mirror of
https://github.com/torvalds/linux.git
synced 2026-10-04 18:29:02 +02:00
36bb85cf36
1483457 Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
36bb85cf36 |
perf/core: Fix NULL pmu_ctx passed to pmu->sched_task()
perf_pmu_sched_task() returns early when cpuctx->task_ctx is set, and
cpc->task_epc is only non-NULL while a task context is scheduled in on
this CPU. __perf_pmu_sched_task() therefore always passes NULL:
Unable to handle kernel NULL pointer dereference at virtual address 00
pc : armv8pmu_sched_task+0x14/0x50
Call trace:
armv8pmu_sched_task+0x14/0x50 (P)
perf_pmu_sched_task+0xac/0x108
__perf_event_task_sched_out+0x6c/0xe0
Pass &cpc->epc instead, the CPU-wide context for this PMU, which the
function already dereferences a few lines up to find pmu.
armv8pmu_sched_task() is the only in-tree implementation that
dereferences the argument, and it only reads ->pmu, so the oops needs
BRBE, added in v6.17.
Fixes:
|
||
|
|
cca4980630 |
perf/core: Fix a refcount leak in attach_perf_ctx_data()
The attach_perf_ctx_data() can race on global and !global cases. The
global case is protected by global_ctx_data_rwsem and shares a single
reference count using perf_ctx_data.global field.
But when it races with !global case, it may miss to set the global field
and result in a reference count leak.
CPU1 CPU2
----------------------------------------------------------------
attach_task_ctx_data(.global=1) attach_task_ctx_data(.global=0)
cd1 = alloc_perf_ctx_data(); cd2 = alloc_perf_ctx_data();
// { .global = 0, .refcount = 1 };
try_cmpxchg(); // success,
// task->perf_ctx_data = cd2
try_cmpxhg(); // fail; old = cd2
refcount_inc_not_zero(&old->refcount); // success
// old.refcount = 2
free_perf_ctx_data(cd1);
Then later detach_global_ctx_data() will see the data but it's not
marked as global, so it won't call detach_task_ctx_data().
Fixes:
|
||
|
|
d4d9ccbad5 |
perf/x86/intel: Rename NVL offcore_rsp attribute to offmodule_rsp
NVL introduces Offmodule Response events in place of the legacy Offcore Response events, but it still exposes the inherited offcore_rsp PMU attribute for programming the corresponding MSR data. Rename the NVL PMU attribute to offmodule_rsp so the sysfs interface matches the underlying event name and avoids user & tooling confusion. Signed-off-by: Dapeng Mi <dapeng1.mi@linux.intel.com> Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org> Signed-off-by: Ingo Molnar <mingo@kernel.org> Link: https://patch.msgid.link/20260917015234.981153-13-dapeng1.mi@linux.intel.com |
||
|
|
0102c8c7fd |
perf/x86/intel: Rename DMR offcore_rsp attribute to offmodule_rsp
DMR introduces Offmodule Response events in place of the legacy Offcore Response events, but it still exposes the inherited offcore_rsp PMU attribute for programming the corresponding MSR data. Rename the DMR PMU attribute to offmodule_rsp so the sysfs interface matches the underlying event name and avoids user & tooling confusion. Signed-off-by: Dapeng Mi <dapeng1.mi@linux.intel.com> Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org> Signed-off-by: Ingo Molnar <mingo@kernel.org> Link: https://patch.msgid.link/20260917015234.981153-12-dapeng1.mi@linux.intel.com |
||
|
|
ff1621adfd |
perf/x86/intel: Fix precise OMR event scheduling for DMR/NVL
The latest perfmon event database introduces below precise OMR event support for DMR/NVL: - MEM_LOAD_L2_MISS_RETIRED.* (event 0xd6) - MEM_STORE_L2_MISS_RETIRED.* (event 0x4f) These events use the same OMR MSRs as the existing OMR events, but they are not listed in intel_pnc_extra_regs[]. As a result, perf cannot assign the required OMR extra registers when scheduling them. Add the new precise OMR events to intel_pnc_extra_regs[] so they can be scheduled with the correct OMR MSRs. MEM_LOAD_L2_MISS_RETIRED.* remains limited to GP counters 0-3, while MEM_STORE_L2_MISS_RETIRED.* is available on all GP counters. Signed-off-by: Dapeng Mi <dapeng1.mi@linux.intel.com> Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org> Signed-off-by: Ingo Molnar <mingo@kernel.org> Link: https://patch.msgid.link/20260917015234.981153-11-dapeng1.mi@linux.intel.com |
||
|
|
04a7ef3b7a |
perf/x86/intel: Constrain Panther Cove UOPS_DISPATCHED events to PMCs 0-3
Per the latest Panther Cove event definitions, the following events are
only supported on PMCs 0-3:
- UOPS_DISPATCHED.INT_EU_ALL (0x1b2)
- UOPS_DISPATCHED.ALU (0x2b2)
Add explicit event constraints for these two events so scheduling does
not place them on unsupported counters.
Fixes:
|
||
|
|
858b37ca19 |
perf/x86/intel: Delete dead NVL PEBS data-source initcall
Nova Lake now uses the OMR data-source table for PEBS data-source
decoding and no longer depends on the legacy static pebs_data_source[]
mapping.
Remove the dead intel_pmu_pebs_data_source_lnl() initialization call
for NVL.
Fixes:
|
||
|
|
0ac5d6ca2c |
perf/x86/intel: Fix Panther Cove PEBS data-source snoop states
For Panther Cove, the snoop states for the data source encodings
"Prefetch Promotion" and "Cross Core Prefetch Promotion" should be
SNOOP_NONE instead of SNOOP_MISS.
Fix the incorrect snooping states for Panther Cove.
Fixes:
|
||
|
|
9f93d33ad6 |
perf/x86/intel: Remove incorrect Panther Cove PEBS data-source constraints
Same issue exists on Panther Cove, PEBS data source is valid only for
these events:
- MEM_TRANS_RETIRED.LOAD_LATENCY (0x1cd)
- MEM_TRANS_RETIRED.STORE_SAMPLE (0x2cd)
The perfmon database (https://github.com/intel/perfmon) previously
tagged additional memory events such as MEM_INST_RETIRED.STLB_MISS_LOADS
with L1_Hit_Indication, implying PEBS data-source support, which is
incorrect. The database has since been fixed, but
intel_pnc_pebs_event_constraints[] still follows the old definition and
marks those events as data-source capable.
As a result, get_data_src() may decode data-source information for
events that do not provide valid PEBS data-source data and mislead
users.
Remove those non-data-source memory events from the Pather Cove PEBS
constraint table so matching falls back to the regular non-PEBS
constraints, which already provide the same counter constraints.
Also update pnc_latency_data() to decode LOAD/STORE flags explicitly
when setting memory operation direction, for consistency with other
*_latency_data() helpers.
Fixes:
|
||
|
|
7c944595cc |
perf/x86/intel: Remove incorrect LionCove PEBS data-source constraints
On Lion Cove, PEBS data source is valid only for these events:
- MEM_TRANS_RETIRED.LOAD_LATENCY (0x1cd)
- MEM_TRANS_RETIRED.STORE_SAMPLE (0x2cd)
The perfmon database (https://github.com/intel/perfmon) previously
tagged additional memory events such as MEM_INST_RETIRED.STLB_MISS_LOADS
with L1_Hit_Indication, implying PEBS data-source support, which is
incorrect. The database has since been fixed, but
intel_lnc_pebs_event_constraints[] still follows the old definition and
marks those events as data-source capable.
As a result, get_data_src() may decode data-source information for
events that do not provide valid PEBS data-source data and mislead
users.
Remove those non-data-source memory events from the Lion Cove PEBS
constraint table so matching falls back to the regular non-PEBS
constraints, which already provide the same counter constraints.
Also update lnc_latency_data() to decode LOAD/STORE flags explicitly
when setting memory operation direction, for consistency with other
*_latency_data() helpers.
Fixes:
|
||
|
|
335b064281 |
perf/x86/intel: Update arw_latency_data() mem-op direction handling
Align arw_latency_data() with other *_latency_data() helpers by explicitly decoding LOAD/STORE event flags when setting the sampled memory operation direction. This keeps the latency data path behavior consistent across platforms and avoids relying on implicit direction inference. Signed-off-by: Dapeng Mi <dapeng1.mi@linux.intel.com> Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org> Signed-off-by: Ingo Molnar <mingo@kernel.org> Link: https://patch.msgid.link/20260917015234.981153-5-dapeng1.mi@linux.intel.com |
||
|
|
8302c5f475 |
perf/x86/intel: Fix DKT PEBS load/store direction for latency events, to fix sample classification
Same bug exists on Darkmont as on Gracemont:
intel_dkt_pebs_event_constraints[] applies LAT_CONSTRAINT constraints to
MEM_UOPS_RETIRED.{LOAD,STORE}_LATENCY, but does not set explicit
LOAD/STORE flags for those events.
The PEBS latency path (pebs_latency_data(), via cmt_latency_data) uses
the event flags to determine memory operation direction. Without an
explicit STORE flag, samples from MEM_UOPS_RETIRED.STORE_LATENCY can be
misclassified as LOADs.
Set explicit LOAD/STORE flags in intel_dkt_pebs_event_constraints[] for:
- MEM_UOPS_RETIRED.LOAD_LATENCY
- MEM_UOPS_RETIRED.STORE_LATENCY
This fixes incorrect STORE sample classification. Additionally remove
INTEL_HYBRID_LAT_CONSTRAINT() since no one uses it anymore.
Fixes:
|
||
|
|
e961d6db42 |
perf/x86/intel: Fix CMT PEBS load/store direction for latency events, to fix sample classification
The same bug exists on Crestmont as on Gracemont:
intel_cmt_pebs_event_constraints[] applies LAT_CONSTRAINT constraints to
MEM_UOPS_RETIRED.{LOAD,STORE}_LATENCY, but does not set explicit
LOAD/STORE flags for those events.
The PEBS latency path (pebs_latency_data(), via cmt_latency_data) uses
the event flags to determine memory operation direction. Without an
explicit STORE flag, samples from MEM_UOPS_RETIRED.STORE_LATENCY can be
misclassified as LOADs.
Set explicit LOAD/STORE flags in intel_cmt_pebs_event_constraints[] for:
- MEM_UOPS_RETIRED.LOAD_LATENCY
- MEM_UOPS_RETIRED.STORE_LATENCY
This fixes incorrect STORE sample classification.
Fixes:
|
||
|
|
89dc568e8c |
perf/x86/intel: Fix GRT PEBS load/store direction for latency events, to fix sample classification
On Gracemont, intel_grt_pebs_event_constraints[] applies LAT_CONSTRAINT
constraints to MEM_UOPS_RETIRED.{LOAD,STORE}_LATENCY, but does not set
explicit LOAD/STORE flags for those events.
The PEBS latency path (pebs_latency_data(), via __grt_latency_data())
uses the event flags to determine memory operation direction. Without an
explicit STORE flag, samples from MEM_UOPS_RETIRED.STORE_LATENCY can be
misclassified as LOADs.
Set explicit LOAD/STORE flags in intel_grt_pebs_event_constraints[] for:
- MEM_UOPS_RETIRED.LOAD_LATENCY
- MEM_UOPS_RETIRED.STORE_LATENCY
Also update __grt_latency_data() to explicitly interpret these flags when
assigning the sampled memory operation direction.
This fixes incorrect STORE sample classification.
Fixes:
|
||
|
|
a391618e1d |
perf/x86/intel: Make @data a mandatory param for intel_guest_get_msrs()
Drop "support" for passing a NULL @data/@kvm_pmu param when getting guest
MSRs. KVM, the only in-tree user, unconditionally passes a non-NULL
pointer, and carrying code that suggests @data may be NULL is confusing,
e.g. incorrectly implies that there are scenarios where KVM doesn't pass
a PMU context.
