mirror of
https://github.com/torvalds/linux.git
synced 2026-10-07 19:16:02 +02:00
156fa7417f
1483416 Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
156fa7417f |
x86 fixes:
- Reject the loading of a potentially problematic microcode version
on Intel Granite Rapids systems (Chang S. Bae)
- On FRED, reconstruct the proper #GP context for rejected INT
instructions, to fix a signal ABI regression (Matthew Schwartz)
- Add a test for this signal ABI regression the x86
self-test suite (Matthew Schwartz)
- Don't emit the new and not yet properly supported EGPR instructions
(%r16-%r31) on CONFIG_X86_NATIVE_CPU=y builds (Chang S. Bae)
Signed-off-by: Ingo Molnar <mingo@kernel.org>
-----BEGIN PGP SIGNATURE-----
iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqvrhgRHG1pbmdvQGtl
cm5lbC5vcmcACgkQEnMQ0APhK1inbQ/9G4Q0h9esQ945n0uYRYvVLuj2P8DvE3XN
9d5IJ5pIYdhJCvlv8yXyv1u3sq59QYNmUgpBMghHJonhqobtnchvBSiznoAMgi8L
yjRlcaFBPX9qjFQV1W9WJQuUHhW/12QFy9Bo9n1uXEv6pYspYVDwodCaS+rEvkTF
0wK3TjETv90TravGjFscYTt2VLAiy+cd/FxkUA0sBaMLjhFpUyAPHGJe/vcf8vT3
rEXkY8EeSjv5F6eKMTDVacrSZu2c9wco1bJIsSFEcxZGFzhDbuCOGiDCkwmB3uuD
ReKbEUC0KmF8qd4Ubf0dMGpbHT9LDu9Ggex619cHFOHMupPubP+yym7aCpm3v7Sb
gZe6eV6VrSREJ+oBVKsqMrWXsg1YDj6uJhC/5K3S78xBeRq64kKsmBbC93Zp20TC
QpSAxKIFqp8C+tfKzpBmcSbcipRUfATJxLjp94QaQDp467jjJCvpDJdc12mV7WR9
0gMtFjxUaIe8BGX7s2PuWPgZ8+CIH0hZQuttxUU4QWvM2RGU+QrDaMwTeAY7wme4
xomc0wpXQb5enrjmFu8betlD0xfjgt7k6eW0njezRpWSk3wyHDd5w/6Vfn8pA6Fx
AQV4UuszXzQmG+W2pdIjLhnjmsjEeWMpmwgzn0rkcqujWHeh8XOSvQIjULFrFtFv
srSbum6vEfk=
=MP1H
-----END PGP SIGNATURE-----
Merge tag 'x86-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
Pull x86 fixes from Ingo Molnar:
- Reject the loading of a potentially problematic microcode version
on Intel Granite Rapids systems (Chang S. Bae)
- On FRED, reconstruct the proper #GP context for rejected INT
instructions, to fix a signal ABI regression (Matthew Schwartz)
- Add a test for this signal ABI regression the x86
self-test suite (Matthew Schwartz)
- Don't emit the new and not yet properly supported EGPR instructions
(%r16-%r31) on CONFIG_X86_NATIVE_CPU=y builds (Chang S. Bae)
* tag 'x86-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
x86/build/64: Prevent native builds from generating EGPR use
selftests/x86: Check signal state for rejected software interrupts
x86/fred: Reconstruct the #GP context for rejected INT instructions
x86/microcode/intel: Reject problematic loading on Granite Rapids systems
|
||
|
|
0a15ba6b0c |
Timer race fixes:
- Fix timer signal <-> exec() race, to prevent UAF (Thomas Gleixner)
- Clean up POSIX CPU timers right after de_thread(), to prevent UAF
(Hyunwoo Kim)
- Fix POSIX CPU timers race between expiry and timer_settime(),
to prevent UAF (Thomas Gleixner)
Signed-off-by: Ingo Molnar <mingo@kernel.org>
-----BEGIN PGP SIGNATURE-----
iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqvrMYRHG1pbmdvQGtl
cm5lbC5vcmcACgkQEnMQ0APhK1gqUQ/+NkruN984bFynF/eZ0/2DFv91AAUP8zgH
/S3PBlwuSbYFN9JVhngDMwxQkamE56weJbFc+0QuvVT5UVw/vX9BS4QOvvzN+f8D
FEN3UqD0d1B8OwlPNTw0sFPwJDdPctTinfKOhNjNQe6RLFsNARvGyaKDIDroWTfV
dxuJ/7Ecs+5m1bmGJnPEC+IH/OnV9BEEl1NdZb+INKpBlui9LCsw4rRIj/8dPK/H
UNhvXpykKrJCDftbCzAFSNryuzcJgq4kHtMbsqiUL6y50AB69eHGi/Y0xYBAEr1h
NiDPq2PAMmH1NCCMsTtqbJZMqgCr+7DSZiCFn7bZPwg0V5tV4PFZD484q0sCbiej
Fwg+arHd0icnceIcWMsBWPUVOSLxZaWdp9a2Tj3Ill06//b5bEDBJBbpecS+so3t
8W6IvdoCYm7sz50mohnjOdx7biHPu0yhwgj+EoAV3nZKoALQAAcI7+HJzSWpGnJi
HIO0zylRAZCjk9H3QNWO+LdWgifc8DysAZOWpmbuwGgp8q483IDRDtme/kMt3+D1
1qTHa1TD/tPo8UmmgyVJQ7e1hCxBkGuuBBu5Y3/qkUEOQM6B/H2Ji7stxsLpW3JL
HLzC3kL2SBBVBO2ljqiH5IhVAL10Qm5vPxaCOjExdBt1vjMxN1DowZqD4rT/tw58
ArpD4zmr8VQ=
=KhWJ
-----END PGP SIGNATURE-----
Merge tag 'timers-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
Pull timer race fixes from Ingo Molnar:
- Fix timer signal <-> exec() race, to prevent UAF (Thomas Gleixner)
- Clean up POSIX CPU timers right after de_thread(), to prevent UAF
(Hyunwoo Kim)
- Fix POSIX CPU timers race between expiry and timer_settime(),
to prevent UAF (Thomas Gleixner)
* tag 'timers-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list
exec: Cleanup POSIX timers right after de_thread()
signal: Prevent exec() race
|
||
|
|
fecbe78ac0 |
Scheduler fix:
- Avoid false positive migration warning for proxy donors
(Andrea Righi)
Signed-off-by: Ingo Molnar <mingo@kernel.org>
-----BEGIN PGP SIGNATURE-----
iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqvqssRHG1pbmdvQGtl
cm5lbC5vcmcACgkQEnMQ0APhK1gPzBAAhE9hcpkBV6vNW9xzBDKdGPxRjch2vcfu
lQbx7da1yC2rHU7RDlcdfEgkhAqTRwEAXKz26zth3sDHLk43tusuNtqG3swELhNW
YAGbHjdn87snQlmP8AOK4EaT3uE5NjWqRSIJWMK+AhWSwqO/zzK91T6yZyQY0fM4
3Edp8CFo3IeyOzCR96vsob2x1fFQhuR//5fWul3uuB0EZ8VA5FhH3ene6VCm7P/1
dauxX0rMTb2730qNXA8cHROZq+bwhqTZOUaoOZ33WxnRPkvY9mV/hZsN8JnJuzBE
ogzyyorcl8dFH8qOapos9Cp3tQj9GkTX7mXWDbuUflt/8uOXtQMf75kFGBVI5NUw
2xNfgubTYGo6Qc1C+wyOhGYJ6T5Al+083pV/vPc4y7Z1i7RgZ94QypMuZuaR/RqS
z+RQcdNQlXiRIAIILGJqq1xdbaCJvbVx3tiFZkhPse6ioOF6UNGbQiNExAq3v5BU
ocvhBuf9p/uvRmfs+ZtQNqAAjZUL7tQPvdFAsjxKjuI2Z5YGPROy1L9NdYKfzryM
yWOEkV2mdn97CwzDS+auC0HmPkGqf8we2VI5Ub4R35UPqDcV6vc5BAnwzAbuxAmc
K7mQOMDEaRkbVQ0MoSMdidIXLL0AcN+BROBUtHv8kqJur6nADE3K3HZNdhr2ViLN
eisNI6m8pLk=
=BEte
-----END PGP SIGNATURE-----
Merge tag 'sched-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
Pull scheduler fix from Ingo Molnar:
- Avoid false positive migration warning for proxy donors
(Andrea Righi)
* tag 'sched-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
sched/core: Avoid false migration warning for proxy donors
|
||
|
|
abb91eed94 |
Perf events fixes:
- Fix crash when probing CS CALL instructions (Jinke Han) - Fix NULL pointer crash during module unload (Vinay Belgaumkar) Signed-off-by: Ingo Molnar <mingo@kernel.org> -----BEGIN PGP SIGNATURE----- iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqvqiURHG1pbmdvQGtl cm5lbC5vcmcACgkQEnMQ0APhK1hiohAAjcvOY7M998pX1tmo1Egw9kAuI0odtNOX weQ4Wq7K3X+tg+q1wVUmE/N/y/WLYWNatjwvjc8TClYdQEiaqBMH4TSLAuY3TOxa TxwdTC20uSN4EPZ0iRhKzm3biPzzzRq4M9hhV+WfGcK7ieXRn4Q7d9S3DDe5oEfG lI4l/RefIBiINVPC7dNM7xpS/7XBEPnzNeshOMwp6ZsPziZJizgC8C7RhQFAPszo Ho36KKFQqMNouCSybQl1GxLyPw+oGtneWESHXrF6Mhp+bcx40fMtJxKNyVLsVWuM wo0Ry843pCbDofOIqg7m0AufWUhz7B4MttTXXrU2/BYMHEbxlgms1AO7lnSGzPmn vP0JHZnT3y34P5uvGaVho7t9QKKbuY47cKNmsiiLuXiBQQuKnvDmDln1Mu1KS3fg a1LI8kv043iLqAjsIWMVtKlRGUX36f4NXUWrxvO/tmup3ocJhG1oYmEe/RaFddVX 5qRbHn7Z1w8jAWldODYSrXkpMRgMtClQuqHdjxZQt5DPZSORzoFxTvSfJLdUUtVx CUiT34zcLPHfvGD+ctHe5kVesgDHCxp/z1tKrJBunB+XZVl6rKHycfiGjaUXQRcR NUp6iFlfay8b79EkMsLC8p6uAmzX2q+gEwNVy8eevBSXdsYqcY5islj3ob7sBHsH vk4gDJikpE0= =onkS -----END PGP SIGNATURE----- Merge tag 'perf-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip Pull perf events fixes from Ingo Molnar: - Fix crash when probing CS CALL instructions (Jinke Han) - Fix NULL pointer crash during module unload (Vinay Belgaumkar) * tag 'perf-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip: perf: Fix null pointer access in is_include_guest_event() x86/kprobes: Fix crash when probing CS CALL instructions |
||
|
|
2f7ff5f547 |
- Fix objtool build error on systems where libopcodes is
present, but development headers (binutils-dev) are not
(Ulises Mendez Martinez)
Signed-off-by: Ingo Molnar <mingo@kernel.org>
-----BEGIN PGP SIGNATURE-----
iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqvqSARHG1pbmdvQGtl
cm5lbC5vcmcACgkQEnMQ0APhK1iBWQ/9HTpCn/GSapwpTLUAXh/d/7VWSTV/xMRS
b/cqx+jFDFeZDU55VbX+bMgKQyW0jNSUPjvVp0ZfjUf0W0LOXL/EnAemZ8VqBqAj
IMIyd+0MjCeUOCVanRiITre65BPuF+g3EbxWypFDiLmb4ziA5YksPknTWYrIVbDP
IMks30B8kJfzC5Qh0jjpSRDSypTvuEAKppbyf3pPmHfKLSbwtKOQzeoFUlLtWfs4
diBm9BVIjosmIr5dxMyixa8+5BTsPs4ojwa4US3H+RzxdXe+2v31Ac2nK/zvCRst
Fr8gefaLhVrnfkJeXU0Xn/rDMYOzayb1JW4jWjJ40I6U20ptdrMQ3aSJqjNrrwkQ
2vikInQX3NKV2ASiTppLDhsq7MFt4AeRYFwj8xmErm5uhoSEKAEPG1QZWS98QkAo
CXQL3PITL5kS0q5wGkkYXNi3TbpKvWy8kPoIRMHoKFUkBHJRssSg8tb17D5Jg0yd
QvsjocvMSf865swQ6p1yj+7+Zd+nGM2JGkIcp9OBPTAzZej4bXmpPwMKDeRv6pgD
GNgKJ2oEhvXWCgokxK9ezgk8rYsH/1Vo/+JyBf4/tcKL9ixfnBTgLNZ80J8VFDn2
5axUt4EO+FZKzLB6UaENhTo813PhGOM/rChKmJ1L4GWi0RywoX+seH4b+FtQk87f
VPvApwwiDHQ=
=vTNY
-----END PGP SIGNATURE-----
Merge tag 'objtool-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
Pull objtool fix from Ingo Molnar:
- Fix objtool build error on systems where libopcodes is
present, but development headers (binutils-dev) are not
(Ulises Mendez Martinez)
* tag 'objtool-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
objtool: Validate disassembler headers in libopcodes probe
|
||
|
|
bdab18633a |
- Also allocate a default private futex hash on vfork()
as well, to avoid races with (private) futex waiters
(Peter Zijlstra)
Signed-off-by: Ingo Molnar <mingo@kernel.org>
-----BEGIN PGP SIGNATURE-----
iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqvp20RHG1pbmdvQGtl
cm5lbC5vcmcACgkQEnMQ0APhK1giDg//VpFKPXgma7fW5E+T0kjWHWD7FS1vYyJ4
nMunKME8PAV0A4S7946iUAWHjViVfksTmfvcXepSFCKZKLf55g8s2aZ1VoigMtYX
bQxNrnOidebSg9npLs9NV4sjvvNy+k03gcNN+OK+ZRfYCVRqbLgfCm5RJbaId5y4
+EuizVmtJuNav6HwAEIbU4LXGIdwSL9Pn8Zitkz/H7g0ZEkv+VA4h6NttvKDNfV7
OltcUFejtU7Z1lItfH+PP9pMcjPA6OPI2h7LLmUcZGUhhQQtW2Gb1fffz45PiH8T
FB7PdFt22TLG5c6hLB7zbrFFillWKn3l3Ihi/IxqVmMulhk6RVTPdCVJcj1cGZxF
9NXZ+L81poKwEETaIk52v5jm9qNF+kHbXJuCjPbmEdPxtxfv+Ma4zXom/xKkuXpx
qf01GXxelUPdCAl0cT0pzRvbEfHNIOsE2Id7f+59jB+L8ZbYEch04cIVRqCQcOgi
9B+lXj36fkFBV6wmuP5SWShWsgMsMpgSzOz5mUdWjY3Ocn9QuzDxPkk50Cm7uL1i
q/HpGv3T849HFnCH7+mi8wSiX33La+N297+AkGO7U7h5QFldPokvbAijwfmF+1Nw
CebsAfsgJsN1GZacDTH0jmRxh4I0Wa32yiCAldeGS2w9EMEAFbA87iwsOgjwHiQl
JOv/s06Pg7o=
=qQHe
-----END PGP SIGNATURE-----
Merge tag 'locking-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
Pull futex fix from Ingo Molnar:
- Also allocate a default private futex hash on vfork() as well, to
avoid races with (private) futex waiters (Peter Zijlstra)
* tag 'locking-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
futex: Also allocate private hash on vfork()
|
||
|
|
5bf70485f9 |
spi: Fixes for v7.3
