Commit Graph

1468525 Commits

Author SHA1 Message Date
Benjamin Tissoires
b6f69097c8 selftests/hid: add unnumbered variant to the hid_bpf tests
A bug appeared in hid_bpf_dispatch.c where it wasn't properly handling
unnumbered reports. Add a device variant without report IDs so we can
also test them.

Signed-off-by: Benjamin Tissoires <bentiss@kernel.org>
2026-09-14 18:06:03 +02:00
Benjamin Tissoires
c4afa4862b HID: bpf: fix __hid_bpf_hw_check_params report length
Turns out that USB, I2C and other transport drivers (except uhid which
just passes the data) still need to have the report ID in the first
byte.

Because they expect the first byte to be the report ID or 0, when the
report ID is 0, they strip that first byte before forwarding to the
device. This means that the transport layer forwards a buffer of size
N-1 to the device, which gets rejected.

Fixes: 5599f80196 ("HID: bpf: export hid_hw_output_report as a BPF kfunc")
Signed-off-by: Benjamin Tissoires <bentiss@kernel.org>
2026-09-14 18:06:03 +02:00
Benjamin Tissoires
9d1e523b92 selftests/hid: add define for commonly used buf size
If we want to add another report descriptor without report IDs with a
report size bigger than 10, we have multiple magic values to replace.

Put a #define once and for all, so we don't have dangling ones.

Signed-off-by: Benjamin Tissoires <bentiss@kernel.org>
2026-09-14 18:06:03 +02:00
Slawomir Stepien
65bcc5f897 HID: amd_sfh: Validate PCI BAR size before mapping
The amd_sfh driver maps PCI BAR 2 using pcim_iomap_regions() and
subsequently accesses MMIO registers at offsets up to 0x10958 (e.g.,
AMD_P2C_MSG3 at 0x1068C). However, the driver never validates that the BAR
size is large enough to cover these accesses. If the driver is bound to a
device with a smaller BAR 2, this leads to an out-of-bounds memory access
and a page fault during the probe function.

For example, a page fault can occur when reading from privdata->mmio +
AMD_P2C_MSG3 in mp2_select_ops():

  BUG: unable to handle page fault for address: ffffc9000390368c
  PGD 100000067 P4D 100000067 PUD 1012c1067 PMD 105b64067 PTE 0
  Oops: Oops: 0000 [#1] SMP KASAN NOPTI
  RIP: 0010:readl arch/x86/include/asm/io.h:59 [inline]
  RIP: 0010:mp2_select_ops drivers/hid/amd-sfh-hid/amd_sfh_pcie.c:282
  [inline]
  RIP: 0010:amd_mp2_pci_probe+0x337/0x5f0
  drivers/hid/amd-sfh-hid/amd_sfh_pcie.c:487
  Call Trace:
   <TASK>
   local_pci_probe drivers/pci/pci-driver.c:332 [inline]
   pci_call_probe drivers/pci/pci-driver.c:394 [inline]
   __pci_device_probe drivers/pci/pci-driver.c:455 [inline]
   pci_device_probe+0x431/0xc90 drivers/pci/pci-driver.c:489

Fix this by verifying that the length of BAR 2 is at least 128KB before
attempting to map it. Since the maximum accessed offset is 0x10958, and PCI
BAR sizes are powers of 2, any legitimate hardware will have a BAR size of
at least 128KB.

Fixes: 4f567b9f81 ("SFH: PCIe driver to add support of AMD sensor fusion hub")
Assisted-by: Gemini:gemini-3.7-flash Gemini:gemini-3.1-pro-preview syzbot
Reported-by: syzbot+4eadd4dfe9e66522bae8@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=4eadd4dfe9e66522bae8
Link: https://syzkaller.appspot.com/ai_job?id=3bc1c45c-548f-4ab5-8243-d2c8ec321d6c
Signed-off-by: Slawomir Stepien <sst@poczta.fm>
Acked-by: Basavaraj Natikar <Basavaraj.Natikar@amd.com>
Link: https://syzkaller.appspot.com/bug?extid=4eadd4dfe9e66522bae8
Signed-off-by: Jiri Kosina <jkosina@suse.com>
2026-09-14 14:41:21 +02:00
Oscar Priego Verdugo
8e2a4b458a HID: elecom: fix bus type for M-XGL20DLBK
The M-XGL20DLBK is matched as a USB device by hid-elecom, but
its entry in hid_have_special_driver[] uses HID_BLUETOOTH_DEVICE.

This prevents the special-driver quirk entry from matching the USB
device handled by hid-elecom. Use HID_USB_DEVICE there as well.

Fixes: 55633e681a ("HID: elecom: add support for EX-G M-XGL20DLBK wireless mouse")
Signed-off-by: Oscar Priego Verdugo <oscar.priegov@gmail.com>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
2026-09-11 18:54:41 +02:00
Berke Durak
f3c2b266b8 HID: elecom: Add support for ELECOM M-XT4DRBK (018E)
The 2025 revision of the left-handed EX-G wireless trackball
(M-XT4DRBK-G) reports USB ID 056e:018e instead of 056e:00fd. Its report
descriptor declares an 8-bit button field (Report Count 8) but only five
usages (Usage Maximum 5), so the sixth (Fn) button ends up as a
duplicate of button 5 and is unusable.

The report descriptor has the same layout as the M-XT3DRBK 018C
(button usage maximum at offset 16, button report count at 22, button
report size at 24, padding report size at 30), so reuse that fixup.

Rename the existing M_XT4DRBK define to M_XT4DRBK_00FD to match the
convention used for the other EX-G revisions.

Tested on a Raspberry Pi 5 with the same fixup in an
out-of-tree module on 6.12 (6.12.96+rpt-rpi-2712);
all six buttons are reported after the fix, and they
work (tested with xev as well).

Report descriptor as sent by the device, pre-fix (056e:018e,
215 bytes):

 05 01 09 02 A1 01 09 01 A1 00 85 01 05 09 19 01
 29 05 15 00 25 01 95 08 75 01 81 02 95 01 75 00
 81 01 05 01 09 30 09 31 16 00 80 26 FF 7F 75 10
 95 02 81 06 C0 A1 00 05 01 09 38 15 81 25 7F 75
 08 95 01 81 06 C0 A1 00 05 0C 0A 38 02 95 01 75
 08 15 81 25 7F 81 06 C0 C0 06 01 FF 09 00 A1 01
 85 02 09 00 15 00 26 FF 00 75 08 95 07 81 02 C0
 05 0C 09 01 A1 01 85 05 15 00 26 3C 02 19 00 2A
 3C 02 75 10 95 01 81 00 C0 05 01 09 80 A1 01 85
 03 19 81 29 83 15 00 25 01 95 03 75 01 81 02 95
 01 75 05 81 01 C0 06 BC FF 09 88 A1 01 85 04 95
 01 75 08 15 00 26 FF 00 19 00 2A FF 00 81 00 C0
 06 02 FF 09 02 A1 01 85 06 09 02 15 00 26 FF 00
 75 08 95 07 B1 02 C0

Assisted-by: LLM
Signed-off-by: Berke Durak <berke.durak@gmail.com>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
2026-09-11 18:30:29 +02:00
Stuart Hayhurst
1d00442cc4 HID: corsair-void: Fix firmware event packet description
The size was incorrectly stated as 4 bytes since the ID was missed out.
Add the ID in and correct the indices for the firmware versions.

Signed-off-by: Stuart Hayhurst <stuart.a.hayhurst@gmail.com>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
2026-09-11 18:22:54 +02:00
Youth Cao
58d97b45f3 HID: i2c-hid: Add i2c-hid-quirk-bad-input-size quirk for 0911:5288 device
I have recently acquired a cheap Apollo Lake-based laptop that uses a
Hynitron CST128-A touchpad controller. While booting from a Debian LiveCD,
the kernel log is flooded with the following error (though the touchpad
works well):

  i2c_hid_acpi i2c-ALPS0001:00: i2c_hid_get_input: incomplete report (27/42405)

The CST128-A was identified via ACPI as ALPS0001:00, and the I2C HID
device ID (0911:5288) was shared with the Hantick 5288.

Add the I2C_HID_QUIRK_BAD_INPUT_SIZE quirk option to the existing Hantick
5288 quirk entry to suppress the kernel log flood.

Signed-off-by: Youth Cao <cocoh2os08@gmail.com>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
2026-09-11 18:04:19 +02:00
Tristan Madani
abd24922c2 HID: hid-oxp: use cancel_delayed_work_sync() in remove
oxp_hid_remove() uses cancel_delayed_work() for all three delayed work
items.  cancel_delayed_work() only dequeues a pending work item without
waiting for a currently executing callback to finish.  If any of the
work callbacks (oxp_rgb_queue_fn, oxp_btn_queue_fn, oxp_mcu_init_fn) is
running at the time of removal, the callback continues executing
concurrently with hid_hw_close() and hid_hw_stop(), accessing the HID
device after it has been closed and stopped.

Use cancel_delayed_work_sync() instead to ensure that any in-progress
work callback completes before device teardown proceeds.

Fixes: 84910c459d ("HID: hid-oxp: Add OneXPlayer configuration driver")
Cc: stable@vger.kernel.org
Signed-off-by: Tristan Madani <tristan@talencesecurity.com>
Reviewed-by: Derek J. Clark <derekjohn.clark@gmail.com>
Link: https://lore.kernel.org/r/20260804-oxp-fix-v2-1-b2d56e4c8a2c@cherr.cc
Link: https://lore.kernel.org/r/20260804-oxp-fix-v1-1-51a4fe787167@cherr.cc
Signed-off-by: Jiri Kosina <jkosina@suse.com>
2026-09-11 17:45:43 +02:00
Oleg Keri
39e8e08571 HID: i2c-hid: add reset quirk for Lenovo Yoga Slim 7x Gen 11 keyboard
The ITE controller behind the keyboard of the Lenovo Yoga Slim 7x Gen 11
(048d:83db) carries out a reset but never raises the interrupt that
acknowledges it. i2c_hid_finish_hwreset() therefore waits out its full
one second timeout and logs "device did not ack reset within 1000 ms" on
every probe and every resume, before the keyboard comes up regardless.

Set I2C_HID_QUIRK_NO_IRQ_AFTER_RESET for it, as is already done for
several other ITE parts, so the reset is followed by a fixed 100 ms sleep
instead.

Signed-off-by: Oleg Keri <okerixx@gmail.com>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
2026-09-11 17:41:39 +02:00
Dmitry Antipov
d76994443e HID: roccat: fix locking in roccat_connect() and roccat_disconnect()
Extend critical section in roccat_connect() to ensure that partially
initialized 'struct roccat_device' is never exposed in 'devices' list,
and do the same in roccat_disconnect() to avoid racy 'devices' access
against roccat_release().

Signed-off-by: Dmitry Antipov <dmantipov@yandex.ru>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
2026-09-11 17:31:37 +02:00
Erik Håkansson
7e749a7972 HID: steelseries: Add support for Arctis 7 (2018)
The headset reports connection and battery status on HID interface
5. When the device is disconnected, ignore incoming battery
reports as they will incorrectly report battery level 0.

Clamp overreported battery values to 100% and add USB ID 1038:12ad
to the driver's device tables.

Signed-off-by: Erik Håkansson <erikhakan@gmail.com>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
2026-09-11 17:22:38 +02:00
Andres Diaz
fce551616d HID: logitech-hidpp: Add support for G502 X Lightspeed USB mouse
The G502 X Lightspeed enumerates as 046d:c098 when connected with its
cable. Add the id so the driver handles the wired device.

Signed-off-by: Andres Diaz <andresd.diaz16@gmail.com>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
2026-09-11 17:16:49 +02:00
Julia Lawall
31fe2cb511 HID: fix semantic patch and improve its performance
Replace "expression" with "identifier" in the declaration of hdev.
This is necessary because hdev is used as the name of a function
parameter.

Move the two uses of @p2 to the relevant function names.

Convert <... ...>, meaning that the contained pattern is optional,
to use ..., when any, and exists.  This requires that the function
contain calls to hid_hw_start, etc, which reduces the set of files
that are considered for matching against this pattern.

Reported-by: Ricardo Ribalda <ribalda@chromium.org>
Signed-off-by: Julia Lawall <Julia.Lawall@inria.fr>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
2026-09-11 16:52:18 +02:00
Chen Changcheng
d3aba34427 HID: alps: fix use-after-free on input2 registration failure
alps_input_configured() stores data->input2 before calling
input_register_device().  If registration fails, input_free_device()
frees the input device but data->input2 still points to the freed memory.
alps_input_configured() calls hid_hw_open() before allocating input2, so
URBs are already active and raw_event can fire during the failure window.
A U1_SP_ABSOLUTE_REPORT_ID report arriving then causes u1_raw_event()
to dereference the freed data->input2 -> use-after-free.

