"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix unused function warning in VF
          driver"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: modify hnae_ to hnae3_"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: use dma_zalloc_coherent instead
          of kzalloc/dma_map_single"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: give default option while
          dependency HNS3 set"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove some unused members of
          some structures"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove a redundant
          hclge_cmd_csq_done"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: using modulo for cyclic counters
          in hclge_cmd_send"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: simplify hclge_cmd_csq_clean"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove some redundant
          assignments"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove useless code in
          hclge_cmd_send"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove unused
          hclge_ring_to_dma_dir"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: use lower_32_bits and
          upper_32_bits"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove back in struct hclge_hw"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: add unlikely for error check"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove the Redundant put_vector
          in hns3_client_uninit"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: print the ret value in error
          information"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: extraction an interface for state
          state init|uninit"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove unused head file in
          hnae3.c"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: add l4_type check for both ipv4
          and ipv6"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: add vector status check before
          free vector"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: rename the interface for
          init_client_instance and uninit_client_instance"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove hclge_get_vector_index
          from hclge_bind_ring_with_vector"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: RX BD information valid only in
          last BD except VLD bit and buffer size"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: add support for serdes loopback
          selftest"
        - net: hns3: Updates RX packet info fetch in case of multi BD
        - net: hns3: remove unused hclgevf_cfg_func_mta_filter
        - net: hns3: Fix for VF mailbox cannot receiving PF response
        - net: hns3: Fix for VF mailbox receiving unknown message
        - net: hns3: Optimize PF CMDQ interrupt switching process
        - net: hns3: remove hclge_get_vector_index from hclge_bind_ring_with_vector
        - net: hns3: rename the interface for init_client_instance and
          uninit_client_instance
        - net: hns3: add vector status check before free vector
        - net: hns3: add l4_type check for both ipv4 and ipv6
        - net: hns3: add unlikely for error check
        - net: hns3: remove unused head file in hnae3.c
        - net: hns3: extraction an interface for state init|uninit
        - net: hns3: print the ret value in error information
        - net: hns3: remove the Redundant put_vector in hns3_client_uninit
        - net: hns3: remove back in struct hclge_hw
        - net: hns3: use lower_32_bits and upper_32_bits
        - net: hns3: remove unused hclge_ring_to_dma_dir
        - net: hns3: remove useless code in hclge_cmd_send
        - net: hns3: remove some redundant assignments
        - net: hns3: simplify hclge_cmd_csq_clean
        - net: hns3: remove a redundant hclge_cmd_csq_done
        - net: hns3: remove some unused members of some structures
        - net: hns3: give default option while dependency HNS3 set
        - net: hns3: use dma_zalloc_coherent instead of kzalloc/dma_map_single
        - net: hns3: modify hnae_ to hnae3_
        - net: hns3: Fix tc setup when netdev is first up
        - net: hns3: Fix for mac pause not disable in pfc mode
        - net: hns3: Fix for waterline not setting correctly
        - net: hns3: Fix for l4 checksum offload bug
        - net: hns3: Fix for mailbox message truncated problem
        - net: hns3: Add configure for mac minimal frame size
        - net: hns3: Fix warning bug when doing lp selftest
        - net: hns3: Fix get_vector ops in hclgevf_main module
        - net: hns3: Remove the warning when clear reset cause
        - net: hns3: Prevent sending command during global or core reset
        - net: hns3: Modify the order of initializing command queue register
        - net: hns3: Reset net device with rtnl_lock
        - net: hns3: Prevent to request reset frequently
        - net: hns3: Correct reset event status register
        - net: hns3: Fix return value error in hns3_reset_notify_down_enet
        - net: hns3: remove unnecessary ring configuration operation while resetting
        - net: hns3: Fix for reset_level default assignment probelm
        - net: hns3: Fix for using wrong mask and shift in
          hclge_get_ring_chain_from_mbx
        - net: hns3: Fix comments for hclge_get_ring_chain_from_mbx
        - net: hns3: Remove some redundant assignments
        - net: hns3: Standardize the handle of return value
        - net: hns3: Remove extra space and brackets
        - net: hns3: Correct unreasonable code comments
        - net: hns3: Use decimal for bit offset macros
        - net: hns3: Modify inconsistent bit mask macros
        - net: hns3: Fix misleading parameter name
        - net: hns3: Remove unused struct member and definition
        - net: hns3: Add SPDX tags to HNS3 PF driver
        - net: hns3: Add support for serdes loopback selftest
        - net: hns3: Fix for phy link issue when using marvell phy driver
        - SAUCE: {topost} net: hns3: separate roce from nic when resetting
      * CVE-2018-6555
        - SAUCE: irda: Only insert new objects into the global database via setsockopt
      * CVE-2018-6554
        - SAUCE: irda: Fix memory leak caused by repeated binds of irda socket
      * Bionic update: upstream stable patchset 2018-08-31 (LP: #1790188)
        - netfilter: nf_tables: fix NULL pointer dereference on
          nft_ct_helper_obj_dump()
        - blkdev_report_zones_ioctl(): Use vmalloc() to allocate large buffers
        - af_key: Always verify length of provided sadb_key
        - gpio: No NULL owner
        - KVM: X86: Fix reserved bits check for MOV to CR3
        - KVM: x86: introduce linear_{read,write}_system
        - KVM: x86: pass kvm_vcpu to kvm_read_guest_virt and
          kvm_write_guest_virt_system
        - staging: android: ion: Switch to pr_warn_once in ion_buffer_destroy
        - NFC: pn533: don't send USB data off of the stack
        - usbip: vhci_sysfs: fix potential Spectre v1
        - usb-storage: Add support for FL_ALWAYS_SYNC flag in the UAS driver
        - usb-storage: Add compatibility quirk flags for G-Technologies G-Drive
        - Input: xpad - add GPD Win 2 Controller USB IDs
        - phy: qcom-qusb2: Fix crash if nvmem cell not specified
        - usb: gadget: function: printer: avoid wrong list handling in printer_write()
        - usb: gadget: udc: renesas_usb3: disable the controller's irqs for
          reconnecting
        - serial: sh-sci: Stop using printk format %pCr
        - tty/serial: atmel: use port->name as name in request_irq()
        - serial: samsung: fix maxburst parameter for DMA transactions
        - serial: 8250: omap: Fix idling of clocks for unused uarts
        - vmw_balloon: fixing double free when batching mode is off
        - tty: pl011: Avoid spuriously stuck-off interrupts
        - kvm: x86: use correct privilege level for sgdt/sidt/fxsave/fxrstor access
        - Input: goodix - add new ACPI id for GPD Win 2 touch screen
        - crypto: caam - strip input zeros from RSA input buffer
        - crypto: caam - fix DMA mapping dir for generated IV
        - crypto: caam - fix IV DMA mapping and updating
        - crypto: caam/qi - fix IV DMA mapping and updating
        - crypto: caam - fix size of RSA prime factor q
        - crypto: vmx - Remove overly verbose printk from AES init routines
        - crypto: vmx - Remove overly verbose printk from AES XTS init
        - crypto: omap-sham - fix memleak
        - usb: typec: wcove: Remove dependency on HW FSM
        - usb: gadget: udc: renesas_usb3: fix double phy_put()
        - usb: gadget: udc: renesas_usb3: should remove debugfs
        - usb: gadget: udc: renesas_usb3: should call pm_runtime_enable() before add
          udc
        - usb: gadget: udc: renesas_usb3: should call devm_phy_get() before add udc
        - usb: gadget: udc: renesas_usb3: should fail if devm_phy_get() returns error
      * Bionic update: upstream stable patchset 2018-08-29 (LP: #1789666)
        - scsi: sd_zbc: Avoid that resetting a zone fails sporadically
        - mmap: introduce sane default mmap limits
        - mmap: relax file size limit for regular files
        - btrfs: define SUPER_FLAG_METADUMP_V2
        - kconfig: Avoid format overflow warning from GCC 8.1
        - be2net: Fix error detection logic for BE3
        - bnx2x: use the right constant
        - dccp: don't free ccid2_hc_tx_sock struct in dccp_disconnect()
        - enic: set DMA mask to 47 bit
        - ip6mr: only set ip6mr_table from setsockopt when ip6mr_new_table succeeds
        - ip6_tunnel: remove magic mtu value 0xFFF8
        - ipmr: properly check rhltable_init() return value
        - ipv4: remove warning in ip_recv_error
        - ipv6: omit traffic class when calculating flow hash
        - isdn: eicon: fix a missing-check bug
        - kcm: Fix use-after-free caused by clonned sockets
        - netdev-FAQ: clarify DaveM's position for stable backports
        - net: ipv4: add missing RTA_TABLE to rtm_ipv4_policy
        - net: metrics: add proper netlink validation
        - net/packet: refine check for priv area size
        - net: phy: broadcom: Fix bcm_write_exp()
        - net: usb: cdc_mbim: add flag FLAG_SEND_ZLP
        - packet: fix reserve calculation
        - qed: Fix mask for physical address in ILT entry
        - sctp: not allow transport timeout value less than HZ/5 for hb_timer
        - team: use netdev_features_t instead of u32
        - vhost: synchronize IOTLB message with dev cleanup
        - vrf: check the original netdevice for generating redirect
        - ipv6: sr: fix memory OOB access in seg6_do_srh_encap/inline
        - net: phy: broadcom: Fix auxiliary control register reads
        - net-sysfs: Fix memory leak in XPS configuration
        - virtio-net: correctly transmit XDP buff after linearizing
        - net/mlx4: Fix irq-unsafe spinlock usage
        - tun: Fix NULL pointer dereference in XDP redirect
        - virtio-net: correctly check num_buf during err path
        - net/mlx5e: When RXFCS is set, add FCS data into checksum calculation
        - virtio-net: fix leaking page for gso packet during mergeable XDP
        - rtnetlink: validate attributes in do_setlink()
        - cls_flower: Fix incorrect idr release when failing to modify rule
        - PCI: hv: Do not wait forever on a device that has disappeared
        - drm: set FMODE_UNSIGNED_OFFSET for drm files
        - l2tp: fix refcount leakage on PPPoL2TP sockets
        - mlxsw: spectrum: Forbid creation of VLAN 1 over port/LAG
        - net: ethernet: ti: cpdma: correct error handling for chan create
        - net: ethernet: davinci_emac: fix error handling in probe()
        - net: dsa: b53: Fix for brcm tag issue in Cygnus SoC
        - net : sched: cls_api: deal with egdev path only if needed
      * Bionic update: upstream stable patchset 2018-08-24 (LP: #1788897)
        - fix io_destroy()/aio_complete() race
        - mm: fix the NULL mapping case in __isolate_lru_page()
        - objtool: Support GCC 8's cold subfunctions
        - objtool: Support GCC 8 switch tables
        - objtool: Detect RIP-relative switch table references
        - objtool: Detect RIP-relative switch table references, part 2
        - objtool: Fix "noreturn" detection for recursive sibling calls
        - xfs: convert XFS_AGFL_SIZE to a helper function
        - xfs: detect agfl count corruption and reset agfl
        - Input: synaptics - Lenovo Carbon X1 Gen5 (2017) devices should use RMI
        - Input: synaptics - add Lenovo 80 series ids to SMBus
        - Input: elan_i2c_smbus - fix corrupted stack
        - tracing: Fix crash when freeing instances with event triggers
        - tracing: Make the snapshot trigger work with instances
        - selinux: KASAN: slab-out-of-bounds in xattr_getsecurity
        - cfg80211: further limit wiphy names to 64 bytes
        - drm/amd/powerplay: Fix enum mismatch
        - rtlwifi: rtl8192cu: Remove variable self-assignment in rf.c
        - platform/chrome: cros_ec_lpc: remove redundant pointer request
        - kbuild: clang: disable unused variable warnings only when constant
        - tcp: avoid integer overflows in tcp_rcv_space_adjust()
        - iio: ad7793: implement IIO_CHAN_INFO_SAMP_FREQ
        - iio:buffer: make length types match kfifo types
        - iio:kfifo_buf: check for uint overflow
        - iio: adc: select buffer for at91-sama5d2_adc
        - MIPS: lantiq: gphy: Drop reboot/remove reset asserts
        - MIPS: ptrace: Fix PTRACE_PEEKUSR requests for 64-bit FGRs
        - MIPS: prctl: Disallow FRE without FR with PR_SET_FP_MODE requests
        - scsi: scsi_transport_srp: Fix shost to rport translation
        - stm class: Use vmalloc for the master map
        - hwtracing: stm: fix build error on some arches
        - IB/core: Fix error code for invalid GID entry
        - mm/huge_memory.c: __split_huge_page() use atomic ClearPageDirty()
        - Revert "rt2800: use TXOP_BACKOFF for probe frames"
        - intel_th: Use correct device when freeing buffers
        - drm/psr: Fix missed entry in PSR setup time table.
        - drm/i915/lvds: Move acpi lid notification registration to registration phase
        - drm/i915: Disable LVDS on Radiant P845
        - drm/vmwgfx: Use kasprintf
        - drm/vmwgfx: Fix host logging / guestinfo reading error paths
        - nvme: fix extended data LBA supported setting
        - iio: hid-sensor-trigger: Fix sometimes not powering up the sensor after
          resume
        - x86/MCE/AMD: Define a function to get SMCA bank type
        - x86/mce/AMD: Pass the bank number to smca_get_bank_type()
        - x86/mce/AMD, EDAC/mce_amd: Enumerate Reserved SMCA bank type
        - x86/mce/AMD: Carve out SMCA get_block_address() code
        - x86/MCE/AMD: Cache SMCA MISC block addresses
      * errors when scanning partition table of corrupted AIX disk (LP: #1787281)
        - partitions/aix: fix usage of uninitialized lv_info and lvname structures
        - partitions/aix: append null character to print data from disk
      * tlbie master timeout checkstop (using NVidia/GPU) (LP: #1789772)
        - powerpc/mm/hugetlb: Update huge_ptep_set_access_flags to call
          __ptep_set_access_flags directly
        - powerpc/mm/radix: Move function from radix.h to pgtable-radix.c
        - powerpc/mm: Change function prototype
        - powerpc/mm/radix: Change pte relax sequence to handle nest MMU hang
      * performance drop with ATS enabled (LP: #1788097)
        - powerpc/powernv: Fix concurrency issue with npu->mmio_atsd_usage
      * [Regression] kernel crashdump fails on arm64 (LP: #1786878)
        - arm64: export memblock_reserve()d regions via /proc/iomem
        - drivers: acpi: add dependency of EFI for arm64
        - efi/arm: preserve early mapping of UEFI memory map longer for BGRT
        - efi/arm: map UEFI memory map even w/o runtime services enabled
        - arm64: acpi: fix alignment fault in accessing ACPI
        - [Config] CONFIG_ARCH_SUPPORTS_ACPI=y
        - arm64: fix ACPI dependencies
        - ACPI: fix menuconfig presentation of ACPI submenu
      * TB 16 issue on Dell Lattitude 7490 with large amount of data (LP: #1785780)
        - r8152: disable RX aggregation on new Dell TB16 dock
      * dell_wmi: Unknown key codes (LP: #1762385)
        - platform/x86: dell-wmi: Ignore new rfkill and fn-lock events
      * Enable AMD PCIe MP2 for AMDI0011 (LP: #1773940)
        - SAUCE: i2c:amd I2C Driver based on PCI Interface for upcoming platform
        - SAUCE: i2c:amd move out pointer in union i2c_event_base
        - SAUCE: i2c:amd Depends on ACPI
        - [Config] i2c: CONFIG_I2C_AMD_MP2=y on x86
      * r8169 no internet after suspending (LP: #1779817)
        - r8169: restore previous behavior to accept BIOS WoL settings
        - r8169: don't use MSI-X on RTL8168g
        - r8169: don't use MSI-X on RTL8106e
      * Fix Intel Cannon Lake LPSS I2C input clock (LP: #1789790)
        - mfd: intel-lpss: Fix Intel Cannon Lake LPSS I2C input clock
      * Microphone cannot be detected with front panel audio combo jack on HP Z8-G4
        machine (LP: #1789145)
        - ALSA: hda/realtek - Fix HP Headset Mic can't record
      * Tango platform uses __initcall without further checks (LP: #1787945)
        - [Config] disable ARCH_TANGO
      * [18.10 FEAT] Add kernel config option "CONFIG_SCLP_OFB" (LP: #1787898)
        - [Config] CONFIG_SCLP_OFB=y for s390x
    
     -- Kleber Sacilotto de Souza <email address hidden>  Tue, 25 Sep 2018 10:11:22 +0200
  • linux-gcp (4.15.0-1020.21) bionic; urgency=medium
    
      * linux-gcp: 4.15.0-1020.21 -proposed tracker (LP: #1791728)
    
      * Kernel 4.15.0-35.38 fails to build with CONFIG_XFS_ONLINE_SCRUB enabled
        (LP: #1792393)
        - SAUCE: xfs: fix build error with CONFIG_XFS_ONLINE_SCRUB enabled
    
      * [Regression] kernel crashdump fails on arm64 (LP: #1786878)
        - [config] update configs after rebase
    
      [ Ubuntu: 4.15.0-35.38 ]
    