Fixes:
|
||
|
|
d06260e99e |
perf/x86/intel: Don't pointlessly context switch DS_AREA (and PEBS config) if PEBS is unused
When filling the list of MSRs to be loaded by KVM on VM-Enter and VM-Exit,
load the guest values for DS_AREA and (conditionally) MSR_PEBS_DATA_CFG if
and only if PEBS will be active in the guest, i.e. only if a PEBS record
may be generated while running the guest. As shown by the !pebs_ept path,
it's perfectly safe to run with the host's DS_AREA, so long as PEBS-enabled
counters are disabled via PERF_GLOBAL_CTRL.
Omitting DS_AREA and MSR_PEBS_DATA_CFG when PEBS is unused saves two MSR
writes per MSR on each VMX transition, i.e. eliminates two/four pointless
MSR writes on each VMX roundtrip when PEBS isn't being used by the guest.
Fixes:
|
||
|
|
4b64dbdc58 |
perf/x86/intel: Don't write PEBS_ENABLED on host<=>guest xfers if CPU has PEBS isolation, to fix stuck PEBS_ENABLED
When filling the list of MSRs to be loaded by KVM on VM-Enter and VM-Exit, *never* insert an entry for PEBS_ENABLED if the CPU properly isolates PEBS events, in which case disabling counters via PERF_GLOBAL_CTRL is sufficient to prevent unwanted PEBS events in the guest (or host). Because perf loads PEBS_ENABLE with the unfiltered cpu_hw_events.pebs_enabled, i.e. with both host and guest masks, there is no need to load different values for the guest versus host, perf+KVM can and should simply control which counters are enabled/disabled via PERF_GLOBAL_CTRL. Avoiding touching PEBS_ENABLED "fixes" a bug where PEBS_ENABLED can end up with "stuck" bits if a PEBS event is throttled between generating the list and actually entering the guest (Intel CPUs can't arbtitrarily block NMIs). Fixes in quotes because leaving PEBS_ENABLED as-is doesn't fix the underlying problem of perf (via PMIs) being able to modify state after the perf<=>KVM handoff. But not writing PEBS_ENABLED is desirable no matter what, as stating the obvious, leaving PEBS_ENABLED as-is avoids three MSR writes on every VMX transition: one each on entry/exit, and one more explicit WRMSR to zero PEBS_ENABLED before VM-Entry (KVM assumes the only reason PEBS_ENABLED is in the load list is if the CPU lacks PEBS isolation and thus needs a quiescent period). Opportunistically add comments to (better) explain the rules for generating the set of PEBS counters that will be active while the guest is running, along with a FIXME for the suspected hack-a-fix where perf disables guest PEBS if _any_ PEBS event is configured to count in the host (commit |
||
|
|
cec38d5c09 |
perf/x86/intel: Ensure KVM guest PEBS path doesn't set unwanted PERF_GLOBAL_CTRL bits
When reinstating PEBS counters into PERF_GLOBAL_CTRL for a KVM guest, mask
the value with perf's desired/original PERF_GLOBAL_CTRL value to ensure
KVM doesn't unintentionally set reserved bits in PERF_GLOBAL_CTRL. E.g.
if the guest's PEBS_ENABLE value had bit 63, "Enable Precise Store", set,
then using the raw guest PEBS value would propagate bit 63 to the guest's
PERF_GLOBAL_CTRL value (which thankfully would be a failed VM-Entry, not
a VMX Abort).
The only reason this bug isn't reachable is because KVM doesn't support
"Enable Precise Store" (which is probably a KVM bug?), i.e. bit 63 can't
be set in kvm_pmu->pebs_enable and thus not in arr[pebs_enable].guest. In
other words, this _should_ be a glorified NOP in the current code base.
Fixes:
|
||
|
|
93f51579e7 | Linux 7.3-rc4 | ||
|
|
6a5719cc3e |
net: qrtr: resend HELLO on MHI resume
Since the MHI HELLO exchange was relocated, it is sent only at device
registration. During a suspend-resume cycle, the firmware in WiFi
cards such as WCN7850 indefinitely waits for another HELLO,
triggering:
ath12k_wifi7_pci 0004:01:00.0: timeout while waiting for restart complete
ath12k_wifi7_pci 0004:01:00.0: failed to resume core: -110
Fix this by triggering the handshake from resume_early in the MHI
transport.
Validated on Qualcomm X1E-801800 on Lenovo Slim 7x across 10
suspend-resume cycles.
Fixes:
|
||
|
|
a10a019dd4 |
dmaengine fixes for v7.3
Bunch of core and driver fixes:
- Couple of fixes in core around dma_chan_put() for kref underflow, user
after free bug and waiting for rcu readers for dma devices
- mmp sg length and wrong extended DRCMR base for SpacemiT K3
- hardware buffer descriptor chain fix for xilinx dma
- sun6i fixes for status behaviour and dma position registers
- runtime pm reference leak fix for sprd driver
-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEE+vs47OPLdNbVcHzyfBQHDyUjg0cFAmqwEtUACgkQfBQHDyUj
g0dCWQ//ShhhOd2vQQttV+BSHB0xTdT/wENO4mhXcz50chHFh1diBFASMnhejOxG
dv4ZkePAxV7PLpNqRQrCz2gx89wn5Uxf71PmnLbleuJ5lOuSUMGbFL0MhLzrlfqr
2Di122aa5Va4Tp3zjNllQ4ihKMfCF02FLCXoZqelVIR/NQFFMeJhEjv/0P2foFvd
nrf5jzGJuCCbhKiV47H4a8hSb1bG68ct/mV0ZfOT5Koe4B16qPTe7Z9kW5FP0do5
++BeHLbEheA/btWUSzvnLMtGHhhUywlAab6cKEkYAcTsuxtapMMRtJmAq9bYyX1O
qS6hIC9qWMS4xc0+BUsIhwU8cXY6IINy8lPJmwc+/p4V+MJ8QMP+MrfWpWADFy0H
rTvkIdzU+Lc4fqIr97UbW+pi8Naf2NCiV2NJSYF8JT6ufeG1PymtwbeUlbhkThtZ
ISVF2/CIieyHr/eDfzNuGrYmdkSfJZgl6Rd6pCHdYQ5vgK6DImtaHfuBBm1OYXVG
NwA4vkTk6hKu2Sx2JShrSJC2js5q5gdz+9jQuvb9zZZS4I1qOARWjoe/E0wowlir
EB5bivcNX8VR49x2aYmT7Mg1CJovzs6hC1Aw9aqFIhp+1hQRku+iFOSki8Pwzl23
EcpkC7liL8S6WCo73Zh7cmT0aBvw3Y6Gpvfozh+Rr7kLZy6cfmw=
=9a97
-----END PGP SIGNATURE-----
Merge tag 'dmaengine-fix-7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/vkoul/dmaengine
Pull dmaengine fixes from Vinod Koul:
- A couple of fixes in core around dma_chan_put() for kref underflow,
use-after-free and waiting for rcu readers for dma devices
- mmp sg length and wrong extended DRCMR base for SpacemiT K3
- hardware buffer descriptor chain fix for xilinx dma
- sun6i fixes for status behaviour and dma position registers
- runtime pm reference leak fix for sprd driver
* tag 'dmaengine-fix-7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/vkoul/dmaengine:
dmaengine: mmp_pdma: fix wrong sg length in mmp_pdma_prep_slave_sg()
dmaengine: xilinx_dma: Fix hardware buffer descriptor chain after cyclic DMA
dmaengine: pxa: fix double counting of the hw descriptors
dmaengine: sun6i: fix undefined behaviour in sun6i_dma_tx_status
dmaengine: sun6i: fix non-atomic read of DMA position registers
dmaengine: xilinx_dma: Fix hardware buffer descriptor reuse order
dmaengine: wait for RCU readers before releasing dma_device
dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel()
dmaengine: Fix device kref underflow in dma_chan_put()
dmaengine: add dma_device_get() helper
dmaengine: sprd: Fix runtime PM reference leak in probe
dmaengine: ti: k3-udma-glue: fix NULL dereference in k3_udma_glue_release_rx_chn()
dmaengine: mmp_pdma: fix wrong extended DRCMR base for SpacemiT K3
|
||
|
|
60ee24f055 |
phy fixes for 7.3
Couple of driver fixes - Atomic context delay in renesas driver - TMDS and PLL rate calculation fixes for mediatek driver -----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+vs47OPLdNbVcHzyfBQHDyUjg0cFAmqwD8UACgkQfBQHDyUj g0dzqBAAuGIVwSpUaEVAHD7TKcLqrmLpF4kuGXN4mGB+i8Hg3ivCH7n6/cKONOeA LPkdnl7ABRqNYX935oXtRAUuy0CnoIKJKaxrp0ap1x5QtAcyAKWEW+Ej/rHL9JV7 JHt/YQFcMhcvKE1lGUYdFA9eF2PQf0h3Xw0BcaB83WqAlsoWh9EnEOjDnfkv4rZi PMIW5/lXlpkWEfyptomcNHycGbltnLP323IkIscyS6qX7dIfldoN4pinwNKrIvHM CNrg8PPYefjFltVZ7q2u/MB8IeDpYGKNlyGC3Kvspsa04o8Qb0TTMb3aZ+AOn3rJ Ccq69UwdnMARx+V9Gc9gY5Jp6Q503SPwFGhRTybT9iyjft9yIGkaEZL1miWOWpZZ Fsv3xukBZhDVy1jGt6tsyfUVvRh6eu835jYijp4NHBeo1To7/clcKTTAT5o1/upC qWeM/FarR3JB/sAHrHKnA/R3Yh9FTpy5lTD6FhXa95SufJmB12rKbjUYNMNG3EOx OgYpeBeuy8ZXtkzPO36LXFv6OomQkxjThMAZ/syn1T8HStWULkhj9MxkrH0BRsB0 SsxIBkzG7tKlwQizJGDugum9uvxFX0104voNhTkn9DPO2oo4LnxGlsonfqJj7XPD TJoF9/IWV+3bQCL9fLU0mBvniQf/jzEaGXoGX+qY1YtXm8I5jTE= =xn2f -----END PGP SIGNATURE----- Merge tag 'phy-fixes-7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/phy/linux-phy Pull phy fixes from Vinod Koul: - avoid atomic context delay in renesas driver - TMDS and PLL rate calculation fixes for mediatek driver * tag 'phy-fixes-7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/phy/linux-phy: phy: mediatek: phy-mtk-hdmi-mt8195: Fix TMDS clk bit ratio setting phy: mediatek: phy-mtk-hdmi-mt8195: Fix PLL calc divisor overflow phy: renesas: rcar-gen3-usb2: Avoid long delay in atomic context |
||
|
|
0a885f68d0 |
soundwire fixes for 7.3
