Commit Graph

1483612 Commits

Author SHA1 Message Date
Linus Torvalds
415f204422 Landlock fix for v7.3-rc5
-----BEGIN PGP SIGNATURE-----
 
 iIYEABYKAC4WIQSVyBthFV4iTW/VU1/l49DojIL20gUCarVI0xAcbWljQGRpZ2lr
 b2QubmV0AAoJEOXj0OiMgvbSEVgA+gNbC9CVCbCo0oufZbVpQwlwtuuEKEVpvxZx
 q7oFYKCsAP9svCujGCXRHOmWhAAwe+wpXNb43l8coFn+pCfA8x3fCw==
 =NOli
 -----END PGP SIGNATURE-----

Merge tag 'landlock-7.3-rc5' of git://git.kernel.org/pub/scm/linux/kernel/git/mic/linux

Pull Landlock fixes from Mickaël Salaün:
 "This mainly fixes the Landlock tracepoint support merged this cycle so
  that denial and rule events report the intended policy context,
  whether through tracefs or BTF-visible callbacks.

  The size of this all is mainly from propagating the corrected contract
  through event definitions and producers, adding new tests for the
  reported context, and updating the documentation.

  Also improve annotation and fix a GCC 16 build warning"

* tag 'landlock-7.3-rc5' of git://git.kernel.org/pub/scm/linux/kernel/git/mic/linux:
  landlock: Widen ruleset versions to 64 bits
  landlock: Add counted_by in landlock_domain
  landlock: Fix tracepoint contract documentation
  selftests/landlock: Test network denial context
  selftests/landlock: Test filesystem denial blockers
  landlock: Report the effective signal number
  landlock: Report the actual ptrace tracer
  landlock: Fix network denial trace context
  landlock: Fix rule tracepoint context
  landlock: Fix filesystem denial blocker reporting
  landlock: Fix tracepoint fixed-width type names
  landlock: Work around gcc-16 -Wuninitialized warning
2026-09-24 10:53:59 -07:00
Linus Torvalds
5fc5768c7c bpf-fixes
-----BEGIN PGP SIGNATURE-----
 
 iQJRBAABCgA7FiEE+soXsSLHKoYyzcli6rmadz2vbToFAmq1NvAdHGFsZXhlaS5z
 dGFyb3ZvaXRvdkBnbWFpbC5jb20ACgkQ6rmadz2vbTpmpA//fqEoC6Sq1zxo3ADH
 hV0Z9ewkNTjjH85QnispjcRkAhSHG3JscNXKRXm1NmNkwJsHJ4TDIKcjABYDjquD
 wqfvL9hLXPsvud0M/PR6/CZeBAWXpukkaxeYedY+83ttTHjzR0tDq0Ne9yvIV+Nc
 hS0qFIIHs8C6l2nyuNSxvgrv216orG8qd0Bi3tpDfsLqCsLLEmDyQ1H+ZzpJF2xW
 RV3oMcggCeo305m8+uiofQGf8hmmRrmA7SEfF+Qe08ab2GOn9glINfVTbTE3AdQW
 fkvAk8Zuio3hwwMBHDWWYXrKO0N3ykzcDk4V6JPUWiH1dOANf1tS3G1uJyxb4tsv
 dHVdA0xL3sg7YnuSywfb82vTXvQz5QEFeDYxxLB2fMJe8LcCfgF1lkIr1DbdrMjI
 hlozGCs3p/GVIVNhjGVPezWsUvzK4PIuKVM6U1qWojtAhXU/bJCvP0iBU83RlBL7
 S0GGSC/qvkuPed9hAp2pnrrRo/9GEp1PZq8AXsp3nti0OaRxgxpjjQQFzZEWlOrR
 bErtbKziHzl2xARvCRycNZ+QWT4ZdjmK++8pba7hOuFkRclOV4KRWk4OthBvcADu
 NfNsVXdXpOnesg7TNIUJ8heVAYPjKaBHJBuG2Prghrnc95uqEQwOfbYT15zAbe6I
 l3HqGerSa7WtbrnCwsf1DvyPPII=
 =ZxKg
 -----END PGP SIGNATURE-----

Merge tag 'bpf-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf

Pull bpf fixes from Alexei Starovoitov:

 - Fix bpf_skb_change_tail() to drop the checksum offload instead of
   rejecting the trim of CHECKSUM_PARTIAL skbs (Daniel Borkmann)

 - Add KF_PERFMON kfunc flag and require CAP_PERFMON for kfuncs that
   read arbitrary memory and for untrusted read-only memory reads
   (Daniel Borkmann)

 - Clear scalar delta on narrowing stack spill (Daniel Borkmann)

 - Set up the frame pointer for the exception callback in arm64 JIT, and
   zero-fill other CPUs when BPF_F_CPU update creates a per-cpu hash
   element (Donggeun Yoo)

 - Various fixes (Emil Tsalapatis):
     - Fix bounds check underflow for skb-backed dynptrs
     - Fix rx_queue_mapping context access code generation in bpf_sock
     - Reject packet pointer arguments to subprogs that may mutate the
       packet
     - Reject ALU instructions that see arena and non-arena operands on
       different code paths

 - Fix copied_seq double-counting on sockmap self-redirect
   (Geliang Tang)

 - Fix divide-by-zero in btf_struct_walk() on a flexible array of
   zero-sized elements, fix out-of-bounds read of rtt_min in sock_ops
   (Jiayuan Chen)

 - Fix bpf_sock_destroy() out-of-bounds read of sk_protocol on TIME_WAIT
   and request socks, and sleeping under RCU when destroying a listener
   with pending children (Jiayuan Chen)

 - Fix JEQ/JNE with immediate operand in MIPS32 JIT and missing zero
   extension of BSWAP 16/32 in MIPS64 JIT (Johan Almbladh)

 - Avoid soft lockup in htab lookup[_and_delete] batch operations on
   large maps (Jose Fernandez)

 - Various fixes (Kumar Kartikeya Dwivedi):
     - Verify global subprogs in each sleepability context they are
       called from
     - Make post-verification instruction rewrites killable
     - Preserve packet pointer displacement in regsafe()
     - Apply CO-RE relocations before subprogram validation, restrict
       CO-RE poisoning to relocatable instructions, and reject truncated
       ldimm64 CO-RE relocations in libbpf
     - Assign lock identity to callback map values
     - Compare stack frames in regs_exact()
     - Bound ownership depth through local kptrs and graph roots

 - Fix u32 overflow in map batch operations when the map size exceeds
   4GB (Masoud Aghasi)

 - Fix UAF in bpf memalloc due to concurrent consumption of ttrace lists
   in alloc_bulk() (Pu Lehui)

 - Allow gotox as the terminal instruction of a program or a subprogram
   (Siddharth Chintamaneni)

 - Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL, skip unsettled links
   in link iterator, and reject dev-bound-only programs on other devices
   (Weiming Shi)

 - Reject non-negative stack offsets in stack_slot_obj_get_spi()
   (Xu Yunxiang)

 - Check params size before reading reserved fields in
   bpf_crypto_ctx_create() (Yuqi Xu)

 - Reject max_entries > INT_MAX in sock_map_alloc() (Zhao Gongyi)

 - Use a 32-bit compare in xsk_map_gen_lookup() (Zhiling Zou)

 - Use kvfree() in xdp_test_run_teardown() (Zhixing Chen)

* tag 'bpf-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf: (58 commits)
  selftests/bpf: Test per-cpu initialization of a BPF_F_CPU created element
  bpf: Zero-fill other CPUs when BPF_F_CPU creates a per-cpu hash element
  bpf: Fix BSWAP 32 and 16 on MIPS64
  bpf: Fix immediate JMP JEQ/JNE on MIPS32
  bpf: Reject dev-bound-only programs on other devices
  bpf, sockmap: Reject max_entries > INT_MAX in sock_map_alloc
  selftests/bpf: Test for mixed arena/nonarena code paths
  bpf: Prevent variable arena/non-arena register contents
  selftests/bpf: Test rejection of pkt args to mutating subprogs
  bpf: Reject pkt arguments in mutating subprogs
  selftests/bpf: Add selftests for rx_queue_mapping context access
  bpf: Fix bpf_sock context code generation
  selftests/bpf: Test dynptr slices past end of skb
  bpf: Fix bounds check for skb-backed dynptrs
  selftests/bpf: Reject iterator destruction through fp+0
  bpf: Reject non-negative offsets in stack_slot_obj_get_spi()
  bpf: Check params size before reading reserved fields
  selftests/bpf: Check local object ownership depth
  bpf: Bound ownership depth through local kptrs and graph roots
  selftests/bpf: Cover frame changes in bounded loops
  ...
2026-09-24 08:25:26 -07:00
Alexei Starovoitov
1b1dca5682
Merge branch 'bpf-fix-per-cpu-initialization-of-a-bpf_f_cpu-created-hash-element'
Donggeun Yoo says:

====================
bpf: fix per-cpu initialization of a BPF_F_CPU created hash element

A BPF_F_CPU update that creates a [lru_]percpu_hash element writes the
named CPU's slot and leaves the others holding the recycled element's
values, so a lookup of the new key returns a deleted key's per-cpu
values.

Patch 1 zero-fills the other CPUs.  Patch 2 adds the selftest: the
existing cpu_flag subtests always prime a key with BPF_F_ALL_CPUS
first, so the create path is not covered today.

v1: https://lore.kernel.org/bpf/20260920093153.439743-1-donggeunyoo.kernel@gmail.com/
v2: https://lore.kernel.org/bpf/20260923000801.1764758-1-donggeunyoo.kernel@gmail.com/

Changes in v3:
 - patch 1: key init_cpu on BPF_F_CPU rather than on onallcpus (Leon
   Hwang)
 - patch 1: re-flow the paragraph naming pcpu_copy_value() (BPF CI AI
   review)
 - patch 2: pin the thread across the delete and the create, and name a
   CPU other than the pinned one, so the BPF_F_NO_PREALLOC arm does not
   depend on staying put (BPF CI AI review)

Changes in v2:
 - patch 1: cover the BPF_F_CPU entry condition in the block comment
   above pcpu_init_value() (BPF CI AI review, Alexei Starovoitov)
 - patch 2: skip the new subtests instead of failing them on a
   uniprocessor machine (Sashiko AI review)
====================

Link: https://patch.msgid.link/20260924102321.2120434-1-donggeunyoo.kernel@gmail.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
2026-09-24 14:25:01 +00:00
Donggeun Yoo
3422808f4e
selftests/bpf: Test per-cpu initialization of a BPF_F_CPU created element
The existing cpu_flag subtests always prime a key with BPF_F_ALL_CPUS
before any BPF_F_CPU write, so the create path is never covered.

Add a subtest that creates the element with BPF_F_CPU on a map with
max_entries 1, so the key can only reuse the element the previous key
released, and check that the CPUs the update did not name read back
zero.  Run it for PERCPU_HASH preallocated and BPF_F_NO_PREALLOC,
whose per-cpu areas come from different allocators, and for
LRU_PERCPU_HASH.

Under BPF_F_NO_PREALLOC the reuse is only guaranteed on the cpu that
ran the delete, so pin the thread across the pair, and name a cpu other
than that one in map_flags.

Signed-off-by: Donggeun Yoo <donggeunyoo.kernel@gmail.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://patch.msgid.link/20260924102321.2120434-3-donggeunyoo.kernel@gmail.com
2026-09-24 14:24:52 +00:00
Donggeun Yoo
c3a66e5f5b
bpf: Zero-fill other CPUs when BPF_F_CPU creates a per-cpu hash element
pcpu_init_value() initializes the per-cpu area of a newly created
[lru_]percpu_hash element.  The area is recycled, so when the value
comes from a BPF program (onallcpus == false) it writes the running
CPU's slot and zeroes the rest.

bpf_percpu_hash_update() passes onallcpus == true, which delegates to
pcpu_copy_value().  pcpu_copy_value() writes only the CPU named in
map_flags when BPF_F_CPU is set, so on the create path the other slots
keep the recycled element's values:

  update(k1, 0xdeadc0de, BPF_F_ALL_CPUS)  every CPU holds 0xdeadc0de
  delete(k1)                              element back on the freelist
  update(k2, 0xc0ffee, BPF_F_CPU | 0)     creates, writes CPU 0 only
  lookup(k2)                              CPU 0 0xc0ffee, rest 0xdeadc0de

Zero-fill the other CPUs on that arm too.

