Commit Graph

1478381 Commits

Author SHA1 Message Date
Linus Torvalds
ce14fe4cd7 There are thirty-three client fixes:
- five sensitive data leak fixes (clear stack and heap cryptographic
   keys/hashes)
 - six file size and cache synchronization fixes (fscache cookie
   serialization and truncation handling)
 - seven protocol validation and buffer safety fixes (prevent OOB
   access and loff_t underflow)
 - six metadata and POSIX attribute fixes (proper hard-link counts and
   setuid/setgid stripping)
 - three DFS cache and unmount fixes (prevent target-hint UAF and
   unmount hangs)
 - six general client improvements (fix read request leaks, stats
   loops, handle servers that don't support O_TMPFILE)
 -----BEGIN PGP SIGNATURE-----
 
 iHUEABYKAB0WIQTcqRusfSdYROJQwGkpVtNKoQNdYwUCaoy9dgAKCRApVtNKoQNd
 Y5zrAP9HRp0z9rLmezHzGoTnF+0WYnkE9xK9pqRDoIjflXPyDAD+IDYzBXTWJpoq
 O1+3OiuNGvoF+X46i8xE9voAbnCTDgM=
 =ETzr
 -----END PGP SIGNATURE-----

Merge tag 'cifs-fixes-7.3-rc1' of https://git.manguebit.org/linux

Pull smb client updates from Paulo Alcantara:

 - clear sensitive data after use (stack and heap cryptographic
   keys/hashes)

 - file size and cache synchronization fixes (fscache cookie
   serialization and truncation handling)

 - protocol validation and buffer safety fixes (prevent OOB access and
   loff_t underflow)

 - metadata and POSIX attribute fixes (proper hard-link counts and
   setuid/setgid stripping)

 - DFS cache and unmount fixes (prevent target-hint UAF and unmount
   hangs)

 - general client improvements (fix read request leaks, stats loops,
   handle servers that don't support O_TMPFILE)

* tag 'cifs-fixes-7.3-rc1' of https://git.manguebit.org/linux: (33 commits)
  cifs: fix loff_t underflow in cifs_remap_file_range() when len == 0
  smb: client: reject a tree connect response whose byte count is too small
  cifs: call pagecache_isize_extended() in cifs_setsize() when extending
  smb: client: fix copy-paste error in WSL EA length accounting for $LXDEV
  smb: client: remove redundant NULL check before kfree()
  smb: client: restore the data_offset bound in is_valid_oplock_break()
  cifs: clear tcon after cifsFileInfo_put() in cifs_file_set_size()
  smb: client: Avoid leaking sensitive data to the heap in connect.c
  smb: client: Clear sensitive stack data in smb1encrypt.c
  smb: client: Clear sensitive stack data in cifsencrypt.c
  smb: client: Clear sensitive stack and heap data in smb2ops.c
  smb: client: Clear sensitive stack data in smb2transport.c
  Revert "cifs: remove all cifs files before kill super"
  smb: client: fix use-before-check of ReparseDataLength in reparse_buf_ptr()
  smb: client: fix ALIGN() overflow in symlink_data() error context loop
  smb: client: simplify __build_path_from_dentry_optional_prefix()
  smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed secondary T2
  smb: client: fix OOB read/write from unvalidated DataOffset in coalesce_t2()
  smb/client: decode reparse metadata using its payload type
  smb/client: preserve open info type across compound queries
  ...
2026-08-24 18:11:49 -07:00
Frank Sorenson
6c322f5cf7 cifs: fix loff_t underflow in cifs_remap_file_range() when len == 0
With len == 0 (clone to EOF), the effective length is computed as:

    len = src_inode->i_size - off;

If off > i_size, this is a negative loff_t, corrupting the ByteCount
in the FSCTL_DUPLICATE_EXTENTS_TO_FILE request and inverting the range
in filemap_write_and_wait_range().  The existing off >= i_size check
fires only after the ioctl has already been sent.

Snapshot i_size_read() once for both the bounds check and the length
calculation, eliminating the TOCTOU and 32-bit torn-read risk.  Reject
off > src_size with -EINVAL.  Treat off == src_size as a no-op,
consistent with __generic_remap_file_range_prep().

Fixes: 04b38d6012 ("vfs: pull btrfs clone API to vfs layer")
Cc: stable@vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
Reviewed-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
2026-08-24 17:08:53 -03:00
Bryam Vargas
65deb18359 smb: client: reject a tree connect response whose byte count is too small
CIFSTCon() bounds its strnlen() over the byte area with the server's
ByteCount minus two, which for ByteCount 0 or 1 goes negative as an int
and converts to a huge size_t.  The later subtraction wraps the __u16
bytes_left, and that is what bounds cifs_strndup_from_utf16(): a bound of
up to 65535 against a ~16 KB cifs_req_poolp object runs off the end of the
slab object, and the bytes reach userspace through tcon->nativeFileSystem
in /proc/fs/cifs/DebugData.

Reject a byte area too small for what the parser consumes.  Two bytes is
the least it can consume, and no conformant response carries fewer.  The
new trace point is the 129th smb_eio_trace entry, which __mode(byte)
cannot represent, so the attribute goes with it.

Fixes: cc20c031bb ("cifs: convert CIFSTCon to use new unicode helper functions")
Cc: stable@vger.kernel.org
Signed-off-by: Bryam Vargas <hexlabsecurity@proton.me>
Reviewed-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
2026-08-24 17:08:53 -03:00
Frank Sorenson
c510edb973 cifs: call pagecache_isize_extended() in cifs_setsize() when extending
cifs_setsize() calls truncate_pagecache() but skips
pagecache_isize_extended() on extension.  truncate_setsize() shows
the correct pattern:

  i_size_write(inode, newsize);
  if (newsize > oldsize)
      pagecache_isize_extended(inode, oldsize, newsize);
  truncate_pagecache(inode, newsize);

pagecache_isize_extended() zeroes the tail of the page straddling old
EOF.  Without it, dirty bytes in that region can be written back to
the server, exposing stale data in the newly extended range.

Cc: stable@vger.kernel.org
Cc: David Howells <dhowells@redhat.com>
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
Acked-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
2026-08-24 17:08:53 -03:00
Frank Sorenson
5d14030b46 smb: client: fix copy-paste error in WSL EA length accounting for $LXDEV
The LXDEV block in cifs_query_path_info() uses SMB2_WSL_XATTR_MODE_SIZE
(4) instead of SMB2_WSL_XATTR_DEV_SIZE (8), undercounting eas_len by 4
bytes per $LXDEV EA.

eas_len is used only as a zero/non-zero presence flag so there is no
current functional impact, but the value is incorrect and misleading.

Fixes: 97db41604555 ("smb: client: parse uid, gid, mode and dev from WSL reparse points")
Cc: stable@vger.kernel.org
Cc: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
Acked-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
2026-08-24 17:08:53 -03:00
Mohammad Shahid
019716ca26 smb: client: remove redundant NULL check before kfree()
kfree() safely handles NULL pointers, so the explicit NULL check
before calling kfree() is unnecessary.

This issue was reported by ifnullfree.cocci.

Signed-off-by: Mohammad Shahid <mdshahid03@gmail.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
2026-08-24 17:08:53 -03:00
Bryam Vargas
ba22f575de smb: client: restore the data_offset bound in is_valid_oplock_break()
Commit 83bfbd0bb9 ("cifs: Remove the RFC1002 header from smb_hdr")
changed the quantity this bound is measured against.  It used to be
srv->total_read minus the 4-byte RFC1002 preamble that total_read then
included, so it was the SMB message length.  The same commit stopped
counting the preamble, and the mechanical substitution to
srv->total_read - srv->pdu_size left an expression that is identically
zero: standard_receive3() reads MID_HEADER_SIZE() bytes and then exactly
pdu_length - MID_HEADER_SIZE() more, adding both to total_read.

len is therefore 0, the subtraction below it wraps, and no __u32
DataOffset can exceed the result, so the check from commit 097f5863b1
("cifs: read overflow in is_valid_oplock_break()") no longer rejects
anything.  Use total_read, which is now the message length on its own.

Fixes: 83bfbd0bb9 ("cifs: Remove the RFC1002 header from smb_hdr")
Cc: stable@kernel.org
Signed-off-by: Bryam Vargas <hexlabsecurity@proton.me>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
2026-08-24 17:08:53 -03:00
Frank Sorenson
b96db32fed cifs: clear tcon after cifsFileInfo_put() in cifs_file_set_size()
When the else branch of cifs_file_set_size() finds a writable file handle
via find_writable_file(), it borrows tcon and server from the handle's
tlink, attempts the handle-based set_file_size() RPC, and then releases
the handle with cifsFileInfo_put().

If set_file_size() fails, execution falls through to the path-based
fallback, which reuses the borrowed tcon and server under the
"if (tcon == NULL)" guard.  Since tcon is not NULL at that point, the
guard is skipped.  If cifsFileInfo_put() dropped the last reference on a
tlink that was already removed from the tlink tree (TCON_LINK_IN_TREE
cleared, as happens during reconnection or session teardown),
cifs_put_tlink() will have freed tcon; the subsequent set_path_size()
call is then a use-after-free.

Setting tcon = NULL after cifsFileInfo_put() causes the existing guard
to take the cifs_sb_tlink() path, which acquires a fresh reference for
the path-based operation or fails cleanly if the session is gone.

Fixes: 110fee6b9b ("smb: client: fix missing timestamp updates with O_TRUNC")
Cc: stable@vger.kernel.org
Cc: Paulo Alcantara <pc@manguebit.com>
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
2026-08-24 17:08:53 -03:00
Thomas Huth
111a2b8717 smb: client: Avoid leaking sensitive data to the heap in connect.c
TCP_Server_Info contains a preauth_sha_hash[] and a cryptkey[] array
that might contain sensitive data. Thus free its memory with
kfree_sensitive() to avoid that we are leaking this information to
the heap.

Signed-off-by: Thomas Huth <thuth@redhat.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
2026-08-24 17:08:53 -03:00
Thomas Huth
2f9af06e30 smb: client: Clear sensitive stack data in smb1encrypt.c
Make sure to not leak signature data via the stack, clear it
with memzero_explicit() before leaving the function.

To avoid that we have to introduce "goto"-cleanup here, we re-arrange
the code a little bit (and drop the commented cifs_dump_mem debug
code that looks like a leftover from very early days).

Signed-off-by: Thomas Huth <thuth@redhat.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
2026-08-24 17:08:53 -03:00
Thomas Huth
1a6bd74a27 smb: client: Clear sensitive stack data in cifsencrypt.c
Make sure to not leak hash data via the stack, clear it
with memzero_explicit() before leaving the function.

Signed-off-by: Thomas Huth <thuth@redhat.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
2026-08-24 17:08:53 -03:00
Thomas Huth
55a1ad8413 smb: client: Clear sensitive stack and heap data in smb2ops.c
Make sure to not leak key-related data via the heap or the stack
by using kfree_sensitive() or memzero_explicit() here.

Signed-off-by: Thomas Huth <thuth@redhat.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
2026-08-24 17:08:53 -03:00
Thomas Huth
3d93986f68 smb: client: Clear sensitive stack data in smb2transport.c
Sensitive data like keys that are stored in stack-local arrays could
be leaked via the stack to the calling functions. There is no known
vulnerability for this right now, but it's good security style to
explicitly zeroize this sensitive material as soon as possible to
avoid that it could be exploited together with other bugs later.

Signed-off-by: Thomas Huth <thuth@redhat.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
2026-08-24 17:08:53 -03:00
Zizhi Wo
ce31ec06d3 Revert "cifs: remove all cifs files before kill super"
This reverts commit 6d9a4aaaa8.

First, directly flushing fileinfo_put_wq in that commit cannot guarantee
that all in-flight I/O has run its cleanup_work on system_dfl_wq and
subsequently called queue_work(fileinfo_put_wq, ...). Flushing only the
latter workqueue may therefore miss puts that have not yet been queued, so
the fix is not reliable in the first place. Moreover, this fix flushes
inside cifs_umount(), which means the busy-dentry warning can still be
triggered when umount_check() is called inside kill_anon_super(), because
kill_anon_super() is executed before cifs_umount().

Second, commit 75f5c412fa ("smb: client: fix busy dentry warning on
unmount after DIO") already drains both serverclose_wq and fileinfo_put_wq
in cifs_kill_sb(), before kill_anon_super(). By adding a per-superblock
outstanding-rreq counter, it guarantees that all cleanup_work for this sb
have run, and thus all relevant cfile puts are queued on fileinfo_put_wq
or serverclose_wq.

Third, no path between those drains and cifs_umount() can queue new work
onto either workqueue. In the "cifs_sb->root == NULL" path there are no
file-related workers either, so that case is safe as well.

Therefore the busy-dentry and null-ptr-deref problems cannot arise, and
the flush added by commit 6d9a4aaaa8 ("cifs: remove all cifs files before
kill super") is redundant and can be removed.

Signed-off-by: Zizhi Wo <wozizhi@huawei.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
2026-08-24 17:08:53 -03:00
Frank Sorenson
05f78e6cf3 smb: client: fix use-before-check of ReparseDataLength in reparse_buf_ptr()
reparse_buf_ptr() reads buf->ReparseDataLength before checking that
count covers the full fixed header:

    buf = (struct reparse_data_buffer *)((u8 *)io + off);
    len = sizeof(*buf);                          /* 8 bytes */
    rdlen = le16_to_cpu(buf->ReparseDataLength); /* offset 4, 2 bytes */

    if (count < len || count < rdlen + len)      /* check comes after */

struct reparse_data_buffer has ReparseDataLength at offset 4.  If a
server returns OutputCount < 6, the read at offset 4-5 reaches past
the end of the received data.  The off+count bounds against iov_len
were already validated, but that does not protect against count being
smaller than sizeof(*buf).

Split the check: verify count >= sizeof(*buf) before reading
ReparseDataLength, then verify count covers the data region.

Fixes: a158bb66b137 ("smb: client: optimise reparse point querying")
Cc: stable@vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
2026-08-24 17:08:53 -03:00
Frank Sorenson
62656b024e smb: client: fix ALIGN() overflow in symlink_data() error context loop
The check added by commit 7d9a7f1f96 ("smb/client: fix possible
infinite loop and oob read in symlink_data()") compared the post-ALIGN
length against the remaining buffer, but ALIGN() itself can overflow:
for ErrorDataLength near UINT32_MAX (e.g. 0xFFFFFFF9), ALIGN(x, 8)
wraps to 0, so the subsequent bounds check passes, and the loop
advances by zero bytes leaving 'p' pointing into stale data.

Fix by checking the raw ErrorDataLength against the remaining space
before applying ALIGN(), then checking again after.  Since raw_len is
bounded by the buffer, raw_len + 7 cannot overflow, so the second check
is an exact post-alignment bounds guard.

Fixes: 76894f3e2f ("cifs: improve symlink handling for smb2+")
Cc: stable@vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
2026-08-24 17:08:53 -03:00
Dmitry Antipov
3fffaa8a64 smb: client: simplify __build_path_from_dentry_optional_prefix()
Use the convenient 'strreplace()' to simplify
'__build_path_from_dentry_optional_prefix()'.

Signed-off-by: Dmitry Antipov <dmantipov@yandex.ru>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
2026-08-24 17:08:53 -03:00
Frank Sorenson
730d0bb195 smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed secondary T2
When a valid primary TRANSACT2 response has been received (mid->resp_buf
set, mid->multiRsp true) and a subsequent secondary response causes
cifs_check_trans2() to return false -- either because the SMB header is
invalid (malformed != 0) or because check2ndT2() rejects the PDU --
handle_mid() overwrites mid->resp_buf with the new buffer (leaking the
primary buffer) and, because mid->multiRsp is set, skips the
server->smallbuf/bigbuf NULL-out.  When the user thread frees
mid->resp_buf, server->smallbuf or server->bigbuf is left dangling; the
demux thread reuses it for the next packet, resulting in a use-after-free.

Combine both early-exit conditions and, when mid->multiRsp is already
set, abort the pending transaction inline: set multiEnd, call
dequeue_mid() with malformed=true, and return true so handle_mid() exits
without touching mid->resp_buf or the server buffer pointers.

Fixes: 316cf94a91 ("CIFS: Move trans2 processing to ops struct")
Cc: stable@vger.kernel.org # cifs_check_trans2() is in smb1ops.c on kernels < 7.0
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
2026-08-24 17:08:53 -03:00
Frank Sorenson
6343c1da56 smb: client: fix OOB read/write from unvalidated DataOffset in coalesce_t2()
coalesce_t2() computes data pointers directly from server-supplied
DataOffset fields with no validation against buffer bounds:

  data_area_of_tgt = (char *)&pSMBt->hdr.Protocol +
                     get_unaligned_le16(&pSMBt->t2_rsp.DataOffset);
  data_area_of_src = (char *)&pSMBs->hdr.Protocol +
                     get_unaligned_le16(&pSMBs->t2_rsp.DataOffset);
  data_area_of_tgt += total_in_tgt;
  ...
  memcpy(data_area_of_tgt, data_area_of_src, total_in_src);

A small DataOffset can push a pointer below the actual byte area,
overwriting header fields; a large one can push it past the buffer
end, causing out-of-bounds heap reads (source) or writes (target).
The BCC overflow guard does not prevent this: BCC reflects how much
data is present, while DataOffset controls where in the buffer it
starts.

The "validate target area" comment present since the function was
first written in 2005 was a placeholder that was never implemented.

Add lower- and upper-bound checks for both data pointers before the
memcpy, and before any target header fields are modified.

Fixes: e4eb295d38 ("[PATCH] cifs: Handle multiple response transact2 part 1 of 2")
Cc: stable@vger.kernel.org
Reported-by: Shen Yongchao <grayhat@foxmail.com>
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
2026-08-24 17:08:53 -03:00
Ze Tan
43549eb842 smb/client: decode reparse metadata using its payload type
cifs_open_info_data stores FILE_ALL_INFORMATION and SMB3 POSIX query
information in a union. reparse_info_to_fattr() selects a union member
from the mount mode, while several directory checks always read
fi.Attributes.

The metadata can instead come from an SMB2 CREATE response on a POSIX
mount, or from a POSIX query while processing a reparse point. In those
cases the mount mode and hard-coded fi accesses select the wrong union
member.

See the procedures below:

  cifs_nt_open
    smb2_open_file
      SMB2_open
        data->fi = SMB2 CREATE response
        data->contains_posix_file_info = false
    cifs_get_inode_info
      reparse_info_to_fattr
        if (tcon->posix_extensions) // true
          smb311_posix_info_to_fattr
            data->posix_fi // wrong union member

  smb311_posix_get_fattr
    smb2_query_path_info
      smb2_compound_op
        data->posix_fi = SMB3 POSIX query response
        data->contains_posix_file_info = true
    reparse_info_to_fattr
      data->fi.Attributes // wrong union member

Add a common DOS attribute accessor and use contains_posix_file_info
both for attribute reads and for the final fattr conversion.