- Cadence ensure work completion before clock stop - Disable ghost Realtek on Asus GX651AX -----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+vs47OPLdNbVcHzyfBQHDyUjg0cFAmqwABUACgkQfBQHDyUj g0dzrxAAmGpYUaBc5GEnTypOM8NM/UUOOWn+AMUGAb/AekqIChg42a5oVXlaAU5O HXqXIIJ5EVddmn++s1XJvcOrMGM4412wwrOKBpCWP9+h5+My1euY9AGDrApRrFCx DYmLvxqIDCq2MS8NmaY0RWAAkNI6TXQWsn29TBztt6xRCT7EmiM/iERJpBUhK4Sg Oyd9nJkT6Oieln/mfWWxAexBe+W5p9l6StLM/aDnQ7LiVEa6U5vKKfmEbFceQ0z1 1c3NoJC1hTdsNUytIOKcT46an0sF7GdIe6EB0+yAq+MfS1NHZrQWOG6weVxAqldV xS5uUadqDm18xuh8q97+fFueE/rT21JgQFWb9fsuYX3ESNpaO/8dPZtEZFVQOBBJ fR+vvKfqm4X3LXe+wXJt/3SQ7KV1Lth/bdPl2O4FYQlfvX1XmaS6lJiBErDyNxY8 sVCdy+XBcV4MjSciwnYjARpCVAcFo2NRt931TEDgaes2glaQl/v885pTZQEsE/CO mCaDcuBFaceuK2x9fGugqQRjCdOXAY8z6UcAUtwlUvy8g008IBssPuCQiVQvFZxs cPM4dkbrSPiKz2vuMJepytmk2Fm8wIVWHK7ODtYywYxfkFS8pCQOIi4Wj/EiOF++ 6dOKY0qxiDEr/27cqzm6YcGZ91dH9kDT4nR8W/6gXAdoqclJyCA= =mDuH -----END PGP SIGNATURE----- Merge tag 'soundwire-7.3-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/vkoul/soundwire Pull soundwire fixes from Vinod Koul: - Cadence: ensure work completion before clock stop - Disable ghost Realtek on Asus GX651AX * tag 'soundwire-7.3-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/vkoul/soundwire: soundwire: cadence_master: wait and cancel cdns->work before clock stop soundwire: dmi-quirks: Disable ghost Realtek on Asus GX651AX |
||
|
|
156fa7417f |
x86 fixes:
- Reject the loading of a potentially problematic microcode version
on Intel Granite Rapids systems (Chang S. Bae)
- On FRED, reconstruct the proper #GP context for rejected INT
instructions, to fix a signal ABI regression (Matthew Schwartz)
- Add a test for this signal ABI regression the x86
self-test suite (Matthew Schwartz)
- Don't emit the new and not yet properly supported EGPR instructions
(%r16-%r31) on CONFIG_X86_NATIVE_CPU=y builds (Chang S. Bae)
Signed-off-by: Ingo Molnar <mingo@kernel.org>
-----BEGIN PGP SIGNATURE-----
iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqvrhgRHG1pbmdvQGtl
cm5lbC5vcmcACgkQEnMQ0APhK1inbQ/9G4Q0h9esQ945n0uYRYvVLuj2P8DvE3XN
9d5IJ5pIYdhJCvlv8yXyv1u3sq59QYNmUgpBMghHJonhqobtnchvBSiznoAMgi8L
yjRlcaFBPX9qjFQV1W9WJQuUHhW/12QFy9Bo9n1uXEv6pYspYVDwodCaS+rEvkTF
0wK3TjETv90TravGjFscYTt2VLAiy+cd/FxkUA0sBaMLjhFpUyAPHGJe/vcf8vT3
rEXkY8EeSjv5F6eKMTDVacrSZu2c9wco1bJIsSFEcxZGFzhDbuCOGiDCkwmB3uuD
ReKbEUC0KmF8qd4Ubf0dMGpbHT9LDu9Ggex619cHFOHMupPubP+yym7aCpm3v7Sb
gZe6eV6VrSREJ+oBVKsqMrWXsg1YDj6uJhC/5K3S78xBeRq64kKsmBbC93Zp20TC
QpSAxKIFqp8C+tfKzpBmcSbcipRUfATJxLjp94QaQDp467jjJCvpDJdc12mV7WR9
0gMtFjxUaIe8BGX7s2PuWPgZ8+CIH0hZQuttxUU4QWvM2RGU+QrDaMwTeAY7wme4
xomc0wpXQb5enrjmFu8betlD0xfjgt7k6eW0njezRpWSk3wyHDd5w/6Vfn8pA6Fx
AQV4UuszXzQmG+W2pdIjLhnjmsjEeWMpmwgzn0rkcqujWHeh8XOSvQIjULFrFtFv
srSbum6vEfk=
=MP1H
-----END PGP SIGNATURE-----
Merge tag 'x86-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
Pull x86 fixes from Ingo Molnar:
- Reject the loading of a potentially problematic microcode version
on Intel Granite Rapids systems (Chang S. Bae)
- On FRED, reconstruct the proper #GP context for rejected INT
instructions, to fix a signal ABI regression (Matthew Schwartz)
- Add a test for this signal ABI regression the x86
self-test suite (Matthew Schwartz)
- Don't emit the new and not yet properly supported EGPR instructions
(%r16-%r31) on CONFIG_X86_NATIVE_CPU=y builds (Chang S. Bae)
* tag 'x86-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
x86/build/64: Prevent native builds from generating EGPR use
selftests/x86: Check signal state for rejected software interrupts
x86/fred: Reconstruct the #GP context for rejected INT instructions
x86/microcode/intel: Reject problematic loading on Granite Rapids systems
|
||
|
|
0a15ba6b0c |
Timer race fixes:
- Fix timer signal <-> exec() race, to prevent UAF (Thomas Gleixner)
- Clean up POSIX CPU timers right after de_thread(), to prevent UAF
(Hyunwoo Kim)
- Fix POSIX CPU timers race between expiry and timer_settime(),
to prevent UAF (Thomas Gleixner)
Signed-off-by: Ingo Molnar <mingo@kernel.org>
-----BEGIN PGP SIGNATURE-----
iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqvrMYRHG1pbmdvQGtl
cm5lbC5vcmcACgkQEnMQ0APhK1gqUQ/+NkruN984bFynF/eZ0/2DFv91AAUP8zgH
/S3PBlwuSbYFN9JVhngDMwxQkamE56weJbFc+0QuvVT5UVw/vX9BS4QOvvzN+f8D
FEN3UqD0d1B8OwlPNTw0sFPwJDdPctTinfKOhNjNQe6RLFsNARvGyaKDIDroWTfV
dxuJ/7Ecs+5m1bmGJnPEC+IH/OnV9BEEl1NdZb+INKpBlui9LCsw4rRIj/8dPK/H
UNhvXpykKrJCDftbCzAFSNryuzcJgq4kHtMbsqiUL6y50AB69eHGi/Y0xYBAEr1h
NiDPq2PAMmH1NCCMsTtqbJZMqgCr+7DSZiCFn7bZPwg0V5tV4PFZD484q0sCbiej
Fwg+arHd0icnceIcWMsBWPUVOSLxZaWdp9a2Tj3Ill06//b5bEDBJBbpecS+so3t
8W6IvdoCYm7sz50mohnjOdx7biHPu0yhwgj+EoAV3nZKoALQAAcI7+HJzSWpGnJi
HIO0zylRAZCjk9H3QNWO+LdWgifc8DysAZOWpmbuwGgp8q483IDRDtme/kMt3+D1
1qTHa1TD/tPo8UmmgyVJQ7e1hCxBkGuuBBu5Y3/qkUEOQM6B/H2Ji7stxsLpW3JL
HLzC3kL2SBBVBO2ljqiH5IhVAL10Qm5vPxaCOjExdBt1vjMxN1DowZqD4rT/tw58
ArpD4zmr8VQ=
=KhWJ
-----END PGP SIGNATURE-----
Merge tag 'timers-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
Pull timer race fixes from Ingo Molnar:
- Fix timer signal <-> exec() race, to prevent UAF (Thomas Gleixner)
- Clean up POSIX CPU timers right after de_thread(), to prevent UAF
(Hyunwoo Kim)
- Fix POSIX CPU timers race between expiry and timer_settime(),
to prevent UAF (Thomas Gleixner)
* tag 'timers-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list
exec: Cleanup POSIX timers right after de_thread()
signal: Prevent exec() race
|
||
|
|
fecbe78ac0 |
Scheduler fix:
- Avoid false positive migration warning for proxy donors
(Andrea Righi)
Signed-off-by: Ingo Molnar <mingo@kernel.org>
-----BEGIN PGP SIGNATURE-----
iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqvqssRHG1pbmdvQGtl
cm5lbC5vcmcACgkQEnMQ0APhK1gPzBAAhE9hcpkBV6vNW9xzBDKdGPxRjch2vcfu
lQbx7da1yC2rHU7RDlcdfEgkhAqTRwEAXKz26zth3sDHLk43tusuNtqG3swELhNW
YAGbHjdn87snQlmP8AOK4EaT3uE5NjWqRSIJWMK+AhWSwqO/zzK91T6yZyQY0fM4
3Edp8CFo3IeyOzCR96vsob2x1fFQhuR//5fWul3uuB0EZ8VA5FhH3ene6VCm7P/1
dauxX0rMTb2730qNXA8cHROZq+bwhqTZOUaoOZ33WxnRPkvY9mV/hZsN8JnJuzBE
ogzyyorcl8dFH8qOapos9Cp3tQj9GkTX7mXWDbuUflt/8uOXtQMf75kFGBVI5NUw
2xNfgubTYGo6Qc1C+wyOhGYJ6T5Al+083pV/vPc4y7Z1i7RgZ94QypMuZuaR/RqS
z+RQcdNQlXiRIAIILGJqq1xdbaCJvbVx3tiFZkhPse6ioOF6UNGbQiNExAq3v5BU
ocvhBuf9p/uvRmfs+ZtQNqAAjZUL7tQPvdFAsjxKjuI2Z5YGPROy1L9NdYKfzryM
yWOEkV2mdn97CwzDS+auC0HmPkGqf8we2VI5Ub4R35UPqDcV6vc5BAnwzAbuxAmc
K7mQOMDEaRkbVQ0MoSMdidIXLL0AcN+BROBUtHv8kqJur6nADE3K3HZNdhr2ViLN
eisNI6m8pLk=
=BEte
-----END PGP SIGNATURE-----
Merge tag 'sched-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
Pull scheduler fix from Ingo Molnar:
- Avoid false positive migration warning for proxy donors
(Andrea Righi)
* tag 'sched-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
sched/core: Avoid false migration warning for proxy donors
|
||
|
|
abb91eed94 |
Perf events fixes:
- Fix crash when probing CS CALL instructions (Jinke Han) - Fix NULL pointer crash during module unload (Vinay Belgaumkar) Signed-off-by: Ingo Molnar <mingo@kernel.org> -----BEGIN PGP SIGNATURE----- iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqvqiURHG1pbmdvQGtl cm5lbC5vcmcACgkQEnMQ0APhK1hiohAAjcvOY7M998pX1tmo1Egw9kAuI0odtNOX weQ4Wq7K3X+tg+q1wVUmE/N/y/WLYWNatjwvjc8TClYdQEiaqBMH4TSLAuY3TOxa TxwdTC20uSN4EPZ0iRhKzm3biPzzzRq4M9hhV+WfGcK7ieXRn4Q7d9S3DDe5oEfG lI4l/RefIBiINVPC7dNM7xpS/7XBEPnzNeshOMwp6ZsPziZJizgC8C7RhQFAPszo Ho36KKFQqMNouCSybQl1GxLyPw+oGtneWESHXrF6Mhp+bcx40fMtJxKNyVLsVWuM wo0Ry843pCbDofOIqg7m0AufWUhz7B4MttTXXrU2/BYMHEbxlgms1AO7lnSGzPmn vP0JHZnT3y34P5uvGaVho7t9QKKbuY47cKNmsiiLuXiBQQuKnvDmDln1Mu1KS3fg a1LI8kv043iLqAjsIWMVtKlRGUX36f4NXUWrxvO/tmup3ocJhG1oYmEe/RaFddVX 5qRbHn7Z1w8jAWldODYSrXkpMRgMtClQuqHdjxZQt5DPZSORzoFxTvSfJLdUUtVx CUiT34zcLPHfvGD+ctHe5kVesgDHCxp/z1tKrJBunB+XZVl6rKHycfiGjaUXQRcR NUp6iFlfay8b79EkMsLC8p6uAmzX2q+gEwNVy8eevBSXdsYqcY5islj3ob7sBHsH vk4gDJikpE0= =onkS -----END PGP SIGNATURE----- Merge tag 'perf-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip Pull perf events fixes from Ingo Molnar: - Fix crash when probing CS CALL instructions (Jinke Han) - Fix NULL pointer crash during module unload (Vinay Belgaumkar) * tag 'perf-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip: perf: Fix null pointer access in is_include_guest_event() x86/kprobes: Fix crash when probing CS CALL instructions |
||
|
|
2f7ff5f547 |
- Fix objtool build error on systems where libopcodes is
present, but development headers (binutils-dev) are not
(Ulises Mendez Martinez)
Signed-off-by: Ingo Molnar <mingo@kernel.org>
-----BEGIN PGP SIGNATURE-----
iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqvqSARHG1pbmdvQGtl
cm5lbC5vcmcACgkQEnMQ0APhK1iBWQ/9HTpCn/GSapwpTLUAXh/d/7VWSTV/xMRS
b/cqx+jFDFeZDU55VbX+bMgKQyW0jNSUPjvVp0ZfjUf0W0LOXL/EnAemZ8VqBqAj
IMIyd+0MjCeUOCVanRiITre65BPuF+g3EbxWypFDiLmb4ziA5YksPknTWYrIVbDP
IMks30B8kJfzC5Qh0jjpSRDSypTvuEAKppbyf3pPmHfKLSbwtKOQzeoFUlLtWfs4
diBm9BVIjosmIr5dxMyixa8+5BTsPs4ojwa4US3H+RzxdXe+2v31Ac2nK/zvCRst
Fr8gefaLhVrnfkJeXU0Xn/rDMYOzayb1JW4jWjJ40I6U20ptdrMQ3aSJqjNrrwkQ
2vikInQX3NKV2ASiTppLDhsq7MFt4AeRYFwj8xmErm5uhoSEKAEPG1QZWS98QkAo
CXQL3PITL5kS0q5wGkkYXNi3TbpKvWy8kPoIRMHoKFUkBHJRssSg8tb17D5Jg0yd
QvsjocvMSf865swQ6p1yj+7+Zd+nGM2JGkIcp9OBPTAzZej4bXmpPwMKDeRv6pgD
GNgKJ2oEhvXWCgokxK9ezgk8rYsH/1Vo/+JyBf4/tcKL9ixfnBTgLNZ80J8VFDn2
5axUt4EO+FZKzLB6UaENhTo813PhGOM/rChKmJ1L4GWi0RywoX+seH4b+FtQk87f
