mirror of
https://github.com/torvalds/linux.git
synced 2026-09-20 19:01:02 +02:00
185a4caeec
1464154 Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
f4fb100039 |
s390 updates for 7.2-rc3
- Fix missing array_index_nospec() call in diag310 memory topology code to prevent speculative execution with a user controlled array index - Fix get_align_mask() return type to match vm_unmapped_area_info align_mask, avoiding possible truncation for future larger masks - Remove empty zcrypt CEX2 files left over after CEX2 and CEX3 driver removal - Add build salt to the vDSO so it gets a unique build id, similar to the kernel and modules -----BEGIN PGP SIGNATURE----- iQEzBAABCgAdFiEE3QHqV+H2a8xAv27vjYWKoQLXFBgFAmpT1poACgkQjYWKoQLX FBgEkAf/f/qKKj7ojuIsHoPpgTun3csqbGJqOnLShYaX3itzN8wbT5m0JGbKAKfv BMpu5LSC5auGF6fvRhfJM/RbSX2LgEOMBtjx9kSAFFbNtkzu5urzZ1QFQyJ+DZq+ 0Ny8E1ozB5dlizqqIIzijyAXbMt5vDrlaPKUh+LJMlkA0OY9NUt+KLah3soEexli Oh18KMzrmik/SOr0qCuxrUa0Z0B5i2q8mp9AaS9/YaOHeuBspm4G47XKMHg4UMg8 yMb7ofaX4isgRYXrDsNUkLGe/KPkwntWnU7EVVJH/u4ZkjUlwEyIH0lhp6BnVlte LSQ4742J4lxHa2Y+sQDxzFgaFr6reA== =FOvG -----END PGP SIGNATURE----- Merge tag 's390-7.2-4' of git://git.kernel.org/pub/scm/linux/kernel/git/s390/linux Pull s390 fixes from Vasily Gorbik: - Fix missing array_index_nospec() call in diag310 memory topology code to prevent speculative execution with a user controlled array index - Fix get_align_mask() return type to match vm_unmapped_area_info align_mask, avoiding possible truncation for future larger masks - Remove empty zcrypt CEX2 files left over after CEX2 and CEX3 driver removal - Add build salt to the vDSO so it gets a unique build id, similar to the kernel and modules * tag 's390-7.2-4' of git://git.kernel.org/pub/scm/linux/kernel/git/s390/linux: s390: Add build salt to the vDSO s390/zcrypt: Remove the empty file s390/mm: Fix type mismatch in get_align_mask(). s390/diag: Add missing array_index_nospec() call to memtop_get_page_count() |
||
|
|
2f9eb0c54a |
RISC-V updates for v7.2-rc3
- Avoid a null pointer deference in machine_kexec_prepare() that the
IMA subsystem can trigger
- Bypass libc in part of the ptrace_v_not_enabled kselftest to avoid
noise from child atfork handlers that libc might run
- Include Kconfig support for UltraRISC SoCs, already referenced by
some device drivers; and enable it in our defconfig
- Fix the build of the rseq kselftest for RISC-V by borrowing a
technique from the KVM and S390 kselftests that includes
arch-specific header files from tools/arch/<arch>/include
- Fix some memory leaks in the RISC-V vector ptrace kselftests
- Clean up some DT bindings and hwprobe documentation
-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEElRDoIDdEz9/svf2Kx4+xDQu9KksFAmpRj9YACgkQx4+xDQu9
KktUEQ/8Cvup7jqUkHj3JBI/gjLLUyiOsa0q7KC3F2A+CznCFlrjwezGUZSeIiKq
lmVIeBFejOK+8VKNg+SeDTbfw10YlZOpUtBozJmRtFx17K0m5R6eGn6Qjy5IwMSI
wJmDylHtnLqrydYqESRt1iLDgETnZkmYdSlFDow2LKTa2g9BYPno+avB9uuzV2nj
/JCAC7kWSABRmROfNDBtZikT6Qcx1hGAxSQnkHmgvjYEInNggMefIfU7+/wgqksm
CEBCsoIZ3kqIVEkrGrYwlxoyj81wA8uOcg802xJs5ByffrdPc7xy43WZ9J41dKIb
EDXXbXH9tudhLmGfXDI8xt0gJz03L+t05pmYTaNN8o6/CWKQ7Dj5xvqfM1WllUDD
Q71Q6H0Smd7UmQkQ0/olyhG7yFEaewR+yJFvIEhISfQpIKUVWvVEVkEyJQdv66R4
ei2Oc2mUjQd+drCVD8d59whctUPMKDlg0JaesSE7rwNbx03NnOsLtg2JFHQxEVdn
GeUlKqAYLhTjPXrUvoWm3ebnU0DCvchKhY8So00aXWbdJnn2u9Qg81887czT0hQn
lsTLAt1n7/RCsuGo1zdw9lEMXmPJI9uX/HsyfatGYR9CVxj4M4tbVYjEz+wOFu+F
m7JKMnLFrvWF1+gRmmTXwcHCmi1qJnsqsILO4YvB+P/2vLs1FtU=
=P9QE
-----END PGP SIGNATURE-----
Merge tag 'riscv-for-linus-7.2-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/riscv/linux
Pull RISC-V fixes from Paul Walmsley:
"The most notable change involves the rseq kselftest common Makefile
(as it is not RISC-V-specific). The basic approach in the patch
appears similar to one used in the KVM and S390 selftests (grep for
LINUX_TOOL_ARCH_INCLUDE and SUBARCH), and the rseq kselftests pass a
quick build test on x86 after this.
- Avoid a null pointer deference in machine_kexec_prepare() that the
IMA subsystem can trigger
- Bypass libc in part of the ptrace_v_not_enabled kselftest to avoid
noise from child atfork handlers that libc might run
- Include Kconfig support for UltraRISC SoCs, already referenced by
some device drivers; and enable it in our defconfig
- Fix the build of the rseq kselftest for RISC-V by borrowing a
technique from the KVM and S390 kselftests that includes
arch-specific header files from tools/arch/<arch>/include
- Fix some memory leaks in the RISC-V vector ptrace kselftests
- Clean up some DT bindings and hwprobe documentation"
* tag 'riscv-for-linus-7.2-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/riscv/linux:
selftests/riscv: ptrace: Fix memory leak of regset_data in vector tests
selftests/rseq: Fix a building error for riscv arch
riscv: defconfig: enable ARCH_ULTRARISC
riscv: add UltraRISC SoC family Kconfig support
riscv: hwprobe.rst: Document EXT_ZICFISS and EXT_ZICFILP
riscv: hwprobe.rst: Make indentation consistent
dt-bindings: riscv: sort multi-letter Z extensions alphanumerically
selftests: riscv: Bypass libc in inactive vector ptrace test
riscv: Prevent NULL pointer dereference in machine_kexec_prepare()
|
||
|
|
f4bf75d4e8 |
m68knommu: fix on top off v7.2-rc2
. fix broken local SoC IO accesses -----BEGIN PGP SIGNATURE----- iQJEBAABCgAuFiEEmsfM6tQwfNjBOxr3TiQVqaG9L4AFAmpTidQQHGdlcmdAa2Vy bmVsLm9yZwAKCRBOJBWpob0vgHIYEACBKY4WSbwBRjefo+Cw1f2+rM6ZaffCkT4q CdMQb1EQ6EA7OVOov+ZIPuDTgAPv0l2oksi8iZuVh4FaI6M9jlz3QTVVJKXafSAM DSjFj6IUiRyX9Eav96MO7NjOdT0+kUQxZnVEo7Cde4F3LLEoluXiSumkmLKpE9/t MLE+f8lPVxLwlQm4DhYUQvogkHoUb/eYqVbFg1lzs85+PzeC7urhtZVlSXCtvd73 lv37qlPUwAp0hHRe7ASmZCeStwNxXrvJ9sB1BmMYhdp2YHrd8ZJmzLA5cs6HB0w2 wjMBc9wUjRLb3jIosJpEnfOKTmlXZFbZ5hG8i97MTlsUXgw3bPswD+x9Cq9vVP3F w+1rpAMGGG/Cn2I/AABrGpEQS6ld3ZY3er/1E/Fm3wZPGkEwe33f5xlY/0EiCY7g 2tf6yiiyTDtM4sYzZeIJUAItWVYwSZ5ym6H9AfAjaMG8HxnnmcYnHCYH1OOMY1FC ziIElbsVIZPJKTY6ghBEEgijC9ASNGUb2ULwotjtAIHPOLRm44T6HXrmbCbuSdNn DFf7oq2aXmYR/zVmMYk3Iz9z84SFwjDMQo9CCvNwPt5bnVWdfXyCuXvUALGxQ1fN vzDaO1BZGilfW/vYAvaVN6uzEZzZsE1Qk0H66Xmu+Q6p/ydQRvHJstZqXzWLcgO/ S8EkwDXPzQ== =3/dn -----END PGP SIGNATURE----- Merge tag 'm68knommu-fixes-on-top-off-7.2-rc2' of git://git.kernel.org/pub/scm/linux/kernel/git/gerg/m68knommu Pull m68knommu fix from Greg Ungerer: "Fix incorrectly updated local SoC IO access function names. Testing didn't pick them up because there was no specific defconfig for these particular SoC parts. New defconfigs will be introduced in the next merge cycle to remedy that" * tag 'm68knommu-fixes-on-top-off-7.2-rc2' of git://git.kernel.org/pub/scm/linux/kernel/git/gerg/m68knommu: m68k: coldfire: fix breakage of missed IO access updates |
||
|
|
6205562c59 |
tracing fixes for 7.2:
- Free field in error path of synthetic event parse In __create_synth_event() the field was allocated but was not freed in the error path. - Fix ring_buffer_event_length() on 8 byte aligned architectures On architectures with CONFIG_HAVE_64BIT_ALIGNED_ACCESS set to y, the ring_buffer_event_length() may return the wrong size. This is because archs with that config set will always use the "big event meta header" as that is 8 bytes keeping the payload 8 bytes aligned, even when a 4 byte header could hold the size of the event. But ring_buffer_event_length() doesn't take this into account and only subtracts 4 bytes for the meta header in the length when it should have subtracted 8 bytes. - Have osnoise wait for a full rcu synchronization on unregister osnoise_unregister_instance() used to call synchronize_rcu() before freeing its copy of the instance but was switched to kfree_rcu(). The osniose tracer has code that traverses the instances that it uses, and inst is just a pointer to that instance. By using kfree_rcu() instead of synchronize_rcu(), the instance that the inst pointer is pointing to can be freed while the osnoise code is still referencing it. That is, a rmdir on an instance first unregisters the tracer. When the unregister finishes, the rmdir expects that the tracer is finished with the instance that it is using. By putting back the synchronize_rcu() in osnoise_unregister_instance() the unregistering of osnoise will now return when all the users of the instance have finished. - Remove an unused setting of "ret" in tracing_set_tracer() - Fix ring_buffer_read_page() copying events The commit that changed ring_buffer_read_page() to show dropped events from the buffer itself, split the "commit" variable between the commit value (with flags) and "size" that holds the size of the sub-buffer. A cut and paste error changed the test of the reading from checking the size of the buffer to the size of the event causing reads to only read one event at a time. - Make tracepoint_printk a static variable When the tracing sysctl knobs were move from sysctl.c to trace.c, the variable tracepoint_printk no longer needed to be global. Make it static. - Fix some typos - Fix NULL pointer dereference in func_set_flag() The flags update of the function tracer first checks if the value of the flag is the same and exits if they are, and then it checks if the current tracer is the function tracer and exits if it isn't. The problem is that these checks need to be in a reversed order, as if the tracer isn't the function tracer, then the flag being checked may not exist. Reverse the order of these checks. - Fix ufs core trace events to not dereference a pointer in TP_printk() The TP_printk() part of the TRACE_EVENT() macro is called when the user reads the "trace" file. This can be seconds, minutes, hours, days, weeks, and even months after the data was recorded into the ring buffer. Thus, saving a pointer to an object into the ring buffer and then dereferencing it from TP_printk() can cause harm as the object the pointer is pointing to may no longer exist. Fix all the trace events in ufs core to save the device name in the ring buffer instead of dereferencing the device descriptor from TP_printk(). - Prevent out-of-bound reads in glob matching of trace events The filter logic of events allows simple glob logic to add wild cards to filter on strings. But some events have fields that may not have a terminating 'nul' character. This may cause the glob matching to go beyond the string. Change the logic to always pass in the length of the field that is being matched. - Add no-rcu-check version of trace_##event##_enabled() The trace_##event##_enabled() usually wraps trace events to do extra work that is only needed when the trace event is enabled. But this can hide events that are placed in