Commit Graph

1483416 Commits

Author SHA1 Message Date
Linus Torvalds
156fa7417f x86 fixes:
- Reject the loading of a potentially problematic microcode version
    on Intel Granite Rapids systems (Chang S. Bae)
 
  - On FRED, reconstruct the proper #GP context for rejected INT
    instructions, to fix a signal ABI regression (Matthew Schwartz)
 
  - Add a test for this signal ABI regression the x86
    self-test suite (Matthew Schwartz)
 
  - Don't emit the new and not yet properly supported EGPR instructions
    (%r16-%r31) on CONFIG_X86_NATIVE_CPU=y builds (Chang S. Bae)
 
 Signed-off-by: Ingo Molnar <mingo@kernel.org>
 -----BEGIN PGP SIGNATURE-----
 
 iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqvrhgRHG1pbmdvQGtl
 cm5lbC5vcmcACgkQEnMQ0APhK1inbQ/9G4Q0h9esQ945n0uYRYvVLuj2P8DvE3XN
 9d5IJ5pIYdhJCvlv8yXyv1u3sq59QYNmUgpBMghHJonhqobtnchvBSiznoAMgi8L
 yjRlcaFBPX9qjFQV1W9WJQuUHhW/12QFy9Bo9n1uXEv6pYspYVDwodCaS+rEvkTF
 0wK3TjETv90TravGjFscYTt2VLAiy+cd/FxkUA0sBaMLjhFpUyAPHGJe/vcf8vT3
 rEXkY8EeSjv5F6eKMTDVacrSZu2c9wco1bJIsSFEcxZGFzhDbuCOGiDCkwmB3uuD
 ReKbEUC0KmF8qd4Ubf0dMGpbHT9LDu9Ggex619cHFOHMupPubP+yym7aCpm3v7Sb
 gZe6eV6VrSREJ+oBVKsqMrWXsg1YDj6uJhC/5K3S78xBeRq64kKsmBbC93Zp20TC
 QpSAxKIFqp8C+tfKzpBmcSbcipRUfATJxLjp94QaQDp467jjJCvpDJdc12mV7WR9
 0gMtFjxUaIe8BGX7s2PuWPgZ8+CIH0hZQuttxUU4QWvM2RGU+QrDaMwTeAY7wme4
 xomc0wpXQb5enrjmFu8betlD0xfjgt7k6eW0njezRpWSk3wyHDd5w/6Vfn8pA6Fx
 AQV4UuszXzQmG+W2pdIjLhnjmsjEeWMpmwgzn0rkcqujWHeh8XOSvQIjULFrFtFv
 srSbum6vEfk=
 =MP1H
 -----END PGP SIGNATURE-----

Merge tag 'x86-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip

Pull x86 fixes from Ingo Molnar:

 - Reject the loading of a potentially problematic microcode version
   on Intel Granite Rapids systems (Chang S. Bae)

 - On FRED, reconstruct the proper #GP context for rejected INT
   instructions, to fix a signal ABI regression (Matthew Schwartz)

 - Add a test for this signal ABI regression the x86
   self-test suite (Matthew Schwartz)

 - Don't emit the new and not yet properly supported EGPR instructions
   (%r16-%r31) on CONFIG_X86_NATIVE_CPU=y builds (Chang S. Bae)

* tag 'x86-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  x86/build/64: Prevent native builds from generating EGPR use
  selftests/x86: Check signal state for rejected software interrupts
  x86/fred: Reconstruct the #GP context for rejected INT instructions
  x86/microcode/intel: Reject problematic loading on Granite Rapids systems
2026-09-20 09:49:10 -07:00
Linus Torvalds
0a15ba6b0c Timer race fixes:
- Fix timer signal <-> exec() race, to prevent UAF (Thomas Gleixner)
 
  - Clean up POSIX CPU timers right after de_thread(), to prevent UAF
    (Hyunwoo Kim)
 
  - Fix POSIX CPU timers race between expiry and timer_settime(),
    to prevent UAF (Thomas Gleixner)
 
 Signed-off-by: Ingo Molnar <mingo@kernel.org>
 -----BEGIN PGP SIGNATURE-----
 
 iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqvrMYRHG1pbmdvQGtl
 cm5lbC5vcmcACgkQEnMQ0APhK1gqUQ/+NkruN984bFynF/eZ0/2DFv91AAUP8zgH
 /S3PBlwuSbYFN9JVhngDMwxQkamE56weJbFc+0QuvVT5UVw/vX9BS4QOvvzN+f8D
 FEN3UqD0d1B8OwlPNTw0sFPwJDdPctTinfKOhNjNQe6RLFsNARvGyaKDIDroWTfV
 dxuJ/7Ecs+5m1bmGJnPEC+IH/OnV9BEEl1NdZb+INKpBlui9LCsw4rRIj/8dPK/H
 UNhvXpykKrJCDftbCzAFSNryuzcJgq4kHtMbsqiUL6y50AB69eHGi/Y0xYBAEr1h
 NiDPq2PAMmH1NCCMsTtqbJZMqgCr+7DSZiCFn7bZPwg0V5tV4PFZD484q0sCbiej
 Fwg+arHd0icnceIcWMsBWPUVOSLxZaWdp9a2Tj3Ill06//b5bEDBJBbpecS+so3t
 8W6IvdoCYm7sz50mohnjOdx7biHPu0yhwgj+EoAV3nZKoALQAAcI7+HJzSWpGnJi
 HIO0zylRAZCjk9H3QNWO+LdWgifc8DysAZOWpmbuwGgp8q483IDRDtme/kMt3+D1
 1qTHa1TD/tPo8UmmgyVJQ7e1hCxBkGuuBBu5Y3/qkUEOQM6B/H2Ji7stxsLpW3JL
 HLzC3kL2SBBVBO2ljqiH5IhVAL10Qm5vPxaCOjExdBt1vjMxN1DowZqD4rT/tw58
 ArpD4zmr8VQ=
 =KhWJ
 -----END PGP SIGNATURE-----

Merge tag 'timers-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip

Pull timer race fixes from Ingo Molnar:

 - Fix timer signal <-> exec() race, to prevent UAF (Thomas Gleixner)

 - Clean up POSIX CPU timers right after de_thread(), to prevent UAF
   (Hyunwoo Kim)

 - Fix POSIX CPU timers race between expiry and timer_settime(),
   to prevent UAF (Thomas Gleixner)

* tag 'timers-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list
  exec: Cleanup POSIX timers right after de_thread()
  signal: Prevent exec() race
2026-09-20 09:41:00 -07:00
Linus Torvalds
fecbe78ac0 Scheduler fix:
- Avoid false positive migration warning for proxy donors
    (Andrea Righi)
 
 Signed-off-by: Ingo Molnar <mingo@kernel.org>
 -----BEGIN PGP SIGNATURE-----
 
 iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqvqssRHG1pbmdvQGtl
 cm5lbC5vcmcACgkQEnMQ0APhK1gPzBAAhE9hcpkBV6vNW9xzBDKdGPxRjch2vcfu
 lQbx7da1yC2rHU7RDlcdfEgkhAqTRwEAXKz26zth3sDHLk43tusuNtqG3swELhNW
 YAGbHjdn87snQlmP8AOK4EaT3uE5NjWqRSIJWMK+AhWSwqO/zzK91T6yZyQY0fM4
 3Edp8CFo3IeyOzCR96vsob2x1fFQhuR//5fWul3uuB0EZ8VA5FhH3ene6VCm7P/1
 dauxX0rMTb2730qNXA8cHROZq+bwhqTZOUaoOZ33WxnRPkvY9mV/hZsN8JnJuzBE
 ogzyyorcl8dFH8qOapos9Cp3tQj9GkTX7mXWDbuUflt/8uOXtQMf75kFGBVI5NUw
 2xNfgubTYGo6Qc1C+wyOhGYJ6T5Al+083pV/vPc4y7Z1i7RgZ94QypMuZuaR/RqS
 z+RQcdNQlXiRIAIILGJqq1xdbaCJvbVx3tiFZkhPse6ioOF6UNGbQiNExAq3v5BU
 ocvhBuf9p/uvRmfs+ZtQNqAAjZUL7tQPvdFAsjxKjuI2Z5YGPROy1L9NdYKfzryM
 yWOEkV2mdn97CwzDS+auC0HmPkGqf8we2VI5Ub4R35UPqDcV6vc5BAnwzAbuxAmc
 K7mQOMDEaRkbVQ0MoSMdidIXLL0AcN+BROBUtHv8kqJur6nADE3K3HZNdhr2ViLN
 eisNI6m8pLk=
 =BEte
 -----END PGP SIGNATURE-----

Merge tag 'sched-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip

Pull scheduler fix from Ingo Molnar:

 - Avoid false positive migration warning for proxy donors
   (Andrea Righi)

* tag 'sched-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  sched/core: Avoid false migration warning for proxy donors
2026-09-20 09:37:27 -07:00
Linus Torvalds
abb91eed94 Perf events fixes:
- Fix crash when probing CS CALL instructions (Jinke Han)
 
  - Fix NULL pointer crash during module unload (Vinay Belgaumkar)
 
 Signed-off-by: Ingo Molnar <mingo@kernel.org>
 -----BEGIN PGP SIGNATURE-----
 
 iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqvqiURHG1pbmdvQGtl
 cm5lbC5vcmcACgkQEnMQ0APhK1hiohAAjcvOY7M998pX1tmo1Egw9kAuI0odtNOX
 weQ4Wq7K3X+tg+q1wVUmE/N/y/WLYWNatjwvjc8TClYdQEiaqBMH4TSLAuY3TOxa
 TxwdTC20uSN4EPZ0iRhKzm3biPzzzRq4M9hhV+WfGcK7ieXRn4Q7d9S3DDe5oEfG
 lI4l/RefIBiINVPC7dNM7xpS/7XBEPnzNeshOMwp6ZsPziZJizgC8C7RhQFAPszo
 Ho36KKFQqMNouCSybQl1GxLyPw+oGtneWESHXrF6Mhp+bcx40fMtJxKNyVLsVWuM
 wo0Ry843pCbDofOIqg7m0AufWUhz7B4MttTXXrU2/BYMHEbxlgms1AO7lnSGzPmn
 vP0JHZnT3y34P5uvGaVho7t9QKKbuY47cKNmsiiLuXiBQQuKnvDmDln1Mu1KS3fg
 a1LI8kv043iLqAjsIWMVtKlRGUX36f4NXUWrxvO/tmup3ocJhG1oYmEe/RaFddVX
 5qRbHn7Z1w8jAWldODYSrXkpMRgMtClQuqHdjxZQt5DPZSORzoFxTvSfJLdUUtVx
 CUiT34zcLPHfvGD+ctHe5kVesgDHCxp/z1tKrJBunB+XZVl6rKHycfiGjaUXQRcR
 NUp6iFlfay8b79EkMsLC8p6uAmzX2q+gEwNVy8eevBSXdsYqcY5islj3ob7sBHsH
 vk4gDJikpE0=
 =onkS
 -----END PGP SIGNATURE-----

Merge tag 'perf-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip

Pull perf events fixes from Ingo Molnar:

 - Fix crash when probing CS CALL instructions (Jinke Han)

 - Fix NULL pointer crash during module unload (Vinay Belgaumkar)

* tag 'perf-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  perf: Fix null pointer access in is_include_guest_event()
  x86/kprobes: Fix crash when probing CS CALL instructions
2026-09-20 09:26:22 -07:00
Linus Torvalds
2f7ff5f547 - Fix objtool build error on systems where libopcodes is
present, but development headers (binutils-dev) are not
    (Ulises Mendez Martinez)
 
 Signed-off-by: Ingo Molnar <mingo@kernel.org>
 -----BEGIN PGP SIGNATURE-----
 
 iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqvqSARHG1pbmdvQGtl
 cm5lbC5vcmcACgkQEnMQ0APhK1iBWQ/9HTpCn/GSapwpTLUAXh/d/7VWSTV/xMRS
 b/cqx+jFDFeZDU55VbX+bMgKQyW0jNSUPjvVp0ZfjUf0W0LOXL/EnAemZ8VqBqAj
 IMIyd+0MjCeUOCVanRiITre65BPuF+g3EbxWypFDiLmb4ziA5YksPknTWYrIVbDP
 IMks30B8kJfzC5Qh0jjpSRDSypTvuEAKppbyf3pPmHfKLSbwtKOQzeoFUlLtWfs4
 diBm9BVIjosmIr5dxMyixa8+5BTsPs4ojwa4US3H+RzxdXe+2v31Ac2nK/zvCRst
 Fr8gefaLhVrnfkJeXU0Xn/rDMYOzayb1JW4jWjJ40I6U20ptdrMQ3aSJqjNrrwkQ
 2vikInQX3NKV2ASiTppLDhsq7MFt4AeRYFwj8xmErm5uhoSEKAEPG1QZWS98QkAo
 CXQL3PITL5kS0q5wGkkYXNi3TbpKvWy8kPoIRMHoKFUkBHJRssSg8tb17D5Jg0yd
 QvsjocvMSf865swQ6p1yj+7+Zd+nGM2JGkIcp9OBPTAzZej4bXmpPwMKDeRv6pgD
 GNgKJ2oEhvXWCgokxK9ezgk8rYsH/1Vo/+JyBf4/tcKL9ixfnBTgLNZ80J8VFDn2
 5axUt4EO+FZKzLB6UaENhTo813PhGOM/rChKmJ1L4GWi0RywoX+seH4b+FtQk87f
 VPvApwwiDHQ=
 =vTNY
 -----END PGP SIGNATURE-----

Merge tag 'objtool-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip

Pull objtool fix from Ingo Molnar:

 - Fix objtool build error on systems where libopcodes is
   present, but development headers (binutils-dev) are not
   (Ulises Mendez Martinez)

* tag 'objtool-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  objtool: Validate disassembler headers in libopcodes probe
2026-09-20 08:41:19 -07:00
Linus Torvalds
bdab18633a - Also allocate a default private futex hash on vfork()
as well, to avoid races with (private) futex waiters
    (Peter Zijlstra)
 
 Signed-off-by: Ingo Molnar <mingo@kernel.org>
 -----BEGIN PGP SIGNATURE-----
 
 iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqvp20RHG1pbmdvQGtl
 cm5lbC5vcmcACgkQEnMQ0APhK1giDg//VpFKPXgma7fW5E+T0kjWHWD7FS1vYyJ4
 nMunKME8PAV0A4S7946iUAWHjViVfksTmfvcXepSFCKZKLf55g8s2aZ1VoigMtYX
 bQxNrnOidebSg9npLs9NV4sjvvNy+k03gcNN+OK+ZRfYCVRqbLgfCm5RJbaId5y4
 +EuizVmtJuNav6HwAEIbU4LXGIdwSL9Pn8Zitkz/H7g0ZEkv+VA4h6NttvKDNfV7
 OltcUFejtU7Z1lItfH+PP9pMcjPA6OPI2h7LLmUcZGUhhQQtW2Gb1fffz45PiH8T
 FB7PdFt22TLG5c6hLB7zbrFFillWKn3l3Ihi/IxqVmMulhk6RVTPdCVJcj1cGZxF
 9NXZ+L81poKwEETaIk52v5jm9qNF+kHbXJuCjPbmEdPxtxfv+Ma4zXom/xKkuXpx
 qf01GXxelUPdCAl0cT0pzRvbEfHNIOsE2Id7f+59jB+L8ZbYEch04cIVRqCQcOgi
 9B+lXj36fkFBV6wmuP5SWShWsgMsMpgSzOz5mUdWjY3Ocn9QuzDxPkk50Cm7uL1i
 q/HpGv3T849HFnCH7+mi8wSiX33La+N297+AkGO7U7h5QFldPokvbAijwfmF+1Nw
 CebsAfsgJsN1GZacDTH0jmRxh4I0Wa32yiCAldeGS2w9EMEAFbA87iwsOgjwHiQl
 JOv/s06Pg7o=
 =qQHe
 -----END PGP SIGNATURE-----