Fixes: c6936161fd ("bpf: Add BPF_F_CPU and BPF_F_ALL_CPUS flags support for percpu_hash and lru_percpu_hash maps")
Signed-off-by: Donggeun Yoo <donggeunyoo.kernel@gmail.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://patch.msgid.link/20260924102321.2120434-2-donggeunyoo.kernel@gmail.com
2026-09-24 14:24:51 +00:00
Linus Torvalds
f49a343b30 Pin control fixes for the v7.3 series:
- Serialize the calls to pinctrl_generic_dt_nod_to_map()
 
 - Fix a typo in S4 group in the Meson driver.
 
 - Fix bank width and regmap usage in the MPFS-SSIO driver.
 
 - Data register output latch behavior and voltage encoding
   fixes in the Sunxi driver.
 
 - Free the IRQ domain on the error path in the single driver.
 
 - Fix some QUP1 SE2/SE3 groups and a missing OF module
   alias in the Qualcomm drivers.
 
 - Fix up the register banks for AON (I guess always-on)
   pins in the Tegra238 driver.
 
 Signed-off-by: Linus Walleij <linusw@kernel.org>
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEElDRnuGcz/wPCXQWMQRCzN7AZXXMFAmq1Bm4ACgkQQRCzN7AZ
 XXM36g//fk1LQHrRfCHR4VmPTP8SIielpN4J6RaTdVZYrOF5HB4FU1nkJvhgNH73
 YAiIeBR/XG7gevMnfuE3w9H6zSrw7bb4l1+piV+o4T5Zo1SNC2WAnHdIXJ/isrZq
 rHjwBcd5kvit+2VlaUxLZERc8V8L7+t6rD1+QDDrgqd2Ji3ekKB5bB4kdumuE5Yp
 c+oirXvcgC7Bi2Ql35HTeWFmie5IAbfAHFiXryUwJREZNbakS17sQRXQxesib0fi
 UPml71+vDVluKtluB065PwE8W4JpLi7+SkhMcB4xgT/ofMt46wzTtCU6VfBaTM/0
 dHLr6Kr9ajjmNzk5i3DZMFFY2C2ywqyGCCfgTO2m5wX9WaBNFoO8UsZ9Xb/Ij+RZ
 9T6Ub6QCJcvvZIScRXTAQEKiJ4I4cMOt1wL4rJfX8YQA0Aha9r7YXxnLxBM7AgvB
 8AzIJcgm5RSC2uJaRnNpSgOvBk6XYXGnC22MTbDR3CIdkYZcWy7M9XLYI21UtCOh
 ZmYvxiJGHoa2qe+AgHYgvO5lFIW9qTUOL11XXQJQwziTC7A/I/Qnf6Gwyq12KE1Q
 TuAGRqeWCo4UPEYhc5myKceF1J6ljJosWwsF3VH9Vj4N2/CHIcbikWE33g1qCIbf
 VCsPaPKegsLoK4nNau0z296nqNmNFjmuyTn8gcdEMlQYGP4WwhA=
 =PxJM
 -----END PGP SIGNATURE-----

Merge tag 'pinctrl-v7.3-2' of git://git.kernel.org/pub/scm/linux/kernel/git/linusw/linux-pinctrl

Pull pin control fixes from Linus Walleij:

 - Serialize the calls to pinctrl_generic_dt_nod_to_map()

 - Fix a typo in S4 group in the Meson driver

 - Fix bank width and regmap usage in the MPFS-SSIO driver

 - Data register output latch behavior and voltage encoding
   fixes in the Sunxi driver

 - Free the IRQ domain on the error path in the single driver

 - Fix some QUP1 SE2/SE3 groups and a missing OF module alias
   in the Qualcomm drivers

 - Fix up the register banks for AON (I guess always-on) pins
   in the Tegra238 driver

* tag 'pinctrl-v7.3-2' of git://git.kernel.org/pub/scm/linux/kernel/git/linusw/linux-pinctrl:
  pinctrl: tegra238: Fix register bank for AON pin groups
  pinctrl: qcom: ipq5210: Publish the OF module alias
  pinctrl: qcom: nord: Split QUP1 SE2/SE3 into lane-pair functions
  pinctrl: single: free the IRQ on domain creation failure
  pinctrl: sunxi: A523: fix voltage withstand encoding
  pinctrl: sunxi: keep a shadow copy of the data register output latches
  pinctrl: mpfs-mssio: use correct regmap function to set bank voltage
  pinctrl: mpfs-mssio: fix width of unused bank voltage setting
  pinctrl: generic: serialise pinctrl_generic_dt_node_to_map()
  pinctrl: meson: Fix typo in s4 group name
2026-09-24 06:19:09 -07:00
Linus Torvalds
e2936d228b memblock: add missing HugeTLB flag name
Rework of HugeTLB bootmem allocation forgot to add the name for a new
 RSV_HUGETLB flag for proper display in debugfs.
 
 Add the flag name now.
 -----BEGIN PGP SIGNATURE-----
 
 iQEzBAABCgAdFiEEeOVYVaWZL5900a/pOQOGJssO/ZEFAmq00GcACgkQOQOGJssO
 /ZFJxwf/TlhW+APk3p9UXHTMXTvsefWxrox7mlVEBAh+nqpiF43aDeZySV6IW4yr
 cHqBpI+yheyiuh1dOqfsPB/8b8jFV2GyBmknD+QbRhJi5Q8KXALVYgaKIi2WXaj5
 rHNuVn7aTwUbwEBaiwrFWfWce6GSLqFGoDYTb2iSg1Z/ZdOXnWeTil8iOONCAMSw
 3h8joiqPV7OlNDInxWYrlwDAvPo5Sr0VwBT7+GpuahjVB21l/XINPMwZUmLucF3t
 y3+WHYTAH8f98KF0pBzJeD7XJX/nupeyzKhvJHLbg6XxbvFh3pz3OTts4tQA3Khy
 REwmEB/v9Hbl1wsfA6XNROkgQN+l5g==
 =t0mt
 -----END PGP SIGNATURE-----

Merge tag 'fixes-2026-09-24' of git://git.kernel.org/pub/scm/linux/kernel/git/mm/memblock

Pull memblock fix from Mike Rapoport:
 "The rework of HugeTLB bootmem allocation forgot to add the name for a
  new RSV_HUGETLB flag for proper display in debugfs.

  Add the flag name now"

* tag 'fixes-2026-09-24' of git://git.kernel.org/pub/scm/linux/kernel/git/mm/memblock:
  mm: memblock: add missing HugeTLB flag name
2026-09-24 06:16:19 -07:00
Linus Torvalds
ef33dd4e0a arm64 fixes for -rc5
- Fix the recently merged user ABI for the Arm CMN PMU driver filtering
   logic so that the ordering matches the hardware spec
 
 - Fix spurious warning when attempting to read PROT_NONE mappings of
   /dev/mem
 
 - Allow WFxT to be disabled on the command line, which is necessary for
   some configurations of recent Apple SoCs
 
 - Fix EL2 fine-grained trap configuration for the CPU PMU
 
 - Fix MIDR matching when applying CPU errata workarounds in a VM
 -----BEGIN PGP SIGNATURE-----
 
 iQFEBAABCgAuFiEEPxTL6PPUbjXGY88ct6xw3ITBYzQFAmq06TIQHHdpbGxAa2Vy
 bmVsLm9yZwAKCRC3rHDchMFjNPGQCACK7VeQk7ER46znaeMNyHaQARWkuF7D3wdU
 wCvt/hppo6DzHpsiWw5rDrBIHyeVpWkilDVROuaM1q8Qf6HaFe2h+sbuK96OVo1Y
 OLP1aZUBj3ZGLUNBIxDANP4A200Avd6gFLLY2jPvZ2YyJfEB9Ok3D0KahaRdtMh9
 PGX4qo3j7dZaTLChMrVhXApAidkZ079w5+Di5wXilU5QNyCWsfA+SKBY7jZWP7jw
 yPQ5PPDeYDYUziCUT4ooAegY9vODgmtbikXPFQQzF0zPeTtqKuFwSekdXnkJQS3E
 R3+bBmV5JrDuitjMqUvrxreTGZqWj6R1mHL4tsActCnhTFEc2mar
 =dNHO
 -----END PGP SIGNATURE-----

Merge tag 'arm64-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux

Pull arm64 fixes from Will Deacon:

 - Fix the recently merged user ABI for the Arm CMN PMU driver filtering
   logic so that the ordering matches the hardware spec

 - Fix spurious warning when attempting to read PROT_NONE mappings of
  /dev/mem

 - Allow WFxT to be disabled on the command line, which is necessary for
   some configurations of recent Apple SoCs

 - Fix EL2 fine-grained trap configuration for the CPU PMU

 - Fix MIDR matching when applying CPU errata workarounds in a VM

* tag 'arm64-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux:
  arm64/boot: Disable trapping of PMZR_EL0 writes to EL2
  arm64: errata: match the target implementation CPU's own MIDR
  arm64: Add override for WFxT
  arm64: io: Reject non-user protection in ioremap_prot()
  perf/arm-cmn: Fix multi-filter encoding
2026-09-24 06:08:15 -07:00
Johan Almbladh
8110ba0977
bpf: Fix BSWAP 32 and 16 on MIPS64
The 16/32-bit byteswap implementations for MIPS64r1 and earlier do
not have an explicit zero extension afterwards. The input is first
sign-extended to 64 bits, and the byteswap sequence can then leave
the result sign-extended depending on the value of the low bits.

Add the missing zero-extension.

Found with test_bpf on MIPS64r1 emulated by QEMU.

Fixes: fbc802de6b ("mips, bpf: Add new eBPF JIT for 64-bit MIPS")
Signed-off-by: Johan Almbladh <johan.almbladh@anyfinetworks.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://patch.msgid.link/20260923105158.3514342-2-johan.almbladh@anyfinetworks.com
2026-09-24 01:57:52 +00:00
Johan Almbladh
db762fd96b
bpf: Fix immediate JMP JEQ/JNE on MIPS32
An addu instruction was emitted instead of addiu, causing the immediate
value 1 to be interpreted as register $at. This made the comparison
result invalid when the immediate operand was negative. Note that $at
is mapped to BPF_REG_AX, which is used for constant blinding.

Fix the instruction to use the immediate form.

Found with test_bpf on MIPS32r1 emulated by QEMU.

Fixes: eb63cfcd2e ("mips, bpf: Add eBPF JIT for 32-bit MIPS")
Signed-off-by: Johan Almbladh <johan.almbladh@anyfinetworks.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://patch.msgid.link/20260923105158.3514342-1-johan.almbladh@anyfinetworks.com
2026-09-24 01:57:48 +00:00
Linus Torvalds
62f4c998b2 parisc architecture fixes for kernel v7.3-rc5:
- Increase kernel stack to 32kB on 64-bit kernel to avoid crashes
 - Parse early parameters in setup_arch() to enable huge page settings
 - Replace open-coded binary search with bsearch() in unwind code
 - Remove unused <asm/compat_ucontext.h> header
 -----BEGIN PGP SIGNATURE-----
 
 iHUEABYKAB0WIQS86RI+GtKfB8BJu973ErUQojoPXwUCarQ81AAKCRD3ErUQojoP
 X27mAQC1zo+e0CYtpv5EcYhUarMVJcWLVFXCkDzzHtNgx7mraQEAtVVxaqr4A+jM
 pgQfXMBpyDsKAztx38zMC/Bo//8NLgg=
 =hZkl
 -----END PGP SIGNATURE-----

Merge tag 'parisc-for-7.3-rc5' of git://git.kernel.org/pub/scm/linux/kernel/git/deller/parisc-linux

Pull parisc architecture fixes from Helge Deller:

 - Increase kernel stack to 32kB on 64-bit kernel to avoid crashes

 - Parse early parameters in setup_arch() to enable huge page settings

 - Replace open-coded binary search with bsearch() in unwind code

 - Remove unused <asm/compat_ucontext.h> header

* tag 'parisc-for-7.3-rc5' of git://git.kernel.org/pub/scm/linux/kernel/git/deller/parisc-linux:
  parisc: Increase kernel stack size to 32kb
  parisc: parse early parameters in setup_arch()
  parisc: remove unused <asm/compat_ucontext.h> header
  parisc: unwind: Replace open-coded binary search with bsearch()
2026-09-23 14:15:03 -07:00
Fuad Tabba
2bc6b21871 arm64/boot: Disable trapping of PMZR_EL0 writes to EL2
__init_el2_fgt2() writes one mask to both HDFGRTR2_EL2 and HDFGWTR2_EL2.
PMZR_EL0 is write-only, so its trap bit, nPMZR_EL0, exists only in
HDFGWTR2_EL2 and is therefore never set: a PMZR_EL0 write from the host
traps to EL2, where the nVHE hypervisor has no handler and BUG()s. The
kernel never writes PMZR_EL0, but kernel.perf_user_access=1 has the PMU
driver set PMUSERENR_EL0.UEN for a task with a user-read event, so a
write from EL0 reaches the trap and takes the host down without a panic
message.

