Commit Graph

1483457 Commits

Author SHA1 Message Date
Puranjay Mohan
36bb85cf36 perf/core: Fix NULL pmu_ctx passed to pmu->sched_task()
perf_pmu_sched_task() returns early when cpuctx->task_ctx is set, and
cpc->task_epc is only non-NULL while a task context is scheduled in on
this CPU. __perf_pmu_sched_task() therefore always passes NULL:

  Unable to handle kernel NULL pointer dereference at virtual address 00
  pc : armv8pmu_sched_task+0x14/0x50
  Call trace:
   armv8pmu_sched_task+0x14/0x50 (P)
   perf_pmu_sched_task+0xac/0x108
   __perf_event_task_sched_out+0x6c/0xe0

Pass &cpc->epc instead, the CPU-wide context for this PMU, which the
function already dereferences a few lines up to find pmu.

armv8pmu_sched_task() is the only in-tree implementation that
dereferences the argument, and it only reads ->pmu, so the oops needs
BRBE, added in v6.17.

Fixes: bd27568117 ("perf: Rewrite core context handling")
Signed-off-by: Puranjay Mohan <puranjay@kernel.org>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Tested-by: Yifan Wu <wuyifan50@huawei.com>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260810133540.1947118-2-puranjay@kernel.org
2026-09-23 11:48:35 +02:00
Namhyung Kim
cca4980630 perf/core: Fix a refcount leak in attach_perf_ctx_data()
The attach_perf_ctx_data() can race on global and !global cases.  The
global case is protected by global_ctx_data_rwsem and shares a single
reference count using perf_ctx_data.global field.

But when it races with !global case, it may miss to set the global field
and result in a reference count leak.

 CPU1                                  CPU2
 ----------------------------------------------------------------
 attach_task_ctx_data(.global=1)       attach_task_ctx_data(.global=0)
   cd1 = alloc_perf_ctx_data();          cd2 = alloc_perf_ctx_data();
                                         //    { .global = 0, .refcount = 1 };

                                         try_cmpxchg(); // success,
                                         // task->perf_ctx_data = cd2
   try_cmpxhg(); // fail; old = cd2
   refcount_inc_not_zero(&old->refcount); // success
     // old.refcount = 2
   free_perf_ctx_data(cd1);

Then later detach_global_ctx_data() will see the data but it's not
marked as global, so it won't call detach_task_ctx_data().

Fixes: 506e64e710 ("perf: attach/detach PMU specific data")
Assisted-by: Sashiko.dev:Gemini-3.1-pro
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Link: https://patch.msgid.link/20260920231639.11910-1-namhyung@kernel.org
2026-09-23 11:48:35 +02:00
Dapeng Mi
d4d9ccbad5 perf/x86/intel: Rename NVL offcore_rsp attribute to offmodule_rsp
NVL introduces Offmodule Response events in place of the legacy
Offcore Response events, but it still exposes the inherited
offcore_rsp PMU attribute for programming the corresponding MSR data.

Rename the NVL PMU attribute to offmodule_rsp so the sysfs interface
matches the underlying event name and avoids user & tooling confusion.

Signed-off-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Link: https://patch.msgid.link/20260917015234.981153-13-dapeng1.mi@linux.intel.com
2026-09-22 11:38:17 +02:00
Dapeng Mi
0102c8c7fd perf/x86/intel: Rename DMR offcore_rsp attribute to offmodule_rsp
DMR introduces Offmodule Response events in place of the legacy
Offcore Response events, but it still exposes the inherited
offcore_rsp PMU attribute for programming the corresponding MSR data.

Rename the DMR PMU attribute to offmodule_rsp so the sysfs interface
matches the underlying event name and avoids user & tooling confusion.

Signed-off-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Link: https://patch.msgid.link/20260917015234.981153-12-dapeng1.mi@linux.intel.com
2026-09-22 11:37:46 +02:00
Dapeng Mi
ff1621adfd perf/x86/intel: Fix precise OMR event scheduling for DMR/NVL
The latest perfmon event database introduces below precise OMR event
support for DMR/NVL:

- MEM_LOAD_L2_MISS_RETIRED.* (event 0xd6)
- MEM_STORE_L2_MISS_RETIRED.* (event 0x4f)

These events use the same OMR MSRs as the existing OMR events, but
they are not listed in intel_pnc_extra_regs[]. As a result, perf
cannot assign the required OMR extra registers when scheduling them.

Add the new precise OMR events to intel_pnc_extra_regs[] so they can
be scheduled with the correct OMR MSRs. MEM_LOAD_L2_MISS_RETIRED.*
remains limited to GP counters 0-3, while
MEM_STORE_L2_MISS_RETIRED.* is available on all GP counters.

Signed-off-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Link: https://patch.msgid.link/20260917015234.981153-11-dapeng1.mi@linux.intel.com
2026-09-22 11:37:00 +02:00
Dapeng Mi
04a7ef3b7a perf/x86/intel: Constrain Panther Cove UOPS_DISPATCHED events to PMCs 0-3
Per the latest Panther Cove event definitions, the following events are
only supported on PMCs 0-3:

- UOPS_DISPATCHED.INT_EU_ALL (0x1b2)
- UOPS_DISPATCHED.ALU (0x2b2)

Add explicit event constraints for these two events so scheduling does
not place them on unsupported counters.

Fixes: d345b6bb88 ("perf/x86/intel: Add core PMU support for DMR")
Signed-off-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Cc: <stable@vger.kernel.org> # v7.0+
Link: https://patch.msgid.link/20260917015234.981153-10-dapeng1.mi@linux.intel.com
2026-09-22 11:35:40 +02:00
Dapeng Mi
858b37ca19 perf/x86/intel: Delete dead NVL PEBS data-source initcall
Nova Lake now uses the OMR data-source table for PEBS data-source
decoding and no longer depends on the legacy static pebs_data_source[]
mapping.

Remove the dead intel_pmu_pebs_data_source_lnl() initialization call
for NVL.

Fixes: c847a208f4 ("perf/x86/intel: Add core PMU support for Novalake")
Signed-off-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Link: https://patch.msgid.link/20260917015234.981153-9-dapeng1.mi@linux.intel.com
2026-09-22 11:33:49 +02:00
Dapeng Mi
0ac5d6ca2c perf/x86/intel: Fix Panther Cove PEBS data-source snoop states
For Panther Cove, the snoop states for the data source encodings
"Prefetch Promotion" and "Cross Core Prefetch Promotion" should be
SNOOP_NONE instead of SNOOP_MISS.

Fix the incorrect snooping states for Panther Cove.

Fixes: d2bdcde962 ("perf/x86/intel: Add support for PEBS memory auxiliary info field in DMR")
Signed-off-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Cc: <stable@vger.kernel.org> # v7.0+
Link: https://patch.msgid.link/20260917015234.981153-8-dapeng1.mi@linux.intel.com
2026-09-22 11:33:06 +02:00
Dapeng Mi
9f93d33ad6 perf/x86/intel: Remove incorrect Panther Cove PEBS data-source constraints
Same issue exists on Panther Cove, PEBS data source is valid only for
these events:

- MEM_TRANS_RETIRED.LOAD_LATENCY (0x1cd)
- MEM_TRANS_RETIRED.STORE_SAMPLE (0x2cd)

The perfmon database (https://github.com/intel/perfmon) previously
tagged additional memory events such as MEM_INST_RETIRED.STLB_MISS_LOADS
with L1_Hit_Indication, implying PEBS data-source support, which is
incorrect. The database has since been fixed, but
intel_pnc_pebs_event_constraints[] still follows the old definition and
marks those events as data-source capable.

As a result, get_data_src() may decode data-source information for
events that do not provide valid PEBS data-source data and mislead
users.

Remove those non-data-source memory events from the Pather Cove PEBS
constraint table so matching falls back to the regular non-PEBS
constraints, which already provide the same counter constraints.

Also update pnc_latency_data() to decode LOAD/STORE flags explicitly
when setting memory operation direction, for consistency with other
*_latency_data() helpers.

Fixes: d345b6bb88 ("perf/x86/intel: Add core PMU support for DMR")
Signed-off-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Cc: <stable@vger.kernel.org> # v7.0+
Link: https://patch.msgid.link/20260917015234.981153-7-dapeng1.mi@linux.intel.com
2026-09-22 11:31:40 +02:00
Dapeng Mi
7c944595cc perf/x86/intel: Remove incorrect LionCove PEBS data-source constraints
On Lion Cove, PEBS data source is valid only for these events:

- MEM_TRANS_RETIRED.LOAD_LATENCY (0x1cd)
- MEM_TRANS_RETIRED.STORE_SAMPLE (0x2cd)

The perfmon database (https://github.com/intel/perfmon) previously
tagged additional memory events such as MEM_INST_RETIRED.STLB_MISS_LOADS
with L1_Hit_Indication, implying PEBS data-source support, which is
incorrect. The database has since been fixed, but
intel_lnc_pebs_event_constraints[] still follows the old definition and
marks those events as data-source capable.

As a result, get_data_src() may decode data-source information for
events that do not provide valid PEBS data-source data and mislead
users.

Remove those non-data-source memory events from the Lion Cove PEBS
constraint table so matching falls back to the regular non-PEBS
constraints, which already provide the same counter constraints.

Also update lnc_latency_data() to decode LOAD/STORE flags explicitly
when setting memory operation direction, for consistency with other
*_latency_data() helpers.

Fixes: a932aa0e86 ("perf/x86: Add Lunar Lake and Arrow Lake support")
Signed-off-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Cc: <stable@vger.kernel.org>
Link: https://patch.msgid.link/20260917015234.981153-6-dapeng1.mi@linux.intel.com
2026-09-22 11:26:27 +02:00
Dapeng Mi
335b064281 perf/x86/intel: Update arw_latency_data() mem-op direction handling
Align arw_latency_data() with other *_latency_data() helpers by
explicitly decoding LOAD/STORE event flags when setting the sampled
memory operation direction.

This keeps the latency data path behavior consistent across platforms
and avoids relying on implicit direction inference.

Signed-off-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Link: https://patch.msgid.link/20260917015234.981153-5-dapeng1.mi@linux.intel.com
2026-09-22 11:19:35 +02:00
Dapeng Mi
8302c5f475 perf/x86/intel: Fix DKT PEBS load/store direction for latency events, to fix sample classification
Same bug exists on Darkmont as on Gracemont:
intel_dkt_pebs_event_constraints[] applies LAT_CONSTRAINT constraints to
MEM_UOPS_RETIRED.{LOAD,STORE}_LATENCY, but does not set explicit
LOAD/STORE flags for those events.

The PEBS latency path (pebs_latency_data(), via cmt_latency_data) uses
the event flags to determine memory operation direction. Without an
explicit STORE flag, samples from MEM_UOPS_RETIRED.STORE_LATENCY can be
misclassified as LOADs.

Set explicit LOAD/STORE flags in intel_dkt_pebs_event_constraints[] for:

- MEM_UOPS_RETIRED.LOAD_LATENCY
- MEM_UOPS_RETIRED.STORE_LATENCY

This fixes incorrect STORE sample classification. Additionally remove
INTEL_HYBRID_LAT_CONSTRAINT() since no one uses it anymore.

Fixes: 65fd435095 ("perf/x86/intel: Update event constraints for PTL")
Signed-off-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Cc: <stable@vger.kernel.org> # v7.2+
Link: https://patch.msgid.link/20260917015234.981153-4-dapeng1.mi@linux.intel.com
2026-09-22 11:17:59 +02:00
Dapeng Mi
e961d6db42 perf/x86/intel: Fix CMT PEBS load/store direction for latency events, to fix sample classification
The same bug exists on Crestmont as on Gracemont:
intel_cmt_pebs_event_constraints[] applies LAT_CONSTRAINT constraints to
MEM_UOPS_RETIRED.{LOAD,STORE}_LATENCY, but does not set explicit
LOAD/STORE flags for those events.

The PEBS latency path (pebs_latency_data(), via cmt_latency_data) uses
the event flags to determine memory operation direction. Without an
explicit STORE flag, samples from MEM_UOPS_RETIRED.STORE_LATENCY can be
misclassified as LOADs.

Set explicit LOAD/STORE flags in intel_cmt_pebs_event_constraints[] for:

- MEM_UOPS_RETIRED.LOAD_LATENCY
- MEM_UOPS_RETIRED.STORE_LATENCY

This fixes incorrect STORE sample classification.

Fixes: e99fb45436 ("perf/x86/intel: Update event constraints and cache_extra_regsfor MTL")
Signed-off-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Cc: <stable@vger.kernel.org> # v7.2+
Link: https://patch.msgid.link/20260917015234.981153-3-dapeng1.mi@linux.intel.com
2026-09-22 11:17:15 +02:00
Dapeng Mi
89dc568e8c perf/x86/intel: Fix GRT PEBS load/store direction for latency events, to fix sample classification
On Gracemont, intel_grt_pebs_event_constraints[] applies LAT_CONSTRAINT
constraints to MEM_UOPS_RETIRED.{LOAD,STORE}_LATENCY, but does not set
explicit LOAD/STORE flags for those events.

The PEBS latency path (pebs_latency_data(), via __grt_latency_data())
uses the event flags to determine memory operation direction. Without an
explicit STORE flag, samples from MEM_UOPS_RETIRED.STORE_LATENCY can be
misclassified as LOADs.

Set explicit LOAD/STORE flags in intel_grt_pebs_event_constraints[] for:

- MEM_UOPS_RETIRED.LOAD_LATENCY
- MEM_UOPS_RETIRED.STORE_LATENCY

Also update __grt_latency_data() to explicitly interpret these flags when
assigning the sampled memory operation direction.