Merge tag 'locking-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip

Pull futex fix from Ingo Molnar:

 - Also allocate a default private futex hash on vfork() as well, to
   avoid races with (private) futex waiters (Peter Zijlstra)

* tag 'locking-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  futex: Also allocate private hash on vfork()
2026-09-20 08:15:23 -07:00
Linus Torvalds
5bf70485f9 spi: Fixes for v7.3
A few driver specific fixes, none of them particularly severe or
 unusual.
 -----BEGIN PGP SIGNATURE-----
 
 iQEzBAABCgAdFiEEreZoqmdXGLWf4p/qJNaLcl1Uh9AFAmqvmVMACgkQJNaLcl1U
 h9AOdwf/aRa54oHd6iLCPXNAbZLDie0pnJa/Q/5sjpJoVY9ofKc2XM9djmy60YdF
 /VGIphT8gr6at6fLZHEBbLanu2MQC2vxW9zDh5n+Xe8HUS3sdrwtBJPSv74Mcfrf
 OIv6nFrVsbo1IMF7x4ncYOhOBGKyOSqhsVdt+k6jl1wuTDJBHyFs7sdL1DGRCRu/
 ba4n2W+kSxVeFx3ACFyDJ8l8vLqtyotFKkpmslrPmT0yHFwOr8SOMbyQ5MPxITpx
 gqgLikR3OW5alOLxy1U2nWCdjNsc8UWBhx1sCnByYrUO3VmRIEx4j1l2wSVX0J7E
 Ck7/pSpg1NGkxVYSLCTBufqq8kgPTQ==
 =iy0J
 -----END PGP SIGNATURE-----

Merge tag 'spi-fix-v7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/spi

Pull spi fixes from Mark Brown:
 "A few driver specific fixes, none of them particularly severe or
  unusual"

* tag 'spi-fix-v7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/spi:
  spi: fsl-qspi: Reprogram the clock rate when the operation frequency changes
  spi: spi-zynqmp-gqspi: stop the controller on shutdown
  spi: virtio: Use the per-transfer bits per word
  spi: spi-qpic-snand: avoid writing QPIC_EBI2_ECC_BUF_CFG register
2026-09-20 08:08:54 -07:00
Linus Torvalds
aa211c7a58 i2c-fixes for v7.3-rc4
Fixes mainly for cleanup and error handling, a good part of them
 around DMA resource management.
 
 - at91: ensure DMA channels are released on all exit paths
 
 - imx: fix autosuspend cleanup on remove
 
 - qcom-cci: fix device node reference leak
 
 - atr, imx, qcom-geni: set adapter slot to NULL on registration
   failure
 -----BEGIN PGP SIGNATURE-----
 
 iHUEABYKAB0WIQScDfrjQa34uOld1VLaeAVmJtMtbgUCaq+VLAAKCRDaeAVmJtMt
 bqmsAP9umA0ew1WQkQGTlTJLfbQdhwy8IDS7tMRAlgL7vsUxOQEApvFqr6Xtq2j7
 HiSP35cHybZlA7P2T70A+MVniCJDRQ4=
 =Sn1c
 -----END PGP SIGNATURE-----

Merge tag 'i2c-fixes-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/andi.shyti/linux

Pull i2c fixes from Andi Shyti:
 "Fixes mainly for cleanup and error handling, a good part of them
  around DMA resource management:

   - at91: ensure DMA channels are released on all exit paths

   - imx: fix autosuspend cleanup on remove

   - qcom-cci: fix device node reference leak

   - atr, imx, qcom-geni: set adapter slot to NULL on registration
     failure"

* tag 'i2c-fixes-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/andi.shyti/linux:
  i2c: qcom-cci: fix device_node refcount leak in cci_probe()/cci_remove()
  i2c: qcom-geni: release DMA channels on probe error
  i2c: imx: release DMA channels on probe error
  i2c: at91: release DMA channels on remove and probe error
  i2c: atr: fix dangling adapter pointer on add failure
  i2c: imx: disable autosuspend on remove
2026-09-20 07:57:47 -07:00
Linus Torvalds
b12dd0fa48 Input updates for v7.3-rc3
- Fixes for evdev and input compat handling to zero-initialize on-stack
   absinfo and force-feedback effect structures before partial or compat
   copies from userspace, preventing kernel stack memory disclosure
 
 - Fixes for the Synaptics RMI4 driver to prevent an out-of-bounds read
   when writing multi-chunk blocks over SMBus and to avoid a NULL pointer
   dereference during suspend/resume when the RMI device is unbound
 
 - Fixes for the soc_button_array driver to propagate -EPROBE_DEFER on
   non-Bay Trail/Cherry Trail platforms (fixing broken power and volume
   buttons on the Microsoft Surface Pro 11) and to validate the ACPI
   package element count before dereferencing
 
 - A fix for the adp5588-keys driver to cache the initial GPIO hardware
   state before registering the gpiochip so pre-configured pin states are
   not clobbered by GPIO hogs during registration
 
 - A fix for the cyttsp5 touchscreen driver to clamp the device-supplied
   HID report size before copying into the response buffer, preventing a
   buffer overflow
 
 - A fix for the HP SDC serio driver to use timer_shutdown_sync() on
   module exit so the periodic kicker timer cannot rearm itself during
   teardown
 
 - A fix for the eeti_ts touchscreen driver to export its OF module alias
   so the module autoloads on Device Tree platforms
 
 - Updates to the xpad joystick driver adding support for the Victrix Pro
   BFG controller and Azeron devices, and fixing the device type
   classification for the PDP Marvel Xbox 360 controller
 
 - Quirks for the i8042 and atkbd drivers to keep the built-in keyboards
   functional on the Acer Aspire Go 15 AG15-42P and Xiaomi Redmi Book Pro
   16 2026
 
 - A quirk for the Synaptics PS/2 touchpad driver disabling SMBus
   InterTouch on the Lenovo ThinkPad T440p (board ID 2722) so the
   touchpad and TrackPoint respond immediately at boot
 
 - Other minor updates and documentation fixes, including reading the
   "ti,poll-period" property as u32 in tsc2007, adding the mt6572
   compatible to the MediaTek keypad Device Tree binding, fixing an
   attribute name typo in the trackpoint sysfs ABI documentation, and
   documenting that no new LED codes should be added to the input
   subsystem.
 -----BEGIN PGP SIGNATURE-----
 
 iHUEABYKAB0WIQST2eWILY88ieB2DOtAj56VGEWXnAUCaq9j+gAKCRBAj56VGEWX
 nJ5KAQDnTOivIghgIGnlKTIYLSV4cJ0fWJh7J1/ubx9soK+9RwD/bDUdyryAaSTr
 x95U7/fEvq/lXBFyK2LXyahuTC6vNQY=
 =Vsfi
 -----END PGP SIGNATURE-----

Merge tag 'input-for-v7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/dtor/input

Pull input fixes from Dmitry Torokhov:

 - Fixes for evdev and input compat handling to zero-initialize on-stack
   absinfo and force-feedback effect structures before partial or compat
   copies from userspace, preventing kernel stack memory disclosure

 - Fixes for the Synaptics RMI4 driver to prevent an out-of-bounds read
   when writing multi-chunk blocks over SMBus and to avoid a NULL
   pointer dereference during suspend/resume when the RMI device is
   unbound

 - Fixes for the soc_button_array driver to propagate -EPROBE_DEFER on
   non-Bay Trail/Cherry Trail platforms (fixing broken power and volume
   buttons on the Microsoft Surface Pro 11) and to validate the ACPI
   package element count before dereferencing

 - A fix for the adp5588-keys driver to cache the initial GPIO hardware
   state before registering the gpiochip so pre-configured pin states
   are not clobbered by GPIO hogs during registration

 - A fix for the cyttsp5 touchscreen driver to clamp the device-supplied
   HID report size before copying into the response buffer, preventing a
   buffer overflow

 - A fix for the HP SDC serio driver to use timer_shutdown_sync() on
   module exit so the periodic kicker timer cannot rearm itself during
   teardown

 - A fix for the eeti_ts touchscreen driver to export its OF module
   alias so the module autoloads on Device Tree platforms

 - Updates to the xpad joystick driver adding support for the Victrix
   Pro BFG controller and Azeron devices, and fixing the device type
   classification for the PDP Marvel Xbox 360 controller

 - Quirks for the i8042 and atkbd drivers to keep the built-in keyboards
   functional on the Acer Aspire Go 15 AG15-42P and Xiaomi Redmi Book
   Pro 16 2026

 - A quirk for the Synaptics PS/2 touchpad driver disabling SMBus
   InterTouch on the Lenovo ThinkPad T440p (board ID 2722) so the
   touchpad and TrackPoint respond immediately at boot

 - Other minor updates and documentation fixes, including reading the
   "ti,poll-period" property as u32 in tsc2007, adding the mt6572
   compatible to the MediaTek keypad Device Tree binding, fixing an
   attribute name typo in the trackpoint sysfs ABI documentation, and
   documenting that no new LED codes should be added to the input
   subsystem

* tag 'input-for-v7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/dtor/input:
  Input: hp_sdc - shut down kicker timer on module exit
  Input: xpad - add support for Victrix Pro BFG Controller
  Input: tsc2007 - read "ti,poll-period" as u32
  Input: trackpoint - fix the inertia attribute name in the ABI document
  Input: eeti_ts - publish the OF module alias
  Input: xpad - add support for Azeron devices
  Input: xpad - fix PDP Marvel Xbox 360 controller
  Input: document that no new LED codes should be added
  Input: soc_button_array - check btns_desc->package.count
  Input: soc_button_array - fix MS Surface Pro 11 probe failure
  Input: i8042 - add quirk for Acer Aspire Go 15 AG15-42P
  Input: synaptics - disable InterTouch on ThinkPad T440p (board id 2722)
  Input: cyttsp5 - clamp the HID report size before memcpy
  Input: zero ff_effect before compat copy in input_ff_effect_from_user
  Input: evdev - zero absinfo before partial copy in EVIOCSABS
  Input: synaptics-rmi4 - fix GPF in suspend and resume when unbound
  Input: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block()
  Input: atkbd - skip deactivate for Xiaomi Redmi Book Pro 16 2026
  dt-bindings: input: mediatek,mt6779-keypad: add mt6572
  Input: adp5588-keys - cache GPIO state before registering the gpiochip
2026-09-20 07:02:34 -07:00
Linus Torvalds
4a910e594a selinux/stable-7.3 PR 20260919
-----BEGIN PGP SIGNATURE-----
 
 iQJIBAABCgAyFiEES0KozwfymdVUl37v6iDy2pc3iXMFAmqvPSwUHHBhdWxAcGF1
 bC1tb29yZS5jb20ACgkQ6iDy2pc3iXP1rBAAkK6sP+lzXynr/abxWio9UCvlN6NF
 jqMXtKeUeLNg/lJakXKhja/FGaK9w+Rm+zlXQQvVE7YAO5Db758JzCXMTHlK6etD
 T5d+GVdZj/oVcAvfGhov0guNHZqcfKTGWOXKtGV8RQWYL+f6IC1IIHnz9wNeWIfY
 emkfOTgAJpCkX9nXS5xTdQNUiPkUV80LFGqxXCMhxiumvyzqOhUteytfNh3UXXcs
 ldOWRBstUumudBe/MJR09REtQve3emHc7bZUAxSKwXxzdOPTf7UEy4Y7QXCN3Opn
 Dn6Dsrt6lnpIZyzUK/eOnZvQ639gDqTMW2XTmin0JIf2KGG/PhqnvOT07hOPl+X5
 wqXh2wCFn+tXVi5t+S2myMUVZK56GwfRH9kMCo6ca1Ui36iYYEeoJYt7z5tsE6P5
 YBdvKKJ/MPR1/uEwP/TB3UDK0o4OBjyujc6/Ka5iBoIHXKpx7MBLOo/Q0h/Wu2A0
 7HYvG/4lYdWp3p5iR8cdZ+ZgdTQDWi6t5BD3JWOfWi1gHCeGgZCHTCZ9mdSoFS18
 9GpXFXTR4yM5pfwxQEAu6jFH0esSB92HJBd/yS7sU8EIUQ+0XmOge+gVPifMrhWj
 yOHCR7hlAYE5ds51w3ZVOYI0slkYImqCHEdlCz1DiKzyLmQQmfJvshOIvBCl7uwn
 LRHu6Mo0cEBMAvc=
 =kiQE
 -----END PGP SIGNATURE-----

Merge tag 'selinux-pr-20260919' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux

Pull selinux fixes from Paul Moore:

 - Ensure that the cached SELinux access decisions are correct

 - Fix the SELinux overlayfs code to properly track the top-level/user
   information on multiple stacked overlayfs filesystems

 - Fix the SELinux overlayfs code to properly enforce mprotect() access
   control policy on all of the different layers in multiple stacked
   overlayfs filesystems

* tag 'selinux-pr-20260919' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux:
  selinux: recheck intermediate backing files on mprotect()
  selinux: preserve user SID across nested backing files
  selinux: always fill AVC decision in avc_has_perm_noaudit()
2026-09-20 06:50:31 -07:00
Liu Zhenlong
7362a1553e
i2c: qcom-cci: fix device_node refcount leak in cci_probe()/cci_remove()
The of_node_put() matching of_node_get() runs after i2c_del_adapter(),
whose trailing memset() zeroes adap->dev and thus adap->dev.of_node,
making the put a no-op and leaking the node on every adapter removal
and error cleanup.

Use a devm action: the pointer is captured at registration, out of
reach of that memset(), and devres runs the put once on probe failure
and detach, replacing the three manual of_node_put() calls.  The
setup loop uses the scoped iterator form so the child node is released
automatically if devm_add_action_or_reset() fails mid-loop.