locations where RCU is not watching, and can make lockdep not see these bugs when the event is not enabled. The trace_##event##_enabled() was updated to always test to make sure RCU is watching to catch locations that may call events without RCU being active. This caused a false positive for the irq_disabled() and related events. As that use trace_irq_disabled_enabled() to force RCU to be watching when the event is enabled via the ct_irq_enter() function, calls the event, and then calls ct_irq_exit() to put RCU back to its original state. The trace_irq_disabled_enabled() should not trigger a warning when RCU is not watching because the code within its block handles the case properly. Make a __trace_##event##_enabled() version for this event to use that doesn't check RCU is watching as it handles the case when it isn't. - Fix use-after-free in user_event_mm_dup() When the enabler is removed from the link list, it is freed immediately. But it is protected via RCU and needs to be freed after an RCU grace period. Use queue_rcu_work() so that the event_mutex can also be taken as user_event_put() takes the mutex on the last reference is released. - Free type string in error path of parse_synth_field() There's an error path in parse_synth_field() where the allocated type string is not freed. - Add selftest that tests deferred event teardown - Fix leak in error path of trace_remote_alloc_buffer() If page allocation fails, the desc->nr_cpus is not incremented for the current CPU and the allocations done for it are not freed. - Fix allocation length in trace_remote_alloc_buffer() The logic to calculate the struct_len was doing a double count and setting the value too large. Calculate the size upfront to fix the error and simplify the logic. - Fix sparse CPU masks in ring_buffer_desc() If there are sparse CPUs (gaps in the numbering), the ring_buffer_desc() will fail as it tests the CPU number against the number of CPUs that are used. -----BEGIN PGP SIGNATURE----- iQJIBAABCgAyFiEEXtmkj8VMCiLR0IBM68Js21pW3nMFAmpTv/cUHHJvc3RlZHRA Z29vZG1pcy5vcmcACgkQ68Js21pW3nN80w/9HEbliUUrJVNw8QCY8BmeBEzfCRhZ 2CeDzTg+UrLMb2BtqUhA9EjQnRPawe8mPxAfpZ750SdFnCkRhbfNwYmKar3M/8iW y2Bhsvd3Hz6nRiHvKhG/1RkflgKOWLYf/TQSByKlakYLV8t4uffa0fe0N0zcnikK XPGrhrTeRDJ7s94vb1u7p7mSSp2iy4ZhfXbagk966X3I4zvseIYNn5IIzyM3IIPT M7mE60SxvgSRz0QqTJqihmqjXYSeNOQ2iU18wnvp4QfcT0IVuLKm027JnK/YpjWS ZasMNGzO1kp5uo6hkXLrMlT3LjaNEMFTGogs1m9o9auhbMf443LK8GtZ1m1rwnTG cXn1PocBevQIaXWPbnxMrSwIuN7YMUqjgX6SCxbXpDxSSuE5i/x1VmE08CjxnSm6 TdAdom9bE44FvMgaAz9+KhIUgm013c2rFDNiFroYtfkma5FqpfnfglA4/TkJvexY e2L75cR3lrDEDiXXMQDndmvxNMhppwNlAH3mOZLiaCmGyFQFHhgAaG250K2Y6a5K HtIfJkT6RQ3rWifV0E0+zlyRiOrvVCCA8WwNArWb1dTWrVU86Hr7q58jAq9p0Yrz FnhpjdE3eWoUHZ5f28AMR2k5lMG3o6mOGT55JyUVCLw+rPSG5358UIg2xZiEo22k RFlT26FFHbMW50Y= =+//w -----END PGP SIGNATURE----- Merge tag 'trace-v7.2-rc2' of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace Pull tracing fixes from Steven Rostedt: - Free field in error path of synthetic event parse In __create_synth_event() the field was allocated but was not freed in the error path - Fix ring_buffer_event_length() on 8 byte aligned architectures On architectures with CONFIG_HAVE_64BIT_ALIGNED_ACCESS set to y, the ring_buffer_event_length() may return the wrong size. This is because archs with that config set will always use the "big event meta header" as that is 8 bytes keeping the payload 8 bytes aligned, even when a 4 byte header could hold the size of the event But ring_buffer_event_length() doesn't take this into account and only subtracts 4 bytes for the meta header in the length when it should have subtracted 8 bytes - Have osnoise wait for a full rcu synchronization on unregister osnoise_unregister_instance() used to call synchronize_rcu() before freeing its copy of the instance but was switched to kfree_rcu(). The osniose tracer has code that traverses the instances that it uses, and inst is just a pointer to that instance. By using kfree_rcu() instead of synchronize_rcu(), the instance that the inst pointer is pointing to can be freed while the osnoise code is still referencing it That is, a rmdir on an instance first unregisters the tracer. When the unregister finishes, the rmdir expects that the tracer is finished with the instance that it is using. By putting back the synchronize_rcu() in osnoise_unregister_instance() the unregistering of osnoise will now return when all the users of the instance have finished - Remove an unused setting of "ret" in tracing_set_tracer() - Fix ring_buffer_read_page() copying events The commit that changed ring_buffer_read_page() to show dropped events from the buffer itself, split the "commit" variable between the commit value (with flags) and "size" that holds the size of the sub-buffer. A cut and paste error changed the test of the reading from checking the size of the buffer to the size of the event causing reads to only read one event at a time - Make tracepoint_printk a static variable When the tracing sysctl knobs were move from sysctl.c to trace.c, the variable tracepoint_printk no longer needed to be global. Make it static - Fix some typos - Fix NULL pointer dereference in func_set_flag() The flags update of the function tracer first checks if the value of the flag is the same and exits if they are, and then it checks if the current tracer is the function tracer and exits if it isn't. The problem is that these checks need to be in a reversed order, as if the tracer isn't the function tracer, then the flag being checked may not exist. Reverse the order of these checks - Fix ufs core trace events to not dereference a pointer in TP_printk() The TP_printk() part of the TRACE_EVENT() macro is called when the user reads the "trace" file. This can be seconds, minutes, hours, days, weeks, and even months after the data was recorded into the ring buffer. Thus, saving a pointer to an object into the ring buffer and then dereferencing it from TP_printk() can cause harm as the object the pointer is pointing to may no longer exist Fix all the trace events in ufs core to save the device name in the ring buffer instead of dereferencing the device descriptor from TP_printk() - Prevent out-of-bound reads in glob matching of trace events The filter logic of events allows simple glob logic to add wild cards to filter on strings. But some events have fields that may not have a terminating 'nul' character. This may cause the glob matching to go beyond the string. Change the logic to always pass in the length of the field that is being matched - Add no-rcu-check version of trace_##event##_enabled() The trace_##event##_enabled() usually wraps trace events to do extra work that is only needed when the trace event is enabled. But this can hide events that are placed in locations where RCU is not watching, and can make lockdep not see these bugs when the event is not enabled The trace_##event##_enabled() was updated to always test to make sure RCU is watching to catch locations that may call events without RCU being active This caused a false positive for the irq_disabled() and related events. As that use trace_irq_disabled_enabled() to force RCU to be watching when the event is enabled via the ct_irq_enter() function, calls the event, and then calls ct_irq_exit() to put RCU back to its original state The trace_irq_disabled_enabled() should not trigger a warning when RCU is not watching because the code within its block handles the case properly. Make a __trace_##event##_enabled() version for this event to use that doesn't check RCU is watching as it handles the case when it isn't - Fix use-after-free in user_event_mm_dup() When the enabler is removed from the link list, it is freed immediately. But it is protected via RCU and needs to be freed after an RCU grace period. Use queue_rcu_work() so that the event_mutex can also be taken as user_event_put() takes the mutex on the last reference is released - Free type string in error path of parse_synth_field() There's an error path in parse_synth_field() where the allocated type string is not freed - Add selftest that tests deferred event teardown - Fix leak in error path of trace_remote_alloc_buffer() If page allocation fails, the desc->nr_cpus is not incremented for the current CPU and the allocations done for it are not freed - Fix allocation length in trace_remote_alloc_buffer() The logic to calculate the struct_len was doing a double count and setting the value too large. Calculate the size upfront to fix the error and simplify the logic - Fix sparse CPU masks in ring_buffer_desc() If there are sparse CPUs (gaps in the numbering), the ring_buffer_desc() will fail as it tests the CPU number against the number of CPUs that are used * tag 'trace-v7.2-rc2' of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace: ring-buffer: Allow sparse CPU masks in ring_buffer_desc() tracing/remotes: Fix struct_len in trace_remote_alloc_buffer() tracing/remotes: Fix leak in trace_remote_alloc_buffer() error path selftests/user_events: Wait for deferred event teardown after unregister tracing/synthetic: Free type string on error path tracing/user_events: Fix use-after-free in user_event_mm_dup() tracing: Add a no-rcu-check version of trace_##event##_enabled() tracing: Prevent out-of-bounds read in glob matching ufs: core: tracing: Do not dereference pointers in TP_printk() tracing: Fix NULL pointer dereference in func_set_flag() samples: ftrace: Fix typos in benchmark comment tracing: Make tracepoint_printk static as not exported ring-buffer: Fix ring_buffer_read_page() copying only one event per page tracing: Remove unused ret assignment in tracing_set_tracer() tracing/osnoise: Call synchronize_rcu() when unregistering ring-buffer: Fix event length with forced 8-byte alignment tracing/synthetic: Free pending field on error path |
||
|
|
9202ee546b |
xfs: fix null pointer dereference in tracepoint
If dfp is not NULL we exit early here, when dfp is NULL it's allocated
in xfs_defer_alloc() but not assigned. The tracepoint tries to
dereference members of dfp struct.
Signed-off-by: Andrey Albershteyn <aalbersh@kernel.org>
Cc: stable@vger.kernel.org # v6.8
Fixes:
|
||
|
|
d130041a7b |
x86/boot: Reject too long acpi_rsdp= values
cmdline_find_option() returns the full length of the parsed acpi_rsdp=
value. get_cmdline_acpi_rsdp() then silently truncates values which do
not fit in the val[] buffer.
Prevent boot_kstrtoul() from parsing a truncated value and then the
kernel from silently using the wrong RSDP address, see discussion in
Link:.