      * linux: 4.15.0-35.38 -proposed tracker (LP: #1791719)
      * device hotplug of vfio devices can lead to deadlock in vfio_pci_release
        (LP: #1792099)
        - SAUCE: vfio -- release device lock before userspace requests
      * L1TF mitigation not effective in some CPU and RAM combinations
        (LP: #1788563)
        - x86/speculation/l1tf: Fix overflow in l1tf_pfn_limit() on 32bit
        - x86/speculation/l1tf: Fix off-by-one error when warning that system has too
          much RAM
        - x86/speculation/l1tf: Increase l1tf memory limit for Nehalem+
      * CVE-2018-15594
        - x86/paravirt: Fix spectre-v2 mitigations for paravirt guests
      * CVE-2017-5715 (Spectre v2 s390x)
        - KVM: s390: implement CPU model only facilities
        - s390: detect etoken facility
        - KVM: s390: add etoken support for guests
        - s390/lib: use expoline for all bcr instructions
        - s390: fix br_r1_trampoline for machines without exrl
        - SAUCE: s390: use expoline thunks for all branches generated by the BPF JIT
      * Ubuntu18.04.1: cpuidle: powernv: Fix promotion from snooze if next state
        disabled (performance) (LP: #1790602)
        - cpuidle: powernv: Fix promotion from snooze if next state disabled
      * Watchdog CPU:19 Hard LOCKUP when kernel crash was triggered (LP: #1790636)
        - powerpc: hard disable irqs in smp_send_stop loop
        - powerpc: Fix deadlock with multiple calls to smp_send_stop
        - powerpc: smp_send_stop do not offline stopped CPUs
        - powerpc/powernv: Fix opal_event_shutdown() called with interrupts disabled
      * Security fix: check if IOMMU page is contained in the pinned physical page
        (LP: #1785675)
        - vfio/spapr: Use IOMMU pageshift rather than pagesize
        - KVM: PPC: Check if IOMMU page is contained in the pinned physical page
      * Missing Intel GPU pci-id's (LP: #1789924)
        - drm/i915/kbl: Add KBL GT2 sku
        - drm/i915/whl: Introducing Whiskey Lake platform
        - drm/i915/aml: Introducing Amber Lake platform
        - drm/i915/cfl: Add a new CFL PCI ID.
      * CVE-2018-15572
        - x86/speculation: Protect against userspace-userspace spectreRSB
      * Support Power Management for Thunderbolt Controller  (LP: #1789358)
        - thunderbolt: Handle NULL boot ACL entries properly
        - thunderbolt: Notify userspace when boot_acl is changed
        - thunderbolt: Use 64-bit DMA mask if supported by the platform
        - thunderbolt: Do not unnecessarily call ICM get route
        - thunderbolt: No need to take tb->lock in domain suspend/complete
        - thunderbolt: Use correct ICM commands in system suspend
        - thunderbolt: Add support for runtime PM
      * random oopses on s390 systems using NVMe devices (LP: #1790480)
        - s390/pci: fix out of bounds access during irq setup
      * [Bionic] Spectre v4 mitigation (Speculative Store Bypass Disable) support
        for arm64 using SMC firmware call to set a hardware chicken bit
        (LP: #1787993) // CVE-2018-3639 (arm64)
        - arm64: alternatives: Add dynamic patching feature
        - KVM: arm/arm64: Do not use kern_hyp_va() with kvm_vgic_global_state
        - KVM: arm64: Avoid storing the vcpu pointer on the stack
        - arm/arm64: smccc: Add SMCCC-specific return codes
        - arm64: Call ARCH_WORKAROUND_2 on transitions between EL0 and EL1
        - arm64: Add per-cpu infrastructure to call ARCH_WORKAROUND_2
        - arm64: Add ARCH_WORKAROUND_2 probing
        - arm64: Add 'ssbd' command-line option
        - arm64: ssbd: Add global mitigation state accessor
        - arm64: ssbd: Skip apply_ssbd if not using dynamic mitigation
        - arm64: ssbd: Restore mitigation status on CPU resume
        - arm64: ssbd: Introduce thread flag to control userspace mitigation
        - arm64: ssbd: Add prctl interface for per-thread mitigation
        - arm64: KVM: Add HYP per-cpu accessors
        - arm64: KVM: Add ARCH_WORKAROUND_2 support for guests
        - arm64: KVM: Handle guest's ARCH_WORKAROUND_2 requests
        - arm64: KVM: Add ARCH_WORKAROUND_2 discovery through ARCH_FEATURES_FUNC_ID
        - [Config] ARM64_SSBD=y
      * Reconcile hns3 SAUCE patches with upstream (LP: #1787477)
        - Revert "UBUNTU: SAUCE: net: hns3: Optimize PF CMDQ interrupt switching
          process"
        - Revert "UBUNTU: SAUCE: net: hns3: Fix for VF mailbox receiving unknown
          message"
        - Revert "UBUNTU: SAUCE: net: hns3: Fix for VF mailbox cannot receiving PF
          response"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix comments for
          hclge_get_ring_chain_from_mbx"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix for using wrong mask and
          shift in hclge_get_ring_chain_from_mbx"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix for reset_level default
          assignment probelm"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove unnecessary ring
          configuration operation while resetting"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix return value error in
          hns3_reset_notify_down_enet"
        - Revert "UBUNTU: SAUCE: net: hns3: Fix for phy link issue when using marvell
          phy driver"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: separate roce from nic when
          resetting"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: correct reset event status
          register"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: prevent to request reset
          frequently"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: reset net device with rtnl_lock"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: modify the order of initializeing
          command queue register"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: prevent sending command during
          global or core reset"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove the warning when clear
          reset cause"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix get_vector ops in
          hclgevf_main module"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix warning bug when doing lp
          selftest"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: Add configure for mac minimal
          frame size"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix for mailbox message truncated
          problem"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix for l4 checksum offload bug"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix for waterline not setting
          correctly"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix for mac pause not disable in
          pfc mode"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix tc setup when netdev is first
          up"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: Add SPDX tags to hns3 driver"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove unused struct member and
          definition"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix mislead parameter name"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: modify inconsistent bit mask
          macros"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: use decimal for bit offset
          macros"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix unreasonable code comments"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove extra space and brackets"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: standardize the handle of return
          value"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove some redundant
          assignments"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: fix unused function warning in VF
          driver"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: modify hnae_ to hnae3_"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: use dma_zalloc_coherent instead
          of kzalloc/dma_map_single"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: give default option while
          dependency HNS3 set"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove some unused members of
          some structures"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove a redundant
          hclge_cmd_csq_done"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: using modulo for cyclic counters
          in hclge_cmd_send"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: simplify hclge_cmd_csq_clean"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove some redundant
          assignments"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove useless code in
          hclge_cmd_send"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove unused
          hclge_ring_to_dma_dir"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: use lower_32_bits and
          upper_32_bits"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove back in struct hclge_hw"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: add unlikely for error check"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove the Redundant put_vector
          in hns3_client_uninit"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: print the ret value in error
          information"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: extraction an interface for state
          state init|uninit"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove unused head file in
          hnae3.c"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: add l4_type check for both ipv4
          and ipv6"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: add vector status check before
          free vector"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: rename the interface for
          init_client_instance and uninit_client_instance"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: remove hclge_get_vector_index
          from hclge_bind_ring_with_vector"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: RX BD information valid only in
          last BD except VLD bit and buffer size"
        - Revert "UBUNTU: SAUCE: {topost} net: hns3: add support for serdes loopback
          selftest"
        - net: hns3: Updates RX packet info fetch in case of multi BD
        - net: hns3: remove unused hclgevf_cfg_func_mta_filter
        - net: hns3: Fix for VF mailbox cannot receiving PF response
        - net: hns3: Fix for VF mailbox receiving unknown message
        - net: hns3: Optimize PF CMDQ interrupt switching process
        - net: hns3: remove hclge_get_vector_index from hclge_bind_ring_with_vector
        - net: hns3: rename the interface for init_client_instance and
          uninit_client_instance
        - net: hns3: add vector status check before free vector
        - net: hns3: add l4_type check for both ipv4 and ipv6
        - net: hns3: add unlikely for error check
        - net: hns3: remove unused head file in hnae3.c
        - net: hns3: extraction an interface for state init|uninit
        - net: hns3: print the ret value in error information
        - net: hns3: remove the Redundant put_vector in hns3_client_uninit
        - net: hns3: remove back in struct hclge_hw
        - net: hns3: use lower_32_bits and upper_32_bits
        - net: hns3: remove unused hclge_ring_to_dma_dir
        - net: hns3: remove useless code in hclge_cmd_send
        - net: hns3: remove some redundant assignments
        - net: hns3: simplify hclge_cmd_csq_clean
        - net: hns3: remove a redundant hclge_cmd_csq_done
        - net: hns3: remove some unused members of some structures
        - net: hns3: give default option while dependency HNS3 set
        - net: hns3: use dma_zalloc_coherent instead of kzalloc/dma_map_single
        - net: hns3: modify hnae_ to hnae3_
        - net: hns3: Fix tc setup when netdev is first up
        - net: hns3: Fix for mac pause not disable in pfc mode
        - net: hns3: Fix for waterline not setting correctly
        - net: hns3: Fix for l4 checksum offload bug
        - net: hns3: Fix for mailbox message truncated problem
        - net: hns3: Add configure for mac minimal frame size
        - net: hns3: Fix warning bug when doing lp selftest
        - net: hns3: Fix get_vector ops in hclgevf_main module
        - net: hns3: Remove the warning when clear reset cause
        - net: hns3: Prevent sending command during global or core reset
        - net: hns3: Modify the order of initializing command queue register
        - net: hns3: Reset net device with rtnl_lock
        - net: hns3: Prevent to request reset frequently
        - net: hns3: Correct reset event status register
        - net: hns3: Fix return value error in hns3_reset_notify_down_enet
        - net: hns3: remove unnecessary ring configuration operation while resetting
        - net: hns3: Fix for reset_level default assignment probelm
        - net: hns3: Fix for using wrong mask and shift in
          hclge_get_ring_chain_from_mbx
        - net: hns3: Fix comments for hclge_get_ring_chain_from_mbx
        - net: hns3: Remove some redundant assignments
        - net: hns3: Standardize the handle of return value
        - net: hns3: Remove extra space and brackets
        - net: hns3: Correct unreasonable code comments
        - net: hns3: Use decimal for bit offset macros
        - net: hns3: Modify inconsistent bit mask macros
        - net: hns3: Fix misleading parameter name
        - net: hns3: Remove unused struct member and definition
        - net: hns3: Add SPDX tags to HNS3 PF driver
        - net: hns3: Add support for serdes loopback selftest
        - net: hns3: Fix for phy link issue when using marvell phy driver
        - SAUCE: {topost} net: hns3: separate roce from nic when resetting
      * CVE-2018-6555
        - SAUCE: irda: Only insert new objects into the global database via setsockopt
      * CVE-2018-6554
        - SAUCE: irda: Fix memory leak caused by repeated binds of irda socket
      * Bionic update: upstream stable patchset 2018-08-31 (LP: #1790188)
        - netfilter: nf_tables: fix NULL pointer dereference on
          nft_ct_helper_obj_dump()
        - blkdev_report_zones_ioctl(): Use vmalloc() to allocate large buffers
        - af_key: Always verify length of provided sadb_key
        - gpio: No NULL owner
        - KVM: X86: Fix reserved bits check for MOV to CR3
        - KVM: x86: introduce linear_{read,write}_system
        - KVM: x86: pass kvm_vcpu to kvm_read_guest_virt and
          kvm_write_guest_virt_system
        - staging: android: ion: Switch to pr_warn_once in ion_buffer_destroy
        - NFC: pn533: don't send USB data off of the stack
        - usbip: vhci_sysfs: fix potential Spectre v1
        - usb-storage: Add support for FL_ALWAYS_SYNC flag in the UAS driver
        - usb-storage: Add compatibility quirk flags for G-Technologies G-Drive
        - Input: xpad - add GPD Win 2 Controller USB IDs
        - phy: qcom-qusb2: Fix crash if nvmem cell not specified
        - usb: gadget: function: printer: avoid wrong list handling in printer_write()
        - usb: gadget: udc: renesas_usb3: disable the controller's irqs for
          reconnecting
        - serial: sh-sci: Stop using printk format %pCr
        - tty/serial: atmel: use port->name as name in request_irq()
        - serial: samsung: fix maxburst parameter for DMA transactions
        - serial: 8250: omap: Fix idling of clocks for unused uarts
        - vmw_balloon: fixing double free when batching mode is off
        - tty: pl011: Avoid spuriously stuck-off interrupts
        - kvm: x86: use correct privilege level for sgdt/sidt/fxsave/fxrstor access
        - Input: goodix - add new ACPI id for GPD Win 2 touch screen
        - crypto: caam - strip input zeros from RSA input buffer
        - crypto: caam - fix DMA mapping dir for generated IV
        - crypto: caam - fix IV DMA mapping and updating
        - crypto: caam/qi - fix IV DMA mapping and updating
        - crypto: caam - fix size of RSA prime factor q
        - crypto: vmx - Remove overly verbose printk from AES init routines
        - crypto: vmx - Remove overly verbose printk from AES XTS init
        - crypto: omap-sham - fix memleak
        - usb: typec: wcove: Remove dependency on HW FSM
        - usb: gadget: udc: renesas_usb3: fix double phy_put()
        - usb: gadget: udc: renesas_usb3: should remove debugfs
        - usb: gadget: udc: renesas_usb3: should call pm_runtime_enable() before add
          udc
        - usb: gadget: udc: renesas_usb3: should call devm_phy_get() before add udc
        - usb: gadget: udc: renesas_usb3: should fail if devm_phy_get() returns error
      * Bionic update: upstream stable patchset 2018-08-29 (LP: #1789666)
        - scsi: sd_zbc: Avoid that resetting a zone fails sporadically
        - mmap: introduce sane default mmap limits
        - mmap: relax file size limit for regular files
        - btrfs: define SUPER_FLAG_METADUMP_V2
        - kconfig: Avoid format overflow warning from GCC 8.1
        - be2net: Fix error detection logic for BE3
        - bnx2x: use the right constant
        - dccp: don't free ccid2_hc_tx_sock struct in dccp_disconnect()
        - enic: set DMA mask to 47 bit
        - ip6mr: only set ip6mr_table from setsockopt when ip6mr_new_table succeeds
        - ip6_tunnel: remove magic mtu value 0xFFF8
        - ipmr: properly check rhltable_init() return value
        - ipv4: remove warning in ip_recv_error
        - ipv6: omit traffic class when calculating flow hash
        - isdn: eicon: fix a missing-check bug
        - kcm: Fix use-after-free caused by clonned sockets
        - netdev-FAQ: clarify DaveM's position for stable backports
        - net: ipv4: add missing RTA_TABLE to rtm_ipv4_policy
        - net: metrics: add proper netlink validation
        - net/packet: refine check for priv area size
        - net: phy: broadcom: Fix bcm_write_exp()
        - net: usb: cdc_mbim: add flag FLAG_SEND_ZLP
        - packet: fix reserve calculation
        - qed: Fix mask for physical address in ILT entry
        - sctp: not allow transport timeout value less than HZ/5 for hb_timer
        - team: use netdev_features_t instead of u32
        - vhost: synchronize IOTLB message with dev cleanup
        - vrf: check the original netdevice for generating redirect
        - ipv6: sr: fix memory OOB access in seg6_do_srh_encap/inline
        - net: phy: broadcom: Fix auxiliary control register reads
        - net-sysfs: Fix memory leak in XPS configuration
        - virtio-net: correctly transmit XDP buff after linearizing
        - net/mlx4: Fix irq-unsafe spinlock usage
        - tun: Fix NULL pointer dereference in XDP redirect
        - virtio-net: correctly check num_buf during err path
        - net/mlx5e: When RXFCS is set, add FCS data into checksum calculation
        - virtio-net: fix leaking page for gso packet during mergeable XDP
        - rtnetlink: validate attributes in do_setlink()
        - cls_flower: Fix incorrect idr release when failing to modify rule
        - PCI: hv: Do not wait forever on a device that has disappeared
        - drm: set FMODE_UNSIGNED_OFFSET for drm files
        - l2tp: fix refcount leakage on PPPoL2TP sockets
        - mlxsw: spectrum: Forbid creation of VLAN 1 over port/LAG
        - net: ethernet: ti: cpdma: correct error handling for chan create
        - net: ethernet: davinci_emac: fix error handling in probe()
        - net: dsa: b53: Fix for brcm tag issue in Cygnus SoC
        - net : sched: cls_api: deal with egdev path only if needed
      * Bionic update: upstream stable patchset 2018-08-24 (LP: #1788897)
        - fix io_destroy()/aio_complete() race
        - mm: fix the NULL mapping case in __isolate_lru_page()
        - objtool: Support GCC 8's cold subfunctions
        - objtool: Support GCC 8 switch tables
        - objtool: Detect RIP-relative switch table references
        - objtool: Detect RIP-relative switch table references, part 2
        - objtool: Fix "noreturn" detection for recursive sibling calls
        - xfs: convert XFS_AGFL_SIZE to a helper function
        - xfs: detect agfl count corruption and reset agfl
        - Input: synaptics - Lenovo Carbon X1 Gen5 (2017) devices should use RMI
        - Input: synaptics - add Lenovo 80 series ids to SMBus
        - Input: elan_i2c_smbus - fix corrupted stack
        - tracing: Fix crash when freeing instances with event triggers
        - tracing: Make the snapshot trigger work with instances
        - selinux: KASAN: slab-out-of-bounds in xattr_getsecurity
        - cfg80211: further limit wiphy names to 64 bytes
        - drm/amd/powerplay: Fix enum mismatch
        - rtlwifi: rtl8192cu: Remove variable self-assignment in rf.c
        - platform/chrome: cros_ec_lpc: remove redundant pointer request
        - kbuild: clang: disable unused variable warnings only when constant
        - tcp: avoid integer overflows in tcp_rcv_space_adjust()
        - iio: ad7793: implement IIO_CHAN_INFO_SAMP_FREQ
        - iio:buffer: make length types match kfifo types
        - iio:kfifo_buf: check for uint overflow
        - iio: adc: select buffer for at91-sama5d2_adc
        - MIPS: lantiq: gphy: Drop reboot/remove reset asserts
        - MIPS: ptrace: Fix PTRACE_PEEKUSR requests for 64-bit FGRs
        - MIPS: prctl: Disallow FRE without FR with PR_SET_FP_MODE requests
        - scsi: scsi_transport_srp: Fix shost to rport translation
        - stm class: Use vmalloc for the master map
        - hwtracing: stm: fix build error on some arches
        - IB/core: Fix error code for invalid GID entry
        - mm/huge_memory.c: __split_huge_page() use atomic ClearPageDirty()
        - Revert "rt2800: use TXOP_BACKOFF for probe frames"
        - intel_th: Use correct device when freeing buffers
        - drm/psr: Fix missed entry in PSR setup time table.
        - drm/i915/lvds: Move acpi lid notification registration to registration phase
        - drm/i915: Disable LVDS on Radiant P845
        - drm/vmwgfx: Use kasprintf
        - drm/vmwgfx: Fix host logging / guestinfo reading error paths
        - nvme: fix extended data LBA supported setting
        - iio: hid-sensor-trigger: Fix sometimes not powering up the sensor after
          resume
        - x86/MCE/AMD: Define a function to get SMCA bank type
        - x86/mce/AMD: Pass the bank number to smca_get_bank_type()
        - x86/mce/AMD, EDAC/mce_amd: Enumerate Reserved SMCA bank type
        - x86/mce/AMD: Carve out SMCA get_block_address() code
        - x86/MCE/AMD: Cache SMCA MISC block addresses
      * errors when scanning partition table of corrupted AIX disk (LP: #1787281)
        - partitions/aix: fix usage of uninitialized lv_info and lvname structures
        - partitions/aix: append null character to print data from disk
      * tlbie master timeout checkstop (using NVidia/GPU) (LP: #1789772)
        - powerpc/mm/hugetlb: Update huge_ptep_set_access_flags to call
          __ptep_set_access_flags directly
        - powerpc/mm/radix: Move function from radix.h to pgtable-radix.c
        - powerpc/mm: Change function prototype
        - powerpc/mm/radix: Change pte relax sequence to handle nest MMU hang
      * performance drop with ATS enabled (LP: #1788097)
        - powerpc/powernv: Fix concurrency issue with npu->mmio_atsd_usage
      * [Regression] kernel crashdump fails on arm64 (LP: #1786878)
        - arm64: export memblock_reserve()d regions via /proc/iomem
        - drivers: acpi: add dependency of EFI for arm64
        - efi/arm: preserve early mapping of UEFI memory map longer for BGRT
        - efi/arm: map UEFI memory map even w/o runtime services enabled
        - arm64: acpi: fix alignment fault in accessing ACPI
        - [Config] CONFIG_ARCH_SUPPORTS_ACPI=y
        - arm64: fix ACPI dependencies
        - ACPI: fix menuconfig presentation of ACPI submenu
      * TB 16 issue on Dell Lattitude 7490 with large amount of data (LP: #1785780)
        - r8152: disable RX aggregation on new Dell TB16 dock
      * dell_wmi: Unknown key codes (LP: #1762385)
        - platform/x86: dell-wmi: Ignore new rfkill and fn-lock events
      * Enable AMD PCIe MP2 for AMDI0011 (LP: #1773940)
        - SAUCE: i2c:amd I2C Driver based on PCI Interface for upcoming platform
        - SAUCE: i2c:amd move out pointer in union i2c_event_base
        - SAUCE: i2c:amd Depends on ACPI
        - [Config] i2c: CONFIG_I2C_AMD_MP2=y on x86
      * r8169 no internet after suspending (LP: #1779817)
        - r8169: restore previous behavior to accept BIOS WoL settings
        - r8169: don't use MSI-X on RTL8168g
        - r8169: don't use MSI-X on RTL8106e
      * Fix Intel Cannon Lake LPSS I2C input clock (LP: #1789790)
        - mfd: intel-lpss: Fix Intel Cannon Lake LPSS I2C input clock
      * Microphone cannot be detected with front panel audio combo jack on HP Z8-G4
        machine (LP: #1789145)
        - ALSA: hda/realtek - Fix HP Headset Mic can't record
      * Tango platform uses __initcall without further checks (LP: #1787945)
        - [Config] disable ARCH_TANGO
      * [18.10 FEAT] Add kernel config option "CONFIG_SCLP_OFB" (LP: #1787898)
        - [Config] CONFIG_SCLP_OFB=y for s390x
    
     -- Khalid Elmously <email address hidden>  Thu, 13 Sep 2018 16:02:21 -0400
  • linux-gcp (4.15.0-1019.20) bionic; urgency=medium
    
      * linux-gcp: 4.15.0-1019.20 -proposed tracker (LP: #1788752)
    
    
      [ Ubuntu: 4.15.0-34.37 ]
    