Accumulate the HDFGWTR2_EL2 bits separately, as __init_el2_fgt() already
does for HDFGWTR_EL2, and set nPMZR_EL0 with the other FEAT_PMUv3p9
bits.

Fixes: 858c7bfcb3 ("arm64/boot: Enable EL2 requirements for FEAT_PMUv3p9")
Cc: stable@vger.kernel.org
Signed-off-by: Fuad Tabba <fuad.tabba@linux.dev>
Reviewed-by: Anshuman Khandual <anshuman.khandual@arm.com>
Reviewed-by: Oliver Upton <oupton@kernel.org>
Signed-off-by: Will Deacon <will@kernel.org>
2026-09-23 12:34:30 +00:00
Weiming Shi
6db1ce73e9
bpf: Reject dev-bound-only programs on other devices
__bpf_offload_dev_match() falls back to comparing offdev pointers after an
exact netdev mismatch. Bound-only programs normally have NULL offdevs, so
unrelated netdevs compare equal. A bound-only program on an
offload-registered netdev can instead inherit a real offdev and match a
sibling port. With CAP_BPF and CAP_NET_ADMIN, a caller can use
bpf(BPF_LINK_CREATE) with a different target ifindex to run metadata kfuncs
specialized for the bound driver on the target driver's xdp_buff. Running a
veth-bound program on tun reads beyond tun's bare stack xdp_buff as a
veth_xdp_buff.

  Oops: general protection fault, probably for non-canonical address
  KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017]
  RIP: 0010:veth_xdp_rx_timestamp (drivers/net/veth.c:1673)
  Call Trace:
   ...
   tun_build_skb (drivers/net/tun.c:1739)
   tun_get_user (drivers/net/tun.c:1856)
   tun_chr_write_iter (drivers/net/tun.c:2091)
   vfs_write (fs/read_write.c:595 fs/read_write.c:687)
   ksys_write (fs/read_write.c:739)
   do_syscall_64 (arch/x86/entry/syscall_64.c:84)
   entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
  Kernel panic - not syncing: Fatal exception in interrupt

Restrict non-offloaded programs to exact netdev matches and retain the
shared-offdev fallback only for genuinely offloaded multi-port programs.

Fixes: 2b3486bc2d ("bpf: Introduce device-bound XDP programs")
Reported-by: <co+ac0a8c41de69121d@bugs.sh>
Signed-off-by: Weiming Shi <bestswngs@gmail.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://lore.kernel.org/bpf/20260917161335.1020405-2-bestswngs@gmail.com/
Link: https://patch.msgid.link/20260920132303.4109240-3-bestswngs@gmail.com
2026-09-23 02:19:02 +00:00
Zhao Gongyi
814a81c842
bpf, sockmap: Reject max_entries > INT_MAX in sock_map_alloc
sock_map_alloc() only rejects max_entries == 0 and otherwise allows any
u32 value.  sock_map_free() then walks the sks[] array with a signed int
iterator:

	int i;
	for (i = 0; i < stab->map.max_entries; i++)
		struct sock **psk = &stab->sks[i];

When a SOCKMAP is created with max_entries = 0xffffffff (UINT_MAX), the
allocation of 32 GiB can succeed on large-memory hosts.  During free the
counter reaches 0x80000000, wraps to INT_MIN, is sign-extended by movslq
and turned into a ~16 GiB negative offset from stab->sks, pointing far
below the allocation.

The faulting access is an xchg() write in sock_map_free().  Without
KASAN, the same out-of-bounds write can fault on an unmapped vmalloc page
or corrupt an unrelated allocation if that vmalloc address is populated.
On a KASAN kernel with CONFIG_KASAN_VMALLOC=y, the shadow check for that
address hits an unmapped shadow page and oopses first:

  BUG: unable to handle page fault for address: fffff521b59c5a00
  RIP: 0010:kasan_check_range+0x107/0x190
  Call Trace:
   sock_map_free+0x93/0x190
   map_create+0x68d/0xb30
   __sys_bpf+0x21e/0x2e70

Vmcore confirmed stab->map.max_entries == 0xffffffff, stab->sks ==
0xffffc911ace2d000, and the faulting address sks + (s64)INT_MIN * 8
exactly at 0xffffc90dace2d000.  The same buggy path is reached on the
normal close()/bpf_map_free_deferred() path whenever such a map is
destroyed.

sock_map_alloc() used to bound its allocation size through
bpf_map_charge_init(), but the bound was dropped when rlimit-based memory
accounting was removed.  Reject max_entries > INT_MAX at creation time so
the signed iterator in sock_map_free() never sees a value that would
overflow.

Triggered by syzkaller and reproduced on both a 6.6-based KASAN kernel
and the upstream v7.3-rc2 kernel.

Fixes: 0d2c4f9640 ("bpf: Eliminate rlimit-based memory accounting for sockmap and sockhash maps")
Signed-off-by: Zhao Gongyi <zhaogongyi@BYTEDANCE.COM>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://patch.msgid.link/20260917121016.48171-1-zhaogongyi@bytedance.com
2026-09-22 23:52:20 +00:00
Emil Tsalapatis
a9e86dd9de
selftests/bpf: Test for mixed arena/nonarena code paths
Add a selftest to confirm the verifier rejects ALU operations
that return arena or non-arena results depending on code path.

Signed-off-by: Emil Tsalapatis <emil@etsalapatis.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://patch.msgid.link/20260922172028.6269-9-emil@etsalapatis.com
2026-09-22 19:34:05 +00:00
Emil Tsalapatis
f85f5917aa
bpf: Prevent variable arena/non-arena register contents
The verifier marks ALU instructions that include at least
one arena operand with needs_zext: These instructions are
fixed up after verification to be ALU32 instructions to
ensure that the result is a valid offset into an arena.
However, different code paths may provide two non-arena
64-bit arguments to the same instruction. The result of
the operation in that code path is wrong, since it is
now unexpectedly truncated to 32 bits and zero-extended.

Add logic to the verifier to ensure every instruction either
always has at least one PTR_TO_ARENA argument, or never does.
Since needs_zext already tracks the first scenario, add a
prevent_zext field in bpf_insn_aux to track the latter.
Reject instructions that use arena arguments and have prevent_zext
set, or do not have arena arguments and have needs_zext set.

Fixes: 6082b6c328 ("bpf: Recognize addr_space_cast instruction in the verifier.")
Reported-by: Nicholas Carlini <nicholas@carlini.com>
Suggested-by: Nicholas Carlini <nicholas@carlini.com>
Signed-off-by: Emil Tsalapatis <emil@etsalapatis.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://patch.msgid.link/20260922172028.6269-8-emil@etsalapatis.com
2026-09-22 19:34:04 +00:00
Emil Tsalapatis
1ed69a54d3
selftests/bpf: Test rejection of pkt args to mutating subprogs
Add a selftests that ensures that PTR_TO_PACKET arguments can
only be passed to subprogs that will never adjust the underlying
packet memory, and are rejected otherwise.

Signed-off-by: Emil Tsalapatis <emil@etsalapatis.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://patch.msgid.link/20260922172028.6269-7-emil@etsalapatis.com
2026-09-22 19:34:04 +00:00
Emil Tsalapatis
a6c1edfbe2
bpf: Reject pkt arguments in mutating subprogs
The verifier tracks changes in how PTR_TO_PACKET registers'
bounds are modified across subprog boundaries. PTR_TO_PACKET
registers are actually passed as PTR_TO_MEM, which is assumed
valid for the entire call. This is not the case with packet memory,
where a pskb_* call may invalidate its memory region.

Reject BPF code that passes PTR_TO_PACKET pointers to subprogs that
may mutate a packet. We cannot pass the pointer as a true PTR_TO_PACKET
because we would also need to somehow pass the PTR_TO_PACKET_META
or PTR_TO_PACKET_END to the subprog. Since we cannot avoid representing
the pointer in the subprog as PTR_TO_MEM, only permit it if the
subprog is guaranteed not to mutate the packet.

Fixes: 80f281664f5a ("bpf: Support pointers in global func args")
Reported-by: Nicholas Carlini <nicholas@carlini.com>
Suggested-by: Nicholas Carlini <nicholas@carlini.com>
Signed-off-by: Emil Tsalapatis <emil@etsalapatis.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://patch.msgid.link/20260922172028.6269-6-emil@etsalapatis.com
2026-09-22 19:34:04 +00:00
Emil Tsalapatis
dec0c209a6
selftests/bpf: Add selftests for rx_queue_mapping context access
Add tests to ensure the verifier properly tracks the 0 bit state
and width of the rx_queue_mapping field read from struct sock.

Signed-off-by: Emil Tsalapatis <emil@etsalapatis.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://patch.msgid.link/20260922172028.6269-5-emil@etsalapatis.com
2026-09-22 19:34:04 +00:00
Emil Tsalapatis
4a4852376e
bpf: Fix bpf_sock context code generation
Currently, the ctx access code reads the rx_queue_mapping
field with either a 4-byte or 2-byte load. The rest of the bits
in the register are marked known zero by the verifier. However,
the emitted ctx access code places in the register on certain
the special value (-1) using BPF_MOV_IMM64, which gets sign-extended
to turn on all the bits in the register. By shifting this value right,
the program ends up with a value at runtime above what the verifier
assumes is possible.

Fix this by ensuring the read value is as wide as the assumed size.
Use MOV32 instructions instead of MOV64 instructions to keep
the upper bits zero as assumed by the verifier. Also properly report
the size of the destination variable (the bpf_sock field, 4 bytes) instead
of the source (the socket field, 2 bytes).

Fixes: c3c16f2ea6 ("bpf: Add rx_queue_mapping to bpf_sock")
Reported-by: Nicholas Carlini <nicholas@carlini.com>
Suggested-by: Nicholas Carlini <nicholas@carlini.com>
Signed-off-by: Emil Tsalapatis <emil@etsalapatis.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Reviewed-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Link: https://patch.msgid.link/20260922172028.6269-4-emil@etsalapatis.com
2026-09-22 19:34:04 +00:00
Emil Tsalapatis
4fd72eb9f1
selftests/bpf: Test dynptr slices past end of skb
Add a selftest to ensure dynptr slices cannot include
past the end of the linear area of an skb.

Signed-off-by: Emil Tsalapatis <emil@etsalapatis.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://patch.msgid.link/20260922172028.6269-3-emil@etsalapatis.com
2026-09-22 19:34:04 +00:00
Emil Tsalapatis
ed6eec97b5
bpf: Fix bounds check for skb-backed dynptrs
The skb_pointer_if_linear() function checks whether a
memory region of length len starting at offset off into
the skb is in the linear area, and returns a pointer to
the region if so. The check currently subtracts between
skb_headlen and offset of the check, and since skb_headlen
is unsigned the subtraction can underflow. This causes the
bounds check to spuriously pass and generate an arbitrary
pointer of the form *(skb->data + off).

The only user of this helper is currently skb-backed BPF
dynptr code. Returning the wrong pointer leads to the
dynptr erroneously being backed with invalid memory.

Ensure the subtraction cannot underflow, and fail the check if
it would. Use u64 arithmetic to also prevent overflow when
calculating (skb_headlen(skb) - off) since off is unsigned.

Fixes: 6f5a630d7c ("bpf, net: Introduce skb_pointer_if_linear().")
Reported-by: Nicholas Carlini <nicholas@carlini.com>
Signed-off-by: Emil Tsalapatis <emil@etsalapatis.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Reviewed-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Link: https://patch.msgid.link/20260922172028.6269-2-emil@etsalapatis.com
2026-09-22 19:34:04 +00:00
Mickaël Salaün
e7e0a54300
landlock: Widen ruleset versions to 64 bits
Tracepoint consumers use a ruleset ID and version to identify the
successful landlock_add_rule(2) call prefix used to create a domain.
LANDLOCK_MAX_NUM_RULES bounds distinct stored rules, not successful
calls: re-adding already-present rights for an object or port succeeds
without increasing num_rules.  Because every successful call increments
the version, these calls can wrap the 32-bit counter and give different
prefixes the same trace identity.

Widen the counter and its trace fields to 64 bits so the counter cannot
wrap in practice, while preserving the successful-call semantics.
Saturating would alias all subsequent histories, while rejecting a call
at the limit would change otherwise valid syscall behavior solely for
trace metadata.