A few driver specific fixes, none of them particularly severe or unusual. -----BEGIN PGP SIGNATURE----- iQEzBAABCgAdFiEEreZoqmdXGLWf4p/qJNaLcl1Uh9AFAmqvmVMACgkQJNaLcl1U h9AOdwf/aRa54oHd6iLCPXNAbZLDie0pnJa/Q/5sjpJoVY9ofKc2XM9djmy60YdF /VGIphT8gr6at6fLZHEBbLanu2MQC2vxW9zDh5n+Xe8HUS3sdrwtBJPSv74Mcfrf OIv6nFrVsbo1IMF7x4ncYOhOBGKyOSqhsVdt+k6jl1wuTDJBHyFs7sdL1DGRCRu/ ba4n2W+kSxVeFx3ACFyDJ8l8vLqtyotFKkpmslrPmT0yHFwOr8SOMbyQ5MPxITpx gqgLikR3OW5alOLxy1U2nWCdjNsc8UWBhx1sCnByYrUO3VmRIEx4j1l2wSVX0J7E Ck7/pSpg1NGkxVYSLCTBufqq8kgPTQ== =iy0J -----END PGP SIGNATURE----- Merge tag 'spi-fix-v7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/spi Pull spi fixes from Mark Brown: "A few driver specific fixes, none of them particularly severe or unusual" * tag 'spi-fix-v7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/spi: spi: fsl-qspi: Reprogram the clock rate when the operation frequency changes spi: spi-zynqmp-gqspi: stop the controller on shutdown spi: virtio: Use the per-transfer bits per word spi: spi-qpic-snand: avoid writing QPIC_EBI2_ECC_BUF_CFG register |
||
|
|
aa211c7a58 |
i2c-fixes for v7.3-rc4
Fixes mainly for cleanup and error handling, a good part of them
around DMA resource management.
- at91: ensure DMA channels are released on all exit paths
- imx: fix autosuspend cleanup on remove
- qcom-cci: fix device node reference leak
- atr, imx, qcom-geni: set adapter slot to NULL on registration
failure
-----BEGIN PGP SIGNATURE-----
iHUEABYKAB0WIQScDfrjQa34uOld1VLaeAVmJtMtbgUCaq+VLAAKCRDaeAVmJtMt
bqmsAP9umA0ew1WQkQGTlTJLfbQdhwy8IDS7tMRAlgL7vsUxOQEApvFqr6Xtq2j7
HiSP35cHybZlA7P2T70A+MVniCJDRQ4=
=Sn1c
-----END PGP SIGNATURE-----
Merge tag 'i2c-fixes-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/andi.shyti/linux
Pull i2c fixes from Andi Shyti:
"Fixes mainly for cleanup and error handling, a good part of them
around DMA resource management:
- at91: ensure DMA channels are released on all exit paths
- imx: fix autosuspend cleanup on remove
- qcom-cci: fix device node reference leak
- atr, imx, qcom-geni: set adapter slot to NULL on registration
failure"
* tag 'i2c-fixes-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/andi.shyti/linux:
i2c: qcom-cci: fix device_node refcount leak in cci_probe()/cci_remove()
i2c: qcom-geni: release DMA channels on probe error
i2c: imx: release DMA channels on probe error
i2c: at91: release DMA channels on remove and probe error
i2c: atr: fix dangling adapter pointer on add failure
i2c: imx: disable autosuspend on remove
|
||
|
|
b12dd0fa48 |
Input updates for v7.3-rc3
- Fixes for evdev and input compat handling to zero-initialize on-stack absinfo and force-feedback effect structures before partial or compat copies from userspace, preventing kernel stack memory disclosure - Fixes for the Synaptics RMI4 driver to prevent an out-of-bounds read when writing multi-chunk blocks over SMBus and to avoid a NULL pointer dereference during suspend/resume when the RMI device is unbound - Fixes for the soc_button_array driver to propagate -EPROBE_DEFER on non-Bay Trail/Cherry Trail platforms (fixing broken power and volume buttons on the Microsoft Surface Pro 11) and to validate the ACPI package element count before dereferencing - A fix for the adp5588-keys driver to cache the initial GPIO hardware state before registering the gpiochip so pre-configured pin states are not clobbered by GPIO hogs during registration - A fix for the cyttsp5 touchscreen driver to clamp the device-supplied HID report size before copying into the response buffer, preventing a buffer overflow - A fix for the HP SDC serio driver to use timer_shutdown_sync() on module exit so the periodic kicker timer cannot rearm itself during teardown - A fix for the eeti_ts touchscreen driver to export its OF module alias so the module autoloads on Device Tree platforms - Updates to the xpad joystick driver adding support for the Victrix Pro BFG controller and Azeron devices, and fixing the device type classification for the PDP Marvel Xbox 360 controller - Quirks for the i8042 and atkbd drivers to keep the built-in keyboards functional on the Acer Aspire Go 15 AG15-42P and Xiaomi Redmi Book Pro 16 2026 - A quirk for the Synaptics PS/2 touchpad driver disabling SMBus InterTouch on the Lenovo ThinkPad T440p (board ID 2722) so the touchpad and TrackPoint respond immediately at boot - Other minor updates and documentation fixes, including reading the "ti,poll-period" property as u32 in tsc2007, adding the mt6572 compatible to the MediaTek keypad Device Tree binding, fixing an attribute name typo in the trackpoint sysfs ABI documentation, and documenting that no new LED codes should be added to the input subsystem. -----BEGIN PGP SIGNATURE----- iHUEABYKAB0WIQST2eWILY88ieB2DOtAj56VGEWXnAUCaq9j+gAKCRBAj56VGEWX nJ5KAQDnTOivIghgIGnlKTIYLSV4cJ0fWJh7J1/ubx9soK+9RwD/bDUdyryAaSTr x95U7/fEvq/lXBFyK2LXyahuTC6vNQY= =Vsfi -----END PGP SIGNATURE----- Merge tag 'input-for-v7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/dtor/input Pull input fixes from Dmitry Torokhov: - Fixes for evdev and input compat handling to zero-initialize on-stack absinfo and force-feedback effect structures before partial or compat copies from userspace, preventing kernel stack memory disclosure - Fixes for the Synaptics RMI4 driver to prevent an out-of-bounds read when writing multi-chunk blocks over SMBus and to avoid a NULL pointer dereference during suspend/resume when the RMI device is unbound - Fixes for the soc_button_array driver to propagate -EPROBE_DEFER on non-Bay Trail/Cherry Trail platforms (fixing broken power and volume buttons on the Microsoft Surface Pro 11) and to validate the ACPI package element count before dereferencing - A fix for the adp5588-keys driver to cache the initial GPIO hardware state before registering the gpiochip so pre-configured pin states are not clobbered by GPIO hogs during registration - A fix for the cyttsp5 touchscreen driver to clamp the device-supplied HID report size before copying into the response buffer, preventing a buffer overflow - A fix for the HP SDC serio driver to use timer_shutdown_sync() on module exit so the periodic kicker timer cannot rearm itself during teardown - A fix for the eeti_ts touchscreen driver to export its OF module alias so the module autoloads on Device Tree platforms - Updates to the xpad joystick driver adding support for the Victrix Pro BFG controller and Azeron devices, and fixing the device type classification for the PDP Marvel Xbox 360 controller - Quirks for the i8042 and atkbd drivers to keep the built-in keyboards functional on the Acer Aspire Go 15 AG15-42P and Xiaomi Redmi Book Pro 16 2026 - A quirk for the Synaptics PS/2 touchpad driver disabling SMBus InterTouch on the Lenovo ThinkPad T440p (board ID 2722) so the touchpad and TrackPoint respond immediately at boot - Other minor updates and documentation fixes, including reading the "ti,poll-period" property as u32 in tsc2007, adding the mt6572 compatible to the MediaTek keypad Device Tree binding, fixing an attribute name typo in the trackpoint sysfs ABI documentation, and documenting that no new LED codes should be added to the input subsystem * tag 'input-for-v7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/dtor/input: Input: hp_sdc - shut down kicker timer on module exit Input: xpad - add support for Victrix Pro BFG Controller Input: tsc2007 - read "ti,poll-period" as u32 Input: trackpoint - fix the inertia attribute name in the ABI document Input: eeti_ts - publish the OF module alias Input: xpad - add support for Azeron devices Input: xpad - fix PDP Marvel Xbox 360 controller Input: document that no new LED codes should be added Input: soc_button_array - check btns_desc->package.count Input: soc_button_array - fix MS Surface Pro 11 probe failure Input: i8042 - add quirk for Acer Aspire Go 15 AG15-42P Input: synaptics - disable InterTouch on ThinkPad T440p (board id 2722) Input: cyttsp5 - clamp the HID report size before memcpy Input: zero ff_effect before compat copy in input_ff_effect_from_user Input: evdev - zero absinfo before partial copy in EVIOCSABS Input: synaptics-rmi4 - fix GPF in suspend and resume when unbound Input: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block() Input: atkbd - skip deactivate for Xiaomi Redmi Book Pro 16 2026 dt-bindings: input: mediatek,mt6779-keypad: add mt6572 Input: adp5588-keys - cache GPIO state before registering the gpiochip |
||
|
|
4a910e594a |
selinux/stable-7.3 PR 20260919
-----BEGIN PGP SIGNATURE----- iQJIBAABCgAyFiEES0KozwfymdVUl37v6iDy2pc3iXMFAmqvPSwUHHBhdWxAcGF1 bC1tb29yZS5jb20ACgkQ6iDy2pc3iXP1rBAAkK6sP+lzXynr/abxWio9UCvlN6NF jqMXtKeUeLNg/lJakXKhja/FGaK9w+Rm+zlXQQvVE7YAO5Db758JzCXMTHlK6etD T5d+GVdZj/oVcAvfGhov0guNHZqcfKTGWOXKtGV8RQWYL+f6IC1IIHnz9wNeWIfY emkfOTgAJpCkX9nXS5xTdQNUiPkUV80LFGqxXCMhxiumvyzqOhUteytfNh3UXXcs ldOWRBstUumudBe/MJR09REtQve3emHc7bZUAxSKwXxzdOPTf7UEy4Y7QXCN3Opn Dn6Dsrt6lnpIZyzUK/eOnZvQ639gDqTMW2XTmin0JIf2KGG/PhqnvOT07hOPl+X5 wqXh2wCFn+tXVi5t+S2myMUVZK56GwfRH9kMCo6ca1Ui36iYYEeoJYt7z5tsE6P5 YBdvKKJ/MPR1/uEwP/TB3UDK0o4OBjyujc6/Ka5iBoIHXKpx7MBLOo/Q0h/Wu2A0 7HYvG/4lYdWp3p5iR8cdZ+ZgdTQDWi6t5BD3JWOfWi1gHCeGgZCHTCZ9mdSoFS18 9GpXFXTR4yM5pfwxQEAu6jFH0esSB92HJBd/yS7sU8EIUQ+0XmOge+gVPifMrhWj yOHCR7hlAYE5ds51w3ZVOYI0slkYImqCHEdlCz1DiKzyLmQQmfJvshOIvBCl7uwn LRHu6Mo0cEBMAvc= =kiQE -----END PGP SIGNATURE----- Merge tag 'selinux-pr-20260919' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux Pull selinux fixes from Paul Moore: - Ensure that the cached SELinux access decisions are correct - Fix the SELinux overlayfs code to properly track the top-level/user information on multiple stacked overlayfs filesystems - Fix the SELinux overlayfs code to properly enforce mprotect() access control policy on all of the different layers in multiple stacked overlayfs filesystems * tag 'selinux-pr-20260919' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux: selinux: recheck intermediate backing files on mprotect() selinux: preserve user SID across nested backing files selinux: always fill AVC decision in avc_has_perm_noaudit() |
||
|
|
7362a1553e
|
i2c: qcom-cci: fix device_node refcount leak in cci_probe()/cci_remove()
The of_node_put() matching of_node_get() runs after i2c_del_adapter(),
whose trailing memset() zeroes adap->dev and thus adap->dev.of_node,
making the put a no-op and leaking the node on every adapter removal
and error cleanup.