      * linux: 4.15.0-34.37 -proposed tracker (LP: #1788744)
      * Bionic update: upstream stable patchset 2018-08-09 (LP: #1786352)
        - MIPS: c-r4k: Fix data corruption related to cache coherence
        - MIPS: ptrace: Expose FIR register through FP regset
        - MIPS: Fix ptrace(2) PTRACE_PEEKUSR and PTRACE_POKEUSR accesses to o32 FGRs
        - KVM: Fix spelling mistake: "cop_unsuable" -> "cop_unusable"
        - affs_lookup(): close a race with affs_remove_link()
        - fs: don't scan the inode cache before SB_BORN is set
        - aio: fix io_destroy(2) vs. lookup_ioctx() race
        - ALSA: timer: Fix pause event notification
        - do d_instantiate/unlock_new_inode combinations safely
        - mmc: sdhci-iproc: remove hard coded mmc cap 1.8v
        - mmc: sdhci-iproc: fix 32bit writes for TRANSFER_MODE register
        - mmc: sdhci-iproc: add SDHCI_QUIRK2_HOST_OFF_CARD_ON for cygnus
        - libata: Blacklist some Sandisk SSDs for NCQ
        - libata: blacklist Micron 500IT SSD with MU01 firmware
        - xen-swiotlb: fix the check condition for xen_swiotlb_free_coherent
        - drm/vmwgfx: Fix 32-bit VMW_PORT_HB_[IN|OUT] macros
        - arm64: lse: Add early clobbers to some input/output asm operands
        - powerpc/64s: Clear PCR on boot
        - IB/hfi1: Use after free race condition in send context error path
        - IB/umem: Use the correct mm during ib_umem_release
        - idr: fix invalid ptr dereference on item delete
        - Revert "ipc/shm: Fix shmat mmap nil-page protection"
        - ipc/shm: fix shmat() nil address after round-down when remapping
        - mm/kasan: don't vfree() nonexistent vm_area
        - kasan: free allocated shadow memory on MEM_CANCEL_ONLINE
        - kasan: fix memory hotplug during boot
        - kernel/sys.c: fix potential Spectre v1 issue
        - KVM: s390: vsie: fix < 8k check for the itdba
        - KVM: x86: Update cpuid properly when CR4.OSXAVE or CR4.PKE is changed
        - kvm: x86: IA32_ARCH_CAPABILITIES is always supported
        - powerpc/64s: Improve RFI L1-D cache flush fallback
        - powerpc/pseries: Restore default security feature flags on setup
        - powerpc/64s: Fix section mismatch warnings from setup_rfi_flush()
        - MIPS: generic: Fix machine compatible matching
        - mac80211: mesh: fix wrong mesh TTL offset calculation
        - ARC: Fix malformed ARC_EMUL_UNALIGNED default
        - ptr_ring: prevent integer overflow when calculating size
        - arm64: dts: rockchip: fix rock64 gmac2io stability issues
        - arm64: dts: rockchip: correct ep-gpios for rk3399-sapphire
        - libata: Fix compile warning with ATA_DEBUG enabled
        - selftests: sync: missing CFLAGS while compiling
        - selftest/vDSO: fix O=
        - selftests: pstore: Adding config fragment CONFIG_PSTORE_RAM=m
        - selftests: memfd: add config fragment for fuse
        - ARM: OMAP2+: timer: fix a kmemleak caused in omap_get_timer_dt
        - ARM: OMAP3: Fix prm wake interrupt for resume
        - ARM: OMAP2+: Fix sar_base inititalization for HS omaps
        - ARM: OMAP1: clock: Fix debugfs_create_*() usage
        - tls: retrun the correct IV in getsockopt
        - xhci: workaround for AMD Promontory disabled ports wakeup
        - IB/uverbs: Fix method merging in uverbs_ioctl_merge
        - IB/uverbs: Fix possible oops with duplicate ioctl attributes
        - IB/uverbs: Fix unbalanced unlock on error path for rdma_explicit_destroy
        - arm64: dts: rockchip: Fix DWMMC clocks
        - ARM: dts: rockchip: Fix DWMMC clocks
        - iwlwifi: mvm: fix security bug in PN checking
        - iwlwifi: mvm: fix IBSS for devices that support station type API
        - iwlwifi: mvm: always init rs with 20mhz bandwidth rates
        - NFC: llcp: Limit size of SDP URI
        - rxrpc: Work around usercopy check
        - MD: Free bioset when md_run fails
        - md: fix md_write_start() deadlock w/o metadata devices
        - s390/dasd: fix handling of internal requests
        - xfrm: do not call rcu_read_unlock when afinfo is NULL in xfrm_get_tos
        - mac80211: round IEEE80211_TX_STATUS_HEADROOM up to multiple of 4
        - mac80211: fix a possible leak of station stats
        - mac80211: fix calling sleeping function in atomic context
        - cfg80211: clear wep keys after disconnection
        - mac80211: Do not disconnect on invalid operating class
        - mac80211: Fix sending ADDBA response for an ongoing session
        - gpu: ipu-v3: pre: fix device node leak in ipu_pre_lookup_by_phandle
        - gpu: ipu-v3: prg: fix device node leak in ipu_prg_lookup_by_phandle
        - md raid10: fix NULL deference in handle_write_completed()
        - drm/exynos: g2d: use monotonic timestamps
        - drm/exynos: fix comparison to bitshift when dealing with a mask
        - drm/meson: fix vsync buffer update
        - arm64: perf: correct PMUVer probing
        - RDMA/bnxt_re: Unpin SQ and RQ memory if QP create fails
        - RDMA/bnxt_re: Fix system crash during load/unload
        - net/mlx5e: Return error if prio is specified when offloading eswitch vlan
          push
        - locking/xchg/alpha: Add unconditional memory barrier to cmpxchg()
        - md: raid5: avoid string overflow warning
        - virtio_net: fix XDP code path in receive_small()
        - kernel/relay.c: limit kmalloc size to KMALLOC_MAX_SIZE
        - bug.h: work around GCC PR82365 in BUG()
        - selftests/memfd: add run_fuse_test.sh to TEST_FILES
        - seccomp: add a selftest for get_metadata
        - soc: imx: gpc: de-register power domains only if initialized
        - powerpc/bpf/jit: Fix 32-bit JIT for seccomp_data access
        - s390/cio: fix ccw_device_start_timeout API
        - s390/cio: fix return code after missing interrupt
        - s390/cio: clear timer when terminating driver I/O
        - selftests/bpf/test_maps: exit child process without error in ENOMEM case
        - PKCS#7: fix direct verification of SignerInfo signature
        - arm64: dts: cavium: fix PCI bus dtc warnings
        - nfs: system crashes after NFS4ERR_MOVED recovery
        - ARM: OMAP: Fix dmtimer init for omap1
        - smsc75xx: fix smsc75xx_set_features()
        - regulatory: add NUL to request alpha2
        - integrity/security: fix digsig.c build error with header file
        - x86/intel_rdt: Fix incorrect returned value when creating rdgroup sub-
          directory in resctrl file system
        - locking/xchg/alpha: Fix xchg() and cmpxchg() memory ordering bugs
        - x86/topology: Update the 'cpu cores' field in /proc/cpuinfo correctly across
          CPU hotplug operations
        - mac80211: drop frames with unexpected DS bits from fast-rx to slow path
        - arm64: fix unwind_frame() for filtered out fn for function graph tracing
        - macvlan: fix use-after-free in macvlan_common_newlink()
        - KVM: nVMX: Don't halt vcpu when L1 is injecting events to L2
        - kvm: fix warning for CONFIG_HAVE_KVM_EVENTFD builds
        - ARM: dts: imx6dl: Include correct dtsi file for Engicam i.CoreM6
          DualLite/Solo RQS
        - fs: dcache: Avoid livelock between d_alloc_parallel and __d_add
        - fs: dcache: Use READ_ONCE when accessing i_dir_seq
        - md: fix a potential deadlock of raid5/raid10 reshape
        - md/raid1: fix NULL pointer dereference
        - batman-adv: fix packet checksum in receive path
        - batman-adv: invalidate checksum on fragment reassembly
        - netfilter: ipt_CLUSTERIP: put config struct if we can't increment ct
          refcount
        - netfilter: ipt_CLUSTERIP: put config instead of freeing it
        - netfilter: ebtables: convert BUG_ONs to WARN_ONs
        - batman-adv: Ignore invalid batadv_iv_gw during netlink send
        - batman-adv: Ignore invalid batadv_v_gw during netlink send
        - batman-adv: Fix netlink dumping of BLA claims
        - batman-adv: Fix netlink dumping of BLA backbones
        - nvme-pci: Fix nvme queue cleanup if IRQ setup fails
        - clocksource/drivers/fsl_ftm_timer: Fix error return checking
        - libceph, ceph: avoid memory leak when specifying same option several times
        - ceph: fix dentry leak when failing to init debugfs
        - xen/pvcalls: fix null pointer dereference on map->sock
        - ARM: orion5x: Revert commit 4904dbda41c8.
        - qrtr: add MODULE_ALIAS macro to smd
        - selftests/futex: Fix line continuation in Makefile
        - r8152: fix tx packets accounting
        - virtio-gpu: fix ioctl and expose the fixed status to userspace.
        - dmaengine: rcar-dmac: fix max_chunk_size for R-Car Gen3
        - bcache: fix kcrashes with fio in RAID5 backend dev
        - ip_gre: fix IFLA_MTU ignored on NEWLINK
        - ip6_tunnel: fix IFLA_MTU ignored on NEWLINK
        - sit: fix IFLA_MTU ignored on NEWLINK
        - nbd: fix return value in error handling path
        - ARM: dts: NSP: Fix amount of RAM on BCM958625HR
        - ARM: dts: bcm283x: Fix unit address of local_intc
        - powerpc/boot: Fix random libfdt related build errors
        - clocksource/drivers/mips-gic-timer: Use correct shift count to extract data
        - gianfar: Fix Rx byte accounting for ndev stats
        - net/tcp/illinois: replace broken algorithm reference link
        - nvmet: fix PSDT field check in command format
        - net/smc: use link_id of server in confirm link reply
        - mlxsw: core: Fix flex keys scratchpad offset conflict
        - mlxsw: spectrum: Treat IPv6 unregistered multicast as broadcast
        - spectrum: Reference count VLAN entries
        - ARC: mcip: halt GFRC counter when ARC cores halt
        - ARC: mcip: update MCIP debug mask when the new cpu came online
        - ARC: setup cpu possible mask according to possible-cpus dts property
        - ipvs: remove IPS_NAT_MASK check to fix passive FTP
        - IB/mlx: Set slid to zero in Ethernet completion struct
        - RDMA/bnxt_re: Unconditionly fence non wire memory operations
        - RDMA/bnxt_re: Fix incorrect DB offset calculation
        - RDMA/bnxt_re: Fix the ib_reg failure cleanup
        - xen/pirq: fix error path cleanup when binding MSIs
        - drm/amd/amdgpu: Correct VRAM width for APUs with GMC9
        - xfrm: Fix ESN sequence number handling for IPsec GSO packets.
        - arm64: dts: rockchip: Fix rk3399-gru-* s2r (pinctrl hogs, wifi reset)
        - drm/sun4i: Fix dclk_set_phase
        - btrfs: use kvzalloc to allocate btrfs_fs_info
        - Btrfs: send, fix issuing write op when processing hole in no data mode
        - Btrfs: fix log replay failure after linking special file and fsync
        - ceph: fix potential memory leak in init_caches()
        - block: display the correct diskname for bio
        - selftests/powerpc: Skip the subpage_prot tests if the syscall is unavailable
        - net: ethtool: don't ignore return from driver get_fecparam method
        - iwlwifi: mvm: fix TX of CCMP 256
        - iwlwifi: mvm: Fix channel switch for count 0 and 1
        - iwlwifi: mvm: fix assert 0x2B00 on older FWs
        - iwlwifi: avoid collecting firmware dump if not loaded
        - iwlwifi: mvm: Direct multicast frames to the correct station
        - iwlwifi: mvm: Correctly set the tid for mcast queue
        - rds: Incorrect reference counting in TCP socket creation
        - watchdog: f71808e_wdt: Fix magic close handling
        - batman-adv: Fix multicast packet loss with a single WANT_ALL_IPV4/6 flag
        - hv_netvsc: use napi_schedule_irqoff
        - hv_netvsc: filter multicast/broadcast
        - hv_netvsc: propagate rx filters to VF
        - ARM: dts: rockchip: Add missing #sound-dai-cells on rk3288
        - e1000e: Fix check_for_link return value with autoneg off
        - e1000e: allocate ring descriptors with dma_zalloc_coherent
        - ia64/err-inject: Use get_user_pages_fast()
        - RDMA/qedr: Fix kernel panic when running fio over NFSoRDMA
        - RDMA/qedr: Fix iWARP write and send with immediate
        - IB/mlx4: Fix corruption of RoCEv2 IPv4 GIDs
        - IB/mlx4: Include GID type when deleting GIDs from HW table under RoCE
        - IB/mlx5: Fix an error code in __mlx5_ib_modify_qp()
        - fbdev: Fixing arbitrary kernel leak in case FBIOGETCMAP_SPARC in
          sbusfb_ioctl_helper().
        - fsl/fman: avoid sleeping in atomic context while adding an address
        - qed: Free RoCE ILT Memory on rmmod qedr
        - net: qcom/emac: Use proper free methods during TX
        - net: smsc911x: Fix unload crash when link is up
        - IB/core: Fix possible crash to access NULL netdev
        - cxgb4: do not set needs_free_netdev for mgmt dev's
        - xen-blkfront: move negotiate_mq to cover all cases of new VBDs
        - xen: xenbus: use put_device() instead of kfree()
        - hv_netvsc: fix filter flags
        - hv_netvsc: fix locking for rx_mode
        - hv_netvsc: fix locking during VF setup
        - ARM: davinci: fix the GPIO lookup for omapl138-hawk
        - arm64: Relax ARM_SMCCC_ARCH_WORKAROUND_1 discovery
        - selftests/vm/run_vmtests: adjust hugetlb size according to nr_cpus
        - lib/test_kmod.c: fix limit check on number of test devices created
        - dmaengine: mv_xor_v2: Fix clock resource by adding a register clock
        - netfilter: ebtables: fix erroneous reject of last rule
        - can: m_can: change comparison to bitshift when dealing with a mask
        - can: m_can: select pinctrl state in each suspend/resume function
        - bnxt_en: Check valid VNIC ID in bnxt_hwrm_vnic_set_tpa().
        - workqueue: use put_device() instead of kfree()
        - ipv4: lock mtu in fnhe when received PMTU < net.ipv4.route.min_pmtu
        - sunvnet: does not support GSO for sctp
        - KVM: arm/arm64: vgic: Add missing irq_lock to vgic_mmio_read_pending
        - gpu: ipu-v3: prg: avoid possible array underflow
        - drm/imx: move arming of the vblank event to atomic_flush
        - drm/nouveau/bl: fix backlight regression
        - xfrm: fix rcu_read_unlock usage in xfrm_local_error
        - iwlwifi: mvm: set the correct tid when we flush the MCAST sta
        - iwlwifi: mvm: Correctly set IGTK for AP
        - iwlwifi: mvm: fix error checking for multi/broadcast sta
        - net: Fix vlan untag for bridge and vlan_dev with reorder_hdr off
        - vlan: Fix out of order vlan headers with reorder header off
        - batman-adv: fix header size check in batadv_dbg_arp()
        - batman-adv: Fix skbuff rcsum on packet reroute
        - vti4: Don't count header length twice on tunnel setup
        - ip_tunnel: Clamp MTU to bounds on new link
        - vti6: Fix dev->max_mtu setting
        - iwlwifi: mvm: Increase session protection time after CS
        - iwlwifi: mvm: clear tx queue id when unreserving aggregation queue
        - iwlwifi: mvm: make sure internal station has a valid id
        - iwlwifi: mvm: fix array out of bounds reference
        - drm/tegra: Shutdown on driver unbind
        - perf/cgroup: Fix child event counting bug
        - brcmfmac: Fix check for ISO3166 code
        - kbuild: make scripts/adjust_autoksyms.sh robust against timestamp races
        - RDMA/ucma: Correct option size check using optlen
        - RDMA/qedr: fix QP's ack timeout configuration
        - RDMA/qedr: Fix rc initialization on CNQ allocation failure
        - RDMA/qedr: Fix QP state initialization race
        - net/sched: fix idr leak on the error path of tcf_bpf_init()
        - net/sched: fix idr leak in the error path of tcf_simp_init()
        - net/sched: fix idr leak in the error path of tcf_act_police_init()
        - net/sched: fix idr leak in the error path of tcp_pedit_init()
        - net/sched: fix idr leak in the error path of __tcf_ipt_init()
        - net/sched: fix idr leak in the error path of tcf_skbmod_init()
        - net: dsa: Fix functional dsa-loop dependency on FIXED_PHY
        - drm/ast: Fixed 1280x800 Display Issue
        - mm/mempolicy.c: avoid use uninitialized preferred_node
        - mm, thp: do not cause memcg oom for thp
        - xfrm: Fix transport mode skb control buffer usage.
        - selftests: ftrace: Add probe event argument syntax testcase
        - selftests: ftrace: Add a testcase for string type with kprobe_event
        - selftests: ftrace: Add a testcase for probepoint
        - drm/amdkfd: Fix scratch memory with HWS enabled
        - batman-adv: fix multicast-via-unicast transmission with AP isolation
        - batman-adv: fix packet loss for broadcasted DHCP packets to a server
        - ARM: 8748/1: mm: Define vdso_start, vdso_end as array
        - lan78xx: Set ASD in MAC_CR when EEE is enabled.
        - net: qmi_wwan: add BroadMobi BM806U 2020:2033
        - bonding: fix the err path for dev hwaddr sync in bond_enslave
        - net: dsa: mt7530: fix module autoloading for OF platform drivers
        - net/mlx5: Make eswitch support to depend on switchdev
        - perf/x86/intel: Fix linear IP of PEBS real_ip on Haswell and later CPUs
        - x86/alternatives: Fixup alternative_call_2
        - llc: properly handle dev_queue_xmit() return value
        - builddeb: Fix header package regarding dtc source links
        - qede: Fix barrier usage after tx doorbell write.
        - mm, slab: memcg_link the SLAB's kmem_cache
        - mm/page_owner: fix recursion bug after changing skip entries
        - mm/kmemleak.c: wait for scan completion before disabling free
        - hv_netvsc: enable multicast if necessary
        - qede: Do not drop rx-checksum invalidated packets.
        - net: Fix untag for vlan packets without ethernet header
        - vlan: Fix vlan insertion for packets without ethernet header
        - net: mvneta: fix enable of all initialized RXQs
        - sh: fix debug trap failure to process signals before return to user
        - firmware: dmi_scan: Fix UUID length safety check
        - nvme: don't send keep-alives to the discovery controller
        - Btrfs: clean up resources during umount after trans is aborted
        - Btrfs: fix loss of prealloc extents past i_size after fsync log replay
        - x86/pgtable: Don't set huge PUD/PMD on non-leaf entries
        - fs/proc/proc_sysctl.c: fix potential page fault while unregistering sysctl
          table
        - swap: divide-by-zero when zero length swap file on ssd
        - z3fold: fix memory leak
        - sr: get/drop reference to device in revalidate and check_events
        - Force log to disk before reading the AGF during a fstrim
        - cpufreq: CPPC: Initialize shared perf capabilities of CPUs
        - powerpc/fscr: Enable interrupts earlier before calling get_user()
        - perf tools: Fix perf builds with clang support
        - perf clang: Add support for recent clang versions
        - dp83640: Ensure against premature access to PHY registers after reset
        - ibmvnic: Zero used TX descriptor counter on reset
        - mm/ksm: fix interaction with THP
        - mm: fix races between address_space dereference and free in page_evicatable
        - mm: thp: fix potential clearing to referenced flag in
          page_idle_clear_pte_refs_one()
        - Btrfs: bail out on error during replay_dir_deletes
        - Btrfs: fix NULL pointer dereference in log_dir_items
        - btrfs: Fix possible softlock on single core machines
        - IB/rxe: Fix for oops in rxe_register_device on ppc64le arch
        - ocfs2/dlm: don't handle migrate lockres if already in shutdown
        - powerpc/64s/idle: Fix restore of AMOR on POWER9 after deep sleep
        - sched/rt: Fix rq->clock_update_flags < RQCF_ACT_SKIP warning
        - x86/mm: Fix bogus warning during EFI bootup, use boot_cpu_has() instead of
          this_cpu_has() in build_cr3_noflush()
        - KVM: VMX: raise internal error for exception during invalid protected mode
          state
        - lan78xx: Connect phy early
        - sparc64: Make atomic_xchg() an inline function rather than a macro.
        - net: bgmac: Fix endian access in bgmac_dma_tx_ring_free()
        - net: bgmac: Correctly annotate register space
        - btrfs: tests/qgroup: Fix wrong tree backref level
        - Btrfs: fix copy_items() return value when logging an inode
        - btrfs: fix lockdep splat in btrfs_alloc_subvolume_writers
        - btrfs: qgroup: Fix root item corruption when multiple same source snapshots
          are created with quota enabled
        - rxrpc: Fix Tx ring annotation after initial Tx failure
        - rxrpc: Don't treat call aborts as conn aborts
        - xen/acpi: off by one in read_acpi_id()
        - drivers: macintosh: rack-meter: really fix bogus memsets
        - ACPI: acpi_pad: Fix memory leak in power saving threads
        - powerpc/mpic: Check if cpu_possible() in mpic_physmask()
        - ieee802154: ca8210: fix uninitialised data read
        - ath10k: advertize beacon_int_min_gcd
        - iommu/amd: Take into account that alloc_dev_data() may return NULL
        - intel_th: Use correct method of finding hub
        - m68k: set dma and coherent masks for platform FEC ethernets
        - iwlwifi: mvm: check if mac80211_queue is valid in iwl_mvm_disable_txq
        - parisc/pci: Switch LBA PCI bus from Hard Fail to Soft Fail mode
        - hwmon: (nct6775) Fix writing pwmX_mode
        - powerpc/perf: Prevent kernel address leak to userspace via BHRB buffer
        - powerpc/perf: Fix kernel address leak via sampling registers
        - rsi: fix kernel panic observed on 64bit machine
        - tools/thermal: tmon: fix for segfault
        - selftests: Print the test we're running to /dev/kmsg
        - net/mlx5: Protect from command bit overflow
        - watchdog: davinci_wdt: fix error handling in davinci_wdt_probe()
        - ath10k: Fix kernel panic while using worker (ath10k_sta_rc_update_wk)
        - nvme-pci: disable APST for Samsung NVMe SSD 960 EVO + ASUS PRIME Z370-A
        - ath9k: fix crash in spectral scan
        - cxgb4: Setup FW queues before registering netdev
        - ima: Fix Kconfig to select TPM 2.0 CRB interface
        - ima: Fallback to the builtin hash algorithm
        - watchdog: aspeed: Allow configuring for alternate boot
        - arm: dts: socfpga: fix GIC PPI warning
        - ext4: don't complain about incorrect features when probing
        - drm/vmwgfx: Unpin the screen object backup buffer when not used
        - iommu/mediatek: Fix protect memory setting
        - cpufreq: cppc_cpufreq: Fix cppc_cpufreq_init() failure path
        - IB/mlx5: Set the default active rate and width to QDR and 4X
        - zorro: Set up z->dev.dma_mask for the DMA API
        - bcache: quit dc->writeback_thread when BCACHE_DEV_DETACHING is set
        - remoteproc: imx_rproc: Fix an error handling path in 'imx_rproc_probe()'
        - dt-bindings: add device tree binding for Allwinner H6 main CCU
        - ACPICA: Events: add a return on failure from acpi_hw_register_read
        - ACPICA: Fix memory leak on unusual memory leak
        - ACPICA: acpi: acpica: fix acpi operand cache leak in nseval.c
        - cxgb4: Fix queue free path of ULD drivers
        - i2c: mv64xxx: Apply errata delay only in standard mode
        - KVM: lapic: stop advertising DIRECTED_EOI when in-kernel IOAPIC is in use
        - perf top: Fix top.call-graph config option reading
        - perf stat: Fix core dump when flag T is used
        - IB/core: Honor port_num while resolving GID for IB link layer
        - drm/amdkfd: add missing include of mm.h
        - coresight: Use %px to print pcsr instead of %p
        - regulator: gpio: Fix some error handling paths in 'gpio_regulator_probe()'
        - spi: bcm-qspi: fIX some error handling paths
        - net/smc: pay attention to MAX_ORDER for CQ entries
        - MIPS: ath79: Fix AR724X_PLL_REG_PCIE_CONFIG offset
        - watchdog: dw: RMW the control register
        - watchdog: aspeed: Fix translation of reset mode to ctrl register
        - drm/meson: Fix some error handling paths in 'meson_drv_bind_master()'
        - drm/meson: Fix an un-handled error path in 'meson_drv_bind_master()'
        - powerpc: Add missing prototype for arch_irq_work_raise()
        - f2fs: fix to set KEEP_SIZE bit in f2fs_zero_range
        - f2fs: fix to clear CP_TRIMMED_FLAG
        - f2fs: fix to check extent cache in f2fs_drop_extent_tree
        - perf/core: Fix installing cgroup events on CPU
        - max17042: propagate of_node to power supply device
        - perf/core: Fix perf_output_read_group()
        - drm/panel: simple: Fix the bus format for the Ontat panel
        - hwmon: (pmbus/max8688) Accept negative page register values
        - hwmon: (pmbus/adm1275) Accept negative page register values
        - perf/x86/intel: Properly save/restore the PMU state in the NMI handler
        - cdrom: do not call check_disk_change() inside cdrom_open()
        - efi/arm*: Only register page tables when they exist
        - perf/x86/intel: Fix large period handling on Broadwell CPUs
        - perf/x86/intel: Fix event update for auto-reload
        - arm64: dts: qcom: Fix SPI5 config on MSM8996
        - soc: qcom: wcnss_ctrl: Fix increment in NV upload
        - gfs2: Fix fallocate chunk size
        - x86/devicetree: Initialize device tree before using it
        - x86/devicetree: Fix device IRQ settings in DT
        - phy: rockchip-emmc: retry calpad busy trimming
        - ALSA: vmaster: Propagate slave error
        - phy: qcom-qmp: Fix phy pipe clock gating
        - drm/bridge: sii902x: Retry status read after DDI I2C
        - tools: hv: fix compiler warnings about major/target_fname
        - block: null_blk: fix 'Invalid parameters' when loading module
        - dmaengine: pl330: fix a race condition in case of threaded irqs
        - dmaengine: rcar-dmac: Check the done lists in rcar_dmac_chan_get_residue()
        - enic: enable rq before updating rq descriptors
        - watchdog: asm9260_wdt: fix error handling in asm9260_wdt_probe()
        - hwrng: stm32 - add reset during probe
        - pinctrl: devicetree: Fix dt_to_map_one_config handling of hogs
        - pinctrl: artpec6: dt: add missing pin group uart5nocts
        - vfio-ccw: fence off transport mode
        - dmaengine: qcom: bam_dma: get num-channels and num-ees from dt
        - drm: omapdrm: dss: Move initialization code from component bind to probe
        - ARM: dts: dra71-evm: Correct evm_sd regulator max voltage
        - drm/amdgpu: disable GFX ring and disable PQ wptr in hw_fini
        - drm/amdgpu: adjust timeout for ib_ring_tests(v2)
        - net: stmmac: ensure that the device has released ownership before reading
          data
        - net: stmmac: ensure that the MSS desc is the last desc to set the own bit
        - cpufreq: Reorder cpufreq_online() error code path
        - dpaa_eth: fix SG mapping
        - PCI: Add function 1 DMA alias quirk for Marvell 88SE9220
        - udf: Provide saner default for invalid uid / gid
        - ixgbe: prevent ptp_rx_hang from running when in FILTER_ALL mode
        - sh_eth: fix TSU init on SH7734/R8A7740
        - power: supply: ltc2941-battery-gauge: Fix temperature units
        - ARM: dts: bcm283x: Fix probing of bcm2835-i2s
        - ARM: dts: bcm283x: Fix pin function of JTAG pins
        - PCMCIA / PM: Avoid noirq suspend aborts during suspend-to-idle
        - audit: return on memory error to avoid null pointer dereference
        - net: stmmac: call correct function in stmmac_mac_config_rx_queues_routing()
        - rcu: Call touch_nmi_watchdog() while printing stall warnings
        - pinctrl: sh-pfc: r8a7796: Fix MOD_SEL register pin assignment for SSI pins
          group
        - dpaa_eth: fix pause capability advertisement logic
        - MIPS: Octeon: Fix logging messages with spurious periods after newlines
        - drm/rockchip: Respect page offset for PRIME mmap calls
        - x86/apic: Set up through-local-APIC mode on the boot CPU if 'noapic'
          specified
        - perf test: Fix test case inet_pton to accept inlines.
        - perf report: Fix wrong jump arrow
        - perf tests: Use arch__compare_symbol_names to compare symbols
        - perf report: Fix memory corruption in --branch-history mode --branch-history
        - perf tests: Fix dwarf unwind for stripped binaries
        - selftests/net: fixes psock_fanout eBPF test case
        - netlabel: If PF_INET6, check sk_buff ip header version
        - drm: rcar-du: lvds: Fix LVDS startup on R-Car Gen3
        - drm: rcar-du: lvds: Fix LVDS startup on R-Car Gen2
        - ARM: dts: at91: tse850: use the correct compatible for the eeprom
        - regmap: Correct comparison in regmap_cached
        - i40e: Add delay after EMP reset for firmware to recover
        - ARM: dts: imx7d: cl-som-imx7: fix pinctrl_enet
        - ARM: dts: porter: Fix HDMI output routing
        - regulator: of: Add a missing 'of_node_put()' in an error handling path of
          'of_regulator_match()'
        - pinctrl: mcp23s08: spi: Fix regmap debugfs entries
        - kdb: make "mdr" command repeat
        - drm/vmwgfx: Set dmabuf_size when vmw_dmabuf_init is successful
        - perf tools: Add trace/beauty/generated/ into .gitignore
        - tools: sync up .h files with the repective arch and uapi .h files
        - MIPS: xilfpga: Stop generating useless dtb.o
        - MIPS: xilfpga: Actually include FDT in fitImage
        - MIPS: Fix build with DEBUG_ZBOOT and MACH_JZ4770
        - fix breakage caused by d_find_alias() semantics change
        - Btrfs: fix error handling in btrfs_truncate()
        - mmc: block: propagate correct returned value in mmc_rpmb_ioctl
        - arm64: export tishift functions to modules
        - bcma: fix buffer size caused crash in bcma_core_mips_print_irq()
        - PM / core: Fix direct_complete handling for devices with no callbacks
        - ARM: dts: sun4i: Fix incorrect clocks for displays
        - bnxt_en: Ignore src port field in decap filter nodes
        - kasan, slub: fix handling of kasan_slab_free hook
        - riscv/spinlock: Strengthen implementations with fences
        - platform/x86: dell-smbios: Fix memory leaks in build_tokens_sysfs()
        - rxrpc: Fix resend event time calculation
        - i40e: hold the RTNL lock while changing interrupt schemes
        - hv_netvsc: Fix the return status in RX path
        - firmware: fix checking for return values for fw_add_devm_name()
        - bcache: set writeback_rate_update_seconds in range [1, 60] seconds
        - bcache: fix cached_dev->count usage for bch_cache_set_error()
        - bcache: stop dc->writeback_rate_update properly
        - ibmvnic: Fix reset return from closed state
        - powerpc/vas: Fix cleanup when VAS is not configured
        - f2fs: flush cp pack except cp pack 2 page at first
        - drm/amdgpu: Clean sdma wptr register when only enable wptr polling
        - powerpc/mm/slice: Remove intermediate bitmap copy
        - powerpc/mm/slice: create header files dedicated to slices
        - powerpc/mm/slice: Enhance for supporting PPC32
        - powerpc/mm/slice: Fix hugepage allocation at hint address on 8xx
        - ibmvnic: Allocate statistics buffers during probe
        - dt-bindings: display: msm/dsi: Fix the PHY regulator supply props
        - drm/amd/display: Set vsc pack revision when DPCD revision is >= 1.2
        - soc: renesas: r8a77970-sysc: fix power area parents
        - drm/vblank: Data type fixes for 64-bit vblank sequences.
        - selftests: Add FIB onlink tests
        - soc: amlogic: meson-gx-pwrc-vpu: fix error on shutdown when domain is
          powered off
      * arm-smmu-v3 arm-smmu-v3.1.auto: failed to allocate MSIs (LP: #1785282)
        - ACPICA: iasl: Add SMMUv3 device ID mapping index support
        - ACPI/IORT: Remove temporary iort_get_id_mapping_index() ACPICA guard
      * Driver iwlwifi for Intel Wireless-AC 9560 is slow and unreliable in kernel
        4.15.0-20-generic (LP: #1772467)
        - scsi: hpsa: disable device during shutdown
      * [Bionic] i2c: xlp9xx: Add SMBAlert support  (LP: #1786981)
        - i2c: xlp9xx: Add support for SMBAlert
      * qeth: don't clobber buffer on async TX completion (LP: #1786057)
        - s390/qeth: don't clobber buffer on async TX completion
      * Linux 4.15.0-23 crashes during the boot process with a "Unable to handle
        kernel NULL pointer dereference" message (LP: #1777338)
        - x86/xen: Add call of speculative_store_bypass_ht_init() to PV paths
      * ThinkPad systems have no HDMI sound when using the nvidia GPU (LP: #1787058)
        - ACPI / OSI: Add OEM _OSI string to enable NVidia HDMI audio
      * [Bionic] i2c: xlp9xx: Fix case where SSIF read transaction completes early
        (LP: #1787240)
        - i2c: xlp9xx: Fix case where SSIF read transaction completes early
      * [Bionic] integrate upstream fix for Cavium zram driver (LP: #1787469)
        - Revert "UBUNTU: SAUCE: crypto: thunderx_zip: Fix fallout from
          CONFIG_VMAP_STACK"
        - crypto: cavium - Fix fallout from CONFIG_VMAP_STACK
        - crypto: cavium - Limit result reading attempts
        - crypto: cavium - Prevent division by zero
        - crypto: cavium - Fix statistics pending request value
        - crypto: cavium - Fix smp_processor_id() warnings
      * Bugfix for handling of shadow doorbell buffer (LP: #1788222)
        - nvme-pci: add a memory barrier to nvme_dbbuf_update_and_check_event
      * nvme devices namespace assigned to the wrong controller (LP: #1789227)
        - nvme/multipath: Fix multipath disabled naming collisions
      * linux-cloud-tools-common: Ensure hv-kvp-daemon.service starts before
        walinuxagent.service (LP: #1739107)
        - [Debian] hyper-v -- Ensure that hv-kvp-daemon.service starts before
          walinuxagent.service
      * hinic interfaces aren't getting predictable names (LP: #1783138)
        - hinic: Link the logical network device to the pci device in sysfs
      * Suspend fails in Ubuntu and Kubuntu 18.04 but works fine in Ubuntu and
        Kubuntu 17.10 (and on Kubuntu 18.04 using kernel 4.14.47) (LP: #1774950)
        - ACPI / LPSS: Avoid PM quirks on suspend and resume from S3
        - ACPI / LPSS: Avoid PM quirks on suspend and resume from hibernation
      * [Bionic] Bluetooth: Support RTL8723D and RTL8821C Devices (LP: #1784835)
        - Bluetooth: btrtl: Add RTL8723D and RTL8821C devices
      * CacheFiles: Error: Overlong wait for old active object to go away.
        (LP: #1776254)
        - cachefiles: Fix missing clear of the CACHEFILES_OBJECT_ACTIVE flag
        - cachefiles: Wait rather than BUG'ing on "Unexpected object collision"
      * fscache cookie refcount updated incorrectly during fscache object allocation
        (LP: #1776277) // fscache cookie refcount updated incorrectly during fscache
        object allocation (LP: #1776277)
        - fscache: Fix reference overput in fscache_attach_object() error handling
      * FS-Cache: Assertion failed: FS-Cache: 6 == 5 is false (LP: #1774336)
        - Revert "UBUNTU: SAUCE: CacheFiles: fix a read_waiter/read_copier race"
        - fscache: Allow cancelled operations to be enqueued
        - cachefiles: Fix refcounting bug in backing-file read monitoring
      * SMB3: Fix regression in server reconnect detection (LP: #1786110)
        - smb3: on reconnect set PreviousSessionId field
      * CVE-2018-1118
        - vhost: fix info leak due to uninitialized memory
    
     -- Khalid Elmously <email address hidden>  Wed, 29 Aug 2018 00:25:20 -0400
  • linux-gcp (4.15.0-1018.19) bionic; urgency=medium
    
      * linux-gcp: 4.15.0-1018.19 -proposed tracker (LP: #1787156)
    
      * linux-gcp: add a signed kernel (LP: #1782557)
        - [Configuration] enable EFI signing support
    
      [ Ubuntu: 4.15.0-33.36 ]
    