Fix by only storing input2 into drvdata after successful registration
and adding a NULL guard in the raw_event path.

Fixes: 2562756dde ("HID: add Alps I2C HID Touchpad-Stick support")
Cc: stable@vger.kernel.org
Signed-off-by: Chen Changcheng <chenchangcheng@kylinos.cn>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
2026-09-11 16:19:06 +02:00
Chen Changcheng
aa9dde93e0 HID: alps: unregister DualPoint Stick input device on remove
alps_input_configured() allocates a second input device ("DualPoint
Stick") with input_allocate_device() and registers it, but the
alps_driver struct has no .remove handler and input2 is not tracked in
hdev->inputs.  The default remove path (hid_hw_stop -> hidinput_disconnect)
only iterates hdev->inputs, so input2 is never unregistered and leaks
on every device removal.

Add a .remove handler that stops the device first (preventing URB
callbacks from touching input2 during teardown) and then unregisters
input2.

Fixes: 2562756dde ("HID: add Alps I2C HID Touchpad-Stick support")
Cc: stable@vger.kernel.org
Signed-off-by: Chen Changcheng <chenchangcheng@kylinos.cn>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
2026-09-11 16:19:06 +02:00
René Onier
a1a5ad37e5 HID: winwing: fix use-after-free in force feedback teardown
winwing_init_ff() passes the driver's private data, allocated with
devm_kzalloc() in winwing_probe(), as the effect context to
input_ff_create_memless(). The memoryless force-feedback core takes
ownership of that pointer and frees it with kfree() from
input_ff_destroy() (ml_ff_destroy()) when the input device is
destroyed.

Freeing a devm-managed allocation with kfree() is an invalid free, and
the same object is then released again by devres when the HID device is
torn down, a double free. As the allocation also embeds the LED class
devices, their timers and work item live on freed memory and the slab
gets corrupted. This triggers on unbind, rmmod, hot-unplug and on system
suspend, where the firmware cache walks the now-corrupt devres list.
KASAN reports:

  BUG: KASAN: invalid-free in input_ff_destroy
  Allocated by task N:
    winwing_probe

Pass NULL as the memless context instead and fetch the driver data from
the input device in winwing_play_effect(): the HID core already stores
the hid_device as the input device's drvdata. The force-feedback core
then owns nothing that it must not free.

Fixes: 42d020b54e ("HID: winwing: Enable rumble effects")
Signed-off-by: René Onier <f3nr1l@me.com>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
2026-09-11 16:15:42 +02:00
Lovekesh Solanki
aaaea79efb HID: multitouch: Add report ID mismatch quirk for ASUS ROG Z13 Folio
Commit e716edafed ("HID: multitouch: Check to ensure report
responses match the request") introduced validating GET_FEATURE
responses return the requested report ID.

ASUS ROG Z13 Flow (2025) GZ302EA touchpad (USB 0b05:1a30) returns
a different report ID for Win8 feature request. Before this check,
the response was still processed and allowed device to switch into
its full Touchpad Precision mode.

After the validation, the response is discarded before
hid_report_raw_event() processes it and device remains in fallback
mode and no longer exposes ABS_MT_SLOT, ABS_MT_TOOL_TYPE or the
multi-finger BTN_TOOL_* capabilities for palm rejection.

Add a device quirk to allow the known firmware behavior for
this device while preserving report ID validation for all other
devices.

The device previously matched the generic MT_CLS_WIN_8 entry, so
base the new class on MT_CLS_WIN_8 to keep it on the same quirk set
as before the regression.  MT_QUIRK_CONFIDENCE must be set
explicitly: it is normally enabled by the class name check in
mt_touch_input_mapping(), which only matches the MT_CLS_WIN_8*
names, and it is what makes ABS_MT_TOOL_TYPE available for
touchpads.

Fixes: e716edafed ("HID: multitouch: Check to ensure report responses match the request")

Signed-off-by: Lovekesh Solanki <lovekeshsolanki00@gmail.com>
Reported-by: mayhemandcoffee <mayhemandcoffee@gmail.com>
Closes: https://bugzilla.kernel.org/show_bug.cgi?id=221774
Tested-by: mayhemandcoffee <mayhemandcoffee@gmail.com>
Link: https://bugzilla.kernel.org/show_bug.cgi?id=221774
Signed-off-by: Jiri Kosina <jkosina@suse.com>
2026-09-11 16:14:19 +02:00
Wei Jie LAW
9aa237cf66 HID: wacom: fix OOB read in wacom_wac_pen_serial_enforce()
The 'wacom_wac_pen_serial_enforce()' function may calculate and pass an
invalid offset to hid_field_extract(), resulting in memory reads at
incorrect addresses -- possibly beyond the end of the report.  If a
field in the HID descriptor lists more usages than its Report Count
actually reserves space for, the function's inner 'j' will walk past
the end of the field:

	for (i = 0; i < report->maxfield; i++) {
		for (j = 0; j < report->field[i]->maxusage; j++) {
			...
			value = hid_field_extract(hdev, raw_data + 1,
						  offset + j * size, size);

A descriptor listing 12288 usages against Report Count 1 has the loop
extract the usage at index 12287 from bit offset 98296 -- about 12 KB
past a 2-byte received report.  The value is stored in
wacom_wac->serial[0] and can reach userspace as an MSC_SERIAL event,
making this an information disclosure.

Clamp the loop to field->report_count, the number of value slots the
report holds.  Value slots past the last declared usage are still
scanned; they reuse that usage (HID 1.11, 6.2.2.8).

Verified on v6.12.105 with a UHID reproducer: a 2-byte report from
such a descriptor trips KASAN before the patch and not after it.

Fixes: 8341720642 ("HID: wacom: Queue events with missing type/serial data for later processing")
Suggested-by: Jason Gerecke <killertofu@gmail.com>
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-5
Assisted-by: GLM:glm-5.3
Signed-off-by: Wei Jie Law <98lawweijie@gmail.com>
Reviewed-by: Jason Gerecke <jason.gerecke@wacom.com>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
2026-09-11 15:44:01 +02:00
Junjie Cao
cdb669a3b8 HID: quirks: add ALWAYS_POLL quirk for SDINNOVATION gaming keyboard
The SDINNOVATION gaming keyboard (USB ID 36ae:feab) stops reporting
input events after its RGB lighting mode is switched about twice.
Disabling USB autosuspend and unbinding the other HID interfaces make
no difference; the issue does not occur on Windows.

HID_QUIRK_ALWAYS_POLL alone resolves it, verified on 7.1.8 via
usbhid.quirks=0x36ae:0xfeab:0x400.

Reported-by: Marco Carvalho <marcocarvalho.web@gmail.com>
Link: https://bugzilla.redhat.com/show_bug.cgi?id=2514627
Cc: stable@vger.kernel.org
Signed-off-by: Junjie Cao <junjie.cao@intel.com>
Signed-off-by: Benjamin Tissoires <bentiss@kernel.org>
2026-09-07 15:26:56 +02:00
Shen Yongchao
9cdc7e6dc7 HID: bpf: serialize device reference release in struct_ops destroy path
__hid_bpf_ops_destroy_device() and hid_bpf_unreg() can race on the
same registration reference, double-putting struct hid_device and
freeing it while hid_destroy_device() still uses it.  Serialize the
remove/NULL decision under hdev->bpf.prog_list_lock so exactly one
path releases each registration reference: unreg re-checks ops->hdev
under the lock and returns without putting when the destroy path
already cleared it; all put_device() calls happen after the lock is
dropped, which is safe because a concurrent unreg then observes
ops->hdev == NULL under the lock.

Background: each successful attach (hid_bpf_ops_reg) acquires one
device reference (hid_get_device()).  Two paths can release it:

- device destruction: hid_destroy_device() -> hid_bpf_destroy_device()
  -> __hid_bpf_ops_destroy_device(), which walks hdev->bpf.prog_list
  under rcu_read_lock() and drops one reference per attached program;
- BPF link release: bpf map delete (no BPF_F_LINK) synchronously calls
  st_ops->unreg() -> hid_bpf_unreg(), which drops the reference for
  its own registration.

The coordination handshake (e->hdev = NULL on the destroy side vs
"if (!hdev) return" on the unreg side) is a TOCTOU check: the two
paths run under different lock domains (rcu_read_lock vs
prog_list_lock), so a concurrent unreg can read ops->hdev as
non-NULL, block on prog_list_lock, and then proceed while the
destroy traversal executes - both paths then drop the same
reference.  The refcount reaches zero legitimately (each decrement
is individually valid), so no refcount_t saturation fires: the
device is simply freed while the transport is still inside
hid_destroy_device(), and subsequent teardown touches freed memory.

The fix serializes the remove/NULL decision under prog_list_lock on
both sides and moves the destroy-side puts outside the lock.  With
the lock held, plain reads/writes of ops->hdev are sufficient; no
READ_ONCE/WRITE_ONCE are added, keeping the patch minimal.

Unlocked-read safety: the unlocked read of ops->hdev at the top of
hid_bpf_unreg() cannot touch a freed device, because the unreg path
itself still holds this registration's reference (released only by
its own hid_put_device() after the lock is dropped), and a destroy
traversal that already cleared ops->hdev makes the lock-internal
re-check return early without any put.  At most one of the two
paths releases each registration reference.

Fixes: ebc0d8093e ("HID: bpf: implement HID-BPF through bpf_struct_ops")
Cc: stable@vger.kernel.org
Signed-off-by: Shen Yongchao <grayhat@foxmail.com>
Assisted-by: Hermes:kimi-k3
Signed-off-by: Benjamin Tissoires <bentiss@kernel.org>
2026-09-01 18:49:26 +02:00
Wei Jie Law
4956993bb3 HID: rmi: fix OOB access with undersized RMI reports
The hid-rmi driver sizes its writeReport/readReport buffer purely from
the report descriptor supplied by the device, with no minimum bound:

	data->input_report_size  = hid_report_len(input_report);
	data->output_report_size = hid_report_len(output_report);
	alloc_size = data->output_report_size + data->input_report_size;
	data->writeReport = devm_kzalloc(&hdev->dev, alloc_size, GFP_KERNEL);
	data->readReport = data->writeReport + data->output_report_size;

but then reads and writes fixed offsets into it.  A device declaring a
1-byte output and a 1-byte input report makes hid_report_len() return 2
for each, so alloc_size is 4, while rmi_set_page() -- reached
unconditionally at probe time through rmi_input_configured() -- stores
writeReport[4] and rmi_hid_read_block() stores writeReport[0..5].  Since
readReport lives at writeReport + output_report_size, those stores also
corrupt the window the next reply is parsed out of.

The read path is worse: the copy length comes from readReport[1], which
the device fills in and can be up to 255, and the copy starts at
&readReport[2] with no regard for input_report_size, so it runs past the
end of the allocation into adjacent slab objects.  This does not even
need a lying device -- rmi_f01_probe() issues a fixed 21-byte register
read, so any device declaring an input report smaller than 23 bytes
reads out of bounds even when it answers truthfully.  Those bytes become
the register values the RMI core acts on: rmi_f01_probe() prints them to
the kernel log as the product id and exports them through the mode 0444
sysfs attribute of the same name, and rmi_driver_set_irq_bits() sends
them back to the device as the interrupt mask, so an undersized report
descriptor leaks heap contents both to unprivileged userspace and to the
device itself.

The write path has no bound either: rmi_hid_write_block() copies an
unbounded len to &writeReport[4], and the largest caller a device can
drive at probe time is rmi_driver_set_irq_bits(), whose length is
derived from the interrupt source counts the device declares in its Page
Description Table.

Finally, the read loop cannot terminate on a zero-length reply: such a
reply copies nothing and advances neither bytes_read nor bytes_needed,
and because a reply did arrive the one second wait_event_timeout() does
not fire either, so a device answering 0 forever keeps the loop running
inside the probe worker with page_mutex held.  khungtaskd does not
notice, because every reply wakes the task.

Reject reports too small for what the driver builds -- 6 output bytes
for the write reports and 3 input bytes for the read handshake -- at
probe time, clamp the write and the read copy to the report sizes the
device declared, and treat a zero-length reply as an error.  A device
refused this way is started as an ordinary HID device, like one that
does not carry the RMI report ids at all.

RMI_DEVICE must not be left set in device_flags on that path, because
rmi_input_configured() would then run the RMI setup and reach
rmi_set_page(), which writes the writeReport buffer the refusal just
skipped allocating.  The bit can arrive set: rmi_probe() copies
id->driver_data into device_flags before the report checks, and a bind
through the new_id sysfs attribute can supply driver_data with
RMI_DEVICE (BIT(0)) set.  Strip the bit where driver_data is copied, so
RMI_DEVICE keeps meaning exactly "this probe validated the reports"; the
three jumps to start that predate this patch are covered as well.