Cc: Günther Noack <gnoack@google.com>
Cc: Steven Rostedt <rostedt@goodmis.org>
Fixes: 63747c9477 ("landlock: Add landlock_add_rule_fs and landlock_add_rule_net tracepoints")
Reviewed-by: Günther Noack <gnoack@google.com>
Link: https://patch.msgid.link/20260922132615.1025945-1-mic@digikod.net
Signed-off-by: Mickaël Salaün <mic@digikod.net>
2026-09-22 20:52:13 +02:00
Tingmao Wang
bd3a19800d
landlock: Add counted_by in landlock_domain
For a domain, this array stores the access masks for each layer (of
which there are num_layers of them).  This annotation serves as useful
documentation.

Signed-off-by: Tingmao Wang <m@maowtm.org>
Reviewed-by: Günther Noack <gnoack@google.com>
Link: https://patch.msgid.link/20260208235449.1124354-1-m@maowtm.org
[mic: Rebase on the ruleset/domain split, and update commit message]
Signed-off-by: Mickaël Salaün <mic@digikod.net>
2026-09-22 20:52:11 +02:00
Linus Torvalds
fe2ec83746 hid-for-linus-2026092202
-----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCAAdFiEEL65usyKPHcrRDEicpmLzj2vtYEkFAmqyY7EACgkQpmLzj2vt
 YEnprxAAofmpQUorlic97WALU2CamXN/hdzLGlra2RPW6eJyxQUlwqR8xcUptx3e
 14OM5X4WDHfFD1lRFx7/flzn2J5h5CLXUWnNUp5DR7W0GLQSnSwOiuawfb5/Enkd
 aqhgsqC2nfEjxQ3iqdsY1MTASN/MEjolNU66tP31DQH5D+CGY6eZtivNwFHaHjJI
 Ps4/vr2nuddSCsXaWRKwdBQ9wMr8g+F7dIeI8vqAJlWg5IdN0tu3ClAuHUqMr6X3
 zMHJ7xkkrRg7S40xeQsajDiPGRRWPkC6G3lrJ1OSFOP1IEMKT5dLLg5HB2wLwfzI
 Xzw4CJZiSIaNKyMQLQJcik8wZZbc60A2ulDscbpk9PLlr9nweBc+7wzVZ0mOQ6Lo
 rD2iYG7ROG684Jt5HVd9SPrIgjCDnlOXDBT9JLyPCw38eEysEHOdSlwA0CSJyR21
 cD0UmfIUgFDXxR/omcPbZDVng8683eRR3W/Tj2XPBOyKZYF/JtnIsrbowIN2dmGe
 PKnsrtp2LW5/xiO/lTfEsiiHL8WoxtXj/Mwoq/NuZm4TvZ/C3nd3ZiEaL5UQeYYc
 AyTFOqBe4DoLauyS2M50gitvDpSBFS9i5xrjCukalpJGfTUlX8lQjU7kdH7O5rbh
 VlMjlYqPNSyd4Yo/nveqIS3ELrKGs5z3oDSxwSB05h1nCgn3dgo=
 =k0Hr
 -----END PGP SIGNATURE-----

Merge tag 'hid-for-linus-2026092202' of git://git.kernel.org/pub/scm/linux/kernel/git/hid/hid

Pull HID fixes from Jiri Kosina:

 - new device IDs/quirks (Logitech G502X, Elecom M-XT4DRBK, Steelseries
   Arctis 7, Asus Rog Z13 Folio, Lenovo Yoga Slim Gen 11)

 - fixes for various code issues found by LLMs

* tag 'hid-for-linus-2026092202' of git://git.kernel.org/pub/scm/linux/kernel/git/hid/hid:
  selftests/hid: add unnumbered variant to the hid_bpf tests
  HID: bpf: fix __hid_bpf_hw_check_params report length
  selftests/hid: add define for commonly used buf size
  HID: amd_sfh: Validate PCI BAR size before mapping
  HID: elecom: fix bus type for M-XGL20DLBK
  HID: elecom: Add support for ELECOM M-XT4DRBK (018E)
  HID: corsair-void: Fix firmware event packet description
  HID: i2c-hid: Add i2c-hid-quirk-bad-input-size quirk for 0911:5288 device
  HID: hid-oxp: use cancel_delayed_work_sync() in remove
  HID: i2c-hid: add reset quirk for Lenovo Yoga Slim 7x Gen 11 keyboard
  HID: roccat: fix locking in roccat_connect() and roccat_disconnect()
  HID: steelseries: Add support for Arctis 7 (2018)
  HID: logitech-hidpp: Add support for G502 X Lightspeed USB mouse
  HID: fix semantic patch and improve its performance
  HID: alps: fix use-after-free on input2 registration failure
  HID: alps: unregister DualPoint Stick input device on remove
  HID: winwing: fix use-after-free in force feedback teardown
  HID: multitouch: Add report ID mismatch quirk for ASUS ROG Z13 Folio
  HID: wacom: fix OOB read in wacom_wac_pen_serial_enforce()
  HID: quirks: add ALWAYS_POLL quirk for SDINNOVATION gaming keyboard
2026-09-22 10:30:17 -07:00
Linus Torvalds
34e34736ea remoteproc fixes for v7.3
Fix unbalanced handover IRQ for attached and the overwriting of the
 shutdown return value in the Qualcomm PAS remoteproc driver.
 
 Correct the conditions in the Qualcomm modem remoteproc driver for which
 secure services to require after the move to "PAS service".
 
 Ensure that the correct addresses are passed to iommu_unmap() in as
 Qualcomm ADSP carveout are torn down.
 -----BEGIN PGP SIGNATURE-----
 
 iQJCBAABCgAsFiEEBd4DzF816k8JZtUlCx85Pw2ZrcUFAmqx46IOHGJqb3JuQGty
 eW8uc2UACgkQCx85Pw2ZrcUCDRAAhm0J2Y3ol3qrFK7XrhbFvn6TewDHRD7LGntt
 VVhplPj3/QSUWduXEtyNyMV/Illx3LV8DxlmDw85doRJtcMqCeBpRkh/u71YPxYw
 PIrEmXcCjBP3iYDB+7lsX4PkgmQOgnyK+pDK+T5K0ZgE0L3vHT4k1TuyspBLHREt
 d2goRCB61qDOtqcvFuaG9MbZw69cyaeF60drUBTxaaGIcAz12X+6lBjl4xv9sjrE
 fwG/TLrGqRkoioInxuxL8OAks1ylaJtouu6bGnKK65/bvJ3ApE1/yj15Nn2kBv9J
 KjAhAPfY1MXARXa7YR9+HJOZAUMTCyx7RfYbKEsVlNUqazL6PHYWMnTgJZA5IoM0
 j8vfgvDLlZvDjl628DzhKVz4dV7P0QMBKbB1gTWzQaGNxNpgyVznyqpFl8rX7wuC
 Jp5SLR33ujMqK6iWhgexvHC4dbWux03MYovbysvz97Q3kr9U+07pIU2zIb97RS8s
 HAErFKlQLvg7MGk1RkmsXMGnxsHFYpbqvJfngnaUe2bxFuf4NwQ3li2XOrWK/UxP
 61AXNVBBI/aFOlT3VbFLC7YRpmOykGlbv3q/OKKb0s3M7ofLaSQ+F4S/j02g524o
 nZAKejx2rJO9h8ty6bsJodLorGJ5c/sjknQQyFIme3h0jmd1yNmyPpe07GHT44hH
 nbUxZzo=
 =bkNw
 -----END PGP SIGNATURE-----

Merge tag 'rproc-v7.3-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/remoteproc/linux

Pull remoteproc fixes from Bjorn Andersson:
 "Fix unbalanced handover IRQ on attach and the overwriting of the
  shutdown return value in the Qualcomm PAS remoteproc driver.

  Correct the conditions in the Qualcomm modem remoteproc driver for
  which secure services to require after the move to 'PAS service'.

  Ensure that the correct addresses are passed to iommu_unmap() as
  Qualcomm ADSP carveout are torn down"

* tag 'rproc-v7.3-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/remoteproc/linux:
  remoteproc: qcom_q6v5_pas: Fix error masking in qcom_pas_stop()
  remoteproc: qcom_q6v5_adsp: Fix iommu_unmap() usage
  remoteproc: qcom_q6v5_mss: Don't require PAS for memory protection
  remoteproc: qcom: q6v5_pas: Don't enable handover IRQ on attach
2026-09-22 10:12:54 -07:00
Linus Torvalds
c4e9f74da4 This push fixes an hmac hashing bug on s390.
-----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEn51F/lCuNhUwmDeSxycdCkmxi6cFAmqt6wMACgkQxycdCkmx
 i6e4HhAAu/G02WPXAJOG6mzrj1BQdhtBOLzQrtg/3TtX9HM8fAwakQUEToUqdYVT
 qsYxxOXRQtp5eLfDX8qX/sAHhuUF9EzsyM3e44kGw7eZ5fVFfPQk2BGSln6sqS0t
 YGb2Aq9tISP4E9ffzf1DOHo3JYuWyo38olDvGHV9bD321c/KvWxT5mKrXTdVEIQp
 vNwLBBKyCDr93iDVDBJM0OikfgMWyrl44KdAynq/H54bUd3YNi5wh1R8JhvE7fsY
 /q+vQn9vijUDruonWkNVFpohTW6VfOMmKb7iBmTDabvGICmdEx3kOCgL2TwqxKjR
 11vRlwR9ZeWIdHiL734lCft+pECC+vXceV/N79XTaSp9uCc/Lbyt5aVebvHGmNDC
 ZVRRSh43IpYyOEYJnr7UnVfjs1P4DCC+RzWjuvn4m+67V2L1Wfr+WbohoLKEwobu
 vF2CETzWxg0a5C+i+SzzYnj1r6RjOH49QGZwpnT1JwhT9ADBkVSXdqzEbYEbQuRu
 Z5FtX4DcCMqSN0le1Hpxlu2Y05NRD2ZtHAgGSEc8ySqvZGSUiDVqewyjLFbRVYCu
 D/DPVHEwA3uIR4pONu/4lQz74jX0KNIj7nHapSmlIv9HP5d4nUNrSp7XxNL2exKC
 zppAX9KGNzGgZ6kfXo6ceeh+WGbYEoDoORGmFmg5dgDiqpI3/WY=
 =ATO6
 -----END PGP SIGNATURE-----

Merge tag 'v7.3-p5' of git://git.kernel.org/pub/scm/linux/kernel/git/herbert/crypto-2.6

Pull crypto fix from Herbert Xu:
 "This fixes an hmac hashing bug on s390"

* tag 'v7.3-p5' of git://git.kernel.org/pub/scm/linux/kernel/git/herbert/crypto-2.6:
  crypto: s390/hmac - Generate intermediate CV for API partial block handling
2026-09-22 10:10:08 -07:00
Linus Torvalds
a52a93358a 14 hotfixes. 10 are cc:stable. 11 are for MM.
Five are DAMON fixes.  One fixes an arm64 contpte bug where DAMON can
 write past the end of a page-table page, resulting in memory corruption
 and possible crashes.
 
 Two are hugetlb fixes.  One fixes an mremap() address calculation bug
 which can panic x86-64.
 
 There's also a missing anon_vma publication barrier which can result in
 hung tasks, and a writeback fix to keep long cgroup writeback drains from
 delaying Tasks-RCU grace periods.
 
 The remainder are smaller fixes and maintenance changes.
 -----BEGIN PGP SIGNATURE-----
 
 iHUEABYKAB0WIQTTMBEPP41GrTpTJgfdBJ7gKXxAjgUCarHHNAAKCRDdBJ7gKXxA
 jhb7AP4yE/k7RrZC6zWg4M9ejI3fVlHI9+EG1mCLGiV57jZ4mAEA9LLSZryOD6Nc
 zsaeCtZhHcEdxW6EhO18hMfH4b7oJA0=
 =alhC
 -----END PGP SIGNATURE-----

Merge tag 'mm-hotfixes-stable-2026-09-21-17-08' of git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm

Pull MM fixes from Andrew Morton:
 "14 hotfixes.  10 are cc:stable.  11 are for MM.

  Five DAMON fixes: one fixes an arm64 contpte bug where DAMON can write
  past the end of a page-table page, resulting in memory corruption and
  possible crashes.

  Two hugetlb fixes: one fixes an mremap() address calculation bug which
  can panic x86-64.

  There's also a missing anon_vma publication barrier which can result
  in hung tasks, and a writeback fix to keep long cgroup writeback
  drains from delaying Tasks-RCU grace periods.