This fixes incorrect STORE sample classification.

Fixes: 39a41278f0 ("perf/x86/intel: Fix PEBS memory access info encoding for ADL")
Signed-off-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Cc: <stable@vger.kernel.org> # v7.2+
Link: https://patch.msgid.link/20260917015234.981153-2-dapeng1.mi@linux.intel.com
2026-09-22 11:17:00 +02:00
Sean Christopherson
a391618e1d perf/x86/intel: Make @data a mandatory param for intel_guest_get_msrs()
Drop "support" for passing a NULL @data/@kvm_pmu param when getting guest
MSRs.  KVM, the only in-tree user, unconditionally passes a non-NULL
pointer, and carrying code that suggests @data may be NULL is confusing,
e.g. incorrectly implies that there are scenarios where KVM doesn't pass
a PMU context.

Fixes: 8183a538cd ("KVM: x86/pmu: Add IA32_DS_AREA MSR emulation to support guest DS")
Signed-off-by: Sean Christopherson <seanjc@google.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Reviewed-by: Jim Mattson <jmattson@google.com>
Reviewed-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
Link: https://patch.msgid.link/20260921191418.950933-5-seanjc@google.com
2026-09-22 11:09:45 +02:00
Sean Christopherson
d06260e99e perf/x86/intel: Don't pointlessly context switch DS_AREA (and PEBS config) if PEBS is unused
When filling the list of MSRs to be loaded by KVM on VM-Enter and VM-Exit,
load the guest values for DS_AREA and (conditionally) MSR_PEBS_DATA_CFG if
and only if PEBS will be active in the guest, i.e. only if a PEBS record
may be generated while running the guest.  As shown by the !pebs_ept path,
it's perfectly safe to run with the host's DS_AREA, so long as PEBS-enabled
counters are disabled via PERF_GLOBAL_CTRL.

Omitting DS_AREA and MSR_PEBS_DATA_CFG when PEBS is unused saves two MSR
writes per MSR on each VMX transition, i.e. eliminates two/four pointless
MSR writes on each VMX roundtrip when PEBS isn't being used by the guest.

Fixes: c59a1f106f ("KVM: x86/pmu: Add IA32_PEBS_ENABLE MSR emulation for extended PEBS")
Signed-off-by: Sean Christopherson <seanjc@google.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Reviewed-by: Jim Mattson <jmattson@google.com>
Reviewed-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
Link: https://patch.msgid.link/20260921191418.950933-4-seanjc@google.com
2026-09-22 11:09:14 +02:00
Sean Christopherson
4b64dbdc58 perf/x86/intel: Don't write PEBS_ENABLED on host<=>guest xfers if CPU has PEBS isolation, to fix stuck PEBS_ENABLED
When filling the list of MSRs to be loaded by KVM on VM-Enter and VM-Exit,
*never* insert an entry for PEBS_ENABLED if the CPU properly isolates PEBS
events, in which case disabling counters via PERF_GLOBAL_CTRL is sufficient
to prevent unwanted PEBS events in the guest (or host).  Because perf loads
PEBS_ENABLE with the unfiltered cpu_hw_events.pebs_enabled, i.e. with both
host and guest masks, there is no need to load different values for the
guest versus host, perf+KVM can and should simply control which counters
are enabled/disabled via PERF_GLOBAL_CTRL.

Avoiding touching PEBS_ENABLED "fixes" a bug where PEBS_ENABLED can end up
with "stuck" bits if a PEBS event is throttled between generating the list
and actually entering the guest (Intel CPUs can't arbtitrarily block NMIs).
Fixes in quotes because leaving PEBS_ENABLED as-is doesn't fix the
underlying problem of perf (via PMIs) being able to modify state after the
perf<=>KVM handoff.

But not writing PEBS_ENABLED is desirable no matter what, as stating the
obvious, leaving PEBS_ENABLED as-is avoids three MSR writes on every VMX
transition: one each on entry/exit, and one more explicit WRMSR to zero
PEBS_ENABLED before VM-Entry (KVM assumes the only reason PEBS_ENABLED is
in the load list is if the CPU lacks PEBS isolation and thus needs a
quiescent period).

Opportunistically add comments to (better) explain the rules for generating
the set of PEBS counters that will be active while the guest is running,
along with a FIXME for the suspected hack-a-fix where perf disables guest
PEBS if _any_ PEBS event is configured to count in the host (commit
854250329c ("KVM: x86/pmu: Disable guest PEBS temporarily in two rare
situations") doesn't explain the motivation, at all).

Fixes: c59a1f106f ("KVM: x86/pmu: Add IA32_PEBS_ENABLE MSR emulation for extended PEBS")
Signed-off-by: Sean Christopherson <seanjc@google.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Reviewed-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
Link: https://patch.msgid.link/20260921191418.950933-3-seanjc@google.com
2026-09-22 11:07:00 +02:00
Sean Christopherson
cec38d5c09 perf/x86/intel: Ensure KVM guest PEBS path doesn't set unwanted PERF_GLOBAL_CTRL bits
When reinstating PEBS counters into PERF_GLOBAL_CTRL for a KVM guest, mask
the value with perf's desired/original PERF_GLOBAL_CTRL value to ensure
KVM doesn't unintentionally set reserved bits in PERF_GLOBAL_CTRL.  E.g.
if the guest's PEBS_ENABLE value had bit 63, "Enable Precise Store", set,
then using the raw guest PEBS value would propagate bit 63 to the guest's
PERF_GLOBAL_CTRL value (which thankfully would be a failed VM-Entry, not
a VMX Abort).

The only reason this bug isn't reachable is because KVM doesn't support
"Enable Precise Store" (which is probably a KVM bug?), i.e. bit 63 can't
be set in kvm_pmu->pebs_enable and thus not in arr[pebs_enable].guest.  In
other words, this _should_ be a glorified NOP in the current code base.

Fixes: c59a1f106f ("KVM: x86/pmu: Add IA32_PEBS_ENABLE MSR emulation for extended PEBS")
Signed-off-by: Sean Christopherson <seanjc@google.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Reviewed-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
Link: https://patch.msgid.link/20260921191418.950933-2-seanjc@google.com
2026-09-22 11:02:37 +02:00
Linus Torvalds
93f51579e7 Linux 7.3-rc4 2026-09-20 13:48:15 -07:00
Daniel J Blueman
6a5719cc3e net: qrtr: resend HELLO on MHI resume
Since the MHI HELLO exchange was relocated, it is sent only at device
registration. During a suspend-resume cycle, the firmware in WiFi
cards such as WCN7850 indefinitely waits for another HELLO,
triggering:

  ath12k_wifi7_pci 0004:01:00.0: timeout while waiting for restart complete
  ath12k_wifi7_pci 0004:01:00.0: failed to resume core: -110

Fix this by triggering the handshake from resume_early in the MHI
transport.

Validated on Qualcomm X1E-801800 on Lenovo Slim 7x across 10
suspend-resume cycles.

Fixes: 544d85de4d ("net: qrtr: Send HELLO message on endpoint register")
Signed-off-by: Daniel J Blueman <daniel@quora.org>
Reviewed-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Reported-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Link: https://lore.kernel.org/all/6257c447-788d-4362-851e-0d552bcf7c56@oss.qualcomm.com/
Tested-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Reported-by: Vlastimil Babka (SUSE) <vbabka@suse.com>
Link: https://lore.kernel.org/all/ab1491bb-cca5-4145-ac7d-31c966abf7b4@suse.com/
Tested-by: Vlastimil Babka (SUSE) <vbabka@kernel.org>
Reported-by: Takashi Iwai <tiwai@suse.de>
Link: https://lore.kernel.org/all/87a4plsg4w.wl-tiwai@suse.de/
Tested-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Thorsten Leemhuis <linux@leemhuis.info>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
2026-09-20 11:21:10 -07:00
Linus Torvalds
a10a019dd4 dmaengine fixes for v7.3
Bunch of core and driver fixes:
  - Couple of fixes in core around dma_chan_put() for kref underflow,  user
    after free bug and waiting for rcu readers for dma devices
  - mmp sg length and wrong extended DRCMR base for SpacemiT K3
  - hardware buffer descriptor chain fix for xilinx dma
  - sun6i fixes for status behaviour and dma position registers
  - runtime pm reference leak fix for sprd driver
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEE+vs47OPLdNbVcHzyfBQHDyUjg0cFAmqwEtUACgkQfBQHDyUj
 g0dCWQ//ShhhOd2vQQttV+BSHB0xTdT/wENO4mhXcz50chHFh1diBFASMnhejOxG
 dv4ZkePAxV7PLpNqRQrCz2gx89wn5Uxf71PmnLbleuJ5lOuSUMGbFL0MhLzrlfqr
 2Di122aa5Va4Tp3zjNllQ4ihKMfCF02FLCXoZqelVIR/NQFFMeJhEjv/0P2foFvd
 nrf5jzGJuCCbhKiV47H4a8hSb1bG68ct/mV0ZfOT5Koe4B16qPTe7Z9kW5FP0do5
 ++BeHLbEheA/btWUSzvnLMtGHhhUywlAab6cKEkYAcTsuxtapMMRtJmAq9bYyX1O
 qS6hIC9qWMS4xc0+BUsIhwU8cXY6IINy8lPJmwc+/p4V+MJ8QMP+MrfWpWADFy0H
 rTvkIdzU+Lc4fqIr97UbW+pi8Naf2NCiV2NJSYF8JT6ufeG1PymtwbeUlbhkThtZ
 ISVF2/CIieyHr/eDfzNuGrYmdkSfJZgl6Rd6pCHdYQ5vgK6DImtaHfuBBm1OYXVG
 NwA4vkTk6hKu2Sx2JShrSJC2js5q5gdz+9jQuvb9zZZS4I1qOARWjoe/E0wowlir
 EB5bivcNX8VR49x2aYmT7Mg1CJovzs6hC1Aw9aqFIhp+1hQRku+iFOSki8Pwzl23
 EcpkC7liL8S6WCo73Zh7cmT0aBvw3Y6Gpvfozh+Rr7kLZy6cfmw=
 =9a97
 -----END PGP SIGNATURE-----

Merge tag 'dmaengine-fix-7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/vkoul/dmaengine

Pull dmaengine fixes from Vinod Koul:

 - A couple of fixes in core around dma_chan_put() for kref underflow,
   use-after-free and waiting for rcu readers for dma devices

 - mmp sg length and wrong extended DRCMR base for SpacemiT K3

 - hardware buffer descriptor chain fix for xilinx dma

 - sun6i fixes for status behaviour and dma position registers

 - runtime pm reference leak fix for sprd driver

* tag 'dmaengine-fix-7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/vkoul/dmaengine:
  dmaengine: mmp_pdma: fix wrong sg length in mmp_pdma_prep_slave_sg()
  dmaengine: xilinx_dma: Fix hardware buffer descriptor chain after cyclic DMA
  dmaengine: pxa: fix double counting of the hw descriptors
  dmaengine: sun6i: fix undefined behaviour in sun6i_dma_tx_status
  dmaengine: sun6i: fix non-atomic read of DMA position registers
  dmaengine: xilinx_dma: Fix hardware buffer descriptor reuse order
  dmaengine: wait for RCU readers before releasing dma_device
  dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel()
  dmaengine: Fix device kref underflow in dma_chan_put()
  dmaengine: add dma_device_get() helper
  dmaengine: sprd: Fix runtime PM reference leak in probe
  dmaengine: ti: k3-udma-glue: fix NULL dereference in k3_udma_glue_release_rx_chn()
  dmaengine: mmp_pdma: fix wrong extended DRCMR base for SpacemiT K3
2026-09-20 10:45:22 -07:00
Linus Torvalds
60ee24f055 phy fixes for 7.3
Couple of driver fixes
  - Atomic context delay in renesas driver
  - TMDS and PLL rate calculation fixes for mediatek driver
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEE+vs47OPLdNbVcHzyfBQHDyUjg0cFAmqwD8UACgkQfBQHDyUj
 g0dzqBAAuGIVwSpUaEVAHD7TKcLqrmLpF4kuGXN4mGB+i8Hg3ivCH7n6/cKONOeA
 LPkdnl7ABRqNYX935oXtRAUuy0CnoIKJKaxrp0ap1x5QtAcyAKWEW+Ej/rHL9JV7
 JHt/YQFcMhcvKE1lGUYdFA9eF2PQf0h3Xw0BcaB83WqAlsoWh9EnEOjDnfkv4rZi
 PMIW5/lXlpkWEfyptomcNHycGbltnLP323IkIscyS6qX7dIfldoN4pinwNKrIvHM
 CNrg8PPYefjFltVZ7q2u/MB8IeDpYGKNlyGC3Kvspsa04o8Qb0TTMb3aZ+AOn3rJ
 Ccq69UwdnMARx+V9Gc9gY5Jp6Q503SPwFGhRTybT9iyjft9yIGkaEZL1miWOWpZZ
 Fsv3xukBZhDVy1jGt6tsyfUVvRh6eu835jYijp4NHBeo1To7/clcKTTAT5o1/upC
 qWeM/FarR3JB/sAHrHKnA/R3Yh9FTpy5lTD6FhXa95SufJmB12rKbjUYNMNG3EOx
 OgYpeBeuy8ZXtkzPO36LXFv6OomQkxjThMAZ/syn1T8HStWULkhj9MxkrH0BRsB0
 SsxIBkzG7tKlwQizJGDugum9uvxFX0104voNhTkn9DPO2oo4LnxGlsonfqJj7XPD
 TJoF9/IWV+3bQCL9fLU0mBvniQf/jzEaGXoGX+qY1YtXm8I5jTE=
 =xn2f
 -----END PGP SIGNATURE-----