The error path also clears RMI_READ_DATA_PENDING on its way out, because
that flag is what the wait at the top of the loop tests: leaving it set
would make every later wait_event_timeout() return immediately on the
stale reply and kill the read path for the rest of the device's life.

Clamping does not regress working hardware: the read loop already
handles a reply carrying fewer bytes than requested, and a write longer
than the output report was overrunning the buffer already.

Verified on v6.12.69 and on v6.12.105 built with CONFIG_KASAN=y and
booted kasan_multi_shot, whose hid-rmi.c is identical to mainline here.
An emulated RMI4 device driven over /dev/uhid, and the same device again
over dummy_hcd plus raw-gadget, give identical results:

  BUG: KASAN: slab-out-of-bounds in rmi_hid_read_block+0x409/0x750 [hid_rmi]
  Read of size 21 at addr ffff88800bf33bba by task kworker/0:3/285
   __asan_memcpy+0x23/0x60
   rmi_hid_read_block+0x409/0x750 [hid_rmi]
   rmi_f01_probe+0x5dd/0x1dc0 [rmi_core]

  BUG: KASAN: slab-out-of-bounds in rmi_hid_write_block+0x1a9/0x350 [hid_rmi]
  Write of size 35 at addr ffff88810a2b24ac by task kworker/1:10/666
   __asan_memcpy+0x3c/0x60
   rmi_hid_write_block+0x1a9/0x350 [hid_rmi]
   rmi_driver_set_irq_bits+0x1f6/0x4d0 [rmi_core]
   rmi_driver_probe+0x636/0xbf0 [rmi_core]
   rmi_input_configured+0x184/0x2e0 [hid_rmi]
   rmi_probe+0x952/0xcf0 [hid_rmi]

and, for the zero-length reply, a probe worker left in D state in
rmi_hid_read_block() after 225 replies at 200 ms intervals.

After this change the undersized descriptor is refused at probe with
"rmi reports too small (out=2 in=2)", the oversized read and write are
both rejected, the zero-length reply fails the read with -EIO while
later reads on the same device keep working, and a device declaring
reports large enough for a 21-byte register read still probes normally
and reports its real product id.  A device bound through new_id with
RMI_DEVICE in its driver_data no longer reaches rmi_set_page() with an
unallocated writeReport either.

Link: https://lore.kernel.org/linux-input/20260822121007.153988-1-98lawweijie@gmail.com/
Link: https://lore.kernel.org/linux-input/00a489f38b240624dcb5a4bae36a53fcba9cfb47.1787549195.git.98lawweijie@gmail.com/
Link: https://lore.kernel.org/linux-input/20260824122708.76168-1-98lawweijie@gmail.com/
Link: https://lore.kernel.org/linux-input/20260825060954.104890-1-98lawweijie@gmail.com/
Fixes: 9fb6bf02e3 ("HID: rmi: introduce RMI driver for Synaptics touchpads")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-5
Assisted-by: GLM:glm-5.3
Signed-off-by: Wei Jie Law <98lawweijie@gmail.com>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
2026-09-01 17:06:17 +02:00
Benjamin Tissoires
ce58f5a184 selftests/hid: prepare test_rdesc_fixup_get_data_overflow for the new verifier
The new verifier in the bpf-next branch is now capable of detecting the
overflow that was triggered by test_rdesc_fixup_get_data_overflow.
This is better in terms of UI, but now the test is failing and should be
marked as expected to fail.

Add a new parameter to load_programs() when we expect the test to fail,
and dynamically validate the test by checkcing if it loads (it should
fail to load with new verifier), but if it still loads, HID-BPF should
detect the overflow itself and return an error in hid_bpf_get_data().

Signed-off-by: Benjamin Tissoires <bentiss@kernel.org>
2026-09-01 16:08:28 +02:00
Benjamin Tissoires
1fb68c2e76 selftests/hid: Add a test to ensure we can write fields in hid_device
hid_device->{name,uniq,phys} are all writeable fields, we need to have
tests for them in case the verifier becomes too much strict.

Signed-off-by: Benjamin Tissoires <bentiss@kernel.org>
2026-09-01 16:08:28 +02:00
Benjamin Tissoires
67bfe48a29 HID: bpf: mark struct hid_device as safe BPF pointer
Commit ee9ad135b2 ("bpf: Reject a store through a fault prone
pointer") in the BPF tree makes the verifier reject any writes to
hid_device->{name,uniq,phys}. A simple solution is to mark the struct
hid_device as safe from a BPF point of view.

Suggested-by: Daniel Borkmann <daniel@iogearbox.net>
Signed-off-by: Benjamin Tissoires <bentiss@kernel.org>
2026-09-01 16:08:28 +02:00
Ibrahim Hashimov
a8e04f3f89 HID: wacom: validate report length in wacom_intuos_pro2_bt_irq
wacom_intuos_pro2_bt_irq() receives the wire report length in `len`
but never consults it before parsing. After the report-id gate it
unconditionally calls wacom_intuos_pro2_bt_pen() and then, selected by
features.type, a fixed chain of sub-parsers, none of which receive
`len`:

	wacom_intuos_pro2_bt_pen(wacom);
	if (type == INTUOSP2_BT || type == INTUOSP2S_BT) {
		wacom_intuos_pro2_bt_touch(wacom);
		wacom_intuos_pro2_bt_pad(wacom);
		wacom_intuos_pro2_bt_battery(wacom);
	} else {
		wacom_intuos_gen3_bt_pad(wacom);
		wacom_intuos_gen3_bt_battery(wacom);
	}

Each sub-parser dereferences wacom->data at fixed offsets. The furthest
byte touched on each branch is:

  INTUOSP2_BT / INTUOSP2S_BT: wacom_intuos_pro2_bt_pad() reads data[285]
	(the touchring byte), so the report must be at least 286 bytes;
  INTUOSHT3_BT ("gen3"): wacom_intuos_gen3_bt_battery() reads data[45],
	so the report must be at least 46 bytes.

features.type is selected from the VID/PID id_table entry and
wacom_setup_device_quirks() force-registers the pen/pad/touch inputs
for that type independent of the report descriptor, so a malicious or
malfunctioning paired/spoofed Bluetooth peripheral can advertise that
VID/PID and send an undersized report that still satisfies the
data[0] == 0x80/0x81 gate. The driver then reads past the received
report and forwards the bytes to userspace via evdev (MSC_SERIAL /
ABS_MISC / ABS_WHEEL on the pen and pad input nodes), an out-of-bounds
read with a concrete userspace read-back channel, and a true
out-of-bounds read on transports whose backing buffer is sized to the
(small) report descriptor rather than a fixed-size staging buffer.

This is the same class of bug commit 2f1763f629 ("HID: wacom: fix
out-of-bounds read in wacom_intuos_bt_irq") already hardened in the
sibling wacom_intuos_bt_irq(), which guards each report id against its
minimum length before parsing.

Guard wacom_intuos_pro2_bt_irq() the same way: before parsing, reject
reports shorter than the furthest offset the selected branch actually
dereferences, warn, and bail out. Because the whole pen/touch/pad/
battery chain runs unconditionally per branch, a single up-front check
against the maximum offset (286 bytes for INTUOSP2_BT/INTUOSP2S_BT,
46 bytes for the gen3 branch) bounds every sub-parser. Returning 0 on
a short report also skips those calls for the same malformed report,
which is the safe, conservative behavior.

Fixes: 4922cd26f0 ("HID: wacom: Support 2nd-gen Intuos Pro's Bluetooth classic interface")
Cc: stable@vger.kernel.org
Signed-off-by: Ibrahim Hashimov <security@auditcode.ai>
Assisted-by: AuditCode-AI:2026.07
Acked-by: Jason Gerecke <jason.gerecke@wacom.com>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
2026-08-25 14:09:34 +02:00
Dave Carey
e8e60b6439 HID: multitouch: Fix stale MT slots when contact count drops to zero
The INGENIC 17EF:6161 touchscreen (Lenovo Yoga Book 9 14IAH10) reports
HID_DG_CONTACTCOUNT=0 in the frame immediately following the last finger
lift rather than omitting the frame entirely.  In mt_touch_report() the
existing code only updates num_expected when contact_count is non-zero,
so a zero contact count on the first packet of a new frame leaves
num_expected at its previous value (e.g. 2 for a two-finger gesture).
The sync check "num_received >= num_expected" then evaluates "0 >= 2"
and never fires, preventing INPUT_MT_DROP_UNUSED from releasing the
stale slots.  Those slots remain active in the kernel MT layer until the
next touch, at which point they are released in a batch alongside the
new contact — causing the userspace event consumer to miss the
intervening finger-up sequence and corrupt its gesture session state.

Fix by resetting num_expected to 0 when contact_count is zero and
num_received is still 0 (i.e., this is the first and only packet of the
frame, not a continuation packet in a multi-packet sequence).  With
num_expected=0 the sync check "0 >= 0" fires immediately, calling
input_mt_sync_frame() which drops the stale slots via
INPUT_MT_DROP_UNUSED.

The num_received==0 guard is critical: continuation packets in a
multi-packet frame arrive after at least one contact has already been
processed (num_received>0), so they are correctly excluded from this
path and the existing multi-packet logic is unaffected.

Signed-off-by: Dave Carey <carvsdriver@gmail.com>
Tested-by: Dave Carey <carvsdriver@gmail.com>
Signed-off-by: Benjamin Tissoires <bentiss@kernel.org>
2026-08-25 11:33:02 +02:00
Vadim Klishko
1c942462c3 HID: i2c-hid: Add a quirk for a Cirque I2C device.
Cirque touchpads with PID D0C1 generate an error when probed
by the I2C HID driver, resulting in no hidraw device created.
Adding I2C_HID_QUIRK_NO_IRQ_AFTER_RESET fixes the issue.

Signed-off-by: Vadim Klishko <vadim@cirque.com>
Signed-off-by: Benjamin Tissoires <bentiss@kernel.org>
2026-08-25 10:49:04 +02:00
Jiri Kosina
d0ad81b2b5 HID: hyperv: make pointer arithmetics understandable for FORTIFY_SOURCE
Commit 83df7b5fa6 ("HID: hyperv: add KUnit coverage for device info
bounds") introduced this piece of code

	report = ((u8 *)&info->hid_descriptor) + info->hid_descriptor.bLength;
	memset(report, 0x42, 4);

to populate the report, making use of the fact that the report
&info->hid_descriptor points to a struct hid_descriptor (which is a fixed-size
struct).

GCC's FORTIFY_SOURCE infer the object size from that specific struct field
rather than the outer dynamically allocated info buffer. As a result, writing
past sizeof(struct hid_descriptor) triggers the __write_overflow_field warning.

Calculate the pointer offset using info directly, so the compiler evaluates the
memory bounds against the allocated flexible layout of struct
synthhid_device_info instead of the nested struct.

Fixes: 83df7b5fa6 ("HID: hyperv: add KUnit coverage for device info bounds")
Reported-by: Jürgen Groß <jgross@suse.com>
Tested-by: Jürgen Groß <jgross@suse.com>
Acked-by: Benjamin Tissoires <bentiss@kernel.org>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
2026-08-21 15:59:01 +02:00
Jiri Kosina
445fcd33c5 HID: hyperv: fix build breakage with certain configs
If CONFIG_HID_HYPERV is built-in (=y) while CONFIG_KUNIT is built as a module
(=m), the linker fails to resolve kunit_mem_assert_format when creating
vmlinux.

Fix the dependencies in Kconfig.