Signed-off-by: Ze Tan <tanze@kylinos.cn>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
2026-08-24 17:08:53 -03:00
Ze Tan
9437f2113b smb/client: preserve open info type across compound queries
contains_posix_file_info describes the metadata stored in the
fi/posix_fi union. GET_REPARSE and QUERY_WSL_EA do not update that
union, so clearing the flag while processing those responses can make
POSIX metadata look like FILE_ALL_INFORMATION.

Set the flag when CREATE or a validated query response actually
populates the union, and leave it unchanged for auxiliary compound
operations. This also avoids changing the type when a query fails
before copying any metadata.

The issue can be reproduced against a Samba server with SMB3 UNIX
extensions enabled:

  mount -t cifs //<server>/<share> /mnt/cifs \
        -o vers=3.1.1,posix,reparse=nfs,actimeo=0
  mkfifo /mnt/cifs/test-fifo
  umount /mnt/cifs
  mount -t cifs //<server>/<share> /mnt/cifs \
        -o vers=3.1.1,posix,reparse=nfs,actimeo=0
  stat -c '%F %s' /mnt/cifs/test-fifo

Before this change, stat reports "fifo 1024" although the server-side
EOF is zero. After this change, it reports "fifo 0".

Fixes: 9df23801c8 ("smb311: failure to open files of length 1040 when mounting with SMB3.1.1 POSIX extensions")
Signed-off-by: Ze Tan <tanze@kylinos.cn>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
2026-08-24 17:08:52 -03:00
Ze Tan
ebdc1afb1e smb/client: mark missing nlink values as unknown
Several SMB1 fallback and open responses do not provide the hard link
count. The SMB2 create-only query fallback has the same limitation.
These paths currently leave a zero link count or synthesize a value of
one and then expose it as authoritative metadata.

Mark those results with unknown_nlink so existing inodes keep their
cached link count and new inodes receive the usual sane default.

This was tested against Samba with "server min protocol = NT1". Mount
the share using SMB1 with Unix extensions disabled:

  mount -t cifs //<server>/<share> /mnt/cifs \
        -o username=<user>,vers=1.0,nounix

Create three names for the same inode and cache its real link count:

  TESTDIR=/mnt/cifs/nlink-repro-$$
  mkdir "$TESTDIR"
  touch "$TESTDIR/file1"
  ln "$TESTDIR/file1" "$TESTDIR/file2"
  ln "$TESTDIR/file1" "$TESTDIR/file3"
  stat -c 'before open: %h' "$TESTDIR/file1"

Open the file and read the link count through the open descriptor:

  exec 3<"$TESTDIR/file1"
  stat -Lc 'after open: %h' /proc/$$/fd/3
  exec 3<&-

Clean up the test files:

  rm -f "$TESTDIR/file1" "$TESTDIR/file2" "$TESTDIR/file3"
  rmdir "$TESTDIR"

Before this change, the two stat commands report 3 and 1 because the
SMB1 open response overwrites the known link count. With this change,
both commands report 3.

Signed-off-by: Ze Tan <tanze@kylinos.cn>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
2026-08-24 17:08:52 -03:00
Frank Sorenson
48cab1fd57 cifs: fix clearing stats for fastest execution of each smb2 command
The code to clear the 'fastest_cmd' statistics has a typo that
repeatedly clears the stat for cmd 0, rather than iterating
through each cmd.  Fix the typo (0->i).

Fixes: 433b8dd767 ("SMB3: Track total time spent on roundtrips for each SMB3 command")
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
2026-08-24 17:08:52 -03:00
Linus Torvalds
66498c75b4 dmaengine updates for v7.3
Core:
   - New API to combine configuration and preparation and users
 
  New Support:
   - Mediatek MT8189 SoC uart dma support
 
  Updates:
   - Designware dma driver flatten desc structures and simplify code,
     interrupt-path groundwork changes, first part of PCI EP DMA support
   - Updates to zynqmp_dma with runtime PM and device removal improvments
   - Xilinx dma optimizations for AXIDMA and MCDMA channel management
 -----BEGIN PGP SIGNATURE-----
 
 iQIyBAABCgAdFiEE+vs47OPLdNbVcHzyfBQHDyUjg0cFAmqMgZEACgkQfBQHDyUj
 g0e82w/4oLwj2QUjUO3QEO2l4E/RVS2/7UyCYKoJDAh66aM8Z3QjQ+lUvy+4wHHE
 H8AtTpRzGEPpqqU+BckHEySf8mNhlA4ULhX17aPc+NKqYNlW8p2L63kPFYggI1ja
 Z6/zVFrJDLwWTI0bSxAyJ6OoaObSXY0P6qpMcXKcqoHc981+EHMGrt/iVJM4Et/c
 Q6nFMxIMgxYPI1VCMSrJqOBA4ZvymyWBisJPZf6SK0iH3PnaBnGWWWilpT8eUJxm
 /MbVf2aUMetdK1+QVx1nNQUdb1eyAw50zFgbeDFDTXQ85Mfbvwh8XxxuT4wXJS5b
 8MFwIEUq6iRgyjZYlykmFYBXw1A3SZWuWMUuMic4l13lw7dxk92wR31j99pIRaV3
 g2iykz+gzQNQ5RNPuo/9j0s26FAmMNxbFW1RPAMnoVc33vZakV4ueaYtIy7s7mMJ
 eDrE6YNDW24DWfWrSxkQGCW1qFGBUY20dXZ0sBmhUxpTLB0ubPZrWLvKKZe/qTUJ
 wmrGNtTBLAYJMsGBm5VMybXwrQXa2Hvqa6KKFR2TdjpdcJwyWVHzRPpR+sJ7GfxZ
 Lz59ODW3x1MnukRQS/T+RXGT42Tzk+qQQ+xK/yCrXq0VkxE3010n7SglTEEygGYP
 Zk2eos4fARpXOUNqAxoKTVRyvQBxrIrHuJuQjAys2RhLHARuCQ==
 =lUcr
 -----END PGP SIGNATURE-----

Merge tag 'dmaengine-7.3-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/vkoul/dmaengine

Pull dmaengine updates from Vinod Koul:
 "Core:

   - New API to combine configuration and preparation and users

  New hardware support:

   - Mediatek MT8189 SoC uart dma support

  Updates:

   - Designware dma driver flatten desc structures and simplify code,
     interrupt-path groundwork changes, first part of PCI EP DMA support

   - Updates to zynqmp_dma with runtime PM and device removal
     improvments

   - Xilinx dma optimizations for AXIDMA and MCDMA channel management"

* tag 'dmaengine-7.3-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/vkoul/dmaengine: (73 commits)
  dmaengine: dw-edma: Mark emulated IRQ as level-triggered
  dmaengine: idxd: assign all engines to group 0 in IAA defaults
  dmaengine: qcom_hidma: remove conditional return with no effect
  dmaengine: qcom-bam-dma: fix autosuspend cleanup during removal
  dmaengine: fsl-edma: tracing: no ptr dereference during log output
  dmaengine: dw-edma: Program endpoint function numbers
  dmaengine: dw-edma-pcie: Add chip flags to match data
  dmaengine: dw-edma-pcie: Handle optional data blocks
  dmaengine: dw-edma-pcie: Factor out descriptor block address lookup
  dmaengine: dw-edma-pcie: Add register offset match flag
  dmaengine: dw-edma-pcie: Add platform ops to match data
  dmaengine: dw-edma-pcie: Rename vsec_data to dma_data
  dmaengine: dw-edma-pcie: Add capability match data
  dmaengine: dw-edma-pcie: Track non-LL mode in DMA data
  dmaengine: dw-edma: Add partial channel ownership mode
  dmaengine: dw-edma: Initialize IRQ data before requesting IRQs
  dmaengine: dw-edma: Add core quiesce operations
  dmaengine: dw-edma: Add per-channel interrupt routing control
  dmaengine: dw-edma: Factor out HDMA interrupt setup helper
  dmaengine: dw-edma: Defer channel IRQ handling to workqueue
  ...
2026-08-24 12:21:15 -07:00
Linus Torvalds
16e6a1a3cb phy updates for 7.3
As usual bunch of new device and driver support and updates to existing
 drivers and addition of Manivannan to help with reviews.
 
  - New Support
   - Mediatek MT8196 DSI PHY support
   - Renesas RZ/G3L usb2 support
   - Qualcomm SM8475 QMP USB PHY and PCIe phy, IPQ9650 QMP PCIe PHY, QUSB2
     Phy for Shikra SoC,  Hawi support for QMP PCIe phy and UFS PHY. Glymur
     QMP PCIe Multi-PHY driver and multiple link-mode support, ipq5210 PCIe
     phy support
   - Spacemit USB3/PCIe comb PHY driver
 
 - Updates
   - Samsung hdptx driver improvements for modernizing the register
     access and code cleanup
   - Qualcomm drop duplicate v8 DP headers, improved runtime handling for qmp
     drivers
   - Rockchip clock lane phase tuning and 2500 Mbps support and TMDS rate
     handling
   - Freescale imx8mq improvements for runtime pm, pd handling.
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEE+vs47OPLdNbVcHzyfBQHDyUjg0cFAmqMf1YACgkQfBQHDyUj
 g0cx8g/+M2Thg88JXJ1HIbcCD/Dh6gtsZHmnfW71EUxIE//QKV950PE1Oqu/Va7i
 Z9YRonkGjzyuYFJZixW/C8OzL5lqy1vp62t/qbUa1Q4UKawhI+ALEUBrWXkozxyR
 LKM9OSoNTxUa40vJrb54MkiouTrwGOhOPhf0LB6QaIDkQqae5/10uux5TsGdvU57
 pVDC2SIAZaYg4a3xcv0sFVORDuMhPMSGZyjDR2CDSaAdR3H4kau5mfY7+98w8T6u
 dt7wEWThUSFXTSPbHER3zj2JEHlaG/EcOzAmwy44ttqTdqP7X12O4nnJeDE08ymb
 /sib42WwQvL3OwXgzBOKOIF7P6g6691I15lMLIMtGj9j2wyimDchO7YGRcNxtJTt
 3x96YbWABmDbrQblWXZcKro/PG13i0tMxmm4W0HYcCtK5sCvhWpHjwV3n46y6Kuv
 cxgQpsrRwYNGWgMOai9X0ft5tXn5uqFyaGiolPBo7IlOLtbsTuG6Q2H8QbxJKokf
 KjiYofA0EXrp/DtBnSlA1x7S5ODTRi25soHTIvrlJlljls4vRrqV4ZU33peicDY5
 XbXlIX4XOu7pxNtDSpQYoWXnIIDo9/QfpJy4YUlVdGZTtLDcLW98Aqwxre/FWWUj
 c8FeNDGSj0vPaL7Pm8XF4PXmKTW6xjf2MToFcUlAcJsEFsfm1XM=
 =Hg5e
 -----END PGP SIGNATURE-----

Merge tag 'phy-for-7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/phy/linux-phy

Pull phy updates from Vinod Koul:
 "As usual bunch of new device and driver support and updates to
  existing drivers and addition of Manivannan to help with reviews.

  New Support:
   - Mediatek MT8196 DSI PHY support
   - Renesas RZ/G3L usb2 support
   - Qualcomm SM8475 QMP USB PHY and PCIe phy, IPQ9650 QMP PCIe PHY,
     QUSB2 Phy for Shikra SoC, Hawi support for QMP PCIe phy and UFS
     PHY. Glymur QMP PCIe Multi-PHY driver and multiple link-mode
     support, ipq5210 PCIe phy support
   - Spacemit USB3/PCIe comb PHY driver

  Updates:
   - Samsung hdptx driver improvements for modernizing the register
     access and code cleanup
   - Qualcomm drop duplicate v8 DP headers, improved runtime handling
     for qmp drivers
   - Rockchip clock lane phase tuning and 2500 Mbps support and TMDS
     rate handling
   - Freescale imx8mq improvements for runtime pm, pd handling"

* tag 'phy-for-7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/phy/linux-phy: (76 commits)
  MAINTAINERS: Add Manivannan Sadhasivam as the Reviewer for Generic PHY Framework
  phy: rockchip-samsung-dcphy: fix out-of-range max_register
  phy: qcom: qmp-pcie: Add QMP PCIe Multi-PHY driver
  dt-bindings: phy: qcom: Add Glymur QMP PCIe multiple link-mode PHY
  phy: rockchip: samsung-hdptx: Consistently use bitfield macros
  phy: rockchip: samsung-hdptx: Simplify GRF access with FIELD_PREP_WM16()
  phy: rockchip: samsung-hdptx: Drop restrict_rate_change handling
  phy: rockchip: samsung-hdptx: Consolidate consumer_put on error path
  phy: rockchip: samsung-hdptx: Drop TMDS rate setup workaround
  phy: rockchip: samsung-hdptx: Handle uncommitted PHY config changes
  phy: rockchip: samsung-hdptx: Fix rate recalculation for 3.2GHz FRL
  phy: rockchip: samsung-hdptx: Guard against clk rate integer underflow
  phy: rockchip: samsung-hdptx: Prevent divide-by-zero when computing clk rate
  phy: rockchip: samsung-hdptx: Fix rate recalculation for high bpc
  phy: qcom: qmp-combo: Drop qmp_v4_calibrate_dp_phy
  phy: qcom: qmp-combo: Correct pre-emphasis table for QMP v4 DP PHYs
  phy: renesas: rcar-gen3-usb2: Ignore missing VBUS regulator
  phy: qcom: qmp-pcie: Add support for SM8475 Gen3x1 PCIe0 port
  phy: qcom: qmp-pcie: Add pcs_lane1 offset to V5 offsets
  dt-bindings: phy: qcom,sc8280xp-qmp-pcie-phy: Add SM8475 QMP PHY
  ...
2026-08-24 12:19:23 -07:00
Linus Torvalds
ab9b9b51ba soundwire updates for 7.3
- Bunch of Intel dmi quirks ghost list handling for Asus Zenbook Duo, Asus
    ROG Zephyrus Duo and Asus Expertbook. Intel Peripheral
    bra_block_alignment handling
  - Cadence library BRA_NumBytes[8] support
  - Qualcomm SCP address paging, bus mclk_freq support. Increase of data
    ports to 17 and driver improvements.
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEE+vs47OPLdNbVcHzyfBQHDyUjg0cFAmqMd8kACgkQfBQHDyUj
 g0dBjg/+Po6cyEfCuBH88IMxUBrcpjODyRdKDMNdM3MxBxYTJQiJmQPO60OwLOR/
 EGDPDUTqrzDt5HwmalgnyM+gEl7aLknwMAmJoK0gCw9BiO/1RfcXPEmLdoIJtrzG
 r2GnDuGzQBpxP//af7/b3N89eTCI3HKBLCHpYapyqFrhbniKHO9uDYsnBTzgz4NI
 GK6WJU5hqx7n92zvruQZIkHYijhYgkRru566eOBx8sDhO+w9lELHDTm7TmW8Qrwo
 XV1jMlPep9edClwYT9MwfEXe8ICwh0gShM3kWrhdi/i1OeEsT0VCa1NzNh14OOuV
 h4LlT0byLDGvx1zzCeDPEG5ZRqO8wdNwe7/1HeR5VD9Sn0pcEZKDWbzFVsiWTnqG
 /QKGjbylbenKZHfaL5EvnyiWhEXLv2t0qiiSWGbT+qEGa2Jk+IL6vps3Kr6dhNcg
 7KZHs5KAag3DTNAtF/W6n7/Ut9rfz6GI4f7acDSfsHz3gRenLqPQmZeAQLX1rtMR
 /A24EMNWkan2ffxMIGgBigQ6WiAVyuUDQFLr1yefhjIGN3+WTTtE/gGaAn+8xbdd
 o1CBUneoRQ3WtdRCljhBIAfM4HdS1i4GxIdvqrcDu1jmIYLsxs2HJIs24uZOC6Mk
 KgnoJbHsiriJ5CvoM5s6eKBI9jsx6XdT/KsLyHwLvVvSnzczIRM=
 =rjmH
 -----END PGP SIGNATURE-----

Merge tag 'soundwire-7.3-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/vkoul/soundwire

Pull soundwire updates from Vinod Koul:

 - Intel dmi quirks ghost list handling for Asus Zenbook Duo,
   Asus ROG Zephyrus Duo and Asus Expertbook. Intel Peripheral
   bra_block_alignment handling

 - Cadence library BRA_NumBytes[8] support

 - Qualcomm SCP address paging, bus mclk_freq support. Increase of
   data ports to 17 and driver improvements

* tag 'soundwire-7.3-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/vkoul/soundwire:
  soundwire: dmi-quirks: Disable ghost Realtek on Asus ROG Zephyrus Duo
  soundwire: stream: validate slave port properties
  soundwire: honor clock_reg_supported in the clock scaling check
  soundwire: qcom: set the bus mclk_freq property
  soundwire: dmi-quirks: Disable ghost Realtek on Asus Zenbook Duo
  soundwire: intel_ace2x: handle the max_data_per_frame property
  soundwire: get mipi-sdw-bra-mode-max-data-per-frame property
  soundwire: intel: handle Peripheral bra_block_alignment
  soundwire: Add bra_block_alignment property support
  soundwire: cadence_master: add BRA_NumBytes[8] support
  soundwire: bus.h: repair kernel-doc comments
  soundwire: intel_auxdevice: Add cs42l44 to wake_capable_list
  soundwire: qcom: add SCP address paging support
  soundwire: dmi-quirks: add a global ghost list
  soundwire: dmi-quirks: Disable ghost Realtek on Asus Expertbook
  soundwire: qcom: Allocate sruntime array dynamically
  soundwire: qcom: Fix port exhaustion check in stream_alloc_ports
  dt-bindings: soundwire: qcom: Increase max data ports to 17
2026-08-24 12:16:16 -07:00
Linus Torvalds
2f43193b88 dma-mapping updates for Linux 7.3:
- swiotlb: added new configuration option for the default pool size
 (Jagadeesh Pagadala) and reduced overhead for high watermark tracking
 (chenhuguanshen)
 
 - minor code cleanups and improvements (Vova Sharaienko, Honglei Huang
 and Marek Szyprowski)
 -----BEGIN PGP SIGNATURE-----
 
 iHUEABYKAB0WIQSrngzkoBtlA8uaaJ+Jp1EFxbsSRAUCaoxGQgAKCRCJp1EFxbsS
 RFPEAP0eo9usjFcvh0YKTPh6/mXgqxRuTNQZ7i+2lRGEczKcJQEA7mwkgwpiOaKn
 f++mMVOmsPvl2Y7r/5XqBWywwhyygA0=
 =X8pY
 -----END PGP SIGNATURE-----
mergetag object 04a19b35dc
 type commit
 tag dma-mapping-7.3-2026-08-24-2
 tagger Marek Szyprowski <m.szyprowski@samsung.com> 1787582472 +0200
 
 second dma-mapping update for Linux 7.3:
 