Use a devm action: the pointer is captured at registration, out of
reach of that memset(), and devres runs the put once on probe failure
and detach, replacing the three manual of_node_put() calls. The
setup loop uses the scoped iterator form so the child node is released
automatically if devm_add_action_or_reset() fails mid-loop.
Suggested-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Fixes:
|
||
|
|
268aacb2e2
|
i2c: qcom-geni: release DMA channels on probe error
geni_i2c_init() grabs exclusive GPI tx/rx DMA channels when the serial
engine runs in GPI mode. If i2c_add_adapter() subsequently fails, probe
returns without releasing the channels, because the remove callback is
not invoked after a failed probe.
The adapter-registration failure path used to release the channels via
its err_dma label; that release was dropped when the probe tail was
restructured into geni_i2c_init().
Release the channels on the adapter-registration failure path, mirroring
geni_i2c_remove().
Fixes:
|
||
|
|
e9f03b9625
|
i2c: imx: release DMA channels on probe error
i2c_imx_dma_request() acquires exclusive tx/rx DMA channels and is
optional: on errors other than -EPROBE_DEFER the driver falls back to
PIO mode and probe continues. If i2c_add_numbered_adapter() then fails,
probe returns through clk_notifier_unregister without releasing the
channels, because the remove callback is not invoked after a failed
probe.
Release the channels on the probe error path, mirroring
i2c_imx_remove().
Fixes:
|
||
|
|
f7eeb1af85
|
i2c: at91: release DMA channels on remove and probe error
at91_twi_configure_dma() requests exclusive tx/rx DMA channels, but
nothing ever releases them on driver detach, and the probe error path
after the channels are acquired (i2c_add_numbered_adapter() failure)
returns without releasing them either, because the remove callback is
not invoked after a failed probe.
Move the release into a helper, call it from the existing
configure-failure path, the adapter-registration failure path, and
at91_twi_remove().
Fixes:
|
||
|
|
c21eaa72f0 |
posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list
Kijo analyzed another race in the POSIX CPU timer code: Commit |
||
|
|
518e5b794c |
for-7.3-rc3-tag
-----BEGIN PGP SIGNATURE-----
iQJPBAABCgA5FiEE8rQSAMVO+zA4DBdWxWXV+ddtWDsFAmqu3wQbFIAAAAAABAAO
bWFudTIsMi41KzEuMTIsMiwyAAoJEMVl1fnXbVg7Y5kQAJ1ANaQWod+AUKhgbtA6
IcEFH8AAVrrTqqN0SxOl/tqHL6Xt/5mKlQcTpYPxeccUkp72M9BeGik4Gp7OwN1D
vkVTgrmhHT4r+4ae4GJP0yCtNJBa0fRXjsMFbNYTKGWcz9yOsW1OkBsq8VtRo7ym
CSVBc57buUi0mzbnLNDh69G/YA7NCTyaxXKjPARNYy+cy0LMIDmgZCByhgePQvzB
aqJUakRKpaeXEQIf0nT/70XcGhXNtfK1GOnLZM1ySFqLufMzdTsEzFsT8dVugqU1
wr1HMaMq1iNKwE4sJgNWS84wRT1zxZopKIOsTufFu98Zb2C0kvUSjWeJSqtFM88G
ggj/jmaoRhCU1cXE1jvZWy4Fe5zQH8deSQZ7zUB4ZzqCaDRwOEAj4IpuQQ9Ok91E
J/07SCvKPk/QUPbA2e5lwRL3aximsD1LfRxWIOZ+xg/HVX+vYfHmy5gzkl/hhfrm
RHkHLz8iXNHV7qhIVzZ/GYvTxR6U6nbLVUbkl5n/8eFePM7YHnoWtvMHT71qWwrh
mPx8uTK+4BI2+rAHTKqxnwEQ27OHj5odlGKTlKiaMrQR9eqnnhJLTMPDJMzqQ7TI
ZiibxG8UqSTsNbvOXXtd7MykSRpSb/VWyJImKuw30kx3f7f2yd1aCUyU4T7o5N/3
FRI+2AbkoSeype3Rw+VcEPoi
=WxSA
-----END PGP SIGNATURE-----
Merge tag 'for-7.3-rc3-tag' of git://git.kernel.org/pub/scm/linux/kernel/git/kdave/linux
Pull btrfs fixes from David Sterba:
"Among the regular fixes, there are two that were reported recently and
have user impact:
- filesystem id is now stable again on the default and common case
(it broke openconnect key derivation, while this is not secure,
it's still in use), the intention was to change id for the
temp_fsid use case
- fix detection of /dev/root and rename it after device scan, this
broke booting of initramdisk-less system with grub2 as the probe
needs the real device
Regular fixes:
- don't store compressed inline extent if the size is larger than
uncompressed
- in zoned mode, handle activation of zones for all supported block
group profiles in case there are still free ones left
- check space for a chunk item when reading sys array from superblock
- allow using space reserves when removing verity items fails
- fix error handling after free space tree rebuild fails
- abort transaction if reflink or hole punching fails and it's not
possible to update the inode
- properly protect block group iteration during device replace start
- error message fixups"
* tag 'for-7.3-rc3-tag' of git://git.kernel.org/pub/scm/linux/kernel/git/kdave/linux:
btrfs: derive f_fsid with dev_t only when temp_fsid is active
btrfs: add "/dev/root" exception for device path update
btrfs: check if there is space for chunk item when validating sys chunk array
btrfs: abort transaction on failure to update inode for hole punching and reflinking
btrfs: clear free space tree creation state on rebuild failure
btrfs: handle lack of space when cleaning up verity items
btrfs: fix creation of compressed inline extents that don't save space
btrfs: tree-checker: fix error message regarding free space extent items
btrfs: tree-checker: print dev extent offset in error message
btrfs: take commit root semaphore when iterating in mark_block_group_to_copy()
btrfs: zoned: handle RAID profiles in btrfs_can_activate_zone()
|
||
|
|
63edf5a009 |
x86/build/64: Prevent native builds from generating EGPR use
Omar reports that CONFIG_X86_NATIVE_CPU=y allows builds to opportunistically emit instructions using %r16-%r31 (EGPRs) when the build host supports APX since the commit: |
||
|
|
40288c9206 |
drm fixes for 7.3-rc4
core: - fix vblank pending event leak ttm: - swapout fixes dma-buf: - scattergather fixes - enable dma-buf debug on debug kernels dma-fence: - fix signaling bit checks sched: - fix virtual runtime race msm: - DT: - Corrected indentation - Core: - Marked fbdev as system memory - GPU: - Fixed autosuspend cleanup on teardown - a750: fix timestamps - Increase GMU fw init timeout - Misc fixes/cleanups - DPU: - Fixed clock rounding, unbreaking newest platforms - Cleared pending flush state - DP: - Skip PUSH_IDLE when link was never enabled - Fixed bandwidth checks - HDMI: - Fixed runtime PM cleanup on probe failure xe: - shrinker related fixes - xe_mmio_gem fault handler and destroy fixes - xe disable i2c irq on unbind i915: - Revert a commit touching registers that don't necessarily exist - Check for negative numbers before passing to BIT() amdgpu: - SMU 14.x fix - DC IRQ fix - Runtime PM fix for P2P - RAS fix - PCIe reporting fix - DCN 6 fix - Device removal fix - DC MALL fix amdkfd: - GC 12.x fixes - Boundary checks - Mapping clear fix nouveau: - suspend/resume fixes gud: - out of bounds access fix - ignore damage clips in full update vc4: - use-after-free fix -----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEEEKbZHaGwW9KfbeusDHTzWXnEhr4FAmqttwkACgkQDHTzWXnE hr73Ww//S+8xgr8cpmJxoUrOrTnd4yeX/oj+HSRkEHQPdNayOf+pNnP4y+nChfXi ddQ3jTRyG5JwNmXRG0ouKf9koQk/V54R8v9CBtNQYsN2K58xW6riCIaEeOUbe3r1 1IQgYCEfS32b7/9D2lo1768LbJ0KWBr6qznKrfvC7vJ62wK3F0B9EzOmsKSzLxd3 gdUfyxEbtgegKOAamCbUyJyuzCErGkMAtkQ0HnmQGYmqqBBRS7Uvl1HN10JMoLSM MmR40g+dsp6ZzBDywNrdmIGDv749o1/k/zm5i6c2hJSibYBPR5sWtKICwu1ND44u ts2HjJJdyhm5PLiS09i9nVUnMkzV0N2czIDZvt9izp8+k8P4Bh/y1iagda1G0U65 h7dp9j8WXMCApxXNjplNgjMLSO7g4UJI1rAWjxGY4ecu62XHErrZ6tbjrOVOaa1T Xh8IN4EqPr+tRSKnW4AxwwwA1EfxNwoJSxglAvBvIaCjEhRWRlj7Sdo0Wrtg3WKy sORar40ySYHR+MeAbabewjRoMPq1Nyqh4D2PrOv48a4MK7a6Fl5ed6EHpyOSHYKF 7tMbLLLtDMIYX24wd/j8CkvhcTp09iphzXSqmUlIBn3t1gbrXspzCQtRU0UrsamJ QSbtL+qUoYSsobmpYOzuTVnO8W4oOnnIYaLz+TpVNDd7o7nzZf0= =EC37 -----END PGP SIGNATURE----- Merge tag 'drm-fixes-2026-09-19' of https://gitlab.freedesktop.org/drm/kernel Pull drm fixes from Dave Airlie: "Things have picked back up a bit this week, mostly amdgpu, xe and msm this time. There are a bunch of scattered changes across the rest of drivers and core stuff, nouveau, i915. core: - fix vblank pending event leak ttm: - swapout fixes dma-buf: - scattergather fixes - enable dma-buf debug on debug kernels dma-fence: - fix signaling bit checks sched: - fix virtual runtime race msm: - DT: - Corrected indentation - Core: - Marked fbdev as system memory - GPU: - Fixed autosuspend cleanup on teardown - a750: fix timestamps - Increase GMU fw init timeout - Misc fixes/cleanups - DPU: - Fixed clock rounding, unbreaking newest platforms - Cleared pending flush state - DP: - Skip PUSH_IDLE when link was never enabled - Fixed bandwidth checks - HDMI: - Fixed runtime PM cleanup on probe failure xe: - shrinker related fixes - xe_mmio_gem fault handler and destroy fixes - xe disable i2c irq on unbind i915: - Revert a commit touching registers that don't necessarily exist - Check for negative numbers before passing to BIT() amdgpu: - SMU 14.x fix - DC IRQ fix - Runtime PM fix for P2P - RAS fix - PCIe reporting fix - DCN 6 fix - Device removal fix - DC MALL fix amdkfd: - GC 12.x fixes - Boundary checks - Mapping clear fix nouveau: - suspend/resume fixes gud: - out of bounds access fix - ignore damage clips in full update vc4: - use-after-free fix versilicon: - plane format fix longsoon: - blend mode property fix" * tag 'drm-fixes-2026-09-19' of https://gitlab.freedesktop.org/drm/kernel: (59 commits) drm/amd/display: fix MALL hysteresis timer underflow at high refresh rates drm/amdgpu: fix rmmio iounmap skipped on device removal drm/amdgpu: Skip KFD mapping clear before initialization drm/amd/display: Fix NULL dereference in dcn50/dcn60 init_hw drm/amdkfd: Avoid integer underflow in EOP ring size calculation. drm/amdkfd: Avoid integer underflow with ffs in EOP ring size calc drm/amdgpu: Fix GPU PCIe link capability reporting drm/amdgpu: check ras and obj before dereference drm/amdgpu: hold a runtime PM reference for P2P dma-buf attachments drm/amdkfd: implement restore_mqd callbacks for GFX12/12.1 drm/amd/display: Atomize IRQ register read/modify/write ops drm/amd/pm: report energy accumulator for smu 14.0.3 drm/loongson: Create blend mode property for cursor plane drm/xe/i2c: Disable IRQ on unbind Revert "drm/i915/display: Clear SEL_FETCH_PLANE_CTL on plane disable" drm/verisilicon: remove ARGB formats from primary plane drm/verisilicon: add primary modifier for format tables drm/verisilicon: set blend mode for the cursor plane drm/sched: Fix virtual runtime race drm/i915/display: check configuration index before shifting ... |