Reported-by: kernel test robot <lkp@intel.com>
Closes: https://lore.kernel.org/oe-kbuild-all/202608190536.d9qCkWWc-lkp@intel.com/
Fixes: 83df7b5fa6 ("HID: hyperv: add KUnit coverage for device info bounds")
Acked-by: Benjamin Tissoires <bentiss@kernel.org>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
2026-08-21 15:31:51 +02:00
Linus Torvalds
a93f3bf4e1 hid-for-linus-2026081901
-----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCAAdFiEEL65usyKPHcrRDEicpmLzj2vtYEkFAmqFXCEACgkQpmLzj2vt
 YEkTbw//QD2eA9n18g/iDkUk6SAZ6h3YZxhOTQIlHe4sv6auuW64epL/Nz0XKnD7
 5odcrnukMIGXRtUmcu0bO8FP85+bvsPUERz82IWtKSaP1vdYtkTNxeBin6HlAHOR
 A0TfOOMJjfWuVGUVZ1G3AbBq3GGR80Q8c8YyhPnAnTzdh0cjw6+++1iP4NiGfalX
 yAgHmQh++Fo/Ar4c2QyvyEdSqMiAeocVU3qqeNUm7tRImtcsbmFa4cBOMupLSiKR
 YMkQD8A2QqS3M3b9BbXo4HdtB8JLiskkClm8ytUadIsUYSUaRah7aj8C3RaDSc4C
 mHCLZWjNGKEW+My1Q+lNjELRGLWKPkjw0tv+ZK3Ci0rsCTo7/lnopyufBe9XCptQ
 acLvnaCt2RYNRNFPPFhnIBOAuYrIwnWFnhYnNlyGVl9mcgeZfiiRjtk1Lp80YgTo
 WCD7i6/zIm2OobrIpRoEbk3ffNXkZ6wcMkp42p0oNLnI191Gspt6SOmLCnQ2GqHd
 efJAIFPPfbdWbydZW8qPBdRG/lzlaPHoyOL94fTIwqvpznX/Mp5FPQE9RD8APU2Z
 iAhrD6Jxk+5Z27BHCcVUU2jrdeBUGisD6zNdJ+st9Xdp6qLYbU8pl3NLdhCwc6NA
 Avt0IwhrboQZSGu8nZkFcYMc/pGe4I8dcf3+MRqIIjWwXLvUHUY=
 =7+OR
 -----END PGP SIGNATURE-----

Merge tag 'hid-for-linus-2026081901' of git://git.kernel.org/pub/scm/linux/kernel/git/hid/hid

Pull HID updates from Jiri Kosina:
 "Core:
   - fix long-standing force-feedback initialization race across the
     subsystem (Dmitry Torokhov)
   - switch to system_dfl_wq (Marco Crivellari)

  AMD-SFH:
   - support for tablet-mode switch for AMD SFH-based systems (Basavaraj
     Natikar)

  HyperX:
   - support for HyperX QuadCast 2 (Benjamin Blume)

  I2C-HID:
   - support for devices that provide HID descriptor solely through
     the ACPI _DSM method (XIE Zhibang)

  Intel-THC-HID:
   - support for full I2C bus config parameters (Even Xu)

  Logitech:
   - HID++ 2.0 repogrammable button support (Elliot Douglas)
   - Bolt receiver support for HID++ devices (Erik Håkansson)

  MSI:
   - support for MSI Claw (Derek J. Clark)

  Steam:
   - initial support for 2026 Steam Controller (Vicki Pfau)
   - support for sensor events on the 2025 Steam Controller (Vicki Pfau)

  And many, many other fixes for various long standing issues that were
  found by new modern tools, and quite a few device ID additions"

* tag 'hid-for-linus-2026081901' of git://git.kernel.org/pub/scm/linux/kernel/git/hid/hid: (146 commits)
  HID: tmff: Use 64-bit arithmetic for force feedback scaling
  HID: multitouch: reclassify HTIX5288 to WIN_8_FORCE_MULTI_INPUT_NSMU
  HID: sensor: custom: Fix field sysfs group cleanup on failure
  HID: sensor: custom: Fix use-after-free in enable_sensor
  HID: intel-thc-hid: intel-quickspi: bound GET_REPORT response to the caller buffer
  HID: haptic: don't write an uninitialized value to unhandled usages
  HID: intel-thc-hid: intel-quickspi: fix autosuspend cleanup during teardown
  HID: intel-thc-hid: intel-quicki2c: fix autosuspend cleanup during teardown
  HID: steam: Zero out inputs when disabling gamepad mode
  HID: steam: Clean up locking
  HID: steam: Don't set feature reports when disconnecting
  HID: steam: Fix wording of connect/disconnect logs
  HID: steam: Initial 2026 Steam Controller support
  HID: steam: Refactor registration
  HID: logitech: add Bolt receiver support for Logitech HID++ devices
  HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature
  HID: universal-pidff: stop the device when force-feedback init fails
  HID: haptic: move FF initialization into .input_configured()
  HID: logitech-hidpp: move FF initialization to .input_configured()
  HID: megaworld: move FF initialization to .input_configured()
  ...
2026-08-19 10:00:31 -07:00
Linus Torvalds
7acf90feab hwmon updates for v7.3
* New drivers
 
   - Driver for Kandou KB9002 retimer
 
   - Driver for the temp/voltage sensor on PolarFire SoC
 
   - Driver for Eswin EIC7700 PVT sensor
 
   - PMBus:
 
     - Driver for Analog Devices MAX16545/MAX16550 and Volterra VT7505
 
     - Drivers for Monolithic MPQ82D00 and MPQ8646
 
     - Driver for Silergy SQ24860
 
 * Added support to existing drivers
 
   - asus-ec-sensors: Support for ROG STRIX Z390-E GAMING,
     ProArt Z690-CREATOR WIFI, ROG STRIX X870E-E GAMING WIFI7 R2,
     ROG CROSSHAIR X870E HERO, and ROG Maximus Z790 Hero
 
   - asus_rog_ryujin: Siupport for ROG Ryujin III
 
   - ina2xx: Support for INA232
 
   - k10temp: Per-CCD temperature monitoring for Zen5 Turin
 
   - nct6775: List NCT5585D as supported chip
 
   - nzxt-kraken3: Support for NZXT Kraken 2024 Elite
 
   - sht3x: Support for GXCAS GXHT30
 
   - tmp102: Add device IDs for TMP110 and TMP113
 
   - yogafan: Support for LOQ 15IAX9, XiaoXin Pro 13ARE 2020,
     IdeaPad 3 15ALC6, Legion Pro 7 16AFR10H, Yoga Pro 7 14IAH10,
     Yoga 7 16ARP8, and Lenovo LOQ 15IAX9
 
   - PMBus:
 
     - max20830: Support for max20830c and max20840c
 
     - max34440: Support for MAX34452, and support for newer version
       of max34451
 
     - adm1275: Support for ROHM BD12780 and BD12790
 
 * Other notable changes
 
   - Constify various device attributes
 
   - Remove redundant dev_err() and dev_err_probe() from various drivers
 
   - applesmc: Convert to hwmon_device_register_with_info
 
   - adt7470: Add thermal zone sensor support
 
   - coretemp: Fix core_data leak on CPUs without PTS
 
   - emc1403: Drop hysteresis for low limit temperature
 
   - max6621: Fix various over- and underflow problems
 
   - PMBus:
 
     - Introduce pmbus_read_smbus_i2c_block_data() and use it in
       various drivers
 
     - Export and use pmbus_check_and_notify_faults()
 
     - Let PMBus drivers report the supported PMBus revision
 
 * Various other minor fixes and improvements
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCAAdFiEEiHPvMQj9QTOCiqgVyx8mb86fmYEFAmqDzlYACgkQyx8mb86f
 mYGbYxAAgI83CFBSrCZAl269MC8GUqbGKbTMcWJlR8EhQx81TluR97AJvYpPH+eg
 zWyJoSpvXsTYorPKdm+JtEtTyb57CRs0jgNVNzIoCOKE0pxgQ++6vCZj3e7EN/Mc
 lNSrAj5CYNAhEKT/1Cik0O7DLYW3qgdqk6zyIErIAHSrtJH4hVqp/vSRrIz5J9xT
 dDgbsAOMPOQTcstu0VddiewUlWhfl75+oAONUpG7mtkhieN5zp81pFaZICd8aLYH
 AylWylvQf2lmDB6Jqtg4tRXZ7HNieFms3KSV9KGRbw6GZ8xf/1pDlqf9zyqUbs+y
 s2mkIy/mjzulpDxYsozSCsfsMDy5pAUykPWPuL4yP8wmjdnPvJLjfDURKwTEKFZG
 6dCI1eE1y/7amFxA7gTUVAi+sinMxeI/9N9RwVyfQ/cwLvUzc6ObcUkR3GVRDiIY
 6RtsptgiTWOsVvvoa3IgWAP/Tx6HBfwhSuI2uzF+WtpusDRagCIevRC/bImW60IG
 2/PQusB0mc8XwJOl3adhNLjw/CzTuPwYMa0tJwCCn9QR+zEvjVSCj8wDmibIunm3
 6P3iWr/T4qnFi1ASKsEB1j8oDXJuUsp2xX2YzYvYU+F/xQ5fj3q+gJ33qMv5SjGB
 ccb0PpA8i3f83fBcwXj28CFvYwiDKD0u+T0LXa0+rR0zQju6M4Q=
 =GFfF
 -----END PGP SIGNATURE-----

Merge tag 'hwmon-for-v7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/groeck/linux-staging

Pull hwmon updates from Guenter Roeck:
 "New drivers:
   - Kandou KB9002 retimer
   - PolarFire SoC temp/voltage sensor
   - Eswin EIC7700 PVT sensor
   - PMBus:
      - Analog Devices MAX16545/MAX16550 and Volterra VT7505
      - Monolithic MPQ82D00 and MPQ8646
      - Silergy SQ24860

  Added support to existing drivers:
   - asus-ec-sensors: Support for ROG STRIX Z390-E GAMING, ProArt
     Z690-CREATOR WIFI, ROG STRIX X870E-E GAMING WIFI7 R2, ROG CROSSHAIR
     X870E HERO, and ROG Maximus Z790 Hero
   - asus_rog_ryujin: Siupport for ROG Ryujin III
   - ina2xx: Support for INA232
   - k10temp: Per-CCD temperature monitoring for Zen5 Turin
   - nct6775: List NCT5585D as supported chip
   - nzxt-kraken3: Support for NZXT Kraken 2024 Elite
   - sht3x: Support for GXCAS GXHT30
   - tmp102: Add device IDs for TMP110 and TMP113
   - yogafan: Support for LOQ 15IAX9, XiaoXin Pro 13ARE 2020, IdeaPad 3
     15ALC6, Legion Pro 7 16AFR10H, Yoga Pro 7 14IAH10, Yoga 7 16ARP8,
     and Lenovo LOQ 15IAX9
   - PMBus:
      - max20830: Support for max20830c and max20840c
      - max34440: Support for MAX34452, and support for newer version of
        max34451
      - adm1275: Support for ROHM BD12780 and BD12790

  Other notable changes:
   - Constify various device attributes
   - Remove redundant dev_err() and dev_err_probe() from various drivers
   - applesmc: Convert to hwmon_device_register_with_info
   - adt7470: Add thermal zone sensor support
   - coretemp: Fix core_data leak on CPUs without PTS
   - emc1403: Drop hysteresis for low limit temperature
   - max6621: Fix various over- and underflow problems
   - PMBus:
      - Introduce pmbus_read_smbus_i2c_block_data() and use it in
        various drivers
      - Export and use pmbus_check_and_notify_faults()
      - Let PMBus drivers report the supported PMBus revision

  Various other minor fixes and improvements"

* tag 'hwmon-for-v7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/groeck/linux-staging: (110 commits)
  hwmon: (emc1403) Drop hysteresis for low limit temperature
  hwmon: (coretemp) Fix core_data leak on CPUs without PTS
  hwmon: (max6621) fix negative temperature offset and crit readings
  hwmon: (max6621) fix temperature clamp range
  hwmon: (asus_rog_ryujin) Add ROG Ryujin III White Edition
  hwmon: (asus_rog_ryujin) Add ROG Ryujin III support
  hwmon: (asus_rog_ryujin) Add per-device configuration
  hwmon: (k10temp) Add per-CCD temperature monitoring for Zen5 Turin
  hwmon: (tmp102) Add TMP113 device ID
  hwmon: (tmp102) Add TMP110 device ID
  hwmon: (nct6775) Add NCT5585D to list of supported chips
  Documentation: hwmon: (nct6775) Add missing NCT6797D and NCT6798D
  hwmon: (emc1403) Add regulator support
  hwmon: (emc1403) Convert to use OF bindings
  dt-bindings: hwmon: Document SMSC EMC1402/1403/1404/1428
  hwmon: (asus-ec-sensors) add ROG STRIX Z390-E GAMING
  hwmon: (sysfs) Allow drivers to register const attributes
  hwmon: (corsair-psu) Update documentation
  hwmon: (core) Use const APIs for the dynamically allocated sysfs attributes
  hwmon: (core) Constify device attributes
  ...
2026-08-19 09:56:28 -07:00
Linus Torvalds
4e1b759c06 watchdog updates for v7.3
* New Drivers
 