 - important dma-mapping update for confidential-computing, which adds
 proper tracking of the shared DMA state through direct, pool and swiotlb
 paths (Aneesh Kumar K.V)
 -----BEGIN PGP SIGNATURE-----
 
 iHUEABYKAB0WIQSrngzkoBtlA8uaaJ+Jp1EFxbsSRAUCaoxYzgAKCRCJp1EFxbsS
 RM9bAP4mJuHHzj2DqsKV7QX19uhyzmsHIg+ecjBNRaOdUAgelQD9FsaG/fwrZnRT
 y89H0QUErqLsdmkDqV0zsXfaGzWY4gk=
 =dKjS
 -----END PGP SIGNATURE-----

Merge tags 'dma-mapping-7.3-2026-08-24' and 'dma-mapping-7.3-2026-08-24-2' of git://git.kernel.org/pub/scm/linux/kernel/git/mszyprowski/linux

Pull dma-mapping updates from Marek Szyprowski:

 - swiotlb:
     - new configuration option for the default pool size
       (Jagadeesh Pagadala)
     - reduce overhead for high watermark tracking (chenhuguanshen)

 - minor code cleanups and improvements (Vova Sharaienko, Honglei Huang
   and Marek Szyprowski)

 - add proper tracking of the shared DMA state through direct, pool and
   swiotlb paths (Aneesh Kumar K.V)

   This is important for confidential-computing

* tag 'dma-mapping-7.3-2026-08-24' of git://git.kernel.org/pub/scm/linux/kernel/git/mszyprowski/linux:
  dma/swiotlb: decouple high watermark tracking from CONFIG_DEBUG_FS
  MAINTAINERS: update tree for DMA MAPPING HELPERS
  dma/swiotlb: introduce Kconfig option for compile-time default pool size
  dma-direct: Improve readability of the dma_direct_map_sg() for P2PDMA case
  iommu/dma: simplify dma_iova_destroy() and drop the free_iova helper
  dma-coherent: use KiB in DMA allocation logs
  dma-coherent: fix spacing coding style issue

* tag 'dma-mapping-7.3-2026-08-24-2' of git://git.kernel.org/pub/scm/linux/kernel/git/mszyprowski/linux: (23 commits)
  swiotlb: remove unused SWIOTLB_FORCE flag
  dma: swiotlb: handle set_memory_decrypted() failures
  dma: swiotlb: free dynamic pools from process context
  dma-direct: rename ret to cpu_addr in alloc helpers
  dma-direct: select DMA address encoding from __DMA_ATTR_ALLOC_CC_SHARED
  dma-direct: set decrypted flag for remapped DMA allocations
  dma-direct: make dma_direct_map_phys() honor DMA_ATTR_CC_SHARED
  dma-direct: Move dma_direct_map_phys() to dma/direct.c
  dma-direct: pass attrs to dma_capable() for DMA_ATTR_CC_SHARED checks
  dma-mapping: make dma_pgprot() honor __DMA_ATTR_ALLOC_CC_SHARED
  dma: swiotlb: track pool encryption state and honor DMA_ATTR_CC_SHARED
  dma: swiotlb: pass mapping attributes by reference
  dma-pool: track decrypted atomic pools and select them via attrs
  dma-direct: use __DMA_ATTR_ALLOC_CC_SHARED in alloc/free paths
  dma-mapping: Add internal shared allocation attribute
  coco: arm64: s390: powerpc: Mark secure guests with CC_ATTR_GUEST_MEM_ENCRYPT
  dma-direct: swiotlb: handle swiotlb alloc/free outside __dma_direct_alloc_pages
  s390: Expose protected virtualization through cc_platform_has()
  swiotlb: Preserve allocation virtual address for dynamic pools
  dma: free atomic pool pages by physical address
  ...
2026-08-24 11:35:46 -07:00
Linus Torvalds
918e25291c slab changes for 7.3
-----BEGIN PGP SIGNATURE-----
 
 iQFPBAABCAA5FiEEe7vIQRWZI0iWSE3xu+CwddJFiJoFAmqMSHQbFIAAAAAABAAO
 bWFudTIsMi41KzEuMTIsMiwyAAoJELvgsHXSRYiaC8EH/ihctMRDnqbUxyc3cSIZ
 cuy3ocSSu8UnHzSNarylY8sVYIYflgY6owV7UvaUKmXGYHiHIDdI5NMDzpjola7X
 Ct7mpIuobFHpFhTQMqvYkeEQ3EytS7NPHKs3jd6t2HSOYJdY4lghjRZcxOlo7+GA
 5EJa468TSHswWbT34e3NY7gpoHCXTucR6FBqoVtluLOliQWNMkWbeDQ9hEnMoyNy
 hEdooWDxt8vBuSqVRCZxrgJRK2nauf1P/CHZm4HcNttOQp0iwr8Q7GER7dBpW0jR
 1b1zM9YPH4g6CSll5V6sWSMUNAaDx3Akx3ZyKhd3G2kyP3HkPXKSag/fS8xxCFLN
 hh0=
 =6lTR
 -----END PGP SIGNATURE-----

Merge tag 'slab-for-7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/vbabka/slab

Pull slab updates from Vlastimil Babka:

 - Add kfree_rcu_nolock() that can be used from contexts where spinning
   on a lock might be unsafe, such as a BPF program attached to an
   arbitrary function, or in NMI context. This complements the existing
   kfree_nolock() support (Harry Yoo)

 - Runtime instead of compile-time slabobj_ext sizing.

   Avoid wasting memory when memory allocation profiling is compiled but
   not enabled, with initial partial support to also avoid wasting
   memory for objcg pointers when those are not needed, while profiling
   is enabled (Vlastimil Babka)

 - Various non-urgent fixes, cleanups and optimizations (Hao Li,
   Hongling Zeng, Li RongQing, Li Xiasong, Seongjun Hong, Shengming Hu)

* tag 'slab-for-7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/vbabka/slab: (31 commits)
  mm/slab, kfence, memcg: completely remove obj_ext for kfence objects
  mm/slab: stop allocating objcg pointers when unnecessary
  mm/slab: add cache_ and slab_needs_objcg() helpers
  mm/slab: stop exporting kvfree_rcu_barrier[_on_cache]()
  slub_kunit: extend the test for kfree_rcu_nolock()
  mm/slab: introduce kfree_rcu_nolock()
  mm/slab: introduce struct kvfree_rcu_head for kvfree_rcu batching
  mm/slab: reduce slabobj_ext memory with allocation profiling disabled
  mm/slab: introduce slab_obj_ext_has_codetag()
  mm/slab: allow kfree_rcu_sheaf() on PREEMPT_RT
  mm/slab: extend deferred free mechanism to handle rcu sheaves
  mm/slab: use call_rcu() in unknown context if irqs are enabled
  mm/slab: handle the !allow_spin case in kfree_rcu_sheaf()
  mm/slab: change struct slabobj_ext to a union
  mm/slab: replace slab.stride with obj_exts_in_object
  mm/slab: abstract slabobj_ext.ref access
  mm/slab: abstract slabobj_ext.objcg access
  mm/slab: make slab_obj_ext() determine object index
  mm: move struct slabobj_ext to mm/slab.h
  mm/slab: remove objs_per_slab()
  ...
2026-08-24 10:58:57 -07:00
Linus Torvalds
a0300e8cf0 configfs changes for v7.3-rc1
-----BEGIN PGP SIGNATURE-----
 
 iQJKBAABCgA0FiEEV4rZyNlmdiYqwGqG+lApCKrFvdAFAmqMG1kWHGEuaGluZGJv
 cmdAa2VybmVsLm9yZwAKCRD6UCkIqsW90MdID/wOtlQoSX0AgF0P8caePJ460pag
 hny+JQsywMqR3nnFzbNW8mchGtKg643rS5ub3GexiJdj1ZS1++5haqAgVh0G3XSn
 kT9CZ9ndMWAzKC+QFfO7F34VLXYx5klZkjF5FJx/NGrNlxaH/gkVMYPbDsJX+FJu
 4YYqu/E7HQ6wPyA4jdnErRW/fBKSHJ9DosJ7L19u/xbXrStk1oRMQC2xHY3gnEuX
 3MEJOjm62mB3d2Syr42gjggL47hy0JDm38wI8akky7EvK7uOzhNE9Wk+cTpoUz7w
 zTTTr+N03jRPkrbFL3nHlGj38sUh3y7b1Ce650YvkRVIebo/2xKMhK+sZUnfmz/v
 aUEN0MrEzT05uYxZGtv96TtXm+980LVsJuARbvfrQAIeApGnkqm+x+AVSk2SaHXN
 kGtGUvOd+0XCPA1ZYxMkBcUOIDv5rLnlQrYAdWDq6OK4hjbL0I+qC0gbFZqtYKr8
 yn/0PNjNoz52qimdtxft280tKQT3jC0no3IOUOcEhgUl4ibpHOK5R0nAKdtHUMCE
 mo7XK2tsR/EfZkJRLhNaYIK2kF+kVmmY5LECZgbZeBaqQk+0f14bNhwwUANTE9DJ
 vsxEdsYDSSW+FKPxnrqnLvprJg1WOnjYORDhjkIArNJNawaPR1uaoJpQkanwUdnW
 j/SHjUoloWAAr35LAg==
 =fzXE
 -----END PGP SIGNATURE-----

Merge tag 'configfs-for-v7.3-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/a.hindborg/linux

Pull configfs update from Andreas Hindborg:
 "Update configfs MAINTAINERS entry.

  Breno Leitao will maintain configfs C code going forward. I will
  continue maintaining configfs Rust parts"

* tag 'configfs-for-v7.3-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/a.hindborg/linux:
  MAINTAINERS: configfs: split configfs entry in C and Rust parts
2026-08-24 10:51:49 -07:00
Linus Torvalds
5b05bb3f6c platform-drivers-x86 for v7.3-1
Highlights:
 
 - amd/halo: Add Halo RGB LED driver
 
 - amd/hsmp:
   - Properly serialize probe, remove, and data paths
   - Add support for protocol v7 used by Family 1AH Model 80H
   - Fix error checking corner cases (largely from AI review)
   - Reject negative power cap
 
 - amd/pmc:
   - Improve behavior on platforms that do not support STB
   - Add T14 Gen2 AMD (20XL) to s2idle quirk list
 
 - amd/pmf:
   - Add ioctl interface to retrieve device metrics
   - Add support for new metrics tables used by Family 1AH Model 80H
 
 - arm64: qcom-hamoa-ec: Reject short responses
 
 - asus-nb-wmi: Support ProArt key on ASUS ProArt PX13
 
 - asus-armoury:
   - Gate PPT writes behind active fan curve
   - Add power limits for more models
 
 - dell-wmi-base: Fix handling of ultra performance key
 
 - dell-wmi-sysman: Don't hex dump attribute security buffer
 
 - hp-bioscfg:
   - Various fixes
   - Improve reduced ACPI packages support (necessary for HP EliteBook 840 G2)
 
 - lg-laptop:
   - Fix LED resource handling
   - Add support for events used in newer models
   - Fix keyboard backlight support on LG Gram 16T90SP
 
 - hp-wmi:
   - Generalize thermal params to board params
   - Manage CPU and GPU PWM independently
   - Add GPU MUX switch support
   - Add Victus 15-fb0xxx support
   - Add OMEN MAX 16-ak0xxx, OMEN 16-n0xxx, OMEN 16-wd0xxx, OMEN
     16-wf0xxx, and OMEN board ID 8D88 support
   - Add OMEN Transcend 16-u0xxx support
 
 - huawei: Add support for Fn-lock ACPI interface found on newer Huawei
           laptops such as MateBook 14 2024
 
 - ISST:
   - Improve input validation (many fixes)
   - Disallow SST-CP (core-power) feature if perf profile add fails
 
 - lenovo/yb9-kbdock: Add driver for Yoga Book 9 14IAH10
 
 - lenovo/ymc:
   - Extend hinge switch query to support Yoga 9 2-in-1 14IPH11
   - Prevent loading on Yoga Book 9 14IAH10 to avoid duplicated input
     nodes
 
 - msi-ec: Add MSI Raider A18 HX A9WJG and MSI Katana GF76 11UEK support
 
 - msi-wmi: Add MSI Claw M-Center keys support
 
 - oxpec: Add support for OneXPlayer X2 Mini Pro
 
 - redmi-wmi: Report kbd backlight cycle, OEM preset power mode, and FnLock
              toggle events to userspace
 
 - samsung-galaxybook: Add Samsung Galaxy Book6 Pro support
 
 - thinkpad_acpi: Add USB-C Security support
 
 - uniwill-laptop:
   - Add keyboard backlight, AC auto boot, and USB powershare support
   - Add MACHENIKE L16 Pro, AiStone X4SP4NAL, and Avell A60 MUV support
   - Make lightbar max brightness configurable and add support for
     LAPQC71A/B
 
 - Major refactoring efforts:
   - Stop setting acpi_device_name/class() and pnp.device_class to
     faciliate their eventual removal
 
 - Many rollback/remove path fixes (presumably mostly found by AI)
 
 - Miscellaneous cleanups / refactoring / improvements
 
 The following is an automated shortlog grouped by driver:
 
 acer-wmi:
  -  reject missing gaming WMI results
 
 amd/hsmp:
  -  ACPI HSMP refcounted sockets and coordinated release
  -  Add HSMP messages for Family 1Ah, Model 50h-5Fh
  -  Add IOCTL_GET_TELEMETRY_DATA for metric table reads
  -  Clear mdev.this_device on deregister
  -  Enable protocol version 7 metric tables on the ACPI driver
  -  Gate the data plane on a fully initialized socket
  -  Map the metric table with ioremap() and unmap it explicitly
  -  Pass struct device explicitly to ACPI mailbox parsers
  -  Reject negative power cap writes in hwmon
  -  Serialize ACPI HSMP probe and remove with an rwsem
  -  Serialize per-socket metric table reads with a mutex
  -  Serialize the data plane against socket teardown
  -  Source metric-table size from firmware
  -  Unify response_sz validation to an upper-bound check
  -  Validate ACPI UID before parsing socket index
  -  Validate _DSD mailbox sub-package element count
 
 amd:
  -  Introduce Halo Box RGB LED driver
 
 amd/pmc:
  -  Add T14 Gen2 AMD (20XL) to s2idle quirk list
  -  Do not fail probe when STB init fails
  -  Fix LPS0 and debugfs leaks when STB init fails
  -  Fix msg_port restoration in amd_stb_debugfs_open_v2()
  -  Only expose stb_read after telemetry buffer is mapped
  -  Propagate SMU errors and validate S2D address
  -  Restore msg_port on amd_stb_s2d_init() error paths
 
 amd/pmf:
  -  Add 1AH_M80H device IDs and extended SMU mailbox registers
  -  Add 1AH_M80H metrics table and NPU metrics support
  -  Add missing newline in dev_err message
  -  Add util layer and userspace character device interface
  -  Implement util layer ioctl handler
  -  Introduce AMD PMF testing tool for driver metrics and features
  -  Move debug helper functions to UAPI header
  -  Move metrics code to dedicated file
  -  Refactor NPU metrics for platform extensibility
  -  store BIOS output values for user-space metrics via util IOCTL
  -  Store commonly used enums in the header file
  -  Use per-SoC smu_regs struct for SMU mailbox registers
  -  Use upper/lower_32_bits() in amd_pmf_set_dram_addr()
 
 arm64: qcom-hamoa-ec:
  -  reject incomplete responses
 
 asus-armoury:
  -  Add power limits for ROG Strix SCAR 16 (G635LX)
  -  Add power limits quirk for FA401KM
  -  Add power limits quirk for FA608WV
  -  add support for FX517ZR
  -  add support for HN7306EA and HN7306EAC
  -  fix Use-After-Free and memory leak in driver init
  -  gate PPT writes behind active fan curve
  -  use cleanup.h to manage tunables
 
 asus-laptop:
  -  Stop setting acpi_device_name/class()
 
 asus-nb-wmi:
  -  map ProArt key (0x8b) to KEY_PROG3
 
 asus-wireless:
  -  Fail probe when there is no ACPI match
 
 asus-wmi:
  -  fix resource leaks on probe failure
 
 dell-ddv:
  -  Use no_free_ptr() to simplify error handling
 
 dell-privacy:
  -  Fix race condition
 
 dell-smbios:
  -  Pass device to callbacks
 
 dell-smbios-wmi:
  -  Fix chardev resource management
  -  Replace global list with single item
 
 dell-wmi-base:
  -  Fix handling of ultra performance key
  -  Fix resource leak on module load failure
 
 dell-wmi-sysman:
  -  Don't hex dump attribute security buffer
  -  Fix instance ID bounds
 
 Documentation/ABI:
  -  add testing entry for AMD PMF character device interface
 
 eeepc-laptop:
  -  Stop setting acpi_device_name/class()
 
 fujitsu-laptop:
  -  Stop setting acpi_device_name/class()
 
 fujitsu-tablet:
  -  Stop setting acpi_device_name/class()
 
 hp-bioscfg:
  -  accept reduced ACPI packages from older HP BIOS
  -  advance elem past consumed array elements
  -  bound ordered-list parsing by the package count
  -  fix heap OOB read in sk_store() and kek_store()
  -  fix heap OOB read on empty password write
  -  fix new_password_store() overwriting current_password
  -  fix off-by-one write in hp_get_string_from_buffer()
  -  fix ORD_LIST_ELEMENTS never being parsed
  -  fix password encoding bounds check
  -  pass validated element count to package parsers
  -  warn on element type mismatch instead of failing
 
 hp-wmi:
  -  Add dual-channel PWM fan control
  -  Add GPU MUX switch support
  -  Add OMEN board 8A43 thermal profile support
  -  Add OMEN board 8BA9 thermal profile support
  -  Add OMEN board 8BAA thermal profile support
  -  Add OMEN board 8D88 thermal profile support
  -  Add OMEN Transcend 16 8BB3 support
  -  Add support for OMEN MAX 16-ak0xxx (8DD6)
  -  Add Victus 15-fb0xxx support
  -  Drive fan control from board data
  -  Introduce board-specific feature data
 
 huawei-wmi:
  -  add ACPI fallback for Fn-lock on newer models
 
 ideapad-laptop:
  -  Fix driver unregistration order
 
 int1092:
  -  Fix info leak in parse_package()
  -  Fix potential memory leak in sar_probe()
 
 intel/pmc:
  -  initialize empty PMT read result
 
 ishtp_eclite:
  -  Fix ACPI device reference leak in probe error path
 
 ISST:
  -  Add a NULL check for sst_inst[]
  -  Just allow 2 bits for SST feature enable
  -  Return error during profile addition
  -  Use PP level enable mask
  -  Validate level in perf mask ioctls
  -  Validate logical CPU id and clos id
  -  Validate max level for set feature
  -  Validate parameter for core power state
  -  Validate parameter for frequency and priority
  -  Validate socket ID in clos_assoc ioctl
 
 lenovo:
  -  Add Yoga Book 9 keyboard dock detection driver
 
 lenovo: lenovo-ymc:
  -  Suppress probe on Yoga Book 9 14IAH10
 
 lenovo/ymc:
  -  Only match lower byte in WMI lid switch query response
 
 lg-laptop:
  -  Add support for additional events
  -  Add support for native ACPI events
  -  Fix keyboard backlight support on LG Gram 16T90SP
  -  Fix LED resource handling
  -  Improve WMAB control method support
 