  The remainder are smaller fixes and maintenance changes"

* tag 'mm-hotfixes-stable-2026-09-21-17-08' of git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm:
  MAINTAINERS: update Xu Xin's email
  writeback: report a Tasks-RCU quiescent state per cgwb drain pass
  mm/damon/core: reset invalid quota->charge_target_from
  MAINTAINERS: add Baoquan and Baolin as MGLRU reviewers
  mm/rmap: fix missing barrier between anon_vma init and vma->anon_vma publish
  mm/hugetlb: preserve mremap address delta when skipping page tables
  mm/damon/core: fix unconditionally skip last region
  mm/damon/vaddr: avoid hw-driven pte updates during damon_hugetlb_mkold()
  mm/damon/core: allow esz to be set to zero
  mm/damon/ops-common: use a page-aligned address in damon_ptep_mkold()
  ocfs2: make ocfs2_calc_xattr_init() return void
  mailmap: update Haowen Bai's email address
  selftests/cgroup: account for zswap shrinker writeback
  mm/hugetlb: do not dissolve gigantic pages without runtime support
2026-09-22 10:03:33 -07:00
Andrii Nakryiko
0b6e06f950 Merge branch 'bpf-reject-non-negative-stack-object-offsets'
Xu Yunxiang says:

====================
bpf: Reject non-negative stack object offsets

Reject non-negative offsets before converting a stack object address to a
stack slot index. Add a regression test for iterator destruction through
fp+0.

Changes in v2:
- Split the kernel change and selftest as requested by Andrii.
- Rebase onto bpf/master at a11212910c.
- Keep the original code and test changes unchanged and retain Sun Jian's
  Reviewed-by on both parts.

v1: https://lore.kernel.org/bpf/20260911084314.3481637-1-xyx2021@mail.ustc.edu.cn/
Split request: https://lore.kernel.org/bpf/CAEf4BzbYzt-Riekpc-A=MfQft9ZELwSDSE8kkQO1ZOyR3O_FAg@mail.gmail.com/

Validation on this exact candidate with a matching bpf_testmod:
  - W=1 verifier, full kernel/modules, changed BPF objects and test_progs
    builds passed.
  - iters: 1/97 passed; 0 skipped.
  - dynptr: 2/132 passed; 0 skipped.
  - irq: 1/33 passed; 0 skipped.
  - res_spin_lock: 3/14 passed; 1 skipped.
  - file_reader: 1/8 passed; 0 skipped.
  - kmem_cache_iter: 1/3 passed; 0 skipped.
  - dmabuf_iter: 1/4 passed; 0 skipped.

No selected test failed. The VM ran with panic_on_warn and panic_on_oops;
no kernel WARN, Oops or panic was found.

res_spin_lock_stress skips because the VM has no hardware PMU.

Annotated verifier tests check load outcomes and diagnostics. The full
unfiltered suite, sanitizer configurations and architecture matrix were
not run.

Please queue this fix for stable after it reaches the BPF tree.
====================

Link: https://patch.msgid.link/20260920210423.345636-1-xyx2021@mail.ustc.edu.cn
Signed-off-by: Andrii Nakryiko <andrii@kernel.org>
2026-09-21 15:01:00 -07:00
Xu Yunxiang
8244668cbb selftests/bpf: Reject iterator destruction through fp+0
Add a verifier regression test that initializes a numeric iterator at fp-8
and attempts to destroy it through fp+0. The verifier must reject the
non-negative offset instead of treating it as the initialized stack slot.

Check the offset diagnostic to ensure rejection happens at the stack
object address check. The numeric iterator destroy operation is a no-op;
this test checks verifier rejection and does not run the program.

Signed-off-by: Xu Yunxiang <xyx2021@mail.ustc.edu.cn>
Signed-off-by: Andrii Nakryiko <andrii@kernel.org>
Reviewed-by: Sun Jian <sun.jian.kdev@gmail.com>
Link: https://lore.kernel.org/bpf/20260920210423.345636-3-xyx2021@mail.ustc.edu.cn
2026-09-21 15:00:59 -07:00
Xu Yunxiang
79a9172f3a bpf: Reject non-negative offsets in stack_slot_obj_get_spi()
bpf_get_spi() computes (-off - 1) / BPF_REG_SIZE using C division,
which truncates toward zero. For off == 0, this produces spi 0, the
same index used by the valid stack slot at fp-8.

stack_slot_obj_get_spi() currently checks alignment and the resulting
spi bounds, but does not reject the non-negative offset itself. It can
therefore validate a PTR_TO_STACK register holding fp+0 against an
iterator stored at fp-8 even though the runtime receives the actual fp+0
pointer. An effectful iterator kfunc can then interpret memory outside
the BPF stack as iterator state.

Reject non-negative offsets before converting the offset to an spi. All
valid stack objects begin at a negative offset from the frame pointer.

Fixes: 06accc8779 ("bpf: add support for open-coded iterator loops")
Signed-off-by: Xu Yunxiang <xyx2021@mail.ustc.edu.cn>
Signed-off-by: Andrii Nakryiko <andrii@kernel.org>
Reviewed-by: Sun Jian <sun.jian.kdev@gmail.com>
Link: https://lore.kernel.org/bpf/20260920210423.345636-2-xyx2021@mail.ustc.edu.cn
2026-09-21 15:00:59 -07:00
Helge Deller
94b7e3a7e8 parisc: Increase kernel stack size to 32kb
For 64-bit Linux kernels, increase the default kernel stack size
(THREAD_SIZE_ORDER) to 32 kB, in order to avoid kernel crashes which have been
triggered recently when building the debian vtk9 package with gcc 17:

stackcheck: kworker/u128:0 will most likely overflow kernel stack (sp:179a83af0, stk bottom-top:179a80000-179a84000)
Kernel panic - not syncing: low stack detected by irq handler - check messages
CPU: 2 UID: 0 PID: 30760 Comm: kworker/u128:0 Tainted: G W 6.18.46-dirty #1 NONE
Tainted: [W]=WARN
Hardware name: 9000/800/rp3440
Workqueue: writeback wb_workfn (flush-259:0)
Backtrace:
 [<000000004022f050>] show_stack+0x70/0x90
 [<000000004022378c>] dump_stack_lvl+0x124/0x190
 [<000000004022382c>] dump_stack+0x34/0x48
 [<000000004020212c>] vpanic+0x204/0x648
 [<00000000402025c4>] panic+0x54/0x58
 [<0000000040232230>] do_cpu_irq_mask+0x3f8/0x440
 [<0000000040227070>] intr_return+0x0/0xc

Signed-off-by: Helge Deller <deller@gmx.de>
Reported-by: John David Anglin <dave.anglin@bell.net>
Cc: stable@vger.kernel.org # v6.18+
2026-09-21 22:19:09 +02:00
Linus Torvalds
f0100363d8 xfs: fixes for v7.3-rc5
Signed-off-by: Carlos Maiolino <cem@kernel.org>
 -----BEGIN PGP SIGNATURE-----
 
 iJUEABMJAB0WIQSmtYVZ/MfVMGUq1GNcsMJ8RxYuYwUCarEtCAAKCRBcsMJ8RxYu
 YwmHAX4+ML995OtOeKIN2Cpiu/0RYW/bHPrBBCHsiZN2BFZ3Ap2W7nxm4/OFewA9
 5oB6eKgBgL8Zi2K0ZPsiF+IxAEkWUBkvCgiQtByO3dSS6aMR6KzfrQBj0Pftlcgy
 z+C74fVlyA==
 =USzk
 -----END PGP SIGNATURE-----

Merge tag 'xfs-fixes-7.3-rc5' of gitolite.kernel.org:/pub/scm/fs/xfs/xfs-linux

Pull xfs fixes from Carlos Maiolino:
 "This mostly contain 'random' bugfixes found by LLM tools on different
  xfs subsystems. A few code cleanups and a NULL ptr deref on zoned
  support. Those 'random' bugfixes include possible buf overrus, UAFs,
  block leaks, etc..."

* tag 'xfs-fixes-7.3-rc5' of gitolite.kernel.org:/pub/scm/fs/xfs/xfs-linux: (26 commits)
  xfs: fix wild memcpy access when formatting ondisk rtrefcount btree roots
  xfs: don't let hidden_space go negative in xfs_metafile_resv_init
  xfs: drop dquot flush lock when we can't find a buffer to flush
  xfs: fix cursor and pointer handling when recovering iunlink buckets
  xfs: fix blockgc group quota scanning when usrquota isn't enforced
  xfs: don't merge different file IO error types
  xfs: don't let memory failures leak blocks and kill repairs
  xfs: don't cross reference rmapbt with bitmaps if they're incomplete
  xfs: fix rtgroup repair estimations
  xfs: call xfs_dquot_set_prealloc_limits if we installed default rtb limits
  xfs: fix typos and repeated words in comments
  xfs: remove unused xfs_reflink_remap_range declaration
  xfs: remove duplicate INO1_WRITTEN check
  xfs: don't try to get a reference to a NULL oz in xfs_get_cached_zone
  xfs: check di_forkoff correctly in scrub
  xfs: only flag zero padding for dir3 data blocks, not dir3 block blocks
  xfs: fix integer overflows in xbitmap set functions
  xfs: use the correct reservations for rtrmap/refcount recovery
  xfs: don't call xfs_exchange_range_finish for a dry run
  xfs: check padding field in xfs_ioc_commit_range
  ...
2026-09-21 08:22:53 -07:00
Prathamesh Shete
ae2c5bf969 pinctrl: tegra238: Fix register bank for AON pin groups
The AON pin controller has a single register region and therefore,
the bank defined in the tegra238_functions[] and tegra238_aon_groups[]
for the AON pin groups must be 0. However, commit 25cac7292d
("pinctrl: tegra: Add Tegra238 pinmux driver") incorrectly specified the
bank for these pins as 1 and not 0. This means that in the
tegra_pinctrl_probe() function we use an invalid index when accessing
the pmx->regs[] array which causes an incorrect address to be used for
accessing the pinmux registers.

Fix this by correcting the bank for the AON pin groups.

Fixes: 25cac7292d ("pinctrl: tegra: Add Tegra238 pinmux driver")
Signed-off-by: Prathamesh Shete <pshete@nvidia.com>
Signed-off-by: Linus Walleij <linusw@kernel.org>
2026-09-21 00:06:32 +02:00
Linus Torvalds
93f51579e7 Linux 7.3-rc4 2026-09-20 13:48:15 -07:00
Daniel J Blueman
6a5719cc3e net: qrtr: resend HELLO on MHI resume
Since the MHI HELLO exchange was relocated, it is sent only at device
registration. During a suspend-resume cycle, the firmware in WiFi
cards such as WCN7850 indefinitely waits for another HELLO,
triggering:

  ath12k_wifi7_pci 0004:01:00.0: timeout while waiting for restart complete
  ath12k_wifi7_pci 0004:01:00.0: failed to resume core: -110

Fix this by triggering the handshake from resume_early in the MHI
transport.

Validated on Qualcomm X1E-801800 on Lenovo Slim 7x across 10
suspend-resume cycles.

Fixes: 544d85de4d ("net: qrtr: Send HELLO message on endpoint register")
Signed-off-by: Daniel J Blueman <daniel@quora.org>
Reviewed-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Reported-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Link: https://lore.kernel.org/all/6257c447-788d-4362-851e-0d552bcf7c56@oss.qualcomm.com/
Tested-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Reported-by: Vlastimil Babka (SUSE) <vbabka@suse.com>
Link: https://lore.kernel.org/all/ab1491bb-cca5-4145-ac7d-31c966abf7b4@suse.com/
Tested-by: Vlastimil Babka (SUSE) <vbabka@kernel.org>
Reported-by: Takashi Iwai <tiwai@suse.de>
Link: https://lore.kernel.org/all/87a4plsg4w.wl-tiwai@suse.de/
Tested-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Thorsten Leemhuis <linux@leemhuis.info>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
2026-09-20 11:21:10 -07:00
Linus Torvalds
a10a019dd4 dmaengine fixes for v7.3
Bunch of core and driver fixes:
  - Couple of fixes in core around dma_chan_put() for kref underflow,  user
    after free bug and waiting for rcu readers for dma devices
  - mmp sg length and wrong extended DRCMR base for SpacemiT K3
  - hardware buffer descriptor chain fix for xilinx dma
  - sun6i fixes for status behaviour and dma position registers
  - runtime pm reference leak fix for sprd driver
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEE+vs47OPLdNbVcHzyfBQHDyUjg0cFAmqwEtUACgkQfBQHDyUj
 g0dCWQ//ShhhOd2vQQttV+BSHB0xTdT/wENO4mhXcz50chHFh1diBFASMnhejOxG
 dv4ZkePAxV7PLpNqRQrCz2gx89wn5Uxf71PmnLbleuJ5lOuSUMGbFL0MhLzrlfqr
 2Di122aa5Va4Tp3zjNllQ4ihKMfCF02FLCXoZqelVIR/NQFFMeJhEjv/0P2foFvd
 nrf5jzGJuCCbhKiV47H4a8hSb1bG68ct/mV0ZfOT5Koe4B16qPTe7Z9kW5FP0do5
 ++BeHLbEheA/btWUSzvnLMtGHhhUywlAab6cKEkYAcTsuxtapMMRtJmAq9bYyX1O
 qS6hIC9qWMS4xc0+BUsIhwU8cXY6IINy8lPJmwc+/p4V+MJ8QMP+MrfWpWADFy0H
 rTvkIdzU+Lc4fqIr97UbW+pi8Naf2NCiV2NJSYF8JT6ufeG1PymtwbeUlbhkThtZ
 ISVF2/CIieyHr/eDfzNuGrYmdkSfJZgl6Rd6pCHdYQ5vgK6DImtaHfuBBm1OYXVG
 NwA4vkTk6hKu2Sx2JShrSJC2js5q5gdz+9jQuvb9zZZS4I1qOARWjoe/E0wowlir
 EB5bivcNX8VR49x2aYmT7Mg1CJovzs6hC1Aw9aqFIhp+1hQRku+iFOSki8Pwzl23
 EcpkC7liL8S6WCo73Zh7cmT0aBvw3Y6Gpvfozh+Rr7kLZy6cfmw=
 =9a97
 -----END PGP SIGNATURE-----

