Commit 
a894cf6c5a82 ("mtd: nand: mxc: switch to mtd_ooblayout_ops")
introduced a bug in the OOB layout description. Even if the driver claims
that 3 ECC bytes are reserved to protect 512 bytes of data, it's actually
5 ECC bytes to protect 512+6 bytes of data (some OOB bytes are also
protected using extra ECC bytes).
Fix the mxc_v1_ooblayout_{free,ecc}() functions to reflect this behavior.
Signed-off-by: Boris Brezillon <boris.brezillon@free-electrons.com>
Fixes: a894cf6c5a82 ("mtd: nand: mxc: switch to mtd_ooblayout_ops")
Cc: <stable@vger.kernel.org>
Signed-off-by: Boris Brezillon <boris.brezillon@free-electrons.com>
        }
 }
 
+#define MXC_V1_ECCBYTES                5
+
 static int mxc_v1_ooblayout_ecc(struct mtd_info *mtd, int section,
                                struct mtd_oob_region *oobregion)
 {
                return -ERANGE;
 
        oobregion->offset = (section * 16) + 6;
-       oobregion->length = nand_chip->ecc.bytes;
+       oobregion->length = MXC_V1_ECCBYTES;
 
        return 0;
 }
                        oobregion->length = 4;
                }
        } else {
-               oobregion->offset = ((section - 1) * 16) +
-                                   nand_chip->ecc.bytes + 6;
+               oobregion->offset = ((section - 1) * 16) + MXC_V1_ECCBYTES + 6;
                if (section < nand_chip->ecc.steps)
                        oobregion->length = (section * 16) + 6 -
                                            oobregion->offset;