   - Nuvoton MA35D1
 
   - Lenovo SE30G2 and SE60
 
 * Added support to existing drivers
 
   - snps,dw-wdt: Add RV1106 compatible
 
   - apple,wdt: Add t6030, t6031, and t8132 compatibles
 
 * Other notable changes
 
   - New "dump" pretimeout governor
 
   - Propagate errors from optional IRQ lookup
 
   - Remove redundant dev_err() and dev_err_probe() messages
 
   - npcm, qcom: Improved bootstatus reports
 
   - realtek-otto: Change to use regmap API
 
   - w83627hf_wdt: Report running watchdog, identify NCT6126
 
 * Various other minor fixes and improvements
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCAAdFiEEiHPvMQj9QTOCiqgVyx8mb86fmYEFAmqDYDcACgkQyx8mb86f
 mYGbiBAAkL3MIf4R7bguS1K9xS1iGqYEpZsnlPKcj3vrU5mTOHUrP2QxacltmDQV
 PVgwSC3ExWjGEoR/HMQqIaz3UEPZVNMc97Q/8OK1ewoSpQHTYAVIYhL9vs9GxuCc
 K2Iw5zu3A0HtLfj8bWbr4b1KxDBLsr+dK0VtVJfz+Oqk9GGKALf4H92IJogdqJXg
 ESG0Gl4Ap4GvPywSc5YtNI6BOeUUYaAPeTH8ahdXAIZjXKtbHgU6JTaTC/5MIQ5i
 Gjn+6BGjUkk1CYBxLTC+iFL/9N/CP8HxczOKBnIC3WQ32ZK17vMFo5C5JE3N2U9Y
 KiN1AKW79mzXD9VphQudB6RdPtPHusbZU8nW8MkebK0vD8wDYbHX4LcTUHn5kbyh
 V8pPNV+hXgO6WvAtqkrcb84W2M1iyWQpz0lcQ0f7sI5dtZz+K/d0tF6Chho9F9m2
 0ozR3hFWOZiJoXKZ5M1b1TcU+5c6tcGiK8WWLq/H9f29RI9eA097W2QP6ZzkOOzh
 g7KhL27YXnyHpg1FZV+qZS+kaWuskdEOHfIqS+gHGldJefUyAAHS8pCZQVaXsdK9
 grK4hBtfO65Cbw/H2GA3yz0zYhxzWCTJ9WJqQeMK3kvjqWOxGckfhEx1EbuHCmt1
 4b9CPGEvT/7x8iKfUpHbjUEZY4i2wtkqC5kQzZGXBVgQEC6sQ0A=
 =IefI
 -----END PGP SIGNATURE-----

Merge tag 'watchdog-for-v7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/groeck/linux-staging

Pull watchdog updates from Guenter Roeck:
 "New Drivers:
   - Nuvoton MA35D1
   - Lenovo SE30G2 and SE60

  Added support to existing drivers:
   - snps,dw-wdt: Add RV1106 compatible
   - apple,wdt: Add t6030, t6031, and t8132 compatibles

  Other notable changes:
   - New "dump" pretimeout governor
   - Propagate errors from optional IRQ lookup
   - Remove redundant dev_err() and dev_err_probe() messages
   - npcm, qcom: Improved bootstatus reports
   - realtek-otto: Change to use regmap API
   - w83627hf_wdt: Report running watchdog, identify NCT6126

  Various other minor fixes and improvements"

* tag 'watchdog-for-v7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/groeck/linux-staging: (40 commits)
  watchdog: orion_wdt: Propagate errors from optional IRQ lookup
  watchdog: qcom: Propagate errors from optional IRQ lookup
  watchdog: aspeed: Propagate errors from optional IRQ lookup
  watchdog: stm32_iwdg: Propagate errors from optional IRQ lookup
  watchdog: dw_wdt: Propagate errors from optional IRQ lookup
  watchdog: mediatek: Propagate errors from optional IRQ lookup
  watchdog: apple: Constify some structures
  watchdog: pretimeout: Convert dump pretimeout governor to tristate
  nmi: Export CPU backtrace APIs for loadable modules
  watchdog: booke_wdt: Document unused parameter of __booke_wdt_disable()
  watchdog: wdat_wdt: map registers that fall inside ACPI NVS
  watchdog: Add Nuvoton MA35D1 watchdog driver support
  dt-bindings: watchdog: Add MA35D1 Watchdog
  watchdog: qcom: report bootstatus on IPQ9574 and IPQ5332
  watchdog: qcom: report WDIOF_POWERUNDER in bootstatus
  watchdog: sprd: Remove redundant dev_err()
  watchdog: sama5d4: Remove redundant dev_err()
  watchdog: realtek_otto: Remove redundant dev_err_probe()
  watchdog: orion: Remove redundant dev_err()
  watchdog: marvell_gti: Remove redundant dev_err_probe()
  ...
2026-08-19 09:53:35 -07:00
Linus Torvalds
307b9ddbbc spi: Updates for v7.3
Along with a lot of driver specific work we've got a couple of core
 features here.  The bigger one is that we've now got support for
 instantiating devices from sysfs similarly to how it's already done for
 I2C, this is used with development boards with non-enumerable expansion
 headers since SPI devices need to be manually specified.  We also have
 support for the DQS signal on higher end flash devices.
 
  - Support for intantiating devices from sysfs, useful for development
    boards with non-enumerable plugin modules, from Vishwaroop A.
  - Support for DQS in spi-mem, an additional signal used by flash
    devices to avoid clock skew from Miquel Raynal.
  - Support for more advanced SPI modes on DesignWare controllers from
    Sudip Mukherjee.
  - Changes from Jisheng Zhang to update to modern methods of specifying
    the PM callbacks.
  - Fixes for DMA mapping error handling, plus KUnit tests for this, from
    Honghui Jiang.
  - Substantial cleanup and performance work in the nxp-spi driver.
  - Support for Microchip LAN969x, Nuvoton MA35D1 QSPI, Qualcomm SA8255p
    and SA8797P, and StarFive JHB100 SFC.
 
 There is a trivial add/add conflict with the KUnit tree in their
 all_tests.config.
 -----BEGIN PGP SIGNATURE-----
 
 iQEzBAABCgAdFiEEreZoqmdXGLWf4p/qJNaLcl1Uh9AFAmqDOgcACgkQJNaLcl1U
 h9BKxQf/QznwKffXtoEL4ZFVBckmuYXRzbkHLoX1v7upZ3QFEPG8K6rRySaXufDI
 BX3/W14CfjXANIwWCr7llQmXLBoyOq8faz8U2h/aLnBpbI4WzZELfw49Lh9JQVk5
 dxVwWQ674UFuyRC4B8QaPqMFdbn8a1CORa5Rqg/dyenxwxgsVCyl2qz+PTLVdCGH
 IWO1WW6ZISDJ5YovzMcHM4KBgut1gO6FDtz0DEj2GQC+JpCl8oHyF7E/RQ2E+Nv+
 LWb6nCLfp4z3/68zQ2UrcXa1crdGsdEIFJFwV8FUYdmv24TSD+/pClczK57h422v
 Ros+Krb7fOTE+YCXqFcZgg8IGupZsw==
 =5wbJ
 -----END PGP SIGNATURE-----

Merge tag 'spi-v7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/spi

Pull spi updates from Mark Brown:
 "Along with a lot of driver specific work we've got a couple of core
  features here. The bigger one is that we've now got support for
  instantiating devices from sysfs similarly to how it's already done
  for I2C, this is used with development boards with non-enumerable
  expansion headers since SPI devices need to be manually specified. We
  also have support for the DQS signal on higher end flash devices.

   - Support for instantiating devices from sysfs, useful for
     development boards with non-enumerable plugin modules, from
     Vishwaroop A.

   - Support for DQS in spi-mem, an additional signal used by flash
     devices to avoid clock skew from Miquel Raynal.

   - Support for more advanced SPI modes on DesignWare controllers from
     Sudip Mukherjee.

   - Changes from Jisheng Zhang to update to modern methods of
     specifying the PM callbacks.

   - Fixes for DMA mapping error handling, plus KUnit tests for this,
     from Honghui Jiang.

   - Substantial cleanup and performance work in the nxp-spi driver.

   - Support for Microchip LAN969x, Nuvoton MA35D1 QSPI, Qualcomm
     SA8255p and SA8797P, and StarFive JHB100 SFC"

* tag 'spi-v7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/spi: (132 commits)
  spi: Add KUnit coverage for DMA mapping error paths
  spi: Clear current DMA devices when unmapping a message
  spi: Move __spi_unmap_msg() before __spi_map_msg()
  spi: Fix DMA mapping ownership on partial map failure
  spi: dt-bindings: sun6i: Add compatibles for A733's SPI controllers
  spi: ma35d1-qspi: Use the existing update helper
  spi: ma35d1-qspi: Add DTR support
  spi: ma35d1-qspi: Allow several command bytes
  spi: ma35d1-qspi: Move speed setting to bus configuration
  spi: ma35d1-qspi: Remove redundant reset operation
  spi: dw: Remove shadowed dws in dw_spi_setup()
  spi: img-spfi: don't disable runtime PM on DMA deferred probe
  spi: mtk-nor: Propagate errors from IRQ request
  spi: mtk-nor: Propagate errors from optional IRQ lookup
  spi: spi-qpic-snand: Handle Macronix quad read opcode 0x6b
  spi: spi-qpic-snand: add quad mode support
  spi: spi-qpic-snand: move command mapping helper
  spi: hisi-sfc-v3xx: Propagate errors from optional IRQ lookup
  spi: meson-spifc: use devm_pm_runtime_set_active_enabled
  spi: sprd-adi: Fix probe succeeding without registering the controller
  ...
2026-08-19 09:47:41 -07:00
Linus Torvalds
b3438e5ca7 regulator: Updates for v7.3
This is a relatively quiet release for the regulator API, we've had no
 major core work and not really that much driver work either.  There's a
 bunch of activity, including several new devices, but nothing hugely
 remarkable here.
 
  - Reworking of the mode handling in the max14577 driver to fix issues
    with collisions with enables.
  - Support for onsemi FAN53555BUC23X, Qualcomm IPQ9650, PM4125 VBUS and
    PM8150B and Unisoc SC2730.
 -----BEGIN PGP SIGNATURE-----
 
 iQEzBAABCgAdFiEEreZoqmdXGLWf4p/qJNaLcl1Uh9AFAmqDPDUACgkQJNaLcl1U
 h9CvoAf/Y8owPCZFX9vMl/HUGvw+Bvj/fNXDUAar0rLjseD5hq6LUQi8l7YZJy+3
 Voun5Ehakiti6VfJvA08+guG1orI/BqeT6W/lx6h1DXzvifoU8N3itKsyMk1lvug
 JtYi16gwbMa3RSdWI0W3ftAMIq6GeTNyLnPfqSM8XWJ2McZVABpg3ndOegaU922y
 aSBODYyI7weoWD+p+JI5P9O/vncGoO9tDRdwHBeZXi1HuR7HcOe9aGDSeQn/1dvC
 /dLDRNKpSPV/jscvxAa3MyCIAbubQipRcfEIGZTYXDabr8NE2odgKwWaZRkVyts2
 +mfkEBqz1z5Tsx+AfplwxnXk+3i3vw==
 =0fgh
 -----END PGP SIGNATURE-----

Merge tag 'regulator-v7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/regulator

Pull regulator updates from Mark Brown:
 "This is a relatively quiet release for the regulator API, we've had no
  major core work and not really that much driver work either. There's a
  bunch of activity, including several new devices, but nothing hugely
  remarkable here.