VPvApwwiDHQ=
=vTNY
-----END PGP SIGNATURE-----
Merge tag 'objtool-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
Pull objtool fix from Ingo Molnar:
- Fix objtool build error on systems where libopcodes is
present, but development headers (binutils-dev) are not
(Ulises Mendez Martinez)
* tag 'objtool-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
objtool: Validate disassembler headers in libopcodes probe
|
||
|
|
bdab18633a |
- Also allocate a default private futex hash on vfork()
as well, to avoid races with (private) futex waiters
(Peter Zijlstra)
Signed-off-by: Ingo Molnar <mingo@kernel.org>
-----BEGIN PGP SIGNATURE-----
iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqvp20RHG1pbmdvQGtl
cm5lbC5vcmcACgkQEnMQ0APhK1giDg//VpFKPXgma7fW5E+T0kjWHWD7FS1vYyJ4
nMunKME8PAV0A4S7946iUAWHjViVfksTmfvcXepSFCKZKLf55g8s2aZ1VoigMtYX
bQxNrnOidebSg9npLs9NV4sjvvNy+k03gcNN+OK+ZRfYCVRqbLgfCm5RJbaId5y4
+EuizVmtJuNav6HwAEIbU4LXGIdwSL9Pn8Zitkz/H7g0ZEkv+VA4h6NttvKDNfV7
OltcUFejtU7Z1lItfH+PP9pMcjPA6OPI2h7LLmUcZGUhhQQtW2Gb1fffz45PiH8T
FB7PdFt22TLG5c6hLB7zbrFFillWKn3l3Ihi/IxqVmMulhk6RVTPdCVJcj1cGZxF
9NXZ+L81poKwEETaIk52v5jm9qNF+kHbXJuCjPbmEdPxtxfv+Ma4zXom/xKkuXpx
qf01GXxelUPdCAl0cT0pzRvbEfHNIOsE2Id7f+59jB+L8ZbYEch04cIVRqCQcOgi
9B+lXj36fkFBV6wmuP5SWShWsgMsMpgSzOz5mUdWjY3Ocn9QuzDxPkk50Cm7uL1i
q/HpGv3T849HFnCH7+mi8wSiX33La+N297+AkGO7U7h5QFldPokvbAijwfmF+1Nw
CebsAfsgJsN1GZacDTH0jmRxh4I0Wa32yiCAldeGS2w9EMEAFbA87iwsOgjwHiQl
JOv/s06Pg7o=
=qQHe
-----END PGP SIGNATURE-----
Merge tag 'locking-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
Pull futex fix from Ingo Molnar:
- Also allocate a default private futex hash on vfork() as well, to
avoid races with (private) futex waiters (Peter Zijlstra)
* tag 'locking-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
futex: Also allocate private hash on vfork()
|
||
|
|
5bf70485f9 |
spi: Fixes for v7.3
A few driver specific fixes, none of them particularly severe or unusual. -----BEGIN PGP SIGNATURE----- iQEzBAABCgAdFiEEreZoqmdXGLWf4p/qJNaLcl1Uh9AFAmqvmVMACgkQJNaLcl1U h9AOdwf/aRa54oHd6iLCPXNAbZLDie0pnJa/Q/5sjpJoVY9ofKc2XM9djmy60YdF /VGIphT8gr6at6fLZHEBbLanu2MQC2vxW9zDh5n+Xe8HUS3sdrwtBJPSv74Mcfrf OIv6nFrVsbo1IMF7x4ncYOhOBGKyOSqhsVdt+k6jl1wuTDJBHyFs7sdL1DGRCRu/ ba4n2W+kSxVeFx3ACFyDJ8l8vLqtyotFKkpmslrPmT0yHFwOr8SOMbyQ5MPxITpx gqgLikR3OW5alOLxy1U2nWCdjNsc8UWBhx1sCnByYrUO3VmRIEx4j1l2wSVX0J7E Ck7/pSpg1NGkxVYSLCTBufqq8kgPTQ== =iy0J -----END PGP SIGNATURE----- Merge tag 'spi-fix-v7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/spi Pull spi fixes from Mark Brown: "A few driver specific fixes, none of them particularly severe or unusual" * tag 'spi-fix-v7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/spi: spi: fsl-qspi: Reprogram the clock rate when the operation frequency changes spi: spi-zynqmp-gqspi: stop the controller on shutdown spi: virtio: Use the per-transfer bits per word spi: spi-qpic-snand: avoid writing QPIC_EBI2_ECC_BUF_CFG register |
||
|
|
aa211c7a58 |
i2c-fixes for v7.3-rc4
Fixes mainly for cleanup and error handling, a good part of them
around DMA resource management.
- at91: ensure DMA channels are released on all exit paths
- imx: fix autosuspend cleanup on remove
- qcom-cci: fix device node reference leak
- atr, imx, qcom-geni: set adapter slot to NULL on registration
failure
-----BEGIN PGP SIGNATURE-----
iHUEABYKAB0WIQScDfrjQa34uOld1VLaeAVmJtMtbgUCaq+VLAAKCRDaeAVmJtMt
bqmsAP9umA0ew1WQkQGTlTJLfbQdhwy8IDS7tMRAlgL7vsUxOQEApvFqr6Xtq2j7
HiSP35cHybZlA7P2T70A+MVniCJDRQ4=
=Sn1c
-----END PGP SIGNATURE-----
Merge tag 'i2c-fixes-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/andi.shyti/linux
Pull i2c fixes from Andi Shyti:
"Fixes mainly for cleanup and error handling, a good part of them
around DMA resource management:
- at91: ensure DMA channels are released on all exit paths
- imx: fix autosuspend cleanup on remove
- qcom-cci: fix device node reference leak
- atr, imx, qcom-geni: set adapter slot to NULL on registration
failure"
* tag 'i2c-fixes-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/andi.shyti/linux:
i2c: qcom-cci: fix device_node refcount leak in cci_probe()/cci_remove()
i2c: qcom-geni: release DMA channels on probe error
i2c: imx: release DMA channels on probe error
i2c: at91: release DMA channels on remove and probe error
i2c: atr: fix dangling adapter pointer on add failure
i2c: imx: disable autosuspend on remove
|
||
|
|
b12dd0fa48 |
Input updates for v7.3-rc3
- Fixes for evdev and input compat handling to zero-initialize on-stack absinfo and force-feedback effect structures before partial or compat copies from userspace, preventing kernel stack memory disclosure - Fixes for the Synaptics RMI4 driver to prevent an out-of-bounds read when writing multi-chunk blocks over SMBus and to avoid a NULL pointer dereference during suspend/resume when the RMI device is unbound - Fixes for the soc_button_array driver to propagate -EPROBE_DEFER on non-Bay Trail/Cherry Trail platforms (fixing broken power and volume buttons on the Microsoft Surface Pro 11) and to validate the ACPI package element count before dereferencing - A fix for the adp5588-keys driver to cache the initial GPIO hardware state before registering the gpiochip so pre-configured pin states are not clobbered by GPIO hogs during registration - A fix for the cyttsp5 touchscreen driver to clamp the device-supplied HID report size before copying into the response buffer, preventing a buffer overflow - A fix for the HP SDC serio driver to use timer_shutdown_sync() on module exit so the periodic kicker timer cannot rearm itself during teardown - A fix for the eeti_ts touchscreen driver to export its OF module alias so the module autoloads on Device Tree platforms - Updates to the xpad joystick driver adding support for the Victrix Pro BFG controller and Azeron devices, and fixing the device type classification for the PDP Marvel Xbox 360 controller - Quirks for the i8042 and atkbd drivers to keep the built-in keyboards functional on the Acer Aspire Go 15 AG15-42P and Xiaomi Redmi Book Pro 16 2026 - A quirk for the Synaptics PS/2 touchpad driver disabling SMBus InterTouch on the Lenovo ThinkPad T440p (board ID 2722) so the touchpad and TrackPoint respond immediately at boot - Other minor updates and documentation fixes, including reading the "ti,poll-period" property as u32 in tsc2007, adding the mt6572 compatible to the MediaTek keypad Device Tree binding, fixing an attribute name typo in the trackpoint sysfs ABI documentation, and documenting that no new LED codes should be added to the input subsystem. -----BEGIN PGP SIGNATURE----- iHUEABYKAB0WIQST2eWILY88ieB2DOtAj56VGEWXnAUCaq9j+gAKCRBAj56VGEWX nJ5KAQDnTOivIghgIGnlKTIYLSV4cJ0fWJh7J1/ubx9soK+9RwD/bDUdyryAaSTr x95U7/fEvq/lXBFyK2LXyahuTC6vNQY= =Vsfi -----END PGP SIGNATURE----- Merge tag 'input-for-v7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/dtor/input Pull input fixes from Dmitry Torokhov: - Fixes for evdev and input compat handling to zero-initialize on-stack absinfo and force-feedback effect structures before partial or compat copies from userspace, preventing kernel stack memory disclosure - Fixes for the Synaptics RMI4 driver to prevent an out-of-bounds read when writing multi-chunk blocks over SMBus and to avoid a NULL pointer dereference during suspend/resume when the RMI device is unbound - Fixes for the soc_button_array driver to propagate -EPROBE_DEFER on non-Bay Trail/Cherry Trail platforms (fixing broken power and volume buttons on the Microsoft Surface Pro 11) and to validate the ACPI package element count before dereferencing - A fix for the adp5588-keys driver to cache the initial GPIO hardware state before registering the gpiochip so pre-configured pin states are not clobbered by GPIO hogs during registration - A fix for the cyttsp5 touchscreen driver to clamp the device-supplied HID report size before copying into the response buffer, preventing a buffer overflow - A fix for the HP SDC serio driver to use timer_shutdown_sync() on module exit so the periodic kicker timer cannot rearm itself during teardown - A fix for the eeti_ts touchscreen driver to export its OF module alias so the module autoloads on Device Tree platforms - Updates to the xpad joystick driver adding support for the Victrix Pro BFG controller and Azeron devices, and fixing the device type classification for the PDP Marvel Xbox 360 controller - Quirks for the i8042 and atkbd drivers to keep the built-in keyboards functional on the Acer Aspire Go 15 AG15-42P and Xiaomi Redmi Book Pro 16 2026 - A quirk for the Synaptics PS/2 touchpad driver disabling SMBus InterTouch on the Lenovo ThinkPad T440p (board ID 2722) so the touchpad and TrackPoint respond immediately at boot - Other minor updates and documentation fixes, including reading the "ti,poll-period" property as u32 in tsc2007, adding the mt6572 compatible to the MediaTek keypad Device Tree binding, fixing an attribute name typo in the trackpoint sysfs ABI documentation, and documenting that no new LED codes should be added to the input subsystem * tag 'input-for-v7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/dtor/input: Input: hp_sdc - shut down kicker timer on module exit Input: xpad - add support for Victrix Pro BFG Controller Input: tsc2007 - read "ti,poll-period" as u32 Input: trackpoint - fix the inertia attribute name in the ABI document Input: eeti_ts - publish the OF module alias Input: xpad - add support for Azeron devices Input: xpad - fix PDP Marvel Xbox 360 controller Input: document that no new LED codes should be added Input: soc_button_array - check btns_desc->package.count Input: soc_button_array - fix MS Surface Pro 11 probe failure Input: i8042 - add quirk for Acer Aspire Go 15 AG15-42P Input: synaptics - disable InterTouch on ThinkPad T440p (board id 2722) Input: cyttsp5 - clamp the HID report size before memcpy Input: zero ff_effect before compat copy in input_ff_effect_from_user Input: evdev - zero absinfo before partial copy in EVIOCSABS Input: synaptics-rmi4 - fix GPF in suspend and resume when unbound Input: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block() Input: atkbd - skip deactivate for Xiaomi Redmi Book Pro 16 2026 dt-bindings: input: mediatek,mt6779-keypad: add mt6572 Input: adp5588-keys - cache GPIO state before registering the gpiochip |
||
|
|
4a910e594a |
selinux/stable-7.3 PR 20260919
-----BEGIN PGP SIGNATURE----- iQJIBAABCgAyFiEES0KozwfymdVUl37v6iDy2pc3iXMFAmqvPSwUHHBhdWxAcGF1 bC1tb29yZS5jb20ACgkQ6iDy2pc3iXP1rBAAkK6sP+lzXynr/abxWio9UCvlN6NF jqMXtKeUeLNg/lJakXKhja/FGaK9w+Rm+zlXQQvVE7YAO5Db758JzCXMTHlK6etD T5d+GVdZj/oVcAvfGhov0guNHZqcfKTGWOXKtGV8RQWYL+f6IC1IIHnz9wNeWIfY emkfOTgAJpCkX9nXS5xTdQNUiPkUV80LFGqxXCMhxiumvyzqOhUteytfNh3UXXcs ldOWRBstUumudBe/MJR09REtQve3emHc7bZUAxSKwXxzdOPTf7UEy4Y7QXCN3Opn Dn6Dsrt6lnpIZyzUK/eOnZvQ639gDqTMW2XTmin0JIf2KGG/PhqnvOT07hOPl+X5 wqXh2wCFn+tXVi5t+S2myMUVZK56GwfRH9kMCo6ca1Ui36iYYEeoJYt7z5tsE6P5 YBdvKKJ/MPR1/uEwP/TB3UDK0o4OBjyujc6/Ka5iBoIHXKpx7MBLOo/Q0h/Wu2A0 7HYvG/4lYdWp3p5iR8cdZ+ZgdTQDWi6t5BD3JWOfWi1gHCeGgZCHTCZ9mdSoFS18 9GpXFXTR4yM5pfwxQEAu6jFH0esSB92HJBd/yS7sU8EIUQ+0XmOge+gVPifMrhWj yOHCR7hlAYE5ds51w3ZVOYI0slkYImqCHEdlCz1DiKzyLmQQmfJvshOIvBCl7uwn LRHu6Mo0cEBMAvc= =kiQE -----END PGP SIGNATURE----- Merge tag 'selinux-pr-20260919' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux Pull selinux fixes from Paul Moore: - Ensure that the cached SELinux access decisions are correct - Fix the SELinux overlayfs code to properly track the top-level/user information on multiple stacked overlayfs filesystems - Fix the SELinux overlayfs code to properly enforce mprotect() access control policy on all of the different layers in multiple stacked overlayfs filesystems * tag 'selinux-pr-20260919' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux: selinux: recheck intermediate backing files on mprotect() selinux: preserve user SID across nested backing files selinux: always fill AVC decision in avc_has_perm_noaudit() |
||
|
|
7362a1553e
|
i2c: qcom-cci: fix device_node refcount leak in cci_probe()/cci_remove()
The of_node_put() matching of_node_get() runs after i2c_del_adapter(),
whose trailing memset() zeroes adap->dev and thus adap->dev.of_node,
making the put a no-op and leaking the node on every adapter removal
and error cleanup.
Use a devm action: the pointer is captured at registration, out of
reach of that memset(), and devres runs the put once on probe failure
and detach, replacing the three manual of_node_put() calls. The
setup loop uses the scoped iterator form so the child node is released
automatically if devm_add_action_or_reset() fails mid-loop.
Suggested-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Fixes:
|
||
|
|
268aacb2e2
|
i2c: qcom-geni: release DMA channels on probe error
geni_i2c_init() grabs exclusive GPI tx/rx DMA channels when the serial
engine runs in GPI mode. If i2c_add_adapter() subsequently fails, probe
returns without releasing the channels, because the remove callback is
not invoked after a failed probe.
The adapter-registration failure path used to release the channels via
its err_dma label; that release was dropped when the probe tail was
restructured into geni_i2c_init().
Release the channels on the adapter-registration failure path, mirroring
geni_i2c_remove().
Fixes:
|
||
|
|
e9f03b9625
|
i2c: imx: release DMA channels on probe error
i2c_imx_dma_request() acquires exclusive tx/rx DMA channels and is
optional: on errors other than -EPROBE_DEFER the driver falls back to
PIO mode and probe continues. If i2c_add_numbered_adapter() then fails,
probe returns through clk_notifier_unregister without releasing the
channels, because the remove callback is not invoked after a failed
probe.
Release the channels on the probe error path, mirroring
i2c_imx_remove().
Fixes:
|
||
|
|
f7eeb1af85
|
i2c: at91: release DMA channels on remove and probe error
at91_twi_configure_dma() requests exclusive tx/rx DMA channels, but
nothing ever releases them on driver detach, and the probe error path
after the channels are acquired (i2c_add_numbered_adapter() failure)
returns without releasing them either, because the remove callback is
not invoked after a failed probe.
Move the release into a helper, call it from the existing
configure-failure path, the adapter-registration failure path, and
at91_twi_remove().
Fixes:
|
||
|
|
c21eaa72f0 |
posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list
Kijo analyzed another race in the POSIX CPU timer code: Commit |
||
|
|
518e5b794c |
for-7.3-rc3-tag
-----BEGIN PGP SIGNATURE-----
iQJPBAABCgA5FiEE8rQSAMVO+zA4DBdWxWXV+ddtWDsFAmqu3wQbFIAAAAAABAAO
bWFudTIsMi41KzEuMTIsMiwyAAoJEMVl1fnXbVg7Y5kQAJ1ANaQWod+AUKhgbtA6
IcEFH8AAVrrTqqN0SxOl/tqHL6Xt/5mKlQcTpYPxeccUkp72M9BeGik4Gp7OwN1D
vkVTgrmhHT4r+4ae4GJP0yCtNJBa0fRXjsMFbNYTKGWcz9yOsW1OkBsq8VtRo7ym
CSVBc57buUi0mzbnLNDh69G/YA7NCTyaxXKjPARNYy+cy0LMIDmgZCByhgePQvzB
aqJUakRKpaeXEQIf0nT/70XcGhXNtfK1GOnLZM1ySFqLufMzdTsEzFsT8dVugqU1
wr1HMaMq1iNKwE4sJgNWS84wRT1zxZopKIOsTufFu98Zb2C0kvUSjWeJSqtFM88G
ggj/jmaoRhCU1cXE1jvZWy4Fe5zQH8deSQZ7zUB4ZzqCaDRwOEAj4IpuQQ9Ok91E
J/07SCvKPk/QUPbA2e5lwRL3aximsD1LfRxWIOZ+xg/HVX+vYfHmy5gzkl/hhfrm
RHkHLz8iXNHV7qhIVzZ/GYvTxR6U6nbLVUbkl5n/8eFePM7YHnoWtvMHT71qWwrh
mPx8uTK+4BI2+rAHTKqxnwEQ27OHj5odlGKTlKiaMrQR9eqnnhJLTMPDJMzqQ7TI
ZiibxG8UqSTsNbvOXXtd7MykSRpSb/VWyJImKuw30kx3f7f2yd1aCUyU4T7o5N/3
FRI+2AbkoSeype3Rw+VcEPoi
=WxSA
-----END PGP SIGNATURE-----
Merge tag 'for-7.3-rc3-tag' of git://git.kernel.org/pub/scm/linux/kernel/git/kdave/linux
Pull btrfs fixes from David Sterba:
"Among the regular fixes, there are two that were reported recently and
have user impact:
- filesystem id is now stable again on the default and common case
(it broke openconnect key derivation, while this is not secure,
it's still in use), the intention was to change id for the
temp_fsid use case
- fix detection of /dev/root and rename it after device scan, this
broke booting of initramdisk-less system with grub2 as the probe
needs the real device
Regular fixes:
- don't store compressed inline extent if the size is larger than
uncompressed
- in zoned mode, handle activation of zones for all supported block
group profiles in case there are still free ones left
- check space for a chunk item when reading sys array from superblock
- allow using space reserves when removing verity items fails
- fix error handling after free space tree rebuild fails
- abort transaction if reflink or hole punching fails and it's not
possible to update the inode
- properly protect block group iteration during device replace start
- error message fixups"
* tag 'for-7.3-rc3-tag' of git://git.kernel.org/pub/scm/linux/kernel/git/kdave/linux:
btrfs: derive f_fsid with dev_t only when temp_fsid is active
btrfs: add "/dev/root" exception for device path update
btrfs: check if there is space for chunk item when validating sys chunk array
btrfs: abort transaction on failure to update inode for hole punching and reflinking
btrfs: clear free space tree creation state on rebuild failure
btrfs: handle lack of space when cleaning up verity items
btrfs: fix creation of compressed inline extents that don't save space
btrfs: tree-checker: fix error message regarding free space extent items
btrfs: tree-checker: print dev extent offset in error message
btrfs: take commit root semaphore when iterating in mark_block_group_to_copy()
btrfs: zoned: handle RAID profiles in btrfs_can_activate_zone()
|
||
|
|
63edf5a009 |
x86/build/64: Prevent native builds from generating EGPR use