 MAINTAINERS:
  -  update Intel PMC Core maintainer contact
 
 mlxbf-bootctl:
  -  fix the build error with FIELD_PREP()
 
 mlxbf-pmc:
  -  Check ACPI_COMPANION() against NULL
 
 msi-ec:
  -  Add MSI Katana GF76 11UEK EC firmware
  -  Add MSI Raider A18 HX A9WJG EC firmware
 
 msi-wmi:
  -  Add MSI Claw M-Center keys
  -  Reformat msi_wmi_notify()
 
 oxpec:
  -  Add support for OneXPlayer X2 Mini Pro
 
 panasonic-laptop:
  -  Fix sentinel write past pcc->sinf[]
  -  Stop setting acpi_device_name/class()
 
 power: supply: surface_{battery,charger}:
  -  Consistently define ssam_device_ids using named initializers
 
 redmi-wmi:
  -  report EC state change events
 
 samsung-galaxybook:
  -  Add SAMB430 device ID
 
 sony-laptop:
  -  Stop setting acpi_device_class()
 
 sonypi:
  -  Stop setting acpi_device_name/class()
 
 surface: acpi-notify:
  -  Check ACPI companion before use
 
 surface: aggregator:
  -  Consistently define ssam_device_ids using named initializers
 
 surface: surfacepro3_button:
  -  Stop setting acpi_device_name()
 
 think-lmi:
  -  Fix certificate thumbprint sysfs output
  -  Fix current password length check
  -  Free system certificate signatures
 
 thinkpad_acpi:
  -  Add USB-C Security (USCS) support
  -  Fix fan speed reporting on Edge E330
  -  Fix USB-C Security probe failure on unsupported platforms
  -  Stop setting acpi_device_class()
 
 topstar-laptop:
  -  Stop setting acpi_device_name/class()
 
 toshiba_acpi:
  -  Do not use uninitialized device_class
 
 toshiba_bluetooth:
  -  Use more common error handling code in toshiba_bt_rfkill_probe()
 
 toshiba_haps:
  -  Do not use uninitialized device_class
 
 uniwill-laptop:
  -  Add 2 new feature defines for TUXEDO devices
  -  Add AC auto boot support
  -  Add Avell A60 MUV support
  -  Add keyboard backlight support
  -  Add lightbar support for LAPQC71A/B
  -  Add support for the AiStone X4SP4NAL
  -  Add support for the MACHENIKE L16 Pro
  -  Add support for USB powershare
  -  Handle screen-related events
  -  Remove single color keyboard detection
  -  Split uniwill_kbd_led_init()
 
 x86/platform/olpc: xo15:
  -  Stop setting acpi_device_name/class()
 
 xo15-ebook:
  -  Stop setting acpi_device_name/class()
 -----BEGIN PGP SIGNATURE-----
 
 iHUEABYKAB0WIQSCSUwRdwTNL2MhaBlZrE9hU+XOMQUCaow0EgAKCRBZrE9hU+XO
 MRvYAP412gjYokIoj6ncE2OD897gX2d5BwUVKkraQHoevxLm8wEAikY+iYbdOv3a
 fqhPeCDZSRBn6yEBHewY7cdotNDn2go=
 =d/Uf
 -----END PGP SIGNATURE-----

Merge tag 'platform-drivers-x86-v7.3-1' of git://git.kernel.org/pub/scm/linux/kernel/git/pdx86/platform-drivers-x86

Pull x86 platform driver updates from Ilpo Järvinen
 "Highlights:

  Major refactoring effort: stop setting acpi_device_name/class() and
  pnp.device_class to facilitate their eventual removal

  Many rollback/remove path fixes (presumably mostly found by AI)

  Miscellaneous cleanups / refactoring / improvements

  amd/halo:
   - Add Halo RGB LED driver

  amd/hsmp:
   - Properly serialize probe, remove, and data paths
   - Add support for protocol v7 used by Family 1AH Model 80H
   - Fix error checking corner cases (largely from AI review)
   - Reject negative power cap

  amd/pmc:
   - Improve behavior on platforms that do not support STB
   - Add T14 Gen2 AMD (20XL) to s2idle quirk list

  amd/pmf:
   - Add ioctl interface to retrieve device metrics
   - Add support for new metrics tables used by Family 1AH Model 80H

  qcom-hamoa-ec (arm64):
   - Reject short responses

  asus-nb-wmi:
   - Support ProArt key on ASUS ProArt PX13

  asus-armoury:
   - Gate PPT writes behind active fan curve
   - Add power limits for more models

  dell-wmi-base:
   - Fix handling of ultra performance key

  dell-wmi-sysman:
   - Don't hex dump attribute security buffer

  hp-bioscfg:
   - Various fixes
   - Improve reduced ACPI packages support (necessary for HP EliteBook 840 G2)

  lg-laptop:
   - Fix LED resource handling
   - Add support for events used in newer models
   - Fix keyboard backlight support on LG Gram 16T90SP

  hp-wmi:
   - Generalize thermal params to board params
   - Manage CPU and GPU PWM independently
   - Add GPU MUX switch support
   - Add Victus 15-fb0xxx support
   - Add OMEN MAX 16-ak0xxx, OMEN 16-n0xxx, OMEN 16-wd0xxx, OMEN
     16-wf0xxx, and OMEN board ID 8D88 support
   - Add OMEN Transcend 16-u0xxx support

  huawei:
   - Add support for Fn-lock ACPI interface found on newer Huawei
     laptops such as MateBook 14 2024

  ISST:
   - Improve input validation (many fixes)
   - Disallow SST-CP (core-power) feature if perf profile add fails

  lenovo/yb9-kbdock:
   - Add driver for Yoga Book 9 14IAH10

  lenovo/ymc:
   - Extend hinge switch query to support Yoga 9 2-in-1 14IPH11
   - Prevent loading on Yoga Book 9 14IAH10 to avoid duplicated input
    nodes

  msi-ec:
   - Add MSI Raider A18 HX A9WJG and MSI Katana GF76 11UEK support

  msi-wmi:
   - Add MSI Claw M-Center keys support

  oxpec:
   - Add support for OneXPlayer X2 Mini Pro

  redmi-wmi:
   - Report kbd backlight cycle, OEM preset power mode, and FnLock
     toggle events to userspace

  samsung-galaxybook:
   - Add Samsung Galaxy Book6 Pro support

  thinkpad_acpi:
   - Add USB-C Security support

  uniwill-laptop:
   - Add keyboard backlight, AC auto boot, and USB powershare support
   - Add MACHENIKE L16 Pro, AiStone X4SP4NAL, and Avell A60 MUV support
   - Make lightbar max brightness configurable and add support for
     LAPQC71A/B"

* tag 'platform-drivers-x86-v7.3-1' of git://git.kernel.org/pub/scm/linux/kernel/git/pdx86/platform-drivers-x86: (152 commits)
  platform/x86: think-lmi: Fix current password length check
  platform/x86: redmi-wmi: report EC state change events
  MAINTAINERS: update Intel PMC Core maintainer contact
  platform/x86: oxpec: Add support for OneXPlayer X2 Mini Pro
  platform/x86: thinkpad_acpi: Fix fan speed reporting on Edge E330
  platform/x86: msi-ec: Add MSI Katana GF76 11UEK EC firmware
  platform/x86: think-lmi: Fix certificate thumbprint sysfs output
  mlxbf-bootctl: fix the build error with FIELD_PREP()
  platform/x86: think-lmi: Free system certificate signatures
  platform/x86: ISST: Add a NULL check for sst_inst[]
  platform/x86: ISST: Return error during profile addition
  platform/x86: ISST: Just allow 2 bits for SST feature enable
  platform/x86: ISST: Use PP level enable mask
  platform/x86: ISST: Validate parameter for frequency and priority
  platform/x86: ISST: Validate parameter for core power state
  platform/x86: ISST: Validate max level for set feature
  platform/x86: ISST: Validate logical CPU id and clos id
  platform/x86: ISST: Validate level in perf mask ioctls
  platform/x86: ISST: Validate socket ID in clos_assoc ioctl
  platform/x86/amd/hsmp: Reject negative power cap writes in hwmon
  ...
2026-08-24 10:16:35 -07:00
Linus Torvalds
8bfab832ad mailbox: updates for v7.3
- mhuv2: convert channel translation to fw_xlate() and use generic device
           property APIs
  - axiado: add AX3005 mailbox controller driver and DT bindings
  - bcm2835: use platform_get_irq() and simplify probe error handling
  - cix: fix DT property string typo and use dev_err_probe()
  - exynos: add Exynos850 mailbox driver support and DT bindings
  - microchip: add null check for devm_kasprintf()
  - pcc: fix missed-interrupt command timeout, verify shared memory signature,
        and notify clients on polled completion
  - qcom: fix CPUCP PREEMPT_RT deadlock and NULL data crash, fix IPCC duplicate
         channel allocation across holes, and add IPQ5210 APCS and Nord IPCC bindings
  - riscv: validate RPMI notification buffer lengths and event payload bounds
  - rockchip: manage peripheral clock with devm helper and drop unused struct field
  - ti-msgmgr: convert bindings to DT schema
  - misc: remove redundant dev_err()/dev_err_probe() on IRQ request failures
         across drivers
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEE6EwehDt/SOnwFyTyf9lkf8eYP5UFAmqLoQ8ACgkQf9lkf8eY
 P5X5Yg//fV6vjCgnuCPSfL0z8RbGrE8WlY9XWmQnp5boKa7rjNVKedwkiPxNFMAw
 ro/ERpyfxLSQziws/nonAr7bJ5yxrz6wHFU6++5rT9w5m4e0Y7meoKT6GEj+1bEy
 1kQ/4xmaZSLkUUTJkndU6wGBWxt0GJHObUNzVJxx28E0f1OAQa4MojT96gcgx8tm
 uPzaL6acBigsLRtlCUYgtTR5/CLi9ArJmzRYrWVNG07fxr4sSKuMWTp5Fu+te5/w
 jLJXyEgdzIzbjKrysyQPt0Di3iR2raTlw/86bFQtqdk4GNBMjPcQQtc7qWhUsst8
 XhjXm0OB8yHtJ0cn59yLeChWZ/2Cc+nPqWtYdtadWghuqnTGfdpjkS2sngPsNVRy
 txEvyqgzszQcpAqemKVnVlKHBgq0D3VwMR3KQ/tUIWLgpxw5YcG4oczum/Cf+YOR
 i3VVbxFKkzHjopzh8Gh7pgAuwY4uJnVEgOtFnQLGe6goLcs6nNmBAMe6wi2Ge5mQ
 0ZxoAj1z7pylQPiAQViPYM1uJcgRWJx+B6dzfBJKKBSTsHmHPhjXVYqbs/5/RrU+
 0iHNFVs2dQuKkyjgOQ/qX7Oas3uasc87nuTM7yyHfhFjgt3G+7XaDPETgVuBK/BX
 /3vlpkQEjQFL5CJVcxCZ0/ZSQnwhx0Kr84qXEttq2LMl1Qlzq5w=
 =rp2p
 -----END PGP SIGNATURE-----

Merge tag 'mailbox-v7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/jassibrar/mailbox

Pull mailbox updates from Jassi Brar:

 - mhuv2:
     - convert channel translation to fw_xlate()
     - use generic device property APIs

 - axiado:
     - add AX3005 mailbox controller driver and DT bindings

 - bcm2835:
     - use platform_get_irq()
     - simplify probe error handling

 - cix:
     - fix DT property string typo
     - use dev_err_probe()

 - exynos:
     - add Exynos850 mailbox driver support and DT bindings

 - microchip:
     - add null check for devm_kasprintf()

 - pcc:
     - fix missed-interrupt command timeout
     - verify shared memory signature
     - notify clients on polled completion

 - qcom:
     - fix CPUCP PREEMPT_RT deadlock and NULL data crash
     - fix IPCC duplicate channel allocation across holes
     - add IPQ5210 APCS and Nord IPCC bindings

 - riscv:
     - validate RPMI notification buffer lengths and event payload bounds

 - rockchip:
     - manage peripheral clock with devm helper
     - drop unused struct field

 - ti-msgmgr:
     - convert bindings to DT schema

 - remove redundant dev_err()/dev_err_probe() on IRQ request failures
   across drivers

* tag 'mailbox-v7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/jassibrar/mailbox: (22 commits)
  mailbox: add Axiado AX3005 mailbox driver
  dt-bindings: mailbox: add Axiado AX3005 mailbox
  dt-bindings: mailbox: Convert TI Message Manager to DT schema
  mailbox: cix: fix DT property name string typo and use dev_err_probe()
  mailbox: riscv-sbi-mpxy: validate RPMI notification lengths
  mailbox: bcm2835: use platform_get_irq and simplify probe
  mailbox: qcom-ipcc: fix duplicate channel allocation across holes
  mailbox: mchp-ipc-sbi: Add null check for devm_kasprintf()
  mailbox: Remove redundant dev_err()/dev_err_probe()
  dt-bindings: mailbox: qcom: Add IPQ5210 APCS compatible
  dt-bindings: mailbox: qcom-ipcc: Document Nord IPCC
  mailbox: exynos: Add support for Exynos850 mailbox
  dt-bindings: mailbox: google,gs101-mbox: Add samsung,exynos850-mbox
  mailbox: pcc: Fix command timeout due to missed interrupt
  mailbox: pcc: Check shared memory signature on request
  mailbox: pcc: Notify clients on polled completion
  mailbox: rockchip: drop unneeded runtime pointer (pclk)
  mailbox: rockchip: disable pclk on probe failure and unbind
  mailbox: qcom-cpucp: handle NULL data in send_data callback
  mailbox: qcom-cpucp: fix PREEMPT_RT self-deadlock in IRQ handler
  ...
2026-08-24 10:03:49 -07:00
Linus Torvalds
47096fc3d0 i2c for v7.3, part 2
Fixes and cleanups around probe error handling, resource
 management and a minor Rust cleanup.
 
 Drivers:
 - several drivers: drop duplicate IRQ error reporting
 - imx-lpi2c: improve probe initialization and error cleanup
 - mxs: fix DMA channel leak on probe failure
 - ocores: fix clock cleanup on resume failure
 - rcar: handle reset controllers without status support
 
 Muxes:
 - demux-pinctrl: fix OF node leak on allocation failure
 
 Rust:
 - mark trivial I2cAdapter reference-counting methods inline
 -----BEGIN PGP SIGNATURE-----
 
 iHUEABYKAB0WIQScDfrjQa34uOld1VLaeAVmJtMtbgUCaowtFAAKCRDaeAVmJtMt
 btHCAQCsWbWHyIgqrfHvJqD0IhdB6jc5UB/9Uu1cArF9V4mCVwD/XLkzuBtKDw82
 QAaonKQUp9OaS7TAlZqcmGxMn+yGhg8=
 =ULkr
 -----END PGP SIGNATURE-----

Merge tag 'i2c-7.3-part2' of git://git.kernel.org/pub/scm/linux/kernel/git/andi.shyti/linux

Pull more i2c updates from Andi Shyti:
 "Fixes and cleanups around probe error handling, resource management
  and a minor Rust cleanup.

  Drivers:
   - several drivers: drop duplicate IRQ error reporting
   - imx-lpi2c: improve probe initialization and error cleanup
   - mxs: fix DMA channel leak on probe failure
   - ocores: fix clock cleanup on resume failure
   - rcar: handle reset controllers without status support

  Muxes:
   - demux-pinctrl: fix OF node leak on allocation failure

  Rust:
   - mark trivial I2cAdapter reference-counting methods inline"

* tag 'i2c-7.3-part2' of git://git.kernel.org/pub/scm/linux/kernel/git/andi.shyti/linux:
  i2c: rust: mark I2cAdapter methods as inline
  i2c: rcar: fix reset handling for Gen5
  i2c: mxs: fix DMA channel leak on probe error
  i2c: mux: demux-pinctrl: fix OF node leak on kstrdup failure
  i2c: ocores: Disable clock on failed resume
  i2c: imx-lpi2c: reset controller in probe stage
  i2c: imx-lpi2c: properly unwind resources on probe failure
  i2c: busses: drop redundant dev_err_probe() around irq helpers
2026-08-24 09:07:15 -07:00
Linus Torvalds
cf9610f911 Pin control bulk changes for kernel v7.3
Core changes:
 
 - Use the non-blocking mux_state_try_select() in the generic
   MUX pin control back-end.
 
 - Free pin maps on pinctrl_generic_to_map() failure in the core
   helpers.
 
 New drivers:
 
 - Qualcomm Maili TLMM SoC pin control.
 
 - Qualcomm PMG1110 PMIC pin control.
 
 - Qualcomm Eliza LPASS LPI TLMM SoC pin control (this is for
   the low power audio, LPASS = Low Power Audio SubSystem
   portions).
 
 - Upboard support on top of the Intel pin controller.
 
 - Apple T6030 and T6031 support (just compatible strings).
 
 - Samsung Exynos 8855 SoC pin control.
 
 - Mediatek MT6858 SoC pin control.
 
 - Rockchip RK3308B SoC pin control.
 
 - Rockchip RV1106 SoC pin control.
 
 - Airoha EN7523 SoC pin control.
 
 - Airoha AN7563 SoC pin control.
 
 Improvements:
 
 - Qualcomm TLMM GPIOs are unconditionally marked as wakeup capable.
 
 - Qualcomm improvements on top of the Qualcomm PDC (power domain
   controller) irqchip improvements from tglx:s tree.
 
 - Qualcomm IPQ806x and IPQ9650 nonurgent pin grop fixups.
 
 - The NPCM8xx driver has been put into shape fixing many pin and
   group definitions.
 
 - Some nonurgent Tegra 264 pin assignments are fixed up.
 