Suggested-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Fixes: 02a4a69667 ("i2c: qcom-cci: don't put a device tree node before i2c_add_adapter()")
Assisted-by: Claude:claude-opus-5
Signed-off-by: Liu Zhenlong <dragonliu2018@gmail.com>
Cc: <stable@vger.kernel.org> # v5.17+
Reviewed-by: Vladimir Zapolskiy <vladimir.zapolskiy@linaro.org>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://patch.msgid.link/20260818175750.4205-1-dragonliu2018@gmail.com
2026-09-20 09:40:29 +02:00
Shengzhuo Wei
268aacb2e2
i2c: qcom-geni: release DMA channels on probe error
geni_i2c_init() grabs exclusive GPI tx/rx DMA channels when the serial
engine runs in GPI mode. If i2c_add_adapter() subsequently fails, probe
returns without releasing the channels, because the remove callback is
not invoked after a failed probe.

The adapter-registration failure path used to release the channels via
its err_dma label; that release was dropped when the probe tail was
restructured into geni_i2c_init().

Release the channels on the adapter-registration failure path, mirroring
geni_i2c_remove().

Fixes: d8d3bb127a ("i2c: qcom-geni: Isolate serial engine setup")
Assisted-by: GLM:5.3
Signed-off-by: Shengzhuo Wei <me@cherr.cc>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Mukesh Kumar Savaliya <mukesh.savaliya@oss.qualcomm.com>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://patch.msgid.link/20260827-i2c-dma-channel-leak-v1-3-271d4adc03a0@cherr.cc
2026-09-20 09:40:29 +02:00
Shengzhuo Wei
e9f03b9625
i2c: imx: release DMA channels on probe error
i2c_imx_dma_request() acquires exclusive tx/rx DMA channels and is
optional: on errors other than -EPROBE_DEFER the driver falls back to
PIO mode and probe continues. If i2c_add_numbered_adapter() then fails,
probe returns through clk_notifier_unregister without releasing the
channels, because the remove callback is not invoked after a failed
probe.

Release the channels on the probe error path, mirroring
i2c_imx_remove().

Fixes: ce1a78840f ("i2c: imx: add DMA support for freescale i2c driver")
Assisted-by: GLM:5.3
Signed-off-by: Shengzhuo Wei <me@cherr.cc>
Cc: <stable@vger.kernel.org> # v3.19+
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://patch.msgid.link/20260827-i2c-dma-channel-leak-v1-2-271d4adc03a0@cherr.cc
2026-09-20 09:40:28 +02:00
Shengzhuo Wei
f7eeb1af85
i2c: at91: release DMA channels on remove and probe error
at91_twi_configure_dma() requests exclusive tx/rx DMA channels, but
nothing ever releases them on driver detach, and the probe error path
after the channels are acquired (i2c_add_numbered_adapter() failure)
returns without releasing them either, because the remove callback is
not invoked after a failed probe.

Move the release into a helper, call it from the existing
configure-failure path, the adapter-registration failure path, and
at91_twi_remove().

Fixes: 60937b2cdb ("i2c: at91: add dma support")
Assisted-by: GLM:5.3
Signed-off-by: Shengzhuo Wei <me@cherr.cc>
Cc: <stable@vger.kernel.org> # v3.8+
Acked-by: Mukesh Kumar Savaliya <mukesh.savaliya@oss.qualcomm.com>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://patch.msgid.link/20260827-i2c-dma-channel-leak-v1-1-271d4adc03a0@cherr.cc
2026-09-20 09:40:28 +02:00
Thomas Gleixner
c21eaa72f0 posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list
Kijo analyzed another race in the POSIX CPU timer code:

Commit bf635681c9 converted cpu_timer::firing from a tristate value to a
boolean. This lost the distinction between "not owned by the firing list"
and "still owned, but delivery was canceled". The resulting race is:

    expiry handler              timer_settime()        timer_delete()
    --------------              ---------------        --------------
    collect timer onto
    private firing list
    firing = true
                                observes firing = true
                                firing = false
                                return TIMER_RETRY
                                wait for handler
                                                       observes firing = false
                                                       finish deletion
                                                       unhash and free timer
    resume list traversal
    read freed elist.next
    -> UAF

The firing bit is clearly the wrong indicator since that commit.

Check whether the timer is queued on the expiry list or not instead. If it
is queued clear the firing bit to prevent signal delivery as before and
return TIMER_RETRY so the caller unlocks the timer which allows the expiry
code to make progress and remove it from the list.

Fixes: bf635681c9 ("posix-cpu-timers: Cleanup the firing logic")
Reported-by: Kijo Park <red993688@gmail.com>
Debugged-by: Kijo Park <red993688@gmail.com>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Tested-by: Kijo Park <red993688@gmail.com>
Reviewed-by: Frederic Weisbecker <frederic@kernel.org>
Cc: stable@vger.kernel.org
2026-09-19 22:56:22 +02:00
Linus Torvalds
518e5b794c for-7.3-rc3-tag
-----BEGIN PGP SIGNATURE-----
 
 iQJPBAABCgA5FiEE8rQSAMVO+zA4DBdWxWXV+ddtWDsFAmqu3wQbFIAAAAAABAAO
 bWFudTIsMi41KzEuMTIsMiwyAAoJEMVl1fnXbVg7Y5kQAJ1ANaQWod+AUKhgbtA6
 IcEFH8AAVrrTqqN0SxOl/tqHL6Xt/5mKlQcTpYPxeccUkp72M9BeGik4Gp7OwN1D
 vkVTgrmhHT4r+4ae4GJP0yCtNJBa0fRXjsMFbNYTKGWcz9yOsW1OkBsq8VtRo7ym
 CSVBc57buUi0mzbnLNDh69G/YA7NCTyaxXKjPARNYy+cy0LMIDmgZCByhgePQvzB
 aqJUakRKpaeXEQIf0nT/70XcGhXNtfK1GOnLZM1ySFqLufMzdTsEzFsT8dVugqU1
 wr1HMaMq1iNKwE4sJgNWS84wRT1zxZopKIOsTufFu98Zb2C0kvUSjWeJSqtFM88G
 ggj/jmaoRhCU1cXE1jvZWy4Fe5zQH8deSQZ7zUB4ZzqCaDRwOEAj4IpuQQ9Ok91E
 J/07SCvKPk/QUPbA2e5lwRL3aximsD1LfRxWIOZ+xg/HVX+vYfHmy5gzkl/hhfrm
 RHkHLz8iXNHV7qhIVzZ/GYvTxR6U6nbLVUbkl5n/8eFePM7YHnoWtvMHT71qWwrh
 mPx8uTK+4BI2+rAHTKqxnwEQ27OHj5odlGKTlKiaMrQR9eqnnhJLTMPDJMzqQ7TI
 ZiibxG8UqSTsNbvOXXtd7MykSRpSb/VWyJImKuw30kx3f7f2yd1aCUyU4T7o5N/3
 FRI+2AbkoSeype3Rw+VcEPoi
 =WxSA
 -----END PGP SIGNATURE-----

Merge tag 'for-7.3-rc3-tag' of git://git.kernel.org/pub/scm/linux/kernel/git/kdave/linux

Pull btrfs fixes from David Sterba:
 "Among the regular fixes, there are two that were reported recently and
  have user impact:

   - filesystem id is now stable again on the default and common case
     (it broke openconnect key derivation, while this is not secure,
     it's still in use), the intention was to change id for the
     temp_fsid use case

   - fix detection of /dev/root and rename it after device scan, this
     broke booting of initramdisk-less system with grub2 as the probe
     needs the real device

  Regular fixes:

   - don't store compressed inline extent if the size is larger than
     uncompressed

   - in zoned mode, handle activation of zones for all supported block
     group profiles in case there are still free ones left

   - check space for a chunk item when reading sys array from superblock

   - allow using space reserves when removing verity items fails

   - fix error handling after free space tree rebuild fails

   - abort transaction if reflink or hole punching fails and it's not
     possible to update the inode

   - properly protect block group iteration during device replace start

   - error message fixups"

* tag 'for-7.3-rc3-tag' of git://git.kernel.org/pub/scm/linux/kernel/git/kdave/linux:
  btrfs: derive f_fsid with dev_t only when temp_fsid is active
  btrfs: add "/dev/root" exception for device path update
  btrfs: check if there is space for chunk item when validating sys chunk array
  btrfs: abort transaction on failure to update inode for hole punching and reflinking
  btrfs: clear free space tree creation state on rebuild failure
  btrfs: handle lack of space when cleaning up verity items
  btrfs: fix creation of compressed inline extents that don't save space
  btrfs: tree-checker: fix error message regarding free space extent items
  btrfs: tree-checker: print dev extent offset in error message
  btrfs: take commit root semaphore when iterating in mark_block_group_to_copy()
  btrfs: zoned: handle RAID profiles in btrfs_can_activate_zone()
2026-09-19 13:48:20 -07:00
Chang S. Bae
63edf5a009 x86/build/64: Prevent native builds from generating EGPR use
Omar reports that CONFIG_X86_NATIVE_CPU=y allows builds to opportunistically
emit instructions using %r16-%r31 (EGPRs) when the build host supports APX
since the commit:

  ea1dcca1de ("x86/kbuild/64: Add the CONFIG_X86_NATIVE_CPU option to locally optimize the kernel with '-march=native'")

But the kernel is not yet prepared to use new registers internally. For
example, there is no context-switch support for general in-kernel use.

Explicitly disable EGPR use when building with -march=native.

For C, since GCC 14 and Clang 18, both compilers support suppressing EGPR
use with -mno-apx-features=egpr, whose availability can be detected via
cc-option.

For Rust, pass features=-apxf through the generated JSON to avoid
unstable-feature warnings, see

  https://github.com/rust-lang/rust/issues/139284

Note Rust only accepts the option to disable APX instructions entirely or not.

Support for this gating also depends on the Rust/LLVM combination. Rust
1.88 introduced the `apxf` feature option, but versions prior to 1.93 may
emit an `apxf` attribute to the backend that only LLVM 23 or later can
interpret. Restrict native Rust builds accordingly.

Fixes: ea1dcca1de ("x86/kbuild/64: Add the CONFIG_X86_NATIVE_CPU option to locally optimize the kernel with '-march=native'")
Reported-by: Omar Avelar <omar.avelar@intel.com>
Signed-off-by: Chang S. Bae <chang.seok.bae@intel.com>
Signed-off-by: Borislav Petkov (AMD) <bp@alien8.de>
Reviewed-by: Nathan Chancellor <nathan@kernel.org>
Acked-by: Miguel Ojeda <ojeda@kernel.org>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260916230003.1144622-1-chang.seok.bae@intel.com
2026-09-18 21:43:38 -07:00
Linus Torvalds
40288c9206 drm fixes for 7.3-rc4
core:
 - fix vblank pending event leak
 
 ttm:
 - swapout fixes
 
 dma-buf:
 - scattergather fixes
 - enable dma-buf debug on debug kernels
 
 dma-fence:
 - fix signaling bit checks
 
 sched:
 - fix virtual runtime race
 
 msm:
 - DT:
   - Corrected indentation
 - Core:
   - Marked fbdev as system memory
 - GPU:
   - Fixed autosuspend cleanup on teardown
   - a750: fix timestamps
   - Increase GMU fw init timeout
   - Misc fixes/cleanups
 - DPU:
   - Fixed clock rounding, unbreaking newest platforms
   - Cleared pending flush state
 - DP:
   - Skip PUSH_IDLE when link was never enabled
   - Fixed bandwidth checks
 - HDMI:
   - Fixed runtime PM cleanup on probe failure
 
 xe:
 - shrinker related fixes
 - xe_mmio_gem fault handler and destroy fixes
 - xe disable i2c irq on unbind
 
 i915:
 - Revert a commit touching registers that don't necessarily exist
 - Check for negative numbers before passing to BIT()
 
 amdgpu:
 - SMU 14.x fix
 - DC IRQ fix
 - Runtime PM fix for P2P
 - RAS fix
 - PCIe reporting fix
 - DCN 6 fix
 - Device removal fix
 - DC MALL fix
 
 amdkfd:
 - GC 12.x fixes
 - Boundary checks
 - Mapping clear fix
 
 nouveau:
 - suspend/resume fixes
 
 gud:
 - out of bounds access fix
 - ignore damage clips in full update
 
 vc4:
 - use-after-free fix
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEEKbZHaGwW9KfbeusDHTzWXnEhr4FAmqttwkACgkQDHTzWXnE
 hr73Ww//S+8xgr8cpmJxoUrOrTnd4yeX/oj+HSRkEHQPdNayOf+pNnP4y+nChfXi
 ddQ3jTRyG5JwNmXRG0ouKf9koQk/V54R8v9CBtNQYsN2K58xW6riCIaEeOUbe3r1
 1IQgYCEfS32b7/9D2lo1768LbJ0KWBr6qznKrfvC7vJ62wK3F0B9EzOmsKSzLxd3
 gdUfyxEbtgegKOAamCbUyJyuzCErGkMAtkQ0HnmQGYmqqBBRS7Uvl1HN10JMoLSM
 MmR40g+dsp6ZzBDywNrdmIGDv749o1/k/zm5i6c2hJSibYBPR5sWtKICwu1ND44u
 ts2HjJJdyhm5PLiS09i9nVUnMkzV0N2czIDZvt9izp8+k8P4Bh/y1iagda1G0U65
 h7dp9j8WXMCApxXNjplNgjMLSO7g4UJI1rAWjxGY4ecu62XHErrZ6tbjrOVOaa1T
 Xh8IN4EqPr+tRSKnW4AxwwwA1EfxNwoJSxglAvBvIaCjEhRWRlj7Sdo0Wrtg3WKy
 sORar40ySYHR+MeAbabewjRoMPq1Nyqh4D2PrOv48a4MK7a6Fl5ed6EHpyOSHYKF
 7tMbLLLtDMIYX24wd/j8CkvhcTp09iphzXSqmUlIBn3t1gbrXspzCQtRU0UrsamJ
 QSbtL+qUoYSsobmpYOzuTVnO8W4oOnnIYaLz+TpVNDd7o7nzZf0=
 =EC37
 -----END PGP SIGNATURE-----

Merge tag 'drm-fixes-2026-09-19' of https://gitlab.freedesktop.org/drm/kernel

Pull drm fixes from Dave Airlie:
 "Things have picked back up a bit this week, mostly amdgpu, xe and msm
  this time. There are a bunch of scattered changes across the rest of
  drivers and core stuff, nouveau, i915.

  core:
   - fix vblank pending event leak

  ttm:
   - swapout fixes

  dma-buf:
   - scattergather fixes
   - enable dma-buf debug on debug kernels

  dma-fence:
   - fix signaling bit checks

  sched:
   - fix virtual runtime race

  msm:
   - DT:
      - Corrected indentation
   - Core:
      - Marked fbdev as system memory
   - GPU:
      - Fixed autosuspend cleanup on teardown
      - a750: fix timestamps
      - Increase GMU fw init timeout
      - Misc fixes/cleanups
   - DPU:
      - Fixed clock rounding, unbreaking newest platforms
      - Cleared pending flush state
   - DP:
      - Skip PUSH_IDLE when link was never enabled
      - Fixed bandwidth checks
   - HDMI:
      - Fixed runtime PM cleanup on probe failure

  xe:
   - shrinker related fixes
   - xe_mmio_gem fault handler and destroy fixes
   - xe disable i2c irq on unbind

  i915:
   - Revert a commit touching registers that don't necessarily exist
   - Check for negative numbers before passing to BIT()

  amdgpu:
   - SMU 14.x fix
   - DC IRQ fix
   - Runtime PM fix for P2P
   - RAS fix
   - PCIe reporting fix
   - DCN 6 fix
   - Device removal fix
   - DC MALL fix

  amdkfd:
   - GC 12.x fixes
   - Boundary checks
   - Mapping clear fix

  nouveau:
   - suspend/resume fixes

  gud:
   - out of bounds access fix
   - ignore damage clips in full update

  vc4:
   - use-after-free fix

  versilicon:
   - plane format fix

  longsoon:
   - blend mode property fix"