Merge tag 'phy-fixes-7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/phy/linux-phy

Pull phy fixes from Vinod Koul:

 - avoid atomic context delay in renesas driver

 - TMDS and PLL rate calculation fixes for mediatek driver

* tag 'phy-fixes-7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/phy/linux-phy:
  phy: mediatek: phy-mtk-hdmi-mt8195: Fix TMDS clk bit ratio setting
  phy: mediatek: phy-mtk-hdmi-mt8195: Fix PLL calc divisor overflow
  phy: renesas: rcar-gen3-usb2: Avoid long delay in atomic context
2026-09-20 10:43:12 -07:00
Linus Torvalds
0a885f68d0 soundwire fixes for 7.3
- Cadence ensure work completion before clock stop
  - Disable ghost Realtek on Asus GX651AX
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEE+vs47OPLdNbVcHzyfBQHDyUjg0cFAmqwABUACgkQfBQHDyUj
 g0dzrxAAmGpYUaBc5GEnTypOM8NM/UUOOWn+AMUGAb/AekqIChg42a5oVXlaAU5O
 HXqXIIJ5EVddmn++s1XJvcOrMGM4412wwrOKBpCWP9+h5+My1euY9AGDrApRrFCx
 DYmLvxqIDCq2MS8NmaY0RWAAkNI6TXQWsn29TBztt6xRCT7EmiM/iERJpBUhK4Sg
 Oyd9nJkT6Oieln/mfWWxAexBe+W5p9l6StLM/aDnQ7LiVEa6U5vKKfmEbFceQ0z1
 1c3NoJC1hTdsNUytIOKcT46an0sF7GdIe6EB0+yAq+MfS1NHZrQWOG6weVxAqldV
 xS5uUadqDm18xuh8q97+fFueE/rT21JgQFWb9fsuYX3ESNpaO/8dPZtEZFVQOBBJ
 fR+vvKfqm4X3LXe+wXJt/3SQ7KV1Lth/bdPl2O4FYQlfvX1XmaS6lJiBErDyNxY8
 sVCdy+XBcV4MjSciwnYjARpCVAcFo2NRt931TEDgaes2glaQl/v885pTZQEsE/CO
 mCaDcuBFaceuK2x9fGugqQRjCdOXAY8z6UcAUtwlUvy8g008IBssPuCQiVQvFZxs
 cPM4dkbrSPiKz2vuMJepytmk2Fm8wIVWHK7ODtYywYxfkFS8pCQOIi4Wj/EiOF++
 6dOKY0qxiDEr/27cqzm6YcGZ91dH9kDT4nR8W/6gXAdoqclJyCA=
 =mDuH
 -----END PGP SIGNATURE-----

Merge tag 'soundwire-7.3-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/vkoul/soundwire

Pull soundwire fixes from Vinod Koul:

 - Cadence: ensure work completion before clock stop

 - Disable ghost Realtek on Asus GX651AX

* tag 'soundwire-7.3-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/vkoul/soundwire:
  soundwire: cadence_master: wait and cancel cdns->work before clock stop
  soundwire: dmi-quirks: Disable ghost Realtek on Asus GX651AX
2026-09-20 10:22:37 -07:00
Linus Torvalds
156fa7417f x86 fixes:
- Reject the loading of a potentially problematic microcode version
    on Intel Granite Rapids systems (Chang S. Bae)
 
  - On FRED, reconstruct the proper #GP context for rejected INT
    instructions, to fix a signal ABI regression (Matthew Schwartz)
 
  - Add a test for this signal ABI regression the x86
    self-test suite (Matthew Schwartz)
 
  - Don't emit the new and not yet properly supported EGPR instructions
    (%r16-%r31) on CONFIG_X86_NATIVE_CPU=y builds (Chang S. Bae)
 
 Signed-off-by: Ingo Molnar <mingo@kernel.org>
 -----BEGIN PGP SIGNATURE-----
 
 iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqvrhgRHG1pbmdvQGtl
 cm5lbC5vcmcACgkQEnMQ0APhK1inbQ/9G4Q0h9esQ945n0uYRYvVLuj2P8DvE3XN
 9d5IJ5pIYdhJCvlv8yXyv1u3sq59QYNmUgpBMghHJonhqobtnchvBSiznoAMgi8L
 yjRlcaFBPX9qjFQV1W9WJQuUHhW/12QFy9Bo9n1uXEv6pYspYVDwodCaS+rEvkTF
 0wK3TjETv90TravGjFscYTt2VLAiy+cd/FxkUA0sBaMLjhFpUyAPHGJe/vcf8vT3
 rEXkY8EeSjv5F6eKMTDVacrSZu2c9wco1bJIsSFEcxZGFzhDbuCOGiDCkwmB3uuD
 ReKbEUC0KmF8qd4Ubf0dMGpbHT9LDu9Ggex619cHFOHMupPubP+yym7aCpm3v7Sb
 gZe6eV6VrSREJ+oBVKsqMrWXsg1YDj6uJhC/5K3S78xBeRq64kKsmBbC93Zp20TC
 QpSAxKIFqp8C+tfKzpBmcSbcipRUfATJxLjp94QaQDp467jjJCvpDJdc12mV7WR9
 0gMtFjxUaIe8BGX7s2PuWPgZ8+CIH0hZQuttxUU4QWvM2RGU+QrDaMwTeAY7wme4
 xomc0wpXQb5enrjmFu8betlD0xfjgt7k6eW0njezRpWSk3wyHDd5w/6Vfn8pA6Fx
 AQV4UuszXzQmG+W2pdIjLhnjmsjEeWMpmwgzn0rkcqujWHeh8XOSvQIjULFrFtFv
 srSbum6vEfk=
 =MP1H
 -----END PGP SIGNATURE-----

Merge tag 'x86-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip

Pull x86 fixes from Ingo Molnar:

 - Reject the loading of a potentially problematic microcode version
   on Intel Granite Rapids systems (Chang S. Bae)

 - On FRED, reconstruct the proper #GP context for rejected INT
   instructions, to fix a signal ABI regression (Matthew Schwartz)

 - Add a test for this signal ABI regression the x86
   self-test suite (Matthew Schwartz)

 - Don't emit the new and not yet properly supported EGPR instructions
   (%r16-%r31) on CONFIG_X86_NATIVE_CPU=y builds (Chang S. Bae)

* tag 'x86-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  x86/build/64: Prevent native builds from generating EGPR use
  selftests/x86: Check signal state for rejected software interrupts
  x86/fred: Reconstruct the #GP context for rejected INT instructions
  x86/microcode/intel: Reject problematic loading on Granite Rapids systems
2026-09-20 09:49:10 -07:00
Linus Torvalds
0a15ba6b0c Timer race fixes:
- Fix timer signal <-> exec() race, to prevent UAF (Thomas Gleixner)
 
  - Clean up POSIX CPU timers right after de_thread(), to prevent UAF
    (Hyunwoo Kim)
 
  - Fix POSIX CPU timers race between expiry and timer_settime(),
    to prevent UAF (Thomas Gleixner)
 
 Signed-off-by: Ingo Molnar <mingo@kernel.org>
 -----BEGIN PGP SIGNATURE-----
 
 iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqvrMYRHG1pbmdvQGtl
 cm5lbC5vcmcACgkQEnMQ0APhK1gqUQ/+NkruN984bFynF/eZ0/2DFv91AAUP8zgH
 /S3PBlwuSbYFN9JVhngDMwxQkamE56weJbFc+0QuvVT5UVw/vX9BS4QOvvzN+f8D
 FEN3UqD0d1B8OwlPNTw0sFPwJDdPctTinfKOhNjNQe6RLFsNARvGyaKDIDroWTfV
 dxuJ/7Ecs+5m1bmGJnPEC+IH/OnV9BEEl1NdZb+INKpBlui9LCsw4rRIj/8dPK/H
 UNhvXpykKrJCDftbCzAFSNryuzcJgq4kHtMbsqiUL6y50AB69eHGi/Y0xYBAEr1h
 NiDPq2PAMmH1NCCMsTtqbJZMqgCr+7DSZiCFn7bZPwg0V5tV4PFZD484q0sCbiej
 Fwg+arHd0icnceIcWMsBWPUVOSLxZaWdp9a2Tj3Ill06//b5bEDBJBbpecS+so3t
 8W6IvdoCYm7sz50mohnjOdx7biHPu0yhwgj+EoAV3nZKoALQAAcI7+HJzSWpGnJi
 HIO0zylRAZCjk9H3QNWO+LdWgifc8DysAZOWpmbuwGgp8q483IDRDtme/kMt3+D1
 1qTHa1TD/tPo8UmmgyVJQ7e1hCxBkGuuBBu5Y3/qkUEOQM6B/H2Ji7stxsLpW3JL
 HLzC3kL2SBBVBO2ljqiH5IhVAL10Qm5vPxaCOjExdBt1vjMxN1DowZqD4rT/tw58
 ArpD4zmr8VQ=
 =KhWJ
 -----END PGP SIGNATURE-----

Merge tag 'timers-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip

Pull timer race fixes from Ingo Molnar:

 - Fix timer signal <-> exec() race, to prevent UAF (Thomas Gleixner)

 - Clean up POSIX CPU timers right after de_thread(), to prevent UAF
   (Hyunwoo Kim)

 - Fix POSIX CPU timers race between expiry and timer_settime(),
   to prevent UAF (Thomas Gleixner)

* tag 'timers-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list
  exec: Cleanup POSIX timers right after de_thread()
  signal: Prevent exec() race
2026-09-20 09:41:00 -07:00
Linus Torvalds
fecbe78ac0 Scheduler fix:
- Avoid false positive migration warning for proxy donors
    (Andrea Righi)
 
 Signed-off-by: Ingo Molnar <mingo@kernel.org>
 -----BEGIN PGP SIGNATURE-----
 
 iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqvqssRHG1pbmdvQGtl
 cm5lbC5vcmcACgkQEnMQ0APhK1gPzBAAhE9hcpkBV6vNW9xzBDKdGPxRjch2vcfu
 lQbx7da1yC2rHU7RDlcdfEgkhAqTRwEAXKz26zth3sDHLk43tusuNtqG3swELhNW
 YAGbHjdn87snQlmP8AOK4EaT3uE5NjWqRSIJWMK+AhWSwqO/zzK91T6yZyQY0fM4
 3Edp8CFo3IeyOzCR96vsob2x1fFQhuR//5fWul3uuB0EZ8VA5FhH3ene6VCm7P/1
 dauxX0rMTb2730qNXA8cHROZq+bwhqTZOUaoOZ33WxnRPkvY9mV/hZsN8JnJuzBE
 ogzyyorcl8dFH8qOapos9Cp3tQj9GkTX7mXWDbuUflt/8uOXtQMf75kFGBVI5NUw
 2xNfgubTYGo6Qc1C+wyOhGYJ6T5Al+083pV/vPc4y7Z1i7RgZ94QypMuZuaR/RqS
 z+RQcdNQlXiRIAIILGJqq1xdbaCJvbVx3tiFZkhPse6ioOF6UNGbQiNExAq3v5BU
 ocvhBuf9p/uvRmfs+ZtQNqAAjZUL7tQPvdFAsjxKjuI2Z5YGPROy1L9NdYKfzryM
 yWOEkV2mdn97CwzDS+auC0HmPkGqf8we2VI5Ub4R35UPqDcV6vc5BAnwzAbuxAmc
 K7mQOMDEaRkbVQ0MoSMdidIXLL0AcN+BROBUtHv8kqJur6nADE3K3HZNdhr2ViLN
 eisNI6m8pLk=
 =BEte
 -----END PGP SIGNATURE-----

Merge tag 'sched-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip

Pull scheduler fix from Ingo Molnar:

 - Avoid false positive migration warning for proxy donors
   (Andrea Righi)

* tag 'sched-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  sched/core: Avoid false migration warning for proxy donors
2026-09-20 09:37:27 -07:00
Linus Torvalds
abb91eed94 Perf events fixes:
- Fix crash when probing CS CALL instructions (Jinke Han)
 
  - Fix NULL pointer crash during module unload (Vinay Belgaumkar)
 
 Signed-off-by: Ingo Molnar <mingo@kernel.org>
 -----BEGIN PGP SIGNATURE-----
 
 iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqvqiURHG1pbmdvQGtl
 cm5lbC5vcmcACgkQEnMQ0APhK1hiohAAjcvOY7M998pX1tmo1Egw9kAuI0odtNOX
 weQ4Wq7K3X+tg+q1wVUmE/N/y/WLYWNatjwvjc8TClYdQEiaqBMH4TSLAuY3TOxa
 TxwdTC20uSN4EPZ0iRhKzm3biPzzzRq4M9hhV+WfGcK7ieXRn4Q7d9S3DDe5oEfG
 lI4l/RefIBiINVPC7dNM7xpS/7XBEPnzNeshOMwp6ZsPziZJizgC8C7RhQFAPszo
 Ho36KKFQqMNouCSybQl1GxLyPw+oGtneWESHXrF6Mhp+bcx40fMtJxKNyVLsVWuM
 wo0Ry843pCbDofOIqg7m0AufWUhz7B4MttTXXrU2/BYMHEbxlgms1AO7lnSGzPmn
 vP0JHZnT3y34P5uvGaVho7t9QKKbuY47cKNmsiiLuXiBQQuKnvDmDln1Mu1KS3fg
 a1LI8kv043iLqAjsIWMVtKlRGUX36f4NXUWrxvO/tmup3ocJhG1oYmEe/RaFddVX
 5qRbHn7Z1w8jAWldODYSrXkpMRgMtClQuqHdjxZQt5DPZSORzoFxTvSfJLdUUtVx
 CUiT34zcLPHfvGD+ctHe5kVesgDHCxp/z1tKrJBunB+XZVl6rKHycfiGjaUXQRcR
 NUp6iFlfay8b79EkMsLC8p6uAmzX2q+gEwNVy8eevBSXdsYqcY5islj3ob7sBHsH
 vk4gDJikpE0=
 =onkS
 -----END PGP SIGNATURE-----