Merge tag 'dmaengine-fix-7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/vkoul/dmaengine

Pull dmaengine fixes from Vinod Koul:

 - A couple of fixes in core around dma_chan_put() for kref underflow,
   use-after-free and waiting for rcu readers for dma devices

 - mmp sg length and wrong extended DRCMR base for SpacemiT K3

 - hardware buffer descriptor chain fix for xilinx dma

 - sun6i fixes for status behaviour and dma position registers

 - runtime pm reference leak fix for sprd driver

* tag 'dmaengine-fix-7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/vkoul/dmaengine:
  dmaengine: mmp_pdma: fix wrong sg length in mmp_pdma_prep_slave_sg()
  dmaengine: xilinx_dma: Fix hardware buffer descriptor chain after cyclic DMA
  dmaengine: pxa: fix double counting of the hw descriptors
  dmaengine: sun6i: fix undefined behaviour in sun6i_dma_tx_status
  dmaengine: sun6i: fix non-atomic read of DMA position registers
  dmaengine: xilinx_dma: Fix hardware buffer descriptor reuse order
  dmaengine: wait for RCU readers before releasing dma_device
  dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel()
  dmaengine: Fix device kref underflow in dma_chan_put()
  dmaengine: add dma_device_get() helper
  dmaengine: sprd: Fix runtime PM reference leak in probe
  dmaengine: ti: k3-udma-glue: fix NULL dereference in k3_udma_glue_release_rx_chn()
  dmaengine: mmp_pdma: fix wrong extended DRCMR base for SpacemiT K3
2026-09-20 10:45:22 -07:00
Linus Torvalds
60ee24f055 phy fixes for 7.3
Couple of driver fixes
  - Atomic context delay in renesas driver
  - TMDS and PLL rate calculation fixes for mediatek driver
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEE+vs47OPLdNbVcHzyfBQHDyUjg0cFAmqwD8UACgkQfBQHDyUj
 g0dzqBAAuGIVwSpUaEVAHD7TKcLqrmLpF4kuGXN4mGB+i8Hg3ivCH7n6/cKONOeA
 LPkdnl7ABRqNYX935oXtRAUuy0CnoIKJKaxrp0ap1x5QtAcyAKWEW+Ej/rHL9JV7
 JHt/YQFcMhcvKE1lGUYdFA9eF2PQf0h3Xw0BcaB83WqAlsoWh9EnEOjDnfkv4rZi
 PMIW5/lXlpkWEfyptomcNHycGbltnLP323IkIscyS6qX7dIfldoN4pinwNKrIvHM
 CNrg8PPYefjFltVZ7q2u/MB8IeDpYGKNlyGC3Kvspsa04o8Qb0TTMb3aZ+AOn3rJ
 Ccq69UwdnMARx+V9Gc9gY5Jp6Q503SPwFGhRTybT9iyjft9yIGkaEZL1miWOWpZZ
 Fsv3xukBZhDVy1jGt6tsyfUVvRh6eu835jYijp4NHBeo1To7/clcKTTAT5o1/upC
 qWeM/FarR3JB/sAHrHKnA/R3Yh9FTpy5lTD6FhXa95SufJmB12rKbjUYNMNG3EOx
 OgYpeBeuy8ZXtkzPO36LXFv6OomQkxjThMAZ/syn1T8HStWULkhj9MxkrH0BRsB0
 SsxIBkzG7tKlwQizJGDugum9uvxFX0104voNhTkn9DPO2oo4LnxGlsonfqJj7XPD
 TJoF9/IWV+3bQCL9fLU0mBvniQf/jzEaGXoGX+qY1YtXm8I5jTE=
 =xn2f
 -----END PGP SIGNATURE-----

Merge tag 'phy-fixes-7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/phy/linux-phy

Pull phy fixes from Vinod Koul:

 - avoid atomic context delay in renesas driver

 - TMDS and PLL rate calculation fixes for mediatek driver

* tag 'phy-fixes-7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/phy/linux-phy:
  phy: mediatek: phy-mtk-hdmi-mt8195: Fix TMDS clk bit ratio setting
  phy: mediatek: phy-mtk-hdmi-mt8195: Fix PLL calc divisor overflow
  phy: renesas: rcar-gen3-usb2: Avoid long delay in atomic context
2026-09-20 10:43:12 -07:00
Linus Torvalds
0a885f68d0 soundwire fixes for 7.3
- Cadence ensure work completion before clock stop
  - Disable ghost Realtek on Asus GX651AX
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEE+vs47OPLdNbVcHzyfBQHDyUjg0cFAmqwABUACgkQfBQHDyUj
 g0dzrxAAmGpYUaBc5GEnTypOM8NM/UUOOWn+AMUGAb/AekqIChg42a5oVXlaAU5O
 HXqXIIJ5EVddmn++s1XJvcOrMGM4412wwrOKBpCWP9+h5+My1euY9AGDrApRrFCx
 DYmLvxqIDCq2MS8NmaY0RWAAkNI6TXQWsn29TBztt6xRCT7EmiM/iERJpBUhK4Sg
 Oyd9nJkT6Oieln/mfWWxAexBe+W5p9l6StLM/aDnQ7LiVEa6U5vKKfmEbFceQ0z1
 1c3NoJC1hTdsNUytIOKcT46an0sF7GdIe6EB0+yAq+MfS1NHZrQWOG6weVxAqldV
 xS5uUadqDm18xuh8q97+fFueE/rT21JgQFWb9fsuYX3ESNpaO/8dPZtEZFVQOBBJ
 fR+vvKfqm4X3LXe+wXJt/3SQ7KV1Lth/bdPl2O4FYQlfvX1XmaS6lJiBErDyNxY8
 sVCdy+XBcV4MjSciwnYjARpCVAcFo2NRt931TEDgaes2glaQl/v885pTZQEsE/CO
 mCaDcuBFaceuK2x9fGugqQRjCdOXAY8z6UcAUtwlUvy8g008IBssPuCQiVQvFZxs
 cPM4dkbrSPiKz2vuMJepytmk2Fm8wIVWHK7ODtYywYxfkFS8pCQOIi4Wj/EiOF++
 6dOKY0qxiDEr/27cqzm6YcGZ91dH9kDT4nR8W/6gXAdoqclJyCA=
 =mDuH
 -----END PGP SIGNATURE-----

Merge tag 'soundwire-7.3-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/vkoul/soundwire

Pull soundwire fixes from Vinod Koul:

 - Cadence: ensure work completion before clock stop

 - Disable ghost Realtek on Asus GX651AX

* tag 'soundwire-7.3-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/vkoul/soundwire:
  soundwire: cadence_master: wait and cancel cdns->work before clock stop
  soundwire: dmi-quirks: Disable ghost Realtek on Asus GX651AX
2026-09-20 10:22:37 -07:00
Linus Torvalds
156fa7417f x86 fixes:
- Reject the loading of a potentially problematic microcode version
    on Intel Granite Rapids systems (Chang S. Bae)
 
  - On FRED, reconstruct the proper #GP context for rejected INT
    instructions, to fix a signal ABI regression (Matthew Schwartz)
 
  - Add a test for this signal ABI regression the x86
    self-test suite (Matthew Schwartz)
 
  - Don't emit the new and not yet properly supported EGPR instructions
    (%r16-%r31) on CONFIG_X86_NATIVE_CPU=y builds (Chang S. Bae)
 
 Signed-off-by: Ingo Molnar <mingo@kernel.org>
 -----BEGIN PGP SIGNATURE-----
 
 iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqvrhgRHG1pbmdvQGtl
 cm5lbC5vcmcACgkQEnMQ0APhK1inbQ/9G4Q0h9esQ945n0uYRYvVLuj2P8DvE3XN
 9d5IJ5pIYdhJCvlv8yXyv1u3sq59QYNmUgpBMghHJonhqobtnchvBSiznoAMgi8L
 yjRlcaFBPX9qjFQV1W9WJQuUHhW/12QFy9Bo9n1uXEv6pYspYVDwodCaS+rEvkTF
 0wK3TjETv90TravGjFscYTt2VLAiy+cd/FxkUA0sBaMLjhFpUyAPHGJe/vcf8vT3
 rEXkY8EeSjv5F6eKMTDVacrSZu2c9wco1bJIsSFEcxZGFzhDbuCOGiDCkwmB3uuD
 ReKbEUC0KmF8qd4Ubf0dMGpbHT9LDu9Ggex619cHFOHMupPubP+yym7aCpm3v7Sb
 gZe6eV6VrSREJ+oBVKsqMrWXsg1YDj6uJhC/5K3S78xBeRq64kKsmBbC93Zp20TC
 QpSAxKIFqp8C+tfKzpBmcSbcipRUfATJxLjp94QaQDp467jjJCvpDJdc12mV7WR9
 0gMtFjxUaIe8BGX7s2PuWPgZ8+CIH0hZQuttxUU4QWvM2RGU+QrDaMwTeAY7wme4
 xomc0wpXQb5enrjmFu8betlD0xfjgt7k6eW0njezRpWSk3wyHDd5w/6Vfn8pA6Fx
 AQV4UuszXzQmG+W2pdIjLhnjmsjEeWMpmwgzn0rkcqujWHeh8XOSvQIjULFrFtFv
 srSbum6vEfk=
 =MP1H
 -----END PGP SIGNATURE-----

Merge tag 'x86-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip

Pull x86 fixes from Ingo Molnar:

 - Reject the loading of a potentially problematic microcode version
   on Intel Granite Rapids systems (Chang S. Bae)

 - On FRED, reconstruct the proper #GP context for rejected INT
   instructions, to fix a signal ABI regression (Matthew Schwartz)

 - Add a test for this signal ABI regression the x86
   self-test suite (Matthew Schwartz)

 - Don't emit the new and not yet properly supported EGPR instructions
   (%r16-%r31) on CONFIG_X86_NATIVE_CPU=y builds (Chang S. Bae)

* tag 'x86-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  x86/build/64: Prevent native builds from generating EGPR use
  selftests/x86: Check signal state for rejected software interrupts
  x86/fred: Reconstruct the #GP context for rejected INT instructions
  x86/microcode/intel: Reject problematic loading on Granite Rapids systems
2026-09-20 09:49:10 -07:00
Linus Torvalds
0a15ba6b0c Timer race fixes:
- Fix timer signal <-> exec() race, to prevent UAF (Thomas Gleixner)
 
  - Clean up POSIX CPU timers right after de_thread(), to prevent UAF
    (Hyunwoo Kim)
 
  - Fix POSIX CPU timers race between expiry and timer_settime(),
    to prevent UAF (Thomas Gleixner)
 
