-----BEGIN PGP SIGNATURE-----
iIYEABYKAC4WIQSVyBthFV4iTW/VU1/l49DojIL20gUCarVI0xAcbWljQGRpZ2lr
b2QubmV0AAoJEOXj0OiMgvbSEVgA+gNbC9CVCbCo0oufZbVpQwlwtuuEKEVpvxZx
q7oFYKCsAP9svCujGCXRHOmWhAAwe+wpXNb43l8coFn+pCfA8x3fCw==
=NOli
-----END PGP SIGNATURE-----
Merge tag 'landlock-7.3-rc5' of git://git.kernel.org/pub/scm/linux/kernel/git/mic/linux
Pull Landlock fixes from Mickaël Salaün:
"This mainly fixes the Landlock tracepoint support merged this cycle so
that denial and rule events report the intended policy context,
whether through tracefs or BTF-visible callbacks.
The size of this all is mainly from propagating the corrected contract
through event definitions and producers, adding new tests for the
reported context, and updating the documentation.
Also improve annotation and fix a GCC 16 build warning"
* tag 'landlock-7.3-rc5' of git://git.kernel.org/pub/scm/linux/kernel/git/mic/linux:
landlock: Widen ruleset versions to 64 bits
landlock: Add counted_by in landlock_domain
landlock: Fix tracepoint contract documentation
selftests/landlock: Test network denial context
selftests/landlock: Test filesystem denial blockers
landlock: Report the effective signal number
landlock: Report the actual ptrace tracer
landlock: Fix network denial trace context
landlock: Fix rule tracepoint context
landlock: Fix filesystem denial blocker reporting
landlock: Fix tracepoint fixed-width type names
landlock: Work around gcc-16 -Wuninitialized warning
-----BEGIN PGP SIGNATURE-----
iQJRBAABCgA7FiEE+soXsSLHKoYyzcli6rmadz2vbToFAmq1NvAdHGFsZXhlaS5z
dGFyb3ZvaXRvdkBnbWFpbC5jb20ACgkQ6rmadz2vbTpmpA//fqEoC6Sq1zxo3ADH
hV0Z9ewkNTjjH85QnispjcRkAhSHG3JscNXKRXm1NmNkwJsHJ4TDIKcjABYDjquD
wqfvL9hLXPsvud0M/PR6/CZeBAWXpukkaxeYedY+83ttTHjzR0tDq0Ne9yvIV+Nc
hS0qFIIHs8C6l2nyuNSxvgrv216orG8qd0Bi3tpDfsLqCsLLEmDyQ1H+ZzpJF2xW
RV3oMcggCeo305m8+uiofQGf8hmmRrmA7SEfF+Qe08ab2GOn9glINfVTbTE3AdQW
fkvAk8Zuio3hwwMBHDWWYXrKO0N3ykzcDk4V6JPUWiH1dOANf1tS3G1uJyxb4tsv
dHVdA0xL3sg7YnuSywfb82vTXvQz5QEFeDYxxLB2fMJe8LcCfgF1lkIr1DbdrMjI
hlozGCs3p/GVIVNhjGVPezWsUvzK4PIuKVM6U1qWojtAhXU/bJCvP0iBU83RlBL7
S0GGSC/qvkuPed9hAp2pnrrRo/9GEp1PZq8AXsp3nti0OaRxgxpjjQQFzZEWlOrR
bErtbKziHzl2xARvCRycNZ+QWT4ZdjmK++8pba7hOuFkRclOV4KRWk4OthBvcADu
NfNsVXdXpOnesg7TNIUJ8heVAYPjKaBHJBuG2Prghrnc95uqEQwOfbYT15zAbe6I
l3HqGerSa7WtbrnCwsf1DvyPPII=
=ZxKg
-----END PGP SIGNATURE-----
Merge tag 'bpf-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf
Pull bpf fixes from Alexei Starovoitov:
- Fix bpf_skb_change_tail() to drop the checksum offload instead of
rejecting the trim of CHECKSUM_PARTIAL skbs (Daniel Borkmann)
- Add KF_PERFMON kfunc flag and require CAP_PERFMON for kfuncs that
read arbitrary memory and for untrusted read-only memory reads
(Daniel Borkmann)
- Clear scalar delta on narrowing stack spill (Daniel Borkmann)
- Set up the frame pointer for the exception callback in arm64 JIT, and
zero-fill other CPUs when BPF_F_CPU update creates a per-cpu hash
element (Donggeun Yoo)
- Various fixes (Emil Tsalapatis):
- Fix bounds check underflow for skb-backed dynptrs
- Fix rx_queue_mapping context access code generation in bpf_sock
- Reject packet pointer arguments to subprogs that may mutate the
packet
- Reject ALU instructions that see arena and non-arena operands on
different code paths
- Fix copied_seq double-counting on sockmap self-redirect
(Geliang Tang)
- Fix divide-by-zero in btf_struct_walk() on a flexible array of
zero-sized elements, fix out-of-bounds read of rtt_min in sock_ops
(Jiayuan Chen)
- Fix bpf_sock_destroy() out-of-bounds read of sk_protocol on TIME_WAIT
and request socks, and sleeping under RCU when destroying a listener
with pending children (Jiayuan Chen)
- Fix JEQ/JNE with immediate operand in MIPS32 JIT and missing zero
extension of BSWAP 16/32 in MIPS64 JIT (Johan Almbladh)
- Avoid soft lockup in htab lookup[_and_delete] batch operations on
large maps (Jose Fernandez)
- Various fixes (Kumar Kartikeya Dwivedi):
- Verify global subprogs in each sleepability context they are
called from
- Make post-verification instruction rewrites killable
- Preserve packet pointer displacement in regsafe()
- Apply CO-RE relocations before subprogram validation, restrict
CO-RE poisoning to relocatable instructions, and reject truncated
ldimm64 CO-RE relocations in libbpf
- Assign lock identity to callback map values
- Compare stack frames in regs_exact()
- Bound ownership depth through local kptrs and graph roots
- Fix u32 overflow in map batch operations when the map size exceeds
4GB (Masoud Aghasi)
- Fix UAF in bpf memalloc due to concurrent consumption of ttrace lists
in alloc_bulk() (Pu Lehui)
- Allow gotox as the terminal instruction of a program or a subprogram
(Siddharth Chintamaneni)
- Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL, skip unsettled links
in link iterator, and reject dev-bound-only programs on other devices
(Weiming Shi)
- Reject non-negative stack offsets in stack_slot_obj_get_spi()
(Xu Yunxiang)
- Check params size before reading reserved fields in
bpf_crypto_ctx_create() (Yuqi Xu)
- Reject max_entries > INT_MAX in sock_map_alloc() (Zhao Gongyi)
- Use a 32-bit compare in xsk_map_gen_lookup() (Zhiling Zou)
- Use kvfree() in xdp_test_run_teardown() (Zhixing Chen)
* tag 'bpf-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf: (58 commits)
selftests/bpf: Test per-cpu initialization of a BPF_F_CPU created element
bpf: Zero-fill other CPUs when BPF_F_CPU creates a per-cpu hash element
bpf: Fix BSWAP 32 and 16 on MIPS64
bpf: Fix immediate JMP JEQ/JNE on MIPS32
bpf: Reject dev-bound-only programs on other devices
bpf, sockmap: Reject max_entries > INT_MAX in sock_map_alloc
selftests/bpf: Test for mixed arena/nonarena code paths
bpf: Prevent variable arena/non-arena register contents
selftests/bpf: Test rejection of pkt args to mutating subprogs
bpf: Reject pkt arguments in mutating subprogs
selftests/bpf: Add selftests for rx_queue_mapping context access
bpf: Fix bpf_sock context code generation
selftests/bpf: Test dynptr slices past end of skb
bpf: Fix bounds check for skb-backed dynptrs
selftests/bpf: Reject iterator destruction through fp+0
bpf: Reject non-negative offsets in stack_slot_obj_get_spi()
bpf: Check params size before reading reserved fields
selftests/bpf: Check local object ownership depth
bpf: Bound ownership depth through local kptrs and graph roots
selftests/bpf: Cover frame changes in bounded loops
...
Donggeun Yoo says:
====================
bpf: fix per-cpu initialization of a BPF_F_CPU created hash element
A BPF_F_CPU update that creates a [lru_]percpu_hash element writes the
named CPU's slot and leaves the others holding the recycled element's
values, so a lookup of the new key returns a deleted key's per-cpu
values.
Patch 1 zero-fills the other CPUs. Patch 2 adds the selftest: the
existing cpu_flag subtests always prime a key with BPF_F_ALL_CPUS
first, so the create path is not covered today.
v1: https://lore.kernel.org/bpf/20260920093153.439743-1-donggeunyoo.kernel@gmail.com/
v2: https://lore.kernel.org/bpf/20260923000801.1764758-1-donggeunyoo.kernel@gmail.com/
Changes in v3:
- patch 1: key init_cpu on BPF_F_CPU rather than on onallcpus (Leon
Hwang)
- patch 1: re-flow the paragraph naming pcpu_copy_value() (BPF CI AI
review)
- patch 2: pin the thread across the delete and the create, and name a
CPU other than the pinned one, so the BPF_F_NO_PREALLOC arm does not
depend on staying put (BPF CI AI review)
Changes in v2:
- patch 1: cover the BPF_F_CPU entry condition in the block comment
above pcpu_init_value() (BPF CI AI review, Alexei Starovoitov)
- patch 2: skip the new subtests instead of failing them on a
uniprocessor machine (Sashiko AI review)
====================
Link: https://patch.msgid.link/20260924102321.2120434-1-donggeunyoo.kernel@gmail.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
The existing cpu_flag subtests always prime a key with BPF_F_ALL_CPUS
before any BPF_F_CPU write, so the create path is never covered.
Add a subtest that creates the element with BPF_F_CPU on a map with
max_entries 1, so the key can only reuse the element the previous key
released, and check that the CPUs the update did not name read back
zero. Run it for PERCPU_HASH preallocated and BPF_F_NO_PREALLOC,
whose per-cpu areas come from different allocators, and for
LRU_PERCPU_HASH.
Under BPF_F_NO_PREALLOC the reuse is only guaranteed on the cpu that
ran the delete, so pin the thread across the pair, and name a cpu other
than that one in map_flags.