||
|
|
71f370e9ee |
Two ttm fixes for ttm_tt_swapout(), one page-alignment and one overflow
fix for dma-buf, a drm_pending_vblank_event leak fix for drm, suspend/resume fixes for nouveau, one out-of-bounds access fix for gud, a use-after-free fix for vc4, a fence signaling fix, a race condition fix for sched, planes formats fixes for verisilicon, and add the blend mode property for loongson -----BEGIN PGP SIGNATURE----- iJUEABMJAB0WIQTkHFbLp4ejekA/qfgnX84Zoj2+dgUCaqvVAAAKCRAnX84Zoj2+ dtThAX9JC7SWXw+n4o9EUsxNqvlpviwe8AS7aJR++rq/sZM0an7zl0aCJu/E8p+/ JRkO+X8BfjE+2CX8RWKH63ed95vA+9DF8JfryBTSJiSz4forppFfwH7uovT3nqq2 eOon6nJQzg== =Utup -----END PGP SIGNATURE----- Merge tag 'drm-misc-fixes-2026-09-17' of https://gitlab.freedesktop.org/drm/misc/kernel into drm-fixes Two ttm fixes for ttm_tt_swapout(), one page-alignment and one overflow fix for dma-buf, a drm_pending_vblank_event leak fix for drm, suspend/resume fixes for nouveau, one out-of-bounds access fix for gud, a use-after-free fix for vc4, a fence signaling fix, a race condition fix for sched, planes formats fixes for verisilicon, and add the blend mode property for loongson Signed-off-by: Dave Airlie <airlied@redhat.com> From: Maxime Ripard <self@mripard.dev> Link: https://patch.msgid.link/aqvVENQ4ksJEIcdb@houat |
||
|
|
17e7b8eacf |
smb client fixes for v7.3-rc4
A batch of bug fixes for the smb client:
- Fix multiple out-of-bounds reads and use-after-frees in the SMB2/3
receive path that are reachable from a malicious or compromised
server: a stale next_buffer pointer and an integer overflow in
compound encrypted frame handling, missing minimum-PDU-size and
per-sub-PDU length validation before parsing command-specific
response fields, missing bounds checks in DFS referral, server
interface list, EA list, POSIX SID, snapshot enumeration and SMB1
reparse point parsing
- Fix use-after-frees and races in multichannel and connection
teardown, including an interface freed while still in use when
adding channels, a server used after its channel reference was
dropped, a reconnect work item left queued after the server is
freed and an uninitialized reconnect list node
- Fix a heap overflow in the native symlink parser: an absolute
target without an NT drive prefix caused out-of-bounds writes and a
u16 length underflow leading to a 64K memcpy into a small buffer,
triggerable by a user with write access to a mounted share under
default settings
- Fix WSL reparse point parsing: use unaligned accessors for the
packed extended-attribute payload to avoid alignment faults on some
architectures and stop leaving partially mutated fattr fields on
parse failure
- Fix lease break ACKs being sent through the wrong session on
multiuser mounts, which caused read failures (e.g. on NetApp
ONTAP/Azure Files) when copying files
- Fix an smbd_connection leak when cifs_get_tcp_session() fails after
an RDMA connection was already established
-----BEGIN PGP SIGNATURE-----
iHUEABYKAB0WIQTcqRusfSdYROJQwGkpVtNKoQNdYwUCaq2frwAKCRApVtNKoQNd
Y1mcAQDcDTkep03jzghyJG6xWJ3S7KNbeYpjkOPnPyR+Et7HmAD/eXLFvgkJ3wC7
tBUDjDTLeyP6/DOBmDb/fIKEw2vfBQs=
=+Vsw
-----END PGP SIGNATURE-----
Merge tag 'cifs-fixes-7.3-rc4' of https://git.manguebit.org/linux
Pull smb client fixes from Paulo Alcantara:
"A batch of bug fixes for the smb client:
- Fix multiple out-of-bounds reads and use-after-frees in the SMB2/3
receive path that are reachable from a malicious or compromised
server: a stale next_buffer pointer and an integer overflow in
compound encrypted frame handling, missing minimum-PDU-size and
per-sub-PDU length validation before parsing command-specific
response fields, missing bounds checks in DFS referral, server
interface list, EA list, POSIX SID, snapshot enumeration and SMB1
reparse point parsing
- Fix use-after-frees and races in multichannel and connection
teardown, including an interface freed while still in use when
adding channels, a server used after its channel reference was
dropped, a reconnect work item left queued after the server is
freed and an uninitialized reconnect list node
- Fix a heap overflow in the native symlink parser: an absolute
target without an NT drive prefix caused out-of-bounds writes and a
u16 length underflow leading to a 64K memcpy into a small buffer,
triggerable by a user with write access to a mounted share under
default settings
- Fix WSL reparse point parsing: use unaligned accessors for the
packed extended-attribute payload to avoid alignment faults on some
architectures and stop leaving partially mutated fattr fields on
parse failure
- Fix lease break ACKs being sent through the wrong session on
multiuser mounts, which caused read failures (e.g. on NetApp
ONTAP/Azure Files) when copying files
- Fix an smbd_connection leak when cifs_get_tcp_session() fails after
an RDMA connection was already established"
* tag 'cifs-fixes-7.3-rc4' of https://git.manguebit.org/linux:
cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
smb: client: fix reparse buffer bounds in cifs_query_reparse_point()
smb: client: fix potential OOB read in smb3_enum_snapshots()
smb: client: fix missing iov bounds check in parse_posix_sids()
smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs()
smb: client: reject short Next offsets in parse_server_interfaces()
smb: client: fix missing lower-bound check on DFS referral string offsets
smb: client: fix server->total_read for compound encrypted PDUs
smb: client: validate minimum PDU size before smb2_get_data_area_len()
smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
smb: client: fix use-after-free of iface in cifs_try_adding_channels()
smb: client: fix fattr leaking on wsl_to_fattr() failure
smb: client: fix unaligned access in WSL reparse point parser
smb: client: fix smbd_connection leak on cifs_get_tcp_session() error
smb: client: fix rlist race and missing initialization
smb: client: cancel reconnect work in clean_demultiplex_info()
smb/client: send lease break ACKs thru correct session for multiuser mounts
smb: client: validate absolute native symlink targets before NT fixups
|
||
|
|
925724c081 |
SCSI fixes on 20260918
Four driver fixes, three of which are minor and one of which (fnic) tries to add some logic to try to avoid MSI-X being ineffective if hyperthreading is disabled. The core fix adds validation to mode sense buffer sizes because it is used by ATA and could, theoretically, be exploited by a specially crafted USB device that can simply be plugged in to any laptop or server. Signed-off-by: James E.J. Bottomley <James.Bottomley@HansenPartnership.com> -----BEGIN PGP SIGNATURE----- iLgEABMIAGAWIQTnYEDbdso9F2cI+arnQslM7pishQUCaq2P/hsUgAAAAAAEAA5t YW51MiwyLjUrMS4xMiwyLDImHGphbWVzLmJvdHRvbWxleUBoYW5zZW5wYXJ0bmVy c2hpcC5jb20ACgkQ50LJTO6YrIXJ6AD9FODcORvjoRDhcU626EWsG/Hoy7YcMH2T bZVtZwp3hH8BAPnKar5uj3fCQxJkvI+sLKjiGultTi3llt9VaZGSTFj2 =JgQF -----END PGP SIGNATURE----- Merge tag 'scsi-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/jejb/scsi Pull SCSI fixes from James Bottomley: "Four driver fixes, three of which are minor and one of which (fnic) tries to add some logic to try to avoid MSI-X being ineffective if hyperthreading is disabled. The core fix adds validation to mode sense buffer sizes because it is used by ATA and could, theoretically, be exploited by a specially crafted USB device that can simply be plugged in to any laptop or server" * tag 'scsi-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/jejb/scsi: scsi: core: Validate MODE SENSE lengths in scsi_cdl_enable() scsi: fnic: Fix missed link-up when critical IRQ targets offline CPU scsi: ibmvfc: Add Kconfig dependency to fix link failure when NVME_FC=m scsi: qla2xxx: Fix the ql2xfc2target parameter description scsi: pm80xx: Fix the use_msix, use_tasklet and read_wwn parameter descriptions |
||
|
|
ef31d04b6d |
pci-v7.3-fixes-1
-----BEGIN PGP SIGNATURE----- iQJIBAABCgAyFiEEgMe7l+5h9hnxdsnuWYigwDrT+vwFAmqtiM0UHGJoZWxnYWFz QGdvb2dsZS5jb20ACgkQWYigwDrT+vxDxg/+Nyqg0N+1xxHnG+bsbJ7XA7v7sQY5 DcvfvnMcJg3Lx5ioED4OJwr35rQZy8E3n/swFCxvzyZQ6gp+Q3sA2wUeuqd26kCS OSuMwRj3+HsnCVlYC/LL5fUoyZ+/FFv4drDPvIl3vCo5kIoNuWJslIox1eqPgmtZ SZO70qyQcA8jjCHYqQR07kvtqyainZrOoPP5uASnRqSGVlTLI3mzKdLtzrVytgel bAb6CPKrqF1XQY2HBBH3MEU6mhXbr7zeSrncZnb0QimqHCloq4dUK+WF9ZQnxSk5 wXgftOvg2ycYhE6hUVZGrRf/fMwzWatkD/Vi9a69wKN2lspwacKCGi0LhNS1u/Em ypak/Wg0sEic5y//eOgJjIfodJLsHiyvBIZxC3ziqZj1q6Kc4pCvg1iHePFYCSQj gB4Khkm6sWx63GX02g9ytc9bl00xCkjuck8OSVExP2MhaWajlksvzy9VXsZG9BzH QianraVVqVZd+LM3eFTy16qaD7jQuNMCIzOzB3UDh2gSzO+Lr9OtK36iTsn0NELc lKjrIlh5yEp5uD9vrrD4k8xAbaVGBnzzK7Whc42rt2n/gIs2SbV8TXWTyxtk29DJ XlbUAOiBLYEuO3YWAvq47kezyafwRtBqXxjyyoZajteD+hoRFFtkcT5OcaiWVZUL qzRbS1eB3IfB/q8= =9dUn -----END PGP SIGNATURE----- Merge tag 'pci-v7.3-fixes-1' of git://git.kernel.org/pub/scm/linux/kernel/git/pci/pci Pull PCI fix from Bjorn Helgaas: - Enable clock after core reset is asserted to fix enumeration regression on i.MX6Q Apalis platforms with ASM1061/ASM1062 SATA controllers (Richard Zhu) * tag 'pci-v7.3-fixes-1' of git://git.kernel.org/pub/scm/linux/kernel/git/pci/pci: PCI: imx6: Move clock enable after core reset assertion |
||
|
|
c3d85c669d |
- Fix session expiration so that valid sessions are no longer removed
after ten seconds of inactivity when a new session setup request is
received. Sessions now expire only after credential expiration, while
stale unauthenticated sessions are cleaned up after a 45-second timeout.
- Keep earlier responses in compound requests when Query Info fails
because the output buffer is too small. The error response is appended
without truncating preceding responses.
- Return STATUS_BUFFER_OVERFLOW for partial
FILE_NORMALIZED_NAME_INFORMATION responses instead of incorrectly
returning STATUS_INFO_LENGTH_MISMATCH.