   - Reworking of the mode handling in the max14577 driver to fix issues
     with collisions with enables

   - Support for onsemi FAN53555BUC23X, Qualcomm IPQ9650, PM4125 VBUS
     and PM8150B and Unisoc SC2730"

* tag 'regulator-v7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/regulator: (36 commits)
  regulator: fan53555: Add support for FAN53555BUC23X type
  regulator: qcom-rpmh: Fix coding style issues
  regulator: qcom-rpmh: readback voltage/bypass/mode set during bootup
  regulator: qcom-rpmh: Fix PMIC5 BOB bypass mode handling
  soc: qcom: rpmh: Add support to read back resource settings
  regulator: dt-bindings: ti,pbias-omap: Convert to DT schema
  regulator: ab8500: Remove stale expand_register kernel-doc entry
  regulator: dt-bindings: Correct white-space style
  regulator: pfuze100: add set_suspend_disable for LDO ops
  regulator: core: use system_freezable_wq for init complete work
  regulator: rt6245: Restore state on enable failure
  regulator: tps65185: handle gpiod_get_value_cansleep() error returns
  regulator: fan53555: Add support for mode operations on Silergy devices
  regulator: dt-bindings: Add fan53555 allowed modes
  regulator: wm831x-isink: remove conditional return with no effect
  regulator: dt-bindings: Convert ltc3589.txt to yaml format
  regulator: dt-bindings: tps51632: Convert to DT schema
  regulator: mcp16502: Convert to dev_err_probe() in mcp16502_probe()
  regulator: adp5055: Fix error code in adp5055_of_parse_cb()
  regulator: qcom_usb_vbus: add support for qcom,pm4125-vbus-reg
  ...
2026-08-19 09:36:58 -07:00
Linus Torvalds
259c4f8e77 regmap: Updates for v7.3
This is a relatively busy release, though it's mostly cleanup work.  We
 did add some new hooks for regmap-irq to support some driver work, that
 should also come in as part of a shared branch with the relevant driver
 work in the GPIO subsystem.
 -----BEGIN PGP SIGNATURE-----
 
 iQEzBAABCgAdFiEEreZoqmdXGLWf4p/qJNaLcl1Uh9AFAmqDMxkACgkQJNaLcl1U
 h9D2zAgAhtilvZs1DOVuoIMjOQ7EOSmaszoRBWGQKJ+T9FOj8QuSuJrTj1DIByi9
 R9TFcsKaiBK2KjBVg/eb4YCch5FfDYC+kANjw0+9aYs+02nKvpJYkZhODAumRT6F
 Df7ftdy9lFEfZoOnG/Ehebay2i3zvhc9gyfiI3XSuvFuFlg/sqwQQ9qh1BRYLian
 EmV4V4SBz4DG6MU0sXA/83TGMleev8qH/+itD0meS4YF7zbFi599q0cAihNqn0Tp
 hzxUH0PY89R7hXcZKgFGxq0I6/O/7zrbQNnA3BarCM9RXGH04DYpw9R1/kjTlMP3
 JmlkCSiuS7/sj7n6B0/pQmMn2k6G7Q==
 =iTaj
 -----END PGP SIGNATURE-----

Merge tag 'regmap-v7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/regmap

Pull regmap updates from Mark Brown:
 "This is a relatively busy release, though it's mostly cleanup work. We
  did add some new hooks for regmap-irq to support some driver work,
  that should also come in as part of a shared branch with the relevant
  driver work in the GPIO subsystem"

* tag 'regmap-v7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/regmap:
  regmap: clean up kernel-doc comments
  regcache: Validate cache_only state in regcache_sync_region()
  regcache: Warn if regcache_sync() is called in cache_only mode
  regcache: Mark cache dirty if selector register rewrite fails
  regcache: Preserve cache synchronization errors in regcache_sync()
  regmap: maple: Workaround for another false-positive compiler warning
  regcache: Make ->exit() callback return void
2026-08-19 09:32:57 -07:00
Linus Torvalds
ee1b6365f0 pmdomain providers:
- amlogic: Add support for A9 power domains
  - bcm: Raise ASB poll timeout to 100us for bcm2835-power
  - imx: Allow building power domain drivers as a modules
  - mediatek: Add support for the MT6858 power domains
  - mediatek: Add support for the MT8196 HFRP DirectCTL power domains
  - qcom: Add support for RPMh power domains for Maili
  - qcom: Skip retention by default for rpmhpd
  - renesas: Add support for R-Car X5H Module Controller
  - rockchip: Add a regulator to the RK3568 NPU power domain
  - tegra: Add support for multi-socket platforms
 -----BEGIN PGP SIGNATURE-----
 
 iQJEBAABCgAuFiEEugLDXPmKSktSkQsV/iaEJXNYjCkFAmqC8RYQHHVsZmhAa2Vy
 bmVsLm9yZwAKCRD+JoQlc1iMKYloEADS2kGT/z2l2NgivbXZFvz0RSNRG18nIpML
 6HwJd0qKr5r+U9mpIkfwvHzI3BQGYWOAt0P8y9Wrf+b32lBoDeZqKAB7N7NSOOB7
 FhNHeI+U1BIKoDxjuh/zWlHpwTAIbVDdiEJnBk1uGiG5ydco/CmwaQnDNnJywJfz
 dsfiDM1q+okolagNxx+VzhvRaxgSqvGBiX52CAMJmcmiIXIlfNTMKK9rnQRhD3lh
 kfhSnZYRQwtl7MQ7990vULYrINxAidU4KIoRnCPSJ+eA7Rl2udtsiEdQYdFba6C5
 lzEhHzgDWN9YTExCHFhy/vLOWbehoW/z6Jfz3m/Lxmkv7Zd37t3SuMj/0KnPCrpM
 Vtg8ZirqG1hvhihcoUpk20jR7LlUGcX1k5ipsP/ptj8uVkdHKVzen6bHy2FvpMle
 bYNRWwd8TKqYxAGsxEMZ59GRpRdIRowFSUAOmcP09b5CI8wslkljpmZWZgBxk1f8
 31CpmIDMIIxuYY3m0GR5CHlcAXxZO7N+5kk7AqBgDh1IXKf1/CcvgABetAMcJl07
 jcUfBBaZDA64ulzqnAEclW+xjITX5+qONVjEy5D/JORo89ttbYaAKyL10BrAb2lm
 WbkAP3R15ueHAKsE9Q6xMZ66V3qJxdF9wqmq3f/4TE+QRntDzvE/KMhCjxG5LOJ4
 I1Bb9v3rYA==
 =6EOE
 -----END PGP SIGNATURE-----

Merge tag 'pmdomain-v7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/ulfh/linux-pm

Pull pmdomain updates from Ulf Hansson:
 - amlogic: Add support for A9 power domains
 - bcm: Raise ASB poll timeout to 100us for bcm2835-power
 - imx: Allow building power domain drivers as a modules
 - mediatek:
    - Add support for the MT6858 power domains
    - Add support for the MT8196 HFRP DirectCTL power domains
 - qcom:
    - Add support for RPMh power domains for Maili
    - Skip retention by default for rpmhpd
 - renesas: Add support for R-Car X5H Module Controller
 - rockchip: Add a regulator to the RK3568 NPU power domain
 - tegra: Add support for multi-socket platforms

* tag 'pmdomain-v7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/ulfh/linux-pm: (24 commits)
  pmdomain: renesas: Add R-Car X5H MDLC driver
  dt-bindings: power: Document Renesas R-Car X5H Module Controller
  pmdomain: amlogic: Add support for A9 power domains controller
  dt-bindings: power: Add Amlogic A9 power domains
  clk: imx: imx8qxp: add soft dependency on SCU power domain driver
  pmdomain: imx: scu-pd: allow building as a module
  of: export of_stdout symbol
  pmdomain: imx8m{p,}-blk-ctrl: Add MODULE_DESCRIPTION
  pmdomain: mediatek: Add support for MT6858 SoC
  pmdomain: mediatek: Add support for secure modem power domain control
  dt-bindings: power: Add MediaTek MT6858 power domain controller
  pmdomain: rockchip: Add a regulator to the RK3568 NPU power domain
  pmdomain: imx: Make IMX8M/IMX9 BLK_CTRL tristate
  dt-bindings: power: qcom,rpmpd: document RPMh power domain for Maili
  pmdomain: tegra: Add support for multi-socket platforms
  pmdomain: bcm: bcm2835-power: Raise ASB poll timeout to 100us
  pmdomain: mediatek: Add support for MT8196 HFRP DirectCTL domains
  pmdomain: mediatek: Add support for Direct CTL simple power sequence
  pmdomain: mediatek: Respect PD relationships during error cleanup
  dt-bindings: power: mediatek: Add support for MT8196 direct HFRP
  ...
2026-08-19 09:28:46 -07:00
Linus Torvalds
abea5c3493 i2c for v7.3
Core and helpers:
 - support bus recovery with single-ended GPIOs
 - acpi: clean up resource handling
 - acpi: force ELAN1300 to 100 kHz
 - algo-bit: allow consumers to skip the optional bus test
 
 Drivers:
 - use generic bus frequency definitions in nomadik,
   octeon-core, microchip-corei2c, k1, davinci and pnx
 - i2c-gpio: support multiple buses sharing the same SCL line
 - qup: propagate clock enable failures
 - spacemit: configure SCL timing and clean up clock handling
 - amd-asf: guard against oversized firmware length
 
 qcom-geni:
 - add tracepoints for bus setup, interrupts and errors
 - use dedicated completion events for abort and reset
 - distinguish address and data NACK handling
 - cancel transfers before falling back to abort
 - simplify runtime PM and resource management
 - refactor resource and serial engine initialization
 
 DT bindings:
 - convert Altera bindings to DT schema
 - convert Axxia bindings to DT schema
 
 New support:
 - R-Car Gen5 and R-Car X5H
 - Axiado AX3005
 - Qualcomm Nord SA8797P
 - Qualcomm SA8255p
 -----BEGIN PGP SIGNATURE-----
 
 iHUEABYKAB0WIQScDfrjQa34uOld1VLaeAVmJtMtbgUCaoA//QAKCRDaeAVmJtMt
 bvzYAQDPhRd2O6BruFmCkxKKvlrxZ2AaHQX/ZHLNqLAq/oX4NwD8CSecgva9faf/
 bC+kTGoTMBhje3FEJFufHKe2YtmJdgg=
 =u6az
 -----END PGP SIGNATURE-----

Merge tag 'i2c-7.3-part1' of git://git.kernel.org/pub/scm/linux/kernel/git/andi.shyti/linux

Pull i2c updates from Andi Shyti:
 "The main changes are support for shared SCL lines in i2c-gpio, a
  larger qcom-geni update covering tracing and transfer recovery and
  support for R-Car Gen5.

  The rest is mostly smaller driver, core and DT binding updates.

  Core and helpers:
   - support bus recovery with single-ended GPIOs
   - acpi: clean up resource handling
   - acpi: force ELAN1300 to 100 kHz
   - algo-bit: allow consumers to skip the optional bus test

  Drivers:
   - use generic bus frequency definitions in nomadik, octeon-core,
     microchip-corei2c, k1, davinci and pnx
   - i2c-gpio: support multiple buses sharing the same SCL line
   - qup: propagate clock enable failures
   - spacemit: configure SCL timing and clean up clock handling
   - amd-asf: guard against oversized firmware length

  qcom-geni:
   - add tracepoints for bus setup, interrupts and errors
   - use dedicated completion events for abort and reset
   - distinguish address and data NACK handling
   - cancel transfers before falling back to abort
   - simplify runtime PM and resource management
   - refactor resource and serial engine initialization

  DT bindings:
   - convert Altera bindings to DT schema
   - convert Axxia bindings to DT schema

  New support:
   - R-Car Gen5 and R-Car X5H
   - Axiado AX3005
   - Qualcomm Nord SA8797P
   - Qualcomm SA8255p"

* tag 'i2c-7.3-part1' of git://git.kernel.org/pub/scm/linux/kernel/git/andi.shyti/linux: (33 commits)
  i2c: core: support recovery for single-ended GPIOs
  i2c: rcar: add R-Car Gen5 support
  dt-bindings: i2c: rcar-i2c: Document R-Car X5H support
  i2c: i2c-gpio: Enhance driver for buses with shared SCL
  i2c: algo: bit: Allow to skip bit test
  i2c: qcom-geni: Add trace events for Qualcomm GENI I2C driver
  i2c: qcom-geni: trace: Add trace events for Qualcomm GENI I2C
  i2c: qup: Propagate clock enable failures
  i2c: qcom-geni: distinguish address-phase and data-phase NACK
  i2c: qcom-geni: use dedicated completions for abort and reset events
  i2c: qcom-geni: use cancel command before abort on transfer timeout
  dt-bindings: i2c: cdns: add Axiado AX3005 I2C variant
  i2c: qcom-geni: Use devm_pm_runtime_enable() for PM management
  dt-bindings: i2c: qcom,sa8255p-geni-i2c: Add compatible for Nord SA8797P
  i2c: nomadik: Use generic definitions for bus frequencies
  i2c: octeon-core: Use generic definitions for bus frequencies
  i2c: microchip-corei2c: Use generic definitions for bus frequencies
  i2c: k1: Use generic definitions for bus frequencies
  i2c: davinci: Use generic definitions for bus frequencies
  i2c: pnx: Use generic definitions for bus frequencies
  ...
2026-08-19 09:23:13 -07:00
Linus Torvalds
7711f4417f gpio updates for v7.3-rc1
GPIO core:
 - extend the gpio-regmap abstraction layer with more features allowing users
   to override configuration setting, translate register values and masks and
   enable/disable interrupts
 - extend GPIO kunit tests with suites verifying probe ordering by software
   node devlink support and software node hogs
 - shrink GPIO kunit initialization code
 - coding style updates (remove commas from sentinels where applicable)
 - with all users now converted treewide to using real firmware node links for
   software node GPIO lookup: remove the deprecated label-matching mechanism
   from from GPIO core
 - drop redundant return value check of nonseekable_open() in gpiolib-cdev
 - use IRQ trigger helpers where applicable
 
