mirror of
https://github.com/torvalds/linux.git
synced 2026-10-05 02:39:02 +02:00
c4e941bb76
1482842 Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
c4e941bb76
|
landlock: Work around gcc-16 -Wuninitialized warning
gcc has a bug with -ftrivial-auto-var-init=pattern that produces a
warning for correct code that uses sparse bitfields:
security/landlock/fs.c: In function 'is_access_to_paths_allowed.isra':
security/landlock/fs.c:767:28: error: '_layer_masks_child1' is used uninitialized [-Werror=uninitialized]
767 | struct layer_masks _layer_masks_child1, _layer_masks_child2;
| ^~~~~~~~~~~~~~~~~~~
security/landlock/fs.c:767:28: note: '_layer_masks_child1' declared here
767 | struct layer_masks _layer_masks_child1, _layer_masks_child2;
| ^~~~~~~~~~~~~~~~~~~
security/landlock/fs.c: In function 'hook_unix_find':
security/landlock/fs.c:1649:28: error: 'layer_masks' is used uninitialized [-Werror=uninitialized]
1649 | struct layer_masks layer_masks;
| ^~~~~~~~~~~
security/landlock/fs.c:1649:28: note: 'layer_masks' declared here
1649 | struct layer_masks layer_masks;
| ^~~~~~~~~~~
To work around this, change the definition of struct layer_mask to
use an explictit padding field.
Link: https://gcc.gnu.org/bugzilla/show_bug.cgi?id=110743
Link: https://lore.kernel.org/all/20260619082133.3504146-1-arnd@kernel.org/
Fixes:
|
||
|
|
fd73f4a665 | Linux 7.3-rc3 | ||
|
|
22098763a1 |
tracing fixes for 7.3:
- Don't destroy user event fields when removal fails
User event fields are destroyed before the event is removed from
visibility. But that can fail leaving the still visible event with no
fields. Move the destroying of the fields to after the event is
successfully removed from visibility.
- Initialize function graph state is fork before calling copy_exec_state()
For non-CLONE_VM forks, copy_exec_state() allocates a new task_exec_state.
If that allocation fails, ftrace_graph_exit_task() will free the tasks
ret_stack pointer. Since that pointer is still using the parent's
ret_stack, it mistakenly frees the parent's pointer too.
Call ftrace_graph_init() on the task first which will NULL out the new
tasks's ret_stack and if the copy fails, it will not free anything.
- Remove FGRAPH_MAX_INDEX
The macro FGRAPH_MAX_INDEX was added but never used. Remove it.
- Save ent_size in function graph printing of nested functions
The function graph tracer needs to look at the next event to see if the
next event is the return of the current function entry. If it is, it
prints a single line:
ktime_get();
Otherwise it prints it like a nested function:
tick_nohz_irq_exit() {
ktime_get();
kcpustat_irq_exit();
}
In order to look at the next event, it must save the current event so that
it has the information to print from it. It saves the event in the
iterator descriptor called "ent". What it doesn't save is the ent_size of
the event which is now used to know if the function graph arguments are to
be printed. The peek doesn't save the size so the size used happens to be
that of the size of the last event that was seen.
Save the entry event size in the iterator descriptor so that the correct
size is used.
- Fix several errors with freeing data in the histogram code
The histogram code had a lot of leaked or or incorrect accounting when
failures happen. Correct them.
- Fix histogram regression of .percent and .graph modifiers
Up until 6.3 histogram values could have "percent" or "graph" modifiers
that changed how they were printed. But a change that added restricting
histograms values from being strings, stack traces and other modifiers
inadvertently prevented them from using the percent and graph modifiers,
which were legal use cases for values.
Put back the percent and graph modifiers.
- Fix various typos in the comments
- Set the trace_clock before initializing a histogram with clock argument
The histogram API allows the user to specific which trace clock to use via
a "clock=" string. The histogram is set up first before the clock is
checked. If the passed in clock is not valid, it exits without fully
fixing up the histogram leaving it on the list and a use-after-free can
trigger.
Update the clock argument first and if it fails then exit gracefully
before the histogram trigger is placed on any lists.
- Restore :mod: trailer after parsing in ftrace_set_clr_event
The function ftrace_set_clr_event() modifies the parse string and needs to
put it back to what was passed in. It searches for ":mod:" via a strsep()
but fails to put back the first ':' in the string.
Add back the ':' in the passed in string.
- Take trace_array reference when opening a tracer options file
The options files are dynamically created and some tracers add their own
options. When a tracer adds their own list of options, the trace_array
holding them has an array to hold the list of options for each tracer.
This array increases in size via a krealloc(), and the new entry gets a
newly allocated array to hold the options of the new tracer being added.
The element in each entry of the tracer's option array holds a pointer
back to the trace_array, a pointer to the tracer it is associated to, a
pointer to the flags of the option.
The issue is that these arrays are freed when the trace_array is freed
when its instance it represents is removed from the instances directory.
There's a race that an open of one of these options files can happen when
the instance is being removed.
Add a new helper function to be called by the open function of the options
file to iterate all existing trace_arrays under a lock and find the one
that has the given option element in one of it's tracer arrays. If found,
then update the associated trace_array's reference counter to keep it from
being freed. If not found, have the open call return -ENODEV.
- Disable interrupts when acquiring the lock in rb_wake_up_waiters()
The function rb_wake_up_waiters() assumes it will be called in interrupt
context and does not disable irqs when taking cpu_buffer->reader_lock,
which can be called in hard interrupt context. The issue is in PREEMPT_RT,
this function is called in thread context leaving this lock open to a
deadlock.
Take the lock with interrupts disabled.
- Use rcu_assign_pointer() for tmp_ops filter hash
The tmp_ops used in update_ftrace_direct_mod() assigns its filter_hash
field directly, but that field is annotated as __rcu and sparse complains.
Assign it with rcu_assign_pointer()
- Fix use-after-free in enable_trigger_private_data_free()
The trace_event_call is accessed through the event_trigger_data's
trace_event_file pointer to put the trace_event_call on freeing. The issue
is that the trace_event_file data may have been freed already causing a
use-after-free. Add a field to the event_trigger_data that points directly
to the trace_event_call so that it can decrement its reference directly
without needing to go through the trace_event_file.
- Fix accounting of buffer data remote headers
trace_buffer_desc_size() and trace_remote_alloc_buffer() undercount the
number of pages is needed for the asked for size as it doesn't take into
account the meta data on each page. Add a helper function to do the
calculation properly and use that in these functions.
- Catch nr_page_va overflow in ring_buffer_desc sizing
The number of pages per remote ring buffer is capped by
ring_buffer_desc::nr_page_va (32 bits). A buffer_size large enough to
overflow that field would silently allocate a descriptor smaller than what
was asked for.
- Do not resize the subbuf order if any per_cpu buffer is disabled
The mmapping of ring buffers disables resizing the subbuffers, but it is
done per-cpu whereas the subbuf size change is done for all the per_cpu
buffers under the buffer->mutex. It could change the size of some while
the mapping is happening on others. Have the resize of the subbuf order
check all the per_cpu buffers under the lock to see if any of them is
disabled before starting and causing an inconsistency between buffers that
are being mapped.
-----BEGIN PGP SIGNATURE-----
iIoEABYKADIWIQRRSw7ePDh/lE+zeZMp5XQQmuv6qgUCaqbdrBQccm9zdGVkdEBn
b29kbWlzLm9yZwAKCRAp5XQQmuv6qro9AQDF/j3VW3Uu98lVFI9AB10XYhLDd5nt
Zpf+3RviNgFpxgEAiE2+4K+4sM2SfaDDh9JMww9MKg1exL+cemE3a+JbBgY=
=jgYE
-----END PGP SIGNATURE-----
Merge tag 'trace-v7.3-rc2' of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace
Pull tracing fixes from Steven Rostedt:
- Don't destroy user event fields when removal fails
User event fields are destroyed before the event is removed from
visibility. But that can fail leaving the still visible event with no
fields. Move the destroying of the fields to after the event is
successfully removed from visibility.
- Initialize function graph state is fork before calling
copy_exec_state()
For non-CLONE_VM forks, copy_exec_state() allocates a new
task_exec_state. If that allocation fails, ftrace_graph_exit_task()
will free the tasks ret_stack pointer. Since that pointer is still
using the parent's ret_stack, it mistakenly frees the parent's
pointer too.
Call ftrace_graph_init() on the task first which will NULL out the
new tasks's ret_stack and if the copy fails, it will not free
anything.
- Remove FGRAPH_MAX_INDEX
The macro FGRAPH_MAX_INDEX was added but never used. Remove it.
- Save ent_size in function graph printing of nested functions
The function graph tracer needs to look at the next event to see if
the next event is the return of the current function entry. If it is,
it prints a single line:
ktime_get();
Otherwise it prints it like a nested function:
tick_nohz_irq_exit() {
ktime_get();
kcpustat_irq_exit();
}
In order to look at the next event, it must save the current event so
that it has the information to print from it. It saves the event in
the iterator descriptor called "ent". What it doesn't save is the
ent_size of the event which is now used to know if the function graph
arguments are to be printed. The peek doesn't save the size so the
size used happens to be that of the size of the last event that was
seen.
Save the entry event size in the iterator descriptor so that the
correct size is used.
- Fix several errors with freeing data in the histogram code
The histogram code had a lot of leaked or or incorrect accounting
when failures happen. Correct them.
- Fix histogram regression of .percent and .graph modifiers
Up until 6.3 histogram values could have "percent" or "graph"
modifiers that changed how they were printed. But a change that added
restricting histograms values from being strings, stack traces and
other modifiers inadvertently prevented them from using the percent
and graph modifiers, which were legal use cases for values.
Put back the percent and graph modifiers.
- Fix various typos in the comments
- Set the trace_clock before initializing a histogram with clock
argument
The histogram API allows the user to specific which trace clock to
use via a "clock=" string. The histogram is set up first before the
clock is checked. If the passed in clock is not valid, it exits
without fully fixing up the histogram leaving it on the list and a
use-after-free can trigger.
Update the clock argument first and if it fails then exit gracefully
before the histogram trigger is placed on any lists.
- Restore :mod: trailer after parsing in ftrace_set_clr_event
The function ftrace_set_clr_event() modifies the parse string and
needs to put it back to what was passed in. It searches for ":mod:"
via a strsep() but fails to put back the first ':' in the string.
Add back the ':' in the passed in string.
- Take trace_array reference when opening a tracer options file
The options files are dynamically created and some tracers add their
own options. When a tracer adds their own list of options, the
trace_array holding them has an array to hold the list of options for
each tracer. This array increases in size via a krealloc(), and the
new entry gets a newly allocated array to hold the options of the new
tracer being added.
The element in each entry of the tracer's option array holds a
pointer back to the trace_array, a pointer to the tracer it is
associated to, a pointer to the flags of the option.
The issue is that these arrays are freed when the trace_array is
freed when its instance it represents is removed from the instances
directory. There's a race that an open of one of these options files
can happen when the instance is being removed.
Add a new helper function to be called by the open function of the
options file to iterate all existing trace_arrays under a lock and
find the one that has the given option element in one of it's tracer
arrays. If found, then update the associated trace_array's reference
counter to keep it from being freed. If not found, have the open call
return -ENODEV.
- Disable interrupts when acquiring the lock in rb_wake_up_waiters()
The function rb_wake_up_waiters() assumes it will be called in
interrupt context and does not disable irqs when taking
cpu_buffer->reader_lock, which can be called in hard interrupt
context. The issue is in PREEMPT_RT, this function is called in
thread context leaving this lock open to a deadlock.
Take the lock with interrupts disabled.
- Use rcu_assign_pointer() for tmp_ops filter hash
The tmp_ops used in update_ftrace_direct_mod() assigns its
filter_hash field directly, but that field is annotated as __rcu and
sparse complains. Assign it with rcu_assign_pointer()
- Fix use-after-free in enable_trigger_private_data_free()
The trace_event_call is accessed through the event_trigger_data's
trace_event_file pointer to put the trace_event_call on freeing. The
issue is that the trace_event_file data may have been freed already
causing a use-after-free. Add a field to the event_trigger_data that
points directly to the trace_event_call so that it can decrement its
reference directly without needing to go through the
trace_event_file.
- Fix accounting of buffer data remote headers
trace_buffer_desc_size() and trace_remote_alloc_buffer() undercount
the number of pages is needed for the asked for size as it doesn't
take into account the meta data on each page. Add a helper function
to do the calculation properly and use that in these functions.
- Catch nr_page_va overflow in ring_buffer_desc sizing
The number of pages per remote ring buffer is capped by
ring_buffer_desc::nr_page_va (32 bits). A buffer_size large enough to
overflow that field would silently allocate a descriptor smaller than
what was asked for.
- Do not resize the subbuf order if any per_cpu buffer is disabled
The mmapping of ring buffers disables resizing the subbuffers, but it
is done per-cpu whereas the subbuf size change is done for all the
per_cpu buffers under the buffer->mutex. It could change the size of
some while the mapping is happening on others. Have the resize of the
subbuf order check all the per_cpu buffers under the lock to see if
any of them is disabled before starting and causing an inconsistency
between buffers that are being mapped.