      * linux: 4.15.0-33.36 -proposed tracker (LP: #1787149)
      * RTNL assertion failure on ipvlan (LP: #1776927)
        - ipvlan: drop ipv6 dependency
        - ipvlan: use per device spinlock to protect addrs list updates
        - SAUCE: fix warning from "ipvlan: drop ipv6 dependency"
      * ubuntu_bpf_jit test failed on Bionic s390x systems (LP: #1753941)
        - test_bpf: flag tests that cannot be jited on s390
      * HDMI/DP audio can't work on the laptop of Dell Latitude 5495 (LP: #1782689)
        - drm/nouveau: fix nouveau_dsm_get_client_id()'s return type
        - drm/radeon: fix radeon_atpx_get_client_id()'s return type
        - drm/amdgpu: fix amdgpu_atpx_get_client_id()'s return type
        - platform/x86: apple-gmux: fix gmux_get_client_id()'s return type
        - ALSA: hda: use PCI_BASE_CLASS_DISPLAY to replace PCI_CLASS_DISPLAY_VGA
        - vga_switcheroo: set audio client id according to bound GPU id
      * locking sockets broken due to missing AppArmor socket mediation patches
        (LP: #1780227)
        - UBUNTU SAUCE: apparmor: fix apparmor mediating locking non-fs, unix sockets
      * Update2 for ocxl driver (LP: #1781436)
        - ocxl: Fix page fault handler in case of fault on dying process
      * netns: unable to follow an interface that moves to another netns
        (LP: #1774225)
        - net: core: Expose number of link up/down transitions
        - dev: always advertise the new nsid when the netns iface changes
        - dev: advertise the new ifindex when the netns iface changes
      * [Bionic] Disk IO hangs when using BFQ as io scheduler (LP: #1780066)
        - block, bfq: fix occurrences of request finish method's old name
        - block, bfq: remove batches of confusing ifdefs
        - block, bfq: add requeue-request hook
      * HP ProBook 455 G5 needs mute-led-gpio fixup (LP: #1781763)
        - ALSA: hda: add mute led support for HP ProBook 455 G5
      * [Bionic] bug fixes to improve stability of the ThunderX2 i2c driver
        (LP: #1781476)
        - i2c: xlp9xx: Fix issue seen when updating receive length
        - i2c: xlp9xx: Make sure the transfer size is not more than
          I2C_SMBUS_BLOCK_SIZE
      * x86/kvm: fix LAPIC timer drift when guest uses periodic mode (LP: #1778486)
        - x86/kvm: fix LAPIC timer drift when guest uses periodic mode
      * Please include ax88179_178a and r8152 modules in d-i udeb (LP: #1771823)
        - [Config:] d-i: Add ax88179_178a and r8152 to nic-modules
      * Nvidia fails after switching its mode (LP: #1778658)
        - PCI: Restore config space on runtime resume despite being unbound
      * Kernel error "task zfs:pid blocked for more than 120 seconds" (LP: #1781364)
        - SAUCE: (noup) zfs to 0.7.5-1ubuntu16.3
      * CVE-2018-12232
        - PATCH 1/1] socket: close race condition between sock_close() and
          sockfs_setattr()
      * CVE-2018-10323
        - xfs: set format back to extents if xfs_bmap_extents_to_btree
      * change front mic location for more lenovo m7/8/9xx machines (LP: #1781316)
        - ALSA: hda/realtek - Fix the problem of two front mics on more machines
        - ALSA: hda/realtek - two more lenovo models need fixup of MIC_LOCATION
      * Cephfs + fscache: unable to handle kernel NULL pointer dereference at
        0000000000000000 IP: jbd2__journal_start+0x22/0x1f0 (LP: #1783246)
        - ceph: track read contexts in ceph_file_info
      * Touchpad of ThinkPad P52 failed to work with message "lost sync at byte"
        (LP: #1779802)
        - Input: elantech - fix V4 report decoding for module with middle key
        - Input: elantech - enable middle button of touchpads on ThinkPad P52
      * xhci_hcd 0000:00:14.0: Root hub is not suspended (LP: #1779823)
        - usb: xhci: dbc: Fix lockdep warning
        - usb: xhci: dbc: Don't decrement runtime PM counter if DBC is not started
      * CVE-2018-13406
        - video: uvesafb: Fix integer overflow in allocation
      * CVE-2018-10840
        - ext4: correctly handle a zero-length xattr with a non-zero e_value_offs
      * CVE-2018-11412
        - ext4: do not allow external inodes for inline data
      * CVE-2018-10881
        - ext4: clear i_data in ext4_inode_info when removing inline data
      * CVE-2018-12233
        - jfs: Fix inconsistency between memory allocation and ea_buf->max_size
      * CVE-2018-12904
        - kvm: nVMX: Enforce cpl=0 for VMX instructions
      * Error parsing PCC subspaces from PCCT (LP: #1528684)
        - mailbox: PCC: erroneous error message when parsing ACPI PCCT
      * CVE-2018-13094
        - xfs: don't call xfs_da_shrink_inode with NULL bp
      * other users' coredumps can be read via setgid directory and killpriv bypass
        (LP: #1779923) // CVE-2018-13405
        - Fix up non-directory creation in SGID directories
      * Invoking obsolete 'firmware_install' target breaks snap build (LP: #1782166)
        - snapcraft.yaml: stop invoking the obsolete (and non-existing)
          'firmware_install' target
      * snapcraft.yaml: missing ubuntu-retpoline-extract-one script breaks the build
        (LP: #1782116)
        - snapcraft.yaml: copy retpoline-extract-one to scripts before build
      * Allow Raven Ridge's audio controller to be runtime suspended (LP: #1782540)
        - ALSA: hda: Add AZX_DCAPS_PM_RUNTIME for AMD Raven Ridge
      * CVE-2018-11506
        - sr: pass down correctly sized SCSI sense buffer
      * Bionic update: upstream stable patchset 2018-07-24 (LP: #1783418)
        - net: Fix a bug in removing queues from XPS map
        - net/mlx4_core: Fix error handling in mlx4_init_port_info.
        - net/sched: fix refcnt leak in the error path of tcf_vlan_init()
        - net: sched: red: avoid hashing NULL child
        - net/smc: check for missing nlattrs in SMC_PNETID messages
        - net: test tailroom before appending to linear skb
        - packet: in packet_snd start writing at link layer allocation
        - sock_diag: fix use-after-free read in __sk_free
        - tcp: purge write queue in tcp_connect_init()
        - vmxnet3: set the DMA mask before the first DMA map operation
        - vmxnet3: use DMA memory barriers where required
        - hv_netvsc: empty current transmit aggregation if flow blocked
        - hv_netvsc: Use the num_online_cpus() for channel limit
        - hv_netvsc: avoid retry on send during shutdown
        - hv_netvsc: only wake transmit queue if link is up
        - hv_netvsc: fix error unwind handling if vmbus_open fails
        - hv_netvsc: cancel subchannel setup before halting device
        - hv_netvsc: fix race in napi poll when rescheduling
        - hv_netvsc: defer queue selection to VF
        - hv_netvsc: disable NAPI before channel close
        - hv_netvsc: use RCU to fix concurrent rx and queue changes
        - hv_netvsc: change GPAD teardown order on older versions
        - hv_netvsc: common detach logic
        - hv_netvsc: Use Windows version instead of NVSP version on GPAD teardown
        - hv_netvsc: Split netvsc_revoke_buf() and netvsc_teardown_gpadl()
        - hv_netvsc: Ensure correct teardown message sequence order
        - hv_netvsc: Fix a network regression after ifdown/ifup
        - sparc: vio: use put_device() instead of kfree()
        - ext2: fix a block leak
        - s390: add assembler macros for CPU alternatives
        - s390: move expoline assembler macros to a header
        - s390/crc32-vx: use expoline for indirect branches
        - s390/lib: use expoline for indirect branches
        - s390/ftrace: use expoline for indirect branches
        - s390/kernel: use expoline for indirect branches
        - s390: move spectre sysfs attribute code
        - s390: extend expoline to BC instructions
        - s390: use expoline thunks in the BPF JIT
        - scsi: sg: allocate with __GFP_ZERO in sg_build_indirect()
        - scsi: zfcp: fix infinite iteration on ERP ready list
        - loop: don't call into filesystem while holding lo_ctl_mutex
        - loop: fix LOOP_GET_STATUS lock imbalance
        - cfg80211: limit wiphy names to 128 bytes
        - hfsplus: stop workqueue when fill_super() failed
        - x86/kexec: Avoid double free_page() upon do_kexec_load() failure
        - usb: gadget: f_uac2: fix bFirstInterface in composite gadget
        - usb: dwc3: Undo PHY init if soft reset fails
        - usb: dwc3: omap: don't miss events during suspend/resume
        - usb: gadget: core: Fix use-after-free of usb_request
        - usb: gadget: fsl_udc_core: fix ep valid checks
        - usb: dwc2: Fix dwc2_hsotg_core_init_disconnected()
        - usb: cdc_acm: prevent race at write to acm while system resumes
        - net: usbnet: fix potential deadlock on 32bit hosts
        - ARM: dts: imx7d-sdb: Fix regulator-usb-otg2-vbus node name
        - usb: host: xhci-plat: revert "usb: host: xhci-plat: enable clk in resume
          timing"
        - USB: OHCI: Fix NULL dereference in HCDs using HCD_LOCAL_MEM
        - net/usb/qmi_wwan.c: Add USB id for lt4120 modem
        - net-usb: add qmi_wwan if on lte modem wistron neweb d18q1
        - Bluetooth: btusb: Add USB ID 7392:a611 for Edimax EW-7611ULB
        - ALSA: usb-audio: Add native DSD support for Luxman DA-06
        - usb: dwc3: Add SoftReset PHY synchonization delay
        - usb: dwc3: Update DWC_usb31 GTXFIFOSIZ reg fields
        - usb: dwc3: Makefile: fix link error on randconfig
        - xhci: zero usb device slot_id member when disabling and freeing a xhci slot
        - usb: dwc2: Fix interval type issue
        - usb: dwc2: hcd: Fix host channel halt flow
        - usb: dwc2: host: Fix transaction errors in host mode
        - usb: gadget: ffs: Let setup() return USB_GADGET_DELAYED_STATUS
        - usb: gadget: ffs: Execute copy_to_user() with USER_DS set
        - usbip: Correct maximum value of CONFIG_USBIP_VHCI_HC_PORTS
        - usb: gadget: udc: change comparison to bitshift when dealing with a mask
        - usb: gadget: composite: fix incorrect handling of OS desc requests
        - media: lgdt3306a: Fix module count mismatch on usb unplug
        - media: em28xx: USB bulk packet size fix
        - Bluetooth: btusb: Add device ID for RTL8822BE
        - xhci: Show what USB release number the xHC supports from protocol capablity
        - staging: bcm2835-audio: Release resources on module_exit()
        - staging: lustre: fix bug in osc_enter_cache_try
        - staging: fsl-dpaa2/eth: Fix incorrect casts
        - staging: rtl8192u: return -ENOMEM on failed allocation of priv->oldaddr
        - staging: ks7010: Use constants from ieee80211_eid instead of literal ints.
        - staging: lustre: lmv: correctly iput lmo_root
        - crypto: inside-secure - wait for the request to complete if in the backlog
        - crypto: atmel-aes - fix the keys zeroing on errors
        - crypto: ccp - don't disable interrupts while setting up debugfs
        - crypto: inside-secure - do not process request if no command was issued
        - crypto: inside-secure - fix the cache_len computation
        - crypto: inside-secure - fix the extra cache computation
        - crypto: sunxi-ss - Add MODULE_ALIAS to sun4i-ss
        - crypto: inside-secure - fix the invalidation step during cra_exit
        - scsi: mpt3sas: fix an out of bound write
        - scsi: ufs: Enable quirk to ignore sending WRITE_SAME command
        - scsi: bnx2fc: Fix check in SCSI completion handler for timed out request
        - scsi: sym53c8xx_2: iterator underflow in sym_getsync()
        - scsi: mptfusion: Add bounds check in mptctl_hp_targetinfo()
        - scsi: qla2xxx: Avoid triggering undefined behavior in
          qla2x00_mbx_completion()
        - scsi: storvsc: Increase cmd_per_lun for higher speed devices
        - scsi: qedi: Fix truncation of CHAP name and secret
        - scsi: aacraid: fix shutdown crash when init fails
        - scsi: qla4xxx: skip error recovery in case of register disconnect.
        - scsi: qedi: Fix kernel crash during port toggle
        - scsi: mpt3sas: Do not mark fw_event workqueue as WQ_MEM_RECLAIM
        - scsi: sd: Keep disk read-only when re-reading partition
        - scsi: iscsi_tcp: set BDI_CAP_STABLE_WRITES when data digest enabled
        - scsi: aacraid: Insure command thread is not recursively stopped
        - scsi: core: Make SCSI Status CONDITION MET equivalent to GOOD
        - scsi: mvsas: fix wrong endianness of sgpio api
        - ASoC: hdmi-codec: Fix module unloading caused kernel crash
        - ASoC: rockchip: rk3288-hdmi-analog: Select needed codecs
        - ASoC: samsung: odroid: Fix 32000 sample rate handling
        - ASoC: topology: create TLV data for dapm widgets
        - ASoC: samsung: i2s: Ensure the RCLK rate is properly determined
        - clk: rockchip: Fix wrong parent for SDMMC phase clock for rk3228
        - clk: Don't show the incorrect clock phase
        - clk: hisilicon: mark wdt_mux_p[] as const
        - clk: tegra: Fix pll_u rate configuration
        - clk: rockchip: Prevent calculating mmc phase if clock rate is zero
        - clk: samsung: s3c2410: Fix PLL rates
        - clk: samsung: exynos7: Fix PLL rates
        - clk: samsung: exynos5260: Fix PLL rates
        - clk: samsung: exynos5433: Fix PLL rates
        - clk: samsung: exynos5250: Fix PLL rates
        - clk: samsung: exynos3250: Fix PLL rates
        - media: dmxdev: fix error code for invalid ioctls
        - media: Don't let tvp5150_get_vbi() go out of vbi_ram_default array
        - media: ov5645: add missing of_node_put() in error path
        - media: cx23885: Override 888 ImpactVCBe crystal frequency
        - media: cx23885: Set subdev host data to clk_freq pointer
        - media: s3c-camif: fix out-of-bounds array access
        - media: lgdt3306a: Fix a double kfree on i2c device remove
        - media: em28xx: Add Hauppauge SoloHD/DualHD bulk models
        - media: v4l: vsp1: Fix display stalls when requesting too many inputs
        - media: i2c: adv748x: fix HDMI field heights
        - media: vb2: Fix videobuf2 to map correct area
        - media: vivid: fix incorrect capabilities for radio
        - media: cx25821: prevent out-of-bounds read on array card
        - serial: xuartps: Fix out-of-bounds access through DT alias
        - serial: sh-sci: Fix out-of-bounds access through DT alias
        - serial: samsung: Fix out-of-bounds access through serial port index
        - serial: mxs-auart: Fix out-of-bounds access through serial port index
        - serial: imx: Fix out-of-bounds access through serial port index
        - serial: fsl_lpuart: Fix out-of-bounds access through DT alias
        - serial: arc_uart: Fix out-of-bounds access through DT alias
        - serial: 8250: Don't service RX FIFO if interrupts are disabled
        - serial: altera: ensure port->regshift is honored consistently
        - rtc: snvs: Fix usage of snvs_rtc_enable
        - rtc: hctosys: Ensure system time doesn't overflow time_t
        - rtc: rk808: fix possible race condition
        - rtc: m41t80: fix race conditions
        - rtc: tx4939: avoid unintended sign extension on a 24 bit shift
        - rtc: rp5c01: fix possible race condition
        - rtc: goldfish: Add missing MODULE_LICENSE
        - cxgb4: Correct ntuple mask validation for hash filters
        - net: dsa: bcm_sf2: Fix RX_CLS_LOC_ANY overwrite for last rule
        - net: dsa: Do not register devlink for unused ports
        - net: dsa: bcm_sf2: Fix IPv6 rules and chain ID
        - net: dsa: bcm_sf2: Fix IPv6 rule half deletion
        - 3c59x: convert to generic DMA API
        - net: ip6_gre: Request headroom in __gre6_xmit()
        - net: ip6_gre: Split up ip6gre_tnl_link_config()
        - net: ip6_gre: Split up ip6gre_tnl_change()
        - net: ip6_gre: Split up ip6gre_newlink()
        - net: ip6_gre: Split up ip6gre_changelink()
        - qed: LL2 flush isles when connection is closed
        - qed: Fix possibility of list corruption during rmmod flows
        - qed: Fix LL2 race during connection terminate
        - powerpc: Move default security feature flags
        - Bluetooth: btusb: Add support for Intel Bluetooth device 22560 [8087:0026]
        - staging: fsl-dpaa2/eth: Fix incorrect kfree
        - crypto: inside-secure - move the digest to the request context
        - scsi: lpfc: Fix NVME Initiator FirstBurst
        - serial: mvebu-uart: fix tx lost characters
      * Bionic update: upstream stable patchset 2018-07-20 (LP: #1782846)
        - usbip: usbip_host: refine probe and disconnect debug msgs to be useful
        - usbip: usbip_host: delete device from busid_table after rebind
        - usbip: usbip_host: run rebind from exit when module is removed
        - usbip: usbip_host: fix NULL-ptr deref and use-after-free errors
        - usbip: usbip_host: fix bad unlock balance during stub_probe()
        - ALSA: usb: mixer: volume quirk for CM102-A+/102S+
        - ALSA: hda: Add Lenovo C50 All in one to the power_save blacklist
        - ALSA: control: fix a redundant-copy issue
        - spi: pxa2xx: Allow 64-bit DMA
        - spi: bcm-qspi: Avoid setting MSPI_CDRAM_PCS for spi-nor master
        - spi: bcm-qspi: Always read and set BSPI_MAST_N_BOOT_CTRL
        - KVM: arm/arm64: VGIC/ITS save/restore: protect kvm_read_guest() calls
        - KVM: arm/arm64: VGIC/ITS: protect kvm_read_guest() calls with SRCU lock
        - vfio: ccw: fix cleanup if cp_prefetch fails
        - tracing/x86/xen: Remove zero data size trace events
          trace_xen_mmu_flush_tlb{_all}
        - tee: shm: fix use-after-free via temporarily dropped reference
        - netfilter: nf_tables: free set name in error path
        - netfilter: nf_tables: can't fail after linking rule into active rule list
        - netfilter: nf_socket: Fix out of bounds access in nf_sk_lookup_slow_v{4,6}
        - i2c: designware: fix poll-after-enable regression
        - powerpc/powernv: Fix NVRAM sleep in invalid context when crashing
        - drm: Match sysfs name in link removal to link creation
        - lib/test_bitmap.c: fix bitmap optimisation tests to report errors correctly
        - radix tree: fix multi-order iteration race
        - mm: don't allow deferred pages with NEED_PER_CPU_KM
        - drm/i915/gen9: Add WaClearHIZ_WM_CHICKEN3 for bxt and glk
        - s390/qdio: fix access to uninitialized qdio_q fields
        - s390/qdio: don't release memory in qdio_setup_irq()
        - s390: remove indirect branch from do_softirq_own_stack
        - x86/pkeys: Override pkey when moving away from PROT_EXEC
        - x86/pkeys: Do not special case protection key 0
        - efi: Avoid potential crashes, fix the 'struct efi_pci_io_protocol_32'
          definition for mixed mode
        - ARM: 8771/1: kprobes: Prohibit kprobes on do_undefinstr
        - x86/mm: Drop TS_COMPAT on 64-bit exec() syscall
        - tick/broadcast: Use for_each_cpu() specially on UP kernels
        - ARM: 8769/1: kprobes: Fix to use get_kprobe_ctlblk after irq-disabed
        - ARM: 8770/1: kprobes: Prohibit probing on optimized_callback
        - ARM: 8772/1: kprobes: Prohibit kprobes on get_user functions
        - Btrfs: fix xattr loss after power failure
        - Btrfs: send, fix invalid access to commit roots due to concurrent
          snapshotting
        - btrfs: property: Set incompat flag if lzo/zstd compression is set
        - btrfs: fix crash when trying to resume balance without the resume flag
        - btrfs: Split btrfs_del_delalloc_inode into 2 functions
        - btrfs: Fix delalloc inodes invalidation during transaction abort
        - btrfs: fix reading stale metadata blocks after degraded raid1 mounts
        - xhci: Fix USB3 NULL pointer dereference at logical disconnect.
        - KVM: arm/arm64: Properly protect VGIC locks from IRQs
        - KVM: arm/arm64: VGIC/ITS: Promote irq_lock() in update_affinity
        - hwmon: (k10temp) Fix reading critical temperature register
        - hwmon: (k10temp) Use API function to access System Management Network
        - vsprintf: Replace memory barrier with static_key for random_ptr_key update
        - x86/amd_nb: Add support for Raven Ridge CPUs
        - x86/apic/x2apic: Initialize cluster ID properly
      * Bionic update: upstream stable patchset 2018-07-09 (LP: #1780858)
        - 8139too: Use disable_irq_nosync() in rtl8139_poll_controller()
        - bridge: check iface upper dev when setting master via ioctl
        - dccp: fix tasklet usage
        - ipv4: fix fnhe usage by non-cached routes
        - ipv4: fix memory leaks in udp_sendmsg, ping_v4_sendmsg
        - llc: better deal with too small mtu
        - net: ethernet: sun: niu set correct packet size in skb
        - net: ethernet: ti: cpsw: fix packet leaking in dual_mac mode
        - net/mlx4_en: Fix an error handling path in 'mlx4_en_init_netdev()'
        - net/mlx4_en: Verify coalescing parameters are in range
        - net/mlx5e: Err if asked to offload TC match on frag being first
        - net/mlx5: E-Switch, Include VF RDMA stats in vport statistics
        - net sched actions: fix refcnt leak in skbmod
        - net_sched: fq: take care of throttled flows before reuse
        - net: support compat 64-bit time in {s,g}etsockopt
        - net/tls: Don't recursively call push_record during tls_write_space callbacks
        - net/tls: Fix connection stall on partial tls record
        - openvswitch: Don't swap table in nlattr_set() after OVS_ATTR_NESTED is found
        - qmi_wwan: do not steal interfaces from class drivers
        - r8169: fix powering up RTL8168h
        - rds: do not leak kernel memory to user land
        - sctp: delay the authentication for the duplicated cookie-echo chunk
        - sctp: fix the issue that the cookie-ack with auth can't get processed
        - sctp: handle two v4 addrs comparison in sctp_inet6_cmp_addr
        - sctp: remove sctp_chunk_put from fail_mark err path in
          sctp_ulpevent_make_rcvmsg
        - sctp: use the old asoc when making the cookie-ack chunk in dupcook_d
        - tcp_bbr: fix to zero idle_restart only upon S/ACKed data
        - tcp: ignore Fast Open on repair mode
        - tg3: Fix vunmap() BUG_ON() triggered from tg3_free_consistent().
        - bonding: do not allow rlb updates to invalid mac
        - bonding: send learning packets for vlans on slave
        - net: sched: fix error path in tcf_proto_create() when modules are not
          configured
        - net/mlx5e: TX, Use correct counter in dma_map error flow
        - net/mlx5: Avoid cleaning flow steering table twice during error flow
        - hv_netvsc: set master device
        - ipv6: fix uninit-value in ip6_multipath_l3_keys()
        - net/mlx5e: Allow offloading ipv4 header re-write for icmp
        - nsh: fix infinite loop
        - udp: fix SO_BINDTODEVICE
        - l2tp: revert "l2tp: fix missing print session offset info"
        - proc: do not access cmdline nor environ from file-backed areas
        - net/smc: restrict non-blocking connect finish
        - mlxsw: spectrum_switchdev: Do not remove mrouter port from MDB's ports list
        - net/mlx5e: DCBNL fix min inline header size for dscp
        - net: systemport: Correclty disambiguate driver instances
        - sctp: clear the new asoc's stream outcnt in sctp_stream_update
        - tcp: restore autocorking
        - tipc: fix one byte leak in tipc_sk_set_orig_addr()
        - hv_netvsc: Fix net device attach on older Windows hosts
      * Bionic update: upstream stable patchset 2018-07-06 (LP: #1780499)
        - ext4: prevent right-shifting extents beyond EXT_MAX_BLOCKS
        - ipvs: fix rtnl_lock lockups caused by start_sync_thread
        - netfilter: ebtables: don't attempt to allocate 0-sized compat array
        - kcm: Call strp_stop before strp_done in kcm_attach
        - crypto: af_alg - fix possible uninit-value in alg_bind()
        - netlink: fix uninit-value in netlink_sendmsg
        - net: fix rtnh_ok()
        - net: initialize skb->peeked when cloning
        - net: fix uninit-value in __hw_addr_add_ex()
        - dccp: initialize ireq->ir_mark
        - ipv4: fix uninit-value in ip_route_output_key_hash_rcu()
        - soreuseport: initialise timewait reuseport field
        - inetpeer: fix uninit-value in inet_getpeer
        - memcg: fix per_node_info cleanup
        - perf: Remove superfluous allocation error check
        - tcp: fix TCP_REPAIR_QUEUE bound checking
        - bdi: wake up concurrent wb_shutdown() callers.
        - bdi: Fix oops in wb_workfn()
        - gpioib: do not free unrequested descriptors
        - gpio: fix aspeed_gpio unmask irq
        - gpio: fix error path in lineevent_create
        - rfkill: gpio: fix memory leak in probe error path
        - libata: Apply NOLPM quirk for SanDisk SD7UB3Q*G1001 SSDs
        - dm integrity: use kvfree for kvmalloc'd memory
        - tracing: Fix regex_match_front() to not over compare the test string
        - z3fold: fix reclaim lock-ups
        - mm: sections are not offlined during memory hotremove
        - mm, oom: fix concurrent munlock and oom reaper unmap, v3
        - ceph: fix rsize/wsize capping in ceph_direct_read_write()
        - can: kvaser_usb: Increase correct stats counter in kvaser_usb_rx_can_msg()
        - can: hi311x: Acquire SPI lock on ->do_get_berr_counter
        - can: hi311x: Work around TX complete interrupt erratum
        - drm/vc4: Fix scaling of uni-planar formats
        - drm/i915: Fix drm:intel_enable_lvds ERROR message in kernel log
        - drm/atomic: Clean old_state/new_state in drm_atomic_state_default_clear()
        - drm/atomic: Clean private obj old_state/new_state in
          drm_atomic_state_default_clear()
        - net: atm: Fix potential Spectre v1
        - atm: zatm: Fix potential Spectre v1
        - cpufreq: schedutil: Avoid using invalid next_freq
        - Revert "Bluetooth: btusb: Fix quirk for Atheros 1525/QCA6174"
        - Bluetooth: btusb: Only check needs_reset_resume DMI table for QCA rome
          chipsets
        - thermal: exynos: Reading temperature makes sense only when TMU is turned on
        - thermal: exynos: Propagate error value from tmu_read()
        - nvme: add quirk to force medium priority for SQ creation
        - smb3: directory sync should not return an error
        - sched/autogroup: Fix possible Spectre-v1 indexing for sched_prio_to_weight[]
        - tracing/uprobe_event: Fix strncpy corner case
        - perf/x86: Fix possible Spectre-v1 indexing for hw_perf_event cache_*
        - perf/x86/cstate: Fix possible Spectre-v1 indexing for pkg_msr
        - perf/x86/msr: Fix possible Spectre-v1 indexing in the MSR driver
        - perf/core: Fix possible Spectre-v1 indexing for ->aux_pages[]
        - perf/x86: Fix possible Spectre-v1 indexing for x86_pmu::event_map()
        - i2c: dev: prevent ZERO_SIZE_PTR deref in i2cdev_ioctl_rdwr()
        - bdi: Fix use after free bug in debugfs_remove()
        - drm/ttm: Use GFP_TRANSHUGE_LIGHT for allocating huge pages
        - drm/i915: Adjust eDP's logical vco in a reliable place.
        - drm/nouveau/ttm: don't dereference nvbo::cli, it can outlive client
        - sched/core: Fix possible Spectre-v1 indexing for sched_prio_to_weight[]
      * Bionic update: upstream stable patchset 2018-06-26 (LP: #1778759)
        - percpu: include linux/sched.h for cond_resched()
        - ACPI / button: make module loadable when booted in non-ACPI mode
        - USB: serial: option: Add support for Quectel EP06
        - ALSA: hda - Fix incorrect usage of IS_REACHABLE()
        - ALSA: pcm: Check PCM state at xfern compat ioctl
        - ALSA: seq: Fix races at MIDI encoding in snd_virmidi_output_trigger()
        - ALSA: dice: fix kernel NULL pointer dereference due to invalid calculation
          for array index
        - ALSA: aloop: Mark paused device as inactive
        - ALSA: aloop: Add missing cable lock to ctl API callbacks
        - tracepoint: Do not warn on ENOMEM
        - scsi: target: Fix fortify_panic kernel exception
        - Input: leds - fix out of bound access
        - Input: atmel_mxt_ts - add touchpad button mapping for Samsung Chromebook Pro
        - rtlwifi: btcoex: Add power_on_setting routine
        - rtlwifi: cleanup 8723be ant_sel definition
        - xfs: prevent creating negative-sized file via INSERT_RANGE
        - RDMA/cxgb4: release hw resources on device removal
        - RDMA/ucma: Allow resolving address w/o specifying source address
        - RDMA/mlx5: Fix multiple NULL-ptr deref errors in rereg_mr flow
        - RDMA/mlx5: Protect from shift operand overflow
        - NET: usb: qmi_wwan: add support for ublox R410M PID 0x90b2
        - IB/mlx5: Use unlimited rate when static rate is not supported
        - IB/hfi1: Fix handling of FECN marked multicast packet
        - IB/hfi1: Fix loss of BECN with AHG
        - IB/hfi1: Fix NULL pointer dereference when invalid num_vls is used
        - iw_cxgb4: Atomically flush per QP HW CQEs
        - drm/vmwgfx: Fix a buffer object leak
        - drm/bridge: vga-dac: Fix edid memory leak
        - test_firmware: fix setting old custom fw path back on exit, second try
        - errseq: Always report a writeback error once
        - USB: serial: visor: handle potential invalid device configuration
        - usb: dwc3: gadget: Fix list_del corruption in dwc3_ep_dequeue
        - USB: Accept bulk endpoints with 1024-byte maxpacket
        - USB: serial: option: reimplement interface masking
        - USB: serial: option: adding support for ublox R410M
        - usb: musb: host: fix potential NULL pointer dereference
        - usb: musb: trace: fix NULL pointer dereference in musb_g_tx()
        - platform/x86: asus-wireless: Fix NULL pointer dereference
        - irqchip/qcom: Fix check for spurious interrupts
        - tracing: Fix bad use of igrab in trace_uprobe.c
        - [Config] CONFIG_ARM64_ERRATUM_1024718=y
        - arm64: Add work around for Arm Cortex-A55 Erratum 1024718
        - Input: atmel_mxt_ts - add touchpad button mapping for Samsung Chromebook Pro
        - infiniband: mlx5: fix build errors when INFINIBAND_USER_ACCESS=m
        - btrfs: Take trans lock before access running trans in check_delayed_ref
        - drm/vc4: Make sure vc4_bo_{inc,dec}_usecnt() calls are balanced
        - xhci: Fix use-after-free in xhci_free_virt_device
        - platform/x86: Kconfig: Fix dell-laptop dependency chain.
        - KVM: x86: remove APIC Timer periodic/oneshot spikes
        - clocksource: Allow clocksource_mark_unstable() on unregistered clocksources
        - clocksource: Initialize cs->wd_list
        - clocksource: Consistent de-rate when marking unstable
      * Bionic update: upstream stable patchset 2018-06-22 (LP: #1778265)
        - ext4: set h_journal if there is a failure starting a reserved handle
        - ext4: add MODULE_SOFTDEP to ensure crc32c is included in the initramfs
        - ext4: add validity checks for bitmap block numbers
        - ext4: fix bitmap position validation
        - random: fix possible sleeping allocation from irq context
        - random: rate limit unseeded randomness warnings
        - usbip: usbip_event: fix to not print kernel pointer address
        - usbip: usbip_host: fix to hold parent lock for device_attach() calls
        - usbip: vhci_hcd: Fix usb device and sockfd leaks
        - usbip: vhci_hcd: check rhport before using in vhci_hub_control()
        - Revert "xhci: plat: Register shutdown for xhci_plat"
        - USB: serial: simple: add libtransistor console
        - USB: serial: ftdi_sio: use jtag quirk for Arrow USB Blaster
        - USB: serial: cp210x: add ID for NI USB serial console
        - usb: core: Add quirk for HP v222w 16GB Mini
        - USB: Increment wakeup count on remote wakeup.
        - ALSA: usb-audio: Skip broken EU on Dell dock USB-audio
        - virtio: add ability to iterate over vqs
        - virtio_console: don't tie bufs to a vq
        - virtio_console: free buffers after reset
        - virtio_console: drop custom control queue cleanup
        - virtio_console: move removal code
        - virtio_console: reset on out of memory
        - drm/virtio: fix vq wait_event condition
        - tty: Don't call panic() at tty_ldisc_init()
        - tty: n_gsm: Fix long delays with control frame timeouts in ADM mode
        - tty: n_gsm: Fix DLCI handling for ADM mode if debug & 2 is not set
        - tty: Avoid possible error pointer dereference at tty_ldisc_restore().
        - tty: Use __GFP_NOFAIL for tty_ldisc_get()
        - ALSA: dice: fix OUI for TC group
        - ALSA: dice: fix error path to destroy initialized stream data
        - ALSA: hda - Skip jack and others for non-existing PCM streams
        - ALSA: opl3: Hardening for potential Spectre v1
        - ALSA: asihpi: Hardening for potential Spectre v1
        - ALSA: hdspm: Hardening for potential Spectre v1
        - ALSA: rme9652: Hardening for potential Spectre v1
        - ALSA: control: Hardening for potential Spectre v1
        - ALSA: pcm: Return negative delays from SNDRV_PCM_IOCTL_DELAY.
        - ALSA: core: Report audio_tstamp in snd_pcm_sync_ptr
        - ALSA: seq: oss: Fix unbalanced use lock for synth MIDI device
        - ALSA: seq: oss: Hardening for potential Spectre v1
        - ALSA: hda: Hardening for potential Spectre v1
        - ALSA: hda/realtek - Add some fixes for ALC233
        - ALSA: hda/realtek - Update ALC255 depop optimize
        - ALSA: hda/realtek - change the location for one of two front mics
        - mtd: spi-nor: cadence-quadspi: Fix page fault kernel panic
        - mtd: cfi: cmdset_0001: Do not allow read/write to suspend erase block.
        - mtd: cfi: cmdset_0001: Workaround Micron Erase suspend bug.
        - mtd: cfi: cmdset_0002: Do not allow read/write to suspend erase block.
        - mtd: rawnand: tango: Fix struct clk memory leak
        - kobject: don't use WARN for registration failures
        - scsi: sd: Defer spinning up drive while SANITIZE is in progress
        - bfq-iosched: ensure to clear bic/bfqq pointers when preparing request
        - vfio: ccw: process ssch with interrupts disabled
        - ANDROID: binder: prevent transactions into own process.
        - PCI: aardvark: Fix logic in advk_pcie_{rd,wr}_conf()
        - PCI: aardvark: Set PIO_ADDR_LS correctly in advk_pcie_rd_conf()
        - PCI: aardvark: Use ISR1 instead of ISR0 interrupt in legacy irq mode
        - PCI: aardvark: Fix PCIe Max Read Request Size setting
        - ARM: amba: Make driver_override output consistent with other buses
        - ARM: amba: Fix race condition with driver_override
        - ARM: amba: Don't read past the end of sysfs "driver_override" buffer
        - ARM: socfpga_defconfig: Remove QSPI Sector 4K size force
        - KVM: arm/arm64: Close VMID generation race
        - crypto: drbg - set freed buffers to NULL
        - ASoC: fsl_esai: Fix divisor calculation failure at lower ratio
        - libceph: un-backoff on tick when we have a authenticated session
        - libceph: reschedule a tick in finish_hunting()
        - libceph: validate con->state at the top of try_write()
        - fpga-manager: altera-ps-spi: preserve nCONFIG state
        - earlycon: Use a pointer table to fix __earlycon_table stride
        - drm/amdgpu: set COMPUTE_PGM_RSRC1 for SGPR/VGPR clearing shaders
        - drm/i915: Enable display WA#1183 from its correct spot
        - objtool, perf: Fix GCC 8 -Wrestrict error
        - tools/lib/subcmd/pager.c: do not alias select() params
        - x86/ipc: Fix x32 version of shmid64_ds and msqid64_ds
        - x86/smpboot: Don't use mwait_play_dead() on AMD systems
        - x86/microcode/intel: Save microcode patch unconditionally
        - x86/microcode: Do not exit early from __reload_late()
        - tick/sched: Do not mess with an enqueued hrtimer
        - arm/arm64: KVM: Add PSCI version selection API
        - powerpc/eeh: Fix race with driver un/bind
        - serial: mvebu-uart: Fix local flags handling on termios update
        - block: do not use interruptible wait anywhere
        - ASoC: dmic: Fix clock parenting
        - PCI / PM: Do not clear state_saved in pci_pm_freeze() when smart suspend is
          set
        - module: Fix display of wrong module .text address
        - drm/edid: Reset more of the display info
        - drm/i915/fbdev: Enable late fbdev initial configuration
        - drm/i915/audio: set minimum CD clock to twice the BCLK
        - drm/amd/display: Fix deadlock when flushing irq
        - drm/amd/display: Disallow enabling CRTC without primary plane with FB
      * Bionic update: upstream stable patchset 2018-06-22 (LP: #1778265) //
        CVE-2018-1108.
        - random: set up the NUMA crng instances after the CRNG is fully initialized
      * Ryzen/Raven Ridge USB ports do not work (LP: #1756700)
        - xhci: Fix USB ports for Dell Inspiron 5775
      * [Ubuntu 1804][boston][ixgbe] EEH causes kernel BUG at /build/linux-
        jWa1Fv/linux-4.15.0/drivers/pci/msi.c:352 (i2S) (LP: #1776389)
        - ixgbe/ixgbevf: Free IRQ when PCI error recovery removes the device
      * Need fix to aacraid driver to prevent panic (LP: #1770095)
        - scsi: aacraid: Correct hba_send to include iu_type
      * kernel: Fix arch random implementation (LP: #1775391)
        - s390/archrandom: Rework arch random implementation.
      * kernel: Fix memory leak on CCA and EP11 CPRB processing. (LP: #1775390)
        - s390/zcrypt: Fix CCA and EP11 CPRB processing failure memory leak.
      * Various fixes for CXL kernel module (LP: #1774471)
        - cxl: Remove function write_timebase_ctrl_psl9() for PSL9
        - cxl: Set the PBCQ Tunnel BAR register when enabling capi mode
        - cxl: Report the tunneled operations status
        - cxl: Configure PSL to not use APC virtual machines
        - cxl: Disable prefault_mode in Radix mode
      * Bluetooth not working (LP: #1764645)
        - Bluetooth: btusb: Apply QCA Rome patches for some ATH3012 models
      * linux-snapdragon: wcn36xx: mac address generation on boot (LP: #1776491)
        - [Config] arm64: snapdragon: WCN36XX_SNAPDRAGON_HACKS=y
        - SAUCE: wcn36xx: read MAC from file or randomly generate one
      * fscache: Fix hanging wait on page discarded by writeback (LP: #1777029)
        - fscache: Fix hanging wait on page discarded by writeback
    