Issue a warning so that the user is aware that s/he supplied a malformed
value and can get feedback instead of silent crashes.
[ bp: Make commit message more precise. ]
Fixes:
|
||
|
|
1ecb29b084 |
x86/cpu: Remove Makefile rule for removed UMC CPU support
Support for UMC CPUs was removed in |
||
|
|
44696aa3a4 |
Input updates for v7.2-rc2
- A fix for MELFAS MMS114 touchscreen driver to reject invalid touch IDs and avoid multi-touch slot corruption - A fix for a crash in Sega Dreamcast (Maple) mouse driver when opening the device, caused by missing driver data - Fixes for Maple drivers (keyboard, mouse, joystick) to properly order setting driver data and device registration to avoid races. -----BEGIN PGP SIGNATURE----- iHUEABYKAB0WIQST2eWILY88ieB2DOtAj56VGEWXnAUCalLC2QAKCRBAj56VGEWX nLLwAQDExlB/cWm2Hpmim13SIetpNbnRNDDUBXZqlx26U6tCUgD9Ek85LvbRiWOJ dTqs7ieSn2iPQxHFvHOAZD5ohSGj/wI= =g2px -----END PGP SIGNATURE----- Merge tag 'input-for-v7.2-rc2' of git://git.kernel.org/pub/scm/linux/kernel/git/dtor/input Pull input fixes from Dmitry Torokhov: - fix MELFAS MMS114 touchscreen driver to reject invalid touch IDs and avoid multi-touch slot corruption - fix a crash in the Sega Dreamcast (Maple) mouse driver when opening the device, caused by missing driver data - fixes for Maple drivers (keyboard, mouse, joystick) to properly order setting driver data and device registration to avoid races * tag 'input-for-v7.2-rc2' of git://git.kernel.org/pub/scm/linux/kernel/git/dtor/input: Input: mms114 - fix multi-touch slot corruption Input: maple_keyb - set driver data before registering input device Input: maplecontrol - set driver data before registering input device Input: maplemouse - set driver data before registering input device Input: maplemouse - fix NULL pointer dereference in open() |
||
|
|
59dee6d287 |
- dm-log: fix overflow on 32-bit machines
- dm-era: fix out of bounds memory access; fix crashes on invalid args - dm-verity: fix buffer overflow in forward error correction - dm-thin: fix misbehavior on I/O failures - dm-pcache: fix NULL pointer dereference on invalid arguments - dm-inlinecrypt: fix memory leak on error handling - dm-integrity: fix ignoring the 'fix_hmac' option on device open - dm: don't store the keyring in memory for a long term - 12 miscellaneous fixes for bugs found by Claude Opus 4.6 -----BEGIN PGP SIGNATURE----- iIoEABYIADIWIQRnH8MwLyZDhyYfesYTAyx9YGnhbQUCalKUaxQcbXBhdG9ja2FA cmVkaGF0LmNvbQAKCRATAyx9YGnhbbQwAP9pHgNUinD95o9vnu3d3QNmjnEDmrgZ +kxNFRpWXvbzKQEArYWPLS/2dwf4nG0Fa8PtJTwkjI/6UeublAy5MrdTqA0= =pkBx -----END PGP SIGNATURE----- Merge tag 'for-7.2/dm-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/device-mapper/linux-dm Pull device mapper fixes from Mikulas Patocka: - dm-log: fix overflow on 32-bit machines - dm-era: fix out of bounds memory access; fix crashes on invalid args - dm-verity: fix buffer overflow in forward error correction - dm-thin: fix misbehavior on I/O failures - dm-pcache: fix NULL pointer dereference on invalid arguments - dm-inlinecrypt: fix memory leak on error handling - dm-integrity: fix ignoring the 'fix_hmac' option on device open - dm: don't store the keyring in memory for a long term - 12 miscellaneous fixes for bugs found by Claude Opus 4.6 * tag 'for-7.2/dm-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/device-mapper/linux-dm: (23 commits) dm thin metadata: fix superblock refcount leak on snapshot shadow failure dm-stats: fix dm_jiffies_to_msec64 dm-stats: fix merge accounting dm-bufio: fix wrong count calculation in dm_bufio_issue_discard dm-verity: make error counter atomic dm-verity: increase sprintf buffer size dm-verity: fix a possible NULL pointer dereference dm-verity: avoid double increment of &use_bh_wq_enabled dm-ioctl: fix a possible overflow in list_version_get_info dm_early_create: fix freeing used table on dm_resume failure dm-integrity: fix a bug if the bio is out of limits dm-integrity: don't increment hash_offset twice dm-integrity: fix leaking uninitialized kernel memory dm-integrity: fix the 'fix_hmac' option dm era: fix error code propagation in era_ctr() dm era: fix NULL pointer dereference in metadata_open() dm: avoid leaking the caller's thread keyring via the table device file dm-inlinecrypt: Fix an error handling path in inlinecrypt_ctr() dm-pcache: reject option groups without values dm thin metadata: fix metadata snapshot consistency on commit failure ... |
||
|
|
cab9e339cf |
Misc perf events fixes:
- Fix SVM #GP on AMD CPUs that LBR but not BRS
(Sandipan Das)
- Fix UAF bug in the perf AUX code (Lee Jia Jie)
- Fix address leakage in the AMD LBR code
(Sandipan Das)
- Fix address leakage in the AMD BRS code
(Sandipan Das)
Signed-off-by: Ingo Molnar <mingo@kernel.org>
-----BEGIN PGP SIGNATURE-----
iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmpSKr0RHG1pbmdvQGtl
cm5lbC5vcmcACgkQEnMQ0APhK1hsTA//Vm7AzLa5iDBu12fINDMC/62kDTfLu5OD
WvIeygRJYOkx/P1FxAigJHXnA6/dqAoLusbgaLG0pzoNr0cI+MREuvuIYP0xDb6V
yTQe2mvvjBoQ+5XDRnt2D19Pgo9PAIN62zk3UJSTvtkJ7u0P+POGxKSMq6Kbg3sO
DcYaAXrs+JnFeKjAahXnX4USB15uhkq1BKDFfB+PJUaaAoysueu2/ceGRtXiN9eW
X/v59IhCYJ5sfOOJ72CCkLsAdXKjyHFnhaYoslu5V9nfUxhLzbEGGWTIdsVLazsp
t6F16c/dsxrMpG24TLfbucIDvV4Qt+oZrfVqHdLXvfunRwuCQt+ajXNBVi1krgKQ
mjFaXJ15NGE9xrs+Id+m0rBFMVvKqvEh0sw+1URItsmZKB4RK7IA6ktlnod5J9XF
nYPNr0OqYw/Nd8MAEERvlOmqB0GQ/XGxRF8AsYo+IY7VRD/hrC+wRvsCDkZnOnrf
Jc4zJVW/+kXI0PzA1o7qolCGR5t9Ed8VDGK7dxwMF7lWshidgpFtBOm6MW9yuVgc
DjemSRObXRDqrspF/VFn9u7xJ/RNiAi+tARDmKQRPKeu3dX0QaYVt5umSwjmas39
KVGP3vhVoPFyeuis1VJxdgDXyssaruXglV/AJo6yCZZDK1UgMzRo726ZUi2c5OZL
43uBh4RKUi8=
=OpxC
-----END PGP SIGNATURE-----
Merge tag 'perf-urgent-2026-07-11' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
Pull perf events fixes from Ingo Molnar:
- Fix SVM #GP on AMD CPUs that LBR but not BRS (Sandipan Das)
- Fix UAF bug in the perf AUX code (Lee Jia Jie)
- Fix address leakage in the AMD LBR code (Sandipan Das)
- Fix address leakage in the AMD BRS code (Sandipan Das)
* tag 'perf-urgent-2026-07-11' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
perf/x86/amd/brs: Fix kernel address leakage
perf/x86/amd/lbr: Fix kernel address leakage
perf/aux: Fix page UAF in map_range()
perf/x86/amd/core: Avoid enabling BRS from the SVM reload path
|
||
|
|
b37fa0d0a3 |
Misc x86 fixes:
- Fix resctrl resource leak (Tony Luck)
- Fix resctrl umount race (Tony Luck)
- Fix resctrl double-free (Reinette Chatre)
- Fix x86 VGA display fallback logic during bootup on
certain multi-GPU systems (Mario Limonciello)
- Re-add a WBINVD call to the SNP bootstrap path to
fix an SNP regression (Tycho Andersen)
Signed-off-by: Ingo Molnar <mingo@kernel.org>
-----BEGIN PGP SIGNATURE-----
iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmpSKV8RHG1pbmdvQGtl
cm5lbC5vcmcACgkQEnMQ0APhK1juPhAAsylTtlr70GPw/3gMyMJ/RGcKHxGBQe6W
ARBT/dzULzA37zPQ0UYqab5gwtb8M4mdTiH0756BUgeNpjO0HAyokAyblcnPsrIz
+nQEcnh6eMrr6nEm3evwEsPv7koi1KwdDhA8RAUhzhAc9YGpwXXBPRlsec0slfdR
y7b5rPT89wCCtuQK2va0BiErvWcWvaEOtBGVw4FpJ7oqqWte7Cp4vk93i9CZfhJ9
369+M2O46Za8Qj9AOgm7TQiV3d4EQ0sAxCnb2Q7c87EyJnBBftEN5cfVOtGvBZUz
2Wego8h9iFkZdo87WMTsFwCwn6qbetyKTn2zO15BmKEKPn2gIm5A8CVBnrTji96L
yR7LXZE+tufpRg6rCW2myjkT65QmLRi2D3ZpBpTkmmgnXZITx+YzfCDy+bqR6x7w
nJ/KJx2YYE9Rve/z8P1giVy5omgI5aMEhveas+NlUBxDuX+OvkI7yrxW0GYAloL6
pcGGlDGml5b5S0rADApaptnL0EqA2QwB/OWA4W7cb+3pm5GZJkyalDioKzm9VEmt
hfVDzYrDM/1YHp9tywGLZeshJ7kkRSd7CvL6mU4UQnBMbtBku/Nbr3KEWK0EOY3N
wnpsFNrnS/CWfT9gygQINbJAZKt6LcLhPwwo0ZzxiVAEA2dRkhDkJCS8Vl2STxht
N2wmpqTmMUw=
=3lBD
-----END PGP SIGNATURE-----
Merge tag 'x86-urgent-2026-07-11' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
Pull x86 fixes from Ingo Molnar:
- Fix resctrl resource leak (Tony Luck)
- Fix resctrl umount race (Tony Luck)
- Fix resctrl double-free (Reinette Chatre)
- Fix x86 VGA display fallback logic during bootup on
certain multi-GPU systems (Mario Limonciello)
- Re-add a WBINVD call to the SNP bootstrap path to
fix an SNP regression (Tycho Andersen)