* tag 'trace-v7.3-rc2' of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace: (25 commits)
ring-buffer: Check resize_disabled before publishing the new subbuf order
tracing/remotes: Catch nr_page_va overflow in ring_buffer_desc sizing
tracing/remotes: Account for ring buffer page header in size calculation
tracing: Don't dereference trace_event_file in deferred trigger free
ftrace: Use rcu_assign_pointer() for tmp_ops filter hash
ring-buffer: Acquire the lock with irqsave in rb_wake_up_waiters()
tracing: Take trace_array reference when opening a tracer options file
tracing: Fix ring_buffer_read_page_size() kernel-doc
tracing: Restore :mod: trailer after parsing in ftrace_set_clr_event()
tracing: Fix memory corruption from a "STACKTRACE" histogram key
tracing: Fix memory corruption from the histogram stacktrace modifier
tracing: Undo the registration when enabling the histogram trigger fails
tracing: Take the reference before publishing the named histogram trigger
tracing: Set the trace clock before registering the histogram trigger
tracing: Fix typo "preceeded" in comment
tracing: Fix typo "availabe" in comment
tracing: Let histogram values keep the percent and graph modifiers
tracing: Keep the entry count when the histogram stats allocation fails
tracing: Free histogram the field rejected for a bad modifier
tracing: Free histogram the var ref when its initialization fails
...
|
||
|
|
d681d7ef61 |
Merge misc regression fixes that seem to have fallen through the cracks
Thorsten continues to track regressions, and reporting on known issues with fixes that don't seem to make any progress. I'm going to do an rc3 release later today - let's not keep these known issues pending for yet another rc for no obvious reason. Reported-by: Thorsten Leemhuis <regressions@leemhuis.info> Link: https://lore.kernel.org/all/46403cf8-9a81-4596-87eb-dde58ae4c5db@leemhuis.info/ * regressions: media: ipu-bridge: do not use the CVS device lookup for IVSC wifi: mt76: mt792x: fix NULL dereference in ACPI SAR init during probe wifi: mt76: mt7921: skip unknown CLC firmware records |
||
|
|
856c562c94 |
media: ipu-bridge: do not use the CVS device lookup for IVSC
Since commit |
||
|
|
7825de3f75 |
wifi: mt76: mt792x: fix NULL dereference in ACPI SAR init during probe
Some laptops carry a MediaTek power table in their firmware, and the driver reads it to set a transmit limit for each frequency range. It only fills in the ranges themselves when it registers the device. The startup step that does this existed already, but it never programmed anything. Two recent commits made it run a regulatory update instead, which sets the limits on the way through, long before registration. As a result, on a machine that has the table the driver reads through an empty pointer and the interface never appears: BUG: kernel NULL pointer dereference, address: 0000000000000004 RIP: 0010:mt792x_init_acpi_sar_power Call Trace: mt7921_set_tx_sar_pwr mt7921_mcu_regd_update mt7921_regd_update mt7921_run_firmware mt7921e_mcu_init mt7921_init_work Skip it when the ranges are missing. They are applied again once the device is up, which is where they came from before. Reported-by: Klara Modin <klarasmodin@gmail.com> Closes: https://lore.kernel.org/linux-wireless/aoyxqHYvSuaBeubf@soda.int.kasm.eu/ Fixes: |
||
|
|
1a296bfd3e |
wifi: mt76: mt7921: skip unknown CLC firmware records
Treat an out-of-range CLC index as newer firmware rather than a
malformed image. linux-firmware 20260810 ships MT7922 records with
idx 3, and rejecting them made mt7921e fail to probe.
Keep the record-length checks, and report those as errors so a
truncated table is visible instead of a silent retry loop.
Fixes:
|
||
|
|
d860c67c05 |
ring-buffer: Check resize_disabled before publishing the new subbuf order
ring_buffer_subbuf_order_set() stores the new order and only then walks
the CPUs, returning -EBUSY if any of them has resizing disabled. A user
mapped buffer has resizing disabled, and __rb_map_vma() reads
buffer->subbuf_order without buffer->mutex, so an mmap of an already
mapped CPU racing the failing order change sizes the mapping with the
new order and inserts pages past the sub-buffer into the VMA.
Check the CPUs before storing the new order.
Cc: stable@vger.kernel.org
Fixes:
|
||
|
|
d059d8bf2c |
tracing/remotes: Catch nr_page_va overflow in ring_buffer_desc sizing
The number of pages per remote ring buffer is capped by
ring_buffer_desc::nr_page_va (32 bits). A buffer_size large enough to
overflow that field would silently allocate a descriptor smaller than
what was asked for.
Return SIZE_MAX from trace_buffer_desc_size() on nr_page_va overflow.
Link: https://patch.msgid.link/20260911193937.602202-3-vdonnefort@google.com
Fixes:
|
||
|
|
442ffa742d |
tracing/remotes: Account for ring buffer page header in size calculation
trace_buffer_desc_size() and trace_remote_alloc_buffer() undercount the
required pages because every ring buffer page contains a header
(BUF_PAGE_HDR_SIZE). Account for that header to ensure allocated remote
ring buffers aren't smaller than requested by the user.
The newly introduced helper __calc_nr_pages_ring_buffer_desc() can
return a value that overflows the descriptor nr_pages field (32 bits).
Link: https://patch.msgid.link/20260911193937.602202-2-vdonnefort@google.com
Fixes:
|
||
|
|
180534c09b |
Rust fixes for v7.3 (2nd)
Toolchain and infrastructure:
- Work around a 'bindgen' 0.73.2 bug that emits an 'allow' attribute
for 'unnecessary_transmutes', which is unknown in older compilers.
- Clean 'clippy::as_underscore' lints in generated code by the new
'bindgen' 0.73.0+ releases.
- Clean new 'clippy::needless_range_loop' lint for the upcoming Rust
1.100.0 (expected 2026-11-12).
'kernel' crate:
- 'num' module: fix soundness issue in 'Bounded' by sealing the
'Integer' trait.
'pin-init' crate:
- Fix unreachable warning for the upcoming Rust 1.100.0 (expected
2026-11-12) due to 'Infallible' becoming an alias of '!'.
Samples:
- Add missing newlines in 'pr_*!'s macro calls.
-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEEPjU5OPd5QIZ9jqqOGXyLc2htIW0FAmqmuA8ACgkQGXyLc2ht
IW0ZVRAAk75N61v8xzY5dsQjA0O0ivCxDBqrPnFYYOq9jWWwKR4XF8zfX7dxPzFG
48NHlQ9s3XEOSfmoVdaab9DMz8l2gCLMcCUOqmEGZtf1ORlFqCn7m0OMXfsidgx9
YIWYSAySpjaQ27bg8+uvbBlBmD2KaE6zBlrAKbvdC9dJBOMfLjEnT3wtzkRkROzo
WJMyx+OjIk0kmFNMUPBV/J+VWyxP5IAl8C5xK/hl3L+tf0VeQWkn82f7zzoGfwRV
xLuIybzlxF2QK6D8OSf+SpxIqgl1fCDxh2rzWyNBJKbdGn1fMTTY7Ci6rM2DK853
PjmQWtlkrYIOnO7k2qdCebOOv8wOBKE1hNpK+23mkEUbsZjWPNgSHVuf6X098NuH
GEk5okH6+1e2w80dSRfUjKPY2omYhNoq4/4KEC+0IcV3xV+9FLq1uo9K/eOEr0Cf
z430H31YnollXCWUx56QJZ7p3r0dITwhKHPE9pfKB53yWZelTEboRuD1zRKYEO4E
0f+bDuLOAJeCzSX66YteZ+DiWphNB4OX49TGKRJpo9gWKn6+29TKIbJjAuk/oAu9
FVkE5//WAu8El5++1W0YE4AM5eVvhrarH4vo6q44o6bd3acNHHJDzwUR8fu3FSYA
skFb9vcRAq6vUPlzotlQMbuCP1PfBuFIhJdfqDcsVzGJO8oQPuk=
=/75K
-----END PGP SIGNATURE-----
Merge tag 'rust-fixes-7.3-2' of git://git.kernel.org/pub/scm/linux/kernel/git/ojeda/linux
Pull Rust fixes from Miguel Ojeda:
"Toolchain and infrastructure:
- Work around a 'bindgen' 0.73.2 bug that emits an 'allow' attribute
for 'unnecessary_transmutes', which is unknown in older compilers
- Clean 'clippy::as_underscore' lints in generated code by the new
'bindgen' 0.73.0+ releases
- Clean new 'clippy::needless_range_loop' lint for the upcoming Rust
1.100.0 (expected 2026-11-12)
'kernel' crate:
- 'num' module: fix soundness issue in 'Bounded' by sealing the
'Integer' trait
'pin-init' crate:
- Fix unreachable warning for the upcoming Rust 1.100.0 (expected
2026-11-12) due to 'Infallible' becoming an alias of '!'
Samples:
- Add missing newlines in 'pr_*!'s macro calls"
* tag 'rust-fixes-7.3-2' of git://git.kernel.org/pub/scm/linux/kernel/git/ojeda/linux:
rust: allow `unknown_lints` in generated bindings for Rust < 1.88
rust: allow `clippy::as_underscore` in the generated bindings
rust: num: seal Integer
drm/panic: clean new `clippy::needless_range_loop` lint for Rust 1.100.0
rust: samples: add missing newlines in rust_print_main
rust: pin-init: use irrefutable pattern for `stack_pin_init`
|
||
|
|
6a0b3fb48d |
Bootconfig fixes for v7.3-rc3
- bootconfig: Fix integer overflow and truncation vulnerabilities in size checks
. tools/bootconfig: Fix integer overflow and truncation in size checks.
Fix size check bypasses caused by integer overflow and truncation
when parsing initrd or standalone bootconfig files, preventing
buffer overflow and out-of-bounds writes in the userspace tool.
. bootconfig: Fix integer overflow in initrd size check.
Fix pointer arithmetic wrap-around in get_boot_config_from_initrd()
when handling crafted huge size values, preventing fatal kernel
page faults during early boot.
-----BEGIN PGP SIGNATURE-----
iQFPBAABCgA5FiEEh7BulGwFlgAOi5DV2/sHvwUrPxsFAmqml0UbHG1hc2FtaS5o
aXJhbWF0c3VAZ21haWwuY29tAAoJENv7B78FKz8bXecH/jH1wLtkeeDumrR+5OGn
hbLnTDryprnhXBP7gKmYfcVRJzF9HZ1Ro12R8ea4N/NJieUi+EDQQ/yn6TdIpV3z
AU4In+zKT/q2hF3R1rmYuYxEMo9Po+dxgoB3BxKdwh9aDz8kPxQGP2/0Q/vjVMvZ
5YosoEGYtNW6NpovVK+nMkYY0TwGXtft3tdGvbdMFToGf73EgeDA7POgdCXYgiP2
D6equcjf7mRyBxzApCXzEEBynmHI6JTbZ6w0HGWN2bU9iwk/a/jiSBGGFrWopar6
YhQdySy7mmyHZaQUOiz6M6kYvmF0PaLsiA0NMmZ6B3uKPv+wc7OShSoiknGRgBJc
Vc4=
=TCCT
-----END PGP SIGNATURE-----
Merge tag 'bootconfig-fixes-v7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace
Pull bootconfig fixes from Masami Hiramatsu:
"Fix integer overflow and truncation in size checks.
- Fix size check bypasses caused by integer overflow and truncation
when parsing initrd or standalone bootconfig files, preventing
buffer overflow and out-of-bounds writes in the userspace tool.