Signed-off-by: Donggeun Yoo <donggeunyoo.kernel@gmail.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://patch.msgid.link/20260924102321.2120434-3-donggeunyoo.kernel@gmail.com
pcpu_init_value() initializes the per-cpu area of a newly created
[lru_]percpu_hash element. The area is recycled, so when the value
comes from a BPF program (onallcpus == false) it writes the running
CPU's slot and zeroes the rest.
bpf_percpu_hash_update() passes onallcpus == true, which delegates to
pcpu_copy_value(). pcpu_copy_value() writes only the CPU named in
map_flags when BPF_F_CPU is set, so on the create path the other slots
keep the recycled element's values:
update(k1, 0xdeadc0de, BPF_F_ALL_CPUS) every CPU holds 0xdeadc0de
delete(k1) element back on the freelist
update(k2, 0xc0ffee, BPF_F_CPU | 0) creates, writes CPU 0 only
lookup(k2) CPU 0 0xc0ffee, rest 0xdeadc0de
Zero-fill the other CPUs on that arm too.
Fixes: c6936161fd ("bpf: Add BPF_F_CPU and BPF_F_ALL_CPUS flags support for percpu_hash and lru_percpu_hash maps")
Signed-off-by: Donggeun Yoo <donggeunyoo.kernel@gmail.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://patch.msgid.link/20260924102321.2120434-2-donggeunyoo.kernel@gmail.com
- Serialize the calls to pinctrl_generic_dt_nod_to_map()
- Fix a typo in S4 group in the Meson driver.
- Fix bank width and regmap usage in the MPFS-SSIO driver.
- Data register output latch behavior and voltage encoding
fixes in the Sunxi driver.
- Free the IRQ domain on the error path in the single driver.
- Fix some QUP1 SE2/SE3 groups and a missing OF module
alias in the Qualcomm drivers.
- Fix up the register banks for AON (I guess always-on)
pins in the Tegra238 driver.
Signed-off-by: Linus Walleij <linusw@kernel.org>
-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEElDRnuGcz/wPCXQWMQRCzN7AZXXMFAmq1Bm4ACgkQQRCzN7AZ
XXM36g//fk1LQHrRfCHR4VmPTP8SIielpN4J6RaTdVZYrOF5HB4FU1nkJvhgNH73
YAiIeBR/XG7gevMnfuE3w9H6zSrw7bb4l1+piV+o4T5Zo1SNC2WAnHdIXJ/isrZq
rHjwBcd5kvit+2VlaUxLZERc8V8L7+t6rD1+QDDrgqd2Ji3ekKB5bB4kdumuE5Yp
c+oirXvcgC7Bi2Ql35HTeWFmie5IAbfAHFiXryUwJREZNbakS17sQRXQxesib0fi
UPml71+vDVluKtluB065PwE8W4JpLi7+SkhMcB4xgT/ofMt46wzTtCU6VfBaTM/0
dHLr6Kr9ajjmNzk5i3DZMFFY2C2ywqyGCCfgTO2m5wX9WaBNFoO8UsZ9Xb/Ij+RZ
9T6Ub6QCJcvvZIScRXTAQEKiJ4I4cMOt1wL4rJfX8YQA0Aha9r7YXxnLxBM7AgvB
8AzIJcgm5RSC2uJaRnNpSgOvBk6XYXGnC22MTbDR3CIdkYZcWy7M9XLYI21UtCOh
ZmYvxiJGHoa2qe+AgHYgvO5lFIW9qTUOL11XXQJQwziTC7A/I/Qnf6Gwyq12KE1Q
TuAGRqeWCo4UPEYhc5myKceF1J6ljJosWwsF3VH9Vj4N2/CHIcbikWE33g1qCIbf
VCsPaPKegsLoK4nNau0z296nqNmNFjmuyTn8gcdEMlQYGP4WwhA=
=PxJM
-----END PGP SIGNATURE-----
Merge tag 'pinctrl-v7.3-2' of git://git.kernel.org/pub/scm/linux/kernel/git/linusw/linux-pinctrl
Pull pin control fixes from Linus Walleij:
- Serialize the calls to pinctrl_generic_dt_nod_to_map()
- Fix a typo in S4 group in the Meson driver
- Fix bank width and regmap usage in the MPFS-SSIO driver
- Data register output latch behavior and voltage encoding
fixes in the Sunxi driver
- Free the IRQ domain on the error path in the single driver
- Fix some QUP1 SE2/SE3 groups and a missing OF module alias
in the Qualcomm drivers
- Fix up the register banks for AON (I guess always-on) pins
in the Tegra238 driver
* tag 'pinctrl-v7.3-2' of git://git.kernel.org/pub/scm/linux/kernel/git/linusw/linux-pinctrl:
pinctrl: tegra238: Fix register bank for AON pin groups
pinctrl: qcom: ipq5210: Publish the OF module alias
pinctrl: qcom: nord: Split QUP1 SE2/SE3 into lane-pair functions
pinctrl: single: free the IRQ on domain creation failure
pinctrl: sunxi: A523: fix voltage withstand encoding
pinctrl: sunxi: keep a shadow copy of the data register output latches
pinctrl: mpfs-mssio: use correct regmap function to set bank voltage
pinctrl: mpfs-mssio: fix width of unused bank voltage setting
pinctrl: generic: serialise pinctrl_generic_dt_node_to_map()
pinctrl: meson: Fix typo in s4 group name
Rework of HugeTLB bootmem allocation forgot to add the name for a new
RSV_HUGETLB flag for proper display in debugfs.
Add the flag name now.
-----BEGIN PGP SIGNATURE-----
iQEzBAABCgAdFiEEeOVYVaWZL5900a/pOQOGJssO/ZEFAmq00GcACgkQOQOGJssO
/ZFJxwf/TlhW+APk3p9UXHTMXTvsefWxrox7mlVEBAh+nqpiF43aDeZySV6IW4yr
cHqBpI+yheyiuh1dOqfsPB/8b8jFV2GyBmknD+QbRhJi5Q8KXALVYgaKIi2WXaj5
rHNuVn7aTwUbwEBaiwrFWfWce6GSLqFGoDYTb2iSg1Z/ZdOXnWeTil8iOONCAMSw
3h8joiqPV7OlNDInxWYrlwDAvPo5Sr0VwBT7+GpuahjVB21l/XINPMwZUmLucF3t
y3+WHYTAH8f98KF0pBzJeD7XJX/nupeyzKhvJHLbg6XxbvFh3pz3OTts4tQA3Khy
REwmEB/v9Hbl1wsfA6XNROkgQN+l5g==
=t0mt
-----END PGP SIGNATURE-----
Merge tag 'fixes-2026-09-24' of git://git.kernel.org/pub/scm/linux/kernel/git/mm/memblock
Pull memblock fix from Mike Rapoport:
"The rework of HugeTLB bootmem allocation forgot to add the name for a
new RSV_HUGETLB flag for proper display in debugfs.
Add the flag name now"
* tag 'fixes-2026-09-24' of git://git.kernel.org/pub/scm/linux/kernel/git/mm/memblock:
mm: memblock: add missing HugeTLB flag name
- Fix the recently merged user ABI for the Arm CMN PMU driver filtering
logic so that the ordering matches the hardware spec
- Fix spurious warning when attempting to read PROT_NONE mappings of
/dev/mem
- Allow WFxT to be disabled on the command line, which is necessary for
some configurations of recent Apple SoCs
- Fix EL2 fine-grained trap configuration for the CPU PMU
- Fix MIDR matching when applying CPU errata workarounds in a VM
-----BEGIN PGP SIGNATURE-----
iQFEBAABCgAuFiEEPxTL6PPUbjXGY88ct6xw3ITBYzQFAmq06TIQHHdpbGxAa2Vy
bmVsLm9yZwAKCRC3rHDchMFjNPGQCACK7VeQk7ER46znaeMNyHaQARWkuF7D3wdU
wCvt/hppo6DzHpsiWw5rDrBIHyeVpWkilDVROuaM1q8Qf6HaFe2h+sbuK96OVo1Y
OLP1aZUBj3ZGLUNBIxDANP4A200Avd6gFLLY2jPvZ2YyJfEB9Ok3D0KahaRdtMh9
PGX4qo3j7dZaTLChMrVhXApAidkZ079w5+Di5wXilU5QNyCWsfA+SKBY7jZWP7jw
yPQ5PPDeYDYUziCUT4ooAegY9vODgmtbikXPFQQzF0zPeTtqKuFwSekdXnkJQS3E
R3+bBmV5JrDuitjMqUvrxreTGZqWj6R1mHL4tsActCnhTFEc2mar
=dNHO
-----END PGP SIGNATURE-----
Merge tag 'arm64-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux
Pull arm64 fixes from Will Deacon:
- Fix the recently merged user ABI for the Arm CMN PMU driver filtering
logic so that the ordering matches the hardware spec
- Fix spurious warning when attempting to read PROT_NONE mappings of
/dev/mem
- Allow WFxT to be disabled on the command line, which is necessary for
some configurations of recent Apple SoCs
- Fix EL2 fine-grained trap configuration for the CPU PMU
- Fix MIDR matching when applying CPU errata workarounds in a VM
* tag 'arm64-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux:
arm64/boot: Disable trapping of PMZR_EL0 writes to EL2
arm64: errata: match the target implementation CPU's own MIDR
arm64: Add override for WFxT
arm64: io: Reject non-user protection in ioremap_prot()
perf/arm-cmn: Fix multi-filter encoding
The 16/32-bit byteswap implementations for MIPS64r1 and earlier do
not have an explicit zero extension afterwards. The input is first
sign-extended to 64 bits, and the byteswap sequence can then leave
the result sign-extended depending on the value of the low bits.
Add the missing zero-extension.
Found with test_bpf on MIPS64r1 emulated by QEMU.
Fixes: fbc802de6b ("mips, bpf: Add new eBPF JIT for 64-bit MIPS")
Signed-off-by: Johan Almbladh <johan.almbladh@anyfinetworks.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://patch.msgid.link/20260923105158.3514342-2-johan.almbladh@anyfinetworks.com
An addu instruction was emitted instead of addiu, causing the immediate
value 1 to be interpreted as register $at. This made the comparison
result invalid when the immediate operand was negative. Note that $at
is mapped to BPF_REG_AX, which is used for constant blinding.