* tag 'x86-urgent-2026-07-11' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
x86/virt/sev: Revert "Drop WBINVD before setting MSR_AMD64_SYSCFG_SNP_EN"
x86/video: Only fall back to vga_default_device() without screen info
fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list
fs/resctrl: Fix use-after-free during unmount
fs/resctrl: Free mon_data structures on rdt_get_tree() failure
|
||
|
|
767707a53e |
- Fix a subtle posix-cpu-timers vs. exec() race, which
unearthed other races in the area (Thomas Gleixner) Signed-off-by: Ingo Molnar <mingo@kernel.org> -----BEGIN PGP SIGNATURE----- iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmpSJ0gRHG1pbmdvQGtl cm5lbC5vcmcACgkQEnMQ0APhK1hyKA//W5KqLrRgXjH9cS7tF6PLo9NhbZZn5FhH jxThPvJosNyCj8UEVD+iCRjkqkNxiY9mzx3px2ZVlJg8K35ez2PeZ/zx0wvuSWlM sD7k4S3JJQ7vAE4CkYvsf91TxCWqiOMw+NLyo7MgDhwsOdgPgUAAKlCdCyoFzRK7 rAV7FQWMQag24donwPiesk8bnU4pWrooq8BoY7XVCy6aHDwwPVxrs1yPyUEikIXq AT2HiYFOu9ok6rSlJs+A2JQnmke6M6aIJ5dmUGR7gUDRAqlXesmM6jlwklzK0a4O j6lpE05ouIhZpYzQVTDxvf8cytp0+rutTX8w0lPRlqxYkaeBVEpktxfBAoqFCsoe GpK8hK0PM57W29zhnTygQib53QQAk9QBQetp0NwUjLSOu3ouhCAOC3wuoctJ4fKY oNSKGPBhHwJN5932JuxlEll/xbo+bFyHfP87tqn1SA0bgKMSNet5q7+wYE+1gcTp 9LHQnoMpjyRBjuOupnvxqeOVbN3qlNdY6MINFwxBZuKG7UwmYpTH7l72fuUM/eNr b4UHKgwv3vuQX/BfBoT1mLnzWQTltrfEywBCXHsEHUQ7KFhdRHEbnh3zVDZCT5S3 5N/RS8aFcryD/0/DhxWEhO2DBTgjDDvmOKplIPYFtikDI1dkjZ9dZ0BCI42u6wMH by25mw2rF2s= =2I60 -----END PGP SIGNATURE----- Merge tag 'timers-urgent-2026-07-11' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip Pull timer fix from Ingo Molnar: - Fix a subtle posix-cpu-timers vs. exec() race, which unearthed other races in the area (Thomas Gleixner) * tag 'timers-urgent-2026-07-11' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip: posix-cpu-timers: Prevent UAF caused by non-leader exec() race |
||
|
|
64d9ca4b44 |
block-7.2-20260710
-----BEGIN PGP SIGNATURE----- iQJEBAABCAAuFiEEwPw5LcreJtl1+l5K99NY+ylx4KYFAmpRcgYQHGF4Ym9lQGtl cm5lbC5kawAKCRD301j7KXHgplILD/4pSlngdLhIRuGnzHEXz507ySn8XSim6NEs gNf89HClYgIwSbMjHOuzPLpp/6FHxKMnyEzxsrJ6Rj3PXSc0sSWbKHMGD5UUwg4X gYUIwH5WfvzHxU9zJ6tGLgkepTow+vPhoTnJJqtK5qLO2C56I7dSV38fP5S2ucMU flVzYFRMtO8svWekol9bA278/p3GxR0qXKLCKq/tadTLcLo9AyAz+gEGHAYCNTVE 9Kix7uiAVMg8CtwK5lJDFd6pLSZaYFCkzAI2/H/mxB25ydZRKcfLADmj/uDOboJH 8Q2FezpQSdM6bEWqsjSwA3qhfNaUzyVuCEoFZl2V4vuD/RvEe+y5hSGM9AGW0hwQ 57UwLKgohupTNb6149Mhq5AvmIcD2/FEmxMCyHB0DdSWFp1uHR/8jrHyh/ZQXBHl VgCeErIIaG5Yruta80WsZp7lagBduU0zndG4a3OONOj76vLA5iilzxEo4K7yFVdu 22Uiw2oIJPzwm9OOmVvpaIozBDNqG8Ims9e2U/me6ODFP4kdcHjqyS6FOnDoRxz2 PiPxW0FHJt4ywjFuHTE05+8N3/eiJivANjaeAnj1mqIIH4UwxzCiCl/raVf4VCtH HWoGFQQ5R2gg4Q1BGllmOvyG9ZPhV/TJgoRnatyVqGVHXJOBKc+5PQREy3HXZ54J Z6xq2lobKQ== =LIqA -----END PGP SIGNATURE----- Merge tag 'block-7.2-20260710' of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux Pull block fixes from Jens Axboe: - Limit blk_hctx_poll() to one jiffy. Prevents buggy drivers from spinning for too long, hence triggering a stalled RCU read section warning - Avoid a potential deadlock on zone revalidation failure, which could otherwise trigger a lockdep circular locking splat during a SCSI disk rescan - Remove a redundant GD_NEED_PART_SCAN set in add_disk_final() - Make writes to queue/wbt_lat_usec honor the WBT enable state - ublk fix to snapshot the batch commands before preparing IO, so that userspace can't change an already processed tag and trip the WARN_ON_ONCE() in the rollback path - xen-blkfront fix for a double completion of split requests on resume - drbd fix to reject data replies with an out-of-range payload size * tag 'block-7.2-20260710' of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux: block: remove redundant GD_NEED_PART_SCAN in add_disk_final() drbd: reject data replies with an out-of-range payload size xen-blkfront: fix double completion of split requests on resume ublk: snapshot batch commands before preparing I/O block: Make WBT latency writes honor enable state block: avoid potential deadlock on zone revalidation failure blk-mq: bound blk_hctx_poll() to one jiffy |
||
|
|
596d603126 |
io_uring-7.2-20260710
-----BEGIN PGP SIGNATURE----- iQJEBAABCAAuFiEEwPw5LcreJtl1+l5K99NY+ylx4KYFAmpRch8QHGF4Ym9lQGtl cm5lbC5kawAKCRD301j7KXHgpqORD/9xYHpNwkeIXfG+6giRGCF03u0eGlreUsIl uCGdqfNKjKZqWOw6q7uzNHll7/2SmwOniB32mdo6jpUgXeE3/RJ4U37kZ8ypIyO8 1iOSM5zz5ZNQQuHa/HZMqMRy9mqBa5WIJqRO4CpRk9uaqq6flU2CEq4/y3SdOc0S 9u+UxzVhmoYuL7iQhaLg6xQSrNxtwynVXqIru/bN1Ft01sCo3Yf3w0SmNnmsrr34 jG1tkn0J7QtwkaN81poX8WTqm0D7McFc5xcq8wWM+BDnpvllPxQ+J+J3+zMfvAbN tbb3FiXkc5SeYTOrBu8FWwPMn8reNpUBgEGjrcZWyRIkHdzxrDhwvC9tyQs85l4w j93PSsJnlprVPI4LWGfglCaNBZ85hFFKpm83rAFJgJjLuyzRFSF7+/EKrHFP58sK v8oYq/iXpQunu1YLfBIAjW4OnVkqSYM95Xax4l5yFSgeCS+hNd/naRgvqzrM4puq tspIH9zjZCyRftRuVebW4V/cxfceSp3kg5cPyW/PRonO9iGZ1Q2scK0bovNO0QKC gDjax1qancwp/GlT65jgdLp9lAx1TIofPz2gP22lGlZe732bi3gvX5rGPo1bT98v 1NJXrEIqLHOuId308+pzpvl4j4YyJAC3llThVg4L2TZb6jy+S5qYnbBnRkQoNPVi iMP+XrWPjw== =vHWI -----END PGP SIGNATURE----- Merge tag 'io_uring-7.2-20260710' of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux Pull io_uring fixes from Jens Axboe: - Restore full RCU read section in io_req_local_work_add(), which was mistakenly dropped with the DEFER_TASKRUN rework in this merge window. Revert the commit that grabbed the RCU read lock in io_ctx_mark_taskrun(), as that's no longer required with the previous fix. - Fix a dangling iovec after a provided-buffer bundle grow failure, also an issue introduced in this merge window. - Reject IORING_CQE_F_32 flag pass-through in MSG_RING to rings that weren't setup with CQE32 or CQE_MIXED. - Return -EINVAL rather than -ENOMEM from get_unmapped_area() when mmap validation fails, matching io_uring_mmap(). * tag 'io_uring-7.2-20260710' of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux: Revert "io_uring: grab RCU read lock marking task run" io_uring: restore RCU read section in io_req_local_work_add() io_uring: fix dangling iovec after provided-buffer bundle grow failure io_uring/uring_cmd: fix uring_cmd.c comments io_uring/msg_ring: reject CQE32 flag pass-through to normal rings io_uring/memmap: return -EINVAL from get_unmapped_area() on bad mmap |
||
|
|
4b22d0801f |
dm thin metadata: fix superblock refcount leak on snapshot shadow failure
__reserve_metadata_snap() increments THIN_SUPERBLOCK_LOCATION in the
metadata space map before shadowing it. When dm_tm_shadow_block()
fails, a reference is leaked in the metadata space map.
Fix by adding the missing dm_sm_dec_block().
Signed-off-by: Genjian Zhang <zhanggenjian@kylinos.cn>
Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>
Fixes:
|
||
|
|
5a81c35c3b |
objtool/rust: add one more noreturn Rust function for Rust 1.99.0
Starting with Rust 1.99.0 (expected 2026-10-01), under
`CONFIG_RUST_DEBUG_ASSERTIONS=y`, `objtool` may report:
rust/kernel.o: warning: objtool: _R..._6kernel12module_param9set_paramaEB4_()
falls through to next function _R..._6kernel12module_param9set_paramhEB4_()
(and many others) due to calls to the `noreturn` symbol [1]:
core::panicking::panic_null_reference_constructed
Thus add the mangled one to the list so that `objtool` knows it is
actually `noreturn`.
See commit
|
||
|
|
425e10586c |
rust: zerocopy: update to v0.8.54
Update our vendored copy of `zerocopy` (and `zerocopy-derive`) to v0.8.54.
It is a very small delta from v0.8.52, and most importantly it resolves
the unexpected lack of inlining [1] which triggered a modpost error
under `CONFIG_CC_OPTIMIZE_FOR_SIZE=y` reported by Alexandre using Gary's
suggestion [2]:
ERROR: modpost: "_RNvMNtCs5wX7wwEUCR9_8zerocopy6layoutNtB2_8SizeInfo24try_to_nonzero_elem_size" [drivers/gpu/nova-core.ko] undefined!
ERROR: modpost: "_RNvNtCs5wX7wwEUCR9_8zerocopy4util18padding_needed_for" [drivers/gpu/nova-core.ko] undefined!
It also resolves `most_traits` being unexpectedly documented [3] that I
reported and adds a missing SPDX license identifier [4] that I requested
to match the kernel version.