- Fix pointer arithmetic wrap-around in get_boot_config_from_initrd()
when handling crafted huge size values, preventing fatal kernel
page faults during early boot"
* tag 'bootconfig-fixes-v7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace:
bootconfig: Fix integer overflow in initrd size check
tools/bootconfig: Fix integer overflow and truncation in size checks
|
||
|
|
c874ace034 |
Misc timer fixes:
- Fix clockevents replacement race when a broadcast
device is replaced which may trigger a BUG() crash
(朱恺乾 - Zhu Kaiqian)
- Fix potential timerqueue ordering bug when rearming
a queued timer with nonzero slack (Andrea Parri)
Signed-off-by: Ingo Molnar <mingo@kernel.org>
-----BEGIN PGP SIGNATURE-----
iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqmXaERHG1pbmdvQGtl
cm5lbC5vcmcACgkQEnMQ0APhK1jM9RAAnEShNuh27uYj3oxVgaLo+Dhsk1AYzNnr
WVS/Cz8HfFXMEVnOsT3CibcB6p5wydTHms/8248GZWWUuM1HtL/7zcUHWGFgs72S
WRTcw/ouzvdAKQfxlH2j96uApMWwnWnv9XRfpFel9bgIIK1POL9g0JJmcuFK5uNf
5aYvzkdLv3SKHR0BnrIF4a6jqq1Shf2sZPDXHmJDE/k/He28zvFjiOlIEChxfCfh
qUEzY036hSU0RbAONSbn88bj7dc10/Xuck/iW3WVW8cOqtVxw79biAoumUe9jqwE
hX3B6rvDEPvaEOPDm2PgUlrapFukjfImu7K9rDljbFMX1jF6eb7ZQMk4ftJXL+rM
M0RPCdrS2ZrVOKt3VFIYRH7ZzFNwtE+RHPZSD6lpVgia6xpgi6yY++AzTeCn+VpK
3AmkxMg3xHOLkISyCRUlmtTn3Cis6O7+9+9dEad24dh5mkQM7Tr6nzprYeg3fgpR
z714UKjOUvBNBtxCjdZl5/c/i8mb0IaH4DmT+/V6mIXWoHchbqgw0Or7G7XMm5XM
M1J+4RJrGhhg1eUTb254PWi/OixuXZ8XgcB1wwAiJFMTJY9YqBExKRAdZ+Al1DJP
FgHDEPyvElpeh5XFFqf8Ft9xXOTn1CSEc6G+dCO0MswcikHnw4UnmLGn9z3js2AS
SRlK75Dm49s=
=SyXt
-----END PGP SIGNATURE-----
Merge tag 'timers-urgent-2026-09-13' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
Pull timer fixes from Ingo Molnar:
- Fix clockevents replacement race when a broadcast
device is replaced which may trigger a BUG() crash
(朱恺乾 - Zhu Kaiqian)
- Fix potential timerqueue ordering bug when rearming
a queued timer with nonzero slack (Andrea Parri)
* tag 'timers-urgent-2026-09-13' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
hrtimer: Use hard expiry when updating timers on the same base
tick/broadcast: Plug clockevents replacement race
|
||
|
|
b2a8a7669e |
Miscellaneous scheduler fixes:
- Fix EEVDF se->max_slice value on enqueueing (Vincent Guittot)
- Fix EEVDF augmented rb-trees re-balancing with
multiple fields (Vincent Guittot)
- In proxy scheduling, account cgroup CPU time to the execution
context, not the scheduling context (Hui Su)
- Likewise, call wq_worker_tick() for the execution context,
not the scheduling context (Hui Su)
Signed-off-by: Ingo Molnar <mingo@kernel.org>
-----BEGIN PGP SIGNATURE-----
iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqmXEMRHG1pbmdvQGtl
cm5lbC5vcmcACgkQEnMQ0APhK1hchg/6A1gRkn7T5+K957U8wpB9vjtV9cKVdWpI
XFDGm60ylFUmU388Xb8mmrbDgmej6RpX6C4ccppygM3196w513tB+Zr8w6jbSszk
ddgWwfwi58FFBJZTH7JDqeJ64wvrl8KId44yM6k2JdXATxh2DGF0w+YdsA+M5HVJ
EJbjACYhePdK27wvQDtj1poDfAyiabqEnv7w62dhEU9I+ikmcPAyrhmqU0yFDNUR
sNozsDQnEJrHtllGHpr3FVxYRqob6lOtG+86VSiZ8F6i2kA3p/451mpMyyCOMUrF
kZlBIryLG0gylXIensqLox+z2ZIE4nUL0OX3o7mC+MLNERdWvsdgHi9AcZlIoFpJ
wMPBLENnnGbilmwhXjk0pL655rlVVUGwaTV4T9Pk5D5qew6B9LGe8uqiLo8U/qih
1o5Lf3ZnUi0o8XHMfNkwQ3Y0m1S7CbgJYKItE+ec+2QifmKGD5dOKo5WWDKszywF
Zb9ScP2fMKideS/JEX1/+jvLcpDmV+HE3mC58Muek96fbJG1IQ4bL5tu+fqO85rM
68dJymtMrkoeegmq4jqERt758sZnyv2QbDmr1Kc1G9vSKNAeahYldPU2gQ6qFBnO
VCMvI2BUmfiia9A6NBKKgpjijc4zWydyuaQ2zdvEBddYnLWKZ5Ge26lLrjraNtdB
GtHalAP1gVs=
=zJHp
-----END PGP SIGNATURE-----
Merge tag 'sched-urgent-2026-09-13' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
Pull scheduler fixes from Ingo Molnar:
- Fix EEVDF se->max_slice value on enqueueing (Vincent Guittot)
- Fix EEVDF augmented rb-trees re-balancing with multiple
fields (Vincent Guittot)
- In proxy scheduling, account cgroup CPU time to the execution
context, not the scheduling context (Hui Su)
- Likewise, call wq_worker_tick() for the execution context,
not the scheduling context (Hui Su)
* tag 'sched-urgent-2026-09-13' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
sched/core: Call wq_worker_tick() for the execution context
sched: Account cgroup CPU time to the execution context
sched/eevdf: Fix rb augmented with multi fields
sched/eevdf: Fix augmented max_slice
|
||
|
|
85855f85de |
Miscellaneous perf events fixes:
- Fix sched_cb_list corruption on PMU callbacks that
invoke list_del() during perf_event_overflow()
calls (Thomas Richter)
- Fix PEBS pt_regs->flags snapshot data that was
regressed with the introduction of adaptive
PEBS v4 support (Dapeng Mi)
- Fix possible drain_pebs() re-entry bug
when intel_pmu_drain_pebs_buffer() is called from
process context (Dapeng Mi)
Signed-off-by: Ingo Molnar <mingo@kernel.org>
-----BEGIN PGP SIGNATURE-----
iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqmWoURHG1pbmdvQGtl
cm5lbC5vcmcACgkQEnMQ0APhK1hzhA//TBu2jx/c2r5tafuW5mpPJH+3eGcMWUh9
KfVLt/FMzgt+sOtzM/eIQ2Sk4VAachTkSLjh6MQR1m9g4jXTVr5rH8lJlFXqW/74
v5XhaEryXTSOn6zpxXpKrVGYFq6RfdTijtmrAK+7ac6HChgRrMa0Eb5yVvPauLXE
+Y0RugHjF75c4iXapb68osWF+7EoVKGqLPZjdQ12D6wga7+1DRTZWV37hOXHtu1M
GbajBMTKF5Q4QCffsyY9PDks86dKLDrv8z7XxGNYz4pdcnwD4bMdYfu8FxohowaO
EXx9b0dxK1RobcsMo+wHZojTD0i4ySSIbN7lJU6dHopMFJ3nKgCDYuPvzov9T/Dm
8eFrzlQbr0m9+NqndFomjv4so1WGF1Q2DHqEOJQgSeHNECpUAx7mzIzv/AJiJm1P
AC3S8PJT5+AFQZtySqV6nI8UyzyMgoDo3EYdp3oKHq/B6SGDlAUHr3k8e5bpI8ss
JbIvyo1RH6DrB+FstHHve7zn5ueYmjxPQRS8NdIRrBKAeMryC7DYEDU7ZUwkAJS9
jJZE7wM0zhLbF5EPVEA3+rhrh1wZ0mUFsWJwWbn7QwIpSm331J8AEKdpKFa3k5op
FH9PusGL/SKeVwo1nReExLJWghdlxhbHAC8QhLMHTKOrhoqoUzpp5hRQ9rgx5z7N
hksCg2xZC+U=
=mKBo
-----END PGP SIGNATURE-----
Merge tag 'perf-urgent-2026-09-13' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
Pull perf events fixes from Ingo Molnar
- Fix sched_cb_list corruption on PMU callbacks that
invoke list_del() during perf_event_overflow()
calls (Thomas Richter)
- Fix PEBS pt_regs->flags snapshot data that
regressed with the introduction of adaptive
PEBS v4 support (Dapeng Mi)
- Fix possible drain_pebs() re-entry bug when
intel_pmu_drain_pebs_buffer() is called from
process context (Dapeng Mi)
* tag 'perf-urgent-2026-09-13' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
perf/x86/intel: Prevent drain_pebs() reentry
perf/x86/intel: Correct pt_regs->flags update for PEBS path
perf/core: Allow list_del during perf_event_overflow()
|
||
|
|
feb66eea6b |
Fix misc objtool bugs:
- Fix potential klp-build allocation leak in
cleanup functionality handling kzalloc() failure
(Yafang Shao)
- Fix KLP checksum false positives triggering with
GCC, caused by quirks in string literal symbol
generation (Josh Poimboeuf)
Signed-off-by: Ingo Molnar <mingo@kernel.org>
-----BEGIN PGP SIGNATURE-----
iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqmWJIRHG1pbmdvQGtl
cm5lbC5vcmcACgkQEnMQ0APhK1hGRA//fpBKxCoMv13E2ZLyzwWgz8nGkApXCmyg
+cmmWM8uhNHfH9dA5d7Ipp6ziQcsob0cJ9QM48VM+PdJ1b46Dh41WPb7z9IA+kjG
smV9wnH4dnfXqtFEUbGpzVc9GVv5tP5ZATqZe05rwlbgk8jQpbsr2EhoyAHShg7J
Nqw0CmqFhnP3lKGjhU31UkwusFtI0F/m/tTlwT6n/EumpAPgcdiLo7d4I7Mx9d1g
R0xwNy5OJGUci9bxYU97T6p5aRc4Kkq3XwNHyZcpJNoVjsXphYxSc2Rf/V4QPCTJ
p8weOOBevYk/fScbq7v1LbflUTUvyjh25CQDwz0VUrSxXHrsAKCAiS60D3Fhate+
lLtNnRDxCYDlNW50+sB0ch8WhhHpEqKBpnAdkdI4SUIQbAruvSO2s3Ygrs/JIirw
CoXTzN5yFvSxGw/7DrTDhtrqwGRlCKYvAridbd12tEXGlkOaDB1KZnsazlhqdv1j
1DjnP7SJu+mzDoBJXwz2Fw3TRWzwqx5w9leAFPjm/AaWWqFo/HvspJEKhh4RfhS9
Ulb7wO4ftV6R0hdUS6Q48vSZdGr2Mu3U3cLku051kpdXNCZ4z+2liz9vhZgTx9JP
8X6wMn7kUmg7jc3PR3p0i4Hgar6VYlddJ0BKrSzz5lghi2sA6HDhaB6I9gl7iafj
/fJd8EjglqQ=
=g7d3
-----END PGP SIGNATURE-----
Merge tag 'objtool-urgent-2026-09-13' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
Pull objtool fixes from Ingo Molnar:
- Fix potential klp-build allocation leak in cleanup
functionality handling kzalloc() failure (Yafang Shao)
- Fix KLP checksum false positives triggering with GCC, caused
by quirks in string literal symbol generation (Josh Poimboeuf)
* tag 'objtool-urgent-2026-09-13' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
objtool/klp: Fix checksums for constant pool references
klp-build: Fix wrong index in funcs cleanup error path
|
||
|
|
f10ae89f3d |
- Fix ARM gic-v5 irqchip driver regression, where its
enable/disable functions may corrupt unrelated
ICC_CR0_EL1 hardware state (Sascha Bischoff)
Signed-off-by: Ingo Molnar <mingo@kernel.org>
-----BEGIN PGP SIGNATURE-----
iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqmVqMRHG1pbmdvQGtl
cm5lbC5vcmcACgkQEnMQ0APhK1iHxA/+JPy8xMVQzoWDkMIAkm8GyuC8xWRoF+OC
thsCWv/KZAiysjuttpG6nyJrATt+2qP5AnmmNDKZaX5qofwU4bKjw0tt6MqIvtVo
l1quxcNafpLBlw27EqaePp56McMMext609E9PUkU/fVlwewvfT34ABnIYOJnRSei
0ZyovAmGU3jGdExXGSvDyUkoK6FuyL5R8/ugKTXs+6nRypj9eJuX8ZO0G8/FsZF+
OCbM21959/wI9imSjbbVeUINILjMv6+KMbNCh2x+8rSoOMOa0uuL7jvfmK2y8a0m
/N9mTDSZiaFCddzubx5r1lHsFs4DUtrT8ScKl0M7p/HQVYEWXtlA9rkE89BcJPk/
ibHbY6sIjyGnLfKlBiKjLzxkoYvMN7qJ76PI6bDU8ic/3i2FMnULR5URzKYsYaof
I8m3BHUTFvcjkkr+tAM6/OEsVZqVXtenJe8PduPVrxJ6OUOorvlEORV2Wuzf1qHA
DpJb49+PbElBeCBsDo7GNGKUOrp83sYaJJwUcJOeHZSGi6LyVHgklEK+2uxGHTpF
jtkAoCrjJPO6HKZloUQCrVAAXWTwImb/j/WD1pt3tz0ymHtTKJgkj5FtklXL2oID
wkydja+7UbSU+4R2/NQo8RG7m2IXERqcMEaFZoFvASeAe2UGNfxfQJ2jHE1Ugif1