Fix the instruction to use the immediate form.
Found with test_bpf on MIPS32r1 emulated by QEMU.
Fixes: eb63cfcd2e ("mips, bpf: Add eBPF JIT for 32-bit MIPS")
Signed-off-by: Johan Almbladh <johan.almbladh@anyfinetworks.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://patch.msgid.link/20260923105158.3514342-1-johan.almbladh@anyfinetworks.com
__init_el2_fgt2() writes one mask to both HDFGRTR2_EL2 and HDFGWTR2_EL2.
PMZR_EL0 is write-only, so its trap bit, nPMZR_EL0, exists only in
HDFGWTR2_EL2 and is therefore never set: a PMZR_EL0 write from the host
traps to EL2, where the nVHE hypervisor has no handler and BUG()s. The
kernel never writes PMZR_EL0, but kernel.perf_user_access=1 has the PMU
driver set PMUSERENR_EL0.UEN for a task with a user-read event, so a
write from EL0 reaches the trap and takes the host down without a panic
message.
Accumulate the HDFGWTR2_EL2 bits separately, as __init_el2_fgt() already
does for HDFGWTR_EL2, and set nPMZR_EL0 with the other FEAT_PMUv3p9
bits.
Fixes: 858c7bfcb3 ("arm64/boot: Enable EL2 requirements for FEAT_PMUv3p9")
Cc: stable@vger.kernel.org
Signed-off-by: Fuad Tabba <fuad.tabba@linux.dev>
Reviewed-by: Anshuman Khandual <anshuman.khandual@arm.com>
Reviewed-by: Oliver Upton <oupton@kernel.org>
Signed-off-by: Will Deacon <will@kernel.org>
__bpf_offload_dev_match() falls back to comparing offdev pointers after an
exact netdev mismatch. Bound-only programs normally have NULL offdevs, so
unrelated netdevs compare equal. A bound-only program on an
offload-registered netdev can instead inherit a real offdev and match a
sibling port. With CAP_BPF and CAP_NET_ADMIN, a caller can use
bpf(BPF_LINK_CREATE) with a different target ifindex to run metadata kfuncs
specialized for the bound driver on the target driver's xdp_buff. Running a
veth-bound program on tun reads beyond tun's bare stack xdp_buff as a
veth_xdp_buff.
Oops: general protection fault, probably for non-canonical address
KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017]
RIP: 0010:veth_xdp_rx_timestamp (drivers/net/veth.c:1673)
Call Trace:
...
tun_build_skb (drivers/net/tun.c:1739)
tun_get_user (drivers/net/tun.c:1856)
tun_chr_write_iter (drivers/net/tun.c:2091)
vfs_write (fs/read_write.c:595 fs/read_write.c:687)
ksys_write (fs/read_write.c:739)
do_syscall_64 (arch/x86/entry/syscall_64.c:84)
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
Kernel panic - not syncing: Fatal exception in interrupt
Restrict non-offloaded programs to exact netdev matches and retain the
shared-offdev fallback only for genuinely offloaded multi-port programs.
Fixes: 2b3486bc2d ("bpf: Introduce device-bound XDP programs")
Reported-by: <co+ac0a8c41de69121d@bugs.sh>
Signed-off-by: Weiming Shi <bestswngs@gmail.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://lore.kernel.org/bpf/20260917161335.1020405-2-bestswngs@gmail.com/
Link: https://patch.msgid.link/20260920132303.4109240-3-bestswngs@gmail.com
sock_map_alloc() only rejects max_entries == 0 and otherwise allows any
u32 value. sock_map_free() then walks the sks[] array with a signed int
iterator:
int i;
for (i = 0; i < stab->map.max_entries; i++)
struct sock **psk = &stab->sks[i];
When a SOCKMAP is created with max_entries = 0xffffffff (UINT_MAX), the
allocation of 32 GiB can succeed on large-memory hosts. During free the
counter reaches 0x80000000, wraps to INT_MIN, is sign-extended by movslq
and turned into a ~16 GiB negative offset from stab->sks, pointing far
below the allocation.
The faulting access is an xchg() write in sock_map_free(). Without
KASAN, the same out-of-bounds write can fault on an unmapped vmalloc page
or corrupt an unrelated allocation if that vmalloc address is populated.
On a KASAN kernel with CONFIG_KASAN_VMALLOC=y, the shadow check for that
address hits an unmapped shadow page and oopses first:
BUG: unable to handle page fault for address: fffff521b59c5a00
RIP: 0010:kasan_check_range+0x107/0x190
Call Trace:
sock_map_free+0x93/0x190
map_create+0x68d/0xb30
__sys_bpf+0x21e/0x2e70
Vmcore confirmed stab->map.max_entries == 0xffffffff, stab->sks ==
0xffffc911ace2d000, and the faulting address sks + (s64)INT_MIN * 8
exactly at 0xffffc90dace2d000. The same buggy path is reached on the
normal close()/bpf_map_free_deferred() path whenever such a map is
destroyed.
sock_map_alloc() used to bound its allocation size through
bpf_map_charge_init(), but the bound was dropped when rlimit-based memory
accounting was removed. Reject max_entries > INT_MAX at creation time so
the signed iterator in sock_map_free() never sees a value that would
overflow.
Triggered by syzkaller and reproduced on both a 6.6-based KASAN kernel
and the upstream v7.3-rc2 kernel.
Fixes: 0d2c4f9640 ("bpf: Eliminate rlimit-based memory accounting for sockmap and sockhash maps")
Signed-off-by: Zhao Gongyi <zhaogongyi@BYTEDANCE.COM>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://patch.msgid.link/20260917121016.48171-1-zhaogongyi@bytedance.com
Add a selftest to confirm the verifier rejects ALU operations
that return arena or non-arena results depending on code path.
Signed-off-by: Emil Tsalapatis <emil@etsalapatis.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://patch.msgid.link/20260922172028.6269-9-emil@etsalapatis.com
The verifier marks ALU instructions that include at least
one arena operand with needs_zext: These instructions are
fixed up after verification to be ALU32 instructions to
ensure that the result is a valid offset into an arena.
However, different code paths may provide two non-arena
64-bit arguments to the same instruction. The result of
the operation in that code path is wrong, since it is
now unexpectedly truncated to 32 bits and zero-extended.
Add logic to the verifier to ensure every instruction either
always has at least one PTR_TO_ARENA argument, or never does.
Since needs_zext already tracks the first scenario, add a
prevent_zext field in bpf_insn_aux to track the latter.
Reject instructions that use arena arguments and have prevent_zext
set, or do not have arena arguments and have needs_zext set.
Fixes: 6082b6c328 ("bpf: Recognize addr_space_cast instruction in the verifier.")
Reported-by: Nicholas Carlini <nicholas@carlini.com>
Suggested-by: Nicholas Carlini <nicholas@carlini.com>
Signed-off-by: Emil Tsalapatis <emil@etsalapatis.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://patch.msgid.link/20260922172028.6269-8-emil@etsalapatis.com
Add a selftests that ensures that PTR_TO_PACKET arguments can
only be passed to subprogs that will never adjust the underlying
packet memory, and are rejected otherwise.
Signed-off-by: Emil Tsalapatis <emil@etsalapatis.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://patch.msgid.link/20260922172028.6269-7-emil@etsalapatis.com
The verifier tracks changes in how PTR_TO_PACKET registers'
bounds are modified across subprog boundaries. PTR_TO_PACKET
registers are actually passed as PTR_TO_MEM, which is assumed
valid for the entire call. This is not the case with packet memory,
where a pskb_* call may invalidate its memory region.
Reject BPF code that passes PTR_TO_PACKET pointers to subprogs that
may mutate a packet. We cannot pass the pointer as a true PTR_TO_PACKET
because we would also need to somehow pass the PTR_TO_PACKET_META
or PTR_TO_PACKET_END to the subprog. Since we cannot avoid representing
the pointer in the subprog as PTR_TO_MEM, only permit it if the
subprog is guaranteed not to mutate the packet.
Fixes: 80f281664f5a ("bpf: Support pointers in global func args")
Reported-by: Nicholas Carlini <nicholas@carlini.com>
Suggested-by: Nicholas Carlini <nicholas@carlini.com>
Signed-off-by: Emil Tsalapatis <emil@etsalapatis.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://patch.msgid.link/20260922172028.6269-6-emil@etsalapatis.com
Add tests to ensure the verifier properly tracks the 0 bit state
and width of the rx_queue_mapping field read from struct sock.
Signed-off-by: Emil Tsalapatis <emil@etsalapatis.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://patch.msgid.link/20260922172028.6269-5-emil@etsalapatis.com
Currently, the ctx access code reads the rx_queue_mapping
field with either a 4-byte or 2-byte load. The rest of the bits
in the register are marked known zero by the verifier. However,
the emitted ctx access code places in the register on certain
the special value (-1) using BPF_MOV_IMM64, which gets sign-extended
to turn on all the bits in the register. By shifting this value right,
the program ends up with a value at runtime above what the verifier
assumes is possible.
Fix this by ensuring the read value is as wide as the assumed size.
Use MOV32 instructions instead of MOV64 instructions to keep
the upper bits zero as assumed by the verifier. Also properly report
the size of the destination variable (the bpf_sock field, 4 bytes) instead
of the source (the socket field, 2 bytes).
Fixes: c3c16f2ea6 ("bpf: Add rx_queue_mapping to bpf_sock")
Reported-by: Nicholas Carlini <nicholas@carlini.com>
Suggested-by: Nicholas Carlini <nicholas@carlini.com>
Signed-off-by: Emil Tsalapatis <emil@etsalapatis.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Reviewed-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Link: https://patch.msgid.link/20260922172028.6269-4-emil@etsalapatis.com
Add a selftest to ensure dynptr slices cannot include
past the end of the linear area of an skb.