* tag 'drm-fixes-2026-09-19' of https://gitlab.freedesktop.org/drm/kernel: (59 commits)
  drm/amd/display: fix MALL hysteresis timer underflow at high refresh rates
  drm/amdgpu: fix rmmio iounmap skipped on device removal
  drm/amdgpu: Skip KFD mapping clear before initialization
  drm/amd/display: Fix NULL dereference in dcn50/dcn60 init_hw
  drm/amdkfd: Avoid integer underflow in EOP ring size calculation.
  drm/amdkfd: Avoid integer underflow with ffs in EOP ring size calc
  drm/amdgpu: Fix GPU PCIe link capability reporting
  drm/amdgpu: check ras and obj before dereference
  drm/amdgpu: hold a runtime PM reference for P2P dma-buf attachments
  drm/amdkfd: implement restore_mqd callbacks for GFX12/12.1
  drm/amd/display: Atomize IRQ register read/modify/write ops
  drm/amd/pm: report energy accumulator for smu 14.0.3
  drm/loongson: Create blend mode property for cursor plane
  drm/xe/i2c: Disable IRQ on unbind
  Revert "drm/i915/display: Clear SEL_FETCH_PLANE_CTL on plane disable"
  drm/verisilicon: remove ARGB formats from primary plane
  drm/verisilicon: add primary modifier for format tables
  drm/verisilicon: set blend mode for the cursor plane
  drm/sched: Fix virtual runtime race
  drm/i915/display: check configuration index before shifting
  ...
2026-09-18 16:37:37 -07:00
Dave Airlie
71f370e9ee Two ttm fixes for ttm_tt_swapout(), one page-alignment and one overflow
fix for dma-buf, a drm_pending_vblank_event leak fix for drm,
 suspend/resume fixes for nouveau, one out-of-bounds access fix for gud,
 a use-after-free fix for vc4, a fence signaling fix, a race condition
 fix for sched, planes formats fixes for verisilicon, and add the blend
 mode property for loongson
 -----BEGIN PGP SIGNATURE-----
 
 iJUEABMJAB0WIQTkHFbLp4ejekA/qfgnX84Zoj2+dgUCaqvVAAAKCRAnX84Zoj2+
 dtThAX9JC7SWXw+n4o9EUsxNqvlpviwe8AS7aJR++rq/sZM0an7zl0aCJu/E8p+/
 JRkO+X8BfjE+2CX8RWKH63ed95vA+9DF8JfryBTSJiSz4forppFfwH7uovT3nqq2
 eOon6nJQzg==
 =Utup
 -----END PGP SIGNATURE-----

Merge tag 'drm-misc-fixes-2026-09-17' of https://gitlab.freedesktop.org/drm/misc/kernel into drm-fixes

Two ttm fixes for ttm_tt_swapout(), one page-alignment and one overflow
fix for dma-buf, a drm_pending_vblank_event leak fix for drm,
suspend/resume fixes for nouveau, one out-of-bounds access fix for gud,
a use-after-free fix for vc4, a fence signaling fix, a race condition
fix for sched, planes formats fixes for verisilicon, and add the blend
mode property for loongson

Signed-off-by: Dave Airlie <airlied@redhat.com>

From: Maxime Ripard <self@mripard.dev>
Link: https://patch.msgid.link/aqvVENQ4ksJEIcdb@houat
2026-09-19 06:49:36 +10:00
Linus Torvalds
17e7b8eacf smb client fixes for v7.3-rc4
A batch of bug fixes for the smb client:
 
  - Fix multiple out-of-bounds reads and use-after-frees in the SMB2/3
    receive path that are reachable from a malicious or compromised
    server: a stale next_buffer pointer and an integer overflow in
    compound encrypted frame handling, missing minimum-PDU-size and
    per-sub-PDU length validation before parsing command-specific
    response fields, missing bounds checks in DFS referral, server
    interface list, EA list, POSIX SID, snapshot enumeration and SMB1
    reparse point parsing
 
  - Fix use-after-frees and races in multichannel and connection
    teardown, including an interface freed while still in use when
    adding channels, a server used after its channel reference was
    dropped, a reconnect work item left queued after the server is
    freed and an uninitialized reconnect list node
 
  - Fix a heap overflow in the native symlink parser: an absolute
    target without an NT drive prefix caused out-of-bounds writes and a
    u16 length underflow leading to a 64K memcpy into a small buffer,
    triggerable by a user with write access to a mounted share under
    default settings
 
  - Fix WSL reparse point parsing: use unaligned accessors for the
    packed extended-attribute payload to avoid alignment faults on some
    architectures and stop leaving partially mutated fattr fields on
    parse failure
 
  - Fix lease break ACKs being sent through the wrong session on
    multiuser mounts, which caused read failures (e.g. on NetApp
    ONTAP/Azure Files) when copying files
 
  - Fix an smbd_connection leak when cifs_get_tcp_session() fails after
    an RDMA connection was already established
 -----BEGIN PGP SIGNATURE-----
 
 iHUEABYKAB0WIQTcqRusfSdYROJQwGkpVtNKoQNdYwUCaq2frwAKCRApVtNKoQNd
 Y1mcAQDcDTkep03jzghyJG6xWJ3S7KNbeYpjkOPnPyR+Et7HmAD/eXLFvgkJ3wC7
 tBUDjDTLeyP6/DOBmDb/fIKEw2vfBQs=
 =+Vsw
 -----END PGP SIGNATURE-----

Merge tag 'cifs-fixes-7.3-rc4' of https://git.manguebit.org/linux

Pull smb client fixes from Paulo Alcantara:
 "A batch of bug fixes for the smb client:

   - Fix multiple out-of-bounds reads and use-after-frees in the SMB2/3
     receive path that are reachable from a malicious or compromised
     server: a stale next_buffer pointer and an integer overflow in
     compound encrypted frame handling, missing minimum-PDU-size and
     per-sub-PDU length validation before parsing command-specific
     response fields, missing bounds checks in DFS referral, server
     interface list, EA list, POSIX SID, snapshot enumeration and SMB1
     reparse point parsing

   - Fix use-after-frees and races in multichannel and connection
     teardown, including an interface freed while still in use when
     adding channels, a server used after its channel reference was
     dropped, a reconnect work item left queued after the server is
     freed and an uninitialized reconnect list node

   - Fix a heap overflow in the native symlink parser: an absolute
     target without an NT drive prefix caused out-of-bounds writes and a
     u16 length underflow leading to a 64K memcpy into a small buffer,
     triggerable by a user with write access to a mounted share under
     default settings

   - Fix WSL reparse point parsing: use unaligned accessors for the
     packed extended-attribute payload to avoid alignment faults on some
     architectures and stop leaving partially mutated fattr fields on
     parse failure

   - Fix lease break ACKs being sent through the wrong session on
     multiuser mounts, which caused read failures (e.g. on NetApp
     ONTAP/Azure Files) when copying files

   - Fix an smbd_connection leak when cifs_get_tcp_session() fails after
     an RDMA connection was already established"

* tag 'cifs-fixes-7.3-rc4' of https://git.manguebit.org/linux:
  cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
  smb: client: fix reparse buffer bounds in cifs_query_reparse_point()
  smb: client: fix potential OOB read in smb3_enum_snapshots()
  smb: client: fix missing iov bounds check in parse_posix_sids()
  smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs()
  smb: client: reject short Next offsets in parse_server_interfaces()
  smb: client: fix missing lower-bound check on DFS referral string offsets
  smb: client: fix server->total_read for compound encrypted PDUs
  smb: client: validate minimum PDU size before smb2_get_data_area_len()
  smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
  smb: client: fix use-after-free of iface in cifs_try_adding_channels()
  smb: client: fix fattr leaking on wsl_to_fattr() failure
  smb: client: fix unaligned access in WSL reparse point parser
  smb: client: fix smbd_connection leak on cifs_get_tcp_session() error
  smb: client: fix rlist race and missing initialization
  smb: client: cancel reconnect work in clean_demultiplex_info()
  smb/client: send lease break ACKs thru correct session for multiuser mounts
  smb: client: validate absolute native symlink targets before NT fixups
2026-09-18 13:44:59 -07:00
Linus Torvalds
925724c081 SCSI fixes on 20260918
Four driver fixes, three of which are minor and one of which (fnic)
 tries to add some logic to try to avoid MSI-X being ineffective if
 hyperthreading is disabled.  The core fix adds validation to mode sense
 buffer sizes because it is used by ATA and could, theoretically, be
 exploited by a specially crafted USB device that can simply be plugged
 in to any laptop or server.
 
 Signed-off-by: James E.J. Bottomley <James.Bottomley@HansenPartnership.com>
 -----BEGIN PGP SIGNATURE-----
 
 iLgEABMIAGAWIQTnYEDbdso9F2cI+arnQslM7pishQUCaq2P/hsUgAAAAAAEAA5t
 YW51MiwyLjUrMS4xMiwyLDImHGphbWVzLmJvdHRvbWxleUBoYW5zZW5wYXJ0bmVy
 c2hpcC5jb20ACgkQ50LJTO6YrIXJ6AD9FODcORvjoRDhcU626EWsG/Hoy7YcMH2T
 bZVtZwp3hH8BAPnKar5uj3fCQxJkvI+sLKjiGultTi3llt9VaZGSTFj2
 =JgQF
 -----END PGP SIGNATURE-----

Merge tag 'scsi-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/jejb/scsi

Pull SCSI fixes from James Bottomley:
 "Four driver fixes, three of which are minor and one of which (fnic)
  tries to add some logic to try to avoid MSI-X being ineffective if
  hyperthreading is disabled.

  The core fix adds validation to mode sense buffer sizes because it is
  used by ATA and could, theoretically, be exploited by a specially
  crafted USB device that can simply be plugged in to any laptop or
  server"

* tag 'scsi-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/jejb/scsi:
  scsi: core: Validate MODE SENSE lengths in scsi_cdl_enable()
  scsi: fnic: Fix missed link-up when critical IRQ targets offline CPU
  scsi: ibmvfc: Add Kconfig dependency to fix link failure when NVME_FC=m
  scsi: qla2xxx: Fix the ql2xfc2target parameter description
  scsi: pm80xx: Fix the use_msix, use_tasklet and read_wwn parameter descriptions
2026-09-18 13:10:29 -07:00
Linus Torvalds
ef31d04b6d pci-v7.3-fixes-1
-----BEGIN PGP SIGNATURE-----
 
 iQJIBAABCgAyFiEEgMe7l+5h9hnxdsnuWYigwDrT+vwFAmqtiM0UHGJoZWxnYWFz
 QGdvb2dsZS5jb20ACgkQWYigwDrT+vxDxg/+Nyqg0N+1xxHnG+bsbJ7XA7v7sQY5
 DcvfvnMcJg3Lx5ioED4OJwr35rQZy8E3n/swFCxvzyZQ6gp+Q3sA2wUeuqd26kCS
 OSuMwRj3+HsnCVlYC/LL5fUoyZ+/FFv4drDPvIl3vCo5kIoNuWJslIox1eqPgmtZ
 SZO70qyQcA8jjCHYqQR07kvtqyainZrOoPP5uASnRqSGVlTLI3mzKdLtzrVytgel
 bAb6CPKrqF1XQY2HBBH3MEU6mhXbr7zeSrncZnb0QimqHCloq4dUK+WF9ZQnxSk5
 wXgftOvg2ycYhE6hUVZGrRf/fMwzWatkD/Vi9a69wKN2lspwacKCGi0LhNS1u/Em
 ypak/Wg0sEic5y//eOgJjIfodJLsHiyvBIZxC3ziqZj1q6Kc4pCvg1iHePFYCSQj
 gB4Khkm6sWx63GX02g9ytc9bl00xCkjuck8OSVExP2MhaWajlksvzy9VXsZG9BzH
 QianraVVqVZd+LM3eFTy16qaD7jQuNMCIzOzB3UDh2gSzO+Lr9OtK36iTsn0NELc
 lKjrIlh5yEp5uD9vrrD4k8xAbaVGBnzzK7Whc42rt2n/gIs2SbV8TXWTyxtk29DJ
 XlbUAOiBLYEuO3YWAvq47kezyafwRtBqXxjyyoZajteD+hoRFFtkcT5OcaiWVZUL
 qzRbS1eB3IfB/q8=
 =9dUn
 -----END PGP SIGNATURE-----

Merge tag 'pci-v7.3-fixes-1' of git://git.kernel.org/pub/scm/linux/kernel/git/pci/pci

Pull PCI fix from Bjorn Helgaas:

 - Enable clock after core reset is asserted to fix enumeration
   regression on i.MX6Q Apalis platforms with ASM1061/ASM1062 SATA
   controllers (Richard Zhu)

* tag 'pci-v7.3-fixes-1' of git://git.kernel.org/pub/scm/linux/kernel/git/pci/pci:
  PCI: imx6: Move clock enable after core reset assertion
2026-09-18 12:16:25 -07:00
Linus Torvalds
c3d85c669d - Fix session expiration so that valid sessions are no longer removed
after ten seconds of inactivity when a new session setup request is
    received. Sessions now expire only after credential expiration, while
    stale unauthenticated sessions are cleaned up after a 45-second timeout.
 
  - Keep earlier responses in compound requests when Query Info fails
    because the output buffer is too small. The error response is appended
    without truncating preceding responses.
 