      [ Ubuntu: 4.15.0-32.35 ]
    
      * CVE-2018-3620 // CVE-2018-3646
        - cpu: Fix per-cpu regression on ARM64
    
     -- Kleber Sacilotto de Souza <email address hidden>  Thu, 16 Aug 2018 14:43:00 +0200
  • linux-gcp (4.15.0-1017.18) bionic; urgency=medium
    
      [ Ubuntu: 4.15.0-32.34 ]
    
      * CVE-2018-5391
        - Revert "net: increase fragment memory usage limits"
      * CVE-2018-3620 // CVE-2018-3646
        - x86/Centaur: Initialize supported CPU features properly
        - x86/Centaur: Report correct CPU/cache topology
        - x86/CPU/AMD: Have smp_num_siblings and cpu_llc_id always be present
        - perf/events/amd/uncore: Fix amd_uncore_llc ID to use pre-defined cpu_llc_id
        - x86/CPU: Rename intel_cacheinfo.c to cacheinfo.c
        - x86/CPU/AMD: Calculate last level cache ID from number of sharing threads
        - x86/CPU: Modify detect_extended_topology() to return result
        - x86/CPU/AMD: Derive CPU topology from CPUID function 0xB when available
        - x86/CPU: Move cpu local function declarations to local header
        - x86/CPU: Make intel_num_cpu_cores() generic
        - x86/CPU: Move cpu_detect_cache_sizes() into init_intel_cacheinfo()
        - x86/CPU: Move x86_cpuinfo::x86_max_cores assignment to
          detect_num_cpu_cores()
        - x86/CPU/AMD: Fix LLC ID bit-shift calculation
        - x86/mm: Factor out pageattr _PAGE_GLOBAL setting
        - x86/mm: Undo double _PAGE_PSE clearing
        - x86/mm: Introduce "default" kernel PTE mask
        - x86/espfix: Document use of _PAGE_GLOBAL
        - x86/mm: Do not auto-massage page protections
        - x86/mm: Remove extra filtering in pageattr code
        - x86/mm: Comment _PAGE_GLOBAL mystery
        - x86/mm: Do not forbid _PAGE_RW before init for __ro_after_init
        - x86/ldt: Fix support_pte_mask filtering in map_ldt_struct()
        - x86/power/64: Fix page-table setup for temporary text mapping
        - x86/pti: Filter at vma->vm_page_prot population
        - x86/boot/64/clang: Use fixup_pointer() to access '__supported_pte_mask'
        - x86/speculation/l1tf: Increase 32bit PAE __PHYSICAL_PAGE_SHIFT
        - x86/speculation/l1tf: Change order of offset/type in swap entry
        - x86/speculation/l1tf: Protect swap entries against L1TF
        - x86/speculation/l1tf: Protect PROT_NONE PTEs against speculation
        - x86/speculation/l1tf: Make sure the first page is always reserved
        - x86/speculation/l1tf: Add sysfs reporting for l1tf
        - x86/speculation/l1tf: Disallow non privileged high MMIO PROT_NONE mappings
        - x86/speculation/l1tf: Limit swap file size to MAX_PA/2
        - x86/bugs: Move the l1tf function and define pr_fmt properly
        - sched/smt: Update sched_smt_present at runtime
        - x86/smp: Provide topology_is_primary_thread()
        - x86/topology: Provide topology_smt_supported()
        - cpu/hotplug: Make bringup/teardown of smp threads symmetric
        - cpu/hotplug: Split do_cpu_down()
        - cpu/hotplug: Provide knobs to control SMT
        - x86/cpu: Remove the pointless CPU printout
        - x86/cpu/AMD: Remove the pointless detect_ht() call
        - x86/cpu/common: Provide detect_ht_early()
        - x86/cpu/topology: Provide detect_extended_topology_early()
        - x86/cpu/intel: Evaluate smp_num_siblings early
        - x86/CPU/AMD: Do not check CPUID max ext level before parsing SMP info
        - x86/cpu/AMD: Evaluate smp_num_siblings early
        - x86/apic: Ignore secondary threads if nosmt=force
        - x86/speculation/l1tf: Extend 64bit swap file size limit
        - x86/cpufeatures: Add detection of L1D cache flush support.
        - x86/CPU/AMD: Move TOPOEXT reenablement before reading smp_num_siblings
        - x86/speculation/l1tf: Protect PAE swap entries against L1TF
        - x86/speculation/l1tf: Fix up pte->pfn conversion for PAE
        - Revert "x86/apic: Ignore secondary threads if nosmt=force"
        - cpu/hotplug: Boot HT siblings at least once
        - x86/KVM: Warn user if KVM is loaded SMT and L1TF CPU bug being present
        - x86/KVM/VMX: Add module argument for L1TF mitigation
        - x86/KVM/VMX: Add L1D flush algorithm
        - x86/KVM/VMX: Add L1D MSR based flush
        - x86/KVM/VMX: Add L1D flush logic
        - x86/KVM/VMX: Split the VMX MSR LOAD structures to have an host/guest numbers
        - x86/KVM/VMX: Add find_msr() helper function
        - x86/KVM/VMX: Separate the VMX AUTOLOAD guest/host number accounting
        - x86/KVM/VMX: Extend add_atomic_switch_msr() to allow VMENTER only MSRs
        - x86/KVM/VMX: Use MSR save list for IA32_FLUSH_CMD if required
        - cpu/hotplug: Online siblings when SMT control is turned on
        - x86/litf: Introduce vmx status variable
        - x86/kvm: Drop L1TF MSR list approach
        - x86/l1tf: Handle EPT disabled state proper
        - x86/kvm: Move l1tf setup function
        - x86/kvm: Add static key for flush always
        - x86/kvm: Serialize L1D flush parameter setter
        - x86/kvm: Allow runtime control of L1D flush
        - cpu/hotplug: Expose SMT control init function
        - cpu/hotplug: Set CPU_SMT_NOT_SUPPORTED early
        - x86/bugs, kvm: Introduce boot-time control of L1TF mitigations
        - Documentation: Add section about CPU vulnerabilities
        - x86/speculation/l1tf: Unbreak !__HAVE_ARCH_PFN_MODIFY_ALLOWED architectures
        - x86/KVM/VMX: Initialize the vmx_l1d_flush_pages' content
        - Documentation/l1tf: Fix typos
        - cpu/hotplug: detect SMT disabled by BIOS
        - x86/KVM/VMX: Don't set l1tf_flush_l1d to true from vmx_l1d_flush()
        - x86/KVM/VMX: Replace 'vmx_l1d_flush_always' with 'vmx_l1d_flush_cond'
        - x86/KVM/VMX: Move the l1tf_flush_l1d test to vmx_l1d_flush()
        - x86/irq: Demote irq_cpustat_t::__softirq_pending to u16
        - x86/KVM/VMX: Introduce per-host-cpu analogue of l1tf_flush_l1d
        - x86: Don't include linux/irq.h from asm/hardirq.h
        - x86/irq: Let interrupt handlers set kvm_cpu_l1tf_flush_l1d
        - x86/KVM/VMX: Don't set l1tf_flush_l1d from vmx_handle_external_intr()
        - Documentation/l1tf: Remove Yonah processors from not vulnerable list
        - x86/speculation: Simplify sysfs report of VMX L1TF vulnerability
        - x86/speculation: Use ARCH_CAPABILITIES to skip L1D flush on vmentry
        - KVM: x86: Add a framework for supporting MSR-based features
        - KVM: X86: Introduce kvm_get_msr_feature()
        - KVM: VMX: support MSR_IA32_ARCH_CAPABILITIES as a feature MSR
        - KVM: VMX: Tell the nested hypervisor to skip L1D flush on vmentry
        - cpu/hotplug: Fix SMT supported evaluation
        - x86/speculation/l1tf: Invert all not present mappings
        - x86/speculation/l1tf: Make pmd/pud_mknotpresent() invert
        - x86/mm/pat: Make set_memory_np() L1TF safe
    
     -- Stefan Bader <email address hidden>  Fri, 10 Aug 2018 11:58:32 +0200
  • linux-gcp (4.15.0-1015.15) bionic; urgency=medium
    
      [ Ubuntu: 4.15.0-30.32 ]
    
      * CVE-2018-5390
        - tcp: free batches of packets in tcp_prune_ofo_queue()
        - tcp: avoid collapses in tcp_prune_queue() if possible
        - tcp: detect malicious patterns in tcp_collapse_ofo_queue()
        - tcp: call tcp_drop() from tcp_data_queue_ofo()
        - tcp: add tcp_ooo_try_coalesce() helper
    
     -- Stefan Bader <email address hidden>  Thu, 26 Jul 2018 20:49:07 +0200
  • linux-gcp (4.15.0-1014.14) bionic; urgency=medium
    
      * linux-gcp: 4.15.0-1014.14 -proposed tracker (LP: #1782174)
    
    
      [ Ubuntu: 4.15.0-29.31 ]
    
      * linux: 4.15.0-29.31 -proposed tracker (LP: #1782173)
      * [SRU Bionic][Cosmic] kernel panic in ipmi_ssif at msg_done_handler
        (LP: #1777716)
        - ipmi_ssif: Fix kernel panic at msg_done_handler
      * Update to ocxl driver for 18.04.1 (LP: #1775786)
        - misc: ocxl: use put_device() instead of device_unregister()
        - powerpc: Add TIDR CPU feature for POWER9
        - powerpc: Use TIDR CPU feature to control TIDR allocation
        - powerpc: use task_pid_nr() for TID allocation
        - ocxl: Rename pnv_ocxl_spa_remove_pe to clarify it's action
        - ocxl: Expose the thread_id needed for wait on POWER9
        - ocxl: Add an IOCTL so userspace knows what OCXL features are available
        - ocxl: Document new OCXL IOCTLs
        - ocxl: Fix missing unlock on error in afu_ioctl_enable_p9_wait()
      * Critical upstream bugfix missing in Ubuntu 18.04 - frequent Xorg crash after
        suspend (LP: #1776887)
        - ocxl: Document the OCXL_IOCTL_GET_METADATA IOCTL
      * Hard LOCKUP observed on stressing Ubuntu 18 04 (LP: #1777194)
        - powerpc: use NMI IPI for smp_send_stop
        - powerpc: Fix smp_send_stop NMI IPI handling
      * IPL: ppc64_cpu --frequency hang with INFO: rcu_sched detected stalls on
        CPUs/tasks on w34 and wsbmc016 with 920.1714.20170330n (LP: #1773964)
        - rtc: opal: Fix OPAL RTC driver OPAL_BUSY loops
      * [Regression] EXT4-fs error (device sda2): ext4_validate_block_bitmap:383:
        comm stress-ng: bg 4705: bad block bitmap checksum (LP: #1781709)
        - SAUCE: Revert "UBUNTU: SAUCE: ext4: fix ext4_validate_inode_bitmap: comm
          stress-ng: Corrupt inode bitmap"
        - SAUCE: ext4: check for allocation block validity with block group locked
    
      [ Ubuntu: 4.15.0-28.30 ]
    
      * linux: 4.15.0-28.30 -proposed tracker (LP: #1781433)
      * Cannot set MTU higher than 1500 in Xen instance (LP: #1781413)
        - xen-netfront: Fix mismatched rtnl_unlock
        - xen-netfront: Update features after registering netdev
    
    linux-gcp (4.15.0-1013.13) bionic; urgency=medium
    
      * linux-gcp: 4.15.0-1013.13 -proposed tracker (LP: #1781067)
    
      [ Ubuntu: 4.15.0-27.29 ]
    
      * linux: 4.15.0-27.29 -proposed tracker (LP: #1781062)
      * [Regression] EXT4-fs error (device sda1): ext4_validate_inode_bitmap:99:
        comm stress-ng: Corrupt inode bitmap (LP: #1780137)
        - SAUCE: ext4: fix ext4_validate_inode_bitmap: comm stress-ng: Corrupt inode
          bitmap
    
    linux-gcp (4.15.0-1012.12) bionic; urgency=medium
    
      * linux-gcp: 4.15.0-1012.12 -proposed tracker (LP: #1780118)
    
    
      [ Ubuntu: 4.15.0-26.28 ]
    
      * linux: 4.15.0-26.28 -proposed tracker (LP: #1780112)
      * failure to boot with linux-image-4.15.0-24-generic (LP: #1779827) // Cloud-
        init causes potentially huge boot delays with 4.15 kernels (LP: #1780062)
        - random: Make getrandom() ready earlier
    
    linux-gcp (4.15.0-1011.11) bionic; urgency=medium
    
      * linux-gcp: 4.15.0-1011.11 -proposed tracker (LP: #1779361)
    
      [ Ubuntu: 4.15.0-25.27 ]
    
      * linux: 4.15.0-25.27 -proposed tracker (LP: #1779354)
      * hisi_sas_v3_hw: internal task abort: timeout and not done. (LP: #1777736)
        - scsi: hisi_sas: Update a couple of register settings for v3 hw
      * hisi_sas: Add missing PHY spinlock init (LP: #1777734)
        - scsi: hisi_sas: Add missing PHY spinlock init
      * hisi_sas: improve read performance by pre-allocating slot DMA buffers
        (LP: #1777727)
        - scsi: hisi_sas: use dma_zalloc_coherent()
        - scsi: hisi_sas: Use dmam_alloc_coherent()
        - scsi: hisi_sas: Pre-allocate slot DMA buffers
      * hisi_sas: Failures during host reset (LP: #1777696)
        - scsi: hisi_sas: Only process broadcast change in phy_bcast_v3_hw()
        - scsi: hisi_sas: Fix the conflict between dev gone and host reset
        - scsi: hisi_sas: Adjust task reject period during host reset
        - scsi: hisi_sas: Add a flag to filter PHY events during reset
        - scsi: hisi_sas: Release all remaining resources in clear nexus ha
      * Fake SAS addresses for SATA disks on HiSilicon D05 are non-unique
        (LP: #1776750)
        - scsi: hisi_sas: make SAS address of SATA disks unique
      * Vcs-Git header on bionic linux source package points to zesty git tree
        (LP: #1766055)
        - [Packaging]: Update Vcs-Git
      * large KVM instances run out of IRQ routes (LP: #1778261)
        - SAUCE: kvm -- increase KVM_MAX_IRQ_ROUTES to 2048 on x86
    
     -- Khalid Elmously <email address hidden>  Wed, 18 Jul 2018 02:48:20 +0000
  • linux-gcp (4.15.0-1013.13) bionic; urgency=medium
    
      * linux-gcp: 4.15.0-1013.13 -proposed tracker (LP: #1781067)
    
      [ Ubuntu: 4.15.0-27.29 ]
    
      * linux: 4.15.0-27.29 -proposed tracker (LP: #1781062)
      * [Regression] EXT4-fs error (device sda1): ext4_validate_inode_bitmap:99:
        comm stress-ng: Corrupt inode bitmap (LP: #1780137)
        - SAUCE: ext4: fix ext4_validate_inode_bitmap: comm stress-ng: Corrupt inode
          bitmap
    
    linux-gcp (4.15.0-1012.12) bionic; urgency=medium
    
      * linux-gcp: 4.15.0-1012.12 -proposed tracker (LP: #1780118)
    
    
      [ Ubuntu: 4.15.0-26.28 ]
    
      * linux: 4.15.0-26.28 -proposed tracker (LP: #1780112)
      * failure to boot with linux-image-4.15.0-24-generic (LP: #1779827) // Cloud-
        init causes potentially huge boot delays with 4.15 kernels (LP: #1780062)
        - random: Make getrandom() ready earlier
    
    linux-gcp (4.15.0-1011.11) bionic; urgency=medium
    
      * linux-gcp: 4.15.0-1011.11 -proposed tracker (LP: #1779361)
    
      [ Ubuntu: 4.15.0-25.27 ]
    