Omar reports that CONFIG_X86_NATIVE_CPU=y allows builds to opportunistically emit instructions using %r16-%r31 (EGPRs) when the build host supports APX since the commit: |
||
|
|
40288c9206 |
drm fixes for 7.3-rc4
core: - fix vblank pending event leak ttm: - swapout fixes dma-buf: - scattergather fixes - enable dma-buf debug on debug kernels dma-fence: - fix signaling bit checks sched: - fix virtual runtime race msm: - DT: - Corrected indentation - Core: - Marked fbdev as system memory - GPU: - Fixed autosuspend cleanup on teardown - a750: fix timestamps - Increase GMU fw init timeout - Misc fixes/cleanups - DPU: - Fixed clock rounding, unbreaking newest platforms - Cleared pending flush state - DP: - Skip PUSH_IDLE when link was never enabled - Fixed bandwidth checks - HDMI: - Fixed runtime PM cleanup on probe failure xe: - shrinker related fixes - xe_mmio_gem fault handler and destroy fixes - xe disable i2c irq on unbind i915: - Revert a commit touching registers that don't necessarily exist - Check for negative numbers before passing to BIT() amdgpu: - SMU 14.x fix - DC IRQ fix - Runtime PM fix for P2P - RAS fix - PCIe reporting fix - DCN 6 fix - Device removal fix - DC MALL fix amdkfd: - GC 12.x fixes - Boundary checks - Mapping clear fix nouveau: - suspend/resume fixes gud: - out of bounds access fix - ignore damage clips in full update vc4: - use-after-free fix -----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEEEKbZHaGwW9KfbeusDHTzWXnEhr4FAmqttwkACgkQDHTzWXnE hr73Ww//S+8xgr8cpmJxoUrOrTnd4yeX/oj+HSRkEHQPdNayOf+pNnP4y+nChfXi ddQ3jTRyG5JwNmXRG0ouKf9koQk/V54R8v9CBtNQYsN2K58xW6riCIaEeOUbe3r1 1IQgYCEfS32b7/9D2lo1768LbJ0KWBr6qznKrfvC7vJ62wK3F0B9EzOmsKSzLxd3 gdUfyxEbtgegKOAamCbUyJyuzCErGkMAtkQ0HnmQGYmqqBBRS7Uvl1HN10JMoLSM MmR40g+dsp6ZzBDywNrdmIGDv749o1/k/zm5i6c2hJSibYBPR5sWtKICwu1ND44u ts2HjJJdyhm5PLiS09i9nVUnMkzV0N2czIDZvt9izp8+k8P4Bh/y1iagda1G0U65 h7dp9j8WXMCApxXNjplNgjMLSO7g4UJI1rAWjxGY4ecu62XHErrZ6tbjrOVOaa1T Xh8IN4EqPr+tRSKnW4AxwwwA1EfxNwoJSxglAvBvIaCjEhRWRlj7Sdo0Wrtg3WKy sORar40ySYHR+MeAbabewjRoMPq1Nyqh4D2PrOv48a4MK7a6Fl5ed6EHpyOSHYKF 7tMbLLLtDMIYX24wd/j8CkvhcTp09iphzXSqmUlIBn3t1gbrXspzCQtRU0UrsamJ QSbtL+qUoYSsobmpYOzuTVnO8W4oOnnIYaLz+TpVNDd7o7nzZf0= =EC37 -----END PGP SIGNATURE----- Merge tag 'drm-fixes-2026-09-19' of https://gitlab.freedesktop.org/drm/kernel Pull drm fixes from Dave Airlie: "Things have picked back up a bit this week, mostly amdgpu, xe and msm this time. There are a bunch of scattered changes across the rest of drivers and core stuff, nouveau, i915. core: - fix vblank pending event leak ttm: - swapout fixes dma-buf: - scattergather fixes - enable dma-buf debug on debug kernels dma-fence: - fix signaling bit checks sched: - fix virtual runtime race msm: - DT: - Corrected indentation - Core: - Marked fbdev as system memory - GPU: - Fixed autosuspend cleanup on teardown - a750: fix timestamps - Increase GMU fw init timeout - Misc fixes/cleanups - DPU: - Fixed clock rounding, unbreaking newest platforms - Cleared pending flush state - DP: - Skip PUSH_IDLE when link was never enabled - Fixed bandwidth checks - HDMI: - Fixed runtime PM cleanup on probe failure xe: - shrinker related fixes - xe_mmio_gem fault handler and destroy fixes - xe disable i2c irq on unbind i915: - Revert a commit touching registers that don't necessarily exist - Check for negative numbers before passing to BIT() amdgpu: - SMU 14.x fix - DC IRQ fix - Runtime PM fix for P2P - RAS fix - PCIe reporting fix - DCN 6 fix - Device removal fix - DC MALL fix amdkfd: - GC 12.x fixes - Boundary checks - Mapping clear fix nouveau: - suspend/resume fixes gud: - out of bounds access fix - ignore damage clips in full update vc4: - use-after-free fix versilicon: - plane format fix longsoon: - blend mode property fix" * tag 'drm-fixes-2026-09-19' of https://gitlab.freedesktop.org/drm/kernel: (59 commits) drm/amd/display: fix MALL hysteresis timer underflow at high refresh rates drm/amdgpu: fix rmmio iounmap skipped on device removal drm/amdgpu: Skip KFD mapping clear before initialization drm/amd/display: Fix NULL dereference in dcn50/dcn60 init_hw drm/amdkfd: Avoid integer underflow in EOP ring size calculation. drm/amdkfd: Avoid integer underflow with ffs in EOP ring size calc drm/amdgpu: Fix GPU PCIe link capability reporting drm/amdgpu: check ras and obj before dereference drm/amdgpu: hold a runtime PM reference for P2P dma-buf attachments drm/amdkfd: implement restore_mqd callbacks for GFX12/12.1 drm/amd/display: Atomize IRQ register read/modify/write ops drm/amd/pm: report energy accumulator for smu 14.0.3 drm/loongson: Create blend mode property for cursor plane drm/xe/i2c: Disable IRQ on unbind Revert "drm/i915/display: Clear SEL_FETCH_PLANE_CTL on plane disable" drm/verisilicon: remove ARGB formats from primary plane drm/verisilicon: add primary modifier for format tables drm/verisilicon: set blend mode for the cursor plane drm/sched: Fix virtual runtime race drm/i915/display: check configuration index before shifting ... |
||
|
|
71f370e9ee |
Two ttm fixes for ttm_tt_swapout(), one page-alignment and one overflow
fix for dma-buf, a drm_pending_vblank_event leak fix for drm, suspend/resume fixes for nouveau, one out-of-bounds access fix for gud, a use-after-free fix for vc4, a fence signaling fix, a race condition fix for sched, planes formats fixes for verisilicon, and add the blend mode property for loongson -----BEGIN PGP SIGNATURE----- iJUEABMJAB0WIQTkHFbLp4ejekA/qfgnX84Zoj2+dgUCaqvVAAAKCRAnX84Zoj2+ dtThAX9JC7SWXw+n4o9EUsxNqvlpviwe8AS7aJR++rq/sZM0an7zl0aCJu/E8p+/ JRkO+X8BfjE+2CX8RWKH63ed95vA+9DF8JfryBTSJiSz4forppFfwH7uovT3nqq2 eOon6nJQzg== =Utup -----END PGP SIGNATURE----- Merge tag 'drm-misc-fixes-2026-09-17' of https://gitlab.freedesktop.org/drm/misc/kernel into drm-fixes Two ttm fixes for ttm_tt_swapout(), one page-alignment and one overflow fix for dma-buf, a drm_pending_vblank_event leak fix for drm, suspend/resume fixes for nouveau, one out-of-bounds access fix for gud, a use-after-free fix for vc4, a fence signaling fix, a race condition fix for sched, planes formats fixes for verisilicon, and add the blend mode property for loongson Signed-off-by: Dave Airlie <airlied@redhat.com> From: Maxime Ripard <self@mripard.dev> Link: https://patch.msgid.link/aqvVENQ4ksJEIcdb@houat |
||
|
|
17e7b8eacf |
smb client fixes for v7.3-rc4
A batch of bug fixes for the smb client:
- Fix multiple out-of-bounds reads and use-after-frees in the SMB2/3
receive path that are reachable from a malicious or compromised
server: a stale next_buffer pointer and an integer overflow in
compound encrypted frame handling, missing minimum-PDU-size and
per-sub-PDU length validation before parsing command-specific
response fields, missing bounds checks in DFS referral, server
interface list, EA list, POSIX SID, snapshot enumeration and SMB1
reparse point parsing
- Fix use-after-frees and races in multichannel and connection
teardown, including an interface freed while still in use when
adding channels, a server used after its channel reference was
dropped, a reconnect work item left queued after the server is
freed and an uninitialized reconnect list node
- Fix a heap overflow in the native symlink parser: an absolute
target without an NT drive prefix caused out-of-bounds writes and a
u16 length underflow leading to a 64K memcpy into a small buffer,
triggerable by a user with write access to a mounted share under
default settings
- Fix WSL reparse point parsing: use unaligned accessors for the
packed extended-attribute payload to avoid alignment faults on some
architectures and stop leaving partially mutated fattr fields on
parse failure
- Fix lease break ACKs being sent through the wrong session on
multiuser mounts, which caused read failures (e.g. on NetApp
ONTAP/Azure Files) when copying files
- Fix an smbd_connection leak when cifs_get_tcp_session() fails after
an RDMA connection was already established
-----BEGIN PGP SIGNATURE-----
iHUEABYKAB0WIQTcqRusfSdYROJQwGkpVtNKoQNdYwUCaq2frwAKCRApVtNKoQNd
Y1mcAQDcDTkep03jzghyJG6xWJ3S7KNbeYpjkOPnPyR+Et7HmAD/eXLFvgkJ3wC7
tBUDjDTLeyP6/DOBmDb/fIKEw2vfBQs=
=+Vsw
-----END PGP SIGNATURE-----
Merge tag 'cifs-fixes-7.3-rc4' of https://git.manguebit.org/linux
Pull smb client fixes from Paulo Alcantara:
"A batch of bug fixes for the smb client:
- Fix multiple out-of-bounds reads and use-after-frees in the SMB2/3
receive path that are reachable from a malicious or compromised
server: a stale next_buffer pointer and an integer overflow in
compound encrypted frame handling, missing minimum-PDU-size and
per-sub-PDU length validation before parsing command-specific
response fields, missing bounds checks in DFS referral, server