  - Return STATUS_BUFFER_OVERFLOW for partial
    FILE_NORMALIZED_NAME_INFORMATION responses instead of incorrectly
    returning STATUS_INFO_LENGTH_MISMATCH.
 -----BEGIN PGP SIGNATURE-----
 
 iQJKBAABCgA0FiEE6NzKS6Uv/XAAGHgyZwv7A1FEIQgFAmqtTBMWHGxpbmtpbmpl
 b25Aa2VybmVsLm9yZwAKCRBnC/sDUUQhCD2GD/9OzkmZ+/kIMum8IQi9upOM5zUD
 +2nyFMebJ6qXmrhOuUgLn2ptUYxO3q1B9VvzTjKrM1Vun0VuvHmHQbGUp9a/3F7c
 VTncl7E3FEHqlPkLWQJFv2dS+TYYcOhjoc2TDAY9093xktcMHK5zjv4E/DV2o0bf
 NN/GcrrcWSxdJU8WI9JvY2kzmPQMDfM8uVbj2RqHSZ8m9mF5cajtDnzCCS0K6UOR
 qzMrekzewIskUtcQNqU8hJWl1sgiYdD+16LmKmwLd3uOZISc3Miy5Bg8VpNN+B1g
 XHhr49G4Fb8PkEYjncjxQH7zop1ID5UyC2xN63NuoH8+mkm4qn6uG2NrLhmVQO+f
 Z81Ov3g77/jK3Z2fw00H3A7VGSPs931BaRTNj+lPkHTVVq3PyP1XZsfXkPUoRu1Q
 xeaJydScGNYE+kaYbseXwN8haJGawd1Dd+Afn4W2zikUU5tKZxO9d2tBr4Fhl/Fm
 0OBcAssTArhrY7PX2fAOQ4sUwAC4nMXSEIfdWIvcgU2OoyuFltQ55ooCoM0uLs6+
 7R4rxZLipdZmKhuE2mlAWcFQJn8nS0EHXeyEDjO0u8KYsV6C8d+jDNpvtS+/5QVF
 bKE4/uUX/lV0IZ55nFSPT7XdI+gxeiUql3+8bqOVqkw7wR4VjaC0xIQybyEBTMYH
 IJEKfjx4tZcWGTzmdA==
 =9nNl
 -----END PGP SIGNATURE-----

Merge tag 'ksmbd-for-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/linkinjeon/smb

Pull smb server fixes from Namjae Jeon:

 - Fix session expiration so that valid sessions are no longer removed
   after ten seconds of inactivity when a new session setup request is
   received.

   Sessions now expire only after credential expiration, while stale
   unauthenticated sessions are cleaned up after a 45-second timeout.

 - Keep earlier responses in compound requests when Query Info fails
   because the output buffer is too small. The error response is
   appended without truncating preceding responses.

 - Return STATUS_BUFFER_OVERFLOW for partial
   FILE_NORMALIZED_NAME_INFORMATION responses instead of incorrectly
   returning STATUS_INFO_LENGTH_MISMATCH.

* tag 'ksmbd-for-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/linkinjeon/smb:
  ksmbd: keep compound responses on query info errors
  ksmbd: fix partial normalized name responses
  ksmbd: follow SMB2 session expiration semantics
2026-09-18 11:05:55 -07:00
Linus Torvalds
bfda5a01aa - Make MFT extension work on existing Windows-created volumes by
dynamically reserving MFT tail records, accounting for records added
    during allocation, and avoiding false -ENOSPC failures.
 
  - Repack non-resident $MFT/$ATTRIBUTE_LIST when its mapping pairs no longer
    fit in the base MFT record, while propagating allocation and writeback
    errors.
 
  - Serialize runlist updates with the runlist lock and restore both the
    in-memory runlist and on-disk mapping pairs when allocation rollback is
    required.
 
  - Propagate folio errors and harden inode failure handling by treating
    interrupted reads as transient failures and discarding and unhashing
    inodes whose initialization fails.
 
  - Fix the $MFTMirr write offset when mirror records span multiple folios,
    preventing mirror records from overwriting the first record with large
    MFT record sizes.
 -----BEGIN PGP SIGNATURE-----
 
 iQJKBAABCgA0FiEE6NzKS6Uv/XAAGHgyZwv7A1FEIQgFAmqtRIEWHGxpbmtpbmpl
 b25Aa2VybmVsLm9yZwAKCRBnC/sDUUQhCBK8EAChFdTxig3sYog3dL27SX+1yNC4
 S1QtSQMvPJzcvLG2/mESC57snx1u6AXZ6enaQ/m8zQQvkWHFdwD+odgjOQ3474Yc
 MS7xQn5pCsAo3LmSWiDsQfHmvxgDMYlIRU1vmqr7fG2pj+W6BR2LB1PD3RI9exI7
 0WWAXBPZH5w5C9GE1Zo7TF9Xwby5Or31RS8+R57PXA/PJ1ivpWnlkpfLi4M/YkZK
 GIpunZafSpcKbEsuWcjhdz11bR4G9Qlwuuq0MDguLC/qsqsobHCeSbdx+4IsEAq5
 02yBl5hYm2E4u2KBedpe7oRwFvlPN0uakEGYS8SA1ad9XamjGIw6T0tkzkDL48Pq
 dhVAeX2oa8O9u+VK+qF/HIUylh/UbmHQJW8iSiZWO8WdULGBG8oCHI1hcSnMguwJ
 njyK75UXz4fMsKW6ZpRu0sRGqtKKcbg8IrCvLslPIOS2A9OAwSzytDKI+x1Kbgu0
 SVPYjf6XeOz83tvE+2OhfTT1hWkeKezMiUe4E/y9rgEDxv5vE4C5pvpDfRlj3oyn
 2JTXXjjUQGSQw/9cKbLsbElDH/FLEojLAsIFgM+2FbcG+x7PUUgSGdC4R4qZ9MUF
 cuMzfhi8vKyCYmJc8nNE4J6b6UkBNOFJMYBcArtByFW3LqfIzmqwW81Xx0Hz4cxi
 dmOhD6gXXYoi9m3lBQ==
 =rT1L
 -----END PGP SIGNATURE-----

Merge tag 'ntfs-for-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/linkinjeon/ntfs

Pull ntfs fixes from Namjae Jeon:

 - Make MFT extension work on existing Windows-created volumes by
   dynamically reserving MFT tail records, accounting for records added
   during allocation, and avoiding false -ENOSPC failures

 - Repack non-resident $MFT/$ATTRIBUTE_LIST when its mapping pairs no
   longer fit in the base MFT record, while propagating allocation and
   writeback errors

 - Serialize runlist updates with the runlist lock and restore both the
   in-memory runlist and on-disk mapping pairs when allocation rollback
   is required

 - Propagate folio errors and harden inode failure handling by treating
   interrupted reads as transient failures and discarding and unhashing
   inodes whose initialization fails

 - Fix the $MFTMirr write offset when mirror records span multiple
   folios, preventing mirror records from overwriting the first record
   with large MFT record sizes

* tag 'ntfs-for-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/linkinjeon/ntfs:
  ntfs: fix $MFTMirr write offset when it spans multiple folios
  ntfs: unhash failed inode reads
  ntfs: discard inodes that fail initialization
  ntfs: ignore interrupted inode reads as corruption
  ntfs: propagate folio errors
  ntfs: protect runlist updates with the runlist lock
  ntfs: account for MFT records added during allocation
  ntfs: repack $MFT/$ATTRIBUTE LIST
  ntfs: use dynamic MFT tail reservation
2026-09-18 11:02:08 -07:00
Linus Torvalds
8cb0606271 MMC core:
- Prevent potential use-after-free for SDIO IRQ work
  - Fix OF node reference leak on card add failure
  - Fix memory lea when the port table is full for sdio_uart
 
 MMC host:
  - hsq: Fix use-after-free in retry work
  - mmci: Fix use-after-free in busy-timeout work
  - mmc_spi: Reset bytes_xfered before retrying CRC failures
  - mxcmmc: Cancel data work and watchdog on remove
  - rtsx_pci_sdmmc: Ignore broken write-protect on ThinkPad X260
  - sdhci_am654: A couple of fixes for the tuning sequence
  - sdhci-of-aspeed: Remove children before releasing SDC resources
  - sh_mmcif: Initialize IRQ-thread mutex before requesting interrupt
 
 MEMSTICK:
  - ms_block: Destroy io_queue workqueue on removal
 -----BEGIN PGP SIGNATURE-----
 
 iQJEBAABCgAuFiEEugLDXPmKSktSkQsV/iaEJXNYjCkFAmqtI4oQHHVsZmhAa2Vy
 bmVsLm9yZwAKCRD+JoQlc1iMKcjwD/91lyNP8fb8cxorEtmkiNt63Sb+glVEnobW
 aOlXS23GuV9ZsPw7kKEEfZ4EWCOTEZ86Lj0OMzlpXE8dxYHGlu0qG97uxSiJ4wux
 LQ0+OR5ljqDN48BWrn3wWsJ1YLfM4xXL7XukiCEuxLU9jwlbPHNjtY8c0+JqMapH
 D1yE7tH7/ZPJuYwKt9DJlx5DKg0BTiRn/7j+o3IETNyuBP05ZzrUjNdgQW8DVawg
 2uR0GCZ268Asd7XhnywvLXbeg5jxRAEVMGVjEzn2CY5uY0YyUW9ye9e+TpbNqpYf
 OA2MnYiTNpcRIiI3Z8R5vrhGxMpqFd5hFdIUE64O5gnjSyrBKeo9SSw4huXlLvac
 xjdBYmtLxSQjIgvZaEG4hl12lJt/snLJODTEq690zei9oWCUnCKzZaargLFPcDje
 0J8HwPYStynI0nc2Jc4oGZEGGwgvSmFPk15JtMEdmJb3eIwOfzGLA1ky9+5VEVCC
 zzMifnvnseAJwz+iAaJYxkED3Gd4t/jm4n8XIihddsKBQHAbMtGhUmhSzNnzD6NF
 xgscpv8s8SKExwS6X+6f/SBZD4VoF9b1JDhJ+fVUJDQ1Dsgv9AyT/bl8gDBHPNwr
 JHflPaQhc3hM9RppdcZnW3KSCu3DCJ04XaoHy6m5zKWZHUBEAtxujHA5u373Wv89
 StY7v7d7UQ==
 =KPXN
 -----END PGP SIGNATURE-----

Merge tag 'mmc-v7.3-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/ulfh/mmc

Pull MMC/MEMSTICK fixes from Ulf Hansson:
 "MMC core:
   - Prevent potential use-after-free for SDIO IRQ work
   - Fix OF node reference leak on card add failure
   - Fix memory lea when the port table is full for sdio_uart

  MMC host:
   - hsq: Fix use-after-free in retry work
   - mmci: Fix use-after-free in busy-timeout work
   - mmc_spi: Reset bytes_xfered before retrying CRC failures
   - mxcmmc: Cancel data work and watchdog on remove
   - rtsx_pci_sdmmc: Ignore broken write-protect on ThinkPad X260
   - sdhci_am654: A couple of fixes for the tuning sequence
   - sdhci-of-aspeed: Remove children before releasing SDC resources
   - sh_mmcif: Initialize IRQ-thread mutex before requesting interrupt

  MEMSTICK:
   - ms_block: Destroy io_queue workqueue on removal

* tag 'mmc-v7.3-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/ulfh/mmc:
  mmc: sdhci-of-aspeed: Remove children before releasing SDC resources
  mmc: sh_mmcif: initialize IRQ-thread mutex before requesting interrupt
  mmc: core: Fix OF node reference leak on card add failure
  mmc: rtsx_pci_sdmmc: ignore broken write-protect on ThinkPad X260
  mmc: sdio_uart: fix xmit_fifo leak when the port table is full
  mmc: spi: reset bytes_xfered before retrying CRC failures
  mmc: sdhci_am654: Fallback to DT-provided itap delay on DDR50 tuning failure
  mmc: sdhci_am654: Clear ITAPDLY on tuning failure
  mmc: sdhci_am654: Reset command and data lines on failed tuning
  mmc: sdhci_am654: Move tuning_loop to local variable
  mmc: hsq: Fix use-after-free in retry work
  mmc: mxcmmc: cancel data work and watchdog on remove
  mmc: mmci: Fix use-after-free in busy-timeout work
  mmc: core: Cancel SDIO IRQ work before freeing host
  memstick: ms_block: destroy io_queue workqueue on removal
2026-09-18 10:53:42 -07:00
Linus Torvalds
ae09f35bd3 ata fixes for 7.4-rc4
- Explicitly clear upper address bits on quirked AHCI controllers
 
    AHCI controllers that claim to support 64-bit DMA, but which have
    been quirked to only do 32-bit DMA, could start the DMA engine
    with a non-zero value in the upper address bits registers (me)
 
  - Fix a resource leak in ahci_platform_get_resources() (Wentao)
 
  - Fix invalid kernel-doc formatting for ata_dsm_trim_pages() (me)
 -----BEGIN PGP SIGNATURE-----
 
 iHUEABYKAB0WIQRN+ES/c4tHlMch3DzJZDGjmcZNcgUCaq0h5wAKCRDJZDGjmcZN
 cla0AQD9oseos93LDPzXR5SSMirdjoL9Qee8RsVeIMMlRtahiAD/Tx+vlEYrQ3QG
 yESu9KV1YCaV2qDzG+nFjNt9Z6uc4wo=
 =xqFb
 -----END PGP SIGNATURE-----

Merge tag 'ata-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/libata/linux

Pull ata fixes from Niklas Cassel:

 - Explicitly clear upper address bits on quirked AHCI controllers

   AHCI controllers that claim to support 64-bit DMA, but which have
   been quirked to only do 32-bit DMA, could start the DMA engine with a
   non-zero value in the upper address bits registers (me)

 - Fix a resource leak in ahci_platform_get_resources() (Wentao)

 - Fix invalid kernel-doc formatting for ata_dsm_trim_pages() (me)

* tag 'ata-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/libata/linux:
  ata: libata-scsi: fix ata_dsm_trim_pages() kernel-doc
  ata: libahci_platform: Fix device reference leak in ahci_platform_get_resources()
  ata: libahci: clear PxCLBU and PxFBU for AHCI_HFLAG_32BIT_ONLY
2026-09-18 10:51:14 -07:00
Linus Torvalds
d24e3bf4c5 hwmon fixes for v7.3-rc4
* cgbc-hwmon: Add missing sensors, and fix current sensors ID lookup
 
 * gpioufan: Return IRQ_HANDLED from the shared alarm IRQ handler to fix
   possible interrupt storm
 
 * hp-wmi-sensors: Improve raw WMI string handling, and fix UaF in show
   function
 
 * k10temp: Fix model id range of Zen5 Turin to stop reporting temperature
   data for non-existing CCDs
 
 * pmbus
 
   - core: Increase number of phases to fix UaF problems
 
   - tps53679: Fix TPS53676 phase page decoding, and select page 0
     for single-page applications
 
 * pwm-fan: Stop RPM timer before freeing tach data to fix UaF problem
 
 * w83793: Release probe data through kref to fix UaF problem
 
 * w83791d: Remove fan/pwm 4-5 sysfs group on remove to fix UaF problem
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCAAdFiEEiHPvMQj9QTOCiqgVyx8mb86fmYEFAmqtY4YACgkQyx8mb86f
 mYHX0Q//UmlkmqkHH3XdKi1QX/RV60f82HfzXRkMq98FYocEYv4TKnru3U5pRLY3
 Vs/h4GcDWT16ApqKbciBxgoUj72XBohm/T0gv8rhC/gkx4w8F7/CPuCB6vq9kIAj
 EIOHM3KoulfwUN6K1JeFdo5sIrTMxYGnQoJjS31/HfExEGbcBMZjA4eWLkqA0s18
 zmtYKbCJbG2WFRkI8/HKeQ2MwFE3RLNrxPVNvWJNzwIPjMvaAD7eDSsRjgXpaH6s
 A2OHpnGkDLE1qeyuYYx+nFYmMQDGDxnt6QvEjX5cVUYE+jDIXuzF5HJVfLCaXoSJ
 cFJmyNVTNE6Is1g6qeBRwObSq/NJH3O6p7kXCf5qwO27XBXgt/7K4q751tMq8oEE
 kXiYn3WfBL4WJjYqQw8kEh2/D18fyj9XmoS7iBXzf1qXgRSROm/9irMBjsWiw0WF
 92iE9U7UaE/a5fGX+dbRnB7QmLZ33U5TzA3ERb+MwJQj6o8Llvb5gmJOmlYebpa1
 zRiu285Y3oGnjjkFgzvpps9hsVw3kb2Xs2utMbTPrJ2z4SUO9KInl+ifOr5w9VI+
 sNU0Rn3eQ6IT40NMO9FhHPciZygKmob6hNDYh/6e+OulMDW7XW46ES2e8jjwME30
 fjDpfKDxoAU/xQ548XQJBRcUNjUhV8S6NYZr3H4PpyWlPVmSkOY=
 =lG35
 -----END PGP SIGNATURE-----