Signed-off-by: Emil Tsalapatis <emil@etsalapatis.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://patch.msgid.link/20260922172028.6269-3-emil@etsalapatis.com
The skb_pointer_if_linear() function checks whether a
memory region of length len starting at offset off into
the skb is in the linear area, and returns a pointer to
the region if so. The check currently subtracts between
skb_headlen and offset of the check, and since skb_headlen
is unsigned the subtraction can underflow. This causes the
bounds check to spuriously pass and generate an arbitrary
pointer of the form *(skb->data + off).
The only user of this helper is currently skb-backed BPF
dynptr code. Returning the wrong pointer leads to the
dynptr erroneously being backed with invalid memory.
Ensure the subtraction cannot underflow, and fail the check if
it would. Use u64 arithmetic to also prevent overflow when
calculating (skb_headlen(skb) - off) since off is unsigned.
Fixes: 6f5a630d7c ("bpf, net: Introduce skb_pointer_if_linear().")
Reported-by: Nicholas Carlini <nicholas@carlini.com>
Signed-off-by: Emil Tsalapatis <emil@etsalapatis.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Reviewed-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Link: https://patch.msgid.link/20260922172028.6269-2-emil@etsalapatis.com
Tracepoint consumers use a ruleset ID and version to identify the
successful landlock_add_rule(2) call prefix used to create a domain.
LANDLOCK_MAX_NUM_RULES bounds distinct stored rules, not successful
calls: re-adding already-present rights for an object or port succeeds
without increasing num_rules. Because every successful call increments
the version, these calls can wrap the 32-bit counter and give different
prefixes the same trace identity.
Widen the counter and its trace fields to 64 bits so the counter cannot
wrap in practice, while preserving the successful-call semantics.
Saturating would alias all subsequent histories, while rejecting a call
at the limit would change otherwise valid syscall behavior solely for
trace metadata.
Cc: Günther Noack <gnoack@google.com>
Cc: Steven Rostedt <rostedt@goodmis.org>
Fixes: 63747c9477 ("landlock: Add landlock_add_rule_fs and landlock_add_rule_net tracepoints")
Reviewed-by: Günther Noack <gnoack@google.com>
Link: https://patch.msgid.link/20260922132615.1025945-1-mic@digikod.net
Signed-off-by: Mickaël Salaün <mic@digikod.net>
For a domain, this array stores the access masks for each layer (of
which there are num_layers of them). This annotation serves as useful
documentation.
Signed-off-by: Tingmao Wang <m@maowtm.org>
Reviewed-by: Günther Noack <gnoack@google.com>
Link: https://patch.msgid.link/20260208235449.1124354-1-m@maowtm.org
[mic: Rebase on the ruleset/domain split, and update commit message]
Signed-off-by: Mickaël Salaün <mic@digikod.net>
-----BEGIN PGP SIGNATURE-----
iQIzBAABCAAdFiEEL65usyKPHcrRDEicpmLzj2vtYEkFAmqyY7EACgkQpmLzj2vt
YEnprxAAofmpQUorlic97WALU2CamXN/hdzLGlra2RPW6eJyxQUlwqR8xcUptx3e
14OM5X4WDHfFD1lRFx7/flzn2J5h5CLXUWnNUp5DR7W0GLQSnSwOiuawfb5/Enkd
aqhgsqC2nfEjxQ3iqdsY1MTASN/MEjolNU66tP31DQH5D+CGY6eZtivNwFHaHjJI
Ps4/vr2nuddSCsXaWRKwdBQ9wMr8g+F7dIeI8vqAJlWg5IdN0tu3ClAuHUqMr6X3
zMHJ7xkkrRg7S40xeQsajDiPGRRWPkC6G3lrJ1OSFOP1IEMKT5dLLg5HB2wLwfzI
Xzw4CJZiSIaNKyMQLQJcik8wZZbc60A2ulDscbpk9PLlr9nweBc+7wzVZ0mOQ6Lo
rD2iYG7ROG684Jt5HVd9SPrIgjCDnlOXDBT9JLyPCw38eEysEHOdSlwA0CSJyR21
cD0UmfIUgFDXxR/omcPbZDVng8683eRR3W/Tj2XPBOyKZYF/JtnIsrbowIN2dmGe
PKnsrtp2LW5/xiO/lTfEsiiHL8WoxtXj/Mwoq/NuZm4TvZ/C3nd3ZiEaL5UQeYYc
AyTFOqBe4DoLauyS2M50gitvDpSBFS9i5xrjCukalpJGfTUlX8lQjU7kdH7O5rbh
VlMjlYqPNSyd4Yo/nveqIS3ELrKGs5z3oDSxwSB05h1nCgn3dgo=
=k0Hr
-----END PGP SIGNATURE-----
Merge tag 'hid-for-linus-2026092202' of git://git.kernel.org/pub/scm/linux/kernel/git/hid/hid
Pull HID fixes from Jiri Kosina:
- new device IDs/quirks (Logitech G502X, Elecom M-XT4DRBK, Steelseries
Arctis 7, Asus Rog Z13 Folio, Lenovo Yoga Slim Gen 11)
- fixes for various code issues found by LLMs
* tag 'hid-for-linus-2026092202' of git://git.kernel.org/pub/scm/linux/kernel/git/hid/hid:
selftests/hid: add unnumbered variant to the hid_bpf tests
HID: bpf: fix __hid_bpf_hw_check_params report length
selftests/hid: add define for commonly used buf size
HID: amd_sfh: Validate PCI BAR size before mapping
HID: elecom: fix bus type for M-XGL20DLBK
HID: elecom: Add support for ELECOM M-XT4DRBK (018E)
HID: corsair-void: Fix firmware event packet description
HID: i2c-hid: Add i2c-hid-quirk-bad-input-size quirk for 0911:5288 device
HID: hid-oxp: use cancel_delayed_work_sync() in remove
HID: i2c-hid: add reset quirk for Lenovo Yoga Slim 7x Gen 11 keyboard
HID: roccat: fix locking in roccat_connect() and roccat_disconnect()
HID: steelseries: Add support for Arctis 7 (2018)
HID: logitech-hidpp: Add support for G502 X Lightspeed USB mouse
HID: fix semantic patch and improve its performance
HID: alps: fix use-after-free on input2 registration failure
HID: alps: unregister DualPoint Stick input device on remove
HID: winwing: fix use-after-free in force feedback teardown
HID: multitouch: Add report ID mismatch quirk for ASUS ROG Z13 Folio
HID: wacom: fix OOB read in wacom_wac_pen_serial_enforce()
HID: quirks: add ALWAYS_POLL quirk for SDINNOVATION gaming keyboard
Fix unbalanced handover IRQ for attached and the overwriting of the
shutdown return value in the Qualcomm PAS remoteproc driver.
Correct the conditions in the Qualcomm modem remoteproc driver for which
secure services to require after the move to "PAS service".
Ensure that the correct addresses are passed to iommu_unmap() in as
Qualcomm ADSP carveout are torn down.
-----BEGIN PGP SIGNATURE-----
iQJCBAABCgAsFiEEBd4DzF816k8JZtUlCx85Pw2ZrcUFAmqx46IOHGJqb3JuQGty
eW8uc2UACgkQCx85Pw2ZrcUCDRAAhm0J2Y3ol3qrFK7XrhbFvn6TewDHRD7LGntt
VVhplPj3/QSUWduXEtyNyMV/Illx3LV8DxlmDw85doRJtcMqCeBpRkh/u71YPxYw
PIrEmXcCjBP3iYDB+7lsX4PkgmQOgnyK+pDK+T5K0ZgE0L3vHT4k1TuyspBLHREt
d2goRCB61qDOtqcvFuaG9MbZw69cyaeF60drUBTxaaGIcAz12X+6lBjl4xv9sjrE
fwG/TLrGqRkoioInxuxL8OAks1ylaJtouu6bGnKK65/bvJ3ApE1/yj15Nn2kBv9J
KjAhAPfY1MXARXa7YR9+HJOZAUMTCyx7RfYbKEsVlNUqazL6PHYWMnTgJZA5IoM0
j8vfgvDLlZvDjl628DzhKVz4dV7P0QMBKbB1gTWzQaGNxNpgyVznyqpFl8rX7wuC
Jp5SLR33ujMqK6iWhgexvHC4dbWux03MYovbysvz97Q3kr9U+07pIU2zIb97RS8s
HAErFKlQLvg7MGk1RkmsXMGnxsHFYpbqvJfngnaUe2bxFuf4NwQ3li2XOrWK/UxP
61AXNVBBI/aFOlT3VbFLC7YRpmOykGlbv3q/OKKb0s3M7ofLaSQ+F4S/j02g524o
nZAKejx2rJO9h8ty6bsJodLorGJ5c/sjknQQyFIme3h0jmd1yNmyPpe07GHT44hH
nbUxZzo=
=bkNw
-----END PGP SIGNATURE-----
Merge tag 'rproc-v7.3-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/remoteproc/linux
Pull remoteproc fixes from Bjorn Andersson:
"Fix unbalanced handover IRQ on attach and the overwriting of the
shutdown return value in the Qualcomm PAS remoteproc driver.
Correct the conditions in the Qualcomm modem remoteproc driver for
which secure services to require after the move to 'PAS service'.
Ensure that the correct addresses are passed to iommu_unmap() as
Qualcomm ADSP carveout are torn down"
* tag 'rproc-v7.3-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/remoteproc/linux:
remoteproc: qcom_q6v5_pas: Fix error masking in qcom_pas_stop()
remoteproc: qcom_q6v5_adsp: Fix iommu_unmap() usage
remoteproc: qcom_q6v5_mss: Don't require PAS for memory protection
remoteproc: qcom: q6v5_pas: Don't enable handover IRQ on attach
Five are DAMON fixes. One fixes an arm64 contpte bug where DAMON can
write past the end of a page-table page, resulting in memory corruption
and possible crashes.
Two are hugetlb fixes. One fixes an mremap() address calculation bug
which can panic x86-64.
There's also a missing anon_vma publication barrier which can result in
hung tasks, and a writeback fix to keep long cgroup writeback drains from
delaying Tasks-RCU grace periods.
The remainder are smaller fixes and maintenance changes.