JFsJv/KTLS4=
=sj7n
-----END PGP SIGNATURE-----
Merge tag 'irq-urgent-2026-09-13' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
Pull irq fix from Ingo Molnar:
- Fix ARM gic-v5 irqchip driver regression, where its
enable/disable functions may corrupt unrelated
ICC_CR0_EL1 hardware state (Sascha Bischoff)
* tag 'irq-urgent-2026-09-13' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
irqchip/gic-v5: Preserve ICC_CR0_EL1 state
|
||
|
|
086fd27ee9 |
- Fix generic entry code cross-build failure on
!CONFIG_AUDITSYSCALL kernels using older
RISCV64 and S390 cross-compilers (Thomas Gleixner)
Signed-off-by: Ingo Molnar <mingo@kernel.org>
-----BEGIN PGP SIGNATURE-----
iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmqmVHsRHG1pbmdvQGtl
cm5lbC5vcmcACgkQEnMQ0APhK1iBhRAAhhh0vf2NMI+BmGiXJ6EQa924gHpMcIUl
nFqAWdQxa2g+seIP/mDJnFabdXEBAj/IRuen4QQ/Q0CqtX9PMAVFL5C5H4Co/ge6
cO6Z/0cCfFoiP1IVMnjGqIr0vrS/e+x+qxI9UjVqGDqDonWeZCZjULq5tXMgcBtB
pFNSwPcvB/5odIbtM2lCCcdT0zT79y+EWVBPusb/7Cr5X6LwpyjMiRtMIN5mB/OR
ZNkdk8016kMEeU9AYRyQ5fJeM1RshYlzbK4ENejoHID2qyZHq+6piD97F3tfyIQo
3rIehne6iHr1MRvIoKpyEhWKZEsH/ZLpdbYIhKOhz+E0ONRuz484XAoha/Usk4Y/
bXf2deqCWi6HY4CDxhnB6FaA0tLTx6a1zl2G7WicSzjGTN0IvAZABy7IkntOHp31
4f4TCHNSBOQyNd+xlX2+unlJzZrYdeg3R2izWyfJHKqhVJVTVZ/0K1s4afu4Ex9h
yv9DSzWdfP4aOS5o0LiHRQMCaEBgPTLzerRnyvDbmoS8KUOdkEmOHqydIUymHesJ
Pd8VTqKprbXpYKK41tuSkbyh+9TNu2sq4U9FPVNn4QyLbEKTfWI6pO8esOH6OceN
90pFj1pnNFQIaEvu5PqAXC0IS6eFSoK8c09fSliHCAaCe4KlgrMzjRDCuwzh4+Lg
jmetvmY1STw=
=z8y5
-----END PGP SIGNATURE-----
Merge tag 'core-urgent-2026-09-13' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
Pull entry code fix from Ingo Molnar:
- Fix generic entry code cross-build failure on
!CONFIG_AUDITSYSCALL kernels using older
RISCV64 and S390 cross-compilers (Thomas Gleixner)
* tag 'core-urgent-2026-09-13' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
entry: Guard syscall_enter_audit() invocation with CONFIG_AUDITSYSCALL
|
||
|
|
ff4b61e3b7 |
- A single fix to altera_edac to use the proper objects when performing
managed device operations instead of using temporary shallow struct copies which can cause dangling list pointers and havoc eventually -----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEEzv7L6UO9uDPlPSfHEsHwGGHeVUoFAmql7LQACgkQEsHwGGHe VUqEWRAAnNFX6gIKn3s5yiAs389zNNZjbvWkEVqKNLS73jhMyPNS3WjcQc+BM3NY ZCvc880ulbiSmCdK6dcd/RsepAdIvHVaz4dH8RrdiKHUxjMFH8VEAZsrb+eghD4A npDK65UrQJujXaIhAU5K5wRVjlmIsVlcxC7qUl882rMZSluMiuQpwJHpNTPccsXU 18SsEA9r2LQSDXEq4+QoAwjW5c2FZcpaPh/P00diqm33dX73wC99Q2DY2z6V5bo1 74XEOm4ClbvpGt6D7avslo2sGzBplV1HUxR67S6Zu5ixwUQ6k9cHe991gR67H9eO 993NppbAOlMXqv5evJpks3MSLcNao61lRH1AQulzXUTLXJMODHFy4a+yyG6HE87i qUXgBRKuTodYBNz/PEmY5NhWm+ehVevVxfsx5eXaIdOPMUrpiK7Lz6HcwzMScO+w jBjWUlqp0WhPuM0uCAfiBO5ltIuy5hyMJIsfmp1VgTUKYkxm+BN/sKanwLQVqBJx 6jL6cfOFL2BVMjS6YBvdRXUDjjlbVb4YjkUZhus9JyIKiOKCllO9WuNxwtutm7Cc +k3ygxbH/1CkJTotCplgTZjg4TdsFOQPtWeIB+jkxHgAFpiJctFjaH7ayWQ/wn6e M79hUVnX3Cy34zAR2oAbH65u1tUeKkic1DY5oWz5Rf2v9I5VtBw= =rNxL -----END PGP SIGNATURE----- Merge tag 'edac_urgent_for_v7.3_rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/ras/ras Pull EDAC fix from Borislav Petkov: - A single fix to altera_edac to use the proper objects when performing managed device operations instead of using temporary shallow struct copies which can cause dangling list pointers and havoc eventually * tag 'edac_urgent_for_v7.3_rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/ras/ras: EDAC/altera: Use parent device for devres in altr_portb_setup() |
||
|
|
2f0c1cf72f |
s390 updates for 7.3-rc3
- Fix NULL pointer dereferences in s390dbf when setting debug levels or resizing debug areas while logging events. Remove duplicate messages about kernel parameter overrides - Fix PAI perf crashes when per task events move to newly onlined CPUs. Add CPU hotplug callbacks to allocate and free the per-CPU data - Fix mutex use in atomic context in AES and PAES CTR code by using semaphore trylocks instead. Remove conditional locking and enable Clang CONTEXT_ANALYSIS for the crypto code - Fix scatterlist walk error handling in AES and PAES and avoid freeing PAES walk resources twice - Fix missing scrubbing of temporary AES and PAES buffers, including AES GCM error paths - Set missing CRYPTO_ALG_ASYNC and CRYPTO_ALG_NO_FALLBACK flags for PAES - Fix -EBUSY handling in PAES and PHMAC to avoid cleaning up requests already queued to the crypto engine - Fix PAES and PHMAC requests being completed twice on errors - Fix PAES and PHMAC hangs when key conversion keeps returning -EBUSY by returning -EIO after the last retry -----BEGIN PGP SIGNATURE----- iQEzBAABCgAdFiEE3QHqV+H2a8xAv27vjYWKoQLXFBgFAmqlzRcACgkQjYWKoQLX FBg65gf9H1AoBZnwcgcjhGzJL93sqj8nm9BRquCIdHi85FxypAYFX4nM8o7ESUWj HaIuleZA6OncKWBdHSEkBOj8fak+6RixjK7j1chUXzg0+J/bmTSWWE3j9zw8ZWUj TGY7yuvDtZ/XRefO3yxirh9Nr7OyS98FH7rxcwnlmKYz6AKQmLayLrMfw+E6BP+a Juw1aWPHRMvd+9JqakqzTOIfJNmNz34HT3yL0phqiHojU5mNsgGPUPjlD6jNkFCf 6TdRVcnkHMuhTEx/HD+/8nHTlYDVFJkLbpe9WYk94ubVY6kLaLxuBWE1ycCk7bv8 GOQygNWL5mZpL5c0MTtlm49ybIELuw== =cYX9 -----END PGP SIGNATURE----- Merge tag 's390-7.3-3' of git://git.kernel.org/pub/scm/linux/kernel/git/s390/linux Pull s390 fixes from Vasily Gorbik: - Fix NULL pointer dereferences in s390dbf when setting debug levels or resizing debug areas while logging events. Remove duplicate messages about kernel parameter overrides - Fix PAI perf crashes when per task events move to newly onlined CPUs. Add CPU hotplug callbacks to allocate and free the per-CPU data - Fix mutex use in atomic context in AES and PAES CTR code by using semaphore trylocks instead. Remove conditional locking and enable Clang CONTEXT_ANALYSIS for the crypto code - Fix scatterlist walk error handling in AES and PAES and avoid freeing PAES walk resources twice - Fix missing scrubbing of temporary AES and PAES buffers, including AES GCM error paths - Set missing CRYPTO_ALG_ASYNC and CRYPTO_ALG_NO_FALLBACK flags for PAES - Fix -EBUSY handling in PAES and PHMAC to avoid cleaning up requests already queued to the crypto engine - Fix PAES and PHMAC requests being completed twice on errors - Fix PAES and PHMAC hangs when key conversion keeps returning -EBUSY by returning -EIO after the last retry * tag 's390-7.3-3' of git://git.kernel.org/pub/scm/linux/kernel/git/s390/linux: s390/crypto: Enable CONTEXT_ANALYSIS s390/crypto: Map EBUSY to EIO when key conversion fails repeatedly s390/crypto: Fix wrong return code to engine in asynch callbacks s390/crypto: Fix handling of EBUSY in PHMAC when req is pushed to crypto engine s390/crypto: Fix handling of EBUSY in PAES when req is pushed to crypto engine s390/crypto: Fix missing cra_flags in paes_s390 s390/crypto: Fix use of mutex in atomic context in PAES s390/crypto: Fix missing scrub of temp buffers with PAES algorithm s390/crypto: Fix return code handling at skcipher_walk_done in PAES algorithms s390/crypto: Fix use of mutex in atomic context s390/crypto: Fix missing scrub of temp buffers with AES ctr and gcm algorithm s390/crypto: Fix skcipher_walk return code handling in aes_s390 s390/debug: Fix race between debug area resize and event logging s390/debug: Do not repeat parameter override notice on debug_set_level() s390/debug: Fix NULL pointer dereference in debug_set_level() s390/pai: Support CPU hotplug for PMU PAI s390/pai: Move locking to event init and delete s390/pai: Use PAI PMU index as parameter replacing event |
||
|
|
3ce99a68f7 |
First round of Kbuild fixes for 7.3
- kbuild: don't delete in-flight filechk temporaries in asm-headers
A rule for generating header files was changed from using make
$(wildcard) fnglob to 'find' instead; as 'find' finds "hidden" files
by default, temporary files from Kbuild's 'filechk', used for
generating asm header files, may get deleted and break header file
generating.
- scripts/sorttable: Mark long_size as __maybe_unused
Fix builds with clang-23 or newer on trees w/o commit
|
||
|
|
59351365ac
|
scripts/mksysmap: fix escape of '$' in the __pi_ pattern
Commit |
||
|
|
281b61d408
|
scripts/mksysmap: drop the MODULE_INFO() symbols from kallsyms
Commit |
||
|
|
4f73462856
|
scripts/sorttable: Mark long_size as __maybe_unused
When building in a kernel tree prior to commit
|
||
|
|
06bb43d8c7
|
kbuild: don't delete in-flight filechk temporaries in asm-headers
Commit |
||
|
|
bcfe2816e6 |
tracing: Don't dereference trace_event_file in deferred trigger free
The enable_event trigger defers trace_event_put_ref() to the
trigger free kthread, but the trace_event_file can already be freed
when the instance is removed.
Keep the trace_event_call directly in enable_trigger_data so the
deferred free does not access the freed trace_event_file.
Cc: stable@vger.kernel.org
Fixes:
|
||
|
|
b4dcc18b97 |
ftrace: Use rcu_assign_pointer() for tmp_ops filter hash
tmp_ops.func_hash->filter_hash is annotated __rcu, but
update_ftrace_direct_mod() assigns hash to it directly. Sparse reports an
address-space mismatch.
Use rcu_assign_pointer() for the assignment.