The following script may be used to check for the remaining differences:
for path in $(cd rust/zerocopy-derive/ && find . -type f ! -name README.md); do
curl --silent --show-error --location \
https://github.com/google/zerocopy/raw/v0.8.54/zerocopy/zerocopy-derive/src/$path |
git diff --no-index - rust/zerocopy-derive/$path &&
echo $path: OK
done
for path in $(cd rust/zerocopy/ && find . -type f ! -name README.md); do
curl --silent --show-error --location \
https://github.com/google/zerocopy/raw/v0.8.54/zerocopy/$path |
git diff --no-index - rust/zerocopy/$path &&
echo $path: OK
done
Cc: Joshua Liebow-Feeser <joshlf@google.com>
Cc: Jack Wrenn <jswrenn@google.com>
Reported-by: Alexandre Courbot <acourbot@nvidia.com>
Closes: https://lore.kernel.org/rust-for-linux/20260708-zerocopy-export-v1-1-2bfc355853c6@nvidia.com/ [1]
Suggested-by: Gary Guo <gary@garyguo.net>
Link: https://lore.kernel.org/rust-for-linux/DJT6235B3DOV.222XR5O6VHG4M@garyguo.net/ [2]
Link: https://github.com/google/zerocopy/issues/3466 [3]
Link: https://github.com/google/zerocopy/issues/3457 [4]
Reviewed-by: Alice Ryhl <aliceryhl@google.com>
Tested-by: Alexandre Courbot <acourbot@nvidia.com>
Reviewed-by: Gary Guo <gary@garyguo.net>
Link: https://patch.msgid.link/20260709211311.142544-1-ojeda@kernel.org
Signed-off-by: Miguel Ojeda <ojeda@kernel.org>
|
||
|
|
2808a39639 |
rust: zerocopy: update to v0.8.52
Update our vendored copy of `zerocopy` (and `zerocopy-derive`) to v0.8.52.
Most SPDX identifiers have been added upstream at our request [1]
(without parentheses -- supporting them is an issue on the kernel side,
but it does already reduce our differences). The CSS one for `rustdoc`
was added too [2], but will be picked up in a later version.
For `zerocopy`, enable `--cfg no_fp_fmt_parse`, which was added at our
request to avoid our local workaround [3]. This means one less difference,
thus indicate so in our `README.md`.
For `zerocopy-derive`, enable `--cfg zerocopy_unstable_linux`. This
allows us to use `#[derive(zerocopy_derive::most_traits)]`, a new feature
upstream added for us [4]. We noticed a minor doc render bug [5], which
will be fixed for a future version too.
The following script may be used to check for the remaining differences:
for path in $(cd rust/zerocopy-derive/ && find . -type f ! -name README.md); do
curl --silent --show-error --location \
https://github.com/google/zerocopy/raw/v0.8.52/zerocopy/zerocopy-derive/src/$path |
git diff --no-index - rust/zerocopy-derive/$path &&
echo $path: OK
done
for path in $(cd rust/zerocopy/ && find . -type f ! -name README.md); do
curl --silent --show-error --location \
https://github.com/google/zerocopy/raw/v0.8.52/zerocopy/$path |
git diff --no-index - rust/zerocopy/$path &&
echo $path: OK
done
Cc: Joshua Liebow-Feeser <joshlf@google.com>
Cc: Jack Wrenn <jswrenn@google.com>
Link: https://github.com/google/zerocopy/issues/3428 [1]
Link: https://github.com/google/zerocopy/issues/3457 [2]
Link: https://github.com/google/zerocopy/issues/3426 [3]
Link: https://github.com/google/zerocopy/pull/3416 [4]
Link: https://github.com/google/zerocopy/issues/3466 [5]
Acked-by: Nicolas Schier <n.schier@fritz.com>
Reviewed-by: Alice Ryhl <aliceryhl@google.com>
Link: https://patch.msgid.link/20260625231919.692444-1-ojeda@kernel.org
Signed-off-by: Miguel Ojeda <ojeda@kernel.org>
|
||
|
|
3f1f755366 |
net: openvswitch: reject oversized nested action attrs
Open vSwitch stores generated flow actions as nlattrs, whose nla_len field is u16. Commit |
||
|
|
7410d11460 |
macsec: fix promiscuity refcount leak in macsec_dev_open()
When a MACsec interface with IFF_PROMISC set is brought up on top of a
device that has hardware offload enabled, macsec_dev_open() first calls
dev_set_promiscuity(real_dev, 1) and then propagates the open to the
offload device. If that propagation fails, the error path jumps to the
clear_allmulti label, which only reverts allmulti and the unicast
address. The promiscuity taken on the lower device is never dropped, so
real_dev is left permanently stuck in promiscuous mode. Its promiscuity
count can no longer be balanced from software.
Add a clear_promisc label that drops the promiscuity reference and
route the two offload failure paths to it. The dev_set_promiscuity()
failure itself still jumps to clear_allmulti, since on that failure the
count was not incremented.
Fixes:
|
||
|
|
389704eb51 |
ipsec-2026-07-10
-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEEH7ZpcWbFyOOp6OJbrB3Eaf9PW7cFAmpQtBkACgkQrB3Eaf9P
W7fEwQ//ZGlVHLizm9aK0bcoIGOuUBCASQOmtk19n5vYP97612LbMeaQD9jEBCd2
c/gLK2P9hn9dnH25lvOXPwrWG+gje7lpPypeTjvzvW/andg/2DWGMvmhSv1M8a5q
J6NUKRsCJ2jwwkpILw6ziD+xskEh9t2hxXSc1Xk6K0W5MHJlx07ieoMrL/r/HbvJ
lDiHfg87Hlcp8K6W/aecN8NcliXEuo3KTSYCsBZM48R+Oar3VpqMC2QiLxvYZDqQ
IEVshugVQ8FQCgSp37hDxQLqsGdAfzAcjE8SjAGPJk12IODO8MKLsSsDJWt3MX4a
sjbIiQjEr0nDxtnwtPOBYN5ko5cpeU/A0mvAIHCTcJ36SFucii32i5hBABRV/WKh
gKAppFmXb4TL63heupYff3jlSWRSZKvlXc4R4ybMcIHHXVslK/9DGheEAYvVxTgh
NlV6wmj89cx/Xvzk/ODS4TlsnypIjcE+TINA5lGscRSNwtWYAeqBOxCK8fkSabka
aau0PTkoGaLHQWp2HwjIiJFrat/ZMJfsHWUvISeaKQ5ZJFtq++rE0alkgMpnfVmp
EOtvMdxrxYMPmeDVewH2XQseYWLFgdGzAf3i7MG1dHxEunqaoFCxSqzSnrKuFZLA
tbkHCjm2m2/oW3A0FdqmIIKrMLIDoBYjsEG5PXVYNqOnKpx/PEw=
=k1zg
-----END PGP SIGNATURE-----
Merge tag 'ipsec-2026-07-10' of git://git.kernel.org/pub/scm/linux/kernel/git/klassert/ipsec
Steffen Klassert says:
====================
pull request (net): ipsec 2026-07-10
1) xfrm: propagate -EINPROGRESS from validate_xmit_xfrm()
Return -EINPROGRESS from xfrm_output_one when validate_xmit_xfrm
requeues the packet asynchronously, so the caller doesn't treat it
as a real error and free the skb.
2) xfrm: fix stale skb->prev after async crypto steals a GSO segment
Re-derive skb->prev from the fragment list after async crypto splits
a GSO skb, keeping the linked-list pointers validi.
3) xfrm: nat_keepalive: avoid double free on send error
Hold a state ref while the nat_keepalive timer is active and drop the
timer before freeing the state, preventing a re-entered free on send
error.
4) xfrm: fix sk_dst_cache double-free in xfrm_user_policy()
Null the skb dst cache before freeing the policy so a later skb
destructor doesn't double-free it.
5) xfrm: cache the offload ifindex for netlink dumps
Cache the device ifindex at state-add time and use it for netlink
dumps instead of dereferencing dst->dev, which may have changed by
the time the dump runs.
6) xfrm: reject optional IPTFS templates in outbound policies
Reject outbound policies with an optional IPTFS template,
IPTFS must always be used if configured.
7) xfrm: clear mode callbacks after failed mode setup
Clear the mode->init_flags and init_state callbacks on the error path
after xfrm_init_mode fails, so a partially-initialised mode isn't
reused in xfrm_state_construct.
8) xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags()
Propagate SKBFL_SHARED_FRAG from the original skb to fragments
allocated by iptfs_skb_add_frags, keeping shared-fragment accounting
correct after IPTFS reassembly.
9) xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst()
Clear dst->dev on the error path of xfrm6_fill_dst() so the caller
doesn't release the netdev reference twice via dst_release.
10) xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert
Preallocate all inexact hash bins before existing entries are
reinserted during xfrm_hash_rebuild, so reinsertion always hits an
existing bin.
Please pull or let me know if there are problems.
ipsec-2026-07-10
* tag 'ipsec-2026-07-10' of git://git.kernel.org/pub/scm/linux/kernel/git/klassert/ipsec:
xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert
xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst()
xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags()
xfrm: clear mode callbacks after failed mode setup
xfrm: reject optional IPTFS templates in outbound policies
xfrm: cache the offload ifindex for netlink dumps
xfrm: fix sk_dst_cache double-free in xfrm_user_policy()
xfrm: nat_keepalive: avoid double free on send error
xfrm: fix stale skb->prev after async crypto steals a GSO segment
xfrm: propagate -EINPROGRESS from validate_xmit_xfrm()
====================
Link: https://patch.msgid.link/20260710090349.343389-1-steffen.klassert@secunet.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
|
||
|
|
47915e855f |
perf/x86/amd/brs: Fix kernel address leakage
A user-only branch stack can contain branches that originate from
the kernel. As a result, kernel addresses are exposed to user space
even when PERF_SAMPLE_BRANCH_USER is requested. On AMD processors
supporting X86_FEATURE_BRS (Zen 3 only), perf can still report entries
such as SYSRET/interrupt returns for which the branch-from addresses
are in the kernel.
E.g.
$ perf record -j any,u -c 4000 -e branch-brs -o - -- \
perf bench syscall basic --loop 1000 | \
perf script -i - -F brstack|tr ' ' '\n'| \
grep -E '0x[89a-f][0-9a-f]{15}'
...
0xffffffff810001c4/0x72e2e32955eb/-/-/-/0//-
0xffffffff810001c4/0x72e2d94a9821/-/-/-/0//-
0xffffffff810001c4/0x72e2d94ffa1b/-/-/-/0//-
...
BRS provides no hardware branch filtering, so privilege level
filtering is performed entirely in software. However, amd_brs_match_plm()
only validates the branch-to address against the requested privilege
levels. For branches from the kernel to user space, the branch-from
address is left unchecked and is leaked. Extend the software filter to
also validate the branch-from address, so that any branch record whose
branch-from address is in the kernel is dropped when
PERF_SAMPLE_BRANCH_USER is requested.
Fixes:
|
||
|
|
adea84ee6c |
Input: mms114 - fix multi-touch slot corruption
If the touchscreen controller reports a touch ID of 0, the driver
calculates the slot ID as touch->id - 1, which underflows to UINT_MAX.
This is passed to input_mt_slot() as -1.
Since the input core ignores negative slot values, the active slot remains
unchanged. The driver then reports the touch coordinates for the previously
active slot, corrupting its state.
Fix this by rejecting touch reports with ID 0.