Merge tag 'hwmon-for-v7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/groeck/linux-staging

Pull hwmon fixes from Guenter Roeck:

 - Add missing sensors, and fix current sensors ID lookup (cgbc-hwmon)

 - Return IRQ_HANDLED from the shared alarm IRQ handler to fix possible
   interrupt storm (gpioufan)

 - Improve raw WMI string handling, and fix UaF in show function
   (hp-wmi-sensors)

 - Fix k10temp model id range of Zen5 Turin to stop reporting
   temperature data for non-existing CCDs

 - pmbus:
     - Increase number of phases to fix UaF problems
     - Fix TPS53676 phase page decoding, and select page 0 for
       single-page applications

 - Stop pwm-fan RPM timer before freeing tach data to fix UaF

 - Release w83793 probe data through kref to fix UaF

 - Remove w83791d fan/pwm 4-5 sysfs group on remove to fix UaF

* tag 'hwmon-for-v7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/groeck/linux-staging:
  hwmon: (hp-wmi-sensors) Improve raw WMI string handling
  hwmon: (pmbus/tps53679) Select page 0 for single-page TPS53676
  hwmon: (pmbus/tps53679) Fix TPS53676 phase page decoding
  hwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show()
  hwmon: (w83793) release probe data through kref
  hwmon: (w83791d) remove fan/pwm 4-5 sysfs group on remove
  hwmon: (gpio-fan) return IRQ_HANDLED from the shared alarm IRQ handler
  hwmon: (pmbus/core) increase number of phases and add new mask
  hwmon: (cgbc-hwmon) Add missing sensors
  hwmon: (cgbc-hwmon) Fix current sensors ID lookup
  hwmon: (pwm-fan) Stop RPM timer before freeing tach data
  hwmon: (k10temp) Fix model id range of Zen5 Turin
2026-09-18 10:27:23 -07:00
Linus Torvalds
928ba50514 watchdog fixes for v7.3-rc4
* da9062, da9063: Fix suspend/resume handling of HW_RUNNING watchdog
 
 * digicolor, rtd119x, and rzv2h: Avoid division by zero if clock rate is 0
 
 * msc313e: Fix premature reset during timeout update, and propagate error
   code in resume()
 
 * sp5100_tco: Fix pci_dev reference leak in sp5100_tco_init()
 
 * starfive-wdt: Fix runtime PM leak in starfive_wdt_pm_start()
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCAAdFiEEiHPvMQj9QTOCiqgVyx8mb86fmYEFAmqtZJEACgkQyx8mb86f
 mYGnwA/8C90wOrDbHonYx0SahuJaYniOmz6yHCuAR1AwtzKfXDua3WJ7ry4WfZXN
 WCACTcFCUp1CiLvstwpX7nDKGReYG47FOq6Rbou+JaJo43m9SGga5IGxKM28MBy7
 F4TH3CDMSOcomlgPYeXc5jx0oRkNXyDPMDHtbCOM5h+WwJb0Zxtfh+77l5q2LrQg
 D7nIGCkoztl7PDIgbvYESp9DYVdUgT6paeIRjJbs5BCwmNleU9LInDPDAtcXHnRp
 cyCa8FlfPrQMxhtbF1YQyaEdU04GlAwtHW4HE55tcxY3pTE/9qqA5SUzQBDXT2gO
 yCCG1qIFOmJY6QnlSfIYpHZtNxcpA75d8fQvqm14H+ACxkbaRF1d+sobtJTTckTD
 WBSr6RlrB5f/DAltqbV2OAsLddhBl4rQkW2RiljTW4C4pUiedPoSR8StTpnM6lC3
 VBpUdYp7tCIWihX/v/v+iRK1Y7JWVM+lhQnMpqBtpLtl3k7VLCLoFsmSbz0hHhu6
 kAJ1ZWeBy2xYgiGOM+D361iKhefjsZk9tdrC8IxriJ/gUwlcazELqqcsvU+I5ebN
 sutAYvE6Vdl5qwiLIRRHNpHvKm0wu9URIpPJrdwDtAIbaT3joSZIkV3TA7ZFBwGG
 tU4Z9ok0O4N4DDPv0CAg82lXBrMiWt3agYKKkhKTsmKROqqWVa8=
 =oqFf
 -----END PGP SIGNATURE-----

Merge tag 'watchdog-fixes-for-v7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/groeck/linux-staging

Pull watchdog fixes from Guenter Roeck:

 - Fix suspend/resume handling of HW_RUNNING watchdog (da9062, da9063)

 - Avoid division by zero if clock rate is 0 (digicolor, rtd119x, and
   rzv2h)

 - Fix premature reset during timeout update, and propagate error code
   in msc313e resume()

 - Fix pci_dev reference leak in sp5100_tco_init()

 - Fix runtime PM leak in starfive_wdt_pm_start()

* tag 'watchdog-fixes-for-v7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/groeck/linux-staging:
  watchdog: da9063: fix suspend/resume handling of HW_RUNNING watchdog
  watchdog: starfive-wdt: Fix runtime PM leak in starfive_wdt_pm_start()
  watchdog: da9062: fix suspend/resume handling of HW_RUNNING watchdog
  watchdog: msc313e: Fix premature reset during timeout update
  watchdog: msc313e: Propagate error code in resume()
  watchdog: rzv2h: Avoid division by zero
  watchdog: rtd119x: Avoid division by zero
  watchdog: digicolor: Avoid division by zero
  watchdog: sp5100_tco: Fix pci_dev reference leak in sp5100_tco_init()
2026-09-18 10:18:32 -07:00
Linus Torvalds
5ad17a9760 This push fixes a regression in caam.
-----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEn51F/lCuNhUwmDeSxycdCkmxi6cFAmqqZ7AACgkQxycdCkmx
 i6d4jA/+Ozs275ubKEbaC+keI4/G8DZ/QDYFOTCr4SEBWHyhGh1od29AbHXhUGof
 3Ev/Zzqg9mWRDhLo+tbx/ja9Qe3d7lHCHPcFPUsom0MumfGm8NaWgGxaxrrhRYwY
 EOks6UxolxUCw65/ECxcgxsOfp6LgcrNuapkIJRcg1R5s6kz9zAGhse+13AgAv1G
 49x+AL1KkvJkPev6lZrhG+m0SX3P7CO5OVAe0NNFqSlaxBSg3JSO/JnEQK95B7vi
 cakFjskdfukqQs84hOq+KPI93pqbi7aZEemVsxGK2UdADVRr7C3Ls6nKiGQ7VtyR
 EW2hniQxHOruvDrXHMJpE92/Tw7g0LL6O5CZuKe+p2MfnQKEvVpPuWwysug0AhVU
 cKV4mBX/fu2bgV7o2QEGByhhAuCtcezGqbX5o2cYLdn/jX2DErNTWzLbdUHpcgLu
 bTWtIWzEwKZgqU5Oa9i4J6TdV6xcReh7gKKWykrQVodnvin6sUywsMmX3vkl33VJ
 upVo1FhLZnv0krUMTGUDNTzuVczEliM8c+dMEJcGLAzM3d0SdduRSukznX09Wrj8
 yS0AH3Tqn81Ux5FWYxNMPSeKaTIRX14LG3jjzsLSq9iMTM50dZf6xmOS9ZyYh/+j
 tq3fPrBf3PVipdI9xhDOqDF9gYtG+FgVwt93Pb0Ao569HgWyS5c=
 =odnL
 -----END PGP SIGNATURE-----

Merge tag 'v7.3-p4' of git://git.kernel.org/pub/scm/linux/kernel/git/herbert/crypto-2.6

Pull crypto fix from Herbert Xu:
 "Fix a regression in caam"

* tag 'v7.3-p4' of git://git.kernel.org/pub/scm/linux/kernel/git/herbert/crypto-2.6:
  crypto: caam - map job ring registers without claiming region
2026-09-18 10:01:31 -07:00
Linus Torvalds
f259f446f5 soc: fixes for 7.3
The driver fixes are all for simple mistakes: a use-after-free bug
 on Samsung Exynos, error handling and reference counting on Arm SCMI
 firmware and a problem dealing with inconsistent firmware information.
 
 The rest are devicetree fixes for arm64 platforms from Altera, Renesas
 and Amlogic. On the Renesas platform, one patch addresses a boot time
 regression, the rest address minor performance and correctness issues.
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEo6/YBQwIrVS28WGKmmx57+YAGNkFAmqtProACgkQmmx57+YA
 GNku+BAAsyHGF7f7tniVyH1lDfZ+BY8G0i8856Pgi6xJfwTPcrtxJe15ALFJz5sa
 DRvCmt3fx2e4LmED2wEfTVYr+RIEmlgD27pT8lUvMo4avIcXlIxtAlqCOyKTOALS
 LzOJPD5VaEs/ZKXqqGDPnHzYJNO9DJ18uAuk8yGY7cK4z4IV+aANCJzCN83vhYu2
 OAl37i/0PmaMhHTgLgIugd2uc28GJsyZQiFu9k9hlRWGjn9WpYivSohbF8p8Cqcw
 Eg/TzWVNcTrm95uuHbhaQ3tsYDtBHoy5V7e5w1a4NnJ7ufouW/I1Z9s2OrulWadY
 3Hw/pEtrkWAgK1NMfAaXtErkWUjuKeMRzWwOZ0NR4Zi0Zsdt+VTyDajSLbUEuePI
 AfknmGcrgSIgK/HlSkLw5R0VnYI8duUjnBSDVTKBLMxFnAdBs/vDhr/ZDy8HgLjN
 i+Poe36q6JLTw88/d/uF+2T2HdZXwPiL9tDl16WmAUQOvZOcr6dfQdLZGIb8zwuV
 rghM9rnh7v2Lb5nFsC++MebH2xNw33faWplpnc0WxcUdzov20Wcr7IbdNVzKaVTn
 IcnjnTtCCaxXM9NxyjMrxJ8+tkkFAPyDczSPxcxL3xcOjoQ2nr4XlfPMaYwoV2N7
 siwksezj55bWANuZwxObou3ZJgHHFqO0RYUdtJxDn/mBnWNOq3A=
 =Z5GP
 -----END PGP SIGNATURE-----

Merge tag 'soc-fixes-7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/soc/soc

Pull SoC fixes from Arnd Bergmann:
 "The driver fixes are all for simple mistakes: a use-after-free bug on
  Samsung Exynos, error handling and reference counting on Arm SCMI
  firmware and a problem dealing with inconsistent firmware information.

  The rest are devicetree fixes for arm64 platforms from Altera, Renesas
  and Amlogic. On the Renesas platform, one patch addresses a boot time
  regression, the rest address minor performance and correctness issues"

* tag 'soc-fixes-7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/soc/soc: (21 commits)
  soc: samsung: exynos-pmu: fix use-after-free of interrupt generator node
  arm64: dts: renesas: r8a779f0: Set UFS lane count
  firmware: arm_scmi: Fix typo "upto" in comment
  arm64: dts: renesas: r9a09g087: Switch GBETH TX queue scheduling to WRR
  arm64: dts: renesas: r9a09g077: Switch GBETH TX queue scheduling to WRR
  arm64: dts: renesas: r9a09g047: Switch GBETH TX queue scheduling to WRR
  arm64: dts: renesas: r9a09g056: Switch GBETH TX queue scheduling to WRR
  arm64: dts: renesas: r9a09g057: Switch GBETH TX queue scheduling to WRR
  firmware: arm_ffa: Tear down driver during shutdown
  clk: scpi: use PLATFORM_DEVID_NONE for scpi-cpufreq
  clk: scpi: register scpi-cpufreq once and clear on failure
  clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate
  firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS
  firmware: arm_scpi: fix device_node leak in scpi_dev_domain_id
  arm64: dts: socfpga: change access permission from 755 to 644
  ARM: socfpga: select the PL310 erratum 753970 workaround
  arm64: dts: amlogic: t7: fix the pin groups of the vsync PWM
  arm64: dts: amlogic: t7: khadas-vim4: add the PWM-driven supplies
  arm64: dts: amlogic: t7: fix the pin groups of two PWM outputs
  arm64: dts: amlogic: t7: khadas-vim4: allow the SD card to be power cycled
  ...
2026-09-18 09:34:57 -07:00
Linus Torvalds
a077be4fde arm64 fixes for -rc4
- Fix hypercall arguments when resetting EL2 vectors during hibernation
 
 - Fix hibernation with 52-bit capable kernels on machines without
   52-bit addressing, similarly to the recent kexec fix
 
 - Fix a bunch of clumsy codegen issues with our per-cpu accessors
 
 - Fix MTE ptrace documentation to reflect the de-facto ABI behaviour
 
 - Fix pthread_join() usage in MTE selftest
 
 - Fix port selection in the Arm CMN PMU driver
 -----BEGIN PGP SIGNATURE-----
 
 iQFEBAABCgAuFiEEPxTL6PPUbjXGY88ct6xw3ITBYzQFAmqtMZ4QHHdpbGxAa2Vy
 bmVsLm9yZwAKCRC3rHDchMFjNNujB/4pa4pdivXRMOH39HSDu+8i3KlREGpTA9dq
 LJvwUjlgoIw0d8/b5sMSAxJi8RA29IENJPqrU97eBBLKgC2gq1oMwjOaHNTV8XUj
 gal9hwuZcfO5NIJi61TkyLxn++ysVYXD3J0tbhSXbqz2oeg/jxwj9SsFfQux34GY
 GeGb2cWvEXznLgN0h+vZiNh6+FsQRN+dizpiHKLh+wpbZ/vIzuVTQEo6w/+BEUWg
 R4YQlvpj/2yAC0BBdPb9gALUWFbjea6zpX5gM5/PgLoqW0CIJvGXahZ7T5kDoXBT
 Xp5zsKvcC8dxM5nCJIJ7xRPg75v97toYrrl2AoNQN9bgOynQAI5k
 =j0NQ
 -----END PGP SIGNATURE-----

Merge tag 'arm64-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux

Pull arm64 fixes from Will Deacon:
 "In this batch we've got a couple of hibernation fixes, a couple of
  minor MTE fixes, some per-cpu codegen fixes (which were found as part
  of Mark's series adding preemptible this_cpu_*() operations) and a fix
  for the Arm CMN PMU driver.