interface list, EA list, POSIX SID, snapshot enumeration and SMB1
reparse point parsing
- Fix use-after-frees and races in multichannel and connection
teardown, including an interface freed while still in use when
adding channels, a server used after its channel reference was
dropped, a reconnect work item left queued after the server is
freed and an uninitialized reconnect list node
- Fix a heap overflow in the native symlink parser: an absolute
target without an NT drive prefix caused out-of-bounds writes and a
u16 length underflow leading to a 64K memcpy into a small buffer,
triggerable by a user with write access to a mounted share under
default settings
- Fix WSL reparse point parsing: use unaligned accessors for the
packed extended-attribute payload to avoid alignment faults on some
architectures and stop leaving partially mutated fattr fields on
parse failure
- Fix lease break ACKs being sent through the wrong session on
multiuser mounts, which caused read failures (e.g. on NetApp
ONTAP/Azure Files) when copying files
- Fix an smbd_connection leak when cifs_get_tcp_session() fails after
an RDMA connection was already established"
* tag 'cifs-fixes-7.3-rc4' of https://git.manguebit.org/linux:
cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
smb: client: fix reparse buffer bounds in cifs_query_reparse_point()
smb: client: fix potential OOB read in smb3_enum_snapshots()
smb: client: fix missing iov bounds check in parse_posix_sids()
smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs()
smb: client: reject short Next offsets in parse_server_interfaces()
smb: client: fix missing lower-bound check on DFS referral string offsets
smb: client: fix server->total_read for compound encrypted PDUs
smb: client: validate minimum PDU size before smb2_get_data_area_len()
smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
smb: client: fix use-after-free of iface in cifs_try_adding_channels()
smb: client: fix fattr leaking on wsl_to_fattr() failure
smb: client: fix unaligned access in WSL reparse point parser
smb: client: fix smbd_connection leak on cifs_get_tcp_session() error
smb: client: fix rlist race and missing initialization
smb: client: cancel reconnect work in clean_demultiplex_info()
smb/client: send lease break ACKs thru correct session for multiuser mounts
smb: client: validate absolute native symlink targets before NT fixups
|
||
|
|
925724c081 |
SCSI fixes on 20260918
Four driver fixes, three of which are minor and one of which (fnic) tries to add some logic to try to avoid MSI-X being ineffective if hyperthreading is disabled. The core fix adds validation to mode sense buffer sizes because it is used by ATA and could, theoretically, be exploited by a specially crafted USB device that can simply be plugged in to any laptop or server. Signed-off-by: James E.J. Bottomley <James.Bottomley@HansenPartnership.com> -----BEGIN PGP SIGNATURE----- iLgEABMIAGAWIQTnYEDbdso9F2cI+arnQslM7pishQUCaq2P/hsUgAAAAAAEAA5t YW51MiwyLjUrMS4xMiwyLDImHGphbWVzLmJvdHRvbWxleUBoYW5zZW5wYXJ0bmVy c2hpcC5jb20ACgkQ50LJTO6YrIXJ6AD9FODcORvjoRDhcU626EWsG/Hoy7YcMH2T bZVtZwp3hH8BAPnKar5uj3fCQxJkvI+sLKjiGultTi3llt9VaZGSTFj2 =JgQF -----END PGP SIGNATURE----- Merge tag 'scsi-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/jejb/scsi Pull SCSI fixes from James Bottomley: "Four driver fixes, three of which are minor and one of which (fnic) tries to add some logic to try to avoid MSI-X being ineffective if hyperthreading is disabled. The core fix adds validation to mode sense buffer sizes because it is used by ATA and could, theoretically, be exploited by a specially crafted USB device that can simply be plugged in to any laptop or server" * tag 'scsi-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/jejb/scsi: scsi: core: Validate MODE SENSE lengths in scsi_cdl_enable() scsi: fnic: Fix missed link-up when critical IRQ targets offline CPU scsi: ibmvfc: Add Kconfig dependency to fix link failure when NVME_FC=m scsi: qla2xxx: Fix the ql2xfc2target parameter description scsi: pm80xx: Fix the use_msix, use_tasklet and read_wwn parameter descriptions |
||
|
|
ef31d04b6d |
pci-v7.3-fixes-1
-----BEGIN PGP SIGNATURE----- iQJIBAABCgAyFiEEgMe7l+5h9hnxdsnuWYigwDrT+vwFAmqtiM0UHGJoZWxnYWFz QGdvb2dsZS5jb20ACgkQWYigwDrT+vxDxg/+Nyqg0N+1xxHnG+bsbJ7XA7v7sQY5 DcvfvnMcJg3Lx5ioED4OJwr35rQZy8E3n/swFCxvzyZQ6gp+Q3sA2wUeuqd26kCS OSuMwRj3+HsnCVlYC/LL5fUoyZ+/FFv4drDPvIl3vCo5kIoNuWJslIox1eqPgmtZ SZO70qyQcA8jjCHYqQR07kvtqyainZrOoPP5uASnRqSGVlTLI3mzKdLtzrVytgel bAb6CPKrqF1XQY2HBBH3MEU6mhXbr7zeSrncZnb0QimqHCloq4dUK+WF9ZQnxSk5 wXgftOvg2ycYhE6hUVZGrRf/fMwzWatkD/Vi9a69wKN2lspwacKCGi0LhNS1u/Em ypak/Wg0sEic5y//eOgJjIfodJLsHiyvBIZxC3ziqZj1q6Kc4pCvg1iHePFYCSQj gB4Khkm6sWx63GX02g9ytc9bl00xCkjuck8OSVExP2MhaWajlksvzy9VXsZG9BzH QianraVVqVZd+LM3eFTy16qaD7jQuNMCIzOzB3UDh2gSzO+Lr9OtK36iTsn0NELc lKjrIlh5yEp5uD9vrrD4k8xAbaVGBnzzK7Whc42rt2n/gIs2SbV8TXWTyxtk29DJ XlbUAOiBLYEuO3YWAvq47kezyafwRtBqXxjyyoZajteD+hoRFFtkcT5OcaiWVZUL qzRbS1eB3IfB/q8= =9dUn -----END PGP SIGNATURE----- Merge tag 'pci-v7.3-fixes-1' of git://git.kernel.org/pub/scm/linux/kernel/git/pci/pci Pull PCI fix from Bjorn Helgaas: - Enable clock after core reset is asserted to fix enumeration regression on i.MX6Q Apalis platforms with ASM1061/ASM1062 SATA controllers (Richard Zhu) * tag 'pci-v7.3-fixes-1' of git://git.kernel.org/pub/scm/linux/kernel/git/pci/pci: PCI: imx6: Move clock enable after core reset assertion |
||
|
|
c3d85c669d |
- Fix session expiration so that valid sessions are no longer removed
after ten seconds of inactivity when a new session setup request is
received. Sessions now expire only after credential expiration, while
stale unauthenticated sessions are cleaned up after a 45-second timeout.
- Keep earlier responses in compound requests when Query Info fails
because the output buffer is too small. The error response is appended
without truncating preceding responses.
- Return STATUS_BUFFER_OVERFLOW for partial
FILE_NORMALIZED_NAME_INFORMATION responses instead of incorrectly
returning STATUS_INFO_LENGTH_MISMATCH.
-----BEGIN PGP SIGNATURE-----
iQJKBAABCgA0FiEE6NzKS6Uv/XAAGHgyZwv7A1FEIQgFAmqtTBMWHGxpbmtpbmpl
b25Aa2VybmVsLm9yZwAKCRBnC/sDUUQhCD2GD/9OzkmZ+/kIMum8IQi9upOM5zUD
+2nyFMebJ6qXmrhOuUgLn2ptUYxO3q1B9VvzTjKrM1Vun0VuvHmHQbGUp9a/3F7c
VTncl7E3FEHqlPkLWQJFv2dS+TYYcOhjoc2TDAY9093xktcMHK5zjv4E/DV2o0bf
NN/GcrrcWSxdJU8WI9JvY2kzmPQMDfM8uVbj2RqHSZ8m9mF5cajtDnzCCS0K6UOR
qzMrekzewIskUtcQNqU8hJWl1sgiYdD+16LmKmwLd3uOZISc3Miy5Bg8VpNN+B1g
XHhr49G4Fb8PkEYjncjxQH7zop1ID5UyC2xN63NuoH8+mkm4qn6uG2NrLhmVQO+f
Z81Ov3g77/jK3Z2fw00H3A7VGSPs931BaRTNj+lPkHTVVq3PyP1XZsfXkPUoRu1Q
xeaJydScGNYE+kaYbseXwN8haJGawd1Dd+Afn4W2zikUU5tKZxO9d2tBr4Fhl/Fm
0OBcAssTArhrY7PX2fAOQ4sUwAC4nMXSEIfdWIvcgU2OoyuFltQ55ooCoM0uLs6+
7R4rxZLipdZmKhuE2mlAWcFQJn8nS0EHXeyEDjO0u8KYsV6C8d+jDNpvtS+/5QVF
bKE4/uUX/lV0IZ55nFSPT7XdI+gxeiUql3+8bqOVqkw7wR4VjaC0xIQybyEBTMYH
IJEKfjx4tZcWGTzmdA==
=9nNl
-----END PGP SIGNATURE-----
Merge tag 'ksmbd-for-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/linkinjeon/smb
Pull smb server fixes from Namjae Jeon:
- Fix session expiration so that valid sessions are no longer removed
after ten seconds of inactivity when a new session setup request is
received.
Sessions now expire only after credential expiration, while stale
unauthenticated sessions are cleaned up after a 45-second timeout.
- Keep earlier responses in compound requests when Query Info fails
because the output buffer is too small. The error response is
appended without truncating preceding responses.
- Return STATUS_BUFFER_OVERFLOW for partial
FILE_NORMALIZED_NAME_INFORMATION responses instead of incorrectly
returning STATUS_INFO_LENGTH_MISMATCH.
* tag 'ksmbd-for-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/linkinjeon/smb:
ksmbd: keep compound responses on query info errors
ksmbd: fix partial normalized name responses
ksmbd: follow SMB2 session expiration semantics
|
||
|
|
bfda5a01aa |
- Make MFT extension work on existing Windows-created volumes by
dynamically reserving MFT tail records, accounting for records added
during allocation, and avoiding false -ENOSPC failures.
- Repack non-resident $MFT/$ATTRIBUTE_LIST when its mapping pairs no longer
fit in the base MFT record, while propagating allocation and writeback
errors.
- Serialize runlist updates with the runlist lock and restore both the
in-memory runlist and on-disk mapping pairs when allocation rollback is
required.
- Propagate folio errors and harden inode failure handling by treating
interrupted reads as transient failures and discarding and unhashing
inodes whose initialization fails.
- Fix the $MFTMirr write offset when mirror records span multiple folios,
preventing mirror records from overwriting the first record with large
MFT record sizes.