Merge tag 'perf-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip

Pull perf events fixes from Ingo Molnar:

 - Fix crash when probing CS CALL instructions (Jinke Han)

 - Fix NULL pointer crash during module unload (Vinay Belgaumkar)

* tag 'perf-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  perf: Fix null pointer access in is_include_guest_event()
  x86/kprobes: Fix crash when probing CS CALL instructions
2026-09-20 09:26:22 -07:00
Linus Torvalds
2f7ff5f547 - Fix objtool build error on systems where libopcodes is
present, but development headers (binutils-dev) are not
    (Ulises Mendez Martinez)
 
 Signed-off-by: Ingo Molnar <mingo@kernel.org>
 -----BEGIN PGP SIGNATURE-----
 
 iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqvqSARHG1pbmdvQGtl
 cm5lbC5vcmcACgkQEnMQ0APhK1iBWQ/9HTpCn/GSapwpTLUAXh/d/7VWSTV/xMRS
 b/cqx+jFDFeZDU55VbX+bMgKQyW0jNSUPjvVp0ZfjUf0W0LOXL/EnAemZ8VqBqAj
 IMIyd+0MjCeUOCVanRiITre65BPuF+g3EbxWypFDiLmb4ziA5YksPknTWYrIVbDP
 IMks30B8kJfzC5Qh0jjpSRDSypTvuEAKppbyf3pPmHfKLSbwtKOQzeoFUlLtWfs4
 diBm9BVIjosmIr5dxMyixa8+5BTsPs4ojwa4US3H+RzxdXe+2v31Ac2nK/zvCRst
 Fr8gefaLhVrnfkJeXU0Xn/rDMYOzayb1JW4jWjJ40I6U20ptdrMQ3aSJqjNrrwkQ
 2vikInQX3NKV2ASiTppLDhsq7MFt4AeRYFwj8xmErm5uhoSEKAEPG1QZWS98QkAo
 CXQL3PITL5kS0q5wGkkYXNi3TbpKvWy8kPoIRMHoKFUkBHJRssSg8tb17D5Jg0yd
 QvsjocvMSf865swQ6p1yj+7+Zd+nGM2JGkIcp9OBPTAzZej4bXmpPwMKDeRv6pgD
 GNgKJ2oEhvXWCgokxK9ezgk8rYsH/1Vo/+JyBf4/tcKL9ixfnBTgLNZ80J8VFDn2
 5axUt4EO+FZKzLB6UaENhTo813PhGOM/rChKmJ1L4GWi0RywoX+seH4b+FtQk87f
 VPvApwwiDHQ=
 =vTNY
 -----END PGP SIGNATURE-----

Merge tag 'objtool-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip

Pull objtool fix from Ingo Molnar:

 - Fix objtool build error on systems where libopcodes is
   present, but development headers (binutils-dev) are not
   (Ulises Mendez Martinez)

* tag 'objtool-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  objtool: Validate disassembler headers in libopcodes probe
2026-09-20 08:41:19 -07:00
Linus Torvalds
bdab18633a - Also allocate a default private futex hash on vfork()
as well, to avoid races with (private) futex waiters
    (Peter Zijlstra)
 
 Signed-off-by: Ingo Molnar <mingo@kernel.org>
 -----BEGIN PGP SIGNATURE-----
 
 iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqvp20RHG1pbmdvQGtl
 cm5lbC5vcmcACgkQEnMQ0APhK1giDg//VpFKPXgma7fW5E+T0kjWHWD7FS1vYyJ4
 nMunKME8PAV0A4S7946iUAWHjViVfksTmfvcXepSFCKZKLf55g8s2aZ1VoigMtYX
 bQxNrnOidebSg9npLs9NV4sjvvNy+k03gcNN+OK+ZRfYCVRqbLgfCm5RJbaId5y4
 +EuizVmtJuNav6HwAEIbU4LXGIdwSL9Pn8Zitkz/H7g0ZEkv+VA4h6NttvKDNfV7
 OltcUFejtU7Z1lItfH+PP9pMcjPA6OPI2h7LLmUcZGUhhQQtW2Gb1fffz45PiH8T
 FB7PdFt22TLG5c6hLB7zbrFFillWKn3l3Ihi/IxqVmMulhk6RVTPdCVJcj1cGZxF
 9NXZ+L81poKwEETaIk52v5jm9qNF+kHbXJuCjPbmEdPxtxfv+Ma4zXom/xKkuXpx
 qf01GXxelUPdCAl0cT0pzRvbEfHNIOsE2Id7f+59jB+L8ZbYEch04cIVRqCQcOgi
 9B+lXj36fkFBV6wmuP5SWShWsgMsMpgSzOz5mUdWjY3Ocn9QuzDxPkk50Cm7uL1i
 q/HpGv3T849HFnCH7+mi8wSiX33La+N297+AkGO7U7h5QFldPokvbAijwfmF+1Nw
 CebsAfsgJsN1GZacDTH0jmRxh4I0Wa32yiCAldeGS2w9EMEAFbA87iwsOgjwHiQl
 JOv/s06Pg7o=
 =qQHe
 -----END PGP SIGNATURE-----

Merge tag 'locking-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip

Pull futex fix from Ingo Molnar:

 - Also allocate a default private futex hash on vfork() as well, to
   avoid races with (private) futex waiters (Peter Zijlstra)

* tag 'locking-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  futex: Also allocate private hash on vfork()
2026-09-20 08:15:23 -07:00
Linus Torvalds
5bf70485f9 spi: Fixes for v7.3
A few driver specific fixes, none of them particularly severe or
 unusual.
 -----BEGIN PGP SIGNATURE-----
 
 iQEzBAABCgAdFiEEreZoqmdXGLWf4p/qJNaLcl1Uh9AFAmqvmVMACgkQJNaLcl1U
 h9AOdwf/aRa54oHd6iLCPXNAbZLDie0pnJa/Q/5sjpJoVY9ofKc2XM9djmy60YdF
 /VGIphT8gr6at6fLZHEBbLanu2MQC2vxW9zDh5n+Xe8HUS3sdrwtBJPSv74Mcfrf
 OIv6nFrVsbo1IMF7x4ncYOhOBGKyOSqhsVdt+k6jl1wuTDJBHyFs7sdL1DGRCRu/
 ba4n2W+kSxVeFx3ACFyDJ8l8vLqtyotFKkpmslrPmT0yHFwOr8SOMbyQ5MPxITpx
 gqgLikR3OW5alOLxy1U2nWCdjNsc8UWBhx1sCnByYrUO3VmRIEx4j1l2wSVX0J7E
 Ck7/pSpg1NGkxVYSLCTBufqq8kgPTQ==
 =iy0J
 -----END PGP SIGNATURE-----

Merge tag 'spi-fix-v7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/spi

Pull spi fixes from Mark Brown:
 "A few driver specific fixes, none of them particularly severe or
  unusual"

* tag 'spi-fix-v7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/spi:
  spi: fsl-qspi: Reprogram the clock rate when the operation frequency changes
  spi: spi-zynqmp-gqspi: stop the controller on shutdown
  spi: virtio: Use the per-transfer bits per word
  spi: spi-qpic-snand: avoid writing QPIC_EBI2_ECC_BUF_CFG register
2026-09-20 08:08:54 -07:00
Linus Torvalds
aa211c7a58 i2c-fixes for v7.3-rc4
Fixes mainly for cleanup and error handling, a good part of them
 around DMA resource management.
 
 - at91: ensure DMA channels are released on all exit paths
 
 - imx: fix autosuspend cleanup on remove
 
 - qcom-cci: fix device node reference leak
 
 - atr, imx, qcom-geni: set adapter slot to NULL on registration
   failure
 -----BEGIN PGP SIGNATURE-----
 
 iHUEABYKAB0WIQScDfrjQa34uOld1VLaeAVmJtMtbgUCaq+VLAAKCRDaeAVmJtMt
 bqmsAP9umA0ew1WQkQGTlTJLfbQdhwy8IDS7tMRAlgL7vsUxOQEApvFqr6Xtq2j7
 HiSP35cHybZlA7P2T70A+MVniCJDRQ4=
 =Sn1c
 -----END PGP SIGNATURE-----

Merge tag 'i2c-fixes-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/andi.shyti/linux

Pull i2c fixes from Andi Shyti:
 "Fixes mainly for cleanup and error handling, a good part of them
  around DMA resource management:

   - at91: ensure DMA channels are released on all exit paths

   - imx: fix autosuspend cleanup on remove

   - qcom-cci: fix device node reference leak

   - atr, imx, qcom-geni: set adapter slot to NULL on registration
     failure"

* tag 'i2c-fixes-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/andi.shyti/linux:
  i2c: qcom-cci: fix device_node refcount leak in cci_probe()/cci_remove()
  i2c: qcom-geni: release DMA channels on probe error
  i2c: imx: release DMA channels on probe error
  i2c: at91: release DMA channels on remove and probe error
  i2c: atr: fix dangling adapter pointer on add failure
  i2c: imx: disable autosuspend on remove
2026-09-20 07:57:47 -07:00
Linus Torvalds
b12dd0fa48 Input updates for v7.3-rc3
- Fixes for evdev and input compat handling to zero-initialize on-stack
   absinfo and force-feedback effect structures before partial or compat
   copies from userspace, preventing kernel stack memory disclosure
 
 - Fixes for the Synaptics RMI4 driver to prevent an out-of-bounds read
   when writing multi-chunk blocks over SMBus and to avoid a NULL pointer
   dereference during suspend/resume when the RMI device is unbound
 
 - Fixes for the soc_button_array driver to propagate -EPROBE_DEFER on
   non-Bay Trail/Cherry Trail platforms (fixing broken power and volume
   buttons on the Microsoft Surface Pro 11) and to validate the ACPI
   package element count before dereferencing
 
 - A fix for the adp5588-keys driver to cache the initial GPIO hardware
   state before registering the gpiochip so pre-configured pin states are
   not clobbered by GPIO hogs during registration
 
 - A fix for the cyttsp5 touchscreen driver to clamp the device-supplied
   HID report size before copying into the response buffer, preventing a
   buffer overflow
 
 - A fix for the HP SDC serio driver to use timer_shutdown_sync() on
   module exit so the periodic kicker timer cannot rearm itself during
   teardown
 
 - A fix for the eeti_ts touchscreen driver to export its OF module alias
   so the module autoloads on Device Tree platforms
 
 - Updates to the xpad joystick driver adding support for the Victrix Pro
   BFG controller and Azeron devices, and fixing the device type
   classification for the PDP Marvel Xbox 360 controller
 
 - Quirks for the i8042 and atkbd drivers to keep the built-in keyboards
   functional on the Acer Aspire Go 15 AG15-42P and Xiaomi Redmi Book Pro
   16 2026
 
 - A quirk for the Synaptics PS/2 touchpad driver disabling SMBus
   InterTouch on the Lenovo ThinkPad T440p (board ID 2722) so the
   touchpad and TrackPoint respond immediately at boot
 
 - Other minor updates and documentation fixes, including reading the
   "ti,poll-period" property as u32 in tsc2007, adding the mt6572
   compatible to the MediaTek keypad Device Tree binding, fixing an
   attribute name typo in the trackpoint sysfs ABI documentation, and
   documenting that no new LED codes should be added to the input
   subsystem.
 -----BEGIN PGP SIGNATURE-----
 
 iHUEABYKAB0WIQST2eWILY88ieB2DOtAj56VGEWXnAUCaq9j+gAKCRBAj56VGEWX
 nJ5KAQDnTOivIghgIGnlKTIYLSV4cJ0fWJh7J1/ubx9soK+9RwD/bDUdyryAaSTr
 x95U7/fEvq/lXBFyK2LXyahuTC6vNQY=
 =Vsfi
 -----END PGP SIGNATURE-----

Merge tag 'input-for-v7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/dtor/input

Pull input fixes from Dmitry Torokhov:

 - Fixes for evdev and input compat handling to zero-initialize on-stack
   absinfo and force-feedback effect structures before partial or compat
   copies from userspace, preventing kernel stack memory disclosure

 - Fixes for the Synaptics RMI4 driver to prevent an out-of-bounds read
   when writing multi-chunk blocks over SMBus and to avoid a NULL
   pointer dereference during suspend/resume when the RMI device is
   unbound

 - Fixes for the soc_button_array driver to propagate -EPROBE_DEFER on
   non-Bay Trail/Cherry Trail platforms (fixing broken power and volume
   buttons on the Microsoft Surface Pro 11) and to validate the ACPI
   package element count before dereferencing

 - A fix for the adp5588-keys driver to cache the initial GPIO hardware
   state before registering the gpiochip so pre-configured pin states
   are not clobbered by GPIO hogs during registration

 - A fix for the cyttsp5 touchscreen driver to clamp the device-supplied
   HID report size before copying into the response buffer, preventing a
   buffer overflow