Fixes:
|
||
|
|
dd3210c47e |
regulator: Fixes for v7.2
A couple of straightforward fixes for device loading, plus a fix for the core support for keeping multiple regulators with voltages close to each other that was sadly introduced due to one of the more beautiful corners of our API design. -----BEGIN PGP SIGNATURE----- iQEzBAABCgAdFiEEreZoqmdXGLWf4p/qJNaLcl1Uh9AFAmpRWw8ACgkQJNaLcl1U h9DeWwf/V6Op0a4A0D3/I0/vbYnnXmVdewO9wB2syfJp/SjtmWZyd6spNRT0ai1J QEbavn73gr/LcSj0YpoW9Oivp0y59B32nnBijCY4FmpjWhUH/NztzZbdHHkmpF4U AnyHi9kc09CCkxjzhqTDZ7rGCSPTtHfuJmoFI1fufCAGbBfqp3dXxhUPRCF2dIWt 5/FCgHTDsxRtVZ4AraNC81P7TYxeOxeygVpq3U2YziWcobKITiY+28/tKmACOFzH n2cbvB3tyPiUGzHyeXJmThlaUFUaoCnafyv51rLsnt55rmHKwX9aQVM/W69Sjhys 8MtQw6GrLhq0BI/GdVeECUS2STwugQ== =QBSG -----END PGP SIGNATURE----- Merge tag 'regulator-fix-v7.2-rc2' of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/regulator Pull regulator fixes from Mark Brown: "A couple of straightforward fixes for device loading, plus a fix for the core support for keeping multiple regulators with voltages close to each other that was sadly introduced due to one of the more beautiful corners of our API design" * tag 'regulator-fix-v7.2-rc2' of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/regulator: regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK regulator: mt6363: add missing MODULE_DEVICE_TABLE() regulator: mt6316: add missing MODULE_DEVICE_TABLE() |
||
|
|
bf124bae08 |
audit/stable-7.2 PR 20260710
-----BEGIN PGP SIGNATURE----- iQJIBAABCgAyFiEES0KozwfymdVUl37v6iDy2pc3iXMFAmpRNpEUHHBhdWxAcGF1 bC1tb29yZS5jb20ACgkQ6iDy2pc3iXN5+Q/+N1wsGx07LPmidKbPTx3R+yej3JCW hoLhnmPt7AXxVL671W29vkazKZ8hyQ5hzRy3wITyue9hsiXTNIwNffE1iBKkqMVA mchh38ziazJJ3h9PVWdiXdW/PoqOIAicFCUe0KJw8bV21Tdzjl+tCqVylU4j57k8 xpkGUifsK8FpkvDMzMlOfD5e4qShOqkPhacVz1OJDrW8gHV5Dh1AuTXdKz58dA1F Plu7IrtNd+CM1AQwS8ucawDB5PXnxHa708evS5bId/9fG/x5L5ZPJw6+jCPVA+Ea qUkWWalAJzOEp4jWDhvCyymtqiGhj9rFAydxCy32IAsF7TLTDCV8E+6Iq78wGtjg Oep+Tn9wOqV5QMILqlZ0zQxeDWnQWA0MzVRqIOFAvMrpurPLUbYZLFbUyNWouGBD cfU6O+AhADTmfkFfxxTFLsm0RQCEdnF1XeZEreXgwFuuF/A7SybmB2WTWE5wcmbu Riks3O9NHK620vCLf+wNpDc7+BkNmfBBhLUsyk0NDzEsIpViWS24stumBAP7+Fge 0KnWaB+vOD8IVub1YGgrxTNf3DfK6p8CLgwGYZMBjYFczJF8gCYXTfKlqmRVpXzw 20WaBbriMeMKgC5azD3aPqCg+/vgfBdCcEHSXAIS2KZivMQqYaodlFtTUowoDKng sn2hwA3SKfZ4aGw= =wY2k -----END PGP SIGNATURE----- Merge tag 'audit-pr-20260710' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/audit Pull audit fixes from Paul Moore: "Two relatively small audit patches to fix potential data races with the main audit backlog queue as well as possible integer overflows when logging data as hex strings" * tag 'audit-pr-20260710' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/audit: audit: fix potential integer overflow in audit_log_n_hex() audit: Fix data races of skb_queue_len() readers on audit_queue |
||
|
|
ccce5f6e7c |
selinux/stable-7.2 PR 20260710
-----BEGIN PGP SIGNATURE----- iQJIBAABCgAyFiEES0KozwfymdVUl37v6iDy2pc3iXMFAmpRNjYUHHBhdWxAcGF1 bC1tb29yZS5jb20ACgkQ6iDy2pc3iXOuTg//bE+PiQbWeAQFK69l4/sl9vaxNw5P YBGRIVxGLaGhkTl30jVbwXDY5W6bvYf3iq+S9lbu1OPtAgye7ijQtM5p62CL9V/Y D9/oz8gR/CBySEs9+rCWKhijTDO2MlmDTH8ygG7Z7/eOgPXDMcZ61/xPrTJtO10k rMpboPAQPyCYTDB0Qakju31N65b5+ZgOQizux64l1ANQEQSarL7VJn2wWleuQL7W le0ggVJ16f9sUk50G97vN1mKnqy7p5/7La/P4KaNgzD/sb1Y6NLqItcOzs+9lT4x Uu2Wob1nBD2WS7Occ5ruwkl9jToEk9aGx1Ez5buzbKA4YjhEwQJc6gD1LjZTLRvj Gy8CP32PJNnKp+y1BVv0yNTWZKOqRQouvg1H/4JccoS9ZlRRQc6ctFWpJjNqHrN8 pzagkE3vFX1CTz1MxHY1VXVgj6ezlLAjJuUBvpJ+nhvwRIDkwZPTCYNCgt42zpQF lQeuOdMtMU7dsYYScJd22fOG3ySm2auXyMaVitS43gNHVuV3zjWnWalHzwI31HrW 63L9sbt4jXhR/EqoNJNRvJfFlDy95z+rqLPHusT6SmS7cciasG7WjJV51Wnf5JK8 Rz3rXbuD7teCVh/bOkJmdxPUfSq7cVolBmvmPXVwhK45AifFmfmwkScao0/WZw8d 2AlNWfkfUA2tCOc= =P3C9 -----END PGP SIGNATURE----- Merge tag 'selinux-pr-20260710' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux Pull selinux fixes from Paul Moore: "Two small SELinux patches to fix a missing permission check for TCP Fast Open operations and fix a socket lookup issue with SCTP ASCONF operations" * tag 'selinux-pr-20260710' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux: selinux: avoid sk_socket dereference in selinux_sctp_bind_connect() selinux: check connect-related permissions on TCP Fast Open |
||
|
|
61c03dfde8 |
Description for this pull request:
- fix stale runlist element dereferences in MFT writeback and fallocate - fix mrec_lock ABBA deadlock in rename - prevent userspace modification of NTFS system files - avoid inode eviction/writeback self-deadlocks - reject malformed resident attributes in non-resident runlist mapping - avoid post_write_mst_fixup() on invalid index blocks - fix a hole runlist leak in insert-range error handling - sanitize directory lookup MFT references from disk - fail attribute-list updates after SB_ACTIVE is cleared during teardown -----BEGIN PGP SIGNATURE----- iQJKBAABCgA0FiEE6NzKS6Uv/XAAGHgyZwv7A1FEIQgFAmpRiDMWHGxpbmtpbmpl b25Aa2VybmVsLm9yZwAKCRBnC/sDUUQhCD43EADKiCMxaenYjS7BveKvxV1eCMUW LY5OaS8pEAILxX1Et5XFH96eqkHYlrGvneOd9txZpO48j/Ieyep0/cqeZFK4hw31 JyIItrSM1VwbPUK75bMPSXCpJn/BbzCDf+PsQwp44SE6VQWwZfWQfmj3neSU1hIU S8jI3GZaf6Ry5s5BQOiLP4gpfOcPKFhlTDLFycHg8Rn5Uqt3LwDoFTsfHh/Bs9ls MMcoyEmEJ7twF4+PpEZtCw/Am6FY3t2rSFTtfw3GuNNEKCemKm1V1L8CdFCbu0xo fC3cyq+aWBWiEFTueotszbLl4MHYODPZKfwtH/FgT+MUFPKQidsuAFsuRYHS+V28 lRPb+XTxfCeerLTlTlseX3Tes3Auw3XW9nojduvGKxK5w0Bsu/2c638fviOxd9Uk RmZ7EOPB/ROwXFswQF+xk9YAFWLN2FwJtdnWyj4f5XLF6vxFDxzU5lvrc/BW6TQM ePUCr+0ngKe93Nl+4xCcITTkSjNy5jM7iQCy26/8946+nYtYZ4Nd9tbcDpYpSoiT gvyIK/MauqJ1Uuxs9VvmZZj4SMcWdJHMPjDSLNyalTgSSzS0LO6zEvgLJo0n4+Tj wbhR0A8rqEWAT42Owj2SpMNzwd/wC7lTfgIPePAVF2uGI8n9tWC+xT9iUTf19MN1 w+YM/ZPQmD0eDPgU9w== =TC/T -----END PGP SIGNATURE----- Merge tag 'ntfs-for-7.2-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/linkinjeon/ntfs Pull ntfs fixes from Namjae Jeon: - fix stale runlist element dereferences in MFT writeback and fallocate - fix mrec_lock ABBA deadlock in rename - prevent userspace modification of NTFS system files - avoid inode eviction/writeback self-deadlocks - reject malformed resident attributes in non-resident runlist mapping - avoid post_write_mst_fixup() on invalid index blocks - fix a hole runlist leak in insert-range error handling - sanitize directory lookup MFT references from disk - fail attribute-list updates after SB_ACTIVE is cleared during teardown * tag 'ntfs-for-7.2-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/linkinjeon/ntfs: ntfs: fail attrlist updates when the superblock is inactive ntfs: sanitize MFT references returned from ntfs_lookup_inode_by_name() ntfs: fix hole runlist memory leak in insert range error path ntfs: avoid calling post_write_mst_fixup() for invalid index_block ntfs: fix WARN_ON for resident attribute in ntfs_map_runlist_nolock() ntfs: avoid self-deadlock during inode eviction ntfs: make system files immutable to prevent corruption ntfs: fix mrec_lock ABBA deadlock in rename ntfs: avoid stale runlist element dereference in fallocate ntfs: avoid stale runlist element dereference in MFT writeback |
||
|
|
58d9f84279 |
NFS Client Bugfixes for Linux 7.2-rc3
Bugfixes:
* SUNRPC: Release lower rpc_clnt if killed waiting for XPRT_LOCKED
* SUNRPC: Pin upper rpc_clnt across the TLS connect_worker
* NFS: Include MAY_WRITE in open permission mask for O_TRUNC
* NFS: Charge unstable writes by request size, not folio size
-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEEnZ5MQTpR7cLU7KEp18tUv7ClQOsFAmpRWv0ACgkQ18tUv7Cl
QOtb+xAA6IzOT6tSlcCuFYV4pOk6OCCUtntcDxqQDuYupQbkE04AJBq6sVPLSfXy
69BOLCKlG9hNCkZvLAb3tSWJTD1NzRX8tYhVFb6GKTz8cf/s7QqqVaaNKZu5Rrn3
AfZWNpw8KiUBhkjSMHVQL42QkIzASdDZ83vnL+LahbT4YAx9TNkkQIZLPBM0CKGU
pYdtd43Ex87M8g5gteBT0qVGsSLzGxoV2qO8qxatDvvQDQFZmnl1w4x6HwuxEVcB
1EhzfSDcWJOujHLpYV4+tk7FIw03MQvjPOoz71H2EXPUBZGRfXQjVggBzmvM6a91
aNLIUfv8LTGmqewfDdEe0r1amJPoknXnIoIvYiZIcKPT1VlMiK2A1y8r8zS307Rj
q3Lax7p6WawTx/Ecg1HD2jLRvn6I7SI7gF/IUcw8mL1uWOiT2quBLHrOcOvwZHzs
IGJ5ox+lMn1Dwdn86SF3zVxscMNSQ6aUr/zUXIeIx8EHUDyWwZ7gGSgmuP7YPS0I
wu34tm4T3pjFKjfylUoVidU/tvKMipREQoETxEvlWByfoxVabD9yahni3GL+oKcT
6/kAeJGpZh6+y2Er8dzxUStijCuv27X4V+DfOXSAWACLO8Sixcj52gkVydLKiFCc
dXFbti9Sjjqjyijmd93GSMhouAiASslLIfHVpvcYHR/AfA2ReGg=
=FUd/
-----END PGP SIGNATURE-----
Merge tag 'nfs-for-7.2-2' of git://git.linux-nfs.org/projects/anna/linux-nfs
Pull NFS client fixes from Anna Schumaker:
- SUNRPC:
- Release lower rpc_clnt if killed waiting for XPRT_LOCKED
- Pin upper rpc_clnt across the TLS connect_worker
- NFS:
- Include MAY_WRITE in open permission mask for O_TRUNC
- Charge unstable writes by request size, not folio size
* tag 'nfs-for-7.2-2' of git://git.linux-nfs.org/projects/anna/linux-nfs:
NFS: Charge unstable writes by request size, not folio size
NFSv4: include MAY_WRITE in open permission mask for O_TRUNC
SUNRPC: pin upper rpc_clnt across the TLS connect_worker
SUNRPC: release lower rpc_clnt if killed waiting for XPRT_LOCKED
|
||
|
|
8eae393cbf |
seventeen client fixes