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260911142512.19344-1-leon.hwang@linux.dev
Fixes:
|
||
|
|
cba2348ab1 |
xfs: fixes for 7.3-rc3
Signed-off-by: Carlos Maiolino <cem@kernel.org> -----BEGIN PGP SIGNATURE----- iJUEABMJAB0WIQSmtYVZ/MfVMGUq1GNcsMJ8RxYuYwUCaqUKSwAKCRBcsMJ8RxYu Y+MGAYDYcY0bdSotlB2fysx0oanBi+qtwHj2lyarMhyVgt9RiVEjJCd3QltOdvCX //c47YQBgKneMUlhsvgYaYkimXLnXozJkPMh1ItAi292T+pjRJmh5slafghibmjA tSPy1tLdEQ== =Hi7p -----END PGP SIGNATURE----- Merge tag 'xfs-fixes-7.3-rc3' of git://git.kernel.org/pub/scm/fs/xfs/xfs-linux Pull xfs fixes from Carlos Maiolino: "More than the usual amount of fixes. The highlights here are a block under reservation fix which caused an assert to be triggered in non-default configurations. The assert, initially added on 7.3-rc2 just makes the problem explicit but is not the cause. Another highlight is a missed lock/unlock mutex in the xfs healthmonitor which was causing lockdeps warnings. Besides those two, this also contains a myriad of fixes for random bugs found by LLM tools in the healthmon, scrub and online repair. A few bug fixes for zoned xfs are also included. This also includes an accounting fix for our buffer slab cache where the memory payload associated to each object was not being properly accounted for. The remaining of the patches are a few lock context annotations added and/or fixed. They are mostly disabled by now, but still worth fixing before we get them enabled. And last but not least, a few clean ups" * tag 'xfs-fixes-7.3-rc3' of git://git.kernel.org/pub/scm/fs/xfs/xfs-linux: (75 commits) xfs: advance the findparent inode scan cursor while holding ILOCK xfs: reset parent pointer args before each dir tree unlink repair xfs: fix replaying dirent removals into the temporary directory xfs: fix termination logic in xchk_bmap xfs: fix rtrmap cross-referencing elision logic xfs: actually check internal-rtdev fields in the superblock xfs: fix under-reservation of blocks when repairing sf directories xfs: take hm->lock in xfs_ioc_health_monitor() before insert xfs: set IOMAP_F_INTEGRITY for zoned writes on integrity devices xfs: avoid extra cache flushes for multi-device file systems in xfs_fsync xfs: don't continue on error in xfs_fsync xfs: also flush the RT device cache in xlog_write_iclog xfs: bail out on bitmap errors in xrep_agfl_fill xfs: snapshot old AGFL before rewriting it xfs: remove redundant function declaration xfs: report runtime failures in scrub xfs: report healthy filesystem events in scrub stats xfs: snapshot scrub stats when rendering them xfs: remove several unused and never-implemented declarations xfs: count escaped corruption errors in scrub stats ... |
||
|
|
95deca8dd9 |
for-7.3-rc2-tag
-----BEGIN PGP SIGNATURE----- iQJPBAABCgA5FiEE8rQSAMVO+zA4DBdWxWXV+ddtWDsFAmqkjz8bFIAAAAAABAAO bWFudTIsMi41KzEuMTIsMiwyAAoJEMVl1fnXbVg72aYP/iJfylH6S+RbQMRFvon2 TixmsPcGaFgUUAyAG4uLmfVX7KS4Z7uJD8zoZKqP0DMBbCOUwEjWriY2Fy9dKAJm I8UNJpPfQzXV7Oalpdy5UaNVVtdk/mE1Rhv4+G4EdqNLf9GuxTd+kuO1Tn1EK/Ql gQKL1WZgYmHBHDv9R1uip/ibEMsTzow2RDQGDI/AKILlnWjoMthd22NXdX0bC7Tb sKZfEmDKbIpiVkoMaJdoXsXnDifsAb31W0KqiqOvG3PGS5bY/TJgV9l5x9heExvR pQ4CCSY/wH+dWKetl3YvHiWBiSXdKlsufnYwsO00PxJAr+Q7pNsBrXH5fys9bORC G7qCWiEmTJElNnTBTv0yUaJq+FQ6/FSzTPZXQgGhUctamiM2hgnEVv4vc8YiEGcN dk7rBSKMfA08BXqGhEwLZkVwleM09uUa89kK9gG/pdh0aY5twHB4CQ2EQFwitJgE QhtTrKLa8yjP7HpzR82VEioTkj7KZlI+jYDksaIACANjbxk7tZ73F81lPi7vNhRj YyYOXZOQaD081d+h09NM89C/XTXrKMND6Ft8iRSzSec/U75YWeDRFHJ2O986n0dj DAxzArrAR18lQwCmFODJbRMi6ELcnSjSbiIusNjUpwXsVSOuZR/ulriTRktPvptq UtDnhWOvBjHwoeqUlgB4OAEG =DZIQ -----END PGP SIGNATURE----- Merge tag 'for-7.3-rc2-tag' of git://git.kernel.org/pub/scm/linux/kernel/git/kdave/linux Pull btrfs fixes from David Sterba: - tree-checker updates, validate values in b-tree item keys, other item length checks - don't do unnecessary transaction commit fallback when logging parent directories - in zoned mode, initialize space info of a block group early enough so it does not lead to NULL pointer dereference * tag 'for-7.3-rc2-tag' of git://git.kernel.org/pub/scm/linux/kernel/git/kdave/linux: btrfs: tree-checker: validate name length for extref items btrfs: tree-checker: validate parent field for inode extref items btrfs: tree-checker: validate key offset for inode ref keys btrfs: fix unnecessary transaction commit fallback from btrfs_log_all_parents() btrfs: set space_info before adding new free space in btrfs_make_block_group() |
||
|
|
4d85a45df0 |
Changes since last update:
- Fix the missing sysfs feature entry for xattr prefixes
- Fix invalid LZMA decoders on resize failure
- Disable LZ4 rolling decompression for now due to the uncontrolled
LZ4 implementation
- Rearrange the inode_share cache key to avoid potential collisions
- Fix erofs_bread() when fsoffset is used on sub-page-block EROFS
filesystems
-----BEGIN PGP SIGNATURE-----
iQJFBAABCgAvFiEEQ0A6bDUS9Y+83NPFUXZn5Zlu5qoFAmqlRUkRHHhpYW5nQGtl
cm5lbC5vcmcACgkQUXZn5Zlu5qpHEg/8C9Ih/XK8spRppF+rWGUnhf+9iARJE4aP
31NJgvs8h5R8tfxu3vOhOlhOT3pybxAuPI2qkx+c5kZRlo1wtCN2HQPH5NeZ7nUn
JhA99YHs7UTz8FYa2gKO4F9gTqorEOJO4R3jrSPNFT2V5Ae3ApgLhvfjZfSv4+4X
zQox+fdmzKT3G4sOuCPhTz4Fo5NleiJSrA+sVBn8lPcT3xCJZiUsJb7hK31rco0J
tnAVJsbhy9Yq7FZiUDIdbAQl9ukPoYbF8rYXVkcbXGFE8Qq1Gmm1Ep1OndmB3k0U
JFOub70cp4x/T8EKjc+W7Ft1mhq9yZkGlVMUb3otb3cFIOYBfl/8ClO3i0xltBXG
4uafbtc5Lfs7tSOaYoJ0JHDzgIx91hFbCXEM0QW+WYXh9bLTpSZv3FG93tQ4QSHN
1m8jqjF5i4eGnp/xEFFSltrgqtwmiyIgeSg8tHyTG7pIao5zengZiysdcmZi2Akl
/0txH8hSx3qldt69PadotW2rGROPb8SOgDpFvlcfitSwOoN2RF0R+Mq/afog+WkY
99EmJ32okgGN9LK8scX1cynW30X065pWzWpLm3WvbBDNmKl+jX+i4RkuEOKFV3zQ
IqOZjmHCDHv2NJq7EzC8XE18Z6LewXXX1nw6iO/5UneZgrODltlDfuq9f4pdwYI2
UugUZKgygoU=
=fmjB
-----END PGP SIGNATURE-----
Merge tag 'erofs-for-7.3-rc3-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/xiang/erofs
Pull erofs updates from Gao Xiang:
"The most impactful fix here is to disable LZ4 rolling decompression
for now.
AWS folks recently found their systems could get corrupted data with
some rare, specific LZ4 datasets, and after a deeper analysis, I found
the root cause is that there could be uncontrolled backward memory
copies in the current LZ4 implementation and it breaks the assumption
of the rolling decompression optimization, since the kernel LZ4
codebase is out of our control and it needs more time to plan how to
do next, so disable LZ4 rolling decompression for now to ensure data
correctness for real production on these rare cases first. The
technical details also see the corresponding commit.
Other changes are random minor fixes.
Summary:
- Disable LZ4 rolling decompression for now due to the uncontrolled
LZ4 implementation
- Fix missing sysfs feature entry for xattr prefixes
- Fix invalid LZMA decoders on resize failure
- Rearrange the inode_share cache key to avoid potential collisions
- Fix erofs_bread() when fsoffset is used on sub-page-block EROFS
filesystems"
* tag 'erofs-for-7.3-rc3-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/xiang/erofs:
erofs: add missing buf->off in erofs_bread()
erofs: delimit inode_share cache key components
erofs: disable LZ4 rolling decompression for now
erofs: preserve LZMA decoders on resize failure
erofs: add sysfs feature entry for xattr prefixes
|
||
|
|
31a4327ffe |
fbdev fixes for 7.3-rc3:
- vt core: prevent potential out of bounds read on font change - fbcon: prevent out of bounds read when logo bigger than screen - atafb: limit SuperBlitter operations to supported layouts only - vfb: fix driver removal cleanup sequence - ssd1307fb: fix possible NULL pointer dereference on missing match data - omapfb: Fix sparse warning in panel_enabled() -----BEGIN PGP SIGNATURE----- iHUEABYKAB0WIQS86RI+GtKfB8BJu973ErUQojoPXwUCaqUOqgAKCRD3ErUQojoP XzVJAQDnJRpRl9+xwTyUrE3iJk4SllnV6SF5td3AnkUZrjTbcAEA7zCEnH0jwfJ1 NsU/EKj2+PleQ0+SGRBKHIoZPEC1bQU= =T0+q -----END PGP SIGNATURE----- Merge tag 'fbdev-for-7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/deller/linux-fbdev Pull fbdev fixes from Helge Deller: "Two patches for VT core code and fbcon prevent potential out-of-bounds reads on font or screen size changes, one fix limits the Superblitter in atafb to supported modes only, and some minor fixes for vfb, ssd1307fb and omapfb" * tag 'fbdev-for-7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/deller/linux-fbdev: fbdev: vfb: defer cleanup until the last reference fbdev: atafb: Restrict SuperBlitter to supported formats fbdev: ssd1307fb: fix NULL pointer dereference on missing match data fbcon: Fix KASAN slab-out-of-bounds Read in fbcon_prepare_logo fbdev: omapfb: Fix __be32 sparse warning in panel_enabled() vt: hide cursor prior to font changes to avoid out-of-bound reads |
||
|
|
f6e213d5a2 |
IOMMU fixes for Linux v7.3-rc3:
- RISC-V IOMMU:
- Serialize command queue publication to prevent concurrent producers
from exposing incomplete or out-of-order commands to hardware.
- Wait for queue space outside the command queue lock.
- Avoid waiting for IOFENCE completion when command enqueue failed.
- AMD IOMMU:
- Prevent GA log buffers from being reallocated and leaked during
resume, where allocation also occurs in an unsuitable syscore
callback context.
- Fix a regression on older systems whose firmware advertises
incorrect IOMMU features.
- Preserve allocation errors when assigning host domain IDs to nested
domains.
- s390 IOMMU:
- Prevent a NULL dereference when translating an unmapped IOVA with
five-level ZPCI translation tables.
- Miscellaneous:
- Remove a stale MAINTAINERS entry and clean up unused or redundant
AMD IOMMU declarations, macros, and checks.