 - A fix for the HP SDC serio driver to use timer_shutdown_sync() on
   module exit so the periodic kicker timer cannot rearm itself during
   teardown

 - A fix for the eeti_ts touchscreen driver to export its OF module
   alias so the module autoloads on Device Tree platforms

 - Updates to the xpad joystick driver adding support for the Victrix
   Pro BFG controller and Azeron devices, and fixing the device type
   classification for the PDP Marvel Xbox 360 controller

 - Quirks for the i8042 and atkbd drivers to keep the built-in keyboards
   functional on the Acer Aspire Go 15 AG15-42P and Xiaomi Redmi Book
   Pro 16 2026

 - A quirk for the Synaptics PS/2 touchpad driver disabling SMBus
   InterTouch on the Lenovo ThinkPad T440p (board ID 2722) so the
   touchpad and TrackPoint respond immediately at boot

 - Other minor updates and documentation fixes, including reading the
   "ti,poll-period" property as u32 in tsc2007, adding the mt6572
   compatible to the MediaTek keypad Device Tree binding, fixing an
   attribute name typo in the trackpoint sysfs ABI documentation, and
   documenting that no new LED codes should be added to the input
   subsystem

* tag 'input-for-v7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/dtor/input:
  Input: hp_sdc - shut down kicker timer on module exit
  Input: xpad - add support for Victrix Pro BFG Controller
  Input: tsc2007 - read "ti,poll-period" as u32
  Input: trackpoint - fix the inertia attribute name in the ABI document
  Input: eeti_ts - publish the OF module alias
  Input: xpad - add support for Azeron devices
  Input: xpad - fix PDP Marvel Xbox 360 controller
  Input: document that no new LED codes should be added
  Input: soc_button_array - check btns_desc->package.count
  Input: soc_button_array - fix MS Surface Pro 11 probe failure
  Input: i8042 - add quirk for Acer Aspire Go 15 AG15-42P
  Input: synaptics - disable InterTouch on ThinkPad T440p (board id 2722)
  Input: cyttsp5 - clamp the HID report size before memcpy
  Input: zero ff_effect before compat copy in input_ff_effect_from_user
  Input: evdev - zero absinfo before partial copy in EVIOCSABS
  Input: synaptics-rmi4 - fix GPF in suspend and resume when unbound
  Input: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block()
  Input: atkbd - skip deactivate for Xiaomi Redmi Book Pro 16 2026
  dt-bindings: input: mediatek,mt6779-keypad: add mt6572
  Input: adp5588-keys - cache GPIO state before registering the gpiochip
2026-09-20 07:02:34 -07:00
Linus Torvalds
4a910e594a selinux/stable-7.3 PR 20260919
-----BEGIN PGP SIGNATURE-----
 
 iQJIBAABCgAyFiEES0KozwfymdVUl37v6iDy2pc3iXMFAmqvPSwUHHBhdWxAcGF1
 bC1tb29yZS5jb20ACgkQ6iDy2pc3iXP1rBAAkK6sP+lzXynr/abxWio9UCvlN6NF
 jqMXtKeUeLNg/lJakXKhja/FGaK9w+Rm+zlXQQvVE7YAO5Db758JzCXMTHlK6etD
 T5d+GVdZj/oVcAvfGhov0guNHZqcfKTGWOXKtGV8RQWYL+f6IC1IIHnz9wNeWIfY
 emkfOTgAJpCkX9nXS5xTdQNUiPkUV80LFGqxXCMhxiumvyzqOhUteytfNh3UXXcs
 ldOWRBstUumudBe/MJR09REtQve3emHc7bZUAxSKwXxzdOPTf7UEy4Y7QXCN3Opn
 Dn6Dsrt6lnpIZyzUK/eOnZvQ639gDqTMW2XTmin0JIf2KGG/PhqnvOT07hOPl+X5
 wqXh2wCFn+tXVi5t+S2myMUVZK56GwfRH9kMCo6ca1Ui36iYYEeoJYt7z5tsE6P5
 YBdvKKJ/MPR1/uEwP/TB3UDK0o4OBjyujc6/Ka5iBoIHXKpx7MBLOo/Q0h/Wu2A0
 7HYvG/4lYdWp3p5iR8cdZ+ZgdTQDWi6t5BD3JWOfWi1gHCeGgZCHTCZ9mdSoFS18
 9GpXFXTR4yM5pfwxQEAu6jFH0esSB92HJBd/yS7sU8EIUQ+0XmOge+gVPifMrhWj
 yOHCR7hlAYE5ds51w3ZVOYI0slkYImqCHEdlCz1DiKzyLmQQmfJvshOIvBCl7uwn
 LRHu6Mo0cEBMAvc=
 =kiQE
 -----END PGP SIGNATURE-----

Merge tag 'selinux-pr-20260919' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux

Pull selinux fixes from Paul Moore:

 - Ensure that the cached SELinux access decisions are correct

 - Fix the SELinux overlayfs code to properly track the top-level/user
   information on multiple stacked overlayfs filesystems

 - Fix the SELinux overlayfs code to properly enforce mprotect() access
   control policy on all of the different layers in multiple stacked
   overlayfs filesystems

* tag 'selinux-pr-20260919' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux:
  selinux: recheck intermediate backing files on mprotect()
  selinux: preserve user SID across nested backing files
  selinux: always fill AVC decision in avc_has_perm_noaudit()
2026-09-20 06:50:31 -07:00
Liu Zhenlong
7362a1553e
i2c: qcom-cci: fix device_node refcount leak in cci_probe()/cci_remove()
The of_node_put() matching of_node_get() runs after i2c_del_adapter(),
whose trailing memset() zeroes adap->dev and thus adap->dev.of_node,
making the put a no-op and leaking the node on every adapter removal
and error cleanup.

Use a devm action: the pointer is captured at registration, out of
reach of that memset(), and devres runs the put once on probe failure
and detach, replacing the three manual of_node_put() calls.  The
setup loop uses the scoped iterator form so the child node is released
automatically if devm_add_action_or_reset() fails mid-loop.

Suggested-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Fixes: 02a4a69667 ("i2c: qcom-cci: don't put a device tree node before i2c_add_adapter()")
Assisted-by: Claude:claude-opus-5
Signed-off-by: Liu Zhenlong <dragonliu2018@gmail.com>
Cc: <stable@vger.kernel.org> # v5.17+
Reviewed-by: Vladimir Zapolskiy <vladimir.zapolskiy@linaro.org>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://patch.msgid.link/20260818175750.4205-1-dragonliu2018@gmail.com
2026-09-20 09:40:29 +02:00
Shengzhuo Wei
268aacb2e2
i2c: qcom-geni: release DMA channels on probe error
geni_i2c_init() grabs exclusive GPI tx/rx DMA channels when the serial
engine runs in GPI mode. If i2c_add_adapter() subsequently fails, probe
returns without releasing the channels, because the remove callback is
not invoked after a failed probe.

The adapter-registration failure path used to release the channels via
its err_dma label; that release was dropped when the probe tail was
restructured into geni_i2c_init().

Release the channels on the adapter-registration failure path, mirroring
geni_i2c_remove().

Fixes: d8d3bb127a ("i2c: qcom-geni: Isolate serial engine setup")
Assisted-by: GLM:5.3
Signed-off-by: Shengzhuo Wei <me@cherr.cc>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Mukesh Kumar Savaliya <mukesh.savaliya@oss.qualcomm.com>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://patch.msgid.link/20260827-i2c-dma-channel-leak-v1-3-271d4adc03a0@cherr.cc
2026-09-20 09:40:29 +02:00
Shengzhuo Wei
e9f03b9625
i2c: imx: release DMA channels on probe error
i2c_imx_dma_request() acquires exclusive tx/rx DMA channels and is
optional: on errors other than -EPROBE_DEFER the driver falls back to
PIO mode and probe continues. If i2c_add_numbered_adapter() then fails,
probe returns through clk_notifier_unregister without releasing the
channels, because the remove callback is not invoked after a failed
probe.

Release the channels on the probe error path, mirroring
i2c_imx_remove().

Fixes: ce1a78840f ("i2c: imx: add DMA support for freescale i2c driver")
Assisted-by: GLM:5.3
Signed-off-by: Shengzhuo Wei <me@cherr.cc>
Cc: <stable@vger.kernel.org> # v3.19+
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://patch.msgid.link/20260827-i2c-dma-channel-leak-v1-2-271d4adc03a0@cherr.cc
2026-09-20 09:40:28 +02:00
Shengzhuo Wei
f7eeb1af85
i2c: at91: release DMA channels on remove and probe error
at91_twi_configure_dma() requests exclusive tx/rx DMA channels, but
nothing ever releases them on driver detach, and the probe error path
after the channels are acquired (i2c_add_numbered_adapter() failure)
returns without releasing them either, because the remove callback is
not invoked after a failed probe.

Move the release into a helper, call it from the existing
configure-failure path, the adapter-registration failure path, and
at91_twi_remove().

Fixes: 60937b2cdb ("i2c: at91: add dma support")
Assisted-by: GLM:5.3
Signed-off-by: Shengzhuo Wei <me@cherr.cc>
Cc: <stable@vger.kernel.org> # v3.8+
Acked-by: Mukesh Kumar Savaliya <mukesh.savaliya@oss.qualcomm.com>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://patch.msgid.link/20260827-i2c-dma-channel-leak-v1-1-271d4adc03a0@cherr.cc
2026-09-20 09:40:28 +02:00
Thomas Gleixner
c21eaa72f0 posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list
Kijo analyzed another race in the POSIX CPU timer code:

Commit bf635681c9 converted cpu_timer::firing from a tristate value to a
boolean. This lost the distinction between "not owned by the firing list"
and "still owned, but delivery was canceled". The resulting race is:

    expiry handler              timer_settime()        timer_delete()
    --------------              ---------------        --------------
    collect timer onto
    private firing list
    firing = true
                                observes firing = true
                                firing = false
                                return TIMER_RETRY
                                wait for handler
                                                       observes firing = false
                                                       finish deletion
                                                       unhash and free timer
    resume list traversal
    read freed elist.next
    -> UAF

The firing bit is clearly the wrong indicator since that commit.

Check whether the timer is queued on the expiry list or not instead. If it
is queued clear the firing bit to prevent signal delivery as before and
return TIMER_RETRY so the caller unlocks the timer which allows the expiry
code to make progress and remove it from the list.

Fixes: bf635681c9 ("posix-cpu-timers: Cleanup the firing logic")
Reported-by: Kijo Park <red993688@gmail.com>
Debugged-by: Kijo Park <red993688@gmail.com>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Tested-by: Kijo Park <red993688@gmail.com>
Reviewed-by: Frederic Weisbecker <frederic@kernel.org>
Cc: stable@vger.kernel.org
2026-09-19 22:56:22 +02:00
Linus Torvalds
518e5b794c for-7.3-rc3-tag
-----BEGIN PGP SIGNATURE-----
 
 iQJPBAABCgA5FiEE8rQSAMVO+zA4DBdWxWXV+ddtWDsFAmqu3wQbFIAAAAAABAAO
 bWFudTIsMi41KzEuMTIsMiwyAAoJEMVl1fnXbVg7Y5kQAJ1ANaQWod+AUKhgbtA6
 IcEFH8AAVrrTqqN0SxOl/tqHL6Xt/5mKlQcTpYPxeccUkp72M9BeGik4Gp7OwN1D
 vkVTgrmhHT4r+4ae4GJP0yCtNJBa0fRXjsMFbNYTKGWcz9yOsW1OkBsq8VtRo7ym
 CSVBc57buUi0mzbnLNDh69G/YA7NCTyaxXKjPARNYy+cy0LMIDmgZCByhgePQvzB
 aqJUakRKpaeXEQIf0nT/70XcGhXNtfK1GOnLZM1ySFqLufMzdTsEzFsT8dVugqU1
 wr1HMaMq1iNKwE4sJgNWS84wRT1zxZopKIOsTufFu98Zb2C0kvUSjWeJSqtFM88G
 ggj/jmaoRhCU1cXE1jvZWy4Fe5zQH8deSQZ7zUB4ZzqCaDRwOEAj4IpuQQ9Ok91E
 J/07SCvKPk/QUPbA2e5lwRL3aximsD1LfRxWIOZ+xg/HVX+vYfHmy5gzkl/hhfrm
 RHkHLz8iXNHV7qhIVzZ/GYvTxR6U6nbLVUbkl5n/8eFePM7YHnoWtvMHT71qWwrh
 mPx8uTK+4BI2+rAHTKqxnwEQ27OHj5odlGKTlKiaMrQR9eqnnhJLTMPDJMzqQ7TI
 ZiibxG8UqSTsNbvOXXtd7MykSRpSb/VWyJImKuw30kx3f7f2yd1aCUyU4T7o5N/3
 FRI+2AbkoSeype3Rw+VcEPoi
 =WxSA
 -----END PGP SIGNATURE-----

Merge tag 'for-7.3-rc3-tag' of git://git.kernel.org/pub/scm/linux/kernel/git/kdave/linux

Pull btrfs fixes from David Sterba:
 "Among the regular fixes, there are two that were reported recently and
  have user impact:

   - filesystem id is now stable again on the default and common case
     (it broke openconnect key derivation, while this is not secure,
     it's still in use), the intention was to change id for the
     temp_fsid use case

   - fix detection of /dev/root and rename it after device scan, this
     broke booting of initramdisk-less system with grub2 as the probe
     needs the real device

  Regular fixes:

   - don't store compressed inline extent if the size is larger than
     uncompressed

   - in zoned mode, handle activation of zones for all supported block
     group profiles in case there are still free ones left

   - check space for a chunk item when reading sys array from superblock

   - allow using space reserves when removing verity items fails

   - fix error handling after free space tree rebuild fails

   - abort transaction if reflink or hole punching fails and it's not
     possible to update the inode

   - properly protect block group iteration during device replace start

   - error message fixups"

* tag 'for-7.3-rc3-tag' of git://git.kernel.org/pub/scm/linux/kernel/git/kdave/linux:
  btrfs: derive f_fsid with dev_t only when temp_fsid is active
  btrfs: add "/dev/root" exception for device path update
  btrfs: check if there is space for chunk item when validating sys chunk array
  btrfs: abort transaction on failure to update inode for hole punching and reflinking
  btrfs: clear free space tree creation state on rebuild failure
  btrfs: handle lack of space when cleaning up verity items
  btrfs: fix creation of compressed inline extents that don't save space
  btrfs: tree-checker: fix error message regarding free space extent items
  btrfs: tree-checker: print dev extent offset in error message
  btrfs: take commit root semaphore when iterating in mark_block_group_to_copy()
  btrfs: zoned: handle RAID profiles in btrfs_can_activate_zone()
2026-09-19 13:48:20 -07:00
Chang S. Bae
63edf5a009 x86/build/64: Prevent native builds from generating EGPR use
Omar reports that CONFIG_X86_NATIVE_CPU=y allows builds to opportunistically
emit instructions using %r16-%r31 (EGPRs) when the build host supports APX
since the commit:

  ea1dcca1de ("x86/kbuild/64: Add the CONFIG_X86_NATIVE_CPU option to locally optimize the kernel with '-march=native'")

But the kernel is not yet prepared to use new registers internally. For
example, there is no context-switch support for general in-kernel use.