  Summary:

   - Fix hypercall arguments when resetting EL2 vectors during
     hibernation

   - Fix hibernation with 52-bit capable kernels on machines without
     52-bit addressing, similarly to the recent kexec fix

   - Fix a bunch of clumsy codegen issues with our per-cpu accessors

   - Fix MTE ptrace documentation to reflect the de-facto ABI behaviour

   - Fix pthread_join() usage in MTE selftest

   - Fix port selection in the Arm CMN PMU driver"

* tag 'arm64-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux:
  arm64: mte: Fix PTRACE_{PEEK,POKE}MTETAGS error documentation
  kselftest/arm64: Fix size of thread_data values for pthread_join()
  arm64: percpu: Fix LSE operations on {8,16}-bit types
  arm64: percpu: Fix this_cpu_and() mask generation
  arm64: percpu: Fix this_cpu_write() casting
  arm64: hibernate: clone only the linear map that exists at runtime
  perf/arm-cmn: Fix wp_dev_sel2 setting for multi-DTM configurations
  arm64: hibernate: pass HVC_SET_VECTORS args to the resume hvc
2026-09-18 09:28:30 -07:00
Linus Torvalds
5023f5b861 - Fix kconfig dependencies for ECONET
- Enable weak reordering for EYEQ
 - Include USB FDT fixup for Octeon even when USB is modular
 -----BEGIN PGP SIGNATURE-----
 
 iQJOBAABCAA4FiEEbt46xwy6kEcDOXoUeZbBVTGwZHAFAmqs5dUaHHRzYm9nZW5k
 QGFscGhhLmZyYW5rZW4uZGUACgkQeZbBVTGwZHBYbg//QPIXQOga1IcvP7OJlLxu
 UocYmNpgVJtPCksDtnBUx82o/D+CZdqeGtHNP6ak5YpyXOcQpUdMuYSwHwIXsHLB
 HhVOBmyVgyNlP0zo8zXE3iW1JMz1wfSSigDZdPFX8Jq3O5RsMq3udHJYZtAEXnIM
 eV8m465I9DnJWX9mlETqTli5cwL5VpDYRSy1fmGF4CYgRvbErrUZ0iZSvqdwRe7v
 J/p+sLBsSmEoxXL5etpvHLet+Jr9Eb8v+1k8262YcoPfvENeu3cYJpvZnIgXmeol
 T912xD+JmLapcICNot0QvrMZJ3RVSu/Z6ddxCGqHmiEiQGMYB9xrWYbgfQ/9hGKp
 aup5G1X3n3YPKd60DKRnSFgZ4+xPzEoUTh5nKlMz0XqZmtoa9m00BRTXhi8XoqFK
 kvBRJREb4Za3Ig40dhIJTcluLoLjgPqUs+1MfwnFnXZTbuctSZ4BtEauQL1x/A6E
 EbQ7gvesMQHUwW6fb70U9UbhlKuI/8t1Ao7OuI5+qs6+qnvgiScavW8CDu+W16s1
 tbFQFUN1ZkP0a0SXkl5JGu6WOkl9fc3TkBDrmfuK68Fu2hUMAiE/ffCoBq+6iZBj
 pkagkDr5CjFxogpKveE02l9WJAVAujzMmyCusTv2NQ53mu2ZloCT3BA3cKsM6vFP
 dPtQD7d5qIEK3WPMENxCrcA=
 =PNfi
 -----END PGP SIGNATURE-----

Merge tag 'mips-fixes_7.3_1' of git://git.kernel.org/pub/scm/linux/kernel/git/mips/linux

Pull MIPS fixes from Thomas Bogendoerfer:

 - Fix kconfig dependencies for ECONET

 - Enable weak reordering for EYEQ

 - Include USB FDT fixup for Octeon even when USB is modular

* tag 'mips-fixes_7.3_1' of git://git.kernel.org/pub/scm/linux/kernel/git/mips/linux:
  MIPS: Octeon: apply USB FDT fixups also when USB is modular
  mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ
  MIPS: config: Add EcoNet EN751221 defconfig
  mips: econet: fix unmet dependencies for ECONET
2026-09-18 09:25:07 -07:00
Li Jun
7cb575b71a watchdog: da9063: fix suspend/resume handling of HW_RUNNING watchdog
da9063_wdt_suspend() and da9063_wdt_resume() only check watchdog_active(),
when the watchdog is left running by the driver sets
WDOG_HW_RUNNING in da9063_wdt_probe() but userspace never opens the
device, so WDOG_ACTIVE remains cleared, the wdt_disable() will not be
executed in da9063_wdt_suspend. In this case, the suspend callback is
a no-op and the watchdog keeps counting during system suspend,
leading to an unexpected system reset.
Check WDOG_HW_RUNNING and wdd,can fix this issue.

Fixes: a7ceca4398 ("watchdog: da9063: optionally disable watchdog during suspend")
Cc: stable@vger.kernel.org
Signed-off-by: Li Jun <lijun01@kylinos.cn>
Link: https://patch.msgid.link/20260917013710.2754679-1-lijun01@kylinos.cn
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
2026-09-18 08:10:45 -07:00
Alexey Klimov
4dd1999783
soc: samsung: exynos-pmu: fix use-after-free of interrupt generator node
The setup_cpuhp_and_cpuidle() parses the device tree node for the
interrupt generation block via of_parse_phandle() and decrements its
reference count using of_node_put() immediately after fetching the resource
address. However, later the intr_gen_node pointer is passed into
of_syscon_register_regmap().

Fix this by declaring intr_gen_node with __free() and removing
of_node_put().

Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/20260513-exynos850-cpuhotplug-v4-0-54fec5f65362@linaro.org?part=3
Fixes: 78b72897a5 ("soc: samsung: exynos-pmu: Enable CPU Idle for gs101")
Cc: stable@vger.kernel.org
Signed-off-by: Alexey Klimov <alexey.klimov@linaro.org>
Link: https://patch.msgid.link/20260828-exynos-pmu-cpuhp-idle-fixes-v2-1-06bce6107bd6@linaro.org
Signed-off-by: Krzysztof Kozlowski <krzk@kernel.org>
Link: https://lore.kernel.org/r/20260917081641.72291-2-krzk@kernel.org
Signed-off-by: Arnd Bergmann <arnd@arndb.de>
2026-09-18 14:39:19 +02:00
Arnd Bergmann
2d5061ff37 Renesas fixes for v7.3 (take two)
- Fix UFS regression on R-Car S4.
 -----BEGIN PGP SIGNATURE-----
 
 iHUEABYKAB0WIQQ9qaHoIs/1I4cXmEiKwlD9ZEnxcAUCaqztfAAKCRCKwlD9ZEnx
 cLmlAP4hG63oxIP1QUeZpEMjRkTBGhFXnlSkvluVyrd8otWniQEAvCCC31KtKqqK
 B9W1mWzwBX9UITXB4cL69Zw/26W9+QI=
 =5xv9
 -----END PGP SIGNATURE-----
gpgsig -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEo6/YBQwIrVS28WGKmmx57+YAGNkFAmqtL8EACgkQmmx57+YA
 GNkQ9A/9FuSvFGANim6ksz5JN4ObTC4hjJu8rxrxF3uGekQNJZPO06EDU9DkM/bJ
 XOLDFkt3k+M3e60wdH9NKzEl54xQxyLre2XyRN2diit3ihDF9Jrv3YPFzuZcA+gR
 vmRh9LLIStdDNxGbRrEubfx1+WqbiNpkXqE8syXVsn93hYduMsWnrSReXA5jGENt
 Wjq9ghujL9Othgh8B1FOi6W4oupsBN1mCLAL0DJ0k8z0whBfb2Qkq5tnrDCPcjXc
 CVKzVWqe5nIMw5akMu14MToId3JpTxTrws5FOP4OUoxEVL/sCBUbS4PNujgHEMVh
 Ovd5DmpfNjWOB+rr4/B/u2H97e6AmNvCp5Sbd8gADBCO7RHD9zxYbGYPy9Pemhqd
 YBNAufAR3Bkkq0IheXVS5Dtzg2TSUchomaIz7o/hhMBu4lLdaVJyyalAy5bVOR1W
 l7DtetG1DqABWAsF5pm0Q8iy7lFEJlzWdhzONJn4TBCXOLi6k3lO07gmd+eIYhyM
 EvssZFTciDoyhurdDgqeLfjKQvvgiOi0l4SpdT606+YMipz5C5zo0oPOk4j26qvp
 22Mw3JupFQCDCwsN37locBhQccdKfHuzfsy52vDMxHRuOcpnfIIcCsPkaMq5VMQu
 Bm8c3No5AJQGcODe4Rg7nmZrxzSNnilWGxKSkWH7C0J5vbzuXRY=
 =9HfJ
 -----END PGP SIGNATURE-----

Merge tag 'renesas-fixes-for-v7.3-tag2' of git://git.kernel.org/pub/scm/linux/kernel/git/geert/renesas-devel into arm/fixes

Renesas fixes for v7.3 (take two)

  - Fix UFS regression on R-Car S4.

* tag 'renesas-fixes-for-v7.3-tag2' of git://git.kernel.org/pub/scm/linux/kernel/git/geert/renesas-devel:
  arm64: dts: renesas: r8a779f0: Set UFS lane count

Signed-off-by: Arnd Bergmann <arnd@arndb.de>
2026-09-18 14:34:03 +02:00
Matthew Schwartz
96443a53bc selftests/x86: Check signal state for rejected software interrupts
Add a test of the signal ABI for INT instructions in both 32-bit and
64-bit processes. Check the signal number, trap number, error code,
si_code, si_addr, instruction pointer and RF/TF state against legacy
IDT behavior. Include a 15-byte prefixed INT to check that IP uses the
hardware instruction length. Exercise both INT3 encodings, INT4, UD2
and HLT to cover the unchanged trap and fault paths.

Run each instruction with TF clear and set. Resume at a known NOP after
handling the signal and check that single-stepping traps after the NOP.

Also drive INT 0x2d under ptrace, which resumes through the fault frame
rather than sigreturn and so exposes a stale FRED software event flag.
Start from an INT3 stop, whose FRED frame has no software event flag,
instead of the syscall frame of raise(SIGSTOP). Single-step into the INT
and check that the fault reports its address. Then suppress SIGSEGV and
resume at the NOP, once with PTRACE_SINGLESTEP and once with PTRACE_CONT
and TF set. Section 6.2.3 of the Intel FRED specification [1] specifies
the immediate single-step trap caused by returning with both that flag
and TF set. Check that each trap occurs after the NOP, rather than at
its address.

Report whether the CPU supports FRED, since a pass looks the same on
either entry path. INT 0x80 with IA32 emulation disabled and a 64-bit
tracer of a 32-bit tracee are not covered.

Both variants pass all 29 checks on a non-FRED AMD host and on Panther
Lake with FRED enabled and the fix applied. With the same binaries on
unpatched Panther Lake, 16 signal-context checks fail and the first
ptrace check reports the IP after the INT. The two dependent ptrace
resume checks are not reached.

[1] Intel Flexible Return and Event Delivery (FRED) Specification,
revision 9.0 (346446-009US), section 6.2.3.

Signed-off-by: Matthew Schwartz <matthew.schwartz@linux.dev>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Link: https://cdrdv2.intel.com/v1/dl/getContent/678938 # [1]
Link: https://patch.msgid.link/20260917230907.2080792-3-matthew.schwartz@linux.dev
2026-09-18 12:33:18 +02:00
Matthew Schwartz
93f53499d0 x86/fred: Reconstruct the #GP context for rejected INT instructions
FRED event delivery does not use the IDT, so the gate DPL check that
rejects a user INT n falls to software (Intel FRED specification [1],
section 8.3). fred_intx() rejects the same vectors as IDT delivery, but
reports a zero error code and the IP after the INT. This breaks the
signal ABI. Wine uses the error code to recognize INT 0x2d, so the
changed context turns a handled breakpoint into an access violation in
Elden Ring.

Rewind IP using the instruction length in the augmented SS and
synthesize the IDT selector error code, (vector << 3) | 2. Set RF in the
saved flags, as the CPU does for a #GP fault. Section 5.2.1 defines the
saved vector, instruction length and RF state. The supplied length
handles prefixes without reading user memory. Limit the changes to
already-rejected software interrupts, preserving the accepted INT3, INT4
and enabled INT80 paths and hardware exceptions. With IA32 emulation
disabled, INT 0x80 now reports the same #GP as the DPL 0 gate IDT
installs there. The rewound IP also stops fixup_iopl_exception() from
inspecting the byte after the INT.

Also clear the software event flag. Section 6.2.3 specifies that ERETU
with this flag and TF set traps before executing any user instruction. A
tracer that suppresses SIGSEGV and resumes with TF set expects the next
instruction to run first, as after IRET. The sigreturn path clears the
same flag for this reason in prevent_single_step_upon_eretu().

[1] Intel Flexible Return and Event Delivery (FRED) Specification,
revision 9.0 (346446-009US), sections 5.2.1, 6.2.3 and 8.3.

Fixes: 14619d912b ("x86/fred: FRED entry/exit and dispatch code")
Closes: https://gitlab.freedesktop.org/mesa/mesa/-/work_items/15745
Closes: https://gitlab.freedesktop.org/mesa/mesa/-/work_items/16132
Reported-by: Paul Gofman <pgofman@codeweavers.com>
Signed-off-by: Matthew Schwartz <matthew.schwartz@linux.dev>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Reviewed-by: H. Peter Anvin <hpa@zytor.com>
Link: https://cdrdv2.intel.com/v1/dl/getContent/678938 # [1]
Link: https://patch.msgid.link/20260917230907.2080792-2-matthew.schwartz@linux.dev
2026-09-18 12:33:17 +02:00
Andrea Righi
fe3c73d7bc sched/core: Avoid false migration warning for proxy donors
Proxy execution can move a blocked donor's scheduling context to the
lock owner's CPU even when the donor is migration-disabled. The donor
does not execute there, and its original execution CPU remains recorded
in wake_cpu.

set_task_cpu() warns unconditionally for migration-disabled tasks, so a
subsequent proxy migration or the wakeup path returning the donor home
triggers a false positive: moving a blocked scheduling context does not
violate the migration-disabled execution context.

For example, creating a mutex owner on CPU1 and a migration-disabled
waiter on CPU0 can trigger the following warning:

  proxy_migrate_repro: donor blocking on CPU0 with migration disabled
  proxy_migrate_repro: donor moved from CPU0 to CPU1
  WARNING: kernel/sched/core.c:3389 at set_task_cpu+0x1d3/0x280
  ...
  Call Trace:
   try_to_wake_up+0x43f/0x780
   __mutex_unlock_slowpath+0x330/0x540
   owner_fn+0x9f/0xc0 [proxy_migrate_repro]
  ...
  proxy_migrate_repro: donor woke on CPU0, task_cpu=0
  proxy_migrate_repro: completed

Exclude blocked proxy donors from the warning. The proxy wakeup path
restores an executable placement before clearing the blocked state.