-----BEGIN PGP SIGNATURE-----
iHUEABYKAB0WIQTTMBEPP41GrTpTJgfdBJ7gKXxAjgUCarHHNAAKCRDdBJ7gKXxA
jhb7AP4yE/k7RrZC6zWg4M9ejI3fVlHI9+EG1mCLGiV57jZ4mAEA9LLSZryOD6Nc
zsaeCtZhHcEdxW6EhO18hMfH4b7oJA0=
=alhC
-----END PGP SIGNATURE-----
Merge tag 'mm-hotfixes-stable-2026-09-21-17-08' of git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm
Pull MM fixes from Andrew Morton:
"14 hotfixes. 10 are cc:stable. 11 are for MM.
Five DAMON fixes: one fixes an arm64 contpte bug where DAMON can write
past the end of a page-table page, resulting in memory corruption and
possible crashes.
Two hugetlb fixes: one fixes an mremap() address calculation bug which
can panic x86-64.
There's also a missing anon_vma publication barrier which can result
in hung tasks, and a writeback fix to keep long cgroup writeback
drains from delaying Tasks-RCU grace periods.
The remainder are smaller fixes and maintenance changes"
* tag 'mm-hotfixes-stable-2026-09-21-17-08' of git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm:
MAINTAINERS: update Xu Xin's email
writeback: report a Tasks-RCU quiescent state per cgwb drain pass
mm/damon/core: reset invalid quota->charge_target_from
MAINTAINERS: add Baoquan and Baolin as MGLRU reviewers
mm/rmap: fix missing barrier between anon_vma init and vma->anon_vma publish
mm/hugetlb: preserve mremap address delta when skipping page tables
mm/damon/core: fix unconditionally skip last region
mm/damon/vaddr: avoid hw-driven pte updates during damon_hugetlb_mkold()
mm/damon/core: allow esz to be set to zero
mm/damon/ops-common: use a page-aligned address in damon_ptep_mkold()
ocfs2: make ocfs2_calc_xattr_init() return void
mailmap: update Haowen Bai's email address
selftests/cgroup: account for zswap shrinker writeback
mm/hugetlb: do not dissolve gigantic pages without runtime support
Xu Yunxiang says:
====================
bpf: Reject non-negative stack object offsets
Reject non-negative offsets before converting a stack object address to a
stack slot index. Add a regression test for iterator destruction through
fp+0.
Changes in v2:
- Split the kernel change and selftest as requested by Andrii.
- Rebase onto bpf/master at a11212910c.
- Keep the original code and test changes unchanged and retain Sun Jian's
Reviewed-by on both parts.
v1: https://lore.kernel.org/bpf/20260911084314.3481637-1-xyx2021@mail.ustc.edu.cn/
Split request: https://lore.kernel.org/bpf/CAEf4BzbYzt-Riekpc-A=MfQft9ZELwSDSE8kkQO1ZOyR3O_FAg@mail.gmail.com/
Validation on this exact candidate with a matching bpf_testmod:
- W=1 verifier, full kernel/modules, changed BPF objects and test_progs
builds passed.
- iters: 1/97 passed; 0 skipped.
- dynptr: 2/132 passed; 0 skipped.
- irq: 1/33 passed; 0 skipped.
- res_spin_lock: 3/14 passed; 1 skipped.
- file_reader: 1/8 passed; 0 skipped.
- kmem_cache_iter: 1/3 passed; 0 skipped.
- dmabuf_iter: 1/4 passed; 0 skipped.
No selected test failed. The VM ran with panic_on_warn and panic_on_oops;
no kernel WARN, Oops or panic was found.
res_spin_lock_stress skips because the VM has no hardware PMU.
Annotated verifier tests check load outcomes and diagnostics. The full
unfiltered suite, sanitizer configurations and architecture matrix were
not run.
Please queue this fix for stable after it reaches the BPF tree.
====================
Link: https://patch.msgid.link/20260920210423.345636-1-xyx2021@mail.ustc.edu.cn
Signed-off-by: Andrii Nakryiko <andrii@kernel.org>
Add a verifier regression test that initializes a numeric iterator at fp-8
and attempts to destroy it through fp+0. The verifier must reject the
non-negative offset instead of treating it as the initialized stack slot.
Check the offset diagnostic to ensure rejection happens at the stack
object address check. The numeric iterator destroy operation is a no-op;
this test checks verifier rejection and does not run the program.
Signed-off-by: Xu Yunxiang <xyx2021@mail.ustc.edu.cn>
Signed-off-by: Andrii Nakryiko <andrii@kernel.org>
Reviewed-by: Sun Jian <sun.jian.kdev@gmail.com>
Link: https://lore.kernel.org/bpf/20260920210423.345636-3-xyx2021@mail.ustc.edu.cn
bpf_get_spi() computes (-off - 1) / BPF_REG_SIZE using C division,
which truncates toward zero. For off == 0, this produces spi 0, the
same index used by the valid stack slot at fp-8.
stack_slot_obj_get_spi() currently checks alignment and the resulting
spi bounds, but does not reject the non-negative offset itself. It can
therefore validate a PTR_TO_STACK register holding fp+0 against an
iterator stored at fp-8 even though the runtime receives the actual fp+0
pointer. An effectful iterator kfunc can then interpret memory outside
the BPF stack as iterator state.
Reject non-negative offsets before converting the offset to an spi. All
valid stack objects begin at a negative offset from the frame pointer.
Fixes: 06accc8779 ("bpf: add support for open-coded iterator loops")
Signed-off-by: Xu Yunxiang <xyx2021@mail.ustc.edu.cn>
Signed-off-by: Andrii Nakryiko <andrii@kernel.org>
Reviewed-by: Sun Jian <sun.jian.kdev@gmail.com>
Link: https://lore.kernel.org/bpf/20260920210423.345636-2-xyx2021@mail.ustc.edu.cn
For 64-bit Linux kernels, increase the default kernel stack size
(THREAD_SIZE_ORDER) to 32 kB, in order to avoid kernel crashes which have been
triggered recently when building the debian vtk9 package with gcc 17:
stackcheck: kworker/u128:0 will most likely overflow kernel stack (sp:179a83af0, stk bottom-top:179a80000-179a84000)
Kernel panic - not syncing: low stack detected by irq handler - check messages
CPU: 2 UID: 0 PID: 30760 Comm: kworker/u128:0 Tainted: G W 6.18.46-dirty #1 NONE
Tainted: [W]=WARN
Hardware name: 9000/800/rp3440
Workqueue: writeback wb_workfn (flush-259:0)
Backtrace:
[<000000004022f050>] show_stack+0x70/0x90
[<000000004022378c>] dump_stack_lvl+0x124/0x190
[<000000004022382c>] dump_stack+0x34/0x48
[<000000004020212c>] vpanic+0x204/0x648
[<00000000402025c4>] panic+0x54/0x58
[<0000000040232230>] do_cpu_irq_mask+0x3f8/0x440
[<0000000040227070>] intr_return+0x0/0xc
Signed-off-by: Helge Deller <deller@gmx.de>
Reported-by: John David Anglin <dave.anglin@bell.net>
Cc: stable@vger.kernel.org # v6.18+
Signed-off-by: Carlos Maiolino <cem@kernel.org>
-----BEGIN PGP SIGNATURE-----
iJUEABMJAB0WIQSmtYVZ/MfVMGUq1GNcsMJ8RxYuYwUCarEtCAAKCRBcsMJ8RxYu
YwmHAX4+ML995OtOeKIN2Cpiu/0RYW/bHPrBBCHsiZN2BFZ3Ap2W7nxm4/OFewA9
5oB6eKgBgL8Zi2K0ZPsiF+IxAEkWUBkvCgiQtByO3dSS6aMR6KzfrQBj0Pftlcgy
z+C74fVlyA==
=USzk
-----END PGP SIGNATURE-----
Merge tag 'xfs-fixes-7.3-rc5' of gitolite.kernel.org:/pub/scm/fs/xfs/xfs-linux
Pull xfs fixes from Carlos Maiolino:
"This mostly contain 'random' bugfixes found by LLM tools on different
xfs subsystems. A few code cleanups and a NULL ptr deref on zoned
support. Those 'random' bugfixes include possible buf overrus, UAFs,
block leaks, etc..."
* tag 'xfs-fixes-7.3-rc5' of gitolite.kernel.org:/pub/scm/fs/xfs/xfs-linux: (26 commits)
xfs: fix wild memcpy access when formatting ondisk rtrefcount btree roots
xfs: don't let hidden_space go negative in xfs_metafile_resv_init
xfs: drop dquot flush lock when we can't find a buffer to flush
xfs: fix cursor and pointer handling when recovering iunlink buckets
xfs: fix blockgc group quota scanning when usrquota isn't enforced
xfs: don't merge different file IO error types
xfs: don't let memory failures leak blocks and kill repairs
xfs: don't cross reference rmapbt with bitmaps if they're incomplete
xfs: fix rtgroup repair estimations
xfs: call xfs_dquot_set_prealloc_limits if we installed default rtb limits
xfs: fix typos and repeated words in comments
xfs: remove unused xfs_reflink_remap_range declaration
xfs: remove duplicate INO1_WRITTEN check
xfs: don't try to get a reference to a NULL oz in xfs_get_cached_zone
xfs: check di_forkoff correctly in scrub
xfs: only flag zero padding for dir3 data blocks, not dir3 block blocks
xfs: fix integer overflows in xbitmap set functions
xfs: use the correct reservations for rtrmap/refcount recovery
xfs: don't call xfs_exchange_range_finish for a dry run
xfs: check padding field in xfs_ioc_commit_range
...
The AON pin controller has a single register region and therefore,
the bank defined in the tegra238_functions[] and tegra238_aon_groups[]
for the AON pin groups must be 0. However, commit 25cac7292d
("pinctrl: tegra: Add Tegra238 pinmux driver") incorrectly specified the
bank for these pins as 1 and not 0. This means that in the
tegra_pinctrl_probe() function we use an invalid index when accessing
the pmx->regs[] array which causes an incorrect address to be used for
accessing the pinmux registers.
Fix this by correcting the bank for the AON pin groups.
Fixes: 25cac7292d ("pinctrl: tegra: Add Tegra238 pinmux driver")
Signed-off-by: Prathamesh Shete <pshete@nvidia.com>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Since the MHI HELLO exchange was relocated, it is sent only at device
registration. During a suspend-resume cycle, the firmware in WiFi
cards such as WCN7850 indefinitely waits for another HELLO,
triggering:
ath12k_wifi7_pci 0004:01:00.0: timeout while waiting for restart complete
ath12k_wifi7_pci 0004:01:00.0: failed to resume core: -110
Fix this by triggering the handshake from resume_early in the MHI
transport.