Explicitly disable EGPR use when building with -march=native.

For C, since GCC 14 and Clang 18, both compilers support suppressing EGPR
use with -mno-apx-features=egpr, whose availability can be detected via
cc-option.

For Rust, pass features=-apxf through the generated JSON to avoid
unstable-feature warnings, see

  https://github.com/rust-lang/rust/issues/139284

Note Rust only accepts the option to disable APX instructions entirely or not.

Support for this gating also depends on the Rust/LLVM combination. Rust
1.88 introduced the `apxf` feature option, but versions prior to 1.93 may
emit an `apxf` attribute to the backend that only LLVM 23 or later can
interpret. Restrict native Rust builds accordingly.

Fixes: ea1dcca1de ("x86/kbuild/64: Add the CONFIG_X86_NATIVE_CPU option to locally optimize the kernel with '-march=native'")
Reported-by: Omar Avelar <omar.avelar@intel.com>
Signed-off-by: Chang S. Bae <chang.seok.bae@intel.com>
Signed-off-by: Borislav Petkov (AMD) <bp@alien8.de>
Reviewed-by: Nathan Chancellor <nathan@kernel.org>
Acked-by: Miguel Ojeda <ojeda@kernel.org>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260916230003.1144622-1-chang.seok.bae@intel.com
2026-09-18 21:43:38 -07:00
Linus Torvalds
40288c9206 drm fixes for 7.3-rc4
core:
 - fix vblank pending event leak
 
 ttm:
 - swapout fixes
 
 dma-buf:
 - scattergather fixes
 - enable dma-buf debug on debug kernels
 
 dma-fence:
 - fix signaling bit checks
 
 sched:
 - fix virtual runtime race
 
 msm:
 - DT:
   - Corrected indentation
 - Core:
   - Marked fbdev as system memory
 - GPU:
   - Fixed autosuspend cleanup on teardown
   - a750: fix timestamps
   - Increase GMU fw init timeout
   - Misc fixes/cleanups
 - DPU:
   - Fixed clock rounding, unbreaking newest platforms
   - Cleared pending flush state
 - DP:
   - Skip PUSH_IDLE when link was never enabled
   - Fixed bandwidth checks
 - HDMI:
   - Fixed runtime PM cleanup on probe failure
 
 xe:
 - shrinker related fixes
 - xe_mmio_gem fault handler and destroy fixes
 - xe disable i2c irq on unbind
 
 i915:
 - Revert a commit touching registers that don't necessarily exist
 - Check for negative numbers before passing to BIT()
 
 amdgpu:
 - SMU 14.x fix
 - DC IRQ fix
 - Runtime PM fix for P2P
 - RAS fix
 - PCIe reporting fix
 - DCN 6 fix
 - Device removal fix
 - DC MALL fix
 
 amdkfd:
 - GC 12.x fixes
 - Boundary checks
 - Mapping clear fix
 
 nouveau:
 - suspend/resume fixes
 
 gud:
 - out of bounds access fix
 - ignore damage clips in full update
 
 vc4:
 - use-after-free fix
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEEKbZHaGwW9KfbeusDHTzWXnEhr4FAmqttwkACgkQDHTzWXnE
 hr73Ww//S+8xgr8cpmJxoUrOrTnd4yeX/oj+HSRkEHQPdNayOf+pNnP4y+nChfXi
 ddQ3jTRyG5JwNmXRG0ouKf9koQk/V54R8v9CBtNQYsN2K58xW6riCIaEeOUbe3r1
 1IQgYCEfS32b7/9D2lo1768LbJ0KWBr6qznKrfvC7vJ62wK3F0B9EzOmsKSzLxd3
 gdUfyxEbtgegKOAamCbUyJyuzCErGkMAtkQ0HnmQGYmqqBBRS7Uvl1HN10JMoLSM
 MmR40g+dsp6ZzBDywNrdmIGDv749o1/k/zm5i6c2hJSibYBPR5sWtKICwu1ND44u
 ts2HjJJdyhm5PLiS09i9nVUnMkzV0N2czIDZvt9izp8+k8P4Bh/y1iagda1G0U65
 h7dp9j8WXMCApxXNjplNgjMLSO7g4UJI1rAWjxGY4ecu62XHErrZ6tbjrOVOaa1T
 Xh8IN4EqPr+tRSKnW4AxwwwA1EfxNwoJSxglAvBvIaCjEhRWRlj7Sdo0Wrtg3WKy
 sORar40ySYHR+MeAbabewjRoMPq1Nyqh4D2PrOv48a4MK7a6Fl5ed6EHpyOSHYKF
 7tMbLLLtDMIYX24wd/j8CkvhcTp09iphzXSqmUlIBn3t1gbrXspzCQtRU0UrsamJ
 QSbtL+qUoYSsobmpYOzuTVnO8W4oOnnIYaLz+TpVNDd7o7nzZf0=
 =EC37
 -----END PGP SIGNATURE-----

Merge tag 'drm-fixes-2026-09-19' of https://gitlab.freedesktop.org/drm/kernel

Pull drm fixes from Dave Airlie:
 "Things have picked back up a bit this week, mostly amdgpu, xe and msm
  this time. There are a bunch of scattered changes across the rest of
  drivers and core stuff, nouveau, i915.

  core:
   - fix vblank pending event leak

  ttm:
   - swapout fixes

  dma-buf:
   - scattergather fixes
   - enable dma-buf debug on debug kernels

  dma-fence:
   - fix signaling bit checks

  sched:
   - fix virtual runtime race

  msm:
   - DT:
      - Corrected indentation
   - Core:
      - Marked fbdev as system memory
   - GPU:
      - Fixed autosuspend cleanup on teardown
      - a750: fix timestamps
      - Increase GMU fw init timeout
      - Misc fixes/cleanups
   - DPU:
      - Fixed clock rounding, unbreaking newest platforms
      - Cleared pending flush state
   - DP:
      - Skip PUSH_IDLE when link was never enabled
      - Fixed bandwidth checks
   - HDMI:
      - Fixed runtime PM cleanup on probe failure

  xe:
   - shrinker related fixes
   - xe_mmio_gem fault handler and destroy fixes
   - xe disable i2c irq on unbind

  i915:
   - Revert a commit touching registers that don't necessarily exist
   - Check for negative numbers before passing to BIT()

  amdgpu:
   - SMU 14.x fix
   - DC IRQ fix
   - Runtime PM fix for P2P
   - RAS fix
   - PCIe reporting fix
   - DCN 6 fix
   - Device removal fix
   - DC MALL fix

  amdkfd:
   - GC 12.x fixes
   - Boundary checks
   - Mapping clear fix

  nouveau:
   - suspend/resume fixes

  gud:
   - out of bounds access fix
   - ignore damage clips in full update

  vc4:
   - use-after-free fix

  versilicon:
   - plane format fix

  longsoon:
   - blend mode property fix"

* tag 'drm-fixes-2026-09-19' of https://gitlab.freedesktop.org/drm/kernel: (59 commits)
  drm/amd/display: fix MALL hysteresis timer underflow at high refresh rates
  drm/amdgpu: fix rmmio iounmap skipped on device removal
  drm/amdgpu: Skip KFD mapping clear before initialization
  drm/amd/display: Fix NULL dereference in dcn50/dcn60 init_hw
  drm/amdkfd: Avoid integer underflow in EOP ring size calculation.
  drm/amdkfd: Avoid integer underflow with ffs in EOP ring size calc
  drm/amdgpu: Fix GPU PCIe link capability reporting
  drm/amdgpu: check ras and obj before dereference
  drm/amdgpu: hold a runtime PM reference for P2P dma-buf attachments
  drm/amdkfd: implement restore_mqd callbacks for GFX12/12.1
  drm/amd/display: Atomize IRQ register read/modify/write ops
  drm/amd/pm: report energy accumulator for smu 14.0.3
  drm/loongson: Create blend mode property for cursor plane
  drm/xe/i2c: Disable IRQ on unbind
  Revert "drm/i915/display: Clear SEL_FETCH_PLANE_CTL on plane disable"
  drm/verisilicon: remove ARGB formats from primary plane
  drm/verisilicon: add primary modifier for format tables
  drm/verisilicon: set blend mode for the cursor plane
  drm/sched: Fix virtual runtime race
  drm/i915/display: check configuration index before shifting
  ...
2026-09-18 16:37:37 -07:00
Dave Airlie
71f370e9ee Two ttm fixes for ttm_tt_swapout(), one page-alignment and one overflow
fix for dma-buf, a drm_pending_vblank_event leak fix for drm,
 suspend/resume fixes for nouveau, one out-of-bounds access fix for gud,
 a use-after-free fix for vc4, a fence signaling fix, a race condition
 fix for sched, planes formats fixes for verisilicon, and add the blend
 mode property for loongson
 -----BEGIN PGP SIGNATURE-----
 
 iJUEABMJAB0WIQTkHFbLp4ejekA/qfgnX84Zoj2+dgUCaqvVAAAKCRAnX84Zoj2+
 dtThAX9JC7SWXw+n4o9EUsxNqvlpviwe8AS7aJR++rq/sZM0an7zl0aCJu/E8p+/
 JRkO+X8BfjE+2CX8RWKH63ed95vA+9DF8JfryBTSJiSz4forppFfwH7uovT3nqq2
 eOon6nJQzg==
 =Utup
 -----END PGP SIGNATURE-----

Merge tag 'drm-misc-fixes-2026-09-17' of https://gitlab.freedesktop.org/drm/misc/kernel into drm-fixes

Two ttm fixes for ttm_tt_swapout(), one page-alignment and one overflow
fix for dma-buf, a drm_pending_vblank_event leak fix for drm,
suspend/resume fixes for nouveau, one out-of-bounds access fix for gud,
a use-after-free fix for vc4, a fence signaling fix, a race condition
fix for sched, planes formats fixes for verisilicon, and add the blend
mode property for loongson

Signed-off-by: Dave Airlie <airlied@redhat.com>

From: Maxime Ripard <self@mripard.dev>
Link: https://patch.msgid.link/aqvVENQ4ksJEIcdb@houat
2026-09-19 06:49:36 +10:00
Linus Torvalds
17e7b8eacf smb client fixes for v7.3-rc4
A batch of bug fixes for the smb client:
 
  - Fix multiple out-of-bounds reads and use-after-frees in the SMB2/3
    receive path that are reachable from a malicious or compromised
    server: a stale next_buffer pointer and an integer overflow in
    compound encrypted frame handling, missing minimum-PDU-size and
    per-sub-PDU length validation before parsing command-specific
    response fields, missing bounds checks in DFS referral, server
    interface list, EA list, POSIX SID, snapshot enumeration and SMB1
    reparse point parsing
 
  - Fix use-after-frees and races in multichannel and connection
    teardown, including an interface freed while still in use when
    adding channels, a server used after its channel reference was
    dropped, a reconnect work item left queued after the server is
    freed and an uninitialized reconnect list node
 
  - Fix a heap overflow in the native symlink parser: an absolute
    target without an NT drive prefix caused out-of-bounds writes and a
    u16 length underflow leading to a 64K memcpy into a small buffer,
    triggerable by a user with write access to a mounted share under
    default settings
 
  - Fix WSL reparse point parsing: use unaligned accessors for the
    packed extended-attribute payload to avoid alignment faults on some
    architectures and stop leaving partially mutated fattr fields on
    parse failure
 
  - Fix lease break ACKs being sent through the wrong session on
    multiuser mounts, which caused read failures (e.g. on NetApp
    ONTAP/Azure Files) when copying files
 
  - Fix an smbd_connection leak when cifs_get_tcp_session() fails after
    an RDMA connection was already established
 -----BEGIN PGP SIGNATURE-----
 
 iHUEABYKAB0WIQTcqRusfSdYROJQwGkpVtNKoQNdYwUCaq2frwAKCRApVtNKoQNd
 Y1mcAQDcDTkep03jzghyJG6xWJ3S7KNbeYpjkOPnPyR+Et7HmAD/eXLFvgkJ3wC7
 tBUDjDTLeyP6/DOBmDb/fIKEw2vfBQs=
 =+Vsw
 -----END PGP SIGNATURE-----