      * linux: 4.15.0-25.27 -proposed tracker (LP: #1779354)
      * hisi_sas_v3_hw: internal task abort: timeout and not done. (LP: #1777736)
        - scsi: hisi_sas: Update a couple of register settings for v3 hw
      * hisi_sas: Add missing PHY spinlock init (LP: #1777734)
        - scsi: hisi_sas: Add missing PHY spinlock init
      * hisi_sas: improve read performance by pre-allocating slot DMA buffers
        (LP: #1777727)
        - scsi: hisi_sas: use dma_zalloc_coherent()
        - scsi: hisi_sas: Use dmam_alloc_coherent()
        - scsi: hisi_sas: Pre-allocate slot DMA buffers
      * hisi_sas: Failures during host reset (LP: #1777696)
        - scsi: hisi_sas: Only process broadcast change in phy_bcast_v3_hw()
        - scsi: hisi_sas: Fix the conflict between dev gone and host reset
        - scsi: hisi_sas: Adjust task reject period during host reset
        - scsi: hisi_sas: Add a flag to filter PHY events during reset
        - scsi: hisi_sas: Release all remaining resources in clear nexus ha
      * Fake SAS addresses for SATA disks on HiSilicon D05 are non-unique
        (LP: #1776750)
        - scsi: hisi_sas: make SAS address of SATA disks unique
      * Vcs-Git header on bionic linux source package points to zesty git tree
        (LP: #1766055)
        - [Packaging]: Update Vcs-Git
      * large KVM instances run out of IRQ routes (LP: #1778261)
        - SAUCE: kvm -- increase KVM_MAX_IRQ_ROUTES to 2048 on x86
    
     -- Khalid Elmously <email address hidden>  Tue, 10 Jul 2018 22:06:24 -0400
  • linux-gcp (4.15.0-1012.12) bionic; urgency=medium
    
      * linux-gcp: 4.15.0-1012.12 -proposed tracker (LP: #1780118)
    
    
      [ Ubuntu: 4.15.0-26.28 ]
    
      * linux: 4.15.0-26.28 -proposed tracker (LP: #1780112)
      * failure to boot with linux-image-4.15.0-24-generic (LP: #1779827) // Cloud-
        init causes potentially huge boot delays with 4.15 kernels (LP: #1780062)
        - random: Make getrandom() ready earlier
    
    linux-gcp (4.15.0-1011.11) bionic; urgency=medium
    
      * linux-gcp: 4.15.0-1011.11 -proposed tracker (LP: #1779361)
    
      [ Ubuntu: 4.15.0-25.27 ]
    
      * linux: 4.15.0-25.27 -proposed tracker (LP: #1779354)
      * hisi_sas_v3_hw: internal task abort: timeout and not done. (LP: #1777736)
        - scsi: hisi_sas: Update a couple of register settings for v3 hw
      * hisi_sas: Add missing PHY spinlock init (LP: #1777734)
        - scsi: hisi_sas: Add missing PHY spinlock init
      * hisi_sas: improve read performance by pre-allocating slot DMA buffers
        (LP: #1777727)
        - scsi: hisi_sas: use dma_zalloc_coherent()
        - scsi: hisi_sas: Use dmam_alloc_coherent()
        - scsi: hisi_sas: Pre-allocate slot DMA buffers
      * hisi_sas: Failures during host reset (LP: #1777696)
        - scsi: hisi_sas: Only process broadcast change in phy_bcast_v3_hw()
        - scsi: hisi_sas: Fix the conflict between dev gone and host reset
        - scsi: hisi_sas: Adjust task reject period during host reset
        - scsi: hisi_sas: Add a flag to filter PHY events during reset
        - scsi: hisi_sas: Release all remaining resources in clear nexus ha
      * Fake SAS addresses for SATA disks on HiSilicon D05 are non-unique
        (LP: #1776750)
        - scsi: hisi_sas: make SAS address of SATA disks unique
      * Vcs-Git header on bionic linux source package points to zesty git tree
        (LP: #1766055)
        - [Packaging]: Update Vcs-Git
      * large KVM instances run out of IRQ routes (LP: #1778261)
        - SAUCE: kvm -- increase KVM_MAX_IRQ_ROUTES to 2048 on x86
    
     -- Marcelo Henrique Cerri <email address hidden>  Wed, 04 Jul 2018 16:36:10 -0300
  • linux-gcp (4.15.0-1011.11) bionic; urgency=medium
    
      * linux-gcp: 4.15.0-1011.11 -proposed tracker (LP: #1779361)
    
      [ Ubuntu: 4.15.0-25.27 ]
    
      * linux: 4.15.0-25.27 -proposed tracker (LP: #1779354)
      * hisi_sas_v3_hw: internal task abort: timeout and not done. (LP: #1777736)
        - scsi: hisi_sas: Update a couple of register settings for v3 hw
      * hisi_sas: Add missing PHY spinlock init (LP: #1777734)
        - scsi: hisi_sas: Add missing PHY spinlock init
      * hisi_sas: improve read performance by pre-allocating slot DMA buffers
        (LP: #1777727)
        - scsi: hisi_sas: use dma_zalloc_coherent()
        - scsi: hisi_sas: Use dmam_alloc_coherent()
        - scsi: hisi_sas: Pre-allocate slot DMA buffers
      * hisi_sas: Failures during host reset (LP: #1777696)
        - scsi: hisi_sas: Only process broadcast change in phy_bcast_v3_hw()
        - scsi: hisi_sas: Fix the conflict between dev gone and host reset
        - scsi: hisi_sas: Adjust task reject period during host reset
        - scsi: hisi_sas: Add a flag to filter PHY events during reset
        - scsi: hisi_sas: Release all remaining resources in clear nexus ha
      * Fake SAS addresses for SATA disks on HiSilicon D05 are non-unique
        (LP: #1776750)
        - scsi: hisi_sas: make SAS address of SATA disks unique
      * Vcs-Git header on bionic linux source package points to zesty git tree
        (LP: #1766055)
        - [Packaging]: Update Vcs-Git
      * large KVM instances run out of IRQ routes (LP: #1778261)
        - SAUCE: kvm -- increase KVM_MAX_IRQ_ROUTES to 2048 on x86
    
     -- Khalid Elmously <email address hidden>  Sun, 01 Jul 2018 22:09:51 -0400
  • linux-gcp (4.15.0-1010.10) bionic; urgency=medium
    
      * linux-gcp: 4.15.0-1010.10 -proposed tracker (LP: #1776344)
    
      [ Ubuntu: 4.15.0-24.26 ]
    