-----BEGIN PGP SIGNATURE-----
iQJKBAABCgA0FiEE6NzKS6Uv/XAAGHgyZwv7A1FEIQgFAmqtTBMWHGxpbmtpbmpl
b25Aa2VybmVsLm9yZwAKCRBnC/sDUUQhCD2GD/9OzkmZ+/kIMum8IQi9upOM5zUD
+2nyFMebJ6qXmrhOuUgLn2ptUYxO3q1B9VvzTjKrM1Vun0VuvHmHQbGUp9a/3F7c
VTncl7E3FEHqlPkLWQJFv2dS+TYYcOhjoc2TDAY9093xktcMHK5zjv4E/DV2o0bf
NN/GcrrcWSxdJU8WI9JvY2kzmPQMDfM8uVbj2RqHSZ8m9mF5cajtDnzCCS0K6UOR
qzMrekzewIskUtcQNqU8hJWl1sgiYdD+16LmKmwLd3uOZISc3Miy5Bg8VpNN+B1g
XHhr49G4Fb8PkEYjncjxQH7zop1ID5UyC2xN63NuoH8+mkm4qn6uG2NrLhmVQO+f
Z81Ov3g77/jK3Z2fw00H3A7VGSPs931BaRTNj+lPkHTVVq3PyP1XZsfXkPUoRu1Q
xeaJydScGNYE+kaYbseXwN8haJGawd1Dd+Afn4W2zikUU5tKZxO9d2tBr4Fhl/Fm
0OBcAssTArhrY7PX2fAOQ4sUwAC4nMXSEIfdWIvcgU2OoyuFltQ55ooCoM0uLs6+
7R4rxZLipdZmKhuE2mlAWcFQJn8nS0EHXeyEDjO0u8KYsV6C8d+jDNpvtS+/5QVF
bKE4/uUX/lV0IZ55nFSPT7XdI+gxeiUql3+8bqOVqkw7wR4VjaC0xIQybyEBTMYH
IJEKfjx4tZcWGTzmdA==
=9nNl
-----END PGP SIGNATURE-----
Merge tag 'ksmbd-for-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/linkinjeon/smb
Pull smb server fixes from Namjae Jeon:
- Fix session expiration so that valid sessions are no longer removed
after ten seconds of inactivity when a new session setup request is
received.
Sessions now expire only after credential expiration, while stale
unauthenticated sessions are cleaned up after a 45-second timeout.
- Keep earlier responses in compound requests when Query Info fails
because the output buffer is too small. The error response is
appended without truncating preceding responses.
- Return STATUS_BUFFER_OVERFLOW for partial
FILE_NORMALIZED_NAME_INFORMATION responses instead of incorrectly
returning STATUS_INFO_LENGTH_MISMATCH.
* tag 'ksmbd-for-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/linkinjeon/smb:
ksmbd: keep compound responses on query info errors
ksmbd: fix partial normalized name responses
ksmbd: follow SMB2 session expiration semantics
|
||
|
|
bfda5a01aa |
- Make MFT extension work on existing Windows-created volumes by
dynamically reserving MFT tail records, accounting for records added
during allocation, and avoiding false -ENOSPC failures.
- Repack non-resident $MFT/$ATTRIBUTE_LIST when its mapping pairs no longer
fit in the base MFT record, while propagating allocation and writeback
errors.
- Serialize runlist updates with the runlist lock and restore both the
in-memory runlist and on-disk mapping pairs when allocation rollback is
required.
- Propagate folio errors and harden inode failure handling by treating
interrupted reads as transient failures and discarding and unhashing
inodes whose initialization fails.
- Fix the $MFTMirr write offset when mirror records span multiple folios,
preventing mirror records from overwriting the first record with large
MFT record sizes.
-----BEGIN PGP SIGNATURE-----
iQJKBAABCgA0FiEE6NzKS6Uv/XAAGHgyZwv7A1FEIQgFAmqtRIEWHGxpbmtpbmpl
b25Aa2VybmVsLm9yZwAKCRBnC/sDUUQhCBK8EAChFdTxig3sYog3dL27SX+1yNC4
S1QtSQMvPJzcvLG2/mESC57snx1u6AXZ6enaQ/m8zQQvkWHFdwD+odgjOQ3474Yc
MS7xQn5pCsAo3LmSWiDsQfHmvxgDMYlIRU1vmqr7fG2pj+W6BR2LB1PD3RI9exI7
0WWAXBPZH5w5C9GE1Zo7TF9Xwby5Or31RS8+R57PXA/PJ1ivpWnlkpfLi4M/YkZK
GIpunZafSpcKbEsuWcjhdz11bR4G9Qlwuuq0MDguLC/qsqsobHCeSbdx+4IsEAq5
02yBl5hYm2E4u2KBedpe7oRwFvlPN0uakEGYS8SA1ad9XamjGIw6T0tkzkDL48Pq
dhVAeX2oa8O9u+VK+qF/HIUylh/UbmHQJW8iSiZWO8WdULGBG8oCHI1hcSnMguwJ
njyK75UXz4fMsKW6ZpRu0sRGqtKKcbg8IrCvLslPIOS2A9OAwSzytDKI+x1Kbgu0
SVPYjf6XeOz83tvE+2OhfTT1hWkeKezMiUe4E/y9rgEDxv5vE4C5pvpDfRlj3oyn
2JTXXjjUQGSQw/9cKbLsbElDH/FLEojLAsIFgM+2FbcG+x7PUUgSGdC4R4qZ9MUF
cuMzfhi8vKyCYmJc8nNE4J6b6UkBNOFJMYBcArtByFW3LqfIzmqwW81Xx0Hz4cxi
dmOhD6gXXYoi9m3lBQ==
=rT1L
-----END PGP SIGNATURE-----
Merge tag 'ntfs-for-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/linkinjeon/ntfs
Pull ntfs fixes from Namjae Jeon:
- Make MFT extension work on existing Windows-created volumes by
dynamically reserving MFT tail records, accounting for records added
during allocation, and avoiding false -ENOSPC failures
- Repack non-resident $MFT/$ATTRIBUTE_LIST when its mapping pairs no
longer fit in the base MFT record, while propagating allocation and
writeback errors
- Serialize runlist updates with the runlist lock and restore both the
in-memory runlist and on-disk mapping pairs when allocation rollback
is required
- Propagate folio errors and harden inode failure handling by treating
interrupted reads as transient failures and discarding and unhashing
inodes whose initialization fails
- Fix the $MFTMirr write offset when mirror records span multiple
folios, preventing mirror records from overwriting the first record
with large MFT record sizes
* tag 'ntfs-for-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/linkinjeon/ntfs:
ntfs: fix $MFTMirr write offset when it spans multiple folios
ntfs: unhash failed inode reads
ntfs: discard inodes that fail initialization
ntfs: ignore interrupted inode reads as corruption
ntfs: propagate folio errors
ntfs: protect runlist updates with the runlist lock
ntfs: account for MFT records added during allocation
ntfs: repack $MFT/$ATTRIBUTE LIST
ntfs: use dynamic MFT tail reservation
|
||
|
|
8cb0606271 |
MMC core:
- Prevent potential use-after-free for SDIO IRQ work - Fix OF node reference leak on card add failure - Fix memory lea when the port table is full for sdio_uart MMC host: - hsq: Fix use-after-free in retry work - mmci: Fix use-after-free in busy-timeout work - mmc_spi: Reset bytes_xfered before retrying CRC failures - mxcmmc: Cancel data work and watchdog on remove - rtsx_pci_sdmmc: Ignore broken write-protect on ThinkPad X260 - sdhci_am654: A couple of fixes for the tuning sequence - sdhci-of-aspeed: Remove children before releasing SDC resources - sh_mmcif: Initialize IRQ-thread mutex before requesting interrupt MEMSTICK: - ms_block: Destroy io_queue workqueue on removal -----BEGIN PGP SIGNATURE----- iQJEBAABCgAuFiEEugLDXPmKSktSkQsV/iaEJXNYjCkFAmqtI4oQHHVsZmhAa2Vy bmVsLm9yZwAKCRD+JoQlc1iMKcjwD/91lyNP8fb8cxorEtmkiNt63Sb+glVEnobW aOlXS23GuV9ZsPw7kKEEfZ4EWCOTEZ86Lj0OMzlpXE8dxYHGlu0qG97uxSiJ4wux LQ0+OR5ljqDN48BWrn3wWsJ1YLfM4xXL7XukiCEuxLU9jwlbPHNjtY8c0+JqMapH D1yE7tH7/ZPJuYwKt9DJlx5DKg0BTiRn/7j+o3IETNyuBP05ZzrUjNdgQW8DVawg 2uR0GCZ268Asd7XhnywvLXbeg5jxRAEVMGVjEzn2CY5uY0YyUW9ye9e+TpbNqpYf OA2MnYiTNpcRIiI3Z8R5vrhGxMpqFd5hFdIUE64O5gnjSyrBKeo9SSw4huXlLvac xjdBYmtLxSQjIgvZaEG4hl12lJt/snLJODTEq690zei9oWCUnCKzZaargLFPcDje 0J8HwPYStynI0nc2Jc4oGZEGGwgvSmFPk15JtMEdmJb3eIwOfzGLA1ky9+5VEVCC zzMifnvnseAJwz+iAaJYxkED3Gd4t/jm4n8XIihddsKBQHAbMtGhUmhSzNnzD6NF xgscpv8s8SKExwS6X+6f/SBZD4VoF9b1JDhJ+fVUJDQ1Dsgv9AyT/bl8gDBHPNwr JHflPaQhc3hM9RppdcZnW3KSCu3DCJ04XaoHy6m5zKWZHUBEAtxujHA5u373Wv89 StY7v7d7UQ== =KPXN -----END PGP SIGNATURE----- Merge tag 'mmc-v7.3-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/ulfh/mmc Pull MMC/MEMSTICK fixes from Ulf Hansson: "MMC core: - Prevent potential use-after-free for SDIO IRQ work - Fix OF node reference leak on card add failure - Fix memory lea when the port table is full for sdio_uart MMC host: - hsq: Fix use-after-free in retry work - mmci: Fix use-after-free in busy-timeout work - mmc_spi: Reset bytes_xfered before retrying CRC failures - mxcmmc: Cancel data work and watchdog on remove - rtsx_pci_sdmmc: Ignore broken write-protect on ThinkPad X260 - sdhci_am654: A couple of fixes for the tuning sequence - sdhci-of-aspeed: Remove children before releasing SDC resources - sh_mmcif: Initialize IRQ-thread mutex before requesting interrupt MEMSTICK: - ms_block: Destroy io_queue workqueue on removal * tag 'mmc-v7.3-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/ulfh/mmc: mmc: sdhci-of-aspeed: Remove children before releasing SDC resources mmc: sh_mmcif: initialize IRQ-thread mutex before requesting interrupt mmc: core: Fix OF node reference leak on card add failure mmc: rtsx_pci_sdmmc: ignore broken write-protect on ThinkPad X260 mmc: sdio_uart: fix xmit_fifo leak when the port table is full mmc: spi: reset bytes_xfered before retrying CRC failures mmc: sdhci_am654: Fallback to DT-provided itap delay on DDR50 tuning failure mmc: sdhci_am654: Clear ITAPDLY on tuning failure mmc: sdhci_am654: Reset command and data lines on failed tuning mmc: sdhci_am654: Move tuning_loop to local variable mmc: hsq: Fix use-after-free in retry work mmc: mxcmmc: cancel data work and watchdog on remove mmc: mmci: Fix use-after-free in busy-timeout work mmc: core: Cancel SDIO IRQ work before freeing host memstick: ms_block: destroy io_queue workqueue on removal |
||
|
|
ae09f35bd3 |
ata fixes for 7.4-rc4
- Explicitly clear upper address bits on quirked AHCI controllers
AHCI controllers that claim to support 64-bit DMA, but which have
been quirked to only do 32-bit DMA, could start the DMA engine
with a non-zero value in the upper address bits registers (me)
- Fix a resource leak in ahci_platform_get_resources() (Wentao)
- Fix invalid kernel-doc formatting for ata_dsm_trim_pages() (me)
-----BEGIN PGP SIGNATURE-----
iHUEABYKAB0WIQRN+ES/c4tHlMch3DzJZDGjmcZNcgUCaq0h5wAKCRDJZDGjmcZN
cla0AQD9oseos93LDPzXR5SSMirdjoL9Qee8RsVeIMMlRtahiAD/Tx+vlEYrQ3QG
yESu9KV1YCaV2qDzG+nFjNt9Z6uc4wo=
=xqFb
-----END PGP SIGNATURE-----
Merge tag 'ata-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/libata/linux
Pull ata fixes from Niklas Cassel:
- Explicitly clear upper address bits on quirked AHCI controllers
AHCI controllers that claim to support 64-bit DMA, but which have
been quirked to only do 32-bit DMA, could start the DMA engine with a
non-zero value in the upper address bits registers (me)
- Fix a resource leak in ahci_platform_get_resources() (Wentao)
- Fix invalid kernel-doc formatting for ata_dsm_trim_pages() (me)
* tag 'ata-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/libata/linux:
ata: libata-scsi: fix ata_dsm_trim_pages() kernel-doc
ata: libahci_platform: Fix device reference leak in ahci_platform_get_resources()
ata: libahci: clear PxCLBU and PxFBU for AHCI_HFLAG_32BIT_ONLY
|
||
|
|
d24e3bf4c5 |
hwmon fixes for v7.3-rc4
* cgbc-hwmon: Add missing sensors, and fix current sensors ID lookup
* gpioufan: Return IRQ_HANDLED from the shared alarm IRQ handler to fix
possible interrupt storm
* hp-wmi-sensors: Improve raw WMI string handling, and fix UaF in show
function
* k10temp: Fix model id range of Zen5 Turin to stop reporting temperature
data for non-existing CCDs
* pmbus
- core: Increase number of phases to fix UaF problems
- tps53679: Fix TPS53676 phase page decoding, and select page 0
for single-page applications
* pwm-fan: Stop RPM timer before freeing tach data to fix UaF problem
* w83793: Release probe data through kref to fix UaF problem