-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEEr9jSbILcajRFYWYyK/BELZcBGuMFAmqkH6kACgkQK/BELZcB
GuPgZhAAtYhzeVbH6IKimy29zj6TZKvzdlWtMOuAk7wj/URPWPK6kA+LC44uH9OB
+WY+6P922vC5pqcL5YkA7GNt8KQaJEgTFp9zdQ15hY7PFAw+GIM66HVVn96iCv5a
RY1485YJopQEHSfpb3e2GyuR6mdW6b7ReEmzFr0P9Md1Flm/6TaGvCmSCjLLVrto
BkJ6DfWQ0zNC3eByAHFE8HOh3T6Eea8J64tC+Tt6jOFO6ynQL7+acwv2zG66z1RM
bZAjgNMAdPO7AHU3Kue7OT8mVFKy75G3AOtT55dobiBWFJ4jPgziw6ZhjEEMNZDs
eADcQT1reXLdQkiOYGxZt5fNAI9RQiZRNizIidFG4KmaYGxWaPUR2nQUxyCSvlig
Wv8GMHaFskZxkJyqAonYtlUxaUk6XAF3L4nQrDZW2KJsHZdopcDnUeGi526J414h
bvD/p4IxSNhlzib+70mQ3XPHqzVAyDjjRBuQBK+B4MXfKMet68/O1qBzxBQVqgQX
gJaz++7hGSE4uvt4NCANjhpC6aTKGZdeWsFc8xs44krHjQo6ssPZSlxl3nclJOUQ
O6N50eV6nItnE/kqbdKxpdZIzYHmW6DLxL+2bvueZjRMXxpCuPmSuCpJux+Hl2RW
RqMVhUAgGPm35RNmRTkAh534WzElNc2K66VM6952ck8xrZ6+Hy8=
=2Cze
-----END PGP SIGNATURE-----
Merge tag 'iommu-fixes-v7.3-rc2' of git://git.kernel.org/pub/scm/linux/kernel/git/iommu/linux
Pull IOMMU fixes from Joerg Roedel:
"RISC-V:
- Serialize command queue publication to prevent concurrent producers
from exposing incomplete or out-of-order commands to hardware
- Wait for queue space outside the command queue lock
- Avoid waiting for IOFENCE completion when command enqueue failed
AMD:
- Prevent GA log buffers from being reallocated and leaked during
resume, where allocation also occurs in an unsuitable syscore
callback context
- Fix a regression on older systems whose firmware advertises
incorrect IOMMU features
- Preserve allocation errors when assigning host domain IDs to nested
domains
s390:
- Prevent a NULL dereference when translating an unmapped IOVA with
five-level ZPCI translation tables
Misc:
- Remove a stale MAINTAINERS entry and clean up unused or redundant
AMD IOMMU declarations, macros, and checks"
* tag 'iommu-fixes-v7.3-rc2' of git://git.kernel.org/pub/scm/linux/kernel/git/iommu/linux:
iommu/amd: Remove unused macro
iommu/amd: Remove redundant checks from interrupt handler path
iommu/amd: Remove redundant check in irq_remapping_select()
iommu/amd: Make iommu_sva_set_dev_pasid as static
MAINTAINERS: Drop the nonexistent vsi-iommu.h file entry
iommu/amd: Fix ineffective error check in nested domain allocation
iommu/amd: Fix premature break in init_iommu_one() again
iommu/amd: Do not reallocate GA log buffers on resume
iommu/s390: Fix NULL dereference in iova_to_phys() with ZPCI_TABLE_TYPE_RFX
iommu/riscv: Avoid waiting on failed command enqueue
iommu/riscv: Serialize command queue publishing
iommu/riscv: Add command queue lock
|
||
|
|
52311be52f |
powerpc fixes for 7.3 #3
- powerpc/entry: Fix double accounting of user time on interrupt entry - Fix leak in htmdump_init_debugfs - KVM: PPC: Book3S HV: Set irqfd->producer only on success - powerpc/kexec_file: print configured kernel command line - Remove redundant early_init_dt_scan_root() call - misc fixes and cleanup Thanks to: Aboorva Devarajan, Amit Machhiwal, Athira Rajeev, Christophe Leroy, Christophe Leroy (CS GROUP), Kunwu Chan, leixiang, longlong yan, Michail Tatas, Mukesh Kumar Chaurasiya (IBM), Ritesh Harjani (IBM), Shivang Upadhyay, Sourabh Jain, Thibault Ferrante, Vaibhav Jain, Venkat Rao Bagalkote -----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEEqX2DNAOgU8sBX3pRpnEsdPSHZJQFAmqk60sACgkQpnEsdPSH ZJQsGRAArQi4cAIMzc0w44DA4othVOjUauS81/z0TfgxCT3pUPdG0C71x5uJrDpF Cdtc03xsxLURAGy1afQX9WsWQwpimWbGLhI/KQpSgGoKEq5RNVVMvOMKVzlB8Wmo XW/bfugU0jov8Iz6vH8iQAn2hazE52G98NHU6y8ZDcOrpFBA4RRY2CaqJIt40Xzm kxgkH773ErKPbyKycW3NBYxm9Bf2Cm3HUB1RO0OnAcLE2dHr3AqUGvt0ruLx+Cew YEJEenbKaxM8YWtji6cjkGKOCjgmKdUe+t+fh4G4KZVhG8whb4Ci/NhZxlkup9AC 64B3gkqIK3Hh+ufsvbSlN6/ignFtdZsioneLoMteCx7C0cs+HTnLBoghI3FlDNXc f0ywaNlZgzDt73zAejLMp4PPiqjMyELAq9V4sKatSTugexELM1t9b3f/pIa2kFNR s/VVXJ5YL2ni6gS26vg2GVOCZeBoJ5ucrxDiZVEyaWHpnuq1cu35a+Sbf4O0yVBK h70SVyi2OLUc+DNSMJMoIDfFg+6gfzo4cbbW/s2MV2hYrDRCu0Rx3xNzq1qNAiN0 RNSC4cOQ4hCrmORzEOJzuCAahRKGrFR3vaW73KhmhCNJ7DnDqJR2luSa7f4aKg8T d/z1FY7eTqNPbt4EH4+GB/MajF59xM8OihcnjbmoSDnSGUp2DTI= =zcTl -----END PGP SIGNATURE----- Merge tag 'powerpc-7.3-3' of git://git.kernel.org/pub/scm/linux/kernel/git/powerpc/linux Pull powerpc fixes from Madhavan Srinivasan: - powerpc/entry: Fix double accounting of user time on interrupt entry - Fix leak in htmdump_init_debugfs - KVM: PPC: Book3S HV: Set irqfd->producer only on success - powerpc/kexec_file: print configured kernel command line - Remove redundant early_init_dt_scan_root() call - misc fixes and cleanup Thanks to Aboorva Devarajan, Amit Machhiwal, Athira Rajeev, Christophe Leroy, Christophe Leroy (CS GROUP), Kunwu Chan, leixiang, longlong yan, Michail Tatas, Mukesh Kumar Chaurasiya (IBM), Ritesh Harjani (IBM), Shivang Upadhyay, Sourabh Jain, Thibault Ferrante, Vaibhav Jain, and Venkat Rao Bagalkote * tag 'powerpc-7.3-3' of git://git.kernel.org/pub/scm/linux/kernel/git/powerpc/linux: powerpc/pasemi: Add a null pointer check to the pas_setup_mce_regs powerpc/prom: Remove redundant early_init_dt_scan_root() call selftests/powerpc: use MAP_FAILED instead of (void *)-1 in tm-signal-context-force-tm powerpc/kexec_file: print configured kernel command line KVM: PPC: Book3S HV: Set irqfd->producer only on success powerpc/pseries/htmdump: Fix leak in htmdump_init_debugfs selftests/powerpc/tm: Fix tcheck() reading uninitialised CR value selftests/powerpc/pmu/ebb: fix lost_exception_test hang with sched yield change powerpc/entry: Fix double accounting of user time on interrupt entry |
||
|
|
5225b8eec4 |
mailmap: update entry for Jens Axboe
I recently changed jobs, let's update the .mailmap entry so that patches are attributed to the right (current) company. Signed-off-by: Jens Axboe <axboe@kernel.dk> Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org> |
||
|
|
114f73092b |
regulator: Fixes for v7.2
One fix for pf1550 which checked for errors on multiple regulators but always notified via one of them regardless of which one had the problem, plus one device ID addition in the fan53555 DT bindings. -----BEGIN PGP SIGNATURE----- iQEzBAABCgAdFiEEreZoqmdXGLWf4p/qJNaLcl1Uh9AFAmqkbckACgkQJNaLcl1U h9Dfewf+PacEx4Rc51FaF9OGmniMQ5wLU8W7maJv8L/68hghxhwGQZL/KxgYZAjU HuniSGz6GMbsJ+S1HVYVqA5GPzJgjf6CpCc8WvHZnyCNQ+R5zrAW2e9tylWJniwu 7ngrImiRdtRJkyyTv01j5KSORc7jGqXJR/Iea2nqe5IAdNxYVAbl5Jar6vynF3wA rOJ5s2WTMu7J/ygRAVdqH0yIDbpqKaLTBn9IrCzFYxGllMkNMnKmjNICKI7OpQGu hP8Dghe1TSFCJUPCuWMG9O8GjRZZNkYOQakr52pClhBCvI2vJPCY5D5yRCp7CDoY 5bQtDEv+we+FsuuVxvCJ60NhH8zH7A== =fjiq -----END PGP SIGNATURE----- Merge tag 'regulator-fix-v7.3-rc2' of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/regulator Pull regulator fixes from Mark Brown: "One fix for pf1550 which checked for errors on multiple regulators but always notified via one of them regardless of which one had the problem, plus one device ID addition in the fan53555 DT bindings" * tag 'regulator-fix-v7.3-rc2' of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/regulator: regulator: pf1550: fix which regulator is notified regulator: dt-bindings: fan53555: add tcs,tcs4526 |
||
|
|
0fb234ce37 |
spi: New device ID for v7.3
Update the DesignWare DT binding to say how to describe the UltraRISC DP1000 instance of the controller. -----BEGIN PGP SIGNATURE----- iQEzBAABCgAdFiEEreZoqmdXGLWf4p/qJNaLcl1Uh9AFAmqkbi8ACgkQJNaLcl1U h9AmXwf/fx62hiA+UOPrKA1d4hjMI1s828iif4dgo2WPfZLkAeMnd4ibFgf/gIYv gLKJHmdtLAJ0z1JY+01cOEvRw4UvSiPLuwaM9+tR/jWc+KhF711IJBFRba8aKH0Q GHjbooYTkmJotx70V6MkACRgJSQjoHizHgHQoYF/UdG9YO6S8Ee0ya9XC3jMbvaZ 0cRhKPtZozuJrrra7IvNVANt0KR4W8mKcuYFWaXmtwIP8wZyL4FilGcnLfNZiz7B GfrZ9GLJcoRbSq4gnQx4/I/8GTS8J7AaEQo69dNiexYWs+fOgDCSclLcR/GznVAU bawIajipjKNi3pZcaoaSrgKjAWMu5Q== =ta0L -----END PGP SIGNATURE----- Merge tag 'spi-fix-v7.3-rc2' of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/spi Pull spi fix from Mark Brown: "New device ID for v7.3: update the DesignWare DT binding to say how to describe the UltraRISC DP1000 instance of the controller" * tag 'spi-fix-v7.3-rc2' of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/spi: spi: dt-bindings: snps,dw-apb-ssi: Add compatible for UltraRISC DP1000 SoC |
||
|
|
525f0f99a4 |
drm fixes for 7.3-rc3
drm_exec: - fix 0 object handling sched: - null ptr deref fix in kunit tests amdgpu: - Freesync fix - GPUVM fix - Debugfs fixes - HDMI fixes - IPS fix - GPU reset fix - RGB quantization fixes - SMU 13.0.x fixes xe: - runtime PM guard fix - cache flushing fix i915: - Fix a memleak on perf config query error path - Fix UHBR SST SDP splitting when sink doesn't support it bridge: - fix ti-sn65dsi83 error handling - tc358768: Enforce input bus flags via atomic_check ast: - fix blend mode property on cursor plane qxl: - fix blend mode property on primary/cursor planes virtio: - fix blend mode property on cursor plane vboxvideo: - fix blend mode property on planes rockchip: - fix endpoint name length - fix Kconfig issues ivpu: - limit firmware log prints to field size - validate buffer range in ivpu address translation - validate fw log buffers ethosu: - ensure SRAM sizing - ensure cmd stream formatting - drop IRQF_SHARED - fix open return value adp: - fix Kconfig logicvc: - fix Kconfig -----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEEEKbZHaGwW9KfbeusDHTzWXnEhr4FAmqkZ3gACgkQDHTzWXnE hr73LQ//YciKV7q62r31apitbxB/pffXWbQsKZU3FtBBUwyPvuO0R1iyQiaxN71O DqVqSBpnRf2SjAyyF0YAon1hmOcbkiDli1oZ3X8I20C1llGcTCzT8mYjnFejFBoX ScqBO3iwdKEI6vrSBy9SJjnL6h2OBhPaE8EH3tZVko5OalpLwnUyLP4UffX25sIF 2kN904rA5yaBSdnMGry2I819m85K9I+kx321u08LaUlXUzJa28uPWm2rPsSSWRj5 HB83FIIYe5z2DH2GyBQJa6XP/oP3ysbra68wfB34mHrfjgGxQVgoe1oY1ERcqlo1 V4a/N0lJCvjEPAfTQ+jO28wj1H4my7YPDekv+iA9mBETM0sUKTb63KTt95L44Ap+ I6OyommsHZAcMDWvvRW5Q1DlQ5DRCYUSUhvSan6WzxtFueobwhl+SpJ3EHLevDIy xmlnoG6qV5YHYiw9CG+95+Y69N8kj9FffNvAdE/Db/5JyMTlhC2sagLAAJC4z54X BlGS96yRzJm9spmGctzCTMFCfgDDR7TqSSi6pPMazFB4vLpmkfr7xZ7C54Gerrjp Q4lWW/MoS+wSpzZuGa7EZq8e65dTRdDo5TgpOMI6qS8uYfaidNsU9lG6x8/xRDKD elniWmhe2b49RwoAUXQz7IIDFR3gzbo8MxI1ikCtyOfE7fIKCBI= =WQ9l -----END PGP SIGNATURE----- Merge tag 'drm-fixes-2026-09-12' of https://gitlab.freedesktop.org/drm/kernel Pull drm fixes from Dave Airlie: "Weekly fixes pull, this seems relatively quiet for the new world, scattered fixes, mostly amdgpu leading the way, but lots of minor fixes in other drivers. drm_exec: - fix 0 object handling sched: - null ptr deref fix in kunit tests amdgpu: - Freesync fix - GPUVM fix - Debugfs fixes - HDMI fixes - IPS fix - GPU reset fix - RGB quantization fixes - SMU 13.0.x fixes xe: - runtime PM guard fix - cache flushing fix i915: - Fix a memleak on perf config query error path - Fix UHBR SST SDP splitting when sink doesn't support it bridge: - fix ti-sn65dsi83 error handling - tc358768: Enforce input bus flags