-----BEGIN PGP SIGNATURE-----
iQJKBAABCgA0FiEE6NzKS6Uv/XAAGHgyZwv7A1FEIQgFAmqtRIEWHGxpbmtpbmpl
b25Aa2VybmVsLm9yZwAKCRBnC/sDUUQhCBK8EAChFdTxig3sYog3dL27SX+1yNC4
S1QtSQMvPJzcvLG2/mESC57snx1u6AXZ6enaQ/m8zQQvkWHFdwD+odgjOQ3474Yc
MS7xQn5pCsAo3LmSWiDsQfHmvxgDMYlIRU1vmqr7fG2pj+W6BR2LB1PD3RI9exI7
0WWAXBPZH5w5C9GE1Zo7TF9Xwby5Or31RS8+R57PXA/PJ1ivpWnlkpfLi4M/YkZK
GIpunZafSpcKbEsuWcjhdz11bR4G9Qlwuuq0MDguLC/qsqsobHCeSbdx+4IsEAq5
02yBl5hYm2E4u2KBedpe7oRwFvlPN0uakEGYS8SA1ad9XamjGIw6T0tkzkDL48Pq
dhVAeX2oa8O9u+VK+qF/HIUylh/UbmHQJW8iSiZWO8WdULGBG8oCHI1hcSnMguwJ
njyK75UXz4fMsKW6ZpRu0sRGqtKKcbg8IrCvLslPIOS2A9OAwSzytDKI+x1Kbgu0
SVPYjf6XeOz83tvE+2OhfTT1hWkeKezMiUe4E/y9rgEDxv5vE4C5pvpDfRlj3oyn
2JTXXjjUQGSQw/9cKbLsbElDH/FLEojLAsIFgM+2FbcG+x7PUUgSGdC4R4qZ9MUF
cuMzfhi8vKyCYmJc8nNE4J6b6UkBNOFJMYBcArtByFW3LqfIzmqwW81Xx0Hz4cxi
dmOhD6gXXYoi9m3lBQ==
=rT1L
-----END PGP SIGNATURE-----
Merge tag 'ntfs-for-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/linkinjeon/ntfs
Pull ntfs fixes from Namjae Jeon:
- Make MFT extension work on existing Windows-created volumes by
dynamically reserving MFT tail records, accounting for records added
during allocation, and avoiding false -ENOSPC failures
- Repack non-resident $MFT/$ATTRIBUTE_LIST when its mapping pairs no
longer fit in the base MFT record, while propagating allocation and
writeback errors
- Serialize runlist updates with the runlist lock and restore both the
in-memory runlist and on-disk mapping pairs when allocation rollback
is required
- Propagate folio errors and harden inode failure handling by treating
interrupted reads as transient failures and discarding and unhashing
inodes whose initialization fails
- Fix the $MFTMirr write offset when mirror records span multiple
folios, preventing mirror records from overwriting the first record
with large MFT record sizes
* tag 'ntfs-for-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/linkinjeon/ntfs:
ntfs: fix $MFTMirr write offset when it spans multiple folios
ntfs: unhash failed inode reads
ntfs: discard inodes that fail initialization
ntfs: ignore interrupted inode reads as corruption
ntfs: propagate folio errors
ntfs: protect runlist updates with the runlist lock
ntfs: account for MFT records added during allocation
ntfs: repack $MFT/$ATTRIBUTE LIST
ntfs: use dynamic MFT tail reservation
|
||
|
|
8cb0606271 |
MMC core:
- Prevent potential use-after-free for SDIO IRQ work - Fix OF node reference leak on card add failure - Fix memory lea when the port table is full for sdio_uart MMC host: - hsq: Fix use-after-free in retry work - mmci: Fix use-after-free in busy-timeout work - mmc_spi: Reset bytes_xfered before retrying CRC failures - mxcmmc: Cancel data work and watchdog on remove - rtsx_pci_sdmmc: Ignore broken write-protect on ThinkPad X260 - sdhci_am654: A couple of fixes for the tuning sequence - sdhci-of-aspeed: Remove children before releasing SDC resources - sh_mmcif: Initialize IRQ-thread mutex before requesting interrupt MEMSTICK: - ms_block: Destroy io_queue workqueue on removal -----BEGIN PGP SIGNATURE----- iQJEBAABCgAuFiEEugLDXPmKSktSkQsV/iaEJXNYjCkFAmqtI4oQHHVsZmhAa2Vy bmVsLm9yZwAKCRD+JoQlc1iMKcjwD/91lyNP8fb8cxorEtmkiNt63Sb+glVEnobW aOlXS23GuV9ZsPw7kKEEfZ4EWCOTEZ86Lj0OMzlpXE8dxYHGlu0qG97uxSiJ4wux LQ0+OR5ljqDN48BWrn3wWsJ1YLfM4xXL7XukiCEuxLU9jwlbPHNjtY8c0+JqMapH D1yE7tH7/ZPJuYwKt9DJlx5DKg0BTiRn/7j+o3IETNyuBP05ZzrUjNdgQW8DVawg 2uR0GCZ268Asd7XhnywvLXbeg5jxRAEVMGVjEzn2CY5uY0YyUW9ye9e+TpbNqpYf OA2MnYiTNpcRIiI3Z8R5vrhGxMpqFd5hFdIUE64O5gnjSyrBKeo9SSw4huXlLvac xjdBYmtLxSQjIgvZaEG4hl12lJt/snLJODTEq690zei9oWCUnCKzZaargLFPcDje 0J8HwPYStynI0nc2Jc4oGZEGGwgvSmFPk15JtMEdmJb3eIwOfzGLA1ky9+5VEVCC zzMifnvnseAJwz+iAaJYxkED3Gd4t/jm4n8XIihddsKBQHAbMtGhUmhSzNnzD6NF xgscpv8s8SKExwS6X+6f/SBZD4VoF9b1JDhJ+fVUJDQ1Dsgv9AyT/bl8gDBHPNwr JHflPaQhc3hM9RppdcZnW3KSCu3DCJ04XaoHy6m5zKWZHUBEAtxujHA5u373Wv89 StY7v7d7UQ== =KPXN -----END PGP SIGNATURE----- Merge tag 'mmc-v7.3-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/ulfh/mmc Pull MMC/MEMSTICK fixes from Ulf Hansson: "MMC core: - Prevent potential use-after-free for SDIO IRQ work - Fix OF node reference leak on card add failure - Fix memory lea when the port table is full for sdio_uart MMC host: - hsq: Fix use-after-free in retry work - mmci: Fix use-after-free in busy-timeout work - mmc_spi: Reset bytes_xfered before retrying CRC failures - mxcmmc: Cancel data work and watchdog on remove - rtsx_pci_sdmmc: Ignore broken write-protect on ThinkPad X260 - sdhci_am654: A couple of fixes for the tuning sequence - sdhci-of-aspeed: Remove children before releasing SDC resources - sh_mmcif: Initialize IRQ-thread mutex before requesting interrupt MEMSTICK: - ms_block: Destroy io_queue workqueue on removal * tag 'mmc-v7.3-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/ulfh/mmc: mmc: sdhci-of-aspeed: Remove children before releasing SDC resources mmc: sh_mmcif: initialize IRQ-thread mutex before requesting interrupt mmc: core: Fix OF node reference leak on card add failure mmc: rtsx_pci_sdmmc: ignore broken write-protect on ThinkPad X260 mmc: sdio_uart: fix xmit_fifo leak when the port table is full mmc: spi: reset bytes_xfered before retrying CRC failures mmc: sdhci_am654: Fallback to DT-provided itap delay on DDR50 tuning failure mmc: sdhci_am654: Clear ITAPDLY on tuning failure mmc: sdhci_am654: Reset command and data lines on failed tuning mmc: sdhci_am654: Move tuning_loop to local variable mmc: hsq: Fix use-after-free in retry work mmc: mxcmmc: cancel data work and watchdog on remove mmc: mmci: Fix use-after-free in busy-timeout work mmc: core: Cancel SDIO IRQ work before freeing host memstick: ms_block: destroy io_queue workqueue on removal |
||
|
|
ae09f35bd3 |
ata fixes for 7.4-rc4
- Explicitly clear upper address bits on quirked AHCI controllers
AHCI controllers that claim to support 64-bit DMA, but which have
been quirked to only do 32-bit DMA, could start the DMA engine
with a non-zero value in the upper address bits registers (me)
- Fix a resource leak in ahci_platform_get_resources() (Wentao)
- Fix invalid kernel-doc formatting for ata_dsm_trim_pages() (me)
-----BEGIN PGP SIGNATURE-----
iHUEABYKAB0WIQRN+ES/c4tHlMch3DzJZDGjmcZNcgUCaq0h5wAKCRDJZDGjmcZN
cla0AQD9oseos93LDPzXR5SSMirdjoL9Qee8RsVeIMMlRtahiAD/Tx+vlEYrQ3QG
yESu9KV1YCaV2qDzG+nFjNt9Z6uc4wo=
=xqFb
-----END PGP SIGNATURE-----
Merge tag 'ata-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/libata/linux
Pull ata fixes from Niklas Cassel:
- Explicitly clear upper address bits on quirked AHCI controllers
AHCI controllers that claim to support 64-bit DMA, but which have
been quirked to only do 32-bit DMA, could start the DMA engine with a
non-zero value in the upper address bits registers (me)
- Fix a resource leak in ahci_platform_get_resources() (Wentao)
- Fix invalid kernel-doc formatting for ata_dsm_trim_pages() (me)
* tag 'ata-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/libata/linux:
ata: libata-scsi: fix ata_dsm_trim_pages() kernel-doc
ata: libahci_platform: Fix device reference leak in ahci_platform_get_resources()
ata: libahci: clear PxCLBU and PxFBU for AHCI_HFLAG_32BIT_ONLY
|
||
|
|
d24e3bf4c5 |
hwmon fixes for v7.3-rc4
* cgbc-hwmon: Add missing sensors, and fix current sensors ID lookup
* gpioufan: Return IRQ_HANDLED from the shared alarm IRQ handler to fix
possible interrupt storm
* hp-wmi-sensors: Improve raw WMI string handling, and fix UaF in show
function
* k10temp: Fix model id range of Zen5 Turin to stop reporting temperature
data for non-existing CCDs
* pmbus
- core: Increase number of phases to fix UaF problems
- tps53679: Fix TPS53676 phase page decoding, and select page 0
for single-page applications
* pwm-fan: Stop RPM timer before freeing tach data to fix UaF problem
* w83793: Release probe data through kref to fix UaF problem
* w83791d: Remove fan/pwm 4-5 sysfs group on remove to fix UaF problem
-----BEGIN PGP SIGNATURE-----
iQIzBAABCAAdFiEEiHPvMQj9QTOCiqgVyx8mb86fmYEFAmqtY4YACgkQyx8mb86f
mYHX0Q//UmlkmqkHH3XdKi1QX/RV60f82HfzXRkMq98FYocEYv4TKnru3U5pRLY3
Vs/h4GcDWT16ApqKbciBxgoUj72XBohm/T0gv8rhC/gkx4w8F7/CPuCB6vq9kIAj
EIOHM3KoulfwUN6K1JeFdo5sIrTMxYGnQoJjS31/HfExEGbcBMZjA4eWLkqA0s18
zmtYKbCJbG2WFRkI8/HKeQ2MwFE3RLNrxPVNvWJNzwIPjMvaAD7eDSsRjgXpaH6s
A2OHpnGkDLE1qeyuYYx+nFYmMQDGDxnt6QvEjX5cVUYE+jDIXuzF5HJVfLCaXoSJ
cFJmyNVTNE6Is1g6qeBRwObSq/NJH3O6p7kXCf5qwO27XBXgt/7K4q751tMq8oEE
kXiYn3WfBL4WJjYqQw8kEh2/D18fyj9XmoS7iBXzf1qXgRSROm/9irMBjsWiw0WF
92iE9U7UaE/a5fGX+dbRnB7QmLZ33U5TzA3ERb+MwJQj6o8Llvb5gmJOmlYebpa1
zRiu285Y3oGnjjkFgzvpps9hsVw3kb2Xs2utMbTPrJ2z4SUO9KInl+ifOr5w9VI+
sNU0Rn3eQ6IT40NMO9FhHPciZygKmob6hNDYh/6e+OulMDW7XW46ES2e8jjwME30
fjDpfKDxoAU/xQ548XQJBRcUNjUhV8S6NYZr3H4PpyWlPVmSkOY=
=lG35
-----END PGP SIGNATURE-----
Merge tag 'hwmon-for-v7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/groeck/linux-staging
Pull hwmon fixes from Guenter Roeck:
- Add missing sensors, and fix current sensors ID lookup (cgbc-hwmon)
- Return IRQ_HANDLED from the shared alarm IRQ handler to fix possible
interrupt storm (gpioufan)
- Improve raw WMI string handling, and fix UaF in show function
(hp-wmi-sensors)
- Fix k10temp model id range of Zen5 Turin to stop reporting
temperature data for non-existing CCDs
- pmbus:
- Increase number of phases to fix UaF problems
- Fix TPS53676 phase page decoding, and select page 0 for
single-page applications
- Stop pwm-fan RPM timer before freeing tach data to fix UaF
- Release w83793 probe data through kref to fix UaF
- Remove w83791d fan/pwm 4-5 sysfs group on remove to fix UaF
* tag 'hwmon-for-v7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/groeck/linux-staging:
hwmon: (hp-wmi-sensors) Improve raw WMI string handling
hwmon: (pmbus/tps53679) Select page 0 for single-page TPS53676
hwmon: (pmbus/tps53679) Fix TPS53676 phase page decoding
hwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show()
hwmon: (w83793) release probe data through kref
hwmon: (w83791d) remove fan/pwm 4-5 sysfs group on remove
hwmon: (gpio-fan) return IRQ_HANDLED from the shared alarm IRQ handler
hwmon: (pmbus/core) increase number of phases and add new mask
hwmon: (cgbc-hwmon) Add missing sensors
hwmon: (cgbc-hwmon) Fix current sensors ID lookup
hwmon: (pwm-fan) Stop RPM timer before freeing tach data
hwmon: (k10temp) Fix model id range of Zen5 Turin
|