Validated on Qualcomm X1E-801800 on Lenovo Slim 7x across 10
suspend-resume cycles.
Fixes: 544d85de4d ("net: qrtr: Send HELLO message on endpoint register")
Signed-off-by: Daniel J Blueman <daniel@quora.org>
Reviewed-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Reported-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Link: https://lore.kernel.org/all/6257c447-788d-4362-851e-0d552bcf7c56@oss.qualcomm.com/
Tested-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Reported-by: Vlastimil Babka (SUSE) <vbabka@suse.com>
Link: https://lore.kernel.org/all/ab1491bb-cca5-4145-ac7d-31c966abf7b4@suse.com/
Tested-by: Vlastimil Babka (SUSE) <vbabka@kernel.org>
Reported-by: Takashi Iwai <tiwai@suse.de>
Link: https://lore.kernel.org/all/87a4plsg4w.wl-tiwai@suse.de/
Tested-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Thorsten Leemhuis <linux@leemhuis.info>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Bunch of core and driver fixes:
- Couple of fixes in core around dma_chan_put() for kref underflow, user
after free bug and waiting for rcu readers for dma devices
- mmp sg length and wrong extended DRCMR base for SpacemiT K3
- hardware buffer descriptor chain fix for xilinx dma
- sun6i fixes for status behaviour and dma position registers
- runtime pm reference leak fix for sprd driver
-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEE+vs47OPLdNbVcHzyfBQHDyUjg0cFAmqwEtUACgkQfBQHDyUj
g0dCWQ//ShhhOd2vQQttV+BSHB0xTdT/wENO4mhXcz50chHFh1diBFASMnhejOxG
dv4ZkePAxV7PLpNqRQrCz2gx89wn5Uxf71PmnLbleuJ5lOuSUMGbFL0MhLzrlfqr
2Di122aa5Va4Tp3zjNllQ4ihKMfCF02FLCXoZqelVIR/NQFFMeJhEjv/0P2foFvd
nrf5jzGJuCCbhKiV47H4a8hSb1bG68ct/mV0ZfOT5Koe4B16qPTe7Z9kW5FP0do5
++BeHLbEheA/btWUSzvnLMtGHhhUywlAab6cKEkYAcTsuxtapMMRtJmAq9bYyX1O
qS6hIC9qWMS4xc0+BUsIhwU8cXY6IINy8lPJmwc+/p4V+MJ8QMP+MrfWpWADFy0H
rTvkIdzU+Lc4fqIr97UbW+pi8Naf2NCiV2NJSYF8JT6ufeG1PymtwbeUlbhkThtZ
ISVF2/CIieyHr/eDfzNuGrYmdkSfJZgl6Rd6pCHdYQ5vgK6DImtaHfuBBm1OYXVG
NwA4vkTk6hKu2Sx2JShrSJC2js5q5gdz+9jQuvb9zZZS4I1qOARWjoe/E0wowlir
EB5bivcNX8VR49x2aYmT7Mg1CJovzs6hC1Aw9aqFIhp+1hQRku+iFOSki8Pwzl23
EcpkC7liL8S6WCo73Zh7cmT0aBvw3Y6Gpvfozh+Rr7kLZy6cfmw=
=9a97
-----END PGP SIGNATURE-----
Merge tag 'dmaengine-fix-7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/vkoul/dmaengine
Pull dmaengine fixes from Vinod Koul:
- A couple of fixes in core around dma_chan_put() for kref underflow,
use-after-free and waiting for rcu readers for dma devices
- mmp sg length and wrong extended DRCMR base for SpacemiT K3
- hardware buffer descriptor chain fix for xilinx dma
- sun6i fixes for status behaviour and dma position registers
- runtime pm reference leak fix for sprd driver
* tag 'dmaengine-fix-7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/vkoul/dmaengine:
dmaengine: mmp_pdma: fix wrong sg length in mmp_pdma_prep_slave_sg()
dmaengine: xilinx_dma: Fix hardware buffer descriptor chain after cyclic DMA
dmaengine: pxa: fix double counting of the hw descriptors
dmaengine: sun6i: fix undefined behaviour in sun6i_dma_tx_status
dmaengine: sun6i: fix non-atomic read of DMA position registers
dmaengine: xilinx_dma: Fix hardware buffer descriptor reuse order
dmaengine: wait for RCU readers before releasing dma_device
dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel()
dmaengine: Fix device kref underflow in dma_chan_put()
dmaengine: add dma_device_get() helper
dmaengine: sprd: Fix runtime PM reference leak in probe
dmaengine: ti: k3-udma-glue: fix NULL dereference in k3_udma_glue_release_rx_chn()
dmaengine: mmp_pdma: fix wrong extended DRCMR base for SpacemiT K3
- Cadence ensure work completion before clock stop
- Disable ghost Realtek on Asus GX651AX
-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEE+vs47OPLdNbVcHzyfBQHDyUjg0cFAmqwABUACgkQfBQHDyUj
g0dzrxAAmGpYUaBc5GEnTypOM8NM/UUOOWn+AMUGAb/AekqIChg42a5oVXlaAU5O
HXqXIIJ5EVddmn++s1XJvcOrMGM4412wwrOKBpCWP9+h5+My1euY9AGDrApRrFCx
DYmLvxqIDCq2MS8NmaY0RWAAkNI6TXQWsn29TBztt6xRCT7EmiM/iERJpBUhK4Sg
Oyd9nJkT6Oieln/mfWWxAexBe+W5p9l6StLM/aDnQ7LiVEa6U5vKKfmEbFceQ0z1
1c3NoJC1hTdsNUytIOKcT46an0sF7GdIe6EB0+yAq+MfS1NHZrQWOG6weVxAqldV
xS5uUadqDm18xuh8q97+fFueE/rT21JgQFWb9fsuYX3ESNpaO/8dPZtEZFVQOBBJ
fR+vvKfqm4X3LXe+wXJt/3SQ7KV1Lth/bdPl2O4FYQlfvX1XmaS6lJiBErDyNxY8
sVCdy+XBcV4MjSciwnYjARpCVAcFo2NRt931TEDgaes2glaQl/v885pTZQEsE/CO
mCaDcuBFaceuK2x9fGugqQRjCdOXAY8z6UcAUtwlUvy8g008IBssPuCQiVQvFZxs
cPM4dkbrSPiKz2vuMJepytmk2Fm8wIVWHK7ODtYywYxfkFS8pCQOIi4Wj/EiOF++
6dOKY0qxiDEr/27cqzm6YcGZ91dH9kDT4nR8W/6gXAdoqclJyCA=
=mDuH
-----END PGP SIGNATURE-----
Merge tag 'soundwire-7.3-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/vkoul/soundwire
Pull soundwire fixes from Vinod Koul:
- Cadence: ensure work completion before clock stop
- Disable ghost Realtek on Asus GX651AX
* tag 'soundwire-7.3-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/vkoul/soundwire:
soundwire: cadence_master: wait and cancel cdns->work before clock stop
soundwire: dmi-quirks: Disable ghost Realtek on Asus GX651AX
- Reject the loading of a potentially problematic microcode version
on Intel Granite Rapids systems (Chang S. Bae)
- On FRED, reconstruct the proper #GP context for rejected INT
instructions, to fix a signal ABI regression (Matthew Schwartz)
- Add a test for this signal ABI regression the x86
self-test suite (Matthew Schwartz)
- Don't emit the new and not yet properly supported EGPR instructions
(%r16-%r31) on CONFIG_X86_NATIVE_CPU=y builds (Chang S. Bae)
Signed-off-by: Ingo Molnar <mingo@kernel.org>
-----BEGIN PGP SIGNATURE-----
iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqvrhgRHG1pbmdvQGtl
cm5lbC5vcmcACgkQEnMQ0APhK1inbQ/9G4Q0h9esQ945n0uYRYvVLuj2P8DvE3XN
9d5IJ5pIYdhJCvlv8yXyv1u3sq59QYNmUgpBMghHJonhqobtnchvBSiznoAMgi8L
yjRlcaFBPX9qjFQV1W9WJQuUHhW/12QFy9Bo9n1uXEv6pYspYVDwodCaS+rEvkTF
0wK3TjETv90TravGjFscYTt2VLAiy+cd/FxkUA0sBaMLjhFpUyAPHGJe/vcf8vT3
rEXkY8EeSjv5F6eKMTDVacrSZu2c9wco1bJIsSFEcxZGFzhDbuCOGiDCkwmB3uuD
ReKbEUC0KmF8qd4Ubf0dMGpbHT9LDu9Ggex619cHFOHMupPubP+yym7aCpm3v7Sb
gZe6eV6VrSREJ+oBVKsqMrWXsg1YDj6uJhC/5K3S78xBeRq64kKsmBbC93Zp20TC
QpSAxKIFqp8C+tfKzpBmcSbcipRUfATJxLjp94QaQDp467jjJCvpDJdc12mV7WR9
0gMtFjxUaIe8BGX7s2PuWPgZ8+CIH0hZQuttxUU4QWvM2RGU+QrDaMwTeAY7wme4
xomc0wpXQb5enrjmFu8betlD0xfjgt7k6eW0njezRpWSk3wyHDd5w/6Vfn8pA6Fx
AQV4UuszXzQmG+W2pdIjLhnjmsjEeWMpmwgzn0rkcqujWHeh8XOSvQIjULFrFtFv
srSbum6vEfk=
=MP1H
-----END PGP SIGNATURE-----
Merge tag 'x86-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