Fixes: b049b81bdf ("sched: Handle blocked-waiter migration (and return migration)")
Signed-off-by: Andrea Righi <arighi@nvidia.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Acked-by: John Stultz <jstultz@google.com>
Link: https://patch.msgid.link/20260915184101.2621252-1-arighi@nvidia.com
2026-09-18 12:19:43 +02:00
Vinay Belgaumkar
88aed0422f perf: Fix null pointer access in is_include_guest_event()
A typical module unload occurring event when there is an active perf
connection leads to freeing of the pmu pointer. The call log is something
like:
 ..
 __pmu_detach_event
 pmu_detach_event
 pmu_detach_events
 perf_pmu_unregister
 ..

__pmu_detach_event() sets event->pmu to null. When the perf connection
finally is closed, the following stack trace is observed:

 Oops: general protection fault, kernel NULL pointer dereference
 ...
 RIP: 0010:_free_event+0x3e/0x370
 ...
 Call Trace:
 ...
 perf_event_release_kernel+0x260/0x2d0
 perf_release+0x12/0x20

A call to mediated_pmu_unaccount_event() inside _free_event() is the root
cause of this crash. Adding a check inside is_include_guest_event() ensures
we don't accidentally access a null pmu ptr. In addition to this, we will
now call mediated_pmu_unaccount_event() before clearing the pmu ptr so that
nr_include_guest_events counts are maintained correctly.

Fixes: eff95e1702 ("perf: Add APIs to create/release mediated guest vPMUs")
Assisted-by: Claude:Claude-Sonnet-5
Signed-off-by: Vinay Belgaumkar <vinay.belgaumkar@intel.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Reviewed-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
Link: https://patch.msgid.link/20260904181625.1394082-1-vinay.belgaumkar@intel.com
2026-09-18 12:19:43 +02:00
Dave Airlie
94f69bfa18 amd-drm-fixes-7.3-2026-09-17:
amdgpu:
 - SMU 14.x fix
 - DC IRQ fix
 - Runtime PM fix for P2P
 - RAS fix
 - PCIe reporting fix
 - DCN 6 fix
 - Device removal fix
 - DC MALL fix
 
 amdkfd:
 - GC 12.x fixes
 - Boundary checks
 - Mapping clear fix
 -----BEGIN PGP SIGNATURE-----
 
 iHUEABYKAB0WIQQgO5Idg2tXNTSZAr293/aFa7yZ2AUCaqxIpQAKCRC93/aFa7yZ
 2HcZAP9ZA5cERbp6QfT0a1tT3kDoMP02BKev5/XUNWEJjdgOYAEAsCj7UFE4oKjb
 0996gK/lJvqq9lOgFTJnwl/z2jwytA0=
 =Ye34
 -----END PGP SIGNATURE-----

Merge tag 'amd-drm-fixes-7.3-2026-09-17' of https://gitlab.freedesktop.org/drm/amdgpu/kernel into drm-fixes

amd-drm-fixes-7.3-2026-09-17:

amdgpu:
- SMU 14.x fix
- DC IRQ fix
- Runtime PM fix for P2P
- RAS fix
- PCIe reporting fix
- DCN 6 fix
- Device removal fix
- DC MALL fix

amdkfd:
- GC 12.x fixes
- Boundary checks
- Mapping clear fix

Signed-off-by: Dave Airlie <airlied@redhat.com>

From: Alex Deucher <alexander.deucher@amd.com>
Link: https://patch.msgid.link/20260917201213.3880863-1-alexander.deucher@amd.com
2026-09-18 11:24:43 +10:00
Dave Airlie
cd011719ba Merge tag 'drm-intel-fixes-2026-09-17' of https://gitlab.freedesktop.org/drm/i915/kernel into drm-fixes
drm/i915 fixes for 7.3-rc4:
- Revert a commit touching registers that don't necessarily exist
- Check for negative numbers before passing to BIT()

Signed-off-by: Dave Airlie <airlied@redhat.com>
From: Jani Nikula <jani.nikula@intel.com>
Link: https://patch.msgid.link/3f86e0ede95fb3d52053934ac43c5271812428f5@intel.com
2026-09-18 11:08:19 +10:00
Dave Airlie
c24f824f0b Couple shrinker related fixes plus a series of patches fixing several
xe_mmio_gem issues around fault handler and destroy path.
 -----BEGIN PGP SIGNATURE-----
 
 iQEzBAABCgAdFiEEbSBwaO7dZQkcLOKj+mJfZA7rE8oFAmqr550ACgkQ+mJfZA7r
 E8p3UggAtIEI+BFbK7zeELK3zEtO85WQnIvUP/PprLu9Ga7Vvl+quXxZrWCHYcIE
 VwcK/5y2BGVKBmR1Vwm+PNBmtlbrNvIPGTn9u0oXB1bWVKqPT5o5MjY7lxdWhK95
 MkLFo7rsQM791DAEUeo6IzbdHd6K9k2At8Yzz5+1zt97zxGmXSNpGRxV6Ee8/crU
 e/B1cQSfY8I4sjhAormTLZ13M6vRh1Yoy5P21UdCqIU/Eq/PjpkW2bcmM6+8K+qO
 2a4y2CHIQnd+2bR4nEnuHYIa6DVuXEZIHh5v/8amenuZqBgVj7OcxUKiiZ4TnhMY
 bGe1UFyy0OWyEJ/X4ddGfCggpiFi6w==
 =0FwX
 -----END PGP SIGNATURE-----

Merge tag 'drm-xe-fixes-2026-09-17' of https://gitlab.freedesktop.org/drm/xe/kernel into drm-fixes

Couple shrinker related fixes plus a series of patches fixing several
xe_mmio_gem issues around fault handler and destroy path.

Signed-off-by: Dave Airlie <airlied@redhat.com>

From: Rodrigo Vivi <rodrigo.vivi@intel.com>
Link: https://patch.msgid.link/aqvoKaPuLLPBGayA@intel.com
2026-09-18 11:08:01 +10:00
Chang S. Bae
e7d3e2f46d x86/microcode/intel: Reject problematic loading on Granite Rapids systems
Microcode updates can usually jump revisions. However, there is an erratum on
Granite Rapids systems. If they "jump over" revision 0x1000405, they result in
an #MC. Avoid it.

Signed-off-by: Chang S. Bae <chang.seok.bae@intel.com>
Signed-off-by: Borislav Petkov (AMD) <bp@alien8.de>
Reviewed-by: Dave Hansen <dave.hansen@linux.intel.com>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260916225939.1144524-1-chang.seok.bae@intel.com
2026-09-17 16:54:20 -07:00
Linus Torvalds
5dd1818b15 Hi
Please pull these bug fixes for keys accumulated since v7.3-rc1.
 
 BR, Jarkko
 -----BEGIN PGP SIGNATURE-----
 
 iHUEABYKAB0WIQRE6pSOnaBC00OEHEIaerohdGur0gUCaqxgxQAKCRAaerohdGur
 0jQdAQDG18jcqZxuj+DC4H5FIqRNBn+YhhRA2iOT1Qwc6wSpNAEAkgl6rdm4KY8l
 EQj0HTbX8qEXSsuGGkoA41lYlwf0pAY=
 =jCQU
 -----END PGP SIGNATURE-----

Merge tag 'for-next-keys-v7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/jarkko/linux-tpmdd

Pull key fixes from Jarkko Sakkinen.

* tag 'for-next-keys-v7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/jarkko/linux-tpmdd:
  KEYS: encrypted: fix integer overflow of datablob_len
  KEYS: trusted: Fix tpm2_load_cmd() boundary check
  keys: translate request_key_auth pid for the reading procfs instance
  keys: fix lost wakeup when reaping a dead key type
2026-09-17 16:53:26 -07:00
Wentao Liang
717e0a2503 cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
When a secondary channel is no longer supported by the server,
cifs_chan_skip_or_disable() drops the channel reference with
cifs_put_tcp_session() and then continues to use the server pointer by
calling cifs_signal_cifsd_for_reconnect() on it and reading its
primary_server pointer. cifs_put_tcp_session() can drop the last
reference of the channel and tear it down, so both the channel and the
primary server (whose reference is also dropped by
cifs_put_tcp_session()) can be freed before they are signaled for
reconnect.

Signal the channel and the primary server and capture the primary
server pointer before dropping the channel reference with
cifs_put_tcp_session().

Fixes: f591062bdb ("cifs: handle servers that still advertise multichannel after disabling")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
2026-09-17 19:29:25 -03:00
Richard Zhu
c9dc7d7303 PCI: imx6: Move clock enable after core reset assertion
Commit 610fa91d98 ("PCI: imx6: Assert PERST# before enabling regulators")
inadvertently moved clock enablement before core reset assertion, breaking
PCI device initialization on i.MX6Q Apalis platforms with
ASM1061/ASM1062 SATA controllers connected:

  imx6q-pcie 1ffc000.pcie: host bridge /soc/pcie@1ffc000 ranges:
  imx6q-pcie 1ffc000.pcie:       IO 0x0001f80000..0x0001f8ffff -> 0x0000000000
  imx6q-pcie 1ffc000.pcie:      MEM 0x0001000000..0x0001efffff -> 0x0001000000
  imx6q-pcie 1ffc000.pcie: config reg[1] 0x01f00000 == cpu 0x01f00000
  imx6q-pcie 1ffc000.pcie: iATU: unroll F, 4 ob, 4 ib, align 64K, limit 4G
  imx6q-pcie 1ffc000.pcie: Link: Only Gen1 is enabled
  imx6q-pcie 1ffc000.pcie: Link failed to come up. LTSSM: POLL_CONFIG
  imx6q-pcie 1ffc000.pcie: probe with driver imx6q-pcie failed with error -110

NOTE: It is not 100% clear if the issue is specific to the ASM1061/ASM1062
device or on the specific power-up sequence (reset vs cold-power-on).

To fix this regression, restore the original sequence where clocks are
enabled after asserting core reset and configuring the controller type.

Fixes: 610fa91d98 ("PCI: imx6: Assert PERST# before enabling regulators")
Reported-by: Leonardo Costa <leoreis.costa@gmail.com>
Closes: https://lore.kernel.org/all/bl7i3obu2clzsgeoct2a4mtfhv6typcjdqmgneropf3hpgwve6@n2m5uhlduw57/T/#u
Reported-by: Franz Schnyder <fra.schnyder@gmail.com>
Closes: https://lore.kernel.org/all/t65y5d54axtksbfs7r4olcefqhwm6m4dz3njgnrnf7fcotj74i@o7avoznlafbj/
Signed-off-by: Richard Zhu <hongxing.zhu@nxp.com>
Signed-off-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
[bhelgaas: move to pci/for-linus for v7.3]
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Cc: stable@vger.kernel.org # 7.2+
Link: https://patch.msgid.link/20260813095003.356062-1-hongxing.zhu@oss.nxp.com
2026-09-17 16:54:34 -05:00
Frieder Schrempf
3d743adf09
spi: fsl-qspi: Reprogram the clock rate when the operation frequency changes
fsl_qspi_select_mem() returns early when the chip select has not changed,
which happens before it reaches clk_set_rate(). Since the rate is now
taken from the spi-mem operation rather than from the SPI device, the
controller honours op->max_freq exactly once per chip select and ignores
it for every operation after that.

q->selected is only reset to -1 in fsl_qspi_default_setup(), i.e. at probe
and on resume, so on the common single chip select board the very first
operation latches a rate that all subsequent operations inherit, whatever
frequency they asked for.

This results in operations being issued with the wrong frequency.

Cache the operation frequency the clock was programmed for next to the
selected chip select, and redo the clock setup when either changes.

Fixes: 2438db5253 ("spi: fsl-qspi: Support per spi-mem operation frequency switches")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-5
Signed-off-by: Frieder Schrempf <frieder.schrempf@kontron.de>
Acked-by: Han Xu <han.xu@nxp.com>
Link: https://patch.msgid.link/20260917-fsl-qspi-freq-op-fix-v1-1-5fbe6b02f738@kontron.de
Signed-off-by: Mark Brown <broonie@kernel.org>
2026-09-17 19:46:29 +01:00
Frank Sorenson
5f0306e731 smb: client: fix reparse buffer bounds in cifs_query_reparse_point()
In cifs_query_reparse_point(), the start >= end check before casting to
struct reparse_data_buffer * only ensures the start pointer is within the
response. It fails to verify that there is enough space remaining for the
fixed 8-byte header of the structure.

If a server provides a DataOffset that leaves less than 8 bytes remaining,
the check passes, but subsequent reads of ReparseTag and ReparseDataLength
will occur out-of-bounds.

Fix this by ensuring the remaining space is at least the size of the
reparse_data_buffer structure before accessing its fields.

Fixes: 56e84c64fc ("cifs: Fix validation of SMB1 query reparse point response")
Cc: stable@vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
Reviewed-by: David Howells <dhowells@redhat.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
2026-09-17 15:04:26 -03:00
Frank Sorenson
4775c3b7a5 smb: client: fix potential OOB read in smb3_enum_snapshots()
If snapshot_array_size is smaller than GMT_TOKEN_SIZE,
smb3_enum_snapshots() sets ret_data_len to
sizeof(struct smb_snapshot_array) without verifying the actual length
of the server's reply.

Because SMB2_ioctl() places no lower bound on the server-supplied
OutputCount and allocates retbuf to exactly that length, a short reply
results in ret_data_len exceeding the size of retbuf. The subsequent
copy_to_user() then reads past the end of retbuf, leaking adjacent slab
memory to userspace.  The subsequent clamp check is ineffective as it
only reduces ret_data_len.

Fix this by rejecting replies shorter than
sizeof(struct smb_snapshot_array) with -EIO. Note that the bound is set
to the 12-byte struct size rather than the 16-byte
MIN_SNAPSHOT_ARRAY_SIZE defined in MS-SMB2 3.3.5.15.1, because 12 bytes
is exactly what copy_to_user() attempts to read.

Fixes: e02789a53d ("smb3: enumerating snapshots was leaving part of the data off end")
Cc: stable@vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
Reviewed-by: David Howells <dhowells@redhat.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
2026-09-17 15:04:20 -03:00
Frank Sorenson
b09d092eb2 smb: client: fix missing iov bounds check in parse_posix_sids()
In parse_posix_sids(), sidsbuf_end is calculated using the server-supplied
out_len without being validated against the actual length of the received
iov (iov_len).

If a server provides an inflated out_len, sidsbuf_end will point past the
end of the iov. This defeats the bounds guards in posix_info_sid_size(),
allowing out-of-bounds reads into adjacent kernel memory.

Fix this by rejecting responses where the calculated sidsbuf_end would
exceed the received iov boundaries or cause pointer wraparound.

Fixes: a90f37e3d7ac ("smb: client: parse owner/group when creating reparse points")
Cc: stable@vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
Reviewed-by: David Howells <dhowells@redhat.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
2026-09-17 15:04:12 -03:00