* w83791d: Remove fan/pwm 4-5 sysfs group on remove to fix UaF problem
-----BEGIN PGP SIGNATURE-----
iQIzBAABCAAdFiEEiHPvMQj9QTOCiqgVyx8mb86fmYEFAmqtY4YACgkQyx8mb86f
mYHX0Q//UmlkmqkHH3XdKi1QX/RV60f82HfzXRkMq98FYocEYv4TKnru3U5pRLY3
Vs/h4GcDWT16ApqKbciBxgoUj72XBohm/T0gv8rhC/gkx4w8F7/CPuCB6vq9kIAj
EIOHM3KoulfwUN6K1JeFdo5sIrTMxYGnQoJjS31/HfExEGbcBMZjA4eWLkqA0s18
zmtYKbCJbG2WFRkI8/HKeQ2MwFE3RLNrxPVNvWJNzwIPjMvaAD7eDSsRjgXpaH6s
A2OHpnGkDLE1qeyuYYx+nFYmMQDGDxnt6QvEjX5cVUYE+jDIXuzF5HJVfLCaXoSJ
cFJmyNVTNE6Is1g6qeBRwObSq/NJH3O6p7kXCf5qwO27XBXgt/7K4q751tMq8oEE
kXiYn3WfBL4WJjYqQw8kEh2/D18fyj9XmoS7iBXzf1qXgRSROm/9irMBjsWiw0WF
92iE9U7UaE/a5fGX+dbRnB7QmLZ33U5TzA3ERb+MwJQj6o8Llvb5gmJOmlYebpa1
zRiu285Y3oGnjjkFgzvpps9hsVw3kb2Xs2utMbTPrJ2z4SUO9KInl+ifOr5w9VI+
sNU0Rn3eQ6IT40NMO9FhHPciZygKmob6hNDYh/6e+OulMDW7XW46ES2e8jjwME30
fjDpfKDxoAU/xQ548XQJBRcUNjUhV8S6NYZr3H4PpyWlPVmSkOY=
=lG35
-----END PGP SIGNATURE-----
Merge tag 'hwmon-for-v7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/groeck/linux-staging
Pull hwmon fixes from Guenter Roeck:
- Add missing sensors, and fix current sensors ID lookup (cgbc-hwmon)
- Return IRQ_HANDLED from the shared alarm IRQ handler to fix possible
interrupt storm (gpioufan)
- Improve raw WMI string handling, and fix UaF in show function
(hp-wmi-sensors)
- Fix k10temp model id range of Zen5 Turin to stop reporting
temperature data for non-existing CCDs
- pmbus:
- Increase number of phases to fix UaF problems
- Fix TPS53676 phase page decoding, and select page 0 for
single-page applications
- Stop pwm-fan RPM timer before freeing tach data to fix UaF
- Release w83793 probe data through kref to fix UaF
- Remove w83791d fan/pwm 4-5 sysfs group on remove to fix UaF
* tag 'hwmon-for-v7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/groeck/linux-staging:
hwmon: (hp-wmi-sensors) Improve raw WMI string handling
hwmon: (pmbus/tps53679) Select page 0 for single-page TPS53676
hwmon: (pmbus/tps53679) Fix TPS53676 phase page decoding
hwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show()
hwmon: (w83793) release probe data through kref
hwmon: (w83791d) remove fan/pwm 4-5 sysfs group on remove
hwmon: (gpio-fan) return IRQ_HANDLED from the shared alarm IRQ handler
hwmon: (pmbus/core) increase number of phases and add new mask
hwmon: (cgbc-hwmon) Add missing sensors
hwmon: (cgbc-hwmon) Fix current sensors ID lookup
hwmon: (pwm-fan) Stop RPM timer before freeing tach data
hwmon: (k10temp) Fix model id range of Zen5 Turin
|
||
|
|
928ba50514 |
watchdog fixes for v7.3-rc4
* da9062, da9063: Fix suspend/resume handling of HW_RUNNING watchdog * digicolor, rtd119x, and rzv2h: Avoid division by zero if clock rate is 0 * msc313e: Fix premature reset during timeout update, and propagate error code in resume() * sp5100_tco: Fix pci_dev reference leak in sp5100_tco_init() * starfive-wdt: Fix runtime PM leak in starfive_wdt_pm_start() -----BEGIN PGP SIGNATURE----- iQIzBAABCAAdFiEEiHPvMQj9QTOCiqgVyx8mb86fmYEFAmqtZJEACgkQyx8mb86f mYGnwA/8C90wOrDbHonYx0SahuJaYniOmz6yHCuAR1AwtzKfXDua3WJ7ry4WfZXN WCACTcFCUp1CiLvstwpX7nDKGReYG47FOq6Rbou+JaJo43m9SGga5IGxKM28MBy7 F4TH3CDMSOcomlgPYeXc5jx0oRkNXyDPMDHtbCOM5h+WwJb0Zxtfh+77l5q2LrQg D7nIGCkoztl7PDIgbvYESp9DYVdUgT6paeIRjJbs5BCwmNleU9LInDPDAtcXHnRp cyCa8FlfPrQMxhtbF1YQyaEdU04GlAwtHW4HE55tcxY3pTE/9qqA5SUzQBDXT2gO yCCG1qIFOmJY6QnlSfIYpHZtNxcpA75d8fQvqm14H+ACxkbaRF1d+sobtJTTckTD WBSr6RlrB5f/DAltqbV2OAsLddhBl4rQkW2RiljTW4C4pUiedPoSR8StTpnM6lC3 VBpUdYp7tCIWihX/v/v+iRK1Y7JWVM+lhQnMpqBtpLtl3k7VLCLoFsmSbz0hHhu6 kAJ1ZWeBy2xYgiGOM+D361iKhefjsZk9tdrC8IxriJ/gUwlcazELqqcsvU+I5ebN sutAYvE6Vdl5qwiLIRRHNpHvKm0wu9URIpPJrdwDtAIbaT3joSZIkV3TA7ZFBwGG tU4Z9ok0O4N4DDPv0CAg82lXBrMiWt3agYKKkhKTsmKROqqWVa8= =oqFf -----END PGP SIGNATURE----- Merge tag 'watchdog-fixes-for-v7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/groeck/linux-staging Pull watchdog fixes from Guenter Roeck: - Fix suspend/resume handling of HW_RUNNING watchdog (da9062, da9063) - Avoid division by zero if clock rate is 0 (digicolor, rtd119x, and rzv2h) - Fix premature reset during timeout update, and propagate error code in msc313e resume() - Fix pci_dev reference leak in sp5100_tco_init() - Fix runtime PM leak in starfive_wdt_pm_start() * tag 'watchdog-fixes-for-v7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/groeck/linux-staging: watchdog: da9063: fix suspend/resume handling of HW_RUNNING watchdog watchdog: starfive-wdt: Fix runtime PM leak in starfive_wdt_pm_start() watchdog: da9062: fix suspend/resume handling of HW_RUNNING watchdog watchdog: msc313e: Fix premature reset during timeout update watchdog: msc313e: Propagate error code in resume() watchdog: rzv2h: Avoid division by zero watchdog: rtd119x: Avoid division by zero watchdog: digicolor: Avoid division by zero watchdog: sp5100_tco: Fix pci_dev reference leak in sp5100_tco_init() |
||
|
|
5ad17a9760 |
This push fixes a regression in caam.
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEEn51F/lCuNhUwmDeSxycdCkmxi6cFAmqqZ7AACgkQxycdCkmx i6d4jA/+Ozs275ubKEbaC+keI4/G8DZ/QDYFOTCr4SEBWHyhGh1od29AbHXhUGof 3Ev/Zzqg9mWRDhLo+tbx/ja9Qe3d7lHCHPcFPUsom0MumfGm8NaWgGxaxrrhRYwY EOks6UxolxUCw65/ECxcgxsOfp6LgcrNuapkIJRcg1R5s6kz9zAGhse+13AgAv1G 49x+AL1KkvJkPev6lZrhG+m0SX3P7CO5OVAe0NNFqSlaxBSg3JSO/JnEQK95B7vi cakFjskdfukqQs84hOq+KPI93pqbi7aZEemVsxGK2UdADVRr7C3Ls6nKiGQ7VtyR EW2hniQxHOruvDrXHMJpE92/Tw7g0LL6O5CZuKe+p2MfnQKEvVpPuWwysug0AhVU cKV4mBX/fu2bgV7o2QEGByhhAuCtcezGqbX5o2cYLdn/jX2DErNTWzLbdUHpcgLu bTWtIWzEwKZgqU5Oa9i4J6TdV6xcReh7gKKWykrQVodnvin6sUywsMmX3vkl33VJ upVo1FhLZnv0krUMTGUDNTzuVczEliM8c+dMEJcGLAzM3d0SdduRSukznX09Wrj8 yS0AH3Tqn81Ux5FWYxNMPSeKaTIRX14LG3jjzsLSq9iMTM50dZf6xmOS9ZyYh/+j tq3fPrBf3PVipdI9xhDOqDF9gYtG+FgVwt93Pb0Ao569HgWyS5c= =odnL -----END PGP SIGNATURE----- Merge tag 'v7.3-p4' of git://git.kernel.org/pub/scm/linux/kernel/git/herbert/crypto-2.6 Pull crypto fix from Herbert Xu: "Fix a regression in caam" * tag 'v7.3-p4' of git://git.kernel.org/pub/scm/linux/kernel/git/herbert/crypto-2.6: crypto: caam - map job ring registers without claiming region |
||
|
|
f259f446f5 |
soc: fixes for 7.3
The driver fixes are all for simple mistakes: a use-after-free bug on Samsung Exynos, error handling and reference counting on Arm SCMI firmware and a problem dealing with inconsistent firmware information. The rest are devicetree fixes for arm64 platforms from Altera, Renesas and Amlogic. On the Renesas platform, one patch addresses a boot time regression, the rest address minor performance and correctness issues. -----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEEo6/YBQwIrVS28WGKmmx57+YAGNkFAmqtProACgkQmmx57+YA GNku+BAAsyHGF7f7tniVyH1lDfZ+BY8G0i8856Pgi6xJfwTPcrtxJe15ALFJz5sa DRvCmt3fx2e4LmED2wEfTVYr+RIEmlgD27pT8lUvMo4avIcXlIxtAlqCOyKTOALS LzOJPD5VaEs/ZKXqqGDPnHzYJNO9DJ18uAuk8yGY7cK4z4IV+aANCJzCN83vhYu2 OAl37i/0PmaMhHTgLgIugd2uc28GJsyZQiFu9k9hlRWGjn9WpYivSohbF8p8Cqcw Eg/TzWVNcTrm95uuHbhaQ3tsYDtBHoy5V7e5w1a4NnJ7ufouW/I1Z9s2OrulWadY 3Hw/pEtrkWAgK1NMfAaXtErkWUjuKeMRzWwOZ0NR4Zi0Zsdt+VTyDajSLbUEuePI AfknmGcrgSIgK/HlSkLw5R0VnYI8duUjnBSDVTKBLMxFnAdBs/vDhr/ZDy8HgLjN i+Poe36q6JLTw88/d/uF+2T2HdZXwPiL9tDl16WmAUQOvZOcr6dfQdLZGIb8zwuV rghM9rnh7v2Lb5nFsC++MebH2xNw33faWplpnc0WxcUdzov20Wcr7IbdNVzKaVTn IcnjnTtCCaxXM9NxyjMrxJ8+tkkFAPyDczSPxcxL3xcOjoQ2nr4XlfPMaYwoV2N7 siwksezj55bWANuZwxObou3ZJgHHFqO0RYUdtJxDn/mBnWNOq3A= =Z5GP -----END PGP SIGNATURE----- Merge tag 'soc-fixes-7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/soc/soc Pull SoC fixes from Arnd Bergmann: "The driver fixes are all for simple mistakes: a use-after-free bug on Samsung Exynos, error handling and reference counting on Arm SCMI firmware and a problem dealing with inconsistent firmware information. The rest are devicetree fixes for arm64 platforms from Altera, Renesas and Amlogic. On the Renesas platform, one patch addresses a boot time regression, the rest address minor performance and correctness issues" * tag 'soc-fixes-7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/soc/soc: (21 commits) soc: samsung: exynos-pmu: fix use-after-free of interrupt generator node arm64: dts: renesas: r8a779f0: Set UFS lane count firmware: arm_scmi: Fix typo "upto" in comment arm64: dts: renesas: r9a09g087: Switch GBETH TX queue scheduling to WRR arm64: dts: renesas: r9a09g077: Switch GBETH TX queue scheduling to WRR arm64: dts: renesas: r9a09g047: Switch GBETH TX queue scheduling to WRR arm64: dts: renesas: r9a09g056: Switch GBETH TX queue scheduling to WRR arm64: dts: renesas: r9a09g057: Switch GBETH TX queue scheduling to WRR firmware: arm_ffa: Tear down driver during shutdown clk: scpi: use PLATFORM_DEVID_NONE for scpi-cpufreq clk: scpi: register scpi-cpufreq once and clear on failure clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS firmware: arm_scpi: fix device_node leak in scpi_dev_domain_id arm64: dts: socfpga: change access permission from 755 to 644 ARM: socfpga: select the PL310 erratum 753970 workaround arm64: dts: amlogic: t7: fix the pin groups of the vsync PWM arm64: dts: amlogic: t7: khadas-vim4: add the PWM-driven supplies arm64: dts: amlogic: t7: fix the pin groups of two PWM outputs arm64: dts: amlogic: t7: khadas-vim4: allow the SD card to be power cycled ... |
||
|
|
a077be4fde |
arm64 fixes for -rc4
- Fix hypercall arguments when resetting EL2 vectors during hibernation
- Fix hibernation with 52-bit capable kernels on machines without
52-bit addressing, similarly to the recent kexec fix
- Fix a bunch of clumsy codegen issues with our per-cpu accessors
- Fix MTE ptrace documentation to reflect the de-facto ABI behaviour
- Fix pthread_join() usage in MTE selftest
- Fix port selection in the Arm CMN PMU driver
-----BEGIN PGP SIGNATURE-----
iQFEBAABCgAuFiEEPxTL6PPUbjXGY88ct6xw3ITBYzQFAmqtMZ4QHHdpbGxAa2Vy
bmVsLm9yZwAKCRC3rHDchMFjNNujB/4pa4pdivXRMOH39HSDu+8i3KlREGpTA9dq
LJvwUjlgoIw0d8/b5sMSAxJi8RA29IENJPqrU97eBBLKgC2gq1oMwjOaHNTV8XUj
gal9hwuZcfO5NIJi61TkyLxn++ysVYXD3J0tbhSXbqz2oeg/jxwj9SsFfQux34GY
GeGb2cWvEXznLgN0h+vZiNh6+FsQRN+dizpiHKLh+wpbZ/vIzuVTQEo6w/+BEUWg
R4YQlvpj/2yAC0BBdPb9gALUWFbjea6zpX5gM5/PgLoqW0CIJvGXahZ7T5kDoXBT
Xp5zsKvcC8dxM5nCJIJ7xRPg75v97toYrrl2AoNQN9bgOynQAI5k
=j0NQ
-----END PGP SIGNATURE-----
Merge tag 'arm64-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux
Pull arm64 fixes from Will Deacon:
"In this batch we've got a couple of hibernation fixes, a couple of
minor MTE fixes, some per-cpu codegen fixes (which were found as part
of Mark's series adding preemptible this_cpu_*() operations) and a fix
for the Arm CMN PMU driver.