 - Some nonurgent fixups to Airoha AN7581 and AN7583 registers and
   pin assignments, missing features etc.
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEElDRnuGcz/wPCXQWMQRCzN7AZXXMFAmqMBvYACgkQQRCzN7AZ
 XXOCRw//aRnxM6R7HJkmcJt70749sE2GSbQ5Vx22zkRLRt8FA0QL4GdPQWjG+rwA
 /Q5XhMv5TpSXaBo63fFyAEHEhgbuxlgyUMijpXuMFVHB4AKIcp0P9Mn+TfTkpsIu
 QPIUktn2wqaIoFoAZj7G2KhXUyyeQnISplBSFl4wfpsJ25fjKqqeoiOMrMCVc05A
 Hfgm047beur5vkvYBIwFG0BC992l9ucSQJ4jDEm2XtkQ/NqIQBd16lYdxrb6vkJu
 Bj2qUH/GVQN3c+n2ZgfwVbkoWMum7VgBymxbnjhraJmQoGm27IQsnBtDnhD5bv6s
 bk5Y6Vyji0kNhHYU5uBFwjDWmYt5PxjXynkeFuruNuBkqnioQCyoTNlIeiJf5pZv
 kM0dBkR0eUTQVPrZX5kXbi9B2JqdbnkdhKbL2YQt1zV0uvs1m8xl3dLu+bvtHjEM
 xNghQKkSDvSHDgulbjTcKEthILSA48Q+poCaOoYre8KIOc4I7novSal6UzcHoTH7
 4D8+BnwJXbS5RRIG2snUWHRLB8aY+yuPlfAQBrAu0apuKWrnr2SjfWMMek1kDv57
 U/iXjSKvjSUQc+sYhq+cPMrD8yYqjIgfg483p4L8xsTIi0Mer6UhnHcZJ82TONTa
 K1A3iGlKOtw4jNFOeow8VAW8MyEHcnx3q70rgA2O+eH7WpT28rs=
 =sSjn
 -----END PGP SIGNATURE-----

Merge tag 'pinctrl-v7.3-1' of git://git.kernel.org/pub/scm/linux/kernel/git/linusw/linux-pinctrl

Pull pin control updates from Linus Walleij:
 "Core changes:

   - Use the non-blocking mux_state_try_select() in the generic MUX pin
     control back-end

   - Free pin maps on pinctrl_generic_to_map() failure in the core
     helpers

  New hardware pin control:

   - Qualcomm Maili TLMM SoC, PMG1110 PMIC, and Eliza LPASS LPI TLMM SoC
     (this is for the low power audio, LPASS = Low Power Audio SubSystem
     portions)

   - Upboard support on top of the Intel pin controller

   - Apple T6030 and T6031 support (just compatible strings)

   - Samsung Exynos 8855 SoC

   - Mediatek MT6858 SoC

   - Rockchip RK3308B and RV1106 SoCs

   - Airoha EN7523 and AN7563 SoCs

  Improvements:

   - Qualcomm TLMM GPIOs are unconditionally marked as wakeup capable

   - Qualcomm improvements on top of the Qualcomm PDC (power domain
     controller) irqchip improvements from tglx:s tree

   - Qualcomm IPQ806x and IPQ9650 non-urgent pin grop fixups

   - The NPCM8xx driver has been put into shape fixing many pin and
     group definitions

   - Some non-urgent Tegra 264 pin assignments are fixed up

   - Some non-urgent fixups to Airoha AN7581 and AN7583 registers and
     pin assignments, missing features etc"

* tag 'pinctrl-v7.3-1' of git://git.kernel.org/pub/scm/linux/kernel/git/linusw/linux-pinctrl: (130 commits)
  dt-bindings: pinctrl: Convert TI DA850 pupd to DT schema
  pinctrl: meson: sync some modify from A4
  pinctrl: meson: a4: Add input enable pin configuration
  pinctrl: realtek: rtd1625: remove unused group name spdif_sel
  pinctrl: realtek: rtd1625: fix base_bit for VE4 GPIO 13
  dt-bindings: pinctrl: microchip,pic32mzda-pinctrl: Convert to DT schema
  Revert "Merge branch 'ib-rsk7204' into devel"
  pinctrl: rockchip: Add RV1106 pinctrl support
  dt-bindings: pinctrl: rockchip: Add RV1106 compatible
  pinctrl: rockchip: Decode drive strength in the get function
  pinctrl: fix PINCTRL_GENERIC_MUX not always being selectable
  pinctrl: airoha: add support of an7563 SoC
  dt-bindings: pinctrl: airoha: add support of an7563 pin controller
  pinctrl: airoha: try to find chip scu node by phandle first
  pinctrl: airoha: add support of en7523 SoC
  dt-bindings: pinctrl: airoha: add support of en7523 pin controller
  pinctrl: airoha: an7583: add support for olt pinmux
  pinctrl: airoha: an7583: add support for pon_alt pinmux
  pinctrl: airoha: an7583: add support for npu_uart pinmux
  dt-bindings: pinctrl: airoha: an7583: add missed features
  ...
2026-08-24 08:46:03 -07:00
Linus Torvalds
0b0e645ed2 auxdisplay for v7.3-1
* Cancel backlight work on panel registration failure
 * Miscellaneous cleanups
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEqaflIX74DDDzMJJtb7wzTHR8rCgFAmqL4y0ACgkQb7wzTHR8
 rCh9oQ/+LJ/jsPyYb43AupK1iyOVCA9BO6Vjn/eb8bM+v4cyt9BN3NdoIgLe5bQM
 HdLBqQuuB2UD5Fo5QmGNitcmqU9XGucOMzrGK9nJlgdXHsMCeNtykbt0Jpunr5t8
 1d0CQgCfsk2PF6YcPLuwZOK1jsHjyI5bmyhFENilO/+mxTFsZNj1s9s4auGDIqnH
 nhfmIWogCnL9CQQYsnHkZvj41DBY7ReM8Wt5T4gj4Bk5VHfcytOIouq5g/+j3r/D
 rAu/7oV5xPZmQBGovmD4ZHaxmF9bjpe32wsmhXKxEsQ+rvoKh71XAIvf/o+gvwBv
 V5DCJfLc3TvCLv/eoGNutNwXejX4EgoSfPBVDxj1+YhjuydGFmWRTvNwnELAGoKW
 /lhLCQ9+MzRHoDaIEcI3ae1Yzwpo95PnI6yKSCzhxaLAzJ9VgAMETnHIwHUOQ/fu
 7YjknaCTIFt/2OlXlBXuZzyRmXSAbFSv0P3S/H2IWrY7BHJQlTmO+w1G98sqDQLQ
 lXiO1kd8mVRjOtCZIDFLqGig729DXvnmX3idbjkwGF7G2KApnW7Kl55QmvM9RqEi
 bHRLxhBrtAtj1Exu47hV9dR6Xy2lLYb7zFr9SpV7+b4MnCXygayB1S2SzxozFUG8
 Br3rfwEavUDBnh5p3h+Q0itaoCaOvuj/j9O84TvIoSwp/QzhxfU=
 =GaAa
 -----END PGP SIGNATURE-----

Merge tag 'auxdisplay-v7.3-1' of git://git.kernel.org/pub/scm/linux/kernel/git/andy/linux-auxdisplay

Pull auxdisplay updates from Andy Shevchenko:

 - Cancel backlight work on panel registration failure

 - Miscellaneous cleanups

* tag 'auxdisplay-v7.3-1' of git://git.kernel.org/pub/scm/linux/kernel/git/andy/linux-auxdisplay:
  auxdisplay: charlcd: cancel backlight work on registration failure
  auxdisplay: panel: Remove unused callback binding code
  auxdisplay: Remove redundant dev_err()
2026-08-24 08:15:59 -07:00
Vlastimil Babka (SUSE)
564ed40708 Merge branch 'slab/for-7.3/kfree_rcu_nolock' into slab/for-next
Merge series "mm/slab: introduce kfree_rcu_nolock() and improve
slub_kunit coverage" from Harry Yoo. From the cover letter [1]:

This series improves kmalloc_nolock() and kfree_nolock() coverage in
slub_kunit and introduces kfree_rcu_nolock() for unknown context as
suggested by Alexei Starovoitov.

Unknown context means the caller does not know whether spinning on a
lock is safe (e.g., a BPF program attached to an arbitrary kernel
function or in NMI context).

The slab allocator already supports unknown context via kmalloc_nolock()
and kfree_nolock(), but te slab allocator does not support freeing
objects by RCU in unknown context.

It is not ideal to have completely separate batching for unknown context
because the worst scenario where spinning on a lock would lead to
deadlock is very rare, and in most cases, it is safe to use the existing
mechanism (kfree_rcu_sheaf()).

Since most part of the slab allocator already supports unknown context
and sheaves support batching kvfree_rcu() calls for slab objects,
implement kfree_rcu_nolock() with minimal changes by teaching
kfree_rcu_sheaf() how to support unknown context and making it a little
bit harder to allocate an empty sheaf, instead of making intrusive
changes to the existing kvfree_rcu batching logic.

kfree_rcu_nolock() tries to free the object to the rcu sheaf if trylock
succeeds. Once the rcu sheaf becomes full, it is submitted to RCU via
call_rcu() if spinning is allowed or IRQs are enabled (to avoid calling
call_rcu() in the middle of call_rcu()). Otherwise, call_rcu() is
deferred via irq work.

When there is no sheaf available, kfree_rcu_sheaf() falls back to
defer_kfree_rcu(). It submits the object to kvfree_rcu batching via irq
work. To do this, patch 6 converts kvfree_rcu to use kvfree_rcu_head
without visible changes to the API for now.

Unlike kfree_rcu(), only the 2-argument variant is supported.  This is
because the last resort of the 1-arg variant is synchronize_rcu(), which
cannot be used in an unknown context.

As suggested by Alexei Starovoitov, kfree_rcu_nolock() can be used with
struct kvfree_rcu_head (8 bytes), which is smaller than struct rcu_head
(16 bytes).

Link: https://lore.kernel.org/all/20260729-kfree_rcu_nolock-v5-0-a28cdcda9673@kernel.org/ [1]
2026-08-24 15:01:27 +02:00
Vlastimil Babka (SUSE)
160dcfe7f9 Merge branch 'slab/for-7.3/objext_split' into slab/for-next
Merge series "mm/slab, alloc_tag: reduce obj_ext memory waste" from
myself. From the cover letter [1]:

It's been bothering me that the memory usage of struct slabobj_ext
depend only on config options and not whether the fields are actually
used. So with both CONFIG_MEMCG=y and CONFIG_MEM_ALLOC_PROFILING=y there
is always objcg field and codetag_ref field. And thus:

1) Having memory allocation profiling config-enabled but not
   boot-enabled means wasted memory on unused codetag_refs. This makes
   it less suitable for a general distro config and the page allocator
   side doesn't suffer from this, only slab and percpu.

2) Complementary, with memory allocation profiling enabled, there are
   caches/slabs that don't need the objcg field, so memory is wasted on
   those.

This series should solve the point 1) fully for slab; pcpuobj_ext
handling can be perhaps improved similarly, haven't looked into that.

For 2) it avoids allocating objcg fields for KMALLOC_NORMAL and
KMALLOC_NO_OBJ_EXT caches where we know they are not necessary because
kmalloc() with __GFP_ACCOUNT will pick a KMALLOC_CGROUP type (except
with SLUB_TINY).

The named kmem_caches are tricky. They can be created with SLAB_ACCOUNT
and then we know objcg fields are always needed. But also they can be
created without SLAB_ACCOUNT and then some allocations have
__GFP_ACCOUNT and some not and we don't know that in advance.

This series introduces a SLAB_MAY_ACCOUNT flag that's currently internal
only and is applied to all caches (unless kmem accounting is disabled)
except KMALLOC_NORMAL (unless that aliases KMALLOC_RECLAIM) and
KMALLOC_NO_OBJ_EXT.

As a followup we can make SLAB_MAY_ACCOUNT explicit and add it to to
caches where we know __GFP_ACCOUNT is used. Then we could only honour
__GFP_ACCOUNT for those, while warning for an unexpected usage
elsewhere.

To check for regressions, I forward-ported a microbenchmark hacked into
slub_kunit that was used to evaluate sheaves.

Tried 3 scenarios, MEMCG and KFENCE were always enabled:
- CONFIG_MEM_ALLOC_PROFILING=n
- CONFIG_MEM_ALLOC_PROFILING=y but _ENABLED_BY_DEFAULT=n
- same but booted with sysctl.vm.mem_profiling=1

The results are quite noisy, but no regression was apparent, except
perhaps few percents for the last case. I don't expect it will be
visible in any real workloads.

Link: https://lore.kernel.org/all/20260727-b4-objext_split-v3-0-c29ef0f1f257@kernel.org/ [1]
2026-08-24 14:57:07 +02:00
Andreas Hindborg
41a9c2b48e MAINTAINERS: configfs: split configfs entry in C and Rust parts
Split configfs MAINTAINERS entry in C and Rust parts. Mark Breno Leitao as
maintainer of configfs C parts. Mark Andreas Hindborg as maintainer of
configfs Rust parts.

Acked-by: Breno Leitao <leitao@debian.org>
Signed-off-by: Andreas Hindborg <a.hindborg@kernel.org>
2026-08-24 12:19:13 +02:00
Linus Torvalds
0a0d1d55da smp_call_function() torture-test updates:
* Count single_rpc offline failures in statistics output.
  * Make invoker threads actually wait for all threads to start.
 -----BEGIN PGP SIGNATURE-----
 
 iQJHBAABCgAxFiEEbK7UrM+RBIrCoViJnr8S83LZ+4wFAmqE5f8THHBhdWxtY2tA
 a2VybmVsLm9yZwAKCRCevxLzctn7jIB7D/9MgrSRbOAK+Kou/DoIDeNNcPtLV3hH
 Scuq6xwsIyvKKs4IhjtDrnilHI51OaPOH6boySPJQ02cC5D1mtXWZBedH6wcQCHS
 ItE4AJJD2Mr2yoy1ld3fFPOeLkgqK/3YfN5aMwNB+BmzW9ZmeAhxBZJACwyuj0OE
 J+9eIq3TUBqR4gtAprfbDQqXtKGdEfhq62WmJFvM0VVPVujYIDyfSh+1hnEl3yp6
 dgb1c3Z2xfMEhp86rLQFgjBYNdgb9GrNb9wX2QEjb0vMw9N5Ky2+do2EprD5DWev
 B0ihHt2fAD4tZr2TubnXy5p8gCy2k3nILODmgfu69pS/LMcdIuBe4rRm1lXpjkDG
 gem1KHjT4nLWte9dI5+D8urwu5dZOJe99NNQDg/qZkVVdkJ9KWxwDx4azd3AKGnW
 qWZUKRks6GL8/SmRuVzQAaVHKtwFh44Wf9h4BoxLNC/dJxokC9+SH4XNUPIHdy5J
 BGhZSiAqmixtKGqXI6nshze88gHVwYIU3UukppyXkPmMih+S5dJzFlVB2gJVFaB9
 lYxXIPVFr9uVNoV5zipCZUxtPW1jasfqth8u2fqxaBP6ChN/e36lWLhHqOLc7DPh
 WgNPQK6wTZnM6eL6qzWqE4A+Bfleaivyp3Ia3gpzyGGgxG0a/5P3m0+/KgPRX0Jm
 iaIKs/gamZErtA==
 =L89j
 -----END PGP SIGNATURE-----

Merge tag 'scftorture.2026.08.18a' of git://git.kernel.org/pub/scm/linux/kernel/git/rcu/linux

Pull smp_call_function() torture-test updates from Paul McKenney:

 - Count single_rpc offline failures in statistics output

 - Make invoker threads actually wait for all threads to start

* tag 'scftorture.2026.08.18a' of git://git.kernel.org/pub/scm/linux/kernel/git/rcu/linux:
  scftorture: Make invoker threads actually wait for all threads to start
  scftorture: Count single_rpc offline failures in statistics output
2026-08-23 19:28:04 -07:00
Linus Torvalds
83684c4e4d RCU updates:
Make expedited grace periods expedite normal RCU callbacks
 
 Miscellaneous fixes:
  * Improve diagnostic output with character task states.
  * Mark accesses to inform KCSAN of concurrency design.
  * Move from kmalloc() to kmalloc_obj().
  * Documentation updates.
  * Improve handling of RCU deferred quiescent states.
  * Clean up unused function arguments and structure fields.
  * Reduce show_rcu_gp_kthreads() stack space.
 
 Tasks RCU updates:
  * Clean up after SRCU re-implementation of Tasks Trace RCU.
  * Mark accesses to inform KCSAN of concurrency design.
  * Add ->lazy_timer status to diagnostic output.
  * Remove an unnecessary memory barrier.
  * Fix a data race, courtesy of KCSAN.
  * Documentation updates.
  * Convert cond_resched_tasks_rcu_qs() from macro to static inline
    function.
 
 SRCU updates:
  * Add Rust helpers for SRCU.
  * Avoid losing queued work at cleanup_srcu_struct() time.
 