-----BEGIN PGP SIGNATURE----- iQGzBAABCgAdFiEE6fsu8pdIjtWE/DpLiiy9cAdyT1EFAmpRLz8ACgkQiiy9cAdy T1GalgwAqtaIFVMj7T1CDZcV/S0RymYPaiI2RNaaEcdn1T59mpsjaf5UVHwXN04K SZjQcAdGOgWvjZlPYvzah4pw0/T6EHRMYe7d2MRanV5epx6PJqfmBS3/gJ+I1NvN jckWo3RPnrixYWpIH/f9S0aIksyr19UUsxkDpfUHhQPerWXwIZNXR0+k/VbiHUDn OnyhpasP6/okrNqZBZ8GjkCx7p5PENckd1p5hD+NeIRzQybHuWPos7kGIExp1973 BvXXzK76OXvB4aOUS/ofP1MxbmCvMaXUeM3JecPSspjOiu02z2qmRCnJVsCXztPC uHe63kKHWSlunSAVH1wJHTG3BsI0hTK9Kmkyi7jbExpqYydpXwjLSEeQeggnoCBj bQuVNslAYRzPFddjhxGyTkIyry8Hh2drlCD7FF1cxnlIz4x9ADOxiyEKHS7m9Xv+ ZJiEIuhs5IUJnU7xGXqSx4Ve4AU8rW7aRXYvXRS1LrdWj8EZpbIW70leFyv6ocAI hG/TeGmG =RhsK -----END PGP SIGNATURE----- Merge tag 'v7.2-rc2-smb3-client-fixes' of git://git.samba.org/sfrench/cifs-2.6 Pull smb client fixes from Steve French: - DFS cache allocation fix - DFS referral bounds check fix - Fix absolute symlinks when mounting with POSIX extensions - Fixes for incorrect nlink returned by fstat - Fix atime in read completion - Fix busy dentry on umount - ioctl_query_info buffer overflow fix - Two fixes for creating special files with SFU - Fix mode mask in parse_dacl - SMB1 is_path_accessible wildcard fix and minor SMB1 cleanup - smb2_check_message fix - Debug message improvement - Minor cleanup * tag 'v7.2-rc2-smb3-client-fixes' of git://git.samba.org/sfrench/cifs-2.6: cifs: Remove CIFSSMBSetPathInfoFB() fallback function cifs: Fix and improve cifs_is_path_accessible() function smb: client: mask server-provided mode to 07777 in modefromsid cifs: Show reason why autodisabling serverino support smb/client: fix incorrect nlink returned by fstat() smb/client: zero-initialize stack-allocated cifs_open_info_data smb/client: pass cifs_open_info_data to SMB2_open() smb/client: use stack-allocated smb2_file_all_info in smb3_query_mf_symlink() smb: client: fix overflow in passthrough ioctl bounds check smb: client: fix busy dentry warning on unmount after DIO cifs: Fix support for creating SFU fifo cifs: Fix support for creating SFU socket smb: client: fix atime clamp check in read completion cifs: validate DFS referral string offsets smb: client: use GFP_KERNEL for DFS cache allocations smb: client: restrict implied bcc[0] exemption to responses without data area smb: client: preserve leading slash for POSIX absolute symlink targets smb: client: refactor cifs_revalidate_mapping() to use clear_and_wake_up_bit() |
||
|
|
1d0e25c1dd |
udmabuf: Ensure to perform cache synchronisation in begin_cpu_udmabuf()
The message of commit |
||
|
|
76f38ad1b3 |
ARC: configs: Drop redundant I2C_DESIGNWARE_PLATFORM
I2C_DESIGNWARE_PLATFORM is default=y via I2C_DESIGNWARE_CORE, which is enabled. No impact on include/generated/autoconf.h. Signed-off-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com> Signed-off-by: Vineet Gupta <vgupta@kernel.org> |
||
|
|
460511c11f |
arc: validate DT CPU map strings before parsing them
arc_get_cpu_map() fetches the possible-cpus or present-cpus property from the flat DT and immediately passes the raw pointer to cpulist_parse(). That parser expects a NUL-terminated text buffer, but this path does not prove that the DT property is terminated within its declared bounds. Reject unterminated CPU-map properties before handing them to cpulist_parse(). Changes since v1: - fold the NUL-termination check into the initial lookup test, as suggested by Vineet Gupta Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn> Signed-off-by: Vineet Gupta <vgupta@kernel.org> |
||
|
|
601ddaceb8 |
ring-buffer: Allow sparse CPU masks in ring_buffer_desc()
No user currently relies on sparse CPU masks, but the descriptor logic already
supports them via linear fallback. Remove the arbitrary limitation.
Link: https://patch.msgid.link/20260709160017.1729517-4-vdonnefort@google.com
Fixes:
|
||
|
|
d471d4f86e |
tracing/remotes: Fix struct_len in trace_remote_alloc_buffer()
Pre-calculate desc->struct_len up-front in trace_remote_alloc_buffer()
with trace_buffer_desc_size() to fix double-counting.
While at it, use the accessor __first_ring_buffer_desc().
Link: https://patch.msgid.link/20260709160017.1729517-3-vdonnefort@google.com
Fixes:
|
||
|
|
ec082d0b97 |
tracing/remotes: Fix leak in trace_remote_alloc_buffer() error path
If page allocation fails in trace_remote_alloc_buffer(), desc->nr_cpus
is not yet incremented for the current CPU. As a consequence, on error,
half-allocated rb_desc will not be freed in trace_remote_free_buffer().
Increment desc->nr_cpus as soon as the first allocation for the current
CPU has succeeded.
Link: https://patch.msgid.link/20260709160017.1729517-2-vdonnefort@google.com
Fixes:
|
||
|
|
78bf392ba7
|
platform/x86: asus-wmi: temporarily revert to setting a charge limit
A userspace regression has been observed leaving the battery charging
threshold unconfigured, so while the fix is being shipped revert
the change keeping the infrastructure in place to return to the
preferred behaviour as soon as it's appropriate to do.
Link: https://lore.kernel.org/all/5db117b7-aad1-437f-a3d4-ba7b29fc68b3@redhat.com/
Link: https://gitlab.freedesktop.org/upower/upower/-/work_items/347
Closes: https://lore.kernel.org/all/CABsFS_g+V_Owum6knLhenhM15EXJRrsF0FcLiw30WZxarsTpUA@mail.gmail.com/
Fixes:
|
||
|
|
09b2ae290a
|
platform/x86/intel/vsec: free ACPI discovery data on early errors
intel_vsec_add_dev() may attach an ACPI discovery table copy to the
intel_vsec_device before passing ownership to intel_vsec_add_aux(). The
normal auxiliary-device release path frees that copy, but the earliest
intel_vsec_add_aux() failures free only the outer structure directly.
Route those direct frees through a common helper so acpi_disc is
released consistently on the parent, xarray, and ID allocation failure
paths.
Fixes:
|
||
|
|
d96fcfe1b7 |
arm64 fixes for -rc3
- Fix crash when using SMT hotplug on ACPI systems in conjunction with maxcpus=. - Fix 30% kswapd performance regression introduced by C1-Pro SME erratum workaround. - Fix TLB over-invalidation regression during memory hotplug. - Fix incorrect encoding of FEAT_BWE2 value in ID_AA64DFR2_EL1.BWE. - Typo fixes in the arm64 selftests. -----BEGIN PGP SIGNATURE----- iQFEBAABCgAuFiEEPxTL6PPUbjXGY88ct6xw3ITBYzQFAmpQ3FkQHHdpbGxAa2Vy bmVsLm9yZwAKCRC3rHDchMFjNB5/B/9L6cQyMiFFdHiPdyZs1zzx2U5pTtKZQuLZ KQsJNhEuk0x50zSHJry+Be2FPkbqJzGiEl+cIyMjWt5hbDnTuj1MylLPX1HgpblG oXCsBOq3ahPBCmngLTq9jmQWGqBsc/9x9IscIhICY3hbjyc1esl7OAfRCxZeDjMW +ybpv6pYsheMvNm8NAN3RmpSWgxgiiP50HBdOHkSNNsF8NfVr3SwW7fv2sdaLWEo jdPvpP8k+misIZoXw/tdXhpUlTrseWnuhuV8R08mloJF4J6fMoYgwJNpkOttTphT EomGhwYI7pCqh7otX1GPvcZtzL4OB2zVBCJwmRNmdlOegMnFoWtK =J2Ug -----END PGP SIGNATURE----- Merge tag 'arm64-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux Pull arm64 fixes from Will Deacon: - Fix crash when using SMT hotplug on ACPI systems in conjunction with maxcpus= - Fix 30% kswapd performance regression introduced by C1-Pro SME erratum workaround - Fix TLB over-invalidation regression during memory hotplug - Fix incorrect encoding of FEAT_BWE2 value in ID_AA64DFR2_EL1.BWE - Typo fixes in the arm64 selftests * tag 'arm64-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux: selftests/arm64: fix spelling errors in comments arm64/sysreg: Fix BWE field encoding in ID_AA64DFR2_EL1 arm64/mm: Optimize TLB flush in unmap_hotplug_[pmd|pud]_range() arm64: Avoid eager DVMSync reclaim batches with C1-Pro SME erratum cpu/hotplug: Fix NULL kobject warning in cpuhp_smt_enable() arm64: smp: Fix hot-unplug tearing by forcing unregistration |
||
|
|
1f0fe3220f |
platform-drivers-x86 for v7.2-2
Fixes
- amd/pmc:
- Use correct IP block table for AMD 1Ah M80H SoC
- Avoid logging "(null)" for missing DMI values
- asus-armoury: update power limits for G614PR
- bitland-mifs-wmi: Fix NULL pointer dereference during suspend/resume
The following is an automated shortlog grouped by driver:
amd/pmc:
- Avoid logging "(null)" for DMI values
amd-pmc:
- Use correct IP block table for AMD 1Ah M80H SoC
asus-armoury:
- update power limits for G614PR
bitland-mifs-wmi:
- Fix NULL pointer dereference during suspend/resume
-----BEGIN PGP SIGNATURE-----
iHUEABYKAB0WIQSCSUwRdwTNL2MhaBlZrE9hU+XOMQUCalDWfQAKCRBZrE9hU+XO
MRg6AQClzm56cAKihLDveRd1iQxSK1SC5SR1ZlAsrUiH1iIClQEAr/e8V0Ax8On+
O7nhuR6Jh4nWuLijj+BuCfhg3D88yg0=
=CBFq
-----END PGP SIGNATURE-----
Merge tag 'platform-drivers-x86-v7.2-2' of git://git.kernel.org/pub/scm/linux/kernel/git/pdx86/platform-drivers-x86
Pull x86 platform driver fixes from Ilpo Järvinen:
- amd/pmc:
- Use correct IP block table for AMD 1Ah M80H SoC
- Avoid logging "(null)" for missing DMI values
- asus-armoury: update power limits for G614PR
- bitland-mifs-wmi: Fix NULL pointer dereference during suspend/resume
* tag 'platform-drivers-x86-v7.2-2' of git://git.kernel.org/pub/scm/linux/kernel/git/pdx86/platform-drivers-x86:
platform/x86: amd-pmc: Use correct IP block table for AMD 1Ah M80H SoC
platform/x86: asus-armoury: update power limits for G614PR
platform/x86: bitland-mifs-wmi: Fix NULL pointer dereference during suspend/resume
platform/x86/amd/pmc: Avoid logging "(null)" for DMI values
|
||
|
|
0e2f4ab68a |
sched_ext: Skip ops.set_weight() for disabled tasks
When switching a task's sched_class away from sched_ext, we get the
following sequence of events in __sched_setscheduler():
sched_change_begin()
switched_from_scx()
scx_disable_task(p)
ops.disable(p)
__setscheduler_params()
set_load_weight()
reweight_task_scx(p)
ops.set_weight(p)
p->sched_class = next_class;
sched_change_end()
...