Summary:
- Fix hypercall arguments when resetting EL2 vectors during
hibernation
- Fix hibernation with 52-bit capable kernels on machines without
52-bit addressing, similarly to the recent kexec fix
- Fix a bunch of clumsy codegen issues with our per-cpu accessors
- Fix MTE ptrace documentation to reflect the de-facto ABI behaviour
- Fix pthread_join() usage in MTE selftest
- Fix port selection in the Arm CMN PMU driver"
* tag 'arm64-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux:
arm64: mte: Fix PTRACE_{PEEK,POKE}MTETAGS error documentation
kselftest/arm64: Fix size of thread_data values for pthread_join()
arm64: percpu: Fix LSE operations on {8,16}-bit types
arm64: percpu: Fix this_cpu_and() mask generation
arm64: percpu: Fix this_cpu_write() casting
arm64: hibernate: clone only the linear map that exists at runtime
perf/arm-cmn: Fix wp_dev_sel2 setting for multi-DTM configurations
arm64: hibernate: pass HVC_SET_VECTORS args to the resume hvc
|
||
|
|
5023f5b861 |
- Fix kconfig dependencies for ECONET
- Enable weak reordering for EYEQ - Include USB FDT fixup for Octeon even when USB is modular -----BEGIN PGP SIGNATURE----- iQJOBAABCAA4FiEEbt46xwy6kEcDOXoUeZbBVTGwZHAFAmqs5dUaHHRzYm9nZW5k QGFscGhhLmZyYW5rZW4uZGUACgkQeZbBVTGwZHBYbg//QPIXQOga1IcvP7OJlLxu UocYmNpgVJtPCksDtnBUx82o/D+CZdqeGtHNP6ak5YpyXOcQpUdMuYSwHwIXsHLB HhVOBmyVgyNlP0zo8zXE3iW1JMz1wfSSigDZdPFX8Jq3O5RsMq3udHJYZtAEXnIM eV8m465I9DnJWX9mlETqTli5cwL5VpDYRSy1fmGF4CYgRvbErrUZ0iZSvqdwRe7v J/p+sLBsSmEoxXL5etpvHLet+Jr9Eb8v+1k8262YcoPfvENeu3cYJpvZnIgXmeol T912xD+JmLapcICNot0QvrMZJ3RVSu/Z6ddxCGqHmiEiQGMYB9xrWYbgfQ/9hGKp aup5G1X3n3YPKd60DKRnSFgZ4+xPzEoUTh5nKlMz0XqZmtoa9m00BRTXhi8XoqFK kvBRJREb4Za3Ig40dhIJTcluLoLjgPqUs+1MfwnFnXZTbuctSZ4BtEauQL1x/A6E EbQ7gvesMQHUwW6fb70U9UbhlKuI/8t1Ao7OuI5+qs6+qnvgiScavW8CDu+W16s1 tbFQFUN1ZkP0a0SXkl5JGu6WOkl9fc3TkBDrmfuK68Fu2hUMAiE/ffCoBq+6iZBj pkagkDr5CjFxogpKveE02l9WJAVAujzMmyCusTv2NQ53mu2ZloCT3BA3cKsM6vFP dPtQD7d5qIEK3WPMENxCrcA= =PNfi -----END PGP SIGNATURE----- Merge tag 'mips-fixes_7.3_1' of git://git.kernel.org/pub/scm/linux/kernel/git/mips/linux Pull MIPS fixes from Thomas Bogendoerfer: - Fix kconfig dependencies for ECONET - Enable weak reordering for EYEQ - Include USB FDT fixup for Octeon even when USB is modular * tag 'mips-fixes_7.3_1' of git://git.kernel.org/pub/scm/linux/kernel/git/mips/linux: MIPS: Octeon: apply USB FDT fixups also when USB is modular mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ MIPS: config: Add EcoNet EN751221 defconfig mips: econet: fix unmet dependencies for ECONET |
||
|
|
7cb575b71a |
watchdog: da9063: fix suspend/resume handling of HW_RUNNING watchdog
da9063_wdt_suspend() and da9063_wdt_resume() only check watchdog_active(),
when the watchdog is left running by the driver sets
WDOG_HW_RUNNING in da9063_wdt_probe() but userspace never opens the
device, so WDOG_ACTIVE remains cleared, the wdt_disable() will not be
executed in da9063_wdt_suspend. In this case, the suspend callback is
a no-op and the watchdog keeps counting during system suspend,
leading to an unexpected system reset.
Check WDOG_HW_RUNNING and wdd,can fix this issue.
Fixes:
|
||
|
|
4dd1999783
|
soc: samsung: exynos-pmu: fix use-after-free of interrupt generator node
The setup_cpuhp_and_cpuidle() parses the device tree node for the
interrupt generation block via of_parse_phandle() and decrements its
reference count using of_node_put() immediately after fetching the resource
address. However, later the intr_gen_node pointer is passed into
of_syscon_register_regmap().
Fix this by declaring intr_gen_node with __free() and removing
of_node_put().
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/20260513-exynos850-cpuhotplug-v4-0-54fec5f65362@linaro.org?part=3
Fixes:
|
||
|
|
2d5061ff37 |
Renesas fixes for v7.3 (take two)
- Fix UFS regression on R-Car S4. -----BEGIN PGP SIGNATURE----- iHUEABYKAB0WIQQ9qaHoIs/1I4cXmEiKwlD9ZEnxcAUCaqztfAAKCRCKwlD9ZEnx cLmlAP4hG63oxIP1QUeZpEMjRkTBGhFXnlSkvluVyrd8otWniQEAvCCC31KtKqqK B9W1mWzwBX9UITXB4cL69Zw/26W9+QI= =5xv9 -----END PGP SIGNATURE----- gpgsig -----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEEo6/YBQwIrVS28WGKmmx57+YAGNkFAmqtL8EACgkQmmx57+YA GNkQ9A/9FuSvFGANim6ksz5JN4ObTC4hjJu8rxrxF3uGekQNJZPO06EDU9DkM/bJ XOLDFkt3k+M3e60wdH9NKzEl54xQxyLre2XyRN2diit3ihDF9Jrv3YPFzuZcA+gR vmRh9LLIStdDNxGbRrEubfx1+WqbiNpkXqE8syXVsn93hYduMsWnrSReXA5jGENt Wjq9ghujL9Othgh8B1FOi6W4oupsBN1mCLAL0DJ0k8z0whBfb2Qkq5tnrDCPcjXc CVKzVWqe5nIMw5akMu14MToId3JpTxTrws5FOP4OUoxEVL/sCBUbS4PNujgHEMVh Ovd5DmpfNjWOB+rr4/B/u2H97e6AmNvCp5Sbd8gADBCO7RHD9zxYbGYPy9Pemhqd YBNAufAR3Bkkq0IheXVS5Dtzg2TSUchomaIz7o/hhMBu4lLdaVJyyalAy5bVOR1W l7DtetG1DqABWAsF5pm0Q8iy7lFEJlzWdhzONJn4TBCXOLi6k3lO07gmd+eIYhyM EvssZFTciDoyhurdDgqeLfjKQvvgiOi0l4SpdT606+YMipz5C5zo0oPOk4j26qvp 22Mw3JupFQCDCwsN37locBhQccdKfHuzfsy52vDMxHRuOcpnfIIcCsPkaMq5VMQu Bm8c3No5AJQGcODe4Rg7nmZrxzSNnilWGxKSkWH7C0J5vbzuXRY= =9HfJ -----END PGP SIGNATURE----- Merge tag 'renesas-fixes-for-v7.3-tag2' of git://git.kernel.org/pub/scm/linux/kernel/git/geert/renesas-devel into arm/fixes Renesas fixes for v7.3 (take two) - Fix UFS regression on R-Car S4. * tag 'renesas-fixes-for-v7.3-tag2' of git://git.kernel.org/pub/scm/linux/kernel/git/geert/renesas-devel: arm64: dts: renesas: r8a779f0: Set UFS lane count Signed-off-by: Arnd Bergmann <arnd@arndb.de> |
||
|
|
96443a53bc |
selftests/x86: Check signal state for rejected software interrupts
Add a test of the signal ABI for INT instructions in both 32-bit and 64-bit processes. Check the signal number, trap number, error code, si_code, si_addr, instruction pointer and RF/TF state against legacy IDT behavior. Include a 15-byte prefixed INT to check that IP uses the hardware instruction length. Exercise both INT3 encodings, INT4, UD2 and HLT to cover the unchanged trap and fault paths. Run each instruction with TF clear and set. Resume at a known NOP after handling the signal and check that single-stepping traps after the NOP. Also drive INT 0x2d under ptrace, which resumes through the fault frame rather than sigreturn and so exposes a stale FRED software event flag. Start from an INT3 stop, whose FRED frame has no software event flag, instead of the syscall frame of raise(SIGSTOP). Single-step into the INT and check that the fault reports its address. Then suppress SIGSEGV and resume at the NOP, once with PTRACE_SINGLESTEP and once with PTRACE_CONT and TF set. Section 6.2.3 of the Intel FRED specification [1] specifies the immediate single-step trap caused by returning with both that flag and TF set. Check that each trap occurs after the NOP, rather than at its address. Report whether the CPU supports FRED, since a pass looks the same on either entry path. INT 0x80 with IA32 emulation disabled and a 64-bit tracer of a 32-bit tracee are not covered. Both variants pass all 29 checks on a non-FRED AMD host and on Panther Lake with FRED enabled and the fix applied. With the same binaries on unpatched Panther Lake, 16 signal-context checks fail and the first ptrace check reports the IP after the INT. The two dependent ptrace resume checks are not reached. [1] Intel Flexible Return and Event Delivery (FRED) Specification, revision 9.0 (346446-009US), section 6.2.3. Signed-off-by: Matthew Schwartz <matthew.schwartz@linux.dev> Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org> Link: https://cdrdv2.intel.com/v1/dl/getContent/678938 # [1] Link: https://patch.msgid.link/20260917230907.2080792-3-matthew.schwartz@linux.dev |
||
|
|
93f53499d0 |
x86/fred: Reconstruct the #GP context for rejected INT instructions
FRED event delivery does not use the IDT, so the gate DPL check that
rejects a user INT n falls to software (Intel FRED specification [1],
section 8.3). fred_intx() rejects the same vectors as IDT delivery, but
reports a zero error code and the IP after the INT. This breaks the
signal ABI. Wine uses the error code to recognize INT 0x2d, so the
changed context turns a handled breakpoint into an access violation in
Elden Ring.