 Signed-off-by: Ingo Molnar <mingo@kernel.org>
 -----BEGIN PGP SIGNATURE-----
 
 iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqvrMYRHG1pbmdvQGtl
 cm5lbC5vcmcACgkQEnMQ0APhK1gqUQ/+NkruN984bFynF/eZ0/2DFv91AAUP8zgH
 /S3PBlwuSbYFN9JVhngDMwxQkamE56weJbFc+0QuvVT5UVw/vX9BS4QOvvzN+f8D
 FEN3UqD0d1B8OwlPNTw0sFPwJDdPctTinfKOhNjNQe6RLFsNARvGyaKDIDroWTfV
 dxuJ/7Ecs+5m1bmGJnPEC+IH/OnV9BEEl1NdZb+INKpBlui9LCsw4rRIj/8dPK/H
 UNhvXpykKrJCDftbCzAFSNryuzcJgq4kHtMbsqiUL6y50AB69eHGi/Y0xYBAEr1h
 NiDPq2PAMmH1NCCMsTtqbJZMqgCr+7DSZiCFn7bZPwg0V5tV4PFZD484q0sCbiej
 Fwg+arHd0icnceIcWMsBWPUVOSLxZaWdp9a2Tj3Ill06//b5bEDBJBbpecS+so3t
 8W6IvdoCYm7sz50mohnjOdx7biHPu0yhwgj+EoAV3nZKoALQAAcI7+HJzSWpGnJi
 HIO0zylRAZCjk9H3QNWO+LdWgifc8DysAZOWpmbuwGgp8q483IDRDtme/kMt3+D1
 1qTHa1TD/tPo8UmmgyVJQ7e1hCxBkGuuBBu5Y3/qkUEOQM6B/H2Ji7stxsLpW3JL
 HLzC3kL2SBBVBO2ljqiH5IhVAL10Qm5vPxaCOjExdBt1vjMxN1DowZqD4rT/tw58
 ArpD4zmr8VQ=
 =KhWJ
 -----END PGP SIGNATURE-----

Merge tag 'timers-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip

Pull timer race fixes from Ingo Molnar:

 - Fix timer signal <-> exec() race, to prevent UAF (Thomas Gleixner)

 - Clean up POSIX CPU timers right after de_thread(), to prevent UAF
   (Hyunwoo Kim)

 - Fix POSIX CPU timers race between expiry and timer_settime(),
   to prevent UAF (Thomas Gleixner)

* tag 'timers-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list
  exec: Cleanup POSIX timers right after de_thread()
  signal: Prevent exec() race
2026-09-20 09:41:00 -07:00
Linus Torvalds
fecbe78ac0 Scheduler fix:
- Avoid false positive migration warning for proxy donors
    (Andrea Righi)
 
 Signed-off-by: Ingo Molnar <mingo@kernel.org>
 -----BEGIN PGP SIGNATURE-----
 
 iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqvqssRHG1pbmdvQGtl
 cm5lbC5vcmcACgkQEnMQ0APhK1gPzBAAhE9hcpkBV6vNW9xzBDKdGPxRjch2vcfu
 lQbx7da1yC2rHU7RDlcdfEgkhAqTRwEAXKz26zth3sDHLk43tusuNtqG3swELhNW
 YAGbHjdn87snQlmP8AOK4EaT3uE5NjWqRSIJWMK+AhWSwqO/zzK91T6yZyQY0fM4
 3Edp8CFo3IeyOzCR96vsob2x1fFQhuR//5fWul3uuB0EZ8VA5FhH3ene6VCm7P/1
 dauxX0rMTb2730qNXA8cHROZq+bwhqTZOUaoOZ33WxnRPkvY9mV/hZsN8JnJuzBE
 ogzyyorcl8dFH8qOapos9Cp3tQj9GkTX7mXWDbuUflt/8uOXtQMf75kFGBVI5NUw
 2xNfgubTYGo6Qc1C+wyOhGYJ6T5Al+083pV/vPc4y7Z1i7RgZ94QypMuZuaR/RqS
 z+RQcdNQlXiRIAIILGJqq1xdbaCJvbVx3tiFZkhPse6ioOF6UNGbQiNExAq3v5BU
 ocvhBuf9p/uvRmfs+ZtQNqAAjZUL7tQPvdFAsjxKjuI2Z5YGPROy1L9NdYKfzryM
 yWOEkV2mdn97CwzDS+auC0HmPkGqf8we2VI5Ub4R35UPqDcV6vc5BAnwzAbuxAmc
 K7mQOMDEaRkbVQ0MoSMdidIXLL0AcN+BROBUtHv8kqJur6nADE3K3HZNdhr2ViLN
 eisNI6m8pLk=
 =BEte
 -----END PGP SIGNATURE-----

Merge tag 'sched-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip

Pull scheduler fix from Ingo Molnar:

 - Avoid false positive migration warning for proxy donors
   (Andrea Righi)

* tag 'sched-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  sched/core: Avoid false migration warning for proxy donors
2026-09-20 09:37:27 -07:00
Linus Torvalds
abb91eed94 Perf events fixes:
- Fix crash when probing CS CALL instructions (Jinke Han)
 
  - Fix NULL pointer crash during module unload (Vinay Belgaumkar)
 
 Signed-off-by: Ingo Molnar <mingo@kernel.org>
 -----BEGIN PGP SIGNATURE-----
 
 iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqvqiURHG1pbmdvQGtl
 cm5lbC5vcmcACgkQEnMQ0APhK1hiohAAjcvOY7M998pX1tmo1Egw9kAuI0odtNOX
 weQ4Wq7K3X+tg+q1wVUmE/N/y/WLYWNatjwvjc8TClYdQEiaqBMH4TSLAuY3TOxa
 TxwdTC20uSN4EPZ0iRhKzm3biPzzzRq4M9hhV+WfGcK7ieXRn4Q7d9S3DDe5oEfG
 lI4l/RefIBiINVPC7dNM7xpS/7XBEPnzNeshOMwp6ZsPziZJizgC8C7RhQFAPszo
 Ho36KKFQqMNouCSybQl1GxLyPw+oGtneWESHXrF6Mhp+bcx40fMtJxKNyVLsVWuM
 wo0Ry843pCbDofOIqg7m0AufWUhz7B4MttTXXrU2/BYMHEbxlgms1AO7lnSGzPmn
 vP0JHZnT3y34P5uvGaVho7t9QKKbuY47cKNmsiiLuXiBQQuKnvDmDln1Mu1KS3fg
 a1LI8kv043iLqAjsIWMVtKlRGUX36f4NXUWrxvO/tmup3ocJhG1oYmEe/RaFddVX
 5qRbHn7Z1w8jAWldODYSrXkpMRgMtClQuqHdjxZQt5DPZSORzoFxTvSfJLdUUtVx
 CUiT34zcLPHfvGD+ctHe5kVesgDHCxp/z1tKrJBunB+XZVl6rKHycfiGjaUXQRcR
 NUp6iFlfay8b79EkMsLC8p6uAmzX2q+gEwNVy8eevBSXdsYqcY5islj3ob7sBHsH
 vk4gDJikpE0=
 =onkS
 -----END PGP SIGNATURE-----

Merge tag 'perf-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip

Pull perf events fixes from Ingo Molnar:

 - Fix crash when probing CS CALL instructions (Jinke Han)

 - Fix NULL pointer crash during module unload (Vinay Belgaumkar)

* tag 'perf-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  perf: Fix null pointer access in is_include_guest_event()
  x86/kprobes: Fix crash when probing CS CALL instructions
2026-09-20 09:26:22 -07:00
Linus Torvalds
2f7ff5f547 - Fix objtool build error on systems where libopcodes is
present, but development headers (binutils-dev) are not
    (Ulises Mendez Martinez)
 
 Signed-off-by: Ingo Molnar <mingo@kernel.org>
 -----BEGIN PGP SIGNATURE-----
 
 iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqvqSARHG1pbmdvQGtl
 cm5lbC5vcmcACgkQEnMQ0APhK1iBWQ/9HTpCn/GSapwpTLUAXh/d/7VWSTV/xMRS
 b/cqx+jFDFeZDU55VbX+bMgKQyW0jNSUPjvVp0ZfjUf0W0LOXL/EnAemZ8VqBqAj
 IMIyd+0MjCeUOCVanRiITre65BPuF+g3EbxWypFDiLmb4ziA5YksPknTWYrIVbDP
 IMks30B8kJfzC5Qh0jjpSRDSypTvuEAKppbyf3pPmHfKLSbwtKOQzeoFUlLtWfs4
 diBm9BVIjosmIr5dxMyixa8+5BTsPs4ojwa4US3H+RzxdXe+2v31Ac2nK/zvCRst
 Fr8gefaLhVrnfkJeXU0Xn/rDMYOzayb1JW4jWjJ40I6U20ptdrMQ3aSJqjNrrwkQ
 2vikInQX3NKV2ASiTppLDhsq7MFt4AeRYFwj8xmErm5uhoSEKAEPG1QZWS98QkAo
 CXQL3PITL5kS0q5wGkkYXNi3TbpKvWy8kPoIRMHoKFUkBHJRssSg8tb17D5Jg0yd
 QvsjocvMSf865swQ6p1yj+7+Zd+nGM2JGkIcp9OBPTAzZej4bXmpPwMKDeRv6pgD
 GNgKJ2oEhvXWCgokxK9ezgk8rYsH/1Vo/+JyBf4/tcKL9ixfnBTgLNZ80J8VFDn2
 5axUt4EO+FZKzLB6UaENhTo813PhGOM/rChKmJ1L4GWi0RywoX+seH4b+FtQk87f
 VPvApwwiDHQ=
 =vTNY
 -----END PGP SIGNATURE-----

Merge tag 'objtool-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip

Pull objtool fix from Ingo Molnar:

 - Fix objtool build error on systems where libopcodes is
   present, but development headers (binutils-dev) are not
   (Ulises Mendez Martinez)

* tag 'objtool-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  objtool: Validate disassembler headers in libopcodes probe
2026-09-20 08:41:19 -07:00
Linus Torvalds
bdab18633a - Also allocate a default private futex hash on vfork()
as well, to avoid races with (private) futex waiters
    (Peter Zijlstra)
 
 Signed-off-by: Ingo Molnar <mingo@kernel.org>
 -----BEGIN PGP SIGNATURE-----
 
 iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqvp20RHG1pbmdvQGtl
 cm5lbC5vcmcACgkQEnMQ0APhK1giDg//VpFKPXgma7fW5E+T0kjWHWD7FS1vYyJ4
 nMunKME8PAV0A4S7946iUAWHjViVfksTmfvcXepSFCKZKLf55g8s2aZ1VoigMtYX
 bQxNrnOidebSg9npLs9NV4sjvvNy+k03gcNN+OK+ZRfYCVRqbLgfCm5RJbaId5y4
 +EuizVmtJuNav6HwAEIbU4LXGIdwSL9Pn8Zitkz/H7g0ZEkv+VA4h6NttvKDNfV7
 OltcUFejtU7Z1lItfH+PP9pMcjPA6OPI2h7LLmUcZGUhhQQtW2Gb1fffz45PiH8T
 FB7PdFt22TLG5c6hLB7zbrFFillWKn3l3Ihi/IxqVmMulhk6RVTPdCVJcj1cGZxF
 9NXZ+L81poKwEETaIk52v5jm9qNF+kHbXJuCjPbmEdPxtxfv+Ma4zXom/xKkuXpx
 qf01GXxelUPdCAl0cT0pzRvbEfHNIOsE2Id7f+59jB+L8ZbYEch04cIVRqCQcOgi
 9B+lXj36fkFBV6wmuP5SWShWsgMsMpgSzOz5mUdWjY3Ocn9QuzDxPkk50Cm7uL1i
 q/HpGv3T849HFnCH7+mi8wSiX33La+N297+AkGO7U7h5QFldPokvbAijwfmF+1Nw
 CebsAfsgJsN1GZacDTH0jmRxh4I0Wa32yiCAldeGS2w9EMEAFbA87iwsOgjwHiQl
 JOv/s06Pg7o=
 =qQHe
 -----END PGP SIGNATURE-----

Merge tag 'locking-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip

Pull futex fix from Ingo Molnar:

 - Also allocate a default private futex hash on vfork() as well, to
   avoid races with (private) futex waiters (Peter Zijlstra)

* tag 'locking-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  futex: Also allocate private hash on vfork()
2026-09-20 08:15:23 -07:00
Linus Torvalds
5bf70485f9 spi: Fixes for v7.3
A few driver specific fixes, none of them particularly severe or
 unusual.
 -----BEGIN PGP SIGNATURE-----
 
 iQEzBAABCgAdFiEEreZoqmdXGLWf4p/qJNaLcl1Uh9AFAmqvmVMACgkQJNaLcl1U
 h9AOdwf/aRa54oHd6iLCPXNAbZLDie0pnJa/Q/5sjpJoVY9ofKc2XM9djmy60YdF
 /VGIphT8gr6at6fLZHEBbLanu2MQC2vxW9zDh5n+Xe8HUS3sdrwtBJPSv74Mcfrf
 OIv6nFrVsbo1IMF7x4ncYOhOBGKyOSqhsVdt+k6jl1wuTDJBHyFs7sdL1DGRCRu/
 ba4n2W+kSxVeFx3ACFyDJ8l8vLqtyotFKkpmslrPmT0yHFwOr8SOMbyQ5MPxITpx
 gqgLikR3OW5alOLxy1U2nWCdjNsc8UWBhx1sCnByYrUO3VmRIEx4j1l2wSVX0J7E
 Ck7/pSpg1NGkxVYSLCTBufqq8kgPTQ==
 =iy0J
 -----END PGP SIGNATURE-----

Merge tag 'spi-fix-v7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/spi

Pull spi fixes from Mark Brown:
 "A few driver specific fixes, none of them particularly severe or
  unusual"

* tag 'spi-fix-v7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/spi:
  spi: fsl-qspi: Reprogram the clock rate when the operation frequency changes
  spi: spi-zynqmp-gqspi: stop the controller on shutdown
  spi: virtio: Use the per-transfer bits per word
  spi: spi-qpic-snand: avoid writing QPIC_EBI2_ECC_BUF_CFG register
2026-09-20 08:08:54 -07:00
Linus Torvalds
aa211c7a58 i2c-fixes for v7.3-rc4
Fixes mainly for cleanup and error handling, a good part of them
 around DMA resource management.
 