Pull x86 fixes from Ingo Molnar:
- Reject the loading of a potentially problematic microcode version
on Intel Granite Rapids systems (Chang S. Bae)
- On FRED, reconstruct the proper #GP context for rejected INT
instructions, to fix a signal ABI regression (Matthew Schwartz)
- Add a test for this signal ABI regression the x86
self-test suite (Matthew Schwartz)
- Don't emit the new and not yet properly supported EGPR instructions
(%r16-%r31) on CONFIG_X86_NATIVE_CPU=y builds (Chang S. Bae)
* tag 'x86-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
x86/build/64: Prevent native builds from generating EGPR use
selftests/x86: Check signal state for rejected software interrupts
x86/fred: Reconstruct the #GP context for rejected INT instructions
x86/microcode/intel: Reject problematic loading on Granite Rapids systems
- Fix timer signal <-> exec() race, to prevent UAF (Thomas Gleixner)
- Clean up POSIX CPU timers right after de_thread(), to prevent UAF
(Hyunwoo Kim)
- Fix POSIX CPU timers race between expiry and timer_settime(),
to prevent UAF (Thomas Gleixner)
Signed-off-by: Ingo Molnar <mingo@kernel.org>
-----BEGIN PGP SIGNATURE-----
iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqvrMYRHG1pbmdvQGtl
cm5lbC5vcmcACgkQEnMQ0APhK1gqUQ/+NkruN984bFynF/eZ0/2DFv91AAUP8zgH
/S3PBlwuSbYFN9JVhngDMwxQkamE56weJbFc+0QuvVT5UVw/vX9BS4QOvvzN+f8D
FEN3UqD0d1B8OwlPNTw0sFPwJDdPctTinfKOhNjNQe6RLFsNARvGyaKDIDroWTfV
dxuJ/7Ecs+5m1bmGJnPEC+IH/OnV9BEEl1NdZb+INKpBlui9LCsw4rRIj/8dPK/H
UNhvXpykKrJCDftbCzAFSNryuzcJgq4kHtMbsqiUL6y50AB69eHGi/Y0xYBAEr1h
NiDPq2PAMmH1NCCMsTtqbJZMqgCr+7DSZiCFn7bZPwg0V5tV4PFZD484q0sCbiej
Fwg+arHd0icnceIcWMsBWPUVOSLxZaWdp9a2Tj3Ill06//b5bEDBJBbpecS+so3t
8W6IvdoCYm7sz50mohnjOdx7biHPu0yhwgj+EoAV3nZKoALQAAcI7+HJzSWpGnJi
HIO0zylRAZCjk9H3QNWO+LdWgifc8DysAZOWpmbuwGgp8q483IDRDtme/kMt3+D1
1qTHa1TD/tPo8UmmgyVJQ7e1hCxBkGuuBBu5Y3/qkUEOQM6B/H2Ji7stxsLpW3JL
HLzC3kL2SBBVBO2ljqiH5IhVAL10Qm5vPxaCOjExdBt1vjMxN1DowZqD4rT/tw58
ArpD4zmr8VQ=
=KhWJ
-----END PGP SIGNATURE-----
Merge tag 'timers-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
Pull timer race fixes from Ingo Molnar:
- Fix timer signal <-> exec() race, to prevent UAF (Thomas Gleixner)
- Clean up POSIX CPU timers right after de_thread(), to prevent UAF
(Hyunwoo Kim)
- Fix POSIX CPU timers race between expiry and timer_settime(),
to prevent UAF (Thomas Gleixner)
* tag 'timers-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list
exec: Cleanup POSIX timers right after de_thread()
signal: Prevent exec() race
present, but development headers (binutils-dev) are not
(Ulises Mendez Martinez)
Signed-off-by: Ingo Molnar <mingo@kernel.org>
-----BEGIN PGP SIGNATURE-----
iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqvqSARHG1pbmdvQGtl
cm5lbC5vcmcACgkQEnMQ0APhK1iBWQ/9HTpCn/GSapwpTLUAXh/d/7VWSTV/xMRS
b/cqx+jFDFeZDU55VbX+bMgKQyW0jNSUPjvVp0ZfjUf0W0LOXL/EnAemZ8VqBqAj
IMIyd+0MjCeUOCVanRiITre65BPuF+g3EbxWypFDiLmb4ziA5YksPknTWYrIVbDP
IMks30B8kJfzC5Qh0jjpSRDSypTvuEAKppbyf3pPmHfKLSbwtKOQzeoFUlLtWfs4
diBm9BVIjosmIr5dxMyixa8+5BTsPs4ojwa4US3H+RzxdXe+2v31Ac2nK/zvCRst
Fr8gefaLhVrnfkJeXU0Xn/rDMYOzayb1JW4jWjJ40I6U20ptdrMQ3aSJqjNrrwkQ
2vikInQX3NKV2ASiTppLDhsq7MFt4AeRYFwj8xmErm5uhoSEKAEPG1QZWS98QkAo
CXQL3PITL5kS0q5wGkkYXNi3TbpKvWy8kPoIRMHoKFUkBHJRssSg8tb17D5Jg0yd
QvsjocvMSf865swQ6p1yj+7+Zd+nGM2JGkIcp9OBPTAzZej4bXmpPwMKDeRv6pgD
GNgKJ2oEhvXWCgokxK9ezgk8rYsH/1Vo/+JyBf4/tcKL9ixfnBTgLNZ80J8VFDn2
5axUt4EO+FZKzLB6UaENhTo813PhGOM/rChKmJ1L4GWi0RywoX+seH4b+FtQk87f
VPvApwwiDHQ=
=vTNY
-----END PGP SIGNATURE-----
Merge tag 'objtool-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
Pull objtool fix from Ingo Molnar:
- Fix objtool build error on systems where libopcodes is
present, but development headers (binutils-dev) are not
(Ulises Mendez Martinez)
* tag 'objtool-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
objtool: Validate disassembler headers in libopcodes probe
as well, to avoid races with (private) futex waiters
(Peter Zijlstra)
Signed-off-by: Ingo Molnar <mingo@kernel.org>
-----BEGIN PGP SIGNATURE-----
iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqvp20RHG1pbmdvQGtl
cm5lbC5vcmcACgkQEnMQ0APhK1giDg//VpFKPXgma7fW5E+T0kjWHWD7FS1vYyJ4
nMunKME8PAV0A4S7946iUAWHjViVfksTmfvcXepSFCKZKLf55g8s2aZ1VoigMtYX
bQxNrnOidebSg9npLs9NV4sjvvNy+k03gcNN+OK+ZRfYCVRqbLgfCm5RJbaId5y4
+EuizVmtJuNav6HwAEIbU4LXGIdwSL9Pn8Zitkz/H7g0ZEkv+VA4h6NttvKDNfV7
OltcUFejtU7Z1lItfH+PP9pMcjPA6OPI2h7LLmUcZGUhhQQtW2Gb1fffz45PiH8T
FB7PdFt22TLG5c6hLB7zbrFFillWKn3l3Ihi/IxqVmMulhk6RVTPdCVJcj1cGZxF
9NXZ+L81poKwEETaIk52v5jm9qNF+kHbXJuCjPbmEdPxtxfv+Ma4zXom/xKkuXpx
qf01GXxelUPdCAl0cT0pzRvbEfHNIOsE2Id7f+59jB+L8ZbYEch04cIVRqCQcOgi
9B+lXj36fkFBV6wmuP5SWShWsgMsMpgSzOz5mUdWjY3Ocn9QuzDxPkk50Cm7uL1i
q/HpGv3T849HFnCH7+mi8wSiX33La+N297+AkGO7U7h5QFldPokvbAijwfmF+1Nw
CebsAfsgJsN1GZacDTH0jmRxh4I0Wa32yiCAldeGS2w9EMEAFbA87iwsOgjwHiQl
JOv/s06Pg7o=
=qQHe
-----END PGP SIGNATURE-----
Merge tag 'locking-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
Pull futex fix from Ingo Molnar:
- Also allocate a default private futex hash on vfork() as well, to
avoid races with (private) futex waiters (Peter Zijlstra)
* tag 'locking-urgent-2026-09-20' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
futex: Also allocate private hash on vfork()
A few driver specific fixes, none of them particularly severe or
unusual.
-----BEGIN PGP SIGNATURE-----
iQEzBAABCgAdFiEEreZoqmdXGLWf4p/qJNaLcl1Uh9AFAmqvmVMACgkQJNaLcl1U
h9AOdwf/aRa54oHd6iLCPXNAbZLDie0pnJa/Q/5sjpJoVY9ofKc2XM9djmy60YdF
/VGIphT8gr6at6fLZHEBbLanu2MQC2vxW9zDh5n+Xe8HUS3sdrwtBJPSv74Mcfrf
OIv6nFrVsbo1IMF7x4ncYOhOBGKyOSqhsVdt+k6jl1wuTDJBHyFs7sdL1DGRCRu/
ba4n2W+kSxVeFx3ACFyDJ8l8vLqtyotFKkpmslrPmT0yHFwOr8SOMbyQ5MPxITpx
gqgLikR3OW5alOLxy1U2nWCdjNsc8UWBhx1sCnByYrUO3VmRIEx4j1l2wSVX0J7E
Ck7/pSpg1NGkxVYSLCTBufqq8kgPTQ==
=iy0J
-----END PGP SIGNATURE-----
Merge tag 'spi-fix-v7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/spi
Pull spi fixes from Mark Brown:
"A few driver specific fixes, none of them particularly severe or
unusual"
* tag 'spi-fix-v7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/spi:
spi: fsl-qspi: Reprogram the clock rate when the operation frequency changes
spi: spi-zynqmp-gqspi: stop the controller on shutdown
spi: virtio: Use the per-transfer bits per word
spi: spi-qpic-snand: avoid writing QPIC_EBI2_ECC_BUF_CFG register
Fixes mainly for cleanup and error handling, a good part of them
around DMA resource management.