via atomic_check ast: - fix blend mode property on cursor plane qxl: - fix blend mode property on primary/cursor planes virtio: - fix blend mode property on cursor plane vboxvideo: - fix blend mode property on planes rockchip: - fix endpoint name length - fix Kconfig issues ivpu: - limit firmware log prints to field size - validate buffer range in ivpu address translation - validate fw log buffers ethosu: - ensure SRAM sizing - ensure cmd stream formatting - drop IRQF_SHARED - fix open return value adp: - fix Kconfig logicvc: - fix Kconfig" * tag 'drm-fixes-2026-09-12' of https://gitlab.freedesktop.org/drm/kernel: (38 commits) drm/amd/pm: report energy accumulator for smu 13.0.0 drm/amd/pm: fix gpu metrics energy accumulator for smu 13.0.0/13.0.7 drm/amd/display: Rebuild InfoFrames on output color space changes drm/amd/display: Honor Broadcast RGB for BT.2020 RGB output drm/amd/display: Propagate HDMI RGB quantization selectability Revert "drm/amdgpu: debugfs: avoid extra EOLs in amdgpu_gem_info" drm/amdgpu: skip gfx switch_power_profile during GPU reset drm/amd/display: Fix HF-VSDB DSC bpc detection to be cumulative drm/amd/display: Exit IPS before connector detection on resume drm/amd/display: Shorten hdmi_frl_status_polling_workqueue dm/amdgpu: fix malformed link_settings debugfs output drm/amdgpu: skip the VMID 0 flush for VRAM drm/amd/display: Consult MCCS FreeSync cap only if requested & supported drm/i915: Fix memory leak in query_perf_config_list() drm/i915/dp: Gate UHBR SST SDP splitting on sink capability drm/xe: Flush LSC untyped L1 dataport cache after rcs/ccs batches drm/xe: Guard page-fault worker with runtime PM check drm/bridge: ti-sn65dsi83: Fix error handling in sn65dsi83_reset_work() drm/bridge: tc358768: Enforce input bus flags via atomic_check drm/drm_exec: fix up contended obj when num_objects is 0 ... |
||
|
|
827751b699 |
RISC-V updates for v7.3-rc3
- Revert a bad fix, likely LLM-generated, in the pointer masking code
that confused the RISC-V hardware pointer masking implementation
with the Linux kernel tagged address feature
- Fix unexpected faults caused by kprobe instruction slot writes when
!CONFIG_STRICT_MODULE_RWX
- Fix unexpected faults on minimal configurations during runtime code
patching on !CONFIG_STRICT_MODULE_RWX systems
- Fix a misplaced variable clear causing incorrect reuse of previous
values in the RISC-V hardware feature probing code
- Fix two bugs in the PMU SBI perf code on rv32: use BIT_ULL rather
than BIT on 64-bit masks; and use a bitmap rather than an unsigned
long on a quantity that can exceed 32 bits
And a few miscellaneous cleanups:
- Avoid a potential dereference-before-NULL-pointer-check bug in the
PMU SBI perf driver
- Simplify the rv32 bug table code by using
CONFIG_GENERIC_BUG_RELATIVE_POINTERS (following x86 and PPC)
- Report the RISC-V standard ISA extensions Z[v]fhmin when support is
claimed for the superset RISC-V standard ISA extensions Z[v]fh; and
simplify our FPU test code to only check for the presence of the D
extension
- Use an existing kernel string helper in place of some open-coded
code in kernel/usercfi.c
- Fix some yamllint issues in the RISC-V DT bindings for CPUs
- Convert one use of __ASSEMBLY__ to __ASSEMBLER__ that snuck into the
RISC-V CFI selftest code
- Update the translation for the simplified Chinese translation of the
RISC-V kernel patch acceptance policy
-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEElRDoIDdEz9/svf2Kx4+xDQu9KksFAmqghcoACgkQx4+xDQu9
KkvmEQ/7BVmPFuoR6OLNk2Eu8Exqen6a41KxdM/B91NJBEbBM60GAyejjWDXWmm0
K21yhRu58RGbfg2kKUJMvawzwIfuDswxCS31VtpDKnTrmP4HQz1Yvnh2M7jH9D2d
/wJCIYcJ0hJx0yDIZOUhU24aoy63ZXRygp8nTOgjkAxhkF31w+MJxTPDD0Ir7Eai
y4sRMTCabMonmyA0qozfnMoXaO3FkPv9l7pw/LHfqUYjaLNQyMHiiDPrRj1oNZPD
GQFUWykRgMccMW6kIgTJrjmzn7+vEJ7UZ/fvOD97+rGeaoyE19vcW8owUQWp6Hgb
Jq3WyS9HImrpCBTr079ht5lhu3ZucpAEP6sK5v/m4GOlBv1HdYHUS6JH0qo4DnXZ
aFrxg7WXxaFZ8dD3P8ErZkXy5Vid3+ZlpK//AOfWAqxX7q6c4K1w3lJm4bPKyNBX
vh3ASQr5oEj3KpGbihsrX2lVB/5LVP3pWTcH5f6rBBYiVFMMhWKLJXA3pjiRFN7v
ZXClKh5MznvS6ycMp5pXVYpVn2Kk+Y/mywsDqNRUigHwppkxI9MTJBq8+qcOiM9I
a7mHna4XHVVu0+B4/JMhkWgnGYRjFD6bsGzxPZODLFcmBUxmsoa5+HOENLAGdQ1w
s/Z2HmDO8yL37DxLq5O2aF3KNPSkXNBl+upQwj5lTTzR/bmghjc=
=oMU+
-----END PGP SIGNATURE-----
Merge tag 'riscv-for-linus-7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/riscv/linux
Pull RISC-V fixes from Paul Walmsley:
"From a RISC-V point of view, there's one notable fix here, reverting
an earlier bogus fix to the pointer masking code. Fortunately the
practical impact appears to be small.
- Revert a bad fix, likely LLM-generated, in the pointer masking code
that confused the RISC-V hardware pointer masking implementation
with the Linux kernel tagged address feature
- Fix unexpected faults caused by kprobe instruction slot writes when
!CONFIG_STRICT_MODULE_RWX
- Fix unexpected faults on minimal configurations during runtime code
patching on !CONFIG_STRICT_MODULE_RWX systems
- Fix a misplaced variable clear causing incorrect reuse of previous
values in the RISC-V hardware feature probing code
- Fix two bugs in the PMU SBI perf code on rv32: use BIT_ULL rather
than BIT on 64-bit masks; and use a bitmap rather than an unsigned
long on a quantity that can exceed 32 bits
And a few miscellaneous cleanups:
- Avoid a potential dereference-before-NULL-pointer-check bug in the
PMU SBI perf driver
- Use CONFIG_GENERIC_BUG_RELATIVE_POINTERS to simplify the rv32 bug
table code (like x86 and PPC)
- Report the RISC-V standard ISA extensions Z[v]fhmin when support is
claimed for the superset RISC-V standard ISA extensions Z[v]fh; and
simplify our FPU test code to only check for the presence of the D
extension
- Use an existing kernel string helper in place of some open-coded
code in kernel/usercfi.c
- Fix some yamllint issues in the RISC-V DT bindings for CPUs
- Convert one use of __ASSEMBLY__ to __ASSEMBLER__ that snuck into
the RISC-V CFI selftest code
- Update the translation for the simplified Chinese translation of
the RISC-V kernel patch acceptance policy"
* tag 'riscv-for-linus-7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/riscv/linux:
riscv: skip software algning code for HAVE_EFFICIENT_UNALIGNED_ACCESS
kselftest/riscv: Replace __ASSEMBLY__ with __ASSEMBLER__
docs/zh_CN: Update arch/riscv/patch-acceptance.rst translation
dt-bindings: riscv: cpus: Fix yamllint style issues
riscv: hwprobe: simplify has_fpu() to check D extension only
perf: RISC-V: check cpu_hw_evt before dereference in overflow IRQ
riscv: report Zfhmin/Zvfhmin when Zfh/Zvfh are present
perf: RISC-V: store available counter mask as bitmap
perf: RISC-V: use BIT_ULL for u64 overflow masks
riscv: bug: Make RV32 use GENERIC_BUG_RELATIVE_POINTERS
riscv: hwprobe: initialize pair->value in hwprobe_one_pair()
riscv: use string helper in setup_global_riscv_enable()
Revert "riscv: Reset pmm when PR_TAGGED_ADDR_ENABLE is not set"
riscv: patch: skip fixmap mapping when kernel text is already writable
riscv: mm: make EXECMEM_KPROBES writable without CONFIG_STRICT_MODULE_RWX
|
||
|
|
1235ff3299 |
platform-drivers-x86 for v7.3-2
Fixes - amd/pmf: Fix build on !CONFIG_AMD_PMF_DEBUG - asus-laptop: Fix ACPI event handling - hp-wmi: Fix board_params typo for 8DD6 board - x86-android-tablets: Fix Arizona and Crystal Cove GPIO lookups The following is an automated shortlog grouped by driver: amd/pmf: - fix build on !CONFIG_AMD_PMF_DEBUG asus-laptop: - Fix ACPI event handling hp-wmi: - Fix board_params typo for 8DD6 board MAINTAINERS: - fix sysfs-platform-ayaneo-ec documentation path x86-android-tablets: - add Crystal Cove GPIO swnode support - drop redundant swnode group on YT3 - fix Arizona GPIO swnode references - fix gpio_secondary_fwnode_init() not working - hold device reference for secondary fwnode teardown - pass node group to gpio_secondary_fwnode_init() - use shared battery swnode group on Yoga Tab 2 -----BEGIN PGP SIGNATURE----- iHUEABYKAB0WIQSCSUwRdwTNL2MhaBlZrE9hU+XOMQUCaqPXbQAKCRBZrE9hU+XO MQPMAP93XM4XaHUIoX2+xhCKXQxE0+3XlhrE1n737BweWFz1qgEApBFBXipytFFU 85WexocupoYbJtlOoQ4gI8nt86XhcQk= =NAG2 -----END PGP SIGNATURE----- Merge tag 'platform-drivers-x86-v7.3-2' of git://git.kernel.org/pub/scm/linux/kernel/git/pdx86/platform-drivers-x86 Pull x86 platform driver fixes from Ilpo Järvinen: - amd/pmf: Fix build on !CONFIG_AMD_PMF_DEBUG - asus-laptop: Fix ACPI event handling - hp-wmi: Fix board_params typo for 8DD6 board - x86-android-tablets: Fix Arizona and Crystal Cove GPIO lookups * tag 'platform-drivers-x86-v7.3-2' of git://git.kernel.org/pub/scm/linux/kernel/git/pdx86/platform-drivers-x86: MAINTAINERS: fix sysfs-platform-ayaneo-ec documentation path platform/x86: x86-android-tablets: fix gpio_secondary_fwnode_init() not working platform/x86: x86-android-tablets: use shared battery swnode group on Yoga Tab 2 platform/x86: x86-android-tablets: drop redundant swnode group on YT3 platform/x86: x86-android-tablets: add Crystal Cove GPIO swnode support platform/x86: x86-android-tablets: pass node group to gpio_secondary_fwnode_init() platform/x86: x86-android-tablets: hold device reference for secondary fwnode teardown platform/x86: x86-android-tablets: fix Arizona GPIO swnode references platform/x86/amd/pmf: fix build on !CONFIG_AMD_PMF_DEBUG platform/x86: asus-laptop: Fix ACPI event handling platform/x86: hp-wmi: Fix board_params typo for 8DD6 board |
||
|
|
707662b40a |
ata fix for 7.3-rc3
- Drop documentation for no longer existing pata_legacy kernel
parameters (Ethan)
-----BEGIN PGP SIGNATURE-----
iHUEABYKAB0WIQRN+ES/c4tHlMch3DzJZDGjmcZNcgUCaqRQ0QAKCRDJZDGjmcZN
ct1FAP96qnI8tDPHzWU+1znXhDEBXl3aVw8lvSBokR4yvqyDVQEAs3Jeaq38mZTQ
C3jV+RbN4YUC/St8AFt7t73soEOb8wc=
=zZKx
-----END PGP SIGNATURE-----
Merge tag 'ata-7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/libata/linux
Pull ata fix from Niklas Cassel:
- Drop documentation for no longer existing pata_legacy kernel
parameters (Ethan)
* tag 'ata-7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/libata/linux:
ata: pata_legacy: remove documentation for removed module parameters
|
||
|
|
35ef102063 |
block-7.3-20260911