      * linux: 4.15.0-24.26 -proposed tracker (LP: #1776338)
      * Bionic update: upstream stable patchset 2018-06-06 (LP: #1775483)
        - drm: bridge: dw-hdmi: Fix overflow workaround for Amlogic Meson GX SoCs
        - i40e: Fix attach VF to VM issue
        - tpm: cmd_ready command can be issued only after granting locality
        - tpm: tpm-interface: fix tpm_transmit/_cmd kdoc
        - tpm: add retry logic
        - Revert "ath10k: send (re)assoc peer command when NSS changed"
        - bonding: do not set slave_dev npinfo before slave_enable_netpoll in
          bond_enslave
        - ipv6: add RTA_TABLE and RTA_PREFSRC to rtm_ipv6_policy
        - ipv6: sr: fix NULL pointer dereference in seg6_do_srh_encap()- v4 pkts
        - KEYS: DNS: limit the length of option strings
        - l2tp: check sockaddr length in pppol2tp_connect()
        - net: validate attribute sizes in neigh_dump_table()
        - llc: delete timers synchronously in llc_sk_free()
        - tcp: don't read out-of-bounds opsize
        - net: af_packet: fix race in PACKET_{R|T}X_RING
        - tcp: md5: reject TCP_MD5SIG or TCP_MD5SIG_EXT on established sockets
        - net: fix deadlock while clearing neighbor proxy table
        - team: avoid adding twice the same option to the event list
        - net/smc: fix shutdown in state SMC_LISTEN
        - team: fix netconsole setup over team
        - packet: fix bitfield update race
        - tipc: add policy for TIPC_NLA_NET_ADDR
        - pppoe: check sockaddr length in pppoe_connect()
        - vlan: Fix reading memory beyond skb->tail in skb_vlan_tagged_multi
        - amd-xgbe: Add pre/post auto-negotiation phy hooks
        - sctp: do not check port in sctp_inet6_cmp_addr
        - amd-xgbe: Improve KR auto-negotiation and training
        - strparser: Do not call mod_delayed_work with a timeout of LONG_MAX
        - amd-xgbe: Only use the SFP supported transceiver signals
        - strparser: Fix incorrect strp->need_bytes value.
        - net: sched: ife: signal not finding metaid
        - tcp: clear tp->packets_out when purging write queue
        - net: sched: ife: handle malformed tlv length
        - net: sched: ife: check on metadata length
        - llc: hold llc_sap before release_sock()
        - llc: fix NULL pointer deref for SOCK_ZAPPED
        - net: ethernet: ti: cpsw: fix tx vlan priority mapping
        - virtio_net: split out ctrl buffer
        - virtio_net: fix adding vids on big-endian
        - KVM: s390: force bp isolation for VSIE
        - s390: correct module section names for expoline code revert
        - microblaze: Setup dependencies for ASM optimized lib functions
        - commoncap: Handle memory allocation failure.
        - scsi: mptsas: Disable WRITE SAME
        - cdrom: information leak in cdrom_ioctl_media_changed()
        - m68k/mac: Don't remap SWIM MMIO region
        - block/swim: Check drive type
        - block/swim: Don't log an error message for an invalid ioctl
        - block/swim: Remove extra put_disk() call from error path
        - block/swim: Rename macros to avoid inconsistent inverted logic
        - block/swim: Select appropriate drive on device open
        - block/swim: Fix array bounds check
        - block/swim: Fix IO error at end of medium
        - tracing: Fix missing tab for hwlat_detector print format
        - s390/cio: update chpid descriptor after resource accessibility event
        - s390/dasd: fix IO error for newly defined devices
        - s390/uprobes: implement arch_uretprobe_is_alive()
        - ACPI / video: Only default only_lcd to true on Win8-ready _desktops_
        - docs: ip-sysctl.txt: fix name of some ipv6 variables
        - net: mvpp2: Fix DMA address mask size
        - net: stmmac: Disable ACS Feature for GMAC >= 4
        - l2tp: hold reference on tunnels in netlink dumps
        - l2tp: hold reference on tunnels printed in pppol2tp proc file
        - l2tp: hold reference on tunnels printed in l2tp/tunnels debugfs file
        - l2tp: fix {pppol2tp, l2tp_dfs}_seq_stop() in case of seq_file overflow
        - s390/qeth: fix error handling in adapter command callbacks
        - s390/qeth: avoid control IO completion stalls
        - s390/qeth: handle failure on workqueue creation
        - bnxt_en: Fix memory fault in bnxt_ethtool_init()
        - virtio-net: add missing virtqueue kick when flushing packets
        - VSOCK: make af_vsock.ko removable again
        - hwmon: (k10temp) Add temperature offset for Ryzen 2700X
        - hwmon: (k10temp) Add support for AMD Ryzen w/ Vega graphics
        - s390/cpum_cf: rename IBM z13/z14 counter names
        - kprobes: Fix random address output of blacklist file
        - Revert "pinctrl: intel: Initialize GPIO properly when used through irqchip"
      * Lenovo V330 needs patch in ideapad_laptop module for rfkill (LP: #1774636)
        - SAUCE: Add Lenovo V330 to the ideapad_laptop rfkill blacklist
      * bluetooth controller fail after suspend with USB autosuspend on XPS 13 9360
        (LP: #1775217)
        - Bluetooth: btusb: Add Dell XPS 13 9360 to btusb_needs_reset_resume_table
      * [Hyper-V] PCI: hv: Fix 2 hang issues in hv_compose_msi_msg (LP: #1758378)
        - PCI: hv: Only queue new work items in hv_pci_devices_present() if necessary
        - PCI: hv: Remove the bogus test in hv_eject_device_work()
        - PCI: hv: Fix a comment typo in _hv_pcifront_read_config()
      * register on binfmt_misc may overflow and crash the system (LP: #1775856)
        - fs/binfmt_misc.c: do not allow offset overflow
      * CVE-2018-11508
        - compat: fix 4-byte infoleak via uninitialized struct field
      * Network installs fail on SocioNext board (LP: #1775884)
        - net: netsec: reduce DMA mask to 40 bits
        - net: socionext: reset hardware in ndo_stop
        - net: netsec: enable tx-irq during open callback
      * r8169 ethernet card don't work after returning from suspension
        (LP: #1752772)
        - PCI: Add pcim_set_mwi(), a device-managed pci_set_mwi()
        - r8169: switch to device-managed functions in probe
        - r8169: remove netif_napi_del in probe error path
        - r8169: remove some WOL-related dead code
        - r8169: disable WOL per default
        - r8169: improve interrupt handling
        - r8169: fix interrupt number after adding support for MSI-X interrupts
      * ISST-LTE:KVM:Ubuntu18.04:BostonLC:boslcp3:boslcp3g3:Guest conosle hangs
        after hotplug CPU add operation. (LP: #1759723)
        - genirq/affinity: assign vectors to all possible CPUs
        - genirq/affinity: Don't return with empty affinity masks on error
        - genirq/affinity: Rename *node_to_possible_cpumask as *node_to_cpumask
        - genirq/affinity: Move actual irq vector spreading into a helper function
        - genirq/affinity: Allow irq spreading from a given starting point
        - genirq/affinity: Spread irq vectors among present CPUs as far as possible
        - blk-mq: simplify queue mapping & schedule with each possisble CPU
        - blk-mq: make sure hctx->next_cpu is set correctly
        - blk-mq: Avoid that blk_mq_delay_run_hw_queue() introduces unintended delays
        - blk-mq: make sure that correct hctx->next_cpu is set
        - blk-mq: avoid to write intermediate result to hctx->next_cpu
        - blk-mq: introduce blk_mq_hw_queue_first_cpu() to figure out first cpu
        - blk-mq: don't check queue mapped in __blk_mq_delay_run_hw_queue()
        - nvme: pci: pass max vectors as num_possible_cpus() to pci_alloc_irq_vectors
        - scsi: hpsa: fix selection of reply queue
        - scsi: megaraid_sas: fix selection of reply queue
        - scsi: core: introduce force_blk_mq
        - scsi: virtio_scsi: fix IO hang caused by automatic irq vector affinity
        - scsi: virtio_scsi: unify scsi_host_template
      * Fix several bugs in RDMA/hns driver (LP: #1770974)
        - RDMA/hns: Use structs to describe the uABI instead of opencoding
        - RDMA/hns: Remove unnecessary platform_get_resource() error check
        - RDMA/hns: Remove unnecessary operator
        - RDMA/hns: Add names to function arguments in function pointers
        - RDMA/hns: Fix misplaced call to hns_roce_cleanup_hem_table
        - RDMA/hns: Fix a bug with modifying mac address
        - RDMA/hns: Use free_pages function instead of free_page
        - RDMA/hns: Replace __raw_write*(cpu_to_le*()) with LE write*()
        - RDMA/hns: Bugfix for init hem table
        - RDMA/hns: Intercept illegal RDMA operation when use inline data
        - RDMA/hns: Fix the qp context state diagram
        - RDMA/hns: Only assign mtu if IB_QP_PATH_MTU bit is set
        - RDMA/hns: Remove some unnecessary attr_mask judgement
        - RDMA/hns: Only assign dqpn if IB_QP_PATH_DEST_QPN bit is set
        - RDMA/hns: Adjust the order of cleanup hem table
        - RDMA/hns: Update assignment method for owner field of send wqe
        - RDMA/hns: Submit bad wr
        - RDMA/hns: Fix a couple misspellings
        - RDMA/hns: Add rq inline flags judgement
        - RDMA/hns: Bugfix for rq record db for kernel
        - RDMA/hns: Load the RoCE dirver automatically
        - RDMA/hns: Update convert function of endian format
        - RDMA/hns: Add return operation when configured global param fail
        - RDMA/hns: Not support qp transition from reset to reset for hip06
        - RDMA/hns: Fix the bug with rq sge
        - RDMA/hns: Set desc_dma_addr for zero when free cmq desc
        - RDMA/hns: Enable inner_pa_vld filed of mpt
        - RDMA/hns: Set NULL for __internal_mr
        - RDMA/hns: Fix the bug with NULL pointer
        - RDMA/hns: Bugfix for cq record db for kernel
        - RDMA/hns: Move the location for initializing tmp_len
        - RDMA/hns: Drop local zgid in favor of core defined variable
        - RDMA/hns: Add 64KB page size support for hip08
        - RDMA/hns: Rename the idx field of db
        - RDMA/hns: Modify uar allocation algorithm to avoid bitmap exhaust
        - RDMA/hns: Increase checking CMQ status timeout value
        - RDMA/hns: Add reset process for RoCE in hip08
        - RDMA/hns: Fix the illegal memory operation when cross page
        - RDMA/hns: Implement the disassociate_ucontext API
      * powerpc/livepatch: Implement reliable stack tracing for the consistency
        model (LP: #1771844)
        - powerpc/livepatch: Implement reliable stack tracing for the consistency
          model
      * vmxnet3: update to latest ToT (LP: #1768143)
        - vmxnet3: avoid xmit reset due to a race in vmxnet3
        - vmxnet3: use correct flag to indicate LRO feature
        - vmxnet3: fix incorrect dereference when rxvlan is disabled
      * 4.15.0-22-generic fails to boot on IBM S822LC (POWER8 (raw), altivec
        supported) (LP: #1773162)
        - Revert "powerpc/64s: Add support for a store forwarding barrier at kernel
          entry/exit"
        - powerpc/64s: Add support for a store forwarding barrier at kernel entry/exit
      * Decode ARM CPER records in kernel (LP: #1770244)
        - [Config] CONFIG_UEFI_CPER_ARM=y
        - efi: Move ARM CPER code to new file
        - efi: Parse ARM error information value
      * Adding back alx WoL feature (LP: #1772610)
        - SAUCE: Revert "alx: remove WoL support"
        - SAUCE: alx: add enable_wol paramenter
      * Lancer A0 Asic HBA's won't boot with 18.04 (LP: #1768103)
        - scsi: lpfc: Fix WQ/CQ creation for older asic's.
        - scsi: lpfc: Fix 16gb hbas failing cq create.
      * [LTCTest][OPAL][OP920] cpupower idle-info is not listing stop4 and stop5
        idle states when all CORES are guarded (LP: #1771780)
        - SAUCE: cpuidle/powernv : init all present cpus for deep states
      * Huawei 25G/100G Network Adapters Unsupported (LP: #1770970)
        - net-next/hinic: add pci device ids for 25ge and 100ge card
      * [Ubuntu 18.04.1] POWER9 - Nvidia Volta - Kernel changes to enable Nvidia
        driver on bare metal (LP: #1772991)
        - powerpc/powernv/npu: Fix deadlock in mmio_invalidate()
        - powerpc/powernv/mce: Don't silently restart the machine
        - powerpc/npu-dma.c: Fix crash after __mmu_notifier_register failure
        - powerpc/mm: Flush cache on memory hot(un)plug
        - powerpc/powernv/memtrace: Let the arch hotunplug code flush cache
        - powerpc/powernv/npu: Add lock to prevent race in concurrent context
          init/destroy
        - powerpc/powernv/npu: Prevent overwriting of pnv_npu2_init_contex() callback
          parameters
        - powerpc/powernv/npu: Do a PID GPU TLB flush when invalidating a large
          address range
        - powerpc/mce: Fix a bug where mce loops on memory UE.
      * cpum_sf: ensure sample freq is non-zero (LP: #1772593)
        - s390/cpum_sf: ensure sample frequency of perf event attributes is non-zero
      * PCIe link speeds of 16 GT/s are shown as "Unknown speed" (LP: #1773243)
        - PCI: Add decoding for 16 GT/s link speed
      * False positive ACPI _PRS error messages (LP: #1773295)
        - ACPI / PCI: pci_link: Allow the absence of _PRS and change log level
      * Dell systems crash when disabling Nvidia dGPU (LP: #1773299)
        - ACPI / OSI: Add OEM _OSI strings to disable NVidia RTD3
      * wlp3s0: failed to remove key (1, ff:ff:ff:ff:ff:ff) from hardware (-22)
        (LP: #1720930)
        - iwlwifi: mvm: fix "failed to remove key" message
      * Expose arm64 CPU topology to userspace (LP: #1770231)
        - ACPICA: ACPI 6.2: Additional PPTT flags
        - drivers: base: cacheinfo: move cache_setup_of_node()
        - drivers: base: cacheinfo: setup DT cache properties early
        - cacheinfo: rename of_node to fw_token
        - arm64/acpi: Create arch specific cpu to acpi id helper
        - ACPI/PPTT: Add Processor Properties Topology Table parsing
        - [Config] CONFIG_ACPI_PPTT=y
        - ACPI: Enable PPTT support on ARM64
        - drivers: base cacheinfo: Add support for ACPI based firmware tables
        - arm64: Add support for ACPI based firmware tables
        - arm64: topology: rename cluster_id
        - arm64: topology: enable ACPI/PPTT based CPU topology
        - ACPI: Add PPTT to injectable table list
        - arm64: topology: divorce MC scheduling domain from core_siblings
      * hisi_sas robustness fixes (LP: #1774466)
        - scsi: hisi_sas: delete timer when removing hisi_sas driver
        - scsi: hisi_sas: print device id for errors
        - scsi: hisi_sas: Add some checks to avoid free'ing a sas_task twice
        - scsi: hisi_sas: check host frozen before calling "done" function
        - scsi: hisi_sas: check sas_dev gone earlier in hisi_sas_abort_task()
        - scsi: hisi_sas: stop controller timer for reset
        - scsi: hisi_sas: update PHY linkrate after a controller reset
        - scsi: hisi_sas: change slot index allocation mode
        - scsi: hisi_sas: Change common allocation mode of device id
        - scsi: hisi_sas: Reset disks when discovered
        - scsi: hisi_sas: Create a scsi_host_template per HW module
        - scsi: hisi_sas: Init disks after controller reset
        - scsi: hisi_sas: Try wait commands before before controller reset
        - scsi: hisi_sas: Include TMF elements in struct hisi_sas_slot
        - scsi: hisi_sas: Add v2 hw force PHY function for internal ATA command
        - scsi: hisi_sas: Terminate STP reject quickly for v2 hw
        - scsi: hisi_sas: Fix return value when get_free_slot() failed
        - scsi: hisi_sas: Mark PHY as in reset for nexus reset
      * hisi_sas: Support newer v3 hardware (LP: #1774467)
        - scsi: hisi_sas: update RAS feature for later revision of v3 HW
        - scsi: hisi_sas: check IPTT is valid before using it for v3 hw
        - scsi: hisi_sas: fix PI memory size
        - scsi: hisi_sas: config ATA de-reset as an constrained command for v3 hw
        - scsi: hisi_sas: remove redundant handling to event95 for v3
        - scsi: hisi_sas: add readl poll timeout helper wrappers
        - scsi: hisi_sas: workaround a v3 hw hilink bug
        - scsi: hisi_sas: Add LED feature for v3 hw
      * hisi_sas: improve performance by optimizing DQ locking (LP: #1774472)
        - scsi: hisi_sas: initialize dq spinlock before use
        - scsi: hisi_sas: optimise the usage of DQ locking
        - scsi: hisi_sas: relocate smp sg map
        - scsi: hisi_sas: make return type of prep functions void
        - scsi: hisi_sas: allocate slot buffer earlier
        - scsi: hisi_sas: Don't lock DQ for complete task sending
        - scsi: hisi_sas: Use device lock to protect slot alloc/free
        - scsi: hisi_sas: add check of device in hisi_sas_task_exec()
        - scsi: hisi_sas: fix a typo in hisi_sas_task_prep()
      * Request to revert SAUCE patches in the 18.04 SRU and update with upstream
        version (LP: #1768431)
        - scsi: cxlflash: Handle spurious interrupts
        - scsi: cxlflash: Remove commmands from pending list on timeout
        - scsi: cxlflash: Synchronize reset and remove ops
        - SAUCE: (no-up) cxlflash: OCXL diff between v2 and v3
      * After update to 4.13-43 Intel Graphics are Laggy (LP: #1773520)
        - SAUCE: Revert "drm/i915/edp: Allow alternate fixed mode for eDP if
          available."
      * ELANPAD ELAN0612 does not work, patch available (LP: #1773509)
        - SAUCE: Input: elan_i2c - add ELAN0612 to the ACPI table
      * FS-Cache: Assertion failed: FS-Cache: 6 == 5 is false (LP: #1774336)
        - SAUCE: CacheFiles: fix a read_waiter/read_copier race
      * hns3 driver updates (LP: #1768670)
        - net: hns3: VF should get the real rss_size instead of rss_size_max
        - net: hns3: set the cmdq out_vld bit to 0 after used
        - net: hns3: fix endian issue when PF get mbx message flag
        - net: hns3: fix the queue id for tqp enable&&reset
        - net: hns3: set the max ring num when alloc netdev
        - net: hns3: add support for VF driver inner interface
          hclgevf_ops.get_tqps_and_rss_info
        - net: hns3: refactor the hclge_get/set_rss function
        - net: hns3: refactor the hclge_get/set_rss_tuple function
        - net: hns3: fix for RSS configuration loss problem during reset
        - net: hns3: fix for pause configuration lost during reset
        - net: hns3: fix for use-after-free when setting ring parameter
        - net: hns3: refactor the get/put_vector function
        - net: hns3: fix for coalesce configuration lost during reset
        - net: hns3: refactor the coalesce related struct
        - net: hns3: fix for coal configuation lost when setting the channel
        - net: hns3: add existence check when remove old uc mac address
        - net: hns3: fix for netdev not running problem after calling net_stop and
          net_open
        - net: hns3: fix for ipv6 address loss problem after setting channels
        - net: hns3: unify the pause params setup function
        - net: hns3: fix rx path skb->truesize reporting bug
        - net: hns3: add support for querying pfc puase packets statistic
        - net: hns3: fix for loopback failure when vlan filter is enable
        - net: hns3: fix for buffer overflow smatch warning
        - net: hns3: fix error type definition of return value
        - net: hns3: fix return value error of hclge_get_mac_vlan_cmd_status()
        - net: hns3: add existence checking before adding unicast mac address
        - net: hns3: add result checking for VF when modify unicast mac address
        - net: hns3: reallocate tx/rx buffer after changing mtu
        - net: hns3: fix the VF queue reset flow error
        - net: hns3: fix for vlan table lost problem when resetting
        - net: hns3: increase the max time for IMP handle command
        - net: hns3: change GL update rate
        - net: hns3: change the time interval of int_gl calculating
        - net: hns3: fix for getting wrong link mode problem
        - net: hns3: add get_link support to VF
        - net: hns3: add querying speed and duplex support to VF
        - net: hns3: fix for not returning problem in get_link_ksettings when phy
          exists
        - net: hns3: Changes to make enet watchdog timeout func common for PF/VF
        - net: hns3: Add VF Reset Service Task to support event handling
        - net: hns3: Add VF Reset device state and its handling
        - net: hns3: Add support to request VF Reset to PF
        - net: hns3: Add support to reset the enet/ring mgmt layer
        - net: hns3: Add support to re-initialize the hclge device
        - net: hns3: Changes to support ARQ(Asynchronous Receive Queue)
        - net: hns3: Add *Asserting Reset* mailbox message & handling in VF
        - net: hns3: Changes required in PF mailbox to support VF reset
        - net: hns3: hclge_inform_reset_assert_to_vf() can be static
        - net: hns3: fix for returning wrong value problem in hns3_get_rss_key_size
        - net: hns3: fix for returning wrong value problem in hns3_get_rss_indir_size
        - net: hns3: fix for the wrong shift problem in hns3_set_txbd_baseinfo
        - net: hns3: fix for not initializing VF rss_hash_key problem
        - net: hns3: never send command queue message to IMP when reset
        - net: hns3: remove unnecessary pci_set_drvdata() and devm_kfree()
        - net: hns3: fix length overflow when CONFIG_ARM64_64K_PAGES
        - net: hns3: Remove error log when getting pfc stats fails
        - net: hns3: fix to correctly fetch l4 protocol outer header
        - net: hns3: Fixes the out of bounds access in hclge_map_tqp
        - net: hns3: Fixes the error legs in hclge_init_ae_dev function
        - net: hns3: fix for phy_addr error in hclge_mac_mdio_config
        - net: hns3: Fix to support autoneg only for port attached with phy
        - net: hns3: fix a dead loop in hclge_cmd_csq_clean
        - net: hns3: Fix for packet loss due wrong filter config in VLAN tbls
        - net: hns3: Remove packet statistics in the range of 8192~12287
        - net: hns3: Add support of hardware rx-vlan-offload to HNS3 VF driver
        - net: hns3: Fix for setting mac address when resetting
        - net: hns3: remove add/del_tunnel_udp in hns3_enet module
        - net: hns3: fix for cleaning ring problem
        - net: hns3: refactor the loopback related function
        - net: hns3: Fix for deadlock problem occurring when unregistering ae_algo
        - net: hns3: Fix for the null pointer problem occurring when initializing
          ae_dev failed
        - net: hns3: Add a check for client instance init state
        - net: hns3: Change return type of hnae3_register_ae_dev
        - net: hns3: Change return type of hnae3_register_ae_algo
        - net: hns3: Change return value in hnae3_register_client
        - net: hns3: Fixes the back pressure setting when sriov is enabled
        - net: hns3: Fix for fiber link up problem
        - net: hns3: Add support of .sriov_configure in HNS3 driver
        - net: hns3: Fixes the missing PCI iounmap for various legs
        - net: hns3: Fixes error reported by Kbuild and internal review
        - net: hns3: Fixes API to fetch ethernet header length with kernel default
        - net: hns3: cleanup of return values in hclge_init_client_instance()
        - net: hns3: Fix the missing client list node initialization
        - net: hns3: Fix for hns3 module is loaded multiple times problem
        - net: hns3: Use enums instead of magic number in hclge_is_special_opcode
        - net: hns3: Fix for netdev not running problem after calling net_stop and
          net_open
        - net: hns3: Fixes kernel panic issue during rmmod hns3 driver
        - net: hns3: Fix for CMDQ and Misc. interrupt init order problem
        - net: hns3: Updates RX packet info fetch in case of multi BD
        - net: hns3: Add support for tx_accept_tag2 and tx_accept_untag2 config
        - net: hns3: Add STRP_TAGP field support for hardware revision 0x21
        - net: hns3: Add support to enable TX/RX promisc mode for H/W rev(0x21)
        - net: hns3: Fix for PF mailbox receving unknown message
        - net: hns3: Fixes the state to indicate client-type initialization
        - net: hns3: Fixes the init of the VALID BD info in the descriptor
        - net: hns3: Removes unnecessary check when clearing TX/RX rings
        - net: hns3: Clear TX/RX rings when stopping port & un-initializing client
        - net: hns3: Remove unused led control code
        - net: hns3: Adds support for led locate command for copper port
        - net: hns3: Fixes initalization of RoCE handle and makes it conditional
        - net: hns3: Disable vf vlan filter when vf vlan table is full
        - net: hns3: Add support for IFF_ALLMULTI flag
        - net: hns3: Add repeat address checking for setting mac address
        - net: hns3: Fix setting mac address error
        - net: hns3: Fix for service_task not running problem after resetting
        - net: hns3: Fix for hclge_reset running repeatly problem
        - net: hns3: Fix for phy not link up problem after resetting
        - net: hns3: Add missing break in misc_irq_handle
        - net: hns3: Fix for vxlan tx checksum bug
        - net: hns3: Optimize the PF's process of updating multicast MAC
        - net: hns3: Optimize the VF's process of updating multicast MAC
        - SAUCE: {topost} net: hns3: add support for serdes loopback selftest
        - SAUCE: {topost} net: hns3: RX BD information valid only in last BD except
          VLD bit and buffer size
        - SAUCE: {topost} net: hns3: remove hclge_get_vector_index from
          hclge_bind_ring_with_vector
        - SAUCE: {topost} net: hns3: rename the interface for init_client_instance and
          uninit_client_instance
        - SAUCE: {topost} net: hns3: add vector status check before free vector
        - SAUCE: {topost} net: hns3: add l4_type check for both ipv4 and ipv6
        - SAUCE: {topost} net: hns3: remove unused head file in hnae3.c
        - SAUCE: {topost} net: hns3: extraction an interface for state state
          init|uninit
        - SAUCE: {topost} net: hns3: print the ret value in error information
        - SAUCE: {topost} net: hns3: remove the Redundant put_vector in
          hns3_client_uninit
        - SAUCE: {topost} net: hns3: add unlikely for error check
        - SAUCE: {topost} net: hns3: remove back in struct hclge_hw
        - SAUCE: {topost} net: hns3: use lower_32_bits and upper_32_bits
        - SAUCE: {topost} net: hns3: remove unused hclge_ring_to_dma_dir
        - SAUCE: {topost} net: hns3: remove useless code in hclge_cmd_send
        - SAUCE: {topost} net: hns3: remove some redundant assignments
        - SAUCE: {topost} net: hns3: simplify hclge_cmd_csq_clean
        - SAUCE: {topost} net: hns3: using modulo for cyclic counters in
          hclge_cmd_send
        - SAUCE: {topost} net: hns3: remove a redundant hclge_cmd_csq_done
        - SAUCE: {topost} net: hns3: remove some unused members of some structures
        - SAUCE: {topost} net: hns3: give default option while dependency HNS3 set
        - SAUCE: {topost} net: hns3: use dma_zalloc_coherent instead of
          kzalloc/dma_map_single
        - SAUCE: {topost} net: hns3: modify hnae_ to hnae3_
        - SAUCE: {topost} net: hns3: fix unused function warning in VF driver
        - SAUCE: {topost} net: hns3: remove some redundant assignments
        - SAUCE: {topost} net: hns3: standardize the handle of return value
        - SAUCE: {topost} net: hns3: remove extra space and brackets
        - SAUCE: {topost} net: hns3: fix unreasonable code comments
        - SAUCE: {topost} net: hns3: use decimal for bit offset macros
        - SAUCE: {topost} net: hns3: modify inconsistent bit mask macros
        - SAUCE: {topost} net: hns3: fix mislead parameter name
        - SAUCE: {topost} net: hns3: remove unused struct member and definition
        - SAUCE: {topost} net: hns3: Add SPDX tags to hns3 driver
        - SAUCE: {topost} net: hns3: Add pf reset for hip08 RoCE
        - SAUCE: {topost} net: hns3: optimize the process of notifying roce client
        - SAUCE: {topost} net: hns3: Add calling roce callback function when link
          status change
        - SAUCE: {topost} net: hns3: fix tc setup when netdev is first up
        - SAUCE: {topost} net: hns3: fix for mac pause not disable in pfc mode
        - SAUCE: {topost} net: hns3: fix for waterline not setting correctly
        - SAUCE: {topost} net: hns3: fix for l4 checksum offload bug
        - SAUCE: {topost} net: hns3: fix for mailbox message truncated problem
        - SAUCE: {topost} net: hns3: Add configure for mac minimal frame size
        - SAUCE: {topost} net: hns3: fix warning bug when doing lp selftest
        - SAUCE: {topost} net: hns3: fix get_vector ops in hclgevf_main module
        - SAUCE: {topost} net: hns3: remove the warning when clear reset cause
        - SAUCE: {topost} net: hns3: Use roce handle when calling roce callback
          function
        - SAUCE: {topost} net: hns3: prevent sending command during global or core
          reset
        - SAUCE: {topost} net: hns3: modify the order of initializeing command queue
          register
        - SAUCE: {topost} net: hns3: reset net device with rtnl_lock
        - SAUCE: {topost} net: hns3: prevent to request reset frequently
        - SAUCE: {topost} net: hns3: correct reset event status register
        - SAUCE: {topost} net: hns3: separate roce from nic when resetting
        - SAUCE: net: hns3: Fix for phy link issue when using marvell phy driver
        - SAUCE: {topost} net: hns3: fix return value error in
          hns3_reset_notify_down_enet
        - SAUCE: {topost} net: hns3: remove unnecessary ring configuration operation
          while resetting
        - SAUCE: {topost} net: hns3: fix for reset_level default assignment probelm
        - SAUCE: {topost} net: hns3: fix for using wrong mask and shift in
          hclge_get_ring_chain_from_mbx
        - SAUCE: {topost} net: hns3: fix comments for hclge_get_ring_chain_from_mbx
        - SAUCE: net: hns3: Fix for VF mailbox cannot receiving PF response
        - SAUCE: net: hns3: Fix for VF mailbox receiving unknown message
        - SAUCE: net: hns3: Optimize PF CMDQ interrupt switching process
      * enable mic-mute hotkey and led on Lenovo M820z and M920z (LP: #1774306)
        - ALSA: hda/realtek - Enable mic-mute hotkey for several Lenovo AIOs
      * Bionic update: upstream stable patchset 2018-05-29 (LP: #1774063)
        - cifs: do not allow creating sockets except with SMB1 posix exensions
        - btrfs: fix unaligned access in readdir
        - x86/acpi: Prevent X2APIC id 0xffffffff from being accounted
        - clocksource/imx-tpm: Correct -ETIME return condition check
        - x86/tsc: Prevent 32bit truncation in calc_hpet_ref()
        - drm/vc4: Fix memory leak during BO teardown
        - drm/i915/gvt: throw error on unhandled vfio ioctls
        - drm/i915/audio: Fix audio detection issue on GLK
        - drm/i915: Do no use kfree() to free a kmem_cache_alloc() return value
        - drm/i915: Fix LSPCON TMDS output buffer enabling from low-power state
        - drm/i915/bxt, glk: Increase PCODE timeouts during CDCLK freq changing
        - usb: musb: fix enumeration after resume
        - usb: musb: call pm_runtime_{get,put}_sync before reading vbus registers
        - usb: musb: Fix external abort in musb_remove on omap2430
        - firewire-ohci: work around oversized DMA reads on JMicron controllers
        - x86/tsc: Allow TSC calibration without PIT
        - NFSv4: always set NFS_LOCK_LOST when a lock is lost.
        - ACPI / LPSS: Do not instiate platform_dev for devs without MMIO resources
        - ALSA: hda - Use IS_REACHABLE() for dependency on input
        - ASoC: au1x: Fix timeout tests in au1xac97c_ac97_read()
        - kvm: x86: fix KVM_XEN_HVM_CONFIG ioctl
        - RDMA/core: Clarify rdma_ah_find_type
        - KVM: PPC: Book3S HV: Enable migration of decrementer register
        - netfilter: ipv6: nf_defrag: Pass on packets to stack per RFC2460
        - tracing/hrtimer: Fix tracing bugs by taking all clock bases and modes into
          account
        - KVM: s390: use created_vcpus in more places
        - platform/x86: dell-laptop: Filter out spurious keyboard backlight change
          events
        - xprtrdma: Fix backchannel allocation of extra rpcrdma_reps
        - selftest: ftrace: Fix to pick text symbols for kprobes
        - PCI: Add function 1 DMA alias quirk for Marvell 9128
        - Input: psmouse - fix Synaptics detection when protocol is disabled
        - libbpf: Makefile set specified permission mode
        - Input: synaptics - reset the ABS_X/Y fuzz after initializing MT axes
        - i40iw: Free IEQ resources
        - i40iw: Zero-out consumer key on allocate stag for FMR
        - perf unwind: Do not look just at the global callchain_param.record_mode
        - tools lib traceevent: Simplify pointer print logic and fix %pF
        - perf callchain: Fix attr.sample_max_stack setting
        - tools lib traceevent: Fix get_field_str() for dynamic strings
        - perf record: Fix failed memory allocation for get_cpuid_str
        - iommu/exynos: Don't unconditionally steal bus ops
        - powerpc: System reset avoid interleaving oops using die synchronisation
        - iommu/vt-d: Use domain instead of cache fetching
        - dm thin: fix documentation relative to low water mark threshold
        - dm mpath: return DM_MAPIO_REQUEUE on blk-mq rq allocation failure
        - ubifs: Fix uninitialized variable in search_dh_cookie()
        - net: stmmac: dwmac-meson8b: fix setting the RGMII TX clock on Meson8b
        - net: stmmac: dwmac-meson8b: propagate rate changes to the parent clock
        - spi: a3700: Clear DATA_OUT when performing a read
        - IB/cq: Don't force IB_POLL_DIRECT poll context for ib_process_cq_direct
        - nfs: Do not convert nfs_idmap_cache_timeout to jiffies
        - MIPS: Fix clean of vmlinuz.{32,ecoff,bin,srec}
        - PCI: Add dummy pci_irqd_intx_xlate() for CONFIG_PCI=n build
        - watchdog: sp5100_tco: Fix watchdog disable bit
        - kconfig: Don't leak main menus during parsing
        - kconfig: Fix automatic menu creation mem leak
        - kconfig: Fix expr_free() E_NOT leak
        - ipmi/powernv: Fix error return code in ipmi_powernv_probe()
        - Btrfs: set plug for fsync
        - btrfs: Fix out of bounds access in btrfs_search_slot
        - Btrfs: fix scrub to repair raid6 corruption
        - btrfs: fail mount when sb flag is not in BTRFS_SUPER_FLAG_SUPP
        - Btrfs: fix unexpected EEXIST from btrfs_get_extent
        - Btrfs: raid56: fix race between merge_bio and rbio_orig_end_io
        - RDMA/cma: Check existence of netdevice during port validation
        - f2fs: avoid hungtask when GC encrypted block if io_bits is set
        - scsi: devinfo: fix format of the device list
        - scsi: fas216: fix sense buffer initialization
        - Input: stmfts - set IRQ_NOAUTOEN to the irq flag
        - HID: roccat: prevent an out of bounds read in kovaplus_profile_activated()
        - nfp: fix error return code in nfp_pci_probe()
        - block: Set BIO_TRACE_COMPLETION on new bio during split
        - bpf: test_maps: cleanup sockmaps when test ends
        - i40evf: Don't schedule reset_task when device is being removed
        - i40evf: ignore link up if not running
        - platform/x86: thinkpad_acpi: suppress warning about palm detection
        - KVM: s390: vsie: use READ_ONCE to access some SCB fields
        - blk-mq-debugfs: don't allow write on attributes with seq_operations set
        - ASoC: rockchip: Use dummy_dai for rt5514 dsp dailink
        - igb: Allow to remove administratively set MAC on VFs
        - igb: Clear TXSTMP when ptp_tx_work() is timeout
        - fm10k: fix "failed to kill vid" message for VF
        - x86/hyperv: Stop suppressing X86_FEATURE_PCID
        - tty: serial: exar: Relocate sleep wake-up handling
        - device property: Define type of PROPERTY_ENRTY_*() macros
        - crypto: artpec6 - remove select on non-existing CRYPTO_SHA384
        - RDMA/uverbs: Use an unambiguous errno for method not supported
        - jffs2: Fix use-after-free bug in jffs2_iget()'s error handling path
        - ixgbe: don't set RXDCTL.RLPML for 82599
        - i40e: program fragmented IPv4 filter input set
        - i40e: fix reported mask for ntuple filters
        - samples/bpf: Partially fixes the bpf.o build
        - powerpc/numa: Use ibm,max-associativity-domains to discover possible nodes
        - powerpc/numa: Ensure nodes initialized for hotplug
        - RDMA/mlx5: Avoid memory leak in case of XRCD dealloc failure
        - ntb_transport: Fix bug with max_mw_size parameter
        - gianfar: prevent integer wrapping in the rx handler
        - x86/hyperv: Check for required priviliges in hyperv_init()
        - netfilter: x_tables: fix pointer leaks to userspace
        - tcp_nv: fix potential integer overflow in tcpnv_acked
        - kvm: Map PFN-type memory regions as writable (if possible)
        - x86/kvm/vmx: do not use vm-exit instruction length for fast MMIO when
          running nested
        - fs/dax.c: release PMD lock even when there is no PMD support in DAX
        - ocfs2: return -EROFS to mount.ocfs2 if inode block is invalid
        - ocfs2/acl: use 'ip_xattr_sem' to protect getting extended attribute
        - ocfs2: return error when we attempt to access a dirty bh in jbd2
        - mm/mempolicy: fix the check of nodemask from user
        - mm/mempolicy: add nodes_empty check in SYSC_migrate_pages
        - asm-generic: provide generic_pmdp_establish()
        - sparc64: update pmdp_invalidate() to return old pmd value
        - mm: thp: use down_read_trylock() in khugepaged to avoid long block
        - mm: pin address_space before dereferencing it while isolating an LRU page
        - mm/fadvise: discard partial page if endbyte is also EOF
        - openvswitch: Remove padding from packet before L3+ conntrack processing
        - blk-mq: fix discard merge with scheduler attached
        - IB/hfi1: Re-order IRQ cleanup to address driver cleanup race
        - IB/hfi1: Fix for potential refcount leak in hfi1_open_file()
        - IB/ipoib: Fix for potential no-carrier state
        - IB/core: Map iWarp AH type to undefined in rdma_ah_find_type
        - drm/nouveau/pmu/fuc: don't use movw directly anymore
        - s390/eadm: fix CONFIG_BLOCK include dependency
        - netfilter: ipv6: nf_defrag: Kill frag queue on RFC2460 failure
        - x86/power: Fix swsusp_arch_resume prototype
        - x86/dumpstack: Avoid uninitlized variable
        - firmware: dmi_scan: Fix handling of empty DMI strings
        - ACPI: processor_perflib: Do not send _PPC change notification if not ready
        - ACPI / bus: Do not call _STA on battery devices with unmet dependencies
        - ACPI / scan: Use acpi_bus_get_status() to initialize ACPI_TYPE_DEVICE devs
        - MIPS: TXx9: use IS_BUILTIN() for CONFIG_LEDS_CLASS
        - perf record: Fix period option handling
        - MIPS: Generic: Support GIC in EIC mode
        - perf evsel: Fix period/freq terms setup
        - xen-netfront: Fix race between device setup and open
        - xen/grant-table: Use put_page instead of free_page
        - bpf: sockmap, fix leaking maps with attached but not detached progs
        - RDS: IB: Fix null pointer issue
        - arm64: spinlock: Fix theoretical trylock() A-B-A with LSE atomics
        - proc: fix /proc/*/map_files lookup
        - PM / domains: Fix up domain-idle-states OF parsing
        - cifs: silence compiler warnings showing up with gcc-8.0.0
        - bcache: properly set task state in bch_writeback_thread()
        - bcache: fix for allocator and register thread race
        - bcache: fix for data collapse after re-attaching an attached device
        - bcache: return attach error when no cache set exist
        - cpufreq: intel_pstate: Enable HWP during system resume on CPU0
        - selftests/ftrace: Add some missing glob checks
        - rxrpc: Don't put crypto buffers on the stack
        - svcrdma: Fix Read chunk round-up
        - net: Extra '_get' in declaration of arch_get_platform_mac_address
        - tools/libbpf: handle issues with bpf ELF objects containing .eh_frames
        - SUNRPC: Don't call __UDPX_INC_STATS() from a preemptible context
        - net: stmmac: discard disabled flags in interrupt status register
        - bpf: fix rlimit in reuseport net selftest
        - ACPI / EC: Restore polling during noirq suspend/resume phases
        - PM / wakeirq: Fix unbalanced IRQ enable for wakeirq
        - vfs/proc/kcore, x86/mm/kcore: Fix SMAP fault when dumping vsyscall user page
        - powerpc/mm/hash64: Zero PGD pages on allocation
        - x86/platform/UV: Fix GAM Range Table entries less than 1GB
        - locking/qspinlock: Ensure node->count is updated before initialising node
        - powerpc/powernv: IMC fix out of bounds memory access at shutdown
        - perf test: Fix test trace+probe_libc_inet_pton.sh for s390x
        - irqchip/gic-v3: Ignore disabled ITS nodes
        - cpumask: Make for_each_cpu_wrap() available on UP as well
        - irqchip/gic-v3: Change pr_debug message to pr_devel
        - RDMA/core: Reduce poll batch for direct cq polling
        - alarmtimer: Init nanosleep alarm timer on stack
        - netfilter: x_tables: cap allocations at 512 mbyte
        - netfilter: x_tables: add counters allocation wrapper
        - netfilter: compat: prepare xt_compat_init_offsets to return errors
        - netfilter: compat: reject huge allocation requests
        - netfilter: x_tables: limit allocation requests for blob rule heads
        - perf: Fix sample_max_stack maximum check
        - perf: Return proper values for user stack errors
        - RDMA/mlx5: Fix NULL dereference while accessing XRC_TGT QPs
        - Revert "KVM: X86: Fix SMRAM accessing even if VM is shutdown"
        - mac80211_hwsim: fix use-after-free bug in hwsim_exit_net
        - btrfs: Fix race condition between delayed refs and blockgroup removal
        - mm,vmscan: Allow preallocating memory for register_shrinker().
      * Bionic update: upstream stable patchset 2018-05-24 (LP: #1773233)
        - tty: make n_tty_read() always abort if hangup is in progress
        - cpufreq: CPPC: Use transition_delay_us depending transition_latency
        - ubifs: Check ubifs_wbuf_sync() return code
        - ubi: fastmap: Don't flush fastmap work on detach
        - ubi: Fix error for write access
        - ubi: Reject MLC NAND
        - mm/ksm.c: fix inconsistent accounting of zero pages
        - mm/hmm: hmm_pfns_bad() was accessing wrong struct
        - task_struct: only use anon struct under randstruct plugin
        - fs/reiserfs/journal.c: add missing resierfs_warning() arg
        - resource: fix integer overflow at reallocation
        - ipc/shm: fix use-after-free of shm file via remap_file_pages()
        - mm, slab: reschedule cache_reap() on the same CPU
        - usb: musb: gadget: misplaced out of bounds check
        - phy: allwinner: sun4i-usb: poll vbus changes on A23/A33 when driving VBUS
        - usb: gadget: udc: core: update usb_ep_queue() documentation
        - ARM64: dts: meson: reduce odroid-c2 eMMC maximum rate
        - KVM: arm/arm64: vgic-its: Fix potential overrun in vgic_copy_lpi_list
        - ARM: EXYNOS: Fix coupled CPU idle freeze on Exynos4210
        - arm: dts: mt7623: fix USB initialization fails on bananapi-r2
        - ARM: dts: at91: at91sam9g25: fix mux-mask pinctrl property
        - ARM: dts: exynos: Fix IOMMU support for GScaler devices on Exynos5250
        - ARM: dts: at91: sama5d4: fix pinctrl compatible string
        - spi: atmel: init FIFOs before spi enable
        - spi: Fix scatterlist elements size in spi_map_buf
        - spi: Fix unregistration of controller with fixed SPI bus number
        - media: atomisp_fops.c: disable atomisp_compat_ioctl32
        - media: vivid: check if the cec_adapter is valid
        - media: vsp1: Fix BRx conditional path in WPF
        - x86/xen: Delay get_cpu_cap until stack canary is established
        - regmap: Fix reversed bounds check in regmap_raw_write()
        - ACPI / video: Add quirk to force acpi-video backlight on Samsung 670Z5E
        - ACPI / hotplug / PCI: Check presence of slot itself in get_slot_status()
        - USB: gadget: f_midi: fixing a possible double-free in f_midi
        - USB:fix USB3 devices behind USB3 hubs not resuming at hibernate thaw
        - usb: dwc3: prevent setting PRTCAP to OTG from debugfs
        - usb: dwc3: pci: Properly cleanup resource
        - usb: dwc3: gadget: never call ->complete() from ->ep_queue()
        - cifs: fix memory leak in SMB2_open()
        - fix smb3-encryption breakage when CONFIG_DEBUG_SG=y
        - smb3: Fix root directory when server returns inode number of zero
        - HID: i2c-hid: fix size check and type usage
        - i2c: i801: Save register SMBSLVCMD value only once
        - i2c: i801: Restore configuration at shutdown
        - CIFS: refactor crypto shash/sdesc allocation&free
        - CIFS: add sha512 secmech
        - CIFS: fix sha512 check in cifs_crypto_secmech_release
        - powerpc/64s: Fix dt_cpu_ftrs to have restore_cpu clear unwanted LPCR bits
        - powerpc/64: Call H_REGISTER_PROC_TBL when running as a HPT guest on POWER9
        - powerpc/64: Fix smp_wmb barrier definition use use lwsync consistently
        - powerpc/kprobes: Fix call trace due to incorrect preempt count
        - powerpc/kexec_file: Fix error code when trying to load kdump kernel
        - powerpc/powernv: define a standard delay for OPAL_BUSY type retry loops
        - powerpc/powernv: Fix OPAL NVRAM driver OPAL_BUSY loops
        - HID: Fix hid_report_len usage
        - HID: core: Fix size as type u32
        - soc: mediatek: fix the mistaken pointer accessed when subdomains are added
        - ASoC: ssm2602: Replace reg_default_raw with reg_default
        - ASoC: topology: Fix kcontrol name string handling
        - irqchip/gic: Take lock when updating irq type
        - random: use a tighter cap in credit_entropy_bits_safe()
        - extcon: intel-cht-wc: Set direction and drv flags for V5 boost GPIO
        - block: use 32-bit blk_status_t on Alpha
        - jbd2: if the journal is aborted then don't allow update of the log tail
        - ext4: shutdown should not prevent get_write_access
        - ext4: eliminate sleep from shutdown ioctl
        - ext4: pass -ESHUTDOWN code to jbd2 layer
        - ext4: don't update checksum of new initialized bitmaps
        - ext4: protect i_disksize update by i_data_sem in direct write path
        - ext4: limit xattr size to INT_MAX
        - ext4: always initialize the crc32c checksum driver
        - ext4: don't allow r/w mounts if metadata blocks overlap the superblock
        - ext4: move call to ext4_error() into ext4_xattr_check_block()
        - ext4: add bounds checking to ext4_xattr_find_entry()
        - ext4: add extra checks to ext4_xattr_block_get()
        - dm crypt: limit the number of allocated pages
        - RDMA/ucma: Don't allow setting RDMA_OPTION_IB_PATH without an RDMA device
        - RDMA/mlx5: Protect from NULL pointer derefence
        - RDMA/rxe: Fix an out-of-bounds read
        - ALSA: pcm: Fix UAF at PCM release via PCM timer access
        - IB/srp: Fix srp_abort()
        - IB/srp: Fix completion vector assignment algorithm
        - dmaengine: at_xdmac: fix rare residue corruption
        - cxl: Fix possible deadlock when processing page faults from cxllib
        - tpm: self test failure should not cause suspend to fail
        - libnvdimm, dimm: fix dpa reservation vs uninitialized label area
        - libnvdimm, namespace: use a safe lookup for dimm device name
        - nfit, address-range-scrub: fix scrub in-progress reporting
        - nfit: skip region registration for incomplete control regions
        - ring-buffer: Check if memory is available before allocation
        - um: Compile with modern headers
        - um: Use POSIX ucontext_t instead of struct ucontext
        - iommu/vt-d: Fix a potential memory leak
        - mmc: jz4740: Fix race condition in IRQ mask update
        - mmc: tmio: Fix error handling when issuing CMD23
        - PCI: Mark Broadcom HT1100 and HT2000 Root Port Extended Tags as broken
        - clk: mvebu: armada-38x: add support for missing clocks
        - clk: fix false-positive Wmaybe-uninitialized warning
        - clk: mediatek: fix PWM clock source by adding a fixed-factor clock
        - clk: bcm2835: De-assert/assert PLL reset signal when appropriate
        - pwm: rcar: Fix a condition to prevent mismatch value setting to duty
        - thermal: imx: Fix race condition in imx_thermal_probe()
        - dt-bindings: clock: mediatek: add binding for fixed-factor clock axisel_d4
        - watchdog: f71808e_wdt: Fix WD_EN register read
        - ALSA: pcm: Use ERESTARTSYS instead of EINTR in OSS emulation
        - ALSA: pcm: Avoid potential races between OSS ioctls and read/write
        - ALSA: pcm: Return -EBUSY for OSS ioctls changing busy streams
        - ALSA: pcm: Fix mutex unbalance in OSS emulation ioctls
        - ALSA: pcm: Fix endless loop for XRUN recovery in OSS emulation
        - drm/amdgpu: Add an ATPX quirk for hybrid laptop
        - drm/amdgpu: Fix always_valid bos multiple LRU insertions.
        - drm/amdgpu/sdma: fix mask in emit_pipeline_sync
        - drm/amdgpu: Fix PCIe lane width calculation
        - drm/amdgpu/si: implement get/set pcie_lanes asic callback
        - drm/rockchip: Clear all interrupts before requesting the IRQ
        - drm/radeon: add PX quirk for Asus K73TK
        - drm/radeon: Fix PCIe lane width calculation
        - ALSA: line6: Use correct endpoint type for midi output
        - ALSA: rawmidi: Fix missing input substream checks in compat ioctls
        - ALSA: hda - New VIA controller suppor no-snoop path
        - random: fix crng_ready() test
        - random: use a different mixing algorithm for add_device_randomness()
        - random: crng_reseed() should lock the crng instance that it is modifying
        - random: add new ioctl RNDRESEEDCRNG
        - HID: input: fix battery level reporting on BT mice
        - HID: hidraw: Fix crash on HIDIOCGFEATURE with a destroyed device
        - HID: wacom: bluetooth: send exit report for recent Bluetooth devices
        - MIPS: uaccess: Add micromips clobbers to bzero invocation
        - MIPS: memset.S: EVA & fault support for small_memset
        - MIPS: memset.S: Fix return of __clear_user from Lpartial_fixup
        - MIPS: memset.S: Fix clobber of v1 in last_fixup
        - powerpc/eeh: Fix enabling bridge MMIO windows
        - powerpc/lib: Fix off-by-one in alternate feature patching
        - udf: Fix leak of UTF-16 surrogates into encoded strings
        - fanotify: fix logic of events on child
        - mmc: sdhci-pci: Only do AMD tuning for HS200
        - drm/i915: Correctly handle limited range YCbCr data on VLV/CHV
        - jffs2_kill_sb(): deal with failed allocations
        - hypfs_kill_super(): deal with failed allocations
        - orangefs_kill_sb(): deal with allocation failures
        - rpc_pipefs: fix double-dput()
        - Don't leak MNT_INTERNAL away from internal mounts
        - autofs: mount point create should honour passed in mode
        - mm/filemap.c: fix NULL pointer in page_cache_tree_insert()
        - Revert "media: lirc_zilog: driver only sends LIRCCODE"
        - media: staging: lirc_zilog: incorrect reference counting
        - writeback: safer lock nesting
        - Bluetooth: hci_bcm: Add irq_polarity module option
        - mm: hwpoison: disable memory error handling on 1GB hugepage
        - media: rc: oops in ir_timer_keyup after device unplug
        - acpi, nfit: rework NVDIMM leaf method detection
        - ceph: always update atime/mtime/ctime for new inode
        - ext4: fix offset overflow on 32-bit archs in ext4_iomap_begin()
        - ext4: force revalidation of directory pointer after seekdir(2)
        - RDMA/core: Avoid that ib_drain_qp() triggers an out-of-bounds stack access
        - xprtrdma: Fix latency regression on NUMA NFS/RDMA clients
        - xprtrdma: Fix corner cases when handling device removal
        - IB/srpt: Fix an out-of-bounds stack access in srpt_zerolength_write()
        - drivers/infiniband/core/verbs.c: fix build with gcc-4.4.4
        - drivers/infiniband/ulp/srpt/ib_srpt.c: fix build with gcc-4.4.4
        - mmc: core: Prevent bus reference leak in mmc_blk_init()
        - drm/amd/display: HDMI has no sound after Panel power off/on
        - trace_uprobe: Use %lx to display offset
        - clk: tegra: Mark HCLK, SCLK and EMC as critical
        - pwm: mediatek: Fix up PWM4 and PWM5 malfunction on MT7623
        - pwm: mediatek: Improve precision in rate calculation
        - HID: i2c-hid: Fix resume issue on Raydium touchscreen device
        - s390: add support for IBM z14 Model ZR1
        - drm/i915: Fix hibernation with ACPI S0 target state
        - libnvdimm, dimm: handle EACCES failures from label reads
        - device-dax: allow MAP_SYNC to succeed
        - HID: i2c-hid: fix inverted return value from i2c_hid_command()
      * CVE-2018-7755
        - SAUCE: floppy: Do not copy a kernel pointer to user memory in FDGETPRM ioctl
    