Rewind IP using the instruction length in the augmented SS and
synthesize the IDT selector error code, (vector << 3) | 2. Set RF in the
saved flags, as the CPU does for a #GP fault. Section 5.2.1 defines the
saved vector, instruction length and RF state. The supplied length
handles prefixes without reading user memory. Limit the changes to
already-rejected software interrupts, preserving the accepted INT3, INT4
and enabled INT80 paths and hardware exceptions. With IA32 emulation
disabled, INT 0x80 now reports the same #GP as the DPL 0 gate IDT
installs there. The rewound IP also stops fixup_iopl_exception() from
inspecting the byte after the INT.
Also clear the software event flag. Section 6.2.3 specifies that ERETU
with this flag and TF set traps before executing any user instruction. A
tracer that suppresses SIGSEGV and resumes with TF set expects the next
instruction to run first, as after IRET. The sigreturn path clears the
same flag for this reason in prevent_single_step_upon_eretu().
[1] Intel Flexible Return and Event Delivery (FRED) Specification,
revision 9.0 (346446-009US), sections 5.2.1, 6.2.3 and 8.3.
Fixes:
|
||
|
|
fe3c73d7bc |
sched/core: Avoid false migration warning for proxy donors
Proxy execution can move a blocked donor's scheduling context to the
lock owner's CPU even when the donor is migration-disabled. The donor
does not execute there, and its original execution CPU remains recorded
in wake_cpu.
set_task_cpu() warns unconditionally for migration-disabled tasks, so a
subsequent proxy migration or the wakeup path returning the donor home
triggers a false positive: moving a blocked scheduling context does not
violate the migration-disabled execution context.
For example, creating a mutex owner on CPU1 and a migration-disabled
waiter on CPU0 can trigger the following warning:
proxy_migrate_repro: donor blocking on CPU0 with migration disabled
proxy_migrate_repro: donor moved from CPU0 to CPU1
WARNING: kernel/sched/core.c:3389 at set_task_cpu+0x1d3/0x280
...
Call Trace:
try_to_wake_up+0x43f/0x780
__mutex_unlock_slowpath+0x330/0x540
owner_fn+0x9f/0xc0 [proxy_migrate_repro]
...
proxy_migrate_repro: donor woke on CPU0, task_cpu=0
proxy_migrate_repro: completed
Exclude blocked proxy donors from the warning. The proxy wakeup path
restores an executable placement before clearing the blocked state.
Fixes:
|
||
|
|
88aed0422f |
perf: Fix null pointer access in is_include_guest_event()
A typical module unload occurring event when there is an active perf
connection leads to freeing of the pmu pointer. The call log is something
like:
..
__pmu_detach_event
pmu_detach_event
pmu_detach_events
perf_pmu_unregister
..
__pmu_detach_event() sets event->pmu to null. When the perf connection
finally is closed, the following stack trace is observed:
Oops: general protection fault, kernel NULL pointer dereference
...
RIP: 0010:_free_event+0x3e/0x370
...
Call Trace:
...
perf_event_release_kernel+0x260/0x2d0
perf_release+0x12/0x20
A call to mediated_pmu_unaccount_event() inside _free_event() is the root
cause of this crash. Adding a check inside is_include_guest_event() ensures
we don't accidentally access a null pmu ptr. In addition to this, we will
now call mediated_pmu_unaccount_event() before clearing the pmu ptr so that
nr_include_guest_events counts are maintained correctly.
Fixes:
|
||
|
|
94f69bfa18 |
amd-drm-fixes-7.3-2026-09-17:
amdgpu: - SMU 14.x fix - DC IRQ fix - Runtime PM fix for P2P - RAS fix - PCIe reporting fix - DCN 6 fix - Device removal fix - DC MALL fix amdkfd: - GC 12.x fixes - Boundary checks - Mapping clear fix -----BEGIN PGP SIGNATURE----- iHUEABYKAB0WIQQgO5Idg2tXNTSZAr293/aFa7yZ2AUCaqxIpQAKCRC93/aFa7yZ 2HcZAP9ZA5cERbp6QfT0a1tT3kDoMP02BKev5/XUNWEJjdgOYAEAsCj7UFE4oKjb 0996gK/lJvqq9lOgFTJnwl/z2jwytA0= =Ye34 -----END PGP SIGNATURE----- Merge tag 'amd-drm-fixes-7.3-2026-09-17' of https://gitlab.freedesktop.org/drm/amdgpu/kernel into drm-fixes amd-drm-fixes-7.3-2026-09-17: amdgpu: - SMU 14.x fix - DC IRQ fix - Runtime PM fix for P2P - RAS fix - PCIe reporting fix - DCN 6 fix - Device removal fix - DC MALL fix amdkfd: - GC 12.x fixes - Boundary checks - Mapping clear fix Signed-off-by: Dave Airlie <airlied@redhat.com> From: Alex Deucher <alexander.deucher@amd.com> Link: https://patch.msgid.link/20260917201213.3880863-1-alexander.deucher@amd.com |
||
|
|
cd011719ba |
Merge tag 'drm-intel-fixes-2026-09-17' of https://gitlab.freedesktop.org/drm/i915/kernel into drm-fixes
drm/i915 fixes for 7.3-rc4: - Revert a commit touching registers that don't necessarily exist - Check for negative numbers before passing to BIT() Signed-off-by: Dave Airlie <airlied@redhat.com> From: Jani Nikula <jani.nikula@intel.com> Link: https://patch.msgid.link/3f86e0ede95fb3d52053934ac43c5271812428f5@intel.com |
||
|
|
c24f824f0b |
Couple shrinker related fixes plus a series of patches fixing several
xe_mmio_gem issues around fault handler and destroy path. -----BEGIN PGP SIGNATURE----- iQEzBAABCgAdFiEEbSBwaO7dZQkcLOKj+mJfZA7rE8oFAmqr550ACgkQ+mJfZA7r E8p3UggAtIEI+BFbK7zeELK3zEtO85WQnIvUP/PprLu9Ga7Vvl+quXxZrWCHYcIE VwcK/5y2BGVKBmR1Vwm+PNBmtlbrNvIPGTn9u0oXB1bWVKqPT5o5MjY7lxdWhK95 MkLFo7rsQM791DAEUeo6IzbdHd6K9k2At8Yzz5+1zt97zxGmXSNpGRxV6Ee8/crU e/B1cQSfY8I4sjhAormTLZ13M6vRh1Yoy5P21UdCqIU/Eq/PjpkW2bcmM6+8K+qO 2a4y2CHIQnd+2bR4nEnuHYIa6DVuXEZIHh5v/8amenuZqBgVj7OcxUKiiZ4TnhMY bGe1UFyy0OWyEJ/X4ddGfCggpiFi6w== =0FwX -----END PGP SIGNATURE----- Merge tag 'drm-xe-fixes-2026-09-17' of https://gitlab.freedesktop.org/drm/xe/kernel into drm-fixes Couple shrinker related fixes plus a series of patches fixing several xe_mmio_gem issues around fault handler and destroy path. Signed-off-by: Dave Airlie <airlied@redhat.com> From: Rodrigo Vivi <rodrigo.vivi@intel.com> Link: https://patch.msgid.link/aqvoKaPuLLPBGayA@intel.com |
||
|
|
e7d3e2f46d |
x86/microcode/intel: Reject problematic loading on Granite Rapids systems
Microcode updates can usually jump revisions. However, there is an erratum on Granite Rapids systems. If they "jump over" revision 0x1000405, they result in an #MC. Avoid it. Signed-off-by: Chang S. Bae <chang.seok.bae@intel.com> Signed-off-by: Borislav Petkov (AMD) <bp@alien8.de> Reviewed-by: Dave Hansen <dave.hansen@linux.intel.com> Cc: stable@vger.kernel.org Link: https://patch.msgid.link/20260916225939.1144524-1-chang.seok.bae@intel.com |
||
|
|
5dd1818b15 |
Hi
Please pull these bug fixes for keys accumulated since v7.3-rc1. BR, Jarkko -----BEGIN PGP SIGNATURE----- iHUEABYKAB0WIQRE6pSOnaBC00OEHEIaerohdGur0gUCaqxgxQAKCRAaerohdGur 0jQdAQDG18jcqZxuj+DC4H5FIqRNBn+YhhRA2iOT1Qwc6wSpNAEAkgl6rdm4KY8l EQj0HTbX8qEXSsuGGkoA41lYlwf0pAY= =jCQU -----END PGP SIGNATURE----- Merge tag 'for-next-keys-v7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/jarkko/linux-tpmdd Pull key fixes from Jarkko Sakkinen. * tag 'for-next-keys-v7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/jarkko/linux-tpmdd: KEYS: encrypted: fix integer overflow of datablob_len KEYS: trusted: Fix tpm2_load_cmd() boundary check keys: translate request_key_auth pid for the reading procfs instance keys: fix lost wakeup when reaping a dead key type |
||
|
|
717e0a2503 |
cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
When a secondary channel is no longer supported by the server,
cifs_chan_skip_or_disable() drops the channel reference with
cifs_put_tcp_session() and then continues to use the server pointer by
calling cifs_signal_cifsd_for_reconnect() on it and reading its
primary_server pointer. cifs_put_tcp_session() can drop the last
reference of the channel and tear it down, so both the channel and the
primary server (whose reference is also dropped by
cifs_put_tcp_session()) can be freed before they are signaled for
reconnect.
Signal the channel and the primary server and capture the primary
server pointer before dropping the channel reference with
cifs_put_tcp_session().
Fixes:
|
||
|
|
c9dc7d7303 |
PCI: imx6: Move clock enable after core reset assertion
Commit |
||
|
|
3d743adf09
|
spi: fsl-qspi: Reprogram the clock rate when the operation frequency changes
fsl_qspi_select_mem() returns early when the chip select has not changed,
which happens before it reaches clk_set_rate(). Since the rate is now
taken from the spi-mem operation rather than from the SPI device, the
controller honours op->max_freq exactly once per chip select and ignores
it for every operation after that.
q->selected is only reset to -1 in fsl_qspi_default_setup(), i.e. at probe
and on resume, so on the common single chip select board the very first
operation latches a rate that all subsequent operations inherit, whatever
frequency they asked for.
This results in operations being issued with the wrong frequency.
Cache the operation frequency the clock was programmed for next to the
selected chip select, and redo the clock setup when either changes.
Fixes:
|
||
|
|
5f0306e731 |
smb: client: fix reparse buffer bounds in cifs_query_reparse_point()
In cifs_query_reparse_point(), the start >= end check before casting to
struct reparse_data_buffer * only ensures the start pointer is within the
response. It fails to verify that there is enough space remaining for the
fixed 8-byte header of the structure.
If a server provides a DataOffset that leaves less than 8 bytes remaining,
the check passes, but subsequent reads of ReparseTag and ReparseDataLength
will occur out-of-bounds.
Fix this by ensuring the remaining space is at least the size of the
reparse_data_buffer structure before accessing its fields.
Fixes:
|
||
|
|
4775c3b7a5 |
smb: client: fix potential OOB read in smb3_enum_snapshots()
If snapshot_array_size is smaller than GMT_TOKEN_SIZE,
smb3_enum_snapshots() sets ret_data_len to
sizeof(struct smb_snapshot_array) without verifying the actual length
of the server's reply.
Because SMB2_ioctl() places no lower bound on the server-supplied
OutputCount and allocates retbuf to exactly that length, a short reply
results in ret_data_len exceeding the size of retbuf. The subsequent
copy_to_user() then reads past the end of retbuf, leaking adjacent slab
memory to userspace. The subsequent clamp check is ineffective as it
only reduces ret_data_len.
Fix this by rejecting replies shorter than
sizeof(struct smb_snapshot_array) with -EIO. Note that the bound is set
to the 12-byte struct size rather than the 16-byte
MIN_SNAPSHOT_ARRAY_SIZE defined in MS-SMB2 3.3.5.15.1, because 12 bytes
is exactly what copy_to_user() attempts to read.
Fixes:
|
||
|
|
b09d092eb2 |
smb: client: fix missing iov bounds check in parse_posix_sids()
In parse_posix_sids(), sidsbuf_end is calculated using the server-supplied
out_len without being validated against the actual length of the received
iov (iov_len).
If a server provides an inflated out_len, sidsbuf_end will point past the
end of the iov. This defeats the bounds guards in posix_info_sid_size(),
allowing out-of-bounds reads into adjacent kernel memory.
Fix this by rejecting responses where the calculated sidsbuf_end would
exceed the received iov boundaries or cause pointer wraparound.
Fixes: a90f37e3d7ac ("smb: client: parse owner/group when creating reparse points")
Cc: stable@vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
Reviewed-by: David Howells <dhowells@redhat.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
|