 Torture-test updates:
  * Preparation work for immediate RCU priority deboosting.
  * Test RCU readers from real interrupt handlers (as opposed to softirq).
  * Simplify code through use of cpumask_next_wrap().
  * Improve diagnostic output with character task states.
  * Add rcutorture.nwriters parameter to allow lightweight stall testing,
    and rcutorture.stall_only to make doing so easier.
  * Test an RCU Tasks Trace grace period implying an RCU grace period.
  * Make RCU Tasks Trace torturing track reader batches.
  * Fix a data race, courtesy of KCSAN.
  * Plug a shuffle_tmp_mask memory leak on kthread spawn failure.
 -----BEGIN PGP SIGNATURE-----
 
 iQJHBAABCgAxFiEEbK7UrM+RBIrCoViJnr8S83LZ+4wFAmqE5nYTHHBhdWxtY2tA
 a2VybmVsLm9yZwAKCRCevxLzctn7jCoDD/4uM0FYUucaPFp1DcQDSHR/o+UIvqS4
 UBuVNXN3kz0kTM2qWQ4mwsCPDtv2uxmzp+6OEmWpoPtutSujQc1vM9aEMxeEfCDo
 W4PRAJrtXCCfDCZu0xkq+UaXmIF5ajjfFtJIYZxsu6Gv1xR2XtvZqQ58x0MnVXU9
 FfW8XNBhTlXX+2WT9rFxkP4XR6hn1AIY5F9vEIamvu/z3DXwMRHD1wCEJ6BD60qg
 uPIPIIArAC79vidZPK/HBmj0FBqZ0S2NK4uugbkc1xzx1HBfcWA6Y8m+ECkeKbOH
 P4UArtTpwAszvrRAfNNmNe/1bR4fMoGcoLFdvAK9vmc8qpYXKVkZh6XblLUiV/XF
 oo6NKnWeywIQ595RfBzziK8d5coV/ge56P/7Idf+QBUM0XtDTFpwtzmzsYWgdzqi
 Y6s9+t022Eh9013rZ6aMHSNa4Vdffg5P8SjkEWmkqYGIP597kjpRRKYe0y3WGYhy
 wB21LDTi69BFgniytTbH5K0nw1sFbyWOmBpY6ABfDuagGmEDIHzYSw/cI4OW0BMI
 V+ZwpNYY1IPM00GLI76940iLekT6EAV/b06ca0xWum1Am4rR8qwxvCdg4oFCXcGD
 +tomWerTZtK53mkVt+z27iETH8jQD50vdaFYn/WWhQtTeVlYEmzm0qJcyBEp9xWV
 NtLzoF1NZBT8Mw==
 =JeeV
 -----END PGP SIGNATURE-----

Merge tag 'rcu.2026.08.18a' of git://git.kernel.org/pub/scm/linux/kernel/git/rcu/linux

Pull RCU updates from Paul McKenney:
 "Make expedited grace periods expedite normal RCU callbacks

  Miscellaneous fixes:
   - Improve diagnostic output with character task states
   - Mark accesses to inform KCSAN of concurrency design
   - Move from kmalloc() to kmalloc_obj()
   - Documentation updates
   - Improve handling of RCU deferred quiescent states
   - Clean up unused function arguments and structure fields
   - Reduce show_rcu_gp_kthreads() stack space

  Tasks RCU updates:
   - Clean up after SRCU re-implementation of Tasks Trace RCU
   - Mark accesses to inform KCSAN of concurrency design
   - Add ->lazy_timer status to diagnostic output
   - Remove an unnecessary memory barrier
   - Fix a data race, courtesy of KCSAN
   - Documentation updates
   - Convert cond_resched_tasks_rcu_qs() from macro to static inline
     function

  SRCU updates:
   - Add Rust helpers for SRCU
   - Avoid losing queued work at cleanup_srcu_struct() time

  Torture-test updates:
   - Preparation work for immediate RCU priority deboosting
   - Test RCU readers from real interrupt handlers (as opposed to
     softirq)
   - Simplify code through use of cpumask_next_wrap()
   - Improve diagnostic output with character task states
   - Add rcutorture.nwriters parameter to allow lightweight stall
     testing, and rcutorture.stall_only to make doing so easier
   - Test an RCU Tasks Trace grace period implying an RCU grace period
   - Make RCU Tasks Trace torturing track reader batches
   - Fix a data race, courtesy of KCSAN
   - Plug a shuffle_tmp_mask memory leak on kthread spawn failure"

* tag 'rcu.2026.08.18a' of git://git.kernel.org/pub/scm/linux/kernel/git/rcu/linux: (59 commits)
  rcu: Add closing parenthesis in comment in rcu_read_unlock_strict()
  rcutorture: Make {,s}rcu_read_delay() better handle forward-progress testing
  rcutorture: Announce declining to forward-progress test
  torture: Don't leak shuffle_tmp_mask when shuffler kthread fails to start
  rcutorture: Use this_cpu_inc() for rcu_torture_count[] and rcu_torture_batch[]
  rcutorture: Make RCU Tasks Trace track Reader Batches
  rcutorture: Test RCU Tasks Trace GP implying RCU GP
  rcutorture: Add a stall_only module parameter
  rcutorture: Add nwriters module parameter
  rcutorture: Use task_state_to_char() for task-state reporting
  rcutorture: Use cpumask_next_wrap() in rcu_torture_preempt()
  rcutorture: Test RCU readers from hardware interrupt handlers
  rcutorture: Check for immediate deboosting at reader end
  srcu: Queue sdp->work when the delay timer is successfully deleted
  rcu-tasks: Convert cond_resched_tasks_rcu_qs() to static inline
  rcu-tasks: Fix some comments for call_rcu_tasks() and call_rcu_tasks_rude()
  rcu-tasks: Rename tasks_rcu_exit_srcu_stall_timer to tasks_rcu_exit_stall_timer
  rcu: Mark interrupts-enabled accesses to rdp->cpu_no_qs.s
  rcu: Reduce stack usage in show_rcu_gp_kthreads()
  rcu: Mark accesses to ->rcu_urgent_qs and ->rcu_need_heavy_qs
  ...
2026-08-23 18:00:22 -07:00
Swark Yang
14af7a96af mailbox: add Axiado AX3005 mailbox driver
Add a mailbox controller driver for the Axiado AX3005 SoC.
The controller provides communication channels between
the host CPU and the coprocessor.

The hardware provides 8 TX channels and 8 RX channels
through separate register regions. RX channels use
per-channel interrupts, while TX completion is detected by
polling the FIFO status.

Add the driver path to the existing Axiado mailbox entry in
MAINTAINERS.

Signed-off-by: Swark Yang <syang@axiado.com>
Signed-off-by: Jassi Brar <jassisinghbrar@gmail.com>
2026-08-23 15:41:13 -05:00
Swark Yang
289413b807 dt-bindings: mailbox: add Axiado AX3005 mailbox
Add a devicetree binding for the Axiado AX3005 mailbox controller.
The controller provides inter-processor communication channels
between the host CPU and the coprocessor, with separate TX and RX
register regions.

Add the corresponding MAINTAINERS entry covering the binding.

Signed-off-by: Swark Yang <syang@axiado.com>
Reviewed-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Signed-off-by: Jassi Brar <jassisinghbrar@gmail.com>
2026-08-23 15:41:13 -05:00
Linus Torvalds
4352b8aee9 I3C for 7.3
New driver:
  - AMD AXI I3C master controller
 
 Subsystem:
  - I3C Common Command Code (CCC) handling improvements, especially around GET
    CCCs
  - SETAASA device discovery support
  - ACPI support for all existing DAA methods like SETDASA, SETNEWDA as well as
    I2C devices on I3C bus
  - IBI-based wakeup support
 
 Drivers:
  - dw: SETAASA support
  - mipi-i3c-hci: advertise IBI wakeup capability, AMD_PT I3C controller support,
    PIO queue management support for HCI v1.2
  - renesas: improve suspend to RAM support, add runtime PM support
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEBqsFVZXh8s/0O5JiY6TcMGxwOjIFAmqLU40ACgkQY6TcMGxw
 OjL0cw//Zewbfj2+F6ugxmyntn1fUvxm54b+/LbB03Bw6vLo+uAQWHNyeqC1P+Kn
 cZzzNSUicdGjvmn6M6JPkxO7mtgr4mUkCZpdPMiTg5iTi6nxSEzuXkksIOOdvEd+
 mw/+9UdboWbxWQ6YfAv0uKVWA8AUKoR91+CO4msqJPIEhLSAjUMcQp3sYdOYUrcJ
 aL9v0S7DbLsOQrh34WgWMzH3U1hJ8Y8i4v+fIRJO+8GwoYEZVo2oL0aRWTsLsi7P
 XUPK1uDwWC5RtcEcI02MY6v+aOKVF99G+Z2lVm8iZkYrozuFJxH8niP0pZaKVTQs
 7Ud8qT6cM7GvBPMg0oE+DCr70rg1/+xsPt0Gd7Np11jwhBVaPHm1fklO3HX+Tfl5
 ic7SjufL5GnjMW1WXh3qC2CReLmuheTlaUkOUYderFml8faN46VTVDMTwwXlCtaY
 crYAAQ+rGWWLrJbVHEbxMpyoEyLWwAxuVies7qUMMhrQtFgPCtRB19p4MiDBwHmF
 ChFdDEF8kG8Y/MX6BEOJHDMFz1x49sESjV+C1xefBrcKLKbLu2JB06eLXgJfi7Hh
 DN91qbeaIl3vReVgwYaqau8BN3xKMU07LY6KEO4qvjGsWiQwFzA81Idyg5Zl217V
 hEbTzz+VCOW7xAHtekXPB+SPKuyV8a/Y3OLqsEiQ8+4XldY7Uh0=
 =77m4
 -----END PGP SIGNATURE-----

Merge tag 'i3c/for-7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/i3c/linux

Pull I3C updates from Alexandre Belloni:
 "A new driver this cycle, for the AMD AXI I3C controller.

  There are also new features such as IBI wakeup support, SETAASA device
  discovery and ACPI support for the the DAA methods, meaning we can now
  communicate with the SPD devices on DDR5 modules.

  New driver:
   - AMD AXI I3C master controller

  Subsystem:
   - I3C Common Command Code (CCC) handling improvements, especially
     around GET CCCs
   - SETAASA device discovery support
   - ACPI support for all existing DAA methods like SETDASA, SETNEWDA as
     well as I2C devices on I3C bus
   - IBI-based wakeup support

  Drivers:
   - dw: SETAASA support
   - mipi-i3c-hci: advertise IBI wakeup capability, AMD_PT I3C
     controller support, PIO queue management support for HCI v1.2
   - renesas: improve suspend to RAM support, add runtime PM support"

* tag 'i3c/for-7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/i3c/linux: (70 commits)
  i3c: dw: reduce do_daa time if there's no client
  i3c: mipi-i3c-hci: Add support for AMD_PT I3C controller
  i3c: mipi-i3c-hci: Add PIO queue management support for HCI v1.2
  i3c: mipi-i3c-hci: Fix missing STAT_IBI_STATUS_THLD in PIO mode
  i3c: dw: rename "pclk" to "apb" to match dt-binding
  i3c: dw: make struct dw_i3c_cmd smaller
  i3c: dw: use COMMAND_PORT_TRANSFER_ARG instead of hardcoding
  i3c: renesas: Don't register devices when ENTDAA times out
  i3c: master: dw-i3c-master: fix OD timing for first broadcast
  i3c: mipi-i3c-hci: Advertise IBI wakeup capability
  i3c: mipi-i3c-hci: Factor out i3c_hci_sysdev()
  i3c: mipi-i3c-hci-pci: Propagate I3C wakeup requirements to PCI
  i3c: master: Reject IBI requests from non-IBI-capable devices
  i3c: master: Add helper to query bus wakeup requirements
  i3c: master: Report wakeup events for IBIs
  i3c: master: Support IBI-based wakeup capability
  i3c: master: Fix potential UAF in i3c_device_match()
  i3c: master: Fix potential UAF in i3c_device_uevent()
  i3c: Make dev->desc locking assumptions explicit
  i3c: master: Fix use-after-free of master->this
  ...
2026-08-23 13:28:57 -07:00
Linus Torvalds
570f7e331f pci-v7.3-changes
-----BEGIN PGP SIGNATURE-----
 
 iQJIBAABCgAyFiEEgMe7l+5h9hnxdsnuWYigwDrT+vwFAmqIy5UUHGJoZWxnYWFz
 QGdvb2dsZS5jb20ACgkQWYigwDrT+vw79g//dJCdLjB7Hu/pYOkkZ1VGpQC4x8eu
 RR2if7TxHOceOkzIzd9OB68NU3KLuBthyMRdcfZ5VjayiRKZHbY1NnQX8qzoXsPM
 F10QbJ/JOhZF0bvtr5nkTS2659AkHfMgiEPAN1hN6M0gHzFEB0vNoYb9lgMRkdXm
 3jxMX8tq1x8QlbpiTx5nmfHtbK40u8BI/zcpsBW6P8LHmRMhlEgLViPDNVNfup9p
 OK4Ra/jeExIkODwVI5ngBJgtetcXs5jFPgAkbk+efjU32VSLUwIETj2l1JsfDh79
 taj7XKEYReghFIvIUmm0vkNZU3CRvkMdoZQnep/HypxpPc5cJAFcHRpAb70QRgA5
 CbHeFKfFr4D1fOXyUq0atbpb4O3wZdCRgaULDgRmP7TmLIY+8VaUv4wjYDi9vVW9
 QVxxFmaydF4lRLsKGrUX5755QVMTAN7Hyqs984R/zi66WjF1MLPqXkaqOKZxrjj8
 8oJ9HCLX+B1hHnIENN/D0kcc1YSsruCke2RF0FFDpc3N48Y0LOGyof5S7GUx2Z1+
 MohLF/Y8TSsdmzo9a25OZ8Oyq+kyZ1spDYbpBmN/Pqu3GZBNBan7EsbY5pg0LVG+
 NtQv7+oX7Q4VGmbDvxfGCwauA3ekaSfyIW0KJtk5y1xLJO2pAQn4QOBqUZtYtyJf
 wu10ek23s7w9wbI=
 =cNUI
 -----END PGP SIGNATURE-----

Merge tag 'pci-v7.3-changes' of git://git.kernel.org/pub/scm/linux/kernel/git/pci/pci

Pull PCI updates from Bjorn Helgaas:
 "Resource management:

   - Add hotplug reservation only once (not at each level of the
     hierarchy) so bridge windows don't grow more than necessary (Ilpo
     Järvinen)

  Driver binding:

   - Rework device matching so device ID lifetime only needs to cover
     the probe path since dynamic IDs can be removed at any time (Gary
     Guo)

  Error handling:

   - Update mappings of AER errors to agent & layer and log them for
     each individual error when multiple errors detected (Lukas Wunner)

   - Log Error Source only once, not twice in separate messages (Lukas
     Wunner)

   - Emit TLP Log only for unmasked errors (Lukas Wunner)

   - Support Advisory Non-Fatal Errors (Lukas Wunner)

   - Allow DPC on all Downstream Ports, not just Root Ports, when OS
     controls AER (Darshit Shah)

  ASPM:

   - Program the same ASPM Control values for every function of
     multi-function devices, as recommended by the PCIe spec (Krishna
     Chaitanya Chundru)

   - Avoid L0s for Realtek RTS525A, where it causes an AER interrupt
     storm (Max Lee)

   - Avoid ASPM L0s, L1, and L1 PM Substates based on 'aspm-no-l0s',
     'aspm-no-l1' [1], and 'aspm-no-l1ss' DT properties (Krishna
     Chaitanya Chundru)

  Power management:

   - Allow D3 for native hotplug-capable Root Ports on non-x86 platforms
     (we avoid D3 for these ports on x86 because some old platforms
     didn't validate it) (Manivannan Sadhasivam)

   - Allow portdrv to claim Ports even if they don't support services
     (AER, PME, DPC, hotplug, etc) so it can do power management (Brian
     Norris)

  Power control:

   - Add support for PCIe WAKE# interrupt when described via DT (Krishna
     Chaitanya Chundru)

   - For the TC9563 PCIe switch:

       - Take a reference on the I2C adapter to avoid uninterruptible
         hang when unloading an I2C module while in-use (Johan Hovold)

       - Update DT binding and driver to restrict Tx Amplitude, DFE and
         N_FTS to USP, DSP1 and DSP2 (Manivannan Sadhasivam)

       - Power off only external-facing ports (DSP1, DSP2), leaving USP
         and DSP3 (aka VDSP) powered up (Manivannan Sadhasivam)

       - Move integrated MAC Endpoint out of the list of internal ports
         and configure it separately (Manivannan Sadhasivam)

  Virtualization:

   - Add ACS quirk for Pericom PI7C9X2G608 switches (Tim Harvey)

   - Fix a long-standing bug in the Intel PCH Root Port MPC ACS quirk
     that didn't update the intended INTEL_MPC_REG_IRBNCE bit because it
     used a 16-bit config write when a 32-bit write was intended
     (Mohamad Raizudeen)

  Procfs:

   - Avoid spurious runtime PM wakeup on config space accesses that are
     outside config space and fail before reaching PCI (Krzysztof
     Wilczyński)

   - Warn on user-space writes to kernel-exclusive config space regions,
     as we already do for sysfs (Krzysztof Wilczyński)

   - Check credentials of opener, not reader, for config space reads, as
     we already do for sysfs (Krzysztof Wilczyński)

  Sysfs:

   - In pci_write_legacy_io(), avoid out-of-bounds reads from the user
     buffer and fix incorrect ioport write data (1-byte writes on
     little-endian powerpc, 2- and 4-byte writes on big-endian powerpc)
     (Krzysztof Wilczyński)

   - In pci_read_legacy_io(), fix incorrect ioport read data for 2- and
     4-byte reads on big-endian powerpc (Krzysztof Wilczyński)

   - Fix I/O port accessor argument order in Alpha pci_legacy_write()
     (Krzysztof Wilczyński)

   - Avoid spurious runtime PM wakeup on config space accesses that are
     outside config space and fail before reaching PCI (Krzysztof
     Wilczyński)

   - Return -EINVAL, not -ENODEV, for mmap of I/O BAR that fails because
     the arch doesn't support it, as we do for procfs (Krzysztof
     Wilczyński)

   - Check for LOCKDOWN_PCI_ACCESS for legacy_io and legacy_mem, as we
     do for other config space accessors (Krzysztof Wilczyński)

  Peer-to-peer DMA:

   - Add Nvidia Vera Rubin to list of platforms that support P2PDMA
     (Leon Romanovsky)

  Endpoint framework:

   - Check doorbell SUCCESS bit in pci_endpoint_test to avoid treating
     some failures as successes (Niklas Cassel)

   - Fail doorbell test when the trigger IRQ is missed (Niklas Cassel)

  New native PCIe controller drivers:

   - Add DT binding and driver for NVIDIA Tegra264 (Thierry Reding)

  Native PCIe controllers:

   - Use common wait time definitions for PCIe link monitoring instead
     of defining driver-private duplicates (Thierry Reding)

  Generic host bridge driver:

   - Fix NULL pointer dereference that caused enumeration failures on
     32-bit CAM systems (Steffen Persvold)

  Amlogic Meson PCIe controller driver:

   - Correct the PERST# GPIO state so it remains asserted until power
     and REFCLK become stable to fix enumeration failure (Ronald
     Claveau)

  ASPEED PCIe controller driver:

   - Switch to irq_domain_create_linear() so we can obsolete
     irq_domain_add_linear() (Jiri Slaby)

  Cadence PCIe controller driver:

   - Add MODULE_DEVICE_TABLE to generate module aliases for OF-based
     module autoloading (Pengpeng Hou)

   - Add debugfs 'ltssm_status' file for LGA- and HPA-based Cadence
     controllers (Hans Zhang)

   - Support up to x4 (not x2) lanes for J200 (Takuma Fujiwara)

   - Fix host/endpoint dependencies for cadence-plat driver to fix link
     error when cadence-plat is built-in but the host or endpoint driver
     is modular (Aksh Garg)

  Freescale i.MX6 PCIe controller driver:

   - Add imx6 intr/aer/pme interrupt lines for i.MX95 (Richard Zhu)

   - Remove PERST# checking from pci_host_common_parse_port() so callers
     can decide whether to fall back to legacy DT binding with PERST# in
     the host bridge (Sherry Sun)

   - Fix build issues when PCI_PWRCTRL_GENERIC or PCI_HOST_COMMON is a
     module (Arnd Bergmann)

   - Create pwrctrl devices only once by doing it from imx_pcie_probe()
     instead of imx_pcie_host_init(), which is used during both probe
     and resume (Sherry Sun)

   - Use 'dw_pcie_rp->skip_pwrctrl_off' to avoid powering off devices
     during suspend to preserve wakeup capability (Sherry Sun)

   - Add runtime PM support for i.MX95 to allow dynamic power management
     when the link is idle (Richard Zhu)

  Intel VMD host bridge driver:

   - Support device ID 0x28C1 and assume that BIOS has already
     enumerated the hierarchy below VMD and stored bus range info for OS
     to use (Nirmal Patel)

   - Add support for VMCONFIG BUS_RESTRICT_CFG=3, which makes it
     possible to enumerate downstream devices on Intel Arrow Lake-HX
     systems and probably others (Ali Alaei)

   - Pay attention to _OSC negotiation for VMD hierarchy only when
     running on bare metal, not when running in a VM (Nirmal Patel)

   - Add Nova Lake (NVL) and Dunlow (DNL) Device IDs (Szymon Durawa)

  MediaTek PCIe controller driver:

   - Add support for PCIe controller in EcoNet EN7528 and EN751221 SoCs
     (Caleb James DeLisle)

  MediaTek PCIe Gen3 controller driver:

   - Add mediatek-gen3 'memory-region' for restricted DMA buffer
     (Chen-Yu Tsai)

  NVIDIA Tegra264 PCIe controller driver:

   - Distinguish Tegra264 C0 PCIe controller for internal GPU from C1-C5
     controllers so the unit address matches the first 'reg' entry
     (Thierry Reding)

   - Add Tegra264 Root Port stanzas to prepare for generic WAKE#
     handling (Thierry Reding)

  Qualcomm PCIe controller driver:

   - Add IPQ9650 compatible with global interrupt (Kathiravan
     Thirumoorthy)

   - Add IPQ5210 compatible with IPQ9574 fallback (Varadarajan
     Narayanan)

   - Add DT binding and driver support for Hawi SoC (Matthew Leung)

   - Skip PERST# GPIOs provided by downstream PCIe devices, which should
     be handled by drivers of those devices (Manivannan Sadhasivam)

   - Stop advertising Attention Button Present (no Qcom SoCs support
     Attention Buttons) so pciehp can use Presence Detect Changed events
     (Qiang Yu)

  Renesas R-Car PCIe controller driver:

   - Add rcar-gen4-pci-host optional 'msi-parent' for GIT ITS (Marek
     Vasut)

   - When MSI is enabled but iMSI-RX is not used, configure AXIINTC to
     allow GIT ITS to handle MSI (Marek Vasut)

   - Refactor GIC600 implementation to make it easier to add platforms
     that only support 32-bit addressing (Marek Vasut)

   - Add Renesas R-Car Gen4 S4/V4H/V4M to the list of GIC600
     integrations that only support 32-bit addressing (Marek Vasut)

  Renesas RZ/G3S PCIe controller driver:

   - Add DT binding and driver support for RZ/V2H(P) SoC, which contains
     two PCIe controllers, configured either as a single x4 link or two
     independent x2 link controllers (Lad Prabhakar)

  SpacemiT K1 PCIe controller driver:

   - Add missing MODULE_DEVICE_TABLE() to generate module alias info for
     OF-based module autoloading (Pengpeng Hou)

  StarFive PCIe controller driver:

   - Fix resource leaks on error paths in host_init() (Ali Tariq)

   - Fix runtime PM handling and teardown ordering to avoid register
     access while power or clocks are disabled (Ali Tariq)

   - Check for runtime PM resume failure to avoid register access while
     power or clocks are disabled (Ali Tariq)

  Synopsys DesignWare PCIe controller driver:

   - Add LECARC PMU IDs to the DWC RAS/DES VSEC list so it can take
     advantage of the existing debugfs support for silicon debug, error
     injection, and event counters (Brett Zhou)

   - Factor pcie_valid_speed() and pci_bus_speed2lnkctl2() out of bwctrl
     so they can be shared by the DWC core (Hans Zhang)

   - Flush MSI writes from endpoint before unmapping the iATU, as we
     already do for MSI-X writes (Niklas Cassel)

   - Unmap MSI iATU window before mapping MSI-X window, to avoid a
     subsequent MSI write using a disabled aperture and losing the
     interrupt (Niklas Cassel)

   - Change endpoint .pre_init() and .init() callbacks to return errors
     and handle them (Marek Vasut)

  UltraRISC PCIe controller driver:

   - Add 'core', 'dbi', and 'aux' clocks to DT binding and manage them
     in the driver (Jia Wang)

   - Use module_platform_driver() since this may be built as a module,
     though not removable because IRQs can't be safely disposed (Jia
     Wang)

  MicroSemi Switchtec management driver:

   - Add Microchip PCI1008 device ID and include it in NTB DMA alias
     quirk (Logan Gunthorpe)

  Miscellaneous:

   - Document how to write PCI Host Controller drivers (Manivannan
     Sadhasivam)

   - Fix typos in documentation (D'Orus Tsitera)

   - Use %pe format specifier to print error pointers so we get symbolic
     errname when available (Krzysztof Wilczyński)"

* tag 'pci-v7.3-changes' of git://git.kernel.org/pub/scm/linux/kernel/git/pci/pci: (124 commits)
  PCI: vmd: Add Nova Lake (NVL) and Dunlow (DNL) Device IDs
  PCI: tegra264: Add Tegra264 support
  dt-bindings: PCI: tegra264: Switch to PCIe Root Port bindings
  dt-bindings: PCI: tegra264: Strictly distinguish C0 from C1-C5
  PCI/AER: Support Advisory Non-Fatal Errors
  PCI: Fix 32-bit config write in Intel PCH Root Port MPC ACS quirk
  PCI: dwc: Handle return value from endpoint .pre_init callback
  PCI: dwc: Handle return value from endpoint .init callback
  PCI: dwc: Add PCI ID for LECARC PCIe PMU
  PCI/ASPM: Mask ASPM states based on Devicetree properties
  PCI/ASPM: Disable/restore ASPM on every function for multi-function devices
  Documentation: PCI: Document how to write PCI Host Controller drivers
  PCI/ASPM: Use pcie_capability_clear_and_set_word() for ASPM disable/restore
  PCI: Add support for PCIe WAKE# interrupt
  PCI: Allow D3 for native hotplug-capable Root Ports on non-x86 platforms
  dt-bindings: PCI: Correct white-space style
  PCI/ASPM: Avoid L0s for Realtek RTS525A
  PCI: ultrarisc: Use module_platform_driver()
  PCI: ultrarisc: Get and enable DP1000 PCIe controller clocks
  dt-bindings: PCI: ultrarisc: Add required DP1000 PCIe clocks
  ...
2026-08-23 12:44:10 -07:00
Linus Torvalds
b6b019a1d9 parisc architecture fixes and updates for kernel v7.3-rc1:
- Drop PER_HPUX personality from UAPI headers
 - Infinite loop fix when parsing IRQ value in eisa code
 - Switch to use asm-generic/serial.h
 - Prevent possible unaligned asm code in head.S
 -----BEGIN PGP SIGNATURE-----
 
 iHUEABYKAB0WIQS86RI+GtKfB8BJu973ErUQojoPXwUCaosmlQAKCRD3ErUQojoP
 X6U0AQCDiDmKtBw0lzf3ej4slibydKQTh5vyF45IKTP/RO1hywEA9bt8L/335DGp
 H+feM1LvLjuVvfpdco41UwnTF0HwDQo=
 =7xok
 -----END PGP SIGNATURE-----

Merge tag 'parisc-for-7.3-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/deller/parisc-linux

Pull parisc architecture updates from Helge Deller:

 - Drop PER_HPUX personality from UAPI headers

 - Infinite loop fix when parsing IRQ value in eisa code

 - Switch to use asm-generic/serial.h

 - Prevent possible unaligned asm code in head.S

* tag 'parisc-for-7.3-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/deller/parisc-linux:
  parisc: eisa: Fix infinite loop when parsing invalid IRQ value
  parisc: Fix alignment of asm statements in head.S
  parisc: eisa_eeprom: Add missing MODULE_DESCRIPTION()
  parisc: Use asm-generic/serial.h
  parisc: sba_iommu: Remove dead DEBUG_DMB_TRAP code
  UAPI: Drop PER_HPUX personality
  parisc: superio: Spelling s/Peterson/Petersen/
2026-08-23 10:30:02 -07:00
Linus Torvalds
66ec24c5d7 s390 updates for 7.3 merge window
- Add a cpuidle driver with polling and enabled wait states using the
   existing CPU idle infrastructure and idle governor to improve latency
   for frequent sleep/wakeup cycles. Remove the obsolete tick delay
   heuristic and generic arch_needs_cpu() hook. Add the corresponding
   driver entry to MAINTAINERS
 
 - Add kCFI support using the generic support provided by Clang
 
 - Enable Clang CONTEXT_ANALYSIS for various architecture code and for
   char, PCI, CIO and virtio drivers. Add required lock annotations,
   exclude unsupported mm helpers and remove conditional PCI locking
 
 - Fix secure storage access exception handling and reintroduce
   DCACHE_WORD_ACCESS previously removed as a workaround
 
 - Fix cpum_cf perf crashes when CPUs are brought online while per-task
   events are active. Allocate and remove per-CPU counter data from CPU
   hotplug callbacks
 
 - Fix a deadlock when an s390dbf debug area is unregistered while one
   of its debugfs files is being written to
 
 - Fix MVIY_PERCPU() with binutils older than 2.39, where an assembler
   macro silently omitted an instruction needed to repair interrupted
   operations after CPU migration
 
 - Remove/replace cond_resched() calls which are no-ops with the supported
   s390 preemption models
 
 - Fix AP queue depth and maximum message length decoding according to
   the architecture. Current hardware is not affected, but future hardware
   could report values which were handled incorrectly
 
 - Reflect the configured CPU state in cpu_enabled_mask so deconfigured
   CPUs are not presented as available for onlining
 
 - Restore the vDSO GNU_EH_FRAME program header which was lost when the
   build switched to direct linker invocation, and mark it read-only
 
 - Add SCLP action qualifiers used by Spyre for card initialization,
   recoverable error and telemetry reporting
 
 - Move KMSAN interrupt flag helpers out of line to fix
   -Wstatic-in-inline build warnings
 
 - Use level-specific page table entry accessors for hugetlb entries and
   ptep_get() when accessing crashed kernel memory in kdump
 
 - Make forced AP bus rescans killable so that a user process blocked
   behind an ongoing scan can still be terminated with SIGKILL
 
 - Rework pkey ioctl error paths to remove duplicated cleanup code and
   avoid freeing error pointers
 
 - Allow the protected guest SWIOTLB buffer to be allocated outside the
   first 2GB. Also enable dynamic SWIOTLB growth and the coherent atomic
   pool fallback to improve I/O behavior when the initial pool is exhausted
 
 - Add program check statistics and spinlock contention tracepoints.
   Increase the lockdep chain capacity to keep lockdep enabled for complex
   code paths such as btrfs
 
 - Simplify IPL, trap and syscall code and remove the obsolete unistd_32.h
   generation entry
 -----BEGIN PGP SIGNATURE-----
 
 iQEzBAABCgAdFiEE3QHqV+H2a8xAv27vjYWKoQLXFBgFAmqLHuoACgkQjYWKoQLX
 FBhf2Qf+JlV+jQM1Lvn/Dj16vuQ77a4aP5C/OnLGMaTrrzbX420qU04yvC96v2Xu
 ux01aDU9VakonE74IT0NmrNo1VDUk8nSvIWUTB6GH7KvK76VEZN5Kkyn8TmeRmE0
 bZ0Fg7MgnhwdYijFDiX9w4rLyirwxs7vkScdJdJd0iKEdoZHXojGSjPDvmSpXght
 FgCszt+YOqu9MMf9B5oGAl+P40mgPTlm6M+ygoe2dX7qPQBUHLbDPTgZiWnKdXi2
 LPx0QPEha921ePDWrWz2HEqNetMfwGl12iertXddf1uzuK6LLObi0M5QrGw/ZbOy
 UJFM+AjFekTQyZPSunD4NWyCjglqrA==
 =XF7Y
 -----END PGP SIGNATURE-----

Merge tag 's390-7.3-1' of git://git.kernel.org/pub/scm/linux/kernel/git/s390/linux

Pull s390 updates from Vasily Gorbik:

 - Add a cpuidle driver with polling and enabled wait states using the
   existing CPU idle infrastructure and idle governor to improve latency
   for frequent sleep/wakeup cycles. Remove the obsolete tick delay
   heuristic and generic arch_needs_cpu() hook. Add the corresponding
   driver entry to MAINTAINERS

 - Add kCFI support using the generic support provided by Clang

 - Enable Clang CONTEXT_ANALYSIS for various architecture code and for
   char, PCI, CIO and virtio drivers. Add required lock annotations,
   exclude unsupported mm helpers and remove conditional PCI locking

 - Fix secure storage access exception handling and reintroduce
   DCACHE_WORD_ACCESS previously removed as a workaround

 - Fix cpum_cf perf crashes when CPUs are brought online while per-task
   events are active. Allocate and remove per-CPU counter data from CPU
   hotplug callbacks

 - Fix a deadlock when an s390dbf debug area is unregistered while one
   of its debugfs files is being written to

 - Fix MVIY_PERCPU() with binutils older than 2.39, where an assembler
   macro silently omitted an instruction needed to repair interrupted
   operations after CPU migration

 - Remove/replace cond_resched() calls which are no-ops with the
   supported s390 preemption models

 - Fix AP queue depth and maximum message length decoding according to
   the architecture. Current hardware is not affected, but future
   hardware could report values which were handled incorrectly

 - Reflect the configured CPU state in cpu_enabled_mask so deconfigured
   CPUs are not presented as available for onlining

 - Restore the vDSO GNU_EH_FRAME program header which was lost when the
   build switched to direct linker invocation, and mark it read-only

 - Add SCLP action qualifiers used by Spyre for card initialization,
   recoverable error and telemetry reporting

 - Move KMSAN interrupt flag helpers out of line to fix
   -Wstatic-in-inline build warnings

 - Use level-specific page table entry accessors for hugetlb entries and
   ptep_get() when accessing crashed kernel memory in kdump

 - Make forced AP bus rescans killable so that a user process blocked
   behind an ongoing scan can still be terminated with SIGKILL

 - Rework pkey ioctl error paths to remove duplicated cleanup code and
   avoid freeing error pointers

 - Allow the protected guest SWIOTLB buffer to be allocated outside the
   first 2GB. Also enable dynamic SWIOTLB growth and the coherent atomic
   pool fallback to improve I/O behavior when the initial pool is
   exhausted

 - Add program check statistics and spinlock contention tracepoints.
   Increase the lockdep chain capacity to keep lockdep enabled for
   complex code paths such as btrfs

 - Simplify IPL, trap and syscall code and remove the obsolete
   unistd_32.h generation entry

* tag 's390-7.3-1' of git://git.kernel.org/pub/scm/linux/kernel/git/s390/linux: (59 commits)
  s390/percpu: Fix MVIY_PERCPU() with older binutils
  s390/debug: Fix deadlock during unregister
  s390/cpum_cf: Handle CPU hotplug via prepare/dead callbacks
  s390: Enable CONTEXT_ANALYSIS for various directories
  s390/mm: Add __context_unsafe() attribute to gmap helper functions
  s390/mm: Add __context_unsafe() attribute to do_secure_storage_access()
  s390/sysinfo: Add context analysis attributes
  s390/irqflags: Add out-of-line definitions of arch_local_irq_*() for KMSAN
  s390/virtio: Enable CONTEXT_ANALYSIS
  s390/cio: Enable CONTEXT_ANALYSIS
  s390/vfio_ccw: Add __must_hold() attribute to vfio_ccw_sch_quiesce()
  s390/pci: Enable CONTEXT_ANALYSIS
  s390/pci: Rework __zpci_event_availability() to remove conditional locking
  s390/pci: Rework __zpci_event_error() to remove conditional locking
  s390/char: Enable CONTEXT_ANALYSIS
  s390/con3215: Add __must_hold() attribute to raw3215_make_room()
  s390/ap: Fix MAPML computation
  s390/cio: Remove cond_resched() calls
  s390: Remove cond_resched() calls
  KVM: s390: Remove cond_resched() calls
  ...
2026-08-23 10:26:44 -07:00
Linus Torvalds
388b607d10 EFI updates for v7.3
- Set a timeout for EFI runtime service completions, and declare the
   firmware wedged if it is exceeded. Note that this requires special
   handling in case the firmware does return after all.
 
 - Rate limit the efivarfs statfs() handler as the QueryVariableInfo()
   runtime service can be costly
 
 - Sanity check the size of struct properties_header on Mac/x86
 
 - Tweak the prototype of efi_guid_to_str()
 -----BEGIN PGP SIGNATURE-----
 
 iHUEABYKAB0WIQQQm/3uucuRGn1Dmh0wbglWLn0tXAUCaoqdVQAKCRAwbglWLn0t
 XAb1AP9DIuHIAYlD4j8FKXcJtq1O/MzOadE3c4fNIdTPlTeUaAD8CAP0gHG3iRvc
 G265QOG2tjmmnFbCe+R8JVSdXBwCEAU=
 =GNJQ
 -----END PGP SIGNATURE-----

Merge tag 'efi-next-for-v7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/efi/efi

Pull EFI updates from Ard Biesheuvel:

 - Set a timeout for EFI runtime service completions, and declare the
   firmware wedged if it is exceeded. Note that this requires special
   handling in case the firmware does return after all

 - Rate limit the efivarfs statfs() handler as the QueryVariableInfo()
   runtime service can be costly

 - Sanity check the size of struct properties_header on Mac/x86

 - Tweak the prototype of efi_guid_to_str()

* tag 'efi-next-for-v7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/efi/efi:
  efivarfs: Rate limit statfs() handler
  efi: apple-properties: validate setup data header length
  efi: make efi_guid_to_str() take a const GUID pointer
  efi/runtime-wrappers: retire the worker if a wedged call ever returns
  efi/runtime-wrappers: honour EFI_RUNTIME_SERVICES in the non-blocking paths
  efi/runtime-wrappers: bound the wait for EFI runtime service calls
  efi/runtime-wrappers: check EFI_RUNTIME_SERVICES before using efi_rts_work
  efi/runtime-wrappers: handle queue_work() failure with goto exit
  efi/runtime-wrappers: factor out efi_rts_park_worker()
  efi: fix stale reference to efi_recover_from_page_fault()
2026-08-23 09:24:34 -07:00
Linus Torvalds
91959a31a3 kho: make boot time huge page allocation work nicely with KHO
Today allocation of gigantic pages in HugeTLB cannot work reliably with KHO:
 
 * HugeTLB allocates gigantic pages using memblock and autoscaling of KHO
   scratch accounts for these allocations. When gigantic pages occupy half
   of the memory of more, KHO fails to allocate its scratch memory.
 * After kexec handover, memblock allocations exclusively use KHO scratch
   that is not supposed to contain preserved memory. This essentially blocks
   preservation of HugeTLB with gigantic pages.
 