 - at91: ensure DMA channels are released on all exit paths
 
 - imx: fix autosuspend cleanup on remove
 
 - qcom-cci: fix device node reference leak
 
 - atr, imx, qcom-geni: set adapter slot to NULL on registration
   failure
 -----BEGIN PGP SIGNATURE-----
 
 iHUEABYKAB0WIQScDfrjQa34uOld1VLaeAVmJtMtbgUCaq+VLAAKCRDaeAVmJtMt
 bqmsAP9umA0ew1WQkQGTlTJLfbQdhwy8IDS7tMRAlgL7vsUxOQEApvFqr6Xtq2j7
 HiSP35cHybZlA7P2T70A+MVniCJDRQ4=
 =Sn1c
 -----END PGP SIGNATURE-----

Merge tag 'i2c-fixes-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/andi.shyti/linux

Pull i2c fixes from Andi Shyti:
 "Fixes mainly for cleanup and error handling, a good part of them
  around DMA resource management:

   - at91: ensure DMA channels are released on all exit paths

   - imx: fix autosuspend cleanup on remove

   - qcom-cci: fix device node reference leak

   - atr, imx, qcom-geni: set adapter slot to NULL on registration
     failure"

* tag 'i2c-fixes-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/andi.shyti/linux:
  i2c: qcom-cci: fix device_node refcount leak in cci_probe()/cci_remove()
  i2c: qcom-geni: release DMA channels on probe error
  i2c: imx: release DMA channels on probe error
  i2c: at91: release DMA channels on remove and probe error
  i2c: atr: fix dangling adapter pointer on add failure
  i2c: imx: disable autosuspend on remove
2026-09-20 07:57:47 -07:00
Linus Torvalds
b12dd0fa48 Input updates for v7.3-rc3
- Fixes for evdev and input compat handling to zero-initialize on-stack
   absinfo and force-feedback effect structures before partial or compat
   copies from userspace, preventing kernel stack memory disclosure
 
 - Fixes for the Synaptics RMI4 driver to prevent an out-of-bounds read
   when writing multi-chunk blocks over SMBus and to avoid a NULL pointer
   dereference during suspend/resume when the RMI device is unbound
 
 - Fixes for the soc_button_array driver to propagate -EPROBE_DEFER on
   non-Bay Trail/Cherry Trail platforms (fixing broken power and volume
   buttons on the Microsoft Surface Pro 11) and to validate the ACPI
   package element count before dereferencing
 
 - A fix for the adp5588-keys driver to cache the initial GPIO hardware
   state before registering the gpiochip so pre-configured pin states are
   not clobbered by GPIO hogs during registration
 
 - A fix for the cyttsp5 touchscreen driver to clamp the device-supplied
   HID report size before copying into the response buffer, preventing a
   buffer overflow
 
 - A fix for the HP SDC serio driver to use timer_shutdown_sync() on
   module exit so the periodic kicker timer cannot rearm itself during
   teardown
 
 - A fix for the eeti_ts touchscreen driver to export its OF module alias
   so the module autoloads on Device Tree platforms
 
 - Updates to the xpad joystick driver adding support for the Victrix Pro
   BFG controller and Azeron devices, and fixing the device type
   classification for the PDP Marvel Xbox 360 controller
 
 - Quirks for the i8042 and atkbd drivers to keep the built-in keyboards
   functional on the Acer Aspire Go 15 AG15-42P and Xiaomi Redmi Book Pro
   16 2026
 
 - A quirk for the Synaptics PS/2 touchpad driver disabling SMBus
   InterTouch on the Lenovo ThinkPad T440p (board ID 2722) so the
   touchpad and TrackPoint respond immediately at boot
 
 - Other minor updates and documentation fixes, including reading the
   "ti,poll-period" property as u32 in tsc2007, adding the mt6572
   compatible to the MediaTek keypad Device Tree binding, fixing an
   attribute name typo in the trackpoint sysfs ABI documentation, and
   documenting that no new LED codes should be added to the input
   subsystem.
 -----BEGIN PGP SIGNATURE-----
 
 iHUEABYKAB0WIQST2eWILY88ieB2DOtAj56VGEWXnAUCaq9j+gAKCRBAj56VGEWX
 nJ5KAQDnTOivIghgIGnlKTIYLSV4cJ0fWJh7J1/ubx9soK+9RwD/bDUdyryAaSTr
 x95U7/fEvq/lXBFyK2LXyahuTC6vNQY=
 =Vsfi
 -----END PGP SIGNATURE-----

Merge tag 'input-for-v7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/dtor/input

Pull input fixes from Dmitry Torokhov:

 - Fixes for evdev and input compat handling to zero-initialize on-stack
   absinfo and force-feedback effect structures before partial or compat
   copies from userspace, preventing kernel stack memory disclosure

 - Fixes for the Synaptics RMI4 driver to prevent an out-of-bounds read
   when writing multi-chunk blocks over SMBus and to avoid a NULL
   pointer dereference during suspend/resume when the RMI device is
   unbound

 - Fixes for the soc_button_array driver to propagate -EPROBE_DEFER on
   non-Bay Trail/Cherry Trail platforms (fixing broken power and volume
   buttons on the Microsoft Surface Pro 11) and to validate the ACPI
   package element count before dereferencing

 - A fix for the adp5588-keys driver to cache the initial GPIO hardware
   state before registering the gpiochip so pre-configured pin states
   are not clobbered by GPIO hogs during registration

 - A fix for the cyttsp5 touchscreen driver to clamp the device-supplied
   HID report size before copying into the response buffer, preventing a
   buffer overflow

 - A fix for the HP SDC serio driver to use timer_shutdown_sync() on
   module exit so the periodic kicker timer cannot rearm itself during
   teardown

 - A fix for the eeti_ts touchscreen driver to export its OF module
   alias so the module autoloads on Device Tree platforms

 - Updates to the xpad joystick driver adding support for the Victrix
   Pro BFG controller and Azeron devices, and fixing the device type
   classification for the PDP Marvel Xbox 360 controller

 - Quirks for the i8042 and atkbd drivers to keep the built-in keyboards
   functional on the Acer Aspire Go 15 AG15-42P and Xiaomi Redmi Book
   Pro 16 2026

 - A quirk for the Synaptics PS/2 touchpad driver disabling SMBus
   InterTouch on the Lenovo ThinkPad T440p (board ID 2722) so the
   touchpad and TrackPoint respond immediately at boot

 - Other minor updates and documentation fixes, including reading the
   "ti,poll-period" property as u32 in tsc2007, adding the mt6572
   compatible to the MediaTek keypad Device Tree binding, fixing an
   attribute name typo in the trackpoint sysfs ABI documentation, and
   documenting that no new LED codes should be added to the input
   subsystem

* tag 'input-for-v7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/dtor/input:
  Input: hp_sdc - shut down kicker timer on module exit
  Input: xpad - add support for Victrix Pro BFG Controller
  Input: tsc2007 - read "ti,poll-period" as u32
  Input: trackpoint - fix the inertia attribute name in the ABI document
  Input: eeti_ts - publish the OF module alias
  Input: xpad - add support for Azeron devices
  Input: xpad - fix PDP Marvel Xbox 360 controller
  Input: document that no new LED codes should be added
  Input: soc_button_array - check btns_desc->package.count
  Input: soc_button_array - fix MS Surface Pro 11 probe failure
  Input: i8042 - add quirk for Acer Aspire Go 15 AG15-42P
  Input: synaptics - disable InterTouch on ThinkPad T440p (board id 2722)
  Input: cyttsp5 - clamp the HID report size before memcpy
  Input: zero ff_effect before compat copy in input_ff_effect_from_user
  Input: evdev - zero absinfo before partial copy in EVIOCSABS
  Input: synaptics-rmi4 - fix GPF in suspend and resume when unbound
  Input: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block()
  Input: atkbd - skip deactivate for Xiaomi Redmi Book Pro 16 2026
  dt-bindings: input: mediatek,mt6779-keypad: add mt6572
  Input: adp5588-keys - cache GPIO state before registering the gpiochip
2026-09-20 07:02:34 -07:00
Linus Torvalds
4a910e594a selinux/stable-7.3 PR 20260919
-----BEGIN PGP SIGNATURE-----
 
 iQJIBAABCgAyFiEES0KozwfymdVUl37v6iDy2pc3iXMFAmqvPSwUHHBhdWxAcGF1
 bC1tb29yZS5jb20ACgkQ6iDy2pc3iXP1rBAAkK6sP+lzXynr/abxWio9UCvlN6NF
 jqMXtKeUeLNg/lJakXKhja/FGaK9w+Rm+zlXQQvVE7YAO5Db758JzCXMTHlK6etD
 T5d+GVdZj/oVcAvfGhov0guNHZqcfKTGWOXKtGV8RQWYL+f6IC1IIHnz9wNeWIfY
 emkfOTgAJpCkX9nXS5xTdQNUiPkUV80LFGqxXCMhxiumvyzqOhUteytfNh3UXXcs
 ldOWRBstUumudBe/MJR09REtQve3emHc7bZUAxSKwXxzdOPTf7UEy4Y7QXCN3Opn
 Dn6Dsrt6lnpIZyzUK/eOnZvQ639gDqTMW2XTmin0JIf2KGG/PhqnvOT07hOPl+X5
 wqXh2wCFn+tXVi5t+S2myMUVZK56GwfRH9kMCo6ca1Ui36iYYEeoJYt7z5tsE6P5
 YBdvKKJ/MPR1/uEwP/TB3UDK0o4OBjyujc6/Ka5iBoIHXKpx7MBLOo/Q0h/Wu2A0
 7HYvG/4lYdWp3p5iR8cdZ+ZgdTQDWi6t5BD3JWOfWi1gHCeGgZCHTCZ9mdSoFS18
 9GpXFXTR4yM5pfwxQEAu6jFH0esSB92HJBd/yS7sU8EIUQ+0XmOge+gVPifMrhWj
 yOHCR7hlAYE5ds51w3ZVOYI0slkYImqCHEdlCz1DiKzyLmQQmfJvshOIvBCl7uwn
 LRHu6Mo0cEBMAvc=
 =kiQE
 -----END PGP SIGNATURE-----

Merge tag 'selinux-pr-20260919' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux

Pull selinux fixes from Paul Moore:

 - Ensure that the cached SELinux access decisions are correct

 - Fix the SELinux overlayfs code to properly track the top-level/user
   information on multiple stacked overlayfs filesystems

 - Fix the SELinux overlayfs code to properly enforce mprotect() access
   control policy on all of the different layers in multiple stacked
   overlayfs filesystems

* tag 'selinux-pr-20260919' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux:
  selinux: recheck intermediate backing files on mprotect()
  selinux: preserve user SID across nested backing files
  selinux: always fill AVC decision in avc_has_perm_noaudit()
2026-09-20 06:50:31 -07:00
Mickaël Salaün
3fa5aa398e
landlock: Fix tracepoint contract documentation
The tracepoint documentation claims that denial and lifecycle events
expose every input needed to reproduce a verdict. Instead document how
denial, ruleset, and domain events identify the denying policy, checked
operation and object, and reason for denial. Direct consumers to generic
tracepoints for additional operational context.

State the reconstruction limits: IDs are boot-local, rule checks have no
request ID, and exported records may be lost or cross-CPU reordered.

Also replace the incorrect BPF_RAW_TRACEPOINT guidance with libbpf
SEC("tp_btf/...") attachment and refer consumers to the event prototypes
for callback argument layouts.

Cc: Günther Noack <gnoack@google.com>
Cc: Steven Rostedt <rostedt@goodmis.org>
Link: https://patch.msgid.link/20260918185036.608651-10-mic@digikod.net
Signed-off-by: Mickaël Salaün <mic@digikod.net>
2026-09-20 14:13:33 +02:00