- at91: ensure DMA channels are released on all exit paths
- imx: fix autosuspend cleanup on remove
- qcom-cci: fix device node reference leak
- atr, imx, qcom-geni: set adapter slot to NULL on registration
failure
-----BEGIN PGP SIGNATURE-----
iHUEABYKAB0WIQScDfrjQa34uOld1VLaeAVmJtMtbgUCaq+VLAAKCRDaeAVmJtMt
bqmsAP9umA0ew1WQkQGTlTJLfbQdhwy8IDS7tMRAlgL7vsUxOQEApvFqr6Xtq2j7
HiSP35cHybZlA7P2T70A+MVniCJDRQ4=
=Sn1c
-----END PGP SIGNATURE-----
Merge tag 'i2c-fixes-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/andi.shyti/linux
Pull i2c fixes from Andi Shyti:
"Fixes mainly for cleanup and error handling, a good part of them
around DMA resource management:
- at91: ensure DMA channels are released on all exit paths
- imx: fix autosuspend cleanup on remove
- qcom-cci: fix device node reference leak
- atr, imx, qcom-geni: set adapter slot to NULL on registration
failure"
* tag 'i2c-fixes-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/andi.shyti/linux:
i2c: qcom-cci: fix device_node refcount leak in cci_probe()/cci_remove()
i2c: qcom-geni: release DMA channels on probe error
i2c: imx: release DMA channels on probe error
i2c: at91: release DMA channels on remove and probe error
i2c: atr: fix dangling adapter pointer on add failure
i2c: imx: disable autosuspend on remove
- Fixes for evdev and input compat handling to zero-initialize on-stack
absinfo and force-feedback effect structures before partial or compat
copies from userspace, preventing kernel stack memory disclosure
- Fixes for the Synaptics RMI4 driver to prevent an out-of-bounds read
when writing multi-chunk blocks over SMBus and to avoid a NULL pointer
dereference during suspend/resume when the RMI device is unbound
- Fixes for the soc_button_array driver to propagate -EPROBE_DEFER on
non-Bay Trail/Cherry Trail platforms (fixing broken power and volume
buttons on the Microsoft Surface Pro 11) and to validate the ACPI
package element count before dereferencing
- A fix for the adp5588-keys driver to cache the initial GPIO hardware
state before registering the gpiochip so pre-configured pin states are
not clobbered by GPIO hogs during registration
- A fix for the cyttsp5 touchscreen driver to clamp the device-supplied
HID report size before copying into the response buffer, preventing a
buffer overflow
- A fix for the HP SDC serio driver to use timer_shutdown_sync() on
module exit so the periodic kicker timer cannot rearm itself during
teardown
- A fix for the eeti_ts touchscreen driver to export its OF module alias
so the module autoloads on Device Tree platforms
- Updates to the xpad joystick driver adding support for the Victrix Pro
BFG controller and Azeron devices, and fixing the device type
classification for the PDP Marvel Xbox 360 controller
- Quirks for the i8042 and atkbd drivers to keep the built-in keyboards
functional on the Acer Aspire Go 15 AG15-42P and Xiaomi Redmi Book Pro
16 2026
- A quirk for the Synaptics PS/2 touchpad driver disabling SMBus
InterTouch on the Lenovo ThinkPad T440p (board ID 2722) so the
touchpad and TrackPoint respond immediately at boot
- Other minor updates and documentation fixes, including reading the
"ti,poll-period" property as u32 in tsc2007, adding the mt6572
compatible to the MediaTek keypad Device Tree binding, fixing an
attribute name typo in the trackpoint sysfs ABI documentation, and
documenting that no new LED codes should be added to the input
subsystem.
-----BEGIN PGP SIGNATURE-----
iHUEABYKAB0WIQST2eWILY88ieB2DOtAj56VGEWXnAUCaq9j+gAKCRBAj56VGEWX
nJ5KAQDnTOivIghgIGnlKTIYLSV4cJ0fWJh7J1/ubx9soK+9RwD/bDUdyryAaSTr
x95U7/fEvq/lXBFyK2LXyahuTC6vNQY=
=Vsfi
-----END PGP SIGNATURE-----
Merge tag 'input-for-v7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/dtor/input
Pull input fixes from Dmitry Torokhov:
- Fixes for evdev and input compat handling to zero-initialize on-stack
absinfo and force-feedback effect structures before partial or compat
copies from userspace, preventing kernel stack memory disclosure
- Fixes for the Synaptics RMI4 driver to prevent an out-of-bounds read
when writing multi-chunk blocks over SMBus and to avoid a NULL
pointer dereference during suspend/resume when the RMI device is
unbound
- Fixes for the soc_button_array driver to propagate -EPROBE_DEFER on
non-Bay Trail/Cherry Trail platforms (fixing broken power and volume
buttons on the Microsoft Surface Pro 11) and to validate the ACPI
package element count before dereferencing
- A fix for the adp5588-keys driver to cache the initial GPIO hardware
state before registering the gpiochip so pre-configured pin states
are not clobbered by GPIO hogs during registration
- A fix for the cyttsp5 touchscreen driver to clamp the device-supplied
HID report size before copying into the response buffer, preventing a
buffer overflow
- A fix for the HP SDC serio driver to use timer_shutdown_sync() on
module exit so the periodic kicker timer cannot rearm itself during
teardown
- A fix for the eeti_ts touchscreen driver to export its OF module
alias so the module autoloads on Device Tree platforms
- Updates to the xpad joystick driver adding support for the Victrix
Pro BFG controller and Azeron devices, and fixing the device type
classification for the PDP Marvel Xbox 360 controller
- Quirks for the i8042 and atkbd drivers to keep the built-in keyboards
functional on the Acer Aspire Go 15 AG15-42P and Xiaomi Redmi Book
Pro 16 2026
- A quirk for the Synaptics PS/2 touchpad driver disabling SMBus
InterTouch on the Lenovo ThinkPad T440p (board ID 2722) so the
touchpad and TrackPoint respond immediately at boot
- Other minor updates and documentation fixes, including reading the
"ti,poll-period" property as u32 in tsc2007, adding the mt6572
compatible to the MediaTek keypad Device Tree binding, fixing an
attribute name typo in the trackpoint sysfs ABI documentation, and
documenting that no new LED codes should be added to the input
subsystem
* tag 'input-for-v7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/dtor/input:
Input: hp_sdc - shut down kicker timer on module exit
Input: xpad - add support for Victrix Pro BFG Controller
Input: tsc2007 - read "ti,poll-period" as u32
Input: trackpoint - fix the inertia attribute name in the ABI document
Input: eeti_ts - publish the OF module alias
Input: xpad - add support for Azeron devices
Input: xpad - fix PDP Marvel Xbox 360 controller
Input: document that no new LED codes should be added
Input: soc_button_array - check btns_desc->package.count
Input: soc_button_array - fix MS Surface Pro 11 probe failure
Input: i8042 - add quirk for Acer Aspire Go 15 AG15-42P
Input: synaptics - disable InterTouch on ThinkPad T440p (board id 2722)
Input: cyttsp5 - clamp the HID report size before memcpy
Input: zero ff_effect before compat copy in input_ff_effect_from_user
Input: evdev - zero absinfo before partial copy in EVIOCSABS
Input: synaptics-rmi4 - fix GPF in suspend and resume when unbound
Input: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block()
Input: atkbd - skip deactivate for Xiaomi Redmi Book Pro 16 2026
dt-bindings: input: mediatek,mt6779-keypad: add mt6572
Input: adp5588-keys - cache GPIO state before registering the gpiochip
-----BEGIN PGP SIGNATURE-----
iQJIBAABCgAyFiEES0KozwfymdVUl37v6iDy2pc3iXMFAmqvPSwUHHBhdWxAcGF1
bC1tb29yZS5jb20ACgkQ6iDy2pc3iXP1rBAAkK6sP+lzXynr/abxWio9UCvlN6NF
jqMXtKeUeLNg/lJakXKhja/FGaK9w+Rm+zlXQQvVE7YAO5Db758JzCXMTHlK6etD
T5d+GVdZj/oVcAvfGhov0guNHZqcfKTGWOXKtGV8RQWYL+f6IC1IIHnz9wNeWIfY
emkfOTgAJpCkX9nXS5xTdQNUiPkUV80LFGqxXCMhxiumvyzqOhUteytfNh3UXXcs
ldOWRBstUumudBe/MJR09REtQve3emHc7bZUAxSKwXxzdOPTf7UEy4Y7QXCN3Opn
Dn6Dsrt6lnpIZyzUK/eOnZvQ639gDqTMW2XTmin0JIf2KGG/PhqnvOT07hOPl+X5
wqXh2wCFn+tXVi5t+S2myMUVZK56GwfRH9kMCo6ca1Ui36iYYEeoJYt7z5tsE6P5
YBdvKKJ/MPR1/uEwP/TB3UDK0o4OBjyujc6/Ka5iBoIHXKpx7MBLOo/Q0h/Wu2A0
7HYvG/4lYdWp3p5iR8cdZ+ZgdTQDWi6t5BD3JWOfWi1gHCeGgZCHTCZ9mdSoFS18
9GpXFXTR4yM5pfwxQEAu6jFH0esSB92HJBd/yS7sU8EIUQ+0XmOge+gVPifMrhWj
yOHCR7hlAYE5ds51w3ZVOYI0slkYImqCHEdlCz1DiKzyLmQQmfJvshOIvBCl7uwn
LRHu6Mo0cEBMAvc=
=kiQE
-----END PGP SIGNATURE-----
Merge tag 'selinux-pr-20260919' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux
Pull selinux fixes from Paul Moore:
- Ensure that the cached SELinux access decisions are correct
- Fix the SELinux overlayfs code to properly track the top-level/user
information on multiple stacked overlayfs filesystems
- Fix the SELinux overlayfs code to properly enforce mprotect() access
control policy on all of the different layers in multiple stacked
overlayfs filesystems
* tag 'selinux-pr-20260919' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux:
selinux: recheck intermediate backing files on mprotect()
selinux: preserve user SID across nested backing files
selinux: always fill AVC decision in avc_has_perm_noaudit()
The tracepoint documentation claims that denial and lifecycle events
expose every input needed to reproduce a verdict. Instead document how
denial, ruleset, and domain events identify the denying policy, checked
operation and object, and reason for denial. Direct consumers to generic
tracepoints for additional operational context.
State the reconstruction limits: IDs are boot-local, rule checks have no
request ID, and exported records may be lost or cross-CPU reordered.
Also replace the incorrect BPF_RAW_TRACEPOINT guidance with libbpf
SEC("tp_btf/...") attachment and refer consumers to the event prototypes
for callback argument layouts.
Cc: Günther Noack <gnoack@google.com>
Cc: Steven Rostedt <rostedt@goodmis.org>
Link: https://patch.msgid.link/20260918185036.608651-10-mic@digikod.net
Signed-off-by: Mickaël Salaün <mic@digikod.net>