 Extend early memory pools available for KHO kernel with areas that are
 guaranteed not to contain preserved memory.
 -----BEGIN PGP SIGNATURE-----
 
 iQEzBAABCgAdFiEEeOVYVaWZL5900a/pOQOGJssO/ZEFAmqK9NwACgkQOQOGJssO
 /ZGN3wgAqX/mXawYnhwDW2J931VsT54RuEctSNTCZ4Va8CWfeVjSV2bD2BlM+ibi
 VtsvEAIdKb8tyx3t+3JLR3jrANE5XcxeDiS7sJG7QWaek6G++GdAmrm7q98rU7Pc
 rqX8kMf65AZpHuV5wzKgF1fuYYur5Y4sKK00GVq+hPyWshmeYhaa+nGtJNe67D1a
 CFw38r5WAPs/DwyvWg/3yfupbgTG6OShHPnKxqR7aaOJE4YnD3snsBM7hot/ZI7e
 kz4TqixkxKn1RXq0XDcj8w11LxhxxsI67x02Fnnc1ClgMynCgDOvRXW6B93qRIRM
 ZUK8fbzIxFDQHnfzWRXcIIsN7r54Ow==
 =JHVN
 -----END PGP SIGNATURE-----

Merge tag 'liveupdate-v7.3-rc1-20260823' of git://git.kernel.org/pub/scm/linux/kernel/git/liveupdate/linux

Pull more liveupdate updates from Mike Rapoport:
 "Make boot time huge page allocation work nicely with kexec handover.

  Today allocation of gigantic pages in HugeTLB cannot work reliably
  with kexec handover (KHO):

   - HugeTLB allocates gigantic pages using memblock and autoscaling of
     KHO scratch accounts for these allocations. When gigantic pages
     occupy half of the memory of more, KHO fails to allocate its
     scratch memory.

   - After kexec handover, memblock allocations exclusively use KHO
     scratch that is not supposed to contain preserved memory. This
     essentially blocks preservation of HugeTLB with gigantic pages.

  Extend early memory pools available for KHO kernel with areas that are
  guaranteed not to contain preserved memory"

* tag 'liveupdate-v7.3-rc1-20260823' of git://git.kernel.org/pub/scm/linux/kernel/git/liveupdate/linux: (21 commits)
  kho: exclude hugetlb memory from scratch size calculation
  memblock: add memblock_reserved_hugetlb_size()
  memblock: make HugeTLB bootmem allocation work with KHO
  memblock: always include KHO headers
  kho: extend scratch
  mm/mm_init: don't rely on memblock to get KHO scratch migratetype
  kho: initialize preserved memory map radix tree earlier
  kho: initialize kho_scratch pointer earlier in boot
  kho: expose kho_scratch_overlap() to kexec_handover.h
  kho: add kho_radix_init_tree()
  kho: allow destroying KHO radix tree
  kho: allow early-boot usage of the KHO radix tree
  kho: add data argument to radix walk callback
  kho: add callback for table pages
  kho: add a struct for radix callbacks
  kho: move all memory retrieval logic to kho_mem_retrieve()
  kho: store incoming radix tree in kho_in
  kho: disallow wide keys in radix tree
  kho: make radix max key width more obvious
  kho: generalize radix tree APIs
  ...
2026-08-23 09:17:38 -07:00
Linus Torvalds
df51bdc5e8 * Raw NAND changes
- Sunxi: Support added for the H616 compatible
 - Qcom: Support added for the MDM9607 compatible
 - Support for the Toshiba TC58NVG1S3H part
 - GPMI: New debugfs entry to expose the chip geometry
 - PL353: Timing updates and software ECC support have been fixed
 
 * SPI NAND changes
 - fmsh: Support added for FM25G{01,02}B chips
 - HeYangTek: Support added for HYF1GQ4UDACAE
 
 Aside from these main changes, there is a high load of misc fixes and
 hardening changes, and exceptionally no SPI NOR change.
 -----BEGIN PGP SIGNATURE-----
 
 iQEzBAABCgAdFiEE9HuaYnbmDhq/XIDIJWrqGEe9VoQFAmqK6JQACgkQJWrqGEe9
 VoQa/QgAjuWoPOE1euZlAwwAwje44JZn+FfONyIjUeEfq8SFH9nchfyVpEKF95tU
 PF3YkhCCKavD0FNeTPpJoAhEYsqomVQmLLhUg+smoj5ii7Rudihpwn1f+7QpYrXS
 jdmWCz3YigILWL3B4CE0GWfUR+GhBH8kF+N+5/rcAddC9XC/22Y/rKKQ7LDcC6TM
 AH6OT+1J92lX/rSAyym/BHAmqydN6ZNKe4+LY8kghRd01XNBgMx1a2WoZ4RL+v3a
 J7sCoG6YCZE7pm9UqPHQfIWHtDyrTbQKy51jgUNyy8TdbTrhiTwuhO5LgYq/WrS0
 Y3PGbxWV0tcvRTaYvzNFCKyaZVjIxg==
 =dLT3
 -----END PGP SIGNATURE-----

Merge tag 'mtd/for-7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/mtd/linux

Pull mtd updates from Miquel Raynal:
 "Raw NAND changes:
   - Sunxi: Support added for the H616 compatible
   - Qcom: Support added for the MDM9607 compatible
   - Support for the Toshiba TC58NVG1S3H part
   - GPMI: New debugfs entry to expose the chip geometry
   - PL353: Timing updates and software ECC support have been fixed

  SPI NAND changes:
   - fmsh: Support added for FM25G{01,02}B chips
   - HeYangTek: Support added for HYF1GQ4UDACAE

  Aside from these main changes, there is a high load of misc fixes and
  hardening changes, and exceptionally no SPI NOR change"

* tag 'mtd/for-7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/mtd/linux: (30 commits)
  mtd: rawnand: sunxi: fix H6/H616 controller timings
  mtd: rawnand: sunxi: describe tADL and tWHR delays
  mtd: rawnand: sunxi: group controller delay tables
  mtd: maps: remove dead select of MTD_CFI_BE_BYTE_SWAP
  mtd: rawnand: gpmi: add debugfs entry for BCH geometry
  mtd: rawnand: validate ONFI extended parameter page sections
  mtd: rawnand: sunxi: add H616 MBUS DMA support
  mtd: spinand: fmsh: fix FM25G01B/FM25G02B Quad I/O read dummy cycles
  mtd: part: reject MTDPART_OFS_RETAIN in mtd_add_partition()
  mtd: mpc5121_nfc: use platform for irq and ioremap
  mtd: mtdoops: free page bitmap when the backing MTD is removed
  mtd: mtdswap: Avoid freeing registered blktrans device twice
  mtd: afs: validate v2 image info bounds
  mtd: intel-dg: Fix runtime PM error path in probe
  mtd: nand-omap2: Move omap_nand_ids[] to raw nand driver
  mtd: rawnand: add Toshiba TC58NVG1S3H
  mtd: nand: realtek-ecc: add missing MODULE_DEVICE_TABLE()
  mtd: rawnand: qcom: Add MDM9607 compatible
  mtd: rawnand: qcom: Make has_onfi_read_op separate from qpic_version2
  mtd: rawnand: qcom: Make "aon" clock optional
  ...
2026-08-23 09:11:21 -07:00
Linus Torvalds
61a09cfc12 This contains a set of 142 SMB server updates focused on SMB2 command
sequencing, SMB3 request replay and encryption, Apple Time Machine
 interoperability, protocol-compatibility fixes validated with smbtorture,
 security hardening, SMB Direct transport support, connection reliability,
 and other correctness improvements.
 
 New features:
 
  - Implement the SMB2 command sequence window.
    Enforce the credit-based MessageId range for each connection, rejecting
    out-of-window, duplicate, and wrapped sequence numbers. This prevents
    invalid requests and same-channel replays from being processed.
 
  - Add SMB3 request replay support.
    SMB3 clients may resend requests with SMB2_FLAGS_REPLAY_OPERATION after
    a channel disconnect when the original response was lost. Track the
    required channel and open state to safely handle durable CREATE replays
    and make oplock, lease, and lock replays idempotent, avoiding duplicate
    state changes and improving multichannel reconnect reliability.
 
  - Add opt-in Apple Time Machine support.
    Implement the AAPL negotiation and related Finder, stream, COPYCHUNK,
    sparse-file, CHANGE_NOTIFY, and RPC compatibility required for Time
    Machine shares, allowing macOS backupd to use ksmbd for backups.
 
  - Add per-share SMB3 encryption support.
    Allow individual shares to require SMB3 encryption by advertising
    SMB2_SHAREFLAG_ENCRYPT_DATA in TREE_CONNECT responses and rejecting
    unencrypted tree connects and plaintext requests for protected shares.
 
  - Add SMB Direct RDMA encryption support.
    Extend SMB Direct to support SMB3 encrypted payloads over RDMA, with
    transform negotiation and encryption/decryption for RDMA READ/WRITE.
 
 Other changes:
 
  - Parse and retain AppInstanceVersion contexts, enforce version ordering,
    close older active handles for newer takeovers, and reject invalid or
    unversioned opens according to the SMB2 semantics.
 
  - Accept durable reconnect requests that omit VolatileFileId when the
    persistent ID and reconnect context identify the handle, while
    continuing to reject explicit volatile-ID mismatches.
 
  - Fix SMB2/SMB3 protocol validation and security issues, including request
    offsets, file and object IDs, IPC responses, output buffer sizes,
    SMB3.1.1 binding validation, signing-required handling, durable handles,
    ACLs, maximal access, and security information.
 
  - Fix heap out-of-bounds accesses, use-after-free bugs, memory leaks,
    invalid pointer dereferences, and sensitive-data lifetime issues in
    authentication, Kerberos, preauthentication, sessions, connections,
    and module teardown.
 
  - Correct alternate-data-stream and named-stream handling, COPYCHUNK
    behavior, sparse-file and compression attributes, allocated-range
    queries, file trimming, duplicate extents, DOS attributes, snapshots,
    normalized names, and partial information responses.
 
  - Fix locking, lease, oplock, durable reconnect, async request, and
    CHANGE_NOTIFY races, including deferred-lock rollback, parent directory
    lease notifications, and connection teardown lifetime bugs.
 
  - Fix SMB3 encryption handling for compressed requests, expired encrypted
    sessions, interim responses, bound multichannel connections, and
    decryption failures.
 
  - Fix SMB3 multichannel session lookup and session state transitions so
    changes are scoped to the correct bound connections and cannot revive
    connections that are already shutting down.
 
  - Fix DACL access checks so ACE walks are bounded by the declared DACL
    size, preventing data beyond the DACL boundary from being interpreted
    during access validation.
 
  - Fix session accounting and lifetime issues, including session counter
    updates during publication and removal, session leaks on registration
    failure, and procfs creation diagnostics.
 
  - Improve TCP connection reliability by enabling TCP keepalive for
    accepted connections and preserving TCP timers for kernel sockets,
    preventing silent peers from holding connections indefinitely.
 
  - Fix smbdirect RDMA cleanup ordering for completion queues, QPs, child
    sockets, and listener locking.
 
  - Improve async response framing, multi-iovec signing, RPC pipe status
    handling, and ksmbd procfs monitoring for server, share, connection,
    session, and open-file state.
 
  - Remove the obsolete DES crypto header and Kconfig dependency now that
    NTLMv1 support has been removed.
 
  - Update the ksmbd repository URL in MAINTAINERS and add an additional
    KSMBD reviewer.
 -----BEGIN PGP SIGNATURE-----
 
 iQJKBAABCgA0FiEE6NzKS6Uv/XAAGHgyZwv7A1FEIQgFAmqKrvwWHGxpbmtpbmpl
 b25Aa2VybmVsLm9yZwAKCRBnC/sDUUQhCExxEACUk9E89TrgHUlSni/U4WEcg95n
 YNVm+oeRNnpqu7axGtIqmzgc7eU96ofR8un0pNLjkdWSD27hv6bmUv0e2+uOI7LU
 04FIwJfOLPR4roKgwyLhC+I88zjHWBxU2fAx1l0ksFpTAF4vFuo2Il/TsaM57QEm
 qhE0laiLV95jrtafnW8l2E+Be+qsRy7wRrj69IThfBBpwEMvehL3JK42yDItLKUm
 ETKJuO4O3QCN1tyMlntzshdLhuFIWrnNspTwKqMEE9/Ba4cuzGrcm6Y4tLDHDX/j
 Vr45w6rFsULJhw2mSz8cRYV3HcrPea7CVynJVDYtdIAngez0O3iLE5qAM1gff0HG
 5H4N57ye3iabySD9B9Hy8ISqreCGW7dNZf3LACmZyeXjNGmxGB4nrgTc9fz1SAcl
 JizpgMxrh2xj0YmABShgfqHFn9u+QvWaMIDYUddIQ+fX1Y+TxHDPssGJ0ygXCyJ0
 BrIwqRHgL7XONY2sx8bPWExAzVZq/4gPWVZACM7X138iuR1kDIEpnPqvMMpPx8am
 x5jSgvQ8NdABxLUZWU3BhcJseGG4gbvq0HzYibR6MPNy6P5ct3q+ifiWuY/JZ8Op
 ZTxcyShSXziy8uk7iKvGgS3eJ5bDSb2Wo9flkvoCifG7VgPfDec3d/V4f1n9cTix
 2TpmzQRF98f6arzzSQ==
 =uocO
 -----END PGP SIGNATURE-----

Merge tag 'ksmbd-for-7.3-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/linkinjeon/smb

Pull smb server updates from Namjae Jeon:
 "This contains server updates focused on SMB2 command sequencing, SMB3
  request replay and encryption, Apple Time Machine interoperability,
  protocol-compatibility fixes validated with smbtorture, security
  hardening, SMB Direct transport support, connection reliability, and
  other correctness improvements.

  New features:

   - Implement the SMB2 command sequence window

     Enforce the credit-based MessageId range for each connection,
     rejecting out-of-window, duplicate, and wrapped sequence numbers.
     This prevents invalid requests and same-channel replays from being
     processed

   - Add SMB3 request replay support

     SMB3 clients may resend requests with SMB2_FLAGS_REPLAY_OPERATION
     after a channel disconnect when the original response was lost.
     Track the required channel and open state to safely handle durable
     CREATE replays and make oplock, lease, and lock replays idempotent,
     avoiding duplicate state changes and improving multichannel
     reconnect reliability

   - Add opt-in Apple Time Machine support

     Implement the AAPL negotiation and related Finder, stream,
     COPYCHUNK, sparse-file, CHANGE_NOTIFY, and RPC compatibility
     required for Time Machine shares, allowing macOS backupd to use
     ksmbd for backups

   - Add per-share SMB3 encryption support

     Allow individual shares to require SMB3 encryption by advertising
     SMB2_SHAREFLAG_ENCRYPT_DATA in TREE_CONNECT responses and rejecting
     unencrypted tree connects and plaintext requests for protected
     shares

   - Add SMB Direct RDMA encryption support

     Extend SMB Direct to support SMB3 encrypted payloads over RDMA,
     with transform negotiation and encryption/decryption for RDMA
     READ/WRITE

  Other changes:

   - Parse and retain AppInstanceVersion contexts, enforce version
     ordering, close older active handles for newer takeovers, and
     reject invalid or unversioned opens according to the SMB2 semantics

   - Accept durable reconnect requests that omit VolatileFileId when the
     persistent ID and reconnect context identify the handle, while
     continuing to reject explicit volatile-ID mismatches

   - Fix SMB2/SMB3 protocol validation and security issues, including
     request offsets, file and object IDs, IPC responses, output buffer
     sizes, SMB3.1.1 binding validation, signing-required handling,
     durable handles, ACLs, maximal access, and security information

   - Fix heap out-of-bounds accesses, use-after-free bugs, memory leaks,
     invalid pointer dereferences, and sensitive-data lifetime issues in
     authentication, Kerberos, preauthentication, sessions, connections,
     and module teardown

   - Correct alternate-data-stream and named-stream handling, COPYCHUNK
     behavior, sparse-file and compression attributes, allocated-range
     queries, file trimming, duplicate extents, DOS attributes,
     snapshots, normalized names, and partial information responses

   - Fix locking, lease, oplock, durable reconnect, async request, and
     CHANGE_NOTIFY races, including deferred-lock rollback, parent
     directory lease notifications, and connection teardown lifetime
     bugs

   - Fix SMB3 encryption handling for compressed requests, expired
     encrypted sessions, interim responses, bound multichannel
     connections, and decryption failures

   - Fix SMB3 multichannel session lookup and session state transitions
     so changes are scoped to the correct bound connections and cannot
     revive connections that are already shutting down

   - Fix DACL access checks so ACE walks are bounded by the declared
     DACL size, preventing data beyond the DACL boundary from being
     interpreted during access validation

   - Fix session accounting and lifetime issues, including session
     counter updates during publication and removal, session leaks on
     registration failure, and procfs creation diagnostics

   - Improve TCP connection reliability by enabling TCP keepalive for
     accepted connections and preserving TCP timers for kernel sockets,
     preventing silent peers from holding connections indefinitely

   - Fix smbdirect RDMA cleanup ordering for completion queues, QPs,
     child sockets, and listener locking

   - Improve async response framing, multi-iovec signing, RPC pipe
     status handling, and ksmbd procfs monitoring for server, share,
     connection, session, and open-file state

   - Remove the obsolete DES crypto header and Kconfig dependency now
     that NTLMv1 support has been removed

   - Update the ksmbd repository URL in MAINTAINERS and add an
     additional KSMBD reviewer"

* tag 'ksmbd-for-7.3-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/linkinjeon/smb: (142 commits)
  MAINTAINERS: update ksmbd repository URL
  MAINTAINERS: add myself as KSMBD reviewer
  smb: server: remove unused DES crypto header
  smb: server: Remove obsolete "select CRYPTO_LIB_DES" from Kconfig file
  ksmbd: keep TCP timers alive for kernel sockets
  ksmbd: enable TCP keepalive for accepted connections
  smb/server: fix session counter on session removal
  smb/server: update session counter under sessions table lock
  smb/server: fix session leak in ksmbd_session_register()
  smb/server: warn if ksmbd_proc_create() fails
  ksmbd: bound smb_check_perm_dacl() ACE walks by DACL size
  ksmbd: make RDMA encryption diagnostics conditional
  ksmbd: add SMB Direct RDMA encryption transform
  ksmbd: handle encrypted compressed requests
  ksmbd: decrypt requests from expired encrypted sessions
  ksmbd: disconnect on SMB3 decryption failure
  ksmbd: encrypt interim responses to encrypted requests
  ksmbd: scope session state changes to bound connections
  ksmbd: fix encrypted request lookup on bound channels
  ksmbd: add per-share SMB3 encryption enforcement
  ...
2026-08-23 08:41:36 -07:00
David Sterba
0714cf44ac MAINTAINERS: update btrfs git tree entries
Add new entry pointing to the development branch so e.g. sashiko can
pick it as the baseline. The other entry is for linux-next and slightly
behind.

Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
2026-08-23 08:32:05 -07:00