-----BEGIN PGP SIGNATURE----- iQJEBAABCAAuFiEEwPw5LcreJtl1+l5K99NY+ylx4KYFAmqj5hAQHGF4Ym9lQGtl cm5lbC5kawAKCRD301j7KXHgphqIEADE/9nkItU8nufHLICBr8FI+IncrvHJQpag 1iLerBftMLxNJDS+CAQEF5oOcorL/6bUga6nHmMAds7pILdDzafWkvnuCbrGIC1q j0V7a0Rkalv87ObbYZcoKWTTjv0IdCmNEC93fitwTujqYclI7Hwvr/t+0nkprcxU jjbHq9tzkVHVX771usCIKOVRdI+xc5TSDbOfm13tE5ESH2GzZaPqu4Aqq3nvVSOO xmLYzDlz8NRApmCl6a3KzCxHi8fROMnjlaeQrAmh6+Zov/iB5Bzqo98NBeWXgbh6 WvFxLm/zR5+WFppp+GblAZ5FtkOv5ICAYeM9fQkuiCo6o8/t+cxnTUgyex9qtMBr Uhoct1jM+eNCEWEgA1ZBRVWLsyr0FbNDrowsP4YvvqW3WdQeq8ABRz44lcRqhQJy BQYydnk7PpANdDhaAOO2JpoYbkokvPfT/8TwDFMmJlp+gwydXfE64IjE5ljaf6xr DRMxeZzFkwYrF++1KiN3Kozqe0jFINDuB9ysPrGlDHlPFK/tbx8nZn8aKOIHccBj mGNJ+fNWkFJczeuGiIbWEtNci0ZL+8eaDqF+uOp5odQ7vo8rYPv2TRff436dcI0c 0EnQrC9orScabgRAIklnnEWjw9XoHmpoCTQE/LhlA1rf+zDNQ2cvNopBePDuxaku IChLh+u+0g== =JeEt -----END PGP SIGNATURE----- Merge tag 'block-7.3-20260911' of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux Pull block fixes from Jens Axboe: - Fix the start and length check added to iov_iter_extract_bvecs(), which used iter_iov_addr()/iter_iov_len() helpers that aren't safe for the ITER_BVEC/FOLIOQ/etc iterator types passed - sunvdc fixes for an -EIO issue from lack of retries, and unmapping LDC cookies when the descriptor send fails - Clear force_abort in ublk_queue_reset_io_flags() - ublk selftest install fix * tag 'block-7.3-20260911' of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux: selftests: ublk: add batch IO cases to recover_03 ublk: clear force_abort in ublk_queue_reset_io_flags() sunvdc: fix -EIO issue due to lack of retries sunvdc: unmap LDC cookies when the descriptor send fails block: Fix start and length check added to iov_iter_extract_bvecs() selftests: ublk: install test_common.sh and trace/ scripts |
||
|
|
42f961c42b |
io_uring-7.3-20260911
-----BEGIN PGP SIGNATURE----- iQJEBAABCAAuFiEEwPw5LcreJtl1+l5K99NY+ylx4KYFAmqj5fsQHGF4Ym9lQGtl cm5lbC5kawAKCRD301j7KXHgpmGsD/0W7eNXJd/tFNPOdDwTr1/3yciqYXw5QO5Q eb2SLyr34sAODOItTYoBrIZ5b1Mbgm0yhT1wJ3YrVKLNLVSvbDPNtx5qtnAGcKvm 09XsPmvlDcW8JLRsjd5dcsP+EDmgTNLuNGSeVycuTG91f5VD63vPHTKUhgKDabtC InM1LbIs2rz0tojdV6n4MOOF2AwZAOHqFtac+cQUCwuJhNtwUFClSUHxqYoP+JzE 97ores3f+ArAtmOoVeH2wSCZTmwdB7MxOB8jmt8fdNSprW8nxTO3oT/eQzYXvlM9 7LRJV/6SGVsWjuoEHAfW8G0p+JOzGGFvFIXGWEBenjtNmlyXJqfxYhkcLMw826ob pct3Rc5nheZbxKdCkHnY1AmEibS/c1kTZbDvSBXk9GLBKyQuI7B3yo163zMs3JjO YSAlLllDjdzOR6gCPg5HHZlywBWtXveC/xVBzDq7b1q07ysHFNO1yQplMM3U8sC0 Eic4RcFU4ld+/L2GmbdgRZ9ataZsju+RFojSogA0NzR18HqVNQuZiVbY764GSop9 HVW28lzoYamgvg5fLWJPrzJmdFrj/p8pi+cw1dK8uMk9VnFwdA740Nfhz1NWFS0Y TpvJtxc0f2ofrI1ilaa95vHC+wMyds1zxq9Bf4i9cgIhT17WqvE4SD0JMXmvza4k Yi72jzTTfQ== =zpCb -----END PGP SIGNATURE----- Merge tag 'io_uring-7.3-20260911' of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux Pull io_uring fixes from Jens Axboe: - Fix a deadlock in the write path with superblock freezing - Fix an issue where a provided buffer ring would overconsume when using MSG_TRUNC - Keep the CQE flags on iopoll requests when adding kbuf flags * tag 'io_uring-7.3-20260911' of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux: io_uring/rw: keep CQE flags on iopoll requests when adding kbuf flags io_uring/net: don't overconsume buffers when using MSG_TRUNC io_uring/net: let io_recv_buf_select return the length of the buffer region io_uring/rw: end write accounting from ->ki_complete |
||
|
|
3026c6e4f2 |
slab fixes for 7.3-rc2
-----BEGIN PGP SIGNATURE----- iQFPBAABCAA5FiEEe7vIQRWZI0iWSE3xu+CwddJFiJoFAmqjuAUbFIAAAAAABAAO bWFudTIsMi41KzEuMTIsMiwyAAoJELvgsHXSRYia070H/RpgbPlRT+YF5EceAqlz gbCHYJa7ep52uCIZSgHd0DpMiE3jF8tRtLlpaF2l961hYXIr+NhEC9HKerJcD5tc 4LUpGu6Cs5/ruYz7fbAltYrAZ2YOAhaJwBBy0Buc2Xl37OpONR8hUWMYlqqXBSWM bApp9mrRYzLmQBpYn5N1KyZU9gBespiouCnStEUzD2s06VjnHSUJ5tBplbXXPC0v My/kjaUim9z0P91FHPFooFQtzhlLQI96obROsbKR18euePml+C+XPhhmDwAY0NVT VtAPm2ov7oTvy0FvjDAVzAdrYGIIXVluonJqhgLFi6+Um1L3iBE39Q2OEMiQ/Lq3 044= =B/eP -----END PGP SIGNATURE----- Merge tag 'slab-for-7.3-rc2' of git://git.kernel.org/pub/scm/linux/kernel/git/mm/slab Pull slab fixes from Vlastimil Babka: - Stable fix for an ABA issue causing slab list corruption introduced in 7.2 (Harry Yoo, with big thanks to Hyunwoo Kim for the thorough report and initial version of the fix) - Fix for 7.3 regression of kvfree_rcu() on PREEMPT_RT which can cause a deadlock from the set_cpus_allowed_force() caller (Vlastimil Babka) * tag 'slab-for-7.3-rc2' of git://git.kernel.org/pub/scm/linux/kernel/git/mm/slab: mm/slab: take n->list_lock in __slab_try_return_freelist() to avoid race mm/slab: disallow kfree_rcu_sheaf() on PREEMPT_RT again |
||
|
|
815e07c8fe |
ring-buffer: Acquire the lock with irqsave in rb_wake_up_waiters()
rb_wake_up_waiters() is a irq_work callback which is initialized with
init_irq_work(). As such it will be invoked in thread context on
PREEMPT_RT. Invoking the callback in IRQ context on PREEMPT_RT is not an
option due its usage of wake_up_all(). Since this callback may run in
thread context, it needs to acquire ring_buffer_per_cpu::reader_lock with
disabling interrupts and may not assume that they are disabled.
Use raw_spinlock_irqsave() to acquire ring_buffer_per_cpu::reader_lock.
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260911102152.YEtwkBj9@linutronix.de
Fixes:
|
||
|
|
ed0aff60f8 |
tracing: Take trace_array reference when opening a tracer options file
When a tracer option file is opened, it is passed a descriptor that points
to an element on the trace_array's topts array. This element has
information to find the trace array and other information. It uses this
element to take a reference of the trace_array so that the trace_array
does not get removed while this file is opened.
Unfortunately, there's a race condition where the element itself could be
freed by the removal of the instance the trace_array represents causing a
use-after-free as this element that is used to find the trace_array to
increment its reference counter is also freed when the instance is
removed.
To solve this, add a trace_array_tracer_options_get() helper function that
will take the address of the element that is passed to the open function
by the inode->i_private pointer and search all the trace_arrays under a
lock to find the one that the element's address is in the range of the
trace_arrays topts array elements. When a match happens, that trace_array's
reference would be increased.
Note, there's a race where if an admin was deleting and creating trace
instances at the same time and the memory of the old trace_array's array
matched the memory of the new trace_array that it could in theory open the
option from the wrong trace array. But we do not care because it would be
stupid to perform that kind of action. As long as the only thing that can
happen is that the option from the wrong trace array is used and doesn't
crash the kernel it will only make the user confused. But if they are
doing something stupid like this, they are already confused, so no harm
done.
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260910221209.62dad8d3@robin
Fixes:
|
||
|
|
7e645147df |
tracing: Fix ring_buffer_read_page_size() kernel-doc
ring_buffer_read_page_size() takes a parameter named rpage, but its
kernel-doc describes page. As a result, kernel-doc reports rpage as
undescribed and page as an excess parameter description.
Rename the documentation entry to match the function.
Link: https://patch.msgid.link/20260909062917.89482-1-kmehltretter@gmail.com
Fixes:
|
||
|
|
911002e99e |
tracing: Restore :mod: trailer after parsing in ftrace_set_clr_event()
While ftrace_set_clr_event() modifies its input buffer during parsing,
before returning to the caller the buffer is supposed to be restored
to its original state.
This works correctly for the colon between the subsystem and event
but not the colon at the beginning of :mod:.
Restore the colon, so the :mod: trailer is not stripped after
ftrace_set_clr_event().
Cc: stable@vger.kernel.org
Fixes:
|
||
|
|
7f711e6235 |
tracing: Fix memory corruption from a "STACKTRACE" histogram key
"cpu", "CPU", "stacktrace" and "STACKTRACE" are generic fields, defined
with an offset and a size of zero so that the filter code can match them
by name. parse_field() maps them onto their common_* equivalents for
backward compatibility, but unlike the common_* names it hands the
placeholder back to the caller instead of NULL.
create_hist_field() takes a non-NULL field as a promise that the record
carries a stacktrace and picks HIST_FIELD_FN_STACK, so the __data_loc
word is read from offset 0, that is from common_type, and its low 16
bits are followed as an offset into the record. What is found there
becomes the length of an unbounded memcpy. Pick an event whose id is
small enough that the offset stays inside its own record and the length
is a kernel text address:
# cd /sys/kernel/tracing
# echo 'hist:keys=STACKTRACE' > events/ftrace/print/trigger
# echo hello > trace_marker
Oops: general protection fault, probably for non-canonical address
RIP: 0010:rb_next+0x23/0x60
</IRQ>
RIP: 0010:memcpy+0xc/0x30
event_hist_trigger+0x2e7/0x12c0
Kernel panic - not syncing: Fatal exception in interrupt
Leave the field NULL, which is what the comment above the branch says
the code does and what common_stacktrace already does. FILTER_CPU and
FILTER_COMM are left alone, their create_hist_field() branches never
look at the field.
Cc: stable@vger.kernel.org
Fixes:
|
||
|
|
a5e70ba87c |
tracing: Fix memory corruption from the histogram stacktrace modifier
parse_field() sets HIST_FIELD_FL_STACKTRACE from the ".stacktrace"
modifier before it looks the field name up, and nothing afterwards
checks that the name resolved to a field which holds a stacktrace.
create_hist_field() picks HIST_FIELD_FN_STACK on the strength of the
field pointer alone, which reads a __data_loc word from the record and
follows its low 16 bits as an offset into the same record.
event_hist_trigger() takes the first word there as an entry count and
copies that many longs into a 31 entry array:
n_entries = *stack;
memcpy(entries, ++stack, n_entries * sizeof(unsigned long));
Neither end of that copy is bounded, and the count is whatever the event
holds at the offset, so any field will do:
# cd /sys/kernel/tracing/events/sched/sched_process_fork
# echo 'hist:keys=parent_pid.stacktrace' > trigger
# (true)
BUG: kernel NULL pointer dereference, address: 0000000000000008
RIP: 0010:rb_insert_color+0x18/0x130
timerqueue_linked_add+0x7e/0xd0
enqueue_hrtimer+0x39/0xb0
__hrtimer_run_queues+0x10f/0x1f0
</IRQ>
RIP: 0010:memcpy+0xc/0x30
event_hist_trigger+0x165/0x690
The timer interrupt landed on the rbtree the copy had already run over.
No debug options are needed for this; KASAN reports the same write as an
out-of-bounds read of 13835058055416381440 bytes.
Documentation/trace/histogram.rst already states the rule, "must be a
long[] type", so enforce it once the name has been resolved. Names which
resolve to no field at all, "hitcount.stacktrace" and the common_*
pseudo-fields, are refused for the same reason: they hold no stacktrace
to read.
Cc: stable@vger.kernel.org
Fixes:
|
||
|
|
92383cef66 |
tracing: Undo the registration when enabling the histogram trigger fails
Commit |