Merge tag 'cifs-fixes-7.3-rc4' of https://git.manguebit.org/linux

Pull smb client fixes from Paulo Alcantara:
 "A batch of bug fixes for the smb client:

   - Fix multiple out-of-bounds reads and use-after-frees in the SMB2/3
     receive path that are reachable from a malicious or compromised
     server: a stale next_buffer pointer and an integer overflow in
     compound encrypted frame handling, missing minimum-PDU-size and
     per-sub-PDU length validation before parsing command-specific
     response fields, missing bounds checks in DFS referral, server
     interface list, EA list, POSIX SID, snapshot enumeration and SMB1
     reparse point parsing

   - Fix use-after-frees and races in multichannel and connection
     teardown, including an interface freed while still in use when
     adding channels, a server used after its channel reference was
     dropped, a reconnect work item left queued after the server is
     freed and an uninitialized reconnect list node

   - Fix a heap overflow in the native symlink parser: an absolute
     target without an NT drive prefix caused out-of-bounds writes and a
     u16 length underflow leading to a 64K memcpy into a small buffer,
     triggerable by a user with write access to a mounted share under
     default settings

   - Fix WSL reparse point parsing: use unaligned accessors for the
     packed extended-attribute payload to avoid alignment faults on some
     architectures and stop leaving partially mutated fattr fields on
     parse failure

   - Fix lease break ACKs being sent through the wrong session on
     multiuser mounts, which caused read failures (e.g. on NetApp
     ONTAP/Azure Files) when copying files

   - Fix an smbd_connection leak when cifs_get_tcp_session() fails after
     an RDMA connection was already established"

* tag 'cifs-fixes-7.3-rc4' of https://git.manguebit.org/linux:
  cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
  smb: client: fix reparse buffer bounds in cifs_query_reparse_point()
  smb: client: fix potential OOB read in smb3_enum_snapshots()
  smb: client: fix missing iov bounds check in parse_posix_sids()
  smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs()
  smb: client: reject short Next offsets in parse_server_interfaces()
  smb: client: fix missing lower-bound check on DFS referral string offsets
  smb: client: fix server->total_read for compound encrypted PDUs
  smb: client: validate minimum PDU size before smb2_get_data_area_len()
  smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
  smb: client: fix use-after-free of iface in cifs_try_adding_channels()
  smb: client: fix fattr leaking on wsl_to_fattr() failure
  smb: client: fix unaligned access in WSL reparse point parser
  smb: client: fix smbd_connection leak on cifs_get_tcp_session() error
  smb: client: fix rlist race and missing initialization
  smb: client: cancel reconnect work in clean_demultiplex_info()
  smb/client: send lease break ACKs thru correct session for multiuser mounts
  smb: client: validate absolute native symlink targets before NT fixups
2026-09-18 13:44:59 -07:00
Linus Torvalds
925724c081 SCSI fixes on 20260918
Four driver fixes, three of which are minor and one of which (fnic)
 tries to add some logic to try to avoid MSI-X being ineffective if
 hyperthreading is disabled.  The core fix adds validation to mode sense
 buffer sizes because it is used by ATA and could, theoretically, be
 exploited by a specially crafted USB device that can simply be plugged
 in to any laptop or server.
 
 Signed-off-by: James E.J. Bottomley <James.Bottomley@HansenPartnership.com>
 -----BEGIN PGP SIGNATURE-----
 
 iLgEABMIAGAWIQTnYEDbdso9F2cI+arnQslM7pishQUCaq2P/hsUgAAAAAAEAA5t
 YW51MiwyLjUrMS4xMiwyLDImHGphbWVzLmJvdHRvbWxleUBoYW5zZW5wYXJ0bmVy
 c2hpcC5jb20ACgkQ50LJTO6YrIXJ6AD9FODcORvjoRDhcU626EWsG/Hoy7YcMH2T
 bZVtZwp3hH8BAPnKar5uj3fCQxJkvI+sLKjiGultTi3llt9VaZGSTFj2
 =JgQF
 -----END PGP SIGNATURE-----

Merge tag 'scsi-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/jejb/scsi

Pull SCSI fixes from James Bottomley:
 "Four driver fixes, three of which are minor and one of which (fnic)
  tries to add some logic to try to avoid MSI-X being ineffective if
  hyperthreading is disabled.

  The core fix adds validation to mode sense buffer sizes because it is
  used by ATA and could, theoretically, be exploited by a specially
  crafted USB device that can simply be plugged in to any laptop or
  server"

* tag 'scsi-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/jejb/scsi:
  scsi: core: Validate MODE SENSE lengths in scsi_cdl_enable()
  scsi: fnic: Fix missed link-up when critical IRQ targets offline CPU
  scsi: ibmvfc: Add Kconfig dependency to fix link failure when NVME_FC=m
  scsi: qla2xxx: Fix the ql2xfc2target parameter description
  scsi: pm80xx: Fix the use_msix, use_tasklet and read_wwn parameter descriptions
2026-09-18 13:10:29 -07:00
Linus Torvalds
ef31d04b6d pci-v7.3-fixes-1
-----BEGIN PGP SIGNATURE-----
 
 iQJIBAABCgAyFiEEgMe7l+5h9hnxdsnuWYigwDrT+vwFAmqtiM0UHGJoZWxnYWFz
 QGdvb2dsZS5jb20ACgkQWYigwDrT+vxDxg/+Nyqg0N+1xxHnG+bsbJ7XA7v7sQY5
 DcvfvnMcJg3Lx5ioED4OJwr35rQZy8E3n/swFCxvzyZQ6gp+Q3sA2wUeuqd26kCS
 OSuMwRj3+HsnCVlYC/LL5fUoyZ+/FFv4drDPvIl3vCo5kIoNuWJslIox1eqPgmtZ
 SZO70qyQcA8jjCHYqQR07kvtqyainZrOoPP5uASnRqSGVlTLI3mzKdLtzrVytgel
 bAb6CPKrqF1XQY2HBBH3MEU6mhXbr7zeSrncZnb0QimqHCloq4dUK+WF9ZQnxSk5
 wXgftOvg2ycYhE6hUVZGrRf/fMwzWatkD/Vi9a69wKN2lspwacKCGi0LhNS1u/Em
 ypak/Wg0sEic5y//eOgJjIfodJLsHiyvBIZxC3ziqZj1q6Kc4pCvg1iHePFYCSQj
 gB4Khkm6sWx63GX02g9ytc9bl00xCkjuck8OSVExP2MhaWajlksvzy9VXsZG9BzH
 QianraVVqVZd+LM3eFTy16qaD7jQuNMCIzOzB3UDh2gSzO+Lr9OtK36iTsn0NELc
 lKjrIlh5yEp5uD9vrrD4k8xAbaVGBnzzK7Whc42rt2n/gIs2SbV8TXWTyxtk29DJ
 XlbUAOiBLYEuO3YWAvq47kezyafwRtBqXxjyyoZajteD+hoRFFtkcT5OcaiWVZUL
 qzRbS1eB3IfB/q8=
 =9dUn
 -----END PGP SIGNATURE-----

Merge tag 'pci-v7.3-fixes-1' of git://git.kernel.org/pub/scm/linux/kernel/git/pci/pci

Pull PCI fix from Bjorn Helgaas:

 - Enable clock after core reset is asserted to fix enumeration
   regression on i.MX6Q Apalis platforms with ASM1061/ASM1062 SATA
   controllers (Richard Zhu)

* tag 'pci-v7.3-fixes-1' of git://git.kernel.org/pub/scm/linux/kernel/git/pci/pci:
  PCI: imx6: Move clock enable after core reset assertion
2026-09-18 12:16:25 -07:00
Linus Torvalds
c3d85c669d - Fix session expiration so that valid sessions are no longer removed
after ten seconds of inactivity when a new session setup request is
    received. Sessions now expire only after credential expiration, while
    stale unauthenticated sessions are cleaned up after a 45-second timeout.
 
  - Keep earlier responses in compound requests when Query Info fails
    because the output buffer is too small. The error response is appended
    without truncating preceding responses.
 
  - Return STATUS_BUFFER_OVERFLOW for partial
    FILE_NORMALIZED_NAME_INFORMATION responses instead of incorrectly
    returning STATUS_INFO_LENGTH_MISMATCH.
 -----BEGIN PGP SIGNATURE-----
 
 iQJKBAABCgA0FiEE6NzKS6Uv/XAAGHgyZwv7A1FEIQgFAmqtTBMWHGxpbmtpbmpl
 b25Aa2VybmVsLm9yZwAKCRBnC/sDUUQhCD2GD/9OzkmZ+/kIMum8IQi9upOM5zUD
 +2nyFMebJ6qXmrhOuUgLn2ptUYxO3q1B9VvzTjKrM1Vun0VuvHmHQbGUp9a/3F7c
 VTncl7E3FEHqlPkLWQJFv2dS+TYYcOhjoc2TDAY9093xktcMHK5zjv4E/DV2o0bf
 NN/GcrrcWSxdJU8WI9JvY2kzmPQMDfM8uVbj2RqHSZ8m9mF5cajtDnzCCS0K6UOR
 qzMrekzewIskUtcQNqU8hJWl1sgiYdD+16LmKmwLd3uOZISc3Miy5Bg8VpNN+B1g
 XHhr49G4Fb8PkEYjncjxQH7zop1ID5UyC2xN63NuoH8+mkm4qn6uG2NrLhmVQO+f
 Z81Ov3g77/jK3Z2fw00H3A7VGSPs931BaRTNj+lPkHTVVq3PyP1XZsfXkPUoRu1Q
 xeaJydScGNYE+kaYbseXwN8haJGawd1Dd+Afn4W2zikUU5tKZxO9d2tBr4Fhl/Fm
 0OBcAssTArhrY7PX2fAOQ4sUwAC4nMXSEIfdWIvcgU2OoyuFltQ55ooCoM0uLs6+
 7R4rxZLipdZmKhuE2mlAWcFQJn8nS0EHXeyEDjO0u8KYsV6C8d+jDNpvtS+/5QVF
 bKE4/uUX/lV0IZ55nFSPT7XdI+gxeiUql3+8bqOVqkw7wR4VjaC0xIQybyEBTMYH
 IJEKfjx4tZcWGTzmdA==
 =9nNl
 -----END PGP SIGNATURE-----

Merge tag 'ksmbd-for-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/linkinjeon/smb

Pull smb server fixes from Namjae Jeon:

 - Fix session expiration so that valid sessions are no longer removed
   after ten seconds of inactivity when a new session setup request is
   received.

   Sessions now expire only after credential expiration, while stale
   unauthenticated sessions are cleaned up after a 45-second timeout.

 - Keep earlier responses in compound requests when Query Info fails
   because the output buffer is too small. The error response is
   appended without truncating preceding responses.

 - Return STATUS_BUFFER_OVERFLOW for partial
   FILE_NORMALIZED_NAME_INFORMATION responses instead of incorrectly
   returning STATUS_INFO_LENGTH_MISMATCH.

* tag 'ksmbd-for-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/linkinjeon/smb:
  ksmbd: keep compound responses on query info errors
  ksmbd: fix partial normalized name responses
  ksmbd: follow SMB2 session expiration semantics
2026-09-18 11:05:55 -07:00
Linus Torvalds
bfda5a01aa - Make MFT extension work on existing Windows-created volumes by
dynamically reserving MFT tail records, accounting for records added
    during allocation, and avoiding false -ENOSPC failures.
 
  - Repack non-resident $MFT/$ATTRIBUTE_LIST when its mapping pairs no longer
    fit in the base MFT record, while propagating allocation and writeback
    errors.
 
  - Serialize runlist updates with the runlist lock and restore both the
    in-memory runlist and on-disk mapping pairs when allocation rollback is
    required.
 
  - Propagate folio errors and harden inode failure handling by treating
    interrupted reads as transient failures and discarding and unhashing
    inodes whose initialization fails.
 