 Driver updates:
 - refactor error paths and logging in gpio-nomadik
 - use more modern interfaces for getting resources in gpio-rockchip,
   gpio-bt8xx and gpio-pca9570
 - add missing MODULE_DEVICE_TABLE() to gpio-sifive and gpio-vf610
 - drop unused FILONOFF macro from gpio-rcar
 - extend build coverage of ioport GPIO drivers with COMPILE_TEST=y
 - only enable the gpio-rtd driver by default with ARCH_REALTEK=y to avoid
   bloating the build
 - refactor coding style in several drivers
 - use correct endianess translation in gpio-pcf85x
 - add wake-up interrupt support to gpio-mvebu
 - apply initial value in direction output setter in gpio-by-pinctrl
 
 Misc:
 - replace linux/gpio.h inclusions treewide with linux/gpio/legacy.h which now
   exports all the deprecated APIs
 - select GPIOLIB_LEGACY in Kconfig where required treewide
 - use software nodes for gpio-keys in MFD drivers
 
 Devicetree bindings:
 - describe the realtek rtd1625 GPIO controller
 - document new models for gpio-pca95xx and gpio-cadence
 - document new property in gpio-rockchip
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEkeUTLeW1Rh17omX8BZ0uy/82hMMFAmqET1QACgkQBZ0uy/82
 hMMXLRAArm8tuPq9ehmJIBwSxXmK4HGM9x2PBXBOtv7NZ4x5skSpsMOmJBlb9r3S
 EJ7IK7DIqb1XIilRxgfLwmza9e4wXEQ3OK7lrxx/9qW52XKvJ0JxoUhEw4vn9etJ
 N3qc4p2EByR98PLWrnPmcDyG8oZDzBixcDsaeuvulIDtFklTpTRH0FHuEJQ1sEfa
 2y7/K6/n2Gru56u2iTjW8AIIfG18h2SG9Pm92UL006O6Xl8bKHexrmb98WEpIKoU
 UzKGgQ/alnOFsevt6zuB30StX6qKmagdu1+dRpVypczBaoUjs6YG4EfJQJ0mw/vR
 qBzui/HsGwYlkMmHgVoqSbm0khIS9vd85NSVTk/jC45+ZGyJRmdCJh30VBpXjOy4
 3zEVrZUo0kMIW/foszAqCZrn1P5kpmlwXR3oP89NwMzzEQQFzVjdirXih+dmhq0e
 /nxUjAY2CmEXd4wep183Swobqadi2tyuktWnE1mz/YH2Tv/KlMzzwIQEXyd4jSOc
 gOh8ACVp/wdsvihF+E/kjuRaLs3JX5nvoIMQu0CZAAl6TAYmCrXJbMDSLncY/4jv
 sCWuUVEowR3V+1RpVD++eIOsrD8ItNdn0aY3aXL1ez7oUCsisI651oRUCS/is1S/
 fw4DN5gTdNt+iNUWHIJM3lOPjTPO6hCPXAyht3B6pibCibiI1Dk=
 =rUDt
 -----END PGP SIGNATURE-----

Merge tag 'gpio-updates-for-v7.3-rc1-v2' of git://git.kernel.org/pub/scm/linux/kernel/git/brgl/linux

Pull gpio updates from Bartosz Golaszewski:
 "GPIO core:
   - extend the gpio-regmap abstraction layer with more features
     allowing users to override configuration setting, translate
     register values and masks and enable/disable interrupts
   - extend GPIO kunit tests with suites verifying probe ordering by
     software node devlink support and software node hogs
   - shrink GPIO kunit initialization code
   - coding style updates (remove commas from sentinels where
     applicable)
   - with all users now converted treewide to using real firmware node
     links for software node GPIO lookup: remove the deprecated
     label-matching mechanism from from GPIO core
   - drop redundant return value check of nonseekable_open() in
     gpiolib-cdev
   - use IRQ trigger helpers where applicable

  Driver updates:
   - refactor error paths and logging in gpio-nomadik
   - use more modern interfaces for getting resources in gpio-rockchip,
     gpio-bt8xx and gpio-pca9570
   - add missing MODULE_DEVICE_TABLE() to gpio-sifive and gpio-vf610
   - drop unused FILONOFF macro from gpio-rcar
   - extend build coverage of ioport GPIO drivers with COMPILE_TEST=y
   - only enable the gpio-rtd driver by default with ARCH_REALTEK=y to
     avoid bloating the build
   - refactor coding style in several drivers
   - use correct endianess translation in gpio-pcf85x
   - add wake-up interrupt support to gpio-mvebu
   - apply initial value in direction output setter in gpio-by-pinctrl

  Misc:
   - replace linux/gpio.h inclusions treewide with linux/gpio/legacy.h
     which now exports all the deprecated APIs
   - select GPIOLIB_LEGACY in Kconfig where required treewide
   - use software nodes for gpio-keys in MFD drivers

  Devicetree bindings:
   - describe the realtek rtd1625 GPIO controller
   - document new models for gpio-pca95xx and gpio-cadence
   - document new property in gpio-rockchip"

* tag 'gpio-updates-for-v7.3-rc1-v2' of git://git.kernel.org/pub/scm/linux/kernel/git/brgl/linux: (61 commits)
  gpio: gpio-by-pinctrl: Apply initial value in direction output wrapper
  dt-bindings: gpio: rockchip,gpio-bank: Add rockchip,grf property
  gpio: Use IRQ trigger mask helpers
  gpio: allow COMPILE_TEST for IOPORT drivers
  gpio: realtek: Add driver for Realtek DHC RTD1625 SoC
  gpio: regmap: Add IRQ enable/disable helpers
  gpio: regmap: Add set_config callback
  gpio: regmap: Add value_xlate callback
  gpio: regmap: Add gpio_regmap_operation to extend reg_mask_xlate callback
  gpio: regmap: Order kernel-doc descriptions with the actual appearance
  gpio: regmap: Apply default resource callbacks for regmap IRQ chip
  gpio: regmap: Provide default IRQ resource request and release callbacks
  Revert "gpio: realtek: Add driver for Realtek DHC RTD1625 SoC"
  gpib: gpio: replace linux/gpio.h inclusion
  Input: matrix_keyboard - replace linux/gpio.h inclusion
  phy: replace linux/gpio.h inclusions
  pcmcia: replace linux/gpio.h inclusions
  ASoC: replace linux/gpio.h inclusions
  mfd: replace linux/gpio.h inclusions
  sh: replace linux/gpio.h inclusions
  ...
2026-08-19 09:10:07 -07:00
Linus Torvalds
d0d82a84c9 power sequencing updates for v7.3-rc1
- add support for new devices to pwrseq-pcie-m2
 - make device matching more fine-grained for cases where the same combo
   chips are wired differently on the M.2 card (and - for instance - don't
   require serial device creation because they expose BT over USB) in
   pwrseq-pcie-m2
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEkeUTLeW1Rh17omX8BZ0uy/82hMMFAmp9fyoACgkQBZ0uy/82
 hMNUbA/+Kx/J/EaKdgQ3anbjdfByUuVHAAKOLOiLmIgK+EjH1TnBAABXYPwinExy
 a7wb3th7VyHRAIXkVArHJ3cIQg2B2N+L2A+9ABV5z0GGRgzFUaDZv7yn5++LxrAd
 oZ8ug8JcmUmqccdRa7mH0GkQLMK8mWZ/zBnGvd6q8qXFE4wHxM9IUIAyiyMVAqjj
 lX0X2vPaRCAaWzT17iehkA5liZV23ViVcwFj1EK03bFW0nkb/TeyHcuUbHmKdN+6
 YhDkg8g/FGP3gq1T5YPKq3sRzI4qQPRvw5xaynFqn/v156jd7/7rEz+F4LApF1xF
 1S19he1UK1sndouo8CclqEhY1MfgIs/8Gp7PiDK9Koksuc82BYxO9+NzKSnPcImK
 bMiUOwuY37Mpbe0y2j1gmgxVdFcEzksrMTlw2oguVFDfrzUcmL2VdP4J2i8GJqo5
 JKRMhQNwuSF11G1Ke7qKPuve1zbFvxNXcwRzeQK+TXOFcmzU4/akIS6RcDy3Oa3o
 e/lw2DB4vHSbviF7BBgf2aPWCcYJkenG3yUKaSkPBDIE+4q45Xm2bdtwGgJqqof9
 22O7w/MWOk/+WWRVISPHmoJTXuTmhWseFp5W/0EAzLg4C2tNNr/5yB1+S6psOJud
 PV+IF+hkb2IjGr+bTmpv1muFI715r+1Z/6L1hPhWS2Yf6aJkCRQ=
 =1mGa
 -----END PGP SIGNATURE-----

Merge tag 'pwrseq-updates-for-v7.3-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/brgl/linux

Pull power sequencing updates from Bartosz Golaszewski:
 "This a very tiny pull for v7.3 from the power sequencing tree. It only
  contains a handful of updates to the pwrseq-pcie-m2 driver:

   - add support for new devices to pwrseq-pcie-m2

   - make device matching more fine-grained for cases where the same
     combo chips are wired differently on the M.2 card (and - for
     instance - don't require serial device creation because they expose
     BT over USB) in pwrseq-pcie-m2"

* tag 'pwrseq-updates-for-v7.3-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/brgl/linux:
  power: sequencing: pcie-m2: Match WCN6855 and WCN7851 UART BT variants by subdevice ID
  power: sequencing: pcie-m2: Add QCA2066 (QCNFA765) BT serdev ID
  power: sequencing: pcie-m2: Add PCI ID for NXP 88W9098 and AW693 Bluetooth
2026-08-19 09:08:06 -07:00
Linus Torvalds
a288cd69f7 pwm: Changes for v7.3-rc1
A bunch of cleanups---in C and Rust---and  a devicetree and driver
 extension for a new SoC variant.
 
 Thanks for Biju Das, Francis Laniel, Guru Das Srinagesh, Markus Elfring,
 Mikko Perttunen, Thierry Reding, and Yi-Wei Wang for their changes and
 further Alexandre Courbot, Benno Lossin, Chen Wang, Geert Uytterhoeven,
 Jon Hunter, Laurent Pinchart, Michal Wilczynski, Mikko Perttunen, and
 Rob Herring for valuable review feedback.
 -----BEGIN PGP SIGNATURE-----
 
 iQEzBAABCgAdFiEEP4GsaTp6HlmJrf7Tj4D7WH0S/k4FAmqCN9MACgkQj4D7WH0S
 /k6YZwgAkCOWUj5cZbcFfNE+AoUyuikvH8zfECfDInGDJMOSSP1BJp1Gfby04D4w
 kPtSvIEpECri6xVkW8vYRKZV2HZVeXCiKFXK8Yz/Z2udOOsDmkTsTBKlYQmyY5nO
 lEOhUnXZ2IgpnAfRRcPmtBxzTQdLpH8Y9xncj77Mhl4qbMqsHC886C4RbxiDyksw
 EAd6U30MbbkPHntQB1/s4rBtqSR9B72L/d84BD9Kbq+N2wvZYpGd9Ym9fG2z3SQg
 rb3XGh+9kE38CO9e+CxTjlzq0wmIq90kJlmHmoPJGazlW2pmDj2pyYr/yEd6w4VM
 85pzQx6oXgx09N53nD3+ncs+SynDoQ==
 =dAjh
 -----END PGP SIGNATURE-----

Merge tag 'pwm/for-7.3-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/ukleinek/linux

Pull pwm updates from Uwe Kleine-König:
 "A bunch of cleanups - in C and Rust - and a devicetree and driver
  extension for a new SoC variant.