     -- Kleber Sacilotto de Souza <email address hidden>  Wed, 13 Jun 2018 14:48:53 +0200
  • linux-gcp (4.15.0-1009.9) bionic; urgency=medium
    
      * linux-gcp: 4.15.0-1009.9 -proposed tracker (LP: #1772934)
    
      * Switch Build-Depends: transfig to fig2dev (LP: #1770770)
        - [Config] update Build-Depends: transfig to fig2dev
    
      [ Ubuntu: 4.15.0-23.25 ]
    
      * linux: 4.15.0-23.25 -proposed tracker (LP: #1772927)
      * arm64 SDEI support needs trampoline code for KPTI (LP: #1768630)
        - arm64: mmu: add the entry trampolines start/end section markers into
          sections.h
        - arm64: sdei: Add trampoline code for remapping the kernel
      * Some PCIe errors not surfaced through rasdaemon (LP: #1769730)
        - ACPI: APEI: handle PCIe AER errors in separate function
        - ACPI: APEI: call into AER handling regardless of severity
      * qla2xxx: Fix page fault at kmem_cache_alloc_node() (LP: #1770003)
        - scsi: qla2xxx: Fix session cleanup for N2N
        - scsi: qla2xxx: Remove unused argument from qlt_schedule_sess_for_deletion()
        - scsi: qla2xxx: Serialize session deletion by using work_lock
        - scsi: qla2xxx: Serialize session free in qlt_free_session_done
        - scsi: qla2xxx: Don't call dma_free_coherent with IRQ disabled.
        - scsi: qla2xxx: Fix warning in qla2x00_async_iocb_timeout()
        - scsi: qla2xxx: Prevent relogin trigger from sending too many commands
        - scsi: qla2xxx: Fix double free bug after firmware timeout
        - scsi: qla2xxx: Fixup locking for session deletion
      * Several hisi_sas bug fixes (LP: #1768974)
        - scsi: hisi_sas: dt-bindings: add an property of signal attenuation
        - scsi: hisi_sas: support the property of signal attenuation for v2 hw
        - scsi: hisi_sas: fix the issue of link rate inconsistency
        - scsi: hisi_sas: fix the issue of setting linkrate register
        - scsi: hisi_sas: increase timer expire of internal abort task
        - scsi: hisi_sas: remove unused variable hisi_sas_devices.running_req
        - scsi: hisi_sas: fix return value of hisi_sas_task_prep()
        - scsi: hisi_sas: Code cleanup and minor bug fixes
      * [bionic] machine stuck and bonding not working well when nvmet_rdma module
        is loaded (LP: #1764982)
        - nvmet-rdma: Don't flush system_wq by default during remove_one
        - nvme-rdma: Don't flush delete_wq by default during remove_one
      * Warnings/hang during error handling of SATA disks on SAS controller
        (LP: #1768971)
        - scsi: libsas: defer ata device eh commands to libata
      * Hotplugging a SATA disk into a SAS controller may cause crash (LP: #1768948)
        - ata: do not schedule hot plug if it is a sas host
      * ISST-LTE:pKVM:Ubuntu1804: rcu_sched self-detected stall on CPU follow by CPU
        ATTEMPT TO RE-ENTER FIRMWARE! (LP: #1767927)
        - powerpc/powernv: Handle unknown OPAL errors in opal_nvram_write()
        - powerpc/64s: return more carefully from sreset NMI
        - powerpc/64s: sreset panic if there is no debugger or crash dump handlers
      * fsnotify: Fix fsnotify_mark_connector race (LP: #1765564)
        - fsnotify: Fix fsnotify_mark_connector race
      * Hang on network interface removal in Xen virtual machine (LP: #1771620)
        - xen-netfront: Fix hang on device removal
      * HiSilicon HNS NIC names are truncated in /proc/interrupts (LP: #1765977)
        - net: hns: Avoid action name truncation
      * Ubuntu 18.04 kernel crashed while in degraded mode (LP: #1770849)
        - SAUCE: powerpc/perf: Fix memory allocation for core-imc based on
          num_possible_cpus()
      * Switch Build-Depends: transfig to fig2dev (LP: #1770770)
        - [Config] update Build-Depends: transfig to fig2dev
      * smp_call_function_single/many core hangs with stop4 alone (LP: #1768898)
        - cpufreq: powernv: Fix hardlockup due to synchronous smp_call in timer
          interrupt
      * Add d-i support for Huawei NICs (LP: #1767490)
        - d-i: add hinic to nic-modules udeb
      * unregister_netdevice: waiting for eth0 to become free. Usage count = 5
        (LP: #1746474)
        - xfrm: reuse uncached_list to track xdsts
      * Include nfp driver in linux-modules (LP: #1768526)
        - [Config] Add nfp.ko to generic inclusion list
      * Kernel panic on boot (m1.small in cn-north-1) (LP: #1771679)
        - x86/xen: Reset VCPU0 info pointer after shared_info remap
      * CVE-2018-3639 (x86)
        - x86/bugs: Fix the parameters alignment and missing void
        - KVM: SVM: Move spec control call after restore of GS
        - x86/speculation: Use synthetic bits for IBRS/IBPB/STIBP
        - x86/cpufeatures: Disentangle MSR_SPEC_CTRL enumeration from IBRS
        - x86/cpufeatures: Disentangle SSBD enumeration
        - x86/cpufeatures: Add FEATURE_ZEN
        - x86/speculation: Handle HT correctly on AMD
        - x86/bugs, KVM: Extend speculation control for VIRT_SPEC_CTRL
        - x86/speculation: Add virtualized speculative store bypass disable support
        - x86/speculation: Rework speculative_store_bypass_update()
        - x86/bugs: Unify x86_spec_ctrl_{set_guest,restore_host}
        - x86/bugs: Expose x86_spec_ctrl_base directly
        - x86/bugs: Remove x86_spec_ctrl_set()
        - x86/bugs: Rework spec_ctrl base and mask logic
        - x86/speculation, KVM: Implement support for VIRT_SPEC_CTRL/LS_CFG
        - KVM: SVM: Implement VIRT_SPEC_CTRL support for SSBD
        - x86/bugs: Rename SSBD_NO to SSB_NO
        - bpf: Prevent memory disambiguation attack
        - KVM: VMX: Expose SSBD properly to guests.
      * Suspend to idle: Open lid didn't resume (LP: #1771542)
        - ACPI / PM: Do not reconfigure GPEs for suspend-to-idle
      * Fix initialization failure detection in SDEI for device-tree based systems
        (LP: #1768663)
        - firmware: arm_sdei: Fix return value check in sdei_present_dt()
      * No driver for Huawei network adapters on arm64 (LP: #1769899)
        - net-next/hinic: add arm64 support
      * CVE-2018-1092
        - ext4: fail ext4_iget for root directory if unallocated
      * kernel 4.15 breaks nouveau on Lenovo P50 (LP: #1763189)
        - drm/nouveau: Fix deadlock in nv50_mstm_register_connector()
      * update-initramfs not adding i915 GuC firmware for Kaby Lake, firmware fails
        to load (LP: #1728238)
        - Revert "UBUNTU: SAUCE: (no-up) i915: Remove MODULE_FIRMWARE statements for
          unreleased firmware"
      * Battery drains when laptop is off  (shutdown) (LP: #1745646)
        - PCI / PM: Check device_may_wakeup() in pci_enable_wake()
      * Dell Latitude 5490/5590 BIOS update 1.1.9 causes black screen at boot
        (LP: #1764194)
        - drm/i915/bios: filter out invalid DDC pins from VBT child devices
      * Intel 9462 A370:42A4 doesn't work (LP: #1748853)
        - iwlwifi: add shared clock PHY config flag for some devices
        - iwlwifi: add a bunch of new 9000 PCI IDs
      * Fix an issue that some PCI devices get incorrectly suspended (LP: #1764684)
        - PCI / PM: Always check PME wakeup capability for runtime wakeup support
      * [SRU][Bionic/Artful] fix false positives in W+X checking (LP: #1769696)
        - init: fix false positives in W+X checking
      * Bionic update to v4.15.18 stable release (LP: #1769723)
        - netfilter: ipset: Missing nfnl_lock()/nfnl_unlock() is added to
          ip_set_net_exit()
        - cdc_ether: flag the Cinterion AHS8 modem by gemalto as WWAN
        - rds: MP-RDS may use an invalid c_path
        - slip: Check if rstate is initialized before uncompressing
        - vhost: fix vhost_vq_access_ok() log check
        - l2tp: fix races in tunnel creation
        - l2tp: fix race in duplicate tunnel detection
        - ip_gre: clear feature flags when incompatible o_flags are set
        - vhost: Fix vhost_copy_to_user()
        - lan78xx: Correctly indicate invalid OTP
        - media: v4l2-compat-ioctl32: don't oops on overlay
        - media: v4l: vsp1: Fix header display list status check in continuous mode
        - ipmi: Fix some error cleanup issues
        - parisc: Fix out of array access in match_pci_device()
        - parisc: Fix HPMC handler by increasing size to multiple of 16 bytes
        - Drivers: hv: vmbus: do not mark HV_PCIE as perf_device
        - PCI: hv: Serialize the present and eject work items
        - PCI: hv: Fix 2 hang issues in hv_compose_msi_msg()
        - KVM: PPC: Book3S HV: trace_tlbie must not be called in realmode
        - perf/core: Fix use-after-free in uprobe_perf_close()
        - x86/mce/AMD: Get address from already initialized block
        - hwmon: (ina2xx) Fix access to uninitialized mutex
        - ath9k: Protect queue draining by rcu_read_lock()
        - x86/apic: Fix signedness bug in APIC ID validity checks
        - f2fs: fix heap mode to reset it back
        - block: Change a rcu_read_{lock,unlock}_sched() pair into
          rcu_read_{lock,unlock}()
        - nvme: Skip checking heads without namespaces
        - lib: fix stall in __bitmap_parselist()
        - blk-mq: order getting budget and driver tag
        - blk-mq: don't keep offline CPUs mapped to hctx 0
        - ovl: fix lookup with middle layer opaque dir and absolute path redirects
        - xen: xenbus_dev_frontend: Fix XS_TRANSACTION_END handling
        - hugetlbfs: fix bug in pgoff overflow checking
        - nfsd: fix incorrect umasks
        - scsi: qla2xxx: Fix small memory leak in qla2x00_probe_one on probe failure
        - block/loop: fix deadlock after loop_set_status
        - nfit: fix region registration vs block-data-window ranges
        - s390/qdio: don't retry EQBS after CCQ 96
        - s390/qdio: don't merge ERROR output buffers
        - s390/ipl: ensure loadparm valid flag is set
        - get_user_pages_fast(): return -EFAULT on access_ok failure
        - mm/gup_benchmark: handle gup failures
        - getname_kernel() needs to make sure that ->name != ->iname in long case
        - Bluetooth: Fix connection if directed advertising and privacy is used
        - Bluetooth: hci_bcm: Treat Interrupt ACPI resources as always being active-
          low
        - rtl8187: Fix NULL pointer dereference in priv->conf_mutex
        - ovl: set lower layer st_dev only if setting lower st_ino
        - Linux 4.15.18
      * Kernel bug when unplugging Thunderbolt 3 cable, leaves xHCI host controller
        dead (LP: #1768852)
        - xhci: Fix Kernel oops in xhci dbgtty
      * Incorrect blacklist of bcm2835_wdt (LP: #1766052)
        - [Packaging] Fix missing watchdog for Raspberry Pi
      * CVE-2018-8087
        - mac80211_hwsim: fix possible memory leak in hwsim_new_radio_nl()
      * Integrated Webcam Realtek Integrated_Webcam_HD (0bda:58f4) not working in
        DELL XPS 13 9370 with firmware 1.50 (LP: #1763748)
        - SAUCE: media: uvcvideo: Support realtek's UVC 1.5 device
      * [ALSA] [PATCH] Clevo P950ER ALC1220 Fixup (LP: #1769721)
        - SAUCE: ALSA: hda/realtek - Clevo P950ER ALC1220 Fixup
      * Bionic: Intermittently sent to Emergency Mode on boot with unhandled kernel
        NULL pointer dereference at  0000000000000980 (LP: #1768292)
        - thunderbolt: Prevent crash when ICM firmware is not running
      * linux-snapdragon: reduce EPROBEDEFER noise during boot (LP: #1768761)
        - [Config] snapdragon: DRM_I2C_ADV7511=y
      * regression Aquantia Corp. AQC107 4.15.0-13-generic -> 4.15.0-20-generic ?
        (LP: #1767088)
        - net: aquantia: Regression on reset with 1.x firmware
        - net: aquantia: oops when shutdown on already stopped device
      * e1000e msix interrupts broken in linux-image-4.15.0-15-generic
        (LP: #1764892)
        - e1000e: Remove Other from EIAC
      * Acer Swift sf314-52 power button not managed  (LP: #1766054)
        - SAUCE: platform/x86: acer-wmi: add another KEY_POWER keycode
      * set PINCFG_HEADSET_MIC to parse_flags for Dell precision 3630 (LP: #1766398)
        - ALSA: hda/realtek - set PINCFG_HEADSET_MIC to parse_flags
      * Change the location for one of two front mics on a lenovo thinkcentre
        machine (LP: #1766477)
        - ALSA: hda/realtek - adjust the location of one mic
      * SRU: bionic: apply 50 ZFS upstream bugfixes (LP: #1764690)
        - SAUCE: (noup) Update zfs to 0.7.5-1ubuntu15 (LP: #1764690)
      * [8086:3e92] display becomes blank after S3 (LP: #1763271)
        - drm/i915/edp: Do not do link training fallback or prune modes on EDP
    
     -- Khalid Elmously <email address hidden>  Thu, 24 May 2018 11:33:07 -0400
  • linux-gcp (4.15.0-1008.8) bionic; urgency=medium
    
      [ Ubuntu: 4.15.0-22.24 ]
    
      * CVE-2018-3639 (powerpc)
        - powerpc/64s: Add support for a store forwarding barrier at kernel entry/exit
        - stf-barrier: set eieio instruction bit 6 for future optimisations
      * CVE-2018-3639 (x86)
        - x86/nospec: Simplify alternative_msr_write()
        - x86/bugs: Concentrate bug detection into a separate function
        - x86/bugs: Concentrate bug reporting into a separate function
        - x86/bugs: Read SPEC_CTRL MSR during boot and re-use reserved bits
        - x86/bugs, KVM: Support the combination of guest and host IBRS
        - x86/bugs: Expose /sys/../spec_store_bypass
        - x86/cpufeatures: Add X86_FEATURE_RDS
        - x86/bugs: Provide boot parameters for the spec_store_bypass_disable
          mitigation
        - x86/bugs/intel: Set proper CPU features and setup RDS
        - x86/bugs: Whitelist allowed SPEC_CTRL MSR values
        - x86/bugs/AMD: Add support to disable RDS on Fam[15,16,17]h if requested
        - x86/KVM/VMX: Expose SPEC_CTRL Bit(2) to the guest
        - x86/speculation: Create spec-ctrl.h to avoid include hell
        - prctl: Add speculation control prctls
        - x86/process: Allow runtime control of Speculative Store Bypass
        - x86/speculation: Add prctl for Speculative Store Bypass mitigation
        - nospec: Allow getting/setting on non-current task
        - proc: Provide details on speculation flaw mitigations
        - seccomp: Enable speculation flaw mitigations
        - x86/bugs: Make boot modes __ro_after_init
        - prctl: Add force disable speculation
        - seccomp: Use PR_SPEC_FORCE_DISABLE
        - seccomp: Add filter flag to opt-out of SSB mitigation
        - seccomp: Move speculation migitation control to arch code
        - x86/speculation: Make "seccomp" the default mode for Speculative Store
          Bypass
        - x86/bugs: Rename _RDS to _SSBD
        - proc: Use underscores for SSBD in 'status'
        - Documentation/spec_ctrl: Do some minor cleanups
        - x86/bugs: Fix __ssb_select_mitigation() return type
        - x86/bugs: Make cpu_show_common() static
      * LSM Stacking prctl values should be redefined as to not collide with
        upstream prctls (LP: #1769263) // CVE-2018-3639
        - SAUCE: LSM stacking: adjust prctl values
    
    linux-gcp (4.15.0-1007.7) bionic; urgency=medium
    
      * linux-gcp: 4.15.0-1007.7 -proposed tracker (LP: #1767400)
    
      * linux-image-4.15.0-20-generic install after upgrade from xenial breaks
        (LP: #1767133)
        - Packaging: Depends on linux-base that provides the necessary tools
    
      [ Ubuntu: 4.15.0-21.22 ]
    
      * linux: 4.15.0-21.22 -proposed tracker (LP: #1767397)
      * initramfs-tools exception during pm.DoInstall with  do-release-upgrade from
        16.04 to 18.04  (LP: #1766727)
        - Add linux-image-* Breaks on s390-tools (<< 2.3.0-0ubuntu3)
      * linux-image-4.15.0-20-generic install after upgrade from xenial breaks
        (LP: #1767133)
        - Packaging: Depends on linux-base that provides the necessary tools
      * linux-image packages need to Breaks flash-kernel << 3.90ubuntu2
        (LP: #1766629)
        - linux-image-* breaks on flash-kernel (<< 3.90ubuntu2)
    
     -- Stefan Bader <email address hidden>  Thu, 17 May 2018 09:36:23 +0200
  • linux-gcp (4.15.0-1007.7) bionic; urgency=medium
    
      * linux-gcp: 4.15.0-1007.7 -proposed tracker (LP: #1767400)
    
      * linux-image-4.15.0-20-generic install after upgrade from xenial breaks
        (LP: #1767133)
        - Packaging: Depends on linux-base that provides the necessary tools
    
      [ Ubuntu: 4.15.0-21.22 ]
    
      * linux: 4.15.0-21.22 -proposed tracker (LP: #1767397)
      * initramfs-tools exception during pm.DoInstall with  do-release-upgrade from
        16.04 to 18.04  (LP: #1766727)
        - Add linux-image-* Breaks on s390-tools (<< 2.3.0-0ubuntu3)
      * linux-image-4.15.0-20-generic install after upgrade from xenial breaks
        (LP: #1767133)
        - Packaging: Depends on linux-base that provides the necessary tools
      * linux-image packages need to Breaks flash-kernel << 3.90ubuntu2
        (LP: #1766629)
        - linux-image-* breaks on flash-kernel (<< 3.90ubuntu2)
    
     -- Thadeu Lima de Souza Cascardo <email address hidden>  Tue, 08 May 2018 11:27:48 -0300
  • linux-gcp (4.15.0-1006.6) bionic; urgency=medium
    
      * linux-gcp: 4.15.0-1006.6 -proposed tracker (LP: #1766471)
    
      [ Ubuntu: 4.15.0-20.21 ]
    
      * linux: 4.15.0-20.21 -proposed tracker (LP: #1766452)
      * package shim-signed (not installed) failed to install/upgrade: installed
        shim-signed package post-installation script subprocess returned error exit
        status 5 (LP: #1766391)
        - [Packaging] fix invocation of header postinst hooks
    
     -- Stefan Bader <email address hidden>  Tue, 24 Apr 2018 09:12:25 +0200