  - Fix the $MFTMirr write offset when mirror records span multiple folios,
    preventing mirror records from overwriting the first record with large
    MFT record sizes.
 -----BEGIN PGP SIGNATURE-----
 
 iQJKBAABCgA0FiEE6NzKS6Uv/XAAGHgyZwv7A1FEIQgFAmqtRIEWHGxpbmtpbmpl
 b25Aa2VybmVsLm9yZwAKCRBnC/sDUUQhCBK8EAChFdTxig3sYog3dL27SX+1yNC4
 S1QtSQMvPJzcvLG2/mESC57snx1u6AXZ6enaQ/m8zQQvkWHFdwD+odgjOQ3474Yc
 MS7xQn5pCsAo3LmSWiDsQfHmvxgDMYlIRU1vmqr7fG2pj+W6BR2LB1PD3RI9exI7
 0WWAXBPZH5w5C9GE1Zo7TF9Xwby5Or31RS8+R57PXA/PJ1ivpWnlkpfLi4M/YkZK
 GIpunZafSpcKbEsuWcjhdz11bR4G9Qlwuuq0MDguLC/qsqsobHCeSbdx+4IsEAq5
 02yBl5hYm2E4u2KBedpe7oRwFvlPN0uakEGYS8SA1ad9XamjGIw6T0tkzkDL48Pq
 dhVAeX2oa8O9u+VK+qF/HIUylh/UbmHQJW8iSiZWO8WdULGBG8oCHI1hcSnMguwJ
 njyK75UXz4fMsKW6ZpRu0sRGqtKKcbg8IrCvLslPIOS2A9OAwSzytDKI+x1Kbgu0
 SVPYjf6XeOz83tvE+2OhfTT1hWkeKezMiUe4E/y9rgEDxv5vE4C5pvpDfRlj3oyn
 2JTXXjjUQGSQw/9cKbLsbElDH/FLEojLAsIFgM+2FbcG+x7PUUgSGdC4R4qZ9MUF
 cuMzfhi8vKyCYmJc8nNE4J6b6UkBNOFJMYBcArtByFW3LqfIzmqwW81Xx0Hz4cxi
 dmOhD6gXXYoi9m3lBQ==
 =rT1L
 -----END PGP SIGNATURE-----

Merge tag 'ntfs-for-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/linkinjeon/ntfs

Pull ntfs fixes from Namjae Jeon:

 - Make MFT extension work on existing Windows-created volumes by
   dynamically reserving MFT tail records, accounting for records added
   during allocation, and avoiding false -ENOSPC failures

 - Repack non-resident $MFT/$ATTRIBUTE_LIST when its mapping pairs no
   longer fit in the base MFT record, while propagating allocation and
   writeback errors

 - Serialize runlist updates with the runlist lock and restore both the
   in-memory runlist and on-disk mapping pairs when allocation rollback
   is required

 - Propagate folio errors and harden inode failure handling by treating
   interrupted reads as transient failures and discarding and unhashing
   inodes whose initialization fails

 - Fix the $MFTMirr write offset when mirror records span multiple
   folios, preventing mirror records from overwriting the first record
   with large MFT record sizes

* tag 'ntfs-for-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/linkinjeon/ntfs:
  ntfs: fix $MFTMirr write offset when it spans multiple folios
  ntfs: unhash failed inode reads
  ntfs: discard inodes that fail initialization
  ntfs: ignore interrupted inode reads as corruption
  ntfs: propagate folio errors
  ntfs: protect runlist updates with the runlist lock
  ntfs: account for MFT records added during allocation
  ntfs: repack $MFT/$ATTRIBUTE LIST
  ntfs: use dynamic MFT tail reservation
2026-09-18 11:02:08 -07:00
Linus Torvalds
8cb0606271 MMC core:
- Prevent potential use-after-free for SDIO IRQ work
  - Fix OF node reference leak on card add failure
  - Fix memory lea when the port table is full for sdio_uart
 
 MMC host:
  - hsq: Fix use-after-free in retry work
  - mmci: Fix use-after-free in busy-timeout work
  - mmc_spi: Reset bytes_xfered before retrying CRC failures
  - mxcmmc: Cancel data work and watchdog on remove
  - rtsx_pci_sdmmc: Ignore broken write-protect on ThinkPad X260
  - sdhci_am654: A couple of fixes for the tuning sequence
  - sdhci-of-aspeed: Remove children before releasing SDC resources
  - sh_mmcif: Initialize IRQ-thread mutex before requesting interrupt
 
 MEMSTICK:
  - ms_block: Destroy io_queue workqueue on removal
 -----BEGIN PGP SIGNATURE-----
 
 iQJEBAABCgAuFiEEugLDXPmKSktSkQsV/iaEJXNYjCkFAmqtI4oQHHVsZmhAa2Vy
 bmVsLm9yZwAKCRD+JoQlc1iMKcjwD/91lyNP8fb8cxorEtmkiNt63Sb+glVEnobW
 aOlXS23GuV9ZsPw7kKEEfZ4EWCOTEZ86Lj0OMzlpXE8dxYHGlu0qG97uxSiJ4wux
 LQ0+OR5ljqDN48BWrn3wWsJ1YLfM4xXL7XukiCEuxLU9jwlbPHNjtY8c0+JqMapH
 D1yE7tH7/ZPJuYwKt9DJlx5DKg0BTiRn/7j+o3IETNyuBP05ZzrUjNdgQW8DVawg
 2uR0GCZ268Asd7XhnywvLXbeg5jxRAEVMGVjEzn2CY5uY0YyUW9ye9e+TpbNqpYf
 OA2MnYiTNpcRIiI3Z8R5vrhGxMpqFd5hFdIUE64O5gnjSyrBKeo9SSw4huXlLvac
 xjdBYmtLxSQjIgvZaEG4hl12lJt/snLJODTEq690zei9oWCUnCKzZaargLFPcDje
 0J8HwPYStynI0nc2Jc4oGZEGGwgvSmFPk15JtMEdmJb3eIwOfzGLA1ky9+5VEVCC
 zzMifnvnseAJwz+iAaJYxkED3Gd4t/jm4n8XIihddsKBQHAbMtGhUmhSzNnzD6NF
 xgscpv8s8SKExwS6X+6f/SBZD4VoF9b1JDhJ+fVUJDQ1Dsgv9AyT/bl8gDBHPNwr
 JHflPaQhc3hM9RppdcZnW3KSCu3DCJ04XaoHy6m5zKWZHUBEAtxujHA5u373Wv89
 StY7v7d7UQ==
 =KPXN
 -----END PGP SIGNATURE-----

Merge tag 'mmc-v7.3-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/ulfh/mmc

Pull MMC/MEMSTICK fixes from Ulf Hansson:
 "MMC core:
   - Prevent potential use-after-free for SDIO IRQ work
   - Fix OF node reference leak on card add failure
   - Fix memory lea when the port table is full for sdio_uart

  MMC host:
   - hsq: Fix use-after-free in retry work
   - mmci: Fix use-after-free in busy-timeout work
   - mmc_spi: Reset bytes_xfered before retrying CRC failures
   - mxcmmc: Cancel data work and watchdog on remove
   - rtsx_pci_sdmmc: Ignore broken write-protect on ThinkPad X260
   - sdhci_am654: A couple of fixes for the tuning sequence
   - sdhci-of-aspeed: Remove children before releasing SDC resources
   - sh_mmcif: Initialize IRQ-thread mutex before requesting interrupt

  MEMSTICK:
   - ms_block: Destroy io_queue workqueue on removal

* tag 'mmc-v7.3-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/ulfh/mmc:
  mmc: sdhci-of-aspeed: Remove children before releasing SDC resources
  mmc: sh_mmcif: initialize IRQ-thread mutex before requesting interrupt
  mmc: core: Fix OF node reference leak on card add failure
  mmc: rtsx_pci_sdmmc: ignore broken write-protect on ThinkPad X260
  mmc: sdio_uart: fix xmit_fifo leak when the port table is full
  mmc: spi: reset bytes_xfered before retrying CRC failures
  mmc: sdhci_am654: Fallback to DT-provided itap delay on DDR50 tuning failure
  mmc: sdhci_am654: Clear ITAPDLY on tuning failure
  mmc: sdhci_am654: Reset command and data lines on failed tuning
  mmc: sdhci_am654: Move tuning_loop to local variable
  mmc: hsq: Fix use-after-free in retry work
  mmc: mxcmmc: cancel data work and watchdog on remove
  mmc: mmci: Fix use-after-free in busy-timeout work
  mmc: core: Cancel SDIO IRQ work before freeing host
  memstick: ms_block: destroy io_queue workqueue on removal
2026-09-18 10:53:42 -07:00
Linus Torvalds
ae09f35bd3 ata fixes for 7.4-rc4
- Explicitly clear upper address bits on quirked AHCI controllers
 
    AHCI controllers that claim to support 64-bit DMA, but which have
    been quirked to only do 32-bit DMA, could start the DMA engine
    with a non-zero value in the upper address bits registers (me)
 
  - Fix a resource leak in ahci_platform_get_resources() (Wentao)
 
  - Fix invalid kernel-doc formatting for ata_dsm_trim_pages() (me)
 -----BEGIN PGP SIGNATURE-----
 
 iHUEABYKAB0WIQRN+ES/c4tHlMch3DzJZDGjmcZNcgUCaq0h5wAKCRDJZDGjmcZN
 cla0AQD9oseos93LDPzXR5SSMirdjoL9Qee8RsVeIMMlRtahiAD/Tx+vlEYrQ3QG
 yESu9KV1YCaV2qDzG+nFjNt9Z6uc4wo=
 =xqFb
 -----END PGP SIGNATURE-----

Merge tag 'ata-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/libata/linux

Pull ata fixes from Niklas Cassel:

 - Explicitly clear upper address bits on quirked AHCI controllers

   AHCI controllers that claim to support 64-bit DMA, but which have
   been quirked to only do 32-bit DMA, could start the DMA engine with a
   non-zero value in the upper address bits registers (me)

 - Fix a resource leak in ahci_platform_get_resources() (Wentao)

 - Fix invalid kernel-doc formatting for ata_dsm_trim_pages() (me)

* tag 'ata-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/libata/linux:
  ata: libata-scsi: fix ata_dsm_trim_pages() kernel-doc
  ata: libahci_platform: Fix device reference leak in ahci_platform_get_resources()
  ata: libahci: clear PxCLBU and PxFBU for AHCI_HFLAG_32BIT_ONLY
2026-09-18 10:51:14 -07:00
Linus Torvalds
d24e3bf4c5 hwmon fixes for v7.3-rc4
* cgbc-hwmon: Add missing sensors, and fix current sensors ID lookup
 
 * gpioufan: Return IRQ_HANDLED from the shared alarm IRQ handler to fix
   possible interrupt storm
 
 * hp-wmi-sensors: Improve raw WMI string handling, and fix UaF in show
   function
 
 * k10temp: Fix model id range of Zen5 Turin to stop reporting temperature
   data for non-existing CCDs
 
 * pmbus
 
   - core: Increase number of phases to fix UaF problems
 
   - tps53679: Fix TPS53676 phase page decoding, and select page 0
     for single-page applications
 
 * pwm-fan: Stop RPM timer before freeing tach data to fix UaF problem
 
 * w83793: Release probe data through kref to fix UaF problem
 
 * w83791d: Remove fan/pwm 4-5 sysfs group on remove to fix UaF problem
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCAAdFiEEiHPvMQj9QTOCiqgVyx8mb86fmYEFAmqtY4YACgkQyx8mb86f
 mYHX0Q//UmlkmqkHH3XdKi1QX/RV60f82HfzXRkMq98FYocEYv4TKnru3U5pRLY3
 Vs/h4GcDWT16ApqKbciBxgoUj72XBohm/T0gv8rhC/gkx4w8F7/CPuCB6vq9kIAj
 EIOHM3KoulfwUN6K1JeFdo5sIrTMxYGnQoJjS31/HfExEGbcBMZjA4eWLkqA0s18
 zmtYKbCJbG2WFRkI8/HKeQ2MwFE3RLNrxPVNvWJNzwIPjMvaAD7eDSsRjgXpaH6s
 A2OHpnGkDLE1qeyuYYx+nFYmMQDGDxnt6QvEjX5cVUYE+jDIXuzF5HJVfLCaXoSJ
 cFJmyNVTNE6Is1g6qeBRwObSq/NJH3O6p7kXCf5qwO27XBXgt/7K4q751tMq8oEE
 kXiYn3WfBL4WJjYqQw8kEh2/D18fyj9XmoS7iBXzf1qXgRSROm/9irMBjsWiw0WF
 92iE9U7UaE/a5fGX+dbRnB7QmLZ33U5TzA3ERb+MwJQj6o8Llvb5gmJOmlYebpa1
 zRiu285Y3oGnjjkFgzvpps9hsVw3kb2Xs2utMbTPrJ2z4SUO9KInl+ifOr5w9VI+
 sNU0Rn3eQ6IT40NMO9FhHPciZygKmob6hNDYh/6e+OulMDW7XW46ES2e8jjwME30
 fjDpfKDxoAU/xQ548XQJBRcUNjUhV8S6NYZr3H4PpyWlPVmSkOY=
 =lG35
 -----END PGP SIGNATURE-----

Merge tag 'hwmon-for-v7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/groeck/linux-staging

Pull hwmon fixes from Guenter Roeck:

 - Add missing sensors, and fix current sensors ID lookup (cgbc-hwmon)

 - Return IRQ_HANDLED from the shared alarm IRQ handler to fix possible
   interrupt storm (gpioufan)

 - Improve raw WMI string handling, and fix UaF in show function
   (hp-wmi-sensors)

 - Fix k10temp model id range of Zen5 Turin to stop reporting
   temperature data for non-existing CCDs

 - pmbus:
     - Increase number of phases to fix UaF problems
     - Fix TPS53676 phase page decoding, and select page 0 for
       single-page applications

 - Stop pwm-fan RPM timer before freeing tach data to fix UaF

 - Release w83793 probe data through kref to fix UaF

 - Remove w83791d fan/pwm 4-5 sysfs group on remove to fix UaF

* tag 'hwmon-for-v7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/groeck/linux-staging:
  hwmon: (hp-wmi-sensors) Improve raw WMI string handling
  hwmon: (pmbus/tps53679) Select page 0 for single-page TPS53676
  hwmon: (pmbus/tps53679) Fix TPS53676 phase page decoding
  hwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show()
  hwmon: (w83793) release probe data through kref
  hwmon: (w83791d) remove fan/pwm 4-5 sysfs group on remove
  hwmon: (gpio-fan) return IRQ_HANDLED from the shared alarm IRQ handler
  hwmon: (pmbus/core) increase number of phases and add new mask
  hwmon: (cgbc-hwmon) Add missing sensors
  hwmon: (cgbc-hwmon) Fix current sensors ID lookup
  hwmon: (pwm-fan) Stop RPM timer before freeing tach data
  hwmon: (k10temp) Fix model id range of Zen5 Turin
2026-09-18 10:27:23 -07:00