  Thanks to Biju Das, Francis Laniel, Guru Das Srinagesh, Markus
  Elfring, Mikko Perttunen, Thierry Reding, and Yi-Wei Wang for their
  changes and further Alexandre Courbot, Benno Lossin, Chen Wang, Geert
  Uytterhoeven, Jon Hunter, Laurent Pinchart, Michal Wilczynski, Mikko
  Perttunen, and Rob Herring for valuable review feedback"

* tag 'pwm/for-7.3-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/ukleinek/linux:
  pwm: th1520: use vertical import style
  rust: pwm: replace `core::mem::zeroed` with `pin_init::zeroed`
  pwm: rzg2l-gpt: Drop unused rzg2l_gpt_chip parameter from rzg2l_gpt_calculate_prescale()
  pwm: Use seq_putc() calls in pwm_dbg_show()
  pwm: tegra: Add support for Tegra264
  pwm: tegra: Parametrize duty and scale field widths
  pwm: tegra: Modify read/write accessors for multi-register channel
  pwm: tegra: Avoid hard-coded max clock frequency
  pwm: tegra: Prefix driver-local macros and functions
  dt-bindings: pwm: Document Tegra264 controller
  pwm: lpss-pci: Unify coding style of pci_device_id array
  pwm: Unify coding style of of_device_id arrays
  pwm: Unify coding style of acpi_device_id arrays
  pwm: Use named initializers for arrays of acpi_device_id
  pwm: pca9685: Drop unused assignment of acpi_device_id driver data
  pwm: pxa: Depend on OF and simplify accordingly
  pwm: Use named initializers for platform_device_id arrays
  pwm: mc33xs2410: Initialize spi_device_id arrays using member names
2026-08-19 09:03:59 -07:00
Linus Torvalds
1be05c6afb Input updates for v7.3-rc0
- A new driver and device tree binding for Imagis ISA1200 haptic motor
   controller
 
 - Improvements to input core opening, closing and inhibiting devices,
   ensuring devices are fully ready before delivering events, deferring
   handler start() until the device is opened, resyncing state on
   uninhibit, and rejecting inhibit requests during unregistration
 
 - Updates to cap11xx capacitive touch driver to support Microchip
   CAP1114, optional hardware reset GPIO handling, and per-chip LED
   constraints
 
 - Fixes for MELFAS MMS114 touchscreen driver hardening incoming data
   parsing, endianness fixes for I2C packet layout, Y-resolution
   configuration, and refactoring to use chip variant descriptors
 
 - Updates for psmouse driver resolving a potential UAF during protocol
   disconnect, cleaning up PNP ID matching, and making use of guard()
 
 - Fix for FocalTech PS/2 protocol to prevent coordinate underflow and
   cursor jumps at boundaries
 
 - A change to Synaptics driver to enable InterTouch (SMBus) mode on
   Dell Inspiron 3521
 
 - Refactoring of PA-RISC keyboard support in gscps2 to supply keymaps
   via software node device properties, removing architecture-specific
   tables from the generic atkbd driver
 
 - Updates to Samsung keypad driver to keep interrupts disabled while
   device is closed, along with wakeup logic cleanups and use of
   pm_runtime_active guards
 
 - Updates to NXP i.MX SNVS power key driver to report press events
   during resume to avoid lost events, and error handling cleanups
 
 - Updated TCA8418 keypad driver enabling overflow mode per hardware
   errata
 
 - Conversion of ROHM BD718x7 and BD71828 PMIC drivers to instantiate
   gpio-keys child devices using software nodes instead of platform data
   (coming from MFD immutable branch)
 
 - Updates to Synaptics RMI4 driver to use touchscreen dimensions from
   platform data when specified
 
 - Firmware update speed optimization for IC Type 0x19 in ELAN I2C driver
 
 - A fix to Azoteq IQS5xx driver to validate firmware record spans
   against programmable map size
 
 - Update to Samsung SUR40 contact count based on PixelSense
   specification
 
 - A number of updates to device tree bindings, including TI TPS65217
   power button schema conversion and new compatibles for FocalTech
   FT3D81 and Synaptics S3706B
 
 - Other assorted driver cleanups, style fixes, and conversions to
   modern string and cleanup helpers
 -----BEGIN PGP SIGNATURE-----
 
 iHUEABYKAB0WIQST2eWILY88ieB2DOtAj56VGEWXnAUCaoFTdwAKCRBAj56VGEWX
 nPMxAP9MpDgWs3mIjYFwg555CQyD0ZD44WOC48yQtt7hfYW/GQEArVmBQY0YW9D6
 DiSCos8VK7bCZFcLwrVpe+BzbP6E2QA=
 =FEOj
 -----END PGP SIGNATURE-----

Merge tag 'input-for-v7.3-rc0' of git://git.kernel.org/pub/scm/linux/kernel/git/dtor/input

Pull input updates from Dmitry Torokhov:

 - A new driver and device tree binding for Imagis ISA1200 haptic motor
   controller

 - Improvements to input core opening, closing and inhibiting devices,
   ensuring devices are fully ready before delivering events, deferring
   handler start() until the device is opened, resyncing state on
   uninhibit, and rejecting inhibit requests during unregistration

 - Updates to cap11xx capacitive touch driver to support Microchip
   CAP1114, optional hardware reset GPIO handling, and per-chip LED
   constraints

 - Fixes for MELFAS MMS114 touchscreen driver hardening incoming data
   parsing, endianness fixes for I2C packet layout, Y-resolution
   configuration, and refactoring to use chip variant descriptors

 - Updates for psmouse driver resolving a potential UAF during protocol
   disconnect, cleaning up PNP ID matching, and making use of guard()

 - Fix for FocalTech PS/2 protocol to prevent coordinate underflow and
   cursor jumps at boundaries

 - A change to Synaptics driver to enable InterTouch (SMBus) mode on
   Dell Inspiron 3521

 - Refactoring of PA-RISC keyboard support in gscps2 to supply keymaps
   via software node device properties, removing architecture-specific
   tables from the generic atkbd driver

 - Updates to Samsung keypad driver to keep interrupts disabled while
   device is closed, along with wakeup logic cleanups and use of
   pm_runtime_active guards

 - Updates to NXP i.MX SNVS power key driver to report press events
   during resume to avoid lost events, and error handling cleanups

 - Updated TCA8418 keypad driver enabling overflow mode per hardware
   errata

 - Conversion of ROHM BD718x7 and BD71828 PMIC drivers to instantiate
   gpio-keys child devices using software nodes instead of platform data
   (coming from MFD immutable branch)

 - Updates to Synaptics RMI4 driver to use touchscreen dimensions from
   platform data when specified

 - Firmware update speed optimization for IC Type 0x19 in ELAN I2C
   driver

 - A fix to Azoteq IQS5xx driver to validate firmware record spans
   against programmable map size

 - Update to Samsung SUR40 contact count based on PixelSense
   specification

 - A number of updates to device tree bindings, including TI TPS65217
   power button schema conversion and new compatibles for FocalTech
   FT3D81 and Synaptics S3706B

 - Other assorted driver cleanups, style fixes, and conversions to
   modern string and cleanup helpers

* tag 'input-for-v7.3-rc0' of git://git.kernel.org/pub/scm/linux/kernel/git/dtor/input: (61 commits)
  Input: rmi4 - use platform data instead of query, when available
  Input: elan_i2c - sort include statements
  Input: elan_i2c - optimize update speed for IC Type 0x19.
  Input: elan_i2c - use device-id/acpi.h for ACPI IDs
  Input: reject inhibit and uninhibit requests on unregistering devices
  Input: defer handler's start() until device is opened
  Input: call handler->start() when uninhibiting device
  Input: clear inhibited flag before re-opening device on uninhibit
  Input: ensure device is ready before delivering events
  Input: gscps2 - supply PA-RISC keyboard keymap via device property
  Input: synaptics_i2c - return 0 explicitly on success
  Input: rmi_smbus - remove conditional return with no effect
  Input: pmic8xxx-keypad - remove conditional return with no effect
  Input: focaltech - use signed coordinates to prevent underflow
  Input: psmouse - use guard() for resource management
  Input: psmouse - modernize PNP ID parsing
  Input: psmouse - clean up locking around disable_work_sync()
  Input: psmouse - fix use-after-free during protocol disconnect
  Input: samsung-keypad - use pm_runtime_active guard
  Input: samsung-keypad - keep interrupt disabled while closed
  ...
2026-08-19 08:59:24 -07:00
Linus Torvalds
e8bf40d154 chrome-platform-firmware: Updates for v7.3
* Fixes
 
   - Don't map no-map memory regions for CBMEM entries.
   - Check bound of coreboot table entries.
 
 * Cleanups
 
   - Fix typo in docs.
 -----BEGIN PGP SIGNATURE-----
 
 iIkEABYKADEWIQS0yQeDP3cjLyifNRUrxTEGBto89AUCaoJ4OxMcdHp1bmdiaUBr
 ZXJuZWwub3JnAAoJECvFMQYG2jz0FaQBAMc6loxNAMroK625wbCxO2IT/wlDASTI
 pu3MTiLy/YvxAP9ba8Vb6BC1/UGb0Wdri/CsKhvmoxoPkf6dStyhs6ovDA==
 =WVTG
 -----END PGP SIGNATURE-----

Merge tag 'chrome-platform-firmware-v7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/chrome-platform/linux

Pull chrome platform firmware updates from Tzung-Bi Shih:
 "Fixes:
    - Don't map no-map memory regions for CBMEM entries
    - Check bound of coreboot table entries

  Cleanups:
  - Fix typo in docs"

* tag 'chrome-platform-firmware-v7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/chrome-platform/linux:
  firmware: coreboot: Validate table bounds
  firmware: coreboot: Skip no-map CBMEM entries
  docs: ABI: testing: Fix typo
2026-08-19 08:49:43 -07:00
Linus Torvalds
c36a4991e2 chrome-platform: Updates for v7.3
* New
 
   - Add post_power_on_delay_ms for Hana in of_hw_prober.
 
 * Improvements
 
   - Use dumb trackpad prober for Spherion in of_hw_prober.
 
 * Fixes
 
   - Check bound of firmware-reported data in cros_ec_sensorhub and
     cros_ec_typec.
   - Fix memory overread in cros_ec_sensorhub.
   - Fix resource leak in cros_ec_debugfs.
   - Clamp payload length for LIGHTBAR_CMD_SET_PROGRAM_EX in
     cros_ec_lightbar.
 
 * Cleanups
 
   - Drop unused platform_device_id driver data.
   - Remove redundant log.
 -----BEGIN PGP SIGNATURE-----
 
 iIkEABYKADEWIQS0yQeDP3cjLyifNRUrxTEGBto89AUCaoJ2DxMcdHp1bmdiaUBr
 ZXJuZWwub3JnAAoJECvFMQYG2jz0+7EA/0xXn94u/by9d2gBbTSmM8zAm0vJUEig
 h2gBS1/mfB78AP907nez2SFGc0LBQM+Bc6v63IXOl30TW8iP8p1PLjqtAg==
 =ysx4
 -----END PGP SIGNATURE-----

Merge tag 'chrome-platform-v7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/chrome-platform/linux

Pull chrome platform updates from Tzung-Bi Shih:
 "New:
   - Add post_power_on_delay_ms for Hana in of_hw_prober

  Improvements:
   - Use dumb trackpad prober for Spherion in of_hw_prober

  Fixes:
   - Check bound of firmware-reported data in cros_ec_sensorhub and
     cros_ec_typec
   - Fix memory overread in cros_ec_sensorhub
   - Fix resource leak in cros_ec_debugfs
   - Clamp payload length for LIGHTBAR_CMD_SET_PROGRAM_EX in
     cros_ec_lightbar

  Cleanups:
   - Drop unused platform_device_id driver data
   - Remove redundant log"

* tag 'chrome-platform-v7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/chrome-platform/linux:
  platform/chrome: of_hw_prober: Add delay for hana trackpads
  platform/chrome: lightbar: Limit payload to max packet size
  platform/chrome: cros_ec_debugfs: Unregister panic notifier
  platform/chrome: cros_ec_debugfs: Clean up console log on probe failure
  platform/chrome: cros_ec: Remove redundant dev_err()
  platform/chrome: sensorhub: Fix dropped timestamp events and log spam
  platform/chrome: sensorhub: Fix memory overread in ring handler
  platform/chrome: cros_ec_typec: Reject out-of-bounds PD cap count
  platform/chrome: of_hw_prober: Use dumb trackpad prober for Spherion
  platform/chrome: Drop unused assignment of platform_device_id driver data
  platform/chrome: sensorhub: Bound the EC-reported sensor number
2026-08-19 08:27:06 -07:00
Jiri Kosina
d89f04ac41 Merge branch 'for-7.3/core' into for-linus
- fix long-standing force-feedback initialization race across the subsystem
  (Dmitry Torokhov)
- switch to system_dfl_wq (Marco Crivellari)
2026-08-19 09:27:26 +02:00
Jiri Kosina
db95550340 Merge branch 'for-7.3/amd-sfh' into for-linus
- support for tablet-mode switch for AMD SFH-based systems (Basavaraj Natikar)
2026-08-19 09:26:37 +02:00
Jiri Kosina
395c8fc5e5 Merge branch 'for-7.3/apple' into for-linus
- backlight fixes and improvements (Andre Eikmeyer)
2026-08-19 09:25:28 +02:00
Jiri Kosina
2b6e857455 Merge branch 'for-7.3/hyperx' into for-linus
- support for HyperX QuadCast 2 (Benjamin Blume)
2026-08-19 09:24:50 +02:00
Jiri Kosina
ea1a0889f9 Merge branch 'for-7.3/i2c-hid' into for-linus
- add support for devices that provide HID descriptor solely through ACPI _DSM
  method (XIE Zhibang)
2026-08-19 09:23:42 +02:00
Jiri Kosina
649203e69e Merge branch 'for-7.3/intel-thc-hid' into for-linus
- support for full I2C bus config parameters (Even Xu)
2026-08-19 09:23:04 +02:00