Notably, ops.set_weight() is called _after_ ops.disable().
This violates the expected semantics of the callbacks, the expectation
being that ops.disable() can only be followed by ops.exit_task() or
ops.enable().
Skipping the weight adjustment for disabled tasks should be harmless
since the weight will be recalculated in scx_enable_task() if the task
ever rejoins SCX.
Fixes:
|
||
|
|
386df1a57b |
dm-stats: fix dm_jiffies_to_msec64
There were wrong calculations in dm_jiffies_to_msec64 that produced
incorrect output when HZ was different from 1000. This commit fixes them.
Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>
Assisted-by: Claude:claude-opus-4-6
Fixes:
|
||
|
|
1917eb2db7 |
dm-stats: fix merge accounting
There were wrong parentheses when setting stats_aux->merged, so that
merging was never properly accounted. This commit fixes it.
Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>
Assisted-by: Claude:claude-opus-4-6
Fixes:
|
||
|
|
422f1d4f14 |
dm-bufio: fix wrong count calculation in dm_bufio_issue_discard
block_to_sector converts a block number to a sector number and adds
c->start to the result. It is inappropriate to use this function for
converting the number of blocks to a number to sectors because c->start
would be incorrectly added to the result.
Luckily, the only target that uses dm_bufio_issue_discard is dm-ebs,
which sets c->start to 0, so this bug is latent.
Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>
Assisted-by: Claude:claude-opus-4-6
Fixes:
|
||
|
|
f827c27e57 |
gpio fixes for v7.2-rc3
- provide the missing .get_direction() callback in gpio-palmas - fix interrupt handling in gpio-dwapb - add a GPIO self-test program binary to .gitignore - fix a resource leak in gpio-mvebu - make the GPIO sharing heuristic more adaptable -----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEEkeUTLeW1Rh17omX8BZ0uy/82hMMFAmpQsEsACgkQBZ0uy/82 hMNmAQ/+NXDigkDMVNy5K93G//7YF+OI5UlCB+R1+7eQW1QDpVHx/dEwSnoOST1I ieBfJZ7haT3HqkdcKn8XgNgqsvg2Egn+CjMVXu8HsEIQtgG8L8SycAuFnoKQFgYZ vq6IW3zmQ3sfNH8E0RrJBlT0jthjh95hX1lD9Wp86xcEx2pqIv/yM780NEVIUxhS TdIZwwwvsknPVwjNLL3cJbgj/vcYr36QqK3UBPGj/eiyJnYn3xIuIKrFsd87SUkf 85JytEapkCMBY2svABX3bCzZF2kUuOhA7AaFhIVzVDXAIthl60dd7gFS55eqxEdR 3P1yfcKJZF2G6cYGIAh0QhgcSja6IZa4opp4phD2x5cD6Yp0XWW3l+WbJHWfelNG 1QAfS2gIT7QDVK2Q0kOCLxkdk3mNYK3b2iyNvtnmQMwIzgkzBF7rzS9t+w5tzA8K geeqLt0kehIMtO3M6gMGIJZptzC95nYwlJnq4tDbxeG7VqTjadVsy55XauMk1cET 9fn70RYLlor87xT28svAdpGqd6uOBY7Agd6l/CujPhqTsNDikx4FE6510iDOM0Em fQ45cpQPoqConlowjjtWFhpnIeWAAEdgjwFgdXeYvQTCzaqOIK8XHy20l+sWEO3+ MQeUrJrXf2XMujdEwxu5N8d7UjhNWcHO3g2lfCg4lHzLrc9WnHg= =ld94 -----END PGP SIGNATURE----- Merge tag 'gpio-fixes-for-v7.2-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/brgl/linux Pull gpio fixes from Bartosz Golaszewski: - provide the missing .get_direction() callback in gpio-palmas - fix interrupt handling in gpio-dwapb - add a GPIO self-test program binary to .gitignore - fix a resource leak in gpio-mvebu - make the GPIO sharing heuristic more adaptable * tag 'gpio-fixes-for-v7.2-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/brgl/linux: gpio: mvebu: free generic chips on unbind selftests: gpio: add gpio-cdev-uaf to .gitignore gpio: dwapb: Mask interrupts at hardware initialization gpio: dwapb: Defer clock gating until noirq gpio: shared: make the voting mechanism adaptable gpios: palmas: add .get_direction() op |
||
|
|
5142c56651 |
bug: fix warning suppressions with kunit built as module
CONFIG_KUNIT is a tristate symbol but the warning suppression code in
lib/bug.c is only built if it's built-in due to it using a plain #ifdef,
rendering warning suppressions broken for kunit build as loadable module.
kunit_is_suppressed_warning() already has a stub for when kunit is
disabled so drop that guard entirely.
Link: https://lore.kernel.org/r/20260708095459.12111-1-bartosz.golaszewski@oss.qualcomm.com
Suggested-by: Albert Esteve <aesteve@redhat.com>
Cc: stable@vger.kernel.org
Fixes:
|
||
|
|
8f964d992e |
ata fixes for 7.2-rc3
- Fix handling of security locked drive revalidation. This prevents
such drives from being dropped when locked on resume (Terrence).
-----BEGIN PGP SIGNATURE-----
iHUEABYKAB0WIQSRPv8tYSvhwAzJdzjdoc3SxdoYdgUCalCc1gAKCRDdoc3SxdoY
dn5AAQDFOituq8siLG4lUjsTmZ0yOzzZO3dzLFmDASXDmdPJ1AEAqsW4AYOt0FHO
1ePotSlMoRQ8/Q3sHg8SDkjC2iw6QAQ=
=2Hqi
-----END PGP SIGNATURE-----
Merge tag 'ata-7.2-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/libata/linux
Pull ata fixes from Damien Le Moal:
- Fix handling of security locked drive revalidation. This prevents
such drives from being dropped when locked on resume (Terrence)
* tag 'ata-7.2-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/libata/linux:
ata: libata-core: Allow capacity transition to zero for locked drives
ata: libata-core: Skip HPA resize for locked drives
|
||
|
|
c5c413534d |
selftests/tracing: Have trigger-hist-poll.tc use sched_process_exit
Currently trigger-hist-poll.tc uses sched_process_free to test the polling of the histogram file. The way it does that is to run sleep, then execute the poll.c code that polls on the sched_process_free for up to 4 seconds to test that when sleep triggers the sched_process_free trace event, it will update the histogram and wake the poll.c code up. The issue is that sched_process_free trace event is called by delayed_put_task_struct() which is called after a RCU grace period has ended. If CONFIG_RCU_LAZY is enabled, RCU callbacks are batched together and do not execute right away. This causes the delayed_put_task_struct() to be called after the poll.c function finishes and it will report an error that it did not wake up on the event. That's because the event didn't trigger during its wait time. Use sched_process_exit instead, which is called when a process exits and doesn't depend on RCU callbacks that may be delayed. Link: https://lore.kernel.org/r/20260708163436.058cc3df@gandalf.local.home Signed-off-by: Steven Rostedt <rostedt@goodmis.org> Acked-by: Masami Hiramatsu (Google) <mhiramat@kernel.org> Signed-off-by: Shuah Khan <skhan@linuxfoundation.org> |
||
|
|
22a78be412 |
selftests/ftrace: Fix reading enabled_functions in add_remove_fprobe_module test
The add_remove_fprobe_module test checks the number of functions added to the enabled_functions file to make sure that the functions added or removed is as expected. The issue is that it expects this file to be empty on start up. Now that systemd uses BPF that attaches to functions via ftrace, this file is not empty in several systems: # cat /sys/kernel/tracing/enabled_functions bpf_lsm_file_open (1) R D M tramp: ftrace_regs_caller+0x0/0x61 (call_direct_funcs+0x0/0x50) direct(jmp)-->bpf_trampoline_6442529439+0x0/0xe9 Change the test to read the number of lines in enabled_functions at the start of the test and subtract that from the value of the count for the checks within the test. Link: https://lore.kernel.org/r/20260708153239.055d56dd@gandalf.local.home Signed-off-by: Steven Rostedt <rostedt@goodmis.org> Acked-by: Masami Hiramatsu (Google) <mhiramat@kernel.org> Signed-off-by: Shuah Khan <skhan@linuxfoundation.org> |
||
|
|
cfbebb55e5 |
KVM: TDX: Reject concurrent change to CPUID entry count
Reject KVM_TDX_INIT_VM if userspace changes cpuid.nent between the
initial read and the subsequent copy of the initialization data.
tdx_td_init() first reads user_data->cpuid.nent to size the flexible
kvm_tdx_init_vm copy. The copied structure also contains cpuid.nent,
and that field can differ from the value used to size the allocation if
userspace modifies the input concurrently. setup_tdparams_cpuids() later
passes init_vm->cpuid.nent to kvm_find_cpuid_entry2(), which uses it as
the array bound for the copied entries.
Require the copied count to match the value used to size the allocation
so that CPUID parsing cannot access beyond the entries actually copied.
Fixes:
|
||
|
|
745df2052c |
MAINTAINERS: Update maintainer and git tree for CIX SoC
Peter Chen has left CIX Technology. Take over maintenance of the CIX SoC and Update the git tree URL accordingly. Signed-off-by: Gary Yang <gary.yang@cixtech.com> Reviewed-by: Fugang Duan <fugang.duan@cixtech.com> Acked-by: Peter Chen <peter.chen@kernel.org> Signed-off-by: Arnd Bergmann <arnd@arndb.de> |